Community discussions

MikroTik App

Search found 515 matches

  • 1
  • 2
by tdw
Sun Oct 25, 2020 4:33 pm
Forum: Beginner Basics
Topic: 750G download speed very slow
Replies: 21
Views: 583

Re: 750G download speed very slow

MMIPS for 750G, Long term version. MMIPS is only for the 750Gr3 (second version of the hEX). The original 750G, which the OP has, and the 750Gr2 (first version of the hEX) are MIPSBE. The /system routerboard settings set cpu-frequency=150MHz will be reducing the performance, it should be several ti...
by tdw
Fri Oct 23, 2020 7:05 pm
Forum: General
Topic: "Holy war" against masquerade and ike2 dynamic ip address on your wan interface
Replies: 8
Views: 383

Re: "Holy war" against masquerade and ike2 dynamic ip address on your wan interface

You might be able to use/abuse /routing filter to modify dynamically added routes.
by tdw
Thu Oct 22, 2020 2:57 pm
Forum: General
Topic: Optical cable and SFP advice
Replies: 6
Views: 299

Re: Optical cable and SFP advice

There is stretched up optical cable already(label on cable is: SC simplex 2.0 mm OFNR That does not tell you the type of fibre - SC is the type of plug, simplex is single fibre, 2.0mm OFNR is the diameter and and fire rating of the cable. You need to know if the fibre is single mode or multimode, a...
by tdw
Thu Oct 22, 2020 2:22 pm
Forum: Beginner Basics
Topic: Mikrotik as VPN Server in existing network
Replies: 3
Views: 177

Re: Mikrotik as VPN Server in existing network

I want the vpn clients to have an ip from the main dhcp server. That isn't going to happen unless you use a layer 2 VPN (so OpenVPN TAP or Mikrotik-to-Mikrotik EoIP). Whilst layer 3 VPNs (OpenVPN TUN, SSTP, L2TP/IPsec, etc.) can be used with proxy-arp so the VPN clients can appear to be part of a l...
by tdw
Tue Oct 20, 2020 1:44 pm
Forum: General
Topic: Microtik and AD
Replies: 3
Views: 200

Re: Microtik and AD

For clients to resolve hosts in your AD you have to use your DC as their DNS server. The DC itself should act as a recursive resolver for any other DNS requests.
by tdw
Tue Oct 20, 2020 2:58 am
Forum: Beginner Basics
Topic: Pools, VPNs, and profiles
Replies: 6
Views: 230

Re: Pools, VPNs, and profiles

If the VPN is for remote access rather than shifting large amounts of data you should be OK, there are plenty of articles covering the issue on the internet if you search for 'tcp meltdown' or 'tcp over tcp problem'. We have a number of Mikrotiks running L2TP/IPsec (permanent site-to-site with stati...
by tdw
Tue Oct 20, 2020 2:32 am
Forum: Beginner Basics
Topic: Pools, VPNs, and profiles
Replies: 6
Views: 230

Re: Pools, VPNs, and profiles

What can we do if we want to use OpenVPN on MikroTik when it lacks UDP?
The Mikrotik implementation only supports TCP for the VPN client to server connection itself (I believe UDP has been added in RouterOS 7), the VPN tunnel handles any layer 3 payload in IP / TUN mode.
by tdw
Tue Oct 20, 2020 1:39 am
Forum: Beginner Basics
Topic: Pools, VPNs, and profiles
Replies: 6
Views: 230

Re: Pools, VPNs, and profiles

I was thinking the server address should be in the same subnet as the pool, but it doesn't seem to care. It doesn't have to be. VPNs are point-to-point tunnels with a /32 address at either end, they can be pretty much anything. I'm about to add an OpenVPN server, as well, mainly to overcome the lac...
by tdw
Mon Oct 19, 2020 6:28 pm
Forum: Beginner Basics
Topic: DHCP on physical interface comes out invalid using Wizard
Replies: 6
Views: 228

Re: DHCP on physical interface comes out invalid using Wizard

Do you have anything plugged in to ether9? If a DHCP server is bound to an interface in the non-running state it appears in red in Winbox / with an invalid flag in /ip dhcp-server print even though it isn't. Physical and some logical interfaces (e.g. VPN tunnels) follow the state of the underlying c...
by tdw
Mon Oct 19, 2020 3:53 pm
Forum: General
Topic: VLAN DHCP on MAIN router not working to WLAN on AP [SOLVED]
Replies: 13
Views: 484

Re: VLAN DHCP on MAIN router not working to WLAN on AP [SOLVED]

If a bridge has vlan-filtering=yes only untagged traffic will pass through the bridge ports. However, if vlan-filtering=no the bridge behaves similarly to an unmanaged switch so any VLAN tagged traffic will pass through all bridge ports.
by tdw
Mon Oct 19, 2020 3:36 pm
Forum: General
Topic: VLAN DHCP on MAIN router not working to WLAN on AP [SOLVED]
Replies: 13
Views: 484

Re: VLAN DHCP on MAIN router not working to WLAN on AP [SOLVED]

You need to specify which tagged VLANs are made available to the various bridge ports, including the bridge itself as a bridge has two roles - a switch-like role for transporting packets between ports, and a port-like role for transporting packets between the bridge and other functions provided by t...
by tdw
Mon Oct 19, 2020 2:42 pm
Forum: General
Topic: VLAN DHCP on MAIN router not working to WLAN on AP [SOLVED]
Replies: 13
Views: 484

Re: VLAN DHCP on MAIN router not working to WLAN on AP [SOLVED]

You have set the bridge to be VLAN-aware but not configured any bridge VLANs, so no tagged traffic will pass through the bridge. See https://wiki.mikrotik.com/wiki/Manual:I ... _Filtering
by tdw
Mon Oct 19, 2020 12:01 pm
Forum: General
Topic: EiOP in Bridge -TCP problem [SOLVED]
Replies: 3
Views: 192

Re: EiOP in Bridge -TCP problem [SOLVED]

You must change the EOIP interface MTU to 1500
by tdw
Sun Oct 18, 2020 8:08 pm
Forum: General
Topic: PPTP and Proxy Arp
Replies: 5
Views: 247

Re: PPTP and Proxy Arp

All of those I mentioned have both client and server support: https://wiki.mikrotik.com/wiki/Manual:IP/IPsec - there are some examples in section 17 https://wiki.mikrotik.com/wiki/Manual:Interface/OVPN - there are some limitations (no UDP mode or LZO compression) https://wiki.mikrotik.com/wiki/Manua...
by tdw
Sun Oct 18, 2020 1:34 am
Forum: General
Topic: PPTP and Proxy Arp
Replies: 5
Views: 247

Re: PPTP and Proxy Arp

There are plenty of other VPNs available - plain IPsec, L2TP/IPsec, Open VPN, SSTP
by tdw
Sat Oct 17, 2020 10:29 pm
Forum: General
Topic: PPTP and Proxy Arp
Replies: 5
Views: 247

Re: PPTP and Proxy Arp

You may have used the same IP pool for VPN clients, but they do not use DHCP for address allocation. Proxy-arp should be enabled on the same local interface which has the IP address, so the parent bridge rather than the child ethernet and wireless interfaces. Enabling on an interface which has no IP...
by tdw
Fri Oct 16, 2020 10:33 pm
Forum: Beginner Basics
Topic: Building LAN from scratch: 4 mikrotiks - 4 networks
Replies: 15
Views: 448

Re: Building LAN from scratch: 4 mikrotiks - 4 networks

There are different approaches - you could route between subnets on mikrotik2-4 and have static routing rules on mikrotik1 so traffic is directed to the correct mikrotik, or you could use mikrotik2-4 as switches with VLANs and perform all of the routing/firewalling on mikrotik1 which is probably the...
by tdw
Fri Oct 16, 2020 10:19 pm
Forum: General
Topic: join 2 ports without dhcp
Replies: 2
Views: 187

Re: join 2 ports without dhcp

If you have a working setup with ether1 as WAN and ether2-5 in a bridge as LAN all you should have to do is remove ether5 from the bridge and add an IP address to that port. The mikrotik will route traffic between the two subnets, subject to firewall rules, but you will have to make changes to devic...
by tdw
Fri Oct 16, 2020 9:57 pm
Forum: General
Topic: router SSTP VPN Client connects and pings but does not route to JRC VPN
Replies: 21
Views: 514

Re: router SSTP VPN Client connects and pings but does not route to JRC VPN

You haven't said which model Mikrotik you have, there is a wide range of CPU capabilities. The best to worst performing VPN protocols supported are IPsec, OpenVPN, SSTP (I'm Ignoring PPTP and L2TP/MPPE which are insecure). Only some flavours of IPsec are supported with hardware acceleration on some ...
by tdw
Fri Oct 16, 2020 5:50 pm
Forum: General
Topic: Client isolation and proxy-arp
Replies: 12
Views: 449

Re: Client isolation and proxy-arp

I was looking for "easier" way than bridging ) As from manual, proxy-arp should exactly be it in my case. Not really, the examples do not have the same subnet on different interfaces. My scenario is that I host VMs for clients using both real and private IP space. Making /30 subnets for real IP spa...
by tdw
Fri Oct 16, 2020 4:51 pm
Forum: General
Topic: Client isolation and proxy-arp
Replies: 12
Views: 449

Re: Client isolation and proxy-arp

Using gateway=someinterface is only valid for point-to-point interfaces, and using the same subnet on different interfaces requires special handling.

Port isolation or bridge horizon would be a more usual approach for isolating clients within the same L2 network.
by tdw
Fri Oct 16, 2020 4:33 pm
Forum: General
Topic: router SSTP VPN Client connects and pings but does not route to JRC VPN
Replies: 21
Views: 514

Re: router SSTP VPN Client connects and pings but does not route to JRC VPN

I can't comment on how it appears in Webfig - in Winbox the equivalent control is either blank or "!", not a check mark. It doesn't select whether or not to use an interface, it means 'not' so out-interface="!JRC vpn" means traffic leaving by any interface other than JRC vpn - the reverse of what wa...
by tdw
Thu Oct 15, 2020 7:36 pm
Forum: Beginner Basics
Topic: Vlans problem
Replies: 6
Views: 341

Re: Vlans problem

The text on the front of the Mikrotik is just text. The default configuration has port1 = WAN, ports 2-5 & SFP = LAN, but all can be reconfigured for any use. I vaguely recall that the UniFi SFP+ ports have to be configured as 1000FDX to work with gigabit optics - you will have to temporarily connec...
by tdw
Thu Oct 15, 2020 7:26 pm
Forum: General
Topic: router SSTP VPN Client connects and pings but does not route to JRC VPN
Replies: 21
Views: 514

Re: router SSTP VPN Client connects and pings but does not route to JRC VPN

also copy and paste does not work in the terminal screen (firefox) Not sure why that would be, I use Winbox or SSH rather than the web interface. You can export the configuration to a file with /export hide-sensitive file=somefilename and then download the resulting .rsc file from Files - it is dra...
by tdw
Thu Oct 15, 2020 6:50 pm
Forum: General
Topic: Export config without MAC - automation
Replies: 1
Views: 141

Re: Export config without MAC - automation

Just remove the mac-address=xx:xx:xx:xx:xx:xx from your master config, a suitable MAC will be generated on the target when the configuration is applied
by tdw
Thu Oct 15, 2020 1:50 pm
Forum: Beginner Basics
Topic: Alternatives for RB450G router
Replies: 9
Views: 269

Re: Alternatives for RB450G router

Yes, they both come with RouterOS L5 licenses preinstalled
by tdw
Thu Oct 15, 2020 12:07 pm
Forum: General
Topic: router SSTP VPN Client connects and pings but does not route to JRC VPN
Replies: 21
Views: 514

Re: router SSTP VPN Client connects and pings but does not route to JRC VPN

It is difficult to tell the name of the VPN interface from screen shots, apparently not "JRC vpn" from the error message you got. Entering a rule via the web interface is fine, and traffic appears to be hitting it as the packet/byte counters are non-zero, so something else isn't quite right. The bes...
by tdw
Thu Oct 15, 2020 11:35 am
Forum: Beginner Basics
Topic: Alternatives for RB450G router
Replies: 9
Views: 269

Re: Alternatives for RB450G router

I have another two routers which connected with RB450G. Those are RB951Ui-2HnD and RB2011UiAS routers which use MIPSBE architecture. Will there be nay issues if I replaced my RB450G router with RB450Gx4 since its is using ARM architecture? No. The connections between devices use standard ethernet a...
by tdw
Thu Oct 15, 2020 11:25 am
Forum: Beginner Basics
Topic: Alternatives for RB450G router
Replies: 9
Views: 269

Re: Alternatives for RB450G router

Information on exporting and importing configurations here https://wiki.mikrotik.com/wiki/Manual:C ... Management
by tdw
Thu Oct 15, 2020 1:35 am
Forum: General
Topic: router SSTP VPN Client connects and pings but does not route to JRC VPN
Replies: 21
Views: 514

Re: router SSTP VPN Client connects and pings but does not route to JRC VPN

With point-to-point interfaces you can specify the interface as a the gateway rather than an IP address. It correctly becomes disabled when the interface is down and active when the interface is up. That has not been my experience in the past, but admittedly, I haven't tried it in the last year or ...
by tdw
Thu Oct 15, 2020 1:32 am
Forum: General
Topic: router SSTP VPN Client connects and pings but does not route to JRC VPN
Replies: 21
Views: 514

Re: Progress! Thanks TDW. router SSTP VPN Client connects and pings but does not route to JRC VPN

Thats progress! thanks TDW. Added route. see attached. The route added is one UNDER "ADDED MANUALLY" The other route is created when the VPN connects and is not removable as it is dynamic. I tried. Good News: I can now ping from TERMINAL addresses other than and including the remote gateway. You li...
by tdw
Thu Oct 15, 2020 1:12 am
Forum: General
Topic: router SSTP VPN Client connects and pings but does not route to JRC VPN
Replies: 21
Views: 514

