Community discussions

MikroTik App
 
spy65
just joined
Topic Author
Posts: 1
Joined: Wed Mar 08, 2023 5:33 pm

mangle prerouting src-address-list and !dst-address-list

Wed Mar 08, 2023 6:37 pm

Hello. I've got a problem without a solution.
hap ac2(arm) routerboard 7.8, routeros 7.8. Two interfaces, different subnets, 192.168.224.0/24 and long way: 172.16.1.1(mikrotik)--172.16.1.2(switch),192.168.4.1(switch)- 192.168.4.0/24. gateways for nets - 192.168.224.1 and 192.168.4.1 (switch).
list "Permit local internet": 192.168.224.220 (for example)
192.168.4.90 has an internet access through 192.168.224.165(outside)

/ip firewall mangle add chain=prerouting src-address=192.168.4.90 dst-address-list=!"Permit local internet" action=mark-routing new-routing-mark=outside

outside table's gateway ip 192.168.224.165
test computer ip 192.168.224.220
I ping 192.168.4.90 from 192.168.4.90
timeouts
192.168.224.165 it is linux computer, I run tcpdump, I see echo reply 192.168.4.90 > 192.168.224.220

prerouting: in:ether5 out:(unknown 0), connection-state:established,snat src-mac 00:23:33:3d:f3:ff, proto ICMP (type 0, code 0), 192.168.4.90->172.16.1.1, NAT 192.168.4.90->(172.16.1.1->192.168.224.220), len 60
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19323
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: mangle prerouting src-address-list and !dst-address-list

Thu Mar 09, 2023 2:40 am

hahaha sorry I havent spent weeks with my head in that config so slow down spell it out far more clearly and provide a diagram,
and dont be suprized if someone asks for a config as well.

Who is online

Users browsing this forum: loloski, neitro and 119 guests