Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


michaelmurfy

cat
12229 posts

Uber Geek

Moderator
ID Verified
Trusted
Lifetime subscriber

#206084 9-Dec-2016 04:02
Send private message

I started off with a configuration guide for the Mikrotik RB750Gr3 however as others rightfully pointed out the configuration I posted had hardcoded MAC addresses (fail) and thus I pulled it to write a better guide. I thought instead of focusing on one Mikrotik router I'd focus on a general configuration for most Mikrotik routers out there.

 

Configuration:
Whilst I do know it is tempting to create a configuration with all the things this guide is more focusing on getting an internet connection via a secured router. This guide will touch on the basics of:

 

- Basic Configuration (PPPoE + IPoE) connections for use with UFB or FibreX.
- Basic network configuration.
- Firewall Configuration as per recommended standards.

 

Before you start:

 

You'll need a PC / Laptop with Ethernet ideally Windows based (not required - but the screenshots below will be via Winbox). Speaking of which, you'll also need Winbox and Mikrotik have removed this off their latest routers in favor for a download off their website so grab it here and put it somewhere safe.

 

Unpackage your shiny (or beige) router and set it up - you're ready to start. The router I am using for this guide is the Mikrotik RB3011UiAS.

 

Now, getting started:

 

Quite literally I am resetting the router I've been using for the last week and setting things up from scratch. I anticipate my phone to go crazy from the notifications I'm about to get from external monitoring.

 

When you first boot up a Mikrotik router their default IP range sits on 192.168.88.0/24 with the routers IP address sitting on 192.168.88.1. On the 2 routers I've got here they come default with their DHCP server responding on Port 2. Confirm your computer has an IP on that range or if not, set your PC with an IP of 192.168.88.2/24.

 

Open up Winbox and connect to your router with the IP of 192.168.88.1, username admin with no password:

 

Click to see full size

 

Next, you'll likely have Winbox inform you about the parameters of the default configuration - we'll be keeping this as a starting point in our guide so just press OK:

 

Click to see full size

 

Now, with that out of the way we're going to first use the Quick Set guide to initially set up the router. This gives you a good starting point to setting things up:

 

Click to see full size

 

You can essentially follow through this guide to create a starting configuration. If you are not on a VLAN'd connection then once you hit apply you'll have internet with default firewall rules but as we know most of NZ is on a VLAN'd connection (via UFB or FibreX).

 

- For FibreX, IPoE (Orcon and maybe some others) your configuration will look like this:

 

Click to see full size

 

- For PPPoE (most providers) your configuration will look something like this:

 

Click to see full size

 

Please pay special attention to the Password field at the very bottom of the wizard as this is where you secure your router with a password. Also you're able to configure your IP address + range here too (in this example I'll be using 192.168.2.0/24).

 

If you're not on a VLAN'd connection then this is honestly all you're needing to do - congrats. You've now configured your router with the basics however if you are on a VLAN'd connection (like myself) then you'll need to go through some additional steps to get internet connectivity.

 

VLAN'd Connections (PPPoE):
Skip this for IPoE connections...

 

So at this point you've got the basic configuration on your router but you're still needing additional configuration in order to make it work. Fear not, it is pretty simple once you know where to look.

 

Click on Interfaces. You'll be presented with a screen like so:

 

Click to see full size

 

Up in the top left corner of the Interface List window you'll notice a blue + - you'll want to click on this and add a new VLAN.

 

Click to see full size

 

Name it something meaningful, set its MTU to 1500 and set the VLAN ID to 10. The interface is the port your ONT is connected to (in my case ether1).

 

Click to see full size

 

Next, double-click on pppoe-out1 in the interfaces list and assign it to your VLAN:

 

Click to see full size

 

Straight after hitting Apply I had an internet connection via PPPoE on VLAN 10 with the default firewall rules applied (passing the GRC ShieldsUP! test). This gave me a pretty solid speed on my BigPipe Gigabit UFB connection with around 35% CPU load:

 

Click to see full size

 

 

VLAN'd Connections (IPoE):

 

If you've got an IPoE connection (Vodafone FibreX, Orcon, BigPipe IPoE) there is additional configuration and also some additional security considerations so we'll be doing things a little different.

 

Click on Interfaces. You'll be presented with a screen like so:

 

Click to see full size

 

Up in the top left corner of the Interface List window you'll notice a blue + - you'll want to click on this and add a new VLAN.

 

Click to see full size

 

Name it something meaningful, set its MTU to 1500 and set the VLAN ID to 10. The interface is the port your ONT is connected to (in my case ether1).

