rukawa22 wrote:G兄您好~其實您說的...(恕刪) 會沒反應是因您連出的組合src-port與dst-address-list,這兩個組合其中有個沒設到。您連出設到了src-address-list都沒更正,所以從頭至尾都出了問題。
pctine wrote:Bandwidth Management - Simple QueueRouterOS 其中一項最吸引小弟的功能就是頻寬管理, 素聞其擁有強大的管理能力, 但小弟還沒有學到那麼多, 先介紹最基本的 Simple Queue............ 小的實測,下圖此種方式,似乎是整個限制target網段的速度,並非分配每個IP流量。簡單說就是整個網段搶target upload/target download。這種方式似乎導致整個網段ip有人先搶先贏的狀態。及routeros6版本與routeros5介面有些小改了。
5/6 在露天買的RB450到家一直到5/12幾乎每天都會查看address-list.但都沒有封鎖的ip,除非有神功護體..中間有升級到6.12,5/12 netinstall 重新安裝RB450 routeros 6.12附上firewall設定檔 第一條drop input我卻可以上Mobile01,是不是代表firewall沒有動作呢?請問大大這是什麼原因呢?/ip firewall address-listadd address=0.0.0.0/8 list=blacklistadd address=10.0.0.0/8 list=blacklistadd address=192.168.0.0/16 list=blacklistadd address=172.0.0.0/8 list=blacklistadd address=14.0.0.0/8 list=blacklistadd address=169.254.0.0/16 list=blacklistadd address=100.0.0.0/8 list=blacklistadd address=1.0.0.0/8 list=blacklistadd address=224.0.0.0/4 list=blacklistadd address=240.0.0.0/4 list=blacklistadd address=255.0.0.0/8 list=blacklistadd address=8.8.8.8 list=dnsadd address=208.67.220.220 list=dns/ip firewall filteradd action=drop chain=inputadd action=drop chain=input in-interface=wan src-address-list=blacklistadd action=drop chain=input dst-address-list=blacklist in-interface=wanadd action=add-src-to-address-list address-list=blacklist chain=input \in-interface=wan protocol=icmpadd action=drop chain=input in-interface=wan protocol=icmpadd action=add-src-to-address-list address-list=blacklist chain=input \connection-state=new in-interface=wanadd action=drop chain=input connection-state=new in-interface=wanadd action=add-src-to-address-list address-list=blacklist chain=input \connection-state=invalid in-interface=wanadd action=drop chain=input connection-state=invalid in-interface=wanadd action=add-src-to-address-list address-list=blacklist chain=input \add action=add-src-to-address-list address-list=blacklist chain=input \add action=drop chain=input dst-port=0-10240 in-interface=wan protocol=tcpadd action=add-src-to-address-list address-list=blacklist chain=input \dst-port=0-10240 in-interface=wan protocol=udpadd action=drop chain=input dst-port=0-10240 in-interface=wan protocol=udpadd chain=input connection-state=established in-interface=wan protocol=tcpadd chain=input connection-state=established in-interface=wan protocol=udp \src-address-list=dns src-port=53add action=drop chain=input in-interface=wanadd action=drop chain=output dst-address-list=blacklist out-interface=wanadd chain=output connection-state=new out-interface=wan protocol=tcpadd chain=output connection-state=established out-interface=wan protocol=tcpadd chain=output connection-state=new out-interface=wan protocol=udpadd action=drop chain=output out-interface=wan/ip firewall natadd action=masquerade chain=srcnat src-address=10.168.168.0/24add action=masquerade chain=srcnat src-address=10.168.169.0/24
>> 一直到5/12幾乎每天都會查看address-list.但都沒有封鎖的ip,除非有神功護體..既然大大出考題, 那大家就先動動腦, 大大這些 firewall rule 是自己設定的嗎? 你原本預期這些 firewall rule 是要達到什麼作用? 小弟比較建議了解每個指令或是功能所達到的目的, 而並非一下子就套用一大堆規則進來.>> 中間有升級到6.12,5/12 netinstall 重新安裝RB450 routeros 6.12firmware 升級並需要用到 netinstall 那麼麻煩, 你可以參考前面的討論文章.>> 附上firewall設定檔 第一條drop input我卻可以上Mobile01,是不是代表firewall沒有動作呢?chain=input 是指任何封包目的地是 router 本身, 你應該要處理的是 chain=forward.