Community discussions

Search found 98 matches

by whatever
Thu Sep 12, 2019 6:58 pm
Forum: Wireless Networking
Topic: CAPsMAN with GUEST in non dhcp environment
Replies: 2
Views: 302

Re: CAPsMAN with GUEST in non dhcp environment

Use multiple vlans to separate your stuff.
by whatever
Wed Aug 28, 2019 9:10 am
Forum: Wireless Networking
Topic: Capsman Channels
Replies: 5
Views: 554

Re: Capsman Channels

Yes, one capsman channel is actually more like a channel list and can have multiple frequencies.
by whatever
Tue Aug 27, 2019 9:12 pm
Forum: Wireless Networking
Topic: Capsman Channels
Replies: 5
Views: 554

Re: Capsman Channels

Defining a channel in capsman does nothing until you refer to it in a configuration.
by whatever
Fri Aug 23, 2019 6:27 pm
Forum: General
Topic: New RB450G☓4 Breaks Google and its Services (Solved)
Replies: 13
Views: 1061

Re: New RB450G☓4 Breaks Google and its Services

Your IP addresses are both assigned to ether2 which is part of the bridge, you probably meant to assign them to bride and ether5, like your dhcp servers.

Edit: 172.0.0.0/8 is not a private ip range!!! Don't use it on your LAN. Your configured netmask fucks up routing to any public 172.x.y.z IP.
by whatever
Tue Aug 20, 2019 9:00 am
Forum: Wireless Networking
Topic: RBwAPG-5HacT2HnD + CAPsMAN + Rates config = 5Ghz network doesn't work
Replies: 6
Views: 719

Re: RBwAPG-5HacT2HnD + CAPsMAN + Rates config = 5Ghz network doesn't work

I've tried enabling all rates, and I get the same result.
Expected result, i don't think you understand how basic rates are used.
Why do you want to use custom rates at all? Is there any issue with the default rateset?


PS: Try enabling only 12Mbps as basic rate.
by whatever
Thu Aug 15, 2019 8:47 am
Forum: Wireless Networking
Topic: RBwAPG-5HacT2HnD + CAPsMAN + Rates config = 5Ghz network doesn't work
Replies: 6
Views: 719

Re: RBwAPG-5HacT2HnD + CAPsMAN + Rates config = 5Ghz network doesn't work

You have disabled all basic rates!? I don't think that is a good idea.
by whatever
Thu Jul 18, 2019 6:41 pm
Forum: Wireless Networking
Topic: Wireless AC performence issue
Replies: 3
Views: 626

Re: Wireless AC performence issue

This seems to be a common pattern, looks like it's pretty much impossible to achieve more than 250-300 Mbit/s real world single client throughput with Mikrotik ac WiFi.
In case you ever manage to break this limit please let me know how you did it :)
by whatever
Tue Jun 11, 2019 7:20 pm
Forum: Announcements
Topic: v6.44.3 [stable] is released!
Replies: 123
Views: 31077

Re: v6.44.3 [stable] is released!

[Ticket#2019030922002071] CAP not correctly forwarding tagged vlan traffic towards wired network Glad it is not just me, I have the same issue effecting 1000's of units, if you disable the CAP and enable everything works again for a period of time and stops again. I have raised tickets with support...
by whatever
Fri Jun 07, 2019 9:13 am
Forum: Wireless Networking
Topic: [ETA] new wireless driver?
Replies: 3
Views: 640

Re: [ETA] new wireless driver?

New driver will be bundled with ROS 7 :lol:
by whatever
Wed May 29, 2019 7:35 pm
Forum: Wireless Networking
Topic: Access Point and Sniffer on one Wlan 2.4
Replies: 7
Views: 503

Re: Access Point and Sniffer on one Wlan 2.4

Is this "very important" way of tracking people legal in your country? As far as I know iOS devices as well as the latest Android versions already randomize their mac address when probing for wifi networks as countermeasure to this kind of privacy violation.
by whatever
Tue May 07, 2019 9:14 am
Forum: Wireless Networking
Topic: RB4011iGS+5HacQ2HnD-IN 5Ghz disappearing
Replies: 8
Views: 1065

Re: RB4011iGS+5HacQ2HnD-IN 5Ghz disappearing

This might be related to viewtopic.php?f=7&t=148263 !?
At least it sounds similar.
by whatever
Mon May 06, 2019 7:00 pm
Forum: Wireless Networking
Topic: CAPsMAN and CAP AC2 - 5Ghz stops working without any log message
Replies: 23
Views: 1873

Re: CAPsMAN and CAP AC2 - 5Ghz stops working without any log message

I have the same issue, forcing channel reselect is enough to revive the 5GHz interface. I'm using a low channel reselect interval as workaround.

