Community discussions

MikroTik App
 
brotherdust
Member Candidate
Member Candidate
Topic Author
Posts: 130
Joined: Tue Jun 05, 2007 1:31 am

VLAN->Transparent Bridge Bandwidth Control->VLAN

Fri Feb 22, 2008 7:41 pm

Hi guys,
This one is really eating my lunch. =/
Here's the setup:
I have a cisco 2950T (2 gigabit ports) at the core of my network.
I have a bandwidth management system that works via a bridge (astroflowguard)

My new (shiny) firewall, powered by ROS 3.3, is physically connected via a trunk link to gigabit port 1 to the cisco 2950.

I'll give you a logical traffic flow for my current setup, then I'll give you the same for the setup I'll be implementing with this new firewall.

Current setup: Let's go from a client machine to the internet:
Client -> Wireless Bridge -> Internal Router (Run on a Cisco 3550) -> Bridged Bandwidth Management -> Firewall -> Internet

You can see that I have passed through 2 subnets before I even got to the internet, which is fine. Now, I am trying to install this new ROS firewall to closely approximate this current setup, but allow me to replace my Internal Router, and Firewall. So, here's my planned setup:

Client -> Wireless Bridge -> ( ROS Firewall (On vlan 60) -> ROS Firewall (Vlan 30) this is internal process) -> Bridged Bandwidth Management -> ROS Firewall (vlan 20) -> ROS Firewall (Vlan 10) again, an internal process) -> Internet

So, basically I'm using this ROS firewall as the core router of my network (typical router on a stick setup). The PROBLEM is that I can't figure out a rule to force traffic out of the internal process and onto VLAN 30 for processing by the Bandwidth Management System, which will then land back on vlan 20. All of the traffic stays internal to the device (since the routing and arp tables have all the answers).

I was thinking I could make a rule that said something like, "If the traffic is bound for x address, then output on this interface (or maybe go to x mac address?), instead of staying internal"

I'm not sure how to explain this better. Please, ask me questions. Any thoughts would be appreciated greatly!

Thanks!
 
User avatar
gmsmstr
Trainer
Trainer
Posts: 982
Joined: Fri Jun 04, 2004 2:22 am
Location: St. Louis, MO
Contact:

Re: VLAN->Transparent Bridge Bandwidth Control->VLAN

Fri Feb 22, 2008 11:31 pm

why not just use MT as the bandwidth management, put it in bridge and you are good!
 
brotherdust
Member Candidate
Member Candidate
Topic Author
Posts: 130
Joined: Tue Jun 05, 2007 1:31 am

Re: VLAN->Transparent Bridge Bandwidth Control->VLAN

Fri Feb 22, 2008 11:44 pm

why not just use MT as the bandwidth management, put it in bridge and you are good!
Yes! That's a great idea, but not feasible at this moment as I haven't thoroughly researched MikroTik's bandwidth management. We have about 400 customers in the bandwidth controller at the moment. Do you think that (when I am done with this) ROS can handle that many clients? (Not to digress much from the conversation at hand).

Thanks!
 
brotherdust
Member Candidate
Member Candidate
Topic Author
Posts: 130
Joined: Tue Jun 05, 2007 1:31 am

Re: VLAN->Transparent Bridge Bandwidth Control->VLAN

Sun Feb 24, 2008 2:29 am

Hello? Anyone out there?
 
User avatar
gmsmstr
Trainer
Trainer
Posts: 982
Joined: Fri Jun 04, 2004 2:22 am
Location: St. Louis, MO
Contact:

Re: VLAN->Transparent Bridge Bandwidth Control->VLAN

Sun Feb 24, 2008 3:27 am

Sorry for the delay. However, I KNOW, Mikrotik can handle this without issues!

Let see recently.::

-- Successfully ran 2600 PPPoE Clients with queues on one MT box
-- 300meg + traffic with a quite a few firewall rules without issues
-- Known deployments controlling / routing 3000+ clients
-- known usages running 1000 + customers per tower

yep, I know it can cause i have done it :)
 
brotherdust
Member Candidate
Member Candidate
Topic Author
Posts: 130
Joined: Tue Jun 05, 2007 1:31 am

Re: VLAN->Transparent Bridge Bandwidth Control->VLAN

Sun Feb 24, 2008 4:39 am

Sorry for the delay. However, I KNOW, Mikrotik can handle this without issues!

Let see recently.::

-- Successfully ran 2600 PPPoE Clients with queues on one MT box
-- 300meg + traffic with a quite a few firewall rules without issues
-- Known deployments controlling / routing 3000+ clients
-- known usages running 1000 + customers per tower

yep, I know it can cause i have done it :)

Ok. I can respect that. So, what you're saying is that I can really trust this ROS? =)
One more question for you -
Would you mind showing (perhaps with a snippet of config) how it is that you queue? I've looked at the wiki and the connection-based one is really neat. Is this the one you use?
Thanks for your time. I know it's valuable.

Who is online

Users browsing this forum: Ahrefs [Bot], anav, DanMos79, h1ghrise, Jeans, jmszuch1, sindy, youheng and 116 guests