Community discussions

MikroTik App

Search found 23729 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 80
by anav
Sat Apr 26, 2025 6:25 pm
Forum: Beginner Basics
Topic: force subnet through specific gateway
Replies: 7
Views: 444

Re: force subnet through specific gateway

Without some diagrams nothing makes sense.
by anav
Sat Apr 26, 2025 6:22 pm
Forum: General
Topic: Dual WAN Failover script - feedback pls
Replies: 3
Views: 234

Re: Dual WAN Failover script - feedback pls

Will stick to recursive, works and is much easier or via netwatch if one doesnt want to wait 10 seconds etc....
by anav
Sat Apr 26, 2025 6:21 pm
Forum: General
Topic: Can not access the CPU via incomming vlan !! :(
Replies: 5
Views: 357

Re: Can not access the CPU via incomming vlan !! :(

Well, its pretty straightforward...... Only one vlan is identified on the switch, the management vlan and in IP address is where switch gets its IP address from. Only the managment vlan is tagged with the bridge, the rest are tagged on the incoming trunk port and as required on outgoing ports ( unta...
by anav
Sat Apr 26, 2025 4:29 am
Forum: General
Topic: Can not access the CPU via incomming vlan !! :(
Replies: 5
Views: 357

Re: Can not access the CPU via incomming vlan !! :(

Is this the same device that mkx was trying to help you with??
by anav
Fri Apr 25, 2025 7:59 pm
Forum: Beginner Basics
Topic: Primary gateway with static ip address not activating
Replies: 15
Views: 715

Re: Primary gateway with static ip address not activating

You didnt get rid of raw rules................
by anav
Fri Apr 25, 2025 7:08 pm
Forum: Beginner Basics
Topic: force subnet through specific gateway
Replies: 7
Views: 444

Re: force subnet through specific gateway

draw a network diagram.
Do you mean you have two WAN connections?
Do you mean you have two Subnets?

Etc..............
by anav
Fri Apr 25, 2025 7:06 pm
Forum: Wireless Networking
Topic: hEX and CAP ac
Replies: 3
Views: 304

Re: hEX and CAP ac

I use my capacs with my hex without capsman its quick and easy to config. Your hair will not turn gray or fall out!!
by anav
Fri Apr 25, 2025 7:05 pm
Forum: General
Topic: Dual WAN failover - check internet
Replies: 12
Views: 557

Re: Dual WAN failover - check internet

Sweet!!
by anav
Fri Apr 25, 2025 7:04 pm
Forum: General
Topic: WireGuard connectivity issue assistance
Replies: 4
Views: 318

Re: WireGuard connectivity issue assistance

You have hidden way to much information, just the WAN public information and the only thing that would relevent is the username and password on pppoe. 1. Improve Interface list entries, but I dont see a trusted or management vlan?? Ahh you are mixing apples and oranges. Once you go vlans so will cha...
by anav
Fri Apr 25, 2025 6:44 pm
Forum: General
Topic: Dual WAN failover - check internet
Replies: 12
Views: 557

Re: Dual WAN failover - check internet

Netwatch leaks out any wan to find a connection and thus you need to blackhole any netwatch routing with a second following route same table distance add one.
by anav
Fri Apr 25, 2025 6:39 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1098

Re: WireGuard Traffic Issue

Then setup vlan filtering now and once its smooth, do the wireguard, should take me 10minutes to fix once you have an initial config its like butta. First however, its best to work the config from an OFF the bridge position. What i recommend is create an offbridge port for local emergency access. So...
by anav
Fri Apr 25, 2025 6:38 pm
Forum: General
Topic: Reliable addresses to ping on internet
Replies: 19
Views: 763

Re: Reliable addresses to ping on internet

Yearly rate of $20,000, that an over 50% markdown sale!! Get it while its hot!
by anav
Fri Apr 25, 2025 6:36 pm
Forum: General
Topic: Respond for the internet connection through which they connect.
Replies: 3
Views: 346

Re: Respond for the internet connection through which they connect.

As you may have guessed the responders have some WHAT IFs, and other suggestions ( and also some errors). In other words, you should not be asking for a part solution if the requirements are not fully identified. A better response can be had when we know what else is going on the router for both inc...
by anav
Fri Apr 25, 2025 6:32 pm
Forum: General
Topic: Reliable addresses to ping on internet
Replies: 19
Views: 763

Re: Reliable addresses to ping on internet

You can use mine, only 5c per ping.
by anav
Fri Apr 25, 2025 1:44 pm
Forum: Beginner Basics
Topic: Primary gateway with static ip address not activating
Replies: 15
Views: 715

Re: Primary gateway with static ip address not activating

This is a clue that the router is not happy with your config....... /interface list member add comment=defconf interface=bridge list=LAN add comment=defconf interface=ether1 list=WAN add interface= *9 list=WAN add interface=ether2 list=WAN /ipv6 dhcp-client add add-default-route=yes interface =*9 po...
by anav
Fri Apr 25, 2025 1:38 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1098

Re: WireGuard Traffic Issue

The point is wireguard is not the real issue at the moment. Once the config is fixed, then we will be able to see whats going with wireguard, if its still a problem.
by anav
Fri Apr 25, 2025 4:47 am
Forum: General
Topic: Confused about Bridge PVID 1
Replies: 10
Views: 589

Re: Confused about Bridge PVID 1

Put cement in the serial port ;-P
by anav
Thu Apr 24, 2025 9:28 pm
Forum: General
Topic: Confused about Bridge PVID 1
Replies: 10
Views: 589

Re: Confused about Bridge PVID 1

also add
/ip neighbours discovery
set interface-list=TRUSTED


The option to change the pvid of the bridge exists because in some niche situations it may be required.
I would say its rare but I dont know enought to state what weird setups this would make sense for.
by anav
Thu Apr 24, 2025 8:58 pm
Forum: General
Topic: Confused about Bridge PVID 1
Replies: 10
Views: 589

Re: Confused about Bridge PVID 1

1. Any port not being used should be a. disabled preferably OR b. at least removed from bridge c. the bridge itself retain default pvid but set frame-types=admit-only-vlan-tagged. d. on ports being used, ensure ingress-filtering is enabled and frame types set as required ( either vlan tagged, OR pri...
by anav
Thu Apr 24, 2025 8:50 pm
Forum: Beginner Basics
Topic: Primary gateway with static ip address not activating
Replies: 15
Views: 715

Re: Primary gateway with static ip address not activating

a diagram and revised cleaned up config may help us provide better assistance.
by anav
Thu Apr 24, 2025 8:37 pm
Forum: Beginner Basics
Topic: hEX refresh/ as Switch ->Pros & Cons?
Replies: 22
Views: 1058

Re: hEX refresh/ as Switch ->Pros & Cons?

One flat network or vlans? diagram will help understand
by anav
Thu Apr 24, 2025 8:33 pm
Forum: General
Topic: Defeated by VLAN issue [SOLVED]
Replies: 9
Views: 583

Re: Defeated by VLAN issue [SOLVED]

Okay, so depending upon the ability of the unmanaged switch then we have two options and one, both, or none may work. a. make it a trunk port to the un-managed switch both vlans tagged b. make it a hybrid port to the un-managed switch, tagged for one, and untagged for the other. May the best option ...
by anav
Thu Apr 24, 2025 8:01 pm
Forum: Beginner Basics
Topic: Primary gateway with static ip address not activating
Replies: 15
Views: 715

Re: Primary gateway with static ip address not activating

Yes please, clean up the config, garbage is noise and noise makes it difficult to read a config OR to spot errors..........
by anav
Thu Apr 24, 2025 7:30 pm
Forum: Beginner Basics
Topic: hEX refresh/ as Switch ->Pros & Cons?
Replies: 22
Views: 1058

Re: hEX refresh/ as Switch ->Pros & Cons?

Any hex device makes a great little managed switch that works great in a home setting or even an office setting. If one is in a corporate setting where, for example, the same vlan spans two or more ports on the switch, to users that will be sending huge amounts of data back and forth across the swit...
by anav
Thu Apr 24, 2025 7:27 pm
Forum: General
Topic: WireGuard connectivity issue assistance
Replies: 4
Views: 318

Re: WireGuard connectivity issue assistance

Best to provide your config for review /export file=anynameyouwish (minus router serial number, any public WANIP information, keys),.\ Steps 1. Take the private key given to you and when you make an interface on the MT router, use that private key to generate a public key ( that way windscribe alrea...
by anav
Thu Apr 24, 2025 7:06 pm
Forum: General
Topic: Defeated by VLAN issue [SOLVED]
Replies: 9
Views: 583

Re: Defeated by VLAN issue [SOLVED]

There are several options. a. connect PC requiring vlan 10 directly to the audience OR ax3 b. replace the un-managed switch with a managed switch (could even be a hex) and then send the two vlans to the new device 10,20 c. buy a second cheap unmanaged switch untagged to vlan 10 and then plug in the ...
by anav
Thu Apr 24, 2025 5:35 pm
Forum: General
Topic: Defeated by VLAN issue [SOLVED]
Replies: 9
Views: 583

Re: Defeated by VLAN issue [SOLVED]

Please draw a network diagram because the explanation muddles devices relationship and clarity is required.
In general, the management vlan needs to go to all smart devices ( such as the audience) as smart devices should get their IP address from the managment vlan.
by anav
Thu Apr 24, 2025 5:32 pm
Forum: General
Topic: Can't re-add peer key Wireguard
Replies: 1
Views: 199

Re: Can't re-add peer key Wireguard

The information you have provided is sparse. In general on your mikrotik you generate a private key and public key ("######" ) when creating the wireguard interface and lets say create an address like 10.20.30.1/24 with listening port of 51280. The public key is for use on the peer or remo...
by anav
Thu Apr 24, 2025 5:24 pm
Forum: Beginner Basics
Topic: Primary gateway with static ip address not activating
Replies: 15
Views: 715

Re: Primary gateway with static ip address not activating

Not sure how pppoe works but for security purposes, would remove any username passwords and any public IP address associated from your config. 1. As to the config I didnt get past your IP addressess which are wrong. You have ONE bridge, and one subnet and pool and address associated so not sure what...
by anav
Thu Apr 24, 2025 2:24 pm
Forum: Beginner Basics
Topic: Hex refresh download speed
Replies: 17
Views: 1686

Re: Hex refresh download speed

Liina, this is NOT your thread, it was started by Hiutale, suggest you start your own thread, to narrow down your specific issues and get assistance.
In other words, we are not focussed on your problems in this thread, so getting upset here, is not going to get you anywhere.
by anav
Thu Apr 24, 2025 2:19 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1098

Re: WireGuard Traffic Issue

Im saying a bridge gets one address, if you want different subnets you can cover ports A-F with the same subnet and single bridge and use different addresses for ports G,H,I NOT on the bridge, as that will cover three different subnets. OR use one bridge and assign as many vlans as you need (subnets...
by anav
Thu Apr 24, 2025 2:16 pm
Forum: General
Topic: Block youtube/facebook using Layer 7 working perfect and blocking on pc and phones
Replies: 2
Views: 390

Re: Block youtube/facebook using Layer 7 working perfect and blocking on pc and phones

Just dont use the internet, there are too many ways around non DPI solutions........
by anav
Thu Apr 24, 2025 2:21 am
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 2098

