<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title>Mikrotik.moscow [тема: Правила фильтрации брандмауэра и результаты сканирования nmap.]</title>
		<link>http://mikrotik.moscow</link>
		<description>Новое в теме Правила фильтрации брандмауэра и результаты сканирования nmap. форума RouterOS на сайте Mikrotik.moscow [mikrotik.moscow]</description>
		<language>ru</language>
		<docs>http://backend.userland.com/rss2</docs>
		<pubDate>Sun, 16 Aug 2026 13:40:40 -0400</pubDate>
		<item>
			<title>Правила фильтрации брандмауэра и результаты сканирования nmap.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236622">Правила фильтрации брандмауэра и результаты сканирования nmap.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Используй силу анализа сетевых пакетов, Люк! Wireshark — мой лучший инструмент для копания в любых сетевых проблемах/вопросах. #1 <br />
			<i>29.01.2014 16:21:00, CblP.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236622</link>
			<guid>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236622</guid>
			<pubDate>Wed, 29 Jan 2014 16:21:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Правила фильтрации брандмауэра и результаты сканирования nmap.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236621">Правила фильтрации брандмауэра и результаты сканирования nmap.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Просто ради прикола просканировал внутренний адрес с помощью nmap. <br />
			<i>24.01.2014 22:28:00, lambert.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236621</link>
			<guid>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236621</guid>
			<pubDate>Fri, 24 Jan 2014 22:28:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Правила фильтрации брандмауэра и результаты сканирования nmap.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236620">Правила фильтрации брандмауэра и результаты сканирования nmap.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Еще один мой вклад. PPPoE-соединение установлено через ADSL-модем Draytek Vigor 120v2. Может ли это устройство иметь какое-то отношение к открытым портам? <br />
			<i>14.01.2014 20:02:00, Toby7.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236620</link>
			<guid>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236620</guid>
			<pubDate>Tue, 14 Jan 2014 20:02:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Правила фильтрации брандмауэра и результаты сканирования nmap.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236619">Правила фильтрации брандмауэра и результаты сканирования nmap.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Тест namp -sT сейчас показывает другой результат:<br />PORT &nbsp; &nbsp; STATE SERVICE<br />25/tcp &nbsp; open &nbsp;smtp<br />80/tcp &nbsp; open &nbsp;http<br />110/tcp &nbsp;open &nbsp;pop3<br />143/tcp &nbsp;open &nbsp;imap<br />993/tcp &nbsp;open &nbsp;imaps<br />8080/tcp open &nbsp;http-proxy<br /><br />Меньше открытых портов, но всё ещё нет объяснения, почему они открыты… Изменений в routing-marks и т.п. не вносилось. <br />
			<i>12.01.2014 23:16:00, Toby7.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236619</link>
			<guid>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236619</guid>
			<pubDate>Sun, 12 Jan 2014 23:16:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Правила фильтрации брандмауэра и результаты сканирования nmap.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236618">Правила фильтрации брандмауэра и результаты сканирования nmap.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Попробую ещё раз завтра. Обычно открытые порты всё равно видны… Хм, странно, если маршрутизация влияет на открытые порты файрвола. Может, в nmap какой-то баг, из-за которого показываются якобы открытые порты, которые на самом деле невидимы? <br />
			<i>11.01.2014 19:18:00, Toby7.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236618</link>
			<guid>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236618</guid>
