Community discussions

MikroTik App
 
User avatar
Chupaka
Forum Guru
Forum Guru
Topic Author
Posts: 8709
Joined: Mon Jun 19, 2006 11:15 pm
Location: Minsk, Belarus
Contact:

Non-contigous network mask is incorrectly converted/used in firewall

Fri Jan 28, 2022 12:55 pm

When I add a rule like this:
/ip firewall filter add chain=output dst-address=192.168.0.168/255.255.0.255
it is automatically converted to this:
chain=output action=accept dst-address=192.168.0.168-192.168.255.168
But this catches addresses like 192.168.1.169, not only 192.168.X.168

Where do things go wrong?
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 11627
Joined: Thu Mar 03, 2016 10:23 pm

Re: Non-contigous network mask is incorrectly converted/used in firewall

Fri Jan 28, 2022 12:59 pm

Ignorance about particular use case ... hence wrong conversion. Not sure why address/mask notation needs conversion to address range though.

If I may ask: what would be use case of your accept rule?
 
User avatar
Chupaka
Forum Guru
Forum Guru
Topic Author
Posts: 8709
Joined: Mon Jun 19, 2006 11:15 pm
Location: Minsk, Belarus
Contact:

Re: Non-contigous network mask is incorrectly converted/used in firewall

Fri Jan 28, 2022 1:07 pm

Thinking about (CG)NAT applications, Filter was just an easy example

Who is online

Users browsing this forum: Ahrefs [Bot] and 211 guests