mikrotik yang simple akan tetapi powerfull
Membuat firewall mikrotik yang simple akan tetapi powerfull.
Berikut untuk firewall managementnya
1. Untuk filter brute forces
/ ip firewall filter
add chain=input protocol=tcp dst-port=22 src-address-list=sshblacklist action=drop comment=”Drop SSH brute forcers” disabled=no
add chain=input protocol=tcp dst-port=22 connection-state=new src-address-list=sshstage3 action=add-src-to-address-list address-list=sshblacklist \
address-list-timeout=1w3d comment=”” disabled=no
add chain=input protocol=tcp dst-port=22 connection-state=new src-address-list=sshstage2 action=add-src-to-address-list address-list=sshstage3 \
address-list-timeout=1m comment=”” disabled=no
add chain=input protocol=tcp dst-port=22 connection-state=new src-address-list=sshstage1 action=add-src-to-address-list address-list=sshstage2 \
address-list-timeout=1m comment=”” disabled=no
add chain=input protocol=tcp dst-port=22 connection-state=new action=add-src-to-address-list address-list=sshstage1 address-list-timeout=1m comment=”” \
disabled=no
2. Untuk filter port scaning
(Read more)