Re: AX3 as basic AP/switch

Any sailor worth their salt, knows that a vessel is used for drinking!! Drinkware, beverageware (in other words, cups, jugs and ewers) is a general term for a vessel intended to contain beverages or liquid foods for drinking or consumption. The word cup comes from Middle English cuppe, from Old Engl...
by anav
Thu Apr 24, 2025 12:56 am
Forum: Beginner Basics
Topic: Hex refresh download speed
Replies: 17
Views: 1686

Re: Hex refresh download speed

How do you get 940Mb upload??? Thats amazing........ No firewall rules??? hEX refresh can route 1430 Mbps based on the official test results when using large packet size. Interesting using large packet size has never given me accurate results but the smaller 512 byte size does match my real world r...
by anav
Thu Apr 24, 2025 12:52 am
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 2098

Re: AX3 as basic AP/switch

For MKX, just to be clear, a submarine is NOT a ship! ;-)
by anav
Wed Apr 23, 2025 7:08 pm
Forum: Beginner Basics
Topic: Load Balancing and Failover not working with my VPN connection
Replies: 4
Views: 334

Re: Load Balancing and Failover not working with my VPN connection

Also the MT config
/export file=anynameyouwish (minus router serial number, any public WANIP information, keys )
by anav
Wed Apr 23, 2025 7:07 pm
Forum: Beginner Basics
Topic: Stops Responding [SOLVED]
Replies: 10
Views: 2114

Re: Stops Responding [SOLVED]

Also I recommend taking one of the unused ports on the switch and make it an OFF BRIDGE access port, but will wait to see the config.
by anav
Wed Apr 23, 2025 4:39 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1098

Re: WireGuard Traffic Issue

Each vlan is created with interface being bridge. Each vlan gets its own dhcp server, ip pool, dhcp-server network AND!!! own IP address ( not a sniff of bridge on these subnet config lines ). The only other place vlans and bridges are mixed is /interface bridge port and /interface bridge lans.
by anav
Wed Apr 23, 2025 4:36 pm
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 2098

Re: AX3 as basic AP/switch

Same with the PHY? Functionality onboard is a subset of available options?
by anav
Wed Apr 23, 2025 3:14 pm
Forum: Beginner Basics
Topic: Hex refresh download speed
Replies: 17
Views: 1686

Re: Hex refresh download speed

How do you get 940Mb upload??? Thats amazing........ No firewall rules???
by anav
Wed Apr 23, 2025 3:08 pm
Forum: General
Topic: Wireguard issue - L009
Replies: 7
Views: 590

Re: Wireguard issue - L009

Repost the config, when done if still having problems.
by anav
Wed Apr 23, 2025 2:26 pm
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 2098

Re: AX3 as basic AP/switch

According to AI..........In diagrams, the CPU is typically represented by a rectangular box, often colored dark grey or black. The switch chip, which facilitates communication between different parts of a network, is often shown as a similar rectangular or square box, but colored light blue, orange,...
by anav
Tue Apr 22, 2025 11:10 pm
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 2098

Re: AX3 as basic AP/switch

Concur, well stated.
Yes, if one has heavy VLAN traffic ( same vlan ) between different ports on the switch, the ax3 whether its a switch or a router will see some slow down in traffic, whereas a proper switch will not.
by anav
Tue Apr 22, 2025 9:58 pm
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 2098

Re: AX3 as basic AP/switch

I use my ax3 with vlan filtering and I see no ill effects on my LAN subnets...............
by anav
Tue Apr 22, 2025 9:56 pm
Forum: General
Topic: Wireguard issue - L009
Replies: 7
Views: 590

Re: Wireguard issue - L009

My issue with the config is two bridges. Keep it simple, one bridge. Ditch the wrongly named one about vlan10 as you have multiple vlans on that bridge, not just 10. Move the default vlan subnet 88 to a vlan, call it vlan-default. As was pointed out you have two related discrepancies to deal with. a...
by anav
Tue Apr 22, 2025 7:10 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1098

Re: WireGuard Traffic Issue

The config is far to complex for my level of understanding, however I will say that you give away addresses like candy to kids, and as far as I understand the single bridge should not have multiple IP addresses, nor probably any single etherport............ /ip address add address=192.168.100.254/24...
by anav
Tue Apr 22, 2025 1:55 pm
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 2098

Re: AX3 as basic AP/switch

Why waste a vlan capable device when a flat unmanaged switch will do?
by anav
Mon Apr 21, 2025 7:06 pm
Forum: Beginner Basics
Topic: Port Forwarding via WireGuard Tunnel
Replies: 1
Views: 322

Re: Port Forwarding via WireGuard Tunnel

ON VPS FIX the wireguard peers TO: /interface wireguard peers add allowed-address= 192.168.254.2 , 192.168.100.0/24 interface=WG_VPS \ name=peer_WG_VPS public-key= "----" Remove the funky nat rule. /ip firewall nat add action=dst-nat chain=dstnat comment=\ "RDP-Forwarding to local Ro...
by anav
Mon Apr 21, 2025 12:28 pm
Forum: Beginner Basics
Topic: Port forwarding
Replies: 15
Views: 1310

Re: Port forwarding

So you are using a third party APP to access your feed. Have you thought about the fact that you have to forward a port on your router to everyone in the world............ I have three different types of video cameras in the house and I dont forward a single port and I also use an APP to view them. ...
by anav
Mon Apr 21, 2025 12:22 pm
Forum: General
Topic: Looking for advice Hiding my IP to show up other IP [SOLVED]
Replies: 5
Views: 2077

Re: Looking for advice Hiding my IP to show up other IP [SOLVED]

concur, as stated, your best bet is to have all the others use WAN2 and your family only use wan1.
by anav
Mon Apr 21, 2025 12:56 am
Forum: Beginner Basics
Topic: Why does this not work (very basic setup)
Replies: 11
Views: 795

Re: Why does this not work (very basic setup)

It would seem your double posting, which is verbotten.
Will follow your thread here............... viewtopic.php?t=216313
by anav
Mon Apr 21, 2025 12:54 am
Forum: Beginner Basics
Topic: Why does this not work (very basic setup)
Replies: 11
Views: 795

Re: Why does this not work (very basic setup)

Without the config, all i here is opinion of some things that may or may not be relevant, its akin to hearing blah blah blah....
Please post the config for assistance.
/export file=anynameyouwish ( minus router serial number and any public WANIP information (probably none as this is a switch)
by anav
Sun Apr 20, 2025 6:20 pm
Forum: Beginner Basics
Topic: No DNS on wlan
Replies: 1
Views: 351

Re: No DNS on wlan

You have remnants of the default config 1. From: /ip dhcp-server network add address=192.168.119.0/24 comment=defconf dns-server= 192.168.88.1 gateway=192.168.119.1 netmask=24 TO: /ip dhcp-server network add address=192.168.119.0/24 comment=defconf dns-server= 192.168.119.1 gateway=192.168.119.1 net...
by anav
Sun Apr 20, 2025 6:10 pm
Forum: Beginner Basics
Topic: Why does this not work (very basic setup)
Replies: 11
Views: 795

Re: Why does this not work (very basic setup)

Review the video and when you have something close post here for review/comments
/export file=anynameyouwish ( minus router serial number, any PUBLIC WANIP information )
by anav
Sun Apr 20, 2025 6:08 pm
Forum: Beginner Basics
Topic: Why does this not work (very basic setup)
Replies: 11
Views: 795

Re: Why does this not work (very basic setup)

The article provided and video only show one bridge. To configure the switch the best thing for you do to is take one port OFF the bridge and do all your configuring from this safe spot. Configuring OffBridge So remove ether24 from /interface bridge port Modify the following entry /ethernet set [ fi...
by anav
Sun Apr 20, 2025 2:45 pm
Forum: Beginner Basics
Topic: Port forwarding
Replies: 15
Views: 1310

Re: Port forwarding

I would revise the following: From: add action=drop chain=forward comment=\ "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \ connection-state=new in-interface-list=WAN add action=passthrough chain=forward comment=CAM dst-address=192.168.88.30 \ dst-port=80 protocol=...
by anav
Sat Apr 19, 2025 7:57 pm
Forum: Beginner Basics
Topic: Hairpin NAT with dynamic WAN IP [SOLVED]
Replies: 12
Views: 2490

Re: Hairpin NAT with dynamic WAN IP [SOLVED]

Not that I am aware of sorry.

But perhaps this explains the situation best:
..................
usetherighttool.jpg
by anav
Sat Apr 19, 2025 5:32 pm
Forum: General
Topic: Failover RouterOS v7
Replies: 9
Views: 725

Re: Failover RouterOS v7

Fixed, thanks!
by anav
Fri Apr 18, 2025 8:06 pm
Forum: Beginner Basics
Topic: Question VLAN Setup [SOLVED]
Replies: 12
Views: 2781

Re: Question VLAN Setup [SOLVED]

No I said, a. if you only have one vlan per port then you dont really need vlans. b. also since this is a lab environment then you dont need any security. c. if you are trying to practice for real world setups then it would be nutso to have to manage 10 or more devices (config them) using all the di...
by anav
Fri Apr 18, 2025 6:02 pm
Forum: Beginner Basics
Topic: Question VLAN Setup [SOLVED]
Replies: 12
Views: 2781

Re: Question VLAN Setup [SOLVED]

Why do you want vlans? There is no need, there is never a duplication of any subnet over a single port? In reality, every device would be on a managed vlan, so every device would have at least two vlans coming in a trunk port. Suggest you look at basic videos and read this article. https://forum.mik...
by anav
Fri Apr 18, 2025 5:00 pm
Forum: Forwarding Protocols
Topic: Dual wan connexion from winbox
Replies: 3
Views: 4031

Re: Dual wan connexion from winbox

The problem is that your requirement is not clearly stated. Do you mean, I wish to access my Router while at a remote location? OR Do you mean I wish to access my router while on the LAN of ISP1 modem/router or on the LAN of the ISP2 modem/router. (hint they are not strictly modems if they get a sta...
by anav
Fri Apr 18, 2025 3:19 pm
Forum: Beginner Basics
Topic: Bridging WAN to VLAN [SOLVED]
Replies: 9
Views: 2460

Re: Bridging WAN to VLAN [SOLVED]

I dont understand the first post.
Why cannot you simply make the devices available via port forwarding.
How can you expose devices to the internet if you only have one WANIP address, dont you need a block of public IP addresses??
by anav
Fri Apr 18, 2025 3:04 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1098

Re: WireGuard Traffic Issue

It should work so there may be something else in your config interfering.
/export file=anynameyouwish ( minus router serial number, any public WANIP information, keys )
by anav
Fri Apr 18, 2025 2:15 pm
Forum: Beginner Basics
Topic: Help with hAP ax lite access point [SOLVED]
Replies: 8
Views: 2341

Re: Help with hAP ax lite access point [SOLVED]

It has two chains, and thus thought the default would include wifi1 andw ifi2 so at least the op could provide coverage for two freqs.....oh well. Nope. Only 2.4Ghz radio so only wifi1. 2 chains does not mean 2 radios. Reminds me to ask you, why do they even state the number of chains, its like use...
by anav
Fri Apr 18, 2025 2:11 pm
Forum: Beginner Basics
Topic: Hairpin NAT with dynamic WAN IP [SOLVED]
Replies: 12
Views: 2490

Re: Hairpin NAT with dynamic WAN IP [SOLVED]

Mikrotik provides its own domain URL in IP CLOUD use that.........
https://help.mikrotik.com/docs/spaces/R ... Cloud-DDNS
by anav
Fri Apr 18, 2025 2:05 pm
Forum: General
Topic: Reset RouterOS without losing remote access (Winbox/SSH)
Replies: 21
Views: 1360

Re: Reset RouterOS without losing remote access (Winbox/SSH)

How can you eat an apple but keep it intact ?

