We do not have a static IP address, so on a simple linux pc, the config would default to
sudo iptables -t nat -A POSTROUTING -o $WAN_IFACE -j MASQUERADE
sudo iptables -A FORWARD -i $WAN_IFACE -o $ZT_IFACE -m state --state RELATED,ESTABLISHED -j ACCEPT
sudo iptables -A FORWARD -i $ZT_IFACE -o $WAN_IFACE -j ACCEPT
as proposed in the link.
So on the router i set :
/ip firewall nat
Code: Select all
add chain=srcnat action=masquerade
Code: Select all
add chain=forward in-interface=ZT_IFACE out-interface=WAN_IFACE action=accept
add chain=forward in-interface=$WAN_IFACE out-interface=$ZT_IFACE action=accept connection-state=established,related
Firstly, is it possible to do this?
Secondly, if yes, how to improve the config to do it?