Community discussions

MikroTik App

Search found 308 matches

  • 1
  • 2
by olivier2831
Fri Feb 23, 2024 12:13 pm
Forum: Wireless Networking
Topic: Which devices for a wireless link between two buildings, <100m range ?
Replies: 13
Views: 1132

Re: Which devices for a wireless link between two buildings, <100m range ?

If you manage to install the devices outside, then definitely choose 60 GHz. It's a cheap solution, actually gives 900+ Mbps and it is future-proof. I agree. The key is to have: a way to route a cable from the outside to the inside (an extra flat PoE compatible Ethernet cable ?) a mean to mount the...
by olivier2831
Fri Feb 23, 2024 10:16 am
Forum: Wireless Networking
Topic: Which devices for a wireless link between two buildings, <100m range ?
Replies: 13
Views: 1132

Re: Which devices for a wireless link between two buildings, <100m range ?

Thank you very much for your reply.

I agree SXTsq Lite2 or SXTsq Lite5 seem to fit.
by olivier2831
Thu Feb 22, 2024 12:40 pm
Forum: Wireless Networking
Topic: Which devices for a wireless link between two buildings, <100m range ?
Replies: 13
Views: 1132

Which devices for a wireless link between two buildings, <100m range ?

Hello, On a remote location, I need to set a temporary point-to-point wireless link between two buildings. The use is for Internet surfing and target throughput is 100Mb/s. The buildings are quite close to each other (<100m) with clear line of sight. I currently have no path between the building roo...
by olivier2831
Fri Jan 26, 2024 7:14 pm
Forum: General
Topic: LLDP-MED : missing 802.3 MAC/PHY TLV and fast start timer, RouterOS 7.14beta7 - RB5009
Replies: 4
Views: 562

Re: LLDP-MED : missing 802.3 MAC/PHY TLV and fast start timer, RouterOS 7.14beta7 - RB5009

Unfortunately LLDP-MED is rarely used, at least for small and medium telephony installation, because the hardware does not always implement it. I think the main reason is small and medium installations do not use VLANs at all, either for telephony or for other applications. Anyway, with other vendo...
by olivier2831
Fri Jan 26, 2024 4:04 pm
Forum: General
Topic: LLDP-MED : missing 802.3 MAC/PHY TLV and fast start timer, RouterOS 7.14beta7 - RB5009
Replies: 4
Views: 562

Re: LLDP-MED : missing 802.3 MAC/PHY TLV and fast start timer, RouterOS 7.14beta7 - RB5009

Thank you very much for starting this thread: the topic seems very important to me.
by olivier2831
Fri Oct 13, 2023 2:23 pm
Forum: Scripting
Topic: Advice on configuring Mikrotik devices with Ansible
Replies: 4
Views: 2022

Re: Advice on configuring Mikrotik devices with Ansible

Check TR069 instead, will it work for you or not.
Does TR069 support VLAN configuration (ie not just for WAN port but for bridge or interface) ?
by olivier2831
Fri Oct 13, 2023 10:11 am
Forum: Scripting
Topic: Advice on configuring Mikrotik devices with Ansible
Replies: 4
Views: 2022

Re: Advice on configuring Mikrotik devices with Ansible

When using CLI to configure RouterOS, I had trouble to script idempotent operations such as "create VLAN 10 if it doesn't exist". I don't mean it's not possible to write idempotent scripts with CLI, I only mean I had trouble doing so. One expected benefit from using Ansible is to ease idem...
by olivier2831
Fri Oct 13, 2023 10:05 am
Forum: Scripting
Topic: Advice on configuring Mikrotik devices with Ansible
Replies: 4
Views: 2022

Advice on configuring Mikrotik devices with Ansible

Hello, I'm quite used now to manage Debian hosts with Ansible. I would like to also manage Mikrotik RouterOS device with Ansible. The whole picture is: - using Flashfig to initialize the platform (management IP, firmware, certs, creds, management accounts, enabling/disabling protocols, ...) - using ...
by olivier2831
Mon Oct 02, 2023 11:58 am
Forum: General
Topic: [OT] How to properly test NAT/firewalling perf ?
Replies: 0
Views: 932

[OT] How to properly test NAT/firewalling perf ?

Hello, How do you test NAT/firewalling perf of a given NAT/firewall router (could be a Mikrotik RouterOS device or not) ? If I'm not mistaken, some NAT/firewall operations are done when a new flow is detected while other are repeated afterwards. So do you need to often create new flows (ie changing ...
by olivier2831
Thu Sep 21, 2023 1:50 pm
Forum: Wireless Networking
Topic: Finally success - 802.11r/k/v fast roaming works reliably with WifiWave2
Replies: 53
Views: 14882

Re: Finally success - 802.11r/k/v fast roaming works reliably with WifiWave2

Agree with you, i think Mikrotik wireless became good, at least for home users, now i have same or even better experience with cap ax when compared to ubiquiti u6 lite. Signal is better for sure.
Do you have figures (dB, ...) echoing this ?
Were both AP ceiling mounted ?
by olivier2831
Wed Sep 20, 2023 9:28 am
Forum: Wireless Networking
Topic: A bit better WiFi security with per-user PSK? [SOLVED]
Replies: 62
Views: 10045

Re: A bit better WiFi security with per-user PSK? [SOLVED]

A side note: latest Unifi 7.5.185 UNA finally supports PPSK !
Having PPSK on Mikrotik would be great !
by olivier2831
Wed Sep 20, 2023 9:01 am
Forum: General
Topic: How visualize TCP/UDP traffic from IP/port range ?
Replies: 2
Views: 415

Re: How visualize TCP/UDP traffic from IP/port range ? [SOLVED]

Yes, I think this reply to my needs.
Thanks for replying.

If the log rule is strictly focused on the IP/port range I'm after, this won't produce too much log data.
Thanks again
by olivier2831
Tue Sep 19, 2023 6:55 pm
Forum: General
Topic: How visualize TCP/UDP traffic from IP/port range ?
Replies: 2
Views: 415

How visualize TCP/UDP traffic from IP/port range ?

Hello, I've got the following setup: Internet ---- RouterOS ----- Linux Host ---- PC The Linux Host implement do NAT on traffic from PC. I would like to check if this NAT is properly done. My first idea was to connect on RouterOS device and use Packet Sniffer but, if I'm not mistaken, on 6.48.5, it ...
by olivier2831
Tue Sep 19, 2023 1:05 pm
Forum: Wireless Networking
Topic: A bit better WiFi security with per-user PSK? [SOLVED]
Replies: 62
Views: 10045

Re: A bit better WiFi security with per-user PSK? [SOLVED]

Smart TVs perfectly show how difficult it can be to securely connect guest devices on a Wifi network. Some (most ?) smart TVs do no embed any browser so no portal. To my knowledge, none supports EAP. So basically, it only leaves three options: WPA Personal with a shared password, PPSK with device de...
by olivier2831
Tue Sep 12, 2023 9:49 am
Forum: RouterBOARD hardware
Topic: Product suggestion: 10Gbps router in CRS310 form factor
Replies: 4
Views: 3361

Re: Product suggestion: 10Gbps router in CRS310 form factor

Maybe trading RB5009's 5 Gigabit ports to 2 2.5Gb/s would cover such needs without involving too much dev effort.
by olivier2831
Mon Sep 11, 2023 1:57 pm
Forum: Announcements
Topic: Newsletter #114 | September 2023
Replies: 72
Views: 15310

Re: Newsletter #114 | September 2023

The same as above but aid differently: There are hundred of devices types that can by powered by PoE, but by far, the most common ones are either IP phones, IP cams or WiFi APs. - To my knowledge, IP phones are still and only Gigabit devices. - For IP cams, maybe 2.5Gb/s will break trough given vide...
by olivier2831
Wed Sep 06, 2023 5:08 pm
Forum: RouterBOARD hardware
Topic: Why placing DC power port on the front of newest devices ?
Replies: 4
Views: 2829

Re: Why placing DC power port on the front of newest devices ?

I am wondering if there are no other reasons such as power supply circuitry placement on the PCB (as close as possible to PoE circuitry and as far as possible from WiFi antennas) to avoid interference for instance... Maybe a large enough hole in the left mounting ear (as the power input plug is on ...
by olivier2831
Wed Aug 30, 2023 10:20 am
Forum: RouterBOARD hardware
Topic: Equivalent for USW Flex - no MT alternative?
Replies: 13
Views: 4179

Re: Equivalent for USW Flex - no MT alternative?

hEX PoE may fit.
I use them to remotely power AP and cameras
by olivier2831
Wed Aug 30, 2023 9:29 am
Forum: RouterBOARD hardware
Topic: MikroTik CRS309-1G-8S+INL -- 10G RJ45 Transceiver?
Replies: 54
Views: 7828

Re: MikroTik CRS309-1G-8S+INL -- 10G RJ45 Transceiver?

In the light of common practices in networking, it seems to me that jumping from 1G/s to to 10Gb/s is a too long jump as it introduces thermal or compatibility issues we didn't have to deal with in the past. Maybe going from 1Gb/s to 2.5Gb/s would be a smarter move allowing bandwidth increase withou...
by olivier2831
Mon Aug 28, 2023 12:20 pm
Forum: General
Topic: LLDP-MED: setting two different policies
Replies: 0
Views: 968

LLDP-MED: setting two different policies

Hello,

Is it possible to set several LLDP-MED policies on RouterOS 6.X or 7.Y device ?
I would like to set lldp-med-net-policy-vlan to 5 on interface-list LAN1 and lldp-med-net-policy-vlan to 10 on interface-list LAN2.
(of course LAN1 and LAN2 have no interface in common).
Is it possible ?

Regards
by olivier2831
Fri Aug 25, 2023 3:50 pm
Forum: General
Topic: r5009-like switch with heat-sink allowing DIN Rail mounting ?
Replies: 6
Views: 1462

Re: r5009-like switch with heat-sink allowing DIN Rail mounting ?

Thanks for including the image: it's much easier now to follow this thread. With a single DIN Rail accessory, you can position a whole device family on this uncovered market. To be complete, industrial switches sure have unique capabilities (temperature range, ...) but current r5009 also has its str...
by olivier2831
Fri Aug 25, 2023 3:26 pm
Forum: General
Topic: r5009-like switch with heat-sink allowing DIN Rail mounting ?
Replies: 6
Views: 1462

Re: r5009-like switch with heat-sink allowing DIN Rail mounting ?

On the above attachment, the U shaped thing at the right of the drawing is a DIN rail profile.
by olivier2831
Fri Aug 25, 2023 3:24 pm
Forum: General
Topic: r5009-like switch with heat-sink allowing DIN Rail mounting ?
Replies: 6
Views: 1462

Re: r5009-like switch with heat-sink allowing DIN Rail mounting ?

What I have in mind is something that can compete with :
https://www.fs.com/products/138513.html

Those devices can be wall mounted or DIN rail mounted without any rack and very easy to swap.
r5009-like devices are even more compact than those.
r5009 DIN.pdf
by olivier2831
Wed Aug 23, 2023 6:12 pm
Forum: General
Topic: r5009-like switch with heat-sink allowing DIN Rail mounting ?
Replies: 6
Views: 1462

r5009-like switch with heat-sink allowing DIN Rail mounting ?

Hello, Current R5009 or L009 are very compact and silent rack-mountable devices. It could very interesting in hospitality or industry to have switches of the same form factor but with rail bracket allowing them to be vertically (or horizontally) side-by-sied, mounted on a wall through a DIN rail. In...
by olivier2831
Wed Aug 23, 2023 5:47 pm
Forum: Wireless Networking
Topic: A bit better WiFi security with per-user PSK? [SOLVED]
Replies: 62
Views: 10045

Re: A bit better WiFi security with per-user PSK? [SOLVED]

Yesterday, I discovered Freeradius 3.2 recently introduced a DPSK module (ie myPSK, PPSK, iPSK, ...). This new module comes with a warning from its devs saying this module may suffer from scaling issues as it needs brute force iteration to process messages. I wonder if a single SSID can both have re...
by olivier2831
Tue Aug 22, 2023 8:19 pm
Forum: General
Topic: Filtering traffic with a LAN
Replies: 8
Views: 1889

Re: Filtering traffic with a LAN [SOLVED]

That was it: turning Hardware Offload to Off on one port forced my IP Firewall Filter rules to be run !

Thank you all very much for you help !
by olivier2831
Tue Aug 22, 2023 7:52 pm
Forum: General
Topic: Filtering traffic with a LAN
Replies: 8
Views: 1889

Re: Filtering traffic with a LAN

My setup is: PC1 ---- Switch1---- mAP ---- PC3 | PC2 --------- My test is ping PC3 from PC2 while PC1 is for configuring mAP. mAP's interface to PC3 is ether2 and mAP ether1 is connected is upstream Switch1. During my tests, PC2 could positively ping PC3. I was waiting this to fail due to my firewal...
by olivier2831
Tue Aug 22, 2023 6:13 pm
Forum: General
Topic: Filtering traffic with a LAN
Replies: 8
Views: 1889

Re: Filtering traffic with a LAN

I couldn't succeed yet, using a 6.49.6 powered mAP.

