Community discussions

MikroTik App

Search found 3327 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 12
by Zacharias
Thu May 26, 2022 11:04 pm
Forum: Wireless Networking
Topic: Network a camera through RBWAPG-60AD-A [SOLVED]
Replies: 2
Views: 88

Re: Network a camera through RBWAPG-60AD-A [SOLVED]

If the question is whether you can connect the LAN side of Injector 1 to the LAN side of the Injector 2, yes.
by Zacharias
Tue May 24, 2022 11:02 pm
Forum: General
Topic: Card Payment machines do not work on 6.40 and above
Replies: 9
Views: 1254

Re: Card Payment machines do not work on 6.40 and above

With this i got some kind of success as the terminals CAN connect to the Wi-Fi but they instantly loose conection again. What does the log say about that on the WAP when you set /system/logging/add topics=wireless,debug action=memory and then you try to connect ? Also, check here https://wiki.mikro...
by Zacharias
Tue May 24, 2022 10:55 pm
Forum: General
Topic: LtAP mini LTE passthrough+ no internet
Replies: 6
Views: 265

Re: LtAP mini LTE passthrough+ no internet

/ip address
add address=10.10.59.1/24 interface=ether2 network=10.10.59.0
Change it to
/ip address
add address=10.10.59.1/24 interface=bridge-local network=10.10.59.0
by Zacharias
Tue May 24, 2022 9:52 pm
Forum: RouterBOARD hardware
Topic: CRS112-8P-4S-IN/CRS305-1G-4S+IN Tandem Tray
Replies: 9
Views: 1963

Re: CRS112-8P-4S-IN/CRS305-1G-4S+IN Tandem Tray

What do you mean by modern ?

CRS3xx line.
ok, indeed CRS3xx are very very good...
by Zacharias
Tue May 24, 2022 2:18 pm
Forum: General
Topic: recomended mikrotik for 2 isp
Replies: 3
Views: 123

Re: recomended mikrotik for 2 isp

What are the network requirements ?
RB5009 is a good choice.. but there are other routers too https://mikrotik.com/products/group/ethernet-routers

One is enough, but in a more advanced scenrario, e.g. VRRP you could use two as well...
by Zacharias
Tue May 24, 2022 2:12 pm
Forum: General
Topic: CAPsMAN second vlan cant connect to internet
Replies: 7
Views: 260

Re: CAPsMAN second vlan cant connect to internet

Why do you have both :

add address=192.168.0.0/24 gateway=192.168.0.1
add address=192.168.0.0/14 gateway=192.168.1.1
by Zacharias
Tue May 24, 2022 1:54 pm
Forum: RouterBOARD hardware
Topic: CRS112-8P-4S-IN/CRS305-1G-4S+IN Tandem Tray
Replies: 9
Views: 1963

Re: CRS112-8P-4S-IN/CRS305-1G-4S+IN Tandem Tray

Looks good! And proof, that we need a short depth modern PoE switch.
What do you mean by modern ?
by Zacharias
Tue May 24, 2022 1:44 pm
Forum: General
Topic: Can't connect to Mikrotik from internet
Replies: 3
Views: 130

Re: Can't connect to Mikrotik from internet

I agree with @mkx.
A VPN is suggested, or at least a port knocking mechanism...
by Zacharias
Sun May 22, 2022 8:32 pm
Forum: General
Topic: Switch port aggregation
Replies: 3
Views: 209

Re: Switch port aggregation

I agree with @mkx... Also, i want to add that indeed CRS1xx does not support neither 802.3ad nor xor in hardware... According to the manual CRS3xx, CRS5xx series switches and CCR2116, CCR2216 support xor and 802.3ad bonding in hardware... https://help.mikrotik.com/docs/display/ROS/CRS3xx%2C+CRS5xx%2...
by Zacharias
Sat May 21, 2022 9:21 pm
Forum: Beginner Basics
Topic: Bonding Beginner [SOLVED]
Replies: 9
Views: 426

Re: Bonding Beginner [SOLVED]

Looks like DS416play or alike.
Exactly...
It supports 802.3ad...
by Zacharias
Sat May 21, 2022 9:13 pm
Forum: RouterOS beta and rc versions
Topic: Update RouterOS
Replies: 9
Views: 1072

Re: Update RouterOS

@winap, here is the changelog https://mikrotik.com/download/changelogs
You can see all the fixes and improvements that are made on V7 as far as the LTE is concerned... Its not always about performance only...
by Zacharias
Sat May 21, 2022 12:37 pm
Forum: RouterOS beta and rc versions
Topic: protected-routerboot not enable in 7.2.3
Replies: 4
Views: 259

Re: protected-routerboot not enable in 7.2.3

It is normal that it now asks to press the RESET button
Exactly, it was added on ROS v 6.49.1
*) routerboot - enabling "protected-routerboot" feature requires a press of a button;
https://mikrotik.com/download/changelogs
by Zacharias
Sat May 21, 2022 12:30 pm
Forum: RouterOS beta and rc versions
Topic: Update RouterOS
Replies: 9
Views: 1072

Re: Update RouterOS

Personally i install ROS v7 on all the LTE devices i have in production since there are many improvements there...
by Zacharias
Sat May 21, 2022 11:53 am
Forum: General
Topic: Question regarding IKEv2/IPSEC route based
Replies: 6
Views: 307

Re: Question regarding IKEv2/IPSEC route based

IPsec does not create any interfaces. so you can not manually create any routes as you would do with GRE for example.
by Zacharias
Sat May 21, 2022 11:41 am
Forum: Beginner Basics
Topic: Bonding Beginner [SOLVED]
Replies: 9
Views: 426

Re: Bonding Beginner [SOLVED]

Remove ports ether1 and ether2 from the Bridge.
Then create the bonding interface with ports ether1 and ether2.
Finally, add the bonding interface to the Bridge.

As simple as that...
by Zacharias
Sat May 21, 2022 11:39 am
Forum: RouterBOARD hardware
Topic: External antenna on hAP or mAP
Replies: 11
Views: 528

Re: External antenna on hAP or mAP

Also check Basebox (and the set of pigtail cables).
I like this suggestion.
by Zacharias
Wed May 18, 2022 8:36 pm
Forum: General
Topic: Bridge port egress stop STP/BPDU
Replies: 8
Views: 2582

Re: Bridge port egress stop STP/BPDU

Everything you need to know is here https://help.mikrotik.com/docs/display/ROS/Bridging+and+Switching#BridgingandSwitching-Createedgeports Create Edge ports so that you restrict the port from sending BPDUs and ignore the received ones : /interface bridge add name=bridge1 /interface bridge port add b...
by Zacharias
Wed May 18, 2022 8:29 pm
Forum: RouterBOARD hardware
Topic: External antenna on hAP or mAP
Replies: 11
Views: 528

Re: External antenna on hAP or mAP

will sit hidden inside a grounded electrical cabinet -- which I can't imagine will result in good Wi-Fi experience.
What's the purpose of that ?
Managing another device ?
by Zacharias
Wed May 18, 2022 8:16 pm
Forum: General
Topic: PPPOE target
Replies: 7
Views: 319

Re: PPPOE target

Does that VLAN interface exist ?
by Zacharias
Wed May 18, 2022 4:56 pm
Forum: General
Topic: PPPOE target
Replies: 7
Views: 319

Re: PPPOE target

I think that is an indication of an unknown interface.
What did you set as target there? Maybe a dynamic interface ?
by Zacharias
Wed May 18, 2022 4:42 pm
Forum: RouterBOARD hardware
Topic: RB dead? netinstall completes but no signs of life after reboot
Replies: 5
Views: 283

Re: RB dead? netinstall completes but no signs of life after reboot

Maybe yes, maybe no...
What was the initial reason that led you to netInstall the device ?
by Zacharias
Wed May 18, 2022 11:00 am
Forum: Beginner Basics
Topic: Bonding Beginner [SOLVED]
Replies: 9
Views: 426

Re: Bonding Beginner [SOLVED]

The error message indicates you exactly what the problem is.
The port members of a bonding must not be slave interfaces of the Bridge itself. When you create the Bond interface, add that bond to the Bridge.

Also read here https://help.mikrotik.com/docs/display/ ... ng-Summary
by Zacharias
Tue May 17, 2022 10:19 pm
Forum: General
Topic: DHCP assign static outside pool
Replies: 5
Views: 241

Re: DHCP assign static outside pool

Create static leases...
by Zacharias
Tue May 17, 2022 10:12 pm
Forum: Beginner Basics
Topic: Lost "Management VLAN" access to switches [SOLVED]
Replies: 6
Views: 362

Re: Lost "Management VLAN" access to switches [SOLVED]

It looks like they have no IP addresses set
They don't.

Your management VLAN is 99 and not VLAN 10.
For testing, set the PVID on the port of PC1 to 99, and then check again.. Do the switches have an IP now ?
by Zacharias
Tue May 17, 2022 9:57 pm
Forum: General
Topic: DHCP assign static outside pool
Replies: 5
Views: 241

Re: DHCP assign static outside pool

but wondering if I can assign static leases/ips outside the dhcp server pool? But those IPs you specify are not outside the main DHCP pool... You can assign static leases to those devices... Let the DHCP assign an address to them, and then make it static and assign the IP you wish... On the Lease r...
by Zacharias
Tue May 17, 2022 9:53 pm
Forum: General
Topic: Ping -> multiple replies per request
Replies: 13
Views: 560

Re: Ping -> multiple replies per request

@rextended thanks for your answer...
by Zacharias
Tue May 17, 2022 9:32 pm
Forum: General
Topic: Ping -> multiple replies per request
Replies: 13
Views: 560

Re: Ping -> multiple replies per request

The 4-MAC problem on Wi-Fi...
What does that mean ?
by Zacharias
Tue May 17, 2022 9:20 pm
Forum: General
Topic: Ping -> multiple replies per request
Replies: 13
Views: 560

Re: Ping -> multiple replies per request

To be honest its the first time i see this.
Do you get the same result if you ping any other external host for example ?
by Zacharias
Tue May 17, 2022 1:30 pm
Forum: General
Topic: Ping -> multiple replies per request
Replies: 13
Views: 560

Re: Ping -> multiple replies per request

What do you mean ?
You have loss of ping replies ?
by Zacharias
Mon May 16, 2022 8:42 pm
Forum: RouterOS beta and rc versions
Topic: PPPoE disconnected doesn't dial up auomatically
Replies: 9
Views: 599

Re: PPPoE disconnected doesn't dial up auomatically

The pppoe tunnel, should and will go up as long as the pppoe server responds to the discovery messages of the pppoe client and all the stages get completed successfully.
https://wiki.mikrotik.com/wiki/Manual:I ... _Operation
by Zacharias
Fri May 13, 2022 4:50 pm
Forum: General
Topic: PoE Switch Options? [SOLVED]
Replies: 3
Views: 520

Re: PoE Switch Options? [SOLVED]

Or a CRS328 if you need more than 8 ports.
by Zacharias
Thu May 12, 2022 9:45 pm
Forum: Beginner Basics
Topic: moving bridge vlan to switch vlan to use hw offload
Replies: 8
Views: 760

Re: moving bridge vlan to switch vlan to use hw offload

I have tried this and I keep losing access to my dlink device, the moment that I enable vlan mode secure on the port
Can we see an export of your Switch configuration ?
by Zacharias
Thu May 12, 2022 9:39 pm
Forum: General
Topic: Connection tracking - forced off vs. auto off
Replies: 24
Views: 1442

Re: Connection tracking - forced off vs. auto off

ROS v 7.2, setting connection tracking to off created the exact same Dynamic entries in the RAW table too...
Instantly or after reboot?
Instantly...
by Zacharias
Wed May 11, 2022 10:33 pm
Forum: Beginner Basics
Topic: moving bridge vlan to switch vlan to use hw offload
Replies: 8
Views: 760

