Community discussions

MikroTik App

Search found 23470 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 79
by anav
Wed Apr 02, 2025 3:16 am
Forum: Beginner Basics
Topic: Best gear to receive 4G/5G signal to a cottage
Replies: 5
Views: 919

Re: Best gear to receive 4G/5G signal to a cottage

There is also ATL LTE18 KIT ?
by anav
Wed Apr 02, 2025 3:13 am
Forum: General
Topic: MikroTik RB5009 setting up remotely first time
Replies: 37
Views: 1528

Re: MikroTik RB5009 setting up remotely first time

An accurate description of context is always appreciated from the get go!!
by anav
Wed Apr 02, 2025 2:17 am
Forum: Beginner Basics
Topic: DHCP server for VLAN not working [SOLVED]
Replies: 5
Views: 194

Re: DHCP server for VLAN not working [SOLVED]

Dont understand your diagram, and dont even know which devices you have....... If you are going to provide config /export file=anynameyouwish ( minus router serial number, any publicWANIP information, keys ) You have a trunk port to an AP in the garage which model of AP You dont show a trunk to a sw...
by anav
Tue Apr 01, 2025 10:53 pm
Forum: General
Topic: is it really necesary to mangle wan traffic in a dual ISP scenario?
Replies: 4
Views: 319

Re: is it really necesary to mangle wan traffic in a dual ISP scenario?

If you keep changing the requirements and questions of course the answers will change. The original question was about load balancing the use of the WANs NOT external users access to the LANs or to the routers for config. Vague request beget general answers. Well detailed articulated requirements be...
by anav
Tue Apr 01, 2025 10:37 pm
Forum: General
Topic: Device-mode changes are hilarious
Replies: 13
Views: 533

Re: Device-mode changes are hilarious

... just to change de cpu speed, i need to visit all the country for do that.

Consider yourself lucky. France is not so big. Imagine @anav visiting e.g. Whitehorse suburbs to change cpu speed :wink:
Nothing a trained cat cannot salvage.
Just hire mkx ;-)
......
mkxyes.jpg
by anav
Tue Apr 01, 2025 9:26 pm
Forum: Beginner Basics
Topic: RB951G-2HnD - DUAL Wan Static IP
Replies: 4
Views: 278

Re: RB951G-2HnD - DUAL Wan Static IP

Objective still not fulfilled LARSA, the response from the secondary WAN will still have a source IP of the secondary WAN.
by anav
Tue Apr 01, 2025 9:23 pm
Forum: General
Topic: MikroTik RB5009 setting up remotely first time
Replies: 37
Views: 1528

Re: MikroTik RB5009 setting up remotely first time

If there is a computer in House 1 it would be easiest to use something like TeamViewer to get remote access to the computer, from where you can configure the RB5009 using Winbox.
See post #21 --> Or use anydesk behind a PC that can reach the config.
by anav
Tue Apr 01, 2025 9:21 pm
Forum: General
Topic: WinBox 4 export list of Devices
Replies: 1
Views: 107

Re: WinBox 4 export list of Devices

Take a screenshot?
by anav
Tue Apr 01, 2025 9:20 pm
Forum: General
Topic: Device-mode changes are hilarious
Replies: 13
Views: 533

Re: Device-mode changes are hilarious

If your complaining about you run your support business, wont get much sympathy from here.
There are tools within RoS to accomplish much and if not so technically astute sign up for something like this......... https://admiralplatform.com/
by anav
Tue Apr 01, 2025 2:42 pm
Forum: Beginner Basics
Topic: RB951G-2HnD - DUAL Wan Static IP
Replies: 4
Views: 278

Re: RB951G-2HnD - DUAL Wan Static IP

So you dont want to use the throughput of the secondary WAN at all?
Just the primary router......... is that becasue the secondary WAN is of little throughput?

If the primary goes down, then you will have to use the second WAN, and it will not be possible to hide this fact.
by anav
Tue Apr 01, 2025 12:57 am
Forum: Beginner Basics
Topic: lan ip to wan ip scenario
Replies: 2
Views: 279

Re: lan ip to wan ip scenario

Are you saying you get 9 WANIP addresses from a single provider?
Are you saying the gateway for all 9 is the same?

Why do some have ip address starting with 92.x and some have 88.y ??

PS. wireguard is not an interface that gets a pool, no dhcp etc..
by anav
Mon Mar 31, 2025 10:02 pm
Forum: Wireless Networking
Topic: Guest Network: VLAN vs. Bridge
Replies: 6
Views: 1038

Re: Guest Network: VLAN vs. Bridge

Your funeral to go off on tangents, and no bridge filters are for advanced users only, I dont touch them being an intermediate user.
Quickset should have been name quicksand :-)
by anav
Mon Mar 31, 2025 8:36 pm
Forum: Beginner Basics
Topic: internet speed
Replies: 5
Views: 382

Re: internet speed

What model of access points? The config is basically default so there should be no difference between wired or wifi clients based on the config.
So the issue is a the AP side............
by anav
Mon Mar 31, 2025 8:03 pm
Forum: Beginner Basics
Topic: CRS326 powerful enough?
Replies: 8
Views: 476

Re: CRS326 powerful enough?

Can your ISP router even do vlans?
by anav
Mon Mar 31, 2025 8:02 pm
Forum: General
Topic: MikroTik RB5009 setting up remotely first time
Replies: 37
Views: 1528

Re: MikroTik RB5009 setting up remotely first time

Or string two soup cans together and shoot one over to the remote location and get a person at that end to put it near the MT device.
Or use anydesk behind a PC that can reach the config.
by anav
Mon Mar 31, 2025 3:19 pm
Forum: General
Topic: VRRP Stuck in Master in both devices
Replies: 13
Views: 1597

Re: VRRP Stuck in Master in both devices

Mimiko, I call BS, you didnt originate the thread, popped in to complain, and have not provided the configs of your devices......
/export file=anynameyouwish ( minus router serial number, any public WANIP information,keys)
by anav
Mon Mar 31, 2025 6:02 am
Forum: General
Topic: is it really necesary to mangle wan traffic in a dual ISP scenario?
Replies: 4
Views: 319

Re: is it really necesary to mangle wan traffic in a dual ISP scenario?

ECMP is perfectly fine to use for dual or more wans. Its the least complicated approach. With version 7 firmware it should be the first go to approach.
Mangling and PCC come into play for more complex user needs or if the admin has wan throughputs that are wildly dissimilar
by anav
Mon Mar 31, 2025 4:30 am
Forum: General
Topic: MikroTik RB5009 setting up remotely first time
Replies: 37
Views: 1528

Re: MikroTik RB5009 setting up remotely first time

Guidance provided based on your answer above!!
You have lots to learn prior to trying to remotely configuring a 5009.
If you are truly DYI then get GNS3 or EVE-NG and setup a lab type setting where you can practice learning about RoS.
by anav
Mon Mar 31, 2025 3:36 am
Forum: General
Topic: MikroTik RB5009 setting up remotely first time
Replies: 37
Views: 1528

Re: MikroTik RB5009 setting up remotely first time

Have you ever used Mikrotik and configured it before?
No
https://mikrotik.com/consultants
by anav
Mon Mar 31, 2025 12:48 am
Forum: Wireless Networking
Topic: access point won't start
Replies: 8
Views: 782

Re: access point won't start

something wrong with the ignition coil no doubt. ;-) I will have a look at the config. This if for L1009 with wifi, since its the only config provided. 1. REMOVE bridge from interface list! It is no longer required as it is the vlans that need to be identified as members. add interface=bridge_router...
by anav
Mon Mar 31, 2025 12:45 am
Forum: General
Topic: Wireguard setup for both internal and external access
Replies: 3
Views: 293

Re: Wireguard setup for both internal and external access

If you can port forward then you can host wireguard which you will need to do. AirVPN and other types of VPN are NOT for connecting to Air VPN and then to your home router. They are of the type of VPN service that simply provides internet out a different location/country, by either users on the rout...
by anav
Sun Mar 30, 2025 11:52 pm
Forum: Wireless Networking
Topic: Mikrotik hAP LTE6 as a travel router setup?
Replies: 10
Views: 947

Re: Mikrotik hAP LTE6 as a travel router setup?

More importantly can some one wifi expertise please help the OP. Geez!!
by anav
Sun Mar 30, 2025 11:51 pm
Forum: Wireless Networking
Topic: WiFi 2.4GHz b/g/n Setup
Replies: 3
Views: 304

Re: WiFi 2.4GHz b/g/n Setup

I believe AX covers all, in other words it defaults and covers off whatever signal comes in and is thus equivalent to ALL Not really sure, but I also believe that whatever signal is processed then that is the lowest commen denominator. AKA if our processing B, then all other connections after will c...
by anav
Sun Mar 30, 2025 11:44 pm
Forum: Beginner Basics
Topic: VPN with relay on a VPS - working around the CGNAT
Replies: 15
Views: 877

Re: VPN with relay on a VPS - working around the CGNAT

I use winbox all the time from PC behind my router to reach distant devices. If you need to connect to devices behind the router, then type in their applicable IP address, in this case its management IP address. Once connected to the 5009 over wireguard try this ( critical first step ) For example t...
by anav
Sun Mar 30, 2025 11:40 pm
Forum: Beginner Basics
Topic: Basic settings for PCC [SOLVED]
Replies: 4
Views: 350

Re: Basic settings for PCC [SOLVED]

ECMP on MT not to be confused with EMP LOL
by anav
Sun Mar 30, 2025 11:38 pm
Forum: Wireless Networking
Topic: RB2011 with a router switch and hap ax2 as aps
Replies: 5
Views: 377

Re: RB2011 with a router switch and hap ax2 as aps

Typical AP setup will assume 99 is management vlan, 10 is home 20 is guest wifi and 30 is IOT wifi, and ether2 is a wired port for home user. /interface bridge add ingress-filtering=no name=bridgegym port-cost-mode=short vlan-filtering=yes /interface ethernet set [ find default-name=ether5 ] name=Of...
by anav
Sun Mar 30, 2025 11:05 pm
Forum: General
Topic: routerOS & Mirkotik for the noobs
Replies: 6
Views: 679

Re: routerOS & Mirkotik for the noobs

When working with vlans and bridge the best approach is take one port Off the Bridge and do all the configuring from this safe spot. The best thing you can do is take one port off the bridge and do your config from there, a safe spot. 1. Take ether5off the bridge at /interface bridge port 2. Make th...
by anav
Sun Mar 30, 2025 11:00 pm
Forum: Wireless Networking
Topic: RB2011 with a router switch and hap ax2 as aps
Replies: 5
Views: 377

Re: RB2011 with a router switch and hap ax2 as aps

I do not know with any certainty but I would think that having all devices on the same version of firmware will be helpful. I am not a capsman guy but to get your RB2011 and 6 APs working, I can provide assistance without capsman to at least get you to a working config. While you have that, suggest ...
by anav
Sun Mar 30, 2025 10:57 pm
Forum: Wireless Networking
Topic: Unifi access point
Replies: 16
Views: 2379

Re: Unifi access point

My first instinct was correct still have my lama sense workin. /file=anynameyouwish ( minus router serial number, any public WANIP information, keys ). Answer is the same, it will work if you configure it properly. The problem is you have not provided the FACTS, or EVIDENCE with which folks here can...
by anav
Sun Mar 30, 2025 10:45 pm
Forum: Wireless Networking
Topic: 7.18 CAPSMAN v2 VLAN provisioning problem to WAP ax
Replies: 9
Views: 619

Re: 7.18 CAPSMAN v2 VLAN provisioning problem to WAP ax

Yup, hair turned grey, or loss of hair, skin aged, and suddenly it works. to bad the OP has no clue why, nothing learned. caps SUCKETH the big bone.
by anav
Sun Mar 30, 2025 10:43 pm
Forum: Wireless Networking
Topic: Wifi connects, but no internet
Replies: 9
Views: 554

Re: Wifi connects, but no internet

The best thing you can do is take one port off the bridge and do your config from there, a safe spot. 1. Take ether5 off the bridge at /interface bridge port 2. Make the following additions/mods /interface ethernet set [ find default-name=ether5] comment=OffBridge5 /interface list member add interfa...
by anav
Sun Mar 30, 2025 10:36 pm
Forum: Beginner Basics
Topic: HAP AC3 Error in Master - selection expected!
Replies: 1
Views: 206

Re: HAP AC3 Error in Master - selection expected!

