Community discussions

Search found 44 matches

by tdw
Sun Mar 17, 2019 3:19 pm
Forum: Beginner Basics
Topic: Port forwarding doesn't work [SOLVED]
Replies: 18
Views: 502

Re: Port forwarding doesn't work [SOLVED]

Looking at the assigned WAN IP address it appears your ISP is using CGNAT
1 D 100.64.68.8/32 94.229.236.4 mts-pppoe
Without a public IP no amount of tinkering with your router will allow your web server to be accessed from the internet.
by tdw
Mon Feb 25, 2019 5:59 pm
Forum: Beginner Basics
Topic: Radius issue with username and special characters
Replies: 3
Views: 354

Re: Radius issue with username and special characters

It could be in any number of places - the VPN client, the Mikrotik or the RADIUS server. Most likely a character set mapping issue, enabling debugging/logging on the Mikrotik and/or RADIUS server should display the usernames and hopefully show where it is being misinterpreted. When you say you have ...
by tdw
Wed Feb 06, 2019 2:19 pm
Forum: Beginner Basics
Topic: Subnet to Subnet marked as invalid [SOLVED]
Replies: 3
Views: 174

Re: Subnet to Subnet marked as invalid [SOLVED]

Forwarding a packet out of the interface on which it is received is considered invalid. You have to explicitly allow traffic which does this, typically for asymmetric routing as in your case, also for some multinetted and VRRP configurations as well.
by tdw
Mon Feb 04, 2019 2:12 am
Forum: General
Topic: Setting 2 MikroTik for hot-standby
Replies: 6
Views: 484

Re: Setting 2 MikroTik for hot-standby

Yes, but if you attach a server directly to a router and that router fails you have no access to that server. As your servers have multiple NICs you could connect each server to both routers, but you would have to either run a routing protocol on the servers to announce their presence to the two rou...
by tdw
Sun Feb 03, 2019 5:34 pm
Forum: General
Topic: IPv6 on second VLAN
Replies: 18
Views: 896

Re: IPv6 on second VLAN

SLAAC requires /64 as that is the size of an automatically generated address. It is possible to use smaller subnet sizes when using static addresses or DHCP, but AFAIK it is no longer recommended
by tdw
Sun Feb 03, 2019 5:26 pm
Forum: General
Topic: PPP secert Password [SOLVED]
Replies: 2
Views: 246

Re: PPP secert Password [SOLVED]

In a word, no. Some encryption algorithms (notably CHAP) require the plaintext password so PPP secrets (for servers), passwords for VPN/PPPoE clients, wireless PSKs, etc. are all stored as plain text in the configuration file. Only trusted administrators should have full access to the Mikrotik. When...
by tdw
Sat Feb 02, 2019 2:00 pm
Forum: General
Topic: Question about interface loopback + NAT
Replies: 1
Views: 229

Re: Question about interface loopback + NAT

You don't have to send the traffic through a loopback address on a Mikrotik. Create a loopback interface using a bridge, add the public IP address to the loopback interface, use a srcnat rule specifying the public IP as the to-address: /interface bridge add name=loopback protocol-mode=none /interfac...
by tdw
Mon Jan 21, 2019 8:49 pm
Forum: Beginner Basics
Topic: Invalid DHCP server [SOLVED]
Replies: 8
Views: 360

Re: Invalid DHCP server [SOLVED]

You have assigned the address 192.168.1.3 to ether1 and no address to wlan1. If you want to bridge ether1 and wlan1 so they are the same layer2 network then both interfaces should be added to a bridge, the IP address and DHCP server should specify the bridge as the interface, not any of the members....
by tdw
Sat Jan 19, 2019 2:35 pm
Forum: General
Topic: Mikrotik CRS326 6.43.8 not forwarding some L2 traffic ?
Replies: 4
Views: 292

Re: Mikrotik CRS326 6.43.8 not forwarding some L2 traffic ?

All ports are in the default bridge1 bridge and there is no special configuration on those ports. That is incorrect, as you have: /interface bridge port add bridge=bridge1 interface=ether6 add bridge=bridge1 interface=ether23 add bridge=bridge1 interface=ether24 /interface bridge vlan add bridge=br...
by tdw
Tue Jan 15, 2019 11:06 pm
Forum: General
Topic: One Mikrotik, many businesses?
Replies: 2
Views: 232

Re: One Mikrotik, many businesses?

