Community discussions

Search found 37 matches

by tdw
Mon Jan 21, 2019 8:49 pm
Forum: Beginner Basics
Topic: Invalid DHCP server
Replies: 6
Views: 172

Re: Invalid DHCP server

You have assigned the address 192.168.1.3 to ether1 and no address to wlan1. If you want to bridge ether1 and wlan1 so they are the same layer2 network then both interfaces should be added to a bridge, the IP address and DHCP server should specify the bridge as the interface, not any of the members....
by tdw
Sat Jan 19, 2019 2:35 pm
Forum: General
Topic: Mikrotik CRS326 6.43.8 not forwarding some L2 traffic ?
Replies: 4
Views: 195

Re: Mikrotik CRS326 6.43.8 not forwarding some L2 traffic ?

All ports are in the default bridge1 bridge and there is no special configuration on those ports. That is incorrect, as you have: /interface bridge port add bridge=bridge1 interface=ether6 add bridge=bridge1 interface=ether23 add bridge=bridge1 interface=ether24 /interface bridge vlan add bridge=br...
by tdw
Tue Jan 15, 2019 11:06 pm
Forum: General
Topic: One Mikrotik, many businesses?
Replies: 2
Views: 193

Re: One Mikrotik, many businesses?

Each would need their own IP address/subnet, IP pool, DHCP network & DHCP server, plus firewall rules to prevent them communicating with each other - by default the router routes traffic between all LAN networks. Depending on the physical location of the router with respect to the offices, plus the ...
by tdw
Tue Jan 15, 2019 10:46 pm
Forum: General
Topic: Strange IP addresses forwarded to internal server
Replies: 6
Views: 352

Re: Strange IP addresses forwarded to internal server

That rule will allow any IP address to connect to your VPN server, if you expose services on well known ports they will get scanned at some point. You could create an address list, e.g. 'VPNusers' and add src-address-list=VPNusers to the rule. This will prevent access to your VPN server if the addre...
by tdw
Sat Jan 12, 2019 10:06 pm
Forum: Forwarding Protocols
Topic: 6.4x OpenVPN + OSPF trouble
Replies: 8
Views: 1171

Re: 6.4x OpenVPN + OSPF trouble

but their OpenVPN implementation is known to be rudimentary.
And insecure, the MT OpenVPN client does not check the server certificate, see https://nvd.nist.gov/vuln/detail/CVE-2018-10066 and https://janis-streib.de/post/mikrotik-ovpn-security/, which AFAIK has not been addressed
by tdw
Tue Jan 08, 2019 3:41 am
Forum: General
Topic: Synology Radius MIKROTIK Login
Replies: 3
Views: 226

Re: Synology Radius MIKROTIK Login

If you are running RouterOS <6.43 then upgrade to the latest (6.43.8) *BUT* check the release notes for things which may need configuration changes (e.g. bridge / master-port changes if upgrading from <6.41) If the RADIUS traffic is on an internal LAN you are probably OK, it isn't the sort of thing ...
by tdw
Tue Jan 08, 2019 3:36 am
Forum: General
Topic: Switch mode for PPPoE, safety
Replies: 3
Views: 246

Re: Switch mode for PPPoE, safety

If there is no IP configuration on the 2011 bridge no firewall rules required, you could exclude the interfaces for mac-telnet & mac-winbox access though. However for management access you probably do want some IP configuration - you have a few options: IP on the bridge, blocking IP on RB2011 ether1...
by tdw
Sun Jan 06, 2019 6:21 pm
Forum: General
Topic: VRRP with VLAN -> problem
Replies: 4
Views: 279

Re: VRRP with VLAN -> problem

It appears you have the wrong netmask on the VRRP interface - unlike all the other VRRP implementations I've seen Mikrotik need the VRRP address to be specfied with /32 NOT /24 (or whatever is appropriate for your LAN/VLAN), see https://wiki.mikrotik.com/wiki/Manual:Interface/VRRP#IPv4 . You then ge...
by tdw
Sun Jan 06, 2019 4:24 am
Forum: General
Topic: Synology Radius MIKROTIK Login
Replies: 3
Views: 226

Re: Synology Radius MIKROTIK Login

AD usually contains NT hash of the users password which will not work with CHAP - you need the plaintext at the server. Presumably you are running RouterOS version < 6.43 as this changed the login service authentication from CHAP to MSCHAPv2 (which should work authenticating against AD). Ensure the ...
by tdw
Thu Dec 20, 2018 1:39 pm
Forum: General
Topic: CRS109's > 6.40 and wifi+ethernet with vlans? HOW?? It WAS working in 6.40 :(
Replies: 6
Views: 314

