hi guys
I dont know why for some reason authored users cannot ping any ip beyond router, it seems that ICMP blocked but I can’t find the culprit in my firewall.
thanks
/ ip firewall
set input name="input" policy=accept comment=""
set forward name="forward" policy=accept comment=""
set output name="output" policy=accept comment=""
add name="hotspot-temp" policy=none comment="limit unauthorized hotspot clients"
add name="hotspot" policy=none comment="account authorized hotspot clients"
/ ip firewall rule forward
add in-interface=onboard action=jump jump-target=hotspot-temp comment="limit access for \
unauthorized hotspot clients" disabled=no
add action=jump jump-target=hotspot comment="account traffic for authorized hotspot clients" \
disabled=no
/ ip firewall rule hotspot
/ ip firewall rule hotspot-temp
add flow=hs-auth action=return comment="return, if connection is authorized" disabled=no
add protocol=icmp action=return comment="allow ping requests" disabled=no
add dst-address=:53 protocol=udp action=return comment="allow dns requests" disabled=no
add action=reject comment="reject access for unauthorized hotspot clients" disabled=no
/ ip firewall rule input
add in-interface=onboard dst-address=:80 protocol=tcp action=jump jump-target=hotspot \
comment="account traffic from hotspot clients to hotspot servlet" disabled=no
add in-interface=onboard dst-address=:80 protocol=tcp action=accept comment="accept requests \
for hotspot servlet" disabled=no
add in-interface=onboard dst-address=:67 protocol=udp action=accept comment="accept requests \
for local DHCP server" disabled=no
add in-interface=onboard action=jump jump-target=hotspot-temp comment="limit access for \
unauthorized hotspot clients" disabled=no
/ ip firewall rule output
add src-address=:80 out-interface=onboard protocol=tcp action=jump jump-target=hotspot \
comment="account traffic from hotspot servlet to hotspot clients" disabled=no
/ ip firewall service-port
set ftp ports=21 disabled=no
set pptp disabled=no
set gre disabled=no
set h323 disabled=yes
set mms disabled=no
set irc ports=6667 disabled=no
set quake3 disabled=no
set tftp ports=69 disabled=no
/ ip firewall mangle
/ ip firewall src-nat
add src-address=192.168.1.0/32 dst-address=:!80 out-interface=ether2 protocol=tcp flow=hs-auth \
action=masquerade comment="" disabled=no
/ ip firewall dst-nat
add dst-address=:53 protocol=udp action=redirect comment="intercept all DNS requests" \
disabled=no
add in-interface=onboard protocol=tcp flow=!hs-auth action=redirect to-dst-port=80 \
comment="redirect unauthorized hotspot clients to hotspot service" disabled=no
add in-interface=onboard dst-address=:80 protocol=tcp action=redirect to-dst-port=3128 \
comment="transparent HTTP proxy for hotspot clients" disabled=no
add dst-address=192.168.0.1/32:4600-4700 flow=hs-auth action=nat to-dst-address=192.168.1.101 \
comment="" disabled=yes
/ ip firewall connection tracking
set enabled=yes tcp-syn-sent-timeout=2m tcp-syn-received-timeout=1m tcp-established-timeout=5d \
tcp-fin-wait-timeout=2m tcp-close-wait-timeout=1m tcp-last-ack-timeout=30s \
tcp-time-wait-timeout=2m tcp-close-timeout=10s udp-timeout=30s udp-stream-timeout=3m \
icmp-timeout=30s generic-timeout=10m