MikroTik RouterOS NAT: Masquerade and dst-nat Rules - 夜莺博客

MikroTik RouterOS NAT: Masquerade and dst-nat Rules

RouterOS NAT is simple on the surface and full of edges: masquerade behaves differently from src-nat when the uplink address changes, dst-nat rules need a paired filter rule or they do nothing useful, and internal clients cannot reach a published server through the public address without an extra rule. This guide covers the three NAT operations with the exact CLI, plus the ordering rules that decide what actually happens to a packet.

src-nat vs Masquerade

Both rewrite the source address of outbound traffic. Masquerade takes the address of whatever interface the packet exits through, applies only to that interface, and clears its conntrack entries whenever the interface's address changes - which is why it is the right choice on DHCP or PPPoE uplinks. Plain src-nat to a fixed address keeps conntrack entries across link events and is the better option on a static circuit.

/ip firewall nat
add chain=srcnat src-address=10.0.0.0/24 out-interface=WAN action=masquerade
add chain=srcnat src-address=10.0.0.0/24 out-interface=WAN action=src-nat to-addresses=203.0.113.10

Rule order matters within a chain: the first matching rule wins unless the action passes through. Put more specific rules above general ones.

Port Forwarding with dst-nat

/ip firewall nat
add chain=dstnat action=dst-nat protocol=tcp   dst-address=203.0.113.10 dst-port=8443 to-addresses=10.0.0.20 to-ports=443

/ip firewall filter
add chain=forward action=accept connection-nat-state=dstnat   in-interface=WAN protocol=tcp dst-port=443

The connection-nat-state=dstnat matcher is the clean way to permit forwarded traffic: it accepts exactly the connections that this router translated, without opening the internal host to any other access. Without a forward rule the packet is translated and then dropped by the default drop policy, and the NAT counter increments anyway - a symptom that misleads a lot of people.

Hairpin NAT for Internal Clients

When a LAN client connects to the public address of a server that lives on the same LAN, the reply goes directly back and the connection stalls. Add a masquerade rule scoped to that source-destination pair, placed above any general srcnat rule:

/ip firewall nat
add chain=srcnat action=masquerade protocol=tcp   src-address=10.0.0.0/24 dst-address=10.0.0.20 dst-port=443

A cleaner alternative in many deployments is split DNS - resolve the public name to the internal address for internal clients - which avoids the extra NAT entirely.

Verification and Debugging

/ip firewall nat print stats
/ip firewall connection print where dst-port~"443"
/ip firewall filter print stats
/tool torch interface=WAN port=any
/ip firewall mangle print stats

The print stats output shows packet and byte counters per rule, which localises the problem in one glance: a zero counter on the dstnat rule means the packet is not arriving at that chain, while a rising nat counter with a zero forward-accept counter means the filter is dropping the translated traffic. /tool torch shows live traffic per address pair without needing a packet capture.

Address Lists and Netmap

/ip firewall address-list add list=servers address=10.0.0.20
/ip firewall nat add chain=dstnat dst-address-list=servers action=netmap   to-addresses=203.0.113.20-203.0.113.29

netmap creates a static 1:1 mapping across a range, which is how you publish multiple internal servers with multiple public addresses without writing a rule per host. Address lists make rules reusable and are far easier to audit than inline IP addresses.

Ordering Rules That Actually Apply

RouterOS evaluates chains in a fixed sequence - input, forward, output for filtering; prerouting, postrouting for NAT - and within each chain by position. Use place-before to insert a rule at a specific position rather than relying on append order, and keep a comment on every rule. For the filtering side in depth see RouterOS firewall filter and address list guide, and for layer 2 designs RouterOS bridge VLAN filtering.

原文链接:https://help.mikrotik.com/docs/spaces/ROS/pages/3211299/NAT