Community discussions

MikroTik App

Search found 2271 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 8
by Zacharias
Mon May 18, 2020 9:25 pm
Forum: General
Topic: How to limit upload while downloading is at its maximum?
Replies: 15
Views: 2420

Re: How to limit upload while downloading is at its maximum?

The queues in RouterOS only limit egress traffic
And i' ve seen the packet flow diagram a hundred times... but i missed it... why why ....
Thanks @sindy...

So it is better to use the Global Parent, meaning all the Interfaces and mark egress packets accordingly for Download and Upload, right ?
by Zacharias
Mon May 18, 2020 12:22 pm
Forum: General
Topic: Help with hotspot
Replies: 1
Views: 313

Re: Help with hotspot

Try login with MAC...
by Zacharias
Mon May 18, 2020 10:23 am
Forum: General
Topic: How to limit upload while downloading is at its maximum?
Replies: 15
Views: 2420

Re: How to limit upload while downloading is at its maximum?

That's the whole point - the line is not 50/50 symmetric
Ok my mistake...
We did not choose an interface but global - that's not an interface
Yes i know, am asking in general, how do we make the choice of an interface to be the upload or download one...
by Zacharias
Sun May 17, 2020 8:27 pm
Forum: General
Topic: How to limit upload while downloading is at its maximum?
Replies: 15
Views: 2420

Re: How to limit upload while downloading is at its maximum?

But any of the child queues is free to use that bandwidth completely if there is no traffic in the other child queues, This is what i mean, if the Download child uses the whole 50Mbits, what will then happen with the Upload? Since the Parent is limited to 50Mbit.. The Upload child will get the guar...
by Zacharias
Sat May 16, 2020 2:36 pm
Forum: General
Topic: No internet via non-main routing tables if missing default route on main [SOLVED]
Replies: 21
Views: 2233

Re: No internet via non-main routing tables if missing default route on main [SOLVED]

I did disable/enable and again i do get the expected result...
What is your ROS versions?
by Zacharias
Sat May 16, 2020 2:19 pm
Forum: General
Topic: No internet via non-main routing tables if missing default route on main [SOLVED]
Replies: 21
Views: 2233

Re: No internet via non-main routing tables if missing default route on main [SOLVED]

I have just reproduced the error again. i will post details in a moment please bear with me. i am not going insane after all
I reproduced it as well and it gave me the expected result...
by Zacharias
Sat May 16, 2020 2:15 pm
Forum: General
Topic: No internet via non-main routing tables if missing default route on main [SOLVED]
Replies: 21
Views: 2233

Re: No internet via non-main routing tables if missing default route on main [SOLVED]

why does creating a bogus default route on the main routing table otherwise solve my issue?
No it does not solve the issue...
by Zacharias
Sat May 16, 2020 1:58 pm
Forum: General
Topic: No internet via non-main routing tables if missing default route on main [SOLVED]
Replies: 21
Views: 2233

Re: No internet via non-main routing tables if missing default route on main [SOLVED]

You ve set Routing Marks, so there is no Main Routing Table...
It is actually your mistake...
Tell the Router to use the Table named "foo" and everything will work just fine...
by Zacharias
Sat May 16, 2020 1:50 pm
Forum: General
Topic: How to limit upload while downloading is at its maximum?
Replies: 15
Views: 2420

Re: How to limit upload while downloading is at its maximum?

@sindy shouldn't the max limit of the Parent be the sum of the Child's max limit? If the Upload is 50Mbit and the Download 50Mbit as well then the Max limit of the Parent must be the sum of it... Also something i have difficulty understanding, if we do not use Global as parent, then for the Upload s...
by Zacharias
Fri May 15, 2020 8:56 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 167
Views: 219745

Re: Using RouterOS to QoS your network - 2020 Edition

I ve used Queue Trees mostly with Global Parent.
My question is, why do we use as Parent the Lan Interface for the Download Traffic and the WAN for the Upload Traffic ?
by Zacharias
Sun May 10, 2020 7:32 pm
Forum: Beginner Basics
Topic: Admin access via the internet
Replies: 14
Views: 1742

Re: Admin access via the internet

Where is this super simple magical VPN tick box.
I wonder that too...
by Zacharias
Sun May 10, 2020 7:30 pm
Forum: General
Topic: IPsec between two RB behind NAT
Replies: 18
Views: 1890

Re: IPsec between two RB behind NAT

ok @sindy thanks for reminding me :D
by Zacharias
Sun May 10, 2020 5:35 pm
Forum: General
Topic: IPsec between two RB behind NAT
Replies: 18
Views: 1890

Re: IPsec between two RB behind NAT

ESP need not be forwarded as if there is NAT at at least one end, it cannot be used.
Isn't ESP encapsulated inside the UDP packet ?
by Zacharias
Sun May 10, 2020 4:33 pm
Forum: General
Topic: IPsec between two RB behind NAT
Replies: 18
Views: 1890

Re: IPsec between two RB behind NAT

it will work with IKEv2 (for IKE(v1), you would need to forward also UDP port 500).
@sindy could you remind me why this happens ?
by Zacharias
Sun May 10, 2020 4:29 pm
Forum: Wireless Networking
Topic: CapsMan with mikrotik Vs Wireless mikrotik only?
Replies: 21
Views: 2371

Re: CapsMan with mikrotik Vs Wireless mikrotik only?

2404-2408-2412-2417-2422 for C
It is 2402-2407-2412 ...etc...
by Zacharias
Sun May 10, 2020 4:03 pm
Forum: Beginner Basics
Topic: Router Speed 1/3 of Direct Connection to Modem
Replies: 12
Views: 1592

Re: Router Speed 1/3 of Direct Connection to Modem

You ll get great performance results with this model...
by Zacharias
Sat May 09, 2020 10:42 pm
Forum: General
Topic: Access to server from internal LAN
Replies: 2
Views: 506

Re: Access to server from internal LAN

Example of Hairpin NAT here https://wiki.mikrotik.com/wiki/Hairpin_NAT
by Zacharias
Sat May 09, 2020 10:32 pm
Forum: General
Topic: Bidirectional Load Balancing for 2 LANs using 2 WANs
Replies: 8
Views: 1278

Re: Bidirectional Load Balancing for 2 LANs using 2 WANs

Where exactly would that help ?
by Zacharias
Sat May 09, 2020 9:31 pm
Forum: Beginner Basics
Topic: Failed to connect to internet
Replies: 16
Views: 2039

Re: Failed to connect to internet

/ip address
add address=192.168.2.1/24 comment=defconf interface=bridge network=\
    192.168.2.0
Set the address on your Bridge Interface and not on the ether2 slave Interface...
by Zacharias
Sat May 09, 2020 9:19 pm
Forum: Beginner Basics
Topic: Admin access via the internet
Replies: 14
Views: 1742

Re: Admin access via the internet

What is the VPN you mention about ?
by Zacharias
Sat May 09, 2020 9:07 pm
Forum: Beginner Basics
Topic: Router Speed 1/3 of Direct Connection to Modem
Replies: 12
Views: 1592

Re: Router Speed 1/3 of Direct Connection to Modem

I ll agree with @anav, RB4011 would be a good choice...
by Zacharias
Sat May 09, 2020 8:51 pm
Forum: Wireless Networking
Topic: CapsMan with mikrotik Vs Wireless mikrotik only?
Replies: 21
Views: 2371

Re: CapsMan with mikrotik Vs Wireless mikrotik only?

Set control channel width to 20Mhz and extention channel either disabled, in case you only want to use 20Mhz as channel width, or Ce, eC, XX in case you want to support 40 Mhz channel width as well...
by Zacharias
Sat May 09, 2020 1:06 pm
Forum: Wireless Networking
Topic: CapsMan with mikrotik Vs Wireless mikrotik only?
Replies: 21
Views: 2371

Re: CapsMan with mikrotik Vs Wireless mikrotik only?

Your question is already answered...
If you leave the Tx Power empty, the MAX allowed by interface is used...!
However, you must use the Tx Power allowed in your Country... That is why we select the Country...
by Zacharias
Sat May 09, 2020 12:54 pm
Forum: RouterBOARD hardware
Topic: VoIP POE Switch Recommendation [SOLVED]
Replies: 1
Views: 503

Re: VoIP POE Switch Recommendation [SOLVED]

I would suggest the CRS112... and don't forget the 48V Power supply...
by Zacharias
Sat May 09, 2020 12:48 pm
Forum: Announcements
Topic: Updated btest.exe available for download
Replies: 13
Views: 3063

Re: Updated btest.exe available for download

I guess most of you have already noticed that <TAB> key does not move focus from one input field to another.
And double click on an input field does not select the text.
I can confirm that as well...
by Zacharias
Sat May 09, 2020 12:44 pm
Forum: Wireless Networking
Topic: CapsMan with mikrotik Vs Wireless mikrotik only?
Replies: 21
Views: 2371

Re: CapsMan with mikrotik Vs Wireless mikrotik only?

If under Capsman -> Configurations -> Wireless you did set your Country (as you should) then the Tx Power will be the maximum allowed for you Country...
Only in case you want to lower the Tx Power you do use the Tx Power paramater field...
by Zacharias
Sat May 09, 2020 11:03 am
Forum: Wireless Networking
Topic: CapsMan with mikrotik Vs Wireless mikrotik only?
Replies: 21
Views: 2371

Re: CapsMan with mikrotik Vs Wireless mikrotik only?

The signal strength will be the same as long as your configuration is correct....
by Zacharias
Sat May 09, 2020 10:58 am
Forum: Wireless Networking
Topic: Band steering Mikrotik Audience and other aps [SOLVED]
Replies: 2
Views: 489

Re: Band steering Mikrotik Audience and other aps [SOLVED]

has anyone heard anything from Mikrotik yet, shell we hope for ROS 7?
Not really...
by Zacharias
Sat May 09, 2020 10:47 am
Forum: Announcements
Topic: Updated btest.exe available for download
Replies: 13
Views: 3063

Re: Updated btest.exe available for download

I guess most of you have already noticed that <TAB> key does not move focus from one input field to another.
Yes...
by Zacharias
Fri May 08, 2020 8:52 pm
Forum: General
Topic: router randomly drops WAN connection
Replies: 9
Views: 2344

Re: router randomly drops WAN connection

so even if the cable works with the PC, it may not with the Mikrotik
Am not really sure how that would make sense...
by Zacharias
Fri May 08, 2020 8:48 pm
Forum: Beginner Basics
Topic: CRS125 - PPPoE - NAT
Replies: 11
Views: 1504

Re: CRS125 - PPPoE - NAT

in-interface=PPPoE
You do not need to specify destination address... At least when accessing your Devices from outside the Local Network...
However you do not provide any information enough so that someone can actually help...
by Zacharias
Fri May 08, 2020 5:04 pm
Forum: General
Topic: Load balancing same gateway
Replies: 3
Views: 597

Re: Load balancing same gateway

by Zacharias
Fri May 08, 2020 5:00 pm
Forum: General
Topic: IPsec between two RB behind NAT
Replies: 18
Views: 1890

Re: IPsec between two RB behind NAT

Make sure only one will be behind NAT and make sure under /ip ipsec peer passive is enabled fo the RB that is not behind NAT...
The other RB must have send-initial-contact to yes
by Zacharias
Fri May 08, 2020 4:51 pm
Forum: General
Topic: IPsec between two RB behind NAT
Replies: 18
Views: 1890

Re: IPsec between two RB behind NAT

Are they both behind NAT ?
If yes, it will not work...
by Zacharias
Fri May 08, 2020 4:29 pm
Forum: Announcements
Topic: Updated btest.exe available for download
Replies: 13
Views: 3063

Re: Updated btest.exe available for download

Maybe the Local Tx Size and Remote Tx size would be best if they were renamed to MTU and MRU size ?
by Zacharias
Fri May 08, 2020 4:17 pm
Forum: Beginner Basics
Topic: How to access network from internet for some IP [SOLVED]
Replies: 7
Views: 875

Re: How to access network from internet for some IP [SOLVED]

Add that specific IP in the src-address parameter of your Firewall rule...
by Zacharias
Fri May 08, 2020 4:08 pm
Forum: Beginner Basics
Topic: CRS125 - PPPoE - NAT
Replies: 11
Views: 1504

Re: CRS125 - PPPoE - NAT

Does the PPPoE client get a Dynamic Public IP or not?
If it is a Dynamic you can use the cloud DNS of your Router...
by Zacharias
Sat May 02, 2020 5:05 pm
Forum: Beginner Basics
Topic: Idea for 2 routers and avoiding Double NAT while running srcnat on second router?
Replies: 2
Views: 751

Re: Idea for 2 routers and avoiding Double NAT while running srcnat on second router?