You can not.
I disagree, a whale can swallow it whole....... and then regurgitate it back whole.
by anav
Thu Apr 17, 2025 11:20 pm
Forum: General
Topic: Failover RouterOS v7
Replies: 9
Views: 725

Re: Failover RouterOS v7

VERSION7 instituted some changes mostly to the way of using scope and target scope.......... Nested using a faux address for two canary selections. /ip route add dst-address=0.0.0.0/0 gateway=10.10.10.10 scope=10 target-scope=14 add distance=2 check-gateway=ping dst-address=10.10.10.10/32 gateway=9....
by anav
Thu Apr 17, 2025 10:32 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1098

Re: WireGuard Traffic Issue

If WAN1 is your primary WAN ( and WAN2 is rarely used ), then it stands to reason that all your wireguard users have WAN1 as their endpoint address. To test if the router will switch to WAN2 automatically, due to distance in route difference, please do not SWAP distances. To test simply unplug inter...
by anav
Thu Apr 17, 2025 5:20 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1098

Re: WireGuard Traffic Issue

Your testing method may be flawed.
If you swap distances on the WANs, do you also change the endoint address to WAN2 for the device??
You need to NOT change the WAN distance, simply unplug the cable from wan1 into the router.
by anav
Thu Apr 17, 2025 1:35 pm
Forum: General
Topic: How to use Mikrotik router as a “switch”?
Replies: 13
Views: 47497

Re: How to use Mikrotik router as a “switch”?

What kind of switch, like an unmanaged switch with one flat network OR switch with multiple vlans?
by anav
Thu Apr 17, 2025 1:32 pm
Forum: General
Topic: Firewall to block Facebook but allow WhatsApp?
Replies: 8
Views: 752

Re: Firewall to block Facebook but allow WhatsApp?

Without a router with (DPI) and like services that looks at encrypted packets there is no foolproof way...........
by anav
Thu Apr 17, 2025 1:28 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1098

Re: WireGuard Traffic Issue

In a dual wan scenario where WAN2 is secondary lets say by distance and your current setup is for users to connect to WAN1 address, when WAN1 fails ( is no longer available ), the router will move wireguard traffic to WAN2 after a short delay. I havent tested that lately but it used to be the case. ...
by anav
Wed Apr 16, 2025 11:22 pm
Forum: General
Topic: Firewall to block Facebook but allow WhatsApp?
Replies: 8
Views: 752

Re: Firewall to block Facebook but allow WhatsApp?

How do the users get their access,,,,,,,,, if by WIFI, then turn off access point or WLANs at a certain time.
by anav
Wed Apr 16, 2025 10:42 pm
Forum: General
Topic: 2kbps DNS-Resolution Spam for cloud.mikrotik.com from detect-interface feature
Replies: 9
Views: 862

Re: 2kbps DNS-Resolution Spam for cloud.mikrotik.com from detect-interface feature

I would add mkx, an admin using MT equipment would probably be trained to some degree to use the equipment in an enterprise networking position. I wonder if any of the certs cover detect internet. OR,
to have at least read viewtopic.php?t=215004 ;-) Item 5
by anav
Wed Apr 16, 2025 10:41 pm
Forum: General
Topic: Why does ROS allow the creation of a route table with the same name?
Replies: 8
Views: 695

Re: Why does ROS allow the creation of a route table with the same name?

Perhaps they never coded to detect and warn about duplicates.....??
by anav
Wed Apr 16, 2025 8:26 pm
Forum: General
Topic: How many VLANs?
Replies: 18
Views: 1067

Re: How many VLANs?

I have heard ubiquiti is so designed but never have read TPLink Aps were particularly useful in dense environments.......
by anav
Wed Apr 16, 2025 8:00 pm
Forum: General
Topic: Allow for some devices, Internet access for 1 hour each day [SOLVED]
Replies: 18
Views: 2605

Re: Allow for some devices, Internet access for 1 hour each day [SOLVED]

Concur unless you set DHCP static lease to phones with randomizer turned off and do not let any other leases occur
by anav
Wed Apr 16, 2025 7:44 pm
Forum: Beginner Basics
Topic: What is the purpose of client-dns setting in wireguard
Replies: 6
Views: 1981

Re: What is the purpose of client-dns setting in wireguard

Good question, the answer is there is no certainty in the ways of MT programmers regarding wireguard. There is lots wrong with the implementation or GUI or display of information to the admin in RoS regarding wireguard. Typically we dont change our local DNS based on wireguard settings, we simply us...
by anav
Wed Apr 16, 2025 7:35 pm
Forum: Beginner Basics
Topic: Router configuration - basic
Replies: 4
Views: 546

Re: Router configuration - basic

I hear wifi coming and CRS326 and assuming this router will replace the ASUS. Thus I am assuming you will have more than just one flat network and are planning on vlans? [ if not, send me your CRS326 and I will send you my un-managed switch ;-) ] Also there is nothing secret about your private IP ad...
by anav
Wed Apr 16, 2025 3:17 pm
Forum: General
Topic: How many VLANs?
Replies: 18
Views: 1067

Re: How many VLANs?

So you want to get into an argument. Nope … stop using MikroTik wireless and all your limiting factors go away. Yes multiple AP’s provide the required balance and improved performance … Ubiquiti, TP-Link dedicated Access points provide exceptional value for installations thatn require special purpo...
by anav
Wed Apr 16, 2025 2:33 pm
Forum: General
Topic: How many VLANs?
Replies: 18
Views: 1067

Re: How many VLANs?

So you want to get into an argument. Then tell me how many WLANs can a single ax3 PRACTICALLY provide.................. ( and remember your the one jumping up and down about network performance !!! ) NOT as many vlans as I have in my house thats for sure............ So one has to use multiple APs to...
by anav
Wed Apr 16, 2025 2:24 pm
Forum: Beginner Basics
Topic: Overview of WireGuard packet flow
Replies: 3
Views: 616

Re: Overview of WireGuard packet flow

Yes, one needs the handshake negotiation to take place via the input chain and then manage traffic exiting and entering the tunnel from the LAN (forward chain)
by anav
Wed Apr 16, 2025 2:16 pm
Forum: General
Topic: How many VLANs?
Replies: 18
Views: 1067

Re: How many VLANs?

First, No one is going to hold your hand and tell you what is the optimal number of vlans. Second: The creation of vlans is to segment your network into logical manageable entities/functions and thats a personal choice. Some may prefer lumping all IOT devices into one vlan, and some might separate t...
by anav
Wed Apr 16, 2025 1:58 pm
Forum: General
Topic: How many VLANs?
Replies: 18
Views: 1067

Re: How many VLANs?

Its the only perspective! Trying to reduce the number of vlans, is not a valid requirement, its convenience at best. You create the vlans based on the functions your network will be performing. This is both logical and practical and easy to manage. One of the valid overall requirements for a network...
by anav
Wed Apr 16, 2025 1:48 pm
Forum: General
Topic: How many VLANs?
Replies: 18
Views: 1067

Re: How many VLANs?

One should view it as, if a device was compromised, what can it then attack........................... simple question. There is no RIGHT answer, its personal , and what level of comfort you have exposing devices to other devices be they IOT, media, voip, laptops, smartphones etc....... . PS Erlinde...
by anav
Tue Apr 15, 2025 9:54 pm
Forum: Beginner Basics
Topic: Suggestions for hAP ac2 configuration
Replies: 10
Views: 783

Re: Suggestions for hAP ac2 configuration

Hex S refresh router with two Access points, very few access points handle 70 clients very well.
If stuck on one AP, look at High density access point brands look at wifi6 as a minimum ubiquiti, RUKUS etc........
by anav
Tue Apr 15, 2025 8:08 pm
Forum: Beginner Basics
Topic: Doubt about bridges
Replies: 1
Views: 304

Re: Doubt about bridges

use firewall rule to allow it
by anav
Tue Apr 15, 2025 8:05 pm
Forum: Beginner Basics
Topic: Help with hAP ax lite access point [SOLVED]
Replies: 8
Views: 2341

Re: Help with hAP ax lite access point [SOLVED]

It has two chains, and thus thought the default would include wifi1 andw ifi2 so at least the op could provide coverage for two freqs.....oh well.
by anav
Tue Apr 15, 2025 1:56 pm
Forum: Beginner Basics
Topic: Help with hAP ax lite access point [SOLVED]
Replies: 8
Views: 2341

Re: Help with hAP ax lite access point [SOLVED]

Assuming one flat network........... First create a safe place to config the router, an off bridge port ( remove from /interface bridge ports) and then you will be able to change the main IP structure of the haplite without issue to that of the upstream router without locking yourself out. After ens...
by anav
Tue Apr 15, 2025 1:44 pm
Forum: Beginner Basics
Topic: Masquerading errors but not sure how to fix.
Replies: 3
Views: 556

Re: Masquerading errors but not sure how to fix.

why did you mess with default firewall rules, and then mix up chains etc...... Seems like you are hosting RDP.........its not the best security practice anymore hint........ Also you seem to think its okay to have your winbox port (still in default) to be accessible over the WWW and not via VPN. I h...
by anav
Tue Apr 15, 2025 1:37 pm
Forum: General
Topic: 2kbps DNS-Resolution Spam for cloud.mikrotik.com from detect-interface feature
Replies: 9
Views: 862

Re: 2kbps DNS-Resolution Spam for cloud.mikrotik.com from detect-interface feature

For me the question is, to default ON or disabled. Seeing as the majority of users end up turning this OFF and it does create traffic probably unbeknownst to most, it should really be defaulted to disabled. The associated MT doc page is perhaps vague on its purpose and seems to indicate it is OFF by...
by anav
Mon Apr 14, 2025 10:11 pm
Forum: General
Topic: hAP AC2 vs. AX2...
Replies: 20
Views: 1627

Re: hAP AC2 vs. AX2...

