2014年12月10日 星期三

DNS 攻擊




參考看看:

/ip firewall filter
add action=drop chain=input protocol=udp dst-port=53 in-interface=pppoe-out1 comment="Blocking DNS requests"
add action=drop chain=input protocol=tcp dst-port=53 in-interface=pppoe-out1 comment="Blocking DNS requests"
add action=drop chain=forward protocol=udp dst-port=53 out-interface=!pppoe-out1 comment="Blocking DNS requests"
add action=drop chain=forward protocol=tcp dst-port=53 out-interface=!pppoe-out1 comment="Blocking DNS requests"

/ip firewall nat
add action=redirect chain=dstnat protocol=udp dst-port=53 in-interface=!pppoe-out1 comment="Blocking DNS requests"
add action=redirect chain=dstnat protocol=tcp dst-port=53 in-interface=!pppoe-out1 comment="Blocking DNS requests"

PS. WAN Port interface 請修改成你的設定名稱。



http://www.mobile01.com/topicdetail.php?f=110&t=3205444&p=283


ip >DNS> cache 看是否有異常

增加設定,可以還原原本的效率

2014年11月10日 星期一

查 mtu 的程式

mturoute.exe - Debug the MTU values between you and a host.

Current Version (v2.5) from 2011-8-8:

Can be downloaded right here: mturoute.exe or as a zip file which includes source code here: mturoute_v2_5.zip

Description:



C:\>mturoute.exe www.hinet.net
* ICMP Fragmentation is not permitted. *
* Speed optimization is enabled. *
* Maximum payload is 10000 bytes. *
- ICMP payload of 1472 bytes is too big.
+ ICMP payload of 92 bytes succeeded.
+ ICMP payload of 782 bytes succeeded.
+ ICMP payload of 1127 bytes succeeded.
+ ICMP payload of 1299 bytes succeeded.
+ ICMP payload of 1385 bytes succeeded.
+ ICMP payload of 1428 bytes succeeded.
+ ICMP payload of 1450 bytes succeeded.
- ICMP payload of 1461 bytes is too big.
- ICMP payload of 1455 bytes is too big.
+ ICMP payload of 1452 bytes succeeded.
- ICMP payload of 1453 bytes is too big.
Path MTU: 1480 bytes.
# 路徑上最大MTU為1480,mss為1452

C:\>mturoute.exe -t www.hinet.net
mturoute to www.hinet.net, 30 hops max, variable sized packets
* ICMP Fragmentation is not permitted. *
* Speed optimization is enabled. *
* Maximum payload is 10000 bytes. *
 1  +-  host: 192.168.2.254  max: 1500 bytes
 2  -+++++++--+-  host: 168.95.98.254  max: 1480 bytes
 3  +-  host: 168.95.144.86  max: 1480 bytes
 4  +-  host: 220.128.16.142  max: 1480 bytes
 5  +-  host: 220.128.3.102  max: 1480 bytes
 6  +-  host: 220.128.3.145  max: 1480 bytes
 7  +-  host: 211.22.41.237  max: 1480 bytes
 8  No response from traceroute for this TTL.  Tried 3 times
 9  +-  host: 202.39.224.7  max: 1480 bytes

--
http://blog.xuite.net/u870q217/blog/47195684-PMTU+Discovery%E6%A6%82%E8%BF%B0

2014年11月5日 星期三

ipv6 setup routeros

rb450g 




固定ip v6 設定 x86

2014年10月28日 星期二

routeros 固定ipv6 ip 設定方式



http://www.mobile01.com/topicdetail.php?f=110&t=3205444&p=168#48875262
==


謝謝!! gfx、pctine、虎._."三位大大
將成功的固定制IPV6設定分享給大家。


註:
另外,想問一下RouterOS有辦法根據連結到的IP位置(或國家區域),使用指定的DNS伺服器做域名查詢嗎?
例:220.130.158.71(台灣)->指定使用168.95.1.1這台DNS伺服器做域名查詢。

routeros 固定ip 設定wan to lan






/ip firewall nat
add action=dst-nat chain=dstnat  dst-address=\
    211.72.x.x dst-address-list="" in-interface=WAN1 to-addresses=192.168.11.103

指定目的是211.72.x.x 從 wan 1 介面進來對映到lan 的 192.168.11.103



add action=src-nat chain=srcnat src-address=\
    192.168.11.103 to-addresses=211.72.155.56

指定來自192.168.11.103 從 "不指定的" 介面進來對映到wan 的 211.72.x.x (會從路由表查詢,從wan  走)

