Community discussions

MikroTik App

Search found 1048 matches

by xvo
Wed Oct 21, 2020 10:11 pm
Forum: Beginner Basics
Topic: Route via a Specific Interface Only
Replies: 10
Views: 305

Re: Route via a Specific Interface Only

It seems, that you are right.
by xvo
Wed Oct 21, 2020 2:55 pm
Forum: RouterOS v7 BETA
Topic: Feature Request : Non routable Management VLAN
Replies: 6
Views: 304

Re: Feature Request : Non routable Management VLAN

You might be right.

Ok. Another suggestion: putting vlan-mgmt into separate vrf will definitely make it unroutable, unless needed.
by xvo
Wed Oct 21, 2020 2:47 pm
Forum: General
Topic: Mikrotik CCR as Console server for cisco ?
Replies: 6
Views: 201

Re: Mikrotik CCR as Console server for cisco ?

when i set slient-boot do i need rebootthe router?
I’m not sure: this setting is needed to prevent mikrotik from writing into console port on startup.
But I don’t know if it will be applied on first reboot or after it.
by xvo
Wed Oct 21, 2020 1:03 pm
Forum: General
Topic: Mikrotik CCR as Console server for cisco ?
Replies: 6
Views: 201

Re: Mikrotik CCR as Console server for cisco ?

Never used it between mikrotik and cisco, only between two mikrotiks, so can't say about the needed baud rate.
But don't forget to disable serial console on mikrotik's serial port.
And also set silent-boot=yes in /system routerboard settings.
by xvo
Wed Oct 21, 2020 12:55 pm
Forum: Beginner Basics
Topic: Pi-Hole and Mikrotik - DNS - Pi-hole only show my router’s IP address
Replies: 12
Views: 440

Re: Pi-Hole and Mikrotik - DNS - Pi-hole only show my router’s IP address

Where do you run your pi-hole?
Bare device, VM, docker container?
It looks like some misconfiguration in VM/docker networking.

Anyway, it most likely has nothing to do with mikrotik.
by xvo
Wed Oct 21, 2020 10:45 am
Forum: RouterOS v7 BETA
Topic: Feature Request : Non routable Management VLAN
Replies: 6
Views: 304

Re: Feature Request : Non routable Management VLAN

I believe there is even simpler way: /ip route rule add interface=vlan-mgmt action=drop With this approach, you are explicitly ending your set of rules using "drop everything else". That means you have to whitelist (allow/accept) every single separate type of traffic you want to allow. With this log...
by xvo
Wed Oct 21, 2020 7:39 am
Forum: RouterOS v7 BETA
Topic: Feature Request : Non routable Management VLAN
Replies: 6
Views: 304

Re: Feature Request : Non routable Management VLAN

And your question is?!
What exactly prevents you to configure what you describe?
by xvo
Wed Oct 21, 2020 12:02 am
Forum: Beginner Basics
Topic: Mikrotik DNS resolver [SOLVED]
Replies: 2
Views: 126

Re: Mikrotik DNS resolver [SOLVED]

IP -> DNS -> Static

Of course that will work only if mikrotik is used as DNS server for you network.
by xvo
Wed Oct 21, 2020 12:01 am
Forum: Beginner Basics
Topic: Route via a Specific Interface Only
Replies: 10
Views: 305

Re: Route via a Specific Interface Only

The second is the right one.
That's interesting to know if %interface can actually be used to "bind" ping check to this interface only.
by xvo
Tue Oct 20, 2020 11:44 pm
Forum: Forwarding Protocols
Topic: 1-way OSPF between RB2011 and RB4011
Replies: 3
Views: 208

Re: 1-way OSPF between RB2011 and RB4011

Is ospf permitted by firewall on both sides?
by xvo
Mon Oct 19, 2020 8:02 pm
Forum: Beginner Basics
Topic: Pi-Hole and Mikrotik - DNS - Pi-hole only show my router’s IP address
Replies: 12
Views: 440

Re: Pi-Hole and Mikrotik - DNS - Pi-hole only show my router’s IP address

As already stated - It's not a bug, but a misinterpretation of router's config options.
by xvo
Mon Oct 19, 2020 7:14 pm
Forum: Beginner Basics
Topic: Pi-Hole and Mikrotik - DNS - Pi-hole only show my router’s IP address
Replies: 12
Views: 440

Re: Pi-Hole and Mikrotik - DNS - Pi-hole only show my router’s IP address

I guess you entered pi-hole as DNS server in IP -> DNS?
You should additionally specify pi-hole as DNS server in IP -> DHCP -> Networks
by xvo
Sun Oct 18, 2020 7:54 pm
Forum: Beginner Basics
Topic: Building LAN from scratch: 4 mikrotiks - 4 networks
Replies: 15
Views: 427

Re: Building LAN from scratch: 4 mikrotiks - 4 networks

And it works like a charm. Yes it does! And another great thing about that - the addresses doesn't have to be adjacent, so I have all my PTP links like 172.27.XXX.YYY - 172.27.YYY.XXX (where XXX is some unique identifier for this particular router). That is perfect for 1) ease of reading 2) the abi...
by xvo
Sun Oct 18, 2020 7:17 pm
Forum: Beginner Basics
Topic: Route via a Specific Interface Only
Replies: 10
Views: 305

Re: Route via a Specific Interface Only

That should work.
by xvo
Sun Oct 18, 2020 6:36 pm
Forum: Beginner Basics
Topic: Building LAN from scratch: 4 mikrotiks - 4 networks
Replies: 15
Views: 427

Re: Building LAN from scratch: 4 mikrotiks - 4 networks

I'm not sure if Mikrotik supports /31 but I thought I'd mention it.
It doesn't. You need to use pair of /32 addresses with network specified as the "opposite" one.
by xvo
Sun Oct 18, 2020 6:29 pm
Forum: Beginner Basics
Topic: Route via a Specific Interface Only
Replies: 10
Views: 305

Re: Route via a Specific Interface Only

Hi, This is for Internet fail over. What's the best way in RouterOS to configure a route via a specific interface, so that if that interface is down it won't route via the default route (or any other less specific route)? I think I can do it by adding a route to Null for the same /32 but with worse...
by xvo
Sun Oct 18, 2020 4:20 pm
Forum: Beginner Basics
Topic: Building LAN from scratch: 4 mikrotiks - 4 networks
Replies: 15
Views: 427

Re: Building LAN from scratch: 4 mikrotiks - 4 networks

Yes, that's exactly my point.
by xvo
Sun Oct 18, 2020 3:41 pm
Forum: Beginner Basics
Topic: Building LAN from scratch: 4 mikrotiks - 4 networks
Replies: 15
Views: 427

Re: Building LAN from scratch: 4 mikrotiks - 4 networks

Performance-wise you're right. Configuration-wise, VLANs and centralized routing config is much simpler than distributed routing. Plus it would make a good basis for expansion (much easier to add another subnet or increase number of ports within subnet or replacement of RB760iGS with a proper manag...
by xvo
Sun Oct 18, 2020 12:21 pm
Forum: RouterBOARD hardware
Topic: RBM33G Voltage Monitoring
Replies: 8
Views: 3400

Re: RBM33G Voltage Monitoring

that there are no additional GPIO pins
Have you seen this in the latest 6.48beta48?
*) m33g - added support for "/system gpio" menu (CLI only);
viewtopic.php?f=21&t=163308#p822721
by xvo
Fri Oct 16, 2020 11:35 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 270
Views: 69361

Re: v7.1beta2 [development] is released!

including wiping the file storage...where I had stored a couple backup configs
Are you sure they were in /flash folder, not in the root directory that is mounted to RAM?
by xvo
Fri Oct 16, 2020 11:32 pm
Forum: Beginner Basics
Topic: Building LAN from scratch: 4 mikrotiks - 4 networks
Replies: 15
Views: 427

Re: Building LAN from scratch: 4 mikrotiks - 4 networks

There are different approaches - you could route between subnets on mikrotik2-4 and have static routing rules on mikrotik1 so traffic is directed to the correct mikrotik, or you could use mikrotik2-4 as switches with VLANs and perform all of the routing/firewalling on mikrotik1 RB760iGS won't be go...
by xvo
Fri Oct 16, 2020 9:54 pm
Forum: General
Topic: Which rule is a connection matching
Replies: 3
Views: 246

Re: Which rule is a connection matching

Firewall doesn't allow connections, it allows packets.
And different packets from that connection can be allowed by different rules.
by xvo
Thu Oct 15, 2020 12:44 pm
Forum: SwOS
Topic: Number of SWOS VLANs
Replies: 7
Views: 389

Re: Number of SWOS VLANs

This is an all wireless network with the AP's UN-tagging VLAN traffic. In this scenario, is there any advantage to tagging all the switch ports? Thanks again.
If all ports need to have the same set of tagged vlans, then there is no point really.
by xvo
Thu Oct 15, 2020 1:32 am
Forum: Beginner Basics
Topic: WOL before RDP
Replies: 2
Views: 153

Re: WOL before RDP

I've come to conclusion that the easiest way to wol a pc in remote network is running a small bash script that will connect to mikrotik by ssh and run a wol command. A special user can be used for that: only ssh and test permissions are needed. But anyway, ssh port open to outside network is not a g...
by xvo
Tue Oct 13, 2020 6:26 pm
Forum: SwOS
Topic: Number of SWOS VLANs
Replies: 7
Views: 389

Re: Number of SWOS VLANs

manual.jpg
That is from the very beginning of that page.
https://wiki.mikrotik.com/wiki/SwOS/CRS ... s_features

Unfortunately, it looks like RoS is the only option here.
by xvo
Tue Oct 13, 2020 11:36 am
Forum: SwOS
Topic: Number of SWOS VLANs
Replies: 7
Views: 389

Re: Number of SWOS VLANs

Yes, there is 250 VLAN limit in SwOS:
https://wiki.mikrotik.com/wiki/SwOS/CRS3xx
by xvo
Sun Oct 11, 2020 2:51 pm
Forum: Beginner Basics
Topic: IPV6 Firewall [SOLVED]
Replies: 55
Views: 1676

Re: IPV6 Firewall [SOLVED]

In winbox you have to choose needed action first (in this case action=reject) and then options for this action will appear.
by xvo
Sat Oct 10, 2020 11:45 am
Forum: The Dude
Topic: Strange graphs plot [SOLVED]
Replies: 2
Views: 176

Re: Strange graphs plot [SOLVED]

That is the expected behaviour - latest period of time is stored in max resolution, the next one - in lower (10 min), and so on (2 hours, 1 day).
You can change the exact time for each period in settings:
dude charts.jpg
by xvo
Sat Oct 10, 2020 12:24 am
Forum: Forwarding Protocols
Topic: Routing Advices
Replies: 4
Views: 325

Re: Routing Advices

First you have to decide: do you really need to "bridge" or to "route" will be enough? In first case you will have one subnet, only one of the routers will act as a DHCP server for both networks and so on. While in the second case you will have two completely independent networks, but yet they will ...
by xvo
Sat Oct 10, 2020 12:07 am
Forum: General
Topic: ECMP balancing sometimes breaks TCP connection
Replies: 9
Views: 398

Re: ECMP balancing sometimes breaks TCP connection

A load balancer would slightly complicate things, nothing terrible, but a couple rules like sindy suggested would be a much simpler solution in this case. These rules are what load balancer is mostly. And now meaning the "destination". The only thing that is lacking - taking the up/down status of t...
by xvo
Fri Oct 09, 2020 11:45 pm
Forum: Beginner Basics
Topic: NAT + Tag/Untag multiple identical devices
Replies: 15
Views: 678

Re: NAT + Tag/Untag multiple identical devices

Now ping and ssh connection are working from management RPi to DEVs! Thanks xvo! Niiice! However that makes me wonder if the guy who wrote the article ever tried it himself in the exact way he wrote. I once built a test setup somehow using this article as a guidance, but the setup itself had some m...
by xvo
Fri Oct 09, 2020 10:45 am
Forum: Beginner Basics
Topic: Unable to Access
Replies: 5
Views: 175

Re: Unable to Access

Then check IP -> Services, System -> Users and IP -> Firewall -> Filter (input chain) sections to see if access is not restricted to some ip's (whether for this user only, or to device in general).
by xvo
Thu Oct 08, 2020 10:35 pm
Forum: RouterBOARD hardware
Topic: PoE help
Replies: 1
Views: 115

Re: PoE help

Yes, all ports are gigabit no matter if you use PoE or not. And yes, hap ac definitely can benefit from gigabit connection. Especially if you use 5Ghz wifi. On the other hand I am not completely sure what you want to do. If you want to daisy chain devices like: hEX S PoE-out --> 1st hAP ac PoE-in an...
by xvo
Thu Oct 08, 2020 10:20 pm
Forum: Beginner Basics
Topic: Unable to Access
Replies: 5
Views: 175

Re: Unable to Access

Are both of PCs have the same winbox version?
by xvo
Thu Oct 08, 2020 10:18 pm
Forum: Beginner Basics
Topic: Help validating PoE will work in my setup?
Replies: 5
Views: 211

Re: Help validating PoE will work in my setup?

