Tuesday, May 7, 2019

Transparent traffic shaping using Mikrotik RouterOS

Hello, hoping to get a sanity check on this. I have set and am just about to test traffic shaping on an RB2011UiAS-RM. The question I have is whether or not this can all be performed via a single port (router-on-a-stick) setup.

  • The router currently runs as the gateway and traffic shaper for guest Wi-Fi on its own public IP.
  • It was thought that the router also performed traffic shaping for some of the WAN links. (Some devices have direct WAN like the primary corporate internet, other devices are on a different VLAN thought to be running through this for shaping).
  • I set up a new bridge interface, two VLAN interfaces (WAN VLAN and shaped WAN VLAN), and a PCQ shaping policy with the help of some of the Mikrotik guides.

What I did differently from their guides was rather than using two physical interfaces for the transparent shaping, I used two VLANs. One of the VLAN's is the same VLAN it gets it's public IP from.

To clarify, the following are connected to the first gigabit interface from the switch:

VLAN 1 (WAN VLAN) Native

VLAN 2 (Guest Wi-Fi) Tagged

VLAN 3 (WAN traffic I am trying to shape) Tagged.

This sounds to me like it may not work since VLAN 1 is both attempting to be transparently bridged with traffic shaping, and is also being used with a public IP for the Guest Wi-Fi.



No comments:

Post a Comment