Community discussions

MikroTik App
 
ranto
just joined
Topic Author
Posts: 12
Joined: Wed Feb 08, 2006 11:45 am

Block access from internet

Wed Feb 08, 2006 1:08 pm

HI...all
First I'm sorry cause my english not good...

I've a MT Versi 2.9.11
and I want to set my client have the public IP but limited...where their IP can't access from internet...
so can't be a server like web server, ftp server, etc...but still can access to the internet...
I've try to configure as I can, but still not found :( :(

I hope you can help me ....

thx b4
 
cibernet
Long time Member
Long time Member
Posts: 610
Joined: Fri Jan 28, 2005 7:22 pm
Location: Marcos Juárez, Córdoba, Argentina
Contact:

Re: Block access from internet

Wed Feb 08, 2006 1:24 pm

HI...all
First I'm sorry cause my english not good...

I've a MT Versi 2.9.11
and I want to set my client have the public IP but limited...where their IP can't access from internet...
so can't be a server like web server, ftp server, etc...but still can access to the internet...
I've try to configure as I can, but still not found :( :(

I hope you can help me ....

thx b4
You must setup a bridge, then on firewall you have to open or close the ports that you want.. read the manual and search the forums..

Regards
 
User avatar
raulborda
just joined
Posts: 11
Joined: Tue Nov 01, 2005 8:57 pm
Location: Argentina
Contact:

Re: Block access from internet

Wed Feb 08, 2006 5:42 pm

HI...all
First I'm sorry cause my english not good...

I've a MT Versi 2.9.11
and I want to set my client have the public IP but limited...where their IP can't access from internet...
so can't be a server like web server, ftp server, etc...but still can access to the internet...
I've try to configure as I can, but still not found :( :(

I hope you can help me ....

thx b4
You need to configure a bridge, in this way you can assign a public ip to any client and block ports in your MT.
 
ranto
just joined
Topic Author
Posts: 12
Joined: Wed Feb 08, 2006 11:45 am

I've Found the Rule :)

Fri Feb 10, 2006 7:09 am

Okay...tq b4 Mr.Cibernet and Mr.Raulborda

I think my question not connect with the answer...
Maybe cause my english to mussy :roll: :roll:

But...pleasing 4 me coz I've found the "rule" :) :) :)

I put this script and ..yeah...walking matching with the one which I wish :) :) :) :)

[admin@Gw] ip firewall filter> pr
Flags: X - disabled, I - invalid, D - dynamic
0 chain=forward in-interface=eth1 out-interface=eth0 src-address=xxx.xxx.xxx.xxx action=accept

1 chain=forward connection-state=established action=accept

2 chain=forward connection-state=related action=accept

3 chain=input connection-state=established action=accept

4 chain=input connection-state=related action=accept

5 chain=forward protocol=icmp action=accept

6 chain=forward connection-state=invalid action=drop

7 chain=forward action=drop


With that script, client where connect to router can access internet but can't access from internet ....

So their IP although "Public" but can't be a server....

Tq and tq again
With respon all of you I become to motivated :wink: :wink: :wink:
 
User avatar
raulborda
just joined
Posts: 11
Joined: Tue Nov 01, 2005 8:57 pm
Location: Argentina
Contact:

Re: I've Found the Rule :)

Fri Feb 10, 2006 8:12 am

Okay...tq b4 Mr.Cibernet and Mr.Raulborda

I think my question not connect with the answer...
Maybe cause my english to mussy :roll: :roll:

But...pleasing 4 me coz I've found the "rule" :) :) :)

I put this script and ..yeah...walking matching with the one which I wish :) :) :) :)

[admin@Gw] ip firewall filter> pr
Flags: X - disabled, I - invalid, D - dynamic
0 chain=forward in-interface=eth1 out-interface=eth0 src-address=xxx.xxx.xxx.xxx action=accept

1 chain=forward connection-state=established action=accept

2 chain=forward connection-state=related action=accept

3 chain=input connection-state=established action=accept

4 chain=input connection-state=related action=accept

5 chain=forward protocol=icmp action=accept

6 chain=forward connection-state=invalid action=drop

7 chain=forward action=drop


With that script, client where connect to router can access internet but can't access from internet ....

So their IP although "Public" but can't be a server....

Tq and tq again
With respon all of you I become to motivated :wink: :wink: :wink:
Yes answer & question not are in the same topic :?
Your problem was other.
But if you founded a solution is good. Congratulations!!!!
 
ranto
just joined
Topic Author
Posts: 12
Joined: Wed Feb 08, 2006 11:45 am

Re: I've Found the Rule :)

Fri Feb 10, 2006 10:29 am

Yes answer & question not are in the same topic :?
Your problem was other.
But if you founded a solution is good. Congratulations!!!!
he..he..he..
I lose face...
Ok...case closed...

I've another problem but I'm trying 1st... :) :) :) :)

Tq :wink: :wink: :wink: :wink: