- 62
- 622 211
Wilmer Almazan / The Network Trip
Canada
Приєднався 18 гру 2020
Video tutorials about networking, cloud computing, and network security. One new video every week. Covering configuration on Cisco, Fortinet, Mikrotik, Ubiquiti and much more.
Block DHCP Attacks - Deep Dive
#DHCP #NetworkSecurity #MikroTik #Networking
In this video, I’ll show you how to block DHCP starvation and spoofing attacks before they bring your network down.
You’ll learn how attackers exploit DHCP to exhaust IP pools or introduce rogue servers-and more importantly, I’ll guide you through practical defenses. With a hands-on lab, I’ll explain how to use DHCP Snooping, Option 82, Port Security, and other strategies to keep your network safe and running smoothly.
📌 What You’ll Learn:
• How DHCP Starvation and Spoofing Attacks Work
• Using DHCP Snooping, Option 82, and Port Security for Defense
• Step-by-Step Lab for Network Protection
Connect with Wilmer Almazan
LinkedIN: www.linkedin.com/in/wilmeralmazan/
Facebook: nsswilmeralmazan/
Twitter: wilmer_almazan
Instagram: wilmer_almazan
mikrotik
routeros 7
ospf
mtcna
mtcre
cybersecurity
routing
cloud computing
virtualization
switching
network automation
In this video, I’ll show you how to block DHCP starvation and spoofing attacks before they bring your network down.
You’ll learn how attackers exploit DHCP to exhaust IP pools or introduce rogue servers-and more importantly, I’ll guide you through practical defenses. With a hands-on lab, I’ll explain how to use DHCP Snooping, Option 82, Port Security, and other strategies to keep your network safe and running smoothly.
📌 What You’ll Learn:
• How DHCP Starvation and Spoofing Attacks Work
• Using DHCP Snooping, Option 82, and Port Security for Defense
• Step-by-Step Lab for Network Protection
Connect with Wilmer Almazan
LinkedIN: www.linkedin.com/in/wilmeralmazan/
Facebook: nsswilmeralmazan/
Twitter: wilmer_almazan
Instagram: wilmer_almazan
mikrotik
routeros 7
ospf
mtcna
mtcre
cybersecurity
routing
cloud computing
virtualization
switching
network automation
Переглядів: 1 401
Відео
Master MikroTik Policy Routing - Rules or Marks?
Переглядів 2,1 тис.Місяць тому
#PolicyBasedRouting #mikrotik #mikrotikrouter In this video, we dive deep into Policy-Based Routing (PBR) and how you can use it to control traffic flow on your network. We cover three key topics: - What is Policy-Based Routing? - A clear explanation of PBR and how it can improve traffic management. - Routing Rules - Learn how to define and apply specific routing rules for different types of tr...
Block DNS Flood Attacks on Mikrotik - Live Demo Included!
Переглядів 3,2 тис.Місяць тому
#NetworkSecurity #MikroTik #DDoSProtection #CyberSecurity In this video, we dive into the world of DNS flood attacks and how they can overwhelm your network with a flood of small DNS requests, disrupting services and slowing everything down. I’ll give you an overview of what a DNS flood attack is, followed by a live demonstration of its impact on a network. Most importantly, I’ll walk you throu...
Adlist Mikrotik - Step by Step Lab
Переглядів 2,4 тис.Місяць тому
#MikroTik #Adlist #NetworkSecurity In this video, we dive into MikroTik's Adlist feature, a powerful tool for blocking unwanted ads and boosting your network's security by filtering harmful domains at the DNS level. Whether you're trying to stop ads from cluttering your browsing experience or protect your network from malicious domains. Here’s what we’ll cover in the video: - What is the Adlist...
mDNS Mikrotik - Discover Your Devices Without a DNS Server
Переглядів 3,3 тис.Місяць тому
#MikroTik #mDNS #MikroTikLabIn mDNS (Multicast DNS) is a protocol that allows devices on the same local network to resolve hostnames without relying on a central DNS server. It operates using multicast to broadcast queries and responses to all devices within the local subnet. mDNS is commonly used for device discovery in home or small office networks, enabling services like printers and smart d...
MACSec Mikrotik - Hop by Hop Encryption
Переглядів 1,4 тис.Місяць тому
#macsec #mikrotik #networksecurity In this video, I break down the MACsec protocol and how it secures Layer 2 communication across multiple hops. I’ll show you the risks of unencrypted traffic in a multi-hop network and then guide you through the full configuration process of enabling MACsec on MikroTik devices. You'll see step-by-step how to set it up, followed by a demonstration of the networ...
