Firewall in RouterOS: Stopping a DDoS Attack

Поделиться
HTML-код
  • Опубликовано: 2 дек 2024
  • НаукаНаука

Комментарии • 25

  • @engyem2462
    @engyem2462 7 месяцев назад +1

    Keep it going. In terms of mikrotik, this is one of the most advantageous channels.

  • @p_menta
    @p_menta Год назад +1

    Even with RAW rules blocking an NTP Amplification attack, my RB750Gr3 stills hits 95% CPU. What can i do? 😢

  • @pierpa_76pierpaolo
    @pierpa_76pierpaolo Год назад +1

    How to protect modem
    outer from any cyber hackers attack. Can any brand be made inviolable?
    In the past few days I noticed that I was getting my network card disabled and something else remotely. I know perfectly well who is the cause but without evidence with you can proceed with the complaint and move on to the 'arrest of these people (who do not even live far from me. It just so happens!!). Greetings.

  • @kwanelevilakati
    @kwanelevilakati 2 года назад +3

    Thank you so much for this video. Do you create seperate rules for udp packets?

    • @MikroTikCanada
      @MikroTikCanada  2 года назад +1

      Yes, you need to create a separate rule for the UDP protocol.

  • @jeytis72
    @jeytis72 2 года назад +3

    Excellent. It's one of your videos I liked the most. Very clear and helpful explanation. Keep up the good work. Thanks

    • @HaniRahrouh
      @HaniRahrouh 2 года назад

      Thank you for your feedback.

    • @MikroTikCanada
      @MikroTikCanada  2 года назад +2

      Dear jeytis72,
      Many thanks as always for watching our tutorials and sharing your feedback. Now that some of the basics are out of the way, we will be dealing with more practical issues as we move down the MTCNA path.

  • @PilarTecno
    @PilarTecno 7 месяцев назад

    Wow, i started to see the video thinking this was another unuseful one but it gave me very relevant and important information. Im kinda new in mikrotik so it came very handy. Very well explained !

  • @Losdog79
    @Losdog79 10 месяцев назад

    What happens if my router is being sent DDOS attacks from port 53? Can I disable this port without harming my pc?

  • @axeljacobs5276
    @axeljacobs5276 2 года назад +3

    Very good quality ! Many thanks for this excellent work !!

    • @HaniRahrouh
      @HaniRahrouh 2 года назад

      Thank you for your feedback.

    • @MikroTikCanada
      @MikroTikCanada  2 года назад

      Dear Axel Jacobs,
      Many thanks for watching this video and leaving us your feedback. Stay tuned as we will be dealing with more practical issues in the coming weeks.

  • @TubeSkaterRudy
    @TubeSkaterRudy Год назад +2

    Something bothers me in this video. The narrator talks first about simply disabling the 3 services in case you only have a private router and you don't need these services. After that he starts talking about the other case scenario working with raw routing. But this is still blocking all traffic to the same ports so eventually doing exactly the same as simply disabling the services. Or do I understand this wrong and is the second method complimentary to the first one, to really solve the problem of a DDOS attack?

    • @stevebot
      @stevebot 11 месяцев назад +1

      If you disable services they will not be available inside or outside the firewall. FTP and telnet should be fully deprecated by now and disabled by default. SSH remains generally secure and is good for administration and file transfer. With some advanced filtering and rules you can mitigate DoS also.

  • @adaanhauptzn
    @adaanhauptzn 15 дней назад

    Thank you, This helped me out of a jam

  • @MahdiRaeesi
    @MahdiRaeesi Год назад +3

    brief and useful, good job thank you.👍

    • @MikroTikCanada
      @MikroTikCanada  Год назад

      Dear Mahdi Raeesi,
      Many thanks for watching our videos! If you have any feedback, we'd love to hear it!

  • @Glenners
    @Glenners 2 года назад +3

    Daniel told me to follow

    • @MikroTikCanada
      @MikroTikCanada  2 года назад +1

      Dear Glenners,
      Many thanks for subscribing to our channel. Indeed, we will greatly appreciate any input you may have to improve our content!

  • @Anavllama
    @Anavllama 2 месяца назад +1

    Completely bogus, the MT router has no business being used to attempt to stop a DDOS attack. This is the responsibility of the ISP provider and upstream carriers. If you want to play a fools game do waste your time with a DDOS config on the MT device.............

    • @MikroTikCanada
      @MikroTikCanada  Месяц назад +1

      Thank you for sharing your thoughts! You’re absolutely right that ISPs and upstream carriers play a important role in mitigating large-scale DDoS attacks. For massive volumetric attacks, their intervention is often necessary to block traffic at the source before it overwhelms the network.
      That said, MikroTik routers can still be part of a multi-layered defense strategy. While they may not completely stop a full-scale DDoS attack, they can help reduce the impact of smaller attacks, especially at the local network level. Implementing firewall rules, rate limiting, and traffic filters can help protect internal networks from certain types of threats. It’s not a foolproof solution, but it adds another layer of security, which is always beneficial in a comprehensive approach to network protection.
      Thanks again for your comment, and I appreciate your perspective!

  • @mohamadnor3074
    @mohamadnor3074 Год назад +1

    شي جميل شكرا كثير على هذا الفيديو

    • @MikroTikCanada
      @MikroTikCanada  Год назад

      Dear Mohamad Nor,
      Many thanks for your feedback. We’re happy that you’re enjoyed our content. Spread the word and stay tuned!