S
S
Sekii2019-10-16 13:19:45
Mikrotik
Sekii, 2019-10-16 13:19:45

If address-list is specified as dns, then dstnat does not work, why?

Good afternoon.
There is a rule in NAT:
/ip firewall nat add action=netmap chain=dstnat protocol=tcp dst-port=2222 src-address-list=list to-addresses=192.168.1.1 to-port=1111
only list contains dns name , not IP. For some reason, it doesn't work like that. If you replace list with IP, then everything is ok.
Plz tell me how to fix this?
Thank you.

Answer the question

In order to leave comments, you need to log in

1 answer(s)
P
poisons, 2019-10-16
@poisons

I see 2 options:
1. The Balts again drank Riga Balsam when assembling the firmware and broke NAT / dynamic address lists.
2. The DNS name resolves to many addresses, the router resolved it and remembered it until the TTL expired, but in fact they are breaking into you from a different ip

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question