Community discussions

MikroTik App

Search found 713 matches

by tdw
Wed Mar 03, 2021 2:40 pm
Forum: Beginner Basics
Topic: CCR2004 Beginner inter-VLAN Routing and upstream LAN questions
Replies: 14
Views: 649

Re: CCR2004 Beginner inter-VLAN Routing and upstream LAN questions

Not good. /ip address and /interface vlan objects should not be attached to interfaces which are a member of a bridge, but the bridge itself. What interface is MGMT - there is nothing which creates an interface with this name, or renames an existing interface to this. You have two default routes wit...
by tdw
Tue Mar 02, 2021 8:18 pm
Forum: General
Topic: Firmware 6.48.1 with Gigaset VoIP
Replies: 3
Views: 222

Re: Firmware 6.48.1 with Gigaset VoIP

by tdw
Tue Mar 02, 2021 7:24 pm
Forum: Beginner Basics
Topic: CCR2004 Beginner inter-VLAN Routing and upstream LAN questions
Replies: 14
Views: 649

Re: CCR2004 Beginner inter-VLAN Routing and upstream LAN questions

You cannot route VLANs - they are ethernet / layer2, IP routing is layer 3.

Attaching an /ip address to an /interface vlan on an interface (or bridge containing one more more interfaces) will automatically create static routes for those address subnets.
by tdw
Mon Mar 01, 2021 8:22 pm
Forum: General
Topic: CRS317-1G-16S+ High CPU lead to drop packet
Replies: 12
Views: 618

Re: CRS317-1G-16S+ High CPU lead to drop packet

Also the OP only provided CPU ustilisation for one core. AFAIK not all processes utilise multiple CPU cores well.
by tdw
Mon Mar 01, 2021 2:11 pm
Forum: General
Topic: Winbox to remote router over L2TP/IPsec [SOLVED]
Replies: 12
Views: 454

Re: Winbox to remote router over L2TP/IPsec [SOLVED]

Just as an aside, the rule add action=accept chain=input comment="accept L2TP" dst-port=1701 protocol=udp also permits access to the L2TP server for traffic which is not encapsulated with IPsec. Whilst the L2TP server should reject these if use-ipsec=require is specified, you can definitiv...
by tdw
Mon Mar 01, 2021 1:49 pm
Forum: General
Topic: CRS317-1G-16S+ High CPU lead to drop packet
Replies: 12
Views: 618

Re: CRS317-1G-16S+ High CPU lead to drop packet

CRS devices are intended to be L2 switches with some L3 functionality, such as providing DHCP, but NOT wire-speed L3 routing/firewalling as they performance-limited by the CPU. If you use CAPsMAN manager forwarding it imposes a significant CPU load on the CAPsMAN controller, so with a CRS as the con...
by tdw
Sun Feb 28, 2021 2:49 am
Forum: Beginner Basics
Topic: Bridge VLANs on RB4011iGS+RM
Replies: 6
Views: 403

Re: Bridge VLANs on RB4011iGS+RM

I got confused by the fact that you can add multiple VLAN IDs under one entry. It makes much more sense now. You can, and it is fine if you have a large collection of the same VLANs on several tagged interfaces. However, if you wish to have differing sets of VLANs on the interfaces you should creat...
by tdw
Sat Feb 27, 2021 3:02 am
Forum: Beginner Basics
Topic: Bridge VLANs on RB4011iGS+RM
Replies: 6
Views: 403

Re: Bridge VLANs on RB4011iGS+RM

- Once I enable Bridge VLAN filtering, the IP address set on the bridge is ignored? So far it seems like it is, but it's not marked as invalid in /ip address The implicit bridge-to-CPU port can be configured as an access, trunk or hybrid port, just as with any other bridge ports. An IP address on t...
by tdw
Fri Feb 26, 2021 6:50 pm
Forum: Beginner Basics
Topic: Simple setup as AP - ping from LAN fails
Replies: 2
Views: 130

Re: Simple setup as AP - ping from LAN fails

Change the hAP IP address to be in the subnet provided by the router (so 192.168.1.x, not the Mikrotik default of 192.168.88.x)
by tdw
Fri Feb 26, 2021 3:53 pm
Forum: Beginner Basics
Topic: PC can not reach internet, router can.
Replies: 9
Views: 549

Re: PC can not reach internet, router can.

So the linux VM can successfully ping 192.168.1.1?

What has the address 192.168.1.5 - if it is the linux VM have you configured a default route?
by tdw
Thu Feb 25, 2021 11:52 pm
Forum: Beginner Basics
Topic: VLAN & Trunk on CRS354 & other questions
Replies: 4
Views: 271

Re: VLAN & Trunk on CRS354 & other questions

Well, when I do a 'remove' command in /int bri port mode and delete 0,1,2 which are respectively interfaces mgt,eth1,eth2. Now eth3,4,5... start and 0,1,2 its very frustrating. I'd rather always look for the same numbers eg. MGT = 49 not 0... Basically the physical definitions don't change, but the...
by tdw
Thu Feb 25, 2021 9:50 pm
Forum: Beginner Basics
Topic: VLAN & Trunk on CRS354 & other questions
Replies: 4
Views: 271

Re: VLAN & Trunk on CRS354 & other questions

-Under "/interface bridge vlan" do I really have to list all 40 ports as untaged? [vice-versa, do I really need to list every tagged port for every untaged port?] No. The untagged membership will be dynamically generated from the pvid= settings under /interface bridge port -Why do the int...
by tdw
Thu Feb 25, 2021 4:15 pm
Forum: General
Topic: Simple HE 6to4 tunnel can Tx but not Rx
Replies: 4
Views: 226

Re: Simple HE 6to4 tunnel can Tx but not Rx

I use HE based on the example configuration without any issues, currently on 6.47.9 (long-term). I don't have any specific input firewall rules for the IPv4 encapsulated tunnel packets - the input chain established,related rule permits inbound tunnel traffic once outbound traffic has established a c...
by tdw
Thu Feb 25, 2021 2:28 pm
Forum: Beginner Basics
Topic: Simple VLAN fails....
Replies: 8
Views: 428

Re: Simple VLAN fails....

I thought Vlan 1 is the VLAn for all untagged packages? Untagged traffic by its very nature has no VLAN ID. Many vendors use a default of adding VLAN ID 1 tags to untagged traffic on ingress and removing them on egress if their device does not support untagged packets internally. The switch chip in...
by tdw
Wed Feb 24, 2021 7:10 pm
Forum: Beginner Basics
Topic: Bridge VLANs on RB4011iGS+RM
Replies: 6
Views: 403

Re: Bridge VLANs on RB4011iGS+RM

The guide mentioned by @anav and the wiki/help pages are a good start, in general random blogs/videos found on the web tend to use obsolete methods, less than optimal, or wrong. - A physical interface (ether10 in my case) cannot be added to multiple bridges. Is the best practice to create one big br...
by tdw
Wed Feb 24, 2021 5:56 pm
Forum: Beginner Basics
Topic: Simple VLAN fails....
Replies: 8
Views: 428

Re: Simple VLAN fails....

Setting the PVID under /interface bridge port is only applicable to bridges with vlan-filtering=yes . Mikrotik have only fully combined bridge VLAN filtering with hardware offload configuration on CRS3xx devices. On all others to achieve wire-speed switching you must use a bridge with vlan-filtering...
by tdw
Wed Feb 24, 2021 5:17 pm
Forum: Beginner Basics
Topic: Simple VLAN fails....
Replies: 8
Views: 428

Re: Simple VLAN fails....

Do not create another bridge, if all ports are already in the bridge created by the default configuration all you have to do is add the /ethernet interface switch settings. For VLAN 1337 tagged on SFP1 and untagged on SFP2 this would be /interface ethernet switch ingress-vlan-translation add ports=s...
by tdw
Wed Feb 24, 2021 2:30 pm
Forum: General
Topic: Dot1x PEAP rejected: no key for certificate found
Replies: 2
Views: 132

Re: Dot1x PEAP rejected: no key for certificate found

The dot1x certificate= setting is to specify a client certificate for the eap-tls method, it should not be set to the CA certificate.

"certificate not yet valid" points to the time and date on the Mikrotik being set to before the CA certificate start date.
by tdw
Mon Feb 22, 2021 4:43 pm
Forum: Beginner Basics
Topic: Simple VLAN fails....
Replies: 8
Views: 428

Re: Simple VLAN fails....

Use a single bridge, then on CRS1xx/2xx devices configure the switch chip so you have wire-speed connections between ports. The switch menu doesn't hide any of the huge number of switch registers which may be configured for different scenarios, however there are some basic examples here https://wiki...
by tdw
Mon Feb 22, 2021 4:36 pm
Forum: General
Topic: IP > Service > winbox/www - Not Able to Use DNS?
Replies: 3
Views: 222

Re: IP > Service > winbox/www - Not Able to Use DNS?

It is not trivial to use DNS entries for this (or src-address / dst-address in firewall rules) as you can't wait until DNS resolution has completed before continuing to process packets. However, it is possible to use address lists with firewall rules ( src-address-list / dst-address-list ) which wil...
by tdw
Mon Feb 22, 2021 3:17 pm
Forum: General
Topic: Problem with L2/L3 Tunnel VLAN
Replies: 14
Views: 736

Re: Problem with L2/L3 Tunnel VLAN

There is some redundant configuration from bridges and interfaces being deleted which should be cleaned up: /interface bridge port .... add disabled=yes interface=ether3 add disabled=yes interface=ether12 add bridge="bridge L2 PtoP_" disabled=yes interface=*21 /ip firewall filter add actio...
by tdw
Sun Feb 21, 2021 5:25 pm
Forum: General
Topic: No DNS for PPP-clients
Replies: 1
Views: 115

Re: No DNS for PPP-clients

AFAIK there isn't. At some point a 'No DNS' option was added to the DHCP server to prevent DNS being offered to DHCP clients, it would be nice if Mikrotik added similar for PPP profiles.
by tdw
Sun Feb 21, 2021 4:56 pm
Forum: General
Topic: /interface ethernet set [ find default-name=ether1 ] speed=100Mbps [SOLVED]
Replies: 4
Views: 252

Re: /interface ethernet set [ find default-name=ether1 ] speed=100Mbps [SOLVED]

There is /system default-configuration print which displays the commands applied to create the default setup from a factory reset state, however AFAIK there is nothing to show the initial configuration other than not to apply the default setup and then use /export verbose
by tdw
Sun Feb 21, 2021 3:11 pm
Forum: General
Topic: /interface ethernet set [ find default-name=ether1 ] speed=100Mbps [SOLVED]
Replies: 4
Views: 252

Re: /interface ethernet set [ find default-name=ether1 ] speed=100Mbps [SOLVED]

At some point the default values which are supressed during /export were changed, so any existing configurations after a firmware update exhibit this. If you reset the configuration back to factory with the newer firmware the newer defaults are used. I'm not sure why it was changed as only 10-Half, ...
by tdw
Sun Feb 21, 2021 2:53 pm
Forum: Beginner Basics
Topic: hAP ac2 setup with VLAN
Replies: 4
Views: 312

Re: hAP ac2 setup with VLAN

2. In terms of throughput, should there be big difference if I resign from switch-chip for sake of vlan-filtering (bridge)? Or for a home user (video streaming, web surfing, email, NO gaming capabilities needed) the difference should not be noticeable at all? Another thing is that I am trying to se...
by tdw
Sat Feb 20, 2021 3:01 pm
Forum: General
Topic: Static DNS Route with Dynamic Address
Replies: 19
Views: 830

Re: Static DNS Route with Dynamic Address

If a static CNAME entry in 6.47.x does not work I would suspect the UniFi discovery implementation, in which case the scheduled script option suggested by @Sob would be a solution. @Sob & @sindy the OP putting 'route' in the topic title is completely misleading. The UniFi devices have a number o...
by tdw
Fri Feb 19, 2021 3:56 pm
Forum: Scripting
Topic: Append Bridge vlan values
Replies: 2
Views: 233

Re: Append Bridge vlan values

set untagged=([get value-name=untagged [find vlan-ids=10] ],"ether4") [find vlan-ids=10] Is there a reason you explicitly set the untagged= parameter as this will be dynamically populated from the pvid= parameter under /interface bridge port for bridge members and /interface bridge for th...
by tdw
Fri Feb 19, 2021 3:05 pm
Forum: General
Topic: Moving SSTP (vpn) CA certificate to another MT
Replies: 1
Views: 131

Re: Moving SSTP (vpn) CA certificate to another MT

The certificate store can be backed up and restored on the same Mikrotik, but not to a different one. It is possible to make a backup which can be restored to something else by exporting a certificate in PKCS12 format so the private key is exported too, see export-certificate in https://wiki.mikroti...
by tdw
Fri Feb 19, 2021 2:43 pm
Forum: General
Topic: Problem with L2/L3 Tunnel VLAN
Replies: 14
Views: 736

Re: Problem with L2/L3 Tunnel VLAN

It isn't clear exactly what your configuration is, posting the output of /export hide-sensitive is much more informative than some vague description. If you have multiple bridges, VLANs attached to interfaces which are members of a bridge, or VLAN interfaces as members of a bridge it could be one of...
by tdw
Thu Feb 18, 2021 6:10 pm
Forum: General
Topic: Why does 6.38 to 6.48.1 upgrade destroy my router and how can I avoid it?
Replies: 4
Views: 381

Re: Why does 6.38 to 6.48.1 upgrade destroy my router and how can I avoid it?

I don't think you have much option other than reorganising the bridge/VLAN setup. You could just convert from master-port to bridge and leave the VLAN interfaces attached to other bridges setup, except there are many pitfalls see https://wiki.mikrotik.com/wiki/Manual:Layer2_misconfiguration especial...
by tdw
Thu Feb 18, 2021 1:51 pm
Forum: General
Topic: Why does 6.38 to 6.48.1 upgrade destroy my router and how can I avoid it?
Replies: 4
Views: 381

Re: Why does 6.38 to 6.48.1 upgrade destroy my router and how can I avoid it?