			<pubDate>Sat, 11 Jan 2014 19:18:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Правила фильтрации брандмауэра и результаты сканирования nmap.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236617">Правила фильтрации брандмауэра и результаты сканирования nmap.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Я не вижу ничего, что говорило бы о проблеме. Ты все еще видишь лишние порты, когда сканируешь свой IP A.B.C.14 с помощью nmap? Я не использую routing-marks, так что это, вероятно, какой-то побочный эффект. Прости, но я, кажется, исчерпал все идеи. <br />
			<i>10.01.2014 06:53:00, lambert.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236617</link>
			<guid>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236617</guid>
			<pubDate>Fri, 10 Jan 2014 06:53:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Правила фильтрации брандмауэра и результаты сканирования nmap.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236616">Правила фильтрации брандмауэра и результаты сканирования nmap.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Команда nmap — nmap -sT, как ты и сказал.<br /><br />/ip address print<br />ADDRESS &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;NETWORK &nbsp; &nbsp; &nbsp; &nbsp; INTERFACE<br />0 &nbsp; 192.168.0.254/24 &nbsp; 192.168.0.0 &nbsp; &nbsp; ether2_homenet<br />1 &nbsp; 192.168.128.254/24 192.168.128.0 &nbsp; ether3_telekom<br />2 &nbsp; 10.0.128.254/24 &nbsp; &nbsp;10.0.128.0 &nbsp; &nbsp; &nbsp;vlan100_ether5<br />3 &nbsp; 10.0.192.254/24 &nbsp; &nbsp;10.0.192.0 &nbsp; &nbsp; &nbsp;vlan200_ether5<br />4 D 192.168.179.21/24 &nbsp;192.168.179.0 &nbsp; ether1_fritzbox<br />5 D A.B.C.14/32 &nbsp; &nbsp;	F.G.H.165 &nbsp;		PPPoE-TelekomDSL<br /><br />/ip route export add check-gateway=ping distance=1 gateway=PPPoE-TelekomDSL routing-mark=WANTelekom<br />add distance=1 dst-address=192.168.0.0/24 gateway=ether2_homenet routing-mark=WANTelekom<br />add distance=1 dst-address=192.168.128.0/24 gateway=ether3_telekom routing-mark= WANTelekom<br />add distance=1 gateway=192.168.179.1 routing-mark= fromFreyPV<br />add check-gateway=ping distance=1 gateway= 192.168.179.1 routing-mark=fromflyingEllertGuest<br />add distance=1 dst-address=A.B.C.14/32 gateway=192.168.0.240 routing-mark=table_PenetrationTesting<br />add check-gateway=ping distance=1 gateway=192.168.0.240<br />add check-gateway=ping distance=5 gateway= PPPoE-TelekomDSL<br /><br />/ip route rule add action=drop dst-address=192.168.0.0/24 src-address=10.0.128.0/24<br />add action=drop dst-address=192.168.128.0/24 src-address= 10.0.128.0/24<br />add action=drop dst-address=10.0.192.0/24 src-address=10.0.128.0/24<br />add dst-address=192.168.128.0/24 src-address=192.168.0.0/24 table=main<br />add action=drop disabled=yes dst-address=192.168.0.0/24 src-address= 10.0.192.0/24<br />add action=drop disabled=yes dst-address=192.168.0.0/24 src-address=10.0.192.0/24<br /><br />Я не знаю ничего о VRF, поэтому их не использую. Очередей нет! <br />
			<i>09.01.2014 17:18:00, Toby7.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236616</link>
			<guid>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236616</guid>
			<pubDate>Thu, 09 Jan 2014 17:18:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Правила фильтрации брандмауэра и результаты сканирования nmap.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236615">Правила фильтрации брандмауэра и результаты сканирования nmap.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Похоже, я забыл попросить тебя выдать IP-адрес. А какая команда nmap ты использовал? `nmap -sT A.B.C.14`? Кажется, ты используешь маршрутизацию. Можешь показать нам вывод `/ip route export`? Ты пытаешься изолировать адресное пространство (VRF) или пытаешься настроить ограничение скорости (очереди)? Я пока мало работал с VRF. <br />
			<i>09.01.2014 08:20:00, lambert.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236615</link>
			<guid>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236615</guid>
