UPNP for firewalled Mikrotiks

Universal Plug and Plug is a technology that can automatically open a port forward from your home router to a P.C.

This is an essential technology for the likes of home games consoles and Xbox Live to get that Open NAT setting; in a business enviroment I’d rather leave it disabled.

With firewall filter rules enabled on a Mikrotik UPNP is useless, unless you have one special rule:

add chain=forward connection-nat-state=dstnat in-interface=[inbound-interface]

This rule permits the connection through the firewall if it is to a port that is forwarded, even those through UPNP.

Make sure to place this rule in an appropriate place in case you are restricting access to any other ports!






Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.