Each would need their own IP address/subnet, IP pool, DHCP network & DHCP server, plus firewall rules to prevent them communicating with each other - by default the router routes traffic between all LAN networks. Depending on the physical location of the router with respect to the offices, plus the ...
by tdw
Tue Jan 15, 2019 10:46 pm
Forum: General
Topic: Strange IP addresses forwarded to internal server
Replies: 6
Views: 414

Re: Strange IP addresses forwarded to internal server

That rule will allow any IP address to connect to your VPN server, if you expose services on well known ports they will get scanned at some point. You could create an address list, e.g. 'VPNusers' and add src-address-list=VPNusers to the rule. This will prevent access to your VPN server if the addre...
by tdw
Sat Jan 12, 2019 10:06 pm
Forum: Forwarding Protocols
Topic: 6.4x OpenVPN + OSPF trouble
Replies: 8
Views: 1554

Re: 6.4x OpenVPN + OSPF trouble

but their OpenVPN implementation is known to be rudimentary.
And insecure, the MT OpenVPN client does not check the server certificate, see https://nvd.nist.gov/vuln/detail/CVE-2018-10066 and https://janis-streib.de/post/mikrotik-ovpn-security/, which AFAIK has not been addressed
by tdw
Tue Jan 08, 2019 3:41 am
Forum: General
Topic: Synology Radius MIKROTIK Login
Replies: 3
Views: 345

Re: Synology Radius MIKROTIK Login

If you are running RouterOS <6.43 then upgrade to the latest (6.43.8) *BUT* check the release notes for things which may need configuration changes (e.g. bridge / master-port changes if upgrading from <6.41) If the RADIUS traffic is on an internal LAN you are probably OK, it isn't the sort of thing ...
by tdw
Tue Jan 08, 2019 3:36 am
Forum: General
Topic: Switch mode for PPPoE, safety
Replies: 3
Views: 279

Re: Switch mode for PPPoE, safety

If there is no IP configuration on the 2011 bridge no firewall rules required, you could exclude the interfaces for mac-telnet & mac-winbox access though. However for management access you probably do want some IP configuration - you have a few options: IP on the bridge, blocking IP on RB2011 ether1...
by tdw
Sun Jan 06, 2019 6:21 pm
Forum: General
Topic: VRRP with VLAN -> problem
Replies: 4
Views: 315

Re: VRRP with VLAN -> problem

It appears you have the wrong netmask on the VRRP interface - unlike all the other VRRP implementations I've seen Mikrotik need the VRRP address to be specfied with /32 NOT /24 (or whatever is appropriate for your LAN/VLAN), see https://wiki.mikrotik.com/wiki/Manual:Interface/VRRP#IPv4 . You then ge...
by tdw
Sun Jan 06, 2019 4:24 am
Forum: General
Topic: Synology Radius MIKROTIK Login
Replies: 3
Views: 345

Re: Synology Radius MIKROTIK Login

AD usually contains NT hash of the users password which will not work with CHAP - you need the plaintext at the server. Presumably you are running RouterOS version < 6.43 as this changed the login service authentication from CHAP to MSCHAPv2 (which should work authenticating against AD). Ensure the ...
by tdw
Thu Dec 20, 2018 1:39 pm
Forum: General
Topic: CRS109's > 6.40 and wifi+ethernet with vlans? HOW?? It WAS working in 6.40 :(
Replies: 6
Views: 357

Re: CRS109's > 6.40 and wifi+ethernet with vlans? HOW?? It WAS working in 6.40 :(

Having VLAN configuration spread across multiple menus is confusing, especially as there are two completely different sets of configuration which depends on an interface being hardware accelerated or not. I suspect the stopping working after 5 minutes is when ARP or FDB table entries age out. This, ...
by tdw
Thu Dec 20, 2018 1:56 am
Forum: General
Topic: Configuring EoFTTC (and failing massively)
Replies: 4
Views: 265

Re: Configuring EoFTTC (and failing massively)

