Community discussions

MikroTik App
LeftHandedCat
刚刚加入了
Topic Author
Posts: 1
Joined: Mon May 16, 2022 8:08 pm

Need product recommendation

Mon May 16, 2022 9:46 pm

Hello,

I'm new to mikrotik, a friend recommended this brand to me as very good and useful networking products.

I need a solution for the following problem:
Current setup: Internet connection with static IP, router from the ISP only limited / almost no configuration possible and if only from the provider, Router exchange not possible. Internal, we use a switch to connect all Computer and Network devices. The ISP configured their router to forward a few ports we need for external access: mail server and NVR.

Problem: NVR can only be secured with a very weak password. But it must be reached externally.

Our Goal: In the future, access should be possible from a small number of end devices only, or at least restricted, e.g. via VPN, especially from outside. If possible, all open ports should generally be better protected (firewall?).

The following ideas have been discussed so far: a separate router between internal switch and NVR that can only be reached via VPN in order to limit NVR access in this way. Or an intelligent new switch that allows certain devices or MAC addresses to access the NVR or the mail server, or otherwise controls firewall rules.

How can we solve this and are there any products from mikrotik, that can provide a solution. Any help is welcome, thanks in advance.

all the best
Top
User avatar
anav
Forum Guru
Forum Guru
Posts: 17479
Joined: 太阳2月18日,2018年十一28便士m
Location:Nova Scotia, Canada
Contact:

Re: Need product recommendation

Tue May 17, 2022 5:03 am

Throughput of internet connection(s) ?
Top
User avatar
IPANetEngineer
Trainer
Trainer
Posts: 1739
Joined: Fri Aug 10, 2012 6:46 am
Location:iparchitechs.com
Contact:

Re: Need product recommendation

Tue May 17, 2022 6:04 am

NVR access externally is a great use case for the ZeroTIer VPN protocol which was just added to MikroTik on ARM based devices last year.

If you're unfamiliar with ZeroTier - here is an overview of it (before MIkroTik support was added)

https://stubarea51.net/2020/03/10/remot ... frrouting/

Then, once you've determined the bandwidth needed, you can look at either an all-in-one solution with one of the ARM based MikroTik CRS 3xx series switches - which will be slower speeds of 50 to 100 Mbps (give or take). Or also use an ARM64 router like the RB5009 or CCR2116 - both of which have excellent performance over the Internet for ZeroTier and can do 500+ Mbps.

Because ZeroTIer is so easy to configure and has PC/Mac and mobile clients, it's really straightforward to access an NVR (or any other system) behind NAT.
Top
reinerotto
Long time Member
Long time Member
Posts: 518
Joined: Thu Dec 04, 2008 2:35 am

Re: Need product recommendation

Tue May 17, 2022 9:29 am

选择,可能比zerotier更快,没有license hassles, but requiring more tech know-how for setup:
Use wireguard as VPN. wireguard-"client" on local router, setting up tunnel to private wireguard-"server" on the web.
You can do this with mikrotik equipment, but also using alternatives, i.e. based on openwrt, which is totally opensource, opposed to mikrotiks stuff.
Top
User avatar
Larsa
Forum Veteran
Forum Veteran
Posts: 892
Joined: Sat Aug 29, 2015 7:40 pm
Location:The North Pole, Santa's Workshop

Re: Need product recommendation

Tue May 17, 2022 12:00 pm

Agree that both options are pretty good but I believe that ZeroTier (ZT) might be somewhat easier to administer when you want to connect additional clients to your private network.

When it comes to ZT licenses, there are normally no costs for the private user if using either the "open source" community edition with a self-hosted controller or the "basic" version using the ZT hosted controller.https://www.zerotier.com/pricing/

Regardless of what solution you choose, I recommend buying an arm-based device to be able to take advantage of all the new features that are in router-os v7.
Top
User avatar
IPANetEngineer
Trainer
Trainer
Posts: 1739
Joined: Fri Aug 10, 2012 6:46 am
Location:iparchitechs.com
Contact:

Re: Need product recommendation

Tue May 17, 2022 4:41 pm

I agree, wireguard is great for technical people and infrastructure, but it's not a great client facing VPN for non-technical people.

ZeroTier excels at this use case and is perfect if you want a solution that you don't have to spend much time "administering" it just works. It also scales incredibly well.
Top
User avatar
mozerd
Forum Veteran
Forum Veteran
Posts: 865
Joined: Thu Oct 05, 2017 3:39 pm
Location:Canada
Contact:

Re: Need product recommendation

Tue May 17, 2022 5:14 pm

Can your ISP provided Router operate in BRIDGE mode?
What Bandwidth does your ISP provide you and is that throughputsymmetricalorasymmetrical?
How many users will you need to support?
Top
User avatar
Larsa
Forum Veteran
Forum Veteran
Posts: 892
Joined: Sat Aug 29, 2015 7:40 pm
Location:The North Pole, Santa's Workshop

Re: Need product recommendation

Tue May 17, 2022 6:26 pm

I agree, wireguard is great for technical people and infrastructure, but it's not a great client facing VPN for non-technical people. ZeroTier excels at this use case and is perfect if you want a solution that you don't have to spend much time "administering" it just works. It also scales incredibly well.

Yep indeed!

Somewhat OT but regarding wg and dynamic ip address assignment (aka pptp) there are several solutions but they all are dependent on alterations at both endpoints (peers) as well as custom-made clients. Also, one really shouldn't have to be a hard-core network technician just to perform a new setup.

It's a pity Jason and gang didn't put more effort to create standardized reference implementation for this as well some other stuff like simplified configuration.

However I have to admit they've made some progress on both the windows and mac client since I last visited their dev IRC channel some years ago. I almost got thrown out when I mentioned they might consider to put some more work on the windows client. It was really a wild bunch of linux fanatics at that time, more like a sect actually :- )
Top
User avatar
anav
Forum Guru
Forum Guru
Posts: 17479
Joined: 太阳2月18日,2018年十一28便士m
Location:Nova Scotia, Canada
Contact:

Re: Need product recommendation

Tue May 17, 2022 7:29 pm

Concur, the lack of solid MT instructions is not conducive to their use.........
Top
reinerotto
Long time Member
Long time Member
Posts: 518
Joined: Thu Dec 04, 2008 2:35 am

Re: Need product recommendation

Tue May 17, 2022 7:37 pm

+1.
Using wireguard on openwrt, which is much more "Linux" than MTs stuff, is straight forward.
Top

Who is online

Users browsing this forum:Ahrefs [Bot],TomjNorthIdahoand 11 guests

Baidu
map