Yes you can remove the NAT from the 4011, but then you will have to create a route on your ISPs Modem-Router for the RB's 4011 Local Subnet...
by Zacharias
Sat May 02, 2020 4:54 pm
Forum: General
Topic: Problem Hardware Offload on CRS326-24G-2S+
Replies: 4
Views: 790

Re: Problem Hardware Offload on CRS326-24G-2S+

In case you want to segment your network, VLANs is what you should choose...
by Zacharias
Sat May 02, 2020 12:59 pm
Forum: RouterBOARD hardware
Topic: CCR2004-1G-12S+2XS with more RAM ?
Replies: 14
Views: 2828

Re: CCR2004-1G-12S+2XS with more RAM ?

I think you should better contact Mikrotik support for that question...
by Zacharias
Fri May 01, 2020 11:12 pm
Forum: General
Topic: can't connect to hEX S after factory reset / netinstall
Replies: 8
Views: 1228

Re: can't connect to hEX S after factory reset / netinstall

/system interface
How sure are you of that command ?
by Zacharias
Fri May 01, 2020 11:09 pm
Forum: General
Topic: Trying to duplicate a SwOS feature on ROS...
Replies: 9
Views: 1542

Re: Trying to duplicate a SwOS feature on ROS...

But, this "lock on first" feature does not seem to be possible with ROS nor does another similar solution. Something similar i do not think you will find in ROS... But it is possible with many other ways... Bridge Firewall as suggested earlier, with Bridge Reply-Only etc..., VLANs, PPPoE as others ...
by Zacharias
Fri May 01, 2020 9:08 pm
Forum: General
Topic: Trying to duplicate a SwOS feature on ROS...
Replies: 9
Views: 1542

Re: Trying to duplicate a SwOS feature on ROS...

You can make use of the Bridge Firewall under Bridge Settings...
Then you could restrict access to your Network only to a Specific MAC address...
by Zacharias
Fri May 01, 2020 8:55 pm
Forum: Wireless Networking
Topic: hap ac lite can't connect to another AP
Replies: 21
Views: 2789

Re: hap ac lite can't connect to another AP

the dhcp client went red
If you did let the DHCP-Client on the slave interface (wlan) obviously it did...
My simple suggestion, is unless you need Layer 2 connectivity, forget about any Bridge Mode and use Station Mode...
Then configure the Hap as a Router...
by Zacharias
Fri May 01, 2020 8:37 pm
Forum: General
Topic: Trying to duplicate a SwOS feature on ROS...
Replies: 9
Views: 1542

Re: Trying to duplicate a SwOS feature on ROS...

Yes but the Client might have 2 different laptops and in some cases work with one or the other... So, if you limit the MAC address that can access the network, simply you deny him the use of any other equipment might have... So does the client know that can only use 1 specific device and nothing els...
by Zacharias
Fri May 01, 2020 8:29 pm
Forum: General
Topic: convert QoS CISCO to Mikrotik
Replies: 3
Views: 2782

Re: convert QoS CISCO to Mikrotik

I am not really familiar with Cisco, so trying to translate its configuration might not be the best thing...
But, if you give us the Network Topology of your equipment and what does your Device should do we can as well help on that easily :D
by Zacharias
Fri May 01, 2020 8:26 pm
Forum: SwOS
Topic: LACP not work correct with Windows Server
Replies: 2
Views: 1000

Re: LACP not work correct with Windows Server

The mode used is Active on the Server by default : When you configure a Teaming mode of LACP, NIC Teaming always operates in LACP's Active mode with a short timer So you can let it to Passive on the Switch which is the default mode as well... What is the Loading Balancing Mode you use on the Server ...
by Zacharias
Fri May 01, 2020 8:14 pm
Forum: General
Topic: Trying to duplicate a SwOS feature on ROS...
Replies: 9
Views: 1542

Re: Trying to duplicate a SwOS feature on ROS...

May i ask a little more details about the topology ?
Does the Client have an equipment managed by you ? No ?
by Zacharias
Fri May 01, 2020 12:51 am
Forum: Wireless Networking
Topic: hap ac lite can't connect to another AP
Replies: 21
Views: 2789

Re: hap ac lite can't connect to another AP

Have a look at the screenshots posted- DHCP client is on the bridge interface, so (provided DHCP server is only accessible over wireless) there's no way it will work. Sorry but you are wrong on that... :D Yes the DHCP Client is on the Bridge Interface and that Bridge Interface has a slave Interface...
by Zacharias
Thu Apr 30, 2020 11:50 pm
Forum: Wireless Networking
Topic: hap ac lite can't connect to another AP
Replies: 21
Views: 2789

Re: hap ac lite can't connect to another AP

You can configure that, obviously, but it won't work. This does not change the fact that the DHCP Client should get an IP address without problems... As for the station-pseudobridge, should always be avoided !!! We should either create a Station mode and configure our Station to act as a router... ...
by Zacharias
Thu Apr 30, 2020 11:06 pm
Forum: Wireless Networking
Topic: hap ac lite can't connect to another AP
Replies: 21
Views: 2789

Re: hap ac lite can't connect to another AP

Are you sure you are connected to a network with an active and working DHCP server ?
You should be able to get an IP address and as i can see you do not...

After that, next question is, do you want to be on the same Layer 2 (same LAN) network as the AP you connect to ?
by Zacharias
Thu Apr 30, 2020 8:58 pm
Forum: Wireless Networking
Topic: hap ac lite can't connect to another AP
Replies: 21
Views: 2789

Re: hap ac lite can't connect to another AP

What is the Wireless Mode you use on your Mikrotik Station Device ?
I won't guess this time :lol:
by Zacharias
Thu Apr 30, 2020 8:55 pm
Forum: Wireless Networking
Topic: hAP ac lite router will not connect wifi printer to network
Replies: 6
Views: 1412

Re: hAP ac lite router will not connect wifi printer to network

another poster blaming the equipment and not the admin LOL. Isn't that what happens most of the times ? I guess you did connect your printer to your ADSL Router using the WPS Function of the Router's... So, you can either do it in two ways, your Hap AC has a physical WPS button, so either press thi...
by Zacharias
Thu Apr 30, 2020 8:40 pm
Forum: General
Topic: Can't update - could not resolve DNS name error [SOLVED]
Replies: 12
Views: 2116

Re: Can't update - could not resolve DNS name error [SOLVED]

I've never found any issue to be actually fixed by moving the IP settings from the slave port to the bridge.
Wrong is only something that makes our configuration not to work ?
by Zacharias
Thu Apr 30, 2020 7:24 pm
Forum: General
Topic: Can't update - could not resolve DNS name error [SOLVED]
Replies: 12
Views: 2116

Re: Can't update - could not resolve DNS name error [SOLVED]

What ROS Version your 2011 has?
Your router has its LAN IP address configured on a slave Interface, which is wrong... :D
by Zacharias
Thu Apr 30, 2020 7:03 pm
Forum: General
Topic: Bricked RB951G-2HnD
Replies: 8
Views: 1412

Re: Bricked RB951G-2HnD

protected-routerboot property ofcorse can be the reason you can not netinstall... RouterBOARD that has the protected RouterBOOT setting enabled will blink the LED every second, to make counting easier. Do you see this behavior ? https://wiki.mikrotik.com/wiki/Manual:RouterBOARD_settings#Protected_b...
by Zacharias
Thu Apr 30, 2020 6:47 pm
Forum: Beginner Basics
Topic: 2 LAN Cables from Mikrotik to Switch
Replies: 24
Views: 3198

Re: 2 LAN Cables from Mikrotik to Switch

BUT, I can only get 98Mps udp between the two when using 802.3ad when testing with udp, 140Mbps TCP 802.3ad does not double the bandwidth nor i ever said it does... If you do not care about the misordering of the Frames as far as TCP connections are concerned and the negative effects of that do not...
by Zacharias
Thu Apr 30, 2020 6:37 pm
Forum: Wireless Networking
Topic: 160MHz support for US RB4011
Replies: 13
Views: 4189

Re: 160MHz support for US RB4011

On a RB4011...
by Zacharias
Thu Apr 30, 2020 4:19 pm
Forum: Beginner Basics
Topic: 2 LAN Cables from Mikrotik to Switch
Replies: 24
Views: 3198

Re: 2 LAN Cables from Mikrotik to Switch

I just made a comment on TCP connections and 802.3ad...
The OP can choose the Mode that betters fits to his needs and ofcorse the mode that is supported by his equpment...
by Zacharias
Thu Apr 30, 2020 4:00 pm
Forum: Beginner Basics
Topic: 2 LAN Cables from Mikrotik to Switch
Replies: 24
Views: 3198

Re: 2 LAN Cables from Mikrotik to Switch

@pe1chl i do not see the point on what you said... The balancing modes are: 802.3ad, balance-rr, active-backup, balance-xor etc... So according to what you said: It depends on how you configure it the answer is simple, 802.3ad is a Bodning Mode and not a variation of the Balance-rr mode... So you ca...
by Zacharias
Thu Apr 30, 2020 3:37 pm
Forum: General
Topic: CRS354-48G-4S+2Q+ VLANs over bonding interface
Replies: 3
Views: 859

Re: CRS354-48G-4S+2Q+ VLANs over bonding interface

I already have a setup on GNS3 for such a scenario, so i wil give you an example with working and tested code... I ll give you the basic parts of the configuration... Main Router R1: Create Interface VLAN for every VID: /interface vlan add interface=bridge1 name=vlan10 vlan-id=10 add interface=bridg...
by Zacharias
Thu Apr 30, 2020 12:59 pm
Forum: General
Topic: CRS354-48G-4S+2Q+ VLANs over bonding interface
Replies: 3
Views: 859

Re: CRS354-48G-4S+2Q+ VLANs over bonding interface

Do you use any VLAN as management VLAN ? Since i do not see the whole config, What i would do is, have a management VLAN e.g. 99 setup on my router and then on the Switch, i would: Set an IP Address on the VLAN 99 e.g. 192.168.99.2 Set DNS 192.168.99.1 (Router's MGMT Vlan) Add the Bridge as Tagged M...
by Zacharias
Thu Apr 30, 2020 12:42 pm
Forum: Beginner Basics
Topic: 2 LAN Cables from Mikrotik to Switch
Replies: 24
Views: 3198

Re: 2 LAN Cables from Mikrotik to Switch

802.3ad (LACP) bonding does not have any negative effect on TCP connections...
Every existing connection always chooses the same link, they never get split between links... So there is no misordering...
by Zacharias
Thu Apr 30, 2020 12:20 pm
Forum: Wireless Networking
Topic: 160MHz support for US RB4011
Replies: 13
Views: 4189

Re: 160MHz support for US RB4011

For testing purposes i did try Regulatory Domain for Canada and United States 3. They both did work when setting Channel Width to 80Mhz and Secondary Frequency to Auto...
by Zacharias
Thu Apr 30, 2020 12:00 pm
Forum: General
Topic: PPPoE client connected but no internet [SOLVED]
Replies: 10
Views: 1978

Re: PPPoE client connected but no internet [SOLVED]

On your first post you had: add action=masquerade chain=srcnat comment="default configuration" disabled=no out-interface=ether1-gateway \ Which obviously is wrong, your out interface is not eth1 but the PPPoE client... This wrong rule does not keep the router from having access to the Internet, but ...
by Zacharias
Thu Apr 30, 2020 12:30 am
Forum: Wireless Networking
Topic: 160MHz support for US RB4011
Replies: 13
Views: 4189