During my first testing, I wrote a couple of rules in IP/Firewall/Filter rules. Is it the correct tool to implement my rules ?
While searching, I also found potentially relevant forms in Bridge/Filters and Switch/Rules but I didn't use any of them.
by olivier2831
Tue Aug 22, 2023 1:23 pm
Forum: General
Topic: RFC8910 Captive Portal
Replies: 20
Views: 6376

Re: RFC8910 Captive Portal

Reading this not so old thread, have OP met success with RFC8910 since asking here ?
What about Win10 and Win11 clients ?
by olivier2831
Wed Aug 09, 2023 6:13 pm
Forum: General
Topic: Filtering traffic with a LAN
Replies: 8
Views: 1889

Re: Filtering traffic with a LAN

So I can leave both Ethernet interfaces (the LAN-facing and the printer-facing ones) belonging to the same single bridge ?
by olivier2831
Wed Aug 09, 2023 5:15 pm
Forum: General
Topic: Filtering traffic with a LAN
Replies: 8
Views: 1889

Filtering traffic with a LAN

Hello, On a remote site, I've got the following setup (details omitted): Cloud server ---<Internet> ------ Router ----- <LAN> ---- Printer The printer receives printing jobs from a Cloud server over the Internet. This cloud server has a fixed public IP address. The router is provided by an ISP. It c...
by olivier2831
Fri Jul 07, 2023 8:37 am
Forum: General
Topic: RouterOS USB Ethernet support
Replies: 7
Views: 2467

Re: RouterOS USB Ethernet support

Does RouterOS support the use of USB Ethernet adapters? If so, are there any caveats I should be aware of? This one should be officially supported (I never used it), at least on Mikrotik device with a USB A port. https://mikrotik.com/product/woobm An Ethernet alternative would be welcomed by sysadm...
by olivier2831
Mon Jun 26, 2023 10:21 am
Forum: General
Topic: New Ubiquiti Multi-gig RJ45 NBASE-T Transceiver not working
Replies: 48
Views: 9311

Re: New Ubiquiti Multi-gig RJ45 NBASE-T Transceiver not working

I always use the small LC connectors,
...
Thank you very much for this very informative reply.
by olivier2831
Wed Jun 21, 2023 7:45 pm
Forum: General
Topic: New Ubiquiti Multi-gig RJ45 NBASE-T Transceiver not working
Replies: 48
Views: 9311

Re: New Ubiquiti Multi-gig RJ45 NBASE-T Transceiver not working

If you can pull cat6e (or cat7) UTP cables, then you could pull FO cables as well. I thought FO is harder to deploy than copper as: you can't easily pull a FO along its connector end within small conduits (20mm diameter or so) FO required minimum bend radius you can't pull the FO cable with the sam...
by olivier2831
Fri Jun 16, 2023 2:25 pm
Forum: General
Topic: New Ubiquiti Multi-gig RJ45 NBASE-T Transceiver not working
Replies: 48
Views: 9311

Re: New Ubiquiti Multi-gig RJ45 NBASE-T Transceiver not working

I was looking for alternative to S+RJ10 because that runs as hot as fusion reactor. IMHO, having on the market, a 30$/€ SFP or SFP+ module supporting 1Gb/s or 2.5Gb/s would be very interesting if it can avoid such heat issues. If my memory serves me right, reducing speed from 10Gb/s to 2.5 Gb/s is ...
by olivier2831
Thu Jun 08, 2023 11:21 am
Forum: RouterBOARD hardware
Topic: USB -> RJ45 for PoE? Or will MT start putting USB-C ports?
Replies: 23
Views: 4022

Re: USB -> RJ45 for PoE? Or will MT start putting USB-C ports?

Some PoE Injectors accept Ethernet and DC power source (from 9V and up) and deliver some kind of PoE (passive 24V PoE, 48V PoE).
One such reference is TP-DCDC-1224.

I use one of these to power both a Raspberry and a WiFi AP using a single PowerBank.
by olivier2831
Mon May 29, 2023 11:12 am
Forum: RouterBOARD hardware
Topic: req: wAP AC w/ PoE passthrough
Replies: 6
Views: 3409

Re: req: wAP AC w/ PoE passthrough

No AC. Ax please.
Some Gigabit PoE-powered devices (hex PoE) can provide several (1,2 or 4) Gigabit PoE source ports.
I've never seen such devices with 2.5Gb/s input.
This could be very convenient if you don't want to sacrify thoughput/speed when using a single cable for two devices.
by olivier2831
Wed May 10, 2023 11:20 am
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 42931

Re: Newsletter #113 | May 2023

MT support told me that all their 10G SFP+ modules will work if forced in 2,5G mode. With exception of S+RJ10 as that requires 10G internal link. About heat, i would assume it is same as in RB5009, and that one has dedicated 10G SFP+ port. So as L009 comes in the same case cooling should not be iss...
by olivier2831
Wed May 10, 2023 8:53 am
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 42931

Re: Newsletter #113 | May 2023

- L009 series - the perfect RB2011 upgrade;
One interesting thing is that L009 has a 2.5Gb/s capable SFP slot (not an SFP+).
What kind of SFP modules can take advantage of it ?
What about heat with such 2.5 Gb/s SFP modules ?
by olivier2831
Fri May 05, 2023 4:01 pm
Forum: General
Topic: My PoE-powered Hex PoE turns off when I plugged a second port
Replies: 3
Views: 408

Re: My PoE-powered Hex PoE turns off when I plugged a second port

In principle, non-PoE NICs don't like 48V thrown at them (that kind of voltage can cause permanent damage to NICs). Therefore PoE power sourcing device (PSE) has to make sure that the other end is ready to accept the power. Not all PoE PSEs do the job correctly (and not all non-PoE devices react to...
by olivier2831
Fri May 05, 2023 12:04 pm
Forum: General
Topic: My PoE-powered Hex PoE turns off when I plugged a second port
Replies: 3
Views: 408

My PoE-powered Hex PoE turns off when I plugged a second port

Hello, My setup is: PoE Switch1 ----- PoE Switch2 ---- PoE Switch 3 where: Switch1 is a grid powered DLink DGS-1210-10P Switch 2 is an Hex PoE powered on ether1 by switch1 (with routerOS 6.48.6) Switch 3 is either: Switch 3A: a grid powered TP Link SG2428P Switch 3B: a grid powered Ubiquiti Edgeswit...
by olivier2831
Fri May 05, 2023 11:41 am
Forum: RouterBOARD hardware
Topic: Ideal ax travel router
Replies: 3
Views: 2298

Re: Ideal ax travel router

The simplest, cheapest option is to upgrade the USB-C port on the "lite" so that it will not only accept PD at a variety of voltage levels, it will act as a wired network interface. This will let you plug it into any USB-C laptop, with the router pulling power from it in exchange for prov...
by olivier2831
Mon Apr 17, 2023 11:48 am
Forum: RouterBOARD hardware
Topic: hAP ax lite
Replies: 86
Views: 17637

Re: hAP ax lite

I understood however for ISP purposes it might be better this way.
For curiosity's sake, why ?
by olivier2831
Fri Mar 24, 2023 10:25 am
Forum: RouterBOARD hardware
Topic: MikroTik cAP ax [cAPGi-5HaxD2HaxD] (r2)
Replies: 114
Views: 25347

Re: MikroTik cAP ax [cAPGi-5HaxD2HaxD] (r2)

My only beef with the size of the unit is that it's very large (228mm) for only a 2x2 MIMO. Unifi fit 4x4 MIMO into a smaller footprint (197mm). If "long range" is intended then the direct comparison would be the Unifi U6 LR which is 220mm across but it's 4x4 MIMO. So yes, I think this is...
by olivier2831
Thu Mar 23, 2023 10:47 am
Forum: General
Topic: 7.4.x and 7.5 SIP issue
Replies: 17
Views: 3707

Re: 7.4.x and 7.5 SIP issue

I can also confirm that after moving to ROS 7.8 from latest 6.X version SIP was broken. Once I updated the UDP timeout to 20 seconds, from the 10 seconds, and killed the existing connections in the IP->Firewall->Connections tab, then SIP started working again. No need to enable the SIP Helper, just...
by olivier2831
Mon Mar 13, 2023 2:25 pm
Forum: General
Topic: UPS Connection to hEX?
Replies: 10
Views: 1103

Re: UPS Connection to hEX?

Works!
What do you mean by that ? hEX to Cyberpower or hEX to APC ?
by olivier2831
Mon Feb 20, 2023 6:51 pm
Forum: General
Topic: How to mass configure 50 hAP units ?
Replies: 19
Views: 2009

Re: How to mass configure 50 hAP units ?

After reading Flashfig feature, maybe I should spit the config process in two steps: 1. apply common configuration "on bare metal" with Flashfig/Netinstall (updating firmware, creating system users, changing IP services ports, defining some firewall address list, uploading SSH keys) 2. app...
by olivier2831
Mon Feb 20, 2023 5:18 pm
Forum: General
Topic: How to mass configure 50 hAP units ?
Replies: 19
Views: 2009

How to mass configure 50 hAP units ?

Hello, How would you configure 50 hAP units spread over a building ? Which tools would you select ? Each unit should simply offer Internet access to WiFi users. Each unit a PoE uplink to a PoE switch. Each unit serves a personal SSID (users from room A connect to Room A's SSID , ...) without any roa...
by olivier2831
Wed Feb 01, 2023 5:09 pm
Forum: RouterBOARD hardware
Topic: hAP ax lite
Replies: 86
Views: 17637

Re: hAP ax lite

2.4Ghz Wi-Fi only.
Datasheet touts an increase in speed of up to 90% within 2.4GHz.
How is that possible ? Using 40 MHz channels ? Which part of WiFi6 enables this ?

An other question: what is a "dual-chain antenna"
by olivier2831
Fri Jan 20, 2023 11:10 am
Forum: Beginner Basics
Topic: Public IP - advantage, disanvantage
Replies: 4
Views: 421

Re: Public IP - advantage, disanvantage

A public IP can help for LetsEncrypt cert generation and renewal though opening port 80 to the Internet is scaring.
by olivier2831
Fri Jan 20, 2023 11:07 am
Forum: RouterBOARD hardware
Topic: MikroTik cAP ax [cAPGi-5HaxD2HaxD] (r2)
Replies: 114
Views: 25347

Re: MikroTik cAP ax [cAPGi-5HaxD2HaxD] (r2)

During latest CES, I read one vendor unveiled two WiFi7 devices: one device with a single "10G PoE++" port, the other with two "10G PoE++" ! I never heard of so-called 10G PoE++ (10 Gb/s and PoE++ over copper, I suppose) nor bonding two of them while 2.5Gb/s with is still hard to...
by olivier2831
Thu Jan 19, 2023 12:28 pm
Forum: RouterBOARD hardware
Topic: MikroTik cAP ax [cAPGi-5HaxD2HaxD] (r2)
Replies: 114
Views: 25347

Re: MikroTik cAP ax [cAPGi-5HaxD2HaxD] (r2)

A U6-lite vs U6-enterprise with the some output levels and the same series radio but 2x2 vs 4x4 and I'm able to get 100Mbps on the U6-Enterprise where I can't get the U6-lite to stay connected. On a side note, U6-Enterprise has one 2.5GbE RJ45 port (PoE in). A Mikrotik switch with 2.5 Gb/s and PoE ...
by olivier2831
Wed Jan 18, 2023 9:42 am
Forum: RouterBOARD hardware
Topic: MikroTik cAP ax [cAPGi-5HaxD2HaxD] (r2)
Replies: 114
Views: 25347

Re: MikroTik cAP ax [cAPGi-5HaxD2HaxD] (r2)

Disclaimer: I've worked as senior radio engineer for a major MNO for 15+ years. I was responsible for optimization of network coverage and performance of UMTS and LTE networks, so I believe I know sonething about antennae, MIMO, etc. Vast majority of simple WiFi devices (such as SOHO APs) have omni...
by olivier2831
Tue Jan 17, 2023 4:33 pm
Forum: RouterBOARD hardware
Topic: MikroTik cAP ax [cAPGi-5HaxD2HaxD] (r2)
Replies: 114
Views: 25347

Re: MikroTik cAP ax [cAPGi-5HaxD2HaxD] (r2)

Who needs whole preceding post to be quoted to be answered? Use "Post Reply"
So I should still look for a wall mount accessory, allowing horizontal mount on a wall.
by olivier2831
Tue Jan 17, 2023 10:13 am
Forum: RouterBOARD hardware
Topic: MikroTik cAP ax [cAPGi-5HaxD2HaxD] (r2)
Replies: 114
Views: 25347

Re: MikroTik cAP ax [cAPGi-5HaxD2HaxD] (r2)

I eagerly await some 4x4 designs. I have almost 100 U6-lites out there right now, but I've even replaced some with the U6-Pro and U6-Enterprise, the difference between 2x2 and 4x4 in a busy environment is unbelievable. I often met the case where I couldn't cover four rooms in a building in 5GHz ban...
by olivier2831
Tue Jan 17, 2023 9:52 am
Forum: SwOS
Topic: Does the CSS610-8G-2S+ SFP+ port with S+RJ10 support 2.5GbE speed? [SOLVED]
Replies: 10
Views: 5209

Re: Does the CSS610-8G-2S+ SFP+ port with S+RJ10 support 2.5GbE speed? [SOLVED]

Please confirm if this will work at 2.5GbE speeds.
If my memory serves me right, selecting 2.5 Gb/s over 10 Gb/s was not so easy to set, due to autoneg issues.
by olivier2831
Thu Dec 15, 2022 7:09 pm
Forum: General
Topic: Tri or dual radio WiFi CPE to extend wifi coverage
Replies: 6
Views: 512

Re: Tri or dual radio WiFi CPE to extend wifi coverage

Unfortunately, I can't use powerline nor coax on this location.
I ordered an OpenWRT-powered tri-radio router,(65 Euro without VAT) without detachable antenna, hoping its range would meet my requirements.
Audience would have been perfect except for its price.
by olivier2831
Wed Dec 14, 2022 2:38 pm
Forum: General
Topic: Tri or dual radio WiFi CPE to extend wifi coverage
Replies: 6
Views: 512

Re: Tri or dual radio WiFi CPE to extend wifi coverage

Lay a network cable, the best solution
Yes, I fully agree ;-))
Still, I'm looking for a second best wireless solution.
by olivier2831
Wed Dec 14, 2022 1:28 pm
Forum: General
Topic: Tri or dual radio WiFi CPE to extend wifi coverage
Replies: 6
Views: 512

Tri or dual radio WiFi CPE to extend wifi coverage

Hello, I've got a remote location in which wired (Ubiquiti) AP supporting both 2.4 and 5 GHz bands are installed. I a couple of spots where I can't easily extend current cabling but have weak Wifi signal issues. I'm looking for Mikrotik device that will work as a repeater/extender/whatever, connecti...
by olivier2831
Tue Nov 15, 2022 7:44 pm
Forum: General
Topic: How many Nat rules is too many Nat rules?
Replies: 10
Views: 803

Re: How many Nat rules is too many Nat rules?

