Hairpin NAT instruction inconsistency?

Thanks for the comments all! For my hairpin NAT src-nat rule I went with “out-interface=bridge”, but I trust “out-interface-list=LAN” would work equally well for home network Mikrotik users where the only entry in the LAN list is in fact bridge. :slight_smile:

After this change to my configuration, I still couldn’t get the hairpin NAT to work. It was only after I found this post Hairpin NAT doesn't work - #14 by Josephny that I found that in fact my misconfiguration happens in the accompanying dst-nat rule.

Since it took ages for me to figure this one out, I echo the solution here: make sure that your dst-nat rule does not include an in-interface!

Of course the example in the documentation is correct and defines the WAN-IP dst-address in the dst-nat rule and not an in-interface. But for home network Mikrotik users with a dynamic WAN-IP, you might hesitate to put the (changing) WAN-IP in your dst-nat rule. And from outside your network, in-interface=WAN works equally well (but not when you want to hairpin NAT).

The link above provides an elegant example. If you use dst-address-type=local instead of dst-address=WAN-ip, you make a dynamic reference to all IP’s that are ‘local to the router’, e.g. both the WAN IP and the LAN-IP.