MikroTik port forwarding: how to open a port
Last updated: 2 October 2026
Port forwarding lets someone on the internet reach a device inside your network, such as a camera recorder or a web server. On MikroTik it is one NAT rule.
Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.
The rule
Forward port 8080 on the internet side to a device at 192.168.88.10, port 80:
/ip firewall nat add chain=dstnat in-interface=ether1 protocol=tcp dst-port=8080 action=dst-nat to-addresses=192.168.88.10 to-ports=80 comment="camera"Replace ether1 with your WAN interface (for example pppoe-out1). With an interface list: in-interface-list=WAN.
The firewall
The default MikroTik firewall already lets forwarded ports through. If you wrote your own rules, allow them:
/ip firewall filter add chain=forward connection-nat-state=dstnat action=accept place-before=0Test from outside
Test from mobile data, not from your own Wi-Fi. Open http://YOUR-PUBLIC-IP:8080. Find your public address with:
/ip cloud set ddns-enabled=yes
/ip cloud printReaching it from inside by the public address
To use the same public address from your own LAN, add a hairpin rule:
/ip firewall nat add chain=srcnat src-address=192.168.88.0/24 dst-address=192.168.88.10 protocol=tcp dst-port=80 action=masqueradeand in the forward rule match the public address with dst-address=YOUR-PUBLIC-IP instead of in-interface.
If it never works: CGNAT
If the address on your WAN interface is different from the public address websites see for you, your ISP shares one public address between many customers. No rule on your router can open a port then. Ask the ISP for a public address.
/ip address print where interface=ether1Keep it safe
- Forward only the ports you need.
- Never forward the router's own Winbox or web port to the internet. See basic firewall.
- Limit who may connect with
src-address=when you can.
Questions and answers
Why does my forwarded port show as closed?
The device is off or has no gateway, the test was made from inside the network, the firewall drops it, or the line is behind CGNAT.
How do I forward a range of ports?
Use dst-port=5000-5010 and leave to-ports empty to keep the same numbers.
TCP or UDP?
It depends on the application. Add one rule per protocol if it needs both.