---
title: Segment53 on MikroTik with DNAT
description: Documentation for additional configuration in MikroTik to apply different rules to different IP groups, using the Segment53 feature of Lumiun DNS. The protocol used is DNS53 or Do53.
---

[Skip to content](https://help.lumiun.com/en-us/hc/segment53-no-mikrotik-com-dnat#main-content)

- [English - United States](https://help.lumiun.com/en-us/hc/segment53-no-mikrotik-com-dnat)
- [Português - Brasil](https://help.lumiun.com/pt-br/hc/segment53-no-mikrotik-com-dnat)

English - United States

Show submenu for translations

[Request Support](https://help.lumiun.com/en-us/hc/kb-tickets/new?hsLang=en-us) [My Tickets](https://tickets.lumiun.com/tickets?hsLang=en-us)

[![logo lumiundns](https://help.lumiun.com/hubfs/lumiundns-x-color.svg)](https://help.lumiun.com/?hsLang=en-us)

Open main navigation

Close main navigation

- - [English - United States](https://help.lumiun.com/en-us/hc/segment53-no-mikrotik-com-dnat)
    - [Português - Brasil](https://help.lumiun.com/pt-br/hc/segment53-no-mikrotik-com-dnat)

  English - United States
  
  Show submenu for translations
- [Request Support](https://help.lumiun.com/en-us/hc/kb-tickets/new)
- [My Tickets](https://tickets.lumiun.com/tickets)
- [Go to Dashboard](https://dns.lumiun.com/)

[Go to Dashboard](https://dns.lumiun.com/)

 How can we help?

- There are no suggestions because the search field is empty.

1. [Lumiun DNS Help Center](https://help.lumiun.com/en-us/hc?hsLang=en-us)
2. [Integrations](https://help.lumiun.com/en-us/hc/integrations?hsLang=en-us)
3. [Routers](https://help.lumiun.com/en-us/hc/integrations?hsLang=en-us#routers)

# Segment53 on MikroTik with DNAT

## Segment53 allows you to create multiple segments with different endpoints for Do53. This enables a single IP to be linked to different network segments, each with specific control and security policies.

#### It is possible to apply this feature in networks with VLANs and DNAT on a MikroTik network. In this article, we will discuss its use with DNAT.

#### When we use DNAT to direct a specific Address List to different DNS servers, we are applying specific address redirection rules to manipulate DNS traffic (port 53) based on the source IP group (Address List).

**Please note**: This article is not recommended if you have a domain server (AD) on your network. If you have any questions, please contact support.

**Let's see how it works in practice:**

### Creating sites in Lumiun DNS

At this initial stage, we will create two sites in Lumiun DNS. The first site will have queries resolved by MikroTik, while the second will have queries resolved by other DNS servers through DNAT. We will link the same public IP, but we will change the segment referring to the site. See the image below:![](https://help.lumiun.com/hs-fs/hubfs/image-png-Oct-08-2025-02-27-14-2121-PM.png?width=670&height=270&name=image-png-Oct-08-2025-02-27-14-2121-PM.png)

For **Employees**, we will follow the standard [MikroTik installation guide](https://help.lumiun.com/pt-br/hc/configurando-mikrotik-para-usar-lumiun-dns-via-do53?hsLang=en-us).

For **Managers**, we will configure DNAT.

**Warning:** Due to limitations in information collection, configurations via DNAT do not have internal IP addresses in reports.

### Configuration via DNAT

1. We will create the Address List. In this example, the list should contain the **IP addresses** of the **management** team's devices.
   
     1. Go to the **IP** → **Firewall** menu. Click on the **Address Lists** tab and then on the **Add New** button.
     2. Fill in the **Name** field with *managers\_ips*.
     3. Fill in the **Address** field with the IP address of one of the devices on the local network. ***Tip:** You can also specify an address range, such as 192.168.88.10-192.168.88.20, or a subnet, for example, 10.10.10.0/24.*
     4. Save by clicking the **OK** button.
     5. Repeat this procedure to add the IP addresses of all devices that are part of the management.
2. Creating the redirect.  
     1. Go to the **IP** → **Firewall** → **NAT** menu and click the **Add New** button.
     2. In the **Chain** field, select **dstnat**.
     3. In the **Protocol** field, select **udp**.
     4. Fill in the **Dst. Port** field with **53**.
     5. In the **Src. Address List** field, select *managers\_ips*.
     6. In the **Action** field, select **dst-nat**.
     7. Fill in the **To Addresses** field with the **primary DNS** server for the managers site. To view it, click on **Settings** in the [Managers site](https://dns.lumiun.com/sites).
     8. Save by clicking the **OK** button.
     9. Repeat this procedure, changing only the **Protocol** field to **tcp**.

That's it! Now, the IPs entered in the Address List *managers\_ips* will follow the rules of the Policy defined in the Lumiun DNS site.

You can use this same process to create other sites and use Segment53 to define other IP groups.

- [Integrations](https://help.lumiun.com/en-us/hc/integrations?hsLang=en-us#main-content)

    - [Routers](https://help.lumiun.com/en-us/hc/integrations?hsLang=en-us#routers)
    - [Firewalls](https://help.lumiun.com/en-us/hc/integrations?hsLang=en-us#firewalls)
    - [Servers](https://help.lumiun.com/en-us/hc/integrations?hsLang=en-us#servers)
    - [Computers](https://help.lumiun.com/en-us/hc/integrations?hsLang=en-us#computers)
    - [Smartphones](https://help.lumiun.com/en-us/hc/integrations?hsLang=en-us#smartphones)
    - [Browser](https://help.lumiun.com/en-us/hc/integrations?hsLang=en-us#browser)
    - [General](https://help.lumiun.com/en-us/hc/integrations?hsLang=en-us#general)
- [Policies and Filters](https://help.lumiun.com/en-us/hc/policies-and-filters?hsLang=en-us)
- [Networks and Sites](https://help.lumiun.com/en-us/hc/networks-and-sites?hsLang=en-us)
- [Reports](https://help.lumiun.com/en-us/hc/reports?hsLang=en-us)
- [Your Account](https://help.lumiun.com/en-us/hc/your-account?hsLang=en-us#main-content)

    - [Plans and Billing](https://help.lumiun.com/en-us/hc/your-account?hsLang=en-us#plans-and-billing)
- [Partners](https://help.lumiun.com/en-us/hc/partners?hsLang=en-us)
- [FAQ](https://help.lumiun.com/en-us/hc/faq?hsLang=en-us#main-content)

    - [General](https://help.lumiun.com/en-us/hc/faq?hsLang=en-us#general)
    - [pfSense](https://help.lumiun.com/en-us/hc/faq?hsLang=en-us#pfsense)

[![logo lumiun dns](https://help.lumiun.com/hubfs/lumiun-dns.svg "logo lumiun dns")](https://help2.lumiun.com/?hsLang=en-us)

<https://www.linkedin.com/company/lumiuntecnologia> <https://www.instagram.com/lumiuntecnologia> <https://www.facebook.com/LumiunTecnologia>

Copyright © 2026, Lumiun