Community discussions

MikroTik App

Search found 930 matches

by Buckeye
Mon Sep 23, 2024 5:40 am
Forum: General
Topic: Networking Advice
Replies: 11
Views: 929

Re: Networking Advice

I can imagine very few things as "static" as cameras, you have to go there, bring near the spot an ethernet connection, drill holes in the wall or ceiling, screw them tightly, they won't likely change. I agree that it makes sense to use static addresses for cameras, but more for the abili...
by Buckeye
Sun Sep 22, 2024 2:44 am
Forum: General
Topic: Networking Advice
Replies: 11
Views: 929

Re: Networking Advice

Without VLAN's I'm afraid your options are ... very limited ... I totally agree with @jvanhambelgium concerning vlans. What you are proposing is much more complex than learning to use vlans. It seems in your original diagrams (as it currently is), that the only MikroTik device is the hex that is be...
by Buckeye
Thu Sep 19, 2024 4:04 am
Forum: Forwarding Protocols
Topic: ARP Table
Replies: 4
Views: 1036

Re: ARP Table

Does anyone know what do I need to perform in my microtik device in order to block the registration in the arp table?
This is a good example of the XY problem

What is ARP and why do we need it? Address Resolution Protocol (ARP)
by Buckeye
Mon Sep 16, 2024 10:57 pm
Forum: Beginner Basics
Topic: Problem with VLANs and Bridge
Replies: 18
Views: 1194

Re: Problem with VLANs and Bridge

- To that point, tagging the bridge is NOT needed IF the router is merely bridging traffic - i.e. NOT the router for the VLAN, e.g. acting as "smart switch". So if the router does not have an IP address (and /interface/vlan) on something "passing through" the bridge, then tagged...
by Buckeye
Mon Sep 16, 2024 10:29 pm
Forum: Beginner Basics
Topic: Problem with VLANs and Bridge
Replies: 18
Views: 1194

Re: Problem with VLANs and Bridge

It sounds odd to me, but it works only this way. For what it's worth, it just found this with google Why do the docs not mention adding "bridge" as its own tagged interface when doing a VLAN trunk? which has the solution post by @mkx which implies it is a bug that affected devices with mu...
by Buckeye
Mon Sep 16, 2024 1:00 pm
Forum: Beginner Basics
Topic: Problem with VLANs and Bridge
Replies: 18
Views: 1194

Re: Problem with VLANs and Bridge

If I remove BR1 as a tagged port and restart the switch, I can't even get access to it via the management port Ether8 (which is not part of the bridge BR1) via Winbox from my PC anymore. Well I obviously don't understand it as well as I thought I did. I will have to try some things on my RB760iGS t...
by Buckeye
Mon Sep 16, 2024 11:01 am
Forum: Beginner Basics
Topic: Problem with VLANs and Bridge
Replies: 18
Views: 1194

Re: Problem with VLANs and Bridge

...If I don't set the bridge as a tagged port too, the device on the access ports don't get their IPs from the dhcp servers running on OPNsense in which I also set the VLANs interfaces. What MikroTik device is this? Is the intervlan routing happening on the OPNsense device? And are devices connecte...
by Buckeye
Fri Jul 19, 2024 3:50 pm
Forum: General
Topic: [Assistance] - VLAN configuration on CRS1xx
Replies: 10
Views: 644

Re: [Assistance] - VLAN configuration on CRS1xx

If you learn from videos, I recommend Mikrotik VLANs - CRS1xx & CRS2xx - Mikrotik Tutorial by Wilmer Almazan / The Network Trip In the example he is configuring there are two switches connected by trunk link, and access ports. And an external router for routing between vlans. This video is three...
by Buckeye
Sat Apr 27, 2024 12:00 pm
Forum: General
Topic: Any solution for admit-only-VLAN-tagged misconfiguration
Replies: 16
Views: 1310

Re: Any solution for admit-only-VLAN-tagged misconfiguration

Assuming the only interface defined on the CRS using ethernet was the bridge, then I don't think there is any recovery without a serial connection, or a factory reset (and losing the previous config). The bridge interface is connected to the switch ASIC via untagged traffic over the internal trunk l...
by Buckeye
Fri Apr 26, 2024 7:45 am
Forum: Beginner Basics
Topic: a basic (I think...) VLAN problem.
Replies: 11
Views: 1087

Re: a basic (I think...) VLAN problem.

