MikroTik Tutorial 29 - Essential Firewall Filter Rules

  Рет қаралды 188,278

TKSJa

TKSJa

Күн бұрын

Пікірлер: 123
@MarkM_
@MarkM_ 7 жыл бұрын
Hey TKSJa, I just wanted to thank you for all of your videos. I have been using MikroTik devices for a few years and I cannot believe how many people have never heard of them. There are so few tutorial videos in English. Your channel is very unique in that way and you are servicing the world with your work. I have been recommending the routers and your videos to everybody I know that has the technical knowledge to follow along. God bless.
@nikko444
@nikko444 3 жыл бұрын
Same here! I can't believe somebody does such a great job supporting networking pros for free. I mean my paid CCNA course couldn't boast such a solid curriculum convey. Hats off for TKSJa!
@AikimaniacX
@AikimaniacX 4 жыл бұрын
Bought my first Mikrotik. Thanks a lot for videos and the website. Its great and i think it is actually only website where is all explained so average IT guy understands details without being network engineer. Thanks a lot.
@josephstalin7995
@josephstalin7995 5 жыл бұрын
I'm gonna learn like Mike Boyd with these videos!
@nikko444
@nikko444 3 жыл бұрын
Hey, TKSJa! Man, thanks for your fantastic job on Mikrotik Tutorials. I can't tell you how many times your content saved my ass. Much respect and support from Canada. May luck and prosperity always be by your side! If you got a Patreon or whatnot, I'll be your patron hands-down!
@AP-qc9hi
@AP-qc9hi 6 жыл бұрын
Good guide. One question, what is the reasoning behind allowing tftp udp port 69 in the input and fwd chain?
@jefftee448
@jefftee448 5 жыл бұрын
I would like to know as well
@ronviejo4994
@ronviejo4994 5 жыл бұрын
Thank you sooooo much for these vids in English!! Your web site is excellent as well. I highly recommend his web page to anyone interested in learning more. I have an MTCNA but I learn more here than in the other classes I have taken. Great job!!
@sherwinceralbo1028
@sherwinceralbo1028 2 жыл бұрын
How can I get certified by you, you are a better mentor than a paid ccna instructor, in my own opinion. BTW kudos. We all love your content.
@harryp4618
@harryp4618 6 жыл бұрын
Hi TKSJa, I just got my hEX S couple of weeks ago and I'm going see some of your video tutorials. Thank you so much sir! You are very kind of sharing your work. :)
@paulhemmerling579
@paulhemmerling579 6 жыл бұрын
Thank you for providing this tutorial (and all the others as well). This video is essential for Mikrotik noobs like myself.
@TKSJa
@TKSJa 6 жыл бұрын
You are welcome
@JohnSmith-dc6lc
@JohnSmith-dc6lc Жыл бұрын
? Should that script be modified to suite different ip pools?
@shtumpa1
@shtumpa1 4 жыл бұрын
I wish you still did videos .. it’s been so long !!!
@waqasahmed1915
@waqasahmed1915 3 жыл бұрын
I already have some rules created by hotspot automatically. Should these rules (discussed in this video) go up the hotspot rules or below the hotspot rules?
@fdlp1445
@fdlp1445 6 жыл бұрын
Thank you TKSJA for sharing your knowledge about configuring Mikrotik routers it helps me a lot , i hope you continue making videos like this ^_^ more power to you bro
@TKSJa
@TKSJa 6 жыл бұрын
You are welcome.
@tinashemutero878
@tinashemutero878 4 жыл бұрын
hi great tutorials, im getting better by using your videos
@MrThe184
@MrThe184 2 жыл бұрын
Thank you...it's a really great video I'm a beginner ...but I understand can you make one video on hotspot user and firewall policy's... That' will be great help for me .....
@signalvision
@signalvision Жыл бұрын
Hi, How the configuration if i have 2 input WAN eth 1 and 2, i need to add both . Thanks
@JohnSmith-dc6lc
@JohnSmith-dc6lc Жыл бұрын
Excellent work as usual! Thank you Your site is down…
@noelechavez7364
@noelechavez7364 7 жыл бұрын
thank you for very informative tutorials. can i ask if i have a hotspot rule where i put your firewall rule. before hotspot rule or after? thank you.
