Community discussions

MikroTik App
 
georgios
just joined
Topic Author
Posts: 6
Joined: Mon May 22, 2017 9:27 am

Public IP Firewall with Bridging Wan Interface

Tue Sep 25, 2018 1:03 am

Helllo,

In order to assign directly Public IP on my Servers and Have FIREWALL with Mikrotik, I follow this tutorial https://www.youtube.com/watch?v=c91uXBF22n4&t=711s

I take two interface :
ETH_WAN : my Internet Provider delivering me /27 (30 publics IP)
ETH_VLANx: Special VlanX created on the Switch to put all my server / Public IP filtered

I did a "BRIDGE" with ETH_WAN and ETH_VLANx

I setup IP/Firewall with "FORWARDING" (drop or accept Traffic) from this BRIDGE.

One a our server does not accept the DSTNAT Translation because of too strange streaming IIS server....and It's helpful for some configurations.

My questions are:
- are they any better option to assign Public IP with Mikrotik Firewall rules? like Bridge/Filters?
- to you suggest a better setup?

many thanks
 
Sob
Forum Guru
Forum Guru
Posts: 9121
Joined: Mon Apr 20, 2009 9:11 pm

Re: Public IP Firewall with Bridging Wan Interface

Tue Sep 25, 2018 1:59 am

It's not exactly clear what you want and what doesn't work. The point of bridging config is to give public addresses directly to internal devices. But you complain about some dstnat, where did that come from?
 
georgios
just joined
Topic Author
Posts: 6
Joined: Mon May 22, 2017 9:27 am

Re: Public IP Firewall with Bridging Wan Interface

Tue Sep 25, 2018 2:33 pm

Yes I could like to give access directly to servers. / I do not want to do any DSNAT.

But in the same tim I would like also to do transparent "firewalling" with the bridge.

I currently did it with two ETH interfaces and IP/Firewall.

Is this the best way ? or should I use Bridge/Firewall?

many thanks.
 
Sob
Forum Guru
Forum Guru
Posts: 9121
Joined: Mon Apr 20, 2009 9:11 pm

Re: Public IP Firewall with Bridging Wan Interface

Wed Sep 26, 2018 3:54 am

If you mean that you had NAT before and changed it to bridging to get rid of it, then it makes sense.

What to say about it, it works. Bridge firewall is a little more low-level. It could be used for some purposes, but it won't give you things like connection states and other extras.

Another approach could be using proxy-ARP, but I can't say in what sense it would be clearly better.

Who is online

Users browsing this forum: abbio90, alixviral, anav, jaclaz, VirtualEvan and 196 guests