MikroTips: How to firewall

Поділитися
Вставка
  • Опубліковано 25 гру 2024

КОМЕНТАРІ •

  • @AlexApol
    @AlexApol Рік тому +6

    The documentation and tutorials for Mikrotik put all of the other manufacturers to shame. Looking at you Ubiquiti!

  • @eferkano
    @eferkano 2 роки тому +16

    the "let say i trust my colleagues, even though i don't" part really made my day

    • @jamesclavel25
      @jamesclavel25 2 роки тому +2

      I'm about to comment the same then I read yours! :) - seems it not just about the network security anymore... hahaha.

  • @TheNetworkBerg
    @TheNetworkBerg 3 роки тому +71

    Great content Normis & MikroTik :)! Please keep these awesome MikroTips coming, I know many people enjoy watching them!

    • @defaultroute
      @defaultroute 2 роки тому

      Don’t listen to Berg. He’s started doing Fortigate stuff. Absolutely terrible person. 😂

  • @sebastianmangelsen8056
    @sebastianmangelsen8056 2 роки тому +19

    I can not agree more, great content and please continue in the same way supporting customers. My journey with Mikrotik has been a pure pleasure so far.

  • @JSBroadcast
    @JSBroadcast 2 роки тому +5

    As many have said, those are really useful videos, so please, keep them coming. I've worked as a MT admin 13 years ago and I forgot a lot of this stuff since then, so this makes the onboarding again really simple. Thank you very much.

  • @xaviertorres2142
    @xaviertorres2142 2 роки тому +2

    It was a good starting for MIKROTIK FIREWALL, thanks by this approaching to the comunity!
    Great job!

  • @JeffPedlow
    @JeffPedlow 2 роки тому +5

    This is a great starter/intro video to the FW and I sincerely hope there are more for the future - perhaps topics like point to point VPN, home AP, throttling Kids devices etc...

  • @nadtz
    @nadtz 2 роки тому +2

    As someone about to pick up my first mikrotik device this was a great beginner how to vid for the much feared firewall config, thanks!

    • @mikrotik
      @mikrotik  2 роки тому +2

      Great to hear! Be sure to watch our other videos too, we have more beginner tips

    • @Nikola__K
      @Nikola__K 6 місяців тому

      @@mikrotikDo you guys have a support department of kinds where you can book a network engineer to help you make your best dream network?
      As a Home user who prefers privacy and safety I would pay for a ready made secure plug and play file that I can just sync to the device and set a password, or finish up with some small modifications.

  • @mantaspudzemis566
    @mantaspudzemis566 2 роки тому +1

    I love mikrotik routers and support material has improved a lot too now. Great job

  • @sestoscemo
    @sestoscemo 2 роки тому +3

    Thank you! Can't wait for next video. Bying a Mikrotik router for home was a great choice. Forced me to an extrmely interesting study process

  • @andrejscernusenko4866
    @andrejscernusenko4866 2 роки тому +4

    Thanks, excellent video for first steps in firewall. Watching 20 minutes of long video was not boring. Thank you Normis!
    It takes a lot of courage to make good videos, but you are doing great! Keep up ;)

  • @kolifx
    @kolifx 2 роки тому +11

    Really good to see tutorials like this, keep going, make more. You have a great product range with great features, however features bring complexity. I feel the biggest hurdle for your home users to be able to use your gear will be the lack of knowledge. Tutorials will be a huge help for people to learn and buy more of you great gear.

    • @cleytonlombra
      @cleytonlombra 2 роки тому

      Kkkkk gmn ox

    • @DanPellegrino486
      @DanPellegrino486 2 роки тому

      This - 100%. Even the Prosumer market needs guidance, especially because we tend to sell and move on if it doesn't work out.

  • @Andrew_Thrift
    @Andrew_Thrift 3 роки тому +8

    These videos are great. Keep it up.

  • @dzejkobone
    @dzejkobone Рік тому +16

    Shouldn't the 6th rule with IP 150.140.130.13 be moved upper? When firewall sees a rule for .13 it will accept it because it belongs to 150.140.130.0/24 network. Then router will stop looking for filter for this IP, because it has been already accepted. So in my opinion the trick is to move this rule up (on position 5 or smaller) to block the .13 address, and then firewall will stop looking for filtering, because it has been already blocked.

