Local site:
WAN: something.sn.mynetname.net
LAN: 192.168.77.1/24
VPN: 10.10.10.1
/ip firewall nat
add action=masquerade chain=srcnat
add action=dst-nat chain=dstnat comment=NVR port forward dst-port=6060 protocol=tcp to-addresses=192.168.10.102 to-ports=6060
[admin@MikroTik] /ppp active> print
Flags: R - radius
# NAME SERVICE CALLER-ID ADDRESS UPTIME ENCODING
4 laguna sstp 191.xxx.xxx.xxx 10.10.10.2 1h45m25s AES256-CBC
[admin@MikroTik] /ip route> print
Flags: X - disabled, A - active, D - dynamic, C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme, B - blackhole, U - unreachable, P - prohibit
# DST-ADDRESS PREF-SRC GATEWAY DISTANCE
0 ADS 0.0.0.0/0 190.xxx.xxx.xxx 1
3 ADC 10.10.10.2/32 10.10.10.1 <sstp-laguna> 0
11 ADS 192.168.10.0/24 <sstp-laguna> 1
15 ADC 192.168.77.0/24 192.168.77.1 bridge2 0
Remote site:
LAN: 192.168.10.1/24
VPN: 10.10.10.2
NVR: 192.168.10.102 listening at port 6060
[admin@MikroTik Laguna] /ip route> print
Flags: X - disabled, A - active, D - dynamic,
C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme,
B - blackhole, U - unreachable, P - prohibit
# DST-ADDRESS PREF-SRC GATEWAY DISTANCE
0 ADS 0.0.0.0/0 192.168.8.1 1
1 ADC 10.10.10.1/32 10.10.10.2 vpn sopro 0
2 A S 172.16.0.0/24 192.168.10.102 1
3 ADC 192.168.8.0/24 192.168.8.100 ether1 0
4 ADC 192.168.10.0/24 192.168.10.1 bridge2 0
[admin@MikroTik Laguna] /ip firewall connection> print
Flags: E - expected, S - seen-reply, A - assured, C - confirmed, D - dying,
F - fasttrack, s - srcnat, d - dstnat
# PR.. SRC-ADDRESS DST-ADDRESS TCP-STATE
309 SAC s tcp 10.10.10.1:35558 192.168.10.102:6060 close
323 SAC s tcp 10.10.10.1:43726 192.168.10.102:6060 close
[admin@MikroTik Laguna] /ip firewall connection> print detail
Flags: E - expected, S - seen-reply, A - assured, C - confirmed, D - dying, F - fasttrack, s - srcnat, d - dstnat
0 SAC protocol=tcp src-address=192.168.8.100:39045 dst-address=190.45.xxx.xxx:443 reply-src-address=190.45.xxx.xxx:443 reply-dst-address=192.168.8.100:39045
tcp-state=established timeout=4m59s orig-packets=4 729 orig-bytes=3 532 945 orig-fasttrack-packets=0 orig-fasttrack-bytes=0 repl-packets=4 165
repl-bytes=590 509 repl-fasttrack-packets=0 repl-fasttrack-bytes=0 orig-rate=152.4kbps repl-rate=37.9kbps
1 SAC protocol=tcp src-address=10.10.10.1:51829 dst-address=192.168.10.1:8291 reply-src-address=192.168.10.1:8291 reply-dst-address=10.10.10.1:51829
tcp-state=established timeout=4m59s connection-mark="VPN_SoPro" orig-packets=24 171 orig-bytes=1 570 375 orig-fasttrack-packets=0 orig-fasttrack-bytes=0
repl-packets=30 750 repl-bytes=34 311 553 repl-fasttrack-packets=0 repl-fasttrack-bytes=0 orig-rate=13.2kbps repl-rate=141.5kbps
6 SAC s protocol=tcp src-address=10.10.10.1:27312 dst-address=192.168.10.102:6060 reply-src-address=192.168.10.102:6060 reply-dst-address=192.168.10.1:27312
tcp-state=close timeout=4s connection-mark="VPN_SoPro" orig-packets=10 orig-bytes=896 orig-fasttrack-packets=0 orig-fasttrack-bytes=0 repl-packets=6
repl-bytes=600 repl-fasttrack-packets=0 repl-fasttrack-bytes=0 orig-rate=0bps repl-rate=0bps
13 S C s protocol=udp src-address=192.168.10.102:30008 dst-address=54.165.xx.xxx:3478 reply-src-address=54.165.xx.xxx:3478 reply-dst-address=192.168.8.100:30008
timeout=7s orig-packets=1 orig-bytes=56 orig-fasttrack-packets=0 orig-fasttrack-bytes=0 repl-packets=1 repl-bytes=116 repl-fasttrack-packets=0
repl-fasttrack-bytes=0 orig-rate=0bps repl-rate=0bps
14 S C s protocol=udp src-address=192.168.10.102:30006 dst-address=54.165.xx.xxx:3478 reply-src-address=54.165.xx.xxx:3478 reply-dst-address=192.168.8.100:30006
timeout=7s orig-packets=1 orig-bytes=56 orig-fasttrack-packets=0 orig-fasttrack-bytes=0 repl-packets=1 repl-bytes=116 repl-fasttrack-packets=0
repl-fasttrack-bytes=0 orig-rate=0bps repl-rate=0bps
21 SAC s protocol=tcp src-address=10.10.10.1:19507 dst-address=192.168.10.102:6060 reply-src-address=192.168.10.102:6060 reply-dst-address=192.168.10.1:19507
tcp-state=established timeout=23h59m59s connection-mark="VPN_SoPro" orig-packets=4 orig-bytes=340 orig-fasttrack-packets=0 orig-fasttrack-bytes=0
repl-packets=3 repl-bytes=300 repl-fasttrack-packets=0 repl-fasttrack-bytes=0 orig-rate=0bps repl-rate=0bps