Community discussions

MikroTik App

Search found 366 matches

  • 1
  • 2
by tdw
Sat May 23, 2020 5:27 pm
Forum: Beginner Basics
Topic: RB2011UiAS-IN VLANs on second switch bank
Replies: 10
Views: 1429

Re: RB2011UiAS-IN VLANs on second switch bank

The VLAN interfaces giving the CPU to access VLANs in /interface vlan must be attached to the parent interface not members, so bridge not ether17.

That setup will work, but will not use hardware switching.
by tdw
Fri May 22, 2020 12:41 am
Forum: General
Topic: OpenVPN with VLANs
Replies: 24
Views: 3450

Re: OpenVPN with VLANs

You can only have one server binding per username - if the same username is used more than once you end up with the server binding plus additional dynamic interfaces <ovpn-someuser-1>, <ovpn-someuser-2>, etc. If a connection is interrupted you can end up with the user connected via a dynamic interfa...
by tdw
Thu May 21, 2020 11:48 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 24
Views: 3450

Re: OpenVPN with VLANs

That rule is for the outer tunnel, not the inner tunnelled traffic. As discussed in post #4 with having firewall rules referring to the lists 'BASE', 'VLAN', 'BASE+VLAN' the open VPN server interface has to be added to these if you wish the VPN traffic to use the rules. Having interface-list=VLAN in...
by tdw
Thu May 21, 2020 9:07 pm
Forum: Beginner Basics
Topic: VLAN Bridge - Trunk with Wireless Wire "bridge port received packet with own address"
Replies: 14
Views: 1690

Re: VLAN Bridge - Trunk with Wireless Wire "bridge port received packet with own address"

By default it will capture everything - including broadcast/multicast traffic from the rest of your network and the Winbox traffic to and from the Mikrotik itself. You can apply filters to reduce the scope of the capture and hopefully volume of packets, there should be something transmitted and rece...
by tdw
Thu May 21, 2020 8:52 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 24
Views: 3450

Re: OpenVPN with VLANs

Local is server, remote is client. For point-to-point interfaces you can have the same local address on multiple interfaces. VLANs are not the issue, they only have significance for layer 2 ethernet. IP routes are automatically added to the routing table ( /ip route print or Winbox, IP > Routes), on...
by tdw
Thu May 21, 2020 7:58 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 24
Views: 3450

Re: OpenVPN with VLANs

There is nowhere to enter an interface in /ip pool - just a pool name, addresses and an optional next pool. So, based on your config, something along the lines of: /ip pool add name=pool_ovpn ranges=10.0.98.10-10.0.98.254 ... /ppp profile add dns-server=10.0.0.3 interface-list=VLAN local-address=10....
by tdw
Thu May 21, 2020 7:32 pm
Forum: Beginner Basics
Topic: system logging - no rule but still logging? [SOLVED]
Replies: 8
Views: 1213

Re: system logging - no rule but still logging? [SOLVED]

Rules 2, 5 & 12 still have log=yes so the messages will be from one of those
by tdw
Wed May 20, 2020 10:59 pm
Forum: Beginner Basics
Topic: VLAN Bridge - Trunk with Wireless Wire "bridge port received packet with own address"
Replies: 14
Views: 1690

Re: VLAN Bridge - Trunk with Wireless Wire "bridge port received packet with own address"

The configuration has an incorrect VLAN configuration. You diagram shows the master ether1 carrying VLAN 1000 and 1051 tagged, but you have configured the port has VLAN 1000 untagged. It should be: /interface bridge port add bridge=bridge comment=defconf ingress-filtering=yes interface=ether1 pvid=...
by tdw
Wed May 20, 2020 3:45 pm
Forum: Beginner Basics
Topic: VLAN Bridge - Trunk with Wireless Wire "bridge port received packet with own address"
Replies: 14
Views: 1690

Re: VLAN Bridge - Trunk with Wireless Wire "bridge port received packet with own address"

The master and slave configurations appear identical. Cut and paste issue? The configuration has an incorrect VLAN configuration. You diagram shows the master ether1 carrying VLAN 1000 and 1051 tagged, but you have configured the port has VLAN 1000 untagged. It should be: /interface bridge port add ...
by tdw
Wed May 20, 2020 2:28 am
Forum: General
Topic: OpenVPN with VLANs
Replies: 24
Views: 3450

Re: OpenVPN with VLANs

I don't know what is causing the problem. Tried different setups. It is odd that you got to a point where you had some connectivity and then lost it. I might not understand your question, but if this is the question: The remote client has an IP address from a completely different subnet (172.XX...)...
by tdw
Wed May 20, 2020 2:13 am
Forum: Beginner Basics
Topic: VLAN Bridge - Trunk with Wireless Wire "bridge port received packet with own address"
Replies: 14
Views: 1690

Re: VLAN Bridge - Trunk with Wireless Wire "bridge port received packet with own address"

What other equipment do you have in your network, and the running configuration /export hide-sensitive would help.
by tdw
Wed May 20, 2020 2:03 am
Forum: Beginner Basics
Topic: RB2011UiAS-IN VLANs on second switch bank
Replies: 10
Views: 1429

Re: RB2011UiAS-IN VLANs on second switch bank

Yes, you do get the impression that Mikrotik just created a UI exposing a load of switch chip registers and left people to figure it out. Originally switch configuration was completely separate from bridges, but they have gradually been merging so the bridge becomes a placeholder for configuring and...
by tdw
Tue May 19, 2020 9:31 pm
Forum: Beginner Basics
Topic: RB2011UiAS-IN VLANs on second switch bank
Replies: 10
Views: 1429

Re: RB2011UiAS-IN VLANs on second switch bank

If you do not need wire-speed switching between ports the RB2011 is fine with a VLAN-aware bridge and no hardware offload. The CRS1xx/2xx switching is very different to the RB devices, the wiki examples are a good starting point. Normally I would say that the CRS devices are intended to be L2 switch...
by tdw
Mon May 18, 2020 11:31 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 24
Views: 3450

Re: OpenVPN with VLANs

Nothing immediately jumps out. Is the Open VPN client connecting from an address within the IP range you are trying to tunnel? I've never tried it myself to see if handles this situation. Also, IIRC there have been comments about /internet detect-internet causing odd behaviour so it may be worth rem...
by tdw
Sun May 17, 2020 2:18 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 24
Views: 3450

Re: OpenVPN with VLANs

Per my previous email either add routing statements to the OpenVPN client configuration file route 10.0.0.0 255.255.0.0 vpn_gateway OR change the Mikrotik VPN server /interface ovpn-server server set auth=sha1 certificate=server cipher=aes256 default-profile=ppp_private enabled=yes netmask=16 requir...
by tdw
Sun May 17, 2020 1:37 pm
Forum: General
Topic: User Manager - Radius Authentication - Response send from wrong Interface
Replies: 6
Views: 976

Re: User Manager - Radius Authentication - Response send from wrong Interface

It does sound like a bug, you could report it to Mikrotik support.
by tdw
Sun May 17, 2020 1:59 am
Forum: General
Topic: OpenVPN with VLANs
Replies: 24
Views: 3450

Re: OpenVPN with VLANs

Ok thanks for clearing this up for me. Now I can access the 10.0.99.0/24 subnet from which the address is given to the interface, but not other subnets, though I have created an address list with 10.0.0.0/16 and added it under the /ppp profile address-list option. Should I need to do anything else ...
by tdw
Sat May 16, 2020 10:49 pm
Forum: Beginner Basics
Topic: Routing issue or ISP issue
Replies: 1
Views: 325

Re: Routing issue or ISP issue

It depends if the addresses are in the same /26 subnet or not - if they are then layer2 port isolation, or similar, could well be an issue. What do you get if you try ping and traceroute from one router to the other, and again in the other direction?
by tdw
Sat May 16, 2020 10:33 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 24
Views: 3450

Re: OpenVPN with VLANs

The Mikrotik OpenVPN implementation is shoehorned into their PPP model, and it does not quite fit, so some of the PPP profile settings have no meaning when used with the OpenVPN server - in particular setting bridge= under /ppp profile has no effect, this is used by PPP Bridge Control Protocol (BCP)...
by tdw
Sat May 16, 2020 8:08 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 24
Views: 3450

Re: OpenVPN with VLANs

Not being able to access the router itself is likely to be firewall rules. Having the same VLAN ID on different bridges will not pass that traffic between bridges, are you looking to bridge or route traffic? Printing the bridge and PPP profile entries provides no useful information, post the output ...
by tdw
Sat May 16, 2020 2:21 pm
Forum: General
Topic: User Manager - Radius Authentication - Response send from wrong Interface
Replies: 6
Views: 976

Re: User Manager - Radius Authentication - Response send from wrong Interface

We set the RADIUS source address to a loopback /32 on each Mikrotik and tunnel traffic to FreeRADIUS based servers over L2TP/IPsec tunnels (rather than GRE) without issue. As your user manager and tunnel endpoints are on the same device it isn't possible to determine the exact source of the problem ...
by tdw
Sat May 16, 2020 1:43 pm
Forum: Beginner Basics
Topic: RB2011UiAS-IN VLANs on second switch bank
Replies: 10
Views: 1429

Re: RB2011UiAS-IN VLANs on second switch bank

You also have a mix of bridge and switch VLAN configuration. Either use a VLAN-aware bridge OR hardware switching mixing them can have unintentional side-effects, currently the /interface bridge port PVID settings are ignored and /interface bridge vlan does nothing. Unless you need wirespeed switchi...
by tdw
Tue May 12, 2020 10:14 pm
Forum: Beginner Basics
Topic: Hybrid Ports
Replies: 2
Views: 535

Re: Hybrid Ports

There will be no communication between ports without /interface bridge and /interface bridge port configuration. Confusingly, depending on which type of Mikrotik you have, hardware switching with VLANs is implemented differently. For the CRS1xx/2xx devices you need a non-VLAN-aware bridge plus ether...
by tdw
Tue May 12, 2020 8:57 pm
Forum: General
Topic: Dot1X
Replies: 3
Views: 831

Re: Dot1X

No. EAP-MSCHAPv2 is plain old MSCHAPv2, so man-in-the middle attacks gathering the handshake are possible - these allow the NTLM password hash to be recovered. Protected EAP may be used as an "outer" method wrapping an "inner" insecure EAP method inside a TLS tunnel to prevent eavesdropping. The ful...
by tdw
Tue May 12, 2020 12:52 am
Forum: General
Topic: VLAN filtering on a sigle bridge problem
Replies: 6
Views: 720

Re: VLAN filtering on a sigle bridge problem

That is a fragment of the configuration on one device, so impossible to tell what is happening elsewhere. Nothing should be generating VLAN ID 4095 as it is a reserved value. As @mkx said ingress-filtering=yes is only set on a couple of ports, without it frame-types= has no effect. Also /interface b...
by tdw
Fri May 08, 2020 1:10 am
Forum: General
Topic: VRRP & RSTP
Replies: 22
Views: 2568

Re: VRRP & RSTP

I would suggest protocol-mode=rstp rather than protocol-mode=stp as it converges much more quickly. RouterOS does not change port path cost based on the link speed so you may wish to review the values. Also, on the secondary switch your choice of priority is odd. From the wiki "In RouterOS it is pos...
by tdw
Thu May 07, 2020 4:40 pm
Forum: General
Topic: VRRP & RSTP
Replies: 22
Views: 2568

Re: VRRP & RSTP

From what I recall of the HPE STP/RSTP implementation it is standards compliant - the BPDUs are always untagged. If you stick with RSTP you must have the same selection of VLANs present on all legs of the loop (as the RSTP blocking could interrupt any leg), and RSTP only transmitted untagged for the...
by tdw
Thu May 07, 2020 3:16 pm
Forum: General
Topic: User Manager - Radius Authentication - Response send from wrong Interface
Replies: 6
Views: 976

Re: User Manager - Radius Authentication - Response send from wrong Interface

Without any configuration details it is difficult to say. By default the RADIUS client will use the address of the egress interface as the source address unless you explicitly set one, and the RADIUS server / user manager will reply to that address.
by tdw
Tue May 05, 2020 11:05 pm
Forum: Beginner Basics
Topic: Vlan Filtering
Replies: 8
Views: 1361

Re: Vlan Filtering

It depends on how you access traffic on VLAN5 by the CPU, you can either do /interface bridge add name=bridge protocol-mode=none vlan-filtering=yes /interface vlan add interface=bridge name=vlan-5 vlan-id=5 interface bridge vlan add bridge=bridge tagged=bridge vlan-ids=5 /ip address add address=192...
by tdw
Tue May 05, 2020 11:03 pm
Forum: Beginner Basics
Topic: Vlan Filtering
Replies: 8
Views: 1361

Re: Vlan Filtering

It depends on how you access traffic on VLAN5 by the CPU, you can either do /interface bridge add name=bridge protocol-mode=none vlan-filtering=yes /interface vlan add interface=bridge name=vlan-5 vlan-id=5 /ip address add address=192.168.1.1/24 interface=vlan-5 network=192.168.1.0 or /interface bri...
by tdw
Tue May 05, 2020 10:39 pm
Forum: Beginner Basics
Topic: CRS112 traffic slow issue, with negotiation?
Replies: 8
Views: 1404

Re: CRS112 traffic slow issue, with negotiation?