I think you can search for CGNAT or deterministic NAT threads, within this list
by olivier2831
Thu Nov 10, 2022 2:04 pm
Forum: General
Topic: Can CSS610-8P-2S+IN power 24V passive PoE devices ? [SOLVED]
Replies: 10
Views: 1599

Re: Can CSS610-8P-2S+IN power 24V passive PoE devices ? [SOLVED]

Nice. This makes CSS610-8P one of rare MT devices (if not the only one) that actually do perform voltage (down)conversion internally. Which makes mentioning it in product page and user manuals even more important. CRS328-24P also provide "on demand 24 or 48V". I second datasheet could be ...
by olivier2831
Thu Nov 10, 2022 11:24 am
Forum: General
Topic: Can CSS610-8P-2S+IN power 24V passive PoE devices ? [SOLVED]
Replies: 10
Views: 1599

Re: Can CSS610-8P-2S+IN power 24V passive PoE devices ? [SOLVED]

Have the very same PoE options with my CRS328-24P which I know for sure does passive. Very inclined to believe the CSS610-8P does as well.
Thank you all for you valuable inputs.
I hope I'll test a CSS610-8P soon.
by olivier2831
Thu Nov 10, 2022 10:46 am
Forum: General
Topic: Can CSS610-8P-2S+IN power 24V passive PoE devices ? [SOLVED]
Replies: 10
Views: 1599

Re: Can CSS610-8P-2S+IN power 24V passive PoE devices ? [SOLVED]

Product page specifies power input as AC or 48-57 V DC . So where is the 24V for PoE out supposed to come in? CRS328-24P also has an integrated power supply. With it, you can select 24V or 48V PoE out on each interface. CRS328-24P datasheet is not explicit about this specific capability. If Mikroti...
by olivier2831
Wed Nov 09, 2022 1:19 pm
Forum: General
Topic: Can CSS610-8P-2S+IN power 24V passive PoE devices ? [SOLVED]
Replies: 10
Views: 1599

Can CSS610-8P-2S+IN power 24V passive PoE devices ? [SOLVED]

Hello,

Do you know if a CSS610-8P-2S+IN can power 24V passive PoE devices ?
Datasheet does not specify this.

Best regards
by olivier2831
Fri Oct 21, 2022 12:01 pm
Forum: General
Topic: Mikrotik devices and UPS / NUT ?
Replies: 5
Views: 2212

Re: Mikrotik devices and UPS / NUT ?

My linux servers are configured to perform actual reboot if shutdown sequence was due to UPS battery depletion so if mains returns during shutdown sequence, they simply reboot. Can you elaborate as I'm thinking about how I should properly protect some Linux NUC servers. The main point is from previ...
by olivier2831
Mon Oct 10, 2022 11:37 am
Forum: General
Topic: Comparing config files
Replies: 39
Views: 3473

Re: Comparing config files

I see no need to have customized sort keys, when people want fancy sorting they can do that themselves. But what I want is some sorting so that the output is always the same for the same configuration (i.e. addresses in a list, addresses on interfaces, etc) no matter how that configuration was cons...
by olivier2831
Fri Oct 07, 2022 2:58 pm
Forum: General
Topic: Comparing config files
Replies: 39
Views: 3473

Re: Comparing config files

I use this: https://sourceforge.net/projects/winmerge/ to visualy compare .rsc files Coincidence, I was about to open a new thread on a very similar topic. Lately I needed to compare two configs and spot differences using Meld (winmerge-like tool). Current and default export behaviour, IMHO, should...
by olivier2831
Fri Sep 09, 2022 11:33 am
Forum: RouterBOARD hardware
Topic: RB5009 PoE in doesn't work with Netgear GSM4210P PoE+ switch
Replies: 5
Views: 1582

Re: RB5009 PoE in doesn't work with Netgear GSM4210P PoE+ switch

RB5009 does not get the PoE power from the Netgear GSM4210P switch. The switch is PoE+ capable and supports all necessary standards (802.3at, 802.3af, passive POE, and compatible 802.3at). Different devices work perfectly, including Unifi APs and Raspberry PI. I also tried different Mikrotik device...
by olivier2831
Thu Sep 01, 2022 4:13 pm
Forum: RouterBOARD hardware
Topic: Smaller Netpower with PoE out
Replies: 6
Views: 953

Re: Smaller Netpower with PoE out

Hi, any Chance of having a smaller netpower with PoE af/at out in the near future? Netpower with 16 ports for an attic, barn or garage is a bit much. Maybe a Netpower with 8 Ports? I was also looking for such product to connect and power WiFi APs, up to 8 APs/per floor or so. For such use, having 2...
by olivier2831
Fri Aug 19, 2022 9:57 am
Forum: Announcements
Topic: Newsletter 107
Replies: 50
Views: 26451

Re: Newsletter 107

What kind of SFP/SFP+ module are you expecting, then ? Some GPON or similar ones ? Ethernet ones ? Others ? Actually it would be nice if MT could consider implementing EPON support directly in the products. Symmetric 10G/10G-EPON would look like the best choice for the future at this point. No spec...
by olivier2831
Tue Aug 16, 2022 7:27 pm
Forum: Announcements
Topic: Newsletter 107
Replies: 50
Views: 26451

Re: Newsletter 107

Good afternoon. Do you know what's missing from this great product? SFP or SFP+ port! Many ISPs run optical cable in apartment buildings.
What kind of SFP/SFP+ module are you expecting, then ? Some GPON or similar ones ? Ethernet ones ? Others ?
by olivier2831
Thu Jun 16, 2022 5:00 pm
Forum: General
Topic: How to SSH from RouterOS to a Linux host without password ?
Replies: 3
Views: 598

Re: How to SSH from RouterOS to a Linux host without password ?


No, the changelog just says that specifically in 7.3 there was a bug, which was fixed. 7.2.1 still works ok
OK thanks
by olivier2831
Thu Jun 16, 2022 4:39 pm
Forum: General
Topic: How to SSH from RouterOS to a Linux host without password ?
Replies: 3
Views: 598

Re: How to SSH from RouterOS to a Linux host without password ?

Looking at 7.4-beta4, I read:
*) ssh - fixed host key generation (introduced in v7.3);
It seems to me that what I'm looking for requires 7.3 (or 7.4 beta4), right ?
by olivier2831
Thu Jun 16, 2022 12:50 pm
Forum: General
Topic: How to SSH from RouterOS to a Linux host without password ?
Replies: 3
Views: 598

How to SSH from RouterOS to a Linux host without password ?

Hello, I'd like to connect from a RouterOS device to a remote Linux host without entering any password. I've read [1] and tried the command bellow without success. Before entering this command from RouterOS 6.48.5 terminal, I uploaded on my RouterOS device, both id_rsa and id_rsa.pub files from my o...
by olivier2831
Tue Jun 07, 2022 3:07 pm
Forum: General
Topic: NAT Logging
Replies: 3
Views: 687

Re: NAT Logging

Does anyone know of any Linux applications that allow you to do this?
nfdump itself allows for some filtering and aggregation.
I've not used those features, yet but would be very curious bto read about this.
by olivier2831
Tue May 31, 2022 5:26 pm
Forum: Announcements
Topic: MikroTik Devices Controller
Replies: 332
Views: 238531

Re: MikroTik Devices Controller

For start, start just with: Daily backup on text format, not binary on any point, and full configuration, included ssh keys, certificates, user-manager and dude database. Some instruments to compare backup among various days for see the changes. Some instrument for push configuration (like change N...
by olivier2831
Tue May 31, 2022 5:21 pm
Forum: Announcements
Topic: MikroTik Devices Controller
Replies: 332
Views: 238531

Re: MikroTik Devices Controller

I think issue today is the export/import isn't symmetrical, backup/restore is monolithic+binary, . What's missing is idempotent configuration file. And that's the first step to being able to monitor/apply a configuration in "controller software".
+1
by olivier2831
Fri May 27, 2022 10:04 am
Forum: General
Topic: NAT Logging
Replies: 3
Views: 687

Re: NAT Logging

Using Netflow/IPFix feature on Mikrotik devices, you can send 5 mins long reports to a configured data collector.
These reports can include NAT log data.
If your data collector is a Linux box, some Netflow/IPFix data collecting apps exist, nfdump being the one I tested.
by olivier2831
Mon May 09, 2022 10:00 am
Forum: RouterOS beta
Topic: Feature request: HSGMII for SFP >1Gbps synchronization. [SOLVED]
Replies: 22
Views: 15603

Re: [SOLVED !!!] Feature request: HSGMII for SFP >1Gbps synchronization. [SOLVED]

Does any 2.5Gb/s Ethernet interface support HSGMII or vice versa or both ? In other words, beside 2.5Gb/s speed, what does an Ethernet interface need to support to fully implement HSGMII ? Nope, it has to be 2.5g+HSGMII compatible. A lot of 2.5g interfaces are not HSGMII compatible. @Florian: Thank...
by olivier2831
Wed Apr 27, 2022 8:52 am
Forum: RouterOS beta
Topic: Feature request: HSGMII for SFP >1Gbps synchronization. [SOLVED]
Replies: 22
Views: 15603

Re: [SOLVED !!!] Feature request: HSGMII for SFP >1Gbps synchronization. [SOLVED]

Does any 2.5Gb/s Ethernet interface support HSGMII or vice versa or both ?
In other words, beside 2.5Gb/s speed, what does an Ethernet interface need to support to fully implement HSGMII ?
by olivier2831
Fri Apr 08, 2022 10:21 am
Forum: Announcements
Topic: NEWSLETTER 105
Replies: 56
Views: 46012

Re: NEWSLETTER 105

The mind boggles with all the potentional uses for the CRS504
Do Mikrotik QSFP28 modules exist ?
by olivier2831
Wed Mar 09, 2022 7:18 pm
Forum: Beginner Basics
Topic: NAT logging with IPFIX
Replies: 0
Views: 589

NAT logging with IPFIX

Hello, I've trying to set a NAT logging system up to comply with local regulation (copyright infringement and so on) in a RouterOS 6.48 environment. I'm completely new to NetFlow/IPFIX world. I intend (but I'm not 100% sure yet) to save NAT translation details and leave out outbound flows destinatio...
by olivier2831
Tue Mar 08, 2022 1:59 pm
Forum: General
Topic: RouterOS v7 - WAN failover
Replies: 8
Views: 9899

Re: RouterOS v7 - WAN failover

An unusual thing I can spot in your setup is that the gateway parameters of the routes towards the reference addresses are set to interface names rather than to IP addresses of the gateway devices; this is a possible setting but the gateway device must act as an ARP proxy, responding with its own M...
by olivier2831
Thu Mar 03, 2022 7:25 pm
Forum: Beginner Basics
Topic: Advices on NTP setup [SOLVED]
Replies: 7
Views: 2559

Re: Advices on NTP setup [SOLVED]

Thank you both for replying.
Now I think I understand why "proper" NTP is not installed by default.
Thanks again !
by olivier2831
Thu Mar 03, 2022 3:40 pm
Forum: Beginner Basics
Topic: Advices on NTP setup [SOLVED]
Replies: 7
Views: 2559

Advices on NTP setup [SOLVED]

Hello, I'm preparing a couple of RouterOS CCR1009 with 6.49 that should be used as the main router to the Internet for 100 or 200 users. I always thought I would these routers as the single time source for all LAN devices (switches, AP, a Linux server, ...). To my surprise, it seems the only include...
by olivier2831
Wed Mar 02, 2022 10:20 am
Forum: RouterBOARD hardware
Topic: PowerBox Pro - 4 Pair Input? Full .at output?
Replies: 7
Views: 1430

Re: PowerBox Pro - 4 Pair Input? Full .at output?

These seem like minor things, but they are limiting where I can use the PowerBox and hEX PoE. For curiosity's sake, what do you use the PowerBox and hEX PoE, for ? For powering WiFi AP? IP phones ? As in WiFi AP, Nbase-T is a growing requirement, maybe, a PowerBox-like device with a small port coun...
by olivier2831
Thu Feb 24, 2022 2:24 pm
Forum: General
Topic: Which use cases for CCR2004-1G-2XS-PCIe ?
Replies: 34
Views: 6106

Re: Which use cases for CCR2004-1G-2XS-PCIe ?

putting it into a Linux/BSD box instead of a 10G NIC or putting it into a server used for virtualization (Proxmox or just Debian).
How would a Linux host + CCR2004 card combo compare to a single server host with Open vSwitch ?
by olivier2831
Thu Feb 24, 2022 2:11 pm
Forum: General
Topic: Which use cases for CCR2004-1G-2XS-PCIe ?
Replies: 34
Views: 6106

Re: Which use cases for CCR2004-1G-2XS-PCIe ?

- option to have external power so it can run even when server is off (possibility for failsafe or doing ring networking that doesn't go down with server) Having a PoE-IN Gigabit port, instead of non-PoE one, would be awesome. It might even solve some booting issues and bring dual power sources (on...
by olivier2831
Wed Feb 23, 2022 6:32 pm
Forum: General
Topic: Which use cases for CCR2004-1G-2XS-PCIe ?
Replies: 34
Views: 6106

Which use cases for CCR2004-1G-2XS-PCIe ?

Hello,

I've just discovered this new CCR2004-1G-2XS-PCIe.

Given its unusual form factor, which use case do you foresee for it ?
In which kind of host machine would you plus it in ?

Best regards
by olivier2831
Tue Feb 15, 2022 10:24 am
Forum: Scripting
Topic: Compute IPv4 addresses in script [SOLVED]
Replies: 2
Views: 1594

Re: Compute IPv4 addresses in script [SOLVED]

A quick google search:
viewtopic.php?t=116253

PS I have not tested it.
Thanks for replying.

