Community discussions

MikroTik App
 
doush
Long time Member
Long time Member
Topic Author
Posts: 665
Joined: Thu Jun 04, 2009 3:11 pm

Virtual Things for isolation

Wed Jul 04, 2007 12:14 pm

Well, I was in search for blocking the client to client traffic for a while ago and I gave up.


One of the ISPs here does the following. DHCP assigns an IP and a gateway to the customer. But the gateway is virtual and is -1 of the users IP address. Its like

192.168.178.50 ----> clients IP address
192.168.178.49 ----> Virtual Gateway

Client only communicates with the 192.168.178.49 due to the /30 subnet. and the virtual gateway only communicates with the real router.

WAN Router -----> Virtual GW ------> Client

So the client gets completely isolated from the others.

Do you know how to implement such kind of networking environment or is there a manual for it for MT ?

Thanks
 
User avatar
nazadnan2003
newbie
Posts: 31
Joined: Tue Sep 05, 2006 10:12 am
Location: Iraq
Contact:

Re: Virtual Things for isolation

Wed Jul 04, 2007 4:41 pm

If someone can help us to achieve this scenario
It will be the optimum soluthin for too many problems for example:
- client to client traffic.
- MAC Spoofing.

Thanks
Adnan Ahmed
 
pedja
Long time Member
Long time Member
Posts: 684
Joined: Sat Feb 26, 2005 5:37 am

Re: Virtual Things for isolation

Wed Jul 04, 2007 6:07 pm

I asked about this long time ago... haven't noticed that this is provided as option.
 
User avatar
warwick09
Member Candidate
Member Candidate
Posts: 190
Joined: Mon Aug 07, 2006 1:34 pm
Location: The Bahamas / Florida

Re: Virtual Things for isolation

Thu Jul 05, 2007 8:47 am

Well client to client traffic can easily* be managed via a wireless interface simply by disabling the intra communication option... as for wired networks, sad to say; a managed switched is required that has features like port security and more important vlans. example: Cisco catalyst 2900+ ....



The latter is for obvious reasons ... (layers)

Im not so much fam. with the virt. gateway proposal.... but hey if isolation/security is that important to you, you can always use a direct tunneling protocol such as pppoe.

Regards.
 
doush
Long time Member
Long time Member
Topic Author
Posts: 665
Joined: Thu Jun 04, 2009 3:11 pm

Re: Virtual Things for isolation

Mon Jul 16, 2007 1:16 pm

Well client to client traffic can easily* be managed via a wireless interface simply by disabling the intra communication option... as for wired networks, sad to say; a managed switched is required that has features like port security and more important vlans. example: Cisco catalyst 2900+ ....



The latter is for obvious reasons ... (layers)

Im not so much fam. with the virt. gateway proposal.... but hey if isolation/security is that important to you, you can always use a direct tunneling protocol such as pppoe.

Regards.
Currently Im using Mt as a standalone AAA Server with hotspot enabled. AP is a ZCOMAX 1500HP. Do you say that If i use Routerboards as an AP, I can disable client to client traffic in the wireless environment ?
 
User avatar
tgrand
Long time Member
Long time Member
Posts: 667
Joined: Mon Aug 21, 2006 2:57 am
Location: Winnipeg, Manitoba, Canada

Re: Virtual Things for isolation

Mon Jul 16, 2007 2:59 pm

Create a chain of /30 pools, and have each pool refernce the next pool.
It would take forever to set up all the pools, but you could write a script to do it for you.
 
User avatar
gustkiller
Member
Member
Posts: 419
Joined: Sat Jan 07, 2006 5:15 am
Location: Brazil
Contact:

Re: Virtual Things for isolation

Mon Jul 16, 2007 8:31 pm

can u post an exemple of that script?

Who is online

Users browsing this forum: lif2k3, lurker888, qatar2022, sas2k, svmk and 111 guests