Community discussions

MikroTik App
 
Pilgrim
Member Candidate
Member Candidate
Topic Author
Posts: 265
Joined: Sun Mar 30, 2008 1:04 pm

Bridge nat or firewall nat ?

Sat Oct 04, 2008 3:54 pm

if the output ports (lan interfaces) are bridged shall I then do the port forwarding in firewall nat or in bridge nat?

rgs Pilgrim
 
User avatar
sergejs
MikroTik Support
MikroTik Support
Posts: 6695
Joined: Thu Mar 31, 2005 3:33 pm
Location: Riga, Latvia
Contact:

Re: Bridge nat or firewall nat ?

Wed Oct 15, 2008 4:25 pm

I assume you are making NAT between public and local interface. ip firewall nat should be used for this.
Do not forget to enable bridged packets to go through firewall,
interface bridge setting set use-ip-firewall=yes.
 
Pilgrim
Member Candidate
Member Candidate
Topic Author
Posts: 265
Joined: Sun Mar 30, 2008 1:04 pm

Re: Bridge nat or firewall nat ?

Thu Oct 23, 2008 10:53 pm

Thank you Sergejs

I didn't manage to get the setting entered. I tried as pasted in below. Please could you - or any other kind person on the board here give a hint where I am going wrong.

Thanks, Pilgrim

[admin@MikroTik] interface bridge> pr
Flags: X - disabled, R - running
0 R name="bridge-1" mtu=1500 arp=enabled mac-address=00:0C:42:13:66:18 stp=no priority=32768
ageing-time=5m forward-delay=15s garbage-collection-interval=4s hello-time=2s
max-message-age=20s
[admin@MikroTik] interface bridge> bridge-1
no such command or directory (bridge-1)
[admin@MikroTik] interface bridge> set
numbers: 0
[admin@MikroTik] interface bridge> use-ip-firewall=yes
no such command or directory (use-ip-firewall)
[admin@MikroTik] interface bridge> set use-ip-firewall=yes
no such argument (=)
[admin@MikroTik] interface bridge>
 
nightstar
Frequent Visitor
Frequent Visitor
Posts: 62
Joined: Sun Jun 29, 2008 12:28 am

Re: Bridge nat or firewall nat ?

Fri Oct 24, 2008 2:09 pm

Thank you Sergejs

I didn't manage to get the setting entered. I tried as pasted in below. Please could you - or any other kind person on the board here give a hint where I am going wrong.

Thanks, Pilgrim

[admin@MikroTik] interface bridge> pr
Flags: X - disabled, R - running
0 R name="bridge-1" mtu=1500 arp=enabled mac-address=00:0C:42:13:66:18 stp=no priority=32768
ageing-time=5m forward-delay=15s garbage-collection-interval=4s hello-time=2s
max-message-age=20s
[admin@MikroTik] interface bridge> bridge-1
no such command or directory (bridge-1)
[admin@MikroTik] interface bridge> set
numbers: 0
[admin@MikroTik] interface bridge> use-ip-firewall=yes
no such command or directory (use-ip-firewall)
[admin@MikroTik] interface bridge> set use-ip-firewall=yes
no such argument (=)
[admin@MikroTik] interface bridge>

Try:

interface bridge settings set use-ip-firewall=yes
or in winbox click on BRIDGE menu then on the SETTINGS menu and check "use IP firewall"
Which version of RouterOS you are using? looks like this command does not exists in version 2.9.x?

Best regards!
 
Pilgrim
Member Candidate
Member Candidate
Topic Author
Posts: 265
Joined: Sun Mar 30, 2008 1:04 pm

Re: Bridge nat or firewall nat ?

Fri Oct 24, 2008 4:44 pm

Thank you Nightstar

Neither of them seems to be possible in my router os. I am running ver. 2.9.51.

Or did I do something wrong again?

Best regards, Pilgrim

MikroTik RouterOS 2.9.51 (c) 1999-2007 http://www.mikrotik.com/

Terminal vt102 detected, using multiline input mode
[admin@MikroTik] > interface bridge
[admin@MikroTik] interface bridge> settings
no such command or directory (settings)
[admin@MikroTik] interface bridge> setting
no such command or directory (setting)
[admin@MikroTik] interface bridge>
 
Pilgrim
Member Candidate
Member Candidate
Topic Author
Posts: 265
Joined: Sun Mar 30, 2008 1:04 pm

Re: Bridge nat or firewall nat ?

Fri Oct 24, 2008 4:49 pm

In winbox I do not get any "seetings" tab when cliking on the bridge menu. I just get the following.

Best regards Pilgrim
You do not have the required permissions to view the files attached to this post.
 
nightstar
Frequent Visitor
Frequent Visitor
Posts: 62
Joined: Sun Jun 29, 2008 12:28 am

Re: Bridge nat or firewall nat ?

Fri Oct 24, 2008 7:29 pm

In winbox I do not get any "seetings" tab when cliking on the bridge menu. I just get the following.

Best regards Pilgrim

Yep...it looks like you need to upgrade to RouterOS 3.x

Best Regards!
 
Pilgrim
Member Candidate
Member Candidate
Topic Author
Posts: 265
Joined: Sun Mar 30, 2008 1:04 pm

Re: Bridge nat or firewall nat ?

Mon Oct 27, 2008 12:56 pm

Re-visiting this issue I would like to ask if I can not use bridging of the interfaces used for my me LAN in combination with the IP firewall.

The use-ip-firewall is as far as I was able to check not available in ver. 2.9.

I have a routerboard 150 and this board seems not to be compatible with ver. 3.x. So I can't upgrade unless I buy a new mini router board.

The set up is that I am using Interface "ether1" as public interface and interfaces Ether2 through ether5 is brigded and used for my LAN.

I want of course to be able to do port forwarding and forward packets received through the public interface at a given port to computers on my LAN.

Can this not be done using the the IP firewall in ver. 2.9?

Best regards, Pilgrim
 
User avatar
sergejs
MikroTik Support
MikroTik Support
Posts: 6695
Joined: Thu Mar 31, 2005 3:33 pm
Location: Riga, Latvia
Contact:

Re: Bridge nat or firewall nat ?

Wed Oct 29, 2008 4:03 pm

For 2.9 version use 'ip firewall' menu for NAT and filtering.

Who is online

Users browsing this forum: gigabyte091, McSee and 38 guests