Re: router SSTP VPN Client connects and pings but does not route to JRC VPN

You probably want the static route to be 192.168.5.0/24 via 192.168.5.10. The JRC vpn interface is dynamic and will disappear when it is down, causing your route to change to a next hop value of unknown, and it will not recover. Setting the next hop to an IP will simply disable the route when the t...
by tdw
Thu Oct 15, 2020 12:00 am
Forum: Beginner Basics
Topic: Alternatives for RB450G router
Replies: 9
Views: 269

Re: Alternatives for RB450G router

01. Is it possible to use RB450G router backup file with all other architectures like MMIPS,TILE,SMIPS and ARM? No. Even restoring a .backup file to the same model is not officially supported, although if running the same version of RouterOS it usually works. An exported .rsc file can be imported o...
by tdw
Wed Oct 14, 2020 11:38 pm
Forum: General
Topic: router SSTP VPN Client connects and pings but does not route to JRC VPN
Replies: 21
Views: 514

Re: router SSTP VPN Client connects and pings but does not route to JRC VPN

For your information the majority of forum support is by the community, not Mikrotik employees. The default route via the VPN is inactive (DS not DAS), other than for ECMP you cannot have more than one active route to the same destination. Given you only wish to route some traffic via the VPN, remov...
by tdw
Wed Oct 14, 2020 10:38 pm
Forum: General
Topic: Multiple hotspot profiles on multiple VLAN interfaces on a bridge
Replies: 17
Views: 610

Re: Multiple hotspot profiles on multiple VLAN interfaces on a bridge

So a device connects to an SSID with WPA2-PSK, the traffic to/from it will be placed in a VLAN based upon the AP configuration. When the user successfully authenticates supplying a VLAN ID to the Mikrotik isn't going to move that traffic to another VLAN - it is fixed by the AP.
by tdw
Wed Oct 14, 2020 8:44 pm
Forum: General
Topic: Multiple hotspot profiles on multiple VLAN interfaces on a bridge
Replies: 17
Views: 610

Re: Multiple hotspot profiles on multiple VLAN interfaces on a bridge

But how do devices get assigned to all of these VLANs if you use the same SSID everywhere. Managing MAC-based VLAN assignment will be time consuming if every single device needs adding.
by tdw
Wed Oct 14, 2020 7:11 pm
Forum: General
Topic: Multiple hotspot profiles on multiple VLAN interfaces on a bridge
Replies: 17
Views: 610

Re: Multiple hotspot profiles on multiple VLAN interfaces on a bridge

CCRs don't have any hardware switching so bridge functions which disable hardware don't apply to them. Port isolation / private VLANs can be achieved with hardware switching, but I'm pretty sure there are strange interactions when also using switch chip VLAN filtering - the CRS3xx may be OK, but I h...
by tdw
Wed Oct 14, 2020 4:34 pm
Forum: General
Topic: Bridge VLAN Filter : not possible to use tagged traffic with VLAN ID = 1
Replies: 10
Views: 348

Re: Bridge VLAN Filter : not possible to use tagged traffic with VLAN ID = 1

I don't know if 7.x handles things differently to 6.x, but certainly with that all traffic within the bridge is tagged - untagging only occurs on egress for access and hybrid ports. When a port is added to a bridge the default is an access port with PVID 1, as with many other settings on Mikrotiks d...
by tdw
Wed Oct 14, 2020 3:51 pm
Forum: General
Topic: single ipv6 /64 range
Replies: 21
Views: 658

Re: single ipv6 /64 range

I've found https://www.ripe.net/publications/docs/ripe-690 covers the pros and cons of various WAN link addressing methods and prefix size suggestions, pity not all ISPs follow it. You can use the Mikrotik packet sniffer to capture traffic and stream it to Wireshark running on a computer which is of...
by tdw
Wed Oct 14, 2020 2:56 pm
Forum: General
Topic: Bridge VLAN Filter : not possible to use tagged traffic with VLAN ID = 1
Replies: 10
Views: 348

Re: Bridge VLAN Filter : not possible to use tagged traffic with VLAN ID = 1

The dynamic VLAN memberships are generated from the pvid= setting under /interface bridge port for access and hybrid ports, so if you have all the PVIDs set to something other than 1 there should be no dynamic entries with the value 1. Internally everything is tagged inside a VLAN-aware bridge, tags...
by tdw
Tue Oct 06, 2020 11:53 pm
Forum: General
Topic: Weird traffic
Replies: 6
Views: 335

Re: Weird traffic

So what can i do to stop that ? it's doing it even on static IPs, also when i restart router It's odd that you are seeing it from devices with static addresses. Using the packet sniffer rather than torch may reveal more. BIND on linux uses raw rather than IP sockets so traffic cannot be blocked by ...
by tdw
Tue Oct 06, 2020 11:45 pm
Forum: General
Topic: Network Lock Down
Replies: 6
Views: 365

Re: Network Lock Down

MAC addresses are easy to spoof, you should really be looking at 802.1x for wired and WPA2-Enterprise for wireless authentication against a RADIUS server Not always possible. Depends on the devices. If these devices have no "supplicant" embedded in their software, MAC-authentication is the best thi...
by tdw
Tue Oct 06, 2020 11:03 pm
Forum: Beginner Basics
Topic: RB4011 VLAN + unifi [SOLVED]
Replies: 14
Views: 523

Re: RB4011 VLAN + unifi [SOLVED]

To the OP - the forum is not always like this, don't be put off by it if you have other issues you need help with.
by tdw
Tue Oct 06, 2020 10:44 pm
Forum: Beginner Basics
Topic: RouterOS/SwitchOS Test Result Questions
Replies: 6
Views: 290

Re: RouterOS/SwitchOS Test Result Questions

SwitchOS is quite limited and doesn't have any encrypted management access, for example. I would be tempted to use RouterOS with a hardware-assisted VLAN-aware bridge from the outset to minimise any disruptions if you needed to change in future. See https://wiki.mikrotik.com/wiki/Manual:Basic_VLAN_s...
by tdw
Tue Oct 06, 2020 9:50 pm
Forum: Beginner Basics
Topic: RB4011 VLAN + unifi [SOLVED]
Replies: 14
Views: 523

Re: RB4011 VLAN + unifi [SOLVED]

Erm, no. There is nothing preventing SSIDs or switch ports being assigned to the untagged network in UniFi, in fact you have to explicitly assign them to be tagged.
Then its not a switch its an abomination following no standards.
Exactly which standards prohibit that behaviour?
by tdw
Tue Oct 06, 2020 9:47 pm
Forum: Beginner Basics
Topic: RB4011 VLAN + unifi [SOLVED]
Replies: 14
Views: 523

Re: RB4011 VLAN + unifi [SOLVED]

For testing purposes, I connected a NAS to a port designated for the Corporate vlan (id =10). It properly received an IP from the appropriate pool (10.0.10.11) and I can ping it from my pc in the home vlan but am unable to access it. Am I missing a firewall rule that allows intervlan communication ...
by tdw
Tue Oct 06, 2020 9:41 pm
Forum: Beginner Basics
Topic: No pings over trunk
Replies: 2
Views: 132

Re: No pings over trunk

That is the old way of configuring VLANs, and doesn't work well with STP/RSTP see https://wiki.mikrotik.com/wiki/Manual:Layer2_misconfiguration#VLAN_in_bridge_with_a_physical_interface ConfigTX.rsc appears to have no IP configuration, so no way to way to ping it. ConfigRX.rsc has the IP addresses di...
by tdw
Tue Oct 06, 2020 9:26 pm
Forum: General
Topic: Weird traffic
Replies: 6
Views: 335

Re: Weird traffic

UDP port 67 & 68 are used for bootp and DHCP, devices will periodically renew their leases after half of the lease period.
by tdw
Tue Oct 06, 2020 8:25 pm
Forum: RouterBOARD hardware
Topic: Looking for passive 12V/1G PoE splitter on RB4011
Replies: 1
Views: 127

Re: Looking for passive 12V/1G PoE splitter on RB4011

Mikrotik have https://mikrotik.com/product/RBGPOE - it has a DC socket so you can use a gender converter if you need a plug.

There are quite a few other suppliers of gigabit passive converters such as https://www.poetexas.com/ plus many clones of their products.
by tdw
Tue Oct 06, 2020 7:24 pm
Forum: Beginner Basics
Topic: RB4011 VLAN + unifi [SOLVED]
Replies: 14
Views: 523

Re: RB4011 VLAN + unifi [SOLVED]

Okay if the goal is to pass VLAN 100 as untagged to the Ubiquiti so it gets an IP address on the VLAN100, you must realize that this prevents vlan 100 from being used at any other ports on the ubiquiti. The way to ensure vlan100 is available to be passed on to the other ports on the switch is to se...
by tdw
Tue Oct 06, 2020 6:04 pm
Forum: Beginner Basics
Topic: RB4011 VLAN + unifi [SOLVED]
Replies: 14
Views: 523

Re: RB4011 VLAN + unifi [SOLVED]

What? Why would ubiquiti need a hybrid port? That's they way they work. Out of the box APs and switches will acquire an IP address with DHCP (untagged, obviously) and attempt to connect to a controller using a number of layer 2 and layer 3 discovery mechanisms. If you have a setup with additional S...
by tdw
Tue Oct 06, 2020 4:22 pm
Forum: Beginner Basics
Topic: Interface / VLAN Configuration
Replies: 9
Views: 349

Re: Interface / VLAN Configuration

You haven't changed the VLAN interfaces to the parent which can cause odd behaviour: /interface vlan add interface= TRUNK LAN name=IOT vlan-id=20 /interface vlan add interface= TRUNK LAN name=MGMT vlan-id=10 /interface vlan add interface= TRUNK LAN name=UPC vlan-id=100 I would remove the switch chip...
by tdw
Tue Oct 06, 2020 2:08 pm
Forum: Beginner Basics
Topic: Interface / VLAN Configuration
Replies: 9
Views: 349

Re: Interface / VLAN Configuration

Still the device which I attached to ether1 is not reachable with pvid10 and is stated as "disabled port" via winbox. Did I miss something? Presumably that is in the Role column on Bridge > Ports. What is the status (the column to the left of the Interface one)? The output of /interface ethernet pr...
by tdw
Tue Oct 06, 2020 1:37 pm
Forum: Beginner Basics
Topic: Interface / VLAN Configuration
Replies: 9
Views: 349

Re: Interface / VLAN Configuration

Most of that is incorrect. You don't say which model Mikrotik, so I'm assuming a 2011/3011/4011 as there are ten ethernet ports and an SFP mentioned - the full reference for VLAN-aware bridges for non-CRS devices is here https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filtering Fi...
by tdw
Mon Oct 05, 2020 7:50 pm
Forum: Beginner Basics
Topic: RB4011 VLAN + unifi [SOLVED]
Replies: 14
Views: 523

Re: RB4011 VLAN + unifi [SOLVED]

For Ubiquiti devices you need a hybrid rather than trunk port with your Home VLAN set as the PVID, it is worth turning on ingress filtering on all of the interfaces to prevent devices injecting any other tagged packets they like: /interface bridge port add bridge=bridgeNET ingress-filtering=yes inte...
by tdw
Mon Oct 05, 2020 7:28 pm
Forum: General
Topic: [VLAN] Set a port to untagged using switch chip
Replies: 17
Views: 775

Re: [VLAN] Set a port to untagged using switch chip

VLANs creations under Bridge Management (VLAN1 is hidden, right?) Sort of. A bridge has two roles, one switch-like connecting interfaces together, the other an interface-like one to access services within the Mikrotik (routing, DHCP, etc.). Whilst VLAN ID 1 is used within the switch-like part it is...
by tdw
Mon Oct 05, 2020 6:37 pm
Forum: General
Topic: Log pppoe,info
Replies: 1
Views: 108

Re: Log pppoe,info

It is some client device (A8:BF:3C is registered to HDV Phoelectron Technology Limited) connected to your layer2 / ethernet network attempting to make a PPPoE connection. If you have a PPPoE server for several ports bridged together you will have to check the bridge hosts table, or use torch / packe...
by tdw
Sun Oct 04, 2020 9:10 pm
Forum: General
Topic: Network Lock Down
Replies: 6
Views: 365

Re: Network Lock Down

MAC addresses are easy to spoof, you should really be looking at 802.1x for wired and WPA2-Enterprise for wireless authentication against a RADIUS server
by tdw
Fri Oct 02, 2020 2:11 pm
Forum: Beginner Basics
Topic: Inner DNS server doesn't resolve domain names for hotspot users
Replies: 15
Views: 461

Re: Inner DNS server doesn't resolve domain names for hotspot users

The DNS lookups via the Mikrotik and your bind server appear to be working as expected. The N hazartilirot-pc unknown 0.0.0.0 cached record shows that the upstream DNS server (your BIND server) replied with NXDOMAIN so the type and data fields have no value, hence the suggestion to check the BIND se...
by tdw
Fri Oct 02, 2020 1:38 am
Forum: Beginner Basics
Topic: Inner DNS server doesn't resolve domain names for hotspot users
Replies: 15
Views: 461

Re: Inner DNS server doesn't resolve domain names for hotspot users

That looks OK, the WAN DHCP client does not use any DNS servers offered and 192.168.10.252 is specified as an upstream DNS server, although without seeing the configuration it is difficult to say if there is anything else which could interfere. The DHCP setup for the 192.168.20.0/24 network should o...
by tdw
Fri Oct 02, 2020 12:18 am
Forum: Beginner Basics
Topic: Inner DNS server doesn't resolve domain names for hotspot users
Replies: 15
Views: 461

Re: Inner DNS server doesn't resolve domain names for hotspot users

The Mikrotik hotspot redirects any DNS requests from hotspot clients to the Mikrotik itself. This happens quite early in the firewall chains so the walled garden or walled garden IP functions may occur too late. Is there any reason you can't set the Mikrotik itself to use your DNS server?
by tdw
Thu Oct 01, 2020 2:32 pm
Forum: Beginner Basics
Topic: Bridge and VLANs configuration
Replies: 7
Views: 511

