/ip firewall address-list
add address=192.168.16.0/24 list="IP LAN"
add address=10.10.20.0/24 list="IP LAN"
/ip firewall filter
add action=drop chain=forward dst-address=192.168.16.0/24 src-address=\
10.10.20.0/24
add action=drop chain=forward disabled=yes layer7-protocol="!BLOCK DELL" \
protocol=tcp src-address=192.168.16.97
add action=drop chain=forward disabled=yes layer7-protocol="!BLOCK DELL" \
protocol=udp src-address=192.168.16.97
/ip firewall mangle
add action=accept chain=prerouting comment=QOS dst-address-list=CONNECTED \
src-address-list=CONNECTED
add action=accept chain=forward dst-address-list=CONNECTED src-address-list=\
CONNECTED
add action=mark-connection chain=postrouting comment="KET NOI BROWSING" \
dst-address-list="IP BROWSING" new-connection-mark=BROWSING passthrough=\
yes src-address-list="IP LAN"
add action=mark-packet chain=forward connection-mark=BROWSING \
dst-address-list="IP LAN" in-interface=pppoe-VNPT new-packet-mark=\
"BROWSING- DOWNLOAD" passthrough=no
add action=mark-packet chain=forward connection-mark=BROWSING \
new-packet-mark="BROWSING- UPLOAD" out-interface=pppoe-VNPT passthrough=\
no src-address-list="IP LAN"
add action=mark-packet chain=forward connection-mark="BROWSING CONLAI" \
dst-address-list="IP LAN" in-interface=pppoe-VNPT new-packet-mark=\
"BROWSING CONLAI- DOWNLOAD" passthrough=no
add action=mark-packet chain=forward connection-mark="BROWSING CONLAI" \
new-packet-mark="BROWSING CONLAI- UPLOAD" out-interface=pppoe-VNPT \
passthrough=no src-address-list="IP LAN"
add action=mark-connection chain=postrouting comment="KET NOI HEAVY BROWSING" \
connection-mark=BROWSING connection-rate=2048k-40M dst-address-list=\
!CONNECTED new-connection-mark="HEAVY BROWSING" passthrough=yes \
src-address-list="IP LAN"
add action=mark-connection chain=prerouting connection-mark="BROWSING CONLAI" \
connection-rate=2048k-40M dst-address-list=!CONNECTED \
new-connection-mark="HEAVY BROWSING" passthrough=yes src-address-list=\
"IP LAN"
add action=mark-packet chain=forward connection-mark="HEAVY BROWSING" \
new-packet-mark="HEAVY BROWSING- UPLOAD" out-interface=pppoe-VNPT \
passthrough=no src-address-list="IP LAN"
add action=mark-connection chain=prerouting comment="KET NOI ICMP" \
dst-address-list=!CONNECTED new-connection-mark=ICMP passthrough=yes \
protocol=icmp src-address-list="IP LAN"
add action=mark-packet chain=forward connection-mark=ICMP dst-address-list=\
"IP LAN" in-interface=pppoe-VNPT new-packet-mark="ICMP- DOWNLOAD" \
passthrough=no
add action=mark-packet chain=forward connection-mark=ICMP new-packet-mark=\
"ICMP- UPLOAD" out-interface=pppoe-VNPT passthrough=no src-address-list=\
"IP LAN"
add action=mark-connection chain=prerouting comment="KET NOI DNS" \
connection-mark=!BROWSING dst-address-list=!CONNECTED dst-port=53 \
new-connection-mark
NS passthrough=yes protocol=tcp src-address-list=\
"IP LAN"
add action=mark-connection chain=prerouting connection-mark=!BROWSING \
dst-address-list=!CONNECTED dst-port=53 new-connection-mark
NS \
passthrough=yes protocol=udp src-address-list="IP LAN"
add action=mark-packet chain=forward connection-mark
NS dst-address-list=\
"IP LAN" in-interface=pppoe-VNPT new-packet-mark="DNS- DOWNLOAD" \
passthrough=no
add action=mark-packet chain=forward connection-mark
NS new-packet-mark=\
"DNS- UPLOAD" out-interface=pppoe-VNPT passthrough=no src-address-list=\
"IP LAN"
add action=mark-connection chain=postrouting comment="KET NOI FACEBOOK" \
dst-address-list="IP FACEBOOK" new-connection-mark=FACEBOOK passthrough=\
yes src-address-list="IP LAN"
add action=mark-packet chain=forward connection-mark=FACEBOOK \
dst-address-list="IP LAN" in-interface=pppoe-VNPT new-packet-mark=\
"FACEBOOK- DOWNLOAD" passthrough=no
add action=mark-packet chain=forward connection-mark=FACEBOOK \
new-packet-mark="FACEBOOK- UPLOAD" out-interface=pppoe-VNPT passthrough=\
no src-address-list="IP LAN"
add action=mark-connection chain=postrouting comment="KET NOI YOUTUBE" \
dst-address-list="IP YOUTUBE" new-connection-mark=YOUTUBE passthrough=yes \
src-address-list="IP LAN"
