You are on page 1of 1

Configuracion de Router Mikrotik Routerboard Cap 04 Seguridad

Para este video aprenderemos a como cambiar la contraseña, cerrar puertos de


acceso, cambiar los puertos de administracion y reglas mas avanzadas de seguridad.

Script version RouterOS 6.42:


/ip firewall filter
add action=add-src-to-address-list address-list=lista_negra_ssh address-list-
timeout=1w3d chain=input comment=\
"Bloquear fuerza bruta" connection-state=new dst-port=22 protocol=tcp src-
address-list=ssh3
add action=add-src-to-address-list address-list=ssh3 address-list-timeout=1m
chain=input connection-state=new \
dst-port=22 protocol=tcp src-address-list=ssh2
add action=add-src-to-address-list address-list=ssh2 address-list-timeout=1m
chain=input connection-state=new \
dst-port=22 protocol=tcp src-address-list=ssh1
add action=add-src-to-address-list address-list=ssh1 address-list-timeout=1m
chain=input connection-state=new \
dst-port=22 protocol=tcp
add action=drop chain=input dst-port=22 protocol=tcp src-address-
list=lista_negra_ssh
add action=tarpit chain=forward comment="Bloquear DOS 01" connection-limit=20,32
dst-address=163.10.0.84 \
dst-port=80 protocol=tcp
add action=drop chain=forward comment="Bloquear DOS 02" connection-limit=5,32
connection-state=new dst-address=\
163.10.0.84 dst-port=80 protocol=tcp
add action=drop chain=input comment="Denegando escaners de puertos" src-address-
list="Escaner de Puertos"
add action=add-src-to-address-list address-list="Escaner de Puertos" address-list-
timeout=2w chain=input \
comment="Listar como escaner de puertos" protocol=tcp psd=21,3s,3,1
add action=add-src-to-address-list address-list="Escaner de Puertos" address-list-
timeout=2w chain=input \
comment="Escaneo de sigilo NMAP FIN" protocol=tcp tcp-flags=fin,!syn,!rst,!
psh,!ack,!urg
add action=add-src-to-address-list address-list="Escaner de Puertos" address-list-
timeout=2w chain=input \
comment="Escaner SYN/FIN" protocol=tcp tcp-flags=fin,syn
add action=add-src-to-address-list address-list="Escaner de Puertos" address-list-
timeout=2w chain=input \
comment="Escaner SYN/RST" protocol=tcp tcp-flags=syn,rst
add action=add-src-to-address-list address-list="Escaner de Puertos" address-list-
timeout=2w chain=input \
comment="Escaner FIN/PSH/URG" protocol=tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack
add action=add-src-to-address-list address-list="Escaner de Puertos" address-list-
timeout=2w chain=input \
comment="Escaner TODO/TODO" protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg
add action=add-src-to-address-list address-list="Escaner de Puertos" address-list-
timeout=2w chain=input \
comment="Escaner NMAP NULL" protocol=tcp tcp-flags=!fin,!syn,!rst,!psh,!ack,!
urg

You might also like