For complex setups the replacement of master-port configuration with a hardware-offloaded bridge is not handled well by the upgrade process, as in your case. It isn't clear what your original setup was as there is a br-lan and a br-wan, but all five switch ports are configured for hardware VLAN swit...
by tdw
Thu Feb 18, 2021 1:08 pm
Forum: General
Topic: RB750GL - Port Redirect
Replies: 6
Views: 389

Re: RB750GL - Port Redirect

As the source and destination addresses are within the same subnet you need to disable any bridge hardware offload and set use-ip-firewall=yes under /interface bridge settings as normally the IP firewall filter/NAT/mangle rules only apply to routed layer 3, not bridged layer 2 traffic. This does inc...
by tdw
Wed Feb 17, 2021 7:55 pm
Forum: RouterBOARD hardware
Topic: DBM33G Hardware documentation
Replies: 1
Views: 187

Re: DBM33G Hardware documentation

The forums do have a search facility, and what published information there is available can be found in the help pages. One of the headers could be JTAG for manufacturing test, others may be for features which may be implemented - no point saying what they are if there is not a guaranteed developmen...
by tdw
Wed Feb 17, 2021 6:08 pm
Forum: Beginner Basics
Topic: VLAN-Problems [SOLVED]
Replies: 18
Views: 1030

Re: VLAN-Problems [SOLVED]

The bridge itself is still set to be both untagged /interface bridge add ingress-filtering=yes name=Bridge pvid=10 vlan-filtering=yes and tagged tagged=Bridge,... under /interface bridge vlan together with /interface vlan add interface=Bridge name=PrivateVLAN vlan-id=10 Change the bridge-to-CPU inte...
by tdw
Mon Feb 15, 2021 7:10 pm
Forum: General
Topic: How to connect vrrp'ed routers to wan (ISP)
Replies: 12
Views: 666

Re: How to connect vrrp'ed routers to wan (ISP)

Hmm what about a managed switch in between?
That would become a single point of failure - takes out both WAN connections. Engineering redundancy solutions which does not make your setup less reliable is not straightforward.
by tdw
Mon Feb 15, 2021 6:19 pm
Forum: Beginner Basics
Topic: VLAN-Problems [SOLVED]
Replies: 18
Views: 1030

Re: VLAN-Problems [SOLVED]

In the article it says "Access ports are configured in a way that means ingress (incoming) packets must not have tags and thus will get a tag applied." so, shouldn't Ingress-Filtering only be activated at ports where there are only packages without tags? Tagged only (a.k.a. trunk): frame-...
by tdw
Mon Feb 15, 2021 5:47 pm
Forum: Beginner Basics
Topic: L2TP with Radius Authentication
Replies: 15
Views: 557

Re: L2TP with Radius Authentication

You can only do PAP or MSCHAPv2 against AD, there is no way CHAP can work.

The 'Ignore user dial-in account properties' box is not ticked in your screenshots. I'm not a Windows expert, but without this I expect you have to apply a policy to the user accounts as the default is not to permit dial-in.
by tdw
Mon Feb 15, 2021 5:41 pm
Forum: Beginner Basics
Topic: VLAN-Problems [SOLVED]
Replies: 18
Views: 1030

Re: VLAN-Problems [SOLVED]

As the bridge and all of the ports have a PVID=1 things are getting confused by also having a VLAN with VID=1 attached to the bridge. There are several options * Use VLAN IDs excluding 1 OR * Set the bridge & port PVIDs to some other value OR * Disable the PVID on ports where you wish to use VLA...
by tdw
Mon Feb 15, 2021 5:23 pm
Forum: Beginner Basics
Topic: Port Forwarding after ISP Switch
Replies: 3
Views: 159

Re: Port Forwarding after ISP Switch

Screenshots of winbox/webfig pages are generally not very useful, the output of /export hide-sensitive from a terminal window posted as code (the [] icon above the text entry box on the forum page) shows the precise configuration
by tdw
Mon Feb 15, 2021 5:17 pm
Forum: Beginner Basics
Topic: Internet / VPN Problem
Replies: 11
Views: 772

Re: Internet / VPN Problem

But today I´ve seen something strange, i´ve connected my office mikrotik router to mine to access some devices from my home and in the moment I lost internet connection "ping 8.8.8.8" doesn´t response but ping to my office devices response correctly, so I have an internet connection. Goog...
by tdw
Mon Feb 15, 2021 4:55 pm
Forum: Beginner Basics
Topic: VLAN-Problems [SOLVED]
Replies: 18
Views: 1030

Re: VLAN-Problems [SOLVED]

Screenshots of winbox pages are generally not very useful, the output of /export hide-sensitive from a terminal window posted as code (the [] icon above the text entry box on the forum page) shows the precise configuration Mikrotik documentation on VLAN-aware bridges is here https://wiki.mikrotik.co...
by tdw
Sat Feb 13, 2021 8:00 pm
Forum: Beginner Basics
Topic: Splitting Ports into Seperate Isolated Networks
Replies: 25
Views: 1443

Re: Splitting Ports into Seperate Isolated Networks

If you have the default 'allow forward established/related/untracked connection' rule before your rule, yes. The first request from PC on LAN network to media server on IOT network has the connection state new , the reply from media server to PC has the state established and hits this rule. If you a...
by tdw
Fri Feb 12, 2021 7:06 pm
Forum: General
Topic: How to connect vrrp'ed routers to wan (ISP)
Replies: 12
Views: 666

Re: How to connect vrrp'ed routers to wan (ISP)

You need not switch the LAN VRRP over due to an external WAN failure, you can have backup default routes, i.e. with a greater distance via the other. If they are static routes the packets will bounce back and forth between the two Mikrotiks when both WANs are down, but you probably don't care in tha...
by tdw
Fri Feb 12, 2021 5:04 pm
Forum: General
Topic: no Access for local web management of DSL !
Replies: 2
Views: 181

Re: no Access for local web management of DSL !

Screenshots of Winbox are generally not particularly useful, the output of /export hide-sensitive from a terminal window posted as code (the [] icon above the text entry box on the form page) shows the precise configuration. I suspect that the ADSL and VDSL modems have no route to return traffic to ...
by tdw
Fri Feb 12, 2021 4:47 pm
Forum: General
Topic: How to connect vrrp'ed routers to wan (ISP)
Replies: 12
Views: 666

Re: How to connect vrrp'ed routers to wan (ISP)

If you have two public IPs provided by two different providers there isn't much you can do if the public addresses are terminated on the Mikrotiks, other than have an active-active setup with each Mikrotik handling one WAN connection and you loose access to that WAN if there is an issue with the att...
by tdw
Thu Feb 11, 2021 5:11 pm
Forum: Beginner Basics
Topic: L2TP routed/bridged/vlans
Replies: 13
Views: 614

Re: L2TP routed/bridged/vlans

What are: 192.168.11.0/24 + 192.168.12.0/24 and Remote: 192.168.21.0/24 + 192.168.22.0/24 ?
They were examples of subnets attached to the VLAN interfaces at each end. Your original example has two VLANs but only one subnet at each end which is insufficient.
by tdw
Thu Feb 11, 2021 5:07 pm
Forum: Beginner Basics
Topic: Confused how to do VLAN Firewall filters? [SOLVED]
Replies: 8
Views: 441

Re: Confused how to do VLAN Firewall filters? [SOLVED]

For input you should allow established/related/untracked connections, drop invalid connections, allow ICMP as blocking it breaks things such as PMTU detection, then have your drop from outside rule: /ip firewall filter add action=accept chain=input comment="Allow input 'established', 'related' ...
by tdw
Thu Feb 11, 2021 4:10 pm
Forum: Beginner Basics
Topic: L2TP routed/bridged/vlans
Replies: 13
Views: 614

Re: L2TP routed/bridged/vlans

If you had Head: 192.168.11.0/24 + 192.168.12.0/24 and Remote: 192.168.21.0/24 + 192.168.22.0/24 By this you mean V10 and V20 (example) IP addresses on Head and Remote? Yes, although the IP could be encapsulated in VID 11 + 12 at one end, and VID 21 + 22 at the other. So this is something along L3 ...
by tdw
Thu Feb 11, 2021 3:27 pm
Forum: Beginner Basics
Topic: L2TP routed/bridged/vlans
Replies: 13
Views: 614

Re: L2TP routed/bridged/vlans

If I go back to my original goal and want to connect head office with remote office and want to bridge L2 between sites then I need to use some kind of EoIP or BCP protocol. This way I can extend VLANs over to remote office. Yes, excepting the limitations of the current BCP implementation. What if ...
by tdw
Thu Feb 11, 2021 1:58 pm
Forum: Beginner Basics
Topic: L2TP routed/bridged/vlans
Replies: 13
Views: 614

Re: L2TP routed/bridged/vlans

I am trying to wrap my head around all this. I think I am still missing some peices to understand correctly. - Ethernet is L2 - VLAN is ethernet construct and therefore also L2. - bridge is also operating on L2 as it is kind of a "virtual" switch between interfaces Yes to all. - as long a...
by tdw
Thu Feb 11, 2021 1:37 pm
Forum: Beginner Basics
Topic: Confused how to do VLAN Firewall filters? [SOLVED]
Replies: 8
Views: 441

Re: Confused how to do VLAN Firewall filters? [SOLVED]

To have a conversation between LAN and DMZ after the initial packet from LAN to DMZ there will be a reply packet from DMZ to LAN and your drop DMZ to LAN rule will drop these too, typically you have an allow established/related/untracked rule as the first item in the forward chain to permit the ongo...
by tdw
Wed Feb 10, 2021 11:47 pm
Forum: Beginner Basics
Topic: L2TP routed/bridged/vlans
Replies: 13
Views: 614

Re: L2TP routed/bridged/vlans

Similar yes, in fact you can have both L2 & L3 if desired. One thing to watch out for is that BCP doesn't play nicely with VLAN-aware bridges, hopefully Mikrotik will fix it one day. I do have vlans configured under bridge vlan filtering as this appears to be a "promoted" way (I guess...
by tdw
Wed Feb 10, 2021 9:40 pm
Forum: Beginner Basics
Topic: L2TP routed/bridged/vlans
Replies: 13
Views: 614

Re: L2TP routed/bridged/vlans

Because I must not forget about vpn dial-in users I am sympathizing with L2TP now. Hopefully L2TP/IPsec, plain L2TP is either not or weakly encrypted and the MSCHAPv2 password can have the NT hash and an equivalent password recovered. With L2TP I also have routed or bridged (BCP) way. With BCP I gu...
by tdw
Wed Feb 10, 2021 9:13 pm
Forum: Beginner Basics
Topic: unifi cloud key
Replies: 7
Views: 1279

Re: unifi cloud key

I'm not sure the Cloud Key would like 57V passive - the MT48-480095-11DG (45W) would be a better choice, or if you are powering several additional devices from the hEX PoE too the 48POW (70W) may be required depending on their power requirements. Any third-party PSU with a centre-positive 2.1mm barr...
by tdw
Wed Feb 10, 2021 4:17 am
Forum: Beginner Basics
Topic: Splitting Ports into Seperate Isolated Networks
Replies: 25
Views: 1443

Re: Splitting Ports into Seperate Isolated Networks

With regards to the firewall rules that prevent the networks from talking to each other, I used the rules below. After applying these rules things work as I wanted with the exception that computers on each network can still ping the gateway on the opposite networks. This is not what I expected, but...
by tdw
Wed Feb 10, 2021 3:42 am
Forum: Beginner Basics
Topic: EoIP Tunnel Clamp TPC MSS
Replies: 7
Views: 448

Re: EoIP Tunnel Clamp TPC MSS

I have set 1300 MTU on the EoIP tunnel. Additional rule set MSS to 1250.
Be aware that if you add an EoIP interface with an MTU<1500 to a bridge it will impact any traffic between local bridge ports too, usually breaking things.
by tdw
Mon Feb 08, 2021 6:21 pm
Forum: Beginner Basics
Topic: Cisco AP Autonomout Mode VLAN issue on one VLAN [SOLVED]
Replies: 17
Views: 982

Re: Cisco AP Autonomout Mode VLAN issue on one VLAN [SOLVED]

My experiences with Cisco APs, albeit some years ago on 1230 series, was that they didn't particularly like a fully tagged setup so I used managment to the BVI interface untagged. Their newer APs may be better.
by tdw
Mon Feb 08, 2021 2:08 pm
Forum: General
Topic: LT2P VPN
Replies: 8
Views: 574

Re: LT2P VPN

You should have add-default-route=no under /interface l2tp-client - this is likely what is causing all your local devices to use the VPN connection. It would be better to use single mangle rule with an address list rather than having three mangle rules with individual addresses as it reduces the CPU...
by tdw
Sat Feb 06, 2021 9:46 pm
Forum: General
Topic: LT2P VPN
Replies: 8
Views: 574

Re: LT2P VPN

It depends on how the decision to route traffic via the VPN is going to be made. If there are a small number of destination addresses, e.g. a few company subnets, you can use static routes to direct traffic to those addresses via the VPN. However if there are a small number of local source addresses...
by tdw
Sat Feb 06, 2021 2:57 am
Forum: Beginner Basics
Topic: Enable DHCP passthrough to upper router (DHCP server)
Replies: 1
Views: 219

Re: Enable DHCP passthrough to upper router (DHCP server)

That won't work, the wiki example is using DHCP relay to pass requests for 192.168. 1 .0/24 and 192.168. 2 .0/24 subnets to a DHCP server running in the 192.168. 0 .0/24 subnet. If you wish to extend the network from the other router the hAP should have all ports in one bridge, no DHCP server or DHC...
by tdw
Wed Feb 03, 2021 7:02 pm
Forum: Beginner Basics
Topic: Cisco AP Autonomout Mode VLAN issue on one VLAN [SOLVED]
Replies: 17
Views: 982

Re: Cisco AP Autonomout Mode VLAN issue on one VLAN [SOLVED]

@anav The Cisco AP on ether2 is configured with VLAN10 untagged & VLAN20 tagged so frame-types=admit-only-vlan-tagged isn't appropriate either
by tdw
Wed Feb 03, 2021 2:35 pm
Forum: Beginner Basics
Topic: Cisco AP Autonomout Mode VLAN issue on one VLAN [SOLVED]
Replies: 17
Views: 982

Re: Cisco AP Autonomout Mode VLAN issue on one VLAN [SOLVED]

Having frame-types=admit-only-untagged-and-priority-tagged for ether2 isn't appropriate for a hybrid port
by tdw
Mon Feb 01, 2021 10:07 pm
Forum: General
Topic: After Hack are we clean ?
Replies: 6
Views: 652

Re: After Hack are we clean ?

