<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title>Mikrotik.moscow [тема: Как назначить публичный IP-адрес серверу без NAT?]</title>
		<link>http://mikrotik.moscow</link>
		<description>Новое в теме Как назначить публичный IP-адрес серверу без NAT? форума RouterOS на сайте Mikrotik.moscow [mikrotik.moscow]</description>
		<language>ru</language>
		<docs>http://backend.userland.com/rss2</docs>
		<pubDate>Mon, 17 Aug 2026 09:57:06 -0400</pubDate>
		<item>
			<title>Как назначить публичный IP-адрес серверу без NAT?</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/68547-kak-naznachit-publichnyy-ip_adres-serveru-bez-nat/message269087">Как назначить публичный IP-адрес серверу без NAT?</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Пожалуйста, свяжитесь со мной по адресу ниже с подробностями, чтобы я мог посмотреть, как они промаршрутировали /29. <br />
			<i>06.12.2013 20:43:00, CelticComms.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/68547-kak-naznachit-publichnyy-ip_adres-serveru-bez-nat/message269087</link>
			<guid>http://mikrotik.moscow/forum/forum57/68547-kak-naznachit-publichnyy-ip_adres-serveru-bez-nat/message269087</guid>
			<pubDate>Fri, 06 Dec 2013 20:43:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Как назначить публичный IP-адрес серверу без NAT?</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/68547-kak-naznachit-publichnyy-ip_adres-serveru-bez-nat/message269086">Как назначить публичный IP-адрес серверу без NAT?</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Я последовал твоей рекомендации и изменил запись в таблице адресов: 100.100.100.217/29 100.100.100.100.216 ether1-wan на 100.100.100.217/29 100.100.100.100.216 bridge-wan. Две проблемы: я все еще могу пинговать с хоста 100.100.100.220 (Asterisk box) во внешний мир, но DNS не работает, и TCP-соединения к google.ca не устанавливаются. При запуске netstat на хосте 220, TCP-соединения к IP-адресу Google показывают состояние SYN-SENT. Когда я делаю traceroute до 100.100.100.220 извне, маршрут показывает, что мой провайдер выбирает адрес pppoe-шлюза вместо "правильного" шлюза к моей сети 100.100.100.216/29. Неужели мне нужно отдельные записи для каждого IP-адреса (т.е. 100.100.100.217/32, 100.100.100.218/32, 100.100.100.219/32, 100.100.100.220/32 и т.д.)? <br />
			<i>06.12.2013 18:02:00, red6.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/68547-kak-naznachit-publichnyy-ip_adres-serveru-bez-nat/message269086</link>
			<guid>http://mikrotik.moscow/forum/forum57/68547-kak-naznachit-publichnyy-ip_adres-serveru-bez-nat/message269086</guid>
			<pubDate>Fri, 06 Dec 2013 18:02:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Как назначить публичный IP-адрес серверу без NAT?</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/68547-kak-naznachit-publichnyy-ip_adres-serveru-bez-nat/message269085">Как назначить публичный IP-адрес серверу без NAT?</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Если используете bridge, то IP-адрес/маску роутера лучше указать на самом bridge, а не на одном из интерфейсов bridge port. Поэтому перенесите настройки /29 на bridge и сообщите о результатах. <br />
			<i>06.12.2013 16:44:00, CelticComms.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/68547-kak-naznachit-publichnyy-ip_adres-serveru-bez-nat/message269085</link>
			<guid>http://mikrotik.moscow/forum/forum57/68547-kak-naznachit-publichnyy-ip_adres-serveru-bez-nat/message269085</guid>