 

Click to see full size

 

Then once you hit OK you'll see your VLAN in the list:

 

Click to see full size

 

Now, click on IP then Firewall (on the left menu bar) - there are 2 rules we'd like to edit here (highlighted):

 

Click to see full size

 

Change the In. Interface of both rules to your newly connected VLAN:

 

Click to see full size

 

Next, go to IP then DHCP Client (on the left menu) and double-click on the only rule there - change the interface to your VLAN interface:

 

Click to see full size

 

You should note it'll get an IP however you'll still not have any internet. Lets fix that, go back to the Firewall config and click "NAT" at the very top of the window - double-click on the only rule there and change the Out. Interface to your VLAN:

 

Click to see full size

 

And done! You'll now have internet and also pass the GRC ShieldsUP! test. A test on this connection type (same connection) makes my Mikrotik sit at around 30% CPU load:

 

Click to see full size

 

Conclusion:

 

On the Mikrotik RB3011 I've found no difference between PPPoE and IPoE however on the Mikrotik RB750Gr3 I've found that IPoE performs much better (it peaks out at around 650Mbit on PPPoE in my tests). If you've got a PPPoE connection I'd strongly recommend going towards one of the newer ARM based Mikrotiks. The RB750Gr3 is a great router but what makes it fail is the older MIPS processor it is running. I have no idea if this can be improved by firmware in the future.

 

The routers used were kindly provided by Go Wireless for my testing. The router used for the above tutorial was the Mikrotik RB3011UiAS-RM which is a larger router great for office use however I've tested the same guide on the Mikrotik RB750Gr3 which is a great router if you're just wanting to get started with Mikrotik.

 

There are many things you can do with the Mikrotik series of routers (even running an ISP) but if I was going to touch on every point I'll be here all night. The Mikrotik Wiki is a great place to get started along with the general Geekzone community who have several members with expert Mikrotik experience potentially willing to lend a hand for home baking or beer.





Michael Murphy | https://murfy.nz
Referral Links: Tessie | Tesla | Quic Broadband (use R122101E7CV7Q for free setup)

Are you happy with what you get from Geekzone? Please consider supporting us by subscribing.
Opinions are my own and not the views of my employer.


Create new topic
antoniosk
2331 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #1696527 30-Dec-2016 16:49
Send private message

Michael

 

 

 

awesome guide, but did you try this with a FibreX connection?

 

MF has given me this unit to try with my setup at home, and while I've replicated as you've outlined, failing to get an IP address at startup....





________

 

Antoniosk


 
 
 

Best TrendMicro deals for antivirus and malware protection(affiliate link).
chiefie
I iz your trusted friend
5877 posts

Uber Geek

Retired Mod
Trusted
Lifetime subscriber

  #1696533 30-Dec-2016 17:15
Send private message

antoniosk:

 

awesome guide, but did you try this with a FibreX connection?

 

 

I've used this/previous guide to set up FibreX.

 

 

 

Also @michaelmurfy. The part

 

"When you first boot up a Mikrotik router their default IP range sits on 192.168.88.0/24 with the routers IP address sitting on 192.168.1.1"

 

The router's IP address should be 192.168.88.1, you did mention this address in the next paragraph though.

 

 

 

Also, I have found a guide on configuring Apple Airport to use its Guest WiFi on VLAN 1003, and successfully set that up. Perhaps I can do a guide to expand on this at some stage if anyone interested.





Internet is my backyard...

 

«Geekzone blog: Tech 'n Chips Takeaway» «Personal blog: And then...»

 

Please read the Geekzone's FUG

 


shrub
715 posts

Ultimate Geek

ID Verified

  #1696536 30-Dec-2016 17:19
Send private message

I followed this guide and it worked for me on FibreX max. 




antoniosk
2331 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #1696537 30-Dec-2016 17:20
Send private message

Yep gettin in to configure is fine

It's getting an IP address from the technicolor 4400 that's the issue - would have thought it would just pick up once the router was plugged in.

The microtik is assigning without problem




________

 

Antoniosk


antoniosk
2331 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #1696538 30-Dec-2016 17:21
Send private message

shrub:

I followed this guide and it worked for me on FibreX max. 



Did you restart the technicolor?




________

 

Antoniosk


michaelmurfy

cat
12229 posts

Uber Geek

Moderator
ID Verified
Trusted
Lifetime subscriber

  #1696540 30-Dec-2016 17:22
Send private message

@chiefie cheers for pointing that out! Updated. Blame my insomnia (posted at 4am).





Michael Murphy | https://murfy.nz
Referral Links: Tessie | Tesla | Quic Broadband (use R122101E7CV7Q for free setup)

Are you happy with what you get from Geekzone? Please consider supporting us by subscribing.
Opinions are my own and not the views of my employer.


antoniosk
2331 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #1696555 30-Dec-2016 18:10
Send private message

Did anyone ever figure out the IP address for the technicolor? Would sure make debugging easier.




________

 

Antoniosk




antoniosk
2331 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #1696584 30-Dec-2016 19:55
Send private message

OK, so I got everything to work correctly.

