MikroTik RB750GL as office Firewall

TheHxckid

Well-Known Member
Joined
Dec 30, 2008
Messages
198
Reaction score
1
Location
Skaapstad
Hi Everyone!

We have a small office at work and our current setup consists of:

Direct CAT5 cable from our ISP (They are in our building that is why) coming into our office and into a 8 port switch. Branching from this switch is 1) another switch and 2) a wireless access point. Everything at the moment works perfectly.

If I'm right, this leaves our internal network completely exposed to our ISP. We don't want this. We are in the process of connecting our office with CTWUG and after buying the components are now in possession of a lovely little MikroTik RouterBoard 750GL.

After some playing around I've managed to get access to the RB and changed the password and so on through Winbox.

So to protect our own internal network, we would like to let our ISP cable run straight into our RB "ether1" to act as a Firewall and then let our own internal network "ether2" go from there.

I'm very much a newb when it comes to network stuff and I need help setting this up. But I have no idea even where to start D:

Thank you in advance!
 
connect the office to CTWUG and we will configure the firewall for you ;)

Come join us on IRC and we will sort you out.
 
Routerboard is complicated.

You could get a PC with two network cards and run Smoothwall Express on it.
 
connect the office to CTWUG and we will configure the firewall for you ;)

Come join us on IRC and we will sort you out.

Awesome! We are not connected yet, boss is taking a while with the manual labour :P
But I will shout as soon as it's sorted! Thanks
 
Last edited:
RB750 is awesome little routers and great firewalls.

This is how mine is configured:
Ether1 : Connected to bridged adsl router (the RB750 dials the PPPOE)
Ether2 : Runs DHCP for my home network.
Ether3 : Is connected a 2.4Ghz ubiquiti bullet for sharing wug/internet with my neigbours also running a DHCP server on a seperate subnet.

Some simple quees to limit the neighbours bandwidth.
a PPTP server for sharing internet over the wug (shhht) (also with simple quees)

a few dst-nat rules for portforwarding from the internet to my server.

and a few filter/drop rules.
 
I have done a similar setup but to be honest does offer much for reporting side, if you have a spare box with 2 nics try pfsense with squid, sqiudguard and SARG. FW and transparent proxy with reporting nicely packaged all in one. If you got R2.5k buy HP Microserver and additional nic and off you go, going to do this for solution for 2 clients soon.

PS: took me one evening to get pfsense2.0, squid up and running.
 
Top
Sign up to the MyBroadband newsletter
X