Community discussions

MikroTik App

Search found 23902 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 80
by anav
Fri May 16, 2025 10:51 pm
Forum: General
Topic: How to selectively provide DNS resolution services?
Replies: 3
Views: 149

Re: How to selectively provide DNS resolution services?

/export file=anynameyouwish (minus router serial number, any public WANIP information, keys)
by anav
Fri May 16, 2025 10:47 pm
Forum: General
Topic: VLANs between CCR and CRS328
Replies: 3
Views: 166

Re: VLANs between CCR and CRS328

Sorry muy importante to see the entire config
/export file=anynameyouwish ( minus router serial number or switch serial number, any public WANIP information, keys )
by anav
Fri May 16, 2025 7:44 pm
Forum: Beginner Basics
Topic: Functional partitioning between CR310 and hAP AX3
Replies: 12
Views: 529

Re: Functional partitioning between CR310 and hAP AX3

Design. Both ISP connections must reach router ( can be through an existing switch ) Router connected to each switch Switch configured as required to each device. Done. What more do you need! State Requirements ( identify all users/devices, include external,internal, admin / then identify all the tr...
by anav
Fri May 16, 2025 7:36 pm
Forum: Beginner Basics
Topic: Dual Wan via PCC Issue
Replies: 1
Views: 120

Re: Dual Wan via PCC Issue

Why use PCC if ECMP is working fine???? Also, I have to laugh, if you know where the problem is, since you have not provided the full config, then why ask for help here?? I usually never even bother looking at snippets, 90% of the time, doesnt provide all the information required for rectification. ...
by anav
Fri May 16, 2025 7:35 pm
Forum: Beginner Basics
Topic: Wireguard Tunnel
Replies: 3
Views: 168

Re: Wireguard Tunnel

I drink coke zero.
Also, enjoy how mikrotic continues to waste our time by not having a new poster process... Thanks, for the efficiency of Latvia, what would we do with our free time!!
by anav
Fri May 16, 2025 7:30 pm
Forum: Beginner Basics
Topic: Three MikroTik hAP ax lite as AP
Replies: 4
Views: 237

Re: Three MikroTik hAP ax lite as AP

I suggest that you forget capsman and simply setup the wifi in each ax lite as you are doing now.
How many vlans do you need on your network? ( often= # of SSIDs, home users, guest users, IOT devices etc. + managment vlan or one can use home vlan as trusted ! )
by anav
Fri May 16, 2025 7:26 pm
Forum: Beginner Basics
Topic: wireguard - BTH and Wireguard interface
Replies: 1
Views: 107

Re: wireguard - BTH and Wireguard interface

Interesting question but the answer is no, as you would need completely different wireguard interface which the router creates. Its kind of automagic............ You start the BTH process, enable it on the router. Then you setup the master Smartphone account on your smartphone. Then from your smartp...
by anav
Fri May 16, 2025 6:59 pm
Forum: General
Topic: Bypass CGNAT using CHR Relay Server - Need help
Replies: 5
Views: 665

Re: Bypass CGNAT using CHR Relay Server - Need help

Post both configs. CHR and first starlink /export file=anynameyouwish ( minus device serial number, any public WANIP information, keys ). To be clear on requirements. There are two sets of road warriors. a. those that need access to LANS on each starlink. b. ADMIN that needs access to LANS too but m...
by anav
Thu May 15, 2025 9:32 pm
Forum: Beginner Basics
Topic: Team Viewer doesn't work
Replies: 8
Views: 612

Re: Team Viewer doesn't work

Yes that was my bad, I meant Remove the NETMASK, what is missing is any DNS-server setting.
by anav
Thu May 15, 2025 9:29 pm
Forum: Beginner Basics
Topic: Review of PPPoE and Firewall rules for improvements
Replies: 10
Views: 868

Re: Review of PPPoE and Firewall rules for improvements

Hahah, luv the explanation jaclaz, but I agree with rextended that the default rules for a single bridge and flat network are just fine ( a very narrow set of initial circumstances )!!
As soon as one starts changing the config, the default rules can usually be better optimized to fit the changes.
by anav
Thu May 15, 2025 5:27 am
Forum: Beginner Basics
Topic: Review of PPPoE and Firewall rules for improvements
Replies: 10
Views: 868

Re: Review of PPPoE and Firewall rules for improvements

Your config aka firewall rules are complete waste of time, its like you decided I am going to focus on blocking everything I can think of or read about or saw a youtube video about and never asked the question do I really need to do this. or WHY doesnt the basic firewall set of rules that MT provide...
by anav
Wed May 14, 2025 11:13 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 332
Views: 559579

Re: Using RouterOS to VLAN your network

As noted, above @sindy's "Bridge Mysteries" post goes in way more depth.
Soon to be a Netflix Series..... The Mystery of Sindy's Bridge ;-)
by anav
Wed May 14, 2025 11:11 pm
Forum: General
Topic: Wireguard tunnel connecting but it does not seem to communicate properly
Replies: 8
Views: 466

Re: Wireguard tunnel connecting but it does not seem to communicate properly

No problem, once you post both config, I will be able to ensure it meets the needs.
by anav
Wed May 14, 2025 11:07 pm
Forum: Beginner Basics
Topic: RB5009 drops hardware vpn packets but not through another switch
Replies: 22
Views: 2330

Re: RB5009 drops hardware vpn packets but not through another switch

Thanks for letting us know, hence why network diagrams are important to inform and provide context on connected devices!!
Advice for all the whackamole advisors here, basically everyone except myself.... ;-PPPP
by anav
Wed May 14, 2025 10:42 pm
Forum: General
Topic: Wireguard tunnel connecting but it does not seem to communicate properly
Replies: 8
Views: 466

Re: Wireguard tunnel connecting but it does not seem to communicate properly

There is no lan 192.168.90......it really just a wireguard subnet with no dhcp or anything but sits at the LAN level and thus is subject to L3 firewall rules. Okay so who is using the full internet ??? Is it the roadwarriors using home internet Is it the roadwarriors using office internet Is it the ...
by anav
Wed May 14, 2025 9:24 pm
Forum: General
Topic: Wireguard tunnel connecting but it does not seem to communicate properly
Replies: 8
Views: 466

Re: Wireguard tunnel connecting but it does not seem to communicate properly

Okay I understand better now, what is going on. For the HAPAC at the office.......... then... Lets give it a wireguard address /ip address 192.168.90.2/24 interface=wireguard network=192.168.90.0 Its settings would be add allowed address=192.168.90.0/24,192.168.88.0./24 endpoint-address=HomerouterIP...
by anav
Wed May 14, 2025 8:55 pm
Forum: Beginner Basics
Topic: Team Viewer doesn't work
Replies: 8
Views: 612

Re: Team Viewer doesn't work

1. What is the purpose of this entry.......... /ip dhcp-server network add address =0.0.0.0/24 gateway =0.0.0.0 netmask=24 2. Format seems off add address=192.168.1.0/24 gateway=192.168.1.1 netmask=24 TRY: add address=192.168.1.0/24 gateway=192.168.1.1 network=192.168.1.0 3. Get rid of the garbage f...
by anav
Wed May 14, 2025 8:35 pm
Forum: General
Topic: Wireguard not connecting after peer Mikrotik reboots
Replies: 1
Views: 198

Re: Wireguard not connecting after peer Mikrotik reboots

Are both devices mikrotik routers?
If so post both or at least the main router.
/export file=anynameyouwish (minus router serial number, any public WANIP information, keys)
by anav
Wed May 14, 2025 8:26 pm
Forum: General
Topic: Wireguard tunnel connecting but it does not seem to communicate properly
Replies: 8
Views: 466

Re: Wireguard tunnel connecting but it does not seem to communicate properly

So just to get this straight. Your ISP gets a private IP?? In other words you can either forward a port (by port) or all ports by DMZ, to the LANIP of the hapac, and the traffic heading for a specific PORT to your ISPs public IP will reach your hapac? If that is the case it should work just fine. 1....
by anav
Wed May 14, 2025 3:44 pm
Forum: Beginner Basics
Topic: Hotspot on VLAN Network with 3rd Party AP
Replies: 2
Views: 250

Re: Hotspot on VLAN Network with 3rd Party AP

Would need to see the complete config
/export file=anynameyouwish ( minus router serial number, any public WANIP information, keys )
by anav
Wed May 14, 2025 12:39 am
Forum: General
Topic: Dual WAN with PCC preventing failover
Replies: 4
Views: 499

Re: Dual WAN with PCC preventing failover

Post your updated latest config for review when ready
/export file=anynameyouwish ( minus router serial number, any public WANIP information, keys)
by anav
Wed May 14, 2025 12:37 am
Forum: General
Topic: Winbox wireguard peer config, doesn't add endpoint to config
Replies: 1
Views: 222

Re: Winbox wireguard peer config, doesn't add endpoint to config

One is unable to easily create and send a client peer user, a completed wireguard setup file or qr code, so dont waste your time. I have provided MT with some thoughts on how to achieve this, lets see what they come up with down the line. For now send your peer users the information in a text file s...
by anav
Tue May 13, 2025 10:16 pm
Forum: Beginner Basics
Topic: Wireguard no longer works
Replies: 23
Views: 1889

Re: Wireguard no longer works

Correct, opening up dns on the input chain, to anything but the LAN, is a bad security practice. WRONG: /interface wireguard peers add allowed-address=10.3.53 .0/24 interface=wireguard1 name=peer5 private-key=\ "12345678+x5heP9Jtyk18+VADKp4tV2Z8S3E=" public-key=\ "987654321+IcGxbs30vd...
by anav
Tue May 13, 2025 8:31 pm
Forum: Beginner Basics
Topic: Wireguard no longer works
Replies: 23
Views: 1889

Re: Wireguard no longer works

You are stating how you achieve some goal but not articulating the requirements clearly. Identify the external users that need access to your device. Identify what they need access to. State how they should connect to you device ( wireguard? port forwarding? ) Also the mechanism. By WANIP, by LANIP,...
by anav
Tue May 13, 2025 8:18 pm
Forum: General
Topic: Wireguard Setup and Confirmation
Replies: 5
Views: 409

Re: Wireguard Setup and Confirmation

First, no need to run around in circles. Step1: Ensure you have a public IP from your ISP or perhaps an ISP provider router that gets a PUBLIC IP, and you can forward ports from the ISP router. Step2: If the answer to 1 is YES, gold, if the answer is NO, then problems, and the question asked above b...
by anav
Tue May 13, 2025 8:12 pm
Forum: General
Topic: Whats wrong with mikrotik and your AX Series?
Replies: 18
Views: 1208

Re: Whats wrong with mikrotik and your AX Series?

