Тёмный

(3) NAT Router Rules (Port Forwarding) in MikroTik RouterOS 

Category5 Technology TV with Robbie Ferguson
Подписаться 35 тыс.
Просмотров 57 тыс.
50% 1

Follow The Series: cat5.tv/mikrotik
The next step in our MikroTik series will see us routing NAT firewall rules to allow outside (Internet) users to access ports 80 and 443 on our internal web server. We'll create the required NAT (Network Address Translation) rules, and configure a Firewall Rule for each port to direct traffic through our Internet connection to the in-house server.

Наука

Опубликовано:

 

24 май 2020

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 73   
@LinuxTechShow
@LinuxTechShow 4 года назад
Just waiting for RU-vid to transcode this. Once finished, you'll see the 1440p and 1080p options which will be MUCH clearer than the previous upload (which had really blurry screenshots). Thanks for your patience. If you don't see the HD options yet, sit tight and refresh in a few minutes.
@LinuxTechShow
@LinuxTechShow 4 года назад
I am now seeing HD resolutions. That should be remarkably better than the previous upload. Enjoy the show!
@falciloid
@falciloid 3 года назад
Hello there. Sorry for necroposting but i must to ask you: do you know why set "to ports" field is not a good idea in case of dst-nat a same external and internal port? I will don't unerstood before guys in one telegram community explain it to me. Of course, it will works. But for a what price? Also I wanna note - it's able to set several ports at one rule or even port ranges. But it works correctly just in case direct PAT(Port-Adress Translation). Also one more thing - it`s don't need to add new firewall filter rule for forwarded ports in RouterOS at near a half of year as far as I remember and maybe more cuz last default drop rule in forward chain looks like "drop all from WAN exept dst-nat" P.S. Hello from Ukraine! You going well =)
@jaxpad
@jaxpad 3 года назад
Honestly- thank you for being the only person to explain as thoroughly as you do. I could successfully implement port forwarding into my network because of you and it's appreciated.
@cataphractster
@cataphractster 2 года назад
Didn’t work for me until I figured out that my internet wasn’t on ether1, but on pppoe-out1. After I substituted pppoe-out1 for ether1, it worked perfectly. Thanks for the great video.
@barrymalawi
@barrymalawi 3 года назад
Hi, Robbie, I have to thank you for this great content. Best wishes from Germany! Stay tuned!
@itskyb
@itskyb 2 года назад
Thank you so much for this video. This showed the process so much better compared to the other videos I have watched.
@astraenz
@astraenz 4 года назад
On the default config you don't need to do a firewall rule to allow the port forward. If you look at the comment on your forward drop rule you will see it says "not DSTNATed" So if it is DST-Nat it will allow it anyway. If you want firewall rules you need to edit the drop rule, go to 'Connection NAT State' untick 'dstnat' and remove the little '!' sign. The hazard sign means 'NOT'. Also if you are working on the forward chain, change the filter top right to select the chain you are working on. It makes it easier to see which rules apply. You also shouldn't be dragging these rules above "Allow Established and Related" rule. Established traffic has already been processed by the firewall so the router can use less resources to inspect it. As you moved the rules above this, the firewall will be checking every single packet.
@LinuxTechShow
@LinuxTechShow 4 года назад
Excellent eye, Scott. I didn't expect anyone to catch that, but you're bang-on correct (it's like you can read the future!) During the course of the series, we will be teaching how to limit the connectivity to only certain IP addresses / lists. During that tutorial, we are removing the dnsnat exception from the drop rule. But since we knew we were doing this, we taught to set up the Firewall Rule during this week's tutorial. Otherwise, when we later teach to to change the drop rule, we'll break all the connectivity. It's a bit chicken-and-egg, but we know people will later refer back to this week's tutorial to see how to set up port forwarding, so we wanted to include everything they will inevitably need. Thanks for the comment! And seriously - good eye! Thanks for the tip re. the order as well, I'll look closer on a followup tutorial.
@bog5620
@bog5620 3 года назад
