Tuesday, September 15, 2009

IP Addresses and ARP

1. IP Addressing
Submenu level: /ip address

Description

IP addresses serve for a general host identification purposes in IP networks. Typical (IPv4) address consists of four octets. For proper addressing the router also needs the network mask value, id est which bits of the complete IP address refer to the address of the host, and which - to the address of the network. The network address value is calculated by binary AND operation from network mask and IP address values. It's also possible to specify IP address followed by slash "/" and the amount of bits that form the network address.

In most cases, it is enough to specify the address, the netmask, and the interface arguments. The network prefix and the broadcast address are calculated automatically.

It is possible to add multiple IP addresses to an interface or to leave the interface without any addresses assigned to it. In case of bridging or PPPoE connection, the physical interface may bot have any address assigned, yet be perfectly usable. Putting an IP address to a physical interface included in a bridge would mean actually putting it on the bridge interface itself. You can use /ip address print detail to see to which interface the address belongs to.

MikroTik RouterOS has following types of addresses:

* Static - manually assigned to the interface by a user
* Dynamic - automatically assigned to the interface by DHCP or an estabilished PPP connections

Property Description
actual-interface (read-only: name) - name of the actual interface the logical one is bound to. For example, if the physical interface you assigned the address to, is included in a bridge, the actual interface will show that bridge.

address (IP address) - IP address

broadcast (IP address; default: 255.255.255.255) - broadcasting IP address, calculated by default from an IP address and a network mask

disabled (yes | no; default: no) - specifies whether the address is disabled or not

interface (name) - interface name the IP address is assigned to

netmask (IP address; default: 0.0.0.0) - delimits network address part of the IP address from the host part

network (IP address; default: 0.0.0.0) - IP address for the network. For point-to-point links it should be the address of the remote end

Notes

You cannot have two different IP addresses from the same network assigned to the router. Exempli gratia, the combination of IP address 10.0.0.1/24 on the ether1 interface and IP address 10.0.0.132/24 on the ether2 interface is invalid (unless both interfaces are bridged together), because both addresses belong to the same network 10.0.0.0/24. Use addresses from different networks on different interfaces.

Example

[admin@MikroTik] ip address> add address=10.10.10.1/24 interface=ether2
[admin@MikroTik] ip address> print
Flags: X - disabled, I - invalid, D - dynamic
# ADDRESS NETWORK BROADCAST INTERFACE
0 2.2.2.1/24 2.2.2.0 2.2.2.255 ether2
1 10.5.7.244/24 10.5.7.0 10.5.7.255 ether1
2 10.10.10.1/24 10.10.10.0 10.10.10.255 ether2
[admin@MikroTik] ip address>

2. Address Resolution Protocol
Submenu level: /ip arp

Description


Even though IP packets are addressed using IP addresses, hardware addresses must be used to actually transport data from one host to another. Address Resolution Protocol is used to map OSI level 3 IP addreses to OSI level 2 MAC addreses. Router has a table of currently used ARP entries. Normally the table is built dynamically, but to increase network security, it can be partialy or completely built statically by means of adding static entries.

Property Description

address (IP address) - IP address to be mapped

interface (name) - interface name the IP address is assigned to

mac-address (MAC address; default: 00:00:00:00:00:00) - MAC address to be mapped to

Notes

Maximal number of ARP entries is 8192.

If ARP feature is turned off on the interface, i.e., arp=disabled is used, ARP requests from clients are not answered by the router. Therefore, static arp entry should be added to the clients as well. For example, the router's IP and MAC addresses should be added to the Windows workstations using the arp command:

C:\> arp -s 10.5.8.254 00-aa-00-62-c6-09

If arp property is set to reply-only on the interface, then router only replies to ARP requests. Neighbour MAC addresses will be resolved using /ip arp statically, but there will be no need to add the router's MAC address to other hosts' ARP tables.

Example

[admin@MikroTik] ip arp> add address=10.10.10.10 interface=ether2 mac-address=06 \
\... :21:00:56:00:12
[admin@MikroTik] ip arp> print
Flags: X - disabled, I - invalid, H - DHCP, D - dynamic
# ADDRESS MAC-ADDRESS INTERFACE
0 D 2.2.2.2 00:30:4F:1B:B3:D9 ether2
1 D 10.5.7.242 00:A0:24:9D:52:A4 ether1
2 10.10.10.10 06:21:00:56:00:12 ether2
[admin@MikroTik] ip arp>

If static arp entries are used for network security on an interface, you should set arp to 'reply-only' on that interface. Do it under the relevant /interface menu:

[admin@MikroTik] ip arp> /interface ethernet set ether2 arp=reply-only
[admin@MikroTik] ip arp> print
Flags: X - disabled, I - invalid, H - DHCP, D - dynamic
# ADDRESS MAC-ADDRESS INTERFACE
0 D 10.5.7.242 00:A0:24:9D:52:A4 ether1
1 10.10.10.10 06:21:00:56:00:12 ether2

[admin@MikroTik] ip arp>

39 Comments:

喝酒 said...

