Community discussions

MikroTik App

Search found 30 matches

by F1le
Wed Jan 10, 2024 10:58 pm
Forum: General
Topic: EoIP DHCP to specific MAC from SITE B
Replies: 2
Views: 922

Re: EoIP DHCP to specific MAC from SITE B

I want to make sure that two MAC addresses from Site "A" will get from DHCP server IPs from Site "B", but rest of the network is cut from any DHCP visibility outside of own network.
by F1le
Tue Jan 09, 2024 2:07 am
Forum: General
Topic: EoIP DHCP to specific MAC from SITE B
Replies: 2
Views: 922

EoIP DHCP to specific MAC from SITE B

Hello, I have configured EoIP, bridged and cut DHCP on UDP ports 67-68 just to make sure network is working correctly and Site "A" receives its own DHCP pool and Site "B" its own. In reality the traffic between Site A and B works L3 using Wireguard fully routed -> all works fine ...
by F1le
Wed Dec 06, 2023 11:15 pm
Forum: General
Topic: Wireguard tunnel - speed problem
Replies: 19
Views: 3447

Re: Wireguard tunnel - speed problem

Yeah I think about moving back to IPSEC (IKEv2) to test it... GUYS YOU WON'T BELIEVE! It's running full speed. What I have done? I forced both Mikrotiks RB5009 to work on max CPU Frequency = 1400Mhz without "auto" power savings! https://puu.sh/JW7Ad/db6c645fe1.png And here comes the result...
by F1le
Mon Dec 04, 2023 1:18 pm
Forum: General
Topic: Wireguard tunnel - speed problem
Replies: 19
Views: 3447

Re: Wireguard tunnel - speed problem

You are right. I launched 3 FTP sessions on WireGuard and managed to reach 80MB/s. But when I launched 3xSMB transfers they were all total 35MB/s so they were split 10-12MB/s each. What kinds of CPE's you have in both sites? I'm guessing from the speeds that at least the 2000/600 side is GPON some v...
by F1le
Sun Dec 03, 2023 4:56 pm
Forum: General
Topic: Wireguard tunnel - speed problem
Replies: 19
Views: 3447

Re: Wireguard tunnel - speed problem

I just tested FTP connection without WireGuard, and I managed to get full 1Gbit/s. There's no any queues, and config is really basic, with just UDP ports opened for WireGuard server. There's seriously nothing extraordinary in config. Totally default, zero queues. Hi, Could you graph the Rx only (To ...
by F1le
Sat Dec 02, 2023 11:15 pm
Forum: General
Topic: Wireguard tunnel - speed problem
Replies: 19
Views: 3447

Re: Wireguard tunnel - speed problem

I have enough of those Mikrotiks unfortunately, but I need 2.5GbE ethernet. Slowly I start to think to get rid of Mikrotiks.

I think about : QNAP QHORA-322 but doesn't have SFP+, I need 2.5GbE and SFP+.
by F1le
Sat Dec 02, 2023 11:06 pm
Forum: General
Topic: Wireguard tunnel - speed problem
Replies: 19
Views: 3447

Re: Wireguard tunnel - speed problem

I can't get more than 350Mbit/s on TCP, but server can receive 450Mbit/s. I don't get it. This is speed test from router "A" (1Gbit symmetric MTU=1500 without PPPoE) to "B" (2/600, PPPoE MTU=1492) on WireGuard tunnel. https://puu.sh/JVORn/1274866361.png But let's check only TX fr...
by F1le
Sat Dec 02, 2023 6:20 pm
Forum: General
Topic: Wireguard tunnel - speed problem
Replies: 19
Views: 3447

Re: Wireguard tunnel - speed problem

I guess you're hitting the CPU ceiling here. While running tests, run CPU profiler, likely one of CPU cores will be at 100%. And I can imagine that wireguard handling might be tied to single CPU core for a few good reasons. https://puu.sh/JVNUj/e205b48725.png I would say 300-350 is pretty decent wi...
by F1le
Sat Dec 02, 2023 1:32 am
Forum: General
Topic: Wireguard tunnel - speed problem
Replies: 19
Views: 3447

Wireguard tunnel - speed problem

Guys, I've been trying to get a full speed between 2 links using Wireguard tunnel. Ping between them is 5-7ms. Two different operators, but having link in local IX so path is very short. Both routers RB5009. One site which has server on board (let's call it A) is full symmetric 1Gbit/s, second one h...
by F1le
Thu Sep 14, 2023 4:33 am
Forum: General
Topic: New Ubiquiti Multi-gig RJ45 NBASE-T Transceiver not working
Replies: 48
Views: 9330

Re: New Ubiquiti Multi-gig RJ45 NBASE-T Transceiver not working

I've been in contact with support on this and can now happily report as of latest version v7.11, for me this is now working!!! No more RX Loss. I was trying RB5009 + this UACC-CM-RJ45-MG on 7.11.2 and nope. It can see it, but nothing can be negotiated (1000Mbit/s on the other side), even if I put m...
by F1le
Sun May 28, 2023 2:27 pm
Forum: Announcements
Topic: v7.9.1 [stable] is released!
Replies: 59
Views: 18337

Re: v7.9.1 [stable] is released!

