uPnP Dynamic NAT Rules on top

Hello,

Is there a way to put the dynamic uPnP NAT rules on top?

I have a rule to dst-nat everything to a specific IP on the internal network, but if another client needs a port open via uPnP their packets should be forwarded to them.

So in essence I need the uPnP rules to be added above the dst-nat rule I already have configured.


According to the manual there is no such option. So I am guessing this could be done maybe with scripting? Has anyone done anything similar?


Thanks!

bump?
:smiley:

You can move dynamic rules on the top of nat table with something like this:

/ip firewall nat move [find dynamic ] 0

Execute every 5 min

sent from my mobile phone using tapatalk