αααααΆαααΆαααΆαααααΆαααααααα Covid-19 αα·αααΆαααΆααα±αααα
ααΆα
αααΈαααααα»αααααααααΆα
αααΎα αααααααΆααααα½αααααααααΆαααααα»αα αα»αααΆα
αααΎααααα»αααΆαααααααΆαααΆαααΊααΆαα
αΌααα
ααΆααααααααααααΎααΆαααΈα
ααααΆαααΆααααα’ααΈαααΊαα·αα ααΆααα·ααΈααΆααααααα»ααααα·ααΆαααΆα
αααΎααααααΆααααΆαααΆαααΈα
ααααΆα - ααα»αααααααααΆαααα ααααααα αΆ αα·ααΈααΆαααααααΆαααααααααΆααα’αααααααΎααααΆααααΆααααΆααααΎααααΈααααΆαααα
ααΆαα·ααΆαααααΈα
ααααΆαααΊα
αΆαααΆα
α α αΎαααααα·αα
αΆαααΆα
αααΆαααΆαααααααααααα ααΆααααααα ααΆαααααΉααααΆαααα»αααααΆαα αα·αααΆαααααΆααααααααααΆαα αα·ααΈααΆααααααααααααΌαααΆααααααΆαααααα’ααααααααααααααΆα
αααΎα RDP (Remote Desktop Protocol) α ααΆααααααΆαααααααααΆαααα
ααααααααααΎααΆαααΆαααα RDP αααααααΆααααα αΆααααααΎαααΆαα§ααααααα· ααΎααααααααΆαα ααα αΎααααααα½ααα
αααα»ααα½α - ααΆααααααΆα
ααα RDP α±ααααΎαα
αα αααααΆααα’ααΈαααΊαα·αααΊαα·αααΆααα»ααααα·ααΆαααααΆααα ααΌα
αααα ααΆααααααβαααβαααα»αβααΌαβααααΆαβαα·ααΈααΆαααααβααΆαααΆαβααβααΆαααα ααα»ααααβα’αΆα
βαα»αα
α·αααβααΆαβα
αααααΆααααα»αα§ααααΆα αααααααΆααα’αααααΆαααΌα
ααααα§ααααα Mikrotik ααααΌαααΆαααααΎααΆααΆαα
αΌαααααΎα’ααΈαααΊαα·α ααΆαααααααααααΆααΉααααα αΆαααΈααααα’αα»ααααααΆαα
ααΎ Mikrotik ααα»αααααα·ααΈααΆαααααααΆαααΆα Port Knocking ααααΌαααΆαα’αα»αααααααΆαααΆααααα½ααα
ααΎα§αααααααααΆααααααααααααααααααααΆαααΆααααααααααααααααα
αΌα αα·ααααααΆααααααΎαααααααααααΆα .
ααααααα’αααΈ Port Knocking. ααΆαααΆαααΆαααΆααααα ααααα’αααααααΆααααααααΆαααα α’ααΈαααΊαα·αααΊαα ααααααααααΆα αα·αα αααααΆααα’ααααααΌαααΆααα·αααΈααΆααααα ααααααααΆααααααΎαα α αΎααααααΈααΆααααααααααααΆααααααΆααααααΎααααααΆαααααααα ααΆαααααααααααααααα·αααΆαααααα·αααααααα»ααααααααΆαααΆαα½αα αααααααα ααααααααΆααααααααΈααΆααααα ααααα ααααΆααααΆαααα½ααααααα ααΌα ααααα αΎα α’αααα’αΆα ααααααα ααΆααααααααααααααα ααΌα αααααα αααααααααα ααααααααΆααααααΆαααΆααααΆαααα½αααααΌαααΆαααα½ααα ααΎα αααααααααααααΆ ααΆ (ααααααα) αααααΆαα IP ααααααα ααααααααΆαααΆαααααΈααΆαααΆααααααΆα αααΆαα αΌαααααΎααααΆααααααΆααα½αα ααα½α (α ααα αα·ααΈααΆαα αα )
α₯α‘αΌαααααα α’αΆααΈαααααα αααα»αααΉααα·αααααΎααΆααααααΆαααα’α·αα’αααΈααΆαααααααααααΆααααααΎααα ααΎ Mikrotik αα - α’αα·αααΊαα·αααΊαααααααα αααααααααααααΆααα»αααΆαααααααααααΆααααΏααααα ααΆαα§ααααααα· αααααΆααααααΎαααΆααΆαααααα ααααααααΆαα αΌαααΆααα’αα ααα»αααα
/ip firewall filter
add action=accept chain=input comment="established and related accept" connection-state=established,related
α’αα»ααααΆαα±ααα
ααΆα
