Community discussions

MikroTik App

Search found 63 matches

by CTSsean
Tue Jul 25, 2023 5:31 pm
Forum: General
Topic: MikroTik same network on location A and B double NAT - how to solve
Replies: 6
Views: 571

Re: MikroTik same network on location A and B double NAT - how to solve

Good day, I have on location A - 192.168.0.0/24 on location B - 192.168.0.0/24 On site A, for example, I have a printer at 192.168.0.5 At site B, I have a server with an accounting system of 192.168.0.5 When I'm at location A and I want to connect to location B VPN - which has its own range - 10.10...
by CTSsean
Tue Jul 25, 2023 5:19 pm
Forum: General
Topic: VRRP Failover when WAN drops [SOLVED]
Replies: 7
Views: 1184

Re: VRRP Failover when WAN drops [SOLVED]

Had a request from a customer so I have been brainstorming and just wanted to get some input :) would like to know if what I'm thinking below will work for the purpose and if anyone has any thoughts on optimising. So I will be managing a router that will connect to the customer's LAN. That LAN will...
by CTSsean
Tue Jul 25, 2023 4:37 pm
Forum: General
Topic: Poe catching fire?
Replies: 3
Views: 726

Re: Poe catching fire?

I have a couple of customers out in a community that is off the grid. They power their equipment through inverters and generals/solar panels. I've had two customers contact me after a storm both with equipment that burnt up. The one just had his router power supply fry. (burnt a hole right through ...
by CTSsean
Tue Jul 25, 2023 12:22 am
Forum: General
Topic: Feature Request - implement Q-BRIDGE-MIB
Replies: 0
Views: 485

Feature Request - implement Q-BRIDGE-MIB

802.1Q Q-BRIDGE-MIB (RFC 2674) is a standard MIB for retrieving vlan information. Currently, LibreNMS and other network monitoring platforms require special agents / scripts to retrieve vlan information from RouterOS devices.
by CTSsean
Sat Jul 22, 2023 12:10 am
Forum: Announcements
Topic: MikroTik Devices Controller
Replies: 332
Views: 239090

Re: MikroTik Devices Controller

I'd personally love it if Mikrotik could make a centralized controller. Even if it was required to be its on VM appliance. Here are my reasons: A) when deploying capsman, only the the wifi radios are configured. The rest of the device isn't protected. B) It's difficult to have a standardized install...
by CTSsean
Thu Jul 20, 2023 7:12 pm
Forum: General
Topic: Mikrotik devices dying
Replies: 7
Views: 1026

Re: Mikrotik devices dying

Auto software upgrades is not recommended... on almost ANY platform.

While that's probably not killing your tiks, probably doesn't help. I'd verify that your power at the site is within expected range and is protected with either a UPS or other battery solution.
by CTSsean
Thu Jul 20, 2023 7:08 pm
Forum: General
Topic: CRS-3xx Learn Limit/Lock on first
Replies: 9
Views: 4087

Re: CRS-3xx Learn Limit/Lock on first

+1 on this... I'm not sure why this was available on CRS2x, but not CRS3x.
by CTSsean
Wed Jul 05, 2023 6:39 pm
Forum: Wireless Networking
Topic: Is WIFIWAVE2 Capsman working with VLANs?
Replies: 7
Views: 2230

Re: Is WIFIWAVE2 Capsman working with VLANs?

Yes it is for me for v7.10 .... And where and how are your VLANs defined ? Or is this a setup without VLANs ? That we all know works just fine. If you look at my config, it lists the vlan IDs My vlans are deployed at my router (which the CAP AX is connected at). /interface vlan add interface=LANBri...
by CTSsean
Wed Jul 05, 2023 6:27 pm
Forum: Wireless Networking
Topic: PPSK on Mikrotik
Replies: 2
Views: 1629

Re: PPSK on Mikrotik

No. Not without specifying the individual mac addresses. This has been tested over and over again, but not available yet.
by CTSsean
Tue Jul 04, 2023 5:41 pm
Forum: Wireless Networking
Topic: Is WIFIWAVE2 Capsman working with VLANs?
Replies: 7
Views: 2230

Re: Is WIFIWAVE2 Capsman working with VLANs?