@TKSJa
@TKSJa 7 жыл бұрын
+Noel Echavez It depends on what your rule is doing. You could move the rule up or down and see if the rule still works.
@noelechavez7364
@noelechavez7364 7 жыл бұрын
i will try, thank you.
@arkan7rb
@arkan7rb 7 жыл бұрын
mainly after the hotspot rules because they stop all from moving after hotspot but this rules is to filter them after getting access to gateway and the network
@thegoodsamaritan4333
@thegoodsamaritan4333 4 жыл бұрын
Good Sir, thank you for this free video. Guys, get this MAN a SUB!!
@hartantosetiawan4835
@hartantosetiawan4835 Жыл бұрын
Hey TKSJa, i didnt find block all wan connection that did not dstnated ? is it all right
@arksurvivalevolved9190
@arksurvivalevolved9190 4 жыл бұрын
Thank you, very useful indeed. I have MikroTik CRS309-1G-8S+. I did copy firewall rules as you did and all seems ok, but when I reboot the switch, the rules are gone, empty again, can you comment why is this? Thank you
@TKSJa
@TKSJa 4 жыл бұрын
Check your if there any free space on the router
@6i668
@6i668 2 жыл бұрын
Can someone please explain how well this rule will help in TJ's Fire Wall, My comments are not there to undermine his Fire Wall, I am using it. I just want to know how well and what the scope of this rule is. Thanks
@samiam9059
@samiam9059 4 жыл бұрын
Thank you for the education. Work's excellent!
@Pesonkmamen
@Pesonkmamen 6 жыл бұрын
One of the best channel, thanks
@TKSJa
@TKSJa 6 жыл бұрын
You are welcome
@dwaynearthur1476
@dwaynearthur1476 6 жыл бұрын
Clear concise explanations for all of your videos . Excellent !!!
@UPPERKEES
@UPPERKEES 4 жыл бұрын
What's the deal with the bridge filter? I would understand if it only would handle stuff like MAC filtering. But you can also do layer 3 stuff there (IP/port). Or, you can even enable an option to use the IP filter for the bridge. Can someone explain when and why you should use the bridge filter? And why there is an option to use the IP filter? And perhaps, is there a performance cost involved in these combinations of enabling the IP firewall for a bridge filter? The documentation only explains the options, but doesn't go into detail of applying these features the right way.
@shanescudero9237
@shanescudero9237 6 жыл бұрын
thank you it helps me alot continue on making this kind of tutorials sir :)
@sheprev
@sheprev 4 жыл бұрын
thats so educative indeed. Thank you so much man
@janecua9053
@janecua9053 5 жыл бұрын
What is the reason why the PORT 17 enable or allowed?
@TheTeflon490
@TheTeflon490 5 жыл бұрын
The bogons rule order change @8:40 changes absolutely nothing, since it is in another chain (forward vs. input.) You should emphasize the critical importance of an order within a chain in the tutorial, otherwise people can be confused. First thing should be to group the list based on a chain, the way it is in this video is quite messy and hard to understand the flow as such.
@TKSJa
@TKSJa 5 жыл бұрын
Thanks for your feedback.
@stephenkojovan8634
@stephenkojovan8634 3 жыл бұрын
Pls sir can you.. kindly help us with internal firewall...on interface basis (that is blocking one network from reaching other.......thanks..l love ur videos...
@sanches2
@sanches2 Жыл бұрын
Thank you, mate!😊
@jefftee448
@jefftee448 5 жыл бұрын
What is the reasoning behind allowing udp 69? I get if you have a specific tftp service, but that doesnt seem to apply in a generalized ruleset like this.
@TKSJa
@TKSJa 5 жыл бұрын
Not really necessary, you can remove it if you don't need it
@gerryfinnegan3942
@gerryfinnegan3942 6 жыл бұрын
Hello, Thank you, for all your well delivered videos. Would you consider doing a video on DMZ setup (SXT-LTE), where the goal is avoid double NAT (Bridging is not an option). The application - Internet > SXT LTE Kit > Wireless Router (Tomato firmware) with Vlan (ADSL connection + SXT LTE). If not maybe refer us to a clear walkthrough guide for this scenario. Thanks in hope ...
