Security

How to Blacklist Filters on MikroTik RouterOS?

How to Blacklist Filters on MikroTik RouterOS?

Fadıl

To prevent your users from accessing blacklist IP addresses, you need to create the following firewall rules. Thus, we protect our users from unnecessary sites.

In order to use any of the following lists you will want to add a rule to your input or forward chains like the following:

/ip firewall  filter add action=drop chain=input 
comment=" Drop new connectionsfrom blacklisted IP's to this router" 
connection-state=new  in-interface=ether1 src-address-list=blacklist

or

/ip firewall filter
add action=drop chain=forward comment=" Drop new connectionsfrom blacklisted 
IP's to this router"  dst-address-list=blacklist

SpamHaus

“Spamhaus Don’t Route Or Peer List (DROP)”

The DROP list will not include any IP address space under the control of any legitimate network – even if being used by “the spammers from hell”. DROP will only include netblocks allocated directly by an established Regional Internet Registry (RIR) or National Internet Registry (NIR) such as ARIN, RIPE, AFRINIC, APNIC, LACNIC or KRNIC or direct RIR allocations.”

6 Ways To Secure MikroTik Router

Fadıl

As a network administrator, the first thing is to Secure the Mikrotik (Proxy Router) that we manage, by closing the gaps that might be taken into “attack loopholes” by irresponsible users.

Here Are Some Ways To Secure MikroTik Router:

  1. Credentials, change the default admin password username.
  2. Disable Some Services.
  3. Disable Bandwidth Test Server.
  4. Deactivate the MAC Server feature.
  5. Disable Neighbors Discovery.
  6. Disable the RoMON feature.
  7. Update the RouterOS version.

Credentials

The first thing you can do to secure the Mikrotik Router before your router is discoverable to the internet cloud is to change the default admin username & password Of Mikrotik. You should also replace the default username “admin” to another username.

How to SMTP Over an SSH Tunnel?

Fadıl

Spammers would sniff it out fairly quickly, and proceed to hammer it. To get around this, I decided to set up an SSH tunnel from a port on my laptop to port 25 on the mail server. It was a fairly easy task, and well worth it in the long run. The remainder of this article will explain how I set things up.

Set up the Tunnel

The first thing I decided was to establish the tunnel as a non-root user. Since the tunnel was going to exist for solely mail relaying purposes, I created a relay user on both my laptop and the server in question. I also ran ssh-keygen(1) and gave the relay user an empty passphrase. If you’re overly paranoid, you can use a passphrase and then use ssh-agent(1). The way I figure is if someone gets into my laptop, I have more things to worry about than them sending mail through my relay.

How do you know when someone probing your network?

How do you know when someone probing your network?

Fadıl

How do you know if someone is probing your network?  Logs are a great place to start, especially your FW-1 logs.  Unfortunately, those logs can be difficult and time consuming to sift through (especially if you are logging 400+ B every day). Wouldn’t it be great if there was an automated method of alerting you?

There are a variety of different probes and attacks black-hats will attempt. he types we will be focusing on is port scans. Port scans are where an individual attempt to connect to a variety of ports to identify what services a system is running.  The scans can be used on a specific target or used to scan entire IP ranges, often chosen at random.  This is one of the most popular information gathering methods used by black-hats today as it identifies what ports and services are open.

How to Anonymous ftp Server Configuration

Fadıl

We will use only anonymous ftp and will not allow any non-anonymous user any access. Here we describe the anonymous ftp server setup that allows anonymous uploads. Any self-respecting guide on the subject will tell you that “this is a bad thing”. But how is it worse than allowing users to FTP from untrusted location and transfer their passwords in clear text? Not everybody (especially, using Windows) can easily setup an FTP tunnel via ssh.