I haven't tested the above linked solution, yet but it seems to fit.
by olivier2831
Mon Feb 14, 2022 2:14 pm
Forum: RouterBOARD hardware
Topic: Force 2.5G or 5G
Replies: 8
Views: 6569

Re: Force 2.5G or 5G

I think this could be relevant
viewtopic.php?t=179294
by olivier2831
Fri Feb 11, 2022 6:08 pm
Forum: General
Topic: How to test PCC with src-address classifier ? [SOLVED]
Replies: 11
Views: 1607

Re: How to test PCC with src-address classifier ? [SOLVED]

Unless $GUESTIF is bridge1 , you assign connection-marks properly, but you do not translate connection-marks to routing-marks properly. That's why I was asking you to watch counters of all rules, not just the mark-connnection/per-connection-classifier ones. Yes, your are right: the rule that transl...
by olivier2831
Fri Feb 11, 2022 4:14 pm
Forum: General
Topic: How to test PCC with src-address classifier ? [SOLVED]
Replies: 11
Views: 1607

Re: How to test PCC with src-address classifier ? [SOLVED]

I should have written I ran latest tests with 6.49.2 box, not with 6.48.6 anymore.
by olivier2831
Fri Feb 11, 2022 4:10 pm
Forum: General
Topic: How to test PCC with src-address classifier ? [SOLVED]
Replies: 11
Views: 1607

Re: How to test PCC with src-address classifier ? [SOLVED]

What does /ip route print detail show? And what does /ip route rule export show? Also, disable the fasttrack rule, fasttracking bypasses mangle. What does /ip route print detail show? And what does /ip route rule export show? Also, disable the fasttrack rule, fasttracking bypasses mangle. [foo@Mikr...
by olivier2831
Fri Feb 11, 2022 10:36 am
Forum: General
Topic: PCC/6.48.6: cannot change src-address rule with WebFig
Replies: 2
Views: 385

Re: PCC/6.48.6: cannot change src-address rule with WebFig

I've just opened my very first ticket (SUP-74425) on this.
by olivier2831
Thu Feb 10, 2022 6:01 pm
Forum: General
Topic: How to test PCC with src-address classifier ? [SOLVED]
Replies: 11
Views: 1607

Re: How to test PCC with src-address classifier ? [SOLVED]

Does the order with which routes are entered matter ?
If positive, can you change it with WebFig ? In my testing, I couldn't move routes as I could move firewall routes.
by olivier2831
Thu Feb 10, 2022 5:54 pm
Forum: General
Topic: How to test PCC with src-address classifier ? [SOLVED]
Replies: 11
Views: 1607

Re: How to test PCC with src-address classifier ? [SOLVED]

The issue is as long as the hashing algo remains unknown as Sindy said, it's not easy to check if PCC is working at all ! Testing failover is easy, testing load balance is not, IMHO. /ip firewall mangle print stats will show you immediately whether the rules do something or not. Do you see any erro...
by olivier2831
Thu Feb 10, 2022 5:39 pm
Forum: Scripting
Topic: Compute IPv4 addresses in script [SOLVED]
Replies: 2
Views: 1594

Compute IPv4 addresses in script [SOLVED]

Hello,

I'm currently developing a script that starts with:
:global IP1 25.74.135.17
:global CIDR1 255.255.255.248
:global NET1 25.74.135.16
:global LEN1 29

As you may see, all four values could be computed from a single 25.74.135.17/29 value.
How can this done, efficiently on 6.4X ?

Best regards
by olivier2831
Thu Feb 10, 2022 5:30 pm
Forum: General
Topic: How to test PCC with src-address classifier ? [SOLVED]
Replies: 11
Views: 1607

Re: How to test PCC with src-address classifier ? [SOLVED]

It's easier to test with dst-address, you won't have to reconfigure anything, just select different target address for e.g. ping. To make sure it doesn't work because of some mistake elsewhere, enable logging for these PCC rules (log=yes log-prefix="PCC1"), and you'll see what they do, in...
by olivier2831
Thu Feb 10, 2022 5:20 pm
Forum: General
Topic: PCC/6.48.6: cannot change src-address rule with WebFig
Replies: 2
Views: 385

Re: PCC/6.48.6: cannot change src-address rule with WebFig

May I add that classifier (src-address, both-addresses, ...) can be changed through Winbox64.
It works with CLI and Winbox.
It doesn't with WebFig.
by olivier2831
Thu Feb 10, 2022 12:40 pm
Forum: General
Topic: How to test PCC with src-address classifier ? [SOLVED]
Replies: 11
Views: 1607

How to test PCC with src-address classifier ? [SOLVED]

Hello, I'm discovering PCC on CCR1009 with 6.48.6. At the moment, I'm focusing on src-address classifier as it look like the simplest classifier to check. My setup is: Webserver ------ WAN1 router ------ CCR1009 ------- My PC |----------------WAN2 router -------------| CCR1009 config includes: 7 ;;;...
by olivier2831
Thu Feb 10, 2022 12:13 pm
Forum: General
Topic: PCC/6.48.6: cannot change src-address rule with WebFig
Replies: 2
Views: 385

PCC/6.48.6: cannot change src-address rule with WebFig

Hello, Supposing whatever is shown with CLI is the Source Of Truth, on a CCR1009 powered with 6.48.6, I'm seeing the following issue. I can set a PCC rule to use src-address as with: set [ find comment=PCC1 ] per-connection-classifier=src-address:2/0 I can also set this rule to use both-addresses in...
by olivier2831
Wed Feb 09, 2022 7:57 pm
Forum: RouterBOARD hardware
Topic: Force 2.5G or 5G
Replies: 8
Views: 6569

Re: Force 2.5G or 5G

resurecting. Setting negotiation rates still doesn't work on these. I'm wanting to use this to copper feed a netpower 16 on the roof in a router-on-a-stick kind of setup. I don't know if I'm going to get a reliable 10G error free and I got these specific modules thinking I would be able to set 2.5G...
by olivier2831
Wed Feb 09, 2022 7:15 pm
Forum: Beginner Basics
Topic: Can't sign a certificate from script
Replies: 0
Views: 347

Can't sign a certificate from script

Hello, I'm writing a script with which I want to set HTTPS service up. This script is copied to my 6.48 CCR1009 box through an scp command and then executed throuh a RouterOS /import. Everything seems to working fine except for the last two statements. These statements are: /certificate sign myrootc...
by olivier2831
Wed Feb 09, 2022 5:58 pm
Forum: Beginner Basics
Topic: PCC example: What does Accept mean in prerouting chain ? [SOLVED]
Replies: 2
Views: 1684

Re: PCC example: What does Accept mean in prerouting chain ? [SOLVED]

The rules in your mean, that traffic to the IP-address ranges 10.111.0.0/24 and 10.112.0.0/24 that enters the Router of the LAN-Interface will be accepted, so the following mangle rules did not affect the traffic (first match). If you do not use such rules it the PCC rules could route your traffic....
by olivier2831
Wed Feb 09, 2022 5:03 pm
Forum: Beginner Basics
Topic: PCC example: What does Accept mean in prerouting chain ? [SOLVED]
Replies: 2
Views: 1684

PCC example: What does Accept mean in prerouting chain ? [SOLVED]

Hello, Looking at [1], there are the following rules : / ip firewall mangle add chain=prerouting dst-address=10.111.0.0/24 action=accept in-interface=LAN add chain=prerouting dst-address=10.112.0.0/24 action=accept in-interface=LAN Those are explained with With policy routing it is possible to force...
by olivier2831
Wed Feb 09, 2022 3:23 pm
Forum: Beginner Basics
Topic: SD Card Uses
Replies: 9
Views: 3991

Re: SD Card Uses

For the rb750gr3, if you're not using "the dude," is there any good use for an sd card? What else could it be used for, and is it worth it/useful?
For curiosity's sake, if you're using "the dude", what else these cards could be used for ?
by olivier2831
Wed Feb 09, 2022 3:20 pm
Forum: Beginner Basics
Topic: How to access WebFig through SSH ? [SOLVED]
Replies: 2
Views: 1286

Re: How to access WebFig through SSH ? [SOLVED]

It should work, just don't forget to enable it on RB:
/ip ssh set forwarding-enabled=local
It works !
If I'm not mistaken, too bad WebFig doesn't show this option, but at least, forwarding-enabled can also be set to both.
Thanks !
by olivier2831
Wed Feb 09, 2022 10:01 am
Forum: RouterOS beta
Topic: Let's Encrypt cert renewal
Replies: 31
Views: 21846

Re: Let's Encrypt cert renewal

I'm sorry if my questions seem obvious for many (most ?) but: Until MikroTik decides to properly document the feature (and give it a UI probably), Have anyone a pointer on this command within or outside (blogs, ...) Mikrotik documentation ? What are requirements to test this function in a lab ? Havi...
by olivier2831
Wed Feb 09, 2022 9:34 am
Forum: RouterOS beta
Topic: Let's Encrypt cert renewal
Replies: 31
Views: 21846

Re: Let's Encrypt cert renewal

Most of the residential ISP's have a drop rule for port 22 so... .
What do you mean by that ?
The CPE the IPSs provide, forbids incoming connections from the Internet to port 22 ?
by olivier2831
Wed Feb 09, 2022 9:31 am
Forum: Beginner Basics
Topic: How to access WebFig through SSH ? [SOLVED]
Replies: 2
Views: 1286

How to access WebFig through SSH ? [SOLVED]

Hello, I was thinking about restricting WebFig to localhost and then access WebFig through SSH for the sake of having one less service open the world. I was thinking of using something like "ssh -f -N foo@1.2.3.4 -LXXX:127.0.0.1:80" but my attempts failed. How can you do that, from a Linux...
by olivier2831
Mon Feb 07, 2022 5:42 pm
Forum: Beginner Basics
Topic: Where is /system script's copy-from doc ?
Replies: 0
Views: 524

Where is /system script's copy-from doc ?

Hello, 1. Where can I read anything (example, doc, ...) regarding /system script parameters and options ? It is missing from [1], if I'm not mistaken. 2. Is there a reliable way to create a script from an existing file (either fetching or copying from disk or with HTTP) ? [1] https://help.mikrotik.c...
by olivier2831
Mon Feb 07, 2022 3:18 pm
Forum: Beginner Basics
Topic: How to write idempotent script
Replies: 23
Views: 3371

Re: How to write idempotent script

you can not put "reset" inside (re)config file
must be doed separately, waith the reboot, then apply the (new) config
Life is hard, anyway ;-))
by olivier2831
Mon Feb 07, 2022 3:02 pm
Forum: Beginner Basics
Topic: How to write idempotent script
Replies: 23
Views: 3371

[SOLVED] Re: How to write idempotent script

I often get errors because I'm trying to add something that already exists. How can I solve this ? Is there anything like "delete ifexists" like in SQL scripts ? Any of the above approaches above can work to re-write an exported config, pick you poison. All have pro/cons: the issue with &...
by olivier2831
Fri Feb 04, 2022 7:50 pm
Forum: Beginner Basics
Topic: How to write idempotent script
Replies: 23
Views: 3371

How to write idempotent script

Hello, I'm discovering RouterOS scripting. I often get errors because I'm trying to add something that already exists. For instance, if I run twice a script that includes the following lines, it would fail the second time. /interface vlan add interface=bridge1 name=vlan2 vlan-id=2 How can I solve th...
by olivier2831
Wed Jan 26, 2022 10:26 am
Forum: RouterOS beta
Topic: [Feature Request] Dot1x Multiple Host Auth in a single port
Replies: 4
Views: 2201

Re: [Feature Request] Dot1x Multiple Host Auth in a single port

I don't this is even possible. While I never used it myself, from what I know Dot1x uses MAC address to authenticate clients. This means that your MT sees traffic from all clients connected to a port under a MAC of the dumb switch. The moment a single client behind that switch passes authentication...
by olivier2831
Tue Jan 18, 2022 7:01 pm
Forum: General
Topic: CGN NAT ( NAT444 ) help
Replies: 39
Views: 6294

Re: CGN NAT ( NAT444 ) help

One good thing for me is that it is super easy and quick to lookup and identify what customer is being referenced when I now get one of those copyright notices where some customer downloaded a copyrighted movie. These notices provide two pieces of information ( Live-IP-Address and the Port-Number )...
by olivier2831
Tue Jan 18, 2022 5:07 pm
Forum: General
Topic: CGN NAT ( NAT444 ) help
Replies: 39
Views: 6294

Re: CGN NAT ( NAT444 ) help

Be aware that only 63 concurrent DNS requests are possible, still. You might also want to aggressively time down your UDP timers in connection tracking, when using such a low amount of ports per user. Can you elaborate, both above points, please ? In the first one, are you implying DNS requests pas...
by olivier2831
Tue Jan 18, 2022 4:55 pm
Forum: General
Topic: CGN NAT ( NAT444 ) help
Replies: 39
Views: 6294

Re: CGN NAT ( NAT444 ) help

Limiting the ports per user does not mean there will be a hard limit of connections=ports. Mikrotik does port-overloading. This means it can re-use the same port for another destination.
But still, original and re-used ports are always binded to the very same private IP, right ?
by olivier2831
Tue Jan 18, 2022 10:48 am
Forum: General
Topic: Advice on certificates for managing Mikrotik devices with www-ssl ? [SOLVED]
Replies: 6
Views: 2488

Re: Advice on certificates for managing Mikrotik devices with www-ssl ? [SOLVED]

Then make your life easy and forget about certificates and https. It's not that they are too difficult, but it is some extra work, and I don't see how they can add anything for your use case. Allow only ssh, and if someone wants WebFig, they can use ssh port forwarding to access it. Since ssh alrea...
by olivier2831
Mon Jan 17, 2022 6:26 pm
Forum: General
Topic: CGN NAT ( NAT444 ) help
Replies: 39
Views: 6294

Re: CGN NAT ( NAT444 ) help ( almost RESOLVED )

Well - I think I finally got my NAT444 working I don't know if it's the appropriate place to ask, but what happens if a customer consumes too much TCP or UDP ports ? 1. Is this something that is logged ? 2. From end user perspective, does it trigger some 5XX HTTP error code ? 3. What are the networ...
by olivier2831
Mon Jan 17, 2022 3:40 pm
Forum: General
Topic: Advice on certificates for managing Mikrotik devices with www-ssl ? [SOLVED]
Replies: 6
Views: 2488

Advice on certificates for managing Mikrotik devices with www-ssl ? [SOLVED]

I'm about to remotely deploy 30 RouterOS 6.4X devices. Some are Internet-facing while some are not. I would like to manage them with WebFig and HTTPS, if possible, along with SSH. Only a couple of Linux PCs (from sysadmin team) will ever need to access WebFig. May I add, that I'm not familiar with P...
by olivier2831
Thu Jan 06, 2022 11:03 am
Forum: RouterBOARD hardware
Topic: hAP AC2 successor (WiFi 6 + nBase-T ???)
Replies: 13
Views: 7427

Re: hAP AC2 successor (WiFi 6 + nBase-T ???)

I'm quite sure that there's no technical need, but most customers don't know and simply see: "Delta offers 8Gbit", "OpenFiber offers 1Gbit". Someone selling 10G/s shared among 100 users may even get more success than an other one sharing 1G/s among 5 ! That's the reason why I wo...
by olivier2831
Tue Jan 04, 2022 3:03 pm
Forum: RouterBOARD hardware
Topic: hAP AC2 successor (WiFi 6 + nBase-T ???)
Replies: 13
Views: 7427

Re: hAP AC2 successor (WiFi 6 + nBase-T ???)

