Configure Hairpin NAT on RouterOS (Mikrotik)

In this article I will give an example of setting Hairpin NAT on RouterOS (Mikrotik).

I happen to have a server or a DVR in the local network, the ports to which are forwarded in the firewall, but you can connect only from other networks, and from the local network it is obtained only by the local IP address, but not external, on the WAN interface of the router.

Suppose the router’s WAN IP address is, the LAN is, the server’s IP address is

Suppose there is a standard NAT rule (let’s leave it):

ip firewall nat add action=masquerade chain=srcnat comment="defconf: masquerade" out-interface=ether1

Now configure “Hairpin NAT” (forward port 22 for SSH):

ip firewall nat add action=dst-nat chain=dstnat dst-address= dst-port=22 protocol=tcp to-addresses=
ip firewall nat add action=masquerade chain=srcnat dst-address= dst-port=22 out-interface=bridge protocol=tcp src-address=


See also my article:
Port forwarding on Mikrotik routers
Configuring Remote Access in Mikrotik Router

Did my article help you? How about buying me a cup of coffee as an encouragement? Buy me a coffe.

Leave a comment

Leave a Reply