MIKROTIK possibly.
anyone have practical experience with a decent router that routes 2 VLANs on the local gigabit LAN NOT on the WAN side.
I want to be able to route two separate subnets of a c class on a local lan by eth port hopefully so I can give one internet access as well as printer and file access whilst restricting the other subnet to just the file and print services.
not many under $1500 that will do it from what I am seeing except for a couple of draytec units.
anyone know of any others that are capable?
TIA
2007 Discovery 3 SE7 TDV6 2.7
2012 SZ Territory TX 2.7 TDCi
"Make the lie big, make it simple, keep saying it, and eventually they will believe it." -- a warning from Adolf Hitler
"If you don't have a sense of humour, you probably don't have any sense at all!" -- a wise observation by someone else
'If everyone colludes in believing that war is the norm, nobody will recognize the imperative of peace." -- Anne Deveson
“What you leave behind is not what is engraved in stone monuments, but what is woven into the lives of others.” - Pericles
"We can ignore reality, but we cannot ignore the consequences of ignoring reality.” – Ayn Rand
"The happiness of your life depends upon the quality of your thoughts." Marcus Aurelius
MIKROTIK possibly.
Current Cars:
2013 E3 Maloo, 350kw
2008 RRS, TDV8
1995 VS Clubsport
Previous Cars:
2008 ML63, V8
2002 VY SS Ute, 300kw
2002 Disco 2, LS1 conversion
Depending on the application Dave, well inside your budget you could pick up a second hand Cisco. ( either route or layer 3 switch)
If you want something with supplier warranty though - ignore that.![]()
Mark
Of all the things I've lost, I miss my mind the most![]()
2015 TDV6 D4.... the latest project... Llams, Traxide, Icom 455, Tuffant Kimberleys and Mofos.... so far.
2012 SDV6 SE D4 with some stuff... gone...
2003 D2a TD5...gone...
2000 D2 V8...gone...
https://bymark.photography
most likely candidate looks like a draytec 2952 at this stage
anybody used one?
2007 Discovery 3 SE7 TDV6 2.7
2012 SZ Territory TX 2.7 TDCi
"Make the lie big, make it simple, keep saying it, and eventually they will believe it." -- a warning from Adolf Hitler
"If you don't have a sense of humour, you probably don't have any sense at all!" -- a wise observation by someone else
'If everyone colludes in believing that war is the norm, nobody will recognize the imperative of peace." -- Anne Deveson
“What you leave behind is not what is engraved in stone monuments, but what is woven into the lives of others.” - Pericles
"We can ignore reality, but we cannot ignore the consequences of ignoring reality.” – Ayn Rand
"The happiness of your life depends upon the quality of your thoughts." Marcus Aurelius
Not that model, but we used a Draytec in a small office about 5-6 years ago that behaved well enough. I was just providing internet access for 4-5 staff.
Mark
Of all the things I've lost, I miss my mind the most![]()
2015 TDV6 D4.... the latest project... Llams, Traxide, Icom 455, Tuffant Kimberleys and Mofos.... so far.
2012 SDV6 SE D4 with some stuff... gone...
2003 D2a TD5...gone...
2000 D2 V8...gone...
https://bymark.photography
We're running a Mikrotik CCR1016 at one of our sites for work.
Running voice and data vlans on lan side, has policy based routing so we're doing things like source ip tagging so that traffic from certain LAN IPs goes via different gateway or interface etc.
They take a bit of getting used to as they have slightly different approach to configuration but haven't found anything we can't do with it.
Amazing bit of gear for the price.
Steve
1985 County - Isuzu 4bd1 with HX30W turbo, LT95, 255/85-16 KM2's
1988 120 with rust and potential
1999 300tdi 130 single cab - "stock as bro"
2003 D2a Td5 - the boss's daily drive
I use mikrotik too. Excellent kit. Set up multiple VLAN no issue. As noted getting started or used to them takes a bit of work but well worth it. Once set up forget about it they just keep on working.
Neil
(Really shouldn't be a...) Grumpy old fart!
MY2013 2.2l TDCi Dual Cab Ute
Nulla tenaci invia est via
Maybe also check out edgerouter by ubuiqiti.
There's a few models and pretty affordable.
We considered those before buying the Mikrotik - but I don't recall the reason we decided against them.
Definitely affordable and by all accounts a good bit of gear, but I've a feeling they may not have been up to the gigabit routing throughput we were looking for.
Steve
1985 County - Isuzu 4bd1 with HX30W turbo, LT95, 255/85-16 KM2's
1988 120 with rust and potential
1999 300tdi 130 single cab - "stock as bro"
2003 D2a Td5 - the boss's daily drive
Just had another read of your post, and a poke around on the router to confirm it can definitely do it (answer is yes). Comments below apply to the Mikrotik but I can't comment on the Draytek as I've never used them, and only have sketchy Cisco vlan and ACL experience.
When you say you're wanting to route "by eth port" it almost sounds like you can physically split the subnets and plug one into eg eth0 and the other into eth1. If that's the case you don't need to mess around with vlan's - just configure the subnets on different ports - it will automatically route between interfaces as it sees both active. If I've misinterpreted and you're talking proper 802.1Q tagging the Mikrotik will still handle it happily.
A few firewall rules would sort out the access control you want to put in place. Default block rule for all traffic from LAN outbound on the internet port/interface, then allow what you DO want to go out. You've got the complete range of network/device attributes to base your rules on but simple ones based on source interface/port, subnet or vlan would likely sort you out.
Very easy bandwidth throttling/reservation too if you need to keep little Johnny developer's software download from impacting the owner streaming his favorite sport.
I expect that you could get away with a much lower spec Mikrotik device than the CCR1016, but I don't have personal experience with any.
To give you and idea of the CCR1016 capability - in our case it handles multiple lans/vlans with upwards of 1000 devices total (data and voice), a bunch of on-premises servers, and multiple internet WAN interfaces.
We have all but one of the 12 ports used, either bridged and connected to one of the lan, or as various seperate interfaces (LAN/WAN/DMZ etc).
It was originally bought it as we needed something at a reasonable price that had better than Gigabit routing throughput for a high speed connection between sites and the $3K HP layer3 switches we had bought were ghastly to work with (and not really appropriate in hindsight).
Its ended up being a case of "damn - these are seriously awesome, does everything we throw at it and I don't need a PhD in astroCiscoPIX to drive it!!!"
Only downside from our perspective is they aren't really mainstream so don't have Cisco Smartnet style extended support and availability is limited. Definitely not a suitable fit for some organisations.
Steve
1985 County - Isuzu 4bd1 with HX30W turbo, LT95, 255/85-16 KM2's
1988 120 with rust and potential
1999 300tdi 130 single cab - "stock as bro"
2003 D2a Td5 - the boss's daily drive
| Search AULRO.com ONLY! |
Search All the Web! |
|---|
|
|
|
Bookmarks