Community discussions

MikroTik App
 
networknoob88
newbie
Topic Author
Posts: 45
Joined: Sun Jul 15, 2018 6:00 pm

Forward rule vs acl rule precedence

Wed Jan 16, 2019 9:06 am

I noticed that even if I disable forwarding from port A to port B under the "Forward" tab, an ACL rule that redirects traffic from port A to port B still works.

Is this intended behavior? Basically ACL rules take precedence over Forward rules?
 
User avatar
sebastia
Forum Guru
Forum Guru
Posts: 1782
Joined: Tue Oct 12, 2010 3:23 am
Location: Antwerp, BE

Re: Forward rule vs acl rule precedence

Wed Jan 16, 2019 12:31 pm

What exactly do you mean by "ACL rule"?
 
networknoob88
newbie
Topic Author
Posts: 45
Joined: Sun Jul 15, 2018 6:00 pm

Re: Forward rule vs acl rule precedence

Wed Jan 16, 2019 6:21 pm

What exactly do you mean by "ACL rule"?

Just ACL. By "rule" I meant the action I set to redirect ports with a match.

Under Forward, I disabled port1 to port3 forward.

Under ACL, I created an entry that redirect port1 packets to port3, and it works.
Last edited by networknoob88 on Wed Jan 16, 2019 6:43 pm, edited 1 time in total.
 
User avatar
sebastia
Forum Guru
Forum Guru
Posts: 1782
Joined: Tue Oct 12, 2010 3:23 am
Location: Antwerp, BE

Re: Forward rule vs acl rule precedence

Wed Jan 16, 2019 6:28 pm

... And where do you configure that ACL?
 
networknoob88
newbie
Topic Author
Posts: 45
Joined: Sun Jul 15, 2018 6:00 pm

Re: Forward rule vs acl rule precedence

Wed Jan 16, 2019 7:42 pm

... And where do you configure that ACL?

Under SWOS's ACL tab. See pic.
Screenshot (2).png
You do not have the required permissions to view the files attached to this post.
 
User avatar
sebastia
Forum Guru
Forum Guru
Posts: 1782
Joined: Tue Oct 12, 2010 3:23 am
Location: Antwerp, BE

Re: Forward rule vs acl rule precedence

Wed Jan 16, 2019 8:33 pm

My bad, didn't notice that it's posted under swos...

I don't use swos myself, so won't be of much help.
The documentation https://wiki.mikrotik.com/wiki/SwOS/CSS106 doesn't mention any order or flow diagram (@Mikrotik that's a must! It's available for ROS).

The doc does mention what Access Control List is/provides:
Ingress ACL tables
Up to 32 ACL rules (limited by SwOS)
Classification based on ports, L2, L3, L4 protocol header fields
ACL actions include filtering, forwarding and modifying of the protocol header fields

So it could be that ACL is taking precedence over forwarding config

Who is online

Users browsing this forum: No registered users and 51 guests