Community discussions

MikroTik App
 
engel
just joined
Topic Author
Posts: 5
Joined: Tue Jun 27, 2023 8:37 pm

Port forwarding rule on WAN interface doen't work when VPN Client connected

Tue Jun 27, 2023 8:45 pm

Hello, everybody.

I am a newbie in Mikrotik configuration.
I need forward port from WAN (ether1 with public IP) to local host in my local network.
I did this through WinBox: IP -> Firewall -> Nat -> Add Rule:

Chain: dstnat
Protocol: 6 (tcp)
Dst Port: 1000
In Interface: ether 1

Action:
Action: netmap
To Addresses: 192.168.46.201
To Ports: 1000

And it works when I coonects throguth public IP X.X.X.X:1000 until I connect to L2TP/IPSec server Y.Y.Y.Y with enabled default route.
Device adds route 0.0.0.0 through Y.Y.Y.Y - And I think that is why forwarding is not working.

Could you please help me how to configure right? That VPN connection and port forwading works (on WAN ip)?
 
User avatar
Kentzo
Long time Member
Long time Member
Posts: 666
Joined: Mon Jan 27, 2014 3:35 pm
Location: California

Re: Port forwarding rule on WAN interface doen't work when VPN Client connected

Tue Jun 27, 2023 11:38 pm

I think you need to add a policy rule (action=none) with lower priority that would exclude TCP 1000 from IPsec. See this topic for some reference.
 
engel
just joined
Topic Author
Posts: 5
Joined: Tue Jun 27, 2023 8:37 pm

Re: Port forwarding rule on WAN interface doen't work when VPN Client connected

Wed Jun 28, 2023 1:07 pm

I think you need to add a policy rule (action=none) with lower priority that would exclude TCP 1000 from IPsec. See this topic for some reference.
I tried to add this rule - but no effect. I think then Mikrotik connects to VPN server it adds default route though l2tp interface.
So I see syn packets received by router WAN interface but reply packets seem to go throuhg l2tp interface through WAN.
Last edited by engel on Wed Jun 28, 2023 1:08 pm, edited 1 time in total.
 
User avatar
Kentzo
Long time Member
Long time Member
Posts: 666
Joined: Mon Jan 27, 2014 3:35 pm
Location: California

Re: Port forwarding rule on WAN interface doen't work when VPN Client connected

Wed Jun 28, 2023 6:09 pm

Never needed to set up an L2TP/IPsec (I’m using IKEv2). Looks like I was wrong regarding policies as L2TP is route based. Try firewall marks as means to select a specific route, like discussed in this thread. Search forum for other examples.
 
engel
just joined
Topic Author
Posts: 5
Joined: Tue Jun 27, 2023 8:37 pm

Re: Port forwarding rule on WAN interface doen't work when VPN Client connected

Wed Jun 28, 2023 9:21 pm

Never needed to set up an L2TP/IPsec (I’m using IKEv2). Looks like I was wrong regarding policies as L2TP is route based. Try firewall marks as means to select a specific route, like discussed in this thread. Search forum for other examples.
Thanks. I already found topic which explain how to use different routing tables.
 
User avatar
r0berts
newbie
Posts: 49
Joined: Mon Jul 30, 2018 3:29 pm

Re: Port forwarding rule on WAN interface doen't work when VPN Client connected

Thu Jun 29, 2023 9:21 am

Hi engel, did you manage to solve your problem? I have a pretty similar one (without Ipsec) and I am getting stuck.