Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.




5 posts

Wannabe Geek


Topic # 138514 7-Jan-2014 16:36 Send private message

Hi,

I am trying to configure the MikroTik RB750 to be fully bridge to a firewall, so the firewall will have the public IP at WAN with full control of traffic and port forwarding.

The RB750 is connected with Telecom UFB (fibre).


Connection:

Chrous ONT -----> (eth1) RB750 (eth2) -----> (WAN) firewall (LAN) ----> devices.




I am new to MikroTik product and RouterOS so not 100% sure the correct setup. Anybody who have experience please shed some light.



Thanks









Create new topic
7532 posts

Uber Geek
+1 received by user: 236

Trusted
Subscriber

  Reply # 962577 7-Jan-2014 16:48 Send private message

You probably want a transparent bridge, there's a thread here about a similar setup
http://www.geekzone.co.nz/forums.asp?forumid=66&topicid=136810






5 posts

Wannabe Geek


  Reply # 962606 7-Jan-2014 18:01 Send private message

Thanks for the reply. 

I did comes across that forum but I am not too sure if it will actually pass the Public IP over to the firewall.


So following are the configuration I have copy from the forum mentioned.

interface bridge add name=bridge1 disabled=no arp=enabled - in order to create a bridge
interface bridge port set ether0 bridge=bridge1 priority=128 path-cost=10 - To add the physical eth0(WAN cable from UFB) interface to the bridge.
interface bridge port set ether2 bridge=bridge1 priority=128 path-cost=10 - to add the physical eth1(Cable connecting UTM9s and Mikrotik) to the bridge.

Will these be all the command I need? Or there are more ?

what about the add ip address command mentioned in here: http://ferdi.blog.unas.ac.id/pengenalan-dasar/transparent-bridge-with-mikrotik/. What IP should I enter given the example below.


ONT  ------->     (eth1) RB750 (192.168.88.1)     ----->    (WAN public ip: 111.222.333.444/32) Firewall (Lan 192.168.15.1/24)      ---->          192.168.15.0/24




Thanks.

Just A Geek
1860 posts

Uber Geek
+1 received by user: 304

Trusted
Subscriber

  Reply # 962612 7-Jan-2014 18:15 Send private message

From factory...
Connect your computer to say port 3 as you will be doing stuff on ports 0/1
Celete DHCP Client from ether0
Create VLAN10 on eth0
Create a new Bridge
Add the VLAN10 and Port 1 to it.

Now that will bridge VLAN10 (UFB) and ether1

then run DHCP or PPPOE (or whatever your provider needs) on the firewall)

The Mikrotik is a pretty good firewall so any reason you don't want to use that to terminate the L3 Side of the UFB Connection? (your'd like RUN DHCP Cleint or PPPoE on the VLAN10 interface)

And if your Firewall cannot do VLANS maybe upgrade firmware/read manual as I presume you are using the Mikrotik as the firewall cannot do VLANS?




7532 posts

Uber Geek
+1 received by user: 236

Trusted
Subscriber

  Reply # 962621 7-Jan-2014 18:31 Send private message

WickedWings: Thanks for the reply. 

I did comes across that forum but I am not too sure if it will actually pass the Public IP over to the firewall.



1: What make/model/software is your firewall? Can it do VLAN tagging on the WAN?
2: What is your ISP? Does the ISP use PPPoE or DHCP or something else for the connection?

The main reason to use a Mikrotik RB750 in addition to the firewall is if firewall can't do VLAN tagging (quite common on older stuff) on it's WAN interface or can't do PPPoE (which would be weird). Though their are other reasons for using the RB750 like load balancing over multiple connections etc but doesn't sound like the case here.

The Firewall would connect to the ISP and get the public ip address, dns, gateway etc (via PPPoE or DHCP) but it would go via the Mikrotik transparent bridge which adds the required VLAN tag id.





5 posts

Wannabe Geek


  Reply # 962634 7-Jan-2014 18:50 Send private message



1. The firewall is a Netgear UTM9s. I have contacted netgear and they are working on a firmware that will support VLAN on WAN for NZ UFB. Should be out next few month. So the RB750 is a temporary solution that I need.

2. ISP is telecom. I am actually not too sure which connection type they are using. Maybe someone can confirm this for me. At the moment I am just playing with free modem from telecom which can't do bridging......



Thanks

7532 posts

Uber Geek
+1 received by user: 236

Trusted
Subscriber

  Reply # 962638 7-Jan-2014 18:57 Send private message

Yeah you want the same setup as the other thread.

So you would setup PPPoE in the Netgear and transparent bridge in the Mikrotik.

Telecom uses PPPoE but you can put blank in the username and password as Telecom authenticates your account/session by physical line.

http://help.telecom.co.nz/app/answers/detail/a_id/1180

Operating Mode : MDI/MDIX
PPP Protocol : PPPoE
PPP Username: blank
PPP Password: blank
PPP Auth Type : blank
Encapsulation : 802.1Q
PCP Marking : 0
VID (or VLAN) : 10
MTU : 1,500 or AUTO



5 posts

Wannabe Geek


  Reply # 963876 9-Jan-2014 13:58 Send private message

It worked!!! Awesome.

Thanks to everyone who helped so promptly......

Cheers.

Create new topic








Twitter »
Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when new jobs are posted to our jobs board:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:




News »

Trending now »
Hot discussions in our forums right now:

Telecom introduces unlimited broadband data plan
Created by freitasm, last reply by KiwiNZ on 24-Apr-2014 07:28 (94 replies)
Pages... 5 6 7


Stonedine
Created by Lizard1977, last reply by surfisup1000 on 23-Apr-2014 21:27 (58 replies)
Pages... 2 3 4


Forms of government for New Zealand
Created by charsleysa, last reply by KiwiNZ on 23-Apr-2014 20:57 (169 replies)
Pages... 10 11 12


Telecom has started metering their TiVo customers' broadband usage (WITHOUT PRENOTIFICATION)
Created by Peteriv, last reply by kre8uv on 24-Apr-2014 08:03 (70 replies)
Pages... 3 4 5


Parallel imported product
Created by Wills1, last reply by joker97 on 23-Apr-2014 21:01 (53 replies)
Pages... 2 3 4


MH370 - Call for Search & Rescue Help
Created by DS248, last reply by joker97 on 23-Apr-2014 22:37 (737 replies)
Pages... 48 49 50


Labour MP Shane Jones to step down
Created by jeffnz, last reply by jeffnz on 23-Apr-2014 20:41 (32 replies)
Pages... 2 3


Upcoming Freeview Restack AUCKLAND
Created by Brunzy, last reply by richms on 23-Apr-2014 21:05 (13 replies)


Geekzone Live »
Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.

Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.