Block Port scanner, DDOS dan netcut di MIKROTIK - Vertical Network Solution
Headlines News :
Home » » Block Port scanner, DDOS dan netcut di MIKROTIK

Block Port scanner, DDOS dan netcut di MIKROTIK

Written By Vertical Network on Senin, 25 Maret 2013 | 21.47



Ini adalah scrip untuk mengamankan jaringan dari port scanner, DDOS dan netcut di Router Mikrotik.
Langkah² nya adalah sebagai berikut :
/ip firewall filter add action=add-src-to-address-list address-list=DDOS address-list-timeout=15s \ chain=input comment=”" disabled=no dst-port=1337 protocol=tcp
Kemudian :
add action=add-src-to-address-list address-list=DDOS address-list-timeout=15m \ chain=input comment=”" disabled=no dst-port=7331 protocol=tcp src-address-list=knock
add action=add-src-to-address-list address-list=”port scanners” address-list-timeout=2w \ chain=input comment=”Port scanners to list ” disabled=no protocol=tcp psd=21,3s,3,1
add action=add-src-to-address-list address-list=”port scanners” address-list-timeout=2w \ chain=input comment=”SYN/FIN scan” disabled=no protocol=tcp tcp-flags=fin,syn
add action=add-src-to-address-list address-list=”port scanners” address-list-timeout=2w \ chain=input comment=”SYN/RST scan” disabled=no protocol=tcp tcp-flags=syn,rst
add action=add-src-to-address-list address-list=”port scanners” address-list-timeout=2w \ chain=input  disabled=no tcp-flags=fin,psh,urg,!syn,!rst,!ack protocol=tcp \ comment=”FIN/PSH/URG scan”
add action=add-src-to-address-list address-list=”port scanners” address-list-timeout=2w \ chain=input disabled=no protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg \
comment=”ALL/ALL scan”
add action=add-src-to-address-list address-list=”port scanners” address-list-timeout=2w \ chain=input  tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg comment=”NMAP NULL scan” \ disabled=no protocol=tcp
add action=add-src-to-address-list address-list=”port scanners” address-list-timeout=2w \ chain=input comment=”NMAP FIN Stealth scan” disabled=no protocol=tcp
add action=accept chain=input comment=”ANTI NETCUT” disabled=no dst-port=0-65535 \ protocol=tcp src-address=61.213.183.1-61.213.183.254
add action=accept chain=input comment=”ANTI NETCUT” disabled=no dst-port=0-65535 \ protocol=tcp src-address=67.195.134.1-67.195.134.254
add action=accept chain=input comment=”ANTI NETCUT” disabled=no dst-port=0-65535 \ protocol=tcp src-address=68.142.233.1-68.142.233.254
Share this article :

0 komentar:

Speak up your mind

Tell us what you're thinking... !

Deskripsi Iklan
Deskripsi Iklan
Deskripsi Iklan
Deskripsi Iklan
Pasang Iklan Di Sini
 
Support : Creating Website | Johny Template | Mas Template
Copyright © 2011. Vertical Network Solution - All Rights Reserved
Template Created by Creating Website Published by Mas Template
Proudly powered by Blogger