Community discussions

MikroTik App
 
eoleg
newbie
Topic Author
Posts: 47
Joined: Wed Dec 02, 2009 4:47 pm

The NAT is not working Content.

Tue May 12, 2015 10:24 am

The NAT is not working Content.
It turns out a bug or it is certainly under any special conditions it work?

В NAT не работает Content.
Получается баг, или всетаки при каких то особых условиях работает?
 
User avatar
vasilevkirill
Trainer
Trainer
Posts: 56
Joined: Tue May 22, 2012 7:38 am
Location: Russian, Saint-Petersburg
Contact:

Re: The NAT is not working Content.

Tue May 12, 2015 11:39 am

What exactly are you trying to filter?

-------
Покажите правило которым вы хотите отфильтровать пакет, а также объясните что хотите поймать!
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7056
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: The NAT is not working Content.

Tue May 12, 2015 1:35 pm

NAT rules match only the first packet. And TCP SYN packet typically does not have nay content.
 
User avatar
ZeroByte
Forum Guru
Forum Guru
Posts: 4047
Joined: Wed May 11, 2011 6:08 pm

Re: The NAT is not working Content.

Tue May 12, 2015 6:01 pm

The NAT is not working Content.
It turns out a bug or it is certainly under any special conditions it work?

В NAT не работает Content.
Получается баг, или всетаки при каких то особых условиях работает?
It's not a bug. What you've been trying to do is impossible.
You cannot change NAT after a TCP connection establishes.
TCP must establish before any content can be requested / delivered.
Therefore the content match is useless in NAT rules for protocols that use TCP as their transport.

Your request here is the same as asking a condom company why your girlfriend stays pregnant even after you start using their product.

You've been asking about this for a month now - the community has given you some alternative ideas, but you stated that they require too much CPU. Unfortunately, this is just how it is for deep packet inspection. Period. If you need to do this kind of filtering, then buy a box that is built specifically to do deep packet inspection and content filtering.
(our company uses iBoss)

It's not Mikrotik's fault that a platform designed for packet forwarding cannot keep up with the load of running a regular expression against the payload of each and every packet that flows through it. The CPU was chosen to be inexpensive but capable of quickly comparing the headers of IP packets against binary lists of routing destinations. String comparisons are vastly more complicated at the CPU level.
 
eoleg
newbie
Topic Author
Posts: 47
Joined: Wed Dec 02, 2009 4:47 pm

Re: The NAT is not working Content.

Fri May 15, 2015 11:23 am

What exactly are you trying to filter?

-------
Покажите правило которым вы хотите отфильтровать пакет, а также объясните что хотите поймать!

It is necessary to highlight the url something like this - ljre4wem4dygt and redirect to a certain ip

Нужно в url выделить чтото типа этого - ljre4wem4dygt и перенаправить на определенный ip
 
eoleg
newbie
Topic Author
Posts: 47
Joined: Wed Dec 02, 2009 4:47 pm

Re: The NAT is not working Content.

Fri May 15, 2015 11:28 am

"Your request here is the same as asking a condom company why your girlfriend stays pregnant even after you start using their product."


Well then you do not need to give an opportunity to use a condom!

ну тогда не нужно давать возможность использовать презерватив!
 
User avatar
vasilevkirill
Trainer
Trainer
Posts: 56
Joined: Tue May 22, 2012 7:38 am
Location: Russian, Saint-Petersburg
Contact:

Re: The NAT is not working Content.

Sat May 16, 2015 11:41 pm

Чтобы понимать конкретно чтовы хотите сделать, покажите на примере. "правило студию"
 
eoleg
newbie
Topic Author
Posts: 47
Joined: Wed Dec 02, 2009 4:47 pm

Re: The NAT is not working Content.

Sat May 16, 2015 11:54 pm

Чтобы понимать конкретно чтовы хотите сделать, покажите на примере. "правило студию"
/ip firewall nat add action=dst-nat chain=dstnat content=tzhgsvcdtfg to-addresses=999.999.999.999
 
User avatar
vasilevkirill
Trainer
Trainer
Posts: 56
Joined: Tue May 22, 2012 7:38 am
Location: Russian, Saint-Petersburg
Contact:

Re: The NAT is not working Content.

Mon May 18, 2015 8:53 pm

Вы либо что то недоговариваете, либо вы не знаете чего вы хотите.
по ваше правилу вы собираетесь парсить весь трафик, не конктратизируя ТСP или UDP какие порты dst. А также action, просто accept?
 
eoleg
newbie
Topic Author
Posts: 47
Joined: Wed Dec 02, 2009 4:47 pm

Re: The NAT is not working Content.

Mon May 18, 2015 9:27 pm

Вы либо что то недоговариваете, либо вы не знаете чего вы хотите.
по ваше правилу вы собираетесь парсить весь трафик, не конктратизируя ТСP или UDP какие порты dst. А также action, просто accept?
извините, скопировал не все
вот так правильно
/ip firewall nat add chain=dstnat protocol=tcp content=tzhgsvcdtfg action=dst-nat to-addresses=999.999.999.999
я просто хочу направить абонента на другой ip при попытке посмотреть некоторые ролики youtube у которых в урле есть например tzhgsvcdtfg
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7056
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: The NAT is not working Content.

Thu May 21, 2015 5:50 pm

Kak uzhe bilo skazano ranshe, eto njevozmozhno. NAT vidit tolky TCP syn paket, a v etom paketje njetu "content".

redirekt na drugije http stranici mozhno sdelatjs s web proxy.

Who is online

Users browsing this forum: akakua, haung05, massinia, panzermaster18, Valerio5000 and 233 guests