<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title>Mikrotik.moscow [тема: Трафик из VLAN не маскируется на WAN-интерфейсе.]</title>
		<link>http://mikrotik.moscow</link>
		<description>Новое в теме Трафик из VLAN не маскируется на WAN-интерфейсе. форума RouterOS на сайте Mikrotik.moscow [mikrotik.moscow]</description>
		<language>ru</language>
		<docs>http://backend.userland.com/rss2</docs>
		<pubDate>Sun, 16 Aug 2026 12:27:05 -0400</pubDate>
		<item>
			<title>Трафик из VLAN не маскируется на WAN-интерфейсе.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/60614-trafik-iz-vlan-ne-maskiruetsya-na-wan_interfeyse./message231052">Трафик из VLAN не маскируется на WAN-интерфейсе.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			У меня была та же проблема — невозможно было сделать NAT через VLAN. В итоге я обновился с OS 5.24 до OS 6.9, и сразу же всё заработало (я даже ничего не менял). <br />
			<i>14.02.2014 14:36:00, danielm.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/60614-trafik-iz-vlan-ne-maskiruetsya-na-wan_interfeyse./message231052</link>
			<guid>http://mikrotik.moscow/forum/forum57/60614-trafik-iz-vlan-ne-maskiruetsya-na-wan_interfeyse./message231052</guid>
			<pubDate>Fri, 14 Feb 2014 14:36:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Трафик из VLAN не маскируется на WAN-интерфейсе.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/60614-trafik-iz-vlan-ne-maskiruetsya-na-wan_interfeyse./message231051">Трафик из VLAN не маскируется на WAN-интерфейсе.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Извини, у меня была загруженная неделя, которая вывела меня из города на некоторое время. Вот соответствующая информация о конфигурации маршрутизаторов. Я опустил некоторую информацию, не имеющую отношения к этой конкретной проблеме, для ясности.<br /><br />**Домашний (основной) маршрутизатор**<br /><br />`/ip address print`<br /><br />```<br /># &nbsp; ADDRESS &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;NETWORK &nbsp; &nbsp; &nbsp; &nbsp; INTERFACE<br /> 0 &nbsp; ;;; WISP Antennas<br /> &nbsp; &nbsp; 10.10.0.1/24 &nbsp; &nbsp; &nbsp; 10.10.0.0 &nbsp; &nbsp; &nbsp; bridgeWISP<br /> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <br /> 2 &nbsp; ;;; Company Network<br /> &nbsp; &nbsp; 10.20.0.1/24 &nbsp; &nbsp; &nbsp; 10.20.0.0 &nbsp; &nbsp; &nbsp; bridgeCompany<br /> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<br /> 4 &nbsp; ;;; VSAT<br /> &nbsp; &nbsp; 10.2.8.18/29 &nbsp; &nbsp; &nbsp; 10.2.8.16 &nbsp; &nbsp; &nbsp; ether1-VSAT ip route print<br />Flags: X - disabled, A - active, D - dynamic, <br />C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme, <br />B - blackhole, U - unreachable, P - prohibit<br /> # &nbsp; &nbsp; &nbsp;DST-ADDRESS &nbsp; &nbsp; &nbsp; &nbsp;PREF-SRC &nbsp; &nbsp; &nbsp; &nbsp;GATEWAY &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;DISTANCE<br /> 0 A S &nbsp;0.0.0.0/0 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 10.2.8.17 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;10<br /> 1 ADC &nbsp;10.2.8.16/29 &nbsp; &nbsp; &nbsp; 10.2.8.18 &nbsp; &nbsp; &nbsp; ether1-VSAT &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0<br /> 2 ADC &nbsp;10.10.0.0/24 &nbsp; &nbsp; &nbsp; 10.10.0.1 &nbsp; &nbsp; &nbsp; bridgeWISP &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0<br /><br /> 5 ADC &nbsp;10.20.0.0/24 &nbsp; &nbsp; &nbsp; 10.20.0.1 &nbsp; &nbsp; &nbsp; bridgeCompany &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0<br />interface print<br />Flags: D - dynamic, X - disabled, R - running, S - slave<br /> # &nbsp; &nbsp; NAME &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;TYPE &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; MTU L2MTU &nbsp;MAX-L2MTU<br /> 2 &nbsp;R &nbsp;;;; AP 11 Southeast<br /> &nbsp; &nbsp; &nbsp; ether7-Southeast &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;ether &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 1500 &nbsp;1600 &nbsp; &nbsp; &nbsp; 4080<br /> 3 &nbsp; &nbsp; ether8 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;ether &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 1500 &nbsp;1600 &nbsp; &nbsp; &nbsp; 4080<br /> 4 &nbsp;R &nbsp;;;; AP 10 North<br /> &nbsp; &nbsp; &nbsp; ether6-North &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;ether &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 1500 &nbsp;1600 &nbsp; &nbsp; &nbsp; 4080<br /> 5 &nbsp;R &nbsp;;;; Servers<br /> &nbsp; &nbsp; &nbsp; ether5-Servers &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;ether &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 1500 &nbsp;1598 &nbsp; &nbsp; &nbsp; 4078<br /> 9 &nbsp;R &nbsp;;;; VSAT (WAN)<br /> &nbsp; &nbsp; &nbsp; ether1-VSAT &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ether &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 1500 &nbsp;1598 &nbsp; &nbsp; &nbsp; 4078<br />10 &nbsp;R &nbsp;;;; WISP<br /> &nbsp; &nbsp; &nbsp; bridgeWISP &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; bridge &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1500 &nbsp;1598<br />11 &nbsp;R &nbsp;;;; Company bridge<br /> &nbsp; &nbsp; &nbsp; bridgeCompany &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; bridge &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1500 &nbsp;1594<br />12 &nbsp;R &nbsp;;;; Company VLAN<br /> &nbsp; &nbsp; &nbsp; vlan100-bridgeWISP &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;vlan &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1500 &nbsp;1594<br />interface bridge port print<br />Flags: X - disabled, I - inactive, D - dynamic<br /> # &nbsp; &nbsp;INTERFACE &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; BRIDGE &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;PRIORITY &nbsp;PATH-COST &nbsp; &nbsp;HORIZON<br /> 1 &nbsp; &nbsp;ether7-Southeast &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;bridgeWISP &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0x80 &nbsp; &nbsp; &nbsp; &nbsp; 10 &nbsp; &nbsp; &nbsp; none<br /> 2 &nbsp; &nbsp;ether6-North &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;bridgeWISP &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0x80 &nbsp; &nbsp; &nbsp; &nbsp; 10 &nbsp; &nbsp; &nbsp; none<br /> 3 &nbsp; &nbsp;ether5-Servers &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;bridgeCompany &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0x80 &nbsp; &nbsp; &nbsp; &nbsp; 10 &nbsp; &nbsp; &nbsp; none<br /> 4 &nbsp; &nbsp;vlan100-bridgeWISP &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; bridgeCompany &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0x80 &nbsp; &nbsp; &nbsp; &nbsp; 10 &nbsp; &nbsp; &nbsp; none<br />ip firewall nat print<br />Flags: X - disabled, I - invalid, D - dynamic<br /> 0 &nbsp; ;;; Masquerade WAN traffic<br /> &nbsp; &nbsp; chain=srcnat action=masquerade out-interface=ether1-VSAT<br />```<br /><br />**Офисный маршрутизатор**<br /><br />`/ip address print`<br /><br />```<br />Flags: X - disabled, I - invalid, D - dynamic<br /> # &nbsp; ADDRESS &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;NETWORK &nbsp; &nbsp; &nbsp; &nbsp; INTERFACE<br /> 0 &nbsp; ;;; Guest Network<br /> &nbsp; &nbsp; 10.0.0.1/24 &nbsp; &nbsp; &nbsp; &nbsp;10.0.0.0 &nbsp; &nbsp; &nbsp; &nbsp;wlan2<br /> 1 &nbsp; ;;; WISP<br /> &nbsp; &nbsp; 10.10.0.80/24 &nbsp; &nbsp; &nbsp;10.10.0.0 &nbsp; &nbsp; &nbsp; ether1-Ant<br />interface print<br />Flags: D - dynamic, X - disabled, R - running, S - slave<br /> # &nbsp; &nbsp; NAME &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;TYPE &nbsp; &nbsp; &nbsp; &nbsp; MTU L2MTU &nbsp;MAX-L2MTU<br /> 0 &nbsp;R &nbsp;ether1-Ant &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;ether &nbsp; &nbsp; &nbsp; 1500 &nbsp;1600 &nbsp; &nbsp; &nbsp; 4076<br /> 5 &nbsp;RS wlan1 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; wlan &nbsp; &nbsp; &nbsp; &nbsp;1500 &nbsp;2290<br /> 6 &nbsp; S wlan2 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; wlan &nbsp; &nbsp; &nbsp; &nbsp;1500 &nbsp;2290<br /> 8 &nbsp;R &nbsp;bridgeCompany &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; bridge &nbsp; &nbsp; &nbsp;1500 &nbsp;1596<br /> 9 &nbsp;RS ether1-Ant-VLAN100 