Community discussions

MikroTik App
 
Seccour
newbie
Topic Author
Posts: 42
Joined: Sat Apr 02, 2005 11:10 pm

NAT and Bridged Interfaces

Wed Nov 08, 2006 12:40 am

I have a unique scenario in which using NAT (to free up IP's) cases browsing and general internet to stop working. Let me explain...

I have a Mikrotik RB532 with 5 total interfaces, 3 Ethernet and two wireless. The internet comes into this MT via ether1. All of the interfaces are bridged. The other two ethernet interfaces have seperate AP's on them, and the two wireless function as ap's.

Today, as part of reengineering the network to have each interface not bridged and routed instead, I removed wlan1, applied its own private IP address and created your standard SRC-NAT rule. When I created the src-nat rule, the users on the wlan1 work fine, however everyone else connected to the bridge suddenly is unable to query the DNS server, but is able to still ping outside gateway and other internet hosts. Immediately disabling the src-nat rule makes everyone else work, but users on wlan1 becomes disabled.

We wanted to use NAT as we have ran out of IP's to effectively just rearrange my network. My clients get a static public IP address, and we currently have three full class C's subnets on my network. Many of these clients are static. The idea was that we would turn over a segment at a time over to nat, freeing up the IP's and then we could gradually and slowly redistribute the public IP's giving us a purely routed network as having the bridged network with so many clients is starting to take its toll.

The nat rule as configured...
 2 X chain=srcnat out-interface=ether1 action=masquerade 
It is DISABLED as its currently breaking my network to have it enabled so I am aware of this ;)

Pretty standard. Is there a way to get that single interface doing the nat without causing the other interfaces to break so oddly ? I've seen a few posts about connection lists, however a connection list can only address a single subnet at a time, and I have several.

The manual doesn't seam to address situations like this.

Ideas ? (Yes, I've RTFM several times but its possible that I'm not looking in the right place for this particular application)
 
User avatar
macgaiver
Forum Guru
Forum Guru
Posts: 1768
Joined: Wed May 18, 2005 5:57 pm
Location: Sol III, Sol system, Sector 001, Alpha Quadrant

Wed Nov 08, 2006 11:10 am

I think you need to consult support@mikrotik.com (don't forget the supout.rif file :D)

Or you could paste all /ip address /ip route / ip firewall nat configuration in here

Who is online

Users browsing this forum: Bing [Bot], gabin8207, rhodri and 47 guests