Community discussions

MikroTik App
 
PhilipLykov
newbie
Topic Author
Posts: 48
Joined: Fri Dec 10, 2010 12:24 am

Connection Limit rule above/beyond Established Connections

Thu Sep 13, 2012 11:33 pm

Hello,

I cannot understand well the principle of work the "Connection Limit" rule in the Firewall/Filter. Should it be placed above or beyond the rule which allow all already established connections?
 
forne
Frequent Visitor
Frequent Visitor
Posts: 65
Joined: Tue Feb 15, 2011 3:18 pm

Re: Connection Limit rule above/beyond Established Connectio

Sun Sep 16, 2012 4:36 pm

The rule "action=accept connection-state=established" should be placed as early as possible (ideally, first) in any firewall filter chain for performance reasons. After it you should place other rules that limit the creation of new connections. Connection-limit can be used as one of the matchers in those rules.
 
PhilipLykov
newbie
Topic Author
Posts: 48
Joined: Fri Dec 10, 2010 12:24 am

Re: Connection Limit rule above/beyond Established Connectio

Sun Sep 16, 2012 6:30 pm

Yes, I know, but it seems that Established Connections rule should be beyond the Connection Limit because it cannot calculate all established connections then. In any case there is should be some kind of advanced documentation which will describe such things.

Who is online

Users browsing this forum: abhsek, sindy, Spe, Znevna and 142 guests