My understanding is that for 1G (and faster) copper links it is not only connection speed that needs to be negotiated, but also the line needs to be tested and some other TX/RX parameters then needs to be negotiated and/or tuned. That's done during the standard link negotiation procedure. You can s...
by tdw
Tue May 05, 2020 5:00 pm
Forum: General
Topic: Switch VLAN Trunks - Can't get it to work [SOLVED]
Replies: 8
Views: 1223

Re: Switch VLAN Trunks - Can't get it to work [SOLVED]

You have not included the CPU port in the switch VLAN configuration, see https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Management_access_configuration /interface ethernet switch vlan add independent-learning=yes ports=ether1,ether2 ,switch1-cpu switch=switch1 vlan-id=100 ... Be aware th...
by tdw
Mon May 04, 2020 5:12 pm
Forum: General
Topic: PPP profile ***-filter parametes
Replies: 4
Views: 1621

Re: PPP profile ***-filter parametes

The incoming/outgoing filter options have been present in RouterOS for some time, and do have limitations. The newer interface list or address list options may be more suitable - when set in a PPP profile these add the interface name or address respectively to a list which can be used as desired in ...
by tdw
Sun May 03, 2020 6:23 pm
Forum: Beginner Basics
Topic: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]
Replies: 56
Views: 6198

Re: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]

It is unusual to want to firewall at wire speed within a layer 2 network. At this level isolation is often for devices, rather than specific services on a device, and implemented with split-horizon or port isolation. ACLs will provide some of the functionality you are looking for but they operate pe...
by tdw
Sat May 02, 2020 6:14 pm
Forum: Beginner Basics
Topic: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]
Replies: 56
Views: 6198

Re: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]

Now, I can tell you that most of the traffic is accepted in the output chain and to a fraction in the input chain, but there is nothing in the forward chain. Hello! What about the forward chain? Cf. the documentation above: that's exactly the discrepancy between documentation and reality I mean!......
by tdw
Sat May 02, 2020 4:55 pm
Forum: Beginner Basics
Topic: SSTP - Certificates for users but not for Routers
Replies: 4
Views: 692

Re: SSTP - Certificates for users but not for Routers

The Mikrotik client certificates are optional, the VPN can still be secure without them, and Windows doesn't support them: Client checks it is talking to an authentic server by matching the CA which signed the server certificate, and optionally verifying the server hostname matches the certificate. ...
by tdw
Sat May 02, 2020 3:15 pm
Forum: Beginner Basics
Topic: Accidently overrode my License
Replies: 1
Views: 618

Re: Accidently overrode my License

Create an account on mikrotik.com (this is different from your forum account).
Select 'Request RouterBOARD license key', enter your device serial number and software ID to retrieve the license key data.
by tdw
Sat May 02, 2020 2:23 pm
Forum: Beginner Basics
Topic: SSTP - Certificates for users but not for Routers
Replies: 4
Views: 692

Re: SSTP - Certificates for users but not for Routers

Hopefully you are not using the SSTP without certificates for any important data as it is extremely insecure. From the Wiki "Between two Mikrotik routers it is also possible to set up an insecure tunnel by not using certificates at all. In this case data going through SSTP tunnel is using anonymous ...
by tdw
Fri May 01, 2020 4:29 pm
Forum: Beginner Basics
Topic: What is the Best Practice for detecting/preventing unauthorized devices in LAN?
Replies: 24
Views: 2695

Re: What is the Best Practice for detecting/preventing unauthorized devices in LAN?

If you do not use RADIUS built in to RouterOS v7 the usual choice is FreeRADIUS or Window NPS (integrated with newer Windows Server products). MAC auth - there are no changes to the device, but you need to record the MAC address of authorised devices. Certificate 802.1X - you need to create, distrib...
by tdw
Fri May 01, 2020 2:32 pm
Forum: Beginner Basics
Topic: What is the Best Practice for detecting/preventing unauthorized devices in LAN?
Replies: 24
Views: 2695

Re: What is the Best Practice for detecting/preventing unauthorized devices in LAN?

It depends on how hard you want to try preventing unauthorised devices and how determined someone is to bypass your blocks. A very simple method is to disable DHCP and only assign IP addresses with static leases or statically, this would require someone to either manually set an IP address and gatew...
by tdw
Thu Apr 30, 2020 1:51 pm
Forum: General
Topic: PPPoE client connected but no internet [SOLVED]
Replies: 10
Views: 1977

Re: PPPoE client connected but no internet [SOLVED]

On your first post you had: add action=masquerade chain=srcnat comment="default configuration" disabled=no out-interface=ether1-gateway \ Which obviously is wrong, your out interface is not eth1 but the PPPoE client... This wrong rule does not keep the router from having access to the Internet, but...
by tdw
Thu Apr 30, 2020 2:43 am
Forum: General
Topic: PPPoE client connected but no internet [SOLVED]
Replies: 10
Views: 1977

Re: PPPoE client connected but no internet [SOLVED]

There are still significant vulnerabilities in versions prior to v6.44.x. Having upgraded from such an old version I would strongly suggest resetting to the default configuration, disable the default WAN DHCP client, add a PPPoE client, add the PPPoE client interface to the WAN interface list - the ...
by tdw
Thu Apr 30, 2020 1:21 am
Forum: General
Topic: PPPoE client connected but no internet [SOLVED]
Replies: 10
Views: 1977

Re: PPPoE client connected but no internet [SOLVED]

750's are fine with recent RouterOS - I have one running v6.44.6 doing minor stuff, but due to the limited RAM disable packages you are not using (e.g. hotspot, ipv6, mpls, routing, wireless).

Not sure if you can upgrade directly from 4.5 to 6.x, going via 5.26 may work or use netinstall.
by tdw
Wed Apr 29, 2020 7:26 pm
Forum: Beginner Basics
Topic: Mangle doesn't mark website traffic from Layer 7 Protocol entry [SOLVED]
Replies: 9
Views: 1791

Re: Mangle doesn't mark website traffic from Layer 7 Protocol entry [SOLVED]

From the wiki "Warning: Queues (except Queue Trees parented to interfaces), firewall filter and mangle rules will not be applied for FastTracked traffic." so try disabling the fasttrack rule.
by tdw
Mon Apr 27, 2020 6:35 pm
Forum: General
Topic: FreeRadius-Mikrotik
Replies: 11
Views: 2198

Re: FreeRadius-Mikrotik

As I said in an earlier post the FreeRADIUS output seems incomplete, sending an Access-Accept outside of an EAP conversation will never work. The choice of MAC address as username is most unusual - typical setups are either EAP-PEAP-MSCHAPv2 with someuser@realm + somepassword as credentials allowing...
by tdw
Mon Apr 27, 2020 1:27 pm
Forum: Beginner Basics
Topic: Basic VLAN Setup
Replies: 22
Views: 3208

Re: Basic VLAN Setup

I removed switch1-cpu from switch vlan and everything is working as expected. I am not sure why this was the problem, switch1-cpu just gives access to CPU, needed or not i don't see why it caused a problem... Yeah, I couldn't begin to guess I don't really know this architecture. But I tested adding...
by tdw
Sun Apr 26, 2020 4:06 pm
Forum: Beginner Basics
Topic: Radius issue with username and special characters
Replies: 5
Views: 1293

Re: Radius issue with username and special characters

Please do not hijack old threads if they are not related - the original question was about support of extended ASCII characters. "@" is the network access identifier separator symbol and may be handled differently in FreeRADIUS 3.x, see https://networkradius.com/doc/current/raddb/mods-available/real...
by tdw
Sun Apr 26, 2020 2:14 pm
Forum: Beginner Basics
Topic: Basic VLAN Setup
Replies: 22
Views: 3208

Re: Basic VLAN Setup

Nothing obvious to stop communications, if you configure a VLAN directly on DEV-PC and connect it directly to FW1 without the CRS does it work? There are a few minor points but nothing affecting your immediate issue... As you are just using the CRS as a switch the default configuration 'WAN' and 'LA...
by tdw
Sun Apr 26, 2020 1:28 pm
Forum: Beginner Basics
Topic: Help checking my hEX S config for home office
Replies: 9
Views: 2282

Re: Help checking my hEX S config for home office

That changed the default configuration static DNS entry 'router.lan' address to match one of the new gateway addresses so the Mikrotik can be referenced by name, which is fine.
by tdw
Sat Apr 25, 2020 10:26 pm
Forum: Beginner Basics
Topic: Basic VLAN Setup
Replies: 22
Views: 3208

Re: Basic VLAN Setup

The wiki examples tend to be command-line, but making the equivalent changes through Winbox is fine. Note that many of the examples expect there to be no configuration present - if you try running the commands on a device with a default configuration you will likely get errors about ports already be...
by tdw
Sat Apr 25, 2020 6:34 pm
Forum: General
Topic: FreeRadius-Mikrotik
Replies: 11
Views: 2198

Re: FreeRadius-Mikrotik

Nothing obvious. You appear to have configured the RADIUS connector to handle PPP, login, hotspot & wireless - these will send requests in differing formats so your RADIUS server will have to handle them appropriately, the PPP and hotspot options appear to be redundant as there are no PPP or hostpot...
by tdw
Sat Apr 25, 2020 6:16 pm
Forum: Beginner Basics
Topic: Basic VLAN Setup
Replies: 22
Views: 3208

Re: Basic VLAN Setup

Assuming that your other firewalls are handling routing, etc. and the CRS is just being a switch then https://wiki.mikrotik.com/wiki/Manual:CRS1xx/2xx_series_switches_examples#Example_1_.28Trunk_and_Access_ports.29 for the access ports, and the incremental changes https://wiki.mikrotik.com/wiki/Manu...
by tdw
Fri Apr 24, 2020 3:51 pm
Forum: General
Topic: FreeRadius-Mikrotik
Replies: 11
Views: 2198

Re: FreeRadius-Mikrotik

Screenshots do not show enough detail, posting the output of /export hide-sensitive is a good starting point.

The FreeRADIUS output seems incomplete, there is no indication of EAP messages - sending an Access-Accept outside of the EAP handshake will fail as there is no keying information provided.
by tdw
Wed Apr 22, 2020 1:42 pm
Forum: General
Topic: RB4011: Untagged Ports Overriden by Default VID1? [SOLVED]
Replies: 13
Views: 2191

Re: RB4011: Untagged Ports Overriden by Default VID1? [SOLVED]

you can also omit /interface bridge vlan untagged entries ( untagged= ), these will be generated automatically from the /interface bridge port PVID entries ( pvid= ) If I need to change some ports PVID later, will the untagged entries follow automatically? Yes, changing the pvid= settings in /inter...
by tdw
Wed Apr 22, 2020 1:57 am
Forum: General
Topic: RB4011: Untagged Ports Overriden by Default VID1? [SOLVED]
Replies: 13
Views: 2191

Re: RB4011: Untagged Ports Overriden by Default VID1? [SOLVED]

A bridge has two roles - one like a switch between member ports, the other an interface for traffic to the CPU. You haven't included the interface-like role in the bridge VLAN configuration. If you are creating VLAN interfaces for all CPU traffic leave the PVID on the bridge itself unchanged (i.e. 1...
by tdw
Tue Apr 21, 2020 11:03 pm
Forum: General
Topic: RB4011: Untagged Ports Overriden by Default VID1? [SOLVED]
Replies: 13
Views: 2191

Re: RB4011: Untagged Ports Overriden by Default VID1? [SOLVED]

Mikrotik have not implemented hardware VLAN support for the switch chip used in the RB4011. You should be using a single VLAN-aware bridge, in which case you just have to set the PVID for the bridge port interface. Posting the output of /export hide-sensitive usually helps.
by tdw
Tue Apr 21, 2020 2:24 pm
Forum: General
Topic: 802.3ad bond running when link down
Replies: 13
Views: 2024

Re: 802.3ad bond running when link down

That is a different case to the scenario the OP describes - you are disconnecting the cables, not interrupting traffic flow. From the wiki "MII monitoring monitors only the state of the local interface .... Main disadvantage is that MII monitoring can't tell if the link can actually pass packets or ...
by tdw
Sun Apr 19, 2020 3:54 pm
Forum: Beginner Basics
Topic: UPnP doesn't work [SOLVED]
Replies: 3
Views: 1262

Re: UPnP doesn't work [SOLVED]

Your ISP may offer public IP addresses. Some do not, some do but often charge an extra fee.
by tdw
Fri Apr 17, 2020 4:01 pm
Forum: Beginner Basics
Topic: Problem with external IP [SOLVED]
Replies: 2
Views: 1150

Re: Problem with external IP [SOLVED]

Your netmask is incorrect, it should likely be 255.255.255.0 or /24 so any destination outside 192.168.1.x is reached via the gateway.
by tdw
Fri Apr 17, 2020 3:53 pm
Forum: Beginner Basics
Topic: UPnP doesn't work [SOLVED]
Replies: 3
Views: 1262

Re: UPnP doesn't work [SOLVED]

The 100.64.x.x address indicates your ISP is using CGNAT to share public IP addresses between customers. It is not possible to port forward or use UPnP with this additional layer of NAT between a public IP and your router.
by tdw
Wed Apr 15, 2020 2:02 pm
Forum: Beginner Basics
Topic: I can't login in to my Router after Setting up hotspot of default bridge.
Replies: 1
Views: 1005

Re: I can't login in to my Router after Setting up hotspot of default bridge.

When the hotspot is activated on an interface all traffic through that interface is processed by the hotspot firewall chains. Once you are authenticated to the hotspot you should be able to connect to the Mikrotik, or you can use a hotspot IP binding to bypass hotspot authentication https://wiki.mik...
by tdw
Wed Apr 15, 2020 1:51 pm
Forum: Beginner Basics
Topic: Problems with DHCP server and bridge mode
Replies: 16
Views: 2653

Re: Problems with DHCP server and bridge mode

Why do you have domain=208.67.222.220 and dns-server=8.8.8.8,208.67.222.222,8.8.4.4,0.0.0.0 in the /ip dhcp-server network configuration?
by tdw
Tue Apr 14, 2020 2:25 pm
Forum: Beginner Basics
Topic: Problems with DHCP server and bridge mode
Replies: 16
Views: 2653

Re: Problems with DHCP server and bridge mode

Those screenshots provide insufficient information, post the output of /export hide-sensitive from a terminal window.
by tdw
Tue Apr 14, 2020 2:14 pm
Forum: Beginner Basics
Topic: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]
Replies: 54
Views: 7317

Re: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]

You have removed the /interface list member entry for the PPPoE client completely, not changed it as suggested.

