First time with RouterOS, where to start, how to configure?

I was able to configure the dhcp server.
But still I don’t understand how to configure the ISP router…

I was able to give the private network an IP with the dhcp server. But how does the private network use the ISP ‘internet’?

And how to configure the other network to receive an IP form the ISP router?

Thank you

Ok I searched a bit further…

Now I was able to give one port an IP of the ISP router… by setting the masterport of to the port where the ISP router is connected…
But off course I can not set a masterport on a bridge… How do i configure this?

Thanks

still waiting for feedback…

Are my reply’s invisible :smiley:
Can someone help please?

Post your export and exactly what is wrong. I can look at it later today.

what do you mean by output?

I want in one subnet that all devices receive an IP from the ISP dhcpserver,
in the other subnets I want that the devices receive an IP from my own dhcp server on the microtik switch.

I could figure most things out, but I am still unable to find how to give one subnet ip’s from my isp dhcpserver… How can I configure the bridge that all devices under it receive an ip from ISP…

I’m not sure what you mean? Post a diagram of your network… and what exactly you want to accomplish… as for the export…

Copy and paste the output of /export into ROS2 tags on this site (click on select syntax at the top of the post and click router os)…

-Eric

I deleted all settings again to start from scratch, so there is no output, because i don’t know what to do…

I don’t have a diagram… how do I make this?

Maybe you can assist me a bit with msn/skype/…?

thank you very much

Maybe. This weekend is pretty busy for me. If I get a chance I can setup a basic config and post it here… should basically do what you want from what I can tell… I’ll just assume your CRS has no config.

Diagram software… look around on the forum… there are tons (visio, dia, omnigraffle, etc)… personally I’m on OSX and use Omnigraffle.

At some point maybe we can chat and I can help you set it up remotely if you give me access.

-Eric

can you already help me how I can configure the subnet to receive ip’s from my isp dhcprouter?

/ip dhcp-client
add interface=ether1-gatewayOr something like that depending on the interface. That sets up a dhcp client on the specific interface.

I will try to setup everything, i will make a diagram if necessary. If I need additional help I will let you know, thanks a lot already!

Ok i tried to setup the switch, hereunder is my output.
It seems that my device on port10 is getting an IP but it cannot access internet…

