Community discussions

MikroTik App
 
toxicfusion
Member
Member
Topic Author
Posts: 326
Joined: Mon Jan 14, 2013 6:02 pm

input drop all rule - moved by accident!!

Wed Dec 07, 2016 6:13 pm

Hey there,

I was in a customer router (Winbox) monitoring traffic and doing a review of the firewall rules....

SOMEHOW, when I was ready to close the firewall window -- the filter input = drop all rule, got moved to top of list.

I realized this and tried to move it back below the filter accept rules, was too late and lost connection.

Their outside port forwarding / dst-nat rules appear to still be working.

How can I be able to correct this?

onsite visit and connect to router and Use neighbor discovery? Or completely locked out from accessing and require a full reset?
 
User avatar
tslytsly
Frequent Visitor
Frequent Visitor
Posts: 65
Joined: Tue Oct 27, 2015 6:52 pm
Location: Nottingham
Contact:

Re: input drop all rule - moved by accident!!

Wed Dec 07, 2016 6:23 pm

Hi Toxicfusion,

I'm afraid that you will likely have to go to site and connect via console cable.

This is why the Safe Mode is so good....
 
freemannnn
Forum Veteran
Forum Veteran
Posts: 700
Joined: Sun Oct 13, 2013 7:29 pm

Re: input drop all rule - moved by accident!!

Wed Dec 07, 2016 6:24 pm

next time use "safe mode". better safe than sorry.
"lol i dont use safe mode also"
tell us what u finally did
 
toxicfusion
Member
Member
Topic Author
Posts: 326
Joined: Mon Jan 14, 2013 6:02 pm

Re: input drop all rule - moved by accident!!

Wed Dec 07, 2016 6:24 pm

Absolutely love safe mode. However, unfortunately by default winbox does not connect via safe mode

When i make any config changes, I'll enable safe mode prior to changes. However, it was one of those -- let me watch some VOIP traffic and look over my firewall rules. As last night I made some rule changes and more traffic shaping, so was watching on business hours traffic.
 
toxicfusion
Member
Member
Topic Author
Posts: 326
Joined: Mon Jan 14, 2013 6:02 pm

Re: input drop all rule - moved by accident!!

Wed Dec 07, 2016 6:26 pm

access via console... its a RB2011 device

There is a Mini USB port in front, can connect with mini-usb and use terminal?

Idea's?
 
User avatar
tslytsly
Frequent Visitor
Frequent Visitor
Posts: 65
Joined: Tue Oct 27, 2015 6:52 pm
Location: Nottingham
Contact:

Re: input drop all rule - moved by accident!!

Wed Dec 07, 2016 6:31 pm

access via console... its a RB2011 device

There is a Mini USB port in front, can connect with mini-usb and use terminal?

Idea's?
RB2011's have an RJ45 Cisco type serial connection.
 
freemannnn
Forum Veteran
Forum Veteran
Posts: 700
Joined: Sun Oct 13, 2013 7:29 pm

Re: input drop all rule - moved by accident!!

Wed Dec 07, 2016 6:32 pm

Absolutely love safe mode. However, unfortunately by default winbox does not connect via safe mode
there should be an option in winbox start screen like "connect in safe mode"
You do not have the required permissions to view the files attached to this post.
Last edited by freemannnn on Wed Dec 07, 2016 6:34 pm, edited 1 time in total.
 
User avatar
nickshore
Long time Member
Long time Member
Posts: 524
Joined: Thu Mar 03, 2005 4:14 pm
Location: Suffolk, UK.
Contact:

Re: input drop all rule - moved by accident!!

Wed Dec 07, 2016 6:32 pm

there is an rj45 on the back or just use winbox to a mac address if you are plugged into one of the ethernets
 
nescafe2002
Forum Veteran
Forum Veteran
Posts: 915
Joined: Tue Aug 11, 2015 12:46 pm
Location: Netherlands

Re: input drop all rule - moved by accident!!

Wed Dec 07, 2016 6:34 pm

Just connect via MAC and you can bypass the (IP) firewall.

Assuming you haven't disabled WinBox interface under MAC Server :)
 
User avatar
tslytsly
Frequent Visitor
Frequent Visitor
Posts: 65
Joined: Tue Oct 27, 2015 6:52 pm
Location: Nottingham
Contact:

Re: input drop all rule - moved by accident!!