I can't comment on Dude access as we do not use it. If you are restricting external access by means of an address lists there is not really a need to change the port(s). It depends on how determined/clever the hackers were as not everything in the underlying OS is exposed through Winbox or CLI. The ...
by tdw
Mon Feb 01, 2021 5:15 pm
Forum: General
Topic: [Question]: Anyone running a MA5671A GPON ONU at 2.5 GBit/s
Replies: 7
Views: 644

Re: [Question]: Anyone running a MA5671A GPON ONU at 2.5 GBit/s

The raw GPON interface always operates at 2.5Gbps down / 1.25Gbps up, regardless of the SFP interface rate. GPON supports upto 1:128 split ratios which would be 20Mbps down / 10Mbps up if everyone were using the service at the same instant. The ONU converts ethernet packet payloads to/from GEM (GPON...
by tdw
Mon Feb 01, 2021 4:49 pm
Forum: General
Topic: hardware offload (HW) hap ac Lile?
Replies: 5
Views: 456

Re: hardware offload (HW) hap ac Lile?

Set hw=no for the ethernet interfaces attached to the other bridges under /interface bridge port , in Winbox this is the 'Hardware Offload' checkbox on the General tab for the ports under Bridge > Ports. Hardware offload is only for ethernet to ethernet traffic for ports attached to one bridge, it w...
by tdw
Sun Jan 31, 2021 9:55 pm
Forum: Beginner Basics
Topic: Switch chip
Replies: 9
Views: 849

Re: Switch chip

As I said in my previous post your configuration does not allow traffic from the access ports to the CPU.
by tdw
Sun Jan 31, 2021 9:00 pm
Forum: General
Topic: hardware offload (HW) hap ac Lile?
Replies: 5
Views: 456

Re: hardware offload (HW) hap ac Lile?

Whichever has the greatest port to port traffic, e.g. if you have a PC and a NAS connected to a couple of ethernet ports then the bridge including those. Also note that wlan interfaces cannot be hardware accelerated as the traffic is handled by device driver code running on the CPU.
by tdw
Sat Jan 30, 2021 3:53 pm
Forum: Beginner Basics
Topic: Switch chip
Replies: 9
Views: 849

Re: Switch chip

The trunk and access ports have no access (IP or MAC based) to the CPU with that configuration: There is a VLAN5 interface configured for IP management of the device, however it is not connected to any ethernet ports. VLAN6 is untagged on ether2, tagged on ether1 and switch1-CPU, however there is no...
by tdw
Fri Jan 29, 2021 12:46 am
Forum: General
Topic: Help on wiring solution
Replies: 18
Views: 1331

Re: Help on wiring solution

No, one VLAN aware bridge. Then make the port connected to the guest network on the router (blue line) an access port for the guest VLAN. As the unmanaged switch may not pass tagged traffic make all the other Mikrotik ports access ports too, and use CAPsMAN forwarding to encapsulate the guest traffic.
by tdw
Thu Jan 28, 2021 8:50 pm
Forum: Beginner Basics
Topic: Switch chip
Replies: 9
Views: 849

Re: Switch chip

You mention VLAN 6 for management, however this configuration uses VLAN 5 which is not configured on any of the ether ports: add ports=switch1-cpu switch=switch1 vlan-id=5
by tdw
Thu Jan 28, 2021 8:37 pm
Forum: General
Topic: Reconfigure VLAN on CRS-326-24P-2S+ [SOLVED]
Replies: 7
Views: 531

Re: Reconfigure VLAN on CRS-326-24P-2S+ [SOLVED]

Generally I find it best not to include any untagged= membership entries under /interface bridge vlan as they will be dynamically added when interfaces are running/up based on the pvid= entries under /interface bridge port . If the untagged membership entries are present you have to remember to upda...
by tdw
Thu Jan 28, 2021 8:04 pm
Forum: General
Topic: Help on wiring solution
Replies: 18
Views: 1331

Re: Help on wiring solution

Having two subnets on one link without VLANs is possible but is unusual - it doesn't provide isolation, and DHCP can only be used to assign dynamic addresses to one subnet. Other than this weird internet connection the normal way of implementing this would be to use a single VLAN-aware bridge on the...
by tdw
Thu Jan 28, 2021 7:50 pm
Forum: General
Topic: APC SMT750U & CRS326-24G-2S+RM
Replies: 9
Views: 623

Re: APC SMT750U & CRS326-24G-2S+RM

Would it work if I use a USB to RJ45 Cisco Console Cable with FTDI chip? From UPS USB-B port to the serial RJ45 of the MikroTik? Or somehow connecting the USB port of the UPS to the serial RJ45 port of the MikroTik? No. USB only supports host-to-peripheral communications, not host-to-host or periph...
by tdw
Mon Jan 25, 2021 8:08 pm
Forum: General
Topic: APC SMT750U & CRS326-24G-2S+RM
Replies: 9
Views: 623

Re: APC SMT750U & CRS326-24G-2S+RM

I thought rollover cable would work as the that's how you can connect the APC UPS form its serial port to another device with RJ45 serial port. I don;t think I've ever seen an APC connection which didn't require a custom cable to swap pin connections as they are not a 1-to-1 mapping. So basically t...
by tdw
Mon Jan 25, 2021 7:54 pm
Forum: General
Topic: Help on wiring solution
Replies: 18
Views: 1331

Re: Help on wiring solution

The recommended setup for Mikrotiks with VLANs is to use a single VLAN-aware bridge, there is a good primer in the forum https://forum.mikrotik.com/viewtopic.php?t=143620 If the wired client connections (what you have called terminals) are on one network you can use CAPsMAN forwarding to segregate t...
by tdw
Mon Jan 25, 2021 2:28 pm
Forum: General
Topic: Making PPPOE-Client ip's static
Replies: 1
Views: 166

Re: Making PPPOE-Client ip's static

The PPPoE server uses the remote-address setting from the PPP profile, for authentication against a RADIUS server this may be overridden by including a Framed-IP-Address , Framed-Pool or Mikrotik-Group attribute in the Access-Accept message. You can specify local users under /ppp secret with specifi...
by tdw
Sat Jan 23, 2021 4:51 am
Forum: General
Topic: APC SMT750U & CRS326-24G-2S+RM
Replies: 9
Views: 623

Re: APC SMT750U & CRS326-24G-2S+RM

I'm trying to connect an APC UPS SMT750I from its RJ45 console port to the CRS326-24G-2S+RM via its serial console RJ45 port. I used RJ45-to-RJ45 rollover cable to do so. However the RouterOS is not recognising it. What makes you think a rollover cable will work? The APC connector is actually 10-pi...
by tdw
Sat Jan 23, 2021 3:47 am
Forum: General
Topic: 2 Mikrotiks on same layer 2
Replies: 15
Views: 936

Re: 2 Mikrotiks on same layer 2

Using /export hide-sensitive is generally recommended, and as you also appear to have left login credentials for external services in scripts you may wish to change them. R2 has lots of unnecessary configuration for a simple bridged access point (ipsec, ppp, firewall rules, dhcp-server, static dns, ...
by tdw
Fri Jan 22, 2021 5:49 pm
Forum: General
Topic: 2 Mikrotiks on same layer 2
Replies: 15
Views: 936

Re: 2 Mikrotiks on same layer 2

If I set the uplink interface on R2 to not be part of the bridge and then add the IP address in the interface, it works as it should be, but not if the uplink is part of the bridge. All of the ether and wlan interfaces should be members of one bridge and an IP address assigned to the bridge, can be...
by tdw
Fri Jan 22, 2021 3:23 pm
Forum: General
Topic: invalid dhcp server on vlan interface
Replies: 10
Views: 656

Re: invalid dhcp server on vlan interface

Either method will work. Using a VLAN-aware bridge is the simplest, you really only need to use the switch chip if you expect a lot of traffic between ethernet ports in the same VLAN as any routed traffic (between VLANs or between VLAN and internet) has to pass through the CPU in any case. Example u...
by tdw
Thu Jan 21, 2021 4:52 pm
Forum: Beginner Basics
Topic: Virtual MAC setup for load balancing and failover L2 links
Replies: 2
Views: 194

Re: Virtual MAC setup for load balancing and failover L2 links

VRRP is for failover, not load balancing/sharing, and works for L3 traffic, not L2.

Bonding the L2 interfaces together with an appropriate mode and transmit-hash-policy may work depending on the nature of the traffic, see https://wiki.mikrotik.com/wiki/Manual:Interface/Bonding
by tdw
Wed Jan 20, 2021 6:48 pm
Forum: Beginner Basics
Topic: Controlling "lease time" ip pool in defined in ppp profile
Replies: 3
Views: 424

Re: Controlling "lease time" ip pool in defined in ppp profile

IP pools have no concept of lease time, that is specific to DHCP. A PPP-like connection uses IPCP to inform the client of their IP address, and lasts for as long as the PPP session is connected. Address allocation from pools is generally 'sticky' between reboots of the Mikrotik so if a client discon...
by tdw
Tue Jan 19, 2021 8:05 pm
Forum: General
Topic: Discovery protocols through different bridge
Replies: 2
Views: 241

Re: Discovery protocols through different bridge

Most discovery protocols use layer 2 broadcasts and generally can not be routed. You may be able to use multicast routing for some, although from various posts I've seen it does seem to be somewhat hit and miss. There are also some third-party utilities you can run on a separate computer. Also why a...
by tdw
Tue Jan 19, 2021 5:01 am
Forum: General
Topic: ASK {switch chip}
Replies: 13
Views: 781

Re: ASK {switch chip}

Using both switch chips on a 2011/3011 will use the CPU for traffic between the two switch chips, and has issues https://wiki.mikrotik.com/wiki/Manual:L ... itch_chips
by tdw
Mon Jan 18, 2021 8:23 pm
Forum: General
Topic: CRS326 "proper" setup for Bridge and Switch
Replies: 1
Views: 196

Re: CRS326 "proper" setup for Bridge and Switch

Should I really stick with all my ports on both the switch and the default bridge? Or does this approach limit my performance or flexibility? Yes, the CRS3xx automatically offloads hardware switching to bridge ports. As I get around to setting up VLANs on my network, do I need to make changes in th...
by tdw
Fri Jan 15, 2021 7:15 pm
Forum: Beginner Basics
Topic: Need help setting up (VLAN?) [SOLVED]
Replies: 8
Views: 796

Re: Need help setting up (VLAN?) [SOLVED]

The 8337 and 8327 work properly, it is just a case of terminology/wording. Basically forget about the vlan-header= setting, with vlan-mode=secure the chip will use the default-vlan-id= setting to tag packets with that VLAN ID on ingress and strip the tag on egress.
by tdw
Fri Jan 15, 2021 12:14 am
Forum: General
Topic: CAPsMAN with Local Forwarding & VLANS Router/Switch/AP (hAP AC) [SOLVED]
Replies: 9
Views: 713

Re: CAPsMAN with Local Forwarding & VLANS Router/Switch/AP (hAP AC) [SOLVED]

As the wireless interfaces are managed by CAPsMAN they should not be manually added under /interface bridge port
by tdw
Thu Jan 14, 2021 8:14 pm
Forum: Beginner Basics
Topic: Bridge NAT Port Forwarding
Replies: 6
Views: 379

Re: Bridge NAT Port Forwarding

Did you clear the connection tracking entries or wait (~3 minutes for UDP connections)? The connection state includes flags to indicate if source and/or destination NAT is required, these are set on the first packet of a connection. As UDP doesn't have any concept of a connection, unlike TCP where y...
by tdw
Thu Jan 14, 2021 5:16 pm
Forum: Beginner Basics
Topic: Bridge NAT Port Forwarding
Replies: 6
Views: 379

Re: Bridge NAT Port Forwarding

Yes, unless a particular selector / matcher is used it will apply to all traffic. That rule has no to-addresses or to-ports so nothing would be changed.
by tdw
Thu Jan 14, 2021 3:39 pm
Forum: Beginner Basics
Topic: Bridge NAT Port Forwarding
Replies: 6
Views: 379

Re: Bridge NAT Port Forwarding

/interface bridge nat operates at layer 2 / ethernet and changes the MAC address based on the to-dst-mac-address parameter. The dst-port is just one of many selectors to identify a packets on which to perform actions. Is the traffic passing through the bridge to another port, in which case you do n...
by tdw
Tue Jan 12, 2021 4:36 am
Forum: Beginner Basics
Topic: How to use VLANs to isolate clients and route single public IP from subnet over it? [SOLVED]
Replies: 8
Views: 530

Re: How to use VLANs to isolate clients and route single public IP from subnet over it? [SOLVED]

I'm surprised it works as there do not appear to be any addresses associated with the VLANs (ether2.102, ether2.103, etc.), having an address on the base ether2 isn't propagated to the child VLAN interfaces. Our main use of routed IP blocks is public addresses for PPPoE clients, but we have used /32...
by tdw
Tue Jan 12, 2021 12:25 am
Forum: Beginner Basics
Topic: Bell WTTH / WHI help! Mikrotik Hex S . No ppoe needed
Replies: 1
Views: 140

Re: Bell WTTH / WHI help! Mikrotik Hex S . No ppoe needed

Starting with the standard config it should be: Remove ether1 from the WAN interface list Remove ether5 from the bridge Add a vlan to ether5 with ID 35, you can name it something more representative than vlan1 e.g. vlan35 Add the vlan to the WAN interface list Change the DHCP client interface to the...
by tdw
Tue Jan 12, 2021 12:02 am
Forum: General
Topic: VPN Server: Migrate certificates to new hardware
Replies: 9
Views: 740

Re: VPN Server: Migrate certificates to new hardware

You certainly have to export the certificates as a bundle in PKCS12 format so the private keys are exported too, see export-certificate in https://wiki.mikrotik.com/wiki/Manual:System/Certificates#General_Menu I recall there have been some reports that if a CRL has been specified (as in your example...
by tdw
Mon Jan 11, 2021 9:30 pm
Forum: Beginner Basics
Topic: How to use VLANs to isolate clients and route single public IP from subnet over it? [SOLVED]
Replies: 8
Views: 530

Re: How to use VLANs to isolate clients and route single public IP from subnet over it? [SOLVED]

Your confusing layer 2 (ethernet) and layer 3 (IP) functionality. There is mention of an IP address per subnet with the form 10.1.0.1 & 10.2.0.1, but then addresses with the form 10.1.0.2 & 10.1.0.3 which is completely different - if a subnet is attached to an ethernet interface layer 2 swit...
by tdw
Mon Jan 11, 2021 9:13 pm
Forum: Beginner Basics
Topic: External OVPN Problems
Replies: 1
Views: 144

Re: External OVPN Problems

OpenVPN does not use IPsec. Screenshots are not particularly helpful, they usually don't display everything. Execute /export hide-sensitive in a terminal window, post the output in a code block (the [] icon on the toolbar when posting in the forum) after redacting any public IP addresses.
by tdw
Mon Jan 11, 2021 7:12 pm
Forum: General
Topic: Static IP address for L2TP client on ROS v6.46.4 [SOLVED]
Replies: 2
Views: 246

Re: Static IP address for L2TP client on ROS v6.46.4 [SOLVED]

Get your RADIUS server to return a Framed-IP-Address attribute when the client authenticates, if present this overrides the pool specified in the PPP profile on the Mikrotik.
by tdw
Mon Jan 11, 2021 5:27 pm
Forum: Beginner Basics
Topic: DHCP Client on CRS interface got IP once, then expired..
Replies: 8
Views: 559

Re: DHCP Client on CRS interface got IP once, then expired..