No idea where the parts for MT devices are made or where assembled for that matter.
Concur, eap245 was great, and yes omada sucks, all good when manually configured.
Most people stream video these days!!
by anav
Mon Apr 14, 2025 9:50 pm
Forum: General
Topic: Erratic Behavior of Winbox ROS 7
Replies: 1
Views: 316

Re: Erratic Behavior of Winbox ROS 7

Yes, using winbox 3, typically it happens 1, 2 or 3 times in a row but never more.
I resolve by closing all the open windows, and that seems to help.
No such issues with winbox4
by anav
Mon Apr 14, 2025 9:49 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 2076

Re: Using CRS326 as a switch

Smells like MT testosterone in here! ;-PP
by anav
Mon Apr 14, 2025 8:20 pm
Forum: Beginner Basics
Topic: Forwarding port behind NAT and FW to router
Replies: 3
Views: 413

Re: Forwarding port behind NAT and FW to router

Please state MT model.. A switch is not a router?? Although RoS lets one do so, it most cases its a bad idea.
by anav
Mon Apr 14, 2025 8:17 pm
Forum: Beginner Basics
Topic: Question about unknown IP address trying to connect though capsman
Replies: 11
Views: 947

Re: Question about unknown IP address trying to connect though capsman

Another nail in the coffin for Capsman if you ask me, if the directions are so vague or out there that this happens, its not worth its weight in chicken feathers or whatever......... argg disgusted...... https://help.mikrotik.com/docs/spaces/ROS/pages/7962638/CAPsMAN Nary a peep I could find about c...
by anav
Mon Apr 14, 2025 6:08 pm
Forum: Beginner Basics
Topic: Quick setup without using 192.168.88.1
Replies: 2
Views: 412

Re: Quick setup without using 192.168.88.1

What I suggest is you configure the router from a safe spot to make subnet changes and later if you use vlans. Take etherX like ether5 OFF the bridge in /interface bridge ports So it looks like /interface ethernet set [ find default-name=ether5 ] name=OffBridge5 /ip address add address=192.168.77.1/...
by anav
Mon Apr 14, 2025 5:39 pm
Forum: Beginner Basics
Topic: PPPOE with static IP
Replies: 20
Views: 1569

Re: PPPOE with static IP

1. FROM /interface list add name=WAN TO /interface list add name=WAN add name=LAN 2. FROM /interface list member add disabled=yes interface=pppoe-out1 list=WAN add disabled=yes interface=ether1 list=WAN TO /interface list member add disabled= NO interface=pppoe-out1 list=WAN add disabled= NO interfa...
by anav
Mon Apr 14, 2025 2:52 pm
Forum: Beginner Basics
Topic: Problem with internet access on router
Replies: 6
Views: 821

Re: Problem with internet access on router

rplant ur killen me, whats your address will send you the game whackamole.
Please ask for config LOL
/export file=anynameyouwish ( minus router serial number, any public WANIP information, vpn keys etc.)(
by anav
Mon Apr 14, 2025 2:50 pm
Forum: Beginner Basics
Topic: Overview of WireGuard packet flow
Replies: 3
Views: 616

Re: Overview of WireGuard packet flow

Conceptually speaking you only need two tunnels or two interfaces. The one for you to use your own internet while at a remote location (0.0.0.0/0) has to be on its own Wireguard interface. Also, consider the traffic coming out of the tunnel and hitting your router, being subject to firewall rules as...
by anav
Mon Apr 14, 2025 2:37 pm
Forum: Beginner Basics
Topic: Question about unknown IP address trying to connect though capsman
Replies: 11
Views: 947

Re: Question about unknown IP address trying to connect though capsman

Danger Danger: Its amazing your ISP has not blocked you yet. WELL you attract flies with honey and you lay a big fricken goose egg here add action=log chain=input connection-state=new dst-port=53 log-prefix="TCP 53" protocol=tcp Inviting the whole world to use your router for DNS. I would...
by anav
Mon Apr 14, 2025 2:17 pm
Forum: General
Topic: hAP AC2 vs. AX2...
Replies: 20
Views: 1627

Re: hAP AC2 vs. AX2...

By the way, I hope you do know about controversy around TP-Link... I see you have been recommending them here and there. Yes, tp link routers, not access points and in reality, CISCO had issue in the past in the same vein, as guess what most devices are made in China so, do you think parts can get ...
by anav
Mon Apr 14, 2025 2:05 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 2076

Re: Using CRS326 as a switch

I wouldnt take forum responses personally, they are of no consequence. People here are free to speak their mind, sometimes its refreshing and eye opening and humbling. I make posts based on what I know, and if someone better comes along, who actually knows their stuff, I am all the better for it. (E...
by anav
Sun Apr 13, 2025 11:18 pm
Forum: Beginner Basics
Topic: Question about unknown IP address trying to connect though capsman
Replies: 11
Views: 947

Re: Question about unknown IP address trying to connect though capsman

Bad actors/bots are constantly hammering ALL routers, nature of the beast. There is no point logging it and nothing you can do.
However it would not hurt to have your setup/config reviewed to ensure its not getting special attention for some reason.
by anav
Sun Apr 13, 2025 10:54 pm
Forum: Wireless Networking
Topic: chateau pro ax
Replies: 3
Views: 512

Re: chateau pro ax

The what, I cannot find any such model.
I see the Chateau 5G AX??

There will be no appreciable difference.
Suggest considering TPlink and Zyxel wifi 7 products.
OR
add another MT product in the home for better coverage capax for example.
by anav
Sun Apr 13, 2025 10:44 pm
Forum: Beginner Basics
Topic: Question VLAN Setup [SOLVED]
Replies: 12
Views: 2781

Re: Question VLAN Setup [SOLVED]

Are you stating that there is no port with more than one vlan going through it???
At a minimum there should be two vlans per port if all are trunk ports going to smart devices, one being the management vlan which all smart devices should get their IP address from.
by anav
Sun Apr 13, 2025 10:42 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 2076

Re: Using CRS326 as a switch

by anav
Sun Apr 13, 2025 5:34 pm
Forum: General
Topic: Request for WireGuard Peers, configurable Client ListenPort and AllowedIPs
Replies: 44
Views: 4880

Re: Request for WireGuard Peers, configurable Client ListenPort and AllowedIPs

Doing the exercise was very helpful to determine form follows function approach and to realize that really what is going on is three different requirements based on how wireguard keys are handled. a. Both ends of a connection manually make and trade public keys (standard wireguard construction) b. A...
by anav
Sun Apr 13, 2025 5:26 pm
Forum: General
Topic: Netwatch/Ping Problem with Recursive Route
Replies: 3
Views: 1975

Re: Netwatch/Ping Problem with Recursive Route

Correct interrelated moving parts, and its unfair to ask for definitive specific answers to vaguish questions without the context and information required.
by anav
Sun Apr 13, 2025 5:24 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 2076

Re: Using CRS326 as a switch

You know I am always truly grateful for the enormous amount of help you have provided to me, but my limited capabilities are focused here, in this thread, on understanding the config items that distinguish router versus switch use in a CRS. Sorry, you dont control the narrative in a public space LO...
by anav
Sun Apr 13, 2025 5:22 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 2076

Re: Using CRS326 as a switch

Routers --> both bridge/switch and route have multiple IP addresses
Switches --> only bridge/switch have single IP address (for management of switch)
RoS Unique (confuses some) --> determines function by Software not by hardware.
by anav
Sun Apr 13, 2025 5:17 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 2076

Re: Using CRS326 as a switch

The CRS should be written as Cloud Router Switch . That is indeed the problem, and by the way, you should note that ONLY one switch in the entire lineup uses the terms Cloud Router Switch and that is the CRS317 ( MT informed to remove). There are couple more that use the term Cloud Switch but most ...
by anav
Sun Apr 13, 2025 1:50 pm
Forum: General
Topic: Request for WireGuard Peers, configurable Client ListenPort and AllowedIPs
Replies: 44
Views: 4880

Re: Request for WireGuard Peers, configurable Client ListenPort and AllowedIPs

Hi Mozerd, I attempted to rejig the Wireguard GUI in winbox 4 and supplied the advice to MT as you can see here. https://forum.mikrotik.com/viewtopic.php?t=215684: The response I got was not enthusiastic as the peer page was too busy etc. So I resubmitted a simplified approach. SEE post #7 for simpl...
by anav
Sun Apr 13, 2025 1:46 pm
Forum: Beginner Basics
Topic: Question VLAN Setup [SOLVED]
Replies: 12
Views: 2781

Re: Question VLAN Setup [SOLVED]

A good network diagram will help planning as well....
by anav
Sun Apr 13, 2025 1:35 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 2076

Re: Using CRS326 as a switch

The example provided is a bit confusing. - why include ports 5 through spf-sfpplus2 if not relevant (not being used) - then I see sfp-sfpplus1 is being used but no indication its a trunk port ( frame types or comment missing ) which is inconsistent from the other entries........ - why are you missin...
by anav
Sun Apr 13, 2025 1:20 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 2076

Re: Using CRS326 as a switch

https://www.spiceworks.com/tech/networking/articles/network-switch-vs-router/ Clues to you are routing. -DHCP -WAN and LAN -NAT -all subnets have an address -need firewall rules (layer3) Switch..... Single Ip address provided to switch setup is primarily about vlan traffic only management or trusted...
by anav
Sun Apr 13, 2025 1:07 pm
Forum: Beginner Basics
Topic: likely hitting software-based routing limits [SOLVED]
Replies: 23
Views: 3490

Re: likely hitting software-based routing limits [SOLVED]

I would go a step further, why are people making excuses for a chap thats willing to spend $600 without research and where the nomenclature NEVER stated cloud router. Go to the switch section of mikrotik, pull up the applicable switch page and I bet you wont find mention of cloud router!!!. Would as...
by anav
Sun Apr 13, 2025 2:54 am
Forum: Beginner Basics
Topic: Port forwarding
Replies: 15
Views: 1310

Re: Port forwarding

Since you didnt bother to post config, Im outta here good luck. Others have more patience than I.
by anav
Sat Apr 12, 2025 9:24 pm
Forum: Beginner Basics
Topic: Help with NAT
Replies: 6
Views: 621

Re: Help with NAT

Yeah much too busy for me to look at in any detail and wont bother until cleaned up. I did note that this is wrong. add allowed-address= 0.0.0.0/0 client-address=10.194.91.2/32 client-endpoint=xx.xx.xx.xx client-keepalive=10s \ client-listen-port=13834 interface= wireguard_1 name= public-key="&...
by anav
Sat Apr 12, 2025 4:33 pm
Forum: General
Topic: Strange PoE issue between MT router and Omada AP
Replies: 8
Views: 701

Re: Strange PoE issue between MT router and Omada AP

I have a 650 myself but plugged into a socket using the adapter ( luckily my wall mount is close to an electrical outlet on the other side of the wall.) I have used injectors with no issue on other tplink and MT access points. https://www.canadacomputers.com/en/power-injector/188906/tp-link-tl-poe16...
by anav
Sat Apr 12, 2025 3:09 pm
Forum: Beginner Basics
Topic: Can't get URL connections that originate from LAN to work on the LAN side!
Replies: 3
Views: 508

Re: Can't get URL connections that originate from LAN to work on the LAN side!

While waiting for the diagram, if you have users in the same subnet as the servers and they are attempting to reach the server via domainname/url then the easy fix is a. change server or users to a different subnet otherwise b. need a hairpin nat rule /ip firewall nat add chain=srnat action=masquera...
by anav
Sat Apr 12, 2025 3:06 pm
Forum: Beginner Basics
Topic: Help with NAT
Replies: 6
Views: 621

Re: Help with NAT

Would need to see MT config
/export file=anynameyouwish (minus router serial number, any public WANIP information, vpn keys )

The wireguard info you were given to connect to the remote wireguard site.
( minus endpoint address, keys )

Diagram of how all the pieces are connected would be useful.
by anav
Sat Apr 12, 2025 1:56 pm
Forum: General
Topic: hAP AC2 vs. AX2...
Replies: 20
Views: 1627

Re: hAP AC2 vs. AX2...

