MikroTik Tutorial 29 - Essential Firewall Filter Rules

  Рет қаралды 187,600

TKSJa

TKSJa

Күн бұрын

Пікірлер: 123
@MarkM_
@MarkM_ 7 жыл бұрын
Hey TKSJa, I just wanted to thank you for all of your videos. I have been using MikroTik devices for a few years and I cannot believe how many people have never heard of them. There are so few tutorial videos in English. Your channel is very unique in that way and you are servicing the world with your work. I have been recommending the routers and your videos to everybody I know that has the technical knowledge to follow along. God bless.
@nikko444
@nikko444 2 жыл бұрын
Same here! I can't believe somebody does such a great job supporting networking pros for free. I mean my paid CCNA course couldn't boast such a solid curriculum convey. Hats off for TKSJa!
@AikimaniacX
@AikimaniacX 4 жыл бұрын
Bought my first Mikrotik. Thanks a lot for videos and the website. Its great and i think it is actually only website where is all explained so average IT guy understands details without being network engineer. Thanks a lot.
@ronviejo4994
@ronviejo4994 5 жыл бұрын
Thank you sooooo much for these vids in English!! Your web site is excellent as well. I highly recommend his web page to anyone interested in learning more. I have an MTCNA but I learn more here than in the other classes I have taken. Great job!!
@harryp4618
@harryp4618 6 жыл бұрын
Hi TKSJa, I just got my hEX S couple of weeks ago and I'm going see some of your video tutorials. Thank you so much sir! You are very kind of sharing your work. :)
@josephstalin7995
@josephstalin7995 5 жыл бұрын
I'm gonna learn like Mike Boyd with these videos!
@sherwinceralbo1028
@sherwinceralbo1028 2 жыл бұрын
How can I get certified by you, you are a better mentor than a paid ccna instructor, in my own opinion. BTW kudos. We all love your content.
@nikko444
@nikko444 2 жыл бұрын
Hey, TKSJa! Man, thanks for your fantastic job on Mikrotik Tutorials. I can't tell you how many times your content saved my ass. Much respect and support from Canada. May luck and prosperity always be by your side! If you got a Patreon or whatnot, I'll be your patron hands-down!
@JohnSmith-dc6lc
@JohnSmith-dc6lc Жыл бұрын
Excellent work as usual! Thank you Your site is down…
@MrThe184
@MrThe184 2 жыл бұрын
Thank you...it's a really great video I'm a beginner ...but I understand can you make one video on hotspot user and firewall policy's... That' will be great help for me .....
@shtumpa1
@shtumpa1 4 жыл бұрын
I wish you still did videos .. it’s been so long !!!
@paulhemmerling579
@paulhemmerling579 6 жыл бұрын
Thank you for providing this tutorial (and all the others as well). This video is essential for Mikrotik noobs like myself.
@TKSJa
@TKSJa 6 жыл бұрын
You are welcome
@fdlp1445
@fdlp1445 6 жыл бұрын
Thank you TKSJA for sharing your knowledge about configuring Mikrotik routers it helps me a lot , i hope you continue making videos like this ^_^ more power to you bro
@TKSJa
@TKSJa 6 жыл бұрын
You are welcome.
@AP-qc9hi
@AP-qc9hi 6 жыл бұрын
Good guide. One question, what is the reasoning behind allowing tftp udp port 69 in the input and fwd chain?
@jefftee448
@jefftee448 5 жыл бұрын
I would like to know as well
@hartantosetiawan4835
@hartantosetiawan4835 11 ай бұрын
Hey TKSJa, i didnt find block all wan connection that did not dstnated ? is it all right
@thegoodsamaritan4333
@thegoodsamaritan4333 4 жыл бұрын
Good Sir, thank you for this free video. Guys, get this MAN a SUB!!
@signalvision
@signalvision Жыл бұрын
Hi, How the configuration if i have 2 input WAN eth 1 and 2, i need to add both . Thanks
@JohnSmith-dc6lc
@JohnSmith-dc6lc Жыл бұрын
? Should that script be modified to suite different ip pools?
@dwaynearthur1476
@dwaynearthur1476 6 жыл бұрын
Clear concise explanations for all of your videos . Excellent !!!
