✅ Настройка MikroTik. Создание туннеля L2TP-IPSec для объединения офисов
Как закрыть порты в Mikrotik (Router OS)
Иногда может потребоваться запретить какому то сервису или программе ходить в интернет по какому-либо порту. Сегодня мы разберем процесс создания правила блокировки порта. Входим в MIkrotik через Winbox. В качестве примера запретим порт 22 Идем в: IP→Firewall→Filter Rules→New Firewall rule (синий плюсик) Добавляем правило: Chain – input
Protocol – tcp
Dst.port – 22
In...
В январе состаялся релиз новой мажорной версии RouterOS 7.17 для Mikrotik. Список изменений довольно внушительный. --- The major version of Mikrotik RouterOS 7.17 was released in January. There is an impressive list of changes. What's new in 7.17.1 (2025-Jan-30 12:29): *) bgp - improved system stability when printing BGP advertisements; *) bridge - fixed endless MAC update loop (introduced in v7.17); *) dhcpv4-server - fixed lease assigning when server address is not bind to server interface (introduced in v7.17); *) igmp-proxy - fixed multicast routing after upstream interface flaps (introduced in v7.17); *) ipsec - fixed chacha20 poly1305 proposal; *) ipsec - fixed installed SAs update process when SAs are removed; *) ipv6 - fixed an issue where bridge, IP, IPv6 and discovery settings were lost after upgrade due to conflicting IPv6 properties (introduced in v7.17); *) ovpn - added requirement for server name when exporting configuration; *) ppc - fixed HW encryption (introduced in v7.17); *) queue - improved system stability when many simple queues are added (introduced in v7.17); *) resolver - fixed static FQDN resolving (introduced in v7.17); *) system,arm - automatically increase boot part size on upgrade or netinstall (fixed upgrade failed due to a lack of space on kernel disk/partition); *) winbox - show warning messages for static DNS entries; What's new in 7.17 (2025-Jan-16 10:19): !) device-mode - after upgrade, mode "enterprise" is renamed to "advanced" and traffic-gen, partition (command "repartition"), routerboard and install-any-version features will be disabled; !) webfig - redesigned HTML, styling and functionality; *) 6to4 - fixed issue where 6to4 relay would not forward traffic unless destination address is set; *) adlist - improved logging; *) adlist - improved system stability; *) adlist - optimized import on system with low disk space; *) api - fixed REST API serialization of binary data; *) arm64 - fixed for bare-metal servers to be able to access more than 2GB RAM; *) arm64 - show CPU frequency on bare-metal installations; *) arm64/x86 - added missing PCI id for mlx4 driver; *) bonding - hide mlag-id property on non-compatible devices; *) bridge - add HW offload support for active-backup bonds on 98DXxxxx, 88E6393X, 88E6191X and88E6190 switches; *) bridge - added interface-list support for VLANs; *) bridge - added message for inactive port reason; *) bridge - added priority setting to manually elect primary MLAG peer; *) bridge - correctly display PPP interfaces in VLAN menu; *) bridge - disallow duplicate static VLAN entries; *) bridge - disallow multicast MAC address as admin-mac; *) bridge - enable faster HW offloading when detect-internet is disabled; *) bridge - fixed first host table response for SNMP; *) bridge - fixed incorrect HW offloaded port state in certain cases on MSTI add; *) bridge - fixed missing slave flag on port in certain cases; *) bridge - fixed MVRP registrar and applicant port options; *) bridge - fixed port monitor with interface-lists; *) bridge - fixed port move command; *) bridge - fixed setting bridge MTU to L2MTU value; *) bridge - fixed VLAN overlap check; *) bridge - ignore disabled interfaces when calculating bridge L2MTU; *) bridge - improved port handling; *) bridge - improved stability; *) bridge - prioritize MAC selection from Ethernet interfaces when using auto-mac feature; *) bridge - re-synchronize MLAG system-id when bridge MAC changes; *) bridge - removed support for master port config conversion (used before version 6.41); *) bridge - update dynamic MSTI priority value when changing configuration; *) bth - improved stability on system time change; *) certificate - do not download CRL if there is not enough free RAM; *) certificate - do not show not relevant values for certificate template (CLI only); *) certificate - fixed handling of capsman-cap certificates (introduced in v7.16); *) certificate - removed unstructured address field support; *) chr - added Chelsio VF driver for PCIID 5803;