@pawemadej8589
@pawemadej8589 Жыл бұрын
I have RouterOS on virtual machine for learning and I've applied those rules and I see 1/3 of packets hitting last drop rule ... router is routing nothing at all now, why it's happening like this?
@epicclips6603
@epicclips6603 5 жыл бұрын
Hello, i am very confused. Rule 4 indicates all traffic from internet is dropped. But how..? secondly Rule 5. the destination list is list of all private addresses. what is firewall doing in this rule? is it preventing all traffic to these private addresses over internet from lan? because he says these addresses shouldnt go to internet than should the bogon list be source address list.?
@eheroi
@eheroi 5 жыл бұрын
thank you for your time to do these videos. i have learned a lot. thanks you again. keep going :)
@6i668
@6i668 2 жыл бұрын
Filtering full bogon list requires about 5000 rules for IPv4 and about 70,000 rules for IPv6. Double those numbers numbers if you want to filter in both directions.
@Martin-ot7xj
@Martin-ot7xj 5 жыл бұрын
Hi there, please make a tutorial video about which ports by default we must to block on microtik firewall for more security?? Thnx
@Ser_Eyas
@Ser_Eyas 4 жыл бұрын
thank you for sharing your knowledge sir.. it help a lot.
@TKSJa
@TKSJa 4 жыл бұрын
You are most welcome
@TriTranTrong
@TriTranTrong 4 жыл бұрын
I just wanted to thank you for all of your videos. I use this line with Mikrotik but VPN sitetosite connect but isn't ping to Office 2 not working. I have tried to disable this rule then everything is fine. I use the network subnet mark 192.168.10.0/23 and office 2 is 192.168.30.0/24. Please help me
@gilbertkipbett3487
@gilbertkipbett3487 Жыл бұрын
hello, the link to download the script is not available. Please help. Thank you.
@Stefan-nn9zo
@Stefan-nn9zo 7 жыл бұрын
plz plz keep going make more mikrotik videos plz ....nice videos!!!
@TKSJa
@TKSJa 7 жыл бұрын
Thank you, more on the way.
@usmanjutt7908
@usmanjutt7908 7 жыл бұрын
how to block all websites and allow specfic like gmail yahoo hotmail and etc
@shahiinalam
@shahiinalam 4 жыл бұрын
how can I get firewall scripts ? also do i need ip address or anything edit before runnig sripts ? plz advise, much appriciated in advance
@alanasiimwe
@alanasiimwe 6 жыл бұрын
Thanks for sharing very informative and educative!
@tinashemutero878
@tinashemutero878 4 жыл бұрын
Are you still answering questions ? please i really need your help
@nabinmallik1290
@nabinmallik1290 6 жыл бұрын
is it apply for crs 210 mikrotik router or not
@haseebj1449
@haseebj1449 5 жыл бұрын
Sir this video suit for if i share Internet through Microtik to clients So Internet Service Provider does not know the net is forword to clients
@mauechristiankimcalitina2337
@mauechristiankimcalitina2337 Жыл бұрын
hi do you have any script of this?
@niazwali381
@niazwali381 6 жыл бұрын
Hello Sir, I am going from a newbie to an advance user by watching you channel so first thanks for you effort, secondly I have a question that how to use this script if I have multiple WAN Connections Load balanced by PCC?
@TKSJa
@TKSJa 6 жыл бұрын
It should work ok because not out interface was defined in the rules.
@tessabacon9291
@tessabacon9291 7 жыл бұрын
Can you please make a video on how to only allow access to specific sites and block everything else.
@Martin-ot7xj
@Martin-ot7xj 5 жыл бұрын
Hi there edgerouter firewall is better or microtik router??
@Wahinies
@Wahinies 5 жыл бұрын
Mikrotik by far. I have a Hex RB750Gr3 at one office with longer uptime than three dead ER3L combined lifetimes at another office. Ubiquiti approved the first RMA but not the second. I only recommend UAPs from them. Routers and switches are firmly Mikrotiks territory. The RB4011, a $200 router, is capable of 10Gb between subinterfaces. Nothing from Ubiquiti can do that and to get something from Cisco or PAN would cost several thousand.
