Community discussions

MikroTik App
 
User avatar
Stuntrider
just joined
Topic Author
Posts: 8
Joined: Tue Jul 29, 2014 11:12 am
Location: Russia

ip cloud rule broblem

Tue Jul 29, 2014 11:47 am

what you need to add a rule in the firewall to work ip cloud. I have a rule in the late drop input and it interferes with the service.
 
npero
Member
Member
Posts: 317
Joined: Tue Mar 01, 2005 1:59 pm
Location: Serbia

Re: ip cloud rule broblem

Tue Jul 29, 2014 12:45 pm

add chain=input comment=Cloud in-interface=WAN_interface protocol=udp src-port=15252
My rule for Cloud, also Normis send me name of server if you want to open all port to cloud server.
 
User avatar
Stuntrider
just joined
Topic Author
Posts: 8
Joined: Tue Jul 29, 2014 11:12 am
Location: Russia

Re: ip cloud rule broblem

Tue Jul 29, 2014 12:51 pm

does not work
 
User avatar
Stuntrider
just joined
Topic Author
Posts: 8
Joined: Tue Jul 29, 2014 11:12 am
Location: Russia

Re: ip cloud rule broblem

Tue Jul 29, 2014 12:55 pm

my serial number 444a04378c0a
 
npero
Member
Member
Posts: 317
Joined: Tue Mar 01, 2005 1:59 pm
Location: Serbia

Re: ip cloud rule broblem

Tue Jul 29, 2014 1:39 pm

Paste your firewall rules in input chain, that rules tested on five router and working.

Whet disable your input rules in filter it is working ?
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26379
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Re: ip cloud rule broblem

Tue Jul 29, 2014 1:50 pm

maybe you have deleted the default firewall rule that allows "established" connections?
 
User avatar
Stuntrider
just joined
Topic Author
Posts: 8
Joined: Tue Jul 29, 2014 11:12 am
Location: Russia

Re: ip cloud rule broblem

Tue Jul 29, 2014 1:52 pm

yes, if I unplug the rule prohibiting all works
 
User avatar
Stuntrider
just joined
Topic Author
Posts: 8
Joined: Tue Jul 29, 2014 11:12 am
Location: Russia

Re: ip cloud rule broblem

Tue Jul 29, 2014 1:55 pm

maybe you have deleted the default firewall rule that allows "established" connections?
There are 2 rules to permit INPUT and forward passing established connections
 
User avatar
Stuntrider
just joined
Topic Author
Posts: 8
Joined: Tue Jul 29, 2014 11:12 am
Location: Russia

Re: ip cloud rule broblem

Tue Jul 29, 2014 2:05 pm

here is a screenshot of my firewall
Untitled-1.jpg
may be something wrong with me?
You do not have the required permissions to view the files attached to this post.
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 12003
Joined: Tue Feb 25, 2014 12:49 pm
Location: Italy
Contact:

Re: ip cloud rule broblem

Tue Jul 29, 2014 2:44 pm

But Cloud service how works?


CPU -> output -> cloud server -> reply -> same (related/estabilished) connection before -> CPU

or

cloud server -> input -> CPU -> reply -> same (related/estabilished) connection before -> cloud server

?

Is working on this way, and input chain is not "used"

iprouterboard:port UDP -> output chain -> 81.198.87.240:15252
81.198.87.240:15252 UDP -> related reply -> iprouterboard:port

You do not have any new connection on Input but only estabilished/related.

Firewall Connection Tracking are active?
Last edited by rextended on Tue Jul 29, 2014 2:51 pm, edited 1 time in total.
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26379
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Re: ip cloud rule broblem

Tue Jul 29, 2014 2:50 pm

this:
CPU -> output -> cloud server -> reply -> same (related/estabilished) connection before -> CPU
cloud server makes no connection, the routerboard asks and gets reply in established connection. accepting established should be enough
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 12003
Joined: Tue Feb 25, 2014 12:49 pm
Location: Italy
Contact:

Re: ip cloud rule broblem

Tue Jul 29, 2014 2:52 pm

this:
CPU -> output -> cloud server -> reply -> same (related/estabilished) connection before -> CPU
cloud server makes no connection, the routerboard asks and gets reply in established connection. accepting established should be enough
I do not know if you have reply to my post before I complete it:

iprouterboard:port UDP -> output chain -> 81.198.87.240:15252
81.198.87.240:15252 UDP -> related (estabilished) reply -> iprouterboard:port

Who is online

Users browsing this forum: Ahrefs [Bot], MauriceW, shahzaddj1 and 106 guests