I’ve just learned how to slice the backed chicken and realized that it has no hands and knees bend to the back not to the front … could you provide me more info and notes how to cook it better? Setting small restaurant.
How ISP admin with pfsense and other brands experience is not able to find proper info?
not much to digest here - these are the def.conf FW rules on a RB
CCR/CRS are shipped with no default config!
PLEASE, for [insert something here] sake - get familiar and get GOOD with mikrotik, routing and firewalling before playing (W)ISP
try out your plans/ideas/setups in a virtual or lab environment before would be a good “green field” practicing ground thb.
for example EVE-NG
What exactly do you think I’m doing?? I’ve set up a lab! I’m getting familiar with Mikrotik. I’m getting familiar with routing, firewalling, and VLANs… before as you say, “playing WISP”.. whatever the [insert something here] that means??
I swear.. open mouth, insert foot kind of guy I see. I got my examples (From others here thanks) that I can study now.. It was a simple question, please just go away and troll someone else now.
@borg357
Everything that has been written is perfectly useless…
It is not enough to take a small piece of something to understand everything.
Before “something”, for example, you first need to understand what interface groups are, that are written to the firewall.
If you copy & paste (regardless if you understand the rules, or not) it’s absolutely useless if you don’t first create the groups and configure everything else.
So first everything else needs to be configured well before worrying about the firewall.
And about WISP comment of other users,
obviously if you write
Setting up a basic small WISP
is logical than others they think, “here’s another novice who can’t even configure a firewall himself”,
given the example of other WISPs who don’t know what they’re doing…
he certainly didn’t want to be an offense against you, but an obvious concern that another ass–le doesn’t go “up in the air”…
Im NOT copying and pasting. I have discovered that I can digest and understand more while looking at exports. In fact, even as I understand basic concepts such as In and Out.. By doing my own exports and looking at it in a text editor, it helps me understand even more about what’s going on even after I set up my own router. Perhaps that’s something about the way my mind works, or the programmer in me, or maybe something else.
I asked simply about posting some firewall examples… I didn’t need assumptions about me not setting up a lab (which was assumed incorrect), or comments about working with a WISP in which people have NO understanding of my capabilities or any other comments. Simply just move on if you can’t provide the answer which is a copy and paste on your end.
Sorry to be snarky, but this was simply a pretty straightforward example of looking at other people’s firewalls in pure export format, nothing more needs to be assumed about it.
Since no one is perfect and anyone can make mistakes no matter how experienced,
I don't think other ISPs give you "a copy of own house keys" if you allow the ANALogy
Take us less seriously, you're between friends and as–les...
Seriously now:
The concept must be, starting from the default one, BLOCK EVERYTHING and allow only what is necessary...
NEVER block ICMP for no reason (except big Large fragmented ICMP that for sure do not are Path MTU Discovery...)
Prvent generate IP spoofing from your side, and do not accept spoofed packets.
Take a look here
But is all useless if you do not provide public IPs on your LAN.