J
J
JackBauer2016-09-20 23:22:07
SIP
JackBauer, 2016-09-20 23:22:07

Can't make Hairpin NAT for SIP server. Mikrotik. as????

Inside 192.168.1.0/24, outside direct IP.
Outside, I calmly go to my SIP server .1.2
From the inside, using WANIP, no way. Already tried many options.
.1.2 grandstream piece of iron.
Here is my NAT:
0 chain=srcnat action=masquerade to-addresses=192.168.1.2
to-ports=0-65535 protocol=udp src-address=192.168.1.0/24
dst-address=192.168.1.2 dst-port=5060- 5061 log=no
1 chain=dstnat action=dst-nat to-addresses=192.168.1.2 to-ports=5060-5061
protocol=udp src-address=192.168.1.0/24 dst-address=WANIP
dst-port=5060- 5061 log=no
2 chain=dstnat action=dst-nat to-addresses=192.168.1.2 to-ports=5060-5061
protocol=udp dst-address-type="" dst-port=5060-5061 log=no
3 chain=srcnat action=masquerade protocol=udp src-address=192.168.1.0/24
dst-address=192.168.1.2 dst-port =10000-20000 log=no
4 chain=dstnat action=dst-nat to-addresses=192.168.1.2
to-ports=10000-20000 protocol=udp src-address=192.168.1.0/24
dst-address=WANIP dst-port =10000-20000 log=no
5 chain=dstnat action=dst-nat to-addresses=192.168.1.2
to-ports=10000-20000 protocol=udp dst-port=10000-20000 log=no
6 chain=dstnat action=dst -nat to-addresses=192.168.1.2 to-ports=8089
protocol=tcp in-interface=ether1-gateway dst-port=8089 log=no
7 ;;; default configuration
chain=srcnat action=masquerade out-interface=ether1-gateway log=no
log-prefix=""
Taken from here Mikrotik: portmapping on the external interface and a client from the local network cannot connect using the white address of the router. Is there a solution?
Of course, I tried a simple rule from the Mikrotik wiki. started with it.

Answer the question

In order to leave comments, you need to log in

2 answer(s)
D
Dmitry, 2016-09-21
@plin2s

The wiki article works. Check the addresses, and the order of the rules. You can also disable ALL firewall rules for verification to be sure that it has nothing to do with it.
PS and don't forget that in the first rule you have 192.168. 2.1

J
JackBauer, 2016-09-21
@JackBauer

Substituted a wild crutch... Static dns entry for a symbolic name (spring ip)->.1.2 + registered a symbolic name instead of ip in clients.
Bad taste in mouth, but it worked.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question