Community discussions

MikroTik App

Search found 9203 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 31
by anav
Thu Dec 02, 2021 5:51 am
Forum: Beginner Basics
Topic: Why not a definitive solution to block Youtube?
Replies: 7
Views: 5238

Re: Why not a definitive solution to block Youtube?

By removing internet privileges if they break the rules..........
by anav
Wed Dec 01, 2021 11:30 pm
Forum: Wireless Networking
Topic: WIFI 6 Roadmap
Replies: 112
Views: 73911

Re: WIFI 6 Roadmap

Man I missed the boat, this is netgear 6E
Includes 6ghz network. Insane!! (like the price)
Nothing else on the market like this that I know about.
But dont see a wall/ceiling version??
by anav
Wed Dec 01, 2021 10:55 pm
Forum: Wireless Networking
Topic: WIFI 6 Roadmap
Replies: 112
Views: 73911

Re: WIFI 6 Roadmap

Hi Tom, If you have room in your cough cough 'small budget" can you get a TP link 660HD and the new Ubiquiti WIFI U6 Pro (both wifi 6 models) and compare to the Netgear of which you speak. Just single Access Point performance. The Ubiquiti at $180 Cdn seems to be very very competitively priced ...
by anav
Wed Dec 01, 2021 10:46 pm
Forum: General
Topic: Using Let's Encrypt for SSTP
Replies: 13
Views: 665

Re: Using Let's Encrypt for SSTP

Hi Sob, You just verified a simple fact for me. Wireguard rocks every other VPN needing client certificate management up the ying yang sucks and ISPAPP.co which does not rely upon open ports or certificates (https connections only) is very appealing as an alternate remote access to config the MT dev...
by anav
Wed Dec 01, 2021 10:34 pm
Forum: General
Topic: Confused about DHCP server
Replies: 14
Views: 512

Re: Confused about DHCP server

I dont think its possible or wise to attach your VPN connections to bridges. Simply make the firewall rules you need to allow connectivity from VPN access to LAN subnets and vice versa etc...... I think of VPNs a faux LANs, they are not real LANs but are parallel to them. A VPN is a tunnel that with...
by anav
Wed Dec 01, 2021 10:29 pm
Forum: General
Topic: [HELP] Need help with bandwidth
Replies: 2
Views: 104

Re: [HELP] Need help with bandwidth

Check out queues, that is how MT does this.
https://help.mikrotik.com/docs/display/ROS/Queues
by anav
Wed Dec 01, 2021 10:29 pm
Forum: General
Topic: [HELP] Need help with bandwidth
Replies: 2
Views: 104

Re: [HELP] Need help with bandwidth

Check out queues, that is how MT does this.
by anav
Wed Dec 01, 2021 10:27 pm
Forum: General
Topic: drop ports from WAN side
Replies: 3
Views: 143

Re: drop ports from WAN side

Please post config if you want assistance.......
/export hide-sensitive file=anynameyouwish
by anav
Wed Dec 01, 2021 10:23 pm
Forum: General
Topic: Has a RB4011 some hardware/sofware bugs now?
Replies: 5
Views: 283

Re: Has a RB4011 some hardware/sofware bugs now?

The last person complaining about RB4011 freezing is running ROS 6.47.10 ... which is rather old. While it's generally fine, very stable release, it's old for RB4011, which is by itself not that old and AFAIK some work had been done regarding stability in more recent ROS versions. 6.47.10 is a prev...
by anav
Wed Dec 01, 2021 10:21 pm
Forum: General
Topic: dhcp client get`s wrong dns
Replies: 21
Views: 615

Re: dhcp client get`s wrong dns

This is all very confusing. There are two possibilities. Either your ISP is dynamic and they set everything automatically and all you need to do is set IP DHCP Client and tick both boxes for use ISP DNS and Create Route Automatically OR They have provided you with the settings to use. Which is true?...
by anav
Wed Dec 01, 2021 10:13 pm
Forum: Beginner Basics
Topic: Cannot connect to guest wifi (VLAN) on cAP ac [SOLVED]
Replies: 2
Views: 83

Re: Cannot connect to guest wifi (VLAN) on cAP ac [SOLVED]

Sure, how many vlans are involved? I see home wifi and guest wifi is the trusted vlan or managment vlan the same as the home wifi. Clue the Access point should have an IP address on the subnet of the trusted vlan. I will assume vlan 2 is the trusted vlan. (1) Missing vlans. You need two identify all...
by anav
Wed Dec 01, 2021 9:48 pm
Forum: Beginner Basics
Topic: Firewall drop rule not working
Replies: 3
Views: 164

Re: Firewall drop rule not working

Why is ether4 on the Bridge? Should be removed. /interface bridge port add bridge=bridge comment=defconf interface=ether2 add bridge=bridge comment=defconf interface=ether3 add bridge=bridge comment=defconf interface=ether4 To help decide the above......what is attached to ether4? If you dont need t...
by anav
Wed Dec 01, 2021 9:40 pm
Forum: Beginner Basics
Topic: How would you go about this - 2 separate nets 1 router
Replies: 1
Views: 81

Re: How would you go about this - 2 separate nets 1 router

Very feasible, the only question I have is why are the two VLANS 'open' to each other.
Why not just have one LAN then?
by anav
Wed Dec 01, 2021 9:36 pm
Forum: Beginner Basics
Topic: how to setup a correct firewall rules when the Mikrotik is behind the ISP modem
Replies: 3
Views: 155

Re: how to setup a correct firewall rules when the Mikrotik is behind the ISP modem

Well for starters, its cleaner and less prone to errors if you group the chains together .......... That way you can see the order within a chain more readily etc.. rules out of order Irules need modifying rules to remove rules missing /ip firewall filter {input chain} add action=accept chain=input ...
by anav
Wed Dec 01, 2021 2:00 pm
Forum: General
Topic: Has a RB4011 some hardware/sofware bugs now?
Replies: 5
Views: 283

Re: Has a RB4011 some hardware/sofware bugs now?

Recommendation to buy any appliance should be based on your requirements. There is nothing wrong iwth the RB4011 but I would invest in the RB5009 a newer product and around the same price point........ better value for money.
by anav
Wed Dec 01, 2021 1:49 pm
Forum: Beginner Basics
Topic: Firewall drop rule not working
Replies: 3
Views: 164

Re: Firewall drop rule not working

If you dont know what the problem is, why do you think only showing us part of the config will help? Please post your config /export hide-sensitive file=anynameyouwish Seeing as you only wanted one port the rule could be refined to add action=drop chain=forward dst-address=192.168.0.0/24 src-address...
by anav
Tue Nov 30, 2021 10:40 pm
Forum: Beginner Basics
Topic: SM Fiber Modules
Replies: 4
Views: 215

Re: SM Fiber Modules

Hi there, then explain to me how the product I noted at the top [ XS+2733LC15D ] can DO ALL THREE!! 1.25/10/25.
In fact how come it calls them SFP+ transceivers and yet it can do 25gigs, which is SFP28 standard??

Call me confused!!
by anav
Tue Nov 30, 2021 7:38 pm
Forum: General
Topic: Using two routers
Replies: 8
Views: 381

Re: Using two routers

Ahh okay, that makes sense!!
by anav
Tue Nov 30, 2021 7:21 pm
Forum: Beginner Basics
Topic: SM Fiber Modules
Replies: 4
Views: 215

Re: SM Fiber Modules

Well seeing the plethora of 25Gig managed switches, I dont think I will be buying the more expensive SPF28 modules and will stick to those that can handle both SFP and SFP+
Looking for a Bidi Module for 1.25 and 10gig (that will do SFP and SFP+)
Guess what they dont seem to exist? :-(
by anav
Tue Nov 30, 2021 5:52 pm
Forum: Wireless Networking
Topic: cAP vs cAP XL
Replies: 16
Views: 989

Re: cAP vs cAP XL

The Ubiquiti WIFI U6 Pro is cheaper than the TPLINK eap660HD by about $80 and thus may be excellent value IF, IF it can be configured in a stand alone mode.
by anav
Tue Nov 30, 2021 5:41 pm
Forum: Beginner Basics
Topic: SM Fiber Modules
Replies: 4
Views: 215

SM Fiber Modules

Specifically this one, seems to be super human! XS+2733LC15D https://mikrotik.com/product/xs_2733lc15d Do I have this right, its a BIdi SM module that can negotiate speeds including 1.25 / 10 / 25 up to 15K.......... Funny distance as most vendors will state, 10, 20, 40K as standard distances. I won...
by anav
Tue Nov 30, 2021 5:17 pm
Forum: General
Topic: Confused about DHCP server
Replies: 14
Views: 512

Re: Confused about DHCP server

To be honest (and afterwards always easy to say): I was already wondering about that one as well. WAN and LAN but what about <nothing> ? But I do not think this is related to the DHCP problem. Is it ? With MT one never knows what is or isnt connected,.........well Sindy and Sob know, but I dont. :-)
by anav
Tue Nov 30, 2021 4:26 pm
Forum: General
Topic: Using Let's Encrypt for SSTP
Replies: 13
Views: 665

Re: Using Let's Encrypt for SSTP

I ask the question mainly because in the SSTP examples I find, verify (server/client) certificates is never checked off, so was wondering is that because the certificates were produced on the MT (self signed). and thus verification is not required? What is the difference between a self-signed MT cer...
by anav
Tue Nov 30, 2021 4:24 pm
Forum: General
Topic: Using two routers
Replies: 8
Views: 381

Re: Using two routers

Can you please post the config of the Mikrotik device
(/export hide-sensitive file=anynameyouwish)
Unable??---> I don't know the login for either of them!!!
by anav
Tue Nov 30, 2021 4:23 pm
Forum: General
Topic: Confused about DHCP server
Replies: 14
Views: 512

Re: Confused about DHCP server

(1) Your are missing one thing....... Maybe? /interface list member add interface=ether1 list=WAN add interface=bridgeNet1 list=LAN add interface=bridgeNet2 list=LAN ???? (2) Confused about another part of the setup....... add address=172.16.200.254/24 interface=bridgeNet1 network=172.16.200.0 add a...
by anav
Tue Nov 30, 2021 4:09 pm
Forum: Beginner Basics
Topic: Travel VPN router - Wireless both WAN and LAN
Replies: 10
Views: 437

Re: Travel VPN router - Wireless both WAN and LAN

mAPLite is a very good Travel-Router! I have 3 of them and one is always in my Laptop-Bag It's Compact and you can power it with your laptop or Power-Bank, everyone should have one =) I do a lot of Job-Hopping... And realised most company's have a PoE-Network So my Main Travel-Router at the moment ...
by anav
Tue Nov 30, 2021 4:07 pm
Forum: Beginner Basics
Topic: Winboxing towards a Mikrotik behind NAT [SOLVED]
Replies: 14
Views: 518

Re: Winboxing towards a Mikrotik behind NAT [SOLVED]

Well if you do get hacked and held ransom for lets say $50,000 just send the bill to Sob and if he gives you any trouble I know some really good lawyers. ;-P
by anav
Tue Nov 30, 2021 12:50 am
Forum: General
Topic: Using Let's Encrypt for SSTP
Replies: 13
Views: 665

Re: Using Let's Encrypt for SSTP

Can one use lets encrypt, assuming this is simply a certificate maker, for use between two MIkrotik routers ??
by anav
Mon Nov 29, 2021 10:04 pm
Forum: Beginner Basics
Topic: Winboxing towards a Mikrotik behind NAT [SOLVED]
Replies: 14
Views: 518

Re: Winboxing towards a Mikrotik behind NAT [SOLVED]

Dont open up winbox to the internet is clear and simple advice in order to configure the router. Cant say it any more plainly. The answer was already provided so not sure why SOB stated it again, other than to note that the default port for winbox is 8291................. seems like he wanted to pil...
by anav
Mon Nov 29, 2021 9:57 pm
Forum: General
Topic: RDP connencton on a specific WAN
Replies: 3
Views: 126

Re: RDP connencton on a specific WAN

I assumed outgoing from the LAN as he wants the router to ensure a specific WANIP is used.
If it was incoming he wouldnt need to do so as the incoming would be from external users in which case he would tell those external users to use a specific WANIP or domain name!
But agree its not clear!!!
by anav
Mon Nov 29, 2021 9:50 pm
Forum: General
Topic: How to access Mikrotik in Bridge mode with Netbox?
Replies: 13
Views: 595

Re: How to access Mikrotik in Bridge mode with Netbox?

