Conceito de Firewall Mikrotik
Conceito de Firewall Mikrotik
Conceito de Firewall Mikrotik
7 APLICAÇÃO APLICAÇÃO
DADOS
6 APRESENTAÇÃO HTTP, HTTPS 5
DNS, DHCP, FTP
5 SESSÃO SSH, TELNET
https://wiki.mikrotik.com/wiki/Manual:Packet_Flow
Fluxo de Pacotes em Blocos Simples
In-Interface - Decapsulate
Out-Interface - Encapsulate
Decisões Expandidas
Chains (corrente) de Fluxo dos Pacotes
Fluxo dos Pacotes IP Completo
FORWARD
PRE POST
ROUTING INPUT OUTPUT ROUTING
ROUTING
MANGLE MANGLE
DST-NAT ADJUSTA-
INPUT MENT POSTROUTING
TO IN LOCAL ROUTING
QUEUE TREE
PROCESS TO OUT DECISION INTERFACE HTB
INPUT OUTPUT
INTERFACE INTERFACE
Tabelas em /ip firewall
PRE POST
ROUTING INPUT OUTPUT ROUTING
ROUTING
MANGLE MANGLE
DST-NAT ADJUSTA-
INPUT MENT POSTROUTING
TO IN LOCAL ROUTING
QUEUE TREE
PROCESS TO OUT DECISION INTERFACE HTB
INPUT OUTPUT
INTERFACE INTERFACE
/ip firewall filter add chain=
FORWARD
INPUT OUTPUT
OUTPUT INPUT
FORWARD
Src: 192.168.10.10
Dst: 192.168.20.20
192.168.10.10/24 192.168.20.20/24
Src: 192.168.20.20
Dst: 192.168.10.10
Conexão Estabelecida
Fluxo de Pacotes Connection Tracking
FORWARD
PRE POST
ROUTING INPUT OUTPUT ROUTING
ROUTING
MANGLE MANGLE
DST-NAT ADJUSTA-
INPUT MENT POSTROUTING
TO IN LOCAL ROUTING
QUEUE TREE
PROCESS TO OUT DECISION INTERFACE HTB
INPUT OUTPUT
INTERFACE INTERFACE
/ip firewall nat add chain=
Fluxo de Pacotes src-nat e dst-nat
FORWARD
PRE POST
ROUTING INPUT OUTPUT ROUTING
ROUTING
MANGLE MANGLE
DST-NAT ADJUSTA-
INPUT MENT POSTROUTING
TO IN LOCAL ROUTING
QUEUE TREE
PROCESS TO OUT DECISION INTERFACE HTB
INPUT OUTPUT
INTERFACE INTERFACE
/ip firewall nat add chain=srcnat
192.168.1.1/24
192.168.1.2:80 177.1.1.1:5781
200.1.1.1:80
/ip firewall nat add chain=dstnat
DICA
Objetivo
PRE POST
ROUTING INPUT OUTPUT ROUTING
ROUTING
MANGLE MANGLE
DST-NAT ADJUSTA-
INPUT MENT POSTROUTING
TO IN LOCAL ROUTING
QUEUE TREE
PROCESS TO OUT DECISION INTERFACE HTB
INPUT OUTPUT
INTERFACE INTERFACE
Camada 3, Rede - Cabeçalho IPv4
Fluxo de Pacotes TTL-1
FORWARD
PRE POST
ROUTING INPUT OUTPUT ROUTING
ROUTING
MANGLE MANGLE
DST-NAT ADJUSTA-
INPUT MENT POSTROUTING
TO IN LOCAL ROUTING
QUEUE TREE
PROCESS TO OUT DECISION INTERFACE HTB
INPUT OUTPUT
INTERFACE INTERFACE
/ip firewall mangle set action=change-ttl
Objetivo
• Não redistribuir Internet ao acrescentar um novo Router DICA
TTL = 2 TTL = 1
1 2 3
TTL = 1
1 2
/ip firewall raw add chain=
Fluxo de Pacotes Raw
FORWARD
PRE POST
ROUTING INPUT OUTPUT ROUTING
ROUTING
MANGLE MANGLE
DST-NAT ADJUSTA-
INPUT MENT POSTROUTING
TO IN LOCAL ROUTING
QUEUE TREE
PROCESS TO OUT DECISION INTERFACE HTB
INPUT OUTPUT
INTERFACE INTERFACE
/ip firewall raw set action=drop
DICA
Objetivos
Comandos
Objetivos
Comandos
Objetivos
Comandos
/ip firewall raw
Objetivo
• Bloquear Prefixos BOGONS
/ip firewall address-list
add address=0.0.0.0/8 comment="Auto Identificacao" list=BOGONS
add address=10.0.0.0/8 comment="Privada - Verifique se voce necessita" \
disabled=yes list=BOGONS
add address=127.0.0.0/8 comment=Loopback list=BOGONS
add address=169.254.0.0/16 comment="Link Local - APIPA" list=BOGONS
add address=172.16.0.0/12 comment="Privada - Verifique se voce necessita" \
disabled=yes list=BOGONS
add address=192.168.0.0/16 comment="Privada - Verifique se voce necessita" \
disabled=yes list=BOGONS
add address=192.0.2.0/24 comment="Reservada - TestNet1" list=BOGONS
add address=192.88.99.0/24 comment="6to4 Relay Anycast" list=BOGONS
add address=198.18.0.0/15 comment="Teste NIDB" list=BOGONS
add address=198.51.100.0/24 comment="Reservada - TestNet2" list=BOGONS
add address=203.0.113.0/24 comment="Reservada - TestNet3" list=BOGONS
add address=224.0.0.0/4 comment="Multicast - Verifique se voce necessita" \
disabled=yes list=BOGONS
/ip firewall raw
add action=drop chain=prerouting comment="dst BOGONS" dst-address-list=BOGONS
*
Crédito
https://www.mikrotik-trainings.com/docs#form
Conteúdo Abordado
João Krieger
48 9-9982-8707
[email protected]
Treinamentos
Curso
Introdutório
Roteamento
Avançado
OSPF e Túneis