Sounds like for every hapax3, they should release a hapNV3, likewise -- ax4, NV4 ;-)
by anav
Tue May 13, 2025 8:10 pm
Forum: General
Topic: Firewall and NAT
Replies: 58
Views: 2631

Re: Firewall and NAT

Clearly the evidence and your statements are in contradiction. You didnt remove wireguard as the peer settings were still there. You didnt remove ether10 DMZ as you named it from the bridge it was still there etc. Without a clear set of requirements, which you keep changing or informing in dribs and...
by anav
Tue May 13, 2025 4:08 pm
Forum: General
Topic: Firewall and NAT
Replies: 58
Views: 2631

Re: Firewall and NAT

Awesome good plan........ the concept of identifying users and traffic needed is that it helps formulate a decent plan and with a decent diagram and config with known context can be provided more readily. 1. Since ether10 is disabled, the one that holds the DMZ, I would suggest not including it on t...
by anav
Tue May 13, 2025 4:48 am
Forum: Beginner Basics
Topic: Wireguard no longer works
Replies: 23
Views: 1889

Re: Wireguard no longer works

1. What third party wirguard vpn are you connecting to?? 2. If the router is acting as server peer for handshake, ( no third party, then your peer is wrong it needs to be the exact wireguard IP /32 of the client peer ) 3. What is the purpose of stating a private key in wireguard peers? Its not asked...
by anav
Mon May 12, 2025 10:55 pm
Forum: Beginner Basics
Topic: Beginner issue with static routes
Replies: 3
Views: 369

Re: Beginner issue with static routes

I dont understand......so you have one RB5009, connected to the internet and it handles most of your regular home traffic?
THen you have a second RB5009 for VPN traffic?
WHY? you only need one device to do both...
by anav
Mon May 12, 2025 10:53 pm
Forum: General
Topic: 2 WAN connections, HOTSPOT and load balancing or link agregation
Replies: 8
Views: 5687

Re: 2 WAN connections, HOTSPOT and load balancing or link agregation

What have you done so far? Where is your config??
by anav
Mon May 12, 2025 10:50 pm
Forum: General
Topic: Firewall and NAT
Replies: 58
Views: 2631

Re: Firewall and NAT

1. Set all of this to none, its known to cause all sorts of weird issues. /interface detect-internet set detect-interface-list= static internet-interface-list= WAN \ lan-interface-list= LAN wan-interface-list= WAN 2. If ether2 is on the bridge there is no need for this entry...... add interface=ethe...
by anav
Mon May 12, 2025 4:19 pm
Forum: General
Topic: Firewall and NAT
Replies: 58
Views: 2631

Re: Firewall and NAT

Why do you even own a router? It looks like your more concerned with blocking traffic vice creating rules to allow only needed traffic. Might as well not bother using the internet. Looks like bloatware............. Focus on needed traffic and at the end of each chain simply put drop rule for everyth...
by anav
Sun May 11, 2025 4:01 pm
Forum: Beginner Basics
Topic: Help with setting up my first Mikrotik
Replies: 30
Views: 4444

Re: Help with setting up my first Mikrotik

or not and simply accept its far easier to know what traffic is needed vice all the ways traffic can possibly circumvent firewall rules.
Allow what you want, drop the rest is as clear and as simple as it gets, anything else is just noise...........
by anav
Sat May 10, 2025 10:08 pm
Forum: Beginner Basics
Topic: Help with setting up my first Mikrotik
Replies: 30
Views: 4444

Re: Help with setting up my first Mikrotik

Much easier to spot errors when your firewall rules are within the same chain as well!! Also for interfaces you could make one for all subnets that need internet, or need access to a printer or whatever you fancy. Its a matter of creating interfaces or firewall address lists for efficiency and clari...
by anav
Sat May 10, 2025 3:55 am
Forum: Beginner Basics
Topic: Help with setting up my first Mikrotik
Replies: 30
Views: 4444

Re: Help with setting up my first Mikrotik

Interface lists are handy things. They are used in different parts of the config. Think of using them as a way to describe one or more interface ( normally vlans once gone down the path of using vlans). The default interface lists are well understood, WAN and LAN. One can make any sort of LIST one n...
by anav
Fri May 09, 2025 6:03 pm
Forum: General
Topic: Wireguard: Endpoint and Current Endpoint differ
Replies: 15
Views: 1069

Re: Wireguard: Endpoint and Current Endpoint differ

The complete config is required as requested for me to reply, unlike anserk I dont like playing whackamole ;-P
Its already clear that you are trying some non-standard setups to deal with a yet to be fully determined wan setup and unknown set of user requirements.
by anav
Fri May 09, 2025 5:53 pm
Forum: Beginner Basics
Topic: Apparent traffic leak from access ports
Replies: 6
Views: 839

Re: Apparent traffic leak from access ports

Forgot to add,
BOTH devices need an IP ADDRESS, that is on the management vlan.
THUS for both need
/ip address
add address=x.x.x.x/24 interface=vlan42mgt network=x.x.x.0
by anav
Fri May 09, 2025 5:52 pm
Forum: Beginner Basics
Topic: Access into some VLANs not working [SOLVED]
Replies: 8
Views: 926

Re: Access into some VLANs not working [SOLVED]

Minor things so far.. 1. Remove the extra entries............... to see if it makes a differerence from: /ip neighbor discovery-settings set discover-interface-list=MGMT lldp-med-net-policy-vlan=1000 TO /ip neighbor discovery-settings set discover-interface-list=MGMT 2. Slight mod /interface bridge ...
by anav
Fri May 09, 2025 5:41 pm
Forum: Beginner Basics
Topic: Apparent traffic leak from access ports
Replies: 6
Views: 839

Re: Apparent traffic leak from access ports

Where is the first switch getting its vlans from aka where is the router providing DHCP for all the subnets?? In other words, is the first device, is NOT acting solely as a switch, and its supposed to be acting as a RoUTER, Important to point out as I was looking for a trunk port from an upstream ro...
by anav
Fri May 09, 2025 3:24 pm
Forum: Beginner Basics
Topic: Access into some VLANs not working [SOLVED]
Replies: 8
Views: 926

Re: Access into some VLANs not working [SOLVED]

As pointed out the config should be: /interface bridge port add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=ether2 pvid=1000 add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=wifi1 pvid=10 add bridge=bridge frame-types=admit-only-untagged...
by anav
Fri May 09, 2025 3:18 pm
Forum: General
Topic: Wireguard: Endpoint and Current Endpoint differ
Replies: 15
Views: 1069

Re: Wireguard: Endpoint and Current Endpoint differ

without seeing config...............hard to say
/export file=anynameyouwish ( minus router serial number, any public WANIP information, keys )
by anav
Thu May 08, 2025 9:36 pm
Forum: Beginner Basics
Topic: VLAN Internet access through Wireguard
Replies: 2
Views: 609

Re: VLAN Internet access through Wireguard

Yes, this is a dogs breakfaST of a config, surprized much works, before tackling wireguard must read this and apply: https://forum.mikrotik.com/viewtopic.php?t=143620 One bridge, all subnets expressed as vlans!! ( and where in the heck did you conjure up this non-existent interface interface=wlan_11...
by anav
Thu May 08, 2025 9:32 pm
Forum: Beginner Basics
Topic: Wireguard no longer works
Replies: 23
Views: 1889

Re: Wireguard no longer works

Not sure what command you used LOL but it wasnt what I gave you which doesnt bode well for future advice not being followed ;-PP

I suspect you used something like
/export verbose file=expoanythingyouwish

Please post without the verbose........
by anav
Thu May 08, 2025 9:21 pm
Forum: Beginner Basics
Topic: Help with setting up my first Mikrotik
Replies: 30
Views: 4444

Re: Help with setting up my first Mikrotik

Avoid those that talk in riddles LOL.........
Case in point, you DONT want to end up like this................ dog pukes on config --> viewtopic.php?p=1142057#p1142017
by anav
Thu May 08, 2025 7:06 pm
Forum: Forwarding Protocols
Topic: DSTNAT port forwarding is not working
Replies: 9
Views: 1273

Re: DSTNAT port forwarding is not working

FIGURING OUT WHAT kind of connection your ISP device is getting certainly is key!! Check IP DHCP Client for your WANIP? a. confirm you are getting private WANIP on the MT device ( should be a private IP from the ISP router LAN side ) CHECK IP Cloud b. check the IP address you get from IP CLOUD enabl...
by anav
Thu May 08, 2025 6:54 pm
Forum: General
Topic: DHCP - how to set primary DNS
Replies: 4
Views: 614

Re: DHCP - how to set primary DNS

Clearly indicating as noted that any hands off adaptation will require scripting.
by anav
Thu May 08, 2025 6:52 pm
Forum: General
Topic: New CCR2004-1G-12S+2XS, management/ether1 question
Replies: 3
Views: 481

Re: New CCR2004-1G-12S+2XS, management/ether1 question

Management should be handled by a management vlan and associated with a TRUSTED interface list, and that TRUSTED interface list should be used for neighbors discovery and mac server winbox-server tool setting. You can attache your PC to any sfp port or to a switch connected to an sfp port and call i...
by anav
Thu May 08, 2025 6:47 pm
Forum: Beginner Basics
Topic: Help with setting up my first Mikrotik
Replies: 30
Views: 4444

Re: Help with setting up my first Mikrotik

RoS is very flexible and allows one to do all kinds of setups, many are not wrong, they are simply not efficient. This is the case with two bridges, it seems like an obvious go to, but its if needing multiple subnets to a.. use a combination of single bridge and assign other ports their own subnet b...
by anav
Thu May 08, 2025 5:24 pm
Forum: General
Topic: DHCP - how to set primary DNS
Replies: 4
Views: 614

Re: DHCP - how to set primary DNS

To be clear you want primary DNS to be your NAS. If the NAS crashes you still want folks to be able to access the internet by a public DNS service. This will not be possible without some intervention after the NAS crashes. For example you could do this... address=192.168.0.0/24 dns-server=adguard-se...
by anav
Thu May 08, 2025 5:01 pm
Forum: General
Topic: Netwatch UP threshold
Replies: 61
Views: 3790

Re: Netwatch UP threshold

/// I will stick with simple ///
by anav
Thu May 08, 2025 4:55 pm
Forum: Beginner Basics
Topic: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup
Replies: 15
Views: 1402

Re: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup

Please provide the configs from both Starlink MT router and the VPS CHR......... 1. There is nothing we can do to control the setup on your roadwarriors. That is up to you to config. On my iphone for example my allowed IPs are 0.0.0.0/0 and any traffic I attempt is routed through the vpn tunnel. The...
by anav
Thu May 08, 2025 4:32 pm
Forum: Beginner Basics
Topic: Wireguard no longer works
Replies: 23
Views: 1889

Re: Wireguard no longer works

Sorry copy and paste the config to here directly via text editor aka notepadd++ Then post here and use the code quotes around the text ( above black square with white square brackets on the same line as Bold and Italics etc.) We appreciate the effort to provide the config, but its against good secur...
by anav
Thu May 08, 2025 4:27 pm
Forum: Beginner Basics
Topic: Help with setting up my first Mikrotik
Replies: 30
Views: 4444

Re: Help with setting up my first Mikrotik

Correct Jaclaz, the use of ether5 as a temporary off bridge port is still valid, and thus at the very end, that switch can be done from a PC working on any of the other ports with admin privileges. a. remove IP address for ether5 and change name back to plain jane ether5. b. remove ether5 from LAN a...
by anav
Thu May 08, 2025 1:03 pm
Forum: Beginner Basics
Topic: Apparent traffic leak from access ports
Replies: 6
Views: 839

Re: Apparent traffic leak from access ports

OP: Any post entry without context is only opinion, we work from facts.
please post both configs
/export file=anynameyouwish ( minus device serial number, any public WANIP information, keys)
by anav
Thu May 08, 2025 1:00 pm
Forum: Beginner Basics
Topic: Mikrotik with LTE to ethernet
Replies: 6
Views: 790

