How To Prevent Port Scanning on MikroTik | Lecture-80

In MikroTik Router OS the PSD format is: psd = WeightThreshold, TimeWindow, LowPortWeight, HighPortWeight For the rule: psd=36,3s,6,6 Parameter Meaning Parameter Value Explanation Weight Threshold 36 Total score needed before the IP is detected as a port scanner Time Window 3s Detection window is 3 seconds Low Port Weight 6 Ports 0–1023 add 6 points each High Port Weight 6 Ports 1024–65535 add 6 points each What This Rule Means in Practice Because each port gives 6 points, the attacker must scan 6 different ports within 3 seconds to be detected. Difference vs Common Rule Common rule used by admins: Psd=21,3s,3,1 Rule Sensitivity 21,3s,3,1 More sensitive (detects scanners faster) 36,3s,6,6 Less sensitive but reduces false positives Real-World Behavior The rule psd=36,3s,6,6: • Detects fast scanners (like those from Nmap) • Avoids blocking normal users • Requires 6 port probes in 3 seconds before triggering Simple Explanation This rule means: If an IP tries 6 different ports within 3 seconds, MikroTik marks it as a port scanner. This configuration is moderate detection—not too aggressive and not too weak. #kamranawan #mikrotik #mikrotikrouter #mikrotiktutorial