为什么 Mikrotik RouterOS 中的端口转发卡在 SYN_RECV?

为什么 Mikrotik RouterOS 中的端口转发卡在 SYN_RECV?

我想在我的 Mikrotik RouterOS 上设置端口->的tcp端口转发。8000192.168.1.16:4200

我已完成以下操作:

/ip firewall nat add dstnat chain=dstnat action=dst-nat to-addresses=192.168.1.16 to-ports=4200 protocol=tcp dst-address=<PUBLIC_IP> dst-port=8000

当我尝试通过互联网使用该服务时,以下命令就挂起了:

curl <PUBLIC_IP>:8000

我可以看到计数器在 Mikrotik 的 NAT 规则上移动(通过 WebBox)。

在目标机器上,我可以看到以下内容netstat -an | grep 4200

tcp        0      0 0.0.0.0:4200            0.0.0.0:*               LISTEN
tcp        0      0 192.168.1.16:4200       <REMOTE_HOST>:37720     SYN_RECV

我验证了我能够通过 本地连接到机器curl 192.168.1.16:4200

我不知道哪里出了问题 :(

更新:防火墙过滤规则:

/ip firewall filter
add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="fasttrack - except for ipsec" connection-mark=!ipsec connection-state=established,related
add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN

相关内容