Diferencias
Muestra las diferencias entre dos versiones de la página.
Ambos lados, revisión anterior Revisión previa Próxima revisión | Revisión previa | ||
doc:tec:net:router:ros:faq:duo:inicio [2025/04/13 12:41] – borrado - editor externo (Fecha desconocida) 127.0.0.1 | doc:tec:net:router:ros:faq:duo:inicio [2025/04/13 12:41] (actual) – ↷ Enlaces adaptados debido a una operación de mover fepg | ||
---|---|---|---|
Línea 1: | Línea 1: | ||
+ | ====== Interacción entre dos routers ====== | ||
+ | <WRAP center round tip> | ||
+ | Se trata de estudiar las diferentes combinaciones para disponer de un router neutro, en nuestra oficina o casa, que se conecte al router proporcionado por el distribuidor de internet ISP. De esta manera se esperan conseguir mayores prestaciones y control de nuestra red que lo que permite el router de la compañía ISP. | ||
+ | </ | ||
+ | |||
+ | <WRAP center round help> | ||
+ | |||
+ | * Artículos | ||
+ | * [[https:// | ||
+ | |||
+ | * Vídeos | ||
+ | * [[https:// | ||
+ | |||
+ | </ | ||
+ | \\ | ||
+ | ===== Configuración de router Mikrotik para Vodafone con IPTV ===== | ||
+ | |||
+ | <WRAP center round help> | ||
+ | |||
+ | * [[https:// | ||
+ | |||
+ | </ | ||
+ | |||
+ | {{ doc: | ||
+ | |||
+ | < | ||
+ | #Creación de Bridge | ||
+ | /interface bridge | ||
+ | add name=switch0-lan priority=0x1000 | ||
+ | # | ||
+ | /interface ethernet | ||
+ | set [ find default-name=ether7 ] name=ether7-deco | ||
+ | set [ find default-name=ether8 ] name=ether8-wan | ||
+ | #Creación de VLANs sobre el puerto ethernet WAN | ||
+ | /interface vlan | ||
+ | add interface=ether8-wan name=eth8-vlan100 vlan-id=100 | ||
+ | add comment=WAN-IPTV interface=ether8-wan name=eth8-vlan105 vlan-id=105 | ||
+ | #Listas de interfaces | ||
+ | /interface list | ||
+ | add name=LAN-IPTV | ||
+ | add name=WAN-IPTV | ||
+ | add name=WAN | ||
+ | add name=LAN | ||
+ | add include=WAN, | ||
+ | #DHCP Flag aplicado posteriormente en el DHP de la IPTV | ||
+ | /ip dhcp-server option | ||
+ | add code=12 name=VF_Tivo value="' | ||
+ | #Dos pool de direcciones. Uno para LAN y otro para IPTV | ||
+ | /ip pool | ||
+ | add name=dhcp-lan-pool ranges=192.168.0.100-192.168.0.200 | ||
+ | add name=dhcp-iptv-pool ranges=192.168.10.10-192.168.10.15 | ||
+ | #Creación de dos servidores DHCP | ||
+ | /ip dhcp-server | ||
+ | add address-pool=dhcp-lan-pool interface=switch0-lan name=dhcp-lan | ||
+ | add address-pool=dhcp-iptv-pool interface=ether7-deco name=dhcp-iptv | ||
+ | #Cliente PPPoE sobre la interfaz virtual creada con la VLAN de datos | ||
+ | /interface pppoe-client | ||
+ | add add-default-route=yes comment=WAN disabled=no interface=eth8-vlan100 max-mru=1492 max-mtu=1492 name=pppoe0-wan profile=default-encryption user=XXXXXXXXXX@vodafone | ||
+ | # | ||
+ | /interface bridge port | ||
+ | add bridge=switch0-lan fast-leave=yes interface=ether1 | ||
+ | add bridge=switch0-lan fast-leave=yes interface=ether2 | ||
+ | add bridge=switch0-lan fast-leave=yes interface=ether3 | ||
+ | add bridge=switch0-lan fast-leave=yes interface=ether4 | ||
+ | # | ||
+ | /interface list member | ||
+ | add interface=ether7-deco list=LAN-IPTV | ||
+ | add interface=eth8-vlan105 list=WAN-IPTV | ||
+ | add interface=switch0-lan list=LAN | ||
+ | add interface=eth8-vlan100 list=WAN | ||
+ | add interface=pppoe0-wan list=WAN | ||
+ | add interface=ether8-wan list=WAN | ||
+ | # | ||
+ | /ip address | ||
+ | add address=192.168.0.1/ | ||
+ | add address=192.168.10.1/ | ||