@tinashemutero878
@tinashemutero878 4 жыл бұрын
hi great tutorials, im getting better by using your videos
@6i668
@6i668 2 жыл бұрын
Filtering full bogon list requires about 5000 rules for IPv4 and about 70,000 rules for IPv6. Double those numbers numbers if you want to filter in both directions.
@pawemadej8589
@pawemadej8589 Жыл бұрын
I have RouterOS on virtual machine for learning and I've applied those rules and I see 1/3 of packets hitting last drop rule ... router is routing nothing at all now, why it's happening like this?
@waqasahmed1915
@waqasahmed1915 3 жыл бұрын
I already have some rules created by hotspot automatically. Should these rules (discussed in this video) go up the hotspot rules or below the hotspot rules?
@6i668
@6i668 2 жыл бұрын
Can someone please explain how well this rule will help in TJ's Fire Wall, My comments are not there to undermine his Fire Wall, I am using it. I just want to know how well and what the scope of this rule is. Thanks
@samiam9059
@samiam9059 4 жыл бұрын
Thank you for the education. Work's excellent!
@gilbertkipbett3487
@gilbertkipbett3487 Жыл бұрын
hello, the link to download the script is not available. Please help. Thank you.
@shanescudero9237
@shanescudero9237 6 жыл бұрын
thank you it helps me alot continue on making this kind of tutorials sir :)
@eheroi
@eheroi 5 жыл бұрын
thank you for your time to do these videos. i have learned a lot. thanks you again. keep going :)
@sheprev
@sheprev 4 жыл бұрын
thats so educative indeed. Thank you so much man
@Ser_Eyas
@Ser_Eyas 4 жыл бұрын
thank you for sharing your knowledge sir.. it help a lot.
@TKSJa
@TKSJa 4 жыл бұрын
You are most welcome
@arksurvivalevolved9190
@arksurvivalevolved9190 4 жыл бұрын
Thank you, very useful indeed. I have MikroTik CRS309-1G-8S+. I did copy firewall rules as you did and all seems ok, but when I reboot the switch, the rules are gone, empty again, can you comment why is this? Thank you
@TKSJa
@TKSJa 4 жыл бұрын
Check your if there any free space on the router
@Pesonkmamen
@Pesonkmamen 6 жыл бұрын
One of the best channel, thanks
@TKSJa
@TKSJa 6 жыл бұрын
You are welcome
@gerryfinnegan3942
@gerryfinnegan3942 6 жыл бұрын
Hello, Thank you, for all your well delivered videos. Would you consider doing a video on DMZ setup (SXT-LTE), where the goal is avoid double NAT (Bridging is not an option). The application - Internet > SXT LTE Kit > Wireless Router (Tomato firmware) with Vlan (ADSL connection + SXT LTE). If not maybe refer us to a clear walkthrough guide for this scenario. Thanks in hope ...
@sanches2
@sanches2 Жыл бұрын
Thank you, mate!😊
@Stefan-nn9zo
@Stefan-nn9zo 7 жыл бұрын
plz plz keep going make more mikrotik videos plz ....nice videos!!!
@TKSJa
@TKSJa 7 жыл бұрын
Thank you, more on the way.
@usmanjutt7908
@usmanjutt7908 7 жыл бұрын
how to block all websites and allow specfic like gmail yahoo hotmail and etc
@shahiinalam
@shahiinalam 4 жыл бұрын
how can I get firewall scripts ? also do i need ip address or anything edit before runnig sripts ? plz advise, much appriciated in advance
@stephenkojovan8634
@stephenkojovan8634 3 жыл бұрын
Pls sir can you.. kindly help us with internal firewall...on interface basis (that is blocking one network from reaching other.......thanks..l love ur videos...
@alanasiimwe
@alanasiimwe 6 жыл бұрын
Thanks for sharing very informative and educative!
@janecua9053
@janecua9053 5 жыл бұрын
What is the reason why the PORT 17 enable or allowed?
@jefftee448
@jefftee448 5 жыл бұрын
What is the reasoning behind allowing udp 69? I get if you have a specific tftp service, but that doesnt seem to apply in a generalized ruleset like this.
@TKSJa
@TKSJa 5 жыл бұрын
Not really necessary, you can remove it if you don't need it
@mauechristiankimcalitina2337
@mauechristiankimcalitina2337 Жыл бұрын
hi do you have any script of this?