Edit: I'm running only hap ac2 units with local forwarding and one of them acting as capsman, no other hardware involved.
by whatever
Mon Apr 29, 2019 9:30 am
Forum: Wireless Networking
Topic: hAP ac2 as bridge and CAP
Replies: 6
Views: 691

Re: hAP ac2 as bridge and CAP

I think that's only possible without capsman.
by whatever
Tue Apr 02, 2019 9:46 pm
Forum: Wireless Networking
Topic: Single SSID multiple passwords
Replies: 8
Views: 729

Re: Single SSID multiple passwords

You can only achieve that by setting password and vlan id per client MAC address. As you probably won't know all your guest's devices, you would have to set up an access rule for each of your private devices. I wouldn't recommend it, a second SSID is most likely the better solution.
by whatever
Thu Mar 28, 2019 10:03 am
Forum: Wireless Networking
Topic: Mikrotik WLAN & CAPsMAN - Bad download perfomance
Replies: 47
Views: 5087

Re: CAPsMAN poor wireless speed

So MIMO is broken in some way that prevent any speed gain from additional chains? Interesting observation, let's hope that this is reproducible and fixable by mikrotik.
by whatever
Wed Mar 20, 2019 6:01 pm
Forum: Announcements
Topic: v6.43.13 [long-term] is released!
Replies: 44
Views: 9296

Re: v6.43.13 [long-term] is released!

Is it safe to downgrade from 6.44?
Edit: Did it, appears to work fine.
by whatever
Fri Mar 15, 2019 9:22 am
Forum: General
Topic: Problems with Router hap ac2
Replies: 4
Views: 309

Re: Problems with Router hap ac2

Once you start to change settings outside of quickset you should stop using quickset.
by whatever
Sun Mar 10, 2019 5:09 pm
Forum: Wireless Networking
Topic: HD video over ptp 60Ghz wirless wire
Replies: 3
Views: 308

Re: HD video over ptp 60Ghz wirless wire

Are you 100% sure that your converter outputs standard Ethernet frames?
by whatever
Fri Mar 08, 2019 10:45 pm
Forum: Wireless Networking
Topic: Mikrotik WLAN & CAPsMAN - Bad download perfomance
Replies: 47
Views: 5087

Re: CAPsMAN poor wireless speed

Personally, I get > 100Mbps using wAP AC + RB3011 running CAPsMAN, local forwarding.
But you shouldn't you expect > 500Mbps with three chains on 5GHz ac? I consider 100Mbps with that hardware pretty slow, that speed is already achievable with 2.4GHz dual chain n.
by whatever
Wed Mar 06, 2019 9:21 am
Forum: General
Topic: IPv6, subnet isolation, NAT
Replies: 1
Views: 157

Re: IPv6, subnet isolation, NAT

You really shouldn't try to use only local addresses and NAT with IPv6. If you want local addresses use them additionally to your public prefix. For public routable addresses enable IPv6 prefix delegation on your Fritz Box, add DHCPv6 client on your Fritz Box facing mikrotik interface to request pre...
by whatever
Mon Mar 04, 2019 9:22 am
Forum: Wireless Networking
Topic: CAPsMAN & Wireless Speeds
Replies: 2
Views: 838

Re: CAPsMAN & Wireless Speeds

Try local forwarding
by whatever
Mon Feb 25, 2019 6:36 pm
Forum: Wireless Networking
Topic: Mikrotik WLAN & CAPsMAN - Bad download perfomance
Replies: 47
Views: 5087

Re: CAPsMAN poor wireless speed

How do you decide how fast your wireless speed is supposed to be? My hap ac2 802.11ac 2x2 speed with capsman and local forwarding is indeed about half of what you would expect from the standard under perfect conditions, until now I've been blaming it on cheap hardware and poor drivers. But consideri...
by whatever
Fri Feb 22, 2019 9:26 am
Forum: General
Topic: Security issue when Winbox exposed
Replies: 68
Views: 5698

Re: Security issue when Winbox exposed

Are there still people dumb enough to expose winbox to anything but an isolated management vlan? Don't do it, the winbox protocol obviously is not designed to be secure.
by whatever
Thu Feb 14, 2019 8:40 am
Forum: Wireless Networking
Topic: Help Hacker sending deauth packet
Replies: 6
Views: 753

