enable_nat_rule
Enable an existing MikroTik firewall NAT rule by its comment, optionally scoped to srcnat or dstnat. Never creates rules; previews changes before applying when confirm is false.
Instructions
Enable an EXISTING firewall NAT rule (/ip/firewall/nat set disabled=no), resolved by its comment - optionally narrowed by
chain (srcnat/dstnat) if more than one rule shares that
comment.
Same "never creates a rule" guarantee and comment-based resolution
as enable_firewall_rule (see its docstring and README's "Firewall
rule toggle (by comment)" section) - extended to /ip/firewall/nat.
WRITE tool, guarded: blocked entirely unless the server is running
with MIKROTIK_ALLOW_WRITE=true. Call with confirm=False (the
default) to get a before/after preview - the FULL matched rule, not
just its disabled field - without changing anything; call again
with confirm=True to actually apply it. Errors clearly if no rule
matches comment (narrowed by chain), or if more than one still
does (AmbiguousResourceError) - never guesses which one to toggle.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| chain | No | ||
| comment | Yes | ||
| confirm | No | ||
| device_name | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||