Community discussions

MikroTik App
 
michalkos
newbie
Topic Author
Posts: 49
Joined: Sun Jun 11, 2006 11:33 pm

3.0RC11 - Filter in PPP profile not work

Thu Nov 29, 2007 4:57 pm

I try use filter for securing my VPN clients in PPP profile - not work.

I used Incoming filter, and in filter I used LOG rule.
I didn't see any log messages in log viewer.

Bridge option didn't work too.
 
cwolff
just joined
Posts: 5
Joined: Thu Sep 15, 2005 8:29 pm
Contact:

Re: 3.0RC11 - Filter in PPP profile not work

Mon Mar 10, 2008 9:47 pm

It doesn't work in 3.4 either. Vaya con dios.
 
changeip
Forum Guru
Forum Guru
Posts: 3833
Joined: Fri May 28, 2004 5:22 pm

Re: 3.0RC11 - Filter in PPP profile not work

Mon Mar 10, 2008 11:15 pm

are you placing a shim jump rule in the forward chain to jump to your ppp chain? Otherwise these new chains are ignored.
 
cwolff
just joined
Posts: 5
Joined: Thu Sep 15, 2005 8:29 pm
Contact:

Re: 3.0RC11 - Filter in PPP profile not work

Tue Mar 11, 2008 3:04 am

Yes, that's the workaround, which creates unwelcome "invalid" displays in the firewall rule display.

Ciao
 
changeip
Forum Guru
Forum Guru
Posts: 3833
Joined: Fri May 28, 2004 5:22 pm

Re: 3.0RC11 - Filter in PPP profile not work

Tue Mar 11, 2008 3:51 am

no no no ... it shouldnt be invalid. a single jump rule with no other specifiers (in-interface, out-interface, ips, etc should all be blank) and jump to chain=ppp. It has always been this way, even in 2.9. The dynamic jumps are placed in the ppp chain then and are used.

Sam
 
cwolff
just joined
Posts: 5
Joined: Thu Sep 15, 2005 8:29 pm
Contact:

Re: 3.0RC11 - Filter in PPP profile not work

Tue Mar 11, 2008 5:15 am

Well, it's invalid until the PPP user connects, then it becomes valid and applies the rules appropriately. It would be nice if it were valid at all times..
 
changeip
Forum Guru
Forum Guru
Posts: 3833
Joined: Fri May 28, 2004 5:22 pm

Re: 3.0RC11 - Filter in PPP profile not work

Tue Mar 11, 2008 6:26 am

ah ... i think thats why ive seen a blank passthru rule at the top in the hotspot on the custom chains... can you enter a passthru rule with a comment and have it always be valid ?