Hopeful MikroTik have 6E in their roadmap because its revolutionary .... Why revolutionary? The Great 6 GHz Invasion – Here Come the Wi-Fi 6E Clients! Key Takeaway But with all due respect to some of the Wi-Fi 6E naysayers, “you just don’t get it.” Wi-Fi 6E is not just another ho-hum technology upg...
by olivier2831
Tue Jan 04, 2022 2:21 pm
Forum: RouterBOARD hardware
Topic: hAP AC2 successor (WiFi 6 + nBase-T ???)
Replies: 13
Views: 7427

Re: hAP AC2 successor (WiFi 6 + nBase-T ???)

We are hoping / wondering if a hAP AC2 successor is on the roadmap, with at least: - WiFi 6 support - nBase-T / 2.5G / 5G RJ45 port(s) It's not that the technology is currently unavailable or too expensive, brands like TP-Link offer WiFi 6 capable routers for < €40. Preferable in a semi robust tiny...
by olivier2831
Fri Dec 31, 2021 7:02 pm
Forum: RouterOS beta
Topic: Let's Encrypt cert renewal
Replies: 31
Views: 21846

Re: Let's Encrypt cert renewal

I'm not sure if Web-Fig is a web server or as a separate service, It could be a simple Web-Fig enable/disable functionality. I don't mine the port 80 if they cant use it to log in. +1 IMHO, the simplest solution would be to dedicate a port to cert renewal and WebFig out of it. I think LetsEncrypt m...
by olivier2831
Fri Dec 31, 2021 5:19 pm
Forum: General
Topic: MIKROTIK as OLT/GEPON
Replies: 13
Views: 21591

Re: MIKROTIK as OLT/GEPON

Resurrecting this old thread, I think having a Mikrotik device supporting OLT functions would make sense in hospitality (hotels, ...). Currently among others, Zyxel or Ubiquiti address these markets with GPON OLT/ONT devices. In a single hotel, you can easily have 100 ONT integrating Ethernet or/and...
by olivier2831
Fri Dec 31, 2021 4:42 pm
Forum: General
Topic: Is 24V PoE required to power R5009 ?
Replies: 3
Views: 1139

Re: Is 24V PoE required to power R5009 ?

I plugged my r5009 to an old DLink DES-1210-08P (Fast Ethernet only): no powering on. I left it connected while working on other things during at least 15 minutes, and I saw it powered on ! Looking at DHCP logs, if necessary, I think I can have an exact measure of elapsed time between cord plug and ...
by olivier2831
Fri Dec 31, 2021 2:23 pm
Forum: General
Topic: Is 24V PoE required to power R5009 ?
Replies: 3
Views: 1139

Is 24V PoE required to power R5009 ?

Hello, In my lab I've got: a 7.0.5 powered r5009, a 6.48.6-powered hex PoE a 6.48.6-powered RB2011 and an old DLink DGS-1210-10P switch in my lab. When I plug an Ethernet patch cord between this DLink switch and the hex PoE, this later one powers up. When I plug it into the r5009, it remains powered...
by olivier2831
Tue Dec 28, 2021 10:07 am
Forum: RouterBOARD hardware
Topic: CRS328-24P-4S+RM - 24x7 fans or temperature sensitive?
Replies: 68
Views: 39433

Re: CRS328-24P-4S+RM - 24x7 fans or temperature sensitive?

Is anyone else seeing something similar, specifically with respect to SFP+ 10GbE transceivers? I am planning to introduce another 10GbE computer on one of the other SFP+ ports when its 10GbE NIC arrives and am weary about how the switch will behave. 10GbE over copper seems to come with a lot of hea...
by olivier2831
Thu Dec 23, 2021 4:20 pm
Forum: General
Topic: How do you configure RouterOS? Poll
Replies: 11
Views: 2204

Re: How do you configure RouterOS? Poll

This is just a small poll to see how people are configuring their RouterOS. I mostly configure RouterOS device using WebFig and I'm not satisfied doing so, as you may guess, when using a GUI, it is very easy to forget to configure something (ie changing SSH port, ...). I tried to configure using te...
by olivier2831
Tue Dec 21, 2021 2:40 pm
Forum: Wireless Networking
Topic: Should Mikrotik achieve Wi-Fi Alliance certification on popular APs?
Replies: 9
Views: 5166

Re: Should Mikrotik achieve Wi-Fi Alliance certification on popular APs?

I was absolutely blown away by my early testing of caps man. When I started applying the flexibility of routerOS to caps-man, I was really excited by all the things I could do with it. SSIDs that could shut down if a gateway was unreachable. Per device passwords. ACLs. Near instant feed back of eve...
by olivier2831
Mon Dec 20, 2021 8:01 pm
Forum: General
Topic: feature request: add Port List to firewall
Replies: 48
Views: 19975

Re: feature request: add Port List to firewall

... finally "nice to have" enhancements. My guess is that this one falls into the latter category.
Agreed
by olivier2831
Mon Dec 20, 2021 3:56 pm
Forum: General
Topic: feature request: add Port List to firewall
Replies: 48
Views: 19975

Re: feature request: add Port List to firewall

I agree. In order not to view al the open ports just in one place, would be very useful. I am opening ports now that I might change in the future, it would be useful to havd them all listed together. I don't think I currently need to reuse a Port List several times in the same config but I would su...
by olivier2831
Fri Dec 17, 2021 5:13 pm
Forum: General
Topic: What to do when WebFig's left menu is missing ?
Replies: 16
Views: 4398

Re: What to do when WebFig's left menu is missing ?

Is it possible that the seller/shop has installed some sort of branding on these devices? The vendors have the option to hide it from you, if they preconfigure the devices in some way I don't think the seller/shop ever customized these devices as: 1. I bought them from several different sources 2. ...
by olivier2831
Fri Dec 17, 2021 11:57 am
Forum: General
Topic: What to do when WebFig's left menu is missing ?
Replies: 16
Views: 4398

What to do when WebFig's left menu is missing ?

Hello,

On various 6.4X Mikrotik boxes, WebFig's left menu (the one with CAPSMAN, Wireless, Interfaces, ...IP, System, ...) is sometimes missing.

Where does it come from ?
What can I can do to have it back ?

Best regards
by olivier2831
Wed Dec 15, 2021 6:24 pm
Forum: General
Topic: How to connect to CCR1009 through serial/USB cable ?
Replies: 0
Views: 2992

How to connect to CCR1009 through serial/USB cable ?

Hello, I'm trying to connect to a 6.48.6 powered CCR1009 through a serial/USB cable. I'm trying to connect through a: - a Linux-enabled laptop (some variant of Ubuntu) - a serial to USB cable - and CuteCom app. As I'm not familiar at all with serial/console connection, it's quite possible that I wou...
by olivier2831
Wed Dec 15, 2021 12:44 pm
Forum: General
Topic: SSH or HTTPS access in case of timing issues
Replies: 4
Views: 1216

Re: SSH or HTTPS access in case of timing issues

Question 2: SSH as being immune to timing issues ? I never had a Problem with Mikrotik and timing. Even when the Device think it`s still 1970 =) Question 3: Suggest using some other tools (Wireguard, OVPN, ...)? In the context of a Productive and/or Business Environment , i think it is "Best P...
by olivier2831
Tue Dec 14, 2021 7:07 pm
Forum: General
Topic: Explain why Netpower 16P SFP+ shows all-0 Rx stats
Replies: 2
Views: 677

Re: Explain why Netpower 16P SFP+ shows all-0 Rx stats

- that all values within Rx Stats (Rx Unicast, Rx Broadcast, Rx Pause, ...) show 0 while Tx Stats values are non-zero
May I add that looking at the CCR2004 port to which this Netpower 16P is connected to, I see normal stats with non-zero values in both Rx and Tx Stats.
by olivier2831
Tue Dec 14, 2021 6:59 pm
Forum: General
Topic: Explain why Netpower 16P SFP+ shows all-0 Rx stats
Replies: 2
Views: 677

Explain why Netpower 16P SFP+ shows all-0 Rx stats

Hello, On a remote location I'm reading stats provided by a 6.48.4-powered NetPower 16P. This box has 2 SFP+ slots. One is populated with a Mikrotik RJ+10 module. Looking at this populated slot, I see: - that all values within Rx Stats (Rx Unicast, Rx Broadcast, Rx Pause, ...) show 0 while Tx Stats ...
by olivier2831
Tue Dec 14, 2021 3:08 pm
Forum: RouterOS beta
Topic: MLAG not Work in RouterOS 7.1 Stable
Replies: 13
Views: 6588

Re: MLAG not Work in RouterOS 7.1 Stable

What version are you running now? Because on v7.1 stable the problem still exists ..
Wasn't MLAG dedicated to a few Mkt devices (CRS3XX, if I'm not mistaken) ?
by olivier2831
Fri Dec 10, 2021 4:36 pm
Forum: General
Topic: SSH or HTTPS access in case of timing issues
Replies: 4
Views: 1216

SSH or HTTPS access in case of timing issues

Hello, I'm thinking about using SSH or HTTPS (with self-signed cert) to remotely manage RouterOS devices. As it involves certificate, I always viewed HTTPS as being time sensitive in the sense that if, for any reason, a device has a bogus time and date, HTTPS cannot be used anymore. To my knowledge,...
by olivier2831
Thu Dec 09, 2021 7:49 pm
Forum: General
Topic: Can enable www-ssl on any port but 443
Replies: 2
Views: 1730

Re: Can enable www-ssl on any port but 443 [SOLVED]

You need to find what uses the port, there are not so many things on router that can do it. If it's not something in IP->Services, it could be VPN server (SSTP, OpenVPN), possibly few other things I don't remember just now. I'd try to export config and look for "443" in there. I exported ...
by olivier2831
Thu Dec 09, 2021 6:44 pm
Forum: General
Topic: Can enable www-ssl on any port but 443
Replies: 2
Views: 1730

Can enable www-ssl on any port but 443

Hi, On a RB2011, I'm trying to enable www-ssl with my self-signed cert. I followed these steps [1]. It does work when setting ssl port to many value but 443, as if this 443 was already used for something else. Using webfig, after changing port value to 443 and clicking over Apply button, an "in...
by olivier2831
Wed Nov 24, 2021 4:25 pm
Forum: General
Topic: [Feature Request] More Control over Non-Automatic Negotiation Speeds of SFP+
Replies: 6
Views: 1412

Re: [Feature Request] More Control over Non-Automatic Negotiation Speeds of SFP+

What is the use case? Autonegotiation is mandatory in the standards for 1000BASE-T and 10GBASE-T (includes the lesser 2.5GBASE-T & 5GBASE-T rates). Over copper, 10Gb/s can generate a lot of heat. Forcing 2.5 or 5Gb/s may reduce this heat and give increased speed over 1Gb/s. I back this request ...
by olivier2831
Thu Nov 18, 2021 2:05 pm
Forum: General
Topic: Hardware for 10Gbps bandwidth test
Replies: 8
Views: 3244

Re: Hardware for 10Gbps bandwidth test

Not sure if all thunderbolt 10Gbps adapters are equally good. Found https://www.servethehome.com/usb-3-1-gen1-to-5gbe-network-adapter-guide/ for 5Gb/s adapters but no such comparison for 10Gb/s networking. Also found https://www.qnap.com/en/product/qna-t310g1s with Linux support, it seems. I would ...
by olivier2831
Fri Nov 12, 2021 5:56 pm
Forum: Wireless Networking
Topic: DPSK/PPSK individual PSK without preconfig
Replies: 6
Views: 6497

Re: DPSK/PPSK individual PSK without preconfig

However you could configure 2 access methods on the same AP (with a different SSID) and have most devices connected with username/password and reserve the other one for the few devices that cannot do it. Can you specify a VLAN in which each device with an individual PSK would be allocated into ? Th...
by olivier2831
Fri Nov 12, 2021 5:43 pm
Forum: Wireless Networking
Topic: DPSK Dynamic WPA2 PSK support [SOLVED]
Replies: 36
Views: 30705

Re: DPSK Dynamic WPA2 PSK support [SOLVED]

The more I use Mikrotik wireless... The more I love Ruckus.
Which Ruckus AP do you prefer within 100-150 Euros price range ?
by olivier2831
Wed Nov 10, 2021 4:57 pm
Forum: RouterBOARD hardware
Topic: RB 4011 GS+RM SFP+ Port not working on 10gbp
Replies: 3
Views: 5034

Re: RB 4011 GS+RM SFP+ Port not working on 10gbp

I would disable "Auto-Negotiation" and play with the Speeds on the Mikrotik. My 2 cents: Lately, I had unsuccessful experiences trying to (remotely) control the speed/rate between 2 Mikrotik devices connected through an SFP+ 10Gb/s module over a 25m Cat6A copper wire. One of the two boxes...
by olivier2831
Tue Nov 09, 2021 6:38 pm
Forum: General
Topic: How to log ARP table on 6.48
Replies: 0
Views: 976

How to log ARP table on 6.48

Hello,

For compliance reasons, I need to log ARP entries from a 6.48-powered CCR1009.
I need entries such as :

<timestamp> <MAC> <private IP>

How can I do that ?
If necessary I've got a local Debian host I can push entries or files to.

Best regards
by olivier2831
Tue Nov 09, 2021 6:33 pm
Forum: General
Topic: How to log NAT translation on 6.48 ?
Replies: 0
Views: 998

How to log NAT translation on 6.48 ?

Hello, For compliance reasons, I need to log NAT translations occurring on a 6.48-powered CCR1009. I need to log entries such as: <timestamp> <proto> <private_src_ip> <private_src_port> <public_src_ip> <public_src_port> If necessary, I've got a Debian host close to the CCR1009 where I can push log e...
by olivier2831
Tue Nov 09, 2021 6:11 pm
Forum: General
Topic: How do we properly perform CGNAT on a MikroTik Router for customers?
Replies: 23
Views: 14439

Re: How do we properly perform CGNAT on a MikroTik Router for customers?

I m testing with this, but it has some problems with streams plataforms like netflix and microsoftstream.
Can you describe those problems ?
by olivier2831
Tue Nov 09, 2021 1:24 pm
Forum: General
Topic: RB5009 Questions on rackmount kit ? [SOLVED]
Replies: 2
Views: 1171

Re: RB5009 Questions on rackmount kit ? [SOLVED]

Looking at the picture you can make short ears and connectors by beaking off/out the parts. If you do that the long ears are destroyed.
I didn't notice this : thank you very much for pointing this !
This solves my first question !

