No video

How to protect and restrict VLAN traffic on MikroTik.

  Рет қаралды 18,377

The Network Berg

The Network Berg

Күн бұрын

Пікірлер: 45
@TheNetworkBerg
@TheNetworkBerg 5 ай бұрын
Just pinning this here for a direct link to the MikroTik firewall docs :D help.mikrotik.com/docs/display/ROS/Firewall+and+Quality+of+Service
@KamenosTheGreek
@KamenosTheGreek 5 ай бұрын
Thanks for producing all these videos, you make learning about mikrotik easier and more fun !
@TheNetworkBerg
@TheNetworkBerg 5 ай бұрын
Thank you, I really appreciate the nice comment and I really enjoy making MikroTik easier for everyone ^^
@killswitchscar1060
@killswitchscar1060 4 ай бұрын
Man, Gothic 1 and 2 were such awesome games. I still replay them every few years and besides a bit of jank they hold up really well still. Great video!
@TheNetworkBerg
@TheNetworkBerg 4 ай бұрын
Same here!!! I sometimes add some mods for some extra flavor if I get tired of vanilla gothic but it is amazing. Piranhabytes were at their prime with Gothic2 for me.
@killswitchscar1060
@killswitchscar1060 4 ай бұрын
@@TheNetworkBerg For sure, I remember being quite disappointed with Gothic 3 at the time, mostly due to the fact it would just perpetually crash after trying to start a new game haha! Helped me discover Oblivion though, which was no Gothic 2 but I still had a blast with it. I've always wanted to try out a bunch of the awesome looking Gothic mods but, alas I speak about 3 words of German so it rules out a lot of them.
@ColinM9991
@ColinM9991 5 ай бұрын
How very timely that I saw your month old VLAN video only 3 days after this one. Great content, definitely earned a subscriber. I weighed up the choice between Mikrotik and Ubiquiti a year ago and settled with Mikrotik for routing, with Ubiquiti's WiFi APs, as I do really like the look of Mikrotik's product suite, the level of control that you have as well as the longevity of their products what with them all running RouterOS/SwitchOS. With that said, it comes with a steep learning curve and I've forgotten the majority of my networking education from a decade ago since I chose software engineering as my occupation. It's always great to have content creators like yourself that give a succinct view over the ways of working with this hardware.
@TheNetworkBerg
@TheNetworkBerg 5 ай бұрын
I think that's a solid choice and would highly recommend using MT for routing and UI for Wifi access :D
@ColinM9991
@ColinM9991 5 ай бұрын
@@TheNetworkBerg As a quick heads up, it seems the Discord link in your video descriptions has expired.
@TheNetworkBerg
@TheNetworkBerg 5 ай бұрын
@@ColinM9991 Oh sorry, I was sure I removed the discord server from the posts. The server was discontinued last month.
@rchrstphr-smp1043
@rchrstphr-smp1043 5 ай бұрын
Thanks, Great video.I was expecting blocking using bridge decisions in "vlan tab" admit only ingress vlan - i dont know if this way work too - ... This way showed is more easy to understand.
@ukaszl5733
@ukaszl5733 3 ай бұрын
Great tutorial, you helped me set up a secure home network :)
@maychocansing
@maychocansing 5 ай бұрын
I learn a lot from your tutorials keep on uploading :) Thank you
@pmsyedsyed7588
@pmsyedsyed7588 Ай бұрын
Thankyou for i get knowledge about types of vpn.❤
@P0w3rgamer
@P0w3rgamer 4 ай бұрын
Couldn't make it work, only with RAW rules could work..i even enabled firewall on bridge settings but still...but great job man, i learned a lot from you Thank you!!
@djKenpLan09
@djKenpLan09 5 ай бұрын
You rock! thanks a lot for sharing your knowledge! Regards
@h3techsme
@h3techsme 5 ай бұрын
Thanks so much for this. I've seen some questions here that echo my first thought - how does this relate to bridge filtering? I'm just imagining that (VLAN filtering) is a *first* option and the method you show here is for some higher-order concern or secondary option if VLAN filtering is not implemented for some reason. This video is a great "how" but it would be nice to see some companion that details the "why" questions - choosing one method or the other (and of course how both may be used together) ;)
@drumaddict89
@drumaddict89 5 ай бұрын
maybe useful examples for MACVLAN next, maybe? 🤔🤔
@TheNetworkBerg
@TheNetworkBerg 5 ай бұрын
Great idea :D
@acme.consulting
@acme.consulting 5 ай бұрын
How about setting firewall rules using In Interface / Out Interface and specifying VLAN interfaces for that?
@TheNetworkBerg
@TheNetworkBerg 5 ай бұрын
Logically speaking it is the same concept, just different conditions. Instead of using a source/destination address or address list you can specify your VLAN interfaces as an in or out interface and apply actions based off of your requirements. ie In-interface=mgmt out-interface=servers action=accept. This is nice as the MikroTik will use any addresses bound to a VLAN interface to make forwarding decisions. You can even do the same thing as a firewall address list by using an interface list.
@xerr0n
@xerr0n 5 ай бұрын
you can also group the interfaces together via the "interface lists" in which the appropriate interfaces are added to. Another way would be to use bridges as bridges give us interfaces that dont drop when we disconnect a cable or do something with that specific port mikrotik is versatile like this
@frankfix247
@frankfix247 5 ай бұрын
Nice video, but could you please make one explaining using HW VLAN switching using ACL rules?
