Protection
The allow-list
Section titled “The allow-list”Only the networks on the allow-list can reach the router’s API (port 8880), the web monitor (port 8881) and the MK-api listener (port 8728). Everything else is dropped. Localhost is always allowed.
dtvsol protect listdtvsol protect add XXX.XXX.XXX.0/24 "NOC"dtvsol protect add XXX.XXX.XXX.25 "billing server"dtvsol protect del XXX.XXX.XXX.25Add the networks of your NOC, your billing server and any wall screens.
The monitor’s Settings → Protection page shows and changes the same list. It refuses to remove the entry your own browser comes through, and never removes localhost.
fail2ban
Section titled “fail2ban”fail2ban bans addresses after repeated failed logins: SSH, bad API keys, and failed monitor
logins (all written to /opt/dtvsol/log/auth.log).
dtvsol fail2bandtvsol fail2ban unban XXX.XXX.XXX.23The monitor also slows down guessing by itself: after 5 failed logins from one address in 10 minutes, that address has to wait.
Anti-spoofing
Section titled “Anti-spoofing”Everything the router does for a subscriber keys on its address: the speed limit, a suspension, accounting and the CGNAT log. A CPE that types in another address would escape all of them. With anti-spoofing on, a packet is forwarded only when its source MAC and IP are a pair the router knows on that VLAN. ARP is checked the same way. Everything else is dropped and logged with the MAC that sent it.
dtvsol antispoof # status: per-VLAN mode, bindings, drops in the last hourdtvsol antispoof on # enforce on every VLAN DHCP servesdtvsol antispoof off # remove every rule; settings are keptModes:
- strict: registered subscribers only. Unknown devices still get DHCP (so they show in
dtvsol ips) and nothing else. - dynamic: registered subscribers are locked to their address, and unknown devices may use the address DHCP leased them.
dtvsol antispoof set mode strictdtvsol antispoof set log ondtvsol antispoof set exempt 10.0.0.0/30 # e.g. an OLT's relay addressdtvsol antispoof iface vlan100 dynamic # one VLAN's mode: strict|dynamic|off|defaultdtvsol antispoof log 2h # who was dropped: MAC, address, VLANServices are bound by their port interface and address, not by MAC. For IPv6, a client’s reserved address, its DHCPv6 address and its delegated prefix are bound to its MAC; link-local always passes; router advertisements and redirects from subscribers are dropped.
The rules follow the DHCP lease files by themselves. dtvsol antispoof sync rebuilds them now.
In the monitor, Settings → Protection has the global switch, the mode, logging, the exempt list and a per-interface mode. Turning anti-spoofing off asks for a second click.
Port forwards
Section titled “Port forwards”Forward a public port to a subscriber (inbound DNAT):
dtvsol portforward listdtvsol portforward add tcp 8443 100.64.16.9 443 XXX.XXX.XXX.64 "customer camera"dtvsol portforward del tcp 8443 XXX.XXX.XXX.64Arguments: protocol, public port, subscriber address, subscriber port, and optionally the public address (any when left out) and a comment. Forwards survive reboots. Forwards to a disabled VLAN are held until it is enabled again.
The monitor’s Settings → Protection page lists, adds and removes forwards too.
MAC filtering rules
Section titled “MAC filtering rules”dtvsol firewall listThis shows the per-MAC rules the router keeps for registered clients, and the whole forwarding chain. The monitor’s Settings → Protection page lists them too.