My mangle rules stopped working after 7.9.1 update... on RB5009 It just can't mark certain CONTENT packets anylonger... Anybody has same issue? I made another entry in Mangle rule : chain=prerouting action=add-dst-to-address-list protocol=tcp address-list=TEST address-list-timeout=5d dst-port=443 lo...
by F1le
Sun May 28, 2023 1:29 am
Forum: General
Topic: Suddenly firewall rule stopped adding IP addresses to a LIST
Replies: 10
Views: 869

Suddenly firewall rule stopped adding IP addresses to a LIST

I'm not sure if after 7.9.1 update suddenly my mangle rules stopped working. I have 2xWANs and there are some IPs I want to route through 2nd WAN. Normally I used this config to add specific CONTENT name using prerouting to a LIST and later mark routing to second WAN, it was working 100% fine and su...
by F1le
Wed Apr 12, 2023 12:48 am
Forum: RouterBOARD hardware
Topic: Port flapping RB5009 + vodafone modem
Replies: 35
Views: 14034

Re: Port flapping RB5009 + vodafone modem

Hello there :-) I had the same problem: mikrotik rb5009 and Arris TG 3442 cable modem. Also port was flapping off and on, and my internet connection was interrupting. I have changed settings on mikrotik: autonegotiation off, and set 1 Gb with full duplex, but this didn't help. Then I called my ISP,...
by F1le
Fri Apr 07, 2023 1:01 am
Forum: RouterBOARD hardware
Topic: Port flapping RB5009 + vodafone modem
Replies: 35
Views: 14034

Re: Port flapping RB5009 + vodafone modem

I have a pretty standard network config: Vodafone modem (Arris TG3442) -> RB5009 Got the same configuration 1:1 and same problem - Arris TG3492LG + RB5009. Sometimes once a day, sometimes 10 times per 10 minutes... v7.8. Anybody got any fix for that port flapping? Doesn't matter if it's port #1 2.5...
by F1le
Sun May 03, 2020 12:48 am
Forum: Beginner Basics
Topic: IPSec IPIP tunnel
Replies: 2
Views: 1308

Re: IPSec IPIP tunnel

I think I found a mistake ... I created 2 tunnels : IPIP and IPSEC, instead of one tunnel IPIP encrypted by IPSEC...

Wrong entries in IPSEC addresses. I put external IP instead of local IPs... Tunnel connected on 1480, and all problems seems to be gone.
by F1le
Sat May 02, 2020 5:43 pm
Forum: Beginner Basics
Topic: IPSec IPIP tunnel
Replies: 2
Views: 1308

IPSec IPIP tunnel

Guys just quick question I got 2xRB4011 on 2 sites. Got the linked by IPSEC Tunnel IPIP, I think I observe weird behavior and trying to figure out what's going on, but IPIP connects on MTU 1418, while rest of the network and of course internet connection is 1500. Can it have any influence? Result : ...
by F1le
Sun Sep 15, 2019 11:39 pm
Forum: Beginner Basics
Topic: Router allows ping but not allowing to display www
Replies: 7
Views: 2736

Re: Router allows ping but not allowing to display www

But it does not ...
So far the whole day IPIP works fine. I do not use IPv6 so don't really care about GRE if that's the only one difference vs IPIP, there are no drops in browsing pages like with GRE active tunnel.
by F1le
Sun Sep 15, 2019 5:41 pm
Forum: Beginner Basics
Topic: Router allows ping but not allowing to display www
Replies: 7
Views: 2736

Re: Router allows ping but not allowing to display www

Thanks, so far I've changed GRE to IPIP and looks like problem has gone. Don't know what happened but one site was changing MTU to 1380 second to 1420 and lots of problems were happening there. Changing MTU statically to 1500 on GRE killed performance and transfers and raised up tons of packet losse...
by F1le
Sun Sep 15, 2019 1:28 pm
Forum: Beginner Basics
Topic: Router allows ping but not allowing to display www
Replies: 7
Views: 2736

Re: Router allows ping but not allowing to display www

lower MTU to what value you suggest? Can MTU be lowered on WAN interface, but still be 1500 on the rest of the ports? After excessive tests it looks like my GRE tunnel is causing troubles. Have GRE IPSec connection to my parent's house to have LAN-LAN connection and that started to cause trouble. Le...
by F1le
Sun Sep 15, 2019 1:57 am
Forum: Beginner Basics
Topic: Router allows ping but not allowing to display www
Replies: 7
Views: 2736

Router allows ping but not allowing to display www

Guys, Weird thing, I got 3011 and from some time I'm facing some challenge. Suddenly router is not routing correctly. Ping works fine, but it doesn't want to display www I disconnected router and the same time put a cable directly to my computer - all works fine Each time need to leave as it is, but...
by F1le
Tue Nov 27, 2018 2:39 am
Forum: General
Topic: Problem with IPsec after update to 6.42
Replies: 18
Views: 12436

Re: Problem with IPsec after update to 6.42

I do confirm. Has the same problem with IPSec...