A bridge has two roles - its is both like a switch connecting various ethernet ports together, and also like an ethernet port to pass traffic to services on the Mikrotik itself. Whilst you have br01-Core as a tagged member for VLAN IDs 99, 13 & 22 under /interface bridge vlan it is missing for V...
by tdw
Mon Jan 11, 2021 4:48 pm
Forum: Beginner Basics
Topic: Enable IPv6 with static address range from ISP
Replies: 1
Views: 209

Re: Enable IPv6 with static address range from ISP

There are several mechanisms an ISP may use to provide IPv6 addresses so you need to know which they use. The main issue is that each network requires a /64 prefix, if the ISP provides only one this is fine for a mobile phone as it is the endpoint, however if you are going to route you need one /64 ...
by tdw
Mon Jan 11, 2021 1:48 pm
Forum: Beginner Basics
Topic: Basic Understanding Bridge, VLAN, Switch, ... [SOLVED]
Replies: 23
Views: 1837

Re: Basic Understanding Bridge, VLAN, Switch, ... [SOLVED]

It had to be something simple like that, nothing obviously incorrect in the configurations. I did notice that VLAN IDs 10 & 99 are tagged on ether1-4 on switch1, however VLAN IDs 50, 70, 80, 90, 100, 200 & 300 are only tagged on ether1 so will not propagate on the trunks connected to ether2-...
by tdw
Sun Jan 10, 2021 8:54 pm
Forum: Beginner Basics
Topic: Basic Understanding Bridge, VLAN, Switch, ... [SOLVED]
Replies: 23
Views: 1837

Re: Basic Understanding Bridge, VLAN, Switch, ... [SOLVED]

Post the actual configs from /export hide-sensitive
by tdw
Fri Jan 08, 2021 6:30 pm
Forum: General
Topic: TalkTalk FTTP Configuration Help!
Replies: 12
Views: 878

Re: TalkTalk FTTP Configuration Help!

Finally someone who knows what talk talk is :) It is likely confusing for residents of one country who have never come across the businesses operating as ISPs in others. In the UK the top four ISPs with greater than one million clients each are BT Group (BT, Plusnet, EE), Sky Broadband, Virgin Medi...
by tdw
Fri Jan 08, 2021 4:53 pm
Forum: General
Topic: TalkTalk FTTP Configuration Help!
Replies: 12
Views: 878

Re: TalkTalk FTTP Configuration Help!

That does seem to make sense with TalkTalk documentation not being up to date as I did find a forum post on the talk talk community that says you dont need to do the VLAN tagging any more for FTTP. The official TalkTalk documentation for using your own router doesnt specify if those settings are fo...
by tdw
Fri Jan 08, 2021 3:53 pm
Forum: General
Topic: AP Router doesn't bind to mikrotik
Replies: 4
Views: 392

Re: AP Router doesn't bind to mikrotik

If you have set a manual address on the D-Link it will not appear in DHCP leases, only devices which make and accept DHCP requests will appear there. As you are connecting to the 'LAN' side of the D-Link router and using it is a wireless access point none of the routing/NAT/firewall functionality on...
by tdw
Fri Jan 08, 2021 3:42 pm
Forum: General
Topic: TalkTalk FTTP Configuration Help!
Replies: 12
Views: 878

Re: TalkTalk FTTP Configuration Help!

The TalkTalk help pages do not appear to have caught up with their available broadband products, having only recently started selling FTTP services via Openreach connections - PTM encoding and VLAN 101 are only applicable to FTTC / VDSL2 connections. Whilst PPPoE is often used to provide the custome...
by tdw
Mon Jan 04, 2021 10:58 pm
Forum: Beginner Basics
Topic: DHCP Server is active - but service port 67 doesn't exist
Replies: 3
Views: 399

Re: DHCP Server is active - but service port 67 doesn't exist

Then how do I get a list of all active services ? This is an almost-complete list https://wiki.mikrotik.com/wiki/Manual:IP/Services#Protocols_and_ports , OpenVPN is missing for example. If a particular service is not enabled the port will be inactive. Some services allow their ports to be changed f...
by tdw
Mon Jan 04, 2021 10:43 pm
Forum: General
Topic: Isolate two bridges at Layer 2 [SOLVED]
Replies: 7
Views: 501

Re: Isolate two bridges at Layer 2 [SOLVED]

Now that you're asking I think I made a dumb question. The bridges, being logical interfaces, act like normal interfaces, so there should be no L2 talk between them, right? Correct. Once you add IP addresses to each bridge then IP traffic at layer 3 can route between them unless blocked with firewa...
by tdw
Mon Jan 04, 2021 3:45 pm
Forum: Beginner Basics
Topic: Basic Understanding Bridge, VLAN, Switch, ... [SOLVED]
Replies: 23
Views: 1837

Re: Basic Understanding Bridge, VLAN, Switch, ... [SOLVED]

a) Instead of creating a new Bridge, I could use the Bridge from the default config of the CRS326 where all Ports are configured with hw-offloading and pvid=1. I would then need to add VLAN-ID 1 to the trunk port. By doing this, I would simply transition the current flat network in a VLAN-based fla...
by tdw
Sat Jan 02, 2021 9:20 pm
Forum: Beginner Basics
Topic: EoIP bridging over PPTP for remote IPTV [SOLVED]
Replies: 6
Views: 944

Re: EoIP bridging over PPTP for remote IPTV [SOLVED]

The EoIP settings in that presentation are not correct in as much that the MTU is not set - it should be forced to 1500 to be properly transparent to full-size ethernet frames. BCP over a PPP-like interface with MRRU set (to enable Multilink PPP) will also handle full-sized ethernet frames. There is...
by tdw
Fri Jan 01, 2021 4:38 pm
Forum: Beginner Basics
Topic: VPN status by email
Replies: 2
Views: 325

Re: VPN status by email

For PPP-like VPNs you could use the on-up and on-down script actions under /ppp profile to send an email using /tool e-mail send
by tdw
Thu Dec 31, 2020 3:32 pm
Forum: General
Topic: Attributes sent by the radius server
Replies: 6
Views: 469

Re: Attributes sent by the radius server

See 'Support request instructions' under https://mikrotik.com/support, as you have a reproducible bug you can skip 1 & 2.
by tdw
Thu Dec 31, 2020 12:06 am
Forum: General
Topic: Attributes sent by the radius server
Replies: 6
Views: 469

Re: Attributes sent by the radius server

Does idle-timeout under /ip hotspot active change when you send that attribute? If not you will likely have to report it as a bug, if it does it may be that background traffic from the device is more frequent than the timeout - you can check the idle-time value.
by tdw
Wed Dec 30, 2020 1:26 pm
Forum: General
Topic: /interface bridge VLAN filtering untag onto bridge
Replies: 14
Views: 991

Re: /interface bridge VLAN filtering untag onto bridge

A bridge has two roles - its is both like a switch connecting various ethernet ports together, and also like an ethernet port to pass traffic to services on the Mikrotik itself. Somewhat confusingly the settings for both of these roles are made under /interface bridge - the frame-types , ingress-fil...
by tdw
Tue Dec 29, 2020 8:05 pm
Forum: General
Topic: Basic VLAN switching !
Replies: 5
Views: 530

Re: Basic VLAN switching !

Currently for each VLAN's I create a interface VLAN10 for ether1 and interface VLAN10 for ether2 , then create a bridge and add both of those Vlans to that bridge, That isn't necessarily the wrong way of doing it, in fact prior to VLAN-aware bridges being introduced it was the standard method if no...
by tdw
Tue Dec 29, 2020 7:55 pm
Forum: Beginner Basics
Topic: Can't get dhcp address
Replies: 1
Views: 150

Re: Can't get dhcp address

The 802.11 WiFi standards do not support transparent layer 2 / ethernet bridging which can break protocols such as DHCP. Various vendors use the 802.11 four address frame packet format / WDS to implement transparent bridging, but as there is no standard method interoperability between vendors is hit...
by tdw
Mon Dec 28, 2020 5:15 pm
Forum: General
Topic: Different DHCP ranges with Mikrotik with Cisco AiroNet [SOLVED]
Replies: 17
Views: 1122

Re: Different DHCP ranges with Mikrotik with Cisco AiroNet [SOLVED]

I would suspect that the firewall rules are being overly restrictive, certainly that is the case for OpenVPN - you permit the OpenVPN connection, but not traffic from the connected clients. Enabling logging on the input and forward drop rules will likely provide a clue. Not allowing ICMP input will ...
by tdw
Mon Dec 28, 2020 3:58 pm
Forum: General
Topic: CCR1009 Hardware offload [SOLVED]
Replies: 12
Views: 1937

Re: CCR1009 Hardware offload [SOLVED]

I am considering using a CRS3XX as the PPPoE server for the VLAN's and have the CCR1009 for firewall and monitoring. The hardware offloading only applies to traffic bridged between ethernet ports, everything else is handled by the CPU. You might get somewhere between 100-200Mbps out of a PPPoE serv...
by tdw
Mon Dec 28, 2020 12:01 am
Forum: General
Topic: CCR1009 Hardware offload [SOLVED]
Replies: 12
Views: 1937

Re: CCR1009 Hardware offload [SOLVED]

When using VLAN's in the bridge ports, is there any work around for HW offloading or put another way what Mikrotik hardware can do VLAN HW offloading? Only the CRS3xx devices support VLAN-aware hardware-offloaded bridges, but these are designed to be layer 2 switches with limited layer 3 support. O...
by tdw
Sun Dec 27, 2020 8:18 pm
Forum: General
Topic: CCR1009 Hardware offload [SOLVED]
Replies: 12
Views: 1937

Re: CCR1009 Hardware offload [SOLVED]

Is there such thing as a 1009??
Yes, they have been around for over five years.
by tdw
Sun Dec 27, 2020 8:13 pm
Forum: General
Topic: CCR1009 Hardware offload [SOLVED]
Replies: 12
Views: 1937

Re: CCR1009 Hardware offload [SOLVED]

Am I correct that CCR1009-7G-1C-1S+ does not have hardware offload CCR1009-8G-1S-1S+ has hardware offload Yes, the discontinued CCR1009-8G-1S and CCR1009-8G-1S-1S+ (there are fan and passive cooled versions of both) have ether1-4 connected to the processor via an Atheros 8327 switch chip which can ...
by tdw
Thu Dec 24, 2020 10:24 pm
Forum: General
Topic: RB3011UIAS-RM: how to make it tag VLANs?
Replies: 5
Views: 541

Re: RB3011UIAS-RM: how to make it tag VLANs?

The /interface bridge port and /interface bridge vlan settings are completely ignored unless you set vlan-filtering=yes on the bridge. You also need to add the bridge itself as a tagged member of VLAN ID 100 under /interface bridge vlan , you do not need to set untagged membership as these are dynam...
by tdw
Thu Dec 24, 2020 3:33 pm
Forum: General
Topic: Different DHCP ranges with Mikrotik with Cisco AiroNet [SOLVED]
Replies: 17
Views: 1122

Re: Different DHCP ranges with Mikrotik with Cisco AiroNet [SOLVED]

Even though the sample has it commented, what is the purpose of admin (vlan 99)? Wouldn't vlan-10 be sufficient? I believe it is to separate management from all user device traffic, there isn't an issue with having a combined 'trusted device and management' network and just separating untrusted / g...
by tdw
Thu Dec 24, 2020 2:55 pm
Forum: General
Topic: Switch-chip config RB951Ui-2HnD [SOLVED]
Replies: 7
Views: 519

Re: Switch-chip config RB951Ui-2HnD [SOLVED]

Yes. The switch chip is always used, creating a bridge and adding ports with hardware offload reconfigures the switch chip at which point the 802.1Q VLAN setup can be made. Without a bridge being configured port-based VLANs are used to multiplex the physical ethernet ports to the logical interfaces ...
by tdw
Thu Dec 24, 2020 1:34 pm
Forum: General
Topic: Switch-chip config RB951Ui-2HnD [SOLVED]
Replies: 7
Views: 519

Re: Switch-chip config RB951Ui-2HnD [SOLVED]

You have to create a bridge with vlan-filtering=no to use the switch chip, see https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#VLAN_Example_1_.28Trunk_and_Access_Ports.29 , https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Management_access_configuration and https://wiki.mikrotik...
by tdw
Wed Dec 23, 2020 1:27 pm
Forum: General
Topic: best pattern to setup inter-vlan routing with 2 switches and 1 router?
Replies: 5
Views: 462

Re: best pattern to setup inter-vlan routing with 2 switches and 1 router?

