Community discussions

MikroTik App
 
User avatar
jrecabeitia
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 91
Joined: Tue Jun 05, 2007 2:26 pm
Location: Villa Dolores - Cordoba - Argentina
Contact:

ip firewall for pppoe

Tue Sep 15, 2009 2:53 pm

I want to filter traffic ip firewall for pppoe. While inspects is correct, I note that much traffic (pppoe) go to stop, but not observed to be blocked by any existing rule in the firewall.
I clarify that I want to do filtering on a bridge ptp, through which pass all the PPPoE connection.
I removed all firewall rules, but still follows the same behavior block some traffic.
Anyone have any idea whether it's a bug or some other problem?
 
User avatar
jrecabeitia
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 91
Joined: Tue Jun 05, 2007 2:26 pm
Location: Villa Dolores - Cordoba - Argentina
Contact:

ip firewall for pppoe

Wed Sep 16, 2009 2:01 pm

No one has implemented ip firewall for pppoe?
There is no documentation on this?
 
User avatar
jrecabeitia
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 91
Joined: Tue Jun 05, 2007 2:26 pm
Location: Villa Dolores - Cordoba - Argentina
Contact:

ip firewall for pppoe

Fri Sep 18, 2009 1:19 pm

Normis, do not stain or theme idea? It is an implementation that is not to be used? (ip firewall for pppoe)
 
User avatar
Chupaka
Forum Guru
Forum Guru
Posts: 8712
Joined: Mon Jun 19, 2006 11:15 pm
Location: Minsk, Belarus
Contact:

Re: ip firewall for pppoe

Fri Sep 18, 2009 2:03 pm

I don't think you can painlessly drop packets inside of pppoe connection. ROS don't rebuild tunnel, so dropping should cause retransmitting. you can only see what exactly is in PPPoE tunnel, and then shape it
 
User avatar
jrecabeitia
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 91
Joined: Tue Jun 05, 2007 2:26 pm
Location: Villa Dolores - Cordoba - Argentina
Contact:

Re: ip firewall for pppoe

Fri Sep 18, 2009 4:48 pm

I know that the ROS inspects the contents of PPPoE tunnels and even if they are rules, they work.
The issue is that with or without rules, there are connections within the tunnel to pass and others not.
For example:
Connecting to an SMTP server and / or pop3. Some servers will come and some do not.
The question is: Why?