Community discussions

MikroTik App
 
jeroenp
Member Candidate
Member Candidate
Topic Author
Posts: 159
Joined: Mon Mar 17, 2014 11:30 am
Location: Amsterdam
Contact:

[Needs Mikrotik feedback] `reject-with` values are not documented any more

Wed Oct 19, 2016 6:26 pm

http://wiki.mikrotik.com/wiki/Manual:IP/Firewall/Filter does not document the `reject-with` values any more.

https://www.google.com/search?q=%22reje ... i%2FManual reveals one tiny example with one value not explaining what it means.

Please re-add the relevant bits of https://www.mikrotik.com/testdocs/ros/2.9/ip/filter.php again and explain the various values.

--jeroen
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 6111
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: [Needs Mikrotik feedback] `reject-with` values are not documented any more

Wed Oct 19, 2016 7:00 pm

Values are self explanatory.
Do you wan to see something like
icmp-echo-reply - sends icmp echo reply
etc :)
 
User avatar
boen_robot
Forum Guru
Forum Guru
Posts: 2411
Joined: Thu Aug 31, 2006 4:43 pm
Location: europe://Bulgaria/Plovdiv

Re: [Needs Mikrotik feedback] `reject-with` values are not documented any more

Wed Oct 19, 2016 7:16 pm

Just include the values in there, like other enumerated values (no explanation for each needed), i.e. have the first column as:
reject-with (icmp-admin-prohibited | icmp-echo-reply | icmp-host-prohibited | icmp-host-unreachable | icmp-net-prohibited | icmp-network-unreachable | icmp-port-unreachable | icmp-protocol-unreachable | tcp-reset | integer; Default: )
It saves people from going to terminal and typing "add reject-with=?" just to see the possible values they're working with.

Personally, I'd also appreciate an explanation for the integer. I'm guessing it's ICMP code, but it would be nice if this is explicitly said.
PEAR2_Net_RouterOS(1.0.0b6) - My API client in PHP
(Rate my posts? If you want... no pressure...)
 
User avatar
ZeroByte
Forum Guru
Forum Guru
Posts: 4051
Joined: Wed May 11, 2011 6:08 pm

Re: [Needs Mikrotik feedback] `reject-with` values are not documented any more

Wed Oct 19, 2016 7:51 pm

http://wiki.mikrotik.com/wiki/Manual:IP/Firewall/Filter does not document the `reject-with` values any more.
With the exception of "integer" (mentioned by Boen Robot) these response types are standard IP packet types. If you want to learn about those, then just google for any networking tutorials / guides / rfcs etc.
When given a spoon,
you should not cling to your fork.
The soup will get cold.
 
jeroenp
Member Candidate
Member Candidate
Topic Author
Posts: 159
Joined: Mon Mar 17, 2014 11:30 am
Location: Amsterdam
Contact:

Re: [Needs Mikrotik feedback] `reject-with` values are not documented any more

Wed Oct 19, 2016 10:31 pm

http://wiki.mikrotik.com/wiki/Manual:IP/Firewall/Filter does not document the `reject-with` values any more.
With the exception of "integer" (mentioned by Boen Robot) these response types are standard IP packet types. If you want to learn about those, then just google for any networking tutorials / guides / rfcs etc.
That's the problem: https://www.google.com/search?q="icmp-admin-prohibited" does not return meaningful results at least not in my location.

Why not just have the documentation link to a relevant URL that explains the values?

Don't expect all your users to be RFC gurus.

--jeroen
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 6111
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: [Needs Mikrotik feedback] `reject-with` values are not documented any more

Thu Oct 20, 2016 2:20 pm

Let me do that for you
http://lmgtfy.com/?q=icmp+admin+prohibi ... e&l=1#seen

BTW there is no integer code in ROS v6.
 
jeroenp
Member Candidate
Member Candidate
Topic Author
Posts: 159
Joined: Mon Mar 17, 2014 11:30 am
Location: Amsterdam
Contact:

Re: [Needs Mikrotik feedback] `reject-with` values are not documented any more

Sat Oct 22, 2016 12:04 pm

Let me do that for you
http://lmgtfy.com/?q=icmp+admin+prohibi ... e&l=1#seen

BTW there is no integer code in ROS v6.
Your post was *not* helpful, especially not in your role as Mikrotik Support employee. In that light I regard your post even as unprofessional especially since you insinuate I cannot search and your search results does not reveal any relevant standards explaining the information I was after.

After a long search, I found https://tools.ietf.org/html/rfc1812#section-5.2.7.1 which explains what the rejection code means and got there via https://tools.ietf.org/html/rfc5508#section-6 after observing that these RFCs call the flag "Communication administratively prohibited" which is not near a search for "icmp-admin-prohibited" or "icmp admin prohibited".

I don't expect you guys to be like companies such as Cisco in the extension of documentation, but I do expect linking to relevant documentation when you don't explain the why/how of certain functionality especially if you name things differently from standards.

In this case you guys should link to these RFCs or similar kinds of information (maybe even through the WayBack machine if you expect 404-errors) as right now you put the search burden on your customers instead of helping them.

--jeroen

Who is online

Users browsing this forum: No registered users and 24 guests