Thanks again
by olivier2831
Tue Nov 09, 2021 11:10 am
Forum: General
Topic: RB5009 Questions on rackmount kit ? [SOLVED]
Replies: 2
Views: 1171

RB5009 Questions on rackmount kit ? [SOLVED]

Hello, I've just got a new RB5009 and its rackmount kit. 1. The rackmount kit I bought has K-79 reference on purchase order or billing documents. On its packaging RME5009 is printed. The kit content seems appropriate to mount a single or two RB5009 in a 19'' rack as it includes 2 long ears, 16 screw...
by olivier2831
Mon Nov 08, 2021 2:40 pm
Forum: Beginner Basics
Topic: VLAN configuration RB4011IGS+RM once again
Replies: 18
Views: 5070

Re: VLAN configuration RB4011IGS+RM once again

When I either ping 10.119.0.1 from ether3 or ether7, I've got no answer.
For an unknown reason, my config started to work, so I'm sorry for the noise.

Anyway, may I re-iterate that for reference, IMHO, adding details on the way addresses are set, should help.
by olivier2831
Mon Nov 08, 2021 11:43 am
Forum: Beginner Basics
Topic: VLAN configuration RB4011IGS+RM once again
Replies: 18
Views: 5070

Re: VLAN configuration RB4011IGS+RM once again

Hi everyone, after days of reading how-tos (e.g. https://forum.mikrotik.com/viewtopic.php?t=143620 and many others) and struggling with the configuration I head to you and ask for help. Attached you can find a diagram of the network I want to achieve and an rsc file with the configuration my latest...
by olivier2831
Thu Nov 04, 2021 11:02 am
Forum: General
Topic: Captive Portal API RCF8908
Replies: 11
Views: 3606

Re: Captive Portal API RCF8908

Google, FB and all the other are going to REMOVE LOGIN FROM INTERNAL WEBVIEW.
If this "notification" will not be "focused" nobody will ever be able to login using OAuth2 in a few months
Can you elaborate a bit ?
Any pointer to Google or FB intents on the matter ?
by olivier2831
Wed Nov 03, 2021 5:41 pm
Forum: General
Topic: RB5009 Which firmware to use ?
Replies: 2
Views: 1339

RB5009 Which firmware to use ?

Hello, I need to deploy a new router on a remote site. This router must NAT and load balance traffic from for 3 internal LAN to two WAN uplinks (from the same ISP). Each uplink has 500 or 600 Mb/s download capacity. I've just got a brand new RB5009UG+S+IN (with 7.0.5 installed). I'm hesitant to use ...
by olivier2831
Mon Oct 18, 2021 7:21 pm
Forum: General
Topic: Questions on Wiki's PCC page
Replies: 1
Views: 523

Questions on Wiki's PCC page

Hello, After reading it several times, I still have some question on [1]. / ip firewall mangle add chain=prerouting dst-address=10.111.0.0/24 action=accept in-interface=LAN add chain=prerouting dst-address=10.112.0.0/24 action=accept in-interface=LAN With policy routing it is possible to force all t...
by olivier2831
Thu Oct 14, 2021 5:02 pm
Forum: RouterBOARD hardware
Topic: Powering cAP ac from another cAP
Replies: 5
Views: 3033

Re: Powering cAP ac from another cAP

I want to power a cAP ac from another cAP ac with the included 24v power supply, but I noticed that its listed maximum power output on the second port is 500mA. A cAP ac takes up to 13w, which equates to 540mA with 24 volts. Is this power requirement close enough, or is it too risky? Note that the ...
by olivier2831
Wed Oct 13, 2021 11:39 am
Forum: General
Topic: Can't edit PCC settings with WebFig [BUG ?]
Replies: 0
Views: 611

Can't edit PCC settings with WebFig [BUG ?]

Hello, Some times ago I configured a CRS328 that used 3 DSL lines to connect to the Internet. I followed [1] to edit the different rules. Months later, I changed my config when this CRS328 became connected to the Internet through a single FTTH line. Doing so, I mostly disabled existing rules. Now, t...
by olivier2831
Tue Oct 12, 2021 10:00 am
Forum: RouterBOARD hardware
Topic: CRS328 and POE problems (not standard 802.3af?), Flapping Port?
Replies: 5
Views: 2746

Re: CRS328 and POE problems (not standard 802.3af?), Flapping Port?

And I wonder if there is a reason that CRS328 were taken out of the assortment?
CRS328 is unavailable in France, these days.
by olivier2831
Mon Oct 11, 2021 11:56 am
Forum: RouterBOARD hardware
Topic: SFP+ Link Up but no Traffic
Replies: 2
Views: 2612

Re: SFP+ Link Up but no Traffic

Hi I have the following configuration: R1: CCR1072-1G-8S+ on 6.41 with SPF+ port 4 using the following SM Single Strand fibre SFP+ module S+23LC10D. At the other end of this link, across about 2.5km we have the following: R2: CCR1009-7G-1C-1S+ on 6.42.7 with SFP+ port using the following SM Single ...
by olivier2831
Tue Oct 05, 2021 9:13 am
Forum: RouterBOARD hardware
Topic: RB5009 and S-RJ01 SFP speed problem
Replies: 13
Views: 9152

Re: RB5009 and S-RJ01 SFP speed problem

We have seen CRS, RB4011 and RB5009 devices having auto neg issues with fibre and copper 1G SFP modules running in 10G SFP+ ports. Auto neg status never completes, depending on the device at the other end resulting link is reported as none, 100MB or 1GB and is prone to flaps. Connections to media c...
by olivier2831
Mon Oct 04, 2021 7:37 pm
Forum: General
Topic: Feature Request: Forcing 2.5G or 5G on 10G/s interface
Replies: 0
Views: 654

Feature Request: Forcing 2.5G or 5G on 10G/s interface

Hello, Doc [1] says: auto-negotiation (yes | no; Default: yes) When enabled, the interface "advertises" its maximum capabilities to achieve the best connection possible. Note1: Auto-negotiation should not be disabled on one end only, otherwise Ethernet Interfaces may not work properly. Not...
by olivier2831
Fri Oct 01, 2021 5:43 pm
Forum: General
Topic: S+RJ10 overheating: how to reduce to 5Gbs/s ?
Replies: 3
Views: 1367

Re: S+RJ10 overheating: how to reduce to 5Gbs/s ?

I was thinking about the following process:

- On central CCR2004,
check all Advertise boxes but 10G box
uncheck Auto-negociation
click OK or Apply

- On leaf (overheating) Netpower 16P
check all Advertise boxes but 10G box
uncheck Auto-negociation
click OK or Apply

Thoughts ?
by olivier2831
Fri Oct 01, 2021 5:30 pm
Forum: General
Topic: S+RJ10 overheating: how to reduce to 5Gbs/s ?
Replies: 3
Views: 1367

S+RJ10 overheating: how to reduce to 5Gbs/s ?

Hello, On a remote site, I've got a central CCR2004 connected to two Netpower16P. All 3 devices includes S+RJ10 modules. On one Netpower 16P, I've just discovered an "auto disabled due to overheating" message. 1. What does "disabled" mean in this context as I needed the disabled/...
by olivier2831
Wed Sep 29, 2021 6:56 pm
Forum: General
Topic: [OT] Linux equivalent of MT connection-mark=no-mark ? [SOLVED]
Replies: 3
Views: 1423

[OT] Linux equivalent of MT connection-mark=no-mark ? [SOLVED]

Hello, In nftables or iptables language, what could be the equivalent of Mikrotik's connection-mark=no-mark ? Semantic: "if an un- marked packet is received in interface ISP_1, then add mark it with 17 mark" /ip firewall mangle MT implementation addchain=input connection-mark=no-mark in-in...
by olivier2831
Wed Sep 29, 2021 12:46 pm
Forum: Announcements
Topic: Newsletter 102
Replies: 29
Views: 46053

Re: Newsletter 102

How do you exactly cover a building for inventory tracking ?
Do you deploy several Knot devices or do reuse some existing radio infra (WiFi AP with BLE capability) ?
What is the "radio range" of a TG-BT5-IN in a casual situation, with concrete walls, glass doors, ... ?
by olivier2831
Mon Sep 27, 2021 5:22 pm
Forum: General
Topic: Customizing columns in Interfaces/Interface view
Replies: 0
Views: 581

Customizing columns in Interfaces/Interface view

Hello, In 6.48.4 (or other versions), the Interfaces/Interface view shows columns such as: Actual MTU L2 MTU Tx Rx Tx Packets ... I would appreciate to read in this view things like PVID, PoE Priority or PoE out Current. Is it possible to add these columns or remove some existing ones ? Am I the one...
by olivier2831
Thu Sep 23, 2021 9:42 am
Forum: General
Topic: MTP250-53V47-OD availability ?
Replies: 0
Views: 604

MTP250-53V47-OD availability ?

Hello,

When will MTP250-53V47-OD (power supply for Netpower 16P) be available in western Europe countries ?

Best regards
by olivier2831
Wed Sep 22, 2021 12:28 pm
Forum: RouterBOARD hardware
Topic: NetPower 16p.... Rubbish PoE design. Workarounds?
Replies: 20
Views: 4451

Re: NetPower 16p.... Rubbish PoE design. Workarounds?

I love those 16P switches, I run 4 Core power cable up to it. Use 48V and 24V Meanwell redundancy modules so I have power from 2 different sources. One trough battery bank and one from mains. I wish it was able to put more power trough it on 48V as I can't power 16 devices on 48V with the draw we n...
by olivier2831
Wed Sep 22, 2021 9:04 am
Forum: Wireless Networking
Topic: Packetfence (RADIUS) + Hotspot + CAPsMAN + Dynamic VLAN
Replies: 5
Views: 5115

Re: Packetfence (RADIUS) + Hotspot + CAPsMAN + Dynamic VLAN

My goal is to setup a hotel wireless network where guests can roam across any AP in the building but remain in their dedicated room assigned VLAN. I've got a very similar target with the following differences: - I'm planning to use a Freeradius server - I'm planning to use different APs. I've not s...
by olivier2831
Tue Aug 24, 2021 7:35 pm
Forum: General
Topic: How to configure a CCRXXXX as router with VLAN trunk ports ?
Replies: 3
Views: 1908

How to configure a CCRXXXX as router with VLAN trunk ports ?

hello, I've got (quite urgent) need for help on setting up a CCRXXXX (currently a CCR2004 vith RouterOS 6.48.4) to act as a router between: - a DHCP-configured Ethernet uplink to the Internet with 1.2.3.4 address - a couple of trunk Ethernet interfaces to 3 other LAN switchs - on LAN switches, are c...
by olivier2831
Sun Aug 22, 2021 11:20 pm
Forum: General
Topic: What if mynetname.net was available for Letsencrypt DNS challenges ?
Replies: 0
Views: 691

What if mynetname.net was available for Letsencrypt DNS challenges ?

Hello, Reading about how to add a Letsencrypt certificate, I observed most used a DNS challenge. As all Mikrotik boxes are shipped with a pre-configured VPN that defines a specific 123456789abcd.sn.mynetname.net-like hostname, would it make sense if this hostname could be used to get an almost out-o...
by olivier2831
Thu Aug 19, 2021 12:09 pm
Forum: General
Topic: CCR2004: Power2 working while Power1 not working [SOLVED]
Replies: 3
Views: 841

Re: CCR2004: Power2 working while Power1 not working [SOLVED] [SOLVED]

Is broken or on transport the internal patch form psu1 to board is off, try to open the case and reconnect the cable. Is not the first time than happen to us... After years those devices are still on without problem. Yes, that was exactly that: an internal plug not fully inserted ! Thank very much ...
by olivier2831
Thu Aug 19, 2021 11:58 am
Forum: General
Topic: CCR2004: Which routerOS version to select ?
Replies: 2
Views: 682

CCR2004: Which routerOS version to select ?

Hello, I'm about to deploy my very first CCR2004-1G-12S+2XS in a remote location. Its mission is to NAT-route traffic to Internet for about 100 simultaneous LAN users (segregated into 3 VLANs). I don't plan to upgrade this box OS without any good reason (repeated failures, major vulnerability, ...)....
by olivier2831
Thu Aug 19, 2021 11:44 am
Forum: General
Topic: CCR2004: Power2 working while Power1 not working [SOLVED]
Replies: 3
Views: 841

CCR2004: Power2 working while Power1 not working [SOLVED]

Hello,

I'm preparing a new CCR2004-1G-12S+2XS i received a couple of days.
It has 2 power supply plugs.
When plugging a power cord in Power1, nothing seems to happen.
When plugging the same cord in Power2, box is starting (lights turning, ...).

Is it a defect or nominal ?

Best regards
by olivier2831
Wed Aug 18, 2021 11:00 am
Forum: General
Topic: Syslog to log NAT/CGN-Nat translations
Replies: 13
Views: 2853

Re: Syslog to log NAT/CGN-Nat translations

NetFlow is the answer here. It will export ("log") all the connection tracking statistics for you. Use NetFlow v9 as it provides a richer set of information, including full NAT details for each connection. Which NATing device did you use with NetFlow ? A Mikrotik device ? If positive, whi...
by olivier2831
Wed Jul 07, 2021 3:58 pm
Forum: RouterBOARD hardware
Topic: SFP+ on the small devices
Replies: 14
Views: 2846

Re: SFP+ on the small devices

8P-2S+ would make sense in some ring-like scenarios. 4P-1S+ would just be ridiculous. I think a four 2.5Gb/s PoE ports with a single SFP+ uplink would also make sense but I only one device to select, I would pick the 8 ports one. 2.5Gb/s is also interesting in WiFi as WiFi bandwidth now theorically...
by olivier2831
Wed Jul 07, 2021 10:29 am
Forum: RouterBOARD hardware
Topic: SFP+ on the small devices
Replies: 14
Views: 2846

Re: SFP+ on the small devices

Yes, a router version of the CSS610 would be helpful. That and the lack of PoE is why it dropped off my list of options for the core switch pretty early on. However, the CSS610 would fit into the "leaf" role from my " holes at the low end of the CSR line " thread. (I'm posting m...
by olivier2831
Wed Jul 07, 2021 10:15 am
Forum: RouterBOARD hardware
Topic: Internal power supplies instead of wall warts
Replies: 9
Views: 3128

Re: Internal power supplies instead of wall warts

"wall warts" may fail, but anyone can replace them and the failure is easy to diagnose. When an internal power supply fails, it often means people will throw the whole device. Replacement PSU is often non-existent and even if it existed, not everyone will be able to open the device and re...
by olivier2831
Wed Jul 07, 2021 10:04 am
Forum: General
Topic: Syslog to log NAT/CGN-Nat translations
Replies: 13
Views: 2853

Re: Syslog to log NAT/CGN-Nat translations

Syslog to log NAT/CGN-Nat translations I hope somebody knows to the answer to the question I am asking. Can I and how do I , log ( syslog and/or syslog to a remote syslog server ) all NAT translations ? Like many ISPs and WISPs , we get copyright notices which state somebody at an IP address downlo...
by olivier2831
Thu Jun 17, 2021 10:32 am
Forum: General
Topic: Hardware recommendation for routing up to 2Gb/s
Replies: 6
Views: 1215

Re: Hardware recommendation for routing up to 2Gb/s

My ideal pick would be a 2 (or 4 ports) 2.5Gb ports with RB4011 processing power.
You can build one using SBCs like Hardkernel's H2+ but that is a very path ...

