Create a dedicated management interface on MikroTik.

Поділитися
Вставка
  • Опубліковано 28 чер 2024
  • In this comprehensive tutorial, we dive deep into setting up a management interface on your MikroTik router. Whether you're a home user looking to enhance your network management or a professional tasked with maintaining an enterprise network, this guide has got you covered. We'll walk you through the step-by-step process of configuring your MikroTik router using RouterOS, ensuring you can manage your network with ease and efficiency.
    Don't miss out on unlocking the full potential of your MikroTik router. Subscribe to our channel for more networking tutorials, tips, and tricks that will empower you to take control of your digital world. If you find this video helpful, please like, share, and comment below with any questions or topics you'd like us to cover in future videos.
    🕘Timestamps🕘
    📕00:00 - Introduction
    📕01:08 - Overview
    Support the Channel:
    ⭐Become a Patreon: / thenetworkberg
    ⭐Become a UA-cam Member: / @thenetworkberg
    Social Media:
    🌏 / thenetworkberg
    🌏 / bergnetwork
    🌏 / the-network-berg-39451...
    MTCRE Playlist:
    • Free MTCRE RoSv6
    MTCNA Playlist:
    • Free MTCNA RoSv6
    Credits:
    Thumbnail: Created on Canva
    Intro: Created on Canva
    Music by Alumo
    Songs used:
    Dioitic
    Outland 85
    Music by Bensound.com/free-music-for-videos
    • Bensound: "The Elevato...
    Thanks again for watching

КОМЕНТАРІ • 29

  • @marakito
    @marakito 4 місяці тому +4

    It would be nice to see a mikrotik tutorial with a dedicated port placed in a separate vrf limiting it from data traffic ;)

  • @blindside995
    @blindside995 4 місяці тому +2

    Good advice including the onscreen bit for some additional info was nice.

  • @seantellsit1431
    @seantellsit1431 4 місяці тому +1

    I always set up an 'emergency' port on all my mikrotiks. Saves so much time. This includes routers and switches. This acts like a dedicated management port we see on enterprise gear like Juniper or Extreme.

  • @kirksteinklauber260
    @kirksteinklauber260 4 місяці тому +2

    I use a different approach but similar. I just edit the FW rule that blocks all what is LAN and I change it to WAN, so any bridge or VLAN interfaces will allow to connect to the router for Management.!!! Very nice video by the way!

  • @Flankymanga
    @Flankymanga 4 місяці тому +1

    Thumbs up just for the Berserk wallpaper!

  • @oneoxide
    @oneoxide 4 місяці тому +1

    Good advice! Mistakes taught me to create such management interfaces already 😅

  • @mikkio5371
    @mikkio5371 4 місяці тому +4

    Networkberg . Been a while ,u look more brit now 😅 . Nice one for dropping this . Well appreciated.

    • @TheNetworkBerg
      @TheNetworkBerg  4 місяці тому +3

      Hahaha I need to get a haircut and trim my beard and moustache a little bit, my wife wants me to try a new style since I have looked the same since we met 7 years ago so letting my hair grow out a little bit.

  • @welldone8564
    @welldone8564 4 місяці тому +2

    Thank you

  • @jamesw5584
    @jamesw5584 4 місяці тому +1

    safe mode is a good mode to be in, just dont forget to leave. ive made that mistake, usually 100 lines into a vrf and it only happened once. honest.

  • @user-zb2qm7gn7w
    @user-zb2qm7gn7w 2 місяці тому

    I think you could create a DHCP server on ether2 so you don't need to hard set it on the laptop

  • @drumaddict89
    @drumaddict89 4 місяці тому +1

    yeeeeah gothic FTW in the background!
    also looking forward to the remake?
    oh and also a side note ... naming interfaces with something like "[ ]" could cause trouble once one starts to work with scripts. just a precaution ;)

    • @TheNetworkBerg
      @TheNetworkBerg  4 місяці тому

      Yeah indeed! Gothic's atmosphere is one of the best ever. I usually replay 1 and 2 every couple of years. Definitely looking forward to the remake, but I can see myself still playing the original more. Sad that Piranhabytes is being closed down by Embracer group.

