I try in different way to make that config to work but without succes. I have public IPs just from PPPoE.
I make in exact way like wiki example https://wiki.mikrotik.com/wiki/Manual:L ... bnet_links but without success
I make the internet work from lan but dst-nat no. I want to connect from internet to All IPs from PPPoE but not working.
I try some example but nothing work with DSTNAT
In LOG I see:
Code: Select all
Jul/14/2018 23:16:55 firewall,info firewall: prerouting: in:Local(ether3) out:(unknown 0), src-mac 10:bf:48:4f:3f:11, proto UDP, 192.168.19.252:56740->192.168.19.255:20561, len 50
Jul/14/2018 23:16:55 firewall,info firewall: prerouting: in:Local(ether3) out:(unknown 0), src-mac 6c:3b:6b:83:35:b6, proto UDP, 192.168.19.251:60641->255.255.255.255:5246, len 48
Jul/14/2018 23:16:55 firewall,info firewall: prerouting: in:Local(ether3) out:(unknown 0), src-mac 10:bf:48:4f:3f:11, proto UDP, 192.168.19.252:56740->192.168.19.255:20561, len 50
Please can help me with that ?
I do not know what to do anymore
Code: Select all
/interface bridge add fast-forward=no name=Local
/interface pppoe-client
add disabled=no interface=ether1 name=pppoe-out1 password=pRb654B user=rt65445
add disabled=no interface=ether1 name=pppoe-out2 password=626hggff8 user=rt56542
add disabled=no interface=ether1 name=pppoe-out3 password=yt78j543vh user=rt56545
/ip pool
add name=dhcp_pool0 ranges=192.168.18.1-192.168.19.254
/ip dhcp-server
add address-pool=dhcp_pool0 disabled=no interface=Local name=dhcp1
/interface bridge port
add bridge=Local interface=ether3
add bridge=Local interface=ether4
add bridge=Local interface=ether5
/ip firewall connection tracking
set enabled=yes
/ip address
add address=192.168.16.1/22 interface=Local network=192.168.16.0
/ip dhcp-server network
add address=192.168.16.0/22 dns-server=192.168.16.1 gateway=192.168.16.1
/ip dns
set allow-remote-requests=yes cache-size=5000KiB max-udp-packet-size=512 \
servers=8.8.8.8,8.8.4.4
/ip firewall mangle
add action=mark-routing chain=prerouting dst-address=81.123.231.156 \
new-routing-mark=toWAN2 passthrough=yes
add action=mark-routing chain=output new-routing-mark=toWAN2 passthrough=yes \
src-address=81.123.231.156
add action=mark-routing chain=prerouting new-routing-mark=toWAN1 passthrough=\
yes src-address=192.168.16.0/22
/ip firewall nat
add action=masquerade chain=srcnat out-interface=pppoe-out1
add action=masquerade chain=srcnat out-interface=pppoe-out2
add action=dst-nat chain=dstnat dst-address=81.123.231.156 dst-port=80 log=\
yes protocol=tcp to-addresses=192.168.17.250 to-ports=80
/ip route
add distance=1 gateway=10.0.0.1%pppoe-out2 routing-mark=toWAN2
add distance=1 gateway=10.0.0.1%pppoe-out1 routing-mark=toWAN1
add distance=1 gateway=10.0.0.1
/ip service
set telnet disabled=yes
set ftp disabled=yes
set ssh disabled=yes
/system clock
set time-zone-name=Europe/Bucharest
/system routerboard settings
set silent-boot=no