Community discussions

MikroTik App
 
User avatar
sjoram
Member Candidate
Member Candidate
Topic Author
Posts: 187
Joined: Sun Feb 10, 2013 8:47 pm
Location: Essex, UK

Unreplied connections

Sat Oct 22, 2016 1:20 pm

I have 2x RouterOS running on 2x RB750 series routers.

I'm having major problems with unreplied connections on both devices. Both the source and destination addresses are NOT on my local network, so I suspect there is some spoofing of the source addresses.

My question is how can I block these reliably? I've tried a few suggestions in the past I've found on other threads but I backed those out as they seemed to only cause problems for legitimate connections trying to send SYN FIN/RST packets which left me with a load of stale connections.
miktotik-unreplied.PNG
You do not have the required permissions to view the files attached to this post.
 
User avatar
sjoram
Member Candidate
Member Candidate
Topic Author
Posts: 187
Joined: Sun Feb 10, 2013 8:47 pm
Location: Essex, UK

Re: Unreplied connections

Sat Oct 22, 2016 1:46 pm

Update: I noticed the problem was more pronounced on one device than the other and there were subtle differences between the two in the rules configured to drop traffic.
I've tweaked this and will see how things go over the next week or so.
 
User avatar
Murmaider
Member Candidate
Member Candidate
Posts: 126
Joined: Fri Oct 30, 2015 10:10 am

Re: Unreplied connections

Sat Oct 22, 2016 6:45 pm

If you don't have a very dynamic routing environment (for example traffic coming into the network on one router and leaving through another router) then you can enable Reverse Path Filtering.

Go to IP -> Settings
Set RP Filter to strict.

If you do have a dynamic routing environment, then create some firewall rules on your forward chain to:
accept traffic from anything to your network range.
accept traffic from your network range to anything.
drop all other forward traffic.
 
User avatar
sjoram
Member Candidate
Member Candidate
Topic Author
Posts: 187
Joined: Sun Feb 10, 2013 8:47 pm
Location: Essex, UK

Re: Unreplied connections

Sat Oct 29, 2016 7:27 pm

I've now enabled reverse path filtering as well as tweaking the drop rules at the bottom of the chain...and things are looking much better now.

Who is online

Users browsing this forum: haung05, litogorospe and 68 guests