			<pubDate>Thu, 09 Jan 2014 08:20:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Правила фильтрации брандмауэра и результаты сканирования nmap.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236614">Правила фильтрации брандмауэра и результаты сканирования nmap.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Вот переведенный текст:<br /><br />Вот список экспортируемых настроек:<br />/interface print<br />NAME &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;TYPE &nbsp; &nbsp; &nbsp; &nbsp; MTU L2MTU &nbsp;MAX-L2MTU MAC-ADDRESS<br />0 &nbsp;R &nbsp;ether1_fritzbox &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ether &nbsp; &nbsp; &nbsp; 1500 &nbsp;1598 &nbsp; &nbsp; &nbsp; 4074 00:0C:42:C1:F9:9D<br />1 &nbsp;R &nbsp;ether2_homenet &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;ether &nbsp; &nbsp; &nbsp; 1500 &nbsp;1598 &nbsp; &nbsp; &nbsp; 4074 00:0C:42:C1:F9:9E<br />2 &nbsp;R &nbsp;ether3_telekom &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;ether &nbsp; &nbsp; &nbsp; 1500 &nbsp;1598 &nbsp; &nbsp; &nbsp; 4074 00:0C:42:C1:F9:9F<br />3 &nbsp;R &nbsp;ether4_modem_telekom &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;ether &nbsp; &nbsp; &nbsp; 1500 &nbsp;1598 &nbsp; &nbsp; &nbsp; 4074 00:0C:42:C1:F9:A0<br />4 &nbsp;R &nbsp;;;; ::: VLAN Trunk ::: ether5_trunk &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;ether &nbsp; &nbsp; &nbsp; 1500 &nbsp;1598 &nbsp; &nbsp; &nbsp; 4074 00:0C:42:C1:F9:A1<br />5 &nbsp;R &nbsp;PPPoE-TelekomDSL &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;pppoe-out &nbsp; 1480<br />6 &nbsp;R &nbsp;vlan1_ether5 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;vlan &nbsp; &nbsp; &nbsp; &nbsp;1500 &nbsp;1594 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;00:0C:42:C1:F9:A1<br />7 &nbsp;R &nbsp;vlan100_ether5 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;vlan &nbsp; &nbsp; &nbsp; &nbsp;1500 &nbsp;1594 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;00:0C:42:C1:F9:A1<br />8 &nbsp;R &nbsp;vlan200_ether5 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;vlan &nbsp; &nbsp; &nbsp; &nbsp;1500 &nbsp;1594 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;00:0C:42:C1:F9:A1<br />/ip address add address=192.168.0.254/24 interface=ether2_homenet network=192.168.0.0<br />add address=192.168.128.254/24 &nbsp;interface=ether3_telekom network=192.168.128.0<br />add address=10.0.128.254/24 interface=vlan100_ether5 network=10.0.128.0<br />add address=10.0.192.254/24 &nbsp;interface=vlan200_ether5 network=10.0.192.0<br />/ip firewall export<br />/ip firewall address-list add address=192.168.128.0/24 list=local-addresses<br />add address=192.168.0.0/24 &nbsp;list=local-addresses<br />add address=10.0.192.0/24 &nbsp;list=local-addresses<br />add address=10.0.128.0/24 list=local-addresses<br />add address=192.168.128.0/24 list=“Telekom Subnet”<br />add address=192.168.0.0/24 list=“E Homenet Subnet”<br />add address=10.0.192.0/24 list=“F PV Subnet”<br />add address=10.0.128.0/24 list=“Guest WLAN Subnet”<br />add address=192.168.0.119 list=addressList_PenetrationTesting<br />add address=A.B.C.14 list=addressList_WANIPTelekom<br />/ip firewall filter add action=drop chain=input connection-state=invalid in-interface=PPPoE-TelekomDSL<br />add action=drop chain=forward connection-state=invalid in-interface=PPPoE-TelekomDSL<br />add chain=input connection-state=established in-interface=PPPoE-TelekomDSL<br />add action=drop chain=input in-interface=PPPoE-TelekomDSL<br />add chain=forward connection-state=new in-interface=PPPoE-TelekomDSL src-address-list=“Telekom Subnet”<br />add chain=forward connection-state=related in-interface=PPPoE-TelekomDSL<br />add chain=forward connection-state=established in-interface=PPPoE-TelekomDSL<br />add action=drop chain=forward in-interface=PPPoE-TelekomDSL<br />/ip firewall mangle add chain=prerouting dst-address-list=local-addresses dst-address-type=“” fragment=no add action=mark-routing<br />chain=prerouting dst-address-list=addressList_WANIPTelekom new-routing-mark=table_PenetrationTesting passthrough=no src-address-list=addressList_PenetrationTesting<br />add action=mark-routing chain=prerouting &nbsp;new-routing-mark=WANTelekom passthrough=no src-address-list=“Telekom Subnet”<br />add action=mark-routing chain=prerouting &nbsp;new-routing-mark=fromFPV passthrough=no src-address-list=“F PV Subnet”<br />add