add action=mark-packet chain=forward connection-mark=YOUTUBE \
dst-address-list="IP LAN" in-interface=pppoe-VNPT new-packet-mark=\
"YOUTUBE- DOWNLOAD" passthrough=no
add action=mark-packet chain=forward connection-mark=YOUTUBE new-packet-mark=\
"YOUTUBE- UPLOAD" out-interface=pppoe-VNPT passthrough=no \
src-address-list="IP LAN"
add action=mark-connection chain=postrouting comment="KET NOI ZALO" \
dst-address-list="IP ZALO" new-connection-mark=ZALO passthrough=yes \
src-address-list="IP LAN"
add action=mark-packet chain=forward connection-mark=ZALO dst-address-list=\
"IP LAN" in-interface=pppoe-VNPT new-packet-mark="ZALO- DOWNLOAD" \
passthrough=no
add action=mark-packet chain=forward connection-mark=ZALO new-packet-mark=\
"ZALO- UPLOAD" out-interface=pppoe-VNPT passthrough=no src-address-list=\
"IP LAN"
add action=mark-connection chain=postrouting comment="KET NOI INSTAGRAM" \
dst-address-list="IP INSTAGRAM" new-connection-mark=INSTAGRAM \
passthrough=yes src-address-list="IP LAN"
add action=mark-packet chain=forward connection-mark=INSTAGRAM \
dst-address-list="IP LAN" in-interface=pppoe-VNPT new-packet-mark=\
"INSTAGRAM- DOWNLOAD" passthrough=no
add action=mark-packet chain=forward connection-mark=INSTAGRAM \
new-packet-mark="INSTAGRAM- UPLOAD" out-interface=pppoe-VNPT passthrough=\
no src-address-list="IP LAN"
add action=mark-connection chain=postrouting comment="KET NOI TIKTOK" \
dst-address-list="IP TIKTOK" new-connection-mark=TIKTOK passthrough=yes \
src-address-list="IP LAN"
add action=mark-packet chain=forward connection-mark=TIKTOK dst-address-list=\
"IP LAN" in-interface=pppoe-VNPT new-packet-mark="TIKTOK- DOWNLOAD" \
passthrough=no
add action=mark-packet chain=forward connection-mark=TIKTOK new-packet-mark=\
"TIKTOK- UPLOAD" out-interface=pppoe-VNPT passthrough=no \
src-address-list="IP LAN"
add action=mark-connection chain=postrouting comment="KET NOI GAME ONLINE" \
connection-mark=!BROWSING dst-address-list="IP GAME" new-connection-mark=\
"GAME ONLINE" passthrough=yes src-address-list="IP LAN"
add action=mark-packet chain=forward connection-mark="GAME ONLINE" \
dst-address-list="IP LAN" in-interface=pppoe-VNPT new-packet-mark=\
"GAME ONLINE- DOWNLOAD" passthrough=no
add action=mark-packet chain=forward connection-mark="GAME ONLINE" \
new-packet-mark="GAME ONLINE- UPLOAD" out-interface=pppoe-VNPT \
passthrough=no src-address-list="IP LAN"
/ip firewall nat
add action=masquerade chain=srcnat out-interface=pppoe-VNPT src-address=\
192.168.16.0/24
add action=masquerade chain=srcnat out-interface=pppoe-VNPT src-address=\
10.10.20.0/24
add action=dst-nat chain=dstnat comment="MO PROT NAS" dst-port=5000 \
in-interface=pppoe-VNPT protocol=tcp to-addresses=192.168.16.6 to-ports=\
5000
add action=dst-nat chain=dstnat dst-port=6990 in-interface=pppoe-VNPT \
protocol=tcp to-addresses=192.168.16.6 to-ports=6990
add action=dst-nat chain=dstnat dst-port=6690 in-interface=pppoe-VNPT \
protocol=tcp to-addresses=192.168.16.6 to-ports=6690
add action=dst-nat chain=dstnat dst-port=5001 in-interface=pppoe-VNPT \
protocol=tcp to-addresses=192.168.16.6 to-ports=5001
add action=dst-nat chain=dstnat dst-port=8443 in-interface=pppoe-VNPT \
protocol=tcp to-addresses=192.168.16.6 to-ports=8443
/ip firewall raw
add action=add-dst-to-address-list address-list="IP BROWSING" \
address-list-timeout=30m chain=prerouting comment="IP BROWSING" \
dst-address-list=!CONNECTED dst-port=\
80,81,443,8000-8081,21,22,23,81,88,5050,843,182,53 protocol=tcp \
src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP BROWSING" \
address-list-timeout=30m chain=prerouting dst-address-list=!CONNECTED \
dst-port=80,81,443,8000-8081,21,22,23,81,88,5050,843,182,53 protocol=udp \
src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP YOUTUBE" \
address-list-timeout=30m chain=prerouting comment="IP YOUTUBE" content=\
googlevideo.com dst-address-list=!CONNECTED src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP YOUTUBE" \
address-list-timeout=30m chain=prerouting content=.youtube \
dst-address-list=!CONNECTED src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP YOUTUBE" \