I also found MikroTik RBGPOE power injectors, with these I think I should be able to use the power supply that comes with the ac²s to supply PoE. This way, all of my APs should be able to pull up to 0.8A*24V=19.2W in ideal conditions. Besides the extra wiring and cabling in the basement, that shoul...
by xvo
Thu Oct 08, 2020 10:10 pm
Forum: General
Topic: ECMP balancing sometimes breaks TCP connection
Replies: 9
Views: 398

Re: ECMP balancing sometimes breaks TCP connection

You are misusing ECMP - it is meant to load balance routes, not the "destinations".
by xvo
Thu Oct 08, 2020 10:08 pm
Forum: Beginner Basics
Topic: NAT + Tag/Untag multiple identical devices
Replies: 15
Views: 678

Re: NAT + Tag/Untag multiple identical devices

I have one idea. For returning packets you do this: /ip firewall mangle add action=mark-routing chain=prerouting dst-address=192.168.2.2 new-routing-mark=main Is this rule being hit at all? The idea is, dst-nat is performed after the prerouting chain, so probably the action reversing the src-nat too...
by xvo
Thu Oct 08, 2020 4:48 pm
Forum: General
Topic: Firewall for ROS device used as internal switch? [SOLVED]
Replies: 2
Views: 177

Re: Firewall for ROS device used as internal switch? [SOLVED]

No, if the device is configured as a switch it doesn't forward any IP packets.
You can even disable IP forwarding in IP -> Settings.
by xvo
Thu Oct 08, 2020 10:01 am
Forum: Beginner Basics
Topic: Help validating PoE will work in my setup?
Replies: 5
Views: 211

Re: Help validating PoE will work in my setup?

I agree that it would be nice to have a bit of a buffer, but I can't seem to find that 28V 3.4A supply while browsing MikroTik products. I think it may be a one-off accessory for that specific switch. Do you happen to know if it is sold anywhere? I'm not finding similar products offered elsewhere e...
by xvo
Thu Oct 08, 2020 12:12 am
Forum: Beginner Basics
Topic: Help validating PoE will work in my setup?
Replies: 5
Views: 211

Re: Help validating PoE will work in my setup?

No attachments in case of hAP ac2 means no usb devices. The device itself consumes 16W which is 0.666A at 24V (not 0,5A). So 3 of them will give exactly 48W which is 2A at 24V. So theoretically this is as much as hEX PoE can provide. But that doesn't account for losses on the cables on one hand, and...
by xvo
Thu Oct 08, 2020 12:00 am
Forum: Beginner Basics
Topic: Help setting up new router - RB4011
Replies: 2
Views: 167

Re: Help setting up new router - RB4011

If you changed the IP for your LAN bridge you should change dhcp pool and dhcp-server network as well.
by xvo
Wed Oct 07, 2020 11:58 pm
Forum: Beginner Basics
Topic: Hex and VLAN trunk port Ether5
Replies: 1
Views: 101

Re: Hex and VLAN trunk port Ether5

Why your vlan-interfaces are created on top of the bridge if you want ether5 to be a trunk port?
Move them to ether5. Also add all of them to interface-list=LAN.

And also move the address from ether2 to the bridge.
Despite the fact that it is in the default config it is wrong.
by xvo
Wed Oct 07, 2020 5:15 pm
Forum: Beginner Basics
Topic: Hitting a brick wall with VLANs on RB4011 [SOLVED]
Replies: 4
Views: 202

Re: Hitting a brick wall with VLANs on RB4011 [SOLVED]

So, I did try that - I set a port on the bridge to untagged VLAN4 and then enabled vlan-filtering on the bridge. Plugging in a client to that port and I do not get an IP from the DHCP server on that VLAN. I may be missing something else here. Would I need to also add the VLAN interfaces to the brid...
by xvo
Wed Oct 07, 2020 5:08 pm
Forum: General
Topic: Help with POE at Powerbox Pro
Replies: 1
Views: 134

Re: Help with POE at Powerbox Pro

Mikrotik uses Mode B (4,5 - 7,8) to supply power.
Most likely cameras support only Mode A (1,2 - 3,6) which is against the standard.
by xvo
Wed Oct 07, 2020 4:57 pm
Forum: Beginner Basics
Topic: Hitting a brick wall with VLANs on RB4011 [SOLVED]
Replies: 4
Views: 202

Re: Hitting a brick wall with VLANs on RB4011 [SOLVED]

RB4011 doesn't support vlans on hardware.
So you should configure bridge vlan filtering (and lose hw-offloading).
by xvo
Wed Oct 07, 2020 11:48 am
Forum: General
Topic: Disable Firewall and NAT (Allow Traffic in both Directions
Replies: 3
Views: 199

Re: Disable Firewall and NAT (Allow Traffic in both Directions

Thanks for your reply, there are some default rule under the filter rules tab NAT tab or Mangle Which I am not able to delete.
If you are talking about "special dummy rules", the will be deleted on first reboot once you delete the fasttrack rule in filter forard chain.
by xvo
Tue Oct 06, 2020 10:49 pm
Forum: Beginner Basics
Topic: RB4011 VLAN + unifi [SOLVED]
Replies: 14
Views: 504

Re: RB4011 VLAN + unifi [SOLVED]

How an untagged flow of traffic into a switch can then be turned into tagged traffic coming out other ports of the switch It will be tagged by a switch, I guess :))) Isn't that what is switch for after all: tagging, untagging and tagging again, just to fulfil the darkest of admin's designs?! You co...
by xvo
Tue Oct 06, 2020 7:42 pm
Forum: SwOS
Topic: Mikrotik SwOS for CRS112-8P-4S-IN
Replies: 8
Views: 251

Re: Mikrotik SwOS for CRS112-8P-4S-IN

Thanks for keep supporting. I know RoS has more configuration features than SwOS, but some features i didn't get in RoS what i see with SwOS such as port isolation, port forwarding, port locking, port mirroring, bandwidth limit etc. Thanks. All is there, in switch menu, with far more possibilities ...
by xvo
Tue Oct 06, 2020 7:13 pm
Forum: SwOS
Topic: Mikrotik SwOS for CRS112-8P-4S-IN
Replies: 8
Views: 251

Re: Mikrotik SwOS for CRS112-8P-4S-IN

Okay! i disappointed to know this as i thought all Mikrotik smart switches come with SwOS opeating system. Totally waste my money on this. Thanks. There are 3 families of Mikrotik switches: - CSS: that run SwOS - CRS1XX/2XX: that run RoS - CRS3XX: that allow dual-boot (you can choose what os to run...
by xvo
Tue Oct 06, 2020 6:55 pm
Forum: SwOS
Topic: Mikrotik SwOS for CRS112-8P-4S-IN
Replies: 8
Views: 251

Re: Mikrotik SwOS for CRS112-8P-4S-IN

No, you can't.
by xvo
Tue Oct 06, 2020 6:39 pm
Forum: SwOS
Topic: Mikrotik SwOS for CRS112-8P-4S-IN
Replies: 8
Views: 251

Re: Mikrotik SwOS for CRS112-8P-4S-IN

CRS1XX/2XX are RoS devices, not SwOS.
by xvo
Tue Oct 06, 2020 1:04 pm
Forum: Beginner Basics
Topic: New Router Choice RB4011iGS+5HacQ2HnD-IN or what?
Replies: 1
Views: 130

Re: New Router Choice RB4011iGS+5HacQ2HnD-IN or what?

Adding an 8-port switch makes far more sense in your situation.
by xvo
Tue Oct 06, 2020 11:07 am
Forum: Beginner Basics
Topic: interVlan Routering with only routerBoard
Replies: 2
Views: 122

Re: interVlan Routering with only routerBoard

You don't need switch functionality if you want separate LAN on each of the ports.
by xvo
Tue Oct 06, 2020 11:04 am
Forum: General
Topic: Disable Firewall and NAT (Allow Traffic in both Directions
Replies: 3
Views: 199

Re: Disable Firewall and NAT (Allow Traffic in both Directions

Remove all firewall and NAT rules.

Or reset the device with no default configuration and configure only things you need.
Only be aware that after resetting with no config the router won't have any IP addresses, so it will be possible to connect to it only by mac-address using winbox.
by xvo
Tue Oct 06, 2020 12:02 am
Forum: RouterBOARD hardware
Topic: What's a good router that supports both 2.4 GHz and 5 GHz at the same time?
Replies: 4
Views: 291

Re: What's a good router that supports both 2.4 GHz and 5 GHz at the same time?

It sounds like what I'm looking for is the Dual-concurrent label. Well, there are some examples (most likely the more newer ones) that don't have this said explicitly, and yet they are still dual-concurrent. To be sure, you can check the block diagram of the device, and for dual-concurrent you will...
by xvo
Mon Oct 05, 2020 11:42 pm
Forum: RouterBOARD hardware
Topic: What's a good router that supports both 2.4 GHz and 5 GHz at the same time?
Replies: 4
Views: 291

Re: What's a good router that supports both 2.4 GHz and 5 GHz at the same time?

All current dual-band Mikrotik routers from this section are dual-concurrent, meaning that they can work in 2.4Ghz and 5Ghz simultaneously: https://mikrotik.com/products/group/wireless-for-home-and-office And as an example of AP that can work either in 2.4Ghz or 5Ghz, but not at the same time: https...
by xvo
Mon Oct 05, 2020 10:57 pm
Forum: Scripting
Topic: notification on incoming and established vpn connection
Replies: 2
Views: 169

Re: notification on incoming and established vpn connection

PPP-profile-Scripts.jpg
by xvo
Mon Oct 05, 2020 7:11 pm
Forum: RouterBOARD hardware
Topic: 951G-2HnD too slow for 1Gbps connection?
Replies: 35
Views: 5621

Re: 951G-2HnD too slow for 1Gbps connection?