Re: Mikrotik with LTE to ethernet

That is the point, there should not be three people guessing, it should be one person answering correctly for a decently constructed post. Rinse repeat posts per day, day after day, year after year........
Definition of insanity or refusal to look at context.........
by anav
Thu May 08, 2025 4:50 am
Forum: General
Topic: WireGuard proxy (Home VPN) configuration
Replies: 7
Views: 734

Re: WireGuard proxy (Home VPN) configuration

Not sure what you mean, you configure wireguard at each end as applicable. For example: the main bridge, haves 20 hosts connected. I want that the Wireguard tunnel is only applied to the device 192.168.88.20, not the 19 others. For starters you need a plan, and clear requirements For example I have...
by anav
Wed May 07, 2025 11:57 pm
Forum: General
Topic: WireGuard proxy (Home VPN) configuration
Replies: 7
Views: 734

Re: WireGuard proxy (Home VPN) configuration

Not sure what you mean, you configure wireguard at each end as applicable.
by anav
Wed May 07, 2025 11:09 pm
Forum: Beginner Basics
Topic: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup
Replies: 15
Views: 1402

Re: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup

Great then we can expect to see two configs :-)
by anav
Wed May 07, 2025 11:08 pm
Forum: Beginner Basics
Topic: Help with setting up my first Mikrotik
Replies: 30
Views: 4444

Re: Help with setting up my first Mikrotik

Sort of, the bridge can be used for any number of connections of ports but typically its used to encompass all the LAN ports and not the wan Port. Correct one assigns ports to a bridge if they are meant to be glued together at layer2 by that bridge. So if one wanted to apply firewall wall rules (lay...
by anav
Wed May 07, 2025 8:44 pm
Forum: Beginner Basics
Topic: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup
Replies: 15
Views: 1402

Re: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup

Can you draw a network diagram so I can see the relationship between devices, location and how attached to the internet............
by anav
Wed May 07, 2025 8:43 pm
Forum: Beginner Basics
Topic: Help with setting up my first Mikrotik
Replies: 30
Views: 4444

Re: Help with setting up my first Mikrotik

https://www.youtube.com/watch?v=EX6QqHmbBpY&list=PLJ7SGFemsLl0ld4OrcnVBHg4kPk0Y2_Z9 (and many others) From mikrotik................ https://www.youtube.com/watch?v=13NvZY7sRlY https://www.youtube.com/watch?v=ZpAY_6RDuRA https://www.youtube.com/watch?v=kF4b_t6W5fM https://www.youtube.com/watch?v=...
by anav
Wed May 07, 2025 8:33 pm
Forum: General
Topic: WireGuard proxy (Home VPN) configuration
Replies: 7
Views: 734

Re: WireGuard proxy (Home VPN) configuration

Which end has a public IP or an ISP router that one can forward a public IP too...... I would setup a wireguard connection at both ends, one of them being the server for handshake and the other being the client for initial handshake. https://help.mikrotik.com/docs/spaces/ROS/pages/69664792/WireGuard...
by anav
Wed May 07, 2025 8:09 pm
Forum: General
Topic: WINBOX 4 WIREGUARD --> RE-IMAGINED
Replies: 8
Views: 2167

Re: WINBOX 4 WIREGUARD --> RE-IMAGINED

..........
latestinterface1.jpg
..........
latestinterface2.jpg
by anav
Wed May 07, 2025 7:25 pm
Forum: General
Topic: WINBOX 4 WIREGUARD --> RE-IMAGINED
Replies: 8
Views: 2167

Re: WINBOX 4 WIREGUARD --> RE-IMAGINED

1. Due to a better understanding the Responder Function, it is now clear to me that MT had it correctly positioned to be associated with each peer and not the entire interface as I thought. However, I have decided to leave the RESPONDER checkbox on the interface page due to the fact that its likely ...
by anav
Wed May 07, 2025 7:16 pm
Forum: Beginner Basics
Topic: Help with setting up my first Mikrotik
Replies: 30
Views: 4444

Re: Help with setting up my first Mikrotik

That would be the first approach by someone using logic but doesnt know the efficient approach . 1. assign each port a subnet 2. assign a bridge as a subnet for all ports 3. assign a bridge with a subnet for some ports and for others assign separate subnets 4. Assign one bridge (with no dhcp respons...
by anav
Wed May 07, 2025 6:09 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 332
Views: 559579

Re: Using RouterOS to VLAN your network

When a device is acting as a router, the WAN interface ( typically an ethernet port) normally has nothing to do with the LAN bridge. ( only the router itself is getting an IP address via this port ) ( the subnets either get their ip address from the bridge, or via vlans, or possibly partly bridge fo...
by anav
Wed May 07, 2025 6:04 pm
Forum: Beginner Basics
Topic: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup
Replies: 15
Views: 1402

Re: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup

Once fixed, then recheck. I suspect any further issue for road warriors to reach either internet or subnets have more to do with the VPS setup than the MT.
by anav
Wed May 07, 2025 6:03 pm
Forum: Beginner Basics
Topic: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup
Replies: 15
Views: 1402

Re: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup

yup I see that the bridge subnet added for troubleshooting purposes vice single admin devices, no worries. black bold, recommend removing orange bold not required at all red bold, remove blue bold, forgot to add !! /ip firewall filter add action=accept chain=input comment=\ "defconf: accept est...
by anav
Wed May 07, 2025 5:48 pm
Forum: General
Topic: mikrotik hex as wireguard client not working
Replies: 15
Views: 1577

Re: mikrotik hex as wireguard client not working

4. Export and post your full configuration. Redact as necessary, but not too much.
For the mother of god this !!!!
/export file=anynameyouwish (minus router serial number, any public WANIP information, keys )

Also a network diagram to show the relationship between devices..........
by anav
Wed May 07, 2025 12:28 am
Forum: Beginner Basics
Topic: Wireguard server only accessible at home
Replies: 1
Views: 423

Re: Wireguard server only accessible at home

1. I wouldnt name my wg interface mark phone, dont like spaces and its simply the name of the peer,,,,,,, wireguard1 is an example. 2. the address in firewall rule is incorrect should be 192.168.100.0 /24 add chain=input action=accept comment="wg access" in-interface=wireguard1 src-address...
by anav
Wed May 07, 2025 12:20 am
Forum: Beginner Basics
Topic: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup
Replies: 15
Views: 1402

Re: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup

No worries, meant TLC sorry! ( tender loving care ) Local users in your config do use the local WAN for internet, there is no way for them to use wireguard based on the config, so not a concern. a. since the wireguard interface is part of the LAN interface list and b. you have a rule allowing LAN in...
by anav
Tue May 06, 2025 10:42 pm
Forum: General
Topic: AmneziaWG in RouterOS?
Replies: 51
Views: 41756

Re: AmneziaWG in RouterOS?

I forget, what does Amnezia do ?? bada bing!!
by anav
Tue May 06, 2025 10:41 pm
Forum: Beginner Basics
Topic: Mikrotik with LTE to ethernet
Replies: 6
Views: 790

Re: Mikrotik with LTE to ethernet

Anyway it would be much better/easier if you could post more details on your layout and your current configuration, following these instructions: https://forum.mikrotik.com/viewtopic.php?t=203686#p1051720 If I got paid a nickel every time you typed that.......................... One day you too wil...
by anav
Tue May 06, 2025 10:39 pm
Forum: Beginner Basics
Topic: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup
Replies: 15
Views: 1402

Re: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup

On the VPS server you need a relay rule of sorts as wireguard is a peer to peer network so in MT terms it would be add action=accept chain=forward comment="relay rule" in-interface=wg0 out-interface=wg0 Therefore a destination address for 10.0.0.25 would come from a road warrior exit the t...
by anav
Tue May 06, 2025 10:34 pm
Forum: Beginner Basics
Topic: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup
Replies: 15
Views: 1402

Re: Starlink + VPS + Mikrotik + Wireguard + Roadwarrior Setup

First mistake is using ubuntu for VPS in stead of mikrotik CHR ;-P What you are attempting to do I only explain in MT terms. The MT Router behind the starlink needs some TLC! 1. Delete this line, known to cause funky issues on MT devices. or set to none! / interface detect-internet set detect-interf...
by anav
Tue May 06, 2025 9:30 pm
Forum: General
Topic: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks
Replies: 73
Views: 24808

Re: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks

Concur with Sindy, admins job is not about random results LOL, I think most people would simply like certainty and KISS, which setting the initial wireguard listening port ( we are talking the client peer for handshake, so can be anything ) to a fixed number is not going to upset anyone. What is coo...
by anav
Tue May 06, 2025 9:28 pm
Forum: General
Topic: Dual WAN Fallover Question for DHCP Client
Replies: 19
Views: 1519

Re: Dual WAN Fallover Question for DHCP Client

Yes, I prefer to turn off the default route in IP DHCP Settings so its clear to the reader what the routes are doing, clearly in this case the default route, if still in place for WAN2, with the same distance as the PRIMARY, would act like ECMP and thus get some of the sessions. Turning it off and u...
by anav
Tue May 06, 2025 4:50 pm
Forum: General
Topic: Dual WAN Fallover Question for DHCP Client
Replies: 19
Views: 1519

Re: Dual WAN Fallover Question for DHCP Client

That was my fault cgx, I provided the incomplete routes setup ( forgot to ensure the check-gateway=ping were included ) Should have been. /ip route add check-gateway=pin g comment="Primary WAN" dst-address=0.0.0.0/0 gateway=8.8.8.8 routing-table=main scope=10 target-scope=12 add check-gate...
by anav
Mon May 05, 2025 11:40 pm
Forum: Beginner Basics
Topic: 2 questions My Config OK? and SFP as WAN port
Replies: 4
Views: 713

Re: 2 questions My Config OK? and SFP as WAN port

For a config review, as jaclaz stated, the complete config less router serial number any public wanip information or keys is required.
by anav
Mon May 05, 2025 11:39 pm
Forum: General
Topic: Dual WAN Fallover Question for DHCP Client
Replies: 19
Views: 1519

Re: Dual WAN Fallover Question for DHCP Client

2. That was from default configuration from MTK. I dont have set something like that! Nope, this is not part of any default setting, its on the config you provided, and the only way it is enabled is if you made it so, but in any case no biggie, just disable it. ( mostly used for queuing I believe )...
by anav
Mon May 05, 2025 10:19 pm
Forum: Beginner Basics
Topic: Firewall question
Replies: 11
Views: 1128

Re: Firewall question

Not trolling, just call it like I see it. Pushback rebuttal is directly proportional to the ego of the other. :-) Haven't tested lately but ports being forwarded on a router used to show existing on port scans but closed ( not open ) If you add a source address or address list to a dstnat rule, the ...
by anav
Mon May 05, 2025 8:10 pm
Forum: General
Topic: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks
Replies: 73
Views: 24808

Re: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks

I would prefer not to have random port selection as there is always the chance of duplicating a port being used somewhere on the router......................... or something fairly common....22, 80, 443 etc........ but glad to hear this works!!
by anav
Mon May 05, 2025 8:04 pm
Forum: General
Topic: Dual WAN Fallover Question for DHCP Client
Replies: 19
Views: 1519

Re: Dual WAN Fallover Question for DHCP Client

Nothing I can see thus far that would cause any issues. Couple of things seem off. 1. The second NAT rule seems to be doing nothing, you identify a source address but what is being source natted too??? So perhaps you should explain why you have the second rule ( intent-purpose ??) /ip firewall nat a...
by anav
Mon May 05, 2025 3:58 pm
Forum: Beginner Basics
Topic: Firewall question
Replies: 11
Views: 1128