Yes it is for me for v7.10 bof CAP AX ---------------------- /interface wifiwave2 # managed by CAPsMAN /interface wifiwave2 cap set discovery-interfaces=bridgeLocal enabled=yes slaves-datapath=capdp slaves-static=yes /interface wifiwave2 datapath add bridge=bridgeLocal comment=defconf disabled=no na...
by CTSsean
Tue Jul 04, 2023 5:22 pm
Forum: General
Topic: Feature request for v7.x
Replies: 296
Views: 107492

Re: Feature request for v7.x

Plus 1 for this! WIFI multiple PSK ACL with wildcard MAC. Here Engenius description on that. Ruckus also have something similar and I think Meraki also do so... https://www.engeniustech.com/mypsk-a-network-access-solution-for-universities-multi-tenant-dwellings-and-large-corporations/ Here discussio...
by CTSsean
Sat Jun 24, 2023 7:05 pm
Forum: General
Topic: ROS 7.9 IPSec defect
Replies: 24
Views: 4870

Re: ROS 7.9 IPSec defect

Can the fix be posted publically? This will affect more than just 1 user.
by CTSsean
Thu May 18, 2023 5:25 pm
Forum: General
Topic: Connection between Wireguard and L2TP/IPSEC [SOLVED]
Replies: 9
Views: 1615

Re: Connection between Wireguard and L2TP/IPSEC [SOLVED]

Thanks @anav, luckily it was possible without getting physically to Location 1. Just learnt that Mikrotik router does not have ssh client but there were other devices to ssh further to Location 2 router.

exportTik.txt
what? All tik devices have ssh clients / servers.
by CTSsean
Fri Apr 28, 2023 12:00 am
Forum: Wireless Networking
Topic: Point-to-Multipoint with 60G/5G failover
Replies: 13
Views: 3415

Re: Point-to-Multipoint with 60G/5G failover

You just make bonding only on other, client side and thats it. On AP you just put 60Ghz station interfaces in same bridge as 5Ghz interface. This wont make loopback with client side, thanks to active backup in that bonding. We are using this style of client backup for 4 months without any problems....
by CTSsean
Thu Mar 30, 2023 5:32 pm
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101574

Re: mDNS repeater feature

Today, I've been able to get IGMP Proxy working with Chromecast cross vlans. I'll get my documentation together and post a new thread so its easily findable. Thank you to Nate for provided the basis of this solution. I don't understand quite how it works as the IGMP Proxy doesn't show much under the...
by CTSsean
Tue Mar 28, 2023 11:47 pm
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101574

Re: mDNS repeater feature

Unless you are an advanced networking user or engineer, I agree. Using VLANs at home makes no sense for the added complexity and bullshit hacks required. With Mikrotik and CAPSMAN1 you can cordon off Wifi devices without using VLANs to their own bridge as long as you don't use local-forwarding for ...
by CTSsean
Tue Mar 28, 2023 11:45 pm
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101574

Re: mDNS repeater feature

It worked sooooooo!!!!




:lol: :lol: :lol: :lol: :lol: :lol:
Ty. Keep it up ;)
by CTSsean
Tue Mar 28, 2023 4:30 pm
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101574

Re: mDNS repeater feature

Reach out to MikroTik support. Give them the supout export file. This needs to be solved by them, not me.
Ok, I will reach out to Tik support and report back.
by CTSsean
Tue Mar 28, 2023 9:37 am
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101574

Re: mDNS repeater feature

I did a PCAP on my end. So IPv4 (IGMP) does get queried by the proxy/MikroTik. But IPv6 (MLD) does not. And this could impact apps that explicitly rely only on IPv6 Multicast or prefer IPv6, so of course you're not going to see it working. The experts in this thread should demand for IPv6 MLD suppo...
by CTSsean
Mon Mar 27, 2023 5:59 am
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101574

Re: mDNS repeater feature

tested ccast, torched vlan69 for port 1900. Saw a kids pc trying to connect to 239.255.255.250:1900

Guessing Chrome is always looking for ccast devices. Still no joy on IGMP Proxy. I'm open to suggestions. I don't mind reading some digestible information about it.
by CTSsean
Mon Mar 27, 2023 3:19 am
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101574

