找回密码
 注册

QQ登录

只需一步,快速开始

搜索
查看: 11040|回复: 2

[策略设置] 发扬举一反三精神,一个IPV6的防止重复尝试登录ROS的设置

[复制链接]
发表于 2013-9-21 01:00:22 | 显示全部楼层 |阅读模式

马上注册,结交更多好友,享用更多功能,让你轻松玩转社区。

您需要 登录 才可以下载或查看,没有账号?注册

×
有IPV4下的防止重复尝试登录ros的设置,现在将这种精神引申到IPV6上来,提高ROS的安全性。
同一IP30秒尝试4次以上时,阻止新建的TCP连接(端口 21,22,23,8291)
  1. # sep/20/2013 10:55:04 by routeros 5.25
  2. # software id = XXOO-XXOO
  3. #
  4. /ipv6 firewall filter
  5. add action=reject chain=input connection-state=new disabled=no dst-port=21,22,23,8291 protocol=tcp \
  6.     reject-with=tcp-reset src-address-list=blocked
  7. /ipv6 firewall mangle
  8. add action=add-src-to-address-list address-list=blocked address-list-timeout=4h chain=input comment=\
  9.     blocked connection-state=new disabled=no dst-port=21,22,23,8291 protocol=tcp src-address-list=\
  10.     telnet4
  11. add action=add-src-to-address-list address-list=telnet4 address-list-timeout=30s chain=input comment=\
  12.     telnet4 connection-state=new disabled=no dst-port=21,22,23,8291 protocol=tcp src-address-list=\
  13.     telnet3
  14. add action=add-src-to-address-list address-list=telnet3 address-list-timeout=30s chain=input comment=\
  15.     telnet3 connection-state=new disabled=no dst-port=21,22,23,8291 protocol=tcp src-address-list=\
  16.     telnet2
  17. add action=add-src-to-address-list address-list=telnet2 address-list-timeout=30s chain=input comment=\
  18.     telnet2 connection-state=new disabled=no dst-port=21,22,23,8291 protocol=tcp src-address-list=\
  19.     telnet1
  20. add action=add-src-to-address-list address-list=telnet1 address-list-timeout=30s chain=input comment=\
  21.     telnet1 connection-state=new disabled=no dst-port=21,22,23,8291 protocol=tcp

复制代码
routeros
发表于 2013-9-21 20:06:06 | 显示全部楼层
等我试用一下
routeros
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 注册

本版积分规则

QQ|Archiver|手机版|小黑屋|软路由 ( 渝ICP备15001194号-1|渝公网安备 50011602500124号 )

GMT+8, 2025-4-20 12:29 , Processed in 0.060371 second(s), 14 queries , Gzip On, Redis On.

Powered by Discuz! X3.5 Licensed

© 2001-2025 Discuz! Team.

快速回复 返回顶部 返回列表