关于在私有LAN中直接分配已购公网IP的可行性及实现方法咨询
Hey there! Great question—this is totally doable, and it’s a pretty standard setup when you’ve got a block of public IPs from your ISP. No port forwarding needed, which is exactly what you’re after. Let me walk you through how to make this work with your MikroTik router.
First, a quick prerequisite to confirm: Your ISP must already be routing that /29 subnet to your MikroTik’s main WAN interface IP. If they haven’t done that, you’ll need to reach out to them first—this is critical because it tells the internet where to send traffic destined for your /29 IPs.
Assuming that’s sorted, here’s the step-by-step process:
1. Add a public IP gateway to your MikroTik’s LAN interface
Pick one of your unused /29 IPs to act as the gateway for your Windows machine (and any other devices you want to assign public IPs to later). Let’s say your /29 block is 203.0.113.0/29 (replace this with your actual IP range). You could use 203.0.113.1 as the gateway.
On your MikroTik, use this command (swap LAN with your actual LAN interface or bridge name):
/ip address add address=203.0.113.1/29 interface=LAN
2. Assign a public IP to your Windows machine
Instead of using DHCP, set a static IP on your Windows device:
- IP address: Pick another unused IP from your /29 block (e.g.,
203.0.113.2) - Subnet mask:
255.255.255.248(this matches the /29 CIDR) - Default gateway: Enter the gateway IP you set on the MikroTik (e.g.,
203.0.113.1) - DNS servers: Use your ISP’s DNS or public ones like
8.8.8.8/8.8.4.4
3. Adjust MikroTik’s NAT rules to avoid SNAT for your public IPs
By default, MikroTik uses MASQUERADE (source NAT) to turn all internal traffic into your WAN IP. We need to exclude your /29 block from this rule so your Windows machine’s traffic uses its own public IP.
If you have an existing MASQUERADE rule, modify it to exclude your subnet:
/ip firewall nat add chain=srcnat out-interface=WAN src-address=!203.0.113.0/29 action=masquerade
(Make sure to delete your old MASQUERADE rule after adding this new one.)
4. Update MikroTik’s firewall to allow traffic for your public IPs
You need to make sure your router doesn’t block incoming or outgoing traffic for your /29 block. Add these filter rules:
- Allow incoming traffic to your public IPs:
/ip firewall filter add chain=input dst-address=203.0.113.0/29 action=accept - Allow outgoing traffic from your public IPs:
/ip firewall filter add chain=forward src-address=203.0.113.0/29 action=accept
If you have a default "drop all" rule at the bottom of your filter list, make sure these accept rules come before it—otherwise they won’t take effect.
Once all this is set up, your Windows machine will be directly reachable from anywhere on the internet using its assigned public IP, no port forwarding required. Just double-check that your ISP hasn’t placed any restrictions on using these IPs internally, and you should be good to go!
备注:内容来源于stack exchange,提问作者Yeasir Arafat