If your considering WIFI as a factor then get a hex refresh (or better router) and tplink or zyxel wifi7 APs. No point IMHO of going anything less than wifi7 at this point. By the time MT figures out the dogs breakfast of wifi packages and capsman, wifi8 will be out. In other words, dont tie your ro...
by anav
Sat Apr 12, 2025 1:03 am
Forum: Wireless Networking
Topic: How to update CAP from CAPsMAN v2?
Replies: 5
Views: 686

Re: How to update CAP from CAPsMAN v2?

seppuku may be less painful ;-)
by anav
Sat Apr 12, 2025 12:59 am
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4975

Re: ROMON fails with frame-types=admit-only-vlan-tagged

Hi Ammo, Im assuming the distinction was soley at the LAB Rb 5009 regarding changing the Bridge settings ( and not the CRS326 which I am assuming are set at vlan-tagged only on bridge itself ) .... romon.jpg The admins work around was to ignore the ethernet connection and connect to an AP behind the...
by anav
Sat Apr 12, 2025 12:41 am
Forum: Beginner Basics
Topic: No internet on rb260gs conected to cAP ax [SOLVED]
Replies: 10
Views: 2078

Re: No internet on rb260gs conected to cAP ax [SOLVED]

Truth be told you are brave and I am a coward......... when it comes to capsman implementation.
Also, you didnt learn anything from me as I dont know anything, but I have successfully passed on information other 'real' experts provide.
by anav
Fri Apr 11, 2025 11:40 pm
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4975

Re: ROMON fails with frame-types=admit-only-vlan-tagged

Well based on the avatar, I guess that post could be considered a dud! ;-)) So what is the summary on why RoMON does not work here? I lost track of the conversation. The OP was trying to use romon from on a PC behind a second rb5009 (that was giving the lab 5009) a WANIP on its flan LAN, to reach t...
by anav
Fri Apr 11, 2025 11:25 pm
Forum: Beginner Basics
Topic: hAP ax lite LTE6 - Security
Replies: 8
Views: 778

Re: hAP ax lite LTE6 - Security

There is nothing about setting up a router for security that is different at home or if travelling.
So ensure on your PC you use vpn for internet and if not at least VPN on the browser or AV software.
by anav
Fri Apr 11, 2025 11:23 pm
Forum: Beginner Basics
Topic: RB5009 drops hardware vpn packets but not through another switch
Replies: 11
Views: 1079

Re: RB5009 drops hardware vpn packets but not through another switch

Well the problem could still be the config, which you have refused to provide. There may be some collision with the box protocols and the MT config for example.
by anav
Fri Apr 11, 2025 11:22 pm
Forum: Beginner Basics
Topic: No internet on rb260gs conected to cAP ax [SOLVED]
Replies: 10
Views: 2078

Re: No internet on rb260gs conected to cAP ax [SOLVED]

When you get tired of capsman, I can help get it working....... Its more pain that its worth IMHO. In fact it takes over the config like effing egg plant in a garden. ;-)
by anav
Fri Apr 11, 2025 11:20 pm
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4975

Re: ROMON fails with frame-types=admit-only-vlan-tagged

Well based on the avatar, I guess that post could be considered a dud! ;-))
by anav
Fri Apr 11, 2025 7:49 pm
Forum: Beginner Basics
Topic: RB5009 drops hardware vpn packets but not through another switch
Replies: 11
Views: 1079

Re: RB5009 drops hardware vpn packets but not through another switch

Maybe the separate box, does not follow protocols properly?? Bad cables??
by anav
Fri Apr 11, 2025 7:47 pm
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4975

Re: ROMON fails with frame-types=admit-only-vlan-tagged

Hi Sindy, I dont think the OP has a problem using ROMON when behind the LAB 5009 to reach the connected CRS326 also part of the lab network. The OP, although didnt provide the pertinent information or the pertinent config, only disclosed the fact that he was actually behind another 5009, that provid...
by anav
Fri Apr 11, 2025 5:19 pm
Forum: General
Topic: Replacing RB2011UiAS-2HnD with hAP ax lite LTE6?
Replies: 8
Views: 847

Re: Replacing RB2011UiAS-2HnD with hAP ax lite LTE6?

There are many factors involved here. a. how often does the main internet go down? b. what throughput or level of Cellular performance is good enough c. what level of wifi connectivity is good enough..... What is shocking to me is that as the IT person of this network, states that that there was a f...
by anav
Fri Apr 11, 2025 4:52 pm
Forum: Beginner Basics
Topic: hAP ax lite LTE6 - Security
Replies: 8
Views: 778

Re: hAP ax lite LTE6 - Security

I would have a home MT router, and use the travel router to use the MT router internet via a wireguard tunnel. There is no special sauce be it on the road or at home to keep the traffic as secure as possible. A layered approach works, so if you dont vpn into home use a vpn on the connected devices, ...
by anav
Fri Apr 11, 2025 1:51 pm
Forum: Beginner Basics
Topic: RB5009 drops hardware vpn packets but not through another switch
Replies: 11
Views: 1079

Re: RB5009 drops hardware vpn packets but not through another switch

Hard to day without seeing your 5009 config
/export file=anynameyouwish ( minus router serial number, and any public IP information)

The router should be transparent to the device and its connectivity through the internet to office site using the office vpn.
by anav
Fri Apr 11, 2025 12:56 am
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4975

Re: ROMON fails with frame-types=admit-only-vlan-tagged

We are going to connect the PC on the master router to the lab router directly on vlan32. So ensure vlan32 is associated with ether1 as well, on the lab router. To facilitate the idea, lets say on the master 5009, its etherport YY that you have connected to the lab5009. Further, you have our pc on t...
by anav
Fri Apr 11, 2025 12:34 am
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4975

Re: ROMON fails with frame-types=admit-only-vlan-tagged

Only stating there was a second 5009 at play at such a late stage, and that the Romon issue stemmed from the first one to the Switch was a criminal omission. Consider yourself flogged ;-)
Your punishment is having to eat the entire plate of smoked meat served at Katz's.
by anav
Fri Apr 11, 2025 12:16 am
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4975

Re: ROMON fails with frame-types=admit-only-vlan-tagged

According to CGX, there were no shortcomings to using bridge itself vlan tagged, so I hesitate to completely swallow the information provided by AMMO and maybe in-between is a more accurate answer???? It would appear to me that any data from a PC trying to talk ROMON that is assumed to be on the man...
by anav
Thu Apr 10, 2025 11:12 pm
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4975

Re: ROMON fails with frame-types=admit-only-vlan-tagged

Who told you this............... ??????
I need Romon to access the CRS

its clear that even though ROMON should not be affected by vlan tag settings on the bridge itself, they are, so avoid its use is my advice.
by anav
Thu Apr 10, 2025 11:08 pm
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4975

Re: ROMON fails with frame-types=admit-only-vlan-tagged

So what is now on ether7?? What is the conflict? I am having difficulty identifying the conflict. ether7 is the CRS. The config paints a conflicted story? set [ find default-name= sfp-sfpplus1 ] comment= CSS326 Hard to find ether7 tagged for any vlans going to CRS326 ??? /interface bridge vlan add ...
by anav
Thu Apr 10, 2025 8:51 pm
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4975

Re: ROMON fails with frame-types=admit-only-vlan-tagged

I access all my downstream devices, ax3 ap, hex switch, etc via neighbours discovery not ROMON (via winbox)
by anav
Thu Apr 10, 2025 8:07 pm
Forum: General
Topic: SmartDNS not working
Replies: 5
Views: 633

Re: SmartDNS not working

Perhaps "smart"dns was just a marketing ploy? ;-)
by anav
Thu Apr 10, 2025 8:05 pm
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4975

Re: ROMON fails with frame-types=admit-only-vlan-tagged

What are you using ROMON for,,,,,,,,,that is not available through neighbours discovery?
by anav
Thu Apr 10, 2025 8:03 pm
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4975

Re: ROMON fails with frame-types=admit-only-vlan-tagged

ROUTER You have a disconnect and duplication when I noted on your trusted listed you had three ports ( vice just one trusted offbridge port ) identified. The fallout of that is 1. a. in ethernet interface settings you identify ether5 as the hapax upstairs, and on /interface bridge ports ( athough m...
by anav
Thu Apr 10, 2025 6:50 pm
Forum: General
Topic: ROMON fails with frame-types=admit-only-vlan-tagged
Replies: 31
Views: 4975

Re: ROMON fails with frame-types=admit-only-vlan-tagged

SWITCH Why are you treating the switch like a router? The only address on the switch is the one given to the switch over the management vlan32 ??? Bridge is not involved............ reminder to look at switch example: https://forum.mikrotik.com/viewtopic.php?t=143620 There is only need of ONE inter...
by anav
Thu Apr 10, 2025 6:41 pm
Forum: Beginner Basics
Topic: interligando RBs
Replies: 2
Views: 397

Re: interligando RBs

For a secure connection suggest wireguard, assuming you have at least on public IP available at one of the routers, or the ISP router in front is capable of forwarding ports.
Alternatively use Zerotier.
by anav
Thu Apr 10, 2025 6:37 pm
Forum: Beginner Basics
Topic: PPPOE with static IP
Replies: 20
Views: 1569

Re: PPPOE with static IP

CGX nailed it........
/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether1 should be pppoe-out1
WINBOX
IP menu firewall -->NAT

Sorry dont know the CLI commands to change.
by anav
Thu Apr 10, 2025 3:51 pm
Forum: General
Topic: WireGuard - dynamic routes [SOLVED]
Replies: 5
Views: 1793

Re: WireGuard - dynamic routes [SOLVED]

RoS is very for giving, many of the default settings are ALLOW by default, so unless you define what is allowed, everything is allowed.
by anav
Thu Apr 10, 2025 3:46 pm
Forum: Beginner Basics
Topic: PPPOE with static IP
Replies: 20
Views: 1569

Re: PPPOE with static IP

Here is one problem........ The termination of the ISP connection is done through pppoe, so the ip address entry for ether1 is incorrect, should be removed. /ip address add address=192.168.88.1/24 interface=bridge1 network=192.168.88.0 add address=cc.220.222.dd/24 interface=ether1 network=91.220.222...
by anav
Thu Apr 10, 2025 2:21 pm
Forum: Beginner Basics
Topic: PPPOE with static IP
Replies: 20
Views: 1569

Re: PPPOE with static IP

What does a duck do on the router? quackNat quacknat quacknat quacknat.
fixed it for ya
by anav
Thu Apr 10, 2025 2:18 pm
Forum: General
Topic: WireGuard - dynamic routes [SOLVED]
Replies: 5
Views: 1793

Re: WireGuard - dynamic routes [SOLVED]

1. Typically the recommendation here is loose , not strict! /ip settings set rp-filter= strict 2. Lack of decent set of firewall rules, plus should be organized together in chains and in a coherent order. PLUS security infraction, one does not access winbox from external as you are attempting. Only ...
by anav
Wed Apr 09, 2025 11:54 pm
Forum: Beginner Basics
Topic: Port forwarding
Replies: 15
Views: 1310

Re: Port forwarding

/export file=anynameyouwish ( minus router serial number, any public WANIP information ) It should be quick to find the issue! also. a. confirm you are using LANIP of server to reach from LAN? b. confirm you have a public IP address (static or dynamic) OR you have an ISP router that has a public IP ...
by anav
Wed Apr 09, 2025 11:28 pm
Forum: General
Topic: DHCP Issues on Port 4 Despite Normal EoIP Operation [SOLVED]
Replies: 3
Views: 1667