The 1588 (PTP Timing) VLAN seems to be working (at least it works on Machine 1). But now I cannot SSH (or even ping) Machine 2 from Machine 1 via VLAN 5. I have tried adding a VLAN to Machine 1 SSH interface and pinging through that and still was not able to reach Machine 2. Machine 2 is a headless...
by Buckeye
Thu Apr 25, 2024 1:11 am
Forum: Beginner Basics
Topic: a basic (I think...) VLAN problem.
Replies: 11
Views: 1087

Re: a basic (I think...) VLAN problem.

I would like to use two vlans: -1588: ptp travels from grandmaster clock to both machine 1 and 2. -5: packets sent between machine 1 and 2 (must be tagged) Essentially I want the RU port to be a trunk port to allow both 1588 and 5 vlan traffic simultaneously. The TIMING and SOURCE interfaces can be...
by Buckeye
Fri Apr 05, 2024 11:38 pm
Forum: General
Topic: Firewall/Routing Question
Replies: 19
Views: 1189

Re: Firewall/Routing Question

Because if you have lots of users, its easier to give them and have them remember a name than a number. I do understand that it is easier to remember BlueIris:81 than 192.168.0.1:81; but he doesn't want this accessible from the internet, so I don't see any advantage to using the public ip. So why n...
by Buckeye
Fri Apr 05, 2024 10:56 pm
Forum: Beginner Basics
Topic: How to block subnet to subnet access
Replies: 10
Views: 1549

Re: How to block subnet to subnet access

I know this is covered https://forum.mikrotik.com/viewtopic.php?t=60451 , I think, but that method doesn't work: /ip firewall filter add chain=forward action=drop src-address=192.168.0.0/24 dst-addresss=10.0.0.0/24 But that simply doesn't work at all since I'm still able to log in to the router via...
by Buckeye
Fri Apr 05, 2024 9:34 pm
Forum: General
Topic: Firewall/Routing Question
Replies: 19
Views: 1189

Re: Firewall/Routing Question

Is there a way to make it so that I can browse to A.dyndns.org:81
There are many things that can be done, but I have to ask; what is the advantage of accessing it via the "external" A.dyndns.org ip address?

To me, this just seems like added complexity with no real benefit.
by Buckeye
Fri Mar 29, 2024 11:06 am
Forum: Beginner Basics
Topic: VLAN'ising an existing configuration without disrupting service
Replies: 23
Views: 1917

Re: VLAN'ising an existing configuration without disrupting service

I did all that. Could be the ad-blocking in my browser that kills it -- but frankly I can't digest video tutorials even in languages I understand. I use uBlock Origin and auto-translated subtitles works for me with Chrome on Win 10. Do you get subtitles in Ukranian if you don't turn on auto-transla...
by Buckeye
Fri Mar 29, 2024 10:50 am
Forum: Beginner Basics
Topic: VLAN'ising an existing configuration without disrupting service
Replies: 23
Views: 1917

Re: VLAN'ising an existing configuration without disrupting service

That's why I suggested you using subtitles (forgot to mention with the option "Auto-translate" :) ) Yeah, that option exists but causes no CC at all (for me, anyway). I didn't know there was an auto-translate feature until @TheCat12 mentioned it. To get it to work you must do several thin...
by Buckeye
Fri Mar 29, 2024 10:26 am
Forum: Beginner Basics
Topic: Basic VLAN Access Port
Replies: 5
Views: 1782

Re: Basic VLAN Access Port

I'm clearly having some trouble understanding some of the fundamental concepts here. Again, I agree with what @gigabyte091 said, especially the importance of understanding why things work. Confidence comes with understanding, so start there. Do you have any previous experience with tagged vlans? If...
by Buckeye
Thu Mar 28, 2024 12:54 pm
Forum: Beginner Basics
Topic: Basic VLAN Access Port
Replies: 5
Views: 1782

