Community discussions

MikroTik App
 
cibernet
Long time Member
Long time Member
Topic Author
Posts: 610
Joined: Fri Jan 28, 2005 7:22 pm
Location: Marcos Juárez, Córdoba, Argentina
Contact:

Security Problem :(

Thu Apr 14, 2005 7:04 am

Hi, i have RouterOS 2.8.26, we are a small ISP, and have a problem with security, i have set up a DHCP server with static leases for the clients, but if someone put an IP from mi local net, he can connect with internet and.. without traffic shapping... i need a way to add some security that only permited IP and MAC address can connect with Internet...

Sorry my bad English... :oops:

THANKS!! :P
 
User avatar
djape
Member
Member
Posts: 465
Joined: Sat Nov 06, 2004 7:54 pm
Location: Serbia

Thu Apr 14, 2005 12:05 pm

Use static ARP, bound IP address to mac-address for each user, than turn on ARP=reply-only on your ap-bridge interface.
This means that only users that have exact mac an ip address can use your network.

Cheers...
 
kallocom
just joined
Posts: 10
Joined: Sat May 29, 2004 3:23 pm

Thu Apr 14, 2005 2:27 pm

good idea, but doesn't work behind some Ethernet Converters... how about PPPOE?
 
cibernet
Long time Member
Long time Member
Topic Author
Posts: 610
Joined: Fri Jan 28, 2005 7:22 pm
Location: Marcos Juárez, Córdoba, Argentina
Contact:

Thu Apr 14, 2005 4:27 pm

Hi, any other way to do it? before nobody was allowed to pass through the router, but now... anyone can, i dont know what could it be..
 
jarosoup
Long time Member
Long time Member
Posts: 596
Joined: Sun Aug 22, 2004 9:02 am

Fri Apr 15, 2005 5:25 am

Not really a security fix, but more of a way to hinder - How about set a catch-all bandwidth queue for any addresses not accounted for...and set it to 1Kb or something extremely slow. Idealy, maybe get radius going or use the hotspot feature if pppoe isn't an option.

Who is online

Users browsing this forum: No registered users and 72 guests