Community discussions

MikroTik App
 
WirelessRudy
Forum Guru
Forum Guru
Topic Author
Posts: 3119
Joined: Tue Aug 08, 2006 5:54 pm
Location: Spain

IP\Firewall block PtP blocks ALL Traffic?

Sun Feb 04, 2007 1:23 pm

Hi,

I have a MT router with w wireless cards (one AP, one Backhaul) and 1 eth. They are all bridged and router is DHCP server. All nodes in same network.
When I enable the filter ¨ALL PtP traffic¨ (or only one specific) and the action=drop the packet filter stops ALL TRAFFIC?

When I try to stop specific ip adress by dropping all packets coming and going to this certain clients ip adress (src ip and dst ip) all traffic stops on other users too! It doesn´t matter if the filter is on top or bottom of the firewal filters and all in the ¨forward¨ chain.

I´ve been searching this forum and the OS manual but find no answer for this behaviour.
Its anyway not clear to me why the ¨block PtP traffic¨ filter option is in the OS packet filter while most forum users try to block by using mangle or prioritising traffic. What is the use of this simple (on/off!) setting and why is everybody going a much more complicated way?

The simple ¨add chain=forward p2p=all-p2p connection-state=established action=drop comment="p2p" disabled=no¨ does NOT work. It stops ALL traffic on the router!
 
ferry
Frequent Visitor
Frequent Visitor
Posts: 75
Joined: Mon Jan 15, 2007 11:59 am

Firewall Filter

Mon Feb 05, 2007 11:45 am

Maybe u should change ur rule with this and see :

before :
The simple ¨add chain=forward p2p=all-p2p connection-state=established action=drop comment="p2p" disabled=no¨ does NOT work. It stops ALL traffic on the router!

after :
The simple ¨add chain=forward p2p=!all-p2p connection-state=established action=accept comment="p2p" disabled=no¨
 
ferry
Frequent Visitor
Frequent Visitor
Posts: 75
Joined: Mon Jan 15, 2007 11:59 am

Firewall Filter

Mon Feb 05, 2007 11:45 am

Maybe u should change ur rule with this and see :

before :
The simple ¨add chain=forward p2p=all-p2p connection-state=established action=drop comment="p2p" disabled=no¨ does NOT work. It stops ALL traffic on the router!

after :
The simple ¨add chain=forward p2p=!all-p2p connection-state=established action=accept comment="p2p" disabled=no¨
 
WirelessRudy
Forum Guru
Forum Guru
Topic Author
Posts: 3119
Joined: Tue Aug 08, 2006 5:54 pm
Location: Spain

Tue Feb 06, 2007 3:33 am

Thanks for the reply.

I work with Winbox more then with command line and in Winbox this ptp blocking option has a ´tic´ box infront of that option.
Normally checking a ticbox means you enable the belonging option.
But with MT you actually tic that you wan´t NOT to block your choosen option, so NOT ptp traffic. But you tic actually to block ALL OTHER traffic and have ptp go on!

Although it even pops up with a little ¨NOT¨ when the mouse is above this tic box it still didn´t make that conclusion for me!

Stupid? Well call it that way. But when tic boxes are used to perform a 180 degrees turn in the option you just set is not a logical action in my brain..

But thanks again for your reply.
 
User avatar
janisk
MikroTik Support
MikroTik Support
Posts: 6263
Joined: Tue Feb 14, 2006 9:46 am
Location: Riga, Latvia

Tue Feb 06, 2007 10:39 am

if you check carefully you can see that is not a simple tick box, when you click it exclamation mark (!) appears.

and you know how to read !=
:roll:


when nothing works - just remember - humans, actually, cannot read and that you/me are just a human :D

Who is online

Users browsing this forum: jounij, miankamran7100, raov, tarfox, wispmikrotik and 44 guests