Community discussions

MikroTik App
User avatar
Charlie Whiskey
just joined
Topic Author
Posts: 24
Joined: Wed Nov 16, 2005 7:45 am

Question on NAT and routing mark

Wed Dec 14, 2005 12:41 pm

Referring to the last example on this manual page,, I only need to write a masquerade (SNAT) and a routing mark rule to get a computer with a private IP behind the router connected to the outside. How come I don't need a matching pair of rules to cater for the incoming packets as well? Under what circumstances would I NOT need to cater for the returning traffic?
User avatar
Member Candidate
Member Candidate
Posts: 140
Joined: Fri May 28, 2004 3:26 pm
Location: Norway, Østfold

Thu Dec 22, 2005 5:12 pm

You'd need rules for incoming traffic if you wanted to NAT traffic to an IP behind your gateway.
Otherwise translation of you LAN traffic is done inside of your router so the traffic coming from the LAN side appears as it was coming from the WAN side.
All the established connections from your LAN clients are kept open as long as necessarily and the track of them are kept by the NATing mechanism.

Who is online

Users browsing this forum: No registered users and 25 guests