ether1-fibre -> fibre router (CISCO) - Intended as primary internet
ether2-lte -> LTE router (Huawei B618) - Intended as backup internet
ether3-master -> POE switch - For SIP phones and Wifi POE - Intended to be master-port
ether4 -> Gigabit switch - For PCs
ADDRESSES
Code: Select all
Flags: X - disabled, I - invalid, D - dynamic
# ADDRESS NETWORK INTERFACE
0 ;;; defconf
192.168.88.1/24 192.168.88.0 bridge1
1 X 192.168.55.1/24 192.168.55.0 *1
2 192.168.8.2/24 192.168.8.0 ether2-lte
3 D 10.0.0.3/24 10.0.0.0 ether1-fibre
ROUTES:
Code: Select all
Flags: X - disabled, A - active, D - dynamic,
C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme,
B - blackhole, U - unreachable, P - prohibit
# DST-ADDRESS PREF-SRC GATEWAY DISTANCE
0 A S ;;; Default Route
0.0.0.0/0 ether1-fibre 1
1 S 0.0.0.0/0 ether2-lte 2
2 ADC 10.0.0.0/24 10.0.0.3 ether1-fibre 0
3 ADC 192.168.8.0/24 192.168.8.2 ether2-lte 0
4 ADC 192.168.88.0/24 192.168.88.1 bridge1 0
NAT:
Code: Select all
Flags: X - disabled, I - invalid, D - dynamic
0 chain=srcnat action=masquerade out-interface=ether1-fibre log=no
log-prefix=""
1 chain=srcnat action=masquerade out-interface=ether2-lte log=no
log-prefix=""
INTERFACES:
Code: Select all
Flags: D - dynamic, X - disabled, R - running, S - slave
# NAME TYPE ACTUAL-MTU L2MTU MAX-L2MTU
0 R ether1-fibre ether 1500 1596 2026
1 R ether2-lte ether 1500 1598 2026
2 RS ether3-master ether 1500 1598 2026
3 RS ether4 ether 1500 1598 2026
4 ether5 ether 1500 1598 2026
5 R ;;; created from master port
bridge1 bridge 1500 1598
PROBLEM:
The primary internet works fine and I have gateway-check="ping", however when attempting to fail over to the backup internet the routing breaks.
DIAGNOSIS:
- I can ping the LTE router (192.168.8.1) from the Mikrotik and my internal network
- I can ping the outside network from the LTE router so the internet connection is working (via the browser interface)
- I see connection probes coming through the LTE router from the internet to the Mikrotik firewall
- I cannot ping outside network from the Mikrotik when specifying the ether2-lte interface. It returns "timeout" then intermittently "192.168.8.2 host unreachable"
- If I adjust the distance on the ether1-fibre route so the ether2-lte becomes active then nothing works
SUMMARY:
This should be working and I don't understand why it's not. I suspect it may be due to me importing the config from a hEX LITE router which caused some issues with the master-port and switching ports.
If there is any other information I can provide please ask