Bridge Filter

FUN with Mikrotik BRIDGE Series# Redirecting Traffic with Mikrotik Bridge – Part#2

Filed under: Mikrotik— Tags: bridge filter, Mikrotik bridge, mikrotik dst-nat, redirect — Silicon Care / Pune~:) @ 2:13 PM

  1. FUN with Mikrotik BRIDGE Series#1. Filter PPPoE Requests – Part#1

Disclaimer! This is important!

This post is related to a solution designed specific to cater some local manipulation requirement therefore you may continue to read it as an reference purpose only !

Every Network is different , so one solution cannot be applied to all. Therefore try to understand logic & create your own solution as per your network scenario. Just dont follow copy paste.

Please donot think that I am an expert on this stuff, I am NOT certified in anything including Mikrotik/Cisco/Linux or Windows. However I have worked with some core networks and I read , research & try stuff all of the time. So I am not speaking/posting about stuff I am formerly trained in, I pretty much go with experience and what I have learned on my own. And , If I don’t know something then I read & learn all about it.

So , please don’t hold me/my-postings to be always 100 percent correct. I am human being , I do make mistakes just like everybody else. However – I do my best, learn from my mistakes and always try to help others

Scenario & Requirements:

We want to connect Network A & B using Mikrotik Bridge so that we can transparently intercept some traffic for control & redirection purposes. Example we want to make sure that any dns traffic that is traveling from A to B or B to A should be redirected to Mikrotik DNS for manipulation purposes. Also we would like to Block ICMP traffic travelling between both networks.

Solution:

We are using Mikrotik 2011UiAS-2HnD model.

Port-1 is connected with Network A and Port-2 is connected with Network B.

# BRIDGE Configuration

First we will do Bridge configuration & add ports in it,

/interface bridge
add name=bridge1
 
/interface bridge port
add bridge=bridge1 interface=ether1
add bridge=bridge1 interface=ether2
/interface bridge settings
set use-ip-firewall=yes

As showed in image below …

# DNS Configuration

Now setup Local DNS server

/ip dns
set allow-remote-requests=yes servers=8.8.8.8
 
# Now we will add static DNS entry for our requirements
/ip dns static
add address=1.2.3.4 name=aacable.wordpress.com

As showed in image below …

# DNS Redirection

Firewall NAT configuration to redirect DNS traffic travelling via BRIDGE interface to Mikrotik local DNS for manipulation purposes

/ip firewall nat
add action=redirect chain=dstnat comment="Redirect DNS Traffic via BRIDGE to local DNS - tejas" dst-port=53 in-interface=bridge1 protocol=udp to-ports=53

# ICMP Filteration

Firewall Filter configuration to block ICMP protocol

/ip firewall filter
add action=reject chain=forward comment="Block ICMP Rule in BRIDGE - tejas" in-interface=bridge1 protocol=icmp reject-with=icmp-network-unreachable

Client Testing

Result of testing NSLOOKUP from user PC. [Before vs After]

Result of testing ICMP & PING from user PC.

 Linux is amazing 
however Mikrotik is handy most of the times

Regard’s

Silicon Care

19 Comments

  1. September 19, 2019 at 11:42 am

    I’ve been browsing on-line greater than 3 hours nowadays, yet
    I never found any attention-grabbing article like yours.
    It’s pretty worth enough for me. Personally, if all site owners and
    bloggers made excellent content as you did, the web will probably be
    much more helpful than ever before.

  2. September 19, 2019 at 12:48 pm

    I seriously love your website.. Great colors & theme.
    Did you build this web site yourself? Please reply back as I’m attempting to create my own blog and would love to find out where you
    got this from or exactly what the theme is named. Thank you!

  3. September 19, 2019 at 1:56 pm

    Enjoy discounts with no discount codes needed.

  4. September 19, 2019 at 10:57 pm

    After I initially commented I seem to have clicked the -Notify me when new comments are added-
    checkbox and from now on every time a comment is added I get four emails with the exact same comment.
    Perhaps there is an easy method you can remove me from that service?
    Thank you!

  5. September 19, 2019 at 10:58 pm

    No matter if some one searches for his essential thing,
    thus he/she wishes to be available that in detail, so that thing
    is maintained over here.

  6. September 20, 2019 at 5:50 am

    The Simpsons: Tapped Out seems great.

  7. September 20, 2019 at 9:06 am

    Appreciate the recommendation. Let me try it out.

  8. September 20, 2019 at 3:27 pm

    Thanks for sharing your thoughts on florida. Regards

  9. September 20, 2019 at 6:46 pm

    WOW just what I was searching for. Came here by searching for Streaming
    Hentai Online Free

  10. September 20, 2019 at 7:15 pm

    I am not sure where you are getting your
    information, but great topic. I needs to spend
    some time learning much more or understanding more.
    Thanks for magnificent info I was looking for this info for my mission.

  11. September 21, 2019 at 12:02 am

    Hey! I know this is kinda off topic but I was wondering if you knew where I could
    get a captcha plugin for my comment form? I’m using the same blog platform as yours and I’m having problems
    finding one? Thanks a lot!

  12. September 21, 2019 at 1:44 am

    Excellent blog right here! Also your website so much up very fast!
    What host are you the use of? Can I get your affiliate link
    for your host? I desire my web site loaded up as quickly as yours lol

  13. September 21, 2019 at 6:54 am

    Howdy! Someone in my Myspace group shared this website with us so
    I came to look it over. I’m definitely loving the information. I’m bookmarking and will be tweeting this to my
    followers! Terrific blog and brilliant design.

  14. September 21, 2019 at 4:21 pm

    My developer is trying to convince me to move to .net from PHP.
    I have always disliked the idea because of the costs.
    But he’s tryiong none the less. I’ve been using WordPress on various websites for
    about a year and am nervous about switching to another platform.
    I have heard great things about blogengine.net. Is there a way I can import all my
    wordpress content into it? Any kind of help would be greatly appreciated!

  15. September 22, 2019 at 11:13 am

    I do trust all the concepts you have presented in your post.
    They are really convincing and can definitely work. Nonetheless, the posts are too quick
    for novices. May just you please extend them a bit from subsequent time?
    Thank you for the post.

  16. September 24, 2019 at 12:52 am

    That is one can possibly choose his personal team along with the techniques that’ll be accustomed to
    play the game. The Internet is filled with online games which can be specifically made keeping boys in mind.
    The major reason roulette is such an interesting game is because from the
    numerous ways that gamers can lay the bets.

  17. September 24, 2019 at 6:16 am

    Hi, I do believe this is an excellent site. I stumbledupon it
    😉 I may return once again since i have book marked it.

    Money and freedom is the greatest way to change, may you be rich and continue to
    guide others.

  18. September 24, 2019 at 2:23 pm

    Hello There. I discovered your blog using msn. That iss a reeally smartly writfen article.
    I’ll be ssure to bookmark it and come back to learn more of
    your helpful information. Thanks for the post. I’ll definitely comeback.

  19. When I initially commented I seem to have clicked on the -Notify me when new comments are
    added- checkbox and now whenever a comment
    is added I get four emails with the exact same comment.
    There has to be an easy method you are able to remove me from that
    service? Thanks a lot!

Leave A Comment