Community discussions

MikroTik App
 
User avatar
r359
just joined
Topic Author
Posts: 8
Joined: Wed Jan 18, 2017 2:22 pm
Location: Iran

Firewall Input Destination Address

Wed Nov 22, 2017 8:05 pm

Hello,
I encountered a question today, it's about firewall and the Input chain.
as I know we use Input chain for those packets that their destinations are set to our address. and they want to ask something from us, so we use input here. we use output when we are giving them a reply to their request that was asked before from an input operation, and forward ..
my question is in IP> Firewall> Filter> chain> input> why can we set a dst address ? isn't it that all input data's Destination Addresses are just same as our address ?

Thanks in advance
 
User avatar
Paternot
Forum Guru
Forum Guru
Posts: 1064
Joined: Thu Jun 02, 2016 4:01 am
Location: Niterói / Brazil

Re: Firewall Input Destination Address  [SOLVED]

Wed Nov 22, 2017 8:42 pm

Hello,

my question is in IP> Firewall> Filter> chain> input> why can we set a dst address ? isn't it that all input data's Destination Addresses are just same as our address ?

Thanks in advance
Not always. Your router may have 5 different IPs - one for each network. All of them are "input", but that doesn't mean you want to, say, open ssh on all interfaces.
Or you may want to allow ssh from network in interface 1 - but only if it goes to the address on a VPN interface.
 
User avatar
r359
just joined
Topic Author
Posts: 8
Joined: Wed Jan 18, 2017 2:22 pm
Location: Iran

Re: Firewall Input Destination Address

Wed Nov 22, 2017 9:13 pm

Hello,

my question is in IP> Firewall> Filter> chain> input> why can we set a dst address ? isn't it that all input data's Destination Addresses are just same as our address ?

Thanks in advance
Not always. Your router may have 5 different IPs - one for each network. All of them are "input", but that doesn't mean you want to, say, open ssh on all interfaces.
Or you may want to allow ssh from network in interface 1 - but only if it goes to the address on a VPN interface.
yea, you've enlighten me :D thanks for the answer.