本帖最后由 Ryo_ 于 2022-9-1 23:58 编辑
不用的服务可以关掉,或者限制只允许特定网段访问
- /ip service
- set telnet disabled=yes
- set ftp disabled=yes
- set www disabled=yes
- set ssh disabled=yes
- set api disabled=yes
- set winbox address=192.168.1.0/24
- set api-ssl disabled=yes
复制代码
然后是防止扫描,可以加上这些规则,对僵尸网络的扫描有一定的抵抗力
- /ip firewall raw
- add action=drop chain=prerouting comment=ANTI-BOT src-address-list=BOT
- add action=add-src-to-address-list address-list=BOT address-list-timeout=1w chain=prerouting comment=ANTI-SCAN dst-port=\
- 20-23,53,80,135,139,443,445,1433,2049,3389,5900,8080,8089 log=yes log-prefix=ANTI-SCAN protocol=tcp src-address-list=SCAN_S2
- add action=add-src-to-address-list address-list=SCAN_S2 address-list-timeout=1m chain=prerouting comment=ANTI-SCAN dst-port=\
- 20-23,53,80,135,139,443,445,1433,2049,3389,5900,8080,8089 protocol=tcp src-address-list=SCAN_S1
- add action=add-src-to-address-list address-list=SCAN_S1 address-list-timeout=1m chain=prerouting comment=ANTI-SCAN dst-port=\
- 20-23,53,80,135,139,443,445,1433,2049,3389,5900,8080,8089 in-interface-list=WAN protocol=tcp src-address-list=!whitelist
复制代码
PS: 外网需要白名单的可以加到名为whitelist的地址表里
我这边大概一周会拉黑200个左右的ip,实际尝试扫描的ip会更多,不过一般扫几个常见端口不成功就放弃了,这部分也就不管了
|