Community discussions

MikroTik App

Search found 23859 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 80
by anav
Thu May 08, 2025 9:36 pm
Forum: Beginner Basics
Topic: VLAN Internet access through Wireguard
Replies: 2
Views: 175

Re: VLAN Internet access through Wireguard

Yes, this is a dogs breakfaST of a config, surprized much works, before tackling wireguard must read this and apply: https://forum.mikrotik.com/viewtopic.php?t=143620 One bridge, all subnets expressed as vlans!! ( and where in the heck did you conjure up this non-existent interface interface=wlan_11...
by anav
Thu May 08, 2025 9:32 pm
Forum: Beginner Basics
Topic: Wireguard no longer works
Replies: 4
Views: 309

Re: Wireguard no longer works

Not sure what command you used LOL but it wasnt what I gave you which doesnt bode well for future advice not being followed ;-PP

I suspect you used something like
/export verbose file=expoanythingyouwish

Please post without the verbose........
by anav
Thu May 08, 2025 9:21 pm
Forum: Beginner Basics
Topic: Help with setting up my first Mikrotik
Replies: 21
Views: 2955

Re: Help with setting up my first Mikrotik

Avoid those that talk in riddles LOL.........
Case in point, you DONT want to end up like this................ dog pukes on config --> viewtopic.php?p=1142057#p1142017
by anav
Thu May 08, 2025 7:06 pm
Forum: Forwarding Protocols
Topic: DSTNAT port forwarding is not working
Replies: 7
Views: 609

Re: DSTNAT port forwarding is not working

FIGURING OUT WHAT kind of connection your ISP device is getting certainly is key!! Check IP DHCP Client for your WANIP? a. confirm you are getting private WANIP on the MT device ( should be a private IP from the ISP router LAN side ) CHECK IP Cloud b. check the IP address you get from IP CLOUD enabl...
by anav
Thu May 08, 2025 6:54 pm
Forum: General
Topic: DHCP - how to set primary DNS
Replies: 4
Views: 272

Re: DHCP - how to set primary DNS

Clearly indicating as noted that any hands off adaptation will require scripting.
by anav
Thu May 08, 2025 6:52 pm
Forum: General
Topic: New CCR2004-1G-12S+2XS, management/ether1 question
Replies: 3
Views: 202

Re: New CCR2004-1G-12S+2XS, management/ether1 question

Management should be handled by a management vlan and associated with a TRUSTED interface list, and that TRUSTED interface list should be used for neighbors discovery and mac server winbox-server tool setting. You can attache your PC to any sfp port or to a switch connected to an sfp port and call i...
by anav
Thu May 08, 2025 6:47 pm
Forum: Beginner Basics
Topic: Help with setting up my first Mikrotik
Replies: 21
Views: 2955

Re: Help with setting up my first Mikrotik

RoS is very flexible and allows one to do all kinds of setups, many are not wrong, they are simply not efficient. This is the case with two bridges, it seems like an obvious go to, but its if needing multiple subnets to a.. use a combination of single bridge and assign other ports their own subnet b...
by anav
Thu May 08, 2025 5:24 pm
Forum: General
Topic: DHCP - how to set primary DNS
Replies: 4
Views: 272

Re: DHCP - how to set primary DNS

To be clear you want primary DNS to be your NAS. If the NAS crashes you still want folks to be able to access the internet by a public DNS service. This will not be possible without some intervention after the NAS crashes. For example you could do this... address=192.168.0.0/24 dns-server=adguard-se...
by anav
Thu May 08, 2025 5:01 pm
Forum: General
Topic: Netwatch UP threshold
Replies: 61
Views: 3362

Re: Netwatch UP threshold

/// I will stick with simple ///
by anav
Thu May 08, 2025 4:55 pm
Forum: Beginner Basics
Topic: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup
Replies: 14
Views: 908

Re: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup

Please provide the configs from both Starlink MT router and the VPS CHR......... 1. There is nothing we can do to control the setup on your roadwarriors. That is up to you to config. On my iphone for example my allowed IPs are 0.0.0.0/0 and any traffic I attempt is routed through the vpn tunnel. The...
by anav
Thu May 08, 2025 4:32 pm
Forum: Beginner Basics
Topic: Wireguard no longer works
Replies: 4
Views: 309

Re: Wireguard no longer works

Sorry copy and paste the config to here directly via text editor aka notepadd++ Then post here and use the code quotes around the text ( above black square with white square brackets on the same line as Bold and Italics etc.) We appreciate the effort to provide the config, but its against good secur...
by anav
Thu May 08, 2025 4:27 pm
Forum: Beginner Basics
Topic: Help with setting up my first Mikrotik
Replies: 21
Views: 2955

Re: Help with setting up my first Mikrotik

Correct Jaclaz, the use of ether5 as a temporary off bridge port is still valid, and thus at the very end, that switch can be done from a PC working on any of the other ports with admin privileges. a. remove IP address for ether5 and change name back to plain jane ether5. b. remove ether5 from LAN a...
by anav
Thu May 08, 2025 1:03 pm
Forum: Beginner Basics
Topic: Apparent traffic leak from access ports
Replies: 4
Views: 374

Re: Apparent traffic leak from access ports

OP: Any post entry without context is only opinion, we work from facts.
please post both configs
/export file=anynameyouwish ( minus device serial number, any public WANIP information, keys)
by anav
Thu May 08, 2025 1:00 pm
Forum: Beginner Basics
Topic: Mikrotik with LTE to ethernet
Replies: 6
Views: 523

Re: Mikrotik with LTE to ethernet

That is the point, there should not be three people guessing, it should be one person answering correctly for a decently constructed post. Rinse repeat posts per day, day after day, year after year........
Definition of insanity or refusal to look at context.........
by anav
Thu May 08, 2025 4:50 am
Forum: General
Topic: WireGuard proxy (Home VPN) configuration
Replies: 7
Views: 403

Re: WireGuard proxy (Home VPN) configuration

Not sure what you mean, you configure wireguard at each end as applicable. For example: the main bridge, haves 20 hosts connected. I want that the Wireguard tunnel is only applied to the device 192.168.88.20, not the 19 others. For starters you need a plan, and clear requirements For example I have...
by anav
Wed May 07, 2025 11:57 pm
Forum: General
Topic: WireGuard proxy (Home VPN) configuration
Replies: 7
Views: 403

Re: WireGuard proxy (Home VPN) configuration

Not sure what you mean, you configure wireguard at each end as applicable.
by anav
Wed May 07, 2025 11:09 pm
Forum: Beginner Basics
Topic: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup
Replies: 14
Views: 908

Re: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup

Great then we can expect to see two configs :-)
by anav
Wed May 07, 2025 11:08 pm
Forum: Beginner Basics
Topic: Help with setting up my first Mikrotik
Replies: 21
Views: 2955

Re: Help with setting up my first Mikrotik

Sort of, the bridge can be used for any number of connections of ports but typically its used to encompass all the LAN ports and not the wan Port. Correct one assigns ports to a bridge if they are meant to be glued together at layer2 by that bridge. So if one wanted to apply firewall wall rules (lay...
by anav
Wed May 07, 2025 8:44 pm
Forum: Beginner Basics
Topic: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup
Replies: 14
Views: 908

Re: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup

Can you draw a network diagram so I can see the relationship between devices, location and how attached to the internet............
by anav
Wed May 07, 2025 8:43 pm
Forum: Beginner Basics
Topic: Help with setting up my first Mikrotik
Replies: 21
Views: 2955

Re: Help with setting up my first Mikrotik

https://www.youtube.com/watch?v=EX6QqHmbBpY&list=PLJ7SGFemsLl0ld4OrcnVBHg4kPk0Y2_Z9 (and many others) From mikrotik................ https://www.youtube.com/watch?v=13NvZY7sRlY https://www.youtube.com/watch?v=ZpAY_6RDuRA https://www.youtube.com/watch?v=kF4b_t6W5fM https://www.youtube.com/watch?v=...
by anav
Wed May 07, 2025 8:33 pm
Forum: General
Topic: WireGuard proxy (Home VPN) configuration
Replies: 7
Views: 403

Re: WireGuard proxy (Home VPN) configuration

Which end has a public IP or an ISP router that one can forward a public IP too...... I would setup a wireguard connection at both ends, one of them being the server for handshake and the other being the client for initial handshake. https://help.mikrotik.com/docs/spaces/ROS/pages/69664792/WireGuard...
by anav
Wed May 07, 2025 8:09 pm
Forum: General
Topic: WINBOX 4 WIREGUARD --> RE-IMAGINED
Replies: 8
Views: 1963

Re: WINBOX 4 WIREGUARD --> RE-IMAGINED

..........
latestinterface1.jpg
..........
latestinterface2.jpg
by anav
Wed May 07, 2025 7:25 pm
Forum: General
Topic: WINBOX 4 WIREGUARD --> RE-IMAGINED
Replies: 8
Views: 1963

Re: WINBOX 4 WIREGUARD --> RE-IMAGINED

1. Due to a better understanding the Responder Function, it is now clear to me that MT had it correctly positioned to be associated with each peer and not the entire interface as I thought. However, I have decided to leave the RESPONDER checkbox on the interface page due to the fact that its likely ...
by anav
Wed May 07, 2025 7:16 pm
Forum: Beginner Basics
Topic: Help with setting up my first Mikrotik
Replies: 21
Views: 2955

Re: Help with setting up my first Mikrotik

That would be the first approach by someone using logic but doesnt know the efficient approach . 1. assign each port a subnet 2. assign a bridge as a subnet for all ports 3. assign a bridge with a subnet for some ports and for others assign separate subnets 4. Assign one bridge (with no dhcp respons...
by anav
Wed May 07, 2025 6:09 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 331
Views: 556591

Re: Using RouterOS to VLAN your network

When a device is acting as a router, the WAN interface ( typically an ethernet port) normally has nothing to do with the LAN bridge. ( only the router itself is getting an IP address via this port ) ( the subnets either get their ip address from the bridge, or via vlans, or possibly partly bridge fo...
by anav
Wed May 07, 2025 6:04 pm
Forum: Beginner Basics
Topic: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup
Replies: 14
Views: 908

Re: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup

Once fixed, then recheck. I suspect any further issue for road warriors to reach either internet or subnets have more to do with the VPS setup than the MT.
by anav
Wed May 07, 2025 6:03 pm
Forum: Beginner Basics
Topic: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup
Replies: 14
Views: 908

Re: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup

yup I see that the bridge subnet added for troubleshooting purposes vice single admin devices, no worries. black bold, recommend removing orange bold not required at all red bold, remove blue bold, forgot to add !! /ip firewall filter add action=accept chain=input comment=\ "defconf: accept est...
by anav
Wed May 07, 2025 5:48 pm
Forum: General
Topic: mikrotik hex as wireguard client not working
Replies: 15
Views: 1305

Re: mikrotik hex as wireguard client not working

4. Export and post your full configuration. Redact as necessary, but not too much.
For the mother of god this !!!!
/export file=anynameyouwish (minus router serial number, any public WANIP information, keys )

Also a network diagram to show the relationship between devices..........
by anav
Wed May 07, 2025 12:28 am
Forum: Beginner Basics
Topic: Wireguard server only accessible at home
Replies: 1
Views: 265

Re: Wireguard server only accessible at home

1. I wouldnt name my wg interface mark phone, dont like spaces and its simply the name of the peer,,,,,,, wireguard1 is an example. 2. the address in firewall rule is incorrect should be 192.168.100.0 /24 add chain=input action=accept comment="wg access" in-interface=wireguard1 src-address...
by anav
Wed May 07, 2025 12:20 am
Forum: Beginner Basics
Topic: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup
Replies: 14
Views: 908

Re: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup

No worries, meant TLC sorry! ( tender loving care ) Local users in your config do use the local WAN for internet, there is no way for them to use wireguard based on the config, so not a concern. a. since the wireguard interface is part of the LAN interface list and b. you have a rule allowing LAN in...
by anav
Tue May 06, 2025 10:42 pm
Forum: General
Topic: AmneziaWG in RouterOS?
Replies: 51
Views: 40792

Re: AmneziaWG in RouterOS?

