Community discussions

MikroTik App

Search found 18381 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 62
by anav
Mon Dec 11, 2023 9:48 pm
Forum: General
Topic: Couldn't change the SSTP server can't bind, check if the port is not used by other services!
Replies: 1
Views: 84

Re: Couldn't change the SSTP server can't bind, check if the port is not used by other services!

No one believes opinion, evidence is provided by the config,
/export file=anynamewyouwish ( minus router serial number, any pubic WANIP information etc...)
by anav
Mon Dec 11, 2023 9:32 pm
Forum: Beginner Basics
Topic: Mikrotik Failover
Replies: 3
Views: 321

Re: Mikrotik Failover

Apparently you can use the pppoe-interface name in your routes and that will pick up changes in gateway IP and thus a script is not needed only for the IP DHCP client.
by anav
Mon Dec 11, 2023 9:21 pm
Forum: Beginner Basics
Topic: using hAP ax lite to extend existing network
Replies: 3
Views: 319

Re: using hAP ax lite to extend existing network

If not using capsman, then this is the correct link Holvoe........ viewtopic.php?t=182276
by anav
Mon Dec 11, 2023 9:18 pm
Forum: General
Topic: Can't access device on management VLAN remotely via Wireguard
Replies: 1
Views: 82

Re: Can't access device on management VLAN remotely via Wireguard

(1) This makes me ponder....... /ip address add address= 192.168.20.1 /28 interface=VLAN_1_VLAN network=192.168.20.0 add address= 192.168.30.1 /24 interface=VLAN_2_VLAN network=192.168.30.0 add address= 192.168.10.1 /29 interface=MGMT_VLAN network=192.168.10.0 add address=10.0.8.7/24 interface=wireg...
by anav
Mon Dec 11, 2023 6:20 pm
Forum: Scripting
Topic: Script run in another script
Replies: 3
Views: 149

Re: Script run in another script

This reminds me of the monty python sketch, "the lost world of Roiurama" but the best part of the skit is........ who is filming us now??

https://www.youtube.com/watch?v=rX2rHJg30xA
by anav
Mon Dec 11, 2023 6:14 pm
Forum: General
Topic: Routing Filter ROS v7
Replies: 3
Views: 481

Re: Routing Filter ROS v7

Why are you asking about routing tables when the title of the thread is Routing Filter, get your story straight.

/routing table add fib name=anynamewilldo
by anav
Mon Dec 11, 2023 6:03 pm
Forum: Beginner Basics
Topic: Back to home supported router
Replies: 28
Views: 997

Re: Back to home supported router

Hi Normis, 1. As an admin or helper admin, I can go to the local site and quickly setup a vpn connection which I can use later when remote. 2. What about the opposite, I want to send my brother the ability to connect to my MT wireguard router a. from his device directly (no mt router), be it windows...
by anav
Mon Dec 11, 2023 5:04 pm
Forum: Beginner Basics
Topic: Back to home supported router
Replies: 28
Views: 997

Re: Back to home supported router

Much thanks Normis, its slowly getting clearer. Basically the process is a. at home or office router setup BTH. b. then any user can connect to this VPN c. if the BTH is using a public IP, no relay service is used d. If the BTH is used behind a cgnat or non port forwarding capable ISP, then relay se...
by anav
Mon Dec 11, 2023 4:31 pm
Forum: General
Topic: Route specific site traffic through wan2
Replies: 3
Views: 169

Re: Route specific site traffic through wan2

Fixed my post so it was clearer
by anav
Mon Dec 11, 2023 4:29 pm
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 97
Views: 7855

Re: Multi-WAN Load Balancing Starlink issue

Way ahead of me gotsprings. I am thinking of using a CHR cloud router and connecting a ground site to it via multiple ISPs Then using L2TP plain over transparent wireguard to connect the ground site to the CHR ( L2Tp allows mrru adjustment for packet fragmentation). THEN using OSPF and BFD to monito...
by anav
Mon Dec 11, 2023 4:25 pm
Forum: Beginner Basics
Topic: RBD53iG WiFi and VLAN
Replies: 2
Views: 117

Re: RBD53iG WiFi and VLAN

Looks like your attempting to add this as an AP/switch to an existing MT or other router.....

viewtopic.php?t=182276
by anav
Mon Dec 11, 2023 3:16 pm
Forum: General
Topic: Difficulties with VLAN setup -- help requested
Replies: 7
Views: 543

Re: Difficulties with VLAN setup -- help requested

(1) This rule is no longer required in the input chain.......... add action=drop chain=input comment="defconf: drop all not coming from LAN" \ in-interface-list=!LAN (2) You made the same error in the forward chain, you DIDNT get rid of the old rule that we replaced. Get rid of it!! add ac...
by anav
Mon Dec 11, 2023 3:14 pm
Forum: General
Topic: WireGuard access
Replies: 13
Views: 854

Re: WireGuard access

Why dont you pull the crystall ball out of your ass then and provide the config on the MT router please.
/export file=anynameyouwish ( minus router serial number, any public WANIP information, keys etc.)
by anav
Mon Dec 11, 2023 3:10 pm
Forum: General
Topic: Bridge all ports on hAP AX^2
Replies: 7
Views: 406

Re: Bridge all ports on hAP AX^2

Why would you want to bridge all ports............... That is not a requirement its an attempt, maybe legit, or maybe wrong, to design a config for some reason. We care about the reason because the WHOLE CONFIG is often integrated and thus having the complete picture helps point towards development ...
by anav
Mon Dec 11, 2023 3:06 pm
Forum: General
Topic: Route specific site traffic through wan2
Replies: 3
Views: 169

Re: Route specific site traffic through wan2

1. If its a fixed IP you can use either routing rules or mangling. 2. What version of RoS are you using?? MANGLE For vers6 as you have done...... /ip firewall mangle add chain=prerouting dst-address=example.com action=mark-routing new-routing-mark=example_route /ip route add dst-address=0.0.0.0/0 ga...
by anav
Mon Dec 11, 2023 2:57 pm
Forum: Beginner Basics
Topic: WG handshake drops !!
Replies: 4
Views: 263

Re: WG handshake drops !!

(1) Why the duplicate?? Interface] PrivateKey = ------------------------------- Address = 10.10.10.3/32 [Peer] PublicKey = ----------------------------------------- AllowedIPs = 10.10.10.0/24 , 10.10.0.0/24 , 172.16.10.0/22 Endpoint = DDNS:13231 PersistentKeepalive = 25 2. Please provide a diagram b...
by anav
Mon Dec 11, 2023 2:38 pm
Forum: Beginner Basics
Topic: Back to home supported router
Replies: 28
Views: 997

Re: Back to home supported router

Dear Sir Holvoe, I have written many times of MTs unwritten agenda to move all users to newer ARM products, its called the 'obsolescence - death by 1000 cuts product strategy' Just so I can get this straight the difference then between BTH and normal wireguard, and the power/allure of BTH, is that M...
by anav
Mon Dec 11, 2023 5:37 am
Forum: Beginner Basics
Topic: Forwarding
Replies: 1
Views: 140

Re: Forwarding

Yes, setup a VPN network on the fortigate and seek advice on a fortigate forum. Once you have all the information and setup complete on the other router. Modify the configs on the MT routers with the correct parameters. https://help.mikrotik.com/docs/display/ROS/IPsec Search on Youtube, seem to be m...
by anav
Mon Dec 11, 2023 5:34 am
Forum: Beginner Basics
Topic: Back to home supported router
Replies: 28
Views: 997

Re: Back to home supported router

Dont forget the other question,
a. do you have a public IP
b. IF NOT, can you forward a port from your ISP modem/router to your ROUTER.
by anav
Mon Dec 11, 2023 5:21 am
Forum: General
Topic: Difficulties with VLAN setup -- help requested
Replies: 7
Views: 543

Re: Difficulties with VLAN setup -- help requested

(1) It makes zero sense to send a hybrid port to a managed switch. Get off the drugs! All vlans should be tagged to the managed switch on the trunk port. /interface bridge port add bridge=vlan-bridge comment=defconf interface=ether2 ingress-filtering=yes frame-types=admit-only-vlan-tagged add bridge...
by anav
Sun Dec 10, 2023 11:20 pm
Forum: General
Topic: Bridge all ports on hAP AX^2
Replies: 7
Views: 406

Re: Bridge all ports on hAP AX^2

I really thing asking about adding stuff to a bridge is the WRONG WAY to think. Instead a. identify all user(s)/device(s) / groups of users/devices including the admin b. identify all the traffic the above users/devices require to accomplish. Draw a network diagram of the plan, detailing where the m...
by anav
Sun Dec 10, 2023 11:16 pm
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 40
Views: 3718

Re: Firewall - DNS Open? - Urgent [SOLVED]

Okay got it, The MAIN ROUTER acts as the server for handshakes on TWO separate wireguard networks. It connects to two other routers acting as clients which initiate the handshake. Once connected the wireguard network is established between routers, users from all devices behind the routers, should b...
by anav
Sun Dec 10, 2023 10:54 pm
Forum: Beginner Basics
Topic: Back to home supported router
Replies: 28
Views: 997

Re: Back to home supported router

BTH is not the only way to apply wireguard parameters silly ammo!
by anav
Sun Dec 10, 2023 9:47 pm
Forum: Beginner Basics
Topic: Back to home supported router
Replies: 28
Views: 997

Re: Back to home supported router

Sure the 750 supports wireguard what seems to be the issue?
by anav
Sun Dec 10, 2023 8:06 pm
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 40
Views: 3718

Re: Firewall - DNS Open? - Urgent [SOLVED]

I need a diagram to make sense of what your saying.........
by anav
Sun Dec 10, 2023 8:05 pm
Forum: General
Topic: Multi WAN and port forwarding
Replies: 12
Views: 617

Re: Multi WAN and port forwarding

Would have to see the latest config to investigate..........
by anav
Sun Dec 10, 2023 7:09 pm
Forum: Beginner Basics
Topic: Mikrotik Router has the connectivity problem.
Replies: 1
Views: 175

Re: Mikrotik Router has the connectivity problem.

Clearly there is a problem on the config, but I cannot quite put my finger on it. Try anything. Try nothing, maybe like magic it will fix itself. House owner to plumber: I turned on the knob and no water is coming out. Please tell me how to fix it. Plumber: Did you pay your water bill? :-) Plumber: ...
by anav
Sun Dec 10, 2023 7:06 pm
Forum: Beginner Basics
Topic: WG handshake drops !!
Replies: 4
Views: 263

Re: WG handshake drops !!

I dont like to suspect, guess or speculate. I am not an investor! ;-PP

Please provide facts/evidence
/export file=anynameyouwish ( minus router serial number, public WANIP information, keys etc.... )

Additionally, the client devices wireguard settings would be necessary to review.
by anav
Sun Dec 10, 2023 7:05 pm
Forum: General
Topic: Conflict by ICMP Response
Replies: 9
Views: 498

Re: Conflict by ICMP Response

COP28, oh you mean Continue Oil Production 28!
by anav
Sun Dec 10, 2023 5:43 pm
Forum: Useful user articles
Topic: New User Pathway To Config Success
Replies: 69
Views: 46759

Re: New User Pathway To Config Success

Hope this rewrite make more sense for you!! J2. ENSURING Same WAN for Return Traffic { no mangling } A common problem can occur in multi-wan setups. External traffic to the router ( such as wireguard handshake ) may enter via one ISP and depending upon the configuration on the router, exit a differe...
by anav
Sun Dec 10, 2023 5:13 pm
Forum: General
Topic: Wireguard Stopped After Upgrade
Replies: 3
Views: 645

Re: Wireguard Stopped After Upgrade

Without seeing your config, its merely an opinion based on no evidence!!

