Community discussions

MikroTik App
 
User avatar
ocgltd
Member Candidate
Member Candidate
Topic Author
Posts: 112
Joined: Sun Sep 02, 2012 12:53 am
Location: Ontario, Canada

Firewall rules - how control <pptp-*> interface traffic?

Thu Sep 06, 2012 5:32 pm

Under linux I could setup iptables rules which affected all pptp users, by referencing the interface like pptp-*

Under RBOS I can no longer do so - I think. Does that mean I can only create filters for PPTP control based on their source address? That seems very risky!

Thanks
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7189
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: Firewall rules - how control <pptp-*> interface traffic?

Thu Sep 06, 2012 6:22 pm

you can add static pptp entries in "/interface pptp-server" menu and use those interfaces.
 
User avatar
ocgltd
Member Candidate
Member Candidate
Topic Author
Posts: 112
Joined: Sun Sep 02, 2012 12:53 am
Location: Ontario, Canada

Re: Firewall rules - how control <pptp-*> interface traffic?

Thu Sep 06, 2012 8:45 pm

but that means I would have to create one new interface for EACH user. Then, I would have to replicate the firewall rules for EACH interface.

Is there a way to reference all interfaces by prefix like pptp-*

otherwise I would have to now create one (or more) firewall rules to EACH interface (for EACH user).
 
Inssomniak
Member
Member
Posts: 332
Joined: Fri Apr 13, 2007 11:21 pm

Re: Firewall rules - how control <pptp-*> interface traffic?

Thu Sep 06, 2012 11:01 pm

Address list?
 
User avatar
ocgltd
Member Candidate
Member Candidate
Topic Author
Posts: 112
Joined: Sun Sep 02, 2012 12:53 am
Location: Ontario, Canada

Re: Firewall rules - how control <pptp-*> interface traffic?

Thu Sep 06, 2012 11:13 pm

There's no easy to add each user to the address list (road warrior scenario)...or perhaps you could be more specific (maybe Im missing something).
 
User avatar
cbrown
Trainer
Trainer
Posts: 1839
Joined: Thu Oct 14, 2010 8:57 pm
Contact:

Firewall rules - how control interface traffic?

Fri Sep 07, 2012 3:46 am

There is an option in /ppp profile to add to address list.

http://wiki.mikrotik.com/wiki/Manual:PPP_AAA
 
User avatar
ocgltd
Member Candidate
Member Candidate
Topic Author
Posts: 112
Joined: Sun Sep 02, 2012 12:53 am
Location: Ontario, Canada

Re: Firewall rules - how control <pptp-*> interface traffic?

Fri Sep 07, 2012 4:50 am

OK - so the address list is associated with the profile, and the profile is associated with one or more users/secrets.

OK - thanks.

Who is online

Users browsing this forum: aboshhab and 64 guests