Thats nice, and how do you suppose we are supposed to assist without seeing what you have done on the config to cause this?? Im assuming you at least created a wifi profile for wifi1 or wifi2 such that a master would exist. /export file=anynameyouwish (minus router serial number, any public WANIP in...
by anav
Sun Mar 30, 2025 10:34 pm
Forum: Beginner Basics
Topic: VLAN issue(s)
Replies: 11
Views: 662

Re: VLAN issue(s)

Good to hear, others prefer insanity, greying of hair and hair loss, to get capsman going. Is it worth it, not to me!
by anav
Sun Mar 30, 2025 10:08 pm
Forum: Beginner Basics
Topic: VPN with relay on a VPS - working around the CGNAT
Replies: 15
Views: 877

Re: VPN with relay on a VPS - working around the CGNAT

As for your switch which port on the 5009 goes to the switch........ SAME ISSUE for discover,... WRONG /tool mac-server set allowed-interface-list= MGMT /tool mac-server mac-winbox set allowed-interface-list= none /tool mac-server set allowed-interface-list= none /tool mac-server mac -winbox set all...
by anav
Sun Mar 30, 2025 10:07 pm
Forum: Beginner Basics
Topic: VPN with relay on a VPS - working around the CGNAT
Replies: 15
Views: 877

Re: VPN with relay on a VPS - working around the CGNAT

Not sure what you mean.......... You have this on the config, which is a good start. /ip neighbor discovery-settings set discover-interface-list=MGMT BUT THE ERROR comes later. You reversed the settings /tool mac-server set allowed-interface-list= MGMT /tool mac-server mac-winbox set allowed-interfa...
by anav
Sun Mar 30, 2025 10:01 pm
Forum: Beginner Basics
Topic: Basic settings for PCC [SOLVED]
Replies: 4
Views: 350

Re: Basic settings for PCC [SOLVED]

No PCC is for load balancing multiple WAN connections for: a. the purpose of redundancy so that if one ISP goes down you have a backup ( clearly not useful if all the WANs come from the same provider ) b. to provide a greater overall bandwidth to share with users, so there are less bottlenecks in tr...
by anav
Sun Mar 30, 2025 9:57 pm
Forum: Beginner Basics
Topic: Wireguard roadwarrior on LTE router- Handshake failed
Replies: 3
Views: 271

Re: Wireguard roadwarrior on LTE router- Handshake failed

Without seeing your config, hard to see what you have done??
Assuming you have a public WANIP or you can forward ports from an ISP router that has a public IP??
by anav
Sun Mar 30, 2025 9:55 pm
Forum: Beginner Basics
Topic: Disable CAP mode without UI
Replies: 7
Views: 3597

Re: Disable CAP mode without UI

Another reason to avoid anything cap like the plague.
by anav
Sun Mar 30, 2025 9:53 pm
Forum: General
Topic: Wireguard setup for both internal and external access
Replies: 3
Views: 293

Re: Wireguard setup for both internal and external access

Draw a diagram because you seem to want opposed uses. Wireguard to a third party server Wireguard to home. Which is it or both? ++++++++++++++ It sounds like you need two wireguard interfaces one for third party and one for home. Do you have a public IP address or can you forward ports from an ISP r...
by anav
Sun Mar 30, 2025 5:11 pm
Forum: Beginner Basics
Topic: VPN with relay on a VPS - working around the CGNAT
Replies: 15
Views: 877

Re: VPN with relay on a VPS - working around the CGNAT

Easy Peasy now that I have facts to work with! :-) /interface list member add interface=ether7 list=WAN add interface=PRIVATE_VLAN list=VLAN add interface=GUEST_VLAN list=VLAN add interface=IOT_VLAN list=VLAN add interface=SECURITY_VLAN list=VLAN add interface=MGMT_VLAN list=VLAN add interface=MGMT_...
by anav
Sun Mar 30, 2025 2:34 pm
Forum: Beginner Basics
Topic: VPN with relay on a VPS - working around the CGNAT
Replies: 15
Views: 877

Re: VPN with relay on a VPS - working around the CGNAT

Then add access to the management vlan.
add action=accept chain=forward comment="remote admin to trusted vlan" in-interface=BTHWireguard out-interface=vlan-mgmt
by anav
Sun Mar 30, 2025 2:27 am
Forum: Beginner Basics
Topic: VPN with relay on a VPS - working around the CGNAT
Replies: 15
Views: 877

Re: VPN with relay on a VPS - working around the CGNAT

Well the way it works is you enable BTH on the router. Take the first created user and install that on your smart phone, any other users have to be created on the smartphone as well. You will need to go to the router at your parents place allows the subnet of wireguard access on the input chain add ...
by anav
Sun Mar 30, 2025 2:21 am
Forum: General
Topic: Wireguard tunnel stopping on its own
Replies: 10
Views: 2251

Re: Wireguard tunnel stopping on its own

There is a responder checkbox in winbox I think, try checking that, and see if the issue persists.
.........
Screenshot 2025-03-29 212138.png
by anav
Sat Mar 29, 2025 11:22 pm
Forum: Beginner Basics
Topic: Choice of VPN
Replies: 1
Views: 202

Re: Choice of VPN

Look at zerotier to share gaming server............
by anav
Sat Mar 29, 2025 11:21 pm
Forum: Beginner Basics
Topic: Noob can't seem to integrate VLAN, despite following guide
Replies: 11
Views: 818

Re: Noob can't seem to integrate VLAN, despite following guide

The arubas will need to be setup with vlans. They should get their IP address on the VLAN99
by anav
Sat Mar 29, 2025 11:12 pm
Forum: Beginner Basics
Topic: Noob can't seem to integrate VLAN, despite following guide
Replies: 11
Views: 818

Re: Noob can't seem to integrate VLAN, despite following guide

So theree switches means three trunk ports BUT................. The unifi expects the trusted or managament vlan untagged and the data vlans tagged. If they are consistent in setup. I'm assuming the arubas are more standard switches. What are the AP types?? /interface bridge port add bridge=bridge1 ...
by anav
Sat Mar 29, 2025 11:07 pm
Forum: Beginner Basics
Topic: VLAN issue(s)
Replies: 11
Views: 662

Re: VLAN issue(s)

I dont use capsman because its too difficult and a headache for me. I use what works. Capsman is better if you do it successfully as it allows for better handoff between APs, I could care less in my own house. This will get you setup and working, and then you can implement capsman and whatever else ...
by anav
Sat Mar 29, 2025 10:01 pm
Forum: Beginner Basics
Topic: VPN with relay on a VPS - working around the CGNAT
Replies: 15
Views: 877

Re: VPN with relay on a VPS - working around the CGNAT

Well the VPS aka a CHR in a cloud is about $6 a month to rent plus the CHR license and use Wireguard VPN, and is a great way to do what you want to do without third party servers. Preferred option 4 You could do it right now with VPN WIREGUARD BTH depending upon what router you bought your parents a...
by anav
Sat Mar 29, 2025 9:55 pm
Forum: General
Topic: What's using the memory?
Replies: 10
Views: 586

Re: What's using the memory?

I have an ax3
Total memory 1024 MiB
Avail Free memory: 651.2 MiB

Meaning used memory is 373.

I do not use any logging or at least minimize it if all possible.
Do not expect the ax3 to be any zippier, unless your holvoe, the rest of us mere mortals get around what you are getting.
by anav
Sat Mar 29, 2025 7:42 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 6993

Re: My recent VLAN fiasco [SOLVED]

Even more pertinent in Basic but based on your lack of experience on the forum ( clearly IT trained and more knowledgeable than I will ever be ) I disagree. :-)
by anav
Sat Mar 29, 2025 7:37 pm
Forum: Beginner Basics
Topic: VLAN issue(s)
Replies: 11
Views: 662

Re: VLAN issue(s)

CAPAC, same concept using offbridge on etherport 2. ALso I always wire the capac on ether2 to a spot where I can at least plug in a laptop, could be a closet etc...... emerg config when the capac is very hard to reach etc. Where you set the cap address statically to 192.168.1.xx .......................
by anav
Sat Mar 29, 2025 6:51 pm
Forum: Beginner Basics
Topic: VLAN issue(s)
Replies: 11
Views: 662

Re: VLAN issue(s)

Why are you using the capax as a router. All the router stuff should be done on the chateau and the capax as an ap/switch ?? If this is the chateaux then.............. concur the simple approach works and should be the starting point...... Will stick to one trusted vlan and one untrusted vlan. Note ...
by anav
Sat Mar 29, 2025 6:48 pm
Forum: Beginner Basics
Topic: Noob can't seem to integrate VLAN, despite following guide
Replies: 11
Views: 818

Re: Noob can't seem to integrate VLAN, despite following guide

1. Adjusted as required. add name=bridge1 port-cost-mode=short vlan-filtering=yes { add the YES as last rule change) /interface ethernet set [ find default-name=ether8 ] name=OffBridge8 /interface vlan add interface=bridge1 name=BASE_VLAN vlan-id=99 add comment="Guest VLAN" interface=bridg...
by anav
Sat Mar 29, 2025 4:51 pm
Forum: Beginner Basics
Topic: firewall rules advices
Replies: 7
Views: 531

Re: firewall rules advices

Before you apply anything one must understand the purpose of the chains. Input chain is traffic TO the router, so to router services. None of your servers behind the router and on the LAN have anything to do with router services and thus seeing their rules in the input chain is ridonkulous. So from ...
by anav
Sat Mar 29, 2025 4:44 pm
Forum: General
Topic: Beginner VLAN questions
Replies: 18
Views: 1212

Re: Beginner VLAN questions

That is weird behaviour, perhaps the power cord or supply is wonky? Cables wonky? or maybe the router is toasted??
Suggest try netsinstall as well.
by anav
Sat Mar 29, 2025 4:34 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 6993

Re: My recent VLAN fiasco [SOLVED]

I think mkx said it best in poetry, just make your config look like mine and all will be happy. ;-)
What we need, no joke, is for new users to be educated prior to making their first posting, and a sandbox where posts can be reviewed prior to posting live.
by anav
Fri Mar 28, 2025 6:35 pm
Forum: General
Topic: Feature request - add interface Vlans & ports & bridge functions into a single easy Winbox/Web settings page
Replies: 10
Views: 1810

Re: Feature request - add interface Vlans & ports & bridge functions into a single easy Winbox/Web settings page

Haha,
My answer to your question is simple, Welcome to Canada, South BC ( formerly North Idaho ). :-)

I see what your getting at, try to merge SwoS simplicity within RoS for vlans.
I like the concept.

PS. Working on my Teeter Accent, in case things go awry.
by anav
Fri Mar 28, 2025 3:50 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 6993

Re: My recent VLAN fiasco [SOLVED]

I wouldnt know eltikpad, I have never had to resort to putting an address on the bridge while using vlans. I prefer clean separation of bridge from DHCP etc, once I start using vlans.
by anav
Fri Mar 28, 2025 3:15 pm
Forum: Beginner Basics
Topic: Noob can't seem to integrate VLAN, despite following guide
Replies: 11
Views: 818

Re: Noob can't seem to integrate VLAN, despite following guide

Two recommendations
a. take one port off the bridge and safely do all configuration from this port
b. go all vlans, remove bridge from dhcp etc, and simple move this subnet to another vlan.

Willing to go this route let me know.
by anav
Fri Mar 28, 2025 3:10 pm
Forum: General
Topic: Feature request - add interface Vlans & ports & bridge functions into a single easy Winbox/Web settings page
Replies: 10
Views: 1810

Re: Feature request - add interface Vlans & ports & bridge functions into a single easy Winbox/Web settings page

Tom, these engineers are not all that resourceful, they never came here for help! ;-) I do know that Mikrotik has been making advancements in the automation of setting up vlans on multiple connected devices and automations on interface lists etc...... But nothing towards what you are looking at ... ...
by anav
Fri Mar 28, 2025 3:04 pm
Forum: General
Topic: how to route multiple WANs to CHR over the Wireguard tunnel.
Replies: 16
Views: 1350

Re: how to route multiple WANs to CHR over the Wireguard tunnel.

If you dont post the complete config I dont bother looking.

/export file=anynameyouwish ( minus router serial number, any public WANIP information, vpn keys, long dchp lease lists )
by anav
Fri Mar 28, 2025 3:02 pm
Forum: General
Topic: Traffic shaping (filter the WhatsApp and TikTok traffic)
Replies: 7
Views: 559

Re: Traffic shaping (filter the WhatsApp and TikTok traffic)

Sorry sippan, what is BS is false hope and promises.
If you are unable to inspect encrypted traffic, then do pray tell what effing magic do you use........
by anav
Fri Mar 28, 2025 2:45 pm
Forum: General
Topic: Winbox timeout with wireguard
Replies: 3
Views: 502

Re: Winbox timeout with wireguard

Why do you think that the firewall is where the problem is...............
by anav
Fri Mar 28, 2025 2:30 am
Forum: General
Topic: Traffic shaping (filter the WhatsApp and TikTok traffic)
Replies: 7
Views: 559

Re: Traffic shaping (filter the WhatsApp and TikTok traffic)

Probably neither you need an expensive router add then pay for subscription services to handle DPI etc.........
by anav
Thu Mar 27, 2025 9:47 pm
Forum: General
Topic: Make WireGuard VPN accessible from anywhere
Replies: 2
Views: 343

Re: Make WireGuard VPN accessible from anywhere

Your request is not clear.
Do you host a wireguard server on your router or are you connecting to a 3rd party server for example.
What are the use cases for wireguard, who uses it and for what purposes.
by anav
Thu Mar 27, 2025 5:25 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 6993

Re: My recent VLAN fiasco [SOLVED]

For me its clear enough, /interface bridge ports and /interface bridge vlans tells a story, the combination informs the router ( and the reader ) how to distribute subnets on the device. Nothing hidden all up front. The two groups of settings cross-check each other for a consistent story. Really the...
by anav
Thu Mar 27, 2025 4:07 pm
Forum: General
Topic: rOS for L2 switches
Replies: 6
Views: 585

Re: rOS for L2 switches

Doesnt show up in winbox, and cannot open it in winbox................ Finicky as shit when playing with access permissions.........
by anav
Thu Mar 27, 2025 2:47 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 6993

Re: My recent VLAN fiasco [SOLVED]

Not hyping it down, but its actual use as a data vlan is very niche (rare).
by anav
Thu Mar 27, 2025 12:56 pm
Forum: General
Topic: Feature request - add interface Vlans & ports & bridge functions into a single easy Winbox/Web settings page
Replies: 10
Views: 1810

Re: Feature request - add interface Vlans & ports & bridge functions into a single easy Winbox/Web settings page

Hi Nathan, great summary. However I am helping mostly new persons and they dont understand the basic entry method (manual) which uses both /interface bridge port and vlan to tell a coherent story. In fact by cross-checking the two sets of entries, a consistent approach and understanding is solidifie...
by anav
Thu Mar 27, 2025 2:56 am
Forum: General
Topic: Beginner VLAN questions
Replies: 18
Views: 1212

Re: Beginner VLAN questions

On the switch, are all ports used, if not dont include them in config.
Why is ether2 part of an LACP and yet you have an address assigned to it.....

More to the point are all these other ports using 10.10.1.X addresses
by anav
Thu Mar 27, 2025 2:49 am
Forum: General
Topic: Beginner VLAN questions
Replies: 18
Views: 1212

Re: Beginner VLAN questions

Okay how to create an offbridge port. REMOVE ether4 from /interface bridge ports /interface ethernet set [ find default-name=ether4 ] comment=OffBridge4 /interface list add list=TRUSTED /interface list member add interface=OffBridge4 list=TRUSTED add interface=mgmt_vlan list=TRUSTED add interface=mg...
by anav
Thu Mar 27, 2025 1:43 am
Forum: General
Topic: Beginner VLAN questions
Replies: 18
Views: 1212

Re: Beginner VLAN questions

Looking at it more closely I dont see any vlans assigned in your cap so maybe tis okay....... Just didnt want to put my foot in it, so to speak., Happy to take a look and pretend its not there LOL. The first problem is that there is only one VLAN, the management vlan. Where is the vlan for the WIFI>...
by anav
Thu Mar 27, 2025 1:30 am
Forum: General
Topic: Beginner VLAN questions
Replies: 18
Views: 1212

Re: Beginner VLAN questions

Cant help you since using capsman. Dont know how that interacts with bridges and vlans sorry.
by anav
Wed Mar 26, 2025 10:54 pm
Forum: General
Topic: how to route multiple WANs to CHR over the Wireguard tunnel.
Replies: 16
Views: 1350

Re: how to route multiple WANs to CHR over the Wireguard tunnel.

It should work with the settings I provided via CLI at the end of the post. Additional note for CHR Traffic. To ensure stable connectivity with all types of internet sites (banking etc.) Suggest try the default L3 hash on ECMP as that should provide optimal results. If that doesnt work you can try L...
by anav
Wed Mar 26, 2025 10:52 pm
Forum: Beginner Basics
Topic: Wireguard, Routing Tables and Mangle
Replies: 3
Views: 503

Re: Wireguard, Routing Tables and Mangle

Duplicate Thread, please follow here............ viewtopic.php?p=1135310#p1135262
by anav
Wed Mar 26, 2025 10:47 pm
Forum: Beginner Basics
Topic: Wireguard Client to remote Ubuntu Wireguard [SOLVED]
Replies: 6
Views: 4411

Re: Wireguard Client to remote Ubuntu Wireguard [SOLVED]

allright so to be clear its not the entire subnet but only two Ip addresses, this should work for you /routing table add fib name=useWG / ip route add dst-address=0.0.0.0/0 gateway=WG_Interface routing-table=useWG /routing rules add min-prefix=0 action=lookup-only-in-bridge table=main { permits any ...
by anav
Wed Mar 26, 2025 9:39 pm
Forum: General
Topic: wireguard went down after advanced guide
Replies: 6
Views: 541

Re: wireguard went down after advanced guide

No worries, many parts of a config are interrelated and thus a snippet really never tells the whole story.
by anav
Wed Mar 26, 2025 9:22 pm
Forum: General
Topic: wireguard went down after advanced guide
Replies: 6
Views: 541

Re: wireguard went down after advanced guide

Ironic, that you were comfortable applying advances pages but dont understand what they are doing, but less so, for experienced users that are willing to provide some practical advice. There is nothing in an anonimized configuration that renders your network to any danger. /export file=anynameyouwis...
by anav
Wed Mar 26, 2025 7:58 pm
Forum: General
Topic: WINBOX 4 WIREGUARD --> RE-IMAGINED
Replies: 6
Views: 918

Re: WINBOX 4 WIREGUARD --> RE-IMAGINED

On feedback from MT, some changes could be made to re-arrange the menus and thus the next attempt will be to do so, while preserving the overall concept of form follows function. The approach to the wireguard interface is simply superior and should be adopted, including the option to add IP address ...
by anav
Wed Mar 26, 2025 7:51 pm
Forum: Beginner Basics
Topic: Can't get VLAN trunk working
Replies: 10
Views: 777

Re: Can't get VLAN trunk working

Bingo! Many thanks @CGGXANNX I was working from the assumption (stupid me) that setting the untagged VLAN was sufficient, but effectively it also needed to be manually assigned the PVID and I hadn't even looked into that submenu as the VID title didn't make me think of everything. If only the title...
by anav
Wed Mar 26, 2025 7:06 pm
Forum: General
Topic: wireguard went down after advanced guide
Replies: 6
Views: 541

Re: wireguard went down after advanced guide

Instead of describing hypotheticals, and rules completely out of context, please provide the use-cases, aka actual traffic requirements. a. identify user(s)/groups of users including admin, external, internal b. identify all the traffic they require to execute. c. detail particulars about wan connec...
by anav
Wed Mar 26, 2025 6:51 pm
Forum: General
Topic: [Routing/Firewall] Mixed network mikrotik - Ubiquiti
Replies: 12
Views: 876

Re: [Routing/Firewall] Mixed network mikrotik - Ubiquiti

Good point tdw,
The Unifi Gateway (its wanip) can be on the same mikrotik vlan as the Unifi AP for example which should simplify matters.
by anav
Wed Mar 26, 2025 6:35 pm
Forum: Useful user articles
Topic: Optimizing MikroTik hAP ax³ (C53UiG+5HPaxD2HPaxD) WiFi Speeds
Replies: 4
Views: 6363

Re: Optimizing MikroTik hAP ax³ (C53UiG+5HPaxD2HPaxD) WiFi Speeds

Strictly wifi, correct, no capsman right!
by anav
Wed Mar 26, 2025 6:31 pm
Forum: General
Topic: [Routing/Firewall] Mixed network mikrotik - Ubiquiti
Replies: 12
Views: 876

Re: [Routing/Firewall] Mixed network mikrotik - Ubiquiti

For example this OP seems to be doing just that................
viewtopic.php?t=215720
by anav
Wed Mar 26, 2025 6:13 pm
Forum: Beginner Basics
Topic: Wireguard Client to remote Ubuntu Wireguard [SOLVED]
Replies: 6
Views: 4411

Re: Wireguard Client to remote Ubuntu Wireguard [SOLVED]

https://forum.mikrotik.com/viewtopic.php?t=143620 Bridge should not normally do DHCP in a vlan setup......... simply create another vlan, amend any associated config lines. It is not clear yet what subnet or user(s) are supposed to go out wireguard. I do see an attempt so sourcneat wireguard traffic...
by anav
Wed Mar 26, 2025 6:03 pm
Forum: Beginner Basics
Topic: When is connection-nat-state applied (default firewall rule)?
Replies: 13
Views: 1588

Re: When is connection-nat-state applied (default firewall rule)?

What you probably realized somewhere through the long winded explanations of my colleagues ;-P, is that the rule actually provides three functions. a. allows traffic from the wan that is for port forwarding ( obtainable understanding ) b. drops any other traffic from the wan ( kinda obscure ) c. all...
by anav
Wed Mar 26, 2025 5:47 pm
Forum: Beginner Basics
Topic: Wireguard, Routing Tables and Mangle
Replies: 3
Views: 503

Re: Wireguard, Routing Tables and Mangle

Not sure what you are connecting to, that is the missing link
3rd party VPN, a friends server, a Cloud based wireguard ????
by anav
Wed Mar 26, 2025 5:19 pm
Forum: General
Topic: how to route multiple WANs to CHR over the Wireguard tunnel.
Replies: 16
Views: 1350

Re: how to route multiple WANs to CHR over the Wireguard tunnel.

Sorry cannot help you. I have provided enough information to give you a load balance of ALL users going to CHR and a load balance of any users not going through CHR.
Not my problem you are fixated on PCC, when its not required and far more complex.
by anav
Wed Mar 26, 2025 5:04 pm
Forum: General
Topic: Which switch?
Replies: 20
Views: 1149

Re: Which switch?

You can read specifications as well as anyone else, depends on your requirements etc.
For me since I love, setting up vlans on mikrotik products via RoS, its the one I would go with.
If you want a plugNplay setup, then I would go with the zyxel ( but only because of that killer sale price )
by anav
Wed Mar 26, 2025 5:03 pm
Forum: General
Topic: [Routing/Firewall] Mixed network mikrotik - Ubiquiti
Replies: 12
Views: 876

Re: [Routing/Firewall] Mixed network mikrotik - Ubiquiti

I would throw away the ubiquiti gateway ultra. Pretty dumb if you cannot buy an AP and get it to work, but instead you have to buy a second ubiquiti product to talk to the AP. To unlock the full potential of UniFi APs, including advanced features and centralized management, you'll need to use a UniF...
by anav
Wed Mar 26, 2025 4:54 pm
Forum: General
Topic: Block OpenVPN connection
Replies: 6
Views: 559

Re: Block OpenVPN connection

Try a more useful set of firewall rules. /ip firewall filter {default rules to keep} add action=accept chain=input connection-state=established,related,untracked add action=drop chain=input connection-state=invalid add action=accept chain=input protocol=icmp (admin rules) add action=accept chain=inp...
by anav
Wed Mar 26, 2025 4:39 pm
Forum: General
Topic: Which switch?
Replies: 20
Views: 1149

Re: Which switch?

Looking at competitors, the only one that comes close to the 328 is this one in terms of price and features..
Personally, If you prefer RoS, then MT is the way to go. If not using RoS, then at the price prefer the latter.
https://www.zyxelguard.com/XGS1930-28HP.asp
by anav
Wed Mar 26, 2025 4:22 pm
Forum: General
Topic: Beginner VLAN questions
Replies: 18
Views: 1212

Re: Beginner VLAN questions

Repost both configs for review and use code tags for both.
by anav
Wed Mar 26, 2025 4:19 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 6993

Re: My recent VLAN fiasco [SOLVED]

Thanks Nathan, that is the practical answer and enough technical description I was looking for to continue a general approach to all configs. Very often there is a mix of different vendor switches involved downstream from an MT router. Luckily, thus far I have not needed a config that required vlan1...
by anav
Wed Mar 26, 2025 4:07 pm
Forum: General
Topic: VRRP Best Practices
Replies: 3
Views: 506

Re: VRRP Best Practices

Counter opinion, or at least different, TWO VRRF instances. RouterA - VRRF1 - Primary Router and used by VLANs from Router A RouterB - VRRF2 - Primary Router and used by VLANS from Router B. In this way the throughput of both providers is utilized ( why not paying for both!!) and the router vlans do...
by anav
Sat Mar 22, 2025 12:59 am
Forum: General
Topic: hAP ac2 vs ax2 or ax3 ethernet performance
Replies: 8
Views: 1049

Re: hAP ac2 vs ax2 or ax3 ethernet performance

I have no reason to doubt that the AX3 is best followed by hapac2 followed by hapax2 based on those tests.
Your in Riga, pop over to MT to confirm!!
by anav
Sat Mar 22, 2025 12:57 am
Forum: General
Topic: MT Wireguard over VRRP WAN
Replies: 5
Views: 733

Re: MT Wireguard over VRRP WAN

Well endpoint has to be a specific WAN for the client to reach the right ROUTER.
The VRRP is for the inside facing users from what I understand.
But its a good point for discussion. Looking forward to what comes out of this thread.
by anav
Fri Mar 21, 2025 10:30 pm
Forum: Beginner Basics
Topic: WireGuard with CloudFlare DNS [SOLVED]
Replies: 21
Views: 5514

Re: WireGuard with CloudFlare DNS [SOLVED]

Nice!!
by anav
Fri Mar 21, 2025 10:28 pm
Forum: General
Topic: Expired SSL cert locks you out of 7.18.2 GUI
Replies: 7
Views: 681

Re: Expired SSL cert locks you out of 7.18.2 GUI

Use wireguard.
by anav
Fri Mar 21, 2025 6:58 pm
Forum: Beginner Basics
Topic: WireGuard with CloudFlare DNS [SOLVED]
Replies: 21
Views: 5514

Re: WireGuard with CloudFlare DNS [SOLVED]

Sure that makes sense, if you have misconfigured your wireguard.
If the router is server peer for handshake and it has a number of peers, and one of the peer client settings on the ROUTER, has the error of 0.0.0.0/0 set in Allowed addresses, then this type of problem occurs.
by anav
Fri Mar 21, 2025 6:56 pm
Forum: Beginner Basics
Topic: SRC-Nat confused
Replies: 2
Views: 437

Re: SRC-Nat confused

Your trying to stuff a pre-conceived solution for an unknown problem into the MT, the worst way to proceed.
Suggest you detail the USER TRAFFIC requirements, the use-cases that are driving your request.

