Hi,
I must be missing something very basic. I want to block all traffic on my RB750 except traffic with a specific src or dst address. In order to verify this I am first trying to block all traffic and I cannot block traffic. Setup is:
[admin@MikroTik] > /int print
Flags: D - dynamic, X - disabled, R - running, S - slave
NAME TYPE MTU L2MTU MAX-L2MTU
0 ether1-gateway ether 1500 1600 4076
1 R ether2-master-local ether 1500 1598 2028
2 ether3-slave-local ether 1500 1598 2028
3 R ether4-slave-local ether 1500 1598 2028
4 R ether5-slave-local ether 1500 1598 2028
[admin@MikroTik] >
I am plugged as follows
RB750
port 0: unconnected
port 1: Laptop1 eth0 ip:192.168.88.2 for management access to router
port 2: unconnected
port 3: Laptop1 eth1 ip: 10.4.29.58
port 4: Laptop2 eth0 ip: 10.4.29.57
I have a rule to drop everything as shown below but can still ping:
Pinging 10.4.29.57 with 32 bytes of data:
Reply from 10.4.29.57: bytes=32 time<1ms TTL=128
Reply from 10.4.29.57: bytes=32 time<1ms TTL=128
Reply from 10.4.29.57: bytes=32 time<1ms TTL=128
Reply from 10.4.29.57: bytes=32 time<1ms TTL=128
Reply from 10.4.29.57: bytes=32 time<1ms TTL=128
Network on laptop1, what I am pinging FROM.
Ethernet adapter Local Area Connection:
[...]
IPv4 Address. . . . . . . . . . . : 10.4.29.58(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.252.0
Default Gateway . . . . . . . . . : 0.0.0.0
Firewall rules - Default chain=input temporarily disabled:
[admin@MikroTik] > /ip firewall filter print
Flags: X - disabled, I - invalid, D - dynamic
0 ;;; drop everything
chain=forward action=drop
1 X ;;; default configuration
chain=input action=accept protocol=icmp
2 X ;;; default configuration
chain=input action=accept connection-state=established
3 X ;;; default configuration
chain=input action=accept connection-state=related
4 X ;;; default configuration
chain=input action=drop in-interface=ether1-gateway
[admin@MikroTik] >
It seems that first one, rule zero, should prevent me from pinging the other system but it's not. I think I'm missing something here... Any help would be appreciated. Once I can block then I would add a firewall rule before this that accepts anything with a src or dst address of the end device 10.4.29.57 and I think that would block all traffic except for that specific IP. Once I get this working it needs to go into an actual environment but now I'm just trying to get the setup figured out.
Thanks,
Jim