Re: moving bridge vlan to switch vlan to use hw offload

Correct, on Atheros8327 you can not offload your VLANs on the Switch Chip using Bridge VLAN Filtering. The only way to offload them is to use VLANs on the Switch chip. how would you move this config from bridge vlan to switch vlan? This is how you can configure your VLANs on the switch chip: https:/...
by Zacharias
Wed May 11, 2022 8:25 pm
Forum: General
Topic: Connection tracking - forced off vs. auto off
Replies: 24
Views: 1442

Re: Connection tracking - forced off vs. auto off

ROS v 7.2, setting connection tracking to off created the exact same Dynamic entries in the RAW table too...
by Zacharias
Wed May 11, 2022 4:16 pm
Forum: Useful user articles
Topic: rb4011 With crs328 config
Replies: 11
Views: 715

Re: rb4011 With crs328 config

our network is down help me please
How can actually someone help you with almost no valuable information provided ?
For example an export of your configurations with sensitive information removed and a more detailed analysis of what the problem is...
by Zacharias
Wed May 11, 2022 4:13 pm
Forum: General
Topic: Connection tracking - forced off vs. auto off
Replies: 24
Views: 1442

Re: Connection tracking - forced off vs. auto off

More info here https://wiki.mikrotik.com/wiki/Manual:I ... n_tracking
When set to no then connection tracking is disabled.
If set to auto then if you have a filter or Nat rule it will automatically get enabled.
by Zacharias
Wed May 11, 2022 3:55 pm
Forum: Beginner Basics
Topic: poor bridge/vlan throughput
Replies: 8
Views: 742

Re: poor bridge/vlan throughput

CRS354 supports L3 hardware offload after ROS v7.1...
https://help.mikrotik.com/docs/display/ ... 2000Series
by Zacharias
Wed May 11, 2022 2:28 pm
Forum: Useful user articles
Topic: rb4011 With crs328 config
Replies: 11
Views: 715

Re: rb4011 With crs328 config

how to make the configuration to emit a wifi zone?
If by that you mean a seperate network, then you can use VLANs.
by Zacharias
Wed May 11, 2022 2:24 pm
Forum: Beginner Basics
Topic: poor bridge/vlan throughput
Replies: 8
Views: 742

Re: poor bridge/vlan throughput

What is the device model you are using ?
by Zacharias
Wed May 11, 2022 1:40 pm
Forum: Beginner Basics
Topic: allowing traffic between vlans
Replies: 5
Views: 477

Re: allowing traffic between vlans

Can you show a network diagram of your topology and point on the traffic that you assume it is blocked ?
by Zacharias
Wed May 11, 2022 9:53 am
Forum: General
Topic: CRS328-24G-2S+ dhcp issues ether 1
Replies: 11
Views: 692

Re: CRS328-24G-2S+ dhcp issues ether 1

Indeed...
I have not noticed that...
by Zacharias
Wed May 11, 2022 9:46 am
Forum: General
Topic: CRS328-24G-2S+ dhcp issues ether 1
Replies: 11
Views: 692

Re: CRS328-24G-2S+ dhcp issues ether 1

When ask something like that, remember to the user to remove sensitive data inside the posted config...
But isn't that what hide-sensitive does ?
by Zacharias
Sun May 08, 2022 11:21 am
Forum: Wireless Networking
Topic: Unable to update firmware on R11e-LTE-US modem
Replies: 5
Views: 460

Re: Unable to update firmware on R11e-LTE-US modem

I guess you could contact the support https://mikrotik.com/support
by Zacharias
Tue May 03, 2022 8:53 pm
Forum: Wireless Networking
Topic: CRS125, VLANs and WLAN
Replies: 14
Views: 713

Re: CRS125, VLANs and WLAN

Here is another example too https://wiki.mikrotik.com/wiki/Manual:VLANs_on_Wireless
it consists of Wifi tagging and Bridge VLAN filtering, similar to what @mkx suggested i think.

Notice, though, i don't know if it has been mentioned, CRS1xx does not support bridge VLAN filtering in hardware.
by Zacharias
Tue May 03, 2022 7:50 pm
Forum: General
Topic: Do you get answers from mikrotik support ?
Replies: 16
Views: 825

Re: Do you get answers from mikrotik support ?

From my personal experience, every time i opened a ticket i got a reply back if not the same day, the next one...
They are really helpful...
by Zacharias
Mon May 02, 2022 9:05 pm
Forum: RouterBOARD hardware
Topic: Problema con modulos SFP+ colgados
Replies: 4
Views: 461

Re: Problema con modulos SFP+ colgados

Well it could be better than that, or even 0 transfer time...
But ofcorse i can't be sure that it might be related to that...
by Zacharias
Sun May 01, 2022 12:35 pm
Forum: Forwarding Protocols
Topic: Using Mangle Is Breaking Remote Access
Replies: 10
Views: 583

Re: Using Mangle Is Breaking Remote Access

@sob you are right, sorry.
I just missed that the reply will have nowhere to go because of the missing main Routing Table and that the Routing decision in Output chain is earlier than the Routing Adjustment.
by Zacharias
Sat Apr 30, 2022 9:31 pm
Forum: RouterBOARD hardware
Topic: Problema con modulos SFP+ colgados
Replies: 4
Views: 461

Re: Problema con modulos SFP+ colgados

What is the response/transfer time of the UPS and its voltage Output ?
by Zacharias
Sat Apr 30, 2022 9:04 pm
Forum: Forwarding Protocols
Topic: Using Mangle Is Breaking Remote Access
Replies: 10
Views: 583

Re: Using Mangle Is Breaking Remote Access

@anav you are right on that.
However i thought the OP was trying to access 200.1 as you can see from my previous answer and not 200.2.
Anyways, the OP indicated that it works on some cases, so i am confused now, maybe the tests where made with firewall disabled ? who knows...
by Zacharias
Sat Apr 30, 2022 8:51 pm
Forum: Forwarding Protocols
Topic: Using Mangle Is Breaking Remote Access
Replies: 10
Views: 583

Re: Using Mangle Is Breaking Remote Access

@sob i don't agree with you. Yes there are cases where not having a Main Routing Table can cause situations where the packets can't be routed and are dropped or are routed in a wrong way. But not in this case. The OP describes that can't reach from B corp the Router 200.1. The packet looking the Pac...
by Zacharias
Sat Apr 30, 2022 7:38 pm
Forum: Beginner Basics
Topic: ARP Modes
Replies: 8
Views: 531

Re: ARP Modes

Much clearer now. Still some doubt about the reply-only ARP feature though.
The Router will only reply to its own MAC address.
Other than that, you have to manually add ARP entries in the ARP Table for the rest of the LAN devices you want to communicate with.
by Zacharias
Sat Apr 30, 2022 3:20 pm
Forum: General
Topic: CRS326-24G-2S+ low speed
Replies: 12
Views: 543

Re: CRS326-24G-2S+ low speed

@rextended indeed is impressive.

How have you tested it ? It seems it can achieve those speeds but in larger packets, 1518 Bytes... https://mikrotik.com/product/rb5009ug_s ... estresults
by Zacharias
Sat Apr 30, 2022 3:17 pm
Forum: General
Topic: CRS326-24G-2S+ low speed
Replies: 12
Views: 543

Re: CRS326-24G-2S+ low speed

Which Mikrotik router can handle more than that?
Many, check in the Ethernet Routers section https://mikrotik.com/products/group/ethernet-routers
The Test results page will help you see what each device can perform.
by Zacharias
Sat Apr 30, 2022 3:13 pm
Forum: General
Topic: CRS326-24G-2S+ low speed
Replies: 12
Views: 543

Re: CRS326-24G-2S+ low speed

yes, I use it as a router.
You shouldn't ( since you expect better results )
It is a device with advanced switching capabilities.

Here you can see how the device performs as a Router https://mikrotik.com/product/CRS326-24G ... estresults
by Zacharias
Sat Apr 30, 2022 3:07 pm
Forum: Beginner Basics
Topic: hAP ac2 connection to server within LAN from outside
Replies: 10
Views: 703

Re: hAP ac2 connection to server within LAN from outside

To add to what @sob said, Indeed the connection tracking Table keeps track of all the connections that are taking place to the Router. So it knows if a packet was Source Nated, Dst Nated etc... In that example, the router knows the packet was dst nated and it will un-nat that connection. The same ha...
by Zacharias
Sat Apr 30, 2022 2:15 pm
Forum: Beginner Basics
Topic: ARP Modes
Replies: 8
Views: 531

Re: ARP Modes

Did you read here https://wiki.mikrotik.com/wiki/Manual:IP/ARP#Summary
Also, on proxy-arp the photo missing is this one here viewtopic.php?t=71721 might help you understand
by Zacharias
Sat Apr 30, 2022 11:46 am
Forum: General
Topic: Configure router interface as a switchport
Replies: 3
Views: 236

Re: Configure router interface as a switchport

Please draw a network diagram of the desired network topology and how it should work.
Also can you export the VLAN configuration you already have configured ?
by Zacharias
Sat Apr 30, 2022 11:43 am
Forum: Announcements
Topic: v7.2.1 [stable] is released!
Replies: 245
Views: 30491

Re: v7.2.1 [stable] is released!

I never change interface name of physical interfaces... ;)
I used to change the names in the past, but i don't do that anymore.
I use the default names too, even for WAN ports, and i add comments whenever needed...
by Zacharias
Sat Apr 30, 2022 11:39 am
Forum: General
Topic: Missing ether7 / no DHCP active on Port [SOLVED]
Replies: 8
Views: 575

Re: Missing ether7 / no DHCP active on Port [SOLVED]

How can the port be missing from /interface ethernet print ?
Shouldn't it be there even with another name ?
by Zacharias
Thu Apr 28, 2022 8:01 pm
Forum: Announcements
Topic: v7.2.1 [stable] is released!
Replies: 245
Views: 30491

Re: v7.2.1 [stable] is released!

