Firewall and NAT

On a properly configured device detect-internet either:
a) does nothing
or
b) may - in some cases - create isssues

on a configuration like yours it may actually do something useful (i.e. allow connection from the outside, this is actually the reason why the good Mikrotik guys made it) but at the same time it is a symptom that your device is not properly configured.

It is not very useful, when you change something, that you describe that something without posting the new, complete configuration (and PLEASE, learn to enclose it in “code” tags, see the instructions here: http://forum.mikrotik.com/t/forum-rules/173010/1 )

The point is that:

  1. we don’t trust your report :open_mouth:
  2. even if we trusted you :slight_smile: , you may accidentally wrongly describe something or omit something that you have done in the meantime.

Something that you might want to consider is that the default set of rules in /ip firewall filter (for SoHo devices) that you can find here as a reference:
http://forum.mikrotik.com/t/buying-rb1100ahx4-dude-edition-questions-about-firewall/148996/4
consists of 11 (eleven) rules.
Mikrotik publishes the results of tests made with 25 (twentyfive) rules in /ip firewall filter.
And it is rare to see configurations posted on the forum with more.

The ones you posted (that are a subset of the ones you actually have) are (if I have counted them correctly) 191 (onehundredandninetynine).

I would suspect that you are overdoing it.
Or maybe your connection was too d@mn fast and you needed to find a way to slow it down. :wink:

And of course. JFYI:
http://forum.mikrotik.com/t/the-twelve-rules-of-mikrotik-club/182164/1