Community discussions

MikroTik App
 
wulfwareltd
just joined
Topic Author
Posts: 4
Joined: Thu Oct 09, 2014 10:04 pm

Problems with VLAN accessing Internet

Wed Feb 14, 2018 3:05 pm

Hello,

I have a network with hundreds of devices connected to network switches (non-mikrotik) and access points (again, non-mikrotik). This network is setup with multiple vlans and everything is working great on the LAN side.

Below are 4 images from winbox (sorry not familiar with the cli yet). I have setup vlan interfaces, switch vlan config and firewall rules, but I can't get my firewall settings to work to only allow certain VLans access to the internet. As you will see from my firewall rules in the below images, there is traffic arriving on the TMTITOffice VLan, so traffic is obviously being tagged correctly on the network switches.

However, if you look at my firewall rules, if I disable the LAN to WAN-VM rule, and enable the TMTITOffice to WAN-VM rule, internet access stops working about 10 - 15 seconds later.

Any idea's what I am doing wrong?

I'm guessing it has something to do with the network traffic having the correct VLAN ID before going out to the internet, but returning traffic doesn't have any VLAN ID associated with it, so it gets dropped?

Firewall (Filter):
Image

Firewall (NAT)
Image

Interfaces:
Image

Switch (Not sure if this is needed - I read somewhere I need this for tagged traffic?):
Image

Cheers,

Matt
 
User avatar
acruhl
Member
Member
Posts: 371
Joined: Fri Jul 03, 2015 7:22 pm

Re: Problems with VLAN accessing Internet

Thu Feb 15, 2018 2:24 am

There's not enough information here. You should do /export hide-sensitive from the cli.

It appears that you might have multiple internet connections based on your interface naming, you should explain that.

I doubt you're passing tagged packets to your ISP, so I'm not sure what you're saying about packets being properly tagged. Routing to the ISP happens completely at layer3, vlans are irrelevant at layer 3.
 
p3rad0x
Long time Member
Long time Member
Posts: 637
Joined: Fri Sep 18, 2015 5:42 pm
Location: South Africa
Contact:

Re: Problems with VLAN accessing Internet

Thu Feb 15, 2018 9:47 am

Maybe the 2 last drop rules causing your problem. Try disabling only those and check if it fixes the issue.
 
wulfwareltd
just joined
Topic Author
Posts: 4
Joined: Thu Oct 09, 2014 10:04 pm

Re: Problems with VLAN accessing Internet

Thu Feb 15, 2018 10:58 am

There's not enough information here. You should do /export hide-sensitive from the cli.

It appears that you might have multiple internet connections based on your interface naming, you should explain that.

I doubt you're passing tagged packets to your ISP, so I'm not sure what you're saying about packets being properly tagged. Routing to the ISP happens completely at layer3, vlans are irrelevant at layer 3.
We do have multiple internet connections, but I have disabled all the configuration for the second line to simplify trying to work out why this isn't working correctly. I know the tagged packets won't get sent to the ISP but I don't know whether I have to do something on the MikroTik so that when packets come back from my ISP they are re-tagged with the correct VLAN based on connection tracking?

I can no longer export the configuration as this is the only router on site and people need to use the internet so I had to remove all the VLAN configuration and put it back as it was :/

Ignoring the second connection, what I want to have is:

Port 1 - ISP
Port 2 - LAN - Tagged packets from switch, with ether ID:1 (Default VLAN) or ID:201 through to ID:208 for departments.

All computers are in the same IP range of 10.0.0.0/8 and any vlan security is done by our switches (They have the vlan config to decide which vlans can communicate with each other). This is due to high volume of traffic between vlans (several gigabit constant).

All I want is the router to have IP 10.255.255.1 on port 2 LAN and have firewall rules to dictate which vlans have access to the internet (Port 1)

Cheers,

Matt

Who is online

Users browsing this forum: Bing [Bot], mszru and 47 guests