Community discussions

MikroTik App
 
User avatar
SoundGuyFYI
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 74
Joined: Wed Jun 05, 2013 12:43 am

NAT firewall Chain Input or Forward?

Mon Oct 06, 2014 10:07 pm

I have a dumb question. If you have traffic that is being NAT'ed or masqueraded, does the incoming traffic classify under forward or input in the firewall.

I assume since its dst. address is an address on the router that it would be input but then it is actually being forwarded to another packet. So I'm confused.

Just looking for clarity. Thanks.
 
User avatar
lordkappa
Member Candidate
Member Candidate
Posts: 133
Joined: Wed May 16, 2012 1:53 pm
Location: Vancouver, Canada

Re: NAT firewall Chain Input or Forward?

Mon Oct 06, 2014 10:21 pm

It's classified as Input, unless there is already an associated entry in ip tracking or NAT; Then it's forwarding.
Last edited by lordkappa on Tue Oct 07, 2014 12:28 am, edited 1 time in total.
 
rkau045
newbie
Posts: 45
Joined: Mon Jun 25, 2012 9:14 pm

Re: NAT firewall Chain Input or Forward?

Mon Oct 06, 2014 10:47 pm

If the destination address after NAT is not the router address it is processed in the FORWARD chain.

Otherwise it would be processed in the INPUT chain.

Sent from my LG-D800 using Tapatalk

Who is online

Users browsing this forum: BartoszP, DanMos79, inazmul, Mosmos and 68 guests