Saturday, June 6, 2015

Spam detection using Mikrotik Router OS




/ip firewall filter

add chain=forward protocol=tcp dst-port=25 \
    src-address-list=suspectedspambot \
    action=drop comment="Drop traffic from those on the suspect list"

add chain=forward protocol=tcp dst-port=25 \
    connection-limit=10,32 \
    action=add-src-to-address-list \
    address-list=suspectedspambot \
    address-list-timeout=2d \
    comment="More than 10 simultaneous connections looks spammy"


I have alternated colors for readability. The operation of this approach is quite simple. The first rule (in blue) simply drops any SMTP connection attempts from anyone who is found in the address list called “suspectedspambot”. The second rule (in red) is the one that does the work of actually detecting spammers. What this rule does is watch for SMTP connections and, if the count of connections from a single IP (/32) goes above 10, then the source address of that packet is added to an address list called “suspectedspambot”. On the next connection attempt, the packet will be dropped. The only problem with this approach is that it assumes that there are NO mail servers that MAY be sending more than 10 emails at a time legitimately. If this is the case, you can simply create another address list called “smtpservers” then add a rule as follows ABOVE the rule above (in blue):


add chain=forward protocol=tcp dst-port=25 \
       src-address-list=smtpservers action=accept \
       comment="Allow known smtp servers to send email"


This would allow your known mail servers to send email without fear of being “caught” and tagged as a spam source. One further comment on these rules. This set of rules does not take into account smtp traffic that is going TO your mail server. I will leave that fix as an exercise for the reader. If one of your customers is “tagged” as a suspected spambot, you will find their IP address in the address list and can begin troubleshooting from there.
 
===============================================================================

 

Wednesday, March 12, 2014

MikroTik-Router-pppoe-server-setup-with-Cisco Switch vlan



Basic Ip Address Configuration :
/ip address
add address=103.7.248.206/29 network=103.7.248.200 broadcast=103.7.248.207 interface=WAN
         
Ip Pool configuration for PPPOE user :
/ip pool
add name=PPPOE ranges=172.16.10.1-172.16.10.254
/ppp profile
add name="PPPOE" local-address=172.16.10.1 remote-address=PPPOE dns-server=8.8.8.8,4.4.4.4
interface vlan
add name=100-ADMIN  interface=LOCAL  vlan-id=100
add name=200-NOC  interface=LOCAL  vlan-id=200

/interface pppoe-server server
Add service-name="PPPOE_ADMIN" interface=ADMIN max-mtu=1480 max-mru=1480
     mrru=disabled authentication=pap,chap keepalive-timeout=10
     one-session-per-host=yes max-sessions=0 default-profile=default

 add service-name="PPPOE_NOC" interface=NOC max-mtu=1480 max-mru=1480
     mrru=disabled authentication=pap,chap keepalive-timeout=10
     one-session-per-host=yes max-sessions=0 default-profile=default


Create a PPPOE  User:
/ppp secret
 add name=Test service=pppoe password=123 profile=PPPOE local-address=172.16.10.1 remote-address=172.16.10.3

Bandwidth Control Using PCQ Method:
/Queue type
add name=PPPOE_1M_DOWNLOAD kind=pcq pcq-rate=1M pcq-classifier=src-address
add name=PPPOE_1M_UPLOAD kind=pcq pcq-rate=1M pcq-classifier=dst-address
/queue simple

add name="Total" target-addresses=172.16.10.0/24 interface=all parent=none
      packet-marks="" direction=both priority=8
      queue=default-small/default-small limit-at=0/0 max-limit=0/0
      burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s
      total-queue=default-small
                       
add  name="PPPOE-1M User" target-addresses=172.16.10.0/24 interface=LOCAL
      parent=Total packet-marks="" direction=both priority=2
      queue=PPPOE_1M_UPLAOAD/PPPOE_1M_DOWNLOAD limit-at=0/0 max-limit=0/0
      burst-limit=0/0 burst-threshold=0/0 burst-time=0s/0s
      total-queue=default-small

Lowest priority is better than other, If use this type of queue then we can easy to manage bandwidth  a group of client

/ip firewall nat
add chain=srcnat action=masquerade src-address=172.16.10.0/24 out-interface=WAN


IP Route Configuration:

