Hey TKSJa, I just wanted to thank you for all of your videos. I have been using MikroTik devices for a few years and I cannot believe how many people have never heard of them. There are so few tutorial videos in English. Your channel is very unique in that way and you are servicing the world with your work. I have been recommending the routers and your videos to everybody I know that has the technical knowledge to follow along. God bless.
@nikko4443 жыл бұрын
Same here! I can't believe somebody does such a great job supporting networking pros for free. I mean my paid CCNA course couldn't boast such a solid curriculum convey. Hats off for TKSJa!
@AikimaniacX4 жыл бұрын
Bought my first Mikrotik. Thanks a lot for videos and the website. Its great and i think it is actually only website where is all explained so average IT guy understands details without being network engineer. Thanks a lot.
@josephstalin79955 жыл бұрын
I'm gonna learn like Mike Boyd with these videos!
@nikko4443 жыл бұрын
Hey, TKSJa! Man, thanks for your fantastic job on Mikrotik Tutorials. I can't tell you how many times your content saved my ass. Much respect and support from Canada. May luck and prosperity always be by your side! If you got a Patreon or whatnot, I'll be your patron hands-down!
@AP-qc9hi6 жыл бұрын
Good guide. One question, what is the reasoning behind allowing tftp udp port 69 in the input and fwd chain?
@jefftee4485 жыл бұрын
I would like to know as well
@ronviejo49945 жыл бұрын
Thank you sooooo much for these vids in English!! Your web site is excellent as well. I highly recommend his web page to anyone interested in learning more. I have an MTCNA but I learn more here than in the other classes I have taken. Great job!!
@sherwinceralbo10282 жыл бұрын
How can I get certified by you, you are a better mentor than a paid ccna instructor, in my own opinion. BTW kudos. We all love your content.
@harryp46186 жыл бұрын
Hi TKSJa, I just got my hEX S couple of weeks ago and I'm going see some of your video tutorials. Thank you so much sir! You are very kind of sharing your work. :)
@paulhemmerling5796 жыл бұрын
Thank you for providing this tutorial (and all the others as well). This video is essential for Mikrotik noobs like myself.
@TKSJa6 жыл бұрын
You are welcome
@JohnSmith-dc6lc Жыл бұрын
? Should that script be modified to suite different ip pools?
@shtumpa14 жыл бұрын
I wish you still did videos .. it’s been so long !!!
@waqasahmed19153 жыл бұрын
I already have some rules created by hotspot automatically. Should these rules (discussed in this video) go up the hotspot rules or below the hotspot rules?
@fdlp14456 жыл бұрын
Thank you TKSJA for sharing your knowledge about configuring Mikrotik routers it helps me a lot , i hope you continue making videos like this ^_^ more power to you bro
@TKSJa6 жыл бұрын
You are welcome.
@tinashemutero8784 жыл бұрын
hi great tutorials, im getting better by using your videos
@MrThe1842 жыл бұрын
Thank you...it's a really great video I'm a beginner ...but I understand can you make one video on hotspot user and firewall policy's... That' will be great help for me .....
@signalvision Жыл бұрын
Hi, How the configuration if i have 2 input WAN eth 1 and 2, i need to add both . Thanks
@JohnSmith-dc6lc Жыл бұрын
Excellent work as usual! Thank you Your site is down…
@noelechavez73647 жыл бұрын
thank you for very informative tutorials. can i ask if i have a hotspot rule where i put your firewall rule. before hotspot rule or after? thank you.
@TKSJa7 жыл бұрын
+Noel Echavez It depends on what your rule is doing. You could move the rule up or down and see if the rule still works.
@noelechavez73647 жыл бұрын
i will try, thank you.
@arkan7rb7 жыл бұрын
mainly after the hotspot rules because they stop all from moving after hotspot but this rules is to filter them after getting access to gateway and the network
@thegoodsamaritan43334 жыл бұрын
Good Sir, thank you for this free video. Guys, get this MAN a SUB!!
