Community discussions

MikroTik App
 
vereto
just joined
Topic Author
Posts: 11
Joined: Wed Jun 15, 2016 10:35 pm

Cannot access 2011 via ssh [SOLVED]

Wed Jun 29, 2016 3:00 am

I moved the router over to 192.168.1.1 and I cannot seem to access the console via ssh. I feel like this is probably a silly problem but I cannot find any settings regarding this access.

Anyone have any thoughts?

Thank you!

EDIT: I was missing my input firewall rule for local network accessing the router... *face palm*
Thank you all for the help.
Last edited by vereto on Thu Jun 30, 2016 2:12 am, edited 2 times in total.
 
User avatar
hgonzale
Member Candidate
Member Candidate
Posts: 272
Joined: Thu Nov 06, 2014 1:12 pm
Location: Fuengirola, Spain
Contact:

Re: Cannot access 2011 via ssh

Wed Jun 29, 2016 7:47 pm

Had you allowed the port 22 in the firewall, just before the ALL DROP rules?
 
vereto
just joined
Topic Author
Posts: 11
Joined: Wed Jun 15, 2016 10:35 pm

Re: Cannot access 2011 via ssh

Wed Jun 29, 2016 10:18 pm

No. How should that be set?

I did try to disable the ALL DROP entry and still no go. I am trying to connect from within the firewall.

Thanks.
 
User avatar
hgonzale
Member Candidate
Member Candidate
Posts: 272
Joined: Thu Nov 06, 2014 1:12 pm
Location: Fuengirola, Spain
Contact:

Re: Cannot access 2011 via ssh

Wed Jun 29, 2016 11:34 pm

ACEEPT port 22 TCP in the interface desired and put the rule before the DROPS/REJECTS

Also, in IP, SERVICES enable SSH service
 
vereto
just joined
Topic Author
Posts: 11
Joined: Wed Jun 15, 2016 10:35 pm

Re: Cannot access 2011 via ssh

Wed Jun 29, 2016 11:53 pm

Ok, in IP>Services, ssh is enabled (and was enabled)

I have added my rule in firewall like so:
http://i.imgur.com/e7QYnw7.png

I reordered the accepts to move before the DROPS but it still does not work.
 
User avatar
hgonzale
Member Candidate
Member Candidate
Posts: 272
Joined: Thu Nov 06, 2014 1:12 pm
Location: Fuengirola, Spain
Contact:

Re: Cannot access 2011 via ssh

Thu Jun 30, 2016 12:03 am

did you try a nmap/port scan to the router?

Do you have a outgoing firewall in the pc?

Had you tried other computer?
 
vereto
just joined
Topic Author
Posts: 11
Joined: Wed Jun 15, 2016 10:35 pm

Re: Cannot access 2011 via ssh

Thu Jun 30, 2016 12:14 am

I have tried accessing it via different hosts.
I have disabled firewalls on these hosts.
nmap output:
Starting Nmap 5.51 ( http://nmap.org ) at 2016-06-29 16:15 CDT
Nmap scan report for router (192.168.1.1)
Host is up (0.00028s latency).
PORT   STATE    SERVICE
22/tcp filtered ssh
MAC Address: 6C:3B:6B:0B:C8:16 (Unknown)

Nmap done: 1 IP address (1 host up) scanned in 0.25 seconds

Does not give me much to go on. Looking into more options to use with nmap - not very familiar with this command.
 
User avatar
ZeroByte
Forum Guru
Forum Guru
Posts: 4047
Joined: Wed May 11, 2011 6:08 pm

Re: Cannot access 2011 via ssh

Thu Jun 30, 2016 12:20 am

Just a quick point - make sure the firewall rules you're fixing are in the INPUT chain, and not the FORWARD chain....
 
vereto
just joined
Topic Author
Posts: 11
Joined: Wed Jun 15, 2016 10:35 pm

Re: Cannot access 2011 via ssh

Thu Jun 30, 2016 12:23 am

I think they already are. Would the listings showing as INPUT (in my image) verify that these options have been set correctly?
 
User avatar
ZeroByte
Forum Guru
Forum Guru
Posts: 4047
Joined: Wed May 11, 2011 6:08 pm

Re: Cannot access 2011 via ssh [SOLVED]

Thu Jun 30, 2016 6:22 pm

Yes, your rules are in the proper chain.
The counters in the screenshot show zero packets - I don't know if this is because the screenshot was taken after a reboot / clearing of the counters, and before any attempts to ssh into the box... but if not, then the packets are just not making it to the router. I suspect the counters were cleared, though, since you've edited the original post with the solution (thanks for doing so, by the way).
 
User avatar
hgonzale
Member Candidate
Member Candidate
Posts: 272
Joined: Thu Nov 06, 2014 1:12 pm
Location: Fuengirola, Spain
Contact:

Re: Cannot access 2011 via ssh [SOLVED]

Thu Jun 30, 2016 9:13 pm

Where was the problem?
 
User avatar
ZeroByte
Forum Guru
Forum Guru
Posts: 4047
Joined: Wed May 11, 2011 6:08 pm

Re: Cannot access 2011 via ssh [SOLVED]

Thu Jun 30, 2016 10:03 pm

Where was the problem?
Vereto edited the solution into the original post:
EDIT: I was missing my input firewall rule for local network accessing the router... *face palm*
Thank you all for the help.
I.e. - he forgot to say "the LAN interface can do whatever it wants" so this led to the default-drop rule snagging too much traffic.
 
vereto
just joined
Topic Author
Posts: 11
Joined: Wed Jun 15, 2016 10:35 pm

Re: Cannot access 2011 via ssh [SOLVED]

Thu Jun 30, 2016 11:21 pm

Where was the problem?
I was missing a rule in my firewall filters that allowed internal access to the router. My rudimentary understanding tells me that I was blocking access through one of my drop rules.
Thanks again for all your help.

Who is online

Users browsing this forum: FAB1150, Kanzler, pre and 97 guests