Re: Help Hacker sending deauth packet

Did you try to change your MAC address to something that doesn't look like mikrotik? Like use your phone mac and increment the last byte?
by whatever
Sat Feb 02, 2019 2:12 pm
Forum: Wireless Networking
Topic: CAPsMAN not adding dynamically interfaces to bridge
Replies: 4
Views: 403

Re: CAPsMAN not adding dynamically interfaces to bridge

Local forwarding means the traffic is forwarded to a bridge on the cap itself, not on capsman. You can select the bridge in the cap settings on your cap.
by whatever
Fri Feb 01, 2019 11:19 pm
Forum: General
Topic: Poor WiFi performance - hAP AC ^2
Replies: 6
Views: 1585

Re: Poor WiFi performance - hAP AC ^2

In optimal conditions I get up to ~230 Mbit/s WiFi downstream with hap ac2 as AP on a 400 Mbit/s Internet Connection. 5 GHz, 80 Mhz channel (Ceee), dual chain, ac-only, 1-2m distance without any obstacles. It should be possible to achieve more than 400Mbit/s in this conditions (I maxed out 400 with ...
by whatever
Tue Jan 29, 2019 9:36 am
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 87509

Re: Winbox vulnerability: please upgrade

@Darman: if your device got infected you should reset it to factory defaults to ensure all the nasty stuff is removed.
by whatever
Fri Jan 18, 2019 9:08 am
Forum: Wireless Networking
Topic: android devices chooses 2.4Ghz over 5Ghz on hAP ac^2
Replies: 13
Views: 1392

Re: android devices chooses 2.4Ghz over 5Ghz on hAP ac^2

You can raise the "antenna gain" setting on the 2.4GHz interface by some db, this will lower its tx power and cause most clients to prefer the now stronger 5GHz network.
However, this will also reduce your 2.4GHz signal range, so this "solution" isn't always feasible.
by whatever
Thu Jan 17, 2019 6:10 pm
Forum: RouterBOARD hardware
Topic: RouterBOARD naming... not consistent!
Replies: 4
Views: 446

Re: RouterBOARD naming... not consistent!

Afaik there is no way to change it. Other models like hap ac2 are similarly affected.
by whatever
Thu Jan 10, 2019 10:09 pm
Forum: Announcements
Topic: v6.42.11 [long-term] is released!
Replies: 42
Views: 8736

Re: v6.42.11 [long-term] is released!

So do not make this big change in "long-term". This is not a bugfix, but a change in function....... I guess releasing a "new" version which doesn't respect country regulations might cause legal trouble. But a simple notice in the changelog wouldn't hurt either: "Make sure you are compliant with yo...
by whatever
Tue Jan 01, 2019 12:35 pm
Forum: Announcements
Topic: v6.43.8 [stable] is released!
Replies: 169
Views: 32986

Re: v6.43.8 [stable] is released!

Wow. Does every process in routeros run with unrestricted root privileges?
by whatever
Mon Dec 31, 2018 12:08 am
Forum: Announcements
Topic: v6.43.8 [stable] is released!
Replies: 169
Views: 32986

Re: v6.43.8 [stable] is released!

Thank you for that info, it's rather interesting that wifi is still usable with 36 sec update interval.
I really hope that the fix gets backported to long-term soon.
by whatever
Fri Dec 28, 2018 10:16 pm
Forum: Announcements
Topic: v6.43.8 [stable] is released!
Replies: 169
Views: 32986

Re: v6.43.8 [stable] is released!

*) capsman - fixed "group-key-update" parameter not using correct units;
Can we get some details on this?
How was the parameter interpreted before this fix? Is the long-term release affected by the same bug? If yes: when can we expect a backport of this bugfix to long-term?
by whatever
Thu Dec 27, 2018 2:56 pm
Forum: Wireless Networking
Topic: Mikrotik RB4011iGS+5HacQ2HnD and WiFi 802.11 AC 160mhz
Replies: 36
Views: 4829

Re: Mikrotik RB4011iGS+5HacQ2HnD and WiFi 802.11 AC 160mhz

As already mentioned: You can only benefit from features which are supported by AP and client. If your client only supports 80 MHz with dual chain you will not benefit from all four chains which are available on the 4011.
by whatever
Tue Dec 04, 2018 10:17 pm
Forum: Wireless Networking
Topic: Capsman anf firmware 6.43.4
Replies: 1
Views: 413

Re: Capsman anf firmware 6.43.4

It's highly unlikely that your dst-address=127.0.0.1 rule will match traffic to 192.168.0.1:5246. Try to use a dst-address-type=local src-address-type=local rule like documented at https://wiki.mikrotik.com/wiki/Manual:S ... in_CAPsMAN
by whatever
Sat Dec 01, 2018 2:02 pm
Forum: Wireless Networking
Topic: Multiple APs + seamless + wired backbone
Replies: 3
Views: 590

Re: Multiple APs + seamless + wired backbone

RTSP or WDS is completely unrelated to your problem. I had some ARP issues that disappeared as soon as I set multicast-helper on the wireless interfaces to "full", you might try if that helps your usecase. In order to support your client devices in roaming you should rather lower the tx-power of you...
by whatever
Fri Nov 30, 2018 6:37 pm
Forum: Wireless Networking
Topic: Removing Mikrotik elements from beacons
Replies: 15
Views: 2294

Re: Removing Mikrotik elements from beacons

Didn't even know they were doing this, that's definitely something I'd like to turn off. +1
by whatever
Mon Nov 26, 2018 12:21 pm
Forum: Beginner Basics
Topic: Advertising with Mikrotik
Replies: 4
Views: 443

Re: Advertising with Mikrotik

You dont!?
Nowadays the majority of websites uses https which is designed to be non-interceptable.
by whatever
Mon Nov 26, 2018 9:19 am
Forum: Wireless Networking
Topic: how to disabled WMM?
Replies: 1
Views: 465

Re: how to disabled WMM?

You don't. You can only toggle the QOS part, why do you want to disable it completely?
by whatever
Fri Nov 23, 2018 9:27 am
Forum: General
Topic: Windows update + Proxy
Replies: 5
Views: 626

Re: Windows update + Proxy

Shouldn't they have a WSUS server for centralized update management?
by whatever
Thu Nov 22, 2018 3:37 pm
Forum: Wireless Networking
Topic: Capsman wrongly provisions CAPs
Replies: 5
Views: 611

Re: Capsman wrongly provisions CAPs

Changing identity to serial number via script should be possible.
by whatever
Wed Nov 21, 2018 10:02 pm
Forum: General
Topic: 802.3ad Hash Keys
Replies: 2
Views: 276

Re: 802.3ad Hash Keys

That is not possible with the standard linux transmit hash policies for 802.3ad.
Thoughts: Why the hell would you want that???
by whatever
Wed Nov 21, 2018 6:08 pm
Forum: Wireless Networking
Topic: Capsman wrongly provisions CAPs
Replies: 5
Views: 611

Re: Capsman wrongly provisions CAPs

Well, regex "79" does indeed match "179", etc., so the result you are experiencing is expected.
Try using "^" and "$" in your regexes to match beginning and end of your identity strings.
by whatever
Fri Nov 16, 2018 7:38 pm
Forum: RouterBOARD hardware
Topic: hAP AC2 availability
Replies: 26
Views: 4129

Re: hAP AC2 availability

That's interesting, I guess the change happened with the switch to factory software 6.42+. I own several devices with factory software 6.40 and 6.41 and all of them have 233MB.
by whatever
Thu Nov 15, 2018 11:36 am
Forum: RouterBOARD hardware
Topic: hAP AC2 availability
Replies: 26
Views: 4129

Re: hAP AC2 availability

Has anyone ever received a unit with less than 230MB RAM?
by whatever
Sun Nov 11, 2018 6:14 pm
Forum: RouterBOARD hardware
Topic: hAP AC2 availability
Replies: 26
Views: 4129

Re: hAP AC2 availability

While it's currently unavailable at all the large distributors, the smaller ones apparently have some stock left.
by whatever
Fri Nov 09, 2018 5:54 pm
Forum: Wireless Networking
Topic: Hap ac & poor performance in 2.4GHz and 5GHz [SOLVED]
Replies: 20
Views: 1895

Re: Hap ac & poor performance in 2.4GHz and 5GHz [SOLVED]

For local forwarding to work you got to setup your L2 network accordingly and configure the bridge to drop the traffic on the CAP.
Without local forwarding all your traffic will be tunneled (possibly encrypted) to the CapsMan, that's not a good idea on a device with low CPU power.
by whatever
Wed Nov 07, 2018 9:17 am
Forum: General
Topic: Bonding LACP
Replies: 2
Views: 334