/ip route
add dst-address=0.0.0.0/0 gateway=103.7.248.201


Cisco Switch Configuration:
CISCO>enable
CISCO#configuration terminal
CISCO(config)#interface fastethernet 0/1
CISCO(config-if)#switchport mode trunk
CISCO(config-if)#switchport trunk allowed vlan all
CISCO(config-if)#switchport nonegotiate
CISCO(config)#vlan 100
CISCO(config-vlan)#name ADMIN
CISCO(config)#vlan 200
CISCO(config-vlan)#name NOC
CISCO(config)#interface fastethernet 0/2
 CISCO(config-if)#switchport mode access
CISCO(config-if)#switchport access vlan 100

CISCO(config)#interface fastethernet 0/3
 CISCO(config-if)#switchport mode access
CISCO(config-if)#switchport access vlan 200

CISCO#wr


Sunday, September 29, 2013

Selective Policy-Based Routing with Mikrotik RouterOS

This guide assumes that you have two Internet Connections of different or the same provider. Selective policy-based routing is useful when you want to route specific services to a dedicated or specific network or service provider (e.g all voip connections goes to provider “A” and all http connections goes to provider “B”).
selective routing diagram
Benefits of Policy-based routing
  • Load sharing - when you want to separate the voice from data traffic, or assign bandwidth hunger services to a much bigger bandwidth pipe.
  • Quality of Service - all network services will have a fair weighted share of bandwidth, such as network administrator will be able to classify what services would be routed or assign to a bigger bandwidth link.
Setting up Mikrotik RouterOS for Policy-based Routing
  • Login to your Mikrotik winbox
  • Once logged in, click on “IP -> Routes” then add a route
  • Select the gateway where you want to route selected traffic or protocols, under the “Mark” input box enter the name of the route (we will be using the route name later for marking packet route), Click Ok.
routing mark
After adding the route name in your routing table, we will now proceed to the packet mangling, where all packet alteration will be done.
  • Click on “IP -> Firewall -> Mangle”, then click add. Under general tab, input your src address, destination address, protocol these are not required, only if you want to be too specific with your mangling rule.
  • packet mangling
  • Click on “Action” tab, then under Action, select the “Mark Routing” then enter the routing name where you want the traffic to be routed under the “New Routing Mark”.
    packet mangling routing mark
  • Lastly, Click ok.
To check if the traffic is routed to the desired link, perform a traceroute

Automatically find unathorized devices and block it on firewall

One of the features I like most in Mikrotik RouterOS is the ability to run custom scripts that will enable you to automate some things on router side. In a workplace where “bring your own device” is practiced, being able to control the registration of these devices on your network is very important especially for mobile devices - laptops, tablets and smartphones.
It’s becoming harder to control these device especially if they are in large number. Smartphone can be just placed inside a bag or pocket while it automatically connect through your access points where wireless key is known to the user and download unnecessary files on the internet thus wasting network bandwidth while increasing network security risk.
Now, if you happen to have a Mikrotik RouterOS in your network and is facing the same dilemma then probably the script below will help you solve it or least get you started on a better solution.

01
02# Tested to work on RouterOS 5.19
03 
04:foreach i in=[/ip dhcp-server lease find dynamic=yes] do={
05   :local dynamicIP [/ip dhcp-server lease get $i address];
06   :local dynamicMAC [/ip dhcp-server lease get $i mac-address];
07   :local dynamicHOST [/ip dhcp-server lease get $i host-name];
08   :local macfound [/ip firewall filter find src-mac-address=$dynamicMAC];
09 
10    :if ($macfound != "") do={
11        :log info ($dynamicMAC. " already filtered")
12    } else= {
13        /ip firewall filter add chain=forward src-mac-address=$dynamicMAC action=drop comment=($dynamicHOST . " - " . $dynamicMAC . " Unregistered device")
14        :log info ("Added " . $dynamicMAC. " to firewall filter")
15    }
16}
Basically, the script will look for dynamic ip addresses inside the dhcp server leases table and search their mac address in the firewall filter table. If it’s not yet blocked then it will create an entry blocking the mac address to prevent it from sending traffic through your network.
To automatically execute the script periodically, you will need to add it on the scheduler, see example below:

1/system scheduler add comment="Find unauthorized devices and block" disabled=no interval=5m  name=block_unauthorized_devices on-event=block_unauthorized_devices policy=read,write,test
You should be able to see on your log what devices are being blocked as the script finds one.

