New Home Setup VLANs

Thanks for the quick reply anav,

From your post, I already have 1 and 2 from previous configurations.

I added the third (firewall nat) rule. I am not trying to port translate. I am able to connect to the server on the desired port from my ADMIN computer. However, when I try to connect to it from outside my network I get nothing.

Trying with the dns from dynu, I can see the mikrotik mainpage if I try from my ADMIN computer, but nothing from outside the network.

Any thoughts?

How are you trying to connect to it from the outside??

By the way I just signed up for dynu, and used the microtik cloud ddns (as one can assign a cname in dynu) and thus you dont need a script on the router at all!!!

Is your admin PC in the same SUBNET as the server?? I thought it was a different VLAN??

My admin PC is on VLAN101, the server on VLAN10. Note that the ADMIN PC has access to everything on the network.


Oh, do tell about this mikrotik cloud ddns. Do I just use enable the cloud function within mikrotik and then some config on the dynu side?

Edit:
Ok, I got the CName cloud ddns working.

I still can’t get access to the server from the outside..

can you post a complete config again or email it to me.

Emailed to you.

I have never used this setting…I would get rid of it.
/interface detect-internet
set detect-interface-list=WAN

Why do you have this enabled…
/ip upnp
set enabled=yes

I would consider turning this off set to none, if the functionality is not required
/tool mac-server
set allowed-interface-list=LAN

Other than that I cannot see what could be preventing port forwarding from working??
I am not familiar with pppoe interfaces and maybe it doesnt like in-interface-list=WAN ??? in the dstnat rule - its a stretch

try: in-interface=pppoe wan

Well, I tried diff configs on that rule.. There is no pppoe-wan interface..

Admin
Internet
LAN
WAN
All
Dynamic
None

The detect internet is my fault. I forgot it on. It’s set to none now..

from your config???
/interface list member
add comment=defconf interface=“Home Bridge” list=LAN
add interface=“PPPoE WAN” list=WAN


Hmm maybe try putting as a member of the list=WAN
add interface=“1 - Valerie WAN” list=WAN

Trying all the other interfaces wont work LOL.
but if the above is correct then in-interface-list=WAN should work.

Added 1- Valerie to the WAN list. Seems a bit redundant as PPPoE WAN is using 1-Valerie to connect to the internet..

No dice.

so the PPPoE WAN is using port 1 which is connected to the ISP router. I don’t have anything connected to the ISP router… There is the possibility that there is some double NAT’ing going on there?

Edit: I thought by using the PPPoE it would avoid double NAT. I’m a bit confused now…

Is this maybe what is causing the problems? How would I switch over from PPPoE to using an IP from the ISP router?

Okay lets zero in on your ISP connection.
Is it DSL, Cable, Fiber etc.
Is it cellular??

How are you physically connecting the ISP to the Mikrotik??

I am with Virgin Mobile, sub of Bell (canadian ISPs).

I have a Valerie all-in-one that brings FTTH. on eth1 of Valerie, I have the Mikrotik connected to eth1. I am using PPPoE from the Mikrotic to enable the web access. I went the PPPoE route because I thought it would help remove the possibility of double NAT.

The rest is in the config I sent you.

I guess what are the options on the FTTH?
Is it a modem or a modem/router?
Can you access the FTTH?
If so is there a bridge passthrough mode?

Does the FTTH provide pppoe output?
Can you give me an example of what IP address it gives you - just use fake numbers but so we get the idea of what it looks like?

This may be your unit but it only shows WIFI connection…???
https://www.virginmobile.ca/en/support/internet/assisted-self-install.html

Ref: https://www.virginmobile.ca/en/support/internet/interactive-guides.html

It is a modem/router. and the options inside are less than desirable. There is no bridge mode/passthrough modes.

Right now the way I have it hooked up, when I login to Valerie, I don’t see any other devices connected. I have Wifi disabled, and eth shows nothing connected. The PPPoE is logged on Valerie (it has an IP assigned to it) and the PPPoE on the Mikrotik is logged on (it has a separate IP).

That’s about all I can do with it?

It looks like you are trying to use pppoe on a built in wifi router modem.
Suggest you call Virgin and let them know you want a unit that is configured only as a modem and not a wifi router and see what they say.

Yes it would appear you are screwed into a double nat scenario unless the IP you pull, I am assuming that you can connect to it via ethernet, may be wide open.
To check attach ethernet to the wan port but just assume its a straight ethernet connection (aka cable) and NOT pppoe connection.


Call them and state you want to use your own router and see what they do. They may be able to do something over the lines or you may need a new device from them??

Wow, it is taking me so long to get back to this!

I haven’t called the ISP yet. I wanted to first try the other option you just mentioned being without the PPPoE connection. I’m not exactly sure how to configure the switch to remove the pppoe and let it get internet straight from the ISP modem. The only place I can see to configure that is from the quickset page.. but that looks like it is going to change a lot more than just my pppoe settings.

Thanks for your help.

First thing I need is the latest config. So that I am working with the latest actual setup.

emailed to you! :slight_smile:

Taking a look at the config,
I would do a couple of things differently
for example on interface-list members.
Remove the bridge - LAN
and replace with all the vlans - LAN
also add the ethernet-1 to WAN (to go along iwth the pppoe name) to wan.
Then see if your results change.


next…
Ive established I can ping your server and I believe attempt to connect via SSH but obviously dont have the right parameters.
So it looks like the connectivity may be there. Is it possible there are some settings on the SSH server that is blocking?

only other thing I can think of is modify the destination nat rule from this
add action=dst-nat chain=dstnat comment=“SERVER PORT FORWARDING” dst-port=
2202 in-interface-list=WAN protocol=tcp to-addresses=192.168.10.10
to-ports=22

TO
add action=dst-nat chain=dstnat comment=“SERVER PORT FORWARDING” dst-port=
2202 dst-address-list=mydnscloudIP protocol=tcp to-addresses=192.168.10.10
to-ports=22

where in firewall address list you make
add address= your cloudddns name list=mydnscloudIP ( the router will resolve the name to an IP)

Finally, if nothing above works,
try disabling not deleting this rule and try again, just wondering if its interfering some how??
add action=accept chain=forward comment=“Server Access” dst-address-list=LAB
in-interface=“Server/Lab VLAN10” src-address=192.168.10.10