Community discussions

MikroTik App
 
Burgerito
just joined
Topic Author
Posts: 2
Joined: Fri Mar 21, 2025 10:57 pm

Basic firewall from tutorial

Fri Mar 21, 2025 11:28 pm

I have basic firewall rules from First Time Configuration tutorial:
https://help.mikrotik.com/docs/spaces/R ... figuration

Image

And now I'm wondering:
1) Should I have this first position "passthrough" or maybe it should be deleted? Does it make router less safe?
2) Is it necessary to extend these basic firewall rules or they are safe enough for typical user like me? :D
Maybe I should replace these tutorial ip firewall rules with default ip firewall rules? Probably there are more firewall rules in default config than in tutorial.
 
User avatar
tangent
Forum Guru
Forum Guru
Posts: 1695
Joined: Thu Jul 01, 2021 3:15 pm
Contact:

Re: Basic firewall from tutorial

Sun Mar 23, 2025 12:40 am

maybe it should be deleted?

The "D" in the flags column means it's a dynamic rule, created by the router when you add the fasttrack rule. If you try to delete it, the OS will give a complaint like "cannot remove builtin".

Does it make router less safe?

RouterOS wouldn't automatically add it if it did.

Is it necessary to extend these basic firewall rules or they are safe enough for typical user like me? :D

The defaults do cover all typical use cases.

A different perspective might help you sort this out.

Probably there are more firewall rules in default config than in tutorial.

Many more, yes.

(And that collection is partially outdated by 7.18, which added at least one more relative to the 7.15/16 prevalent when I began collecting defconfs.)
 
Burgerito
just joined
Topic Author
Posts: 2
Joined: Fri Mar 21, 2025 10:57 pm

Re: Basic firewall from tutorial

Sun Mar 23, 2025 1:17 am

Thanks for reply. Just to be sure. Is it better to stay with these firewall rules which i attached as image or just reset router to default router configuration with default ip firewall rules (different that on my photo)?
 
jaclaz
Forum Guru
Forum Guru
Posts: 2723
Joined: Tue Oct 03, 2023 4:21 pm

Re: Basic firewall from tutorial

Sun Mar 23, 2025 2:03 am

 
User avatar
tangent
Forum Guru
Forum Guru
Posts: 1695
Joined: Thu Jul 01, 2021 3:15 pm
Contact:

Re: Basic firewall from tutorial

Sun Mar 23, 2025 4:00 am

just reset router to default router configuration

Yes. Building a firewall from scratch is either an educational exercise, a hold-my-beer stunt, or a sign that you're way up at the top end of the expertise curve.

And incidentally, I happened to have roached my RB4011 since my prior post, giving me the opportunity (hah!) to netinstall it and pull a fresh defconf. You can see the differences relative to 7.15.2 here. The biggest is the addition of the IPv6 fasttrack rule.