Community discussions

MikroTik App
 
Macke
just joined
Topic Author
Posts: 8
Joined: Sun Aug 09, 2015 1:39 pm

Rb2011il-In

Sun Aug 09, 2015 5:58 pm

Hello,

I am new to this type of networking products and is grateful for all the help I can get!

I have been recommended to use Rb2011il-In in order to solve my task.
I wish to have verified that this product can solve this, and tips on configuring the device. (enclose a picture of the topology)
TOPOLOGY

Feel free to ask questions if anything is unclear!

Thanks in advance!

Best Regards Marcus
 
plisken
Forum Guru
Forum Guru
Posts: 2509
Joined: Sun May 15, 2011 12:24 am
Location: Belgium
Contact:

Re: Rb2011il-In

Mon Aug 10, 2015 12:32 pm

Have you made a config for this?
Don't use 2.4 GHz point to point links but 5 GHz links (tip)
If you have a configuration go to terminal and do export.
Paste the result here on this forum.
Hide sensitive information such as passwords.
 
bkuhn
Frequent Visitor
Frequent Visitor
Posts: 72
Joined: Fri Oct 15, 2010 12:17 am

Re: Rb2011il-In

Tue Aug 11, 2015 2:11 am

Yes, a RB2011 can handle what you have in your topology.

What part do you need help with?
 
Macke
just joined
Topic Author
Posts: 8
Joined: Sun Aug 09, 2015 1:39 pm

Re: Rb2011il-In

Tue Aug 11, 2015 8:09 pm

Hello

Thanks for the replies. I will order the product and familiarize myself with it :)
I will return with any issues when they arise :?

/Marcus
 
Macke
just joined
Topic Author
Posts: 8
Joined: Sun Aug 09, 2015 1:39 pm

Re: Rb2011il-In

Thu Aug 27, 2015 8:36 pm

Hello,

I have familiarized myself with the menus on the Winbox now.

What I want to create is to connect my existing router (LAN) in Ether1 and then my Wi-Fi link on Ether2. This works with the default configuration as it comes with. But the problem is that I can access all devices from Ether2 available in Ether1 network. I want Ether2 only be able to connect to the Internet via Ether1s LAN without seeing what's there (other LAN IP's).

/Marcus
 
jebz
Member
Member
Posts: 367
Joined: Sun May 01, 2011 12:03 pm
Location: Australia

Re: Rb2011il-In

Sat Aug 29, 2015 7:15 am

I want Ether2 only be able to connect to the Internet via Ether1s LAN without seeing what's there (other LAN IP's).
/Marcus
In Winbox go to IP, Firewall and make a new rule to drop the traffic from the neighbor network interface (source port 6 in your diagram) to your destination 192.168.1.0/24 internal network.
 
Macke
just joined
Topic Author
Posts: 8
Joined: Sun Aug 09, 2015 1:39 pm

Re: Rb2011il-In

Sat Aug 29, 2015 3:12 pm

I want Ether2 only be able to connect to the Internet via Ether1s LAN without seeing what's there (other LAN IP's).
/Marcus
In Winbox go to IP, Firewall and make a new rule to drop the traffic from the neighbor network interface (source port 6 in your diagram) to your destination 192.168.1.0/24 internal network.
Thanks for the reply. I tried to add a new rule but i got this message ? Message
 
jebz
Member
Member
Posts: 367
Joined: Sun May 01, 2011 12:03 pm
Location: Australia

Re: Rb2011il-In

Sun Aug 30, 2015 3:56 am

Thanks for the reply. I tried to add a new rule but i got this message ? Message
You need to remove port 6 from the group so it's a standalone interface with address 192.168.2.1/24 . I'd think about moving this separate network to port 10. It then has a bit of logical separation and is easier to separate from the group by removing it's slave status from the default master port of 6.

You also shouldn't have out interface in the rule as the destination to be blocked is 192.168.1.0/24
I just reviewed your network diagram. You'll need an allow for 192.168.1.1 before this block rule to pass the internet destined traffic. Normally the adsl routers can be bridged to enable the more flexible and powerful features of the RB2011 router to be utilized.
 
Macke
just joined
Topic Author
Posts: 8
Joined: Sun Aug 09, 2015 1:39 pm

Re: Rb2011il-In

Sun Aug 30, 2015 8:44 am

Thanks for the reply. I tried to add a new rule but i got this message ? Message
You need to remove port 6 from the group so it's a standalone interface with address 192.168.2.1/24 . I'd think about moving this separate network to port 10. It then has a bit of logical separation and is easier to separate from the group by removing it's slave status from the default master port of 6.

You also shouldn't have out interface in the rule as the destination to be blocked is 192.168.1.0/24
I just reviewed your network diagram. You'll need an allow for 192.168.1.1 before this block rule to pass the internet destined traffic. Normally the adsl routers can be bridged to enable the more flexible and powerful features of the RB2011 router to be utilized.
Since I'm a beginner I'm a little unsure about all the steps needed to be done.
I have done the following (screenshot) , but no effect on port 10?
 
jebz
Member
Member
Posts: 367
Joined: Sun May 01, 2011 12:03 pm
Location: Australia

Re: Rb2011il-In

Sun Aug 30, 2015 12:26 pm

Since I'm a beginner I'm a little unsure about all the steps needed to be done.
I have done the following (screenshot) , but no effect on port 10?
There's a few configurations items from the default that you don't need. The old address 192.168.88.1 is one. You also probably have a scrnat rule that's no longer required.
You'll need to add a default gateway on the RB2011 192.168.1.1 . You'll also need to add a route on the ADSL router for 192.168.2.0/24 with gateway 192.168.1.99 the address of the RB2011.

These extra configuration items come about because you have 2 routers in the mix. Consider bridging the ADSL router so it acts as a modem and things get simpler. Later you can expand it back when you get a feel for the Mikrotik.
 
Macke
just joined
Topic Author
Posts: 8
Joined: Sun Aug 09, 2015 1:39 pm

Re: Rb2011il-In

Tue Sep 01, 2015 9:07 pm

Ok, I'll do as you say and tries to bridge the ADSL router. Then I can test some basic configurations. Thanks for all the help so far :)

Who is online

Users browsing this forum: Amazon [Bot], pfturner and 50 guests