Hello,
I have strange problem on my x86 mikrotik router/firewall. I have 2 core intel CPU, one intergrated NIC and one 4port mikrotik NIC. All ports except one that is connected to internet are in same bridge.
I have quite few NAT rules and firewall rules, but no mangles.
From time to time few packets miss NAT rule and go to input chain. For example I have dst-nat rule for web server:
chain=dstnat action=dst-nat to-addresses=[internal_ip] protocol=tcp dst-address=[external_ip] dst-port=80
Most of the packets to externap_ip:80 are NATed to internal_ip:80, but I have quite a few packets catched by deny all rule in INPUT chain which should be matched by that NAT rule:
input: in:InetGB out:(none), srv-mac: xx:xx:xx:xx:xx, proto TCP (ACK), some_address:some_port -> external_ip:80, len 52
in proto part of log is TCP(ACK), TCP(ACK, RST) TCP (ACK, FIN) or TCP(SYN).
I currently have rOS 5.0rc8, but I have this exactly issue for at least year (for sure same problem was on rOS 4.xx).
Can anyone please help me?