It may very well be that other tools and methods make sense.
by anav
Fri Mar 21, 2025 6:49 pm
Forum: General
Topic: dst-nat to local server with clients on same VLAN
Replies: 1
Views: 376

Re: dst-nat to local server with clients on same VLAN

For all IPs that either should not or admin wants not to get forced out of server. /ip firewall address-list add address=IPofDNS list= Exempt comment=" the dns server itself" add address=someOtherUser list=Exempt comment="user to router DNS not my server" /ip firewall nat add cha...
by anav
Fri Mar 21, 2025 3:50 pm
Forum: Beginner Basics
Topic: WireGuard with CloudFlare DNS [SOLVED]
Replies: 21
Views: 5514

Re: WireGuard with CloudFlare DNS [SOLVED]

Its not wireguard, that is the problem.
Reset your config to defaults then add wireguard and see if it works.
by anav
Fri Mar 21, 2025 3:06 pm
Forum: General
Topic: RB4011iGS+5HacQ2HnD-IN end of life?
Replies: 5
Views: 1411

Re: RB4011iGS+5HacQ2HnD-IN end of life?

Thats the European polite answer or part of anyway. This is the German answer!!! This is why if the OP came to me, offering their business I would run for the hills ( okay drive to the Swiss Alps in my Audi ) Tying the router to wifi is STEWPID, wifi technology changes much more quickly and ideal pl...
by anav
Fri Mar 21, 2025 4:13 am
Forum: General
Topic: Question about how wireguard and routing
Replies: 3
Views: 553

Re: Question about how wireguard and routing

In this case the wireguard traffic is going to some third party site, presumably to go out internet there. Probably not even a wireguard device at the other end. Since we dont control both ends, how is the remote end supposed to know what subnets we are going to have coming through on wireguard. THe...
by anav
Thu Mar 20, 2025 8:30 pm
Forum: Beginner Basics
Topic: A switch for the switches
Replies: 3
Views: 659

Re: A switch for the switches

Is this a homework question?
If not, then please detail the business requirements and traffic flow requirements.
by anav
Thu Mar 20, 2025 5:19 pm
Forum: General
Topic: Switching capability
Replies: 3
Views: 512

Re: Switching capability

I’m planning to setup a LAN with few CRS354 and CRS328 all PoE capable ( that’s why of 328 choice for 24ports switches) all linked by 10G sfp+ The only concern is about different switching capability between these two machines, 328 are rather old design…. Any thought ? ? YEAH what a crappy way to m...
by anav
Thu Mar 20, 2025 5:12 pm
Forum: General
Topic: WINBOX 4 WIREGUARD --> RE-IMAGINED
Replies: 6
Views: 918

Re: WINBOX 4 WIREGUARD --> RE-IMAGINED

BLANK FOR FUTURE IDEAS
by anav
Thu Mar 20, 2025 5:12 pm
Forum: General
Topic: WINBOX 4 WIREGUARD --> RE-IMAGINED
Replies: 6
Views: 918

Re: WINBOX 4 WIREGUARD --> RE-IMAGINED

Blue squigglies on the diagrams are my attempt to show mandatory entries. One should note that much is based upon having made the wireguard interface first, as this is a reasonable assumption. Where possible, admins may or may not select fields depending upon logic. Ignore the poor quality and non-s...
by anav
Thu Mar 20, 2025 5:06 pm
Forum: General
Topic: WINBOX 4 WIREGUARD --> RE-IMAGINED
Replies: 6
Views: 918

Re: WINBOX 4 WIREGUARD --> RE-IMAGINED

Manual Peer creation ( key-pair creation at both ends ) This process addresses setting up the router as a client peer for handshake and setting up incoming client peers. The entry process for ‘manual’ will consist of first entering the Interface Name from a pull-down menu. The next common entry arg...
by anav
Thu Mar 20, 2025 5:00 pm
Forum: General
Topic: WINBOX 4 WIREGUARD --> RE-IMAGINED
Replies: 6
Views: 918

Re: WINBOX 4 WIREGUARD --> RE-IMAGINED

Discussion for the Peer Creation Options: (2) New Peer Creation Process Discussion: The current peer creation process is an attempt to squeeze a number of processes into one page and from a UI perspective fails to be an intuitive and clear approach. After some review, even though there is overlap in...
by anav
Thu Mar 20, 2025 4:57 pm
Forum: General
Topic: WINBOX 4 WIREGUARD --> RE-IMAGINED
Replies: 6
Views: 918

Re: WINBOX 4 WIREGUARD --> RE-IMAGINED

DISCUSSION: (1) New Wireguard Interface Creation Process Discussion: Overall. the current Wireguard Interface creation menu (New) is acceptable except for the ambiguous nature of the private key. A plus symbol is used to indicate a manual private key entry, typically only used in a third-party VPN s...
by anav
Thu Mar 20, 2025 4:55 pm
Forum: General
Topic: WINBOX 4 WIREGUARD --> RE-IMAGINED
Replies: 6
Views: 918

WINBOX 4 WIREGUARD --> RE-IMAGINED

When I started using Winbox4, and wireguard, I realized it needs much work! The GUI IMHO is not particularly useful, efficient, or intuitive. Everything is mushed onto one page and one has to sift up and down to find the right information to enter and of course we know there are errors in the curren...
by anav
Thu Mar 20, 2025 4:40 pm
Forum: Scripting
Topic: $wgshare - using /ip/cloud file share for WG peer client config & complaints
Replies: 12
Views: 2371

Re: $wgshare - using /ip/cloud file share for WG peer client config & complaints

Blue squigglies on the diagrams are my attempt to show mandatory entries. One should note that much is based upon having made the wireguard interface first, this is a reasonable assumption. Where possible, admins may or may not select fields depending upon logic. Please feel free to critique and imp...
by anav
Thu Mar 20, 2025 4:37 pm
Forum: Scripting
Topic: $wgshare - using /ip/cloud file share for WG peer client config & complaints
Replies: 12
Views: 2371

Re: $wgshare - using /ip/cloud file share for WG peer client config & complaints

Discussion for the Peer Creation Options: (2) New Peer Creation Process Discussion: The peer creation current process is an attempt to squeeze a number of processes into one page and from a UI perspective fails to be an intuitive and clear approach. After some review, even though there is overlap in...
by anav
Thu Mar 20, 2025 4:07 pm
Forum: Scripting
Topic: $wgshare - using /ip/cloud file share for WG peer client config & complaints
Replies: 12
Views: 2371

Re: $wgshare - using /ip/cloud file share for WG peer client config & complaints

DISCUSSION: (1) New Interface Creation Process Discussion: Overall. the current Wireguard Interface creation menu (New) is acceptable except for the ambiguous nature of the private key. A plus symbol is used to indicate a manual private key entry, typically only used in a third-party VPN scenario, w...
by anav
Thu Mar 20, 2025 3:00 pm
Forum: Scripting
Topic: $wgshare - using /ip/cloud file share for WG peer client config & complaints
Replies: 12
Views: 2371

Re: $wgshare - using /ip/cloud file share for WG peer client config & complaints

I was trying to keep it as close to the current setup, using clipNsave and paint LOL, no fancy tools. Its simply representative, and while doing it I realized what the three USE CASEs really are. a. local and remote key pair generation required ( manual ) b. local key pair generation not required ( ...
by anav
Thu Mar 20, 2025 1:34 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 6993

Re: My recent VLAN fiasco [SOLVED]

Well either you did monkey with the MTUs, and have forgotten OR someone else configured the router.
by anav
Thu Mar 20, 2025 4:51 am
Forum: Scripting
Topic: $wgshare - using /ip/cloud file share for WG peer client config & complaints
Replies: 12
Views: 2371

Re: $wgshare - using /ip/cloud file share for WG peer client config & complaints

New Proposed winbox4 ideas: Much is predicated on first completing the Wireguard Interface setup! Note in the Tab Under WIreguard additional grey entries. ................. wg-peers.jpg ............... when selecting NEW, the options to select type are presented ------------- Peers2.jpg __________ N...
by anav
Thu Mar 20, 2025 3:05 am
Forum: Beginner Basics
Topic: WireGuard with CloudFlare DNS [SOLVED]
Replies: 21
Views: 5514

Re: WireGuard with CloudFlare DNS [SOLVED]

1. Most people set this to none, its been known to cause issues. /interface detect-internet set detect-interface-list= INTERNE T 2. Why do you think its okay to assign two Subnets to the bridge. If you want more subnets make vlans and remove bridge from dchp. /ip address add address=192.168.10.1/25 ...
by anav
Thu Mar 20, 2025 12:49 am
Forum: Beginner Basics
Topic: WireGuard VPN + home router + travel router + help setup [SOLVED]
Replies: 23
Views: 5661

Re: WireGuard VPN + home router + travel router + help setup [SOLVED]

Suggest you open a new thread in the wireless forum State what device you have and how you can set up the WIFI to accept WIFI on 2ghz wifi as a WLAN from the hotel for example and then use WIFI on 5ghz ( and ether ports ) to distribute to LAN devices. mode (station | station-wds | ap-bridge | bridge...
by anav
Thu Mar 20, 2025 12:05 am
Forum: General
Topic: Firewall Rules for Limiting Inter-VLAN Traffic [SOLVED]
Replies: 3
Views: 4241

Re: Firewall Rules for Limiting Inter-VLAN Traffic [SOLVED]

1. YES, this can be simplified. /interface bridge vlan add bridge=bridge_LAN comment=home_vlan tagged=bridge_LAN,bond_2-4 vlan-ids=10 add bridge=bridge_LAN comment=guest_vlan tagged=bridge_LAN,bond_2-4 vlan-ids=60 add bridge=bridge_LAN comment=eyes_vlan tagged=bridge_LAN,bond_2-4 vlan-ids=50 add bri...
by anav
Wed Mar 19, 2025 9:52 pm
Forum: Beginner Basics
Topic: WireGuard VPN + home router + travel router + help setup [SOLVED]
Replies: 23
Views: 5661

Re: WireGuard VPN + home router + travel router + help setup [SOLVED]

Both configs are good, except on home router this rule is not required as access is covered in the src-address list rule in the input chain. add action=accept chain=input comment="allow WireGuard traffic" src-address=192.168.100.0/24 Its time to ensure the public IPs from generated by oppo...
by anav
Wed Mar 19, 2025 8:54 pm
Forum: Beginner Basics
Topic: WireGuard VPN + home router + travel router + help setup [SOLVED]
Replies: 23
Views: 5661

Re: WireGuard VPN + home router + travel router + help setup [SOLVED]

I predict success with the above changes. :-)
by anav
Wed Mar 19, 2025 8:35 pm
Forum: Beginner Basics
Topic: WireGuard VPN + home router + travel router + help setup [SOLVED]
Replies: 23
Views: 5661

Re: WireGuard VPN + home router + travel router + help setup [SOLVED]

Can you please forget about whatever you are doing with OPVN, it makes no sense to me and is getting in the way. There is no port forwarding ON any of your configs. Also the diagram showing input chain rule on travel router is wrong. I will have a look at the configs. Home router looks okay! One sub...
by anav
Wed Mar 19, 2025 7:43 pm
Forum: General
Topic: Blocking the "standard"/most common DNS-over-HTTPS servers
Replies: 15
Views: 1178

Re: Blocking the "standard"/most common DNS-over-HTTPS servers

In other words, unless you get a true DPI router, any type of control over access of google, youtube, etc, is not really effective or worth it.
DNS is a different kettle of fish, so not sure if DPI would even help in that regard.
by anav
Wed Mar 19, 2025 7:13 pm
Forum: Beginner Basics
Topic: WireGuard VPN + home router + travel router + help setup [SOLVED]
Replies: 23
Views: 5661

Re: WireGuard VPN + home router + travel router + help setup [SOLVED]

Getting there LOL. On the HOME router you failed to put in the forward chain rules I had recommended earlier. { default rules to keep } add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related hw-offload=yes add action=accept chain=for...
by anav
Wed Mar 19, 2025 5:55 pm
Forum: Beginner Basics
Topic: Setting up 100+ Hex Units [SOLVED]
Replies: 3
Views: 4058

Re: Setting up 100+ Hex Units [SOLVED]

There are some tools and ways to do so, and thus experts should chime in, who do this stuff.
In the meantime there are external third party applications designed for the deployment of large numbers of MT devices. Admiral Platform comes to mind.
by anav
Wed Mar 19, 2025 5:53 pm
Forum: Beginner Basics
Topic: Home network/lab upgrade question
Replies: 7
Views: 662

Re: Home network/lab upgrade question

Good the zyxel has a stand alone configuration which I prefer.
Will be very curious as to your wifi results, throughputs with iphone or android phones etc....
by anav
Wed Mar 19, 2025 4:49 pm
Forum: Beginner Basics
Topic: Home network/lab upgrade question
Replies: 7
Views: 662

Re: Home network/lab upgrade question

Mkx was faster, but faster is not always better, ask any woman.................

