- Добавляем UpnP Mikrotik
- MikroTik — настройка UPnP
- Manual:IP/UPnP
- Contents
- Summary
- Additional Resources
- General Properties
- UPnP Interfaces
- Configuration Example
- Инструкции по настройке MikroTik
- Настройка UPnP MikroTik, автоматический проброс портов
- Как настроить UPnP в MikroTik
- Описание параметров UPnP
- Активация режима UPnP
- Определить internal и external интерфейсы
- Пример настройки UPnP MikroTik в видеорегистраторе Dahua
- Активация UPnP в Dahua
- Пробросы портов через UPnP
- Introduction
- Configuration
- General properties
- UPnP Interfaces
- Configuration Example
Добавляем UpnP Mikrotik
UPnP (Universal Plug and Play) — универсальная автоматическая настройка сетевых устройств, автоматически открывает порты для p2p приложений, игр и т. д.
Именно эта штука и отвечает за то, что нужные порты будут открываться автоматически по запросу программы. Настройка достаточно простая и заключается всего нескольких нажатиях мышки.
Подключаемся к нашему Mikrotik через Winbox и открываем необходимый раздел:
Здесь достаточно поставить галочку Enable, но после этого все-равно ничего работать не будет. А все потому, что надо микротику сказать, что есть внешний интерфейс, а что внутренний. Для этого, в открытом ранее окошке находим кнопку Interfaces и нажимаем ее.
Сейчас у нас ничего нет и окно пустое. Жмем синий плюсик и добавляем два интерфейса.
External — это наш внешний интерфейс. У меня это pppoe-соединение с провайдером. У вас может быть так же, а если получаете по DHCP, то выбрать надо тот, где висит DHCP-клиент.
Internal — это наш внутренний интерфейс. У меня часть портов объединена в bridge, поэтому я выбираю интерфейс bridge-home. Вы же выбираете свой.
Теперь закрываем окошко настройки интерфейсов. Затем жмем Apply и Ok. Вот и все. После проделанных манипуляций порты на микротике будут открываться автоматически без вмешательства в его настройку.
То же самое можно сделать не только в графической оболочке, но и через терминал.
/ip upnp set enabled=yes show-dummy-rule=yes allow-disable-external-interface=no
/ip upnp interfaces add interface=pppoe-out1 type=external add interface=bridge-home type=internal
Проверить работает или нет довольно просто, для этого достаточно зайти в раздел IP->Firewall->NAT и посмотреть наличие новых правил с префиксом D. Если такие есть, значит все в порядке.
Источник
MikroTik — настройка UPnP
Никогда о такой штуке даже не слышал, но обратился клиент, которому необходимо было настроить данный протокол. UPnP (Universal Plug and Play) — универсальная автоматическая настройка сетевых устройств, автоматически открывает порты для p2p приложений, игр и так далее.
Заходим в Winbox, подключаемся к нашему MikroTik’у, затем переходим на вкладку «IP» — «UPnP».
Для включения ставим галочку напротив Enabled.
Теперь нужно указать интерфейсы, переходим в «Interfaces» и нажимаем «Add New».
Добавим внешний (External) WAN порт, обычно это ether1.
Добавим внутренний (Internal) порт или бридж, в моем случае я добавлял туда сразу Bridge (Бридж).
На этом настройка UPnP в MikroTik завершена.
Так же приведу пример как это будет выглядеть через консоль:
[admin@MikroTik] > ip upnp set enabled=yes
[admin@MikroTik] > ip upnp interfaces add interface=ether1-gateway type=external
[admin@MikroTik] > ip upnp interfaces add interface=bridge type=internal
Источник
Manual:IP/UPnP
Applies to RouterOS: 2.9, v3, v4 +
Contents
Summary
Sub-menu: /ip upnp
Packages required: system
The MikroTik RouterOS supports Universal Plug and Play architecture for transparent peer-to-peer network connectivity of personal computers and network-enabled intelligent devices or appliances.
UPnP enables data communication between any two devices under the command of any control device on the network. Universal Plug and Play is completely independent of any particular physical medium. It supports networking with automatic discovery without any initial configuration, whereby a device can dynamically join a network. DHCP and DNS servers are optional and will be used if available on the network. UPnP implements simple yet powerfull NAT traversal solution, that enables the client to get full two-way peer-to-peer network support from behind the NAT.
