/ip firewall filter
add chain=forward connection-state=established action=accept comment="Com estab"
add chain=forward connection-state=related action=accept comment="Com relac"
add chain=forward connection-state=invalid action=drop comment="Drop com inval"
add chain=input content=.scr action=drop comment="drop arquivo scr"
add chain=forward protocol=tcp dst-port=137-139 action=drop comment="drop netbios"
add chain=forward protocol=tcp dst-port=445 action=drop comment="drop netbios2"
add chain=input in-interface=VLAN_CEMIG_TELECOM_300 protocol=tcp dst-port=53
action=drop comment="drop server dns"
add chain=input in-interface=VLAN_CEMIG_TELECOM_300 protocol=udp dst-port=53
action=drop comment="drop server dns"
/ip firewall filter
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=445 action=drop
add comment="bloqueio virus" chain=virus protocol=udp dst-port=445 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=593 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=1080 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=1363 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=1364 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=1373 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=1377 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=1368 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=1433-1434
action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=1024-1030
action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=1214 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=135-139 action=drop
add comment="bloqueio virus" chain=virus protocol=udp dst-port=135-139 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=445 action=drop
add comment="bloqueio virus" chain=virus protocol=udp dst-port=445 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=593 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=1024-1030
action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=1080 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=1214 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=1363 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=1364 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=1368 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=1373 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=1377 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=1433-1434
action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=2745 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=2283 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=2535 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=2745 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=3127-3128
action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=3410 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=4444 action=drop
add comment="bloqueio virus" chain=virus protocol=udp dst-port=4444 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=5554 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=8866 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=9898 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=10000 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=10080 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=12345 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=17300 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=27374 action=drop
add comment="bloqueio virus" chain=virus protocol=tcp dst-port=65506 action=drop