    • @makeativity
      @makeativity Рік тому

      Agreed. From the docs: If a packet matches the criteria of the rule, then the specified action is performed on it, and no more rules are processed in that chain (the exception is the passthrough action). If a packet has not matched any rule within the built-in chain, then it is accepted.

  • @ruf3st
    @ruf3st 2 роки тому +53

    There is a mistake @15min, the drop rule will not work since the connection will be accepted by the rule preceding the drop.

    • @mikrotik
      @mikrotik  2 роки тому +16

      good catch, had to move it one position more!

    • @محمدالعجيري-ر5م
      @محمدالعجيري-ر5م 2 роки тому

      Hmmm 🤔

    • @Rcbeacon
      @Rcbeacon 2 роки тому

      Thanks for the video and to ruf3st for pointing out the adjustment. I've been working to understand the firewall and NAT for a while before implementing a MikroTik router to replace a old dd-wrt unit. It's a big step for someone new to this because it seems a mistake could compromise network security and you may not know until too late. I have found information and guides on-line that don't work and seem wrong but as a newbee it's difficult to decide, maybe just not the best way to achieve something. For something this important and with a router as versatile as the MikroTik there is a huge learning curve. It's a big responsibility advising or teaching how to secure a network.

    • @donatasdicmanas5009
      @donatasdicmanas5009 2 роки тому +2

      @@mikrotik add a note on video :)

    • @ergohack
      @ergohack 2 роки тому

      @@donatasdicmanas5009 Pretty sure that UA-cam removed the ability to add annotations a while ago.

  • @bolto90
    @bolto90 11 місяців тому

    Amazing video and very informative, Mikrotik hardware and software are fantastic

  • @justdoit7318
    @justdoit7318 2 роки тому +1

    Really good to see tutorials like this, keep going, and make more

  • @sam1lama
    @sam1lama 2 роки тому

    شكرا لطريقة الشرح
    اول فيديو شاهدتو وعجبتني المعلومات وطريقة شرحك شكرا

  • @rajkoplecko33
    @rajkoplecko33 2 роки тому +1

    ....let's say i trust my colleagues. even though I don't.... nice touch :-D
    nice and useful video... I expect advanced firewalling also.... thank you...

  • @FelixBank
    @FelixBank 3 роки тому +4

    More, MikroTik. More 😊

  • @rusnyasosat
    @rusnyasosat 2 роки тому +1

    Very nice. I would love more firewall tutorials. 👍

  • @stephanszarafinski9001
    @stephanszarafinski9001 3 роки тому +1

    Thanks for making this video, top quality 😀 Will show this to firewall n00bs to make them pro.

  • @yevheniistoliarenko7986
    @yevheniistoliarenko7986 2 роки тому +5

    Hmmm just to clarify
    On 15:27, will rule #6 for blocking X.X.X.13 actually work?
    Preceeding rule #5 is accepting whole subnet traffic...

  • @محمدالعجيري-ر5م
    @محمدالعجيري-ر5م 2 роки тому +2

    Nice, Great to know about the SAFEMODE feature.. to me it means not to reset my router and getting kicked out of it when ever i'm experiencing with the ip adressess things XD
    thank you sir

  • @joker2chaik
    @joker2chaik 2 роки тому

    Thanks for review and I can't wait to see russian version of this video

  • @cabonamigo
    @cabonamigo 2 роки тому

    I wish people in the industry were as sincere as you were, from the beginig (windows 95 begginig) by saying : "No network is completely secure..." . What you said kind of defies the reason to why choose mikrotik instead of any other, but anyway, also a great reason for a "heck, why not !" right ?

  • @kollerpaul
    @kollerpaul 3 роки тому +3

    Well done! Keep it up.
    Is this the new Mikrotik Logo?

  •  2 роки тому

    Great ;
    Normis , the basic building block of Mikrotik. :)

  • @itzizag2280
    @itzizag2280 2 роки тому

    Thanks for video it very help full for me. keep making

  • @rchrstphr-smp1043
    @rchrstphr-smp1043 2 роки тому

    Great video , keep going !!!!

  • @helgaalan1361
    @helgaalan1361 3 місяці тому +1

    I am waiting for NGFW from MikroTik Device and I am still looking for how to configure MikroTik Router like NGFW (IPS, IDS)

  • @Numian
    @Numian 2 роки тому

    Great tutorial!

  • @rajeshbose2802
    @rajeshbose2802 2 роки тому

    please discuss about advance firewall some other day. we are waiting. Thnaks

  • @djz-zmix2763
    @djz-zmix2763 2 роки тому

    thanks, it actually let me through so i could download it.

  • @milicsantiago
    @milicsantiago 2 роки тому

    great content!

  • @k4qdex
    @k4qdex 2 роки тому

    thank you for this Normis

  • @LuLuXDCraft
    @LuLuXDCraft 2 роки тому +2

    Great video thank you ! This MicroTips series is perfect !
    I'm curious about the new MikroTik icon in the macOS dock, new software soon ? 🤔

  • @beansprout_apg886
    @beansprout_apg886 2 роки тому

    Good day. May I ask if you can demo how to maximize the use of Mikrotik if I wanted to use firewall for deception? Thanks!

  • @ve55
    @ve55 3 роки тому +1

    Do you use the M1 MacBook? How did you manage to install winbox? BR Nice Video Thank you!

    • @mikrotik
      @mikrotik  3 роки тому +5

      Follow my other video about it ua-cam.com/video/FXhT2QGxgp0/v-deo.html
      It works on M1 devices if you use Wine 6.21 or newer

    • @ve55
      @ve55 2 роки тому

      @@mikrotik i did not found wine 6.21 only 5.7 like in your video suggested.

  • @UlrichWessendorf
    @UlrichWessendorf 2 роки тому +5

    I appreciate such videos, but I miss IPv6 Firewall Rules. Many people use IPv6 in their home routers because of missing IPv4 addresses (e.g. DS-Lite). Could you do an advanced video about firewalling with IPv6?

    • @mikrotik
      @mikrotik  2 роки тому +4

      MikroTik devices also have default IPv6 firewall, you can learn from the default rules. To load them, enable IPv6 pacage and reset routerOS config to defaults, it will load the rules

  • @timschulenburg3240
    @timschulenburg3240 2 роки тому +1

    It would be very useful to have a video about setting up a hotspot with vouchers.

  • @danteregis9466
    @danteregis9466 Рік тому

    Please help some websites can't access using the set firewall.

  • @itzizag2280
    @itzizag2280 2 роки тому

    what would i do when i want to block bulk of domains. it is hard to enter every web-site.

  • @Da4HuK
    @Da4HuK Рік тому

    Thanks for Safe mode feature))

  • @ccfer
    @ccfer 5 місяців тому

    Can you provide the default firewall rules for rb5009ug+?

  • @bergertshitenge1375
    @bergertshitenge1375 2 роки тому

    very cool ! I like that

  • @mikkio5371
    @mikkio5371 2 роки тому

    My router is configured in DHCP with ISp providers. I use rb1100 . In order to block certain pages . On new rule forward chain in.interfwfe list . I could not find any interfaces . What can I do

  • @ITKOMP
    @ITKOMP 2 роки тому

    nice video and very good content

  • @jermsbestfriend9296
    @jermsbestfriend9296 2 роки тому

    can you please use a magnifying glass? Even in 1080p I cannot see.

  • @sergeymaslov2028
    @sergeymaslov2028 2 роки тому +1

    Shouldn't the new input drop rule for .13 be above accept rule to work?

    • @mikrotik
      @mikrotik  2 роки тому +2

      Yes, small mistake in moving the rule. Other commenters also said the same

    • @sergeymaslov2028
      @sergeymaslov2028 2 роки тому

      @@mikrotik ah, sorry, missed them. need to keep those colleagues you can’t trust at bay, you know ;) you have great product, keep it up!

  • @k4qdex
    @k4qdex 2 роки тому +1

    how to block the raw ip as well as the domain? somene might just punch in the raw IP of the webpage

    • @mikrotik
      @mikrotik  2 роки тому +1

      Just add one more rule and block the IP also. How to block IP is also in this video

    • @k4qdex
      @k4qdex 2 роки тому

      @@mikrotik what part of the video is the raw ip covered?

  • @onequestonevideo9457
    @onequestonevideo9457 Рік тому

    Thank you !!

