Community discussions

MikroTik App
 
jbar
just joined
Topic Author
Posts: 9
Joined: Sun Nov 12, 2017 8:46 pm

How specific do you make your FW rules?

Fri Jul 06, 2018 11:26 pm

Hey everyone, I've always used either firewalls in AWS/Azure or something simple for a SOHO. I have a web app sitting behind my Mikrotik, and after setting up the Firewall rules, reading a few books, just wondered if I am making my life difficult or going down the right approach.

Current setup

2 WANs, incoming everything is blocked incoming except port 80, 443.
Downloaded a few blacklist scripts to block those IPs for all incoming, forwarded or outgoing traffic.
Blocking port scanning attempts.
Outgoing on the WANs have port 443 open, and DNS is restricted to only the DNS servers I picked.
All new connections are logged via syslog to an offsite location.
1 DMZ network, and 1 vlan network on another switch. That vlan only accepts incoming connections from the DMZ on one port. Outgoing on the vlan is restricted to just DNS.

After setting this up, testing it, I realize I have other 30 rules. If there was a SRC/DST Port list I think I could cut the rules down some. Since none of my local networking friends use Mikrotik, I figured I would ask you guys in a production environment, how many rules do you end up with and when is it being too specific or just too much?
 
User avatar
Steveocee
Forum Guru
Forum Guru
Posts: 1120
Joined: Tue Jul 21, 2015 10:09 pm
Location: UK
Contact:

Re: How specific do you make your FW rules?

Sat Jul 07, 2018 10:55 pm

I take a very simple approach.
Block everything, allow only what you want.

You can cut the rules down by comma separating your TCP ports and UDP ports but it’s only worth doing on low powered devices as the separation will show you what ports are getting hit.
 
eXS
newbie
Posts: 47
Joined: Fri Apr 14, 2017 4:01 am

Re: How specific do you make your FW rules?

Sun Jul 08, 2018 3:30 am

i get very specific and 30 rules isn't even worth the post :)
 
jbar
just joined
Topic Author
Posts: 9
Joined: Sun Nov 12, 2017 8:46 pm

Re: How specific do you make your FW rules?

Sun Jul 08, 2018 11:19 pm

I take a very simple approach.
Block everything, allow only what you want.

You can cut the rules down by comma separating your TCP ports and UDP ports but it’s only worth doing on low powered devices as the separation will show you what ports are getting hit.
OHHH I can!

Great, so 30 is not a crazy amount, is good to hear. Thought I was going overboard but sounds like these FW can handle it.
 
User avatar
karlisi
Member
Member
Posts: 438
Joined: Mon May 31, 2004 8:09 am
Location: Latvia

Re: How specific do you make your FW rules?

Tue Jul 10, 2018 10:51 am

I have from 9 to 60 rules on different sites, it depends. 30 rules for 2 WANs is not so much, I think.

Who is online

Users browsing this forum: No registered users and 93 guests