How to Port Forward ports when using dynamic IP with Mikrotik RouterBoard.

What is Port Forwarding ?

In computer networking, port forwarding or port mapping is an application of network address translation (NAT) that redirects a communication request from one address and port number combination to another while the packets are traversing a network gateway, such as a router or firewall. This technique is most commonly used to make services on a host residing on a protected or masqueraded (internal) network available to hosts on the opposite side of the gateway (external network), by remapping the destination IP address and port number of the communication to an internal host

Port Forward in Mikrotik Router

Down and dirty version. The command line version is below the Winbox instructions. Let’s say you have a DVR that has a static IP of, and you need to forward port 3999.

Assuming you have Dynamic IP, there is another way for static IPs or subnets.


In Winbox


1. Go to IP -> Firewall -> NAT (Image 1).



2. Click the “+” to add a new NAT rule. Modify the “Chain” to “dstnat”, “Protocol” to “tcp”, and “Dst. Port” to “3999”. Set the “In. Interface” to your WAN port. (Note: You are telling the router that any traffic coming IN from the Internet on port 3999 should follow this rule. If you forget this step, the router will grab ANY traffic on port 3999 and send it to the IP you specify in the next step) (Image 2).


3. Click the “Action” tab, change the “Action” value to “dst-nat”, the “To Addresses” to “” and “To Ports” to “3999” (Image 3).


Terminal Version

Type the following value into a Terminal window to enter this port forwarding rule.

/ip firewall nat

add action=dst-nat chain=dstnat disabled=no dst-port=3999 in-interface=ether1-gateway protocol=tcp to-addresses= to-ports=3999