Community discussions

 
technonotux
newbie
Topic Author
Posts: 32
Joined: Tue Jan 18, 2011 6:05 pm

Forward all ports except Mikrotik reserved

Wed Jan 21, 2015 8:51 am

I am using RB450G with PPPOE-Client Internet connection with public ip, i have forwarded all ports using the

/ip firewall nat add chain=dstnat protocol=tcp dst-port=1-65535 action=dst-nat to-addresses=192.168.1.101 to-ports=1-65535
/ip firewall filter add action=accept chain=input disabled=no dst-port=8291 protocol=tcp

above script has successfully forward all ports i have lost connection to RB450G from Winbox (8291), http (80), ssh(22) as all ports are forwarded to local ip, i want to exclude RB450G (RouterOS Ports) i.e. 8291, 80, 22, 21 etc.. how can i do it.
 
jarda
Forum Guru
Forum Guru
Posts: 7604
Joined: Mon Oct 22, 2012 4:46 pm

Re: Forward all ports except Mikrotik reserved

Wed Jan 21, 2015 9:18 am

Make accept rules for these ports in input chain.
 
technonotux
newbie
Topic Author
Posts: 32
Joined: Tue Jan 18, 2011 6:05 pm

Re: Forward all ports except Mikrotik reserved

Wed Jan 21, 2015 9:45 am

Make accept rules for these ports in input chain.
i already have following accept rule for the port 8291 but when i forward all ports the LAN ip, i loose Winbox(8291) connection what could be the reason ?
/ip firewall filter add action=accept chain=input disabled=no dst-port=8291 protocol=tcp
 
User avatar
bajodel
Long time Member
Long time Member
Posts: 545
Joined: Sun Nov 24, 2013 8:30 am
Location: Italy

Re: Forward all ports except Mikrotik reserved

Thu Jan 22, 2015 9:00 am

Make accept rules for these ports in input chain.
i already have following accept rule for the port 8291 but when i forward all ports the LAN ip, i loose Winbox(8291) connection what could be the reason ?
/ip firewall filter add action=accept chain=input disabled=no dst-port=8291 protocol=tcp
nat happens before filter, exclude 8291 from the range or put another rule before
 
technonotux
newbie
Topic Author
Posts: 32
Joined: Tue Jan 18, 2011 6:05 pm

Re: Forward all ports except Mikrotik reserved

Thu Jan 22, 2015 9:05 am

as there are multiple ports to exclude like 8291, 80, 22, 21 etc.. which RouterOS uses, is there any other simple way to exclude in single / multiple rule
 
User avatar
bajodel
Long time Member
Long time Member
Posts: 545
Joined: Sun Nov 24, 2013 8:30 am
Location: Italy

Re: Forward all ports except Mikrotik reserved

Thu Jan 22, 2015 9:31 am

as there are multiple ports to exclude like 8291, 80, 22, 21 etc.. which RouterOS uses, is there any other simple way to exclude in single / multiple rule
put before you nat range rule something like..

/ip firewall nat add chain=dstnat protocol=tcp dst-port=22,80,8291 action=accept
 
technonotux
newbie
Topic Author
Posts: 32
Joined: Tue Jan 18, 2011 6:05 pm

Re: Forward all ports except Mikrotik reserved

Thu Jan 29, 2015 8:45 am

as there are multiple ports to exclude like 8291, 80, 22, 21 etc.. which RouterOS uses, is there any other simple way to exclude in single / multiple rule
put before you nat range rule something like..

/ip firewall nat add chain=dstnat protocol=tcp dst-port=22,80,8291 action=accept

Thanks it solved my issue :D

Who is online

Users browsing this forum: MSN [Bot] and 47 guests