Hello to all,
i need some help with zerotier and firewall. I have a hap ax2, with zerotier installed, behing isp router. Mikrotik is at dmz from isp router.
[admin@MikroTik] > /ip firewall filter print
Flags: X - disabled, I - invalid; D - dynamic
0 D ;;; special dummy rule to show fasttrack counters
chain=forward action=passthrough
1 chain=forward action=accept in-interface=zerotier1 log=no log-prefix=“”
2 chain=input action=accept in-interface=zerotier1 log=no log-prefix=“”
3 ;;; defconf: accept established,related,untracked
chain=input action=accept
connection-state=established,related,untracked log=no log-prefix=“”
4 ;;; block everything else
chain=input action=drop connection-state=invalid log=no log-prefix=“”
5 ;;; defconf: accept ICMP
chain=input action=accept protocol=icmp log=no log-prefix=“”
6 X ;;; defconf: drop all not coming from LAN
chain=input action=drop in-interface-list=!LAN log=no log-prefix=“”
7 ;;; defconf: fasttrack
chain=forward action=fasttrack-connection hw-offload=yes
connection-state=established,related log=no log-prefix=“”
8 ;;; defconf: accept established,related, untracked
chain=forward action=accept
connection-state=established,related,untracked log=no log-prefix=“”
9 ;;; defconf: drop invalid
chain=forward action=drop connection-state=invalid log=no log-prefix=“”
10 ;;; defconf: drop all from WAN not DSTNATed
chain=forward action=drop connection-state=new
connection-nat-state=!dstnat in-interface-list=WAN log=no log-prefix=“”
You can see that i have disable defconf: drop all not coming from LAN
The problem that it blocks my remote desktop connection thru zerotier( i want to use zerotier as vpn for rdp )
any suggestion to correct this issue? or better firewall rules for better security?