So I am trying to access a couple PTP panels externally that are behind a Mikrotik. The setup is as follows...
Me -----> Internet -----> (public IP) Mikrotik 3011 (10.1.10.1) -----> LAN (10.1.10.0/24) -----> QRT ac (10.1.10.209) -----> QRT ac (10.1.10.211)
I have full Winbox access to the 3011. The PTP panels are a very basic setup. The ether1 interface and the wlan interface are in a bridge and the bridge has a DHCP client setup. I have verified communication across and I can access both QRT panels via Winbox while on the 10.1.10.0/24 network.
My goal is to have external Winbox access to all 3 devices. Here is what I was thinking at first but it didn't work...
1. Port 8291 accepted from anywhere (bad practice but just for this example)
2. Anything with the source address of my house's public IP on port 8291 dstnat to the first QRT panel
3. Anything with the source address another location's public IP on port 8291 dstnat to the second QRT panel
I could see the external traffic hit the nat rules and could see it in connections but it seems like the QRT panels are responding. They are not set to filter via ip services.
I also tried changing the default Winbox port on the 3011 and the QRT thinking that there was a conflict with no success. I also tried SSH with SSH disabled on the 3011 with no success.
I am able to mac-telnet from the 3011 to the QRT panels but what I need to change on the QRT panels is the wireless settings and I am much more comfortable with those settings via Winbox.
I am sure I am missing something. Thoughts?