- Upraveno
Že by ten android? Já tam mám zatím Android 11 a po upgradu to taky nějakou chvíli nefungovalo, musel jsem to vypnout a zase zapnout.....
Skus to v tom telefonu vypnout a restartovat a pak zase zapnout a restartovat co to udělá.
Na mikrotiku skoukni firewall zda máš povolené ty příchozí porty atd.....
Já tam mám:
/ip firewall filter
add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=accept chain=input comment="Moje IP OK" src-address-list=moje_ip
add action=drop chain=input comment="Co nen\ED z CZ blokujeme" in-interface-list=!LAN src-address-list=!CountryIPBlocks
add action=accept chain=input comment="Povoleno icmp filtrovano v RAW" protocol=icmp
add action=drop chain=input comment="invalid drop" connection-state=invalid
add action=accept chain=input comment="VPN: allow IKE" dst-port=500 protocol=udp
add action=accept chain=input comment="VPN: allow L2TP" dst-port=1701 protocol=udp
add action=accept chain=input comment="VPN: allow IPsec NAT-T" dst-port=4500 protocol=udp
add action=accept chain=input protocol=ipsec-ah
add action=accept chain=input protocol=ipsec-esp
add action=accept chain=input comment="Pristup k routeru (ssh, https)" connection-state=new dst-port=801,8585 protocol=tcp
add action=accept chain=input comment="BTest server" disabled=yes dst-port=2000-2009 protocol=udp
add action=accept chain=input comment="BTest server" disabled=yes dst-port=2000-2009 protocol=tcp
add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN log-prefix="droop neni z LAN"
add action=drop chain=forward comment="Disable internet IP 192.168.1.99" out-interface-list=WAN src-address=192.168.1.99
add action=fasttrack-connection chain=forward comment=Fasttrack connection-state=established,related hw-offload=yes
add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked
add action=accept chain=forward comment="Moje IP OK" src-address-list=moje_ip
add action=drop chain=forward comment="Co nen\ED z CZ blokujeme" in-interface-list=!LAN src-address-list=!CountryIPBlocks
add action=accept chain=forward comment="Povoleno icmp filtrov\E1no v RAW" protocol=icmp
add action=drop chain=forward comment="invalid drop" connection-state=invalid
add action=accept chain=forward comment="ssh (ssh, nas, htpc)" connection-state=new disabled=yes dst-port=22,806,812 protocol=tcp
add action=accept chain=forward comment="Tv headend" connection-state=new disabled=yes dst-address=192.168.1.12 dst-port=9981 protocol=tcp
add action=accept chain=forward comment="Voip telefon" connection-state=new disabled=yes dst-address=192.168.1.20 dst-port=8586 protocol=tcp
add action=accept chain=forward comment="rsync nas" connection-state=new disabled=yes dst-address=192.168.1.6 dst-port=873 protocol=tcp
add action=accept chain=forward comment=Wol dst-address=192.168.1.12 dst-port=9 protocol=udp
add action=drop chain=forward comment="defconf: drop bad forward IPs" src-address-list=no_forward_ipv4
add action=drop chain=forward comment="defconf: drop bad forward IPs" dst-address-list=no_forward_ipv4
add action=drop chain=forward comment="Neni z LAN" in-interface-list=!LAN
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface-list=WAN
add action=dst-nat chain=dstnat comment=Tvheadend disabled=yes dst-port=9981 in-interface-list=WAN protocol=tcp to-addresses=192.168.1.12 \
to-ports=9981
add action=dst-nat chain=dstnat comment="ssh htpc" disabled=yes dst-port=812 in-interface-list=WAN protocol=tcp to-addresses=192.168.1.12 \
to-ports=812
add action=dst-nat chain=dstnat comment="ssh nas" dst-port=806 in-interface-list=WAN protocol=tcp to-addresses=192.168.1.6
add action=dst-nat chain=dstnat comment="Voip telefon" disabled=yes dst-port=8586 in-interface-list=WAN protocol=tcp to-addresses=192.168.1.20 \
to-ports=8586
add action=dst-nat chain=dstnat comment="WWW HTPC" disabled=yes dst-port=443 in-interface-list=WAN protocol=tcp to-addresses=192.168.1.12
add action=dst-nat chain=dstnat comment="HTPC Wol" dst-port=9 in-interface-list=WAN protocol=udp to-addresses=192.168.1.12 to-ports=9