$wgDBname<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://www.cablefree.net/support/radio/software/index.php?action=history&amp;feed=atom&amp;title=Manual%3AIP%2FFirewall%2FConnection_tracking</id>
	<title>Manual:IP/Firewall/Connection tracking - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://www.cablefree.net/support/radio/software/index.php?action=history&amp;feed=atom&amp;title=Manual%3AIP%2FFirewall%2FConnection_tracking"/>
	<link rel="alternate" type="text/html" href="https://www.cablefree.net/support/radio/software/index.php?title=Manual:IP/Firewall/Connection_tracking&amp;action=history"/>
	<updated>2026-06-04T18:45:23Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.37.3</generator>
	<entry>
		<id>https://www.cablefree.net/support/radio/software/index.php?title=Manual:IP/Firewall/Connection_tracking&amp;diff=200&amp;oldid=prev</id>
		<title>Administrator: Created page with &quot;__TOC__  ==Connection tracking entries==  &lt;p id=&quot;shbox&quot;&gt;&lt;b&gt;Sub-menu:&lt;/b&gt; &lt;code&gt;/ip firewall connection&lt;/code&gt;&lt;/p&gt;   There are several ways to see what connections are making t...&quot;</title>
		<link rel="alternate" type="text/html" href="https://www.cablefree.net/support/radio/software/index.php?title=Manual:IP/Firewall/Connection_tracking&amp;diff=200&amp;oldid=prev"/>
		<updated>2015-01-29T11:54:20Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;__TOC__  ==Connection tracking entries==  &amp;lt;p id=&amp;quot;shbox&amp;quot;&amp;gt;&amp;lt;b&amp;gt;Sub-menu:&amp;lt;/b&amp;gt; &amp;lt;code&amp;gt;/ip firewall connection&amp;lt;/code&amp;gt;&amp;lt;/p&amp;gt;   There are several ways to see what connections are making t...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;__TOC__&lt;br /&gt;
&lt;br /&gt;
==Connection tracking entries==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p id=&amp;quot;shbox&amp;quot;&amp;gt;&amp;lt;b&amp;gt;Sub-menu:&amp;lt;/b&amp;gt; &amp;lt;code&amp;gt;/ip firewall connection&amp;lt;/code&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
There are several ways to see what connections are making their way though the router. &lt;br /&gt;
&lt;br /&gt;
In the Winbox Firewall window, you can switch to the Connections tab, to see current connections to/from/through your router. It looks like this: &lt;br /&gt;
&lt;br /&gt;
[[Image:2009-01-26 1346.jpg]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Properties ===&lt;br /&gt;
&lt;br /&gt;
All properties in connection list are read-only&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table-h&lt;br /&gt;
|prop=Property&lt;br /&gt;
|desc=Description&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=seen reply&lt;br /&gt;
|type=yes {{!}} no&lt;br /&gt;
|desc=&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=assured&lt;br /&gt;
|type=yes {{!}} no&lt;br /&gt;
|desc=&amp;quot;assured&amp;quot; flag indicates that this connection is assured and that it will not be erased if maximum possible tracked connection count is reached.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=connection-mark&lt;br /&gt;
|type=string&lt;br /&gt;
|desc=connection mark set by [[M:IP/Firewall/Mangle | mangle]] rule.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=connection-type&lt;br /&gt;
|type=pptp {{!}} ftp {{!}} p2p&lt;br /&gt;
|desc=Type of connection, property is empty if connection tracking is unable to determine predefined connection type.&lt;br /&gt;
}} &lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=dst-address&lt;br /&gt;
|type=ip[:port]&lt;br /&gt;
|desc=Destination address and port (if protocol is port based).&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=gre-key&lt;br /&gt;
|type=integer&lt;br /&gt;
|desc=&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=gre-version&lt;br /&gt;
|type=string&lt;br /&gt;
|desc=&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=icmp-code&lt;br /&gt;
|type=string&lt;br /&gt;
|desc=&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=icmp-id&lt;br /&gt;
|type=string&lt;br /&gt;
|desc=&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=icmp-type&lt;br /&gt;
|type=string&lt;br /&gt;
|desc=&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=p2p&lt;br /&gt;
|type=yes {{!}} no&lt;br /&gt;
|desc=Shows if connection is identified as p2p by firewall p2p matcher.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=protocol&lt;br /&gt;
|type=string&lt;br /&gt;
|desc=IP protocol type&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=reply-dst-address&lt;br /&gt;
|type=ip[:port]&lt;br /&gt;
|desc=Destination address (and port) expected of return packets. Usually the same as &amp;quot;src-address:port&amp;quot;&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=reply-src-address&lt;br /&gt;
|type=ip[:port]&lt;br /&gt;
|desc=Source address (and port) expected of return packets. Usually the same as &amp;quot;dst-address:port&amp;quot;&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=src-address&lt;br /&gt;
