Configure Port-Knocking in RouterOS.
Port knocking is a method of establishing a connection to a networked device that has no open ports.
Before a connection is established, ports are opened using a port knock sequence, which is a series of connection attempts to closed ports.
A remote host generates and sends an authentic knock sequence in order to manipulate device firewall rules to open one or more specific ports.
Once the desired ports are opened, the remote host can establish a connection and begin a session (in this example, SSH will be available after issuing the correct Knocking Sequence to a RouterOS Based Router).
Optionally, another knock sequence may used to trigger the closing of the previously enabled port.
In this example Address-Lists are created with a validity of 15s, so the knocking sequence needs to be issued quite fast.Before a connection is established, ports are opened using a port knock sequence, which is a series of connection attempts to closed ports.
A remote host generates and sends an authentic knock sequence in order to manipulate device firewall rules to open one or more specific ports.
Once the desired ports are opened, the remote host can establish a connection and begin a session (in this example, SSH will be available after issuing the correct Knocking Sequence to a RouterOS Based Router).
Optionally, another knock sequence may used to trigger the closing of the previously enabled port.
|
Better security will be granted using a sequence with decreasing port number and different protocols (to avoid basic Port Scans).
Example: 30001/TCP -> 2001/UDP -> 101/TCP => Open 22/TCP.
fonte: https://blog.bravi.org/?p=634#more-634






0 comentários:
Postar um comentário