Gigabytes answer gets my vote. Management control is saaweet over RoS.
Your setup looks good!!! Which wifi AP did you get, TPLINK, Zyxel ??
by anav
Wed Mar 19, 2025 4:46 pm
Forum: General
Topic: Repeated disconnects on WAN (ether1)
Replies: 10
Views: 969

Re: Repeated disconnects on WAN (ether1)

Well I have driven to NYC many a time, and the rules of thumb are carry a gazillion one dollar bills for tolls, get a toll pass when it makes sense, park the car and take the ferry, get a multi-day transport pass ( subway and bus) if there for any length of time. I guess what has changed is this new...
by anav
Wed Mar 19, 2025 4:43 pm
Forum: General
Topic: Functionality Suggestion on RouterOS
Replies: 8
Views: 723

Re: Functionality Suggestion on RouterOS

Well I have a suggestion for MT, make their AI bot better, so that I dont have to see people beg rextended for scripts, especially when they pull out AI outputs that are pure crap.
by anav
Wed Mar 19, 2025 1:55 pm
Forum: General
Topic: ICMP reply not routed correctly on MikroTik [SOLVED]
Replies: 4
Views: 4196

Re: ICMP reply not routed correctly on MikroTik [SOLVED]

No need to be specific of protocol etc. The fact is that any traffic to the router over 4G itself should respond back via 4G. Finally only two rules are required. /ip firewall mangle add action=mark-connection chain=input comment="Mark connection ICMP for 4G" in-interface=l2tp-4G new-conne...
by anav
Wed Mar 19, 2025 1:43 pm
Forum: Beginner Basics
Topic: Devices and Networks Network Configuration – WAN Aggregation + Failover with Mikrotik + Firewall
Replies: 1
Views: 522

Re: Devices and Networks Network Configuration – WAN Aggregation + Failover with Mikrotik + Firewall

WAN aggregation does not improve speed. Any singular sessions speed is limited by the WAN being used for that session. What you get is MORE bandwidth overall to share with users, so that there is less bottleneck. Additionally you get redundancy in that being separate Providers, if one is not availab...
by anav
Wed Mar 19, 2025 1:01 pm
Forum: Beginner Basics
Topic: Help in setting up VPN exceptions
Replies: 4
Views: 536

Re: Help in setting up VPN exceptions

How do you propose to identify sites that users traffic is supposed to use the local WAN? Are we talking about programs (like youtube or google), that the router cannot do as its DPI dependent. Then the answer is NO. Are we talking about static public WANIPs ( or dynamic ones that can be identified ...
by anav
Wed Mar 19, 2025 12:51 pm
Forum: General
Topic: Functionality Suggestion on RouterOS
Replies: 8
Views: 723

Re: Functionality Suggestion on RouterOS

I only have to know it has come from darkextended to understand it............. it was very much close to my reaction to reading the Ops post,,,,, in english we use the word gibberish.

Reminds me: https://www.youtube.com/shorts/g8ZF3zE7hh4
by anav
Wed Mar 19, 2025 4:32 am
Forum: General
Topic: 2 ISPs (1 static/1 dynamic), 3 subnets (wired/wifi/tests), Policy-Based Routing with recursive routing for failover
Replies: 3
Views: 950

Re: 2 ISPs (1 static/1 dynamic), 3 subnets (wired/wifi/tests), Policy-Based Routing with recursive routing for failover

I am not interested in proving or disproving some testing or lab creation. If you need assistance it will be important that there is clarity in all the use cases of needed traffic flow by users internal, external and admin. Including any vpns, port forwarding etc. and sufficient details if more than...
by anav
Wed Mar 19, 2025 3:10 am
Forum: Announcements
Topic: New exciting features for storage
Replies: 172
Views: 19474

Re: New exciting features for storage

Dunno, I thought it was so Larsa can fly around and sniff sweet smelling MT equipment. ;-P ROSE (RouterOS Enterprise) package adds data center functionality to RouterOS - for supporting disk monitoring, improved formatting, RAIDs, rsync, iSCSI ,NVMe over TCP, NFS . This functionality currently is su...
by anav
Wed Mar 19, 2025 3:07 am
Forum: General
Topic: Repeated disconnects on WAN (ether1)
Replies: 10
Views: 969

Re: Repeated disconnects on WAN (ether1)

You need to buy a car, that scooter just doesnt cut it and you cannot carry much. ;-P
by anav
Wed Mar 19, 2025 3:06 am
Forum: General
Topic: Kid control keeps TCP sessions open
Replies: 5
Views: 1288

Re: Kid control keeps TCP sessions open

We are all going to end up as batteries for machines anyway ;-)
..........................................
the_matrix_human_batteries.jpg
by anav
Wed Mar 19, 2025 3:00 am
Forum: Beginner Basics
Topic: WireGuard VPN + home router + travel router + help setup [SOLVED]
Replies: 23
Views: 5661

Re: WireGuard VPN + home router + travel router + help setup [SOLVED]

Of course things didnt work, you made very little of the recommended changes and based on that, I dont think I can help much further.
The main error was pointed out again. Good luck!
by anav
Wed Mar 19, 2025 2:59 am
Forum: Beginner Basics
Topic: WireGuard VPN + home router + travel router + help setup [SOLVED]
Replies: 23
Views: 5661

Re: WireGuard VPN + home router + travel router + help setup [SOLVED]

You failed to hoist in this point properly.............. Travel Router First problem USING THE SAME SUBNET BEHIND THE ROUTER> Now that you have access on ether5, you should have changed the subnet on the Travel Router, I had suggested to 192.168.38.0/24. THis would be reflected in the allowed addres...
by anav
Tue Mar 18, 2025 11:45 pm
Forum: General
Topic: Kid control keeps TCP sessions open
Replies: 5
Views: 1288

Re: Kid control keeps TCP sessions open

Are they wired or is by wifi?
by anav
Tue Mar 18, 2025 11:44 pm
Forum: General
Topic: Repeated disconnects on WAN (ether1)
Replies: 10
Views: 969

Re: Repeated disconnects on WAN (ether1)

So they have confirmed connectivity from the street to their modem is solid? If thats the case sounds like the connection fro the modem to the router is the problem. Try a different cable.
by anav
Tue Mar 18, 2025 6:43 pm
Forum: General
Topic: Feature Request : don't log specific user login/logout actions
Replies: 6
Views: 875

Re: Feature Request : don't log specific user login/logout actions

Plan for device replacement strategy based on flash usage?
by anav
Tue Mar 18, 2025 5:00 pm
Forum: Wireless Networking
Topic: Guest Network: VLAN vs. Bridge
Replies: 6
Views: 1038

Re: Guest Network: VLAN vs. Bridge

vlan-filtering one bridge can be daunting for the new user as one is adding vlans and eventually drop DCHP and address from the bridge as one should ( bridge subnet simply becomes another data vlan etc.) reference to read: https://forum.mikrotik.com/viewtopic.php?t=143620 To facilitate a painless ex...
by anav
Tue Mar 18, 2025 4:50 pm
Forum: Forwarding Protocols
Topic: NAT and Switch on a Single Device
Replies: 5
Views: 1532

Re: NAT and Switch on a Single Device

Netmap maybe?
Take an etherport off the bridge that is attached to the device..............
Etherport not part of LAN interface
Separate firewall rules if required for etherport
by anav
Tue Mar 18, 2025 2:25 am
Forum: Beginner Basics
Topic: Beaten by.. or hEX ref saved me
Replies: 1
Views: 558

Re: Beaten by.. or hEX ref saved me

Config of hex
/export file=anynameyouwish ( minus router serial number, any public WANIP information, keys)
by anav
Tue Mar 18, 2025 2:24 am
Forum: Beginner Basics
Topic: WireGuard VPN + home router + travel router + help setup [SOLVED]
Replies: 23
Views: 5661

Re: WireGuard VPN + home router + travel router + help setup [SOLVED]

Travel Router First problem USING THE SAME SUBNET BEHIND THE ROUTER> Remember first post I stated: " I would use ether5 as a config port or emergency access port OFF the bridge. " Doing so allows one to easily change subnets. I know its difficult otherwise!! 1- So REMOVE ether5 from the b...
by anav
Tue Mar 18, 2025 1:19 am
Forum: Beginner Basics
Topic: WireGuard VPN + home router + travel router + help setup [SOLVED]
Replies: 23
Views: 5661

Re: WireGuard VPN + home router + travel router + help setup [SOLVED]

A dynamic IP is not a problem with the home router, and I am assuming its a public IP. The router provides domainurl mynetname under IP cloud to use as a Wireguard endpoint on the travel router I will take a look at the config later. home router config looks pretty normal. If you are not using IPV6 ...
by anav
Tue Mar 18, 2025 1:17 am
Forum: General
Topic: forum guru status
Replies: 27
Views: 2006

Re: forum guru status

Well, congrats on guru status! Now, the real test: What’s the meaning of life? 😁
Easy: "Always look at the bright side!"
ex. If I have to leave USA (NY) before it turns into Russia, I have a new friend in Canada with room! :-) ( well at least a tent LOL)
by anav
Tue Mar 18, 2025 1:15 am
Forum: General
Topic: GNS3 with Mikrotik devices
Replies: 7
Views: 860

Re: GNS3 with Mikrotik devices

IS EVE-NG any better then??
by anav
Mon Mar 17, 2025 11:41 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 326
Views: 544911

Re: Using RouterOS to VLAN your network

CGG is bang on, it looks like that the BRIDGE itself, should not really have any selections for ingress filtering for frame types or PVID for that matter for vlan-filtering=yes and leaving PVID=1. As I stated I use frame-types admit only vlan tagged specifically to stop any traffic entering the rout...
by anav
Mon Mar 17, 2025 10:55 pm
Forum: General
Topic: forum guru status
Replies: 27
Views: 2006

Re: forum guru status

luv it!
by anav
Mon Mar 17, 2025 9:46 pm
Forum: General
Topic: forum guru status
Replies: 27
Views: 2006

Re: forum guru status

Fascinating but does not answer the question I have in the other thread and request about wireguard.................. our ongoing conversation!!
by anav
Mon Mar 17, 2025 9:44 pm
Forum: General
Topic: Bonding Question
Replies: 4
Views: 558

Re: Bonding Question

The bond XR option should only be used with some smart (but dumb) managed switches that only have LAG option. Concur with patrick, 802.ad is the way to go.
by anav
Mon Mar 17, 2025 9:42 pm
Forum: General
Topic: WireGuard Issue After WAN Port Change (hAP ax3, RouterOS 7.17)
Replies: 5
Views: 1431

Re: WireGuard Issue After WAN Port Change (hAP ax3, RouterOS 7.17)

All good to know......... ! Hope its working now.
by anav
Mon Mar 17, 2025 6:02 pm
Forum: General
Topic: PPPoE Compatibility Issues with vBRAS/NFV
Replies: 24
Views: 3129

Re: PPPoE Compatibility Issues with vBRAS/NFV

Huawei products should not be used for a multitude of reasons, and one you probably dont know about is how poorly they treat their workers
by anav
Mon Mar 17, 2025 5:59 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 326
Views: 544911

Re: Using RouterOS to VLAN your network

Thanks for this topic guys, helped me to understand MikroTik better. But I have a little question. For me Ethernet2 is a trunk port (admit only vlan tagged) carrying about 4 vlans(one is the mangement ). I tagged the bridge on each vlan table and the ethernet2 also. At this moment normally my L3 wo...
by anav
Mon Mar 17, 2025 5:46 pm
Forum: General
Topic: vlans and hybrid ports problem.
Replies: 4
Views: 646

Re: vlans and hybrid ports problem.

Based on your config I have no clue what your are doing. Vlan filtering typically has one bridge you have two?? Is this device supposed to be acting as a router or a switch? I suspect a switch because its a switch LOL, and also by ethernet1, I assume that is a trunk port to the upstream router. IF s...
by anav
Mon Mar 17, 2025 4:05 pm
Forum: General
Topic: MikroTik hAP ax3 ( WIFI + VLANS )
Replies: 11
Views: 1206

Re: MikroTik hAP ax3 ( WIFI + VLANS )

No worries, by the way if you wanted to block wifi clients to wired clients on the same vlan, use bridge horizon same value on /interface bridge ports
by anav
Mon Mar 17, 2025 3:25 pm
Forum: General
Topic: forum guru status
Replies: 27
Views: 2006

Re: Guru?!?!?

I will but, one should not think that more slaps are better!!
https://www.youtube.com/watch?v=IhJQp-q ... xhcA%3D%3D
by anav
Mon Mar 17, 2025 3:12 pm
Forum: General
Topic: MikroTik hAP ax3 ( WIFI + VLANS )
Replies: 11
Views: 1206

Re: MikroTik hAP ax3 ( WIFI + VLANS )

@Holvoe SEE my friend, simple capsmanless datapthless config IS SUPERIOR. said somewhat in jest of course, The challenge is to provide this chap with a working config with all the datapath entries he was using at the beginning and for the config to work. We can deal with capsman at another time as i...
by anav
Mon Mar 17, 2025 3:10 pm
Forum: General
Topic: MikroTik hAP ax3 ( WIFI + VLANS )
Replies: 11
Views: 1206

Re: MikroTik hAP ax3 ( WIFI + VLANS )

Yup, good execution, to start with a working config then add pieces back slowly to ensure you understand what breaks and what works. For data path isolation, no worries, assign a datapth1 JUST with isolation invoked and add that to the WLAN where you want to isolate wifi users from each other. That ...
by anav
Mon Mar 17, 2025 3:07 pm
Forum: General
Topic: Recommendation for Hardware
Replies: 6
Views: 762

Re: Recommendation for Hardware

Personally, I see no reason to change your hardware at the moment. Both cameras are on the same vlan so untagg the camera vlan to the dumb switch and you are covered there. The two APs are what unifi, nothing wrong with those, they handle vlans and you just need to feed them hybrid ports from the MT...
by anav
Mon Mar 17, 2025 2:58 pm
Forum: General
Topic: forum guru status
Replies: 27
Views: 2006

Re: Guru?!?!?

No offense taken, in fact MKX is bang on the money and I would unashamedly say that his sentiment lasted far longer than that. I can say that I probably crossed the line when it penetrated my thick skull to find my pea brain, that a wireguard address on the MT router was actually a good thing. And L...
by anav
Mon Mar 17, 2025 12:24 am
Forum: Beginner Basics
Topic: Is there a guide on which models are suitable for what purpose?
Replies: 5
Views: 676

Re: Is there a guide on which models are suitable for what purpose?

The more detailed the requirements the more accurate the answer!!
by anav
Mon Mar 17, 2025 12:11 am
Forum: Beginner Basics
Topic: multi-WAN, one dst always through one WAN
Replies: 3
Views: 804

Re: multi-WAN, one dst always through one WAN

Since you don't know the problem, why do you think you know the relevent parts of the config. :-) Seems illogical. In any case /export file=anynameyouwish ( minus router serial number, any public WANIP information, keys, long dhcp leases etc.) and for the love of god, dont use VERBOSE export!!! Plea...
by anav
Mon Mar 17, 2025 12:08 am
Forum: Beginner Basics
Topic: Is there a guide on which models are suitable for what purpose?
Replies: 5
Views: 676

Re: Is there a guide on which models are suitable for what purpose?

Much better and fruitful ways to spend your time LOL
by anav
Mon Mar 17, 2025 12:07 am
Forum: General
Topic: How to block Google DNS on router?
Replies: 3
Views: 771

Re: How to block Good DNS on router?

well where will your users get their internet phone book information from then??
by anav
Sun Mar 16, 2025 11:32 pm
Forum: Beginner Basics
Topic: Is there a guide on which models are suitable for what purpose?
Replies: 5
Views: 676

Re: Is there a guide on which models are suitable for what purpose?

Not really but you can ask here but be sure to state your requirements and use cases for traffic and also ISP information. etc.
by anav
Sun Mar 16, 2025 7:11 pm
Forum: Beginner Basics
Topic: Cap AC Wall Plate - Sourcing.
Replies: 2
Views: 1215

Re: Cap AC Wall Plate - Sourcing.

I may still have one floating around, and if you know anyone with a 3D printer, they could probably make one.
by anav
Sun Mar 16, 2025 7:09 pm
Forum: General
Topic: how to route multiple WANs to CHR over the Wireguard tunnel.
Replies: 16
Views: 1350

Re: how to route multiple WANs to CHR over the Wireguard tunnel.

Based on Sindys advice, this may do the trick......... TO ADDRESS ADDITIONAL REQUIREMENT OF SOME USERS USING LOCAL WANS. The key to ensure ECMP works, is for the routes in question to all have the same table with same distance. /ip firewall filter add action=fasttrack-connection connection-state=est...
by anav
Sun Mar 16, 2025 5:06 pm
Forum: General
Topic: how to route multiple WANs to CHR over the Wireguard tunnel.
Replies: 16
Views: 1350

Re: how to route multiple WANs to CHR over the Wireguard tunnel.

Thats changing the requirements which nobody wants to deal with --> its called scope creep. The onus is on you to be honest and state the full requirements PRIOR to designing a config. Do better next time!! So before answering, will request much better detail on any other requirements percolating......
by anav
Sun Mar 16, 2025 5:01 pm
Forum: General
Topic: IPSEC tunnel established, traffic not passing through
Replies: 23
Views: 1691

Re: IPSEC tunnel established, traffic not passing through

I'm curious as to the purpose of the tunnel to this swiss device.
Is the requirement to reach a subnet behind that ISP router?
Is the requirement to simply use internet at that router?
Is the requirement for some entity behind the swiss router to reach the single LANIP on your MT?
by anav
Sun Mar 16, 2025 4:27 pm
Forum: General
Topic: how to route multiple WANs to CHR over the Wireguard tunnel.
Replies: 16
Views: 1350

Re: how to route multiple WANs to CHR over the Wireguard tunnel.

Not sure what you mean? The LAN user will only go over the wireguard to the CHR, so there is no other alternative. Yes expect a reduction of speed through wireguard to the CHR. 1. First consider the throughput of each WAN will limit the speed of any session using that WAN 2. Consider the limit on th...
by anav
Sun Mar 16, 2025 3:31 am
Forum: General
Topic: MikroTik hAP ax3 ( WIFI + VLANS )
Replies: 11
Views: 1206

Re: MikroTik hAP ax3 ( WIFI + VLANS )

Thanks ! I will fix the PVID 93, my Switch gets ip from the main vlan dhcp and I wanted it to get some ip from the management so I tried to put pvid93 so the device will prioritise that but it is still on MainVlan 15 subnet the switch. I guess I have to put pvid 1 ( default ) instead of pvid93 on t...
by anav
Sun Mar 16, 2025 1:14 am
Forum: General
Topic: MikroTik hAP ax3 ( WIFI + VLANS )
Replies: 11
Views: 1206

Re: MikroTik hAP ax3 ( WIFI + VLANS )

Im no wifi datapath expert but I am guessing that since you have detailed both the bridge and vlan in datapath. You need NO entries in either /interface bridge port or /interface bridge vlan FOR ANY of the VLAN traffic, But before you try that first fix the gross error to see if that helps 1. Trunk ...
by anav
Sun Mar 16, 2025 12:58 am
Forum: Scripting
Topic: $wgshare - using /ip/cloud file share for WG peer client config & complaints
Replies: 12
Views: 2371

Re: $wgshare - using /ip/cloud file share for WG peer client config & complaints

Hi AMMO, can you go through the page above, and think of making what I have better, and I am missing anything?
A better way to reorg, or to enter data etc.. Or anyone for that matter.

PS. send me a hello on discord anav_ds, I have a word doc for your to critique/peruse!
by anav
Sun Mar 16, 2025 12:26 am
Forum: General
Topic: MikroTik hAP ax3 ( WIFI + VLANS )
Replies: 11
Views: 1206

Re: MikroTik hAP ax3 ( WIFI + VLANS )

Well as always it depends, and it depends because the full config has not been provided. A config is very much interrelated so snippets dont provide full context.

/export file=anynameyouwish ( minus router serial number, any public WANIP information, keys)
by anav
Sat Mar 15, 2025 11:21 pm
Forum: General
Topic: Router and Switch Redundancy
Replies: 2
Views: 2831

Re: Router and Switch Redundancy

I would consider setting up VRRP Instances. VRRPA - Router 1 is the primary and Router 2 is backup VRRPB - Router 2 is the primary and Router1 is backup. Why you ask, so that Router1 LAN subnets can use R1 ( via VRRPA) and Router2 LAN subnets can use R2 ( via VRRPB). A more efficient use of both ROU...
by anav
Sat Mar 15, 2025 11:14 pm
Forum: Beginner Basics
Topic: WireGuard VPN + home router + travel router + help setup [SOLVED]
Replies: 23
Views: 5661

Re: WireGuard VPN + home router + travel router + help setup [SOLVED]

My bad, I thought your standard use was connecting to wifi WAN, and then sending the traffic through wifi to other devices in the room. IF that is not your go to, then by all means IP DHCP client on ether1 is ENABLED and the 2.4ghz WAN link in wifi is disable. In both cases wifi to local devices is ...
by anav
Sat Mar 15, 2025 10:39 pm
Forum: Beginner Basics
Topic: Acces Remote Gateway for settings Via Wireguard
Replies: 3
Views: 701

Re: Acces Remote Gateway for settings Via Wireguard

Very reasonable request, and without going to much into the config it shouldnt be too much of a problem. If the ask was for a USER on the LAN originate traffic to router A that would be more difficult. Basically since we NAT all the traffic leaving router B, going to the TPLINK router, the wireguard...
by anav
Sat Mar 15, 2025 7:24 pm
Forum: Beginner Basics
Topic: WireGuard VPN + home router + travel router + help setup [SOLVED]
Replies: 23
Views: 5661

Re: WireGuard VPN + home router + travel router + help setup [SOLVED]

Looks good from what I can see. The travel router should also be setup with IP DHCP disabled on ether1, just in case you have a wired connection. Otherwise you will need to figure out how to a. grab wifi WAN from 2.4ghz connection to hotel etc ( the part you may need to ask for WIFI assistance to co...
by anav
Sat Mar 15, 2025 7:20 pm
Forum: Beginner Basics
Topic: A simple WAN/LAN/DMZ VLAN config to start off
Replies: 26
Views: 7062

Re: A simple WAN/LAN/DMZ VLAN config to start off

I think it would be worthwhile to point out WHEN vlan-id=1 HAS to be used, (no other way/recourse), and I can probably count on my four finger amputated hand, how many situations that is........
When the time comes though, I will be asking graelex for advice so dont piss him off ;-)
by anav
Sat Mar 15, 2025 5:37 pm
Forum: Beginner Basics
Topic: VLANS Through Managed Switches - Beginner Config [SOLVED]
Replies: 8
Views: 4759

Re: VLANS Through Managed Switches - Beginner Config [SOLVED]

Well all the ports are 1gig, the Hex can route about 250-300 Mbps, so that may be your limiting factor, but more likely its the AP throughput. Six vlans but 8? pools? You are still confused a. please remove any IP address assigned to the bridge, it does no dhcp on vlan bridge filtering, to keep it s...
by anav
Sat Mar 15, 2025 4:35 pm
Forum: General
Topic: Mikrotik iOS app - can't connect over Wireguard using IP
Replies: 17
Views: 1098

Re: Mikrotik iOS app - can't connect over Wireguard using IP

Must be an IPV6 issue then.
by anav
Sat Mar 15, 2025 4:34 pm
Forum: General
Topic: Firewall Rule Help Needed
Replies: 3
Views: 544

Re: Firewall Rule Help Needed

I think water broke through the dykes and got into your ears. The chap doesnt need such fancy stuff. A. Basic need, two separate VLAN to separate guest users and trusted users each one tied to the approriate WLAN and different security settings. B. More advanced need, invoke isolation between wifi u...
by anav
Sat Mar 15, 2025 4:26 pm
Forum: General
Topic: how to route multiple WANs to CHR over the Wireguard tunnel.
Replies: 16
Views: 1350

Re: how to route multiple WANs to CHR over the Wireguard tunnel.