Is Mikrotik RouterBoard RBD52G-5HacD2HnD-TC hAP ac2 up? This one will do? I meant up the product line. Starting from hAP ac2 and then to more powerful/expensive models. hAP ac2 will be ok for 1Gbit as long as traffic can be fasttracked (for example with the default config). If you need load balanci...
by xvo
Sun Oct 04, 2020 12:43 pm
Forum: Forwarding Protocols
Topic: OSPF / PTMP no subnets
Replies: 5
Views: 256

Re: OSPF / PTMP no subnets

Could you please explain the sense behind this? I see no practical reason to distribute /32 routes. Each router can reach each router - but the hosts in the networks connected to the router cannot reach other hosts in network connected to other routers? It is suited fine for point-to-point links (t...
by xvo
Sun Oct 04, 2020 2:45 am
Forum: Forwarding Protocols
Topic: OSPF / PTMP no subnets
Replies: 5
Views: 256

Re: OSPF / PTMP no subnets

MT-Wikis says: Discovery on PTMP Subnets Point-to-MultiPoint treats the network as a collection of point-to-point links. Is this behaviour Mikrotik specific or is this "per design" of the PTMP network-type? It works exactly as stated in your quote - you end up with bunch of /32 addresses. For anyth...
by xvo
Sun Oct 04, 2020 2:26 am
Forum: RouterBOARD hardware
Topic: GPeR
Replies: 2
Views: 162

Re: GPeR

Yes, you can remove jumpers on PoE-out side and then it won't pass PoE further.
But there is a note, that it won't work if 802.3af/at is used - the power source device won't power the GPeR alone.
https://i.mt.lv/cdn/product_files/GPeRqg_190928.pdf
by xvo
Sun Oct 04, 2020 2:03 am
Forum: RouterBOARD hardware
Topic: hAP ac2 vs. cAP ac, CAP only usage
Replies: 10
Views: 592

Re: hAP ac2 vs. cAP ac, CAP only usage

But running the default configuration makes it impossible to connect to the router because of the firewall. What do you mean? From WAN interface? Yes, so? I don't really understand what your point is. Firewall won't prevent powering the device up :))) PoE input and "internet" schould not be on the ...
by xvo
Fri Oct 02, 2020 11:18 pm
Forum: Beginner Basics
Topic: NAT + Tag/Untag multiple identical devices
Replies: 15
Views: 678

Re: NAT + Tag/Untag multiple identical devices

xvo, I tried your example in https://habr.com/ru/post/262091/, but it doesn't work as such. I used Raspberry PIs in ether3, ether4 and ether5 with identical addresses as yours. No connection available from 192.168.2.2 to 192.168.2.13 or 192.168.2.14. Is there something missing? You should have your...
by xvo
Thu Oct 01, 2020 11:57 pm
Forum: Beginner Basics
Topic: VLAN Client Isolation
Replies: 10
Views: 761

Re: VLAN Client Isolation

I think this is where my knowledge on how to configure CRS1XX/2XX ends. I have only one of the line and it's in production, so I can't use it for testing purposes. I guess that port-profile is somehow messing with the vlan config, or at least with it's part that makes ether1 a trunk port. But I don'...
by xvo
Thu Oct 01, 2020 11:42 pm
Forum: RouterBOARD hardware
Topic: hAP ac2 vs. cAP ac, CAP only usage
Replies: 10
Views: 592

Re: hAP ac2 vs. cAP ac, CAP only usage

Why is the PoE input also the WAN interface by default? Because it is the port, that will definitely be used on a wifi router run with default config. So you don't need to reconfigure the device only to power it up from an injector. For cAP ac it is even more obvious, as it don't have separate powe...
by xvo
Wed Sep 30, 2020 12:52 am
Forum: Beginner Basics
Topic: NAT from a TCP port to a UDP port
Replies: 3
Views: 170

Re: NAT from a TCP port to a UDP port

That can't work even in theory.
by xvo
Wed Sep 30, 2020 12:48 am
Forum: Announcements
Topic: Newsletter 97 (September 2020)
Replies: 85
Views: 12725

Re: Newsletter 97 (September 2020)

May be but on the other hand it seems more cost effective just to buy a larger unit like for example CSS326-24G-2S+RM that is only a bit more expensive but is full 19" rack unit and gives you 24Gbps ports etc ... Sure, but the idea mainly is to combine two 8-port PoE switches, or one PoE and one no...
by xvo
Mon Sep 28, 2020 2:10 pm
Forum: Announcements
Topic: Newsletter 97 (September 2020)
Replies: 85
Views: 12725

Re: Newsletter 97 (September 2020)

It would be really nice if for smaller devices like this CSS610-8G-2S+IN switch MikroTik bundles second ear for 10" racks mount that are increasingly popular ...
And also (as a separate item) a kit that will make possible to mount two units in one 19" space.
by xvo
Mon Sep 28, 2020 1:45 pm
Forum: General
Topic: Is there a router/switch to beat the 4011?
Replies: 21
Views: 1924

Re: Is there a router/switch to beat the 4011?

Right you are... shame on me for not checking for this. No shame here: too many devices to remember all their specs. And no distinctive pattern between names - generations - architecture. As for this particular case: wAP ac2 LTE would be a more proper name, clearly indicating, that this a new gener...
by xvo
Mon Sep 28, 2020 1:12 pm
Forum: General
Topic: Is there a router/switch to beat the 4011?
Replies: 21
Views: 1924

Re: Is there a router/switch to beat the 4011?

Think about some of the devices built around the IPQ-4018/9 SoC, such as hAP ac², wAP ac, or cAP ac.
Only wAP ac LTE is IPQ-4018.
wAP ac is mipsbe, and hence not a competitor to the above ones.
by xvo
Mon Sep 28, 2020 11:24 am
Forum: SwOS
Topic: Help me please, switch keeps briking on me
Replies: 3
Views: 270

Re: Help me please, switch keeps briking on me

To get an access from trunk port you might need to specify the correct vlan id for management access (System tab, Allow from VLAN).
by xvo
Mon Sep 28, 2020 12:27 am
Forum: Beginner Basics
Topic: [problem] high ping latency - MultiWAN
Replies: 11
Views: 552

Re: [problem] high ping latency - MultiWAN

it is ok , i think i do not use https://wiki.mikrotik.com/wiki/Manual:IP/Fasttrack in full config above. Actually I don't see any firewall at all, which is not good, if the router is facing the internet, and there are public IPs on any of your Dlink DSL-modems. Last think please @xvo , for the 2 WA...
by xvo
Mon Sep 28, 2020 12:02 am
Forum: Beginner Basics
Topic: [problem] high ping latency - MultiWAN
Replies: 11
Views: 552

Re: [problem] high ping latency - MultiWAN

also , do you think i need chain=input rules ? because i use only prerouting and output chain's ? No, you don't. Prerouting covers both "input" and "forward" traffic. how can i check https://wiki.mikrotik.com/wiki/Manual:IP/Fasttrack is enabled ? Look at your firewall/filter's forward chain to see ...
by xvo
Sun Sep 27, 2020 11:42 pm
Forum: Beginner Basics
Topic: [problem] high ping latency - MultiWAN
Replies: 11
Views: 552

Re: [problem] high ping latency - MultiWAN

or it is just a problem with per-connection-classifier=both-addresses:2/0 for WAN-09 and per-connection-classifier=both-addresses:2/1 for WAN-12 ? That is definitely a problem, and has to be corrected the way you figured out yourself. Also be sure that you don't have fasttrack enabled. Apart from t...
by xvo
Sun Sep 27, 2020 10:52 pm
Forum: Beginner Basics
Topic: [problem] high ping latency - MultiWAN
Replies: 11
Views: 552

Re: [problem] high ping latency - MultiWAN

also , can i use both-addresses-and-ports rather than both-addresses ?
You can, but it might potentially break applications that rely on multiple parallel connections.
by xvo
Sun Sep 27, 2020 9:10 pm
Forum: Wireless Networking
Topic: Compare United States wireless country settings [SOLVED]
Replies: 11
Views: 4264

Re: Compare United States wireless country settings [SOLVED]

Antenna Gain doesn't show up on my settings
Search field on the forum too? :)
by xvo
Sun Sep 27, 2020 6:28 pm
Forum: General
Topic: Is there a router/switch to beat the 4011?
Replies: 21
Views: 1924

Re: Is there a router/switch to beat the 4011?

There is no such product.
So, just buy a decent 16-24 port switch and continue using 4011 as a router.
by xvo
Sun Sep 27, 2020 3:03 pm
Forum: Announcements
Topic: Newsletter 97 (September 2020)
Replies: 85
Views: 12725

Re: Newsletter 97 (September 2020)

CCR 2004 is not longer listed in newsleter
and caralog ;) https://download2.mikrotik.com/catalog_2020.pdf
any idea why?
It is there, announced in May/2020:
https://mikrotikdownload.s3.eu-west-1.a ... ews_95.pdf
The catalogue most likely was created earlier.
by xvo
Sun Sep 27, 2020 12:14 am
Forum: General
Topic: Share 2mbps equal on two user with different limit-at
Replies: 5
Views: 1640

Re: Share 2mbps equal on two user with different limit-at

Set MAX Limit for leaf queues a little lower than for the parent.
by xvo
Sat Sep 26, 2020 2:46 pm
Forum: Beginner Basics
Topic: HAP AC - SFP port [SOLVED]
Replies: 3
Views: 215

Re: HAP AC - SFP port [SOLVED]

I assume the concern is throughput and CPU impact rather than function.
Yes, exactly.
by xvo
Sat Sep 26, 2020 1:39 pm
Forum: Beginner Basics
Topic: HAP AC - SFP port [SOLVED]
Replies: 3
Views: 215

Re: HAP AC - SFP port [SOLVED]

It's a separate interface.
Keep in mind that it is connected directly to CPU not to a switch chip, so it's good to use it as an uplink from ISP, and not so good as a LAN port.
by xvo
Fri Sep 25, 2020 11:00 am
Forum: Beginner Basics
Topic: VLAN Client Isolation
Replies: 10
Views: 761

Re: VLAN Client Isolation

How would that rule look like? (Blue VLAN is on interface "BLUE_VLAN", vlan-id is 10 and subnet is 10.0.10.0/24. Port ether1 on each switch is connected to the router.) I guess something like this: /interface bridge filter add action=drop chain=forward in-interface=ether2 mac-protocol=vlan out-inte...
by xvo
Fri Sep 25, 2020 10:19 am
Forum: Beginner Basics
Topic: VLAN Client Isolation
Replies: 10
Views: 761

Re: VLAN Client Isolation

In that case it would be possible to isolate clients using split horizon (assuming each has own access port on one of CRSes). It would probably work nicely for clients of each CRS1xx, however isolation of clients connected to different CRS1xx would still be a challenge, which could be solved by usi...
by xvo
Wed Sep 23, 2020 9:36 pm
Forum: Beginner Basics
Topic: VPN Works with PPTP but not with L2TP
Replies: 3
Views: 273

Re: VPN Works with PPTP but not with L2TP

Does your hap lite have a public ip assigned to it, or is it behind some other router with some ports forwarded?
by xvo
Wed Sep 23, 2020 10:03 am
Forum: Wireless Networking
Topic: CAPsMAN manual channel
Replies: 1
Views: 124

Re: CAPsMAN manual channel

And the last steps to do are:
- create different configurations using different channels.
- and then provisioning rules for groups of caps, that will use their own configurations.
by xvo
Wed Sep 23, 2020 9:52 am
Forum: Beginner Basics
Topic: AT&T FTTH, VLANs, CapsMAN Full Config
Replies: 15
Views: 743

Re: AT&T FTTH, VLANs, CapsMAN Full Config

Dont know about proprietary crap but I use firewall rules to allow users on vlans to access a printer on another vlan. Firewall won't help you in case of discovery protocols that rely on broadcasts (and are supposed to work inside one broadcast domain), no matter if they are open or proprietary. On...
by xvo
Wed Sep 23, 2020 1:03 am
Forum: Beginner Basics
Topic: Can't access to my services with my public IP
Replies: 11
Views: 779

Re: Can't access to my services with my public IP

Can't see anything else in your config, that could interfere with it.
Apart from what @anav had already pointed out (address being assigned to the wrong interface).
by xvo
Tue Sep 22, 2020 10:39 pm
Forum: Beginner Basics
Topic: Can't access to my services with my public IP
Replies: 11
Views: 779

Re: Can't access to my services with my public IP

/ip firewall nat add action=dst-nat chain=dstnat dst-address=your_public_IP to-addresses=192.168.1.60

And with it the hairpin rule:

/ip firewall nat add action=src-nat chain=srcnat dst-address=192.168.1.60 src-address=192.168.1.0/24 to-addresses=192.168.1.1
by xvo
Tue Sep 22, 2020 2:39 pm
Forum: Beginner Basics
Topic: Can't access to my services with my public IP
Replies: 11
Views: 779

Re: Can't access to my services with my public IP

Yesterday i saw some posts about "hairpin nat" and tried to implement, but still doesn't work (currently are not implemented as you can see in the FW rules). How exactly did you try to implement hairpin nat? As your public IP is not assigned to your mikrotik but to the ISP router, you should add an...
by xvo
Tue Sep 22, 2020 12:51 pm
Forum: General
Topic: L2tp+bcp+ipsec not working
Replies: 7
Views: 534

Re: L2tp+bcp+ipsec not working

but it fails on phase 2 i have double checked the policy's and they match
You mean proposals, right?
by xvo
Tue Sep 22, 2020 12:30 pm
Forum: Beginner Basics
Topic: Can't access to my services with my public IP
Replies: 11
Views: 779

Re: Can't access to my services with my public IP

Search for "hairpin nat".

