And yes, we have fixed public IP on our sim card.
Sorry. Did not understand correctly. But i don't need to export anything. I only need to make some changes in port forwarding so it could port forward FROM LTE1 (sim card) to ETH2. Previous configuration was working from ETH1 port forward to ETH2. Now my internet is coming not from ETH1, but from LTE1, while main switch still on the ETH2./export file=anynameyouwish ( minus serial number and any public WANIP information )
Is that correct? I don't have such rule in my configuration, and dstnat forwarding works. I have only input rules for accessing ROS system services (VPNs)The port also needs to be allowed on the "input" in the /ip firewall filter for the same port/protocol as the dst-nat to work.
You mean on the same FW NAT rule, on this page:The port also needs to be allowed on the "input" in the /ip firewall filter for the same port/protocol as the dst-nat to work. And it should be added just below the ICMP input accept rule. The dst-nat rule is still needed.
Do you have your internet over sim card, from LTE1 ?Is that correct? I don't have such rule in my configuration, and dstnat forwarding works. I have only input rules for accessing ROS system services (VPNs)The port also needs to be allowed on the "input" in the /ip firewall filter for the same port/protocol as the dst-nat to work.
You mean there is no way to make port forward using sim card (lte1) as internet source?since most standard LTE services use CGNAT, which would not allow port forwarding. [/i]
Yes, I'm using Chateau LTE12. My WAN (internet) inteface is lte1Do you have your internet over sim card, from LTE1 ?
Is that correct? I don't have such rule in my configuration, and dstnat forwarding works. I have only input rules for accessing ROS system services (VPNs)
And you only have "in.interface" as lte1 and port forward is working for you ?Yes, I'm using Chateau LTE12. My WAN (internet) inteface is lte1
If is the same SIM as was in ZTE and from there it worked, I doubt that ISP changed something in the mean time, but also can be APN configuration (I have different to get public IP, not network APN)You mean there is no way to make port forward using sim card (lte1) as internet source?since most standard LTE services use CGNAT, which would not allow port forwarding. [/i]
hard to believe..
Sorry for being confusing: If you have a public IP, you really just need to add an input rule with action accept in the IP > Firewall > Filter page. Your title is going to attract attention, so more a note for others, not your case. e.g. having a public IP on LTE is not commonsince most standard LTE services use CGNAT, which would not allow port forwarding. [/i]
Yes, I actually use In. interface list WAN (which is set to lte1) but it should be the same, others settings as I posted before.And you only have "in.interface" as lte1 and port forward is working for you ?Yes, I'm using Chateau LTE12. My WAN (internet) inteface is lte1
Wooow. You maybe right!!!If is the same SIM as was in ZTE and from there it worked, I doubt that ISP changed something in the mean time, but also can be APN configuration (I have different to get public IP, not network APN)
YES !!!!If is the same SIM as was in ZTE and from there it worked, I doubt that ISP changed something in the mean time, but also can be APN configuration (I have different to get public IP, not network APN)
I guess manual not Network APNYES !!!!If is the same SIM as was in ZTE and from there it worked, I doubt that ISP changed something in the mean time, but also can be APN configuration (I have different to get public IP, not network APN)
You are my saver !!!
I only add one setting in APN and it started to work (with LTE1) as In.interface!!!
Thank you !!!!
It was only the APN problemWith the default firewall and QuickSet, you need to allow the input traffic to router.
LTE is/should be in WAN interface list, so the !LAN rule in /ip/firewall/filter would drop the traffic incoming traffic for the LTE's public IP. The dst-nat rule looks right. But it will never get hit because the !LAN is dropping it.
No problemIt was only the APN problemWith the default firewall and QuickSet, you need to allow the input traffic to router.
LTE is/should be in WAN interface list, so the !LAN rule in /ip/firewall/filter would drop the traffic incoming traffic for the LTE's public IP. The dst-nat rule looks right. But it will never get hit because the !LAN is dropping it.
It was using default APN and i was getting random IP address. That's where the problem was.
After i changed to correct APN, (and in.interface to LTE1), all started to work!
thank's to Optio !!!
Yes. ISP long time ago, gave me a custom APN, but i really forgot this.I guess manual not Network APN
Very good catch. I was looking for a problem absolutely in other placeSo the issue was the "Use Network APN" was checked... That would cause the APN that set to not be used. Good catch.
Same here, network is CGNAT, custom provided - publicYes. ISP long time ago, gave me a custom APN, but i really forgot this.I guess manual not Network APN
one small configuration line, makes many servers downSame here, network is CGNAT, custom provided - publicYes. ISP long time ago, gave me a custom APN, but i really forgot this.
Can you give an exaple of this filter rule setup?The port also needs to be allowed on the "input" in the /ip firewall filter for the same port/protocol as the dst-nat to work. And it should be added just below the ICMP input accept rule. The dst-nat rule is still needed.
Note here....this part is critical:And yes, we have fixed public IP on our sim card.
since most standard LTE services use CGNAT, which would not allow port forwarding.