Router Redundancy - VRRP Mikrotik (Step by Step)
Переглядів 2,8 тис.Місяць тому
#VRRP #MikroTik #NetworkRedundancy VRRP in MikroTik: Achieving Network Redundancy for LAN Networks In this video, I dive into why VRRP (Virtual Router Redundancy Protocol) is crucial for ensuring high availability and redundancy in your network. If you're managing critical networks, ensuring uptime is essential. That's where VRRP comes in. I explain: - What VRRP is and why it's important for ne...
DNS over HTTPS (DoH) on MikroTik: Complete Lab
Переглядів 2,4 тис.Місяць тому
#DoH #MikroTik #DNSoverHTTPS In this video, we dive deep into DNS over HTTPS (DoH), explaining how it works and why it's an important privacy enhancement over traditional DNS. You'll learn how DoH can protect your browsing by encrypting DNS queries, preventing them from being easily intercepted or logged by third parties. We'll cover: - A comparison of traditional DNS vs. DoH - How DoH can impr...
MVRP - Dynamic VLANs Mikrotik (Full Lab - Step by Step)
Переглядів 3,2 тис.2 місяці тому
#MVRP #MikroTik #VLANManagement Master MVRP in MikroTik with This Step-by-Step Lab! In this video, we’re diving into MVRP (Multiple VLAN Registration Protocol) in MikroTik. I’ll guide you through the concept, configuration, and implementation of MVRP with a hands-on, step-by-step lab. Whether you're new to MVRP or looking to expand your MikroTik skills, this lab will help you understand how to ...
Deterring Network Intrusions: How to use DHCP + ARP for MikroTik LAN Security
Переглядів 1,8 тис.2 місяці тому
#mikrotik #dhcp #arp In this video, we'll show you how to improve your LAN security using DHCP and ARP on MikroTik devices. By combining DHCP with static ARP, you can prevent unauthorized devices from joining your network and ensure that only trusted devices get access. Here's what we'll cover: - How DHCP and ARP work together to secure your network. - Setting up static ARP to lock down IP-to-M...
Static ARP on MikroTik Devices
Переглядів 6102 місяці тому
#arp #mikrotiktutorial #mikrotikrouter In this video, we explore how Static ARP can significantly enhance the security of your LAN on MikroTik devices. By locking ARP entries, you can prevent unauthorized devices from hijacking IP addresses and ensure better control over your network. We'll cover: - What ARP is and the difference between dynamic and static ARP entries. - How Static ARP works to...
Mikrotik Certifications & Hardware
Переглядів 3102 місяці тому
#MikroTik #MikroTikCertifications #MikroTikDevices MikroTik Certifications and Devices Explained! In this video, I’ll walk you through everything you need to know about MikroTik Certifications and their wide range of networking devices. Whether you’re looking to become a certified MikroTik professional or want to explore their top-tier devices, this video will guide you through the essentials. ...
What is Mikrotik? - Profile, Operating System & MUMs
Переглядів 5662 місяці тому
MikroTik #RouterOS #MikroTikTraining 🌐 What is MikroTik? 🌐 In this video, I’ll introduce you to MikroTik, the company behind some of the most powerful and flexible networking products in the industry. Whether you're new to networking or already familiar with MikroTik, this video will give you a deeper understanding of the company and its products. ✅ What you’ll learn: - The history and profile ...
Analyzing the ARP Table in Mikrotik Devices
Переглядів 4622 місяці тому
#arp #mikrotik #bridging In this video, we dive into Analyzing the ARP Table on MikroTik Devices! The ARP table is a crucial part of your network's operation, helping resolve IP addresses to MAC addresses. Understanding how to interpret and manage this table can help you troubleshoot network issues and improve efficiency. We’ll cover: - What the ARP table is and how it works in a network. - How...
My First Bridge in Mikrotik Devices
Переглядів 9252 місяці тому
#mikrotiktraining #mikrotik #bridging Welcome to my tutorial on setting up your first bridge in MikroTik devices! This video is perfect for beginners and those new to MikroTik or network bridging. We'll go through the basics of what a network bridge is, its role in connectivity, and a straightforward, step-by-step guide to creating your first bridge using RouterOS. What you'll learn: - Step-by-...
