Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Industry Forums » Wireless Service Providers » Mikrotik Winbox Access
Uniqs:
785
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Utilize wireless(wi-fi) type producst for customers? »
« Canadian CPE dealers?  
Diddy1

join:2003-07-19
Sidney, NE


1 edit

Mikrotik Winbox Access

Can someone with MT experience give me an idea how to prevent access via Winbox from any other Ip other than one authorized address? I've disabled discovery on all interfaces so no MAC discovery. But, if someone on our private subnet were to learn the address of the router, how would one prevent access attempts via winbox? I can turn off all other access methods, to my knowledge. I do know that winbox uses Port 8291 and I have made a firewall to drop, or reject, anything attempting to login via that port on TCP that is not the address of the authorized machine. But unfortunately this doesn't work.
Any suggestions?
Aaron
Diddy1

join:2003-07-19
Sidney, NE


3 edits

Re: Mikrotik Winbox Access

Well, after 2.5 hours of messing around, it would appear that there is no way to prevent someone using winbox to log-in to a MT router if they are on same subnet with MAC or Ip. I'm not saying I've explored every option, but I think I have tried every combination of firewall settings that are possible?
Interesting to say the least. Anyone know of a way I haven't figured out? This is more of curious "computer science" question I guess
Aaron
slipstream1
Premium
join:2005-11-15
Jacksonville, TX
Can you not just set a secure user name and password to prevent unauthorized access.
ibliz

join:2007-01-24


1 edit
Greetings,

You can set the authorized IP address for each username using winbox as follows :
1. Click Users menu.
2. Then on the userlist that appears next, click the user which you'd like to restrict access
3. A window with the settings for that username will appear. Notice there is a field named Allowed Address. Enter the authorized address into that field. IP addresses other than the one listed will not be able to log onto the usename.

Iam sure there is console command for those steps I just discussed, but I cant seem to find it.

Hope that helps.
khoaled

join:2002-11-08
Geneseo, IL
The Mikrotik manual has a section on securing your router.

»www.mikrotik.com/testdocs/ros/2.···lter.php
Forums » Industry Forums » Wireless Service ProvidersUtilize wireless(wi-fi) type producst for customers? »
« Canadian CPE dealers?  


Thursday, 10-Dec 19:02:58 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [200] Sprint Sued For Distracted Driving Death
· [135] AT&T Launching New 24 Mbps U-Verse Tier
· [87] AT&T Hints At Usage-Based iPhone Data Pricing
· [82] 3G Network Test Says AT&T Is Tops
· [72] Mediacom Unveils 105 Mbps Pricing
· [72] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [66] Sprint Poised For A Turnaround?
· [54] Average American Consumes 34 Gigabytes Daily
· [51] The Future Of Wi-Fi Is Bright
· [50] Sprint, T-Mobile Merger Rumor Lives
Most people now reading
· [WIN7] Well, I was dumb, but do I have recourse? [Microsoft Help]
· New Mediacom Email [Mediacom]
· malware has been found hidden inside an Ubuntu screensaver [Security]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Windows 7 boot manager editing questions [Microsoft Help]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· It's happening again [AT&T Southwest]
· Cross Server Dungeon Experience [World of Warcraft]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Snow on Roof [Home Repair & Improvement]