caute,
robil som 2 vlany (hostia a domaca siet) a nahodil som podla jedneho navodu aj komplet nove pravidla na firewall pretoze uz predtym mi padal net. Od Vas by som chcel vediet ci aktualne pravidla postacuju:
ip firewall filter
Flags: X - disabled, I - invalid, D - dynamic
0 chain=input action=accept connection-state=established,related
1 chain=WAN>INPUT action=accept src-address-list=mgmt_ip
2 chain=input action=jump jump-target=WAN>INPUT in-interface=WAN
3 chain=input action=accept in-interface=fix_vlan
4 chain=input action=accept in-interface=host_vlan
5 chain=forward action=accept connection-state=established,related
6 chain=forward action=accept in-interface=fix_vlan out-interface=WAN
7 chain=forward action=accept in-interface=host_vlan out-interface=WAN
8 chain=forward action=drop in-interface=host_vlan out-interface=fix_vlan log=no log-prefix=""
9 chain=input action=drop connection-state=invalid
10 chain=WAN>INPUT action=drop log=yes
11 chain=input action=drop log=yes
12 chain=forward action=drop connection-state=invalid
13 chain=forward action=drop in-interface=WAN out-interface=fix_vlan
14 chain=forward action=drop in-interface=WAN out-interface=host_vlan
ip firewall nat
0 chain=srcnat action=masquerade src-address-list=fix_ip out-interface=WAN log=no log-prefix=""
1 chain=srcnat action=masquerade src-address-list=host_ip out-interface=WAN log=no log-prefix=""
2 chain=dstnat action=dst-nat to-addresses=server ip to-ports=443 protocol=tcp dst-address-list=brana in-interface=WAN dst-port=443 log=no log-prefix=""
3 chain=dstnat action=dst-nat to-addresses=server ip to-ports=80 protocol=tcp dst-address-list=brana in-interface=WAN dst-port=80 log=no log-prefix=""
V mgmt address liste je len MT, SWITCHE a APcka,
moja topologia
gateway bridge od ISP -> MT ETH1 (WAN)
MT ETH2 -> SWITCH1 ETH1
SWITCH1 ETH2-ETH4 -> UBNT APs, ETH6-ETH16 -> Koncove zariadenia, ETH5 -> SWITCH2
SWITCH2 ETH2-ETH3 -> SERVER1 SERVER2, ETH4-ETH8 -> Koncove zariadenia, SWITCH2 ETH1 -> SWITCH1
Mam jednu VLANu, v ktorej su zaradene vsetky porty obidvoch switchov a tag je len MT port na switchi1, ostatne porty su untag.
Druha VLANa obsahuje len MT a APs, vsetky 4 porty tagovane
Siet pre hosti je prevadzkovana len na wifi UBNT APs. Tretiu MGMT VLANu nemam pretoze zo ziadneho navodu som nepochopil jej zmysel resp. ked som sa pokusil ju vytvorit tak mi nefungovala siet vobec.
Su teda tie pravidla ok alebo je tam nejaka vazna diera?
btw FW pravidla som robil podla tohto https://cnnc.cz/mikrotik-routeros-firewalling/
Este mam v plane si pozriet fail2ban v suvislosti s MT resp. DDoS pravidla a doplnit to