MikroTik security findings, explained
Every finding the audit can report has its own page: what it means, why it matters, what it looks like in Winbox, and the exact RouterOS commands that fix it. Written for people who run a MikroTik router, not only for security specialists.
IPv6 is active but there is no IPv6 firewall
Your router has IPv6 connectivity but not a single rule in the IPv6 firewall. Because IPv6 has no NAT, that leaves the router and every device on your LAN reachable from the internet, regardless of how good your IPv4 firewall is.
IPv6 forward chain lets the internet reach internal devices
Over IPv6 every device on your LAN has a public address, and there is no NAT to hide behind. Without a drop rule in the IPv6 forward chain, the internet can open connections straight to your PCs, printers and cameras. One rule closes it.
Router management reachable over IPv6 from the internet
Your IPv4 firewall may be fine, but the IPv6 input chain does not drop unsolicited traffic from the WAN side. Winbox, SSH and the other services listen on both, so they are exposed over IPv6 anyway.
New article every other day · RSS