Lungiselela i-firewall ku-mikrotik router

Anonim

Lungiselela i-firewall ku-mikrotik router

Ama-routers eMikrotik athandwa futhi afakwe emakhaya noma emahhovisi avela kubasebenzisi abaningi. Ukuphepha okusemqoka kokusebenza okunemishini enjalo yilungelo le-firewall elilungiselelwe. Kubandakanya iqoqo lamapharamitha kanye nemithetho ukuvikela inethiwekhi kubantu ongabazi nokugenca.

Lungiselela i-firewall router mikrotik

Ukusetha kwe-router kwenziwa kusetshenziswa uhlelo olukhethekile lokusebenza olukuvumela ukuthi usebenzise isikhombimsebenzisi sewebhu noma uhlelo olukhethekile. Kwezimbili lezi zinguqulo kukhona konke okudingekayo ekuhleleni i-firewall, ngakho-ke akunandaba ukuthi ukhetha ini. Sizogxila kunguqulo yesiphequluli. Ngaphambi kokuthi uqale, udinga ukungena ngemvume:

  1. Nganoma yisiphi isiphequluli esikahle, iya ku-192.168.88.1.
  2. Iya ekhasini lezilungiselelo ze-Microtik Router

  3. Esibonelweni sokuqala kwewebhu ye-router, khetha u- "Webfig".
  4. Isiqalo se-Microtik Web Interface

  5. Uzobonisa ifomu lokungena ngemvume. Faka ukungena ngemvume nephasiwedi ezintanjeni, okungamanani azenzakalelayo omphathi.
  6. Ngena ngemvume kwi-Microtik Interface

Ungathola okuningi mayelana nokuhlelwa okuphelele kwama-routers ale nkampani kwenye i-athikili kusixhumanisi esingezansi, futhi sizophendukela ngqo ekucushweni kwamapharamitha avikelayo.

Funda kabanzi: Ungayisetha kanjani uMikrotik Router

Ukuhlanza imithetho yeshidi nokudala okusha

Ngemuva kokungena, uzokhombisa imenyu enkulu, lapho iphaneli nazo zonke izigaba zikhona ngakwesobunxele. Ngaphambi kokungeza ukucushwa kwakho, kuzodingeka wenze okulandelayo:

  1. Nweba isigaba se- "IP" bese uya engxenyeni ethi "Firewall".
  2. Iya ku-firewall ku-microtik router

  3. Hlanza yonke imithetho ekhona ngokucindezela inkinobho efanele. Kuyadingeka ukukhiqiza lokhu ukuze uqhubeke nokushayisana esikhathini esizayo lapho udala ukucushwa kwakho.
  4. Sula Uhlu Lokuvikelwa Imithetho ku-Microtik Router

  5. Uma ufake imenyu ngesiphequluli, ukuguqulwa kwewindows yokusetha kwenziwa nge-inkinobho ethi "Faka", kufanele uchofoze kuhlelo ohlelweni.
  6. Dala umthetho omusha wokuvikela ku-microtik router

Manje, ngemuva kokungeza umthetho ngamunye, kuzodingeka uchofoze izinkinobho ezifanayo zendalo ukuze uphinde uphinde uphinde usebenzise iwindi lokuhlela. Ake sihlale imininingwane eminingi kuzo zonke izilungiselelo zokuphepha eziyisisekelo.

Bheka Idivaysi Yokuxhumana

I-router exhunywe kwikhompyutha kwesinye isikhathi ihlolwe uhlelo lokusebenza lweWindows ngokuxhumana okusebenzayo. Ungaqhuba inqubo enjalo ngesandla, kepha lesi sikhalazo sitholakala kuphela uma i-firewall ikhona ivumela ukuxhumana ne-OS. Kulungiselelwe kanjena:

  1. Chofoza ku- "Faka" noma Red Plus ukukhombisa iwindi elisha. Lapha kulayini we- "Chain", ohunyushwe ngokuthi "Network" Cacisa "Okokufaka" - Ayingenayo. Ngakho-ke kuzosiza ekuboneni ukuthi uhlelo lubhekisela ku-router.
  2. Ukukhetha uhlobo lwenethiwekhi lwe-microtik pinting