@Martin-ot7xj
@Martin-ot7xj 5 жыл бұрын
Thankyou for quick answer. How can i block all incoming traffic from outside or internet to my network for more security?? How can i make a rule in microtik firewall to block all incoming traffic to my network for more security against of attacks or trojan or malware ?? Please help me. Thnx
@Martin-ot7xj
@Martin-ot7xj 5 жыл бұрын
Thankyou for quick response. I have a quetion about firewall : between microtik and edgerouter 4 firewall, which one in term of firewall are more power than the other?? Thnx
@Xyamta
@Xyamta 3 жыл бұрын
Thank you!
@ehldora3262
@ehldora3262 6 жыл бұрын
Dear TKSJa, thanks a lot for great Tutorial. Can you explain more about the script: add address=10.0.0.0/8 comment="Private[RFC 1918] - CLASS A # Check if you nee\ d this subnet before enable it" list=Bogons What it is used for ? or can I just ignore this line?
@TKSJa
@TKSJa 6 жыл бұрын
It prevents certain ip addresses from going to your WAN interface.
@emmanuelkitengo9906
@emmanuelkitengo9906 7 жыл бұрын
thank you sir your tutorial are spot on
@TKSJa
@TKSJa 7 жыл бұрын
You are welcome
@us5109
@us5109 5 жыл бұрын
filter rule for hostpot server?
@michaelsenkale9595
@michaelsenkale9595 Жыл бұрын
you didnt provide the scripts in your comment section for this video
@meazz1
@meazz1 7 жыл бұрын
Hey TKSJa, great tutorial. One question, does it matter what Lan subnet it use? For example, if I use Lan 192.168.3.1 or 10.0.8.1 and the default script will still or? thanks
@TKSJa
@TKSJa 7 жыл бұрын
No it doesn't.
@mehdiazzad565
@mehdiazzad565 7 жыл бұрын
I need to add a rule so if someone ping my gateway's ip address from outside my network should reject it. Currently its sends reply.
@johntaylor8509
@johntaylor8509 6 жыл бұрын
Enable NAT, action=masquerade
@2001yareka
@2001yareka 5 жыл бұрын
hi sir this video are same hotspot filter rule thank you for reply..
@adob1992
@adob1992 4 жыл бұрын
how to disable all firewall from mikrotik router manually
@boyansokolov6802
@boyansokolov6802 7 жыл бұрын
Man, I see you are learning every day and you are getting better and better. But in most of your videos where you speak about firewalls, I see that you are not completele aware about firewall rules. You need to learn a little bit more to clear the picture in your mind. In the firewall menu, in FILTER tab, NAT tab, MANGLE tab and so on, it is organised into chains where you can see them better from the drop down menu. So when you move some of your rules (lines) up or down, they take effect only in their respective chains. For example in your video in minute 8:50 you are moving a "forward" rule above "input" rule which will have the same effect as if you do not move it. If you want to take an effect you must think of moving it above the last forward rule (same chain). In other words, if you have two drop rules in different chains, it doesn't matter which one of them is above the other. I hope i cleared it for you.
@TKSJa
@TKSJa 7 жыл бұрын
Thanks for feedback, you have imparted valuable knowledge.
@boyansokolov6802
@boyansokolov6802 7 жыл бұрын
TKSJa keep going. You are doing well
@NiskarShrestha
@NiskarShrestha 5 жыл бұрын
can we block all the vpn from mikrotik??
@TKSJa
@TKSJa 5 жыл бұрын
yes, you need to know the ports.
@johnlohan9900
@johnlohan9900 7 жыл бұрын
Please where can we have the script in this tutorial ?
@Palapi_H
@Palapi_H 7 жыл бұрын
tksja.com/essential-firewall-rules/
@tonyferguson7956
@tonyferguson7956 5 жыл бұрын
Hello TKSJa I have a router between two networks, I would like to allow all traffic between these two networks, how do I configure my router?
@fajkoson
@fajkoson 5 жыл бұрын
lets say you have WAN port on eth1 and eth2-3 subnet1, eth4-5 subnet2, then for each subnet you can use vlan... check cisco tutorials
@TrongHuanNguyen
@TrongHuanNguyen 6 жыл бұрын
Thank you so much.
