Community discussions

MikroTik App
 
User avatar
Paradox
just joined
Topic Author
Posts: 20
Joined: Fri Oct 15, 2021 3:50 pm

VRRP, VLAN and firewall rules

Wed Dec 15, 2021 6:33 pm

Hello,
I'm running 2 VRRP routers, that have some VLANS configured. See the interfaces:
mikro-interfaces.png
But now I've got a problem when setting up firewall rules.
In the forward chain I'm trying to match against the output interface (which actually should be vrrp62), but I've noticed that some packets are using vlan62 and others are using vrrp62 as output interface.

I wonder how this happens? This way I'd need to setup all rules twice.
You do not have the required permissions to view the files attached to this post.
 
User avatar
Paradox
just joined
Topic Author
Posts: 20
Joined: Fri Oct 15, 2021 3:50 pm

Re: VRRP, VLAN and firewall rules

Wed Dec 15, 2021 6:46 pm

I guess this is caused because the route list has a dynamic route entry for each interface: vlan62 and vrrp62 which cannot be deactivated nor deleted.

A possible workaround:
Use the mangle rules to add a mark to all packets matching vlan62 and vrrp62. On the filter table use this mark instead of the output interface to match packets. But that doesn't feel like a real solution to me, more like a dirty workaround :(
 
Sob
Forum Guru
Forum Guru
Posts: 9188
Joined: Mon Apr 20, 2009 9:11 pm

Re: VRRP, VLAN and firewall rules

Wed Dec 15, 2021 6:57 pm

Did you by any chance miss this?
Note: address on VRRP interface must have /32 netmask if address configured on VRRP is from the same subnet as on router's any other interface.
 
User avatar
Paradox
just joined
Topic Author
Posts: 20
Joined: Fri Oct 15, 2021 3:50 pm

Re: VRRP, VLAN and firewall rules

Wed Dec 15, 2021 10:46 pm

I've indeed missed this... :oops: And it makes so much sense! Thanks!