Re: Bridge and VLANs configuration

A bridge has two distinct roles - both a switch connecting ports together, and an interface connecting bridge traffic to services (routing, DHCP, etc) on the Mikrotik itself. You haven't included the interface role in your bridge VLAN statements, so: /interface bridge vlan add bridge=bridge-LAN tagg...
by tdw
Mon Sep 28, 2020 7:18 pm
Forum: Beginner Basics
Topic: HAP AC - L2TP - Funny NAT issue
Replies: 4
Views: 527

Re: HAP AC - L2TP - Funny NAT issue

Once an entry exists in the connection tracking table, along with any associated NAT flags, that's it until the connection is closed. UDP connection tracking is tricky - as there is no equivalent of the TCP FIN flag to peek at, the "connection" is deemed to exist until no matching packets are seen f...
by tdw
Sat Sep 26, 2020 12:56 pm
Forum: General
Topic: Mikrotik to replace our faulty Cisco core switch
Replies: 6
Views: 515

Re: Mikrotik to replace our faulty Cisco core switch

The OP was specifically asking about inter-VLAN routing performance. The CRS devices are ill-suited to that role as they are primarily designed as layer2 switches with limited layer3 support. Although there is tentative support for layer3 hardware offloading in RouterOS 7 for a handful for CRS3xx de...
by tdw
Thu Sep 24, 2020 6:12 pm
Forum: Beginner Basics
Topic: VLAN Client Isolation
Replies: 10
Views: 775

Re: VLAN Client Isolation

By default firewall rules will only act on routed, not bridged, traffic. You could use the use-ip-firewall=yes and use-ip-firewall-for-vlan=yes under /interface bridge settings to force the bridged traffic within a VLAN to be processed too, alternatively a bridge filter or bridge split horizon. Note...
by tdw
Thu Sep 24, 2020 2:56 pm
Forum: Beginner Basics
Topic: Can't add Unifi Switch
Replies: 4
Views: 320

Re: Can't add Unifi Switch

I've not had any problems mixing Mikrotik and UniFi. One site is similar to yours with an RB750Gr3 connected to a US-8-60W, both with the default ethernet port settings and a regular network cable, the switch obtains an address with DHCP and appeared in a remotely located controller using the DNS la...
by tdw
Thu Sep 24, 2020 2:07 pm
Forum: Beginner Basics
Topic: Generating QinQ test traffic with Ethertype 0x88a8
Replies: 3
Views: 233

Re: Generating QinQ test traffic with Ethertype 0x88a8

Adding use-service-tag=yes to a vlan interface statement changes the ethertype from 0x8100 to 0x88a8.
by tdw
Thu Sep 24, 2020 1:57 pm
Forum: General
Topic: VLAN Issues
Replies: 7
Views: 477

Re: VLAN Issues

Switching to RSTP would depend on your core network - it isn't suitable for network topologies which pass groups of VLANs along differing redundant paths, you would have to use MSTP which the CRS3xx also support without loosing hardware offloading. As you don't particularly need spanning tree in thi...
by tdw
Thu Sep 24, 2020 1:21 am
Forum: General
Topic: L2tp+bcp+ipsec not working
Replies: 7
Views: 542

Re: L2tp+bcp+ipsec not working

As you must be able to support 1500 byte MTU for BCP to work properly there is bound to be fragmentation somewhere. The L2TP MRU/MTU needs to be smaller than 1450 so there isn't nested fragmentation for both L2TP/IPsec traffic and the BCP payload - I've not found a definitive calculation, others on ...
by tdw
Wed Sep 23, 2020 7:18 pm
Forum: General
Topic: Multicasting inside VLAN, CRS 1xx
Replies: 4
Views: 298

Re: Multicasting inside VLAN, CRS 1xx

You could try asking Mikrotik support directly if they ever intend adding this functionality.
by tdw
Wed Sep 23, 2020 6:20 pm
Forum: General
Topic: VLAN Issues
Replies: 7
Views: 477

Re: VLAN Issues

For info Cisco trunks with a native VLAN, e.g. interface SOMEPORT switchport trunk encapsulation dot1q switchport trunk native vlan R switchport trunk allowed vlan R , S , T switchport mode trunk translates to /interface bridge port add bridge=bridge ingress-filtering=yes interface= PORTNAME pvid= R...
by tdw
Wed Sep 23, 2020 5:51 pm
Forum: General
Topic: VLAN Issues
Replies: 7
Views: 477

Re: VLAN Issues

Firstly the Mikrotik bridge is currently operating as an unmanaged switch, the pvid= settings in the /interface bridge port section and all of the /interface bridge vlan section are ignored until the bridge has the vlan-filtering=yes setting. It appears you have also deleted some interfaces which ha...
by tdw
Wed Sep 23, 2020 3:59 pm
Forum: General
Topic: Multicasting inside VLAN, CRS 1xx
Replies: 4
Views: 298

Re: Multicasting inside VLAN, CRS 1xx

According to https://wiki.mikrotik.com/wiki/Manual:I ... Offloading although CRS1xx/CRS2xx series support bridge IGMP snooping there is a note which states "Feature will not work properly in VLAN switching setups"
by tdw
Wed Sep 23, 2020 2:21 pm
Forum: Beginner Basics
Topic: VLAN Gateway IP not pingable and thus no routing.
Replies: 4
Views: 239

Re: VLAN Gateway IP not pingable and thus no routing.

A bridge has two distinct roles - both a switch connecting ports together, and an interface connecting bridge traffic to services (routing, DHCP, etc) on the Mikrotik itself. You haven't included the interface role in your bridge VLAN statements. Also you have a mismatch between tagged and untagged ...
by tdw
Wed Sep 23, 2020 12:56 pm
Forum: General
Topic: VLAN Issues
Replies: 7
Views: 477

Re: VLAN Issues

Post the output of /export hide-sensitive, preferably in a code block (the square brackets icon) to make it more readable.
by tdw
Mon Sep 21, 2020 11:55 pm
Forum: General
Topic: PPPoE creation and PPPoE scan
Replies: 7
Views: 425

Re: PPPoE creation and PPPoE scan

I would not expect binding multiple servers to the same interface to work as only one can listen to the PPPoE ethertypes, multiple servers each on a different interface is fine. Why are your attempting to run multiple services on the same interface as any parameters can be set in the client PPP secr...
by tdw
Sun Sep 20, 2020 6:17 pm
Forum: General
Topic: Weird routing problem [SOLVED]
Replies: 18
Views: 1276

Re: Weird routing problem [SOLVED]

The IP addresses should be applied to the bridge, not any of the member ports as this breaks things in odd ways.
by tdw
Sun Sep 20, 2020 6:12 pm
Forum: Beginner Basics
Topic: Configure CRS328-24P-4S+RM Initial config?
Replies: 14
Views: 635

Re: Configure CRS328-24P-4S+RM Initial config?

You have /interface bridge port add bridge=bridge1 interface=ether1 hw=yes comment=WiFi add bridge=bridge1 interface=ether2 hw=yes comment=WiFi add bridge=bridge1 interface=ether3 hw=yes comment=WiFi add bridge=bridge1 interface=ether4 hw=yes pvid=10 comment=NAS add bridge=bridge1 interface=ether5 h...
by tdw
Sun Sep 20, 2020 5:28 pm
Forum: General
Topic: Weird routing problem [SOLVED]
Replies: 18
Views: 1276

Re: Weird routing problem [SOLVED]

Without seeing the actual configurations rather than what you believe you have configured it is impossible to say.
by tdw
Sun Sep 20, 2020 5:26 pm
Forum: Beginner Basics
Topic: Configure CRS328-24P-4S+RM Initial config?
Replies: 14
Views: 635

Re: Configure CRS328-24P-4S+RM Initial config?

You have created a second /interface vlan port section rather than updating the original one with the correct settings. This will fail when the statements in the second section attempt to add ports which have already been added by statements in the first section - merge the two together.
by tdw
Sun Sep 20, 2020 3:07 pm
Forum: Beginner Basics
Topic: Configure CRS328-24P-4S+RM Initial config?
Replies: 14
Views: 635

Re: Configure CRS328-24P-4S+RM Initial config?

There should be no comma before the comment= How would the switch know what the PVID is, if I don't actually define said VLANs on the switch? The VLANs and untagged membership are dynamically generated from the pvid= entries under /interface bridge port if they have not been made explicitly. Your Mi...
by tdw
Sat Sep 19, 2020 8:30 pm
Forum: Beginner Basics
Topic: Configure CRS328-24P-4S+RM Initial config?
Replies: 14
Views: 635

Re: Configure CRS328-24P-4S+RM Initial config?

Almost. The syntax of your /interface bridge vlan section is not correct - you can only specify a vlan-ids= value once and the tagged= / untagged= entries expect a list rather than being repeated, also if you wish to comment entries the syntax is comment="some text" , so: /interface bridge vlan add ...
by tdw
Fri Sep 18, 2020 8:48 pm
Forum: General
Topic: PPPoE WAN, L2TP UDP works, TCP unreliable (some bursts of data work randomly) - I am lost :(
Replies: 7
Views: 324

Re: PPPoE WAN, L2TP UDP works, TCP unreliable (some bursts of data work randomly) - I am lost :(

I have set MTU, MRU and MRRU and now everything works! It's still bugging me... I have exactly the same setup (same ISP, PPPoE, same modem type, L2TP, Mikrotik, but another firmware there) on a different location and everything works there without any required changes to MTU.... Likely something di...
by tdw
Fri Sep 18, 2020 8:30 pm
Forum: Beginner Basics
Topic: hex S as simple L2 VLAN-switch behind Cisco L3 [SOLVED]
Replies: 6
Views: 321

Re: hex S as simple L2 VLAN-switch behind Cisco L3 [SOLVED]

Only thing not working 1. Can not ping from any VLAN <>vlan1 connected to cisco. (This routing is working to all other switches in VLAN1) so I assume routing is correctly assigned on L3 Therefore I checked on STP: On Cisco Spanning tree was enabled by default – L3 using STP – with Rapid STP. Uplink...
by tdw
Fri Sep 18, 2020 2:40 pm
Forum: Beginner Basics
Topic: hex S as simple L2 VLAN-switch behind Cisco L3 [SOLVED]
Replies: 6
Views: 321

Re: hex S as simple L2 VLAN-switch behind Cisco L3 [SOLVED]

No there isn't a changelog, only a CLI command history. I thought you may be trying to use the switch chip, which isn't straightforward, but a VLAN-aware bridge doesn't use it. There isn't anything obviously wrong. I prefer to leave out the untagged= entries under /interface bridge vlan as they will...
by tdw
Fri Sep 18, 2020 12:39 am
Forum: General
Topic: PPPoE WAN, L2TP UDP works, TCP unreliable (some bursts of data work randomly) - I am lost :(
Replies: 7
Views: 324

Re: PPPoE WAN, L2TP UDP works, TCP unreliable (some bursts of data work randomly) - I am lost :(

As you are using BCP to provide a L2 connection you could use MRRU on the L2TP server and client so full ethernet frames are handled correctly, rather than resorting to mangling the MSS.
by tdw
Thu Sep 17, 2020 10:13 pm
Forum: Beginner Basics
Topic: hex S as simple L2 VLAN-switch behind Cisco L3 [SOLVED]
Replies: 6
Views: 321

Re: hex S as simple L2 VLAN-switch behind Cisco L3 [SOLVED]

There are limitations with some of older switch chips which do not apply to newer ones, and RouterOS 6.4 was released 7 years ago - there have been many changes since then.

Post your configuration from /export hide-sensitive
by tdw
Wed Sep 16, 2020 2:52 am
Forum: Beginner Basics
Topic: connecting two Cloud router switches with vlans
Replies: 4
Views: 246

Re: connecting two Cloud router switches with vlans

You don't appear to have followed the examples... Switch B: Yes, you do need to create a bridge with all of the ports as members. The CRS1xx/2xx link aggregation trunk applies to ports which are already members of the bridge, unlike CRS3xx and non-CRS devices where the ports added to a bond interfac...
by tdw
Tue Sep 15, 2020 7:47 pm
Forum: General
Topic: VPN clients cannot reach each other [SOLVED]
Replies: 6
Views: 448

Re: VPN clients cannot reach each other [SOLVED]

Just remove the Framed-IP-Netmask attribute from your FreeRADIUS configuration. Defining a pool in FreeRADIUS and the Mikrotik PPP profile is redundant - the 'Remote Address' in the Mikrotik profile (vpn_pptp in your original screenshot) is overridden by the Framed-Pool attribute from FreeRADIUS, th...
by tdw
Tue Sep 15, 2020 2:30 pm
Forum: Beginner Basics
Topic: connecting two Cloud router switches with vlans
Replies: 4
Views: 246

Re: connecting two Cloud router switches with vlans

The CRS1xx should be configured to use the switch https://wiki.mikrotik.com/wiki/Manual:CRS1xx/2xx_VLANs_with_Trunks (the inter-VLAN routing and DHCP server sections are not applicable to your setup), and the CRS3xx should be configured with a single VLAN-aware bridge https://wiki.mikrotik.com/wiki/...
by tdw
Sun Sep 13, 2020 10:15 pm
Forum: Beginner Basics
Topic: VLAN bridge - tagged and untagged
Replies: 11
Views: 483

Re: VLAN bridge - tagged and untagged

Are you sure the UniFi AP is configured to use tagged VLANs only? We use UniFi APs and switches with Mikrotik routers frequently, and usually leave the UniFi management interface untagged so APs can acquire IP addresses, discover and be adopted by a controller. In the newer versions of UniFi I belie...
by tdw
Sat Sep 12, 2020 8:45 pm
Forum: Forwarding Protocols
Topic: CRS112 and IGMP snooping - problem
Replies: 5
Views: 944

Re: CRS112 and IGMP snooping - problem

According to https://wiki.mikrotik.com/wiki/Manual:I ... Offloading bridge IGMP snooping does not work properly (whatever that means) on CRS1xx/2xx with VLAN switching setups.
by tdw
Fri Sep 11, 2020 7:57 pm
Forum: General
Topic: Weird routing problem [SOLVED]
Replies: 18
Views: 1276