αα
αΌαααΈααΆααααααΆαααααααΆααααααααααααΆααααααΎαα‘αΎαα
α₯α‘αΌααααααΎααααα
α Port Knocking αα
ααΎ Mikrotikα
/ip firewall filter
add action=drop chain=input dst-port=19000 protocol=tcp src-address-list="Black_scanners" comment=RemoteRules
add action=drop chain=input dst-port=16000 protocol=tcp src-address-list="Black_scanners" comment=RemoteRules
add action=add-src-to-address-list address-list="remote_port_1" address-list-timeout=1m chain=input dst-port=19000 protocol=tcp comment=RemoteRules
add action=add-src-to-address-list address-list="Black_scanners" address-list-timeout=60m chain=input dst-port=19001 protocol=tcp src-address-list="remote_port_1" comment=RemoteRules
add action=add-src-to-address-list address-list="Black_scanners" address-list-timeout=60m chain=input dst-port=18999 protocol=tcp src-address-list="remote_port_1" comment=RemoteRules
add action=add-src-to-address-list address-list="Black_scanners" address-list-timeout=60m chain=input dst-port=16001 protocol=tcp src-address-list="remote_port_1" comment=RemoteRules
add action=add-src-to-address-list address-list="Black_scanners" address-list-timeout=60m chain=input dst-port=15999 protocol=tcp src-address-list="remote_port_1" comment=RemoteRules
add action=add-src-to-address-list address-list="allow_remote_users" address-list-timeout=1m chain=input dst-port=16000 protocol=tcp src-address-list="remote_port_1" comment=RemoteRules
move [/ip firewall filter find comment=RemoteRules] 1
/ip firewall nat
add action=dst-nat chain=dstnat comment="remote_rdp" src-address-list="allow_remote_users" dst-port=33890 in-interface-list=WAN protocol=tcp to-addresses=192.168.1.33 to-ports=3389
α₯α‘αΌαααααα αααα»ααααα’α·αααααααααα:
α αααΆααααΈαααααΌα
/ip firewall filter
add action=drop chain=input dst-port=19000 protocol=tcp src-address-list="Black_scanners" comment=RemoteRules
add action=drop chain=input dst-port=16000 protocol=tcp src-address-list="Black_scanners" comment=RemoteRules
α αΆαααΆαααααα ααααααααΆαα αΌαααΈα’αΆααααααΆα IP αααααααΌαααΆαααΆαααααα»ααααααΈαααα ααα‘α»αααααααααα αααα
α αααΆααααΈααΈα
add action=add-src-to-address-list address-list="remote_port_1" address-list-timeout=1m chain=input dst-port=19000 protocol=tcp comment=RemoteRules
αααααα ip αα
αααα»ααααααΈαααΆαααΈααααααΆαααααΎα±αααααααααΌαααααΉαααααΌααα
ααΎα
αααααααΉαααααΌα (19000);
α
αααΆαααα½ααααααΆααααΊα
