harden_services
Disable insecure services like telnet, ftp, and www on MikroTik routers, and restrict SSH/Winbox management to specified subnets. Supports dry-run and rollback.
Instructions
Common hardening. disable_services default: telnet, ftp, www, api, api-ssl (SSH and Winbox stay on; SSH can never be disabled here). restrict_mgmt_to: subnets allowed to use SSH/Winbox (ask the user), comma-separated, '/prefix' or dotted mask. Refused if this computer's IP is not inside them.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | No | router | |
| dry_run | No | ||
| disable_upnp | No | ||
| disable_services | No | ||
| restrict_mgmt_to | No | ||
| rollback_minutes | No | ||
| ssh_strong_crypto | No | ||
| mac_access_lan_only | No | ||
| disable_socks_proxy_bwtest | No | ||
| neighbor_discovery_lan_only | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |