Community discussions

MikroTik App

Search found 6587 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 22
by anav
Mon Apr 12, 2021 9:37 pm
Forum: General
Topic: Mangle or firewall rule
Replies: 2
Views: 134

Re: Mangle or firewall rule

I'm going to restrict access to a specific destinations based on source Mac address. I have two solution. 1. using mangle for marking connections and Policy Base Routing 2. Restrict access with some firewall rule and without mangle and Policy Base Routing Which one is better? Which one is more reso...
by anav
Mon Apr 12, 2021 9:32 pm
Forum: Beginner Basics
Topic: hEX-S "advanced" setup with VLANs, dynamic DNS, CAPsMAN, etc.
Replies: 7
Views: 322

Re: hEX-S "advanced" setup with VLANs, dynamic DNS, CAPsMAN, etc.

Hi @anav The diagram is great! I only had one question, where is the guest wifi coming from?? (AP device?) Glad you like the diagram! It should make setup easier to work through and make maintenance / expansion easier to understand / plan! Yes, guest Wi-Fi should be available on each wAP-AC device ...
by anav
Mon Apr 12, 2021 6:12 pm
Forum: General
Topic: Firewall input chain and broadcast packets
Replies: 1
Views: 176

Re: Firewall input chain and broadcast packets

If you are connecting to the internet just fine and users are not complaining, then why open up your router to garbage. Drop all is fine.
Near identical is not identical and one rule can make a huge difference.
by anav
Mon Apr 12, 2021 6:07 pm
Forum: General
Topic: Dual WAN failover using recursive routing
Replies: 2
Views: 233

Re: Dual WAN failover using recursive routing

The best guide is reading this thread! It seems you have half an implementation there of using recursive. The Thread will help sort you out.
viewtopic.php?f=23&t=157048
by anav
Mon Apr 12, 2021 6:05 pm
Forum: Beginner Basics
Topic: VLANs with hybrid ports, trunks and 2 different WiFi networks
Replies: 1
Views: 69

Re: VLANs with hybrid ports, trunks and 2 different WiFi networks

Router: (WLAN2) remove wireless entry vlan-mode=use tag and vlan identification. It should be NO tag and default of vlan1 left there Router: VLANs should be associated with the Bridge when making the vlans, and not with the WLANs. Router: One dhcp pool per subnet, you have overlapping pools and Its ...
by anav
Mon Apr 12, 2021 5:27 pm
Forum: Beginner Basics
Topic: Proper Management VLAN Setup requested?
Replies: 1
Views: 83

Re: Proper Management VLAN Setup requested?

The description you gave however muddled, is a bit helpful as is a diagram but really need your config to see what is going on.
/export hide-sensitive file=anynameyouwish
by anav
Mon Apr 12, 2021 4:07 pm
Forum: Beginner Basics
Topic: hEX-S "advanced" setup with VLANs, dynamic DNS, CAPsMAN, etc.
Replies: 7
Views: 322

Re: hEX-S "advanced" setup with VLANs, dynamic DNS, CAPsMAN, etc.

Pretty basic vlan setup required. The longest times will be spent on creating the DHCP setup for each VLAN (ip address, ip pool, dhcp-server, dhcp-server-network) Getting your bridge port and bridge vlan configuration correct. Getting the switch netgear setup to match the vlan setup coming from the ...
by anav
Mon Apr 12, 2021 3:04 pm
Forum: Beginner Basics
Topic: hEX-S "advanced" setup with VLANs, dynamic DNS, CAPsMAN, etc.
Replies: 7
Views: 322

Re: hEX-S "advanced" setup with VLANs, dynamic DNS, CAPsMAN, etc.

The diagram is great! I only had one question, where is the guest wifi coming from?? (AP device?)
by anav
Mon Apr 12, 2021 2:40 am
Forum: General
Topic: Wireguard fails to work [SOLVED]
Replies: 2
Views: 163

Re: Wireguard fails to work [SOLVED]

Why are you posting here, thats a beta firmware issue!!
Search the threads to see if there is already a similar thread or start your own.
viewforum.php?f=1
by anav
Sun Apr 11, 2021 2:43 pm
Forum: Wireless Networking
Topic: Suggested additional APs (CAPsMAN)
Replies: 3
Views: 344

Re: Suggested additional APs (CAPsMAN)

I use the eap245 as standalone units just like I do capacs and its not a problem.
No need for added complexity.
by anav
Sun Apr 11, 2021 2:23 pm
Forum: Beginner Basics
Topic: blocking devices off your network
Replies: 17
Views: 1033

Re: blocking devices off your network

Curious as to where you got the idea that mikrotik were consumer dumbed down devices??
The config seems okay on a quick view.
by anav
Sun Apr 11, 2021 12:07 am
Forum: General
Topic: 2 DHCP Server, 2 VLAN, 1 eth IF
Replies: 1
Views: 216

Re: 2 DHCP Server, 2 VLAN, 1 eth IF

THis config is so messy and bloated I dont think there is a quick fix. I would use only one bridge and put all subnets as vlans with interface bridge and each vlan has their own dhcp service. AND start with default firewall rules. Then come back here and explain clearly what is to be allowed for tra...
by anav
Sat Apr 10, 2021 11:49 pm
Forum: Beginner Basics
Topic: blocking devices off your network
Replies: 17
Views: 1033

Re: blocking devices off your network

unless you post your config answers will be hard to come by
/export hide-sensitive file=anynameyouwish
by anav
Sat Apr 10, 2021 8:18 pm
Forum: Wireless Networking
Topic: Suggested additional APs (CAPsMAN)
Replies: 3
Views: 344

Re: Suggested additional APs (CAPsMAN)

If your intent on using WIFI5 devices, suggest the TPLINK eap245.
Stable decent performance. I dont recommend MT wifi current choices.
by anav
Sat Apr 10, 2021 7:22 pm
Forum: General
Topic: CRS328 Temperature high
Replies: 5
Views: 540

Re: CRS328 Temperature high

Makes sense!
From specs: Tested Ambient Temp ---> -20°C to 60°C
by anav
Sat Apr 10, 2021 6:03 pm
Forum: General
Topic: CRS328 Temperature high
Replies: 5
Views: 540

Re: CRS328 Temperature high

Does it have fans?
If not purchase some to blow air in and suck air out........
by anav
Sat Apr 10, 2021 4:53 pm
Forum: Beginner Basics
Topic: Issue with my network setup
Replies: 43
Views: 2427

Re: Issue with my network setup

As you had warned CRS112 became unstable when i connected multiple devices with frequent connections drops. As some of you had recommended I am planning to use CRS112 as a PoE switch and buy another router. Need your advice on the router , will a hEX router suffice for me? This is for a home setup ...
by anav
Sat Apr 10, 2021 3:50 pm
Forum: General
Topic: Port forwarding from a different subnet
Replies: 15
Views: 877

Re: Port forwarding from a different subnet

Good to hear, I suspected it has nothing to do with the MT but more so configuring the ISP modem router.
by anav
Sat Apr 10, 2021 2:37 pm
Forum: General
Topic: Tools/email and ports
Replies: 3
Views: 400

Re: Tools/email and ports

So all you are saying is that 465 is to be no longer user for SMPT and one should use 587. However I fail to see how this makes email traffic any more or less secure because that is what I care about more than some organization telling me what I can and cannot use ports for LOL. If 587 was magically...
by anav
Sat Apr 10, 2021 1:14 pm
Forum: General
Topic: Tools/email and ports
Replies: 3
Views: 400

Re: Tools/email and ports

All I know is it works fine with my ISP provider??
My ISP provider requires 465 by the way.
Also my settings are start TLS=tls only
by anav
Sat Apr 10, 2021 1:10 pm
Forum: Beginner Basics
Topic: New to MikroTIK
Replies: 7
Views: 570

Re: New to MikroTIK

hi Erk, yup and I already ordered his book on switching https://www.amazon.ca/gp/product/B08ZW38C46/ref=ppx_yo_dt_b_asin_title_o00_s00?ie=UTF8&psc=1 Hi anav, I took MTCNA, MTCRE, MTCINE, MTCTCE, MTCSE and MTCWE from him in udemy, unfortunately he doesn't have MTCSWE courses yet. Mind to share t...
by anav
Sat Apr 10, 2021 3:01 am
Forum: General
Topic: ac2 vs ac3 wifi not over 200Mb
Replies: 13
Views: 914

Re: ac2 vs ac3 wifi not over 200Mb

Buyer beware, I would have recommended the wired version of the RB4011 if you had asked.
by anav
Sat Apr 10, 2021 3:00 am
Forum: General
Topic: sfp-sfpplus1 FCS error on link - SFP+ ERROR FCS
Replies: 1
Views: 195

Re: sfp-sfpplus1 FCS error on link - SFP+ ERROR FCS

I had no luck with my sfp+ port using an SJR10+ ethernet cage attached to my CCR1009 connecting to FIbre OP modem.
The modem has fibre in and ethernet out.

I think the CCR1009 SFP+ is broken. :-(
by anav
Fri Apr 09, 2021 11:44 pm
Forum: General
Topic: ac2 vs ac3 wifi not over 200Mb
Replies: 13
Views: 914

Re: ac2 vs ac3 wifi not over 200Mb

Regardless of the wifi 5 devices, advertised speeds are two way without consideration of tx loss. So whether its tplink or MT etc........... an 866 advertised should yield around 290, if you do better great but one needs to temper expectations. similarly advertised of 1300 should yield around 433, e...
by anav
Fri Apr 09, 2021 8:58 pm
Forum: General
Topic: MacTelnet-Client
Replies: 11
Views: 2510

Re: MacTelnet-Client

Anyway, a working mac-telnet from linux terminal would be very handy.
Mikrotik, please share information about authentication mechanism. You do not need to provide any code, just share that information!
+1
Avatar for mkx!!
mkx.jpg

If you poke him hard enough he falls over. ;-)
by anav
Fri Apr 09, 2021 8:40 pm
Forum: Beginner Basics
Topic: Connect switch and router via SFP - partially working [SOLVED]
Replies: 7
Views: 465

Re: Connect switch and router via SFP - partially working [SOLVED]

No wasnt aware that the large switch setups with sWOS dont have a config to export.....

Any switch setups with swOS only have one type of human-readable configuration export: the graphical one.
Ahh the snipping tool! :-)
by anav
Fri Apr 09, 2021 8:39 pm
Forum: Beginner Basics
Topic: Port forwarding not working?
Replies: 17
Views: 792

Re: Port forwarding not working?

Your set of extra rules and splunk has little worth to this thread???? I was merely pointing out that the OP already has a firewall rule in place to permit Wan to LAN dst nat traffic and that your suggesting was not only confusing but it assumed he had a drop all end rule which he does not. Call it ...
by anav
Fri Apr 09, 2021 7:02 pm
Forum: General
Topic: Slow speed for marked traffic through WAN2
Replies: 4
Views: 294

Re: Slow speed for marked traffic through WAN2

DONT DISABLE FIREWALL RULES IF CONNECTED TO THE INTERNET>......................... As for fastrack yes, mangling and fastrack dont work well together. However there is a better easier way to accomplish what you want WITHOUT MANGLING which is always better as you can leave fastrack rule up and runnin...
by anav
Fri Apr 09, 2021 6:41 pm
Forum: Beginner Basics
Topic: Connect switch and router via SFP - partially working [SOLVED]
Replies: 7
Views: 465

Re: Connect switch and router via SFP - partially working [SOLVED]

Thanks. I was just ready to post the router config, and did some more troubleshooting. Seems I had 2 bad cables. The third one worked. BTW, the CSS switches run SWOS, not RouterOS. I don't believe there is any option to dump the config to a file. There is a backup, but that is not really human read...
by anav
Fri Apr 09, 2021 6:34 pm
Forum: Beginner Basics
Topic: Port forwarding not working?
Replies: 17
Views: 792

Re: Port forwarding not working?

(1) Looking okay for the most part. Remove the source address, not required. See if it works after this removal. add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface-list=WAN \ src-address=10.10.0.0/24 (2) Only have winbox-mac setup, the stan...
by anav
Fri Apr 09, 2021 5:34 pm
Forum: General
Topic: Tagging Untagged VLAN From Other Devices
Replies: 3
Views: 352

Re: Tagging Untagged VLAN From Other Devices

A single cable can carry lots of vlans and how they are handled are determined by the equipment at either end. So other than going and renting a large Drill (anything is possible if you really want to do it), using vlans is a viable option. Need to see your configs (both).... to make any design reco...
by anav
Fri Apr 09, 2021 3:35 pm
Forum: General
Topic: ac2 vs ac3 wifi not over 200Mb
Replies: 13
Views: 914

Re: ac2 vs ac3 wifi not over 200Mb

866/3 = 288 should be doable in LOS scenario.
by anav
Fri Apr 09, 2021 1:54 pm
Forum: Beginner Basics
Topic: MIKROTIK TO UISP FULL INTEGRATION
Replies: 1
Views: 152

Re: MIKROTIK TO UISP FULL INTEGRATION

Ever heard of flogging a dead horse. If you have been searching for a decade you should simply have visited Latvia and talked to MT staff directly.
Besides your in the wrong forum suggest this one..........
https://www.reddit.com/r/Ubiquiti/
by anav
Fri Apr 09, 2021 1:51 pm
Forum: Beginner Basics
Topic: Issue with my network setup
Replies: 43
Views: 2427

Re: Issue with my network setup

Yes i am using CRS112 as a router. FIOS is also a router for now as i look out for options to change that. Is your suggestion to use FIOS as router and keep CRS112 as switch for better performance? I tried with one device connected to CRS112 and i dont see any degrade but its possible that CRS112 m...
by anav
Fri Apr 09, 2021 3:24 am
Forum: General
Topic: Dst.Address
Replies: 1
Views: 134

Re: Dst.Address

/export hide-sensitive file=anynameyouwish
by anav
Fri Apr 09, 2021 3:22 am
Forum: Beginner Basics
Topic: Accessing clients / servers across different VLANs (printer, USB server, NAS, ...)
Replies: 4
Views: 237

Re: Accessing clients / servers across different VLANs (printer, USB server, NAS, ...)

Why start another thread as I dealt with your firewall rules here....... https://forum.mikrotik.com/viewtopic.php?f=13&t=174254 In my opinion you dont need to delineate ports or protocols of that access as I dont think the printer can do much harm. Basically with a drop all rule at the end of th...
by anav
Fri Apr 09, 2021 3:13 am
Forum: Beginner Basics
Topic: Port forwarding not working?
Replies: 17
Views: 792

Re: Port forwarding not working?

Thank you.. I found this (https://wiki.mikrotik.com/wiki/Hairpin_NAT). I'm going to try to follow along with this.. And see if I can't make it work. If not I'll come back and bug you some more. Thanks again for all the help Dont waste your time, I covered completely the best ways to handle hairpin ...
by anav
Fri Apr 09, 2021 3:10 am
Forum: Beginner Basics
Topic: NTP setup with VLANs
Replies: 6
Views: 406

Re: NTP setup with VLANs

Well stated pelch1, its a service provided by the router so handled in input chain and the Gateway links in the vlans point to the router as noted.
by anav
Fri Apr 09, 2021 3:07 am
Forum: Beginner Basics
Topic: DNS problem
Replies: 8
Views: 683

Re: DNS problem

I just wanted to add this: As you enabled the setting to allow remote DNS query, Make sure to drop any incoming traffic from WAN on port 53 TCP/UDP as anyone can use your DNS service and may be used it to attack others or your own router. /ip firewall nat add action=redirect chain=dstnat src-addres...
by anav
Fri Apr 09, 2021 3:02 am
Forum: Beginner Basics
Topic: Port forwarding not working?
Replies: 17
Views: 792

Re: Port forwarding not working?

Seems like this should work for you at the moment. One thing I would change is the following no access via unprotected mac address access, keep only mac winbox active. FROM /tool mac-server set allowed-interface-list=LAN /tool mac-server mac-winbox set allowed-interface-list=LAN TO /tool mac-server ...
by anav
Thu Apr 08, 2021 10:13 pm
Forum: Beginner Basics
Topic: NTP setup with VLANs
Replies: 6
Views: 406

Re: NTP setup with VLANs

Feedback. Get rid of VLAN1 it serves no purpose. (1) I dont have Snooping DHCP or IGMP on my bridge, and just wondering what is the value of those settings?? (2) We do not identify vlans in the wirless settings themselves. We associate the vlans to the Bridge ports (ether ports or WLAN ports). inter...
by anav
Thu Apr 08, 2021 7:07 pm
Forum: Beginner Basics
Topic: Connect switch and router via SFP - partially working [SOLVED]
Replies: 7
Views: 465

Re: Connect switch and router via SFP - partially working [SOLVED]

Without seeing the configs on the router and switch not much can be done. Ok, please tell me what you would like to see. Screen shots? something else? The configs LOL /export hide-sensitive file=anynameyouwish Download from files, in winbox and open in notepadd++ paste here and use the code icons (...
by anav
Thu Apr 08, 2021 7:05 pm
Forum: Beginner Basics
Topic: New to MikroTIK
Replies: 7
Views: 570

Re: New to MikroTIK

hi Erk, yup and I already ordered his book on switching

https://www.amazon.ca/gp/product/B08ZW3 ... UTF8&psc=1
by anav
Thu Apr 08, 2021 7:03 pm
Forum: Beginner Basics
Topic: Port forwarding not working?
Replies: 17
Views: 792

Re: Port forwarding not working?

Once the above is setup then we can tackle hairpin nat!! By the way if you put your server on a third subnet by itself. Lets say the server is on ether4 port, Then remove ether 4 from the bridge and simply associate the server with ether4 Or create a bridge for the server. In this way all home users...
by anav
Thu Apr 08, 2021 6:56 pm
Forum: Beginner Basics
Topic: Port forwarding not working?
Replies: 17
Views: 792

Re: Port forwarding not working?

Hi there, Yes all etherports (and wlans are considered wireless etherports) should be on the bridge. IN GENERAL! but we have to take a look at your specific case see (2) below. One only needs one FIREWALL RULE, which basically states to the router allow all NAT traffic heading towards your router. I...
by anav
Thu Apr 08, 2021 5:23 pm
Forum: Beginner Basics
Topic: VLAN setup with RouterOS v6.48.1 on hAP lite (952Ui-5ac2nD)
Replies: 1
Views: 105

Re: VLAN setup with RouterOS v6.48.1 on hAP lite (952Ui-5ac2nD)

First advice - read this best link on vlans https://forum.mikrotik.com/viewtopic.php?f=23&t=143620 Second once you have a config to look at based on the above, please post it here, the pics are not always that helpful and frankly I dont bother hurting my eyes. /export hide-sensitive file=anyname...
by anav
Thu Apr 08, 2021 5:19 pm
Forum: Beginner Basics
Topic: Port forwarding not working?
Replies: 17
Views: 792

Re: Port forwarding not working?

Once you have cleaned up the config then you may be ready to try this.......... but recommend you post your config first for a review. Here is the short explanation. You have come across the need for loopback called in the MT world, HairpinNAT. This occurs when users on the same LAN as a server are ...
by anav
Thu Apr 08, 2021 5:17 pm
Forum: Beginner Basics
Topic: Port forwarding not working?
Replies: 17
Views: 792

Re: Port forwarding not working?

Hi enos, then you are probably also dealing with hairpin nat and will need to modify your setup.
However prefer to see you working from a fixed up config as all the other noise may get in the way.
by anav
Thu Apr 08, 2021 1:49 pm
Forum: Beginner Basics
Topic: Port forwarding not working?
Replies: 17
Views: 792

Re: Port forwarding not working?

Get rid of this. Its rarely used and can cause issues. Just use the normal and default firewall rules for traffic control at layer 3. /Interface bridge filter # no interface add action=drop chain=forward in-interface=*A # no interface add action=drop chain=forward out-interface=*A add action=drop ch...
by anav
Thu Apr 08, 2021 1:39 pm
Forum: Beginner Basics
Topic: Connect switch and router via SFP - partially working [SOLVED]
Replies: 7
Views: 465

Re: Connect switch and router via SFP - partially working [SOLVED]

Without seeing the configs on the router and switch not much can be done.
by anav
Wed Apr 07, 2021 11:34 pm
Forum: Beginner Basics
Topic: NTP setup with VLANs
Replies: 6
Views: 406

Re: NTP setup with VLANs

/export hide-sensitive file=anynameyouwish

should be resolved quickly once viewed.
by anav
Wed Apr 07, 2021 7:08 pm
Forum: Beginner Basics
Topic: Add an Access Point to my home installation ... how ?
Replies: 7
Views: 360

Re: Add an Access Point to my home installation ... how ?

ETH-7: Here the access point should be connected (via PWR-LINE PRO) WLAN-1 2.4GHz: SSID "HomeBase", frequency 2437, ACL WLAN-2 5GHz: SSID "HomeBase", frequency 5180, ACL Virtual AP 2.4GHz: SSID "Homeautomation-24". Virtual AP 5GHz: SSID "Homeautomation-50" Vi...
by anav
Wed Apr 07, 2021 6:44 pm
Forum: Beginner Basics
Topic: Add an Access Point to my home installation ... how ?
Replies: 7
Views: 360

Re: Add an Access Point to my home installation ... how ?

Then how were you expecting to move all those WLAN networks to another device?? Trust me its not that complicated and it makes life actually easier during the config. You define the vlans in the router (interface is bridge-router) You create the dhcp networks for the vlans (same as you would for a t...
by anav
Wed Apr 07, 2021 5:55 pm
Forum: Beginner Basics
Topic: Add an Access Point to my home installation ... how ?
Replies: 7
Views: 360

Re: Add an Access Point to my home installation ... how ?

OK, thx :-) IP Range in Router is 192.168.0.0/24 ... router IP is 192.168.0.1 ... so IP Range in AP is the same ? br, Richard PS: does the WISP "quick set" set device address DHCP from wired ? ... so the the main router is DHCP for the clients connected to the AP ? Basically yes, assuming...
by anav
Wed Apr 07, 2021 4:59 pm
Forum: Beginner Basics
Topic: Add an Access Point to my home installation ... how ?
Replies: 7
Views: 360

Re: Add an Access Point to my home installation ... how ?

Nope dont need capsman. Use ether2 to setup the capac and use ether1 to power the capac while configuring. Ether2 is the default connection on 192.168.88.1 network. Keep all that as you will be able to troubleshoot the capac independently of the bridge setup. I typically put the capac into WISP mode...
by anav
Wed Apr 07, 2021 4:00 pm
Forum: Wireless Networking
Topic: POE Surge protection test!
Replies: 4
Views: 1005

Re: POE Surge protection test!

An independent review my ass.................
by anav
Wed Apr 07, 2021 2:20 pm
Forum: Beginner Basics
Topic: New to MikroTIK
Replies: 7
Views: 570

Re: New to MikroTIK

by anav
Wed Apr 07, 2021 2:16 pm
Forum: Beginner Basics
Topic: VLANs, trunk ports and vlan interfaces
Replies: 3
Views: 384

Re: VLANs, trunk ports and vlan interfaces

viewtopic.php?f=23&t=143620

Obviously CISCO is obsolete then! ;-)

Also, hot off the press.....
https://www.youtube.com/watch?v=v9GBZMmMBYA.
by anav
Tue Apr 06, 2021 9:23 pm
Forum: Beginner Basics
Topic: Can't access hosts via certain ports from a computer connected to an hEX-S
Replies: 24
Views: 1163

Re: Can't access hosts via certain ports from a computer connected to an hEX-S

Question above me, in that I have always thought bridges were software driven entities not hardware.
I like to keep it simple, one bridge is enough, just like one woman is enough!!
by anav
Tue Apr 06, 2021 6:04 pm
Forum: Beginner Basics
Topic: Yet another VLAN issues topic...
Replies: 7
Views: 514

Re: Yet another VLAN issues topic...

Normally one configures the switch for VLANS.
by anav
Tue Apr 06, 2021 6:01 pm
Forum: Beginner Basics
Topic: Default Configuration
Replies: 3
Views: 245

Re: Default Configuration

What is important to understand is that the default firewall rules let you work out of the box safely. The input chain rules are for traffic to and from the router from LAN or Internet (think changing router configuration or accessing router services (DNS, NTP, IPSEC, etc.....). The forward chain is...
by anav
Tue Apr 06, 2021 5:37 pm
Forum: Beginner Basics
Topic: Dynamic DNS remove
Replies: 5
Views: 285

Re: Dynamic DNS remove

DOH doesnt work yet from what I understand.
DoH works, but have a memory leakage in all current version of RouterOS
Well yes to be accurate, but are you recommending using it, NO, :-)
by anav
Tue Apr 06, 2021 1:15 pm
Forum: Beginner Basics
Topic: Dynamic DNS remove
Replies: 5
Views: 285

Re: Dynamic DNS remove

client1.jpg
client2.jpg
by anav
Tue Apr 06, 2021 1:07 pm
Forum: Beginner Basics
Topic: Can't access hosts via certain ports from a computer connected to an hEX-S
Replies: 24
Views: 1163

Re: Can't access hosts via certain ports from a computer connected to an hEX-S

All doable Gluck! will be here when you need help!!
by anav
Tue Apr 06, 2021 1:01 pm
Forum: Beginner Basics
Topic: UPnP not working?
Replies: 1
Views: 114

Re: UPnP not working?

Not quite everything.
Apparently upnp is a service that the router provides and thus needs INPUT CHAIN rule allowing upnp from LAN.

add chain=input action=accept ( in-interface-list=LAN OR in-interface=subnet ) and source-address=server
by anav
Tue Apr 06, 2021 2:49 am
Forum: General
Topic: Looking for a little help for my tiny ISP
Replies: 1
Views: 160

Re: Looking for a little help for my tiny ISP

Not the place to ask. Please visit the consultants in your area and contact them. https://mikrotik.com/consultants I know mikrotik has a hotspot mechanism already so not sure how much more work is entailed in setting up accounts, but you may be able to do all without a third party??? https://help.mi...
by anav
Tue Apr 06, 2021 2:44 am
Forum: Beginner Basics
Topic: Dynamic DNS remove
Replies: 5
Views: 285

Re: Dynamic DNS remove

DOH doesnt work yet from what I understand.
by anav
Tue Apr 06, 2021 12:14 am
Forum: Wireless Networking
Topic: How to enable Bridge VLAN Filtering on a wireless access-list rule?
Replies: 9
Views: 366

Re: How to enable Bridge VLAN Filtering on a wireless access-list rule?

(1) What you should conclude is that you either didnt read the reference URL or didnt understand it......... (2) Also very few people use firewall on the bridge its very tricky and causes issues. Why do you need to use this setting vice the normal firewall rules?? /interface bridge settings set use-...
by anav
Mon Apr 05, 2021 11:58 pm
Forum: Beginner Basics
Topic: Multiple wan without failover but routing different lans through their own connection
Replies: 9
Views: 504

Re: Multiple wan without failover but routing different lans through their own connection

Okay so its working for the most part. (1) Did you fix the sourcenat rules as suggested? (2) HERE could be the issue! From From /ip dhcp-server network add address=10.10.0.0/24 gateway=10.10.0.1 add address=10.10.1.0/24 gateway=10.10.1.1 TO /ip dhcp-server network add address=10.10.0.0/24 gateway=10...
by anav
Mon Apr 05, 2021 9:27 pm
Forum: Wireless Networking
Topic: How to enable Bridge VLAN Filtering on a wireless access-list rule?
Replies: 9
Views: 366

Re: How to enable Bridge VLAN Filtering on a wireless access-list rule?

Please dont use vlanid1 for anything other than the default pvid setting on the bridge.
The best source for vlan documentation is viewtopic.php?f=23&t=143620
by anav
Mon Apr 05, 2021 8:23 pm
Forum: General
Topic: marking packets to an external gateway
Replies: 2
Views: 182

Re: marking packets to an external gateway

For me the easiest would be for linux admin to assign vlan tags to your traffic,

Then all you have to do is assign the vlan to the ethernet interface and the connection is made.......
by anav
Mon Apr 05, 2021 8:14 pm
Forum: Beginner Basics
Topic: Multiple wan without failover but routing different lans through their own connection
Replies: 9
Views: 504

Re: Multiple wan without failover but routing different lans through their own connection

Just out of curiosity is the 10.10.1.0 traffic going out ISP2?? Routes and Route rules are for going out the router, not internal routing so I have no clue of what you are trying to accomplish with winbox?? Going back to first post...... IdeallyI would like these two networks to be separated from ea...
by anav
Mon Apr 05, 2021 5:37 pm
Forum: Wireless Networking
Topic: ipone and sonos
Replies: 9
Views: 659

Re: ipone and sonos

Update the firmware and to get your network going, dont use capsman (at least for now), and it only adds complexity to a config and more work for the router and IMHO not worth it unless one has many access points. Talk less update more! ;-)
by anav
Mon Apr 05, 2021 5:32 pm
Forum: General
Topic: Transparent hEX S to change vlan-priority for DHCP request only
Replies: 19
Views: 1448

Re: Transparent hEX S to change vlan-priority for DHCP request only

Mikrotik support for ONT SFPs is non existent so some might work and most don't. Even compatibility with "normal" SFPs is incomplete (mildly put). Which means that trying to get ONT SFP to work with any MT device is similar to trying to win a jackpot, even if particular ONT SFP works with...
by anav
Mon Apr 05, 2021 5:29 pm
Forum: Beginner Basics
Topic: VLAN Filter - how do ingress and egress rules work?
Replies: 15
Views: 767

Re: VLAN Filter - how do ingress and egress rules work?

So you mean this is correct....... https://networkdirection.net/articles/network-theory/taggeduntaggedandnativevlans/ https://networkengineering.stackexchange.com/questions/6483/why-and-how-are-ethernet-vlans-tagged http://www.firewall.cx/networking-topics/vlan-networks/219-vlan-tagging.html and of ...
by anav
Sun Apr 04, 2021 11:09 pm
Forum: Beginner Basics
Topic: VLAN Filter - how do ingress and egress rules work?
Replies: 15
Views: 767

Re: VLAN Filter - how do ingress and egress rules work?

The best guide for vlans, is
viewtopic.php?f=23&t=143620
If you are having issues please post your config
/export hide-sensitive file=anynameyouwish

and stop using multiple posts for basically the same questions.
by anav
Sun Apr 04, 2021 11:08 pm
Forum: Beginner Basics
Topic: Why is there "Current Tag" & "Current Untagged" in each VLAN
Replies: 6
Views: 454

Re: Why is there "Current Tag" & "Current Untagged" in each VLAN

The best guide for vlans, is
viewtopic.php?f=23&t=143620
If you are having issues please post your config
/export hide-sensitive file=anynameyouwish
by anav
Sun Apr 04, 2021 6:19 pm
Forum: General
Topic: vlan problem on hEX
Replies: 18
Views: 1140

Re: vlan problem on hEX

I suspect your issues are self-caused in having a way too complicated for me to understand dhcp server setup coupled with add firewall rules to the bridge.

What I would do is ensure that a plain jane vanilla setup works and then add in dhcp stuff after...........
by anav
Sun Apr 04, 2021 3:29 pm
Forum: General
Topic: vlan problem on hEX
Replies: 18
Views: 1140

Re: vlan problem on hEX

Would you consider making all VLANs going over the ports........... would make it clearer and cleaner. aka make home subnet vlan10
by anav
Sun Apr 04, 2021 3:22 pm
Forum: Beginner Basics
Topic: Multiple wan without failover but routing different lans through their own connection
Replies: 9
Views: 504

Re: Multiple wan without failover but routing different lans through their own connection

With a quick look, cannot see anything grossly in error?? The IP routes do look a bit out of sorts though.. /ip route add check-gateway=ping distance=5 gateway=WAN-pppoe-ISP1 routing-mark=USE_ISP1 add distance=10 gateway=x.x.x.1 routing-mark=USE_ISP2 add check-gateway=ping distance=5 gateway=WAN-ppp...
by anav
Sun Apr 04, 2021 3:02 pm
Forum: Beginner Basics
Topic: Nev to Mikrotik Routers - 2trunk ports
Replies: 3
Views: 321

Re: Nev to Mikrotik Routers - 2trunk ports

(1) IF it works for you great, if not, then I would recommend not deviating from vlan1 as the default pvid for the bridge (not vlan10). Remember from the guide...... one does not change the default and introduce a different pvid!! # create one bridge, set VLAN mode off while we configure /interface ...
by anav
Sun Apr 04, 2021 1:27 am
Forum: Beginner Basics
Topic: blocking devices off your network
Replies: 17
Views: 1033

Re: blocking devices off your network

Again, describe the situation in sufficient detail.
What devices?
How do they attach to the network to begin with
What is their purpose.
Stop being so obtuse..........
by anav
Sun Apr 04, 2021 1:26 am
Forum: Beginner Basics
Topic: Yet another VLAN issues topic...
Replies: 7
Views: 514

Re: Yet another VLAN issues topic...

/export hide-sensitive file=anynameyouwish
by anav
Sat Apr 03, 2021 9:32 pm
Forum: General
Topic: Multiple Trunk setup performance issues
Replies: 13
Views: 758

Re: Multiple Trunk setup performance issues

/ip firewall filter add action=accept chain=input comment="##INPUT:Allow Winbox from Radu" connection-state="" in-interface-list=WAN src-address-list=Winbox_Allow add action=accept chain=input comment="##INPUT:Allow Established and Related " connection-state=established...
by anav
Sat Apr 03, 2021 9:24 pm
Forum: Beginner Basics
Topic: blocking devices off your network
Replies: 17
Views: 1033

Re: blocking devices off your network

Your requirement is not clear.
Please state what you want users to be able or not able to do.
Please state what you want devices to be able or not able to do....
by anav
Sat Apr 03, 2021 5:05 pm
Forum: General
Topic: Port Forwarding in a Force route with Dual WAN
Replies: 4
Views: 332

Re: Port Forwarding in a Force route with Dual WAN

Your explanation is again not sufficient. I dont see vlans in your diagram and what does winbox have to do with it? Just stated your managment vlan or subnet is X, could be the same as your home vlan/subnet. Please post entire config /export hide-sensitive file=anynameyouwish Winbox has no need to e...
by anav
Sat Apr 03, 2021 3:17 pm
Forum: Wireless Networking
Topic: ipone and sonos
Replies: 9
Views: 659

Re: ipone and sonos

All of the config, many items have interdependencies and only showing bits and pieces is not usually fruitful.
by anav
Sat Apr 03, 2021 2:40 pm
Forum: General
Topic: vlan problem on hEX
Replies: 18
Views: 1140

Re: vlan problem on hEX

(1) Am I to assume that all three ports are going to 'Smart Devices' that can read vlan tags?? /interface bridge port add bridge=bridge-home interface=ether2 add bridge=bridge-home interface=ether3 add bridge=bridge-home interface=ether4 /interface bridge settings set use-ip-firewall-for-vlan=yes /i...
by anav
Sat Apr 03, 2021 2:10 pm
Forum: General
Topic: port 53 open despite firewall rules
Replies: 41
Views: 1863

Re: port 53 open despite firewall rules

Still, would like to see the results of the config I recommended.
That would be more convincing.
by anav
Sat Apr 03, 2021 4:41 am
Forum: General
Topic: port 53 open despite firewall rules
Replies: 41
Views: 1863

Re: port 53 open despite firewall rules

I think your DNS rules are the problem. This works just fine........... THe key here is to only allow the admin to the router itself and only allow USERS on the LAN to access the DNS servers. To accomplish this make sure you construct an allow rule first for the admin to access the router in the inp...
by anav
Fri Apr 02, 2021 3:45 pm
Forum: General
Topic: port 53 open despite firewall rules
Replies: 41
Views: 1863

Re: port 53 open despite firewall rules

Yes, quite correct, the router is alive and has a mind of its own.
You are just a pawn in the evil plans of the router.

