Community discussions

MikroTik App
 
kvstudio6
just joined
Topic Author
Posts: 16
Joined: Thu Jun 18, 2020 10:06 am

Firewall NAT , Route List Setting is will running

Wed Oct 14, 2020 5:21 am

Hi Guys,

need help from you guys. As the pic I upload,
from the Firwall NAT - Out.Interface
and Route List - Gateway

all the time I reboot the mikrotik, this 2 part setting is will be running, and all the time I need manually set it back!
how I can solve this problem?
Capture1.PNG
Capture.PNG
You do not have the required permissions to view the files attached to this post.
 
kvstudio6
just joined
Topic Author
Posts: 16
Joined: Thu Jun 18, 2020 10:06 am

Re: Firewall NAT , Route List Setting is will running

Wed Oct 14, 2020 6:14 am

anyone can help?

thanks
 
User avatar
vecernik87
Forum Veteran
Forum Veteran
Posts: 882
Joined: Fri Nov 10, 2017 8:19 am

Re: Firewall NAT , Route List Setting is will running

Wed Oct 14, 2020 9:18 am

You didn't provide much info (especially, you did not bother to say what interface was there in the first place), but given your routing mark names, I assume that all these rules are related to a dynamic VPN interfaces, most likely you are running server and clients are connecting and everytime client connects, it creates an interface. That would explain everything:
Dynamic interfaces (notice the "D" letter on beginning row) are dynamic. If the tunnel/vpn is down (or router is rebooted), interface is removed. Next time it is created, it is actually different interface. This is expected behavior.

You have following choices:
1) Create a "server binding" interface (interfaces->add -> select corresponding type based on your VPN type) for each username. Then, this interface will not disappear once user disconnects, instead, it will just turn off "running" state.
2) create an "interface list" (interfaces-> lists -> add) and then, in your PPP profile, select this list. Once dynamic interfaces are created, they will be instantly assigned to selected list. In your firewall/routes, use this interface list instead of specifying particular interface.

The first option will give you more flexibility, but you have to create the interface for every single user and you can't have multiple interfaces for one user.
The second option means less flexibility and maybe not suitable for you at all because all interfaces within the list will have same route or firewall rule applied, but it is easier to set up because all you need is a single list.
 
kvstudio6
just joined
Topic Author
Posts: 16
Joined: Thu Jun 18, 2020 10:06 am

Re: Firewall NAT , Route List Setting is will running

Thu Oct 15, 2020 4:18 am

You have following choices:
1) Create a "server binding" interface (interfaces->add -> select corresponding type based on your VPN type) for each username. Then, this interface will not disappear once user disconnects, instead, it will just turn off "running" state.
2) create an "interface list" (interfaces-> lists -> add) and then, in your PPP profile, select this list. Once dynamic interfaces are created, they will be instantly assigned to selected list. In your firewall/routes, use this interface list instead of specifying particular interface.


1) I alreay create the each username VPN type with SSTP server binding [DR] and running all the time. but once reboot still happen again?
 
kvstudio6
just joined
Topic Author
Posts: 16
Joined: Thu Jun 18, 2020 10:06 am

Re: Firewall NAT , Route List Setting is will running

Mon Oct 19, 2020 12:15 pm

anyone can help ?

Who is online

Users browsing this forum: gtsspmsbr, HeinoHomm, holvoetn, JohnConnett, madmeesh and 126 guests