The concept proposed is a non-PCC, ECMP approach with minimal mangling required. We will use the listening port of the interfaces we create at the CHR (the endpoint ports in the router wireguard peer settings) as an entry argument for our mangle output chain rules. In this way, the handshake ORIGINA...
by anav
Sat Mar 15, 2025 3:54 pm
Forum: General
Topic: Firewall Rule Help Needed
Replies: 3
Views: 544

Re: Firewall Rule Help Needed

You cannot. You are hamstrung by whatever device is coming in the WIFI. Stupidly dumb wifi devices internally create a faux guest network. This network uses the same LANIPs but is isolated from the other wifi users and also are isolated from any LAN users on the same subnet but wired. They can only ...
by anav
Sat Mar 15, 2025 3:48 pm
Forum: General
Topic: Mikrotik iOS app - can't connect over Wireguard using IP
Replies: 17
Views: 1098

Re: Mikrotik iOS app - can't connect over Wireguard using IP

But I can wireguard to my router (establish tunnel) and then use ip addresses on the router to configure the router via the MT app. Do you mean wireguard to a device directly that is downstream of the router, so lets say an AX3 or other MT device behind the router? If so do you want me to test if it...
by anav
Sat Mar 15, 2025 3:45 pm
Forum: Beginner Basics
Topic: Multiple bridges for multiple switch chips on CCR2004-16G-2S+?
Replies: 9
Views: 861

Re: Multiple bridges for multiple switch chips on CCR2004-16G-2S+?

or just reboot the router? often a good idea after many changes.
by anav
Sat Mar 15, 2025 2:27 pm
Forum: General
Topic: Mikrotik iOS app - can't connect over Wireguard using IP
Replies: 17
Views: 1098

Re: Mikrotik iOS app - can't connect over Wireguard using IP

My apologies, but I dont understand your network and I dont use IPV6. If you can provide a similar scenario that I could test on my equipment to confirm your findings I am glad to attempt such tests. Do you mean you wireguard into a downstream router or device and wish to be able to reach and config...
by anav
Sat Mar 15, 2025 3:29 am
Forum: General
Topic: Mikrotik iOS app - can't connect over Wireguard using IP
Replies: 17
Views: 1098

Re: Mikrotik iOS app - can't connect over Wireguard using IP

Okay so I need to test this by attempting to access a subnet on my Router from my ios app. The allowed IPs on my WG app thus should be restricted to a subnet and the wireguardIP of the router......okay will try. Added wireguard subnet access to a printer on a printer vlan. router firewall rule Chang...
by anav
Sat Mar 15, 2025 12:22 am
Forum: Beginner Basics
Topic: Smart and straight forward Inter-VLAN Routing configuration on CRS328
Replies: 1
Views: 498

Re: Smart and straight forward Inter-VLAN Routing configuration on CRS328

If the upstream or downstream device is a unifi, then you simply need to create a hyrid port vice a trunk port Assume the unifi subnet/management comes into the MT device as untagged and the data vlans tagged. If your running the CRS3XX as a switch then its simple Only define the management VLAN let...
by anav
Fri Mar 14, 2025 9:00 pm
Forum: General
Topic: Port forwarding on a RB4011 with a GPON ONT
Replies: 3
Views: 767

Re: Port forwarding on a RB4011 with a GPON ONT

Well this is true, port forwarding requires either a. you get a public IP from the ISP modem b. you get a private IP frome the ISP modem Router BUT, you can access the ISP modem/router to forward ports, or ask the ISP provider and they forward ports upon your request. If not , then you cannot port f...
by anav
Fri Mar 14, 2025 7:18 pm
Forum: General
Topic: Port forwarding on a RB4011 with a GPON ONT
Replies: 3
Views: 767

Re: Port forwarding on a RB4011 with a GPON ONT

Sorry not a capsman expert so if its the problem, cannot help. On the hairpin nat rule DUMP the extra stuff and be granular. add action=masquerade chain=srcnat comment="Hairpin NAT" dst-address=192.168.0.0/16 src-address=192.168.0.0/16 to-addresses=192.168.2.100 should just be add action=m...
by anav
Fri Mar 14, 2025 7:15 pm
Forum: Scripting
Topic: $wgshare - using /ip/cloud file share for WG peer client config & complaints
Replies: 12
Views: 2371

Re: $wgshare - using /ip/cloud/back-to-home-file to share WG peer client config

Okay, it got me to thinking that the MT approach is a mess. Their import function is located on the main page so how do you know which interface the peer applies to. Wireguard files do NOT include interface name! When you select a wireguard interface, the IMPORT function is GONE. Similarly to the EX...
by anav
Fri Mar 14, 2025 5:37 pm
Forum: General
Topic: Mikrotik iOS app - can't connect over Wireguard using IP
Replies: 17
Views: 1098

Re: Mikrotik iOS app - can't connect over Wireguard using IP

Usual problems. ROUTER: a. forgot to add allow input chain rule for incoming handshake port b. forgot to add allow wireguard interface or incoming IP address on input chain (for config purposes) c. forgot to add wireguard address on the router under /ip address d. copied public key from client incor...
by anav
Fri Mar 14, 2025 5:31 pm
Forum: General
Topic: Mikrotik iOS app - can't connect over Wireguard using IP
Replies: 17
Views: 1098

Re: Mikrotik iOS app - can't connect over Wireguard using IP

Okay just tested in on my Router, from iphone on cellular, MT app worked just fine with format a. trusted LAN address ( like 192.168.88.1 : winbox port ) b. actual wireguard IP of the router ( Like 10.20.30.1 : winboxport ) Steps created wg interface and wireguard address created input chain rule fo...
by anav
Fri Mar 14, 2025 4:40 pm
Forum: Beginner Basics
Topic: 2 LANS over WIFI
Replies: 5
Views: 739

Re: 2 LANS over WIFI

Okay so its acting as a router. Okay so the purpose of the wifi is so that clients can go where????? ( if not the internet). Should I assume the idea is that: - you have a bunch of users on one wifi that need to talk to each other --> WLAN1 - you have a bunch of users on a different wifi that need t...
by anav
Fri Mar 14, 2025 4:32 pm
Forum: General
Topic: rOS V7 on mAP lite
Replies: 4
Views: 669

Re: rOS V7 on mAP lite

Wireguard fine!, BTH wireguard no and thus assuming you are using the maplite as a client to server somewhere, or have a public IP available locally ( from ISP directly ) or port forwarding from upstream router.
by anav
Fri Mar 14, 2025 4:08 pm
Forum: Scripting
Topic: $wgshare - using /ip/cloud file share for WG peer client config & complaints
Replies: 12
Views: 2371

Re: $wgshare - using /ip/cloud/back-to-home-file to share WG peer client config

Your assuming that we have created the FILE and stored the file, which assumes you have external storage and know how to set that up??? Edit, just read the bit about small files, and no storage required.......I was wondering about that, (size of peer files) thanks..... What I would like to see on th...
by anav
Fri Mar 14, 2025 4:01 pm
Forum: Beginner Basics
Topic: 2 LANS over WIFI
Replies: 5
Views: 739

Re: 2 LANS over WIFI

Are you setting this up as a ROUTER or as an AP?
post your config thus far
/export file=anynameyouwish ( minus device serial number, any public WANIP information ).
by anav
Fri Mar 14, 2025 3:55 pm
Forum: Beginner Basics
Topic: Multiple bridges for multiple switch chips on CCR2004-16G-2S+?
Replies: 9
Views: 861

Re: Multiple bridges for multiple switch chips on CCR2004-16G-2S+?

Well, it depends. If you can ensure that a group of vlans share the same bridge and then a group of vlans share the other bridge. To ensure HW offloading, then yes two bridges one bridge for 1-5 and another bridge for ports 6-10. Note that this supports traffic on the same vlan across ports. So asse...
by anav
Fri Mar 14, 2025 1:05 pm
Forum: General
Topic: Bridge VLAN Filtering Problem
Replies: 24
Views: 2142

Re: Bridge VLAN Filtering Problem

Your logic seems sound and its certainly product specific to the 5009 as many other devices are used as switches let say behind a 5009 even, and they dont report such issues. Using the 5009 as a router, all /interface bridge vlans would be tagged with Bridge, so it would not normally be seen. Since ...
by anav
Thu Mar 13, 2025 10:32 pm
Forum: General
Topic: can't access a specific URL I need help!!!!!
Replies: 6
Views: 663

Re: can't access a specific URL I need help!!!!!

Well it was a little better than "there was no sugar in my coffee", as at least we know equipment that accesses the www was involved, unless it was a bad dream! ;-)
by anav
Thu Mar 13, 2025 8:23 pm
Forum: General
Topic: can't access a specific URL I need help!!!!!
Replies: 6
Views: 663

Re: can't access a specific URL I need help!!!!!

It has nothing to do with the router.
by anav
Thu Mar 13, 2025 8:20 pm
Forum: General
Topic: IP DNS QUESTION
Replies: 9
Views: 993

Re: IP DNS QUESTION

Understood, I didnt realize that if I had static entries they would be ignored if I set gw dhcp dns-server to none. It is not clear to me HOW static entries are then advertised to devices:??? In other words what is the difference between dns-server=no-server /ip dns set servers=10.44.44.1,1.1.1.1 AN...
by anav
Thu Mar 13, 2025 7:58 pm
Forum: Beginner Basics
Topic: Route policy [SOLVED]
Replies: 7
Views: 5423

Re: Route policy [SOLVED]

1. You have me confused, You only have 2 vlans, all traffic from one goes out ISP1 and all traffic from the other goes out ISP2 -2 pools - 2 dhcp servers etc. But magically you have a server on a non-existing subnet?? 2. Your IP addresses are wrong a. the two vlans need the interface to be the bridg...
by anav
Thu Mar 13, 2025 7:29 pm
Forum: Beginner Basics
Topic: WireGuard [SOLVED]
Replies: 11
Views: 6146

Re: WireGuard [SOLVED]

Honestly dont care about ubuntu..... In terms of the MT and manually sending subnet to wither wireguard or local WAN.... Modify what I had before...... /routing table add fib name=useWG /routing rules { order of rules is important } add action=lookup-only-in-table src-address=192.168.88.0/24 dst-add...
by anav
Thu Mar 13, 2025 7:16 pm
Forum: Beginner Basics
Topic: Route policy [SOLVED]
Replies: 7
Views: 5423

Re: Route policy [SOLVED]

Its a start but needs major work First thing is to be clear on requirements. 1. So you have two sets of user ONLY vlanX and vlanY Each has its own WAN it should go out of. 2. What happens if wan1 is not available, should users on VLANX be allowed to use WAN2 ?? 3. Are there any VPNS to the router? 4...
by anav
Thu Mar 13, 2025 7:09 pm
Forum: General
Topic: IP DNS QUESTION
Replies: 9
Views: 993

Re: IP DNS QUESTION

Super, much thanks.
by anav
Thu Mar 13, 2025 6:28 pm
Forum: General
Topic: IPS do not communicate with mark-routing
Replies: 1
Views: 547

Re: IPS do not communicate with mark-routing

The RB3011 has ports 1-5 on one chip and ports 6-10 on another chip, So practically speaking one bridge makes sense not three ( on all newer products, ) two bridges does in your case. Figure out which traffic load amongst your three bridges is the greates and use that bridge for ports 1-5 and put th...
by anav
Thu Mar 13, 2025 6:20 pm
Forum: Beginner Basics
Topic: VLANS Through Managed Switches - Beginner Config [SOLVED]
Replies: 8
Views: 4759

Re: VLANS Through Managed Switches - Beginner Config [SOLVED]

Stick to standard subnets /24 until you get more experience!!! Additions/Modification 1. Adjust frame type, the default is admit-all. /interface bridge add comment="LAN Bridge" frame-types=admit-all name=bridge_LAN vlan-filtering=yes 2. YIKES< your diagram screams problem . You have multip...
by anav
Thu Mar 13, 2025 5:34 pm
Forum: Beginner Basics
Topic: VLANS Through Managed Switches - Beginner Config [SOLVED]
Replies: 8
Views: 4759

Re: VLANS Through Managed Switches - Beginner Config [SOLVED]

Understood, it can be tricky the first time, just click on the tab to make new one.
...........
Screenshot 2025-03-13 123152.jpg
by anav
Thu Mar 13, 2025 5:01 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 525
Views: 149470

Re: v7.18 [stable] is released!

holvoe, can you comment on the wifi changes, good bad ugly??
I am not seeing much difference but then again I am lucky enough not to have those problems with disconnects like some others do.
You have the only ax3 made in Latvia then. ;-)
by anav
Thu Mar 13, 2025 4:57 pm
Forum: Wireless Networking
Topic: Wrong DHCP with VLANs
Replies: 9
Views: 1092

Re: Wrong DHCP with VLANs

Sorry wont touch your config cause you mix apples and oranges.
In a vlan setup the bridge should do no DHCP and if you need that subnet for something real, then make it a vlan as well.