add action=add-src-to-address-list address-list="Black_scanners" address-list-timeout=60m chain=input dst-port=19001 protocol=tcp src-address-list="remote_port_1" comment=RemoteRules
add action=add-src-to-address-list address-list="Black_scanners" address-list-timeout=60m chain=input dst-port=18999 protocol=tcp src-address-list="remote_port_1" comment=RemoteRules
add action=add-src-to-address-list address-list="Black_scanners" address-list-timeout=60m chain=input dst-port=16001 protocol=tcp src-address-list="remote_port_1" comment=RemoteRules
add action=add-src-to-address-list address-list="Black_scanners" address-list-timeout=60m chain=input dst-port=15999 protocol=tcp src-address-list="remote_port_1" comment=RemoteRules
αααααΎαα αααα’ααααΆαααααααΆααα’ααααααα αααααααα αααααααα’ααα α αΎαααααα·αααΎααΆαααα»ααααααααααααααΌαααΆαααααΎα αααααΈαααα ip αααααα½ααααααααΆαααααααα 60 ααΆααΈ αααα»αα’αα‘α»αααααααα αααΆααααΈαααααΌαααΉααα·ααααααα±ααααα αΆααααααααααααααΌαα±ααΆαααΎααααΈαααα αααααααΉαααααΌααααααα
α αααΆαααααααΆααα
add action=add-src-to-address-list address-list="allow_remote_users" address-list-timeout=1m chain=input dst-port=16000 protocol=tcp src-address-list="remote_port_1" comment=RemoteRules
ααΆαα ββip αα αααα»ααααααΈαααααΆαα’αα»ααααΆααααααα 1 ααΆααΈ (αααααααααΆααααΎααααΈαααααΎαααΆααααααΆαα) α αΆααααΆααααΈααΆααααααααΉαααααΌαααΈααΈαααααΌαααΆαααααΎα‘αΎααα ααΎα ααααααα ααααΆα (16000);
ααΆααααααααΆαααααΆααα
move [/ip firewall filter find comment=RemoteRules] 1
ααααΆααααΈα αααΆααααααααΎαα‘αΎαααΎαααααααααΆααααααΎαααΆααααααΆααααααΎα αααααΆαααΆαα αααΎαααααααΆααΎαααΉαααΆαα αααΆααααα·ααααααααααααΆαααααΆαααααααα ααΆαααααααααα½α α αΎα αααααΉαααΆααΆααα’ααααααααΎαααααΈααααααΎααα·αααααΎαααΆαα α αααΆααααααΌααααα»ααα αααα»α Mikrotik α αΆααααααΎαααΈααΌααα ααα»αααααα ααΎα§ααααααααααααα»αααΌαααααααΌαααΆαααΆααααΆαααααα αααΆαααααααΆαααααΆαα α αΎαααΆαα·αα’αΆα αα αα½α αααααα»αααΆαααααΆααααΈααΆ - αααα»αααΆαααααΆααααΈααΆαα ααα 1α ααΌα ααααα αΎα ααΎαααΎαααΆααααααααααααΎα - αααααΆαααααααααα’αααα’αΆα ααααΆααααΈααΆααΆα αα·αα ααα’α»ααααα αΆαααααααα ααααΆαα
ααΆαααααααααααΆααα
/ip firewall nat
add action=dst-nat chain=dstnat comment="remote_rdp_to_33" src-address-list="allow_remote_users" dst-port=33890 in-interface-list=WAN protocol=tcp to-addresses=192.168.1.33 to-ports=3389