address-list-timeout=30m chain=prerouting content=ytimg.com \
dst-address-list=!CONNECTED src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP FACEBOOK" \
address-list-timeout=30m chain=prerouting comment="IP FACEBOOK" content=\
.facebook.com dst-address-list=!CONNECTED src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP FACEBOOK" \
address-list-timeout=30m chain=prerouting content=.facebook.net \
dst-address-list=!CONNECTED src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP FACEBOOK" \
address-list-timeout=30m chain=prerouting content=.fbcdn.net \
dst-address-list=!CONNECTED src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP ZALO" \
address-list-timeout=30m chain=prerouting comment="IP ZALO" content=\
.chat.zalo.me dst-address-list=!CONNECTED src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP ZALO" \
address-list-timeout=30m chain=prerouting content=.zalo.me \
dst-address-list=!CONNECTED src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP ZALO" \
address-list-timeout=30m chain=prerouting content=log.api.zaloapp.com \
dst-address-list=!CONNECTED src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP ZALO" \
address-list-timeout=30m chain=prerouting content=.zadn.vn \
dst-address-list=!CONNECTED src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP INSTAGRAM" \
address-list-timeout=30m chain=prerouting comment="IP INSTAGRAM" content=\
.cdninstagram.com dst-address-list=!CONNECTED src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP INSTAGRAM" \
address-list-timeout=30m chain=prerouting content=\
scontent-sin6-2.cdninstagram.com dst-address-list=!CONNECTED \
src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP INSTAGRAM" \
address-list-timeout=30m chain=prerouting content=.instagram.com \
dst-address-list=!CONNECTED src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP TIKTOK" \
address-list-timeout=30m chain=prerouting comment="IP TIKTOK" content=\
tiktokcdn.com dst-address-list=!CONNECTED src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP TIKTOK" \
address-list-timeout=30m chain=prerouting content=tiktokv.com \
dst-address-list=!CONNECTED src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP TIKTOK" \
address-list-timeout=30m chain=prerouting content=.amemv.com \
dst-address-list=!CONNECTED src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP TIKTOK" \
address-list-timeout=30m chain=prerouting content=.musical.ly \
dst-address-list=!CONNECTED src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP GAME" \
address-list-timeout=1h chain=prerouting comment="GAME: AOV - LIEN QUAN" \
dst-address-list=!CONNECTED dst-port=10001-10094 protocol=tcp \
src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP GAME" \
address-list-timeout=1h chain=prerouting dst-address-list=!CONNECTED \
dst-port=10101-10201,10080-10110,17000-18000 protocol=udp \
src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP GAME" \
address-list-timeout=1h chain=prerouting comment="GAME: FREE FIRE" \
dst-address-list=!CONNECTED dst-port=7006,14000,20561,39698,39779,39003 \
protocol=tcp src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP GAME" \
address-list-timeout=1h chain=prerouting dst-address-list=!CONNECTED \
dst-port=7008,10000-10009,17000 protocol=udp src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP GAME" \
address-list-timeout=1h chain=prerouting comment="GAME: MOBILE LEGENDS" \
dst-address-list=!CONNECTED dst-port=\
5000-5508,5551-5558,5601-5608,5651-5658,30097-30147,9000-9010 protocol=\
tcp src-address-list="IP LAN"
add action=add-dst-to-address-list address-list="IP GAME" \
address-list-timeout=1h chain=prerouting dst-address-list=!CONNECTED \
dst-port=5000-5200,5500-5700,8001,30000-30300,9000-9010 protocol=udp \
src-address-list="IP LAN"
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www disabled=yes
set ssh disabled=yes
set api disabled=yes
set api-ssl disabled=yes
/system clock
set time-zone-name=Asia/Ho_Chi_Minh
/system ntp client
set enabled=yes primary-ntp=216.239.35.8
/system routerboard settings
set auto-upgrade=yes