And as you are behind an ISP router, you should probably implement it there, not on mikrotik.
by xvo
Mon Sep 21, 2020 11:56 pm
Forum: RouterBOARD hardware
Topic: RB4011 carrying traffic but access is lost
Replies: 4
Views: 275

Re: RB4011 carrying traffic but access is lost

Yes, that sounds different indeed.
Still worth "digging" the forum.
by xvo
Mon Sep 21, 2020 10:33 pm
Forum: RouterBOARD hardware
Topic: RB4011 carrying traffic but access is lost
Replies: 4
Views: 275

Re: RB4011 carrying traffic but access is lost

If I recall correctly, the were some messages describing similar behaviour on 4011: one cpu core maxes out, cutting out access to the device itself.
Try searching the forum for last couple of month.
by xvo
Mon Sep 21, 2020 8:35 pm
Forum: Beginner Basics
Topic: Wan added on bridge [SOLVED]
Replies: 3
Views: 161

Re: Wan added on bridge [SOLVED]

I do not want to achieve anything . this is a basic setup . but what kind of problems does having wan to the same bridge as lan create ? It would be the same as using a switch instead of a router - one device would probably get internet access, all others - won't. Probably no one will get internet ...
by xvo
Mon Sep 21, 2020 8:21 pm
Forum: Beginner Basics
Topic: How to Setup hap ac2 are router w/o wifi
Replies: 3
Views: 179

Re: How to Setup hap ac2 are router w/o wifi

Tryed disabling both wlans, but when I did the config change to CAP
Just disable both wlan interfaces and don't change anything else in Home AP Dual setup.
by xvo
Mon Sep 21, 2020 8:17 pm
Forum: Beginner Basics
Topic: Wan added on bridge [SOLVED]
Replies: 3
Views: 161

Re: Wan added on bridge [SOLVED]

Depending on what exactly you want to achieve by that, but in most usual situation when WAN port goes to your ISP and all other ports are for your LAN devices, that is not what you want to do.
by xvo
Mon Sep 21, 2020 7:01 pm
Forum: Beginner Basics
Topic: h AP Lite VPN
Replies: 4
Views: 147

Re: h AP Lite VPN

but both office and home needs public ip address
Public IP at one side is enough.
by xvo
Mon Sep 21, 2020 5:39 pm
Forum: SwOS
Topic: Powering RB260GS from PoE
Replies: 3
Views: 2355

Re: Powering RB260GS from PoE

Hi.
And what if I will plug ETH1 of RB260 to some PoE Switch with 802.3af / 802.3at? Because of passive PoE I am afraid auto-negotiation will fail to set proper voltage? Or it will work OK?
802.3af / 802.3at is 48V (actually can be between 36-57V), so it is too much for RB260.
by xvo
Mon Sep 21, 2020 3:14 pm
Forum: The Dude
Topic: The Dude installed & enabled but not working
Replies: 13
Views: 419

Re: The Dude installed & enabled but not working

Is there an official place where I could submit a ticket directly to Mikrotik for this? At least so they're aware of the issue, since this is a new, pretty powerful device. The official way to contact support is via email: support@mikrotik.com You can add a link to this thread to your message not t...
by xvo
Mon Sep 21, 2020 2:39 pm
Forum: The Dude
Topic: The Dude installed & enabled but not working
Replies: 13
Views: 419

Re: The Dude installed & enabled but not working

Such a shame, I would really love to test out the features The Dude has to offer... No other ideas cross your mind? Unfortunately - no. If the Dude tab does not appear, that means something is definitely wrong. You can try it on some other device, dedicated for the dude server only: for example on ...
by xvo
Mon Sep 21, 2020 2:27 pm
Forum: The Dude
Topic: The Dude installed & enabled but not working
Replies: 13
Views: 419

Re: The Dude installed & enabled but not working

Could the original installation of the wrong architecture screw things up, even after uninstallation? Could be. If it's a test environment - you can try to netinstall the device and try from scratch. But arm64 being a new architecture in mikrotik line, I'd rather think that it just doesn't work pro...
by xvo
Mon Sep 21, 2020 1:06 pm
Forum: The Dude
Topic: The Dude installed & enabled but not working
Replies: 13
Views: 419

Re: The Dude installed & enabled but not working

Nope, can connect with winbox but can't see the Dude tab on the left side panel.
Where do I need to set up the server settings on the router side?
In this "Dude" tab.

Try disabling/enabling the package (with reboots in between).
And removing/reinstalling, if the first doesn't help.
by xvo
Mon Sep 21, 2020 12:52 pm
Forum: General
Topic: Weird PING behavior on RouterOS
Replies: 10
Views: 576

Re: Weird PING behavior on RouterOS

Having two bridges doesn't disable hardware offload for one of the bridges?
Not if there are two switch chips.
by xvo
Mon Sep 21, 2020 12:33 pm
Forum: The Dude
Topic: The Dude installed & enabled but not working
Replies: 13
Views: 419

Re: The Dude installed & enabled but not working

Do Dude menu appear in webfig/winbox?
Have you enabled server in settings there?
by xvo
Mon Sep 21, 2020 1:20 am
Forum: Beginner Basics
Topic: Dual WAN Setup - how to get both public IPs reachable
Replies: 3
Views: 264

Re: Dual WAN Setup - how to get both public IPs reachable

Add two additional routing tables with default routes for each of WAN connections. And then a couple of routing rules, that restrict usage of the tables depending on src IP: /ip route add distance=1 gateway=gw-ip-for-isp1 routing-mark=isp1 add distance=1 gateway=gw-ip-for-isp2 routing-mark=isp2 /ip ...
by xvo
Mon Sep 21, 2020 1:13 am
Forum: RouterBOARD hardware
Topic: CRS326-24S+2Q+ // MTU 9000 // Bonding // Balance-RR // Hardware-Offloading
Replies: 3
Views: 276

Re: CRS326-24S+2Q+ // MTU 9000 // Bonding // Balance-RR // Hardware-Offloading

So it is not possible to distribute one TCP-Stream across all available Links?
No, it's not.
What are the alternatives, to archive full speed for these protocols?
Use multiple streams and balance-xor mode: it can use l3+l4 hash policy, so takes ports into account too.
by xvo
Sun Sep 20, 2020 1:02 pm
Forum: Beginner Basics
Topic: Blocking internet
Replies: 36
Views: 1049

Re: Blocking internet

What makes you think 30-30-30 should work for mikrotik?!

Here you can read about reset procedure:
https://i.mt.lv/cdn/product_files/hEXSqg_191001.pdf

If nothing works - try netinstall.
by xvo
Sat Sep 19, 2020 11:00 pm
Forum: Wireless Networking
Topic: hAP ac3 recommended buy?
Replies: 49
Views: 2604

Re: hAP ac3 recommended buy?

Nobody has rukus I've never seen anyway
Yeah, sure, things you've never seen, don't exist at all ;)
by xvo
Sat Sep 19, 2020 10:50 pm
Forum: Beginner Basics
Topic: Set bandwidth limit on WAN [SOLVED]
Replies: 11
Views: 552

Re: Set bandwidth limit on WAN [SOLVED]

What if we leave target as blank though?
Should work the same way in this scenario.
by xvo
Thu Sep 17, 2020 1:17 pm
Forum: Beginner Basics
Topic: No NAT for a host
Replies: 1
Views: 287

Re: No NAT for a host

If it's on the wan bridge, isn't it bypassing mikrotik's NAT anyway?!
Or are you talking about traffic from local subnets to Cisco?
by xvo
Thu Sep 17, 2020 1:08 pm
Forum: Beginner Basics
Topic: Using hEX as VPN gateway only - almost working, sorta [SOLVED]
Replies: 7
Views: 306

Re: Using hEX as VPN gateway only - almost working, sorta [SOLVED]

I guess you are missing local-address in your ppp-profile. I suggest you set it to 192.168.252.1 and change to /24 instead of /30 in the route on the modem and in ovpn-server settings. Can leave /30 in the pool though. And for sure no such route should be present: 2 A S 192.168.252.240/30 192.168.1....
by xvo
Thu Sep 17, 2020 12:14 am
Forum: Beginner Basics
Topic: Using hEX as VPN gateway only - almost working, sorta [SOLVED]
Replies: 7
Views: 306

Re: Using hEX as VPN gateway only - almost working, sorta [SOLVED]

Mikrotik has static IP from modem - 192.168.1.252 Ok, so in the modem all you need is a route to 192.168.252.0/24 via 192.168.1.252. That's all. I see, that you already have it. Modem range is 192.168.1.0/24 subnet 255.255.255.0 --DHCP scope 192.168.1.50-150 --should subnet be 255.255.0.0 if I want...
by xvo
Wed Sep 16, 2020 7:50 pm
Forum: General
Topic: Very slow PPTP tunnel
Replies: 6
Views: 477

Re: Very slow PPTP tunnel

PPTP can't be "a good road warrior VPN solution" anyway.

As for the problem - try lowering MTU on the tunnel to smth like 1400.
by xvo
Wed Sep 16, 2020 11:19 am
Forum: Beginner Basics
Topic: Using hEX as VPN gateway only - almost working, sorta [SOLVED]
Replies: 7
Views: 306

Re: Using hEX as VPN gateway only - almost working, sorta [SOLVED]

When I connect to the VPN, my router assigns my laptop the same IP address I have when I'm normally connected locally on wifi. Local IPs work, but not the internet. Well, don't do it. What Ip does your hEX get from your modem? Specify the completely different subnet for vpn clients. And then two op...
by xvo
Tue Sep 15, 2020 5:10 pm
Forum: Beginner Basics
Topic: Routing mark bug?
Replies: 28
Views: 572

Re: Routing mark bug?

Yes, xvo, you describe more accurately, what I mean... But suppose, this is bug... RP-filter or route with route mark can't be existed at one time. No, it is a limitation, but not a bug. All is working logically... so one just need to understand this logic to workaround this limitations. Thank you ...
by xvo
Tue Sep 15, 2020 4:54 pm
Forum: Beginner Basics
Topic: Routing mark bug?
Replies: 28
Views: 572

Re: Routing mark bug?

Packets routes by route mark to vpn interface... Reply come from the other side, checked by RP-Filter, based on rules without route mark, and discarded. Yes, exactly! The way to overcome it: 1) copy routes pointing to local networks to tovpn routing table 2) and mark the returning packets to use it...
by xvo
Tue Sep 15, 2020 4:43 pm
Forum: Beginner Basics
Topic: Routing mark bug?
Replies: 28
Views: 572

Re: Routing mark bug?

Thank you for patience, xvo I rebooted device and claimed, that this is RP-filter, which discard reply packed in strict mode. I don't understand why... Suppose routers must use only loose mode? So it was rp-filter after all?! I think that is what was happening: - the original packet was routed by t...
by xvo
Tue Sep 15, 2020 3:46 pm
Forum: Beginner Basics
Topic: Routing mark bug?
Replies: 28
Views: 572

Re: Routing mark bug?

And yes, rp-filter=strict, but I changed it to "no" without any success...
Probably you should wait for route cache to expire.

Anyway, that was my last guess...
by xvo
Tue Sep 15, 2020 3:23 pm
Forum: Beginner Basics
Topic: Routing mark bug?
Replies: 28
Views: 572

Re: Routing mark bug?

Do adding the ip directly to the list instead of domain name change anything?

And another suggestion - is rp-filter set in ip settings?
by xvo
Tue Sep 15, 2020 2:58 pm
Forum: Beginner Basics
Topic: Routing mark bug?
Replies: 28
Views: 572

Re: Routing mark bug?

Does routing through vpn work if you make it the default route not only for marked traffic, but for all?
by xvo
Tue Sep 15, 2020 2:23 pm
Forum: Beginner Basics
Topic: Routing mark bug?
Replies: 28
Views: 572

Re: Routing mark bug?

add action=mark-routing chain=prerouting connection-state=new dst-address-list=blocked new-routing-mark=tovpn passthrough=yes First of all: you can't use mark-routinng for only the first packet. Second: same thing about fasttrack - you can't use it for traffic, that has to be mangled and routed thr...
by xvo
Tue Sep 15, 2020 12:52 pm
Forum: General
Topic: wrong vlan id on swith crs3xx/crs326-24G-2S+ [SOLVED]
Replies: 1
Views: 190

Re: wrong vlan id on swith crs3xx/crs326-24G-2S+ [SOLVED]

Bridge -> Ports, open ports in question and set the proper PVID=4 for them.
by xvo
Tue Sep 15, 2020 12:31 pm
Forum: Beginner Basics
Topic: Routing mark bug?
Replies: 28
Views: 572

Re: Routing mark bug?

