Community discussions

MikroTik App

Search found 87 matches

by ehbowen
Fri Aug 23, 2024 3:47 am
Forum: General
Topic: Feature requests
Replies: 1767
Views: 663163

Re: Feature requests: Randomize IPv6 addresses (Opt out of SLACC)

Karl Denninger, who was one of the pioneers in bringing Internet to personal use, just posted a recommendation for users to randomize their IPv6 addresses on Wi-fi (via OS settings) since the standard SLACC protocol for assigning IP addresses results in a globally-unique identifier for each machine,...
by ehbowen
Mon Aug 05, 2024 5:38 am
Forum: General
Topic: Inbound Proxy?
Replies: 3
Views: 554

Re: Inbound Proxy?

There's no built-in support for reverse proxy, If your device has sufficient resource like RB4011 / RB5009 install container package and pull image like nginx or haproxy My main gateway router is an RB4011, but I also have a Raspberry Pi dedicated to network tasks. Best to put it there? Please note...
by ehbowen
Mon Aug 05, 2024 12:21 am
Forum: General
Topic: Inbound Proxy?
Replies: 3
Views: 554

Inbound Proxy?

I've been going through the WebProxy tool in RouterOS. It appears to be for traffic originating on the LAN which needs filtered or indirect access to WAN. How about the other direction? Suppose that I have, behind a single (static) IP, two NAS units which have content that I want to be web-addressab...
by ehbowen
Sun Aug 04, 2024 1:00 am
Forum: General
Topic: RB2011 vs hAP-ac2 (for parents)?
Replies: 4
Views: 648

Re: RB2011 vs hAP-ac2 (for parents)?

The main reason I was leaning towards using the RB2011 was because of the very limited flash RAM on the hAP-ac2. I am planning to configure some VLANs, but I haven't done so yet.
My main router at the house is (currently) an RB4011. Are there problems with it that I should be aware of?
by ehbowen
Sat Aug 03, 2024 6:09 am
Forum: General
Topic: RB2011 vs hAP-ac2 (for parents)?
Replies: 4
Views: 648

RB2011 vs hAP-ac2 (for parents)?

I'm trying to upgrade the (mostly wireless) network at my parents' home nearby. I'm wanting to include a bridge link over Wireguard between the two networks and I'm planning to install one of my NAS boxes there, both for backups of their computer data ("Backups? What are backups?") as well...
by ehbowen
Sat Jul 13, 2024 10:51 pm
Forum: RouterBOARD hardware
Topic: Replacing an hAP-ac?
Replies: 1
Views: 690

Replacing an hAP-ac?

I'm currently using an hAP-ac as a satellite switch/router; it used to be my main router. I think it's a great little unit; the problem is its tiny 16 Mb memory. I've already experienced problems upgrading it to current RouterOS; while I have it running 7.15.2 right now I can see that its day is ove...
by ehbowen
Sun Jun 30, 2024 1:13 am
Forum: General
Topic: Configuring Wireguard Link to Remote site for ROKU
Replies: 8
Views: 639

Re: Configuring Wireguard Link to Remote site for ROKU

I ain't sure what kind of services your NAS provides, you might need a mDNS service.
I'm mostly interested in using it for cloud backup and private video and audio streaming. There is a "DNS Server" application built in, basically a customized version of BIND with a GUI front end.
by ehbowen
Sun Jun 30, 2024 12:57 am
Forum: General
Topic: Configuring Wireguard Link to Remote site for ROKU
Replies: 8
Views: 639

Re: Configuring Wireguard Link to Remote site for ROKU

The "10.255.255.0/30" is the local subnet of the Wireguard peers, nothing special.
Why DNS configuration? for the NAS?
Yes, I want the computers at the remote site to be able to reach my NAS machines (and for me to reach the one over there) with better security and minimum hassle.
by ehbowen
Sun Jun 30, 2024 12:34 am
Forum: General
Topic: Configuring Wireguard Link to Remote site for ROKU
Replies: 8
Views: 639

Configuring Wireguard Link to Remote site for ROKU

I confess to being a VPN newbie. I've got a home office network, and I also take care of the home network for my non-tech-savvy parents a few miles away. Both sites have high-speed 5G wireless Internet through T-Mobile, using FX2000 wireless modems. Both connections have static IPs, with IP passthro...
by ehbowen
Sun Jan 07, 2024 3:05 pm
Forum: General
Topic: How do I clear disk space on a hAP-ac?
Replies: 1
Views: 1205

How do I clear disk space on a hAP-ac?