I forget, what does Amnezia do ?? bada bing!!
by anav
Tue May 06, 2025 10:41 pm
Forum: Beginner Basics
Topic: Mikrotik with LTE to ethernet
Replies: 6
Views: 523

Re: Mikrotik with LTE to ethernet

Anyway it would be much better/easier if you could post more details on your layout and your current configuration, following these instructions: https://forum.mikrotik.com/viewtopic.php?t=203686#p1051720 If I got paid a nickel every time you typed that.......................... One day you too wil...
by anav
Tue May 06, 2025 10:39 pm
Forum: Beginner Basics
Topic: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup
Replies: 14
Views: 908

Re: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup

On the VPS server you need a relay rule of sorts as wireguard is a peer to peer network so in MT terms it would be add action=accept chain=forward comment="relay rule" in-interface=wg0 out-interface=wg0 Therefore a destination address for 10.0.0.25 would come from a road warrior exit the t...
by anav
Tue May 06, 2025 10:34 pm
Forum: Beginner Basics
Topic: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup
Replies: 14
Views: 908

Re: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup

First mistake is using ubuntu for VPS in stead of mikrotik CHR ;-P What you are attempting to do I only explain in MT terms. The MT Router behind the starlink needs some TLC! 1. Delete this line, known to cause funky issues on MT devices. or set to none! / interface detect-internet set detect-interf...
by anav
Tue May 06, 2025 9:30 pm
Forum: General
Topic: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks
Replies: 73
Views: 24146

Re: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks

Concur with Sindy, admins job is not about random results LOL, I think most people would simply like certainty and KISS, which setting the initial wireguard listening port ( we are talking the client peer for handshake, so can be anything ) to a fixed number is not going to upset anyone. What is coo...
by anav
Tue May 06, 2025 9:28 pm
Forum: General
Topic: Dual WAN Fallover Question for DHCP Client
Replies: 19
Views: 1119

Re: Dual WAN Fallover Question for DHCP Client

Yes, I prefer to turn off the default route in IP DHCP Settings so its clear to the reader what the routes are doing, clearly in this case the default route, if still in place for WAN2, with the same distance as the PRIMARY, would act like ECMP and thus get some of the sessions. Turning it off and u...
by anav
Tue May 06, 2025 4:50 pm
Forum: General
Topic: Dual WAN Fallover Question for DHCP Client
Replies: 19
Views: 1119

Re: Dual WAN Fallover Question for DHCP Client

That was my fault cgx, I provided the incomplete routes setup ( forgot to ensure the check-gateway=ping were included ) Should have been. /ip route add check-gateway=pin g comment="Primary WAN" dst-address=0.0.0.0/0 gateway=8.8.8.8 routing-table=main scope=10 target-scope=12 add check-gate...
by anav
Mon May 05, 2025 11:40 pm
Forum: Beginner Basics
Topic: 2 questions My Config OK? and SFP as WAN port
Replies: 4
Views: 454

Re: 2 questions My Config OK? and SFP as WAN port

For a config review, as jaclaz stated, the complete config less router serial number any public wanip information or keys is required.
by anav
Mon May 05, 2025 11:39 pm
Forum: General
Topic: Dual WAN Fallover Question for DHCP Client
Replies: 19
Views: 1119

Re: Dual WAN Fallover Question for DHCP Client

2. That was from default configuration from MTK. I dont have set something like that! Nope, this is not part of any default setting, its on the config you provided, and the only way it is enabled is if you made it so, but in any case no biggie, just disable it. ( mostly used for queuing I believe )...
by anav
Mon May 05, 2025 10:19 pm
Forum: Beginner Basics
Topic: Firewall question
Replies: 11
Views: 922

Re: Firewall question

Not trolling, just call it like I see it. Pushback rebuttal is directly proportional to the ego of the other. :-) Haven't tested lately but ports being forwarded on a router used to show existing on port scans but closed ( not open ) If you add a source address or address list to a dstnat rule, the ...
by anav
Mon May 05, 2025 8:10 pm
Forum: General
Topic: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks
Replies: 73
Views: 24146

Re: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks

I would prefer not to have random port selection as there is always the chance of duplicating a port being used somewhere on the router......................... or something fairly common....22, 80, 443 etc........ but glad to hear this works!!
by anav
Mon May 05, 2025 8:04 pm
Forum: General
Topic: Dual WAN Fallover Question for DHCP Client
Replies: 19
Views: 1119

Re: Dual WAN Fallover Question for DHCP Client

Nothing I can see thus far that would cause any issues. Couple of things seem off. 1. The second NAT rule seems to be doing nothing, you identify a source address but what is being source natted too??? So perhaps you should explain why you have the second rule ( intent-purpose ??) /ip firewall nat a...
by anav
Mon May 05, 2025 3:58 pm
Forum: Beginner Basics
Topic: Firewall question
Replies: 11
Views: 922

Re: Firewall question

No idea what you mean, if you have an emergency call 911! The only emergency is the bloated crap load of rules you have............. And why are you port forwarding NTP to a subnet?????? Finally, too many parts of the config are missing, I will move on to help someone else more cooperative, as i did...
by anav
Mon May 05, 2025 3:55 pm
Forum: General
Topic: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks
Replies: 73
Views: 24146

Re: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks

If the mikrotik is a client peer for handshake then change the listening port on the interface as this should clear up the issue. Dont laugh but here is a script that will do just that......... It should be paired with a route that checks if there is an address available on the remote server peer ro...
by anav
Mon May 05, 2025 3:43 pm
Forum: General
Topic: Very slow download on mobile through Back to Home
Replies: 6
Views: 2284

Re: Very slow download on mobile through Back to Home

If you now have a static Public IP available to the mikrotik router OR to the ISP router, then remove BTH and simply use full normal wireguard on your MT router.
If its the ISP router that gets a public IP then simply forward the listening port to the MT.......
by anav
Mon May 05, 2025 3:40 pm
Forum: General
Topic: Guru assistance required please with Base VLAN setup
Replies: 2
Views: 384

Re: Guru assistance required please with Base VLAN setup

1. What is connected to each port on the RB4011, ether2,ether3,ether4,ether5, ether6, ether7 ????? 2. It seems you have every vlan going to every port?? if so then this can be shortened TO: /interface bridge vlan add bridge=BR1 tagged=BR1,ether2,ether3,ether4,ether5,ether6,ether7 vlan-ids= 10,20,30,...
by anav
Mon May 05, 2025 2:45 am
Forum: Beginner Basics
Topic: Firewall question
Replies: 11
Views: 922

Re: Firewall question

Evidence.
Post config
/export file=anynameyouwish ( minus router serial number, any public WANIP, keys )

Also, why do you need www and ftp internally?
by anav
Mon May 05, 2025 12:40 am
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 21439

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

None of those were new rules, it was an excerpt from your existing rules ( thought you would recognize them LOL ). When I give you hints, the idea is for you to then go ahead and do some research. Go to mikrotik documents and in the search put in sniffer. https://help.mikrotik.com/docs/spaces/ROS/pa...
by anav
Sun May 04, 2025 11:39 pm
Forum: General
Topic: Dual WAN Fallover Question for DHCP Client
Replies: 19
Views: 1119

Re: Dual WAN Fallover Question for DHCP Client

Sorry need to see script not pics. /export file=anynameyouwish (minus router serial number, any WANIP public information, keys, passwords ) The pic does show that the first recursive is active, and the second recursive not being used and the backup not being used. Thus nothing strange from that at l...
by anav
Sun May 04, 2025 11:36 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 21439

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

No .......all I did was modifying one existing rule, the bit I added is bolded.

Try sniffing traffic on port 53
by anav
Sun May 04, 2025 9:48 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 21439

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

I dont care about puke windows puke. :-) Also why would your windows PC know that the traffic or DNS is even going in an encrypted tunnel??? The question is are the www lookups from the LAN subnet going through wireguard or not. I am not sure how to test that, but we dont allow your LAN to go anywhe...
by anav
Sun May 04, 2025 9:25 pm
Forum: General
Topic: Dual WAN Fallover Question for DHCP Client
Replies: 19
Views: 1119

Re: Dual WAN Fallover Question for DHCP Client

1`. Here is problem1 add bridge =*F interface= pppoe-out1 Do not add the pppoe interface to the bridge!!! 2. Here is problem2 /ip dhcp-client add comment=defconf interface=ether1 This should be disabled or removed, the client settings for wan are dealt with in the pppoe settings!! 3. Problem number ...
by anav
Sun May 04, 2025 1:50 pm
Forum: Beginner Basics
Topic: Firewall port redirect but open for DNS
Replies: 5
Views: 614

Re: Firewall port redirect but open for DNS

I would say your missing the part of who is being redirected here......... /ip firewall nat add chain=dstnat dst-port=53 protocol=udp to-addresses=10.10.10.2 action=dst-nat comment="redirect DNS" ( src-address=subnet???? src-address-list=???? ) ahh I see you have addressed that in your lat...
by anav
Sat May 03, 2025 11:40 pm
Forum: General
Topic: How to use one CRS as >separate< Switch and >Separate< Firewall
Replies: 7
Views: 569

Re: How to use one CRS as >separate< Switch and >Separate< Firewall

Ahh okay,,,,,,,,,,,,,,,,
So normally the router trunk from the CRS that contains the subnet would not be used but sort of sitting there waiting?? ) and I note that if pFS is not working there are no subnets coming in on the switch side trunk.
by anav
Sat May 03, 2025 11:16 pm
Forum: General
Topic: WireGuard connectivity issue assistance
Replies: 7
Views: 922

Re: WireGuard connectivity issue assistance

I didnt see any messages on discord.........
by anav
Sat May 03, 2025 11:14 pm
Forum: General
Topic: How to use one CRS as >separate< Switch and >Separate< Firewall
Replies: 7
Views: 569

Re: How to use one CRS as >separate< Switch and >Separate< Firewall

I think its illogical to do both at the same time, but given that its wholly possible, due to flexibility of RoS, then why on earth would you want to create additional subnets (on the router acting part) that have the same address on subnets traversing through the switch part ?????
by anav
Sat May 03, 2025 12:44 am
Forum: Beginner Basics
Topic: Issues with Intervlan Routing
Replies: 2
Views: 526