Ok.
I think I know what the problem is: you need to use address as a gateway, not interface.
It works for a /32 address, thinking that it's just another end of ptp-link, but won't work for destinations with wider mask.
by xvo
Tue Sep 15, 2020 12:19 pm
Forum: RouterBOARD hardware
Topic: 951G-2HnD too slow for 1Gbps connection?
Replies: 35
Views: 5621

Re: 951G-2HnD too slow for 1Gbps connection?

That's hEX on the latest 6.46.7 (long-term).

As I have 300/800 + 600/600 as my Internet connection, I even tried to add something parallel to speedtest, to see if I can push it up to the full gigabit, but no luck there.
So I guess that's actually as much as it can do.
hex_wan.jpg
by xvo
Tue Sep 15, 2020 11:32 am
Forum: RouterBOARD hardware
Topic: 951G-2HnD too slow for 1Gbps connection?
Replies: 35
Views: 5621

Re: 951G-2HnD too slow for 1Gbps connection?

If you're extremely lucky.
No luck involved here.
As surprising as it is.
Regular config: NAT, firewall, fasttrack (obviously).
Even tested the case when WAN connection is L2TP couple of days ago - still good results (800/700mbit).
by xvo
Tue Sep 15, 2020 12:39 am
Forum: RouterBOARD hardware
Topic: 951G-2HnD too slow for 1Gbps connection?
Replies: 35
Views: 5621

Re: 951G-2HnD too slow for 1Gbps connection?

And what You say about HEX S? Better? Worse? (I do not need wifi antenna inside)
Not exactly worse. Just different.
Nevertheless - slower: will cap at 800-900 in real-life scenarios.
by xvo
Mon Sep 14, 2020 8:27 pm
Forum: Forwarding Protocols
Topic: Adding routing mark weird behaviour.
Replies: 6
Views: 253

Re: Adding routing mark weird behaviour.

I prefer to put the distance higher for the non marked route as this allow to sort per distance and makes complex routing table more readable
Yeah, I kind of also sometimes use distance to sort the routes, for which the exact order has no difference.
by xvo
Mon Sep 14, 2020 6:58 pm
Forum: Forwarding Protocols
Topic: Adding routing mark weird behaviour.
Replies: 6
Views: 253

Re: Adding routing mark weird behaviour.

Then have one route (the one you actually want) with higher distance and no routing mark on it... Distance is irrelevant in this case. For packets using the named table, route selection falls back to main table (if it is allowed) only after it failed to find a route in the named one. And if named t...
by xvo
Mon Sep 14, 2020 12:54 pm
Forum: RouterBOARD hardware
Topic: 951G-2HnD too slow for 1Gbps connection?
Replies: 35
Views: 5621

Re: 951G-2HnD too slow for 1Gbps connection?

Dears,

I confirm that the 951g-2hnd is not able to carry more than 300-400 Mbps on 1Gbps link. In this case: which Mikrotik router do you recommend to fully use 1Gbps?
hAP ac2/RB450Gx4 and up.
by xvo
Mon Sep 14, 2020 11:10 am
Forum: Announcements
Topic: v6.46.7 [long-term] is released!
Replies: 39
Views: 8576

Re: v6.46.7 [long-term] is released!

Shouldn't we be seeing the changelog from 6.45.9 to 6.46.7 not from 6.46.6 ? Going up a major version in a long-term release should be looked over a bit more carefully before we take the plunge.
Yes, that would be logical.
by xvo
Mon Sep 14, 2020 8:59 am
Forum: RouterBOARD hardware
Topic: hEX RB750Gr3 micro SD not recognized
Replies: 8
Views: 469

Re: hEX RB750Gr3 micro SD not recognized

Pin side UP is the right way.
by xvo
Sun Sep 13, 2020 6:38 pm
Forum: Beginner Basics
Topic: VLAN bridge - tagged and untagged
Replies: 11
Views: 474

Re: VLAN bridge - tagged and untagged

I tried to follow wiki manual, still unifi AP is nto visible on trunk port ether5. Leaving aside the fact, that you've chosen the less desirable configuration approach, and keeping in mind the mistake, that bpwl already mentioned, I can't see anything wrong in your config at first glance. Recheck w...
by xvo
Sun Sep 13, 2020 1:28 pm
Forum: Beginner Basics
Topic: VLAN bridge - tagged and untagged
Replies: 11
Views: 474

Re: VLAN bridge - tagged and untagged

You need to have: 1) Only one bridge 2) ether2 and ether5 added as bridge ports to that bridge 3) Two vlan-interfaces created on that bridge (created on, not added like the bridge ports) - one for each of the vid's. 4) Add IP configuration to vlan-interfaces 5a) Vlan filtering done in switch menu if...
by xvo
Sun Sep 13, 2020 9:54 am
Forum: General
Topic: Slow routing, fixed by reboot - how to troubleshoot?
Replies: 13
Views: 624

Re: Slow routing, fixed by reboot - how to troubleshoot?

I would try another router between ISP and CRS (use CRS like a switch only) to rule out the possibility, that the problem is on ISP side.
by xvo
Sat Sep 12, 2020 10:47 pm
Forum: General
Topic: A place for poetry
Replies: 46
Views: 182839

Re: A place for poetry

[moderated]
Sophisticacted poetry please.
by xvo
Sat Sep 12, 2020 8:13 pm
Forum: Beginner Basics
Topic: Routing mark bug?
Replies: 28
Views: 572

Re: Routing mark bug?

Post your whole /ip firewall section.
And /ip route as well.
by xvo
Sat Sep 12, 2020 7:11 pm
Forum: Beginner Basics
Topic: Routing mark bug?
Replies: 28
Views: 572

Re: Routing mark bug?

I concatenated two rules, dst-address and route-mark in one route, and it's ignore reply again :( I can't uderstand this situation and hope anybody help me to diagnose it... Having different distances means nothing in this case - these two rules are in the different routing tables. The fact that di...
by xvo
Sat Sep 12, 2020 1:44 pm
Forum: General
Topic: Best Way to let L2TP server accessible only from Local IPs
Replies: 2
Views: 141

Re: Best Way to let L2TP server accessible only from Local IPs

Default firewall will block it, just as any other incoming traffic from the outside world.
by xvo
Thu Sep 10, 2020 11:19 pm
Forum: Wireless Networking
Topic: Antenna Gain 6.47.x Winbox error
Replies: 3
Views: 228

Re: Antenna Gain 6.47.x Winbox error

Use forum search.
At least another two similar topics were created for the last week.
by xvo
Thu Sep 10, 2020 8:34 pm
Forum: General
Topic: Slow routing, fixed by reboot - how to troubleshoot?
Replies: 13
Views: 624

Re: Slow routing, fixed by reboot - how to troubleshoot?

Have you checked the physical port status after the slow down?
Could be some problems on the line, that force renegotiating to 10mbit.
by xvo
Thu Sep 10, 2020 5:21 pm
Forum: Beginner Basics
Topic: Bandwidth limit on Mikrotik RB750Gr3 HEX Gigabit Router
Replies: 3
Views: 205

Re: Bandwidth limit on Mikrotik RB750Gr3 HEX Gigabit Router

the question I have is, is the excess shared equally or goes to the first person accessing it??
If you use PCQ, then yes.
If all queues are configured manually, you can use priority to modify this behaviour in favour of some users.
by xvo
Thu Sep 10, 2020 12:08 pm
Forum: General
Topic: Per Connection Classiefier (PCC) blocks incomming FaceTime calls
Replies: 34
Views: 2521

Re: Per Connection Classiefier (PCC) blocks incomming FaceTime calls

They also offer endpoint as a cloud service which likely has high availability - so no issue with single point of failure. That's the key to effectively move from per-connection to per-packet. You can do the same (more or less) with Mikrotik: get a CHR in the cloud and multiple tunnels running to i...
by xvo
Thu Sep 10, 2020 10:45 am
Forum: Wireless Networking
Topic: hAP ac3 recommended buy?
Replies: 49
Views: 2604

Re: hAP ac3 recommended buy?

So basically at the moment there's no better MikroTik device that will get me increased wireless speeds over what RB922 currently does.
As unsatisfying as it sounds, but yes.
At least not up to the point where what you gain will justify the money spent and overall hassle.
by xvo
Thu Sep 10, 2020 10:37 am
Forum: Beginner Basics
Topic: Link Downs CCR1009
Replies: 10
Views: 394

Re: Link Downs CCR1009

Ok, no errors, good.
But still can be a cabling issue.
Any chance to try different cable, or at least redo the connectors?
by xvo
Thu Sep 10, 2020 10:26 am
Forum: Wireless Networking
Topic: [Help] Mikrotik CAPsMAN Wireless download speed max 200Mb, but PC's /Mobile's link speed is 866Mbps
Replies: 50
Views: 2414

Re: [Help] Mikrotik CAPsMAN Wireless download speed max 200Mb, but PC's /Mobile's link speed is 866Mbps

Sometimes I think Normis and 3-5 other guys are the entire Mikrotik workforce
Not 3-5 of course, but only ~300 employees total.
by xvo
Thu Sep 10, 2020 1:54 am
Forum: Beginner Basics
Topic: NAT + Tag/Untag multiple identical devices
Replies: 15
Views: 678

Re: NAT + Tag/Untag multiple identical devices

Which parts of the processing would you do with the virtual routing and forwarding (VRF) technology? The VLAN tag/untag and NATing has to be done in lower layers than L3 anyway, right? VLAN tagging/untagging don't really complicate anything, you'll just end with bunch of VLAN-interfaces on each of ...
by xvo
Thu Sep 10, 2020 1:18 am
Forum: Beginner Basics
Topic: Link Downs CCR1009
Replies: 10
Views: 394

Re: Link Downs CCR1009

other side is PowerBeam 5AC Gen2 --
what is strange if i setup manualy 1GB on MIkrotik -- there is no LINK with PowerBeam 5AC Gen2 -- must make Auto negotiation to work again :(
Are there any errors registered on the link (TX Stats/RX Stats)?
by xvo
Wed Sep 09, 2020 4:26 pm
Forum: Beginner Basics
Topic: Don´t get an ip adress assigne from my ISP router
Replies: 3
Views: 229

Re: Don´t get an ip adress assigne from my ISP router

Copy MAC-address of 2011's WAN port somewhere, then change it to the one from ASUS's WAN port.
If that resolves the problem, that will indicate the ISP is using binding to MAC for authentication.
Then change the MAC back and call your ISP, and ask them how to rebind to the new address.
by xvo
Wed Sep 09, 2020 4:18 pm
Forum: Beginner Basics
Topic: NAT + Tag/Untag multiple identical devices
Replies: 15
Views: 678

Re: NAT + Tag/Untag multiple identical devices

The clue is VRF.
by xvo
Wed Sep 09, 2020 4:13 pm
Forum: Beginner Basics
Topic: Link Downs CCR1009
Replies: 10
Views: 394

Re: Link Downs CCR1009

what can be reason LINK DOWN? ? for 2-3 s
All ports or just the one?
What's on the other side of the link?
by xvo
Tue Sep 08, 2020 10:23 pm
Forum: Beginner Basics
Topic: Set bandwidth limit on WAN [SOLVED]
Replies: 11
Views: 552

Re: Set bandwidth limit on WAN [SOLVED]

/queue simple add dst=pppoe-out1 max-limit=10M/10M name=queue1 queue=default/default target=eth1 Thanks a lot for the reply. Apart forbthe queues code, do i need to add anything else on the firewall or anywhere else? Nope, but I misread your original post a little, so the command should be: /queue ...
by xvo
Tue Sep 08, 2020 3:42 pm
Forum: Beginner Basics
Topic: Set bandwidth limit on WAN [SOLVED]
Replies: 11
Views: 552

Re: Set bandwidth limit on WAN [SOLVED]

/queue simple add dst=pppoe-out1 max-limit=10M/10M name=queue1 queue=default/default target=eth1
by xvo
Tue Sep 08, 2020 12:48 pm
Forum: General
Topic: PPTP issue
Replies: 2
Views: 189

Re: PPTP issue

Clients don't have a route to 192.168.102.0/24 and use the default one.
by xvo
Mon Sep 07, 2020 11:54 am
Forum: General
Topic: Bridging VLAN and ethernet
Replies: 16
Views: 637

Re: Bridging VLAN and ethernet

Yes, I think I understood. I'm okay with separate subnets.
Ok! :)
by xvo
Sun Sep 06, 2020 11:41 pm
Forum: Wireless Networking
Topic: cAP ac with ROS 6.47.3 - country setting impossible?
Replies: 9
Views: 544

Re: cAP ac with ROS 6.47.3 - country setting impossible?

