Good morning!
I need a little help. We change our firewall to Mikrotiks and i created a tunel from our company to our branch and it’s work like a charm, i can ping the other side no problem but, i can’t acess our file server. i will post our configuraton here, someone could help me with this?
Main:
Local IP: 10.10.12.0
Firewall:
nov/20/2023 14:12:43 by RouterOS 6.49.10
software id = F1IT-3YV7
model = RB3011UiAS
serial number = HEC08S0VTDE
/ip firewall address-list
add address=10.10.12.254 list=rede-suporte
/ip firewall filter
add action=accept chain=input comment=Ipu src-address=206.42.41.168
add action=accept chain=output dst-address=206.42.41.168
add action=accept chain=input src-address=201.131.176.66
add action=accept chain=output dst-address=201.131.176.66
add action=accept chain=forward src-address=10.10.13.0/24
add action=accept chain=forward dst-address=10.10.13.0/24
add action=accept chain=input comment=“Liberar WinBox” connection-state=
established,related connection-type=“” dst-port=2288 protocol=tcp
add action=accept chain=input comment=“ICMP - 10/sec” limit=10,5:packet
protocol=icmp
add action=accept chain=input comment=“Estabelecidas e Relacionadas”
connection-state=established,related
add action=drop chain=input comment=Invalidos connection-state=invalid
add action=drop chain=input comment=“DROP GERAL” disabled=yes
in-interface-list=LINKs
/ip firewall nat
add action=accept chain=srcnat dst-address=10.10.13.0/24 src-address=
10.10.12.0/24
add action=masquerade chain=srcnat out-interface-list=LINKs
Branch:
Local IP: 10.10.13.0
Firewall:
nov/20/2023 14:17:18 by RouterOS 6.49.10
software id = EU20-D8GH
model = RB3011UiAS
serial number = HEC08YHDQZH
/ip firewall filter
add action=accept chain=input comment=Itapipoca src-address=45.178.179.242
add action=accept chain=output dst-address=45.178.179.242
add action=accept chain=input src-address=170.79.200.82
add action=accept chain=output dst-address=170.79.200.82
add action=accept chain=forward src-address=10.10.12.0/24
add action=accept chain=forward dst-address=10.10.12.0/24
add action=accept chain=input comment=“Libera WinBox” limit=5,5:packet
protocol=icmp
add action=accept chain=input comment=ICMP connection-state=
established,related disabled=yes
add action=accept chain=input dst-port=2288 protocol=tcp
add action=drop chain=input connection-state=invalid
add action=drop chain=input disabled=yes in-interface=redeInterna
/ip firewall nat
add action=accept chain=srcnat dst-address=10.10.12.0/24 src-address=
10.10.13.0/24
add action=masquerade chain=srcnat out-interface=“Ether 2 - IpuNET”
add action=masquerade chain=srcnat out-interface=PPPOE-Brisanet
Thans in advantage!
Grecco"