Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


Filter this topic showing only the reply marked as answer View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 
DonGould
3892 posts

Uber Geek


  #1292221 27-Apr-2015 13:12
Send private message

drpaulmartin: I will work out how to open up specific ports later and forward them where they need to go.


/ip firewall nat
add action=dst-nat chain=dstnat comment="Expose web interface of thing" disabled=yes dst-address=17.168.81.142 dst-port=446 protocol=tcp to-addresses=192.168.1.33 to-ports=443

Ok so what's this doing?!

This means that when you go https://17.168.81.142:446 you'll actually get the https web interface on 192.168.1.33:443


add action=dst-nat chain=dstnat comment="Expose web interface of thing" disabled=yes dst-address=17.168.81.142 dst-port=443 protocol=tcp to-addresses=192.168.1.33 to-ports=443

This version means you can just go https://17.168.81.142 and you'll land on the same device but then you can only do this once.

add action=dst-nat chain=dstnat comment="Expose web interface of thing" disabled=yes dst-address=17.168.81.142 dst-port=446 protocol=tcp to-addresses=192.168.1.33 to-ports=443
add action=dst-nat chain=dstnat comment="Expose web interface of thing" disabled=yes dst-address=17.168.81.142 dst-port=447 protocol=tcp to-addresses=192.168.1.34 to-ports=443
add action=dst-nat chain=dstnat comment="Expose web interface of thing" disabled=yes dst-address=17.168.81.142 dst-port=448 protocol=tcp to-addresses=192.168.1.35 to-ports=443

You might use this to expose the web interface on a number of things.

get the idea?

Open a terminal window and just run the command I've given you above, then go back into winbox and see what it did in IP firewall NAT.  You'll get the idea of what it's set up and then be able to reverse it out.

Obviously you'll then need to delete my command because it won't do anything at all because your internal network is 192.168.88.0/24 and your public IP is not the one I used in my exmaple.

Oh ya...  17.168.81.142 is 'my' public fixed IP.

As for that bridge, no you don't need that.  The default config acheives the same result by just setting ether2 as the master port for ether3 to 5.

I didn't actually follow what the bridge port was about in Steves example.  I think he was just making the 1's drop out on to ether2 so that you can pick them up and throw them somewhere else.

Oh, and did you figure out that I gave you the back up command so you can just make a back up of your configuration before you start so you can roll back if you manage to stuff it up.  That's one of the best features of this product over a consumer router.  You can just backup your set up, have a play, break everything, then roll back to known good.






Promote New Zealand - Get yourself a .kiwi.nz domain name!!!

Check out mine - i.am.a.can.do.kiwi.nz - don@i.am.a.can.do.kiwi.nz




drpaulmartin

11 posts

Geek


  #1292713 28-Apr-2015 08:44
Send private message

You are the Yoda of MikroTik. Thank you so much. That will save me a bunch of time. :)

chevrolux
4962 posts

Uber Geek
Inactive user


  #1292729 28-Apr-2015 09:07
Send private message

Steve's guide is for using a mikrotik to bridge a UFB connection to a router that can't do vlan tagging so that would be why it looks different? Or have we already figured that out?

For a new Mikrotik user it wouldn't be a bad idea to just let it load up the default config and adjust to suit. As has been mentioned, the firewall is most important as MT will accept dns requests on any interface. Not to mention SSH too.

But yea from the default should just be add a vlan, move dhcp client and then adjust firewall (and default masquerade rule).



DonGould
3892 posts

Uber Geek


  #1292816 28-Apr-2015 11:10
Send private message

drpaulmartin: You are the Yoda of MikroTik. Thank you so much. That will save me a bunch of time. :)


Yes I am the master!!!!


....that's right, the 'master' of 'ask someone else for help, and then get it...'

In this case I am simply sharing the love that was shared with me by others who follow this space and helped me out when I was in your space, trying to get the little white box with flashing lights to do something useful.

D




Promote New Zealand - Get yourself a .kiwi.nz domain name!!!

Check out mine - i.am.a.can.do.kiwi.nz - don@i.am.a.can.do.kiwi.nz


DonGould
3892 posts

Uber Geek


  #1292819 28-Apr-2015 11:12
Send private message

chevrolux: Steve's guide is for using a mikrotik to bridge a UFB connection to a router that can't do vlan tagging so that would be why it looks different? Or have we already figured that out?


Yes, I didn't read his whole blog properly, but it did look like a good solution to a slightly different problem.


chevrolux: For a new Mikrotik user it wouldn't be a bad idea to just let it load up the default config and adjust to suit. As has been mentioned, the firewall is most important as MT will accept dns requests on any interface. Not to mention SSH too.


DNS requests are only answered if you have that setting on, other wise it won't do that.  If doesn't come on by default when you do a system reset with 'no configuration' (yip, that got me and took me some time to figure out what I'd missed).







Promote New Zealand - Get yourself a .kiwi.nz domain name!!!

Check out mine - i.am.a.can.do.kiwi.nz - don@i.am.a.can.do.kiwi.nz


1 | 2 
Filter this topic showing only the reply marked as answer View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.