Re: Basic VLAN Access Port

I've been able to set up a DHCP server for the VLAN. I can connect to the router on eth5, and I get an address, but that's where the fun stops. You currently have: /interface bridge port add bridge=bridge comment=defconf interface=ether2 add bridge=bridge comment=defconf interface=ether3 add bridge...
by Buckeye
Tue Mar 26, 2024 12:32 pm
Forum: Beginner Basics
Topic: networking and ip services [SOLVED]
Replies: 3
Views: 2849

Re: Dhcp not working [SOLVED]

On Ethernet 2 i want to set up an admin vlan , and on ethernet 3 a guest vlan. A simple setup. My problem is that i don t get a local ip on the mentioned vlan ports. Even if i assign a fixed ip from the correct subnet, i can t connect to the router with winbox. The interface it appears that it does...
by Buckeye
Fri Mar 22, 2024 6:49 am
Forum: Beginner Basics
Topic: MACVLAN on top of current VLAN [SOLVED]
Replies: 7
Views: 4576

Re: MACVLAN on top of current VLAN [SOLVED]

So, first, is it possible to do this without having to replace the tplink dumb switch with a vlan-aware switch? And if that's possible, what are the paths forward to configure the network as such? Thanks again! What happened to vlans 30 and 99 in your diagram? They exist in your config, but not the...
by Buckeye
Thu Mar 21, 2024 11:45 am
Forum: Beginner Basics
Topic: MACVLAN on top of current VLAN [SOLVED]
Replies: 7
Views: 4576

Re: MACVLAN on top of current VLAN [SOLVED]

After successfully configuring my network with VLANs, I had to change the topology, and now I have a situation where one ethernet port has to serve two machines that are in different VLANs. I tried enabling the MACVLAN, untagging the ethernet port and allowing all traffic and setting DHCP on the ma...
by Buckeye
Tue Mar 12, 2024 2:08 pm
Forum: Beginner Basics
Topic: hEXs and internet speed problem [SOLVED]
Replies: 13
Views: 5276

Re: hEXs and internet speed problem [SOLVED]

Are the only connections to the hEX S ether1 to the Fritzbox and ether3 to the external switch? What type of switch is connected to ether3. Is it a vlan-aware switch with a management interface or is it instead a basic plug and play switch with no management? If it is just a dumb switch, and you are...
by Buckeye
Mon Mar 04, 2024 10:51 am
Forum: Beginner Basics
Topic: I made a mess of config
Replies: 5
Views: 866

Re: I made a mess of config

Will there AP's do the job --> MikroTik RBWAPG-5HACD2HND I don't use them, so I can't say. My guess is that they will work, but if you really want to know, start a new thread with a title that will get more nibbles from people that use the device. i.e. a title like "Question about vlan capabil...
by Buckeye
Sat Mar 02, 2024 11:12 pm
Forum: General
Topic: I can't get my network to work in Gigabit [SOLVED]
Replies: 15
Views: 2396

Re: I can't get my network to work in Gigabit [SOLVED]

So, firstly, this is the cable I used: https://www.amazon.it/dp/B07ZVLDCYX. There's this one and another 7a cable for the Windows PC I'm testing. I mean, a cable could be, but in all 4 ports? Have you tested with a pre-made patch cable? If you don't have a portable device, then take the hex to the ...
by Buckeye
Sat Mar 02, 2024 11:35 am
Forum: Beginner Basics
Topic: I made a mess of config
Replies: 5
Views: 866

Re: I made a mess of config

If I turn on VLAN filetring on Bridge --> situation turns 180 degress. ethr1 to ethr4 works normally and gives DHCP addresses, and Trunk side just dies and doesnt want to give anything. Are you saying that when you turn on vlan-filtering, that vlan200 access ports on the switches do not work? It se...
by Buckeye
Thu Feb 08, 2024 10:56 am
Forum: General
Topic: Forum moderation volunteers
Replies: 238
Views: 45254

Re: Forum moderation volunteers

Why were @anav's guide threads deleted? New User Pathway To Config Success https://forum.mikrotik.com/viewtopic.php?p=906567 New User Posting For Assistance https://forum.mikrotik.com/viewtopic.php?p=908118#p908118 Those were really useful threads with pointers to other relevant material. It's been ...
by Buckeye
Wed Oct 18, 2023 2:44 am
Forum: Beginner Basics
Topic: Noob Shock and horror
Replies: 13
Views: 1983