As you only have a single ISP feed having multiple routers will not give you HA for external traffic, it could provide resilience between internal networks using VRRP but you have to take care with things such as DHCP and firewall rules as there is no synchronisation of IP pool use and connection tr...
by tdw
Wed Dec 23, 2020 1:16 pm
Forum: General
Topic: Different DHCP ranges with Mikrotik with Cisco AiroNet [SOLVED]
Replies: 17
Views: 1122

Re: Different DHCP ranges with Mikrotik with Cisco AiroNet [SOLVED]

I studied the page at https://forum.mikrotik.com/viewtopic.php?t=143620 and focused on Router-Switch-AP (all in one) section which applies to me. As I need only Guest access only on Wifi, I dropped the changes related to the physical ports. You will need a hybrid port with main network untagged and...
by tdw
Tue Dec 22, 2020 10:26 pm
Forum: Beginner Basics
Topic: IPv6 - default route
Replies: 1
Views: 200

Re: IPv6 - default route

Firstly, as the IPv6 package is disabled by default it is wise to enable it, reboot, and then reset the configuration to include the IPv6 firewall rules. Configuration varies depending on how your ISP delivers IPv6 - some are static only (my ISP doesn't do native IPv6 so I have a 6to4 tunnel, static...
by tdw
Tue Dec 22, 2020 6:37 pm
Forum: General
Topic: best pattern to setup inter-vlan routing with 2 switches and 1 router?
Replies: 5
Views: 462

Re: best pattern to setup inter-vlan routing with 2 switches and 1 router?

Mikrotik do not support bonding / LAG across multiple switches, if you connect the pair of interfaces on a server to different switches then only layer 2 option is spanning tree. As you have a single point of failure with a single router anyway adding switch failover may introduce additional potenti...
by tdw
Mon Dec 21, 2020 7:15 pm
Forum: General
Topic: Different DHCP ranges with Mikrotik with Cisco AiroNet [SOLVED]
Replies: 17
Views: 1122

Re: Different DHCP ranges with Mikrotik with Cisco AiroNet [SOLVED]

I would ideally like to use both the Mikrotik itself and the Cisco since I need to cover a considerably large area.
Using the WiFi on the Mikrotik itself doesn't require CAPsMAN, just configure the wlan interfaces directly
by tdw
Mon Dec 21, 2020 6:07 pm
Forum: General
Topic: Different DHCP ranges with Mikrotik with Cisco AiroNet [SOLVED]
Replies: 17
Views: 1122

Re: Different DHCP ranges with Mikrotik with Cisco AiroNet [SOLVED]

Thanks for the input. I was following online guides :-) I will reset it and try to find a document I can follow. Unfortunately many third-party blogs and videos are outdated (mostly by firmware changes such as the introduction of VLAN-aware bridges), less than optimal or insecure. The guide in my p...
by tdw
Mon Dec 21, 2020 5:33 pm
Forum: General
Topic: Different DHCP ranges with Mikrotik with Cisco AiroNet [SOLVED]
Replies: 17
Views: 1122

Re: Different DHCP ranges with Mikrotik with Cisco AiroNet [SOLVED]

The bridge and VLAN setup is horrible and has several of the errors described here https://wiki.mikrotik.com/wiki/Manual:Layer2_misconfiguration . The simplest method would be to use a single VLAN-aware bridge - there is a good primer on Mikrotik VLANs https://forum.mikrotik.com/viewtopic.php?t=1436...
by tdw
Thu Dec 17, 2020 1:41 pm
Forum: General
Topic: vlans and protocol mode
Replies: 2
Views: 231

Re: vlans and protocol mode

It would, that forum post is to explain VLAN setup without adding additional baggage. Spanning tree configuration is a complete topic in its own right.
by tdw
Wed Dec 16, 2020 1:43 pm
Forum: Beginner Basics
Topic: L2TP VPN cannot access LAN devices
Replies: 2
Views: 519

Re: L2TP VPN cannot access LAN devices

The proxy-arp setting is only required if the VPN clients and a local network share addresses from the same subnet, it should only be on the parent interface bridge1-lan , not the child interfaces ether3/4/5 . If you are using different subnets it is not required. The routes=192.168.88.0/24 under /p...
by tdw
Wed Dec 16, 2020 6:04 am
Forum: Beginner Basics
Topic: hap ac2: can't get access port based vlans to work
Replies: 2
Views: 279

Re: hap ac2: can't get access port based vlans to work

Your management VLAN (ID=5) is untagged on the interfaces to the cAP and hAP ac2 so can be accessed directly without requiring VLAN interfaces on those devices. If you look at the bridge VLANs in Winbox connected to the cAP you will see bridge plus ether1 and/or ether2 as Current Untagged members of...
by tdw
Wed Dec 16, 2020 3:29 am
Forum: General
Topic: Mikrotik Radius configuration over WS2019 [SOLVED]
Replies: 3
Views: 370

Re: Mikrotik Radius configuration over WS2019 [SOLVED]

AFAIK there are quite a few settings required to configure NPS, I've not tried it myself but others have used this https://mivilisnet.wordpress.com/2018/1 ... indows-ad/
by tdw
Tue Dec 15, 2020 6:35 pm
Forum: General
Topic: Problems with hybridport configuration
Replies: 8
Views: 505

Re: Problems with hybridport configuration

You can actually leave out the untagged= settings under /interface bridge vlan , they will be dynamically added based on the pvid= settings under /interface bridge port , so it would simplify to /interface bridge vlan add bridge=bridge1 tagged=ether6,ether15,ether16,ether17,LACP1,bridge1 vlan-ids=10...
by tdw
Tue Dec 15, 2020 12:51 am
Forum: General
Topic: VPN with TUN interface [SOLVED]
Replies: 12
Views: 864

Re: VPN with TUN interface [SOLVED]

You have confused TUN (layer 3 / IP) with TAP (layer 2 / ethernet). None of the layer 3 VPNs (L2TP, PPTP, SSTP, IPsec or OpenVPN TUN) will route broadcasts, however as you have found you can use the same IP range on the local LAN and remote VPN client using proxy-arp. If you need real layer 2 connec...
by tdw
Mon Dec 14, 2020 1:42 am
Forum: General
Topic: Problems with hybridport configuration
Replies: 8
Views: 505

Re: Problems with hybridport configuration

That is not the actual configuration on the device, post the output of /export hide-sensitive
by tdw
Sun Dec 13, 2020 7:28 pm
Forum: Beginner Basics
Topic: travel router
Replies: 14
Views: 1379

Re: travel router

i was planning to ad the eth1 device to a bridge called wan. however i think that isn't the correct methode. What is the best option to make ETH1 also availible as wan interface (when connected to this interface the wireless interface should not connect to an upstream wifi. but make the "lan&q...
by tdw
Sat Dec 12, 2020 4:06 pm
Forum: Beginner Basics
Topic: Default PPP profiles [SOLVED]
Replies: 2
Views: 356

Re: Default PPP profiles [SOLVED]

A /ppp profile sets various parameters used by PPP-like (PPP, PPPoE, PPTP, L2TP, SSTP, OVPN) clients and servers, but not passwords. Local servers use the passwords specified under /ppp secret , or RADIUS, to authenticate remote clients. See https://wiki.mikrotik.com/wiki/Manual:PPP_AAA Local client...
by tdw
Fri Dec 11, 2020 1:19 am
Forum: General
Topic: DHCP on VLAN
Replies: 5
Views: 409

Re: DHCP on VLAN

Using use-service-tag=yes under /interface vlan is incorrect for standard VLANs. A bridge has two roles - its is both like a switch connecting various ethernet ports together, and also like an ethernet port to pass traffic to services on the Mikrotik itself. So to provide access to DHCP and routing ...
by tdw
Wed Dec 09, 2020 12:06 am
Forum: Beginner Basics
Topic: Vpn Site To Site With Vlan
Replies: 8
Views: 696

Re: Vpn Site To Site With Vlan

As the same VLAN ID at both ends have a different subnet do you really need a layer 2 / ethernet connection, or just to be able to access the IP subnets which is down to IPsec policies and firewall rules.
by tdw
Mon Dec 07, 2020 2:58 am
Forum: General
Topic: Inbound and outbound connections on the same gateway
Replies: 21
Views: 1288

Re: Inbound and outbound connections on the same gateway

If all traffic from the second computer is to go via the WR1043 either put a few ports in a separate bridge on the RB3011, or change the existing bridge to be vlan-aware and use VLANs. No need for any DHCP, NAT, etc. as those few ports are effectively operating as an unmanaged switch. If some of the...
by tdw
Sun Dec 06, 2020 2:56 pm
Forum: General
Topic: VLan config check
Replies: 5
Views: 478

Re: VLan config check

Afternoon, I am installing a CRS tomorrow, can someone just verify my config.
There is no /interface bridge section to create the bridge.

Does the bridge need to be tagged on all vLans?
Only if you wish to access services on the Mikrotik itself from them, e.g. management access.
by tdw
Sun Dec 06, 2020 4:08 am
Forum: Beginner Basics
Topic: Firewall rules order
Replies: 15
Views: 1297

Re: Firewall rules order

From the wiki "Note that not all packets in a connection can be FastTracked, so it is likely to see some packets going through slow path even though connection is marked for FastTrack. This is the reason why fasttrack-connection is usually followed by identical action=accept rule." So unle...
by tdw
Sat Dec 05, 2020 6:05 pm
Forum: Beginner Basics
Topic: Vpn Site To Site With Vlan
Replies: 8
Views: 696

Re: Vpn Site To Site With Vlan

IPsec will not transport tagged VLANs as these are ethernet, not IP. You have to use EoIP or the BCP feature of PPP-like protocols e.g. L2TP/IPsec, SSTP to handle these. As you have different subnets using the same VLAN ID at each end you probably do not need to transport the VLANs, just make the su...
by tdw
Sat Dec 05, 2020 5:56 pm
Forum: Beginner Basics
Topic: Can' figure out VLANs (hap ac3) [SOLVED]
Replies: 5
Views: 571

Re: Can' figure out VLANs (hap ac3) [SOLVED]

You need to set vlan-mode=secure under /interface ethernet switch port for ether2-5. Per the note in the wiki "For devices with QCA8337 and Atheros8327 switch chips a default vlan-header=leave-as-is should be used. When vlan-mode=secure is configured, it ignore switch port vlan-header options. ...
by tdw
Sat Dec 05, 2020 1:32 pm
Forum: General
Topic: configure ubiquiti AP tagged and untagged vlan on mikrotik [SOLVED]
Replies: 2
Views: 398

Re: configure ubiquiti AP tagged and untagged vlan on mikrotik [SOLVED]

You are specifically excluding untagged traffic on the hybrid port connected to the AP. Under /interface bridge port make the following change:
add bridge=bridge-LAN frame-types=admit-only-vlan-taggedadmit-all ingress-filtering=yes interface=ether1 pvid=10
by tdw
Fri Dec 04, 2020 4:49 pm
Forum: General
Topic: L2TP with IPSEC terminating connection exactly every 30 minutes
Replies: 7
Views: 475

Re: L2TP with IPSEC terminating connection exactly every 30 minutes

You could leave a ping running to confirm if the tunnel does then stay up on the problematic link.

If this does turn out to be the case then abusing Tools > Netwatch would do - e.g. interval 25m, no up-script or down-script.
by tdw
Fri Dec 04, 2020 4:00 pm
Forum: General
Topic: L2TP with IPSEC terminating connection exactly every 30 minutes
Replies: 7
Views: 475

Re: L2TP with IPSEC terminating connection exactly every 30 minutes

Perhaps the other connection is transferring some real traffic and USG is ignoring protocol keepalive traffic when looking for idle conditions.
by tdw
Fri Dec 04, 2020 3:27 pm
Forum: General
Topic: L2TP with IPSEC terminating connection exactly every 30 minutes
Replies: 7
Views: 475

Re: L2TP with IPSEC terminating connection exactly every 30 minutes

The server is telling the client to disconnect
13:09:07 l2tp,ppp,debug,packet Tadej: rcvd LCP TermReq id=0x4
which is is complying with
13:09:07 l2tp,ppp,debug,packet Tadej: sent LCP TermAck id=0x4
so some setting at the server end, maybe an idle timeout.
by tdw
Thu Dec 03, 2020 7:02 pm
Forum: General
Topic: PPPoE AC topology question - firewalling
Replies: 12
Views: 796

Re: PPPoE AC topology question - firewalling

You can use raw firewall rules without connection tracking
by tdw
Thu Dec 03, 2020 3:06 pm
Forum: Beginner Basics
Topic: CRS305-1G-4S+IN - routing through SFP+
Replies: 2
Views: 245

Re: CRS305-1G-4S+IN - routing through SFP+

Is it possible to treat the Ethernet port as completely separate? It seems like it's bridged into the rest at the moment. What I would like to do is have 1x 10G "uplink" to my router, then 3x 2.5G to machines. Is this possible? If so, how? Eventually I don't want to have the Ethernet conn...
by tdw
Tue Dec 01, 2020 8:01 pm
Forum: Beginner Basics
Topic: How to assign a management IP to an interface?
Replies: 1
Views: 234

Re: How to assign a management IP to an interface?