@hartantosetiawan4835 Жыл бұрын
Hey TKSJa, i didnt find block all wan connection that did not dstnated ? is it all right
@arksurvivalevolved91904 жыл бұрын
Thank you, very useful indeed. I have MikroTik CRS309-1G-8S+. I did copy firewall rules as you did and all seems ok, but when I reboot the switch, the rules are gone, empty again, can you comment why is this? Thank you
@TKSJa4 жыл бұрын
Check your if there any free space on the router
@6i6682 жыл бұрын
Can someone please explain how well this rule will help in TJ's Fire Wall, My comments are not there to undermine his Fire Wall, I am using it. I just want to know how well and what the scope of this rule is. Thanks
@samiam90594 жыл бұрын
Thank you for the education. Work's excellent!
@Pesonkmamen6 жыл бұрын
One of the best channel, thanks
@TKSJa6 жыл бұрын
You are welcome
@dwaynearthur14766 жыл бұрын
Clear concise explanations for all of your videos . Excellent !!!
@UPPERKEES4 жыл бұрын
What's the deal with the bridge filter? I would understand if it only would handle stuff like MAC filtering. But you can also do layer 3 stuff there (IP/port). Or, you can even enable an option to use the IP filter for the bridge. Can someone explain when and why you should use the bridge filter? And why there is an option to use the IP filter? And perhaps, is there a performance cost involved in these combinations of enabling the IP firewall for a bridge filter? The documentation only explains the options, but doesn't go into detail of applying these features the right way.
@shanescudero92376 жыл бұрын
thank you it helps me alot continue on making this kind of tutorials sir :)
@sheprev4 жыл бұрын
thats so educative indeed. Thank you so much man
@janecua90535 жыл бұрын
What is the reason why the PORT 17 enable or allowed?
@TheTeflon4905 жыл бұрын
The bogons rule order change @8:40 changes absolutely nothing, since it is in another chain (forward vs. input.) You should emphasize the critical importance of an order within a chain in the tutorial, otherwise people can be confused. First thing should be to group the list based on a chain, the way it is in this video is quite messy and hard to understand the flow as such.
@TKSJa5 жыл бұрын
Thanks for your feedback.
@stephenkojovan86343 жыл бұрын
Pls sir can you.. kindly help us with internal firewall...on interface basis (that is blocking one network from reaching other.......thanks..l love ur videos...
@sanches2 Жыл бұрын
Thank you, mate!😊
@jefftee4485 жыл бұрын
What is the reasoning behind allowing udp 69? I get if you have a specific tftp service, but that doesnt seem to apply in a generalized ruleset like this.
@TKSJa5 жыл бұрын
Not really necessary, you can remove it if you don't need it
@gerryfinnegan39426 жыл бұрын
Hello, Thank you, for all your well delivered videos. Would you consider doing a video on DMZ setup (SXT-LTE), where the goal is avoid double NAT (Bridging is not an option). The application - Internet > SXT LTE Kit > Wireless Router (Tomato firmware) with Vlan (ADSL connection + SXT LTE). If not maybe refer us to a clear walkthrough guide for this scenario. Thanks in hope ...
@pawemadej8589 Жыл бұрын
I have RouterOS on virtual machine for learning and I've applied those rules and I see 1/3 of packets hitting last drop rule ... router is routing nothing at all now, why it's happening like this?
@epicclips66035 жыл бұрын
Hello, i am very confused. Rule 4 indicates all traffic from internet is dropped. But how..? secondly Rule 5. the destination list is list of all private addresses. what is firewall doing in this rule? is it preventing all traffic to these private addresses over internet from lan? because he says these addresses shouldnt go to internet than should the bogon list be source address list.?
@eheroi5 жыл бұрын
thank you for your time to do these videos. i have learned a lot. thanks you again. keep going :)
@6i6682 жыл бұрын
Filtering full bogon list requires about 5000 rules for IPv4 and about 70,000 rules for IPv6. Double those numbers numbers if you want to filter in both directions.
@Martin-ot7xj5 жыл бұрын
Hi there, please make a tutorial video about which ports by default we must to block on microtik firewall for more security?? Thnx
@Ser_Eyas4 жыл бұрын
thank you for sharing your knowledge sir.. it help a lot.
