Community discussions

MikroTik App
 
User avatar
nichky
Forum Guru
Forum Guru
Topic Author
Posts: 1389
Joined: Tue Jun 23, 2015 2:35 pm

drop packets on mikrotik

Wed Sep 14, 2016 12:51 am

Hi,
I'm interested how can i see Drop Package on MikroTik. Does anyone know any rules on firewall. It will be helpful. I'm using the rouls, but i'm not sure does it connect.

ip firewall filter
add chain=forward protocol=tcp connection-state=invalid \
action=drop comment="drop invalid connections"
add chain=forward connection-state=established action=accept \
comment="allow already established connections"
add chain=forward connection-state=related action=accept \
comment="allow related connections"

Thanks
 
IntrusDave
Forum Guru
Forum Guru
Posts: 1286
Joined: Fri May 09, 2014 4:36 am
Location: Rancho Cucamonga, CA

Re: drop packets on mikrotik

Wed Sep 14, 2016 1:58 am

you can enabling logging on your default drop rule to see what what is being dropped.
 
User avatar
nichky
Forum Guru
Forum Guru
Topic Author
Posts: 1389
Joined: Tue Jun 23, 2015 2:35 pm

Re: drop packets on mikrotik

Wed Sep 14, 2016 2:12 am

Would you like to be more clear, i have understand you, but i have idea how to do rules.My one is incorrect?

Thanks
 
IntrusDave
Forum Guru
Forum Guru
Posts: 1286
Joined: Fri May 09, 2014 4:36 am
Location: Rancho Cucamonga, CA

Re: drop packets on mikrotik

Wed Sep 14, 2016 2:14 am

just add "log=yes" to your drop rules.
 
User avatar
nichky
Forum Guru
Forum Guru
Topic Author
Posts: 1389
Joined: Tue Jun 23, 2015 2:35 pm

Re: drop packets on mikrotik

Wed Sep 14, 2016 2:31 am

Doesn't matter enable log or not log the package is going on,see picture
You do not have the required permissions to view the files attached to this post.
 
elitebb
just joined
Posts: 11
Joined: Fri Sep 16, 2016 8:00 pm

Re: drop packets on mikrotik

Sat Sep 17, 2016 5:23 pm

Hello .

If you enable log you can see drop packet related log in mikrotik log manu .

And I don't understand what you mean by "the package is going on "

Be more sapcific so staff or other user can help you .

Regards
Nikem

Sent from my Le X507 using Tapatalk
 
stoser
Member Candidate
Member Candidate
Posts: 123
Joined: Sun Aug 21, 2016 12:04 am

Re: drop packets on mikrotik

Sat Sep 17, 2016 11:06 pm

Be more sapcific so staff or other user can help you .
Elittebb : He was tarpitting the packets, and you wrote "be more SAPcific" ... Gave me the best laugh of the week... :lol:

Nitchky: As elitebb wrote. You do not see the logs in the firewall rule in winbox. You can view them in the "LOG" section of the main menu in winbox. if you are loggin a lot of items, you can put a Log Prefix in the firewall rule to make them easier to find in the log. For example, you could put the log prefix "DROP INVALID CONNECTION /// "

Kind regards,
 
User avatar
nichky
Forum Guru
Forum Guru
Topic Author
Posts: 1389
Joined: Tue Jun 23, 2015 2:35 pm

Re: drop packets on mikrotik

Sun Sep 18, 2016 12:14 am

Just i want to follow my package, i've got QoS, and i want to know how many packing i'm losing. For that purpose i found rules for firewall. That one on this post are wrong. I found good one.

http://wiki.mikrotik.com/wiki/Manual:IP/Firewall/Filter

Thanks
 
User avatar
nichky
Forum Guru
Forum Guru
Topic Author
Posts: 1389
Joined: Tue Jun 23, 2015 2:35 pm

Re: drop packets on mikrotik

Sun Sep 18, 2016 12:55 am

yes stoser good advice, have you got that kind of rules? i didn't do similar think before.

Thanks
 
elitebb
just joined
Posts: 11
Joined: Fri Sep 16, 2016 8:00 pm

Re: RE: Re: drop packets on mikrotik

Sun Sep 18, 2016 8:59 am

Be more sapcific so staff or other user can help you .
Elittebb : He was tarpitting the packets, and you wrote "be more SAPcific" ... Gave me the best laugh of the week... [emoji38]

Kind regards,
Thanks.
Keep laughing .


@op

I hope now you find log in LOG menu and adding some prefix is gonna help you too

Regards .

Sent from my Le X507 using Tapatalk

Who is online

Users browsing this forum: jvanhambelgium, PavelRadvan, RaresC95, thezn and 27 guests