Community discussions

MikroTik App
 
student13
just joined
Topic Author
Posts: 9
Joined: Fri Jul 13, 2018 10:07 pm

First mikrotik router-- ned help understanding security instructions.

Fri Jul 13, 2018 10:17 pm

Hi folks, I just bought my first mikrotik router (ethernet ports only). I have a linksys router with dd-wrt , so --- I understand security a little bit, and do on occasion ---I write iptables rules .
I tried looking up how to limit external access to my router from a public ip and I found code, that I DON"T UNDERSTAND WHERE /HOW to implement it.

/user set 0 allowed-address=x.x.x.x/yy


Keep in mind that I use a web browser to access router OS, as I only use linux computers.
Thanks.
 
AndreasGR
newbie
Posts: 45
Joined: Mon May 14, 2018 5:27 pm

Re: First mikrotik router-- ned help understanding security instructions.

Mon Jul 23, 2018 8:24 pm

I would not suggest direct access from public IP.
I recommend to set up a VPN with the mikrotik and connect via winbox or browser.
IMHO browser has problematic functionality so I suggest you get a win vm on your linux just for winbox.

If you need help with VPN there are many tutorials in wiki.
I suggest to follow SSTP with certificates and Road Warrior (RW) client as a start and then see if you can implement IKEv2 with RW client as well.
 
Revelation
Member
Member
Posts: 336
Joined: Fri Dec 25, 2015 5:59 am

Re: First mikrotik router-- ned help understanding security instructions.

Tue Jul 24, 2018 4:53 pm

You can also use Wine to utilize WinBox on Linux, Unix and MacOS.
 
User avatar
Steveocee
Forum Guru
Forum Guru
Posts: 1120
Joined: Tue Jul 21, 2015 10:09 pm
Location: UK
Contact:

Re: First mikrotik router-- ned help understanding security instructions.

Tue Jul 24, 2018 5:24 pm

You can use WINE and run Winbox so you can get the "good" graphical experience from the router, you can also use SSH to get into the router.

The command you found is fine to drop into the terminal replacing your LAN range with the XXXX/YY figures.

The command in short allows user 0 (default admin) to only be allowed from the IP range you are giving it. This is OK but once you find your feet a bit more you will probably want to block these connections with the firewall rather than disallowing them by local IP range. The local IP range option is great if you are an admin and don't want your LAN/co-workers trying to gain access.

***Also welcome to the world of MikroTik where anything is possible and the learning curve is steep.

Who is online

Users browsing this forum: jaclaz and 109 guests