Community discussions

MikroTik App

Search found 8 matches

by LiquidDave
Thu Oct 13, 2016 6:15 am
Forum: Beginner Basics
Topic: Blocking Users From Scanning and DoS Attacks
Replies: 3
Views: 2845

Re: Blocking Users From Scanning and DoS Attacks

A very odd update I am trying out this rule its my understanding that connection-limit=40,32 means 40 connections to the same host and limit=200,5 means 200 new connections over 5 seconds will result in adding the src to address list. However as soon as I refresh a webpage 1 time the address is adde...
by LiquidDave
Wed Oct 12, 2016 5:41 am
Forum: Beginner Basics
Topic: Blocking Users From Scanning and DoS Attacks
Replies: 3
Views: 2845

Re: Blocking Users From Scanning and DoS Attacks

So my SSH rules are working but I still need to figure out how to limit Port 80 TCP DoS attacks that are starting from inside my network. Does anyone have any experience with this type of thing?
by LiquidDave
Sun Oct 09, 2016 4:13 am
Forum: Beginner Basics
Topic: Blocking Users From Scanning and DoS Attacks
Replies: 3
Views: 2845

Blocking Users From Scanning and DoS Attacks

Hi, I am using Mikrotik to route my VPN users traffic. Lately, I have been getting some abuse reports at a couple sites about 1 or more of my users doing some port scans, attempting to brute force SSH and launching DoS attacks on port 80. I came up with some firewall rules to block the SSH stuff but...
by LiquidDave
Tue Sep 16, 2014 9:23 am
Forum: General
Topic: Dealing with 3 different DDOS attacks. Need suggestions
Replies: 6
Views: 3207

Re: Dealing with 3 different DDOS attacks. Need suggestions

Very true. I had hoped to find something I could add to the other routers but maybe I wont be able to be proactive about it. This ddos has been going on for a week now. Hopefully it will let up soon.
by LiquidDave
Tue Sep 16, 2014 9:00 am
Forum: General
Topic: Dealing with 3 different DDOS attacks. Need suggestions
Replies: 6
Views: 3207

Re: Dealing with 3 different DDOS attacks. Need suggestions

Yea that is basically what I am doing now. My problem is users that are assigned public IP addresses can have incoming traffic to their IP. Now anything above UDP 1024 is going to be dropped due to the firewall rule.
by LiquidDave
Tue Sep 16, 2014 5:47 am
Forum: General
Topic: Dealing with 3 different DDOS attacks. Need suggestions
Replies: 6
Views: 3207

Dealing with 3 different DDOS attacks. Need suggestions

I have a problem on one of my Mikrotiks and I am having some issues figuring out a set of rules that will allow incoming OpenVPN connections get to a server behind the router and accept PPTP/L2TP connections on the router itself while still dropping DDoS traffic. There are three things I am seeing I...
by LiquidDave
Thu Aug 14, 2014 9:34 am
Forum: General
Topic: How to Block torrent 100%? Only 2 lines. It is solved.
Replies: 59
Views: 112537

Re: How to Block torrent 100%? Only 2 lines. It is solved.

If I add these rules without adding an interface they should work with all interfaces correct? PPP clients are still downloading torrents and the only thing that is different is I have not added the interfaces,
by LiquidDave
Thu Aug 14, 2014 7:22 am
Forum: General
Topic: Need a better method of stopping P2P on my network
Replies: 3
Views: 1482

Need a better method of stopping P2P on my network

Right now we are blocking and/or rate limiting as much P2P as we know how to. I have setup rules to filter DNS queries, rate limit excessive UDP connections and search for keywords within the packets. The problems are some users are obfuscating P2P, others have figured out that they can download the...