Page 1 of 1

accepting only PPPoE related traffic

Posted: Mon Nov 24, 2008 8:25 am
by captainproton
I have a Mikrotik Router with a wireless interface.

All useres connect to the wireless hotspot. For using the internet, they are required to establish a pppoe connection with a pppoe server in my network.

In order to keep useres from doing someting else then connecting with pppoe and surfing the web, I need some firewall rules.
e.g.: it shall not be possible for the clients to connect to the wireless station and ping network equipment or transfer data with other clients.

I am looking for some general rule, like: "drop all traffic comming in from the wireless interface except the pppoE connections"

Re: accepting only PPPoE related traffic

Posted: Sun Dec 07, 2008 11:24 am
by jcremin
This does sound interesting. I run a bridged network so I assume I'd need to use a bridge filter. Anyone know of a simple way to block everything except pppoe requests, the pppoe tunnel, arp, and mac-telnet. Is there anything else that's critical?

Re: accepting only PPPoE related traffic

Posted: Tue Dec 09, 2008 8:26 am
by kefiroid
arp=reply-only

Re: accepting only PPPoE related traffic

Posted: Tue Dec 09, 2008 8:35 am
by mrz
pppoe is identified as mac protocols 8864 and 8863 in bridge filters, allow these and drop the rest.