Re: DHCP Issues on Port 4 Despite Normal EoIP Operation [SOLVED]

Can you post your latest config on both routers.
/export file=anynameyouwish ( minus router serial number, any public WANIP info, keys. )
by anav
Wed Apr 09, 2025 10:59 pm
Forum: Beginner Basics
Topic: How can I configure DHCP on EoIP over Wireguard? [SOLVED]
Replies: 2
Views: 1601

Re: How can I configure DHCP on EoIP over Wireguard? [SOLVED]

I do not believe DHCP in general works over wireguard but there may be ways..........
Check out VXLANs and EOIP as two possibilities ( running over wireguard or L2TP to keep the traffic secure ).
by anav
Wed Apr 09, 2025 10:45 pm
Forum: General
Topic: WireGuard - dynamic routes [SOLVED]
Replies: 5
Views: 1793

Re: WireGuard - dynamic routes [SOLVED]

Would need to see the complete config, but it sounds like you want the users on your subnets to use wireguard for specific WANIPs that exist, and where they are not static but dynamic WANIPs. First, please do not use the same name for different RoS funcitonalites, aka the name of the list being the ...
by anav
Wed Apr 09, 2025 10:27 pm
Forum: General
Topic: Need a nat rule
Replies: 11
Views: 963

Re: Need a nat rule

How you sussed that out from the information presented boggles my mind. Glad you are here LOL However, the weak point being, how does the router know that 10.72.22.200 should be assigned to the device ( assuming its now in a VLAN of that subnet structure )?? THe router knows that that address might ...
by anav
Wed Apr 09, 2025 7:22 pm
Forum: General
Topic: Need a nat rule
Replies: 11
Views: 963

Re: Need a nat rule

I probably missed the intent entirely but why not something as simple as: If I have a device with LANIP 192.168.0.X and I want it to go out over wireguard but as 10.10.100.Y address add chain=srcnat action=src-nat src-address=192.168.0.97 to-address=10.72.22.200 AND for return traffic..................
by anav
Wed Apr 09, 2025 7:17 pm
Forum: Beginner Basics
Topic: PCC load balancing
Replies: 1
Views: 368

Re: PCC load balancing

What are your qualifiers in the PCC mangle rules??
by anav
Wed Apr 09, 2025 7:15 pm
Forum: General
Topic: This "Sorry but the board is temporarily unavailable, please try again in a few minutes." is getting old.
Replies: 48
Views: 7360

Re: This "Sorry but the board is temporarily unavailable, please try again in a few minutes." is getting old.

Normis, massina seems to have experience with migrations, and that at least should be made aware to the admins in their deliberations. Thanks for your feedback in this thread, its really good to see!
by anav
Wed Apr 09, 2025 1:27 pm
Forum: General
Topic: Multi-wan multi-ip wireguard setup
Replies: 15
Views: 1321

Re: Multi-wan multi-ip wireguard setup

To clarify the source nat address part is STILL required. I think he is saying
add action=dst-nat chain=dstnat connection-mark=wg-wan2 to-addresses=10.20.30.40
add action=src-nat chain=input connection-mark=wg-wan2 to-addresses=10.20.30.40
by anav
Wed Apr 09, 2025 1:27 am
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 1984

Re: Basic VLAN config question (again)

Interesting, as long as there is no downside, narrowing down the frame type at the bridge, is then viable would be my conclusion. Assuming you mean this is valid for both routers and switches CR3 types when using vlan filtering??? Just to be clear this does not interfere with any situations where a....
by anav
Tue Apr 08, 2025 11:37 pm
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 1984

Re: Basic VLAN config question (again)

The first error. 1. is quoting from your config in post #18 EDIT : and is USER OPTIONAL ( without frame limitations vlan-id1 is shown as a dynamic entry but not a concern, as well limit frame types on all bridge ports/wlans - I guess either way is acceptable! 2. is quoting from your confing in post ...
by anav
Tue Apr 08, 2025 10:37 pm
Forum: General
Topic: Multi-wan multi-ip wireguard setup
Replies: 15
Views: 1321

Re: Multi-wan multi-ip wireguard setup

Yup sounds familiar and as CGX pointed out we only need to use one LO address/interface to accomplish same.......... no need for bridge!!
/ip address
add address=10.20.30.40 interface=lo network=10.20.30.40
by anav
Tue Apr 08, 2025 10:34 pm
Forum: General
Topic: This "Sorry but the board is temporarily unavailable, please try again in a few minutes." is getting old.
Replies: 48
Views: 7360

Re: This "Sorry but the board is temporarily unavailable, please try again in a few minutes." is getting old.

re: ... Anyway, whatever they end up doing... I do hope they host it on their RDS ROSE server(s) as proof-point they work in the real-world. ... If I hosted this server , I would go with Proxmox hypervisors Xeon , 40-Gig or 100-Gig network cards , NFS mounts from a TrueNAS ( 512-Gig Ram or 1-TB-Ram...
by anav
Tue Apr 08, 2025 5:44 pm
Forum: Beginner Basics
Topic: Can't Access LAN Devices Behind MikroTik via WireGuard Tunnel
Replies: 11
Views: 906

Re: Can't Access LAN Devices Behind MikroTik via WireGuard Tunnel

Looking at the diagram it would appear you have three separate networks/locations. The laptop is a remote device could be anywhere a true remote peer. The MT device is a fixed remote device. The Server is the local wireguard in this discussion. All three are not connected but all three have access t...
by anav
Tue Apr 08, 2025 4:45 pm
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 1984

Re: Basic VLAN config question (again)

Speed is not all its cracked up to be, taking ones time mostly results in greater satisfaction,.......... Besides there is an error before that..... and many many after LOL 1. /interface bridge add admin-mac=F4:1E:57:2C:BE:98 auto-mac=no comment=defconf frame-types=\ admit-only-vlan-tagged name=brid...
by anav
Tue Apr 08, 2025 4:01 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 9404

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

How does it relate to the input chain rule then?? add chain=input action=accept dst-address=127.0.0.1 and you are saying Then 10.20.30.40 can be used instead of both your 172.16.10.1 and 172.16.10.2. Does this mean the following. /ip firewall nat add action=dst-nat chain=dstnat connection-mark=wg-wa...
by anav
Tue Apr 08, 2025 2:41 am
Forum: Beginner Basics
Topic: Can't Access LAN Devices Behind MikroTik via WireGuard Tunnel
Replies: 11
Views: 906

Re: Can't Access LAN Devices Behind MikroTik via WireGuard Tunnel

Please draw a diagram, I have no clue how everything is hooked up together and to the internet
by anav
Tue Apr 08, 2025 2:39 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 9404

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

Hi CGX...
What the heck is lo LOL, an existing interface on the router that is there all the time??
by anav
Mon Apr 07, 2025 4:44 am
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 19447

Re: WireGuard Multi-WAN Policy Routing

I see no reason to use PCC, if ECMP is ensuring fair usage of all WANs ( they have to be equalish in throughput ). Maybe ECMP circa 7.18, the brewmasters finally got right....................... Better than PCC is actually load balancing which add a layer of additional mangling but you can do it bas...
by anav
Mon Apr 07, 2025 3:22 am
Forum: General
Topic: Split DNS
Replies: 18
Views: 1175

Re: Split DNS

Well HA does not use DHCP Option codes, must have coders from the dark ages. In any case you could try something like this simple DNS pointing. IOT Subnet on R2 - 192.168.55.0/24 IP of server on R1 - 10.10.10.15 ON R2 /ip dhcp-server network add address=192.168.55.0/24 dns-server=192.168.55.1 domain...
by anav
Mon Apr 07, 2025 3:11 am
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 19447

Re: WireGuard Multi-WAN Policy Routing

Never said it was, but to think up such trickery, you are on the spectrum somewhere ;-P You have answered my question, there is no rhyme or reason, it is not controllable and thus the faux bridge approach is STILL required even in ECMP. Thus, the answer is dont have multiple WANS, ;-) Good, so you h...
by anav
Mon Apr 07, 2025 1:08 am
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 1984

Re: Basic VLAN config question (again)

What?? Well the physical port ether1 is a trunk port carrying multiple vlans to the local device. Why would you not think that vlan32 should be allowed to ingress in ether1?? A. its on the trunk port leaving the upstream device. B. its noted as a tagged vlan id on ether1 in /interface bridge vlan s...
by anav
Mon Apr 07, 2025 1:04 am
Forum: General
Topic: Split DNS
Replies: 18
Views: 1175

Re: Split DNS

You miss the point entirely, The two options presented DHCP and DNS are to inform the iot device, what is the IP address of the HA server, not to change the local subnet IP the iot device is using. And how would DHCP or DNS be used to inform the IoT device the address of the HA server? I stated it ...
by anav
Mon Apr 07, 2025 1:01 am
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 19447

Re: WireGuard Multi-WAN Policy Routing

I am saying I have 3 ISPs all different all relatively 1gig connections. I load balance via ECMP /ip route ( main table ) add dst-address=0.0.0.0/0 gateway=gatewayIP-wan1 routing table=main add dst-address=0.0.0.0/0 gateway=gatewayIP-wan2 routing table=main add dst-address=0.0.0.0/0 gateway=gatewayI...
by anav
Mon Apr 07, 2025 12:39 am
Forum: General
Topic: This "Sorry but the board is temporarily unavailable, please try again in a few minutes." is getting old.
Replies: 48
Views: 7360

Re: This "Sorry but the board is temporarily unavailable, please try again in a few minutes." is getting old.

Hahaha, I thought it was simply my browser, I keep forgetting they use a haplite to run their website, the free schnapps in the web lounge is not helping work output either.
by anav
Mon Apr 07, 2025 12:37 am
Forum: General
Topic: Split DNS
Replies: 18
Views: 1175

Re: Split DNS

You miss the point entirely,
The two options presented DHCP and DNS are to inform the iot device, what is the IP address of the HA server, not to change the local subnet IP the iot device is using.
by anav
Sun Apr 06, 2025 11:13 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 19447

Re: WireGuard Multi-WAN Policy Routing

Sorry I meant EMP of course. Does it work during a nuclear blast in the atmosphere??? Of course I meant ECMP, you know this feature --> Equal Cost Multi-Path...... My question is germane, not dry (german), because we are not sure of how the router decides which interface/route it decides to use on t...
by anav
Sun Apr 06, 2025 10:25 pm
Forum: General
Topic: Split DNS
Replies: 18
Views: 1175

Re: Split DNS

Maybe, home assistant appears to be a dogs breakfast with differing information wherever you look. One place says the server scans the network for devices...................
by anav
Sun Apr 06, 2025 10:23 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 19447

Re: WireGuard Multi-WAN Policy Routing

So lurker did you test like 3 WANS with ECMP load balancing
Basic mangle rule in wan3 out wan3 generic all traffic to WAN back out same WAN.
What does the wireguard process choose for source address in this case, alway the correct WAN?? ( regardless if you put wireguard on wan1, wan2, or wan3 )
by anav
Sun Apr 06, 2025 9:44 pm
Forum: General
Topic: Split DNS
Replies: 18
Views: 1175

