Community discussions

 
User avatar
sjoram
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 98
Joined: Sun Feb 10, 2013 8:47 pm
Location: Essex, UK

Unreplied connections

Sat Oct 22, 2016 1:20 pm

I have 2x RouterOS running on 2x RB750 series routers.

I'm having major problems with unreplied connections on both devices. Both the source and destination addresses are NOT on my local network, so I suspect there is some spoofing of the source addresses.

My question is how can I block these reliably? I've tried a few suggestions in the past I've found on other threads but I backed those out as they seemed to only cause problems for legitimate connections trying to send SYN FIN/RST packets which left me with a load of stale connections.
miktotik-unreplied.PNG
You do not have the required permissions to view the files attached to this post.
RouterBOARD RB750 - Xilo ADSL2+ (Annex M)
RouterBOARD RB750GL - Xilo FTTC (VDSL)
 
User avatar
sjoram
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 98
Joined: Sun Feb 10, 2013 8:47 pm
Location: Essex, UK

Re: Unreplied connections

Sat Oct 22, 2016 1:46 pm

Update: I noticed the problem was more pronounced on one device than the other and there were subtle differences between the two in the rules configured to drop traffic.
I've tweaked this and will see how things go over the next week or so.
RouterBOARD RB750 - Xilo ADSL2+ (Annex M)
RouterBOARD RB750GL - Xilo FTTC (VDSL)
 
User avatar
Murmaider
Member Candidate
Member Candidate
Posts: 121
Joined: Fri Oct 30, 2015 10:10 am

Re: Unreplied connections

Sat Oct 22, 2016 6:45 pm

If you don't have a very dynamic routing environment (for example traffic coming into the network on one router and leaving through another router) then you can enable Reverse Path Filtering.

Go to IP -> Settings
Set RP Filter to strict.

If you do have a dynamic routing environment, then create some firewall rules on your forward chain to:
accept traffic from anything to your network range.
accept traffic from your network range to anything.
drop all other forward traffic.
 
User avatar
sjoram
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 98
Joined: Sun Feb 10, 2013 8:47 pm
Location: Essex, UK

Re: Unreplied connections

Sat Oct 29, 2016 7:27 pm

I've now enabled reverse path filtering as well as tweaking the drop rules at the bottom of the chain...and things are looking much better now.
RouterBOARD RB750 - Xilo ADSL2+ (Annex M)
RouterBOARD RB750GL - Xilo FTTC (VDSL)

Who is online

Users browsing this forum: No registered users and 80 guests