  3. Entweni ethi "Protocol", setha inani le- "ICMP". Lolu hlobo lukhonza ukudlulisa imiyalezo ehlotshaniswa namaphutha nezinye izimo ezingejwayelekile.
  4. Ukukhetha kwe-Microtik Pinting Protocolol

  5. Hambisa esigabeni noma ithebhu yesenzo, lapho ukufaka khona "Yamukela", okungukuthi, lokhu kuhlela kukuvumela ukuthi uqhube idivaysi yedivayisi.
  6. Khuphuka uyosebenzisa izinguquko bese uqedela ukuhlela komthetho.
  7. Gcina Ukuvikelwa Kwezilungiselelo ruert Microtik

Kodwa-ke, kulokhu, yonke inqubo yokuthumela imiyalezo nokuhlola imishini ngeWindows ayipheli. Into yesibili ukudluliswa kwedatha. Ngakho-ke, dala ipharamitha entsha lapho ucacisa khona "i-chain" - "Phambili", kanye ne-protocol, chaza ukuthi kwenziwa kanjani esigabeni esedlule.

Umthetho wesibili we-microtik pinge

Ungakhohlwa ukubheka "isenzo" ukuze "kwamukele" kuhanjiswa lapho.

Imvume yokuxhumeka okufakiwe

Amanye amadivaysi axhunyiwe kwi-router nge-Wi-Fi noma izintambo. Ngaphezu kwalokho, iqembu lasekhaya noma lebhizinisi lingasetshenziswa. Kulokhu, uzodinga ukuxazulula ukuxhumana okufakiwe ukuze kungabikho zinkinga ngokufinyelela kwi-Intanethi.

  1. Chofoza u- "Faka". Cacisa uhlobo lohlobo lwenethiwekhi olungenayo. Yehla phansi phansi bese uhlola "okusunguliwe" okuphambene "nombuso wokuxhuma" ukucacisa isethi yokuxhuma.
  2. Ukubusa kokuqala komthetho we-microtik uxhumano

  3. Ungakhohlwa ukubheka "isenzo" ukuze kukhethwe into oyifunayo, njengasemithethweni yemithetho edlule. Ngemuva kwalokho, ungagcina izinguquko bese uqhubeka.

Komunye umthetho, faka "phambili" eduze "kwe-chain" bese ubeka uphawu khona iphuzu elifanayo. Isenzo kufanele futhi siqinisekiswe ngokukhetha ukuthi "Yamukela", kuphela ngemuva kwalokho.

Ukubusa kwesibili kwe-microtik kufakiwe ukuxhumana

Ukuxhuma okuhlobene nokuxazulula

Cishe imithetho efanayo idinga ukuyenzelwe ukuxhumeka okuhlobene, ukuze kungabingelwa lapho kuzanywa khona ubuqiniso. Inqubo yonke yenziwa ngokoqobo ngezenzo eziningana:

  1. Nquma ukuthi umthetho wenani elithi "chain" - "okufakwayo", yehla ubeke uphawu lokuhlola "okuhlobene" nokuhlola "isimo sokuxhumeka". Ungakhohlwa ngesigaba esithi "Action", lapho kusebenze khona ipharamitha efanayo.
  2. Umthetho wokuqala we-microtik uxhumano

  3. Ekucushweni okusha kwesibili, shiya uhlobo lokuxhumeka njenge-efanayo, kepha inethiwekhi isethwe "phambili", futhi esigabeni sezenzo udinga into ethi "Yamukela".
  4. Ukubusa kwesibili kokuxhumeka kwe-microtik okuhlobene

Qiniseka ukuthi ugcina izinguquko ukuze kufakwe imithetho ohlwini.

Isinqumo sokuxhuma kusuka ku-LAN

Abasebenzisi benethiwekhi yendawo bazokwazi ukuxhuma kuphela uma ifakwe emithethweni ye-firewall. Ukuhlela, kuzodingeka ukuthi kudingeke ukuthi uthole ukuthi ikhebula lixhumeke kuphi (ezimweni eziningi liyikheli le-ether1), kanye nekheli le-IP lenethiwekhi yakho. Funda kabanzi ngalokhu kwenye impahla kusixhumanisi esingezansi.

