1. Port Akses yang terbuka
disable port yang tidak digunakan
telnet- disable
atau available from diatur ke ip tertentu misal 192.168.1.25
Winbox atur ke alamat ip tertentu
2. DNS Server & Proxy tidak diamankan
Solusi DNS
protokol UDP :
atur Firewall buat rule Chain = input, Protocol =udp dst port =53
in-interface=eth1 action =drop
dns protokol tcp :
chain= input protocol=tcp dst port =53 in-interface=eth1 action =drop
atau memberikan akses hanya untuk ip tertentu/ Whitelist ex:192.168.1.25:
chain= input src.Addresss = ! 192.168.1.25 protocol=tcp dst port =53 in-interface=eth1 action =drop
Proxy
chain= input protocol=tcp dst port =8080 in-interface=eth1 action =drop
3. Kesalahan Load Balancer
masuk ISP1 keluar lewat ISP2 = salah
harusnya
masuk ISP1 Keluar ISP1
UNTUK ISP 1 Solusi
New Mangle Rule
FIrewall -> Mangle- New (+)
untuk downloadnya router
Chain = input in interface=ether1 (ketika kita kases lewat VPN/dari luar)
action=mark connection New Connection mark=ISP1
untuk downloadnya client
Chain = prerouting IN-interface=ether1 (ketika kita kases lewat VPN/dari luar)
action=mark connection New Connection mark=ISP1
untuk upload
Chain = prerouting in-interface=!ether1 connection mark =ISP1 action=mark connection New Connection mark=ISP1
Untuk merubah jalur
Chain = input connection mark =ISP1 action=mark routing New routing mark=Routing ISP1
Comment : mangle for ISP1
UNTUK ISP 2
untuk downloadnya router
Chain = input in interface=ether1 (ketika kita kases lewat VPN/dari luar)
action=mark connection New Connection mark=ISP2
untuk downloadnya client
Chain = prerouting IN-interface=ether1 (ketika kita kases lewat VPN/dari luar)
action=mark connection New Connection mark=ISP2
untuk upload
Chain = prerouting in-interface=!ether1 connection mark =ISP2 action=mark connection New Connection mark=ISP2
Untuk merubah jalur
Chain = input connection mark =ISP2 action=mark routing New routing mark=Routing ISP2
Comment : mangle for ISP2
mengamankan route
atur route default tambahkan :
Dst address = 0.0.0./0
gateway ex=192.168.1.1 routing Mask=ISP1
tambah lagi
Dst address = 0.0.0./0
gateway ex=192.168.7.1 routing Mask=ISP2
Comments
Post a Comment