Mencegah SSH Brute Force

Ini tulisa pertama saya mengenai Mikrotik, dan saya mencobanya dengan memulai dari Firewall, Walaupun dilain pihak system firewall yang ditawarkan oleh mikrotik tidak sehebat dengan yang lainnya tetapi saya rasa ini bisa membantu,

/ ip firewall filter
add chain=input protocol=tcp dst-port=22 src-address-list=black_list action=drop \
comment="drop ssh brute forcers" disabled=no
add chain=input protocol=tcp dst-port=22 connection-state=new \
src-address-list=ssh_stage3 action=add-src-to-address-list address-list=black_list address-list-timeout=1d \
comment="" disabled=no
add chain=input protocol=tcp dst-port=22 connection-state=new \
src-address-list=ssh_stage2 action=add-src-to-address-list address-list=ssh_stage3 address-list-timeout=1m \
comment="" disabled=no
add chain=input protocol=tcp dst-port=22 connection-state=new \
src-address-list=ssh_stage1 action=add-src-to-address-list address-list=ssh_stage2 address-list-timeout=1m \
comment="" disabled=no
add chain=input protocol=tcp dst-port=22 connection-state=new \
action=add-src-to-address-list address-list=ssh_stage1 address-list-timeout=1m comment="" \
disabled=no

Artikel,belajar,jaringan,tips,trik,windows,tutorial,software,gratis,internet,hacking,komputer;

{ 0 comments... read them below or add one }

Posting Komentar