Re: 160MHz support for US RB4011

What error are you getting?
Also sorry but my test was not for US (U-NII-2)... So my question is, you can not make it work for any country and or frequency ?
by Zacharias
Thu Apr 30, 2020 12:07 am
Forum: General
Topic: PPPoE client connected but no internet [SOLVED]
Replies: 10
Views: 1978

Re: PPPoE client connected but no internet [SOLVED]

How do I upgrade to 6.x? Net install?
System -> Packages -> Check for Updates -> Download and Install
by Zacharias
Wed Apr 29, 2020 11:46 pm
Forum: Wireless Networking
Topic: 160MHz support for US RB4011
Replies: 13
Views: 4189

Re: 160MHz support for US RB4011

Changelog of 6.45.1 shows: *) wireless - improved 160MHz channel width stability on rb4011; So i guess it works... But... I ll make a test on a RB4011 right now and let you know if it works... Edit: You can effectively set 160Mhz channel width...it works... The secondary Frequency parameter though.....
by Zacharias
Wed Apr 29, 2020 9:04 pm
Forum: General
Topic: CRS354-48P-4S+2Q+ traffic problem on ports 1 to 8
Replies: 21
Views: 3479

Re: CRS354-48P-4S+2Q+ traffic problem on ports 1 to 8

I can't take a look at your config right now...
Since it is new, in case you have no important config on it, just reset it to its default settings...
Or make a backup and then reset...
After that, remove all cables from every ethernet port and test them one by one ...
by Zacharias
Wed Apr 29, 2020 9:02 pm
Forum: Wireless Networking
Topic: LHG 60g no internet from the antenna interface [SOLVED]
Replies: 4
Views: 899

Re: LHG 60g no internet from the antenna interface

You can add a little more details of what did you change upon my suggestion so that we can help others who meet the same problem ?
Also please mark the post as solved :D
by Zacharias
Wed Apr 29, 2020 8:07 pm
Forum: Beginner Basics
Topic: Firewall: Locked out myself. What was the reason? [SOLVED]
Replies: 23
Views: 2436

Re: Firewall: Locked out myself. What was the reason? [SOLVED]

Changing the Public port of a Nat Rule or in general the port of a specific service does not provide a great security...
by Zacharias
Wed Apr 29, 2020 7:58 pm
Forum: General
Topic: CRS354-48P-4S+2Q+ traffic problem on ports 1 to 8
Replies: 21
Views: 3479

Re: CRS354-48P-4S+2Q+ traffic problem on ports 1 to 8

I don't think it would harm your device trying the update.
Ports 1-8 is the first Group of ports and since those specific ports do not work maybe you have made any changes in the Switch menu or anything ?
by Zacharias
Wed Apr 29, 2020 7:43 pm
Forum: Beginner Basics
Topic: Firewall: Locked out myself. What was the reason? [SOLVED]
Replies: 23
Views: 2436

Re: Firewall: Locked out myself. What was the reason? [SOLVED]

I had disabled all the MAC things as is recommended in the MT wiki page titled "Securing your router" or something that... Yes indeed is a good practice in case there is an actual risk of someone discovering your device through your Lan Network and trying to access it... If there is no such risk wh...
by Zacharias
Wed Apr 29, 2020 7:35 pm
Forum: Beginner Basics
Topic: Firewall: Locked out myself. What was the reason? [SOLVED]
Replies: 23
Views: 2436

Re: Firewall: Locked out myself. What was the reason? [SOLVED]

Firewall unless told otherwise, will block Layer 3 Activity...
So instead of spending 3 hours with that laptop you could as well login by MAC in less that 1 minute...

@anav a pencil works better...
by Zacharias
Wed Apr 29, 2020 7:23 pm
Forum: General
Topic: Auto updating ROS - yeah or nay?
Replies: 7
Views: 1268

Re: Auto updating ROS - yeah or nay?

It is good and recommended to keep your Device up to date. But i do not think that this means that we should update to every single new release that comes out unless it Fixes a Security issue or a Bug that was causing problems to our setup... But this is just my opinion...
by Zacharias
Wed Apr 29, 2020 7:06 pm
Forum: General
Topic: CRS354-48P-4S+2Q+ traffic problem on ports 1 to 8
Replies: 21
Views: 3479

Re: CRS354-48P-4S+2Q+ traffic problem on ports 1 to 8

Here is a related problem with CRS354, you can check the solution viewtopic.php?f=3&t=159176&p=787552&hil ... 54#p788593 and let us know if it fixes your problem...
by Zacharias
Wed Apr 29, 2020 6:58 pm
Forum: Beginner Basics
Topic: Port range not working in mangle rules
Replies: 6
Views: 1018

Re: Port range not working in mangle rules

Then only one question remains, how sure are you that indeed it was matched by the Rule because of that specific port ?
by Zacharias
Wed Apr 29, 2020 6:56 pm
Forum: General
Topic: Ip Route Rule vs Firewall Mangle on Cpu Load
Replies: 2
Views: 680

Re: Ip Route Rule vs Firewall Mangle on Cpu Load

Indeed, rules for Firewall Filter, Queues and Mangles are not applied for Fasttracked Traffic...
If you do not need the extra features that Mangles facility offers then just go with IP Route Rules...
by Zacharias
Wed Apr 29, 2020 6:10 pm
Forum: Wireless Networking
Topic: LHG 60g no internet from the antenna interface [SOLVED]
Replies: 4
Views: 899

Re: LHG 60g no internet from the antenna interface

Well, to start with, whatever you ve added inside the Interface Bridge VLAN does not work unless Bridge VLAN Filtering is enabled... But you do not as well need any Bridge VLAN Filtering on your Antennas... What i would do is create a seperate VLAN for my management purposes on my Router, eg VLAN 99...
by Zacharias
Wed Apr 29, 2020 5:52 pm
Forum: General
Topic: Fasttrack not working.
Replies: 18
Views: 2827

Re: Fasttrack not working.

Fasttrack wiki page lacks real world example with filter and/or mangle rules https://forum.mikrotik.com/viewtopic.php?f=13&t=160510&p=789313#p789313 Also here https://forum.mikrotik.com/viewtopic.php?f=13&t=160433&p=789209#p789209 Configuring the Firewall in RouterOS again there is a discussion of ...
by Zacharias
Wed Apr 29, 2020 5:46 pm
Forum: Virtualization
Topic: License rent for CHR
Replies: 8
Views: 1540

Re: License rent for CHR

At post #2 that i posted the link with the Wiki, clearly mentions It is possible to transfer a perpetual license to another CHR instance
by Zacharias
Wed Apr 29, 2020 5:44 pm
Forum: Beginner Basics
Topic: Port range not working in mangle rules
Replies: 6
Views: 1018

Re: Port range not working in mangle rules

I can't be sure or guess as to why the first rule was matched by that port although it does not exist in the ports field.
What is your ROS Version ?
Is it updated to latest Version ?
by Zacharias
Wed Apr 29, 2020 5:29 pm
Forum: Beginner Basics
Topic: pleas help me [SOLVED]
Replies: 5
Views: 1246

Re: pleas help me [SOLVED]

@vania902 with the only point of reference my experience, since i do not know all the details of your setup etc... you talk about a Public IP that is in a whole different subnet than the /30 block that your ISP gave you. So the first Public IP you mentioned, is most probably the IP that your ISPs mo...
by Zacharias
Wed Apr 29, 2020 5:16 pm
Forum: General
Topic: Queue at-rate not honoured
Replies: 5
Views: 1231

Re: Queue at-rate not honoured

Well, the HTB Interface as you will see from the Packet flow Diagram https://help.mikrotik.com/docs/display/ROS/Packet+Flow+in+RouterOS#PacketFlowinRouterOS-Example1 is just before the exit of the Physical Interface and more specifically in the Postrouting Chain... Also, as for the limit-at we discu...
by Zacharias
Wed Apr 29, 2020 4:51 pm
Forum: General
Topic: Need advice on firewall rules
Replies: 10
Views: 1651

Re: Need advice on firewall rules

If a Server has services available on the Internet without a VPN then there is always a security Risk... One suggestion would be to use the PSD value on the Firewall, which actually detects TCP and/or UDP Scans... A nice explanation is here: https://forum.mikrotik.com/viewtopic.php?t=108749#p539590 ...
by Zacharias
Tue Apr 28, 2020 11:53 pm
Forum: General
Topic: Fasttrack not working.
Replies: 18
Views: 2827

Re: Fasttrack not working.

At least 2... :D
by Zacharias
Tue Apr 28, 2020 8:54 pm
Forum: Beginner Basics
Topic: Bridge VLAN VRRP
Replies: 1
Views: 706

Re: Bridge VLAN VRRP

1. No it does not seem correct... I would setup VRRP on SFP1, on SFP2 and on SFP3 (Three different VRRPs) for CCR1 and CCR2... CCR1 would be set with higher Priority in order to be the Master and in case something happened to SFP1 of the CCR1 then SFP1 of CCR2 would start... 2. When working with VLA...
by Zacharias
Tue Apr 28, 2020 8:42 pm
Forum: Virtualization
Topic: License rent for CHR
Replies: 8
Views: 1540

Re: License rent for CHR

by Zacharias
Tue Apr 28, 2020 8:38 pm
Forum: General
Topic: Fasttrack not working.
Replies: 18
Views: 2827

Re: Fasttrack not working.

@mutluit how many posts have you opened for Fasttrack ? :lol:
by Zacharias
Tue Apr 28, 2020 5:26 pm
Forum: Beginner Basics
Topic: pleas help me [SOLVED]
Replies: 5
Views: 1246

Re: pleas help me [SOLVED]

It is always Best practice not to use your real Public IPs as an example... Your ISP gave you a /30 Subnet Block, lets say X.Y.Z.136/30 ... One of there addresses, usually the first one, so the 176.74.123.137 will be used by your ISP. The second one 176.74.123.138 must be used by you and setup on th...
by Zacharias
Tue Apr 28, 2020 4:25 pm
Forum: Beginner Basics
Topic: Multiple pptp clients on one mikrotik
Replies: 2
Views: 762

Re: Multiple pptp clients on one mikrotik

Sure you can create more that 1 PPTP Clients...

This is called Policy Based Routing. You can achieve it either with the use of Mangles, example here https://wiki.mikrotik.com/wiki/Policy_Base_Routing
or with IP Route Rules...
by Zacharias
Tue Apr 28, 2020 4:08 pm
Forum: Scripting
Topic: VPN Wake On LAN without DHCP
Replies: 2
Views: 730

Re: VPN Wake On LAN without DHCP

Why not instead use a WOL software, there are many and free, wake your Computer, get Informed as soon as it is active and then do your RDP Session ?

What is the practical reason for waking a Computer up on the first attempt of an RDP Session ? Just wondering...
by Zacharias
Tue Apr 28, 2020 4:02 pm
Forum: Beginner Basics
Topic: Configuring the Firewall in RouterOS [SOLVED]
Replies: 38
Views: 5068

Re: Configuring the Firewall in RouterOS [SOLVED]

I'll remove fasttrack from the input chain when I see a verification in an official MT document.
Did you click the Link i posted ? That answer is from Mikrotik Support member...
But sure, you know...
by Zacharias
Tue Apr 28, 2020 3:54 pm
Forum: Beginner Basics
Topic: Configuring the Firewall in RouterOS [SOLVED]
Replies: 38
Views: 5068

Re: Configuring the Firewall in RouterOS [SOLVED]

viewtopic.php?t=123251#p606537
FastTrack works only for forwarded traffic over the router, so there is no point adding fasttrack-connection in input chain.

