05.01.2015 Views

MikroTik RouterOS™ v2.9

MikroTik RouterOS™ v2.9

MikroTik RouterOS™ v2.9

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

idge1 00:C0:DF:07:5E:E6 ether1 4m46s<br />

bridge1 00:E0:C5:6E:23:25 prism1 4m48s<br />

bridge1 00:E0:F7:7F:0A:B8 ether1 1s<br />

[admin@<strong>MikroTik</strong>] interface bridge host><br />

Bridge Firewall General Description<br />

Home menu level: /interface bridge filter, /interface bridge nat, /interface bridge broute<br />

Description<br />

The bridge firewall implements packet filtering and thereby provides security functions that are<br />

used to manage data flow to, from and through bridge<br />

Note that packets between bridged interfaces, just like any other IP traffic, are also passed through<br />

the 'generic' /ip firewall rules (but bridging filters are always applied before IP filters/NAT of the<br />

built-in chain of the same name, except for the output which is executed after IP Firewall Output).<br />

These rules can be used with real, physical receiving/transmitting interfaces, as well as with bridge<br />

interface that simply groups the bridged interfaces.<br />

There are three bridge filter tables:<br />

• filter - bridge firewall with three predefined chains:<br />

• input - filters packets, which destination is the bridge (including those packets that will<br />

be routed, as they are anyway destined to the bridge MAC address)<br />

• output - filters packets, which come from the bridge (including those packets that has<br />

been routed normally)<br />

• forward - filters packets, which are to be bridged (note: this chain is not applied to the<br />

packets that should be routed through the router, just to those that are traversing between<br />

the ports of the same bridge)<br />

• nat - bridge network address translation provides ways for changing source/destination MAC<br />

addresses of the packets traversing a bridge. Has two built-in chains:<br />

• scnat - used for "hiding" a host or a network behind a different MAC address. This chain<br />

is applied to the packets leaving the router through a bridged interface<br />

• dstnat - used for redirecting some pakets to another destinations<br />

• broute - makes bridge a brouter - router that performs routing on some of the packets, and<br />

bridging - on others. Has one predefined chain: brouting, which is traversed right after a<br />

packet enters an enslaved interface (before "Bridging Decision")<br />

Note: the bridge destination NAT is executed before bridging desision<br />

You can put packet marks in bridge firewall (filter, broute and NAT), which are the same as the<br />

packet marks in IP firewall put by mangle. So packet marks put by bridge firewall can be used in IP<br />

firewall, and vice versa<br />

General bridge firewall properties are described in this section. Some parameters that differ between<br />

nat, broute and filter rules are described in further sections.<br />

Property Description<br />

Page 138 of 615<br />

Copyright 1999-2005, <strong>MikroTik</strong>. All rights reserved. Mikrotik, RouterOS and RouterBOARD are trademarks of Mikrotikls SIA.<br />

Other trademarks and registred trademarks mentioned herein are properties of their respective owners.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!