Port block
The ports each subscriber may hold open on its public address at once. 1,024 suits most homes; 2,048 gives heavy users and game consoles more headroom. A smaller block fits more subscribers on each address.
Work out how many subscribers share each public IPv4 address behind carrier-grade NAT, and how many addresses your subscriber base needs. It runs in your browser: nothing you type is sent anywhere.
Every address in the pool is counted, network and broadcast included: a NAT pool uses them all. 1,024 ports per address are left over, too few for another block.
/ip firewall nat
add chain=srcnat action=src-nat src-address=100.64.0.1 protocol=tcp to-addresses=203.0.113.0 to-ports=1024-3071
add chain=srcnat action=src-nat src-address=100.64.0.1 protocol=udp to-addresses=203.0.113.0 to-ports=1024-3071
add chain=srcnat action=src-nat src-address=100.64.0.1 to-addresses=203.0.113.0
add chain=srcnat action=src-nat src-address=100.64.0.2 protocol=tcp to-addresses=203.0.113.0 to-ports=3072-5119
add chain=srcnat action=src-nat src-address=100.64.0.2 protocol=udp to-addresses=203.0.113.0 to-ports=3072-5119
add chain=srcnat action=src-nat src-address=100.64.0.2 to-addresses=203.0.113.0
add chain=srcnat action=src-nat src-address=100.64.0.3 protocol=tcp to-addresses=203.0.113.0 to-ports=5120-7167
add chain=srcnat action=src-nat src-address=100.64.0.3 protocol=udp to-addresses=203.0.113.0 to-ports=5120-7167
add chain=srcnat action=src-nat src-address=100.64.0.3 to-addresses=203.0.113.0
add chain=srcnat action=src-nat src-address=100.64.0.4 protocol=tcp to-addresses=203.0.113.0 to-ports=7168-9215
add chain=srcnat action=src-nat src-address=100.64.0.4 protocol=udp to-addresses=203.0.113.0 to-ports=7168-9215
add chain=srcnat action=src-nat src-address=100.64.0.4 to-addresses=203.0.113.04 of 200 subscribers shown, three rules each: 600 in all. Paste them above your masquerade rule, and on a large pool put them behind jump chains so each packet is matched against a few rules, not every one.
How the ports on one public address are shared out, and what the rules do with them.
The ports each subscriber may hold open on its public address at once. 1,024 suits most homes; 2,048 gives heavy users and game consoles more headroom. A smaller block fits more subscribers on each address.
The ports the router may translate to. Ports below 1024 are left out by default, which leaves 64,512 per address. A block that does not fit the range is refused rather than rounded.
A /29 holds eight addresses, and a NAT pool translates to all eight: no network or broadcast address is set aside, as it would be on a LAN.
Each subscriber is pinned to one public address and one port block, so who used a port can be read from the rules, without logging every connection.
Subscribers behind CGNAT take addresses from 100.64.0.0/10 (RFC 6598), set aside so they never clash with a customer's own private network.
Centipid assigns addresses, provisions MikroTik and collects the payment that keeps them online.