I bought RB951G two months ago, I am kinda new in Mikrotik firewall rules. I am using the following rules:
/ip firewall filter
add action=accept chain=forward connection-state=established,related in-interface=WAN out-interface=Bridge
add action=accept chain=forward in-interface=Bridge out-interface=Bridge
add action=accept chain=forward in-interface=Bridge out-interface=WAN
add action=accept chain=input in-interface=Bridge
add action=accept chain=input connection-state=established,related in-interface=WAN
add action=drop chain=input log=yes
add action=drop chain=forward log=yes
but I get a lot of traffic being dropped on WAN especially if it has (unknown) interface name, the following is a sample of DROP log:
02:40:49 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 8.8.8.8:53->192.168.0.34:5678, len 80
02:40:58 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto TCP (ACK,FIN,PSH), 104.125.75.201:443->192.168.0.34:53709, len 71
02:41:18 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto 2, 192.168.0.20->224.0.0.1, len 28
02:42:47 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 192.168.0.20:53->192.168.0.34:5678, len 80
02:42:49 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 8.8.8.8:53->192.168.0.34:5678, len 80
02:43:23 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto 2, 192.168.0.20->224.0.0.1, len 28
02:44:47 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 192.168.0.20:53->192.168.0.34:5678, len 80
02:44:49 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 8.8.8.8:53->192.168.0.34:5678, len 80
02:45:28 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto 2, 192.168.0.20->224.0.0.1, len 28
02:46:47 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 192.168.0.20:53->192.168.0.34:5678, len 80
02:46:49 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 8.8.8.8:53->192.168.0.34:5678, len 80
02:47:33 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto 2, 192.168.0.20->224.0.0.1, len 28
02:48:47 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 192.168.0.20:53->192.168.0.34:5678, len 80
02:48:49 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 8.8.8.8:53->192.168.0.34:5678, len 80
02:48:57 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto TCP (ACK,PSH), 104.125.75.201:443->192.168.0.34:53710, len 71
02:49:00 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 192.168.0.20:67->192.168.0.34:68, len 328
02:49:38 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto 2, 192.168.0.20->224.0.0.1, len 28
02:50:47 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 192.168.0.20:53->192.168.0.34:5678, len 80
02:50:49 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 8.8.8.8:53->192.168.0.34:5678, len 80
02:51:43 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto 2, 192.168.0.20->224.0.0.1, len 28
02:52:47 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 192.168.0.20:53->192.168.0.34:5678, len 80
02:52:49 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 8.8.8.8:53->192.168.0.34:5678, len 80
02:53:48 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto 2, 192.168.0.20->224.0.0.1, len 28
02:54:47 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 192.168.0.20:53->192.168.0.34:5678, len 80
02:54:49 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 8.8.8.8:53->192.168.0.34:5678, len 80
02:55:53 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto 2, 192.168.0.20->224.0.0.1, len 28
02:56:47 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 192.168.0.20:53->192.168.0.34:5678, len 80
02:56:49 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 8.8.8.8:53->192.168.0.34:5678, len 80
02:57:58 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto 2, 192.168.0.20->224.0.0.1, len 28
02:58:38 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto TCP (ACK,FIN,PSH), 157.240.20.38:443->192.168.0.34:37152, len 91
02:58:44 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto TCP (ACK,FIN,PSH), 157.240.20.35:443->192.168.0.34:47956, len 91
02:58:47 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 192.168.0.20:53->192.168.0.34:5678, len 80
02:58:49 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 8.8.8.8:53->192.168.0.34:5678, len 80
02:58:49 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto TCP (ACK,FIN,PSH), 157.240.20.19:443->192.168.0.34:52966, len 91
02:58:52 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto TCP (ACK,FIN,PSH), 157.240.20.15:443->192.168.0.34:46552, len 91
02:58:58 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto TCP (ACK,FIN,PSH), 157.240.20.19:443->192.168.0.34:52965, len 91
02:59:00 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto TCP (ACK,FIN,PSH), 157.240.20.38:443->192.168.0.34:37152, len 91
02:59:13 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto TCP (ACK,FIN,PSH), 157.240.20.35:443->192.168.0.34:47956, len 91
02:59:17 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto TCP (ACK,FIN,PSH), 157.240.20.19:443->192.168.0.34:52966, len 91
02:59:37 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto TCP (ACK,FIN,PSH), 37.237.96.210:443->192.168.0.34:52936, len 91
02:59:43 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto TCP (ACK,FIN,PSH), 37.237.96.209:443->192.168.0.34:50773, len 91
02:59:43 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto TCP (ACK,FIN,PSH), 37.237.96.209:443->192.168.0.34:50774, len 91
02:59:59 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto TCP (ACK,FIN,PSH), 37.237.96.210:443->192.168.0.34:52936, len 91
03:00:03 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto 2, 192.168.0.20->224.0.0.1, len 28
03:00:13 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto TCP (ACK,FIN,PSH), 37.237.96.209:443->192.168.0.34:59172, len 83
03:00:47 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 192.168.0.20:53->192.168.0.34:5678, len 80
03:00:49 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto UDP, 8.8.8.8:53->192.168.0.34:5678, len 80
03:00:50 firewall,info input: in:WAN out:(unknown 0), src-mac dc:9f:db:39:7d:cb, proto TCP (ACK,FIN,PSH), 157.240.20.15:443->192.168.0.34:35004, len 83
I get internet service through a nanostation which its LAN is connected to WAN port (ether1) on the Mikrotik RB951G
ISP > Nanostation > RB951G > My PC
Nanostation IP address is 192.168.0.20
Nanostation LAN MAC is dc:9f:db:39:7d:cb
Mikrotik WAN IP address is 192.168.0.34
Mikrotik LAN IP address is 10.11.12.1
Flags: D - dynamic, X - disabled, R - running, S - slave
# NAME TYPE ACTUAL-MTU L2MTU
0 RS ether2 ether 1500 1598
1 RS ether3 ether 1500 1598
2 S ether4 ether 1500 1598
3 S ether5 ether 1500 1598
4 R WAN ether 1500 1598
5 RS Wireless wlan 1500 1600
6 R Bridge bridge 1500 1598
Would you please help me to figure out why I have so much traffic being dropped? Also what is out:(unknown 0), am I supposed to have an interface called unknown??