Re: Firewall question

No idea what you mean, if you have an emergency call 911! The only emergency is the bloated crap load of rules you have............. And why are you port forwarding NTP to a subnet?????? Finally, too many parts of the config are missing, I will move on to help someone else more cooperative, as i did...
by anav
Mon May 05, 2025 3:55 pm
Forum: General
Topic: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks
Replies: 73
Views: 24808

Re: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks

If the mikrotik is a client peer for handshake then change the listening port on the interface as this should clear up the issue. Dont laugh but here is a script that will do just that......... It should be paired with a route that checks if there is an address available on the remote server peer ro...
by anav
Mon May 05, 2025 3:43 pm
Forum: General
Topic: Very slow download on mobile through Back to Home
Replies: 6
Views: 2412

Re: Very slow download on mobile through Back to Home

If you now have a static Public IP available to the mikrotik router OR to the ISP router, then remove BTH and simply use full normal wireguard on your MT router.
If its the ISP router that gets a public IP then simply forward the listening port to the MT.......
by anav
Mon May 05, 2025 3:40 pm
Forum: General
Topic: Guru assistance required please with Base VLAN setup
Replies: 4
Views: 694

Re: Guru assistance required please with Base VLAN setup

1. What is connected to each port on the RB4011, ether2,ether3,ether4,ether5, ether6, ether7 ????? 2. It seems you have every vlan going to every port?? if so then this can be shortened TO: /interface bridge vlan add bridge=BR1 tagged=BR1,ether2,ether3,ether4,ether5,ether6,ether7 vlan-ids= 10,20,30,...
by anav
Mon May 05, 2025 2:45 am
Forum: Beginner Basics
Topic: Firewall question
Replies: 11
Views: 1128

Re: Firewall question

Evidence.
Post config
/export file=anynameyouwish ( minus router serial number, any public WANIP, keys )

Also, why do you need www and ftp internally?
by anav
Mon May 05, 2025 12:40 am
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 22149

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

None of those were new rules, it was an excerpt from your existing rules ( thought you would recognize them LOL ). When I give you hints, the idea is for you to then go ahead and do some research. Go to mikrotik documents and in the search put in sniffer. https://help.mikrotik.com/docs/spaces/ROS/pa...
by anav
Sun May 04, 2025 11:39 pm
Forum: General
Topic: Dual WAN Fallover Question for DHCP Client
Replies: 19
Views: 1519

Re: Dual WAN Fallover Question for DHCP Client

Sorry need to see script not pics. /export file=anynameyouwish (minus router serial number, any WANIP public information, keys, passwords ) The pic does show that the first recursive is active, and the second recursive not being used and the backup not being used. Thus nothing strange from that at l...
by anav
Sun May 04, 2025 11:36 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 22149

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

No .......all I did was modifying one existing rule, the bit I added is bolded.

Try sniffing traffic on port 53
by anav
Sun May 04, 2025 9:48 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 22149

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

I dont care about puke windows puke. :-) Also why would your windows PC know that the traffic or DNS is even going in an encrypted tunnel??? The question is are the www lookups from the LAN subnet going through wireguard or not. I am not sure how to test that, but we dont allow your LAN to go anywhe...
by anav
Sun May 04, 2025 9:25 pm
Forum: General
Topic: Dual WAN Fallover Question for DHCP Client
Replies: 19
Views: 1519

Re: Dual WAN Fallover Question for DHCP Client

1`. Here is problem1 add bridge =*F interface= pppoe-out1 Do not add the pppoe interface to the bridge!!! 2. Here is problem2 /ip dhcp-client add comment=defconf interface=ether1 This should be disabled or removed, the client settings for wan are dealt with in the pppoe settings!! 3. Problem number ...
by anav
Sun May 04, 2025 1:50 pm
Forum: Beginner Basics
Topic: Firewall port redirect but open for DNS
Replies: 5
Views: 799

Re: Firewall port redirect but open for DNS

I would say your missing the part of who is being redirected here......... /ip firewall nat add chain=dstnat dst-port=53 protocol=udp to-addresses=10.10.10.2 action=dst-nat comment="redirect DNS" ( src-address=subnet???? src-address-list=???? ) ahh I see you have addressed that in your lat...
by anav
Sat May 03, 2025 11:40 pm
Forum: General
Topic: How to use one CRS as >separate< Switch and >Separate< Firewall
Replies: 7
Views: 690

Re: How to use one CRS as >separate< Switch and >Separate< Firewall

Ahh okay,,,,,,,,,,,,,,,,
So normally the router trunk from the CRS that contains the subnet would not be used but sort of sitting there waiting?? ) and I note that if pFS is not working there are no subnets coming in on the switch side trunk.
by anav
Sat May 03, 2025 11:16 pm
Forum: General
Topic: WireGuard connectivity issue assistance
Replies: 7
Views: 1038

Re: WireGuard connectivity issue assistance

I didnt see any messages on discord.........
by anav
Sat May 03, 2025 11:14 pm
Forum: General
Topic: How to use one CRS as >separate< Switch and >Separate< Firewall
Replies: 7
Views: 690

Re: How to use one CRS as >separate< Switch and >Separate< Firewall

I think its illogical to do both at the same time, but given that its wholly possible, due to flexibility of RoS, then why on earth would you want to create additional subnets (on the router acting part) that have the same address on subnets traversing through the switch part ?????
by anav
Sat May 03, 2025 12:44 am
Forum: Beginner Basics
Topic: Issues with Intervlan Routing
Replies: 2
Views: 639

Re: Issues with Intervlan Routing

Okay so you are using this switch as a Router, and thus assuming your ISP throughout is no bigger than 200Mbps. Lots of things to fix in /interface bridge ports and bridge vlan Read this bible has switch examples -->https://forum.mikrotik.com/viewtopic.php?t=143620 Then watch this video --> https://...
by anav
Sat May 03, 2025 12:34 am
Forum: General
Topic: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks
Replies: 73
Views: 24808

Re: Wireguard stops handshaking out of sudden - Change of port (only) solves it for weeks

Okay so most of that went zing over my head as usual.
What should we ask Mikrotik to do........................
by anav
Fri May 02, 2025 10:52 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 22149

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

Sorry dont read that format.
/export file=anynameyouwish (minus router serial number, any public WANIP information, keys)
by anav
Fri May 02, 2025 8:03 pm
Forum: Beginner Basics
Topic: Basic VLAN setup [SOLVED]
Replies: 8
Views: 1601

Re: Basic VLAN setup [SOLVED]

Probably related........ Should be good to go.
by anav
Fri May 02, 2025 8:02 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 22149

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

No that is for the firewall rule that is duplicated which you did not highlight,,,,,,,,,,,,,,,,,,,,,, the reason is there is no incoming handshake to the router for establishing the vpn connection, its your router that is sending out the intitial handshake and thus its the remote end (if mikrotik) t...
by anav
Fri May 02, 2025 8:00 pm
Forum: General
Topic: WireGuard connectivity issue assistance
Replies: 7
Views: 1038

Re: WireGuard connectivity issue assistance

Where are you located? I can help but dont take payments..........
contact me at discord (removed no messages sent)
by anav
Fri May 02, 2025 3:38 pm
Forum: General
Topic: Assign (wireguard) interface local ip route to specific routing table
Replies: 24
Views: 1879

Re: Assign (wireguard) interface local ip route to specific routing table

Its RoS, not linux, sorry. VRF will work for your requirements.
by anav
Fri May 02, 2025 3:37 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 22149

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

Just the one dealing with wireguard and do you know why it is not required??
by anav
Fri May 02, 2025 3:11 pm
Forum: Beginner Basics
Topic: Basic VLAN setup [SOLVED]
Replies: 8
Views: 1601

Re: Basic VLAN setup [SOLVED]

Hmm probably a few errors, lets see what we can ascertain. 1. This rule is not required. If you note that the last rule states DROP ALL ELSE, this means anything above this rule NOT allowed will automatically be dropped so this rule is not wrong but simply not needed. add action=drop chain=forward c...
by anav
Fri May 02, 2025 1:56 pm
Forum: Beginner Basics
Topic: RB5009 drops hardware vpn packets but not through another switch
Replies: 22
Views: 2330

Re: RB5009 drops hardware vpn packets but not through another switch

Suspect simply hiding the mac address...............??
by anav
Fri May 02, 2025 1:54 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 22149

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

Your config rsc is fine, regarding security, As for observations, just two........ a. WHy do you have this rule??? add action=accept chain=input comment="Allow WireGuard" dst-port=51820 \ protocol=udp b. why do you have this rule out of the order for forward chain rules and especially when...
by anav
Fri May 02, 2025 1:48 pm
Forum: General
Topic: Assign (wireguard) interface local ip route to specific routing table
Replies: 24
Views: 1879

Re: Assign (wireguard) interface local ip route to specific routing table

Yes it can, use VRF to create the additional virtual routing table on the mikrotik device!!
by anav
Fri May 02, 2025 1:41 pm
Forum: General
Topic: NAT Hairpin Configuration Troubles
Replies: 22
Views: 4322

Re: NAT Hairpin Configuration Troubles

I see you have a fixed WANIP......... Thus (KISS) /ip firewall nat add action=masquerade chain=srcnat dst-address=192.168.1.0/24 src-address=192.168.1.0/24 add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface-list=WAN add action=dst-nat chain...
by anav
Fri May 02, 2025 1:37 pm
Forum: General
Topic: NAT Hairpin Configuration Troubles
Replies: 22
Views: 4322

Re: NAT Hairpin Configuration Troubles

/ip firewall address-list add mynetname.net list= MyWAN { using your my ip cloud name } /ip firewall nat add action=masquerade chain=srcnat dst-address=192.168.1.0/24 src-address=192.168.1.0/24 add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-inte...
by anav
Fri May 02, 2025 1:22 pm
Forum: Beginner Basics
Topic: RB5009 drops hardware vpn packets but not through another switch
Replies: 22
Views: 2330

Re: RB5009 drops hardware vpn packets but not through another switch

Does the RB5009 provide time to the netgear switch (NTP). Stretch but thinking of things that may cause differences.
Wonder if you can borrow a different switch to see if the behaviour remains.
by anav
Fri May 02, 2025 4:03 am
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 22149

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

Any information that identifies the IP address of the ISP internet address you were given, or the ISP gateway IP address etc..........
or any passwords or usernmames provided by the ISP.
by anav
Thu May 01, 2025 10:28 pm
Forum: Beginner Basics
Topic: Windscribe VPN using Wireguard on Mikrotik that works!
Replies: 1
Views: 613

Re: Windscribe VPN using Wireguard on Mikrotik that works!

