Tu je vypis
Kód: Vybrat vše
/ip firewall filter
add action=drop chain=input comment=zahodit_neplatne_spojenia connection-state=invalid
add action=drop chain=forward connection-state=invalid
add action=accept chain=input comment=povolit_icmp_spravy protocol=icmp
add action=accept chain=input comment=povolit_nadviazane_spojenia connection-state=established,related
add action=accept chain=forward connection-state=established,related
add action=drop chain=input comment=zahodit_dns_wan dst-port=53 in-interface=pppoe-out1 protocol=udp
add action=drop chain=input dst-port=53 in-interface=pppoe-out1 protocol=tcp
add action=accept chain=forward comment=openvpn_tcp dst-port=1194 protocol=tcp
...
add action=accept chain=forward comment=moj_pc out-interface=pppoe-out1 src-mac-address=AA:1D:7D:A9:A1:CC
add action=accept chain=forward comment=server_linux out-interface=pppoe-out1 src-mac-address=BB:50:99:36:9A:DD
...
add action=drop chain=forward comment=pravidlo_na_blokovanie_ip_adresy src-address=213.81.214.130
add action=accept chain=input comment=povolit_snmp dst-port=161 in-interface=!pppoe-out1 protocol=udp
add action=drop chain=forward comment=zahodit_vsetko_ostatne_z_wan_na_dstnat connection-nat-state=!dstnat connection-state=new in-interface=pppoe-out1
add action=drop chain=input comment=zahodit_vsetko_ostatne in-interface=pppoe-out1
To pravidlo fungovalo tak, ze ak dana MAC bola vo firewalle, tak z tej MAC fungoval internet (napr. z PC kde je tato MAC AA:1D:7D:A9:A1:CC, tak fungoval internet).
Ak tato MAC vo firewalle nebola, tak internet na tej MAC nefungoval.
Ak by som chcel na danej MAC internet docasne vypnut, tak som to pravidlo disabloval (LAN sluzby fungovali normalne, ale Inet nefungoval).
Teraz som zistil, ze ak pravidlo disablujem, tak Inet funguje dalej.
Ano, staci ked na pravidlo namiesto accept pouzijem DROP, ale to nic neriesi, lebo to by som musel kazdeho kto sa pripoji do LAN hned dropovat.
Neviem dovod preco to prestalo fungovat. Nejake velke zmeny som vo fierwalle nerobil, akurat som pridal na koniec firewallu drop vsetkeho ostatneho