Okay this is dirt simple............. Going back to your config and requirements. ACCESS POINT ONLY. Reset the Access point to default and select wisp mode for example TOP LEFT of quickset menu......... the only setting to touch in quickset (vice See use of ether2 ( removed from bridge and what I us...
by anav
Mon Nov 29, 2021 3:54 pm
Forum: General
Topic: RDP connencton on a specific WAN
Replies: 3
Views: 126

Re: RDP connencton on a specific WAN

How many users on the LAN are using RDP?
by anav
Mon Nov 29, 2021 3:35 pm
Forum: Beginner Basics
Topic: Winboxing towards a Mikrotik behind NAT [SOLVED]
Replies: 14
Views: 518

Re: Winboxing towards a Mikrotik behind NAT [SOLVED]

This sounds like you want to be able to configure or reach the winbox remotely. The way to do this is not by open ports to the router, that is a huge security problem. What you should be asking is "How do I securely manage the MT device remotely that is not the primary router but is acting as a...
by anav
Mon Nov 29, 2021 3:25 pm
Forum: Beginner Basics
Topic: Super Beginnery
Replies: 1
Views: 82

Re: Super Beginnery

What is the purpose of the connectivity (use cases in detail will help resolve equipment and configuration). In other words description of what users should be able to do from both ends........without mentioning the configuration.
by anav
Mon Nov 29, 2021 3:16 pm
Forum: Beginner Basics
Topic: subnets
Replies: 11
Views: 593

Re: subnets

Sorry if you are connected to the internet without any rules I will not help further.
The default firewall rules are safe and do not stop any connectivity (do not cause issuesa) and by removing them you have no security.
by anav
Sun Nov 28, 2021 6:07 pm
Forum: Beginner Basics
Topic: subnets
Replies: 11
Views: 593

Re: subnets

Okay so the switch is also a router and you are using bridges to dish subnets to sets of ports vice using VLANs. Four bridges Four pools Four dhcp servers. so far so good. (1) Why is bridge test NOT part of the LAN interface group?? (2) if this is acting as a router why dont you have any firewall ru...
by anav
Sun Nov 28, 2021 3:34 am
Forum: General
Topic: [Leaked Video] CCR2116-12G-4S+ with RouterOS v7 for processing BGP tables in 30s
Replies: 29
Views: 2368

Re: [LEAKED] CCR2116-12G-4S+ with RouterOS v7 for processing BGP tables in 30s

Do you have a better alternative at that price point? Seems to me this is exactly what many people are looking for when managing multiple devices (especially WISPs) Seems like people here want open ports on their device......... really???? Quick to cast dispersion I see very little debate about the ...
by anav
Sat Nov 27, 2021 11:22 pm
Forum: Beginner Basics
Topic: Load balancing - slow loading of websites and more [SOLVED]
Replies: 2
Views: 281

Re: Load balancing - slow loading of websites and more [SOLVED]

Your mangle rules seem a tad off..... note one set of the rules needs to move (from spot 2 to spot 5) (1 should be 1) /ip firewall mangle add action=accept chain=prerouting dst-address= 10.0.0.0/24 i n-interface=\ bridge1 add action=accept chain=prerouting dst-address= 100.64.0.0/10 in-interface=\ b...
by anav
Sat Nov 27, 2021 3:48 pm
Forum: Beginner Basics
Topic: Correct VLAN Setting between Switches
Replies: 6
Views: 409

Re: Correct VLAN Setting between Switches

As for the 260S, recommendations based on my settings: 1. Under VLAN S a. (FIRST ROW) VLANID1 is the default setting should be set to (left as) LEAVE AS IS - for all trunk ports NOT A MEMBER - for all access ports b. (OTHER ROWS) all other vlans Set to LEAVE AS IS - for all trunk ports (if carrying ...
by anav
Sat Nov 27, 2021 2:24 pm
Forum: Beginner Basics
Topic: Correct VLAN Setting between Switches
Replies: 6
Views: 409

Re: Correct VLAN Setting between Switches

Since all the vlans are created on the router, including firewall rules affecting them, best to include its config as well.
/export hide-sensitive file=anynameyouwish
by anav
Fri Nov 26, 2021 10:35 pm
Forum: General
Topic: Protection agains Frag attacks
Replies: 8
Views: 508

Re: Protection agains Frag attacks

How come I never see any of this so called attack traffic ??
It must be my block all else rule at the end of input and forward chains......... thats right I am not a believer.....
Vaccines yes, anything else not so much. If you dont have open ports, then sleep easy.
by anav
Fri Nov 26, 2021 10:33 pm
Forum: General
Topic: Botnet and bad actor filters
Replies: 22
Views: 2076

Re: Botnet and bad actor filters

Znevna uses mind control on his users and they magically dont send traffic to bad sites and thats why he doesnt need blackholes, honeypots, probe blockers or wait for it.................. updated BLACKLISTS......... I just wish he would get on with patenting his mind control............
by anav
Fri Nov 26, 2021 10:30 pm
Forum: General
Topic: Brute passwords of microtik devices from the local network, how to identify malware?
Replies: 9
Views: 972

Re: Brute passwords of microtik devices from the local network, how to identify malware?

Seems like a no brainer, more secure method if one has many routers to manage.
I post this only to annoy Znevna. :-))
by anav
Fri Nov 26, 2021 5:06 pm
Forum: General
Topic: Can't ping mikrotik LAN gateway from internal end users devices
Replies: 3
Views: 322

Re: Can't ping mikrotik LAN gateway from internal end users devices

A. You have an issue. B. You are looking for help. C. Yes you seem to know for sure what we need to see to solve your problem. Something doesnt fit. Please post entire config for review. /export hide-sensitive file=anynameyouwish (if pppoe also remove any identifying details and any public WANIPs).
by anav
Fri Nov 26, 2021 5:04 pm
Forum: General
Topic: [Leaked Video] CCR2116-12G-4S+ with RouterOS v7 for processing BGP tables in 30s
Replies: 29
Views: 2368

Re: [LEAKED] CCR2116-12G-4S+ with RouterOS v7 for processing BGP tables in 30s

Very nice!,
My CCR1009 cannot keep up with my home demands, that is what I will say to the significant other...............
by anav
Fri Nov 26, 2021 5:02 pm
Forum: Beginner Basics
Topic: Best site to site sertup
Replies: 5
Views: 391

Re: Best site to site sertup

Only on the beta firmware but they are up to RC7 I think. Its getting refined..........
by anav
Fri Nov 26, 2021 3:14 pm
Forum: Beginner Basics
Topic: Best site to site sertup
Replies: 5
Views: 391

Re: Best site to site sertup

Wireguard for the untrained,
Ipsec VPN works great for those that are trained.
by anav
Fri Nov 26, 2021 3:13 pm
Forum: Beginner Basics
Topic: Route marking in OS7.04
Replies: 4
Views: 419

Re: Route marking in OS7.04

So you dont want load balancing???
by anav
Fri Nov 26, 2021 3:12 pm
Forum: Beginner Basics
Topic: macOS Winbox
Replies: 7
Views: 480

Re: macOS Winbox

Better to realize that winbox is for network engineers that are very poor and cannot afford mac desktops or laptops or are not provided such luxurious appliances by their bosses....... (only bosses get macbook pros, not the mere working minions). If lucky an MT enganeer or self made private Certifie...
by anav
Fri Nov 26, 2021 3:09 pm
Forum: Beginner Basics
Topic: subnets
Replies: 11
Views: 593

Re: subnets

In short,
Please post your config,
by anav
Fri Nov 26, 2021 2:44 pm
Forum: Beginner Basics
Topic: macOS Winbox
Replies: 7
Views: 480

Re: macOS Winbox

Does MAC still make computers?? I thought it was just fake props on movies ;-)
I wonder what percentage of Apple Revenue is due to Computers.........
by anav
Thu Nov 25, 2021 11:19 pm
Forum: General
Topic: separate circuit
Replies: 7
Views: 475

Re: separate circuit

In most cases you only need one bridge!
by anav
Thu Nov 25, 2021 6:01 pm
Forum: Wireless Networking
Topic: cAP vs cAP XL
Replies: 16
Views: 989

Re: cAP vs cAP XL

Expectations. The TP LINK EAP 245 is the same cost as a CAPAC and works far better.
If you wanted an improvement to that, look at the EAP660HD
There are no cheaper good solutions to individual APs. I am not familiar with mesh products.
by anav
Thu Nov 25, 2021 5:43 pm
Forum: Useful user articles
Topic: Port Forwarding Not Working, Hairpin NAT & More!!
Replies: 26
Views: 3177

Re: SEXY Hairpin NAT - Some of the Ways To Achieve O......

Most comments now included!
by anav
Wed Nov 24, 2021 4:29 pm
Forum: Useful user articles
Topic: Port Forwarding Not Working, Hairpin NAT & More!!
Replies: 26
Views: 3177

Re: SEXY Hairpin NAT - Some of the Ways To Achieve O......

Done and done for recommended amends
by anav
Wed Nov 24, 2021 3:55 pm
Forum: Wireless Networking
Topic: How tro put two Wi-Fi radios on separate subnets
Replies: 12
Views: 653

Re: How tro put two Wi-Fi radios on separate subnets

I attempted to help by asking pertinent questions, instead, no answer but a NEW question?? use the red X.
Hopefully someone else will have more patience. Good luck.
by anav
Wed Nov 24, 2021 2:18 pm
Forum: Beginner Basics
Topic: Set up as Access Point
Replies: 1
Views: 295

Re: Set up as Access Point

Yup, One bridge ether1 on bridge ether2 not on bridge ether 2 gets IP address of 192.168.5.2 network 192.168.5.0 (ether 2 is your emergency access to the router and the better place to o configure the router from defaults to the setup you want to make) (just hookup; the laptop; to ether2 and set a l...
by anav
Wed Nov 24, 2021 2:00 pm
Forum: Beginner Basics
Topic: Mange Rule - Chain Prerouting vs Forward
Replies: 10
Views: 6658

Re: Mange Rule - Chain Prerouting vs Forward

Regardless if you need to mangle your gaming ports, then its your gaming skills that is the problem. ;-)
by anav
Wed Nov 24, 2021 1:38 am
Forum: Beginner Basics
Topic: Firewall Filter & DNS
Replies: 4
Views: 426

Re: Firewall Filter & DNS

Clearly stated, insight required. Sight being the operative word and thus I noted glasses.
You might say, ocular lubricant may be a part answer! :-)
by anav
Tue Nov 23, 2021 11:10 pm
Forum: General
Topic: Unable to access any MT device behind Mikrotik Router
Replies: 17
Views: 769

Re: Unable to access any MT device behind Mikrotik Router

Sorry if you want to connect MT devices over the internet for configuration purposes, it should be done via VPN. If you want to take short cuts, and let someone else handle connectivity for you try Remote WINBOX service SSTP good enough for home, or even better ISPapp.co service for business (no ope...
by anav
Tue Nov 23, 2021 11:05 pm
Forum: Beginner Basics
Topic: No incoming traffic (Game Ports)
Replies: 10
Views: 1072

Re: No incoming traffic (Game Ports)

What I recommend is that your friend either. a.. has a static fixed WANIP he can give you b. if dynamic he gets a domain name or more accurately a free dyndns name available at many sites............. and then you will ensure that the dst-nat rules for the game has a component of src-address-list=au...
by anav
Tue Nov 23, 2021 7:48 pm
Forum: General
Topic: Unable to access any MT device behind Mikrotik Router
Replies: 17
Views: 769

Re: Unable to access any MT device behind Mikrotik Router

Can you draw a network diagram.
It appears you have setup the LTE devices as routers but I thought the 2011 was your router?
Chicken or egg, whats going on here??

What is connected to the internet and what is the purpose of the LTE devices..............
by anav
Tue Nov 23, 2021 7:41 pm
Forum: Beginner Basics
Topic: Firewall Filter & DNS
Replies: 4
Views: 426

Re: Firewall Filter & DNS

you dont need glasses, there is no user manual.
by anav
Tue Nov 23, 2021 3:50 pm
Forum: Wireless Networking
Topic: How tro put two Wi-Fi radios on separate subnets
Replies: 12
Views: 653

Re: How tro put two Wi-Fi radios on separate subnets

What is your network design.
Is the device acting as a router and access point, or simply as an access point and if so what router is feeding it?

