05.01.2015 Views

MikroTik RouterOS™ v2.9

MikroTik RouterOS™ v2.9

MikroTik RouterOS™ v2.9

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Home menu level: /interface bridge filter<br />

Description<br />

This section describes bridge packet filter specific filtering options, which were omitted in the<br />

general firewall description<br />

Property Description<br />

action (accept | drop | jump | log | mark | passthrough | return; default: accept) - action to undertake<br />

if the packet matches the rule, one of the:<br />

• accept - accept the packet. No action, i.e., the packet is passed through without undertaking any<br />

action, and no more rules are processed in the relevant list/chain<br />

• drop - silently drop the packet (without sending the ICMP reject message)<br />

• jump - jump to the chain specified by the value of the jump-target argument<br />

• log - log the packet<br />

• mark - mark the packet to use the mark later<br />

• passthrough - ignore this rule and go on to the next one. Acts the same way as a disabled rule,<br />

except for ability to count packets<br />

• return - return to the previous chain, from where the jump took place<br />

out-bridge (name) - outgoing bridge interface<br />

out-interface (name) - interface via packet is leaving the bridge<br />

Bridge NAT<br />

Home menu level: /interface bridge nat<br />

Description<br />

This section describes bridge NAT options, which were omitted in the general firewall description<br />

Property Description<br />

action (accept | arp-reply | drop | dst-nat | jump | log | mark | passthrough | redirect | return |<br />

src-nat; default: accept) - action to undertake if the packet matches the rule, one of the:<br />

• accept - accept the packet. No action, i.e., the packet is passed through without undertaking any<br />

action, and no more rules are processed in the relevant list/chain<br />

• arp-reply - send a reply to an ARP request (any other packets will be ignored by this rule) with<br />

the specified MAC address (only valid in dstnat chain)<br />

• drop - silently drop the packet (without sending the ICMP reject message)<br />

• dst-nat - change destination MAC address of a packet (only valid in dstnat chain)<br />

• jump - jump to the chain specified by the value of the jump-target argument<br />

• log - log the packet<br />

• mark - mark the packet to use the mark later<br />

• passthrough - ignore this rule and go on to the next one. Acts the same way as a disabled rule,<br />

Page 142 of 615<br />

Copyright 1999-2005, <strong>MikroTik</strong>. All rights reserved. Mikrotik, RouterOS and RouterBOARD are trademarks of Mikrotikls SIA.<br />

Other trademarks and registred trademarks mentioned herein are properties of their respective owners.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!