TanodTools
EN

MikroTik port forwarding generator

List the ports you want to publish and the servers behind them, and get RouterOS v7 dst-nat rules, with hairpin NAT so LAN clients can use the public address too.

Runs in your browser; nothing you type leaves your device

Match traffic to
Forwards
    Options
    Optional. Leave empty to accept connections from anywhere.

    Generates RouterOS v7 syntax (also valid on v6) for IPv4. Ports and addresses are checked, but not tested against your router. MikroTik and RouterOS are trademarks of SIA Mikrotīkls. This tool is independent and not affiliated with or endorsed by MikroTik.

    How to forward a port on a MikroTik router

    1. Choose how the rule recognises traffic to your public address: the WAN interface list, a fixed public IP, or any of the router's addresses.
    2. Add a row per service: protocol, public port, the internal server's IP and, if it differs, its internal port.
    3. Tick hairpin NAT if LAN clients should reach the service by its public address, then copy the script or download the .rsc file.

    How port forwarding works on RouterOS

    A port forward is a dst-nat rule in the dstnat chain of /ip firewall nat. When a new connection arrives that matches the rule (protocol, destination port, and either the WAN interface or your public address), RouterOS rewrites its destination to the internal server's address and, optionally, port. Connection tracking remembers the translation, so replies are rewritten back automatically; you never need a matching rule for the return traffic.

    Translation happens before the forward chain of the filter sees the packet. That is why MikroTik's default forward rule drops new WAN connections only when connection-nat-state=!dstnat: a connection that a dst-nat rule translated is marked as dstnat'ed and allowed through, while anything else from the internet is dropped.

    Hairpin NAT

    When a computer on the LAN connects to the public address of a server that is also on the LAN, the dst-nat rule sends the packet to the server, but the server sees the client's private address and replies to it directly. The client then receives an answer from an address it never talked to and discards it. The hairpin rule masquerades traffic from the LAN subnet to the server, so the server answers the router, which translates the reply back. The cost is that the server's logs show the router's address for LAN clients. A split-horizon DNS record pointing the name at the internal address avoids NAT entirely and is often the cleaner fix.

    Tips

    Questions

    Why can't I reach my port forward from inside the LAN?

    A LAN client sends to your public IP, the router translates the destination to the server, and the server answers the client directly because both are on the same subnet. The client expected the answer from the public IP, so it drops it. Hairpin NAT masquerades that LAN-to-LAN traffic so the reply goes back through the router. It only works when the dst-nat rule matches the public address rather than the WAN interface, because the packet arrives on the LAN interface.

    Should the rule match in-interface or dst-address?

    Matching the WAN interface list is simplest and survives a changing public IP, but it can't do hairpin NAT. Matching dst-address works with hairpin but must be updated if the IP changes. dst-address-type=local matches any address on the router, which handles dynamic IPs and hairpin at once; the catch is that it also captures those ports on the router's own LAN address.

    Do I need a firewall filter rule as well?

    With MikroTik's default configuration, no: its forward chain drops new connections from the WAN only when they are "not DSTNATed", so port-forwarded connections pass. If you wrote a stricter forward chain, accept connection-nat-state=dstnat before your final drop.

    How do I forward a range of ports?

    Enter the range, such as 50000-50100, or a list such as 80,443, and leave the internal port empty. The ports are forwarded unchanged. Port translation (public 8443 to internal 443) works for single ports.

    Is it safe to forward RDP, SSH or Winbox?

    Exposing remote-access services to the whole internet invites brute-force attempts. Fill in the allowed source networks to limit a forward to known addresses, or put the service behind a VPN such as WireGuard instead.

    Is my configuration sent anywhere?

    No. The rules are generated by JavaScript in this page, and nothing you type is uploaded, stored or logged.