Hi. I'm using ROS 6.1 at RB450G in failover multiwan configuration, where NAT from primary channel performed out of the MT device and NAT for spare channel works with
chain=srcnat action=masquerade to-addresses=0.0.0.0 out-interface=wan2
. wan2 interface also terminates road-warrior ipsec setup and SSTP tunnels. Some time after updgraded 5.24 to 6.1 I noticed that spare channel doesn't work for lan while ping from device itself through that channel works fine. I investigated the issue and disovered that mikrotik device does NAT, but when responses from remote IP arrives to mikrotik device I see them at input firewall chain:
19:02:20 firewall,info input: in:wan2 out:(none), src-mac 00:00:2e:d0:11:48, proto ICMP (type 0, code 0), 8.8.8.8->WAN2_IP, len 84
19:02:21 firewall,info input: in:wan2 out:(none), src-mac 00:00:2e:d0:11:48, proto ICMP (type 0, code 0), 8.8.8.8->WAN2_IP, len 84
19:02:22 firewall,info input: in:wan2 out:(none), src-mac 00:00:2e:d0:11:48, proto ICMP (type 0, code 0), 8.8.8.8->WAN2_IP, len 84
I tried to clean firewall rules holding only masquerade rule for wan2, but without of luck.
Can somebody help me to resolve this issue?
Thanks