Clearly you failed to read the referenced article.
by anav
Thu Mar 13, 2025 4:47 pm
Forum: Beginner Basics
Topic: VLANS Through Managed Switches - Beginner Config [SOLVED]
Replies: 8
Views: 4759

Re: VLANS Through Managed Switches - Beginner Config [SOLVED]

Did you read the article: https://forum.mikrotik.com/viewtopic.php?t=143620? If you say you did, I dont believe because nowhere does it state to have this. /interface bridge add comment="LAN Bridge" frame-type= admit-only-vlan-tagged name=bridge_LAN vlan-filtering=yes The application of in...
by anav
Thu Mar 13, 2025 4:44 pm
Forum: Beginner Basics
Topic: WireGuard [SOLVED]
Replies: 11
Views: 6146

Re: WireGuard [SOLVED]

Sorry cannot provide any useful thoughts on the ubuntu server, I once tried to read docs and forums and the thing is truly PHUCKED up to understand.
by anav
Thu Mar 13, 2025 4:41 pm
Forum: General
Topic: Adding a new interface/trunk port to 500+ vlans [SOLVED]
Replies: 2
Views: 5657

Re: Adding a new interface/trunk port to 500+ vlans [SOLVED]

@supervisor of mischa01101 - MT has reduced the hours you are required to pay mischa01101 and the cost of trips to sites. :-)
by anav
Thu Mar 13, 2025 4:38 pm
Forum: General
Topic: Request for WireGuard Peers, configurable Client ListenPort and AllowedIPs
Replies: 38
Views: 2916

Re: Request for WireGuard Peers, configurable Client ListenPort and AllowedIPs

That makes no sense and not true! My Server has no preshared key............no such thing ( its strictly an extra step between the peers when connecting) in other words I could have preshared key on only ONE of my 20 peers!! The export shows the preshared key and the chosen allowed IPs of that remot...
by anav
Thu Mar 13, 2025 4:33 pm
Forum: General
Topic: IP DNS QUESTION
Replies: 9
Views: 993

Re: IP DNS QUESTION

So the users in the scenarios 1,2,3 do not have to have access to the input chain at all for DNS ???
by anav
Thu Mar 13, 2025 4:31 pm
Forum: General
Topic: Dual WAN with one WAN dedicated for VPN
Replies: 4
Views: 697

Re: Dual WAN with one WAN dedicated for VPN

Not being an SSTP expert by any means, but like wireguard I would separate the SSTP by port as well. This makes it much easier to identify and segregate traffic when required in config rules. Also we dont know how your router is setup for the two WANS, Are they load balanced, is one primary and one ...
by anav
Thu Mar 13, 2025 4:24 pm
Forum: General
Topic: simple 3 isp dhcp clients with aggregation
Replies: 24
Views: 5820

Re: simple 3 isp dhcp clients with aggregation

This approach assumes
a. no vpn coming in on any WAN ( thus no need to mangle for traffic to router itself )
b. no LAN servers, that external users will be visiting through the WAN connections
c. no specific requirements for any Lan user(s) to go out a specific WAN.
by anav
Thu Mar 13, 2025 4:22 pm
Forum: General
Topic: simple 3 isp dhcp clients with aggregation
Replies: 24
Views: 5820

Re: simple 3 isp dhcp clients with aggregation

1. So you have two bridges and two subnets, so what is this.......?? /ip pool add name=dhcp_pool0 ranges=192.168.9.50-192.168.9.254 triplicate add name=dhcp_pool1 ranges=192.168.9.100-192.168.9.254 duplicate add name=dhcp_pool2 ranges=192.168.9.100-192.168.9.254 duplicate add name=dhcp_pool3 ranges=...
by anav
Thu Mar 13, 2025 3:49 pm
Forum: General
Topic: Dual WAN with one WAN dedicated for VPN
Replies: 4
Views: 697

Re: Dual WAN with one WAN dedicated for VPN

1. Quick question, is there any reason you have to use port 444, for both VPNs? Assuming the SSTP VPN is being hosted on third party sites 2 a. are the SSTP clients (application) on PCs on your LANs OR b. are you using the router as an SSTP client 3. Who is using the first SSTP VPN? One user, or one...
by anav
Thu Mar 13, 2025 3:44 pm
Forum: General
Topic: Dual WAN with one WAN dedicated for VPN
Replies: 4
Views: 697

Re: Dual WAN with one WAN dedicated for VPN

I have mikrotik router CRS326-24S+2Q.
Wrong you have a mikrotik switch but it can be used a router but dont expect throughut to reach 200Mbps.
.....
Screenshot 2025-03-13 104300.png
by anav
Thu Mar 13, 2025 1:48 pm
Forum: General
Topic: Request for WireGuard Peers, configurable Client ListenPort and AllowedIPs
Replies: 38
Views: 2916

Re: Request for WireGuard Peers, configurable Client ListenPort and AllowedIPs

THe export button does attempt to send something but its incomplete and a mix of some settings, a few right but wrong on the other, the preshared key I entered for the peer is there, and the allowed IPs, but the private key is wrong. Its dumb because the export should be clearly associated with the ...
by anav
Thu Mar 13, 2025 1:19 pm
Forum: General
Topic: Bridge VLAN Filtering Problem
Replies: 24
Views: 2142

Re: Bridge VLAN Filtering Problem

Not sure why so hostile, mkx and I were just asking for the facts and attempting to determine at the time, model used and exact config to help, based on evidence/facts to assist. An incorrectly configured router is capable of many weird effects for example. In other cases the issue is the PC, or ser...
by anav
Thu Mar 13, 2025 2:07 am
Forum: Beginner Basics
Topic: Struggling to get wireguard to run
Replies: 2
Views: 625

Re: Struggling to get wireguard to run

I use a whip!! Looking at the wireguard peers, it would seem that this device is a Client peer for handshake. But that could just be a mistake on the OPs side as its all settings are contradictory. to make it less hard on the eyes. example of a hot mess allowed IPs configuration. /interface wireguar...
by anav
Thu Mar 13, 2025 1:12 am
Forum: Scripting
Topic: $wgshare - using /ip/cloud file share for WG peer client config & complaints
Replies: 12
Views: 2371

Re: $wgshare - using /ip/cloud/back-to-home-file to share WG peer client config

Okay I have no idea how your script works, but suffice to say, Its hard enough to use the gui. 1. Need to create the peer 2. Need to create a QR entity that we will create and then export , (but where is the export or download button location) 3. Need to deposit this file somewhere, assuming a share...
by anav
Thu Mar 13, 2025 12:51 am
Forum: General
Topic: Request for WireGuard Peers, configurable Client ListenPort and AllowedIPs
Replies: 38
Views: 2916

Re: Request for WireGuard Peers, configurable Client ListenPort and AllowedIPs

I still dont see export in winbox4, can you take a jpeg so i know where to look.....
by anav
Thu Mar 13, 2025 12:33 am
Forum: General
Topic: Offline Router configuration?
Replies: 3
Views: 665

Re: Offline Router configuration?

Many use a virtual network check CNS3 and EVE-NG are two popular ones.
by anav
Wed Mar 12, 2025 10:49 pm
Forum: Useful user articles
Topic: Advanced Routing Failover without Scripting
Replies: 295
Views: 169364

Re: Advanced Routing Failover without Scripting

But why do that................... all this extra typing keeps my typing skills up........... and then I dont have to learn all that syntax stuff.
by anav
Wed Mar 12, 2025 8:19 pm
Forum: General
Topic: IP DNS QUESTION
Replies: 9
Views: 993

Re: IP DNS QUESTION

Thanks for the reply, very clear!

Two questions:
What dependency do any of the working options 1-3 have on the users being able to reach the router services on port 53?

How does the router know if a DNS address is not available?
by anav
Wed Mar 12, 2025 7:23 pm
Forum: General
Topic: IP DNS QUESTION
Replies: 9
Views: 993

IP DNS QUESTION

What is the practical difference between /ip dhcp-server network add address=192.168.88.0/24 comment=defconf gateway=192.168.88.1 dns-server=10.44.44.1,1.1.1.1 /ip dns set allow-remote-requests=yes AND /ip dhcp-server network add address=192.168.88.0/24 comment=defconf gateway=192.168.88.1 dns-serve...
by anav
Wed Mar 12, 2025 6:58 pm
Forum: General
Topic: Bridge VLAN Filtering Problem
Replies: 24
Views: 2142

Re: Is this a bug or something not documented

The Router providing the DHCP service for all vlans sends all the traffic to ether1 on the Switch, on that we agree. The switch then takes that traffic coming in ether1 and distributes to any dumb devices on access ports (untagged) or to smart devices, if applicable on trunk ports (tagged) on that w...
by anav
Wed Mar 12, 2025 6:35 pm
Forum: General
Topic: RB1100 with Wireguard Roadwarrior VPN
Replies: 9
Views: 3263

Re: RB1100 with Wireguard Roadwarrior VPN

Biggest problem I see is this warning....... # vlan90_WAN3 not a bridge port add bridge=bridge1 tagged=bridge1,ether6,vlan90_WAN3 vlan-ids=90 Quite correctly the ether1 fiber connection should not be part of any bridge configuration to the best of my knowledge. set [ find default-name=ether1 ] name=...
by anav
Wed Mar 12, 2025 6:13 pm
Forum: General
Topic: RB1100 with Wireguard Roadwarrior VPN
Replies: 9
Views: 3263

Re: RB1100 with Wireguard Roadwarrior VPN

To login by IP Address you need to enter two things. IPADDRESS:WINBOX PORT ...............the advantage of mac, is you simply click on mac address......... Also your subnet mask usage is weird. The management vpn pool is better suited to /24 setup. The same for your wireguard setup change to /24 mgm...
by anav
Wed Mar 12, 2025 6:12 pm
Forum: General
Topic: Request for WireGuard Peers, configurable Client ListenPort and AllowedIPs
Replies: 38
Views: 2916

Re: Request for WireGuard Peers, configurable Client ListenPort and AllowedIPs

Yes do pray tell. How best to send this QR code to another ROUTER in a secure manner How to best to send this QR code to a single device , smartphone in a secure manner How to best to send this QR code to a a single device, laptop in a secure manner. The problem is that the there is no secure alread...
by anav
Wed Mar 12, 2025 6:03 pm
Forum: General
Topic: Connectivity Issues after Upgrade 7.17.2 > 7.18 / 7.18.2
Replies: 19
Views: 3390

Re: Connectivity Issues after Upgrade 7.17.2 > 7.18 / 7.18.2

Most weird, perhaps an IPSEC variable use has changed slightly ???
by anav
Wed Mar 12, 2025 5:41 pm
Forum: Beginner Basics
Topic: WireGuard [SOLVED]
Replies: 11
Views: 6146

Re: WireGuard [SOLVED]

Okay that is much clearer. Intention is to manually decide if the single LAN subnet will go out local LAN or WIREGUARD for internet. I should also perhaps note that its likely you want DNS requests, while using VPN, to go out wireguard as well and not leak out local router. Factors going into config...
by anav
Wed Mar 12, 2025 5:21 pm
Forum: General
Topic: Upgrade or no (revisited)
Replies: 13
Views: 1126

Re: Upgrade or no (revisited)

I'll be vague, as I was before the CVE for brute-forcing usernames came out publicly. I wouldn't use 7.17 even if they paid me, I believe MikroTik got it done with 7.18.... but with 16MB peripherals I wouldn't use 7.18.2 either... and anyway 7.18.2 is too fresh.... I believe 7.18 got it done, is ba...
by anav
Wed Mar 12, 2025 5:15 pm
Forum: General
Topic: Connectivity Issues after Upgrade 7.17.2 > 7.18 / 7.18.2
Replies: 19
Views: 3390

Re: Connectivity Issues after Upgrade 7.17.2 > 7.18 / 7.18.2

Very true, if he is indeed doing winbox over the IPSEC, that is great, if not then its a concern. Since it was noted on a separate sentence without mention of ipsec, wanted to be sure ( there was no connecting words between the two sentences to give me a warm and fuzzy that ipsec was being used )!!
by anav
Wed Mar 12, 2025 5:12 pm
Forum: Useful user articles
Topic: Advanced Routing Failover without Scripting
Replies: 295
Views: 169364

Re: Advanced Routing Failover without Scripting

May I remind you of the title of this thread WITHOUT SCRIPTING ;-PP
by anav
Wed Mar 12, 2025 5:09 pm
Forum: General
Topic: Connectivity Issues after Upgrade 7.17.2 > 7.18 / 7.18.2
Replies: 19
Views: 3390

Re: Connectivity Issues after Upgrade 7.17.2 > 7.18 / 7.18.2

Sorry not an ipsec guru, but to be clear, the purpose of ipsec is so that a user at one router, on one device can use the RDP app/protocol through the ipsec tunnel to reach a device on the other router?? That sounds reasonable! What does not sound right is using winbox over the internet. That would ...
by anav
Wed Mar 12, 2025 5:04 pm
Forum: General
Topic: Upgrade or no (revisited)
Replies: 13
Views: 1126

Re: Upgrade or no (revisited)

Interesting so there is a serious issue with leaks on RoS post 7.16.2 and they have still not fixed it.

What to do, Hmm perhaps we should Annex Latvia and call it our fourth territory!
  • 1
  • 2
  • 3
  • 4
  • 5
  • 79