Re: Weird routing problem [SOLVED]

If the radios are in bridge mode they pass traffic transparently. The IP address is only required for management access to the radio, plus a default gateway if they need to communicate with something outside of their subnet e.g. a PC on another subnet or the internet to download updates - the gatewa...
by tdw
Fri Sep 11, 2020 7:04 pm
Forum: General
Topic: VPN clients cannot reach each other [SOLVED]
Replies: 6
Views: 448

Re: VPN clients cannot reach each other [SOLVED]

The routes for the l2tp connections are wrong - as they are all the same /24 only one can be active, each should have a unique /32. This is not normal, there must be something else in your configuration creating them, post the output of /export hide-sensitive after redacting any other information (e...
by tdw
Fri Sep 11, 2020 6:54 pm
Forum: General
Topic: PPPoE WAN to LAN
Replies: 7
Views: 408

Re: PPPoE WAN to LAN

The ISP is providing a /32 network sorry I should have mentioned Alright so I'm starting to grasp what your saying now. So are you saying there are two ways to go about this? One way is a second PPPoE session over the same link attached to my 103.x.x.91 so that the second router (we'll call it that...
by tdw
Thu Sep 10, 2020 6:46 pm
Forum: General
Topic: VPN clients cannot reach each other [SOLVED]
Replies: 6
Views: 448

Re: VPN clients cannot reach each other [SOLVED]

Hi! I have a router CCR1016-12S-1S+ and i setup VPN server on router (PPTP, L2TP, openvpn) Firstly stop using PPTP or L2TP with MPPE encryption as they are not secure. L2TP/IPsec, SSTP and OpenVPN are fine if properly configured. Office network 10.10.10.0/24 VPN network 10.10.100.0/24 My VPN client...
by tdw
Thu Sep 10, 2020 4:05 pm
Forum: General
Topic: PPPoE WAN to LAN
Replies: 7
Views: 408

Re: PPPoE WAN to LAN

Thinking of it now, I think the only way to really do it is to bridge eth1 and eth3 together and have the router in eth3 do its own PPPoE session that is tied to this second IP rather than combine the two IPs together into the same PPPoE session Would this sound more like it? Your ISP is only expec...
by tdw
Tue Sep 08, 2020 1:40 pm
Forum: Beginner Basics
Topic: How to set IP address to switch while using VLANs?
Replies: 15
Views: 745

Re: How to set IP address to switch while using VLANs?

Switch, -where are the definitions for all the vlans I only see vlan99?? -you are missing all the untagged interfaces in your bridge vlan rules that should reflect your pvid settings in the bridge ports?? ++++++++++++++++++\ AP -where are the definitions for all the vlans I only see vlan99?? -you a...
by tdw
Mon Sep 07, 2020 4:15 pm
Forum: General
Topic: VPN and subnet have different netmasks
Replies: 11
Views: 559

Re: VPN and subnet have different netmasks

The OpenVPN server netmask has absolutely nothing to do with the WAN subnet mask - for example one router we have is configured with a /32 WAN IP and /30 routed public IP, the VPN local client addresses are a /26 and Open VPN server netmask is /20, encompassing the local client addresses, to allow ...
by tdw
Sun Sep 06, 2020 8:42 pm
Forum: Beginner Basics
Topic: Add MGMT Vlan to DMZ
Replies: 14
Views: 565

Re: Add MGMT Vlan to DMZ

I find it very confusing that for this vlan-aware bridge configuration you both need to specify which port(s) you want to be untagged on each VLAN, and ALSO which VLAN you want to be on those PORTS: /interface bridge port add bridge=bridge1 interface=ether1 pvid=99 /interface bridge vlan add bridge...
by tdw
Sat Sep 05, 2020 11:59 pm
Forum: Beginner Basics
Topic: Mikrotik router behind Comcast business modem with dynamic IPv6
Replies: 59
Views: 1735

Re: Mikrotik router behind Comcast business modem with dynamic IPv6

Thanks. That's really helpful. Currently Quick Set shows the WAN IP address as 0.0.0.0. How/where do I get rid of that or change it in webfig? I'd like to to be an automatic IP address. Is the source of our problem? Should it be changed to match that of Comcast gateway? 0.0.0.0 is not a valid addre...
by tdw
Sat Sep 05, 2020 9:41 pm
Forum: Beginner Basics
Topic: How do you change wlan1 from slave?
Replies: 2
Views: 169

Re: How do you change wlan1 from slave?

That is an old video, the wireless-rep package doesn't exist in recent versions of RouterOS.

Have a look at viewtopic.php?t=153970
by tdw
Sat Sep 05, 2020 9:18 pm
Forum: Beginner Basics
Topic: Mikrotik router behind Comcast business modem with dynamic IPv6
Replies: 59
Views: 1735

Re: Mikrotik router behind Comcast business modem with dynamic IPv6

UPDATE: There's something on the Quick Set page that kept breaking my RB. Whether or not I'm connected to Comcast, once I apply the settings in Quick Set, the box becomes unusable. The config that I restored has WAN IP 192.168.10.2 (static) and LAN IP 192.168.88.1 or 192.168.1.1 on the Quick Set pa...
by tdw
Fri Sep 04, 2020 11:33 pm
Forum: General
Topic: VPN and subnet have different netmasks
Replies: 11
Views: 559

Re: VPN and subnet have different netmasks

The OpenVPN server netmask has absolutely nothing to do with the WAN subnet mask - for example one router we have is configured with a /32 WAN IP and /30 routed public IP, the VPN local client addresses are a /26 and Open VPN server netmask is /20, encompassing the local client addresses, to allow a...
by tdw
Thu Sep 03, 2020 1:04 pm
Forum: Beginner Basics
Topic: VLAN help
Replies: 8
Views: 464

Re: VLAN help

Read something that said I needed to slave all of the interfaces to the uplink: [admin@MikroTik] /interface ethernet> set [ find default-name=ether48 ] master-port=sfp-sfpplus1 expected end of command (line 1 column 35) Everything I've read just gives me errors. Not even trying to config it to my n...
by tdw
Thu Sep 03, 2020 12:16 pm
Forum: Beginner Basics
Topic: openvpn config
Replies: 2
Views: 183

Re: openvpn config

The Mikrotik Open VPN client does not support UDP mode specified by that configuration.
by tdw
Tue Sep 01, 2020 8:11 pm
Forum: RouterBOARD hardware
Topic: USB Data Lines hAP mini (RB931-2nD)
Replies: 3
Views: 231

Re: USB Data Lines hAP mini (RB931-2nD)

There are signals connected to the USB socket data pins, but not standard USB. Mikrotik use them for passing data to their powerline adapter, see https://i.mt.lv/cdn/product_files/PWR-l ... 200241.pdf
by tdw
Sun Aug 30, 2020 9:49 pm
Forum: Beginner Basics
Topic: How to set IP address to switch while using VLANs?
Replies: 15
Views: 745

Re: How to set IP address to switch while using VLANs?

The router VLAN99 config is fine for attached devices with static IPs. The switch is missing most of the management setup - the VLAN99 interface is disabled, there is no IP or routing information: /interface vlan add disabled=yes interface=ether1 name=VLAN4 vlan-id=4 add disabled=yes interface=bridg...
by tdw
Tue Aug 25, 2020 2:08 am
Forum: General
Topic: CRS-112-8G-4S high cpu, dhcp
Replies: 3
Views: 199

Re: CRS-112-8G-4S high cpu, dhcp

CRS products are intended to be L2 switches with limited L3 performance, they are not wire-speed L3 routers.

The performance figures are published on the website for each product, see https://mikrotik.com/product/CRS112-8G- ... estresults for your device.
by tdw
Sun Aug 23, 2020 2:43 am
Forum: General
Topic: Correct way of switch in RouterOS
Replies: 5
Views: 969

Re: Correct way of switch in RouterOS

Not quite. /interface bridge add admin-mac=XXXXXXXXXXXXXXX auto-mac=no igmp-snooping=yes name=bridge1 /interface bridge port add bridge=bridge1 frame-types=admit-only-vlan-tagged interface=ether1 add bridge=bridge1 frame-types=admit-only-vlan-tagged interface=ether2 add bridge=bridge1 frame-types=ad...
by tdw
Fri Aug 21, 2020 4:28 pm
Forum: General
Topic: Dot1X
Replies: 12
Views: 1834

Re: Dot1X

The latest beta (6.48beta27) has these in the changelog: *) dot1x - fixed duplicate EAP request packets for server; *) dot1x - fixed EAP packet version numbering; which might fix it. I'm sure new current and long-term updates including these will appear at some point if you do not want to run a beta...
by tdw
Thu Aug 20, 2020 11:49 pm
Forum: General
Topic: Prevent inter-VLAN routing / isolating VLANs not working [SOLVED]
Replies: 2
Views: 336

Re: Prevent inter-VLAN routing / isolating VLANs not working [SOLVED]

Adding VLANs segregates the networks at the ethernet / layer2 level, but by default the Mikrotik will route IP / layer3 traffic between all attached subnets. Either block specific VLAN-to-VLAN traffic in the forward chain, or accept the traffic you wish to allow followed by a forward drop rule to bl...
by tdw
Thu Aug 20, 2020 2:41 pm
Forum: General
Topic: Help with load balancing 2x PPPOE-out
Replies: 8
Views: 845

Re: Help with load balancing 2x PPPOE-out

I gave a example that i use 5 different PC's and that I initiate 5 separate uploads. According to my understanding that are 5 separate streams. Why all the outbound traffic goes out through only one WAN, instead of making a balance and using both WAN ports for outbound traffic? I am trying to solve...
by tdw
Fri Aug 14, 2020 11:32 pm
Forum: General
Topic: Bridge filter not working
Replies: 8
Views: 2244

Re: Bridge filter not working

If you are using hardware offload the bridge filters will not see packets forwarded between ports as they are handled within the switch chips, look at switch ACLs.
by tdw
Fri Aug 14, 2020 12:14 am
Forum: Beginner Basics
Topic: having a little difficulty transitioning to the mikrotik router
Replies: 23
Views: 3082

Re: having a little difficulty transitioning to the mikrotik router

in my scenario, should i be focusing on the switch settings or the bridge as both has vlan options in them. It depends on your requirements: If wire-speed switching within the same VLAN is not of particular importance then a VLAN-aware bridge ( /interface bridge add name=... vlan-filtering=yes ) is...
by tdw
Thu Aug 13, 2020 9:55 pm
Forum: General
Topic: CRS3xx - Management VLAN stop working
Replies: 3
Views: 826

Re: CRS3xx - Management VLAN stop working

All our switches are STP disabled, may this can be the problem?
If there are no loops in the network, no.
by tdw
Thu Aug 13, 2020 3:36 pm
Forum: Beginner Basics
Topic: having a little difficulty transitioning to the mikrotik router
Replies: 23
Views: 3082

Re: having a little difficulty transitioning to the mikrotik router

thanks for the response, tdw. I think i am starting to get confused with when to use bridge and switch in the config. Initially i bought this device because it has the switch chip as the switch chip provides the hardware offloading to get close to wire speed across vlans. I will be using this mainl...
by tdw
Thu Aug 13, 2020 12:51 pm
Forum: Beginner Basics
Topic: having a little difficulty transitioning to the mikrotik router
Replies: 23
Views: 3082

Re: having a little difficulty transitioning to the mikrotik router

From what i have understood from you statements, can i say that switch1-cpu is the connection from switch chip and cpu Yes. flipping the settings to vlan-mode=secure causes all traffic between the switch and the cpu to be "vlan-aware". By default the switch ports pass all traffic, including tagged ...
by tdw
Thu Aug 13, 2020 12:43 am
Forum: General
Topic: Cannot get gbit switch performance on RB2011
Replies: 5
Views: 1288

Re: Cannot get gbit switch performance on RB2011

Is there no way that I can get hardware performance on traffic within one switch, and only use the bridge for inter-switch traffic? That would already be a great solution. More specifically, what goes wrong in the example on https://wiki.mikrotik.com/wiki/Manual:Layer2_misconfiguration#Configuratio...
by tdw
Thu Aug 13, 2020 12:24 am
Forum: General
Topic: MGMT vlan dhcp
Replies: 3
Views: 681

Re: MGMT vlan dhcp

Thanks for the reply! Should the bridge itself also have pvid 99 or do I leave that on the default of pvid 1?
Leave it as 1, the tagged management traffic is unencapsulated by your mgmt_vlan VLAN interface for access by the CPU.
by tdw
Wed Aug 12, 2020 7:39 pm
Forum: General
Topic: CRS3xx - Management VLAN stop working
Replies: 3
Views: 826

Re: CRS3xx - Management VLAN stop working

Could be many things not knowing what your network topology and device configurations are. If you have many switches and interconnections then spanning tree can block some traffic if incorrectly configured - with VLANs you should use either RSTP with all VLANs configured on all trunk links, or more ...
by tdw
Wed Aug 12, 2020 7:33 pm
Forum: General
Topic: MGMT vlan dhcp
Replies: 3
Views: 681

Re: MGMT vlan dhcp

The PVID for untagged traffic is set to the default of 1, for your setup it should be 99 /interface bridge port add bridge=vlan_trunk interface=ether2 pvid=99 add bridge=vlan_trunk interface=ether3 pvid=99 add bridge=vlan_trunk interface=ether4 pvid=99 add bridge=vlan_trunk interface=ether5 pvid=99 ...
by tdw
Wed Aug 12, 2020 6:09 pm
Forum: Beginner Basics
Topic: Firewall/VLAN setup
Replies: 10
Views: 2192

Re: Firewall/VLAN setup

You only require VLANs to share multiple networks over a single interface, if you only require one interface to be on a separate network that interface can be removed from the bridge and have an IP address, DHCP server, etc. added to it.
by tdw
Wed Aug 12, 2020 5:33 pm
Forum: Beginner Basics
Topic: having a little difficulty transitioning to the mikrotik router
Replies: 23
Views: 3082

