Page 1 of 1

Firewall Rules Factory Setting

Posted: Thu Sep 23, 2021 1:16 pm
by ockac23
Hello guys,

I am attaching here a screenshot of the firewall factory settings of new bought Mikrotik hAP.
My question is why the rule blocking access from outside (rule# 6 currently disabled for testing) is taking effect although the rule allowing this is before it - at first position #1
If I enable rule 6 again it will block traffic from WAN although the rule allowing it is before it (on place 1)

What is the logic here?

https://c.gmx.com/@823553968113195249/F ... mVi9fNIC2A

Re: Firewall Rules Factory Setting

Posted: Thu Sep 23, 2021 1:22 pm
by infabo
The logic here is, that you should make relevant columns visible in WinBox. Add "Connection State" to "show columns". Then you should understand.

Re: Firewall Rules Factory Setting

Posted: Thu Sep 23, 2021 1:28 pm
by ockac23
I am on WebFig.

Re: Firewall Rules Factory Setting

Posted: Thu Sep 23, 2021 1:46 pm
by infabo
Weird WebFig. Apparently you can't add columns to the table. But never mind. Just click on the rule #1 and look whats configured.

Re: Firewall Rules Factory Setting

Posted: Thu Sep 23, 2021 2:01 pm
by ockac23
OK I saw the Connection State settings:
in rule 1: related, established, untracked

Does it mean that I have to create a new rule for allowing connection state "new" packets and to put it before rule #6, which is dropping everything not from !LAN ?

Re: Firewall Rules Factory Setting  [SOLVED]

Posted: Sun Oct 03, 2021 8:03 pm
by ockac23
I figured it out.
Added a new rule for accepting new, related, established, untracked, coming from interface list WAN and placed this new rule before the rule dropping everything coming not from !LAN.

Re: Firewall Rules Factory Setting

Posted: Sun Oct 03, 2021 9:03 pm
by Zacharias
In the default Firewall Configuration there is no rule accepting incoming traffic from WAN to the Router itself unless that traffic was initiated from the Router so it returns back as Established/related...
Only ICMP is explicitly allowed...

Re: Firewall Rules Factory Setting

Posted: Mon Oct 04, 2021 12:59 am
by rextended
Another zombie machine is coming out...