Funda kabanzi: Ungalithola kanjani ikheli le-IP lekhompyutha yakho

Okulandelayo, udinga ukumisa ipharamitha eyodwa kuphela. Lokhu kwenziwa ngale ndlela elandelayo:

  1. Emgqeni wokuqala, faka "okokufaka", bese wehla ku- "SRC elandelayo. Ikheli »bese uthayipha ikheli le-IP lapho. "Ku. I-interface »Cacisa i-" Ether1 "Uma ikhebula lokufaka kumhlinzeki lixhumeke kulo.
  2. Umthetho wokuxhuma izimvume kusuka ku-LAN Microtik

  3. Hambisa kuthebhu ethi "Action" ukubeka inani elithi "ukwamukela" lapho.

Ukuvinjwa kokuxhumeka okuyiphutha

Ukudala lo mthetho kuzokusiza ukuvikela amakhompiyutha anephutha. Kunqunywa ngokuzenzakalela ukuxhumana okungathembeki ngezinto ezithile, ngemuva kwalokho ahlele kabusha futhi ukufinyelela ngeke kunikezwe. Udinga ukudala amapharamitha amabili. Lokhu kwenziwa ngale ndlela elandelayo:

  1. Njengakweminye imithetho edlule, okokuqala ucacisa "okokufaka", bese wehlisa phansi bese uhlola ibhokisi elithi "elingavumelekile" eduze "nombuso wokuxhuma".
  2. Umthetho wokuqala wokuvikelwa kwamakhompiyutha anephutha microtik

  3. Iya kuthebhu noma isigaba "isenzo" bese usetha inani elithi "Drop", okusho ukukhipha amakhompiyutha alolu hlobo.
  4. Ewindini elisha, shintsha kuphela "iketane" ku- "Phambili", okusele, njengakwedlule, kufaka phakathi isenzo "Drop".
  5. Umthetho wesibili wamakhompiyutha anephutha ama-microtik

Ungavimba neminye imizamo yokuxhuma emithonjeni yangaphandle. Lokhu kwenziwa ngokubeka umthetho owodwa nje. Ngemuva kokuthi "Chain" - "Okokufaka" Slip "in. I-Interface "-" Ether1 "ne-" Action "-" Drop ".

Ukwenqatshelwa kokunye ukuxhumana okungenayo kusuka kwinethiwekhi yangaphandle ye-microtik

Imvume yethrafikhi evela kunethiwekhi yendawo kwi-Intanethi

Sebenza ohlelweni lokusebenza lweRouteros likuvumela ukuthi uthuthukise ukucushwa kwamathrafikhi amaningi. Ngeke sihlale kulokhu, ngoba ulwazi olunjalo ngeke lube lusizo kubasebenzisi abajwayelekile. Cabanga ngomthetho owodwa we-firewall okuvumela ukuthi udlule traffic kusuka kwi-Intanethi yendawo:

  1. Khetha u- "Chain" - "Phambili". Setha "ku. Isikhombimsebenzisi "kanye" ngaphandle. Isikhombimsebenzisi esithi "amanani" ether1 ", ngemuva kwalokho okumaka uphawu lokubizelwa" ku. Isikhombimsebenzisi.
  2. Umthetho wethrafikhi evela endaweni yendawo yenethiwekhi yenethiwekhi

  3. Esigabeni se- "Action", khetha isenzo esithi "Yamukela".
  4. Faka isenzo semithetho ye-microtik traffic

Ukwenqabela ukuxhumeka okusele, ungavele nje ngomthetho owodwa:

  1. Khetha inethiwekhi "phambili", ungadaluli enye into.
  2. Bavimbele ukuxhumeka kwe-microtik

  3. Esebenzayo, qiniseka ukuthi "ukwehla" kufanelekile.

Ngokuya ngokucushwa kokugcina, kufanele ube nohlelo lwe-firewall, njengasesikrinini esingezansi.

Umbusi we-Firewall Ubusa uhlelo

Kulokhu, i-athikili yethu iza esiphethweni esinengqondo. Ngingathanda ukuqaphela ukuthi akudingeki ukuthi usebenzise yonke imithetho, ngoba kungenzeka kungadingeki ngaso sonke isikhathi, noma kunjalo, sikhombise ukulungiswa okuyisisekelo okulungele abasebenzisi abajwayelekile kakhulu. Siyethemba ukuthi imininingwane enikeziwe ibilusizo. Uma unemibuzo ngalesi sihloko, babuze kumazwana.

Funda kabanzi