You don't have to worry about the VLAN101 tagging - that is handled by the Openreach modem (I've used Draytek 130 modems extensively and they also handle this by default). Unlike the usual retail/business FTTC/FTTP services which use PPPoE it looks like you have a point-to-point ethernet WAN connect...
by tdw
Wed Dec 19, 2018 5:11 pm
Forum: General
Topic: PPPOE no default route for IPv6 only IPv4
Replies: 6
Views: 323

Re: PPPOE no default route for IPv6 only IPv4

Instead of using 'Add default route' in the PPPoE client interface settings you could add a static default route for IPv4 only
/ip route
add distance=1 gateway=YOUR_PPPOE_INTERFACE_NAME
by tdw
Wed Dec 19, 2018 2:50 pm
Forum: General
Topic: Configuring EoFTTC (and failing massively)
Replies: 4
Views: 265

Re: Configuring EoFTTC (and failing massively)

What information do they provide, and as it is wires-only and FTTC based what VDSL modem are you using?
by tdw
Wed Dec 19, 2018 2:45 pm
Forum: Beginner Basics
Topic: LAN and internet in the same public range /27
Replies: 10
Views: 569

Re: LAN and internet in the same public range /27

Do clients connected to the LAN port using addresses 197.xx.xx.226 - 197.xx.xx.254 have internet access? Assuming they do, the issue is that traffic from the Mikrotik itself will originate from 192.xx.xx.254, as that is assigned to the WAN port, not one of the public IP addresses. You should be able...
by tdw
Mon Dec 03, 2018 3:43 am
Forum: General
Topic: routing between multiple vlans on one bridge
Replies: 12
Views: 619

Re: routing between multiple vlans on one bridge

The bridge itself should be included in the bridge vlan declarations /interface bridge vlan add bridge=MAIN_BRIDGE tagged=MAIN_BRIDGE untagged=ether1 vlan-ids=40 add bridge=MAIN_BRIDGE tagged=MAIN_BRIDGE untagged=ether3 vlan-ids=30 add bridge=MAIN_BRIDGE tagged=MAIN_BRIDGE untagged="ether4,ether5,et...
by tdw
Sat Nov 10, 2018 6:19 pm
Forum: Beginner Basics
Topic: DHCP Server on guest network is invalid - why? [SOLVED]
Replies: 2
Views: 500

Re: DHCP Server on guest network is invalid - why? [SOLVED]

No IP address assigned to bridge-guest /ip address add address=192.168.10.1/24 interface=bridge-guest That should fix DHCP leases, guest devices might be able to perform DNS lookups as you have specified dns=192.168.0.1 rather than 192.168.10.1 for /ip dhcp-server network and the bridge filter forwa...
by tdw
Fri Nov 09, 2018 9:02 pm
Forum: General
Topic: PPPOE reconnect problem
Replies: 6
Views: 609

Re: PPPOE reconnect problem

RFC2516 says "When a PADT is received, no further PPP traffic is allowed to be sent using that session. Even normal PPP termination packets MUST NOT be sent after sending or receiving a PADT. A PPP peer SHOULD use the PPP protocol itself to bring down a PPPoE session, but the PADT MAY be used when P...
by tdw
Wed Nov 07, 2018 11:49 pm
Forum: Beginner Basics
Topic: SSTP server verify user cert
Replies: 2
Views: 311

Re: SSTP server verify user cert

Servers can request client certificates in the TLS handshake, it doesn't depend on EAP support. See https://en.wikipedia.org/wiki/Transport ... _handshake
by tdw
Mon Nov 05, 2018 7:09 pm
Forum: Beginner Basics
Topic: 1 Hotspot in subnet only support 254 ips
Replies: 2
Views: 244

Re: 1 Hotspot in subnet only support 254 ips

Use a larger subnet than the default /24 - if you change to 10.5.50.1/23 you could use 10.5.50.2-10.5.51.254 which gives you 509, or 10.5.50.1/22 you could use 10.5.50.2-10.5.53.254 which gives you 1021. I can't recall if you can set a larger subnet in the hotspot wizard, or if you need to change th...
by tdw
Mon Nov 05, 2018 7:01 pm
Forum: Beginner Basics
Topic: ARP List
Replies: 2
Views: 205

