Community discussions

MikroTik App
 
loveman
Member
Member
Topic Author
Posts: 348
Joined: Tue Mar 10, 2015 9:32 pm

Protect rule

Sat Oct 24, 2015 4:33 pm

Hi
Any one have filter rule to protect server from hacker in outside please write your rule here.
Security rule
 
loveman
Member
Member
Topic Author
Posts: 348
Joined: Tue Mar 10, 2015 9:32 pm

Re: Protect rule

Sun Oct 25, 2015 8:45 am

No answer
 
deanMKD1
Member
Member
Posts: 366
Joined: Fri Dec 12, 2014 12:06 am
Location: Macedonia
Contact:

Re: Protect rule

Sun Oct 25, 2015 10:29 am

1. Disable unused services from your MT device.

2. Add firewall rules to stop port scanning.

3. That it. :)
 
User avatar
docmarius
Forum Guru
Forum Guru
Posts: 1224
Joined: Sat Nov 06, 2010 12:04 pm
Location: Timisoara, Romania
Contact:

Re: Protect rule

Sun Oct 25, 2015 10:46 am

I like the following approach:

- place the server on a private IP
- using destination nat forward only the services you need to be accessible from the WAN
- use masquerade for outgoing server connections
- drop every other forward from the outside to the server
 
yancho
Member Candidate
Member Candidate
Posts: 207
Joined: Tue Jun 01, 2004 3:04 pm
Location: LV

Re: Protect rule

Sun Oct 25, 2015 10:47 am

Router = server? :)
If so Wiki have some examples http://wiki.mikrotik.com/wiki/Firewall
If server is server behind router and providing some services to outside then we need more information.
 
loveman
Member
Member
Topic Author
Posts: 348
Joined: Tue Mar 10, 2015 9:32 pm

Re: Protect rule

Sun Oct 25, 2015 4:51 pm

1. Disable unused services from your MT device.

2. Add firewall rules to stop port scanning.

3. That it. :)
Thank you
In your number
1 you mean go,, ip,services
And disable for example ssh, telnet,, spi, www ssl
And only able
Www, winbox
...
In your number 2 can you show me in picture what you meaning?
 
loveman
Member
Member
Topic Author
Posts: 348
Joined: Tue Mar 10, 2015 9:32 pm

Re: Protect rule

Sun Oct 25, 2015 4:53 pm

I like the following approach:

- place the server on a private IP
- using destination nat forward only the services you need to be accessible from the WAN
- use masquerade for outgoing server connections
- drop every other forward from the outside to the server
Thank you
Can you upload picture for
drop every other forward from the outside to the server
How can do this?
 
loveman
Member
Member
Topic Author
Posts: 348
Joined: Tue Mar 10, 2015 9:32 pm

Re: Protect rule

Sun Oct 25, 2015 4:54 pm

Router = server? :)
If so Wiki have some examples http://wiki.mikrotik.com/wiki/Firewall
If server is server behind router and providing some services to outside then we need more information.
Thank you
I will see the website soon
 
User avatar
cross
just joined
Posts: 18
Joined: Tue Jul 28, 2015 3:41 pm

Re: Protect rule

Fri Nov 20, 2015 11:57 am

About that firewall port scanning rules in MT.

I Saw few posts from the past year and people did notice that none of those tutorials describing rule examples works.

And I checked few of them for example this one http://wiki.mikrotik.com/wiki/Drop_port_scanners(because is more complicate ;) ) and it doesn't work either.

So how to build good rule ?