Re: having a little difficulty transitioning to the mikrotik router

The configuration is completely different to any other vendor, it is a pity Mikrotik have not integrated hardware acceleration (i.e. switching) into the VLAN-aware bridge handling as they have with the CRS3xx devices. https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#VLAN_Example_2_.28Trunk...
by tdw
Mon Aug 10, 2020 7:03 pm
Forum: General
Topic: Help with load balancing 2x PPPOE-out
Replies: 8
Views: 845

Re: Help with load balancing 2x PPPOE-out

Bumping a post usually has little effect. Your existing rules only mark traffic to the Mikrotik itself and return them via the same interface. As the default route specifies both gateways this is an equal cost multi-path (ECMP) route so outbound traffic will exit via both gateways - if they are with...
by tdw
Sun Aug 09, 2020 4:47 pm
Forum: General
Topic: Cannot get gbit switch performance on RB2011
Replies: 5
Views: 1288

Re: Cannot get gbit switch performance on RB2011

I also read that devices with two switches (like RB2011) cannot do switch-level VLAN filtering: https://wiki.mikrotik.com/wiki/Manual:Layer2_misconfiguration#VLAN_filtering_with_multiple_switch_chips Finally I used the 'new' recommended bridge-based method to configure my VLANs (I think), based on ...
by tdw
Wed Aug 05, 2020 4:45 pm
Forum: General
Topic: PowerBox Pro QCA8337 chip [SOLVED]
Replies: 8
Views: 1916

Re: PowerBox Pro QCA8337 chip [SOLVED]

You only have to add it to VLANs which require access to the CPU, in your config you have IP addresses assigned to VLAN10 and VLAN88 so those should be sufficient. If you have management via the VLANs on the all-vlan-bridge bridge I strongly recommend removing the bridge_bkup bridge as only one brid...
by tdw
Wed Aug 05, 2020 4:30 pm
Forum: Beginner Basics
Topic: Load-Balancing (PCC) with two PPPoE Clients (Two different home ISPs) not working
Replies: 3
Views: 942

Re: Load-Balancing (PCC) with two PPPoE Clients (Two different home ISPs) not working

So, what happens is, the connections simply continue to use pppoe-out1 without ever using pppoe-out2 unless pppoe-out1 failover to pppoe-out2. Basically, load balancing isn't working at all. I think I figured out the problem, inside IP>Route, the route to pppoe-out2 is not active when pppoe-out1 is...
by tdw
Tue Aug 04, 2020 8:39 pm
Forum: General
Topic: PowerBox Pro QCA8337 chip [SOLVED]
Replies: 8
Views: 1916

Re: PowerBox Pro QCA8337 chip [SOLVED]

You do not have the CPU switch port (switch1-cpu) in any of the /interface ethernet switch vlan statements so you will loose access.
by tdw
Sun Aug 02, 2020 7:09 pm
Forum: General
Topic: Routing problem with Public IP subnets
Replies: 8
Views: 1859

Re: Routing problem with Public IP subnets

The "# DHCP server can not run on slave interface!" is a hint that the configuration is incorrect - you shouldn't assign IP addresses / connect services to members of a bridge, some things work and some things do not in random ways. There is also a dhcp client attached the interface you have a dhcp ...
by tdw
Sun Aug 02, 2020 5:39 pm
Forum: Beginner Basics
Topic: From VLANs "old way" to "new way" (VLAN Filtering) - WINBOX IP Neighbor list problems nad RoMon issue.
Replies: 16
Views: 3469

Re: From VLANs "old way" to "new way" (VLAN Filtering) - WINBOX IP Neighbor list problems nad RoMon issue.

As I've mentioned previously there are several discovery protocols - LLDP information should only be seen on physically connected interfaces, MNDP is broadcast across the layer-2 network. LLDP contains the system-caps and system-caps enabled information not present in MNDP, and similarly MNDP contai...
by tdw
Sun Aug 02, 2020 4:45 am
Forum: General
Topic: Routing problem with Public IP subnets
Replies: 8
Views: 1859

Re: Routing problem with Public IP subnets

First of all you should make interfaces as arp=proxy-arp, next one you should exclude those IP from NAT What will proxy-arp do to remedy that? Not sure I follow you there. They are not in the nat. That is what makes no sense. The only subnet I nat is 10.0.0.0/8 If your ISP is routing the /23 and /2...
by tdw
Sat Aug 01, 2020 2:30 pm
Forum: Beginner Basics
Topic: From VLANs "old way" to "new way" (VLAN Filtering) - WINBOX IP Neighbor list problems nad RoMon issue.
Replies: 16
Views: 3469

Re: From VLANs "old way" to "new way" (VLAN Filtering) - WINBOX IP Neighbor list problems nad RoMon issue.

Could you please explain what is the effect of adding VLAN20 and Bridge to tagged vlan-IDs=20 from my config below: /interface bridge vlan add bridge=Bridge_T1_vlan10 tagged=\ ether8-TRUNK,ether9-TRUNK,ether10-TRUNK,ether11-TRUNK vlan-ids=10 add bridge=Bridge_T1_vlan10 tagged="ether8-TRUNK,ether9-T...
by tdw
Thu Jul 30, 2020 5:14 pm
Forum: Beginner Basics
Topic: From VLANs "old way" to "new way" (VLAN Filtering) - WINBOX IP Neighbor list problems nad RoMon issue.
Replies: 16
Views: 3469

Re: From VLANs "old way" to "new way" (VLAN Filtering) - WINBOX IP Neighbor list problems nad RoMon issue.

Under /interface bridge the pvid= parameter sets the PVID on the interface-part to the CPU, in the same way that under /interface bridge port the pvid= parameter sets the PVID on the attached interface (typically a physical ethernet port). But, is this mean that setting PVID=10 for a bridge equals ...
by tdw
Wed Jul 29, 2020 11:36 pm
Forum: Beginner Basics
Topic: Cant get all PCs online
Replies: 16
Views: 2797

Re: Cant get all PCs online

Or someone has plugged in another router on your LAN without you knowing it. Most likely they were looking for switching only, but left the DHCP server enabled. This is possible. But to check that I have to be there physically. (I am currently working from home due to the current situation) If DHCP...
by tdw
Wed Jul 29, 2020 7:21 pm
Forum: Beginner Basics
Topic: From VLANs "old way" to "new way" (VLAN Filtering) - WINBOX IP Neighbor list problems nad RoMon issue.
Replies: 16
Views: 3469

Re: From VLANs "old way" to "new way" (VLAN Filtering) - WINBOX IP Neighbor list problems nad RoMon issue.

Wow, So tagging the bridge with specific vlan id is equal to setting PVID at the same value? When you create a bridge it has two roles - a switch-part for connecting interfaces together, and an interface-part for traffic between the CPU and switch-part. The name is the same for both these roles, Ro...
by tdw
Wed Jul 29, 2020 5:45 pm
Forum: Beginner Basics
Topic: Cant get all PCs online
Replies: 16
Views: 2797

Re: Cant get all PCs online

Either the Mikrotik has been configured to hand out the 192.168.3.x addresses, or more likely someone has plugged another router into your network and that is answering DHCP requests more quickly than the Mikrotik. You can enable rogue DHCP server detection under /ip dhcp-server alert , or IP > DHCP...
by tdw
Wed Jul 29, 2020 5:32 pm
Forum: General
Topic: RouterOS v6.27 SSh Key login problem.
Replies: 2
Views: 686

Re: RouterOS v6.27 SSh Key login problem.

v6.27 has several remotely exploitable authentication bypass vulnerabilites. I would suggest updating to at least the current long-term stable version (currently 6.45.9), and if remotely accessible checking for any configuration you do not recognise, ideally completely wipe with netinstall and recon...
by tdw
Wed Jul 29, 2020 2:44 pm
Forum: Beginner Basics
Topic: From VLANs "old way" to "new way" (VLAN Filtering) - WINBOX IP Neighbor list problems nad RoMon issue.
Replies: 16
Views: 3469

Re: From VLANs "old way" to "new way" (VLAN Filtering) - WINBOX IP Neighbor list problems nad RoMon issue.

Thanks fot your feedback, tdw. Main UNIT: Proxy-ARP allow acces via pptp (VPN) to bridge. OK, that is the most common use for proxy-arp. I wouldn't use PPTP for remote access, it is probably the easiest VPN type to setup but is very insecure. CRS125-24G-1S-2Hnd /ip neighbor discovery-settings> prin...
by tdw
Tue Jul 28, 2020 8:45 pm
Forum: General
Topic: Correct VLAN configuration on multiple paths
Replies: 1
Views: 526

Re: Correct VLAN configuration on multiple paths

That is the "old way" of configuring VLANs and can cause potential issues, see https://wiki.mikrotik.com/wiki/Manual:Layer2_misconfiguration There is a good tutorial on the "new way" https://forum.mikrotik.com/viewtopic.php?t=143620 , and descriptions in the Wiki https://wiki.mikrotik.com/wiki/Manua...
by tdw
Tue Jul 28, 2020 12:43 pm
Forum: Beginner Basics
Topic: From VLANs "old way" to "new way" (VLAN Filtering) - WINBOX IP Neighbor list problems nad RoMon issue.
Replies: 16
Views: 3469

Re: From VLANs "old way" to "new way" (VLAN Filtering) - WINBOX IP Neighbor list problems nad RoMon issue.

A few minor things could do with tidying up, but nothing immediately jumps out. Main unit: Is there a reason for arp=proxy-arp on the bridge? There are some specific use cases, but not usually required. The DHCP servers have authoritative=after-2sec-delay , this is historic and better set to authori...
by tdw
Mon Jul 27, 2020 10:55 pm
Forum: Beginner Basics
Topic: From VLANs "old way" to "new way" (VLAN Filtering) - WINBOX IP Neighbor list problems nad RoMon issue.
Replies: 16
Views: 3469

Re: From VLANs "old way" to "new way" (VLAN Filtering) - WINBOX IP Neighbor list problems nad RoMon issue.

If you have changed the bridge PVID to 10 you almost certainly don't need an interface for VLAN 10 too. Post the output of /export hide-sensitive and redact any other identifying data (e.g. public IPs).
by tdw
Mon Jul 13, 2020 11:12 am
Forum: General
Topic: SOS i need help on vlan and trunking crs326 SWL3
Replies: 10
Views: 2048

Re: SOS i need help on vlan and trunking crs326 SWL3

CRS devices are intended to be L2 switches with some L3 functionality NOT wire-speed L3 routing as they performance-limited by the CPU. They are listed in 'Switches' category on the Mikrotik website rather than 'Ethernet routers' - each model has test results showing the switching and routing perfor...
by tdw
Mon Jul 06, 2020 4:05 pm
Forum: General
Topic: Network loop?
Replies: 6
Views: 1789

Re: Network loop?

ether7: bridge port received packet with own address as source address (74:4d:28:01:2f:3a), probably loop As others have said it is likely to be ports connected together via an unmanged switch, or an unintentional wireless to ethernet connection. As ether7 is receiving its own packets back the prob...
by tdw
Tue Jun 09, 2020 1:51 am
Forum: General
Topic: CRS326 - VLAN Access Port
Replies: 1
Views: 392

Re: CRS326 - VLAN Access Port

Do not add the VLAN interface in /interface bridge port. Your have set the bridge VLAN type to 0x88a8 a.k.a. service VLAN, the default 0x8100 would be more usual.
by tdw
Tue Jun 09, 2020 1:43 am
Forum: Beginner Basics
Topic: VLAN by MAC Address Hap AC2
Replies: 3
Views: 715

Re: VLAN by MAC Address Hap AC2

It doesn't appear to be capable, the rules can match packets but there are no suitable actions.
by tdw
Tue Jun 09, 2020 1:40 am
Forum: Beginner Basics
Topic: Hex As Switch -Speeds?
Replies: 6
Views: 904

Re: Hex As Switch -Speeds?

Okay, so basically I would be better off putting in the Netgear GSS108e, then. Its the most minimalistic managed switch I have dealt with, doesnt even have an https login method LOL Just don't use the password anywhere else - Netgear use 'XOR password with a fixed string' for security obsfucation. ...
by tdw
Mon Jun 01, 2020 11:17 am
Forum: Beginner Basics
Topic: VLAN by MAC Address Hap AC2
Replies: 3
Views: 715

Re: VLAN by MAC Address Hap AC2

According to the Wiki https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Rule_Table only the now ancient Atheros 8316 switch chip can alter VLAN IDs. A common technique is to use 802.1x and macauth. Mikrotik implemented 802.1x in v6.45 onwards, and there are limitations - as it requires a VL...
by tdw
Sat May 23, 2020 5:27 pm
Forum: Beginner Basics
Topic: RB2011UiAS-IN VLANs on second switch bank
Replies: 10
Views: 1722

Re: RB2011UiAS-IN VLANs on second switch bank

The VLAN interfaces giving the CPU to access VLANs in /interface vlan must be attached to the parent interface not members, so bridge not ether17.

