Community discussions

MUM Europe 2020
 
QpoX
Member
Member
Topic Author
Posts: 387
Joined: Mon Mar 24, 2008 7:42 pm
Location: Lemvig, Denmark

Firewall setup - Block all inbound but allow all outbound

Sun May 04, 2008 12:46 am

I want to block all inbound trafic on all ports but have port 80 tcp and port 3389 tcp and port 27000-27050 TCP/UDP open.

But when i make this:
add action=accept chain=forward comment="RDP" disabled=no dst-address=xxx.xxx.xxx.123 dst-port=3389 protocol=tcp src-address=yyy.yyy.yyy.0/28
add action=accept chain=forward comment="HTTP" disabled=no dst-address=xxx.xxx.xxx.123 dst-port=80 protocol=tcp src-address=yyy.yyy.yyy.0/28
add action=accept chain=forward comment="TF2" disabled=no dst-address=xxx.xxx.xxx.123 dst-port=27000-27050 protocol=tcp
add action=accept chain=forward comment="TF2" disabled=no dst-address=xxx.xxx.xxx.123 dst-port=27000-27050 protocol=udp
add action=drop chain=forward comment="BLOCK ALL" disabled=yes dst-address=xxx.xxx.xxx.123

It does not work, i can't even ping out from xxx.xxx.xxx.123 or get any trafic out (look at websites and so on).
Is there something that i don't get about the way the firewall in RouterOS is working?
But the RDP and HTTP works??? (and can connect to the RDP running on xxx.xxx.xxx.123 and look at the HTTP server running on it).
And when i disable the "BLOCK ALL" rule it all works, but the machine is expose'd to the net.
 
User avatar
jwcn
Forum Guru
Forum Guru
Posts: 1501
Joined: Sun Aug 27, 2006 6:49 am
Location: Maryland, USA
Contact:

Re: Firewall setup - Block all inbound but allow all outbound

Sun May 04, 2008 2:16 am

Use IP - services to turn off inbound services.
 
QpoX
Member
Member
Topic Author
Posts: 387
Joined: Mon Mar 24, 2008 7:42 pm
Location: Lemvig, Denmark

Re: Firewall setup - Block all inbound but allow all outbound

Sun May 04, 2008 2:50 am

It's not to the box it self thies rules are for. but a server on a subnet...
 
User avatar
jwcn
Forum Guru
Forum Guru
Posts: 1501
Joined: Sun Aug 27, 2006 6:49 am
Location: Maryland, USA
Contact:

Re: Firewall setup - Block all inbound but allow all outbound

Sun May 04, 2008 4:56 am

Are you routing public addresses or nat?
 
QpoX
Member
Member
Topic Author
Posts: 387
Joined: Mon Mar 24, 2008 7:42 pm
Location: Lemvig, Denmark

Re: Firewall setup - Block all inbound but allow all outbound

Sun May 04, 2008 5:34 am

I'm routing public addresses and this server is on a /30
 
User avatar
jwcn
Forum Guru
Forum Guru
Posts: 1501
Joined: Sun Aug 27, 2006 6:49 am
Location: Maryland, USA
Contact:

Re: Firewall setup - Block all inbound but allow all outbound

Sun May 04, 2008 6:12 am

Check out the Wiki. I think you will find your answer there.
 
User avatar
savagedavid
Trainer
Trainer
Posts: 310
Joined: Thu Aug 25, 2005 12:58 pm
Location: Cape Town, South Africa
Contact:

Re: Firewall setup - Block all inbound but allow all outbound

Sun May 04, 2008 11:41 pm

A simple way would be to masquerade the network if you dont mind having a natted output. This will effectively hide your network behind the router but still allow all outgoing traffic.

Currently the last rule in your list will drop ALL traffic in the forward chain, in and out, so the result you are getting is expected.
savagedavid
MTCE+T (MikroTik Certified Everything + Trainer)
MikroTik support and training in South Africa
http://www.mikrotiksa.com
david [at] mikrotiksa dot com
 
QpoX
Member
Member
Topic Author
Posts: 387
Joined: Mon Mar 24, 2008 7:42 pm
Location: Lemvig, Denmark

Re: Firewall setup - Block all inbound but allow all outbound

Mon May 05, 2008 12:20 am

Check out the Wiki. I think you will find your answer there.
Did not find anything usefull :(

A simple way would be to masquerade the network if you dont mind having a natted output. This will effectively hide your network behind the router but still allow all outgoing traffic.

Currently the last rule in your list will drop ALL traffic in the forward chain, in and out, so the result you are getting is expected.
Have had that ideer in my head, but i wanted it on it's own IP free of NAT...
But how do a block all indbound and only allow trafic in that i want open? and allow all outbound trafic?
 
User avatar
jwcn
Forum Guru
Forum Guru
Posts: 1501
Joined: Sun Aug 27, 2006 6:49 am
Location: Maryland, USA
Contact:

Re: Firewall setup - Block all inbound but allow all outbound

Mon May 05, 2008 5:51 am

Dmitri's firewall rules. Read the wiki.
 
QpoX
Member
Member
Topic Author
Posts: 387
Joined: Mon Mar 24, 2008 7:42 pm
Location: Lemvig, Denmark

Re: Firewall setup - Block all inbound but allow all outbound

Mon May 05, 2008 6:29 am

Dmitri's firewall rules. Read the wiki.
Will do...
 
User avatar
andrewluck
Forum Veteran
Forum Veteran
Posts: 702
Joined: Fri May 28, 2004 9:05 pm
Location: Norfolk, UK

Re: Firewall setup - Block all inbound but allow all outbound

Wed May 07, 2008 4:41 pm

Before the final drop rule add this:
chain=forward action=accept connection-state=established
Regards

Andrew

Who is online

Users browsing this forum: Bing [Bot], hngjared, zwarner and 136 guests