The official Mikrotik router thread

Chaps, I'm hoping someone here can help me with this issue I'm having with a brand new AC2 router.

I am trying to port forward on 3 specific ports to a PC on my LAN, and I've watched a dozen YT videos and read numerous guides, but I cannot get it to work.

I've created the following NAT rules:

Code:
add action=dst-nat chain=dstnat comment="Open port 9191" \ dst-address=MyPublicIP dst-port=9191 protocol=tcp to-addresses=\ MyPCIP to-ports=9191
add action=dst-nat chain=dstnat comment="Open port 9595" \ dst-address=MyPublicIP dst-port=9595 protocol=tcp to-addresses=\ MyPCIP to-ports=9595
add action=dst-nat chain=dstnat comment="Open port 9898" \ dst-address=MyPublicIP dst-port=9898 protocol=tcp to-addresses=\ MyPCIP to-ports=9898

None of these work, whether I try to access with the MyPublicIP or a hostname (DDNS).

I've even reset it to default and started from scratch, still no luck.

Help please? :)
This is how my rules are configured. It’s a simple NAT rule and works fine with my config:

;;; Transmission
chain=dstnat action=dst-nat
to-addresses=10.0.0.5 protocol=tcp
dst-port=51413
 
Why are you using dst-address (instead of interface in if anything)?

Sorry, I'm very new to this, I don't understand the question.

At the suggestion of someone else, I changed MyPublicIP to MyRouterPublicIP, and now I'm seeing packets on the NAT rules, but still can't get to the web pages.

I've disabled the PC's firewall and Bitdefender, made no difference.

All I did was remove my crappy Dlink router, plug in the Microtik, and re-create the port forwarding rules.

Everything was working 100% with the Dlink...
 
Wait, does the Dst-address & the to-address need to be the same, i.e. , the target PC?
You need to set the in. Interface and leave the Dst. Address empty for it to work. I've never set an Dst. Address on my firewall rules. I stopped using port forwarding as well, a VPN is just way easier for me. That being said, if you want to access that same URL from inside your network, you need to look at hairpin NAT
 
This is how my rules are configured. It’s a simple NAT rule and works fine with my config:

;;; Transmission
chain=dstnat action=dst-nat
to-addresses=10.0.0.5 protocol=tcp
dst-port=51413
Similar

add action=dst-nat chain=dstnat comment=SABNZBD dst-port=8180 \
in-interface-list=WAN protocol=tcp to-addresses=192.168.0.7 to-ports=8180
 
I don't have WAN in the in-interface list?

the list:

all ethernet
all ppp
all vlan
all wireless
bridge
ether1
ether2
ether3
ether4

ether5
wlan1
wlan2
I made an interface list so I can easily change all my rules if my connection type changes from PPPoE to DHCP etc,so it's basically the interface that has the public IP attached
1651488606910.png
 
I made an interface list so I can easily change all my rules if my connection type changes from PPPoE to DHCP etc,so it's basically the interface that has the public IP attached
View attachment 1301732

Tried that, no luck.

I can see packets when I try to access the sites on my phone (outside of my network), but all I get is:

"This site can't be reached
The web page at xxxx might be down...
ERR_CONNECTION_ABORTED"

I've tried switching off the firewall completely on that PC, but it didn't make any difference. I've added some rules to the firewall to allow TCP traffic on those ports, also didn't make any difference.

Uninstalled BitDefender, still no luck.

Checked that the ports are open on the PC:
Code:
C:\Windows\system32>netsh firewall show state
Firewall status:
-------------------------------------------------------------------
Profile = Standard
Operational mode = Enable
Exception mode = Enable
Multicast/broadcast response mode = Enable
Notification mode = Enable
Group policy version = Windows Firewall
Remote admin mode = Disable
Ports currently open on all network interfaces:
Port Protocol Version Program
-------------------------------------------------------------------
9898 TCP Any (null)
9595 TCP Any (null)
9191 TCP Any (null)
5357 TCP Any (null)
8080 TCP Any (null)
8080 TCP Any (null)
 
If packet count is increasing the NAT is being reached,somewhere between router and pc it's getting lost
 
If packet count is increasing the NAT is being reached,somewhere between router and pc it's getting lost

Hmm, I don't think so, because the packet trace looks like this, in a repeating pattern:

Interface​
Direction​
Src Adddress​
Src Port​
Dst Address​
Dst Port​
ether1​
rx​
Phone​
59046​
RouterIP​
9191​
bridge​
tx​
Phone​
59046​
PC​
9191​
ether2​
tx​
Phone​
59046​
PC​
9191​
ether2​
rx​
PC​
9191​
Phone​
59046​
bridge​
rx​
PC​
9191​
Phone​
59046​
ether1​
tx​
RouterIP​
9191​
Phone​
59046​

All devices are plugged into an 8-port switch into the router, but I don't see how that would be affecting the PF, as everything was working fine with the DLink.

