Community discussions

MikroTik App
 
User avatar
bjorncmtec
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 98
Joined: Thu Apr 19, 2012 1:10 pm

Mikrotik Hotspot Bypass/Exclusion for Subnets

Tue Jul 08, 2014 3:45 pm

I have setup a hotspot on an interface that has 2 IP ranges programmed.

- HotSpot range 192.168.16.0/24
- IP Camera range 172.19.0.128/27

I'm trying to exclude the second range from being caught by the Hotspot.

For this i have done an IP Binding with "bypassed" as the field. This is however not working. Bypass only seems to work on the 192.168.16.0/24 network

See below the firewall rules that get created by the hotspot

Image

See below my IP binding with bypassed

Image
 
SurferTim
Forum Guru
Forum Guru
Posts: 4636
Joined: Mon Jan 07, 2008 10:31 pm
Location: Miramar Beach, Florida

Re: Mikrotik Hotspot Bypass/Exclusion for Subnets

Tue Jul 08, 2014 4:42 pm

Have you tried disabling the hotspot universal NAT?
/ip hotspot
set 0 address-pool=none
If 0 is not the line number of your hotspot, change that.
 
User avatar
bjorncmtec
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 98
Joined: Thu Apr 19, 2012 1:10 pm

Re: Mikrotik Hotspot Bypass/Exclusion for Subnets

Wed Jul 09, 2014 9:14 am

Hi Tim

thanks for your advise, i have changed the address pool to none but it is still blocking the IP Camera range

Image
 
sanitycheck
newbie
Posts: 48
Joined: Wed Nov 16, 2011 6:03 am
Location: USA

Re: Mikrotik Hotspot Bypass/Exclusion for Subnets

Wed Jul 09, 2014 10:30 pm

I'm guessing you are way past this, but did you add an IP address to that shared interface for the camera IP subnet to use as a gateway (e.g. 172.19.0.1), and do you have a route for same?

I have a similar setup with several hotspot access points on a subnet different from the range used by the hotspot. When those addresses are bypassed just as you did, I can ping a host on the Internet using a tool that is part of the access point. So it is possible.
 
User avatar
bjorncmtec
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 98
Joined: Thu Apr 19, 2012 1:10 pm

Re: Mikrotik Hotspot Bypass/Exclusion for Subnets

Thu Jul 10, 2014 11:32 am

Yes the cameras have a seperate gateway of 172.19.0.129 (172.19.0.128/27).
 
sanitycheck
newbie
Posts: 48
Joined: Wed Nov 16, 2011 6:03 am
Location: USA

Re: Mikrotik Hotspot Bypass/Exclusion for Subnets

Fri Jul 11, 2014 7:53 pm

In the picture of the firewall rules it looks like you made modifications to accomodate the special 172.19.0.x subnet. In my case I did not make any changes to the default rules configured by the hotspot setup.

Also, my IP bindings are different. I list only Address, Server, and Type. I leave MAC address and To Address blank.
 
User avatar
bjorncmtec
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 98
Joined: Thu Apr 19, 2012 1:10 pm

Re: Mikrotik Hotspot Bypass/Exclusion for Subnets

Wed Jul 16, 2014 9:39 am

You will see the "D" tag on the left, this is a rule automatically created by the hotspot. IF i disabled the hotspot they dissapear.
 
User avatar
nick3dos
Member Candidate
Member Candidate
Posts: 189
Joined: Fri Apr 29, 2011 11:03 pm
Location: Greece

Re: Mikrotik Hotspot Bypass/Exclusion for Subnets

Wed Jul 16, 2014 10:29 am

Also, add the 172.19.0.128/27 network to the Walled Garden IP List of your Hotspot.
 
User avatar
bjorncmtec
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 98
Joined: Thu Apr 19, 2012 1:10 pm

Re: Mikrotik Hotspot Bypass/Exclusion for Subnets

Wed Jul 16, 2014 12:26 pm

Thanks ill try that.
 
User avatar
bjorncmtec
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 98
Joined: Thu Apr 19, 2012 1:10 pm

Re: Mikrotik Hotspot Bypass/Exclusion for Subnets

Wed Jul 16, 2014 12:28 pm

I realised why the rules 172.19.0.128/27 were automatically added by the hotspot. Its becuase i had already aadded them to the Walled Garden IP List.

Both SRC and DST of those Subnets.

Still blocks my connections :(
 
User avatar
nick3dos
Member Candidate
Member Candidate
Posts: 189
Joined: Fri Apr 29, 2011 11:03 pm
Location: Greece

Re: Mikrotik Hotspot Bypass/Exclusion for Subnets

Wed Jul 16, 2014 12:41 pm

Have your tried to connect a computer to your camera network ?
If yes, does hotspot login page comes up? (it souldn't), if not maybe something else blocking your connections...
The 172.19.0.129 gateway, how it's connected to your mikrotik device?
 
User avatar
bjorncmtec
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 98
Joined: Thu Apr 19, 2012 1:10 pm

Re: Mikrotik Hotspot Bypass/Exclusion for Subnets

Mon Jul 28, 2014 4:13 pm

Unfortunately i am remote from the site +-600km away.
 
User avatar
nick3dos
Member Candidate
Member Candidate
Posts: 189
Joined: Fri Apr 29, 2011 11:03 pm
Location: Greece

Re: Mikrotik Hotspot Bypass/Exclusion for Subnets

Tue Aug 05, 2014 1:15 pm

Try in your IP binding to delete all data from "Mac Address" and "To Address"

Who is online

Users browsing this forum: Ahrefs [Bot], Bing [Bot], elvtechnology, GoogleOther [Bot] and 77 guests