Kuznetsov Olt
Kuznetsov Olt
routing in
MikroTik ROS v7
MUoM
Mikrotik User Online Meeting
1
Об авторе
• MTCRE
• Telegram @smithy1208
• v.kuznetsov48@ya.ru
MUoM
Mikrotik User online Meeting
2
01
Routing tables
MUoM
Mikrotik User Online Meeting
3
Схема
Dualwan
MUoM
Mikrotik User online Meeting
4
Стартовые настройки
# Базовые настройки:
/ip address
add address=198.51.100.6/29 interface=ether1
add address=203.0.113.6/29 interface=ether2
add address=192.168.88.254/24 interface=br-lan
MUoM
Mikrotik User online Meeting
5
# Создать дополнительные роутинг таблицы
Routing [admin@MikroTik] > /routing/table/export terse
tables
# dec/11/2021 00:50:35 by RouterOS 7.1
# software id =
#
/routing table add disabled=no fib name=rtab-1
/routing table add disabled=no fib name=rtab-2
MUoM
Mikrotik User online Meeting
6
# Добавить дефолты в новые таблицы
defaults # software id =
#
/ip route add distance=251 gateway=198.51.100.1
/ip route add distance=252 gateway=203.0.113.1
/ip route add gateway=198.51.100.1 routing-table=rtab-1
/ip route add gateway=203.0.113.1 routing-table=rtab-2
MUoM
Mikrotik User online Meeting
7
Маркировки (mangle)
# Добавить маркировки
MUoM
Mikrotik User online Meeting
8
# Отказоустойчивость через рекурсивные маршруты
Recursive
# software id =
#
/ip route
MUoM
Mikrotik User online Meeting
9
Route recursive
MUoM
Mikrotik User online Meeting
10
Route recursive. Fail ISP1
MUoM
Mikrotik User online Meeting
11
Check
## log check gateway ISP1
10:29:41 forward: proto ICMP (type 8, code 0), 198.51.100.6->4.2.2.1,
MUoM
Mikrotik User online Meeting
12
02
VRF изолированный!
MUoM
Mikrotik User Online Meeting
13
Схема VRF
MUoM
Mikrotik User online Meeting
14
PE
[admin@PE] > export
# dec/13/2021 11:18:15 by RouterOS 7.1
# software id =
#
Provider Edge router — /ip vrf
граничный add interfaces=ether3 name=vrf2
маршрутизатор add interfaces=ether2 name=vrf1
/ip address
провайдера add address=192.168.2.1/30 interface=ether2 network=192.168.2.0
add address=192.168.2.6/30 interface=ether3 network=192.168.2.4
/ip dhcp-client
add interface=ether1
/system identity
set name=PE
MUoM
Mikrotik User online Meeting
15
[admin@CE6] > export
# dec/13/2021 11:15:17 by RouterOS 6.46.8
# software id =
#
#
#
/ip address
add address=192.168.2.2/30 interface=ether1 network=192.168.2.0
/ip route
CE6
add distance=1 gateway=192.168.2.1
/system identity
set name=CE6
Customer Edge router — [admin@CE6] >
граничный маршрутизатор [admin@CE6] > ping count=2 192.168.2.1
клиента, который SEQ HOST SIZE TTL TIME STATUS
0 192.168.2.1 56 64 5ms
подключен в сеть 1 192.168.2.1 56 64 3ms
провайдера. sent=2 received=2 packet-loss=0% min-rtt=3ms avg-rtt=4ms max-rtt=5ms
MUoM 0 192.168.2.6
1 192.168.2.6
84 64 2ms
84 64 5ms
net unreachable
net unreachable
Mikrotik User online Meeting sent=2 received=0 packet-loss=100% 17
03
VRF "route leaking"
MUoM
Mikrotik User Online Meeting
18
[admin@PE] > /export
# dec/13/2021 11:29:48 by RouterOS 7.1
# software id =
PE
#
/ip vrf
add interfaces=ether2 name=vrf1
"route leaking" add interfaces=ether3 name=vrf2
/ip address
add address=192.168.2.1/30 interface=ether2 network=192.168.2.0
add address=192.168.2.6/30 interface=ether3 network=192.168.2.4
/ip dhcp-client
add interface=ether1
/ip route
add distance=1 dst-address=192.168.2.4/30 gateway=ether3@vrf2 routing-table=vrf1
add distance=1 dst-address=192.168.2.0/30 gateway=ether2@vrf1 routing-table=vrf2
/system identity
set name=PE
MUoM
Mikrotik User online Meeting
19
[admin@CE6] > /export
# dec/13/2021 11:37:58 by RouterOS 6.46.8
# software id =
#
#
#
/ip address
add address=192.168.2.2/30 interface=ether1 network=192.168.2.0
CE6
/ip route
add distance=1 gateway=192.168.2.1
/system identity
set name=CE6
"route leaking"
[admin@CE6] > ping count=2 192.168.2.1
SEQ HOST SIZE TTL TIME STATUS
0 192.168.2.1 56 64 4ms
1 192.168.2.1 56 64 2ms
sent=2 received=2 packet-loss=0% min-rtt=2ms avg-rtt=3ms max-rtt=4ms
MUoM
Mikrotik User Online Meeting
21
[admin@PE] /ip/service> set ssh vrf=vrf1
MUoM
Mikrotik User online Meeting
22
[admin@CE6] > sys ssh 192.168.2.1
password:
[admin@PE] >
Welcome back!
MUoM
Mikrotik User online Meeting
23
05
VRF vpn
MUoM
Mikrotik User Online Meeting
24
VRF ####################
MUoM
Mikrotik User online Meeting
25
06
VRF internet
MUoM
Mikrotik User Online Meeting
26
Схема
Dualwan
MUoM
Mikrotik User online Meeting
27
VRF internet
/ip vrf
add interfaces=ether1 name=vrf1
add interfaces=ether2 name=vrf2
/ip address
add address=10.51.100.6/29 interface=ether1
add address=10.51.100.6/29 interface=ether2
/ip route
add check-gateway=ping distance=251 dst-address=0.0.0.0/0 gateway=10.51.100.1@vrf1 routing-table=main
add check-gateway=ping distance=252 dst-address=0.0.0.0/0 gateway=10.51.100.1@vrf2 routing-table=main
add dst-address=192.168.88.0/24 gateway=br-lan routing-table=vrf1
add dst-address=192.168.88.0/24 gateway=br-lan routing-table=vrf2
Без маркировок
MUoM
Mikrotik User online Meeting
28
VRF internet
MUoM
Mikrotik User online Meeting
29
Ссылки
- https://habr.com/ru/post/463813/
MUoM
Mikrotik User online Meeting
30
Спасибо за внимание!
Буду рад ответить на все ваши
вопросы сейчас или свяжитесь
со мной в будущем:
Telegram @smithy1208
v.kuznetsov48@ya.ru
← Конфиги
MUoM
Mikrotik User Online Meeting
31