			<pubDate>Fri, 06 Dec 2013 16:44:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Как назначить публичный IP-адрес серверу без NAT?</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/68547-kak-naznachit-publichnyy-ip_adres-serveru-bez-nat/message269084">Как назначить публичный IP-адрес серверу без NAT?</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Я новичок в Mikrotik… Пытаюсь добиться тех же результатов, что и в теме, но на новой коробке RB2011 integrated. У меня работает 1:1 NAT для хоста Asterisk. Но мне также нужно развернуть хост Asterisk напрямую на публичном IP. Я объединил порт wan (ether1) с выделенным ethernet-портом (ether2) и назначил IP из моего используемого диапазона /29 от моего провайдера хосту Asterisk. Моя локальная сеть на ether3. (ether4 и ether5 являются подчиненными ether3). Хост может получить доступ к интернету с помощью ping, например, до Google, так что, похоже, шлюз настроен правильно на хосте. Кроме того, я могу "ping" или "traceroute -I" до хоста извне, но не могу настроить сеансы ssh или http до хоста. Вот часть моей конфигурации, которая, вероятно, очень важна для отладки… У меня есть статический PPPoE адрес и шлюз, а мой модем находится в режиме bridged. Затем мне выдали 100.100.100.216/29 от моего провайдера для того, что я называю моей «реальной» интернет-сетью. Мне кажется, что PPPoE используется только для аутентификации, потому что мой провайдер является реселлером и вынужден использовать PPPoE для своих DSL-установок. ether1 — это wan-соединение к DSL bridged модему pppoe-out1 — это логическое wan-соединение (если "логический" — это правильный термин?) ether3-lan-private-master — это мой lan-порт (ether 4 и ether 5 являются подчиненными) ether6 и далее и оптический интерфейс отключены пока что /ip address&gt; print<br />Флаги: X - отключен, I - недействителен, D - динамический <br /> &nbsp;# &nbsp; ADDRESS &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; NETWORK &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; INTERFACE &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<br /> &nbsp;0 &nbsp; 192.168.88.1/24 &nbsp; &nbsp; &nbsp;192.168.88.0 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ether3-lan-private-master &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<br /> &nbsp;1 D 200.200.200.70/32 &nbsp;200.20.150.100 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;pppoe-out1 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <br /> &nbsp;2 &nbsp; 100.100.100.217/29 100.100.100.216 &nbsp; ether1-wan<br /><br /><br />Это просто локальные хосты в ether3:<br />/ip arp&gt; print<br />Флаги: X - отключен, I - недействителен, H - DHCP, D - динамический, P - опубликован <br /> &nbsp;# &nbsp; ADDRESS &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; MAC-ADDRESS &nbsp; &nbsp; &nbsp; &nbsp;INTERFACE &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <br /> &nbsp;0 D 192.168.88.239 &nbsp;00:0B:XX:XX:65:6B &nbsp;ether3-lan-private-master &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <br /> &nbsp;1 D 192.168.88.240 &nbsp;BC:AE:XX:XX:F2:65 &nbsp;ether3-lan-private-master &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <br /> &nbsp;2 D 192.168.88.241 &nbsp;14:DA:XX:XX:B4:BA &nbsp;ether3-lan-private-master &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <br /> &nbsp;3 D 192.168.88.248 &nbsp;BC:5F:XX:XX:94:B7 &nbsp;ether3-lan-private-master &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <br /> &nbsp;4 D 192.168.88.246 &nbsp;3E:D6:XX:XX:93:56 &nbsp;ether3-lan-private-master &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <br /> &nbsp;5 D 192.168.88.237 &nbsp;C8:A0:XX:XX:D7:9D &nbsp;ether3-lan-private-master<br /><br />Моя таблица интерфейсов:<br /> /interface&gt; print<br />Флаги: D - динамический, X - отключен, R - работающий, S - подчиненный <br /> &nbsp;# &nbsp; &nbsp; NAME &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;TYPE &nbsp; &nbsp; &nbsp; &nbsp; MTU L2MTU &nbsp;MAX-L2MTU MAC-ADDRESS &nbsp; &nbsp; &nbsp;<br /> &nbsp;0 &nbsp;RS ether1-wan &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;ether &nbsp; &nbsp; &nbsp; 1500 &nbsp;1598 &nbsp; &nbsp; &nbsp; 4074 D4:CA:6D:X7:7X:8A<br /> &nbsp;1 &nbsp;RS ether2-lan-public &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ether &nbsp; &nbsp; &nbsp; 1500 &nbsp;1598 &nbsp; &nbsp; &nbsp; 4074 D4:CA:6D:X7:7X:8B<br /> &nbsp;2 &nbsp;R &nbsp; ether3-lan-private-maste &nbsp; &nbsp; &nbsp;ether &nbsp; &nbsp; &nbsp; 1500 &nbsp;1598 &nbsp; &nbsp; &nbsp; 4074 D4:CA:6D:X7:7X:8C<br /> &nbsp;3 &nbsp; S &nbsp;ether4 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ether &nbsp; &nbsp; &nbsp; 1500 &nbsp;1598 &nbsp; &nbsp; &nbsp; 4074 D4:CA:6D:X7:7X:8D<br /> &nbsp;4 &nbsp; S &nbsp;ether5 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ether &nbsp; &nbsp; &nbsp; 1500 &nbsp;1598 &nbsp; &nbsp; &nbsp; 4074 D4:CA:6D:X7:7X:8E<br /> &nbsp;5 &nbsp;X &nbsp; ether6-master-local &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ether &nbsp; &nbsp; &nbsp; 1500 &nbsp;1598 &nbsp; &nbsp; &nbsp; 2028 D4:CA:6D:X7:7X:8F<br /> &nbsp;6 &nbsp;XS ether7-slave-local &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;ether &nbsp; &nbsp; &nbsp; 1500 &nbsp;1598 &nbsp; &nbsp; &nbsp; 2028 D4:CA:6D:X7:7X:90<br /> &nbsp;7 &nbsp;XS ether8-slave-local &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;ether &nbsp; &nbsp; &nbsp; 1500 &nbsp;1598 &nbsp; &nbsp; &nbsp; 2028 D4:CA:6D:X7:7X:91<br /> &nbsp;8 &nbsp;XS ether9-slave-local &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;ether &nbsp; &nbsp; &nbsp; 1500 &nbsp;1598 &nbsp; &nbsp; &nbsp; 2028 D4:CA:6D:X7:7X:92<br /> &nbsp;9 &nbsp;XS ether10-slave-local &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;ether &nbsp; &nbsp; &nbsp; 1500 &nbsp;1598 &nbsp; &nbsp; &nbsp; 2028 D4:CA:6D:X7:7X:93<br /> 10 &nbsp;X &nbsp;sfp1-gateway &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;ether &nbsp; &nbsp; &nbsp; 1500 &nbsp;1598 &nbsp; &nbsp; &nbsp; 4074 D4:CA:6D:X7:7X:89<br /> 11 &nbsp;X &nbsp;wlan1 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; wlan &nbsp; &nbsp; &nbsp; &nbsp;1500 &nbsp;2290 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;D4:CA:6D:X7:7X:94<br /> 12 &nbsp;R &nbsp;bridge-wan &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;bridge &nbsp; &nbsp; &nbsp;1500 &nbsp;1598 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;D4:CA:6D:X7:7X:8A<br /> 13 &nbsp;R &nbsp;pppoe-out1 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;pppoe-out &nbsp; 1480<br /><br />Мой так называемый wan bridge:<br />/interface bridge&gt; print<br />Флаги: X - отключен, R - работающий <br /> &nbsp;0 &nbsp;R name="bridge-wan" mtu=1500 l2mtu=1598 arp=enabled mac-address=D4:CA:6D:X7:7X:8A protocol-mode=none priority=0x8000 auto-mac=yes <br /> &nbsp; &nbsp; &nbsp;admin-mac=00:00:00:00:00:00 max-message-age=20s forward-delay=15s transmit-hold-count=6 ageing-time=5m <br /><br />Члены моего wan bridge:<br />/interface bridge port&gt; print<br />Флаги: X - отключен, I - неактивен, D - динамический <br /> &nbsp;# &nbsp; &nbsp;INTERFACE &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; BRIDGE &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; PRIORITY &nbsp;PATH-COST &nbsp; &nbsp;HORIZON<br /> &nbsp;0 &nbsp; &nbsp;ether1-wan &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;bridge-wan &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0x80 &nbsp; &nbsp; &nbsp; &nbsp; 10 &nbsp; &nbsp; &nbsp; none<br /> &nbsp;1 &nbsp; &nbsp;ether2-lan-public &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; bridge-wan &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0x80 &nbsp; &nbsp; &nbsp; &nbsp; 10 &nbsp; &nbsp; &nbsp; none<br /><br />Важны ли таблицы Firewall NAT и FILTER?