Hi All,
I am currently suffering on port forwarding with my new mikrotik hex s. My setup looks like this:
Internet -- TELEKOM Router -- Mikrotik hEX S -- LAN
The TELEKOM Router has a port forward setup. I am looking (just as example) 1 port here. 8291, I would like to reach the Router from the internet via WinBox. I know this is abs. dangerous, i am aware of that. This is just an example. (currently i am not able to do it
so thus I do not want to proceed to even more ports) The TELEKOM Router gives fix IP via DHCP to Mikrotik 192.168.1.10, that is my WAN side.
Here is the firewall filter print as of now:
[user@hEX S FENN] > /ip firewall filter print
Flags: D - DYNAMIC
0 D ;;; special dummy rule to show fasttrack counters
chain=forward action=passthrough
1 ;;; mikrotik internet remote access -- NO CLUE WHERE TO PLACE
chain=forward action=accept connection-nat-state=dstnat protocol=tcp src-port=8291 log=no log-prefix=""
2 ;;; from default rule -- accept established, related, untracked
chain=input action=accept connection-state=established,related,untracked log=no log-prefix=""
3 ;;; from default rule -- drop invalid
chain=input action=drop connection-state=invalid log=no log-prefix=""
4 ;;; from default rule -- accept ICMP
chain=input action=accept protocol=icmp log=no log-prefix=""
5 ;;; from default rule -- accept to local loopback (for CAPsMAN)
chain=input action=accept dst-address=127.0.0.1 log=no log-prefix=""
6 ;;; from default rule -- drop all not coming from LAN
chain=input action=drop in-interface=!LAN log=no log-prefix=""
7 ;;; from default rule -- accept in ipsec policy
chain=forward action=accept log=no log-prefix="" ipsec-policy=in,ipsec
8 ;;; from default rule -- accept out ipsec policy
chain=forward action=accept log=no log-prefix="" ipsec-policy=out,ipsec
9 ;;; from default rule -- fasttrack
chain=forward action=fasttrack-connection connection-state=established,related log=no log-prefix=""
10 ;;; from default rule -- accept established, related, untracked
chain=forward action=accept connection-state=established,related,untracked log=no log-prefix=""
11 ;;; from default rule -- drop invalid
chain=forward action=drop connection-state=invalid log=no log-prefix=""
12 ;;; from default rule -- drop all from WAN not DSTNATed
chain=forward action=drop connection-state=new connection-nat-state=!dstnat in-interface=ether1[WAN] log=no log-prefix="
"
rule #1 and #12 are from a mikrotik forum, while the rest, i tried to replicate the Mikrotik firewall demo video in youtube and also read some help in the forum here, I hope i captured it correctly.
I expect rule #1 to be able to handle my request and pass the port (I also moved it to the very first place), but it does not do it
The only way to get this done and working is when I am disabling rule #6 (drop all not coming from LAN). This is kind of drives me now crazy, because I cannot figure out what i am overlooking in the filtering section. Obviously I do not want to deactivate rule #6.
I would like to do at the end portforwarding (proper way) for my Xbox, where I know exactly the ports I need, but if I am unable to configure 1 single port, I am not going to play with 5-7 different one ![]()
Does anybody see the trouble why the Rule #1 does not allow access on that port?
I also did some NAT for this, but i tested it, it does not make a difference (assuming NAT portforwarding will be needed for Xbox, as the device is sitting in my LAN side x.x.2.110, however the mikrotik router itself is x.x.2.1, and the TELEKOM Router already opened the 8291 for it, so here I am really looking JUST a filtering rule to pass 8291)
Many thanks for any help on the topic!