Community discussions

MikroTik App
 
fedor47271
just joined
Topic Author
Posts: 24
Joined: Thu Nov 02, 2017 11:52 am

PPTP VPN Protection

Wed Oct 10, 2018 10:20 am

Hi, guys.

I deployed PPTP+GRE VPN on my Router RB3011. I created firewall rules which allow pptp&gre input traffic.
firewall.jpg

But sometimes i see such connection attempts to my PPTP.
logs.jpg


I ask about your advice: How can i prevent and exclude such attempts?
You do not have the required permissions to view the files attached to this post.
 
User avatar
Anumrak
Forum Guru
Forum Guru
Posts: 1174
Joined: Fri Jul 28, 2017 2:53 pm

Re: PPTP VPN Protection

Wed Oct 10, 2018 10:22 am

Hey. Just google for networks your ISP'es uses and add them in source address list. With second rule you can drop any input traffic.
 
fedor47271
just joined
Topic Author
Posts: 24
Joined: Thu Nov 02, 2017 11:52 am

Re: PPTP VPN Protection

Wed Oct 10, 2018 11:12 am

Hey. Just google for networks your ISP'es uses and add them in source address list. With second rule you can drop any input traffic.
Should I add provider's networks to the first rule in src adr list? Explain me plz how it would work.

How can i block this IP address which i sent in the logs, for example?
 
User avatar
Anumrak
Forum Guru
Forum Guru
Posts: 1174
Joined: Fri Jul 28, 2017 2:53 pm

Re: PPTP VPN Protection

Wed Oct 10, 2018 1:43 pm

Hey. Just google for networks your ISP'es uses and add them in source address list. With second rule you can drop any input traffic.
Should I add provider's networks to the first rule in src adr list? Explain me plz how it would work.

How can i block this IP address which i sent in the logs, for example?
Yes, you should. Traffic will be checked from first rule to the last.

You don't need to block this one, because there will be many others. Much simplier to allow what you want and drop everything else.
 
User avatar
Steveocee
Forum Guru
Forum Guru
Posts: 1199
Joined: Tue Jul 21, 2015 10:09 pm
Location: UK
Contact:

Re: PPTP VPN Protection

Wed Oct 10, 2018 6:44 pm

You are opening a VPN server up to the world and are unhappy the world is trying to use it.

Are you expecting the genuine VPN connections from a set IP address(es) or range or is it more a road warrior kind of setup? If you are expecting specific IP's then you can add them to a list and amend your accept rule to allow only from that src-list. Otherwise you are going to get the occasional attempt.
 
User avatar
Anumrak
Forum Guru
Forum Guru
Posts: 1174
Joined: Fri Jul 28, 2017 2:53 pm

Re: PPTP VPN Protection

Thu Oct 11, 2018 9:09 am

Or not occasional :D
 
solar77
Long time Member
Long time Member
Posts: 586
Joined: Thu Feb 04, 2016 11:42 am
Location: Scotland

Re: PPTP VPN Protection

Thu Oct 11, 2018 12:56 pm

I would disable PPTP and only enable it when I need it. May not suit you but provide some protection. Limit what IP can access it as well if you can.

I being to think I have to do the same for winbox, login to ssh to enable winbox, when I need it.
 
acrophobic
newbie
Posts: 38
Joined: Fri Jan 04, 2013 3:56 pm

Re: PPTP VPN Protection

Thu Oct 11, 2018 2:51 pm

Maybe opt for L2TP instead..?
 
fedor47271
just joined
Topic Author
Posts: 24
Joined: Thu Nov 02, 2017 11:52 am

Re: PPTP VPN Protection

Wed Oct 17, 2018 1:46 pm

You are opening a VPN server up to the world and are unhappy the world is trying to use it.

Are you expecting the genuine VPN connections from a set IP address(es) or range or is it more a road warrior kind of setup? If you are expecting specific IP's then you can add them to a list and amend your accept rule to allow only from that src-list. Otherwise you are going to get the occasional attempt.
Clients which connecting to my PPTP server have dynamic IP addresses. I can adding them all time.
 
User avatar
Steveocee
Forum Guru
Forum Guru
Posts: 1199
Joined: Tue Jul 21, 2015 10:09 pm
Location: UK
Contact:

Re: PPTP VPN Protection

Wed Oct 17, 2018 3:40 pm

Put a cheap MT unit behind with IP>Cloud enabled.
Create address list on your router to only allow those DDNS names access to PPTP port.
Drop all other PPTP requests