Mikrotik + firewall + ssh access

Добрый день.


Есть железка RB1100AHx2

с таким конфигом:

# nov/21/2014 09:58:55 by RouterOS 6.7
# software id = UPCL-YIQ0
/interface ethernet
set [ find default-name=ether2 ] master-port=ether1
set [ find default-name=ether3 ] master-port=ether1
set [ find default-name=ether4 ] master-port=ether1
set [ find default-name=ether5 ] master-port=ether1
set [ find default-name=ether7 ] master-port=ether6
set [ find default-name=ether8 ] master-port=ether6
set [ find default-name=ether9 ] master-port=ether6
set [ find default-name=ether10 ] master-port=ether6
/interface vrrp
add interface=ether1 name=vrrp0 priority=254
/interface ethernet switch
set 0 name=OfficeSwitch
set 1 name=DMZSwitch
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip hotspot user profile
set [ find default=yes ] idle-timeout=none keepalive-timeout=2m mac-cookie-timeout=3d
/ip pool
add name=DHCP-Pool ranges=
/ip dhcp-server
add add-arp=yes address-pool=DHCP-Pool disabled=no interface=vrrp0 lease-time=1h name=router
set 0 name=serial0
set 1 name=serial1
/interface ethernet switch vlan
add independent-learning=no ports=ether9,ether10 switch=DMZSwitch vlan-id=30
/ip address
add address= comment=OfficeLAN interface=ether1 network=
add address= interface=vrrp0 network=
add address= interface=ether6 network=
/ip dhcp-server lease
add address= client-id=VD mac-address=60:A4:4C:A9:CC:C1 server=router
/ip dhcp-server network
add address= dns-server= gateway=
/ip dns
set allow-remote-requests=yes cache-max-ttl=1h servers=
/ip dns static
add address= name=router
/ip firewall filter
add chain=input comment="Allow Ping" protocol=icmp
add chain=forward protocol=icmp
add chain=input comment="Accept established connections" connection-state=established
add chain=forward connection-state=established
add chain=input comment="Accept related connections" connection-state=related
add chain=forward connection-state=related
add action=drop chain=input comment="Drop invalid connections" connection-state=invalid
add action=drop chain=forward connection-state=invalid
add chain=input comment="Allow UDP" protocol=udp
add chain=forward protocol=udp
add chain=forward comment="Access to Internet from local network" in-interface=vrrp0 src-address=
add chain=input comment="Access to Mikrotik only from our local network" src-address=
add chain=forward dst-address= dst-port=3389 protocol=tcp src-port=""
add chain=input src-address=
add chain=forward src-address=
add action=drop chain=input comment="All other drop"
add action=drop chain=forward
/ip firewall nat
add action=src-nat chain=srcnat out-interface=ether6 to-addresses=
add action=dst-nat chain=dstnat dst-address= protocol=tcp to-addresses= to-ports=3389
/ip firewall service-port
set pptp ports=1723
/ip route
add distance=1 gateway=
/ip service
set telnet disabled=yes
set ftp disabled=yes
set ssh port=50022
set www-ssl disabled=no
/system clock
set time-zone-name=Europe/Kiev
/system identity
set name=router
/system logging
add topics=telephony,debug
/system ntp client
set enabled=yes mode=unicast primary-ntp= secondary-ntp=


SSH висит на порту 50022. Из внутренней сети я на него попадаю, а вот с адреса - никак.

Может кто-то сможет подсказать, как решить эту элементарную задачку. Вроде бы все правильно делаю.

А в дампе пакеты долетают от до вашего Ether6 при попытке соедениться?

