Wednesday, November 2, 2016

BLOCK WHATSAPP MESSENGER IN MIKROTIK

WhatsApp

Copy Below address and paste into terminal to block access of Whatsapp Messenger completely..
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
/ip firewall address-list
add address=31.13.64.51 list=Whatsapp
add address=31.13.65.49 list=Whatsapp
add address=31.13.66.49 list=Whatsapp
add address=31.13.67.51 list=Whatsapp
add address=31.13.69.240 list=Whatsapp
add address=31.13.70.49 list=Whatsapp
add address=31.13.71.49 list=Whatsapp
add address=31.13.72.52 list=Whatsapp
add address=31.13.73.49 list=Whatsapp
add address=31.13.74.49 list=Whatsapp
add address=31.13.75.52 list=Whatsapp
add address=31.13.76.81 list=Whatsapp
add address=31.13.77.49 list=Whatsapp
add address=31.13.79.195 list=Whatsapp
add address=31.13.80.53 list=Whatsapp
add address=31.13.81.53 list=Whatsapp
add address=31.13.82.51 list=Whatsapp
add address=31.13.83.51 list=Whatsapp
add address=31.13.84.51 list=Whatsapp
add address=31.13.85.51 list=Whatsapp
add address=31.13.86.51 list=Whatsapp
add address=31.13.87.51 list=Whatsapp
add address=31.13.88.49 list=Whatsapp
add address=31.13.88.57 list=Whatsapp
add address=31.13.90.51 list=Whatsapp
add address=31.13.91.51 list=Whatsapp
add address=31.13.92.52 list=Whatsapp
add address=31.13.93.51 list=Whatsapp
add address=31.13.95.63 list=Whatsapp
add address=50.22.75.192/27 list=Whatsapp
add address=50.22.93.192/27 list=Whatsapp
add address=50.22.198.204/30 list=Whatsapp
add address=50.22.210.32/30 list=Whatsapp
add address=50.22.210.128/27 list=Whatsapp
add address=50.22.225.64/27 list=Whatsapp
add address=50.22.235.248/30 list=Whatsapp
add address=50.22.240.160/27 list=Whatsapp
add address=50.23.90.128/27 list=Whatsapp
add address=50.97.57.128/27 list=Whatsapp
add address=75.126.39.32/27 list=Whatsapp
add address=108.168.174.0/27 list=Whatsapp
add address=108.168.176.192/26 list=Whatsapp
add address=108.168.177.0/27 list=Whatsapp
add address=108.168.180.96/27 list=Whatsapp
add address=108.168.254.65 list=Whatsapp
add address=108.168.255.224 list=Whatsapp
add address=108.168.255.227 list=Whatsapp
add address=158.85.0.96/27 list=Whatsapp
add address=158.85.5.192/27 list=Whatsapp
add address=158.85.46.128/27 list=Whatsapp
add address=158.85.48.224/27 list=Whatsapp
add address=158.85.58.0/25 list=Whatsapp
add address=158.85.61.192/27 list=Whatsapp
add address=158.85.224.160/27 list=Whatsapp
add address=158.85.233.32/27 list=Whatsapp
add address=158.85.249.128/27 list=Whatsapp
add address=158.85.249.224/27 list=Whatsapp
add address=158.85.254.64/27 list=Whatsapp
add address=169.53.29.128/27 list=Whatsapp
add address=169.53.71.224/27 list=Whatsapp
add address=169.53.250.128/26 list=Whatsapp
add address=169.54.2.160/27 list=Whatsapp
add address=169.54.51.32/27 list=Whatsapp
add address=169.54.55.192/27 list=Whatsapp
add address=169.54.210.0/27 list=Whatsapp
add address=169.54.222.128/27 list=Whatsapp
add address=169.55.69.128/26 list=Whatsapp
add address=169.55.74.32/27 list=Whatsapp
add address=169.55.235.160/27 list=Whatsapp
add address=173.192.162.32/27 list=Whatsapp
add address=173.192.219.128/27 list=Whatsapp
add address=173.192.222.160/27 list=Whatsapp
add address=173.192.231.32/27 list=Whatsapp
add address=173.193.205.0/27 list=Whatsapp
add address=173.193.230.96/27 list=Whatsapp
add address=173.193.230.128/27 list=Whatsapp
add address=173.193.230.192/27 list=Whatsapp
add address=173.193.239.0/27 list=Whatsapp
add address=174.36.208.128/27 list=Whatsapp
add address=174.36.210.32/27 list=Whatsapp
add address=174.36.251.192/27 list=Whatsapp
add address=174.37.199.192/27 list=Whatsapp
add address=174.37.215.28/30 list=Whatsapp
add address=174.37.217.64/27 list=Whatsapp
add address=174.37.231.64/27 list=Whatsapp
add address=174.37.243.64/27 list=Whatsapp
add address=174.37.251.0/27 list=Whatsapp
add address=179.60.192.51 list=Whatsapp
add address=179.60.193.51 list=Whatsapp
add address=179.60.195.51 list=Whatsapp
add address=184.173.73.176/28 list=Whatsapp
add address=184.173.136.64/27 list=Whatsapp
add address=184.173.147.32/27 list=Whatsapp
add address=184.173.161.64 list=Whatsapp
add address=184.173.161.160/27 list=Whatsapp
add address=184.173.173.116 list=Whatsapp
add address=184.173.179.32/27 list=Whatsapp
add address=184.173.195.32/27 list=Whatsapp
add address=184.173.201.32/27 list=Whatsapp
add address=184.173.204.32/27 list=Whatsapp
add address=184.173.250.53 list=Whatsapp
add address=192.155.212.192/27 list=Whatsapp
add address=198.11.193.182/31 list=Whatsapp
add address=198.11.212.0/27 list=Whatsapp
add address=198.11.217.192/27 list=Whatsapp
add address=198.11.251.32/27 list=Whatsapp
add address=198.23.80.0/27 list=Whatsapp
add address=198.23.86.224/27 list=Whatsapp
add address=198.23.87.64/27 list=Whatsapp
add address=208.43.115.192/27 list=Whatsapp
add address=208.43.117.79 list=Whatsapp
add address=208.43.117.136 list=Whatsapp
add address=208.43.122.128/27 list=Whatsapp
 