Post the complete config
/export hide-sensitive file=anynameyouwish
by anav
Fri Apr 02, 2021 1:33 am
Forum: Beginner Basics
Topic: Multiple wan without failover but routing different lans through their own connection
Replies: 9
Views: 504

Re: Multiple wan without failover but routing different lans through their own connection

Post the config again when you get stuck or have made progress either way.
/export hide-sensitive file=anynameyouwish
by anav
Thu Apr 01, 2021 10:07 pm
Forum: General
Topic: Trying to duplicate a SwOS feature on ROS...
Replies: 15
Views: 2323

Re: Trying to duplicate a SwOS feature on ROS...

I would use vlans......, IP POOL OF 1 or 2, Each bridge port will get a specific PVID. Each bridge port has ingress filtering applied, Where is the issue?? Would have to provide some sort of bw management queuing etc so every vlan had equal access to internet etc....... This is not solution for me....
by anav
Thu Apr 01, 2021 6:50 pm
Forum: General
Topic: Port Forwarding in a Force route with Dual WAN
Replies: 4
Views: 332

Re: Port Forwarding in a Force route with Dual WAN

Diagrams please, when you say "THAT NETWORK" it means nothing!!
Spell out the requirements more clearly as well.
by anav
Thu Apr 01, 2021 6:47 pm
Forum: General
Topic: Trying to duplicate a SwOS feature on ROS...
Replies: 15
Views: 2323

Re: Trying to duplicate a SwOS feature on ROS...

I would use vlans......,
IP POOL OF 1 or 2,
Each bridge port will get a specific PVID.
Each bridge port has ingress filtering applied,
Where is the issue??

Would have to provide some sort of bw management queuing etc so every vlan had equal access to internet etc.......
by anav
Thu Apr 01, 2021 6:43 pm
Forum: Beginner Basics
Topic: Static DNS Not on VLANs
Replies: 3
Views: 307

Re: Static DNS Not on VLANs

If you are using vlan1 stop there and redo your config and follow this guide. https://forum.mikrotik.com/viewtopic.php?f=23&t=143620 vlan1 is a default ID that should not be changed or used in most circumstances. It is the default bridge vlan pvid and should remain so in most configs' Use vlan10...
by anav
Thu Apr 01, 2021 6:40 pm
Forum: Beginner Basics
Topic: How to connect CAP AP to existing router - the easiest way?
Replies: 3
Views: 241

Re: How to connect CAP AP to existing router - the easiest way?

I would have not recommended the capac at that price point, but concur with erlinden. What I would do is power the unit via ethernet poe on eth1 and access the cap via eth2. Create a bridge on eth1 and assign everything to the bridge. Keep a separate address, dhcp and everything for ether2 so that y...
by anav
Thu Apr 01, 2021 2:54 pm
Forum: Beginner Basics
Topic: Multiple wan without failover but routing different lans through their own connection
Replies: 9
Views: 504

Re: Multiple wan without failover but routing different lans through their own connection

Interesting project, my reccomendations: (1) Just for completeness add ether1 interface to the WAN list. /interface list member add interface=ether1-isp1 (2) I am confused why do you only have one CLIENT noted below???? Are you saying the pppoe connection on ether1 is a static WANIP and ether2 ISP i...
by anav
Thu Apr 01, 2021 2:22 pm
Forum: Beginner Basics
Topic: Multiple VLANs and DHCP servers on a single physical port
Replies: 3
Views: 263

Re: Multiple VLANs and DHCP servers on a single physical port

Both may be possible, switch chip method depends on the hardware.

bridgevlan filtering
viewtopic.php?f=23&t=143620

Switch chip method
https://www.youtube.com/watch?v=Rj9aPoyZOPo
by anav
Thu Apr 01, 2021 2:19 pm
Forum: Beginner Basics
Topic: Dual WAN and bridges [SOLVED]
Replies: 7
Views: 464

Re: Dual WAN and bridges [SOLVED]

Provide network diagrams to explain
by anav
Thu Apr 01, 2021 3:54 am
Forum: General
Topic: NETWATCH & IP CLOUD
Replies: 2
Views: 237

Re: NETWATCH & IP CLOUD

Kk as I though netwatch is incompatible with ip cloud thanks!
by anav
Wed Mar 31, 2021 5:37 pm
Forum: Beginner Basics
Topic: Issue with my network setup
Replies: 43
Views: 2427

Re: Issue with my network setup

Good question not having done it before, but I do suggest going to the System Menu and selecting Configuration and select the checkbox next to NO DEFAULT CONFIGURATION if you fancy starting from zero/scratch otherwise go to new terminal windows and type /system reset-configuration This should reset ...
by anav
Wed Mar 31, 2021 5:28 pm
Forum: General
Topic: NETWATCH & IP CLOUD
Replies: 2
Views: 237

NETWATCH & IP CLOUD

It seemed like a good idea at the time. Using IP Cloud to resolve to currently used Dynamic WANIP. However, IP Cloud address, is no longer accessed once the resolving occurs and thus when the IP address changes, the netwatch rule is invalid. Has anyone else noted this issue or did I configure incorr...
by anav
Wed Mar 31, 2021 5:15 pm
Forum: Beginner Basics
Topic: Invalid Forwards [SOLVED]
Replies: 9
Views: 671

Re: Invalid Forwards [SOLVED]

That is not a router issue that is simply unplugging the ethernet cable from the TV or the wifi connection. However your reasoning does not take into account that most folks have a netflix account via wifi on their TV. So removing internet is not a possibility. Thats why I suggest at least putting T...
by anav
Wed Mar 31, 2021 3:35 pm
Forum: General
Topic: Port forwarding from a different subnet
Replies: 15
Views: 877

Re: Port forwarding from a different subnet

So let me get this straight. Your ROUTER/MODEM has assigned a static LANIP (192.168.3.5) to your MT device also acting as a router and the WANIP is of course also 192.168.3.5 Your MT ROUTER has ONE lan subnet subnets for various purposes 192.168.1.0/24 I will ignore your ether1 as its confusing and ...
by anav
Wed Mar 31, 2021 3:19 pm
Forum: Beginner Basics
Topic: Invalid Forwards [SOLVED]
Replies: 9
Views: 671

Re: Invalid Forwards [SOLVED]

No I do not believe there is any cause for concern.
I would try the long version software though as I do not experience this phenomena.
by anav
Wed Mar 31, 2021 3:17 pm
Forum: Beginner Basics
Topic: Issue with my network setup
Replies: 43
Views: 2427

Re: Issue with my network setup

I would rest to defaults and start clean...........
by anav
Wed Mar 31, 2021 3:04 pm
Forum: General
Topic: Enable port 80 in lan
Replies: 3
Views: 266

Re: Enable port 80 in lan

Here is the short explanation. You have come across the need for loopback called in the MT world, Hairpin NAT. This occurs when users on the same LAN as a server are mandated to use the public IP of the network the server is on, vice the much easier and direct LANIP of the server. If creating a new ...
by anav
Wed Mar 31, 2021 3:02 pm
Forum: General
Topic: Enable port 80 in lan
Replies: 3
Views: 266

Re: Enable port 80 in lan

Here is the short explanation. You have come across the need for loopback called in the MT world, Hairpin NAT. This occurs when users on the same LAN as a server are mandated to use the public IP of the network the server is on, vice the much easier and direct LANIP of the server. If creating a new ...
by anav
Wed Mar 31, 2021 2:46 pm
Forum: General
Topic: Bridge Trunk Ports
Replies: 6
Views: 385

Re: Bridge Trunk Ports

Thanks all I missed a key part of pvid on ports not working until you enable vlan filter on the bridge Been there done that! The enabling of bridge vlan filtering should be the last step after configuring all. Annoyingly this causes the router to burp and one has to relogin and confirm that bridge ...
by anav
Wed Mar 31, 2021 2:44 pm
Forum: General
Topic: vlan problem on hEX
Replies: 18
Views: 1140

Re: vlan problem on hEX

(1) My advice besides posting the complete config as noted above is to remove this rule /interface bridge settings set use-ip-firewall=yes use-ip-firewall-for-vlan=yes as its very tricky to use properly and is only needed in special cases whereas the normal firewall rules work for 99% of needs. (2) ...
by anav
Wed Mar 31, 2021 2:37 pm
Forum: General
Topic: vlan problem on hEX
Replies: 18
Views: 1140

Re: vlan problem on hEX

If you are already at 6.48 you can leave it at that..... I simply prefer the more stable long term versions.
You should post the entire config as its all inter related.
/export hide-sensitive file=anynameyouwish
by anav
Wed Mar 31, 2021 2:35 pm
Forum: General
Topic: Bridge Trunk Ports
Replies: 6
Views: 385

Re: Bridge Trunk Ports

Thanks this is a really nice article but the access ports
don’t work in this scenario on my hardware
Then you need to adjust your thinking as the guide works, and your config does not......... imagine that!
by anav
Wed Mar 31, 2021 2:33 pm
Forum: Beginner Basics
Topic: Issue with my network setup
Replies: 43
Views: 2427

Re: Issue with my network setup

Does the fios require a vlan to pass its internet? Highly unlikely but grasping at straws here. Tools: Packet sniffer https://help.mikrotik.com/docs/display/ROS/Packet+Sniffer Tools: Torch https://help.mikrotik.com/docs/display/ROS/Torch https://wiki.mikrotik.com/wiki/Manual:Troubleshooting_tools wi...
by anav
Wed Mar 31, 2021 2:25 pm
Forum: Beginner Basics
Topic: Ask About Load Balancing with PCC
Replies: 2
Views: 196

Re: Ask About Load Balancing with PCC

No limitations I am aware of, note that one cannot aggregate throughput for a single connection event but you will have more bandwidth overall to share with users.
The other advantage of redundancy does not apply here assuming the wan links are from the SAME isp.
by anav
Wed Mar 31, 2021 2:23 pm
Forum: Beginner Basics
Topic: DNS problem
Replies: 8
Views: 683

Re: DNS problem

Post your config
/export hide-sensitive file=anynameyouwish
by anav
Tue Mar 30, 2021 11:45 pm
Forum: Beginner Basics
Topic: Issue with my network setup
Replies: 43
Views: 2427

Re: Issue with my network setup

Not sure of fios settings is there something else on that thing that needs to be enabled?
Did you try a different connecting cable?
Next step is trying different ports maybe.....
by anav
Tue Mar 30, 2021 11:43 pm
Forum: Beginner Basics
Topic: Invalid Forwards [SOLVED]
Replies: 9
Views: 671

Re: Invalid Forwards [SOLVED]

Is this a recent bug and if so which firmwares does it affect??
by anav
Tue Mar 30, 2021 10:59 pm
Forum: Beginner Basics
Topic: Invalid Forwards [SOLVED]
Replies: 9
Views: 671

Re: Invalid Forwards [SOLVED]

Sounds like you should have a stern talking to with your TV ;-)
Is it searching for something in particular, as in do you have apps that people use on the TV???
Do you have the TV on its own VLAN segregated from your other stuff?
by anav
Tue Mar 30, 2021 10:06 pm
Forum: General
Topic: Three Subnets in one ethernet interface [SOLVED]
Replies: 9
Views: 587

Re: Three Subnets in one ethernet interface [SOLVED]

Thanks for the clarification!!
by anav
Tue Mar 30, 2021 10:04 pm
Forum: Beginner Basics
Topic: Issue with my network setup
Replies: 43
Views: 2427

Re: Issue with my network setup

The fios didnt give out dhcp and thus it would not be visible, you statically assigned it from the MT side.
Suggest you enter the fios and also statically assign the iP to the router.
by anav
Tue Mar 30, 2021 6:36 pm
Forum: General
Topic: Bridge Trunk Ports
Replies: 6
Views: 385

Re: Bridge Trunk Ports

by anav
Tue Mar 30, 2021 2:46 pm
Forum: Beginner Basics
Topic: Issue with my network setup
Replies: 43
Views: 2427

Re: Issue with my network setup

You should not have a dynamic IP assigned. I thought you were applying a static WANIP.
Follow this tutorial!!

https://www.bing.com/videos/search?q=ho ... &FORM=VIRE
by anav
Tue Mar 30, 2021 2:35 pm
Forum: General
Topic: vlan problem on hEX
Replies: 18
Views: 1140

