Answer the question
In order to leave comments, you need to log in
How to properly configure firewall on Mikrotik RB951Ui-2HnD?
Good evening, ambulance staff!)
Recently I took up setting up Mikrotik from scratch, I used to add forwarding, and now it's time to thoroughly get acquainted.
The task is such that it is necessary to implement a PPTP server and some port forwarding.
I started with PPTP, everything turned out great, adding to the standard configuration. Forwarding doesn't work at all.
I reset the device to factory settings and cleared the configuration. Further, according to the standard:
Changed the password
Renamed the ports more conveniently
Combined LAN ports into BRIDGE
Assigned WAN and BRIDGE addresses
Registered GATEWAY and DNS
... etc.
Removed prohibiting rules in the Firewall.
Based on the article https://habrahabr.ru/post/265387/ =))
Answer the question
In order to leave comments, you need to log in
Why mark it for port forwarding?
Also, where are you getting it from? If from the Internet, then this rule is not very good - "add action=accept chain=input connection-state=new dst-port=3389 in-interface=LAN protocol=tcp src-address=192.168.88.0/24"
It states that incoming locale interface, but should be wan interface.
In the firewall, you just allow the connection to this port
- action=accept chain=forward dst-port=3389 in-interface=WAN protocol=tcp
And that's the traffic going through the router, not the incoming.
To forward ports further into the network, a table in NAT is used.
Actions for this are better to use netmap, although no one forbids the use of dst-nat.
the simplest example of RDP forwarding
add action=netmap chain=dstnat dst-port=3389 in-interface=ether1 protocol=tcp \
to-addresses=192.168.88.10 to-ports=3389
Everything that gets into input ether 1 on port 3389 will be thrown on machine port 3389 192.168.88.10
Here's how about port forwarding https://lantorg.com/article/probros-portov-na-mikrotik
Thank you all! I coped with the task, and VPN and sip forwarding with RTP and NAT and switching to an external address from the local network
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question