Seeing this in the log, not sure if the config is right?
Code:
dstnat: in:ether1 out:(unknown 0), src-mac X, proto TCP (ACK,PSH), PhoneIP:34034->RouterIP:9191, len 539
 
Hmm, I don't think so, because the packet trace looks like this, in a repeating pattern:

Interface​
Direction​
Src Adddress​
Src Port​
Dst Address​
Dst Port​
ether1​
rx​
Phone​
59046​
RouterIP​
9191​
bridge​
tx​
Phone​
59046​
PC​
9191​
ether2​
tx​
Phone​
59046​
PC​
9191​
ether2​
rx​
PC​
9191​
Phone​
59046​
bridge​
rx​
PC​
9191​
Phone​
59046​
ether1​
tx​
RouterIP​
9191​
Phone​
59046​

All devices are plugged into an 8-port switch into the router, but I don't see how that would be affecting the PF, as everything was working fine with the DLink.

Seeing this in the log, not sure if the config is right?
Code:
dstnat: in:ether1 out:(unknown 0), src-mac X, proto TCP (ACK,PSH), PhoneIP:34034->RouterIP:9191, len 539
Are you trying to access that IP/port from inside your network?
 
Hmm, I don't think so, because the packet trace looks like this, in a repeating pattern:

Interface​
Direction​
Src Adddress​
Src Port​
Dst Address​
Dst Port​
ether1​
rx​
Phone​
59046​
RouterIP​
9191​
bridge​
tx​
Phone​
59046​
PC​
9191​
ether2​
tx​
Phone​
59046​
PC​
9191​
ether2​
rx​
PC​
9191​
Phone​
59046​
bridge​
rx​
PC​
9191​
Phone​
59046​
ether1​
tx​
RouterIP​
9191​
Phone​
59046​

All devices are plugged into an 8-port switch into the router, but I don't see how that would be affecting the PF, as everything was working fine with the DLink.

Seeing this in the log, not sure if the config is right?
Code:
dstnat: in:ether1 out:(unknown 0), src-mac X, proto TCP (ACK,PSH), PhoneIP:34034->RouterIP:9191, len 539
Your interface list screen shot had pppoe-out1 but this shows ether1?
 
No, that wasn't my screenshot.

Been trying different suggestions, so far still f-all.
So its a bit hard for us to track your config at the moment

Can you paste the current config for firewall nat and interface groups if you are using them
 
So its a bit hard for us to track your config at the moment

Can you paste the current config for firewall nat and interface groups if you are using them

Code:
/interface bridge
add admin-mac=x auto-mac=no comment=defconf name=bridge

/interface wireless
set [ find default-name=wlan1 ] band=2ghz-b/g/n channel-width=20/40mhz-XX country="south africa" disabled=no distance=indoors frequency=\
    auto installation=indoor mode=ap-bridge ssid=x wireless-protocol=802.11
set [ find default-name=wlan2 ] band=5ghz-a/n/ac channel-width=20/40/80mhz-XXXX country="south africa" disabled=no distance=indoors \
    frequency=auto installation=indoor mode=ap-bridge ssid=x wireless-protocol=802.11

/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN

/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa-psk,wpa2-psk mode=dynamic-keys supplicant-identity=MikroTik

/ip pool
add name=dhcp ranges=192.168.88.10-192.168.88.254

/ip dhcp-server
add address-pool=dhcp interface=bridge name=defconf

/interface bridge port
add bridge=bridge comment=defconf interface=ether2
add bridge=bridge comment=defconf interface=ether3
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=ether5
add bridge=bridge comment=defconf interface=wlan1
add bridge=bridge comment=defconf interface=wlan2

/ip neighbor discovery-settings
set discover-interface-list=LAN

/ipv6 settings
set disable-ipv6=yes

/interface detect-internet
set detect-interface-list=all

/interface list member
add comment=defconf interface=bridge list=LAN
add comment=defconf interface=ether1 list=WAN

/ip address
add address=192.168.88.1/24 comment=defconf interface=bridge network=192.168.88.0

/ip arp
add address=192.168.88.243 interface=bridge mac-address=x
add address=192.168.88.242 interface=bridge mac-address=x
add address=192.168.88.246 interface=bridge mac-address=x
add address=192.168.88.248 interface=bridge mac-address=x
add address=192.168.88.250 interface=bridge mac-address=x
add address=192.168.88.251 interface=bridge mac-address=x
add address=192.168.88.253 interface=bridge mac-address=x
add address=192.168.88.241 interface=bridge mac-address=x
add address=192.168.88.249 comment="Oppo 203" interface=bridge mac-address=x

/ip dhcp-client
add comment=defconf interface=ether1

/ip dhcp-server lease
add address=192.168.88.253 client-id=x mac-address=x server=defconf
add address=192.168.88.251 mac-address=x server=defconf
add address=192.168.88.249 client-id=x mac-address=x server=defconf
add address=192.168.88.250 client-id=x mac-address=x server=defconf
add address=192.168.88.248 client-id=x mac-address=x server=defconf
add address=192.168.88.246 client-id=x mac-address=x server=defconf
add address=192.168.88.243 client-id=x mac-address=x server=defconf
add address=192.168.88.242 client-id=x mac-address=x server=defconf

