Hi , i Want to Limit ICMP Packet They Are Input To Router .
I Want 5 ICMP From a Source Be accept And Other Be Deny .
Reply From Router ...
Reply From Router ...
Reply From Router ...
Reply From Router ...
Reply From Router ...
Request Time Out ...
Request Time Out ...
Request Time Out ...
Request Time Out ...
...
I Create A Rule With this Properties , but not Working ...
Ip firewall filter add chain=input action=accept protocol=icmp limit=5,5
Somebody help me Please !
Mark icmp packet
/ip firewall mangle
add action=mark-connection chain=prerouting comment=ICMP disabled=no new-connection-mark=ICMP-CM passthrough=yes protocol=icmp
add action=mark-connection chain=forward comment="" disabled=no new-connection-mark=ICMP-CM passthrough=yes protocol=icmp
add action=change-dscp chain=prerouting comment="" connection-mark=ICMP-CM disabled=no new-dscp=5 protocol=icmp
add action=change-dscp chain=forward comment="" connection-mark=ICMP-CM disabled=no new-dscp=5 protocol=icmp
add action=mark-packet chain=prerouting comment="" connection-mark=ICMP-CM disabled=no new-packet-mark=PRE-ICMP-PM passthrough=no protocol=icmp
add action=mark-packet chain=forward comment="" connection-mark=ICMP-CM disabled=no new-packet-mark=POST-ICMP-PM passthrough=no protocol=icmp
Mark Connection and bypass ICMP
/ip firewall mangle
add action=mark-connection chain=prerouting comment=C.ALL-CN disabled=no new-connection-mark=ALL-CN-PRE passthrough=yes protocol=!icmp src-address="your private network"
add action=mark-connection chain=forward comment="" disabled=no dst-address="your private network" new-connection-mark=ALL-CN-POST passthrough=yes protocol=!icmp
add action=mark-packet chain=prerouting comment=C.ALL-P connection-mark=ALL-CN-PRE disabled=no new-packet-mark=C.ALL-PRE passthrough=yes src-address="your private network"
add action=mark-packet chain=forward comment="" connection-mark=ALL-CN-POST disabled=no dst-address="your private network" new-packet-mark=C.ALL-POST passthrough=yes
sample.jpg
with the correct settings in Mangel & queue should have good results
nb: from my experience to use simple queues make the ping delay is large and very bad for online gaming performance
try using the queue trees if you have lots of clients ( pcq kind is good to try)
good luck !
You do not have the required permissions to view the files attached to this post.