Community discussions

MikroTik App
faber33
just joined
Topic Author
Posts: 5
Joined: Thu Sep 10, 2020 8:24 pm

Port knocking from Mikrotik

Wed Dec 21, 2022 8:14 am

Hello. I have an OpenVPN connection between two mikrotik. I would like to hide the OpenVPN port (1194) with Port Knocking. There are many descriptions on the Internet on how to configure it on the server side, but how to make the mikrotik client knock on the server before connecting?
Top
User avatar
Jotne
Forum Guru
Forum Guru
Posts: 3218
Joined: Sat Dec 24, 2016 11:17 am
Location:Magrathean

Re: Port knocking from Mikrotik

Wed Dec 21, 2022 12:13 pm

Not tested, but I guess you can use the fetch command some like this:
Code:Select all
/tool fetch url="remote_host:8888" keep-result=no /tool fetch url="remote_host:9999" keep-result=no /tool fetch url="remote_host:5555" keep-result=no
Top
User avatar
anav
Forum Guru
Forum Guru
Posts: 17178
Joined: Sun Feb 18, 2018 11:28 pm
Location:Nova Scotia, Canada
Contact:

Re: Port knocking from Mikrotik

Wed Dec 21, 2022 3:04 pm

WHY?
You have a vpn connection why do you think you need port knocking?

Nevermind, you should drop ovpn and simply use wireguard.
Top
User avatar
rextended
Forum Guru
Forum Guru
Posts: 11426
Joined: Tue Feb 25, 2014 12:49 pm
Location:Italy
Contact:

Re: Port knocking from Mikrotik

Thu Dec 22, 2022 12:59 am

[...] you should drop ovpn and simply use wireguard.
+1000
Top
User avatar
nichky
Forum Guru
Forum Guru
Posts: 1203
Joined: Tue Jun 23, 2015 2:35 pm

Re: Port knocking from Mikrotik

Thu Dec 22, 2022 3:09 am

@anav

depenс what u need , about the performance, yes with wireguard, u can get much more bandwidth then ovpn, but from other way ovpn has own advantages.

it's works same as physical interface (TAP), so you can add vlan on that or put in the bridge, choice btw udp/tcp & port.
Top
User avatar
anav
Forum Guru
Forum Guru
Posts: 17178
Joined: Sun Feb 18, 2018 11:28 pm
Location:Nova Scotia, Canada
Contact:

Re: Port knocking from Mikrotik

Thu Dec 22, 2022 4:26 am

@anav

depenс what u need , about the performance, yes with wireguard, u can get much more bandwidth then ovpn, but from other way ovpn has own advantages.

it's works same as physical interface (TAP), so you can add vlan on that or put in the bridge, choice btw udp/tcp & port.
I have yet to see a situation for the majority of users that wireguard doesnt solve.
If ovpn is so good, then why need port knocking.

So be consistent if you are going to espouse NOt wireguard at least have the courtesy to promote IKEv2. You also would do this knowing that OVPN is not fully implemented in ROS.
Top
User avatar
mkx
Forum Guru
Forum Guru
Posts: 10029
Joined: Thu Mar 03, 2016 10:23 pm

Re: Port knocking from Mikrotik

Thu Dec 22, 2022 11:22 am

If ovpn is so good, then why need port knocking.

添加额外的保护层在服务endpoint (OVPN or any other) never hurts ... and doesn't have much to do with how "protected" service handles possible attacks. It's just that some services are outright dangerous if exposed to the wild without any 3rd party protection due to known vulnerabilities, some don't have similar problems ... yet.
BTW, I'm pretty sure wireguard would work behind this additional shield just fine.
Top
User avatar
Jotne
Forum Guru
Forum Guru
Posts: 3218
Joined: Sat Dec 24, 2016 11:17 am
Location:Magrathean

Re: Port knocking from Mikrotik

Thu Dec 22, 2022 11:54 am

I have some VPN tunnel (L2TP IPSec) for personal use only and I can see from the logs (Splunk) that there are always someone trying to open the tunnel, so I see the added security using Port Knocking.

On my work computer I can not use Wireguard, since I can not install any extra protocol doe to limited admin access, so that is not an option.
Top
User avatar
rextended
Forum Guru
Forum Guru
Posts: 11426
Joined: Tue Feb 25, 2014 12:49 pm
Location:Italy
Contact:

Re: Port knocking from Mikrotik

Thu Dec 22, 2022 11:57 am

Sorry for that, but I can't resist...
https://www.youtube.com/watch?v=nJaEy03MEK0
Top
User avatar
own3r1138
Long time Member
Long time Member
Posts: 669
Joined: Sun Feb 14, 2021 12:33 am
Location:Pleiades
Contact:

Re: Port knocking from Mikrotik

Thu Dec 22, 2022 12:08 pm

lol
Top
User avatar
mkx
Forum Guru
Forum Guru
Posts: 10029
Joined: Thu Mar 03, 2016 10:23 pm

Re: Port knocking from Mikrotik

Thu Dec 22, 2022 12:19 pm

Great.

It'd get even better if doors actually opened after that port knocking sequence:lol:
Top
User avatar
rextended
Forum Guru
Forum Guru
Posts: 11426
Joined: Tue Feb 25, 2014 12:49 pm
Location:Italy
Contact:

Re: Port knocking from Mikrotik

Thu Dec 22, 2022 12:21 pm

:facepalm:
:lol:
Top

Who is online

Users browsing this forum: No registered users and 25 guests