That setup will work, but will not use hardware switching.
by tdw
Fri May 22, 2020 12:41 am
Forum: General
Topic: OpenVPN with VLANs
Replies: 24
Views: 4107

Re: OpenVPN with VLANs

You can only have one server binding per username - if the same username is used more than once you end up with the server binding plus additional dynamic interfaces <ovpn-someuser-1>, <ovpn-someuser-2>, etc. If a connection is interrupted you can end up with the user connected via a dynamic interfa...
by tdw
Thu May 21, 2020 11:48 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 24
Views: 4107

Re: OpenVPN with VLANs

That rule is for the outer tunnel, not the inner tunnelled traffic. As discussed in post #4 with having firewall rules referring to the lists 'BASE', 'VLAN', 'BASE+VLAN' the open VPN server interface has to be added to these if you wish the VPN traffic to use the rules. Having interface-list=VLAN in...
by tdw
Thu May 21, 2020 9:07 pm
Forum: Beginner Basics
Topic: VLAN Bridge - Trunk with Wireless Wire "bridge port received packet with own address"
Replies: 15
Views: 2366

Re: VLAN Bridge - Trunk with Wireless Wire "bridge port received packet with own address"

By default it will capture everything - including broadcast/multicast traffic from the rest of your network and the Winbox traffic to and from the Mikrotik itself. You can apply filters to reduce the scope of the capture and hopefully volume of packets, there should be something transmitted and rece...
by tdw
Thu May 21, 2020 8:52 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 24
Views: 4107

Re: OpenVPN with VLANs

Local is server, remote is client. For point-to-point interfaces you can have the same local address on multiple interfaces. VLANs are not the issue, they only have significance for layer 2 ethernet. IP routes are automatically added to the routing table ( /ip route print or Winbox, IP > Routes), on...
by tdw
Thu May 21, 2020 7:58 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 24
Views: 4107

Re: OpenVPN with VLANs

There is nowhere to enter an interface in /ip pool - just a pool name, addresses and an optional next pool. So, based on your config, something along the lines of: /ip pool add name=pool_ovpn ranges=10.0.98.10-10.0.98.254 ... /ppp profile add dns-server=10.0.0.3 interface-list=VLAN local-address=10....
by tdw
Thu May 21, 2020 7:32 pm
Forum: Beginner Basics
Topic: system logging - no rule but still logging? [SOLVED]
Replies: 8
Views: 1736

Re: system logging - no rule but still logging? [SOLVED]

Rules 2, 5 & 12 still have log=yes so the messages will be from one of those
by tdw
Wed May 20, 2020 10:59 pm
Forum: Beginner Basics
Topic: VLAN Bridge - Trunk with Wireless Wire "bridge port received packet with own address"
Replies: 15
Views: 2366

Re: VLAN Bridge - Trunk with Wireless Wire "bridge port received packet with own address"

The configuration has an incorrect VLAN configuration. You diagram shows the master ether1 carrying VLAN 1000 and 1051 tagged, but you have configured the port has VLAN 1000 untagged. It should be: /interface bridge port add bridge=bridge comment=defconf ingress-filtering=yes interface=ether1 pvid=...
by tdw
Wed May 20, 2020 3:45 pm
Forum: Beginner Basics
Topic: VLAN Bridge - Trunk with Wireless Wire "bridge port received packet with own address"
Replies: 15
Views: 2366

Re: VLAN Bridge - Trunk with Wireless Wire "bridge port received packet with own address"

The master and slave configurations appear identical. Cut and paste issue? The configuration has an incorrect VLAN configuration. You diagram shows the master ether1 carrying VLAN 1000 and 1051 tagged, but you have configured the port has VLAN 1000 untagged. It should be: /interface bridge port add ...
by tdw
Wed May 20, 2020 2:28 am
Forum: General
Topic: OpenVPN with VLANs
Replies: 24
Views: 4107

Re: OpenVPN with VLANs

I don't know what is causing the problem. Tried different setups. It is odd that you got to a point where you had some connectivity and then lost it. I might not understand your question, but if this is the question: The remote client has an IP address from a completely different subnet (172.XX...)...
by tdw
Wed May 20, 2020 2:13 am
Forum: Beginner Basics
Topic: VLAN Bridge - Trunk with Wireless Wire "bridge port received packet with own address"
Replies: 15
Views: 2366

Re: VLAN Bridge - Trunk with Wireless Wire "bridge port received packet with own address"

What other equipment do you have in your network, and the running configuration /export hide-sensitive would help.
by tdw
Wed May 20, 2020 2:03 am
Forum: Beginner Basics
Topic: RB2011UiAS-IN VLANs on second switch bank
Replies: 10
Views: 1722

Re: RB2011UiAS-IN VLANs on second switch bank

Yes, you do get the impression that Mikrotik just created a UI exposing a load of switch chip registers and left people to figure it out. Originally switch configuration was completely separate from bridges, but they have gradually been merging so the bridge becomes a placeholder for configuring and...
by tdw
Tue May 19, 2020 9:31 pm
Forum: Beginner Basics
Topic: RB2011UiAS-IN VLANs on second switch bank
Replies: 10
Views: 1722

Re: RB2011UiAS-IN VLANs on second switch bank

If you do not need wire-speed switching between ports the RB2011 is fine with a VLAN-aware bridge and no hardware offload. The CRS1xx/2xx switching is very different to the RB devices, the wiki examples are a good starting point. Normally I would say that the CRS devices are intended to be L2 switch...
by tdw
Mon May 18, 2020 11:31 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 24
Views: 4107

Re: OpenVPN with VLANs

Nothing immediately jumps out. Is the Open VPN client connecting from an address within the IP range you are trying to tunnel? I've never tried it myself to see if handles this situation. Also, IIRC there have been comments about /internet detect-internet causing odd behaviour so it may be worth rem...
by tdw
Sun May 17, 2020 2:18 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 24
Views: 4107

Re: OpenVPN with VLANs

Per my previous email either add routing statements to the OpenVPN client configuration file route 10.0.0.0 255.255.0.0 vpn_gateway OR change the Mikrotik VPN server /interface ovpn-server server set auth=sha1 certificate=server cipher=aes256 default-profile=ppp_private enabled=yes netmask=16 requir...
by tdw
Sun May 17, 2020 1:37 pm
Forum: General
Topic: User Manager - Radius Authentication - Response send from wrong Interface
Replies: 6
Views: 1171

Re: User Manager - Radius Authentication - Response send from wrong Interface

It does sound like a bug, you could report it to Mikrotik support.
by tdw
Sun May 17, 2020 1:59 am
Forum: General
Topic: OpenVPN with VLANs
Replies: 24
Views: 4107

Re: OpenVPN with VLANs

Ok thanks for clearing this up for me. Now I can access the 10.0.99.0/24 subnet from which the address is given to the interface, but not other subnets, though I have created an address list with 10.0.0.0/16 and added it under the /ppp profile address-list option. Should I need to do anything else ...
by tdw
Sat May 16, 2020 10:49 pm
Forum: Beginner Basics
Topic: Routing issue or ISP issue
Replies: 1
Views: 511

Re: Routing issue or ISP issue

It depends if the addresses are in the same /26 subnet or not - if they are then layer2 port isolation, or similar, could well be an issue. What do you get if you try ping and traceroute from one router to the other, and again in the other direction?
by tdw
Sat May 16, 2020 10:33 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 24
Views: 4107

Re: OpenVPN with VLANs

The Mikrotik OpenVPN implementation is shoehorned into their PPP model, and it does not quite fit, so some of the PPP profile settings have no meaning when used with the OpenVPN server - in particular setting bridge= under /ppp profile has no effect, this is used by PPP Bridge Control Protocol (BCP)...
by tdw
Sat May 16, 2020 8:08 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 24
Views: 4107

Re: OpenVPN with VLANs

Not being able to access the router itself is likely to be firewall rules. Having the same VLAN ID on different bridges will not pass that traffic between bridges, are you looking to bridge or route traffic? Printing the bridge and PPP profile entries provides no useful information, post the output ...
by tdw
Sat May 16, 2020 2:21 pm
Forum: General
Topic: User Manager - Radius Authentication - Response send from wrong Interface
Replies: 6
Views: 1171

Re: User Manager - Radius Authentication - Response send from wrong Interface

We set the RADIUS source address to a loopback /32 on each Mikrotik and tunnel traffic to FreeRADIUS based servers over L2TP/IPsec tunnels (rather than GRE) without issue. As your user manager and tunnel endpoints are on the same device it isn't possible to determine the exact source of the problem ...
by tdw
Sat May 16, 2020 1:43 pm
Forum: Beginner Basics
Topic: RB2011UiAS-IN VLANs on second switch bank
Replies: 10
Views: 1722

Re: RB2011UiAS-IN VLANs on second switch bank

You also have a mix of bridge and switch VLAN configuration. Either use a VLAN-aware bridge OR hardware switching mixing them can have unintentional side-effects, currently the /interface bridge port PVID settings are ignored and /interface bridge vlan does nothing. Unless you need wirespeed switchi...
by tdw
Tue May 12, 2020 10:14 pm
Forum: Beginner Basics
Topic: Hybrid Ports
Replies: 2
Views: 843

Re: Hybrid Ports

There will be no communication between ports without /interface bridge and /interface bridge port configuration. Confusingly, depending on which type of Mikrotik you have, hardware switching with VLANs is implemented differently. For the CRS1xx/2xx devices you need a non-VLAN-aware bridge plus ether...
by tdw
Tue May 12, 2020 8:57 pm
Forum: General
Topic: Dot1X
Replies: 12
Views: 1834

Re: Dot1X

No. EAP-MSCHAPv2 is plain old MSCHAPv2, so man-in-the middle attacks gathering the handshake are possible - these allow the NTLM password hash to be recovered. Protected EAP may be used as an "outer" method wrapping an "inner" insecure EAP method inside a TLS tunnel to prevent eavesdropping. The ful...
by tdw
Tue May 12, 2020 12:52 am
Forum: General
Topic: VLAN filtering on a sigle bridge problem
Replies: 6
Views: 879

Re: VLAN filtering on a sigle bridge problem

That is a fragment of the configuration on one device, so impossible to tell what is happening elsewhere. Nothing should be generating VLAN ID 4095 as it is a reserved value. As @mkx said ingress-filtering=yes is only set on a couple of ports, without it frame-types= has no effect. Also /interface b...
by tdw
Fri May 08, 2020 1:10 am
Forum: General
Topic: VRRP & RSTP
Replies: 22
Views: 2877

Re: VRRP & RSTP

I would suggest protocol-mode=rstp rather than protocol-mode=stp as it converges much more quickly. RouterOS does not change port path cost based on the link speed so you may wish to review the values. Also, on the secondary switch your choice of priority is odd. From the wiki "In RouterOS it is pos...
by tdw
Thu May 07, 2020 4:40 pm
Forum: General
Topic: VRRP & RSTP
Replies: 22
Views: 2877

Re: VRRP & RSTP

From what I recall of the HPE STP/RSTP implementation it is standards compliant - the BPDUs are always untagged. If you stick with RSTP you must have the same selection of VLANs present on all legs of the loop (as the RSTP blocking could interrupt any leg), and RSTP only transmitted untagged for the...
by tdw
Thu May 07, 2020 3:16 pm
Forum: General
Topic: User Manager - Radius Authentication - Response send from wrong Interface
Replies: 6
Views: 1171

Re: User Manager - Radius Authentication - Response send from wrong Interface

Without any configuration details it is difficult to say. By default the RADIUS client will use the address of the egress interface as the source address unless you explicitly set one, and the RADIUS server / user manager will reply to that address.
by tdw
Tue May 05, 2020 11:05 pm
Forum: Beginner Basics
Topic: Vlan Filtering
Replies: 8
Views: 1644

Re: Vlan Filtering

It depends on how you access traffic on VLAN5 by the CPU, you can either do /interface bridge add name=bridge protocol-mode=none vlan-filtering=yes /interface vlan add interface=bridge name=vlan-5 vlan-id=5 interface bridge vlan add bridge=bridge tagged=bridge vlan-ids=5 /ip address add address=192...
by tdw
Tue May 05, 2020 11:03 pm
Forum: Beginner Basics
Topic: Vlan Filtering
Replies: 8
Views: 1644

Re: Vlan Filtering

It depends on how you access traffic on VLAN5 by the CPU, you can either do /interface bridge add name=bridge protocol-mode=none vlan-filtering=yes /interface vlan add interface=bridge name=vlan-5 vlan-id=5 /ip address add address=192.168.1.1/24 interface=vlan-5 network=192.168.1.0 or /interface bri...
by tdw
Tue May 05, 2020 10:39 pm
Forum: Beginner Basics
Topic: CRS112 traffic slow issue, with negotiation?
Replies: 8
Views: 1725

Re: CRS112 traffic slow issue, with negotiation?

My understanding is that for 1G (and faster) copper links it is not only connection speed that needs to be negotiated, but also the line needs to be tested and some other TX/RX parameters then needs to be negotiated and/or tuned. That's done during the standard link negotiation procedure. You can s...
by tdw
Tue May 05, 2020 5:00 pm
Forum: General
Topic: Switch VLAN Trunks - Can't get it to work [SOLVED]
Replies: 8
Views: 1698

Re: Switch VLAN Trunks - Can't get it to work [SOLVED]

You have not included the CPU port in the switch VLAN configuration, see https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Management_access_configuration /interface ethernet switch vlan add independent-learning=yes ports=ether1,ether2 ,switch1-cpu switch=switch1 vlan-id=100 ... Be aware th...
by tdw
Mon May 04, 2020 5:12 pm
Forum: General
Topic: PPP profile ***-filter parametes
Replies: 4
Views: 1812

Re: PPP profile ***-filter parametes

The incoming/outgoing filter options have been present in RouterOS for some time, and do have limitations. The newer interface list or address list options may be more suitable - when set in a PPP profile these add the interface name or address respectively to a list which can be used as desired in ...
by tdw
Sun May 03, 2020 6:23 pm
Forum: Beginner Basics
Topic: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]
Replies: 56
Views: 7620

Re: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]

It is unusual to want to firewall at wire speed within a layer 2 network. At this level isolation is often for devices, rather than specific services on a device, and implemented with split-horizon or port isolation. ACLs will provide some of the functionality you are looking for but they operate pe...
by tdw
Sat May 02, 2020 6:14 pm
Forum: Beginner Basics
Topic: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]
Replies: 56
Views: 7620

Re: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]

Now, I can tell you that most of the traffic is accepted in the output chain and to a fraction in the input chain, but there is nothing in the forward chain. Hello! What about the forward chain? Cf. the documentation above: that's exactly the discrepancy between documentation and reality I mean!......
by tdw
Sat May 02, 2020 4:55 pm
Forum: Beginner Basics
Topic: SSTP - Certificates for users but not for Routers
Replies: 4
Views: 924

Re: SSTP - Certificates for users but not for Routers

The Mikrotik client certificates are optional, the VPN can still be secure without them, and Windows doesn't support them: Client checks it is talking to an authentic server by matching the CA which signed the server certificate, and optionally verifying the server hostname matches the certificate. ...
by tdw
Sat May 02, 2020 3:15 pm
Forum: Beginner Basics
Topic: Accidently overrode my License
Replies: 1
Views: 768

Re: Accidently overrode my License

Create an account on mikrotik.com (this is different from your forum account).
Select 'Request RouterBOARD license key', enter your device serial number and software ID to retrieve the license key data.
by tdw
Sat May 02, 2020 2:23 pm
Forum: Beginner Basics
Topic: SSTP - Certificates for users but not for Routers
Replies: 4
Views: 924

Re: SSTP - Certificates for users but not for Routers

Hopefully you are not using the SSTP without certificates for any important data as it is extremely insecure. From the Wiki "Between two Mikrotik routers it is also possible to set up an insecure tunnel by not using certificates at all. In this case data going through SSTP tunnel is using anonymous ...
by tdw
Fri May 01, 2020 4:29 pm
Forum: Beginner Basics
Topic: What is the Best Practice for detecting/preventing unauthorized devices in LAN?
Replies: 24
Views: 3189

Re: What is the Best Practice for detecting/preventing unauthorized devices in LAN?

