Maybe you have forwarded the https 443 port from wan to internal lan device ?
This will be just one cause
updated alreadyupdate to the latest version and check
rodolfo, can you post here your mangle and queue three ?thanks rmichael.
do you think in my implementation there is something wrong ?
Encryption is disabled, connection tracking is disabled...seems like it's due to pppoe encryption - try to disable it and see the result
at first, upgrade to 3.30
could you please post here your CPU graph?
I did it , but ...outside clients steel connectedremove src-address=0.0.0.0
all it`s correct ...i stoped the proxy server because too manny connection from outside (300 clients from outside)make sure you move this rule to the top of your firewall, make sure you specified the correct in-interface
I put this rule first in firewall filter but is never hit-ed, and outside clients is steel connected to my proxyLets say proxy port is 8080 and public interface is "internet"
/ip firewall filter
add chain=input dst-port=8080 protocol=tcp in-interface=internet action=drop
proxy port is 3128Lets say proxy port is 8080 and public interface is "internet"
/ip firewall filter
add chain=input dst-port=8080 protocol=tcp in-interface=internet action=drop
add firewall rule to block access to your proxy from outside
u can be more specific, pleez?either block the entire DNS port, or add a rule to add SRC-ADDRESS to any IP that has too many DNS requests.