Community discussions

MikroTik App
 
skbnet
just joined
Topic Author
Posts: 4
Joined: Fri Apr 24, 2009 2:00 pm

hOW TO REJECT NATTED(nat) INCOMING PACKETS FROM ON MIKROTIK

Wed Jan 06, 2010 3:19 pm

DEAR ALL

I WANT TO KNOW THAT THROUGH IP FIREWALL HOW CAN WE REJECT ANY NATED PACKET COMING ON USER INTERFACE?
MEANS IF ANY USER IS USING NATING AT HIS END, HOW CN MIKROTIK IDENTIFIES AND REJECT THAT PACKETS ?

THANKS

SATISH
 
User avatar
Chupaka
Forum Guru
Forum Guru
Posts: 8709
Joined: Mon Jun 19, 2006 11:15 pm
Location: Minsk, Belarus
Contact:

Re: hOW TO REJECT NATTED(nat) INCOMING PACKETS FROM ON MIKROTIK

Wed Jan 06, 2010 4:29 pm

well, there's no precise ways to define whether the packet was natted or not. you can see TTL Matcher in Firewall Filter. for example, Windows' default TTL is 128, and after a router it becomes 127. for Linux, default is 64, etc.
 
fewi
Forum Guru
Forum Guru
Posts: 7717
Joined: Tue Aug 11, 2009 3:19 am

Re: hOW TO REJECT NATTED(nat) INCOMING PACKETS FROM ON MIKROTIK

Wed Jan 06, 2010 5:56 pm

And if what you're trying to do is keep customers from deploying routers try setting the TTL for packets into the customer (not from the customer) to 1 in firewall mangle. Unless the customer has the knowledge and hardware to rewrite the TTL themselves that will expire packets on the next hop - if that is a computer it will accept the packet, if it's a router it will discard it.
 
skbnet
just joined
Topic Author
Posts: 4
Joined: Fri Apr 24, 2009 2:00 pm

Re: hOW TO REJECT NATTED(nat) INCOMING PACKETS FROM ON MIKROTIK

Thu Jan 07, 2010 12:26 pm

Thanks for reply

We are unable to identify NAT packets, because in case of routers, TTL is change & brand specific and also unable to check if there is any ICS on windows machine.
ICS is also a NAT

So please help me

Thanks

Satish
 
netrat
Member
Member
Posts: 402
Joined: Thu Jun 07, 2007 1:16 pm
Location: Virginia

Re: hOW TO REJECT NATTED(nat) INCOMING PACKETS FROM ON MIKROTIK

Thu Jan 07, 2010 3:23 pm

Thanks for reply

We are unable to identify NAT packets, because in case of routers, TTL is change & brand specific and also unable to check if there is any ICS on windows machine.
ICS is also a NAT

So please help me

Thanks

Satish
If Windows ICS forwards a packet the TTL should still be reduced by one. TTL is "always" decreased by one even if it's traversing NAT. Change outgoing TTL for client traffic to 1.
 
User avatar
Chupaka
Forum Guru
Forum Guru
Posts: 8709
Joined: Mon Jun 19, 2006 11:15 pm
Location: Minsk, Belarus
Contact:

Re: hOW TO REJECT NATTED(nat) INCOMING PACKETS FROM ON MIKROTIK

Thu Jan 07, 2010 8:42 pm

but TTL is not changed for proxied requests...
 
skbnet
just joined
Topic Author
Posts: 4
Joined: Fri Apr 24, 2009 2:00 pm

Re: hOW TO REJECT NATTED(nat) INCOMING PACKETS FROM ON MIKROTIK

Thu Jan 14, 2010 12:41 pm

Thanks it is working fine with DSL and ICS but can you also suggest me if any client is using Linux based router or proxy
because i am unable to block that Proxies

Thanks

Satish Bharadia

Who is online

Users browsing this forum: johnb175a, jvanhambelgium, kleshki, patrikg, woland and 72 guests