@UPPERKEES
@UPPERKEES 4 жыл бұрын
What's the deal with the bridge filter? I would understand if it only would handle stuff like MAC filtering. But you can also do layer 3 stuff there (IP/port). Or, you can even enable an option to use the IP filter for the bridge. Can someone explain when and why you should use the bridge filter? And why there is an option to use the IP filter? And perhaps, is there a performance cost involved in these combinations of enabling the IP firewall for a bridge filter? The documentation only explains the options, but doesn't go into detail of applying these features the right way.
@epicclips6603
@epicclips6603 5 жыл бұрын
Hello, i am very confused. Rule 4 indicates all traffic from internet is dropped. But how..? secondly Rule 5. the destination list is list of all private addresses. what is firewall doing in this rule? is it preventing all traffic to these private addresses over internet from lan? because he says these addresses shouldnt go to internet than should the bogon list be source address list.?
@tinashemutero878
@tinashemutero878 4 жыл бұрын
Are you still answering questions ? please i really need your help
@noelechavez7364
@noelechavez7364 7 жыл бұрын
thank you for very informative tutorials. can i ask if i have a hotspot rule where i put your firewall rule. before hotspot rule or after? thank you.
@TKSJa
@TKSJa 7 жыл бұрын
+Noel Echavez It depends on what your rule is doing. You could move the rule up or down and see if the rule still works.
@noelechavez7364
@noelechavez7364 7 жыл бұрын
i will try, thank you.
@arkan7rb
@arkan7rb 7 жыл бұрын
mainly after the hotspot rules because they stop all from moving after hotspot but this rules is to filter them after getting access to gateway and the network
@TriTranTrong
@TriTranTrong 4 жыл бұрын
I just wanted to thank you for all of your videos. I use this line with Mikrotik but VPN sitetosite connect but isn't ping to Office 2 not working. I have tried to disable this rule then everything is fine. I use the network subnet mark 192.168.10.0/23 and office 2 is 192.168.30.0/24. Please help me
@Martin-ot7xj
@Martin-ot7xj 4 жыл бұрын
Hi there, please make a tutorial video about which ports by default we must to block on microtik firewall for more security?? Thnx
@emmanuelkitengo9906
@emmanuelkitengo9906 7 жыл бұрын
thank you sir your tutorial are spot on
@TKSJa
@TKSJa 7 жыл бұрын
You are welcome
@nabinmallik1290
@nabinmallik1290 6 жыл бұрын
is it apply for crs 210 mikrotik router or not
@niazwali381
@niazwali381 6 жыл бұрын
Hello Sir, I am going from a newbie to an advance user by watching you channel so first thanks for you effort, secondly I have a question that how to use this script if I have multiple WAN Connections Load balanced by PCC?
@TKSJa
@TKSJa 6 жыл бұрын
It should work ok because not out interface was defined in the rules.
@Xyamta
@Xyamta 3 жыл бұрын
Thank you!
@michaelsenkale9595
@michaelsenkale9595 Жыл бұрын
you didnt provide the scripts in your comment section for this video
@Martin-ot7xj
@Martin-ot7xj 5 жыл бұрын
Hi there edgerouter firewall is better or microtik router??
@Wahinies
@Wahinies 5 жыл бұрын
Mikrotik by far. I have a Hex RB750Gr3 at one office with longer uptime than three dead ER3L combined lifetimes at another office. Ubiquiti approved the first RMA but not the second. I only recommend UAPs from them. Routers and switches are firmly Mikrotiks territory. The RB4011, a $200 router, is capable of 10Gb between subinterfaces. Nothing from Ubiquiti can do that and to get something from Cisco or PAN would cost several thousand.
@Martin-ot7xj
@Martin-ot7xj 5 жыл бұрын
Thankyou for quick answer. How can i block all incoming traffic from outside or internet to my network for more security?? How can i make a rule in microtik firewall to block all incoming traffic to my network for more security against of attacks or trojan or malware ?? Please help me. Thnx
@Martin-ot7xj
@Martin-ot7xj 5 жыл бұрын
Thankyou for quick response. I have a quetion about firewall : between microtik and edgerouter 4 firewall, which one in term of firewall are more power than the other?? Thnx
@2001yareka
@2001yareka 5 жыл бұрын
hi sir this video are same hotspot filter rule thank you for reply..