這邊,如果指定 走 wan 介面 那麼 lan 的網段會繞到wan , 再到lan 相對比較慢 (目前設定起來是如此)


設定邏輯

wan to lan
lan to wan  各設定一條






add action=dst-nat chain=dstnat comment="open port 55555" dst-address-type=local dst-port=55555 \
    protocol=tcp to-addresses=192.168.11.250 to-ports=55555


預設的 wan  ip  對映進來的port 有一個是tcp 55555 將被導到  local 的192.168.11.250 的port 55555



==

而在 RouterOS 是以 ip firewall nat 設定. 在官方文件裡找到了二則有關 NAT 方面的資料.

How to link Public addresses to Local ones
Forwarding a port to an internal IP

上述都是以固定 IP 為例. 設置大致如下.

/ip firewall nat add chain=dstnat dst-address=69.69.69.69 protocol=tcp \
dst-port=80 action=dst-nat to-addresses=192.168.22.10 to-ports=80


但如果 WAN IP 是 dynamic IP 呢? 很簡單, 直接用 in-interface 來做就好

/ip firewall nat
add action=dst-nat chain=dstnat comment="http server" disabled=no \
dst-port=80 in-interface=pppoe-out1 protocol=tcp to-addresses=192.168.22.10 \
to-ports=80


2013/11/18更新
WAN 為 dynamic IP 的 port forwarding 也可以利用 dst-address-type=local 來達成, 此時就不需要指定 in-interface

/ip firewall nat
add action=dst-nat chain=dstnat comment="Synology DSM" dst-address-type=local \
dst-port=5000-5006 protocol=tcp to-addresses=192.168.22.10 to-ports=\
5000-5006

2014年10月25日 星期六

routeros 倒出設定值


routeros

透過 new terminal,
export compact
的方式貼上你的設定,這只會列出與RouterOS預設值不同的設定,也就是你有改動過的值,才不會一長串

也可以只倒出某部份設定


info 
http://www.mobile01.com/topicdetail.php?f=110&t=3205444&p=261

2014年10月19日 星期日

routeros 照片 load出來,使用ipv6



我也遇過這問題,FB開很久或照片開不出來,查了好久才找到問題,
ipv6->ND->MTU大於1480就會出現,改MTU1480就沒再發生。


把mtu改成1500吧,匯入下面的命令也可達到相同目的.
/ip firewall mangle
add action=change-mss chain=forward in-interface=all-ppp new-mss=1432 \
protocol=tcp tcp-flags=syn tcp-mss=1433-65535
add action=change-mss chain=forward new-mss=1432 \
out-interface=all-ppp protocol=tcp tcp-flags=syn tcp-mss=1433-65535

請教gfx兄:
為什麼MTU務必要改為1500呢? 另外這串手動修改MSS的用意是?

最大傳輸單元(MTU)
修正MTU ,即讓PPPoE傳輸的封包符合最大傳輸單元1492,不致於因過大被丟棄.
您當然可以將PPPoE MTU變更成更小的1480 ,但傳輸效能會略遜些.

除定義MTU外,還有

透過change MSS只變更PPPoE的IPv6封包,但區域網路傳輸還是維持原來最大傳輸單元1500


===


http://www.mobile01.com/topicdetail.php?f=110&t=3205444&p=252





===
add 
mss要設定在ip 非ipv6

http://wenku.baidu.com/view/4432453083c4bb4cf7ecd1a5.html


Ping bbc.co.uk [212.58.246.103] (使用 1472 位元組的資料):
回覆自 212.58.246.103: 位元組=1472 時間=293ms TTL=50
回覆自 212.58.246.103: 位元組=1472 時間=293ms TTL=50

212.58.246.103 的 Ping 統計資料:
    封包: 已傳送 = 2,已收到 = 2, 已遺失 = 0 (0% 遺失),
大約的來回時間 (毫秒):
    最小值 = 293ms,最大值 = 293ms,平均 = 293ms
Control-C
^C
C:\Users\axx>ping bbc.co.uk -f -l 1476

Ping bbc.co.uk [212.58.246.103] (使用 1476 位元組的資料):
需要切割封包,但已設定 DF 旗標。
需要切割封包,但已設定 DF 旗標。

212.58.246.103 的 Ping 統計資料:
    封包: 已傳送 = 2,已收到 = 0, 已遺失 = 2 (100% 遺失),


所以,上面 1432 可以修改為1472