Hello!
I'm trying to configure port forwarding for double NAT with no success. I can see incoming packets (WAN -> internal server), but no internal server -> WAN are received by WAN.
WAN device is Mikrotik SXT LTE and it cannot be configured as bridge (LTE->Ethernet due to modem limitations), so it's using as router with DMZ to my router Mikrotik RB3011 (3011 is used for some heavy CPU tasks: VPN, etc).
I'm trying to achieve following to work:
LTE WAN on SXT -> DMZ -> RB3011 -> Home web server
I have two rules on SXT (first NAT / router):
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" out-interface=lte1
add action=dst-nat chain=dstnat dst-address-type="" in-interface=lte1 to-addresses=192.168.88.253
and two rules on RB3011 (second NAT / router):
/ip firewall nat
add action=masquerade chain=srcnat comment="WAN nat" out-interface=WAN
add action=dst-nat chain=dstnat comment="DMZ forward" dst-address-type="" to-addresses=192.168.1.101 to-ports=80
I've checked to port 80 with Wireshark and can see packets incoming from WAN to my internal 192.168.1.101 IP and that my 192.168.1.101 responds correctly to WAN packets, but they are not getting transmitted to WAN client.
I'm expecting something is wrong with srcnat inside Router 1 (SXT LTE) or Router 2 (RB3011).
Can you, please, help or provide some information what can be also checked?
Thank you.