Wed Dec 07, 2016 6:34 pm

Just had to say that I'm proud to have ninja'd 2 posts! :lol:
 
toxicfusion
Member
Member
Topic Author
Posts: 326
Joined: Mon Jan 14, 2013 6:02 pm

Re: input drop all rule - moved by accident!!

Wed Dec 07, 2016 6:39 pm

Thanks guys!

I'm aware of the Winbox MAC connect (Neighbor) This was my first guess to access the device, but was uncertain if it would 100% bypass the firewall filter rules.

I have a cisco style rj45 console cable. Will go onsite and make it happen.

FYI: I'm using Winbox version 3.7 -- there is no option to connect with safemode

also newer versions of winbox do not have the 'Connect To:' drop list for finding MicroTik's via Mac addr, so have to use Neighbor.
 
freemannnn
Forum Veteran
Forum Veteran
Posts: 700
Joined: Sun Oct 13, 2013 7:29 pm

Re: input drop all rule - moved by accident!!

Wed Dec 07, 2016 6:42 pm

safe mode is avalaible after you connect to a site. top left.
my #7 post was a suggestion to mikrotik to place an option before you connect to a site
Last edited by freemannnn on Wed Dec 07, 2016 6:43 pm, edited 1 time in total.
 
toxicfusion
Member
Member
Topic Author
Posts: 326
Joined: Mon Jan 14, 2013 6:02 pm

Re: input drop all rule - moved by accident!!

Wed Dec 07, 2016 6:43 pm

safe mode is avalaible after you connect to a site. top left.
Correct - which I use when I make config changes. Just waiting for feature request to be added to winbox for 'connect with safemode'

Will let you guys know if i'm able to regain access
 
toxicfusion
Member
Member
Topic Author
Posts: 326
Joined: Mon Jan 14, 2013 6:02 pm

Re: input drop all rule - moved by accident!!

Wed Dec 07, 2016 7:00 pm

You guys were on fire today replying to post ;). Appreciated!
 
toxicfusion
Member
Member
Topic Author
Posts: 326
Joined: Mon Jan 14, 2013 6:02 pm

Re: input drop all rule - moved by accident!!

Wed Dec 07, 2016 7:23 pm

update:

I just tested this scenario with a spare mikrotik i have in the office. Winbox worked perfectly using mac address, didnt even need to configure an IP on the laptop NIC interface.

However, I tried a tripp-lite USB to Rj45 console cable -- this doesnt appear to work for console? Nothing displays, baud 9600
 
User avatar
tslytsly
Frequent Visitor
Frequent Visitor
Posts: 65
Joined: Tue Oct 27, 2015 6:52 pm
Location: Nottingham
Contact:

Re: input drop all rule - moved by accident!!

Wed Dec 07, 2016 8:44 pm

update:

However, I tried a tripp-lite USB to Rj45 console cable -- this doesnt appear to work for console? Nothing displays, baud 9600
default baud is 115200 on Mikrotik
 
estar
Frequent Visitor
Frequent Visitor
Posts: 50
Joined: Wed Dec 07, 2016 9:26 pm

Re: input drop all rule - moved by accident!!

Wed Dec 07, 2016 9:39 pm

I've got out of sticky situations before by using the MAC telnet if your connected via layer 3. If not working fromm winbox try using a teminal from a neighbour router that you can access on the same layer3 network.

Often you can access because it bypasses the IP side of the firewall just using mac address
 
Sob
Forum Guru
Forum Guru
Posts: 9188
Joined: Mon Apr 20, 2009 9:11 pm

Re: input drop all rule - moved by accident!!

Wed Dec 07, 2016 9:45 pm

Simply connect over IPv6. ;) Ok, I know I'm not being helpful, because if you had it, you'd know to use it. So just for future reference, maybe it will inspire someone. It's really great thing to have, if for nothing else, then for situations like this. No matter how much you mess up one protocol's firewall, it does not affect the other one.
 
toxicfusion
Member
Member
Topic Author
Posts: 326
Joined: Mon Jan 14, 2013 6:02 pm

Re: input drop all rule - moved by accident!!

Thu Dec 08, 2016 6:21 pm

Thanks everyone!

Noted about the baud rate needing to be 115200...

Customer is all set, connected using MAC address method within Winbox

NOTE: we do provide them fiber to their office, however I have telnet service disabled on the customer MikroTiks

I'll keep this in mind for future though!!