Community discussions

MUM Europe 2020
 
synapsis
newbie
Topic Author
Posts: 26
Joined: Thu Jan 13, 2005 7:41 am
Location: Canberra, Australia

Allowing connections between devices on multiple LANs

Thu Jan 13, 2005 8:00 am

Hi there

It's probably going to be a simple answer and something obvious that I have missed, but I have tried all of the obvious things, read the manual and can't seem to work this one out.

I am running RouterOS version 2.18.22 with a total of 5 Ethernet interfaces. One of the Ethernet goes to my ADSL modem, and using Source Masquerading, devices on all of the other networks can successfully access the Internet.

From each LAN, obviously I can ping devices on the same segment, however I have found that I can ping the Ethernet Address of each of the other LAN Interfaces on the router, but I cannot ping or access any devices on any of the other LANs connected to the router.

I haven't posted the entire config, but I have included the relevant section relating to firewalling and the source masquerading as that is my guess as to where the problem might be.

/ ip firewall
set input name="input" policy=accept comment=""
set forward name="forward" policy=accept comment=""
set output name="output" policy=accept comment=""
/ ip firewall rule input
add protocol=tcp connection-state=established action=accept comment="Allow Established TCP Connections" disabled=no
add protocol=udp action=accept comment="Allow UDP Connections" disabled=no
add protocol=icmp action=accept comment="Allow ICMP Connections" disabled=no
add src-address=192.168.10.0/24 action=accept comment="Allow access from trusted network 192.168.10.0/24" disabled=no
add src-address=192.168.20.0/24 action=accept comment="Allow access from trusted network 192.168.20.0/24" disabled=no
add src-address=192.168.30.0/24 action=accept comment="Allow access from trusted network 192.168.30.0/24" disabled=no
add src-address=192.168.40.0/24 action=accept comment="Allow access from trusted network 192.168.40.0/24" disabled=no
add action=reject comment="Reject everything else" disabled=no
/ ip firewall service-port
set ftp ports=21 disabled=no
set pptp disabled=no
set gre disabled=no
set h323 disabled=yes
set mms disabled=no
set irc ports=6667 disabled=no
set quake3 disabled=no
set tftp ports=69 disabled=no
/ ip firewall src-nat
add out-interface="ether5 - Link to the ADSL Modem" action=masquerade comment="" disabled=no
/ ip firewall connection tracking
set enabled=yes tcp-syn-sent-timeout=2m tcp-syn-received-timeout=1m tcp-established-timeout=5d tcp-fin-wait-timeout=2m \
tcp-close-wait-timeout=1m tcp-last-ack-timeout=30s tcp-time-wait-timeout=2m tcp-close-timeout=10s udp-timeout=30s \
udp-stream-timeout=3m icmp-timeout=30s generic-timeout=10m
/ ip address
add address=192.168.10.254/24 network=192.168.10.0 broadcast=192.168.10.255 interface="ether2" comment="" \
disabled=no
add address=192.168.20.254/24 network=192.168.20.0 broadcast=192.168.20.255 interface="ether3" \
comment="" disabled=no
add address=192.168.30.254/24 network=192.168.30.0 broadcast=192.168.30.255 interface="ether4" \
comment="" disabled=no
add address=192.168.40.254/24 network=192.168.40.0 broadcast=192.168.40.255 interface="ether1" comment="" \
disabled=no

Any suggestions welcomed, and I can provide other snippets from the config as reuqired...

Richard
 
User avatar
mag
Member
Member
Posts: 378
Joined: Thu Jul 01, 2004 12:32 pm
Location: Cologne, NRW, Germany
Contact:

Re: Allowing connections between devices on multiple LANs

Thu Jan 13, 2005 9:04 am

in every LAN the .254 (the mt) is set as default gateway on the hosts?

"/ ip firewall rule forward" is empty?

what does a traceroute from a host in on LAN to a host in another lan show?

no other filters or firewall devices between LAN and mt?

regards.
 matthias
 
synapsis
newbie
Topic Author
Posts: 26
Joined: Thu Jan 13, 2005 7:41 am
Location: Canberra, Australia

Thu Jan 13, 2005 9:10 am

Yep, the default gateway is .254 and this is set on all workstations.

There are no other devices doing any firewalling in the network.

Traceroute shows that there is a response from the gateway (.254) and then just times out.

/ip firewall forward is empty at this stage as I'm back to basics are part of trying to diagnose the problem. I have tried forwarding,, but to no avail, but that could have been a misconfiguration by me I guess...

Thanks

Richard
 
User avatar
dwright
Member Candidate
Member Candidate
Posts: 158
Joined: Fri May 28, 2004 1:10 pm
Location: Mchenry, Il

Sun Jan 16, 2005 7:53 pm

what does your routes table look like?
Do you have any routing rules that could be overriding the default table?

Who is online

Users browsing this forum: BlueTechnomage, Google [Bot], Kaos1337, msmeja, MSN [Bot], tito123 and 105 guests