Re: Noob Shock and horror

@anav welcome back. Were you on Holiday/vacation?
by Buckeye
Fri Aug 04, 2023 2:39 am
Forum: General
Topic: VLAN ID translation [SOLVED]
Replies: 7
Views: 1917

Re: VLAN ID translation [SOLVED]

If you are indeed talking about Dell 28xx series, I agree with @pe1chl (at least if I am interpreting what he said correctly). Normally the easiest way to do that is to make the management network untagged, and use tags for all networks for which you know the VLAN ID. Here is what I would do in your...
by Buckeye
Wed Aug 02, 2023 9:02 pm
Forum: Announcements
Topic: v7.11rc is released!
Replies: 195
Views: 53758

Re: v7.11rc is released!

@strods can you comment on the switch changes in more detail? Specifically the one about BPDU and HW vlan-filtering. Here are two threads which were related to the problem this seems to be addressing VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] -...
by Buckeye
Wed Aug 02, 2023 8:42 pm
Forum: General
Topic: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]
Replies: 45
Views: 5905

Re: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]

Were you able to verify that the 7.11rc1 "fix" worked for your hAP ax lite? Because @skyhawk reported in a followup post that it did not solve his problem (which was on a hEX (RB750Gr3) using the MT7621)
by Buckeye
Wed Aug 02, 2023 8:31 pm
Forum: General
Topic: Bridge VLAN-Filter Offload broken on hEXr3?
Replies: 35
Views: 4551

Re: Bridge VLAN-Filter Offload broken on hEXr3?

Initial testing suggests the issues is *not* fixed. Just curious, have you reached out to them about your previous ticket? Did they ever send you any update? Edit: I was mixed up, it was @thn80 that opened the ticket (see this post ) And the was using hap ax lite, not hEX. When I reported a problem...
by Buckeye
Mon Jul 31, 2023 10:55 pm
Forum: Beginner Basics
Topic: pass all vlans trough uplink setup
Replies: 3
Views: 1167

Re: pass all vlans trough uplink setup

Whether to use ROS vs SwOS depends of your familiarity with ROS. SwOS is more lightweight and in my opinion easier to configure if all you want is L2 (which is the primary purpose of the CRS devices). ROS can provide secure management protocols (ssh) which SwOS does not. Whether you use SwOS or ROS,...
by Buckeye
Mon Jul 31, 2023 10:33 pm
Forum: General
Topic: RouterOS 7 Bridge VLAN/DHCP client issue after upgrade
Replies: 23
Views: 7658

Re: RouterOS 7 Bridge VLAN/DHCP client issue after upgrade

This may be fixed by 7.11rc1 as reported by @skyhawk in this post from the thread Bridge VLAN-Filter Offload broken on hEXr3?

More details about the problem in this thread VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports]
by Buckeye
Thu Jul 27, 2023 11:22 pm
Forum: Beginner Basics
Topic: Isolated users based on the ethernet ports.
Replies: 12
Views: 1738

Re: Isolated users based on the ethernet ports.

I am using the PC as Mikrotik router (ROS 7.x). The switches are simple TP-Link managed switches, but I'd like to avoid VLANs if possible. So on the PC, you have two ethernet interfaces in an ROS bridge? Why not just create two separate subnets (no vlan is required) and then you can plug "any ...
by Buckeye
Tue Jul 25, 2023 10:18 am
Forum: Beginner Basics
Topic: Combined Trunk for ISP VLAN and internal VLAN
Replies: 5
Views: 1157

Re: Combined Trunk for ISP VLAN and internal VLAN

/interface vlan add interface=ether1 name=vlan1.10 vlan-id=10 add interface=ether1 name=vlan1.20 vlan-id=20 add interface=ether1 name=vlan1.30 vlan-id= 20 That appears to be a typo. Shouldn't it be vlan-id= 30 What is happening to IPTV on the hAP ax2? I expected to see vlan-filtering and a port on ...
by Buckeye
Tue Jul 25, 2023 1:54 am
Forum: Beginner Basics
Topic: Isolated users based on the ethernet ports.
Replies: 12
Views: 1738

Re: Isolated users based on the ethernet ports.