Please post your config
/export hide-sensitive file=anynameyouwish
by anav
Tue Nov 23, 2021 3:47 pm
Forum: General
Topic: Internet access via Campground Wifi using Metal 52 ac and a Netgear R6400
Replies: 3
Views: 324

Re: Internet access via Campground Wifi using Metal 52 ac and a Netgear R6400

Please post config on metal.....
/export hide-sensitive file=anynameyouwish
by anav
Tue Nov 23, 2021 3:45 pm
Forum: General
Topic: RB750Gr3 Vlan scenario advice
Replies: 10
Views: 962

Re: RB750Gr3 Vlan scenario advice

Please post your config
/export hide-sensitive file=anynameyouwish
by anav
Tue Nov 23, 2021 1:30 pm
Forum: General
Topic: Unable to access any MT device behind Mikrotik Router
Replies: 17
Views: 769

Re: Unable to access any MT device behind Mikrotik Router

The core config is hosed. Start there. Lots of errors......... lack of bridge definition being one of them.
by anav
Tue Nov 23, 2021 1:27 am
Forum: General
Topic: Unable to access any MT device behind Mikrotik Router
Replies: 17
Views: 769

Re: Unable to access any MT device behind Mikrotik Router

How are your devices connected?
Is their a managment vlan or a trusted subnet.
All devices behind the router should have an IP on the trusted subnet or management vlan.
by anav
Mon Nov 22, 2021 10:47 pm
Forum: General
Topic: Load Balancing / Routing
Replies: 16
Views: 748

Re: Load Balancing / Routing

Concur, many MT users have asked for more fidelity such as being able to use firewall-address-lists for many more entries and rules than is currently allowed.
Then the addition of only one Route Rule would be required. I agree its a shame this has not been implemented.
by anav
Mon Nov 22, 2021 10:45 pm
Forum: General
Topic: IP addresses in the same subnet across multiple interfaces? [SOLVED]
Replies: 8
Views: 688

Re: IP addresses in the same subnet across multiple interfaces? [SOLVED]

Thats up to the individual running the laptop. Connectivity is required and provided.
Two separate mac addresses two connections, only one will be used at a time.
by anav
Mon Nov 22, 2021 10:42 pm
Forum: Beginner Basics
Topic: Avoiding double NAT Fritzbox + CCR2004
Replies: 18
Views: 718

Re: Avoiding double NAT Fritzbox + CCR2004

Sob and Fritz are good friends, Im sure they will work it out! ;-)
by anav
Mon Nov 22, 2021 8:40 pm
Forum: General
Topic: Router for test environment
Replies: 10
Views: 546

Re: Router for test environment

yup the hex is a good candidate.
I attache my MT router to various switches, dlink, mt, netgear, tplink .........
all following this guide...... and whatever the vendor requires.........

viewtopic.php?t=143620
by anav
Mon Nov 22, 2021 8:35 pm
Forum: General
Topic: Load Balancing / Routing
Replies: 16
Views: 748

Re: Load Balancing / Routing

If its a nightmare to manage then suggest your hardware design needs improvement. My method works, why is it so hard to manage? Statically set DHCP leases and IPs are static!! If you have a bunch of users with a specific use case, put them on a vlan! If you dont have the equipment to do that, then t...
by anav
Mon Nov 22, 2021 8:33 pm
Forum: General
Topic: cAP WiFi6 etc....
Replies: 6
Views: 641

Re: cAP WiFi6 etc....

Unfair? Wifi 5 Wave 2 is more than 5 years old, and there is no support in stable releases, I think mikrotik Wifi is dead….. And I think, Mikrotik wi-fi is serving to many happy campers, not being obsessed by the latest and greatest. Perhaps but the TPlink eap245 was the same cost as a Capac and is...
by anav
Mon Nov 22, 2021 6:18 pm
Forum: General
Topic: Load Balancing / Routing
Replies: 16
Views: 748

Re: Load Balancing / Routing

Up to you, with mangling you lose fastrack advantages in connection tracking but probablly no biggie. For me I would change how those strange and weird users are segregated. I would put them on one subnet/vlan if at all possible. As I said, even if 50 users, I would make up 50 route rules. I hate ma...
by anav
Mon Nov 22, 2021 5:40 pm
Forum: General
Topic: Bypass the VPN for SMB access from outside [SOLVED]
Replies: 42
Views: 1927

Re: Bypass the VPN for SMB access from outside [SOLVED]

Normally on an ISP controlled modem/router, where they provide you a private IP address, then the subscriber you, still has a very basic access to the ISP modem router. Typically its so that you can forward a port (DMZ typically is not activated). Thus suggest you try to access the ISP modem/router ...
by anav
Mon Nov 22, 2021 5:24 pm
Forum: General
Topic: Load Balancing / Routing
Replies: 16
Views: 748

Re: Load Balancing / Routing

Super. Start with standard ISP route structure. ISP1 route distance=5 check-gateway=ping ISP2 route distance=10 From the above all users will directed to ISP1 and if down go to ISP2. When ISP 1 comes back online, then all users will head back to ISP1. (Note; This presumes the WAN connections are fro...
by anav
Mon Nov 22, 2021 5:11 pm
Forum: Useful user articles
Topic: Port Forwarding Not Working, Hairpin NAT & More!!
Replies: 26
Views: 3177

Re: SEXY Hairpin NAT - Some of the Ways To Achieve O......

Thanks Sob, Will attempt to satisfy your pernicious penchant for particularly pimply and prickly, pickyness ;-P I do have a JUMP question for you....... can that be used for different scenarios................ let say its this scenario, dynamic wanip, add chain=dstnat action=dst-nat dst-address-type...
by anav
Mon Nov 22, 2021 4:57 pm
Forum: Beginner Basics
Topic: Can not dst-nat to vlan device [SOLVED]
Replies: 7
Views: 509

Re: Can not dst-nat to vlan device [SOLVED]

To clarify, users on the bridge 192.168.1.X will be accessing the cameras on the VLAN via dyndns name as well as folks having external access to the cameras. There is no case of users on the vlan accessing the camera on the vlan (as there are no users on the vlan)? In this case there is no hairpin n...
by anav
Mon Nov 22, 2021 4:37 pm
Forum: Beginner Basics
Topic: Best practice for management isolation/security
Replies: 4
Views: 359

Re: Best practice for management isolation/security

I have never used VRFs, so do not know how complex they are but it if more secure than using a management VLAN, then it sounds like a good idea!!
Wish I could be of more help!
by anav
Mon Nov 22, 2021 4:30 pm
Forum: Beginner Basics
Topic: Avoiding double NAT Fritzbox + CCR2004
Replies: 18
Views: 718

Re: Avoiding double NAT Fritzbox + CCR2004

For firewall rules on CCR.......... one should only allow port forwarding, the specifics are located on the associated DST NAT rule. From: /ip firewall filter add action=accept chain=forward comment="Server 1" dst-address=192.168.2.2 \ dst-port=21 protocol=tcp add action=accept chain=forwa...
by anav
Mon Nov 22, 2021 4:17 pm
Forum: Beginner Basics
Topic: Best practice for management isolation/security
Replies: 4
Views: 359

Re: Best practice for management isolation/security

Just curious what is the advantage of this VRF approach compared to a. ipsec connection to router (then using winbox). b. running dude (internal network normally not sure how this is handled remotely as a server). c. cloud SSTP connection using Remote Winbox service (dont like it for business as I d...
by anav
Mon Nov 22, 2021 4:06 pm
Forum: General
Topic: Load Balancing / Routing
Replies: 16
Views: 748

Re: Load Balancing / Routing

Quick question, what is the purpose of setting up the the router this way? It sounds like you want to use both WANs at the same time, why not just simply load balance the routers ???? I have two WANIPs and all traffic goes to one except email traffic which is based on a previous only connection to W...
by anav
Mon Nov 22, 2021 2:50 pm
Forum: Beginner Basics
Topic: Wireguard VPN routing
Replies: 1
Views: 285

Re: Wireguard VPN routing

Sounds like a case where you need to do two things... a. ensure 192.168.189.128 is routed through the WIREGUARD Tunnel b. at the 192.168.188.1 router, internet traffic is routed back through the tunnel to 192.168.189.128 On the 189 Router I would probably accomplish a. with a destination route and r...
by anav
Mon Nov 22, 2021 2:41 pm
Forum: Beginner Basics
Topic: DNS "Allow Remote Requests" Firewall Configuration
Replies: 2
Views: 326

Re: DNS "Allow Remote Requests" Firewall Configuration

The default firewall rules allow LAN to ROUTER access for such things as Router Services (DNS, NTP). Hence the default rule add action=drop chain=input comment="Defconf: drop all not coming from LAN" \ in-interface-list=!LAN This blocks all WAN to router traffic allowing all LAN to router ...
by anav
Mon Nov 22, 2021 2:13 pm
Forum: Beginner Basics
Topic: Can not dst-nat to vlan device [SOLVED]
Replies: 7
Views: 509

Re: Can not dst-nat to vlan device [SOLVED]

I have no clue what you are attempting to do with telefeno and a private IP address block 10.0.X.X beyond my scope of knowledge? Also, it looks like you are using mangle type rules, but in a way I am not familiar with but again beyond my scope of knowledge but I will say typically, mangle rules bein...
by anav
Mon Nov 22, 2021 2:12 pm
Forum: Beginner Basics
Topic: Can not dst-nat to vlan device [SOLVED]
Replies: 7
Views: 509

Re: Can not dst-nat to vlan device [SOLVED]

Remove this (not required) use standard IP Firewall Rules!! /interface bridge settings set use-ip-firewall=yes use-ip-firewall-for-pppoe=yes \ use-ip-firewall-for-vlan=yes IF not required, set this to none, can often cause issues. interface detect-internet set detect-interface-list= all Since you on...
by anav
Mon Nov 22, 2021 1:56 pm
Forum: Beginner Basics
Topic: Configure as Access Point
Replies: 2
Views: 337

Re: Configure as Access Point

What vlans are feeding the capac from the router?
homelan/guestlan/management (often the trusted home LAN/WIFI is also the managment vlan).
by anav
Mon Nov 22, 2021 2:42 am
Forum: General
Topic: Block p2p from IP cameras - RB4011iGS+RM
Replies: 22
Views: 1730

Re: Block p2p from IP cameras - RB4011iGS+RM

IF your task is simply to block a list of cameras from accessing the internet as you have done seems good to go! The only thing I dont understand is why you have some sort of connection limits, why have them.??? add action=drop chain=forward comment="Drop: IP cameras (LAN -> Internet)" con...
by anav
Mon Nov 22, 2021 2:41 am
Forum: General
Topic: Block p2p from IP cameras - RB4011iGS+RM
Replies: 22
Views: 1730

Re: Block p2p from IP cameras - RB4011iGS+RM

To answer your question I believe all the switches and Access points you are using are smart devices which can read vlans. In this case it gives you much flexibility in that you can create and put the vlans to any ports or wlans you want and thus segregate traffic effectively. Its a layer of magnitu...
by anav
Mon Nov 22, 2021 2:33 am
Forum: General
Topic: Block p2p from IP cameras - RB4011iGS+RM
Replies: 22
Views: 1730

Re: Block p2p from IP cameras - RB4011iGS+RM

This is wrong on your config.......... /ip address add address=192.168.88.1/24 comment=defconf interface =ether2 network=192.168.88.0 SHOULD BE /ip address add address=192.168.88.1/24 comment=defconf interface= bridge network=192.168.88.0 Dont see DNS noted on the config although it may be selected ...
by anav
Mon Nov 22, 2021 1:19 am
Forum: Useful user articles
Topic: Port Forwarding Not Working, Hairpin NAT & More!!
Replies: 26
Views: 3177

Re: SEXY Hairpin NAT - The Right Way To Achieve O......

One loosely related bonus tip: Even if you have static address (but not as static to be guaranteed forever, because you may e.g. change ISP), you may be tempted to use shortcuts like in-interface=WAN (let's forget for a while that you can't use it anyway if you want hairpin NAT), simply because it ...
by anav
Sat Nov 20, 2021 11:40 pm
Forum: Useful user articles
Topic: Port Forwarding Not Working, Hairpin NAT & More!!
Replies: 26
Views: 3177

Re: SEXY Hairpin NAT - The Right Way To Achieve O......

Okay article revamped, please be gentle but comments welcome!!!
by anav
Sat Nov 20, 2021 10:34 pm
Forum: Useful user articles
Topic: Port Forwarding Not Working, Hairpin NAT & More!!
Replies: 26
Views: 3177

Re: SEXY Hairpin NAT - The Right Way To Achieve O......

Thanks Znevna, and all made some modifications so that the writeup is closer to the mark.
I will have to do some more amends as Sob has brought up other iterations or use cases to consider vice the mainstream ones.
by anav
Sat Nov 20, 2021 9:37 pm
Forum: Useful user articles
Topic: Port Forwarding Not Working, Hairpin NAT & More!!
Replies: 26
Views: 3177

Re: SEXY Hairpin NAT - The Right Way To Achieve O......