/export file=anynameyouwish ( minus router serial number, public WANIP information, keys etc.... )
by anav
Sun Dec 10, 2023 4:57 pm
Forum: General
Topic: DHCP Problem for static IPs [SOLVED]
Replies: 6
Views: 340

Re: DHCP Problem for static IPs [SOLVED]

Very confusing why do you have this flow:
internet --->MT ROUTER---> drayket modem ---> network
IT should be
internet--->draytek modem ---> L009 ----> network

????
by anav
Sun Dec 10, 2023 4:53 pm
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 40
Views: 3718

Re: Firewall - DNS Open? - Urgent [SOLVED]

You really need to provide a network diagram as the description is too confusing.
by anav
Sun Dec 10, 2023 4:50 pm
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 40
Views: 3718

Re: Firewall - DNS Open? - Urgent [SOLVED]

This statement is problematic........... The WIREGUARD_IT01 = VPN from the customer to us, via site to site. There should be server and client on both sides. Should I assume you mean, that the customer are clients connecting to your WIreguard Server? The other site cannot be a client and server for ...
by anav
Sun Dec 10, 2023 3:42 am
Forum: Beginner Basics
Topic: Blocking DNS traffic
Replies: 6
Views: 499

Re: Blocking DNS traffic

Yup, it makes me cringe when I see people deviate from the defaults and dont know what they are doing. (1) Why in gods earth would you allow port 80 to the router from the internet side. I would guess that using ether1 probably wont work as traffic is actually via the interface name in pppoe. (2) Th...
by anav
Sat Dec 09, 2023 10:36 pm
Forum: Beginner Basics
Topic: Blocking DNS traffic
Replies: 6
Views: 499

Re: Blocking DNS traffic

/export file=anynameyouwish ( minus router serial number, any public WANIP information, keys, etc.. )
by anav
Sat Dec 09, 2023 9:40 pm
Forum: General
Topic: [Help] Portable travel router with VPN configuration - HAP ac2
Replies: 4
Views: 655

Re: [Help] Portable travel router with VPN configuration - HAP ac2

What have you done so far?
Have you ever configged an MT router?
by anav
Sat Dec 09, 2023 9:38 pm
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 40
Views: 3718

Re: Firewall - DNS Open? - Urgent [SOLVED]

I asked you repeatedly for more details but you have not provided them. Posts #28/29 which follows on questions on WG from post #20.
by anav
Sat Dec 09, 2023 9:27 pm
Forum: General
Topic: Multi WAN and port forwarding
Replies: 12
Views: 617

Re: Multi WAN and port forwarding

Mangles for 4 WAN PCC - 12 additional tables, 12 pcc mangles, 24 routes. The concept being that each table is getting 1/12 of the traffic and each WAN has 3 tables associated with it. So each WAN is getting 1/4 of the traffic which makes sense as we have four WANs in PCC. Thus when lets say WAN2 fai...
by anav
Sat Dec 09, 2023 8:42 pm
Forum: General
Topic: Multi WAN and port forwarding
Replies: 12
Views: 617

Re: Multi WAN and port forwarding

/routing table add fib name=useWan1 add fib name=useWan2 add fib name=useWan3 add fib name=useWan4 add fib name=useWan5 /ip firewall mangle { to ensure local traffic to the router is processed before any other mangle rules } add action=accept chain=prerouting in-interface-list=LAN-list dst-address-t...
by anav
Sat Dec 09, 2023 6:56 pm
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 40
Views: 3718

Re: Firewall - DNS Open? - Urgent [SOLVED]

For wireguard read this............
viewtopic.php?t=182340
by anav
Sat Dec 09, 2023 6:49 pm
Forum: General
Topic: HELP - Unable to connect WireGuard when WAN is Public IP
Replies: 4
Views: 308

Re: HELP - Unable to connect WireGuard when WAN is Public IP

8. Your sourcenat rule does not define an out interface and Its not clear to me why you are delineating any source addresses??? /ip firewall nat add action=masquerade chain=srcnat comment="defconf: masquerade" \ src-address-list="All IP" Why not: add action=masquerade chain=srcna...
by anav
Sat Dec 09, 2023 6:33 pm
Forum: General
Topic: HELP - Unable to connect WireGuard when WAN is Public IP
Replies: 4
Views: 308

Re: HELP - Unable to connect WireGuard when WAN is Public IP

1. add the surfshark interface to the WAN list, not the LAN list. There is no incoming traffic to your LAN and thus not appropriate. However, all the users going surfshark from your LAN need to be sourcenatted to the single surfshark IP address you have been given ( per connection, aka separate priv...
by anav
Sat Dec 09, 2023 6:30 pm
Forum: General
Topic: Difficulties with VLAN setup -- help requested
Replies: 7
Views: 543

Re: Difficulties with VLAN setup -- help requested

If afraid of getting kicked by vlan-filtering=yes........ you have a valid concern,, what I do is take an unused port and stick an IP address on it and do all my initial configuring from there safely. https://forum.mikrotik.com/viewtopic.php?t=181718 As to the other points.... 4. Incorrect, the swit...
by anav
Sat Dec 09, 2023 6:17 pm
Forum: Beginner Basics
Topic: InterVLAN routing & ICMP (no response found!)
Replies: 4
Views: 418

Re: InterVLAN routing & ICMP (no response found!)

Interrupt away LOL. To the OP. it not a matter of deciding how to config it, its you getting clarity on the requirements. a. Identify all the user(s)/device(s) and groups of users/devices including the admin b. Identify all the traffic the above users and devices need to execute. With that clarity a...
by anav
Sat Dec 09, 2023 4:07 pm
Forum: General
Topic: New ROuter suggestion please
Replies: 13
Views: 793

Re: New ROuter suggestion please

Zach, you are indeed correct for 2/3 models of 2004, unfortunately I grabbed the one to compare which has a CPU frequency of 1.2 GHz ( Amazon Annapurna Labs Alpine v2 CPU with 4x 64-bit ARMv8-A Cortex-A57 cores. While this CPU is running at 1.2 GHz, the router can be 3x as fast than the previous gen...
by anav
Sat Dec 09, 2023 3:38 pm
Forum: General
Topic: New ROuter suggestion please
Replies: 13
Views: 793

Re: New ROuter suggestion please

When they changed from vers6 to vers7 many of the existing older routers throughput was reduced significantly.
by anav
Sat Dec 09, 2023 4:20 am
Forum: General
Topic: Difficulties with VLAN setup -- help requested
Replies: 7
Views: 543

Re: Difficulties with VLAN setup -- help requested

(1) Turn on vlan-filtering=yes (2) WHY DO YOU HAVE A mgm-vlan bridge??? GET RID OF THIS, its not needed. (3) WHAT THE HECK is the comment here add name=dhcp_pool2 ranges=" ISP provided wan IP" What does internal LAN or VLAN pool have anything to do with the WAN side ????????????? Why are t...
by anav
Sat Dec 09, 2023 3:57 am
Forum: General
Topic: Multi WAN and port forwarding
Replies: 12
Views: 617

Re: Multi WAN and port forwarding

Okay so basically WAN1 not included in PCC. WANS 2-5 PCC. Does each WAN (in 2 thru 5 ) have basically the same throughput? Are the WANS 2-5 from the same provider? The reason I ask is that if there is an issue with a provider it is likely that all internet from that provider will not be available. O...
by anav
Sat Dec 09, 2023 1:30 am
Forum: General
Topic: Multi WAN and port forwarding
Replies: 12
Views: 617

Re: Multi WAN and port forwarding

I dont care about the config first, I care about the requirements. What is your intent with the WANS.................. Do you want user to be able to share all the available WANS? Do you want some subnets to use only WANS. If you dont know what your plan is, I am not going to waste time helping a mo...
by anav
Sat Dec 09, 2023 1:27 am
Forum: General
Topic: WireGuard - can't get to the LAN devices
Replies: 4
Views: 398

Re: WireGuard - can't get to the LAN devices

There is something wrong with your MT peer settings. /interface wireguard peers add allowed-address=192.168.100.0/24,192.168.146.0/24 client-address=\ 192.168.100.2/32 client-dns=1.1.1.1 interface=wireguard1 public-key=\ "-------------------------------------------=" As far as I know there...
by anav
Sat Dec 09, 2023 1:11 am
Forum: General
Topic: interface is slave
Replies: 5
Views: 4583

Re: interface is slave

Your firmware is getting dated.
by anav
Fri Dec 08, 2023 11:35 pm
Forum: Useful user articles
Topic: HOTSPOT
Replies: 1
Views: 380

Re: HOTSPOT

Why do you ask this question in a forum that is designed to point out useful information for folks. " USEFUL USER ARTICLE" Try beginner or general. Did you search hotspot in the search window? Did you search hotspot in youtube "Mikrotik hotspot" Did you check out MT documents? ht...
by anav
Fri Dec 08, 2023 11:19 pm
Forum: General
Topic: Trying to get communication between vLAN Interfaces
Replies: 6
Views: 397

Re: Trying to get communication between vLAN Interfaces

Note that if you want to allow any traffic from vlanX to vlanY it would go here on the above config ************************************** For example: /ip firewall address-list ( using static DHCP leases!! ) add address=user1-IP-address =PERMITTED comment="user1 to vlan301" add address=us...
by anav
Fri Dec 08, 2023 11:06 pm
Forum: General
Topic: Trying to get communication between vLAN Interfaces
Replies: 6
Views: 397

Re: Trying to get communication between vLAN Interfaces

Do not understand?? You have two vlans, WTF is this.......... add address=10.201.1.1/24 interface=ProductionNetwork network=10.201.1.0 add address=10.201.2.1/24 interface=vlan2-TheMiddle network=10.201.2.0 add address=10.201.131.0/24 interface=vlan301-AJPT_QLAN network=10.201.131.0 You have no DHCP ...
by anav
Fri Dec 08, 2023 11:04 pm
Forum: General
Topic: Trying to get communication between vLAN Interfaces
Replies: 6
Views: 397

Re: Trying to get communication between vLAN Interfaces

Thus it should look like this and can be shortened too. /interface bridge vlan add bridge=bridge1 tagged=bridge1,ProductionNetwork vlan-ids=2,301 You have an empty list member entry and should remove it... /interface list member add interface=ProductionNetwork list=WAN add list=LAN add interface=vla...
by anav
Fri Dec 08, 2023 11:04 pm
Forum: General
Topic: Trying to get communication between vLAN Interfaces
Replies: 6
Views: 397

Re: Trying to get communication between vLAN Interfaces

Please show me in any of the configs from the link this line, I think you made it up, eating magic mushrooms???

add bridge=bridge1 untagged=bridge1,ProductionNetwork vlan-ids=1
by anav
Fri Dec 08, 2023 10:59 pm
Forum: General
Topic: Multi WAN and port forwarding
Replies: 12
Views: 617

Re: Multi WAN and port forwarding

WHY DID YOU FAIL TO MENTION YOU ARE ALSO DOING PCC for your LAN??
Do you not think that is important to know? So its not just port fowarding here.

What is your failover plan for PCC????
by anav
Fri Dec 08, 2023 10:47 pm
Forum: Beginner Basics
Topic: Multiple interfaces per vlan and multiple vlans per interface
Replies: 2
Views: 294

Re: Multiple interfaces per vlan and multiple vlans per interface

Two things. 1. Forget config speak if you want to talk requirements. a. identify all user(s)/device(s) and groups of users and devices, including the admin. b. identify all traffic they are supposed to have... Provide your config so far /export file=anynameyouwish (minus router serial number, public...
by anav
Fri Dec 08, 2023 6:46 pm
Forum: Beginner Basics
Topic: InterVLAN routing & ICMP (no response found!)
Replies: 4
Views: 418

Re: InterVLAN routing & ICMP (no response found!)

