Advertisement
Kratex

Mk Configuration - NAT IP translation problem

May 20th, 2023 (edited)
180
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.62 KB | Software | 0 0
  1. /interface ethernet
  2. set [ find default-name=ether1 ] name=ether1-wan1
  3. set [ find default-name=ether2 ] name=ether2-wan2
  4. set [ find default-name=ether3 ] name=ether3-lan2
  5. set [ find default-name=ether4 ] name=ether4-lan2
  6. set [ find default-name=ether5 ] name=ether5-lan1
  7.  
  8. /interface bridge
  9. add name=bridge-wan
  10. add name=bridge-lan1
  11. add name=bridge-lan2
  12.  
  13. /interface bridge port
  14. add bridge=bridge-wan ingress-filtering=yes interface=ether1-wan1
  15. add bridge=bridge-wan ingress-filtering=yes interface=ether2-wan2
  16. add bridge=bridge-lan1 ingress-filtering=yes interface=ether5-lan1
  17. add bridge=bridge-lan1 ingress-filtering=yes interface=wifi2.4
  18. add bridge=bridge-lan1 ingress-filtering=yes interface=wifi5.0
  19. add bridge=bridge-lan2 ingress-filtering=yes interface=ether3-lan2
  20. add bridge=bridge-lan2 ingress-filtering=yes interface=ether4-lan2
  21.  
  22. /ip dhcp-client
  23. add disabled=no interface=bridge-wan
  24.  
  25. /ip dhcp-server
  26. add address-pool=dhcp_pool1 disabled=no interface=bridge-lan1 lease-time=24h name=dhcp-lan1
  27. add address-pool=dhcp_pool0 disabled=no interface=bridge-lan2 lease-time=24h name=dhcp-lan2
  28.  
  29. /ip pool
  30. add name=dhcp_pool1 ranges=192.168.100.2-192.168.100.254
  31. add name=dhcp_pool0 ranges=192.168.200.2-192.168.200.254
  32.  
  33. /ip address
  34. add address=192.168.100.1/24 interface=bridge-lan1 network=192.168.100.0
  35. add address=192.168.200.1/24 interface=bridge-lan2 network=192.168.200.0
  36.  
  37. /ip dhcp-server network
  38. add address=192.168.100.0/24 dns-server=192.168.100.1,192.168.5.1 domain=lan1.local gateway=192.168.100.1 netmask=24
  39. add address=192.168.200.0/24 dns-server=192.168.200.1,192.168.5.1 domain=lan2.local gateway=192.168.200.1 netmask=24
  40.  
  41. /ip firewall nat
  42. add action=masquerade chain=srcnat
  43. add action=dst-nat chain=dstnat dst-address=192.168.5.2 dst-port=25565 in-interface=bridge-wan protocol=tcp to-addresses=192.168.200.2 to-ports=25565
  44. add action=dst-nat chain=dstnat dst-address=192.168.5.2 dst-port=80 protocol=tcp to-addresses=192.168.200.2 to-ports=80
  45. add action=dst-nat chain=dstnat dst-address=192.168.5.2 dst-port=443 protocol=udp to-addresses=192.168.200.2 to-ports=443
  46. add action=dst-nat chain=dstnat dst-address=192.168.5.2 dst-port=443 protocol=tcp to-addresses=192.168.200.2 to-ports=443
  47.  
  48. /ip service
  49. set telnet disabled=yes
  50. set ftp disabled=yes
  51. set www disabled=yes
  52. set ssh disabled=yes
  53. set api disabled=yes
  54. set api-ssl disabled=yes
  55.  
  56. Excluded:
  57.  
  58. /interface list
  59. /interface lte apn
  60. /interface wireless security-profiles
  61. /interface list member
  62. /interface ovpn-server server
  63. /queue type
  64. /ip cloud
  65. /ip dns
  66. /ip firewall address-list
  67. /ip firewall filter (all rules deactivated)
  68. /system clock
  69. /system leds
  70.  
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement