Community discussions

MikroTik App
 
n3kochan
just joined
Topic Author
Posts: 3
Joined: Mon Jun 03, 2024 11:20 pm

VRRP + DST-NAT

Tue Jun 04, 2024 12:04 am

Hello everyone! I'm trying to create HA firewall, which will dst-nat traffic from outside to local network, but I can't understand how to do this. If i enable sync-connection-track=yes all dnat'ed connections are synced to backup router, but without dstnat flag and them are not src-natted(and dst-natted) by backup router [they are routed as-is from LAN to WAN without any address translation], but SRC-NAT works fine, if I trying to connect from LAN to WAN and shutting down master router connection does not dropping. Can anyone help with that?Image (https://imgur.com/a/O3EiSn4)
 
rplant
Long time Member
Long time Member
Posts: 542
Joined: Fri Sep 29, 2017 11:42 am

Re: VRRP + DST-NAT

Tue Jun 04, 2024 7:14 am

Not sure, but

1. They should be using src-nat rather than masquerade
2. dst-nat rules are same on both routers
 
n3kochan
just joined
Topic Author
Posts: 3
Joined: Mon Jun 03, 2024 11:20 pm

Re: VRRP + DST-NAT

Tue Jun 04, 2024 5:30 pm

DST-NAT rules are same on both routers and I'm using SRC-NAT to hide LAN behind WAN IP
You do not have the required permissions to view the files attached to this post.
 
User avatar
Amm0
Forum Guru
Forum Guru
Posts: 4382
Joined: Sun May 01, 2016 7:12 pm
Location: California
Contact:

Re: VRRP + DST-NAT

Tue Jun 04, 2024 6:16 pm

Connection tracking is confusing. So I'm not sure, especially how NAT is handled.

But my first thought would be to disable fast-track rule (if enabled) to see if that changes this "d" vs "s".
 
n3kochan
just joined
Topic Author
Posts: 3
Joined: Mon Jun 03, 2024 11:20 pm

Re: VRRP + DST-NAT

Tue Jun 04, 2024 7:12 pm

Fast-track is disabled everywhere it can be disabled, any configuration I've tried syncs SRC-NAT but not DST-NAT

Who is online

Users browsing this forum: No registered users and 5 guests