I've got an hAP-ac being used as a wireless access point and switch behind a RB4011 gateway router. The 16 MB of flash memory is 98% full, and I haven't been able to upgrade RouterOS due to the low memory. If I add up all of the files in the "Files" listing it comes to less than a megabyte...
by ehbowen
Sun Jan 07, 2024 2:09 pm
Forum: RouterBOARD hardware
Topic: I may have bricked my RB3011 [SOLVED]
Replies: 7
Views: 8682

Re: I may have bricked my RB3011 [SOLVED]

I switched from Windoze to my Linux computer and reconfigured the serial port. I was able to reset my router and configure a new password and turn off Etherboot through RS-232. After that, I was able to upgrade from 7.10.2 to 7.12, and then to 7.14beta. So this issue is resolved, for the moment.
by ehbowen
Mon Jan 01, 2024 9:15 pm
Forum: RouterBOARD hardware
Topic: I may have bricked my RB3011 [SOLVED]
Replies: 7
Views: 8682

Re: I may have bricked my RB3011 [SOLVED]

No response when I connect with a serial cable and PuTTY, either at 9600 baud or 115200 baud.

No response on any of the other Ethernet ports. Winbox shows nothing under "neighbors."
by ehbowen
Mon Jan 01, 2024 7:43 pm
Forum: RouterBOARD hardware
Topic: I may have bricked my RB3011 [SOLVED]
Replies: 7
Views: 8682

Re: I may have bricked my RB3011 [SOLVED]

So far, no success. I attempted a NetInstall of 7.10.2 but, although I'm not getting the error message any more, the router still can't be reached by Winbox or in any other way I know of.
What's my next step?
by ehbowen
Mon Jan 01, 2024 8:06 am
Forum: RouterBOARD hardware
Topic: I may have bricked my RB3011 [SOLVED]
Replies: 7
Views: 8682

I may have bricked my RB3011 [SOLVED]

I was updating my routers/switches, and I noticed that an RB3011 was still on RouterOS 7.10.2. I attempted to use the automatic updater, several times, but it wouldn't update...stayed on 7.10.2. No error messages that I could find in the logs; the update just wouldn't take. I then got the bright ide...
by ehbowen
Mon Sep 25, 2023 3:38 am
Forum: General
Topic: SFP Module not communicating
Replies: 0
Views: 740

SFP Module not communicating

I have an RJ45 Ethernet 1000-Base T SFP module which I once used in my hAP-AC to give me a 6th Ethernet port and it worked fine. Then I set it aside for a couple of years. Now I'd like to use it again, but it's not communicating. I picked up a second, similar module and tried it in an RB2011, but ag...
by ehbowen
Wed Sep 06, 2023 7:05 am
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Re: Multiple Physical Hosts behind Single (dynamic) IP?

Google Docs supports these sharing models: Private to Google account owner. Public to anyone and Google Search. Visible to anyone with the obscure link Visible to selected authenticated Google accounts. I propose the latter and after we're done, redacting for publication is an option. I'm amenable ...
by ehbowen
Wed Sep 06, 2023 4:36 am
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Re: Multiple Physical Hosts behind Single (dynamic) IP?

It's time to consider network design taking into account: Current IPv4 subnet implementation Future IPv4 subnet considerations Future VLAN considerations Future IPv6 subnet design I keep my life simple: IPv4 and IPv6 subnets are paired one to one. IPv46 subnet pairs share one VLAN Simple enough so ...
by ehbowen
Wed Sep 06, 2023 12:23 am
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Re: Multiple Physical Hosts behind Single (dynamic) IP?

OK, I like the Hurricane Electric tunnel path. Do you want to keep the T-Mobile IPv6 option open for when they get their act together? Multiple IPv6 providers works; clients have IPv6 addresses on multiple subnets but has Multi-Home Outgoing Source Address Selection problem. Wikipedia has descripti...
by ehbowen
Tue Sep 05, 2023 11:41 pm
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Re: Multiple Physical Hosts behind Single (dynamic) IP?

I had an actual full IPv6 address at the router. But I've since lost it, possibly due to ham-handed configuration errors. Friday was also about the same time that my VoIP phone service stopped working; it looks as if the changeover broke CallCentric's configuration. I'm supposed to have a telephone...
by ehbowen
Tue Sep 05, 2023 7:52 pm
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Re: Multiple Physical Hosts behind Single (dynamic) IP?

I heard back from my account representative. Note: He's not a tech guy and my situation is new to him. But he tells me that, back on Friday, in response to my request I was supposedly changed over from IPv4 to IPv6. Nice of them not to notify me.... For a short time when I was working with this last...
by ehbowen
Tue Sep 05, 2023 5:20 pm
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Re: Multiple Physical Hosts behind Single (dynamic) IP?

The step after Router Advertisements (RA) is IPv6 DHCP client: # Remove existing IPv6 DHCP client /ipv6 dhcp-client remove [ find where comment=defconf ] # Add IPv6 DHCP client request address and IPv6 prefix delegation - known to work with Comcast /ipv6 dhcp-client add interface=ether1 pool-name=T...
by ehbowen
Tue Sep 05, 2023 4:59 pm
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Re: Multiple Physical Hosts behind Single (dynamic) IP?