..... unless the gain was changed while in a previous release or by a restored or imported configuration (or set to zero due to the update) , and people unfamiliar with RouterOS are facing a rather puzzling fix (CLI only) with a non-trivial error message ..... Well, that's what this forum is for :)))
by xvo
Sun Sep 06, 2020 11:38 pm
Forum: General
Topic: Bridging VLAN and ethernet
Replies: 16
Views: 637

Re: Bridging VLAN and ethernet

Thanks. That's a very useful explanation of VLANs. That doc also confirms what XVO said. The interfaces must be on separate subnets. I'm still not 100% sure that you got me right: both approaches are possible. If you want them to be in one subnet - then you need to bridge two ethernet interfaces to...
by xvo
Sun Sep 06, 2020 5:54 pm
Forum: General
Topic: Bridging VLAN and ethernet
Replies: 16
Views: 637

Re: Bridging VLAN and ethernet

That makes sense. Thanks so much for your help! большое спасибо!
You are welcome! :)
by xvo
Sun Sep 06, 2020 2:36 pm
Forum: Beginner Basics
Topic: Add MGMT Vlan to DMZ
Replies: 14
Views: 552

Re: Add MGMT Vlan to DMZ

Note that the vlan-aware bridge is less versatile than the general solution of putting vlan interfaces in a bridge. For example, it is not possible to have different tags on different ports (tag translation). True. But when talking about tag translation between two ports, the bridge will contain tw...
by xvo
Sun Sep 06, 2020 1:00 pm
Forum: Beginner Basics
Topic: Add MGMT Vlan to DMZ
Replies: 14
Views: 552

Re: Add MGMT Vlan to DMZ

Put the VLAN interface in a bridge together with ether5 and put the IP config you now have on ether5 on that bridge instead. One should avoid bridging physical ports with vlan interfaces: https://wiki.mikrotik.com/wiki/Manual:Layer2_misconfiguration#VLAN_in_bridge_with_a_physical_interface Creating...
by xvo
Sun Sep 06, 2020 11:38 am
Forum: Wireless Networking
Topic: cAP ac with ROS 6.47.3 - country setting impossible?
Replies: 9
Views: 544

Re: cAP ac with ROS 6.47.3 - country setting impossible?

Historically, setting antenna gain higher (and tricking the device so it will lower the TX power automatically) was (and still is) the easiest way to lower the TX power on devices that don't support tx-power-mode=card-rates (tx-power-mode=all-rates-fixed is not exactly that, and setting tx-power for...
by xvo
Sun Sep 06, 2020 10:00 am
Forum: Beginner Basics
Topic: Bridge Mode & DHCP
Replies: 10
Views: 488

Re: Bridge Mode & DHCP

Maybe a warning while using Quickset after initial config would make sense. I also noticed that it randomly removed me a couple of firewall rules for L2TP/IPsec server access Not being told what will happen, is not the "safest" design. sebus While there are some warnings in help web page for quicks...
by xvo
Sun Sep 06, 2020 9:51 am
Forum: General
Topic: Bridging VLAN and ethernet
Replies: 16
Views: 637

Re: Bridging VLAN and ethernet

Per your advice earlier, I got rid of the bridge. Now that there is no bridge, can I go ahead and assign same-subnet different-IPs to the VLAN and ethernet interface? That is not, what I meant: two ethernet ports should be bridged, not ethernet port and vlan. But if you don't want to go that way: y...
by xvo
Sun Sep 06, 2020 1:10 am
Forum: General
Topic: Bridging VLAN and ethernet
Replies: 16
Views: 637

Re: Bridging VLAN and ethernet

Do you know if it's possible to have the VLAN's interface set to 192.168.1.1, and the ethernet port's interface set to 192.168.1.2? Same subnet, same IP pool, but different IP addresses? Assigning an address to a slave interface (and ethernet interface will be a slave to a bridge in your config) is...
by xvo
Sun Sep 06, 2020 12:10 am
Forum: General
Topic: Bridging VLAN and ethernet
Replies: 16
Views: 637

Re: Bridging VLAN and ethernet

Thank you. By "do it properly" you mean bridge vlan filtering, correct? Depending on what exact Mikrotik device we are talking about. And are you saying that to have them on separate subnets will be a performance loss? Or that finding a workaround is not a good idea? Traffic between subnets will be...
by xvo
Sat Sep 05, 2020 11:43 pm
Forum: General
Topic: Bridging VLAN and ethernet
Replies: 16
Views: 637

Re: Bridging VLAN and ethernet

Thanks. This is the man page, then? https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering Yes, that's it. But keep in mind that, despite the fact, that all mikrotik devices can be configured this way, in high-load scenarios this approach it the best option only for CRS3XX swi...
by xvo
Sat Sep 05, 2020 11:18 pm
Forum: Beginner Basics
Topic: Bridge Mode & DHCP
Replies: 10
Views: 488

Re: Bridge Mode & DHCP

That is what I normally expect from the gear I work with. But well... Quickset is just a set of scripts, that apply different predefined configurations with some user-defined variables (like names, passwords, some checkbox-type options). There is absolutely no way someone could make such script che...
by xvo
Sat Sep 05, 2020 11:04 pm
Forum: General
Topic: Bridging VLAN and ethernet
Replies: 16
Views: 637

Re: Bridging VLAN and ethernet

I created a bridge called "office," assigned it two ports (ether3 and VLAN11) That is not the correct way. Bridging VLAN interfaces with physical ports is a misconfiguration. You should add both ethernet ports to the same bridge and then setup a proper vlan filtering. Depending on the RB model, it ...
by xvo
Sat Sep 05, 2020 9:37 pm
Forum: Beginner Basics
Topic: Bridge Mode & DHCP
Replies: 10
Views: 488

Re: Bridge Mode & DHCP

If you didn't disable it yourself, mikrotik won't do it for you, that's for sure. On the other hand, if talking about "bridge mode", you mean quickset, then I'm going to disappoint you: quickset is not meant to be used on the router, that has a non-default configuration. I mean at all. It can screw ...
by xvo
Sat Sep 05, 2020 6:40 pm
Forum: Wireless Networking
Topic: cAP ac with ROS 6.47.3 - country setting impossible?
Replies: 9
Views: 544

Re: cAP ac with ROS 6.47.3 - country setting impossible?

radiating power has not changed also - only ROS thinks that the antenna has less gain. It is so? Yes and no. It thinks that antenna has different gain and adjusts the radiating power to fall into the allowed range. Antenna gain minimal value together with regulatory-domain setting is exactly what p...
by xvo
Sat Sep 05, 2020 5:40 pm
Forum: Wireless Networking
Topic: cAP ac with ROS 6.47.3 - country setting impossible?
Replies: 9
Views: 544

Re: cAP ac with ROS 6.47.3 - country setting impossible?

Set proper antenna gain in terminal:
/interface wireless set 0 antenna-gain=2
by xvo
Wed Sep 02, 2020 1:48 pm
Forum: Wireless Networking
Topic: After enabling multicast-helper mt wireless bridges dont work anymore
Replies: 20
Views: 851

Re: After enabling multicast-helper mt wireless bridges dont work anymore

you mean to create a seperate virtual ssid on the cap that will be connected with the station-bride?
Exactly.
by xvo
Wed Sep 02, 2020 12:32 pm
Forum: Wireless Networking
Topic: After enabling multicast-helper mt wireless bridges dont work anymore
Replies: 20
Views: 851

Re: After enabling multicast-helper mt wireless bridges dont work anymore

As a matter of fact, I was wrong, capsman is the reason after all:
https://wiki.mikrotik.com/wiki/Manual:W ... tion_Modes

So the best thing to try is to create separate virtual interface not managed by capsman.
by xvo
Wed Sep 02, 2020 12:18 pm
Forum: Wireless Networking
Topic: After enabling multicast-helper mt wireless bridges dont work anymore
Replies: 20
Views: 851

Re: After enabling multicast-helper mt wireless bridges dont work anymore

3. this option is necessary to enable communication between wireless clients inside their (with a capsmans acl) assigned vlans, so i have to enable it. Now I get it: it's not really a bridge, but rather ap - station, when the far end of the bridge is among some other "regular" clients. 1. because i...
by xvo
Wed Sep 02, 2020 11:42 am
Forum: Wireless Networking
Topic: After enabling multicast-helper mt wireless bridges dont work anymore
Replies: 20
Views: 851

Re: After enabling multicast-helper mt wireless bridges dont work anymore

First of all, why do you care if mode=station-bridge is supported by capsman, when capsman is not used to configure the station? Second, it is explicitly stated in wiki that for multicast-helper=full station has to be in mode=station-bridge. And the last, why do you need multicast-helper=full in the...
by xvo
Wed Sep 02, 2020 11:09 am
Forum: Announcements
Topic: WinBox v3.27 released!
Replies: 70
Views: 8830

Re: WinBox v3.26 released!

Log window is showing no entries.
by xvo
Wed Sep 02, 2020 10:06 am
Forum: Beginner Basics
Topic: Mikrotik as L2TP Client connected to Mikrotik L2TP server
Replies: 8
Views: 380

Re: Mikrotik as L2TP Client connected to Mikrotik L2TP server

Have you done the same on the other side?

Also you better change the addresses on the tunnel itself so they are not from your local subnet.
by xvo
Tue Sep 01, 2020 1:50 pm
Forum: Beginner Basics
Topic: Mikrotik as L2TP Client connected to Mikrotik L2TP server
Replies: 8
Views: 380

Re: Mikrotik as L2TP Client connected to Mikrotik L2TP server

You can’t use interface as a gateway in this case. It has to be remote router’s tunnel address: 192.168.1.251
by xvo
Tue Sep 01, 2020 12:42 am
Forum: Beginner Basics
Topic: Mikrotik as L2TP Client connected to Mikrotik L2TP server
Replies: 8
Views: 380

Re: Mikrotik as L2TP Client connected to Mikrotik L2TP server

How do I create a route on the core side to the spoke subnet if there is no interface or IP to use? The interface is created dynamically when the spoke mikrotik connects. There are several options: 1) You can create L2TP Server Binding - which is a static interface. 2) You can specify the routes th...
by xvo
Sat Aug 29, 2020 7:04 pm
Forum: General
Topic: Hap Ac2 CPU usage during speedtest.
Replies: 8
Views: 448

Re: Hap Ac2 CPU usage during speedtest.

It's kind of expected for non-fasttracked traffic with queues, and as much mangle rules.
by xvo
Tue Aug 25, 2020 6:36 pm
Forum: The Dude
Topic: TheDude server on Hex-S
Replies: 4
Views: 299

Re: TheDude server on Hex-S

Add this rule to your firewall and move it upper than the default drop rule in input chain:
/ip firewall filter add action=accept chain=input comment="allow dude to self" dst-address-type=local dst-port=8291 protocol=tcp src-address-type=local
by xvo
Sat Aug 22, 2020 7:27 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 270
Views: 69361

Re: v7.1beta2 [development] is released!