I think the explanation you gave to Scott is invented on the spot, in fact you didn't know what you were doing. if indeed that was you intention, you shouldn't make your tutorials like so. most people search on RU-vid a how to video to make something, apply it and move on. they do not want to watch whole series or videos that didn't come yet or may never will. keep things separated, if you want to make a port forwarding, do a port forwarding video and that's it. don't leave some leftover config for future videos. so in a nutshell, I think you are a nice guy that wants to help people but this video, because you didn't know what you were doing, it's misleading.
@MrThock
@MrThock 3 года назад
Thank you so much for this. I was never able to get this to work before, now I know I was missing the firewall rule to go along with the NAT rule.
@wayneharmon2190
@wayneharmon2190 2 года назад
You are awesome! Thank you for doing this. This video has helped me twice now. You do a great job explaining. I'd love to see more
@KarlHamilton
@KarlHamilton Год назад
Excellent! Very well explained. Thanks so much for uploading!
@arvisvideo
@arvisvideo 3 года назад
Thanks for the tutorial! An introduction part about MikroTik and RouterOS was very good but the technical part is quite misleading especially the firewall filter section.
@JohnsTube
@JohnsTube 3 года назад
awesome, big thanks from Egypt :)
@tophatstop1036
@tophatstop1036 3 года назад
Could you do a video explaining how to open your ports for online games if possible?
@anlongdus
@anlongdus 3 года назад
My servers are back online after adding those destination NAT rules. Thanks from Germany…!
@viktorsakermanis3418
@viktorsakermanis3418 2 года назад
Thank you, this tutorial is the best!
@haroldcrisdayritabarquez7795
@haroldcrisdayritabarquez7795 3 года назад
Thank you for this video. I end up following HairPin NAT rule to achieve NAT port forwarding found on the internet while searching for hours how to port forward on our new mikrotik router. But your video is much simpler to understand. After watching your video, deleted all my previous nat and firewall rules and started following yours. Wish you could do more video on mikrotik. Updated: But, when my router rebooted today, it does not work.. :(
@Johann75
@Johann75 Год назад
The best explanation
@bog5620
@bog5620 3 года назад
why do you create two rules, one for port 80 and one for 443, instead of creating one and separate them by comma? you can also use dash (-) when is needed.
@cornbreadcuban5456
@cornbreadcuban5456 3 года назад
thank you for this.
@20bantoo12
@20bantoo12 3 года назад
Thank you for the video, i really learned a lot from it.But I am still having the problem with tp-link router. So, microtek router is on the top of it, And I have my PC with ubuntu linux installed connected as LAN to the tp-link router. Can you help me?
@amb102
@amb102 3 года назад
If you do not have a drop all rule for the forward chain at the end, adding the rule in the firewall is just useless! By default mikrotik allows forward for dst-nat, IT DOES NOT DROP EVERYTHING, so with your config the firewall rule is useless as it will always accept dst-nat connections. Remember that as it may also be a security risk if not properly configured :) If you want to filter incomming connections you can also do this in the nat section(by src-address, etc)
@BattousaiHBr
@BattousaiHBr 3 года назад
indeed. the firewall is very similar to linux iptables (because it uses it under the hood). these must be implemented such that the drop all is at the bottom: on forward and input chains, accept packets incoming from your LAN interface on forward and input chains, accept established and related packets on forward and input chains, drop everything
@KarlHamilton
@KarlHamilton Год назад
Is that right? So I could just remove the drop all rule then?
@TPrudwi
@TPrudwi 3 года назад
Hi, Is CAPsMAN dedicated only for Mikrotik APs?
@mahmoudalaga4613
@mahmoudalaga4613 3 года назад
Thanks you Your explanation is very good I wish you to explain L2TP in Mikrotik (without Ipsec option - i mean also without pre shared key) Most of video explain ip in virtual computers and it doesn't work in real world i have ip phone use L2TP to Connect to HQ from away branch's It have L2TP OR OVPN and i can't make any of them work
@ZachHarner4583
@ZachHarner4583 3 года назад
Did you have any issues with this router blocking outbound processes? I've noticed that my emby server can no longer connect to get live tv data, my php server is unable to connect to a database hosted on the web, and my streaming computer is having major issues with network frame drop since installing. Everything I have read has said that there is no outbound firewall, but it seems like something is blocking my stuff. I've tried the forums, but I posted 6 hours ago and am still waiting for my post to be approved....zzzz Great video by the way, helped me tremendously!
