Exam MTCNA Topic 3 Question 153 Discussion
Actual exam question for MikroTik's MTCNA exam
Question #: 153
Topic #: 3
Question #: 153
Topic #: 3
If you wish to block user access to MSN messenger, which chain should the firewall rule be placed in?
Suggested Answer: C Vote an answer
In MikroTik's firewall, the correct chain depends on the traffic direction and whether the traffic is destined for or originating from the router itself.
To block access to MSN (or any other service being accessed by a user from the LAN to the Internet), you must filter transit traffic. This is done in the forward chain.
* A. input # Used for traffic destined to the router (e.g., WinBox, SSH).
* B.#process # Invalid option (does not exist in RouterOS).
* C.#forward # Used for user traffic passing through the router (e.g., LAN client to MSN servers on the Internet).
* D. output # Used for traffic originating from the router itself (e.g., ping from router to external IP).
Extract from Official MTCNA Course Material - Firewall Chains:
"Use the forward chain to filter traffic passing through the router (LAN to WAN). Blocking access to external services like Facebook or MSN belongs here." Extract from Rene Meneses MTCNA Study Guide - Firewall Chains:
"To block Internet services for users, configure rules in the forward chain. Input is only for traffic targeting the router." Extract from MikroTik Wiki - Firewall Overview:
"forward: filters all traffic going through the router. For user access restrictions, place rules here."
To block access to MSN (or any other service being accessed by a user from the LAN to the Internet), you must filter transit traffic. This is done in the forward chain.
* A. input # Used for traffic destined to the router (e.g., WinBox, SSH).
* B.#process # Invalid option (does not exist in RouterOS).
* C.#forward # Used for user traffic passing through the router (e.g., LAN client to MSN servers on the Internet).
* D. output # Used for traffic originating from the router itself (e.g., ping from router to external IP).
Extract from Official MTCNA Course Material - Firewall Chains:
"Use the forward chain to filter traffic passing through the router (LAN to WAN). Blocking access to external services like Facebook or MSN belongs here." Extract from Rene Meneses MTCNA Study Guide - Firewall Chains:
"To block Internet services for users, configure rules in the forward chain. Input is only for traffic targeting the router." Extract from MikroTik Wiki - Firewall Overview:
"forward: filters all traffic going through the router. For user access restrictions, place rules here."
by Prima at Oct 01, 2026, 12:55 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).