Community discussions

MikroTik App
 
nzjimmy
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 55
Joined: Tue Oct 03, 2017 11:47 pm

One /25 public subnet for 100 vlans without 1:1 nat?

Sun Dec 02, 2018 3:05 am

Hello,

Can one subnet provide addressing for many vlans without 1:1 natting?

I want one vlan per customer's CPE router, but instead of each vlan having its own /30, just one /25 is used across all vlans. The reason I want to do it this way is to avoid the use of PPPoE but still keep customer's traffic separate from one another as it traverses the L2 bridges and radio links, and to make good use of a public subnet.

I have tried and failed by putting vlans on a bridge and assigning the subnet to the bridge - the eth port behaves like an access port rather than a trunk port..

Is this possible? Am I doing it wrong or is there a better way of achieving this?

Thank you!
 
mducharme
Trainer
Trainer
Posts: 1777
Joined: Tue Jul 19, 2016 6:45 pm
Location: Vancouver, BC, Canada

Re: One /25 public subnet for 100 vlans without 1:1 nat?

Sun Dec 02, 2018 4:22 am

Don't do it as different VLANs - use layer 2 isolation to isolate the different customers, then enable "local-proxy-arp" and disable the sending of redirects to allow the customers to contact each other through the router again.
 
nzjimmy
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 55
Joined: Tue Oct 03, 2017 11:47 pm

Re: One /25 public subnet for 100 vlans without 1:1 nat?

Sun Dec 02, 2018 9:43 pm

What method of layers2 isolation are you referring to? More details would be good.

Thank you
 
User avatar
CZFan
Forum Guru
Forum Guru
Posts: 2098
Joined: Sun Oct 09, 2016 8:25 pm
Location: South Africa, Krugersdorp (Home town of Brad Binder)
Contact:

Re: One /25 public subnet for 100 vlans without 1:1 nat?

Mon Dec 03, 2018 12:31 am

Can one subnet provide addressing for many vlans without 1:1 natting?

I want one vlan per customer's CPE router, but instead of each vlan having its own /30, just one /25 is used across all vlans. The reason I want to do it this way is to avoid the use of PPPoE but still keep customer's traffic separate from one another as it traverses the L2 bridges and radio links, and to make good use of a public subnet.

I have tried and failed by putting vlans on a bridge and assigning the subnet to the bridge - the eth port behaves like an access port rather than a trunk port..

Is this possible? Am I doing it wrong or is there a better way of achieving this?

Don't know that Mikrotik supports this functionality, also not sure if Cisco does, but do know that BDCom Gpon OLT equipment does and is called "super net" in their terms where you can have on IP subnet over multiple vlans

If you are not going to use PPPoE, what will you for authetication, etc,

My assumption that what mducharme was referring to is called bridge split horizon, there you setup the clients with only an ip and no gateway ussually making use of proxy arp, so not sure how local proxy arp firs in here

Following with interest