@jayadorable3601
@jayadorable3601 3 жыл бұрын
Thank you
@TKSJa
@TKSJa 3 жыл бұрын
You are welcome
@marine1718
@marine1718 5 жыл бұрын
thanks for the help
@TKSJa
@TKSJa 5 жыл бұрын
You are welcome
@khaingmye7353
@khaingmye7353 7 жыл бұрын
thank you so much
@TKSJa
@TKSJa 7 жыл бұрын
You are welcome
@khaingmye7353
@khaingmye7353 7 жыл бұрын
Could you please upload a video of DNS cache and web proxy set up for Mikrotik please? Much appreciated :)
@Martin-ot7xj
@Martin-ot7xj 5 жыл бұрын
Hi, please make a tutorial video about how we can block all incoming traffic from outside or internet to the network on microtik firewall, i mean block bad traffic or attack for any request from wan port to lan for more security. Thnx
@mostafaali-wr7nj
@mostafaali-wr7nj 5 жыл бұрын
Hi TKJa thank you for your efforts to explain mik Please I have questions for you If you have Facebook account this make interface with you very easy
@gpligor
@gpligor 3 жыл бұрын
aren't you missing the background music on this one ? :)
@matej_stepan
@matej_stepan 6 жыл бұрын
doesn't work on 6.42.6
@alex.username
@alex.username 6 жыл бұрын
what exactly?
@fajkoson
@fajkoson 5 жыл бұрын
@@alex.username since there is not master port you have to set it differently.. you set ports 2-5 under br1 +wan instead using master port.
@somalicinema630
@somalicinema630 3 жыл бұрын
Please make tutorial with apk android mikrotik
@rizhanet2911
@rizhanet2911 6 жыл бұрын
i like script, (copy and paste), you should teach us how to write script not only in this vidoe
@fajkoson
@fajkoson 5 жыл бұрын
well, he doesnt have to do anything at all.. if you want to know something.. learn it yourself..
@wyc2462
@wyc2462 4 жыл бұрын
2020 HERE!!
@Pavel1TU
@Pavel1TU 3 жыл бұрын
Pokud autor povolí ve FW něco jako toto add action=accept chain=input port=69 protocol=udp add action=accept chain=forward port=69 protocol=udp neměl by nikomu radit ;)
@duncansagini685
@duncansagini685 2 жыл бұрын
the config script is nolonger there😑
@mrthapa07
@mrthapa07 5 жыл бұрын
can i get your email ???I need some help .
@jaykay1304
@jaykay1304 5 жыл бұрын
nice videos. is there a way of blocking porn sites with a custom message
@madas2705
@madas2705 4 жыл бұрын
Please do not share personal experiance as general case studies. Fist it is unprofessional and second, it is less concludent!
@mostafaali-wr7nj
@mostafaali-wr7nj 5 жыл бұрын
Please please
@johnmeyers6115
@johnmeyers6115 3 жыл бұрын
I can stand listening to you... too many pauses... too many times you need to think what to say...
@TheMockTv
@TheMockTv 4 жыл бұрын
thank you, the videos it helps me alot to configure my mikrotik router
@alestherabong3798
@alestherabong3798 6 жыл бұрын
Can you please make a video on how to only allow access to specific sites and block everything else.
@mongolianwolf1113
@mongolianwolf1113 4 жыл бұрын
Thank you very much.
@TKSJa
@TKSJa 4 жыл бұрын
You are welcome!
MikroTips: How to firewall
21:56
MikroTik
Рет қаралды 156 М.
It works #beatbox #tiktok
00:34
BeatboxJCOP
Рет қаралды 41 МЛН
人是不能做到吗?#火影忍者 #家人  #佐助
00:20
火影忍者一家
Рет қаралды 20 МЛН
Security Best Practices - Firewall Filtering with MikroTik Marc
32:31
Admiral Platform (RemoteWinBox)
Рет қаралды 7 М.
MikroTik Firewall :  Essential Rules & Pro Tips!
10:18
The Network Guy
Рет қаралды 264
MikroTik Tutorial 39 - Guest Wifi using VLAN
7:43
TKSJa
Рет қаралды 143 М.
MikroTik Tutorial 96 - Manage your Network using RoMON
6:21
MikroTik Tutorial 1 - Getting Started Basic Configuration
10:35