MikroTik NAT Actions Explained with Examples
| Action | What it's for | Example |
|---|---|---|
masquerade |
Hide internal IPs going to the internet with a dynamic public IP | /ip firewall nat add chain=srcnat out-interface=pppoe-out1 action=masquerade |
src-nat |
Replace the source IP with a static public IP | /ip firewall nat add chain=srcnat out-interface=ether1 action=src-nat to-addresses=203.0.113.5 |
dst-nat |
Port forwarding to an internal host | /ip firewall nat add chain=dstnat in-interface=ether1 protocol=tcp dst-port=80 action=dst-nat to-addresses=192.168.88.10 to-ports=80 |
netmap |
1:1 translation of an IP or a whole subnet | /ip firewall nat add chain=srcnat src-address=192.168.88.10 action=netmap to-addresses=203.0.113.10 |
redirect |
Send traffic to a port on the router itself | /ip firewall nat add chain=dstnat protocol=udp dst-port=53 action=redirect to-ports=53 |
same |
Keep the same public IP per client from a pool (rarely used) | /ip firewall nat add chain=srcnat action=same to-addresses=203.0.113.1-203.0.113.3 |
accept |
Skip NAT for some traffic (e.g. site-to-site VPN) | /ip firewall nat add chain=srcnat src-address=192.168.88.0/24 dst-address=10.10.0.0/24 action=accept |
log |
Log matching packets for troubleshooting | /ip firewall nat add chain=srcnat protocol=tcp dst-port=21 action=log log-prefix="FTP-out" |
passthrough |
Count/mark and keep evaluating the next rules | Mostly used in mangle |
Tips:
- Rules are evaluated top-down: put
acceptexceptions abovemasquerade. - In
dst-natrules always setin-interface(ordst-address), otherwise you also redirect internal traffic. - To block traffic, use
/ip firewall filter, not NAT.
Related: MikroTik FastTrack.