Community discussions

MUM Europe 2020
 
opalit
Member Candidate
Member Candidate
Topic Author
Posts: 211
Joined: Wed Aug 24, 2011 10:15 pm

Firewall Rules not working

Thu Sep 27, 2018 7:42 am

I have a PowerBox Pro configured as a Router and running CapsMan
I am trying to block winbox input to the unit via WAN port which is sfp1, I have the following rule but it does not seem to work.

chain=input action=drop in-interface=sfp1 log=no log-prefix=""
I have also tried chain=input action=drop protocol=tcp in-interface=sfp1 dst-port=8291 log=no log-prefix=""

I simply does not block winbox, it blocks other ports and protocols but not winbox
 
User avatar
xvo
Long time Member
Long time Member
Posts: 631
Joined: Sat Mar 03, 2018 1:12 am
Location: Moscow, Russia

Re: Firewall Rules not working

Thu Sep 27, 2018 11:14 am

Winbox has a possibility to work on Level 3 - when you connect to IP address, and on level 2 - when you connect to MAC address.
Firewall works on level 3.
To restrict the ability to connect to winbox by MAC from some ports, look here:
/tool mac-server mac-winbox export
And then remove unwanted interface from interface list that is used.
 
sindy
Forum Guru
Forum Guru
Posts: 4216
Joined: Mon Dec 04, 2017 9:19 pm

Re: Firewall Rules not working

Thu Sep 27, 2018 11:48 am

When connecting using Winbox, do you use IP address or MAC address to identify the PowerBox, and do you actually connect via sfp1?

Is the rule you gave the only one in chain=input of the /ip firewall filter?
Instead of writing novels, post /export hide-sensitive. Use find&replace in your favourite text editor to systematically replace all occurrences of each public IP address potentially identifying you by a distinctive pattern such as my.public.ip.1.
 
opalit
Member Candidate
Member Candidate
Topic Author
Posts: 211
Joined: Wed Aug 24, 2011 10:15 pm

Re: Firewall Rules not working

Thu Sep 27, 2018 12:44 pm

I am using MAC, I am using the connection I used to get in before IP were assigned, just realised it is not discoverable, I am connecting with a saved connection with the MAC already in.

I will leave it like that so I have a back door.

Who is online

Users browsing this forum: gutekpl, lilpri, oskarsk and 56 guests