Why do you have a LANPOOL?? Why are you using bridge filters?? This bridge port makes no sense, you set it up as an access port with pvid ( or even a hybrid port ) and yet limit traffic to vlans.................. illogical!! /interface bridge port add bridge=bridge frame-types= admit-only-vlan-tagge...
by anav
Fri Dec 08, 2023 6:34 pm
Forum: Beginner Basics
Topic: Mikrotik Failover
Replies: 3
Views: 321

Re: Mikrotik Failover

There are many threads for failover did you do a search on the forums. Since both your ISPs provide dynamic WANIP addresses you will need to add distance in your client settings....... The IP DHCP client one defaults to a distance of 1, so if that is your primary then leave it ( looked under the Adv...
by anav
Fri Dec 08, 2023 6:25 pm
Forum: General
Topic: HELP - Unable to connect WireGuard when WAN is Public IP
Replies: 4
Views: 308

Re: HELP - Unable to connect WireGuard when WAN is Public IP

Confusing post. Do you have two mikrotik routers you are trying to connect, one with a public IP and one without? OR Do you have two WAN connections and neither one seems to work to setup wireguard. Please also confirm you are using your MT as a wireguard server for the initial handhake and all the ...
by anav
Fri Dec 08, 2023 2:34 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 258
Views: 382807

Re: Using RouterOS to VLAN your network

by anav
Fri Dec 08, 2023 2:24 pm
Forum: General
Topic: WireGuard access
Replies: 13
Views: 854

Re: WireGuard access

Sorry this is an MT forum not a fortigate forum.
by anav
Fri Dec 08, 2023 2:22 pm
Forum: General
Topic: my wireguard config / dynamic confusion
Replies: 2
Views: 288

Re: my wireguard config / dynamic confusion

https://www.youtube.com/watch?v=OGBWSpl1Wik&t=103s&pp=ygUSd2lyZWd1YXJkIG1pa3JvdGlr https://www.youtube.com/watch?v=P6f8Qc4EItc&t=1291s&pp=ygUSd2lyZWd1YXJkIG1pa3JvdGlr https://www.youtube.com/watch?v=vn9ky7p5ESM&t=8s&pp=ygUSd2lyZWd1YXJkIG1pa3JvdGlr https://www.youtube.com/watc...
by anav
Fri Dec 08, 2023 1:33 pm
Forum: General
Topic: Having issues with DHCP client over trunk [SOLVED]
Replies: 6
Views: 549

Re: Having issues with DHCP client over trunk [SOLVED]

The reference in case you need it in future.....
viewtopic.php?t=143620
by anav
Fri Dec 08, 2023 1:32 pm
Forum: General
Topic: RDP not working in lan
Replies: 7
Views: 756

Re: RDP not working in lan

Your post is confusing. Are you trying to RDP from a remote location into your desktop? If so stop right there, RDP is not a secure protocol, use Wireguard instead. If I am wrong and its RDP within the LAN network of the MT, as noted by others, nothing is blocking that. Your mangle rules are suspect...
by anav
Fri Dec 08, 2023 3:43 am
Forum: Beginner Basics
Topic: How to configure identical WiFi on MikroTik so that the devices switch automatically?
Replies: 7
Views: 592

Re: How to configure identical WiFi on MikroTik so that the devices switch automatically?

Roaming properly between multiple MT wifi devices did not come to fruition until the AX product line.
Your friend didnt give you accurate information
by anav
Fri Dec 08, 2023 1:06 am
Forum: General
Topic: WireGuard - can't get to the LAN devices
Replies: 4
Views: 398

Re: WireGuard - can't get to the LAN devices

you can start by posting your mikrotik config
/export file-=anynameyouwish ( minus router serial #, public WANIp info, keys etc.)

plus linux client wg settings.
by anav
Thu Dec 07, 2023 10:31 pm
Forum: General
Topic: Mangle route for WAN2 causing loop [SOLVED]
Replies: 4
Views: 438

Re: Mangle route for WAN2 causing loop [SOLVED]

1. You have two sets of recursive going on, aka check google and if google is possibly not available, then check cloudflare. You should differentiate the two by distance like so.... add comment="TAG: eth1_wan1 ROUTE GOOGLE" distance=1 dst-address=0.0.0.0/0 gateway=8.8.4.4 scope=10 target-s...
by anav
Thu Dec 07, 2023 9:48 pm
Forum: Beginner Basics
Topic: PCC Config glitching but working ?
Replies: 5
Views: 480

Re: PCC Config glitching but working ?

Sent you necessary changes. As noted all IP routes should have actual Gateway IPs.
Prerouting marking rules for WAN1,2,3 only required if hosting servers, the output chain rules are for ensuring traffic to router comes out the right WAN.
All mark routing rules should have passthrough=no
by anav
Thu Dec 07, 2023 7:02 pm
Forum: Beginner Basics
Topic: Recursive Failover with dynamic IP
Replies: 4
Views: 432

Re: Recursive Failover with dynamic IP

You need a script that takes the newly assigned gateway in IP DHCP client and put it physically in your routing rules.g an easy way is to put a comment in each applicable route could be comment=FIXME Easy to use find command. ;-) Not sure if this is a good script but one that I just saw......... htt...
by anav
Thu Dec 07, 2023 6:59 pm
Forum: General
Topic: WireGuard multi core support?
Replies: 3
Views: 382

Re: WireGuard multi core support?

Concur, the Wireguard specs for Routers would be great, I was just comparing the 5009 to 2004 to 2116 vs TPLINK ER8411, and they do parse out wireguard on their specs.
I dont like how they tout 1518 bytes, standard vice the more real 512 bytes....... but WG is stated as 1400Mpbs,
by anav
Thu Dec 07, 2023 3:20 pm
Forum: General
Topic: New ROuter suggestion please
Replies: 13
Views: 793

Re: New ROuter suggestion please

Nope, you want the throughput, ......... any other router of same ilk will cost far more. Trying to find an alternative, the best TPLINK ER8411 is on par with the 5009 (matches 1518 byte throughput approx 9k Mbps throughput) but it does have amuch higher VPN throughput but at easily double the price...
by anav
Thu Dec 07, 2023 3:19 pm
Forum: General
Topic: WireGuard access
Replies: 13
Views: 854

Re: WireGuard access

No idea what it looks like on fortigate but on the MT it would be simple. /ip route add dst-address=wireguardsubnet gateway=LANIPof MIkrotik. so lets say wg 10.10.10.0/24 and lanip of MT is 192.168.5.5 /ip route add dst-address=10.10.10.0/24 gateway=192.168.5.5 Be advised that on the fortigate you n...
by anav
Thu Dec 07, 2023 1:41 pm
Forum: General
Topic: New ROuter suggestion please
Replies: 13
Views: 793

Re: New ROuter suggestion please

If you have three WANS each 1gig then consider the following

RB5009 - throughput around 3gigs so it fits........
If you add more WANS or higher WAN throughput 2.5 gigs then consider the CCR2116 is one solution.
by anav
Thu Dec 07, 2023 1:05 pm
Forum: General
Topic: WireGuard access
Replies: 13
Views: 854

Re: WireGuard access

IF the fortigate blow up, then your wireguard connection ( via wan1 or wan2 ) is gone, so I guess your plan is not good. If you want to wireguard regardless, then you have two options. a. put in a static route on the fortigate pointing to the LANIP of the MT (on fortigate subnet - also the wanip of ...
by anav
Thu Dec 07, 2023 1:01 pm
Forum: General
Topic: Topology for a better home networking and wifi roaming
Replies: 15
Views: 857

Re: Topology for a better home networking and wifi roaming

Why do you keep talking ac2........ either roaming is a requirement or its not??
by anav
Wed Dec 06, 2023 11:49 pm
Forum: Beginner Basics
Topic: Mullvad WG VPN as a second WAN for use of a subnet?
Replies: 10
Views: 643

Re: Mullvad WG VPN as a second WAN for use of a subnet?

Non-standard but if you understand why it works, then it should be good.
by anav
Wed Dec 06, 2023 10:37 pm
Forum: Beginner Basics
Topic: PCC Config glitching but working ?
Replies: 5
Views: 480

Re: PCC Config glitching but working ?

Change all IP ROUTE entries, from ether1,ether2,ether3 to actual gateway IPs.
That should solve most of your issues.

Sent you an updated email with some modifications to Mangles.
by anav
Wed Dec 06, 2023 10:24 pm
Forum: General
Topic: Topology for a better home networking and wifi roaming
Replies: 15
Views: 857

Re: Topology for a better home networking and wifi roaming

I would buy a cheap managed switch from TPLINK for the TV, the CSS610 10gig switch for the office .
For Wifi if the AX3 is not adequate then get a couple of Capaxs
1xAX3
2xCapax ( if needed )
xcheapswitch tplink for tv room and
1 css610 for office
by anav
Wed Dec 06, 2023 8:37 pm
Forum: General
Topic: [solved] - Route internet traffic from one VLAN to exit via specific IP
Replies: 16
Views: 845

Re: Route internet traffic from one VLAN to exit via specific IP

My head hurts LOL, so the gateway is the same for all the public IPs..........
by anav
Wed Dec 06, 2023 8:27 pm
Forum: General
Topic: Topology for a better home networking and wifi roaming
Replies: 15
Views: 857

Re: Topology for a better home networking and wifi roaming

I suggest a proper router, the L1009 wont even handle a full 1gig fiber network, aka no future growth. Please confirm you can run cat6 or fiber between all rooms? Not sure what you meant by one UTP cable.............. Also if there is coax between all rooms you can get 2.5gib through them with adapt...
by anav
Wed Dec 06, 2023 8:17 pm
Forum: Beginner Basics
Topic: Mullvad WG VPN as a second WAN for use of a subnet?
Replies: 10
Views: 643

Re: Mullvad WG VPN as a second WAN for use of a subnet?

Yes still bizarro, Whats wrong with this picture for example........ /ip dhcp-server add address-pool=pool1 interface=bridge1 add address-pool=pool2 interface= bridge1 / interface bridge port add bridge=bridge1 interface=ether2 add bridge=bridge1 interface=ether3 add bridge=bridge1 interface=ether4 ...
by anav
Wed Dec 06, 2023 5:42 pm
Forum: General
Topic: [solved] - Route internet traffic from one VLAN to exit via specific IP
Replies: 16
Views: 845

Re: Route internet traffic from one VLAN to exit via specific IP

Perhaps its something I dont understand about multiple WANIPs via the same gateway, or perhaps the OP really means a netmap is needed from the IP to the subnet............ in any case, source nat does not grab or do anything in terms of routing. It states, when the traffic is routed ( by some other ...
by anav
Wed Dec 06, 2023 4:01 pm
Forum: General
Topic: [solved] - Route internet traffic from one VLAN to exit via specific IP
Replies: 16
Views: 845

Re: Route internet traffic from one VLAN to exit via specific IP

The source address you noted has no bearing on routing, it has bearing for what is sourcenatted out that WAN, it does not move traffic :-) Let me rephrase........ based on OPs comments: (Goal is to have all external-bound traffic from vlan23 (10.10.23.0/24) to be sourced with public IP 76.xxx.xxx.10...
by anav
Wed Dec 06, 2023 2:49 pm
Forum: Beginner Basics
Topic: Dual WAN, same Gateway, no need for load balancing or failover, just specify which vlans use which wan port
Replies: 5
Views: 826

Re: Dual WAN, same Gateway, no need for load balancing or failover, just specify which vlans use which wan port

Post your config to show what you have setup so far......
/export file=anynameyouwish (minus router serial number, public WANIP information, keys etc.)
by anav
Wed Dec 06, 2023 2:47 pm
Forum: General
Topic: <ask> POLICE BASE ROUTING v7.12.1 (mangle or raw on ax2)
Replies: 8
Views: 634

Re: <ask> POLICE BASE ROUTING v7.12.1 (mangle or raw on ax2)

Firewall raw rules have nothing to do with policy routing.