We know the RB4011 IPv6 stack is running and SLAAC didn't work. Let's accept router advertisements: /ipv6 settings set accept-router-advertisements=yes After a decent pause, let's print IPv6 addresses and routes again. /ipv6 address print Flags: D - DYNAMIC; L - LINK-LOCAL Columns: ADDRESS, INTERFA...
by ehbowen
Tue Sep 05, 2023 3:23 pm
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Re: Multiple Physical Hosts behind Single (dynamic) IP?

Okay... /ipv6 address print Flags: D - DYNAMIC; L - LINK-LOCAL Columns: ADDRESS, INTERFACE, ADVERTISE # ADDRESS INTERFACE ADVERTISE 0 DL fe80::4a8f:5aff:fec5:b6e6/64 ether1 no /ipv6 route print Flags: D - DYNAMIC; A - ACTIVE; c - CONNECT Columns: DST-ADDRESS, GATEWAY, DISTANCE DST-ADDRESS GATEWAY DI...
by ehbowen
Tue Sep 05, 2023 7:06 am
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Re: Multiple Physical Hosts behind Single (dynamic) IP?

Goal: RB4011 enable IPv6 SLAAC on ether1 interface; see: https://en.wikipedia.org/wiki/IPv6#Stateless_address_autoconfiguration_(SLAAC) Expect RB4011 ether1 to negotiate an IPv6 address. Any firewall must allow IPv6 Neighbor Discovery; allowing all ICMPv6 is considered safe. RB4011 configuration ha...
by ehbowen
Tue Sep 05, 2023 5:48 am
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Re: Multiple Physical Hosts behind Single (dynamic) IP?

I also tried changing the PDP setting to dual IPv4/IPv6, but that didn't make a difference...the restriction is upstream. RB4011 configuration disables IPv6. Exploring T-Mobile IPv6 capability is an option while Public IPv4 situation continues. Inseego FX2000 manual Page 60, IPv6 section, Turn on I...
by ehbowen
Tue Sep 05, 2023 5:32 am
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Re: Multiple Physical Hosts behind Single (dynamic) IP?

Please share Hurricane Electric IPv4 address for tunnel server you've chosen. Inseego FX2000 doesn't say anything of internal ping test which is a common feature. Let's verify Public IPv4 the world sees agrees with RB4011 value: http://checkip.dyndns.org/ Hurricane Electric IPv4 address for endpoin...
by ehbowen
Tue Sep 05, 2023 4:39 am
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Re: Multiple Physical Hosts behind Single (dynamic) IP?

@ehbowen I don't see RB4011 major breakage; I do see one suspect item and several unused resources. To save time I shall ignore firewall issues (NAT excepted; it's routing) and ignore scheduler and scripting. I don't see how this firewall NAT rule will work: /ip firewall nat add action=dst-nat chai...
by ehbowen
Tue Sep 05, 2023 3:25 am
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Re: Multiple Physical Hosts behind Single (dynamic) IP?

By The Way, I just found out that my Tunnelbroker account with Hurricane Electric is still active even though I haven't used it since I went to the /29 static block. I'm eligible to create up to 5 tunnels.
by ehbowen
Tue Sep 05, 2023 3:03 am
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Re: Multiple Physical Hosts behind Single (dynamic) IP?

Okay, here goes. Redacted RB4011 Configuration: # 2023-09-04 18:49:09 by RouterOS 7.11 # software id = ****-**** # # model = RB4011iGS+ # serial number = ************ /interface bridge add admin-mac=48:8F:5A:**:**:** auto-mac=no comment=defconf name=bridge /interface list add comment=defconf name=WA...
by ehbowen
Tue Sep 05, 2023 1:06 am
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Re: Multiple Physical Hosts behind Single (dynamic) IP?

Look T-Mobile For Business has IPv6: https://solutions.t-mobile.com/support/ipv6 Let's pursue this first; it restores global end-point connectivity enjoyed with public /29 static subnet. I couldn't do anything with this on IPv6 or IPv4. I believe it requires a login and I've had difficulty establis...
by ehbowen
Tue Sep 05, 2023 12:56 am
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Re: Multiple Physical Hosts behind Single (dynamic) IP?

Download Inseego FX2000 User Guide https://inseego.com/download/FX2000_user_guide.pdf Some gateway devices have "bypass" mode which I didn't see in this manual. I do see "IP Passthrough" in several places. Where are you with that? IP Passthrough is selected and the RB4011 is see...
by ehbowen
Tue Sep 05, 2023 12:40 am
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Re: Multiple Physical Hosts behind Single (dynamic) IP?

RB5009UPr+S+IN has PoE-out on all ports. https://mikrotik.com/product/rb5009upr_s_in
Compare performance with current router and consider for the core router role.
Looks nice! I'll add it to the wish list for if/when the novel I'm bringing out next May becomes a success....
by ehbowen
Tue Sep 05, 2023 12:37 am
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Re: Multiple Physical Hosts behind Single (dynamic) IP?

