Code: Select all
add action=dst-nat chain=dstnat comment="Init" dst-address=1.2.3.4 dst-port=22,80,161,443 protocol=tcp src-address-list=OnlyFromHere to-addresses=192.168.0.2
HOWEVER on the original device (192.168.0.2) there is NOT a gateway setup so it will need to not only bring in the dst-nat traffic, but then rewrite the source IP address so that the traffic appears to be coming in from the LAN. In the firewall we are converting from (Untangle) there is simple a rewrite rule where we could say ANY traffic from OnlyFromHere list destined to 192.168.0.2 should have a new source address of 192.168.0.254 which then of course is local and can communicate.
I cannot figure out how to replicate this functionality in Mikrotik though I am sure it should be possible since RouterOS is far more flexible than Untangle. Would appreciate any clues how to accomplish this. Thanks!