Re: mDNS repeater feature

When I torch the vlan69, and test ccast, i do not see any traffic for port 5353. Doesn't Chromecast actually use SSDP? If so, same story, but 239.255.255.250 port 1900 is what you'd need to look at if it does use SSDP. Also, didn't study the config very carefully, maybe covered...but "ingress-...
by CTSsean
Mon Mar 27, 2023 2:36 am
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101574

Re: mDNS repeater feature

Config looks fine. But possibly, I could've missed something. Run a torch/packet sniffer and perform analysis on what happens when you try Chromecast. Something, somewhere is dropping the packet. Multicast-querier should remain disabled on the bridges/HP switch. ok, is there something I can digest ...
by CTSsean
Sun Mar 26, 2023 10:50 pm
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101574

Re: mDNS repeater feature

Here is my config for following Nate's suggestion. Both Airplay and Chromecast still don't work. Topology R1 > LAG to 2 MLAG connected CRS3X SWITCHES > LAG to POE Switch > CAP AC I get it, I'm not skilled, experienced, smart as others that have done it all. I'm not afraid of being dumb. It allows me...
by CTSsean
Sun Mar 26, 2023 9:11 pm
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101574

Re: mDNS repeater feature

keep segmentation due to security reasons Just to then punch holes in those layers? And just ignoring the vendors advice (e.g. the "illusion of security") here, which be okay if you understood the underlying network protocols risks. But cut-and-paste other peoples configuration you don't ...
by CTSsean
Sun Mar 26, 2023 7:39 pm
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101574

Re: mDNS repeater feature

I liked this quote from Mikrotik: By the looks of it, L2 segregation for the mentioned above cases is an illusion of safety. But... Exactly. Give us a working example to get chromecast/airplay working using the IGMP Proxy and all of this noise goes away. So you want to cut-and-paste without underst...
by CTSsean
Sun Mar 26, 2023 5:37 pm
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101574

Re: mDNS repeater feature

why would someone need to have that? worse, why even relay such network noise? That's the existential question here. But [...] at the end it is Mikrotik's pure business decision [...] And... it sounds like this could be resolved by better docs on IGMP Proxy for those that want to go this route. An ...
by CTSsean
Sun Mar 26, 2023 5:19 pm
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101574

Re: mDNS repeater feature

Ever home user needs mDNS. Don't know why mikrotik keeps ignoring this. why would someone need to have that? worse, why even relay such network noise? IOT. This category of devices is now more prolific than every before. In homes, smb, and enterprises. We’re looking for tools to allow us to segrega...
by CTSsean
Sun Mar 26, 2023 4:28 pm
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101574

Re: mDNS repeater feature

For posters here........... Do not mind Darknate's lack of personal communication skills (probably why he has more dates with large networks than real people ;-) ) and of course the rampant narcissism. He has a lot of experience with many large networks that is invaluable to other large network use...
by CTSsean
Sun Mar 26, 2023 4:56 am
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101574

Re: mDNS repeater feature

If you've gone done the road of subnetting your LAN, IGMP Proxy should not be a huge leap. And if it was, maybe you should re-think segmenting your network in the first place? VLANs + mDNS containers hacks takes like 10 minutes total for a noob. IGMP Proxy, takes 5 seconds to configure for all VLAN...
by CTSsean
Sun Mar 26, 2023 4:44 am
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101574

Re: mDNS repeater feature

Use IGMP Proxy in simple VLAN segregated home networks and call it a day. iPhone in VLAN1 can talk to iPhone in VLAN2 for AirFuckKnowsWhat, no problem. Unicast DNS-SD defeats the whole purpose of multicast aka saving computing resources on L2 and L3. Doesn't work. Used your specific example, includ...
by CTSsean
Sat Mar 25, 2023 7:46 pm
Forum: General
Topic: Why is romon broken is half of 7.X devices?
Replies: 0
Views: 262

Why is romon broken is half of 7.X devices?