@haseebj1449
@haseebj1449 5 жыл бұрын
Sir this video suit for if i share Internet through Microtik to clients So Internet Service Provider does not know the net is forword to clients
@ehldora3262
@ehldora3262 6 жыл бұрын
Dear TKSJa, thanks a lot for great Tutorial. Can you explain more about the script: add address=10.0.0.0/8 comment="Private[RFC 1918] - CLASS A # Check if you nee\ d this subnet before enable it" list=Bogons What it is used for ? or can I just ignore this line?
@TKSJa
@TKSJa 6 жыл бұрын
It prevents certain ip addresses from going to your WAN interface.
@tessabacon9291
@tessabacon9291 7 жыл бұрын
Can you please make a video on how to only allow access to specific sites and block everything else.
@jayadorable3601
@jayadorable3601 3 жыл бұрын
Thank you
@TKSJa
@TKSJa 3 жыл бұрын
You are welcome
@us5109
@us5109 5 жыл бұрын
filter rule for hostpot server?
@TheTeflon490
@TheTeflon490 5 жыл бұрын
The bogons rule order change @8:40 changes absolutely nothing, since it is in another chain (forward vs. input.) You should emphasize the critical importance of an order within a chain in the tutorial, otherwise people can be confused. First thing should be to group the list based on a chain, the way it is in this video is quite messy and hard to understand the flow as such.
@TKSJa
@TKSJa 5 жыл бұрын
Thanks for your feedback.
@adob1992
@adob1992 4 жыл бұрын
how to disable all firewall from mikrotik router manually
@johnlohan9900
@johnlohan9900 7 жыл бұрын
Please where can we have the script in this tutorial ?
@Palapi_H
@Palapi_H 6 жыл бұрын
tksja.com/essential-firewall-rules/
@marine1718
@marine1718 5 жыл бұрын
thanks for the help
@TKSJa
@TKSJa 5 жыл бұрын
You are welcome
@gpligor
@gpligor 3 жыл бұрын
aren't you missing the background music on this one ? :)
@TrongHuanNguyen
@TrongHuanNguyen 6 жыл бұрын
Thank you so much.
@boyansokolov6802
@boyansokolov6802 7 жыл бұрын
Man, I see you are learning every day and you are getting better and better. But in most of your videos where you speak about firewalls, I see that you are not completele aware about firewall rules. You need to learn a little bit more to clear the picture in your mind. In the firewall menu, in FILTER tab, NAT tab, MANGLE tab and so on, it is organised into chains where you can see them better from the drop down menu. So when you move some of your rules (lines) up or down, they take effect only in their respective chains. For example in your video in minute 8:50 you are moving a "forward" rule above "input" rule which will have the same effect as if you do not move it. If you want to take an effect you must think of moving it above the last forward rule (same chain). In other words, if you have two drop rules in different chains, it doesn't matter which one of them is above the other. I hope i cleared it for you.
@TKSJa
@TKSJa 7 жыл бұрын
Thanks for feedback, you have imparted valuable knowledge.
@boyansokolov6802
@boyansokolov6802 7 жыл бұрын
TKSJa keep going. You are doing well
@somalicinema630
@somalicinema630 3 жыл бұрын
Please make tutorial with apk android mikrotik
@tonyferguson7956
@tonyferguson7956 5 жыл бұрын
Hello TKSJa I have a router between two networks, I would like to allow all traffic between these two networks, how do I configure my router?
@fajkoson
@fajkoson 5 жыл бұрын
lets say you have WAN port on eth1 and eth2-3 subnet1, eth4-5 subnet2, then for each subnet you can use vlan... check cisco tutorials
@khaingmye7353
@khaingmye7353 7 жыл бұрын
thank you so much
@TKSJa
@TKSJa 7 жыл бұрын
You are welcome
@khaingmye7353
@khaingmye7353 7 жыл бұрын
Could you please upload a video of DNS cache and web proxy set up for Mikrotik please? Much appreciated :)
@mostafaali-wr7nj
@mostafaali-wr7nj 5 жыл бұрын
Hi TKJa thank you for your efforts to explain mik Please I have questions for you If you have Facebook account this make interface with you very easy
@meazz1
@meazz1 7 жыл бұрын
Hey TKSJa, great tutorial. One question, does it matter what Lan subnet it use? For example, if I use Lan 192.168.3.1 or 10.0.8.1 and the default script will still or? thanks
@TKSJa
@TKSJa 7 жыл бұрын
No it doesn't.
@mehdiazzad565
@mehdiazzad565 7 жыл бұрын
I need to add a rule so if someone ping my gateway's ip address from outside my network should reject it. Currently its sends reply.