I think it can rollback up to about 20 commands
Only ?
by Zacharias
Wed Apr 27, 2022 11:18 pm
Forum: General
Topic: Missing ether7 / no DHCP active on Port [SOLVED]
Replies: 8
Views: 575

Re: Missing ether7 / no DHCP active on Port [SOLVED]

Maybe you are using ether7 somewhere else in your config ? So it does not allow you to add it as a slave port on your Bridge ?
by Zacharias
Wed Apr 27, 2022 11:05 pm
Forum: RouterBOARD hardware
Topic: hEX-S and hardware VLAN switching
Replies: 17
Views: 2546

Re: hEX-S and hardware VLAN switching

You could try to use Wireshark on the host to make a more detailed packet analysis...
by Zacharias
Tue Apr 26, 2022 8:45 pm
Forum: RouterBOARD hardware
Topic: hEX-S and hardware VLAN switching
Replies: 17
Views: 2546

Re: hEX-S and hardware VLAN switching

What is your ROS version ? Did you update to latest 7.2.1 ?
Also a network diagram would help understand your network topology better.
by Zacharias
Tue Apr 26, 2022 7:27 pm
Forum: General
Topic: BW Limit of more than 4200 Mbps CCR1072
Replies: 10
Views: 710

Re: BW Limit of more than 4200 Mbps CCR1072

As far as i know, simple queues use multiple processor cores...
by Zacharias
Sat Apr 23, 2022 7:47 pm
Forum: RouterBOARD hardware
Topic: Sudden drop in signal on LHG LTE 6 Kit
Replies: 29
Views: 1637

Re: Sudden drop in signal on LHG LTE 6 Kit

It seems it is... and in V7 you can use the APN profile as well https://help.mikrotik.com/docs/display/ROS/Peripherals
But you will go from an LTE cat 6 modem to an LTE cat 4 ?
by Zacharias
Sat Apr 23, 2022 11:28 am
Forum: RouterBOARD hardware
Topic: Sudden drop in signal on LHG LTE 6 Kit
Replies: 29
Views: 1637

Re: Sudden drop in signal on LHG LTE 6 Kit

Indeed ros v7 has many fixes on the LTE. I recommend it too...
by Zacharias
Sat Apr 23, 2022 11:21 am
Forum: Wireless Networking
Topic: SXT LTE6 signal issues
Replies: 3
Views: 277

Re: SXT LTE6 signal issues

You could update to ROS v7 as well.
First backup your configuration in case something happens.
by Zacharias
Fri Apr 22, 2022 11:48 am
Forum: Beginner Basics
Topic: [HELP] Can't bandwidth limit through interface
Replies: 2
Views: 190

Re: [HELP] Can't bandwidth limit through interface

Any info on how you did that ?
by Zacharias
Fri Apr 22, 2022 11:26 am
Forum: General
Topic: MikroTik KNOT LTE Interface is missing
Replies: 10
Views: 527

Re: MikroTik KNOT LTE Interface is missing

Does anyone know, why my KNOT after upgraded to version 7.2 the LTE Interface is missing?
Then the lte interface was never there, it dit not dissapear after the update...
by Zacharias
Thu Apr 21, 2022 9:48 pm
Forum: Wireless Networking
Topic: Does RBSXTR&R11e-LTE6 support passthrough?
Replies: 4
Views: 824

Re: Does RBSXTR&R11e-LTE6 support passthrough?

I've used passthrough on LTAP, on LHGG, on WAP R, on WAP R with LTE6 on WAP AC with success... Passthrough is a feature of the modem... Am not really sure why some chipsets do not support it and what is meant by that... If you take a look here https://help.mikrotik.com/docs/display/ROS/Peripherals y...
by Zacharias
Thu Apr 21, 2022 9:19 pm
Forum: Beginner Basics
Topic: PPP - PPTP brute force attack
Replies: 15
Views: 659

Re: PPP - PPTP brute force attack

How else can I replace it in the way I can access my network remotely?
L2TP/IPsec, OVPN, Wireguard, IKEv2 are some of the protocols you can use for Road warriors but for Site to Site tunnels as well ...
by Zacharias
Thu Apr 21, 2022 4:00 pm
Forum: Wireless Networking
Topic: SXT LTE6 signal issues
Replies: 3
Views: 277

Re: SXT LTE6 signal issues

Your RSRP, RSRQ and RSSI values are not bad...
They are not excellent either.. but they are good...

You could try updating to Ros v7, there are a lot of fixes for the LTE.
Also, what is your modem firmware version ?
by Zacharias
Thu Apr 21, 2022 3:13 pm
Forum: Beginner Basics
Topic: PPP - PPTP brute force attack
Replies: 15
Views: 659

Re: PPP - PPTP brute force attack

Do not use PPTP, its not secure...
by Zacharias
Thu Apr 21, 2022 3:08 pm
Forum: RouterBOARD hardware
Topic: MIKROTIK LHGG + QUECTEL EM12-G
Replies: 20
Views: 9704

Re: MIKROTIK LHGG + QUECTEL EM12-G

My EM12G has arrived, just awaiting myipex4 to sma cables. very good upgrade. EM12 is my favorite one. If you buy it with latest firmware then it's just work out-of-box at ros7 Nice, and its cat12 as i can see... How many carriers ( CAs ) does Cat12 use? any reference on that ? Can the firmware be ...
by Zacharias
Wed Apr 20, 2022 9:17 pm
Forum: General
Topic: L2TP IPSec without password and IPSec Secret
Replies: 6
Views: 350

Re: L2TP IPSec without password and IPSec Secret

Or if you meant that it would be possible to drop dst-port and only keep ipsec-policy, then yes and no. Just for L2TP, yes, because created policies are for just this one port anyway. But in case you have some other IPSec tunnels, this rule could allow access to anything on router, which may not be...
by Zacharias
Wed Apr 20, 2022 8:39 pm
Forum: General
Topic: L2TP IPSec without password and IPSec Secret
Replies: 6
Views: 350

Re: L2TP IPSec without password and IPSec Secret

/ip firewall filter
add chain=input protocol=tcp dst-port=1701 ipsec-policy=in,ipsec action=accept
@sob, do we actually need the dst-port=1701 here ?
Its UDP by the way, i guess you just missed that...
by Zacharias
Wed Apr 20, 2022 4:48 pm
Forum: General
Topic: how long interval time for 'reformat-hold-button-max' set?
Replies: 4
Views: 277

Re: how long interval time for 'reformat-hold-button-max' set?

Release 6.49.1
*) routerboot - enabling "protected-routerboot" feature requires a press of a button;

https://mikrotik.com/download/changelog ... lease-tree
by Zacharias
Mon Apr 18, 2022 9:03 pm
Forum: General
Topic: MikroTik KNOT LTE Interface is missing
Replies: 10
Views: 527

Re: MikroTik KNOT LTE Interface is missing

Downgrade to V6...
Is the interface back ?

You can always contact MikroTIK support... https://mikrotik.com/support
by Zacharias
Sun Apr 17, 2022 9:17 pm
Forum: General
Topic: convert access port to trunk port to HP server [SOLVED]
Replies: 12
Views: 906

Re: convert access port to trunk port to HP server [SOLVED]

So a hybrid port only has one untagged vlan (and as many tagged vlans as required)
As long as they do not match.
In practice, it won't let you add the same port as tagged and untagged anyways...
by Zacharias
Sun Apr 17, 2022 8:54 pm
Forum: General
Topic: convert access port to trunk port to HP server [SOLVED]
Replies: 12
Views: 906

Re: convert access port to trunk port to HP server [SOLVED]

An access port, for example, will strip the VLAN tag of the packet matching the VID of the port on egress.
So you can't have port etherX both Access Port for VLAN 10 and Tagged Port for VLAN10.
by Zacharias
Sun Apr 17, 2022 2:26 pm
Forum: General
Topic: MikroTik KNOT LTE Interface is missing
Replies: 10
Views: 527

Re: MikroTik KNOT LTE Interface is missing

I would first give netinstall a try...
https://help.mikrotik.com/docs/display/ROS/Netinstall
by Zacharias
Sun Apr 17, 2022 2:22 pm
Forum: General
Topic: convert access port to trunk port to HP server [SOLVED]
Replies: 12
Views: 906

Re: convert access port to trunk port to HP server [SOLVED]

It depends on the Switch model... So what device are you using ?
by Zacharias
Sun Apr 17, 2022 12:53 pm
Forum: General
Topic: convert access port to trunk port to HP server [SOLVED]
Replies: 12
Views: 906

Re: convert access port to trunk port to HP server [SOLVED]

That is a Hybrid setup. You can have an access port on VLAN10 and at the same time the same port can be a Trunk Port for VLAN 11. Notice though, a trunk Port carries Tagged Traffic, so the port will tag the packets on egress ( the ones that do not belong on VLAN 10 ) with VLAN ID 11. That means your...
by Zacharias
Sun Apr 17, 2022 12:21 pm
Forum: General
Topic: MikroTik KNOT LTE Interface is missing
Replies: 10
Views: 527

Re: MikroTik KNOT LTE Interface is missing

As i can see you have 7.1.5.. but the router shows firmware 7.2 So at some point you did upgraded the ROS and firmware to 7.2, then for some reason your downgraded to 7.1.5 and you left the firmware version as it was... I am missing details on why you downgraded, because the LTE was missing ? Person...
by Zacharias
Sun Apr 17, 2022 12:01 pm
Forum: Announcements
Topic: v7.2.1 [stable] is released!
Replies: 245
Views: 30491

Re: v7.2.1 [stable] is released!

Updating an LTAP LTE6 from version 6.49.5 to 7.2.1, ROS upgrade was successful
After i upgraded the firmware, from 6.49.5 as well, the device upon boot had lost the LTE interface... A second reboot solved it...
Am not sure if that was supposed to happen or not ...
by Zacharias
Sun Apr 17, 2022 11:48 am
Forum: General
Topic: LtAP setup issues with LTE [SOLVED]
Replies: 40
Views: 2059

Re: LtAP setup issues with LTE [SOLVED]

I'd also recommend trying 7.2. It has a lot of LTE fixes over any of the 7.1.x versions.
Updating an LTAP on 7.2.1, the ROS update was successful
When i updated the firmware, the device lost the lte interface, i had to reboot it a second time in order to find it...
by Zacharias
Sat Apr 09, 2022 1:37 pm
Forum: RouterBOARD hardware
Topic: CCR 1009 does not initialize. no netinstall
Replies: 5
Views: 3390

Re: CCR 1009 does not initialize. no netinstall

If you press the reset button before applying power to the device then the backup bootloader will load...
by Zacharias
Sun Apr 03, 2022 8:48 pm
Forum: General
Topic: VoIP vlan
Replies: 10
Views: 635

Re: VoIP vlan

You need a Hybrid VLAN configuration... Set the PVID on port 21 to PVID=14. So, port 21 will be using tagged traffic on VID 1720 and Untagged traffic on VID 14... But since reading on a previous post you say that this does not work ( it should ), maybe a wrong configuration on the VLAN side of the G...
by Zacharias
Sun Apr 03, 2022 8:30 pm
Forum: General
Topic: CRS212 normal behaviour?
Replies: 1
Views: 125

Re: CRS212 normal behaviour?

How are the VLANs configured on your CRS112 ?
by Zacharias
Sun Apr 03, 2022 7:51 pm
Forum: Beginner Basics
Topic: How to passthrough LTE with ipv4 and ipv6
Replies: 4
Views: 346

Re: How to passthrough LTE with ipv4 and ipv6

There is no even IP type ipv4ipv6
What do you mean ?
In the APN menu there is an IP type field where you can select both IPv4 and IPv6.
After that you enable the passthrough feature...
And ofcorse in the LTE general tab you should select the correct APN profile.
by Zacharias
Sun Apr 03, 2022 7:43 pm
Forum: RouterBOARD hardware
Topic: LTE router recommendation
Replies: 6
Views: 590

Re: LTE router recommendation

I would suggest an LTE6 modem device for better performance results ...
by Zacharias
Sun Apr 03, 2022 6:54 pm
Forum: RouterBOARD hardware
Topic: Sudden drop in signal on LHG LTE 6 Kit
Replies: 29
Views: 1637

Re: Sudden drop in signal on LHG LTE 6 Kit

@mkx how can it be useless since it is used in the calculation of the RSRQ value ?
I think all the values ( RSRP, RSRQ, SINR and RSSI ) have their importance...