Re: vlan problem on hEX

First you need to upgrade your firmware its dated,,,,,,,, use the latest LONG version of firmware for best results. Then read this link which shows vlan1 does not need to be identified as it already exists by default. No one creates and uses vlan1 as a traditional vlan. Read this excellent link........
by anav
Tue Mar 30, 2021 2:31 pm
Forum: General
Topic: Question on VLAN 0 & 1 implementation across different MT devices
Replies: 3
Views: 424

Re: Question on VLAN 0 & 1 implementation across different MT devices

Sorry dont use powerbox, but RoS is RoS and the same so vlan1 is the default pvid and normally is never removed or changed for vlan filtering or bridge ports. The only time one defines a PVID on a bridge port (access port) is when that port is going to a dumb device. Typically no one uses vlan1 or v...
by anav
Tue Mar 30, 2021 2:18 pm
Forum: General
Topic: Need help with Vlan routing
Replies: 7
Views: 452

Re: Need help with Vlan routing

The drop invalid rules in both the forward and input chain do not cause issues unless you have configured something else in error. Also you need to post your entire config not just the firewall rules to determine what is going on.................... As for firewall rules you would be best to get rid...
by anav
Tue Mar 30, 2021 2:15 pm
Forum: General
Topic: Discovery of external IP address (Noip.com)
Replies: 25
Views: 1611

Re: Discovery of external IP address (Noip.com)

Have fun with that Sindy, so many errors dont know where to begin......
I will point out that the wan port is on the bridge and he has ethernet2 on the bridge but both the bridge and ethernet2 have IP addresses.
Why all the partial nets of 192.168.0. - just use vlans so much cleaner.
by anav
Tue Mar 30, 2021 2:04 pm
Forum: Beginner Basics
Topic: Multiple VLAN on Single Port
Replies: 6
Views: 924

Re: Multiple VLAN on Single Port

Okay I am confused by your network. Is the switch acting as a router or a switch? A network diagram would be helpful. What is the purpose of using firewall rules on a switch?? assuming its not acting as a router? Also for vlan filtering you should follow this guide....... https://forum.mikrotik.com/...
by anav
Tue Mar 30, 2021 1:59 pm
Forum: Beginner Basics
Topic: 2 links between CSR /using vlan filtering, but without LACP/
Replies: 9
Views: 531

Re: 2 links between CSR /using vlan filtering, but without LACP/

You could put both vlans on one port of sw1 to one port of sw2 and then breakout the two untagged vlans on two ports on sw2. Is that what you want to do You could also do what your diagram shows as well but typically switch to managed switch one uses one port to one port to carry the vlans. LInking ...
by anav
Tue Mar 30, 2021 1:53 pm
Forum: Beginner Basics
Topic: Issue with my network setup
Replies: 43
Views: 2427

Re: Issue with my network setup

I could only find one item but dont think it would block traffic? (1) You should only have one sourcenat rule so get rid of the first one as the second one captures the fixed wanip address. /ip firewall nat add action=masquerade chain=srcnat out-interface-list=WAN add action=src-nat chain=srcnat out...
by anav
Tue Mar 30, 2021 4:06 am
Forum: Wireless Networking
Topic: Is there a way to increase range/signal of cAP AC?
Replies: 4
Views: 621

Re: Is there a way to increase range/signal of cAP AC?

I agree with erlinden, playing guessng games is a waste of time, post your config so we can see all pertinent settings.
by anav
Tue Mar 30, 2021 4:04 am
Forum: Beginner Basics
Topic: N00b - protecting router from external access
Replies: 3
Views: 231

Re: N00b - protecting router from external access

My problem is I dont understand serve external customers........ what the heck do you mean. You can provide public IPs to folks behind the router, and you can provide internal networks private behind the router. However I have no idea how you serve external customers. do you simply mean you have ser...
by anav
Mon Mar 29, 2021 11:11 pm
Forum: Beginner Basics
Topic: Problems with new Install RB4011....
Replies: 9
Views: 636

Re: Problems with new Install RB4011....

Sorry not much of a troubleshooter, check cables, try a different switch etc......
by anav
Mon Mar 29, 2021 10:33 pm
Forum: General
Topic: Need help with Vlan routing
Replies: 7
Views: 452

Re: Need help with Vlan routing

Like I said, let me be more blunt, the FW rules are a farce and make it too difficult to even read.
If you are interested in vlans that work and not cutesy fw rules let me know otherwise someone else can chime in.
by anav
Mon Mar 29, 2021 5:27 pm
Forum: Beginner Basics
Topic: Problems with new Install RB4011....
Replies: 9
Views: 636

Re: Problems with new Install RB4011....

Nope, does the MT recognize the SFP port as being active?
Is the DELL switch on the same LAN subnet?
by anav
Mon Mar 29, 2021 4:56 pm
Forum: General
Topic: Three Subnets in one ethernet interface [SOLVED]
Replies: 9
Views: 587

Re: Three Subnets in one ethernet interface [SOLVED]

Hi Mkx, Understood thanks for the clarification.
During the MTUNA course we call this.......... yes you can stuff a raccoon up the anus, but it hurts!
On a happier note: The Suez canal, unlike the tube in the previous sentence is now unblocked!!
by anav
Mon Mar 29, 2021 4:52 pm
Forum: General
Topic: Since 4 years, I'm donde with VLAN [SOLVED]
Replies: 5
Views: 613

Re: Since 4 years, I'm donde with VLAN [SOLVED]

Since you think defining a vlan is done in Bridge vlan settings and that only providing a partial network diagram is good enough, suggest someone else help.
I can suggest reading this excellent link
viewtopic.php?f=23&t=143620
by anav
Mon Mar 29, 2021 4:48 pm
Forum: Beginner Basics
Topic: Problems with new Install RB4011....
Replies: 9
Views: 636

Re: Problems with new Install RB4011....

In that case the response would be thus.......

(1) Missing (and thus ADD)
/interface list member
add interface=Bridge list=LAN
add interface=Internet list=WAN
add interface="Orange Optic" list=WAN
by anav
Mon Mar 29, 2021 3:49 pm
Forum: General
Topic: Three Subnets in one ethernet interface [SOLVED]
Replies: 9
Views: 587

Re: Three Subnets in one ethernet interface [SOLVED]

Hi Xavi what you are asking is not possible, at least from limited knowledge base. What you need to do is use vlans and a managed switch. Each office should be on its own vlan and then through firewall rules you can allow shared sources in a precise way. For example VLANA to shared printer on VLANB ...
by anav
Mon Mar 29, 2021 3:47 pm
Forum: General
Topic: Need help with Vlan routing
Replies: 7
Views: 452

Re: Need help with Vlan routing

Dont think multicasting or openvpn work very well on MT routers..
Besides that your firewall config is full of un-needed fluff

If you want to focus on vlans this is your best guide.
viewtopic.php?f=23&t=143620
by anav
Mon Mar 29, 2021 3:41 pm
Forum: General
Topic: Double nat hairpin
Replies: 1
Views: 178

Re: Double nat hairpin

First you are in the wrong forum. Wireguard is only available in the beta version of the software so you should be posting here. https://forum.mikrotik.com/viewforum.php?f=1 Hairpin Nat only applies to the MT router. Hairpin Nat applies when one tries to access a LOCAL Server by a public IP address ...
by anav
Mon Mar 29, 2021 3:38 pm
Forum: Beginner Basics
Topic: Forgive my ignorance! Firewall question
Replies: 1
Views: 150

Re: Forgive my ignorance! Firewall question

post your config
/export hide-sensitive file=anynameyouwish
by anav
Mon Mar 29, 2021 3:37 pm
Forum: General
Topic: Routers are not providing speed
Replies: 3
Views: 338

Re: Routers are not providing speed

Your post is confusing and all over the map. a. confirm routing is via an MT router and there are no issues with wired speeds. b. confirm using MT wifi (within a router, or a separate access point/router) and this is the device that is not giving you speeds? c. if b is correct then what speeds are y...
by anav
Mon Mar 29, 2021 3:33 pm
Forum: Beginner Basics
Topic: Enable Ether slot or 3rd isp route when my 1st and 2nd isp is down in netwatch
Replies: 2
Views: 228

Re: Enable Ether slot or 3rd isp route when my 1st and 2nd isp is down in netwatch

Why not just add the third WAN to your failover such that it only is used when WAN1 and WAN are down......... seems like a huge over complication??
by anav
Mon Mar 29, 2021 3:28 pm
Forum: Beginner Basics
Topic: Move WAN from ether1 to ether6? [SOLVED]
Replies: 10
Views: 612

Re: Move WAN from ether1 to ether6? [SOLVED]

(1) Should be removed. add action=drop chain=forward comment="Block IPs to WAN" log=yes log-prefix=\ "IP blocked from WAN" src-address-list="Block IP" (2) This may not be necessary or more likely wrong, not sure why you are routing on the LAN???? ip route rule add actio...
by anav
Mon Mar 29, 2021 3:19 pm
Forum: Beginner Basics
Topic: Problems with new Install RB4011....
Replies: 9
Views: 636

Re: Problems with new Install RB4011....

First question is why have a vlan and then attach it to the bridge? In other words if all the ports attached to the bridge have the same subnet you dont really need the vlan. If however you intend to add vlans then this is a first step but I would recommend removing the bridge from any vlan or dhcp ...
by anav
Mon Mar 29, 2021 2:40 pm
Forum: Beginner Basics
Topic: Move WAN from ether1 to ether6? [SOLVED]
Replies: 10
Views: 612

Re: Move WAN from ether1 to ether6? [SOLVED]

post config
/export hide-sensitive file=anynameyouwish
by anav
Mon Mar 29, 2021 11:20 am
Forum: Beginner Basics
Topic: Help with Firewall
Replies: 1
Views: 761

Re: Help with Firewall

Provide the config not screenshots
/export hide-sensitive file=anynameyouwish
by anav
Mon Mar 29, 2021 11:19 am
Forum: Beginner Basics
Topic: Move WAN from ether1 to ether6? [SOLVED]
Replies: 10
Views: 612

Re: Move WAN from ether1 to ether6? [SOLVED]

Dont use quickset, use winbox to configure MT device
by anav
Sun Mar 28, 2021 11:14 pm
Forum: Beginner Basics
Topic: Issue with my network setup
Replies: 43
Views: 2427

Re: Issue with my network setup

Thanks but why /24, its a single IP only?
by anav
Sun Mar 28, 2021 9:20 pm
Forum: Beginner Basics
Topic: Issue with my network setup
Replies: 43
Views: 2427

Re: Issue with my network setup

As stated dont use quickset to enter in parameters. (1) Okay I see you have ether1 on bridge ports disabled as its not on the bridge being the dhcp client, thats fine. (2) You need at least two IP addresses recognized, the one you have for the Bridge (lan) but also (and missing) the eth1 address. Al...
by anav
Sun Mar 28, 2021 4:21 pm
Forum: General
Topic: DNS connection failure
Replies: 16
Views: 966

Re: DNS connection failure

Hi Anav I'll take your advise. As you know I have 3 Wans IPs, 2 Static and 1 Dynamic. It quite strange that I can not ping by second or third interface in Mikrotik terminal ping 8.8.8.8 interface=ether3 It also not working with firewall mangle to bind and redirect user to second Wan. For DNS failur...
by anav
Sun Mar 28, 2021 7:38 am
Forum: Beginner Basics
Topic: Issue with my network setup
Replies: 43
Views: 2427

Re: Issue with my network setup

Quickset=quicksand, avoid
Will write up something tomorrow.
by anav
Sat Mar 27, 2021 8:18 pm
Forum: General
Topic: EAP-TLS wireless authentication - why a Mikrotik station cannot connect to a Mikrotik AP? [SOLVED]
Replies: 4
Views: 497

Re: EAP-TLS wireless authentication - why a Mikrotik station cannot connect to a Mikrotik AP? [SOLVED]

In my particular case, it's what I wrote at the beginning of the OP - I was getting ready to use Mikrotik as a client in a network not managed by myself which requires that clients authenticate themselves using certificates, and I wanted to make sure everything would run smoothly on site. Thanks fo...
by anav
Sat Mar 27, 2021 8:13 pm
Forum: Beginner Basics
Topic: Dual WAN ( YEAH AGAIN :) )
Replies: 2
Views: 369

Re: Dual WAN ( YEAH AGAIN :) )