Re: CRS109's > 6.40 and wifi+ethernet with vlans? HOW?? It WAS working in 6.40 :(

Having VLAN configuration spread across multiple menus is confusing, especially as there are two completely different sets of configuration which depends on an interface being hardware accelerated or not. I suspect the stopping working after 5 minutes is when ARP or FDB table entries age out. This, ...
by tdw
Thu Dec 20, 2018 1:56 am
Forum: General
Topic: Configuring EoFTTC (and failing massively)
Replies: 4
Views: 225

Re: Configuring EoFTTC (and failing massively)

You don't have to worry about the VLAN101 tagging - that is handled by the Openreach modem (I've used Draytek 130 modems extensively and they also handle this by default). Unlike the usual retail/business FTTC/FTTP services which use PPPoE it looks like you have a point-to-point ethernet WAN connect...
by tdw
Wed Dec 19, 2018 5:11 pm
Forum: General
Topic: PPPOE no default route for IPv6 only IPv4
Replies: 6
Views: 276

Re: PPPOE no default route for IPv6 only IPv4

Instead of using 'Add default route' in the PPPoE client interface settings you could add a static default route for IPv4 only
/ip route
add distance=1 gateway=YOUR_PPPOE_INTERFACE_NAME
by tdw
Wed Dec 19, 2018 2:50 pm
Forum: General
Topic: Configuring EoFTTC (and failing massively)
Replies: 4
Views: 225

Re: Configuring EoFTTC (and failing massively)

What information do they provide, and as it is wires-only and FTTC based what VDSL modem are you using?
by tdw
Wed Dec 19, 2018 2:45 pm
Forum: Beginner Basics
Topic: LAN and internet in the same public range /27
Replies: 10
Views: 489

Re: LAN and internet in the same public range /27

Do clients connected to the LAN port using addresses 197.xx.xx.226 - 197.xx.xx.254 have internet access? Assuming they do, the issue is that traffic from the Mikrotik itself will originate from 192.xx.xx.254, as that is assigned to the WAN port, not one of the public IP addresses. You should be able...
by tdw
Mon Dec 03, 2018 3:43 am
Forum: General
Topic: routing between multiple vlans on one bridge
Replies: 12
Views: 475

Re: routing between multiple vlans on one bridge

The bridge itself should be included in the bridge vlan declarations /interface bridge vlan add bridge=MAIN_BRIDGE tagged=MAIN_BRIDGE untagged=ether1 vlan-ids=40 add bridge=MAIN_BRIDGE tagged=MAIN_BRIDGE untagged=ether3 vlan-ids=30 add bridge=MAIN_BRIDGE tagged=MAIN_BRIDGE untagged="ether4,ether5,et...
by tdw
Sat Nov 10, 2018 6:19 pm
Forum: Beginner Basics
Topic: DHCP Server on guest network is invalid - why? [SOLVED]
Replies: 2
Views: 317

Re: DHCP Server on guest network is invalid - why? [SOLVED]

No IP address assigned to bridge-guest /ip address add address=192.168.10.1/24 interface=bridge-guest That should fix DHCP leases, guest devices might be able to perform DNS lookups as you have specified dns=192.168.0.1 rather than 192.168.10.1 for /ip dhcp-server network and the bridge filter forwa...
by tdw
Fri Nov 09, 2018 9:02 pm
Forum: General
Topic: PPPOE reconnect problem
Replies: 6
Views: 459

Re: PPPOE reconnect problem

RFC2516 says "When a PADT is received, no further PPP traffic is allowed to be sent using that session. Even normal PPP termination packets MUST NOT be sent after sending or receiving a PADT. A PPP peer SHOULD use the PPP protocol itself to bring down a PPPoE session, but the PADT MAY be used when P...
by tdw
Wed Nov 07, 2018 11:49 pm
Forum: Beginner Basics
Topic: SSTP server verify user cert
Replies: 2
Views: 220

Re: SSTP server verify user cert

Servers can request client certificates in the TLS handshake, it doesn't depend on EAP support. See https://en.wikipedia.org/wiki/Transport ... _handshake
by tdw
Mon Nov 05, 2018 7:09 pm
Forum: Beginner Basics
Topic: 1 Hotspot in subnet only support 254 ips
Replies: 2
Views: 210