Thanks for all input
by olivier2831
Wed Jun 16, 2021 5:24 pm
Forum: General
Topic: Hardware recommendation for routing up to 2Gb/s
Replies: 6
Views: 1215

Hardware recommendation for routing up to 2Gb/s

Hello, I'm looking for a Mikrotik device with: - equipped two 2.5 Gb/s Ethernet (either native or through a SFP+ slot) - able to route a 1 or 2 Gb/s flow applying NAT or firewall rules. I've looked at several product but: - RB4011 is fine but only host a single SFP+ slot, - hEX PoE has no SFP+ slot ...
by olivier2831
Thu Jun 03, 2021 1:05 pm
Forum: Announcements
Topic: v6.47.10 [long-term] is released!
Replies: 148
Views: 66533

Re: v6.47.10 [long-term] is released!

*) poe - do not perform PoE firmware upgrade procedure on RB960 and OmniTik devices without PoE out;
Can you elaborate a bit ?
simpy do not try to upgrade poe firmware on device can not have poe...
That makes sense !
Thanks for this clarification !
by olivier2831
Thu Jun 03, 2021 1:02 pm
Forum: Announcements
Topic: v6.47.10 [long-term] is released!
Replies: 148
Views: 66533

Re: v6.47.10 [long-term] is released!

*) poe - do not perform PoE firmware upgrade procedure on RB960 and OmniTik devices without PoE out; Can you elaborate a bit ? Could it be related to this? https://forum.mikrotik.com/viewtopic.php?f=21&t=169553&p=831920#p831920 Yes, it seems to match. Thanks for replying ! How could I rephr...
by olivier2831
Thu Jun 03, 2021 11:10 am
Forum: Announcements
Topic: v6.47.10 [long-term] is released!
Replies: 148
Views: 66533

Re: v6.47.10 [long-term] is released!

*) poe - do not perform PoE firmware upgrade procedure on RB960 and OmniTik devices without PoE out;
Can you elaborate a bit ?
by olivier2831
Thu Apr 15, 2021 6:12 pm
Forum: General
Topic: Feature Request: PoE monitoring and alterting
Replies: 0
Views: 524

Feature Request: PoE monitoring and alterting

Hello, I'm looking for a mean to prevent some people to unplug PoE powered devices (WiFi access points, cameras, ...) to connect rogue devices (laptop, ...) when physical access can't be denied (corridors, common rooms, ...). These PoE powered devices do not support 802.1X. I was thinking of monitor...
by olivier2831
Thu Apr 15, 2021 5:51 pm
Forum: General
Topic: How to view total PoE power consumption in WebFig ?
Replies: 0
Views: 828

How to view total PoE power consumption in WebFig ?

Hello, For PoE supplying devices (CRS328-24P, ...), you have: - a general view showing stats (Rx/Tx, MTU, Packets, ..) from all interfaces - a detailed view showing the same stats and more, specifically PoE power, voltage and current. 1. Is it possible to read somewhere the sum of all PoE powers ? 2...
by olivier2831
Thu Apr 15, 2021 9:56 am
Forum: General
Topic: LLDP
Replies: 136
Views: 69210

Re: LLDP

+1, this is not an optional thing, it is required in most enterprise environements. Need LLDP-MED, even if it's just an installable package.
I felt LLDP features (without WebFig support) were introduced with 6.48.1 or so.
I don't know if it covered LLDP-MED (nor I didn't test it yet).
by olivier2831
Mon Mar 15, 2021 4:45 pm
Forum: General
Topic: Mikrotik UPS Solution
Replies: 11
Views: 2780

Re: Mikrotik UPS Solution

The original poster said that he has two CRS125 routers and two passive POE injectors running on 24 volts. My original and followup suggestions was to run both the routers and the POE injectors off the same 24 volt battery plant. How do you ideally split current between 4 devices (2xCRS, 2xPoE inje...
by olivier2831
Tue Feb 16, 2021 9:07 am
Forum: RouterBOARD hardware
Topic: Which ROS devices do you expect the most?
Replies: 17
Views: 4441

Re: Which ROS devices do you expect the most?

1) Hex with a SFP+ and 5 1Gb ports,
+1 or alternatively, CSS610-8P-2S+ which was announced in MUM 2019 Europe

mAP or mAP Lite with 5GHz radio

A 4-ports device with Ethernet bypass
by olivier2831
Thu Feb 11, 2021 12:23 pm
Forum: General
Topic: Assign a DNS entry for a DHCP device
Replies: 3
Views: 645

Re: Assign a DNS entry for a DHCP device

Yes, that would be a very useful feature.
by olivier2831
Fri Feb 05, 2021 10:01 am
Forum: General
Topic: Which mAP alternative with 5GHz and 802.3 af capabilities ?
Replies: 6
Views: 1616

Re: Which mAP alternative with 5GHz and 802.3 af capabilities ?

I powered a cAP AC with a PoE injector, then connected a Mitel handset to the POE-out port of the cAP AC and it worked fine. I wasn't necessarily expecting the phone to power up as the cAP AC spec says it's passive PoE out. How did you exactly power your cAP AC device ? Using a 48V power supply con...
by olivier2831
Thu Feb 04, 2021 6:44 pm
Forum: General
Topic: Which mAP alternative with 5GHz and 802.3 af capabilities ?
Replies: 6
Views: 1616

Re: Which mAP alternative with 5GHz and 802.3 af capabilities ?

Reading back mAP datasheet, I would appreciate if someone could confirm the following setup would work or not:

LAN <--- non-PoE ethernet or wifi ---> mAP with 48V power supply <--- 802.af ethernet ---> IP phone
by olivier2831
Thu Feb 04, 2021 5:54 pm
Forum: General
Topic: Which mAP alternative with 5GHz and 802.3 af capabilities ?
Replies: 6
Views: 1616

Which mAP alternative with 5GHz and 802.3 af capabilities ?

Hello, I'm looking for a small device that would bring 802.3af PoE, VPN and 2.4/5GHz wifi to a PoE-powered SIP phone allowing some employees to bring their deskphone at home for tele-working. Current mAP (and a 48V power supply) seems to fit except for 5GHz capability. All Mikrotik wireless alternat...
by olivier2831
Mon Nov 30, 2020 11:24 pm
Forum: Beginner Basics
Topic: Questions on Wiki's Traffic generator page ?
Replies: 0
Views: 468

Questions on Wiki's Traffic generator page ?

Hello, I'm reading CCR1036 Test setup in https://wiki.mikrotik.com/wiki/Manual:Performance_Testing_with_Traffic_Generator#Defaults.2C_routing . 1. Where does pt0 comes from in bellow code ? Should this line be simply removed ? /tool traffic-generator stream add id=0 mbps=700 name=str0 packet-size=60...
by olivier2831
Mon Nov 30, 2020 5:50 pm
Forum: General
Topic: Fiber vs Copper 10Gb/s SFP+ power consumption
Replies: 3
Views: 1603

Re: Fiber vs Copper 10Gb/s SFP+ power consumption

Mikrotik don't appear to publish a power consumption figure for the S+AO0005, I would expect it to be less than the regular optical SFPs.
S+AO0005 seems to be fine but a 5m length is not very convenient when connecting devices with a rack.
A 1m S+AO0001 would be much appreciated for this.
by olivier2831
Mon Nov 30, 2020 3:30 pm
Forum: General
Topic: Fiber vs Copper 10Gb/s SFP+ power consumption
Replies: 3
Views: 1603

Fiber vs Copper 10Gb/s SFP+ power consumption

Hello, I've read several times 10Gb/s on Copper SFP+ implied noticeable power consumption and heat. Do you have any comparison between Fiber and Copper SFP+ when connecting over 1 Gb/s ? Can S+AO0005 be seen a way to work around power/heat issues without sacrifying throughput when inter-connecting M...
by olivier2831
Wed Sep 23, 2020 11:33 am
Forum: Beginner Basics
Topic: Can't add Unifi Switch
Replies: 4
Views: 1693

Re: Can't add Unifi Switch

Have a Mikrotik hEX RB750Gr3 that I am trying to plug a Unifi 8 port switch into. The Unifi is a managed switch that should get a ip via dhcp. When I connect it to the Mikrotik it never shows up. I have other non managed switches and when I plug them in devices that are plugged into those switches ...
by olivier2831
Wed Sep 23, 2020 11:06 am
Forum: General
Topic: [FEATURE REQUEST] 802.3bt (PoE++) Switch
Replies: 2
Views: 882

Re: [FEATURE REQUEST] 802.3bt (PoE++) Switch

Would love to see Mikrotik release a PoE++ switch. Is there any plans to release such an item?
+1
by olivier2831
Tue Sep 08, 2020 2:01 pm
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 184
Views: 115354

Re: v6.48beta [testing] is released!

Version 6.48beta35 has been released.
...
*) discovery - added "lldp-med-net-policy-vlan" property for assigning VLAN ID (CLI only);
Is this feature enough to automatically assign IP Phones to specific VLAN (ie configuring a VoiceVLAN per port) ?
by olivier2831
Wed Aug 26, 2020 9:26 am
Forum: RouterOS beta
Topic: Feature Request - Enterprise features like VSS, ZTP, IPv6 L3 HW offloading and SD-WAN
Replies: 13
Views: 3893

Re: Feature Request - Enterprise features like VSS, ZTP, IPv6 L3 HW offloading and SD-WAN

Thanks for the insights!!! Seems that Mikrotik is going in the right track on these features :). My main priorities are ZTP and VSS to have first above the others. Same priorities here: ZTP and VSS. And an other feature not mentioned before: LLDP-MED I would very curious to read about the later one.
by olivier2831
Wed Jul 29, 2020 9:51 am
Forum: General
Topic: Which >96W 48V power supply for netpower16P ?
Replies: 2
Views: 1483

Re: Which >96W 48V power supply for netpower16P ?

Thank you @nz_monkey for the tip: I ordered a Meanwel 48v, 240W DIN-mount power supply and will test it soon. By the way, has anyone ever tried to "split" the output of such power supply for several devices ? On one hand DIN-mount power supplies are quite compact and dedicating one for eac...
by olivier2831
Tue Jul 28, 2020 12:52 pm
Forum: General
Topic: Which >96W 48V power supply for netpower16P ?
Replies: 2
Views: 1483

Which >96W 48V power supply for netpower16P ?

Hello, Netpower16P datasheet mentions "316W max power consumption". Which available power supply would you recommend to get a 150W, 200W or more total output PoE (802.3af/at) budget ? If I'm not mistaken, largest current Mikrotik 48V power supply only provides 96W which means less than 6W ...
by olivier2831
Tue Jul 21, 2020 11:34 am
Forum: RouterBOARD hardware
Topic: Hardware Wishlist
Replies: 18
Views: 8742

Re: Hardware Wishlist

- cAP ax
- 802.3BT switches
For curiosity's sake, which current AP (any brand or model) do comply with this "802.3bt daisy chain" ?
Being able to both pass data (>1 Gb/s) and power (>802.3af) from one AP to next AP would greatly simplify cabling.
by olivier2831
Tue Jul 21, 2020 11:06 am
Forum: General
Topic: mUPS/mUPS Pro plans
Replies: 1
Views: 1100

mUPS/mUPS Pro plans

Hello,
I can't see any reference to mUPS (nor mUPS Pro) among official Mikrotik hardware pages.
What are current plans for both ?
Best regards
by olivier2831
Tue Jul 07, 2020 9:30 am
Forum: General
Topic: [OT] Which IPFIX collector on Debian ?
Replies: 3
Views: 1419

Re: [OT] Which IPFIX collector on Debian ?

Thank you very much for replying.

I'll give nfdump a try.
Thanks again
by olivier2831
Mon Jul 06, 2020 11:51 am
Forum: General
Topic: [OT] Which IPFIX collector on Debian ?
Replies: 3
Views: 1419

[OT] Which IPFIX collector on Debian ?

Hello,

Mikrotik devices can produce IPFIX data.
Which Debian installable IPFIX collector would you recommend to collect this data and store in SQL database ?

Best regards
by olivier2831
Mon Jul 06, 2020 11:34 am
Forum: RouterBOARD hardware
Topic: mUPS Pro?
Replies: 3
Views: 2016

Re: mUPS Pro?

yes, there is another thread, it's over 6 months old so time for new!

Is this product going to see the light of day?
Yes, an official statement about mUPS Pro plans, if such still exists, would be very welcome.
by olivier2831
Fri Jul 03, 2020 4:15 pm
Forum: RouterBOARD hardware
Topic: Hardware Wishlist
Replies: 18
Views: 8742

Re: Hardware Wishlist

- 802.3BT switches
May I add that, if my understanding is correct, 802.3bt also brings multi-gigabit (2.5, 5 or 10Gb/s).
Maybe a simple Midspan 802.3bt would also make sense as devices such do not exist, yet.
by olivier2831
Thu Jul 02, 2020 7:56 pm
Forum: General
Topic: Questions about NAT44/RFC7422
Replies: 3
Views: 1279

Re: Questions about NAT44/RFC7422

Thank you very much for you very informative answer And what if you have 5000 users ? Deterministic NAT is a poor man's workaround for small networks where you cannot log connection initiation events on an external storage. 1. Alternatively, how can you log connection initiation events on an externa...
by olivier2831
Thu Jul 02, 2020 2:40 pm
Forum: General
Topic: Questions about NAT44/RFC7422
Replies: 3
Views: 1279

Questions about NAT44/RFC7422

I've very recently discovered RFC7422 that deals with deterministic NAT. I'm thinking of using RFC7422 to reduce logging requirements when serving 500 devices through a single (or double) Internet connection (FTTH). The way I see this is: "Whenever IP 192.168.0.17 from 192.168.0.0/23 network is...
by olivier2831
Wed Jun 24, 2020 10:32 am
Forum: Announcements
Topic: MikroTik Newsletter June 2020 (#96)
Replies: 29
Views: 20037

Re: MikroTik Newsletter June 2020 (#96)

Hi,

Netpower16 is very welcome addition.

