Why is port forwarding in Mikrotik RouterOS stuck at SYN_RECV?

I’d like to set up port forwarding of tcp port 8000 -> on my Mikrotik RouterOS.

I’ve done the following:

/ip firewall nat add dstnat chain=dstnat action=dst-nat to-addresses= to-ports=4200 protocol=tcp dst-address=<PUBLIC_IP> dst-port=8000

When I try to use the service from the Internet then the following command just hangs:

curl <PUBLIC_IP>:8000

I can see the counters moving on the Mikrotik’s NAT rule (via WebBox).

On the target machine, I can see the following in netstat -an | grep 4200:

tcp        0      0  *               LISTEN
tcp        0      0       <REMOTE_HOST>:37720     SYN_RECV

I verified that I am able to connect to the machine locally via curl

I can’t figure out what can be wrong 🙁

Author: adamsfamily