action=mark-routing chain=prerouting &nbsp;new-routing-mark= fromflyingEGuest passthrough=no src-address-list=“Guest WLAN Subnet”<br />add action=mark-routing chain=prerouting &nbsp;in-interface=PPPoE-TelekomDSL new-routing-mark=WANTelekom passthrough=no<br />/ip firewall nat add action=masquerade chain=srcnat &nbsp;out-interface=PPPoE-TelekomDSL src-address=192.168.128.0/24<br />add action=masquerade chain=srcnat &nbsp;out-interface=PPPoE-TelekomDSL src-address= 192.168.0.0/24<br />/ip route print<br />DST-ADDRESS &nbsp; &nbsp; &nbsp; &nbsp;PREF-SRC &nbsp; &nbsp; &nbsp; &nbsp;GATEWAY &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;DISTANCE<br />0 A S &nbsp;0.0.0.0/0 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;PPPoE-TelekomDSL &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1<br />1 A S &nbsp;192.168.0.0/24 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ether2_homenet &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1<br />2 A S &nbsp;192.168.128.0/24 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ether3_telekom &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1<br />3 A S &nbsp;0.0.0.0/0 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;192.168.179.1 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 1<br />4 A S &nbsp;0.0.0.0/0 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;192.168.179.1 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 1<br />5 A S &nbsp;A.B.C.14/32 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;	 &nbsp; 192.168.0.240 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 1<br />6 A S &nbsp;0.0.0.0/0 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;192.168.0.240 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 1<br />7 &nbsp; S &nbsp;0.0.0.0/0 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;PPPoE-TelekomDSL &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;5<br />8 ADC &nbsp;10.0.128.0/24 &nbsp; &nbsp; &nbsp;10.0.128.254 &nbsp; &nbsp;vlan100_ether5 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0<br />9 ADC &nbsp;10.0.192.0/24 &nbsp; &nbsp; &nbsp;10.0.192.254 &nbsp; &nbsp;vlan200_ether5 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0<br />10 ADC &nbsp;F.G.H.165/32 &nbsp;		A.B.C.14 &nbsp;		PPPoE-TelekomDSL &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0<br />11 ADC &nbsp;192.168.0.0/24 &nbsp; &nbsp; 192.168.0.254 &nbsp; ether2_homenet &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0<br />12 ADC &nbsp;192.168.128.0/24 &nbsp; 192.168.128.254 ether3_telekom &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0<br />13 ADC &nbsp;192.168.179.0/24 &nbsp; 192.168.179.21 &nbsp;ether1_fritzbox &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0<br />IP-адрес моей машины для сканирования сети — 192.168.0.119, подключена к ether2_homenet. <br />
			<i>06.01.2014 23:08:00, Toby7.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236614</link>
			<guid>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236614</guid>
			<pubDate>Mon, 06 Jan 2014 23:08:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Правила фильтрации брандмауэра и результаты сканирования nmap.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236613">Правила фильтрации брандмауэра и результаты сканирования nmap.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Чтобы перестать гадать и разобраться, нам нужно увидеть вывод команд /interface print, /ip address export, /ip firewall export, /ip firewall print, /ip mangle print, /ip route print. Потом сообщите нам IP-адрес вашей машины Nmap, физический порт на Mikrotik, к которому подключена ваша машина Nmap, и целевой IP-адрес, который вы тестируете, и повторите запуск Nmap. Вы можете заменить первые два октета любого публичного IP-адреса буквами, при условии, что это будет однозначная замена октетов, которые они заменяют. <br />
			<i>06.01.2014 06:36:00, lambert.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236613</link>
			<guid>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236613</guid>