You cannot direct traffic for applications using the mikrotik router
You can direct users, subnets, vlans etc
You can elect to share all wans or some with some users etc......
by anav
Wed Dec 06, 2023 2:42 pm
Forum: General
Topic: "NAT forward to gateway"
Replies: 12
Views: 854

Re: "NAT forward to gateway"

If you looked at the config provided its a very simple addition....... focus on the user rules......... {forward chain} (default rules to keep) add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=in,ipsec add action=accept chain=forward comment="defc...
by anav
Wed Dec 06, 2023 2:35 pm
Forum: General
Topic: [solved] - Route internet traffic from one VLAN to exit via specific IP
Replies: 16
Views: 845

Re: Route internet traffic from one VLAN to exit via specific IP

Hi Kev, The sourcenat rule makes sense The ip route makes sense, BUT how do you ensure the specific vlan traffic goes out that route OR CONVERSELY how do you ensure all other vlan traffic does NOT go out that route. Suggesting a routing rule............ /routing table add fib name=useISPX /routing r...
by anav
Tue Dec 05, 2023 11:30 pm
Forum: Beginner Basics
Topic: Mullvad WG VPN as a second WAN for use of a subnet?
Replies: 10
Views: 643

Re: Mullvad WG VPN as a second WAN for use of a subnet?

Yeah use vlan filtering for the subnets, one bridge............
The bizarro approach to address, dhcp server pool,, if not for a specific needed reasons is cutsie crap for nothing.

viewtopic.php?t=14362
by anav
Tue Dec 05, 2023 11:28 pm
Forum: Wireless Networking
Topic: 802.11r for hAP ac2?
Replies: 71
Views: 10070

Re: 802.11r for hAP ac2?

Now lets get real and work on WIFI -7, that is where the meat is on the wifi BONE.
by anav
Tue Dec 05, 2023 6:25 pm
Forum: Wireless Networking
Topic: Wi-Fi 6E devices for an new project
Replies: 10
Views: 814

Re: Wi-Fi 6E devices for an new project

RICH, please dont waste valuable mikrotik resources on an interim, dead before it goes out the door, 6E standard. TP link and other are rolling out Wi-Fi 7 already and even zyxel is heavily discounting (dumping its new 6E stock). Normis, do not pass go, do not collect $200, go straight to jail if yo...
by anav
Tue Dec 05, 2023 5:34 pm
Forum: General
Topic: Port access and port trunk
Replies: 1
Views: 301

Re: Port access and port trunk

by anav
Tue Dec 05, 2023 4:35 pm
Forum: General
Topic: Routing rule VS mangle mark routing
Replies: 9
Views: 664

Re: Routing rule VS mangle mark routing

Also the requirement should be expressed in terms of user traffic required.
Mangling and routing rules are simply tools to use, for a purpose, and that purpose has not been communicated........
by anav
Tue Dec 05, 2023 2:44 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 2379

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

PM me the exact config, sure..........
For all ip routes its best to use the correct gateway vice etherX........... ( exception that comes to mind is wireguard )
If nothing else to demonstrate that the routes are meant for Static IPs/gateways, whereas one would need s cripts for dynamic ones.
by anav
Tue Dec 05, 2023 2:38 pm
Forum: Beginner Basics
Topic: PCC Config glitching but working ?
Replies: 5
Views: 480

Re: PCC Config glitching but working ?

As per your other post, (1) MISMATCH in address and gateway!! (2) Duplicate routes. /ip address add address=192.168.100.1/24 interface="LAN bridge" network=192.168.100.0 add address= 100. 90 . 8 0. 70 /29 interface=ether1 network=100.90.80.70 add address=110.100.90.80/30 interface=ether2 n...
by anav
Tue Dec 05, 2023 2:37 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 2379

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

Also it would appear you have some duplicates.......... /ip route add check-gateway=ping disabled=no distance=1 dst-address=0.0.0.0/0 gateway=100.80.90.70 pref-src="" routing-table=main scope=30 \ suppress-hw-offload=no target-scope=10 add check-gateway=ping disabled=no distance=2 dst-addr...
by anav
Tue Dec 05, 2023 2:32 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 2379

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

Sure, took me a couple of secs to find the problem. /ip address add address=192.168.100.1/24 interface="LAN bridge" network=192.168.100.0 add address= 100. 90 . 80 . 70 /29 interface=ether1 network=100.90.80.70 add address=110.100.90.80/30 interface=ether2 network=110.100.90.80 add address...
by anav
Mon Dec 04, 2023 10:39 pm
Forum: General
Topic: "NAT forward to gateway"
Replies: 12
Views: 854

Re: "NAT forward to gateway"

This is your basic default firewall ruleset with a focus on only identifying needed traffic and dropping everything else. /ip firewall-address list { using static dhcp leases mostly } add address=admin-IP1 list=Authorized comment="admin local desktop" add address=admin-IP2 list=Authorized ...
by anav
Mon Dec 04, 2023 9:57 pm
Forum: Beginner Basics
Topic: 2 WAN connections, mangle rules and wireguard [SOLVED]
Replies: 29
Views: 5115

Re: 2 WAN connections, mangle rules and wireguard [SOLVED]

Well what I recommend between two routers is Setting up WIREGUARD between the two, and if the server goes down, due to WAN1 failing, the client will regenerage the connection on WAN2 as I described. As the backup simply connect an easy MT to MT SSTP backup direct to WAN2. Thus you always have a seco...
by anav
Mon Dec 04, 2023 9:13 pm
Forum: Wireless Networking
Topic: hap ax2 + wireless access points
Replies: 5
Views: 508

Re: hap ax2 + wireless access points

If one has coax between rooms --> moca, if one has modern wiring - powerline are both options.
MOCA adapters can go up to 2.5 gig
https://www.electronicshub.org/best-moca-adapters/

Powerline.......... https://www.techradar.com/news/the-best ... e-adaptors
by anav
Mon Dec 04, 2023 9:11 pm
Forum: General
Topic: Unable to change default IP on RB5009
Replies: 20
Views: 1006

Re: Unable to change default IP on RB5009

Maybe it doesnt work with the new wifiwave wave of products.
Or it was a big security risk?
by anav
Mon Dec 04, 2023 8:56 pm
Forum: Beginner Basics
Topic: 2 WAN connections, mangle rules and wireguard [SOLVED]
Replies: 29
Views: 5115

Re: 2 WAN connections, mangle rules and wireguard [SOLVED]

Hi Broderick, this already happens!! If you have a wireguard server on your Router and WAN1 is the primary, and it goes down the router switches to WAN2, the clients connecting to your WG server will lose connectivity and will try to reconnect and when the WANIP for the router becomes the second ISP...
by anav
Mon Dec 04, 2023 8:49 pm
Forum: General
Topic: Unable to change default IP on RB5009
Replies: 20
Views: 1006

Re: Unable to change default IP on RB5009

So you can enter the router via the USB device? Just curious, how do you type on the usb device? small keyboard?
by anav
Mon Dec 04, 2023 7:45 pm
Forum: General
Topic: Unable to change default IP on RB5009
Replies: 20
Views: 1006

Re: Unable to change default IP on RB5009

Not sure what it has to do with changing IP but okay.....
by anav
Mon Dec 04, 2023 6:29 pm
Forum: General
Topic: Unable to change default IP on RB5009
Replies: 20
Views: 1006

Re: Unable to change default IP on RB5009

NM , posted in error
by anav
Mon Dec 04, 2023 6:28 pm
Forum: Beginner Basics
Topic: Good switch for home use or RB4011 RB5009?
Replies: 18
Views: 10839

Re: Good switch for home use or RB4011 RB5009?

NM....
by anav
Mon Dec 04, 2023 5:48 pm
Forum: Beginner Basics
Topic: L009UiGS-2HaxD-IN fast enough for 1GBIT Internet?
Replies: 9
Views: 687

Re: L009UiGS-2HaxD-IN fast enough for 1GBIT Internet?

What you can do is actually research a product before buying it. Too late now, but on the product page have a look at TEST RESULTS. The throughput one should expect to get with some basic filter rules is somewhere between 300-600Mbps. For 1 gig throughput your best bets are. a. hapax3 --> just over ...
by anav
Mon Dec 04, 2023 3:33 pm
Forum: Beginner Basics
Topic: Failover between 2 ISPs using gateways with same IP (was NAT traffic to VRF)
Replies: 37
Views: 4021

Re: Failover between 2 ISPs using gateways with same IP (was NAT traffic to VRF)

Well if they are static Ips, then that would be easier to deal with, you should confirm with your ISP that they are static!
Confirm you are paying for two separate 1 gig connections? and on each one you can get 1 gig at the same time......
by anav
Mon Dec 04, 2023 1:44 pm
Forum: Beginner Basics
Topic: Failover between 2 ISPs using gateways with same IP (was NAT traffic to VRF)
Replies: 37
Views: 4021

Re: Failover between 2 ISPs using gateways with same IP (was NAT traffic to VRF)

Well I dont understand this o ne...........
but within my LAN I need to allow access between all the VLANs.

Can you elaborate? If they all need access to each other why have separate vlans?

Can you confirm these are dynamic IPs that change BUT the gateway never changes??
by anav
Mon Dec 04, 2023 1:43 pm
Forum: Beginner Basics
Topic: About "Building Your First Firewall" ICMP jump-chain
Replies: 13
Views: 1081

Re: About "Building Your First Firewall" ICMP jump-chain

If your server does not have secure login (encrypted) then you shouldnt be using those servers. Assuming they are secure logins, consider a. src-address-list on your dst-nat rules ( everyone is comming from a public IP address, static or dynamic either directly or from their upstream ISP modem/route...
by anav
Mon Dec 04, 2023 4:53 am
Forum: Beginner Basics
Topic: Failover between 2 ISPs using gateways with same IP (was NAT traffic to VRF)
Replies: 37
Views: 4021

Re: Failover between 2 ISPs using gateways with same IP (was NAT traffic to VRF)

Ahh okay one modem two WAN IPs, same gateway address............ Okay that makes sense, my bad.
by anav
Mon Dec 04, 2023 2:35 am
Forum: Beginner Basics
Topic: Failover between 2 ISPs using gateways with same IP (was NAT traffic to VRF)
Replies: 37
Views: 4021

Re: Failover between 2 ISPs using gateways with same IP (was NAT traffic to VRF)

What are you talking about? The original OP stated he was getting the same IP gateway from two ISPs starlink and something else, aka gateway=192.168.1.1 What does that have to do with you having two 1gig connections? Are you saying you are using two ISP supplied modem routers in front of you and eac...
by anav
Mon Dec 04, 2023 2:20 am
Forum: General
Topic: NordVPN too Slow after configuration
Replies: 1
Views: 344

Re: NordVPN too Slow after configuration

Use wireguard instead!!!
by anav
Mon Dec 04, 2023 2:18 am
Forum: General
Topic: Unable to change default IP on RB5009
Replies: 20
Views: 1006

Re: Unable to change default IP on RB5009

Word of advice, assign to an empty port an IP address and work safely from that port to do all your config initially and then later acts as an emergency access, besides lot of use of SAFE MODE!!
viewtopic.php?t=181718
by anav
Mon Dec 04, 2023 2:14 am
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 40
Views: 3718

Re: Firewall - DNS Open? - Urgent [SOLVED]

Once you provide the details on wireguard I will send an updated config, that gets rid of all the crap..............
by anav
Mon Dec 04, 2023 2:11 am
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 40
Views: 3718

Re: Firewall - DNS Open? - Urgent [SOLVED]

You really need to explain your wireguard setup . ITS STILL WRONG!!! Where is the server for VPN01 for handshake? if not this router then this router is the client for handshake? Where is the server for MGNT for handshake? if not this router then this router is the client for handshake? Server Devi...
by anav
Mon Dec 04, 2023 2:00 am
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 40
Views: 3718

Re: Firewall - DNS Open? - Urgent [SOLVED]

If its disabled on the config, I delete it when looking at it....... KISS I delete all capsman config entries for easier viewing, now the config is looking smaller LOL No problem for queues, I worked around that so you can user fastrack for everything else......... You forgot to add additional vlans...
by anav
Sun Dec 03, 2023 8:07 pm
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 40
Views: 3718

Re: Firewall - DNS Open? - Urgent [SOLVED]

YOur three wans, in IP DHCP CLIENT did you enable default routes and if so did you put any script in there..........??

