Suggest me a firewall

Joined
Sep 1, 2016
Messages
2,196
No I have done the MTCNA and what not. Just a matter of actually being able to play and apply it. I'd like to do the MTCRE course Miro is having next month.

Yeah google can help, but there's a lot of yappies out there that post ****. Also, the Mikrotik forum is useless at best.

Step 1: Go to Scoop Distribution if you don't already have a router to play with
Step 2: Install Winbox
Step 3: Start playing, its really easy if you know something about how Linux handles TCP sockets (well for me it was)
Step 4: Yes the Mikrotik forum is useless, but this one can help you, I can try and help too.
 

SauRoNZA

Honorary Master
Joined
Jul 6, 2010
Messages
47,848
As was already said and done all of this is possible with the Mikrotik you already have.

Just a case of configuring it properly.
 

DMNknight

Expert Member
Joined
Oct 17, 2003
Messages
3,385
You guys are forgetting that the Mikrotik mentioned above is single WAN port and made no suggestions as to an alternate device?

Essentially, the VLAN switch is the first item exposed to the internet before it hits the one NIC firewall. That's really tempting fate imho.

*edit* Just to be clear, which current mikrotik device are we talking about?
 
Last edited:

Dirty Harry101

Active Member
Joined
Sep 23, 2016
Messages
80
The only way he has one LAN port is if he is using a Groove which I highly doubt. He should have a device with atleast 5 ports minimum.
 

Genisys

Honorary Master
Joined
Jan 12, 2016
Messages
11,218
You guys are forgetting that the Mikrotik mentioned above is single WAN port and made no suggestions as to an alternate device?

Essentially, the VLAN switch is the first item exposed to the internet before it hits the one NIC firewall. That's really tempting fate imho.

*edit* Just to be clear, which current mikrotik device are we talking about?
It's actually a RB3011 I'm using.

As for the firewall, Vlans are isolated. It still works like independent NIC's over a single nic. Never have I been able to expose an of my Vlans over the Internet using this setup. The PPPoE connection was still on the firewall, only dialing over a vlan to the modem.
 

SauRoNZA

Honorary Master
Joined
Jul 6, 2010
Messages
47,848
You guys are forgetting that the Mikrotik mentioned above is single WAN port and made no suggestions as to an alternate device?

Essentially, the VLAN switch is the first item exposed to the internet before it hits the one NIC firewall. That's really tempting fate imho.

*edit* Just to be clear, which current mikrotik device are we talking about?

You can make any other LAN port a WAN port.

It's just not pre-configured like that.

****

And even then you could have one single WAN port with multiple PPPoE sessions on that port depending on the configuration/need here.
 

Dirty Harry101

Active Member
Joined
Sep 23, 2016
Messages
80
You can make any other LAN port a WAN port.

It's just not pre-configured like that.

Correcto mundo

And even then you could have one single WAN port with multiple PPPoE sessions on that port depending on the configuration/need here.

I need to understand this. Why and how? Never seen this or the need for it? Not saying there isn't one, just used to the 2ports one for each WAN. Good to learn something new.
 

DMNknight

Expert Member
Joined
Oct 17, 2003
Messages
3,385
You can make any other LAN port a WAN port.

It's just not pre-configured like that.

****

And even then you could have one single WAN port with multiple PPPoE sessions on that port depending on the configuration/need here.

Nice... and powerful
 

Genisys

Honorary Master
Joined
Jan 12, 2016
Messages
11,218
Also, the secondary connection is LTE, so Eth1 is for ADSL and Eth2 is for LTE.
 

SauRoNZA

Honorary Master
Joined
Jul 6, 2010
Messages
47,848
Correcto mundo



I need to understand this. Why and how? Never seen this or the need for it? Not saying there isn't one, just used to the 2ports one for each WAN. Good to learn something new.

Well say you have two accounts with different configurations.

One Unshaped and Capped and the other Shaped but Uncapped.

You maybe want all your VOIP and Gaming traffic to be unshaped so you send all that traffic over one instead of the other.