Re: Bonding LACP

You have to set a different transmit hash policy on the Huawei router.
by whatever
Mon Nov 05, 2018 3:46 pm
Forum: Wireless Networking
Topic: CapAC 1 vs CapAC 2 [SOLVED]
Replies: 4
Views: 520

Re: CapAC 1 vs CapAC 2 [SOLVED]

RSTP is enabled per default on the bridge. If you don't need it you may disable it in bridge settings.
by whatever
Tue Oct 30, 2018 8:22 pm
Forum: General
Topic: CRS317 10Gbps forwarding rate
Replies: 8
Views: 943

Re: CRS317 10Gbps forwarding rate

My understanding is that per VLAN you need an associated bridge. You cannot have a single Bridge with multiple VLANs.
Your understanding is wrong, please read the manual.
by whatever
Tue Oct 23, 2018 6:16 pm
Forum: RouterBOARD hardware
Topic: New High End Router Hardware Soon?
Replies: 11
Views: 1786

Re: New High End Router Hardware Soon?

If I remember correctly, the patch which dropped tile from the Linux Kernel explicitly stated, that nobody was using tile in current Kernels back then and that the vendors who are still shipping tile hardware had no interest in having it maintained for future Kernels. Therefore the chances that tile...
by whatever
Mon Oct 22, 2018 5:14 pm
Forum: RouterBOARD hardware
Topic: Can PowerBox Pro support simultaneous multiple power inputs?
Replies: 6
Views: 876

Re: Can PowerBox Pro support simultaneous multiple power inputs?

I think the device will always use the power input with the highest voltage. Having similar voltage on different inputs may cause flapping between them.
by whatever
Mon Oct 15, 2018 6:32 pm
Forum: Wireless Networking
Topic: Capsman Certificate issue
Replies: 1
Views: 440

Re: Capsman Certificate issue

I think what you are asking for would negate any security benefits gained by using cap certificates in the first place.
by whatever
Thu Oct 04, 2018 2:13 pm
Forum: Announcements
Topic: v6.42.9 [long-term] is released!
Replies: 119
Views: 25599

Re: v6.42.9 [long-term] is released!

Must have missed that, thank you for pointing it out.
by whatever
Thu Oct 04, 2018 12:46 pm
Forum: Announcements
Topic: v6.42.9 [long-term] is released!
Replies: 119
Views: 25599

Re: v6.42.9 [long-term] is released!

How is it possible that I'm still able to login with my password after downgrading from 6.43.2 to 6.42.9? I thought 6.43 changed the authentication API in order to be able to save passwords as hashes and not as plaintext. However, the fact that I'm still able to login after downgrade to 6.42 clearly...
by whatever
Thu Sep 27, 2018 12:07 pm
Forum: Wireless Networking
Topic: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi
Replies: 288
Views: 59288

Re: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi

Try local forwarding (datapath) for even faster speed.
by whatever
Wed Sep 26, 2018 9:13 am
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 359
Views: 66215

Re: RB4011

Agree its going to catch a few people out, but if you look at the link in my post 152 ( https://forum.mikrotik.com/viewtopic.php?p=688286#p687944 ) they are only €35 new, Are you using any of their products? They are offering 10GbE Multimode optics for 15€ while the competition is selling them for ...
by whatever
Mon Sep 24, 2018 10:13 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 359
Views: 66215

Re: RB4011

Imho the lack of switch chip features could be neglected if you had the possibility to connect a "real" switch to the 10G port via a cheap cable. However, the lack of passive DAC support forces you to spend 100+€ for this connection instead of ~25€. Combining both these weaknesses into an otherwise ...
by whatever
Fri Sep 21, 2018 11:35 am
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 359
Views: 66215

Re: RB4011

Footnote 4 says you can only use a SFP+ DAC at 10Gb
Doesn't it rather say that you cannot use passive SFP+ DAC at all? RB4011 seems to be the only Mikrotik SFP+ device which is incompatible with Mikrotik's own direct attach cables.
by whatever
Thu Sep 20, 2018 12:17 pm
Forum: General
Topic: Can't change username on ROS 6.43 [SOLVED]
Replies: 21
Views: 3663

Re: Can't change username on ROS 6.43 [SOLVED]

The only technical reason I can think of is, that the username is now part of the salt for the new password hashes. Otherwise it might just be a case of "not yet implemented".
by whatever
Sun Sep 09, 2018 11:33 am
Forum: General
Topic: PWR-Line AP
Replies: 48
Views: 8247

Re: PWR-Line AP

Hi, do you know what wireless specs will this device have? How many chains on which bands?
2.4Ghz b/g/n, dual chain. See https://fccid.io/TV7PL64112ND
by whatever
Sat Sep 08, 2018 2:12 pm
Forum: RouterBOARD hardware
Topic: Whats the best current home routerboard for a gigabit ISP?
Replies: 15
Views: 3954

Re: Whats the best current home routerboard for a gigabit ISP?