Understanding Bridge Hardware Offloading in Mikrotik Devices
Переглядів 1,7 тис.2 місяці тому
Understanding Bridge Hardware Offloading in Mikrotik Devices
How to Upgrade or Downgrade Your Mikrotik Router
Переглядів 4322 місяці тому
How to Upgrade or Downgrade Your Mikrotik Router
How to Add a License to your Mikrotik CHR?
Переглядів 4062 місяці тому
How to Add a License to your Mikrotik CHR?
IS-IS Mikrotik Full Lab (Step by Step) - Ep 2
Переглядів 2,4 тис.Рік тому
IS-IS Mikrotik Full Lab (Step by Step) - Ep 2
Port Knocking & Scanner Detection - Mikrotik Firewall Ep 3
Переглядів 6 тис.Рік тому
Port Knocking & Scanner Detection - Mikrotik Firewall Ep 3
Mikrotik Firewall - Protecting the Router (Ep 2)
Переглядів 8 тис.Рік тому
Mikrotik Firewall - Protecting the Router (Ep 2)
Mikrotik Firewall From Scratch - The Basics - Episode 1
Переглядів 12 тис.Рік тому
Mikrotik Firewall From Scratch - The Basics - Episode 1
Controller Bridge / Switch - Mikrotik (Full Lab)
Переглядів 11 тис.Рік тому
Controller Bridge / Switch - Mikrotik (Full Lab)
MLAG With Mikrotik - High Availability (Full Lab)
Переглядів 13 тис.Рік тому
MLAG With Mikrotik - High Availability (Full Lab)
Layer 3 Hardware Offloading Mikrotik - Deep Dive
Переглядів 18 тис.Рік тому
Layer 3 Hardware Offloading Mikrotik - Deep Dive
MACVLAN Mikrotik - Multiple MACs, One Interface
Переглядів 5 тис.Рік тому
MACVLAN Mikrotik - Multiple MACs, One Interface
Secure Login on Mikrotik - Good Bye Passwords!
Переглядів 1,9 тис.Рік тому
Secure Login on Mikrotik - Good Bye Passwords!
Excelente tu canal! todo el canal
Very clean, thanks
hi can i intergrate PBR to ospf?
I have watched your Firewall Series and have enjoyed it immensly. After viewing this several times I believe I have the knowledge to configure my CCR in a secure manner. Thank you very much.
Ok maybe I missed something but L3HW can only work if done through bridge with vlan? Just router port to router port it can't work?
Hello! If we want to have pure routing and hardware offloading (without NAT), we need bridge and VLAN interfaces as explained in this video. If you have WAN and LAN interfaces, you can keep the WAN interface outside the bridge, create NAT rules, and add a rule in the forward chain to FastTrack and enable L3 hardware offloading for that traffic. The initial connection will be managed by the CPU, and then the NAT entries will be copied to the switch chip.
@@TheNetworkTrip oh wow ok I didn't expect that and also possibly explains alot about my performance issues. I don't have any Firewall/Nat rules and connection tracking is disabled just pure L3 Routing from Interface A to Interface B but I'm not using any bridge, I have enabled HW offloading and attempted to offload some of the routes to hardware and they do show the H in routes and the /interface/ethernet/swich/l3hw-settings/monitor shows that HW offloading is enabled with about 5000 out of 1m routes is offloaded (i don't have CPU issues) but I feel performance is shaped somehow where once traffic reaches around 4-5Gbps It seems to struggle.
@@TheNetworkTrip Thanks for the key info, will play around and see if it helps me with my issues.
Hello! Can this work between VLAN and WIREGUARD networks? I have enabled the new Media server (UPNP) on the router and I would like to see it when I'm connecting through Wireguard.
hello, great material but I have a question: what does backbone mean? are these routers that only have L2? do I understand this correctly? my English is poor that's why I'm asking thanks in advance for your answer regards Daniel
That's correct. The backbone is the contiguous Level 2 (L2) network responsible for routing between different areas, ensuring global connectivity and hierarchy within the protocol's domain.
@@wilmeralmazan8824 ok, thanks for the answer; but if I had 6 routers in the same backbone, can only L1 do it? what defines the router DR and BDR as in ospf? L2 connects different arenas - right? and if I have 3 arenas? what does the virtual link with ospf look like? please make a material about it divided into one arena, 2 arenas and 3 arenas with virtual link if you have time thank you and best regards Daniel
how about dynamic public ip bridged directly as ISP2. how to do the routing table and routes? thanks.
