I’m setting up a MikroTik router for a small business office (around 20–25 users). While going through documentation, I realized there are so many configuration options related to firewall, VPN, and access rules.
Since this forum has many experienced MikroTik users, I’d like to ask:
What are the recommended best practices for securing a MikroTik router in a small business environment?
Should I enable only specific firewall rules, or is there a standard template that works well?
Any common mistakes beginners make that I should avoid?
To trick hacker and waste his time when trying to hack admin account, if somehow attempt was successful, he will be disappointed after realizing that admin account has no rights and he will jump through the window in despere
Do you recommend no MGMT by wifi because wifi can be hacked? For me, there is a very high PITA factor for only managing via wire. I would appreciate further explanation of this recommendation.
I some way it is, if someone hacks fake admin account you will probably noticed it (even some login alarm can be scripted) and take some measures to prevent further attacks while attacker will not have any rights with such account to do some damage. If attacker was spending time to attack real admin account and succeed it will do some damage while is detected too late.
Wi-Fi can be intercepted and hacked somehow without physical access...
Is point #10:
If you DON'T know how to work around something security, assume there's definitely someone who does.
To access some of the main machines, you have to physically go there, or you have to use the fiber optic cable I rent between the office and the data center.
Of course, if the secret services come and intercept the cable, etc...
These are my recommendations, everyone can do as they wish.
Oddly enough, there are some RouterOS machines on my network and a few "forgotten" ports left open... on purpose...
A word to the wise.
As others have written,
it's easier to spot a mistake if the hacker is wasting time with something virtual and completely useless...
Like finding the password to a useless account, or hacking a virtual machine that... is useless...
@holvoetn
The advice to keep the admin account active anyway, turned out to be useful because whether the account exists or not, whether it is active or not, previously gave milliseconds of different response in which you could guess whether that account existed or not, active or not...
I always block all unused ports and disable default admin access immediately. For a small business, virtual office specialists can handle mail and calls while you focus on firewall rules. I find their London address service useful for privacy. Set up a basic firewall filter and enable Winbox over IPsec only.