# sep/29/2021 22:43:36 by RouterOS 6.44.5
# software id = HPD7-5M08
#
# model = RB941-2nD
# serial number = A1C30BC77780
/ip firewall filter
add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related
add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface-list=WAN
add action=netmap chain=dstnat comment="Minecraft LAN" in-interface=all-ethernet log=yes log-prefix="mine\?" protocol=tcp to-addresses=192.168.88.223 to-ports=40000-65535
add action=netmap chain=dstnat comment="Server utils like SSH, FTP, etc." in-interface=all-ethernet log=yes log-prefix=secserver protocol=tcp to-addresses=192.168.88.156 to-ports=31150-31200
add action=netmap chain=dstnat comment=Server in-interface=all-ethernet protocol=tcp to-addresses=192.168.88.156 to-ports=40000-65535
И ты уверен, что порты именно 40000-65535?
Проверьте открыт ли порт на сайте 2ip.ru. там когда пойдет запрос, в фаерволе микротика должен меняться счетчик пакетов, в большую сторону... если меняется - с правилом ок, вопрос к линуксу
Зачем ты текст прикрепляешь в виде картники?
Закрыто фаирволом.
И да, твой IP 128.74.168.163, что там на скриншотах за попытка проверять 185.29.237.91 непонятно.Это скриншот-пример из инета.
И какие это правила? Только пожалуйста текстом, а не картинкой.
INPUT -p tcp -m tcp --dport 40000:65535 -j ACCEPT
INPUT -p udp -m udp --dport 40000:65535 -j ACCEPT
OUTPUT -p tcp -m tcp --dport 40000:65535 -j ACCEPT
OUTPUT -p udp -m udp --dport 40000:65535 -j ACCEPT
/ip address export
с MikroTIK и мы это выясним точно. # oct/02/2021 19:30:26 by RouterOS 6.44.5
# software id = HPD7-5M08
#
# model = RB941-2nD
# serial number = A1C30BC77780
/ip address
add address=192.168.88.1/24 comment=defconf interface=ether2 network=\
192.168.88.0
[admin@MikroTik] > /ip address print
Flags: X - disabled, I - invalid, D - dynamic
# ADDRESS NETWORK INTERFACE
0 ;;; defconf
192.168.88.1/24 192.168.88.0 ether2
1 D 128.74.168.163/21 128.74.168.0 ether1
~$ sudo nmap -sT -p- 128.74.168.163
PORT STATE SERVICE
49664/tcp open unknown
49665/tcp open unknown
49666/tcp open unknown
49667/tcp open unknown
49671/tcp open unknown
49677/tcp open unknown
49678/tcp open unknown
54288/tcp open unknown
54333/tcp open unknown
Ты уверен, что праило NAT для проброса порта на компьютер ничем кроме IP не отличается от правила дл проброса порта на сервер?
Ты уверен, что приложение на сервере слушает порт 53115, а не какой-то из этого списка?
И да, используй WinBox или консоль.
Проверить доступен ли TCP порт c Mikrotika можно так
[admin@MikroTik] > /system telnet 192.168.88.156 53115
Trying 192.168.88.156...
Connected to 192.168.88.156.
Escape character is '^]'.
Connection closed by foreign host.
add action=masquerade chain=srcnat comment="defconf: masquerade" disabled=yes \
ipsec-policy=out,none out-interface-list=WAN
add action=netmap chain=dstnat comment="Minecraft LAN" disabled=yes \
in-interface=all-ethernet log=yes log-prefix="mine\?" protocol=tcp \
to-addresses=192.168.88.223 to-ports=40000-65535
add action=netmap chain=dstnat comment="Server utils like SSH, FTP, etc." \
disabled=yes in-interface=all-ethernet log=yes log-prefix=secserver \
protocol=tcp to-addresses=192.168.88.156 to-ports=31150-31200
add action=dst-nat chain=dstnat comment=Server disabled=yes in-interface=\
ether1 protocol=tcp to-addresses=192.168.88.156 to-ports=40000-65535
add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=\
out,none out-interface-list=WAN
add action=dst-nat chain=dstnat comment="Minecraft LAN" dst-port=40000-65535 \
in-interface-list=WAN log=yes log-prefix="mine\?" protocol=tcp \
to-addresses=192.168.88.223
add action=dst-nat chain=dstnat comment="Server utils like SSH, FTP, etc." \
dst-port=31150-31200 in-interface-list=WAN log=yes log-prefix=secserver \
protocol=tcp to-addresses=192.168.88.156
add action=dst-nat chain=dstnat comment=Server dst-port=40000-65535 \
in-interface-list=WAN log=yes log-prefix=server protocol=tcp to-addresses=\
