Community discussions

MikroTik App
 
shrek777
Member Candidate
Member Candidate
Topic Author
Posts: 264
Joined: Wed Jan 21, 2009 9:44 am

block some internal clients

Thu Jul 15, 2010 11:23 pm

hello
i have rb600 with 4 sectors and about 70 clients connected to it, i have configured rb600 as bridge (proxy arp) .

all clients have public ips, (client devices are loco2)

i want to block managmanet of client devices, i want to allow only some ips which can change settings for clients, for configuring we are using web managament of loco2.


thank you
 
adrianatkins
Long time Member
Long time Member
Posts: 556
Joined: Wed Sep 05, 2007 10:34 am
Location: Spain
Contact:

Re: block some internal clients

Fri Jul 16, 2010 1:22 am

change admin username from 'ubnt' to 'admin' on the locos.
Throws everyone.
 
shrek777
Member Candidate
Member Candidate
Topic Author
Posts: 264
Joined: Wed Jan 21, 2009 9:44 am

Re: block some internal clients

Fri Jul 16, 2010 10:39 am

of course i have changed but some people nows password again, so i want to block them to accessing loco 2, i want to block them from rb600
 
fewi
Forum Guru
Forum Guru
Posts: 7717
Joined: Tue Aug 11, 2009 3:19 am

Re: block some internal clients

Fri Jul 16, 2010 5:19 pm

Use firewall filters to drop that traffic, if you have a RouterOS device inbetween.

It's hard to be more specific without more details (network layout/diagram, management and customer IP addressing etc.)
 
shrek777
Member Candidate
Member Candidate
Topic Author
Posts: 264
Joined: Wed Jan 21, 2009 9:44 am

Re: block some internal clients

Fri Jul 16, 2010 10:33 pm

rb600 is ap, all clients are connected to rb 600, i want to block managament access on clients,
 
fewi
Forum Guru
Forum Guru
Posts: 7717
Joined: Tue Aug 11, 2009 3:19 am

Re: block some internal clients

Fri Jul 16, 2010 10:55 pm

Same answer. Without IP addressing schemes and a clear idea of what the network looks like it's impossible to write firewall filter rules for you.

So read the wiki on firewall filtering and write rules, or post those details.
 
perezcurda
just joined
Posts: 23
Joined: Wed Dec 24, 2008 10:10 pm

Re: block some internal clients

Sat Jul 17, 2010 1:13 am

just block the port 80 management to the specific nanoloco's IP's. and create a white-list to the IP tha need manage the radios.


ejemplo:

IP firewall address-list add address=xxx.xxx.xxx.xxx. list=WEB-WL

Accept

chain=forward dst-address=xxx.xxx.xxx.xxx (nanolocosIP's) action=accept protocol=tcp dst-address-list=web-WL-Senders dst-port=80
chain=forward dst-address=xxx.xxx.xxx.xxx (nanolocosIP's) action=accept protocol=tcp src-address-list=web-WL-Senders dst-port=80

Block
chain=forward dst-address=xxx.xxx.xxx.xxx (nanolocosIP's) action=drop protocol=tcp dst-address-list=!SMTP-WL-Senders dst-port=80
 
shrek777
Member Candidate
Member Candidate
Topic Author
Posts: 264
Joined: Wed Jan 21, 2009 9:44 am

Re: block some internal clients

Sun Jul 18, 2010 3:56 pm

Thank you everything is working

Who is online

Users browsing this forum: cage7557, jaclaz, McSee and 72 guests