Community discussions

MikroTik App
 
User avatar
andressis2k
Member Candidate
Member Candidate
Topic Author
Posts: 104
Joined: Mon Apr 18, 2011 12:47 am

Urgent feature request: Bind IP services to a specific IP / Interface

Mon Apr 23, 2018 4:53 pm

Due to recent security failures, we'd urgently need the ability to bind IP services to a specific IP / Interface, like can be done in allmost all linux servers.

Filter by src-address isn't enough, cause if service daemon itself gets compromised...

We need to set-up a non-publicly accessible network, and be sure winbox service can only be reachable by these interfaces.

Regards
 
eddieb
Member
Member
Posts: 327
Joined: Thu Aug 28, 2014 10:53 am
Location: Netherlands

Re: Urgent feature request: Bind IP services to a specific IP / Interface

Thu Apr 26, 2018 8:24 pm

+1 for this request.
It should be possible to bind IP services to a specific IP and/or a specific interface.
We do so on our linux servers allways !
 
squeeze
Member Candidate
Member Candidate
Posts: 145
Joined: Thu Mar 22, 2018 7:53 pm

Re: Urgent feature request: Bind IP services to a specific IP / Interface

Fri Apr 27, 2018 1:03 am

Good request. Seems obvious in hindsight. Defense in Depth.
 
changeip
Forum Guru
Forum Guru
Posts: 3830
Joined: Fri May 28, 2004 5:22 pm

Re: Urgent feature request: Bind IP services to a specific IP / Interface

Fri Apr 27, 2018 1:31 am

YES! Binding SNMP to a single IP so it always replies from that same IP would be super nice.
 
kurio
newbie
Posts: 25
Joined: Sun Dec 22, 2013 6:15 pm

Re: Urgent feature request: Bind IP services to a specific IP / Interface

Mon Sep 11, 2023 1:32 pm

Due to recent security failures, we'd urgently need the ability to bind IP services to a specific IP / Interface, like can be done in allmost all linux servers.
Filter by src-address isn't enough, cause if service daemon itself gets compromised...
YES, we need this!
And it is NOT related to filtering.
I need to run www service on LAN bridge interface ONLY. And i need it to bind to port 80 on that specific interface!
Because i need port 80 to be FREE elsewhere to be forwarded from internet to my web server. So, i need to NAT port 80 from internet to a server on my LAN which is behind mikrotik's NAT. And at the same time have the ability for inexperienced administrators to reach webfig from LAN by only typing the IP address, which goes by default to port 80.
We need different services which use the same port number be accessible at different interfaces.
Thanks
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 11591
Joined: Thu Mar 03, 2016 10:23 pm

Re: Urgent feature request: Bind IP services to a specific IP / Interface

Mon Sep 11, 2023 8:39 pm

I need to run www service on LAN bridge interface ONLY. And i need it to bind to port 80 on that specific interface!
Because i need port 80 to be FREE elsewhere to be forwarded from internet to my web server.

That's perfectly doable with NAT: DST-NAT is executed first and if the rule contains also property in-interface-list=WAN (or something similar), then only connections coming in via those interfaces will get DST-NATed. Other connections will still be handled by router's own services (if firewall permits).
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19323
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Urgent feature request: Bind IP services to a specific IP / Interface

Mon Sep 11, 2023 9:07 pm

I have no clue what the op wants.

But it would appear its.

a. SOME WHACKO local port 80 only available for bridge users (local WWW service, so nothing to do with reaching the internet, I have no idea what this local thing is ????????????????)
b. separately to be able to come in external to the router and hit port 80 on a server for external users I presume.........???????????????

Who is online

Users browsing this forum: astronomicz, haung05, sabit, xevete and 102 guests