Hi, Nice example. Can this be enabled on a CCR2216 as a border router against the ISP? Taking into account that this router has active BPG that is published to the internet
Hi! That works as long as you are receiving the default route only (because of the BGP's routing table size)
your teaching is absolutely amazing. please don't stop creating great content like this one.
Thanks so much for the great feedback! I’m really happy you find the content helpful. I’ll keep making more-your support means a lot!
I have star topology with 3 CCR (I.e. R1,R2 and R3). Each CCR has CRS in front of it. And each CRS has single bridge setup. Because it is a star configuration, RSTP set the port to alternate port and trying to prevent loop. Because of that, I can never ping the GW or the port the CRS port role as alternate port. That creates a problem since I will want to get to some of the host on that subnet. If I turn off RSTP, it creates a loop. Any suggestion?
Wilmer - great video - learning RouterOS and your videos are a great help. The docs don’t mention the CRS-310-8G+2S is not mentioned in the docs as supported for either a Controller Bridge or Port Extender. Do you know why it wouldn’t work? I’d like to use it as the CB. Great videos.
thank you so much for your tutorial
I loved it! Thank you so much!
hi my friend i see a lot of your video but i'm looking for something very very precise and not found any answer online. i will resume we are wisp distributer we have data and iptv. we have hap ac2 most of our client have. the problem is client make mistake they plug anywhere in the router anything and cause us problem so what we want is if the person plug a IPTV into any port with the mac adress began with 00:00:00:00:XX:XX it will go to vlan exp : 10. if he plug anything else will go to default vlan 1 how do i configure this into the router OS ?
Thanks for this great video, very helpful and saved my time.
Strange thing, i cant use github link, the file isnt complete only around 17000 entries, fortunatelly there is also non github link on this host file and its works!
Thank youuu Soo good explianed please can you doing ein Lab ebgp, ibgp full mesh/R.R and ospf
Thank you.
Excellent!! And as would be the case with pppoe-client, in ip routes(v7) it does not allow me to set pppoe as the gateway, it does not recognize it. thanks!!
Thank you so much for the elaborate explanation. You along with The Network Berg are the best!!! Can you also explain how to do recursive routing with policy based routing? I have successfully been able to do this following your tutorial, also the policy based routing watching your video. However I want to combine the 2. Please help! Thanks a lot and stay blessed!
Hello, I have the following question, I don't know if you can answer it... if we have one or more switches in front of the switch that interconnects with the router, we have to place the "trunk" (fiber) ports as "trusted" that interconnect the switches between them? Where several VLANS pass as explained in your video "Mikrotik VLANs - CRS3XX Step by Step - Mikrotik Tutorial". Thanks.
Hello! That’s correct, the trunk interfaces will be trusted.
@@TheNetworkTrip Thanks. I will do it.
The best explanation about routing !!
Glad to hear that!
Thanks for this videos it worked like a charm
Great to hear!
What is the impact (at performance level) of use routing mark as a single mangle rule than marking connections and after that mark-routing of only connections marked before? Other scenario can be mark-connection --> mark-packets ---> mark-routing. What is the best procedure, upon your expertise?
Hello! For this specific scenario, the performance is pretty similar.
"Mas claro, echale agua" as we say the latinamericans!!!! Thanks again Wilmer!!!!!
You bet!
Tks very much Mr. Almanzan for this video. One question: I have on my lan a NAS whit a DNS server to resolve local names, so it is possible to add also this local DNS server to the Mikrotik router so other devices on my lan can use both DNS server to resolve local and external ips? As a solution I did include on the Mikrotik default DHCP server network both the Mikrotik and the NAS server local ips (you on 13.31 included only the Mikrotik IP) but I'm not shure if this is the right way to do it. Pls let me know any hint about.
Hello! If you have a dedicated DNS server, you can configure DoH directly on it; there’s no need to set it up on your router. However, configuring it on your router can provide redundancy in case your dedicated server goes down. In that scenario, your approach of providing the server IPs is effective.
i my case, when I connect my Mikrotic router to my home ISP router. After I have followed your lab Routing instruction, with regard to the routing rules. My computer, sitting on one port inside the mikrotik Router Bridge, can not communicate with other IP inside my ISP router local LAN, but only the IP that is set on the Ether port 1. Am i missing some setting(config) on the Mikrotik hAP ac router ?
