Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


tardtasticx

3075 posts

Uber Geek


#303590 20-Feb-2023 22:36
Send private message

Hi all,

 

I've been using the supplied Fritzbox from 2degrees to sit between our ONT and the rest of our network since we joined 2degrees about 5 years ago. Been a great box but today it just turned off and won't come back on.
Can't get through to the Helpdesk so will just deal with that later this week but in the meantime I've dug out an old Mikrotik to use (from the old TrueNet thing if anyone remembers that).

 

It's the first time I've setup this as my primary router so would love to do a sanity check if someone wouldn't mind?
I've followed this guide as best I could - fab guide btw michaelmurfy - some steps have changed or are different from the version I'm on. 

 

The main reason that makes me doubt myself is I punched in the 'local' ip given over pppoe into my browser and got to my Mikrotik login page, I never tested this before swapping to the Mikrotik so I don't know if this is expected. I suspect it's intended since its probably treating my request as a local request. 

 

- Version: RouterOS v6.43.8 (stable)
- Network: 2degrees Fibre in Auckland 300/100 plan
- IP: Non-static, whatever 2degrees gives which at the moment is CGNAT 100.68.0.x

 

Interfaces:

 

  • VLAN: 2degrees_vlan1
  • Bridge: bridgeLocal
  • PPPoE Client: pppoe-out1

Interface List:

 

  • LAN: wlan1 and bridgeLocal
  • WAN pppoe-out1

ip firewall nat print

 

  • 0 chain=srcnat action=masquerade out-interface-list=WAN
  • 1 chain=srcnat action=masquerade out-interface-list=WAN  

ip firewall filter print

 

  • 0 chain=input action=accept protocol=icmp
  • 1 chain=input action=accept connection-state=established  
  • 2 chain=input action=accept connection-state=related
  • 3 chain=input action=drop in-interface-list=WAN log=no log-prefix=""  

 

 

Many thanks in advance and if there's something I've left out let me know.


Create new topic
nztim
3815 posts

Uber Geek

ID Verified
Trusted
TEAMnetwork
Subscriber

  #3039800 20-Feb-2023 23:40
Send private message

Its safe by the virtue of been behind CG-NAT

Disable MAC discovery Mac Winbox

I also tighten deny firewall rules to all interfaces not just the WAN but that is just me




Any views expressed on these forums are my own and don't necessarily reflect those of my employer. 




fe31nz
1229 posts

Uber Geek


  #3039849 21-Feb-2023 00:06
Send private message

You seem to be ignoring IPv6 which 2Degrees provides to everyone.  If that is OK for the moment, make sure the Mikrotik has IPv6 disabled.  Otherwise you will need to create an appropriate firewall for IPv6, as there is no NAT on IPv6 to prevent incoming connections.


tardtasticx

3075 posts

Uber Geek


  #3039867 21-Feb-2023 07:50
Send private message

Thanks for the replies!

 

nztim: Its safe by the virtue of been behind CG-NAT

Disable MAC discovery Mac Winbox

I also tighten deny firewall rules to all interfaces not just the WAN but that is just me

 

MAC discovery disabled - cheers.
Re: firewall on all interfaces does that cause you issues with connecting to other devices within your LAN?

 

 

 

fe31nz:

 

You seem to be ignoring IPv6 which 2Degrees provides to everyone.  If that is OK for the moment, make sure the Mikrotik has IPv6 disabled.  Otherwise you will need to create an appropriate firewall for IPv6, as there is no NAT on IPv6 to prevent incoming connections.

 

 

Yah I saw no options for IPV6 when setting it up, so I haven't touched that but thanks for the reminder to check. Confirmed the IPV6 package is currently disabled.
Not something I'm worried about not having.




cyril7
9058 posts

Uber Geek

ID Verified
Trusted
Subscriber

  #3039875 21-Feb-2023 08:30
Send private message

Hi, is there any reason you have removed the fastpath rules? you wont achieve full performance without them, I am guessing that is not the full firewall that you printed, just what you wanted to check was ok

 

Cyril


SaltyNZ
8227 posts

Uber Geek

Trusted
2degrees
Lifetime subscriber

  #3039935 21-Feb-2023 10:20
Send private message

cyril7:

 

Hi, is there any reason you have removed the fastpath rules? you wont achieve full performance without them, I am guessing that is not the full firewall that you printed, just what you wanted to check was ok

 

Cyril

 

 

 

 

Throttling doesn't work with fastpath enabled, which might be important depending on the connection. Personally I find it only saves a couple of percent CPU if anything, but then again I'm running an LTE connection rather than gigabit fibre.

 

I've been running Mikrotik for years, they're great. Adding to what the others have said, check the firewall rules block all incoming connections from the internet. Update your firmware - the latest is 7.6, from memory. Disable all the config channels except HTTPS GUI.





iPad Pro 11" + iPhone 15 Pro Max + 2degrees 4tw!

 

These comments are my own and do not represent the opinions of 2degrees.


RunningMan
8955 posts

Uber Geek


  #3040101 21-Feb-2023 15:47
Send private message

tardtasticx:The main reason that makes me doubt myself is I punched in the 'local' ip given over pppoe into my browser and got to my Mikrotik login page,

 

This is normal. The router can have multiple IP addresses (WAN, 1 for each LAN subnet, etc.) and unless your input chain firewall rules prohibit it, then you will be able hit any of those from any interface.


MattR
224 posts

Master Geek


  #3041227 24-Feb-2023 11:19
Send private message

RouterOS v6.43.8 (stable)

 

 

 

You need to update that. Current v6 stable is 6.49.7, yours is from 2018.


Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.