Ofcorse you have your experience but that does not change the way things work... :D
by Zacharias
Tue Apr 28, 2020 3:51 pm
Forum: General
Topic: Bricked RB951G-2HnD
Replies: 8
Views: 1412

Re: Bricked RB951G-2HnD

Well @normis personally i ve had cases where the reset button did nothing during the booting process... Neither Reset, etherBoot Mode nor anything else...
And it wasn't physically damaged...
I ve had such a problem on a 951Ui-2hnd...
After NetInstall the button was working again as expected...
by Zacharias
Tue Apr 28, 2020 3:21 pm
Forum: Beginner Basics
Topic: Configuring the Firewall in RouterOS [SOLVED]
Replies: 38
Views: 5068

Re: Configuring the Firewall in RouterOS [SOLVED]

This is just the beginning, not the end :-)
Exactly, i did not go any further, i stopped when i saw that rule...
No it does not make sense...
by Zacharias
Tue Apr 28, 2020 3:15 pm
Forum: General
Topic: Bricked RB951G-2HnD
Replies: 8
Views: 1412

Re: Bricked RB951G-2HnD

does not have one. Checked the board carefully
It is on the back side i think...
by Zacharias
Tue Apr 28, 2020 2:20 pm
Forum: Wireless Networking
Topic: Rural p2p link advice required [SOLVED]
Replies: 14
Views: 2207

Re: Rural p2p link advice required [SOLVED]

I think it will work although i do not like that obstacle there... You should certainly use a higher pole for that Antenna and avoid that obstacle as much as you can (Better Performance)... I ve used both SXTs and LHGs (maybe every model available) on harsh enviroments with a great combination of Wi...
by Zacharias
Tue Apr 28, 2020 2:08 pm
Forum: Beginner Basics
Topic: Port range not working in mangle rules
Replies: 6
Views: 1018

Re: Port range not working in mangle rules

Am not sure if it is correct to add ports and port-ranges at the same line... According to the Manual it should be Ports or Port Ranges...
You can just move your last rules on top and you will be fine...

Edit, both ports and ports ranges can be used without a problem...
by Zacharias
Tue Apr 28, 2020 2:01 pm
Forum: Wireless Networking
Topic: Rural p2p link advice required [SOLVED]
Replies: 14
Views: 2207

Re: Rural p2p link advice required [SOLVED]

I agree with @pukkita and his suggestions...
Nice view as well...
by Zacharias
Tue Apr 28, 2020 1:48 pm
Forum: General
Topic: Bricked RB951G-2HnD
Replies: 8
Views: 1412

Re: Bricked RB951G-2HnD

Sometimes when the reset button does not work, the onboard reset pin does...
by Zacharias
Tue Apr 28, 2020 1:40 pm
Forum: The Dude
Topic: Dude SD failed - unable to recover
Replies: 4
Views: 991

Re: Dude SD failed - unable to recover

To me it seems your SD card just failed on a hardware level...
by Zacharias
Tue Apr 28, 2020 1:26 pm
Forum: General
Topic: L2TP FastPath not working.
Replies: 9
Views: 1583

Re: L2TP FastPath not working.

Please read carefully before reply.
Chill out @acidsas, people here dedicate some of their time to help you...
:D :D
by Zacharias
Tue Apr 28, 2020 1:23 pm
Forum: Beginner Basics
Topic: Configuring the Firewall in RouterOS [SOLVED]
Replies: 38
Views: 5068

Re: Configuring the Firewall in RouterOS [SOLVED]

No one can test your rules through a picture since not all parameters are visible...
But i did stop at the very first rule anyways, where did you find a fasttrack rule on the Input Chain ? :-?
by Zacharias
Tue Apr 28, 2020 1:15 pm
Forum: General
Topic: Failover not working [SOLVED]
Replies: 19
Views: 3096

Re: Failover not working [SOLVED]

I did a packet sniff, the request goes out from the other line to reach 8.8.8.8, but i guess that was obvious...
The unreachability is simulated through firewall or broken link on GNS3...

I also did test the simpler setup and the result remains the same... The DNS requests are always served...
by Zacharias
Tue Apr 28, 2020 2:55 am
Forum: Beginner Basics
Topic: Basic VLAN Setup
Replies: 22
Views: 3209

Re: Basic VLAN Setup

Trying to understand a little more i took a look again at the wiki... https://wiki.mikrotik.com/wiki/Manual:CRS1xx/2xx_series_switches_examples So, it says that when we give access to the CPU e.g from eth2 for management purposes or whatever other reason we would do it like: /interface ethernet swit...
by Zacharias
Tue Apr 28, 2020 1:57 am
Forum: General
Topic: Failover not working [SOLVED]
Replies: 19
Views: 3096

Re: Failover not working [SOLVED]

No @sindy it does not work as it should, i doubled checked... So if you don't mind taking a look in case i dont see something obvious... 0 S dst-address=0.0.0.0/0 gateway=10.10.10.1 gateway-status=10.10.10.1 unreachable distance=1 scope=30 target-scope=10 1 A S dst-address=0.0.0.0/0 gateway=10.10.11...
by Zacharias
Tue Apr 28, 2020 12:05 am
Forum: Beginner Basics
Topic: Configuring the Firewall in RouterOS [SOLVED]
Replies: 38
Views: 5068

Re: Configuring the Firewall in RouterOS [SOLVED]

Mikrotik default firewall uses Lists, to make things easier... Also it is a good practice the use of Lists because the less firewall rules the better performance we have and it is easier to "read" as well... So, list LAN consists of your Local Networks, your Bridge or Bridges in simple words... The ...
by Zacharias
Mon Apr 27, 2020 11:51 pm
Forum: General
Topic: Failover not working [SOLVED]
Replies: 19
Views: 3096

Re: Failover not working [SOLVED]

@sindy yes that is what i meant... However, since i had never tested that the DNS would indeed not work i thought giving it a try on GNS3... So i created a recursive failover with 8.8.8.8 for the first line and 8.8.4.4 for the second one... When the 1st line was off and the 8.8.8.8 was listed as unr...
by Zacharias
Mon Apr 27, 2020 8:46 pm
Forum: Beginner Basics
Topic: Configuring the Firewall in RouterOS [SOLVED]
Replies: 38
Views: 5068

Re: Configuring the Firewall in RouterOS [SOLVED]

IM posts are temporarily ON,,,,,, just click on the users name on the left hand margin to send message
Why are they ON? And why temporarily?
by Zacharias
Mon Apr 27, 2020 8:33 pm
Forum: Beginner Basics
Topic: Configuring the Firewall in RouterOS [SOLVED]
Replies: 38
Views: 5068

Re: Configuring the Firewall in RouterOS [SOLVED]

If that's the case then configure your CRS as a Router-Switch... That means, all the important facilities must be running on the CRS, DHCP, DNS, Firewall, Routing etc... Ofcrorse the above is not important... You can enable IP Firewall in the Bridge Settings and Filter the Traffic passing through th...
by Zacharias
Mon Apr 27, 2020 8:22 pm
Forum: Beginner Basics
Topic: Configuring the Firewall in RouterOS [SOLVED]
Replies: 38
Views: 5068

Re: Configuring the Firewall in RouterOS [SOLVED]

But as said earlier, if you use it as a switch you do not need any Firewall...

Fastrack handler helps packets bypass some procedures that would otherwise slowdown the Routing Process...
https://wiki.mikrotik.com/wiki/Manual:IP/Fasttrack
by Zacharias
Mon Apr 27, 2020 8:16 pm
Forum: General
Topic: making sure the main router manage all connection?
Replies: 25
Views: 3503

Re: making sure the main router manage all connection?

@sindy i was thinking of VLAN Filtering on the Main Router...
But now that you said that, the example here https://wiki.mikrotik.com/wiki/Manual:C ... rding_Mode suits perfectly in the situation...
by Zacharias
Mon Apr 27, 2020 7:53 pm
Forum: General
Topic: Failover not working [SOLVED]
Replies: 19
Views: 3096

Re: Failover not working [SOLVED]

I think it should be mentioned, in case your recursive failover uses some known DNS Servers like 8.8.8.8 then if that DNS is used by your Router as well it won't work...
So make sure you use DNS Servers on your Router more than the ones that are used on your recursive failover as well...
by Zacharias
Mon Apr 27, 2020 7:22 pm
Forum: General
Topic: L2TP FastPath not working.
Replies: 9
Views: 1583

Re: L2TP FastPath not working.

if you play with ipsec you can't use FP That is correct... . IPv4 fast path is automatically used if following conditions are met: . . IpSec policies are not configured (ROS v6.8 ) . . https://wiki.mikrotik.com/wiki/Manual:Fast_Path But you don't mention that you use IPsec, so that might not be you...
by Zacharias
Mon Apr 27, 2020 7:20 pm
Forum: Beginner Basics
Topic: Basic VLAN Setup
Replies: 22
Views: 3209

Re: Basic VLAN Setup

As others mentioned, switch shouldn't be doing that.
Nice to clarify that @mkx...
My logic was saying that this could not be causing a problem but i also had my doubts...
by Zacharias
Mon Apr 27, 2020 7:17 pm
Forum: Beginner Basics
Topic: Configuring the Firewall in RouterOS [SOLVED]
Replies: 38
Views: 5068

Re: Configuring the Firewall in RouterOS [SOLVED]

Exactly... All the CRS Series models are Router-Switches, you might use it as a Switch only or a Router or both... It is up to you... So in case you choose to use it as a Routing Device you must setup a Firewall... Here you can see the performance results of the Device either for Switching or Routin...
by Zacharias
Mon Apr 27, 2020 7:09 pm
Forum: General
Topic: making sure the main router manage all connection?
Replies: 25
Views: 3503

Re: making sure the main router manage all connection?

What would you suggest here @mkx, Bridge VLAN filtering thus losing the HW Offload or SW Filtering ?
by Zacharias
Mon Apr 27, 2020 6:59 pm
Forum: Beginner Basics
Topic: Configuring the Firewall in RouterOS [SOLVED]
Replies: 38
Views: 5068

Re: Configuring the Firewall in RouterOS [SOLVED]

This is the Default Firewall a Mikrotik Router has configured... Your CRS does not have it because it is intended to be used as a switch, that is the reason... I just informed you of the Mikrotik's suggested firewall.. which ofcorse you can make it more strict... The Link that @mozerd posted has the...
by Zacharias
Mon Apr 27, 2020 6:56 pm
Forum: Beginner Basics
Topic: Can't ping between subnets
Replies: 11
Views: 1581

Re: Can't ping between subnets

The point is your guessing again Zach. @anav i really try not to guess... :lol: However i just mentioned some basics that could lead to such a problem, nothing more nothing less... Since no extra configuration is needed for 2 or more Subnets to communicate through the same Routing device when they ...
by Zacharias
Mon Apr 27, 2020 6:48 pm
Forum: Wireless Networking
Topic: capsman 2.4Ghz 40Mhz Turbo hAP lite?
Replies: 11
Views: 1834

Re: capsman 2.4Ghz 40Mhz Turbo hAP lite?

@mkx on your first post i see no explanation as to why use of 40Mhz Channel width is good or not... You just gave the configuration and thats it... At least i explained why i do think 40Mhz is not a good Choice for this Band, and ofcorse the OP can follow my suggestion or not... Also you missed the ...
by Zacharias
Mon Apr 27, 2020 4:12 am
Forum: Beginner Basics
Topic: Configuring the Firewall in RouterOS [SOLVED]
Replies: 38
Views: 5068

Re: Configuring the Firewall in RouterOS [SOLVED]

This is the default Firewall Filter: /ip firewall filter add action=accept chain=input comment=\ "defconf: accept established,related,untracked" connection-state=\ established,related,untracked add action=drop chain=input comment="defconf: drop invalid" connection-state=\ invalid add action=accept c...
by Zacharias
Mon Apr 27, 2020 3:50 am
Forum: General
Topic: L2TP FastPath not working.
Replies: 9
Views: 1583

Re: L2TP FastPath not working.

