سلام دوست عزیز این ها رو داخل روتر میکروتیک که دارید بزارید بسته میشه
این ابیوز بخاطر پورت اسکن هست و باید rfc ها را روی روتر که به عنوان روتر اصلی شبکه هست ببندید


کد PHP:
/ip firewall address-list
add address=0.0.0.0/8 comment="Self-Identification [RFC 3330]" list=bogons
add address
=10.0.0.0/8 comment="Private[RFC 1918] - CLASS A # Check if you nee\
    d this subnet before enable it" 
list=bogons
add address
=127.0.0.0/8 comment="Loopback [RFC 3330]" list=bogons
add address
=169.254.0.0/16 comment="Link Local [RFC 3330]" list=bogons
add address
=172.16.0.0/12 comment="Private[RFC 1918] - CLASS B # Check if you \
    need this subnet before enable it" 
list=bogons
add address
=192.168.0.0/16 comment="Private[RFC 1918] - CLASS C # Check if you\
    \_need this subnet before enable it" 
list=bogons
add address
=192.0.2.0/24 comment="Reserved - IANA - TestNet1" list=bogons
add address
=192.88.99.0/24 comment="6to4 Relay Anycast [RFC 3068]" list=\
    
bogons
add address
=198.18.0.0/15 comment="NIDB Testing" list=bogons
add address
=198.51.100.0/24 comment="Reserved - IANA - TestNet2" list=bogons
add address
=203.0.113.0/24 comment="Reserved - IANA - TestNet3" list=bogons
add address
=224.0.0.0/4 comment=\
    
"MC, Class D, IANA # Check if you need this subnet before enable it" \
    list=
bogons
/ip firewall filter
add action
=drop chain=forward comment="Drop to bogon list" dst-address-list=\
    
bogons
add action
=add-src-to-address-list address-list="port scanners" \
    
address-list-timeout=2w chain=input comment="Port scanners to list " \
    
protocol=tcp psd=21,3s,3,1
add action
=add-src-to-address-list address-list="port scanners" \
    
address-list-timeout=2w chain=input comment="Port scanners to list " \
    
protocol=tcp psd=21,3s,3,1
add action
=add-src-to-address-list address-list="port scanners" \
    
address-list-timeout=2w chain=input comment="NMAP FIN Stealth scan" \
    
protocol=tcp tcp-flags=fin,!syn,!rst,!psh,!ack,!urg
add action
=add-src-to-address-list address-list="port scanners" \
    
address-list-timeout=2w chain=input comment="SYN/FIN scan" protocol=tcp \
    
tcp-flags=fin,syn
add action
=add-src-to-address-list address-list="port scanners" \
    
address-list-timeout=2w chain=input comment="SYN/RST scan" protocol=tcp \
    
tcp-flags=syn,rst
add action
=add-src-to-address-list address-list="port scanners" \
    
address-list-timeout=2w chain=input comment="FIN/PSH/URG scan" protocol=\
    
tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack
add action
=add-src-to-address-list address-list="port scanners" \
    
address-list-timeout=2w chain=input comment="ALL/ALL scan" protocol=tcp \
    
tcp-flags=fin,syn,rst,psh,ack,urg
add action
=add-src-to-address-list address-list="port scanners" \
    
address-list-timeout=2w chain=input comment="NMAP NULL scan" protocol=tcp \
    
tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg
add action
=drop chain=input comment="dropping port scanners" \
    
src-address-list="port scanners"