PTT評價

[問題] ROS 雙PPPOE指定設備出口與HAIRPIN NAT

看板Broad_Band標題[問題] ROS 雙PPPOE指定設備出口與HAIRPIN NAT作者
qscgy4
(菜逼八)
時間推噓 1 推:1 噓:0 →:6

是這樣,
我有個RB750Gr3,

架構大概如下,
https://imgur.com/PMakKy6

我希望手機在內網,
可以透過 my_domain_B 連回NAS,
可是摸了好幾天還是不會弄,
請求協助。

/ip firewall address-list
add address=192.168.1.0/24 list=LAN_IP
add address=my_domain_A list=WAN_IP
add address=my_domain_B list=NEXTCLOUD_WAN_IP

/ip firewall mangle
add action=mark-connection chain=input in-interface=pppoe-out1 \
new-connection-mark=pppoe1_conn passthrough=yes
add action=mark-routing chain=output connection-mark=pppoe1_conn \
new-routing-mark=normal_wan passthrough=yes
add action=mark-connection chain=input in-interface=pppoe-out2 \
new-connection-mark=pppoe2_conn passthrough=yes
add action=mark-routing chain=output connection-mark=pppoe2_conn \
new-routing-mark=nextcloud_wan passthrough=yes

/ip firewall nat
add action=masquerade chain=srcnat comment="HAIRPIN NAT" dst-address=\
192.168.1.0/24 src-address=192.168.1.0/24
add action=masquerade chain=srcnat comment="Local to WAN" out-interface-list=\ WAN
add action=masquerade chain=srcnat comment="Local to LAN" disabled=yes \
out-interface-list=LAN
add action=dst-nat chain=dstnat comment="IP CAM_WANin" dst-address-list=\
WAN_IP dst-port=9999 protocol=tcp to-addresses=192.168.1.7 to-ports=8888
add action=dst-nat chain=dstnat comment=NextCloud_WANin dst-address-list=\
NEXTCLOUD_WAN_IP dst-port=80 protocol=tcp to-addresses=192.168.1.12 \
to-ports=80
add action=dst-nat chain=dstnat dst-address-list=NEXTCLOUD_WAN_IP dst-port=\
443 protocol=tcp to-addresses=192.168.1.12 to-ports=443

/ip route
add distance=1 gateway=pppoe-out1 routing-mark=normal_wan
add distance=1 gateway=pppoe-out2 routing-mark=nextcloud_wan
add distance=1 gateway=pppoe-out1
add distance=2 gateway=pppoe-out2

/ip route rule
add src-address=192.168.1.12/32 table=nextcloud_wan

/interface pppoe-client
add disabled=no interface=ether1 name=pppoe-out1 password=USRPWD1 \
use-peer-dns=yes user=USER1
add disabled=no interface=ether1 name=pppoe-out2 password=USRPWD2 \
use-peer-dns=yes user=USER2

--

※ PTT 留言評論
※ 發信站: 批踢踢實業坊(ptt.cc), 來自: 118.170.254.217 (臺灣)
PTT 網址

lianpig556603/22 17:09沒特殊需求的話,直接去設static dns,把該domain直

lianpig556603/22 17:09接對應到internal ip會不會比較快?

lianpig556603/22 17:15https://i.imgur.com/NSJS8ph.png 我自己是設MANGLE

tomsawyer03/23 07:43你是要全指給nas還是單port? 這好像會有loopback問題

fonzae03/24 01:37無法理解,為何要dual wan去轉送,沒意義

fonzae03/24 01:48https://i.imgur.com/HrAIEzp.jpg

fonzae03/24 01:49相同橋接,進來的位置若屬於local一率轉送內部srv