1&3; There is a fortigate in the colo that handles the public IP and WAF. It has port forwarding for the one thing I need for wireguard to the Mikrotik CHR. The CHR sits on LAN inside our network.
The silly games and bridge I agree with you on and I think I might have to do something as I have some log entries “ether4: bridge RX looped packet” etc. Unfortunately I wasn’t the one that set this up as I don’t have access to the hypervisor, and I think our guy was also struggling with the concept.
Bottom line there; I just need an appliance that can run Dude and receive these wireguard connections to support dude. It would have been so much easier if mikrotik made dude server a windows or linux app. Also if dude would accept a web socket connection like ubiquiti UNMS that would have been perfect. But this is what I’m given and I have to work with it. Let me know if you have better thoughts there.
- Definitely, I think the drop rules are disabled at the moment. But it’s inside our LAN so I’m not panicking right now.
5; answer is here; Port forwarding question with some twists - #12 by Maxburn