My gateway device is an Inseego FX2000, connected directly to ether1 of my RB4011. This is bad news. Do you have full control of Inseego FX2000? Do you care about the Inseego FX2000 WiFi capability? I have admin access to the FX2000, and had to change the default configuration to my APN settings to...
by ehbowen
Tue Sep 05, 2023 12:32 am
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Re: Multiple Physical Hosts behind Single (dynamic) IP?

@ConradPino What I was shopping for (and still have an eBay alert posted for) was a CRS-112-8P-4S-IN. I want the 8 PoE ports (which the Netvanta 1531P has) and I need the small footprint (restricted space in my data 'closet', which is actually a Leviton structured media cabinet). Most of what will b...
by ehbowen
Tue Sep 05, 2023 12:17 am
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Re: Multiple Physical Hosts behind Single (dynamic) IP?

I had not used IPv6 on my LAN before at all as I was unsure as to how best to secure it. I was going to try it with this complete revamp of my LAN, but...well, not supported. But I'd certainly be willing to use a tunnel for the critical services on the NAS devices. As far as IPv4 routing: I specific...
by ehbowen
Mon Sep 04, 2023 5:56 pm
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Re: Multiple Physical Hosts behind Single (dynamic) IP?

Getting the most out of this forum by normis, MikroTik Support The more we know, the more we can offer creative suggestions. Such as Nginx (real reverse proxy) runs in RouterOS Container. Fair enough. Here's a very rough rendering of the physical network topology that I'm aiming for. Yes, it's cond...
by ehbowen
Mon Sep 04, 2023 5:47 am
Forum: General
Topic: Multiple Physical Hosts behind Single (dynamic) IP?
Replies: 56
Views: 5377

Multiple Physical Hosts behind Single (dynamic) IP?

I admit it, I got spoiled. For the past six years I've been able to indulge myself with a /29 subnet of static IPs to connect my three NAS devices to. But now, after two rate hikes within the past year coupled with a lowered income and inflation, I've got to cut it loose. My new service has a single...
by ehbowen
Sun Aug 01, 2021 1:55 pm
Forum: General
Topic: Creating a 2000 entry personal Blacklist
Replies: 10
Views: 1598

Creating a 2000 entry personal Blacklist

My routers have been under attack lately. I have MOAB service installed and running on both of them; however, in the past week my server logs have recorded more than 2000 attempts on my admin account which got past MOAB. I have the list filtered down to bare IPv4 addresses (IPv6 is currently disable...
by ehbowen
Fri Oct 30, 2020 4:30 pm
Forum: General
Topic: A Couple of Configuration Questions
Replies: 2
Views: 692

A Couple of Configuration Questions

I'm performing some upgrades on my home office network and installing a new NAS which will also serve as my email server, so it needs to be web-accessible. I have been manually assigning IP addresses to this kind of hardware in the past, but I'm also planning to implement a VLAN scheme in the near f...
by ehbowen
Tue Oct 27, 2020 6:54 pm
Forum: RouterBOARD hardware
Topic: Hardware Firewall?
Replies: 1
Views: 844

Hardware Firewall?

I'm still a relative newbie to MikroTik networking; still trying to successfully plan and deploy a VPN scheme. That said, I've been looking at possibly installing a hardware firewall, such as the Cisco Meraki Go GX-20 or possibly the Fortigate 40-F. Before I take the plunge, though, does MikroTik of...
by ehbowen
Fri Apr 03, 2020 10:44 am
Forum: Beginner Basics
Topic: Combining MAC and port-based VLANs on a network?
Replies: 1
Views: 1522

Combining MAC and port-based VLANs on a network?

I'm looking at implementing VLANs on a small network; Mikrotik hAP-ac is the gateway and there are two RB2011s and an RB3011 in use as switches. One issue I have, though, is the need to run legacy OS on some of the machines to maintain compatibility with (now obsolete) analog video digitizing equipm...
by ehbowen
Fri Jan 03, 2020 9:18 pm
Forum: RouterBOARD hardware
Topic: How Does the CRS328-24P-4S+RM Perform as a Router?
Replies: 8
Views: 6556

Re: How Does the CRS328-24P-4S+RM Perform as a Router?

Again, I'm not experienced in interpreting these results. But it appears just from looking at the numbers that the CRS328 would be a step down from my present hAP-ac as a router. As a switch it looks fine, but if I'm going to have to purchase a separate router...well, I'll keep looking. I'm not in a...
by ehbowen
Fri Jan 03, 2020 8:34 pm
Forum: RouterBOARD hardware
Topic: How Does the CRS328-24P-4S+RM Perform as a Router?
Replies: 8
Views: 6556

How Does the CRS328-24P-4S+RM Perform as a Router?

I'm looking to make a long-term upgrade to my network, including centralizing the WAN links in a dedicated data cabinet...not a rack, but a "connected home" cabinet mounted between drywall studs. So space is at a premium. I'm wanting to have PoE available, as well as the capability for fib...
by ehbowen
Fri Jan 03, 2020 3:25 pm
Forum: General
Topic: Did MikoTik ever fix DHCPv6?
Replies: 3
Views: 1323

Did MikoTik ever fix DHCPv6?