For CRS317 it was added earlier.
by xvo
Sat Aug 22, 2020 12:06 am
Forum: General
Topic: RB4011iGS+5HacQ2HnD-IN very slow Ethernet bridge
Replies: 20
Views: 1000

Re: RB4011iGS+5HacQ2HnD-IN very slow Ethernet bridge

I have a suggestion. Do you by any chance have a couple of switches, so both NASes are connected to 4011 via its own switch? Or instead you can configure your RB260 this way: ports 1 and 2 untagged members of one vlan, ports 3 and 4 - the other. And another suggestion, watch for errors on TX Stats a...
by xvo
Fri Aug 21, 2020 11:31 pm
Forum: General
Topic: RB4011iGS+5HacQ2HnD-IN very slow Ethernet bridge
Replies: 20
Views: 1000

Re: RB4011iGS+5HacQ2HnD-IN very slow Ethernet bridge

What ports do you use: belonging to one switch or different?
by xvo
Fri Aug 21, 2020 6:43 pm
Forum: Wireless Networking
Topic: Easiest way to point specific devices to other DNS? [SOLVED]
Replies: 17
Views: 1923

Re: Easiest way to point specific devices to other DNS? [SOLVED]

Well, you can certainly do that.
But your initial post was about DNS only, and about the easiest way to do it.
And so was my answer.
by xvo
Fri Aug 21, 2020 5:47 pm
Forum: Wireless Networking
Topic: Easiest way to point specific devices to other DNS? [SOLVED]
Replies: 17
Views: 1923

Re: Easiest way to point specific devices to other DNS? [SOLVED]

Create additional network(s) in DHCP Server --> Networks just for that address(es) with another DNS server setting.
by xvo
Fri Aug 21, 2020 5:40 pm
Forum: General
Topic: CRS212 hw-offload on vlan-aware bridge [SOLVED]
Replies: 1
Views: 247

Re: CRS212 hw-offload on vlan-aware bridge [SOLVED]

Only CRS3XX devices can get hw-offloading when VLANs are configured in the bridge menu.
On all other devices (CRS1XX/CRS2XX as well) you still have to configure VLANs in switch menu, for traffic to be processed by switch chip, and not by CPU.
by xvo
Fri Aug 21, 2020 2:12 pm
Forum: General
Topic: Per Connection Classiefier (PCC) blocks incomming FaceTime calls
Replies: 34
Views: 2521

Re: Per Connection Classiefier (PCC) blocks incomming FaceTime calls

Is there anything else out there that's superior to PCC-type concept for load-balancing between two different ISPs without the use of proper bonding? I mean outside the world of MikroTik. Outside or inside Mikrotik, it is not an implementation question, but rather a question of concept, as you stat...
by xvo
Fri Aug 21, 2020 12:47 pm
Forum: General
Topic: Per Connection Classiefier (PCC) blocks incomming FaceTime calls
Replies: 34
Views: 2521

Re: Per Connection Classiefier (PCC) blocks incomming FaceTime calls

The benefit of "both addresses" is the increased chances of bandwidth aggregation. "both addresses and ports" would double or triple the chances of bandwidth aggregation. That is only true for small amount of client devices. When we are talking about 50, 100 and more active users, the load will be ...
by xvo
Fri Aug 21, 2020 1:08 am
Forum: General
Topic: RB4011iGS+5HacQ2HnD-IN very slow Ethernet bridge
Replies: 20
Views: 1000

Re: RB4011iGS+5HacQ2HnD-IN very slow Ethernet bridge

Thanks all for the tips here. I am sure 3dfx can apply those to get wired speed as well :). He should disable STP as well and make sure there is no loops in his network as this protocol needs to be disabled in order to get wired speed on VLAN 1 I don't think lack of HW-offloading is a problem in hi...
by xvo
Fri Aug 21, 2020 12:55 am
Forum: General
Topic: Per Connection Classiefier (PCC) blocks incomming FaceTime calls
Replies: 34
Views: 2521

Re: Per Connection Classiefier (PCC) blocks incomming FaceTime calls

Nah, you got it wrong. What the other guy tried telling is, when an app/service/site does multiple connections to multiple destination IPs. Hence the hash will never be the same for each pair of "source IP" and "destination IP" where the latter varies. Please, reread the thread: "the other guy" was...
by xvo
Fri Aug 21, 2020 12:30 am
Forum: General
Topic: Per Connection Classiefier (PCC) blocks incomming FaceTime calls
Replies: 34
Views: 2521

Re: Per Connection Classiefier (PCC) blocks incomming FaceTime calls

No one has ever shown any hard evidence for "broken connections due to multiple source IPs".
How will using both-addresses end up with "multiple source IPs" in the first place?!
The hash will always be the same for a given pair of addresses - so the resulting WAN will be the same.
by xvo
Fri Aug 21, 2020 12:25 am
Forum: General
Topic: RB4011iGS+5HacQ2HnD-IN very slow Ethernet bridge
Replies: 20
Views: 1000

Re: RB4011iGS+5HacQ2HnD-IN very slow Ethernet bridge

by default STP is enabled and as soon as I disable it I got HW offload enabled.
Bingo! :)
by xvo
Thu Aug 20, 2020 7:17 pm
Forum: General
Topic: RB4011iGS+5HacQ2HnD-IN very slow Ethernet bridge
Replies: 20
Views: 1000

Re: RB4011iGS+5HacQ2HnD-IN very slow Ethernet bridge

Something is configured on yours that disables HW offload.
Most likely STP.
by xvo
Thu Aug 20, 2020 2:40 pm
Forum: Beginner Basics
Topic: Точка - многоточка
Replies: 9
Views: 545

Re: Точка - многоточка

If I log into routerOS is everything ok?
Login and navigate to System --> License to check the actual licence level.
by xvo
Thu Aug 20, 2020 12:19 pm
Forum: Beginner Basics
Topic: Packet counters for mark connection and mark packet
Replies: 3
Views: 270

Re: Packet counters for mark connection and mark packet

1) Connection is marked on the first packet from LAN to VPN: 1st counter +1 2) The same packet is marked with packet mark by second rule (you have passthrough=yes on the first rule): 2nd counter +1 3) Returning packet is marked with packet mark (as it belongs to already marked connection): 2nd count...
by xvo
Thu Aug 20, 2020 10:22 am
Forum: General
Topic: Problem - traffic showing on inactive port
Replies: 3
Views: 332

Re: Problem - traffic showing on inactive port

No real point, but from your screenshot it is not disabled.
by xvo
Thu Aug 20, 2020 9:48 am
Forum: Beginner Basics
Topic: Packet counters for mark connection and mark packet
Replies: 3
Views: 270

Re: Packet counters for mark connection and mark packet

5 pings = 10 packets (5 leaving + 5 returning)
by xvo
Wed Aug 19, 2020 6:30 pm
Forum: RouterBOARD hardware
Topic: powering a CCR2004-1G-12S+2XS 1x GE
Replies: 4
Views: 546

Re: powering a CCR2004-1G-12S+2XS 1x GE

Haven't seen what's inside, but it should work anyway - you'll just need to find the right connector. This PSU looks like a spare to the default one: https://mikrotik.com/product/gb60a_s12#fndtn-downloads BTW, here is the video, where you can see the internal layout and type of connectors: https://w...
by xvo
Wed Aug 19, 2020 2:35 pm
Forum: General
Topic: Hairpin NAT on Double NAT Network [SOLVED]
Replies: 6
Views: 569

Re: Hairpin NAT on Double NAT Network [SOLVED]

Interesting case, post your config on the MT /export hide-sensitive file=anynameyouwish No it isn't: second NAT on TP-link doesn't make any difference. As always exactly 3 possible solutions: 1) Properly implemented hairpin NAT with all it's pros and cons. 2) Static DNS entry (if mikrotik serves as...
by xvo
Wed Aug 19, 2020 1:30 pm
Forum: RouterBOARD hardware
Topic: CRS328-24P-4S+RM - Fan noise? [SOLVED]
Replies: 4
Views: 413

Re: CRS328-24P-4S+RM - Fan noise? [SOLVED]

Not even with those Noctuas? Even with those Noctuas. I use them (not the PWM version though) in CCR1009. Only one running at a time. Much better than the stock ones - the sound is much softer and not so high-pitched. But at night you can clearly hear it even in the adjacent room if the door is open.
by xvo
Wed Aug 19, 2020 12:50 pm
Forum: RouterBOARD hardware
Topic: CRS328-24P-4S+RM - Fan noise? [SOLVED]
Replies: 4
Views: 413

Re: CRS328-24P-4S+RM - Fan noise? [SOLVED]

Not as silent as you would want.
Definitely not for bedroom.
by xvo
Wed Aug 19, 2020 11:20 am
Forum: General
Topic: Mikrotik behind ADSL model/router - allow UPnP
Replies: 6
Views: 426

Re: Mikrotik behind ADSL model/router - allow UPnP

I guess the UPnP request to forward ports from the machines has to be first processed by Mikrotik (to create port forward rules from MikroTik to certain machine on LAN) and then propagated up to the ADSL router (to create port forward rules from ADSL router to the mikrotik). Mikrotik can't be a uPn...
by xvo
Wed Aug 19, 2020 12:26 am
Forum: Beginner Basics
Topic: VNC with MikroTik LMT LTE18 router
Replies: 19
Views: 2875

Re: VNC with MikroTik LMT LTE18 router

but for the moment I have only one router.
You don't need another one.
You establish VPN connection from a remote PC to your router, and then you run VNC inside VPN.
That is the secure way to do that.
by xvo
Fri Aug 14, 2020 12:17 am
Forum: Virtualization
Topic: Poor WAN speed with CHR on AWS
Replies: 5
Views: 1093

Re: Poor WAN speed with CHR on AWS

Try pinging through the tunnel with different sized packets and don't fragment option to find the right MTU and set it as Max MTU (should be lower then 1500).
by xvo
Thu Aug 13, 2020 11:55 pm
Forum: Virtualization
Topic: Poor WAN speed with CHR on AWS
Replies: 5
Views: 1093

Re: Poor WAN speed with CHR on AWS

What is an Actual MTU on the tunnel?
by xvo
Thu Aug 13, 2020 11:41 pm
Forum: Virtualization
Topic: Poor WAN speed with CHR on AWS
Replies: 5
Views: 1093

Re: Poor WAN speed with CHR on AWS

What is your CHR license level?
by xvo
Thu Aug 13, 2020 10:45 pm
Forum: General
Topic: CCR1016-12S-1S+ 10G port doesn’t work with RJ45 SFP Coper Module.
Replies: 1
Views: 470

Re: CCR1016-12S-1S+ 10G port doesn’t work with RJ45 SFP Coper Module.

https://wiki.mikrotik.com/wiki/MikroTik ... ble#1G_SFP
CCR1016-12S-1S+ / CRS212-1G-10S-1S+ -- SFP+1 interface does not work on any other link speed than 10G (does not support 1.25G fiber optic transceivers)
by xvo
Thu Aug 13, 2020 6:18 pm
Forum: Beginner Basics
Topic: VNC with MikroTik LMT LTE18 router
Replies: 19
Views: 2875

Re: VNC with MikroTik LMT LTE18 router

Previously you had dynamic, but still public IP. Obviously.
Now, your IP is private (doesn't even matter it it is static or dynamic).
Without public IP it won't work on any router.
by xvo
Thu Aug 13, 2020 5:48 pm
Forum: Beginner Basics
Topic: Router Mode
Replies: 6
Views: 1600

Re: Router Mode

Quickset is just an UI that runs a script which applies some predefined configurations.
So such thing as "router mode" doesn't exist outside of quickset.
by xvo
Thu Aug 13, 2020 2:59 pm
Forum: Beginner Basics
Topic: Firewall VLAN Isolation exception
Replies: 2
Views: 541

Re: Firewall VLAN Isolation exception

Sure.
Make a more specific rule accepting this traffic and place it above the drop one.
by xvo
Thu Aug 13, 2020 11:57 am
Forum: General
Topic: Route internal requests for external IP
Replies: 1
Views: 353

Re: Route internal requests for external IP

If your router is serving dns for your lan - you can add a static dns entry pointing to server's internal ip. The other way is to implement so called "hairpin nat". The idea is to remove the routing triangle (router, server, client) by making it look like all internal requests to server are originat...
by xvo
Thu Aug 13, 2020 1:03 am
Forum: Beginner Basics
Topic: Can hEX S power up hAP ac^2 with POE?
Replies: 10
Views: 1638

Re: Can hEX S power up hAP ac^2 with POE?

Is there any distance limitation?
The PSU that comes with hAP ac2 is rated 24V 0.8A (~19W).
The devices consumes 16W.

https://linktest.ru/poecalc.html

Up to 40m it should work with a good cable.
Up to 30m, I guess, you are safe with any :)
by xvo
Thu Aug 13, 2020 12:33 am
Forum: Beginner Basics
Topic: Can hEX S power up hAP ac^2 with POE?
Replies: 10
Views: 1638

Re: Can hEX S power up hAP ac^2 with POE?

What if i buy RBGPOE to power up the hap ac2 with his own power supply it wont work?
Sure it will.
by xvo
Thu Aug 13, 2020 12:29 am
Forum: Wireless Networking
Topic: Error message when setting UK/unable to specify gain
Replies: 3
Views: 638

Re: Error message when setting UK/unable to specify gain

Try /interface wireless export verbose
When some setting is set to it's default value it is not showed by "regular" export.