Right now there is no way to determine how you setup the WANs in terms of priority..........??
by anav
Sun Dec 03, 2023 7:36 pm
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 40
Views: 3718

Re: Firewall - DNS Open? - Urgent [SOLVED]

Which subnets or list of individual devices should be getting NTP services from the router??? Where are the remote subnets coming from in this rule................?? add action=accept chain=forward comment=Accept_Remote_to_Company \ dst-address-list=COMPANY src-address-list=REMOTE Reminder........ a...
by anav
Sun Dec 03, 2023 7:28 pm
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 40
Views: 3718

Re: Firewall - DNS Open? - Urgent [SOLVED]

This rule makes no sense to me...... add action=accept chain=input comment="Accept Radius" dst-port=3799,1812,1813 \ in-interface-list=!WAN protocol=udp src-address-list=FIREWAL WHere the only entry for firewall address list is the following add address=127.0.0.1 list=FIREWALL Another rule...
by anav
Sun Dec 03, 2023 6:54 pm
Forum: Beginner Basics
Topic: Failover between 2 ISPs using gateways with same IP (was NAT traffic to VRF)
Replies: 37
Views: 4021

Re: Failover between 2 ISPs using gateways with same IP (was NAT traffic to VRF)

Have you considered NOT using the starlink router and connect CGNAT direct to your router?
Your gateway in this case will be 100.64.0.1 ............ or something like that.
by anav
Sun Dec 03, 2023 6:26 pm
Forum: Useful user articles
Topic: Wireguard Success For The Beginner
Replies: 164
Views: 79205

Re: Wireguard Success For The Beginner

I see the issue. The paragraph stood on its own and if you tried to correlate with the previous para, it would seem non-congruent. I have adjusted it so that confusion is removed. Much thanks!
by anav
Sun Dec 03, 2023 5:26 pm
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 40
Views: 3718

Re: Firewall - DNS Open? - Urgent [SOLVED]

I will have a look. I am actually hoping that you are understanding the config better and learning as you go and gaining confidence in your own skills! Observations: 1. You have many vlans identified but not fully configured, assumed this was future plans and removed them from the config for the mom...
by anav
Sun Dec 03, 2023 3:05 pm
Forum: Beginner Basics
Topic: About "Building Your First Firewall" ICMP jump-chain
Replies: 13
Views: 1081

Re: About "Building Your First Firewall" ICMP jump-chain

Why, none of those things are required for port forwarding.
by anav
Sun Dec 03, 2023 3:03 pm
Forum: Beginner Basics
Topic: Help with vlan, bridge and internet.
Replies: 3
Views: 436

Re: Help with vlan, bridge and internet.

Actually the RB4011 has two chips on it, so it kinda makes sense to split it into two bridges, but if my memory recalls only one of them will have Offload so in the end one bridge is best.
by anav
Sat Dec 02, 2023 10:42 pm
Forum: Useful user articles
Topic: Wireguard Success For The Beginner
Replies: 164
Views: 79205

Re: Wireguard Success For The Beginner

First, thanks for reviewing and making suggestions!!

Not sure I follow?
The setting in red, is under the heading of
/ip dhcp-network server NOT /ip address ???
by anav
Sat Dec 02, 2023 9:50 pm
Forum: General
Topic: Wireguard tunnel - speed problem
Replies: 19
Views: 1477

Re: Wireguard tunnel - speed problem

Hmm, way better than my results 1gig to 1gig connection but that was using an RB4011 at one end and RGB450Gx4 at the other.
by anav
Sat Dec 02, 2023 7:16 pm
Forum: Beginner Basics
Topic: Issue with CAPsMAN v2 managing its own device
Replies: 8
Views: 671

Re: Issue with CAPsMAN v2 managing its own device

Good common sense information here!!!
Should go in your 'article' Holvoe,,,,,,,,, when the move is done. :-)
by anav
Sat Dec 02, 2023 6:44 pm
Forum: Beginner Basics
Topic: Issue with CAPsMAN v2 managing its own device
Replies: 8
Views: 671

Re: Issue with CAPsMAN v2 managing its own device

I just may hire you to setup my wifi.................. I just cannot afford the postage and cost of envelope to send the cheque. :-)
by anav
Sat Dec 02, 2023 5:57 pm
Forum: General
Topic: Wireguard tunnel - speed problem
Replies: 19
Views: 1477

Re: Wireguard tunnel - speed problem

I would say 300-350 is pretty decent wireguard speeds, I would not be complaining.
by anav
Sat Dec 02, 2023 5:54 pm
Forum: Beginner Basics
Topic: Issue with CAPsMAN v2 managing its own device
Replies: 8
Views: 671

Re: Issue with CAPsMAN v2 managing its own device

In plain english, the setup for wifi on the device hosting capsman is different or separate from the wifi settings within capsman for the external devices.???
by anav
Sat Dec 02, 2023 2:50 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 2379

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

Generally anything is possible but its best to detail all the requirements PRIOR to setting up a config. I would stick to source for PCC because of the banking requirements etc....... I would also contemplate using the # of WANS you need to distribute traffic and then perhaps a couple of dedicated W...
by anav
Sat Dec 02, 2023 2:45 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 2379

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

Again, I dont understand the purpose. Showing someone combined WAN output is a useless exercise. Firstly unless you have a bonded setup with the SAME iSP you cannot ADD the throughput of ISP connection and do a speed test that shows the addition of all of them. What you do have is a larger total ban...
by anav
Sat Dec 02, 2023 2:40 pm
Forum: Beginner Basics
Topic: Need to block parent routers DHCP range
Replies: 2
Views: 358

Re: Need to block parent routers DHCP range

Concur, ideally the Landlord isnt using the same LAN for all his devices, but it seems to be the case. Probably one flat LAN.
Is the landlords router actually the iSPs modem/router or is it his own separate router. If so does it get a public IP?
by anav
Sat Dec 02, 2023 2:37 pm
Forum: Beginner Basics
Topic: Mikrotik Router to Router VLAN Setup [SOLVED]
Replies: 3
Views: 501

Re: Mikrotik Router to Router VLAN Setup [SOLVED]

Further this article addresses using any MT device as an AP/switch ( same same just without AP part).
viewtopic.php?t=182276
by anav
Sat Dec 02, 2023 2:32 pm
Forum: General
Topic: Wireguard Road Warrior to L2 LAN [SOLVED]
Replies: 4
Views: 546

Re: Wireguard Road Warrior to L2 LAN [SOLVED]

You need to understand better the use and setup of allowed IPs........
Check this -->viewtopic.php?t=182340
by anav
Fri Dec 01, 2023 11:47 pm
Forum: Beginner Basics
Topic: VLANs on hAP ax2, v7.13, no CAPsMAN - how?
Replies: 5
Views: 606

Re: VLANs on hAP ax2, v7.13, no CAPsMAN - how?

According to other experts here just stick to the defaults as much as possible....... and that its easy.
I beg to differ but check out some newer videos by MT for wifi, they will be helpful.
by anav
Fri Dec 01, 2023 11:45 pm
Forum: General
Topic: Wireguard client can't access local lan and internet
Replies: 6
Views: 645

Re: Wireguard client can't access local lan and internet

This is a mikrotik forum, if you have windows questions, go to a windows forum or a wireguard forum where windows may be discussed.
by anav
Fri Dec 01, 2023 11:44 pm
Forum: General
Topic: Como acceder en la configuracion de mi router, MikroTik?
Replies: 2
Views: 6840

Re: Como acceder en la configuracion de mi router, MikroTik?

First of all, the router is NOT yours it belongs to the ISP so respect their wishes. However since their device is acting as an ISP/ROUTER and you get a private IP, it is very normal to ask: a. if they can forward ports on the router for you OR b. they can describe the steps you can take to forward ...
by anav
Fri Dec 01, 2023 11:41 pm
Forum: General
Topic: Incomplete settings import
Replies: 2
Views: 354

Re: Incomplete settings import

RSC is not meant for exporting importing.
THe only function that does that is BACKUP and RESTORE and that is for the same device.
You can use an export to guide you manuallly configuring the new device,
and if you know what you are doing you can import chuncks of config via the TERMINAL CLI window.
by anav
Fri Dec 01, 2023 1:52 pm
Forum: General
Topic: Wireguard client can't access local lan and internet
Replies: 6
Views: 645

Re: Wireguard client can't access local lan and internet

If their devices do not allow split tunneling, then perhaps its not possible?
by anav
Fri Dec 01, 2023 5:54 am
Forum: General
Topic: Wireguard client can't access local lan and internet
Replies: 6
Views: 645

Re: Wireguard client can't access local lan and internet

Your explanation is off. If you mean to say that your MT router is the server and the remote clients can connect and reach local router services that would make more sense. Further if the computers that the remote users have cannot reach their local resources that is an issue with the devices they a...
by anav
Fri Dec 01, 2023 5:51 am
Forum: Beginner Basics
Topic: VLANs on hAP ax2, v7.13, no CAPsMAN - how?
Replies: 5
Views: 606

Re: VLANs on hAP ax2, v7.13, no CAPsMAN - how?

Much easier not to use capsman for only one AP .....

For vlans, use this guide. viewtopic.php?t=143620
by anav
Thu Nov 30, 2023 11:26 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 258
Views: 382807

Re: Using RouterOS to VLAN your network

Is this a planned exciting move, or a not so glad eviction notice?
by anav
Thu Nov 30, 2023 11:07 pm
Forum: Beginner Basics
Topic: Unintentionally isolated ethernet ports on RB5009
Replies: 7
Views: 633

Re: Unintentionally isolated ethernet ports on RB5009

Personally I dont ping other users for a living, it is of zero value to me. Can users access the devices they need to access on the LAN and conduct work? Or are they blocked? It doesnt matter what port they are connected to if all ports are part of the same bridge. All to say is so far I do not see ...
by anav
Thu Nov 30, 2023 10:41 pm
Forum: Virtualization
Topic: Documentation improvement: Are the container stateful or stateles?
Replies: 5
Views: 816

Re: Documentation improvement: Are the container stateful or stateles?

@normis--> suggest video how to use vlans with capsman.......... Basically the presenter should take this article viewtopic.php?t=143620
and 'bend it' as required for capsman.
by anav
Thu Nov 30, 2023 10:37 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 258
Views: 382807

Re: Using RouterOS to VLAN your network

The article is meant for vlans primarily and is not intended for vlans under capsman.
I agree its sorely needed but that is best left to an article describing capsman setup and suggest you go bug holvoetn to make such an article ;-)
by anav
Thu Nov 30, 2023 10:17 pm
Forum: General
Topic: Newbie with firewall - Is there a way of combining rules (lesser is better?)
Replies: 2
Views: 347

Re: Newbie with firewall - Is there a way of combining rules (lesser is better?)

