Answer the question
In order to leave comments, you need to log in
How to fight off unwanted people, Mikrotik?
Good afternoon, not so long ago I changed the main router to Mikrotik, I need advice:
We have an IP PBX and some unwanted people on port 5060 and 5073 (PBX ports) are constantly hammering on it, sorting through passwords. To begin with, I specified the nat rule that only allowed from a certain ip (provider) on ports 5060 and 5073, but this did not help, now I want to stupidly not give them access to the firewall.
I write the input rule - the incoming interface - to drop everything from the 85.40.4.0 subnet, no matter which port they are accessing.
So they all the same tap, need some good advice)
Answer the question
In order to leave comments, you need to log in
As already mentioned above, the rule must be added to the forward chain, because incoming traffic is not intended for Mikrotik itself (input chain), but passes through it (forward chain). For the same reason, in the screenshot above, there is a zero canuterus (last two columns).
And as already mentioned above, the rules in the input and forward chains must be built so that at first there are allowing rules (remote access from the outside is allowed, ICMP echo request is allowed, responses to already established sessions - connection state = ESTABLISHED and RELATED, port forwarding) and The last one is to ban everything.
You can mark "good" connections in prerouting, and pass with the mark in the filter, you can simply pass from the provider's IP in the filter, blame everything else on these ports
The best option: configure mikrotik according to the principle that everything that is not allowed is prohibited.
Or you can:
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question