Hi, I have NAS and I made a firewall dst-nat rules, But I have problem, while I’m getting connection from outside (wan) I see in my NAS “connection from 192.168.1.1” (the ip of my router) there is anyway to get the ip that forwarded?
Hello Zivtal,
In your mangle filter, just activate (check box) logging and you’ll see in your log window the original address that was translated.
Suggestion: add a logging prefix to identify those log entries faster.
Regards,
Sent from Tapatalk
Edit: NAT filter!!! My bad…
Sent from Tapatalk
I want the ip address will forward to my NAS because I have there features such “Auto block” on login attempts and etc,…
You have wrong srcnat/masquerade rule which changes source address not only for outgoing connections from LAN to internet, but for all.
Ok, I found the problem, Long time a go I made a srcnat masquerade “rollback” with Out. Interface “my-bridge”. That’s the problem. Anyway I disabled this NAT and it’s work. But reason that I made that NAT as I remember that because I could not connect from local network to my dynamic address (dyndns)… fixed by adding “src. address” of my bridge… Thanks again!
You can have you cake and eat it too, at least in this case, you just need to do it properly. MikroTik calls this “rollback” hairpin NAT and if you do it only connections with source in your LAN, it won’t interfere with incoming connections from internet.
So SOB, are you saying the purpose of Haripin NAT is to enable a LAN device to go external to the Router (to the internet) and back through the router to another device on the LAN??
Call me cwazee but why in the heck provide that feature? Why doesnt the OP simply go directly to the other device via its direct LANIP address??
No, that is not the purpose of hairpin NAT, packet will not go external.
Read the article, where everything is explains in details how it works:
https://wiki.mikrotik.com/wiki/Hairpin_NAT
Ahh okay, now I get it. Hairpin is Mikrotiks nomenclature for NAT LOOPBACK .
Is a checkbox in my current router vice rules but I like seeing what the rule states and is doing.
Other than testing purposes, I still dont see the value of it.
Whenever I wanted to test my FTP server i would call a friend…
Very useful for mail servers, etc when used from a phone that goes back and forth from inside to outside of LAN.
hi guys am new on mikrotik product…i have some challenges when configuring mikrotik router the challenge am having is that i want to set up a dhcp server,i try to set it up but its wasnt working each time i set it up its give me ip from the public ip ,i will really appreciate if anybody can help me out .thanks
Please own a new thread for your issue.
Sent from Tapatalk