fbpx

Kini awọn ofin ti gbogbo olulana MikroTik yẹ ki o ni, ni àlẹmọ ogiriina, nat, ati bẹbẹ lọ?

Ṣiṣe atunto ogiriina ni deede lori olulana MikroTik jẹ pataki lati daabobo nẹtiwọọki rẹ lati iraye si laigba aṣẹ ati awọn iru awọn irokeke aabo miiran. Botilẹjẹpe awọn ofin kan pato le yatọ si da lori awọn iwulo ati iṣeto ti nẹtiwọọki kọọkan, awọn ofin gbogbogbo ati awọn ipilẹ wa ti a ṣeduro fun ọpọlọpọ awọn agbegbe.

Ni isalẹ wa diẹ ninu awọn ofin ati awọn iṣe ti o dara julọ fun àlẹmọ ogiriina, NAT, ati awọn apakan iṣeto ni ibamu miiran ni MikroTik RouterOS.

FirewallFilter

Idi ti àlẹmọ ogiriina ni lati ṣakoso ijabọ ti o kọja nipasẹ olulana, gbigba ọ laaye lati dina tabi gba laaye ijabọ ti o da lori awọn ibeere kan.

  1. Dina wiwọle laigba aṣẹ si olulana:

Rii daju lati ni ihamọ wiwọle si olulana lati ita nẹtiwọki agbegbe rẹ. Eyi jẹ deede nipasẹ didi awọn ibudo iṣakoso, bii 22 (SSH), 23 (Telnet), 80 (HTTP), 443 (HTTPS), ati 8291 (Winbox).

/ip firewall filter
add action=drop chain=input in-interface=ether1 protocol=tcp dst-port=22 comment="Bloquear acceso SSH externo"
add action=drop chain=input in-interface=ether1 protocol=tcp dst-port=23 comment="Bloquear acceso Telnet externo"
add action=drop chain=input in-interface=ether1 protocol=tcp dst-port=80 comment="Bloquear acceso HTTP externo"
add action=drop chain=input in-interface=ether1 protocol=tcp dst-port=443 comment="Bloquear acceso HTTPS externo"
add action=drop chain=input in-interface=ether1 protocol=tcp dst-port=8291 comment="Bloquear acceso Winbox externo"

2. Dabobo lodi si awọn ikọlu ti o wọpọ:

Ṣiṣe awọn ofin lati daabobo nẹtiwọki rẹ lọwọ awọn ikọlu ti o wọpọ, gẹgẹbi iṣan omi SYN, iṣan omi ICMP, ati wíwo ibudo.

SYN Ìkún Kọlu

/ip firewall filter
add action=add-src-to-address-list address-list="syn_flooders" address-list-timeout=1d chain=input connection-state=new dst-limit=30,60,src-address/1m protocol=tcp tcp-flags=syn comment="Detectar SYN flood"
add action=drop chain=input src-address-list="syn_flooders" comment="Bloquear SYN flooders"

ICMP Ìkún Kọlu

/ip firewall filter
add action=add-src-to-address-list address-list="icmp_flooders" address-list-timeout=1d chain=input protocol=icmp limit=10,20 comment="Detectar ICMP flood"
add action=drop chain=input protocol=icmp src-address-list="icmp_flooders" comment="Bloquear ICMP flooders"

3. Gba laaye ijabọ pataki:

Ṣe atunto awọn ofin lati gba ijabọ abẹfẹlẹ pataki fun nẹtiwọọki rẹ. Eyi pẹlu ijabọ inu ati ijabọ si ati lati Intanẹẹti ti o da lori awọn iwulo pato rẹ.