Well clearly I have botched this all up and need to do a rewrite, can you email me Sob, as its too difficult to attempt on this thread due to my lack of understanding of Italian and the extra noise created by Trollnevna!.
by anav
Sat Nov 20, 2021 9:27 pm
Forum: General
Topic: cAP WiFi6 etc....
Replies: 6
Views: 641

Re: cAP WiFi6 etc....

Feature requests should be posted in the beta forum.
by anav
Sat Nov 20, 2021 9:21 pm
Forum: General
Topic: Help on designing Mikrotik network
Replies: 20
Views: 1048

Re: Help on designing Mikrotik network

Ahh okay yeah if its not MT its not relevant LOL.
by anav
Sat Nov 20, 2021 8:59 pm
Forum: General
Topic: Help on designing Mikrotik network
Replies: 20
Views: 1048

Re: Help on designing Mikrotik network

Yes, anav, you are right. I like this feature somehow, but it is only feasible between switches anyway.
Not sure what you mean........
Vlans works for me for all managed switches (independent of vendor) and all smart access points independent of vendor.
by anav
Sat Nov 20, 2021 8:56 pm
Forum: Beginner Basics
Topic: VLAN between Non-wireless router w/ WAP
Replies: 13
Views: 5667

Re: VLAN between Non-wireless router w/ WAP

Basically. IF you want help, do the preliminary leg work of providing a nice network diagram showing the ports and what they are connected too. If you can differentiate the different groups of devices/users that you require to be on each port even better (you can have multiple users going over a sin...
by anav
Sat Nov 20, 2021 8:54 pm
Forum: Beginner Basics
Topic: VLAN between Non-wireless router w/ WAP
Replies: 13
Views: 5667

Re: VLAN between Non-wireless router w/ WAP

Okay, When you reset, the defaults should be there, access on ether2, wan defaults to ether1..... all ports on the bridge except ether1 Not sure for your device but thats typical. Before embarking on the bridge and vlans. take the last port, ether8 for example. Rename it. ether8-emerg under interfac...
by anav
Sat Nov 20, 2021 4:31 pm
Forum: General
Topic: Help on designing Mikrotik network
Replies: 20
Views: 1048

Re: Help on designing Mikrotik network

I think you are way overcomplicating things....... This is a simple case of various vlans supplying the various needs on the network. Router MT should have enough ports to a. connect to one or more WANs as per the network. b. Rest of ports should be on a single bridge c. Reserve one bridge port for ...
by anav
Sat Nov 20, 2021 4:15 pm
Forum: General
Topic: Imposible getting ping when using vlans
Replies: 19
Views: 1037

Re: Imposible getting ping when using vlans

I dont understand the network as described and the config depends on that structure.

What is/are acting as switch(es) and what is acting as router(s) here??
What is/are connected to ISP modem(s)?
by anav
Sat Nov 20, 2021 4:09 pm
Forum: Beginner Basics
Topic: PCC load balance, but pc got 2 default gateway !help [SOLVED]
Replies: 5
Views: 548

Re: PCC load balance, but pc got 2 default gateway !help [SOLVED]

Observations. 1. MISSING firewall rules to protect your router and LAN network. Suggest put in default rules. (2) remove this setting (select NO) and use the normal /ip firewall rules for input chain and forward chain. /interface bridge settings set use-ip-firewall= yes (3) Your mangle rules...........
by anav
Sat Nov 20, 2021 4:47 am
Forum: General
Topic: Accessing a subnet in which the Mikrotik isn't the gateway
Replies: 2
Views: 559

Re: Accessing a subnet in which the Mikrotik isn't the gateway

Not sure if this is similar to your case, but this thread may give you some ideas......
viewtopic.php?p=891129#p891129
by anav
Sat Nov 20, 2021 4:42 am
Forum: Beginner Basics
Topic: VLAN between Non-wireless router w/ WAP
Replies: 13
Views: 5667

Re: VLAN between Non-wireless router w/ WAP

Sob has been away for awhile so he is rusty and not usually prone to long complicated stories ;-) The long and short of it is that a configuration will fall out naturally from a well thought out design. Meaning, you need to articulate your use cases without any discussion of the config. What singula...
by anav
Sat Nov 20, 2021 12:29 am
Forum: Beginner Basics
Topic: Working around NAT hairpin [SOLVED]
Replies: 27
Views: 1714

Re: Working around NAT hairpin [SOLVED]

I needed to take a break, I found out that I was spending way too much time here. So it was a detox of a kind, OK. With this Covid and alike, I was scared you shifted to Juniper :) And all this time I thought he had retired seeing as I was answering all the threads satisfactorily.......... Missed y...
by anav
Fri Nov 19, 2021 10:27 pm
Forum: Beginner Basics
Topic: Working around NAT hairpin [SOLVED]
Replies: 27
Views: 1714

Re: Working around NAT hairpin [SOLVED]

Sob where you have been ole chum, I almost fainted when I saw you had posted!!
Is the real Sob? or some sick imposter??
You have made my day!
by anav
Fri Nov 19, 2021 5:32 pm
Forum: Beginner Basics
Topic: Working around NAT hairpin [SOLVED]
Replies: 27
Views: 1714

Re: Working around NAT hairpin [SOLVED]

My apologies dabardabar, the guide on simply moving the server to a different subnet was not complete. Instead of this the basic default rules. /ip firewall nat add action=masquerade chain=srcnat out-interface-list=WAN add action=dst-nat chain=dstnat dst-port=80 protocol=tcp \ in-interface-list=WAN ...
by anav
Fri Nov 19, 2021 4:52 pm
Forum: General
Topic: Firewall filter rule ignored?
Replies: 13
Views: 785

Re: Firewall filter rule ignored?

As stated separate lists, order is important WITHIN a list.
Input chain, to and fro the router (wan to router, lan to router)
Forward chain, through the router (wan to lan, lan to wan, lan to lan)
by anav
Fri Nov 19, 2021 2:15 pm
Forum: General
Topic: RB-5009 Initial Setup and VLAN configuration
Replies: 6
Views: 709

Re: RB-5009 Initial Setup and VLAN configuration

kk I would also use the unused ether8 as ether8-emergaccess. Give it an IP of 192.168.66.2 network 192.168.66.0 take ether8 off the bridge. Ensure you add it to the management interface as a member. Step 1: You have to define ALL the vlans on the RB5009, you only have defined vlan50 ???? In other wo...
by anav
Fri Nov 19, 2021 3:31 am
Forum: Beginner Basics
Topic: Working around NAT hairpin [SOLVED]
Replies: 27
Views: 1714

Re: Working around NAT hairpin [SOLVED]

Buuuut, I still cannot use testdomain.com from any computer on my internal network, for example a PC with IP 192.168.88.101, it still takes me to MT login page from any of those computers. If I type 192.168.90.200 instead, it will correctly open the website. As I wrote another dozen times already, ...
by anav
Fri Nov 19, 2021 12:45 am
Forum: Beginner Basics
Topic: Working around NAT hairpin [SOLVED]
Replies: 27
Views: 1714

Re: Working around NAT hairpin [SOLVED]

So MKX, Having the server on a different subnet from the Users DOES NOT avoid hairpin nat? ? Further the issue is the makeup of the normal dstnat rule and thus the real culprit is "in-interface-list=WAN" or in-interface=WAN for a dynamic WANIP?? If so I have been working from a wrong assum...
by anav
Thu Nov 18, 2021 11:49 pm
Forum: General
Topic: Botnet and bad actor filters
Replies: 22
Views: 2076

Re: Botnet and bad actor filters

Seeing @anav promoting an useless blacklist and then trying to justify it, is hilarious. Please, continue. I have no steak or stake in any blacklists. I am trying to ascertain the impractical from the practical and apply necessary rules in a minimalistic approach. Thus far I am hearing. Probes are ...
by anav
Thu Nov 18, 2021 11:38 pm
Forum: Beginner Basics
Topic: Working around NAT hairpin [SOLVED]
Replies: 27
Views: 1714

Re: Working around NAT hairpin [SOLVED]

Haha unfortunately I feel so dumb, I still haven't worked it out :) Okay, just to cover the basics, about this: If its no issue to move the server to a different subnet then you are done! Move subnet to different LAN (or users) So, my primary network is 192.168.88.x, and all the client computers ar...
by anav
Thu Nov 18, 2021 11:15 pm
Forum: General
Topic: Botnet and bad actor filters
Replies: 22
Views: 2076

Re: Botnet and bad actor filters

I am making no progress here. So, even if I dont have any ports open, my router is still using cycles to answer port probes?? Is it better to drop all such probes in raw, or ignore the probes. chain=raw action=drop dst-ports=1-65000 in-interface-list=WAN honeypot seem complicated..... I am just gett...
by anav
Thu Nov 18, 2021 11:03 pm
Forum: General
Topic: Firewall filter rule ignored?
Replies: 13
Views: 785

Re: Firewall filter rule ignored?

Basically, I would not put any rules above the default rules myself. But why is your permit SSH rule WIDE FRIGGEN OPEN. Did you mean SSH to be open to the internet and the LAN If its for the internet, suggesting use VPN for access instead. If its for LAN users or the admin then add chain=input actio...
by anav
Thu Nov 18, 2021 7:14 pm
Forum: General
Topic: Botnet and bad actor filters
Replies: 22
Views: 2076

Re: Botnet and bad actor filters

In summary,
if one has no ports open on the router, then does that solve the probe threat??
If one has only VPN ports open (random selection of port for wireguard for example), is that a risk??

I am trying to ascertain the level of threat/risk of the probes??
by anav
Thu Nov 18, 2021 4:37 pm
Forum: General
Topic: Botnet and bad actor filters
Replies: 22
Views: 2076

Re: Botnet and bad actor filters

Hi Mozerd, My question should be posed differently then. Since most firewalls 99% in MT, block wan to lan and wan to router traffic, what is the point of all the lists?? The only threats I see are. a. lan users visiting bad sites, be they torrenting etc....... ( so perhaps the lists have validity to...
by anav
Thu Nov 18, 2021 4:30 pm
Forum: General
Topic: Firewall filter rule ignored?
Replies: 13
Views: 785

Re: Firewall filter rule ignored?

Why are you allowing folks to SSH into your router from the internet??. USE VPN to access the router. OR Are these all internal lan users attempting to do so?? THe only SSH I allow is for the admin to have backup access to the router in case winbox doesnt work. That is only from a very limited LANIP...
by anav
Thu Nov 18, 2021 4:27 pm
Forum: General
Topic: RB-5009 Initial Setup and VLAN configuration
Replies: 6
Views: 709

Re: RB-5009 Initial Setup and VLAN configuration

Is the 5009 acting as a switch or a router. In the previous topic, you had a firewall device in between the ISP and the RB4011. Is that still the case between internet and 5009 and if so what does the firewall provide? (just identifies vlans) (identifies vlans and creates the subnets dchp, pool, add...
by anav
Thu Nov 18, 2021 4:21 pm
Forum: Beginner Basics
Topic: Is that possible?
Replies: 3
Views: 470

Re: Is that possible?

What you do is have all the customers on vlans and the smart devices have IPs on the management vlan and thus not accessible. In other words not on the same subnet. Best suggestion is not to corner yourself into a twisted solution by deciding the config before articulating the requirements. Write do...
by anav
Wed Nov 17, 2021 11:22 pm
Forum: Beginner Basics
Topic: Working around NAT hairpin [SOLVED]
Replies: 27
Views: 1714

Re: Working around NAT hairpin [SOLVED]

Hi there, If its no issue to move the server to a different subnet then you are done! Often that is not possible and then you have to look at the alternate options laid out in the article. So yes, Solution A: Move subnet to different LAN (or users) /ip firewall nat add action=masquerade chain=srcnat...
by anav
Wed Nov 17, 2021 7:54 pm
Forum: General
Topic: RB750Gr3 Vlan scenario advice
Replies: 10
Views: 962

Re: RB750Gr3 Vlan scenario advice

Easy peasy What if @OP wants to have same IP subnet on all involved ports (e.g. because management SW expects cameras to reside in same broadcast domain), he just wants to block certain communication paths? I reread what was posted, and it is not clear whether the cameras need to be able to send in...
by anav
Wed Nov 17, 2021 5:14 pm
Forum: General
Topic: Botnet and bad actor filters
Replies: 22
Views: 2076

Re: Botnet and bad actor filters

Basically all useless. :-P Drop all else for both input and forward chains. Mostly done! One could consider is to route non-public subnets, not on ones router, to blackhole. The idea of blacklists, I suppose is to stop your unsuspecting users that are allowed to access the internet, to hit bad priva...
by anav
Wed Nov 17, 2021 5:06 pm
Forum: General
Topic: RB750Gr3 Vlan scenario advice
Replies: 10
Views: 962

Re: RB750Gr3 Vlan scenario advice

Easy peasy VLAN 10 is assigned to ports 2,3,4 Vlan 11 is assigned to port 1 vlan12 is assigned to port 5 firewall rules forward chain allow vlan11 access to vlan10 allow vlan12 access to vlan10 Drop all else. Would need to know what is physically attached on each port. If its a PC (dumb device) it g...
by anav
Wed Nov 17, 2021 4:42 pm
Forum: Beginner Basics
Topic: My ISP modem/router can't do bridged mode. I'm a newbie.
Replies: 10
Views: 975

Re: My ISP modem/router can't do bridged mode. I'm a newbie.