Hello! The entries keeping in the main table your local networks should be missing something. Please make sure all your local networks are in the main table.
Can there be a manual route added for computers to access the Internet instead of using nat (masquerade)?
Answered myself - there is no local IP-address in the Internet, they should be masked (netted). So routing is not suitable in this situation.
Hello! If the computers have private IPs, you need NAT.
That’s correct
Thanks. New information for me. Did as you showed, everything works fine.
Great!
Is it possible to use failover, recursive routing, and source route LAN to WAN all together for load balance ?
Hello! That’s possible. Next week I’ll have a video about it.
@@TheNetworkTrip Thank you for your video. Today, I configured failover along with recursive routing and PBR, and both are working together successfully.
Nice video. If I want to set up failover and load balancing like this, what do I need to do?
I’ll explain that setup in one upcoming video.
What about the native vlan (untagged) on the trunk port? how do you pass it to the other untagged ports?
Hello! If the trunk interfaces have the PIV=1, it will be added dynamically to the table. If you need a different ID, you can change it on the trunk interfaces.
hmm since you redirect to cpu only packets that are on selected interfaces and of selected type and port destination is it still necessary to specify everything on bridge filter? i mean wouldn't it be enough to only match mac addresses and allow/block then and let the switch chip do the work of filtering out dhcp packets?
Hello! The chip is redirecting all traffic to UDP ports 67 and 68. During a DHCP starvation attack, the packets will still reach the CPU, so you need to block them manually. The chip does not block frames on its own. For DHCP snooping, no additional filters are required, as I demonstrated in the video.
@@TheNetworkTrip yes i understand, i'm talking about the fact that switch chip will redirect only packets that are udp and 67-68 port src/dst so you don't need to check it again at bridge filter, and only check mac address i think less cpu based matching should be a bit faster
That’s correct if those are the only rules under the bridge. However, in a production environment, there may be additional rules targeting other traffic, so it’s important to be specific. The goal of the video is to show what’s happening first, and if we get it, we can customize the configuration as needed. There are tons of potential things we can do, but the video would be extremely longer.
Thank you sir, this video is useful
Glad to hear that
nice video, thanks !!!!!
Glad you liked it!
In IPV6 I think he will have a bit of problem in exhausting the IPV6 addresses on a network:), is time we move on and leave IPV4 behind.
100% agree!
How did you add ISP1 and ISP2 to GNS3? ISP1 has the tap0 interface. After the trace command, both ISPs output the address 192.168.100.254. How is it configured?
Hello! This is a simulation. The uplink router has 10.40.x.x and 10.50.x.x, that’s why the rest of the trace will look similar.
Thank's for the great Video. What tool are you using for the Network Simulation?
Hello! I use GNS3
Nice content!
Glad you think so!
Thanks for the insight
Glad it was helpful!
@TheNetworkTrip well done. Can i ask you , can we get video about /ip cloud advanced set use-local-address=yes and what this does?
Thank you! IP Cloud is an interesting topic, I'll record a video about it.
DHCP attacks can catch networks off guard, but there are ways to block them. Have any thoughts or experiences with DHCP security? Share your insights below!
Thanks
Welcome 🙏
if i have output are vlan's in this case on new policy routing rule i can add them on interface and ignore src addres does it work like that
Hello! If you are referring to traffic leaving through VLAN interfaces, it won’t match these rules because that occurs after the routing process. You need to identify the traffic before it reaches the routing process, which is when it gets evaluated. If you are referring to the output chain (traffic generated by the router itself), yes, we can use the same methods I demonstrated in the video.
Very informative & Detailed video on topic. Could you please create a new video for dual ISP load balancing using different mangle rules like PCC and discuss every points regarding all options available to differentiate traffic (src address, src & dst address, src address & port, src address & port && dst address & port) it will be really helpful if you can teach us mark packet & mark routing with real world scenarios.
Hello! It’s on my to-do list. Thanks for the suggestion.
Hello, I created a loopback interface and gave it the address as in the video, and the RouterID remained 192.168.1.1 and did not change to the loopback interface. What could be the reason?
Hello! The lowest active IP address will be used. This decision is made when the OSPF process starts. Once defined, you will have to restart the process.
Excelente tu trabajo en general. Saludos desde Argentina
Gracias! Saludos
Extraño los videos en Español estimado Wilmer!
Hola! Se vienen pronto, ya hay varios en edición. Saludos