I've been using Tik products for a nearly a decade, and when Romon cameout, it was a dream. It was working fine for everything on v6. In v7, its hit or miss. Some devices work fine, some do not. Some people say its related to vlans, while others say thats not it. A most recent example. I have a camp...
by CTSsean
Fri Dec 16, 2022 7:16 pm
Forum: Containers
Topic: Container environment variable passing not working? (7.6/x86) Topic is solved
Replies: 2
Views: 4329

Re: Container environment variable passing not working? (7.6/x86) Topic is solved

aidanonym, I tried your recommendation when I check the log, I get this... /container /container add cmd=env envlist=ZTnetwork1 interface=veth1-ZT logging=yes start-on-boot=yes /container envs add key=NETWORK_ID name=ZTnetwork1 value=1234 /log/print 17:13:16 container,info,debug r=> Configuring netw...
by CTSsean
Sun Oct 09, 2022 3:55 am
Forum: General
Topic: Now that fq_codel and cake are stable... how are we doing?
Replies: 23
Views: 11377

Re: Now that fq_codel and cake are stable... how are we doing?

Here's been my experience.... If I use a simple queue using the max limit in the simple queue itself, Cake / FQ_Codel seems to work well enough. If I use a simple queue using the limits inside the Cake type itself, during testing, after the download queue has been maxed out, when testing the upload ...
by CTSsean
Thu Sep 15, 2022 6:10 pm
Forum: Wireless Networking
Topic: What is the proper config for a routed 60ghz PTMP AP with failover.
Replies: 1
Views: 640

What is the proper config for a routed 60ghz PTMP AP with failover.

I'm looking to set up a routed PTMP network with failover. Eth1 and wireless would not be bridged together. In the wiki - it shows https://wiki.mikrotik.com/wiki/Manual:Interface/W60G#Point_to_Multi_Point_setup_example It shows adding both the eth1 and wlan1 interfaces to the bridge. If I don't add ...
by CTSsean
Mon Aug 15, 2022 6:52 pm
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101574

Re: mDNS repeater feature

The problem is there is no point separating trusted and untrusted vans when you allow the untrusted one inject an advertisement into the trusted one to get the trusted one to call into it not to mention allowing the untrusted one to see all that is advertised on the trusted one. Very helpful in its...
by CTSsean
Thu Feb 03, 2022 5:12 pm
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101574

Re: mDNS repeater feature

Yes, the question is, why separate the IoT, if you don't really need to separate ? Trust. The same reason is why you firewall your input chain from the world... You can't always trust that people won't do the right thing. This is the reason for a LOT of vlans. However with IoT, there are service ne...
by CTSsean
Fri Dec 03, 2021 3:39 pm
Forum: RouterBOARD hardware
Topic: The sync button doesn’t work on PWR-Line AP
Replies: 0
Views: 3380

The sync button doesn’t work on PWR-Line AP

Recently purchased a pair of PWR-Line APs and discovered the sync button refuses to sync two PWR-Line AP devices together. Followed the instructions, cleared all PLC settings, then used the hold for 2 seconds to start the sync process, and nothing. The two devices do not find each other and the keys...
by CTSsean
Wed Dec 30, 2020 3:07 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 295
Views: 128329

Re: v6.48 [stable] is released!

I think the moral to this story is to avoid majors (6.48) and wait until the first minor (6.48.1) Moral of this story: 1. MKT was forced by sales department to release "new" (7b/6b) versions before christmas without testing 2. Never trust blindly and install anything on holiday season onl...
by CTSsean
Sat Sep 12, 2020 12:22 am
Forum: Wireless Networking
Topic: [Help] Mikrotik CAPsMAN Wireless download speed max 200Mb, but PC's /Mobile's link speed is 866Mbps
Replies: 65
Views: 14356

Re: [Help] Mikrotik CAPsMAN Wireless download speed max 200Mb, but PC's /Mobile's link speed is 866Mbps

I agree with everyone here Getting 'good' to 'great' performance with Mikrotik Wifi is a bear. Compared to say generic Comcast modem, where its instantly connects and has high throughput, I could play with Mikrotik for weeks and not get the same performance. I've been putting wifi networks together ...
by CTSsean
Sat Apr 06, 2019 6:49 pm
Forum: General
Topic: SIP port(s)
Replies: 6
Views: 1530

Re: SIP port(s)

