Community discussions

MikroTik App
 
infused
Member
Member
Topic Author
Posts: 313
Joined: Fri Dec 28, 2012 2:33 pm

ppoe question firewall and input chain

Sun May 11, 2014 8:04 am

Hi Guys.

I've never really dealt with ppoe and single ip addresses in mikrotiks. I'm normally setting them up with subnets and such.

So yesterday I configured a Mikrotik connected to a zyxel vdsl router in bridge mode using ppoe. It all works fine.

However, the IP address obtained from the provider is put in the address list, as expected I guess. However, now all the traffic coming externally to the router is on the input chain. Normally I would be fire walling it on the forward chain.

Can someone tell me why this is, and if it's expected?
 
CelticComms
Forum Guru
Forum Guru
Posts: 1765
Joined: Wed May 02, 2012 5:48 am

Re: ppoe question firewall and input chain

Sun May 11, 2014 6:57 pm

Where is the traffic terminated? On the router? Or is it being forwarded to say LAN clients via NAT & connection tracking?
 
infused
Member
Member
Topic Author
Posts: 313
Joined: Fri Dec 28, 2012 2:33 pm

Re: ppoe question firewall and input chain

Mon May 12, 2014 2:46 am

Should be nat.

For example, I have a src nat for masquerade. If I block input chan port 80 dst, the lan cannot access port 80. And viceversa when incoming traffic hits the router. I thought since there is masquerade, traffic flows through the router, so it would be a forward rule.
 
CelticComms
Forum Guru
Forum Guru
Posts: 1765
Joined: Wed May 02, 2012 5:48 am

Re: ppoe question firewall and input chain

Mon May 12, 2014 4:22 am

Are you using the proxy server?

Normal WAN<>LAN NATed traffic flows through the forward chain.

Who is online

Users browsing this forum: ryancccc, zabloc and 64 guests