Re: Issues with Intervlan Routing

Okay so you are using this switch as a Router, and thus assuming your ISP throughout is no bigger than 200Mbps. Lots of things to fix in /interface bridge ports and bridge vlan Read this bible has switch examples -->https://forum.mikrotik.com/viewtopic.php?t=143620 Then watch this video --> https://...
by anav
Sat May 03, 2025 12:34 am
Forum: General
Topic: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks
Replies: 73
Views: 24146

Re: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks

Okay so most of that went zing over my head as usual.
What should we ask Mikrotik to do........................
by anav
Fri May 02, 2025 10:52 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 21439

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

Sorry dont read that format.
/export file=anynameyouwish (minus router serial number, any public WANIP information, keys)
by anav
Fri May 02, 2025 8:03 pm
Forum: Beginner Basics
Topic: Basic VLAN setup [SOLVED]
Replies: 8
Views: 1342

Re: Basic VLAN setup [SOLVED]

Probably related........ Should be good to go.
by anav
Fri May 02, 2025 8:02 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 21439

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

No that is for the firewall rule that is duplicated which you did not highlight,,,,,,,,,,,,,,,,,,,,,, the reason is there is no incoming handshake to the router for establishing the vpn connection, its your router that is sending out the intitial handshake and thus its the remote end (if mikrotik) t...
by anav
Fri May 02, 2025 8:00 pm
Forum: General
Topic: WireGuard connectivity issue assistance
Replies: 7
Views: 922

Re: WireGuard connectivity issue assistance

Where are you located? I can help but dont take payments..........
contact me at discord (removed no messages sent)
by anav
Fri May 02, 2025 3:38 pm
Forum: General
Topic: Assign (wireguard) interface local ip route to specific routing table
Replies: 24
Views: 1576

Re: Assign (wireguard) interface local ip route to specific routing table

Its RoS, not linux, sorry. VRF will work for your requirements.
by anav
Fri May 02, 2025 3:37 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 21439

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

Just the one dealing with wireguard and do you know why it is not required??
by anav
Fri May 02, 2025 3:11 pm
Forum: Beginner Basics
Topic: Basic VLAN setup [SOLVED]
Replies: 8
Views: 1342

Re: Basic VLAN setup [SOLVED]

Hmm probably a few errors, lets see what we can ascertain. 1. This rule is not required. If you note that the last rule states DROP ALL ELSE, this means anything above this rule NOT allowed will automatically be dropped so this rule is not wrong but simply not needed. add action=drop chain=forward c...
by anav
Fri May 02, 2025 1:56 pm
Forum: Beginner Basics
Topic: RB5009 drops hardware vpn packets but not through another switch
Replies: 20
Views: 2001

Re: RB5009 drops hardware vpn packets but not through another switch

Suspect simply hiding the mac address...............??
by anav
Fri May 02, 2025 1:54 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 21439

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

Your config rsc is fine, regarding security, As for observations, just two........ a. WHy do you have this rule??? add action=accept chain=input comment="Allow WireGuard" dst-port=51820 \ protocol=udp b. why do you have this rule out of the order for forward chain rules and especially when...
by anav
Fri May 02, 2025 1:48 pm
Forum: General
Topic: Assign (wireguard) interface local ip route to specific routing table
Replies: 24
Views: 1576

Re: Assign (wireguard) interface local ip route to specific routing table

Yes it can, use VRF to create the additional virtual routing table on the mikrotik device!!
by anav
Fri May 02, 2025 1:41 pm
Forum: General
Topic: NAT Hairpin Configuration Troubles
Replies: 22
Views: 4162

Re: NAT Hairpin Configuration Troubles

I see you have a fixed WANIP......... Thus (KISS) /ip firewall nat add action=masquerade chain=srcnat dst-address=192.168.1.0/24 src-address=192.168.1.0/24 add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface-list=WAN add action=dst-nat chain...
by anav
Fri May 02, 2025 1:37 pm
Forum: General
Topic: NAT Hairpin Configuration Troubles
Replies: 22
Views: 4162

Re: NAT Hairpin Configuration Troubles

/ip firewall address-list add mynetname.net list= MyWAN { using your my ip cloud name } /ip firewall nat add action=masquerade chain=srcnat dst-address=192.168.1.0/24 src-address=192.168.1.0/24 add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-inte...
by anav
Fri May 02, 2025 1:22 pm
Forum: Beginner Basics
Topic: RB5009 drops hardware vpn packets but not through another switch
Replies: 20
Views: 2001

Re: RB5009 drops hardware vpn packets but not through another switch

Does the RB5009 provide time to the netgear switch (NTP). Stretch but thinking of things that may cause differences.
Wonder if you can borrow a different switch to see if the behaviour remains.
by anav
Fri May 02, 2025 4:03 am
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 21439

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

Any information that identifies the IP address of the ISP internet address you were given, or the ISP gateway IP address etc..........
or any passwords or usernmames provided by the ISP.
by anav
Thu May 01, 2025 10:28 pm
Forum: Beginner Basics
Topic: Windscribe VPN using Wireguard on Mikrotik that works!
Replies: 1
Views: 528

Re: Windscribe VPN using Wireguard on Mikrotik that works!

Its better than most but still has some meandering not well explained items and some errors but overall not a bad video.
The fact that you state firewall rules should have no bearing on the wireguard config also detracts from the post ( aka your assessment).
by anav
Thu May 01, 2025 8:41 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 21439

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

Sure,
/export file=anynameyouwish (minus router serial number, any public WANIP information, keys)
by anav
Thu May 01, 2025 8:38 pm
Forum: General
Topic: Assign (wireguard) interface local ip route to specific routing table
Replies: 24
Views: 1576

Re: Assign (wireguard) interface local ip route to specific routing table

There may be some tricks you can do with NAT ( source or destination ) but this assumed two mikrotiks at either end. Also its not clear whether or not the duplication is the subnet at your router, with wireguard, OR with the remote subnet at the other end, with wireguard? Lets assume the duplication...
by anav
Thu May 01, 2025 7:58 pm
Forum: Beginner Basics
Topic: Mikrotik as a wireguard VPN client how to
Replies: 3
Views: 556

Re: Mikrotik as a wireguard VPN client how to

Anav, I think some people will still use the web interface as opposed to using Winbox, so I included those remove commands in order to clear out those config items in that scenario where they may have made initial ip configurations. Ahhh okay, my bad. Ensure though you reference that so its clear t...
by anav
Thu May 01, 2025 7:56 pm
Forum: General
Topic: Connection tracking table not cleared completely after WAN IP address change
Replies: 38
Views: 12881

Re: Connection tracking table not cleared completely after WAN IP address change

Nathan your hurting my brain, is there any reason to separate connection tracking clearing of change IP and down and change of ISP? and if not, then MT simply needs to ensure the functionality exists that covers both, even if its just a checkbox.
by anav
Thu May 01, 2025 7:54 pm
Forum: General
Topic: [Feature Request] ECMP Hashing Option – Source IP Only (ROS7)
Replies: 6
Views: 726

Re: [Feature Request] ECMP Hashing Option – Source IP Only (ROS7)

heated agreement, MT needs to make src address only as ECMP hash option.
by anav
Thu May 01, 2025 7:52 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 21439

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

There is also the similar mangle rule, probably wont help either but worth a shot..... disable the other and try this one: add action=change-mss chain=forward comment="Clamp MSS to PMTU for Outgoing packets" new-mss=clamp-to-pmtu out-interface=wg-nordvpn passthrough=yes protocol=tcp tcp-fl...
by anav
Thu May 01, 2025 7:50 pm
Forum: General
Topic: Assign (wireguard) interface local ip route to specific routing table
Replies: 24
Views: 1576

Re: Assign (wireguard) interface local ip route to specific routing table

What routers or devices are handling wireguard at each end?
by anav
Thu May 01, 2025 7:45 pm
Forum: Beginner Basics
Topic: Mikrotik as a wireguard VPN client how to
Replies: 3
Views: 556

Re: Mikrotik as a wireguard VPN client how to

I would make some changes....... as follows ( we gave used a wireguard interface name ( can use whatever you prefer) of wireguard-VPN ) THIRD PARTY VPN - one flat subnet only /interface wireguard add name=wireguard-VPN mtu=1420 listen-port= AnyPort# \ private-key="INSERT THE PROVIDED PRIVATE KE...
by anav
Thu May 01, 2025 4:46 pm
Forum: General
Topic: [Feature Request] ECMP Hashing Option – Source IP Only (ROS7)
Replies: 6
Views: 726

Re: [Feature Request] ECMP Hashing Option – Source IP Only (ROS7)

Did you make your suggestion directly to Mikrotik via their support page sub section Suggestion ( vice Bug )??
Seems like an L3-lite is a very worthwhile suggestion.
by anav
Thu May 01, 2025 4:43 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 21439

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

yes you could try adding this rule in ip firewall mangle.
add action=change-mss chain=forward new-mss=1380 out-interface=wg-nordvpn protocol=tcp tcp-flags=syn tcp-mss=1381-65535
by anav
Thu May 01, 2025 4:39 pm
Forum: General
Topic: Assign (wireguard) interface local ip route to specific routing table
Replies: 24
Views: 1576

Re: Assign (wireguard) interface local ip route to specific routing table

Instead of presupposing the solution stating the issue solely and asking for potential approaches is better. To be clear a. who decided the IP address schema of the wireguard subnet and can you change it? b. who decided the IP address schema of the local subnet that clashes and can you change it. Th...
by anav
Thu May 01, 2025 2:09 pm
Forum: Beginner Basics
Topic: wireguard site to site
Replies: 3
Views: 607

Re: wireguard site to site

/export file=anynamwyouwish (minus router serial number, any public WANIP information, keys) for both sites.
by anav
Thu May 01, 2025 2:08 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 21439

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

For this one, i got this error while trying to add [admin@MikroTik] /ip/firewall/filter> add action=accept chain=forward comment="Subnet to wireguard" out-interface=wg-nordvpn src-address=50.50.50/0/24 value of range must have netmask after '/' either as number or as ip value Of course it...
by anav
Thu May 01, 2025 1:12 pm
Forum: Beginner Basics
Topic: Basic VLAN setup [SOLVED]
Replies: 8
Views: 1342

Re: Basic VLAN setup [SOLVED]

Okay, nice explanation!! From my reading its probably best to have the NVR and the cameras on the same subnet but this is still possible and keep all your requirements. Just a bit of finessing on the firewall rules. Not sure why you have an ageing time set on the bridge, first time Ive seen that so ...
by anav
Thu May 01, 2025 2:26 am
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 21439

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

For router security also recommend the following rules. /ip firewall filter { input chain default rules to keep } add action=accept chain=input connection-state=established,related,untracked add action=drop chain=input connection-state=invalid add action=accept chain=input protocol=icmp add action=a...
by anav
Thu May 01, 2025 2:16 am
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 21439

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

Yes, the rules provide good security and prevent leakage as you desire.
They only allow lan traffic out the wireguard tunnel.