There's as slight bug in switch chip in IPQ4xxx which bit me and MT doesn't have a solution (yet).
What is the bug? Could you share some information?
by whatever
Thu Sep 06, 2018 12:15 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 359
Views: 66215

Re: RB4011

One can argue about "router on a stick" SFP+ setup to lift possible limit to 15Gbps total, but i think those will not be numbers anyone is looking for.
Why not? That 15Gbps is exactly the number I'd expected to see as achievable benchmark limit for this block diagram.
by whatever
Mon Sep 03, 2018 7:17 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 359
Views: 66215

Re: RB4011

https://forum.mikrotik.com/download/file.php?id=33451 Anybody else wondering why RB4011 CPU-throughput appears to be capped to 10Gbit/s? Assuming both Realtek GbE switchgroups are connected at 2.5Gbit/s each to the CPU (like RB1100AHx4), this leaves only 5Gbit/s possible thoughput for the 10GbE SFP...
by whatever
Sat Sep 01, 2018 11:17 pm
Forum: Wireless Networking
Topic: Rogue AP prevention/detection
Replies: 1
Views: 562

Re: Rogue AP prevention/detection

1. Use physical security on your ports.
2. You cannot prevent anyone from using "your" SSID, but using WPA2+Radius authentification should prevent MITM.
by whatever
Thu Aug 30, 2018 11:18 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 359
Views: 66215

Re: RB4011

Oh boy, it does look ugly with those rack-mount ears attached.
It's a pretty clever way of combining rack-mount capability and desktop case into the same product. Not exactly pretty, but very funktional; I like it.
by whatever
Wed Aug 22, 2018 11:07 am
Forum: RouterBOARD hardware
Topic: Temperature sensor hap ac^2
Replies: 1
Views: 429

Re: Temperature sensor hap ac^2

No sensor.
by whatever
Mon Aug 20, 2018 11:03 am
Forum: General
Topic: crs326 update problem
Replies: 3
Views: 341

Re: crs326 update problem

It's the same as with every other 16 MB routeros device: The update is stored in RAM until installed. Just try it.
by whatever
Sun Aug 19, 2018 3:53 pm
Forum: General
Topic: crs326 update problem
Replies: 3
Views: 341

Re: crs326 update problem

What happens if you try to upgrade?
by whatever
Sun Aug 19, 2018 11:11 am
Forum: General
Topic: Passwords for hundreds/thousdands of devices
Replies: 10
Views: 978

Re: Passwords for hundreds/thousdands of devices

You shouldn't use local passwords at all for this kind of deployment. Look into asymmetric crypto (ssh public keys) and/or centralized authentication (radius, etc).
by whatever
Sat Aug 18, 2018 3:25 pm
Forum: General
Topic: Question: HAP AC^2, Wan speed less than 100Mbps on 500Mbps internet line. [SOLVED]
Replies: 3
Views: 596

Re: Question: HAP AC^2, Wan speed less than 100Mbps on 500Mbps internet line. [SOLVED]

Use system->resources->CPU and tools->profile to monitor CPU usage while running the speed test. Is any of the cores maxed out? If yes: find out what process causes the high cpu usage, try fasttrack, etc. If not: Check cables and interface speed. Are all the involved interfaces running at gigabit sp...
by whatever
Sat Aug 18, 2018 12:27 am
Forum: RouterBOARD hardware
Topic: When will be RB3011UiAS-2HnD-IN available?
Replies: 65
Views: 19847

Re: When will be RB3011UiAS-2HnD-IN available?

