amigo primeiro tenta bloquear o sent deauth
Código :
/ip firewall filter
add action=tarpit chain=input comment="bloqueio de sent deauth " \
connection-limit=3,32 disabled=no protocol=tcp src-address-list=\
blocked-addr
segundo no ultimo log esta claramente uma tentativa de invasão
alguem esta tentando logar via ssh no seu mk .
para bloquear segue as regras
primeiro desativa os tipos de serviços que vc nao ultiliza
em ip/services ..
segundo coloca essas regras .
Código :
/ ip firewall filter
add chain=input protocol=tcp dst-port=22 src-address-list=acesso_ssh \
action=drop comment="Acesso_ssh" disabled=no
add chain=input protocol=tcp dst-port=21 src-address-list=ftp_blacklist \
action=drop comment="drop ftp brute forcers" disabled=no
add chain=output protocol=tcp content="530 Login incorrect" \
dst-limit=1/1m,9,dst-address/1m action=accept comment="" disabled=no
add chain=output protocol=tcp content="530 Login incorrect" \
action=add-dst-to-address-list address-list=ftp_blacklist \
address-list-timeout=3h comment="" disabled=no
add chain=input protocol=tcp dst-port=22 src-address-list=black_list \
action=drop comment="Drop SSH Brute Forcers" disabled=no
add chain=input protocol=tcp dst-port=22 connection-state=new \
src-address-list=ssh_stage3 action=add-src-to-address-list \
address-list=black_list address-list-timeout=1d comment="" disabled=no
add chain=input protocol=tcp dst-port=22 connection-state=new \
src-address-list=ssh_stage2 action=add-src-to-address-list \
address-list=ssh_stage3 address-list-timeout=1m comment="" disabled=no
add chain=input protocol=tcp dst-port=22 connection-state=new \
src-address-list=ssh_stage1 action=add-src-to-address-list \
address-list=ssh_stage2 address-list-timeout=1m comment="" disabled=no
add chain=input protocol=tcp dst-port=22 connection-state=new \
action=add-src-to-address-list address-list=ssh_stage1 \
address-list-timeout=1m comment="" disabled=no
add chain=forward protocol=tcp dst-port=22 src-address-list=ssh_blacklist \
action=drop comment="drop ssh brute downstream" disabled=no
com essas regras eu duvido que volte a aparecer esse tipo de log no seu mk .
espero ter ajudado .