Dont use vlan #1, that is the default on the bridge and on most switches etc.

Just use
vlan10
vlan11
vlan12
vlan13
etc.......

Also decide which vlan is your management vlan as you are the admin,, sounds like your vlan 4 (or vlan14) would suffice......
by anav
Wed Nov 17, 2021 1:37 am
Forum: Beginner Basics
Topic: VLAN/DHCP configuration [SOLVED]
Replies: 6
Views: 745

Re: VLAN/DHCP configuration [SOLVED]

So the WLAN you are mimicking comes in on vlan80 Okay dont know what you mean by dhcp on only one of the interfaces, that is not a use case description, that is an assumption of a configuration change based on an uncommunicated use case. What do you have for users/devices or groups of users/devices,...
by anav
Tue Nov 16, 2021 7:55 pm
Forum: General
Topic: Propose Mikrotik to adopt TailScale VPN similar to ZeroTierOne VPN
Replies: 7
Views: 728

Re: Propose Mikrotik to adopt TailScale VPN similar to ZeroTierOne VPN

Dear Normis, I propose Mikrotik RouterOS to adopt TailScale VPN https://tailscale.com/ similar to ZeroTier VPN https://www.zerotier.com/ ... as TailScale is much easier to understand and deploy than confusing ZeroTier ... for newbie users... ;) Earlier a year ago I proposed ZeroTier and I thank you...
by anav
Tue Nov 16, 2021 7:52 pm
Forum: Beginner Basics
Topic: How to properly manage multiple mikrotik routers?
Replies: 6
Views: 1073

Re: How to properly manage multiple mikrotik routers?

I use wireguard to access my routers remotely. (just a few). I use winbox remote as a backup router access to my wireguard setup. Its SSTP vpn which is okay for my home but not really good enough for a business, but it attempts to centralize access, so thats a bonus. Dude seems like one to one conne...
by anav
Tue Nov 16, 2021 7:43 pm
Forum: Beginner Basics
Topic: VLAN/DHCP configuration [SOLVED]
Replies: 6
Views: 745

Re: VLAN/DHCP configuration [SOLVED]

Nope but please clarify if you are trying to mimick an MT device as a router attached to an ISP modem.
Or if you are simply mimicking an MT device as a smart switch in a network.
by anav
Tue Nov 16, 2021 2:02 pm
Forum: Beginner Basics
Topic: My ISP modem/router can't do bridged mode. I'm a newbie.
Replies: 10
Views: 975

Re: My ISP modem/router can't do bridged mode. I'm a newbie.

Dont be shy about posting your config here if not sure about settings..........
/export hide-sensitive file=anynameyouwish

and use the code tags to keep it small (black square above with white square brackets)
by anav
Tue Nov 16, 2021 2:08 am
Forum: Beginner Basics
Topic: Absolute noob looking for quick start guide.
Replies: 2
Views: 441

Re: Absolute noob looking for quick start guide.

Start with the default settings and leave them alone for the most part. The default provides a bridge for all ethernet ports except ether1 which is reserved for WAn (connectivity for PC for sure on ether 2). Once you have established connectivity and can use winbox, then use this guide for vlans if ...
by anav
Tue Nov 16, 2021 2:05 am
Forum: Beginner Basics
Topic: VLAN/DHCP configuration [SOLVED]
Replies: 6
Views: 745

Re: VLAN/DHCP configuration [SOLVED]

This is the best link to explain vlans... https://forum.mikrotik.com/viewtopic.php?t=143620 You may have forgotten to add ether1 to the bridge port settings. /interface bridge port add bridge=trunk interface=ether3 add bridge=trunk interface=ether1 Bridge vlan settings seem off so fixing it........ ...
by anav
Mon Nov 15, 2021 11:52 pm
Forum: Wireless Networking
Topic: WPA3 in September?
Replies: 11
Views: 3348

Re: WPA3 in September?

Appropriate Song by the Happenings. Will I see you (WPA) in September ( a classic) https://www.bing.com/videos/search?q=see+you+in+september&view=detail&mid=5FB49595F00085E0CC7A5FB49595F00085E0CC7A&FORM=VIRE0&ru=%2fsearch%3fq%3dsee%2byou%2bin%2bseptember%26form%3dANNTH1%26refig%3da8e...
by anav
Mon Nov 15, 2021 11:49 pm
Forum: Wireless Networking
Topic: trunk vlans across wireless bridge
Replies: 7
Views: 553

Re: trunk vlans across wireless bridge

Good thing, I only support native vlan1 and not for carrying any data either. ;-)
My contract does not cover native vlan8.
by anav
Mon Nov 15, 2021 11:47 pm
Forum: Wireless Networking
Topic: How to bridge 3 buildings wirelessly
Replies: 16
Views: 1095

Re: How to bridge 3 buildings wirelessly

The reason I ask is I will be ordering some OM3 for a 270 foot cable from the house to a potential future shed.
Sounds like SM is better suited for main connection to the house, where I only need internet for a local AP etc, nothing fancy.
by anav
Mon Nov 15, 2021 11:43 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8617

Re: Mikrotik router Hacked!!!

Easy way to build a tower???
The tower generate more money on that way than a standard tower... ahahahahah....... :lol:
Yes, it was architectural stupidity but marketing genius LOL
by anav
Mon Nov 15, 2021 11:41 pm
Forum: Beginner Basics
Topic: bridge port received packet with own address as source address...loop
Replies: 2
Views: 384

Re: bridge port received packet with own address as source address...loop

Wait one, where is the ISP in all of this, I see two switches pretending to be routers.
If you have not ISP connected to either one, where is the router?
what is the router providing?? DHCP services? anything.
by anav
Mon Nov 15, 2021 9:19 pm
Forum: Beginner Basics
Topic: Connect 2 Mikrotik Router network with Ethernet Cable
Replies: 8
Views: 592

Re: Connect 2 Mikrotik Router network with Ethernet Cable

Captain obvious ;-P
Of course I was assuming drop all rule at the end of the forward chain, otherwise default rules do not prevent any LAN to LAN traffic at layer 3.

My question strictly pertained to the use or NON use of 10.0.0.0/30 and as noted, its (transparent).
by anav
Mon Nov 15, 2021 8:00 pm
Forum: Wireless Networking
Topic: How to bridge 3 buildings wirelessly
Replies: 16
Views: 1095

Re: How to bridge 3 buildings wirelessly

Seems like digging for cables will be going again.. How I hate this part when it comes to this.. That 100-metre distance calls for fibre cables. And doit in "star" topology. Any you'll be glad to lay cables later. Fibre cables are only future proof solution (if you're going for future-pro...
by anav
Mon Nov 15, 2021 7:58 pm
Forum: Wireless Networking
Topic: trunk vlans across wireless bridge
Replies: 7
Views: 553

Re: trunk vlans across wireless bridge

Description is too vague/confusing, draw a network diagram.
For MT devices provide config
/export hide-sensitive file=anynameyouwish
by anav
Mon Nov 15, 2021 7:54 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8617

Re: Mikrotik router Hacked!!!

I am begging MT not to use Rextended's advice that many of us should start de-soldering our circuit boards. First of all my eyes are too old to see things that small and more importantly Rextended has told me he will not pay me for a new CCR1009 if I break it. ;-PP I think our definitions of EASY ar...
by anav
Mon Nov 15, 2021 7:51 pm
Forum: Beginner Basics
Topic: No Winbox access [SOLVED]
Replies: 4
Views: 681

Re: No Winbox access [SOLVED]

Ding ding winner winner frogs legs for dinner!! ;-)
by anav
Mon Nov 15, 2021 7:49 pm
Forum: Beginner Basics
Topic: Connect 2 Mikrotik Router network with Ethernet Cable
Replies: 8
Views: 592

Re: Connect 2 Mikrotik Router network with Ethernet Cable

To be clear then, and to answer the final bit. for firewall rules. do we state allow source-address=192.168.88.0/24 dst-address=192.168.91.0/24 on theRB750G allow source-address=192.168.91.0/24 dst-address=192.168.88.0/24 on the RB2011 or on both do we state allow source-address=10.0.0.0/30 dst-addr...
by anav
Mon Nov 15, 2021 12:45 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8617

Re: Mikrotik router Hacked!!!

Whatever is done just make sure the nomenclature is clear. a. VERSION DANGEROUS ( all those that may require the ability to make their device remotely changeable on the bootloader and if compromised the device is garbage) b. VERSION SAFE (all those that do not want to expose the bootloader to hacker...
by anav
Mon Nov 15, 2021 3:42 am
Forum: Wireless Networking
Topic: How to bridge 3 buildings wirelessly
Replies: 16
Views: 1095

Re: How to bridge 3 buildings wirelessly

1. LOS basic requirement 2. Classic pt to Multipoint scenario 3. 60HZ no brainer 4. Bridging is a bad idea in general (desperate final solution if nothing else better can be done) Base station by router (useful up to 200m) https://mikrotik.com/product/wap_60gx3_ap Building Units https://mikrotik.com...
by anav
Sun Nov 14, 2021 8:47 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8617

Re: Mikrotik router Hacked!!!

I am not complaining nor want to............. just want to make sure that if something unexpected happens, that I can recover vice buy a new unit. If i need the added functionality and thus the additional risk, that should be an admins choice, and not a default that those of us have to accept and wh...
by anav
Sun Nov 14, 2021 6:22 pm
Forum: Beginner Basics
Topic: Traffic between two LANs
Replies: 1
Views: 519

Re: Traffic between two LANs

(1) I am confused by this rule and suggest you get rid of it. /interface bridge settings set use-ip-firewall=yes use-ip-firewall-for-pppoe=yes use-ip-firewall-for-vlan=yes First, you are not even using a bridge and secondly only under rare circumstances would one contemplate using ip firewall settin...
by anav
Sun Nov 14, 2021 4:07 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8617

Re: Mikrotik router Hacked!!!

Exactly and thus I dont want to the unit in a mode, if hacked, that I cannot recover from.
by anav
Sat Nov 13, 2021 11:35 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8617

Re: Mikrotik router Hacked!!!

I am a perfect example, I have no clue what you mean by bootloader. I upgrade the firmware and then upgrade the SYSTEM routerboard, keep them always in sync........... I do not know where to find bootloader or why I would need it. I dont want my Router, if hacked remotely, to no longer be recoverabl...
by anav
Sat Nov 13, 2021 11:27 pm
Forum: RouterOS v7 BETA
Topic: RB5009 - RouterOS v7.1rc6: New user help please? [SOLVED]
Replies: 14
Views: 1584

Re: RB5009 - RouterOS v7.1rc6: New user help please? [SOLVED]

/interface vlan add interface=bridge name=Bench vlan-id=30 add interface=bridge name=IoT vlan-id=20 add interface=bridge name=Kids vlan-id=40 add interface=bridge name="Main Network" vlan-id=10 add interface=bridge name=Management vlan-id=11 /ip address add address=192.168.1.1/24 comment=d...
by anav
Sat Nov 13, 2021 10:28 pm
Forum: Beginner Basics
Topic: Help with auditing my Firewall
Replies: 3
Views: 678

Re: Help with auditing my Firewall

Listen, the first thing you have to do is PAY ATTENTION TO DETAIL !! here is what is listed on your exported config. I just copied it. ip firewall filter add action=drop chain=input comment="Kept trying to ssh in. This blocked him, \ but instead set an IP Services Available From for SSH to only...
by anav
Sat Nov 13, 2021 6:20 pm
Forum: RouterOS v7 BETA
Topic: RB5009 - RouterOS v7.1rc6: New user help please? [SOLVED]
Replies: 14
Views: 1584

Re: RB5009 - RouterOS v7.1rc6: New user help please? [SOLVED]

Hi there,,,,, It would be best to see both configs as they do "work together" Dont have time to look at it right now but will later. The change will be minimal Add ingress filtering to spfplus8 (and frame-types admin only tagged /interface bridge vlans add bridge=bridge tagged=bridge,sfppl...
by anav
Sat Nov 13, 2021 5:39 am
Forum: Beginner Basics
Topic: VLAN between Non-wireless router w/ WAP
Replies: 13
Views: 5667

Re: VLAN between Non-wireless router w/ WAP

YEs, please read carefully this excellent guide on vlans and has examples for your setup as well.
viewtopic.php?t=143620
by anav
Sat Nov 13, 2021 5:35 am
Forum: RouterOS v7 BETA
Topic: RB5009 - RouterOS v7.1rc6: New user help please? [SOLVED]
Replies: 14
Views: 1584

Re: RB5009 - RouterOS v7.1rc6: New user help please? [SOLVED]

Well, cannot resist the borg............. Your config needs work IMHO. First thing is remove the bridge from any dhcp and just let it be a bridge. Thus make vlan11 your Management vlan and make the necessary changes. All smart devices connected to the router should get an IP address on this vlan 11 ...
by anav
Fri Nov 12, 2021 9:08 pm
Forum: Beginner Basics
Topic: Help with auditing my Firewall
Replies: 3
Views: 678

Re: Help with auditing my Firewall

Anything in r ed get rid of. anything not changed keep anything in green modified anything in blue recommended add. anything purple danger orange I dont understand......... BUT FIRST AND FOREMOST BY STRAYING FROM DEFAULT FIREWALL RULES YOU HAVE MADE YOUR ROUTER UNSAFE. Besides the ssh rule not requi...
by anav
Fri Nov 12, 2021 8:50 pm
Forum: Beginner Basics
Topic: RB5009 Cant access router interface
Replies: 2
Views: 491

Re: RB5009 Cant access router interface

TYpically in a default setup ether1 is setup for wan and ether2 for the LAN.
by anav
Fri Nov 12, 2021 8:49 pm
Forum: Beginner Basics
Topic: My ISP modem/router can't do bridged mode. I'm a newbie.
Replies: 10
Views: 975

Re: My ISP modem/router can't do bridged mode. I'm a newbie.

