Community discussions

MikroTik App
 
BobcatGuy
Member Candidate
Member Candidate
Topic Author
Posts: 240
Joined: Thu Apr 19, 2007 7:41 am

Connect 493 as firewall to another 493 as firewall ( Natted)

Sun Mar 14, 2010 12:28 am

I have treied this before, and eventually had it to work, but cannot recall what eventually fixed it.
what I am essentially doing is using a 493, set up to be a firewall, and nat 2 ranges of Ips out Ether 2. ie 10.10.10.0/24 and 192.168.17.1. This works.

What my next step is is to connect ANOTHER 493 to this firewall, and have access to it.

I wanted to keep a 10.10.10.6 IP on ether 1 of it, and then ether 2-5 as Mainfloor ports, and Ethers 6 -9 as Basement Ether ports.
Main floor ports are bridged, with DHCP server on the bridge, and likewise for the basement ports.
Nat rule made for each range, and out interface is ether 1.

This does not work. Where am I messing up?

I want to leave the second 493 to assign Ip's, I do not want to have the other traffic on my private lan.
I have set up DNS on both 493's and allowed remote requests.
One last werench.. the two 493's are not connected via ethernet cable, but rather over a couple other devices with wireless WDS bridges, just made it simple to understand and removed those. But they are all in bridging. ( I know, switch to routed network) THis is not a ISP network, just private lan, its not going to get huge. Just 5 locations networked.

Would it e easier to set up an EoIP from ether 1 to the main 493 firewall, and have a public IP be assigned to the second 493?

Thanks for some help!

One funny thing, nothing works except Skype connects somehow. in the above setup I have.
 
BobcatGuy
Member Candidate
Member Candidate
Topic Author
Posts: 240
Joined: Thu Apr 19, 2007 7:41 am

Re: Connect 493 as firewall to another 493 as firewall ( Natted)

Sun Mar 14, 2010 11:55 am

Figured no one would respond..

Anyways, just like I thought, there must be some thing broken in ROS.. I tried and tried, and what seemed to get this to work was to get the ether 1 as a DHCP cleint, to get an IP from the main firewall....

You say, well, yeah, becuase the check box for add defualt route was on so it puts 10.10.10.1 ( ip of main firewall) in the route as 0.0.0.0/24 -> 10.10.10.1

The dumb part is that I did this manually before, and created a static route just like the dynamic one is automatically created, but it didnt work. I rebooted the router after the DHCP on ether 1 setup, and then specified an IP address for ether 1, and rebooted and added the default route, rebooted, removed the dhcp lease of my notebook from within the second 493, and reconnected the notebook. Then it works.

No problems..

as to why, there has to be something broken. I have another issue that I just discovered.. See my other post about Simple QUEUE Not working, Until you disable then re-enable it... FRUSTRATING

Who is online

Users browsing this forum: abdulschizo, ACHim, Amazon [Bot], chrisk, DimoSK, mike7, mozerd, RiStaR and 81 guests