Community discussions

MikroTik App
 
kashifzai86
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 58
Joined: Mon Nov 09, 2015 8:58 am
Location: Karachi

DDOS Rules when Connection tracking is Off

Thu Dec 24, 2020 10:34 am

I'm wondering how to place DDos Attack filter rules when Connection Tracking is Off on Mikrotik CCR-1036 as I'm using this router for Routing only and my rest of traffic is forwarding to CGNAT CCR-1009.

Anyone can help on it
 
User avatar
Chupaka
Forum Guru
Forum Guru
Posts: 8709
Joined: Mon Jun 19, 2006 11:15 pm
Location: Minsk, Belarus
Contact:

Re: DDOS Rules when Connection tracking is Off

Thu Dec 24, 2020 11:59 am

Well, first, why don't you want to place those rules on your CGNAT device? :)
 
kashifzai86
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 58
Joined: Mon Nov 09, 2015 8:58 am
Location: Karachi

Re: DDOS Rules when Connection tracking is Off

Sun Dec 27, 2020 12:02 pm

I think I didn't elaborate my network completely, let me tell you everything

I'm working as Mini ISP having 1500 users, I have 2 publics pools of /24 which are routed by main ISP through my these IPs 14.x.x.x/29 assigned by my ISP to my Mikrotik router (my router IPs are /29).
So, my Edge router is CCR1036 is connected to my user interface (and my user are pppoe clients).

CCR-1036 EDGE ROUTER:- This router has these functions (pppoe server, Routing /24 directly by giving real IP to defined users & forward private 172.16.x.x/16 users to my CGNAT router) as this router has connection tracking is OFF (the reason why connection tracking off becoz when one of my area electric goes off my mikroitk does get any load due CONNECETION TRACKING IS DISABLED) If I put on connection tracking ON at this router then on reconnecting of 100s of users at same time CPU load goes to 100% and Mikrotik start dropping packets for few seconds.

So, I used another router for CGNATing.
Please see below link what I want to elaborate you.
https://aacable.wordpress.com/2018/03/2 ... -mikrotik/

DO you have another solution??
 
User avatar
Cha0s
Forum Guru
Forum Guru
Posts: 1142
Joined: Tue Oct 11, 2005 4:53 pm

Re: DDOS Rules when Connection tracking is Off

Sun Dec 27, 2020 4:22 pm

I don't know what those 'DDoS Rules' are, but you can use the Raw table to do filtering without connection tracking enabled.
 
kashifzai86
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 58
Joined: Mon Nov 09, 2015 8:58 am
Location: Karachi

Re: DDOS Rules when Connection tracking is Off

Sun Dec 27, 2020 6:12 pm

When connection tracking is off, RAW tab rules won't work
 
DarkNate
Forum Guru
Forum Guru
Posts: 1016
Joined: Fri Jun 26, 2020 4:37 pm

Re: DDOS Rules when Connection tracking is Off

Sun Dec 27, 2020 6:25 pm

DDoS protection at ISP level shouldn't be relying on "drop" rules, that's what we do at home.

ISPs should use more pro-grade solutions: https://security.stackexchange.com/a/134770
 
nescafe2002
Forum Veteran
Forum Veteran
Posts: 897
Joined: Tue Aug 11, 2015 12:46 pm
Location: Netherlands

Re: DDOS Rules when Connection tracking is Off

Sun Dec 27, 2020 6:57 pm

Please see below link what I want to elaborate you.
https://aacable.wordpress.com/2018/03/2 ... -mikrotik/

Your link provides the correct information:
"When using Masquarade, RouterOS has to do full connection tracking recalculation on EACH interface connect/disconnect.".
=> Use srcnat instead of masquerade to eliminate extra load on pppoe (dis)connects.


When connection tracking is off, RAW tab rules won't work

Raw works fine without connection tracking.. raw is applied before tracking (if enabled)
 
kashifzai86
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 58
Joined: Mon Nov 09, 2015 8:58 am
Location: Karachi

Re: DDOS Rules when Connection tracking is Off

Mon Dec 28, 2020 2:24 pm

Dear Chupaka (Sorry using yr short name)

How to rectify a user (whose IP is DDoS attackers list in mikrotik)??
 
User avatar
Chupaka
Forum Guru
Forum Guru
Posts: 8709
Joined: Mon Jun 19, 2006 11:15 pm
Location: Minsk, Belarus
Contact:

Re: DDOS Rules when Connection tracking is Off

Tue Jan 05, 2021 1:36 pm

So again, why don't you filter on CGNAT devices? They already have Connection Tracking on, and those rules use "connection-state=new", so CPU load should not be noticable.

What do you mean by "rectify"?..
 
kashifzai86
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 58
Joined: Mon Nov 09, 2015 8:58 am
Location: Karachi

Re: DDOS Rules when Connection tracking is Off

Tue Jan 05, 2021 2:10 pm

Please see below link what I want to elaborate you.
https://aacable.wordpress.com/2018/03/2 ... -mikrotik/

Your link provides the correct information:
"When using Masquarade, RouterOS has to do full connection tracking recalculation on EACH interface connect/disconnect.".
=> Use srcnat instead of masquerade to eliminate extra load on pppoe (dis)connects.

THANKS ISSUE RESOLVED.. I completely remove NATTing and issue resolved
When connection tracking is off, RAW tab rules won't work

Raw works fine without connection tracking.. raw is applied before tracking (if enabled)

Who is online

Users browsing this forum: Bing [Bot], Google [Bot], GoogleOther [Bot], PLJ020 and 100 guests