Hi all,
My LAN is on 192.168.27.0/24 on Ether1 There is a server at 192.168.27.4 that I want to access from LAN, and outside on a random port 21392.
I have 2 ADSL lines which are bonded togeter using PPoE on Ether2 and Ether3
I have put int the src-nat entry as per the wiki but can’t get it to work. Any pointers greatly appreciated?
Thanks!
Here are the NAT Rules
[admin@MikroTik] /ip firewall nat> print
Flags: X - disabled, I - invalid, D - dynamic
0 ;;; CAM incoming
chain=dstnat action=dst-nat to-addresses=192.168.27.4 to-ports=21392
protocol=tcp in-interface=all-ppp dst-port=21392 log=no log-prefix=""
1 ;;; HS3 incoming
chain=dstnat action=dst-nat to-addresses=192.168.27.8 to-ports=44443
protocol=tcp in-interface=all-ppp dst-port=44443 log=yes log-prefix=""
2 ;;; HS3 HSTOUCH incoming
chain=dstnat action=dst-nat to-addresses=192.168.27.8 to-ports=44444
protocol=tcp in-interface=all-ppp dst-port=44444 log=yes log-prefix=""
3 ;;; Hairpin NAT - CAM
chain=srcnat action=masquerade src-address=192.168.27.0/24
dst-address=192.168.27.4 out-interface=ether1-LAN log=no log-prefix=""
4 ;;; Outbound Internet Access
chain=srcnat action=masquerade out-interface=all-ppp log=no
log-prefix=""
[admin@MikroTik] /ip firewall nat>
Here are Firewall filter rules
[admin@MikroTik] /ip firewall filter> print
Flags: X - disabled, I - invalid, D - dynamic
0 ;;; LAN traffic can go anywhere
chain=forward action=accept in-interface=ether1-LAN log=no
log-prefix=""
1 ;;; Established traffic
chain=forward action=accept connection-state=established log=no
log-prefix=""
2 ;;; Related traffic
chain=forward action=accept connection-state=related log=no
log-prefix=""
3 ;;; ICMP
chain=forward action=accept protocol=icmp log=no log-prefix=""
4 ;;; cam allow incoming traffic
chain=forward action=accept protocol=tcp dst-address=192.168.27.4
dst-port=21392 log=yes log-prefix=""
5 ;;; HS3 allow incoming traffic
chain=forward action=accept protocol=tcp dst-address=192.168.27.8
dst-port=44443 log=yes log-prefix=""
6 ;;; HS3 HSTOUCH allow incoming traffic
chain=forward action=accept protocol=tcp dst-address=192.168.27.8
dst-port=44444 log=yes log-prefix=""
7 ;;; Drop the rest
chain=forward action=drop log=no log-prefix=""
8 chain=output action=accept log=no log-prefix=""
9 ;;; LAN traffic can go anywhere
chain=input action=accept in-interface=ether1-LAN log=no log-prefix=""
10 ;;; Established traffic
chain=input action=accept connection-state=established log=no
log-prefix=""
11 ;;; Related traffic
chain=input action=accept connection-state=related log=no log-prefix=""
12 ;;; ICMP
chain=input action=accept protocol=icmp limit=5,5 log=no log-prefix=""
13 ;;; Drop the rest
chain=input action=drop log=no log-prefix=""
[admin@MikroTik] /ip firewall filter>