Konsep
- Deteksi pola scan/login gagal → masukkan IP ke address-list → drop.
Sebelum pasang rule
- Pastikan kamu punya akses management dari IP trusted agar tidak terkunci.
- Letakkan rule allow trusted sebelum rule drop.
Contoh ide rule (sesuaikan port/service) /ip firewall filter add chain=input action=accept connection-state=established,related add chain=input action=drop connection-state=invalid add chain=input action=accept protocol=icmp add chain=input action=drop src-address-list=blacklist add chain=input action=add-src-to-address-list protocol=tcp dst-port=22,8291 \ address-list=blacklist address-list-timeout=1d connection-state=new in-interface-list=WAN add chain=input action=drop in-interface-list=WAN
Catatan
- Pastikan kamu allow management dari IP trusted sebelum drop.
- Jika port management berbeda, sesuaikan dst-port.