Exam MTCNA Topic 3 Question 153 Discussion

Actual exam question for MikroTik's MTCNA exam
Question #: 153
Topic #: 3
If you wish to block user access to MSN messenger, which chain should the firewall rule be placed in?

Suggested Answer: C Vote an answer

In MikroTik's firewall, the correct chain depends on the traffic direction and whether the traffic is destined for or originating from the router itself.
To block access to MSN (or any other service being accessed by a user from the LAN to the Internet), you must filter transit traffic. This is done in the forward chain.
* A. input # Used for traffic destined to the router (e.g., WinBox, SSH).
* B.#process # Invalid option (does not exist in RouterOS).
* C.#forward # Used for user traffic passing through the router (e.g., LAN client to MSN servers on the Internet).
* D. output # Used for traffic originating from the router itself (e.g., ping from router to external IP).
Extract from Official MTCNA Course Material - Firewall Chains:
"Use the forward chain to filter traffic passing through the router (LAN to WAN). Blocking access to external services like Facebook or MSN belongs here." Extract from Rene Meneses MTCNA Study Guide - Firewall Chains:
"To block Internet services for users, configure rules in the forward chain. Input is only for traffic targeting the router." Extract from MikroTik Wiki - Firewall Overview:
"forward: filters all traffic going through the router. For user access restrictions, place rules here."

by Prima at Oct 01, 2026, 12:55 AM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10