No idea why the DNS resolves as you describe, it could be your ISP blocking access to that site. Do other sites resolve correctly?
by tdw
Tue Apr 14, 2020 2:07 pm
Forum: Beginner Basics
Topic: Help checking my hEX S config for home office
Replies: 9
Views: 2282

Re: Help checking my hEX S config for home office

@ITDave According to the block diagram you can use the SFP and ether1 at the same time.

@hallz the output of /export hide-sensitive having executed your script would provide a better picture of what you have done
by tdw
Tue Apr 14, 2020 1:46 pm
Forum: Beginner Basics
Topic: IPv6 in address list
Replies: 1
Views: 914

Re: IPv6 in address list

Are you attempting to add an IPv6 address to an IP(v4) address list? The IPv6 configuration is completely independent from IPv4 so setting up an access control list to a service, for example, requires two address lists (IP > Firewall > Address Lists & IPv6 > Firewall > Address Lists) and correspondi...
by tdw
Mon Apr 13, 2020 4:58 pm
Forum: Beginner Basics
Topic: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]
Replies: 54
Views: 7317

Re: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]

You appear to have two PPPoE client interfaces name=pppoe-out1 and name=pppoe-outl , remove the unused one and correct the /interface list membership entry - it appears to be the wrong PPPoE client, so NAT will not work As mentioned before the /ip address is incorrectly specified on interface=ether2...
by tdw
Sun Apr 12, 2020 7:59 pm
Forum: Beginner Basics
Topic: RB2011 what to do with second switch when doing VLAN
Replies: 8
Views: 1968

Re: RB2011 what to do with second switch when doing VLAN

Yes, the 8337 supports them as detailed in the link
by tdw
Sun Apr 12, 2020 6:52 pm
Forum: Beginner Basics
Topic: RB2011 what to do with second switch when doing VLAN
Replies: 8
Views: 1968

Re: RB2011 what to do with second switch when doing VLAN

https://wiki.mikrotik.com/wiki/Manual:S ... d_Ports.29

Be aware it is not possible to have hybrid ports on the fast ethernet switch chips Mikrotik have used, including the integrated 8227 used for ether6-10 on the 2011
by tdw
Sun Apr 12, 2020 2:03 pm
Forum: Beginner Basics
Topic: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]
Replies: 54
Views: 7317

Re: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]

So the TP-Link should be handling the VLAN encapsulation: [ DSL WAN -- VLAN1885 -- TP-Link bridge ] ==== [ Mikrotik ether1 -- PPPoE client ] To implement the VLAN on the Mikrotik: [ DSL WAN -- TP-Link bridge ] ==== [ Mikrotik ether1 -- VLAN1885 -- PPPoE client ] /interface vlan add interface=ether1 ...
by tdw
Sat Apr 11, 2020 9:14 pm
Forum: Beginner Basics
Topic: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]
Replies: 54
Views: 7317

Re: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]

The LAN IP address should be set on the bridge, not one of the member interfaces (if you have not changed this it may be a bug in Quickset) /ip address add address=192.168.1.2/24 comment=defconf interface= bridge network=192.168.1.0 The DHCP client on ether1 appears to be disabled, if you wish to ac...
by tdw
Sat Apr 11, 2020 6:47 pm
Forum: Beginner Basics
Topic: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]
Replies: 54
Views: 7317

Re: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]

Cloning the TP-Link WAN ethernet address should only necessary if the PPPoE client fails to establish a connection, it sounds as though that is not the case here although it is odd that you are seeing a different IP address. Post the output of /export hide-sensitive after obfuscating public IPs, etc...
by tdw
Fri Apr 10, 2020 8:24 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS+ 802.1Q VLANs
Replies: 4
Views: 2013

Re: RB4011iGS+ 802.1Q VLANs

Atheros switch chips support an additional header in traffic between the CPU and switch chip, together with Linux driver support this allows logical etherX interfaces to be multiplexed over the single communication channel to physical ethernet interfaces using port-based VLANs - this is completely h...
by tdw
Thu Apr 09, 2020 8:45 pm
Forum: General
Topic: CCR1009 configuration
Replies: 6
Views: 1539

Re: CCR1009 configuration

I should have said smart card slot - a SIM is just a particular type of smart card.
by tdw
Thu Apr 09, 2020 8:24 pm
Forum: General
Topic: CCR1009 configuration
Replies: 6
Views: 1539

Re: CCR1009 configuration

There is both a microSD slot and a SIM slot, none of the CCR devices have miniPCIe slots. AFAIK the SIM slot was intended for secure crypto storage, although this was never finished.
by tdw
Wed Apr 08, 2020 9:53 pm
Forum: General
Topic: Hybrid Port Possible?
Replies: 2
Views: 1115

Re: Hybrid Port Possible?

Almost... /interface bridge port add bridge=bridge comment=defconf hw=no interface=ether2 pvid=100 The /interface bridge vlan settings may be incorrect, it depends on what parameters you have specified for the bridge itself under /interface bridge . Note untagged membership does not have to be expli...
by tdw
Tue Apr 07, 2020 8:55 pm
Forum: Beginner Basics
Topic: Unidentified traffic
Replies: 7
Views: 1604

Re: Unidentified traffic

What version of RouterOS are you running, are any services accessible from the internet?

It is odd for the Mikrotik to be the connection destination IP address if the traffic is outbound.
by tdw
Tue Apr 07, 2020 4:27 am
Forum: Beginner Basics
Topic: basic dual WAN configuration do not work
Replies: 10
Views: 2055

Re: basic dual WAN configuration do not work

I'm sure load balancing with dynamic gateways will have cropped up before in the forums - a script triggered by the DHCP client, or possibly using routing filters. It depends on what you need - if all traffic will be to/from ISP1, other than replies to that coming from ISP2, instead of full load bal...
by tdw
Tue Apr 07, 2020 3:10 am
Forum: Beginner Basics
Topic: basic dual WAN configuration do not work
Replies: 10
Views: 2055

Re: basic dual WAN configuration do not work

There do not appear to be any mangle rules or additional routing tables to properly support dual WAN operation. Replies to traffic arriving from either ISP1 or ISP2 will return via the best default route to ISP1 - this may have accidentally worked until the nightly engineering works correctly blocke...
by tdw
Mon Apr 06, 2020 7:34 pm
Forum: General
Topic: CRS326-24G - Dual BSD firewalls, CARP, mac address learning and host timeout issues
Replies: 12
Views: 2186

Re: CRS326-24G - Dual BSD firewalls, CARP, mac address learning and host timeout issues

VRRP transmits the shared MAC address from whichever device is currently master. I've not used CARP, but I would have expected it do the same - maybe with a configuration option if not the default.
by tdw
Mon Apr 06, 2020 4:01 pm
Forum: General
Topic: CRS326-24G - Dual BSD firewalls, CARP, mac address learning and host timeout issues
Replies: 12
Views: 2186

Re: CRS326-24G - Dual BSD firewalls, CARP, mac address learning and host timeout issues

I believe the SSH crypto comment is due to /ip ssh set allow-none-crypto=yes as a previous RouterOS upgrade erroneously added this. The switch itself will only be making ARP requests associated with its management interface. The traffic egress port will be selected by the contents of the FDB, this i...
by tdw
Sun Apr 05, 2020 4:27 pm
Forum: Beginner Basics
Topic: no WAN?
Replies: 8
Views: 1825

Re: no WAN?

That is unlikely to be the MAC address the modem sees - the bridge is 'LAN' side of the Mikrotik. Assuming the modem is connected to ether1, the command for changing the interface MAC address is /interface ethernet set [ find default-name=ether1 ] mac-address=XX:XX:XX:XX:XX:XX I suspect that after t...
by tdw
Sun Apr 05, 2020 3:56 am
Forum: General
Topic: crs3xx - bridge filter - hw offloading?
Replies: 5
Views: 1542

Re: crs3xx - bridge filter - hw offloading?

I do not have a CRS3xx to test on, but whilst hardware offloading is active I would expect /interface bridge filter only to process packets between the switch and CPU, and that to process packets between switch ports you would have to use switch ACLs /interface ethernet switch rule - see https://wik...
by tdw
Sat Apr 04, 2020 11:27 pm
Forum: Beginner Basics
Topic: Bonding multi ISP with CRS312-4C+8XG-RM?
Replies: 10
Views: 2184

Re: Bonding multi ISP with CRS312-4C+8XG-RM?

Be aware that the CRS products are intended to be L2 switches with limited L3 performance. You might achieve a few hundred Mb throughput, performance figures are here https://mikrotik.com/product/crs312_4c_ ... estresults
by tdw
Fri Apr 03, 2020 10:33 pm
Forum: Beginner Basics
Topic: no WAN?
Replies: 8
Views: 1825

Re: no WAN?

If the DHCP client were not present the PC would not have an address from the Mikrotik in either case. This is incorrect, the Mikrotik 'WAN' connection DHCP client not obtaining an address will not interfere with the 'LAN' connection DHCP server providing addresses to the attached PC. My problem is...
by tdw
Fri Apr 03, 2020 5:02 pm
Forum: Beginner Basics
Topic: Easiest VPN method for Native Windows 10 VPN?
Replies: 1
Views: 1145

Re: Easiest VPN method for Native Windows 10 VPN?

Presumably you want to use split tunnelling so not all the client traffic is via the VPN. AFAIK you can use the Windows CMAK to build a VPN connector with associated static routes.
by tdw
Wed Apr 01, 2020 2:15 pm
Forum: Beginner Basics
Topic: RoaS with CRS112 switch and HAP ac2 [SOLVED]
Replies: 8
Views: 2552

Re: RoaS with CRS112 switch and HAP ac2 [SOLVED]

That would not break anything, the non-RSTP device would ignore the BPDU packets, but a non-optimal setup. RSTP is good in larger setups for redundant paths and/or preventing storms if two edge ports are connected together, but probably unnecessary for a home setup. It does introduce a ~15 seconds f...
by tdw
Wed Apr 01, 2020 3:57 am
Forum: General
Topic: ARP Request/Reply [SOLVED]
Replies: 7
Views: 2369

Re: ARP Request/Reply [SOLVED]

Might be worth looking at the /ip dhcp-server option add-arp=yes, and local proxy-arp https://wiki.mikrotik.com/wiki/Manual:I ... _Proxy_Arp mode.
by tdw
Wed Apr 01, 2020 12:52 am
Forum: Beginner Basics
Topic: disabling Auto Negotiation on 1000M full [SOLVED]
Replies: 10
Views: 2645

Re: disabling Auto Negotiation on 1000M full [SOLVED]

It was on fiber, come to think of it, not copper.
That makes sense, there isn't an equivalent of the NWay copper link negotiation for fibre.
by tdw
Tue Mar 31, 2020 3:19 pm
Forum: Beginner Basics
Topic: disabling Auto Negotiation on 1000M full [SOLVED]
Replies: 10
Views: 2645

Re: disabling Auto Negotiation on 1000M full [SOLVED]

If true, the standard is not uniformly obeyed. In my region, CenturyLink gateway feeds are routinely supplied that run 1G and refuse negotiation, and you can't connect with them unless you configure your interface as 1G non-negotiated. Something to watch out for. If that is on a copper interface ce...
by tdw
Tue Mar 31, 2020 4:43 am
Forum: Beginner Basics
Topic: disabling Auto Negotiation on 1000M full [SOLVED]
Replies: 10
Views: 2645

Re: disabling Auto Negotiation on 1000M full [SOLVED]

With both devices, I have never gotten a successful connection to any of my various periphal devices when the routers Ethernet port is configured as a 1G link without Auto Negotiation: You will not, auto-negotiation is mandatory for 1000BASE-T. The definitive reference is IEEE standard 802.3, Secti...
by tdw
Tue Mar 31, 2020 12:35 am
Forum: Beginner Basics
Topic: Port based vlan on CSR1xx and issue with Unifi APs - broadcast SSIDs but they do not have IP addresses
Replies: 4
Views: 1542

Re: Port based vlan on CSR1xx and issue with Unifi APs - broadcast SSIDs but they do not have IP addresses

Historically UniFi only supported untagged management. I believe that tagged management support has been added, BUT this will only be for adopted and provisioned devices - the initial controller discovery and connection to the controller has to be over an untagged network.
by tdw
Mon Mar 30, 2020 4:08 pm
Forum: Beginner Basics
Topic: Anyconnect [SOLVED]
Replies: 2
Views: 1586

Re: Anyconnect [SOLVED]

It isn't possible, RouterOS only supports IPsec (native and L2TP/GRE/IPIP/EoIP tunnels), SSTP, OpenVPN (not all features), PPTP (avoid as insecure).
by tdw
Mon Mar 30, 2020 3:53 pm
Forum: Beginner Basics
Topic: Isolate home devices with VLANs
Replies: 10
Views: 2483

Re: Isolate home devices with VLANs

And here is the Dynamic Bridge config that I think can't be seen in the export above. This is the remains of the default configuration. Maybe this is the reason? I don't know if and possibly how to get rid of it.: The VLAN-aware bridge documentation indicates you have to configure the PVID in /inte...
by tdw
Sun Mar 29, 2020 9:49 pm
Forum: Beginner Basics
Topic: RoaS with CRS112 switch and HAP ac2 [SOLVED]
Replies: 8
Views: 2552

Re: RoaS with CRS112 switch and HAP ac2 [SOLVED]

No default route on the switch so it won't be able to reply to anything outside 192.168.0.0/24
/ip route
add gateway=192.168.0.1
by tdw
Sun Mar 29, 2020 6:54 pm
Forum: Beginner Basics
Topic: allow traffic from eth1 WAN to bridge
Replies: 4
Views: 1286

Re: allow traffic from eth1 WAN to bridge

When you send traffic to any address outside 192.168.1.0/24 from your laptop it is sent to the gateway address on your ISP router. Unless that router knows specifically where to send traffic destined for 192.168.0.0/24 to, it will be sent to the WAN. You need to configure a static route on the ISP r...
by tdw
Sun Mar 29, 2020 6:41 pm
Forum: Beginner Basics
Topic: RoaS with CRS112 switch and HAP ac2 [SOLVED]
Replies: 8
Views: 2552

Re: RoaS with CRS112 switch and HAP ac2 [SOLVED]

Mikrotik VLAN configuration has historically been a mess, older versions of RouterOS it did look as though many of the switch chip registers were just presented to the user to figure out. It is getting better with the CRS3xx implementation handling all the behind-the-scenes switch chip configuration...
by tdw
Sun Mar 29, 2020 4:39 am
Forum: Beginner Basics
Topic: What does it mean by USR led which is always turned off [HAP AC²]
Replies: 1
Views: 1138

Re: What does it mean by USR led which is always turned off [HAP AC²]

It can be configured to report a variety of status information or be controlled by a script https://wiki.mikrotik.com/wiki/Manual:System/LEDS
by tdw
Sun Mar 29, 2020 4:33 am
Forum: Beginner Basics
Topic: RoaS with CRS112 switch and HAP ac2 [SOLVED]
Replies: 8
Views: 2552

Re: RoaS with CRS112 switch and HAP ac2 [SOLVED]

The VLAN-aware bridge documentation indicates you have to configure the untagged membership to be the same in both /interface bridge port and /interface bridge vlan , you are missing it in the bridge port entry. In practice if you only configure it in /interface bridge port the corresponding members...
by tdw
Sun Mar 29, 2020 4:02 am
Forum: General
Topic: VLAN bridging performance
Replies: 1
Views: 923

Re: VLAN bridging performance

There will be no change in performance on a CCR1036 as it does not have a hardware switch chip.
by tdw
Sun Mar 29, 2020 12:23 am
Forum: Beginner Basics
Topic: Bridge with vlan filtering, access points not reachable [SOLVED]
Replies: 4
Views: 2138

Re: Bridge with vlan filtering, access points not reachable [SOLVED]

I did say if they are intended to be trunk rather than hybrid ports (didn't look at the link, UniFi requires management untagged) So, from your original config Remove the PVID from the bridge itself, as you access tagged VLAN69 via the vlan-69 interface. Enable ingress filtering in /interface bridge...
by tdw
Fri Mar 27, 2020 11:59 pm
Forum: Beginner Basics
Topic: Bridge with vlan filtering, access points not reachable [SOLVED]
Replies: 4
Views: 2138

Re: Bridge with vlan filtering, access points not reachable [SOLVED]

You have configured the bridge, ether7, ether22, ether23 to be both tagged (in /interface bridge vlan ) and untagged (by setting pvid=69 in /interface bridge and /interface bridge port ) which will not work. Remove the pvid= for the bridge and those three interfaces if they are intended to be trunk ...
by tdw
Thu Mar 26, 2020 4:33 am
Forum: Forwarding Protocols
Topic: Virtual IP on WAN mikrotik
Replies: 1
Views: 960

Re: Virtual IP on WAN mikrotik

The dst-nat rules only apply to traffic from WAN to your servers.

For traffic originating from your servers to WAN add specific src-nat rules BEFORE the generic one.
by tdw
Thu Mar 26, 2020 4:24 am
Forum: General
Topic: IPV6 novice question....
Replies: 7
Views: 1366

Re: IPV6 novice question....

As mentioned unless your ISP provides you with an IPv6 WAN address there is no way they will be able connect directly using IPv6, so that is the starting point. If the Mikrotik L2TP server does not support IPv6 that will be a non-starter too. If they only have IPv6 their provider will be providing s...
by tdw
Thu Mar 26, 2020 12:00 am
Forum: General
Topic: IPV6 novice question....
Replies: 7
Views: 1366

Re: IPV6 novice question....

If you want to add an IPv6 client you need to implement IPv6 on your device after enabling the package - WAN, LANs, firewall, etc. I can't remember offhand if the L2TP implementation supports IPv6 at the moment.
by tdw
Wed Mar 25, 2020 10:20 pm
Forum: General
Topic: ARP Between VPN
Replies: 5
Views: 1005

Re: ARP Between VPN

If you use a conventional IP / layer 3 VPN, you have no access to the MAC / layer 2 information at the other end. Proxy-arp allows a router to provide its own MAC address to allow communication between devices using the same subnet IP addresses but attached to differing physical networks, e.g. a loc...
by tdw
Wed Mar 25, 2020 10:07 pm
Forum: General
Topic: Homeoffice - VPN
Replies: 7
Views: 1549

Re: Homeoffice - VPN

If you only wish one computer to access your company network it would be far simpler to set up VPN connections from that one computer.
by tdw
Wed Mar 25, 2020 6:58 pm
Forum: Beginner Basics
Topic: How to set up a trunk between Miktrotik and Brocade switch and other devices with LACP trunks
Replies: 17
Views: 2844

Re: How to set up a trunk between Miktrotik and Brocade switch and other devices with LACP trunks

No that's all fine. It is odd that hw=yes but no H flag - possibly the way inactive bonding interfaces work.

The VLAN configuration all looks fine, finding out why the bonding interface is inactive is the next thing to do, what does /interface print show?
by tdw
Wed Mar 25, 2020 6:14 pm
Forum: Beginner Basics
Topic: How to set up a trunk between Miktrotik and Brocade switch and other devices with LACP trunks
Replies: 17
Views: 2844

Re: How to set up a trunk between Miktrotik and Brocade switch and other devices with LACP trunks

What is the MGMT interface, it doesn't appear in the previous config export? That aside, the bridge port print line " 3 I bond_3-4 bridge yes 1 0x80 10 10 none " shows bond3_4 is inactive, and also does not have hardware offloading which is odd as 802.3ad bonding interfaces can be hardware offloaded...
by tdw
Wed Mar 25, 2020 3:55 pm
Forum: Beginner Basics
Topic: How to set up a trunk between Miktrotik and Brocade switch and other devices with LACP trunks
Replies: 17
Views: 2844

Re: How to set up a trunk between Miktrotik and Brocade switch and other devices with LACP trunks

Hmm, the bonding interfaces do not appear to be running (no R after the index number), and only the bridge itself appearing in the bridge current tagged vlans.

What does /interface bridge vlan print detail (provides addition detail) and /interface bridge port print give?
by tdw
Wed Mar 25, 2020 2:45 pm
Forum: Beginner Basics
Topic: How to set up a trunk between Miktrotik and Brocade switch and other devices with LACP trunks
Replies: 17
Views: 2844

Re: How to set up a trunk between Miktrotik and Brocade switch and other devices with LACP trunks

Nothing obvious. What does the output of /interface bridge vlan print and /interface bonding print give?
by tdw
Wed Mar 25, 2020 2:39 pm
Forum: Beginner Basics
Topic: beginner need help pppoe connection
Replies: 2
Views: 985

Re: beginner need help pppoe connection

You have disabled TCP MSS adjustment in the PPP profile, this often breaks TCP sessions, change to /ppp profile set *0 change-tcp-mss= yes The LAN IP addresses should be applied to the bridge not a member port (in this case ether2), change to /ip address add address=10.10.10.1/24 interface= bridge n...
by tdw
Mon Mar 23, 2020 2:34 pm
Forum: Beginner Basics
Topic: One bridge for VLANs or multiple?
Replies: 16
Views: 2700

Re: One bridge for VLANs or multiple?

That sounds a bit confusing to me........ VLAN traffic inherently is already filtered at layer 2 from other vlans or subnets, (even if on the same bridge). However the router will still route between them at layer 3 and thus firewall rules are needed to stop unwanted traffic between the vlans (at l...
by tdw
Mon Mar 23, 2020 2:11 pm
Forum: Beginner Basics
Topic: VLAN setup help
Replies: 30
Views: 5678

Re: VLAN setup help

Assuming the AP is plugged into the CRS as shown in the picture, there is no /interface bridge vlan configuration for VLAN 20 on the CRS
by tdw
Mon Mar 23, 2020 1:57 pm
Forum: Beginner Basics
Topic: One bridge for VLANs or multiple?
Replies: 16
Views: 2700

Re: One bridge for VLANs or multiple?

No. An interface can only be a member of one bridge, bridges can not be members of other bridges. An old way of bridging VLANs was to create VLAN interfaces on ethernet ports, create a bridge per VLAN ID and attach the respective VLANs to bridges. This has various pitfalls, see https://wiki.mikrotik...
by tdw
Sun Mar 22, 2020 10:51 pm
Forum: Beginner Basics
Topic: How to set up a trunk between Miktrotik and Brocade switch and other devices with LACP trunks
Replies: 17
Views: 2844

Re: How to set up a trunk between Miktrotik and Brocade switch and other devices with LACP trunks

A couple of obvious errors... The IP address should be attached to the bridge, not member interfaces (in this case ether1 ) You have only configured VLAN IDs on the bridge itself, not any of the member interfaces. The wiki documentation is slightly out of date, untagged membership is configured dyna...
by tdw
Sun Mar 22, 2020 5:03 pm
Forum: Beginner Basics
Topic: How to set up a trunk between Miktrotik and Brocade switch and other devices with LACP trunks
Replies: 17
Views: 2844

Re: How to set up a trunk between Miktrotik and Brocade switch and other devices with LACP trunks

The output of /export hide-sensitive would let us see what you have currently got configured, none of the PVID or bridge VLAN settings have any effect unless vlan-filtering=yes
by tdw
Sun Mar 22, 2020 4:55 pm
Forum: Beginner Basics
Topic: how to Connect to OpenVPN using Windows 10
Replies: 1
Views: 1096

Re: how to Connect to OpenVPN using Windows 10

Windows does not support OpenVPN natively, install a client e.g. https://openvpn.net/community-downloads/

Alternatively set up the SSTP server on your Mikrotik.
by tdw
Sun Mar 22, 2020 2:01 pm
Forum: Beginner Basics
Topic: CRS Switch - what are "External" learned MAC addresses?
Replies: 10
Views: 2740

Re: CRS Switch - what are "External" learned MAC addresses?

Elsewhere the wiki states "For CRS1xx and CRS2xx series switches it is possible to use DHCP Snooping along with VLAN switching, but then you must make sure that DHCP packets are sent out with the correct VLAN tag using egress ACL rules" - my emphasis added. The rule they provided is for ingress traf...
by tdw
Sun Mar 22, 2020 3:27 am
Forum: Forwarding Protocols
Topic: Help with capacity solutions
Replies: 10
Views: 2288

Re: Help with capacity solutions

AFAIK RIPE ran out of IPv4 addresses 3-4 months ago. New members no longer get a /22 allocation, just put on the waiting list for a /24 so you may have to purchase some from elsewhere, you do get an AS number. If you changed to a different provider you would most likely loose your existing public ad...
by tdw
Sun Mar 22, 2020 2:28 am
Forum: Beginner Basics
Topic: CRS Switch - what are "External" learned MAC addresses?
Replies: 10
Views: 2740

Re: CRS Switch - what are "External" learned MAC addresses?

I was thinking of spanning tree topology changes, but that looks to be fine. What are you expecting the /interface ethernet switch acl rule to do ? My reading of those options is that any packets destined for the standard DHCP server port will be redirected to ether1 - likely including any received ...
by tdw
Sat Mar 21, 2020 10:29 pm
Forum: Beginner Basics
Topic: CRS Switch - what are "External" learned MAC addresses?
Replies: 10
Views: 2740

Re: CRS Switch - what are "External" learned MAC addresses?

What device does the flapping MAC address belong to?

You have RSTP enabled on the CRS, do you have any spanning tree configured on the Cisco devices? IIRC the default is PVST+ which doesn't necessarily play nicely with RSTP.
by tdw
Sat Mar 21, 2020 10:10 pm
Forum: Forwarding Protocols
Topic: Help with capacity solutions
Replies: 10
Views: 2288

Re: Help with capacity solutions

It depends on how your circuits are provided... If you have point-to-point circuits back to a core router in a datacentre you control then you could use ECMP, layer 2 bonding or as another has suggested MPLS and OSPF. If you have managed internet access (MIA) circuits from a provider it would be wor...
by tdw
Fri Mar 20, 2020 5:23 pm
Forum: Beginner Basics
Topic: VLAN on Switch - what functions serves the Bridge
Replies: 2
Views: 1217

Re: VLAN on Switch - what functions serves the Bridge

Hi, I own a CRS112-8P-4S-IN and configured my VLANs directly on the switch like the WIKI states. My question is: what function does the bridge (still) serve then? - Do the ports of a VLAN on the switch also need to be bridged together? Yes. A bridge has two personalities - an ethernet switch and in...
by tdw
Thu Mar 19, 2020 5:08 pm
Forum: General
Topic: [OpenVPN] static key?
Replies: 1
Views: 771

Re: [OpenVPN] static key?

You can't. The Mikrotik OpenVPN implementation does not support a number of features: UDP mode, LZO compression, authentication without username/password, TLS authentication / static keys Some examples of what is supported here https://wiki.mikrotik.com/wiki/Manual:Interface/OVPN#Application_Examples
by tdw
Thu Mar 19, 2020 2:11 pm
Forum: General
Topic: IPv6 gateway of 1234:ab:: not working any more?
Replies: 1
Views: 650

Re: IPv6 gateway of 1234:ab:: not working any more?

