Community discussions

MikroTik App
 
Leon1980
just joined
Topic Author
Posts: 1
Joined: Sun Mar 10, 2019 10:50 pm

Firewall rules

Mon Mar 11, 2019 1:24 am

Hi everybody I have a RB4011 routerboard. 6.43.3
I have a camera system inside the house the port forwarding was success . I set up the camera live view application from the outside IP address and the correct port. Only way it’s working if I’m not on the local Wi-Fi network . Can you help me somebody how to set up the firewall or what rule do I need to set up .
 
User avatar
Steveocee
Forum Guru
Forum Guru
Posts: 1189
Joined: Tue Jul 21, 2015 10:09 pm
Location: UK
Contact:

Re: Firewall rules

Mon Mar 11, 2019 11:51 am

You need hairpin NAT.
 
Van9018
Long time Member
Long time Member
Posts: 558
Joined: Mon Jun 16, 2014 6:26 pm
Location: Canada - Abbotsford

Re: Firewall rules

Mon Mar 11, 2019 10:59 pm

Or use a VPN, then configure your viewer to connect to the local IPs of the cameras. This could be more secure than exposing your Camera's communication protocols to the internet.
 
User avatar
sebastia
Forum Guru
Forum Guru
Posts: 1782
Joined: Tue Oct 12, 2010 3:23 am
Location: Antwerp, BE

Re: Firewall rules

Tue Mar 12, 2019 12:20 am

Or the most simple: add the external dns name used to access camera from outside to dns cache pointing to internal ip.
 
solar77
Long time Member
Long time Member
Posts: 586
Joined: Thu Feb 04, 2016 11:42 am
Location: Scotland

Re: Firewall rules

Tue Mar 12, 2019 1:55 pm

@sebastia
I don't think DNS catch is going to work . Steveocee is right and the OP needs hairping nat.
client send packet to IP of camera, get changed to internal IP of camera, return traffic has source IP of Internal camera IP. client device drops it because it's does not much the dst-ip of original packet. there is a graph somewhere on wiki ....
 
User avatar
sebastia
Forum Guru
Forum Guru
Posts: 1782
Joined: Tue Oct 12, 2010 3:23 am
Location: Antwerp, BE

Re: Firewall rules

Fri Mar 15, 2019 11:52 am

@sebastia
I don't think DNS catch is going to work . Steveocee is right and the OP needs hairping nat.
client send packet to IP of camera, get changed to internal IP of camera, return traffic has source IP of Internal camera IP. client device drops it because it's does not much the dst-ip of original packet. there is a graph somewhere on wiki ....
It should work just fine as long as port on exernal ip & internal ip are same.

The flow is different and not as you described: client will send packet to adapted internal ip, as defined in the overriding dns entry, responses will be going to internal ip of the client. no need for dst+src nat.
 
solar77
Long time Member
Long time Member
Posts: 586
Joined: Thu Feb 04, 2016 11:42 am
Location: Scotland

Re: Firewall rules

Fri Mar 15, 2019 4:29 pm

ok I see what you mean now. So the URL will just be an Internal IP if you connected to it from LAN.
somehow i think the OP is using IP address not URL though
I set up the camera live view application from the outside IP address

Who is online

Users browsing this forum: No registered users and 25 guests