|type=ip[:port]&lt;br /&gt;
|desc=Source address and port (if protocol is port based).&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=tcp-state&lt;br /&gt;
|type=string&lt;br /&gt;
|desc=Current state of TCP connection :&lt;br /&gt;
* &amp;quot;established&amp;quot;&lt;br /&gt;
* &amp;quot;time-wait&amp;quot;&lt;br /&gt;
* &amp;quot;close&amp;quot;&lt;br /&gt;
* &amp;quot;syn-sent&amp;quot; &lt;br /&gt;
* &amp;quot;syn-received&amp;quot;&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table-end&lt;br /&gt;
|arg=timeout&lt;br /&gt;
|type=time&lt;br /&gt;
|desc=Time after connection will be removed from connection list.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
==Connection tracking settings==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p id=&amp;quot;shbox&amp;quot;&amp;gt;&amp;lt;b&amp;gt;Sub-menu:&amp;lt;/b&amp;gt; &amp;lt;code&amp;gt;/ip firewall connection tracking&amp;lt;/code&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Properties===&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table-h&lt;br /&gt;
|prop=Property&lt;br /&gt;
|desc=Description&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=enabled&lt;br /&gt;
|type=yes {{!}} no {{!}} auto&lt;br /&gt;
|default=auto&lt;br /&gt;
|desc=Allows to disable or enable connection tracking. Disabling connection tracking will cause several firewall features to stop working. See the [[#Features affected by connection tracking | list]] of affected features. Starting from v6.0rc2 default value is auto. Which means that connection tracing is disabled until at least one firewall rule is added.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=tcp-syn-sent-timeout&lt;br /&gt;
|type=time&lt;br /&gt;
|default=5s&lt;br /&gt;
|desc=TCP SYN timeout.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=tcp-syn-received-timeout&lt;br /&gt;
|type=time&lt;br /&gt;
|default=5s&lt;br /&gt;
|desc=TCP SYN timeout.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=tcp-established-timeout&lt;br /&gt;
|type=time&lt;br /&gt;
|default=1d&lt;br /&gt;
|desc=Time when established TCP connection times out.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=tcp-fin-wait-timeout&lt;br /&gt;
|type=time&lt;br /&gt;
|default=10s&lt;br /&gt;
|desc=&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=tcp-close-wait-timeout&lt;br /&gt;
|type=time&lt;br /&gt;
|default=10s&lt;br /&gt;
|desc=&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=tcp-last-ack-timeout&lt;br /&gt;
|type=time&lt;br /&gt;
|default=10s&lt;br /&gt;
|desc=&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=tcp-time-wait-timeout&lt;br /&gt;
|type=time&lt;br /&gt;
|default=10s&lt;br /&gt;
|desc=&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=tcp-close-timeout&lt;br /&gt;
|type=time&lt;br /&gt;
|default=10s&lt;br /&gt;
|desc=&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=udp-timeout&lt;br /&gt;
|type=time&lt;br /&gt;
|default=10s&lt;br /&gt;
|desc=&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=udp-stream-timeout&lt;br /&gt;
|type=time&lt;br /&gt;
|default=3m&lt;br /&gt;
|desc=&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table&lt;br /&gt;
|arg=icmp-timeout&lt;br /&gt;
|type=time&lt;br /&gt;
|default=10s&lt;br /&gt;
|desc=&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-table-end&lt;br /&gt;
|arg=generic-timeout&lt;br /&gt;
|type=time&lt;br /&gt;
|default=10m&lt;br /&gt;
|desc=Timeout for all other connection entries&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Read-only properties&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
{{Mr-arg-table-h&lt;br /&gt;
|prop=Property&lt;br /&gt;
|desc=Description&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table&lt;br /&gt;
|arg=max-entries&lt;br /&gt;
|type=integer&lt;br /&gt;
|desc=Max amount of entries that connection tracking table can hold. This value depends on installed amount of RAM. Note that system does not create maximum size connection tracking table when it starts, maximum entry amount can increase if situation demands it and router still has free ram left.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Mr-arg-ro-table-end&lt;br /&gt;
|arg=total-entries&lt;br /&gt;
|type=integer&lt;br /&gt;
|desc=Amount of connections that currently connection table holds.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
==Features affected by connection tracking== &lt;br /&gt;
&lt;br /&gt;
* NAT&lt;br /&gt;
* firewall:&lt;br /&gt;
** connection-bytes&lt;br /&gt;
** connection-mark&lt;br /&gt;
** connection-type&lt;br /&gt;
** connection-state&lt;br /&gt;
** connection-limit&lt;br /&gt;
** connection-rate&lt;br /&gt;
** layer7-protocol&lt;br /&gt;
** p2p&lt;br /&gt;
** new-connection-mark&lt;br /&gt;
** tarpit&lt;br /&gt;
* p2p matching in simple queues&lt;br /&gt;
&lt;br /&gt;
[[Category:Manual|Connection tracking]]&lt;br /&gt;
[[Category:IP|Connection tracking]]&lt;br /&gt;
[[Category:Firewall|Connection tracking]]&lt;/div&gt;</summary>
		<author><name>Administrator</name></author>
	</entry>
</feed>