@TKSJa4 жыл бұрын
You are most welcome
@TriTranTrong4 жыл бұрын
I just wanted to thank you for all of your videos. I use this line with Mikrotik but VPN sitetosite connect but isn't ping to Office 2 not working. I have tried to disable this rule then everything is fine. I use the network subnet mark 192.168.10.0/23 and office 2 is 192.168.30.0/24. Please help me
@gilbertkipbett3487 Жыл бұрын
hello, the link to download the script is not available. Please help. Thank you.
@Stefan-nn9zo7 жыл бұрын
plz plz keep going make more mikrotik videos plz ....nice videos!!!
@TKSJa7 жыл бұрын
Thank you, more on the way.
@usmanjutt79087 жыл бұрын
how to block all websites and allow specfic like gmail yahoo hotmail and etc
@shahiinalam4 жыл бұрын
how can I get firewall scripts ? also do i need ip address or anything edit before runnig sripts ? plz advise, much appriciated in advance
@alanasiimwe6 жыл бұрын
Thanks for sharing very informative and educative!
@tinashemutero8784 жыл бұрын
Are you still answering questions ? please i really need your help
@nabinmallik12906 жыл бұрын
is it apply for crs 210 mikrotik router or not
@haseebj14495 жыл бұрын
Sir this video suit for if i share Internet through Microtik to clients So Internet Service Provider does not know the net is forword to clients
@mauechristiankimcalitina2337 Жыл бұрын
hi do you have any script of this?
@niazwali3816 жыл бұрын
Hello Sir, I am going from a newbie to an advance user by watching you channel so first thanks for you effort, secondly I have a question that how to use this script if I have multiple WAN Connections Load balanced by PCC?
@TKSJa6 жыл бұрын
It should work ok because not out interface was defined in the rules.
@tessabacon92917 жыл бұрын
Can you please make a video on how to only allow access to specific sites and block everything else.
@Martin-ot7xj5 жыл бұрын
Hi there edgerouter firewall is better or microtik router??
@Wahinies5 жыл бұрын
Mikrotik by far. I have a Hex RB750Gr3 at one office with longer uptime than three dead ER3L combined lifetimes at another office. Ubiquiti approved the first RMA but not the second. I only recommend UAPs from them. Routers and switches are firmly Mikrotiks territory. The RB4011, a $200 router, is capable of 10Gb between subinterfaces. Nothing from Ubiquiti can do that and to get something from Cisco or PAN would cost several thousand.
@Martin-ot7xj5 жыл бұрын
Thankyou for quick answer. How can i block all incoming traffic from outside or internet to my network for more security?? How can i make a rule in microtik firewall to block all incoming traffic to my network for more security against of attacks or trojan or malware ?? Please help me. Thnx
@Martin-ot7xj5 жыл бұрын
Thankyou for quick response. I have a quetion about firewall : between microtik and edgerouter 4 firewall, which one in term of firewall are more power than the other?? Thnx
@Xyamta3 жыл бұрын
Thank you!
@ehldora32626 жыл бұрын
Dear TKSJa, thanks a lot for great Tutorial. Can you explain more about the script: add address=10.0.0.0/8 comment="Private[RFC 1918] - CLASS A # Check if you nee\ d this subnet before enable it" list=Bogons What it is used for ? or can I just ignore this line?
@TKSJa6 жыл бұрын
It prevents certain ip addresses from going to your WAN interface.
@emmanuelkitengo99067 жыл бұрын
thank you sir your tutorial are spot on
@TKSJa7 жыл бұрын
You are welcome
@us51095 жыл бұрын
filter rule for hostpot server?
@michaelsenkale9595 Жыл бұрын
you didnt provide the scripts in your comment section for this video
@meazz17 жыл бұрын
Hey TKSJa, great tutorial. One question, does it matter what Lan subnet it use? For example, if I use Lan 192.168.3.1 or 10.0.8.1 and the default script will still or? thanks
@TKSJa7 жыл бұрын
No it doesn't.
@mehdiazzad5657 жыл бұрын
I need to add a rule so if someone ping my gateway's ip address from outside my network should reject it. Currently its sends reply.
@johntaylor85096 жыл бұрын
Enable NAT, action=masquerade
@2001yareka5 жыл бұрын
hi sir this video are same hotspot filter rule thank you for reply..
