Block Service ports to internet?

To day i was looking at my log and i saw lots of red entries saying that.

Authentication failer to ftp: and some IP address.


This means that some one was trying to access my RB ftp server from the net?


How can i prevent people from accessing system services like that?

http://wiki.mikrotik.com/wiki/Securing_New_RouterOs_Router

Please do search the wiki before posting.

thanks for that,

But just a question?

Does adding somany firewall rules, filters and mangles not slow down your router allot?

Cause i have added a few mangles and the cpu usage seems to be allot higher?

Everything the router does slows it down a little bit, of course. Unless you write bad rules just a few shouldn’t have much of an effect.

Oh ok,

So the ones in that tutorial wont like hault opperation.


Thanks :smiley:

All Firewall rules imply actuall inspecting the data that goes thru the router, and that takes CPU time.

Arguably Layer-7 takes the most time, especially with big patterns.

NAT takes time and memory. Each NATed connection eats about 340 bytes of RAM. If you use all 65535 ports, that’s about 21Mb of RAM just for the NAT tracking records.

The simple rule is to use as few ‘hungry’ rules as you can get away with, unless your router has endless RAM and oodles of CPU power.

You booked yourself on a Free MUM yet ?

oh ok.

You booked yourself on a Free MUM yet ?

http://mum.mikrotik.com/2010/US/info
that right place?

But dont you act have to go some where or is it online?

yes, that’s the right place. you have to come yourself, as that’s the best way to learn. you will be able to watch, just like this, but that’s not the same:

http://www.tiktube.com/?category=3

But i live in SA.

Thats not gona work.

Wait for the MUM in South Africa. Maybe next year then.

Yea.

Well i finnish school next year.

So thats deff on my list of things to do.