初次造訪~安安^^ .........................................

如此的 said...

很喜歡你的blog哦...加油唷 ........................................

chat said...

人逢順境不逞強,身處逆境不示弱。........................................

智超 said...

天下沒有走不通的路,沒有克服不了的困難,沒有打不敗的敵人。..................................................

婉婷婉婷 said...

幸福是人人都要,又怎麼可能都歸你所有?要知道這世界幸福本來就不多........................................

婷妏 said...

It's great!!..........................................

嘉容嘉容 said...

驚悚故事分享,晚上別看哦
食人
計程車司機偶遇
恐怖電影生存指南

DesiraeF_Creech0709 said...

A contented mind is a perpetual feast. ....................................................

宛慧桓玲 said...

ut聊天77p2p85cc85st85街視訊視訊聊天ava片a片下載成人情色色情影音視訊聊天洪爺影城洪爺免費視訊免費a片免費一對多utsogo論壇ut聊天室成人片免費看................

上心 said...

你的部落格很棒,我期待更新喔........................................

郁財郁財 said...

I like your blog................................

CyrusD_Ar淑福 said...

請繼續發表好文!加油加油加油!.............................................

HaroldM22 said...

xh美色網 免費a片下載嘟嘟情人色網影片 av,sex520免費影片 完全免費視訊聊天 777美女dvd辣妹視訊 免費視訊celia aio交友視訊愛情館 西門慶成人論壇 台中酒店S援交 sex888影片分享區高中生援交 一葉情貼影片區 1314視訊 情人線上aa片試看嘟嘟 情人視訊網a 妹妹視訊 情色網成人電影 xxxholic次元魔女 成人文學小弟弟貼影片區 亞亞成人館 ut成人聊天室 微風成人 go2av免費看影片 104黑色會美眉自慰 日本同志色教館情色文學成人小說 34c視訊辣妹美女sex888免費電影 情色視訊論壇 0204貼圖區免費色情電影 成人貼圖站 交友ggo 免費影片下載a gogo2sex日本 拓網交友視訊美女 080情人網伊利論壇 一本道 a片 東京熱免費成人影片觀賞 交友ggoo 夜未眠影片中心 34c情人視訊網 一夜情性 情色視訊 美女 亞洲禁果名模影城 日本av論壇 台南視訊34c美女館 bt論壇交友網成人情色視訊妹 免費情人視訊 性愛電影85cc 聊天室交友whei 38girl視訊美女 aa免費影片 獨秀視訊聊天室 av730美眉共國 辣妹哈啦聊天室

DaniloM_Wolff0正玲 said...

人不能像動物一樣活著,而應該追求知識和美德..................................................

廖淑凡 said...

The more haste, the less speed. ............................................................

batesda said...

人有兩眼一舌,是為了觀察倍於說話的緣故。............................................................

孝齊孝齊 said...

思想與理論,貴呼先於行動,但行動較思想或理論更高貴......................................................................

玫友 said...

真是太有道理了~~我支持你~~~.................................................................

陳芳 said...

一棵樹除非在春天開了花,否則難望在秋天結果。....................................................................

峻龍 said...

良言一句三冬暖,惡語傷人六月寒。....................................................................

皇銘 said...

成熟,就是有能力適應生活中的模糊。.................................................................

王名仁 said...

人有兩眼一舌,是為了觀察倍於說話的緣故。............................................................

葉瑞 said...

It takes all kinds to make a world.............................................................

珮陽 said...

A bad workman quarrels with his tools...................................................................

原秋原秋 said...

很喜歡看看別人的生活故事,謝謝您的分享哦~~............................................................

宛真宛真 said...

精彩的部落格 要繼續加油 ..................................................................

曾法幸 said...

期待新的內容 感謝你.................................[/url]...............

幸雨幸雨 said...

只要有心,人人可以是熱門blog!!!............................................................

莊雅和莊雅和莊雅和 said...

生活很多細節都要小心點,請多保重 ..................................................

吳淑芬吳淑芬 said...

認識自己,是發現妳的真性格、掌握妳的命運、創照你前程的根源。.......................................................

于劉辰原蔡毓 said...

Make hay while the sun shines.............................................................

亦奈美妮 said...

人並不是生來要吃敗仗的。人可被毀滅,但不可被擊倒。..................................................................

偉曹琬 said...

做些小善事,說些愛的字句,世界更快樂。..................................................

允黃淑 said...

人生是故事的創造與遺忘。............................................................

張王雅竹欣虹 said...

生存乃是不斷地在內心與靈魂交戰;寫作是坐著審判自己。. . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

孫邦柔 said...

祝福大家開開心心。............................................................

洪勳劉耀德劉耀德華 said...

Subtlety is better than force. ......................................................................

黃英吳思潔吳思潔邦 said...

加油!!! 很棒的分享~

MIKROTIK SOLUsi said...

Abyfine
tanks blog walking