XXXX:XXXX:XXXX:XXXX::/64 is the Subnet-Router anycast address (RFC4291 2.6.1) so should not be configured directly on an interface. It could be that older versions of RouterOS had bugs which permitted you to use this successfully.
by tdw
Thu Mar 19, 2020 1:52 pm
Forum: General
Topic: mikrotik vlan routing between bridge and AP
Replies: 2
Views: 828

Re: mikrotik vlan routing between bridge and AP

You have multiple bridges, a mix of VLAN-aware and non-VLAN-aware configuration, a DHCP server and client on one of the LANs, various firewall rules which will have no effect. Start with https://wiki.mikrotik.com/wiki/Manual:CRS1xx/2xx_series_switches_examples#InterVLAN_Routing as a basis for your s...
by tdw
Wed Mar 18, 2020 1:56 pm
Forum: General
Topic: RESILIENT DHCP & RADIUS SOLUTION
Replies: 4
Views: 975

Re: RESILIENT DHCP & RADIUS SOLUTION

Do your RADIUS servers support pools in addition to static assignments - then they could handle the dynamic allocation and tracking If you have limited addresses then it really needs to be handled by the RADIUS servers, it doesn't really matter if they are directly assigned to a PPPoE session or by ...
by tdw
Wed Mar 18, 2020 12:50 pm
Forum: General
Topic: RESILIENT DHCP & RADIUS SOLUTION
Replies: 4
Views: 975

Re: RESILIENT DHCP & RADIUS SOLUTION

If your RADIUS servers sends Framed-IP-Address attributes that address is assigned to the client, no need for IP pools on the PPPoE servers.
by tdw
Tue Mar 17, 2020 7:35 pm
Forum: General
Topic: PPP secret and RADIUS accounting
Replies: 1
Views: 791

Re: PPP secret and RADIUS accounting

by tdw
Tue Mar 17, 2020 7:26 pm
Forum: General
Topic: Can't use vlan 1 as management vlan
Replies: 10
Views: 1974

Re: Can't use vlan 1 as management vlan

A bridge has two personalities, it is both like a switch and also an interface to the CPU. The VLAN interface should not be added as a member of the bridge - remove add bridge=bridge interface=OAM from under /interface bridge port
by tdw
Tue Mar 17, 2020 4:10 pm
Forum: General
Topic: Symbol(-1) infront of pppoe user ids
Replies: 1
Views: 824

Re: Symbol(-1) infront of pppoe user ids

If the PPPoE connection is interrupted for any reason and the client reconnects before the Mikrotik PPPoE server has removed the previous connection a suffix is added to the interface name. For example, if you have <pppoe-123456> The connection is interrupted and the client establishes a new connect...
by tdw
Sun Mar 15, 2020 2:11 pm
Forum: Beginner Basics
Topic: CRS317 Proxy Arp wont work
Replies: 2
Views: 1060

Re: CRS317 Proxy Arp wont work

Proxy-arp does not work like that. When routing IP there is no external visibility of device MAC addresses in another subnet. Using a CRS device as a router is a bad idea - they are designed to be layer2 switches with some performance-limited layer3 functionality. You could use the CRS as an aggrega...
by tdw
Fri Mar 13, 2020 2:55 pm
Forum: Forwarding Protocols
Topic: PPPOE Client Not able to access Radio Mngt IP
Replies: 2
Views: 1503

Re: PPPOE Client Not able to access Radio Mngt IP

Expected behaviour as you are using the same subnet for different networks - each PPPoE client is on their own network, completely separate from the CCR LAN network.

Either use a different set of addresses for the PPPoE clients, or enable proxy-arp on the CCR LAN network.
by tdw
Wed Mar 11, 2020 10:16 pm
Forum: General
Topic: [MT] OpenVPN Server and static route gateway issue [SOLVED]
Replies: 2
Views: 1242

Re: [MT] OpenVPN Server and static route gateway issue [SOLVED]

Create an OVPN server binding interface - this provides an unchanging name to which routes for firewall rules may be attached, you do not need to check the gateway status. Alternatively you may be able to add routes to the PPP secret which are created and bound to the dynamic interface - I haven't t...
by tdw
Sun Mar 01, 2020 8:51 pm
Forum: General
Topic: IPSEC setup, no psk? [SOLVED]
Replies: 2
Views: 1999

Re: IPSEC setup, no psk? [SOLVED]

The newer versions of RouterOS split the IPsec configuration into various sections. Previously authentication method, including PSK secret, was part of /ip ipsec peer now there is a separate /ip ipsec peer section for this information.
by tdw
Tue Feb 25, 2020 8:10 pm
Forum: Beginner Basics
Topic: OpenVPN routing
Replies: 9
Views: 2595

Re: OpenVPN routing

can t find this(
It is the Netmask field, default value is 24 - equivalent to 255.255.255.0
by tdw
Sat Feb 22, 2020 2:35 am
Forum: Beginner Basics
Topic: OpenVPN routing
Replies: 9
Views: 2595

Re: OpenVPN routing

There are various options: Use an adjacent subnet for the remote clients and adjust the netmask to cover local and remote clients. e.g. the existing 192.168. 83 .x/24 network for local clients, 192.168. 82 .x/24 for remote VPN clients with OpenVPN server netmask=23 that's interesting. but where ope...
by tdw
Thu Feb 20, 2020 7:47 pm
Forum: General
Topic: How to spcific Dintance for routes in ppp->secret
Replies: 7
Views: 1891

Re: How to spcific Dintance for routes in ppp->secret

Already tried that with 192.168.10.0/24 50

.... dynamic route distance is still 1
That syntax is incorrect. As mentioned above, and in the description of routes here https://wiki.mikrotik.com/wiki/Manual:P ... operties_2, it should be 192.168.10.0/24 0.0.0.0 50
by tdw
Thu Feb 20, 2020 4:11 pm
Forum: Beginner Basics
Topic: OpenVPN routing
Replies: 9
Views: 2595

Re: OpenVPN routing

There are various options: Per your suggestion overlap the local and remote client addresses, the OpenVPN server netmask=24 provides a suitable route, but you need to enable proxy-arp on the local network interface so the Mikrotik replies to any local client ARP requests on behalf of the remote VPN ...
by tdw
Wed Feb 19, 2020 8:27 pm
Forum: General
Topic: How to spcific Dintance for routes in ppp->secret
Replies: 7
Views: 1891

Re: How to spcific Dintance for routes in ppp->secret

What value did you use for eee.fff.ggg.hhh? It should be a specific gateway address, or 0.0.0.0 for the Mikrotik to select an appropriate one.
by tdw
Mon Feb 17, 2020 4:02 pm
Forum: Beginner Basics
Topic: VPN L2TP/IPSEC SHA256 - cannot connect from Windows client to Mikrotik Router
Replies: 1
Views: 1142

Re: VPN L2TP/IPSEC SHA256 - cannot connect from Windows client to Mikrotik Router

Windows 10 supports SHA256 for phase1 but only supports SHA1 for phase2 according to the table here https://wiki.mikrotik.com/wiki/Manual:I ... figuration
by tdw
Mon Feb 17, 2020 3:26 pm
Forum: Beginner Basics
Topic: Daisy-chaining a CRS210 behind a CRS326 VLANs not being tagged
Replies: 6
Views: 1434

Re: Daisy-chaining a CRS210 behind a CRS326 VLANs not being tagged

You can safely mix changes in Winbox and the CLI.

If you use Quickset, and subsequently make changes with either Winbox or the CLI, then you should not make further changes with Quickset.
by tdw
Mon Feb 17, 2020 2:49 pm
Forum: Beginner Basics
Topic: Daisy-chaining a CRS210 behind a CRS326 VLANs not being tagged
Replies: 6
Views: 1434

Re: Daisy-chaining a CRS210 behind a CRS326 VLANs not being tagged

If I understand the whole concept correctly, ether3 and sfp-sfpplus1 should be untagged? Those are the ports which connect directly to my PC and TV. While I can set a VLAN-ID on my network card on the PC, I can not do so on the TV. Yes, the most common setup is to present a single untagged VLAN for...
by tdw
Mon Feb 17, 2020 1:45 pm
Forum: General
Topic: Telnet Disable but someone login, is this Hacking?
Replies: 1
Views: 741

Re: Telnet Disable but someone login, is this Hacking?

Opening a terminal window from Winbox ('New Terminal' in the menu) is recorded as log in via telnet.
by tdw
Mon Feb 17, 2020 1:36 pm
Forum: Beginner Basics
Topic: Daisy-chaining a CRS210 behind a CRS326 VLANs not being tagged
Replies: 6
Views: 1434

Re: Daisy-chaining a CRS210 behind a CRS326 VLANs not being tagged

The CRS1xx/2xx switch chip configuration is not at all intuitive - /interface ethernet switch vlan specifies which VLANs are present on which ports, /interface ethernet switch ingress-vlan-translation specifies which tag to apply on untagged ingress packets, /interface ethernet switch egress-vlan-ta...
by tdw
Thu Feb 13, 2020 9:55 pm
Forum: Beginner Basics
Topic: VLAN Tagging between two CCR
Replies: 6
Views: 1647

Re: VLAN Tagging between two CCR

Bridges in older versions of RouterOS, and newer ones with vlan-filtering=no , behave similarly to an unmanaged switch - any tagged VLANs will pass freely across all ports as the VLAN ethertype is treared no differently from any other. As soon as you attach a VLAN interface to an ethernet interface,...
by tdw
Thu Feb 13, 2020 5:22 pm
Forum: Beginner Basics
Topic: VLAN Tagging between two CCR
Replies: 6
Views: 1647

Re: VLAN Tagging between two CCR

You are running an old version of RouterOS with known remote unauthenticated access vulnerabiliites, so I'd suggest upgrading to at least the latest long-term release. With newer versions of RouterOS you can also use a single VLAN-aware bridge instead of having multiple bridges to connecting the VLA...
by tdw
Thu Feb 13, 2020 1:19 pm
Forum: Beginner Basics
Topic: VLan help / ROAS
Replies: 2
Views: 1229

Re: VLan help / ROAS

Setting use-service-tag=yes for the VLAN is likely to be wrong. Unless you have a complex setup VLANs normally use the customer rather than service tag type. Without vlan-filtering=yes on the bridge (under /interface bridge ) it will act like an unmanaged switch - any tagged VLANs will pass freely a...
by tdw
Fri Feb 07, 2020 12:06 pm
Forum: General
Topic: Authenticating VPNs using RADIUS/NPS - radius timeout [SOLVED]
Replies: 4
Views: 1386

Re: Authenticating VPNs using RADIUS/NPS - radius timeout [SOLVED]

Additionally, as your AD credentials will be encrypted you cannot use CHAP authentication. Simple authentication mechanisms have the following requirements for RADIUS credentials: PAP - plaintext or encrypted CHAP - plaintext MSCHAPv2 - plaintext or MSCHAPv2 Also, don't use PPTP for VPNs as it is ve...
by tdw
Mon Feb 03, 2020 5:29 pm
Forum: Beginner Basics
Topic: I need help setting up a RouterBoard hex with a Draytek Vigor 130
Replies: 16
Views: 2158

Re: I need help setting up a RouterBoard hex with a Draytek Vigor 130

I've used Vigor 130 modems with their non-VDSL routers too, so it sounds more like a modem issue if it is not working with either a Mikrotik or Draytek Router.

I've never had to change any modem settings to get PPPoE passthrough to work. Also, which ISP as not all use PPPoE?
by tdw
Mon Feb 03, 2020 2:26 pm
Forum: Beginner Basics
Topic: I need help setting up a RouterBoard hex with a Draytek Vigor 130
Replies: 16
Views: 2158

Re: I need help setting up a RouterBoard hex with a Draytek Vigor 130

AFAIK the newer versions of RouterOS have a Quickset which supports PPPoE as a WAN address acquisition mode. It is generally a bad idea to go back to Quickset and make changes if Webfig/Winbox have been used to make any subsequent changes - it is best to reset to factory defaults, perform Quickset w...
by tdw
Sun Feb 02, 2020 7:39 pm
Forum: General
Topic: Routing public IP addresses odd behaviour [SOLVED]
Replies: 9
Views: 1344

Re: Routing public IP addresses odd behaviour [SOLVED]

The Cisco expects to be able to make an ARP request for any address from .194 to .222. As you are routing the upper half of a physical /27 subnet elsewhere ARP requests will fail, you need to enable proxy ARP on the router 1 interface connected to the Cisco. Proxy ARP is also required if you hand ou...
by tdw
Sun Feb 02, 2020 5:03 pm
Forum: Beginner Basics
Topic: VPN to private network
Replies: 2
Views: 979

Re: VPN to private network

If you use the same subnet for the local LAN and remote VPN client the Mikrotik should have proxy ARP enabled - as the remote VPN client is not directly attached to the LAN the Mikrotik has to respond on behalf of the remote client for ARP requests from any device on the local LAN. See https://wiki....
by tdw
Thu Jan 30, 2020 3:41 pm
Forum: Beginner Basics
Topic: Setup hex PoE as a switch? - With voice AND data VLAN?
Replies: 22
Views: 3047

Re: Setup hex PoE as a switch? - With voice AND data VLAN?

So I guess I'd have to add "add ports=ether1,switch1-cpu switch=switch1 independent-learning=yes vlan-id=798" ? As you already have add ports=ether1,ether2,ether3 switch=switch1 independent-learning=yes vlan-id=798 change it to add ports=ether1,ether2,ether3 ,switch1-cpu switch=switch1 independent-...
by tdw
Thu Jan 30, 2020 2:13 pm
Forum: Beginner Basics
Topic: Setup hex PoE as a switch? - With voice AND data VLAN?
Replies: 22
Views: 3047

Re: Setup hex PoE as a switch? - With voice AND data VLAN?