This has already been discussed here two weeks ago. The corresponding topics have been deleted/hidden, so it's probably not meant to be public yet.
by whatever
Fri Aug 17, 2018 6:23 pm
Forum: RouterBOARD hardware
Topic: High speed network
Replies: 1
Views: 437

Re: High speed network

Please stop calling ethernet over fibre "fibre channel", these are two different things.
by whatever
Wed Aug 15, 2018 12:19 pm
Forum: Wireless Networking
Topic: caps-man manager interface all forbid=yes && caps-man-addresses=127.0.0.1
Replies: 3
Views: 1112

Re: caps-man manager interface all forbid=yes && caps-man-addresses=127.0.0.1

It's rather a fcked up design than a bug, this is even documented in the wiki. Documentation suggests allowing "all" and forbidding every unwanted interface. This could easily be fixed by introducing an "allow local" setting. Link: https://wiki.mikrotik.com/wiki/Manual:Simple_CAPsMAN_setup#CAP_in_CA...
by whatever
Sun Aug 12, 2018 8:32 pm
Forum: RouterBOARD hardware
Topic: No VLAN table on Realtek switch chip?
Replies: 9
Views: 1450

Re: No VLAN table on Realtek switch chip?

But if I'm forced to connect a "real" switch anyway I can get all the ports i need from the switch. Want to connect three ISPs? Configure three ports on your switch on separate vlans and pass them through a "WAN" trunk to your router. Want multiple local networks? Separate them on your switch and pa...
by whatever
Sun Aug 12, 2018 7:31 pm
Forum: RouterBOARD hardware
Topic: No VLAN table on Realtek switch chip?
Replies: 9
Views: 1450

Re: No VLAN table on Realtek switch chip?

Thank you for the confirmation. While I get that a router is expected to provide only limited switching features and has the necessary CPU power to perform certain things in software, I'm still confused by this decision. Why would I need 10+ ports on a router if it can't do proper vlan switching in ...
by whatever
Sun Aug 12, 2018 7:13 pm
Forum: General
Topic: IPv6 reverse path filtering
Replies: 0
Views: 282

IPv6 reverse path filtering

I'm looking for a way to do reverse path filtering for IPv6 in RouterOS. I request a dynamic pool via DHCPv6-PD on my WAN interface and use it to deploy separate /64 prefixes on local vlan interfaces. As far as I can tell, the only way to implement something like rp_filter for IPv6 would be a script...
by whatever
Sat Aug 11, 2018 8:44 pm
Forum: General
Topic: MT sending spam !? Confused!
Replies: 11
Views: 2266

Re: MT sending spam !? Confused!

You should really use the firewall to protect your management ports. Yes, there is a _very_ bad bug in old routeros versions, but it's only exploitable if you f*cked up your firewall rules. Only port accessible from the outside is the Winbox port and SSH custom port. But why are these accessible fr...
by whatever
Fri Aug 10, 2018 7:26 pm
Forum: General
Topic: MT sending spam !? Confused!
Replies: 11
Views: 2266

Re: MT sending spam !? Confused!

You should really use the firewall to protect your management ports. Yes, there is a _very_ bad bug in old routeros versions, but it's only exploitable if you f*cked up your firewall rules.
by whatever
Wed Aug 08, 2018 9:53 am
Forum: General
Topic: Do not open port tcp/23 to your device from internet you will be hacked
Replies: 6
Views: 980

Re: Do not open port tcp/23 to your device from internet you will be hacked

Imho you shouldn't be using telnet at all, not even in LAN. You shouldn't just firewall it but also disable the corresponding service.
by whatever
Wed Aug 08, 2018 12:08 am
Forum: RouterBOARD hardware
Topic: No VLAN table on Realtek switch chip?
Replies: 9
Views: 1450

No VLAN table on Realtek switch chip?

According to https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features the Realtek switch chip used by RB1100AHx4 (and possibly also *future* RBs ;)) lacks a vlan table. Does that result in no way of doing vlan filtering in hardware on these devices? The idea, that a lot of the cheap low-end device...
by whatever
Sun Aug 05, 2018 3:38 pm
Forum: RouterBOARD hardware
Topic: DElay USB Power on reboot
Replies: 2
Views: 366

Re: DElay USB Power on reboot

Wouldn't it be much easier to delay the dhcp client execution on the rpi?
by whatever
Sat Aug 04, 2018 10:25 pm
Forum: General
Topic: Firewall rules not working after 6.42.6 upgrade
Replies: 19
Views: 2358

Re: Firewall rules not working after 6.42.6 upgrade

Try to disable hw-offload on your bridge ports. If the packets can be forwarded in hardware by the switch chip, they will never reach the cpu for filtering.
by whatever
Sat Aug 04, 2018 1:41 pm
Forum: General
Topic: hAP ac2 performance issue
Replies: 4
Views: 708

