Configuracion de Router Mikrotik Routerboard Cap 04 Seguridad

Описание к видео Configuracion de Router Mikrotik Routerboard Cap 04 Seguridad

Configuracion de Router Mikrotik Routerboard Cap 04 Seguridad
Para este video aprenderemos a como cambiar la contraseña, cerrar puertos de acceso, cambiar los puertos de administracion y reglas mas avanzadas de seguridad.

Script version RouterOS 6.42:
/ip firewall filter
add action=add-src-to-address-list address-list=lista_negra_ssh address-list-timeout=1w3d chain=input comment=\
"Bloquear fuerza bruta" connection-state=new dst-port=22 protocol=tcp src-address-list=ssh3
add action=add-src-to-address-list address-list=ssh3 address-list-timeout=1m chain=input connection-state=new \
dst-port=22 protocol=tcp src-address-list=ssh2
add action=add-src-to-address-list address-list=ssh2 address-list-timeout=1m chain=input connection-state=new \
dst-port=22 protocol=tcp src-address-list=ssh1
add action=add-src-to-address-list address-list=ssh1 address-list-timeout=1m chain=input connection-state=new \
dst-port=22 protocol=tcp
add action=drop chain=input dst-port=22 protocol=tcp src-address-list=lista_negra_ssh
add action=tarpit chain=forward comment="Bloquear DOS 01" connection-limit=20,32 dst-address=163.10.0.84 \
dst-port=80 protocol=tcp
add action=drop chain=forward comment="Bloquear DOS 02" connection-limit=5,32 connection-state=new dst-address=\
163.10.0.84 dst-port=80 protocol=tcp
add action=drop chain=input comment="Denegando escaners de puertos" src-address-list="Escaner de Puertos"
add action=add-src-to-address-list address-list="Escaner de Puertos" address-list-timeout=2w chain=input \
comment="Listar como escaner de puertos" protocol=tcp psd=21,3s,3,1
add action=add-src-to-address-list address-list="Escaner de Puertos" address-list-timeout=2w chain=input \
comment="Escaneo de sigilo NMAP FIN" protocol=tcp tcp-flags=fin,!syn,!rst,!psh,!ack,!urg
add action=add-src-to-address-list address-list="Escaner de Puertos" address-list-timeout=2w chain=input \
comment="Escaner SYN/FIN" protocol=tcp tcp-flags=fin,syn
add action=add-src-to-address-list address-list="Escaner de Puertos" address-list-timeout=2w chain=input \
comment="Escaner SYN/RST" protocol=tcp tcp-flags=syn,rst
add action=add-src-to-address-list address-list="Escaner de Puertos" address-list-timeout=2w chain=input \
comment="Escaner FIN/PSH/URG" protocol=tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack
add action=add-src-to-address-list address-list="Escaner de Puertos" address-list-timeout=2w chain=input \
comment="Escaner TODO/TODO" protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg
add action=add-src-to-address-list address-list="Escaner de Puertos" address-list-timeout=2w chain=input \
comment="Escaner NMAP NULL" protocol=tcp tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg

Комментарии

Информация по комментариям в разработке