43
TOP10 RouterOS configuration mistakes

TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

  • Upload
    vanthu

  • View
    237

  • Download
    2

Embed Size (px)

Citation preview

Page 1: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

TOP10 RouterOS configuration mistakes

Page 2: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

Presenter – Andis Arins

andis[at]router.lv

www.linkedin.com/in/andisarins

2

� MikroTik Consultant at

� MikroTik / Microsoft certified trainer

� Member of the board in Latvian Internet Association

� Review expert for EU in future networking research

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

/

Page 3: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

3

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

10

The same IP on multiple interfaces

Page 4: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

4

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

The same IP on multiple interfaces

Page 5: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

5

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

The same IP on multiple interfaces

survival strategy: MAC telnet or

connection from different network

Page 6: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

6

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

9

Lack of monitoring

Page 7: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

7

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

Lack of monitoring

� What is the health of my router?

� Is it reachable from everywhere it should?

� Isn’t it overloaded ?

Page 8: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

8

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

Lack of monitoring

Page 9: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

9

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

Lack of monitoring

IP - SNMP

/snmp> send-trap

for proactive

action

Page 10: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

10

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

Lack of monitoring

The Dude

you can monitor and

manage your devices

new features sinceRouterOS 6.34

Page 11: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

11

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

Lack of monitoring

tools-

netwatch

Page 12: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

12

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

Lack of monitoring

tools-

Traffic monitor

Page 13: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

13

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

Lack of monitoring

IP- Traffic Flow

Page 14: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

14

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

Lack of monitoring

Also HA solutions without monitoring may fail one day

VRRP for 99.9%+

availability

0.365 days or

8.76 hours

down in year

Page 15: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

15

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

8

DNS issues

Page 16: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

16

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

DNS issues

Many requests from

spoofed IPs

VICTIM

Page 17: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

17

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

DNS issues

10.0.0.0/24

Page 18: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

18

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

7

Firewall inefficiency

Page 19: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

19

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

Firewall inefficiency

internet 123.123.123.123

webserver

Page 20: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

20

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

6

NAT issues

Page 21: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

21

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

NAT issues

10.0.0.0/24 123.123.123.123

159.148.147.196

src-ip: 10.0.0.10

dst-ip: 159.148.147.196NAT

masquarade

src-ip: 10.0.0.10

src-ip: 123.123.123.123

dst-ip: 159.148.147.196

Page 22: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

22

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

NAT issues

10.0.0.0/2410.1.1.0/24

10.1.1.0/24

123.123.123.0/24

bad

ok

ok

Page 23: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

23

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

NAT issues

10.0.0.0/24 192.168.0.0/24

IPSec

Page 24: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

24

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

5

Allowed IP Spoofing

Page 25: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

25

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

Allowed IP Spoofing

10.0.0.0/24 123.123.123.123

src-ip: 13.13.13.13

dst-ip: 159.148.147.196 ? 1. routing decision

2. firewall decision

Page 26: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

26

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

Allowed IP Spoofing

Tools- Traffic Generator

Page 27: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

27

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

Allowed IP Spoofing

https://spoofer.caida.org/Test your network

http://ieeexplore.ieee.org/

Page 28: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

28

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

Allowed IP Spoofing

10.0.0.0/24

src-ip: 13.13.13.13

dst-ip: 159.148.147.196 X routing

decision

Page 29: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

29

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

4

Bridge issues

Page 30: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

30

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

Bridge issues

Page 31: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

31

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

Bridge issues

wanlan

bridge

master slave slave slave

Page 32: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

32

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

Bridge issues

bridge-lan

DHCP-Server on individual port, not on bridge itself

Page 33: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

33

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

3

PoE issues

Page 34: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

34

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

PoE issues

Mikrotik PoE standart

(4,5pin +) (7,8pin -)

Hello from DC !!!

Page 35: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

35

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

PoE issues

eth1

PoE in

DC adaper

data,power 2

DC power 1

Page 36: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

36

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

2

Waiting for hackers

Page 37: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

37

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

Waiting for hackers

Dude (if installed ) port 2211

Page 38: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

38

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

Waiting for hackers

Page 39: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

39

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

Waiting for hackers

MAC telnet/winbox server on all interfaces

default configuration allows MAC access only from initial bridge

Page 40: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

40

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

1

Try to Guess …

Page 41: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

41

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

admin / no password

Page 42: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

42

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

admin / no password

Page 43: TOP 10 RouterOS configuration mistakes - MikroTik · PDF filePresenter –Andis Arins andis[at]router.lv 2 MikroTik Consultant at MikroTik/ Microsoftcertified trainer Member of the

MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv

That’s it!