Firewall filter / Port forwarding

Hi All,

I am currently suffering on port forwarding with my new mikrotik hex s. My setup looks like this:

Internet -- TELEKOM Router -- Mikrotik hEX S -- LAN

The TELEKOM Router has a port forward setup. I am looking (just as example) 1 port here. 8291, I would like to reach the Router from the internet via WinBox. I know this is abs. dangerous, i am aware of that. This is just an example. (currently i am not able to do it :smiley: so thus I do not want to proceed to even more ports) The TELEKOM Router gives fix IP via DHCP to Mikrotik 192.168.1.10, that is my WAN side.

Here is the firewall filter print as of now:

[user@hEX S FENN] > /ip firewall filter  print
Flags: D - DYNAMIC
0 D ;;; special dummy rule to show fasttrack counters
chain=forward action=passthrough

1   ;;; mikrotik internet remote access -- NO CLUE WHERE TO PLACE
chain=forward action=accept connection-nat-state=dstnat protocol=tcp src-port=8291 log=no log-prefix=""

2   ;;; from default rule -- accept established, related, untracked
chain=input action=accept connection-state=established,related,untracked log=no log-prefix=""

3   ;;; from default rule -- drop invalid
chain=input action=drop connection-state=invalid log=no log-prefix=""

4   ;;; from default rule -- accept ICMP
chain=input action=accept protocol=icmp log=no log-prefix=""

5   ;;; from default rule -- accept to local loopback (for CAPsMAN)
chain=input action=accept dst-address=127.0.0.1 log=no log-prefix=""

6   ;;; from default rule -- drop all not coming from LAN
chain=input action=drop in-interface=!LAN log=no log-prefix=""

7   ;;; from default rule -- accept in ipsec policy
chain=forward action=accept log=no log-prefix="" ipsec-policy=in,ipsec

8   ;;; from default rule -- accept out ipsec policy
chain=forward action=accept log=no log-prefix="" ipsec-policy=out,ipsec

9   ;;; from default rule -- fasttrack
chain=forward action=fasttrack-connection connection-state=established,related log=no log-prefix=""

10   ;;; from default rule -- accept established, related, untracked
chain=forward action=accept connection-state=established,related,untracked log=no log-prefix=""

11   ;;; from default rule -- drop invalid
chain=forward action=drop connection-state=invalid log=no log-prefix=""

12   ;;; from default rule -- drop all from WAN not DSTNATed
chain=forward action=drop connection-state=new connection-nat-state=!dstnat in-interface=ether1[WAN] log=no log-prefix="
"

rule #1 and #12 are from a mikrotik forum, while the rest, i tried to replicate the Mikrotik firewall demo video in youtube and also read some help in the forum here, I hope i captured it correctly.

I expect rule #1 to be able to handle my request and pass the port (I also moved it to the very first place), but it does not do it :frowning: The only way to get this done and working is when I am disabling rule #6 (drop all not coming from LAN). This is kind of drives me now crazy, because I cannot figure out what i am overlooking in the filtering section. Obviously I do not want to deactivate rule #6.

I would like to do at the end portforwarding (proper way) for my Xbox, where I know exactly the ports I need, but if I am unable to configure 1 single port, I am not going to play with 5-7 different one :smiley:

Does anybody see the trouble why the Rule #1 does not allow access on that port?

I also did some NAT for this, but i tested it, it does not make a difference (assuming NAT portforwarding will be needed for Xbox, as the device is sitting in my LAN side x.x.2.110, however the mikrotik router itself is x.x.2.1, and the TELEKOM Router already opened the 8291 for it, so here I am really looking JUST a filtering rule to pass 8291)

Many thanks for any help on the topic!

Oh boy, port 8291 open from the outside ... there are several reasons why that is a genuinely BAD idea ...
Clearly you have not being following the recent outbreak of discussions as a result from release of several new ROS versions because of security fixes.

So actually what you want to do at the end is have your XBOX exposed from the outside ?
Equally bad idea, if you ask me.

You need to explain more what you want to do and WHY.

As for your problem ... you give as an example port 8291.
Let's assume it's a fantastic idea and we continue there.
Which means you try to get access to your router from the outside. Right ?
OK ... and for your router, what type of traffic would that be ?
Hint: it's not forward...

Towards your XBOX it will end up as being forward but not for your router.

Here is the updated RULE #1 which works:

1 X ;;; mikrotik internet remote access -- DO NOT LET IT ON ! JUST TEST
chain=input action=accept protocol=tcp in-interface=ether1[WAN] dst-port=8291 log=yes log-prefix="PORTFORWARD"

I also disabled the TELEKOM Router port forward, and checked with portchecker, 8291 is not anymore open.

I know, I know :slight_smile: However this is something which I am NOT GOING TO KEEP ENABLE!

So what I did on my own :slight_smile: I enabled logging on RULE 1 and RULE 6 and tried to figure out why it fails. I found out that my src-port was wrong, so i changed that to dst-port.