The PSU supplied with the RB960PGS is 24V, as historically Mikrotik have used 24V passive PoE. The device itself will work with supplies between 12 and 57V but it does not convert voltages. From the website "Ethernet ports 2-5 can power other PoE capable devices with the same voltage as applied to t...
by tdw
Thu Jan 30, 2020 3:57 am
Forum: General
Topic: RouterOS + FreeRadius + Active Directory
Replies: 1
Views: 394

Re: RouterOS + FreeRadius + Active Directory

CHAP, which is used for RADIUS Winbox authentication prior to v6.43, requires plaintext passwords stored on the server.
by tdw
Thu Jan 30, 2020 3:19 am
Forum: General
Topic: CCR + vlan trunk
Replies: 4
Views: 1509

Re: CCR + vlan trunk

You should really start a new topic rather than bumping a not particularly related seven year old thread. A bridge has two aspects - a 'switch part' which handles connections to interfaces, and an 'interface part' which passes traffic from the switch part to other CPU processes. So, to use the vlan1...
by tdw
Wed Jan 29, 2020 4:16 pm
Forum: Beginner Basics
Topic: Setup hex PoE as a switch? - With voice AND data VLAN?
Replies: 22
Views: 3047

Re: Setup hex PoE as a switch? - With voice AND data VLAN?

The first one. The interface ethernet switch ports default-vlan-id= setting is equivalent to the Cisco switchport access vlan . Mikrotiks don't have any specific voice related capabilities such as LLDP-MED and voice VLAN. You are providing the VLAN tagged on ether2-5 as hybrid ports rather than the ...
by tdw
Wed Jan 29, 2020 3:51 pm
Forum: Beginner Basics
Topic: Setup hex PoE as a switch? - With voice AND data VLAN?
Replies: 22
Views: 3047

Re: Setup hex PoE as a switch? - With voice AND data VLAN?

Under /interface ethernet switch port you should change vlan-header=always-strip to vlan-header=leave-as-is for ether2-5. From the note in https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Port_Settings QCA8337 and Atheros8327 switch chips ignore the vlan-header property and uses the defaul...
by tdw
Mon Jan 27, 2020 1:50 pm
Forum: General
Topic: RADIUS x Dot1X x DHCP [SOLVED]
Replies: 3
Views: 711

Re: RADIUS x Dot1X x DHCP [SOLVED]

There are two completely independent operations taking place - firstly the dot1x auth to permit layer 2 network access, and subsequently DHCP to obtain a layer 3 network address - this is very different from the traditional RADIUS use case where an IP address can be provided during authentication an...
by tdw
Mon Jan 27, 2020 1:09 pm
Forum: Beginner Basics
Topic: routing problem [SOLVED]
Replies: 7
Views: 1695

Re: routing problem [SOLVED]

There are some cases where perfectly legitimate traffic is flagged as invalid - often where differing interfaces are used for ingress and egress, or following triangular routes as in your case. If you follow the path of packets during a conversation from PC to radio the routing is: PC -> downstream ...
by tdw
Sun Jan 26, 2020 1:50 pm
Forum: Beginner Basics
Topic: routing problem [SOLVED]
Replies: 7
Views: 1695

Re: routing problem [SOLVED]

Do the Mikrotiks have drop forward invalid firewall rules (included in the default configuration), and if so does the packet counter increase when you try to access from downstream of site two?
by tdw
Mon Dec 30, 2019 5:26 pm
Forum: Beginner Basics
Topic: Trunking Help
Replies: 6
Views: 1239

Re: Trunking Help

If port is already a member of the bridge, e.g. by using the default configuration after reset, you can't add it again and the Wiki examples are usually fragments to apply where there is no existing configuration. You can change the settings of existing through the command line or using Winbox to ac...
by tdw
Mon Dec 30, 2019 5:20 pm
Forum: Beginner Basics
Topic: Trunking Help
Replies: 6
Views: 1239

Re: Trunking Help

VLAN handling is confusing compared with, for example, HP where you just specify if a VLAN is tagged or untagged and it sorts everything out for you. With Mikrotiks in the /interface bridge port section the pvid= parameter only specifies which VLAN ID any untagged ingress traffic is assigned to. The...
by tdw
Mon Dec 30, 2019 4:57 pm
Forum: Beginner Basics
Topic: WAN Link aggregation
Replies: 3
Views: 1096

Re: WAN Link aggregation

Bonding interfaces are software-based so can consume much CPU resource, AFAIK the only hardware-based support is CRS devices which have static (no 802.3ad / 802.1ax) link aggregation groups (certainly on 1xx/2xx, not tried on a 3xx). There doesn't appear to be much info on the Netgear, https://kb.ne...
by tdw
Mon Dec 30, 2019 3:54 pm
Forum: Beginner Basics
Topic: Trunking Help
Replies: 6
Views: 1239

Re: Trunking Help

The VLAN interfaces should not be added under bridge ports. See https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge section 11 for configuration of VLAN-aware bridges, for your setup sections 11.1, 11.2 and 11.4 are likely to be most relevant. In general post the output of /export hide-sensitive ...
by tdw
Thu Dec 12, 2019 7:54 pm
Forum: General
Topic: PPPOE and IP Pool [SOLVED]
Replies: 2
Views: 748

Re: PPPOE and IP Pool [SOLVED]

Any address in the pool may be handed out to a client - do not specify any fixed address contained in the pool as the local address in the profile. If you wish to keep the local and remote addresses in the same range you could specify the local address as xxx.xxx.xxx.1 and the pool as xxx.xxx.xxx.2-...
by tdw
Thu Nov 07, 2019 1:48 pm
Forum: General
Topic: Local VLAN access ports input router via the bridge rather than the VLAN interface [SOLVED]
Replies: 8
Views: 1315

Re: Local VLAN access ports input router via the bridge rather than the VLAN interface [SOLVED]

First thing I noticed was that switch port settings interfered with bridge port settings... It will, traffic always passes through the switch chip - to quote from a previous post: "Looking at Winbox and seeing ether1-5 interfaces you are fooled into thinking that the CPU has five ethernet interface...
by tdw
Tue Nov 05, 2019 1:36 pm
Forum: General
Topic: Local VLAN access ports input router via the bridge rather than the VLAN interface [SOLVED]
Replies: 8
Views: 1315

Re: Local VLAN access ports input router via the bridge rather than the VLAN interface [SOLVED]

It is likely you have incomplete switch configuration settings - unless vlan-mode=secure there will be leakage between VLANs. Post the output of /export hide-sensitive When using the switch chip untagged ingress traffic is tagged with the default-vlan-id , there are some exceptions between switch po...
by tdw
Sun Oct 20, 2019 1:56 pm
Forum: Beginner Basics
Topic: bridge interfaces: tagged or untagged?
Replies: 16
Views: 2193

Re: bridge interfaces: tagged or untagged?

I am not sure what is the use case of enabling use-ip-firewall-for-vlan Do you use more vlans on one bridge? I made one bridge for each vlan. This is probably why I used IP firewall for VLAN. This is my configuration: [Config cut] There is no point in having multiple VLAN-aware bridges with a singl...
by tdw
Sun Oct 20, 2019 1:47 pm
Forum: Beginner Basics
Topic: bridge interfaces: tagged or untagged?
Replies: 16
Views: 2193

Re: bridge interfaces: tagged or untagged?

I use vlans in my bridge (use-ip-firewall-for-vlan is disabled) and these are the rules to prevent vlans from talking to each other. Allows first then a drop all at the bottom. I am not sure if rule 29,32,35 are necessary. I don't think traffic within the same subnet and vlan goes through the ip fi...
by tdw
Sat Oct 19, 2019 5:23 pm
Forum: Beginner Basics
Topic: Challenges configuring /31 network.
Replies: 9
Views: 1036

Re: Challenges configuring /31 network.

Ask the provider if have they given you the correct addresses for your /31 and configured a route.

A trace from the Mikrotik will show how far packets go into their network,
by tdw
Sat Oct 19, 2019 5:17 pm
Forum: Beginner Basics
Topic: bridge interfaces: tagged or untagged?
Replies: 16
Views: 2193

Re: bridge interfaces: tagged or untagged?

IP routing knows nothing about VLANs, they are an ethernet (layer 2) construct. Your rules may have a wider scope then you expect, post the output of /export hide-sensitive after redacting any other identifying material (e.g. public addresses)
by tdw
Thu Oct 17, 2019 7:24 pm
Forum: Beginner Basics
Topic: bridge interfaces: tagged or untagged?
Replies: 16
Views: 2193

Re: bridge interfaces: tagged or untagged?

Unlike switch chips, which typically apply the PVID tag to untagged packets on ingress and remove it on egress, bridges can handle both tagged and untagged packets. The bridge settings "use IP firewall" and "use IP firewall for VLAN" are only required if you want packets travelling directly between ...
by tdw
Thu Oct 17, 2019 4:22 pm
Forum: Beginner Basics
Topic: Challenges configuring /31 network.
Replies: 9
Views: 1036

Re: Challenges configuring /31 network.

Mikrotiks don't support /31 directly, the typical workaround is to configure the interface as a point-to-point link with a /32 address at each end /ip address add address=63.24.113.29 interface=WANVLANNAME network=63.24.113.28 Unless you have disabled or removed the DHCP client in the default config...
by tdw
Wed Oct 16, 2019 2:19 pm
Forum: General
Topic: Static Routing trough Multiple VLAN
Replies: 3
Views: 491

Re: Static Routing trough Multiple VLAN

In that case the statement about not being able to route where the source and destination subnets are the same still applies, set up an EoIP tunnel between the Mikrotiks and bridge the VLAN
by tdw
Wed Oct 16, 2019 2:15 pm
Forum: Beginner Basics
Topic: EOIP tunneling and routing for Radio over IP
Replies: 14
Views: 2702

Re: EOIP tunneling and routing for Radio over IP

In the Mikrotik MPLS/VPLS example the routers are interconnected with IP running over direct ethernet connections, in your case they would be interconnected with IP running over your LTE modem connections. As each of your sites has a single WAN connection, i.e. you don't have redundant paths as in t...
by tdw
Tue Oct 15, 2019 1:41 pm
Forum: General
Topic: Static Routing trough Multiple VLAN
Replies: 3
Views: 491

Re: Static Routing trough Multiple VLAN

VLANs are generally unnecessary where there is only a single subnet present on an ethernet network. In your diagram labelling the left and right hand boxes 'LAN 18' rather than 'VLAN 18' would be more appropriate unless the diagram does not show all the detail. It is impossible to route traffic wher...
by tdw
Fri Oct 11, 2019 10:33 pm
Forum: Beginner Basics
Topic: EOIP tunneling and routing for Radio over IP
Replies: 14
Views: 2702

Re: EOIP tunneling and routing for Radio over IP

Spanning tree will not do what you want - it is designed to block redundant paths. As Mikrotik do not implement SPB (shortest path bridging) you might be able to do something with bridge split horizon, or failing that static bridge filters. Ideally being able to use IP (i.e. layer 3) instead of Ethe...
by tdw
Fri Oct 04, 2019 10:30 pm
Forum: Beginner Basics
Topic: Can't make VLANs to work with RB30011 (cant get PI addres from dhcp)
Replies: 37
Views: 5306

Re: Can't make VLANs to work with RB30011 (cant get PI addres from dhcp)

A few things: Uncheck 'Use service VLAN' in the configuration for vlan10 - it should be a regular 802.1Q VLAN rather than an 802.1ad (service) VLAN. Remove the entries under /interface ethernet switch vlan - it is possible to mix a non-VLAN aware bridge with hardware switching and VLAN filtering, bu...
by tdw
Fri Oct 04, 2019 7:12 pm
Forum: Beginner Basics
Topic: Can't make VLANs to work with RB30011 (cant get PI addres from dhcp)
Replies: 37
Views: 5306

Re: Can't make VLANs to work with RB30011 (cant get PI addres from dhcp)

The current untagged vlan10 entry is incorrect, it may be cleared by a reboot.

Note that vlan10 should not be included under Bridge>Ports, the output of /export hide-sensitive would be more useful than a selection of screenshots.
by tdw
Fri Oct 04, 2019 1:00 pm
Forum: Beginner Basics
Topic: Can't make VLANs to work with RB30011 (cant get PI addres from dhcp)
Replies: 37
Views: 5306

Re: Can't make VLANs to work with RB30011 (cant get PI addres from dhcp)

As you are using a VLAN-aware bridge: The VLAN interface created in #2 should be attached to bridge-lan NOT ether2 When setting up the DHCP server in #4 you need to create an entry under the Network tab too The bridge VLAN settings in #5 are not correct, the entry for VLAN 10 should have tagged=brid...
by tdw
Thu Sep 26, 2019 11:13 pm
Forum: Beginner Basics
Topic: How to hide a bridge?
Replies: 12
Views: 1629

Re: How to hide a bridge?

