It’s in main router (192.168.54.3) (just to prevent ssh and ftp brute force attacks, as in wiki..):
[admin@RouterZZZ] > ip firewall filter pri
Flags: X - disabled, I - invalid, D - dynamic
0 ;;; drop ftp brute forcers
chain=input action=drop src-address-list=ftp_blacklist dst-port=21 protocol=tcp
1 chain=output action=accept protocol=tcp content=530 Login incorrect dst-limit=1/1m,9,dst-address/1m
2 chain=output action=add-dst-to-address-list address-list=ftp_blacklist address-list-timeout=3h protocol=tcp
content=530 Login incorrect
3 ;;; drop ssh brute forcers
chain=input action=drop src-address-list=ssh_blacklist dst-port=22 protocol=tcp
4 chain=input action=add-src-to-address-list connection-state=new src-address-list=ssh_stage3
address-list=ssh_blacklist address-list-timeout=1w3d dst-port=22 protocol=tcp
5 chain=input action=add-src-to-address-list connection-state=new src-address-list=ssh_stage2
address-list=ssh_stage3 address-list-timeout=1m dst-port=22 protocol=tcp
6 chain=input action=add-src-to-address-list connection-state=new src-address-list=ssh_stage1
address-list=ssh_stage2 address-list-timeout=1m dst-port=22 protocol=tcp
7 chain=input action=add-src-to-address-list connection-state=new address-list=ssh_stage1 address-list-timeout=1m
dst-port=22 protocol=tcp
All the rest of routers have nothing in “ip firewall filter”, as they are not accessible from I-net directly.
Pls see previous message for 192.168.54.4. And here is for another one (192.168.54.10):
[admin@RouterYYY] > ip firewall filter pri
Flags: X - disabled, I - invalid, D - dynamic
[admin@RouterYYY] > ip addr pri
Flags: X - disabled, I - invalid, D - dynamic
ADDRESS NETWORK BROADCAST INTERFACE
0 192.168.54.10/24 192.168.54.0 192.168.54.255 ether2
[admin@RouterYYY] > ip route pri
Flags: X - disabled, A - active, D - dynamic, C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme,
B - blackhole, U - unreachable, P - prohibit
DST-ADDRESS PREF-SRC GATEWAY-STATE GATEWAY DISTANCE INTERFACE
0 ADC 192.168.54.0/24 192.168.54.10
This one is a neighbour, not the router which has trouble(192.168.54.3 – let’s call it “Main” router).
The Main (192.168.54.3 ) is pingable from everywhere, and, as I told, it can ping everything EXCEPT neighbour MT routers ( 192.168.54.{4,10,5…} ). There is another router .5 - has similar settings like .10 …
All the other members of network can ping each other.