Furthermore you are right, after saying it out loud and reading 2 more times the mikrotik user manual, I decided to change it to INPUT. and now it works so I am happy... (i already disabled it :smiley: )

On the XBOX SIDE: so there is this connection type NAT, can be Open, Moderate and Strickt.

I try to reach Open, and all I got is Moderate. Here are the PORTS which according to XBOX i need to open: https://support.xbox.com/en-US/help/hardware-network/connect-network/network-ports-used-xbox-live

Right now same as the original 8291, I am trying to somehow resolve 3074 TCP UDP. Once I know how to do 3074, i can do the rest. But unfortunately 3074 is closed at the moment so I need to figure out what else do I need to do or what I am doing wrong in the NAT table.

Since I learned logging before, I added logging in the NAT and FILTER side, and as said in the Mikrotik user manual the DSTNAT will go sooner than the FILTER, so I should be good, but somehow still not working.

Here is a print from the firewall nat side:

[user@hEX S FENN] > ip firewall nat print
Flags: X - DISABLED; D - DYNAMIC
0     ;;; LAN to INTERNET
chain=srcnat action=masquerade out-interface=ether1[WAN] log=no log-prefix=""

1     ;;; XBOX 3074 TCP
chain=dstnat action=dst-nat to-addresses=192.168.2.110 to-ports=3074 protocol=tcp in-interface=ether1[WAN] dst-port=3074 log=yes log-prefix="NAT-TCP3074"

2     ;;; XBOX 3074 UDP
chain=dstnat action=dst-nat to-addresses=192.168.2.110 to-ports=3074 protocol=udp in-interface=ether1[WAN] dst-port=3074 log=yes log-prefix="NAT-UDP3074"

3     ;;; XBOX 88 UDP
chain=dstnat action=dst-nat to-addresses=192.168.2.110 to-ports=88 protocol=udp in-interface=ether1[WAN] dst-port=88 log=no log-prefix=""

4     ;;; XBOX 53 UDP
chain=dstnat action=dst-nat to-addresses=192.168.2.110 to-ports=53 protocol=udp in-interface=ether1[WAN] dst-port=53 log=no log-prefix=""

5     ;;; XBOX 500 UDP
chain=dstnat action=dst-nat to-addresses=192.168.2.110 to-ports=500 protocol=udp in-interface=ether1[WAN] dst-port=500 log=no log-prefix=""

6     ;;; XBOX 3544 UDP
chain=dstnat action=dst-nat to-addresses=192.168.2.110 to-ports=3544 protocol=udp in-interface=ether1[WAN] dst-port=3544 log=no log-prefix=""

7     ;;; XBOX 4500 UDP
chain=dstnat action=dst-nat to-addresses=192.168.2.110 to-ports=4500 protocol=udp in-interface=ether1[WAN] dst-port=4500 log=no log-prefix=""

8     ;;; XBOX 9002 UDP
chain=dstnat action=dst-nat to-addresses=192.168.2.110 to-ports=9002 protocol=udp in-interface=ether1[WAN] dst-port=9002 log=no log-prefix=""

9     ;;; XBOX 53 TCP
chain=dstnat action=dst-nat to-addresses=192.168.2.110 to-ports=53 protocol=tcp in-interface=ether1[WAN] dst-port=53 log=no log-prefix=""

10     ;;; XBOX 80 TCP
chain=dstnat action=dst-nat to-addresses=192.168.2.110 to-ports=80 protocol=tcp in-interface=ether1[WAN] dst-port=80 log=no log-prefix=""


I hope this helps. I am currently working on RULE #1 and RULE #2.

Thanks for the advice !

They should cut off your internet connection for life.

Basically, it takes mere seconds to get infected in this day and age...........
The best thing you can do is netsintall your router to 7.24.2
Then come back for guidance.
First, the default rules out of the box are safe.
In your first attempts, you completely blew that safety away.

Second, running a server for a few friends I suppose?
Consider running wireguard or zerotier so that your friends can get to your router safely and then access the game server. Bit more work up front but much safer.
Cloudflare zero trust makes a setup exactly for this but sadly MT, added zerotier as a package but not ZeroTrust. You could run it in a container but alas I suspect the complexity is high and the throughput probably less than satisfactory.

Lastly, there should be no need to open up ports as the router these days has advanced past basic UPNP for port control and trying to get around TYPE OF NAT requirements. Im not aware of how to but I believe its possible.

Check out NAT endpoint-independent-nat

and this link;

What?

Then come back and get infected again. :rofl: Finally upgrade to 7.24.2.

Twas a typo fellas, take an enema

I see some hard comments but please understand the following things.

I am using (or I hope :smiley: ) the default set of firewall rules on top I try some things around as experience as Mikrotik and winbox is new to me. Of course I want to do it right and I am going to read also the extra links. I was aware of the upnp however I wanted to try out what MS is suggesting for Xbox open NAT.

