I’m new in using the Mikrotik products and changed from a Netgear SRXN3205.
The configuration of my RB2011 was a little bit different but now it works.
Allthough there’s a Point that confuses me and I hope you can help me.
I’m having a cable Connection and my Provider supllied a Fritzbox 6320 Cable.
This device is used only as a “modem”. Unfortunately you just can put the RB2011’s IP as Exposed Host into the Fritzbox.
Ok, my Internet works fine but somethings as said before confuses me: I can reach the Fritzbox GUI through the RB2011.
Is this correct? I’m asking because this was not possible in my SRXN3205 - this device had a separate WAN-Port where the Fritzbox was connected to.
The Fritzbox Network: 192.168.178.0 the RB2011 192.168.127.0.
Do I have a security risk with this configuration?
The modem should be in “bridge” mode
the Mikrotik behind it should be configured as firewall and either DHCP or static IP depending on service level agreement with provider.
In the states we mostly use PPOE auth for DSL connections and just DHCP or static for cable connections… these are for residential services.
As long as your Mikrotik has the appropriate firewall rules and is updated you are safe.
You can search the Mikrotik forum for firewall rules best practices.
Hope that helps.
Ok, my Internet works fine but somethings as said before confuses me: I can reach the Fritzbox GUI through the RB2011.
Is this correct? I’m asking because this was not possible in my SRXN3205 - this device had a separate WAN-Port where the Fritzbox was connected to.
That’s normal. There is no dedicated WAN port on RB2011, every port could be configured as WAN port.
Do I have a security risk with this configuration?