{"id":20822018,"url":"https://github.com/mikehorn-git/routeros-hardening","last_synced_at":"2025-05-11T21:30:59.743Z","repository":{"id":240565739,"uuid":"802948625","full_name":"MikeHorn-git/RouterOS-Hardening","owner":"MikeHorn-git","description":"Secure and Harden your MikroTik RouterBoard / RouterOS.","archived":false,"fork":false,"pushed_at":"2024-05-22T16:29:24.000Z","size":53,"stargazers_count":1,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2024-05-22T22:09:15.223Z","etag":null,"topics":["hardening","mikrotik","routerboard","routeros","script","security"],"latest_commit_sha":null,"homepage":"","language":"RouterOS Script","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/MikeHorn-git.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2024-05-19T17:29:31.000Z","updated_at":"2024-05-22T16:29:28.000Z","dependencies_parsed_at":"2024-05-19T20:25:33.270Z","dependency_job_id":"47542f1f-459a-4b59-a964-4197e635001b","html_url":"https://github.com/MikeHorn-git/RouterOS-Hardening","commit_stats":null,"previous_names":["mikehorn-git/routeros-hardening"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/MikeHorn-git%2FRouterOS-Hardening","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/MikeHorn-git%2FRouterOS-Hardening/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/MikeHorn-git%2FRouterOS-Hardening/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/MikeHorn-git%2FRouterOS-Hardening/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/MikeHorn-git","download_url":"https://codeload.github.com/MikeHorn-git/RouterOS-Hardening/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":225096647,"owners_count":17420293,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["hardening","mikrotik","routerboard","routeros","script","security"],"created_at":"2024-11-17T22:13:45.034Z","updated_at":"2024-11-17T22:13:45.492Z","avatar_url":"https://github.com/MikeHorn-git.png","language":"RouterOS Script","funding_links":[],"categories":[],"sub_categories":[],"readme":"![image](https://github.com/MikeHorn-git/RouterOS-Hardening/assets/123373126/fec74d01-aa82-46ff-85dd-4059cb4ba272)\n\n# Warning\nRead a script before running it.\n\n# Description\nThis script is designed to harden your RouterOS device by disabling unnecessary services, enhancing security settings, and configuring logging. The script follow best practices from the [Securing your router](https://help.mikrotik.com/docs/display/ROS/Securing+your+router) section of MikroTik documentation and a [Manito Networks blog](https://www.manitonetworks.com/networking/2017/7/25/mikrotik-router-hardening) post.\n\n# Installation\n```bash\n/tool fetch url=\"https://raw.githubusercontent.com/MikeHorn-git/RouterOS-Hardening/main/hardening.rsc\" mode=https\n/import file-name=hardened.rsc\n```\n\n# Features\n* Update System Packages [Optional] (Need a valid license)\n* Create new user hardened (Need to change password, the temporary password is hardened)\n* Disable admin user\n* Disable Unnecessary Services (API, FTP, IP Cloud, Telnet, Proxy, SOCKS, UPNP, WWW, WWW-SSL)\n* Disable MAC Server (Ping, Server, Winbox)\n* Disable Bandwidth Server\n* Disable DNS Cache \n* Disable Neighbor Discovery\n* Disable IPv6 Neighbor Discovery\n* Disable Router Management Overlay Network (ROMON)\n* Enable Reverse Path Filtering (RPF)\n* Enable Stronger SSH Crypto\n* Configure Logging to Disk\n* Configure NTP\n* Change SSH Port (2200)\n* Disable LCD Module [Optional] (Need a compatible RouterBoard)\n* Build a Firewall [Partially]\n* Create Configuration Backup\n\n# Recommendations\nThis part cannot be done automatically.\n* Firewall Configuration [Partially]\n* Backup Strategy\n* Change credentials\n* Monitor Log File Size\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmikehorn-git%2Frouteros-hardening","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmikehorn-git%2Frouteros-hardening","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmikehorn-git%2Frouteros-hardening/lists"}