ok New member but have barely gotten by as a mikrotik user for some time.
I have recently had a customer with a vonage phone start having no incoming or going voice on her phone.
I had made no changes to the mikrotik, but vonage was insisting it was a firewall problem.
I checked the firewall and I noticed the default drop rule that is on the tik by default kept shifting position (not staying at the bottom)
Could this be dropping the connection to her vonage?
I also around this time checked the log and noticed at varying intervals the router would deassign her ip then seconds later reassign it back. this would happen over and over again seconds apart for some time. at other times it would deassign and reassign every 40 minutes (nearly exactly 40 minutes, differing only by seconds).
during the time I was trying to discover the cause one time I checked the log I had dozens or hundreds of entries in the log of critical errors due to failed log in over ssh it looked like a brute force attack. I took a snip (win7 screen snip) of the logs.
at this time I get a call from the vonage customer saying everything is working now (but it wasnt anything I changed)[/color]
while logged in remotely... ...later that day or next day I found hundreds again this time over www not ssh and the user name was all admin 8 minutes later I look again and the attack seemed to stop with the last entry saying user admin at the same ip has logged in !
I immediately change the password, and reboot the router, after a couple minutes log back in remotely again change user name and pass and close all ports but 8291
I havent since seen an atack
but what started as her vonage phone deaasign and reassign is no longer affecting her ip but had moved to 2 other ip's these two people have yet to complain
please note that one of the 2 newer affected devices changed ip from 192.168.xxx.xx to 192.168.15.2, the 15.2 seems to be the first ip assigned by a vonage phone to a downstream device. yet this is a differnt customer in a different apartment yet connected to the same wireless ap.
I really don't know what to think of this or what to do, but I was wondering if there is someone who can share their default secure router settings that I could assign to my own as I do not have nearly enough knowledge to handle this alone.
and know nothing of scripting. If I havent been able to do it through the gui I havent been able to do it at all
I also plan to do the add arp to leases and add arp reply only to the interface, to make sure there arent any unknown connected devices on my network..
btw all client devices connect through ubiquiti unifi ap's I keep a computer onsight wired to router for managing the unifi's and other admin tasks
please advise!!! And thanks!!!