Its better than most but still has some meandering not well explained items and some errors but overall not a bad video.
The fact that you state firewall rules should have no bearing on the wireguard config also detracts from the post ( aka your assessment).
by anav
Thu May 01, 2025 8:41 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 22149

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

Sure,
/export file=anynameyouwish (minus router serial number, any public WANIP information, keys)
by anav
Thu May 01, 2025 8:38 pm
Forum: General
Topic: Assign (wireguard) interface local ip route to specific routing table
Replies: 24
Views: 1879

Re: Assign (wireguard) interface local ip route to specific routing table

There may be some tricks you can do with NAT ( source or destination ) but this assumed two mikrotiks at either end. Also its not clear whether or not the duplication is the subnet at your router, with wireguard, OR with the remote subnet at the other end, with wireguard? Lets assume the duplication...
by anav
Thu May 01, 2025 7:58 pm
Forum: Beginner Basics
Topic: Mikrotik as a wireguard VPN client how to
Replies: 3
Views: 673

Re: Mikrotik as a wireguard VPN client how to

Anav, I think some people will still use the web interface as opposed to using Winbox, so I included those remove commands in order to clear out those config items in that scenario where they may have made initial ip configurations. Ahhh okay, my bad. Ensure though you reference that so its clear t...
by anav
Thu May 01, 2025 7:56 pm
Forum: General
Topic: Connection tracking table not cleared completely after WAN IP address change
Replies: 38
Views: 13137

Re: Connection tracking table not cleared completely after WAN IP address change

Nathan your hurting my brain, is there any reason to separate connection tracking clearing of change IP and down and change of ISP? and if not, then MT simply needs to ensure the functionality exists that covers both, even if its just a checkbox.
by anav
Thu May 01, 2025 7:54 pm
Forum: General
Topic: [Feature Request] ECMP Hashing Option – Source IP Only (ROS7)
Replies: 6
Views: 823

Re: [Feature Request] ECMP Hashing Option – Source IP Only (ROS7)

heated agreement, MT needs to make src address only as ECMP hash option.
by anav
Thu May 01, 2025 7:52 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 22149

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

There is also the similar mangle rule, probably wont help either but worth a shot..... disable the other and try this one: add action=change-mss chain=forward comment="Clamp MSS to PMTU for Outgoing packets" new-mss=clamp-to-pmtu out-interface=wg-nordvpn passthrough=yes protocol=tcp tcp-fl...
by anav
Thu May 01, 2025 7:50 pm
Forum: General
Topic: Assign (wireguard) interface local ip route to specific routing table
Replies: 24
Views: 1879

Re: Assign (wireguard) interface local ip route to specific routing table

What routers or devices are handling wireguard at each end?
by anav
Thu May 01, 2025 7:45 pm
Forum: Beginner Basics
Topic: Mikrotik as a wireguard VPN client how to
Replies: 3
Views: 673

Re: Mikrotik as a wireguard VPN client how to

I would make some changes....... as follows ( we gave used a wireguard interface name ( can use whatever you prefer) of wireguard-VPN ) THIRD PARTY VPN - one flat subnet only /interface wireguard add name=wireguard-VPN mtu=1420 listen-port= AnyPort# \ private-key="INSERT THE PROVIDED PRIVATE KE...
by anav
Thu May 01, 2025 4:46 pm
Forum: General
Topic: [Feature Request] ECMP Hashing Option – Source IP Only (ROS7)
Replies: 6
Views: 823

Re: [Feature Request] ECMP Hashing Option – Source IP Only (ROS7)

Did you make your suggestion directly to Mikrotik via their support page sub section Suggestion ( vice Bug )??
Seems like an L3-lite is a very worthwhile suggestion.
by anav
Thu May 01, 2025 4:43 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 22149

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

yes you could try adding this rule in ip firewall mangle.
add action=change-mss chain=forward new-mss=1380 out-interface=wg-nordvpn protocol=tcp tcp-flags=syn tcp-mss=1381-65535
by anav
Thu May 01, 2025 4:39 pm
Forum: General
Topic: Assign (wireguard) interface local ip route to specific routing table
Replies: 24
Views: 1879

Re: Assign (wireguard) interface local ip route to specific routing table

Instead of presupposing the solution stating the issue solely and asking for potential approaches is better. To be clear a. who decided the IP address schema of the wireguard subnet and can you change it? b. who decided the IP address schema of the local subnet that clashes and can you change it. Th...
by anav
Thu May 01, 2025 2:09 pm
Forum: Beginner Basics
Topic: wireguard site to site
Replies: 3
Views: 685

Re: wireguard site to site

/export file=anynamwyouwish (minus router serial number, any public WANIP information, keys) for both sites.
by anav
Thu May 01, 2025 2:08 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 22149

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

For this one, i got this error while trying to add [admin@MikroTik] /ip/firewall/filter> add action=accept chain=forward comment="Subnet to wireguard" out-interface=wg-nordvpn src-address=50.50.50/0/24 value of range must have netmask after '/' either as number or as ip value Of course it...
by anav
Thu May 01, 2025 1:12 pm
Forum: Beginner Basics
Topic: Basic VLAN setup [SOLVED]
Replies: 8
Views: 1601

Re: Basic VLAN setup [SOLVED]

Okay, nice explanation!! From my reading its probably best to have the NVR and the cameras on the same subnet but this is still possible and keep all your requirements. Just a bit of finessing on the firewall rules. Not sure why you have an ageing time set on the bridge, first time Ive seen that so ...
by anav
Thu May 01, 2025 2:26 am
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 22149

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

For router security also recommend the following rules. /ip firewall filter { input chain default rules to keep } add action=accept chain=input connection-state=established,related,untracked add action=drop chain=input connection-state=invalid add action=accept chain=input protocol=icmp add action=a...
by anav
Thu May 01, 2025 2:16 am
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 22149

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

Yes, the rules provide good security and prevent leakage as you desire.
They only allow lan traffic out the wireguard tunnel.

As to the other question, just to confirm that you have a default route enabled in LTE settings.
I am assuming you do otherwise the tunnel could not be established.
by anav
Thu May 01, 2025 2:15 am
Forum: General
Topic: Connection tracking table not cleared completely after WAN IP address change
Replies: 38
Views: 13137

Re: Connection tracking table not cleared completely after WAN IP address change

Sorry lurker didnt really understand but you seem to be saying that with the new kernel ( really still an old kernel ) that MT is now using, the unexpected behaviour is normal/expected, much to our shagrin. Furthermore, you are hoping that MT comes up with a built-in easier way to clear the connecti...
by anav
Thu May 01, 2025 1:11 am
Forum: General
Topic: Connection tracking table not cleared completely after WAN IP address change
Replies: 38
Views: 13137

Re: Connection tracking table not cleared completely after WAN IP address change

Yup watching this thread as most expect masquerade to clear connections..........otherwise rextended scripts will get extended use LOL.
I would not consider this solved until MT replies with certainty about new behaviour or they forget to do something during programming etc............
by anav
Thu May 01, 2025 1:02 am
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 22149

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

Okay, 1. Modify allowed IPs from: /interface wireguard peers add allowed-address=0.0.0.0/0 ,::/0 endpoint-address= \ endpoint-port= interface=wg-nordvpn name=peer1 public-key="" TO: /interface wireguard peers add allowed-address= 0.0.0.0/0 endpoint-address="as provided" \ endpoin...
by anav
Wed Apr 30, 2025 2:52 pm
Forum: Announcements
Topic: v7.19rc [testing] is released!
Replies: 199
Views: 45423

Re: v7.19rc [testing] is released!

Looks like you pushed a release candidate (beta) to production. Probably not the smartest move.
Larsa, dont they teach that at IT school. Use the latest beta firmware for production!
Maybe they took that advice when running the Spanish electrical grid ;-)
by anav
Wed Apr 30, 2025 2:36 pm
Forum: Beginner Basics
Topic: Primary gateway with static ip address not activating
Replies: 24
Views: 10859

Re: Primary gateway with static ip address not activating

If you think the two rules are complex, I imagine you don't do the cooking at home ;-PP
I dont disagree with the simple approach, but nothing wrong with knowing how one gets there and thus able to adjust if required.
by anav
Wed Apr 30, 2025 2:05 am
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 22149

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

You have hidden to much information to be of real assistance. The only thing that should not be entered is a. NORD VPN settings - private key - public key - endpoint address The rest should have been available for viewing. b. Router settings - serial number ( check ) - endpoint-address ( check ) - p...
by anav
Tue Apr 29, 2025 11:39 pm
Forum: Beginner Basics
Topic: hEX refresh/ as Switch ->Pros & Cons?
Replies: 37
Views: 3722

Re: hEX refresh/ as Switch ->Pros & Cons?

Danke!!
by anav
Tue Apr 29, 2025 11:31 pm
Forum: Beginner Basics
Topic: Primary gateway with static ip address not activating
Replies: 24
Views: 10859

Re: Primary gateway with static ip address not activating

Lets set the rules straight here!!! TWO RULES OF THUMB (scope & target scope): First Rule . The resolving route (DIRECT - connected route) with dst-address TO the "real WWW IP (dns site)" and with local ISP gateway IP, has Target-Scope=X and the recursive route (INDIRECT - external rou...
by anav
Tue Apr 29, 2025 11:24 pm
Forum: Beginner Basics
Topic: Basic VLAN setup [SOLVED]
Replies: 8
Views: 1601

Re: Basic VLAN setup [SOLVED]

The bible on setting up vlans: viewtopic.php?t=143620
by anav
Tue Apr 29, 2025 11:24 pm
Forum: Beginner Basics
Topic: Basic VLAN setup [SOLVED]
Replies: 8
Views: 1601

Re: Basic VLAN setup [SOLVED]

Provide a diagram and a clearer description of the requirements Does the NVR need to be on the same subnet as the cameras? One can access the NVR by IP address and not have to be in the same LAN (advised for security reasons). So neither cameras nor NVR need access to the internet?? Wifi will have h...
by anav
Tue Apr 29, 2025 11:13 pm
Forum: Beginner Basics
Topic: Hex refresh download speed
Replies: 25
Views: 2969

Re: Hex refresh download speed

Go to the support page: https://mikrotik.com/support
Select the CONTACT SUPPORT BAR in the middle of the page: https://help.mikrotik.com/servicedesk/s ... r/portal/1
by anav
Tue Apr 29, 2025 11:11 pm
Forum: Beginner Basics
Topic: hEX refresh/ as Switch ->Pros & Cons?
Replies: 37
Views: 3722

Re: hEX refresh/ as Switch ->Pros & Cons?

