Community discussions

MikroTik App
 
captainproton
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 73
Joined: Sat Jan 12, 2008 3:01 pm

accepting only PPPoE related traffic

Mon Nov 24, 2008 8:25 am

I have a Mikrotik Router with a wireless interface.

All useres connect to the wireless hotspot. For using the internet, they are required to establish a pppoe connection with a pppoe server in my network.

In order to keep useres from doing someting else then connecting with pppoe and surfing the web, I need some firewall rules.
e.g.: it shall not be possible for the clients to connect to the wireless station and ping network equipment or transfer data with other clients.

I am looking for some general rule, like: "drop all traffic comming in from the wireless interface except the pppoE connections"
 
jcremin
Member
Member
Posts: 360
Joined: Fri May 25, 2007 7:57 am

Re: accepting only PPPoE related traffic

Sun Dec 07, 2008 11:24 am

This does sound interesting. I run a bridged network so I assume I'd need to use a bridge filter. Anyone know of a simple way to block everything except pppoe requests, the pppoe tunnel, arp, and mac-telnet. Is there anything else that's critical?
 
kefiroid
just joined
Posts: 6
Joined: Thu Nov 27, 2008 10:51 am

Re: accepting only PPPoE related traffic

Tue Dec 09, 2008 8:26 am

arp=reply-only
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7199
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: accepting only PPPoE related traffic

Tue Dec 09, 2008 8:35 am

pppoe is identified as mac protocols 8864 and 8863 in bridge filters, allow these and drop the rest.