Is there any value you take into account the most ?
by Zacharias
Sun Apr 03, 2022 12:33 pm
Forum: RouterBOARD hardware
Topic: Sudden drop in signal on LHG LTE 6 Kit
Replies: 29
Views: 1637

Re: Sudden drop in signal on LHG LTE 6 Kit

RSRP better than -86db
RSRP of -86db does not indicate on any way loss of connection...
You should take into account the RSRQ SINR and RSSI values too...
Also you don't mention what the ROS version is and what the modem firmware version is... ???
by Zacharias
Sun Apr 03, 2022 12:19 pm
Forum: Beginner Basics
Topic: Where to find SIM phone number in MikroTik RBSXTR&R11e-LTE6 (SXT LTE6 kit)
Replies: 3
Views: 256

Re: Where to find SIM phone number in MikroTik RBSXTR&R11e-LTE6 (SXT LTE6 kit)

If you don't know the number and you just want to know what that is, perhaps sending an sms and then verifying the number would help...
https://wiki.mikrotik.com/wiki/Manual:Tools/Sms
by Zacharias
Fri Apr 01, 2022 11:16 pm
Forum: General
Topic: PoE at voltage selection? [SOLVED]
Replies: 17
Views: 894

Re: PoE at voltage selection? [SOLVED]

Which means my fear may be valid - what if Hex negotiates too little power and / or voltage for the device it powers (via passive poe out)?
Why don't you just test it ?
by Zacharias
Fri Apr 01, 2022 9:24 pm
Forum: General
Topic: PoE at voltage selection? [SOLVED]
Replies: 17
Views: 894

Re: PoE at voltage selection? [SOLVED]

My fear is simple - what if mikrotik negotiates voltage, that is too low for my unifi device
From a quick look to some of my production equipment a CAP AC and a wsAP for example, that are capable of af/at at POE in are fed with 52V from a CRS328...
by Zacharias
Fri Apr 01, 2022 9:15 pm
Forum: Beginner Basics
Topic: Create two simple VLANs with D-Link switch
Replies: 6
Views: 504

Re: Create two simple VLANs with D-Link switch

I am a happy beginner who wants to learn more
Since you want to learn, take a look here viewtopic.php?t=143620
Also there are many Articles in the MikroTIK documentation to read...
Very important, is what device model you have... ?
by Zacharias
Fri Apr 01, 2022 9:12 pm
Forum: General
Topic: PoE at voltage selection? [SOLVED]
Replies: 17
Views: 894

Re: PoE at voltage selection? [SOLVED]

@mkx there are devices such as CRS328 and CRS354 that do support voltage selection ( LOW, HIGH ) and do not need 2 PSUs...
Obviously they do have voltage regulators :D
by Zacharias
Mon Mar 28, 2022 4:25 pm
Forum: General
Topic: Where do i see mikrotik public WAN ip?
Replies: 56
Views: 2333

Re: Where do i see mikrotik public WAN ip?

An ISPs router can both act as a Router and at the same time having passthrough enabled...
Since you can reach the internet connected to your ISPs wifi obviously it acts as a router too...

Are you sure the IP address space assigned to you by your ISP belongs to the Public IP address space ?
by Zacharias
Mon Mar 28, 2022 4:19 pm
Forum: Beginner Basics
Topic: Redirect to external domain
Replies: 32
Views: 1533

Re: Redirect to external domain

Nice explanation of Hairpin NAT from @mkx
Not sure if this is hairpin nat?? In the sense that its redirecting wanips vice ensuring traffic gets back from server to originator on same LAN.
Well i think @mkx answered your question...
Same technique...
by Zacharias
Mon Mar 28, 2022 4:12 pm
Forum: RouterBOARD hardware
Topic: 5009 powering question
Replies: 19
Views: 2641

Re: 5009 powering question

It's not switch - it is 5009
I am reffering to the device that gives power to the RB5009 through POE...
by Zacharias
Sun Mar 27, 2022 6:41 pm
Forum: General
Topic: CRS112-8P-4S-IN does not come close to gigabit SPEEDTEST
Replies: 2
Views: 229

Re: CRS112-8P-4S-IN does not come close to gigabit SPEEDTEST

What is the configuration of the CRS112 ?
Is it configured as a switch connected to a router ?
Or is it configured as a router ?

If the second, then as stated on the previous post, CRS112 is a switch it has an advanced switch chip but limited CPU performance...
by Zacharias
Sun Mar 27, 2022 6:24 pm
Forum: Beginner Basics
Topic: Redirect to external domain
Replies: 32
Views: 1533

Re: Redirect to external domain

Nice explanation of Hairpin NAT from @mkx
by Zacharias
Sun Mar 27, 2022 6:05 pm
Forum: General
Topic: 💥Bug : delay action CCR2116-12G-4s+ firewall mikrotik OSv7
Replies: 41
Views: 1999

Re: 💥Bug : delay action CCR2116-12G-4s+ firewall mikrotik OSv7

I don't see what problems could this behaviour cause.
Can someone explain not in a video?
Personally i am not saying that it will cause any problems...
I am just saying that it seems its not because of the connection tracking...
by Zacharias
Sun Mar 27, 2022 5:51 pm
Forum: RouterBOARD hardware
Topic: 5009 powering question
Replies: 19
Views: 2641

Re: 5009 powering question

Scenarios: A) Both sources connected at startup The 2-pin terminal takes charge and PoE is never delivered (confirmed with web-management switch portal). I think your problem is here... RB5009 should be able to negotiate and draw power through the POE in regardless that the 2pin terminal is connect...
by Zacharias
Sun Mar 27, 2022 5:38 pm
Forum: General
Topic: Where do i see mikrotik public WAN ip?
Replies: 56
Views: 2333

Re: Where do i see mikrotik public WAN ip?

I am trying to understand where the problem is... If you have a static IP block given to you by your ISP, a /27 as you said ( 32 available addresses from which the first is the network address and the last the broadcast address ) then you assign ( usually ) the second available host address to the e...
by Zacharias
Sat Mar 26, 2022 8:57 pm
Forum: General
Topic: Can't make DHCP Server VLAN over Trunk Port
Replies: 3
Views: 302

Re: Can't make DHCP Server VLAN over Trunk Port

Also a nice article to read for Bridge VLAN filtering viewtopic.php?t=143620
by Zacharias
Sat Mar 26, 2022 8:53 pm
Forum: General
Topic: L2TP v3 / L2TP Ethernet
Replies: 1
Views: 244

Re: L2TP v3 / L2TP Ethernet

It seems there is no reference on the wiki.
by Zacharias
Sat Mar 26, 2022 8:51 pm
Forum: Announcements
Topic: WinBox v3.35 released!
Replies: 95
Views: 36915

Re: WinBox v3.35 released!

ctrl+- is for zoom out and ctrl+= is for zoom in
by Zacharias
Sat Mar 26, 2022 8:47 pm
Forum: General
Topic: 💥Bug : delay action CCR2116-12G-4s+ firewall mikrotik OSv7
Replies: 41
Views: 1999

Re: 💥Bug : delay action CCR2116-12G-4s+ firewall mikrotik OSv7

@Larsa, i think the OP ( i quickly viewed the video ) at some point of time disables connection tracking and tests again the add/remove firewall filter rule, and it seems there is still a delay, although connection tracking was disabled. So, if the connection tracking was causing the delay, then why...
by Zacharias
Sat Mar 26, 2022 4:22 pm
Forum: General
Topic: 💥Bug : delay action CCR2116-12G-4s+ firewall mikrotik OSv7
Replies: 41
Views: 1999

Re: 💥Bug : delay action CCR2116-12G-4s+ firewall mikrotik OSv7

So, if for example you add 10 rules in the firewall, and you remove a random one, you still get the same delay ?
by Zacharias
Sat Mar 26, 2022 4:19 pm
Forum: Beginner Basics
Topic: VLANs on RB750GR3 - I'm stuck...
Replies: 43
Views: 3868

Re: VLANs on RB750GR3 - I'm stuck...

@Buckeye i am surprised too since i clearly mention that support on Bridge VLAN filtering in hardware is added on Ros v7... So i totally do not understand your point... Also, if the switch chip itself has a VLAN table, but ROS does not use it ( on V6 for example ), this does not change the fact, tha...
by Zacharias
Sat Mar 26, 2022 4:14 pm
Forum: Wireless Networking
Topic: Unable to update firmware on R11e-LTE-US modem
Replies: 5
Views: 460

Re: Unable to update firmware on R11e-LTE-US modem

Upon firmware upgrade procedure the LTE will show as not Running... If i remember right that is at the installing phase...
That is normal...

I would suggest you reset the device to defaults, uninstall any extra packages ( if added ) and retry to update the modem...
by Zacharias
Sat Mar 26, 2022 4:08 pm
Forum: General
Topic: Vlan question
Replies: 5
Views: 429

Re: Vlan question

@chechito you are right, i just missed that Atheros 8227 has a VLAN table too, my mistake...
by Zacharias
Fri Mar 25, 2022 8:37 pm
Forum: General
Topic: Vlan question
Replies: 5
Views: 429

Re: Vlan question

Yes you can... However if you follow the advice on the second post and go with Bridge VLAN Filtering, you will loose the hardware offload on your Bridge since Atheros 8327 ( the switch chip on first 5 ports of RB2011 ) does not support Bridge VLAN filtering in Hardware... However, it supports VLANs ...
by Zacharias
Fri Mar 25, 2022 8:28 pm
Forum: Wireless Networking
Topic: Unable to update firmware on R11e-LTE-US modem
Replies: 5
Views: 460

Re: Unable to update firmware on R11e-LTE-US modem

When you run the command on terminal: /interface/lte/firmware-upgrade lte1 upgrade=yes The modem will download the firmware and upon installing the lte will drop and that is normal... You should not do anything until the terminal informs you that the installation is done... If for some reason it won...
by Zacharias
Fri Mar 25, 2022 6:28 pm
Forum: General
Topic: Hairpin NAT issues [SOLVED]
Replies: 2
Views: 397

Re: Hairpin NAT issues [SOLVED]

by Zacharias
Fri Mar 25, 2022 6:18 pm
Forum: General
Topic: RB4011 utilizing only CPU0
Replies: 2
Views: 397

Re: RB4011 utilizing only CPU0

70% load is high, i don't think that neither your PPPoE nor your NAT are causing it...
by Zacharias
Fri Mar 25, 2022 6:02 pm
Forum: The Dude
Topic: Dude client slow loading
Replies: 3
Views: 333

Re: Dude client slow loading

Yes, it is a limitation of the CHR free license...
https://wiki.mikrotik.com/wiki/Manual:C ... al%20guest.
by Zacharias
Fri Mar 25, 2022 2:31 pm
Forum: Wireless Networking
Topic: CAPsMAN - Slow wifi, devices disconnecting
Replies: 16
Views: 1053

Re: CAPsMAN - Slow wifi, devices disconnecting

@anav, when someone wants a MikroTIK router/switch/AP and you suggest something different than that, obviously you are out off topic 100%... You can suggest whatever you want... Let the other engineers/users etc... make their own suggestions as well and have their own opinions, experience, preferenc...
by Zacharias
Fri Mar 25, 2022 2:18 pm
Forum: General
Topic: 💥Bug : delay action CCR2116-12G-4s+ firewall mikrotik OSv7
Replies: 41
Views: 1999

Re: 💥Bug : delay action CCR2116-12G-4s+ firewall mikrotik OSv7

I sent this bug to the mikrotik team 8 days ago. But no news yet.
🙄😭😢😭
I guess because it is not a bug...
As said earlier, do you plan on adding removing a single firewall rule in your setup ?
by Zacharias
Fri Mar 25, 2022 2:13 pm
Forum: Beginner Basics
Topic: VLANs on RB750GR3 - I'm stuck...
Replies: 43
Views: 3868

Re: VLANs on RB750GR3 - I'm stuck...

