Community discussions

MikroTik App
 
muetzekoeln
Member Candidate
Member Candidate
Topic Author
Posts: 167
Joined: Fri Jun 29, 2018 2:34 pm

Avoid double PAT

Mon Nov 26, 2018 7:43 pm

I already read many threads and manual pages, but I am stuck with one very special problem.
Given are two independent DSL lines, each with a router (=CPE) I have no control over. Each CPE has one public IPv4 address and one private network (each)
(10.0.0.254/24 resp. 192.168.0.254/24) for me to use. Configuring two interfaces for backup and/or load sharing is not the problem. But having a RB960PGS and a LAN
with address 10.10.10.0/24, how to translate addresses by avoiding port-address-translation (=PAT) by my RB? PAT is already done in each of the CPEs.
ip1 - CPE1 --- sfp1--RB960PGS--ether1 --- CPE2 - ip2
                         |
                       ether5
                         |
                         |
                        LAN
 
User avatar
Jotne
Forum Guru
Forum Guru
Posts: 3300
Joined: Sat Dec 24, 2016 11:17 am
Location: Magrathean

Re: Avoid double PAT

Mon Nov 26, 2018 7:51 pm

There are no way you can get around this easy. You have two private net on outside.
So if you want to be able to use both of them, you need to use NAT so you get a third different net on your side.
This will give you double NAT
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19370
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Avoid double PAT

Mon Nov 26, 2018 10:43 pm

Concur, screwed!
Use the private one for all basic internet access and the public one to host whatever services you need to host.
 
User avatar
Steveocee
Forum Guru
Forum Guru
Posts: 1120
Joined: Tue Jul 21, 2015 10:09 pm
Location: UK
Contact:

Re: Avoid double PAT

Mon Nov 26, 2018 11:06 pm

What are you doing that double PAT is becoming a problem? I only ask because there is so much "oooooooh don't do that" about this but rarely is the root cause mentioned other than the originator has "read it's bad".
What are you struggling doing OP?

Is there any room to speak with the ISP and ask them to DMZ an IP in their LAN range which you can specify into your RB to minimise this?
 
User avatar
CZFan
Forum Guru
Forum Guru
Posts: 2098
Joined: Sun Oct 09, 2016 8:25 pm
Location: South Africa, Krugersdorp (Home town of Brad Binder)
Contact:

Re: Avoid double PAT

Mon Nov 26, 2018 11:53 pm

Ask ISPs to add route on CPEs to be our LAN range via the RB960.
 
muetzekoeln
Member Candidate
Member Candidate
Topic Author
Posts: 167
Joined: Fri Jun 29, 2018 2:34 pm

Re: Avoid double PAT

Tue Nov 27, 2018 1:51 pm

What are you doing that double PAT is becoming a problem?
I am afraid it will break SIP and/or give problems with online gaming.
... you need to use NAT so you get a third different net on your side.
This will give you double NAT
What about doing srcnat-netmap from LAN to CPEs and put sfp1 and ether1 into local-proxy-arp mode? This should give 1:1 translation of network addresses. But will IP port numbers change (PAT)? Would this make it better for online gaming? What about SIP? I guess Mikrotiks SIP-Helper will fail?
Is there any room to speak with the ISP and ask them to DMZ an IP in their LAN range which you can specify into your RB to minimise this?
Ask ISPs to add route on CPEs to be our LAN range via the RB960.
For ISP1 there will be no talks. It is more difficult even. CPE1 has two Interfaces with two different private networks. One is for data, and one for their SIP (walled garden). For ISP2, I may be allowed to use my own router and do PPPoE.

Who is online

Users browsing this forum: Syn and 73 guests