Firewall rule guidelines 1. Single Subnets --> use dst-address or src-address 2. More than one subnet (whole subnets) --> use interface lists 3. If you have any list that includes a bunch of users (less than a subnet) or from different subnets (with or without whole subnets) then use firewall addres...
by anav
Thu Nov 30, 2023 10:11 pm
Forum: Beginner Basics
Topic: Unintentionally isolated ethernet ports on RB5009
Replies: 7
Views: 633

Re: Unintentionally isolated ethernet ports on RB5009

This is an unusual rule, did you invent it yourself, or watch youtube from hell channel?? At least its disabled. At the moment I see no reason why users cannot see each other being all on the same subnet and visible at L2. If there are no issues between wired users but issues betwee wired and wired ...
by anav
Thu Nov 30, 2023 6:51 pm
Forum: Beginner Basics
Topic: Moving from DD-WRT to RB3011
Replies: 6
Views: 496

Re: Moving from DD-WRT to RB3011

No that is too old for one thing and is not the link I provided for vlan setup. Dont run away from help LOL.
by anav
Thu Nov 30, 2023 6:48 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 2379

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

1) If some users speed test will they receive the combined speed test result. If not can we make it so that they are able to achieve that result (this is just a requirement and i understand that LB is not for this) Do not understand the question? Conducting a speed test is not a valid user requirem...
by anav
Thu Nov 30, 2023 5:55 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 2379

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

(1) By the way, using ether1, ether2, ether3 WORKS in your config as all your WANIPs are static. My example should reflect the IPs only, so as to not lead others astray. No need to change your config in that regard but I will change my example provided above. :-) (2) Also I may confuse people by usi...
by anav
Thu Nov 30, 2023 5:40 pm
Forum: General
Topic: Road warrior Wireguard
Replies: 5
Views: 551

Re: Road warrior Wireguard

Would concur, wireguard does not scale (pun intended) like an enterprise VPN.
However, tailscale which depends however on a third party, may have some tools/functionality to support such a requirement.

https://tailscale.com/
by anav
Thu Nov 30, 2023 5:38 pm
Forum: Beginner Basics
Topic: Unintentionally isolated ethernet ports on RB5009
Replies: 7
Views: 633

Re: Unintentionally isolated ethernet ports on RB5009

You clearly know where the problem lies, by NOT including your full config.
by anav
Thu Nov 30, 2023 5:35 pm
Forum: Beginner Basics
Topic: Moving from DD-WRT to RB3011
Replies: 6
Views: 496

Re: Moving from DD-WRT to RB3011

Yes absolutely recommend wireguard for both connecting to proton and to host your own wireguard so you can remote into the router to config it or for LAN services or to use its internet or to be forwarded out protons internet.
by anav
Thu Nov 30, 2023 5:32 pm
Forum: Beginner Basics
Topic: About "Building Your First Firewall" ICMP jump-chain
Replies: 13
Views: 1081

Re: About "Building Your First Firewall" ICMP jump-chain

Because they are not necessary and are bloatware............ Instead stick to the defaults........... The defaults are safe for a single user and a single WAN and LAN subnet with no complexities. Once you go beyond that, its 99.999 percent of the time needed to start mucking about in the rules. The ...
by anav
Thu Nov 30, 2023 5:22 pm
Forum: Beginner Basics
Topic: Moving from DD-WRT to RB3011
Replies: 6
Views: 496

Re: Moving from DD-WRT to RB3011

VLANS approach is best described here ---> https://forum.mikrotik.com/viewtopic.php?t=143620 We do one bridge approach here. Open VPN has varied success on MT gear. Recommend you replace your proton connetion to Wireguard. If your MT gets a public IP, or if you are behind and ISP modem/router and ca...
by anav
Thu Nov 30, 2023 12:04 am
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 2379

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

Now for the ROUTES. CAUTION: In your actual implementation use GATEWAY IPS, the use of ether1,2 etc.. is for expediency only. We have the ones we created for the non-pcc mangles as show above...... /ip route add dst-address=0.0.0.0/0 gateway=100.100.100.90 table=useWAN1 add dst-address=0.0.0.0/0 gat...
by anav
Wed Nov 29, 2023 11:51 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 2379

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

Third Step lets do the PCC MANGLES. ( 6 mark connections and 6 route markings aka tables ) (using src-address ONLY not both) /ip firewall mangle add action=mark-connection chain=prerouting connection-mark=no-mark dst-address-type=!local \ in-interface=LAN-bridge new-connection-mark=WANA-B passthroug...
by anav
Wed Nov 29, 2023 11:35 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 2379

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

Non-PCC MANGLE RULES, ensuring traffic entering a WAN exits the same WAN deals with any traffic to the router itself or to any servers on the LAN. These will not interfere with any normal traffic either. /ip firewall mangle add action=mark-connection chain=prerouting connection-mark=no-mark \ in-int...
by anav
Wed Nov 29, 2023 11:04 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 2379

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

First step Basic firewall rules. /ip firewall address-list { use static dhcp leases } add address=192.168.100.X list=Authorized comment="local admin desktop" add address=192.168.100.AB list=Authorized comment="local admin laptop" add address=192.168.100.CD list=Authorized comment...
by anav
Tue Nov 28, 2023 9:42 pm
Forum: General
Topic: Official docs to L2TP-v3 L2TP-ETHER
Replies: 11
Views: 3504

Re: Official docs to L2TP-v3 L2TP-ETHER

For L2TP over WG --> viewtopic.php?t=182340
Check out para 10
(10) L2TP thru WIREGUARD for MTU Issues
by anav
Tue Nov 28, 2023 9:12 pm
Forum: General
Topic: Second third party WireGuard VPN with same network provided [SOLVED]
Replies: 30
Views: 3211

Re: Second third party WireGuard VPN with same network provided [SOLVED]

Quick Look Config 1. Listening port settings for the interface, on the client device, can be anything and do not have to match the ENDPOINT listening port and are basically random. In your case highly recommend to make them different. /interface wireguard add listen-port= 51820 mtu=1420 name=wiregua...
by anav
Tue Nov 28, 2023 9:07 pm
Forum: General
Topic: Second third party WireGuard VPN with same network provided [SOLVED]
Replies: 30
Views: 3211

Re: Second third party WireGuard VPN with same network provided [SOLVED]

Well in terms of requirements, routing ports is nonsensical. What is the user traffic that you are trying to execute. ex. users from LANA on router A need to access LANB on Router B ( via wireguar ) users from LANC on router A need to use internet available at Router B etc... If worded in terms of d...
by anav
Tue Nov 28, 2023 7:49 pm
Forum: General
Topic: Second third party WireGuard VPN with same network provided [SOLVED]
Replies: 30
Views: 3211

Re: Second third party WireGuard VPN with same network provided [SOLVED]

to make recommendations for the two WG, need to see config
/export file=anynameyouwish ( minus router serial #, any publicWANIP information, keys, long dhcp lease lists etc..)
by anav
Tue Nov 28, 2023 7:25 pm
Forum: General
Topic: Second third party WireGuard VPN with same network provided [SOLVED]
Replies: 30
Views: 3211

Re: Second third party WireGuard VPN with same network provided [SOLVED]

Also recommend you move to 7.12 once we have resolved the issue.
by anav
Tue Nov 28, 2023 6:02 pm
Forum: Announcements
Topic: Newsletter #115 | November 2023
Replies: 17
Views: 12870

Re: Newsletter #115 | November 2023

I like the clear explanation, that to upgrade to beyond 7.12 you need to upgrade first to 7.12.
by anav
Tue Nov 28, 2023 4:49 pm
Forum: General
Topic: Proton VPN suddenly stopped working
Replies: 8
Views: 1083

Re: Proton VPN suddenly stopped working

Please post the latest config for me to look at.
by anav
Tue Nov 28, 2023 2:42 pm
Forum: Beginner Basics
Topic: Can't access or ping devices in a LAN over WireGuard tunnel
Replies: 3
Views: 509

Re: Can't access or ping devices in a LAN over WireGuard tunnel

First you need to backup and make a coherent plan and before that read this --> https://forum.mikrotik.com/viewtopic.php?t=182340 You will quickly surmize that putting 0.0.0.0/0 at both ends is not the right approach. Once reading, you may make some changes to the config. Give it a try. If still not...
by anav
Tue Nov 28, 2023 2:26 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 2379

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

(1) Your doing PCC, drop any queueing of WANS for the moment. (2) interface list members...... should be modified to the below /interface list member add interface=ether2-TW list=WAN add interface=ether1-PIE1 list=WAN add interface=ether3-PIE3 list=WAN add interface=ether4-LTE4 list=WAN add interfac...
by anav
Tue Nov 28, 2023 2:17 pm
Forum: General
Topic: ip cloud DDNS does not work
Replies: 5
Views: 1419

Re: ip cloud DDNS does not work

Why would you comment on such an old thread? Do you know the context, did you read the link?
MT at the time was having problems at their end............
by anav
Tue Nov 28, 2023 2:14 am
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 40
Views: 3718

Re: Firewall - DNS Open? - Urgent [SOLVED]

(1) YES, THAT IS THE WAY. (2) WHAT ARE YOU TALKING ABOUT SUBNET 16? Point #2 was pointing that your allowed Ip 10.10.9.X/32 was wrong..... The correct version is blue. (3) If you look at the config line its clearly an /ip address entry. Its disabled which is good, I am saying just get rid of it. (4)...
by anav
Mon Nov 27, 2023 11:10 pm
Forum: General
Topic: Second third party WireGuard VPN with same network provided [SOLVED]
Replies: 30
Views: 3211

Re: Second third party WireGuard VPN with same network provided [SOLVED]

Hmm good question.
Post your config.
/export file=anynameyouwish ( minus router serial number, public WANIP informaiton, keys, long dhcp lease lists etc.)
by anav
Mon Nov 27, 2023 10:57 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 71635

Re: v7.13beta [testing] is released!

Dont tell anyone, they might want them back LOL

Ahh confusion due to RAM vs Storage.......... I was looking at Storage.........
Capax hapax3 hapax2 have 1Gb of RAM.
hapac3 has 256Mb of RAM

perhaps your thinking hapac3 or hex devices........
by anav
Mon Nov 27, 2023 10:55 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 71635

Re: v7.13beta [testing] is released!

But the same specs page you linked above lists 128MB ... hmm. You ok?
Even the capax/hap ax3 have 128MB - meaning the 128MB is sufficient........
Edit. looking at storage not ram, my bad.
by anav
Mon Nov 27, 2023 10:30 pm
Forum: Beginner Basics
Topic: HELP VPN RB3011
Replies: 9
Views: 680

Re: HELP VPN RB3011

Yes......... and https://help.mikrotik.com/docs/display/ROS/WireGuard https://www.youtube.com/watch?v=vn9ky7p5ESM&t=8s&pp=ygUSd2lyZWd1YXJkIG1pa3JvdGlr https://www.youtube.com/watch?v=OGBWSpl1Wik&t=103s&pp=ygUSd2lyZWd1YXJkIG1pa3JvdGlr https://www.youtube.com/watch?v=7F9LG7Qgpmg&pp...
by anav
Mon Nov 27, 2023 10:27 pm
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 40
Views: 3718

Re: Firewall - DNS Open? - Urgent [SOLVED]

(1) Where is bridge vlan-filtering=yes ?? /interface bridge add name=BRIDGE priority=0x7000 (2) Allowed IPs is not quite right, fixed....... add allowed-address=\ 10.10.9 .0/24 ,192.168.254.0/24,192.168.155.0/24,192.168.249.0/24 \ comment=PeerStS_DIM disabled=yes endpoint-address=vpn.test.com \ endp...
by anav
Mon Nov 27, 2023 9:57 pm
Forum: General
Topic: L2TP/IPSec VPN - Cannot get past phase 1
Replies: 5
Views: 527

Re: L2TP/IPSec VPN - Cannot get past phase 1

Id rather not Crokinole my way into the OPs head................. and will let the OP provided the actual information.
by anav
Mon Nov 27, 2023 9:54 pm
Forum: General
Topic: Route Traffic through WireGuard to Internet [SOLVED]
Replies: 20
Views: 2595

Re: Route Traffic through WireGuard to Internet [SOLVED]

Philosophy. The default rules come set for a simple user on the bridge via ether2 and wan setup to work on ether1. The traffic is safely protected but it allows all traffic and drops some key things for general safety. When we want to do more, add vlans and other things its much easier, as the confi...
by anav
Mon Nov 27, 2023 9:42 pm
Forum: Beginner Basics
Topic: HELP VPN RB3011
Replies: 9
Views: 680

