?
Solved

mikrotik problem

Posted on 2014-12-11
3
Medium Priority
?
689 Views
Last Modified: 2014-12-24
we are trying to create an eoip between 2 datacenters with given config below

problem is two mikrotik can ping each other with 1.1.1.1 and 1.1.1.3 but from the both network any machine can't get ip address from other sometimes, but sometimes it works :S how this should happen what is blocking them i could not understand

but while they can not get ip address from each side tcpdump -n -q shows that arp requests between networks still going on :S

# dec/11/2014 23:54:00 by RouterOS 6.0

/interface bridge
add name=Kopru protocol-mode=rstp
/interface ethernet
set 0 name=Lan
set 1 name=Wan
/interface eoip
add local-address=xx.xx.xx.22 mac-address=FE:14:B2:B8:92:DD name="EoIP - 1" remote-address=yy.yy.yy.6 tunnel-id=1
/ip hotspot user profile
set [ find default=yes ] idle-timeout=none keepalive-timeout=2m mac-cookie-timeout=3d
/port
set 0 name=serial0
set 1 name=serial1
/interface bridge port
add bridge=Kopru interface="EoIP - 1"
add bridge=Kopru interface=Lan
/interface bridge settings
set use-ip-firewall-for-vlan=yes
/ip address
add address=xx.xx.xx.22/27 comment="added by setup" interface=Wan network=xx.xx.xx.0
add address=1.1.1.3/24 interface=Kopru network=1.1.1.0
/ip firewall connection tracking
set enabled=no
/ip route
add comment="added by setup" distance=1 gateway=xx.xx.xx.1







# dec/11/2014 22:04:43 by RouterOS 6.0

/interface bridge
add name=Kopru protocol-mode=rstp
/interface ethernet
set 0 name=Lan
set 1 mac-address=00:50:56:31:A4:F0 name=Wan
/interface eoip
add local-address=yy.yy.yy.6 mac-address=02:A4:C8:60:CB:DA name="EoIP - 2" remote-address=xx.xx.xx.22 tunnel-id=1
/ip hotspot user profile
set [ find default=yes ] idle-timeout=none keepalive-timeout=2m mac-cookie-timeout=3d
/port
set 0 name=serial0
set 1 name=serial1
/interface bridge port
add bridge=Kopru interface="EoIP - 2"
add bridge=Kopru interface=Lan
/interface bridge settings
set use-ip-firewall=yes use-ip-firewall-for-vlan=yes
/ip address
add address=yy.yy.yy.6/24 comment="added by setup" interface=Wan network=yy.yy.yy.0
add address=1.1.1.1/24 interface=Kopru network=1.1.1.0
/ip firewall connection tracking
set enabled=no
/ip route
add comment="added by setup" distance=1 gateway=yy.yy.yy.1

Open in new window

0
Comment
Question by:FireBall
  • 2
3 Comments
 
LVL 11

Expert Comment

by:naderz
ID: 40497156
Have you compared notes with Mikrotik wiki? I see you are using firewall and routing settings; which shouldn't be necessary.

See below:
http://wiki.mikrotik.com/wiki/Manual:Interface/EoIP#Notes
0
 

Author Comment

by:FireBall
ID: 40497211
I have already read them as far as start to trying our networks are so complicated and big some professionals need to ask sth. if needed to resolve
0
 
LVL 11

Accepted Solution

by:
naderz earned 2000 total points
ID: 40497239
Have you tried below on both?

/interface bridge settings
set use-ip-firewall=no use-ip-firewall-for-vlan=no
0

Featured Post

Will You Be GDPR Compliant by 5/28/2018?

GDPR? That's a regulation for the European Union. But, if you collect data from customers or employees within the EU, then you need to know about GDPR and make sure your organization is compliant by May 2018. Check out our preparation checklist to make sure you're on track today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
How to fix a SonicWall Gateway Anti-Virus firewall blocking automatic updates to apps like Windows, Adobe, Symantec, etc.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …

589 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question