@EivindGussiasLkseth
@EivindGussiasLkseth Год назад
How to debug dst-nat rules not working as expected? I've been following The Network Berg's tutorial to setup a Mikrotik from no default configuration, and there are some firewall rules that I don't understand, but they are the ones that he recommended. I'm not getting this dst-nat thing right, and I have no clue where the issue might be.
@the-imge
@the-imge 2 года назад
Hello, Thank you for this video, I have a question. I opened Sql port (1433) under Firewall Nat and I want to allow this port just two ip adresses for access my local server. Could you help me. I looked for some document for this but I couldn't.
@FlexibleToast
@FlexibleToast 2 года назад
You're doing some trickery here. How come you can hit your Nextcloud instance from internally without using a hairpin nat? That's the info I was looking for in this video.
@CPapex
@CPapex 3 года назад
please can anyone help me am trying to setup port forwarding for remote camera viewing
@erfanziaee5904
@erfanziaee5904 3 года назад
Hello How are you today? i have a question: in our office we have a mikrotik sxt radio on the roof that with a long LAN cable it is connected to our mikrotik router. so we 2 mikrotik Devices : a mikrotik radio and mikrotik router... i want to know that how can i port forward ? do i have to configure the radio or just the router or both?
@robertwachira6067
@robertwachira6067 3 года назад
Hi l.....so how to port forward different webserver on same network
@dupajasio4801
@dupajasio4801 2 года назад
what would be the 10x more expensive router ? Cause Cisco would be 50x plus. Just curious...
@markuspfeifer9612
@markuspfeifer9612 2 года назад
Unfortunately this doesn't work with a Ubiquiti Router being the Dst behind the MikroTik. The Nextcloud-Server is behind the Ubiquiti - it's a Dream Machine (UDM without Pro). What do I have to do in this case?
@PEIN19218
@PEIN19218 2 года назад
Does latest Mikrotik router support wifi 6?
@FlexibleToast
@FlexibleToast 3 года назад
Can you use a hostname as a source instead of an IP?
@geogmz8277
@geogmz8277 4 года назад
Hey WebConfig is not secure.. It's been historically buggy and xploitable.. If you're going to use it (suggestion) you better use a good set of Firewall Rules for it even from the LAN.. Another suggestion is disable all packages you won't be using like Hotspot or Capsman if you're not going to use them better have them disabled and reduce any vector of attack and save disk space also.
@tophatstop1036
@tophatstop1036 3 года назад
is there any TCP and UDP in Mikrotik? I can't seem to find them to port forward my online games
@slimejude9691
@slimejude9691 3 года назад
Just lookup what ports your game is using, for example DOOM use 666.
@BattousaiHBr
@BattousaiHBr 3 года назад
TCP and UDP are protocols, ports are accompanying numbers to these protocols. and yes, it does have them.
@joramotorsportteam3277
@joramotorsportteam3277 3 года назад
13:23 We have 2 devices with 443 in network 192.168.88.xxx how to forward to outside internet to port 4433 one off devices?
@ChristophWeber77
@ChristophWeber77 3 года назад
set a second rule with dst port 4433 to port 443 to address IP of second device The destination port is the one you have to enter in your browser to access your network, so yournetwork.com:4433 internally goes to the secondary IP:443
@joramotorsportteam3277
@joramotorsportteam3277 3 года назад
@@ChristophWeber77 Thanks! All working
@guyseide
@guyseide 2 года назад
Question for you , I am a gamer I would like to DMZ my pc connection so that I can game better I cant find anything on youtube about this any ideas ?
@zvlogs1113
@zvlogs1113 2 года назад
Good
@Nighta90
@Nighta90 2 года назад
sadly ports still closed. logged as open in router
@shmayazuggot8558
@shmayazuggot8558 Год назад
Turn any of that on and the bandwidth plummets which is far from enterprise grade. I use a cr3xx for 10g switching but nothing else. Use FW, NATS, forwarding and that 10Gb drops to 300Mb…
@KarlHamilton
@KarlHamilton Год назад
RB3011 works well for me at 1000Mbps with firewall and NAT active...
@stevesmith2553
@stevesmith2553 3 года назад
what about udp 53
@JerryRigged
@JerryRigged 2 года назад
followed step by step and it still did not work... I have a NAS on the router with a static IP set through DHCP on the router. Adding the rules and forwards still fails externally. I can hit it internally without issue
