TOP 10 RouterOS Configuration Mistakes

  Рет қаралды 135,751

MikroTik

MikroTik

8 жыл бұрын

TOP 10 RouterOS configuration mistakes by Andis Āriņš (router.lv - Andis Arins, Latvia)

Пікірлер: 40
@thanatos454
@thanatos454 3 жыл бұрын
10 - 3:12 - Same IP on different interfaces 09 - 5:15 - Lack of monitoring 08 - 20:45 - DNS Issues 07 - 25:15 - Firewall Inefficiency 06 - 27:33 - NAT Issues 05 - 33:44 - Allowed IP Spoofing 04 - 39:45 - Bridge Issues 03 - 44:45 - PoE Issues 02 - 48:40 - Waiting for Hackers 01 - 52:00 - admin / no password
@thanatos454
@thanatos454 3 жыл бұрын
Link to presentation slides mum.mikrotik.com//presentations/US16/presentation_3001_1462450916.pdf
@Lann91
@Lann91 2 жыл бұрын
A real hero, thanks
@karlbooklover
@karlbooklover 5 жыл бұрын
Very interesting talk, thank you!
@nirmalacharya3960
@nirmalacharya3960 5 жыл бұрын
just wow sir.
@NwasFalih
@NwasFalih 7 жыл бұрын
Great !
@sardarharis5558
@sardarharis5558 3 жыл бұрын
Great 👍
@azfarhameedkhan7117
@azfarhameedkhan7117 8 жыл бұрын
sir on minute 36:30 when you were discussing traffic generator tool, in packet templates you had 3 tabs General, MAC,IP. but in my routerOS i dont see those 3 Tabs, i only have a General TAB......i am using version 6.35, can you please tell me what version were you using when you prepared those slides? Regards azfar
@xuxamelo
@xuxamelo 5 жыл бұрын
At the NAT section, I supose I don't need the third rule since I'm only accepting related / established connections right?
@gunnargu
@gunnargu 2 жыл бұрын
2 interfaces can share the same LINK LOCAL address just fine, right? Such as using fe80::1 as ipv6 gw
@daaumarius
@daaumarius 6 жыл бұрын
Nice presentation , but on the DNS filtering there is no state for UDP , for what I know UDP is connectionless so you can't filter on new connection state isn't it ?
@pubdigitalix
@pubdigitalix 6 жыл бұрын
I agree with you Marius, but DNS can use TCP when the replay is long enough for the size of UPD datagrams, and TCP is conecction oriented. I don't agree with your evaluation about the presentation in general, because hearing the speaker is a really PTA for someone not english native.
@Roman_4x5
@Roman_4x5 5 жыл бұрын
Mikrotik can keep track of the connection for TCP and UDP the same way conntrack in netfilter works in linux. Filtering new connections works well with few exceptions. Some services may reply from different port and will be also filtered. You can define allow rule that will permit established and related connections before it will filter new one.
@reion78
@reion78 7 жыл бұрын
Hi Andis! Where slides can be downloaded? Thanks
@Akrobs
@Akrobs 7 жыл бұрын
Благодарю.
@wreckedzilla
@wreckedzilla Жыл бұрын
my traineeer
@AndreaFlorio
@AndreaFlorio 4 жыл бұрын
i see some of those mistakes and i think... why doesn't RouterOS handles them? look at junos or IOSm they won't allow to configure overlapping ip/subnets on two interfaces in the same vrf
@sankareshkannan9239
@sankareshkannan9239 6 жыл бұрын
I was disabled the lan interface by winbox now I can’t able to access the router how to solve this issue
@nickandritsos6190
@nickandritsos6190 6 жыл бұрын
You need to reset the router
@sankareshkannan9239
@sankareshkannan9239 6 жыл бұрын
nick andritsos its possible to enable by WAN interface
@mzakelj
@mzakelj 6 жыл бұрын
Conect cable to other port and connect over MAC !!
@jovanjanevski3747
@jovanjanevski3747 7 жыл бұрын
GNU/MikroTik
@janseniogonzalesvenegas2649
@janseniogonzalesvenegas2649 8 жыл бұрын
Haber si las vídeos sean traducidos en español ya que es la lengua que mas se habla en el mundo seria genial
@scarranza22
@scarranza22 6 жыл бұрын
En realidad la lengua mas hablada es el mandarín, y en segundo lugar el ingles. El español ocupa el cuarto lugar de la lista. en.wikipedia.org/wiki/List_of_languages_by_total_number_of_speakers Deberías tomar algunos cursos de ingles, es mas fácil encontrar información o soporte realizando búsquedas en ingles.
@pubdigitalix
@pubdigitalix 6 жыл бұрын
Creo que vos deberías tomar el curso porque si supieras leer ingles podrías observar que el mandarín es el primero y el español es el SEGUNDO (L1 speakers significa nativos). Además no te vendría mal saber un poco de geografía, lo cuál explica las diferencias. Distinto es si miramos la lista de L2 speakers que es una segunda lengua y el ingles lleva lejos la delantera. Coincido que es más facil encontrar información en ingles y eso es en parte por la enorme falta de respeto que tienen los latinos con su propio lenguaje, ya que antes se traducía mucho más al español que ahora.