Nothing obvious jumps out, although what is /interface bridge filter add action=drop chain=input dst-port=68 in-interface=ether1 ip-protocol=udp mac-protocol=ip for? The only thing which comes to mind is that the wireless link isn't operating transparently so a device connected at the remote end has...
by tdw
Tue Sep 24, 2019 8:12 pm
Forum: Beginner Basics
Topic: How to hide a bridge?
Replies: 12
Views: 1629

Re: How to hide a bridge?

post the output of /export hide-sensitive for both devices
by tdw
Sat Sep 14, 2019 11:49 am
Forum: Beginner Basics
Topic: IPv6 not working with a static /48 prefix
Replies: 7
Views: 1112

Re: IPv6 not working with a 2a02:168:2000:9::/6static /48 prefix

I assign an address from the pool on the router wlan1 interface. The router has two global address: 2000:1111:2000:9:aaaa:bbbb:cccc:dddd on sfp1 and 2000:1111:3333::1 on wlan1 There is no mention of wlan1 in anything you have posted so far, all of the IPv6 configuration you have provided references...
by tdw
Thu Sep 12, 2019 5:13 pm
Forum: Beginner Basics
Topic: Router on a Stick
Replies: 6
Views: 1514

Re: Router on a Stick

Most likely the additional networks are not having NAT performed before heading for the 'WAN' interface, post the output of /export hide-sensitive after sanitising any public IPs, etc.
by tdw
Thu Sep 12, 2019 5:02 pm
Forum: Beginner Basics
Topic: Access port to tagged vlan [SOLVED]
Replies: 4
Views: 942

Re: Access port to tagged vlan [SOLVED]

Replace your two existing bridges (bridge & bridge_verejny) with a single VLAN-aware bridge, see https://wiki.mikrotik.com/wiki/Manual:I ... _Filtering and there are many posts on the forms too.
by tdw
Thu Sep 12, 2019 4:47 pm
Forum: Beginner Basics
Topic: IPv6 not working with a static /48 prefix
Replies: 7
Views: 1112

Re: IPv6 not working with a static /48 prefix

It is difficult to tell from a printing the state of a few items, /export hide-sensitive (in this case /ipv6 export hide-sensitive is probably sufficient) and sanitise any public IPs. That said, as your ISP is not using link-local addresses for the WAN connection you should configure the DHCP client...
by tdw
Sun Aug 25, 2019 2:23 pm
Forum: General
Topic: I have a problem with untagged VLAN (access mode) configuration on CAPsMAN
Replies: 1
Views: 423

Re: I have a problem with untagged VLAN (access mode) configuration on CAPsMAN

Without the full configurations it is difficult to see exactly what the problem is. You can't connect bridges together (this isn't strictly true, there are ways of connecting VLANs between bridges but often breaks things in mysterious ways, see https://wiki.mikrotik.com/wiki/Manual:Layer2_misconfigu...
by tdw
Mon Aug 19, 2019 10:07 pm
Forum: Beginner Basics
Topic: Remote Access from the WAN
Replies: 12
Views: 2429

Re: Remote Access from the WAN

1. Managed to update all the interface with the correct MAC address. However, the Admin MAC Address on the Bridge is still incorrect. Will it effect the network in any way if I were to disable it and allow RouterOS to pick it from the attached interfaces ? When you disable the bridge Admin MAC addr...
by tdw
Mon Aug 19, 2019 2:59 pm
Forum: General
Topic: HP 1810 weirdness with RouterOS vLANs and bridges [SOLVED]
Replies: 7
Views: 1485

Re: HP 1810 weirdness with RouterOS vLANs and bridges [SOLVED]

The HP1810G switch used by the OP didn't implement any spanning tree, but apparently violates network standards by passing BPDUs - see https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-c02597134 . I've used HP1810G v2 models which do support spanning tree correctly. The mishandling, toget...
by tdw
Mon Aug 19, 2019 3:55 am
Forum: General
Topic: VLAN setup
Replies: 8
Views: 1255

Re: VLAN setup

The IP address and DHCP server configuration is incorrect: /ip address add address=192.168.2.1/24 interface= bridge1 network=192.168.2.0 add address=10.10.10.1/24 interface=IOT network=10.10.10.0 /ip dhcp-server add add-arp=yes address-pool=dhcp disabled=no interface=bridge1 lease-time=1w name=dhcp ...
by tdw
Sun Aug 18, 2019 2:54 pm
Forum: Beginner Basics
Topic: Remote Access from the WAN
Replies: 12
Views: 2429

Re: Remote Access from the WAN

Thank you for the feedback. I believe all are very appropriate. Router 1 1. Correct, I loaded a backup from another configuration. Have 5 similar sites, same router model, same ISP and configuration, only difference is the public IP and VLAN ID. Any suggestion to remove the MAC addresses? There is ...
by tdw
Sun Aug 18, 2019 2:12 pm
Forum: General
Topic: VLAN separation using new Bridge VLAN Filtering feature
Replies: 5
Views: 947

Re: VLAN separation using new Bridge VLAN Filtering feature

Your VLANs have isolated the various apartments ethernet / layer 2 networks, however without firewall rules to prevent forwarding the CRS will be routing traffic between the subnets on those VLANs. The CRS devices are designed for switching plus the odd service function and a some routing, the CPU i...
by tdw
Sun Aug 18, 2019 1:03 pm
Forum: General
Topic: Partial VLAN configuration [SOLVED]
Replies: 9
Views: 1405

Re: Partial VLAN configuration [SOLVED]

The CCR packet sniffer shows: Untagged packets arriving on ether3-Server from 10.0.15.10 destined for 10.0.10.5 Tagged packets with VID 10 leaving on ether2-HAPac from 10.0.15.10 destined for 10.0.10.5 so the CCR is forwarding the packets as expected. The hAP packet sniffer shows: Tagged packets wit...
by tdw
Sun Aug 18, 2019 12:35 pm
Forum: Beginner Basics
Topic: Remote Access from the WAN
Replies: 12
Views: 2429

Re: Remote Access from the WAN

Router 1 A backup from a different device has been loaded in the past - this is why there are mac-address=CC:2D:E0:39:D0:xx settings present. If the original router with these addresses is connected to the same network it will cause problems. Why the socks proxy setup? The WAN interface list is inco...
by tdw
Sun Aug 18, 2019 12:35 am
Forum: Beginner Basics
Topic: Remote Access from the WAN
Replies: 12
Views: 2429

Re: Remote Access from the WAN

Ah, just had a thought - I missed On Router 2 there is no NAT . It is much easier to read configuration files than written descriptions! If there is no NAT or firewalling on Router 2 then you do not need any changes to it, only some dstnat rules on Router 1: /ip firewall nat add action=dst-nat chain...
by tdw
Sat Aug 17, 2019 9:38 pm
Forum: Beginner Basics
Topic: Remote Access from the WAN
Replies: 12
Views: 2429

Re: Remote Access from the WAN

TDW When I first read and understood your suggestion, I was pretty sure that it would work. Sadly it did not. Question:In your suggestion for Router 1, was it intentional that you did not have a setting for To Ports? If to-ports is not present a rule uses the same port(s) as given in dst-ports , yo...
by tdw
Sat Aug 17, 2019 7:28 pm
Forum: Beginner Basics
Topic: First Attempt at VLANs; Need Help!
Replies: 10
Views: 1334

Re: First Attempt at VLANs; Need Help!

Regarding DNS: Our primary server (a Synology RackStation) is running the DNS Server package and I'm planning to make it the authoritative master DNS record for our domain. What rules would I need to implement to have all devices on the network look to that unit as the DNS server, and then to force...
by tdw
Sat Aug 17, 2019 7:03 pm
Forum: Beginner Basics
Topic: First Attempt at VLANs; Need Help!
Replies: 10
Views: 1334

Re: First Attempt at VLANs; Need Help!

You haven't mentioned what WiFi system you are using, but as long as you can create multiple SSIDs and associate them with tagged VLANs they are just a counduit for the traffic from the client device to the Mikrotik. Thanks for the very helpful answer. I'm planning to spend some time working on the...
by tdw
Sat Aug 17, 2019 4:48 pm
Forum: Beginner Basics
Topic: First Attempt at VLANs; Need Help!
Replies: 10
Views: 1334

Re: First Attempt at VLANs; Need Help!

Where I'd like to get to: Data subnet, /24, for trusted devices...some wired, some Wi-fi...which should be able to access everything on the internal network plus access to Internet. Guest subnet, /25, for guest WI-fi access through a Unifi portal. Should only have access to the Internet...filtered ...
by tdw
Sat Aug 17, 2019 12:55 pm
Forum: Beginner Basics
Topic: can only get a dynamic ip on bridge interface
Replies: 10
Views: 1501

Re: can only get a dynamic ip on bridge interface

The Mikrotik LAN IP is bound to a member of the bridge rather than the bridge itself, this often breaks things in strange ways. It should be

/ip address
add address=192.168.88.1/24 interface=bridge1 network=192.168.88.0
by tdw
Sat Aug 17, 2019 1:08 am
Forum: General
Topic: Partial VLAN configuration [SOLVED]
Replies: 9
Views: 1405

Re: Partial VLAN configuration [SOLVED]

@sindy has covered points I was going to raise, a couple more: On your HP1810-8G you don't have to configure the ingress PVID, as shown under VLANs > VLAN Ports, separately - it is automatically generated from the ports set to Untagged under VLANs > Participation / Tagging. Also the HP only permits ...
by tdw
Fri Aug 16, 2019 8:27 pm
Forum: Beginner Basics
Topic: Problem with DHCP
Replies: 9
Views: 1167

Re: Problem with DHCP

Dang I know that we have a good number of unmanaged swiches in our park. So if I understand, if we have this kind of device I will have to remain with that problem unless we replce them? Yes, if you have a flat unmanaged layer 2 network you are the the mercy of whatever clients plug in. What I do n...
by tdw
Fri Aug 16, 2019 6:55 pm
Forum: Beginner Basics
Topic: No internet access
Replies: 6
Views: 1118

Re: No internet access

The LAN IP address should be attached to the bridge interface=bridge not a member port (currently set to interface=ether2)
by tdw
Fri Aug 16, 2019 6:47 pm
Forum: General
Topic: LTS vs Stable
Replies: 6
Views: 1331

Re: LTS vs Stable

As the device is so far away I'd also recommend having an identical device with a configuration as similar as possible to the remote device to test locally before deployment.

AFAIK it isn't possible to downgrade to a version earlier than the factory default.
by tdw
Fri Aug 16, 2019 4:49 pm
Forum: Beginner Basics
Topic: Problem with DHCP
Replies: 9
Views: 1167

Re: Problem with DHCP

You need to configure it on all of the switches which have the final connection to the client routers, not the central Mikrotik. Some info on the wiki https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#DHCP_Snooping_and_DHCP_Option_82 more via the search engine of your choice. If you are using s...
by tdw
Fri Aug 16, 2019 4:36 pm
Forum: Beginner Basics
Topic: Remote Access from the WAN
Replies: 12
Views: 2429

Re: Remote Access from the WAN

Create NAT rules on both routers, for example on router 1 a single rule can NAT a block of ports /ip firewall nat add action=dst-nat chain=dstnat dst-port=50021-50030 in-interface-list=WAN protocol=tcp to-addresses=192.168.255.2 And on router 2, on rule per target device /ip firewall nat add action=...
by tdw
Fri Aug 16, 2019 4:14 pm
Forum: Beginner Basics
Topic: Problem with DHCP
Replies: 9
Views: 1167

Re: Problem with DHCP

It is unlikely that DHCP on the Mikrotik stops working - it is often the case that a client router miscabled in this way will answer DHCP requests from other nearby client routers more quickly than your main router as they are closer (less network hops). On your distribution switches you can either ...
by tdw
Fri Aug 16, 2019 12:35 pm
Forum: Beginner Basics
Topic: can only get a dynamic ip on bridge interface
Replies: 10
Views: 1501

Re: can only get a dynamic ip on bridge interface

Could be any number of things. Post the output of /export hide-sensitive after also disgusing any public IPs present.
by tdw
Fri Aug 16, 2019 12:29 pm
Forum: General
Topic: DHCP server assigns .0 IP
Replies: 2
Views: 513

Re: DHCP server assigns .0 IP

There is nothing wrong with assigning .0 and .255 addresses IF they are valid for the subnet in question, i.e. not for a /24 ethernet network as they have special meaning, but fine part way through a /23 or larger. If for some reason you object to having .0 present specify multiple non-overlapping r...
by tdw
Fri Aug 16, 2019 12:11 pm
Forum: Beginner Basics
Topic: PPTP and Adsl
Replies: 3
Views: 667

Re: PPTP and Adsl

You can load-balance / load-share outgoing traffic. You have no control over incoming traffic unless you have true load-balancing hardware at the ISP providing the ADSL circuits, or your remote client also has a Mikrotik and creates five VPN connections, one to each of your public IP addresses, and ...
by tdw
Thu Aug 15, 2019 1:59 pm
Forum: General
Topic: 'ip ssh forwarding' any instance where it'll enable itself?
Replies: 1
Views: 488

Re: 'ip ssh forwarding' any instance where it'll enable itself?

Yes, it has come up a couple of times, see https://forum.mikrotik.com/viewtopic.php?f=21&t=150045&p=739992&hilit=forwarding%3Dremote#p739565 and https://forum.mikrotik.com/viewtopic.php?f=2&t=150447&p=741186&hilit=forwarding%3Dremote#p741186 Previous versions of RouterOS had SSH port forwarding enab...
by tdw
Mon Aug 12, 2019 5:29 pm
Forum: RouterBOARD hardware
Topic: Minimum fibre length between S-3553LC20D
Replies: 10
Views: 2157

Re: Minimum fibre length between S-3553LC20D

According to the datasheet https://i.mt.lv/cdn/rb_files/SFP2-131002143606.pdf attenuators are not required as the maximum RX power accepted is at least 0dBm and the TX power will be between -3 and -9dBm.