If you do not use RADIUS built in to RouterOS v7 the usual choice is FreeRADIUS or Window NPS (integrated with newer Windows Server products). MAC auth - there are no changes to the device, but you need to record the MAC address of authorised devices. Certificate 802.1X - you need to create, distrib...
by tdw
Fri May 01, 2020 2:32 pm
Forum: Beginner Basics
Topic: What is the Best Practice for detecting/preventing unauthorized devices in LAN?
Replies: 24
Views: 3189

Re: What is the Best Practice for detecting/preventing unauthorized devices in LAN?

It depends on how hard you want to try preventing unauthorised devices and how determined someone is to bypass your blocks. A very simple method is to disable DHCP and only assign IP addresses with static leases or statically, this would require someone to either manually set an IP address and gatew...
by tdw
Thu Apr 30, 2020 1:51 pm
Forum: General
Topic: PPPoE client connected but no internet [SOLVED]
Replies: 10
Views: 3009

Re: PPPoE client connected but no internet [SOLVED]

On your first post you had: add action=masquerade chain=srcnat comment="default configuration" disabled=no out-interface=ether1-gateway \ Which obviously is wrong, your out interface is not eth1 but the PPPoE client... This wrong rule does not keep the router from having access to the Internet, but...
by tdw
Thu Apr 30, 2020 2:43 am
Forum: General
Topic: PPPoE client connected but no internet [SOLVED]
Replies: 10
Views: 3009

Re: PPPoE client connected but no internet [SOLVED]

There are still significant vulnerabilities in versions prior to v6.44.x. Having upgraded from such an old version I would strongly suggest resetting to the default configuration, disable the default WAN DHCP client, add a PPPoE client, add the PPPoE client interface to the WAN interface list - the ...
by tdw
Thu Apr 30, 2020 1:21 am
Forum: General
Topic: PPPoE client connected but no internet [SOLVED]
Replies: 10
Views: 3009

Re: PPPoE client connected but no internet [SOLVED]

750's are fine with recent RouterOS - I have one running v6.44.6 doing minor stuff, but due to the limited RAM disable packages you are not using (e.g. hotspot, ipv6, mpls, routing, wireless).

Not sure if you can upgrade directly from 4.5 to 6.x, going via 5.26 may work or use netinstall.
by tdw
Wed Apr 29, 2020 7:26 pm
Forum: Beginner Basics
Topic: Mangle doesn't mark website traffic from Layer 7 Protocol entry [SOLVED]
Replies: 9
Views: 2807

Re: Mangle doesn't mark website traffic from Layer 7 Protocol entry [SOLVED]

From the wiki "Warning: Queues (except Queue Trees parented to interfaces), firewall filter and mangle rules will not be applied for FastTracked traffic." so try disabling the fasttrack rule.
by tdw
Mon Apr 27, 2020 6:35 pm
Forum: General
Topic: FreeRadius-Mikrotik
Replies: 11
Views: 2468

Re: FreeRadius-Mikrotik

As I said in an earlier post the FreeRADIUS output seems incomplete, sending an Access-Accept outside of an EAP conversation will never work. The choice of MAC address as username is most unusual - typical setups are either EAP-PEAP-MSCHAPv2 with someuser@realm + somepassword as credentials allowing...
by tdw
Mon Apr 27, 2020 1:27 pm
Forum: Beginner Basics
Topic: Basic VLAN Setup
Replies: 22
Views: 3796

Re: Basic VLAN Setup

I removed switch1-cpu from switch vlan and everything is working as expected. I am not sure why this was the problem, switch1-cpu just gives access to CPU, needed or not i don't see why it caused a problem... Yeah, I couldn't begin to guess I don't really know this architecture. But I tested adding...
by tdw
Sun Apr 26, 2020 4:06 pm
Forum: Beginner Basics
Topic: Radius issue with username and special characters
Replies: 5
Views: 1568

Re: Radius issue with username and special characters

Please do not hijack old threads if they are not related - the original question was about support of extended ASCII characters. "@" is the network access identifier separator symbol and may be handled differently in FreeRADIUS 3.x, see https://networkradius.com/doc/current/raddb/mods-available/real...
by tdw
Sun Apr 26, 2020 2:14 pm
Forum: Beginner Basics
Topic: Basic VLAN Setup
Replies: 22
Views: 3796

Re: Basic VLAN Setup

Nothing obvious to stop communications, if you configure a VLAN directly on DEV-PC and connect it directly to FW1 without the CRS does it work? There are a few minor points but nothing affecting your immediate issue... As you are just using the CRS as a switch the default configuration 'WAN' and 'LA...
by tdw
Sun Apr 26, 2020 1:28 pm
Forum: Beginner Basics
Topic: Help checking my hEX S config for home office
Replies: 9
Views: 2618

Re: Help checking my hEX S config for home office

That changed the default configuration static DNS entry 'router.lan' address to match one of the new gateway addresses so the Mikrotik can be referenced by name, which is fine.
by tdw
Sat Apr 25, 2020 10:26 pm
Forum: Beginner Basics
Topic: Basic VLAN Setup
Replies: 22
Views: 3796

Re: Basic VLAN Setup

The wiki examples tend to be command-line, but making the equivalent changes through Winbox is fine. Note that many of the examples expect there to be no configuration present - if you try running the commands on a device with a default configuration you will likely get errors about ports already be...
by tdw
Sat Apr 25, 2020 6:34 pm
Forum: General
Topic: FreeRadius-Mikrotik
Replies: 11
Views: 2468

Re: FreeRadius-Mikrotik

Nothing obvious. You appear to have configured the RADIUS connector to handle PPP, login, hotspot & wireless - these will send requests in differing formats so your RADIUS server will have to handle them appropriately, the PPP and hotspot options appear to be redundant as there are no PPP or hostpot...
by tdw
Sat Apr 25, 2020 6:16 pm
Forum: Beginner Basics
Topic: Basic VLAN Setup
Replies: 22
Views: 3796

Re: Basic VLAN Setup

Assuming that your other firewalls are handling routing, etc. and the CRS is just being a switch then https://wiki.mikrotik.com/wiki/Manual:CRS1xx/2xx_series_switches_examples#Example_1_.28Trunk_and_Access_ports.29 for the access ports, and the incremental changes https://wiki.mikrotik.com/wiki/Manu...
by tdw
Fri Apr 24, 2020 3:51 pm
Forum: General
Topic: FreeRadius-Mikrotik
Replies: 11
Views: 2468

Re: FreeRadius-Mikrotik

Screenshots do not show enough detail, posting the output of /export hide-sensitive is a good starting point.

The FreeRADIUS output seems incomplete, there is no indication of EAP messages - sending an Access-Accept outside of the EAP handshake will fail as there is no keying information provided.
by tdw
Wed Apr 22, 2020 1:42 pm
Forum: General
Topic: RB4011: Untagged Ports Overriden by Default VID1? [SOLVED]
Replies: 13
Views: 3163

Re: RB4011: Untagged Ports Overriden by Default VID1? [SOLVED]

you can also omit /interface bridge vlan untagged entries ( untagged= ), these will be generated automatically from the /interface bridge port PVID entries ( pvid= ) If I need to change some ports PVID later, will the untagged entries follow automatically? Yes, changing the pvid= settings in /inter...
by tdw
Wed Apr 22, 2020 1:57 am
Forum: General
Topic: RB4011: Untagged Ports Overriden by Default VID1? [SOLVED]
Replies: 13
Views: 3163

Re: RB4011: Untagged Ports Overriden by Default VID1? [SOLVED]

A bridge has two roles - one like a switch between member ports, the other an interface for traffic to the CPU. You haven't included the interface-like role in the bridge VLAN configuration. If you are creating VLAN interfaces for all CPU traffic leave the PVID on the bridge itself unchanged (i.e. 1...
by tdw
Tue Apr 21, 2020 11:03 pm
Forum: General
Topic: RB4011: Untagged Ports Overriden by Default VID1? [SOLVED]
Replies: 13
Views: 3163

Re: RB4011: Untagged Ports Overriden by Default VID1? [SOLVED]

Mikrotik have not implemented hardware VLAN support for the switch chip used in the RB4011. You should be using a single VLAN-aware bridge, in which case you just have to set the PVID for the bridge port interface. Posting the output of /export hide-sensitive usually helps.
by tdw
Tue Apr 21, 2020 2:24 pm
Forum: General
Topic: 802.3ad bond running when link down
Replies: 13
Views: 2308

Re: 802.3ad bond running when link down

That is a different case to the scenario the OP describes - you are disconnecting the cables, not interrupting traffic flow. From the wiki "MII monitoring monitors only the state of the local interface .... Main disadvantage is that MII monitoring can't tell if the link can actually pass packets or ...
by tdw
Sun Apr 19, 2020 3:54 pm
Forum: Beginner Basics
Topic: UPnP doesn't work [SOLVED]
Replies: 3
Views: 2110

Re: UPnP doesn't work [SOLVED]

Your ISP may offer public IP addresses. Some do not, some do but often charge an extra fee.
by tdw
Fri Apr 17, 2020 4:01 pm
Forum: Beginner Basics
Topic: Problem with external IP [SOLVED]
Replies: 2
Views: 1968

Re: Problem with external IP [SOLVED]

Your netmask is incorrect, it should likely be 255.255.255.0 or /24 so any destination outside 192.168.1.x is reached via the gateway.
by tdw
Fri Apr 17, 2020 3:53 pm
Forum: Beginner Basics
Topic: UPnP doesn't work [SOLVED]
Replies: 3
Views: 2110

Re: UPnP doesn't work [SOLVED]

The 100.64.x.x address indicates your ISP is using CGNAT to share public IP addresses between customers. It is not possible to port forward or use UPnP with this additional layer of NAT between a public IP and your router.
by tdw
Wed Apr 15, 2020 2:02 pm
Forum: Beginner Basics
Topic: I can't login in to my Router after Setting up hotspot of default bridge.
Replies: 1
Views: 1118

Re: I can't login in to my Router after Setting up hotspot of default bridge.

When the hotspot is activated on an interface all traffic through that interface is processed by the hotspot firewall chains. Once you are authenticated to the hotspot you should be able to connect to the Mikrotik, or you can use a hotspot IP binding to bypass hotspot authentication https://wiki.mik...
by tdw
Wed Apr 15, 2020 1:51 pm
Forum: Beginner Basics
Topic: Problems with DHCP server and bridge mode
Replies: 16
Views: 3278

Re: Problems with DHCP server and bridge mode

Why do you have domain=208.67.222.220 and dns-server=8.8.8.8,208.67.222.222,8.8.4.4,0.0.0.0 in the /ip dhcp-server network configuration?
by tdw
Tue Apr 14, 2020 2:25 pm
Forum: Beginner Basics
Topic: Problems with DHCP server and bridge mode
Replies: 16
Views: 3278

Re: Problems with DHCP server and bridge mode

Those screenshots provide insufficient information, post the output of /export hide-sensitive from a terminal window.
by tdw
Tue Apr 14, 2020 2:14 pm
Forum: Beginner Basics
Topic: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]
Replies: 54
Views: 8510

Re: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]

You have removed the /interface list member entry for the PPPoE client completely, not changed it as suggested.

No idea why the DNS resolves as you describe, it could be your ISP blocking access to that site. Do other sites resolve correctly?
by tdw
Tue Apr 14, 2020 2:07 pm
Forum: Beginner Basics
Topic: Help checking my hEX S config for home office
Replies: 9
Views: 2618

Re: Help checking my hEX S config for home office

@ITDave According to the block diagram you can use the SFP and ether1 at the same time.