A ro pe o fẹ gba wiwọle SSH nikan lati nẹtiwọki agbegbe rẹ:

/ip firewall filter
add action=accept chain=input protocol=tcp dst-port=22 src-address=192.168.1.0/24 comment="Permitir acceso SSH interno"

4. Fi ohun gbogbo silẹ:

Gẹgẹbi iṣe aabo, eyikeyi ijabọ ti ko gba laaye ni gbangba tẹlẹ yẹ ki o dina. Eyi ni igbagbogbo ṣe ni ipari awọn ofin àlẹmọ ogiriina rẹ pẹlu ofin ti o kọ tabi ju gbogbo awọn ijabọ miiran silẹ.

Ofin yii yẹ ki o gbe ni opin awọn ofin àlẹmọ rẹ lati ṣe bi eto imulo sẹ aiyipada.

/ip firewall filter
add action=drop chain=input comment="Descartar el resto de tráfico no permitido"

NAT (Itumọ Adirẹsi Nẹtiwọọki)

NAT jẹ lilo nigbagbogbo lati tumọ awọn adirẹsi IP ikọkọ lori nẹtiwọọki agbegbe rẹ si adiresi IP ti gbogbo eniyan fun iraye si Intanẹẹti.

  1. Paja:
    • Lo igbese naa masquerade ninu pq srcnat lati gba awọn ẹrọ pupọ laaye lori nẹtiwọọki agbegbe rẹ lati pin adiresi IP ti gbogbo eniyan fun iraye si Intanẹẹti. Eyi ṣe pataki fun awọn nẹtiwọọki ti o wọle si Intanẹẹti nipasẹ ọna asopọ gbohungbohun pẹlu IP ti gbogbo eniyan kan.
  2. DNAT fun awọn iṣẹ inu:
    • Ti o ba nilo lati wọle si awọn iṣẹ inu lati ita nẹtiwọki rẹ, o le lo Nla NAT (DNAT) lati ṣe atunṣe ijabọ ti nwọle si awọn IPs ikọkọ ti o baamu. Rii daju pe o ṣe eyi nikan fun awọn iṣẹ to ṣe pataki ki o gbero awọn ilolu aabo.

Awọn imọran Aabo miiran

  1. Awọn imudojuiwọn sọfitiwia:
    • Jeki olulana MikroTik rẹ ni imudojuiwọn pẹlu ẹya tuntun ti RouterOS ati famuwia lati daabobo lodi si awọn ailagbara ti a mọ.
  2. Layer 7 Aabo:
    • Fun ijabọ-pato ohun elo, o le tunto awọn ofin Layer 7 lati dènà tabi gba awọn ijabọ ti o da lori awọn ilana ni awọn apo data.
  3. Idiwọn IP Adirẹsi Range:
    • Ṣe ihamọ iraye si awọn iṣẹ olulana kan si awọn sakani adiresi IP kan pato, nitorinaa idinku eewu wiwọle laigba aṣẹ.

Ranti pe iwọnyi jẹ awọn itọnisọna gbogbogbo nikan. Iṣeto ogiriina kan pato yẹ ki o da lori igbelewọn alaye ti awọn iwulo aabo rẹ, awọn ilana nẹtiwọọki, ati awọn ero ṣiṣe. Ni afikun, o ni imọran lati ṣe idanwo aabo nẹtiwọki nigbagbogbo lati ṣe idanimọ ati dinku awọn ailagbara ti o pọju.

Ko si awọn afi fun ifiweranṣẹ yii.
Njẹ akoonu yii ṣe iranlọwọ fun ọ?
Facebook
twitter
LinkedIn
WhatsApp
Telegram

Awọn iwe aṣẹ miiran ni ẹka yii

Awọn asọye 2 lori “Kini awọn ofin ti gbogbo olulana MikroTik yẹ ki o ni, ni àlẹmọ ogiriina, nat, ati bẹbẹ lọ?”

Fi esi silẹ

Adirẹsi imeeli rẹ yoo ko le ṣe atejade. O beere aaye ti wa ni samisi pẹlu *

Awọn olukọni wa ni MikroLABs

Ko si Awọn iṣẹ-ẹkọ ti a rii!

