Community discussions

MikroTik App
 
ionutserban
just joined
Topic Author
Posts: 1
Joined: Fri May 31, 2019 7:25 pm

Problem with Firewall Rule

Fri May 31, 2019 7:30 pm

Hello everyone,

I have the following rule:

/ip firewall filter
add action=drop chain=forward comment="Deny SFTP traffic to DESTSERVER" dst-address=172.26.0.2 dst-port=22 out-interface=LTE protocol=tcp

Also this router should exchange banking data with payment pos. Since i added this rule to block traffic through SSH on that destination IP address payments are not working properly and it happens random as hell.

I was wondering if in firewall rule "dst-port=22" will only block SSH connection for that IP_addr or will block for every other connection?
Any ideas?

Thank you!
 
User avatar
CZFan
Forum Guru
Forum Guru
Posts: 2098
Joined: Sun Oct 09, 2016 8:25 pm
Location: South Africa, Krugersdorp (Home town of Brad Binder)
Contact:

Re: Problem with Firewall Rule

Fri Jun 07, 2019 1:54 am

It will block ssh, but as sftp runs over ssh session, it will also block sftp
 
jebz
Member
Member
Posts: 367
Joined: Sun May 01, 2011 12:03 pm
Location: Australia

Re: Problem with Firewall Rule

Mon Jun 10, 2019 4:14 am


Also this router should exchange banking data with payment pos. Since i added this rule to block traffic through SSH on that destination IP address payments are not working properly and it happens random as hell.
.
.
Check the counters when you're experiencing random application of the rule.The counters will tell you if it's the rule or something else.
 
rbnewfan
newbie
Posts: 28
Joined: Sat Oct 22, 2016 5:23 pm

Re: Problem with Firewall Rule

Mon Jun 10, 2019 11:06 am

Depends on what other rules are in effect, their order as well. This rule would block as it says - to this dst IP and this port.
Maybe your banking traffic depends in some step on SSH/port22 and is not always in effect.
Sometimes things are not that simple as one single TCP connection. As other said, look at rule's counter if it increments while banking payment is executing.

Who is online

Users browsing this forum: Qanon and 17 guests