αααααΌαααααα ααα 33890 αααααΆαααααΎαααΎαααΆαα’αααΎα α·ααααα α ααα RDP ααααααΆ 3389 αα·α ip αααααα»αααααΌααα α¬αααΆαααΈαααααααΆααΈααααααΎαααααΌαααΆαα ααΎααααααΎαα αααΆαααααααααααααΆααααααΆαααΆααααα»αα αΆαααΆα αααΆααα’αα αα·αααααααα αααααΆααααα ααααα·ααααααααΆα (αα·ααα»αααααΆ)α ααΆααααααΆ IP ααααααΆαααΆααααα»αααααΌααααα·αα·αααα α¬αα½ααα»ααα ααΎαααΆαααΈααα DHCP α
α₯α‘αΌαααα Mikrotik ααααααΎαααααΌαααΆαααααααα ααΆαααααααα α αΎαααΎαααααΌαααΆαααΈαα·αα·ααΈααΆαααααα½ααααααΆααα’αααααααΎααααΆααααΎααααΈααααΆαααα RDP ααΆααααα»αααααααΎαα αααααΆαααΎαααΆαα’αααααααΎααααΆαα Windows ααΆα αααα ααΎααααααΎαα―αααΆα bat ααΆαααααα½α α αΎαααΆαααααααααΆααΆ StartRDP.batα
1.htm
1.rdp
αααααααΆ 1.htm ααΆαααΌαααΆααααααα
<img src="http://my_router.sn.mynetname.net:19000/1.jpg">
Π½Π°ΠΆΠΌΠΈΡΠ΅ ΠΎΠ±Π½ΠΎΠ²ΠΈΡΡ ΡΡΡΠ°Π½ΠΈΡΡ Π΄Π»Ρ ΠΏΠΎΠ²ΡΠΎΡΠ½ΠΎΠ³ΠΎ Π·Π°Ρ
ΠΎΠ΄Π° ΠΏΠΎ RDP
<img src="http://my_router.sn.mynetname.net:16000/2.jpg">
ααΆααΆααααααααΆααααΈααα ααΌαααΆααααααΎαααααααααααΆαααΈααΆαααα my_router.sn.mynetname.net - ααΎαααα’αΆααααααΆααααααΈαααααααα Mikrotik DDNS αααααΆααααΈααΎαααΆαα αααα»α Mikrotik ααααααΎαα α αΌααα ααΆαα IP-> Cloud menu - αα·αα·ααααααα’ααααΈα DDNS Enabled α α α»α α’αα»αααα α αΎαα ααααααααα dns αααααααααααααααΎαα ααα»αααααααααΊα αΆαααΆα ααααα αααααα ip ααΆααααα αααααααααααααΆαααααααααΆααααα α¬ααΆαααααααα ααΆααααααααααΆαα½αα’ααααααααα’ααΈαααΊαα·αααΆα αααΎαααααΌαααΆαααααΎααααΆααα
α ααααααα»ααααααααΆααααΈαα½αα 19000 ααααΌαααααΆααΉαα αααααΈαα½ααααα’αααααααΌααααααΈααΈα αααααααΆαα ααΈααΈαα αααΆααααααααΆααααΆαααΆαααααΆαααααΈαααααααα αΆαααΈα’αααΈαααααααΌαααααΎααααα·αααΎααααΆααααΆααααααΆααααααααΎαααααΌαααΆαααααΆααααααΆααααα αΆαααααΆαααααΈ - ααΎαααααΎα±αααααααα‘αΎααα·α α ααα RDP ααΎαα‘αΎααα·ααααααΆααααΎα 1 ααΆααΈ α αΎαααααααααααΎαααααΌαααΆαααααΆαα‘αΎααα·αα ααΌα ααααΆαααααααα α’ααααααααΆαααααΆα img αααααΎαααΆαααΆ micro-delay αααααΆαα browser αααααΆαααααααααααααΆααααααα ααααααααΆαααΈαα½ααααααααΌαααΆααααααΌααα α αααααΈααΈα (16000) - αα αΌαααααααααααααα·αααΆαααααΈαααααααααααα»αααααααααΈααααααΆα αααααΆαααααΎααααΆαα (30 ααα»ααα)α
αααααΆααααα―αααΆα 1.rdp αααααΎαα’αΆα ααααααα ααΆαααααααααα½ααααααΆααααΆααα’ααααααΆ α¬αααα‘ααααΈααααΆαααααΆααα’αααααααΎααααΆααααααΆααα (αααα»αααΆαααααΎααΆ - ααΆααΆααααα½αααΆααααα»αααΆαα αααΆαααα 15 ααΆααΈαααααα ααΆαααΈαααΈααααααΎααααΈαα·αααααααΆαα½αα’αααααααα·αα’αΆα αααααΆα)
screen mode id:i:2
use multimon:i:1
.....
connection type:i:6
networkautodetect:i:0
.....
disable wallpaper:i:1
.....
full address:s:my_router.sn.mynetname.net:33890
.....