I've been wanting to implement IPv6 on my home-based network, but my understanding from searching old threads is that as of that time MikroTik only had a partial implementation of DHCPv6 and that it was not reliable. Has this ever been corrected, or is it still the case in 2020?
by ehbowen
Thu Sep 05, 2019 8:04 am
Forum: Beginner Basics
Topic: Can't Access RB2011 after initial setup
Replies: 1
Views: 1645

Can't Access RB2011 after initial setup

I recently purchased a secondhand RB2011UiAS-2HnD-IN to replace a 5-port unmanaged switch on my home network. I have other MikroTik devices; the main home router is an hAP-ac and I have an RB3011 as a switch in an equipment rack with some specialty items, so I'm somewhat familiar with RouterOS and W...
by ehbowen
Fri Aug 23, 2019 10:53 am
Forum: Beginner Basics
Topic: Network Making for (almost) Beginners
Replies: 10
Views: 3116

Re: Network Making for (almost) Beginners

Also, check YouTube. There are some very good video tutorials on setting up MikroTik routers for networking. A gentleman by the handle of 'TKSJa' has a very comprehensive set of tutorial videos, at no charge!
by ehbowen
Sun Aug 18, 2019 6:40 pm
Forum: Beginner Basics
Topic: First Attempt at VLANs; Need Help!
Replies: 10
Views: 2315

Re: First Attempt at VLANs; Need Help!

All right. It's kicking my you-know-what-but-I-can't-say-it-out-loud-in-church. My first uploaded effort was a miscarriage, to put it bluntly; I was trying to do things piecemeal through Winbox while keeping connectivity. I erased it and tried again in the terminal using the provided examples. My pr...
by ehbowen
Sun Aug 18, 2019 12:42 am
Forum: Beginner Basics
Topic: First Attempt at VLANs; Need Help!
Replies: 10
Views: 2315

Re: First Attempt at VLANs; Need Help!

Once you have a fleshed out config, post it here for review /export hide-sensitive file=yourconfig17Aug Thanks for the assistance. Attached is where I'm at right now. Currently all Internet access is broken in and out, but I haven't yet configured the switch ports on the NetVanta for the VLANs. I h...
by ehbowen
Sat Aug 17, 2019 7:33 pm
Forum: Beginner Basics
Topic: First Attempt at VLANs; Need Help!
Replies: 10
Views: 2315

Re: First Attempt at VLANs; Need Help!

Myself I wouldn't expose a NAS to the outside world - there have been several stories of buggy firmware allowing people access to things they shouldn't. Using one port for external traffic rather than sharing it with one for internal traffic makes little difference, a DoS attack on externally acces...
by ehbowen
Sat Aug 17, 2019 5:45 pm
Forum: Beginner Basics
Topic: First Attempt at VLANs; Need Help!
Replies: 10
Views: 2315

Re: First Attempt at VLANs; Need Help!

Regarding DNS: Our primary server (a Synology RackStation) is running the DNS Server package and I'm planning to make it the authoritative master DNS record for our domain. What rules would I need to implement to have all devices on the network look to that unit as the DNS server, and then to force ...
by ehbowen
Sat Aug 17, 2019 5:35 pm
Forum: Beginner Basics
Topic: First Attempt at VLANs; Need Help!
Replies: 10
Views: 2315

Re: First Attempt at VLANs; Need Help!

You haven't mentioned what WiFi system you are using, but as long as you can create multiple SSIDs and associate them with tagged VLANs they are just a counduit for the traffic from the client device to the Mikrotik. Thanks for the very helpful answer. I'm planning to spend some time working on the...
by ehbowen
Sat Aug 17, 2019 3:37 am
Forum: Beginner Basics
Topic: First Attempt at VLANs; Need Help!
Replies: 10
Views: 2315

First Attempt at VLANs; Need Help!

I run a network at my church as a volunteer and as a learning project. I'm trying to break up the various devices for security and to get familiar with subnetting and VLANs. Currently everything is on a /24 private IP address range. I have defined several subnets and, using the Wiki, have assigned i...
by ehbowen
Tue Jun 11, 2019 5:28 pm
Forum: General
Topic: Implementing a Blacklist [SOLVED]
Replies: 2
Views: 3098

Implementing a Blacklist [SOLVED]

I'm getting persistent and repeated attacks on my home office network, mostly from similar IP ranges (which are well away from the main user base of my web site). I've got account protection on my server which cuts an IP address off after repeated unsuccessful connection attempts and I do use strong...
by ehbowen
Sun Jun 09, 2019 4:15 am
Forum: Wireless Networking
Topic: Temporarily disabling 5GHz wi-fi band on hAP ac router
Replies: 2
Views: 3746

Temporarily disabling 5GHz wi-fi band on hAP ac router

I have an IoT device (weather station) which is not connecting to my router any longer (it worked properly for five months, but no more). I've attempted a reset to factory defaults and restarted it several times, but no joy. The manufacturer does not know how to support MikroTik but states that the ...
by ehbowen
Wed Jul 18, 2018 11:56 pm
Forum: Beginner Basics
Topic: Deploying IPv6 on a home/hobbyist/small business network?
Replies: 8
Views: 6824

Re: Deploying IPv6 on a home/hobbyist/small business network?