The hapac2 is still good to use. Think of it as getting a private IP from your ISP vice a public. Decide what IP you want the WANIP to be on the hapac2 and create an IP address for it with interface ether1 (assuming ether will be connected to our isp router). The only issue will be if you need to fo...
by anav
Fri Nov 12, 2021 8:44 pm
Forum: RouterOS v7 BETA
Topic: RB5009 - RouterOS v7.1rc6: New user help please? [SOLVED]
Replies: 14
Views: 1584

Re: RB5009 - RouterOS v7.1rc6: New user help please? [SOLVED]

Helpful to understand in context .........
viewtopic.php?t=157048
by anav
Fri Nov 12, 2021 3:11 pm
Forum: General
Topic: Block Access From Lan 2 To Lan 1
Replies: 2
Views: 392

Re: Block Access From Lan 2 To Lan 1

Depends.........
Need to see the config and your firewall rules to be clear.
/export hide-sensitive file=anynameyouwish
by anav
Fri Nov 12, 2021 3:06 pm
Forum: General
Topic: Client behind CRS switch unable to get VLAN DHCP from CCR Router [SOLVED]
Replies: 16
Views: 1174

Re: Client behind CRS switch unable to get VLAN DHCP from CCR Router [SOLVED]

Yup would make vlan1 into vlan11 and remove Bridge providing any dhcp etc......... All vlans, very clean. whatever your management vlan is........... all smart devices get iP addresses on that vlan. I know unifi APs are funny in that they like hybrid ports, in other words they will accept (default s...
by anav
Fri Nov 12, 2021 3:03 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8617

Re: Mikrotik router Hacked!!!

in next v6 and v7 versions, protected bootloader function will have to be confirmed with press of a button. Nobody who has your password will be able to set it, if he has no physical access to the device.
+1 Like the common sense solution, simpler than my key code or cloud code suggestion.
by anav
Fri Nov 12, 2021 2:57 pm
Forum: Beginner Basics
Topic: I'm having trouble getting the second guest bridge to go to the WAN.
Replies: 2
Views: 460

Re: I'm having trouble getting the second guest bridge to go to the WAN.

Please draw a network diagram showing the connected devices and ports and subnets.

Also export the config of MT devices
/export hide-sensitive file=anynameyouwish
by anav
Fri Nov 12, 2021 5:34 am
Forum: General
Topic: Public IP blacklisted by BBC Amazon and Netflix
Replies: 20
Views: 1189

Re: Public IP blacklisted by BBC Amazon and Netflix

Conny finally figures it out at age 99 but misses his kids and grandkids growing up. The futility of it all!! .... https://www.bing.com/videos/search?q=whackamole&&view=detail&mid=4DC870F794A7DA3A775F4DC870F794A7DA3A775F&&FORM=VRDGAR&ru=%2Fvideos%2Fsearch%3Fq%3Dwhackamole%26F...
by anav
Thu Nov 11, 2021 11:24 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8617

Re: Mikrotik router Hacked!!!

Such responses............... All missed the point entirely that I was getting at. MIKROTIK has added a capability to the router to allow ISPs to modify something such that its useful for the ISPs. This modification is admin user selectable, meaning its thus also available to hackers... IF, and only...
by anav
Thu Nov 11, 2021 8:01 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8617

Re: Mikrotik router Hacked!!!

Okay, for the MT challenged users, like me. What is the quick story? It appears that a hacked router can be compromised such that the home owner can never recover the router via netinstall TRUE/FALSE? Since being compromised means that any admin setting prior to getting hacked to change any routerbo...
by anav
Thu Nov 11, 2021 7:52 pm
Forum: General
Topic: Client behind CRS switch unable to get VLAN DHCP from CCR Router [SOLVED]
Replies: 16
Views: 1174

Re: Client behind CRS switch unable to get VLAN DHCP from CCR Router [SOLVED]

On the CCR to matchup...........
Pretty sure I addressed this in another post.
AGAIN I dont see any vlans identified/created on the bridge ????

I dont see the management vlan 104
Ensure you create the client vlan11 and send it as a vlan to sfp-sfplus8 trunk port.
by anav
Thu Nov 11, 2021 7:45 pm
Forum: General
Topic: Client behind CRS switch unable to get VLAN DHCP from CCR Router [SOLVED]
Replies: 16
Views: 1174

Re: Client behind CRS switch unable to get VLAN DHCP from CCR Router [SOLVED]

Is the Client vlan 104 the same vlan as our management vlan/trusted ???? It looks to me like the vlan104 is the management vlan with a subnet of 192.168.104.0/24 It looks to me like the vlan for the client is 192.168.88.0/24 which is none existtant on the CCR?? (the vlan that is) Both your configs a...
by anav
Thu Nov 11, 2021 7:27 pm
Forum: General
Topic: Public IP blacklisted by BBC Amazon and Netflix
Replies: 20
Views: 1189

Re: Public IP blacklisted by BBC Amazon and Netflix

At some point you are going to have to throw in the towel.
Legal netflix users will still get their netflix no?
So if vpn users do not, too bad.

As long as lawful customers public IP address is not affected, who cares.
by anav
Thu Nov 11, 2021 7:20 pm
Forum: Beginner Basics
Topic: Traffic between seperate networks
Replies: 3
Views: 537

Re: Traffic between seperate networks

Forget picture. post config please /export hide-sensitive file=anynameyouwish Logically speaking what is the point of separate LAN networks if they are allowed to see each other? If its strictly to separate by WANIP, is there a reason for this? It would be better for all to share both WANIPs full ti...
by anav
Thu Nov 11, 2021 4:09 pm
Forum: General
Topic: Public IP blacklisted by BBC Amazon and Netflix
Replies: 20
Views: 1189

Re: Public IP blacklisted by BBC Amazon and Netflix

Advise customers to move away from windscribe as its use is blocking access to NETFLIX for all users..... ???
by anav
Wed Nov 10, 2021 11:59 pm
Forum: General
Topic: Block torrent downloads
Replies: 10
Views: 1026

Re: Block torrent downloads

Hi nichy,
What is the reference for 192.168.50.0/24 is that supposed to represent a private LAN behind the router that you want to control torrent access too??
by anav
Wed Nov 10, 2021 11:43 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8617

Re: Mikrotik router Hacked!!!

MT does software, HF (MMI) is not there strongpoint. ;-)
(MT recommends having a bucket of sand by your PC, and frequently jamming your fingers into the bucket to strengthen them for eventual push button use!!)
by anav
Wed Nov 10, 2021 11:40 pm
Forum: Beginner Basics
Topic: Accessing "parent" network
Replies: 5
Views: 616

Re: Accessing "parent" network

provide a network diagram of how all are connected.
Its not very clear............

If you have access on site, the admin PC should be able to reach every MT device in the building.
If you use remote access, better be by VPN, the same is true.
by anav
Wed Nov 10, 2021 9:21 pm
Forum: General
Topic: Block torrent downloads
Replies: 10
Views: 1026

Re: Block torrent downloads

It's not realistically possible, the best you can do is block DNS of popular torrents and trackers, but with DHT and PeX it only takes 1 peer to get through for torrents to work. Your best option is to throttle the speed you provide so that torrents don't negatively affect your network. This is the...
by anav
Wed Nov 10, 2021 6:30 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8617

Re: Mikrotik router Hacked!!!

1/2 bottle of wine later.............
by anav
Wed Nov 10, 2021 6:09 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8617

Re: Mikrotik router Hacked!!!

Sounds like it does need be confirmed one way or another!
Thanks for your work on this.
by anav
Wed Nov 10, 2021 4:02 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8617

Re: Mikrotik router Hacked!!!

Can we clarify, that a hacked router can be modified so that the normal netinstall process will not work?
by anav
Wed Nov 10, 2021 3:38 pm
Forum: Beginner Basics
Topic: How to configure 2nd mikrotik router as repeater via network cable
Replies: 11
Views: 1031

Re: How to configure 2nd mikrotik router as repeater via network cable

As noted the far WIFI device should be set as an Accesspoint/Switch. No need to repeat There are some basic suggestions. All smart devices need to be on the same management vlan (meaning they should all have an IP address on the management vlan). On all MT devices on the bridge select MSTP (for the ...
by anav
Wed Nov 10, 2021 12:08 am
Forum: General
Topic: Limit number connections per destination host IP???
Replies: 6
Views: 685

Re: Limit number connections per destination host IP???

hotspot/usermanager/radius has some nice limitation settings
By throughput cap
By rate limiting}
By time/day
By 1 mac address etc..........
by anav
Tue Nov 09, 2021 10:54 pm
Forum: Beginner Basics
Topic: CRS309 Switch - cannot ping gateway or any other host
Replies: 17
Views: 1241

Re: CRS309 Switch - cannot ping gateway or any other host

Starting with the CCR1009, the main change is not to mix vlans and not vlans. Best/simple/clear to use all vlans...... (by that I mean not vlan1 for anything other than default bridge settings). So Convert/Create........ Create vlan11 with Ip address 192.168.48.0/24, as well as IP pool, Dhcp server,...
by anav
Tue Nov 09, 2021 7:45 pm
Forum: Beginner Basics
Topic: Internet access
Replies: 8
Views: 745

Re: Internet access

@anav, What about Access-List Function in Mikrotik? Set a default VLAN-TAG with no Internet on the Wireless-Interfaces. Only Clients in the Access-List get access to the Network or Internet! Good idee? No idea as have not used access lists at all. I do like the hotspot,userman approach because of t...
by anav
Tue Nov 09, 2021 7:34 pm
Forum: Beginner Basics
Topic: CRS309 Switch - cannot ping gateway or any other host
Replies: 17
Views: 1241

Re: CRS309 Switch - cannot ping gateway or any other host

What is the purpose of the connection between the UNIFI switch and the CRS309?? This could lead to issues? The only advantage I could see is if there was much traffic on one VLAN that involved like servers/users where they were split up on both switches. The traffic should be able to travel between ...
by anav
Tue Nov 09, 2021 7:03 pm
Forum: Beginner Basics
Topic: Firewall considers packets invalid
Replies: 5
Views: 637

Re: Firewall considers packets invalid

Issues noted: (1) Optional Change this to /ip neighbor discovery-settings set discover-interface-list= LAN (2) Recommended based on all my devices.......... Change this to /ip settings set rp-filter= loose tcp-syncookies= no (3) Optional set all of these to NONE, unless something doesnt work without...
by anav
Tue Nov 09, 2021 6:04 pm
Forum: Beginner Basics
Topic: Internet access
Replies: 8
Views: 745

Re: Internet access

What you are asking for seems reasonable. The best methods would be to use any of a number of available resources on the MT. a. radius server/userman b. hotspot functionality https://www.youtube.com/watch?v=QnSuS88Np_s He touches upon some of the limitations, day/time schedule up time, total downloa...
by anav
Tue Nov 09, 2021 5:31 pm
Forum: RouterOS v7 BETA
Topic: [Feature Request] openvpn push route
Replies: 10
Views: 4688

Re: [Feature Request] openvpn push route

Concur with Rextended and Zvena.
Wireguard will become widely used very rapidly.
by anav
Tue Nov 09, 2021 2:47 pm
Forum: General
Topic: VLANs - bridge port received packet with own address - probably loop
Replies: 7
Views: 641

Re: VLANs - bridge port received packet with own address - probably loop

Hi Mkx can you point me to that information. I use long term on my devices and not seeing it??

