Can someone tell me what is the difference between:
Code: Select all
/ip firewall mangle chain=prerouting action=fasttrack-connection log=no log-prefix=""
Code: Select all
/ip firewall filter chain=forward action=fasttrack-connection connection-state=established,related log=no log-prefix=""
Also, I can mangle all 4 chains using fasttrack-connection action:
Code: Select all
> /ip firewall mangle print
Flags: X - disabled, I - invalid, D - dynamic
0 D ;;; special dummy rule to show fasttrack counters
chain=prerouting action=passthrough
1 D ;;; special dummy rule to show fasttrack counters
chain=forward action=passthrough
2 D ;;; special dummy rule to show fasttrack counters
chain=postrouting action=passthrough
3 chain=prerouting action=fasttrack-connection log=no log-prefix=""
4 chain=input action=fasttrack-connection log=no log-prefix=""
5 chain=output action=fasttrack-connection log=no log-prefix=""
6 chain=postrouting action=fasttrack-connection log=no log-prefix=""
Is there any benefit of fasttracking input/output/postrouting chains ?
Should I also include "established,related' states if using mangle instead of filter ?
There is little info to be found on this topic.
According to the wiki:
ip firewall mangle:
"fasttrack-connection - shows fasttrack counters, useful for statistics"
ip firewall filter:
"fasttrack-connection - process packets from a connection using FastPath by enabling FastTrack for the connection"
The mangle part is not true, because my fasttrack packet counters increase while using mangle action fasttrack (without using filter action fasttrack).