Community discussions

MikroTik App
 
cp8
newbie
Topic Author
Posts: 26
Joined: Sat Dec 08, 2007 6:46 am

Masqurade and src-nat leaking

Mon Jan 03, 2011 9:11 am

I've got an issue with the firewall leaking private IP addresses to the Internet. Quite regularly I'm seeing packets leave the public interface without the source address being translated. The packets that typically make it through w/o NAT are RST or FIN packets, although not always. Two questions. First, is there any way to create a firewall rule that will match the src address after its been through the src-nat chain?

Second, what could be causing the source address to not be translated?

The firewall rules are quite simple:
/ip firewall nat
add action=masquerade chain=srcnat comment="" disabled=no out-interface=public
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7053
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: Masqurade and src-nat leaking

Mon Jan 03, 2011 9:19 am

Drop invalid packets in firewall.
 
cp8
newbie
Topic Author
Posts: 26
Joined: Sat Dec 08, 2007 6:46 am

Re: Masqurade and src-nat leaking

Mon Jan 03, 2011 9:33 am

Drop invalid packets in firewall.
Duh. Thank you. =) Sometimes you need someone to point out the obvious. I already had a rule to drop invalid connections but it was in the wrong place. Everything is working properly after relocating it.

Who is online

Users browsing this forum: andrewrmack, Bing [Bot], pants6000, sebi099 and 59 guests