Are there any plans to add any SIP ports to any switches or routers? The HAP ac with one would make an ideal home router with a SIP port added and remove the need for an extra box for VOIP.
SIP port? Do you mean ATA port as Mikrotik already supports SIP ALG just fine.
by CTSsean
Mon Apr 01, 2019 4:45 pm
Forum: General
Topic: v6 RC and v7 BETA
Replies: 126
Views: 46707

Re: v6 RC and v7 BETA

RouterOS 7 is here [removed link]! Finally!
by CTSsean
Mon Apr 01, 2019 4:16 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 81378

Re: UKNOF 43 CVE

We have near to 10k Mikrotik devices in our network, if every one of them needs to be updated. This is not something you do in a few hours .. or days. ... And the issue is, that it is not the first time, that Mikrotik has handled an issue this way. It is every single time. They only react, when iss...
by CTSsean
Fri Mar 01, 2019 12:45 am
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 387
Views: 192992

Re: RB4011

To those having bad 5Ghz problems, do not choose auto. It may be that MikroTik is choosing a dFS channel and not all modern devices support DFS channels properly.
by CTSsean
Sat Jan 05, 2019 4:40 pm
Forum: RouterBOARD hardware
Topic: ltap mini usb power LTE interface off
Replies: 7
Views: 5415

Re: ltap mini usb power LTE interface off

Same problem. not happy. Why include a USB power input if its not enough to actually power the LTE interface. It's bs.
by CTSsean
Sun Nov 18, 2018 7:39 pm
Forum: RouterBOARD hardware
Topic: LtAP Mini GPS useless without antenna
Replies: 82
Views: 28100

Re: LtAP Mini GPS useless without antenna

My question is how did this get past QA? How did so many devices who cannot lock on to GPS without an external antenna get shipped? This is probably as paramount for a recall from Mikrotik as I've ever seen. A core feature which is advertised (STILL) on the device but doesn't state the external ante...
by CTSsean
Tue Nov 06, 2018 6:23 pm
Forum: General
Topic: Why remote logging not work?
Replies: 9
Views: 4420

Re: Why remote logging not work?

Just to clue other people in... its a matcher in the MT syslog that is the problem.

If you try to send critical,error,info, etc all at once. Only events that match all 3 topics will be sent. you have to send individual topics separately.
by CTSsean
Mon Aug 20, 2018 7:16 pm
Forum: Scripting
Topic: How to Disable auto-completion of commands in terminal
Replies: 8
Views: 24646

Re: How to Disable auto-completion of commands in terminal

^^ Thank you for that!
by CTSsean
Tue May 15, 2018 4:27 pm
Forum: Scripting
Topic: Error handling?
Replies: 4
Views: 13621

Re: Error handling?

Going to resurrect this as I found this during my runtime error handling testing. The syntax format has to be very specific to process the error handling properly. Example: :do {/interface bridge add name=loopback; } on-error={:put "loopback exists"} So its :do {whatever command you want t...
by CTSsean
Wed May 09, 2018 10:10 pm
Forum: Scripting
Topic: Unable to use variables substitution within an array
Replies: 0
Views: 910

Unable to use variables substitution within an array

Another rant... Just discovered that when trying to use a variable within an array with keys, it does a comparison instead. example: :global "newAddressListArray" {$localserver="OnPremiseServer"} or example: :global "newAddressListArray" {"$localserver"="...
by CTSsean
Mon May 07, 2018 5:55 pm
Forum: General
Topic: OpenVPN SHA256 + UDP
Replies: 67
Views: 48344

Re: OpenVPN SHA256 + UDP

IMO, if RouterOS7 is vapor ware, OpenVPN UDP needs to be addressed.
by CTSsean
Mon May 07, 2018 3:24 am
Forum: Scripting
Topic: Scripting can run via console but not import or run scripts. Suggestions?
Replies: 0
Views: 809

Scripting can run via console but not import or run scripts. Suggestions?

