Answer the question
In order to leave comments, you need to log in
Mikrotik SrcNat?
Good day.
The question is, when using rules for the srcnat chain, is it necessary to hardcode Src. Address in case of multiple external IPs?
Or do you need to use Mangle to send the necessary subnets to the desired route and srcnat will already process only marked packets?
Answer the question
In order to leave comments, you need to log in
If we are talking about masquerading, and not exposing the port to the outside, then in principle nothing prevents leaving everything without src nat, even if there are several addresses on the external interface.
For publication, I still recommend using a hard set of ports in both directions - this will make life much easier.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question