Community discussions

MikroTik App
 
ckonsultor
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 58
Joined: Sun Nov 21, 2021 7:57 pm

Firewall rule added in terminal (in Winbox) not shown in GUI list of rules

Thu Oct 06, 2022 4:42 am

Following the instructions for building your first firewall at https://help.mikrotik.com/docs/display/ ... t+Firewall, I ran the configuration commands for firewall rules in a terminal within Winbox. This was in Safe Mode. These additional rules do not appear in the list at IP / Firewall / FilterRules in Winbox. I toggled SafeMode off and on with no change in the list of rules.
Can't find a reference to this case on the Wiki. What am I missing?
 
holvoetn
Forum Guru
Forum Guru
Posts: 5474
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: Firewall rule added in terminal (in Winbox) not shown in GUI list of rules

Thu Oct 06, 2022 5:47 am

Which rules exactly ? Everything on that page ?
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19321
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Firewall rule added in terminal (in Winbox) not shown in GUI list of rules

Thu Oct 06, 2022 1:36 pm

Save yourself grief and use this instead...... viewtopic.php?t=180838

Use of safe mode is a very good idea, unlick safe mode to save the changes you have made thus far, then turn it back on.
Always wait a few seconds, if a change you make causes the router to burp it will come back to the last changes you made that you saved by turning safe mode off and on.
 
ckonsultor
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 58
Joined: Sun Nov 21, 2021 7:57 pm

Re: Firewall rule added in terminal (in Winbox) not shown in GUI list of rules

Sat Oct 08, 2022 4:39 am

Which rules exactly ? Everything on that page ?
Not quite. Didn't install rules to limit admin access, but did the others.
 
ckonsultor
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 58
Joined: Sun Nov 21, 2021 7:57 pm

Re: Firewall rule added in terminal (in Winbox) not shown in GUI list of rules

Sat Oct 08, 2022 4:53 am

Save yourself grief and use this instead...... viewtopic.php?t=180838
Thank you for the link. Have worked through it and compared to my rules. Modified them in places via winbox. RoS 6.49.1 shows "tarpit" under Action menu. Is this the same as blackhole mentioned by anav in the firewall discussion?
anav clarified something I missed up to this point: both Input and Forward chains need "drop all" rules at their ends.
Question: in the list of filter rules, does it matter if the different chains are intermixed? That is, does the filter function for Input ignore "Forward" rules?
Thanks.
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 11587
Joined: Thu Mar 03, 2016 10:23 pm

Re: Firewall rule added in terminal (in Winbox) not shown in GUI list of rules

Sat Oct 08, 2022 2:34 pm

Question: in the list of filter rules, does it matter if the different chains are intermixed? That is, does the filter function for Input ignore "Forward" rules?

It doesn't matter if rules for different chains are intermixed. When firewall determines proper chain for packet to enter, only rules for that chain are evaluated.
However, it is mighty useful if rules are grouped per chain, debugging (following rules) is much easier this way.
 
ckonsultor
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 58
Joined: Sun Nov 21, 2021 7:57 pm

Re: Firewall rule added in terminal (in Winbox) not shown in GUI list of rules

Sat Oct 08, 2022 6:35 pm

Question: in the list of filter rules, does it matter if the different chains are intermixed? That is, does the filter function for Input ignore "Forward" rules?

It doesn't matter if rules for different chains are intermixed. When firewall determines proper chain for packet to enter, only rules for that chain are evaluated.
However, it is mighty useful if rules are grouped per chain, debugging (following rules) is much easier this way.
When I grouped the chains by sorting on the Chain column in Winbox it seems I cannot re-order rules by dragging them up or down; can drag only when sorted by rule number (first column). Can still edit a rule when sorted into chains, so it may be useful to sort depending on what needs doing. Is that right?

Who is online

Users browsing this forum: Bing [Bot], DanMos79, haedertowfeq, Jörg, kg5iru, monotsc, unhuzpt and 62 guests