Community discussions

MikroTik App
 
User avatar
sjoram
Member Candidate
Member Candidate
Topic Author
Posts: 192
Joined: Sun Feb 10, 2013 8:47 pm
Location: Essex, UK

NAT challenge

Thu Jan 02, 2025 1:59 pm

I have a Mikrotik with built-in LTE modem as a secondary connection attached to another Mikrotik. I'm trying to achieve a bit of a funky NAT configuration, but it's not matching the rules as expected.

R1 has 172.22.1.254/24 and 192.168.58.250/24 amongst others
R2 has 192.168.58.254/24
R2 has a static route for 172.22.1.0/24 via 192.168.58.250

The LTE connection has a CGNAT WAN IP address but I have a L2TP tunnel (via the LTE) to another ISP providing a public IP address.

I am trying to achieve:
Source: Any
Destination: L2TP Public IP
Port: TCP/25
dst-nat to 172.22.1.3 port 25
src-nat to 192.168.58.254

Else when the traffic reaches R1, replies will attempt to follow R1's default route.

I've previously been able to use routing rules to send traffic from R1 outbound via R2 with no issue (directly over LTE, not L2TP), but I'm now trying to make traffic flow in the opposite direction.

The dst-nat rule is seeing hits as expected, but the src-nat rule is not.
I can't see any obvious reason for this - any suggestions?
 
User avatar
sindy
Forum Guru
Forum Guru
Posts: 11227
Joined: Mon Dec 04, 2017 9:19 pm

Re: NAT challenge

Thu Jan 02, 2025 2:03 pm

How exactly does the src-nat rule look like, i.e. what are its match conditions?
 
User avatar
sjoram
Member Candidate
Member Candidate
Topic Author
Posts: 192
Joined: Sun Feb 10, 2013 8:47 pm
Location: Essex, UK

Re: NAT challenge

Thu Jan 02, 2025 2:21 pm

chain src-nat
dst address 172.22.1.3
dst proto/port tcp/25
action src-nat to-address 192.168.58.254
 
User avatar
sindy
Forum Guru
Forum Guru
Posts: 11227
Joined: Mon Dec 04, 2017 9:19 pm

Re: NAT challenge

Thu Jan 02, 2025 2:31 pm

Since the src-nat rule is correct, it means the packet that did hit the dst-nat one has never reached the src-nat one. Routing, firewall filter, ipsec policy, or rp-filter setting may cause this.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 22089
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: NAT challenge

Thu Jan 02, 2025 3:48 pm

As usual, without the context of the config, and often a detailed network diagram, the chap from essex wants to play whackamole.
Perhaps being waterlogged has clouded the approach!

/export file=anynameyouwish ( minus router serial number, any public WANIP info, keys etc.) ( for BOTH mt devices )

Actually mostly asking cause it pains me to see Sindy guessing. ;-)
 
User avatar
sindy
Forum Guru
Forum Guru
Posts: 11227
Joined: Mon Dec 04, 2017 9:19 pm

Re: NAT challenge

Thu Jan 02, 2025 3:50 pm

Actually mostly asking cause it pains me to see Sindy guessing. ;-)
@sjoram has been around for a while, so I figure he enjoys the journey as much as the goal, so I play along.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 22089
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: NAT challenge

Thu Jan 02, 2025 3:55 pm

Actually mostly asking cause it pains me to see Sindy guessing. ;-)
@sjoram has been around for a while, so I figure he enjoys the journey as much as the goal, so I play along.
Yes, thats why I thought a round of jousting would be entertaining. But not around for that long, the lad looks to be about 12 in that photo, not even finished O levels... :-)

Who is online

Users browsing this forum: CloudRouting, kickstart24, sindy, StuckSomewhere and 44 guests