MikroTik NAT Actions Explained with Examples

Action What it's for Example
masquerade Hide internal IPs going to the internet with a dynamic public IP /ip firewall nat add chain=srcnat out-interface=pppoe-out1 action=masquerade
src-nat Replace the source IP with a static public IP /ip firewall nat add chain=srcnat out-interface=ether1 action=src-nat to-addresses=203.0.113.5
dst-nat Port forwarding to an internal host /ip firewall nat add chain=dstnat in-interface=ether1 protocol=tcp dst-port=80 action=dst-nat to-addresses=192.168.88.10 to-ports=80
netmap 1:1 translation of an IP or a whole subnet /ip firewall nat add chain=srcnat src-address=192.168.88.10 action=netmap to-addresses=203.0.113.10
redirect Send traffic to a port on the router itself /ip firewall nat add chain=dstnat protocol=udp dst-port=53 action=redirect to-ports=53
same Keep the same public IP per client from a pool (rarely used) /ip firewall nat add chain=srcnat action=same to-addresses=203.0.113.1-203.0.113.3
accept Skip NAT for some traffic (e.g. site-to-site VPN) /ip firewall nat add chain=srcnat src-address=192.168.88.0/24 dst-address=10.10.0.0/24 action=accept
log Log matching packets for troubleshooting /ip firewall nat add chain=srcnat protocol=tcp dst-port=21 action=log log-prefix="FTP-out"
passthrough Count/mark and keep evaluating the next rules Mostly used in mangle

Tips:

  • Rules are evaluated top-down: put accept exceptions above masquerade.
  • In dst-nat rules always set in-interface (or dst-address), otherwise you also redirect internal traffic.
  • To block traffic, use /ip firewall filter, not NAT.

Related: MikroTik FastTrack.

Written by Daniel Ruiz Peláez, Systems & Infrastructure Engineer (Linux, VMware, Proxmox, Active Directory, networking and security). These are notes from real problems I have solved.

← Back to all posts