what am i missing. cannot get firewall working on ccr1036

Need expert help.. I am setting up a ccr1036 and for the life of me cannot get the firewall to work.. it configured everything exactly like my ccr1016 where the firewall is working.
Eventually I want to use the sftp+ ports to get faster than 1g connections, but I even tested on the standard ethernet ports just like my ccr1016.

I have confirmed fast path is off, and both are in bridging mode, as I need a bridging firewall as my default gw is on the same subnet as my 13 private ips.

see the attached pics.. Pulling my hair out here. thanks..

thanks in advance.. i ( i also added the pics as png attachments as the inline dont seem to be coming up)

Screenshot 2023-04-02 103558.png
Screenshot 2023-04-02 103535.png
Screenshot 2023-04-02 103731.png
Screenshot 2023-04-02 103653.png
here is testing showing the firewall NOT working on the ccr1026
Screenshot 2023-04-02 103627.png
here is the testing showing firewall working on my ccr1016
Screenshot 2023-04-02 104038.png

Ur kidding me right?
You bought an over $1000 router and you cannot provide a decent network diagram or export of the config?
Moreover don’t you have certification/training… I mean thats an expensive router for a homeowner.
Why dont you switch, I will send you a hex already setup and you send me the 1036. :slight_smile:

firured it ouit.. it was this setting. that does not show up in the interface.. the only way seems to be set it in the command line, and it is a strange one to set.. took me forever to figure out the set and get options dont work.. you need to use the edit which brings it up in vi

the use-ip-firewall needed to be set..

am i missing something ie is there a way to do this in the ui?
Screenshot 2023-04-02 111841.png

thanks .. very helfull, i have public ips and a mail server.. you cannot use a switch dipshit..

if you dont have anything to contribute DONT

and there really are NO home brew routers that do bridging firewalls other than DDWRT and that cannot keep up wioth the trqaffic I need

Any anyway those are no easier to setup, even harder as there is no UI for that kind of config.

Yes. The IP firewall only operates on packets forwarded through, or input/output to/from, the Mikrotik itself. Enabling that setting forces packets bridged to be also processed unless handled by hardware offload (not applicable to the CCR1036). See packet flow here https://help.mikrotik.com/docs/display/ROS/Packet+Flow+in+RouterOS.

If you do not need stateful firewalling the more limited bridge filter may be sufficient.


am i missing something ie is there a way to do this in the ui?

In Winbox select Bridge, in the Bridge window select the Bridge tab, there is a Settings button to the right of the usual Add / Remove / Enable / Disable / Comment / Filter buttons.

Okay let me hold your hands then.

Open mouth insert spoon…
Pretty please provide your config so that I may assist the almighty Igkahn ( also known as cCmOoaPB → “cannot configure myself out of a paper bag” )
/export file=anynameyouwish ( minus router serial number and any public WANIP information ).

There is no GUI setting for use-ip-firewall ??

There is the standard
/ip firewall filter ( input chain: to the router or router services, forward chain: through the router lan to lan, lan to wan, wan to lan )
/ip nat
/ip mangle
/ip raw

All found in winbox under IP, and selecting sub-menu FIREWALL.
There is also a setting under the BRIDGE menu selection, to the far right of the popup called FILTERS ( just before NAT)

One uses the + symbol to create a rule in any of these areas and the rule is automatically enabled after hitting apply OK.
One can disable or delete the rule or move the rule in some cases to the required position order.

thanks all..

i found the setting now in the ui..

As i said i got it working and have been using it on my older ccr1016

but am preparing the ccr1035 with sft+ to have my isp go over 1g.. And i already have an internal 10g networking to my nas’s etc.

my firewall would not work with bridge filters it is pretty big ie 1400 lines. and loads about 32K addresss to block certain countries wholesale.

Bridge filtering only needs to be done in specific cases, much better off using standard firewall anyway.

Country blocking is a fools game, bad actors come from any country.
If you are interested in a decent blacklist for decent cost - https://itexpertoncall.com/promotional/moab.htm

“Our MOAB subscription service - fully automated and updated 3 times each day because of its very dynamic nature as previously unknown sources get added in - identifies over 600 million unique IP addresses of known malicious or suspicious entities [the Bad Guys] that shouldn’t be allowed access to your Internet connection and Network.”

thanks i am interested.. i will look at that list..

my big countries are china russia kzakstan and brazil believe it or not..

Good idea to discuss with the blacklist provider… He is very knowledgeable in that area and what is useful or not.