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;vlan &nbsp; &nbsp; &nbsp; &nbsp;1500 &nbsp;1596<br />interface bridge port print<br />Flags: X - disabled, I - inactive, D - dynamic<br /> # &nbsp; &nbsp;INTERFACE &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; BRIDGE &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; PRIORITY &nbsp;PATH-COST &nbsp; &nbsp;HORIZON<br /> 0 &nbsp; &nbsp;ether5 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;bridgeCompany &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0x80 &nbsp; &nbsp; &nbsp; &nbsp; 10 &nbsp; &nbsp; &nbsp; none<br /> 1 &nbsp; &nbsp;ether2 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;bridgeCompany &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0x80 &nbsp; &nbsp; &nbsp; &nbsp; 10 &nbsp; &nbsp; &nbsp; none<br /> 2 I &nbsp;ether3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;bridgeCompany &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0x80 &nbsp; &nbsp; &nbsp; &nbsp; 10 &nbsp; &nbsp; &nbsp; none<br /> 3 I &nbsp;ether4 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;bridgeCompany &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0x80 &nbsp; &nbsp; &nbsp; &nbsp; 10 &nbsp; &nbsp; &nbsp; none<br /> 4 &nbsp; &nbsp;wlan1 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; bridgeCompany &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;0x80 &nbsp; &nbsp; &nbsp; &nbsp; 10 &nbsp; &nbsp; &nbsp; none<br /> 5 &nbsp; &nbsp;ether1-Ant-VLAN100 &nbsp; &nbsp; &nbsp;bridgeCompany &nbsp; &nbsp; &nbsp; 0x80 &nbsp; &nbsp; &nbsp; &nbsp; 10 &nbsp; &nbsp; &nbsp; none<br />ip firewall nat print<br />Flags: X - disabled, I - invalid, D - dynamic<br /> 0 &nbsp; chain=srcnat action=masquerade out-interface=ether1-Ant<br />```<br /><br />Весь трафик из сети 10.20.0.0/24, подключенной через VLAN с офисного маршрутизатора, не маскируется, даже если я добавляю правило DST NAT специально для IP-адреса тестовой машины в офисе. Даже если я использую torch на ether1, он все равно показывает трафик с исходного адреса 10.20.0.99. Я пробовал даже это правило для конкретного источника и назначения, но ничего не поймал, когда пытался пинговать 8.8.8.8. Есть ли какие-нибудь другие предложения, почему трафик VLAN может не маскироваться? Мы собираемся попробовать другой маршрутизатор сегодня или завтра, а также последнюю версию RouterOS. <br />
			<i>14.01.2014 11:22:00, OwenITGuy.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/60614-trafik-iz-vlan-ne-maskiruetsya-na-wan_interfeyse./message231051</link>
			<guid>http://mikrotik.moscow/forum/forum57/60614-trafik-iz-vlan-ne-maskiruetsya-na-wan_interfeyse./message231051</guid>
			<pubDate>Tue, 14 Jan 2014 11:22:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Трафик из VLAN не маскируется на WAN-интерфейсе.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/60614-trafik-iz-vlan-ne-maskiruetsya-na-wan_interfeyse./message231050">Трафик из VLAN не маскируется на WAN-интерфейсе.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Привет, efaden. Спасибо за ответ. Давай я подумаю над твоим запросом по конфигам. У нашего основного роутера довольно большой конфиг, и там есть информация, которую я бы не хотел выкладывать всему миру. Может быть, я смогу экспортировать нужные разделы. Придётся отложить это до понедельника, когда вернусь в офис. Да, двойной NAT — это намеренно, и я объясню почему. У нас есть несколько клиентов из разных организаций, которые используют нашу систему. У каждого клиента есть одна антенна (Ubiquiti) в сети 10.10.0.0/24. Каждая из этих антенн работает в режиме NAT-роутера и распределяет DHCP-адреса для каждого клиента на приватной стороне антенны. Таким образом, наш основной (домашний) роутер видит только 1 IP-адрес (10.10.0.x) для каждой клиентской антенны. Таким образом, нам не нужно назначать адреса для каждого клиентского компьютера, и проще контролировать или ограничивать трафик на основном роутере. Плюс это защищает LAN каждого клиента друг от друга. Второй NAT происходит неизбежно при подключении к WAN. Наш офис настроен таким же образом, как и другие клиенты (одно устройство в режиме NAT-роутера в сети 10.10.0.x). Когда я пытался добавить VLAN для трафика “компании” на днях, я решил оставить гостевую сеть на офисном роутере и придерживаться той же модели (1 NAT-адрес). Однако применение правила NAT только на ether1 маскирует только трафик, идущий именно с ether1. Трафик с vlan100-ether1 не маскируется. Трафик отображается в основном роутере как исходящий с адреса 10.20.0.0/24, назначенного ему. Это видно как в таблице подключений, так и при запуске torch на ether1. <br />