The configuration seems incomplete, to use the switch chip you have to create a bridge and add the ethernet ports to it. Additionally you cannot add IP addresses or services to child interfaces. The basics are covered in https://wiki.mikrotik.com/wiki/Manual:Switch_Router and https://wiki.mikrotik.c...
by tdw
Mon Nov 30, 2020 4:04 pm
Forum: General
Topic: Input filter won't drop packets
Replies: 6
Views: 552

Re: Input filter won't drop packets

Note that when I do enable the rule that I can no longer ping from the router to the laptop, however, a machine that is connected to a different subnet that is connected via link aggregation CAN still ping the laptop. I have two subnets in question. 192.168.0.0/24 is connected to a switch using lin...
by tdw
Mon Nov 30, 2020 3:57 pm
Forum: General
Topic: Fiber vs Copper 10Gb/s SFP+ power consumption
Replies: 3
Views: 416

Re: Fiber vs Copper 10Gb/s SFP+ power consumption

Certainly devices such as the S+RJ10 require significantly more power then optical modules - Mikrotik quote an average power consumption of 2.7W driving a 30m 10GBASE-T link, compared to a maximum of 0.8W for a S+85DLC03D which supports 300m on multimode fibre. Conversely the S+DA0001 and S+DA0003 p...
by tdw
Sat Nov 28, 2020 2:30 pm
Forum: General
Topic: Shared VLAN Learning (SVL)
Replies: 14
Views: 1073

Re: Shared VLAN Learning (SVL)

Yes, bridge horizon wouldn't work with groups of ports. How about bridge filters /interface list add name=list1 add name=list2 /interface list member add interface=ether2 list=list1 add interface=ether3 list=list1 add interface=ether4 list=list2 add interface=ether5 list=list2 /interface bridge filt...
by tdw
Fri Nov 27, 2020 5:56 pm
Forum: General
Topic: Very frequent cloud.mikrotik.com activity [SOLVED]
Replies: 4
Views: 472

Re: Very frequent cloud.mikrotik.com activity [SOLVED]

The detect-internet function also uses the Mikrotik cloud servers. From various posts it seemd to cause more trouble than it is worth, you could disable it as the ports are already manually assigned to the LAN & WAN interface lists.
by tdw
Fri Nov 27, 2020 5:42 pm
Forum: General
Topic: Shared VLAN Learning (SVL)
Replies: 14
Views: 1073

Re: Shared VLAN Learning (SVL)

Single malt is good
by tdw
Thu Nov 26, 2020 7:39 pm
Forum: Beginner Basics
Topic: PPTP Server won't work [SOLVED]
Replies: 21
Views: 1579

Re: PPTP Server won't work [SOLVED]

Are you sure the credentials are validated, or just accepted by the Windows client?

Does the packet count on the firewall filter add action=accept chain=input comment="PPTP VPN" dst-port=1723 protocol=tcp rule increase? Anything in the Mikrotik log?
by tdw
Thu Nov 26, 2020 7:05 pm
Forum: Beginner Basics
Topic: PPTP Server won't work [SOLVED]
Replies: 21
Views: 1579

Re: PPTP Server won't work [SOLVED]

With that configuration the address 192.168.10.1 in image #7 does not exist until a connection using the PPTP Server PPP profile is made, you can use the LAN gateway address if connecting locally to test. Also there is no need to add 192.168.10.0/24 under /ip dhcp-server network as PPP-like protocol...
by tdw
Thu Nov 26, 2020 5:08 pm
Forum: Beginner Basics
Topic: No way to get safe wpa wireless working on hapac2 [SOLVED]
Replies: 10
Views: 709

Re: No way to get safe wpa wireless working on hapac2 [SOLVED]

The LAN IP address being applied to ether2 rather than the LAN bridge crops up way too often for everyone to be making the same mistake. I suspect there is something buried in a default script or quickset which was never updated when master-port configuration was replaced by a LAN bridge.
by tdw
Thu Nov 26, 2020 4:49 pm
Forum: General
Topic: Shared VLAN Learning (SVL)
Replies: 14
Views: 1073

Re: Shared VLAN Learning (SVL)

Do you require multiple VLANs on ports, or are you just trying to isolate groups of ports sharing a subnet within a layer 2 network? If so port isolation or bridge horizon may be a solution.
by tdw
Thu Nov 26, 2020 4:42 pm
Forum: Beginner Basics
Topic: PPTP Server won't work [SOLVED]
Replies: 21
Views: 1579

Re: PPTP Server won't work [SOLVED]

Screenshots generally do not convey enough information to be useful, post the output of /export hide-sensitive from a Winbox terminal session in a code block (the [] icon above the text box when posting on the forum). Many third-party guides on the internet are out of date / not optimal / insecure. ...
by tdw
Tue Nov 24, 2020 2:55 am
Forum: Beginner Basics
Topic: Not DST-NAT traffic hits your INPUT
Replies: 11
Views: 615

Re: Not DST-NAT traffic hits your INPUT

Incoming packets have to be handled somwehere. Packets not consumed by dst-nat will either be handled by input if the destination address matches an IP address assigned to the Mikrotik, or forward for any other addresses - this is normal linux routing behaviour. If you have a deny address list you c...
by tdw
Mon Nov 23, 2020 9:20 pm
Forum: Beginner Basics
Topic: 2 separate subnets on 2 different router's ports
Replies: 40
Views: 1995

Re: 2 separate subnets on 2 different router's ports

To access the Mikrotik itself you do indeed need input not forward and/or dst-nat rules. The /ip firewall nat ... add action=dst-nat chain=dstnat comment="Router Remote" dst-port=4770 protocol=tcp src-address=199.51.2.4 to-addresses=10.10.50.1 to-ports=80 ... is incorrect. EDIT: incorrect ...
by tdw
Mon Nov 23, 2020 5:12 pm
Forum: Beginner Basics
Topic: RB 750 Gr hEX not detectable in network
Replies: 16
Views: 852

Re: RB 750 Gr hEX not detectable in network

You mention VLANs with IP addresses which is not strictly correct - ethernet VLANs may carry assorted IP subnets but a VLAN itself does not have an IP address. Winbox discovery will only display devices on directly attached networks as the information is broadcast, so never routed to other subnets. ...
by tdw
Thu Nov 19, 2020 3:56 pm
Forum: Beginner Basics
Topic: 2 separate subnets on 2 different router's ports
Replies: 40
Views: 1995

Re: 2 separate subnets on 2 different router's ports

If you start with the default configuration that has ether1 configured as the WAN interface acquiring an IP address with DHCP client, and ether2-5 in a bridge configured as the LAN interface providing addresses with a DHCP server, along with a reasonable set of firewall and NAT rules. If you only wi...
by tdw
Thu Nov 19, 2020 2:28 am
Forum: Beginner Basics
Topic: Communicate outside the bridge [SOLVED]
Replies: 6
Views: 445

Re: Communicate outside the bridge [SOLVED]

Just because you create two /interface vlan with the same VLAN ID on differing interfaces (ether1 and switch_core_L2), and assign addresses from the same subnet to each of them will not allow access from one to the other. A diagram of what you wish to achieve may be helpful.
by tdw
Mon Nov 16, 2020 4:25 pm
Forum: General
Topic: OVPN Certificate Issue
Replies: 14
Views: 970

Re: OVPN Certificate Issue

The OVPN server should have its own server certificate, not the self-signed CA, selected. The private key for the server certificate must also be present. The CA certificate, and any intermediate certificates if used, must also exist on the server Mikrotik. They will be present if you generated the ...
by tdw
Sun Nov 15, 2020 9:32 pm
Forum: Beginner Basics
Topic: Bridge filter problem
Replies: 1
Views: 165

Re: Bridge filter problem

Any bridge filter rules apply to layer 2 traffic between ports only when hardware acceleration is not being used. When hardware acceleration is used the traffic is internal to the switch chip and never reaches any filter rules handled by the CPU, you may be able to use switch rules https://wiki.mikr...
by tdw
Sat Nov 14, 2020 6:24 pm
Forum: General
Topic: bridge vlan (legacy mode) setup doesn't work - please help
Replies: 1
Views: 184

Re: bridge vlan (legacy mode) setup doesn't work - please help

If the configuration was unchanged between the original hEX Gr3 and hEX lite the most likely cause is the different MAC addresses changing the spanning tree topology - try setting protocol-mode=none on all of the bridges. This is one of the issues discussed here https://wiki.mikrotik.com/wiki/Manual...
by tdw
Sat Nov 14, 2020 1:11 pm
Forum: General
Topic: Feature request: NTP client: canonical name of NTP servers
Replies: 7
Views: 466

Re: Feature request: NTP client: canonical name of NTP servers

What feature? Some arrow to point you to the right menu?
As mentioned in an earlier post the SNTP client is fine, however upon installing the NTP package to provide a local NTP server the replacement NTP client still only accepts IP addresses, not names.
by tdw
Fri Nov 13, 2020 4:15 pm
Forum: General
Topic: OVPN Certificate Issue
Replies: 14
Views: 970

Re: OVPN Certificate Issue

Opened it via Windows Certificate handler ... Key Usage: Certificate Signing (04) That is OK for the CA certificate itself, the child certificate used by the OVPN server should have encipherment usages present. The key files are needed to unlock the certificates, aren't they? I normally import them...
by tdw
Fri Nov 13, 2020 2:20 pm
Forum: General
Topic: OVPN Certificate Issue
Replies: 14
Views: 970

Re: OVPN Certificate Issue

the output of `openssl x509 -in C:\\Users\\someone\\OpenVPN\\config\\cert_export_MY-CA.crt -text` would be helpful, to see what attributes are set in the certificate. Where/how do I run this query? openssl is included with most linux distributions, there will be windows ports available. Alternative...
by tdw
Wed Nov 11, 2020 5:07 pm
Forum: General
Topic: CRS125-24G-1S VLAN problem
Replies: 8
Views: 365

Re: CRS125-24G-1S VLAN problem

If I understand it correctly, VLANs are working in bridge way only if I enable vlan filtering on bridge .... or switch way if I disable vlan filtering on bridge and have everything setup in switch vlan ... is that correct? Yes. When vlan-filtering=yes the VLAN configuration is made under /interface...
by tdw
Wed Nov 11, 2020 4:18 pm
Forum: General
Topic: CRS125-24G-1S VLAN problem
Replies: 8
Views: 365

Re: CRS125-24G-1S VLAN problem

Remove everything in the /interface bridge vlan and /interface ethernet switch egress-vlan-translation sections as they are redundant. The relevant configuration examples are https://wiki.mikrotik.com/wiki/Manual:CRS1xx/2xx_series_switches_examples#Example_1_.28Trunk_and_Access_ports.29 and https://...
by tdw
Wed Nov 11, 2020 4:15 am
Forum: General
Topic: RB3011 as default gateway for a VLAN [SOLVED]
Replies: 2
Views: 223

Re: RB3011 as default gateway for a VLAN [SOLVED]

A bridge as two roles - a switch-like role for transporting packets between ports, and a port-like role for transporting packets between the bridge and other functions provided by the Mikrotik. You need to add the bridge itself to the required VLANs under /interface bridge vlan , also it isn't neces...
by tdw
Sun Nov 08, 2020 2:13 am
Forum: General
Topic: DHCP server offers are not bound when used with VLAN and WLAN
Replies: 11
Views: 508

Re: DHCP server offers are not bound when used with VLAN and WLAN

Hardware offloading is disabled for VLAN-aware bridges, changing the switch chip settings from default can result in odd behaviour so I would changed those back to the defaults. There is little point having two VLAN-aware bridges, and bridgeIoT is incorrectly configured with a PVID having the same V...
by tdw
Fri Nov 06, 2020 12:56 am
Forum: Beginner Basics
Topic: PFsense to Mikrotik RouterOS v6.47.7 vlans
Replies: 12
Views: 645

Re: PFsense to Mikrotik RouterOS v6.47.7 vlans

A number of issues... You only require /interface vlan entries if you wish VLANs to interface with services on the Mikrotik, they are not required for VLANs merely passing through the Mikrotik bridge/switch. Under /interface bridge port setting frame-types= has no effect unless ingress-filtering=yes...
by tdw
Fri Nov 06, 2020 12:01 am
Forum: General
Topic: define wan link for packets with a specific destination port [SOLVED]
Replies: 8
Views: 471

Re: define wan link for packets with a specific destination port [SOLVED]

If WAN1 is not to be used for any other traffic remove its default route so all traffic egresses via WAN2. Use mangle rules to firstly mark the desired connections, then apply policy routing with a routing table entry for the routing marks. The wiki has pages on mangle rules https://wiki.mikrotik.co...
by tdw
Thu Nov 05, 2020 11:44 pm
Forum: Beginner Basics
Topic: PFsense to Mikrotik RouterOS v6.47.7 vlans
Replies: 12
Views: 645

Re: PFsense to Mikrotik RouterOS v6.47.7 vlans

Screenshots are generally not that helpful.

In a terminal window run /export hide-sensitive and paste the configuration output in a code block (the [] icon above the reply box) which makes it more readable.
by tdw
Thu Nov 05, 2020 10:12 pm
Forum: Beginner Basics
Topic: PFsense to Mikrotik RouterOS v6.47.7 vlans
Replies: 12
Views: 645

Re: PFsense to Mikrotik RouterOS v6.47.7 vlans

I just printed out all kinds of documentation so I can ready over tonight.. in the meantime what would I have to do to have port 3 on the switch pass down VLAN 10 from the fw? So if I were to hook up a device to that port then DHCP witch is in my FW will get passed down to it Assuming all of the po...
by tdw
Thu Nov 05, 2020 5:42 pm
Forum: Beginner Basics
Topic: PFsense to Mikrotik RouterOS v6.47.7 vlans
Replies: 12
Views: 645

Re: PFsense to Mikrotik RouterOS v6.47.7 vlans

CR3xx should be configured with a single VLAN-aware bridge as the switch chip is automatically used, a.k.a. hardware offloading. See https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering and there is a good primer on Mikrotik VLANs in the forums https://forum.mikrotik.com/view...
by tdw
Thu Nov 05, 2020 3:56 pm
Forum: Beginner Basics
Topic: PFsense to Mikrotik RouterOS v6.47.7 vlans
Replies: 12
Views: 645

Re: PFsense to Mikrotik RouterOS v6.47.7 vlans

So that means even if I have iSCSI traffic the packets will route all the way back up to the FW with 1G ports then back down to the SFP+ ports on the mikrotik? Is there a way to not do that? That depends on your network architecture. Traffic within a layer2 network will be switched, e.g. IP traffic...
by tdw
Thu Nov 05, 2020 1:47 pm
Forum: Beginner Basics
Topic: PFsense to Mikrotik RouterOS v6.47.7 vlans
Replies: 12
Views: 645

Re: PFsense to Mikrotik RouterOS v6.47.7 vlans

So I have a pfsense device as my FW , and I just purchased a mikrotik device as it's the cheapest I can find with sfp+ and I'm having some trouble restricting a port to just one vlan tag... I've done it in Unifi controller where I had to create a network and then assign a port a vlan tag and it wor...
by tdw
Wed Nov 04, 2020 4:14 pm
Forum: General
Topic: Failover for router hardware (not WAN)
Replies: 11
Views: 576

Re: Failover for router hardware (not WAN)

It's tricky, trying to implement hardware failover can lead to more points of failure. For example, if the LAN is configured to use VRRP for failover between the two routers how would you connect the two routers to your network - if you use a switch that then becomes a single point of failure. Simil...
by tdw
Wed Nov 04, 2020 2:05 pm
Forum: General
Topic: Framed Route - Two IP addresses from my ISP [SOLVED]
Replies: 12
Views: 893

