Community discussions

MikroTik App
 
jerrybrian
just joined
Topic Author
Posts: 1
Joined: Wed Aug 21, 2019 9:48 am

New to mikrotik, forward chain help needed

Wed Aug 21, 2019 9:50 am

I have a handle on my input chain, allow established connections, block invalid, allow all from LAN, then finally block all as a safety net. But below is my forward chain so far after setting up a Guest and Voice VLAN along with the usual rules the wiki suggested adding to secure the device.

I feel like this is overly complicated but can't think of a way to change it all to more efficiently do the same thing. Can anybody share their input on this forward chain and give me ideas on how they would structure it to accomplish the same things but just in a more efficient small matter.
 
User avatar
Anumrak
Forum Guru
Forum Guru
Posts: 1174
Joined: Fri Jul 28, 2017 2:53 pm

Re: New to mikrotik, forward chain help needed

Wed Aug 21, 2019 11:53 am

Hey. Default firewall filter for ipv4 and for ipv6 are pretty safe. You can backup your config to your PC, then do this https://wiki.mikrotik.com/wiki/Manual:Reset copy filter rules to notepad, recover your config, understand the logic of these rules and insert rules you need.
 
User avatar
victorsoares
Member Candidate
Member Candidate
Posts: 106
Joined: Thu Feb 15, 2018 6:29 pm
Location: Ubatuba, São Paulo - Brazil
Contact:

Re: New to mikrotik, forward chain help needed

Wed Aug 21, 2019 5:21 pm

I agree with Anumrak, default firewall is the best solution for 90% of the cases, on the other 10% it's a solid base as well. So unless you have some specific needs on your firewall, default will do you just fine.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 22116
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: New to mikrotik, forward chain help needed

Wed Aug 21, 2019 5:28 pm

Concur, if you want advice, suggest start with the default and then ask advice on specific additions as you go along.
A telling example of the flaw in your I know everything process is the fact that you think the entire LAN should have access to your router.
WRONG!. The only person that needs access via the input chain is the admin. Devices may require DNS access but thats it.

Who is online

Users browsing this forum: No registered users and 59 guests