Товарищи, помогите, сломал всю голову, понять не могу, ЧЯДНТ)! Есть веб сервер iis, висит на 9000 порту, за микротиком, нужно его высунуть наружу, пишу правила, а nat не отрабатывает... Хелп ми плиз(
Flags: X - disabled, I - invalid, D - dynamic # ADDRESS NETWORK INTERFACE 0 192.168.88.1/24 192.168.88.0 ether2-local 1 D 195.54.201.26/29 195.54.201.24 ether1-gateway
Flags: X - disabled, I - invalid, D - dynamic 0 D ;;; special dummy rule to show fasttrack counters chain=forward action=passthrough
1 chain=input action=accept protocol=icmp
2 chain=input action=accept connection-state=related,new log=no log-prefix=«1»
3 chain=input action=accept connection-state=established,related log=no log-prefix=«2»
4 chain=forward action=accept connection-state=related,new in-interface=ether1-gateway log=no log-prefix=«3»
5 chain=forward action=accept connection-state=established,related routing-mark=«» in-interface=ether1-gateway log=no log-prefix=«4»
6 chain=input action=accept src-address=!192.168.88.0/24 in-interface=ether1-gateway log=no log-prefix=«5»
7 chain=forward action=accept src-address=192.168.88.0/24 in-interface=!ether1-gateway log=no log-prefix=«6»
8 chain=forward action=accept src-address=192.168.88.0/24 out-interface=ether1-gateway log=no log-prefix=«»
9 chain=input action=accept protocol=tcp in-interface=ether1-gateway dst-port=9000 log=no log-prefix=«8»
10 chain=forward action=accept connection-state=established,related protocol=tcp in-interface=ether1-gateway dst-port=9000 log=no log-prefix=«»
Flags: X - disabled, I - invalid, D - dynamic 0 chain=srcnat action=masquerade src-address-list=local-lan log=no log-prefix=«»
1 chain=dstnat action=dst-nat to-addresses=192.168.88.249 to-ports=9000 protocol=tcp in-interface=ether1-gateway dst-port=9000 log=no log-prefix=«»
:(