Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Enterprise Networking Mikrotik Routers (RouterBoard & RouterOS), User and owner discussion group

views
     
hao0302
post May 16 2020, 02:24 AM

New Member
*
Junior Member
49 posts

Joined: May 2011


QUOTE(th3game @ Dec 18 2019, 04:42 PM)
hi guys..im still exploring my new hap ac2 and got question..

I have the following setup:

Internet ---->HAP AC2 (local ip 192.168.1.1) --->Dlink dgs 1100 switch (static local IP 192.168.1.2)---> asus router as APs static local ip 192.168.1.3 & 192.168.1.4 (not Vlan aware devices)

hap ac2 trunking port 2 (vlan30,vlan40) to the switch port 1 n configured as tagged vlans
asus AP 1 connect to port 3 on switch as untagged vlan30
asue AP 2 connect to port 4 on switch as untagged vlan40

vlan30 - tagged port 1, untagged port 3
vlan40 - tagged port 1, untagged port 4
management vlan - vlan1

router hap ac2
DHCP address space : 192.168.1.0/24
gateway for DHCP network : 192.168.1.1
addresses to give out : 192.168.1.10 - 192.168.1.254

interface : vlan30
DHCP address space : 10.10.30.0/24
gateway for DHCP network : 10.10.30.1
addresses to give out : 10.10.30.2 - 10.10.30.254

interface : vlan40
DHCP address space : 10.10.40.0/24
gateway for DHCP network : 10.10.40.1
addresses to give out : 10.10.40.2 - 10.10.40.254

default config enable for hap ac2

i can access the internet wifi from asus AP 1 and got ip 10.10.30.254
i can access the internet wifi from asus AP 2 and got ip 10.10.40.254

questions..

I am able to connect to the hap ac2 local IP (192.168.1.1) via Winbox when connected to mikrotik wifi

I also want to be able to connect to the switch (192.168.1.2) & Asus APs (192.168.1.3 & 192.168.1.4) via local IP wirelessly.

Aleady tried to use mikrotik wifi to connect to those local IP but cannot sad.gif

Any solutions/suggestions will be highly appreciated..sorry if my question is bit noob
*
You need to enable forward between vlan30,40 with the local ip under ip>firewall.
Btw if you are not planning to isolate these three network you may use only one ip range instead of difference vlans.

hao0302
post Jul 1 2021, 05:58 PM

New Member
*
Junior Member
49 posts

Joined: May 2011


hi can anyone help me with this.

attachment is the simple diagram of two site ipsec vpn

no issue to access remote site ip address, but cant find a way to route out to internet via remote wan ip

example on hex

ipsec policy is set to
src: 10.1.1.0/22
dst: 0.0.0.0/0

NAT
src any to dst any (wan interface)

policy is allow src all to internet interface

i was trying to set 10.1.3.0/24 route to one of the interface on remote site but it failed.

anyone can enlighten me if i need to config mangle routing mark for this?

any question is while i tried to set ipsec policy - src and dst to 0.0.0.0/0, all the connection will be down. Does it mean all the connection will default route to remote site?

I am able to set ipsec policy as any on enterprise firewall (forti, pan-os), while it will only hit the ipsec policy while the route is pointing remote site.


Attached thumbnail(s)
Attached Image

 

Change to:
| Lo-Fi Version
0.0737sec    0.51    7 queries    GZIP Disabled
Time is now: 21st December 2025 - 05:11 PM