Community discussions

MikroTik App
 
User avatar
ofendt
just joined
Topic Author
Posts: 23
Joined: Mon Jun 20, 2011 10:17 pm

Adresslists (Firewall) to be hosted on one central device

Thu Jun 12, 2014 3:49 pm

If one looks at the logs - there a hundreds of attacks against the router per day.

it would be cool to be able to verify an ip adress against a centraly managed database (like spamhaus...) to block the adresses.

in first step one could block on own "mikrotik farm" but maybe mikrotik will act as a central database for DoS and SSH faild logins to block those adresses on "all mikrotik" who wish to be part of the web of trust.

Oliver
You do not have the required permissions to view the files attached to this post.
 
efaden
Forum Guru
Forum Guru
Posts: 1708
Joined: Sat Mar 30, 2013 1:55 am
Location: New York, USA

Re: Adresslists (Firewall) to be hosted on one central devic

Thu Jun 12, 2014 6:41 pm

Why is your ssh open to the public?

Sent from my SCH-I545 using Tapatalk
 
jarda
Forum Guru
Forum Guru
Posts: 7756
Joined: Mon Oct 22, 2012 4:46 pm

Re: Adresslists (Firewall) to be hosted on one central devic

Thu Jun 12, 2014 6:45 pm

Implement st least bruteforce attack firewall rules described on this forum if you want to keep ssh opened.
 
User avatar
janisk
MikroTik Support
MikroTik Support
Posts: 6263
Joined: Tue Feb 14, 2006 9:46 am
Location: Riga, Latvia

Re: Adresslists (Firewall) to be hosted on one central devic

Mon Jun 16, 2014 2:25 pm

some simple port-knocking to get your IP in whitelist and use a router without script kiddie attacks.
 
User avatar
ofendt
just joined
Topic Author
Posts: 23
Joined: Mon Jun 20, 2011 10:17 pm

Re: Adresslists (Firewall) to be hosted on one central devic

Thu Jun 26, 2014 12:10 pm

It is not that ssh is my real problem - it is that i want those adresses blockt for everything like MAIL, HTTP...

And therefore it would be perfect if not all of us manage there own "bad boys list" but
if there would be a centraly managed adresslist witch blockes everybody witch does
brute-force attacks.
 
User avatar
semakka
Member Candidate
Member Candidate
Posts: 196
Joined: Mon Sep 11, 2006 10:59 am
Location: Moraira, Alicante, Spain
Contact:

Re: Adresslists (Firewall) to be hosted on one central devic

Thu Jun 26, 2014 1:42 pm

I've seen a while ago some firewall rules working on dynamic address lists, maybe is worth looking for them...
Or maybe block everything on input except your address list (office, allowed IPs). Restrictive firewalls are better!

cheers

Who is online

Users browsing this forum: Bing [Bot], jg0007 and 36 guests