There are two interface types for UPnP: internal (the one local clients are connected to) and external (the one the Internet is connected to). A router may only have one external interface with a ‘public’ IP address on it, and as many internal interfaces as needed, all with source-NATted ‘internal’ IP addresses.
The UPnP protocol is used for many modern applications, like most of DirectX games, as well as for various Windows Messenger features (remote asisstance, application sharing, file transfer, voice, video) from behind a firewall.
Additional Resources
General Properties
| Property | Description |
|---|---|
| allow-disable-external-interface (yes | no ; Default: yes) | whether or not should the users be allowed to disable router’s external interface. This functionality (for users to be able to turn the router’s external interface off without any authentication procedure) is required by the standard, but as it is sometimes not expected or unwanted in UPnP deployments which the standard was not designed for (it was designed mostly for home users to establish their ownlocal networks), you can disable this behavior |
| enabled (yes | no ; Default: no) | Enable uPnP service |
| show-dummy-rule (yes | no ; Default: yes) | Enable a workaround for some broken implementations, which are handling the absense of UPnP rules incorrectly (for example, popping up error messages). This option will instruct the server to install a dummy (meaningless) UPnP rule that can be observed by the clients, which refuse to work correctly otherwise |
Warning: if you do not disable the allow-disable-external-interface, any user from the local network will be able (without any authentication procedures) to disable the router’s external interface.
UPnP Interfaces
Sub-menu: /ip upnp interfaces
| Property | Description |
|---|---|
| interface (string; Default: ) | Interface name on which uPnP will be running |
| type (external | internal; Default: no) | uPnP interface type:
|
| forced-external-ip (Ip; Default: ) | Allow to specify what public IP to use if external interface have more than one IP available. |
Note: It is highly recommended to upgrade DirectX runtime libraries to version DirectX 9.0c or higher and Windows Messenger to version Windows Messenger 5.0 or higher in order to get UPnP to work properly.
Note: In more complex setups with VLANs, where VLAN interface is considered as the LAN interface, the VLAN interface itself should be specified as the internal interface for UPnP to work properly.
Configuration Example
We have masquerading already enabled on our router:
To enable UPnP feature:
Now all we have to do is to add interfaces:
Источник
Инструкции по настройке MikroTik
Настройка UPnP MikroTik, автоматический проброс портов
В инструкции будет рассмотрена настройка UPnP в MikroTik, а в качестве наглядного примера будет подключён видеорегистратор Dahua. На выходе образуется инфраструктура, в которой нет необходимости пробрасывать порты для просмотра видеонаблюдения, UPnP полностью автоматизирует этот процесс.
MikroTik RouterOS поддерживает архитектуру Universal Plug and Play для прозрачного однорангового сетевого подключения персональных компьютеров и интеллектуальных устройств или устройств, подключенных к сети.
UPnP обеспечивает обмен данными между любыми двумя устройствами под управлением любого управляющего устройства в сети. Universal Plug and Play полностью не зависит от какого-либо физического носителя. Он поддерживает работу в сети с автоматическим обнаружением без какой-либо начальной настройки, в результате чего устройство может динамически присоединяться к сети. Серверы DHCP и DNS не являются обязательными и будут использоваться, если они доступны в сети. UPnP реализует простое, но мощное решение для обхода NAT, которое позволяет клиенту получить полную поддержку двусторонней одноранговой сети за NAT-ом.
Для UPnP существует два типа интерфейса: internal (тот, к которому подключены локальные клиенты) и external (тот, к которому подключен Интернет). Маршрутизатор может иметь только один внешний интерфейс с «общедоступным» IP-адресом и столько внутренних интерфейсов, сколько необходимо, все с «внутренними» IP-адресами с NAT.
Протокол UPnP используется для многих современных приложений, таких как большинство игр DirectX, а также для различных функций Windows Messenger (удаленная поддержка, совместное использование приложений, передача файлов, голос, видео) из-за брандмауэра.
