Community discussions

MikroTik App
 
kvstudio6
just joined
Topic Author
Posts: 16
Joined: Thu Jun 18, 2020 10:06 am

Allow FTP huge transfers file from port scanners checking

Wed Sep 30, 2020 11:17 am

Hi,

I need help, I set a Raw Rules for port scanners with allow port 21 FTP to connect.

now my problem is when users connect VPN and using FTP to transfers huge files size, their IP will block by port scanners.
how to allow port scanners is wont detect my client ip when using FTP transfers and port scanner raw rules is still enable ?

thanks.
You do not have the required permissions to view the files attached to this post.
 
kvstudio6
just joined
Topic Author
Posts: 16
Joined: Thu Jun 18, 2020 10:06 am

Re: Allow FTP huge transfers file from port scanners checking

Thu Oct 01, 2020 4:13 am

anyone can help ? thanks a lot
 
WeWiNet
Long time Member
Long time Member
Posts: 597
Joined: Thu Sep 27, 2018 4:11 pm

Re: Allow FTP huge transfers file from port scanners checking

Thu Oct 01, 2020 11:16 am

Once your users connect via VPN , dont you consider them from a security level as being part of "LAN"?
Why do you still run port scanner protection on them?
You can maybe exclude the VPN connected clients via address lists from port scanner, or add the VPN interface to LAN i/f list.

Or do you mean your clients get caught into the "port-scan" address list BEFORE they have established VPN connection?
(I guess not as you say they donwload FTP files, which I think means, they are connected to VPN and FTP is tunneled through VPN?)
 
kvstudio6
just joined
Topic Author
Posts: 16
Joined: Thu Jun 18, 2020 10:06 am

Re: Allow FTP huge transfers file from port scanners checking

Thu Oct 01, 2020 11:58 am

Once your users connect via VPN , dont you consider them from a security level as being part of "LAN"?
yes, them is already security level as being part of "LAN"

Why do you still run port scanner protection on them?
I run the port scanner is block from outsider who is attack ours network. but now problem for port scanner is when my users using Filezilla and transfer bigger file size. Port scanner will auto detect the ip and block it.
I not sure Filezilla using what port to transfer the file and why my users will having block using filezilla?
 
kvstudio6
just joined
Topic Author
Posts: 16
Joined: Thu Jun 18, 2020 10:06 am

Re: Allow FTP huge transfers file from port scanners checking

Thu Oct 01, 2020 11:59 am

Once your users connect via VPN , dont you consider them from a security level as being part of "LAN"?
Why do you still run port scanner protection on them?
You can maybe exclude the VPN connected clients via address lists from port scanner, or add the VPN interface to LAN i/f list.

Or do you mean your clients get caught into the "port-scan" address list BEFORE they have established VPN connection?
(I guess not as you say they donwload FTP files, which I think means, they are connected to VPN and FTP is tunneled through VPN?)

Once your users connect via VPN , dont you consider them from a security level as being part of "LAN"?
yes, them is already security level as being part of "LAN"

Why do you still run port scanner protection on them?
I run the port scanner is block from outsider who is attack ours network. but now problem for port scanner is when my users using Filezilla and transfer bigger file size. Port scanner will auto detect the ip and block it.
I not sure Filezilla using what port to transfer the file and why my users will having block using filezilla?
 
WeWiNet
Long time Member
Long time Member
Posts: 597
Joined: Thu Sep 27, 2018 4:11 pm

Re: Allow FTP huge transfers file from port scanners checking

Thu Oct 01, 2020 5:34 pm

if you have the remote public IP address of your VPN clients, add it to a "exclude from port scan protection" address list
which you use with "!" as source address list to exclude those.

PS: Are you creating dynamic interface (like PPPoE etc) which might not be part of LAN. Maybe you need to add dynamic i/f into the interface list (or exlcude them).
 
kvstudio6
just joined
Topic Author
Posts: 16
Joined: Thu Jun 18, 2020 10:06 am

Re: Allow FTP huge transfers file from port scanners checking

Wed Oct 14, 2020 5:16 am

is that mean I have to create a new fule for exclude my client ip from port scanner ?
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19322
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Allow FTP huge transfers file from port scanners checking

Wed Oct 14, 2020 6:47 am

I would get rid of the port scanning rules,,,,,,,,,,, they are more bloatware than effective IMHO.
The fact that they are interfering with your user experience is reason enough to suspend its use until you know more.

Who is online

Users browsing this forum: No registered users and 73 guests