At OP
MSTP may be a reasonable setting to use if have different vendor switches in the mix (connected to each other and the router)
by anav
Tue Nov 09, 2021 2:45 pm
Forum: General
Topic: On Quickset my IP Address changed to 192.168.88.0 [SOLVED]
Replies: 1
Views: 306

Re: On Quickset my IP Address changed to 192.168.88.0 [SOLVED]

Quickset should only be used to decide the router purpose, if used at all, and not for any of the other settings.
Suggest reset to defaults and start fresh
by anav
Tue Nov 09, 2021 2:40 pm
Forum: Beginner Basics
Topic: Firewall considers packets invalid
Replies: 5
Views: 637

Re: Firewall considers packets invalid

/export hide-sensitive file=anynameyouwish
by anav
Tue Nov 09, 2021 2:39 pm
Forum: Beginner Basics
Topic: CRS309 Switch - cannot ping gateway or any other host
Replies: 17
Views: 1241

Re: CRS309 Switch - cannot ping gateway or any other host

We need to see the full latest config of the CCR1009
/export hide-sensitive file=anynameyouwish

Also you need to provide a network diagram for the CCR1009.
It is not clear at all what is attached to etc. both upstream and downstream
by anav
Tue Nov 09, 2021 2:35 pm
Forum: Beginner Basics
Topic: CRS309 Switch - cannot ping gateway or any other host
Replies: 17
Views: 1241

Re: CRS309 Switch - cannot ping gateway or any other host

Everything is muddled here. A. What port is the CCR1009 coming in on for the Switch - I think ether1 B. Is the traffic coming in on a vlan - I think no C. Is all the traffic on the switch supposed to be using the same subnet that is coming in on ether1 - I assume yes D. Is that subnet 192.168.48.0/2...
by anav
Tue Nov 09, 2021 1:01 am
Forum: RouterOS v7 BETA
Topic: v7.1rc6 [development] is released!
Replies: 146
Views: 27175

Re: v7.1rc6 [development] is released!

Are blackhole and prohibit no longer types (under ip routes) available?
by anav
Mon Nov 08, 2021 11:46 pm
Forum: General
Topic: VLANs - bridge port received packet with own address - probably loop
Replies: 7
Views: 641

Re: VLANs - bridge port received packet with own address - probably loop

First thing I would do is update firmware to latest long term version. An access point setup is very simple and sparse!! (1) Is it required to set protocol mode to mstp? Leave at default setting is usually the best start. REMOVE any changes from default that you have made that means also including t...
by anav
Mon Nov 08, 2021 11:10 pm
Forum: General
Topic: New RB5009, complete new setup, need help
Replies: 10
Views: 786

Re: New RB5009, complete new setup, need help

provide the latest config and also a network diagram showing wehre all the vlans should be flowing over which ports to what devices..... For example All the ports on the Router look like trunk ports? Are they all attached to smart devices that can read vlan tags. What about the switch smart switch y...
by anav
Mon Nov 08, 2021 7:23 pm
Forum: Wireless Networking
Topic: Virtual WIFI and VLAN's - driving me crazy
Replies: 36
Views: 2314

Re: Virtual WIFI and VLAN's - driving me crazy

Use this as a guide............ https://forum.mikrotik.com/viewtopic.php?t=143620 Again, please provide a network diagram, I have no idea why you are trying to use DHCP with VLANs on this device and then pass them up through the WAN connection to god knows what?? IF I was to guess, this WAPC is stri...
by anav
Mon Nov 08, 2021 7:22 pm
Forum: General
Topic: New RB5009, complete new setup, need help
Replies: 10
Views: 786

Re: New RB5009, complete new setup, need help

even better have a read through this document....before making any further changes.
viewtopic.php?t=143620
by anav
Mon Nov 08, 2021 7:11 pm
Forum: Beginner Basics
Topic: VLAN configuration RB4011IGS+RM once again
Replies: 8
Views: 949

Re: VLAN configuration RB4011IGS+RM once again

You have to be kidding me right? That is your config/....................... (1) Missing IP pool for bridge network (2) Missing DHCP server for bridge network (3) Missing DHCP server network for bridge network (4) Your /interface bridge vlan settings are wrong. You have identified an entity that is ...
by anav
Mon Nov 08, 2021 5:53 pm
Forum: Beginner Basics
Topic: CRS309 Switch - cannot ping gateway or any other host
Replies: 17
Views: 1241

Re: CRS309 Switch - cannot ping gateway or any other host

This should not be difficult! You should only have one connection from the CCR1009 to the switch. The connecting trunk (carrying all the vlans) should be the selected port joining the two units. The switch should have an IP address on the trusted LAN or management LAN of the CCR1009 All the other po...
by anav
Mon Nov 08, 2021 4:57 pm
Forum: RouterOS v7 BETA
Topic: Wireguard Connection between two sites [SOLVED]
Replies: 22
Views: 2120

Re: Wireguard Connection between two sites [SOLVED]

Which one do you consider the Server and the Peer for the initial connection................... What type of tunnel are you looking for. a. CHR home to go out CHR work internet? b. CHR home to access CHR work Lan subnets? or vice versa c. CHR work to go out CHR home internet d. CHR work to access CH...
by anav
Mon Nov 08, 2021 2:29 pm
Forum: General
Topic: New RB5009, complete new setup, need help
Replies: 10
Views: 786

Re: New RB5009, complete new setup, need help

Add a network diagram, that shows which ports are connected and which vlans and/or devices are connected or running through them. Since your explanation/requests do not match the config shown. Also Please use /export hide-sensitive file=anynameyouwish to provide the config and use the code brackets ...
by anav
Mon Nov 08, 2021 2:24 pm
Forum: RouterOS v7 BETA
Topic: Wireguard Connection between two sites [SOLVED]
Replies: 22
Views: 2120

Re: Wireguard Connection between two sites [SOLVED]

Show your config, cant help without it.
by anav
Mon Nov 08, 2021 3:23 am
Forum: Beginner Basics
Topic: Making sure I did not mess up my firewall protection [SOLVED]
Replies: 16
Views: 1706

Re: Making sure I did not mess up my firewall protection [SOLVED]

THe next step is now improving your firewall rules. Right now the concept is accept everything except for a few things. Better is block everything except for what we allow. Think about what you need to allow in the INPUT chain and the FORWARD CHAIN, if I was to tell you the last rule in each would b...
by anav
Mon Nov 08, 2021 3:17 am
Forum: Beginner Basics
Topic: Making sure I did not mess up my firewall protection [SOLVED]
Replies: 16
Views: 1706

Re: Making sure I did not mess up my firewall protection [SOLVED]

Remuneration not required LOL.
Payback is you learning a bit more every time you play with the router.
Simply copying will lead to disasters so don't be afraid to ask WHY!!!
by anav
Mon Nov 08, 2021 3:15 am
Forum: Beginner Basics
Topic: Wireless Wire Dish and vlans
Replies: 2
Views: 766

Re: Wireless Wire Dish and vlans

The wireless wire is transparent (like plugging in an ethernet cable from a port on your router, to a switch) .In other words, its the settings on the two devices that determines how and what is communicated between them. Think of the wireless wire connection as simply an ethernet cable (no config o...
by anav
Mon Nov 08, 2021 3:13 am
Forum: General
Topic: On home network, block all but internet traffic from router devices
Replies: 2
Views: 501

Re: On home network, block all but internet traffic from router devices

Post your hex config
/export hide-sensitive file=anynameyouwish for review.

this can be simply resolved quickly once provided.
by anav
Mon Nov 08, 2021 3:10 am
Forum: General
Topic: No internet on Vlan's
Replies: 2
Views: 518

Re: No internet on Vlan's

Post your entire config
/export hide-sensitive file=anynameyouwish

the current config is a mess.

ONLY ONE BRIDGE
USE ALL VLANS
every vlan is identified with interface bridge upon creation
every vlan gets an IP pool, IP address, DHCP server, DHCP server network
follow the link provided
by anav
Mon Nov 08, 2021 3:07 am
Forum: General
Topic: Dual Wan with Failover
Replies: 2
Views: 602

Re: Dual Wan with Failover

The config is hosed....... (1) /interface bridge port add bridge=bridge interface=LAN WRONG!! /interface bridge port add bridge=bridge interface=ether3 add bridge=bridge interface=ether4 add bridge=bridge interface=ether5 add bridge=bridge interface=sfp1 (2) /interface list member add interface=ethe...
by anav
Mon Nov 08, 2021 2:55 am
Forum: General
Topic: Firewall rule works with interface, but not interface-list?
Replies: 4
Views: 520

Re: Firewall rule works with interface, but not interface-list?

What is amusing is that you blocked the trusted vlan from reaching the untrusted vlan,
add action=drop chain=forward in-interface-list=Trusted out-interface-list=Untrusted

whereas I am pretty sure you wanted the reverse,
the untrusted vlan not able to reach the trusted vlan. ;-)
by anav
Mon Nov 08, 2021 2:53 am
Forum: General
Topic: Firewall rule works with interface, but not interface-list?
Replies: 4
Views: 520

Re: Firewall rule works with interface, but not interface-list?

As for your Interface lists, looks okayish Here is what you want /interface list -WAN -LAN -TRUSTED /interface list members WAN -ether1 LAN -vlan3 LAN-vlan2 TRUSTED-vlan2 You dont really need to distinguish TRUSTED Or UNTRUSTED because you only have one vlan of each so no GROUPS of vlans here. In ot...
by anav
Mon Nov 08, 2021 2:38 am
Forum: General
Topic: Firewall rule works with interface, but not interface-list?
Replies: 4
Views: 520

Re: Firewall rule works with interface, but not interface-list?

Interface lists are excellent ways to manage GROUPs of users or devices (aka subnets).
Firewall address lists are better to form a group of USERs that is less than a subnet, Iike a subset of IPs on a subnet, IPs from different subnets, or mix of IPs and whole subnets!!!
by anav
Sun Nov 07, 2021 11:10 pm
Forum: Beginner Basics
Topic: Router for 3 internet connections for 3 buildings
Replies: 3
Views: 708

Re: Router for 3 internet connections for 3 buildings

Starlink internet :-)
by anav
Sun Nov 07, 2021 11:07 pm
Forum: Beginner Basics
Topic: Port forwarding
Replies: 3
Views: 657

Re: Port forwarding

Requirements for port forwarding........ A. Firewall rule generic that allows dst-nat packets intended for ports/IP on the router, as identified on dst-nat rules B. The dst-nat rule specific to the server Outcome on port testing software. - port will be visible on scans but will appear closed {norma...
by anav
Sun Nov 07, 2021 9:29 pm
Forum: Wireless Networking
Topic: Mikrotik RBDiscG-5acD distance ?
Replies: 6
Views: 814

Re: Mikrotik RBDiscG-5acD distance ?

The brochure indicates golden to about 4K. https://i.mt.lv/cdn/product_files/DISCplusLite5plusac_180227.pdf The most important thing though is to qualify that LOS. You need a freznel zone ( a tubular zone ) around that line of sight. https://en.wikipedia.org/wiki/Fresnel_zone probably talking 3m aro...
by anav
Sun Nov 07, 2021 6:53 pm
Forum: Beginner Basics
Topic: PPPoE Server - Bridge with other interface
Replies: 6
Views: 690

Re: PPPoE Server - Bridge with other interface

Why would you bridge, I dont understand the purpose of doing that.
Thee pppoe server is your router, not the ISPs router??

