Community discussions

MikroTik App
 
mdennyh
just joined
Topic Author
Posts: 5
Joined: Wed May 08, 2019 11:28 am

How to enable Webfig access from internet?

Wed Sep 11, 2019 2:29 pm

Hi..
I have a Mikrotik RB that is connected directly through a fiber optic modem and I set the RB to dial my ISP with PPPoE.
My Mikrotik Board always have a public IP and I can set port forwarding for any port I want (standard port forwarding with IP/Firewall - NAT)
The problem is I can't access my webfig from internet somehow.
Here's what I had try so far:
  • Change the IP/Services for www from 80 to another port, like: 8181
  • Put a port forward rule to my RB's IP at port 8181
Nothing works, even though I can access another server on another port from internet.

Can someone help ?
Thank you in advance.
 
Sob
Forum Guru
Forum Guru
Posts: 9121
Joined: Mon Apr 20, 2009 9:11 pm

Re: How to enable Webfig access from internet?

Wed Sep 11, 2019 4:28 pm

If you're accessing service on router itself, you only need to open port on router (using accept rule in input chain). Port forwarding rule won't do anything useful.
 
User avatar
k6ccc
Forum Guru
Forum Guru
Posts: 1497
Joined: Fri May 13, 2016 12:01 am
Location: Glendora, CA, USA (near Los Angeles)
Contact:

Re: How to enable Webfig access from internet?

Wed Sep 11, 2019 6:02 pm

Also, HIGHLY recommend putting some additional security on it. There are several things that can be done if you really insist on having a WebFig port directly accessed from the internet. For example, if able, restrict the source IPs that can access it to only the IPs that you want to have access. For example if you want to access from a static IP at work, put that IP into an access list. Obviously if you need access from anywhere, that does not work. You are already using a non-standard port, but that is not much security by itself. Port knocking also helps.
Better would be to not use www access at all. WinBox is better. A VPN would be even better
.
 
kalamaja
Member Candidate
Member Candidate
Posts: 113
Joined: Wed May 23, 2018 3:13 pm

Re: How to enable Webfig access from internet?

Wed Sep 11, 2019 6:21 pm

Do NOT put WebFig directly into Internet. Instead, set up IPSec/L2TP VPN and enable access to WebFig through it. QuickSet can set it up for you, just enable VPN network from IP/Services. IPSec/L2TP is built into Win10/Android/iOS so no additional software is needed.
 
mdennyh
just joined
Topic Author
Posts: 5
Joined: Wed May 08, 2019 11:28 am

Re: How to enable Webfig access from internet?

Thu Sep 12, 2019 1:01 pm

OK. So i decide not to access webfig through internet, but I can't enable the winbox access too.
I enabled the ip/cloud services from Quickset (see the attached screenshot) and I can access any service port from that address.
So I know that the cloud service works.
But still unable to access the RB from winbox from outside (internet)
Can someone tell me what I need to do ?
You do not have the required permissions to view the files attached to this post.
Last edited by mdennyh on Thu Sep 12, 2019 1:05 pm, edited 1 time in total.
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26379
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Re: How to enable Webfig access from internet?

Thu Sep 12, 2019 1:03 pm

so if you enabled VPN access in there, you can connect from a remote location with L2TP/IPsec VPN tunnel, with the credentials you provided
 
mdennyh
just joined
Topic Author
Posts: 5
Joined: Wed May 08, 2019 11:28 am

Re: How to enable Webfig access from internet?

Thu Sep 12, 2019 1:07 pm

so if you enabled VPN access in there, you can connect from a remote location with L2TP/IPsec VPN tunnel, with the credentials you provided
unfortunately I can't :(
I try to change the username/password, disable/enable the cloud service, nothing works so far
 
Sob
Forum Guru
Forum Guru
Posts: 9121
Joined: Mon Apr 20, 2009 9:11 pm

Re: How to enable Webfig access from internet?

Thu Sep 12, 2019 3:02 pm

If you use VPN, then you shouldn't be connecting to xxx.sn.mynetname.net in WinBox, that address is only for VPN client. In WinBox you should use whatever private address the server uses in tunnel (I don't know what Quick Set configures), after you connect to VPN.

Who is online

Users browsing this forum: Google [Bot], GoogleOther [Bot], Michiganbroadband and 59 guests