Is Allow Fast Path enabled on the Client and Server ?
by Zacharias
Mon Apr 27, 2020 3:22 am
Forum: General
Topic: MikroTik L2TP/IPSec client
Replies: 12
Views: 2140

Re: MikroTik L2TP/IPSec client

Go to PPP Profiles, double click the Profile used on your L2TP Client and you will find those attributes on the 1st and 2nd Tab...
Also, you could just try and remove the IPsecret from the L2TP Client and try without it... The server might be configured to allow the connection even without IPsec...
by Zacharias
Mon Apr 27, 2020 1:58 am
Forum: Beginner Basics
Topic: Can't ping between subnets
Replies: 11
Views: 1581

Re: Can't ping between subnets

Unless you block them with your Firewall Filter, you should be able to reach each subnet from your hosts...
Or you have not properly configured Mangles / Policy Route Rules...
by Zacharias
Mon Apr 27, 2020 1:52 am
Forum: General
Topic: making sure the main router manage all connection?
Replies: 25
Views: 3503

Re: making sure the main router manage all connection?

Yes, that would be an option too...
CapsMan to Forwarding Mode so that he makes use of the Bridge Filtering on the HAP...
However the Best certainly not...

A proper segmentation of the Network would consist of VLAN configuration and proper Firewall configured...
by Zacharias
Mon Apr 27, 2020 1:49 am
Forum: Wireless Networking
Topic: capsman 2.4Ghz 40Mhz Turbo hAP lite?
Replies: 11
Views: 1834

Re: capsman 2.4Ghz 40Mhz Turbo hAP lite?

and that enables the auto 20/40 mode.
Correct...
by Zacharias
Mon Apr 27, 2020 1:21 am
Forum: General
Topic: MikroTik L2TP/IPSec client
Replies: 12
Views: 2140

Re: MikroTik L2TP/IPSec client

Your Firewall is fine...
When you try to connect to the Server, make sure there is no other L2TP Client active on your Network...
Also, check the profile for your L2TP Client, make sure Change TCP mss is set to yes. Also try without encryption in case it is enabled...
by Zacharias
Mon Apr 27, 2020 1:17 am
Forum: Beginner Basics
Topic: 2 WANs possible with CRS326-24G-2S+ with RouterOS ? [SOLVED]
Replies: 8
Views: 1719

Re: 2 WANs possible with CRS326-24G-2S+ with RouterOS ? [SOLVED]

Yes, Multi-layer-switches can route at wire speed - MLS ....
A multi Layer switch is just a Switch with Layer 3 capabilities...
And am sure their traffic passes the CPU before reaching the Switch...
by Zacharias
Mon Apr 27, 2020 1:13 am
Forum: Beginner Basics
Topic: Basic VLAN Setup
Replies: 22
Views: 3209

Re: Basic VLAN Setup

I removed switch1-cpu from switch vlan and everything is working as expected.
I am not sure why this was the problem, switch1-cpu just gives access to CPU, needed or not i don't see why it caused a problem...
by Zacharias
Mon Apr 27, 2020 1:08 am
Forum: General
Topic: MikroTik L2TP/IPSec client
Replies: 12
Views: 2140

Re: MikroTik L2TP/IPSec client

Please export your firelwall settings with hide-sensitive...
by Zacharias
Mon Apr 27, 2020 1:03 am
Forum: General
Topic: making sure the main router manage all connection?
Replies: 25
Views: 3503

Re: making sure the main router manage all connection?

i'm able to use the ip firewall to block since i removed the hardware offloading (i have tested it) Then you have enabled the Bridge Firewall under Bridge Settings... Again, the Firewall does not capture Layer 2 traffic.... The only way to achieve that is to enable the Bridge Firewall and force tha...
by Zacharias
Mon Apr 27, 2020 12:45 am
Forum: General
Topic: MikroTik L2TP/IPSec client
Replies: 12
Views: 2140

Re: MikroTik L2TP/IPSec client

Your computer is not handled by the Input chain...
by Zacharias
Mon Apr 27, 2020 12:25 am
Forum: General
Topic: MikroTik L2TP/IPSec client
Replies: 12
Views: 2140

Re: MikroTik L2TP/IPSec client

On the server or client side? A non properly configured firewall could be a reason for that... On the Client, since you ve tested with another device and the server works... If for example on your firewall you have any strange rules on top blocking in the Input chain ports essential for the L2TP/IP...
by Zacharias
Mon Apr 27, 2020 12:15 am
Forum: General
Topic: MikroTik L2TP/IPSec client
Replies: 12
Views: 2140

Re: MikroTik L2TP/IPSec client

A non properly configured firewall could be a reason for that...
by Zacharias
Mon Apr 27, 2020 12:05 am
Forum: Beginner Basics
Topic: Basic VLAN Setup
Replies: 22
Views: 3209

Re: Basic VLAN Setup

Check my #2 post and use the sa-learning and learn values...
by Zacharias
Mon Apr 27, 2020 12:00 am
Forum: General
Topic: making sure the main router manage all connection?
Replies: 25
Views: 3503

Re: making sure the main router manage all connection?

So, you re telling that up to now you were using a Dynamic Address List to block Wireless clients accessing Local Resources (Layer 2 Traffic )using the Firewall... And now you want to extend that on CAP... You know that this is possible only by using Bridge Firewall right ? Otherwise you blocked not...
by Zacharias
Sun Apr 26, 2020 11:44 pm
Forum: General
Topic: making sure the main router manage all connection?
Replies: 25
Views: 3503

Re: making sure the main router manage all connection?

Blocking other based on dynamic address list
Blocking others from doing what ?
Accessing the Internet ? Some local hosts ?
by Zacharias
Sun Apr 26, 2020 11:31 pm
Forum: General
Topic: making sure the main router manage all connection?
Replies: 25
Views: 3503

Re: making sure the main router manage all connection?

i want all traffic to go through the hAP The traffic anyways will go through the HAP when it must go through the HAP... HAP is your Router, when traffic needs to be routed will go through it... Other than that, HAP can handle Layer 2 traffic and CAP can do it as well... For example, when 2 wireless...
by Zacharias
Sun Apr 26, 2020 11:17 pm
Forum: General
Topic: Router is suddenly dropping connections.
Replies: 10
Views: 1950

Re: Router is suddenly dropping connections.

I also faced this issue. Maybe last messages of the following post can help you.
There are hundreds of reasons why a port could go Down/Up or a Router Reboots...
by Zacharias
Sun Apr 26, 2020 11:11 pm
Forum: Wireless Networking
Topic: capsman 2.4Ghz 40Mhz Turbo hAP lite?
Replies: 11
Views: 1834

Re: capsman 2.4Ghz 40Mhz Turbo hAP lite?

@mkx personally i will never use 40Mhz channel width to any CapsMan setup in the 2.4Ghz Band...
by Zacharias
Sun Apr 26, 2020 10:55 pm
Forum: General
Topic: making sure the main router manage all connection?
Replies: 25
Views: 3503

Re: making sure the main router manage all connection?

I have removed hardware offload on both I don't see the reason to do that... You miss one important thing, the devices within the same Broadcast Domain are communicating to each other in the Layer 2, using MAC addresses. Layer 2 Traffic, does not pass through the Firewall. Layer 3 Traffic on the ot...
by Zacharias
Sun Apr 26, 2020 10:42 pm
Forum: Beginner Basics
Topic: 2 WANs possible with CRS326-24G-2S+ with RouterOS ? [SOLVED]
Replies: 8
Views: 1719

Re: 2 WANs possible with CRS326-24G-2S+ with RouterOS ? [SOLVED]

If you want to route at wire speed on the switch YOU will need to look at other brands.
Route at wire speed on the Switch ? :?
What is that supposed to mean? A switch is a switch, it does not route Traffic...
The CPU takes part in the Routing Process...
by Zacharias
Sun Apr 26, 2020 9:53 pm
Forum: Wireless Networking
Topic: capsman 2.4Ghz 40Mhz Turbo hAP lite?
Replies: 11
Views: 1834

Re: capsman 2.4Ghz 40Mhz Turbo hAP lite?

To @syadnom's question: it works if set like this: Code: Select all /caps-man channel add band=2ghz-g/n control-channel-width=20mhz extension-channel=XX <the rest of settings> Nothing guarantees that the client will connect using 40Mhz channel width... but nice try @mkx... It can be either 20Mhz or...
by Zacharias
Sun Apr 26, 2020 7:58 pm
Forum: Wireless Networking
Topic: capsman 2.4Ghz 40Mhz Turbo hAP lite?
Replies: 11
Views: 1834

Re: capsman 2.4Ghz 40Mhz Turbo hAP lite?

Why would you use 40Mhz Channel on the over crowded 2.4Ghz Band that has only 3 non-overlapping channels? No way... :D Besides that, i do not think that there is ANY client on the 2.4Ghz band that supports a 40Mhz Channel width... And, if i remember right, it is not even supported... So, you will se...
by Zacharias
Sun Apr 26, 2020 7:15 pm
Forum: General
Topic: Need advice on firewall rules
Replies: 10
Views: 1651

Re: Need advice on firewall rules

I agee as well...
Best source for studying is always the wiki and not random tutorials around...
by Zacharias
Sun Apr 26, 2020 7:05 pm
Forum: RouterBOARD hardware
Topic: CRS354 not full gigabit on ethernet ports [SOLVED]
Replies: 11
Views: 3247

Re: CRS354 not full gigabit on ethernet ports [SOLVED]

You should mark as solved the actual post that shows the solution, so others can eaily find it without reading all the posts...
by Zacharias
Sun Apr 26, 2020 6:48 pm
Forum: Beginner Basics
Topic: 2 WANs possible with CRS326-24G-2S+ with RouterOS ? [SOLVED]
Replies: 8
Views: 1719

Re: 2 WANs possible with CRS326-24G-2S+ with RouterOS ? [SOLVED]

All Mikrotiks run the same Software, either swOS or RouterOS... swOS can be used on Devices that will do Switching, and thats it...! For routing purposes you use RouterOS... If you want the device to load balance multiple WAN interfaces you must notice that CRS Series are Router-Switches that have l...
by Zacharias
Sun Apr 26, 2020 6:41 pm
Forum: General
Topic: Queue at-rate not honoured
Replies: 5
Views: 1231

Re: Queue at-rate not honoured

One obvious cause may be that we do not get the 1 Gbps from our provider
Well, exactly, if you are not sure of the Bandwidth the ISP gave you at the moment you can't blame the queues...
by Zacharias
Sun Apr 26, 2020 6:37 pm
Forum: SwOS
Topic: RB260GS limitations
Replies: 9
Views: 2168

Re: RB260GS limitations

Sounds ok...
by Zacharias
Sun Apr 26, 2020 5:36 pm
Forum: General
Topic: LACP Active/Passive on RouterOS
Replies: 3
Views: 1230

Re: LACP Active/Passive on RouterOS

Ok i ll check again later in the day :)
Edit: Can't see any LACP Frames neither with Packet Sniffer not With Wireshark, so to me it does not work on CHR's...
by Zacharias
Sun Apr 26, 2020 5:32 pm
Forum: General
Topic: Router is suddenly dropping connections.
Replies: 10
Views: 1950

Re: Router is suddenly dropping connections.

Is your power supply good ? Did you test with another one ?
How often are the Reboots?
by Zacharias
Sun Apr 26, 2020 3:42 am
Forum: General
Topic: Router is suddenly dropping connections.
Replies: 10
Views: 1950

Re: Router is suddenly dropping connections.

