Welcome Guest ( Log In | Register )

176 Pages « < 77 78 79 80 81 > » Bottom

Outline · [ Standard ] · Linear+

Enterprise Networking Mikrotik Routers (RouterBoard & RouterOS), User and owner discussion group

views
     
rioven
post Mar 26 2018, 05:35 PM

Enthusiast
*****
Senior Member
975 posts

Joined: Sep 2004
From: Setapak



QUOTE(Ebony & Ivory @ Mar 26 2018, 05:17 PM)
Is Squidblacklist a dynamic list? It write into the memory or internal flash?
*
Unfortunately its not dynamic list. It might using extra write to internal flash even so you are download directly to usb/micro-sd. Still to figure it out interval update, dont wanna unnecessary write internal nand (they claim they update list every 30 minute, for time being i do update every 6-12 hours)
Ebony & Ivory
post Mar 26 2018, 05:39 PM

Enthusiast
*****
Senior Member
962 posts

Joined: Jan 2016
QUOTE(rioven @ Mar 26 2018, 05:35 PM)
Unfortunately its not dynamic list. It might using extra write to internal flash even so you are download directly to usb/micro-sd. Still to figure it out interval update, dont wanna unnecessary write internal nand (they claim they update list every 30 minute, for time being i do update every 6-12 hours)
*
I see.

If like this, need to reduce the update interval. smile.gif


charymsylyn
post Mar 27 2018, 12:24 AM

On my way
****
Junior Member
500 posts

Joined: May 2007
From: Kuala Lumpur
QUOTE(Ebony & Ivory @ Mar 26 2018, 09:24 AM)
Recently, Dave decided to shutdown the service  sweat.gif

https://forum.mikrotik.com/viewtopic.php?f=...art=550#p650107

still got any good blacklist to recommend?

how about SQUIDBLACKLIST?

https://blog.squidblacklist.org/?p=1407
*
Hi, thanks for recommending this blacklist, I didn't realise Mikrotik could be this powerful. After reading the above 2 links and cross referencing with Mikrotik documentation and Google searches, I found that pasting these lines into Terminal window will automatically download the file and add the rules to IPv4 Firewall.

CODE

/tool fetch address=www.squidblacklist.org host=www.squidblacklist.org mode=http src-path=/downloads/drop.malicious.rsc; import drop.malicious.rsc
ip firewall raw add chain=prerouting dst-address-list="sbl dshield" action=drop comment="sbl dshield"
ip firewall raw add chain=prerouting dst-address-list="sbl spamhaus" action=drop comment="sbl spamhaus"
ip firewall raw add chain=prerouting dst-address-list="sbl blocklist.de" action=drop comment="sbl blocklist.de"


My dumb question is, how to test whether the rules are working? IPv4 Firewall > Raw doesn't seem to be updating after an hour or so of normal surfing. Thank you so much.

Attached Image
Ebony & Ivory
post Mar 27 2018, 01:00 AM

Enthusiast
*****
Senior Member
962 posts

Joined: Jan 2016
QUOTE(charymsylyn @ Mar 27 2018, 12:24 AM)
My dumb question is, how to test whether the rules are working? IPv4 Firewall > Raw doesn't seem to be updating after an hour or so of normal surfing. Thank you so much.

*
yup, mikrotik indeed is a very powerful router, with script it can do a lot of things.

check the rules counter.

firewall will use the rules to inspect network traffic, if the condition is match, it will in effect. like block input/forward packet from certain IP in blacklist.

try add the rule in filter rule, not raw. and the chain to input and forward for each rule, it works for me.

Attached Image

maybe someone with more experience in firewall can comment on this.



This post has been edited by Ebony & Ivory: Mar 27 2018, 01:13 AM
rioven
post Mar 27 2018, 01:31 AM

Enthusiast
*****
Senior Member
975 posts

Joined: Sep 2004
From: Setapak



@charymsylyn u might add another this line
CODE

/ip firewall raw add chain=prerouting src-address-list="sbl dshield" action=drop comment="sbl dshield"
/ip firewall raw add chain=prerouting src-address-list="sbl spamhaus" action=drop comment="sbl spamhaus"
/ip firewall raw add chain=prerouting src-address-list="sbl blocklist.de" action=drop comment="sbl blocklist.de"

With this you will block from internet to ur network (the previous setting block opposite way)
Ebony & Ivory
post Mar 27 2018, 06:01 AM

Enthusiast
*****
Senior Member
962 posts

Joined: Jan 2016
i just fetched the sbl and converted it to dynamic address list manually, a bit hassle, sweat.gif

but at least it reduce write to the tiny flash storage significantly. laugh.gif

it is working fine so far, and i am still figuring how to do it with script.

