Community discussions

MikroTik App
 
nelson6069
Member Candidate
Member Candidate
Topic Author
Posts: 203
Joined: Mon Oct 15, 2012 5:56 pm

How to block unnecessary port or allow important port?

Fri Mar 14, 2014 10:28 am

How to block unnecessary port or allow important port?
It is a students hostel network, and our ISP is offer us a low bandwidth. So i wish to block all unimportant port to disable they use some program for download.
Is this the port that cannot be block?
http://www.webopedia.com/quick_ref/portnumbers.asp

How to block unnecessary port or allow important port?

I want to block most of the port because my ISP offer my network small bandwidth 13Mbps for 480 clients network. I want to block all services except web suffering purpose for the network.
Last edited by nelson6069 on Thu Mar 20, 2014 9:47 am, edited 1 time in total.
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 12008
Joined: Tue Feb 25, 2014 12:49 pm
Location: Italy
Contact:

Re: How to block unnecessary port or allow important port?

Fri Mar 14, 2014 10:44 am

A Hint:

Any malicious user can set any port for any service,
like P2P on DNS, WEB o VoIP port.
do not waste time to try to block ports for load balancing.

Use HotSpot instead.

Each students has the bandwidth limit you set.
 
derr12
Member
Member
Posts: 411
Joined: Fri May 01, 2009 11:32 pm

Re: How to block unnecessary port or allow important port?

Fri Mar 14, 2014 6:20 pm

yeah you are better off using the Proxy + whitelist if you only want to make some services available. It will block everything else. Can also setup firewall rules to allow only specific ports and block the rest.


As far as limiting speeds go, can either use the hotspotor a simple queue to limit the bandwidth available to each user.
 
nelson6069
Member Candidate
Member Candidate
Topic Author
Posts: 203
Joined: Mon Oct 15, 2012 5:56 pm

Re: How to block unnecessary port or allow important port?

Sun Mar 16, 2014 12:37 pm

A Hint:

Any malicious user can set any port for any service,
like P2P on DNS, WEB o VoIP port.
do not waste time to try to block ports for load balancing.

Use HotSpot instead.

Each students has the bandwidth limit you set.
I had set each user limit, but now i want block all ports except the port that allow for suffering website.
It is port 80, 443 and port dns cannot be block?
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 12008
Joined: Tue Feb 25, 2014 12:49 pm
Location: Italy
Contact:

Re: How to block unnecessary port or allow important port?

Sun Mar 16, 2014 12:40 pm

Usually port 80 and 443 TCP are used for web http / https
Never block port 53 TCP and 53 UDP, are used for DNS.
Do not block ICMP.

Also warning about block port 8291 TCP: Winbox!!

But remember, all type of service can be configured on port 80, 443 and 53!
 
nelson6069
Member Candidate
Member Candidate
Topic Author
Posts: 203
Joined: Mon Oct 15, 2012 5:56 pm

Re: How to block unnecessary port or allow important port?

Sun Mar 16, 2014 1:37 pm

yeah you are better off using the Proxy + whitelist if you only want to make some services available. It will block everything else. Can also setup firewall rules to allow only specific ports and block the rest.


As far as limiting speeds go, can either use the hotspotor a simple queue to limit the bandwidth available to each user.
I had set each user limit, but now i want block all ports except the port that allow for suffering website.
It is port 80, 443 and port dns cannot be block?
 
nelson6069
Member Candidate
Member Candidate
Topic Author
Posts: 203
Joined: Mon Oct 15, 2012 5:56 pm

Re: How to block unnecessary port or allow important port?

Thu Mar 20, 2014 9:47 am

I want to block most of the port because my ISP offer my network small bandwidth 13Mbps for 480 clients network. I want to block all services except web suffering purpose for the network.
 
nelson6069
Member Candidate
Member Candidate
Topic Author
Posts: 203
Joined: Mon Oct 15, 2012 5:56 pm

Re: How to block unnecessary port or allow important port?

Thu Mar 20, 2014 10:07 am

I want to block most of the port because my ISP offer my network small bandwidth 13Mbps for 480 clients network. I want to block all services except web suffering purpose for the network.

Who is online

Users browsing this forum: Bing [Bot], GoogleOther [Bot], simtj and 186 guests