Community discussions

MikroTik App
 
VlanLearner
just joined
Topic Author
Posts: 18
Joined: Fri Feb 17, 2017 1:27 pm

Firewallrule: TTL=1 to block Tethering and private Hotspot

Sun Apr 02, 2017 10:42 pm

I know this is not a save rule but the only option I have ....

Please help with this firewall rule. I would like to prevent the user from opening their own hotspot or tethering. In all VLANs it should be forbidden. Only in the AdminVLAN100 it should be allowed.

What do you think of the rules?

1. Rule:
/ip firewall mangle
add chain=postrouting action=change-ttl new-ttl=set:128 out-interface=AdminVLAN100
2. Rule:
/ip firewall mangle
add chain=postrouting action=change-ttl new-ttl=set:1 out-interface=all vlan

Greetings VlanLearner
Excuse me for my bad english (google translation)
 
pe1chl
Forum Guru
Forum Guru
Posts: 10551
Joined: Mon Jun 08, 2015 12:09 pm

Re: Firewallrule: TTL=1 to block Tethering and private Hotspot

Sun Apr 02, 2017 11:23 pm

Remember that such rules do not normally end processing when they match, as "accept" does.
So you need to arrange for that or else your first rule will do nothing.
 
sash7
Frequent Visitor
Frequent Visitor
Posts: 68
Joined: Sun Mar 20, 2016 10:39 pm

Re: Firewallrule: TTL=1 to block Tethering and private Hotspot

Sun Apr 02, 2017 11:58 pm

these guys who "opening their own hotspot" 100% know how to deal with ttl1 )