<br />Вот часть цепочки forward, которая, как я думал, была необходима как указано в этой теме…<br /><br />add chain=forward comment="Open up bridge port ether-public-lan" connection-state=new in-bridge-port=ether1-wan out-bridge-port=\<br /> &nbsp; &nbsp;ether2-lan-public<br />add chain=forward comment="Open up bridge port ether-public-lan" connection-state=established in-bridge-port=ether1-wan \<br /> &nbsp; &nbsp;out-bridge-port=ether2-lan-public<br />add chain=forward comment="Open up bridge port ether-public-lan" connection-state=related in-bridge-port=ether1-wan out-bridge-port<br /> &nbsp; &nbsp;ether2-lan-public Я что-то упускаю из виду, что-то очевидное и фундаментальное. И что любопытно, ICMP работает. Помощь была бы очень признательна. <br />
			<i>05.12.2013 17:12:00, red6.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/68547-kak-naznachit-publichnyy-ip_adres-serveru-bez-nat/message269084</link>
			<guid>http://mikrotik.moscow/forum/forum57/68547-kak-naznachit-publichnyy-ip_adres-serveru-bez-nat/message269084</guid>
			<pubDate>Thu, 05 Dec 2013 17:12:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Как назначить публичный IP-адрес серверу без NAT?</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/68547-kak-naznachit-publichnyy-ip_adres-serveru-bez-nat/message269083">Как назначить публичный IP-адрес серверу без NAT?</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Я обычно не рекомендую метод с использованием loopback-адреса, так как он зависит от ОС роутера/хоста и его трудно отладить, если что-то идёт не так. Похоже, что предлагалось использовать версию с приватным линк-нете, в этом случае роутербоарду нужно добавить маршрут к публичному адресу сервера в формате A.B.C.D/32, а шлюзом указать приватный LAN-адрес сервера. Разумеется, это предполагает, что вы создали приватную подсеть между роутером и сервером и что у них обоих есть валидные приватные IP-адреса в этой подсети. Единственная другая проблема в том, что ваш провайдер скорее всего ожидает, что все эти публичные IP-адреса будут ARPable в сегменте WAN, поэтому вам, скорее всего, придётся использовать proxy-arp на интерфейсе WAN. <br />
			<i>25.02.2013 22:14:00, CelticComms.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/68547-kak-naznachit-publichnyy-ip_adres-serveru-bez-nat/message269083</link>
			<guid>http://mikrotik.moscow/forum/forum57/68547-kak-naznachit-publichnyy-ip_adres-serveru-bez-nat/message269083</guid>
			<pubDate>Mon, 25 Feb 2013 22:14:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Как назначить публичный IP-адрес серверу без NAT?</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/68547-kak-naznachit-publichnyy-ip_adres-serveru-bez-nat/message269082">Как назначить публичный IP-адрес серверу без NAT?</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Во-первых, если я правильно понял, то тебе уже советовали сделать то, что оказалось не лучшим решением. Поскольку ты получаешь от провайдера только 5 адресов из /29, а не весь блок /29, направляемый в твой маршрутизатор, назначь публичный IP-адрес 200.190.xxx.123 напрямую к интерфейсу ether веб-сервера. &nbsp;Свяжи ether2 и ether6 с бриджем.<br /><br />`/interface bridge`<br />`add name="bridge-public"`<br />`/interface bridge port`<br />`add bridge="bridge-public" interface=ether2`<br />`add bridge="bridge-public" interface=ether6`<br /><br />Тебе нужно защитить веб-сервер. Если ты не собираешься защищать его с помощью iptables прямо на веб-сервере, включи брандмауэр на маршрутизаторе для бриджей и принимай входящие соединения на порт 200.190.xxx.123 (плюс любые другие, которые тебе понадобятся), а всё остальное, что не требуется, блокируй. Блокировать исходящий трафик с веб-сервера не обязательно.