/ip firewall filter
add chain=forward dst-address-list=Whatsapp action=drop comment="Whatsapp Drop"
add chain=input src-address-list=Whatsapp action=drop comment="Whatsapp Drop"

BLOCK TEAMVIEWER CONNECTIONS ON MIKROTIK

teamviewer8-laptop-computer-connectionHere is a guide how to block Team Viewer connection
1
2
3
4
5
6
7
8
9
10
11
12
13
14
/ip firewall address-list
add address=92.51.128.0/18 comment=Teamviewer_Server list=Teamviewer
add address=37.48.64.0/18 comment=Teamviewer_Server list=Teamviewer
add address=217.146.26.0/24 comment=Teamviewer_Server list=Teamviewer
add address=88.198.0.0/16 comment=Teamviewer_Server list=Teamviewer
add address=37.252.253.0/24 comment=Teamviewer_Server list=Teamviewer
add address=178.255.155.0/24 comment=Teamviewer_Server list=Teamviewer
add address=159.8.64.0/18 comment=Teamviewer_Server list=Teamviewer
add address=178.77.64.0/18 comment=Teamviewer_Server list=Teamviewer
 
 
/ip firewall filter
add action=drop chain=forward comment="Drop all traffic from address on \\ Teamviewer \\ address list" src-address-list=Teamviewer
add action=drop chain=input comment="Drop all traffic from address on \\ Teamviewer \\ address list" src-address-list=Teamviewer
With these two settings, your router will ignore any client not getting response from Team Viewer.

Mikrotik Limit Download File Extension


IP FIREWALL FILTER
Note: change "192.168.100.0/24" with your Network Rules
/ip firewall filter
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment=\
"Limit Download by using File Extension" content=.exe disabled=no protocol=tcp \
src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.zip disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.arj disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.lzh disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.3gp disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.gz disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.gzip disabled=\
no protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.tar disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.bin disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.mp3 disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.m4a disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.wav disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.rar disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.ram disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.aac disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.aif disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.avi disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.mpg disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.mpeg disabled=\
no protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.qt disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.plj disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.asf disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.mov disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.rm disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.rm1 disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.mp4 disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.wma disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.wmv disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.mpe disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.mpa disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.pdf disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.msi disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.ace disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.iso disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.img disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.ogg disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.7z disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.sea disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.sit disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.doc disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.ppt disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.pps disabled=no \
protocol=tcp src-address=192.168.100.0/24
add action=add-dst-to-address-list address-list=limit-extension \
address-list-timeout=1h chain=forward comment="" content=.flv disabled=no \
protocol=tcp src-address=192.168.100.0/24

IP FIREWALL MANGLE
/ip firewall mangle
add action=mark-packet chain=forward comment="Limit Download" disabled=no \
new-packet-mark=Limit-Download passthrough=no protocol=tcp src-address-list=limit-extension

QUEUE TREE
Note:queue limit is 256k you can change with other limit by change "256000"
/queue tree
add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no limit-at=256000 \
max-limit=256k name=Limit-Download packet-mark=limit-download parent=\
global-out priority=8 queue=default