Antenna gain setting was hidden from winbox/webfig in one of the latest versions, for not to be (mis)used on devices with fixed antenna.
by xvo
Thu Aug 13, 2020 12:10 am
Forum: Beginner Basics
Topic: Can hEX S power up hAP ac^2 with POE?
Replies: 10
Views: 1638

Re: Can hEX S power up hAP ac^2 with POE?

Or you can just buy this :lol: :

https://mikrotik.com/product/rbgpoe_con_hp

Then it will be simpler:

AC outlet --> 48V PSU --> hEX S (PoE-out)--> RBGPOE-CON-HP --> hAP ac2 (PoE-in)
by xvo
Thu Aug 13, 2020 12:07 am
Forum: Beginner Basics
Topic: Can hEX S power up hAP ac^2 with POE?
Replies: 10
Views: 1638

Re: Can hEX S power up hAP ac^2 with POE?

Which 48v to 24v converter is recommended? No idea. Browse aliexpress for anything capable of 30W+ So the flow will be 48v to 24v convertor powering with the converter you mentioned earlier one comes to the hex and second to rbgpoe to power up ac2? Nope. AC outlet --> 48V PSU --> hEX S (PoE-out) --...
by xvo
Wed Aug 12, 2020 11:37 pm
Forum: Beginner Basics
Topic: Can hEX S power up hAP ac^2 with POE?
Replies: 10
Views: 1638

Re: Can hEX S power up hAP ac^2 with POE?

I guess the easiest way would be getting a couple of these: https://cdn.sparkfun.com//assets/parts/ ... 287-01.jpg
One into RBGPoE, one into hAP, and DC-DC converter in between.
by xvo
Wed Aug 12, 2020 7:50 pm
Forum: Beginner Basics
Topic: Can hEX S power up hAP ac^2 with POE?
Replies: 10
Views: 1638

Re: Can hEX S power up hAP ac^2 with POE?

Unfortunately hAP ac2 supports only 18-28V on PoE-in, so 16W of max power consumption will be more than 500mA.
However I can think of a workaround: you can feed 48V to hEX S, and then use RBGPoE as splitter + 48V to 24V DC-DC converter to power hAP ac2 by it's DC jack.
by xvo
Wed Aug 12, 2020 2:35 pm
Forum: General
Topic: Weird routing problem [SOLVED]
Replies: 18
Views: 1246

Re: Weird routing problem [SOLVED]

Bridge is L2 entity.
WAN <-> LAN routing is L3.

I guess some mixture of both entities is producing unpredictable result.

Post your mikrotik configuration.
by xvo
Wed Aug 12, 2020 1:50 pm
Forum: General
Topic: Weird routing problem [SOLVED]
Replies: 18
Views: 1246

Re: Weird routing problem [SOLVED]

From your description it is not completely clear, what exactly you want achieve:
1) for mikrotik to route between it's own network and 192.168.1.0/24
2) for mikrotik to NAT from it's own network to outside world
3) for mikrotik to act as a switch (bridge)
by xvo
Wed Aug 12, 2020 10:56 am
Forum: Scripting
Topic: bug in tool fetch? [SOLVED]
Replies: 6
Views: 1362

Re: bug in tool fetch? [SOLVED]

@pe1chl
Thanks for an insight.
by xvo
Tue Aug 11, 2020 11:15 pm
Forum: RouterBOARD hardware
Topic: Mikrotik CCR2004 B/W Capacity
Replies: 7
Views: 1953

Re: Mikrotik CCR2004 B/W Capacity

The CCR2004 has close to 3 times the forwarding performance of the 1009.
30% improvement, not 300%
When not limited by interface speeds, of course.
by xvo
Tue Aug 11, 2020 2:04 pm
Forum: Scripting
Topic: bug in tool fetch? [SOLVED]
Replies: 6
Views: 1362

Re: bug in tool fetch? [SOLVED]

Not the first time I hear about that.
Now I was able to reproduce (earlier I tried only with H in the beginning).
v.6.46.1 and 6.45.9
by xvo
Mon Aug 10, 2020 12:45 am
Forum: General
Topic: Multisite routing restrictions
Replies: 3
Views: 590

Re: Multisite routing restrictions

While locally you can use in-interface/out-interface matchers to allow/restrict access by firewall, on the remote site you need to switch to different approach and use src-address/dst-address matchers instead. Also, for this to work, make sure you don't src-nat/masquerade traffic outgoing to the tun...
by xvo
Sun Aug 09, 2020 3:05 pm
Forum: Beginner Basics
Topic: Join 2 different networks
Replies: 6
Views: 1274

Re: Join 2 different networks

Since its setup as router, then you have no access to devices behind it.
NAT, firewall and lack of routes is the reason, not the fact that device is acting as a router.
It's a completely legit setup, just needs proper configuration.
by xvo
Sun Aug 09, 2020 3:02 pm
Forum: Beginner Basics
Topic: Join 2 different networks
Replies: 6
Views: 1274

Re: Join 2 different networks

10.1.1.1/8 is not a valid subnet. Anyway, you need to either add a static route to your ddwrt's network via it's address in mikrotik's network. And on ddwrt router disable nat and allow such connections in firewall. Or alternatively you can establish port forwarding on ddwrt router, just as you woul...
by xvo
Sun Aug 09, 2020 12:52 pm
Forum: Beginner Basics
Topic: Hex S - can I change internet port?
Replies: 8
Views: 1899

Re: Hex S - can I change internet port?

I followed the above, except my NAT rule used out-interface list WAN. Would that matter? I'll try again using out interface instead of list.
Rgds,
You can continue to use default rule with interface-list, just modify the members of that list.
by xvo
Sun Aug 09, 2020 12:25 pm
Forum: Beginner Basics
Topic: Hex S - can I change internet port?
Replies: 8
Views: 1899

Re: Hex S - can I change internet port?

Yes, you can use any port for any role.
That depends only on how you configure your device.
There is no hardcoded roles for ports on mikrotik equipment.
by xvo
Sat Aug 08, 2020 11:23 pm
Forum: General
Topic: CRS VLAN / Management IP
Replies: 4
Views: 1307

Re: CRS VLAN / Management IP

Adding a VLAN to the bridge, so far as I know, will cause all hardware offloading to be disabled. Enabling bridge VLAN filtering does, not adding VLAN interface on top of the bridge. In addition to creating interface vlan, switch1-cpu has to be added as a tagged member of management vlan: both in /...
by xvo
Fri Aug 07, 2020 12:52 pm
Forum: Wireless Networking
Topic: Bad performance on hAP ac^2 vs CAPsMAN AP behind hEX s as AP
Replies: 40
Views: 3861

Re: Bad performance on hAP ac^2 vs CAPsMAN AP behind hEX s as AP

But ac2 is connected via ether1 poe to the capsman (hex s)
Can be port flapping.
Check log and port status tab on both devices.
by xvo
Fri Aug 07, 2020 10:36 am
Forum: RouterBOARD hardware
Topic: 10Gb networking
Replies: 4
Views: 1058

Re: 10Gb networking

Thanks, so if you want to use the 10Gb uplink, you effectively lose a port and if you've only obviously got one port available, you also lose the PoE in If it's "just for management" and you do use it as an uplink too, aren't you uplinking at 1Gb? I specifically didn't say, that it is "just for man...
by xvo
Fri Aug 07, 2020 10:06 am
Forum: RouterBOARD hardware
Topic: 10Gb networking
Replies: 4
Views: 1058

Re: 10Gb networking

1G ethernet port is mostly for management in this switch.
However it is connected to same switch chip (not directly to CPU), so you can you use it for effectively passing traffic too.
And as an uplink to the router as well, if you want.

If not - use any of 10G ports.
by xvo
Fri Aug 07, 2020 1:08 am
Forum: Beginner Basics
Topic: Can't get port forwarding working
Replies: 3
Views: 687

Re: Can't get port forwarding working

If you don't see packet counters increasing for dst-nat rule when testing from outside - packets never reach the router at all. Are you sure that you router is actually getting a public IP? By "changing in-interface" you mean not only changing it in the rule, but also trying to test from inside your...
by xvo
Thu Aug 06, 2020 11:53 pm
Forum: Beginner Basics
Topic: "Reset Button" purpose in Winbox GUI
Replies: 6
Views: 1374

Re: "Reset Button" purpose in Winbox GUI

So the GUI button will (if programmed) run the pre-designated script? Correct?
Nope, physical reset button will run the pre-designated script, if such behaviour is configured in the menu, that opens if you press the GUI button.
by xvo
Thu Aug 06, 2020 4:58 pm
Forum: Beginner Basics
Topic: Routing WiFi guest network through more routers in network
Replies: 1
Views: 514

Re: Routing WiFi guest network through more routers in network

Technically you can do NAT for this guest network on R3. But I don't see any problem in OSPF knowing the route to this network: you can always apply some restrictions in firewall. On the other hand with NAT applied it will become a more complicated task - as all guest traffic will look to other rout...
by xvo
Tue Aug 04, 2020 1:06 pm
Forum: Beginner Basics
Topic: hAP ac2 – slow transfer speed between vlans
Replies: 14
Views: 3388

Re: hAP ac2 – slow transfer speed between vlans

Is fasttrack actually working?
Check in /ip firewall connections that connections between vlans (or any at all) are being fasttracked.
by xvo
Mon Aug 03, 2020 3:04 pm
Forum: RouterBOARD hardware
Topic: HEX POE problem
Replies: 8
Views: 1719

Re: HEX POE problem

PoE in input Voltage 12-57 V (is not specified passive POE) What exactly would be 12V or 24V PoE in this case, if not passive? :) Here they forgot to mention af/at: https://i.mt.lv/cdn/product_files/mAP-qg_191149.pdf And here both passive and af/at are mentioned: https://i.mt.lv/cdn/product_files/m...
by xvo
Mon Aug 03, 2020 1:14 pm
Forum: General
Topic: Changing source IP from inbound connections [SOLVED]
Replies: 4
Views: 602

Re: Changing source IP from inbound connections [SOLVED]

You don't really need to always match src-address for src-nat.
In your case you can match these packets by dst-address=192.168.0.100.
by xvo
Mon Aug 03, 2020 10:32 am
Forum: Beginner Basics
Topic: how to tag lan and wifi on the same vlan [SOLVED]
Replies: 9
Views: 1438

Re: how to tag lan and wifi on the same vlan [SOLVED]

if i set vlan mode for switch1-cpu to check/add-if-missing vlan 30, all the clients on vlan 30 works normally (wifi and eth can ping each other), the only drawback is i can not access the RB anymore. To access the RB itself you should add at least one vlan-interface on top of the bridge and address...
by xvo
Mon Aug 03, 2020 10:20 am
Forum: Beginner Basics
Topic: CRS312 Issues
Replies: 20
Views: 3346

Re: CRS312 Issues

That sounds weird.
Do you switch to fixed rates both on client and the switch?
If both ends are set to auto negotiation, what rate is actually chosen?
by xvo
Mon Aug 03, 2020 10:12 am
Forum: General
Topic: question about mikrotik ccr 1072 power supply
Replies: 3
Views: 653

Re: question about mikrotik ccr 1072 power supply

On CCR1009 I own the behaviour is a bit different: it shows statuses (ok/failed) for both PSUs, but only the board voltage, not specifying which PSU is actually in use. I guess you are right, on CCR1072 zero voltage should mean failed/unplugged. Test it yourself: unplug psu2, the unit should switch ...
by xvo
Sun Aug 02, 2020 10:10 pm
Forum: Beginner Basics
Topic: CRS312 Issues
Replies: 20
Views: 3346

Re: CRS312 Issues

When in simple "bridge mode" (all ports in one bridge, no vlans etc.) the bottleneck will be not the CRS but rather your router.
by xvo
Sun Aug 02, 2020 9:42 pm
Forum: General
Topic: question about mikrotik ccr 1072 power supply
Replies: 3
Views: 653

Re: question about mikrotik ccr 1072 power supply

Because it always choses to get power from the PSU with higher voltage: so one is currently used, and another is chosen as a backup.
by xvo
Sun Aug 02, 2020 5:33 pm
Forum: Beginner Basics
Topic: CRS312 Issues
Replies: 20
Views: 3346

Re: CRS312 Issues

How can I use it as a switch only? Which means the IP address follows my current router. I don't really understand the question, but I guess yes, you can use your current router for routing, nat, firewall, dhcp server, dns etc. And CRS will do switching between LAN devices on speeds up to 10Gb/s. A...