Re: Split DNS

By the way, Home Assistant devices typically obtain IP addresses from the Home Assistant server through the network's DHCP server, which is usually the router, rather than directly from the Home Assistant server itself. This sounds much like the UNIFI approach where one can use a. create dhcp option...
by anav
Sun Apr 06, 2025 9:38 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 19447

Re: WireGuard Multi-WAN Policy Routing

@lurker888, does EOIP really have the same handshake issue as WG, like I described above?
Since when does EOIP have a handshake, I use EOIP within a wireguard tunnel LOL, not outside of it.
by anav
Sun Apr 06, 2025 9:02 pm
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 1984

Re: Basic VLAN config question (again)

Not your concern mkx, its hard to keep straight incomplete questions without context................
by anav
Sun Apr 06, 2025 8:57 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 7
Views: 13507

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

Rereading your first post, BOLLOCKS..... Prerequisites A Mikrotik router running RouterOS v7.x A Linux system (e.g., Debian) to retrieve necessary keys An active NordVPN subscription Why?? NordVPN will give you the private key to use on the Mikrotik Router Interface creation. That creates a public k...
by anav
Sun Apr 06, 2025 8:46 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 19447

Re: WireGuard Multi-WAN Policy Routing

I have a better idea, why not just live in my office I have a spare chair and desk and I can setup a tent outside, winter is almost over.
Payment in good food and beer LOL
by anav
Sun Apr 06, 2025 8:41 pm
Forum: Beginner Basics
Topic: Home network configuration through Mikrotik hAp ax3
Replies: 1
Views: 504

Re: Home network configuration through Mikrotik hAp ax3

Sure, the default setup is quite good, in that it is safe to connect ether1 to you internet connection and use ports 2-5 for internet. If you need more than one network on your home you will need bridge vlan filtering.. This is the best article to read --> https://forum.mikrotik.com/viewtopic.php?t=...
by anav
Sun Apr 06, 2025 8:23 pm
Forum: Useful user articles
Topic: How to export your Mikrotik config and share it (Step-by-Step guide)
Replies: 14
Views: 1337

Re: How to export your Mikrotik config and share it (Step-by-Step guide)

I have seeing lots of timezones in shared configs, that also may expose your location.
And of course wifi country settings.
Good point, the somali gang members probably dont want people to know they are in Sweden.,.........shhhhh its a secret.
by anav
Sun Apr 06, 2025 8:20 pm
Forum: Beginner Basics
Topic: Kids Control
Replies: 5
Views: 4269

Re: Kids Control

Kid control is not really intuitive.
Have you notifed MT by a suggestion on their support website.
If not, get on with it. ;-)
by anav
Sun Apr 06, 2025 6:56 pm
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 1984

Re: Basic VLAN config question (again)

Why would a frame tagged with VID=32 ingressing to ether1 be accepted? What?? Well the physical port ether1 is a trunk port carrying multiple vlans to the local device. Why would you not think that vlan32 should be allowed to ingress in ether1?? A. its on the trunk port leaving the upstream device....
by anav
Sun Apr 06, 2025 6:19 pm
Forum: Useful user articles
Topic: How to export your Mikrotik config and share it (Step-by-Step guide)
Replies: 14
Views: 1337

Re: How to export your Mikrotik config and share it (Step-by-Step guide)

The point being, silly goose is that Jaclaz is talking about a. the items in the config that are not already removed by RoS ( RoS removes passwords and ipsec stuff for example ) b. the items you added or router added, NEEDED not whimsically added, to make the config work, be it public IP address, ga...
by anav
Sun Apr 06, 2025 6:06 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 19447

Re: WireGuard Multi-WAN Policy Routing

No worries there Larsa, no I have not tested the hard down theory, but I trust Larsa has, as he seems to be a testing machine, highly motivated. I am starting to think he is an AI brain attached to an MT network. I sent a suggestion to MT to fix the issue based on the fact that 'fwmark' already exis...
by anav
Sun Apr 06, 2025 4:12 pm
Forum: General
Topic: Split DNS
Replies: 18
Views: 1175

Re: Split DNS

BartoszP aka devil colours would be more appropriate ;-) But please answer my questions here --> viewtopic.php?t=215918#p1137048
by anav
Sun Apr 06, 2025 4:10 pm
Forum: Beginner Basics
Topic: Remote WinBox access over WireGuard?
Replies: 9
Views: 820

Re: Remote WinBox access over WireGuard?

If Joseph you are asking a different question, can one see all the routers at one time via winbox, via wireguard, in order to select for configuring, the answer is no. Those protocols dont go over wireguard.
by anav
Sun Apr 06, 2025 4:09 pm
Forum: Beginner Basics
Topic: Remote WinBox access over WireGuard?
Replies: 9
Views: 820

Re: Remote WinBox access over WireGuard?

duplicate.
by anav
Sun Apr 06, 2025 3:35 pm
Forum: Beginner Basics
Topic: Remote WinBox access over WireGuard?
Replies: 9
Views: 820

Re: Remote WinBox access over WireGuard?

Yes /export file=anynameyouwish ( minus serial number, any public WANIP information, wireguard keys ). WHich mean a. serial number one entry at beginning of config b. WANIP information, so removed any PUBLIC wan ip information --> could be in IP DHCP Client text, IP route text ( public IP address or...
by anav
Sun Apr 06, 2025 3:30 pm
Forum: General
Topic: MikroTik RB5009 setting up remotely first time
Replies: 55
Views: 3478

Re: MikroTik RB5009 setting up remotely first time

Bartosz you make me laugh................. this is a non-paid gig, dont complain about playing consultant for free. ;-P
Your stamina is commendable. :-)
by anav
Sun Apr 06, 2025 3:27 pm
Forum: General
Topic: Split DNS
Replies: 18
Views: 1175

Re: Split DNS

I assumed as always, that you are short of time and thus want to getter done. If you have time to read novels, that is a different story '=)
Wait till you hit the chapters on VRRP VXLAN and BGP.
by anav
Sun Apr 06, 2025 3:14 pm
Forum: General
Topic: Multi-wan multi-ip wireguard setup
Replies: 15
Views: 1321

Re: Multi-wan multi-ip wireguard setup

Mimiko read this post please --> viewtopic.php?p=1136686#p1136996
by anav
Sun Apr 06, 2025 3:13 pm
Forum: General
Topic: Split DNS
Replies: 18
Views: 1175

Re: Split DNS

It may or may not be applicable for what you are trying to do.
My question is why do you need split DNS for the IOT subnet?
Do you have different IOT devices on the same subnet?
Are there are other ways to target those specific IOT devices......
by anav
Sun Apr 06, 2025 2:39 pm
Forum: General
Topic: Public DNS to private IP
Replies: 44
Views: 2539

Re: Public DNS to private IP

RIGHT, you proved me right again thank Bartosz........ A config is based on a set of established requirements, not vapour future wishes. If the op wants efficiency, the shortest path to get his 10 routers up and running as they are now, DNS is stewpid. If the op wants to tinker with DNS, which is mo...
by anav
Sun Apr 06, 2025 2:19 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 19447

Re: WireGuard Multi-WAN Policy Routing

The problem with Sindys excellent approach is that it relies on the dstnat rule to un-dst the WAN1 IP to the WAN2IP so that the source of the response traffic leaving the router is correct. The mangle is fine and working as the route chosen is still good. The crux of the problem is how the router de...
by anav
Sun Apr 06, 2025 2:10 pm
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 1984

Re: Basic VLAN config question (again)

Somewhere along the line MT must have changed the default to YES, hard on us ole-timers LOL
by anav
Sun Apr 06, 2025 1:16 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 9404

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

THis is the most interesting part about your post. The packet is annotated with the connection mark in the conntrack phase. Until then, there is no associated connection mark. (On normal linux, wg interfaces have a property fwmark, which allows all packets emitted by wg to be marked on creation - th...
by anav
Sun Apr 06, 2025 1:09 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 9404

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

(I see what you are doing with wireguard just dont agree with it. There is no case where both sides of a connection need 50.0/24 that I can see.) Regarding the contrack and wireguard and dual WAN etc......... I approached it from a different angle so it makes sense to me. The initial problem before ...
by anav
Sat Apr 05, 2025 9:25 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 9404

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

My bad that is valid, but this is assuming the remote router is an MT router. ( client peer for handshake) ........ makes sense, so other peers connecting to the local router can easily re-enter the tunnel and reach the remote router via the local router, so to speak. The local router needs allowed ...
by anav
Sat Apr 05, 2025 8:44 pm
Forum: General
Topic: Beginner VLAN questions
Replies: 32
Views: 2893

Re: Beginner VLAN questions

All a waste of time. Simply input chain last rule drop all else Simply forward chain last rule drop all else WInbox services, include all subnets that are TRUSTED, management vlan, offbridge port, and any other subnet where you may be coming from to access winbox and the router (like wireugard subne...
by anav
Sat Apr 05, 2025 4:58 pm
Forum: General
Topic: Device got hacked 1 min after connected to internet
Replies: 57
Views: 9498

Re: Device got hacked 1 min after connected to internet

They like blinking lights?
by anav
Sat Apr 05, 2025 4:54 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 9404

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

My problem is not properly understanding connection tracking, Nothing more you can do LOL.
At least I kind of grasp your use of faux bridge and how traffic gets there, its after, the response traffic and mangle and routing that eludes me completely.
by anav
Sat Apr 05, 2025 2:00 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 9404

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

It goes to root reason. As I stated, WAN1 being primary WAN2 secondary wanting to use WAN2 for wireguard. We only need to mangle for WAN2 and the problem was the router was sending return traffic via WAN1........ Thus we dsnatted to fool router to send traffic back out WAN2....... You pointed out th...
by anav
Sat Apr 05, 2025 1:55 pm
Forum: General
Topic: Beginner VLAN questions
Replies: 32
Views: 2893

Re: Beginner VLAN questions

Well the drop all rule will certainly cut out non trusted vlan access to winbox, since the interface list allows only trusted vlans, but without the drop all rule, nothing is really blocked, mac-server winbox-mac-server is used in conjunction with neighbours discovery to make all smart MT devices sh...
by anav
Sat Apr 05, 2025 5:07 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 9404

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

So in your example you have to manipulate both wans, not just wan2??
by anav
Sat Apr 05, 2025 5:04 am
Forum: Beginner Basics
Topic: Wireguard Peer not able to reach internet
Replies: 42
Views: 2299

Re: Wireguard Peer not able to reach internet

To config vlan filtering always a good idea to take an unused port or temporarily use a lesser important port and take it off the bridge, Give it an Ip address and config from there safely. Okay how to create an offbridge port. REMOVE ether5 from /interface bridge ports /interface ethernet set [ fin...
by anav
Sat Apr 05, 2025 1:29 am
Forum: Beginner Basics
Topic: internet speed
Replies: 8
Views: 1037

Re: internet speed

Suggest you send supouts to MT as possible bug reports.
by anav
Sat Apr 05, 2025 1:27 am
Forum: Beginner Basics
Topic: Best gear to receive 4G/5G signal to a cottage
Replies: 13
Views: 2355

Re: Best gear to receive 4G/5G signal to a cottage

The top of the tree may tend to sway significantly so not sure if thats ideal, in my experience its always windy. :-(
A pole on a fixed object like house may be better unless there is an earthquake every time you want to use the connection.
by anav
Sat Apr 05, 2025 1:25 am
Forum: Beginner Basics
Topic: Wireguard Peer not able to reach internet
Replies: 42
Views: 2299

