Community discussions

MikroTik App
 
SystemErrorMessage
Member
Member
Topic Author
Posts: 383
Joined: Sat Dec 22, 2012 9:04 pm

Feature request: Domains in IP firewall address

Sat Nov 08, 2014 3:00 am

I've noticed you can add a domain in the address field in IP firewall but when you save it routerOS resolves the IP and works on all traffic relating to that IP address instead of a domain. I ask this because i want to be able to implement filters such as blocking any traffic from known malware sites but these sites could be hosted on legitimate providers such as amazon which may use the same ip address as legitimate sites.

This may also help with routing some traffic between own sites for example if i wanted the default homepage on my network or hotspot to be my website that is hosted on a public web server somewhere else
 
IntrusDave
Forum Guru
Forum Guru
Posts: 1286
Joined: Fri May 09, 2014 4:36 am
Location: Rancho Cucamonga, CA

Re: Feature request: Domains in IP firewall address

Sat Nov 08, 2014 6:38 am

the problem with that is that the filter is an IP filter. not a domain filter.

I think what you should be doing is setting a static DNS entry for the domain names you want filtered, pointing them to 127.0.0.1.
 
neticted
Member Candidate
Member Candidate
Posts: 137
Joined: Wed Jan 04, 2012 10:36 am

Re: Feature request: Domains in IP firewall address

Sat Nov 08, 2014 11:37 am

You can use Layer 7 protocol rules to catch domains. vut be careful as it needs lots of resources.
 
SystemErrorMessage
Member
Member
Topic Author
Posts: 383
Joined: Sat Dec 22, 2012 9:04 pm

Re: Feature request: Domains in IP firewall address

Sat Nov 08, 2014 3:30 pm

I dont want to use L7 because of the resource usage. I would prefer to intercept the requests but not through L7.

Sometimes IP addresses can change so it can invalidate firewall rules based on IP.

Who is online

Users browsing this forum: adwlodaro, complexxL9, dervomsee and 195 guests