Is all of those rules really needed if NAT is being done on the SonicWall and not the MikroTik? Wouldn't this be sufficient?
/ip firewall filter
add action=accept chain=input comment="allow > established/related" connection-state=established,related
add action=drop chain=input comment="drop > invalid" connection-state=invalid
add action=accept chain=input comment="allow > icmp" protocol=icmp
add action=drop chain=input comment="drop > all"
add action=accept chain=forward comment="allow > established/related" connection-state=established,related
add action=drop chain=forward comment="drop > invalid" connection-state=invalid
/ip firewall filter
add action=accept chain=input comment="allow > established/related" connection-state=established,related
add action=drop chain=input comment="drop > invalid" connection-state=invalid
add action=accept chain=input comment="allow > icmp" protocol=icmp
add action=drop chain=input comment="drop > all"
add action=accept chain=forward comment="allow > established/related" connection-state=established,related
add action=drop chain=forward comment="drop > invalid" connection-state=invalid
Statistics: Posted by hwnd — Wed Jan 17, 2024 4:50 pm