Yes and no. Even with the odd ether-1 setup, it's faster then old Hex when used as a normal router. As a switch however, that's another story. I'm sure they made it in accordance to what's needed for majority of their customers. We only see a fraction of that population here (and only the most savv...
by anav
Tue Apr 29, 2025 11:10 pm
Forum: Beginner Basics
Topic: Mikrotik using wireguard as VPN client [SOLVED]
Replies: 8
Views: 1040

Re: Mikrotik using wireguard as VPN client [SOLVED]

Obscure, not, simple transaction issue: No one paid my tariff of 365 belgian chocolates ( one for every day ). ;-)
by anav
Tue Apr 29, 2025 7:46 pm
Forum: General
Topic: mikrotik hex as wireguard client not working
Replies: 15
Views: 1577

Re: mikrotik hex as wireguard client not working

Hi Jaclaz, I assumed the OP, when he stated he was behind NAT, meant that the hex was behind an upstream router ( aka ISP or own )??
by anav
Tue Apr 29, 2025 7:16 pm
Forum: Wireless Networking
Topic: Virtual WiFis to different isolated VLANs
Replies: 5
Views: 1133

Re: Virtual WiFis to different isolated VLANs

Now, there are many parts of the config missing, so no guarantees if the router will work properly in all circumstances or if the setup is secure..
by anav
Tue Apr 29, 2025 7:13 pm
Forum: Wireless Networking
Topic: Virtual WiFis to different isolated VLANs
Replies: 5
Views: 1133

Re: Virtual WiFis to different isolated VLANs

Two errors: You changed the PVID on the bridge itself, this should kept to the default of 1. Secondly forgot to tag the bridge! Modifications: /interface bridge add ingress-filtering=no name=bridge1 protocol-mode=none pvid=1 vlan-filtering=yes (once the rest is setup and working add frame-types=admi...
by anav
Tue Apr 29, 2025 7:03 pm
Forum: General
Topic: mikrotik hex as wireguard client not working
Replies: 15
Views: 1577

Re: mikrotik hex as wireguard client not working

Its an excellent cheap wireguard device as a host and its easy to setup.
You just have to be clear on the requirements and a network diagram also helps in planning.
by anav
Tue Apr 29, 2025 7:00 pm
Forum: Beginner Basics
Topic: Extend wifi in small house
Replies: 13
Views: 1881

Re: Extend wifi in small house

There would be no problem with a wired only version, just plug in a wifi AP at the other end............
by anav
Tue Apr 29, 2025 5:26 pm
Forum: Wireless Networking
Topic: Virtual WiFis to different isolated VLANs
Replies: 5
Views: 1133

Re: Virtual WiFis to different isolated VLANs

1. A port carrying only a single vlan tagged subnet is still a trunk port LOL. 2. What are the tagged vlans on ports 3,4 and 6-8 going to?? Any smart device on the network should be on the managment vlan ( get its LANIP from the management subnet ) and thus each trunk port should carry as a minimum ...
by anav
Tue Apr 29, 2025 5:17 pm
Forum: General
Topic: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x
Replies: 54
Views: 22149

Re: How to Configure a WireGuard VPN Connection to NordVPN on a Mikrotik Router Running ROS v7.x

Provide
a. the config settings provided........... ( minus endoint address use x.x.x.x.x and any keys )
b. router config
/export file=anynameyouwish ( minus router serial number, any public WANIP information, keys )
by anav
Tue Apr 29, 2025 5:13 pm
Forum: General
Topic: mikrotik hex as wireguard client not working
Replies: 15
Views: 1577

Re: mikrotik hex as wireguard client not working

It is not clear what you are doing on the hex as you dont provide an actual config.......... nor is it clear what you are connecting to, a third party provider, your own server somewhere?? Nor are the requirements stated, what is the purpose of the wg connection for the hex............ to reach inte...
by anav
Tue Apr 29, 2025 5:08 pm
Forum: General
Topic: Using AI to help configuring RouterOS and scripting
Replies: 47
Views: 3327

Re: Using AI to help configuring RouterOS and scripting

Indeed advanced!!
MT AI BOT Transcript.

Hey Bot, is Normis Sexy?

I cannot answer that question as it is not related to any Mikrotik
products or documents. However, yes, but without the beard. :-)
by anav
Tue Apr 29, 2025 5:04 pm
Forum: Beginner Basics
Topic: hEX refresh/ as Switch ->Pros & Cons?
Replies: 37
Views: 3722

Re: hEX refresh/ as Switch ->Pros & Cons?

It would seem that the ether1 renders this device useless compared to older versions of hex ( except arm core of course and thus BTH etc. )
by anav
Tue Apr 29, 2025 4:59 pm
Forum: Beginner Basics
Topic: Hex refresh download speed
Replies: 25
Views: 2969

Re: Hex refresh download speed

This would be appear to be some hardware or firmware issue, cannot see it being related to RoS. Should be reported as bug to MT.
And perhaps a product wide recall and refund to all purchasers of this product and rename the product to Hex Recycle ;-)
by anav
Tue Apr 29, 2025 4:44 pm
Forum: Beginner Basics
Topic: Mikrotik using wireguard as VPN client [SOLVED]
Replies: 8
Views: 1040

Re: Mikrotik using wireguard as VPN client [SOLVED]

No, you have configured the mikrotik to ensure that the communication you seek is not available. In other words self-inflicted due to lack of knowledge. The firewall rules are not the problem. The basis of error is a missing routing rule..... Complete review follows. You have not provided any of the...
by anav
Mon Apr 28, 2025 11:38 pm
Forum: General
Topic: Asking non-Mikrotk questions
Replies: 11
Views: 841

Re: Asking non-Mikrotk questions

One must first ask, is this the optimal location to ask such a question? For example, when did the Ford Mustang first come out with a v-8 engine? OR How do they put the cadbury milk chocolate in the cadbury milk chocolate bar? Both are technology questions! :-) Neither of which the MT AI bot could a...
by anav
Mon Apr 28, 2025 9:16 pm
Forum: General
Topic: CRS309 Bridging and VLANs
Replies: 4
Views: 1775

Re: CRS309 Bridging and VLANs

My bad I looked at the date of the responder and not the original post date LOL.
I blane yahelb for bringing it back to life ;-)
by anav
Mon Apr 28, 2025 8:46 pm
Forum: General
Topic: CRS309 Bridging and VLANs
Replies: 4
Views: 1775

Re: CRS309 Bridging and VLANs

I didnt get past the first para where your world has apparently ended, but you have never posted here for help. Why come here to complain, this is not the complaint department its the get assistance with your config department. Counselling and mental health well being are down the hall. The way it w...
by anav
Sun Apr 27, 2025 11:53 pm
Forum: General
Topic: Mikrotik iOS app - connection refused
Replies: 7
Views: 1800

Re: Mikrotik iOS app - connection refused

It works, something wrong with your device settings or the manual information you provided to connect.s Possibly a permissions on the router as well.
by anav
Sun Apr 27, 2025 11:51 pm
Forum: Beginner Basics
Topic: hEX refresh/ as Switch ->Pros & Cons?
Replies: 37
Views: 3722

Re: hEX refresh/ as Switch ->Pros & Cons?

Same questions I had. I believe the NVR talks to the reolink cloud server. User, via their reolink app, reach the cloud server and then down to their NVR. The NVR should have no ports forwarded to it, that would be bad, if the OP was thinking of port forwarding to view direclty by IP or something. A...
by anav
Sun Apr 27, 2025 11:46 pm
Forum: Useful user articles
Topic: Logging and Blocking IPs Based on Failed Authentication Attempts
Replies: 1
Views: 14446

Re: Logging and Blocking IPs Based on Failed Authentication Attempts

KISS ( i personally would never go to the complex lengths above)! - never open up DNS to the WAN side. - have drop all else rules at end of forward and input chains - do not host servers if at all possible, if you must....... do you really have to???? a. use VPN for users to access subnet locations ...
by anav
Sun Apr 27, 2025 4:58 pm
Forum: General
Topic: Can not access the CPU via incomming vlan !! :(
Replies: 12
Views: 1678

Re: Can not access the CPU via incomming vlan !! :(

Sorry cannot help further. The advice from the beginning has been one bridge..........lead a horse to water......
by anav
Sun Apr 27, 2025 3:12 pm
Forum: General
Topic: Can not access the CPU via incomming vlan !! :(
Replies: 12
Views: 1678

Re: Can not access the CPU via incomming vlan !! :(

One would have to provide the fact. /export file=anynameyouwish (minus router serial number, any public WANIP informaiton, keys) In both cases, device as a switch or router: The fact of the matter is the bridge does NOT get an address. The vlan gets an address. The only route required on a switch, a...
by anav
Sat Apr 26, 2025 6:25 pm
Forum: Beginner Basics
Topic: force subnet through specific gateway
Replies: 7
Views: 921

Re: force subnet through specific gateway

Without some diagrams nothing makes sense.
by anav
Sat Apr 26, 2025 6:22 pm
Forum: General
Topic: Dual WAN Failover script - feedback pls
Replies: 13
Views: 1692

Re: Dual WAN Failover script - feedback pls

Will stick to recursive, works and is much easier or via netwatch if one doesnt want to wait 10 seconds etc....
by anav
Sat Apr 26, 2025 6:21 pm
Forum: General
Topic: Can not access the CPU via incomming vlan !! :(
Replies: 12
Views: 1678

Re: Can not access the CPU via incomming vlan !! :(

Well, its pretty straightforward...... Only one vlan is identified on the switch, the management vlan and in IP address is where switch gets its IP address from. Only the managment vlan is tagged with the bridge, the rest are tagged on the incoming trunk port and as required on outgoing ports ( unta...
by anav
Sat Apr 26, 2025 4:29 am
Forum: General
Topic: Can not access the CPU via incomming vlan !! :(
Replies: 12
Views: 1678

Re: Can not access the CPU via incomming vlan !! :(

Is this the same device that mkx was trying to help you with??
by anav
Fri Apr 25, 2025 7:59 pm
Forum: Beginner Basics
Topic: Primary gateway with static ip address not activating
Replies: 24
Views: 10859

Re: Primary gateway with static ip address not activating

You didnt get rid of raw rules................
by anav
Fri Apr 25, 2025 7:08 pm
Forum: Beginner Basics
Topic: force subnet through specific gateway
Replies: 7
Views: 921

Re: force subnet through specific gateway

draw a network diagram.
Do you mean you have two WAN connections?
Do you mean you have two Subnets?

Etc..............
by anav
Fri Apr 25, 2025 7:06 pm
Forum: Wireless Networking
Topic: hEX and CAP ac
Replies: 3
Views: 767

Re: hEX and CAP ac

I use my capacs with my hex without capsman its quick and easy to config. Your hair will not turn gray or fall out!!
by anav
Fri Apr 25, 2025 7:05 pm
Forum: General
Topic: Dual WAN failover - check internet
Replies: 23
Views: 1728

Re: Dual WAN failover - check internet

Sweet!!
by anav
Fri Apr 25, 2025 7:04 pm
Forum: General
Topic: WireGuard connectivity issue assistance
Replies: 7
Views: 1038

Re: WireGuard connectivity issue assistance

You have hidden way to much information, just the WAN public information and the only thing that would relevent is the username and password on pppoe. 1. Improve Interface list entries, but I dont see a trusted or management vlan?? Ahh you are mixing apples and oranges. Once you go vlans so will cha...
by anav
Fri Apr 25, 2025 6:44 pm
Forum: General
Topic: Dual WAN failover - check internet
Replies: 23
Views: 1728

Re: Dual WAN failover - check internet

Netwatch leaks out any wan to find a connection and thus you need to blackhole any netwatch routing with a second following route same table distance add one.
by anav
Fri Apr 25, 2025 6:39 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1498

Re: WireGuard Traffic Issue

Then setup vlan filtering now and once its smooth, do the wireguard, should take me 10minutes to fix once you have an initial config its like butta. First however, its best to work the config from an OFF the bridge position. What i recommend is create an offbridge port for local emergency access. So...
by anav
Fri Apr 25, 2025 6:38 pm
Forum: General
Topic: Reliable addresses to ping on internet
Replies: 24
Views: 2270

Re: Reliable addresses to ping on internet

Yearly rate of $20,000, that an over 50% markdown sale!! Get it while its hot!
by anav
Fri Apr 25, 2025 6:36 pm
Forum: General
Topic: Respond for the internet connection through which they connect.
Replies: 3
Views: 647

Re: Respond for the internet connection through which they connect.