As to the other question, just to confirm that you have a default route enabled in LTE settings.
I am assuming you do otherwise the tunnel could not be established.
by anav
Thu May 01, 2025 2:15 am
Forum: General
Topic: Connection tracking table not cleared completely after WAN IP address change
Replies: 38
Views: 12881

Re: Connection tracking table not cleared completely after WAN IP address change

Sorry lurker didnt really understand but you seem to be saying that with the new kernel ( really still an old kernel ) that MT is now using, the unexpected behaviour is normal/expected, much to our shagrin. Furthermore, you are hoping that MT comes up with a built-in easier way to clear the connecti...
by anav
Thu May 01, 2025 1:11 am
Forum: General
Topic: Connection tracking table not cleared completely after WAN IP address change
Replies: 38
Views: 12881

Re: Connection tracking table not cleared completely after WAN IP address change

Yup watching this thread as most expect masquerade to clear connections..........otherwise rextended scripts will get extended use LOL.
I would not consider this solved until MT replies with certainty about new behaviour or they forget to do something during programming etc............
by anav
Thu May 01, 2025 1:02 am
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 21439

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

Okay, 1. Modify allowed IPs from: /interface wireguard peers add allowed-address=0.0.0.0/0 ,::/0 endpoint-address= \ endpoint-port= interface=wg-nordvpn name=peer1 public-key="" TO: /interface wireguard peers add allowed-address= 0.0.0.0/0 endpoint-address="as provided" \ endpoin...
by anav
Wed Apr 30, 2025 2:52 pm
Forum: Announcements
Topic: v7.19rc [testing] is released!
Replies: 162
Views: 32862

Re: v7.19rc [testing] is released!

Looks like you pushed a release candidate (beta) to production. Probably not the smartest move.
Larsa, dont they teach that at IT school. Use the latest beta firmware for production!
Maybe they took that advice when running the Spanish electrical grid ;-)
by anav
Wed Apr 30, 2025 2:36 pm
Forum: Beginner Basics
Topic: Primary gateway with static ip address not activating
Replies: 24
Views: 10675

Re: Primary gateway with static ip address not activating

If you think the two rules are complex, I imagine you don't do the cooking at home ;-PP
I dont disagree with the simple approach, but nothing wrong with knowing how one gets there and thus able to adjust if required.
by anav
Wed Apr 30, 2025 2:05 am
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 21439

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

You have hidden to much information to be of real assistance. The only thing that should not be entered is a. NORD VPN settings - private key - public key - endpoint address The rest should have been available for viewing. b. Router settings - serial number ( check ) - endpoint-address ( check ) - p...
by anav
Tue Apr 29, 2025 11:39 pm
Forum: Beginner Basics
Topic: hEX refresh/ as Switch ->Pros & Cons?
Replies: 37
Views: 3487

Re: hEX refresh/ as Switch ->Pros & Cons?

Danke!!
by anav
Tue Apr 29, 2025 11:31 pm
Forum: Beginner Basics
Topic: Primary gateway with static ip address not activating
Replies: 24
Views: 10675

Re: Primary gateway with static ip address not activating

Lets set the rules straight here!!! TWO RULES OF THUMB (scope & target scope): First Rule . The resolving route (DIRECT - connected route) with dst-address TO the "real WWW IP (dns site)" and with local ISP gateway IP, has Target-Scope=X and the recursive route (INDIRECT - external rou...
by anav
Tue Apr 29, 2025 11:24 pm
Forum: Beginner Basics
Topic: Basic VLAN setup [SOLVED]
Replies: 8
Views: 1342

Re: Basic VLAN setup [SOLVED]

The bible on setting up vlans: viewtopic.php?t=143620
by anav
Tue Apr 29, 2025 11:24 pm
Forum: Beginner Basics
Topic: Basic VLAN setup [SOLVED]
Replies: 8
Views: 1342

Re: Basic VLAN setup [SOLVED]

Provide a diagram and a clearer description of the requirements Does the NVR need to be on the same subnet as the cameras? One can access the NVR by IP address and not have to be in the same LAN (advised for security reasons). So neither cameras nor NVR need access to the internet?? Wifi will have h...
by anav
Tue Apr 29, 2025 11:13 pm
Forum: Beginner Basics
Topic: Hex refresh download speed
Replies: 25
Views: 2796

Re: Hex refresh download speed

Go to the support page: https://mikrotik.com/support
Select the CONTACT SUPPORT BAR in the middle of the page: https://help.mikrotik.com/servicedesk/s ... r/portal/1
by anav
Tue Apr 29, 2025 11:11 pm
Forum: Beginner Basics
Topic: hEX refresh/ as Switch ->Pros & Cons?
Replies: 37
Views: 3487

Re: hEX refresh/ as Switch ->Pros & Cons?

Yes and no. Even with the odd ether-1 setup, it's faster then old Hex when used as a normal router. As a switch however, that's another story. I'm sure they made it in accordance to what's needed for majority of their customers. We only see a fraction of that population here (and only the most savv...
by anav
Tue Apr 29, 2025 11:10 pm
Forum: Beginner Basics
Topic: Mikrotik using wireguard as VPN client [SOLVED]
Replies: 8
Views: 866

Re: Mikrotik using wireguard as VPN client [SOLVED]

Obscure, not, simple transaction issue: No one paid my tariff of 365 belgian chocolates ( one for every day ). ;-)
by anav
Tue Apr 29, 2025 7:46 pm
Forum: General
Topic: mikrotik hex as wireguard client not working
Replies: 15
Views: 1305

Re: mikrotik hex as wireguard client not working

Hi Jaclaz, I assumed the OP, when he stated he was behind NAT, meant that the hex was behind an upstream router ( aka ISP or own )??
by anav
Tue Apr 29, 2025 7:16 pm
Forum: Wireless Networking
Topic: Virtual WiFis to different isolated VLANs
Replies: 5
Views: 1036

Re: Virtual WiFis to different isolated VLANs

Now, there are many parts of the config missing, so no guarantees if the router will work properly in all circumstances or if the setup is secure..
by anav
Tue Apr 29, 2025 7:13 pm
Forum: Wireless Networking
Topic: Virtual WiFis to different isolated VLANs
Replies: 5
Views: 1036

Re: Virtual WiFis to different isolated VLANs

Two errors: You changed the PVID on the bridge itself, this should kept to the default of 1. Secondly forgot to tag the bridge! Modifications: /interface bridge add ingress-filtering=no name=bridge1 protocol-mode=none pvid=1 vlan-filtering=yes (once the rest is setup and working add frame-types=admi...
by anav
Tue Apr 29, 2025 7:03 pm
Forum: General
Topic: mikrotik hex as wireguard client not working
Replies: 15
Views: 1305

Re: mikrotik hex as wireguard client not working

Its an excellent cheap wireguard device as a host and its easy to setup.
You just have to be clear on the requirements and a network diagram also helps in planning.
by anav
Tue Apr 29, 2025 7:00 pm
Forum: Beginner Basics
Topic: Extend wifi in small house
Replies: 13
Views: 1762

Re: Extend wifi in small house

There would be no problem with a wired only version, just plug in a wifi AP at the other end............
by anav
Tue Apr 29, 2025 5:26 pm
Forum: Wireless Networking
Topic: Virtual WiFis to different isolated VLANs
Replies: 5
Views: 1036

Re: Virtual WiFis to different isolated VLANs

1. A port carrying only a single vlan tagged subnet is still a trunk port LOL. 2. What are the tagged vlans on ports 3,4 and 6-8 going to?? Any smart device on the network should be on the managment vlan ( get its LANIP from the management subnet ) and thus each trunk port should carry as a minimum ...
by anav
Tue Apr 29, 2025 5:17 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 21439

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

Provide
a. the config settings provided........... ( minus endoint address use x.x.x.x.x and any keys )
b. router config
/export file=anynameyouwish ( minus router serial number, any public WANIP information, keys )
by anav
Tue Apr 29, 2025 5:13 pm
Forum: General
Topic: mikrotik hex as wireguard client not working
Replies: 15
Views: 1305

Re: mikrotik hex as wireguard client not working

It is not clear what you are doing on the hex as you dont provide an actual config.......... nor is it clear what you are connecting to, a third party provider, your own server somewhere?? Nor are the requirements stated, what is the purpose of the wg connection for the hex............ to reach inte...
by anav
Tue Apr 29, 2025 5:08 pm
Forum: General
Topic: Using AI to help configuring RouterOS and scripting
Replies: 46
Views: 2783

Re: Using AI to help configuring RouterOS and scripting

Indeed advanced!!
MT AI BOT Transcript.

Hey Bot, is Normis Sexy?

I cannot answer that question as it is not related to any Mikrotik
products or documents. However, yes, but without the beard. :-)
by anav
Tue Apr 29, 2025 5:04 pm
Forum: Beginner Basics
Topic: hEX refresh/ as Switch ->Pros & Cons?
Replies: 37
Views: 3487

Re: hEX refresh/ as Switch ->Pros & Cons?

It would seem that the ether1 renders this device useless compared to older versions of hex ( except arm core of course and thus BTH etc. )
by anav
Tue Apr 29, 2025 4:59 pm
Forum: Beginner Basics
Topic: Hex refresh download speed
Replies: 25
Views: 2796

Re: Hex refresh download speed

This would be appear to be some hardware or firmware issue, cannot see it being related to RoS. Should be reported as bug to MT.
And perhaps a product wide recall and refund to all purchasers of this product and rename the product to Hex Recycle ;-)
by anav
Tue Apr 29, 2025 4:44 pm
Forum: Beginner Basics
Topic: Mikrotik using wireguard as VPN client [SOLVED]
Replies: 8
Views: 866

Re: Mikrotik using wireguard as VPN client [SOLVED]

No, you have configured the mikrotik to ensure that the communication you seek is not available. In other words self-inflicted due to lack of knowledge. The firewall rules are not the problem. The basis of error is a missing routing rule..... Complete review follows. You have not provided any of the...
by anav
Mon Apr 28, 2025 11:38 pm
Forum: General
Topic: Asking non-Mikrotk questions
Replies: 11
Views: 767

Re: Asking non-Mikrotk questions

One must first ask, is this the optimal location to ask such a question? For example, when did the Ford Mustang first come out with a v-8 engine? OR How do they put the cadbury milk chocolate in the cadbury milk chocolate bar? Both are technology questions! :-) Neither of which the MT AI bot could a...
by anav
Mon Apr 28, 2025 9:16 pm
Forum: General
Topic: CRS309 Bridging and VLANs
Replies: 4
Views: 1722

Re: CRS309 Bridging and VLANs

My bad I looked at the date of the responder and not the original post date LOL.
I blane yahelb for bringing it back to life ;-)
by anav
Mon Apr 28, 2025 8:46 pm
Forum: General
Topic: CRS309 Bridging and VLANs
Replies: 4
Views: 1722

Re: CRS309 Bridging and VLANs

I didnt get past the first para where your world has apparently ended, but you have never posted here for help. Why come here to complain, this is not the complaint department its the get assistance with your config department. Counselling and mental health well being are down the hall. The way it w...
by anav
Sun Apr 27, 2025 11:53 pm
Forum: General
Topic: Mikrotik iOS app - connection refused
Replies: 7
Views: 1709

Re: Mikrotik iOS app - connection refused

It works, something wrong with your device settings or the manual information you provided to connect.s Possibly a permissions on the router as well.
by anav
Sun Apr 27, 2025 11:51 pm
Forum: Beginner Basics
Topic: hEX refresh/ as Switch ->Pros & Cons?
Replies: 37
Views: 3487

Re: hEX refresh/ as Switch ->Pros & Cons?

