How to port forward on MikroTik

แชร์
ฝัง
  • เผยแพร่เมื่อ 28 พ.ย. 2024

ความคิดเห็น • 127

  • @mikrotik
    @mikrotik  2 ปีที่แล้ว +9

    Here is the link to the documentation about NAT: help.mikrotik.com/docs/display/ROS/NAT
    Have fun (seriously) :)

  • @seedered
    @seedered ปีที่แล้ว +10

    Awesome Saint Javelin t-shirt! Thanks for support both informational and hardware. Love you guys!

    • @iradeourum
      @iradeourum 6 หลายเดือนก่อน

      Is it a form of worship to governor's boot between breeches?

  • @Pun1sh3r1993
    @Pun1sh3r1993 2 ปีที่แล้ว +20

    Rule added by quickset is wrong. It will do dst-nat to all of packets coming from wan to lan AND from lan to wan. If you will add rule to port forward tcp:80 to 192.168.88.99:80, it will break all connections from lan to wan:80. It is because of in-interface or in-interface-list is not added.

    • @mikrotik
      @mikrotik  2 ปีที่แล้ว +12

      You are completelty right, good eye. We will fix this bug, thanks!

    • @johnrauner2515
      @johnrauner2515 2 ปีที่แล้ว

      Yes but you can add these in the NAT list. From his explanation this is clearly designed as a quick and simple way to forward specific individual ports to single IP's, not the blanket and generic forwarding you mentioned.

    • @TalOrmanda
      @TalOrmanda 2 ปีที่แล้ว +2

      @@mikrotik When are you fixing this? I just ran into this problem.

    • @magundah14
      @magundah14 2 ปีที่แล้ว

      @@mikrotik any update on this? I found a workaround, but having a simple way of port forwarding would be great

    • @ikhsannahdillah
      @ikhsannahdillah ปีที่แล้ว

      Thanks sir, its very help

  • @UlrichWessendorf
    @UlrichWessendorf 2 ปีที่แล้ว +27

    Nice T-Shirt, very strong statement!🔨💪

  • @horvisnone4997
    @horvisnone4997 27 วันที่ผ่านมา

    Good morning,
    I did it the same way as in your video with the difference that I have different ip address values. I think I should have it set up correctly. The only thing that bothers me is whether it works as it should. When I look into IP/Firewall/Nat - here I look at the created 4 port forwarding rules for one online game, so the first two rules are ( for port: 27015 and 27036 ) the other rules are for the TCP protocol and the others are the UDP protocol ( for the port: 27015 and 27031-27036 ) so I look at it and there is no data flowing at all. I still have 0 B in the Bytes column, so I doubt port forwarding is working for me :(

  • @ArthursHD
    @ArthursHD 2 ปีที่แล้ว +8

    UPNP can be dangerous :) Someone printed a page on 80'000 printers because of this. There's an episode of darknet diaries about it.
    So if your router, devices and software has UPNP enabled. It can open ports you don't know about and don't need to have open to the internet. Manually you can limit access from certain countries, an ISP, IP range or even a single IP address.

    • @mikrotik
      @mikrotik  2 ปีที่แล้ว +5

      You have to manually enable it also in the app, so at least you can’t have such things happen without knowing. Also, what printer needs to open ports from the internet? Curious 🤨😂

    • @hariranormal5584
      @hariranormal5584 2 ปีที่แล้ว

      Yep, UPNP is as dangerous as "manually opening ports"
      You need to have whatever program to actually open it, instead of you doing the opening manually you let the app do it.

    • @SZF123456
      @SZF123456 2 หลายเดือนก่อน

      I know I'm 2 years too late, but I have UPnP enabled for my video game consoles in a specific IP range on the network, then I've set up firewall rules to accept UPnP traffic from that range, and deny it from any other IP. This is the unfortunate reality for consoles to get better NAT, and ports to open for specific games.
      /ip firewall filter add chain=forward src-address=192.168.88.151-192.168.88.160 action=accept
      /ip firewall filter add chain=forward src-address=!192.168.88.151-192.168.88.160 action=drop
      Adjust IP's for your environment

  • @channel11121
    @channel11121 9 หลายเดือนก่อน

    You should add a Disable option into the Quick Set's Port Mapping, like in Firewall tab.

  • @Bamsepojken
    @Bamsepojken ปีที่แล้ว

    THANK YOU!,
    I finally got my minecraft server to work, i have littarly spent over 10h trying to fix it.....😄

  • @NokHerakhanza
    @NokHerakhanza 2 ปีที่แล้ว +2

    Saya dari indonesia terimakasih informasinya sangat membatu saya

  • @ChrisNicholson
    @ChrisNicholson 2 ปีที่แล้ว +7

    I am very "anti quickset". Opening Quickset and hitting apply on ANYTHING has broken running configurations, more than once.
    Could an option be added to hide quickset in winbox?
    Also... On NAT... Maybe show people how to use IP cloud to make NAT rules more specific.

    • @mikrotik
      @mikrotik  2 ปีที่แล้ว +5

      Quickset should not break anything, if you do encounter such a scenario, let us know. By the way, closing and not using Quickset is also an option :) Why disable

    • @LuLuXDCraft
      @LuLuXDCraft 2 ปีที่แล้ว +1

      ​@@mikrotik Quickset break the configuration when the PPPoE credential of the ISP need a VLAN Tag, if you apply you loose the connection. For the Quickset menu only eth1 or SFP can be WAN.
      But that not a big deal, more you dig in routerOS, less you need Quickset.

  • @mehdikhosravi8799
    @mehdikhosravi8799 3 หลายเดือนก่อน

    Hello, thank you for teaching how to port forward ipv6 in Mikrotik router❤❤❤

  • @hexandcube
    @hexandcube 5 หลายเดือนก่อน

    In case anyone is getting the "Couldn't add new port mapping - WAN port list is missing (6)" error message, here's how to fix it
    In Winbox, go to Interfaces>Interface List> Click on Lists > Add a new list and call it WAN > close the Interface Lists window>then in Interface List add your WAN interface to the WAN list

  • @izwanmohd
    @izwanmohd 2 ปีที่แล้ว +1

    We dont need to add any filter rules to allow the NAT connection?

  • @yuriylutsyshyn3495
    @yuriylutsyshyn3495 ปีที่แล้ว +2

    Yo have so cool t- thist, thank for wearing it ! Дякую вам за те, що ви з нами !

  • @emmanzki
    @emmanzki 11 หลายเดือนก่อน +1

    can i specify which ip addresses can connect on my network?

    • @mikrotik
      @mikrotik  11 หลายเดือนก่อน

      Yes, you can use the src-address property help.mikrotik.com/docs/display/ROS/NAT#NAT-Properties

  • @nikolashuminosky6987
    @nikolashuminosky6987 2 ปีที่แล้ว +2

    Hi normis,
    in the next video , would be able to explain us what input/output dose for NAT on v7

    • @mikrotik
      @mikrotik  2 ปีที่แล้ว +1

      you can use the new input chain for some rare and complex scenarios, where your address should be changed before or after routing actions take place, see stuffphilwrites.com/wp-content/uploads/2014/09/FW-IDS-iptables-Flowchart-v2019-04-30-1.png

  • @pavelperina7629
    @pavelperina7629 5 หลายเดือนก่อน

    Last time I understood this properly was when I configured firewall on Slackware Linux in 2003 or so for dial up internet and one small company using iptables.
    But what I found somewhat weird on Mikrotik - I could not make it work. I used textbook example from manual. I tried to copy this rule to input and forward and nothing, not a single packet captured by rules. After tens minutes, I disconnected phone from wifi, used termux and ssh, it worked. It somehow seems like if connection comes from internal network, to WAN IP address, it's not captured. Is there a way how to fix this? Something like if destination IP from whatever interface matches IP assigned to router by DHCP then forward port 2222 to homeserver:22?

    • @mikrotik
      @mikrotik  5 หลายเดือนก่อน

      Post your config on our forum forum.mikrotik.com

    • @pavelperina7629
      @pavelperina7629 5 หลายเดือนก่อน

      @@mikrotik Thanks, I solved it using claude ai. problem is missing SNAT rule for server reply - by default, it contacts client directly, so there's mismatch between request going to WAN IP and reply coming from server's IP.

  • @ramanabdelkhalek7957
    @ramanabdelkhalek7957 ปีที่แล้ว +1

    Thanks for explaining. I am new to mikrotik still it is interesting, I need suggestion and help please, I have two mikrotik routers having different isps as well as different local networks " each ", however I connected them to each other through interface " 4" and I need to forward SIP telephone from one mikrotik to another another, is there any guide to do that? Thanks in advance...

    • @mochouinard
      @mochouinard ปีที่แล้ว

      There is a lot of ways to do it depending of your requirements, but if your SIP server had a static IP, you could add a static route on your network where you have your SIP device and put your SIP server as the destination and put the gateway as the IP of your second router where you want the traffic to go though. Just make sure the second gateway have route to reach back the main client.

  • @javitech03
    @javitech03 ปีที่แล้ว

    A question ??? I have the Clients in PPPoE mode on the Mikrotiik CCR1009-7G-1C-1S+ but I want to add a MyCloudPR4100 NAS For Movies.. OK my Question how can I Install it on the Mikrotik CCR1009-7G-1C-1S+ So that my Clients can see it ???

  • @lorcster6694
    @lorcster6694 2 ปีที่แล้ว +1

    Why is your RouterOS set to v7.2.3, whereas mine is 6.49.6? Note: I have checked for updates and installed the latest updates according to my Winbox application. Perhaps you have different hardware and v6.49.6 is the latest OS for my hardware? Thank you for the video, and I love Mikrotik :)

    • @mikrotik
      @mikrotik  2 ปีที่แล้ว +4

      Choose upgrade channel UPGRADE, this at you can move to next big version

  • @Arkoss99
    @Arkoss99 ปีที่แล้ว

    hi i need help i used winbox used the firewall NAT setted up tcp and udp dstnat because you need both for rust server and still it doesnt work i need help :D

  • @dancar2537
    @dancar2537 หลายเดือนก่อน

    Mikrotik RB4011iGS+RM how many rules does this support?

    • @mikrotik
      @mikrotik  หลายเดือนก่อน +1

      No limit, you can make 1000, 2000 rules if you want.

    • @dancar2537
      @dancar2537 หลายเดือนก่อน

      @@mikrotik thank you

  • @TomHusband
    @TomHusband 2 ปีที่แล้ว

    I'm trying to figure out port forwarding but this doesn't look anything like my router which is model hAP ac Lite. I'm in the UK, are they different here?

    • @mikrotik
      @mikrotik  2 ปีที่แล้ว

      No, the interface is identical. Are you connecting to the right device? Send us a screen capture, email support@mikrotik.com and we will help

    • @symix.
      @symix. 2 ปีที่แล้ว

      @@mikrotik I had the same problem, but figured out quickly that I was running routerOS v6 still on my router -> no port mapping,
      I have had it for year, I always though System -> Auto Upgrade being empty that there were no updates available, found out now that the updating part is actually in quick set menu lol

  • @GaryLaaks1
    @GaryLaaks1 ปีที่แล้ว +2

    To the point and accurate. Thank you.

  • @mykyar9142
    @mykyar9142 ปีที่แล้ว +4

    Nice T-Shirt! Thanks from Ukraine! And thanks for the manual!

  • @shaunkaridza1579
    @shaunkaridza1579 2 ปีที่แล้ว

    I need help with a mikrotiq extender

  • @antonio90902
    @antonio90902 2 ปีที่แล้ว

    I open correctly port on pc, but block the internet connection why?

  • @achizalulhaq1974
    @achizalulhaq1974 ปีที่แล้ว

    i have container inside MikroTik, how to forward the port?

    • @mikrotik
      @mikrotik  ปีที่แล้ว

      We talk about it in this video th-cam.com/video/UMcJs4oyHDk/w-d-xo.html

  • @vash7839
    @vash7839 8 หลายเดือนก่อน

    I have a problem.
    Couldn't add new port mapping - WAN port list missing
    Can You help me?, please

    • @robkojabko
      @robkojabko 6 หลายเดือนก่อน

      have you ever solved this?

  • @skipperbentdk
    @skipperbentdk 4 หลายเดือนก่อน

    it doesn't port forward on LAN only the WAN / static ip... wtf is up with that - i don't get it

  • @TheDrAkira
    @TheDrAkira 2 ปีที่แล้ว

    Great, I added the Nat rule usign the advanced menu, but didn't work. Then I went to the same process using quickset and that did the trick. Strange, both rules were the same hahaha.

  • @Weleios
    @Weleios ปีที่แล้ว

    There is no button called port mapping in my winbox

  • @mrpyorplyt7877
    @mrpyorplyt7877 11 หลายเดือนก่อน

    i did all you said but still my freinds couldnt connect to my server

  • @MisticDW
    @MisticDW ปีที่แล้ว

    No port mapping button for me 🤷🏾‍♂️

  • @maddmethod5880
    @maddmethod5880 ปีที่แล้ว

    This must have been changed since then. following these instructions leads to an error "Couldn't add new port mapping - WAN port list is missing (6)"

    • @robkojabko
      @robkojabko 6 หลายเดือนก่อน

      have you ever solved this?

    • @maddmethod5880
      @maddmethod5880 6 หลายเดือนก่อน

      @@robkojabko yeah, I bought a ubiquiti UDM SE

    • @hexandcube
      @hexandcube 5 หลายเดือนก่อน

      ​@@robkojabko In Winbox, go to Interfaces>Interface List> Click on Lists > Add a new list and call it WAN > close the Interface Lists window>then in Interface List add your WAN interface to the WAN list

  • @afshinmohammadbagheri
    @afshinmohammadbagheri ปีที่แล้ว

    I have an Ubuntu server from America
    and I have a MIKROTIK device at home (local)
    I want to connect my Ubuntu server to Mikrotik at home using ssh port
    Because in Iran VPN works with ssh port
    When I connect the ssh port of Ubuntu server to Mikrotik, my web traffic can open all sites
    Like a VPN server can pass traffic
    I request you to send me the tutorial for this item
    Or tell me its instructions
    Or send me a video tutorial of it
    Here we are under very bad conditions in terms of filtering sites
    And we cannot connect to the sites

  • @GordiUA
    @GordiUA 2 ปีที่แล้ว +2

    Awesome background 💛💙

  • @Boatordie
    @Boatordie 2 หลายเดือนก่อน

    Does not work if you are on a vlan. Just set it up in the firewall settings but add "ALL VLAN" under in-interface. That's for kiwi's with Mikrotik. Love to hate it!

  • @channel11121
    @channel11121 9 หลายเดือนก่อน

    It's a good video, but if you're using Minecraft as an example, you should use port 25565, as you can mislead unfamiliar people. :)

  • @KnaufL
    @KnaufL 2 ปีที่แล้ว +3

    What about a video: how to setup 802.11r fast roaming? 😏

    • @KnaufL
      @KnaufL 2 ปีที่แล้ว +1

      @@orgind7778 the original comment was sarcastic and aiming at a lack of 802.11 k v r and wave 2 and wifi 6

  • @altmindo
    @altmindo 2 ปีที่แล้ว

    all i wish from winbox is ability to hide config menus for users :( there are so many i want to hide some for myself.

    • @mikrotik
      @mikrotik  2 ปีที่แล้ว +2

      There is such possibility. Will make a video about it

  • @petrmiskerik
    @petrmiskerik 2 ปีที่แล้ว +6

    That studio colors and Normis shirt, THX Normis/Mikrotik. You are AWESOME. SLAVA UKRAJINI !!!

  • @TheRealStevenPolley
    @TheRealStevenPolley 6 หลายเดือนก่อน

    valheim mentioned

  • @game47top
    @game47top 2 ปีที่แล้ว

    L2TP hungup disconnected every 2 minutes.
    I do not understand how incompatibility between devices of the same brand is possible.

    • @mikrotik
      @mikrotik  2 ปีที่แล้ว +2

      Need to check logs. Devices can’t be incompatible, but configuration can be incomplete

  • @BlackDwarfa
    @BlackDwarfa 2 ปีที่แล้ว

    hi, l2tp + ipsec is very slow, around 1Mbit. how to fix speed?

    • @mikrotik
      @mikrotik  2 ปีที่แล้ว +1

      On what kind of device?

    • @BlackDwarfa
      @BlackDwarfa 2 ปีที่แล้ว

      @@mikrotik CRS112-8G-4S-IN

    • @normis99
      @normis99 2 ปีที่แล้ว +2

      @@BlackDwarfa this is a switch. You need a router to do VPN

    • @BlackDwarfa
      @BlackDwarfa 2 ปีที่แล้ว

      @@normis99 ok, but it works. it's not big problem...

    • @urZcszyYo3TMEDmW
      @urZcszyYo3TMEDmW 2 ปีที่แล้ว +2

      move to wireguard?

  • @theguydanish9293
    @theguydanish9293 2 ปีที่แล้ว +7

    Very nice shirt!

  • @D9ID9I
    @D9ID9I 2 ปีที่แล้ว +8

    And let holy Javelin bless you.

  • @thomascroghan9255
    @thomascroghan9255 2 ปีที่แล้ว +2

    For the uninformed of us, the image on the shirts is one of "st. Javelin". A photoshopped icon of Mary hold a Javelin missile launcher.

    • @mikrotik
      @mikrotik  2 ปีที่แล้ว +2

      Not just that, it's a symbol for a movement

    • @alexandroskolkov2231
      @alexandroskolkov2231 2 ปีที่แล้ว +3

      @@mikrotik Wolfsangel it's a symbol too. as a black sun. what's your next t-short ?

    • @asphacean
      @asphacean ปีที่แล้ว

      ​@@alexandroskolkov2231 burned ruzzian flag

  • @janghoseo7529
    @janghoseo7529 2 ปีที่แล้ว +7

    Nice shirt!

  • @Shuna322
    @Shuna322 2 ปีที่แล้ว +11

    Hi from Ukraine 💛💙

  • @pabloc1519
    @pabloc1519 2 ปีที่แล้ว

    Love the t-shirt!

  • @Andrew_Thrift
    @Andrew_Thrift 2 ปีที่แล้ว +5

    Nice lighting !

    • @mikrotik
      @mikrotik  2 ปีที่แล้ว +3

      Thanks, hope you like the shirt too :)

    • @garyprice3757
      @garyprice3757 2 ปีที่แล้ว

      Maybe the next video could be on blocking Countries by IP address lists?

    • @blackland1233
      @blackland1233 2 ปีที่แล้ว +4

      @@mikrotik I was a mikrotik user, but no more. Instead of you working on network related topics, here you go promoting weaponry and death by association. Team Ubiquiti it is from now on 🙂
      Nice way loosing your customers.

  • @Lann91
    @Lann91 2 ปีที่แล้ว +6

    Nice shirt 🚀

  • @j7ndominica051
    @j7ndominica051 2 ปีที่แล้ว +2

    MIkrotik now focused mainly on consumer applications. Minecraft, seriously? Don't you need to specify the dst.address literally, or dst. address type 'local', so it only acts on the router's IPs? That's how I've always set up dst-nat.

