Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- admin@MikroTik] /ip firewall> nat print
- Flags: X - disabled, I - invalid, D - dynamic
- 0 chain=srcnat action=masquerade src-address=192.168.88.0/24 dst-address=192.168.91.0/24 out-interface=ether1 log=no log-prefix=""
- 1 chain=srcnat action=accept src-address=192.168.88.0/24 dst-address=192.168.91.0/24 out-interface=ether1 log=no log-prefix=""
- 2 ;;; defconf: masquerade
- chain=srcnat action=masquerade out-interface=ether1 log=no log-prefix=""
- [admin@MikroTik] /ip firewall> filter print
- Flags: X - disabled, I - invalid, D - dynamic
- 0 D ;;; special dummy rule to show fasttrack counters
- chain=forward
- 1 ;;; defconf: accept ICMP
- chain=input action=accept protocol=icmp log=no log-prefix=""
- 2 ;;; defconf: accept established,related
- chain=input action=accept connection-state=established,related log=no log-prefix=""
- 3 XI chain=forward action=accept protocol=ipsec-esp src-address=192.168.88.0/24 dst-address=192.168.91.0/24 in-interface=bridge out-interface=ether1 log=no log-prefix=""
- 4 ;;; Allow IKE
- chain=input action=accept protocol=udp dst-port=500 log=no log-prefix=""
- 5 chain=input action=accept protocol=udp port=1701,500,4500 log=no log-prefix=""
- 6 ;;; Allow IPSec-esp
- chain=input action=accept protocol=ipsec-esp log=no log-prefix=""
- 7 ;;; Allow IPsec-ah
- chain=input action=accept protocol=ipsec-ah log=no log-prefix=""
- 8 ;;; defconf: drop all from WAN
- chain=input action=drop in-interface=ether1 log=no log-prefix=""
- 9 ;;; defconf: fasttrack
- chain=forward action=fasttrack-connection connection-state=established,related log=no log-prefix=""
- 10 ;;; defconf: accept established,related
- chain=forward action=accept connection-state=established,related log=no log-prefix=""
- 11 ;;; defconf: drop invalid
- chain=forward action=drop connection-state=invalid log=no log-prefix=""
- 12 ;;; defconf: drop all from WAN not DSTNATed
- chain=forward action=drop connection-state=new connection-nat-state=!dstnat in-interface=ether1 log=no log-prefix=""
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement