Community discussions

MikroTik App
 
User avatar
sjafka
Member Candidate
Member Candidate
Topic Author
Posts: 104
Joined: Wed Jan 03, 2018 5:45 pm

Loggin

Mon May 14, 2018 3:32 pm

Dear Community,


i"d like to ask, what is the best method, to log and send(email or syslog server) router logins attempts (succeed and unsuccefull too) and how could i log who did use specific ports like: 1723,3389(from wan side :) )


Thank you in andvance!

Daniel
 
User avatar
sjafka
Member Candidate
Member Candidate
Topic Author
Posts: 104
Joined: Wed Jan 03, 2018 5:45 pm

Re: Loggin

Tue May 15, 2018 11:33 am

I could solve the login attempts, but how could i get a log to an external server that there was traffic on RDP/VPN (1723,3389,etc..) and from which public ip it came? Thank you in adnvace
 
sindy
Forum Guru
Forum Guru
Posts: 10206
Joined: Mon Dec 04, 2017 9:19 pm

Re: Loggin

Tue May 15, 2018 12:50 pm

You have to add rules with action=log, protocol=tcp and dst-port=<list of ports on which the services you are interested in listen> to the firewall filter chains input and forward, right after the initial "accept related, established" rule. Another such rule for services listening on UDP ports. Then you set logging to write firewall,info messages to the required logging channel.
 
User avatar
sjafka
Member Candidate
Member Candidate
Topic Author
Posts: 104
Joined: Wed Jan 03, 2018 5:45 pm

Re: Loggin

Tue May 15, 2018 2:15 pm

You have to add rules with action=log, protocol=tcp and dst-port=<list of ports on which the services you are interested in listen> to the firewall filter chains input and forward, right after the initial "accept related, established" rule. Another such rule for services listening on UDP ports. Then you set logging to write firewall,info messages to the required logging channel.
I've got it, thank you for your reply, Sindy! (again, you helpd me out, thank you)

Who is online

Users browsing this forum: Bing [Bot], Lupin, raiser, vingjfg and 124 guests