    • @mikrotik
      @mikrotik  2 ปีที่แล้ว +7

      We still make 100Gbit switches and routers, check our other videos.
      Yes, there are many ways to set up DST-NAT, you can specify interfaces etc. There are many ways to set up a MikroTik ;)

    • @romain3877
      @romain3877 2 ปีที่แล้ว +5

      Technically, profesionnal/power user know what is a NAT and how it works. it's more for home user who have a mikrotik router in their home (from their ISP for exemple).

  • @Antonio-hx6vw
    @Antonio-hx6vw ปีที่แล้ว

    Great t-short 😇

  • @GonZOo2007
    @GonZOo2007 2 ปีที่แล้ว +2

    25565

  • @ApertureDG
    @ApertureDG ปีที่แล้ว

    Like for T-Shirt

  • @Oleksandr_Jerszow
    @Oleksandr_Jerszow 2 ปีที่แล้ว +2

    Nice T-Shirt and background

  • @samram8489
    @samram8489 2 ปีที่แล้ว +3

    Love the t-shirt lol

  • @yuriymatushkevych1527
    @yuriymatushkevych1527 ปีที่แล้ว

    Дякую!!!

  • @johnrauner2515
    @johnrauner2515 2 ปีที่แล้ว

    1:32 until he stops talking about the obvious and starts explaining how to do it

    • @johnrauner2515
      @johnrauner2515 2 ปีที่แล้ว

      Actually mate I think everything you said before 1:32 is the very reason why somebody would watch your video in the first place.

    • @johnrauner2515
      @johnrauner2515 2 ปีที่แล้ว

      When you did get on topic your advice and description was clear and precise and easy to follow. Thank you. Really helpful.

  • @r4jin
    @r4jin 6 หลายเดือนก่อน

    Why couldn't you just simply cast the desktop screen instead of showing a fancy studio...... seriously........................................ try following the video on your own

    • @r4jin
      @r4jin 6 หลายเดือนก่อน

      the more I watch the angrier I get. seriously...

  • @OlegShevtsov512
    @OlegShevtsov512 2 ปีที่แล้ว +1

    Thanks, nice t-shirt

  • @mioqwe
    @mioqwe 2 ปีที่แล้ว

    Why when i trying to telnet (public ip : forwarded port) , in terminal shows up this massage: 04:49:26 echo: system,error,critical login failure for user enable from 89.37.95.164 via telnet. And when i paste my public ip in search - it redirects me to Mikrotik login page

    • @mioqwe
      @mioqwe 2 ปีที่แล้ว

      And my friends cant connect to minecraft server :) Слава Україні!!!

  • @amateurwizard
    @amateurwizard 2 ปีที่แล้ว +3

    Nice T-Shirt 👌

  • @JTwisted
    @JTwisted 2 ปีที่แล้ว +8

    Nice shirt)

  • @AlexandrStiopkin
    @AlexandrStiopkin 2 ปีที่แล้ว

    Cool t-shirt!

  • @henriquealexandreh
    @henriquealexandreh 2 ปีที่แล้ว

    Wine sucks! Mikrotik should build a proper Winbox for MacOS.

    • @mikrotik
      @mikrotik  2 ปีที่แล้ว +2

      Did you watch the video at all? 🙄

    • @supra107
      @supra107 2 ปีที่แล้ว +1

      Skip to 7:05 and listen closely.

  • @dnirox
    @dnirox 2 ปีที่แล้ว +5

    T-shirt 5+

  • @danylokulbachinskiy1130
    @danylokulbachinskiy1130 10 หลายเดือนก่อน

    like

  • @crohammer
    @crohammer 2 ปีที่แล้ว

    Nice T-shirt Javelin for more freedom 🙄

  • @AlanMcKay
    @AlanMcKay ปีที่แล้ว +1

    God bless Saint Javelin! Slava Ukraini!

  • @turisti130
    @turisti130 ปีที่แล้ว

    fuu

  • @gang_albanii
    @gang_albanii ปีที่แล้ว

    great tutorial except it is not working on default mikrotik config. congratulations for posting not working tutorial