All right. I have: Upgraded RouterOS to latest version (6.42.6). Enabled the IPv6 package. Set up a DHCP client entry on WAN1 requesting an address and prefix; it has received an address and prefix which correspond to what my ISP is showing in my Internet gateway. Set up a DHCP server entry on the b...
by ehbowen
Wed Jul 18, 2018 9:23 pm
Forum: Beginner Basics
Topic: Deploying IPv6 on a home/hobbyist/small business network?
Replies: 8
Views: 6824

Deploying IPv6 on a home/hobbyist/small business network?

I've got my home network set up and running fairly well with IPv4 using my hAP-AC router and RB3011 as a bridging switch for my home office equipment. I'd like to add IPv6 capability, but I'm cautious about exposing some devices (IoT stuff, mostly) which may not have a very robust firewall to access...
by ehbowen
Tue Jun 19, 2018 8:41 am
Forum: Beginner Basics
Topic: I've lost my hairpin NAT [SOLVED]
Replies: 5
Views: 2212

Re: I've lost my hairpin NAT [SOLVED]

And now it's working again. Why? Dunno. I didn't change a thing.
by ehbowen
Fri Jun 15, 2018 9:43 pm
Forum: Beginner Basics
Topic: I've lost my hairpin NAT [SOLVED]
Replies: 5
Views: 2212

Re: I've lost my hairpin NAT [SOLVED]

Open two more colon "To Address", "To Ports" and find to which local IP:port you translating your 76.212.90.etc It's going to the proper IP addresses and ports. As I said, it was working and I haven't changed that. And I can reach the second server from a browser on the LAN usin...
by ehbowen
Fri Jun 15, 2018 3:18 am
Forum: Beginner Basics
Topic: I've lost my hairpin NAT [SOLVED]
Replies: 5
Views: 2212

I've lost my hairpin NAT [SOLVED]

I have two externally accessible servers, each with primary and secondary LAN connections. I had hairpin NAT rules set up to allow all of the other computers and devices on the network to talk with/to them, and the rules were working. Earlier this morning, I upgraded my RouterOS packages to 6.42.3. ...
by ehbowen
Thu May 17, 2018 4:12 am
Forum: Beginner Basics
Topic: Setting Up DDNS
Replies: 3
Views: 3350

Re: Setting Up DDNS

That's the thing; I need the other commands in order to make it work. Like I said, I'm a newbie. While it's technically a dynamic IP, it really doesn't change much. I believe it's changed maybe one time in the six months since I opened the Internet account. And our church doesn't send a whole lot of...
by ehbowen
Thu May 17, 2018 12:13 am
Forum: Beginner Basics
Topic: Setting Up DDNS
Replies: 3
Views: 3350

Setting Up DDNS

I'm trying to move my master DNS records in-house. I have two Synology servers on public static IP addresses which run the Synology DNS Server package, which is a BIND variant. I also have another server at my church, on a dynamic IP address behind a MikroTik RB3011 router. According to the Wiki the...
by ehbowen
Sun May 13, 2018 6:29 am
Forum: Beginner Basics
Topic: Basic Bridging for a Beginner?
Replies: 4
Views: 1207

Re: Basic Bridging for a Beginner?

What wifi devices do you have (Access Points) and where are they connected in the scheme of things?
My only wifi access point device at the present time is the 2-channel radio built into the hAP-AC.
by ehbowen
Sun May 13, 2018 12:16 am
Forum: Beginner Basics
Topic: Basic Bridging for a Beginner?
Replies: 4
Views: 1207

Basic Bridging for a Beginner?

I've been unable to get wireless devices to talk to wired devices in my home/office LAN and I suspect I've got the wireless bridging set up wrong. Or perhaps something else in my firewall rules, etc. My main router is an hAP-AC. WAN connection is on Ethernet port 1. Ethernet ports 2-5 go to the wire...
by ehbowen
Thu Apr 26, 2018 4:02 pm
Forum: Beginner Basics
Topic: Need to get outgoing IP addresses to match [SOLVED]
Replies: 7
Views: 2376

Re: Need to get outgoing IP addresses to match [SOLVED]

Thanks; that was just what I needed!
by ehbowen
Thu Apr 26, 2018 6:50 am
Forum: Beginner Basics
Topic: Need to get outgoing IP addresses to match [SOLVED]
Replies: 7
Views: 2376

Need to get outgoing IP addresses to match [SOLVED]

I have to admit, I'm still new at this. I've had an email server set up at home for a few years now, but I've always had difficulty getting it to send email and have it delivered unless I use a third-party service such as No-IP. I now have business class service, I've got port 25 unblocked, and I ha...
by ehbowen
Sat Mar 24, 2018 1:37 am
Forum: Beginner Basics
Topic: Protecting An Obsolete Computer
Replies: 3
Views: 1040