Do we have anything new concerning the CSS610-8P-2S+,announced during MUM2019.
This one would still perfectly fill a need between 5 ports PowerBox and 16 ports Netpower16.

Best regards
by olivier2831
Fri Jun 12, 2020 2:05 pm
Forum: General
Topic: How to keep people from connecting PC instead of Access points or Cameras ?
Replies: 6
Views: 1722

Re: How to keep people from connecting PC instead of Access points or Cameras ?

802.1X is then the only way to go. But it depends on the sort of "endpoint" what capabilities are. If the endpoint has a supplicant you can work with username/password/certificates but for real dumb devices MAC "authentication" is a minimum. In *additional* to that, specific fil...
by olivier2831
Fri Jun 12, 2020 1:28 pm
Forum: General
Topic: How to keep people from connecting PC instead of Access points or Cameras ?
Replies: 6
Views: 1722

How to keep people from connecting PC instead of Access points or Cameras ?

Hello, How would you secure your network if you have devices (Wifi Access Points, Cameras, ...) installed in locations where physical access protection can't be provided (corridors, common rooms, ...) ? Those devices have the common properties: - most if not all are PoE powered, - they hold a tag or...
by olivier2831
Tue Jun 09, 2020 4:51 pm
Forum: General
Topic: How to drop all traffic except traffic to the Internet ? [SOLVED]
Replies: 5
Views: 7031

Re: How to drop all traffic except traffic to the Internet ? [SOLVED]

If you want it to be done exactly as you described (based on ip address ranges) use switch chip access rules: https://wiki.mikrotik.com/wiki/Manual:CRS3xx_series_switches#Switch_Rules_.28ACL.29 Or bridge firewall: https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_Firewall Another possib...
by olivier2831
Mon Jun 08, 2020 12:31 pm
Forum: General
Topic: How to drop all traffic except traffic to the Internet ? [SOLVED]
Replies: 5
Views: 7031

How to drop all traffic except traffic to the Internet ? [SOLVED]

Hello, For a building hosting students, I'm trying to replicate current wireless policy with Mikrotik switches. Currently, a student guest WiFi device can only communicate with non-RFC1918 devices (all traffic to RFC1918 addresses ie 192.168.0.0, 172.16.0.0, 10.0.0.0 is discarded by WiFi AP). How ca...
by olivier2831
Fri May 29, 2020 12:22 pm
Forum: General
Topic: How Eth interface for DSL upstream access in PPPoE setup ?
Replies: 1
Views: 926

How Eth interface for DSL upstream access in PPPoE setup ?

Hello,

I've got the following setup:
Internet --- ISP --- DSL Modem --- Mikrotik router --- LAN

How can I configure WAN ethernet interface for both:
- acting as PPPoE client as required by ISP
- acting as DHCP client to configure DSL Modem

What are the basic steps for this ?

Best regards
by olivier2831
Tue Feb 18, 2020 3:57 pm
Forum: RouterOS beta
Topic: CRS3xx MC-LAG in RouterOS 7
Replies: 19
Views: 9595

Re: CRS3xx MC-LAG in RouterOS 7

EVPN multihoming is better than MC-LAG
MC-LAG is dead.
I've never heard about EVPN before.
After reading about it, it does seem to be very interesting.
Thanks for mentioning it here !
by olivier2831
Fri Jan 31, 2020 9:08 am
Forum: Announcements
Topic: MikroTik newsletter January 2020 (#93)
Replies: 26
Views: 35116

Re: MikroTik newsletter January 2020 (#93)

I hoped to hear news about:
CRS354-48P-4S+2Q+RM (with PoE)
CSS610-8P-2S+ (announced last year)

Maybe, next time
by olivier2831
Mon Dec 30, 2019 3:58 pm
Forum: RouterOS beta
Topic: CRS3xx MC-LAG in RouterOS 7
Replies: 19
Views: 9595

Re: CRS3xx MC-LAG in RouterOS 7

We are researching ways how to implement MC-LAG
@Reinis:
Hi,
Do you have any specific information about this MC-LAG feature ?
Should it come with RouterOS 7 first as this thread title implies, or may it come with 6.4X ?
Thanks in advance
by olivier2831
Fri Nov 29, 2019 9:43 am
Forum: General
Topic: The sad state of OpenVPN
Replies: 12
Views: 6981

Re: The sad state of OpenVPN

1) OpenVPN client with weak cyphers and password auth
Yes but ciphering can be quite CPU-intensive and RouterOS covers a wide range of hardware.
by olivier2831
Thu Oct 17, 2019 5:30 pm
Forum: General
Topic: LLDP-MED support in RouterOS 6.46 or 7
Replies: 0
Views: 815

LLDP-MED support in RouterOS 6.46 or 7

Hello,

Is there anything to mention about LLDP-MED support in either RouterOS 6.46 or later 7 ?

Best regards
by olivier2831
Mon Aug 26, 2019 6:05 pm
Forum: Beginner Basics
Topic: How to effectively configure 6 hEX units ?
Replies: 5
Views: 2021

Re: How to effectively configure 6 hEX units ?

Configure 1 how you want it. Do an /export and then do a full reset on the others and import the .rsc file you made from the first one. Which would cover all but last two OP's points (SSH keys and password) ... those two are only possible to automate by using (binary) backups which should not be us...
by olivier2831
Mon Aug 19, 2019 7:24 pm
Forum: Beginner Basics
Topic: How to effectively configure 6 hEX units ?
Replies: 5
Views: 2021

How to effectively configure 6 hEX units ?

Hello, I need to configure 6 hEX PoE UNITS as basic "VLAN enabled switches". Configuration details i need to set, are: - custom settings: - fixed private address (eg 192.168.1.221/24) replacing factory-set 192.168.88.1/24 - common settings: - do not act as DHCP or DNS server - no DNS cache...
by olivier2831
Mon Aug 19, 2019 2:50 pm
Forum: SwOS
Topic: Support for MC-LAG/Port bonding across chassis?
Replies: 3
Views: 6845

Re: Support for MC-LAG/Port bonding across chassis?

I am planning my core switch with 10Gbps, and need MC-LAG or similar function which can bond port across two switch chassis for HA or redundancy. If aggregating bandwith is not required (ie having one port in standby mode is acceptable) maybe alternatives that do not depend on switch features can b...
by olivier2831
Mon Aug 12, 2019 12:30 pm
Forum: Announcements
Topic: Newsletter #90
Replies: 55
Views: 40509

Re: Newsletter #90

Though I'm also really interested in the new outdoor switches (CSS610-8P-2S+, CRS318-16P-2S+, CRS318-16Fi-2S), is there any prediction as to when they'll be released?
+1 for outdoor switches availability prediction
by olivier2831
Fri Jul 26, 2019 6:30 pm
Forum: General
Topic: Feature Request TR-069 CPE
Replies: 87
Views: 51701

Re: Feature Request TR-069 CPE

For ISP - it is not a problem. For ex. you have 30000 rb951ui and tr-069. But some of them - under the NAT. So, you have 2 options - vpn and stun. I prefer stun. Clear?
Yes, I agree, TR069 and Zero-touch configuration are not to be confused.
by olivier2831
Thu Jul 25, 2019 6:53 pm
Forum: General
Topic: Feature Request TR-069 CPE
Replies: 87
Views: 51701

Re: Feature Request TR-069 CPE

+1 for STUN
To keep plug-n-play feature of TR069-Annex G-enabled router, a public STUN server address or hostname should, by default, be configured in Mikrotik router default config, right ?
Does such public STUN server exist or do you think Mikrotik should operate its own STUN server ?
by olivier2831
Tue Jul 23, 2019 6:18 pm
Forum: General
Topic: LLDP
Replies: 136
Views: 69210

Re: LLDP

Agree 100%. It is a fundamental requirement in any enterprise switch.
+1 for LLDP-MED which really simplify things.
by olivier2831
Mon Jul 08, 2019 2:58 pm
Forum: General
Topic: CSS610-8P-2D+OUT availability
Replies: 3
Views: 1421

Re: CSS610-8P-2D+OUT availability

Considering the only reference to that part number I can find is this one thread, you'll have to be more specific at what device your looking at. Do you have a link to the announcement for it? Yes, I should have been explicit on this. My question relates to the product announced in page 38 of the [...
by olivier2831
Mon Jul 08, 2019 11:48 am
Forum: General
Topic: CSS610-8P-2D+OUT availability
Replies: 3
Views: 1421

Re: CSS610-8P-2D+OUT availability

Can we have a rough estimee of its availability ?
Anyone ?
by olivier2831
Tue Jul 02, 2019 7:18 pm
Forum: General
Topic: CSS610-8P-2D+OUT availability
Replies: 3
Views: 1421

CSS610-8P-2D+OUT availability

Hello,

I read announcement of CSS610-8P-2D+OUT switch.
I find it a very attractive product in WiFi setups where it could simplify a lot cabling topologies.

Can we have a rough estimee of its availability ?

Best regards
by olivier2831
Mon Jun 17, 2019 5:27 pm
Forum: Beginner Basics
Topic: Explain RSTP priority and path-cost [SOLVED]
Replies: 1
Views: 3954

Explain RSTP priority and path-cost [SOLVED]

Hello, I'm currently testing RSTP between two 6.44.3 instances. I'm not familiar at all with STP and the likes. I looked at first example (the one involving switches SW1, SW2, SW3 and SW4 and hosts A and B) in RSTP Wiki page (see [1]). 1. I can read that SW1 settings rely on priority while SW4 rely ...
by olivier2831
Mon Jun 17, 2019 9:51 am
Forum: Wireless Networking
Topic: How replace a failing Wireless Wire Dish unit ?
Replies: 2
Views: 1128

Re: How replace a failing Wireless Wire Dish unit ?

Besides admin users, IP addresses, for normal management, etc,you will have to configure the following as a minimum to get the link up: 1. Mode: "Bridge" or "Station Bridge" depending which one you replacing 2: SSID 3: SSID Password Yes I forgot the last two ones. In a couple of...
by olivier2831
Sun Jun 16, 2019 5:43 pm
Forum: Wireless Networking
Topic: Configuring a Wireless Wire Dish as a switch ?
Replies: 2
Views: 1263

Configuring a Wireless Wire Dish as a switch ?

Hello, I hope my question will not sound too stupid for experienced people but in a PtP setup linking a secondary building to a main one where all resources (DHCP server, WAN, ...) are located, is it possible to configure both master and slave units of Wireless Wire Dish as switches ? WAN ---- Main ...
by olivier2831
Sun Jun 16, 2019 5:34 pm
Forum: Wireless Networking
Topic: How replace a failing Wireless Wire Dish unit ?
Replies: 2
Views: 1128

How replace a failing Wireless Wire Dish unit ?

Hello, My first Wireless Wire Dish is about to enter production in a couple of days. Both "dishes" arrived pre-configured : one unit as master, the other as slave. What should I prepare in case master or slave unit has a non-recoverable hardware issue ? Ideal steps include: - configuring s...
by olivier2831
Sun Jun 16, 2019 5:11 pm
Forum: Beginner Basics
Topic: Interconnecting two CRS324 through two different links
Replies: 0
Views: 751

Interconnecting two CRS324 through two different links

Hello, I'm about to install two CRS324 units in two buildings :one CRS324 in main building, one in secondary building. Main building hosts two WAN connections while secondary building has none. Both building can be interconnected through two different dedicated links: - one made of a Wireless Wire D...
by olivier2831
Fri Jun 07, 2019 4:43 pm
Forum: Wireless Networking
Topic: Experience with PtP Wireless Wire Dish link
Replies: 3
Views: 1935

Re: Experience with PtP Wireless Wire Dish link

Complementing my previous message, I installed a 130m PtP Wireless Dish Link.
Rough measures (with iperf and a pair of PCs) showed 900Mb/s throughput, with a sunny weather.
This link will enter production at the end of June.
by olivier2831
Wed May 29, 2019 7:14 pm
Forum: Wireless Networking
Topic: Experience with PtP Wireless Wire Dish link
Replies: 3
Views: 1935

Experience with PtP Wireless Wire Dish link

Hello, I've read in this [1] thread, some kind of survey regarding PtMP W60g performance. Some commented their own experience in a PtP setup. 1. Can I ask here, to sum up here your experiences with a Wireless Wire Dish link in Point-to-Point setup ? Do you have disconnections ? How often ? Do they r...
by olivier2831
Mon May 27, 2019 12:54 pm
Forum: Beginner Basics
Topic: Advice on backing a 60GHz link with a private DSL line
Replies: 2
Views: 1219

Re: Advice on backing a 60GHz link with a private DSL line

With 60m clear LOS you van espect 1GBit with Wireless Wire you don’t need the dish
What are the technical downsides of using a Dish instead of a Wire ?
by olivier2831
Fri May 24, 2019 4:48 pm
Forum: Beginner Basics
Topic: Troubeshooting Performance testing
Replies: 3
Views: 1368

Re: Troubeshooting Performance testing

This will send traffic from TG, through DUT and back to TG.
Am I correct this only involves one DUT interface ?
When would prefer to use such traffic as opposed to traffic going in through one interface and leaving through another ?
by olivier2831
Fri May 24, 2019 3:46 pm
Forum: Beginner Basics
Topic: Troubeshooting Performance testing
Replies: 3
Views: 1368

Re: Troubeshooting Performance testing [SOLVED]

I could at last get some positive testing. Referring to [1], I simply had to run both r12 and r21 traffic to have "quick tx-template ..." command stop displaying "100% Lost". (Previously, I ran r12 traffic alone, as a first step). I hope this would help others [1] https://wiki.mi...
  • 1
  • 2