Help needed to configure

Hi everyone,
I now have an infrastructure I make in order to host some games for my community of gamers. I have an AOC cable connected to my server, which is use as a proxmox virtual environment (PVE). I got a VM hosting PfSense but unfortunately, I cannot use all the services PfSense can offer. Iptables is terrible as I don’t use both 10G ports on the server.
This is the diagram I wish to go to:

I hope someone will take a bit time to explain me how can I configure my CRS305 to get a nice working infrastructure… :smiley:

What I can/can’t do which can be helpful:

  • I can DMZ from modem/router
  • Link between modem/router is only AOC
  • Links between CRS305 and server are only DAC
    Wishes:
  • I’d like to access proxmox from anywhere
  • I have a webserver in VMs (80 and 443)

http://forum.mikrotik.com/t/forward-port-80-on-wan-to-192-168-1-10-80-from-outside-and-inside-networks/164301/2

https://www.youtube.com/watch?v=BbDnBxlBTdY

For wire speed performance limit CRS305 configuration to VLAN switching. CRS305 can route and firewall, it’s just not good at those jobs.

Does modem/router at 192.168.0.254 support tagged VLAN packets on interface to CRS305?

I don’t think so. Settings on modem/router are cheap ^^
Edit: Sure it ain’t support tagged VLAN. I just saw on the ticket website (someone ask for it…)

In my case, I just want to know how to share 1 wan/2 lans.

Well, I just need to:

  • 1 wan → 2 lans
  • isolate lan1 and lan2

I’ve found a youtube link: https://www.youtube.com/watch?v=WpHoojpAe1k
Is it ok? If yes: src address list in Firewall/NAT/+/Advanced is no more there so do you know where it is?

Your LAN design is different subnets requiring routing. CRS305 has L3 Hardware Offloading which has limits made worse by CFS305 specific switch chip.

Within L3HW limits, CRS305 will route at wire speed but outside L3HW limits, throughput falls off a cliff; CPU is small. If WAN link is slow enough then L3HW limit won’t matter.

Design carefully. Start with CRS305 specifications page, Test results tab, Ethernet test results section.