I have a couple of questions regarding NAT Hairpinning.
Reading this WikiTik: https://wiki.mikrotik.com/wiki/Hairpin_NAT
My questions are:
1. If we already created the rule below:
Do we need to add the following rule:
Code: Select all
/ip firewall nat add chain=dstnat dst-address=22.214.171.124 protocol=tcp dst-port=80 \ action=dst-nat to-address=192.168.1.2 add chain=srcnat out-interface=WAN action=masquerade
2. If the devices that are going to access the server is also on the LAN, to make uniformity (i.e. to access the server, just type the external address) can we just have NAT Hairpinning rule above, instead of port forwarding rule?/ip firewall nat
add chain=srcnat src-address=192.168.1.0/24 \
dst-address=192.168.1.2 protocol=tcp dst-port=80 \
Any help would be appreciated.