Comment on Am I doing this (networking) safely?

<- View Parent
redlemace@lemmy.world ⁨1⁩ ⁨day⁩ ago

I’m using RouterOS. In the firewall rules you can create a rule that if an IP touches a port, it get added to a address list (optional with a time-out). So my FW rules begin like this:

  1. If source is whitelisted, Accept
  2. If source IP is in the blacklist, drop all
  3. if source IP tries to connect to port 21,22,25,137-139, 113 (and a bunch of others) add it to the blacklist

This too has endless possibilities. t.ex. like port knocking. (‘touch’ one or more ports in a specified sequence in a specified time to be allowed to access the actual service port)

source
Sort:hotnewtop