Community discussions

MikroTik App
 
infused
Member
Member
Topic Author
Posts: 313
Joined: Fri Dec 28, 2012 2:33 pm

Confused about the firewall

Sun Apr 28, 2013 12:40 pm

Hi Guys,

So I am filtering on the firewall. I have an internal ip, say 172.18.1.1 that I am dst-natting web traffic to from 202.20.1.1

If I create a firewall rule blocking traffic to destination 202.20.1.1, nothing happens. When I change this to the nat address of 172.18.1.1 it works. Does that mean that everything is getting dst-natted first? If so, how can I ensure it goes through the firewall first?
 
CelticComms
Forum Guru
Forum Guru
Posts: 1765
Joined: Wed May 02, 2012 5:48 am

Re: Confused about the firewall

Sun Apr 28, 2013 2:23 pm

Have a look at this:

http://wiki.mikrotik.com/wiki/Manual:Packet_Flow

The DST NAT occurs before the forwarding chain filters are applied.
 
infused
Member
Member
Topic Author
Posts: 313
Joined: Fri Dec 28, 2012 2:33 pm

Re: Confused about the firewall

Sun Apr 28, 2013 10:17 pm

Yep, saw that. Wouldn't that do extra routing that's possibly not needed though?
 
CelticComms
Forum Guru
Forum Guru
Posts: 1765
Joined: Wed May 02, 2012 5:48 am

Re: Confused about the firewall

Tue Apr 30, 2013 11:44 pm

Yep, saw that. Wouldn't that do extra routing that's possibly not needed though?
I don't really follow the question. The diagram shows how the packets flow. If you are using NAT in IP firewall you are using layer 3 functions including routing. Yes - DST NAT occurs before the forward chain filters.
Last edited by CelticComms on Wed May 01, 2013 3:26 am, edited 1 time in total.
 
Infatuas
newbie
Posts: 40
Joined: Fri Jan 18, 2013 5:40 am

Re: Confused about the firewall

Wed May 01, 2013 1:02 am

Which firewall chain are you using to block traffic to the NAT destination?

Who is online

Users browsing this forum: FurfangosFrigyes, moorezilla and 27 guests