			<pubDate>Mon, 06 Jan 2014 06:36:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Правила фильтрации брандмауэра и результаты сканирования nmap.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236612">Правила фильтрации брандмауэра и результаты сканирования nmap.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Нет, просто включены порты сервиса через брандмауэр. Я думал, что это своего рода NAT-хелперы, отключать которые лучше не стоит. Сканирование направлено на локальный адрес PPPoe-клиента. Насколько я знаю, это WAN IP? Для сканирования я использовал tethering через Android (мобильная сеть) в качестве интернет-соединения. Может ли это как-то повлиять? <br />
			<i>05.01.2014 14:22:00, Toby7.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236612</link>
			<guid>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236612</guid>
			<pubDate>Sun, 05 Jan 2014 14:22:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Правила фильтрации брандмауэра и результаты сканирования nmap.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236611">Правила фильтрации брандмауэра и результаты сканирования nmap.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Есть ли у тебя правила переадресации портов, NAT? Если нет, то, возможно, ты сканируешь неверный IP-адрес. Это “” — адрес, назначенный твоему интерфейсу PPPoE-TelekomDSL или LAN IP? <br />
			<i>05.01.2014 05:05:00, lambert.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236611</link>
			<guid>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236611</guid>
			<pubDate>Sun, 05 Jan 2014 05:05:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Правила фильтрации брандмауэра и результаты сканирования nmap.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236610">Правила фильтрации брандмауэра и результаты сканирования nmap.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Привет, сейчас работаю над улучшением файрвола. У меня PPPoE-соединение с моим провайдером. Роутер сконфигурирован как source NAT с правилами фильтрации. Сейчас у меня только базовые правила фильтрации, которые рекомендуются в книге “Router OS by example”.<br /><br />0 &nbsp; ;;; ###<br /> &nbsp; &nbsp; chain=input action=drop connection-state=invalid<br /> &nbsp; &nbsp; in-interface=PPPoE-TelekomDSL<br /><br />1 &nbsp; ;;; ###<br /> &nbsp; &nbsp; chain=forward action=drop connection-state=invalid<br /> &nbsp; &nbsp; in-interface=PPPoE-TelekomDSL<br /><br />2 &nbsp; ;;; ###<br /> &nbsp; &nbsp; chain=input action=accept connection-state=established<br /> &nbsp; &nbsp; in-interface=PPPoE-TelekomDSL<br /><br />3 &nbsp; ;;; ###<br /> &nbsp; &nbsp; chain=input action=drop in-interface=PPPoE-TelekomDSL<br /><br />4 &nbsp; ;;; ###<br /> &nbsp; &nbsp; chain=forward action=accept connection-state=new<br /> &nbsp; &nbsp; src-address-list=Telekom Subnet in-interface=PPPoE-TelekomDSL<br /><br />5 &nbsp; ;;; ###<br /> &nbsp; &nbsp; chain=forward action=accept connection-state=related<br /> &nbsp; &nbsp; in-interface=PPPoE-TelekomDSL<br /><br />6 &nbsp; ;;; ###<br /> &nbsp; &nbsp; chain=forward action=accept connection-state=established<br /> &nbsp; &nbsp; in-interface=PPPoE-TelekomDSL<br /><br />7 &nbsp; ;;; ###<br /> &nbsp; &nbsp; chain=forward action=drop in-interface=PPPoE-TelekomDSL<br /><br />Для проверки настроек использую nmap. Если запускаю nmap -sT, получаю такой вывод:<br /><br />PORT &nbsp; &nbsp; STATE SERVICE<br />25/tcp &nbsp; open &nbsp;smtp<br />80/tcp &nbsp; open &nbsp;http<br />110/tcp &nbsp;open &nbsp;pop3<br />119/tcp &nbsp;open &nbsp;nntp<br />143/tcp &nbsp;open &nbsp;imap<br />465/tcp &nbsp;open &nbsp;smtps<br />587/tcp &nbsp;open &nbsp;submission<br />993/tcp &nbsp;open &nbsp;imaps<br />995/tcp &nbsp;open &nbsp;pop3s<br />8080/tcp open &nbsp;http-proxy<br /><br />Сейчас не знаю, откуда берутся эти открытые порты. Можете помочь, пожалуйста…?<br /><br />Спасибо,<br />Toby <br />
			<i>04.01.2014 14:37:00, Toby7.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236610</link>
			<guid>http://mikrotik.moscow/forum/forum57/61791-pravila-filtratsii-brandmauera-i-rezultaty-skanirovaniya-nmap./message236610</guid>
			<pubDate>Sat, 04 Jan 2014 14:37:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
	</channel>
</rss>