The manual is clear that MT7621 has no VLAN Table support...https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features Bridge HW offload on VLANs was added on ROS v7.1rc5 https://help.mikrotik.com/docs/display/ROS/Switch+Chip+Features Also the changelog https://mikrotik.com/download/changelogs has n...
by Zacharias
Wed Mar 23, 2022 8:25 pm
Forum: General
Topic: 💥Bug : delay action CCR2116-12G-4s+ firewall mikrotik OSv7
Replies: 41
Views: 1999

Re: 💥Bug : delay action CCR2116-12G-4s+ firewall mikrotik OSv7

Did you try connecting over IP instead of MAC?
It would be interesting if the behavior is different...
by Zacharias
Wed Mar 23, 2022 8:01 pm
Forum: Beginner Basics
Topic: Brand new network - noob
Replies: 8
Views: 397

Re: Brand new network - noob

@anav, the OP can as well go to https://mikrotik.com/products the product page and check the Test results for any device... That way, he does not need neither my opinion nor yours... So, when someone asks for a recommendation , i guess he needs something more than what he can already find on the Pro...
by Zacharias
Wed Mar 23, 2022 7:46 pm
Forum: General
Topic: 💥Bug : delay action CCR2116-12G-4s+ firewall mikrotik OSv7
Replies: 41
Views: 1999

Re: 💥Bug : delay action CCR2116-12G-4s+ firewall mikrotik OSv7

Did you try to update to the latest 7.1.5 and see if anything changes ?
Or maybe to 7.2rc5 ?
by Zacharias
Wed Mar 23, 2022 7:25 pm
Forum: Beginner Basics
Topic: Brand new network - noob
Replies: 8
Views: 397

Re: Brand new network - noob

The RB4011 and RB50009 have the port numbers but are easily good to well over 1Gig throughput up and down so a tad overkill. @anav, a Router should always be able to perform better than the actual requirements...At least that is they way i think it should be... Today the OP will use an ISP line of ...
by Zacharias
Wed Mar 23, 2022 7:15 pm
Forum: Beginner Basics
Topic: My final hurdle, VoIP vlans [SOLVED]
Replies: 5
Views: 478

Re: My final hurdle, VoIP vlans [SOLVED]

But they need to be in the same bridge for that to work? Or not?
You will not Bridge the VLAN interfaces, but the ports...
The ports will be either Trunk Ports or Access Ports, depending on how you will configure them...
by Zacharias
Wed Mar 23, 2022 5:06 pm
Forum: Beginner Basics
Topic: Brand new network - noob
Replies: 8
Views: 397

Re: Brand new network - noob

For a simple setup like this, i would suggest an RB4011 or RB5009, for a switch a CRS112 or in case you need something more advanced then a CRS326 or CRS328 in case you need POE and for wireless Access Points CAP AC.
by Zacharias
Wed Mar 23, 2022 5:02 pm
Forum: Beginner Basics
Topic: VLAN Access port issue
Replies: 2
Views: 157

Re: VLAN Access port issue

VLAN Filtering on the bridge is disabled and when I enable it I lose all connection and have to restore to a previous config.
Wrong configuration...
Post your configuration as @anav suggested.
Next time let a port out of the Bridge or use console port for management.
by Zacharias
Wed Mar 23, 2022 4:59 pm
Forum: General
Topic: Irony
Replies: 3
Views: 387

Re: Irony

From what version ( of ROS v6 ) did you upgrade ?
by Zacharias
Wed Mar 23, 2022 4:41 pm
Forum: General
Topic: Where do i see mikrotik public WAN ip?
Replies: 56
Views: 2333

Re: Where do i see mikrotik public WAN ip?

how do i setup the mikrotik router to use the static IP i have?

Here.
As @tangent already said, you configure a Public static IP the same way as you would configure any other IP...
by Zacharias
Wed Mar 23, 2022 4:39 pm
Forum: Beginner Basics
Topic: My final hurdle, VoIP vlans [SOLVED]
Replies: 5
Views: 478

Re: My final hurdle, VoIP vlans [SOLVED]

Have you read this article ? https://forum.mikrotik.com/viewtopic.php?t=143620 Since you already have ROS v7 installed, you can use VLANs along with Bridge filtering enabled, that will be in hardware... Also you do not need all those Bridges... A trunk port with your ISP to receive the VLANs 832 and...
by Zacharias
Tue Mar 22, 2022 9:08 pm
Forum: RouterOS beta and rc versions
Topic: Where is UPS?
Replies: 24
Views: 7795

Re: Where is UPS?

Only APC ups are supported ?
My CyberPower CST135UC works fine
Great...
I mostly use CyberPower too...
I will give it a try soon...
by Zacharias
Tue Mar 22, 2022 9:06 pm
Forum: Beginner Basics
Topic: new ISP wants PPPoE connection with tagged VLAN - need some guidance
Replies: 15
Views: 980

Re: new ISP wants PPPoE connection with tagged VLAN - need some guidance

You do not say which VPN protocol you are trying, IPsec will not work as you are missing add action=accept chain=input comment="allow IPsec ESP" protocol=ipsec-esp It depends... If NAT-T is supported and used by both sides then ESP packet will be encapsulated inside UDP Port 4500 packet.....
by Zacharias
Tue Mar 22, 2022 9:00 pm
Forum: RouterOS beta and rc versions
Topic: Where is UPS?
Replies: 24
Views: 7795

Re: Where is UPS?

Only APC ups are supported ?
by Zacharias
Tue Mar 22, 2022 8:29 pm
Forum: Wireless Networking
Topic: Virtual WLAN and VLAN's
Replies: 133
Views: 5779

Re: Virtual WLAN and VLAN's

RB4011 is indeed a good choice...
If it is a home Router, i would suggest you try V7 and Bridge Hardware Offloading...
If something does not work as expected you can always downgrade...
by Zacharias
Sun Mar 20, 2022 10:22 pm
Forum: Beginner Basics
Topic: Issues with DHCP
Replies: 8
Views: 501

Re: Issues with DHCP

From a quick look i can't see anything wrong in the configuration... From what you describe in your first post, the devices get an IP address from the DHCP server successfully, but they can not reach the internet... I would suggest you change the default network to something else, lets say 192.168.1...
by Zacharias
Sun Mar 20, 2022 6:59 pm
Forum: Beginner Basics
Topic: Issues with DHCP
Replies: 8
Views: 501

Re: Issues with DHCP

Please /export hide-sensitive the Router configuration...
by Zacharias
Sun Mar 20, 2022 6:51 pm
Forum: General
Topic: received DHCP server message on untrusted port?
Replies: 3
Views: 467

Re: received DHCP server message on untrusted port?

Can you /export hide-sensitive the switch configuration ?
by Zacharias
Sun Mar 20, 2022 6:43 pm
Forum: General
Topic: LtAP setup issues with LTE [SOLVED]
Replies: 40
Views: 2059

Re: LtAP setup issues with LTE [SOLVED]

ether1 is not your WAN port... lte1 is your WAN port... So remove ether1 from the WAN list and add your lte interface... Also i see no masquerade rule for your LTE interface... ip firewall/nat/add chain=srcnat out-interface-list=WAN action=masquerade No IP address assignment on your Bridge and no DH...
by Zacharias
Sat Mar 19, 2022 9:08 pm
Forum: General
Topic: LtAP setup issues with LTE [SOLVED]
Replies: 40
Views: 2059

Re: LtAP setup issues with LTE [SOLVED]

Everyone has been so helpful and the config tips get me going however, defaulting and resetting and netinstalls all get me back to my same problem...
Can you please /export hide-sensitive the configuration you have after reset to no defaults was made ?
by Zacharias
Sat Mar 19, 2022 9:03 pm
Forum: General
Topic: received DHCP server message on untrusted port?
Replies: 3
Views: 467

Re: received DHCP server message on untrusted port?

This message indicates that the switch received a message coming from a DHCP server ( probably a DHCP offer ) located to an untrusted port... If it is not the AP itself using a DHCP server then it is a client connected to that AP... This is just a warning message... Since snooping is enabled the swi...
by Zacharias
Sat Mar 19, 2022 8:45 pm
Forum: General
Topic: LtAP setup issues with LTE [SOLVED]
Replies: 40
Views: 2059

Re: LtAP setup issues with LTE [SOLVED]

Here https://help.mikrotik.com/docs/display/ROS/LTE#LTE-Quicksetupexample you can see the APN configuration... Then, in a simple Router setup, create a Bridge and add the ether1 and wlan interfaces as ports, set an IP address to the Bridge interface e.g. 192.168.1.1/24, create a DHCP server on the B...
by Zacharias
Sat Mar 19, 2022 8:04 pm
Forum: General
Topic: LtAP setup issues with LTE [SOLVED]
Replies: 40
Views: 2059

Re: LtAP setup issues with LTE [SOLVED]

@sindy i installed a LTAP LTE6 this week. I noticed nothing strange compared to other MikroTIK LTE devices i' ve used ( WAP, WAP LTE6, LHGG,) as far as the configuration is concerned . As @Amm0 wrote above, there is a difference between the default configuration script of an LtAP "LTE(6) kit&q...
by Zacharias
Sat Mar 19, 2022 7:55 pm
Forum: General
Topic: LtAP setup issues with LTE [SOLVED]
Replies: 40
Views: 2059

Re: LtAP setup issues with LTE [SOLVED]

I would suggest you to reset to defaults, then upgrade to 7.1.3 and test again... Look into the default configuration script of 7.1.3 as posted by @Amm0 in this post . It sets exactly what OP is getting. No point in spawning it over and over again, the result will be the same. @sindy i installed a ...
by Zacharias
Sat Mar 19, 2022 7:42 pm
Forum: General
Topic: LtAP setup issues with LTE [SOLVED]
Replies: 40
Views: 2059

Re: LtAP setup issues with LTE [SOLVED]

I would suggest you to reset to defaults, then upgrade to 7.1.3 and test again...
by Zacharias
Sat Mar 19, 2022 7:17 pm
Forum: Wireless Networking
Topic: CAPsMAN - Slow wifi, devices disconnecting
Replies: 16
Views: 1053

Re: CAPsMAN - Slow wifi, devices disconnecting

Though I'm not @gotsprings...local forwarding will not cause a high cpu load on the CAPsMAN.
I agree on that, but it is a users mistake if Capsman forwarding is used on a low performance CPU device...
by Zacharias
Mon Mar 14, 2022 9:13 pm
Forum: Beginner Basics
Topic: new ISP wants PPPoE connection with tagged VLAN - need some guidance
Replies: 15
Views: 980

Re: new ISP wants PPPoE connection with tagged VLAN - need some guidance

@fevr just create a VLAN interface under /interfaces VLAN, use as interface the Interface the ISPs Router is connected and set as VID= the Vlan ID your ISP needs for communication ...
Then on your PPPoE connection use as Interface the one created under /interfaces VLAN...
by Zacharias
Mon Mar 14, 2022 8:51 pm
Forum: General
Topic: 2 ways to associate bridge and VLAN
Replies: 22
Views: 1294

Re: 2 ways to associate bridge and VLAN

Probably, i used a wrong diagram indeed... :D
Thanks @tdw and @mkx for answering...
I was more confused with the terminology Tagged and Untagged Ends the way they were used, but i think i got it...
by Zacharias
Mon Mar 14, 2022 4:56 pm
Forum: Beginner Basics
Topic: How to WoL to different VLAN devices?
Replies: 6
Views: 456

Re: How to WoL to different VLAN devices?

MikroTIK itself has WoL implemented, you will find it under /tool/wol Devices to be waked through a WoL packet ( magic packet ) must be in the same Broadcast domain. Since you use VLANs, those broadcast domains are seperated... I don't know if there is a workaround on this... But you can try if you ...
by Zacharias
Mon Mar 14, 2022 4:28 pm
Forum: Wireless Networking
Topic: Cap Lite RBcAPL-2nD slow wifi speed [SOLVED]
Replies: 10
Views: 684

Re: Cap Lite RBcAPL-2nD slow wifi speed [SOLVED]

oh my, now i did try to put CAP LITE in Home AP mode, Ive dissabled WPS and now Im getting 62,6Mbit over wifi, which is little improvement.....even upload is now 11,8Mbit, which is strange since my internet connection limit is 150/10Mbit :) As you can see the problem is not the CapsMAN. Don't expec...
by Zacharias
Mon Mar 14, 2022 4:09 pm
Forum: General
Topic: Port forwarding working partially
Replies: 18
Views: 810

Re: Port forwarding working partially

The rule apparently works, since there are packets counting...
Are you sure the server is listening to the correct port ?
Or you don't block it through the Firewall ( the to-ports port )?
by Zacharias
Mon Mar 14, 2022 4:06 pm
Forum: Wireless Networking
Topic: Cap Lite RBcAPL-2nD slow wifi speed [SOLVED]
Replies: 10
Views: 684

Re: Cap Lite RBcAPL-2nD slow wifi speed [SOLVED]

-I tried to use local forwarding, but it didnt have any impact on the wifi speed
So i guess it is not solved...

