Community discussions

MikroTik App
 
bduijnhouwer
just joined
Topic Author
Posts: 6
Joined: Fri Jul 31, 2020 12:06 pm

Connect two subnets

Mon Mar 22, 2021 10:42 pm

Image

New day, new problem, new drawing :-)
I have on my Mikrotik two DHCP servers, one listening to 'bridge' with scope 192.168.88.10-192.168.88.100
and the other one listening to 'ether1' with scope 192.168.2.10-192.168.2.100

From my laptop (192.168.88.20) I can ping my phone (192.168.2.20) but not the other way around.
Both subnets do have internet access.

I would like that my phone (192.168.2.20) for example can access my homeassistant on internal ip address (192.168.88.70)
Only I don't know if I have to do this with a sort of masquerade rule, a firewall rule or a route.
And I also don't know what to put in it then.

Can anyone help me here?

update: drawing error: 192.128.88.1 should be 192.168.88.1 offcourse...
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 11613
Joined: Thu Mar 03, 2016 10:23 pm

Re: Connect two subnets

Mon Mar 22, 2021 10:54 pm

Proper solution would be to add static route towards 192.168.88.0/24 via gateway 192.168.2.1 on ISP router. And add some firewall rules which would allow desired connections and block the rest. And drop SRC-NAT on mikrotik, ISP router should do it for both parts of network.

I'll assume you really want both parts if your LAN separated this way. And that you can actually reconfigure ISP router.
 
bduijnhouwer
just joined
Topic Author
Posts: 6
Joined: Fri Jul 31, 2020 12:06 pm

Re: Connect two subnets

Mon Mar 22, 2021 11:03 pm

I read the answer above here and I realised that I forgot to tell a few things.
The internet router is a Experiabox v10 and has nothing much to configure, so I'd like to configure most parts on the Mikrotik.

The Experiabox does has a better WiFi, so I'd really like to use that.
My two LAN's doesn't need to be separated.
 
User avatar
bpwl
Forum Guru
Forum Guru
Posts: 2993
Joined: Mon Apr 08, 2019 1:16 am

Re: Connect two subnets

Mon Mar 22, 2021 11:20 pm

Yes, easy, if you agree that it then is one network. (Else see answer MKX)

Easiest steps ... on the Mikrotik while connected to the 192.168.88.0/24 network
- backup the current config
- give a 192.168.2.x/24 address to the bridge (for later management access)
- assign a new or move the DHCP client to the bridge. (This will give a second 192.168.2.x address later to the bridge, but will also set DNS and gateway for the Mikrotik only internet access)
- disable the DHCP server on the bridge (we can only have one subnet, and one DHCP server will do). You will lose connection now.
- connect the ether1 cable to ether2 port or other LAN ethernet port !!!
- reconnect your management PC or device. It will now get an 192.168.2.0/24 address from DHCP on the internet router. Access the Mikrotik with the address given in step 2.

Actually here you are up and running, the Mikrotik is now a bridge/switch. Everything behind the internet router is one network 192.168.2.0/24.
- to reclaim the use of ether1: connect ether1 as bridge-port to the bridge. (ether1 will now also be a LAN port like all the other ethernet ports.)
- The Firewall is not used but this firewall and other settings will not block the traffic. Connections can still be tracked in the firewall.

- Now you can still go back, by removing ether1 from the bridge, reassign the DHCP client to ether1, and re-enable the DHCP server
- clean up the config if you want (like remove the IP 192.168.88.1 address, DHCP server, Firewall ...). This might need you to fully reset/restore the Mikrotik to go back.

I assume that the DHCP server 192.168.2.0/24 is in the internet router. Please check that you still have that one active.
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 11613
Joined: Thu Mar 03, 2016 10:23 pm

Re: Connect two subnets

Tue Mar 23, 2021 11:00 am

If you follow instructions by @bpwl ... I don't see a point in having Mikrotik in the first place. It will act as a dumb switch ... which you already have in place.

So you really have to decide the role of Mikrotik router in your LAN. However, if it is to be firewall for your LAN, then ... well, it would be possible to make things work, but your wireless devices would not be protected by it (since they are on the "wrong" side of it).
 
bduijnhouwer
just joined
Topic Author
Posts: 6
Joined: Fri Jul 31, 2020 12:06 pm

Re: Connect two subnets

Tue Mar 23, 2021 1:16 pm

I just found my final solution ...
I bought a MikroTik RB4011iGS+5HacQ2HnD-IN 802.11ac router

This has 5GHz WiFi and with that my problem is hopefully solved.

Thanks for all the answers !

Who is online

Users browsing this forum: chris8896 and 40 guests