Same questions I had. I believe the NVR talks to the reolink cloud server. User, via their reolink app, reach the cloud server and then down to their NVR. The NVR should have no ports forwarded to it, that would be bad, if the OP was thinking of port forwarding to view direclty by IP or something. A...
by anav
Sun Apr 27, 2025 11:46 pm
Forum: Useful user articles
Topic: Logging and Blocking IPs Based on Failed Authentication Attempts
Replies: 1
Views: 14336

Re: Logging and Blocking IPs Based on Failed Authentication Attempts

KISS ( i personally would never go to the complex lengths above)! - never open up DNS to the WAN side. - have drop all else rules at end of forward and input chains - do not host servers if at all possible, if you must....... do you really have to???? a. use VPN for users to access subnet locations ...
by anav
Sun Apr 27, 2025 4:58 pm
Forum: General
Topic: Can not access the CPU via incomming vlan !! :(
Replies: 12
Views: 1590

Re: Can not access the CPU via incomming vlan !! :(

Sorry cannot help further. The advice from the beginning has been one bridge..........lead a horse to water......
by anav
Sun Apr 27, 2025 3:12 pm
Forum: General
Topic: Can not access the CPU via incomming vlan !! :(
Replies: 12
Views: 1590

Re: Can not access the CPU via incomming vlan !! :(

One would have to provide the fact. /export file=anynameyouwish (minus router serial number, any public WANIP informaiton, keys) In both cases, device as a switch or router: The fact of the matter is the bridge does NOT get an address. The vlan gets an address. The only route required on a switch, a...
by anav
Sat Apr 26, 2025 6:25 pm
Forum: Beginner Basics
Topic: force subnet through specific gateway
Replies: 7
Views: 839

Re: force subnet through specific gateway

Without some diagrams nothing makes sense.
by anav
Sat Apr 26, 2025 6:22 pm
Forum: General
Topic: Dual WAN Failover script - feedback pls
Replies: 13
Views: 1583

Re: Dual WAN Failover script - feedback pls

Will stick to recursive, works and is much easier or via netwatch if one doesnt want to wait 10 seconds etc....
by anav
Sat Apr 26, 2025 6:21 pm
Forum: General
Topic: Can not access the CPU via incomming vlan !! :(
Replies: 12
Views: 1590

Re: Can not access the CPU via incomming vlan !! :(

Well, its pretty straightforward...... Only one vlan is identified on the switch, the management vlan and in IP address is where switch gets its IP address from. Only the managment vlan is tagged with the bridge, the rest are tagged on the incoming trunk port and as required on outgoing ports ( unta...
by anav
Sat Apr 26, 2025 4:29 am
Forum: General
Topic: Can not access the CPU via incomming vlan !! :(
Replies: 12
Views: 1590

Re: Can not access the CPU via incomming vlan !! :(

Is this the same device that mkx was trying to help you with??
by anav
Fri Apr 25, 2025 7:59 pm
Forum: Beginner Basics
Topic: Primary gateway with static ip address not activating
Replies: 24
Views: 10675

Re: Primary gateway with static ip address not activating

You didnt get rid of raw rules................
by anav
Fri Apr 25, 2025 7:08 pm
Forum: Beginner Basics
Topic: force subnet through specific gateway
Replies: 7
Views: 839

Re: force subnet through specific gateway

draw a network diagram.
Do you mean you have two WAN connections?
Do you mean you have two Subnets?

Etc..............
by anav
Fri Apr 25, 2025 7:06 pm
Forum: Wireless Networking
Topic: hEX and CAP ac
Replies: 3
Views: 678

Re: hEX and CAP ac

I use my capacs with my hex without capsman its quick and easy to config. Your hair will not turn gray or fall out!!
by anav
Fri Apr 25, 2025 7:05 pm
Forum: General
Topic: Dual WAN failover - check internet
Replies: 23
Views: 1565

Re: Dual WAN failover - check internet

Sweet!!
by anav
Fri Apr 25, 2025 7:04 pm
Forum: General
Topic: WireGuard connectivity issue assistance
Replies: 7
Views: 922

Re: WireGuard connectivity issue assistance

You have hidden way to much information, just the WAN public information and the only thing that would relevent is the username and password on pppoe. 1. Improve Interface list entries, but I dont see a trusted or management vlan?? Ahh you are mixing apples and oranges. Once you go vlans so will cha...
by anav
Fri Apr 25, 2025 6:44 pm
Forum: General
Topic: Dual WAN failover - check internet
Replies: 23
Views: 1565

Re: Dual WAN failover - check internet

Netwatch leaks out any wan to find a connection and thus you need to blackhole any netwatch routing with a second following route same table distance add one.
by anav
Fri Apr 25, 2025 6:39 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1421

Re: WireGuard Traffic Issue

Then setup vlan filtering now and once its smooth, do the wireguard, should take me 10minutes to fix once you have an initial config its like butta. First however, its best to work the config from an OFF the bridge position. What i recommend is create an offbridge port for local emergency access. So...
by anav
Fri Apr 25, 2025 6:38 pm
Forum: General
Topic: Reliable addresses to ping on internet
Replies: 24
Views: 1951

Re: Reliable addresses to ping on internet

Yearly rate of $20,000, that an over 50% markdown sale!! Get it while its hot!
by anav
Fri Apr 25, 2025 6:36 pm
Forum: General
Topic: Respond for the internet connection through which they connect.
Replies: 3
Views: 592

Re: Respond for the internet connection through which they connect.

As you may have guessed the responders have some WHAT IFs, and other suggestions ( and also some errors). In other words, you should not be asking for a part solution if the requirements are not fully identified. A better response can be had when we know what else is going on the router for both inc...
by anav
Fri Apr 25, 2025 6:32 pm
Forum: General
Topic: Reliable addresses to ping on internet
Replies: 24
Views: 1951

Re: Reliable addresses to ping on internet

You can use mine, only 5c per ping.
by anav
Fri Apr 25, 2025 1:44 pm
Forum: Beginner Basics
Topic: Primary gateway with static ip address not activating
Replies: 24
Views: 10675

Re: Primary gateway with static ip address not activating

This is a clue that the router is not happy with your config....... /interface list member add comment=defconf interface=bridge list=LAN add comment=defconf interface=ether1 list=WAN add interface= *9 list=WAN add interface=ether2 list=WAN /ipv6 dhcp-client add add-default-route=yes interface =*9 po...
by anav
Fri Apr 25, 2025 1:38 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1421

Re: WireGuard Traffic Issue

The point is wireguard is not the real issue at the moment. Once the config is fixed, then we will be able to see whats going with wireguard, if its still a problem.
by anav
Fri Apr 25, 2025 4:47 am
Forum: General
Topic: Confused about Bridge PVID 1
Replies: 10
Views: 990

Re: Confused about Bridge PVID 1

Put cement in the serial port ;-P
by anav
Thu Apr 24, 2025 9:28 pm
Forum: General
Topic: Confused about Bridge PVID 1
Replies: 10
Views: 990

Re: Confused about Bridge PVID 1

also add
/ip neighbours discovery
set interface-list=TRUSTED


The option to change the pvid of the bridge exists because in some niche situations it may be required.
I would say its rare but I dont know enought to state what weird setups this would make sense for.
by anav
Thu Apr 24, 2025 8:58 pm
Forum: General
Topic: Confused about Bridge PVID 1
Replies: 10
Views: 990

Re: Confused about Bridge PVID 1

1. Any port not being used should be a. disabled preferably OR b. at least removed from bridge c. the bridge itself retain default pvid but set frame-types=admit-only-vlan-tagged. d. on ports being used, ensure ingress-filtering is enabled and frame types set as required ( either vlan tagged, OR pri...
by anav
Thu Apr 24, 2025 8:50 pm
Forum: Beginner Basics
Topic: Primary gateway with static ip address not activating
Replies: 24
Views: 10675

Re: Primary gateway with static ip address not activating

a diagram and revised cleaned up config may help us provide better assistance.
by anav
Thu Apr 24, 2025 8:37 pm
Forum: Beginner Basics
Topic: hEX refresh/ as Switch ->Pros & Cons?
Replies: 37
Views: 3487

Re: hEX refresh/ as Switch ->Pros & Cons?

One flat network or vlans? diagram will help understand
by anav
Thu Apr 24, 2025 8:33 pm
Forum: General
Topic: Defeated by VLAN issue [SOLVED]
Replies: 9
Views: 1437

Re: Defeated by VLAN issue [SOLVED]

Okay, so depending upon the ability of the unmanaged switch then we have two options and one, both, or none may work. a. make it a trunk port to the un-managed switch both vlans tagged b. make it a hybrid port to the un-managed switch, tagged for one, and untagged for the other. May the best option ...
by anav
Thu Apr 24, 2025 8:01 pm
Forum: Beginner Basics
Topic: Primary gateway with static ip address not activating
Replies: 24
Views: 10675

Re: Primary gateway with static ip address not activating

Yes please, clean up the config, garbage is noise and noise makes it difficult to read a config OR to spot errors..........
by anav
Thu Apr 24, 2025 7:30 pm
Forum: Beginner Basics
Topic: hEX refresh/ as Switch ->Pros & Cons?
Replies: 37
Views: 3487

Re: hEX refresh/ as Switch ->Pros & Cons?

Any hex device makes a great little managed switch that works great in a home setting or even an office setting. If one is in a corporate setting where, for example, the same vlan spans two or more ports on the switch, to users that will be sending huge amounts of data back and forth across the swit...
by anav
Thu Apr 24, 2025 7:27 pm
Forum: General
Topic: WireGuard connectivity issue assistance
Replies: 7
Views: 922

Re: WireGuard connectivity issue assistance

Best to provide your config for review /export file=anynameyouwish (minus router serial number, any public WANIP information, keys),.\ Steps 1. Take the private key given to you and when you make an interface on the MT router, use that private key to generate a public key ( that way windscribe alrea...
by anav
Thu Apr 24, 2025 7:06 pm
Forum: General
Topic: Defeated by VLAN issue [SOLVED]
Replies: 9
Views: 1437

Re: Defeated by VLAN issue [SOLVED]

There are several options. a. connect PC requiring vlan 10 directly to the audience OR ax3 b. replace the un-managed switch with a managed switch (could even be a hex) and then send the two vlans to the new device 10,20 c. buy a second cheap unmanaged switch untagged to vlan 10 and then plug in the ...
by anav
Thu Apr 24, 2025 5:35 pm
Forum: General
Topic: Defeated by VLAN issue [SOLVED]
Replies: 9
Views: 1437

Re: Defeated by VLAN issue [SOLVED]

Please draw a network diagram because the explanation muddles devices relationship and clarity is required.
In general, the management vlan needs to go to all smart devices ( such as the audience) as smart devices should get their IP address from the managment vlan.
by anav
Thu Apr 24, 2025 5:32 pm
Forum: General
Topic: Can't re-add peer key Wireguard
Replies: 1
Views: 433

