Skip to content

Protection

Only the networks on the allow-list can reach the router’s API (port 8880), the web monitor (port 8881) and the MK-api listener (port 8728). Everything else is dropped. Localhost is always allowed.

Terminal window
dtvsol protect list
dtvsol protect add XXX.XXX.XXX.0/24 "NOC"
dtvsol protect add XXX.XXX.XXX.25 "billing server"
dtvsol protect del XXX.XXX.XXX.25

Add the networks of your NOC, your billing server and any wall screens.

The monitor’s Settings → Protection page shows and changes the same list. It refuses to remove the entry your own browser comes through, and never removes localhost.

fail2ban bans addresses after repeated failed logins: SSH, bad API keys, and failed monitor logins (all written to /opt/dtvsol/log/auth.log).

Terminal window
dtvsol fail2ban
dtvsol fail2ban unban XXX.XXX.XXX.23

The monitor also slows down guessing by itself: after 5 failed logins from one address in 10 minutes, that address has to wait.

Everything the router does for a subscriber keys on its address: the speed limit, a suspension, accounting and the CGNAT log. A CPE that types in another address would escape all of them. With anti-spoofing on, a packet is forwarded only when its source MAC and IP are a pair the router knows on that VLAN. ARP is checked the same way. Everything else is dropped and logged with the MAC that sent it.

Terminal window
dtvsol antispoof # status: per-VLAN mode, bindings, drops in the last hour
dtvsol antispoof on # enforce on every VLAN DHCP serves
dtvsol antispoof off # remove every rule; settings are kept

Modes:

  • strict: registered subscribers only. Unknown devices still get DHCP (so they show in dtvsol ips) and nothing else.
  • dynamic: registered subscribers are locked to their address, and unknown devices may use the address DHCP leased them.
Terminal window
dtvsol antispoof set mode strict
dtvsol antispoof set log on
dtvsol antispoof set exempt 10.0.0.0/30 # e.g. an OLT's relay address
dtvsol antispoof iface vlan100 dynamic # one VLAN's mode: strict|dynamic|off|default
dtvsol antispoof log 2h # who was dropped: MAC, address, VLAN

Services are bound by their port interface and address, not by MAC. For IPv6, a client’s reserved address, its DHCPv6 address and its delegated prefix are bound to its MAC; link-local always passes; router advertisements and redirects from subscribers are dropped.

The rules follow the DHCP lease files by themselves. dtvsol antispoof sync rebuilds them now.

In the monitor, Settings → Protection has the global switch, the mode, logging, the exempt list and a per-interface mode. Turning anti-spoofing off asks for a second click.

Forward a public port to a subscriber (inbound DNAT):

Terminal window
dtvsol portforward list
dtvsol portforward add tcp 8443 100.64.16.9 443 XXX.XXX.XXX.64 "customer camera"
dtvsol portforward del tcp 8443 XXX.XXX.XXX.64

Arguments: protocol, public port, subscriber address, subscriber port, and optionally the public address (any when left out) and a comment. Forwards survive reboots. Forwards to a disabled VLAN are held until it is enabled again.

The monitor’s Settings → Protection page lists, adds and removes forwards too.

Terminal window
dtvsol firewall list

This shows the per-MAC rules the router keeps for registered clients, and the whole forwarding chain. The monitor’s Settings → Protection page lists them too.

This site was written with the help of AI and checked by our team.