  • @LeandroPepe90
    @LeandroPepe90 2 роки тому

    Will mikrotik integrate more specific firewall functions such as https proxy, https ispection (tls 1.3), ips and ids functions, smtp proxy and UTM functions in the future?
    Thanks in advance for the answer

    • @mikrotik
      @mikrotik  2 роки тому

      This is a router, not an ids

    • @LeandroPepe90
      @LeandroPepe90 2 роки тому

      @@mikrotik i know, i am aware of It, It was a question to ask if the future you will also integrate third-party services for the aforementioned functions.
      Thanks.

  • @josephantonio4140
    @josephantonio4140 2 роки тому

    Hi, I'm using firmware version is 7.1 and when I try your teaching, in the interface list I don't see the LAN option and it required me to put select protocol is this normal? So I just used in the "in interface List - ALL" and then I put protocol 6(tcp) it work.

    • @mikrotik
      @mikrotik  2 роки тому +2

      In that case, use a specific interface (probably bridge). The interface lists are part of default configuration of our home devices, not all have it

  • @emeka-umegbeaka
    @emeka-umegbeaka 2 роки тому +1

    Great video, but it seems to work for some sites and doesn't work on some other sites. Any reason or solution for this?

    • @mikrotik
      @mikrotik  2 роки тому +1

      Like in the video, check the webpage certificate details and see, maybe it is issued to other domains, that you can also try to block.

    • @mikrotik
      @mikrotik  2 роки тому +3

      also follow this nice video on more details about how to find the correct tls-host value: ua-cam.com/video/cFtZNbY-2Qo/v-deo.html

  • @airwifi2849
    @airwifi2849 2 роки тому

    great video, then P2P selection box is gone from the mangle rule general tab. How is this option chosen now? (It would assist me greatly.

    • @mikrotik
      @mikrotik  2 роки тому

      It was removed, because none of those p2p protocols exist anymore

  • @dktr2
    @dktr2 2 роки тому

    Right click and select "inline comments" definitely more readable.

  • @mazenahmad8554
    @mazenahmad8554 Рік тому

    اناامتلك جهاز روار 1100وهناك مشاكل في ضعف الارسال اعتقد من جدار الحمايه اريد انت تساعدني تشكيل جدار حمايه هل يمكنك مساعدتي

  • @valirmasha4718
    @valirmasha4718 2 роки тому

    I have local DNS Microsoft server, could you tell me how to prevent LAN users to change their client device to external like 8.8.8.8 rather than my local DNS 10.1.1.234? Thank in advance.

    • @mikrotik
      @mikrotik  2 роки тому

      Make a dst-nat rule that captures DNS requests and use action "redirect" to capture them.
      See our video about dst-nat rules ua-cam.com/video/a_8AV6vIDYQ/v-deo.html

  • @VladimirSaneeh
    @VladimirSaneeh 2 роки тому

    Will the whole Mikrotik brand change its identity to like this logo and colour anytime soon? It looks great!

  • @antonioespn4427
    @antonioespn4427 2 роки тому

    Hola como puedo hacer, tengo un router mikrotik 4011, tengo un segmento de red 192.168.1.1/24 tengo que llegar a la red10.10.1.1/24 y no puedo me pueden ayudar por favor.

  • @klaasdebeer9833
    @klaasdebeer9833 Рік тому

    Hallo, how do manage to use winbox on your apple laptop?

    • @mikrotik
      @mikrotik  Рік тому

      We have a video about it: ua-cam.com/video/TCPhYh9Wajw/v-deo.html

  • @oskarsfreimanis8192
    @oskarsfreimanis8192 3 роки тому

    Superīgs video. Paldies.

  • @johnrauner2515
    @johnrauner2515 2 роки тому

    I don't understand the remote IP. I get /24 at the end specifies all devices from that IP. But how does substituting that for .13 identify not only the public IP but then the specific internal IP behind that router?

    • @johnrauner2515
      @johnrauner2515 2 роки тому

      How do I specify all internet traffic for a deny all rule? I know where to put it, I just don't know how to express it.

    • @johnrauner2515
      @johnrauner2515 2 роки тому

      OK got it thanks to Mr Google. 0.0.0.0/0. Easy. But this might have been a helpful little bit of info to have included when talking about denying access to the router from the internet side.

  • @moscowdaily007
    @moscowdaily007 2 роки тому

    my lhg5 is connected to wifi router port and i am unable to login using mac address what to do

  • @dennason
    @dennason 2 роки тому

    Winbox via homebrew?

