Community discussions

MikroTik App
 
cavaughan
newbie
Topic Author
Posts: 45
Joined: Sun Nov 09, 2014 8:01 pm
Location: Seattle, WA, USA
Contact:

Firewall and blocking of certain ports

Fri Apr 28, 2023 6:28 pm

After setting up VPN access over Wireguard or L2TP/IPSEC, access to servers over smb, ssh, http(s), rdp, any service that was available on a server within the network was available. Suddenly, now only rdp and ssh work. Oddly enough https to the Mikrotik server on the LAN, of course, works, but http to any other server doesn't. The biggest issue is smb. Telneting to the proper ports for each service times out for smb, while it works from within the LAN. That is, if you're on the VPN subnet there is no access.
Any ideas why? It would seem that somehow something maybe got added to a blocked address list. But I don't see anything.
 
User avatar
k6ccc
Forum Guru
Forum Guru
Posts: 1591
Joined: Fri May 13, 2016 12:01 am
Location: Glendora, CA, USA (near Los Angeles)
Contact:

Re: Firewall and blocking of certain ports

Fri Apr 28, 2023 6:35 pm

Start by exporting and posting your configuration. Without that were are just guessing.
To export and paste your configuration (and I'm assuming you are using WebFig or Winbox), open a terminal window, and type (without the quotes) "/export hide-sensitive file=any-filename-you-wish". Then open the files section and right click on the filename you created and select download in order to download the file to your computer. It will be a text file with whatever name you saved to with an extension of .rsc. Suggest you then open the .rsc file in your favorite text editor and redact any sensitive information. Then in your message here, click the code display icon in the toolbar above the text entry (the code display icon is the 7th one from the left and looks like a square with a blob in the middle). Then paste the text from the file in between the two code words in brackets.
 
cavaughan
newbie
Topic Author
Posts: 45
Joined: Sun Nov 09, 2014 8:01 pm
Location: Seattle, WA, USA
Contact:

Re: Firewall and blocking of certain ports

Fri Apr 28, 2023 6:46 pm

Last edited by cavaughan on Sat Apr 29, 2023 5:48 am, edited 1 time in total.
 
R1CH
Forum Guru
Forum Guru
Posts: 1108
Joined: Sun Oct 01, 2006 11:44 pm

Re: Firewall and blocking of certain ports

Fri Apr 28, 2023 7:19 pm

Ditch the pointless anti-DDoS / anti-virus / etc rules, they will only slow down your router and cause problems / open you up to DoS.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 22247
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Firewall and blocking of certain ports

Fri Apr 28, 2023 8:15 pm

Concur, most of your rules are about blocking traffic vice only allowing needed traffic. Bloated approach.
 
cavaughan
newbie
Topic Author
Posts: 45
Joined: Sun Nov 09, 2014 8:01 pm
Location: Seattle, WA, USA
Contact:

Re: Firewall and blocking of certain ports

Fri Apr 28, 2023 8:48 pm

Thanks for that advice. I really thought such rules would better protect our network. I know they sure the router down, but what's more important. I'll start disabling and see how that works.