Re: 1 Hotspot in subnet only support 254 ips

Use a larger subnet than the default /24 - if you change to 10.5.50.1/23 you could use 10.5.50.2-10.5.51.254 which gives you 509, or 10.5.50.1/22 you could use 10.5.50.2-10.5.53.254 which gives you 1021. I can't recall if you can set a larger subnet in the hotspot wizard, or if you need to change th...
by tdw
Mon Nov 05, 2018 7:01 pm
Forum: Beginner Basics
Topic: ARP List
Replies: 2
Views: 174

Re: ARP List

The dynamic entries are populated from ARP protocol replies - when a device wants to communicate with something on the same subnet as itself it will broadcast an ARP request, e.g. 'Who has 192.168.1.2' and if the target exists it should reply with '00:01:02:03:04:05 has 192.168.1.2', for example. Ha...
by tdw
Mon Nov 05, 2018 2:00 pm
Forum: General
Topic: Hardware based VLAN QCA8337 and new Bridge configuration
Replies: 5
Views: 363

Re: Hardware based VLAN QCA8337 and new Bridge configuration

See the second note here https://wiki.mikrotik.com/wiki/Manual:Basic_VLAN_switching#Other_devices_with_built-in_switch_chip I've not had chance to experiment with adding all the VLANs to both switch1cpu and switch2cpu (under Switch>VLAN) to see if the traffic would then, for example, take the path e...
by tdw
Sun Nov 04, 2018 8:54 pm
Forum: General
Topic: [L2TP+IPSec] Client to Client Connectivity
Replies: 99
Views: 3492

Re: [L2TP+IPSec] Client to Client Connectivity

I don't feel competent to compare security of IPsec and SSTP, but haven't found anything regarding SSTP's vulnerabilities than this . From other than security perspective, SSTP, like every other VPN which uses TCP transport, is not the best choice in environments where packet loss is an issue, but ...
by tdw
Mon Oct 29, 2018 4:51 pm
Forum: Beginner Basics
Topic: Help with tagged vlans on multiple ports
Replies: 2
Views: 235

Re: Help with tagged vlans on multiple ports

Any port can only be a member of one bridge, with firmware >= 6.41 use a single VLAN-aware bridge and define all of the required VLANs on the one bridge. Your example would become /interface bridge add name=bridge vlan-filtering=no /interface vlan add interface=bridge name=MGMT vlan-id=3524 /interfa...
by tdw
Sun Oct 28, 2018 6:09 pm
Forum: Beginner Basics
Topic: Need help understanding VLAN mode
Replies: 9
Views: 739

Re: Need help understanding VLAN mode

Presumably based on https://wiki.mikrotik.com/wiki/Manual:Basic_VLAN_switching#Other_devices_with_built-in_switch_chip And no, ether2 and ether3 are part of the same layer2 network and can communicate with each other, similarly ether4 and ether5 are another layer2 network and communicate with each o...
by tdw
Sun Oct 28, 2018 4:29 pm
Forum: General
Topic: Cant get Bonding to work properly.
Replies: 2
Views: 175

Re: Cant get Bonding to work properly.

RR is only a sensible choice when the two links are identical, basically copper or fibre connections, or you will suffer from out-of-order packet delivery. Traffic distribution for other algorithms very much depends on the hash algorithm and the traffic - if you have routed IP traffic but are using ...
by tdw
Thu Oct 25, 2018 3:25 pm
Forum: Beginner Basics
Topic: Fiber with PPPoE «logged-in Internet» to ETH1 + ETH2
Replies: 2
Views: 295

Re: Fiber with PPPoE «logged-in Internet» to ETH1 + ETH2

PPPoE uses IPCP for address assignment, not DHCP. You mention you have 5 fixed IP addresses - presumably a /29 subnet? You would connect to the ISP with some thing like: /interface pppoe-client add add-default-route=yes disabled=no interface=sfp1 name=pppoe-out password=*PASS* use-peer-dns=yes user=...
by tdw
Sun Oct 21, 2018 2:52 pm
Forum: General
Topic: Default configuration is broken?
Replies: 5
Views: 444

Re: Default configuration is broken?

