Community discussions

MikroTik App
 
lopan
just joined
Topic Author
Posts: 5
Joined: Tue Nov 30, 2010 11:50 pm

Stateful Firewall

Tue Nov 30, 2010 11:56 pm

Hello!

Mikrotik has a Stateful Firewall like a Feature, right?

There are any method to shutdown this feature?

A Stateful Firewalls can cause instability in multihomed networks...

Best regards,
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7056
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: Stateful Firewall

Wed Dec 01, 2010 9:22 am

By default there are no firewall rules.
 
changeip
Forum Guru
Forum Guru
Posts: 3830
Joined: Fri May 28, 2004 5:22 pm

Re: Stateful Firewall

Wed Dec 01, 2010 10:10 am

disable connection-tracking if you dont need nat or stateful tracking. it will save cpu, etc.
 
lopan
just joined
Topic Author
Posts: 5
Joined: Tue Nov 30, 2010 11:50 pm

Re: Stateful Firewall

Wed Dec 01, 2010 10:51 am

By default there are no firewall rules.
An Stateful Firewall not depend any active rule. If the firewall has the State module active you have an Stateful Firewall. In Linux work like this, but I don't know about Mikrotik.

Thanks,
 
lopan
just joined
Topic Author
Posts: 5
Joined: Tue Nov 30, 2010 11:50 pm

Re: Stateful Firewall

Wed Dec 01, 2010 10:55 am

disable connection-tracking if you dont need nat or stateful tracking. it will save cpu, etc.
Can you explain more about your answer? Where are I disable the connection-tracking?

Thanks,
 
changeip
Forum Guru
Forum Guru
Posts: 3830
Joined: Fri May 28, 2004 5:22 pm

Re: Stateful Firewall

Wed Dec 01, 2010 6:40 pm

/ip firewall connection tracking
set enabled=no

things that depends on conntrack that I know of -

nat
simple queues
(queue tree? - not sure)
certain selections in firewall rules
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26385
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Re: Stateful Firewall

Thu Dec 02, 2010 8:22 am

things that depends on conntrack that I know of -

nat
simple queues
(queue tree? - not sure)
certain selections in firewall rules
full list here: http://wiki.mikrotik.com/wiki/Manual:Co ... n_tracking
 
changeip
Forum Guru
Forum Guru
Posts: 3830
Joined: Fri May 28, 2004 5:22 pm

Re: Stateful Firewall

Thu Dec 02, 2010 5:54 pm

Is PCQ requiring conntrack at all? It seems like the burst time isnt working properly without it.
 
User avatar
janisk
MikroTik Support
MikroTik Support
Posts: 6263
Joined: Tue Feb 14, 2006 9:46 am
Location: Riga, Latvia

Re: Stateful Firewall

Thu Dec 09, 2010 4:15 pm

anyway, "multihomed" or as we know it - multi-path network and ECMP can be unstable if you are using NAT, if you are using global IP addresses - you are good to go.

Also, to overcome this drawback MikroTik has introduced PCC:
http://wiki.mikrotik.com/wiki/PCC

so you can use multi-path in your network and still have everything working.
 
lopan
just joined
Topic Author
Posts: 5
Joined: Tue Nov 30, 2010 11:50 pm

Re: Stateful Firewall

Thu Dec 09, 2010 4:24 pm

anyway, "multihomed" or as we know it - multi-path network and ECMP can be unstable if you are using NAT, if you are using global IP addresses - you are good to go.

Also, to overcome this drawback MikroTik has introduced PCC:
http://wiki.mikrotik.com/wiki/PCC

so you can use multi-path in your network and still have everything working.
OSPF can make this only (PCC)...

http://en.wikipedia.org/wiki/Multihoming - Multiple Links, Multiple IP address

Who is online

Users browsing this forum: No registered users and 53 guests