Community discussions

MikroTik App
 
pr3dict
just joined
Topic Author
Posts: 9
Joined: Sat Jun 19, 2021 5:35 pm

Lte passthrough not working...

Mon Jun 21, 2021 11:26 am

Any help is appreciated. I've stumpled along so far. Management vlan is up and running and my other router receives it's IP address from the mikrotik but as soon as I enable LTE passthrough, connection through the unit is gone.
/interface lte
set [ find ] mtu=1470 name=lte1
/interface bridge
add ingress-filtering=yes name=bridge1 vlan-filtering=yes
/interface vlan
add interface=bridge1 name=vlan3 vlan-id=3
add interface=bridge1 name=vlan99 vlan-id=99
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface lte apn
set [ find default=yes ] apn=broadband default-route-distance=3 passthrough-interface=\
    vlan3 passthrough-mac=xx:xx:xx:Xx
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=default-dhcp ranges=192.168.88.10-192.168.88.254
/ip dhcp-server
add address-pool=default-dhcp interface=ether1 name=defconf
/interface bridge port
add bridge=bridge1 ingress-filtering=yes interface=ether1
/ip neighbor discovery-settings
set discover-interface-list=LAN
/interface bridge vlan
add bridge=bridge1 tagged=bridge1,ether1 vlan-ids=99,3
/interface list member
add comment=defconf interface=ether1 list=LAN
add comment=defconf interface=lte1 list=WAN
add interface=vlan99 list=LAN
add interface=vlan3 list=WAN
/ip address
add address=192.168.88.1/24 comment=defconf interface=ether1 network=192.168.88.0
/ip dhcp-client
add disabled=no interface=vlan99
/ip dhcp-server network
add address=192.168.88.0/24 comment=defconf gateway=192.168.88.1
/ip dns
set allow-remote-requests=yes servers=192.168.99.1
/ip dns static
add address=192.168.88.1 comment=defconf name=router.lan
/ip firewall filter
add action=accept chain=input comment="defconf: accept established,related,untracked" \
    connection-state=established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment="defconf: accept to local loopback (for CAPsMAN)" \
    dst-address=127.0.0.1
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
    in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=\
    in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" \
    ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
    connection-state=established,related
add action=accept chain=forward comment=\
    "defconf: accept established,related, untracked" connection-state=\
    established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" \
    connection-nat-state=!dstnat connection-state=new in-interface-list=WAN
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" disabled=yes \
    ipsec-policy=out,none out-interface-list=WAN
/system clock
set time-zone-name=America/New_York
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN
 
pr3dict
just joined
Topic Author
Posts: 9
Joined: Sat Jun 19, 2021 5:35 pm

Re: Lte passthrough not working...

Mon Jun 21, 2021 4:48 pm

Again - Any help is appreciated. Is there just some silent understanding that this doesn't work? It seems other posts keep getting replies but all of my questions go unanswered. Is there something I need to do to get some feedback/help?

Thanks.
 
Cablenut9
Long time Member
Long time Member
Posts: 542
Joined: Fri Jan 08, 2021 5:30 am

Re: Lte passthrough not working...

Mon Jun 21, 2021 4:59 pm

What version are you using?
 
pr3dict
just joined
Topic Author
Posts: 9
Joined: Sat Jun 19, 2021 5:35 pm

Re: Lte passthrough not working...

Mon Jun 21, 2021 5:29 pm

6.48.3
 
tdw
Forum Guru
Forum Guru
Posts: 1843
Joined: Sat May 05, 2018 11:55 am

Re: Lte passthrough not working...

Tue Jun 22, 2021 1:38 am

Why the odd MTU setting on the LTE interface?

You could try disabling VLAN filtering on the bridge, I had an issue where passthrough wouldn't connect with it enabled but didn't have chance to investigate in detail as to why.
 
pr3dict
just joined
Topic Author
Posts: 9
Joined: Sat Jun 19, 2021 5:35 pm

Re: Lte passthrough not working...

Tue Jun 22, 2021 3:28 am

I got it working by putting the vlan for passthrough on the ether1 instead of the bridge. the management vlan still on the bridge. Not sure why that fixed anything. I guess I can try the turning off ingress filtering.

As for the MTU. My ping was pretty high and I looked around it seems my cell provider uses a lower MTU so it drops some packets or something. Changing it fixed the issue though. Could be a placebo.
/interface lte
set [ find ] mtu=1470 name=lte1
/interface bridge
add ingress-filtering=yes name=bridge1 vlan-filtering=yes
/interface vlan
add interface=ether1 name=vlan3 vlan-id=3
add interface=bridge1 name=vlan99 vlan-id=99
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface lte apn
set [ find default=yes ] apn=broadband default-route-distance=3 passthrough-interface=\
    vlan3 passthrough-mac=00:00:00:00:00:00
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=default-dhcp ranges=192.168.88.10-192.168.88.254
/ip dhcp-server
add address-pool=default-dhcp interface=ether1 name=defconf
/interface bridge port
add bridge=bridge1 ingress-filtering=yes interface=ether1 pvid=3
/ip neighbor discovery-settings
set discover-interface-list=LAN
/interface bridge vlan
add bridge=bridge1 tagged=bridge1,ether1 vlan-ids=99
add bridge=bridge1 tagged=ether1,bridge1 vlan-ids=3
/interface list member
add comment=defconf interface=ether1 list=LAN
add comment=defconf interface=lte1 list=WAN
add interface=vlan99 list=LAN
/ip address
add address=192.168.88.1/24 comment=defconf disabled=yes interface=ether1 network=\
    192.168.88.0
/ip dhcp-client
add disabled=no interface=vlan99
/ip dhcp-server network
add address=192.168.88.0/24 comment=defconf gateway=192.168.88.1
/ip dns
set allow-remote-requests=yes servers=192.168.99.1
/ip dns static
add address=192.168.88.1 comment=defconf name=router.lan
/ip firewall filter
add action=accept chain=input comment="defconf: accept established,related,untracked" \
    connection-state=established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment="defconf: accept to local loopback (for CAPsMAN)" \
    dst-address=127.0.0.1
add action=drop chain=input comment="defconf: drop all not coming from LAN" disabled=\
    yes in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=\
    in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" \
    ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
    connection-state=established,related
add action=accept chain=forward comment=\
    "defconf: accept established,related, untracked" connection-state=\
    established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" \
    connection-nat-state=!dstnat connection-state=new disabled=yes in-interface-list=\
    WAN
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" disabled=yes \
    ipsec-policy=out,none out-interface-list=WAN
/system clock
set time-zone-name=America/New_York
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN

Who is online

Users browsing this forum: Amazon [Bot], Bing [Bot], fposavec, Semrush [Bot] and 58 guests