0% found this document useful (0 votes)
28 views32 pages

Secure Your MikroTik RouterOS Guide

This document provides guidelines for securing a MikroTik RouterOS router, including keeping the router software updated, securing user passwords and physical access, disabling unused packages and services, loading a firewall, enabling logging, syncing the time, and taking additional miscellaneous security steps like static DHCP leases and backup encryption.

Uploaded by

Candra Powit
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
28 views32 pages

Secure Your MikroTik RouterOS Guide

This document provides guidelines for securing a MikroTik RouterOS router, including keeping the router software updated, securing user passwords and physical access, disabling unused packages and services, loading a firewall, enabling logging, syncing the time, and taking additional miscellaneous security steps like static DHCP leases and backup encryption.

Uploaded by

Candra Powit
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

sahoobi.

com
Securing RouterOS router
EASY GUIDELINE TO PROTECT YOUR MIKROTIK ROUTEROS ROUTER
Me:
Anuwat Ngowchieng
อนุวัตร โง้วเชียง
[Link]
Consulting Engineer
Internet Thailand Public Company Limited (INET)
too101@[Link]
Certificate:
◦ MikroTik: MCTNA, MTCWE
◦ Microsoft: MCP, MCSA, MCSE
◦ VMWare: VCP5-DCV
Why ?

[Link]
Why ?
Prevent un-authorized people to access to the
system

[Link]
Intruder can steal information from you, or
even deny you access to your resources
Intruder can use your resources to access to
the other system
Why ?

[Link]
How ?
Keeping router up-to-date
Securing user & password
[Link]
Securing physical access
Configuring packages
Hardening services
How ? (continue)
Loading firewall
Logging
[Link]
NTP Sync
Misc
Keeping router up-to-date

[Link]
Keeping router up-to-date
Use current version
Check Changelog before upgrade

[Link]
to newer version
Download from trusted source
Check file (MD5) when
download from third party site
Keeping router up-to-date

[Link]
Keeping router up-to-date

[Link]
Securing user & password
Change admin account name
Set complex password

[Link] Create separate account for each


user
Set allowed address
Put read-only user in “read”
group
Securing user & password

[Link]
Securing physical access
Disable Console (optional)
Always logout console

[Link] session
Disable Unused interface
Don’t config unused
interface (optional)
Securing physical access

[Link]
Configuring packages
Disable unused packages
Check packages installed
[Link]
Check version of each package
Configuring packages

[Link]
Hardening services
Disable unsecured service (Ex. Telnet)
Change service port (optional)
[Link]
Disable unused service
Define access lists for each service
Hardening services

[Link]
Hardening services

[Link]
Loading firewall
Loading up a firewall will add layer of security
Setup port knocking (optional)
[Link]
Loading firewall

[Link]
Loading firewall

[Link]
Logging
Monitor log
Log to disk (Default RouterOS log to memory)
[Link]
Send log to syslog server
Logging

[Link]
NTP sync
Set time zone
Sync time with NTP server or IP cloud service
[Link]
NTP sync

[Link]
NTP sync

[Link]
NTP sync

[Link]
Misc
Static DHCP lease
Wi-Fi security
[Link]
Backup config with password encrypted
Block Winbox Discovery
Disable Network Neighbor Discovery
Reference:
[Link]
[Link]

[Link]
[Link]
[Link]
prevent-mt-host-from-invalid-login-attempts-from-lanwan-users/
[Link]
[Link]
Thank you

You might also like