RB450 Mikrotik 6.39.3
Linka VDSL (verejna IP adresa)
Od vcera vecera mam CPU load na 100%
V ip firewall connections mam cez 2500 spojeni (Max entries 23080)
ip firewall filter export
Kód: Vybrat vše
add action=drop chain=input comment=Drop_INVALID_connection connection-state=invalid
add action=drop chain=forward connection-state=invalid
add action=accept chain=input comment=Allow_ping icmp-options=8:0-255 protocol=icmp
add action=accept chain=forward comment=Allow_ESTABILISHED_and_RELATED_connection connection-state=established
add action=accept chain=forward connection-state=related
add action=accept chain=input connection-state=related
add action=accept chain=input comment=Allow_DNS_requests dst-port=53 in-interface=!pppoe-out1 protocol=udp
add action=accept chain=input dst-port=53 in-interface=!pppoe-out1 protocol=tcp
add action=accept chain=forward comment=moj_pc out-interface=pppoe-out1 src-mac-address=AA:1D:7D:A9:A1:CC
add action=accept chain=forward comment=server out-interface=pppoe-out1 src-mac-address=BB:50:99:36:9A:DD
add action=accept chain=forward comment=raspberry_pi_3 out-interface=pppoe-out1 src-mac-address=B8:27:EB:65:70:EE
add action=accept chain=forward comment=testing_virtual_01 out-interface=pppoe-out1 src-mac-address=AB:61:D2:2C:36:2
add action=drop chain=forward comment=pravidlo_na_blokovanie_ip_adresy src-address=217.81.214.135
add action=accept chain=forward comment=OpenVPN_tcp dst-port=1194 protocol=tcp
add action=accept chain=input comment=access_ftp_mk_from_mypc dst-port=21 protocol=tcp src-address=192.168.1.2
add action=accept chain=input comment=Allow_SNMP dst-port=161 in-interface=!pppoe-out1 protocol=udp
add action=drop chain=forward comment=DRP_everithing_else out-interface=pppoe-out1
Ak pozrem na http://openresolver.com/ tak Open recursive resolver detected on 178.x.x.x
Neviem kde moze byt problem.
Tieto 2 pravidla hovoria
Kód: Vybrat vše
add action=accept chain=input comment=Allow_DNS_requests dst-port=53 in-interface=!pppoe-out1 protocol=udp
add action=accept chain=input dst-port=53 in-interface=!pppoe-out1 protocol=tcp
Ak v ip dns zrusim allow remote request, tak spojenia v ip firewall connections postupne klesaju a CPU load sa upravi na normalnych 5-10%, ale to nie je riesenie, lebo nefunguje internet