A
A
Aleksandr2017-05-30 20:18:48
Mikrotik
Aleksandr, 2017-05-30 20:18:48

Mikrotik router + public network transit, is it possible?

Initial data: there is a Mikrotik hEX RB750GR3 router, there is an optics from the Provider, through which it gives a subnet of 8 public addresses (the gateway is located at the Provider, it routes this subnet to us through a cable). And I need to implement such a scheme (I appeal to those who really understand what is at stake!): one of the addresses of this subnet must be assigned directly to Mikrotik, and the remaining addresses must be "given" to one of the ports of the router and "caught" it in another remote segment... It will have its own router, and one of the "caught" addresses must be assigned to the network interface of this remote router! I would like, if possible, to implement this without using VLANs ...
The first thing that comes to mind is to "hack" the entire circuit with the help of an auxiliary switch (plug the cable from the provider into the switch, and plug both Mikrotik and the cable from the "remote segment" into its ports ...). But such a solution is not comme il faut due to the additional device, which in itself will introduce a delay + is at risk of failure, freezing, etc.! Yes, and with monitoring, counting traffic, then it will be a hemorrhoid ...

Answer the question

In order to leave comments, you need to log in

4 answer(s)
L
Ltonid, 2017-05-30
@AtaZ

If I understand the question correctly, then I have a scheme where I accept a pool of 40 ip on Mikrotik and distribute them to virtual machines for many many vpn from the current point.
Actually the logic is this: you raise your own direct network between routers (in any convenient way).
Through netmap, you cross-record two rules (on the router on which they are configured in ipaddreses): external ip to internal ip (incoming traffic), internal ip to external ip (outgoing traffic). On the second router, you do not need to configure anything separately.
You can give all ip to one internal node, in principle, for the input, but you will have to choose one for the output, otherwise the traffic may not go.
I didn’t try double forwarding, I didn’t try to control all this. I must say right away that the rules for restricting traffic do not work. technically the whole stream is behind netmap. dnat works. Unfortunately, I can't describe codes.

D
Dmitry Alexandrov, 2017-05-30
@jamakasi666

Look it up =)

V
Viktor Belsky, 2017-05-31
@Belyj

Hmm ... since you were going to "collective farm" the switch, then I will assume that Mikrotik and frya are in the same broadcast domain, i.e. do they see each other on L2? If this is the case, then make the bridge m / y the uplink port from the provider and the port where the frya is connected.

V
Vladimir Zhurkin, 2017-06-28
@icCE

> There will be your own router.
You can configure one more port for the tick as a switch with a wan port, forward it further and receive L2 provider traffic on the router. But as for me, I would use Vlan.
Here you can see how to make two ports in switch, not bridge
https://habrahabr.ru/post/313702/

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question