Re: Framed Route - Two IP addresses from my ISP [SOLVED]

The DHCP process only assigns a single IP address to an interface, as you have a static address this could be done with DHCP option 82 (this isn't seen by the end user) or MAC address binding. The framed route setup at the ISP just directs incoming packets for the additional IP address(es) to your p...
by tdw
Wed Nov 04, 2020 3:44 am
Forum: General
Topic: Framed Route - Two IP addresses from my ISP [SOLVED]
Replies: 12
Views: 893

Re: Framed Route - Two IP addresses from my ISP [SOLVED]

As you are not using a PPP-like connection for your WAN how is your existing main/primary WAN address set/acquired?
by tdw
Mon Nov 02, 2020 7:14 pm
Forum: General
Topic: DHCP setup for multiple VLANs
Replies: 3
Views: 271

Re: DHCP setup for multiple VLANs

As the DHCP server entries are coloured red in Winbox there is an error with their configuration. Have you added the networks under DHCP Server > Networks? The best way to show configurations is to use the /export hide-sensitive command in a terminal window and paste the output in a code block (the ...
by tdw
Mon Nov 02, 2020 4:04 pm
Forum: Beginner Basics
Topic: Two Crs305 as multi media converter setup
Replies: 7
Views: 410

Re: Two Crs305 as multi media converter setup

No, ethernet/IP equipment is likely to only support Ethernet SFP/SFP+. You will need something specifically designed for SDI, likely more expensive than ethernet/IP kit as it is a much smaller market.
by tdw
Mon Nov 02, 2020 2:30 pm
Forum: Beginner Basics
Topic: Two Crs305 as multi media converter setup
Replies: 7
Views: 410

Re: Two Crs305 as multi media converter setup

Now I was told those sdi sfps only work with dedicated equipment and not with any switch or router in general as the device needs to encode or decode video to ip. Is that true? Yes. The SFP/SFP+ physical form factor, pinout and power supply may be common, but the serial data stream is specific to t...
by tdw
Sun Nov 01, 2020 5:13 pm
Forum: Beginner Basics
Topic: Dual WAN (PPPoE, dynamic IP) PCC load balancing to bridge interface
Replies: 12
Views: 1096

Re: Dual WAN (PPPoE, dynamic IP) PCC load balancing to bridge interface

It depends on the optical delivery and type of SFP. For GPON a dumb SFP will not work, but an active SFP which contains ONT functionality and presents a 1000Base-X electrical interface should. There are also some ISPs who use point-to-point 1000Base-LX or 1000Base-BX optics rather than GPON.
by tdw
Sun Nov 01, 2020 3:46 pm
Forum: Beginner Basics
Topic: Need help forwarding port 25
Replies: 10
Views: 567

Re: Need help forwarding port 25

The default configuration forward rules are /ip firewall filter add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked add action=drop chain=forward comment="defconf: drop invalid" connection-state=i...
by tdw
Sat Oct 31, 2020 1:53 pm
Forum: Beginner Basics
Topic: Dual WAN (PPPoE, dynamic IP) PCC load balancing to bridge interface
Replies: 12
Views: 1096

Re: Dual WAN (PPPoE, dynamic IP) PCC load balancing to bridge interface

- created two interface lists LAN (with the bridge), and WAN (with physical ge1 and fe9 ifaces, not the PPPoE interfaces act-ge1 and airtel-fe9) - /ip firewall \ nat add action=masquerade chain=srcnat comment="defconf: masquerade" \ ipsec-policy=out,none out-interface-list=WAN I'm suprise...
by tdw
Fri Oct 30, 2020 1:54 pm
Forum: General
Topic: Fixed IP on PPPoE server with pool
Replies: 4
Views: 365

Re: Fixed IP on PPPoE server with pool

Reduce the pool size to leave some non-overlapping addresses available for static allocation.

Also, you can assign the IP address with the Framed-IP-Address RADIUS attribute, which overrides remote-address in the PPP profile, instead of creating local secrets.
by tdw
Fri Oct 30, 2020 1:43 pm
Forum: Beginner Basics
Topic: VLAN Config on RB750Gr3
Replies: 2
Views: 252

Re: VLAN Config on RB750Gr3

It is unwise to attach VLAN interfaces to individual members of bridges unless you know what the effects will be. There is a good primer on Mikrotik VLANs https://forum.mikrotik.com/viewtopic.php?f=13&t=143620 and there are skeleton examples on the wiki https://wiki.mikrotik.com/wiki/Manual:Inte...
by tdw
Thu Oct 29, 2020 7:53 pm
Forum: Forwarding Protocols
Topic: OSPF Config
Replies: 9
Views: 814

Re: OSPF Config

That should work, we have a site with something similar for six Mikrotiks although using L2TP/IPsec and /32 addresses for the interlinks, so it will be a configuration issue.
by tdw
Sun Oct 25, 2020 4:33 pm
Forum: Beginner Basics
Topic: 750G download speed very slow
Replies: 25
Views: 1185

Re: 750G download speed very slow

MMIPS for 750G, Long term version. MMIPS is only for the 750Gr3 (second version of the hEX). The original 750G, which the OP has, and the 750Gr2 (first version of the hEX) are MIPSBE. The /system routerboard settings set cpu-frequency=150MHz will be reducing the performance, it should be several ti...
by tdw
Fri Oct 23, 2020 7:05 pm
Forum: General
Topic: "Holy war" against masquerade and ike2 dynamic ip address on your wan interface
Replies: 8
Views: 601

Re: "Holy war" against masquerade and ike2 dynamic ip address on your wan interface

You might be able to use/abuse /routing filter to modify dynamically added routes.
by tdw
Thu Oct 22, 2020 2:57 pm
Forum: General
Topic: Optical cable and SFP advice
Replies: 8
Views: 784

Re: Optical cable and SFP advice

There is stretched up optical cable already(label on cable is: SC simplex 2.0 mm OFNR That does not tell you the type of fibre - SC is the type of plug, simplex is single fibre, 2.0mm OFNR is the diameter and and fire rating of the cable. You need to know if the fibre is single mode or multimode, a...
by tdw
Thu Oct 22, 2020 2:22 pm
Forum: Beginner Basics
Topic: Mikrotik as VPN Server in existing network
Replies: 3
Views: 305

Re: Mikrotik as VPN Server in existing network

I want the vpn clients to have an ip from the main dhcp server. That isn't going to happen unless you use a layer 2 VPN (so OpenVPN TAP or Mikrotik-to-Mikrotik EoIP). Whilst layer 3 VPNs (OpenVPN TUN, SSTP, L2TP/IPsec, etc.) can be used with proxy-arp so the VPN clients can appear to be part of a l...
by tdw
Tue Oct 20, 2020 1:44 pm
Forum: General
Topic: Microtik and AD
Replies: 3
Views: 290

Re: Microtik and AD

For clients to resolve hosts in your AD you have to use your DC as their DNS server. The DC itself should act as a recursive resolver for any other DNS requests.
by tdw
Tue Oct 20, 2020 2:58 am
Forum: Beginner Basics
Topic: Pools, VPNs, and profiles
Replies: 6
Views: 371

Re: Pools, VPNs, and profiles

If the VPN is for remote access rather than shifting large amounts of data you should be OK, there are plenty of articles covering the issue on the internet if you search for 'tcp meltdown' or 'tcp over tcp problem'. We have a number of Mikrotiks running L2TP/IPsec (permanent site-to-site with stati...
by tdw
Tue Oct 20, 2020 2:32 am
Forum: Beginner Basics
Topic: Pools, VPNs, and profiles
Replies: 6
Views: 371

Re: Pools, VPNs, and profiles

What can we do if we want to use OpenVPN on MikroTik when it lacks UDP?
The Mikrotik implementation only supports TCP for the VPN client to server connection itself (I believe UDP has been added in RouterOS 7), the VPN tunnel handles any layer 3 payload in IP / TUN mode.
by tdw
Tue Oct 20, 2020 1:39 am
Forum: Beginner Basics
Topic: Pools, VPNs, and profiles
Replies: 6
Views: 371

Re: Pools, VPNs, and profiles

I was thinking the server address should be in the same subnet as the pool, but it doesn't seem to care. It doesn't have to be. VPNs are point-to-point tunnels with a /32 address at either end, they can be pretty much anything. I'm about to add an OpenVPN server, as well, mainly to overcome the lac...
by tdw
Mon Oct 19, 2020 6:28 pm
Forum: Beginner Basics
Topic: DHCP on physical interface comes out invalid using Wizard [SOLVED]
Replies: 7
Views: 490

Re: DHCP on physical interface comes out invalid using Wizard [SOLVED]

Do you have anything plugged in to ether9? If a DHCP server is bound to an interface in the non-running state it appears in red in Winbox / with an invalid flag in /ip dhcp-server print even though it isn't. Physical and some logical interfaces (e.g. VPN tunnels) follow the state of the underlying c...
by tdw
Mon Oct 19, 2020 3:53 pm
Forum: General
Topic: VLAN DHCP on MAIN router not working to WLAN on AP [SOLVED]
Replies: 13
Views: 768

Re: VLAN DHCP on MAIN router not working to WLAN on AP [SOLVED]

If a bridge has vlan-filtering=yes only untagged traffic will pass through the bridge ports. However, if vlan-filtering=no the bridge behaves similarly to an unmanaged switch so any VLAN tagged traffic will pass through all bridge ports.
by tdw
Mon Oct 19, 2020 3:36 pm
Forum: General
Topic: VLAN DHCP on MAIN router not working to WLAN on AP [SOLVED]
Replies: 13
Views: 768

Re: VLAN DHCP on MAIN router not working to WLAN on AP [SOLVED]

You need to specify which tagged VLANs are made available to the various bridge ports, including the bridge itself as a bridge has two roles - a switch-like role for transporting packets between ports, and a port-like role for transporting packets between the bridge and other functions provided by t...
by tdw
Mon Oct 19, 2020 2:42 pm
Forum: General
Topic: VLAN DHCP on MAIN router not working to WLAN on AP [SOLVED]
Replies: 13
Views: 768

Re: VLAN DHCP on MAIN router not working to WLAN on AP [SOLVED]

You have set the bridge to be VLAN-aware but not configured any bridge VLANs, so no tagged traffic will pass through the bridge. See https://wiki.mikrotik.com/wiki/Manual:I ... _Filtering
by tdw
Mon Oct 19, 2020 12:01 pm
Forum: General
Topic: EiOP in Bridge -TCP problem [SOLVED]
Replies: 3
Views: 317

Re: EiOP in Bridge -TCP problem [SOLVED]

You must change the EOIP interface MTU to 1500
by tdw
Sun Oct 18, 2020 8:08 pm
Forum: General
Topic: PPTP and Proxy Arp
Replies: 5
Views: 360

Re: PPTP and Proxy Arp

All of those I mentioned have both client and server support: https://wiki.mikrotik.com/wiki/Manual:IP/IPsec - there are some examples in section 17 https://wiki.mikrotik.com/wiki/Manual:Interface/OVPN - there are some limitations (no UDP mode or LZO compression) https://wiki.mikrotik.com/wiki/Manua...
by tdw
Sun Oct 18, 2020 1:34 am
Forum: General
Topic: PPTP and Proxy Arp
Replies: 5
Views: 360

Re: PPTP and Proxy Arp

There are plenty of other VPNs available - plain IPsec, L2TP/IPsec, Open VPN, SSTP
by tdw
Sat Oct 17, 2020 10:29 pm
Forum: General
Topic: PPTP and Proxy Arp
Replies: 5
Views: 360

Re: PPTP and Proxy Arp

You may have used the same IP pool for VPN clients, but they do not use DHCP for address allocation. Proxy-arp should be enabled on the same local interface which has the IP address, so the parent bridge rather than the child ethernet and wireless interfaces. Enabling on an interface which has no IP...
by tdw
Fri Oct 16, 2020 10:33 pm
Forum: Beginner Basics
Topic: Building LAN from scratch: 4 mikrotiks - 4 networks
Replies: 15
Views: 685

Re: Building LAN from scratch: 4 mikrotiks - 4 networks

There are different approaches - you could route between subnets on mikrotik2-4 and have static routing rules on mikrotik1 so traffic is directed to the correct mikrotik, or you could use mikrotik2-4 as switches with VLANs and perform all of the routing/firewalling on mikrotik1 which is probably the...
by tdw
Fri Oct 16, 2020 10:19 pm
Forum: General
Topic: join 2 ports without dhcp
Replies: 2
Views: 244

Re: join 2 ports without dhcp

If you have a working setup with ether1 as WAN and ether2-5 in a bridge as LAN all you should have to do is remove ether5 from the bridge and add an IP address to that port. The mikrotik will route traffic between the two subnets, subject to firewall rules, but you will have to make changes to devic...
by tdw
Fri Oct 16, 2020 9:57 pm
Forum: General
Topic: router SSTP VPN Client connects and pings but does not route to JRC VPN
Replies: 21
Views: 784

Re: router SSTP VPN Client connects and pings but does not route to JRC VPN

You haven't said which model Mikrotik you have, there is a wide range of CPU capabilities. The best to worst performing VPN protocols supported are IPsec, OpenVPN, SSTP (I'm Ignoring PPTP and L2TP/MPPE which are insecure). Only some flavours of IPsec are supported with hardware acceleration on some ...
by tdw
Fri Oct 16, 2020 5:50 pm
Forum: General
Topic: Client isolation and proxy-arp
Replies: 12
Views: 633

Re: Client isolation and proxy-arp

I was looking for "easier" way than bridging ) As from manual, proxy-arp should exactly be it in my case. Not really, the examples do not have the same subnet on different interfaces. My scenario is that I host VMs for clients using both real and private IP space. Making /30 subnets for r...
by tdw
Fri Oct 16, 2020 4:51 pm
Forum: General
Topic: Client isolation and proxy-arp
Replies: 12
Views: 633

Re: Client isolation and proxy-arp

Using gateway=someinterface is only valid for point-to-point interfaces, and using the same subnet on different interfaces requires special handling.