Please have a look at it :slight_smile:
/interface bridge
add l2mtu=1588 name=private_bridge
/interface wireless
set [ find default-name=wlan1 ] l2mtu=2290
/interface ethernet
set [ find default-name=ether4 ] master-port=ether3
set [ find default-name=ether5 ] master-port=ether3
set [ find default-name=ether6 ] master-port=ether3
set [ find default-name=ether7 ] master-port=ether3
set [ find default-name=ether8 ] master-port=ether3
set [ find default-name=ether9 ] master-port=ether3
set [ find default-name=ether10 ] master-port=ether3
set [ find default-name=ether11 ] master-port=ether3
set [ find default-name=ether12 ] master-port=ether3
set [ find default-name=ether13 ] master-port=ether3
set [ find default-name=ether14 ] master-port=ether1
set [ find default-name=ether15 ] master-port=ether1
set [ find default-name=ether16 ] master-port=ether1
set [ find default-name=ether17 ] master-port=ether1
set [ find default-name=ether18 ] master-port=ether1
set [ find default-name=ether19 ] master-port=ether1
set [ find default-name=ether20 ] master-port=ether1
set [ find default-name=ether21 ] master-port=ether1
set [ find default-name=ether22 ] master-port=ether1
set [ find default-name=ether23 ] master-port=ether1
set [ find default-name=ether24 ] master-port=ether1
/interface ethernet switch
set 0 bridge-type=service-vlan-bridge bypass-l2-security-check-filter-for=“”
bypass-vlan-ingress-filter-for=“” drop-if-invalid-vlan-on-ports=“”
drop-if-no-vlan-assignment-on-ports=“” drop-invalid-vlan=no
egress-mirror-ratio=1/1 egress-mirror0-enable=yes egress-mirror0-format=
modified egress-mirror0-port=cpu egress-mirror1-enable=yes
egress-mirror1-format=modified egress-mirror1-port=cpu
egress-sampling-ratio=1/1 fdb-uses=mirror0 igress-mirror0-port=cpu
igress-mirror1-port=cpu ingress-mirror-ratio=1/1 ingress-mirror0-enable=yes
ingress-mirror0-format=modified ingress-mirror1-enable=yes
ingress-mirror1-format=modified invalid-vlan-lookup-mode=ivl
ipv4-multicast-lookup-mode=dst-mac-and-vid-always mac-level-isolation=no
mirror-egress-if-ingress-mirrored=no mirror-tx-on-mirror-port=no
mirrored-packet-drop-precedence=0 mirrored-packet-qos-priority=0
override-existing-when-ufdb-full=no unicast-fdb-age=5m
use-cvid-in-one2one-vlan-lookup=yes use-svid-in-one2one-vlan-lookup=no
vlan-level-isolation=no vlan-uses=mirror0
/ip hotspot user profile
set [ find default=yes ] idle-timeout=none keepalive-timeout=2m
mac-cookie-timeout=3d
/ip pool
add name=dhcp_pool1 ranges=192.168.14.2-192.168.14.254
add name=dhcp_pool2 ranges=192.168.15.2-192.168.15.254
/ip dhcp-server
add address-pool=dhcp_pool1 disabled=no interface=ether2 name=“AP DHCP”
add address-pool=dhcp_pool2 disabled=no interface=private_bridge name=
“PRIVATE DHCP”
/port
set 0 name=serial0
/interface bridge port
add bridge=private_bridge interface=wlan1
add bridge=private_bridge interface=ether3
/interface ethernet switch port
set 0 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 1 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 2 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 3 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 4 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 5 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 6 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 7 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 8 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 9 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 10 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 11 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 12 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 13 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 14 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 15 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 16 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 17 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 18 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 19 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 20 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 21 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 22 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 23 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 24 egress-vlan-mode=unmodified isolation-profile=1
qos-pcp-dei-map-drop-precedence=0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1
qos-pcp-dei-map-priority=0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(un
known),vlan-based,(unknown),da-based,sa-based,pcp-based,ingress-policy-based
,(unknown)”
set 25 egress-vlan-mode=unmodified qos-pcp-dei-map-drop-precedence=
0,1,0,1,0,1,0,1,0,1,0,1,0,1,0,1 qos-pcp-dei-map-priority=
0,0,0,0,1,1,1,1,2,2,2,2,3,3,3,3 qos-resolution=“(unknown),vlan-based,(unknow
n),da-based,sa-based,pcp-based,ingress-policy-based,(unknown)”
/ip address
add address=192.168.14.0/24 interface=ether2 network=192.168.14.0
add address=192.168.15.0/24 interface=private_bridge network=192.168.15.0
/ip dhcp-client
add dhcp-options=hostname,clientid disabled=no interface=ether1
/ip dhcp-server network
add address=192.168.14.0/24 dns-server=192.168.14.1 gateway=192.168.14.1
add address=192.168.15.0/24 dns-server=192.168.15.1 gateway=192.168.15.1
/lcd interface
set wlan1 interface=wlan1
set ether1 interface=ether1
set ether2 interface=ether2
set ether3 interface=ether3
set ether4 interface=ether4
set ether5 interface=ether5
set ether6 interface=ether6
set ether7 interface=ether7
set ether8 interface=ether8
set ether9 interface=ether9
set ether10 interface=ether10
set ether11 interface=ether11
set ether12 interface=ether12
set ether13 interface=ether13
set ether14 interface=ether14
set ether15 interface=ether15
set ether16 interface=ether16
set ether17 interface=ether17
set ether18 interface=ether18
set ether19 interface=ether19
set ether20 interface=ether20
set ether21 interface=ether21
set ether22 interface=ether22
set ether23 interface=ether23
set ether24 interface=ether24
set sfp1 interface=sfp1
/lcd interface pages
set 0 interfaces=“wlan1,ether1,ether2,ether3,ether4,ether5,ether6,ether7,ether8,
ether9,ether10,ether11”
set 1 interfaces=“ether12,ether13,ether14,ether15,ether16,ether17,ether18,ether1
9,ether20,ether21,ether22,ether23”

Up… Still not solved

Anyone with feedback?

Come on guys…

You appear to have the setup correct with a few problems,

1.IP addresses should be
/ip address
add address=192.168.14.1/24 interface=ether2 network=192.168.14.0
add address=192.168.15.1/24 interface=private_bridge network=192.168.15.0So that the router has a real IP address.

Also firewall rules and a NAT must be created to masquerade all traffic heading onto the internet as if it is coming from on of the DHCP leases of the ISP. thus all traffic out ether1 is to be masqueraded.

and the firewall rule blocking communication between the public and private subsets should also be created. I would recommend you use the winbox tool to create the firewall/NAT rules. Whilst I am proficient in creating them with the GUI(winbox) I don’t know the exact command line setup to use sorry.

Also you based upon your export you have a hotspot set up on what I believe to be the private wifi network. For security reasons I recommended that you use WPA2 sercurty wifi for the private network and hotspot for the public network. I can’t help you to setup a hotspot because I never use them, however I can hep you to create a WPA2 wifi network if you need me to.

If you need an more help perhaps we can arrange a Skype meeting or something similar so that I can demonstrate the setup and solve the problems in real time, whilst using the GUI tool set for non standard tasks. Get your problem solved soon you have been screwed around enough. Sorry I have not replied sooner I have been very busy and I have not logged on in a while

Hey,
no problem, your help is much appriciated!

Can we do the skype session? How can I contact you? I cannot send any private messages here…