@hallz the output of /export hide-sensitive having executed your script would provide a better picture of what you have done
by tdw
Tue Apr 14, 2020 1:46 pm
Forum: Beginner Basics
Topic: IPv6 in address list
Replies: 1
Views: 1006

Re: IPv6 in address list

Are you attempting to add an IPv6 address to an IP(v4) address list? The IPv6 configuration is completely independent from IPv4 so setting up an access control list to a service, for example, requires two address lists (IP > Firewall > Address Lists & IPv6 > Firewall > Address Lists) and correspondi...
by tdw
Mon Apr 13, 2020 4:58 pm
Forum: Beginner Basics
Topic: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]
Replies: 54
Views: 8510

Re: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]

You appear to have two PPPoE client interfaces name=pppoe-out1 and name=pppoe-outl , remove the unused one and correct the /interface list membership entry - it appears to be the wrong PPPoE client, so NAT will not work As mentioned before the /ip address is incorrectly specified on interface=ether2...
by tdw
Sun Apr 12, 2020 7:59 pm
Forum: Beginner Basics
Topic: RB2011 what to do with second switch when doing VLAN
Replies: 8
Views: 2162

Re: RB2011 what to do with second switch when doing VLAN

Yes, the 8337 supports them as detailed in the link
by tdw
Sun Apr 12, 2020 6:52 pm
Forum: Beginner Basics
Topic: RB2011 what to do with second switch when doing VLAN
Replies: 8
Views: 2162

Re: RB2011 what to do with second switch when doing VLAN

https://wiki.mikrotik.com/wiki/Manual:S ... d_Ports.29

Be aware it is not possible to have hybrid ports on the fast ethernet switch chips Mikrotik have used, including the integrated 8227 used for ether6-10 on the 2011
by tdw
Sun Apr 12, 2020 2:03 pm
Forum: Beginner Basics
Topic: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]
Replies: 54
Views: 8510

Re: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]

So the TP-Link should be handling the VLAN encapsulation: [ DSL WAN -- VLAN1885 -- TP-Link bridge ] ==== [ Mikrotik ether1 -- PPPoE client ] To implement the VLAN on the Mikrotik: [ DSL WAN -- TP-Link bridge ] ==== [ Mikrotik ether1 -- VLAN1885 -- PPPoE client ] /interface vlan add interface=ether1 ...
by tdw
Sat Apr 11, 2020 9:14 pm
Forum: Beginner Basics
Topic: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]
Replies: 54
Views: 8510

Re: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]

The LAN IP address should be set on the bridge, not one of the member interfaces (if you have not changed this it may be a bug in Quickset) /ip address add address=192.168.1.2/24 comment=defconf interface= bridge network=192.168.1.0 The DHCP client on ether1 appears to be disabled, if you wish to ac...
by tdw
Sat Apr 11, 2020 6:47 pm
Forum: Beginner Basics
Topic: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]
Replies: 54
Views: 8510

Re: Getting VDSL connected via TPLink with VLAN working with Mikrotik Hap Lite [SOLVED]

Cloning the TP-Link WAN ethernet address should only necessary if the PPPoE client fails to establish a connection, it sounds as though that is not the case here although it is odd that you are seeing a different IP address. Post the output of /export hide-sensitive after obfuscating public IPs, etc...
by tdw
Fri Apr 10, 2020 8:24 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS+ 802.1Q VLANs
Replies: 4
Views: 2429

Re: RB4011iGS+ 802.1Q VLANs

Atheros switch chips support an additional header in traffic between the CPU and switch chip, together with Linux driver support this allows logical etherX interfaces to be multiplexed over the single communication channel to physical ethernet interfaces using port-based VLANs - this is completely h...
by tdw
Thu Apr 09, 2020 8:45 pm
Forum: General
Topic: CCR1009 configuration
Replies: 6
Views: 1705

Re: CCR1009 configuration

I should have said smart card slot - a SIM is just a particular type of smart card.
by tdw
Thu Apr 09, 2020 8:24 pm
Forum: General
Topic: CCR1009 configuration
Replies: 6
Views: 1705

Re: CCR1009 configuration

There is both a microSD slot and a SIM slot, none of the CCR devices have miniPCIe slots. AFAIK the SIM slot was intended for secure crypto storage, although this was never finished.
by tdw
Wed Apr 08, 2020 9:53 pm
Forum: General
Topic: Hybrid Port Possible?
Replies: 2
Views: 1209

Re: Hybrid Port Possible?

Almost... /interface bridge port add bridge=bridge comment=defconf hw=no interface=ether2 pvid=100 The /interface bridge vlan settings may be incorrect, it depends on what parameters you have specified for the bridge itself under /interface bridge . Note untagged membership does not have to be expli...
by tdw
Tue Apr 07, 2020 8:55 pm
Forum: Beginner Basics
Topic: Unidentified traffic
Replies: 7
Views: 1786

Re: Unidentified traffic

What version of RouterOS are you running, are any services accessible from the internet?

It is odd for the Mikrotik to be the connection destination IP address if the traffic is outbound.
by tdw
Tue Apr 07, 2020 4:27 am
Forum: Beginner Basics
Topic: basic dual WAN configuration do not work
Replies: 10
Views: 2431

Re: basic dual WAN configuration do not work

I'm sure load balancing with dynamic gateways will have cropped up before in the forums - a script triggered by the DHCP client, or possibly using routing filters. It depends on what you need - if all traffic will be to/from ISP1, other than replies to that coming from ISP2, instead of full load bal...
by tdw
Tue Apr 07, 2020 3:10 am
Forum: Beginner Basics
Topic: basic dual WAN configuration do not work
Replies: 10
Views: 2431

Re: basic dual WAN configuration do not work

There do not appear to be any mangle rules or additional routing tables to properly support dual WAN operation. Replies to traffic arriving from either ISP1 or ISP2 will return via the best default route to ISP1 - this may have accidentally worked until the nightly engineering works correctly blocke...
by tdw
Mon Apr 06, 2020 7:34 pm
Forum: General
Topic: CRS326-24G - Dual BSD firewalls, CARP, mac address learning and host timeout issues
Replies: 12
Views: 2445

Re: CRS326-24G - Dual BSD firewalls, CARP, mac address learning and host timeout issues

VRRP transmits the shared MAC address from whichever device is currently master. I've not used CARP, but I would have expected it do the same - maybe with a configuration option if not the default.
by tdw
Mon Apr 06, 2020 4:01 pm
Forum: General
Topic: CRS326-24G - Dual BSD firewalls, CARP, mac address learning and host timeout issues
Replies: 12
Views: 2445

Re: CRS326-24G - Dual BSD firewalls, CARP, mac address learning and host timeout issues

I believe the SSH crypto comment is due to /ip ssh set allow-none-crypto=yes as a previous RouterOS upgrade erroneously added this. The switch itself will only be making ARP requests associated with its management interface. The traffic egress port will be selected by the contents of the FDB, this i...
by tdw
Sun Apr 05, 2020 4:27 pm
Forum: Beginner Basics
Topic: no WAN?
Replies: 8
Views: 2034

Re: no WAN?

That is unlikely to be the MAC address the modem sees - the bridge is 'LAN' side of the Mikrotik. Assuming the modem is connected to ether1, the command for changing the interface MAC address is /interface ethernet set [ find default-name=ether1 ] mac-address=XX:XX:XX:XX:XX:XX I suspect that after t...
by tdw
Sun Apr 05, 2020 3:56 am
Forum: General
Topic: crs3xx - bridge filter - hw offloading?
Replies: 5
Views: 1744

Re: crs3xx - bridge filter - hw offloading?

I do not have a CRS3xx to test on, but whilst hardware offloading is active I would expect /interface bridge filter only to process packets between the switch and CPU, and that to process packets between switch ports you would have to use switch ACLs /interface ethernet switch rule - see https://wik...
by tdw
Sat Apr 04, 2020 11:27 pm
Forum: Beginner Basics
Topic: Bonding multi ISP with CRS312-4C+8XG-RM?
Replies: 10
Views: 2348

Re: Bonding multi ISP with CRS312-4C+8XG-RM?

Be aware that the CRS products are intended to be L2 switches with limited L3 performance. You might achieve a few hundred Mb throughput, performance figures are here https://mikrotik.com/product/crs312_4c_ ... estresults
by tdw
Fri Apr 03, 2020 10:33 pm
Forum: Beginner Basics
Topic: no WAN?
Replies: 8
Views: 2034

Re: no WAN?

If the DHCP client were not present the PC would not have an address from the Mikrotik in either case. This is incorrect, the Mikrotik 'WAN' connection DHCP client not obtaining an address will not interfere with the 'LAN' connection DHCP server providing addresses to the attached PC. My problem is...
by tdw
Fri Apr 03, 2020 5:02 pm
Forum: Beginner Basics
Topic: Easiest VPN method for Native Windows 10 VPN?
Replies: 1
Views: 1288

Re: Easiest VPN method for Native Windows 10 VPN?

Presumably you want to use split tunnelling so not all the client traffic is via the VPN. AFAIK you can use the Windows CMAK to build a VPN connector with associated static routes.
by tdw
Wed Apr 01, 2020 2:15 pm
Forum: Beginner Basics
Topic: RoaS with CRS112 switch and HAP ac2 [SOLVED]
Replies: 8
Views: 3709

Re: RoaS with CRS112 switch and HAP ac2 [SOLVED]

That would not break anything, the non-RSTP device would ignore the BPDU packets, but a non-optimal setup. RSTP is good in larger setups for redundant paths and/or preventing storms if two edge ports are connected together, but probably unnecessary for a home setup. It does introduce a ~15 seconds f...
by tdw
Wed Apr 01, 2020 3:57 am
Forum: General
Topic: ARP Request/Reply [SOLVED]
Replies: 7
Views: 3526

Re: ARP Request/Reply [SOLVED]

Might be worth looking at the /ip dhcp-server option add-arp=yes, and local proxy-arp https://wiki.mikrotik.com/wiki/Manual:I ... _Proxy_Arp mode.
by tdw
Wed Apr 01, 2020 12:52 am
Forum: Beginner Basics
Topic: disabling Auto Negotiation on 1000M full [SOLVED]
Replies: 10
Views: 4383

Re: disabling Auto Negotiation on 1000M full [SOLVED]

It was on fiber, come to think of it, not copper.
That makes sense, there isn't an equivalent of the NWay copper link negotiation for fibre.
by tdw
Tue Mar 31, 2020 3:19 pm
Forum: Beginner Basics
Topic: disabling Auto Negotiation on 1000M full [SOLVED]
Replies: 10
Views: 4383

Re: disabling Auto Negotiation on 1000M full [SOLVED]

If true, the standard is not uniformly obeyed. In my region, CenturyLink gateway feeds are routinely supplied that run 1G and refuse negotiation, and you can't connect with them unless you configure your interface as 1G non-negotiated. Something to watch out for. If that is on a copper interface ce...
by tdw
Tue Mar 31, 2020 4:43 am
Forum: Beginner Basics
Topic: disabling Auto Negotiation on 1000M full [SOLVED]
Replies: 10
Views: 4383

Re: disabling Auto Negotiation on 1000M full [SOLVED]

With both devices, I have never gotten a successful connection to any of my various periphal devices when the routers Ethernet port is configured as a 1G link without Auto Negotiation: You will not, auto-negotiation is mandatory for 1000BASE-T. The definitive reference is IEEE standard 802.3, Secti...
by tdw
Tue Mar 31, 2020 12:35 am
Forum: Beginner Basics
Topic: Port based vlan on CSR1xx and issue with Unifi APs - broadcast SSIDs but they do not have IP addresses
Replies: 4
Views: 1705

Re: Port based vlan on CSR1xx and issue with Unifi APs - broadcast SSIDs but they do not have IP addresses

Historically UniFi only supported untagged management. I believe that tagged management support has been added, BUT this will only be for adopted and provisioned devices - the initial controller discovery and connection to the controller has to be over an untagged network.
by tdw
Mon Mar 30, 2020 4:08 pm
Forum: Beginner Basics
Topic: Anyconnect [SOLVED]
Replies: 2
Views: 2495

Re: Anyconnect [SOLVED]

It isn't possible, RouterOS only supports IPsec (native and L2TP/GRE/IPIP/EoIP tunnels), SSTP, OpenVPN (not all features), PPTP (avoid as insecure).
by tdw
Mon Mar 30, 2020 3:53 pm
Forum: Beginner Basics
Topic: Isolate home devices with VLANs
Replies: 10
Views: 2659

Re: Isolate home devices with VLANs

And here is the Dynamic Bridge config that I think can't be seen in the export above. This is the remains of the default configuration. Maybe this is the reason? I don't know if and possibly how to get rid of it.: The VLAN-aware bridge documentation indicates you have to configure the PVID in /inte...
by tdw
Sun Mar 29, 2020 9:49 pm
Forum: Beginner Basics
Topic: RoaS with CRS112 switch and HAP ac2 [SOLVED]
Replies: 8
Views: 3709

Re: RoaS with CRS112 switch and HAP ac2 [SOLVED]

No default route on the switch so it won't be able to reply to anything outside 192.168.0.0/24
/ip route
add gateway=192.168.0.1
by tdw
Sun Mar 29, 2020 6:54 pm
Forum: Beginner Basics
Topic: allow traffic from eth1 WAN to bridge
Replies: 4
Views: 1414

Re: allow traffic from eth1 WAN to bridge

When you send traffic to any address outside 192.168.1.0/24 from your laptop it is sent to the gateway address on your ISP router. Unless that router knows specifically where to send traffic destined for 192.168.0.0/24 to, it will be sent to the WAN. You need to configure a static route on the ISP r...
by tdw
Sun Mar 29, 2020 6:41 pm
Forum: Beginner Basics
Topic: RoaS with CRS112 switch and HAP ac2 [SOLVED]
Replies: 8
Views: 3709

Re: RoaS with CRS112 switch and HAP ac2 [SOLVED]

Mikrotik VLAN configuration has historically been a mess, older versions of RouterOS it did look as though many of the switch chip registers were just presented to the user to figure out. It is getting better with the CRS3xx implementation handling all the behind-the-scenes switch chip configuration...
by tdw
Sun Mar 29, 2020 4:39 am
Forum: Beginner Basics
Topic: What does it mean by USR led which is always turned off [HAP AC²]
Replies: 1
Views: 1284

Re: What does it mean by USR led which is always turned off [HAP AC²]

It can be configured to report a variety of status information or be controlled by a script https://wiki.mikrotik.com/wiki/Manual:System/LEDS
by tdw
Sun Mar 29, 2020 4:33 am
Forum: Beginner Basics
Topic: RoaS with CRS112 switch and HAP ac2 [SOLVED]
Replies: 8
Views: 3709

Re: RoaS with CRS112 switch and HAP ac2 [SOLVED]

The VLAN-aware bridge documentation indicates you have to configure the untagged membership to be the same in both /interface bridge port and /interface bridge vlan , you are missing it in the bridge port entry. In practice if you only configure it in /interface bridge port the corresponding members...
by tdw
Sun Mar 29, 2020 4:02 am
Forum: General
Topic: VLAN bridging performance
Replies: 1
Views: 1036

Re: VLAN bridging performance

There will be no change in performance on a CCR1036 as it does not have a hardware switch chip.
  • 1
  • 2