Re: HELP VPN RB3011

Sounds very doable. Basically server router - input chain rule for port both routers. define interface add ip address add peers, wireguard Ip and remote subnets ( see article for difference between client peer setting and server peer setttings ) add forward chain rules needed for traffic flow add ip...
by anav
Mon Nov 27, 2023 9:16 pm
Forum: Beginner Basics
Topic: HELP VPN RB3011
Replies: 9
Views: 680

Re: HELP VPN RB3011

Before thinking about configurating, its best to understand the requirements and PLAN!!! identify users/devices, groups of users/devices, including admin identify what traffic they need. Do the devices have single WAN or dual WAN? Is there any port forwarding involved on the two devices? What two de...
by anav
Mon Nov 27, 2023 9:14 pm
Forum: General
Topic: L2TP/IPSec VPN - Cannot get past phase 1
Replies: 5
Views: 527

Re: L2TP/IPSec VPN - Cannot get past phase 1

Since the need for VPN is not clear. Which users are coming to the OFFICE and for what purposes?? Why do you hide a private IP address, assuming the upstream router handles the WAN connection and your WAN input is basically a LAN address on the subnet of the ISP router? The other thing funky about t...
by anav
Mon Nov 27, 2023 8:03 pm
Forum: Beginner Basics
Topic: HELP VPN RB3011
Replies: 9
Views: 680

Re: HELP VPN RB3011

Wireguard has generally better performance and easier to setup. Do you control both ends of the tunnel? ( what is at both ends?) Does at least one end have a publicaly reachable IP address ( not cgnat or natted behind another router )?? If natted behind lets say an ISP modem router, can you forward ...
by anav
Mon Nov 27, 2023 8:01 pm
Forum: General
Topic: Route Traffic through WireGuard to Internet [SOLVED]
Replies: 20
Views: 2595

Re: Route Traffic through WireGuard to Internet [SOLVED]

Firewall Rules Server Router; /ip firewall address-list { static dhcp leases or wireguard ip } add address=172.16.24.XX list= Authorized comment="admin local desktop" add address=172.16.24.AA list=Authorized comment="admin local laptop" add address=172.16.24.BB list=Authorized c...
by anav
Mon Nov 27, 2023 7:05 pm
Forum: General
Topic: Route Traffic through WireGuard to Internet [SOLVED]
Replies: 20
Views: 2595

Re: Route Traffic through WireGuard to Internet [SOLVED]

Client Router (1) It would appear you are trying to use srcnat masquerade to route traffic. This is the wrong approach. /ip firewall nat add action=masquerade chain=srcnat dst-address=172.16.24.0/24 out-interface=\ wireguard-oam src-address=192.168.13.0/24 All you need is....... add action=masquera...
by anav
Mon Nov 27, 2023 4:31 pm
Forum: Beginner Basics
Topic: HELP VPN RB3011
Replies: 9
Views: 680

Re: HELP VPN RB3011

Any reason you chose L2TP vice wireguard??
by anav
Mon Nov 27, 2023 4:30 pm
Forum: General
Topic: Route Traffic through WireGuard to Internet [SOLVED]
Replies: 20
Views: 2595

Re: Route Traffic through WireGuard to Internet [SOLVED]

Need facts/evidence.
So latest configs of the routers please.
by anav
Mon Nov 27, 2023 1:25 pm
Forum: Beginner Basics
Topic: Dual WAN failover, port forward not working when changing route distance
Replies: 22
Views: 1535

Re: Dual WAN failover, port forward not working when changing route distance

Well, good to know, defining the requirements clearly is best done before applying a config. a. you have two WANs. b. there is no failover c. the LAN should use WAN1 only if wan1 goes down, no LAN traffic goes to WAN2 if wan2 goes down, no LAN traffic goes to WAN1 Wan 2 is a static fixed WANIP You h...
by anav
Mon Nov 27, 2023 1:20 pm
Forum: Beginner Basics
Topic: HAP ac2 need help with load balancing on 2 WAN connections
Replies: 16
Views: 951

Re: HAP ac2 need help with load balancing on 2 WAN connections

You got me Holvoe, apologies to the OP. I know squat about L2TP so will bow out.
by anav
Mon Nov 27, 2023 1:18 pm
Forum: General
Topic: Some problems in mikrotik 7
Replies: 6
Views: 765

Re: Some problems in mikrotik 7

Is this whining or asking for help?
Provide a network diagram and full config

/export file=anynameyouwish ( minus router serial# and any public WANIP information, keys etc...)
by anav
Mon Nov 27, 2023 1:15 pm
Forum: General
Topic: Problems with DNS, LAN devices can't access internet
Replies: 10
Views: 1224

Re: Problems with DNS, LAN devices can't access internet

have been fighting a starlink DNS issue. I know this sounds strange and I am hoping someone will point out why it is behaving this way. Sounds like your asking for help to me......but okay, maybe your not. What a switch has to do with router issues is a bit strange to interject and you have no clari...
by anav
Mon Nov 27, 2023 2:44 am
Forum: Beginner Basics
Topic: Config with Advanced Firewall verification requested (WG, DoH & server are working great). Nothing is failing
Replies: 2
Views: 405

Re: Config with Advanced Firewall verification requested (WG, DoH & server are working great). Nothing is failing

Just to clarify, my article uses untracked.........
viewtopic.php?t=180838

If you want me to look at your config, I will rip out anything that is not on those pages,,,,,,,,,
Not required, what I refer to as BLOAT.
by anav
Mon Nov 27, 2023 2:42 am
Forum: Beginner Basics
Topic: Dual WAN Load Balancing depending on usage
Replies: 1
Views: 332

Re: Dual WAN Load Balancing depending on usage

Hmm not really, you can setup PCC balancing to favour one over the other but thats hard wired into the config. The only thing I can say off the top is to make a vlan for WIFI in the house and basically route all the traffic from that wifi through the desired WAN. That way folks have a quick and dirt...
by anav
Mon Nov 27, 2023 2:39 am
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 1110

Re: PCC Loadbalancing and distant Port forwarding not working

The improvements to many functions and the ability to do wireguard are huge reasons to move ahead.
If this is a home no worries, 7.12.1 is decent enough.
by anav
Mon Nov 27, 2023 2:38 am
Forum: Beginner Basics
Topic: HAP ac2 need help with load balancing on 2 WAN connections
Replies: 16
Views: 951

Re: HAP ac2 need help with load balancing on 2 WAN connections

Find that hard to believe, wireguard was not possible on vers6
edit: I didnt consider wG on another device, mia culpa!!
by anav
Mon Nov 27, 2023 2:37 am
Forum: Beginner Basics
Topic: Firewall doesn't work properly.
Replies: 14
Views: 965

Re: Firewall doesn't work properly.

The friend is not exactly wrong,,,,,, just a tad misleading. EVERY SWITCH PORT when it comes Default has vlan1 assigned to the port. WE LEAVE THAT vlan1 alone. It works in the background and can basically be ignored. We dont change any vlan1 settings anywhere. EXCEPT.......... when we make a port an...
by anav
Mon Nov 27, 2023 2:28 am
Forum: General
Topic: Route Traffic through WireGuard to Internet [SOLVED]
Replies: 20
Views: 2595

Re: Route Traffic through WireGuard to Internet [SOLVED]

SERVER Comments 1. This indicates an issue....... /interface list member add comment=defconf interface= *C list=LAN I suspect its because you have not identified any LAN list interface members and yet you have a list?? 2. This is wrong. .......... IF you have IP DHCP Client you should not have a se...
by anav
Sun Nov 26, 2023 5:41 pm
Forum: Beginner Basics
Topic: separate different networks on a MikroTik router using the bridge
Replies: 6
Views: 565

Re: separate different networks on a MikroTik router using the bridge

Seems illogical to me.
What is the purpose of buying a MIKROTIK router of that power and using it as a switch??
What am I missing???
by anav
Sun Nov 26, 2023 5:33 pm
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 1110

Re: PCC Loadbalancing and distant Port forwarding not working

Wait you are still on vers 6?? My configs are predicated on vers 7
by anav
Sun Nov 26, 2023 5:32 pm
Forum: Beginner Basics
Topic: HAP ac2 need help with load balancing on 2 WAN connections
Replies: 16
Views: 951

Re: HAP ac2 need help with load balancing on 2 WAN connections

Do you have any port forwarding?
Do you have any VPNs........
Hoelve needs to learn to find all the requirements before planning a config ;-P
by anav
Sun Nov 26, 2023 5:30 pm
Forum: Beginner Basics
Topic: Firewall doesn't work properly.
Replies: 14
Views: 965

Re: Firewall doesn't work properly.

Hi KAT,
There is no vlan1 in your config, in fact it looks like properly all the MT devices got an IP on the trusted 192.168.0.0/24 subnet. ( AKA VLAN100 )
Thus confused by the evidence in the configs contradicted by the diagram and your words??
by anav
Sun Nov 26, 2023 5:05 pm
Forum: Beginner Basics
Topic: Firewall doesn't work properly.
Replies: 14
Views: 965

Re: Firewall doesn't work properly.

(1) Which Router is the one you are referring to in the diagram?????? I am assuming the 5009!! (2) What is with vlan1 between all the MT devices, I dont see that in the router config you have??? Assuming you meant on the diagram to put vlan100 which contains the 192.168.0.0/24 (3) So you have four V...
by anav
Sun Nov 26, 2023 5:01 pm
Forum: General
Topic: WireGuard server on Windows with a MikroTik router as a client
Replies: 12
Views: 1918

Re: WireGuard server on Windows with a MikroTik router as a client

ROUTER COMMENTS ( WOW, nice setup ) (1) Not sure what you mean by this line.............. add address=10.0.20.0/24 comment="the different DNS server is used to make th\ e router use the WireGuard VPN connection for DNS queries" dns-server=\ 208.67.222.222,208.67.220.220 gateway=10.0.20.1 F...
by anav
Sun Nov 26, 2023 4:18 pm
Forum: General
Topic: WireGuard server on Windows with a MikroTik router as a client
Replies: 12
Views: 1918

Re: WireGuard server on Windows with a MikroTik router as a client

Good day, The requirements are pretty good. Who needs access to the windows server, vlan10 and vlan20 Who needs access to vlan10, vlan20 does Who gets internet from wireguard, vlan20 does. +++++++++++++++++++++++++++++++++++++++++++++++++ Its the additional requirements that get a bit murky. a. vlan...
by anav
Sun Nov 26, 2023 2:56 pm
Forum: General
Topic: Route Traffic through WireGuard to Internet [SOLVED]
Replies: 20
Views: 2595

Re: Route Traffic through WireGuard to Internet [SOLVED]

Post your config here seeing as the OPs has solved his case and thus no interference.

/export file=anynameyouwish ( minus router serial number, public WANIP information, keys, long dhcp lease lists, any ipv6 info if not using ipv6 )
by anav
Sun Nov 26, 2023 2:50 pm
Forum: General
Topic: difference in Wireguard behavior between laptop and phone
Replies: 8
Views: 840

Re: difference in Wireguard behavior between laptop and phone

1. Allowed IPs on the mikrotik side have nothing to do with routing. 2. Allowed IPs are a matching flltering function for leaving traffic and a filtering function for arriving traffic. 3. An automatic route is created for wireguard IPs by the wireguard router due to ccreating the interface IP addres...
by anav
Sun Nov 26, 2023 2:45 pm
Forum: Beginner Basics
Topic: separate different networks on a MikroTik router using the bridge
Replies: 6
Views: 565

Re: separate different networks on a MikroTik router using the bridge

Concur, one bridge and three vlans is all that is required here. Unless the fortigate cannot handle vlans? What is the purpose of the fortigate in this setup? Edge Router with some subscription services?? interface list=building one vlans 11,12,13,14 Interface list=building two vlans 21,22,23,24 int...
by anav
Sun Nov 26, 2023 2:29 pm
Forum: Beginner Basics
Topic: looking to switch to a 5g > router > AP setup
Replies: 7
Views: 653

Re: looking to switch to a 5g > router > AP setup

You came here looking for reasons to 'convince' the wife to spend money. Just wanted to help the cause by better understanding the scenario because what you initially presented was a very weak case. :-) Anything is possible between two MT routers. Use the concept provided in post #2. Trunk port betw...
by anav
Sun Nov 26, 2023 2:26 pm
Forum: Beginner Basics
Topic: Firewall doesn't work properly.
Replies: 14
Views: 965

Re: Firewall doesn't work properly.