Monday, May 27, 2013

Mac authentication with Mikrotik for HotSpot user

Mac authentication with Mikrotik


How do I use Mac authentication with Mikrotik?
Using mac authentication you can provide free access to a device without it going through the splash page.
First you have to create a user with the username that will be his wireless mac address, and a password which is set to "password".
Click IP-HOTSPOT-USERS. Click add user.
The name field should be the wireless mac address of the device that you want to bypass the splash page.
The password field should be set to "password".


Click SERVER PROFILES, still under the hotspot section. Double click the current profile in use and under the login tab find the field "mac auth. password". Fill in "password"  for this field.


Monday, March 4, 2013

Dual WAN loadbalancing nth method

/ip address
add address=192.168.1.3/24 network=192.168.1.0 broadcast=192.168.1.255 interface=WAN1 comment="" disabled=no
add address=192.168.2.3/24 network=192.168.2.0 broadcast=192.168.2.255 interface=WAN2 comment="" disabled=no
add address=10.10.0.1/24 network=10.10.0.0 broadcast=10.10.0.255 interface=internal comment="" disabled=no

/ip firewall mangle
add chain=prerouting in-interface=internal connection-state=new nth=2,1 action=mark-connection new-connection-mark=conn1 passthrough=yes comment="" disabled=no
add chain=prerouting in-interface=internal connection-mark=conn1 action=mark-routing new-routing-mark=conn1 passthrough=no comment="" disabled=no
add chain=prerouting in-interface=internal connection-state=new nth=1,1 action=mark-connection new-connection-mark=conn2 passthrough=yes comment="" disabled=no
add chain=prerouting in-interface=internal connection-mark=conn2 action=mark-routing new-routing-mark=conn2 passthrough=no comment="" disabled=no


/ip firewall nat
add chain=srcnat connection-mark=conn1 action=masquerade out-interface=WAN1 comment="" disabled=no
add chain=srcnat connection-mark=conn2 action=masquerade out-interface=WAN2 comment="" disabled=no


/ip route
add dst-address=0.0.0.0/0 gateway=192.168.1.1 scope=255 target-scope=10 routing-mark=conn1 comment="" disabled=no
add dst-address=0.0.0.0/0 gateway=192.168.2.1 scope=255 target-scope=10 routing-mark=conn2 comment="" disabled=no

Dual WAN LoadBalancing PCC Method

/ip address
add address=192.168.0.1/24 network=192.168.0.0 broadcast=192.168.0.255 interface=Local
add address=192.168.1.2/24 network=192.168.1.0 broadcast=192.168.1.255 interface=WAN1
add address=192.168.2.2/24 network=192.168.2.0 broadcast=192.168.2.255 interface=WAN2

/ip dns set allow-remote-requests=yes cache-max-ttl=1w cache-size=5000KiB max-udp-packet-size=512 servers=221.132.112.8,8.8.8.8

/ip firewall mangle
add chain=input in-interface=WAN1 action=mark-connection new-connection-mark=WAN1_conn
add chain=input in-interface=WAN2 action=mark-connection new-connection-mark=WAN2_conn

add chain=output connection-mark=WAN1_conn action=mark-routing new-routing-mark=to_WAN1
add chain=output connection-mark=WAN2_conn action=mark-routing new-routing-mark=to_WAN2

add chain=prerouting dst-address=192.168.1.0/24 action=accept in-interface=Local
add chain=prerouting dst-address=192.168.2.0/24 action=accept in-interface=Local

add chain=prerouting dst-address-type=!local in-interface=Local per-connection-classifier=both-addresses-and-ports:2/0 action=mark-connection new-connection-mark=WAN1_conn passthrough=yes
add chain=prerouting dst-address-type=!local in-interface=Local per-connection-classifier=both-addresses-and-ports:2/1 action=mark-connection new-connection-mark=WAN2_conn passthrough=yes

add chain=prerouting connection-mark=WAN1_conn in-interface=Local action=mark-routing new-routing-mark=to_WAN1
add chain=prerouting connection-mark=WAN2_conn in-interface=Local action=mark-routing new-routing-mark=to_WAN2

/ip route
add dst-address=0.0.0.0/0 gateway=192.168.1.1 routing-mark=to_WAN1 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=192.168.2.1 routing-mark=to_WAN2 check-gateway=ping

add dst-address=0.0.0.0/0 gateway=192.168.1.1 distance=1 check-gateway=ping
add dst-address=0.0.0.0/0 gateway=192.168.2.1 distance=2 check-gateway=ping

/ip firewall nat
add chain=srcnat out-interface=WAN1 action=masquerade
add chain=srcnat out-interface=WAN2 action=masquerade