Hi Folks,
im a newcomer to mikrotik but am familiar with networking in general, I have an issue that research hasnt solved yet.
we have 5 mikrotik routers setup with rip. networks are..
172.21.0.0/24
172.21.1.0/24
172.21.2.0/26
172.21.2.64/26
172.21.2.128/26
... and so on.. etc
one of the routers is setup as the gateway, very basic firewall settings, srcnat masq for nat.
xxx.xxx.198.224/27 from our ISP.
xxx.xxx.198.226 on the wan side
172.21.0.1/24 on the lan side
the above setup works great... rip works fine, everyone can get on the internet etc.
the problem............
i try to port forward xxx.xxx.198.226 to 172.21.2.67 using port 5900.
command is.. (right off the wiki)
/ip firewall nat add chain=dstnat dst-address=xxx.xxx.198.226 protocol=tcp dst-port=5900 \
action=dst-nat to-addresses=172.21.2.67 to-ports=5900
i am not able to reach the internal machine from the outside. looking at the byte count for that rule, it does increment, but only a little. I have tried a number of variations without success. any ideas? are there issues port forwarding to other networks on the inside?
pings and traceroutes all seem normal.
the machine is reachable on the inside from any of the other networks.
any ideas would be great!
tia