Aplicar apenas no roteador de borda.
/ip firewall raw add action=drop chain=prerouting comment="!::ANTISPAM-TCP-PARA-INTERNET" disabled=yes dst-address-list=!REDE-GERAL dst-port=0,17,19,25,69,110,111,135,137,138,139,143,161,162,389 protocol=tcp src-address-list=REDE-GERAL
/ip firewall raw add action=drop chain=prerouting comment="!::ANTISPAM-TCP-PARA-INTERNET" disabled=yes dst-address-list=!REDE-GERAL dst-port=445,799,800,1900,3283,3702,4665,5353,10001,11211,27960 protocol=tcp src-address-list=REDE-GERAL
/ip firewall raw add action=drop chain=prerouting comment="!::ANTISPAM-UDP-PARA-INTERNET" disabled=yes dst-address-list=!REDE-GERAL dst-port=0,17,19,25,69,110,111,135,137,138,139,143,161,162,389 protocol=udp src-address-list=REDE-GERAL
/ip firewall raw add action=drop chain=prerouting comment="!::ANTISPAM-UDP-PARA-INTERNET" disabled=yes dst-address-list=!REDE-GERAL dst-port=445,799,800,1900,3283,3702,4665,5353,10001,11211,27960 protocol=udp src-address-list=REDE-GERAL
#