Re: ARP List

The dynamic entries are populated from ARP protocol replies - when a device wants to communicate with something on the same subnet as itself it will broadcast an ARP request, e.g. 'Who has 192.168.1.2' and if the target exists it should reply with '00:01:02:03:04:05 has 192.168.1.2', for example. Ha...
by tdw
Mon Nov 05, 2018 2:00 pm
Forum: General
Topic: Hardware based VLAN QCA8337 and new Bridge configuration
Replies: 5
Views: 406

Re: Hardware based VLAN QCA8337 and new Bridge configuration

See the second note here https://wiki.mikrotik.com/wiki/Manual:Basic_VLAN_switching#Other_devices_with_built-in_switch_chip I've not had chance to experiment with adding all the VLANs to both switch1cpu and switch2cpu (under Switch>VLAN) to see if the traffic would then, for example, take the path e...
by tdw
Sun Nov 04, 2018 8:54 pm
Forum: General
Topic: [L2TP+IPSec] Client to Client Connectivity
Replies: 99
Views: 3955

Re: [L2TP+IPSec] Client to Client Connectivity

I don't feel competent to compare security of IPsec and SSTP, but haven't found anything regarding SSTP's vulnerabilities than this . From other than security perspective, SSTP, like every other VPN which uses TCP transport, is not the best choice in environments where packet loss is an issue, but ...
by tdw
Mon Oct 29, 2018 4:51 pm
Forum: Beginner Basics
Topic: Help with tagged vlans on multiple ports
Replies: 2
Views: 313

Re: Help with tagged vlans on multiple ports

Any port can only be a member of one bridge, with firmware >= 6.41 use a single VLAN-aware bridge and define all of the required VLANs on the one bridge. Your example would become /interface bridge add name=bridge vlan-filtering=no /interface vlan add interface=bridge name=MGMT vlan-id=3524 /interfa...
by tdw
Sun Oct 28, 2018 6:09 pm
Forum: Beginner Basics
Topic: Need help understanding VLAN mode
Replies: 9
Views: 860

Re: Need help understanding VLAN mode

Presumably based on https://wiki.mikrotik.com/wiki/Manual:Basic_VLAN_switching#Other_devices_with_built-in_switch_chip And no, ether2 and ether3 are part of the same layer2 network and can communicate with each other, similarly ether4 and ether5 are another layer2 network and communicate with each o...
by tdw
Sun Oct 28, 2018 4:29 pm
Forum: General
Topic: Cant get Bonding to work properly.
Replies: 2
Views: 198

Re: Cant get Bonding to work properly.

RR is only a sensible choice when the two links are identical, basically copper or fibre connections, or you will suffer from out-of-order packet delivery. Traffic distribution for other algorithms very much depends on the hash algorithm and the traffic - if you have routed IP traffic but are using ...
by tdw
Thu Oct 25, 2018 3:25 pm
Forum: Beginner Basics
Topic: Fiber with PPPoE «logged-in Internet» to ETH1 + ETH2
Replies: 2
Views: 333

Re: Fiber with PPPoE «logged-in Internet» to ETH1 + ETH2

PPPoE uses IPCP for address assignment, not DHCP. You mention you have 5 fixed IP addresses - presumably a /29 subnet? You would connect to the ISP with some thing like: /interface pppoe-client add add-default-route=yes disabled=no interface=sfp1 name=pppoe-out password=*PASS* use-peer-dns=yes user=...
by tdw
Sun Oct 21, 2018 2:52 pm
Forum: General
Topic: Default configuration is broken?
Replies: 5
Views: 537

Re: Default configuration is broken?