Port isolation or bridge horizon would be a more usual approach for isolating clients within the same L2 network.
by tdw
Fri Oct 16, 2020 4:33 pm
Forum: General
Topic: router SSTP VPN Client connects and pings but does not route to JRC VPN
Replies: 21
Views: 784

Re: router SSTP VPN Client connects and pings but does not route to JRC VPN

I can't comment on how it appears in Webfig - in Winbox the equivalent control is either blank or "!", not a check mark. It doesn't select whether or not to use an interface, it means 'not' so out-interface="!JRC vpn" means traffic leaving by any interface other than JRC vpn - th...
by tdw
Thu Oct 15, 2020 7:36 pm
Forum: Beginner Basics
Topic: Vlans problem
Replies: 6
Views: 466

Re: Vlans problem

The text on the front of the Mikrotik is just text. The default configuration has port1 = WAN, ports 2-5 & SFP = LAN, but all can be reconfigured for any use. I vaguely recall that the UniFi SFP+ ports have to be configured as 1000FDX to work with gigabit optics - you will have to temporarily co...
by tdw
Thu Oct 15, 2020 7:26 pm
Forum: General
Topic: router SSTP VPN Client connects and pings but does not route to JRC VPN
Replies: 21
Views: 784

Re: router SSTP VPN Client connects and pings but does not route to JRC VPN

also copy and paste does not work in the terminal screen (firefox) Not sure why that would be, I use Winbox or SSH rather than the web interface. You can export the configuration to a file with /export hide-sensitive file=somefilename and then download the resulting .rsc file from Files - it is dra...
by tdw
Thu Oct 15, 2020 6:50 pm
Forum: General
Topic: Export config without MAC - automation
Replies: 1
Views: 204

Re: Export config without MAC - automation

Just remove the mac-address=xx:xx:xx:xx:xx:xx from your master config, a suitable MAC will be generated on the target when the configuration is applied
by tdw
Thu Oct 15, 2020 1:50 pm
Forum: Beginner Basics
Topic: Alternatives for RB450G router
Replies: 9
Views: 463

Re: Alternatives for RB450G router

Yes, they both come with RouterOS L5 licenses preinstalled
by tdw
Thu Oct 15, 2020 12:07 pm
Forum: General
Topic: router SSTP VPN Client connects and pings but does not route to JRC VPN
Replies: 21
Views: 784

Re: router SSTP VPN Client connects and pings but does not route to JRC VPN

It is difficult to tell the name of the VPN interface from screen shots, apparently not "JRC vpn" from the error message you got. Entering a rule via the web interface is fine, and traffic appears to be hitting it as the packet/byte counters are non-zero, so something else isn't quite righ...
by tdw
Thu Oct 15, 2020 11:35 am
Forum: Beginner Basics
Topic: Alternatives for RB450G router
Replies: 9
Views: 463

Re: Alternatives for RB450G router

I have another two routers which connected with RB450G. Those are RB951Ui-2HnD and RB2011UiAS routers which use MIPSBE architecture. Will there be nay issues if I replaced my RB450G router with RB450Gx4 since its is using ARM architecture? No. The connections between devices use standard ethernet a...
by tdw
Thu Oct 15, 2020 11:25 am
Forum: Beginner Basics
Topic: Alternatives for RB450G router
Replies: 9
Views: 463

Re: Alternatives for RB450G router

Information on exporting and importing configurations here https://wiki.mikrotik.com/wiki/Manual:C ... Management
by tdw
Thu Oct 15, 2020 1:35 am
Forum: General
Topic: router SSTP VPN Client connects and pings but does not route to JRC VPN
Replies: 21
Views: 784

Re: router SSTP VPN Client connects and pings but does not route to JRC VPN

With point-to-point interfaces you can specify the interface as a the gateway rather than an IP address. It correctly becomes disabled when the interface is down and active when the interface is up. That has not been my experience in the past, but admittedly, I haven't tried it in the last year or ...
by tdw
Thu Oct 15, 2020 1:32 am
Forum: General
Topic: router SSTP VPN Client connects and pings but does not route to JRC VPN
Replies: 21
Views: 784

Re: Progress! Thanks TDW. router SSTP VPN Client connects and pings but does not route to JRC VPN

Thats progress! thanks TDW. Added route. see attached. The route added is one UNDER "ADDED MANUALLY" The other route is created when the VPN connects and is not removable as it is dynamic. I tried. Good News: I can now ping from TERMINAL addresses other than and including the remote gatew...
by tdw
Thu Oct 15, 2020 1:12 am
Forum: General
Topic: router SSTP VPN Client connects and pings but does not route to JRC VPN
Replies: 21
Views: 784

Re: router SSTP VPN Client connects and pings but does not route to JRC VPN

You probably want the static route to be 192.168.5.0/24 via 192.168.5.10. The JRC vpn interface is dynamic and will disappear when it is down, causing your route to change to a next hop value of unknown, and it will not recover. Setting the next hop to an IP will simply disable the route when the t...
by tdw
Thu Oct 15, 2020 12:00 am
Forum: Beginner Basics
Topic: Alternatives for RB450G router
Replies: 9
Views: 463

Re: Alternatives for RB450G router

01. Is it possible to use RB450G router backup file with all other architectures like MMIPS,TILE,SMIPS and ARM? No. Even restoring a .backup file to the same model is not officially supported, although if running the same version of RouterOS it usually works. An exported .rsc file can be imported o...
by tdw
Wed Oct 14, 2020 11:38 pm
Forum: General
Topic: router SSTP VPN Client connects and pings but does not route to JRC VPN
Replies: 21
Views: 784

Re: router SSTP VPN Client connects and pings but does not route to JRC VPN

For your information the majority of forum support is by the community, not Mikrotik employees. The default route via the VPN is inactive (DS not DAS), other than for ECMP you cannot have more than one active route to the same destination. Given you only wish to route some traffic via the VPN, remov...
by tdw
Wed Oct 14, 2020 10:38 pm
Forum: General
Topic: Multiple hotspot profiles on multiple VLAN interfaces on a bridge
Replies: 17
Views: 1030

Re: Multiple hotspot profiles on multiple VLAN interfaces on a bridge

So a device connects to an SSID with WPA2-PSK, the traffic to/from it will be placed in a VLAN based upon the AP configuration. When the user successfully authenticates supplying a VLAN ID to the Mikrotik isn't going to move that traffic to another VLAN - it is fixed by the AP.
by tdw
Wed Oct 14, 2020 8:44 pm
Forum: General
Topic: Multiple hotspot profiles on multiple VLAN interfaces on a bridge
Replies: 17
Views: 1030

Re: Multiple hotspot profiles on multiple VLAN interfaces on a bridge

But how do devices get assigned to all of these VLANs if you use the same SSID everywhere. Managing MAC-based VLAN assignment will be time consuming if every single device needs adding.
by tdw
Wed Oct 14, 2020 7:11 pm
Forum: General
Topic: Multiple hotspot profiles on multiple VLAN interfaces on a bridge
Replies: 17
Views: 1030

Re: Multiple hotspot profiles on multiple VLAN interfaces on a bridge

CCRs don't have any hardware switching so bridge functions which disable hardware don't apply to them. Port isolation / private VLANs can be achieved with hardware switching, but I'm pretty sure there are strange interactions when also using switch chip VLAN filtering - the CRS3xx may be OK, but I h...
by tdw
Wed Oct 14, 2020 4:34 pm
Forum: General
Topic: Bridge VLAN Filter : not possible to use tagged traffic with VLAN ID = 1
Replies: 10
Views: 570

Re: Bridge VLAN Filter : not possible to use tagged traffic with VLAN ID = 1

I don't know if 7.x handles things differently to 6.x, but certainly with that all traffic within the bridge is tagged - untagging only occurs on egress for access and hybrid ports. When a port is added to a bridge the default is an access port with PVID 1, as with many other settings on Mikrotiks d...
by tdw
Wed Oct 14, 2020 3:51 pm
Forum: General
Topic: single ipv6 /64 range
Replies: 21
Views: 937

Re: single ipv6 /64 range

I've found https://www.ripe.net/publications/docs/ripe-690 covers the pros and cons of various WAN link addressing methods and prefix size suggestions, pity not all ISPs follow it. You can use the Mikrotik packet sniffer to capture traffic and stream it to Wireshark running on a computer which is of...
by tdw
Wed Oct 14, 2020 2:56 pm
Forum: General
Topic: Bridge VLAN Filter : not possible to use tagged traffic with VLAN ID = 1
Replies: 10
Views: 570

Re: Bridge VLAN Filter : not possible to use tagged traffic with VLAN ID = 1

The dynamic VLAN memberships are generated from the pvid= setting under /interface bridge port for access and hybrid ports, so if you have all the PVIDs set to something other than 1 there should be no dynamic entries with the value 1. Internally everything is tagged inside a VLAN-aware bridge, tags...
by tdw
Tue Oct 06, 2020 11:53 pm
Forum: General
Topic: Weird traffic
Replies: 6
Views: 422

Re: Weird traffic

So what can i do to stop that ? it's doing it even on static IPs, also when i restart router It's odd that you are seeing it from devices with static addresses. Using the packet sniffer rather than torch may reveal more. BIND on linux uses raw rather than IP sockets so traffic cannot be blocked by ...
by tdw
Tue Oct 06, 2020 11:45 pm
Forum: General
Topic: Network Lock Down
Replies: 6
Views: 553

Re: Network Lock Down

MAC addresses are easy to spoof, you should really be looking at 802.1x for wired and WPA2-Enterprise for wireless authentication against a RADIUS server Not always possible. Depends on the devices. If these devices have no "supplicant" embedded in their software, MAC-authentication is th...
by tdw
Tue Oct 06, 2020 11:03 pm
Forum: Beginner Basics
Topic: RB4011 VLAN + unifi [SOLVED]
Replies: 14
Views: 909

Re: RB4011 VLAN + unifi [SOLVED]

To the OP - the forum is not always like this, don't be put off by it if you have other issues you need help with.
by tdw
Tue Oct 06, 2020 10:44 pm
Forum: Beginner Basics
Topic: RouterOS/SwitchOS Test Result Questions
Replies: 6
Views: 422

Re: RouterOS/SwitchOS Test Result Questions

SwitchOS is quite limited and doesn't have any encrypted management access, for example. I would be tempted to use RouterOS with a hardware-assisted VLAN-aware bridge from the outset to minimise any disruptions if you needed to change in future. See https://wiki.mikrotik.com/wiki/Manual:Basic_VLAN_s...
by tdw
Tue Oct 06, 2020 9:50 pm
Forum: Beginner Basics
Topic: RB4011 VLAN + unifi [SOLVED]
Replies: 14
Views: 909

Re: RB4011 VLAN + unifi [SOLVED]

Erm, no. There is nothing preventing SSIDs or switch ports being assigned to the untagged network in UniFi, in fact you have to explicitly assign them to be tagged.
Then its not a switch its an abomination following no standards.
Exactly which standards prohibit that behaviour?
by tdw
Tue Oct 06, 2020 9:47 pm
Forum: Beginner Basics
Topic: RB4011 VLAN + unifi [SOLVED]
Replies: 14
Views: 909

Re: RB4011 VLAN + unifi [SOLVED]

For testing purposes, I connected a NAS to a port designated for the Corporate vlan (id =10). It properly received an IP from the appropriate pool (10.0.10.11) and I can ping it from my pc in the home vlan but am unable to access it. Am I missing a firewall rule that allows intervlan communication ...
by tdw
Tue Oct 06, 2020 9:41 pm
Forum: Beginner Basics
Topic: No pings over trunk
Replies: 2
Views: 204

Re: No pings over trunk

That is the old way of configuring VLANs, and doesn't work well with STP/RSTP see https://wiki.mikrotik.com/wiki/Manual:Layer2_misconfiguration#VLAN_in_bridge_with_a_physical_interface ConfigTX.rsc appears to have no IP configuration, so no way to way to ping it. ConfigRX.rsc has the IP addresses di...
by tdw
Tue Oct 06, 2020 9:26 pm
Forum: General
Topic: Weird traffic
Replies: 6
Views: 422

Re: Weird traffic

UDP port 67 & 68 are used for bootp and DHCP, devices will periodically renew their leases after half of the lease period.
by tdw
Tue Oct 06, 2020 8:25 pm
Forum: RouterBOARD hardware
Topic: Looking for passive 12V/1G PoE splitter on RB4011
Replies: 1
Views: 228

Re: Looking for passive 12V/1G PoE splitter on RB4011

Mikrotik have https://mikrotik.com/product/RBGPOE - it has a DC socket so you can use a gender converter if you need a plug.

There are quite a few other suppliers of gigabit passive converters such as https://www.poetexas.com/ plus many clones of their products.
by tdw
Tue Oct 06, 2020 7:24 pm
Forum: Beginner Basics
Topic: RB4011 VLAN + unifi [SOLVED]
Replies: 14
Views: 909

Re: RB4011 VLAN + unifi [SOLVED]

Okay if the goal is to pass VLAN 100 as untagged to the Ubiquiti so it gets an IP address on the VLAN100, you must realize that this prevents vlan 100 from being used at any other ports on the ubiquiti. The way to ensure vlan100 is available to be passed on to the other ports on the switch is to se...
by tdw
Tue Oct 06, 2020 6:04 pm
Forum: Beginner Basics
Topic: RB4011 VLAN + unifi [SOLVED]
Replies: 14
Views: 909

Re: RB4011 VLAN + unifi [SOLVED]

What? Why would ubiquiti need a hybrid port? That's they way they work. Out of the box APs and switches will acquire an IP address with DHCP (untagged, obviously) and attempt to connect to a controller using a number of layer 2 and layer 3 discovery mechanisms. If you have a setup with additional S...
by tdw
Tue Oct 06, 2020 4:22 pm
Forum: Beginner Basics
Topic: Interface / VLAN Configuration
Replies: 9
Views: 543

Re: Interface / VLAN Configuration

You haven't changed the VLAN interfaces to the parent which can cause odd behaviour: /interface vlan add interface= TRUNK LAN name=IOT vlan-id=20 /interface vlan add interface= TRUNK LAN name=MGMT vlan-id=10 /interface vlan add interface= TRUNK LAN name=UPC vlan-id=100 I would remove the switch chip...