@JerryRigged
@JerryRigged 2 года назад
Actually, I lied, it works external from the network. Thank you!. What about being connected to the local router and using the external IP to hit it? How do I make that work?
@KarlHamilton
@KarlHamilton Год назад
@@JerryRigged you need Hairpin NAT for that.
@yourpalfranc
@yourpalfranc 4 года назад
Is cascading router the same as bridge mode?? ~Frank
@LinuxTechShow
@LinuxTechShow 4 года назад
Hi Frank. Please consult your modem's manual / online docs / forums, or provide more information so we can assist.
@yourpalfranc
@yourpalfranc 4 года назад
@@LinuxTechShow That's the problem. I've never been able to find a proper manual for the Arris NVG443B and my ISP (Frontier) won't provide any support for bridging it. I found the cascading router feature in the admin GUI but I don't have a good understanding of what it provides. I guess I'll just keep digging. Unfortunately, I don't have another choice for ISP. Thanks.
@geogmz8277
@geogmz8277 4 года назад
@@yourpalfranc If your provider don't help and you're using Mikrotik you can eliminate the double nat by just using static routes.. Don't nat at all! In the Mikrotik just add a default router 0.0.0.0/0 next hop your ISP modem/router.. Just a suggestion.
@yourpalfranc
@yourpalfranc 4 года назад
@@geogmz8277 Thanks for the suggestion. I'm not well versed enough in networking for it to make much sense, so if you can point to some how-to information, I'd really appreciate it. I'll see what I can find. Also, I'm reluctant to go ahead a buy a MicroTik without knowing I can make it work in my network. Thanks again!!
@easyfloorball2655
@easyfloorball2655 3 года назад
Can I know what the command ?
@LinuxTechShow
@LinuxTechShow 3 года назад
No, that's just to help you remember what the setting is for. Can be helpful, but not required.
@denisstpierre7140
@denisstpierre7140 4 года назад
I am looking at Microtik as an option going forward. I appreciate that you are sharing info. However you might consider planing your presentations to be more concise. This 23 minute video could have been done in 10 or less.
@cornbreadcuban5456
@cornbreadcuban5456 3 года назад
You lost me with the ports. You should have set up different ports for the demonstration. You are not clear on what ports go where and why.
@loldebian
@loldebian 3 года назад
23mn of talk for 3mn of interesting matter. You really like to ear yourself talking...
@PaulNaama
@PaulNaama 4 года назад
stop using web admin. use winbox, please.
@LinuxTechShow
@LinuxTechShow 4 года назад
You haven't provided a compelling reason. Why?
@deafno
@deafno 4 года назад
I would also like to know a good reason why we should stop using web admin. Trashing web UI feels like is a habit that some MikroTik admins just develop. I started administrating MikroTik devices in 2016 and been using web UI unless I need to rescue the device using MAC WinBox. HTTPS (if you set it up correctly) is more secure than WinBox security also.
@MladenMarinov
@MladenMarinov 4 года назад
That is the beauty of this type of firmware - you can use it in the way you like it. Why more advanced users prefer WinBox? Web administrative interface is a bit slower and insecure. WinBox is faster and a bit more secure way, and have embedded terminal. Then the best way of course is to get connect using ssh with certificates. :-) The main issue of the HTTPS is that you have one more service which is give more attack surface for well known methods. Knowing how to create attack based on WinBox is more difficult. Also using WinBox and terminal the admin can use technique known as "port knocking" which may make hacking a bit more difficult with proper scripting. There also good scenarios for using web administration but again - attack to web are much more common and there are plenty ot fools for this.
@longtimber1
@longtimber1 4 года назад
Winbox manages networks. Web fig manages one device at a time. Web fig is a waste of time.
@zvlogs1113
@zvlogs1113 2 года назад
Good
Далее
(4) True Guest WiFi with MikroTik Routers
22:57
Просмотров 30 тыс.
Знакомство с NAT
9:50
Просмотров 38 тыс.
(1) Why We're Featuring MikroTik Routers
11:38
Просмотров 58 тыс.
MikroTik Port Forwarding using Winbox
9:02
Просмотров 56 тыс.
04 - Network Switches & Ethernet - Home Networking 101
22:21
Port Forwarding Explained
9:04
Просмотров 2,6 млн
(8) Pi-Hole Custom DNS Servers on MikroTik Routers
12:27
MikroTik - Adding a NAT rule
7:54
Просмотров 16 тыс.