Stats
Om de matchingstatistieken per firewallregel te bekijken, voert u het commando /ip/firewall/filter/print stats uit, of /ipv6/firewall/filter/print stats voor de IPv6-firewall.
| Property | Description |
|---|---|
| bytes (integer) | De totale hoeveelheid bytes die door de regel is gematcht |
| packets (integer) | De totale hoeveelheid pakketten die door de regel is gematcht |
[admin@MikroTik] > ip firewall filter print stats
Flags: X - disabled, I - invalid, D - dynamic
# CHAIN ACTION BYTES PACKETS
0 D ;;; special dummy rule to show fasttrack counters
forward passthrough 50 507 925 242 50 048 246
1 ;;; defconf: drop invalid
forward drop 432 270 9 719
2 ;;; defconf: drop invalid
input drop 125 943 2 434
3 input accept 20 090 211 549 20 009 864
4 ;;; defconf: accept ICMP
input accept 634 926 7 648
5 ;;; defconf: drop all not coming from LAN
input drop 4 288 079 83 428
6 ;;; defconf: accept in ipsec policy
forward accept 0 0
7 ;;; defconf: accept out ipsec policy
forward accept 0 0
8 ;;; defconf: fasttrack
forward fasttrack-connection 28 505 528 775 31 504 682
9 ;;; defconf: accept established,related, untracked
forward accept 28 505 528 775 31 504 682
10 ;;; defconf: drop all from WAN not DSTNATed
forward drop 0 0
Statistiekparameters kunnen met de volgende commando's worden gereset:
| Command | Description |
|---|---|
| reset-counters (id) | Zet de statistiektellers terug op nul voor een specifieke firewallregel of een lijst met regels. |
| reset-counters-all | Zet de statistiektellers terug op nul voor alle firewallregels in de tabel. |
Andere nuttige commando's
Standaard is print gelijk aan print static en toont het alleen statische regels.
Om ook dynamische regels af te drukken, gebruikt u print all.
Of gebruik print dynamic om alleen dynamische regels af te drukken.
Matchers
Matchers worden in een specifieke volgorde uitgevoerd.
Voor IPv4
- Bron-MAC-adres
- In/Out interfaces
- In/Out interface lists
- IP-bereik
- Adrestype
- Adreslijst
- TTL
- DSCP
- Length
- TLS
- IPv4-opties
- Dst Port
- Src Port
- Elke poort
- TCP Options
- TCP MSS
- ICMP-codes
- Ingress Priority
- Priority
- Packet Mark
- Realm (routeringstabel)
- Hotspot
- Connection Mark
- Connection State
- Connection NAT State
- Connection Bytes
- Connection Limit
- Connection Rate
- IPsec Policy
- Helper
- String (inhoud)
- PSD
- Layer7
- Random
- Nth
- PCC
- Limit
- Dst Limit
- Log
Voor IPv6
- Adrestype
- Adreslijst
- Bron-MAC-adres
- In/Out interfaces
- In/Out interface lists
- Hop Limit
- DSCP
- Length
- TLS
- IPv6-header
- Dst Port
- Src Port
- Elke poort
- TCP Options
- TCP MSS
- ICMPv6-codes
- Ingress Priority
- Priority
- Packet Mark
- Connection Mark
- Connection State
- Connection NAT State
- Connection Bytes
- Connection Limit
- Connection Rate
- IPsec Policy
- Helper
- Match String (content)
- Random
- Nth
- PCC
- Limit
- Dst Limit
- Log