Check Log, CPU, Temperatures, any recent changes etc...
by Zacharias
Sun Apr 26, 2020 3:20 am
Forum: General
Topic: LACP Active/Passive on RouterOS
Replies: 3
Views: 1230

Re: LACP Active/Passive on RouterOS

The default seems to be Active...
With a quick capture using Wireshark and GNS3 the 802.3ad Bonding sends LLDP Frames without any 802.3ad Bond on the other Side...
by Zacharias
Sun Apr 26, 2020 3:11 am
Forum: Beginner Basics
Topic: Dual WAN Mangle routing
Replies: 1
Views: 969

Re: Dual WAN Mangle routing

There are 2 ways... First in your Routing Table you mark your 2 WAN connections... e.g. /ip route add distance=1 gateway=192.168.1.1 routing-mark=ISP1 add distance=1 gateway=192.168.75.2 routing-mark=ISP2 Then if i want a host with address 192.168.20.254 to use ISP1 and host with address 192.168.20....
by Zacharias
Sun Apr 26, 2020 2:27 am
Forum: General
Topic: Can't Access Several Website
Replies: 5
Views: 1156

Re: Can't Access Several Website

- change MTU to 1492 both in PPOE connection and in Bridge
The Bridge MTU must be set to 1500Byte...
by Zacharias
Sun Apr 26, 2020 2:23 am
Forum: General
Topic: Simple routing..not so simple for me
Replies: 2
Views: 1049

Re: Simple routing..not so simple for me

I think it will be easier to understand if you make a network diagram...
by Zacharias
Sun Apr 26, 2020 1:58 am
Forum: General
Topic: Router is suddenly dropping connections.
Replies: 10
Views: 1950

Re: Router is suddenly dropping connections.

RouterOS version and model ?
Is Watchdog to default settings ? if yes then a reboot means that the Router was unresponsive for 1 minute...
by Zacharias
Sun Apr 26, 2020 1:51 am
Forum: Beginner Basics
Topic: Lease Expiry Causing DHCP Critical Error [SOLVED]
Replies: 23
Views: 3344

Re: Lease Expiry Causing DHCP Critical Error [SOLVED]

@anav you never provided details of the debug log...
Also if there is no access to the modem from anyone, you don't need an engineer, you need a better modem/Router...
by Zacharias
Sun Apr 26, 2020 1:48 am
Forum: Beginner Basics
Topic: Basic VLAN Setup
Replies: 22
Views: 3209

Re: Basic VLAN Setup

Please make a simple network diagram it will help...
by Zacharias
Sat Apr 25, 2020 11:33 pm
Forum: General
Topic: Queue at-rate not honoured
Replies: 5
Views: 1231

Re: Queue at-rate not honoured

But you have allowed a max limit of 660Mbps... The graph shows something less than 600Mbps...
No limit is exceeded...

During these periods the other groups have less than 330 Mbps.
Did they actually needed more Bandwidth and they could not have it ?
by Zacharias
Sat Apr 25, 2020 11:21 pm
Forum: Wireless Networking
Topic: CAPSMAN issue with v6.46.5
Replies: 6
Views: 1440

Re: CAPSMAN issue with v6.46.5

The problem I see is why I CAPS master is unable to get an IP from the DCHP
Those problems are caused when there is no communication with the CPU, thats why we add the Bridge as Tagged member...
by Zacharias
Sat Apr 25, 2020 11:17 pm
Forum: Beginner Basics
Topic: Lease Expiry Causing DHCP Critical Error [SOLVED]
Replies: 23
Views: 3344

Re: Lease Expiry Causing DHCP Critical Error [SOLVED]

I have no access to the ISP modem, and neither does their useless tech support.
Not you, not them, so who has access ? :lol:
by Zacharias
Sat Apr 25, 2020 9:09 pm
Forum: Beginner Basics
Topic: Lease Expiry Causing DHCP Critical Error [SOLVED]
Replies: 23
Views: 3344

Re: Lease Expiry Causing DHCP Critical Error [SOLVED]

So why magically does it get a new IP, which is really the old IP in the end..................... (after lease expirY) When the Lease Expires the Client just requests an IP address from the server... There is No Renewing, No Rebinding, no extention of the Lease, nothing... So to me your Server Fail...
by Zacharias
Sat Apr 25, 2020 8:46 pm
Forum: Wireless Networking
Topic: CAPSMAN issue with v6.46.5
Replies: 6
Views: 1440

Re: CAPSMAN issue with v6.46.5

/interface bridge vlan
add bridge=bridge-oam tagged=bridge-oam untagged=KKHOME_VLAN_100 vlan-ids=100
Why isn't your trunk post added in the tagged ports? bridge-oam,yourTrunkPort
by Zacharias
Sat Apr 25, 2020 7:19 pm
Forum: Beginner Basics
Topic: Lease Expiry Causing DHCP Critical Error [SOLVED]
Replies: 23
Views: 3344

Re: Lease Expiry Causing DHCP Critical Error [SOLVED]

Okay two logging rule added (topic --> prefix) DHCP -->debug Debug --> debug No, it is 1 Rule with 2 topics selected, debug && DHCP So are you saying the problem is at the ISP end or on the router? Since the DHCP Client goes through T1 and T2 Timers, Rewnew and Rebind, with no success it is obvious...
by Zacharias
Sat Apr 25, 2020 7:11 pm
Forum: RouterBOARD hardware
Topic: SOLVED : RB4011iGS+RM : Unable to get more than 250Mbps Internet connection
Replies: 34
Views: 5322

Re: RB4011iGS+RM : Unable to get more than 250Mbps Internet connection

Well, I do not consider the double-nating from the modem/router. It depends on which mode it has been setup. Ok let us know then what is the mode it has been setup... So what you are telling me is that your RB4011 holds a Static or Dynamic Public IP right ? Since you say there is no NAT happening i...
by Zacharias
Sat Apr 25, 2020 6:11 pm
Forum: Beginner Basics
Topic: Basic VLAN Setup
Replies: 22
Views: 3209

Re: Basic VLAN Setup

I have not tested, but i would try something like: /interface bridge add name=bridge1 /interface bridge port add bridge=bridge1 interface=ether2 hw=yes add bridge=bridge1 interface=ether3 hw=yes add bridge=bridge1 interface=ether4 hw=yes add bridge=bridge1 interface=ether5 hw=yes /interface ethernet...
by Zacharias
Sat Apr 25, 2020 5:37 pm
Forum: Beginner Basics
Topic: Lease Expiry Causing DHCP Critical Error [SOLVED]
Replies: 23
Views: 3344

Re: Lease Expiry Causing DHCP Critical Error [SOLVED]

A DHCP Client at the 50% of the lease Time will try to Renew the Address it already has, this is the Renewal Timer... When the Renewal Timer is Reached then the DHCP Client is at the Renewing state until the address is renewed or untli the 87.5% of the Renewal Time is Reached and then the Client goe...
by Zacharias
Sat Apr 25, 2020 5:16 pm
Forum: RouterBOARD hardware
Topic: SOLVED : RB4011iGS+RM : Unable to get more than 250Mbps Internet connection
Replies: 34
Views: 5322

Re: RB4011iGS+RM : Unable to get more than 250Mbps Internet connection

I don’t see this condition in my setup.
Then sorry but you don't know what double NAT is...
Yes there is double NAT in your setup...

Internet -> ISPs Router does NAT -> RB4011 Does NAT -> Computer
Cable modem is a Technicolor TC4400-AM
This is a Modem/Router....
by Zacharias
Sat Apr 25, 2020 1:06 pm
Forum: General
Topic: ppp-out default route disappears 1 second after interface is enabled
Replies: 31
Views: 4182

Re: ppp-out default route disappears 1 second after interface is enabled

No scripting is needed...
Just a recursive failover...
by Zacharias
Sat Apr 25, 2020 3:57 am
Forum: Wireless Networking
Topic: CAPSMAN issue with v6.46.5
Replies: 6
Views: 1440

Re: CAPSMAN issue with v6.46.5

Export with hide-sensitive the configuration of the Capsman Router and post it inside code tags...
by Zacharias
Sat Apr 25, 2020 3:53 am
Forum: General
Topic: Failover - Missing Wiki Article
Replies: 2
Views: 1203

Re: Failover - Missing Wiki Article

Yes that Article is missing a long time now...
You will find a MUM Presentation for Recursive failover using Virtual Hosts...
https://mum.mikrotik.com/presentations/ ... 743837.pdf
by Zacharias
Sat Apr 25, 2020 3:51 am
Forum: General
Topic: EoIP tunnel not forwarding traffic [SOLVED]
Replies: 4
Views: 1370

Re: EoIP tunnel not forwarding traffic [SOLVED]

Why did you select EoIP in particular ? By creating an Encrypted with IPsec EoIP Tunnel, and that's it, will not give you access to the Hosts behind those Tunnels... You must add routes from R1 to R2 LAN and from R2 to R1 LAN with gateway the EoIP... What concerns me most is that EoIP is mostly used...
by Zacharias
Sat Apr 25, 2020 3:10 am
Forum: RouterBOARD hardware
Topic: SOLVED : RB4011iGS+RM : Unable to get more than 250Mbps Internet connection
Replies: 34
Views: 5322

Re: RB4011iGS+RM : Unable to get more than 250Mbps Internet connection

Using WinBox make a Supout.rif package and copy it off to your computer. Go to System/Reset Configuration and select "No Default Configuration". Click on "Reset Configuration". After Router reboots, go to System/Reset Configuration and don't select any options then click on "Reset Configuration". A...
by Zacharias
Sat Apr 25, 2020 3:07 am
Forum: Beginner Basics
Topic: How to unreserve and MAC address on an IP?
Replies: 5
Views: 1291

Re: How to unreserve and MAC address on an IP?

The desktop won’t ask for a new IP till the lease expires That is wrong... The host will renew the IP at 50% of the lease time, that is the Renewal Timer and the Timer will be reset upon a succesfull renewal... We also have the Rebinding Timer, which comes in play in case there is no successfull re...
by Zacharias
Sat Apr 25, 2020 2:12 am
Forum: Beginner Basics
Topic: How to unreserve and MAC address on an IP?
Replies: 5
Views: 1291

Re: How to unreserve and MAC address on an IP?

When the Lease expires the IP (not the MAC) will be free to be offered to another machine again...
Supposing the host is not active, otherwise will be renewed...
by Zacharias
Sat Apr 25, 2020 2:05 am
Forum: General
Topic: ipsec ikev2 vpn doesn't do his work [SOLVED]
Replies: 6
Views: 1908

Re: ipsec ikev2 vpn doesn't do his work [SOLVED]

To add to what @sindy said, as i think it is important to remind what features are specifically affected when we disable connection tracking... Those are: NAT firewall: connection-bytes connection-mark connection-type connection-state connection-limit connection-rate layer7-protocol new-connection-m...
by Zacharias
Sat Apr 25, 2020 12:54 am
Forum: Beginner Basics
Topic: CPE
Replies: 2
Views: 860

Re: CPE

by Zacharias
Sat Apr 25, 2020 12:44 am
Forum: General
Topic: VLan not working after update router
Replies: 9
Views: 1882

Re: VLan not working after update router

Did you test my suggestion above or perhaps you wait for someone to give you a ready configuration ? :D
by Zacharias
Fri Apr 24, 2020 9:40 pm
Forum: General
Topic: dstnat and traceroute
Replies: 4
Views: 1149

Re: dstnat and traceroute

So, do you believe my NAT rule will otherwise have the intended effects?
If you wonder if the rule is working, yes...
by Zacharias
Fri Apr 24, 2020 9:35 pm
Forum: General
Topic: VLan not working after update router
Replies: 9
Views: 1882

Re: VLan not working after update router

when i set the vlan interface to bridge than i have no internet. Interface Bridge VLAN is used for Bridge VLAN filtering... Not for Switch VLAN FIltering, like in your case... So that entry is not needed.... But i want the vlan on all the ports of the mikrotik so i set the vlan interface to brdige ...
by Zacharias
Fri Apr 24, 2020 9:30 pm
Forum: General
Topic: SIP Through IPSEC VPN Site to Site drops calls randomly
Replies: 30
Views: 4684

Re: SIP Through IPSEC VPN Site to Site drops calls randomly

@spr41178 before changing the PBX you can as well try a different Tunnel just for Testing and see how it goes e.g. an SSTP tunnel...
What is the software you used in the screenshot ?
by Zacharias
Fri Apr 24, 2020 9:19 pm
Forum: General
Topic: VLan not working after update router
Replies: 9
Views: 1882

