Hello!
Mikrotik has a Stateful Firewall like a Feature, right?
There are any method to shutdown this feature?
A Stateful Firewalls can cause instability in multihomed networks...
Best regards,
An Stateful Firewall not depend any active rule. If the firewall has the State module active you have an Stateful Firewall. In Linux work like this, but I don't know about Mikrotik.By default there are no firewall rules.
Can you explain more about your answer? Where are I disable the connection-tracking?disable connection-tracking if you dont need nat or stateful tracking. it will save cpu, etc.
full list here: http://wiki.mikrotik.com/wiki/Manual:Co ... n_trackingthings that depends on conntrack that I know of -
nat
simple queues
(queue tree? - not sure)
certain selections in firewall rules
OSPF can make this only (PCC)...anyway, "multihomed" or as we know it - multi-path network and ECMP can be unstable if you are using NAT, if you are using global IP addresses - you are good to go.
Also, to overcome this drawback MikroTik has introduced PCC:
http://wiki.mikrotik.com/wiki/PCC
so you can use multi-path in your network and still have everything working.