+ | #Cliente DHCP sobre la interfaz virtual creada con la VLAN de IPTV | ||
+ | /ip dhcp-client | ||
+ | add add-default-route=no interface=eth8-vlan105 use-peer-dns=no | ||
+ | # | ||
+ | /ip dhcp-server lease | ||
+ | add address=192.168.10.10 comment=" | ||
+ | #Creación de servidores DHCP | ||
+ | /ip dhcp-server network | ||
+ | add address=192.168.0.0/ | ||
+ | add address=192.168.10.0/ | ||
+ | # | ||
+ | /ip dns | ||
+ | set allow-remote-requests=yes use-doh-server=https:// | ||
+ | #Listas de direcciones para firewall | ||
+ | /ip firewall address-list | ||
+ | add address=192.168.10.0/ | ||
+ | add address=192.168.0.0/ | ||
+ | #Reglas de Firewall | ||
+ | /ip firewall filter | ||
+ | add action=accept chain=input comment=" | ||
+ | add action=add-src-to-address-list address-list=Blacklist address-list-timeout=10h chain=input comment=" | ||
+ | in-interface-list=WAN log=yes log-prefix=" | ||
+ | add action=accept chain=input comment=" | ||
+ | add action=drop chain=input comment=" | ||
+ | add action=accept chain=input comment=" | ||
+ | add action=accept chain=input comment=" | ||
+ | add action=accept chain=input comment=" | ||
+ | add action=accept chain=input comment=" | ||
+ | add action=accept chain=input comment=" | ||
+ | add action=accept chain=input comment=" | ||
+ | add action=drop chain=input comment=" | ||
+ | add action=fasttrack-connection chain=forward comment=" | ||
+ | add action=accept chain=forward comment=" | ||
+ | add action=drop chain=forward comment=" | ||
+ | add action=accept chain=forward comment=" | ||
+ | add action=drop chain=forward comment=" | ||
+ | #Priorizar paquetes de IPTV | ||
+ | /ip firewall mangle | ||
+ | add action=set-priority chain=postrouting new-priority=4 out-interface-list=WAN-IPTV passthrough=yes | ||
+ | add action=set-priority chain=postrouting new-priority=1 out-interface-list=WAN passthrough=no | ||
+ | #Reglas de NAT | ||
+ | /ip firewall nat | ||
+ | add action=masquerade chain=srcnat comment=" | ||
+ | add action=masquerade chain=srcnat comment=" | ||
+ | /ip firewall raw | ||
+ | add action=drop chain=prerouting comment=" | ||
+ | add action=add-dst-to-address-list address-list=Blacklist address-list-timeout=10m chain=output comment=" | ||
+ | BRUTEFORCE | ||
+ | #Rutas estáticas necesarias para Vodafone IPTV | ||
+ | /ip route | ||
+ | add disabled=no distance=1 dst-address=10.8.57.0/ | ||
+ | add disabled=no distance=1 dst-address=10.8.58.0/ | ||
+ | add disabled=no distance=1 dst-address=10.8.59.0/ | ||
+ | add disabled=no distance=1 dst-address=10.15.220.0/ | ||
+ | add disabled=no distance=1 dst-address=10.179.32.0/ | ||
+ | # | ||
+ | /ip service | ||
+ | set telnet disabled=yes | ||
+ | set ftp disabled=yes | ||
+ | set www disabled=yes | ||
+ | set ssh address=192.168.0.0/ | ||
+ | set www-ssl address=192.168.0.0/ | ||
+ | set api disabled=yes | ||
+ | set winbox address=192.168.0.0/ | ||
+ | set api-ssl disabled=yes | ||
+ | # | ||
+ | /routing igmp-proxy | ||
+ | set quick-leave=yes | ||
+ | /routing igmp-proxy interface | ||
+ | add alternative-subnets=0.0.0.0/ | ||
+ | add interface=ether7-deco | ||
+ | # | ||
+ | /system clock | ||
+ | set time-zone-name=Europe/ | ||
+ | /system ntp client | ||
+ | set enabled=yes | ||
+ | /system ntp client servers | ||
+ | add address=0.es.pool.ntp.org | ||
+ | add address=1.es.pool.ntp.org | ||
+ | add address=2.es.pool.ntp.org | ||
+ | add address=3.es.pool.ntp.org | ||
+ | /system routerboard settings | ||
+ | set cpu-frequency=auto | ||
+ | </ | ||
+ | \\ |