Community discussions

MikroTik App
 
jsavinc
just joined
Topic Author
Posts: 2
Joined: Thu Jun 09, 2016 9:35 pm

Layer 7 packet marking between multiple devices

Sat Jun 25, 2016 9:25 pm

Hi everyone,

apologies if this is a silly question, I'm an autodidact.

I run a network with 24 APs, a mix of NETGEAR WNAP210 and MikroTik RB951G-HnD units, connected to a gateway Draytek Vigor 300B load-balancing over 3 WANs (to be upgraded to a pfSense device or MikroTik router).

Is it possible to do layer 7 filtering and mark the packets on the APs, and then use the markings on the gateway to route them to a particular WAN or give them priority? My thinking is that because layer 7 filtering is fairly CPU intensive, it would make sense to do it on the AP, rather than on the gateway. This is for purposes of traffic shaping, and making sure Skype traffic stays on a particular WAN.
 
User avatar
BartoszP
Forum Guru
Forum Guru
Posts: 2880
Joined: Mon Jun 16, 2014 1:13 pm
Location: Poland

Re: Layer 7 packet marking between multiple devices

Sat Jun 25, 2016 9:28 pm

Mikrotik marking is internal only ... the "tags" do not leave router .... but ...
You can do packet classification at AP level or at any device and then pass the trafic to particular VLAN inside this device and then shape particular VLAN's traffic at the router .... just an idea ...
 
User avatar
shaoranrch
Member Candidate
Member Candidate
Posts: 184
Joined: Thu Feb 13, 2014 8:03 pm

Re: Layer 7 packet marking between multiple devices

Sun Jun 26, 2016 1:41 am

You could also set the DSCP marking on a per packet basis from the APs then the main router would be able to interpret this since these markings are part of the IP header and so they can travel the whole network with routers being aware of them.

Enviado desde mi MotoE2(4G-LTE) mediante Tapatalk
 
jsavinc
just joined
Topic Author
Posts: 2
Joined: Thu Jun 09, 2016 9:35 pm

Re: Layer 7 packet marking between multiple devices

Thu Jun 30, 2016 3:26 pm

Thank you for your suggestions, both!

I'm fairly comfortable with VLANs, so I'll look into this first. Part of my network is already divided into VLANs, so I suppose I could divide it further and have a separate VoIP/video VLAN, for example.
I'll look into DSCP, looks like my Draytek WAN balancer supports that, too.

Who is online

Users browsing this forum: No registered users and 115 guests