I don't know if Mikrotik have removed the previous default config in favor of people using Quickset https://wiki.mikrotik.com/wiki/Manual:Quickset instead, but if they have done it should really be mentioned in the release notes
by tdw
Sun Oct 21, 2018 2:44 pm
Forum: General
Topic: Mass Managing Mikrotik
Replies: 11
Views: 1147

Re: Mass Managing Mikrotik

There is at least one commercial product, Unimus, which handles mass config management, auditing, etc. - I've not used it, but they were one of the vendors at MUM Birmingham a few weeks ago
by tdw
Thu Oct 18, 2018 5:23 pm
Forum: Beginner Basics
Topic: WAN NAT Bridge and VLAN yes/no
Replies: 14
Views: 895

Re: WAN NAT Bridge and VLAN yes/no

You only need VLANs if you wish to have multiple segregated layer2 (ethernet) networks connected to a single port. In your case your have four distinct networks on four distinct ethernet ports so your scenario is possible without VLANs. ether2 - set ip address, create ip pool for dhcp, dhcp server &...
by tdw
Thu Oct 18, 2018 2:55 pm
Forum: General
Topic: LAN RSTP bridge [SOLVED]
Replies: 7
Views: 564

Re: LAN RSTP bridge [SOLVED]

STP/RSTP/MSTP were designed to reorganise networks when links failed, not provide bandwidth sharing.If you wish to use both links at the same time see https://wiki.mikrotik.com/wiki/Manual:Interface/Bonding
by tdw
Fri Oct 12, 2018 9:25 pm
Forum: General
Topic: Bridge Vlan Help Request
Replies: 2
Views: 226

Re: Bridge Vlan Help Request

'interface bridge vlan' entries specifies egress handling, in the full config listing you seem to be missing: /interface bridge vlan add bridge=bridge tagged=bridge untagged=ether2,ether3,ether4 vlan-ids=100 some of the 'interface bridge port' parameters handle ingress - in addition to 'pvid' for th...
by tdw
Thu Oct 11, 2018 10:00 pm
Forum: General
Topic: VLAN configuration issue [SOLVED]
Replies: 12
Views: 643

Re: VLAN configuration issue [SOLVED]

Not having vlan-mode=secure (see https://wiki.mikrotik.com/wiki/Manual:S ... d_Ports.29 ) on all switch ports often has unintended side-effects, take care when enabling as a misconfiguration of port VLANs can lock you out if conning via a switch port.
by tdw
Thu Oct 04, 2018 7:50 pm
Forum: General
Topic: Mikrotik routing issue with PPPOE
Replies: 13
Views: 715

Re: Mikrotik routing issue with PPPOE

DHCP network is for IGMP - IP TV PPPoE network is for Internet access Both default routes have the same distance (1), so which one is used depends on the order in which they are seen. The distance used to be zero on DHCP/PPPoE client interfaces which technically was incorrect as distance of 0 shoul...
by tdw
Mon Oct 01, 2018 3:09 pm
Forum: Announcements
Topic: v6.42.9 [long-term] is released!
Replies: 119
Views: 20713

Re: v6.42.9 [long-term] is released!

The warning about master-port configurations being updated to the new bridge configuration should really be repeated in the release notes now this version has changed track from current/stable to bugfix/long-term - people who have been using the bugfix branch may be unaware of the change introduced ...
by tdw
Wed Aug 29, 2018 3:59 pm
Forum: Announcements
Topic: v6.40.9 [bugfix] is released!
Replies: 56
Views: 11902

Re: v6.40.9 [bugfix] is released!

As you say, ideally the switch menu VLAN configuration should be replaced by the VLAN-aware bridge so if a port has hardware offload enabled this is automatically translated into the necessary switch VLAN configuration. Meantime, it should be possible to use the switch chip with a non-VLAN aware bri...
by tdw
Sun May 06, 2018 1:27 am
Forum: Announcements
Topic: v6.42.1 [current]
Replies: 273
Views: 35471

Re: v6.42.1 [current]

Hello Folks! I have problem backing up configuration on practically all devices using ros 6.42 or bigger, just discovered it today. The message I got is: "backup,critical error creating backup file: could not read all configuration files" There is no full filesystems and other visible errors. I saw...
by tdw
Sat May 05, 2018 12:25 pm
Forum: Announcements
Topic: v6.42.1 [current]
Replies: 273
Views: 35471

Re: v6.42.1 [current]

I'm also seeing "backup,critical error creating backup file: could not read all configuration files" messages after upgrading on several devices. 2x RB750 v6.39.3 -> v6.42.1 2011UAS-2HnD v6.41.4 -> v6.42 (may also have produced the same message) -> v6.42.1 All appear to be operating fine, backup wor...