Community discussions

MikroTik App
 
markrudling
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 51
Joined: Tue Aug 15, 2006 6:28 pm

masquerade causing issues

Sun Jul 01, 2007 1:37 am

Hi

Im having issues with something very simple here. all network traffic is masqueraded. However some clients need external ips. I have done this this scr and dst nat rules. i can ping and access my pc externaly.

now for the strange bit. Some services dont work like echolink. the only way i can get them to work is by disabeling the masquerade rule, then they work 100% but ofcorse all other non external ip's have no connectitivity!!!

Any ideas why the masquerade rule will interfier or what i can use as an alternative to the masquerade rule.

Thanks
 
User avatar
Equis
Forum Veteran
Forum Veteran
Posts: 886
Joined: Mon Jun 06, 2005 6:48 am

Re: masquerade causing issues

Sun Jul 01, 2007 3:19 am

A guess....

Would the order of rules matter?

So dstnat first?
Also, do you exclude you real IP users from the masq?
 
markrudling
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 51
Joined: Tue Aug 15, 2006 6:28 pm

Re: masquerade causing issues

Sun Jul 01, 2007 9:52 am

Thanks for the help, i aranged as you recomended and ensured masquerade rule is last on the list, still the same.

How would you exclude real ip users from the masquerade? Infact i have done this with one client by adding an ! next to his ip in the masquerade rule, this then works for his ip, but you can only add one ip rule like this.

But i think thats on the right track, any further sudgestion to exclude the ip's from the masquerade?

Thanks again
 
User avatar
skillful
Trainer
Trainer
Posts: 552
Joined: Wed Sep 06, 2006 1:42 pm
Location: Abuja, Nigeria
Contact:

Re: masquerade causing issues

Sun Jul 01, 2007 6:20 pm

Create a list of all IPs to be excluded in ip--> firewall--> address-list, then apply this list with a ! in "src-address-list" of your masquerade rule.
 
markrudling
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 51
Joined: Tue Aug 15, 2006 6:28 pm

Re: masquerade causing issues

Sun Jul 01, 2007 10:42 pm

Thank you very much, The list trick is working.

Is this the correct way or is it a clever work-around.

Nether the less it worked great for me.
Thank you.
 
markrudling
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 51
Joined: Tue Aug 15, 2006 6:28 pm

Re: masquerade causing issues

Mon Jul 02, 2007 8:41 am

Nope. sorry this acutally did not work.

I recived a call this morning saying there is no internet to clients... after checking the masquerade rule i had left an ip in the wrong place, rendering the masquerade rule useless, but i still had connectivity as i have nated ip.

After checking recomended settings, certain services will not work with masquerade enabled to the natted ip's, but perfect with it dissabled.

PLEASE HELP FURTER.

Thanks
 
User avatar
macgaiver
Forum Guru
Forum Guru
Posts: 1770
Joined: Wed May 18, 2005 5:57 pm
Location: Sol III, Sol system, Sector 001, Alpha Quadrant

Re: masquerade causing issues

Mon Jul 02, 2007 10:59 am

GIve us export of your NAT rules and Ip addresses
 
markrudling
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 51
Joined: Tue Aug 15, 2006 6:28 pm

Re: masquerade causing issues

Mon Jul 02, 2007 11:15 am

Blush

Sorry, i have made the mistake, when adding the ip address to the list, by default they are dissabled. Enabling them cured fault.

Thanks again to everyone giving there time to help me.

Issue completely resolved.