securing routeros router

32
Securing RouterOS router EASY GUIDELINE TO PROTECT YOUR MIKROTIK ROUTEROS ROUTER

Upload: hanhan

Post on 01-Jan-2017

266 views

Category:

Documents


8 download

TRANSCRIPT

Page 1: Securing RouterOS router

Securing RouterOS routerEASY GUIDELINE TO PROTECT YOUR MIKROTIK ROUTEROS ROUTER

Page 2: Securing RouterOS router

Me:

Anuwat Ngowchiengอนุวัตร โง้วเชียงConsulting Engineer

Internet Thailand Public Company Limited (INET)

[email protected]

Certificate:◦ MikroTik: MCTNA, MTCWE◦ Microsoft: MCP, MCSA, MCSE◦ VMWare: VCP5-DCV

Page 3: Securing RouterOS router

Why ?

Page 4: Securing RouterOS router

Why ?

Prevent un-authorized people to access to the system

Intruder can steal information from you, or even deny you access to your resources

Intruder can use your resources to access to the other system

Page 5: Securing RouterOS router

Why ?

Page 6: Securing RouterOS router

How ?

Keeping router up-to-date

Securing user & password

Securing physical access

Configuring packages

Hardening services

Page 7: Securing RouterOS router

How ? (continue)

Loading firewall

Logging

NTP Sync

Misc

Page 8: Securing RouterOS router

Keeping router up-to-date

Page 9: Securing RouterOS router

Keeping router up-to-dateUse current version

Check Changelog before upgrade to newer version

Download from trusted source

Check file (MD5) when download from third party site

Page 10: Securing RouterOS router

Keeping router up-to-date

Page 11: Securing RouterOS router

Keeping router up-to-date

Page 12: Securing RouterOS router

Securing user & passwordChange admin account name

Set complex password

Create separate account for each user

Set allowed address

Put read-only user in “read” group

Page 13: Securing RouterOS router

Securing user & password

Page 14: Securing RouterOS router

Securing physical accessDisable Console (optional)

Always logout console session

Disable Unused interface

Don’t config unused interface (optional)

Page 15: Securing RouterOS router

Securing physical access

Page 16: Securing RouterOS router

Configuring packages

Disable unused packages

Check packages installed

Check version of each package

Page 17: Securing RouterOS router

Configuring packages

Page 18: Securing RouterOS router

Hardening services

Disable unsecured service (Ex. Telnet)

Change service port (optional)

Disable unused service

Define access lists for each service

Page 19: Securing RouterOS router

Hardening services

Page 20: Securing RouterOS router

Hardening services

Page 21: Securing RouterOS router

Loading firewall

Loading up a firewall will add layer of security

Setup port knocking (optional)

Page 22: Securing RouterOS router

Loading firewall

Page 23: Securing RouterOS router

Loading firewall

Page 24: Securing RouterOS router

Logging

Monitor log

Log to disk (Default RouterOS log to memory)

Send log to syslog server

Page 25: Securing RouterOS router

Logging

Page 26: Securing RouterOS router

NTP sync

Set time zone

Sync time with NTP server or IP cloud service

Page 27: Securing RouterOS router

NTP sync

Page 28: Securing RouterOS router

NTP sync

Page 29: Securing RouterOS router

NTP sync

Page 30: Securing RouterOS router

Misc

Static DHCP lease

Wi-Fi security

Backup config with password encrypted

Block Winbox Discovery

Disable Network Neighbor Discovery

Page 31: Securing RouterOS router

Reference:http://wiki.mikrotik.com/wiki/Securing_New_RouterOs_Router

http://wiki.mikrotik.com/wiki/Securing_your_router

http://www.slideshare.net/akbarazwir/portknock

https://aacable.wordpress.com/2011/08/15/mikrotik-howto-prevent-mt-host-from-invalid-login-attempts-from-lanwan-users/

http://www.sysnetcenter.com/board/index.php?topic=2204.0

Page 32: Securing RouterOS router

Thank you