Caveat, I am no pppoe expert so maybe there is some requirement not aware of?
by anav
Sun Nov 07, 2021 6:50 pm
Forum: Beginner Basics
Topic: Making sure I did not mess up my firewall protection [SOLVED]
Replies: 16
Views: 1706

Re: Making sure I did not mess up my firewall protection [SOLVED]

Something like this. /interface bridge add admin-mac=08:55:31:CD:0D:6A auto-mac=no comment=defconf name=bridge /interface vlan add comment="Untrusted IoT" interface=bridge name=VLAN20 vlan-id=20 add comment="Trusted" interface=bridge name=VLAN11 vlan-id=11 /interface list add com...
by anav
Sun Nov 07, 2021 6:37 pm
Forum: Beginner Basics
Topic: Making sure I did not mess up my firewall protection [SOLVED]
Replies: 16
Views: 1706

Re: Making sure I did not mess up my firewall protection [SOLVED]

My Vlan 20 is attached to either 4, port 2, 3 & 5 are Lan only. My smart switch is connect to port 4 on the hex, nothing else connected to lan ports on the router. Kewl, So set vlan 20 to the bridge interface and not to ether4 Create vlan11 with the same IP subnet structure as your bridge and s...
by anav
Sun Nov 07, 2021 6:22 pm
Forum: General
Topic: Isolate IoT devices with hAP AC2 as main router
Replies: 13
Views: 1094

Re: Isolate IoT devices with hAP AC2 as main router

I dont do anything special for my ACCESS POINTS. Clients selecting which AP is more about the client programming/radio/setup behaviour we cannot control. Suffice to say I make sure that there is minimal to zero overlap on channels so that there is minimal interference. I also have more a upstairs (t...
by anav
Sun Nov 07, 2021 6:16 pm
Forum: General
Topic: Isolate IoT devices with hAP AC2 as main router
Replies: 13
Views: 1094

Re: Isolate IoT devices with hAP AC2 as main router

Excellent questions. Yes, I recommend a management VLAN for business environment, as the only person that needs access to this is the admin for the configuration of the devices for winbox purposes and for access to the router itself via winbox. In terms of vlan to vlan access, this is easily accompl...
by anav
Sun Nov 07, 2021 5:21 pm
Forum: Beginner Basics
Topic: PPPoE Server - Bridge with other interface
Replies: 6
Views: 690

Re: PPPoE Server - Bridge with other interface

Me neither, Its an easy connection to the primary router via a static IP address. Just need to set ether1 as a WAN interface and give it an IP address. The pPPOE server aspect is specific to the router and how it handles PPPOE addressing to clients. https://help.mikrotik.com/docs/display/ROS/PPPoE h...
by anav
Sun Nov 07, 2021 4:42 pm
Forum: RouterOS v7 BETA
Topic: Wireguard Connection between two sites [SOLVED]
Replies: 22
Views: 2120

Re: Wireguard Connection between two sites [SOLVED]

Absolutely no need for an address on the WG interface. The RB5009 setup I recommended will route all traffic from 192.168.88.0/24 through the tunnel whenever a destination address of 192.168.9.0/24 is utilized. That is what the OP wants! Why are you assuming different requirements?? ++++++++++++++++...
by anav
Sun Nov 07, 2021 4:24 am
Forum: Beginner Basics
Topic: Making sure I did not mess up my firewall protection [SOLVED]
Replies: 16
Views: 1706

Re: Making sure I did not mess up my firewall protection [SOLVED]

If you have vlan20 as a vlan, and its attached to ether2, why is ether2 still part of the bridge. Suggesting it should be removed but not until we know its purpose............what device is being connected too?? (1) Ensure you add the vlan to the LAN list /interface list member add comment=defconf i...
by anav
Sat Nov 06, 2021 10:11 pm
Forum: General
Topic: Merge 2 ISP bandwidth into one
Replies: 9
Views: 791

Re: Merge 2 ISP bandwidth into one

The discher PDF works for all cases as it more closely controls traffic flow incoming and outgoing and doesnt rely on ISP characteristics or handling.
Its what I would choose.
by anav
Sat Nov 06, 2021 10:08 pm
Forum: General
Topic: Paste image
Replies: 2
Views: 347

Re: Paste image

...
by anav
Sat Nov 06, 2021 6:07 pm
Forum: RouterOS v7 BETA
Topic: Wireguard Connection between two sites [SOLVED]
Replies: 22
Views: 2120

Re: Wireguard Connection between two sites [SOLVED]

Sorry cannot help on the openwrt side of the house but the RB5009 as a client wireguard device is straightforward. WG Setup WG settings -Give WG interface a name, lets call it WG-Client -Listen port NOT required -Private key (internal use only) -Public key (needed on Openwrt setup) Peer settings -In...
by anav
Sat Nov 06, 2021 3:55 am
Forum: General
Topic: Routing LAN and VLANs [SOLVED]
Replies: 14
Views: 982

Re: Routing LAN and VLANs [SOLVED]

Glad you found some success RenzoG.
by anav
Sat Nov 06, 2021 3:53 am
Forum: Beginner Basics
Topic: VLAN configuration RB4011IGS+RM once again
Replies: 8
Views: 949

Re: VLAN configuration RB4011IGS+RM once again

Thanks for the extensive review. First of all: In general it's now working and I can go on going into details. Trunk ports are fine and on the access ports DHCP is giving me an IP depending on the VLAN of the access port. Thanks! Regarding your points (1) TBH Still new to the whole stuff. Different...
by anav
Sat Nov 06, 2021 3:46 am
Forum: General
Topic: Isolate IoT devices with hAP AC2 as main router
Replies: 13
Views: 1094

Re: Isolate IoT devices with hAP AC2 as main router

Hi johnster, Much depends upon the capabilities of those other devices. For example I have four APs in my house, a. TPLINK eap245 (smart) b. TPLINK 660HD (smart) c. MT capac (smart). d. wifi router onlly using its wifi (dumb) What I mean by smart is that I can assign more than one 2.4 SSID and more ...
by anav
Fri Nov 05, 2021 8:44 pm
Forum: Wireless Networking
Topic: Virtual WIFI and VLAN's - driving me crazy
Replies: 36
Views: 2314

Re: Virtual WIFI and VLAN's - driving me crazy

My advice regarding any wifi pertains to a non capsman setup. For the life of me I dont understand why you keep trying to add capsman as it adds needless complexity. Just get the vlan to work first, as per the linked reference. If you need capsman after that, then add it..........at your own risk LO...
by anav
Fri Nov 05, 2021 6:44 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8617

Re: Mikrotik router Hacked!!!

There is a difference between a homeowner being protected by such password rules.........
and a trained admin who should know how to configure a router securely. The EU rules are for the untrained masses.
by anav
Fri Nov 05, 2021 6:40 pm
Forum: General
Topic: Routing LAN and VLANs [SOLVED]
Replies: 14
Views: 982

Re: Routing LAN and VLANs [SOLVED]

Anav, thank you so much for your infos, very very helpful. So: 1) I corrected network class, in DHCP network from 192.168.0.0/16 to 192.168.0.0/22, to accomplish range I need from 192.168.3.1 to 192.168.5.254. I hope this is right. 2) I added VoIP and Hotspot networks into LAN interface list (I did...
by anav
Fri Nov 05, 2021 6:34 pm
Forum: Beginner Basics
Topic: How to configure VLAN?
Replies: 9
Views: 846

Re: How to configure VLAN?

It will be helpful to post your complete config when done. /export hide-sensitive file=anynameyouwish AND.... A network diagram showing the physical connections between them (vlans etc to which ports) including down to PCs, Access points, Switches etc........ IN that regard we can match up the confi...
by anav
Fri Nov 05, 2021 6:32 pm
Forum: Beginner Basics
Topic: RouterOS v7.0.5 Dual PPPoE Wan Setup.
Replies: 15
Views: 1452

Re: RouterOS v7.0.5 Dual PPPoE Wan Setup.

Looks good, but sorry out of ideas.
A fresh look at this may be best from another poster.........
by anav
Fri Nov 05, 2021 6:29 pm
Forum: Beginner Basics
Topic: Vlan blocking and communication between vlanes
Replies: 4
Views: 610

Re: Vlan blocking and communication between vlanes

Your configuration is very confusing and probably all wrong.
Why not use one bridge.
Assign all ports to it (except for the wan port of course)
Assign vlans to the bridge
and follow this guide.........


viewtopic.php?t=143620
by anav
Thu Nov 04, 2021 11:11 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8617

Re: Mikrotik router Hacked!!!

I know.
Still learning that part too :lol:
Well, anybody that calls themselves an admin is allowed to make mistakes but when
they repeat the same mistakes after being given information on how to avoid it............................ blunt is less refined but more appropriate.
by anav
Thu Nov 04, 2021 11:07 pm
Forum: Beginner Basics
Topic: resetting mikrotik without losing remote access
Replies: 2
Views: 505

Re: resetting mikrotik without losing remote access

If you have lots of devices with that issue then perhaps this is something that can be solved by dude, or something similiar.....
viewtopic.php?t=180030
by anav
Thu Nov 04, 2021 11:03 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8617

Re: Mikrotik router Hacked!!!

Adding an analogy, maybe it will become more clear: Water is pouring from the tap, sink is spilling over. What do you do first ? Clean up the spilled water or close the tap ? Right now it looks like you're only cleaning... you'll keep doing that until you close the tap. A much kinder way of saying ...
by anav
Thu Nov 04, 2021 11:02 pm
Forum: General
Topic: Routing LAN and VLANs [SOLVED]
Replies: 14
Views: 982

Re: Routing LAN and VLANs [SOLVED]

Wow, so you get PPOE internet over the wireless connection. Thats brave! Then you with the same device are running a hotspot and have queueus............ not to mention voip. This device is a low cost board meant to be a CPE device not a full fledged router but its cool what you are trying to do. I ...
by anav
Thu Nov 04, 2021 10:30 pm
Forum: Beginner Basics
Topic: Why is my CAPsMAN network not as good as I hope for?
Replies: 25
Views: 2739

Re: Why is my CAPsMAN network not as good as I hope for?

Too funny I moved off of zyxel (and a reseller) many moon ago and migrated to a better bang for the buck in Mikrotik routers. Yes they took a bit more brain power to config but very doable. If I can do it, so can you. The default settings are pretty decent from the getgo. If you want to make adjustm...
by anav
Thu Nov 04, 2021 5:10 pm
Forum: General
Topic: Merge 2 ISP bandwidth into one
Replies: 9
Views: 791

Re: Merge 2 ISP bandwidth into one

Its the dummies guide and best document for Load balancing I have run across.
by anav
Thu Nov 04, 2021 5:09 pm
Forum: General
Topic: "safe" EoIP tunnel
Replies: 2
Views: 389

Re: "safe" EoIP tunnel

I suspect MTU ugly ugly issues..........
by anav
Thu Nov 04, 2021 5:08 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8617

Re: Mikrotik router Hacked!!!

Yes, stop using infected routers. You need to install fresh netinstall latest firmware. Use different passwords etc....... CHANGE ALL YOUR VPN settings, everything should be different from before. Assume all passwords and secrets of all settings are known. The only way you are being hacked is if you...
by anav
Thu Nov 04, 2021 5:03 pm
Forum: Beginner Basics
Topic: RouterOS v7.0.5 Dual PPPoE Wan Setup.
Replies: 15
Views: 1452

Re: RouterOS v7.0.5 Dual PPPoE Wan Setup.

HAHA you blew the mangling copy.................... The only thing you have correct is the first two lines. The rest was not changed to what I had recommended. Can lead a horse to water................. /ip firewall mangle add action=accept chain=prerouting in-interface=pppoe-out1 add action=accept ...
by anav
Thu Nov 04, 2021 4:25 pm
Forum: RouterOS v7 BETA
Topic: Wireguard Connection between two sites [SOLVED]
Replies: 22
Views: 2120

Re: Wireguard Connection between two sites [SOLVED]

So, first off, I have to confess a grievous sin. I thought that the work router was directly bridged to the internet, but it turns out that the last time my ISP had someone here, he reconfigured the routers. So, there was actually not a direct connection from my work (WRT) router to the internet. T...
by anav
Thu Nov 04, 2021 3:36 pm
Forum: Wireless Networking
Topic: Battery life for iOS devices with wAP ac
Replies: 6
Views: 1013

Re: Battery life for iOS devices with wAP ac

A better test would have been the TP Link EAP245.
This is a wifi5 device like the capac but peforms way better and has a reasonable form factor.
I have one in the house (and a 660HD - high and out of sight LOL) and one at the mother in-laws house all working very very well.
by anav
Thu Nov 04, 2021 3:33 pm
Forum: General
Topic: Merge 2 ISP bandwidth into one
Replies: 9
Views: 791

Re: Merge 2 ISP bandwidth into one

Thats funny, never seen load balancing for dual wan setups or more, without mangling.
Here is one such example..............

https://mum.mikrotik.com/presentations/US12/steve.pdf
by anav
Thu Nov 04, 2021 3:31 pm
Forum: General
Topic: ISPApp: MikroTik Cloud Management
Replies: 9
Views: 859

Re: ISPApp: MikroTik Cloud Management

Hi Joe, I am looking into this and I think there are some automated scripts that the service provides to access and view router/device info, but they provide a third party script server so that one can host whatever script they want to store so that it runs on all the routers. Just guessing from my ...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 31