If you remove the CAP from the Capsman, do you see any improvement in the Speeds ?
by Zacharias
Mon Mar 14, 2022 3:36 pm
Forum: Wireless Networking
Topic: Connectivity issus with multiple virtual wlan interfaces
Replies: 3
Views: 322

Re: Connectivity issus with multiple virtual wlan interfaces

The performance will decrease even with less than 30 Virtual SSIDs... To my personal opinion you should not exceed 10 Virtual SSIDs.. Also what plays significant role, is how many APs exist from neighbouring netwroks broadcasting on the same Channel. If for example you create less than 10 SSIDs, doe...
by Zacharias
Mon Mar 14, 2022 3:19 pm
Forum: General
Topic: 2 ways to associate bridge and VLAN
Replies: 22
Views: 1294

Re: 2 ways to associate bridge and VLAN

Thanks for answering.., My question is mostly related to what @mkx names as Tagged end and Untagged end... As far as i know, when you set an interface with a VID under /interface vlan then looking at the packet flow photo https://help.mikrotik.com/docs/display/ROS/Packet+Flow+in+RouterOS#PacketFlowi...
by Zacharias
Sun Mar 13, 2022 9:20 pm
Forum: General
Topic: Problem with l2tp VPN: can surf the net only one device at a time
Replies: 7
Views: 519

Re: Problem with l2tp VPN: can surf the net only one device at a time

My suggestion would be to use another VPN type if you want multiple Road warriors behind the same Public IP to connect to a specific VPN server...
That could be wireguard ( ROS v7 ) OVPN ( TCP on ROS v6 or TCP and UDP on ROS v7 ), IKEv2 etc. ...
by Zacharias
Sun Mar 13, 2022 8:49 pm
Forum: Beginner Basics
Topic: Leave source IP unmodified beyond NAT
Replies: 22
Views: 1051

Re: Leave source IP unmodified beyond NAT

Can you provide a network diagram with the Topology of your network, and a simple example of what you re trying to achieve ?
by Zacharias
Sun Mar 13, 2022 8:41 pm
Forum: RouterBOARD hardware
Topic: Powerbox Pro with 3 PoE devices [SOLVED]
Replies: 12
Views: 1010

Re: Powerbox Pro with 3 PoE devices [SOLVED]

If you want to supply voltage to devices that accept Passive POE and also supply some other with af/at then there is a solution... Using a device that has selectable POE out Voltage... netPower 16P is an example https://mikrotik.com/product/netpower_16p#fndtn-gallery Since the device has no onboard ...
by Zacharias
Sun Mar 13, 2022 8:15 pm
Forum: RouterOS beta and rc versions
Topic: How to downgrade beyond the factory installed version 7.1.1
Replies: 15
Views: 1129

Re: How to downgrade beyond the factory installed version 7.1.1

Hello how can we downgrade from the factory installed version 7.1.1
That is the version the device has installed right now...
But what is the Factory Firmware version under /system routerboard ?
What is the Factory Software version under /system resources ?
by Zacharias
Sun Mar 13, 2022 7:49 pm
Forum: Wireless Networking
Topic: CAPsMAN - Slow wifi, devices disconnecting
Replies: 16
Views: 1053

Re: CAPsMAN - Slow wifi, devices disconnecting

@gotsprings you prefer Local Forwarding mode instead of Capsman Forwarding ? If yes, may i ask why ?
Personally i use both modes but most of the time i use Capsman Forwarding...
by Zacharias
Sun Mar 13, 2022 7:46 pm
Forum: General
Topic: 2 ways to associate bridge and VLAN
Replies: 22
Views: 1294

Re: 2 ways to associate bridge and VLAN

@mkx, reading your post, i tried to visualize the Tagged and Untagged End...
If i understood correctly, you name Tagged end, the Interface used under /Interface VLAN ?
And Untagged End the IP address Interface ?
by Zacharias
Sun Mar 13, 2022 7:07 pm
Forum: RouterBOARD hardware
Topic: Rackmount kit for single RB5099
Replies: 1
Views: 296

Re: Rackmount kit for single RB5099

Can I use the one that mikrotik makes for a single rb5009?
I 've not yet used any RB5009 with a rack mount kit, but watching the Gallery photos https://mikrotik.com/product/rb5009_mou ... -downloads it seems that you can make any combination up to 4 RBs.
by Zacharias
Sun Mar 13, 2022 12:48 pm
Forum: Beginner Basics
Topic: MAC-Based-VLAN on HAP AC3
Replies: 2
Views: 214

Re: MAC-Based-VLAN on HAP AC3

HAP AC3 has an Atheros 8327 switch chip that supports 92 Switch Rules...
So there would be no problem configuring MAC based VLAN...
by Zacharias
Sun Mar 13, 2022 12:35 pm
Forum: The Dude
Topic: Dude Server Alternative?
Replies: 4
Views: 598

Re: Dude Server Alternative?

Take a look at this post from @jotne viewtopic.php?t=179960
Personally i use Dude and also Zabbix to monitor my Networks...
by Zacharias
Sun Mar 13, 2022 12:30 pm
Forum: Wireless Networking
Topic: cAP lite connect to cAP lite wireless [SOLVED]
Replies: 7
Views: 595

Re: cAP lite connect to cAP lite wireless [SOLVED]

Since Hap AC2 is already being used as an AP, then CAP must be configured as a Station-Bridge, the question is, do you need to still be using the CAP as an AP for other devices to connect on it wirelessly ? If yes, then you should create a Station-Bridge on the wireless interface of the CAP and then...
by Zacharias
Sun Mar 13, 2022 12:23 pm
Forum: General
Topic: IPSec-Tunnel to Cisco [SOLVED]
Replies: 8
Views: 427

Re: IPSec-Tunnel to Cisco [SOLVED]

Looks like it works. I now have 2 set and all good

Thanks!!!
Great...
You can mark the post as solved...

What unique actually does, is it creates a unique SA for each particular policy...
https://help.mikrotik.com/docs/display/ROS/IPsec
by Zacharias
Fri Mar 11, 2022 11:48 pm
Forum: Beginner Basics
Topic: Question about SFP optics
Replies: 3
Views: 332

Re: Question about SFP optics

@tdw seems to be right...
I checked it too and its 100Mbit...
by Zacharias
Fri Mar 11, 2022 11:30 pm
Forum: General
Topic: Bridge Firewall and Wireless lan controllers
Replies: 1
Views: 158

Re: Bridge Firewall and Wireless lan controllers

Maybe a diagram with your network topology and your configuration export with hide-sensitive parameter would help to understand better what the issue might be...
by Zacharias
Fri Mar 11, 2022 11:25 pm
Forum: General
Topic: 951Ui-2HnD not enabling 1000 Eth port?
Replies: 4
Views: 272

Re: 951Ui-2HnD not enabling 1000 Eth port?

it does offer the option tho in the OS
Features and options depend on the hardware being used...
by Zacharias
Fri Mar 11, 2022 11:18 pm
Forum: General
Topic: IPSec-Tunnel to Cisco [SOLVED]
Replies: 8
Views: 427

Re: IPSec-Tunnel to Cisco [SOLVED]

I guess there might be a problem with the SAs...
What if you set /ip ipsec policy level to unique for each policy ?
by Zacharias
Fri Mar 11, 2022 11:02 pm
Forum: General
Topic: IPSec-Tunnel to Cisco [SOLVED]
Replies: 8
Views: 427

Re: IPSec-Tunnel to Cisco [SOLVED]

I 've seen cases where when using multiple polices for the same peer some might not show as Active, but as soon as traffic is initiated they do become active...
But that is something different...

It does work when you disable a specific policy ?
by Zacharias
Fri Mar 11, 2022 10:47 pm
Forum: General
Topic: IPSec-Tunnel to Cisco [SOLVED]
Replies: 8
Views: 427

Re: IPSec-Tunnel to Cisco [SOLVED]

Did you try nat-traversal=yes ?
by Zacharias
Thu Mar 10, 2022 8:42 pm
Forum: Beginner Basics
Topic: Where does one buy the SIM cards...?
Replies: 11
Views: 631

Re: Where does one buy the SIM cards...?

I am not sure i understand the question...

I 've used a couple of LTE products, like WAP R, WAP R AC, LHGG LTE and LTAP LTE...
ALL are using standard SIM cards like the ones we are using on Mobile Phones... Never had any problem with the SIM cards...
by Zacharias
Wed Mar 09, 2022 11:18 pm
Forum: General
Topic: Nat and preservice public ip for a port
Replies: 8
Views: 390

Re: Nat and preservice public ip for a port

@Jotne i missed it, edited my previous post...

Also, in your case, the src-nat rule is not actually needed because you have a general masquerade rule... if you add it though, just place it before the masquerade one so that you can see it works ( packets counting )...
by Zacharias
Wed Mar 09, 2022 11:00 pm
Forum: RouterBOARD hardware
Topic: hAP2 Turned to Goo
Replies: 4
Views: 452

Re: hAP2 Turned to Goo

No, never...
by Zacharias
Wed Mar 09, 2022 10:56 pm
Forum: General
Topic: Nat and preservice public ip for a port
Replies: 8
Views: 390

Re: Nat and preservice public ip for a port

I want the above rule to work so inside to outside nat and nat to the sever1.
Since server2 is a web server, I like the webserver to see the public source IP, so that logging of usage would be correct.
Nat rules in post #2 is what you re asking for...
by Zacharias
Wed Mar 09, 2022 10:48 pm
Forum: General
Topic: Nat and preservice public ip for a port
Replies: 8
Views: 390

Re: Nat and preservice public ip for a port

You need src-nat and dst-nat rules... The first one, is used so that the server is src nated using the Public IP you want, and the later to dst-nat all the incoming traffic to that Public IP to the Server... /ip firewall nat add chain=srcnat src-address=x.y.z.w action=src-nat to-addresses=public_IP ...
by Zacharias
Wed Mar 09, 2022 10:20 pm
Forum: Wireless Networking
Topic: R11e-LTE6 modem firmware changelog
Replies: 12
Views: 5969

Re: R11e-LTE6 modem firmware changelog

Today i tried to upgrade again a WAP R with a R11e LTE6 modem card twice... Still i could not update, both times i was getting status failed when installing... I thought then that it might be due to some extra packages added consuming Ram and HDD resources... So i did remove them and left only the d...
by Zacharias
Wed Mar 09, 2022 10:16 am
Forum: Wireless Networking
Topic: R11e-LTE6 modem firmware changelog
Replies: 12
Views: 5969

Re: R11e-LTE6 modem firmware changelog

Last time i remember, i could not upgrade for some reason...
I think that was on V27...
by Zacharias
Tue Mar 08, 2022 11:24 pm
Forum: RouterOS beta and rc versions
Topic: RX Drops on SFP+
Replies: 15
Views: 1149

Re: RX Drops on SFP+

If it is fiber, also check if you use the correct SFP modules along with the Fiber type used...
by Zacharias
Tue Mar 08, 2022 11:10 pm
Forum: General
Topic: RouterOS downgrade to smaler version than the factory installed version
Replies: 7
Views: 389

