network scan protection

HI
im looking for a way to prevent poeple blindly scanning the network.
Im having the standart synflood, port scan and spammer rules up and running .

But i have now scans where one ip is just running through the ip range and trying to make connections by selecting stupid/random ports looking if somebody to answers.

See attached picture.
And even if it states established i the üicture. These IPs are not used ! There is no machine answering behind this IP number.

So the question is how can i block this type of scanning ?

Use a firewall rule with the PSD matcher to add Port Scanners to an address list (for 5 days perhaps) and have another rule to drop the address list.

RTFM: http://wiki.mikrotik.com/wiki/Drop_port_scanners :smiley: