Community discussions

MikroTik App
 
dadach
newbie
Topic Author
Posts: 30
Joined: Wed Aug 22, 2012 4:38 pm

disabling recursive querries on routerOS

Fri Apr 05, 2013 6:11 pm

as it stands, its enabled, which can help attacker do DDoS from mikrotik IP.

how do i disable the recursive queries ability so that external attackers cant use it?

does disabling ALLOW REMOTE REQUESTS prevent recursive querries?

thanks
 
CelticComms
Forum Guru
Forum Guru
Posts: 1765
Joined: Wed May 02, 2012 5:48 am

Re: disabling recursive querries on routerOS

Sat Apr 06, 2013 3:27 am

Block external access to the DNS service using filters on the input chain. Your external interfaces should be blocking *all* input traffic except the few traffic types that you have allowed.
 
dadach
newbie
Topic Author
Posts: 30
Joined: Wed Aug 22, 2012 4:38 pm

Re: disabling recursive querries on routerOS

Sat Apr 06, 2013 12:23 pm

thanks. do i still need to do the filter chains if allow remote requests is turned off?
 
CelticComms
Forum Guru
Forum Guru
Posts: 1765
Joined: Wed May 02, 2012 5:48 am

Re: disabling recursive querries on routerOS

Sat Apr 06, 2013 2:28 pm

thanks. do i still need to do the filter chains if allow remote requests is turned off?
Switching remote requests off will stop network requests but I would still recommend that you check your input filters and make sure that you have appropriate input filters to control access to the router and its services. See info on links below:

http://wiki.mikrotik.com/wiki/Manual:IP/Firewall/Filter

http://wiki.mikrotik.com/wiki/Securing_ ... rOs_Router

Who is online

Users browsing this forum: bschapendonk, mgd093, nkourtzis, perrb, snowzach and 91 guests