CODE eni

AN24-LIB

kan si awọn iwe MikroTik ati awọn akopọ iwe

Awọn ọjọ
Awọn wakati
Awọn iṣẹju
Awọn aaya

Ifihan si
OSPF - BGP - MPLS

Wole soke fun yi free course

MAE-RAV-ROS-240118
Awọn ọjọ
Awọn wakati
Awọn iṣẹju
Awọn aaya

Wole soke fun yi free course

MAS-ROS-240111

Promo fun Ọjọ Ọba mẹta!

REYES24

15%

gbogbo awọn ọja

MikroTik courses
Academy courses
MikroTik awọn iwe ohun

Lo anfani ti koodu ẹdinwo Ọjọ Ọba mẹta!

* igbega wulo titi di ọjọ Sundee Oṣu Kini Ọjọ 7, Ọdun 2024
** koodu (ỌBA 24) kan fun rira rira
*** ra iṣẹ-ẹkọ rẹ ni bayi ki o mu titi di Oṣu Kẹta Ọjọ 31, Ọdun 2024

Promo odun titun ti Efa!

NY24

20%

gbogbo awọn ọja

MikroTik courses
Academy courses
MikroTik awọn iwe ohun

Lo anfani ti Odun titun ká Efa koodu eni!

* igbega wulo titi di ọjọ Mọndee, Oṣu Kini Ọjọ 1, Ọdun 2024
** koodu (NY24) kan fun rira rira
*** ra iṣẹ-ẹkọ rẹ ni bayi ki o mu titi di Oṣu Kẹta Ọjọ 31, Ọdun 2024

Keresimesi eni!

XMAS 23

30%

gbogbo awọn ọja

MikroTik courses
Academy courses
MikroTik awọn iwe ohun

Lo anfani koodu ẹdinwo fun Keresimesi !!!

** Awọn koodu ti wa ni lilo ninu rira rira
Promo wulo titi di Ọjọ Aarọ Oṣu kejila ọjọ 25, Ọdun 2023

EYONU OSE CYBER

CW23-MK

17%

gbogbo MikroTik OnLine courses

CW23-AX

30%

gbogbo Academy courses

CW23-LIB

25%

gbogbo MikroTik Books ati Book Packs

Lo anfani awọn koodu ẹdinwo fun Ọsẹ Cyber ​​​​!!!

** Awọn koodu ti wa ni lilo ninu rira rira
Promo wulo titi di ọjọ Sundee Oṣu kejila ọjọ 3, Ọdun 2023

DUDU Friday eni

BF23-MX

22%

gbogbo MikroTik OnLine courses

BF23-AX

35%

gbogbo Academy courses

BF23-LIB

30%

gbogbo MikroTik Books ati Book Packs

Lo anfani awọn koodu ẹdinwo fun Black Friday !!!

** Awọn koodu ti wa ni lilo ninu rira rira

Awọn koodu ti wa ni loo ninu rira rira
wulo titi di ọjọ Sundee Oṣu kọkanla ọjọ 26, Ọdun 2023

Awọn ọjọ
Awọn wakati
Awọn iṣẹju
Awọn aaya

Wole soke fun yi free course

MAE-VPN-SET-231115

Halloween Promo

Lo anfani awọn koodu ẹdinwo fun Halloween.

Awọn koodu ti wa ni lilo ninu rira rira

HW23-MK

11% eni lori gbogbo MikroTik OnLine courses

11%

HW23-AX

30% eni lori gbogbo Academy courses

30%

HW23-LIB

25% eni lori gbogbo MikroTik Books ati Book Packs

25%

Forukọsilẹ ki o kopa ninu iṣẹ-ọfẹ Ọfẹ Ifihan si Ilọsiwaju Ilọsiwaju pẹlu MikroTik (MAE-RAV-ROS)

Loni (Ọjọbọ) Oṣu Kẹwa Ọjọ 11, Ọdun 2023
7 irọlẹ si 11 irọlẹ (Colombia, Ecuador, Perú)

MAE-RAV-ROS-231011