/ ip firewall mangle
add chain=prerouting protocol=tcp src-port=0-1024 action=mark-packet new-packet-mark=2 passthrough=yes comment="IMPORTANT SERVICES PORTS TCP+UDP" disabled=no
add chain=prerouting protocol=tcp dst-port=0-1024 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp src-port=0-1024 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp dst-port=0-1024 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=4000-4017 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=4000-4017 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp src-port=4000-4017 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp dst-port=4000-4017 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=10000-10020 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=10000-10020 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=icmp action=mark-packet new-packet-mark=2 passthrough=yes comment="ICMP" disabled=no
add chain=prerouting protocol=gre action=mark-packet new-packet-mark=3 passthrough=yes comment="TUNNELING" disabled=no
add chain=prerouting protocol=ipip action=mark-packet new-packet-mark=3 passthrough=yes comment="" disabled=no
add chain=prerouting connection-type=pptp action=mark-packet new-packet-mark=3 passthrough=yes comment="TUNNELING - pptp" disabled=no
add chain=prerouting connection-type=gre action=mark-packet new-packet-mark=3 passthrough=yes comment="TUNNELING - gre" disabled=no
add chain=prerouting protocol=tcp src-port=53 action=mark-packet new-packet-mark=2 passthrough=yes comment="DNS TCP" disabled=no
add chain=prerouting protocol=tcp dst-port=53 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp src-port=123 action=mark-packet new-packet-mark=2 passthrough=yes comment="NTP UDP" disabled=no
add chain=prerouting protocol=udp dst-port=123 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting p2p=all-p2p action=mark-connection new-connection-mark=p2p-connection passthrough=yes comment="P2P" disabled=no
add chain=prerouting connection-mark=p2p-connection action=mark-packet new-packet-mark=4 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp src-port=1200 action=mark-packet new-packet-mark=1 passthrough=yes comment="GAMES - Counterstrike" disabled=no
add chain=prerouting protocol=udp dst-port=1200 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp src-port=27000-27015 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp dst-port=27000-27015 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=27030-27039 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=27030-27039 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp src-port=20500 action=mark-packet new-packet-mark=1 passthrough=yes comment="GAMES - COD2" disabled=no
add chain=prerouting protocol=udp dst-port=20500 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp src-port=20510 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp dst-port=20510 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=28960 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=28960 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp src-port=28960 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp dst-port=28960 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp src-port=6112-6119 action=mark-packet new-packet-mark=1 passthrough=yes comment="GAMES - Warcraft III" disabled=no
add chain=prerouting protocol=udp dst-port=6112-6119 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=6112 action=mark-packet new-packet-mark=1 passthrough=yes comment="GAMES - World Of Warcraft" disabled=no
add chain=prerouting protocol=tcp dst-port=6112 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=6881-6999 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=6881-6999 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp src-port=1500-4999 action=mark-packet new-packet-mark=1 passthrough=yes comment="GAMES - Battlefield 2" disabled=no
add chain=prerouting protocol=udp dst-port=1500-4999 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=3724 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=3724 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=4711 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=4711 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp src-port=16567 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp dst-port=16567 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp src-port=27900 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp dst-port=27900 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=27901 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=27901 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=28910 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=28910 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp src-port=29900 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp dst-port=29900 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=29900-29901 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=29900-29901 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp src-port=55123-55125 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp dst-port=55123-55125 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting connection-type=ftp action=mark-packet new-packet-mark=3 passthrough=yes comment="FTP" disabled=no
add chain=prerouting protocol=tcp src-port=20-21 action=mark-packet new-packet-mark=3 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=20-21 action=mark-packet new-packet-mark=3 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=69 action=mark-packet new-packet-mark=3 passthrough=yes comment="TFTP" disabled=no
add chain=prerouting protocol=tcp dst-port=69 action=mark-packet new-packet-mark=3 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=115 action=mark-packet new-packet-mark=3 passthrough=yes comment="SFTP" disabled=no
