I want that HTTP requests do not even ENTER into WEB PROXY service for some certain sites (I have a list).
/ip proxy cache
add action=deny comment="Annoying" dst-host=annoyingsource.com
If this aforementioned line is like that, then the OP has a typo.Thanks .... I just tested @Shumkov code and it works very nicely .... excellent work.comment=$description timeout=1d} on-error={}
That makes sense.If server (with FQDN/IP and port number) is advertised on some gamers' site, then it will get hammered regardless the port ... because gamers' sites are welcome information source for (wannabe) hackers. Changing port number only works if knowledge about that port is not public.
{:delay 20};
Solution then?I solved my problem. closed topic. Thanks all so much
There's something missing while creating the cert and keyI made new config file, and no I get new error:
1.png
I can see them within the OpenWRT router but none of them reach MT. That's the thing.But are there any UPnP requests from OpenWRT to MT?
That address is the local page of the Modem. It is like 192.168.1.1 for routers to config. This modem has 4 WANs.So where exactly is 192.168.100.1? I assumed connected to WAN1 PoE, but it doesn't seem to be the case.
That might be the one. I problem is that I am not an expert in this field. If you could provide me an example, I'll try right away.What about simply blocking access from LAN subnet to 192.168.100.1?
Not exactly. I want to restrict access to the webpage of the modem. The one from Arris devices.Do you want to restrict the access to the Mikrotik Web Administration? If so, you can create firewall rules for that purpose, without layer7 stuff.
Can you share some configs for those spam and virus rules?Hmm..
spam & virus blocking I do with a combination of Postfix regex, amavisd-new and SpamAssassin
and not with firewall rules.
Thanks for the insight. Could you please give me an example based on the web (192.168.100.1)?well you can block access to port 80 to the modem ip from all ips in your subnet and add an allow rule over the drop one only for the ips you want to access it