Re: Can't re-add peer key Wireguard

The information you have provided is sparse. In general on your mikrotik you generate a private key and public key ("######" ) when creating the wireguard interface and lets say create an address like 10.20.30.1/24 with listening port of 51280. The public key is for use on the peer or remo...
by anav
Thu Apr 24, 2025 5:24 pm
Forum: Beginner Basics
Topic: Primary gateway with static ip address not activating
Replies: 24
Views: 10675

Re: Primary gateway with static ip address not activating

Not sure how pppoe works but for security purposes, would remove any username passwords and any public IP address associated from your config. 1. As to the config I didnt get past your IP addressess which are wrong. You have ONE bridge, and one subnet and pool and address associated so not sure what...
by anav
Thu Apr 24, 2025 2:24 pm
Forum: Beginner Basics
Topic: Hex refresh download speed
Replies: 25
Views: 2796

Re: Hex refresh download speed

Liina, this is NOT your thread, it was started by Hiutale, suggest you start your own thread, to narrow down your specific issues and get assistance.
In other words, we are not focussed on your problems in this thread, so getting upset here, is not going to get you anywhere.
by anav
Thu Apr 24, 2025 2:19 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1421

Re: WireGuard Traffic Issue

Im saying a bridge gets one address, if you want different subnets you can cover ports A-F with the same subnet and single bridge and use different addresses for ports G,H,I NOT on the bridge, as that will cover three different subnets. OR use one bridge and assign as many vlans as you need (subnets...
by anav
Thu Apr 24, 2025 2:16 pm
Forum: General
Topic: Block youtube/facebook using Layer 7 working perfect and blocking on pc and phones
Replies: 2
Views: 753

Re: Block youtube/facebook using Layer 7 working perfect and blocking on pc and phones

Just dont use the internet, there are too many ways around non DPI solutions........
by anav
Thu Apr 24, 2025 2:21 am
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 2659

Re: AX3 as basic AP/switch

Any sailor worth their salt, knows that a vessel is used for drinking!! Drinkware, beverageware (in other words, cups, jugs and ewers) is a general term for a vessel intended to contain beverages or liquid foods for drinking or consumption. The word cup comes from Middle English cuppe, from Old Engl...
by anav
Thu Apr 24, 2025 12:56 am
Forum: Beginner Basics
Topic: Hex refresh download speed
Replies: 25
Views: 2796

Re: Hex refresh download speed

How do you get 940Mb upload??? Thats amazing........ No firewall rules??? hEX refresh can route 1430 Mbps based on the official test results when using large packet size. Interesting using large packet size has never given me accurate results but the smaller 512 byte size does match my real world r...
by anav
Thu Apr 24, 2025 12:52 am
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 2659

Re: AX3 as basic AP/switch

For MKX, just to be clear, a submarine is NOT a ship! ;-)
by anav
Wed Apr 23, 2025 7:08 pm
Forum: Beginner Basics
Topic: Load Balancing and Failover not working with my VPN connection
Replies: 4
Views: 534

Re: Load Balancing and Failover not working with my VPN connection

Also the MT config
/export file=anynameyouwish (minus router serial number, any public WANIP information, keys )
by anav
Wed Apr 23, 2025 7:07 pm
Forum: Beginner Basics
Topic: Stops Responding [SOLVED]
Replies: 10
Views: 2728

Re: Stops Responding [SOLVED]

Also I recommend taking one of the unused ports on the switch and make it an OFF BRIDGE access port, but will wait to see the config.
by anav
Wed Apr 23, 2025 4:39 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1421

Re: WireGuard Traffic Issue

Each vlan is created with interface being bridge. Each vlan gets its own dhcp server, ip pool, dhcp-server network AND!!! own IP address ( not a sniff of bridge on these subnet config lines ). The only other place vlans and bridges are mixed is /interface bridge port and /interface bridge lans.
by anav
Wed Apr 23, 2025 4:36 pm
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 2659

Re: AX3 as basic AP/switch

Same with the PHY? Functionality onboard is a subset of available options?
by anav
Wed Apr 23, 2025 3:14 pm
Forum: Beginner Basics
Topic: Hex refresh download speed
Replies: 25
Views: 2796

Re: Hex refresh download speed

How do you get 940Mb upload??? Thats amazing........ No firewall rules???
by anav
Wed Apr 23, 2025 3:08 pm
Forum: General
Topic: Wireguard issue - L009 [SOLVED]
Replies: 7
Views: 1010

Re: Wireguard issue - L009 [SOLVED]

Repost the config, when done if still having problems.
by anav
Wed Apr 23, 2025 2:26 pm
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 2659

Re: AX3 as basic AP/switch

According to AI..........In diagrams, the CPU is typically represented by a rectangular box, often colored dark grey or black. The switch chip, which facilitates communication between different parts of a network, is often shown as a similar rectangular or square box, but colored light blue, orange,...
by anav
Tue Apr 22, 2025 11:10 pm
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 2659

Re: AX3 as basic AP/switch

Concur, well stated.
Yes, if one has heavy VLAN traffic ( same vlan ) between different ports on the switch, the ax3 whether its a switch or a router will see some slow down in traffic, whereas a proper switch will not.
by anav
Tue Apr 22, 2025 9:58 pm
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 2659

Re: AX3 as basic AP/switch

I use my ax3 with vlan filtering and I see no ill effects on my LAN subnets...............
by anav
Tue Apr 22, 2025 9:56 pm
Forum: General
Topic: Wireguard issue - L009 [SOLVED]
Replies: 7
Views: 1010

Re: Wireguard issue - L009 [SOLVED]

My issue with the config is two bridges. Keep it simple, one bridge. Ditch the wrongly named one about vlan10 as you have multiple vlans on that bridge, not just 10. Move the default vlan subnet 88 to a vlan, call it vlan-default. As was pointed out you have two related discrepancies to deal with. a...
by anav
Tue Apr 22, 2025 7:10 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1421

Re: WireGuard Traffic Issue

The config is far to complex for my level of understanding, however I will say that you give away addresses like candy to kids, and as far as I understand the single bridge should not have multiple IP addresses, nor probably any single etherport............ /ip address add address=192.168.100.254/24...
by anav
Tue Apr 22, 2025 1:55 pm
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 2659

Re: AX3 as basic AP/switch

Why waste a vlan capable device when a flat unmanaged switch will do?
by anav
Mon Apr 21, 2025 7:06 pm
Forum: Beginner Basics
Topic: Port Forwarding via WireGuard Tunnel
Replies: 1
Views: 493

Re: Port Forwarding via WireGuard Tunnel

ON VPS FIX the wireguard peers TO: /interface wireguard peers add allowed-address= 192.168.254.2 , 192.168.100.0/24 interface=WG_VPS \ name=peer_WG_VPS public-key= "----" Remove the funky nat rule. /ip firewall nat add action=dst-nat chain=dstnat comment=\ "RDP-Forwarding to local Ro...
by anav
Mon Apr 21, 2025 12:28 pm
Forum: Beginner Basics
Topic: Port forwarding
Replies: 15
Views: 1555

Re: Port forwarding

So you are using a third party APP to access your feed. Have you thought about the fact that you have to forward a port on your router to everyone in the world............ I have three different types of video cameras in the house and I dont forward a single port and I also use an APP to view them. ...
by anav
Mon Apr 21, 2025 12:22 pm
Forum: General
Topic: Looking for advice Hiding my IP to show up other IP [SOLVED]
Replies: 5
Views: 2646

Re: Looking for advice Hiding my IP to show up other IP [SOLVED]

concur, as stated, your best bet is to have all the others use WAN2 and your family only use wan1.
by anav
Mon Apr 21, 2025 12:56 am
Forum: Beginner Basics
Topic: Why does this not work (very basic setup)
Replies: 11
Views: 948

Re: Why does this not work (very basic setup)

It would seem your double posting, which is verbotten.
Will follow your thread here............... viewtopic.php?t=216313
by anav
Mon Apr 21, 2025 12:54 am
Forum: Beginner Basics
Topic: Why does this not work (very basic setup)
Replies: 11
Views: 948

Re: Why does this not work (very basic setup)

Without the config, all i here is opinion of some things that may or may not be relevant, its akin to hearing blah blah blah....
Please post the config for assistance.
/export file=anynameyouwish ( minus router serial number and any public WANIP information (probably none as this is a switch)
by anav
Sun Apr 20, 2025 6:20 pm
Forum: Beginner Basics
Topic: No DNS on wlan
Replies: 1
Views: 474

Re: No DNS on wlan

You have remnants of the default config 1. From: /ip dhcp-server network add address=192.168.119.0/24 comment=defconf dns-server= 192.168.88.1 gateway=192.168.119.1 netmask=24 TO: /ip dhcp-server network add address=192.168.119.0/24 comment=defconf dns-server= 192.168.119.1 gateway=192.168.119.1 net...
by anav
Sun Apr 20, 2025 6:10 pm
Forum: Beginner Basics
Topic: Why does this not work (very basic setup)
Replies: 11
Views: 948

Re: Why does this not work (very basic setup)

Review the video and when you have something close post here for review/comments
/export file=anynameyouwish ( minus router serial number, any PUBLIC WANIP information )
by anav
Sun Apr 20, 2025 6:08 pm
Forum: Beginner Basics
Topic: Why does this not work (very basic setup)
Replies: 11
Views: 948

Re: Why does this not work (very basic setup)

The article provided and video only show one bridge. To configure the switch the best thing for you do to is take one port OFF the bridge and do all your configuring from this safe spot. Configuring OffBridge So remove ether24 from /interface bridge port Modify the following entry /ethernet set [ fi...
by anav
Sun Apr 20, 2025 2:45 pm
Forum: Beginner Basics
Topic: Port forwarding
Replies: 15
Views: 1555

Re: Port forwarding

I would revise the following: From: add action=drop chain=forward comment=\ "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \ connection-state=new in-interface-list=WAN add action=passthrough chain=forward comment=CAM dst-address=192.168.88.30 \ dst-port=80 protocol=...
by anav
Sat Apr 19, 2025 7:57 pm
Forum: Beginner Basics
Topic: Hairpin NAT with dynamic WAN IP [SOLVED]
Replies: 12
Views: 2981

Re: Hairpin NAT with dynamic WAN IP [SOLVED]

Not that I am aware of sorry.