If support say attenuators are required is the datasheet incorrect?
by tdw
Fri Aug 09, 2019 2:24 pm
Forum: Beginner Basics
Topic: Remote WoL
Replies: 8
Views: 1726

Re: Remote WoL

Routing broadcast, and unicast to broadcast, has been considered to be a bad thing for many years - most network devices don't do it, some have options to allow it, or specific 'helper' functions for some protocols. I've abused the DHCP relay helper in HP routers in the past to broadcast WoL packets...
by tdw
Wed Aug 07, 2019 8:06 pm
Forum: Beginner Basics
Topic: RB750GR3 as switch
Replies: 4
Views: 736

Re: RB750GR3 as switch

Looks fine for access from the x.y.z.0/24 network, anything else will fail as there are no other routes. The bridge has spanning tree enabled, but as you can access the Mikrotik via Winbox with MAC address that doesn't appear to be an issue. Can you ping other devices on that subnet from the Mikroti...
by tdw
Wed Aug 07, 2019 5:56 pm
Forum: Beginner Basics
Topic: RB750GR3 as switch
Replies: 4
Views: 736

Re: RB750GR3 as switch

Your concept is correct, but impossible to diagnose with no information. Post the output of /export hide-sensitive, ideally in code tags (the black [] icon above the text box) to make it more readable.
by tdw
Wed Aug 07, 2019 5:01 pm
Forum: General
Topic: RB3011: Config import fail's with "failure: cannot change builtin"
Replies: 3
Views: 780

Re: RB3011: Config import fail's with "failure: cannot change builtin"

It looks like a bug - there seems little point the interface list builtins being exported to the config file if they cannot be imported or edited. For now, before uploading to the Mikrotik edit the .rsc file and remove the offending lines set [ find name=all ] comment="contains all interfaces" exclu...
by tdw
Mon Aug 05, 2019 12:09 pm
Forum: Beginner Basics
Topic: Cannot get BT (UK) with PPPoE working :(
Replies: 5
Views: 906

Re: Cannot get BT (UK) with PPPoE working :(

The firewall and NAT rules use interface lists to specify roles, and you haven't updated the WAN interface list to reflect the actual WAN interface. Add /interface list member add interface=pppoe-bt list=WAN and upgrade RouterOS to the latest long-term (currently v6.44.5) as that version has known v...
by tdw
Sun Aug 04, 2019 5:23 pm
Forum: Beginner Basics
Topic: Several VPN, several certificates
Replies: 1
Views: 544

Re: Several VPN, several certificates

Now I want to add a new VPN (site to site) by using OVPN. 1) Is it possible to have several VPN ? Yes 2) I already defined 3 certificates (ca,server,client): shall I use ca and server certificates for the second VPN or shall I define others ? The OpenVPN (and SSTP) server only allow a single server...
by tdw
Fri Aug 02, 2019 9:41 am
Forum: Beginner Basics
Topic: Access DSL modem in "bridge mode" behind Mikrotik [SOLVED]
Replies: 12
Views: 2071

Re: Access DSL modem in "bridge mode" behind Mikrotik [SOLVED]

The NAT rule appears to be incorrect, either

/ip firewall nat
add action=src-nat chain=srcnat comment="nat to modem" dst-address=172.16.2.248 out-interface=ether1 to-addresses=172.16.2.250

or
add action=masquerade chain=srcnat comment="nat to modem" dst-address=172.16.2.248 out-interface=ether1
by tdw
Tue Jul 30, 2019 5:42 pm
Forum: General
Topic: The RB4011 does not support Passive DAC modules and SFP GPON modules
Replies: 13
Views: 3346

Re: The RB4011 does not support Passive DAC modules and SFP GPON modules

Care must be taken not to compare dissimilar things. There are a range of SFF specifications, and whilst the electrical interfaces of the 18 contacts and the mechanical dimensions of cage & modules are well defined across SFPs the rate, encoding and interpretation of the data streams very much depen...
by tdw
Mon Jul 29, 2019 11:30 pm
Forum: General
Topic: Getting response from secondary IP ranges
Replies: 6
Views: 944

Re: Getting response from secondary IP ranges

A quick google revealed this https://social.technet.microsoft.com/Forums/en-US/e6408325-013c-4d0a-8130-5ce991355c08/windows-vpn-clients-ignoring-dhcp-option-121-from-rras-server?forum=winserverNIS so it looks like it used to work and then broke - you may have to dig into some Windows forums to find ...
by tdw
Mon Jul 29, 2019 8:07 pm
Forum: General
Topic: Getting response from secondary IP ranges
Replies: 6
Views: 944

Re: Getting response from secondary IP ranges

Your remote PC is likely set to not use the VPN as the default gateway, in which case you require static routes so traffic to your other internal networks are sent via the VPN tunnel, not out of the LAN gateway. Apparently the Windows VPN client will pick up additional routes from DHCP option 121 if...
by tdw
Mon Jul 29, 2019 7:45 pm
Forum: General
Topic: Unable to access router from failover WAN IP when primary WAN IP is active, and vice versa.
Replies: 2
Views: 615

Re: Unable to access router from failover WAN IP when primary WAN IP is active, and vice versa.

If you specify an outgoing interface for the ping check that should work, however it will not fix incoming traffic via the failover interface - that requires connection & route marking to return incoming traffic back out of the same interface. In many cases you can perform failover without scripting...
by tdw
Sun Jul 28, 2019 6:41 pm
Forum: General
Topic: Login failure for user Radius via api
Replies: 3
Views: 2263

Re: Login failure for user Radius via api

6.43 and 6.44 supported both old and new style API logins as RouterOS had reversibly encrypted (old as used prior to 6.43) and hashed (new as using since 6.43) passwords stored. Yes, there was an issue with allowing both style logins which was fixed before the 6.43 stable release, but as of 6.45 the...
by tdw
Mon Jul 22, 2019 2:02 pm
Forum: Beginner Basics
Topic: VLAN and VLAN Interface with DHCP CRS328 [SOLVED]
Replies: 2
Views: 709

Re: VLAN and VLAN Interface with DHCP CRS328 [SOLVED]

You do not add VLAN interfaces in /interface bridge vlan , so /interface vlan add interface=BR1 name=BLUE_VLAN vlan-id=10 is correct for creating a VLAN interface, but this /interface bridge vlan add bridge=BR1 untagged=ether1,ether2,ether3,ether4,ether5,ether6,ether7,ether8,BLUE_VLAN vlan-ids=10 to...
by tdw
Thu Jul 18, 2019 1:28 pm
Forum: General
Topic: NTP Server ... which interface?
Replies: 2
Views: 607

Re: NTP Server ... which interface?

It is an internal process so accessible on any local IP address via any IP interface, e.g. the gateway address you have set on each bridge, unless restricted by firewall rules. We usually set the NTP server & DHCP server fields to be the same as the gateway for each DHCP server network for any DHCP ...
by tdw
Thu Jul 18, 2019 2:52 am
Forum: General
Topic: VPN issue
Replies: 4
Views: 1083

Re: VPN issue

I've set up PPTP VPN on several MK routers. They all work except for one problem. I need to access the local network hosted by the MK router. Only one of the routers works right. It has to be a firewall issue, as the only major difference is the firewall settings. On the problem routers I was able ...
by tdw
Thu Jul 18, 2019 2:35 am
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 111937

Re: v6.45.1 [stable] is released!

It's enough that I've lost switching possibility for ether1 after some prior upgrade (from 6.3x.x to 6.4x).

What does /interface ethernet switch print detail show?
by tdw
Wed Jul 17, 2019 4:13 pm
Forum: Beginner Basics
Topic: VLAN Bridge Filtering ALternative
Replies: 9
Views: 1815

Re: VLAN Bridge Filtering ALternative

Sadly modern SOHO-class RB devices seem to contain crippled switch chips (RB4011 has RTL8367, RB750Gr3 has MT7621) which don't have any VLAN support what so ever. Seems like MT is trying to create some gap between RB and CRS (even low-end) devices. Which in SOHO segment is a pity (RB951G makes a wo...
by tdw
Wed Jul 17, 2019 1:53 am
Forum: General
Topic: rb750gr3 Gigabit auto negotiation [SOLVED]
Replies: 16
Views: 2889

Re: rb750gr3 Gigabit auto negotiation [SOLVED]

Look at speed=100Mbps Not sure why I can not see the correct speed when running this command, but its 1GB link Same here: /interface export /interface ethernet set [ find default-name=ether1 ] name=ether1-Wan speed=100Mbps set [ find default-name=ether2 ] name=ether2 speed=100Mbps set [ find defaul...
by tdw
Sun Jul 14, 2019 12:04 am
Forum: Announcements
Topic: v6.44.5 [long-term] is released!
Replies: 100
Views: 48571

Re: v6.44.5 [long-term] is released!

I connect to manage routers with ssh using an rsa ssh key. SSH stong-crypto is set to yes. I upgraded a remote test router from 6.43.16 long-term to 6.44.5 long-term. It allows me to make a connection using Putty as usual, the connection terminal window displays correctly. But when I try to manage ...
by tdw
Fri Jul 12, 2019 8:20 pm
Forum: Beginner Basics
Topic: ARP on bridge ?
Replies: 1
Views: 404

Re: ARP on bridge ?

The behaviour you see is correct. IP is layer 3 and ARP handles the layer 3 to layer 2 mappings, whereas the bridge is purely layer 2 and 'which MAC is on which port' is stored in the bridge hosts table.
by tdw
Wed Jul 10, 2019 4:28 am
Forum: General
Topic: SFP RB4011
Replies: 19
Views: 3027

Re: SFP RB4011

The issue is the Sync Rate and whether the module is passive or active So insofar as the RB4011 and its SFP+ port is concerned -- it only accepts Active modules that Sync at 1.25G or 10G and will not accept 2.5G for sync rate. I am assuming that Bell move to 10G will have the ability to Sync at 10G...
by tdw
Sun Jul 07, 2019 9:02 pm
Forum: General
Topic: VLAN offload issue on Atheros 8227
Replies: 2
Views: 488

Re: VLAN offload issue on Atheros 8227

In what way does it crash, or rather does it not work as you expect?

There are functional differences between some switch chips which Mikrotik use, in particular only a couple (QCA8337, Atheros8327) support hybrid ports.
by tdw
Thu Jul 04, 2019 1:35 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 111937

Re: v6.45.1 [stable] is released!

we use CRM, ISPadmin, which communicates with MKT by API, but when updating to 6.45.1 API doesnt work, because new API authentification is not implement in our CRM. It says "killing PID 25009, API number exceeds the limit", but when downgrade to 6.44.3, which worked with CRM prior and should have c...
by tdw
Thu Jul 04, 2019 1:02 am
Forum: General
Topic: Winbox to IPv6 to port 8295 - How do you do this ?
Replies: 2
Views: 466

Re: Winbox to IPv6 to port 8295 - How do you do this ?

Example what I am trying that is not working: winbox to IPv6 Mikrotik ---> [2605:4e40:0:1fe::]:8295 (this does not work)
All zeros for the host address is somewhat unusual, so may be a bug.
by tdw
Thu Jul 04, 2019 12:44 am
Forum: Beginner Basics
Topic: unifi cloud key
Replies: 2
Views: 630

Re: unifi cloud key

Not with the Mikrotik supplied 24V PSU as there are several differing incompatible PoE standards. However, it should work if you replace this with a 48V PSU as the RB4011 specification states "DC jack input Voltage 12-57 V ", and the Cloud Key specification states "48V 802.3af or Passive PoE ( Pairs...
by tdw
Tue Jul 02, 2019 1:27 pm
Forum: Beginner Basics
Topic: SFP on hEX PoE
Replies: 3
Views: 673

Re: SFP on hEX PoE

You can't add the SFP to the switch as is connected directly to the CPU, see https://i.mt.lv/cdn/rb_files/RB960PGS-161220141841.png You appear to have the SFP in the bridge and the switch VLANs configured on the CPU port ( /export hide-sensitive is generally more useful than printing settings), so i...
by tdw
Sat Jun 29, 2019 3:45 pm
Forum: General
Topic: PPPoE Session packets being broadcast?? [SOLVED]
Replies: 41
Views: 3923

Re: PPPoE Session packets being broadcast?? [SOLVED]

As you are seeing misdirected unicast from a port on your CRS the issue likely lies with the switch forwarding database therein. I had the same issue with some old Mikrotiks based on AR7240 switch chips where some client MAC addresses on different ports appeared to be hashed to the same value so onl...
by tdw
Sat Jun 29, 2019 1:08 pm
Forum: General
Topic: pppoe mikrotik with radius server and firewall [SOLVED]
Replies: 6
Views: 1123

Re: pppoe mikrotik with radius server and firewall [SOLVED]

Yes. Removing the masquerade rule leaves the source address of the PPPoE client unchanged, enabling proxy ARP allows the router to reply to ARP requests from the firewall for 192.168.10.x PPPoE client addresses so traffic may be returned.
by tdw
Fri Jun 28, 2019 8:18 pm
Forum: General
Topic: pppoe mikrotik with radius server and firewall [SOLVED]
Replies: 6
Views: 1123

Re: pppoe mikrotik with radius server and firewall [SOLVED]

OK, you appear to be statically assigning client PPPoE addresses in your RADIUS server rather than using a dynamic IP pool, the method doesn't change - enable proxy ARP on ether1 /interface ethernet set [ find default-name=ether1 ] arp=proxy-arp and disable/remove the masquerade rule. What is the 19...
by tdw
Fri Jun 28, 2019 3:19 pm
Forum: General
Topic: pppoe mikrotik with radius server and firewall [SOLVED]
Replies: 6
Views: 1123

Re: pppoe mikrotik with radius server and firewall [SOLVED]

It is difficult to say exactly as it isn't clear exactly how devices are connected (hint post the output of /export hide-sensitive and redact any public IPs, etc.). That said stop masquerading your PPPoE clients (as this replaces the PPPoE client address with 192.168.10.3 ), and as you appear to be ...
by tdw
Tue Jun 18, 2019 11:49 pm
Forum: General
Topic: VLAN for guest wifi
Replies: 11
Views: 1516

Re: VLAN for guest wifi

If the unmanaged switch connected to ether4 is only for multimedia devices on VLAN30, then change ether4 to be untagged for VLAN30 /interface bridge port ... add bridge=bridge interface=ether4 pvid=30 ... /interface bridge vlan add bridge=bridge untagged=bridge,ether2,ether3,ether5,ether6,ether7 vla...
by tdw
Mon Jun 17, 2019 11:06 pm
Forum: Beginner Basics
Topic: Explain RSTP priority and path-cost [SOLVED]
Replies: 1
Views: 715

Re: Explain RSTP priority and path-cost [SOLVED]

I looked at first example (the one involving switches SW1, SW2, SW3 and SW4 and hosts A and B) in RSTP Wiki page (see [1]). 1. I can read that SW1 settings rely on priority while SW4 rely on path-cost. Can you explain why ? Per the Wiki: In RouterOS the root bridge will be elected based on the smal...
  • 1
  • 2