Re: hAP ac2 performance issue

https://wiki.mikrotik.com/wiki/Manual:C ... figuration
Your datapath does not include local-forwarding=yes, therefore all your wifi traffic will be tunneled through capsman.
by whatever
Sat Aug 04, 2018 12:55 pm
Forum: General
Topic: hAP ac2 performance issue
Replies: 4
Views: 708

Re: hAP ac2 performance issue

Edit: why no local forwarding?
I can easily max out 150 Mbit/s downstream with hap ac2 (no capsman) and iPhone 7.
by whatever
Tue Jul 31, 2018 3:14 pm
Forum: General
Topic: 6.43 API - Why are you *weakening* authentication?
Replies: 1
Views: 344

Re: 6.43 API - Why are you *weakening* authentication?

Challenge-Response requires the device to have your password available in plain text, which is the reason why the latest winbox bug was able to leak your passwords, no matter how strong they were. The new login mechanisms allows the device to save only password hashes, even if an attacker manages to...
by whatever
Sat Jul 28, 2018 1:11 pm
Forum: General
Topic: multiple gateways using mangle fault
Replies: 2
Views: 286

Re: multiple gateways using mangle fault

Did you disable fastpath/fasttrack? You should.
by whatever
Mon Jul 16, 2018 11:50 pm
Forum: General
Topic: hAP ac2 CAPsMAN bug
Replies: 9
Views: 1294

Re: hAP ac2 CAPsMAN bug

The Wiki (https://wiki.mikrotik.com/wiki/Manual:S ... in_CAPsMAN) suggests using
/ip firewall filter
add action=accept chain=input dst-address-type=local src-address-type=local
by whatever
Sat Jul 14, 2018 3:11 pm
Forum: General
Topic: IPv6 - by default
Replies: 7
Views: 1314

Re: IPv6 - by default

If you take a look at Google's IPv6 data , you will realize that IPv6 adoption in Latvia is negligible. Guess that's one of the reasons for its current state in RouterOS. On the other Hand, there are countries where Dual Stack (or DS-Lite) has become the default for most ISPs. Belguim is already at ...
by whatever
Wed Jul 04, 2018 10:25 pm
Forum: General
Topic: Web Proxy Hacked
Replies: 8
Views: 2166

Re: Web Proxy Hacked

Don't expose the mgmt interface to the internet? If you have to: use additional security features like port knocking and vpn.
by whatever
Tue Jul 03, 2018 11:02 pm
Forum: General
Topic: hAP-AC2 6.42.4 - HWOffload [solved]
Replies: 13
Views: 2384

Re: hAP-AC2 6.42.4 - HWOffload

Wow, thank you for the extensive reply and sorry for my late response. whatever - 1) Bridge VLAN filtering is not so easy to implement on these switch chips. ok, noted. 2) Which examples are missing vlan-header values? If you are talking about the hybrid port setup, then by default it is set to "lea...
by whatever
Tue Jul 03, 2018 10:24 pm
Forum: General
Topic: Detecting IPV4 SYN requests
Replies: 2
Views: 323

Re: Detecting IPV4 SYN requests

Why don't you use a stateful firewall with connection tracking? The first packet of a TCP connection will always be "new", no need to reinvent the wheel by checking flags manually.
by whatever
Sun Jun 24, 2018 11:49 pm
Forum: General
Topic: hAP-AC2 6.42.4 - HWOffload [solved]
Replies: 13
Views: 2384

Re: hAP-AC2 6.42.4 - HWOffload

Current channel is beta only. If you don't like to participate in beta testing programme, stay in bugfix channel. My hAP ac² came preloaded with 6.41.3; am I really expected to downgrade to 6.40.8 if I wish to run non-beta software? I was under the impression, that "current" means stable, "bugfix o...
by whatever
Sun Jun 24, 2018 11:41 pm
Forum: General
Topic: hAP-AC2 6.42.4 - HWOffload [solved]
Replies: 13
Views: 2384

Re: hAP-AC2 6.42.4 - HWOffload

1. Switch Menu in Winbox is missing (hAP AC2 - 6.42.4).. Would be nice if someone else can confirm. 2. Configuring it via CLI works and HW offload is working Both confirmed. 3. New Bridge implementation is incomplete (at best) as documented in Wiki. As someone who just got a hAP ac² as his first Ro...