[more] [more]
Цитата: Тогда нужно изучать проблему.
1. Создаем правило
/ip fi mangle add action=passthrough in-interface=ether1-wan protocol=tcp dst-port=8129 log=yes chain=prerouting comment=wan-winbox
2. Ставим его самым верхним
/ip fi mangle move [find comment=wan-winbox] destination=0
3. Пробуем подключиться и смотрим попало ли что нибудь логи
вот тут попало, только самое интересное что он в оконцове написал "connected", а по факту тот же еrror
http://s017.radikal.ru/i421/1605/cc/a631d150f4d4.jpg Цитата: Desrozen
Правила фаэрвола приведи
Код: /ip firewall filter
add chain=input comment="default configuration" protocol=icmp
add chain=input comment="default configuration" connection-state=\
established,related src-address-list=\
"192.168.0.2; 192.168.2.0/24; xx.xx.xx.xxx"
add chain=input comment="default configuration" in-interface=ether1-gateway \
src-address-list="xx.xx.xx.xxx; yyy.yyy.yy.yyy"
add chain=forward comment="default configuration" connection-state=\
established,related
add action=drop chain=forward comment="default configuration" connection-state=\
invalid
add action=drop chain=forward comment="default configuration" \
connection-nat-state=!dstnat connection-state=new in-interface=\
ether1-gateway
add chain=input protocol=udp
add chain=input protocol=udp
add chain=output protocol=tcp src-port=60001
add chain=input src-address=zz.zz.zzz.zzz
add chain=input dst-address=zz.zz.zzz.zzz
/ip firewall mangle
add action=passthrough chain=prerouting comment=wan-winbox dst-port=8129 \
in-interface=ether1-gateway log=yes protocol=tcp
/ip firewall nat
add action=masquerade chain=srcnat comment="default configuration" \
out-interface=ether1-gateway
add action=dst-nat chain=dstnat dst-port=41389 in-interface=ether1-gateway \
protocol=tcp to-addresses=192.168.0.2 to-ports=3389
add action=dst-nat chain=dstnat dst-port=41808 in-interface=ether1-gateway \
protocol=tcp to-addresses=192.168.0.200 to-ports=8080
add action=dst-nat chain=dstnat dst-port=555 in-interface=ether1-gateway \
protocol=tcp to-addresses=192.168.0.200 to-ports=555
add action=dst-nat chain=dstnat dst-port=48433 in-interface=ether1-gateway \
protocol=tcp to-addresses=192.168.0.2 to-ports=1433
add action=dst-nat chain=dstnat dst-port=3080 in-interface=ether1-gateway \
protocol=tcp to-addresses=192.168.0.200 to-ports=3080
add action=dst-nat chain=dstnat dst-port=3081 in-interface=ether1-gateway \
protocol=tcp to-addresses=192.168.0.200 to-ports=3081
add action=dst-nat chain=dstnat dst-port=5555 in-interface=ether1-gateway \
protocol=tcp to-addresses=192.168.0.106 to-ports=5555
add action=dst-nat chain=dstnat dst-port=41809 in-interface=ether1-gateway \
protocol=tcp to-addresses=192.168.0.230 to-ports=3389
add action=netmap chain=dstnat comment=Video dst-port=8080 in-interface=\
ether1-gateway protocol=tcp to-addresses=192.168.0.200 to-ports=8080
add action=netmap chain=dstnat comment=FTP dst-port=21 in-interface=\
ether1-gateway protocol=tcp to-addresses=192.168.0.2 to-ports=21
add action=netmap chain=dstnat comment="RDP Server" dst-port=39390 \
in-interface=ether1-gateway protocol=tcp to-addresses=192.168.0.2 to-ports=\
3389
add action=netmap chain=dstnat comment="RDP Personal" in-interface=\
ether1-gateway protocol=tcp to-addresses=192.168.0.2 to-ports=3389