Any workaround?
by F1le
Mon Sep 03, 2018 3:37 pm
Forum: RouterBOARD hardware
Topic: RB 3011
Replies: 5
Views: 1550

Re: RB 3011

Got no clue. Replaced my old hAP AC to RB3011... I took, my old configuration from hAP and uploaded it to RB3011. No issues at all, except the fact that LED panel shows all the time "Starting services" while all works fine. Not sure, but initially it was working fine until I uploaded old c...
by F1le
Mon Jan 08, 2018 3:03 am
Forum: Announcements
Topic: v6.41 [current]
Replies: 304
Views: 140541

Re: v6.41 [current]

First thing which happened after upgrade to 6.41 from 6.40.5 was all the time SFP connection drop. I have to go to the router unplug it and plug it again. Running on :

RB962UIGS 5HACT2HNT HAP AC

During 4h after upgrade it happened twice till now. On 6.40.5 it was running rock solid on SFP.
by F1le
Sat Nov 25, 2017 7:03 pm
Forum: Beginner Basics
Topic: Connect to LAN behind mikrotik router over ipsec
Replies: 4
Views: 1293

Re: Connect to LAN behind mikrotik router over ipsec

And from 80 to 9 you can get the response?
by F1le
Sat Nov 25, 2017 5:17 pm
Forum: Beginner Basics
Topic: Tunnels and IPSec encryptions - how to check the encryption?
Replies: 1
Views: 1218

Tunnels and IPSec encryptions - how to check the encryption?

How to check if a GRE (or any other) tunnel is running on an encrypted IPSec connection (tunnel) ?
by F1le
Tue Nov 21, 2017 7:02 pm
Forum: Beginner Basics
Topic: IPSec GRE Tunnel and lack of response of some hosts [SOLVED]
Replies: 6
Views: 1495

Re: IPSec GRE Tunnel and lack of response of some hosts [SOLVED]

Ok solved. Loved when I solve a problem by myself, as it's my 3rd day with Mikrotik :) I added NAT rule and it worked out, so destination to 3 IP addresses 10.0.1.251, 10.0.1.248. 10.0.1.249 are NATted : Based on 1 IP : 10.0.1.251 (I'll create a list with the exceptions) : By-pass NAT : https://puu....
by F1le
Tue Nov 21, 2017 5:03 pm
Forum: Beginner Basics
Topic: IPSec GRE Tunnel and lack of response of some hosts [SOLVED]
Replies: 6
Views: 1495

Re: IPSec GRE Tunnel and lack of response of some hosts [SOLVED]

second site https://puu.sh/yqEol/638290cb17.png Routes are OK. I think if I would have had a possibility to change in those 3 Access Points IP address to DHCP or set them gateways it would have solved the problem, but this is the problem I need to deal with. I think I need to cheat those 3 IPs and c...
by F1le
Tue Nov 21, 2017 4:01 pm
Forum: Beginner Basics
Topic: IPSec GRE Tunnel and lack of response of some hosts [SOLVED]
Replies: 6
Views: 1495

Re: IPSec GRE Tunnel and lack of response of some hosts [SOLVED]

This is how it looks, my static route. That's from the 10.0.1.250/24 172.16.1.2 side. I think last entry in the static route is this what you're talking about : Your approach with the GRE tunnel is good, but you forget to set routes to the network on the other side. So you need to add a route to 10....
by F1le
Tue Nov 21, 2017 11:38 am
Forum: Beginner Basics
Topic: IPSec GRE Tunnel and lack of response of some hosts [SOLVED]
Replies: 6
Views: 1495

Re: IPSec GRE Tunnel and lack of response of some hosts [SOLVED]

I found the issue was created by 3xAP which with netmask /24 na IP addresses made static (they are routeres, so they can't get IP address via DHCP) : 10.0.1.251 10.0.1.248 10.0.1.249 They can't be accessed via 192.168.0.1/24, as all addresses from different sites are by-passed NAT. I can change curr...
by F1le
Tue Nov 21, 2017 1:52 am
Forum: Beginner Basics
Topic: IPSec GRE Tunnel and lack of response of some hosts [SOLVED]
Replies: 6
Views: 1495

IPSec GRE Tunnel and lack of response of some hosts [SOLVED]

I needed to link 2 networks. Mostly because of NAS which is located in one site (Both RB962). The tunnel seems to work fine, I by-passed NAT for local networks, so it looks like this : https://puu.sh/yqfR2/7eead0d2c0.png And got couple of noobie questions : 1/ Can I leave only IpSec removing tunnel ...