But perhaps this explains the situation best:
..................
usetherighttool.jpg
by anav
Sat Apr 19, 2025 5:32 pm
Forum: General
Topic: Failover RouterOS v7
Replies: 9
Views: 929

Re: Failover RouterOS v7

Fixed, thanks!
by anav
Fri Apr 18, 2025 8:06 pm
Forum: Beginner Basics
Topic: Question VLAN Setup [SOLVED]
Replies: 12
Views: 2951

Re: Question VLAN Setup [SOLVED]

No I said, a. if you only have one vlan per port then you dont really need vlans. b. also since this is a lab environment then you dont need any security. c. if you are trying to practice for real world setups then it would be nutso to have to manage 10 or more devices (config them) using all the di...
by anav
Fri Apr 18, 2025 6:02 pm
Forum: Beginner Basics
Topic: Question VLAN Setup [SOLVED]
Replies: 12
Views: 2951

Re: Question VLAN Setup [SOLVED]

Why do you want vlans? There is no need, there is never a duplication of any subnet over a single port? In reality, every device would be on a managed vlan, so every device would have at least two vlans coming in a trunk port. Suggest you look at basic videos and read this article. https://forum.mik...
by anav
Fri Apr 18, 2025 5:00 pm
Forum: Forwarding Protocols
Topic: Dual wan connexion from winbox
Replies: 3
Views: 4150

Re: Dual wan connexion from winbox

The problem is that your requirement is not clearly stated. Do you mean, I wish to access my Router while at a remote location? OR Do you mean I wish to access my router while on the LAN of ISP1 modem/router or on the LAN of the ISP2 modem/router. (hint they are not strictly modems if they get a sta...
by anav
Fri Apr 18, 2025 3:19 pm
Forum: Beginner Basics
Topic: Bridging WAN to VLAN [SOLVED]
Replies: 9
Views: 3095

Re: Bridging WAN to VLAN [SOLVED]

I dont understand the first post.
Why cannot you simply make the devices available via port forwarding.
How can you expose devices to the internet if you only have one WANIP address, dont you need a block of public IP addresses??
by anav
Fri Apr 18, 2025 3:04 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1421

Re: WireGuard Traffic Issue

It should work so there may be something else in your config interfering.
/export file=anynameyouwish ( minus router serial number, any public WANIP information, keys )
by anav
Fri Apr 18, 2025 2:15 pm
Forum: Beginner Basics
Topic: Help with hAP ax lite access point [SOLVED]
Replies: 8
Views: 2486

Re: Help with hAP ax lite access point [SOLVED]

It has two chains, and thus thought the default would include wifi1 andw ifi2 so at least the op could provide coverage for two freqs.....oh well. Nope. Only 2.4Ghz radio so only wifi1. 2 chains does not mean 2 radios. Reminds me to ask you, why do they even state the number of chains, its like use...
by anav
Fri Apr 18, 2025 2:11 pm
Forum: Beginner Basics
Topic: Hairpin NAT with dynamic WAN IP [SOLVED]
Replies: 12
Views: 2981

Re: Hairpin NAT with dynamic WAN IP [SOLVED]

Mikrotik provides its own domain URL in IP CLOUD use that.........
https://help.mikrotik.com/docs/spaces/R ... Cloud-DDNS
by anav
Fri Apr 18, 2025 2:05 pm
Forum: General
Topic: Reset RouterOS without losing remote access (Winbox/SSH)
Replies: 21
Views: 1641

Re: Reset RouterOS without losing remote access (Winbox/SSH)

How can you eat an apple but keep it intact ?

You can not.
I disagree, a whale can swallow it whole....... and then regurgitate it back whole.
by anav
Thu Apr 17, 2025 11:20 pm
Forum: General
Topic: Failover RouterOS v7
Replies: 9
Views: 929

Re: Failover RouterOS v7

VERSION7 instituted some changes mostly to the way of using scope and target scope.......... Nested using a faux address for two canary selections. /ip route add dst-address=0.0.0.0/0 gateway=10.10.10.10 scope=10 target-scope=14 add distance=2 check-gateway=ping dst-address=10.10.10.10/32 gateway=9....
by anav
Thu Apr 17, 2025 10:32 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1421

Re: WireGuard Traffic Issue

If WAN1 is your primary WAN ( and WAN2 is rarely used ), then it stands to reason that all your wireguard users have WAN1 as their endpoint address. To test if the router will switch to WAN2 automatically, due to distance in route difference, please do not SWAP distances. To test simply unplug inter...
by anav
Thu Apr 17, 2025 5:20 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1421

Re: WireGuard Traffic Issue

Your testing method may be flawed.
If you swap distances on the WANs, do you also change the endoint address to WAN2 for the device??
You need to NOT change the WAN distance, simply unplug the cable from wan1 into the router.
by anav
Thu Apr 17, 2025 1:35 pm
Forum: General
Topic: How to use Mikrotik router as a “switch”?
Replies: 13
Views: 48014

Re: How to use Mikrotik router as a “switch”?

What kind of switch, like an unmanaged switch with one flat network OR switch with multiple vlans?
by anav
Thu Apr 17, 2025 1:32 pm
Forum: General
Topic: Firewall to block Facebook but allow WhatsApp?
Replies: 8
Views: 1048

Re: Firewall to block Facebook but allow WhatsApp?

Without a router with (DPI) and like services that looks at encrypted packets there is no foolproof way...........
by anav
Thu Apr 17, 2025 1:28 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1421

Re: WireGuard Traffic Issue

In a dual wan scenario where WAN2 is secondary lets say by distance and your current setup is for users to connect to WAN1 address, when WAN1 fails ( is no longer available ), the router will move wireguard traffic to WAN2 after a short delay. I havent tested that lately but it used to be the case. ...
by anav
Wed Apr 16, 2025 11:22 pm
Forum: General
Topic: Firewall to block Facebook but allow WhatsApp?
Replies: 8
Views: 1048

Re: Firewall to block Facebook but allow WhatsApp?

How do the users get their access,,,,,,,,, if by WIFI, then turn off access point or WLANs at a certain time.
by anav
Wed Apr 16, 2025 10:42 pm
Forum: General
Topic: 2kbps DNS-Resolution Spam for cloud.mikrotik.com from detect-interface feature
Replies: 9
Views: 963

Re: 2kbps DNS-Resolution Spam for cloud.mikrotik.com from detect-interface feature

I would add mkx, an admin using MT equipment would probably be trained to some degree to use the equipment in an enterprise networking position. I wonder if any of the certs cover detect internet. OR,
to have at least read viewtopic.php?t=215004 ;-) Item 5
by anav
Wed Apr 16, 2025 10:41 pm
Forum: General
Topic: Why does ROS allow the creation of a route table with the same name?
Replies: 8
Views: 780

Re: Why does ROS allow the creation of a route table with the same name?

Perhaps they never coded to detect and warn about duplicates.....??
by anav
Wed Apr 16, 2025 8:26 pm
Forum: General
Topic: How many VLANs?
Replies: 18
Views: 1195

Re: How many VLANs?

I have heard ubiquiti is so designed but never have read TPLink Aps were particularly useful in dense environments.......
by anav
Wed Apr 16, 2025 8:00 pm
Forum: General
Topic: Allow for some devices, Internet access for 1 hour each day [SOLVED]
Replies: 18
Views: 2963

Re: Allow for some devices, Internet access for 1 hour each day [SOLVED]

Concur unless you set DHCP static lease to phones with randomizer turned off and do not let any other leases occur
by anav
Wed Apr 16, 2025 7:44 pm
Forum: Beginner Basics
Topic: What is the purpose of client-dns setting in wireguard
Replies: 6
Views: 2088

Re: What is the purpose of client-dns setting in wireguard

Good question, the answer is there is no certainty in the ways of MT programmers regarding wireguard. There is lots wrong with the implementation or GUI or display of information to the admin in RoS regarding wireguard. Typically we dont change our local DNS based on wireguard settings, we simply us...
by anav
Wed Apr 16, 2025 7:35 pm
Forum: Beginner Basics
Topic: Router configuration - basic
Replies: 5
Views: 799

Re: Router configuration - basic

I hear wifi coming and CRS326 and assuming this router will replace the ASUS. Thus I am assuming you will have more than just one flat network and are planning on vlans? [ if not, send me your CRS326 and I will send you my un-managed switch ;-) ] Also there is nothing secret about your private IP ad...
by anav
Wed Apr 16, 2025 3:17 pm
Forum: General
Topic: How many VLANs?
Replies: 18
Views: 1195

Re: How many VLANs?

So you want to get into an argument. Nope … stop using MikroTik wireless and all your limiting factors go away. Yes multiple AP’s provide the required balance and improved performance … Ubiquiti, TP-Link dedicated Access points provide exceptional value for installations thatn require special purpo...
by anav
Wed Apr 16, 2025 2:33 pm
Forum: General
Topic: How many VLANs?
Replies: 18
Views: 1195

Re: How many VLANs?

So you want to get into an argument. Then tell me how many WLANs can a single ax3 PRACTICALLY provide.................. ( and remember your the one jumping up and down about network performance !!! ) NOT as many vlans as I have in my house thats for sure............ So one has to use multiple APs to...
by anav
Wed Apr 16, 2025 2:24 pm
Forum: Beginner Basics
Topic: Overview of WireGuard packet flow
Replies: 3
Views: 739

Re: Overview of WireGuard packet flow

Yes, one needs the handshake negotiation to take place via the input chain and then manage traffic exiting and entering the tunnel from the LAN (forward chain)
by anav
Wed Apr 16, 2025 2:16 pm
Forum: General
Topic: How many VLANs?
Replies: 18
Views: 1195

Re: How many VLANs?

First, No one is going to hold your hand and tell you what is the optimal number of vlans. Second: The creation of vlans is to segment your network into logical manageable entities/functions and thats a personal choice. Some may prefer lumping all IOT devices into one vlan, and some might separate t...
by anav
Wed Apr 16, 2025 1:58 pm
Forum: General
Topic: How many VLANs?
Replies: 18
Views: 1195

Re: How many VLANs?

Its the only perspective! Trying to reduce the number of vlans, is not a valid requirement, its convenience at best. You create the vlans based on the functions your network will be performing. This is both logical and practical and easy to manage. One of the valid overall requirements for a network...
by anav
Wed Apr 16, 2025 1:48 pm
Forum: General
Topic: How many VLANs?
Replies: 18
Views: 1195

Re: How many VLANs?

One should view it as, if a device was compromised, what can it then attack........................... simple question. There is no RIGHT answer, its personal , and what level of comfort you have exposing devices to other devices be they IOT, media, voip, laptops, smartphones etc....... . PS Erlinde...
by anav
Tue Apr 15, 2025 9:54 pm
Forum: Beginner Basics
Topic: Suggestions for hAP ac2 configuration
Replies: 10
Views: 993

Re: Suggestions for hAP ac2 configuration

Hex S refresh router with two Access points, very few access points handle 70 clients very well.
If stuck on one AP, look at High density access point brands look at wifi6 as a minimum ubiquiti, RUKUS etc........
by anav
Tue Apr 15, 2025 8:08 pm
Forum: Beginner Basics
Topic: Doubt about bridges
Replies: 1
Views: 366

Re: Doubt about bridges

use firewall rule to allow it
by anav
Tue Apr 15, 2025 8:05 pm
Forum: Beginner Basics
Topic: Help with hAP ax lite access point [SOLVED]
Replies: 8
Views: 2486

Re: Help with hAP ax lite access point [SOLVED]

It has two chains, and thus thought the default would include wifi1 andw ifi2 so at least the op could provide coverage for two freqs.....oh well.
by anav
Tue Apr 15, 2025 1:56 pm
Forum: Beginner Basics
Topic: Help with hAP ax lite access point [SOLVED]
Replies: 8
Views: 2486

Re: Help with hAP ax lite access point [SOLVED]

Assuming one flat network........... First create a safe place to config the router, an off bridge port ( remove from /interface bridge ports) and then you will be able to change the main IP structure of the haplite without issue to that of the upstream router without locking yourself out. After ens...
by anav
Tue Apr 15, 2025 1:44 pm
Forum: Beginner Basics
Topic: Masquerading errors but not sure how to fix.
Replies: 3
Views: 766

Re: Masquerading errors but not sure how to fix.

why did you mess with default firewall rules, and then mix up chains etc...... Seems like you are hosting RDP.........its not the best security practice anymore hint........ Also you seem to think its okay to have your winbox port (still in default) to be accessible over the WWW and not via VPN. I h...
by anav
Tue Apr 15, 2025 1:37 pm
Forum: General
Topic: 2kbps DNS-Resolution Spam for cloud.mikrotik.com from detect-interface feature
Replies: 9
Views: 963

Re: 2kbps DNS-Resolution Spam for cloud.mikrotik.com from detect-interface feature

For me the question is, to default ON or disabled. Seeing as the majority of users end up turning this OFF and it does create traffic probably unbeknownst to most, it should really be defaulted to disabled. The associated MT doc page is perhaps vague on its purpose and seems to indicate it is OFF by...
by anav
Mon Apr 14, 2025 10:11 pm
Forum: General
Topic: hAP AC2 vs. AX2...
Replies: 20
Views: 2001

Re: hAP AC2 vs. AX2...

