Community discussions

MikroTik App
 
daitea
Member Candidate
Member Candidate
Topic Author
Posts: 118
Joined: Sun May 03, 2009 3:17 pm

Firewall Filter Rule

Fri Jun 19, 2009 3:38 am

This command is for preventing the ip address from working "chain=forward src-address=10.1.90.110 action=drop "
how do i block the whole of 10.1.90.1/24 and allow only a few to work as and when need be?

this will be a good security for my network
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7053
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: Firewall Filter Rule

Fri Jun 19, 2009 1:38 pm

Add accept rules for specific IPs and drop the rest from subnet

chain=forward src-address=10.1.90.110 action=accept
chain=forward src-address=10.1.90.0/24 action=drop
 
daitea
Member Candidate
Member Candidate
Topic Author
Posts: 118
Joined: Sun May 03, 2009 3:17 pm

Re: Firewall Filter Rule

Fri Jun 19, 2009 11:32 pm

i still do have a reply on 10.1.90.110
 
User avatar
Chofex
Member Candidate
Member Candidate
Posts: 141
Joined: Mon Mar 27, 2006 7:03 am
Location: San Rafael, Mendoza, Argentina

Re: Firewall Filter Rule

Sat Jun 20, 2009 6:36 pm

Of course you'll have a reply from 110! That's the only one that will reply!
Add a rule like the one for 110 for each IP you need working. Those are the ones that will reply!
Pice of cake...
 
daitea
Member Candidate
Member Candidate
Topic Author
Posts: 118
Joined: Sun May 03, 2009 3:17 pm

Re: Firewall Filter Rule

Sat Jun 20, 2009 6:55 pm

it still does not work.
all ips on that block are still replying
and traffic is been passed alright
is there a way i can do this ?
 
User avatar
Chofex
Member Candidate
Member Candidate
Posts: 141
Joined: Mon Mar 27, 2006 7:03 am
Location: San Rafael, Mendoza, Argentina

Re: Firewall Filter Rule

Sat Jun 20, 2009 7:08 pm

Do those client flow through this router? They will pass if they see each other directly.
How do you test pings? where do you point to?
You're placing the rule in forward, not input...
Do you have a bridge? if that's so, firewall won't work
Is connection tracking enabled?
Do OTHER firewall rule work?
 
daitea
Member Candidate
Member Candidate
Topic Author
Posts: 118
Joined: Sun May 03, 2009 3:17 pm

Re: Firewall Filter Rule

Sat Jun 20, 2009 7:23 pm

everything is yes apart from it been a bridge
 
User avatar
Chofex
Member Candidate
Member Candidate
Posts: 141
Joined: Mon Mar 27, 2006 7:03 am
Location: San Rafael, Mendoza, Argentina

Re: Firewall Filter Rule

Sat Jun 20, 2009 7:47 pm

you should show your ip addresses and routing, as well as where you're pinging to...
 
daitea
Member Candidate
Member Candidate
Topic Author
Posts: 118
Joined: Sun May 03, 2009 3:17 pm

Re: Firewall Filter Rule

Sat Jun 20, 2009 8:12 pm

i am at 10.1.90.1 and i ping 10.1.90.110

the rout is to stop the ip 10.1.91.2 to 254 from working but ucan ping all of them

the whole idea is to make sure no ip in this block 10.1.90.1/24 works without my knowledge

so if u know any method i will be will to accept
 
User avatar
Chofex
Member Candidate
Member Candidate
Posts: 141
Joined: Mon Mar 27, 2006 7:03 am
Location: San Rafael, Mendoza, Argentina

Re: Firewall Filter Rule

Sun Jun 21, 2009 4:14 am

If you are in the same subnet you're pinging, it won't work, as your're not going through the router!
It'll work when the router really works, that is from one subnet to other...

Who is online

Users browsing this forum: akakua, grusu, Snooops and 21 guests