###This Script will auto create vlans that are missing ###Add the vlans you need to have in the newVlanArray variable by using "vlanid"="vlanName" and the script will do the rest ###BOF### ##Initialize variables :global "physInterface" ether6; :global "newVlanArra...
by CTSsean
Sun May 06, 2018 10:25 pm
Forum: Scripting
Topic: rant about Functions arguments and variables
Replies: 0
Views: 770

rant about Functions arguments and variables

Discovered today that if you send a function an argument, you can no longer use a global variable within the function. Once a argument is passed to the variable, the global variable is no longer referenced by the root, but only by the arguments that are passed in. Example: :global "physInterfac...
by CTSsean
Fri May 04, 2018 6:37 pm
Forum: Scripting
Topic: How To Get Keys of this Array ?
Replies: 4
Views: 7984

Re: How To Get Keys of this Array ?

The array_keys() function is used to get all the keys or a subset of the keys of an array.
Here is syntax

array_keys(input_array, search_key_value, strict)
from my testing... this function doesn't exist within RouterOS. Can you give me a syntax example?
by CTSsean
Thu Apr 26, 2018 5:37 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 613
Views: 257468

Re: RouterOS v7.0 beta1 - when?

DNF was released in 2011, so ...
so 15 years from version to version. Nice... so we only have another 11 years.
by CTSsean
Tue Mar 20, 2018 7:06 pm
Forum: General
Topic: mangle and Qos - pre vs post routing
Replies: 5
Views: 2484

Re: mangle and Qos - pre vs post routing

- there can only be a single packet mark on a packet, so when you want to use packet-marks
both for routing decisions and for QoS, you need to apply the mark for QoS in post-routing
For routing decisions (and routing marks), wouldn't you do that pre-routing?
by CTSsean
Tue Mar 20, 2018 6:35 pm
Forum: General
Topic: mangle and Qos - pre vs post routing
Replies: 5
Views: 2484

Re: mangle and Qos - pre vs post routing

Why would one mangle pre-routing vs post-routing for QOS? I've seen it both ways but don't know why. I'm sure someone will post you a link of the packet flow diagram but it depends on that according to how you are routing the packets. Generally go for pre-routing although for a lot my applications ...
by CTSsean
Tue Mar 20, 2018 1:54 pm
Forum: General
Topic: mangle and Qos - pre vs post routing
Replies: 5
Views: 2484

mangle and Qos - pre vs post routing

Why would one mangle pre-routing vs post-routing for QOS?

I've seen it both ways but don't know why.
by CTSsean
Sun Mar 11, 2018 7:02 pm
Forum: General
Topic: How to setup DSCP 46 Priority for voip?
Replies: 37
Views: 22063

Re: How to setup DSCP 46 Priority for voip?

first, Thank you IntrusDave for the script. If someone wouldn't mind explaining, why put the DSCP mangle on the post routing chain and not the pre-routing chain?

Also, why use the default queue tree and not say pcq?
by CTSsean
Sun Nov 05, 2017 8:43 pm
Forum: Scripting
Topic: Useful scripts
Replies: 116
Views: 297779

Re: Useful scripts

Here are my FreeDNS script for updating a FreeDNS domain, when you have more than 1 FreeDNS domain. It also posts the start and stop of the script in the log. It was originally created by LESHIY_ODESSA, but I've improved it by adding some error checking and making this work when you have more than 1...
by CTSsean
Fri Sep 15, 2017 2:38 pm
Forum: Beginner Basics
Topic: Yet Another OVPN Numpty Issue
Replies: 8
Views: 1722

Re: Yet Another OVPN Numpty Issue

Your firewall rules are all kinds of messed up. action=drop chain=input comment="Rule to stop GuestLAN accessing OfficeLAN" dst-address=192.168.99.0/24 src-address=192.168.150.0/24 action=accept chain=input comment="Rule to allow GuestLAN traffic to Printer1" dst-address=192.168....
by CTSsean
Fri Sep 15, 2017 2:24 pm
Forum: Beginner Basics
Topic: Yet Another OVPN Numpty Issue
Replies: 8
Views: 1722

Re: Yet Another OVPN Numpty Issue

WAN1 and WAN2 are on seperate ethernet connections ether23 and ether24.
why is your gateway set for google?
by CTSsean
Fri Sep 15, 2017 12:57 pm
Forum: Beginner Basics
Topic: Yet Another OVPN Numpty Issue
Replies: 8
Views: 1722

Re: Yet Another OVPN Numpty Issue

How are you connecting WAN1 and WAN2?

Via a single interface or multiple?