Re: Wireguard Peer not able to reach internet

Best thing is to repost your latest for review!
by anav
Sat Apr 05, 2025 1:24 am
Forum: Beginner Basics
Topic: Wireguard Peer not able to reach internet
Replies: 42
Views: 2299

Re: Wireguard Peer not able to reach internet

Perfect so netmask 28 works for you !! As for the rest looking at post #3 your worK! /interface bridge port add bridge=bridge comment=defconf ingress-filtering=no interface= ether2 \ internal-path-cost=10 path-cost=10 /ip address add address= 192.168.88.1/24 comment=defconf interface=bridge network=...
by anav
Sat Apr 05, 2025 1:20 am
Forum: Beginner Basics
Topic: Question about interface lists
Replies: 9
Views: 1169

Re: Question about interface lists

As surmized: Behaviour is normal: MAC server MAC server section allows you to configure MAC Telnet Server, MAC WinBox Server and MAC Ping Server on RouterOS device. MAC Telnet is used to provide access to a router that has no IP address set. It works just like IP telnet. MAC telnet is possible betwe...
by anav
Sat Apr 05, 2025 1:18 am
Forum: Beginner Basics
Topic: Question about interface lists
Replies: 9
Views: 1169

Re: Question about interface lists

Yes, that should not happen, You should only be able to access the router via Winbox from the management VLAN with those settings.......... I would need to see your whole config to comment accurately though.... /export file=anynameyouwish ( minus router serial number, any public WANIP information, k...
by anav
Sat Apr 05, 2025 1:01 am
Forum: Beginner Basics
Topic: Wireguard Peer not able to reach internet
Replies: 42
Views: 2299

Re: Wireguard Peer not able to reach internet

Just started reading the post and yes, MANY ERRORS in the config which are not all yet sorted. Clearly your wireguard IP address is hosed. It should be assuming you only need/want one peer as such add address=192.168.89. 1/30 interface=wireguard1 network=192.168.89.0 { allows only two useable IPs .1...
by anav
Sat Apr 05, 2025 12:52 am
Forum: General
Topic: Beginner VLAN questions
Replies: 32
Views: 2893

Re: Beginner VLAN questions

Why security of course! If you dont want any security
then simply

have two firewall rules
add chain=input action=accept comment="eviscerate me"
add chain=forward action=accept comment="bugger me
"
by anav
Fri Apr 04, 2025 11:43 pm
Forum: General
Topic: Issues with MikroTik L009 Configuration – Firewall & PPPoE
Replies: 1
Views: 826

Re: Issues with MikroTik L009 Configuration – Firewall & PPPoE

setting up pppoe should be easy peasy, go to ppp settings and hit the plus sign and select pppoe client I think near the bottom of the list. This shows a more complex scenario where they use a vlan to send the traffic, whereas in your case you dont need to replace ether1 as the interface. https://ww...
by anav
Fri Apr 04, 2025 11:40 pm
Forum: General
Topic: Cannot reach access point on tagged management vlan
Replies: 3
Views: 633

Re: Cannot reach access point on tagged management vlan

In a switch scenario. One should normally only identify the management vlan! This vlan in /interface bridge vlans is the ONLY vlan-id that requires the bridge to be tagged, the rest are tagged on etherX and go out etherY or WLAN1/WLAN2 etc.. This vlans address is the address of the switch for manage...
by anav
Fri Apr 04, 2025 11:31 pm
Forum: General
Topic: Beginner VLAN questions
Replies: 32
Views: 2893

Re: Beginner VLAN questions

Basic firewall for Router BUT FIRST YOU NEED to add missing pieces!! /interface list add name=WAN add name=LAN add name=TRUSTED /interface list member add interface=ether1 list=WAN add interface=general_vlan list=WAN add interface=media_vlan list=WAN add interface=management_vlan list=WAN add interf...
by anav
Fri Apr 04, 2025 11:11 pm
Forum: General
Topic: Beginner VLAN questions
Replies: 32
Views: 2893

Re: Beginner VLAN questions

Okay matt that clears up that perspective. Firewall rules will speed things up actually, especially with use of fastrack etc.. I mean on the router, switch requires no firewall rules. Save turn OFF ipv6 if not using it. Going back to the configs... then switch 326 1. modify the first line for consis...
by anav
Fri Apr 04, 2025 8:38 pm
Forum: General
Topic: Beginner VLAN questions
Replies: 32
Views: 2893

Re: Beginner VLAN questions

Router . Summary ( incomplete, not ready for deployment ) 1. Not necessary, as the router dynamically untag the port, but it shows you understand the vlan filtering. /interface bridge vlan add bridge=bridge1 comment="General VLAN" tagged=bridge1,bonding1 untagged=ether3 vlan-ids=10 2. Fir...
by anav
Fri Apr 04, 2025 7:41 pm
Forum: Beginner Basics
Topic: NAT mikrotik allowing connexions from another network
Replies: 1
Views: 451

Re: NAT mikrotik allowing connexions from another network

Its easy for computers behind the MT to reach other computers because all traffic out the MT is natted to the WANP of the MT .156, which is on the LAN of box devices. Their return traffic goes back to the MT, and the MT un-sourcenats that back to the originators. However consider the reverse, when t...
by anav
Fri Apr 04, 2025 7:29 pm
Forum: Beginner Basics
Topic: VLANS Through Managed Switches - Beginner Config [SOLVED]
Replies: 11
Views: 10795

Re: VLANS Through Managed Switches - Beginner Config [SOLVED]

Create your own EVE-NG or GNS3 type lab environment..........
by anav
Fri Apr 04, 2025 7:21 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 9404

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

Lurker, gone down many a rabbit hole, I cannot seem to work my way through the noise of your solution.......... Context: Two WANS, WAN1 primary, and WAN2 secondary and wishing to use WAN2 as the wireguard connection. If given a faux bridge 192.168.66.0/32 address and given a listening port of 55555,...
by anav
Fri Apr 04, 2025 1:39 pm
Forum: Beginner Basics
Topic: beginner - i'm trying to build a vlan
Replies: 10
Views: 1023

Re: beginner - i'm trying to build a vlan

By rereading the article, where are frame types list on bridge ports, also basic networking, you got the pools but dont you realize each subnet needs
a. pool
b. dhcp server
c. dhpc server network
d. address
by anav
Fri Apr 04, 2025 1:30 pm
Forum: Beginner Basics
Topic: Question about interface lists
Replies: 9
Views: 1169

Re: Question about interface lists

Correct, manually entered. Typically, once you have vlans, one has to indicate which is a Trusted or the Management vlan, if nothing else for proper security. This is done through creating a TRUSTED interface list........ This ripples through the config a. the input chain, users ONLY need access to ...
by anav
Fri Apr 04, 2025 1:22 pm
Forum: General
Topic: WireGuard Multi-WAN Policy Routing
Replies: 113
Views: 19447

Re: WireGuard Multi-WAN Policy Routing

Hi Larsa, I think we need to go to Lurkers solution as the correct answer as Sindys, does not deal with the issue of the primary WAN being not available, and how that screws up the single dsntnat rule.
by anav
Fri Apr 04, 2025 12:37 am
Forum: Beginner Basics
Topic: Returning Newbie :) - Optimizing Bandwidth Config
Replies: 9
Views: 1547

Re: Returning Newbie :) - Optimizing Bandwidth Config

Sorry couldnt get past the router........ ;-)
by anav
Thu Apr 03, 2025 11:51 pm
Forum: Beginner Basics
Topic: beginner - i'm trying to build a vlan
Replies: 10
Views: 1023

Re: beginner - i'm trying to build a vlan

First do not ask any questions and only show snippets on the config of what you think we should see, if you dont know the problem how can you know where to look. You now have almost duplicate SrcNAT Rules and that is redundant, get rid of the second one. For the export to see what is causing your is...
by anav
Thu Apr 03, 2025 11:47 pm
Forum: Wireless Networking
Topic: Wifi Bridge
Replies: 1
Views: 508

Re: Wifi Bridge

Not possible across brands.
Your best bet is
a. to drill (best)
b. to use moca adapters if there is rgb6 coax in the house (okay) Trendnet makes some
c. use powerline adapters over electrical wiring (mileage will vary) best are https://www.techradar.com/news/the-best ... e-adaptors
by anav
Thu Apr 03, 2025 11:41 pm
Forum: Beginner Basics
Topic: Question about interface lists
Replies: 9
Views: 1169

Re: Question about interface lists

Yup the correct vlan reference article was provided! If you will notice, there is one bridge all vlans, so the bridge does no dhcp or subnet work............. simply create a vlan for that subnet as well. To make changes worry free!!! Actually the best thing to do is take ether5 off the bridge and d...
by anav
Thu Apr 03, 2025 7:58 pm
Forum: General
Topic: Mikrotik iOS app - connection refused
Replies: 3
Views: 701

Re: Mikrotik iOS app - connection refused

Problem would be in the config settings, which are all gone now so cannot really help.......
by anav
Thu Apr 03, 2025 5:27 pm
Forum: Beginner Basics
Topic: beginner - i'm trying to build a vlan
Replies: 10
Views: 1023

Re: beginner - i'm trying to build a vlan

If you will notice, there is one bridge all vlans, so the bridge does no dhcp or subnet work............. simply create a vlan for that subnet as well. Actually the best thing to do is take ether5 off the bridge and do all the config from a safe location. Okay how to create an offbridge port. REMOVE...
by anav
Thu Apr 03, 2025 5:24 pm
Forum: General
Topic: Multi-wan multi-ip wireguard setup
Replies: 15
Views: 1321

Re: Multi-wan multi-ip wireguard setup

Sorry no context provided, why are you mangling for example.......
Do you have a network diagram
by anav
Thu Apr 03, 2025 1:21 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 9404

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

If you want help with your setup post a new thread and will need your traffic requirements and current config.
by anav
Wed Apr 02, 2025 11:22 pm
Forum: General
Topic: Public DNS to private IP
Replies: 44
Views: 2539

Re: Public DNS to private IP

WRONG you do not get to set a false narrative. BE HONEST. First, let's leave out the variable of going to each IoT device. This is something that I will need to do regardless of which solution is implemented. Bullpucky, there is nothing you have to do at each device if they are all currently pointin...
by anav
Wed Apr 02, 2025 10:11 pm
Forum: General
Topic: Public DNS to private IP
Replies: 44
Views: 2539

Re: Public DNS to private IP

That is the point I am making, the work required for firewall rules and routing and allowed IPs needs to be done reqardless of which method is used to get information from the iot device to the home assistant server. What I am saying is that you need to really do a comparison SETUP from where you ar...
by anav
Wed Apr 02, 2025 9:03 pm
Forum: Wireless Networking
Topic: Guest Network: VLAN vs. Bridge
Replies: 10
Views: 2353

Re: Guest Network: VLAN vs. Bridge

Probably more granularity than standard firewall filter rules can provide, although since I dont use bridge filters nothing comes to mind.
by anav
Wed Apr 02, 2025 8:57 pm
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 9404

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

Thanks much lurker, that is most helpful for me and will take the time to digest traffic flows as you have manipulated them!!

Any thoughts on what the responder checkbox is trying to do??
  • 1
  • 2
  • 3
  • 4
  • 5
  • 80