@johntaylor8509
@johntaylor8509 6 жыл бұрын
Enable NAT, action=masquerade
@NiskarShrestha
@NiskarShrestha 5 жыл бұрын
can we block all the vpn from mikrotik??
@TKSJa
@TKSJa 5 жыл бұрын
yes, you need to know the ports.
@rizhanet2911
@rizhanet2911 6 жыл бұрын
i like script, (copy and paste), you should teach us how to write script not only in this vidoe
@fajkoson
@fajkoson 5 жыл бұрын
well, he doesnt have to do anything at all.. if you want to know something.. learn it yourself..
@Pavel1TU
@Pavel1TU 3 жыл бұрын
Pokud autor povolí ve FW něco jako toto add action=accept chain=input port=69 protocol=udp add action=accept chain=forward port=69 protocol=udp neměl by nikomu radit ;)
@Martin-ot7xj
@Martin-ot7xj 4 жыл бұрын
Hi, please make a tutorial video about how we can block all incoming traffic from outside or internet to the network on microtik firewall, i mean block bad traffic or attack for any request from wan port to lan for more security. Thnx
@wyc2462
@wyc2462 4 жыл бұрын
2020 HERE!!
@matej_stepan
@matej_stepan 6 жыл бұрын
doesn't work on 6.42.6
@alex.username
@alex.username 5 жыл бұрын
what exactly?
@fajkoson
@fajkoson 5 жыл бұрын
@@alex.username since there is not master port you have to set it differently.. you set ports 2-5 under br1 +wan instead using master port.
@mrthapa07
@mrthapa07 5 жыл бұрын
can i get your email ???I need some help .
@duncansagini685
@duncansagini685 2 жыл бұрын
the config script is nolonger there😑
@madas2705
@madas2705 4 жыл бұрын
Please do not share personal experiance as general case studies. Fist it is unprofessional and second, it is less concludent!
@jaykay1304
@jaykay1304 5 жыл бұрын
nice videos. is there a way of blocking porn sites with a custom message
@mostafaali-wr7nj
@mostafaali-wr7nj 5 жыл бұрын
Please please
@johnmeyers6115
@johnmeyers6115 3 жыл бұрын
I can stand listening to you... too many pauses... too many times you need to think what to say...
@TheMockTv
@TheMockTv 4 жыл бұрын
thank you, the videos it helps me alot to configure my mikrotik router
@mongolianwolf1113
@mongolianwolf1113 4 жыл бұрын
Thank you very much.
@TKSJa
@TKSJa 4 жыл бұрын
You are welcome!
@alestherabong3798
@alestherabong3798 6 жыл бұрын
Can you please make a video on how to only allow access to specific sites and block everything else.
MikroTips: How to firewall
21:56
MikroTik
Рет қаралды 152 М.
When mom gets home, but you're in rollerblades.
00:40
Daniel LaBelle
Рет қаралды 145 МЛН
Random Emoji Beatbox Challenge #beatbox #tiktok
00:47
BeatboxJCOP
Рет қаралды 62 МЛН
Perfect Pitch Challenge? Easy! 🎤😎| Free Fire Official
00:13
Garena Free Fire Global
Рет қаралды 79 МЛН
ROSÉ & Bruno Mars - APT. (Official Music Video)
02:54
ROSÉ
Рет қаралды 327 МЛН
Защита Mikrotik от внешних угроз
1:09:13
Mikrotik Training
Рет қаралды 106 М.
Getting Started: MikroTik Firewall
28:00
The Network Berg
Рет қаралды 52 М.
Bruteforce protection - MikroTik firewall rules
5:35
MikroTik
Рет қаралды 31 М.
Packet-Flow Diagram: Mangle, NAT, Connection Tracker
1:07:18
Mikrotik Training
Рет қаралды 12 М.
Full MikroTik MTCNA -  Firewall Principles (Forward,Input,Output)
18:14
The Network Berg
Рет қаралды 27 М.
MikroTik Tutorial 47 - Blocking Porn for specific users
8:37
Migrating From OPNsense To Mikrotik
19:11
Mircea Anton
Рет қаралды 24 М.
Настройка офисного Mikrotik для начинающих
1:58:21
When mom gets home, but you're in rollerblades.
00:40
Daniel LaBelle
Рет қаралды 145 МЛН