Attached Image

the address entries is around 20k (blocklist.de+dshield), memory usage is 70MB+

Attached Image

This post has been edited by Ebony & Ivory: Mar 27 2018, 06:16 AM
soonwai
post Mar 27 2018, 03:59 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


Someone scanning for Winbox ports.
https://twitter.com/mikrotik_com/status/978533853324283904
user posted image
charymsylyn
post Mar 27 2018, 11:10 PM

On my way
****
Junior Member
500 posts

Joined: May 2007
From: Kuala Lumpur
QUOTE(rioven @ Mar 27 2018, 01:31 AM)
@charymsylyn u might add another this line
With this you will block from internet to ur network (the previous setting block opposite way)
*
Thanks a lot, now can see some hits.
rioven
post Mar 29 2018, 06:39 PM

Enthusiast
*****
Senior Member
975 posts

Joined: Sep 2004
From: Setapak



Some useful DNS block (other than squidblacklist, can be customized)
Mikrotik Stop Ad

p/s: dont select all option...it will eat ur memory biggrin.gif
ahlong
post Mar 30 2018, 02:07 PM

not a debt collector
****
Junior Member
612 posts

Joined: Apr 2005
From: http://127.0.0.1:80/announce



halo brader soonwai

do u have any working ddns (afraid.org) script? my previous script is not working ar..
System Error Message
post Mar 30 2018, 02:39 PM

Regular
******
Senior Member
1,781 posts

Joined: Jul 2010
QUOTE(soonwai @ Mar 27 2018, 03:59 PM)
If your router can be seen from any of the management ports, your firewall configuration sucks.
In any of the tutorials i've done, despite not being complete i always block all input on WAN except for NTP and DNS to whitelisted servers. If you want to manage your mikrotik remotely, set up VPN on it and allow VPN because VPN does not interface with the OS directly, only the networking part so you can secure it. It is recommended to run your own internal VPN server (if you use ASUS as APs like i do, can use that too) but make sure that it is secured.

Never use blankets, always specify every access. So if you have an automated whitelist, make sure that the whitelist is specific in every way (service, ports, addresses). Dont allow input from google DNS for everything. only for specifics as an example. Not to mention that google does try to spy on you alongside many other servers so making sure they cant access your network is important even if its google or facebook as they're a pain when you set up an IPS as they always get blocked.

And use drop rather than deny as no response is better than unauthorised response.
soonwai
post Mar 30 2018, 05:15 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(ahlong @ Mar 30 2018, 02:07 PM)
halo brader soonwai

do u have any working ddns (afraid.org) script? my previous script is not working ar..
*
Dun have wor. The only script I have for ddns is the namecheap one since that’s the only thing I use. Which script you using? From Mikrotik forum? I’m sure they’ll update it. afraid.org changed their update url format so lots of things stopped working. My old DNS-323 also cannot update already.

This post has been edited by soonwai: Mar 30 2018, 05:18 PM
ahlong
post Apr 1 2018, 11:07 AM

not a debt collector
****
Junior Member
612 posts

Joined: Apr 2005
From: http://127.0.0.1:80/announce



QUOTE(soonwai @ Mar 30 2018, 05:15 PM)
Dun have wor. The only script I have for ddns is the namecheap one since that’s the only thing I use. Which script you using? From Mikrotik forum? I’m sure they’ll update it. afraid.org changed their update url format so lots of things stopped working. My old DNS-323 also cannot update already.
*
ya lor from their forum.. suddenly not working.. haihz..
nevermind brader, already fix using this ddns (afraid.org) mikrotik one.. seems working..