Re: RouterOS downgrade to smaler version than the factory installed version

There is a difference between the firmware version (what is written in that article) and the RouterOS version (what I described). E.g. my RB4011 has minimum firmware 6.47.9 but minimum RouterOS 6.44.6 The article is clearly talking about Downgrading the RouterOS version... It also describes the ste...
by Zacharias
Tue Mar 08, 2022 9:12 pm
Forum: RouterOS beta and rc versions
Topic: RX Drops on SFP+
Replies: 15
Views: 1149

Re: RX Drops on SFP+

How are those SFP ports connected ?
Using a DAC or AOC cable ?
by Zacharias
Tue Mar 08, 2022 9:04 pm
Forum: RouterBOARD hardware
Topic: 5009 powering question
Replies: 19
Views: 2641

Re: 5009 powering question

Higher voltage has greater priority...
Read here viewtopic.php?t=153113#p756002
So i guess the same applies to RB5009...
by Zacharias
Tue Mar 08, 2022 11:35 am
Forum: RouterBOARD hardware
Topic: Defective WAP R
Replies: 4
Views: 454

Re: Defective WAP R

Netinstall is for specific situations and problems...
Just because you did not see it in your neighbors does not suggest a Netinstall...
Disable all your network cards except the ethernet that the WAP is connected to, disable your Antivirus and test again, this will help to identify the problem...
by Zacharias
Mon Mar 07, 2022 8:50 pm
Forum: RouterBOARD hardware
Topic: Defective WAP R
Replies: 4
Views: 454

Re: Defective WAP R

WAP R as you can see here https://mikrotik.com/product/RBwAPR-2nD does not include a modem... It has a mini PCI e slot so that you can use a modem of your choice...
So that is why you could not see an LTE interface...
by Zacharias
Mon Mar 07, 2022 7:54 pm
Forum: General
Topic: Switch rule rate not working on CS326
Replies: 2
Views: 295

Re: Switch rule rate not working on CS326

As i can see you do not use any specific MAC to apply that filter rule to... So obviously you need a Port based Traffic shaping. Can you instead try to apply a rate limit using /interface ethernet switch port menu ? Does it make any difference ? https://help.mikrotik.com/docs/display/ROS/CRS3xx%2C+C...
by Zacharias
Mon Mar 07, 2022 7:35 pm
Forum: Beginner Basics
Topic: QSFP Bonding
Replies: 14
Views: 747

Re: QSFP Bonding

Yes, maybe...
by Zacharias
Mon Mar 07, 2022 7:23 pm
Forum: Beginner Basics
Topic: Setting up RouterOS as a switch with RoaS
Replies: 28
Views: 1543

Re: Setting up RouterOS as a switch with RoaS

The way you have it configured, you should be able to access the Switch using Tagged Traffic with VLAN id 99 coming from ether1... If you want to test it using Untagged Access, you can as well change a PVID of a port to 99 and check if through that port you can access the Switch through its Manageme...
by Zacharias
Mon Mar 07, 2022 7:02 pm
Forum: Beginner Basics
Topic: QSFP Bonding
Replies: 14
Views: 747

Re: QSFP Bonding

Rate is 40Gbps. If rate is 40Gbps, then that's what interface can do ... not sure what you expect though ... Yes, but the question is why the physical interface is being shown as four different ones QSFP1-1,QSFP1-2,QSFP1-3 and QSFP1-4 ... Wouldn't it be more clear if it was shown as one single inte...
by Zacharias
Mon Mar 07, 2022 6:57 pm
Forum: General
Topic: RB5009 SFP+ Flapping on HP Switch
Replies: 5
Views: 443

Re: RB5009 SFP+ Flapping on HP Switch

@jbl42, VLANs 0 and 4095 are reserved and VLAN with id 1 is the default VLAN used by MikroTik and should not be used...
It is explained here https://en.wikipedia.org/wiki/IEEE_802.1Q
by Zacharias
Sat Mar 05, 2022 1:07 pm
Forum: RouterBOARD hardware
Topic: Omnitik 5 PoE ac disconnect issue
Replies: 10
Views: 2923

Re: Omnitik 5 PoE ac disconnect issue

I mentioned the Power supply check on post #3...
by Zacharias
Sat Mar 05, 2022 12:08 pm
Forum: Beginner Basics
Topic: QSFP Bonding
Replies: 14
Views: 747

Re: QSFP Bonding

Update to Latest ROS version, 6.49.4 and test again...
by Zacharias
Sat Mar 05, 2022 12:05 pm
Forum: General
Topic: RB5009 SFP+ Flapping on HP Switch
Replies: 5
Views: 443

Re: RB5009 SFP+ Flapping on HP Switch

Well, first i will comment on your configuration... VLAN-id=1 should not be used in your configuration... Read here : https://help.mikrotik.com/docs/display/ROS/VLAN " The IEEE 802.1Q standard has reserved VLAN IDs with special use cases, the following VLAN IDs should not be used in generic VLA...
by Zacharias
Sat Mar 05, 2022 11:48 am
Forum: Beginner Basics
Topic: QSFP Bonding
Replies: 14
Views: 747

Re: QSFP Bonding

Is there a bond created for QSFP1-1,QSFP1-2,QSFP1-3 and QSFP1-4 ? What is the negotiotaion Rate of the QSFP interface ? What is the module used ? Also on versions 6.49.x there are improvements on the CRS354 regrading the QSFP interfaces... Upgrade to latest V6 ( 6.49.4 ) and test again. https://mikr...
by Zacharias
Sat Mar 05, 2022 11:37 am
Forum: RouterBOARD hardware
Topic: ROAS+CRS+AP+VLANs [SOLVED]
Replies: 2
Views: 453

Re: ROAS+CRS+AP+VLANs [SOLVED]

Also, helpful articles : CapsMAN and VLANs: https://wiki.mikrotik.com/wiki/Manual:CAPsMAN_with_VLANs Bridge VLAN filtering and Management Access: https://help.mikrotik.com/docs/display/ROS/Bridge#Bridge-BridgeVLANFiltering Challenge: Big question is whether 'VLAN filtering' is needed to be "set...
by Zacharias
Sat Mar 05, 2022 11:22 am
Forum: Beginner Basics
Topic: QSFP Bonding
Replies: 14
Views: 747

Re: QSFP Bonding

What is the version running on the CRS354 ?
Can you please provide a screenshot of the interfaces after connecting the QSFP+ port on both sides ?
by Zacharias
Sat Mar 05, 2022 9:45 am
Forum: Beginner Basics
Topic: QSFP Bonding
Replies: 14
Views: 747

Re: QSFP Bonding

Read this post here viewtopic.php?t=151761#p747879 from @mkx
Its about a CRS326, but i guess tha same principle applies...
If you coneect that QSFP+ port to another QSFP+ port of another switch, can you still see the 4 QSFP Virtual Interfaces ? Or now it shows as one ?
by Zacharias
Fri Mar 04, 2022 9:08 pm
Forum: Beginner Basics
Topic: QSFP Bonding
Replies: 14
Views: 747

Re: QSFP Bonding

I 've not used CRS354 yet, however as i can see from the manual it has 2 QSFP+ ports...
You mention 8 ?
Do all of them should be slaves of a bond ?
No.
by Zacharias
Fri Mar 04, 2022 4:46 pm
Forum: RouterBOARD hardware
Topic: Omnitik 5 PoE ac disconnect issue
Replies: 10
Views: 2923

Re: Omnitik 5 PoE ac disconnect issue

Indeed the problem seems to be Hardware related.

However, i would netinstall the device to the latest version and then Test again.
by Zacharias
Fri Mar 04, 2022 4:38 pm
Forum: Beginner Basics
Topic: Setting up RouterOS as a switch with RoaS
Replies: 28
Views: 1543

Re: Setting up RouterOS as a switch with RoaS

To add to what @mkx said, since your Bridge PVID = 10, this means that only members of said VLAN ( 10 ) will be able to access the Switch.

My previous comment is indeed about the performance of the switch...
by Zacharias
Fri Mar 04, 2022 4:06 pm
Forum: Beginner Basics
Topic: Setting up RouterOS as a switch with RoaS
Replies: 28
Views: 1543

Re: Setting up RouterOS as a switch with RoaS

Both Atheros8327 & 8227 support VLANs in Hardware only using the Switch chip, /interface ethernet switch...
You have to configure the VLAN membership, your Trunk and Access Ports to the Switch menu...

Whatever configuration is done other than the above will be in Software ( CPU )...
by Zacharias
Thu Mar 03, 2022 8:38 pm
Forum: General
Topic: RB1100x4 with Bridge VLAN Filtering
Replies: 11
Views: 717

Re: RB1100x4 with Bridge VLAN Filtering

I agree @mkx... The fact that i needed the Bridge on the Router ( mostly ), is because there are multiple APs that are configured with CapsMan forwarding right now... Implementing Router on a Stick means that i will have to reconfigure the APs to Local forwarding... Its not a big deal but anyways......
by Zacharias
Wed Mar 02, 2022 11:35 pm
Forum: General
Topic: RB1100x4 with Bridge VLAN Filtering
Replies: 11
Views: 717

Re: RB1100x4 with Bridge VLAN Filtering

No am not talking about multiple bridges... You do not always need a bridge on your Router, example https://help.mikrotik.com/docs/display/ROS/Basic+VLAN+switching .. Looking at the photo, VLANs 20,30 and 99 can all be configured on an ethernet port of the Router e.g. /interface vlan add interface=e...
by Zacharias
Wed Mar 02, 2022 10:32 pm
Forum: General
Topic: RB1100x4 with Bridge VLAN Filtering
Replies: 11
Views: 717

Re: RB1100x4 with Bridge VLAN Filtering

What you can do in v6 is to configure VLANs on bridge ... and they'll be handled by CPU. When you decide that v7 is stable enough, same config will get a big performance boost. Yes you 're right @mkx... obviously the VLANs exist on that switch chip but for some reason can not be used on V6... I was...
by Zacharias
Wed Mar 02, 2022 7:48 pm
Forum: General
Topic: RB1100x4 with Bridge VLAN Filtering
Replies: 11
Views: 717

Re: RB1100x4 with Bridge VLAN Filtering

@mkx i am talking about RTL8367. Yes they are supported as long as you upgrade to ROS 7... The switch chip on V6 according to the manual does not support VLANs on hardware... https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features So unless i miss something on ROS v6 you cant use VLANs on the Swi...
by Zacharias
Wed Mar 02, 2022 12:36 pm
Forum: General
Topic: RB1100x4 with Bridge VLAN Filtering
Replies: 11
Views: 717

Re: RB1100x4 with Bridge VLAN Filtering

Does anyone know if RTL8367 has support added for VLANs on the Switch Chip ? The manual states that RTL8367 has no VLAN Table, so i can't use VLANs on the Switch in hardware. So actually Bridge Filtering and ROS 7 is the only option... However, here https://wiki.mikrotik.com/wiki/Manual:Basic_VLAN_s...
by Zacharias
Wed Mar 02, 2022 9:17 am
Forum: General
Topic: MikroTik CRS328-4C-20S-4S+ bonding to Cisco 2960S
Replies: 6
Views: 347

Re: MikroTik CRS328-4C-20S-4S+ bonding to Cisco 2960S

Using Source MAC address for EtherChannel Load Balancing on the Cisco appears to be the worst choice for your use case, and layer 2 on the Mikrotik is not great either.
Using Layer2 is not wrong at all...
Most effective would be Layer2+Layer3...
by Zacharias
Tue Mar 01, 2022 8:45 pm
Forum: General
Topic: MikroTik CRS328-4C-20S-4S+ bonding to Cisco 2960S
Replies: 6
Views: 347

Re: MikroTik CRS328-4C-20S-4S+ bonding to Cisco 2960S

802.3ad does not split connections !!!
All traffic that belongs to a single connection will always use the same link... That's how it works...
by Zacharias
Tue Mar 01, 2022 8:29 pm
Forum: RouterBOARD hardware
Topic: Omnitik 5 PoE ac disconnect issue
Replies: 10
Views: 2923

Re: Omnitik 5 PoE ac disconnect issue

I would say the problems are related to Layer 1, e.g. UTP cable, connectors etc
After that i would check the PSU...