Yes of course!
But first,
/export hide-sensitive file=anynameyouwish
by anav
Sat Mar 27, 2021 2:11 pm
Forum: General
Topic: EAP-TLS wireless authentication - why a Mikrotik station cannot connect to a Mikrotik AP? [SOLVED]
Replies: 4
Views: 497

Re: EAP-TLS wireless authentication - why a Mikrotik station cannot connect to a Mikrotik AP? [SOLVED]

Sounds like a case of knowing too much. I would have simply put the square peg into the square hole instead of contemplating the depth of the hole and what instrument was used to cut the holes. In other words Zing over my head but glad you worked it out. So what I dont get is wifi is just a medium, ...
by anav
Sat Mar 27, 2021 2:04 pm
Forum: General
Topic: DNS connection failure
Replies: 16
Views: 966

Re: DNS connection failure

Its a tad to busy for me to see anything wrong. What I suggest is a. copy your current config. b. reset to default settings for everything. c. Add the LAN network you need d. Bring in the ppoe wan TEST to SEE if you have proper DNS YES e. Add second and third static wANIPs TEST to see if you have pr...
by anav
Fri Mar 26, 2021 11:31 pm
Forum: General
Topic: WARNING _ DO NOT USE UPS Feature on MT
Replies: 5
Views: 467

Re: WARNING _ DO NOT USE UPS Feature on MT

Geez I only have 3 UPS and two cyber power strips and no rack either in the garage. One UPS = 1 modem One UPS = 1 router One UPS = 1 other modem backup iSP & 24 port switch . downstairs basement - cyberpower UPS for tplink poe switch (powers tplink AP and capac), zyxel switch and couple more thi...
by anav
Fri Mar 26, 2021 9:08 pm
Forum: General
Topic: WARNING _ DO NOT USE UPS Feature on MT
Replies: 5
Views: 467

Re: WARNING _ DO NOT USE UPS Feature on MT

The APC one also caused the router to reboot but I take your point on the cyber power...... too funny.
They should call the package APC UPS and not UPS LOL.
by anav
Fri Mar 26, 2021 8:31 pm
Forum: General
Topic: WARNING _ DO NOT USE UPS Feature on MT
Replies: 5
Views: 467

WARNING _ DO NOT USE UPS Feature on MT

I loaded the package and connected the UPS (once via APC, once via Cyberpower), to the USB connection on the MY CCR1009. Both times when I pulled the plug on the APC, to test, the router rebooted and the second time it caused the switch connected to the router to lose some of its configuration. Ther...
by anav
Fri Mar 26, 2021 6:40 pm
Forum: General
Topic: Why can't I make my hEX lite into a router?
Replies: 19
Views: 1151

Re: Why can't I make my hEX lite into a router?

3. Yes, there is a learning curve, but not in your case. It should have worked even without any config applied Thus is true. Been working with network for 30 years and RouterOS was/is a steep hill to climb. But when you first get hang of it, you will love it. You can do nearly anything with this sm...
by anav
Fri Mar 26, 2021 6:35 pm
Forum: Beginner Basics
Topic: Home Setup NEWBIE
Replies: 4
Views: 730

Re: Home Setup NEWBIE

Okay so your new to Mikrotik, I have to ask, why not ask first which device you should buy based on your requirements?? For example, that device seems to be a honking switch but maxes out at less than 500Mbps on the routing side meaning your 1gig internet connection is wasted. Its possible you coul...
by anav
Fri Mar 26, 2021 6:32 pm
Forum: Beginner Basics
Topic: Load balancing between 2 wan on same network
Replies: 10
Views: 679

Re: Load balancing between 2 wan on same network

Yes, but are they static public WANIPs?
by anav
Fri Mar 26, 2021 2:46 am
Forum: Beginner Basics
Topic: Issue with my network setup
Replies: 43
Views: 2427

Re: Issue with my network setup

Okay first I will show you the default ones that come from the router and then I will put my variation on them which is similar just a tad more secure. DEFAULT /ip firewall filter add action=accept chain=input comment=\ "defconf: accept established,related,untracked" connection-state=\ est...
by anav
Fri Mar 26, 2021 12:34 am
Forum: General
Topic: Why can't I make my hEX lite into a router?
Replies: 19
Views: 1151

Re: Why can't I make my hEX lite into a router?

I eventually pulled the plug and tossed the unit in the trash. I should have know better the very instant I found that MikroTik did not supply tech support. I will try the Ubiquiti Edge Router to see if that administers any better. Oh that is simply the MT weeding out process designed for folks wit...
by anav
Thu Mar 25, 2021 9:11 pm
Forum: General
Topic: help fix leaky vlans, NP16 + PBP
Replies: 7
Views: 525

Re: help fix leaky vlans, NP16 + PBP

If you are configuring for a hybrid port, lets say vlans,10,11 trunked and 66 untagged. Ether1 is from router, ether2 is the hybrid port, ether 3 is a trunk port (10,11,12) , ether4 is an access port (66) /bridge port add bridge=bridge-new interface=ether1 ingress filtering=yes, allow only vlan tagg...
by anav
Thu Mar 25, 2021 7:32 pm
Forum: Beginner Basics
Topic: Issue with my network setup
Replies: 43
Views: 2427

Re: Issue with my network setup

Do you have access to the cable router (from an ISP provider, or is this like someone giving you an IP on their personal router)?? If its a FIOS router presuming ISP, then, if not shared with others.......... a. do you have access to it? b. can you forward all the ports to you c. can you put it in p...
by anav
Thu Mar 25, 2021 4:43 pm
Forum: Beginner Basics
Topic: hEX & bonding/link aggregation setup
Replies: 4
Views: 344

Re: hEX & bonding/link aggregation setup

I dont see anywhere, any relationship of Static LAG to any of the Bonding options on MiKrotik OS?
by anav
Thu Mar 25, 2021 4:23 pm
Forum: Beginner Basics
Topic: Issue with my network setup
Replies: 43
Views: 2427

Re: Issue with my network setup

CONFUSED as there is no network diagram. Is this supposed to be acting as a switch or a router. The reason I ask is you seem to want to state there is a higher order device (router or something) that is of a different subnet?? But then your firewall rules are very incomplete and not really safe for ...
by anav
Thu Mar 25, 2021 4:05 pm
Forum: Beginner Basics
Topic: Firewall rule nuked access to Mikrotik
Replies: 1
Views: 209

Re: Firewall rule nuked access to Mikrotik

Post your config.
/export hide-sensitive file=anynameyouwish
by anav
Wed Mar 24, 2021 5:39 pm
Forum: Beginner Basics
Topic: RB 2011iL does not get Gib traffic
Replies: 19
Views: 1380

Re: RB 2011iL does not get Gib traffic

Post your config.
In the meantime suggest street to modem wire check by ISP and then modem check (old model) needs to be reprogrammed or something, or you didnt pay your bills LOL.
by anav
Wed Mar 24, 2021 4:47 pm
Forum: Scripting
Topic: Get log line from memory log
Replies: 15
Views: 940

Re: Get log line from memory log

The file is one created in FILES by the fetch tool. The keep-file=no just eliminates the file from being placed in the FILE menu. Okay good to go......... Will give the script a try. OKAY 1. I have no idea if the buffer part of the script works (the first long self-contained part) 2. The parser scri...
by anav
Wed Mar 24, 2021 4:43 pm
Forum: General
Topic: RB4011 > hAP AC Lite VLAN configuration
Replies: 13
Views: 796

Re: RB4011 > hAP AC Lite VLAN configuration

If its working for you, great!
If not would need an updated diagram to match.
by anav
Wed Mar 24, 2021 2:50 pm
Forum: General
Topic: Since 4 years, I'm donde with VLAN [SOLVED]
Replies: 5
Views: 613

Re: Since 4 years, I'm donde with VLAN [SOLVED]

(1) You need to define vlans 10 and 20 and their interface is the bridge, thus far only vlan99 is configured. (2) You dont have vlan20 noted in the bridge vlan configuration. (3) SFP+3 and SFP+4 are not configured on the bridge port settings?? (4) SFP+1 and FP+2 are not configured in bridge vlans?? ...
by anav
Wed Mar 24, 2021 2:43 pm
Forum: Beginner Basics
Topic: Date & Time from NTP Server [SOLVED]
Replies: 14
Views: 856

Re: Date & Time from NTP Server [SOLVED]

Provide a screen shot of the NTP Client page.
by anav
Wed Mar 24, 2021 1:20 pm
Forum: Scripting
Topic: Get log line from memory log
Replies: 15
Views: 940

Re: Get log line from memory log

I guess I missed the purpose of the PUT command or sequence? Are you saying I dont need it in my particular script? ? Also should this work for ensuring no files are added # Check for Power failure :if ([:find [:tostr $logMessage] "USB UPS AC power off"] != "") do={ :beep frequen...
by anav
Wed Mar 24, 2021 1:10 pm
Forum: General
Topic: Port Forward to a Hostname
Replies: 3
Views: 354

Re: Port Forward to a Hostname

Not that I am aware of, the TO-ADDRESSES is IP only as far as I can see. (lists not permitted) The only thing I can think of is use two rules....... DSTNAT RULE1 DSTNAT RULE2 RUN a SYSTEM Script that says check if server1 is down then disable rule 1 If server 1 is up enable rule 1 That way the dst t...
by anav
Wed Mar 24, 2021 1:04 pm
Forum: General
Topic: RB4011 > hAP AC Lite VLAN configuration
Replies: 13
Views: 796

Re: RB4011 > hAP AC Lite VLAN configuration

Im talking about the bridge personality on the hapac. Why is it that the wlan ports which are tagged for ether1 and untagged for wlan port DO NOT NEED the bridge to be also tagged. In comparison the managment VLAN needs to be tagged with ether1 AND the bridge!! In other words explain what is needed ...
by anav
Wed Mar 24, 2021 1:02 pm
Forum: General
Topic: Since 4 years, I'm donde with VLAN [SOLVED]
Replies: 5
Views: 613

Re: Since 4 years, I'm donde with VLAN [SOLVED]

Please post the config
/export hide-sensitive file=anynameyouwish
by anav
Wed Mar 24, 2021 2:00 am
Forum: General
Topic: I can't connect to my NVRs [SOLVED]
Replies: 12
Views: 734

Re: I can't connect to my NVRs [SOLVED]

You dont have a public IP. The ADSL unit is giving you a private IP and thus NAT is not possible. If you have access to the ADSL router then can you forward ALL the ports to the LANIP on the ADSL router that corresponds to the connection to your router, which is also the fixed WANIP on your MT RB401...
by anav
Wed Mar 24, 2021 1:51 am
Forum: Scripting
Topic: Sending telegram bot message
Replies: 5
Views: 502

Re: Sending telegram bot message

This script works well for me for internal interfaces at the moment and for system/cpu temperature and if you go to my other thread, trying to do so for UPS log entry! https://forum.mikrotik.com/viewtopic.php?f=9&t=173565&p=849993#p849993 The one thing I would like to add from the first exam...
by anav
Wed Mar 24, 2021 12:41 am
Forum: Scripting
Topic: Get log line from memory log
Replies: 15
Views: 940

Re: Get log line from memory log

Hi there, I would very much like to use your idea for the UPS monitoring that goes on and available in the LOG. I want to detect a log entry and then send it to my telegram bot. I need help with what to do on the put section Would this be the right approach? (1) Step one would entail adding via CLI ...
by anav
Wed Mar 24, 2021 12:02 am
Forum: Scripting
Topic: Sending telegram bot message
Replies: 5
Views: 502

Re: Sending telegram bot message

Another example /tool fetch "https://api.telegram.org/bot<yourtokencode>/sendMessage\?chat_id=<botcode>&text=Router" Note: Any spaces in the text portion of the URL, the message you wish to send should contain no gaps. Use the '+' symbol for spaces!! You can add time for example. :loca...
by anav
Tue Mar 23, 2021 11:25 pm
Forum: General
Topic: RB4011 > hAP AC Lite VLAN configuration
Replies: 13
Views: 796

Re: RB4011 > hAP AC Lite VLAN configuration

You missed the question entirely LOL.
I was asking to confirm why or why not the Bridge needs to be tagged or just the incoming port on the hapac (ether1) for the vlans that are not management and not trunked elsewhere on the hapac (basic vlan into and untagged out on some port).
by anav
Tue Mar 23, 2021 10:18 pm
Forum: General
Topic: help with a firewall address rule
Replies: 2
Views: 334

Re: help with a firewall address rule

Easy peasy.
Just make a firewall address list entry and then in the firewall rule point to the list (in-interface-list) or (out-interface-list)
by anav
Tue Mar 23, 2021 8:39 pm
Forum: Beginner Basics
Topic: Port forwarding not working. Minecraft Bedrock Server
Replies: 3
Views: 351

Re: Port forwarding not working. Minecraft Bedrock Server

(1) Didnt make this change LOL should be bridge. /ip address add address=192.168.88.1/24 comment=defconf interface= ether2 network=\ 192.168.88.0 (2) not a pppoe guy but shouldnt the dhcp client be the pppoe interface?? /ip dhcp-client add comment=defconf dhcp-options=hostname,clientid interface=eth...
by anav
Tue Mar 23, 2021 6:14 pm
Forum: General
Topic: Netwatch deprecated ? [SOLVED]
Replies: 69
Views: 17262

Re: Netwatch deprecated ? [SOLVED]

Sounds $$
I should post in the MT Charity Forum. ;-)
Anybody would like to donate a few lines of script on their Virtual MT machine for the purposes of running a Script to let me know when my Internet is hard down LOL.
by anav
Tue Mar 23, 2021 6:12 pm
Forum: Beginner Basics
Topic: network for management only
Replies: 1
Views: 278

Re: network for management only

Draw a diagram as its not clear.
By the way, since you are using vlans, that is your L2 separation between users.
On top of that you may need firewall rules to keep vlans from seeing each other.

