RouterOS handleiding

Veelgebruikte firewall-matchers en -acties

Stats

Om de matchingstatistieken per firewallregel te bekijken, voert u het commando /ip/firewall/filter/print stats uit, of /ipv6/firewall/filter/print stats voor de IPv6-firewall.

Property Description
bytes (integer) De totale hoeveelheid bytes die door de regel is gematcht
packets (integer) De totale hoeveelheid pakketten die door de regel is gematcht
[admin@MikroTik] > ip firewall filter print stats
Flags: X - disabled, I - invalid, D - dynamic
 #    CHAIN                                                                                                                 ACTION                            BYTES         PACKETS
 0  D ;;; special dummy rule to show fasttrack counters
      forward                                                                                                               passthrough              50 507 925 242      50 048 246
 1    ;;; defconf: drop invalid
      forward                                                                                                               drop                            432 270           9 719
 2    ;;; defconf: drop invalid
      input                                                                                                                 drop                            125 943           2 434
 3    input                                                                                                                 accept                   20 090 211 549      20 009 864
 4    ;;; defconf: accept ICMP
      input                                                                                                                 accept                          634 926           7 648
 5    ;;; defconf: drop all not coming from LAN
      input                                                                                                                 drop                          4 288 079          83 428
  6    ;;; defconf: accept in ipsec policy
       forward                                                                                                               accept                                0               0
  7    ;;; defconf: accept out ipsec policy
       forward                                                                                                               accept                                0               0
  8    ;;; defconf: fasttrack
       forward                                                                                                               fasttrack-connection     28 505 528 775      31 504 682
  9    ;;; defconf: accept established,related, untracked
       forward                                                                                                               accept                   28 505 528 775      31 504 682
 10    ;;; defconf: drop all from WAN not DSTNATed
      forward                                                                                                               drop                                  0               0

Statistiekparameters kunnen met de volgende commando's worden gereset:

Command Description
reset-counters (id) Zet de statistiektellers terug op nul voor een specifieke firewallregel of een lijst met regels.
reset-counters-all Zet de statistiektellers terug op nul voor alle firewallregels in de tabel.

Andere nuttige commando's

Standaard is print gelijk aan print static en toont het alleen statische regels.

Om ook dynamische regels af te drukken, gebruikt u print all.

Of gebruik print dynamic om alleen dynamische regels af te drukken.

Matchers

Matchers worden in een specifieke volgorde uitgevoerd.

Voor IPv4

  • Bron-MAC-adres
  • In/Out interfaces
  • In/Out interface lists
  • IP-bereik
  • Adrestype
  • Adreslijst
  • TTL
  • DSCP
  • Length
  • TLS
  • IPv4-opties
  • Dst Port
  • Src Port
  • Elke poort
  • TCP Options
  • TCP MSS
  • ICMP-codes
  • Ingress Priority
  • Priority
  • Packet Mark
  • Realm (routeringstabel)
  • Hotspot
  • Connection Mark
  • Connection State
  • Connection NAT State
  • Connection Bytes
  • Connection Limit
  • Connection Rate
  • IPsec Policy
  • Helper
  • String (inhoud)
  • PSD
  • Layer7
  • Random
  • Nth
  • PCC
  • Limit
  • Dst Limit
  • Log

Voor IPv6

  • Adrestype
  • Adreslijst
  • Bron-MAC-adres
  • In/Out interfaces
  • In/Out interface lists
  • Hop Limit
  • DSCP
  • Length
  • TLS
  • IPv6-header
  • Dst Port
  • Src Port
  • Elke poort
  • TCP Options
  • TCP MSS
  • ICMPv6-codes
  • Ingress Priority
  • Priority
  • Packet Mark
  • Connection Mark
  • Connection State
  • Connection NAT State
  • Connection Bytes
  • Connection Limit
  • Connection Rate
  • IPsec Policy
  • Helper
  • Match String (content)
  • Random
  • Nth
  • PCC
  • Limit
  • Dst Limit
  • Log

Bron

Bijgewerkt op 2026-08-22.