Naks
Honorary Master
- Joined
- Jun 3, 2009
- Messages
- 10,115
- Reaction score
- 6,068
@Naks
You mentioned you tried the above but I always prefer to use interface/interface list insead of dst address, less work for the firewall and cleaner when your address changes
On your ip firewall filter rule I dont think the dst-address=192.168.88.248 should be used, since we drop all on the WAN side of the filter, the rule must match before the nat is applied so that would be the WAN ip needed, but in-interface-list is much easier
Can you see if the above rules help
thanks, but same thing: I can see packets but no connection.
In the logs:
Code:
dstnat: in:ether1 out:(unknown 0), src-mac X, proto TCP (SYN), PhoneIP:53594->RouterIP:9898, prio 5->0, len 60
forward: in:ether1 out:bridge, src-mac X, proto TCP (SYN), PhoneIP:53594->192.168.88.248:9898, NAT PhoneIP:53594->(RouterIP:9898->192.168.88.248:9898), prio 5->0, len 60