Hence, I do not understand about untrusted ports as the security is already provided via vlans.
by anav
Tue Mar 23, 2021 5:34 pm
Forum: General
Topic: Netwatch deprecated ? [SOLVED]
Replies: 69
Views: 17262

Re: Netwatch deprecated ? [SOLVED]

So basically, I am out of luck, unless magically I have another mickrotik router somewhere, checking my free dyndns name or mikrot cloud name, it sending me an email or telegram with no reponse.. Call me crazy but this ounds like an addition to the MT cloud service?? Why cannot I add a script to my ...
by anav
Tue Mar 23, 2021 4:53 pm
Forum: General
Topic: Netwatch deprecated ? [SOLVED]
Replies: 69
Views: 17262

Re: Netwatch deprecated ? [SOLVED]

Okay I have no practical way to check if my WAN connection goes down as then I wont have internet but I do have two ISPs. SO what I would like to do is Run a CHeck on my WANs in two parts............... UNLESS There is a better way. NETWATCH (1) USE DNS 9.9.9.9 to check ISP 1 (2) USE DNS 1.1.1.1 to ...
by anav
Tue Mar 23, 2021 4:34 pm
Forum: General
Topic: Netwatch deprecated ? [SOLVED]
Replies: 69
Views: 17262

Re: Netwatch deprecated ? [SOLVED]

QUESTION. CAN I put the same fetch script in a DHCP CLIENT SCRIPT??
Confirmed Yes, this works too.
by anav
Tue Mar 23, 2021 4:30 pm
Forum: General
Topic: Netwatch deprecated ? [SOLVED]
Replies: 69
Views: 17262

Re: Netwatch deprecated ? [SOLVED]

Yup that was it!! , okay so replace all my underlines with the + symbol to effect spaces in a URL - works! batting 1000 this morning :-).!!
by anav
Tue Mar 23, 2021 4:24 pm
Forum: Beginner Basics
Topic: Hardware Noob
Replies: 2
Views: 270

Re: Hardware Noob

Suggesting talking to major distributors in the states.......... ISP Supplies for example!! They are more likely to have technicians that know. https://mikrotik.com/buy/northamerica/usa Alternatively check out the list of USA consultants, it sounds like paying for advice may be well worth it!! https...
by anav
Tue Mar 23, 2021 3:14 pm
Forum: General
Topic: Netwatch deprecated ? [SOLVED]
Replies: 69
Views: 17262

Re: Netwatch deprecated ? [SOLVED]

Thanks, Will give that a try later!! Any ideas on something better for time date on the System scripts than :local sub1 ([/system clock get time]) /tool fetch..............="At $sub1 HP_Printer_is_Offline" :log info "CHECK HP printer stat!!" Seems to work fine for simple netwatch...
by anav
Tue Mar 23, 2021 2:52 pm
Forum: General
Topic: RB4011 > hAP AC Lite VLAN configuration
Replies: 13
Views: 796

Re: RB4011 > hAP AC Lite VLAN configuration

Our on-duty configuration parser @anav missed this question: How do I assign an IP address to the bridge that exists in VLAN50? as just adding "192.168.5.254/24" to the bridge only ever replies locally and then prevents further access to the device. For this you'll have to add bridge (the...
by anav
Tue Mar 23, 2021 2:40 pm
Forum: General
Topic: Port forwarding issue [SOLVED]
Replies: 8
Views: 718

Re: Port forwarding issue [SOLVED]

The best thing you could do is a. reset to defaults to clean up all the bloatware you have added. b. Figure out why your DHCP network is not for your LAN but setup for an ISP1 c. Understand that port forwarding is not going to work if your ISP gives you a private IP address. (unless they have forwar...
by anav
Tue Mar 23, 2021 2:31 pm
Forum: General
Topic: RB4011 > hAP AC Lite VLAN configuration
Replies: 13
Views: 796

Re: RB4011 > hAP AC Lite VLAN configuration

So the Orange firewall does all the Routing and DHCP service and the RB4011 is just a VLAN bridge type entity (switch)?? Seems like a waste but oh well. 1. Your Bridge port wlan-5G needs a PVID, as devices attached are not vlan smart. (add pvid=500 ) 2. Remove reference to vlan in wireless settings!...
by anav
Tue Mar 23, 2021 2:25 am
Forum: General
Topic: Adding to a working Email Netwatch Script. [SOLVED]
Replies: 3
Views: 586

Re: Adding to a working Email Netwatch Script. [SOLVED]

wow thats very advanced for me LOL, an automated master script that runs and updates a bunch of others......... I didnt understand your notification script so rather not use what I dont fathom. What I would like is to know how to insert date/time or just time into my Fetch URL script. This way isnt ...
by anav
Tue Mar 23, 2021 2:14 am
Forum: General
Topic: help fix leaky vlans, NP16 + PBP
Replies: 7
Views: 525

Re: help fix leaky vlans, NP16 + PBP

No idea what all the acronyms means thus please provide a network diagram.
Also post config
/export hide-sensitive file=anynameyouwish
by anav
Tue Mar 23, 2021 2:01 am
Forum: Beginner Basics
Topic: Port forwarding not working. Minecraft Bedrock Server
Replies: 3
Views: 351

Re: Port forwarding not working. Minecraft Bedrock Server

Upgrade your firmware its dated, use long term version 6.47.9 From /ip firewall nat add action=masquerade chain=srcnat comment="defconf: masquerade" \ ipsec-policy=out,none out-interface-list=WAN add action=masquerade chain=srcnat out-interface=pppoe-out1 add action=dst-nat chain=dstnat ds...
by anav
Tue Mar 23, 2021 1:51 am
Forum: Beginner Basics
Topic: Try to make ppp-oit1 as main routeк interface.
Replies: 2
Views: 255

Re: Try to make ppp-oit1 as main routeк interface.

/export hide-sensitive file=anynameyouwish
by anav
Mon Mar 22, 2021 11:18 pm
Forum: General
Topic: Adding to a working Email Netwatch Script. [SOLVED]
Replies: 3
Views: 586

Re: Adding to a working Email Netwatch Script. [SOLVED]

I finally got the Fetch script working the issue was a hidden return character or extra space that I had to remove.
Now my netwatch can fetch a script from systems scripts...........
by anav
Mon Mar 22, 2021 11:07 pm
Forum: General
Topic: Netwatch deprecated ? [SOLVED]
Replies: 69
Views: 17262

Re: Netwatch deprecated ? [SOLVED]

Okay, I have my TelegramFetch system script working great now. SO here is my netwatch script. HoW do I Add to it? And do I have to enable the checkbox (DONT REQUIRE PERMISSIONS in the TelegramFetch system script, or uncheck some of the other boxes etc.... :local sub1 ([/system clock get time]) /tool...
by anav
Mon Mar 22, 2021 9:23 pm
Forum: General
Topic: Netwatch deprecated ? [SOLVED]
Replies: 69
Views: 17262

Re: Netwatch deprecated ? [SOLVED]

having issues getting script to work at the moment in system script, when ready to try from netwatch will come back if doesnt work.
by anav
Mon Mar 22, 2021 5:51 pm
Forum: Wireless Networking
Topic: Problem with wlan
Replies: 6
Views: 501

Re: Problem with wlan

Yes, one still has to program the wifi settings but that is trivial compared to setting up the router properly for interfaces such as subnets and vlans ( i prefer vlans) and then the bridge and bridge port settings (and bridge vlan setting is using vlans). Firewall rules need minimum change. Then se...
by anav
Mon Mar 22, 2021 5:22 pm
Forum: General
Topic: Netwatch deprecated ? [SOLVED]
Replies: 69
Views: 17262

Re: Netwatch deprecated ? [SOLVED]

Hi Deantwo /system script set [find name="Netwatch up script"] dont-require-permissions=yes That wont work for me because netwatch scripts don't have names assigned?? Now that you know my level of script acumen (very little) Do you mean if you create a script that is called by netwatch, th...
by anav
Mon Mar 22, 2021 4:02 pm
Forum: General
Topic: Feature request: Make Quickset to be separate package
Replies: 32
Views: 7854

Re: Feature request: Make Quickset to be separate package

I agree. It is sad that with the 200 checkmarks on the QuickSet page for Design Skin to disable almost all widgets that are on it, there is no such checkmark for the "Apply Configuration" button. That would solve most of the problem. Removing the entire QuickSet page is a workaround, but ...
by anav
Mon Mar 22, 2021 3:58 pm
Forum: Scripting
Topic: SCRIPT Works in System Script but no in NETWATCH??? [SOLVED]
Replies: 4
Views: 495

Re: SCRIPT Works in System Script but no in NETWATCH??? [SOLVED]

Netwatch (also DHCP, PPP, etc.) lacks permissions to use global variables. You can create a script where permissions are not required and then call on that script. 2Frogs, luv you for responding. Others read but no response, should get a life LOL. Okay just to clarify I do not use any of the global...
by anav
Mon Mar 22, 2021 3:52 pm
Forum: Wireless Networking
Topic: Problem with wlan
Replies: 6
Views: 501

Re: Problem with wlan

Yeah, your config needs rework for sure. For starters only need one bridge. Nothing wrong with multiple subnets! Firewall rules need serious help. To much funky stuff for mangling there not required Masquerade nat rules not right. and more............. Recommend go back to default settings. Dont cha...
by anav
Mon Mar 22, 2021 3:46 pm
Forum: Wireless Networking
Topic: No internet connection with MikroTik HAP ac lite 500Mbit/s
Replies: 5
Views: 390

Re: No internet connection with MikroTik HAP ac lite 500Mbit/s

I see nothing wrong with the subnet setup, nothing wrong with using .88! What I Do see. (1) The interface should be the bridge. /ip address add address=192.168.88.1/24 comment=defconf interface =ether2 network=192.168.88.0 TO /ip address add address=192.168.88.1/24 comment=defconf interface =bridge ...
by anav
Mon Mar 22, 2021 3:37 pm
Forum: General
Topic: 3 recursive route failover
Replies: 20
Views: 7310

Re: 3 recursive route failover

I have better indications that the cloud if the main router is not working.
I get yelled at from many different directions (meaning, tympanic membrane medium for communications - very direct)
by anav
Mon Mar 22, 2021 3:33 pm
Forum: General
Topic: Router remplacement
Replies: 2
Views: 250