@adob19924 жыл бұрын
how to disable all firewall from mikrotik router manually
@boyansokolov68027 жыл бұрын
Man, I see you are learning every day and you are getting better and better. But in most of your videos where you speak about firewalls, I see that you are not completele aware about firewall rules. You need to learn a little bit more to clear the picture in your mind. In the firewall menu, in FILTER tab, NAT tab, MANGLE tab and so on, it is organised into chains where you can see them better from the drop down menu. So when you move some of your rules (lines) up or down, they take effect only in their respective chains. For example in your video in minute 8:50 you are moving a "forward" rule above "input" rule which will have the same effect as if you do not move it. If you want to take an effect you must think of moving it above the last forward rule (same chain). In other words, if you have two drop rules in different chains, it doesn't matter which one of them is above the other. I hope i cleared it for you.
@TKSJa7 жыл бұрын
Thanks for feedback, you have imparted valuable knowledge.
@boyansokolov68027 жыл бұрын
TKSJa keep going. You are doing well
@NiskarShrestha5 жыл бұрын
can we block all the vpn from mikrotik??
@TKSJa5 жыл бұрын
yes, you need to know the ports.
@johnlohan99007 жыл бұрын
Please where can we have the script in this tutorial ?
@Palapi_H7 жыл бұрын
tksja.com/essential-firewall-rules/
@tonyferguson79565 жыл бұрын
Hello TKSJa I have a router between two networks, I would like to allow all traffic between these two networks, how do I configure my router?
@fajkoson5 жыл бұрын
lets say you have WAN port on eth1 and eth2-3 subnet1, eth4-5 subnet2, then for each subnet you can use vlan... check cisco tutorials
@TrongHuanNguyen6 жыл бұрын
Thank you so much.
@jayadorable36013 жыл бұрын
Thank you
@TKSJa3 жыл бұрын
You are welcome
@marine17185 жыл бұрын
thanks for the help
@TKSJa5 жыл бұрын
You are welcome
@khaingmye73537 жыл бұрын
thank you so much
@TKSJa7 жыл бұрын
You are welcome
@khaingmye73537 жыл бұрын
Could you please upload a video of DNS cache and web proxy set up for Mikrotik please? Much appreciated :)
@Martin-ot7xj5 жыл бұрын
Hi, please make a tutorial video about how we can block all incoming traffic from outside or internet to the network on microtik firewall, i mean block bad traffic or attack for any request from wan port to lan for more security. Thnx
@mostafaali-wr7nj5 жыл бұрын
Hi TKJa thank you for your efforts to explain mik Please I have questions for you If you have Facebook account this make interface with you very easy
@gpligor3 жыл бұрын
aren't you missing the background music on this one ? :)
@matej_stepan6 жыл бұрын
doesn't work on 6.42.6
@alex.username6 жыл бұрын
what exactly?
@fajkoson5 жыл бұрын
@@alex.username since there is not master port you have to set it differently.. you set ports 2-5 under br1 +wan instead using master port.
@somalicinema6303 жыл бұрын
Please make tutorial with apk android mikrotik
@rizhanet29116 жыл бұрын
i like script, (copy and paste), you should teach us how to write script not only in this vidoe
@fajkoson5 жыл бұрын
well, he doesnt have to do anything at all.. if you want to know something.. learn it yourself..
@wyc24624 жыл бұрын
2020 HERE!!
@Pavel1TU3 жыл бұрын
Pokud autor povolí ve FW něco jako toto add action=accept chain=input port=69 protocol=udp add action=accept chain=forward port=69 protocol=udp neměl by nikomu radit ;)
@duncansagini6852 жыл бұрын
the config script is nolonger there😑
@mrthapa075 жыл бұрын
can i get your email ???I need some help .
@jaykay13045 жыл бұрын
nice videos. is there a way of blocking porn sites with a custom message
@madas27054 жыл бұрын
Please do not share personal experiance as general case studies. Fist it is unprofessional and second, it is less concludent!
@mostafaali-wr7nj5 жыл бұрын
Please please
@johnmeyers61153 жыл бұрын
I can stand listening to you... too many pauses... too many times you need to think what to say...
@TheMockTv4 жыл бұрын
thank you, the videos it helps me alot to configure my mikrotik router
@alestherabong37986 жыл бұрын
Can you please make a video on how to only allow access to specific sites and block everything else.