/ip dhcp-server network
add address=192.168.88.0/24 comment=defconf dns-server=192.168.88.1 gateway=192.168.88.1

/ip dns
set allow-remote-requests=yes

/ip dns static
add address=192.168.88.1 comment=defconf name=router.lan

/ip firewall filter
add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment="defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related hw-offload=yes
add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked
add action=accept chain=forward comment="Port Forward for 9191,9595,9898" dst-address=192.168.88.248 dst-port=9191,9595,9898 protocol=\
    tcp
add action=accept chain=forward comment="Allow Port Forwarding" connection-nat-state=dstnat connection-state=new disabled=yes \
    in-interface-list=WAN
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new \
    in-interface-list=WAN

/ip firewall nat
add action=dst-nat chain=dstnat comment="Port Forward 9191 for Transmission, 9595 for SabNZDB, 9898 for Sonar" dst-address=ROUTERPUBLICIP \
    dst-port=9191,9595,9898 log=yes protocol=tcp to-addresses=192.168.88.248
add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface-list=WAN
add action=src-nat chain=srcnat comment="Internal Port Forward 9191 for Transmission, 9595 for SabNZDB, 9898 for Sonar" disabled=yes \
    dst-port=9191,9595,9898 protocol=tcp src-address=192.168.88.0/24 to-addresses=192.168.88.248

/ip upnp interfaces
add interface=bridge type=internal
add interface=ether1 type=external

/ipv6 firewall address-list
add address=::/128 comment="defconf: unspecified address" list=bad_ipv6
add address=::1/128 comment="defconf: lo" list=bad_ipv6
add address=fec0::/10 comment="defconf: site-local" list=bad_ipv6
add address=::ffff:0.0.0.0/96 comment="defconf: ipv4-mapped" list=bad_ipv6
add address=::/96 comment="defconf: ipv4 compat" list=bad_ipv6
add address=100::/64 comment="defconf: discard only " list=bad_ipv6
add address=2001:db8::/32 comment="defconf: documentation" list=bad_ipv6
add address=2001:10::/28 comment="defconf: ORCHID" list=bad_ipv6
add address=3ffe::/16 comment="defconf: 6bone" list=bad_ipv6

/ipv6 firewall filter
add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
add action=accept chain=input comment="defconf: accept ICMPv6" protocol=icmpv6
add action=accept chain=input comment="defconf: accept UDP traceroute" port=33434-33534 protocol=udp
add action=accept chain=input comment="defconf: accept DHCPv6-Client prefix delegation." dst-port=546 protocol=udp src-address=fe80::/10
add action=accept chain=input comment="defconf: accept IKE" dst-port=500,4500 protocol=udp
add action=accept chain=input comment="defconf: accept ipsec AH" protocol=ipsec-ah
add action=accept chain=input comment="defconf: accept ipsec ESP" protocol=ipsec-esp
add action=accept chain=input comment="defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
add action=drop chain=input comment="defconf: drop everything else not coming from LAN" in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
add action=drop chain=forward comment="defconf: drop packets with bad src ipv6" src-address-list=bad_ipv6
add action=drop chain=forward comment="defconf: drop packets with bad dst ipv6" dst-address-list=bad_ipv6
add action=drop chain=forward comment="defconf: rfc4890 drop hop-limit=1" hop-limit=equal:1 protocol=icmpv6
add action=accept chain=forward comment="defconf: accept ICMPv6" protocol=icmpv6
add action=accept chain=forward comment="defconf: accept HIP" protocol=139
add action=accept chain=forward comment="defconf: accept IKE" dst-port=500,4500 protocol=udp
add action=accept chain=forward comment="defconf: accept ipsec AH" protocol=ipsec-ah
add action=accept chain=forward comment="defconf: accept ipsec ESP" protocol=ipsec-esp
add action=accept chain=forward comment="defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
add action=drop chain=forward comment="defconf: drop everything else not coming from LAN" in-interface-list=!LAN

/system clock
set time-zone-name=Africa/Johannesburg
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN
/tool sniffer
set filter-interface=all filter-ip-protocol=tcp filter-operator-between-entries=and filter-port=9191
 
@Naks
/ip firewall filter
add action=accept chain=forward comment="Port Forward for 9191,9595,9898" in-interface-list=WAN dst-port=9191,9595,9898 protocol=tcp log=yes
/ip firewall nat
add action=dst-nat chain=dstnat comment="Port Forward 9191 for Transmission, 9595 for SabNZDB, 9898 for Sonar" in-interface-list=WAN dst-port=9191,9595,9898 log=yes protocol=tcp to-addresses=192.168.88.248

You mentioned you tried the above but I always prefer to use interface/interface list insead of dst address, less work for the firewall and cleaner when your address changes

On your ip firewall filter rule I dont think the dst-address=192.168.88.248 should be used, since we drop all on the WAN side of the filter, the rule must match before the nat is applied so that would be the WAN ip needed, but in-interface-list is much easier

Can you see if the above rules help
 
Top
Sign up to the MyBroadband newsletter
X