Re: Router remplacement

Concur, the hex cant provide 1 gig throughput and the RB4011 is good at least up to 3-4gig. For IPSEC the hex is capable up to 170Mbps, the RB4011 is probably good for 700-800. Based on a future growth and trend it is not unreasonable to expect 1gig up and down in the future If this is the case, as ...
by anav
Mon Mar 22, 2021 3:20 pm
Forum: General
Topic: Strange one
Replies: 12
Views: 820

Re: Strange one

Here are my concerns:. (1) /ip address add address=192.168.254.250/24 comment="DHCP bridge IP address range" \ interface =ether3 network=192.168.254.0 Should be add address=192.168.254.250/24 comment="DHCP bridge IP address range" \ interface =bridge network=192.168.254.0 (2) As ...
by anav
Mon Mar 22, 2021 2:29 pm
Forum: Beginner Basics
Topic: v6.41rc1+ bridges and broadcast
Replies: 1
Views: 194

Re: v6.41rc1+ bridges and broadcast

Update you firmware to the latest long term version then we can talk.
To answer the question, should not be an issue.
by anav
Mon Mar 22, 2021 1:58 am
Forum: General
Topic: 3 recursive route failover
Replies: 20
Views: 7310

Re: 3 recursive route failover

Why would I buy a cloud service when my router does it for free?
Why would I put all my devices status on the cloud for all to see, if its on the cloud ultimately its not secure.
by anav
Mon Mar 22, 2021 1:53 am
Forum: General
Topic: RouterOS bridge mysteries explained
Replies: 4
Views: 509

Re: RouterOS bridge mysteries explained

Ahh you mean at the beginning of pcunites thread!!!
by anav
Mon Mar 22, 2021 1:49 am
Forum: General
Topic: Data Over Powerlines firmware
Replies: 3
Views: 402

Re: Data Over Powerlines firmware

I think its one firmware upon point of sale. I don't see any software support for these units................ (hope I'm wrong)
by anav
Mon Mar 22, 2021 1:41 am
Forum: Wireless Networking
Topic: Wireless Client Isolation
Replies: 7
Views: 701

Re: Wireless Client Isolation

So the easy thing to do here is have Guess WIFI Upstairs and Guest Wifi Downstairs as two separate SSIDs, being fed by two different vlans. Then in the forward chain they are blocked automatically if your last forward chain rule is drop all else. Combined with same AP default forwarding turned off s...
by anav
Mon Mar 22, 2021 1:38 am
Forum: General
Topic: Adding to a working Email Netwatch Script. [SOLVED]
Replies: 3
Views: 586

Adding to a working Email Netwatch Script. [SOLVED]

How do I add the following to an existing and working email script (it sends a telegram to my phone). / tool fetch "https://api.telegram.org/bot1111111111:t rAndomStrInGof lettersandnumbers/sendMessage?chat_id =-222222222&text=Router $[/system identity get name] has detected the HP Printer ...
by anav
Mon Mar 22, 2021 12:20 am
Forum: Scripting
Topic: SCRIPT Works in System Script but no in NETWATCH??? [SOLVED]
Replies: 4
Views: 495

SCRIPT Works in System Script but no in NETWATCH??? [SOLVED]

This script works well for me when used in the SYSTEM SCRIPT location to send me telegram notices if the temperatures on the Router go out of whack. In particular I am interested in using the /tool fetch portions of the script to similarly report on my netwatch devices status on telegram: A. success...
by anav
Sun Mar 21, 2021 5:33 pm
Forum: General
Topic: 3 recursive route failover
Replies: 20
Views: 7310

Re: 3 recursive route failover

Kewl, would be interested in seeing such a script if you develop one. Right now trying to add telegram messages to iphone from router........ sunday fun.
by anav
Sun Mar 21, 2021 4:13 pm
Forum: General
Topic: 3 recursive route failover
Replies: 20
Views: 7310

Re: 3 recursive route failover

Simple 3/5 ping test would probably be good enough.

But I was thinking about stacking netwatches..
Why not do an IF statement in a single netwatch script.
IF 3 successive pings at 5 seconds apart = no connectiivity to ISP1 then
a. check router is now using ISP2
b. flush DNS
by anav
Sun Mar 21, 2021 2:15 pm
Forum: General
Topic: 3 recursive route failover
Replies: 20
Views: 7310

Re: 3 recursive route failover

No caps here, So what I would considering doing is flushing the cache after 60 seconds of a switch. ISP1 to ISP2 In other words, detect switch, check after 60 seconds if still switched then flush? if still connected via ISP2 flush and vice versa. or something like that. Trying to avoid interrupting ...
by anav
Sun Mar 21, 2021 1:03 pm
Forum: General
Topic: 3 recursive route failover
Replies: 20
Views: 7310

Re: 3 recursive route failover

Hi Gotsprings, the answer is I dont flush. ;-) Seriously, if my main connection goes down for whatever reason it may be very temporary and by flushing things I wiipe out any connections. If only temporary everything continues kinda okay, but if one has flushed connections then all is lost. WHat you ...
by anav
Sat Mar 20, 2021 5:46 pm
Forum: Beginner Basics
Topic: Set up RB fiber router with L2TP
Replies: 7
Views: 476

Re: Set up RB fiber router with L2TP

Great explanation!!!
by anav
Sat Mar 20, 2021 4:09 pm
Forum: Beginner Basics
Topic: Set up RB fiber router with L2TP
Replies: 7
Views: 476

Re: Set up RB fiber router with L2TP

Why is that a solution? It is the fact that all VPN needs proxy ARP on bridges??
Please explain!
by anav
Sat Mar 20, 2021 1:54 pm
Forum: General
Topic: Compromised clients / Firewall question
Replies: 3
Views: 382

Re: Compromised clients / Firewall question

(1) Not a fan of bridge firewall filter rules. What is the purpose of this........... ..??????? /interface bridge filter add action=drop chain=input disabled=yes in-bridge=bridge1 log=yes \ src-mac-address=80:7B:3E:37:9C:E5/FF:FF:FF:FF:FF:FF add action=drop chain=input disabled=yes dst-mac-address=\...
by anav
Sat Mar 20, 2021 1:28 pm
Forum: General
Topic: Discovery of external IP address (Noip.com)
Replies: 25
Views: 1611

Re: Discovery of external IP address (Noip.com)

If you have access to the MT router, enable ddns and look at IP Cloud it should tell you your public IP.
by anav
Sat Mar 20, 2021 1:23 pm
Forum: General
Topic: Mikrotik Switch Recommendation for newbie
Replies: 22
Views: 1164

Re: Mikrotik Switch Recommendation for newbie

The TPLINK eap245 is a solid wifi5 performer and as gotsprings noted, for me importantly it stopped the complaining from a daughter on a macbook pro studying virtually at University plus two smartphones etc and I now get no calls for wifi issues from the Mother-in-law. In both cases replaced Capac. ...
by anav
Sat Mar 20, 2021 1:13 pm
Forum: Beginner Basics
Topic: Set up RB fiber router with L2TP
Replies: 7
Views: 476

Re: Set up RB fiber router with L2TP

Not really, But you can use available documentation https://help.mikrotik.com/docs/display/ROS/Getting+started In winbox go to New terminal (CLI) /export hide-sensitive file=anynameyouwish And download/upload to your pc, open in notepad++ and paste in the thread (use code tags - square brackets arou...
by anav
Fri Mar 19, 2021 5:10 pm
Forum: General
Topic: Mikrotik Switch Recommendation for newbie
Replies: 22
Views: 1164

Re: Mikrotik Switch Recommendation for newbie

Concur, the switch you linked in the first post has no routing stats (L3) and is your basic smart L2 device. That worries me since you state on one hand L3 and then choose a totally opposite switch to discuss. You really need to nail down your requirements FIRST.. Size of network, number of users, n...
by anav
Fri Mar 19, 2021 12:45 pm
Forum: General
Topic: Suggestion: Ethernet Cable Test analog signal information
Replies: 2
Views: 614

Re: Suggestion: Ethernet Cable Test analog signal information

Hi James, not sure why your use of a fluke tester has anything to do with the OPs request for functionality on the router. Similarly I could say that I use a Kelin VDV LAN Scout Jr. Tester with great success but it adds nothing to the thread LOL. As far as the request, concur seems like a good idea ...
by anav
Fri Mar 19, 2021 12:41 pm
Forum: General
Topic: DNS connection failure
Replies: 16
Views: 966

Re: DNS connection failure

I am seeing an issue reported in other threads about DNS. Something to the effect that the MT DNS does not use all the available DNS listed addresse,s but only the last one on the list. If that last one is not working for whatever reason, it does not look at the rest! Could be a bug? If this is the ...
by anav
Fri Mar 19, 2021 12:38 pm
Forum: General
Topic: ccr1009 low performance at BT server udp/random, send
Replies: 4
Views: 317

Re: ccr1009 low performance at BT server udp/random, send

1- Network diagram please as explanation is poor
2- /export hide-sensitive file=anynameyouwish
by anav
Fri Mar 19, 2021 12:36 pm
Forum: General
Topic: DNS connection failure
Replies: 16
Views: 966

Re: DNS connection failure

Exactly, so instead of making us guess.
/export hide-sensitive file=anynameyouwish
by anav
Fri Mar 19, 2021 12:35 pm
Forum: General
Topic: Site-to-Site VPN (3 MikroTik routers) [SOLVED]
Replies: 5
Views: 522

Re: Site-to-Site VPN (3 MikroTik routers) [SOLVED]

Not knowing the complex subject, I can only ask.......

Would it make sense to use MT proprietary Eoip tunneling and create a common network, or is that functionality only useful in a two site scenario??
https://help.mikrotik.com/docs/display/ROS/EoIP
by anav
Fri Mar 19, 2021 12:27 pm
Forum: Beginner Basics
Topic: Port forwarding problem
Replies: 2
Views: 260

Re: Port forwarding problem

Couple of things, (1) What version of firmware are you using, looks dated! (2) Second, this /ip address add address=192.168.1.254/24 comment="default configuration" interface=\ ether2-master-local network=192.168.1.0 Should be interface=YOUR BRIDGE (3) The real problem is that your ISP add...
by anav
Thu Mar 18, 2021 8:47 pm
Forum: General
Topic: RB4011iGS: 4 ports as simple L2 switch [SOLVED]
Replies: 8
Views: 577

Re: RB4011iGS: 4 ports as simple L2 switch [SOLVED]

Yes, and GOOD!! I have to comment that this is what you provided. /interface bridge add name=bridge1 /interface bridge port add bridge=bridge1 interface=ether1 add bridge=bridge1 interface=ether2 add bridge=bridge1 interface=ether3 add bridge=bridge1 interface=ether4 and thus no way for us to tell. ...
by anav
Thu Mar 18, 2021 7:24 pm
Forum: General
Topic: Hot to handle VOIP on multiple WANs/backup
Replies: 21
Views: 1186

Re: Hot to handle VOIP on multiple WANs/backup

All sounds good che, I dont even use SIP, not recommended by most.
by anav
Thu Mar 18, 2021 7:21 pm
Forum: General
Topic: Mikrotik cloud, choose IP interface to update
Replies: 13
Views: 873

Re: Mikrotik cloud, choose IP interface to update

Dear, I'm also facing problem with *Cloud* over dual Wan and two gateway. Can you show me screenshot of this solution how I can resolve this Thanks :) Please explain your requirements with respect to the two ISP connections. 1. Are they load balanced (shared between users, and if so how are they sh...
by anav
Thu Mar 18, 2021 4:45 pm
Forum: General
Topic: RB4011iGS: 4 ports as simple L2 switch [SOLVED]
Replies: 8
Views: 577

Re: RB4011iGS: 4 ports as simple L2 switch [SOLVED]

Not that I am aware of.........if the switch is doing it fine, then the question becomes what does the router do differently???
Yes give igmp proxy a try.
by anav
Thu Mar 18, 2021 4:35 pm
Forum: Beginner Basics
Topic: RB 2011iL does not get Gib traffic
Replies: 19
Views: 1380

Re: RB 2011iL does not get Gib traffic

From the spec sheet, use 512 size and 25 fsimple queues rules to get real world results (roughish) = in the area of 425Mbps should be doable. Im with MKX that expecting everyone to get 800 ish is rare. The RB3011 and RB4011 certainly can route at 1gig. The HEx router 2core 4 thread 800Mhz cpu with25...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 22