I’m a system engineer, but I need to tackle this network situation. This might not be the place for this question (please redirect me if it’s not).
Network administrator has left and deleted all network devices configurations. I have managed to get this working, but this definitely needs improving.
I am looking for pointers and a nudge in the right direction so I can improve this setup.
The RB2011 uses almost-default setup, except Eth2 has 192.168.1.6 IP.
The RB2011 is now connected like on the picture below:

- The computers on public LAN can communicate with those on private LAN and al have internet access
- The 192.168.1.0/25 (first segment) LAN has it’s DHCP server I have no access to
- I have no access to the main router and the device performing NAT and VPN
- UniFi AP’s use above DHCP
- First server is a Windows DC and has public and private IP’s on two interfaces
- Second server is a virtualization host and has public and private IP’s on two interfaces so VM’s can communicate with everyone
- I have installed WiFi controller VM and it also has public and private IP’s
- Management interfaces are connected to a 5-port switch and then to Eth10. I can only communicate with them if a change the IP to its subnet on the server
So, that is the situation now. I am trying to accomplish the following:

- Since I cannot configure the main router, I can live with private and public IP’s on servers and VM’s
- I want to move AP’s to 192.168.2.0/24 LAN and configure DHCP on the RB2011 for WiFi clients and provide internet access
- WiFi controller must be able to communicate with AP’s on 192.168.2.0/24 subnet and have a public IP.
- The problem here is that VM host has only two interfaces configured for public and 192.168.1.0/25 LAN’s
- I would like to communicate with the management interfaces without having to change server’s IP to one of 10.1.1.0/24 range
Any nudge or the pointer in the right direction will be more than appreciated.
Anything more and I owe you a beer.