    • @mikrotik
      @mikrotik  2 роки тому

      No, just install Wine and run the exe

  • @itzizag2280
    @itzizag2280 2 роки тому

    why is drop rule second because you allow everyone to access port in first.

  • @spitfire_rs
    @spitfire_rs 2 роки тому

    Domain blocking doesn't work for me. My Filter Rules are empty and this drop is alone in list.
    Chain: forward
    Protocol: tcp
    In. Interface List: LAN
    TLS Host: *mikrotik*
    Action: drop
    What I need more in Firewall for this blocking?

    • @mikrotik
      @mikrotik  2 роки тому

      Make sure your device is working as a router, not a switch or bridge.

    • @spitfire_rs
      @spitfire_rs 2 роки тому

      @@mikrotik It's working now but why can't work on youtube or google?

  • @JachimRRX
    @JachimRRX 2 роки тому

    At 12:10 this doesn't seem right. If it's public address, adding whole subnet will allow not only Your office, but also other public addresses, that are sharing the mask. Am I correct? Or I missed something? :)
    I mean, this is an example, but should be more precisely explained if my thinking is correct :)
    Other than that, great video!

    • @mikrotik
      @mikrotik  2 роки тому +1

      It's correct, but usually the company has a whole subnet of IP addresses. At least in this example. If you only have one IP, use it like this 159.148.172.204/32

  • @narsil7350
    @narsil7350 Рік тому

    how did you connect from Mac?

    • @mikrotik
      @mikrotik  Рік тому

      Winbox on MacOS M1 in two steps
      ua-cam.com/video/TCPhYh9Wajw/v-deo.html

  • @Tenly2009
    @Tenly2009 2 роки тому

    Don’t bother watching this from a phone!
    The content of this video was fantastic and extremely useful for a beginner like me - although the presentation of it could have been a lot better. As it is, this video is nearly useless for viewing on a mobile phone (even a 13 Pro Max) because the focused content is not zoomed to make it readable. I had to AirPlay to my 70• screen in order to be able to make out what was on the screen. It would have also been fine on a tablet or PC.
    I definitely recommend watching the video - but just bookmark it for now (if you’re on a phone) and watch it later from a larger screen device.
    I hope future videos will keep this in mind since it’s not often convenient for me to watch from a larger screen device.

    • @mikrotik
      @mikrotik  2 роки тому

      Yes, since there is a screen recording of a computer screen, you need to view this video in 4K when watching on a phone screen, then it looks very clear even on the smaller iPhone 13 pro (non max). For lower bandwidth connections, you would need a bigger screen, as details will be lost in 1080p or less.

  • @michaelfladenhofer4931
    @michaelfladenhofer4931 2 роки тому

    Greetings from Austria ;-)
    At first: Great Video! when will it possible to get some new devices ? The stock-situation is .... best wishes for 2023 !!!

    • @mikrotik
      @mikrotik  2 роки тому

      New devices are going out every now and then. Make sure you put your reservation in, don’t just wait

  • @DiegoMonteiroDCADSERVICIOS
    @DiegoMonteiroDCADSERVICIOS 2 роки тому

    Hello, very good to have videos of the brand, I want to tell you that the webpages blocking rule does not work with youtube or putting it at the beginning of the rules. please be more specific with your rules and not so general. Thank you

    • @mikrotik
      @mikrotik  2 роки тому

      It works fine for us, make sure you disable fast track and use correct chain

  • @ljuberzy
    @ljuberzy 2 роки тому

    was that the winbox for osx or safari for windows?

    • @mikrotik
      @mikrotik  2 роки тому

      Winbox runs perfectly fine in Wine 6 for macOS, even on M1 architecture. Follow our other video for more: ua-cam.com/video/FXhT2QGxgp0/v-deo.html

  • @kahitanongmaisip9358
    @kahitanongmaisip9358 2 роки тому

    Sir about games apps like mobile legend what is the TLS HOST?

    • @kahitanongmaisip9358
      @kahitanongmaisip9358 2 роки тому

      And this config work in manggle rules? I'd like to limit the bandwidth of mobile legend

    • @mikrotik
      @mikrotik  2 роки тому +1

      you can block mobile legends game in your network, by blocking ports 3000-30999

  • @mahmudhashim8897
    @mahmudhashim8897 2 роки тому

    requesting to prepared video ospf filter && routed base vpn with juniper SRX ..