    • @ON3RVH
      @ON3RVH 4 місяці тому

      naming interfaces is always a bad idea, that's what the comments are for :)

    • @drumaddict89
      @drumaddict89 4 місяці тому

      @@TheNetworkBerg all of them were great at that time and absolutely stunning for their genre at that time.
      oh i missed out on that close-down story :( need to get myself updated on that. a pity.

  • @kellydavid4021
    @kellydavid4021 Місяць тому

    How can i configure mikrotik for automatic hitspot billing

  • @MB-xh3tv
    @MB-xh3tv 4 місяці тому

    Normally you would remove a port from bridge and therefore Lan list with a good purpose like singing it as a Wan port ore just because you would like to route to an other router. You could then make a special list entry like Management and configger a FW rule for just Management and Mac allowing on Management also. Then make sure connectionfor wan is alliwed also for the Management list,that way when adding it to the port, you are sure to cut off everything and can still have a meaningful dual purpose why you deleted it from Bridge 😀

    • @TheNetworkBerg
      @TheNetworkBerg  4 місяці тому

      This is taking a single port and essentially converting it for PURE management in the event of a critical failure. It beats having to factory reset and rebuilding config from backup or scratch or even having to netinstall. Can be very useful especially for people that many many tweaks to their devices.

    • @ubi6874
      @ubi6874 3 місяці тому

      @@TheNetworkBerg Having added Port 2 to interface list, when the device is rebooted while the port be excluded from the default switch function? What is the function og 'Interface list'?

  • @mofous
    @mofous 4 місяці тому

    This video seems relevant to my interests, however I'm new to Mikrotik and to 'advanced' networking in general, so I though I'd ask before I start going down the rabbit hole. I have a custom 5G router / modem with a RBM33G board. ETH1 is currently being used to power the device via POE and for management. ETH2 is not part of the default bridge (disabled) and is set up as pass-through for the LTE interface (and it's wired into one of the WAN ports of my multi-WAN router, providing internet access). Forgive my ignorance, but is there a way to use ETH1 for POE and LTE pass-through *and* have it be accessible via Winbox for management? Or is setting up VLANs the only option to have all three things work with only one ethernet cable and interface? Thanks.

  • @nikolashuminosky6987
    @nikolashuminosky6987 4 місяці тому

    do u know what bridge-->port-cost-mod does?

  • @garrygoodrege255
    @garrygoodrege255 4 місяці тому

    Hi mr.Berg, can you explain me, why after install virbox or vmware player on PC, i can't see mikrotik packets for winbox, i think that somethg with mutilple interfaces, but not understand how fix it, that problem seeing in vrtual environment like GNS or eve-ng.

  • @AhmadAhmad-jf3wb
    @AhmadAhmad-jf3wb 4 місяці тому

    hello
    in this way cant access to all network
    we must use romon
    is it better to use mangment vlan?

    • @TheNetworkBerg
      @TheNetworkBerg  4 місяці тому +1

      A management vlan is preferred for daily operations, the dedicated port is more of an additional failsafe incase you lock yourself out of a router by accident and need to get back onto it.

  • @michaelsims7728
    @michaelsims7728 4 місяці тому

    Thank you for the video, quick question when you showed the IP firewall and port 2 wasn't on it does that mean it can not pass any traffic ingress and engress out of the switch or just that port can not connect to the winbox ? The reason I ask is wonder if I only have a direct connect computer to have access would it be better to disable port or just use firewall rule on PFsense 6100 router ? I have the CRS 328-24P-4S+RM. The MK is just used as a switch.

    • @TheNetworkBerg
      @TheNetworkBerg  4 місяці тому +1

      No the MT firewall allows everything by default if there is no deny rule or traffic matches any rules it will just be allowed but in that instance since there is a rule referring everything that is not in the LAN interface list will be dropped on input traffic to the router itself. This will however not block transit/forwarding traffic going through the router to other networks or the Internet. Hope that helps

    • @michaelsims7728
      @michaelsims7728 4 місяці тому

      @@TheNetworkBerg Thank you, yes sir it does!

  • @tokoiaoben3842
    @tokoiaoben3842 4 місяці тому

    What happened to your pfsense ? Have you stopped using it

    • @TheNetworkBerg
      @TheNetworkBerg  4 місяці тому +5

      Hello, yes I have stopped using pfSense. If I am looking at opensource firewalls I am more inclined to work on OPNsense.