I can only get wireless Internet where I live, and that means CGNAT. I need to run some public services, so I'm running Mikrotik CHR inside a cheap Azure VM. Site-to-site VPN is working great, and all hosts can see each other at home and in the Azure subnet
I've set up the public IP in Azure to fwd to the Mikrotik. I've then set up a dstnat rule on the public ports, to my on-prem servers. However, it's not working. I can see the SYN packet leave the mikrotik inside Azure, but I can't see anything on-prem. I'd have thought it should be under the firewall forwarding rules, but I'm not seeing it in my packet counts. Any idea what I'm mising?
Thanks