Page 1 of 1

how to stop Intrusion

Posted: Wed May 11, 2011 3:31 pm
by abdonetwork
Hello
Dir Mikrotik

I have a network it working through mikrotik board
V.4.11-RB433AH, Level:
In 3 Mini pci 2.4GHz.
There anther WISP On the outskirts of my network converge
He using my network converges to connect between tow away points
Through my mikrotik board converge.

Please see the attached picture to know my meaning …

This board working only AP Bridge and it connected to
Anther board it working PPPoE &hotspot Server only
How to configurations my board to allow my clients only to be connect my network with PPPoE and Hotspot only in same time stop all anther connections coming out my clients.
or and stop spam AP's on the networks shown in the picture caption = that uses the my board converges for the benefit of and between the points to reach its own is not annotated your attention please
Note : the Ap client useing my network converge to connected between
I hope I have properly explained to you

Thank you Sky net

Image

Re: how to stop Intrusion

Posted: Wed May 11, 2011 7:06 pm
by Ibersystems
Hello,

If you have the 3 wlans in a bridge, make rules in /bridge filter to avoid this connections.

You can make rules like source: ip of the "enemy" and destination the internet router as accepted and the enemy to the whole network as deny. This should work.

Re: how to stop Intrusion

Posted: Thu May 12, 2011 2:35 am
by abdonetwork
i was added all filter protocols = in accepted from my server mac = is that will be ok and stop anther connections !!!!! or i need to stop-drop- some protocols ??

Re: how to stop Intrusion

Posted: Fri May 13, 2011 1:42 am
by sup5
just use horizon bridging.
(setup all wireless interfaces with the same horizon value and the uplink interface with any other horizon value)
This will completely supress cross-wireless connetions.

also disable default forwarding in your wireless properties.

Re: how to stop Intrusion

Posted: Wed May 18, 2011 11:41 pm
by abdonetwork
just use horizon bridging.
(setup all wireless interfaces with the same horizon value and the uplink interface with any other horizon value)
This will completely supress cross-wireless connetions.

also disable default forwarding in your wireless properties.
Thank you for the answer Is it possible explanation more or attach a photo caption

Re: how to stop Intrusion

Posted: Tue Jun 07, 2011 9:38 pm
by sup5
an example:

you've got a five ports routerboard (eg rb750, rb450)
ether1 is your uplink
ether2 to ether5 are customers ports.

put all these ports in a bridge.
setup ports ether2 to ether5 with horizon=1.
at this point you're done.

the customers cannot talk to each other anymore.
they only cann communicate with ether1.