Hi.
I'm trying to establish vpn connection to mikrotik, which is available from local network but completely unavailable from outside.
The problem is in several wan interfaces (3 internet providers to be precise).
From inside connections marked randomly, routing is marked, routing decision goes brilliantly and everything goes fine. The same thing goes on forward flow from the outside to the inside way. The problem appears when I connect to Mikrotik itself from outside.
I'm connecting to one of the wan interfaces and Mikrotik answers me from the wrong one.
According to IP Flow diagram (http://mum.mikrotik.com/presentations/2 ... traweb.pdf page 00-12 or 00-15) all I need is to mark routing on output queue and it should be fine but it seems to be ignoring my marking or the diagram is wrong and the routing decision is going before the output queue.
Let's for instance test output queue. Rule: chain=output action=log protocol=icmp - writes in log strings like: output: in:(none) out:wan2, proto ICMP (type 8, code 0), 111.111.111.111->8.8.8.8, len1400.
Doesn't that shows that we already know wan interface ip address on output queue (111.111.111.111)?
Then how can I chose the output interface and tell mikrotik to answer from the precise interface I need?