Hi,
I am new with Mikrotik and also not so much experienced with TCP/IP, but I have lots of experience with SOHO routers. I also managed to setup few very complex setups, but to be honest, it was done mostly by try-this try-that, oups...undo, reset, reboot, try-again
Now, I have 3 routers now at my small wanna-be hosting center, which are choking on existing config. Now I've got additional /24 public IP subnet assinged, and I decided to give it a try with Mikrotik. I bought RB 1200 model, because merchant says it will do the job.
Here it is what I need to do: Well, I did a kind of config already and it is working....somehow. But I realised I must have made some mistakes. What I did:
- RED interfaces are my connection to internet.
- RED PORT 2 is the main routing segment, which my ISP uses to route 2 public subnets to my router.
- RED PORT 3 is simple Ethernet, for home usage, surfing, whose IP is assigned from IPS side with DHCP and is changing dynamically.
Now, I did (I do not know if this is the correct approach!?):
On PORT 2:
- assigned IP 189.212.79.46, subnet /30
Created 2 BRIDGES:
- 1 bridge between PORTS 1,4,5,6 named "BRIDGE_LAN" and assigned them IP 192.168.20.1, subnet /24
- 1 bridge between PORTS 7,8 named "BRIDGE_WAN1" and assigned them IP 189.212.1.17, subnet /28
For LAN I created FIREWALL--> NAT:
- having IP 192.168.20.1 subnet /24
Now, it is working, but if I PING from BRIDGE_WAN1 --> its Gateway 189.212.1.17, I get response of 200, 300, 1500ms, or even timeout:
Code: Select all
Pinging 89.143.249.33 with 32 bytes of data:
Reply from 89.143.249.33: bytes=32 time=8ms TTL=122
Reply from 89.143.249.33: bytes=32 time=221ms TTL=122
Reply from 89.143.249.33: bytes=32 time=173ms TTL=122
Reply from 89.143.249.33: bytes=32 time=43ms TTL=122
Reply from 89.143.249.33: bytes=32 time=39ms TTL=122
Reply from 89.143.249.33: bytes=32 time=737ms TTL=122
Reply from 89.143.249.33: bytes=32 time=425ms TTL=122
Reply from 89.143.249.33: bytes=32 time=222ms TTL=122
- is my approach correct?
- ...or should I use some other method, like VLAN instead of BRIDGE, or something else?
Thank you!