  • @yannicknieglo8239
    @yannicknieglo8239 2 роки тому

    bro where chalk up u been, it is so cool

  • @NajaTech
    @NajaTech Рік тому

    ❤❤

  • @ivancristianledezmasoria3461
    @ivancristianledezmasoria3461 2 роки тому +2

    Winbox dark mode....please

  • @papemalicksoumare
    @papemalicksoumare 2 роки тому

    Indeed

  • @aspeakgaming3564
    @aspeakgaming3564 Рік тому

    The website rule do not work for me

  • @mrjavaci
    @mrjavaci 2 роки тому

    How use winbox on macos?

    • @mikrotik
      @mikrotik  2 роки тому

      ua-cam.com/video/FXhT2QGxgp0/v-deo.html

  • @lynskri
    @lynskri 2 роки тому

    Labs video! Varbūt var nākotnē kaut ko par CAPsMan un Wifi ar VLAN'iem? :)

    • @mikrotik
      @mikrotik  2 роки тому +1

      Tāds video jau mums ir, skat nedaudz vecākos 😊

  • @ruhullahansari3680
    @ruhullahansari3680 2 роки тому

    Please make a video and show how to limit the internet only for WhatsApp and full internet access from the userman to other users.

  • @burmaentertainment3055
    @burmaentertainment3055 2 роки тому

    nice

  • @rsvidenko
    @rsvidenko 2 роки тому +1

    plz fix WAVE2 wifi and Capsman (!) for 128Mb routers (!!!)

    • @mikrotik
      @mikrotik  2 роки тому +1

      Capsman works fine

  • @dnirox
    @dnirox 2 роки тому

    Thanks a lot. If it’s possible pls make same for Russian speakers user. Thanks 😊

  • @hpsfresh
    @hpsfresh 2 роки тому +1

    New logo?

  • @MSIZAR
    @MSIZAR 2 роки тому

    seems you cant block youtube using the TLS, anyone had any luck blocking yourtube?

    • @mikrotik
      @mikrotik  2 роки тому +1

      It works fine, make sure you follow the video exactly, including disabling of fast track and rule order

  • @jonneyorwhat
    @jonneyorwhat 2 роки тому

    good :)

  • @mehdikhosravi8799
    @mehdikhosravi8799 2 роки тому

    Hi, don't worry, I wanted to know how to monitor which sites the user has visited in Mikrotik

  • @guilhemserra5134
    @guilhemserra5134 2 роки тому

    Ur guaranteed to bang views here lads

  • @mauriciolealdesouza
    @mauriciolealdesouza 2 роки тому

    Hey friend
    I noticed that you are using winbox and a macbook.
    Why does Mikrotik not have windobox for mac?
    This would be important, as we have to use emulated solutions.
    And in view of an official channel.
    Here's the tip.

    • @mikrotik
      @mikrotik  2 роки тому +1

      Because - as you see it works 😂

  • @CeleronS1
    @CeleronS1 2 роки тому

    Normis Malacis! Liels Paldies!

  • @criticalmoorhen
    @criticalmoorhen 2 роки тому

    Is it just me or anyone else always select "show inline comments"? The way WinBox shows comments (in separate line) doesn't make any sense to me.
    Anyway, good vid!

  • @henintsoagabriel8206
    @henintsoagabriel8206 2 роки тому

    its just loading and not responding

  • @pinkyvinnty4439
    @pinkyvinnty4439 2 роки тому

    Others are like, Yeah, so just make a crazy lody and drum and setup.

  • @jeytis72
    @jeytis72 2 роки тому

    The webpage blocking rule would be totally useless if your browser using DoH, I guess. Thanks

    • @mikrotik
      @mikrotik  2 роки тому +3

      This is what encryption is for, yes. It would be great if everyone would be using encryption everywhere.

    • @jeytis72
      @jeytis72 2 роки тому

      @@mikrotik Yes, but just don't tell it to (big companies') network admins :-)

  • @karapadauk2432
    @karapadauk2432 7 місяців тому

    If it's not clear we can't follow along.

  • @usuario2ful
    @usuario2ful 3 роки тому +1

    Please see if it can be done in Spanish. Thank you.