Re: VLan not working after update router

Although i am used to Bridge VLAN Filtering with CRS3xx series switches... I ll give it a try... First you do not need this line of code: /interface bridge vlan add bridge=bridge vlan-ids=3 Also, here: add independent-learning=yes ports=ether2 switch=switch1 vlan-id=3 You do not give access to CPU, ...
by Zacharias
Fri Apr 24, 2020 8:48 pm
Forum: Useful user articles
Topic: Advanced Routing Failover without Scripting
Replies: 21
Views: 6169

Re: Advanced Routing Failover without Scripting

recursive routes are not recalculated (or something) and all traffic still goes via another uplink
About 2 months ago that i made a lab for recursive routes and failover, as far as i remember the recursive routes were recalculated... version was 6.4x.y something...
by Zacharias
Fri Apr 24, 2020 8:37 pm
Forum: General
Topic: VLan not working after update router
Replies: 9
Views: 1882

Re: VLan not working after update router

Also what was the previous version?
by Zacharias
Fri Apr 24, 2020 8:25 pm
Forum: RouterBOARD hardware
Topic: SOLVED : RB4011iGS+RM : Unable to get more than 250Mbps Internet connection
Replies: 34
Views: 5322

Re: RB4011iGS+RM : Unable to get more than 250Mbps Internet connection

On my first post I said it was running the default config. I asked so that i be sure you have not run Quickset 10 times above the default config or made any changes... 4011 is a powerful router and can Route traffic a lot higher than the one you report... Most probably something else causes this is...
by Zacharias
Fri Apr 24, 2020 8:08 pm
Forum: General
Topic: dstnat and traceroute
Replies: 4
Views: 1149

Re: dstnat and traceroute

This happens exactly because of your NAT rule...
Traceroute will not detect any NAT...
by Zacharias
Fri Apr 24, 2020 6:59 pm
Forum: RouterBOARD hardware
Topic: SOLVED : RB4011iGS+RM : Unable to get more than 250Mbps Internet connection
Replies: 34
Views: 5322

Re: RB4011iGS+RM : Unable to get more than 250Mbps Internet connection

Is the 4011 running the latest ROS 6.46.5 ?
Is the configuration the default one or not ?
by Zacharias
Fri Apr 24, 2020 6:01 pm
Forum: RouterBOARD hardware
Topic: SOLVED : RB4011iGS+RM : Unable to get more than 250Mbps Internet connection
Replies: 34
Views: 5322

Re: RB4011iGS+RM : Unable to get more than 250Mbps Internet connection

Can you authenticate with your ISP with PPPoE ? If yes give it a try...
by Zacharias
Fri Apr 24, 2020 4:14 pm
Forum: Beginner Basics
Topic: Correct way of creating a network with my 3 mikrotik hap ac2
Replies: 12
Views: 1969

Re: Correct way of creating a network with my 3 mikrotik hap ac2

Yes...But...
If you set your ISPs modem in Bridge Mode, meaning it does no routing functions anymore, then somehow the Mikrotik must communicate with your providers netowork, that might be a PPPoE connection, a static IP etc... But i do not know what options your ISP will give you...
by Zacharias
Fri Apr 24, 2020 2:18 pm
Forum: RouterBOARD hardware
Topic: hAP ac3 spotted at FCC
Replies: 23
Views: 6413

Re: hAP ac3 spotted at FCC

But the product is listed as Available in that shop...
by Zacharias
Fri Apr 24, 2020 2:16 pm
Forum: General
Topic: Bonding 2 Wireless device to give more bandwidth
Replies: 46
Views: 5622

Re: Bonding 2 Wireless device to give more bandwidth

Mikrotik are supposed to be bringing out a Netpower 16P
You can already find and purchase this product...
by Zacharias
Thu Apr 23, 2020 10:33 pm
Forum: General
Topic: HEX S Bridge VLAN setup - poor performance vlan to vlan (max. ~ 200 MBit/s)
Replies: 10
Views: 2228

Re: HEX S Bridge VLAN setup - poor performance vlan to vlan (max. ~ 200 MBit/s)

HEX S has a max speed of about 385.4 Mbps for 25 IP firewall Rules...
If we add InterVLAN, mangles etc then i can tell this router's performance is expected...
by Zacharias
Thu Apr 23, 2020 10:29 pm
Forum: Beginner Basics
Topic: Hacker attacks on CCR [SOLVED]
Replies: 9
Views: 2434

Re: Hacker attacks on CCR [SOLVED]

Can you be more specific ?
Under what type of attack are you?
by Zacharias
Thu Apr 23, 2020 10:27 pm
Forum: RouterBOARD hardware
Topic: hAP ac3 spotted at FCC
Replies: 23
Views: 6413

Re: hAP ac3 spotted at FCC

and not a single word on routerboard.com.
Indeed, why is that ?
by Zacharias
Thu Apr 23, 2020 9:20 pm
Forum: Wireless Networking
Topic: WDS seciurity not working
Replies: 12
Views: 2244

Re: WDS seciurity not working

From a quick look at your configurations... First, since you use Dynamic Mesh, why are you adding manually the WDS interfaces? They will be added automatically, do not add them manually... Also, remove from the Bridge the WDS interfaces you manually added... They will be added to the Bridge automati...
by Zacharias
Thu Apr 23, 2020 8:44 pm
Forum: General
Topic: CRS317 not functioning with Avago SFP
Replies: 4
Views: 1321

Re: CRS317 not functioning with Avago SFP

Better use SPF modules listed in the Compatibility List...
It can be a Mikrotik SFP Module on one side and another Vendor's on the other, in case you want to choose a compatible one for the Mikrotik and a compatible onoe e.g. for your server... (with same characteristics...)
by Zacharias
Thu Apr 23, 2020 8:39 pm
Forum: Wireless Networking
Topic: WDS seciurity not working
Replies: 12
Views: 2244

Re: WDS seciurity not working

You can export with hide-sensitive the configuration of 2 APs you perform MESH with...
Post the configurations inside tags...
by Zacharias
Thu Apr 23, 2020 8:35 pm
Forum: General
Topic: Bonding 2 Wireless device to give more bandwidth
Replies: 46
Views: 5622

Re: Bonding 2 Wireless device to give more bandwidth

Ok, nice to know that...
by Zacharias
Thu Apr 23, 2020 8:33 pm
Forum: General
Topic: ether2 excessive broadcasts/multicasts, probably a loop
Replies: 2
Views: 1022

Re: ether2 excessive broadcasts/multicasts, probably a loop

Or some RSTP related issue...
by Zacharias
Thu Apr 23, 2020 8:29 pm
Forum: General
Topic: Transparent L2 Passthrough [SOLVED]
Replies: 5
Views: 1533

Re: Transparent L2 Passthrough [SOLVED]

...or MPLS if you prefer.
With VPLS i guess...
by Zacharias
Thu Apr 23, 2020 8:25 pm
Forum: General
Topic: Bonding 2 Wireless device to give more bandwidth
Replies: 46
Views: 5622

Re: Bonding 2 Wireless device to give more bandwidth

Poland i guess...
this requirement is relevant for the bridges on the active network path between the two devices running LACP
Ok that makes it clear to me now...
I made a quick capture with Wireshark under GNS3 and i could see the reserved MAC address range in the LLDP packets...
by Zacharias
Thu Apr 23, 2020 8:11 pm
Forum: General
Topic: CCR1009 High CPU Load
Replies: 10
Views: 2401

Re: CCR1009 High CPU Load

Are those VLANs handled 100% by the CCR ?
Bridge VLAN Filtering enabled etc ?

If yes, well there is no Switch Chip on the CCR, everything is handled by the CPU at 100%...
So it is expected to have a high CPU load...
by Zacharias
Thu Apr 23, 2020 7:46 pm
Forum: General
Topic: Bonding 2 Wireless device to give more bandwidth
Replies: 46
Views: 5622

Re: Bonding 2 Wireless device to give more bandwidth

Ναί
:lol: Where are you from? if i may ask...

As far as i ve tested LACP works just fine with RSTP enabled on the Bridge where the bonding exists... Nor i can find any reference that RSTP must be disabled...
So, i don't really understand...
by Zacharias
Thu Apr 23, 2020 7:05 pm
Forum: General
Topic: Bonding 2 Wireless device to give more bandwidth
Replies: 46
Views: 5622

Re: Bonding 2 Wireless device to give more bandwidth

on the radios, protocol-mode on the bridge between the Ethernet port and the wireless one must be set to none
You mean disable RSTP on the Bridge ?
by Zacharias
Thu Apr 23, 2020 3:35 pm
Forum: General
Topic: Bonding 2 Wireless device to give more bandwidth
Replies: 46
Views: 5622

Re: Bonding 2 Wireless device to give more bandwidth

The solutions in the manual only work with direct cable connection not with wireless links That is actually wrong... It all depends on the Bonding Mode used... The bonding does not know if it has an Antenna connected to it or a wire, so it is up to you to perform a correct implementation of the bon...
by Zacharias
Thu Apr 23, 2020 2:12 pm
Forum: Beginner Basics
Topic: Should I go for Router OS ?
Replies: 6
Views: 1381

Re: Should I go for Router OS ?

something that MikroTik, with its RouterOS firmware, seems not to do too well.
There is no network equipment without vulnerabilities from any Vendor...
And if you make a search you will find out that Mikrotik has less vulnerabilities found from the most of the other Networks Vendors...
by Zacharias
Thu Apr 23, 2020 1:57 pm
Forum: General
Topic: Bonding 2 Wireless device to give more bandwidth
Replies: 46
Views: 5622

Re: Bonding 2 Wireless device to give more bandwidth

have not found any solutions by googling yet. The solution is where it should be, in the Manual :D ARP monitoring sends ARP queries and uses the response as an indication that the link is operational https://wiki.mikrotik.com/wiki/Manual:Interface/Bonding#ARP_Monitoring Notice though, that this mod...
by Zacharias
Thu Apr 23, 2020 4:13 am
Forum: Wireless Networking
Topic: WDS seciurity not working
Replies: 12
Views: 2244

Re: WDS seciurity not working

So I think it is some bug in firmware...
You can always do an update to the latest ROS 6.46.5 ...
by Zacharias
Thu Apr 23, 2020 3:54 am
Forum: Beginner Basics
Topic: VLAN on ISP connection
Replies: 9
Views: 2118

Re: VLAN on ISP connection

@mkx,The eth1 port as you said can be configured with VLAN VIDs 100,300 and 640 under /interface VLAN... Then we can create 1 Bridge with ports 2,3,4,5 and vlan640 (VID 640) Next we create an Interface VLAN e.g. 10 on the Bridge for the home network Set PVID 10 on ports 2,4 and 5 Configure IP addres...
by Zacharias
Thu Apr 23, 2020 12:27 am
Forum: General
Topic: Bonding 2 Wireless device to give more bandwidth
Replies: 46
Views: 5622

Re: Bonding 2 Wireless device to give more bandwidth

Not risking
If you test it in the future let us know how it goes...
by Zacharias
Thu Apr 23, 2020 12:18 am
Forum: Beginner Basics
Topic: to instal backup to another router
Replies: 12
Views: 2442

Re: to instal backup to another router

@mkx is right on that...
Or you can upgrade the old device, then take the back up and restore it to the new one...
by Zacharias
Thu Apr 23, 2020 12:16 am
Forum: SwOS
Topic: RB260GS limitations
Replies: 9
Views: 2168

Re: RB260GS limitations

by Zacharias
Wed Apr 22, 2020 8:25 pm
Forum: General
Topic: Bonding 2 Wireless device to give more bandwidth
Replies: 46
Views: 5622

Re: Bonding 2 Wireless device to give more bandwidth

Sure there is no coordination and the links obviously will not share the traffic equally. However am sure it would help to a certain point...
by Zacharias
Wed Apr 22, 2020 8:05 pm
Forum: Beginner Basics
Topic: Network separation
Replies: 3
Views: 1047

