Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


Cornelius16

4 posts

Wannabe Geek


#261411 26-Nov-2019 12:08
Send private message

Good Day,

 

 

 

I would like to ask if someone could assist with a how to guide on how to setup your Mikrotik Modem to connect to Fibre.

 

 

 

Thanks


View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2
mrgsm021
1471 posts

Uber Geek

Trusted

  #2360901 26-Nov-2019 12:14
Send private message

There is a general guide here




Cornelius16

4 posts

Wannabe Geek


  #2360904 26-Nov-2019 12:18
Send private message

Thanks will use this to set it up


nztim
3819 posts

Uber Geek

ID Verified
Trusted
TEAMnetwork
Subscriber

  #2360918 26-Nov-2019 13:24
Send private message

what ISP are you with?

 

 





Any views expressed on these forums are my own and don't necessarily reflect those of my employer. 




Cornelius16

4 posts

Wannabe Geek


  #2360919 26-Nov-2019 13:25
Send private message

Will be Voyager


mrgsm021
1471 posts

Uber Geek

Trusted

  #2360923 26-Nov-2019 13:42
Send private message

Cornelius16:

 

Will be Voyager

 

 

According to this list, Voyager requires VLAN 10 tagging with PPPOE


Cornelius16

4 posts

Wannabe Geek


  #2360932 26-Nov-2019 14:09
Send private message

Thanks


sbiddle
30853 posts

Uber Geek

Retired Mod
Trusted
Biddle Corp
Lifetime subscriber

  #2361015 26-Nov-2019 16:54
Send private message

Make sure you correctly firewall the PPPoE interface or you'll be the subject of a DNS amplification attack within minutes.

 

 


 
 
 

Move to New Zealand's best fibre broadband service (affiliate link). Free setup code: R587125ERQ6VE. Note that to use Quic Broadband you must be comfortable with configuring your own router.
MichaelNZ
1394 posts

Uber Geek

Trusted
Integrity Tech Solutions

  #2361210 26-Nov-2019 23:04
Send private message

sbiddle:

 

Make sure you correctly firewall the PPPoE interface or you'll be the subject of a DNS amplification attack within minutes.

 

 

 

 

Or turn DNS off.

 

Also make sure you set an admin password before connecting it to the internet otherwise you will be root'd in very short order.





WFH Linux Systems and Networks Engineer in the Internet industry | Specialising in Mikrotik | APNIC member | Open to job offers


sbiddle
30853 posts

Uber Geek

Retired Mod
Trusted
Biddle Corp
Lifetime subscriber

  #2361281 27-Nov-2019 07:15
Send private message

MichaelNZ:

 

sbiddle:

 

Make sure you correctly firewall the PPPoE interface or you'll be the subject of a DNS amplification attack within minutes.

 

 

 

 

Or turn DNS off.

 

Also make sure you set an admin password before connecting it to the internet otherwise you will be root'd in very short order.

 

 

But you need a properly configured firewall regardless so turning DNS off is a just a dumb solution. I can't think of a single good reason why you wouldn't want to run a local DNS proxy for 99.9% of situations where it''s  being used a router.

 

And if you're not going to configure the firewall correctly for PPPoE it won't matter if you change the password or not because unless you're running the latest ROS updates the router can (and probably will eventually if it's sitting in the Internet exposed for long enough) be compromised regardless of what the password is.

 

At least with newer versions of ROS configuring a PPPoE firewall is a lot simpler because you just add the PPPoE interface to the WAN interface lists which means all the default rules will apply.

 

 


nztim
3819 posts

Uber Geek

ID Verified
Trusted
TEAMnetwork
Subscriber

  #2361448 27-Nov-2019 11:42
Send private message

My Three Recommendations

 

* Update ROS (6.44.6)

 

* Once you have configured your router disable the MAC /tool mac-server 

 

* On your PPPoE (or WAN) have two firewall rules MINIMUM (1st an Input rule to allow established, related Traffic, 2nd input rule to drop everything else)

 

 

 

 

 

 

 

  

 

 

 

 





Any views expressed on these forums are my own and don't necessarily reflect those of my employer. 


chevrolux
4962 posts

Uber Geek
Inactive user


  #2361452 27-Nov-2019 11:46
Send private message

Why would you disable the MAC server? You're just making things hard for yourself!

 

And you need a hell of a lot more than just two firewall rules as a minimum. I'd say for a newbie, the default set is a good start.


nztim
3819 posts

Uber Geek

ID Verified
Trusted
TEAMnetwork
Subscriber

  #2361456 27-Nov-2019 11:54
Send private message

chevrolux:

 

Why would you disable the MAC server? You're just making things hard for yourself!

 

 

At least on the WAN ports

 

chevrolux:

 

And you need a hell of a lot more than just two firewall rules as a minimum. I'd say for a newbie, the default set is a good start.

 

 

Agreed, but this is a start 





Any views expressed on these forums are my own and don't necessarily reflect those of my employer. 


hio77
12999 posts

Uber Geek

ID Verified
Trusted
Lizard Networks

  #2361480 27-Nov-2019 12:41
Send private message

MichaelNZ:

 

sbiddle:

 

Make sure you correctly firewall the PPPoE interface or you'll be the subject of a DNS amplification attack within minutes.

 

 

 

 

Or turn DNS off.

 

Also make sure you set an admin password before connecting it to the internet otherwise you will be root'd in very short order.

 

 

damn Michael,

 

please dont tell me you push 8.8.8.8 through your whole network rather than using dns caches?





#include <std_disclaimer>

 

Any comments made are personal opinion and do not reflect directly on the position my current or past employers may have.

 

 


cyril7
9058 posts

Uber Geek

ID Verified
Trusted
Subscriber

  #2361488 27-Nov-2019 12:59
Send private message

The firewall rules out of the box are fine for most domestic situations, just ensure you add the pppoe to the WAN address list and the issues relating to DNS attacks etc go away.

 

Cyril


sbiddle
30853 posts

Uber Geek

Retired Mod
Trusted
Biddle Corp
Lifetime subscriber

  #2361538 27-Nov-2019 14:42
Send private message

chevrolux:

 

Why would you disable the MAC server? You're just making things hard for yourself!

 

And you need a hell of a lot more than just two firewall rules as a minimum. I'd say for a newbie, the default set is a good start.

 

 

Unless people fully understand firewall rules there is no reason why you'd remove any of the default rules. Only having two input rules overlooks all the forward rules which exist by default for a very good reason.

 

At least it's much simpler to add a PPPoE client now with the address lists option. It used to require multiple changes historically. 


 1 | 2
View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.