No description
  • RouterOS Script 100%
Find a file
Mark Hahl 20aba55ce8 Sync router-165e to live config with naming cleanup and TEMP LAN SNAT.
Align config.rsc with the 2026-08-12 export, adopt cbr-* comment taxonomy,
and temporarily masquerade all LAN-NET prefixes (with CEPH/LAB→WAN accept)
while documenting the return to SHARED-only internet policy.
2026-08-12 12:16:51 +10:00
devices/router-165e Sync router-165e to live config with naming cleanup and TEMP LAN SNAT. 2026-08-12 12:16:51 +10:00
docs/diagrams birth 2026-07-23 15:00:07 +10:00
.gitignore birth 2026-07-23 15:00:07 +10:00
README.md Sync router-165e to live config with naming cleanup and TEMP LAN SNAT. 2026-08-12 12:16:51 +10:00

CBR GPS Lab Network Configuration

Source of truth for lab edge routing and segmentation — Canberra (CBR) GPS Lab (gpslab.cbr.redhat.com).

RouterOS 7 configs are intended to be imported on the target devices.

Resource Path
Router config devices/router-165e/config.rsc
Diagrams (source) docs/diagrams/lab.drawio
Overview PNG docs/diagrams/lab-overview.png
Connections PNG docs/diagrams/lab-connections.png

Core device

Device Role Identity OS
router-165e L3 gateway, DHCP, DNS, NTP, webproxy, VLAN edge router-165e.gpslab.cbr.redhat.com RouterOS 7.23.2

Network architecture

Edge path

Internet
   │
Corporate Switch  (Red Hat corp / lab uplink)
   │  ether1-wan  ·  10.76.23.0/24  ·  untagged → VLAN 23
   ▼
MikroTik router  (bridge-core, VLAN filtering)
   │  bond1-trunk (LACP) · all lab VLANs + corp VLAN 23
   ▼
Fabric switches  →  blades / hypervisors / shared infra
  • Corp path: ether1-wan is a bridge access port PVID 23 (untagged from corp switch). L3 is on vlan23-redhat (10.76.23.1/24). VLAN 23 is tagged on bond1-trunk for hypervisors.
  • Default route: 0.0.0.0/0 via 10.76.23.254 (via vlan23 connected route).
  • Security: guests on VLAN 23 share corp L2 and bypass the zone filter for pure L2 traffic.

VLANs (router authoritative)

VLAN Zone Interface Prefix Direct internet Egress method
10 SHARED vlan10-shared 172.16.10.0/24 Yes Routed + SNAT
11 CEPH-PUBLIC vlan11-ceph-public 172.16.11.0/24 TEMP Yes SNAT now; target = webproxy :8080 only
12 CEPH-PRIVATE vlan12-ceph-private 172.16.12.0/24 TEMP Yes SNAT now; target = webproxy :8080 only
13 LAB vlan13-lab 172.16.13.0/24 TEMP Yes SNAT now; target = webproxy :8080 only
23 WAN (corp) vlan23-redhat 10.76.23.0/24 .100–.200 (+ .220–.230 HTTPClient) Untagged on ether1; tagged on fabric trunk

Diagram prefixes (10.0.x, 192.168.x) may differ; map by role. Internal Alpha/Gamma (OCP-Virt) are not on this router.


Internet policy

TEMPORARY (will change): All lab zones (LAN-NET = 172.16.10–13.0/24) may reach WAN with masquerade out vlan23-redhat. Filter rules and NAT comments end in TEMP / cbr-nat-lan-to-wan-TEMP. Target: only SHARED keeps direct internet; LAB/CEPH reject WAN and use HTTP proxy :8080.

From zone To WAN (internet/corp IP) Notes
SHARED Allow Permanent intent; SNAT with other LAN zones for now
LAB Allow (TEMP) Will revert to reject + webproxy
CEPH-PUBLIC Allow (TEMP) Will revert to reject + webproxy
CEPH-PRIVATE Allow (TEMP) Will revert to reject + webproxy
WAN → SHARED / LAB / CEPH Allow Corp can reach all lab zones (direct L3)
WAN → LOCAL SOCKS Allow TCP 1080 (/ip socks) → relay into all internals

Web proxy (disconnected zones)

Router runs explicit HTTP proxy on TCP 8080 (/ip proxy).

  • Allowed from all LAN zones to LOCAL (with DNS/NTP/ICMP).
  • Point clients at any zone gateway, e.g.:
    • Lab: http://172.16.13.1:8080
    • Ceph public: http://172.16.11.1:8080
    • Or shared SVI: http://172.16.10.1:8080
  • HTTPS typically needs CONNECT via the same proxy (browser/system proxy settings).
  • This is not transparent redirect; apps must be configured (or use a PAC/WPAD later).

Proxy outbound uses the router’s own WAN path (LOCAL → WAN allowed). After TEMP LAN SNAT is removed, non-HTTP from LAB/CEPH again has no general internet path except proxy.

SOCKS proxy (corp / WAN)

Router runs SOCKS on TCP 1080 (/ip socks).

  • Firewall: WAN → LOCAL accepts tcp/1080; SOCKS relay is router-originated (LOCAL → all zones accepted).
  • Point clients at corp SVI, e.g. socks5://10.76.23.1:1080 (or the address you use on vlan23).
  • Use for corp clients that need reachability into SHARED / CEPH / LAB without full routing on the client.
  • Access rule (live): Sydney VPN 10.64.136.0/23 may use SOCKS toward lab 172.16.0.0/16 tcp/22.

