- Get link
- X
- Other Apps
- Get link
- X
- Other Apps
This below picture as an example when hacker know your port number and attack with brute force technique :
So, we don't want it be happen.
To make a prevention, we should create a firewall rules to block who is scanning your network and also we can record the IPs of hackers. Using this address list we can drop connection from those IP:
in /ip firewall filter
add chain=input protocol=tcp psd=21,3s,3,1 action=add-src-to-address-list address-list="port scanners" address-list-timeout=2w comment="Port scanners to list " disabled=no
Next, we can detect port scanning from various combinations of TCP flags.
add chain=input protocol=tcp tcp-flags=fin,!syn,!rst,!psh,!ack,!urg action=add-src-to-address-list address-list="port scanners" address-list-timeout=2w comment="NMAP FIN Stealth scan"
add chain=input protocol=tcp tcp-flags=fin,syn action=add-src-to-address-list address-list="port scanners" address-list-timeout=2w comment="SYN/FIN scan"
add chain=input protocol=tcp tcp-flags=syn,rst action=add-src-to-address-list address-list="port scanners" address-list-timeout=2w comment="SYN/RST scan"
add chain=input protocol=tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack action=add-src-to-address-list address-list="port scanners" address-list-timeout=2w comment="FIN/PSH/URG scan"
add chain=input protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg action=add-src-to-address-list address-list="port scanners" address-list-timeout=2w comment="ALL/ALL scan"
add chain=input protocol=tcp tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg action=add-src-to-address-list address-list="port scanners" address-list-timeout=2w comment="NMAP NULL scan"
Then, drop hackers packet data using :
add chain=input src-address-list="port scanners" action=drop comment="dropping port scanners" disabled=no
And voila, they can not touch your network again, even just test ping your IP address :
Comments
where do you get the last image? from which menu?
ReplyDeleteYou can see it on IP->FIrewall->Address Lists.
ReplyDeleteThank you for your visiting. :)
Informative article. Thanks for sharing such an valuable article.this is best article .
ReplyDeleteEpson scanner support
Epson scanner customer service
Epson scanner scanner number
Epson scanner toll-free number