You don't always need a physical secondary WAN. For that matter you could even assign two IP addresses to one WAN port that talks to a 3G and ADSL modem on the same interface and fails over between them.

Never done that but it should work in a pinch.
 
Last edited:

Dirty Harry101

Active Member
Joined
Sep 23, 2016
Messages
80
But if you have two accounts, that means separate links yes? Separate ISP connections essentially, no matter who it is.
The way I see it, or am used to it is, one port, one connection. Well, that's how I have it anyway, with successful failover working.

I'll need to play with your config to see if it works ha ha. I do actually want to setup traffic shaping, but not 100% sure how.

Sorry OP for the hijack.
 

Genisys

Honorary Master
Joined
Jan 12, 2016
Messages
11,218
But if you have two accounts, that means separate links yes? Separate ISP connections essentially, no matter who it is.
The way I see it, or am used to it is, one port, one connection. Well, that's how I have it anyway, with successful failover working.

I'll need to play with your config to see if it works ha ha. I do actually want to setup traffic shaping, but not 100% sure how.

Sorry OP for the hijack.
Also look at CHR. It is free and runs in a virtual machine, so if you break something, you can just set up a new instance.
 

Dirty Harry101

Active Member
Joined
Sep 23, 2016
Messages
80
Nah stuff it, I'll break the on for work, then people can stop wasting time on takealot ha ha ha
 

HApyM3al

Expert Member
Joined
Oct 27, 2012
Messages
1,064
Well say you have two accounts with different configurations.

One Unshaped and Capped and the other Shaped but Uncapped.

You maybe want all your VOIP and Gaming traffic to be unshaped so you send all that traffic over one instead of the other.

You don't always need a physical secondary WAN. For that matter you could even assign two IP addresses to one WAN port that talks to a 3G and ADSL modem on the same interface and fails over between them.

Never done that but it should work in a pinch.

Thank you someone that knows what's up.

What you saying is 100% correct. Currently I am running 2x PPPoE over same Dsl line out one interface. You can run as much as you would like tbh. Any port on mikrotik can be a "wan" port.

Got few clients with Fibre and then Dsl as failover as well. Know people running 3 x Dsl lines out to 3 modems and works fine. That's again one Dsl line to one interface. But you can have multiple PPPoE over one line.

As for normal QoS stuff there is lots of guides and simple rules for this on Mikrotik forums. I'll post some later.
 

SauRoNZA

Honorary Master
Joined
Jul 6, 2010
Messages
47,848
Thank you someone that knows what's up.

What you saying is 100% correct. Currently I am running 2x PPPoE over same Dsl line out one interface. You can run as much as you would like tbh. Any port on mikrotik can be a "wan" port.

Got few clients with Fibre and then Dsl as failover as well. Know people running 3 x Dsl lines out to 3 modems and works fine. That's again one Dsl line to one interface. But you can have multiple PPPoE over one line.

As for normal QoS stuff there is lots of guides and simple rules for this on Mikrotik forums. I'll post some later.

Yeah a great many ways to skin a cat with a Mikrotik.

Only thing I haven't managed to do is a PPPoE connection for VDSL with a tagged VLAN ID.
 

The_Librarian

Another MyBB
Super Moderator
Joined
Nov 20, 2015
Messages
37,658
A mikrotik on its own is fine, but when you want to log sites visited, block or filter certain web sites, do traffic graphs and so on, a smoothwall/pfsense is preferred.

Internet - mikrotik with basic firewall - smoothwall - network
Or just any way you prefer.
 

Dirty Harry101

Active Member
Joined
Sep 23, 2016
Messages
80
A mikrotik on its own is fine, but when you want to log sites visited, block or filter certain web sites, do traffic graphs and so on, a smoothwall/pfsense is preferred.

Internet - mikrotik with basic firewall - smoothwall - network
Or just any way you prefer.

You can do the same with mikrotik, just depends how hands on you are. busy trying to sort that out now.
 
Top