anyway, thanks ar for replying..
mamakap
post Apr 1 2018, 06:47 PM

Casual
***
Junior Member
403 posts

Joined: Jan 2005
Anyone have the step by step or terminal script to setup for Unifi IPv6? Thanks advance.
soonwai
post Apr 1 2018, 09:56 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(mamakap @ Apr 1 2018, 06:47 PM)
Anyone have the step by step or terminal script to setup for Unifi IPv6? Thanks advance.
*
https://klseet.com/5-tm-unifi/unifi-general/258-unifi-ipv6
https://forum.lowyat.net/index.php?showtopi...&#entry63945436

The above 2 links should get you going. Not everything is necessary but they don't hurt so just follow one of them. I used the klseet guide when I first set mine up. I think it's the easiest to follow.
System Error Message
post Apr 4 2018, 03:34 AM

Regular
******
Senior Member
1,781 posts

Joined: Jul 2010
QUOTE(soonwai @ Apr 1 2018, 09:56 PM)
https://klseet.com/5-tm-unifi/unifi-general/258-unifi-ipv6
https://forum.lowyat.net/index.php?showtopi...&#entry63945436

The above 2 links should get you going. Not everything is necessary but they don't hurt so just follow one of them. I used the klseet guide when I first set mine up. I think it's the easiest to follow.
*
TM Unifi have IPV6 already? So we can have both IPV4 and IPV6 public addresses?
soonwai
post Apr 4 2018, 08:00 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(System Error Message @ Apr 4 2018, 03:34 AM)
TM Unifi have IPV6 already? So we can have both IPV4 and IPV6 public addresses?
*
Yeah, quite long already, since 3/4 years ago or thereabouts.
charymsylyn
post Apr 5 2018, 10:24 PM

On my way
****
Junior Member
500 posts

Joined: May 2007
From: Kuala Lumpur
QUOTE(charymsylyn @ Mar 27 2018, 11:10 PM)
Thanks a lot, now can see some hits.
*
I removed this from my router because it was taking up too much resources until at one point, it rejected my attempt to connect to wifi because there wasn't enough resources for me to connect (based on the log messages). It also didn't make sense to commit resources to block outgoing connection attempts to IP addresses blocked for spam and what not, if I was connecting to them, that means my devices was already compromised in some way and my problem is more serious.

After some Googling, I found someone who created and shared a simple ad-blocking script suitable for low RAM routers like my model so I wanted to share it with others. The code shown when pasted into terminal will auto create the script and even scheduler entry for auto updates. This makes adding this easy enough for even newbies like me. biggrin.gif

https://www.micu.eu/mikrotik-adblock-script-lite/
charymsylyn
post Apr 5 2018, 10:40 PM

On my way
****
Junior Member
500 posts

Joined: May 2007
From: Kuala Lumpur
QUOTE(System Error Message @ Apr 4 2018, 03:34 AM)
TM Unifi have IPV6 already? So we can have both IPV4 and IPV6 public addresses?
*
Both Unifi and Time have been running dual stack for several years now. Even mobile telco also supports IPv6 but need to enable support in APN. Operators don't have much choice since APNIC has next to zero unallocated IPv4 addresses to give out having reached exhaustion back in 2011.
rioven
post Apr 6 2018, 05:16 PM

Enthusiast
*****
Senior Member
975 posts

Joined: Sep 2004
From: Setapak



QUOTE(charymsylyn @ Apr 5 2018, 10:24 PM)
I removed this from my router because it was taking up too much resources until at one point, it rejected my attempt to connect to wifi because there wasn't enough resources for me to connect (based on the log messages). It also didn't make sense to commit resources to block outgoing connection attempts to IP addresses blocked for spam and what not, if I was connecting to them, that means my devices was already compromised in some way and my problem is more serious.

After some Googling, I found someone who created and shared a simple ad-blocking script suitable for low RAM routers like my model so I wanted to share it with others. The code shown when pasted into terminal will auto create the script and even scheduler entry for auto updates. This makes adding this easy enough for even newbies like me. biggrin.gif

https://www.micu.eu/mikrotik-adblock-script-lite/
*
Great finding, lest complicated than my previous adblock. The list is almost the same. Btw its advisable to increase its cache to large size (let say about 16mb, cant rember default size)

176 Pages « < 77 78 79 80 81 > » Top
 

Change to:
| Lo-Fi Version
0.0871sec    0.81    6 queries    GZIP Disabled
Time is now: 17th December 2025 - 03:27 AM