Semua ada Ilmunya

Simple IDS buat mencegah Port Scanning (MikroTik Version)

Buat Rekam Port Scanners
chain=input protocol=tcp psd=21,3s,3,1 action=add-src-to-address-list
address-list=port-scanners address-list-timeout=148w5d16h

Buat rekam SYN/FIN Scan
chain=input protocol=tcp tcp-flags=fin,syn
action=add-src-to-address-list address-list=port-scanners
address-list-timeout=148w5d16h

Buat Rekam SYN/RST Scan
chain=input protocol=tcp tcp-flags=syn,rst
action=add-src-to-address-list address-list=port-scanners
address-list-timeout=148w5d16h

Buat Rekam FIN/PSH/URG Scan
chain=input protocol=tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack
action=add-src-to-address-list address-list=port-scanners
address-list-timeout=148w5d16h


Buat Rekam Semua Scan
chain=input protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg
action=add-src-to-address-list address-list=port-scanners
address-list-timeout=148w5d16h

Buat Rekam NMAP Null Scan
chain=input protocol=tcp tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg
action=add-src-to-address-list address-list=port-scanners
address-list-timeout=148w5d16h

Sumber : Forum X-CODE

0 comment:

Posting Komentar