@stathemjonathan7855
@stathemjonathan7855 5 ай бұрын
Thank you
@HoodedMan13
@HoodedMan13 5 ай бұрын
Thanks for the video! It was infomative at least for me. I am wondering though if it would be possible to do the same on a Bridge level with Bridge Filters!!!
@drumaddict89
@drumaddict89 5 ай бұрын
oh another thought ... split firewall rulesets into chains according to your vlan setup. so a chain for each VLAN. what do you think about that approach? i have remodeled it that way at home and it even gave me a little performance bump up
@user-zt1fd9ld7d
@user-zt1fd9ld7d 2 ай бұрын
Hello ! For the same purposes ( to deny access between vlans) I use routing rules. Very interesting, which method is more difficult for the processor?
@okoeroo
@okoeroo 5 ай бұрын
Can you repeat this as a followup to see the effects under high loads?
@bushcraft.azerbaijan
@bushcraft.azerbaijan 2 ай бұрын
thank you
@TubeSkaterRudy
@TubeSkaterRudy 5 ай бұрын
Newbie Question: I would think that with your new rule to block traffic between local-networks you would also block traffic within the same local-network or sub-net, so you couldn't reach a printer or file-server within the same subnet? Or is there a reason or rule why this wouldn't happen?
@TheNetworkBerg
@TheNetworkBerg 5 ай бұрын
Hi Rudy, that is a great question. Typically this should not break access as devices in the same VLAN would connect directly over the same broadcast domain. ie the computer and printer would communicate directly over L2 and traffic would be passed directly between these devices on a switching layer, so you could think of this as the devices will just use the switch to talk. The router would not be involved in passing that traffic or forwarding it. It is worth noting that if you were using the router as a bridge between different devices like other switches or routers then in that event you could potentially stop the traffic and it would be better to define individual networks.
@boniexara
@boniexara 4 ай бұрын
make a paid connection to mikrotik, it would be interesting
@TheNetworkBerg
@TheNetworkBerg 4 ай бұрын
A paid connection?
@boniexara
@boniexara 4 ай бұрын
@@TheNetworkBerg that's right, like 1$ to join
@Learnwithjoseph
@Learnwithjoseph 4 ай бұрын
Quick question ❓ on how to not show ISP company that you are using when doing speed test from any speed test website
@steelasd8097
@steelasd8097 4 ай бұрын
Hi! I have a question. I made a bridge interface (Eth2, Eth3) wich contains 'x' number of VLANS and add a VRRP to that Bridge also. The bridge Interface have the same IP that the VRRP. My question is if it is the right way to do it, because it works but i never saw anyone do it in that way
@kellydavid4021
@kellydavid4021 2 ай бұрын
How do i add isp billing to mikrotik for hotspot
@MustaMT
@MustaMT 4 ай бұрын
Can you please explain fast track concept?
@nova99866
@nova99866 4 ай бұрын
Is it possible to take e-waste from recycling places for free? (South Africa)
@vanomel528
@vanomel528 5 ай бұрын
Do you have a second channel or social media? Wanted to know how your relocation is going.
@TheNetworkBerg
@TheNetworkBerg 5 ай бұрын
You can find me on Twitter, though I really don't do much on social media. Also don't have a second channel, have considered creating one to explore other things I enjoy and putting it out onto YT. But you are always welcome to message me on here. Relocation is going great, have secured full time employment, although I am under a probation at the moment, but life is pretty much the same it was before moving to another country. Though there are definitely other ups and downs when it comes to making a move like this.
@vanomel528
@vanomel528 5 ай бұрын
Happy for ya. Cheers
@Gomo_DD
@Gomo_DD 4 ай бұрын
Is the discord server still available? if so, can you please provide the invite URL
@TheNetworkBerg
@TheNetworkBerg 4 ай бұрын
Unfortunately not, the discord server was decommissioned about a month or so ago. I did make a community post about it and post on the server regarding it. I highly suggest checking out the MikroTik or Surviving Networking & IT discord servers. I have joined those myself :)
@Quick-IT
@Quick-IT 3 ай бұрын
Could you mention your email i want to send a network architecture i designed using mikrotik for your review and input.
Mastering VLAN Configuration on MikroTik, Step-by-Step Guide
34:56
The Network Berg
Рет қаралды 77 М.
Basic introduction to BGP - Ft. MikroTik ROSv7
50:25
The Network Berg
Рет қаралды 36 М.
Logo Matching Challenge with Alfredo Larin Family! 👍
00:36
BigSchool
Рет қаралды 21 МЛН
SPILLED CHOCKY MILK PRANK ON BROTHER 😂 #shorts
00:12
Savage Vlogs
Рет қаралды 46 МЛН
Why Is He Unhappy…?
00:26
Alan Chikin Chow
Рет қаралды 109 МЛН
VLAN в Mikrotik
21:20
Mikrotik Training
Рет қаралды 55 М.
Mikrotik Firewall and Basic Configurations
14:42
NetworkLabs
Рет қаралды 3,6 М.
Full MikroTik MTCRE - Introduction to VLANs on MikroTik. (Episode 1)
29:23
THE UNTOLD STORY: How the PIX Firewall and NAT Saved the Internet
21:50
The Serial Port
Рет қаралды 367 М.
Layer 2 vs Layer 3 Switches
6:02
PowerCert Animated Videos
Рет қаралды 705 М.
The Mikrotik SwOS and VLAN Configuration
14:46
Lawrence Systems
Рет қаралды 99 М.
How Mikrotik Can Transform Your Network Engineering Skills
14:26
The Network Berg
Рет қаралды 11 М.
MLAG With Mikrotik - High Availability  (Full Lab)
35:53
Wilmer Almazan / The Network Trip
Рет қаралды 10 М.