 

Some thoughts on amending the instructions:

 

1 - add a section on 'Starting everything back up'

 

i) Turn off all gear - Mikrotik, your wifi points, switchs etc. Reason for this is everything needs to reacquire a fresh IP address, and not all equipment is consistent in its approach except when starting from cold.

 

ii) Plug WAN (from the Techinicolor 4400 or Chorus ONT) cable in. Turn on Mikrotik and wait for it to start

 

iii) Once beeps complete acknowledging startup, then turn on switch's, access points and so on

 

iv) then begin turning on your equipment. You may need to delete wifi profiles and add again (looking at you Apple Mac's)

 

 

 

Then run nperf, speedtest's etc

 

 

 

Appreciate this can be obvious, but as always detailing matters. 

 

:-)





________

 

Antoniosk


Skillie
192 posts

Master Geek


  #1696585 30-Dec-2016 20:00
Send private message

antoniosk: Did anyone ever figure out the IP address for the technicolor? Would sure make debugging easier.

 

192.168.100.1 

 

User Name = admin

 

Password = password


antoniosk
2331 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #1696628 30-Dec-2016 22:35
Send private message

Cheers - you can access the technicolor when using the Rb3011, but not the HG659.

 

On a different note, I think what would be useful is a short good to locking down the firewall and blocking the ports of the Microtik that a typical user never would need.

 

I ran out of time, but port 53 and 80 are open to responding to outside probes, ping was open as was ports 21-25 and so on. Tackled nearly everything except having 53 and 80 accessible.

 

Chiefie, what have you done?





________

 

Antoniosk


michaelmurfy

cat
12229 posts

Uber Geek

Moderator
ID Verified
Trusted
Lifetime subscriber

  #1696636 30-Dec-2016 23:09
Send private message

@antoniosk I did touch on firewalling. Ensure you've selected the correct interface and have assigned it to the 2 firewall rules above. The interface to add would be your VLAN 10 interface then run GRC Sheilds Up! to confirm.

There is another (older) guide here (http://www.geekzone.co.nz/forums.asp?forumid=66&topicid=161676) that touches on firewalling too.




Michael Murphy | https://murfy.nz
Referral Links: Tessie | Tesla | Quic Broadband (use R122101E7CV7Q for free setup)

Are you happy with what you get from Geekzone? Please consider supporting us by subscribing.
Opinions are my own and not the views of my employer.


antoniosk
2331 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #1696719 31-Dec-2016 09:40
Send private message

michaelmurfy: @antoniosk I did touch on firewalling. Ensure you've selected the correct interface and have assigned it to the 2 firewall rules above. The interface to add would be your VLAN 10 interface then run GRC Sheilds Up! to confirm.

There is another (older) guide here (http://www.geekzone.co.nz/forums.asp?forumid=66&topicid=161676) that touches on firewalling too.

 

Cheers Mike

 

I have added the 2 rules... the responses i got were from shieldsup website...





________

 

Antoniosk


Create new topic





News and reviews »

New Air Traffic Management Platform and Resilient Buildings a Milestone for Airways
Posted 6-Dec-2023 05:00


Logitech G Launches New Flagship Console Wireless Gaming Headset Astro A50 X
Posted 5-Dec-2023 21:00


NordVPN Helps Users Protect Themselves From Vulnerable Apps
Posted 5-Dec-2023 14:27


First-of-its-Kind Flight Trials Integrate Uncrewed Aircraft Into Controlled Airspace
Posted 5-Dec-2023 13:59


Prodigi Technology Services Announces Strategic Acquisition of Conex
Posted 4-Dec-2023 09:33


Samsung Announces Galaxy AI
Posted 28-Nov-2023 14:48


Epson Launches EH-LS650 Ultra Short Throw Smart Streaming Laser Projector
Posted 28-Nov-2023 14:38


Fitbit Charge 6 Review 
Posted 27-Nov-2023 16:21


Cisco Launches New Research Highlighting Gap in Preparedness for AI
Posted 23-Nov-2023 15:50


Seagate Takes Block Storage System to New Heights Reaching 2.5 PB
Posted 23-Nov-2023 15:45


Seagate Nytro 4350 NVMe SSD Delivers Consistent Application Performance and High QoS to Data Centers
Posted 23-Nov-2023 15:38


Amazon Fire TV Stick 4k Max (2nd Generation) Review
Posted 14-Nov-2023 16:17


Over half of New Zealand adults surveyed concerned about AI shopping scams
Posted 3-Nov-2023 10:42


Super Mario Bros. Wonder Launches on Nintendo Switch
Posted 24-Oct-2023 10:56


Google Releases Nest WiFi Pro in New Zealand
Posted 24-Oct-2023 10:18









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.







NordVPN