As you may have guessed the responders have some WHAT IFs, and other suggestions ( and also some errors). In other words, you should not be asking for a part solution if the requirements are not fully identified. A better response can be had when we know what else is going on the router for both inc...
by anav
Fri Apr 25, 2025 6:32 pm
Forum: General
Topic: Reliable addresses to ping on internet
Replies: 24
Views: 2270

Re: Reliable addresses to ping on internet

You can use mine, only 5c per ping.
by anav
Fri Apr 25, 2025 1:44 pm
Forum: Beginner Basics
Topic: Primary gateway with static ip address not activating
Replies: 24
Views: 10859

Re: Primary gateway with static ip address not activating

This is a clue that the router is not happy with your config....... /interface list member add comment=defconf interface=bridge list=LAN add comment=defconf interface=ether1 list=WAN add interface= *9 list=WAN add interface=ether2 list=WAN /ipv6 dhcp-client add add-default-route=yes interface =*9 po...
by anav
Fri Apr 25, 2025 1:38 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1498

Re: WireGuard Traffic Issue

The point is wireguard is not the real issue at the moment. Once the config is fixed, then we will be able to see whats going with wireguard, if its still a problem.
by anav
Fri Apr 25, 2025 4:47 am
Forum: General
Topic: Confused about Bridge PVID 1
Replies: 10
Views: 1089

Re: Confused about Bridge PVID 1

Put cement in the serial port ;-P
by anav
Thu Apr 24, 2025 9:28 pm
Forum: General
Topic: Confused about Bridge PVID 1
Replies: 10
Views: 1089

Re: Confused about Bridge PVID 1

also add
/ip neighbours discovery
set interface-list=TRUSTED


The option to change the pvid of the bridge exists because in some niche situations it may be required.
I would say its rare but I dont know enought to state what weird setups this would make sense for.
by anav
Thu Apr 24, 2025 8:58 pm
Forum: General
Topic: Confused about Bridge PVID 1
Replies: 10
Views: 1089

Re: Confused about Bridge PVID 1

1. Any port not being used should be a. disabled preferably OR b. at least removed from bridge c. the bridge itself retain default pvid but set frame-types=admit-only-vlan-tagged. d. on ports being used, ensure ingress-filtering is enabled and frame types set as required ( either vlan tagged, OR pri...
by anav
Thu Apr 24, 2025 8:50 pm
Forum: Beginner Basics
Topic: Primary gateway with static ip address not activating
Replies: 24
Views: 10859

Re: Primary gateway with static ip address not activating

a diagram and revised cleaned up config may help us provide better assistance.
by anav
Thu Apr 24, 2025 8:37 pm
Forum: Beginner Basics
Topic: hEX refresh/ as Switch ->Pros & Cons?
Replies: 37
Views: 3722

Re: hEX refresh/ as Switch ->Pros & Cons?

One flat network or vlans? diagram will help understand
by anav
Thu Apr 24, 2025 8:33 pm
Forum: General
Topic: Defeated by VLAN issue [SOLVED]
Replies: 9
Views: 1532

Re: Defeated by VLAN issue [SOLVED]

Okay, so depending upon the ability of the unmanaged switch then we have two options and one, both, or none may work. a. make it a trunk port to the un-managed switch both vlans tagged b. make it a hybrid port to the un-managed switch, tagged for one, and untagged for the other. May the best option ...
by anav
Thu Apr 24, 2025 8:01 pm
Forum: Beginner Basics
Topic: Primary gateway with static ip address not activating
Replies: 24
Views: 10859

Re: Primary gateway with static ip address not activating

Yes please, clean up the config, garbage is noise and noise makes it difficult to read a config OR to spot errors..........
by anav
Thu Apr 24, 2025 7:30 pm
Forum: Beginner Basics
Topic: hEX refresh/ as Switch ->Pros & Cons?
Replies: 37
Views: 3722

Re: hEX refresh/ as Switch ->Pros & Cons?

Any hex device makes a great little managed switch that works great in a home setting or even an office setting. If one is in a corporate setting where, for example, the same vlan spans two or more ports on the switch, to users that will be sending huge amounts of data back and forth across the swit...
by anav
Thu Apr 24, 2025 7:27 pm
Forum: General
Topic: WireGuard connectivity issue assistance
Replies: 7
Views: 1038

Re: WireGuard connectivity issue assistance

Best to provide your config for review /export file=anynameyouwish (minus router serial number, any public WANIP information, keys),.\ Steps 1. Take the private key given to you and when you make an interface on the MT router, use that private key to generate a public key ( that way windscribe alrea...
by anav
Thu Apr 24, 2025 7:06 pm
Forum: General
Topic: Defeated by VLAN issue [SOLVED]
Replies: 9
Views: 1532

Re: Defeated by VLAN issue [SOLVED]

There are several options. a. connect PC requiring vlan 10 directly to the audience OR ax3 b. replace the un-managed switch with a managed switch (could even be a hex) and then send the two vlans to the new device 10,20 c. buy a second cheap unmanaged switch untagged to vlan 10 and then plug in the ...
by anav
Thu Apr 24, 2025 5:35 pm
Forum: General
Topic: Defeated by VLAN issue [SOLVED]
Replies: 9
Views: 1532

Re: Defeated by VLAN issue [SOLVED]

Please draw a network diagram because the explanation muddles devices relationship and clarity is required.
In general, the management vlan needs to go to all smart devices ( such as the audience) as smart devices should get their IP address from the managment vlan.
by anav
Thu Apr 24, 2025 5:32 pm
Forum: General
Topic: Can't re-add peer key Wireguard
Replies: 1
Views: 476

Re: Can't re-add peer key Wireguard

The information you have provided is sparse. In general on your mikrotik you generate a private key and public key ("######" ) when creating the wireguard interface and lets say create an address like 10.20.30.1/24 with listening port of 51280. The public key is for use on the peer or remo...
by anav
Thu Apr 24, 2025 5:24 pm
Forum: Beginner Basics
Topic: Primary gateway with static ip address not activating
Replies: 24
Views: 10859

Re: Primary gateway with static ip address not activating

Not sure how pppoe works but for security purposes, would remove any username passwords and any public IP address associated from your config. 1. As to the config I didnt get past your IP addressess which are wrong. You have ONE bridge, and one subnet and pool and address associated so not sure what...
by anav
Thu Apr 24, 2025 2:24 pm
Forum: Beginner Basics
Topic: Hex refresh download speed
Replies: 25
Views: 2969

Re: Hex refresh download speed

Liina, this is NOT your thread, it was started by Hiutale, suggest you start your own thread, to narrow down your specific issues and get assistance.
In other words, we are not focussed on your problems in this thread, so getting upset here, is not going to get you anywhere.
by anav
Thu Apr 24, 2025 2:19 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1498

Re: WireGuard Traffic Issue

Im saying a bridge gets one address, if you want different subnets you can cover ports A-F with the same subnet and single bridge and use different addresses for ports G,H,I NOT on the bridge, as that will cover three different subnets. OR use one bridge and assign as many vlans as you need (subnets...
by anav
Thu Apr 24, 2025 2:16 pm
Forum: General
Topic: Block youtube/facebook using Layer 7 working perfect and blocking on pc and phones
Replies: 2
Views: 1012

Re: Block youtube/facebook using Layer 7 working perfect and blocking on pc and phones

Just dont use the internet, there are too many ways around non DPI solutions........
by anav
Thu Apr 24, 2025 2:21 am
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 2888

Re: AX3 as basic AP/switch

Any sailor worth their salt, knows that a vessel is used for drinking!! Drinkware, beverageware (in other words, cups, jugs and ewers) is a general term for a vessel intended to contain beverages or liquid foods for drinking or consumption. The word cup comes from Middle English cuppe, from Old Engl...
by anav
Thu Apr 24, 2025 12:56 am
Forum: Beginner Basics
Topic: Hex refresh download speed
Replies: 25
Views: 2969

Re: Hex refresh download speed

How do you get 940Mb upload??? Thats amazing........ No firewall rules??? hEX refresh can route 1430 Mbps based on the official test results when using large packet size. Interesting using large packet size has never given me accurate results but the smaller 512 byte size does match my real world r...
by anav
Thu Apr 24, 2025 12:52 am
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 2888

Re: AX3 as basic AP/switch

For MKX, just to be clear, a submarine is NOT a ship! ;-)
by anav
Wed Apr 23, 2025 7:08 pm
Forum: Beginner Basics
Topic: Load Balancing and Failover not working with my VPN connection
Replies: 4
Views: 593

Re: Load Balancing and Failover not working with my VPN connection

Also the MT config
/export file=anynameyouwish (minus router serial number, any public WANIP information, keys )
by anav
Wed Apr 23, 2025 7:07 pm
Forum: Beginner Basics
Topic: Stops Responding [SOLVED]
Replies: 10
Views: 2839

Re: Stops Responding [SOLVED]

Also I recommend taking one of the unused ports on the switch and make it an OFF BRIDGE access port, but will wait to see the config.
by anav
Wed Apr 23, 2025 4:39 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1498

Re: WireGuard Traffic Issue

Each vlan is created with interface being bridge. Each vlan gets its own dhcp server, ip pool, dhcp-server network AND!!! own IP address ( not a sniff of bridge on these subnet config lines ). The only other place vlans and bridges are mixed is /interface bridge port and /interface bridge lans.
by anav
Wed Apr 23, 2025 4:36 pm
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 2888

Re: AX3 as basic AP/switch

Same with the PHY? Functionality onboard is a subset of available options?
by anav
Wed Apr 23, 2025 3:14 pm
Forum: Beginner Basics
Topic: Hex refresh download speed
Replies: 25
Views: 2969

Re: Hex refresh download speed

How do you get 940Mb upload??? Thats amazing........ No firewall rules???
by anav
Wed Apr 23, 2025 3:08 pm
Forum: General
Topic: Wireguard issue - L009 [SOLVED]
Replies: 7
Views: 1200

Re: Wireguard issue - L009 [SOLVED]

Repost the config, when done if still having problems.
by anav
Wed Apr 23, 2025 2:26 pm
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 2888

Re: AX3 as basic AP/switch

According to AI..........In diagrams, the CPU is typically represented by a rectangular box, often colored dark grey or black. The switch chip, which facilitates communication between different parts of a network, is often shown as a similar rectangular or square box, but colored light blue, orange,...
by anav
Tue Apr 22, 2025 11:10 pm
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 2888

Re: AX3 as basic AP/switch

Concur, well stated.
Yes, if one has heavy VLAN traffic ( same vlan ) between different ports on the switch, the ax3 whether its a switch or a router will see some slow down in traffic, whereas a proper switch will not.
by anav
Tue Apr 22, 2025 9:58 pm
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 2888

Re: AX3 as basic AP/switch

I use my ax3 with vlan filtering and I see no ill effects on my LAN subnets...............
by anav
Tue Apr 22, 2025 9:56 pm
Forum: General
Topic: Wireguard issue - L009 [SOLVED]
Replies: 7
Views: 1200

Re: Wireguard issue - L009 [SOLVED]

My issue with the config is two bridges. Keep it simple, one bridge. Ditch the wrongly named one about vlan10 as you have multiple vlans on that bridge, not just 10. Move the default vlan subnet 88 to a vlan, call it vlan-default. As was pointed out you have two related discrepancies to deal with. a...
by anav
Tue Apr 22, 2025 7:10 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1498

Re: WireGuard Traffic Issue

The config is far to complex for my level of understanding, however I will say that you give away addresses like candy to kids, and as far as I understand the single bridge should not have multiple IP addresses, nor probably any single etherport............ /ip address add address=192.168.100.254/24...
by anav
Tue Apr 22, 2025 1:55 pm
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 2888

