Helo ,
I have mikrotik ros 2.9.27, and 400 windows-xp clients.
A lot of clients are virused and make flood to dns provider servers (udp port 53).
How can i make a filter for this virused clients?
10x in advanced
u can be more specific, pleez?either block the entire DNS port, or add a rule to add SRC-ADDRESS to any IP that has too many DNS requests.
Esti din RO ? Daca da, lasa un ym, si te pot ajuta.
You can block the ip of each client suspected of a virus, and they will call you. Just use torch to find out what's happening, and then add a firewall rule with "drop" on a "virused" src-address list. Wich you make by adding the infected ip's to it.