Community discussions

MikroTik App
 
posetr
just joined
Topic Author
Posts: 7
Joined: Thu Feb 14, 2013 6:00 pm

how to syncookie protection

Sun Feb 17, 2013 12:00 am

Hello guys , i need to enable on syncookie protection for detect and block spoof ips. I already enabled TCP-Syn cookies in ip settings and it wont help to prevent ddos attack.
Routerboard inaccessible when synflood attack comes from spoof ips. If i limit whole new synconnections routerboard drops all new and old requests.

Please help me to solve it .
 
dcarrera
newbie
Posts: 27
Joined: Thu Feb 14, 2013 6:45 pm
Location: Spain

Re: how to syncookie protection

Sun Feb 17, 2013 11:36 pm

 
posetr
just joined
Topic Author
Posts: 7
Joined: Thu Feb 14, 2013 6:00 pm

Re: how to syncookie protection

Mon Feb 18, 2013 2:59 am

it drops all new syn packets with that rules whitch written on page.i need drop new syn paket if it comes from spoof ip address
 
dcarrera
newbie
Posts: 27
Joined: Thu Feb 14, 2013 6:45 pm
Location: Spain

Re: how to syncookie protection

Mon Feb 18, 2013 12:22 pm

ahmn okk, drastic solution, you can use blacklists.

filter packets to detect and add ips to firewall address list with action ADD DST TO ADDRESS LIST, and add a filter rule to drop packets.

a similar example http://forum.mikrotik.com/viewtopic.php?f=13&t=54199