No idea where the parts for MT devices are made or where assembled for that matter.
Concur, eap245 was great, and yes omada sucks, all good when manually configured.
Most people stream video these days!!
by anav
Mon Apr 14, 2025 9:50 pm
Forum: General
Topic: Erratic Behavior of Winbox ROS 7
Replies: 1
Views: 364

Re: Erratic Behavior of Winbox ROS 7

Yes, using winbox 3, typically it happens 1, 2 or 3 times in a row but never more.
I resolve by closing all the open windows, and that seems to help.
No such issues with winbox4
by anav
Mon Apr 14, 2025 9:49 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 2295

Re: Using CRS326 as a switch

Smells like MT testosterone in here! ;-PP
by anav
Mon Apr 14, 2025 8:20 pm
Forum: Beginner Basics
Topic: Forwarding port behind NAT and FW to router
Replies: 3
Views: 468

Re: Forwarding port behind NAT and FW to router

Please state MT model.. A switch is not a router?? Although RoS lets one do so, it most cases its a bad idea.
by anav
Mon Apr 14, 2025 8:17 pm
Forum: Beginner Basics
Topic: Question about unknown IP address trying to connect though capsman
Replies: 11
Views: 1055

Re: Question about unknown IP address trying to connect though capsman

Another nail in the coffin for Capsman if you ask me, if the directions are so vague or out there that this happens, its not worth its weight in chicken feathers or whatever......... argg disgusted...... https://help.mikrotik.com/docs/spaces/ROS/pages/7962638/CAPsMAN Nary a peep I could find about c...
by anav
Mon Apr 14, 2025 6:08 pm
Forum: Beginner Basics
Topic: Quick setup without using 192.168.88.1
Replies: 2
Views: 502

Re: Quick setup without using 192.168.88.1

What I suggest is you configure the router from a safe spot to make subnet changes and later if you use vlans. Take etherX like ether5 OFF the bridge in /interface bridge ports So it looks like /interface ethernet set [ find default-name=ether5 ] name=OffBridge5 /ip address add address=192.168.77.1/...
by anav
Mon Apr 14, 2025 5:39 pm
Forum: Beginner Basics
Topic: PPPOE with static IP
Replies: 20
Views: 1856

Re: PPPOE with static IP

1. FROM /interface list add name=WAN TO /interface list add name=WAN add name=LAN 2. FROM /interface list member add disabled=yes interface=pppoe-out1 list=WAN add disabled=yes interface=ether1 list=WAN TO /interface list member add disabled= NO interface=pppoe-out1 list=WAN add disabled= NO interfa...
by anav
Mon Apr 14, 2025 2:52 pm
Forum: Beginner Basics
Topic: Problem with internet access on router
Replies: 6
Views: 977

Re: Problem with internet access on router

rplant ur killen me, whats your address will send you the game whackamole.
Please ask for config LOL
/export file=anynameyouwish ( minus router serial number, any public WANIP information, vpn keys etc.)(
by anav
Mon Apr 14, 2025 2:50 pm
Forum: Beginner Basics
Topic: Overview of WireGuard packet flow
Replies: 3
Views: 739

Re: Overview of WireGuard packet flow

Conceptually speaking you only need two tunnels or two interfaces. The one for you to use your own internet while at a remote location (0.0.0.0/0) has to be on its own Wireguard interface. Also, consider the traffic coming out of the tunnel and hitting your router, being subject to firewall rules as...
by anav
Mon Apr 14, 2025 2:37 pm
Forum: Beginner Basics
Topic: Question about unknown IP address trying to connect though capsman
Replies: 11
Views: 1055

Re: Question about unknown IP address trying to connect though capsman

Danger Danger: Its amazing your ISP has not blocked you yet. WELL you attract flies with honey and you lay a big fricken goose egg here add action=log chain=input connection-state=new dst-port=53 log-prefix="TCP 53" protocol=tcp Inviting the whole world to use your router for DNS. I would...
by anav
Mon Apr 14, 2025 2:17 pm
Forum: General
Topic: hAP AC2 vs. AX2...
Replies: 20
Views: 2001

Re: hAP AC2 vs. AX2...

By the way, I hope you do know about controversy around TP-Link... I see you have been recommending them here and there. Yes, tp link routers, not access points and in reality, CISCO had issue in the past in the same vein, as guess what most devices are made in China so, do you think parts can get ...
by anav
Mon Apr 14, 2025 2:05 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 2295

Re: Using CRS326 as a switch

I wouldnt take forum responses personally, they are of no consequence. People here are free to speak their mind, sometimes its refreshing and eye opening and humbling. I make posts based on what I know, and if someone better comes along, who actually knows their stuff, I am all the better for it. (E...
by anav
Sun Apr 13, 2025 11:18 pm
Forum: Beginner Basics
Topic: Question about unknown IP address trying to connect though capsman
Replies: 11
Views: 1055

Re: Question about unknown IP address trying to connect though capsman

Bad actors/bots are constantly hammering ALL routers, nature of the beast. There is no point logging it and nothing you can do.
However it would not hurt to have your setup/config reviewed to ensure its not getting special attention for some reason.
by anav
Sun Apr 13, 2025 10:54 pm
Forum: Wireless Networking
Topic: chateau pro ax
Replies: 3
Views: 598

Re: chateau pro ax

The what, I cannot find any such model.
I see the Chateau 5G AX??

There will be no appreciable difference.
Suggest considering TPlink and Zyxel wifi 7 products.
OR
add another MT product in the home for better coverage capax for example.
by anav
Sun Apr 13, 2025 10:44 pm
Forum: Beginner Basics
Topic: Question VLAN Setup [SOLVED]
Replies: 12
Views: 2951

Re: Question VLAN Setup [SOLVED]

Are you stating that there is no port with more than one vlan going through it???
At a minimum there should be two vlans per port if all are trunk ports going to smart devices, one being the management vlan which all smart devices should get their IP address from.
by anav
Sun Apr 13, 2025 10:42 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 2295

Re: Using CRS326 as a switch

by anav
Sun Apr 13, 2025 5:34 pm
Forum: General
Topic: Request for WireGuard Peers, configurable Client ListenPort and AllowedIPs
Replies: 44
Views: 5090

Re: Request for WireGuard Peers, configurable Client ListenPort and AllowedIPs

Doing the exercise was very helpful to determine form follows function approach and to realize that really what is going on is three different requirements based on how wireguard keys are handled. a. Both ends of a connection manually make and trade public keys (standard wireguard construction) b. A...
by anav
Sun Apr 13, 2025 5:26 pm
Forum: General
Topic: Netwatch/Ping Problem with Recursive Route
Replies: 3
Views: 2048

Re: Netwatch/Ping Problem with Recursive Route

Correct interrelated moving parts, and its unfair to ask for definitive specific answers to vaguish questions without the context and information required.
by anav
Sun Apr 13, 2025 5:24 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 2295

Re: Using CRS326 as a switch

You know I am always truly grateful for the enormous amount of help you have provided to me, but my limited capabilities are focused here, in this thread, on understanding the config items that distinguish router versus switch use in a CRS. Sorry, you dont control the narrative in a public space LO...
by anav
Sun Apr 13, 2025 5:22 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 2295

Re: Using CRS326 as a switch

Routers --> both bridge/switch and route have multiple IP addresses
Switches --> only bridge/switch have single IP address (for management of switch)
RoS Unique (confuses some) --> determines function by Software not by hardware.
by anav
Sun Apr 13, 2025 5:17 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 2295

Re: Using CRS326 as a switch

The CRS should be written as Cloud Router Switch . That is indeed the problem, and by the way, you should note that ONLY one switch in the entire lineup uses the terms Cloud Router Switch and that is the CRS317 ( MT informed to remove). There are couple more that use the term Cloud Switch but most ...
by anav
Sun Apr 13, 2025 1:50 pm
Forum: General
Topic: Request for WireGuard Peers, configurable Client ListenPort and AllowedIPs
Replies: 44
Views: 5090

Re: Request for WireGuard Peers, configurable Client ListenPort and AllowedIPs

Hi Mozerd, I attempted to rejig the Wireguard GUI in winbox 4 and supplied the advice to MT as you can see here. https://forum.mikrotik.com/viewtopic.php?t=215684: The response I got was not enthusiastic as the peer page was too busy etc. So I resubmitted a simplified approach. SEE post #7 for simpl...
by anav
Sun Apr 13, 2025 1:46 pm
Forum: Beginner Basics
Topic: Question VLAN Setup [SOLVED]
Replies: 12
Views: 2951

Re: Question VLAN Setup [SOLVED]

A good network diagram will help planning as well....
by anav
Sun Apr 13, 2025 1:35 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 2295

Re: Using CRS326 as a switch

The example provided is a bit confusing. - why include ports 5 through spf-sfpplus2 if not relevant (not being used) - then I see sfp-sfpplus1 is being used but no indication its a trunk port ( frame types or comment missing ) which is inconsistent from the other entries........ - why are you missin...
by anav
Sun Apr 13, 2025 1:20 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 2295

Re: Using CRS326 as a switch

https://www.spiceworks.com/tech/networking/articles/network-switch-vs-router/ Clues to you are routing. -DHCP -WAN and LAN -NAT -all subnets have an address -need firewall rules (layer3) Switch..... Single Ip address provided to switch setup is primarily about vlan traffic only management or trusted...
by anav
Sun Apr 13, 2025 1:07 pm
Forum: Beginner Basics
Topic: likely hitting software-based routing limits [SOLVED]
Replies: 23
Views: 4327

Re: likely hitting software-based routing limits [SOLVED]

I would go a step further, why are people making excuses for a chap thats willing to spend $600 without research and where the nomenclature NEVER stated cloud router. Go to the switch section of mikrotik, pull up the applicable switch page and I bet you wont find mention of cloud router!!!. Would as...
by anav
Sun Apr 13, 2025 2:54 am
Forum: Beginner Basics
Topic: Port forwarding
Replies: 15
Views: 1555

Re: Port forwarding

Since you didnt bother to post config, Im outta here good luck. Others have more patience than I.
  • 1
  • 2
  • 3
  • 4
  • 5
  • 80