I don't know if Mikrotik have removed the previous default config in favor of people using Quickset https://wiki.mikrotik.com/wiki/Manual:Quickset instead, but if they have done it should really be mentioned in the release notes
by tdw
Sun Oct 21, 2018 2:44 pm
Forum: General
Topic: Mass Managing Mikrotik
Replies: 11
Views: 1286

Re: Mass Managing Mikrotik

There is at least one commercial product, Unimus, which handles mass config management, auditing, etc. - I've not used it, but they were one of the vendors at MUM Birmingham a few weeks ago
by tdw
Thu Oct 18, 2018 5:23 pm
Forum: Beginner Basics
Topic: WAN NAT Bridge and VLAN yes/no
Replies: 14
Views: 1222

Re: WAN NAT Bridge and VLAN yes/no

You only need VLANs if you wish to have multiple segregated layer2 (ethernet) networks connected to a single port. In your case your have four distinct networks on four distinct ethernet ports so your scenario is possible without VLANs. ether2 - set ip address, create ip pool for dhcp, dhcp server &...
by tdw
Thu Oct 18, 2018 2:55 pm
Forum: General
Topic: LAN RSTP bridge [SOLVED]
Replies: 7
Views: 656

Re: LAN RSTP bridge [SOLVED]

STP/RSTP/MSTP were designed to reorganise networks when links failed, not provide bandwidth sharing.If you wish to use both links at the same time see https://wiki.mikrotik.com/wiki/Manual:Interface/Bonding
by tdw
Fri Oct 12, 2018 9:25 pm
Forum: General
Topic: Bridge Vlan Help Request
Replies: 2
Views: 254

Re: Bridge Vlan Help Request

'interface bridge vlan' entries specifies egress handling, in the full config listing you seem to be missing: /interface bridge vlan add bridge=bridge tagged=bridge untagged=ether2,ether3,ether4 vlan-ids=100 some of the 'interface bridge port' parameters handle ingress - in addition to 'pvid' for th...
by tdw
Thu Oct 11, 2018 10:00 pm
Forum: General
Topic: VLAN configuration issue [SOLVED]
Replies: 12
Views: 720

Re: VLAN configuration issue [SOLVED]

Not having vlan-mode=secure (see https://wiki.mikrotik.com/wiki/Manual:S ... d_Ports.29 ) on all switch ports often has unintended side-effects, take care when enabling as a misconfiguration of port VLANs can lock you out if conning via a switch port.
by tdw
Thu Oct 04, 2018 7:50 pm
Forum: General
Topic: Mikrotik routing issue with PPPOE
Replies: 13
Views: 772

Re: Mikrotik routing issue with PPPOE

DHCP network is for IGMP - IP TV PPPoE network is for Internet access Both default routes have the same distance (1), so which one is used depends on the order in which they are seen. The distance used to be zero on DHCP/PPPoE client interfaces which technically was incorrect as distance of 0 shoul...
by tdw
Mon Oct 01, 2018 3:09 pm
Forum: Announcements
Topic: v6.42.9 [long-term] is released!
Replies: 119
Views: 22681

Re: v6.42.9 [long-term] is released!

The warning about master-port configurations being updated to the new bridge configuration should really be repeated in the release notes now this version has changed track from current/stable to bugfix/long-term - people who have been using the bugfix branch may be unaware of the change introduced ...
by tdw
Wed Aug 29, 2018 3:59 pm
Forum: Announcements
Topic: v6.40.9 [bugfix] is released!
Replies: 56
Views: 12880

Re: v6.40.9 [bugfix] is released!

As you say, ideally the switch menu VLAN configuration should be replaced by the VLAN-aware bridge so if a port has hardware offload enabled this is automatically translated into the necessary switch VLAN configuration. Meantime, it should be possible to use the switch chip with a non-VLAN aware bri...
by tdw
Sun May 06, 2018 1:27 am
Forum: Announcements
Topic: v6.42.1 [current]
Replies: 273
Views: 38422

Re: v6.42.1 [current]

Hello Folks! I have problem backing up configuration on practically all devices using ros 6.42 or bigger, just discovered it today. The message I got is: "backup,critical error creating backup file: could not read all configuration files" There is no full filesystems and other visible errors. I saw...
by tdw
Sat May 05, 2018 12:25 pm
Forum: Announcements
Topic: v6.42.1 [current]
Replies: 273
Views: 38422

Re: v6.42.1 [current]

I'm also seeing "backup,critical error creating backup file: could not read all configuration files" messages after upgrading on several devices. 2x RB750 v6.39.3 -> v6.42.1 2011UAS-2HnD v6.41.4 -> v6.42 (may also have produced the same message) -> v6.42.1 All appear to be operating fine, backup wor...