Community discussions

MikroTik App
 
supermega
just joined
Topic Author
Posts: 21
Joined: Sun Sep 25, 2011 8:06 pm

station-pseudobridge replacement?

Mon Nov 14, 2011 8:36 pm

Hi,

"This mode is available for all protocols except nv2 and should be avoided when possible."
http://wiki.mikrotik.com/wiki/Manual:Wi ... eudobridge

However this mode is very useful and I don't know how to replace it. The drawback of poor handling non-IP traffic is negligible.

Great advantage of station-pseudobridge is that it masks MAC address of hosts on ether1 - this guarantees that MAC is not spoofed.

Can anyone propose an easy solution too secure against MAC spoofing on ether1? Filtering MACs is NOT easy - requires me to reconfigure MT every time the MAC changes.
 
cieplik206
Trainer
Trainer
Posts: 290
Joined: Sun Jul 01, 2007 12:25 am
Contact:

Re: station-pseudobridge replacement?

Mon Nov 14, 2011 11:25 pm

is it used as a CPE ?

if yes, why are you bridging, maybe your mikrotik box will be a router ??
 
supermega
just joined
Topic Author
Posts: 21
Joined: Sun Sep 25, 2011 8:06 pm

Re: station-pseudobridge replacement?

Tue Nov 15, 2011 12:34 am

Yes, CPE. Routing creates other problems. Routers need to know what IP is behind the CPE and I can't divide address space into small subnets (to little public IPs).
 
cieplik206
Trainer
Trainer
Posts: 290
Joined: Sun Jul 01, 2007 12:25 am
Contact:

Re: station-pseudobridge replacement?

Tue Nov 15, 2011 10:53 pm

I understand, only way to avoid mac spoofing is a static ARP on a next L3 device,

Do you use DHCP with static leases ? If yes then DHCP server can automatically set static ARP entry,

If not you have to do it manually yourself



thinking.... pseudobridge is doing nothing esle then MAC-SRC-NAT istn't ???

in bridge you have NAT tab try to make a SRC-NAT chain with SRC-NAT action, maybe this will work
 
supermega
just joined
Topic Author
Posts: 21
Joined: Sun Sep 25, 2011 8:06 pm

Re: station-pseudobridge replacement?

Wed Nov 16, 2011 6:57 am

Does MAC NAT maintain any NAT table as in L3 NAT? I guess it doesn't. So we need to DNAT returning packet (first check in L3 if it's not directed to MT itself). For DNAT we need to set host MAC address which again forces us to reconfigure MT after each MAC change.

Who is online

Users browsing this forum: kekraiser and 80 guests