add chain=prerouting protocol=tcp dst-port=115 action=mark-packet new-packet-mark=3 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp src-port=115 action=mark-packet new-packet-mark=3 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp dst-port=115 action=mark-packet new-packet-mark=3 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp src-port=137-139 action=mark-packet new-packet-mark=3 passthrough=yes comment="Windows NetBIOS" disabled=no
add chain=prerouting protocol=udp dst-port=137-139 action=mark-packet new-packet-mark=3 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=149 action=mark-packet new-packet-mark=4 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=149 action=mark-packet new-packet-mark=4 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=445 action=mark-packet new-packet-mark=4 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=445 action=mark-packet new-packet-mark=4 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=3128 action=mark-packet new-packet-mark=3 passthrough=yes comment="PROXY Client" disabled=no
add chain=prerouting protocol=tcp dst-port=3128 action=mark-packet new-packet-mark=3 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=3130 action=mark-packet new-packet-mark=2 passthrough=yes comment="PROXY - s2s" disabled=no
add chain=prerouting protocol=tcp dst-port=3130 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=8080 action=mark-packet new-packet-mark=3 passthrough=yes comment="PROXY Client" disabled=no
add chain=prerouting protocol=tcp dst-port=8080 action=mark-packet new-packet-mark=3 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=80 action=mark-packet new-packet-mark=3 passthrough=yes comment="HTTP" disabled=no
add chain=prerouting protocol=tcp dst-port=80 action=mark-packet new-packet-mark=3 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=443 action=mark-packet new-packet-mark=3 passthrough=yes comment="HTTPS" disabled=no
add chain=prerouting protocol=tcp dst-port=443 action=mark-packet new-packet-mark=3 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=25 action=mark-packet new-packet-mark=2 passthrough=yes comment="SMTP - POP - IMAP" disabled=no
add chain=prerouting protocol=tcp dst-port=25 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=110 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=110 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=143 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=143 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=22 action=mark-packet new-packet-mark=2 passthrough=yes comment="SSH" disabled=no
add chain=prerouting protocol=tcp dst-port=22 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=23 action=mark-packet new-packet-mark=2 passthrough=yes comment="TELNET" disabled=no
add chain=prerouting protocol=tcp dst-port=23 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=161 action=mark-packet new-packet-mark=1 passthrough=yes comment="SNMP TCP" disabled=no
add chain=prerouting protocol=tcp dst-port=161 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=873 action=mark-packet new-packet-mark=3 passthrough=yes comment="RSYNC" disabled=no
add chain=prerouting protocol=tcp dst-port=873 action=mark-packet new-packet-mark=3 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=3389 action=mark-packet new-packet-mark=2 passthrough=yes comment="REMOTE DESKTOP" disabled=no
add chain=prerouting protocol=tcp dst-port=3389 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=5800-5809 action=mark-packet new-packet-mark=2 passthrough=yes comment="VNC" disabled=no
add chain=prerouting protocol=tcp dst-port=5800-5809 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=5900-5909 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp dst-port=5900-5909 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=8291 action=mark-packet new-packet-mark=2 passthrough=yes comment="WinBox" disabled=no
add chain=prerouting protocol=tcp dst-port=8291 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=2601-2611 action=mark-packet new-packet-mark=2 passthrough=yes comment="Zebra Vtysh Daemons" disabled=no
add chain=prerouting protocol=tcp dst-port=2601-2611 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=179 action=mark-packet new-packet-mark=1 passthrough=yes comment="BGP" disabled=no
add chain=prerouting protocol=tcp dst-port=179 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=698 action=mark-packet new-packet-mark=2 passthrough=yes comment="OLSR" disabled=no
add chain=prerouting protocol=tcp dst-port=698 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp src-port=698 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp dst-port=698 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=6666-7000 action=mark-packet new-packet-mark=2 passthrough=yes comment="IRC" disabled=no
add chain=prerouting protocol=tcp dst-port=6666-7000 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting connection-type=irc action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp src-port=8767 action=mark-packet new-packet-mark=1 passthrough=yes comment="TEAMSPEAK" disabled=no
add chain=prerouting protocol=udp dst-port=8767 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting connection-type=h323 action=mark-packet new-packet-mark=1 passthrough=yes comment="Voip H323" disabled=no
add chain=prerouting protocol=udp src-port=5059-5062 action=mark-packet new-packet-mark=1 passthrough=yes comment="VoIP CONNECT" disabled=no
add chain=prerouting protocol=udp dst-port=5059-5062 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=udp src-port=10000-20000 action=mark-packet new-packet-mark=1 passthrough=yes comment="VoIP RTP" disabled=no
add chain=prerouting protocol=udp dst-port=10000-20000 action=mark-packet new-packet-mark=1 passthrough=yes comment="" disabled=no
add chain=prerouting protocol=tcp src-port=8000-8002 action=mark-packet new-packet-mark=2 passthrough=yes comment="SHOUTCAST" disabled=no
add chain=prerouting protocol=tcp dst-port=8000-8002 action=mark-packet new-packet-mark=2 passthrough=yes comment="" disabled=no
add chain=prerouting connection-type=mms action=mark-packet new-packet-mark=3 passthrough=yes comment="Video mms://" disabled=yes