Upgraded a couple RB912UAG-2HPnD’s to v6.41rc18 and IP Passthrough does not seem to work with Sierra Wireless MC7700 as mentioned in the Supported LTE Aircards list. Log indicates it does not like the apn1/ether1. Does anyone have a log to share showing what a successful IP Passthrough connection looks like? Doesn’t look like any North American Band LTE MiniPCI-e cards are supported. I don’t suppose you could share which MiniPCI-e card you will be shipping in the wAP LTE kit-US?
I think you are supposed to substitute the APN that your carrier uses in the apn field, not literally use ‘apn1’, IOW the command should read something like: /interface lte set lte1 apn=/ether1 (or whatever ethernet port you are using.)
Right: I was using apn=broadband/ether1. But as uldis points out the Sierra cards don’t support ip pass-through. I’d be very interested in hearing about any MiniPCI-e cards which do work. I have been trying a Sierra EM7455 but can’t get RB to recognize it at all, I think there may be an issue with the adapter card I’m using to make it fit.
I’m not sure why you guys consider Sierra Wireless cards, such as the MC7700 or the USB AirCard 313U, not being capable of doing IP passthrough. I can give you two specific examples from my personal use of these functioning beautifully in that mode.
The CradlePoint IBR600 router, which I’ve owned and used for serveral years before I hopped onto MikroTik, specifically has an IP passthrough mode. Once in that mode, all other features are turned off and the router essentially becomes an LTE-to-ethernet dongle, passing the external IP address through either of the ether ports. Mine had an MC7700 card in it as the factory option. Worked perfectly.
My other example is Proxicast’s PocketPort2 dongle, wich I have used for many years for this very purpose with a Sierra Wireless AirCard 313U card on both AT&T and T-Mobile. Plug the USB modem into one end, an ethernet cable to, let’s say, a wired-only router in the other, and bam, the router is getting the outside LTE IP address.
TEST: Over the weekend I tried the new IP passthrough feature in ROS 6.41 RC23 with both cards above installed/plugged into two routerboards, and indeed, they did not work at all with the new feature and the modified APN. (Note that otherwise both work flawlessly with the regular APN on any Routerboard that can accomodate one or the other.)
I hope my two examples will help you guys in experimenting some more to make these cards work with the new ROS feature.
My apologies in advance if I misunderstood your post. Nonetheless…
Your screenshot above suggests that you are subscribed to a cellular connection which gets you a dynamic IP address. Getting IP passthrough working on the MC7700 will not, on its own, allow you to remote in from the outside. The problem is that the IP address doled out by the cellular carriers is, on purpose, not routable (hence the weird message pointed to by the red arrow). If it were, you could still remote in without IP passthrough using DDNS and port forwarding into the router, just like with a home/office dynamic IP scenario.
To solve this, with or without IP passthrough, you have two options:
Get a static IP address from your carrier, which I’ve done and worked great for remoting in, but often expensive.
The better solution is to create a VPN setup whereby the LTE gadget, as soon as it’s turned on, dials out to the serving router and initiates a tunnel. Once the tunnel is up, you can, at any time, remote in via the local IP address on the LTE gadget side. It’s essentially the LTE gadget remoting into the server side router and stands ready for you to reach back in.
Thanks MikroGik, your help is much appreciated. I see what you’re saying about a cellular carrier assigned IP being un-routable.
I will attempt to learn how to implement your suggested VPN option. Unfortunately I’m not an IP networking expert - if you could point me in the direction of some information on how to setup a tunnel I’d appreciate it. One question that comes to mind: would the VPN client in the LTE gadget need a server side router on a static IP to “dial out” to or could DDNS be made to work on both ends?
Your question first: On the server end, yes, you can use DDNS, no need for static IP. On the client side, you don’t care what IP address the gadget receives from the cellular provider, as long as the LTE gadget knows, once its online, to dial into the DDNS address of the the server router. Once it does, the tunnel will be established. And since you will have entered into the server router the fixed local IP address you’ve chosen for the LTE gadget, it can reach out at any time, once the tunnel is up, to the same local address. Consequently, there’s no need for ddns on the client side.
So, the VPN we’re talking about is in fact a “site-to-site” VPN. Which means that on both ends there is a local network of multiple possible host machines behind the router, even if it’s only one (here, the LTE gadget). So not just the server side, but also the LTE gadget side must be a router.
I recommend chosing L2TP over IPSec site-to-site VPN. With the latest versions of ROS, it’s much easier to set up and has the added advantage that you can also a remote-access VPN in from either a Win or Mac laptop, both of which can easily support L2TP over IPSec.
I recommend going over this MT manual page and its diagrams first to familiarize yourself with whole thing: https://wiki.mikrotik.com/wiki/Manual:Interface/L2TP#Site-to-Site_L2TP. Sections 5.1 and 5.2. Take care when googling MikroTik site-to-site L2TP/IPsec as most info out there is now obsolete given the latest ease-of-use modifications by MikroTik in setting up this type of VPN.
I’ve got question regarding WAP LTE KIT:
To set it in passthrough mode I need:
/interface lte apn add name=internet passthrough-interface=bridge
/interface lte set lte1 apn=internet
??
I’ts running bridge mode - will be connected to ether1 on hAP AC and latest RC firmware is there too so I’m checking what’s missing. Cheers!
Yes. those are the correct commands. You will have only the hap ac connected to the wap lte? If not, then you need to specify the passthrough-mac aswell with the hap ac ether1 mac address.
Also note that you will not be able to connect to the wap lte via the passthrough host, so my suggestion would be to create a vlan between the wap lte and hap ac or maybe remove the wlan1 from the bridge on the wap lte so you can later connect to the wap lte via wireless if you would like to change the configuration.
My situation looks like this:
I've got hAP AC, WAP LTE and HEX PoE. Building house right now and idea for network is to connect:
hAP AC and HEX PoE using SFP <- HEX PoE will be acting as a switch so all ethernet interfaces will be in bridge as I need extra 3-4 ports with PoE to power my RPi in different rooms (they will be together in one room)
WAP LTE will be in the attic connected to that pair I've just mentioned using PoE, I think I'll assign static IP and direct all traffic from LAN (in hAP AC) to that IP address
So hAP AC + HEX PoE using SFP gives me 10 ethernet ports with PoE on 6 on them (I need 3-4 PoE), hAP AC acts as a router for LAN.
To get internet hAP will be connected with WAP LTE (using VLAN?) and WAP LTE will have static IP assigned that will be my gateway IP.
If anyone can comment any of those ideas would be great.
EDIT
Passthrough is postponed as I need to get public IP from my cellular provider.
I have spare RB951G that I wanted to try with Huawei E3372s-153 (Megafon provider). After puting commands with passthrough, apn etc. on ether1, and connecting ether1 to my laptop, my computer doesn’t get any IP form MikroTik. Is this modem supported or am I missing something?
We have tried similar modem and get similar issue.
Mikrotik support replied that they found an issue and it was fixed in v6.41rc39. We are waiting this to be published in order to test it.
I got it working with rc44 but not the way I was thinking it will work. My laptop got IP from Huawei’s LAN range (198.168.8.0/24). I thought it will get IP directly from ISP…
So, is this the proper way it is should work, or am I missing something? In my opinion it doesn’t make sense. NAT is USB modem anyway, and we all wanted to have one and only NAT on MikroTik.