@RmFrZQ
@RmFrZQ 6 жыл бұрын
[20:46] Why even implement this feature without any means to configure it the right way, like selecting interfaces for this service to be available on?
@kjeldschouten-lebbing6260
@kjeldschouten-lebbing6260 4 жыл бұрын
Because IP/Port binding is never supposed to be a replacement for a firewall.
@thegorn
@thegorn 3 жыл бұрын
Using Mikrotik without studying all the bugs that affect you is probably #1
@misaelcampos5589
@misaelcampos5589 2 жыл бұрын
underated
@moetarded7757
@moetarded7757 2 жыл бұрын
Get an network interpreter. Preferably a network genius with glasses and pen protector.
@sp4c33
@sp4c33 2 жыл бұрын
Use long-term builds...
@user-ur3nw2yi3k
@user-ur3nw2yi3k 3 жыл бұрын
mikrotik
@SteveWrightNZ
@SteveWrightNZ 5 жыл бұрын
too long
@BillAnt
@BillAnt 4 жыл бұрын
LOL... play in at 2x speed, it will be half as long. ;D
@melonmusk3976
@melonmusk3976 4 жыл бұрын
Just skip this guy's autopromotion about resume and M$ Cerrified B$ and jump directly to kzfaq.info/get/bejne/eNGKe7V1m9nagYk.html
@chuck091955
@chuck091955 6 жыл бұрын
At 26 minutes in, talking about firewall inefficiency, Does this person have any knowledge of the subject matter? Apparently not. MikroTik has a stateful firewall and state tables should be examined before any of the configured rules. For traffic from any of the whitelisted IP addresses the return traffic from the web server should never reach the first firewall rule. It should just be permitted by the state table and that should happen very fast. It says this video was published by MikroTik and seeing misinformation like this gives me concern the company does not even know their own product. I have a very large investment in MikroTik equipment and maybe they have lost their talent that was knowledgeable. A better improvement would be to move the rule 9 up to the top since this is for a web server it should be expected that most of the inbound traffic would be hitting that rule. Also doesn't only the first packet of each connection run down the list of rules and all further packets of that connection would be handled in the state table?
@Roman_4x5
@Roman_4x5 5 жыл бұрын
Stateful firewall keeps track of the connection state, but it still need to know the policy against that traffic. This is why there are matchers for connection state. Each packet is being evaluated against each of the rules until it will match the rule or reach the implicit allow. Above all, the example just explains a "mistake" of allowing for firewall to scan all rules for very common traffic. Solution is to define the explicit rule as close to the top as possible in order to save CPU cycles.
This is Why I Hate MikroTik
36:08
MikroTik
Рет қаралды 58 М.
CAPsMAN, real life uses
43:25
MikroTik
Рет қаралды 20 М.
Жайдарман | Туған күн 2024 | Алматы
2:22:55
Jaidarman OFFICIAL / JCI
Рет қаралды 1,8 МЛН
KINDNESS ALWAYS COME BACK
00:59
dednahype
Рет қаралды 147 МЛН
Heartwarming: Stranger Saves Puppy from Hot Car #shorts
00:22
Fabiosa Best Lifehacks
Рет қаралды 21 МЛН
когда повзрослела // EVA mash
00:40
EVA mash
Рет қаралды 4,5 МЛН
Mikrotik Real World Tips
46:35
MikroTik
Рет қаралды 21 М.
Diving deep into RouterOS: Switching
40:12
MikroTik
Рет қаралды 37 М.
VLAN processing in New bridge implementation
38:24
MikroTik
Рет қаралды 40 М.
OSPF Deep Dive
2:26:28
Kevin Wallace Training, LLC
Рет қаралды 203 М.
Managed MikroTik Solutions for Home Networks
48:21
MikroTik
Рет қаралды 3,9 М.
Network Time Protocol (NTP) - Computerphile
10:41
Computerphile
Рет қаралды 178 М.
BGP Made Easy
1:05:43
NANOG
Рет қаралды 32 М.
Mastering VLAN Configuration on MikroTik, Step-by-Step Guide
34:56
The Network Berg
Рет қаралды 66 М.
TCP Fundamentals Part 1 // TCP/IP Explained with Wireshark
1:17:24
Chris Greer
Рет қаралды 422 М.
Connecting all CAPs to the MikroTik CAPsMAN
21:15
MAICT
Рет қаралды 73 М.
Mastering Picture Editing: Zoom Tools Tutorial
0:52
Photoo Edit
Рет қаралды 507 М.
Хотела заскамить на Айфон!😱📱(@gertieinar)
0:21
Взрывная История
Рет қаралды 6 МЛН
Игровой Комп с Авито за 4500р
1:00
ЖЕЛЕЗНЫЙ КОРОЛЬ
Рет қаралды 2,2 МЛН
Battery  low 🔋 🪫
0:10
dednahype
Рет қаралды 3,8 МЛН