Firewall and Quality of Service
This section provides an overview of RouterOS firewall capabilities including NAT, connection tracking, and QoS features for securing traffic, classifying packets, and managing bandwidth.
This section provides an overview of RouterOS firewall capabilities including NAT, connection tracking, and QoS features for securing traffic, classifying packets, and managing bandwidth.
NAT in MikroTik RouterOS enables IPv4 address translation between private and public networks, supporting both source NAT (masquerading) for hiding internal IPs and destination NAT for redirecting external traffic to specific internal devices. The documentation explains configuration rules, types of NAT, and troubleshooting tips for connection tracking issues.
Socksify forwards traffic chosen by firewall NAT rules through an upstream SOCKS5 server, so applications without SOCKS support can use a SOCKS proxy. Includes a Tor proxy example.
Universal Plug and Play (UPnP) in RouterOS: an Internet Gateway Device service that lets LAN applications request port mappings. The router creates dynamic destination NAT rules for the requested ports. Covers enabling the service, marking external and internal interfaces, and the security implications.