Как настроить UPnP в MikroTik
Для того, чтобы роутер MikroTik начал взаимодействовать с другими устройствами по протоколу UPnP нужно:
- Активировать использование UPnP;
- Определить локальные(internal) и внешние(external) интерфейсы.
Описание параметров UPnP
enabled – активирует UPnP службу;
allow-disable-external-interface – следует ли разрешать пользователям отключать внешний интерфейс маршрутизатора MikroTik. Эта функция добавлена отдельным параметром и регулирует режим совместимости для тех сетей, где UPnP нежелателен или его работа не предусмотрена;
show-dummy-rule – активация обходного пути для некоторых неработающих реализаций, которые неправильно обрабатывают отсутствие правил UPnP (например, появляются сообщения об ошибках). Эта опция проинструктирует сервер установить фиктивное (бессмысленное) правило UPnP, которое могут соблюдать клиенты, которые в противном случае отказываются работать правильно.
Настройка находится IP→UPnP
Активация режима UPnP
Определить internal и external интерфейсы
Настройка находится IP→UPnP→Interfaces
Пример настройки UPnP MikroTik в видеорегистраторе Dahua
На любом устройстве, поддерживающего технологию UPnP достаточно включить данный режим. Все правила со стороны роутера MikroTik создадутся автоматически
Активация UPnP в Dahua
Пробросы портов через UPnP
Настройка находится IP→Firewall→NAT
Есть вопросы или предложения по настройке UPnP в MikroTik? Активно предлагай свой вариант настройки! Оставить комментарий →
Источник
Introduction
The MikroTik RouterOS supports Universal Plug and Play architecture for transparent peer-to-peer network connectivity of personal computers and network-enabled intelligent devices or appliances.
UPnP enables data communication between any two devices under the command of any control device on the network. Universal Plug and Play is completely independent of any particular physical medium. It supports networking with automatic discovery without any initial configuration, whereby a device can dynamically join a network. DHCP and DNS servers are optional and will be used if available on the network. UPnP implements a simple yet powerful NAT traversal solution, that enables the client to get full two-way peer-to-peer network support from behind the NAT.
There are two interface types for UPnP: internal (the one local clients are connected to) and external (the one the Internet is connected to). A router may only have one external interface with a ‘public’ IP address on it, and as many internal interfaces as needed, all with source-NATted ‘internal’ IP addresses. The protocol works by creating dynamic NAT entries.
The UPnP protocol is used for many modern applications, like most DirectX games, as well as for various Windows Messenger features like remote assistance, application sharing, file transfer, voice, video from behind a firewall.
Configuration
General properties
| Property | Description |
|---|---|
| allow-disable-external-interface (yes | no ; Default: yes) | whether or not should the users are allowed to disable the router’s external interface. This functionality (for users to be able to turn the router’s external interface off without any authentication procedure) is required by the standard, but as it is sometimes not expected or unwanted in UPnP deployments which the standard was not designed for (it was designed mostly for home users to establish their own local networks), you can disable this behavior |
| enabled (yes | no ; Default: no) | Enable UPnP service |
| show-dummy-rule (yes | no ; Default: yes) | Enable a workaround for some broken implementations, which are handling the absence of UPnP rules incorrectly (for example, popping up error messages). This option will instruct the server to install a dummy (meaningless) UPnP rule that can be observed by the clients, which refuse to work correctly otherwise |
If you do not disable the allow-disable-external-interface, any user from the local network will be able (without any authentication procedures) to disable the router’s external interface
UPnP Interfaces
| Property | Description |
|---|---|
| interface (string; Default: ) | Interface name on which uPnP will be running |
| type (external | internal; Default: no) | UPnP interface type:
|
| forced-external-ip (Ip; Default: ) | Allow specifying what public IP to use if the external interface has more than one IP available. |
In more complex setups with VLANs, where the VLAN interface is considered as the LAN interface, the VLAN interface itself should be specified as the internal interface for UPnP to work properly.
Configuration Example
We have masquerading already enabled on our router:
To enable the UPnP feature:
Now, all we have to do is to add interfaces:
Now once the client from the internal interface side will send UPnP request dynamic NAT rules will be created on the router, example rules could look something similar to these:
Источник