Concur network diagram gives us context!

In addition need to see complete config again. ( not just snippet of firewall rules )
by anav
Sun Nov 26, 2023 2:24 pm
Forum: Beginner Basics
Topic: HAP ac2 need help with load balancing on 2 WAN connections
Replies: 16
Views: 951

Re: HAP ac2 need help with load balancing on 2 WAN connections

What is PPC................ In terms of requirements. a. identify all the user(s)/devices, groups of users and devices ( including admin and external users) b. identify all the traffic they require do accomplish. What is the purpose of the two WANS. Use a primary and have a secondary as backup? USE ...
by anav
Sun Nov 26, 2023 2:22 pm
Forum: Beginner Basics
Topic: Help on RM3011UiAS's DHCP Servers
Replies: 2
Views: 347

Re: Help on RM3011UiAS's DHCP Servers

Firewall ideas -->viewtopic.php?t=180838
Vlan ideas -->viewtopic.php?t=143620
by anav
Sun Nov 26, 2023 5:26 am
Forum: General
Topic: difference in Wireguard behavior between laptop and phone
Replies: 8
Views: 840

Re: difference in Wireguard behavior between laptop and phone

Good you have surmized there is no problem with your config, thus no help required.
by anav
Sun Nov 26, 2023 5:23 am
Forum: General
Topic: Problems with DNS, LAN devices can't access internet
Replies: 10
Views: 1224

Re: Problems with DNS, LAN devices can't access internet

@lostgone --> Start your own thread please.

@felipe Post your latest config
by anav
Sun Nov 26, 2023 5:20 am
Forum: Beginner Basics
Topic: Firewall doesn't work properly.
Replies: 14
Views: 965

Re: Firewall doesn't work properly.

(1) You dont understand firewall rules. Why make allow port 53 rules, but then later drop everything not coming from the LAN. In other words the port 53 rules are allowed by the rule above and thus not necessary in your setup. However, its not at all what I suggested. (2) These ones also are unnecce...
by anav
Sun Nov 26, 2023 3:54 am
Forum: Beginner Basics
Topic: Issues about wireguard connectivity on RouterOS with multiple WAN ports
Replies: 13
Views: 1174

Re: Issues about wireguard connectivity on RouterOS with multiple WAN ports

firewall rules fixed Main issue is these rules which have been axed...... add action=drop chain=input comment="defconf: drop all coming from ha_ct" \ in-interface=pppoe_ha-ct add action=drop chain=input comment="defconf: drop all coming from ha_cu" \ in-interface=pppoe_ha-cu add ...
by anav
Sun Nov 26, 2023 3:39 am
Forum: Beginner Basics
Topic: Firewall doesn't work properly.
Replies: 14
Views: 965

Re: Firewall doesn't work properly.

Change the approach of at least the forward chain, to DROP ALL. In this regard all connections between different subnets are blocked unless explicitly stated in the firewall rules. {forward chain} add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=e...
by anav
Sun Nov 26, 2023 3:36 am
Forum: General
Topic: Output route selection - Wireguard
Replies: 18
Views: 2264

Re: Output route selection - Wireguard

Same here. By using classic mangle rules such as: /ip firewall mangle add action=mark-connection chain=input connection-state=new in-interface=ether2-pppoe new-connection-mark="From WAN Telecom2" passthrough=yes add action=mark-routing chain=output connection-mark="From WAN Telecom2&...
by anav
Sun Nov 26, 2023 12:47 am
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 1110

Re: PCC Loadbalancing and distant Port forwarding not working

The above handles all the rules required.
Give that a shot and we will see how much progress is made!
by anav
Sun Nov 26, 2023 12:47 am
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 1110

Re: PCC Loadbalancing and distant Port forwarding not working

(1) Order of firewall rules fixed. (2) Its dumb to allow an entire subnet to configure the router and besides, 8291 is not a tcp protocol its udp! Created a firewall address list called authorized........ to solve.... (3) Got rid of unnecessary firewall address lists. (4) Removed logging on drop all...
by anav
Sat Nov 25, 2023 9:42 pm
Forum: General
Topic: Proton VPN suddenly stopped working
Replies: 8
Views: 1083

Re: Proton VPN suddenly stopped working

(1) Wrong order. ..... think through the logic. Will traffic from VPN subnet ever reach another local subnet with the order you have???? /routing rule add action=lookup-only-in-table disabled=no src-address=10.10.20.0/24 table=\ Proton_UK_WG add action=lookup-only-in-table disabled=no src-address=10...
by anav
Sat Nov 25, 2023 5:04 pm
Forum: Beginner Basics
Topic: Micro Tik Hex and tp link multi ap
Replies: 4
Views: 541

Re: Micro Tik Hex and tp link multi ap

You didnt read that article very closely, where the EFF does it show the bridge doing any DHPC....... ALL VLANS So take your bridge subnet and assign it to a vlan. Then you need to actually turn on bridge vlan filtering=yes......... None of your bridge ports are assigned properly for access ports or...
by anav
Sat Nov 25, 2023 5:02 pm
Forum: Beginner Basics
Topic: Issues about wireguard connectivity on RouterOS with multiple WAN ports
Replies: 13
Views: 1174

Re: Issues about wireguard connectivity on RouterOS with multiple WAN ports

Then there is something else on your config that is blocking.
Please post FULL config

/export file=anynameyouwish ( minus router serial #, public WANIP information, keys, long dhcp lease lists, IPV6 anything if not using it)
by anav
Sat Nov 25, 2023 4:54 pm
Forum: General
Topic: After Wireguard Client configuration successfully, lan area cannot access wireguard area.
Replies: 6
Views: 585

Re: After Wireguard Client configuration successfully, lan area cannot access wireguard area.

So assuming the SERVER is not third party, then the problem is also at the other end at the server end!! SeRVER CONSIDERATIONS : a. do you have 192.168.88.0/24 as allowed IPs at the server wg peer settings for router b?? b. do you have 192.168.100.2/32 as allowed IPs at the server wg peer settings f...
by anav
Sat Nov 25, 2023 4:45 pm
Forum: General
Topic: After Wireguard Client configuration successfully, lan area cannot access wireguard area.
Replies: 6
Views: 585

Re: After Wireguard Client configuration successfully, lan area cannot access wireguard area.

What is the remote wireguard server - mikrotik or something else?? Concur lets fix that sourcenat mess..... (drop the crap rule) /ip firewall nat add action=src-nat chain=srcnat dst-address=192.168.100.0/24 dst-limit=\ 1,5,dst-address/1m40s limit=1,5:packet psd=21,3s,3,1 src-address=\ 192.168.88.0/2...
by anav
Sat Nov 25, 2023 4:41 pm
Forum: Beginner Basics
Topic: Dual WAN failover, port forward not working when changing route distance
Replies: 22
Views: 1535

Re: Dual WAN failover, port forward not working when changing route distance

(1) This default rule is now replaced and should be removed. add action=drop chain=forward comment=\ "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \ connection-state=new disabled=yes in-interface-list=WAN add action=accept chain=forward comment=Internet in-interfac...
by anav
Sat Nov 25, 2023 3:04 pm
Forum: Beginner Basics
Topic: Dual WAN, but second link is used only by some LAN machines [SOLVED]
Replies: 3
Views: 521

Re: Dual WAN, but second link is used only by some LAN machines [SOLVED]

Need table /routing-table add name=useWAN2 Need route /ip route normal route ISP1 distance=2 check-gateway=ping table=main normal route ISP2 distance=4 table=main add dst-address=0.0.0.0/0 gateway=ISP2 routing-table=useWAN2 [/b] Need routing rules................. But be careful as a routing rule fo...
by anav
Sat Nov 25, 2023 2:58 pm
Forum: Beginner Basics
Topic: Issues about wireguard connectivity on RouterOS with multiple WAN ports
Replies: 13
Views: 1174

Re: Issues about wireguard connectivity on RouterOS with multiple WAN ports

Try these mangle rules. add chain=prerouting action=mark-connection connection-mark=no-mark \ in-interface=WAN2 new-connection-mark=incomingISP2 passthough=yes add chain=output action=mark-routing connection-mark=incomingISP2 \ new-routing-mark=useWAN2 passthough=no Dont forget the table. /routing t...
by anav
Sat Nov 25, 2023 5:41 am
Forum: General
Topic: After Wireguard Client configuration successfully, lan area cannot access wireguard area.
Replies: 6
Views: 585

Re: After Wireguard Client Setup successfully, lan cannot access wireguard area.

Allowed peer should be 192.168.100.0/24, not 192.168.100.1/24
by anav
Fri Nov 24, 2023 11:31 pm
Forum: General
Topic: Is WireGuard traffic invisible to Torch [SOLVED]
Replies: 2
Views: 557

Re: Is WireGuard traffic invisible to Torch [SOLVED]

The wirguard config is predicated upon the peer for a client to be the specific IP address as noted, which differentiates from the multiple peers possible.

The peer on the client or often remote device, should be the subnet and if a router then most definitely the subnet.
by anav
Fri Nov 24, 2023 5:24 pm
Forum: General
Topic: WireGuard server on Windows with a MikroTik router as a client
Replies: 12
Views: 1918

Re: WireGuard server on Windows with a MikroTik router as a client

Busy today but will look at i this weekend.
by anav
Fri Nov 24, 2023 5:22 pm
Forum: Beginner Basics
Topic: Dual WAN, but second link is used only by some LAN machines [SOLVED]
Replies: 3
Views: 521

Re: Dual WAN, but second link is used only by some LAN machines [SOLVED]

How many machines?? You can use Routing rules for entire subnets - very easy, no mangles. You can use Routing rules for a few users - very easy, no mangles. Basically it comes down to you will need a routing rule per user so it depends how many rules you would like to make. add src-address=userX-IP ...
by anav
Fri Nov 24, 2023 5:05 pm
Forum: Beginner Basics
Topic: Dual WAN failover, port forward not working when changing route distance
Replies: 22
Views: 1535

Re: Dual WAN failover, port forward not working when changing route distance

Busy today, but if you post your latest config I will spend more time on it this weekend.
by anav
Fri Nov 24, 2023 2:25 pm
Forum: Beginner Basics
Topic: 2 Vlans, a firewall, and a PITA DNS.
Replies: 3
Views: 449

Re: 2 Vlans, a firewall, and a PITA DNS.

One bridge..............
viewtopic.php?t=143620
by anav
Fri Nov 24, 2023 2:23 pm
Forum: Beginner Basics
Topic: Issues about wireguard connectivity on RouterOS with multiple WAN ports
Replies: 13
Views: 1174

Re: Issues about wireguard connectivity on RouterOS with multiple WAN ports

Too busy today to look at it, but I would scrap any mangle rules you have for wireguard.
What is required is mangle rules ensuring traffic coming in wanx, goes out wanx.
by anav
Fri Nov 24, 2023 2:19 pm
Forum: Beginner Basics
Topic: Dual WAN failover, port forward not working when changing route distance
Replies: 22
Views: 1535

Re: Dual WAN failover, port forward not working when changing route distance

I have a great idea, why dont you ask the people making vidoes for help........... The onus is ON YOU, to read the mikrotik docs and read as many threads as possible to learn. There are some decent videos out there by a few people the rest will lead you astray. Network Berg is good Network Trip is g...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 62