Protecting An Obsolete Computer

I am doing some video work on the side, mainly conversion of old VHS video tapes to digital video. You may not realize this, but the best hardware and software for doing this was produced around the turn of the century for Win2000 and XP. Vista broke a lot of the drivers, and Windows 8 broke a whole...
by ehbowen
Tue Mar 06, 2018 4:12 am
Forum: Beginner Basics
Topic: Having Trouble Using RB3011 as a Switch [SOLVED]
Replies: 9
Views: 2487

Re: Having Trouble Using RB3011 as a Switch [SOLVED]

Sounds like you have successfully reset it to factory default. Note in this config, it will not have an IP Address. Make sure you disable your firewall / anti virus on your pc as this can cause issues, then click on the "Neighbors" tab, next to the "Managed" tab. The 3011 should...
by ehbowen
Mon Mar 05, 2018 6:06 am
Forum: Beginner Basics
Topic: Having Trouble Using RB3011 as a Switch [SOLVED]
Replies: 9
Views: 2487

Re: Having Trouble Using RB3011 as a Switch [SOLVED]

Well, I attempted resetting to factory defaults a couple of times. It did no good. I disconnected everything from the router except a known good laptop (with wireless shut off and Ethernet IP set to 192.168.88.18) connected by a known good cable to RB3011 Port 2, powered up the router, and attempted...
by ehbowen
Mon Mar 05, 2018 2:44 am
Forum: Beginner Basics
Topic: Having Trouble Using RB3011 as a Switch [SOLVED]
Replies: 9
Views: 2487

Re: Having Trouble Using RB3011 as a Switch [SOLVED]

These are the steps I will do first:

1. Reset to factory default
2. Connect to port 2 via MAC address
3. Update ROS and firmware
When I attempt to reset to factory default, it asks for a passcode. There was no documentation included with the unit. What passcode do I use?
by ehbowen
Sun Mar 04, 2018 11:55 pm
Forum: Beginner Basics
Topic: Having Trouble Using RB3011 as a Switch [SOLVED]
Replies: 9
Views: 2487

Having Trouble Using RB3011 as a Switch [SOLVED]

I've had my home network working off an hAP-ac for a few months now. But I've just built out a rack of equipment which I plan to use in a home-based video business, and I'm trying to get it all hooked up. Right now there's a PC, a Synology RackStation NAS server, and an RB3011 which I want to use as...
by ehbowen
Fri Jan 19, 2018 12:34 am
Forum: Beginner Basics
Topic: Trouble with Static IPs
Replies: 3
Views: 964

Re: Trouble with Static IPs

SOLVED; it was AT&T's problem. I spent an hour on the line with AT&T tech support only to be told bluntly that I couldn't use my own router; I had to plug everything directly into their gateway if I wanted to use the additional IPs. Well, that wasn't acceptable as the only way I could access...
by ehbowen
Thu Jan 18, 2018 9:41 pm
Forum: Beginner Basics
Topic: Trouble with Static IPs
Replies: 3
Views: 964

Re: Trouble with Static IPs

Update: After playing around a little further, I strongly suspect it's a firewall issue within the ISPs gateway. Unfortunately they provide almost no documentation, so I'll probably have to sit in the "customer service" queue for an hour. Still soliciting suggestions for ways to make sure ...
by ehbowen
Thu Jan 18, 2018 9:18 pm
Forum: Beginner Basics
Topic: Trouble with Static IPs
Replies: 3
Views: 964

Trouble with Static IPs

I have a block of 5 (/29) static IPs from my ISP. I have the base address (x.x.x.121) set up and working fine through my hAP AC. I just installed a second server, and I wanted to configure it to accept inbound traffic on the highest address (x.x.x.125). I copied the NAT and hairpin NAT rules from th...
by ehbowen
Sat Nov 25, 2017 2:46 pm
Forum: Beginner Basics
Topic: Problems Accessing Server From Within LAN
Replies: 3
Views: 1068

Re: Problems Accessing Server From Within LAN

Thank you, that solved the issue.
by ehbowen
Sat Nov 25, 2017 1:31 pm
Forum: Beginner Basics
Topic: Problems Accessing Server From Within LAN
Replies: 3
Views: 1068

Problems Accessing Server From Within LAN

I've finally got my port forwarding configured to where I can access the relevant ports on my server from outside the network. When I enter the website address or management port from WAN it goes where it's supposed to. Good. But (there's always a 'but'!)...when I enter these addresses from INSIDE t...
by ehbowen
Sun Nov 12, 2017 3:21 pm
Forum: Beginner Basics
Topic: Multiple Static IPs; Port Forwarding Problems
Replies: 5
Views: 1106

Re: Multiple Static IPs; Port Forwarding Problems

You just posted a question where you need to setup SRC and dst mating correctly.if you post up your static range I can help you setup corrdct translations.

