Community discussions

MikroTik App
 
User avatar
Celtos
just joined
Topic Author
Posts: 6
Joined: Thu Jan 05, 2023 1:06 pm
Contact:

When unlocking port 80 on NAT some sites do not work

Tue Jan 17, 2023 3:52 pm

Good Morning,

I have a problem, when I unlock port 80 on my RB, I can access my website normally via other external connections, but I noticed that I cannot access some websites from the computer where the XAMPP server is hosted.

What am I doing wrong?
You do not have the required permissions to view the files attached to this post.
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 11438
Joined: Thu Mar 03, 2016 10:23 pm

Re: When unlocking port 80 on NAT some sites do not work

Tue Jan 17, 2023 8:01 pm

It seems (and it's hard to verify as screenshot doesn't show everything) that your DST-NAT rule isn't very selective: it matches every packet with dst-port one of configured, regardless where the packet came from. You probably want to perform NAT only on connections from internet, so you should properly configure either in-interface or (better if your firewall still follows default concept of using interface lists) in-interface-list.

A couple of related notes:
  • you configured to-ports property and used whole possible range. This probably has different effect from what you expect: if to-ports is set as multiple ports (or range), then NAT may choose any of those ports as new (destination) port. If, OTOH, this property is not set, tgen NAT keeps (destination) port unchanged
  • while it's fine to use single NAT rule for multiple services/ports, I suggest you to configure muktiple NAT rules, one per service/port. It0s simpky much more flexible, from performance point of view both ways are the same
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19103
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: When unlocking port 80 on NAT some sites do not work

Tue Jan 17, 2023 8:10 pm

Have a read.......... viewtopic.php?t=179343

Properly formatted dst nat rules are key
Forward chain firewall rule required ( usually covered by default rules )

If server is being reached by LAN users on the SAME subnet, and they are attempting to use WANIP vice lanip to reach the server, then you have to consider NAT loopback or hairpin nat.
 
User avatar
Celtos
just joined
Topic Author
Posts: 6
Joined: Thu Jan 05, 2023 1:06 pm
Contact:

Re: When unlocking port 80 on NAT some sites do not work

Tue Jan 17, 2023 9:09 pm

I read the link you sent me, but I don't know where to start, I confess that I'm very newbie.

I currently have 2 problems.

1 - When I open port 80 to access my web server, I cannot access some sites from the machine running XAMPP (IP 172.16.90.2)

2 - I can't access my web server from within itself through the ip 172.16.90.2. Only people outside the network for example using 4G or proxy...
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19103
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: When unlocking port 80 on NAT some sites do not work

Tue Jan 17, 2023 10:41 pm

No worries lets start with the basics........... describe network and requirements...

viewtopic.php?p=908118
 
User avatar
Celtos
just joined
Topic Author
Posts: 6
Joined: Thu Jan 05, 2023 1:06 pm
Contact:

Re: When unlocking port 80 on NAT some sites do not work

Wed Jan 18, 2023 2:23 am

I came to share with you how I solved it.

I put it in IN interface, where the internet link comes from, and it was solved.
You do not have the required permissions to view the files attached to this post.
Last edited by Celtos on Fri Jan 20, 2023 1:51 pm, edited 1 time in total.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19103
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: When unlocking port 80 on NAT some sites do not work

Wed Jan 18, 2023 4:41 am

Dont have the config,
Dont know the network
Dont know the requirements,
Sorry nothing learned here but glad you fixed your problem.
 
User avatar
chechito
Forum Guru
Forum Guru
Posts: 2990
Joined: Sun Aug 24, 2014 3:14 am
Location: Bogota Colombia
Contact:

Re: When unlocking port 80 on NAT some sites do not work

Wed Jan 18, 2023 7:13 am

the nowadays very common practice of doing nat without specifying interface

thank you for sharing the solution

Who is online

Users browsing this forum: 0xAA55, mszru and 48 guests