Moving the firewall rules up didn't help:
Code:
[admin@MikroTik] > /ip firewall filter printFlags: X - disabled, I - invalid; D - dynamic 0 D ;;; special dummy rule to show fasttrack counters chain=forward action=passthrough 1 ;;; defconf: accept established,related,untracked chain=input action=accept connection-state=established,related,untracked 2 ;;; defconf: drop invalid chain=input action=drop connection-state=invalid 3 ;;; defconf: accept ICMP chain=input action=accept protocol=icmp 4 ;;; defconf: accept to local loopback (for CAPsMAN) chain=input action=accept dst-address=127.0.0.1 5 ;;; blueiris tcp port 81 chain=forward action=accept protocol=tcp in-interface-list=WAN dst-port=81 log=yes log-prefix="blueiris" 6 ;;; blueiris udp port 81 chain=forward action=accept protocol=udp in-interface-list=WAN dst-port=81 log=yes log-prefix="blueiris" 7 ;;; defconf: drop all not coming from LAN chain=input action=drop in-interface-list=!LAN 8 ;;; defconf: accept in ipsec policy chain=forward action=accept ipsec-policy=in,ipsec 9 ;;; defconf: accept out ipsec policy chain=forward action=accept ipsec-policy=out,ipsec 10 ;;; defconf: fasttrack chain=forward action=fasttrack-connection hw-offload=yes connection-state=established,related 11 ;;; defconf: accept established,related, untracked chain=forward action=accept connection-state=established,related,untracked 12 ;;; defconf: drop invalid chain=forward action=drop connection-state=invalid 13 ;;; defconf: drop all from WAN not DSTNATed chain=forward action=drop connection-state=new connection-nat-state=!dstnat in-interface-list=WAN
Statistics: Posted by keg415 — Thu Jan 30, 2025 9:41 pm