Skip to main content

20 docs tagged with "firewall"

View all tags

Building Advanced Firewall

This page guides building an advanced firewall on MikroTik RouterOS by configuring interface lists, filtering rules for IPv4 and IPv6, accepting ICMP/DHCPv6 while blocking invalid addresses, and managing traffic flows between WAN and LAN interfaces.

Common Firewall Matchers and Actions

This page explains MikroTik RouterOS firewall statistics and commands, detailing how to view matching stats for IPv4/IPv6 rules, reset counters, and lists common matchers like MAC addresses, interfaces, IP ranges, and ports used in firewall filtering.

Connection rate

Connection Rate is a MikroTik RouterOS firewall feature that monitors and filters traffic based on connection speed, using 'connection-bytes' and 'connection-rate' to detect high-speed connections for prioritization or throttling.

Connection tracking

Connection tracking in MikroTik RouterOS enables stateful firewall functionality by monitoring logical network connections, supporting NAT and various firewall features. It assigns packets to states like new, established, related, invalid, or untracked, with FastTrack optimizing TCP/UDP packet forwarding.

DDoS protection

Limit denial-of-service attacks with RouterOS firewall rules: count new connections per source and destination with dst-limit, put pairs that exceed the rate on address lists and drop them in the raw table. Covers how the detection works, its limits, protecting the router itself, SYN floods with TCP SYN cookies and why SYN-ACK floods are dropped as invalid.

Filter

Firewall filters in MikroTik RouterOS control packet flow by allowing or blocking traffic through predefined chains (input, forward, output) with options to accept specific services or drop malicious packets. Configuration is done via `/ip/firewall/filter` for IPv4 and `/ipv6/firewall/filter` for IPv6, with examples provided for securing both router and LAN devices.

Firewall

MikroTik RouterOS firewall provides stateful and stateless packet filtering, NAT, and advanced traffic classification to secure network data flow and prevent unauthorized access. It includes filter/raw, mangle, and nat modules with pre-defined chains for efficient rule management.

Firewall and QoS Case Studies

This page presents practical case studies for configuring firewall and QoS rules in MikroTik RouterOS, covering brute-force prevention, DDoS protection, connection rate limiting, port knocking, and advanced firewall designs.

Firewall and Quality of Service

This section provides an overview of RouterOS firewall capabilities including NAT, connection tracking, and QoS features for securing traffic, classifying packets, and managing bandwidth.

First Time Configuration

This page provides a step-by-step guide for first-time MikroTik RouterOS configuration, covering prerequisites, connection setup, and key concepts like DHCP, NAT, and firewall. It includes both WinBox graphical and CLI methods for new and advanced users.

HotSpot - Captive portal

The MikroTik HotSpot Gateway enables client authentication for public networks with features like DHCP address pools, multiple authentication methods, and walled-garden access. It requires IPv4 and has specific routing limitations, with configuration examples provided for setup.

Layer7

Layer7 protocol inspection in MikroTik RouterOS searches for patterns in network traffic streams, collecting initial packet data to identify specific protocols. It requires careful configuration for bidirectional traffic and is resource-intensive, with warnings against overuse. Example configurations demonstrate matching RDP and Telnet protocols while managing memory usage.

Packet Flow in RouterOS

This page explains how data packets flow through MikroTik RouterOS, detailing the interaction between bridging, routing, MPLS decisions, and firewall chains. It includes diagrams illustrating packet processing stages from entry to exit points, along with descriptions of key components like routing tables and firewall chains.

Port knocking

Port knocking keeps the management ports of a RouterOS router closed until a client connects to a secret sequence of ports; the firewall then adds the client to a trusted address list. Covers the knock rules in the default firewall, knocking from a client, a blacklist against port scans, a passphrase knock with layer 7, and checking the lists.

Securing your router

This page provides security recommendations for MikroTik RouterOS, including upgrading RouterOS versions, changing default usernames and passwords, securing access with firewall rules and VPNs, disabling unnecessary services like MAC-Telnet and Neighbor Discovery, and managing DNS caching to enhance router security.

Services

The /ip/service menu lists the RouterOS management services (WinBox, SSH, Telnet, FTP, web server, API) and the ports other features and containers listen on. The page shows how to see what the router listens on, limit services to trusted addresses, move them to a management VRF, and lists the ports and IP protocols RouterOS uses.

Socksify

Socksify forwards traffic chosen by firewall NAT rules through an upstream SOCKS5 server, so applications without SOCKS support can use a SOCKS proxy. Includes a Tor proxy example.

Software Specifications

This page outlines RouterOS software specifications covering hardware compatibility, installation methods, configuration tools, backup/restore capabilities, firewall features, routing protocols, and MPLS support for MikroTik devices.

SSH brute-force protection

Protect an internet-facing SSH service on RouterOS with firewall rules that count new connections per source address and block a source that opens too many in a short time. Covers what to do before exposing SSH, placing the rules in the default firewall, exempting trusted addresses, IPv6, checking and unblocking, and how many password guesses the rules still allow.

Web Proxy

The RouterOS web proxy fetches web content for the clients on your network. It filters requests by host name, path and method, caches plain HTTP content, sends requests through a parent proxy, and works as a regular or transparent proxy.