Locking port to public up address

Got a really interesting project on the go :smiley:

What used to be a farm has been converted into a business park and 30 companies expanding to upwards of 100 are going to be sharing a 1gb internet connection spread across the whole site

We have had guys pull in a around 5k of fibre and I have a a combination of mikrotik ccr kit to distribute connectivity to everyone. At the core I have a couple of ccr1072-1G-8S+ routers that will take the incoming connection and distribute to clients using fibre links connected to CRS226-24g-2s+ switches at points over the site

I was simply planning to have two vlans, public and mangement so inly use can the switch configuration.

I was thinking of using proxy-arp to make the public ip addresses available to everyone connected to the public vlan

I was then going to make a queue against each public IP to limit the throughput on the CCR1072.

Think I’m ok with this in the main, it’s just switching and IP so pretty simple stuff (I’m hoping)

I do however how a few questions, let’s start with the easy one :laughing:

  1. It is possible to have the screens on the ccs units display nothing other than the hostname? Would be a nice touch for digital labelling on all kit? I know I can change various bits on the display but can’t see this as an option in winbox


    Getting a little more technical now?

  2. Using the acl on the switches, can I simply enter the allocated public IP address to stop the end users pinching anyone else’s allocated IP?


    Now the biggy

  3. Can I have two ccr1072 routers in an active/passive or even active/active configuration so if one fails everything will keep running.


    Thanks in advance for any help, I am pretty new to the mikrotik gear but have the say the power to cost functionality of this kit is fantastic. Totally love the kit and can’t see why you would ever buy anything else (apart from the fact the don’t do a 24 port Poe switch)