I
I
Ivan Tishchenko2016-08-10 09:36:22
Computer networks
Ivan Tishchenko, 2016-08-10 09:36:22

How to limit connection lifetime in Mikrotik for IPv6?

Firewall options:

# aug/10/2016 09:32:07 by RouterOS 6.36
# software id = X5Q5-12IU
#
/ipv6 firewall filter
add chain=input limit=100,5:packet protocol=icmpv6
add action=drop chain=input protocol=icmpv6
add chain=forward limit=100,5:packet protocol=icmpv6
add action=drop chain=forward protocol=icmpv6
add action=drop chain=input dst-address-list=local log-prefix=""
add action=accept chain=input comment="http(s)" connection-state=established,related,new dst-address-list=web-srvs dst-port=80,443 log-prefix="" \
    protocol=tcp
add action=accept chain=input connection-state=established,related log-prefix=""
add action=drop chain=input connection-state=invalid,new log-prefix=""
add action=accept chain=forward connection-state=!invalid in-interface=ether1-gateway log-prefix="" out-interface=bridge-local
add action=drop chain=forward in-interface=ether1-gateway out-interface=ether1-gateway
add action=drop chain=forward connection-state=invalid log-prefix=""

/ipv6 firewall mangle
add action=accept chain=prerouting log-prefix=""
add action=accept chain=forward log-prefix=""
add action=accept chain=postrouting log-prefix=""

At the same time, I observe more than 200 "established" connections with a lifetime of more than 15 days.
What is the reason for this? How to limit the maximum connection lifetime?

Answer the question

In order to leave comments, you need to log in

1 answer(s)
D
Dmitry Tallmange, 2016-08-10
@p00h

/ip firewall connection tracking, more

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question