V
V
VasHan2020-04-22 19:13:09
Mikrotik
VasHan, 2020-04-22 19:13:09

How to set up Hairpin NAT on Mikrotik correctly?

Good afternoon!

I have two offices connected by VPN
Office #1 WAN: 10.0.0.1, LAN: 192.168.1.0/24
Office #2 WAN: 10.0.1.1, LAN: 192.168.2.0/24
Internet access is disabled in office #1 (NAT is disabled )
Server 192.168.2.100 is installed in office #2, accessible from the outside 10.0.1.1:443

I need users from office #1 to access the server at an external address and be redirected to a local address. I tried setting up a so-called "hairpin" NAT:

/ip firewall nat
add action=dst-nat chain=dstnat dst-address=10.0.1.1 dst-port=443 protocol=tcp src-address=192.168.1.0/24 to-address=192.168.2.100
add action=masquerade chain=srcnat dst-address=192.168.2.100 dst-port=443 protocol=tcp src-address=192.168.1.0/24


Please tell me what am I doing wrong?

Answer the question

In order to leave comments, you need to log in

1 answer(s)
D
Diman89, 2020-04-23
@Diman89

Compare with the example from the wiki and you will find the difference, otherwise the firewall

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question