CRS326-24G-2S+RM : FW question

Notice: Page may contain affiliate links for which we may earn a small commission through services like Amazon Affiliates or Skimlinks.

Draky

New Member
Feb 26, 2021
5
0
1
Hello,
(skip to below question if you don't want to read this story)
I recently purchased a CRS326-24G-2S+RM and am running it with RouterOS v6.48.1(stable) and installed it within my home network. I have a home server and use the 10gig sfp+ port with the server (yes, way over built but it makes me happy). Anyway, last night I attempted to log into the switch, I had no password on the device and left it with the admin name, I never had to worry before as I'm just a home user, but I couldn't log in due to a password. I reset the device and set up the config but as I was setting it up I noticed the "Terminal" or console was showing someone attempting to log in. This time I had added a password so they didn't get in. I then put the ip on the firewall to drop and moved on and finished my basic config using only DHCP-server (for my devices) + this firewall. I then went back to the console and saw a few other IP's attempting to log in. Long story short, I notice that they keep attempting to log in with different IP's from around the world (see below screen shot for an example) and I keep adding it to the firewall (a screenshot below, I did clear the stat before I went to bed to see what would happen).

Question: Is there any way to drop the ability to log into the switch completely from the Ethernet1 (WAN)? I'll always log in locally as it's a home device.

As always, I thank you greatly in advance for any help!

Screen Shot 2021-03-01 at 5.30.38 AM.png
Screen Shot 2021-03-01 at 5.34.43 AM.png
 

Draky

New Member
Feb 26, 2021
5
0
1
I built these and they seem to be working. Is there any other ports I should look at adding? I'm thinking maybe some Mikrotik api port that isn't listed here or may be obscure?
Screen Shot 2021-03-01 at 7.16.05 AM.png
 

Antonio

Member
Dec 20, 2015
42
13
8
It looks like you are using webfig
http://CRS326-24G-2S+RM-networkip/webfig/#IP:Firewall.Service_Ports

all should be disabled.

http://CRS326-24G-2S+RM-networkip/webfig/#IP:Services

all enabled services should only be accessible from your lan (available from your lan subnet)and preferably only from your admin system (available only from your admin pc's ip address).

in winfig.

the same configuration changes would be in ip/firewall/service ports and ip/services.

the same configuration changes in terminal would occur in

/ip firewall service-port set ftp disabled=yes ports=21
/ip service set winbox address=192.168.88.0/24 disabled=no port=8291
 
  • Like
Reactions: Draky

Draky

New Member
Feb 26, 2021
5
0
1
Hi Antonio,

Thank you for the reply, and yes this was via the web UI. I typically prefer CLI but their commands are so different from the Cisco and Juniper I use that rather than searching I just am using the web UI.

I greatly appreciate your input!