Sun Apr 17, 2022 12:33 am
here is firewall rules:
/ip firewall filter
add action=accept chain=input comment=\
"defconf: accept established,related,untracked" connection-state=\
established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" \
ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" \
ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
connection-mark="" connection-state=established,related packet-mark=""
add action=accept chain=forward comment=\
"defconf: accept established,related, untracked" connection-state=\
established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
connection-state=invalid
add action=drop chain=forward comment=\
"defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
connection-state=new in-interface-list=WAN
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" disabled=yes \
ipsec-policy=out,ipsec out-interface-list=WAN
add action=dst-nat chain=dstnat dst-port=80 in-interface=ether1 protocol=tcp \
to-addresses=192.168.5.200 to-ports=80
add action=dst-nat chain=dstnat dst-port=443 in-interface=ether1 port="" \
protocol=tcp to-addresses=192.168.5.200 to-ports=443
add action=dst-nat chain=dstnat dst-port=25 in-interface=ether1 protocol=tcp \
to-addresses=192.168.5.200 to-ports=25
add action=dst-nat chain=dstnat dst-port=22 in-interface=ether1 protocol=tcp \
to-addresses=192.168.5.200 to-ports=22
add action=dst-nat chain=dstnat dst-port=20-21 in-interface=ether1 protocol=\
tcp to-addresses=192.168.5.200 to-ports=20-21
add action=dst-nat chain=dstnat dst-port=19791 in-interface=ether1 protocol=\
tcp to-addresses=192.168.5.21 to-ports=4899
add action=dst-nat chain=dstnat dst-port=995 in-interface=ether1 protocol=tcp \
to-addresses=192.168.5.200 to-ports=995
add action=dst-nat chain=dstnat dst-port=1701,500,4500 in-interface=ether1 \
protocol=udp to-addresses=192.168.5.21
add action=masquerade chain=srcnat out-interface=ether1