Networking · TIBCO · Unix

The settings that break your infrastructure never appear in the config.

Vendor defaults ship enabled and stay invisible. Every guide here is run against equipment I operate, with the commands, the actual output, and what to do when the documentation and the device disagree.

gw-edge · RouterOS 7.14
live audit
[admin@gw-edge] > /ip service print where disabled=no # NAME PORT 0 telnet 23 1 ftp 21 2 www 80 3 ssh 22 4 api 8728 FAILtelnet, ftp, www and api reachableenabled by default — plaintext credentials [admin@gw-edge] > /tool mac-server print FAILMAC-Telnet allowed on all interfacesbypasses every firewall rule you wrote [admin@gw-edge] > /ip neighbor discovery-settings print FAILdiscovery advertising on the WANmodel, RouterOS version, identity — to anyone [admin@gw-edge] > /tool bandwidth-server print FAILbandwidth-test server accepting sessionsa CPU exhaustion primitive, on by default 4 findings. None appear in /export.

NET · MikroTik RouterOS · Cisco IOS

Networking

Hardening, firewall design, and the defaults that ship enabled but never appear in an export.

All 2 →
NET NET-001

MikroTik Security Hardening: 10 Checks Most People Miss

Ten RouterOS defaults that stay enabled after a clean install, why an /export will never show them to you, and the exact command to close each one.

Verified on RouterOS 7.14 6 min

Two articles a month

New guides go out the day they publish. No digest, no roundup, no forwarding other people's links.

Unsubscribe in one click. The list is never shared or sold.