192.168.88.1
add action=dst-nat chain=dstnat comment="Server UDP" dst-port=40000-65535 \
in-interface-list=WAN protocol=udp to-addresses=192.168.88.156
add action=dst-nat chain=dstnat comment=Server_test dst-address=128.74.168.163 \
dst-port=53115 protocol=tcp to-addresses=192.168.88.156 to-ports=53115
add action=masquerade chain=srcnat comment="defconf: masquerade" disabled=yes \
ipsec-policy=out,none out-interface-list=WAN
add action=netmap chain=dstnat comment="Minecraft LAN" disabled=yes \
in-interface=all-ethernet log=yes log-prefix="mine\?" protocol=tcp \
to-addresses=192.168.88.223 to-ports=40000-65535
add action=netmap chain=dstnat comment="Server utils like SSH, FTP, etc." \
disabled=yes in-interface=all-ethernet log=yes log-prefix=secserver \
protocol=tcp to-addresses=192.168.88.156 to-ports=31150-31200
add action=dst-nat chain=dstnat comment=Server disabled=yes in-interface=\
ether1 protocol=tcp to-addresses=192.168.88.156 to-ports=40000-65535
add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=\
out,none out-interface-list=WAN
add action=dst-nat chain=dstnat comment="Minecraft LAN" disabled=yes dst-port=\
40000-65535 in-interface-list=WAN log=yes log-prefix="mine\?" protocol=tcp \
to-addresses=192.168.88.223
add action=dst-nat chain=dstnat comment="Server utils like SSH, FTP, etc." \
disabled=yes dst-port=31150-31200 in-interface-list=WAN log=yes \
log-prefix=secserver protocol=tcp to-addresses=192.168.88.156
add action=dst-nat chain=dstnat comment="Server Mine" dst-port=53115 \
in-interface-list=WAN log=yes log-prefix=server protocol=tcp to-addresses=\
192.168.88.1
add action=dst-nat chain=dstnat comment="Server Mine UDP" dst-port=53115 \
in-interface-list=WAN protocol=udp to-addresses=192.168.88.156
add action=masquerade chain=srcnat comment="defconf: masquerade" disabled=yes \
ipsec-policy=out,none out-interface-list=WAN
add action=netmap chain=dstnat comment="Minecraft LAN" disabled=yes \
in-interface=all-ethernet log=yes log-prefix="mine\?" protocol=tcp \
to-addresses=192.168.88.223 to-ports=40000-65535
add action=netmap chain=dstnat comment="Server utils like SSH, FTP, etc." \
disabled=yes in-interface=all-ethernet log=yes log-prefix=secserver \
protocol=tcp to-addresses=192.168.88.156 to-ports=31150-31200
add action=dst-nat chain=dstnat comment=Server disabled=yes in-interface=\
ether1 protocol=tcp to-addresses=192.168.88.156 to-ports=40000-65535
add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=\
out,none out-interface-list=WAN
add action=dst-nat chain=dstnat comment="Minecraft LAN" disabled=yes dst-port=\
40000-65535 in-interface-list=WAN log=yes log-prefix="mine\?" protocol=tcp \
to-addresses=192.168.88.223
add action=dst-nat chain=dstnat comment="Server utils like SSH, FTP, etc." \
disabled=yes dst-port=31150-31200 in-interface-list=WAN log=yes \
log-prefix=secserver protocol=tcp to-addresses=192.168.88.156
add action=dst-nat chain=dstnat comment="Server Mine" dst-port=53115 \
in-interface-list=WAN log=yes log-prefix=server protocol=tcp to-addresses=\
192.168.88.156
server dstnat: in:ether1 out:(unknown 0), src-mac a4:a1:c2:28:65:3b, proto TCP (SYN), 178.140.41.110:63927->128.74.168.163:53115, len 52
to-addresses=192.168.88.1
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface-list=WAN
add action=dst-nat chain=dstnat comment="Minecraft LAN" in-interface-list=WAN log=yes log-prefix="mine\?" protocol=tcp to-addresses=192.168.88.223 dst-port=40000-65535
add action=dst-nat chain=dstnat comment="Server utils like SSH, FTP, etc." in-interface-list=WAN log=yes log-prefix=secserver protocol=tcp to-addresses=192.168.88.156 dst-port=31150-31200
add action=dst-nat chain=dstnat comment=Server in-interface-list=WAN protocol=tcp to-addresses=192.168.88.156 dst-port=40000-65535
Желательно объяснять как чайнику в стиле "тыкни вот сюда, выбери вот это", поскольку с микротами я даже не на "Вы".