Ethernet over IP (EoIP) Tunneling is a MikroTik RouterOS protocol based on GRE RFC 1701 that creates an Ethernet tunnel between two routers on top of an IP connection. The EoIP tunnel may run over IPIP tunnel, PPTP tunnel, or any other connection capable of transporting IP.
When the bridging function of the router is enabled, all Ethernet traffic (all Ethernet protocols) will be bridged just as if there where a physical Ethernet interface and cable between the two routers (with bridging enabled). This protocol makes multiple network schemes possible.
Network setups with EoIP interfaces:
The EoIP protocol encapsulates Ethernet frames in GRE (IP protocol number 47) packets (just like PPTP) and sends them to the remote side of the EoIP tunnel.
|arp (disabled | enabled | proxy-arp | reply-only; Default: enabled)||Address Resolution Protocol mode.|
|clamp-tcp-mss (yes | no; Default: yes)||Controls whether to change MSS size for received TCP SYN packets. When enabled, a router will change the MSS size for received TCP SYN packets if the current MSS size exceeds the tunnel interface MTU (taking into account the TCP/IP overhead).The received encapsulated packet will still contain the original MSS, and only after decapsulation the MSS is changed.|
|dont-fragment (inherit | no; Default: no)|
|dscp (integer: 0-63; Default: inherited)||DSCP value of packet. Inherited option means that dscp value will be inherited from packet which is going to be encapsulated.|
|ipsec-secret (string; Default: )||When secret is specified, router adds dynamic ipsec peer to remote-address with pre-shared key and policy with default values (by default phase2 uses sha1/aes128cbc).|
|keepalive (integer[/time],integer 0..4294967295; Default: 10s,10)||Tunnel keepalive parameter sets the time interval in which the tunnel running flag will remain even if the remote end of tunnel goes down. If configured time,retries fail, interface running flag is removed. Parameters are written in following format: |
|l2mtu (integer; read-only)||Layer2 Maximum transmission unit. Not configurable for EoIP. MTU in RouterOS|
|local-address (IP; Default: )||Source address of the tunnel packets, local on the router.|
|mac-address (MAC; Default: )||Media Access Control number of an interface. The address numeration authority IANA allows the use of MAC addresses in the range from 00:00:5E:80:00:00 - 00:00:5E:FF:FF:FF freely|
|mtu (integer; Default: auto)||Layer3 Maximum transmission unit|
|name (string; Default: )||Interface name|
|remote-address (IP; Default: )||IP address of remote end of EoIP tunnel|
|tunnel-id (integer: 65536; Default: )||Unique tunnel identifier, which must match other side of the tunnel|
Parameter tunnel-id is a method of identifying a tunnel. It must be unique for each EoIP tunnel.
When bridging EoIP tunnels, it is highly recommended to set unique MAC addresses for each tunnel for the bridge algorithms to work correctly. For EoIP interfaces you can use MAC addresses that are in the range from 00:00:5E:80:00:00 - 00:00:5E:FF:FF:FF , which IANA has reserved for such cases. Alternatively, you can set the second bit of the first byte to modify the auto-assigned address into a 'locally administered address', assigned by the network administrator, and thus use any MAC address, you just need to ensure they are unique between the hosts connected to one bridge.
Let us assume we want to bridge two networks: 'Office LAN' and 'Remote LAN'. By using EoIP setup can be made so that Office and Remote LANs are in the same Layer2 broadcast domain.
Consider the following setup:
As you know wireless stations cannot be bridged, to overcome this limitation (not involving WDS) we will create an EoIP tunnel over the wireless link and bridge it with interfaces connected to local networks.
We will not cover wireless configuration in this example, let's assume that the wireless link is already established.
At first, we create an EoIP tunnel on our gateway:
Next, we will bridge local interfaces with EoIP tunnel on our GW:
Now both sites are in the same Layer2 broadcast domain. You can set up IP addresses from the same network on both sites.