I don't know how it work, but it work!Just add some srcnat, e.g.:And you don't need the route to 192.168.1.212/32, automatic connected route comes from 192.168.1.2/24.Code: Select all/ip firewall nat add chain=srcnat dst-address=192.168.1.212 action=masquerade