Some things not working which I do not understand yet why and therefore I need a little bit of help. I do see them also as risk yes, but I see it more like a calculated risk rather then a full newbie thing :slight_smile:

At the end when I finish I want to protect my router my LAN the best way as I could. Yes there will be wire guard as well and VLAN but I am not there yet I am learning it. :slight_smile:

I hope it make sense even if it does not. As said as experience and for real life :slight_smile: and thank you all comments and guidance, really I need some :slight_smile:

I do appreciate the comment. Can you please easily explain to me why? Am I really making a huge mistake here?

Thank you!

You refer the 8291 port ? Or the Xbox NAT setup? Can you please help me a bit more ?

I assume you refer the 8291 thing :wink:

Hi,

yesterday i tested the xbox and with UPNP it is working, I am also getting moderate sometimes open NAT as message from XBOX.

Now I would like to proceed with my example and experience however I do not know, why this is not working.

In the NAT table I have this rule:

1 ;;; XBOX 3074 TCP
chain=dstnat action=dst-nat to-addresses=192.168.2.110 to-ports=3074 protocol=tcp dst-address=192.168.1.10 in-interface=ether1[WAN] dst-port=3074 log=yes
log-prefix="NAT-TCP3074"

I read the link what you gave me: NAT | RouterOS Manual for me sounds like this is dst-nat and correctly configured as in the example picture...

Here is the example:



/ip/firewall/nat/add chain=dstnat action=dst-nat dst-address=172.16.16.1 dst-port=22 to-addresses=10.0.0.3 protocol=tcp

but when I try it with port checker, i get the message port is closed. Do you have an idea what I am missing here?

XBOX IP: 192.168.2.110

Mikrotik WAN IP: 192.168.1.10 --> given by TELEKOM Router sitting on 192.168.1.1. Ports are open in the Telekom Router, so no further task there.

Mikrotik LOG:



NAT-TCP3074 dstnat: in:ether1[WAN] out:(unknown 0), connection-state:new src-mac BC:3A:29:44:4F:A8, proto TCP (SYN), 45.33.50.110:51450->192.168.1.10:3074, len 60

Thank you for your feedback!

Basically, you're on the right track.

Your log message shows that your dst-nat rule is applied. It's critical that the last "drop all from WAN not dstnat-ed" rule still has the connection-state=!dstnat part intact.

Beyond that, something other than your port forwarding is likely to be the culprit.

Are you sure that port 3074 is actually open on the xbox? Can you try it with another device where you can be sure the given port is open?

What sort of "port checker" are you using? Does it have a different output for "connection refused" (i.e. the TCP SYN is replied to with an RST) and firewalled/filtered (no reply)?

If the port checker is something Xbox- or game-specific, does it only check the single TCP port, or might is also check others?

If the Xbox is set up for uPnP, are you sure that it does not alter the port(s) it listens on?

Ahhh... OK so reading this it seems to be I need to rethink, how can I really check if a port is open or not.

Regarding port scanner i gave it to google and i use this: https://portchecker.co/ and https://dnschecker.org/port-scanner.php on the specific TCP port this comes from the MS Xbox series X manual: https://support.xbox.com/en-US/help/hardware-network/connect-network/network-ports-used-xbox-live and there you will find much more.

Some things for me to consider in the future:

  1. i thought if I open up a port on TELEKOM and Mikrotik the port is generically open no matter if Xbox is running or not. Seems to be this is not the case, so I might need to wait until Xbox really uses 3074 via TCP to see if this is working. (Referring back to the Xbox manual, you see how many ports they want via TCP and UDP to "be NAT OPEN", there is no way I can test all of those :slight_smile: )

  2. currently I see in the NAT table a dynamic UPNP port open as soon as I start the XBOX, therefore I assume XBOX does this on its own now and I do not need to setup NATs 1by1. As also indicated by @anav in his earlier post. I still need to read the full cone NAT link to check in detailed what is happening there.

  3. i will give a try on a port which I know to see if the NAT port forward works, but I will get rid of all of those NAT rules if they are useless because the Xbox is doing its thing on another port "on demand". At the very last step I plan to move the xbox to a separate subnet, give a VLAN to it and then it is separated from my LAN, giving the LAN more security.

Thanks !

The log message verifies that your port forward is working. (There may still be a typo somewhere, etc., but it's at least logically correct.)

As to your point 1.: No. Forwarding just means that the packets are forwarded. The scanner only detects it as "open" if a TCP connection is actually accepted. If the listening device is not present or doesn't accept the connection, you won't get "open".

To your point 2., I would recommend manual forwarding. Maybe I'm just old school, but that's what is the most secure and most reliable. Full cone NAT is not something I would recommend for you.

I have verified that your first linked scanner (https://portchecker.co/) is sort of useless, but the second one (https://dnschecker.org/port-scanner.php) is actually useful. Using this, you will get "Timed out" if you port forwarding is incorrect or the Xbox is off/not connected. You'll only get "Closed" if the connection is actively refused (SYN->RST) - this indicates that the forwarding is correct and the target device refuses the connection.

As to having to forward a daunting number of ports: you don't actually have to specify the to-ports argument, because the default is to leave the port number unchanged. If you do this, you can specify a list of ports for dst-port, as in: 21,22,23. (Also. port ranges are accepted as well.)