I have reset mikrotik and basically done few steps:
1. Add DHCP client on ether1
- after this step I can from MT terminal ping 8.8.8.8 so Internet at this point is accessible
2. Created bridge and added LAN and WLAN ports
3. Created DHCP server and pool
4. Created NAT masq. in fw
Client gets IP but traffic is not forwarded to ether1 as I expect. From client side I can't ping 8.8.8.8 which is working from MT terminal:
Code: Select all
ping 8.8.8.8
PING 8.8.8.8 (8.8.8.8) 56(84) bytes of data.
^C
--- 8.8.8.8 ping statistics ---
559 packets transmitted, 0 received, 100% packet loss, time 559724ms
Code: Select all
[admin@MikroTik] > /export
# oct/11/2023 23:30:31 by RouterOS 6.49.10
# software id = YK1C-QSJ9
#
# model = 751U-2HnD
/interface bridge
add name=bridge1
/interface wireless
set [ find default-name=wlan1 ] disabled=no mode=ap-bridge ssid=coon wireless-protocol=802.11
/interface list
add name=WAN
add name=LAN
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa-psk,wpa2-psk mode=dynamic-keys supplicant-identity=MikroTik wpa-pre-shared-key=<redacted> wpa2-pre-shared-key=<redacted>
/ip pool
add name=pool1 ranges=192.168.9.160-192.168.9.190
/ip dhcp-server
add address-pool=pool1 disabled=no interface=bridge1 name=server1
/interface bridge port
add bridge=bridge1 interface=wlan1
add bridge=bridge1 interface=ether2
add bridge=bridge1 interface=ether3
add bridge=bridge1 interface=ether4
add bridge=bridge1 interface=ether5
/ip neighbor discovery-settings
set discover-interface-list=LAN
/interface list member
add interface=ether1 list=WAN
add list=LAN
add interface=bridge1 list=LAN
/ip address
add address=192.168.9.1/24 interface=bridge1 network=192.168.9.0
/ip dhcp-client
add disabled=no interface=ether1
/ip dns
set servers=1.1.1.1
/ip firewall filter
add action=accept chain=input protocol=icmp
add action=accept chain=input connection-state=established
add action=accept chain=input connection-state=related
add action=drop chain=input in-interface-list=!LAN
/ip firewall nat
add action=masquerade chain=srcnat out-interface-list=WAN
/system clock
set time-zone-name=Europe/Zagreb
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN