Policy Based Routing + Failover - RouterOS v7

Поділитися
Вставка
  • Опубліковано 17 жов 2024
  • #mikrotik #routeros7 #mikrotikTutorial
    Policy based routing (PBR) is a technique that forwards and routes data packets based on policies or filters. In this video, we will configure PBR from scratch in RouterOS v7.
    Menu
    0:00 Introduction
    Network Diagram + Config Backups at
    thenetworktrip...
    Check more videos on my channel
    / @thenetworktrip
    Connect with Wilmer Almazan
    LinkedIN: / wilmeralmazan
    Facebook: / nsswilmeralmazan
    Twitter: / wilmer_almazan
    Instagram: / wilmer_almazan
    Personal Blog: thenetworktrip...
    mikrotik
    routeros 7
    ospf
    mtcna
    mtcre
    cybersecurity
    routing
    cloud computing
    virtualization
    switching
    network automation

КОМЕНТАРІ • 72

  • @Joshv918
    @Joshv918 2 роки тому +1

    spent two days trying to get this to work, After slowly watching your video it worked perfectly! THANK YOU!!

    • @TheNetworkTrip
      @TheNetworkTrip  Рік тому +1

      Great to hear!

    • @S4KUR4_0FFICIAL
      @S4KUR4_0FFICIAL Місяць тому

      @@TheNetworkTrip thanks for your reply. Actually, i want four or five computer in the same network 192.168.0.0/24 using PBR to WAN2, when WAN2 link fail go to WAN1 link like this, Sir. Could you please ping me the link if you able to help me, Sir?

  • @maksimsignatovs8218
    @maksimsignatovs8218 9 місяців тому

    Very detailed explanation.
    When I tried to make a similar configuration, everything immediately worked as it should. Great educational video!👍

  • @undukunduk3432
    @undukunduk3432 Рік тому +2

    Thank you, your explanation is very easy to understand,

  • @mikkio5371
    @mikkio5371 11 місяців тому +2

    beautiful . i have been seeing this but did not take a look at it until today

  • @sunilmahajan7
    @sunilmahajan7 Рік тому +1

    Very clear and easy to understand. thank you for sharing this information..

  • @jeytis72
    @jeytis72 8 місяців тому

    Very informative and useful. Please more videos about policy routing, especially about routing rules possibly. Thanks

  • @ivanpetkov5365
    @ivanpetkov5365 2 роки тому +1

    Thank You! This video was very helpfull. Thank You again and hope to see more interesting movies.

  • @Papanara22
    @Papanara22 Рік тому +2

    Can you explain more about failover? In some conditions, it happens that the gateway from the modem is active, but the internet connection coming from the ISP is experiencing problems.
    In this video, the router only checks the ping to the gateway, without knowing whether the gateway has an active internet connection.

    • @TheNetworkTrip
      @TheNetworkTrip  Рік тому

      Hello!
      We can add recursive routing to monitor an IP beyond the connected gateway. I’ve explained that process on the following video: Recursive Routing + Failover - Mikrotik RouterOS v7
      ua-cam.com/video/eTmpBAAW_pQ/v-deo.html

  • @chilli9129
    @chilli9129 Рік тому +1

    Dziękuje bardzo za dobry film !

  • @sonricsg7499
    @sonricsg7499 24 дні тому +1

    Hi! Wilmer, In the mangle prerouting configuration in the extra tab dst address type=local can you still select local and deny it?

    • @TheNetworkTrip
      @TheNetworkTrip  22 дні тому +1

      Yes, absolutely

    • @sonricsg7499
      @sonricsg7499 22 дні тому

      thank you very much for your response. The thing is that only by enabling that option can my local IP addresses access my web server, but I don't understand why? I would like to know how that option behaves. I would like to understand it, but if it is something that requires consulting and payment, how can we do it?

  • @stevebot
    @stevebot Рік тому +1

    Thanks for this, you got me motivated to try it out. I did it on a RB952-Ui-xxxx with v7.8 and the marked traffic is deadly slow even though CPU usage is in the single digits. I’m going to try it on a better router to see how it performs.

    • @TheNetworkTrip
      @TheNetworkTrip  Рік тому +1

      Hello!
      It should work fine in any model. Something else should be affecting in your RB952

    • @stevebot
      @stevebot Рік тому

      @@TheNetworkTripFasttrack was the issue, firewall forward rules in and out before fasttrack rule solved it.

  • @Serg_B.
    @Serg_B. 2 роки тому +1

    Thank you very much! Very informative tutorial. Great work!

  • @diegozupo-btcaas3009
    @diegozupo-btcaas3009 Рік тому +1

    Thank you man, it was a great video and a good class. Keep going 💪

  • @luisvilla4811
    @luisvilla4811 2 роки тому +2

    Al fin pude configurar mi RB en modo PBR, te agradezco mucho, saludos!

  • @rubigero2191
    @rubigero2191 Місяць тому +1

    Hi i have 2 routers 1st router is core, and the 2nd is access concentrator, i put my isp 1 and 2 in my core router, and i connect router 2 using ospf, how can i configure PBR? thank you

    • @TheNetworkTrip
      @TheNetworkTrip  Місяць тому +1

      Hello!
      The PBR rules must be placed on the core router since it’s the point where traffic is sent out to the internet.

  • @luisgutierrez-kb8re
    @luisgutierrez-kb8re 2 роки тому

    gracias por compartir la info ya logre configurar en modo PBR, saludos

  • @Anavllama
    @Anavllama Рік тому +1

    Okay now Lets say ISP2 is a cable ISP with dynamic ISP. The Default route created always switches to the new gateway and new IP address but the policy Route with FIB will not change its gateway as it was created manually. How will this get updated??

    • @TheNetworkTrip
      @TheNetworkTrip  Рік тому

      Hello!
      In you scenario, you will require a script to monitor the current gateway and update the route whenever it changes. I will create a video about that.

    • @IgorEnot
      @IgorEnot Рік тому

      Please! Most possible real life situation when ISP 1 is static and wired (ether1) and ISP 2 is LTE or other dynamic IP connection (ether2 or internal LTE). How to manage this situation in ROS7x correctly?@@TheNetworkTrip

  • @Johann75
    @Johann75 Рік тому +1

    Good explanation

  • @dublegun4884
    @dublegun4884 Рік тому +1

    Спасибо!

  • @omargayle6634
    @omargayle6634 Рік тому +1

    muchas gracias por el video!!

  • @yancyrodrigo149
    @yancyrodrigo149 2 роки тому +1

    Thank you for the great discussion good sir. Unfortunately, my WANs are directly connected to my Mikrotik so it will always have a connection even without internet. May I ask how I could apply this on my system?

    • @TheNetworkTrip
      @TheNetworkTrip  2 роки тому

      Hello, thank you. You can use recursive routing to monitor if the WAN connection has access to Internet. I have a video about it on my channel: ua-cam.com/video/eTmpBAAW_pQ/v-deo.html

  • @chilli9129
    @chilli9129 Рік тому +1

    Hello
    i.e. if you excluded lan addresses, you don't need to specify in.interface ether3 ?

    • @TheNetworkTrip
      @TheNetworkTrip  Рік тому +1

      Hello, it's still required because the traffic coming from Internet must not be excluded.

  • @RicardoHoos
    @RicardoHoos 2 роки тому +1

    Greetings The Network Trip, thank you very much for the tutorial, and all the knowledge you share with Mikrotik enthusiasts, I wanted to ask a very specific question:
    When making this configuration, there is a problem if only the Mangle part of the backup WAN2 is configured, of course without omitting the Routes part so that the failover works properly. Thank you!

    • @TheNetworkTrip
      @TheNetworkTrip  2 роки тому +2

      Hello Ricardo,
      No problem at all. The traffic without routing-marks will use the main routing table.

  • @iambongna
    @iambongna 2 роки тому

    Thank you, I like your Videos.

  • @JavierPlay
    @JavierPlay Рік тому

    So nice

  • @christosaivazoglou5860
    @christosaivazoglou5860 2 роки тому +1

    Hello, could you please provide guidelines how to use port forwording + recursive routing to avoid to check ping the ISP gateway but a public ip address. Thank you. Amazing Video !

    • @TheNetworkTrip
      @TheNetworkTrip  2 роки тому +1

      Hi Christos, my video about port-forwarding can solve that part of your requirement: ua-cam.com/video/-kNHtlOb5n0/v-deo.html. Then, the logic behind recursive routes is similar to the process explained in this video (just ignoring the PBR and routing tables): ua-cam.com/video/JWSfC_7p1yU/v-deo.html
      I will create a video on failover + recursive routing only.

    • @christosaivazoglou5860
      @christosaivazoglou5860 2 роки тому +1

      @@TheNetworkTrip hello yes I just watching both videos to combine .
      Recursive routing failover and port forwarding and in case of PPC will be easy because I saw in comments many colleagues request the full package. Never mind you are amazing I am happy to see videos true ambassador of MikroTik !!

    • @TheNetworkTrip
      @TheNetworkTrip  2 роки тому +1

      @@christosaivazoglou5860 Good point, I'll do that.

    • @christosaivazoglou5860
      @christosaivazoglou5860 2 роки тому

      @@TheNetworkTrip I will wait you and then configure me two pending warehouses to avoid to buy 2K euro Fortinet router for a single kibo
      One again,
      You are amazing

  • @nosharwangujar1323
    @nosharwangujar1323 2 роки тому +2

    brother kindly make a video PBR +Failover + Recursive Routing

  • @mishasawangwan6652
    @mishasawangwan6652 11 місяців тому

    hi wilmer what happened to your VRRP video?

  • @MindSparqTrivia
    @MindSparqTrivia 2 роки тому +1

    Good work sir. , how about separating traffic on pppoe clients based on their profile(ip pool) sir? Lets say I have two mikrotik routers R1(core) and R2(pppoe server). Thank you so much sir

    • @TheNetworkTrip
      @TheNetworkTrip  2 роки тому

      Hi Michael, thank you
      You can add the address-list in the PPPoE profile.

  • @JumWong
    @JumWong 7 місяців тому

    Which one is better for PPPoE? PBR or Load Balancing?

  • @jesusmaster16
    @jesusmaster16 Рік тому +1

    Gracias maestro, me tuve que venir a su canal en inglés para ver cómo se hace completamente el PBR en v7 😂😂😂

  • @Rouly88
    @Rouly88 2 роки тому +1

    Thank you very much..
    All your video it's very helpful. Thanks.
    Please think about how to configure Load balancing PCC + Fail over on RouterOS v7

    • @TheNetworkTrip
      @TheNetworkTrip  2 роки тому

      Hi, thank you
      My next video is about Failover + Recursive Routing. PCC is coming soon!

  • @OfficialRoot
    @OfficialRoot 2 роки тому

    Good work!!!

  • @romanm.4763
    @romanm.4763 6 місяців тому

    It looks like ROS v6 works differently about prerouting and firstly checks accessible routes before applying mangle rules. So the PBR rule can work well in ROS v6 without explicitly excluding dest private networks

  • @nosharwangujar1323
    @nosharwangujar1323 2 роки тому

    i need to configure my router with policy based routing and external host for fail over bro kindly make a video according this scenario thanks alot

  • @S4KUR4_0FFICIAL
    @S4KUR4_0FFICIAL Місяць тому +1

    Could you please assist me step by step guide for this lab with snap shot pictures if possible? Sir, Hopefully, you can. Thank you, Sir

    • @TheNetworkTrip
      @TheNetworkTrip  16 днів тому

      Hello!
      You can get that behaviour by pausing the video at every step. The video is giving you the full picture, but you can go slowly if you wish.
      Good luck!

  • @chilli9129
    @chilli9129 Рік тому

    16:59 what if I have several networks on several interfaces?

    • @TheNetworkTrip
      @TheNetworkTrip  Рік тому

      You can use an interface-list instead of a single interface (interface/list)

  • @JavierPlay
    @JavierPlay Рік тому

    How would work port forwarding after you set pbr?

  • @gerojasblanco
    @gerojasblanco 2 роки тому

    Excellent video!, thank you for share it.
    I´ve a inverse situation: 1 isp and 2 routes to same ip subnet but different interfaces: a bridge and vlan interface. The vlan interface make possible a trunk link with a Cisco switch, where are PCs of the same ip subnet of bridge in Mikrotik RB. I mean, the same ip subnet has 2 routes and none PC work, obsviously. PBR may be the solution?

  • @helper_maestro1956
    @helper_maestro1956 2 роки тому +1

    Greetings.. sir can you make a video how to separate social media and videos to ISP1 and other traffics goes to ISP2..

  • @nosharwangujar1323
    @nosharwangujar1323 2 роки тому

    something like this video brother sorry for disturb you again and again

  • @nicoladellino8124
    @nicoladellino8124 Рік тому +1

    Muchas gracias por el video.