
Postado originalmente por
olivionet
Cara tem uns filtros que você pode adicionar no wireless que bloqueia compartilhamento e DHCP server dos clientes (se usar RB mikrotik).
***********************************************************************
# Filtros de bridge, bloqueia comunicação entre clientes
# Defina nas variaveis abaixo todas as interfaces wireless que atendem clientes
# Cuidado: Nao coloque nessas regras as interfaces wireless de link PTP
# Variavies, altere os nomes das interfaces que estao entre aspas conforme nescessario, caso tenha menos interfaces que nesse
# Script, basta comentar a linha que nao for utilizar. Esse script esta preparado para quatro interfaces.
:local if1 "wlan1";
:local if2 "wlan2";
:local if3 "wlan3";
:local if4 "wlan4";
# Nao altere nada daqui para baixo
/interface bridge filter
add action=drop chain=forward comment="Block invalid DHPC Servers" \
disabled=no in-interface=$if1 ip-protocol=udp mac-protocol=ip \
src-port=67
add action=drop chain=forward comment="" disabled=no in-interface=$if2 \
ip-protocol=udp mac-protocol=ip src-port=67
add action=drop chain=forward comment="" disabled=no in-interface=$if3 \
ip-protocol=udp mac-protocol=ip src-port=67
add action=drop chain=forward comment="" disabled=no in-interface=$if4 \
ip-protocol=udp mac-protocol=ip src-port=67
add action=drop chain=forward comment="Block Relay" disabled=yes ip-protocol=\
tcp mac-protocol=ip src-port=135-139
add action=drop chain=forward comment="" disabled=yes ip-protocol=udp \
mac-protocol=ip src-port=135-139
add action=drop chain=forward comment="" disabled=yes dst-port=135-139 \
ip-protocol=tcp mac-protocol=ip
add action=drop chain=forward comment="" disabled=yes dst-port=135-139 \
ip-protocol=udp mac-protocol=ip
add action=drop chain=forward comment="" disabled=yes ip-protocol=tcp \
mac-protocol=ip src-port=445
add action=drop chain=forward comment="" disabled=yes dst-port=445 \
ip-protocol=tcp mac-protocol=ip
add action=drop chain=forward comment="" disabled=yes ip-protocol=tcp \
mac-protocol=ip src-port=5355-5358
add action=drop chain=forward comment="" disabled=yes dst-port=5355-5358 \
ip-protocol=tcp mac-protocol=ip
add action=drop chain=forward comment="" disabled=yes ip-protocol=udp \
mac-protocol=ip src-port=5355-5358
add action=drop chain=forward comment="" disabled=yes dst-port=5355-5358 \
ip-protocol=udp mac-protocol=ip
add action=drop chain=forward comment="" disabled=yes ip-protocol=udp \
mac-protocol=ip src-port=3702
add action=drop chain=forward comment="" disabled=yes dst-port=3702 \
ip-protocol=udp mac-protocol=ip
add action=drop chain=forward comment="" disabled=yes ip-protocol=udp \
mac-protocol=ip src-port=1900
add action=drop chain=forward comment="" disabled=yes dst-port=1900 \
ip-protocol=udp mac-protocol=ip
add action=drop chain=forward comment="" disabled=yes ip-protocol=tcp \
mac-protocol=ip src-port=2869
add action=drop chain=forward comment="" disabled=yes dst-port=2869 \
ip-protocol=tcp mac-protocol=ip
OBS.: NÃO POSTEI A FONTE POIS NÃO ME LEMBRO MAS PEGUEI AQUI NO FORUM !!