Community discussions

MikroTik App
 
lavv17
Member Candidate
Member Candidate
Topic Author
Posts: 120
Joined: Sat Sep 01, 2007 9:01 am

selective connection tracking

Fri Jun 10, 2016 4:02 pm

Hello!

Is it possible to do selective connection tracking? In my setup the routers forward lots of traffic, but connection tracking is only required for input/output chains, not forward. Is it possible to implement to save resources?
 
User avatar
macgaiver
Forum Guru
Forum Guru
Posts: 1764
Joined: Wed May 18, 2005 5:57 pm
Location: Sol III, Sol system, Sector 001, Alpha Quadrant

Re: selective connection tracking

Fri Jun 10, 2016 5:00 pm

Yes you can, starting from 6.36rc, there is "raw" firewall table that have "action=no-track". it happens before connection tracking.
 
lavv17
Member Candidate
Member Candidate
Topic Author
Posts: 120
Joined: Sat Sep 01, 2007 9:01 am

Re: selective connection tracking

Thu Jun 16, 2016 9:59 am

Thanks! I'll try it when it will be released.
 
lavv17
Member Candidate
Member Candidate
Topic Author
Posts: 120
Joined: Sat Sep 01, 2007 9:01 am

Re: selective connection tracking

Wed Oct 11, 2017 12:16 pm

It works very well! Thanks, MikroTik!
 
User avatar
amt
Long time Member
Long time Member
Posts: 529
Joined: Fri Jan 16, 2015 2:05 pm

Re: selective connection tracking

Wed Oct 11, 2017 4:07 pm

Hi,

do I need connection tracking when there is no any firewall rule and nat on router ? I have some PPPoE Server and connection tracking is enabled on them. and I have some routers just passing traffic to other sites or other routers and connection tracking a enabled on them too. I read some post and see that connection tracking using too much cpu, is there any disadvantage to disable them ?

Thanks
 
lavv17
Member Candidate
Member Candidate
Topic Author
Posts: 120
Joined: Sat Sep 01, 2007 9:01 am

Re: selective connection tracking

Tue Oct 31, 2017 8:18 am

connection tracking is needed for NAT and connection-state checking in the firewall. If you don't need these features, it should be safe to disable connection tracking. But it will only help if CPU is already quite loaded.

Who is online

Users browsing this forum: Bing [Bot], k6ccc, rextended, TEOshkin, xrlls and 124 guests