Re: Network separation

So many things to do and unless you take it step by step you will finally mess the configuration... I will just give you some hints, as for the Lans, there is not need to create 4-5 different Lans directly on the eth interfaces and then create 1-2 bridges and then i don't know what else... Your conf...
by Zacharias
Wed Apr 22, 2020 7:57 pm
Forum: Beginner Basics
Topic: Setting up /29 over /30 [SOLVED]
Replies: 7
Views: 1650

Re: Setting up /29 over /30 [SOLVED]

That is simple... Set public 1 IP to eth1 Set public 2 IP to eth2 Or just let the Public IP /30 (whole subnet block) to your eth1... But i do not prefer that way... Lets say you have 2 Lans subnets 192.168.1.0/24 and 192.168.2.0/24... On your firewall NAT you will create a src-nat rule with src-addr...
by Zacharias
Wed Apr 22, 2020 7:52 pm
Forum: General
Topic: Bonding 2 Wireless device to give more bandwidth
Replies: 46
Views: 5622

Re: Bonding 2 Wireless device to give more bandwidth

so the two directions of the sam application connection can use different links @sindy LACP 802.3ad does not split traffic accross links... All packets associated with a given “conversation” are transmitted on the same link to prevent mis-ordering http://www.ieee802.org/3/hssg/public/apr07/frazier_...
by Zacharias
Wed Apr 22, 2020 7:33 pm
Forum: Beginner Basics
Topic: Setting up /29 over /30 [SOLVED]
Replies: 7
Views: 1650

Re: Setting up /29 over /30 [SOLVED]

This looks totally fine... Lets say my ISP gives me a /30 block x.y.z.200/30 First of all in this /30 block, one address is used by your ISP , which is actually your gateway and the other one is for you. So... 1. I will assign the address x.y.z.202/30 to my eth1 interface 2. I ll create a deafult ro...
by Zacharias
Wed Apr 22, 2020 7:26 pm
Forum: Wireless Networking
Topic: How to connect Mikrotik through TP-link
Replies: 1
Views: 719

Re: How to connect Mikrotik through TP-link

This has to do with the TP-Link and not the Mikrotik, right ?
As you said, your phone can connect to the Mikrotik...
by Zacharias
Wed Apr 22, 2020 7:13 pm
Forum: Beginner Basics
Topic: Correct way of creating a network with my 3 mikrotik hap ac2
Replies: 12
Views: 1969

Re: Correct way of creating a network with my 3 mikrotik hap ac2

I must admit that i guess a lot... :?
by Zacharias
Wed Apr 22, 2020 6:39 pm
Forum: Wireless Networking
Topic: WDS seciurity not working
Replies: 12
Views: 2244

Re: WDS seciurity not working

It is about a year since i last played with WDS Mesh networks, i can assure you it works fine with non default security profile... I would make a quick test for you but unfortunatelly i do not have 2 wireless devices for testing right now... If i were you i would reset the Wireless configuration on ...
by Zacharias
Wed Apr 22, 2020 6:19 pm
Forum: Beginner Basics
Topic: Correct way of creating a network with my 3 mikrotik hap ac2
Replies: 12
Views: 1969

Re: Correct way of creating a network with my 3 mikrotik hap ac2

All we have is one modem and three APs, but hey you guys are the experts... ;-P
haha @anav we are just trying our best...
I guess the modem is actually a router-modem and the OP will let the routing there...
by Zacharias
Wed Apr 22, 2020 6:16 pm
Forum: SwOS
Topic: RB260GS limitations
Replies: 9
Views: 2168

Re: RB260GS limitations

On RB260 VLANs are working on a hardware Level (Switch VLAN filtering), so you don't have the Bridge Hardware offload feature because you do it on a switch level already...
by Zacharias
Wed Apr 22, 2020 6:14 pm
Forum: Beginner Basics
Topic: How to diagnose VLAN performance issues on RB3011
Replies: 21
Views: 3410

Re: How to diagnose VLAN performance issues on RB3011

3011 can do more that 500Mbps without fasttrack enabled, so either On or Off it would be the same as for the speed...
Also Queues (except the queue trees) do not work when fasttrack is enabled...
by Zacharias
Wed Apr 22, 2020 6:12 pm
Forum: Wireless Networking
Topic: Meaning of: disconnected, received deauth: no activity (4)
Replies: 9
Views: 2323

Re: Meaning of: disconnected, received deauth: no activity (4)

even though I am the admin there and I know that nothing would happen
:lol:
by Zacharias
Wed Apr 22, 2020 5:06 pm
Forum: General
Topic: Bonding 2 Wireless device to give more bandwidth
Replies: 46
Views: 5622

Re: Bonding 2 Wireless device to give more bandwidth

@opalit the E for the Ubiquiti means it excluded that port from the default Group ? @sindy, if i wanted to implement the exact same thing with a 24port Mikrotik switch,i would add all 24 ports in my Bridge, then i could let e.g. the 12 first ports with PVID 1 the rest 12 with PVID lets say 2 and i w...
by Zacharias
Wed Apr 22, 2020 2:10 pm
Forum: Beginner Basics
Topic: Correct way of creating a network with my 3 mikrotik hap ac2
Replies: 12
Views: 1969

Re: Correct way of creating a network with my 3 mikrotik hap ac2

Run cables...always.
That is always by far the Best...
by Zacharias
Wed Apr 22, 2020 2:08 pm
Forum: General
Topic: Bonding 2 Wireless device to give more bandwidth
Replies: 46
Views: 5622

Re: Bonding 2 Wireless device to give more bandwidth

I see...
Can you sum up the overall changes you had to do as far as the VLANs are concerned ?
by Zacharias
Wed Apr 22, 2020 1:59 pm
Forum: General
Topic: Bonding 2 Wireless device to give more bandwidth
Replies: 46
Views: 5622

Re: Bonding 2 Wireless device to give more bandwidth

I am at the moment to ill to go up to the mast to fix if I screw up.
Yes that would be bad am sure :D
by Zacharias
Wed Apr 22, 2020 1:54 pm
Forum: Beginner Basics
Topic: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]
Replies: 54
Views: 7318

Re: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]

You go to the specific post reply that helped you and click the check-mark (solved) icon...
by Zacharias
Wed Apr 22, 2020 1:52 pm
Forum: Beginner Basics
Topic: Correct way of creating a network with my 3 mikrotik hap ac2
Replies: 12
Views: 1969

Re: Correct way of creating a network with my 3 mikrotik hap ac2

I agree, if the frequency is lower it can penetrate walls and objects better... However if the 5Ghz band does not work at all because of walls or anything am sure that the result with the 2.4Ghz will be bad as well... So there would be no point of such implementation in the end... You can as well us...
by Zacharias
Wed Apr 22, 2020 1:48 pm
Forum: Wireless Networking
Topic: Meaning of: disconnected, received deauth: no activity (4)
Replies: 9
Views: 2323

Re: Meaning of: disconnected, received deauth: no activity (4)

You cant even add a usb wireless adapter ?
by Zacharias
Wed Apr 22, 2020 1:46 pm
Forum: General
Topic: 802.3ad bond running when link down
Replies: 13
Views: 2024

Re: 802.3ad bond running when link down

I do not know how other Manufacturers implement LACP, what i know is that you need 2 slaves for an LACP implementation...
And it totally makes sense, what would be the point of LACP with 1 link ? None...
by Zacharias
Wed Apr 22, 2020 1:43 pm
Forum: Beginner Basics
Topic: VLAN on ISP connection
Replies: 9
Views: 2118

Re: VLAN on ISP connection

@mkx am trying to think how we could avoid the creation of 2 Bridges but i can't find something...
I don't see where's the problem?
Just a more tidy configuration... I never said there is a problem, relax @mkx :lol:
by Zacharias
Wed Apr 22, 2020 1:40 pm
Forum: SwOS
Topic: RB260GS limitations
Replies: 9
Views: 2168

Re: RB260GS limitations

by Zacharias
Wed Apr 22, 2020 1:35 pm
Forum: General
Topic: Bonding 2 Wireless device to give more bandwidth
Replies: 46
Views: 5622

Re: Bonding 2 Wireless device to give more bandwidth

I turned off my simple QoS queue so I could get fast track back on. I thought that would help. @sindy i said LACP between Mikrotik and Ubiquiti in case the later supports it... This makes us 4 Antennas and not 2 as you said... And the antennas would not play any role in the actual LACP process exce...
by Zacharias
Wed Apr 22, 2020 1:05 pm
Forum: Wireless Networking
Topic: WDS seciurity not working
Replies: 12
Views: 2244

Re: WDS seciurity not working

To make things clear, you want to create a WDS-Mesh Network ?
If yes, notice that the security profiles must be identical, not only the same password, but the same 100%...
The same applies to the Wireless config as well...
by Zacharias
Wed Apr 22, 2020 12:58 pm
Forum: Beginner Basics
Topic: How to diagnose VLAN performance issues on RB3011
Replies: 21
Views: 3410

Re: How to diagnose VLAN performance issues on RB3011

I turned off my simple QoS queue so I could get fast track back on. I thought that would help.
Help on what ?
What is your Internet Speed from your ISP ?
by Zacharias
Wed Apr 22, 2020 12:55 pm
Forum: RouterBOARD hardware
Topic: Adding a cooling fan to CRS326
Replies: 39
Views: 5468

Re: Adding a cooling fan to CRS326

but, unfortunately after closing the case the CPU-temp has now risen to 63C
So do you still believe they forgot to put paste on the CPU ?
by Zacharias
Wed Apr 22, 2020 12:44 pm
Forum: Wireless Networking
Topic: Meaning of: disconnected, received deauth: no activity (4)
Replies: 9
Views: 2323

Re: Meaning of: disconnected, received deauth: no activity (4)

If i were you i would use a usb wireless adapter for a 1-2 days and see if the problem persists... If not then the problem is caused by the Laptop's wireless card... Also, since it happens often, i would set my laptop to safe mode with networking and see how it goes... The problem might as well be s...
by Zacharias
Wed Apr 22, 2020 12:41 pm
Forum: Beginner Basics
Topic: Vlan and bridge
Replies: 8
Views: 1680

Re: Vlan and bridge

anav says it can't work if dhcp is enabled on the bridge and associating a vlan with the bridge. Well I'm just saying that I saw her on a router in production and it works.

so I too am confused
That is correct...
by Zacharias
Tue Apr 21, 2020 8:30 pm
Forum: Wireless Networking
Topic: WDS seciurity not working
Replies: 12
Views: 2244

Re: WDS seciurity not working

WDS has no problem working when a password is set, so you have something wrong in your configuration that is why it does not work... However, there is no reason to use WDS between two Mikrotik Devices, AP-Bridge on one side and Station Bridge to other will bring the same result and it is the preferr...
by Zacharias
Tue Apr 21, 2020 8:26 pm
Forum: Beginner Basics
Topic: VLAN on ISP connection
Replies: 9
Views: 2118

Re: VLAN on ISP connection

@mkx am trying to think how we could avoid the creation of 2 Bridges but i can't find something...
by Zacharias
Tue Apr 21, 2020 8:00 pm
Forum: Beginner Basics
Topic: dhcp client searching
Replies: 1
Views: 820

Re: dhcp client searching

Connect to the Mikrotik device, go to DHCP-Client and make sure that eth1 is set...
by Zacharias
Tue Apr 21, 2020 7:58 pm
Forum: General
Topic: Bonding 2 Wireless device to give more bandwidth
Replies: 46
Views: 5622

Re: Bonding 2 Wireless device to give more bandwidth

Well, you could use LACP, 802.3ad protocol between the Mikrotik and the Edge switch, if the Ubiquiti supports the protocol as well, you will have to check that out... Also my concern is that CCR1009 will not support the protocol in hardware level... It would be best to use the CCR as router and a CR...
by Zacharias
Tue Apr 21, 2020 7:44 pm
Forum: Wireless Networking
Topic: How can I route successfuly 2 different segments.....
Replies: 3
Views: 945

Re: How can I route successfuly 2 different segments.....

You should be able to reach that subnet unless you block the traffic... You can export your configuration with hide-sensitive and post it insde code tags...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 8