Port forwarding - Why it IS working
Posted: Fri Oct 06, 2023 11:10 pm
Hi,
I have a torrent client on my home server and when I was setting up my new mikrotik router I was expecting to have to enable UPnP or set up port forwarding.
But to my surprise uploads works fine and I'm not sure why. May someone look at my config please?
I have a torrent client on my home server and when I was setting up my new mikrotik router I was expecting to have to enable UPnP or set up port forwarding.
But to my surprise uploads works fine and I'm not sure why. May someone look at my config please?
Code: Select all
/ip firewall filter
add action=accept chain=input comment="allow established" connection-state=\
established,related
add action=drop chain=input comment="drop invalid" connection-state=invalid
add action=accept chain=input comment="allow local connections" \
in-interface-list=local
add action=drop chain=input comment="drop all other connections"
add action=fasttrack-connection chain=forward connection-state=\
established,related hw-offload=yes
add action=accept chain=forward connection-state=established,related
add action=drop chain=forward connection-state=invalid
add action=drop chain=forward connection-nat-state=!dstnat connection-state=new \
in-interface-list=wan
/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether1-modem
add action=masquerade chain=srcnat out-interface=VDSL
add action=masquerade chain=srcnat out-interface=LTE
add action=masquerade chain=srcnat comment="Hairpin NAT" disabled=yes \
dst-address=10.0.0.10 out-interface=bridge-lan src-address=10.0.0.0/24
add action=dst-nat chain=dstnat comment="Redirect DNS to server" disabled=yes \
dst-port=53 in-interface=bridge-lan protocol=tcp src-address=!10.0.0.10 \
to-addresses=10.0.0.10
add action=dst-nat chain=dstnat disabled=yes dst-port=53 in-interface=\
bridge-lan protocol=udp src-address=!10.0.0.10 to-addresses=10.0.0.10
add action=dst-nat chain=dstnat disabled=yes in-interface=VDSL protocol=tcp \
src-port=37367 to-addresses=10.0.0.10 to-ports=37367
add action=dst-nat chain=dstnat disabled=yes in-interface=VDSL protocol=udp \
src-port=37367 to-addresses=10.0.0.10 to-ports=37367