Physical / LACP & pending SFP hardware

              │   MikroTik Router
              │   bond1-trunk (802.3ad LACP)
              │     INTERIM: ether3 + ether4
              │     TARGET:  sfp1 + sfp2  (waiting on SFP modules)
              └────────────┬────────────┘
                           │
                    Fabric (switches)
Item Status
SFP modules Not installed yet — waiting on hardware
Interim bond slaves ether3-trunk (disabled on live) + ether4-trunk
Target (diagrams) SFP ports as bond members once modules arrive
Bond settings mode=802.3ad, lacp-rate=1sec, transmit-hash-policy=layer-2-and-3, mtu=9000
Jumbo ether2/3/4 mtu=9004; bond mtu=9000; all SVIs mtu=9000 (no manual L2MTU)
Peer requirement One LACP domain (same switch, stack, or MLAG). Dual independent switches without MLAG will not work with 802.3ad

When SFPs arrive: rename/configure SFP ports, set slaves= on bond1-trunk to the SFP interfaces, free ether3/4, match LAG on the fabric switches.


Address lists

List Members Use
SHARED-NET 172.16.10.0/24 Shared policy; target SNAT source
CEPH-PUBLIC-NET 172.16.11.0/24 Future rules
CEPH-PRIVATE-NET 172.16.12.0/24 Future rules
LAB-NET 172.16.13.0/24 Future rules
WAN-NET 10.76.23.0/24 Corp prefix
LAN-NET all 172.16.10–13.0/24 TEMP SNAT source (cbr-nat-lan-to-wan-TEMP)
DISCONNECTED-NET 172.16.11–13.0/24 Target: zones without direct internet

Zone firewall (summary)

Structure (RouterOS sequential filter):

  1. Connection tracking (accept established/related, fasttrack, drop invalid)
  2. Policy chains zone-<FROM>-to-<TO>-v4 / *-to-LOCAL / LOCAL-to-*
  3. Jump table on input / output / forward by interface-list
  4. Default reject on input/forward (log=no); accept residual output
Zone → LOCAL Policy
SHARED DNS, NTP, DHCP, proxy, ICMP, SSH, WinBox, WebFig + accept remainder
LAB / CEPH-* DNS, NTP, DHCP, proxy :8080, ICMP only; then reject
WAN (corp, trusted) DHCP 67, WinBox 8291, WebFig 80/443, SOCKS 1080, RDP 3389, ICMP; else reject

Managed objects use comment (or name=) prefix cbr- for cleanup:

Prefix Objects
cbr-ether-* / cbr-bond-* / cbr-bridge* L2
cbr-vlan-if-* / cbr-zonelist-* / cbr-zone-* SVIs + zone lists
cbr-addr-* / cbr-route-* / cbr-pool-* / cbr-dhcp-* Addressing + DHCP
cbr-dns-* / cbr-ntp-* / cbr-socks-* / cbr-ipv6-* Services
cbr-alist-* / cbr-fw-* / cbr-nat-* Firewall / NAT

Config organization

Section Contents
SYSTEM Identity, clock, DNS, NTP, /ip service (telnet/ftp/api off)
L2 Ethernet (SFP interim), bond, bridge, ports, VLANs (explicit ports — no interface lists)
L3 SVIs, zone interface-list membership (firewall only)
ADDRESSING & ROUTING IPs, default route
SERVICES & DHCP Webproxy, SOCKS, pools (incl. HTTPClient / RHOSO discovery ISO), servers, matcher
DNS static *.rhlab.local / RHOSO names → lab / corp hosts
FIREWALL PREP Address lists
FIREWALL Zone filter (log=no defaults); jumps use zone interface-lists
NAT TEMP: LAN-NET → masquerade out vlan23-redhat (cbr-nat-lan-to-wan-TEMP); target SHARED-only

Deployment

Prefer serial/OOB access. Objects are not fully idempotent — clean cbr- tags before re-import if needed:

/ip/firewall/filter/remove [find comment~"cbr-"]
/ip/firewall/nat/remove [find comment~"cbr-"]
/ip/firewall/address-list/remove [find comment~"cbr-"]
/import file-name=config.rsc

Live notes (export 2026-08-12 + local edits)

  • HTTPClient bootfile (opt 67): http://10.76.23.5/images/discovery_image_rhoso.iso (cbr-dhcp-opt-bootfile-rhoso)
  • No DHCP server/pool on CEPH-PRIVATE (172.16.12.0/24 still has SVI + dhcp-network for docs/static)
  • VLAN 23 hybrid: untagged ether1 + tagged bond1; L2 fabric hosts must appear on bond1 vid=23 to reach corp .254
  • IPv6: DHCPv6 client on ether1-wan (prefer SVI later)
  • TEMP internet: all LAN-NET masq + CEPH/LAB→WAN accept (*-TEMP); revert to SHARED-only later

Known gaps

  • Diagram address plan vs 172.16.x still needs reconciliation
  • Internal Alpha/Gamma VLANs not on router
  • /ip service has no address= CIDR lock yet (zone filter is primary)
  • SFP modules pending — bond is interim copper (ether3 disabled; ether4 active)
  • Fabric switch LAG/MLAG config not in this repo
  • No WPAD/PAC auto-proxy yet (clients must be configured manually)
  • IPv6 firewall not configured; DHCPv6 on bridge slave is interim
  • HTTPClient DHCP matcher may need exact option-60 string from clients