			<i>04.01.2014 13:47:00, OwenITGuy.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/60614-trafik-iz-vlan-ne-maskiruetsya-na-wan_interfeyse./message231050</link>
			<guid>http://mikrotik.moscow/forum/forum57/60614-trafik-iz-vlan-ne-maskiruetsya-na-wan_interfeyse./message231050</guid>
			<pubDate>Sat, 04 Jan 2014 13:47:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Трафик из VLAN не маскируется на WAN-интерфейсе.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/60614-trafik-iz-vlan-ne-maskiruetsya-na-wan_interfeyse./message231049">Трафик из VLAN не маскируется на WAN-интерфейсе.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Выложи экспорты с двух Mikrotik-боксов. Посмотрю конфиги. Должно работать, но есть один вопрос. Судя по текущей настройке, пакеты приходится перенаправлять через двойной NAT. Почему бы просто не пропускать VLAN-пакеты с одного роутера на другой и не делать весь NAT в одном месте? <br />
			<i>03.01.2014 17:58:00, efaden.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/60614-trafik-iz-vlan-ne-maskiruetsya-na-wan_interfeyse./message231049</link>
			<guid>http://mikrotik.moscow/forum/forum57/60614-trafik-iz-vlan-ne-maskiruetsya-na-wan_interfeyse./message231049</guid>
			<pubDate>Fri, 03 Jan 2014 17:58:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Трафик из VLAN не маскируется на WAN-интерфейсе.</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/60614-trafik-iz-vlan-ne-maskiruetsya-na-wan_interfeyse./message231048">Трафик из VLAN не маскируется на WAN-интерфейсе.</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Наша организация работает в регионе с ограниченным доступом в Интернет. У нас есть VSAT-система для доступа в Интернет в одном из служебных домов. Мы также обслуживаем небольшую сеть WISP для других организаций в этом районе и подключаем наш офис, другие служебные дома и клиентов WISP к сети через одну беспроводную сеть. Я решил настроить VLAN между нашим офисом и служебным домом (где также находится наш сервер), чтобы обеспечить связь второго уровня между этими местами. После тщательного изучения вики и других сайтов о настройке VLAN на MikroTik я пришел к конфигурации, показанной на схеме. <img class="lazyload "  src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==" data-src="/upload/forum/mikrotik/e176d5d463f65110f0e69a1d4effca076221502e.png" alt="Пользователь добавил изображение" border="0" /> Конфигурация, кажется, работает: компьютер сотрудника в офисе получает адрес 10.20.0.0/24 от роутера в доме через DHCP с 10.20.0.1 в качестве шлюза по умолчанию. Я могу подключаться к чему угодно на серверах, устройствам в подсети WISP и нашим другим подсетям. Однако трафик, предназначенный для Интернета, не проходит. Я запустил torch на ether1 на роутере в доме и обнаружил, что исходный адрес с компьютера сотрудника не маскируется. Я не могу понять, почему трафик, приходящий из VLAN, не маскируется. Все остальное со всех подсетей маскируется правильно. Я использую это правило: &gt; ip firewall nat print chain=srcnat <br />Flags: X - disabled, I - invalid, D - dynamic <br /> 0 &nbsp; ;;; Masquerade WAN traffic<br /> &nbsp; &nbsp; chain=srcnat action=masquerade out-interface=ether1-VSAT Спасибо за помощь! <br />
			<i>03.01.2014 12:58:00, OwenITGuy.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/60614-trafik-iz-vlan-ne-maskiruetsya-na-wan_interfeyse./message231048</link>
			<guid>http://mikrotik.moscow/forum/forum57/60614-trafik-iz-vlan-ne-maskiruetsya-na-wan_interfeyse./message231048</guid>
			<pubDate>Fri, 03 Jan 2014 12:58:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
	</channel>
</rss>