But if i understood correctly you have tried all the above...
What is your ROS version?
Are those devices the only equipment in the network ?
What is the overall network topology ?
by Zacharias
Mon Feb 28, 2022 9:04 am
Forum: Wireless Networking
Topic: sxt5 and connect on my router
Replies: 12
Views: 668

Re: sxt5 and connect on my router

station-pseudobridge should work just fine...
by Zacharias
Sun Feb 27, 2022 8:16 pm
Forum: General
Topic: CCR1036-8G-2S+ all pppoe disconect every 3-4 days
Replies: 21
Views: 1238

Re: CCR1036-8G-2S+ all pppoe disconect every 3-4 days

Did you try to netinstall the device and configure again ?
No , do you think that will do any change ?
You can give it a try...
Netinstall to the long-term version...
by Zacharias
Sun Feb 27, 2022 8:12 pm
Forum: Wireless Networking
Topic: sxt5 and connect on my router
Replies: 12
Views: 668

Re: sxt5 and connect on my router

The router, is it a MikroTik ?
by Zacharias
Sat Feb 26, 2022 9:41 pm
Forum: General
Topic: CCR1036-8G-2S+ all pppoe disconect every 3-4 days
Replies: 21
Views: 1238

Re: CCR1036-8G-2S+ all pppoe disconect every 3-4 days

Did you try to netinstall the device and configure again ?
by Zacharias
Sat Feb 26, 2022 8:00 pm
Forum: Wireless Networking
Topic: sxt5 and connect on my router
Replies: 12
Views: 668

Re: sxt5 and connect on my router

Am not really sure i understand
Can you provide a simple network topology diagram so that i can understand what is the configuration needed ?
by Zacharias
Sat Feb 26, 2022 7:57 pm
Forum: General
Topic: RB1100x4 with Bridge VLAN Filtering
Replies: 11
Views: 717

Re: RB1100x4 with Bridge VLAN Filtering

@Znevna you' re right... Since its a router in a production environment, i am not really sure if its better to upgrade it to ROS 7 or keep ROS v6 without HW offload on the Bridge... That is why i am asking, what is the load added to the device if we enable Bridge VLAN filtering handled by the CPU......
by Zacharias
Sat Feb 26, 2022 11:55 am
Forum: General
Topic: RB1100x4 with Bridge VLAN Filtering
Replies: 11
Views: 717

RB1100x4 with Bridge VLAN Filtering

Hey everyone,

Just wondering, what would be the performance of RB1100 with Bridge VLAN filtering enabled ? Of course i know that the filtering can not be done in hardware in that model.
So has anyone tested the amount of performance drop in that particular model ?

Thanks...
by Zacharias
Sat Feb 26, 2022 11:48 am
Forum: Wireless Networking
Topic: sxt5 and connect on my router
Replies: 12
Views: 668

Re: sxt5 and connect on my router

If your purpose is only access to the Internet, remove wlan1 from your Bridge and use mode Station. Add DHCP-Client on your wlan interface and masquerade it... Then assign an IP address to your Bridge and create a DHCP server on it using a different subnet... Of course that way there is no Layer 2 B...
by Zacharias
Thu Feb 24, 2022 8:44 pm
Forum: Wireless Networking
Topic: sxt5 and connect on my router
Replies: 12
Views: 668

Re: sxt5 and connect on my router

You could \export hide-sensitive file=any-name ...
by Zacharias
Wed Feb 23, 2022 8:44 pm
Forum: General
Topic: How to mangle packets on CRS112
Replies: 3
Views: 306

Re: How to mangle packets on CRS112

That is correct... You need to enable the IP firewall in the Bridge Settings and disable hardware offload... Sure the performance will not be good... CRS112 is a switch... If you need to process packets, apply queues etc. you should get a Router... https://mikrotik.com/products/group/ethernet-router...
by Zacharias
Wed Feb 23, 2022 7:53 pm
Forum: Announcements
Topic: WinBox v3.35 released!
Replies: 95
Views: 36915

Re: WinBox v3.35 released!

Indeed, i can see the hint too...
by Zacharias
Wed Feb 23, 2022 7:24 pm
Forum: Wireless Networking
Topic: SIM NOT INSERTED
Replies: 14
Views: 4723

Re: SIM NOT INSERTED

I do use LTE devices, some of them are WAP both with LTE and LTE6 cards, LHG, WAP AC etc... From my experience you have to carefully place the card in the SIM slot... Sometimes, especially when an adapter is used, it might be a little more difficult to place it in position. Maybe if you applied extr...
by Zacharias
Wed Feb 23, 2022 7:15 pm
Forum: Wireless Networking
Topic: sxt5 and connect on my router
Replies: 12
Views: 668

Re: sxt5 and connect on my router

Do you mean that the SXT is wirelessly connected to another vendors WiFi ?
If yes then only modes Station and Station Pseudobridge can be used.
The differences on those modes can be found here : https://wiki.mikrotik.com/wiki/Manual:W ... tion_Modes
by Zacharias
Wed Feb 23, 2022 6:17 pm
Forum: Announcements
Topic: WinBox v3.35 released!
Replies: 95
Views: 36915

Re: WinBox v3.35 released!

@SiB, honestly i did not know that if you let the mouse on the CIDR then a hint appears showing the addresses available...
Since when does this exist ?
by Zacharias
Wed Feb 23, 2022 2:54 pm
Forum: Announcements
Topic: WinBox v3.35 released!
Replies: 95
Views: 36915

Re: WinBox v3.35 released!

@pe1chl i tried to reproduce this issue with no success...
Can you give an example of winbox hanging after a copy/paste ?
by Zacharias
Mon Feb 21, 2022 9:23 pm
Forum: Announcements
Topic: WinBox v3.35 released!
Replies: 95
Views: 36915

Re: WinBox v3.35 released!

Thank you, but it still doesn't work properly. When connecting in a new window, Winbox takes about 20 seconds to spawn the new window. Before 3.33 everything worked properly instantly.
Works fine for me...

@ pe1chl did you notice anything as far as the order of rules is concerned ?
by Zacharias
Sun Feb 20, 2022 8:17 pm
Forum: Announcements
Topic: WinBox v3.33 and v3.34 released!
Replies: 115
Views: 15223

Re: WinBox v3.33 and v3.34 released!

I had a similar problem as @pe1chl described, not with firewall rules but with the CapsMan access list... i was testing an access list on a lab environment, and i did change the position of some rules several times... There was a moment that i noticed that some rules were not on the position i had p...
by Zacharias
Sun Feb 20, 2022 8:01 pm
Forum: General
Topic: IP on Bridge for Multicast snooping?
Replies: 13
Views: 810

Re: IP on Bridge for Multicast snooping?

Take a look at the example here https://help.mikrotik.com/docs/pages/viewpage.action?pageId=59277403#BridgeIGMP/MLDsnooping-IGMPsnoopingconfigurationwithVLANs As you can see, the only IP address assigned is to the Management VLAN, that each switch has for management purposes... Other than that, the ...
by Zacharias
Fri Feb 18, 2022 8:15 pm
Forum: General
Topic: mAP & mAP lite: The Wireless Swiss Knife Always in Your Pocket
Replies: 12
Views: 741

Re: mAP & mAP lite: The Wireless Swiss Knife Always in Your Pocket

yes, thank you, i already set this 2 modes and they are working. only for the mybridge wlan i have no clue how to solve this...
What about it ?
by Zacharias
Fri Feb 18, 2022 8:09 pm
Forum: General
Topic: IP on Bridge for Multicast snooping?
Replies: 13
Views: 810

Re: IP on Bridge for Multicast snooping?

No.
by Zacharias
Fri Feb 18, 2022 8:00 pm
Forum: General
Topic: IP on Bridge for Multicast snooping?
Replies: 13
Views: 810

Re: IP on Bridge for Multicast snooping?

Multicast communication uses the Multicast address space...
Your SetTop-Box should have either an IP or a multicast one, it depends.
by Zacharias
Fri Feb 18, 2022 7:45 pm
Forum: General
Topic: mAP & mAP lite: The Wireless Swiss Knife Always in Your Pocket
Replies: 12
Views: 741

Re: mAP & mAP lite: The Wireless Swiss Knife Always in Your Pocket

Mode station, so that you can connect to e.g. the Hotels AP.
And mode AP Bridge on the virtual interface, so that you can connect e.g. your Laptop.
by Zacharias
Fri Feb 18, 2022 7:18 pm
Forum: General
Topic: Push same traffic to different devices
Replies: 13
Views: 647

Re: Push same traffic to different devices

@tangent you 're right...
I missed that...
by Zacharias
Fri Feb 18, 2022 7:09 pm
Forum: General
Topic: Push same traffic to different devices
Replies: 13
Views: 647

Re: Push same traffic to different devices

@msatter, maybe using Multicast Routing ?
Have you searched for PIM ? It is a multicast routing protocol.

Hope that helps...
by Zacharias
Fri Feb 18, 2022 7:02 pm
Forum: Beginner Basics
Topic: Bridge mode (route WAN access directly to LAN port)
Replies: 6
Views: 459

Re: Bridge mode (route WAN access directly to LAN port)

Yes you can...
Notice though, that the LTE device will not have Internet itself from the time that passthrough will be enabled.
You will have to configure a default route and a DNS server pointing at your router.
by Zacharias
Fri Feb 18, 2022 6:56 pm
Forum: General
Topic: CCR1036-8G-2S+ all pppoe disconect every 3-4 days
Replies: 21
Views: 1238

Re: CCR1036-8G-2S+ all pppoe disconect every 3-4 days

My suggestion is an external SNMP monitor...

It is better to use a remote syslog server to collect your logs...
system logging add topics=pppoe,debug action=remote 
by Zacharias
Thu Feb 17, 2022 9:26 pm
Forum: General
Topic: CCR1036-8G-2S+ all pppoe disconect every 3-4 days
Replies: 21
Views: 1238

Re: CCR1036-8G-2S+ all pppoe disconect every 3-4 days

Anything in the Log ? Did you try enabling debug && PPPoE in the logs to see if you get any information ? Or maybe it would be best if you monitored your router with an SNMP Software and collect valuable info such as CPU, Memory utilization etc. so that you can see the Router's status at the...
by Zacharias
Thu Feb 17, 2022 8:16 pm
Forum: General
Topic: mark routing not working if there is not default route
Replies: 1
Views: 188

Re: mark routing not working if there is not default route

That is correct... When the packets enter the Router, they are marked with a connection mark in the prerouting chain, then routing takes place ( according to the mark ) and the packets reach their destination. However, when the router tries to reply back, and here we' re talking about the Output cha...
by Zacharias
Thu Feb 17, 2022 7:55 pm
Forum: General
Topic: CCR1036-8G-2S+ all pppoe disconect every 3-4 days
Replies: 21
Views: 1238

Re: CCR1036-8G-2S+ all pppoe disconect every 3-4 days

All at the same time ?
So your CCR acts as a PPPoE server ?
  • 1
  • 2
  • 3
  • 4
  • 5
  • 12