username:s:myuserlogin
domain:s:mydomain
ααααΆαααααααα½αα±ααα αΆααα’αΆαααααααα ααΈαααααΊααααΎ multimon: i: 1 - ααααα½ααααα αΌαααΆααααΆαααααΎααααΆαααααΌααΈαααα αααΎα - αα½αα ααα½αααααΌαααΆαααΆ ααα»αααααα½αααααααΆααααΉααα·ααα·αααΈααΆαααΎαααΆααα
ααααααααΆααααααΆααα i: 6 αα·α networkautodetect: i: 0 - αααααΆαα’ααΈαααΊαααααΆαα αααΎαααΎαααΈ 10 Mbps αααααΆααααααΎαααααααααΆααααααΆαα 6 (αααααΆαααΌαααααΆα 10 Mbps αα·ααααααααΆαααα) α αΎααα·α networkautodetect αααααααααα·αααΎααΆαααααΆαααΎα (ααααααααααααα·) αααααΆαααα ααΌααααΈααααΆαααΊααααααααΆαααΌα αα½αααααααααΉααααααααααααααααΎααααααααααααααααα·αα ααΆααααΏαααΊααααα»αααααααααΌα αααα’αΆα αααααΎαααΆααααααΆαααααα½αα±ααααααααααΆαααααα»αααΆαααΆα ααΆαα·ααααα αααα»ααααααα·ααΈααααΆα ααα·αα
αα·αααααΆααααΌαααΆα: i: 1 - αα·αααΌαααΆααααααα»
username:s:myuserlogin - ααΎααααααΆααααΆαα
αΌαααααα’αααααααΎ α
αΆααααΆααααΈαααααααααΆααααα’αααααααΎααααΆααααααααΎααα·αααααΆααααΆαα
αΌααααααα½ααα
domain:s:mydomain - αααααΆαα domain α¬ααααααα»αααααΌααα
ααα»ααααβααααα·αβααΎβααΎαβα ααβααααα½αβαα·α αα ααΆαβααααβααΎαβαααα»αβααΆαβαααααΎαβααΈαα·αα·ααΈβααβααΆαβαααααΆαα αααβααΎαβααβα’αΆα βααααΎ PowerShell - StartRDP.ps1
Test-NetConnection -ComputerName my_router.sn.mynetname.net -Port 19000
Test-NetConnection -ComputerName my_router.sn.mynetname.net -Port 16000
mstsc /v:my_router.sn.mynetname.net:33890
ααααα·α αααα’αααΈαααΆαααΈαααααα RDP αα αααα»α Windowsα MS ααΆααααααααααΌαααααααα½ααααα»αααΆααααααΎαααααα·αααααΆααα·ααΈααΆα αα·αααααααααΆαααΈααα αα·ααααΆαααΈααααααααααααΆ ααΆαα’αα»αααααα»αααΆαααΆαααααααααααΆα αααΎα ααΌα ααΆααΆαααααΎααΆαααΆαα½ααααααααΉα 3D ααΆααααααΎααα»αααΆααααα αΆαα’αααααααααααΆαααααΌααΈααα α’ααααααα αααΎαααααα’αααα αβαα ααα»ααααααΆααΆααα·αααΆαα α’αααΈααααααααΆαααααΌαααΆαα’αα»αααααα αααα»αααααααΆαααααααΆααααααα α αΎαααααα·αααΎαααΆαααΈααααααααΊ Windows 7 α αΎααα»αααααΌαααααΈα ααααΆαααΊ Windows 10 ααα RDP ααΉαααααΎαααΆααααααααΎαα·ααΈααΆααααα 7.0 α ααα»ααααα’αααααααααααααΊααΆα’αααα’αΆα ααααΎαα αα α»ααααααααΆααααα RDP αα ααααααααΈαααααααααα - α§ααΆα αααα’αααα’αΆα ααα‘αΎααααααα·ααΈααΆαααΈ 7.0 (Windows 7) αα 8.1 α ααΌα αααα ααΎααααΈααΆαααΆααααα½αααααα’αα·αα·αα ααΆα αΆαααΆα ααααα»αααΆααααααΎαααααααααααααααΆαααΈαααα±ααααΆαα αααΎαααΆααααα’αΆα ααααΎαα ααΆα ααααΌα ααΆααααααααΆααααΎααααΈααα‘αΎααααααα ααααααααΈααααα’αα·αα·αααα·ααΈααΆα RDP α
ααΆαααααα ααΎαααΆααα αα αααα·ααααΆααΆαααα αα·αααΆααα»ααααα·ααΆααααααΆααααΆααααααΆααααΈα ααααΆααα ααΆαααα»αααααΌαααααααααα»αααααΎαααΆα α¬αααΆαααΈαααααααΆααΈαα ααα»αααααααααΆααααΆααααααΆαααααααΆααα»ααααα·ααΆαααΆααα»α αα·ααΈααΆααααα Port Knocking ααααααΎαα’αΆα ααΆαααααα·ααΆαααΆααααα αΆααααααΆααααααΆαα·αα αααΎααα αααααααααα αααααΎααααΈαα·αα·αααααΎα - α’αααα’αΆα αααααα 3,4,5,6 ... α ααααα½αααααα ααΆααααααα·ααααΆααΌα ααααΆ α αΎααααα»αααααΈααα ααΆααααααα αΌααααααααΆαααα αααα»ααααααΆαααααα’αααααΉαααααΎααααα·αα’αΆα αα αα½α ααα
ααααα: www.habr.com