I can open port to my subnet PC for all, but if i need allow connect to this port server a from specific Public IP , i cannot manage . I make allow list with included Public IP and when I put this list it in scr adress list dstnat, the port is closed .
Example
Local server adress - 192.168.1.11
in Allow List - i put public adress - 100.100.100.100
My router WAN (ether10) IP adress - 200.200.200.200
Server port - 3377
Are you sure this is working without the source IP address list as the rules don’t seem to imply you have anything to allow a dst-nat conneciton or more specific one through?
I would do exactly as you have done by using a source IP to narrow down the “caller” and it should work fine if your rules are in place.
This is a NAT rule though - not a firewall filter rule. MT does not do this automatically for you. It did used to be a part of the default config though (that may be a while ago though) Here is what I use, it’s relatively near the top.
Oh My God
Everything is wok now
Thanks
The friend who is scanning my port from outside , hi scan not from pc scan(lie nmap or etc..) , but hi use a some web online scanner service and ofcourse there is diferent public IP . ))