Re: AX3 as basic AP/switch

Why waste a vlan capable device when a flat unmanaged switch will do?
by anav
Mon Apr 21, 2025 7:06 pm
Forum: Beginner Basics
Topic: Port Forwarding via WireGuard Tunnel
Replies: 1
Views: 544

Re: Port Forwarding via WireGuard Tunnel

ON VPS FIX the wireguard peers TO: /interface wireguard peers add allowed-address= 192.168.254.2 , 192.168.100.0/24 interface=WG_VPS \ name=peer_WG_VPS public-key= "----" Remove the funky nat rule. /ip firewall nat add action=dst-nat chain=dstnat comment=\ "RDP-Forwarding to local Ro...
by anav
Mon Apr 21, 2025 12:28 pm
Forum: Beginner Basics
Topic: Port forwarding
Replies: 15
Views: 1688

Re: Port forwarding

So you are using a third party APP to access your feed. Have you thought about the fact that you have to forward a port on your router to everyone in the world............ I have three different types of video cameras in the house and I dont forward a single port and I also use an APP to view them. ...
by anav
Mon Apr 21, 2025 12:22 pm
Forum: General
Topic: Looking for advice Hiding my IP to show up other IP [SOLVED]
Replies: 5
Views: 2713

Re: Looking for advice Hiding my IP to show up other IP [SOLVED]

concur, as stated, your best bet is to have all the others use WAN2 and your family only use wan1.
by anav
Mon Apr 21, 2025 12:56 am
Forum: Beginner Basics
Topic: Why does this not work (very basic setup)
Replies: 11
Views: 1010

Re: Why does this not work (very basic setup)

It would seem your double posting, which is verbotten.
Will follow your thread here............... viewtopic.php?t=216313
by anav
Mon Apr 21, 2025 12:54 am
Forum: Beginner Basics
Topic: Why does this not work (very basic setup)
Replies: 11
Views: 1010

Re: Why does this not work (very basic setup)

Without the config, all i here is opinion of some things that may or may not be relevant, its akin to hearing blah blah blah....
Please post the config for assistance.
/export file=anynameyouwish ( minus router serial number and any public WANIP information (probably none as this is a switch)
by anav
Sun Apr 20, 2025 6:20 pm
Forum: Beginner Basics
Topic: No DNS on wlan
Replies: 1
Views: 532

Re: No DNS on wlan

You have remnants of the default config 1. From: /ip dhcp-server network add address=192.168.119.0/24 comment=defconf dns-server= 192.168.88.1 gateway=192.168.119.1 netmask=24 TO: /ip dhcp-server network add address=192.168.119.0/24 comment=defconf dns-server= 192.168.119.1 gateway=192.168.119.1 net...
by anav
Sun Apr 20, 2025 6:10 pm
Forum: Beginner Basics
Topic: Why does this not work (very basic setup)
Replies: 11
Views: 1010

Re: Why does this not work (very basic setup)

Review the video and when you have something close post here for review/comments
/export file=anynameyouwish ( minus router serial number, any PUBLIC WANIP information )
by anav
Sun Apr 20, 2025 6:08 pm
Forum: Beginner Basics
Topic: Why does this not work (very basic setup)
Replies: 11
Views: 1010

Re: Why does this not work (very basic setup)

The article provided and video only show one bridge. To configure the switch the best thing for you do to is take one port OFF the bridge and do all your configuring from this safe spot. Configuring OffBridge So remove ether24 from /interface bridge port Modify the following entry /ethernet set [ fi...
by anav
Sun Apr 20, 2025 2:45 pm
Forum: Beginner Basics
Topic: Port forwarding
Replies: 15
Views: 1688

Re: Port forwarding

I would revise the following: From: add action=drop chain=forward comment=\ "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \ connection-state=new in-interface-list=WAN add action=passthrough chain=forward comment=CAM dst-address=192.168.88.30 \ dst-port=80 protocol=...
by anav
Sat Apr 19, 2025 7:57 pm
Forum: Beginner Basics
Topic: Hairpin NAT with dynamic WAN IP [SOLVED]
Replies: 12
Views: 3095

Re: Hairpin NAT with dynamic WAN IP [SOLVED]

Not that I am aware of sorry.

But perhaps this explains the situation best:
..................
usetherighttool.jpg
by anav
Sat Apr 19, 2025 5:32 pm
Forum: General
Topic: Failover RouterOS v7
Replies: 9
Views: 990

Re: Failover RouterOS v7

Fixed, thanks!
by anav
Fri Apr 18, 2025 8:06 pm
Forum: Beginner Basics
Topic: Question VLAN Setup [SOLVED]
Replies: 12
Views: 3052

Re: Question VLAN Setup [SOLVED]

No I said, a. if you only have one vlan per port then you dont really need vlans. b. also since this is a lab environment then you dont need any security. c. if you are trying to practice for real world setups then it would be nutso to have to manage 10 or more devices (config them) using all the di...
by anav
Fri Apr 18, 2025 6:02 pm
Forum: Beginner Basics
Topic: Question VLAN Setup [SOLVED]
Replies: 12
Views: 3052

Re: Question VLAN Setup [SOLVED]

Why do you want vlans? There is no need, there is never a duplication of any subnet over a single port? In reality, every device would be on a managed vlan, so every device would have at least two vlans coming in a trunk port. Suggest you look at basic videos and read this article. https://forum.mik...
by anav
Fri Apr 18, 2025 5:00 pm
Forum: Forwarding Protocols
Topic: Dual wan connexion from winbox
Replies: 3
Views: 4185

Re: Dual wan connexion from winbox

The problem is that your requirement is not clearly stated. Do you mean, I wish to access my Router while at a remote location? OR Do you mean I wish to access my router while on the LAN of ISP1 modem/router or on the LAN of the ISP2 modem/router. (hint they are not strictly modems if they get a sta...
by anav
Fri Apr 18, 2025 3:19 pm
Forum: Beginner Basics
Topic: Bridging WAN to VLAN [SOLVED]
Replies: 9
Views: 3198

Re: Bridging WAN to VLAN [SOLVED]

I dont understand the first post.
Why cannot you simply make the devices available via port forwarding.
How can you expose devices to the internet if you only have one WANIP address, dont you need a block of public IP addresses??
by anav
Fri Apr 18, 2025 3:04 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1498

Re: WireGuard Traffic Issue

It should work so there may be something else in your config interfering.
/export file=anynameyouwish ( minus router serial number, any public WANIP information, keys )
by anav
Fri Apr 18, 2025 2:15 pm
Forum: Beginner Basics
Topic: Help with hAP ax lite access point [SOLVED]
Replies: 8
Views: 2565

Re: Help with hAP ax lite access point [SOLVED]

It has two chains, and thus thought the default would include wifi1 andw ifi2 so at least the op could provide coverage for two freqs.....oh well. Nope. Only 2.4Ghz radio so only wifi1. 2 chains does not mean 2 radios. Reminds me to ask you, why do they even state the number of chains, its like use...
by anav
Fri Apr 18, 2025 2:11 pm
Forum: Beginner Basics
Topic: Hairpin NAT with dynamic WAN IP [SOLVED]
Replies: 12
Views: 3095

Re: Hairpin NAT with dynamic WAN IP [SOLVED]

Mikrotik provides its own domain URL in IP CLOUD use that.........
https://help.mikrotik.com/docs/spaces/R ... Cloud-DDNS
by anav
Fri Apr 18, 2025 2:05 pm
Forum: General
Topic: Reset RouterOS without losing remote access (Winbox/SSH)
Replies: 21
Views: 1761

Re: Reset RouterOS without losing remote access (Winbox/SSH)

How can you eat an apple but keep it intact ?

You can not.
I disagree, a whale can swallow it whole....... and then regurgitate it back whole.
by anav
Thu Apr 17, 2025 11:20 pm
Forum: General
Topic: Failover RouterOS v7
Replies: 9
Views: 990

Re: Failover RouterOS v7

VERSION7 instituted some changes mostly to the way of using scope and target scope.......... Nested using a faux address for two canary selections. /ip route add dst-address=0.0.0.0/0 gateway=10.10.10.10 scope=10 target-scope=14 add distance=2 check-gateway=ping dst-address=10.10.10.10/32 gateway=9....
by anav
Thu Apr 17, 2025 10:32 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1498

Re: WireGuard Traffic Issue

If WAN1 is your primary WAN ( and WAN2 is rarely used ), then it stands to reason that all your wireguard users have WAN1 as their endpoint address. To test if the router will switch to WAN2 automatically, due to distance in route difference, please do not SWAP distances. To test simply unplug inter...
by anav
Thu Apr 17, 2025 5:20 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1498

Re: WireGuard Traffic Issue

Your testing method may be flawed.
If you swap distances on the WANs, do you also change the endoint address to WAN2 for the device??
You need to NOT change the WAN distance, simply unplug the cable from wan1 into the router.
by anav
Thu Apr 17, 2025 1:35 pm
Forum: General
Topic: How to use Mikrotik router as a “switch”?
Replies: 13
Views: 48382

Re: How to use Mikrotik router as a “switch”?

What kind of switch, like an unmanaged switch with one flat network OR switch with multiple vlans?
by anav
Thu Apr 17, 2025 1:32 pm
Forum: General
Topic: Firewall to block Facebook but allow WhatsApp?
Replies: 8
Views: 1151

Re: Firewall to block Facebook but allow WhatsApp?

Without a router with (DPI) and like services that looks at encrypted packets there is no foolproof way...........
by anav
Thu Apr 17, 2025 1:28 pm
Forum: General
Topic: WireGuard Traffic Issue
Replies: 17
Views: 1498

Re: WireGuard Traffic Issue

In a dual wan scenario where WAN2 is secondary lets say by distance and your current setup is for users to connect to WAN1 address, when WAN1 fails ( is no longer available ), the router will move wireguard traffic to WAN2 after a short delay. I havent tested that lately but it used to be the case. ...
by anav
Wed Apr 16, 2025 11:22 pm
Forum: General
Topic: Firewall to block Facebook but allow WhatsApp?
Replies: 8
Views: 1151

Re: Firewall to block Facebook but allow WhatsApp?

How do the users get their access,,,,,,,,, if by WIFI, then turn off access point or WLANs at a certain time.
by anav
Wed Apr 16, 2025 10:42 pm
Forum: General
Topic: 2kbps DNS-Resolution Spam for cloud.mikrotik.com from detect-interface feature
Replies: 9
Views: 1048

Re: 2kbps DNS-Resolution Spam for cloud.mikrotik.com from detect-interface feature

I would add mkx, an admin using MT equipment would probably be trained to some degree to use the equipment in an enterprise networking position. I wonder if any of the certs cover detect internet. OR,
to have at least read viewtopic.php?t=215004 ;-) Item 5
by anav
Wed Apr 16, 2025 10:41 pm
Forum: General
Topic: Why does ROS allow the creation of a route table with the same name?
Replies: 8
Views: 836

Re: Why does ROS allow the creation of a route table with the same name?

Perhaps they never coded to detect and warn about duplicates.....??
by anav
Wed Apr 16, 2025 8:26 pm
Forum: General
Topic: How many VLANs?
Replies: 18
Views: 1272

Re: How many VLANs?

I have heard ubiquiti is so designed but never have read TPLink Aps were particularly useful in dense environments.......
  • 1
  • 2
  • 3
  • 4
  • 5
  • 80