Sent from my SUPER using Tapatalk
That will probably help. Here's the relevant screenshot:
Capture.20171112-3.PNG
by ehbowen
Sun Nov 12, 2017 3:18 pm
Forum: Beginner Basics
Topic: Multiple Static IPs; Port Forwarding Problems
Replies: 5
Views: 1106

Re: Multiple Static IPs; Port Forwarding Problems

At the present time I only have one physical server which I want to be globally accessible. But it's (going to be) hosting several websites, two or three of which may eventually be migrated to their own hardware on the same static IP subnet. I'd like to set it up now so that incoming traffic for tho...
by ehbowen
Sat Nov 11, 2017 8:29 am
Forum: Beginner Basics
Topic: Multiple Static IPs; Port Forwarding Problems
Replies: 5
Views: 1106

Multiple Static IPs; Port Forwarding Problems

I am fairly new to RouterOS and just purchased a hAP AC for my home network. I set it up largely with autoconfig; the wireless networks and guest network seem to be working fine and I have connectivity out. My problem is that I have been unable to get port forwarding from outside to work, whether th...
by ehbowen
Wed Oct 25, 2017 6:13 am
Forum: Beginner Basics
Topic: Setting Up Port Forwarding
Replies: 5
Views: 1223

Re: Setting Up Port Forwarding

***Also doing it via dst-ip address is a good way to get yourself setup for hairpin NAT as you can't do that (easily) if you name interfaces the connections should be coming down as with LAN>LAN via host name the connections never leave the router. I'm afraid I'm going to need that one spelled out...
by ehbowen
Wed Oct 25, 2017 6:11 am
Forum: Beginner Basics
Topic: IP (cam), Phone Home!
Replies: 2
Views: 932

Re: IP (cam), Phone Home!

How can I block IPv6 access from WAN to some more vulnerable devices (IP cameras, IoT, maybe VoIP phones) while leaving it open to systems (server, computers) which have a firewall which can be readily configured and monitored?
by ehbowen
Tue Oct 24, 2017 3:59 pm
Forum: Beginner Basics
Topic: IP (cam), Phone Home!
Replies: 2
Views: 932

IP (cam), Phone Home!

As part of my new church network , I'm installing IP security cameras. So far I've picked out four HikVision PTZ cams, two for indoor and two for outdoor. One is already in and is working fine. My area of concern here is the many reports about low-end Chinese IP cameras "phoning home" to C...
by ehbowen
Tue Oct 24, 2017 3:48 pm
Forum: Beginner Basics
Topic: Setting Up Port Forwarding
Replies: 5
Views: 1223

Re: Setting Up Port Forwarding

Good start, Steve, but at least as of the present I'm on a dynamic IP. Now, my ISP has been pretty good about not changing it capriciously, but...how would you suggest coping with that?
by ehbowen
Tue Oct 24, 2017 2:55 pm
Forum: Beginner Basics
Topic: Setting Up Port Forwarding
Replies: 5
Views: 1223

Setting Up Port Forwarding

Ok, I've got the beginnings of my church network up and running. The server is functional, as is one of the cameras and one of the access points. They're all talking together fine. I've got SafeDNS filtering set up at the router to protect the entire network. It's time to configure port forwarding. ...
by ehbowen
Wed Sep 13, 2017 6:02 pm
Forum: Beginner Basics
Topic: Is the CRS106 suitable as a router?
Replies: 6
Views: 2072

Re: Is the CRS106 suitable as a router?

Note also that when I get everything up and running I will want the capability for dual WANs; my current ISP offers decent speed but their reliability has been less than stellar. The phone company can't match their speed, but when I was using their service I almost never, ever suffered an outage. P...
by ehbowen
Wed Sep 13, 2017 4:48 am
Forum: Beginner Basics
Topic: Is the CRS106 suitable as a router?
Replies: 6
Views: 2072

Is the CRS106 suitable as a router?

Along with the church network mentioned elsewhere, I'm also in the process of preplanning a major upgrade to my home network. I'm planning to mount the components in a Leviton Structured Media Enclosure, not a rack, and I do want a lot of PoE ports for security cameras, access points, VoIP telephone...
by ehbowen
Sat Sep 09, 2017 7:27 pm
Forum: Beginner Basics
Topic: Brand New to MikroTik
Replies: 5
Views: 2409

Re: Brand New to MikroTik

Doing all of this on a new to you platform is going to involve a steep learning curve. That's great if you have the time. If you know how to do all of this with something else, you may want to go that direction, even if it costs more. If you have to learn how to do this for any platform you might u...
by ehbowen
Tue Sep 05, 2017 7:06 am
Forum: Beginner Basics
Topic: Brand New to MikroTik
Replies: 5
Views: 2409

Brand New to MikroTik

In the "Lemons to Lemonade" department: I live in Houston, Texas...you may have heard of the recent unpleasantness...and currently my small church has the bottom 18" of wallboard cut out all through the property. I was struck by the notion that this would be an excellent opportunity t...