Community discussions

MikroTik App
 
savage
Forum Guru
Forum Guru
Topic Author
Posts: 1264
Joined: Mon Oct 18, 2004 12:07 am
Location: Cape Town, South Africa
Contact:

PCQ Examples

Tue Nov 20, 2007 8:54 am

Hi,

Just a quick arb question I think... In all the examples I've seen... There is a connection-mark as well as a packet-mark. Why?

Surely, if you match on packets only it should include the initial connection regardless? I'm just wondering whether two rules are actually needed or not...
 
User avatar
Chupaka
Forum Guru
Forum Guru
Posts: 8709
Joined: Mon Jun 19, 2006 11:15 pm
Location: Minsk, Belarus
Contact:

Re: PCQ Examples

Tue Nov 20, 2007 3:30 pm

tcp connection is virtually two opposite streams: from A to B and from B to A.
if you mark only packets, you should use two rules: (scr=A dst=B) and (src=B dst=A). or you just mark the connection, and then mark all of the connection's packets =)
plus, when using NAT, the router watches connection's addresses, not you

Who is online

Users browsing this forum: 4l4R1, Google [Bot], hazem, HeinoHomm, nbotov and 210 guests