Community discussions

 
cwsatpry
just joined
Topic Author
Posts: 6
Joined: Thu Jul 07, 2011 10:29 pm

Accessing WAN interface from LAN

Mon Aug 08, 2011 10:57 pm

Hello all,

I'm trying to test port forwarding and NAT from the WAN interface to a machine on the LAN on an almost-stock 750GL (only other thing I set up is some port forwarding and some alterations to the IP pools). What I am finding however is that whenever I try to hit the WAN IP (XXX.YYY.ZZZ.XYZ) from behind the router (i.e. a 192.168.88.x address) nothing appears to happen. Today I happened by chance to attempt to forward port 443, and discovered that I'm getting the WebFig page - apparently all requests for the WAN interface get sent to the LAN interface instead.
Alas, my Google-fu is weak on this end as many of the keywords I'm using to describe the issue (WAN, LAN, nat, etc) tend to rank higher for more general-type questions. Now I could spend a few hours mucking around with the firewall and NAT settings, but I'm sure someone else would have come upon the same issue.

Below is my NAT table. I'm guessing that I either need to change the masquerade rule or add some other one translation. I'm also sure that once the answer is known it will seem really obvious, but I'm out of coffee and my brain refuses to help me out here.
 0   ;;; default configuration
     chain=srcnat action=masquerade out-interface=ether1-gateway 
 1 X chain=dstnat action=dst-nat to-addresses=192.168.88.120 to-ports=443 protocol=tcp dst-address=XXX.YYY.ZZZ.XYZ dst-port=443 
Any ideas?
 
fewi
Forum Guru
Forum Guru
Posts: 7734
Joined: Tue Aug 11, 2009 3:19 am

Re: Accessing WAN interface from LAN

Mon Aug 08, 2011 11:04 pm

If you're testing port forwarding from behind the router (WAN to LAN port forwarding, testing from LAN), read this: http://wiki.mikrotik.com/wiki/Hairpin_NAT
Specific answers require specific questions. When in doubt, post the output of "/ip address print detail", "/ip route print detail", "/interface print detail", "/ip firewall export", and an accurate network diagram.
 
cwsatpry
just joined
Topic Author
Posts: 6
Joined: Thu Jul 07, 2011 10:29 pm

Re: Accessing WAN interface from LAN

Mon Aug 08, 2011 11:17 pm

If you're testing port forwarding from behind the router (WAN to LAN port forwarding, testing from LAN), read this: http://wiki.mikrotik.com/wiki/Hairpin_NAT
Thanks! That looks like it describes my problem, I will try that. If I don't post an update then it worked. As a bonus I added a new term to my vocabulary!

PS: yep, that did the trick. Thanks again!
 
User avatar
antwal
just joined
Posts: 12
Joined: Sun Jul 08, 2012 4:07 pm
Contact:

Re: Accessing WAN interface from LAN

Fri Nov 16, 2012 8:46 pm

hello, i have the same problem but, with Hairpin NAT, not woking.... others solutions?

Who is online

Users browsing this forum: Majestic-12 [Bot], MSN [Bot] and 84 guests