<br /><br />`/interface bridge settings set use-ip-firewall=yes`<br />`/ip firewall filter`<br />`add chain=forward in-bridge-port=ether2 out-bridge-port=ether6 protocol=tcp dst-port=80,443 action=accept`<br />`add chain=forward in-bridge-port=ether2 out-bridge-port=ether6 action=drop`<br /><br />Маршрутизация на MT не требуется. Тебе стоит удалить настройку NAT и 10.1.1.0/24, которую ты ранее применил к ether6. <br />
			<i>25.02.2013 20:59:00, jgellis.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/68547-kak-naznachit-publichnyy-ip_adres-serveru-bez-nat/message269082</link>
			<guid>http://mikrotik.moscow/forum/forum57/68547-kak-naznachit-publichnyy-ip_adres-serveru-bez-nat/message269082</guid>
			<pubDate>Mon, 25 Feb 2013 20:59:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Как назначить публичный IP-адрес серверу без NAT?</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/68547-kak-naznachit-publichnyy-ip_adres-serveru-bez-nat/message269081">Как назначить публичный IP-адрес серверу без NAT?</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Привет. Вот какая ситуация: у меня оптоволоконное подключение с 5 публичными IP-адресами и Mikrotik rb1200. Один из них используется для моей локальной сети. Порт 2 — там подключен LINK. Порты ether1, ether3, ether4 и ether5 работают как коммутатор с DHCP-сервером, который выдаёт IP-адреса из диапазона 192.168.55.0/24. Для всех этих портов я использую всего один публичный IP. Допустим, это 200.190.xxx.122. Я добавил сервер с Apache на ether6 и хочу назначить ему публичный IP-адрес (допустим, 200.190.xxx.123), но без NAT. Я уже смог заставить это работать, перенаправляя запросы с помощью NAT. Но я хочу другой способ. Приватный диапазон IP-адресов, назначенный ether6, — 10.1.1.0/24, а приватный IP-адрес сервера — 10.1.1.9. На другом форуме кто-то посоветовал вот что: назначить публичный IP-адрес серверу в качестве loopback IP (не связан с каким-либо интерфейсом), настроить маршрутизатор для маршрутизации трафика к этому публичному IP-адресу на внутренний IP-адрес сервера (просто добавить один статический маршрут), убедиться, что маршрутизатор настроен для пропуска исходящего трафика без ограничений (не предполагать, что весь трафик из внутренней сети имеет внутренний исходный IP-адрес или просто добавить правило для маршрутизации трафика из внутренней LAN с этим конкретным исходным IP-адресом). Ну. Я смог назначить публичный IP-адрес, который хочу использовать, как loopback IP. Тогда, если я ввожу его в браузере на компьютере, где работает Apache, страница открывается. Что я не знаю, так это как сделать следующее: настроить маршрутизатор для маршрутизации трафика к этому публичному IP-адресу на внутренний IP-адрес сервера и «убедиться, что маршрутизатор настроен для пропуска исходящего трафика без ограничений», и человек, ответивший на это, больше не отвечал. Может ли кто-нибудь помочь? Я совсем новичок в Mikrotik, так что, пожалуйста, пишите чётко, где настраивать, например "ip &gt; routes" и т.д. Спасибо. <br />
			<i>25.01.2013 15:39:00, valters.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/68547-kak-naznachit-publichnyy-ip_adres-serveru-bez-nat/message269081</link>
			<guid>http://mikrotik.moscow/forum/forum57/68547-kak-naznachit-publichnyy-ip_adres-serveru-bez-nat/message269081</guid>
			<pubDate>Fri, 25 Jan 2013 15:39:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
	</channel>
</rss>