Read Port isolation

You don't specify what MikroTik device you have, it is done differently in SwOS than ROS.
by Buckeye
Sat Jul 22, 2023 9:54 pm
Forum: General
Topic: Forum moderation volunteers
Replies: 238
Views: 45254

Re: Forum moderation volunteers

But preventing later editing of posts can be bad as well. An example is @anav's "how to" posts, and @pcunites vlan topic. it is nice for long time users to be able to edit the posts. If it is easy to limit users that are new or have few posts, that is a good idea to disallow editing, becau...
by Buckeye
Fri Jul 21, 2023 12:06 am
Forum: Beginner Basics
Topic: VLAN Routing and General Review
Replies: 16
Views: 2994

Re: VLAN Routing and General Review

If you can't set the default gateway for the management interface of the switch, then the only other option I am aware of is to use NAT masquerade on the Router interface connecting to the switch. That will make it appear to the switch that the traffic is sourced from the router, and therefore on th...
by Buckeye
Wed Jul 19, 2023 9:50 pm
Forum: Beginner Basics
Topic: VLAN Routing and General Review
Replies: 16
Views: 2994

Re: VLAN Routing and General Review

The issue appears to be that the switch I am using does not allow for a gateway configuration for the management interface IP and therefore it doesn't know to route to any other network. Perhaps it's a peculiarity of the switches we are using - Allen Bradley Stratix 5700. I don't think it is a limi...
by Buckeye
Sat Jul 15, 2023 1:01 pm
Forum: Beginner Basics
Topic: Direction connection to port on RB5009 to access VLAN
Replies: 2
Views: 966

Re: Direction connection to port on RB5009 to access VLAN

I have set up eth8 as a trunk port for VLAN10 and VLAN20 and it goes to a switch that splits out the VLANs, but I also want a direct connection for my PC to the router on say, eth2. How do I configure eth2 on the router to be an access port for VLAN20 in WinBox? Without seeing your exported config,...
by Buckeye
Sat Jul 15, 2023 9:05 am
Forum: Beginner Basics
Topic: VLAN Routing and General Review
Replies: 16
Views: 2994

Re: VLAN Routing and General Review

I should note that the sample router.rsc on the original forum doesn't have any lines with "untagged" so perhaps it's an error there too? That's true, but it is not an error. In that example vlan 1 is not used for user data (other than possibly by the router for spanning tree protocol). I...
by Buckeye
Fri Jul 14, 2023 10:20 am
Forum: Beginner Basics
Topic: VLAN Routing and General Review
Replies: 16
Views: 2994

Re: VLAN Routing and General Review

I don't think the following is correct: # create one bridge, set VLAN mode off while we configure /interface bridge add name=BR1 protocol-mode=none vlan-filtering=no # ingress behavior /interface bridge port # Purple Trunk. Leave pvid set to default of 1 This is what you want, don't chage add bridge...
by Buckeye
Fri Jul 07, 2023 11:14 am
Forum: RouterOS beta
Topic: Hex: No DHCP IP address acquired on WAN interface
Replies: 41
Views: 7831

Re: Hex: No DHCP IP address acquired on WAN interface

This reminded me of a problem on the MT7621 based ER-X (very similar architecture to the hEX), where everything goes "through" the switch ASIC. The problem was that any priority only tagged packets with PCP (Priority) != 0 would be dropped. This was fixed with a patch, so it would be inter...
by Buckeye
Fri Jul 07, 2023 6:22 am
Forum: Beginner Basics
Topic: RB5009 inter-VLAN vs port-based subnet
Replies: 5
Views: 1676

Re: RB5009 inter-VLAN vs port-based subnet

What is the purpose of the diagram if it doesn't correspond to any export? It is especially confusing when you post a diagram and a config that doesn't correspond to the diagram in the same post. And then after people have commented on the export, to replace it with yet another unrelated one. What w...
by Buckeye
Thu Jul 06, 2023 9:12 pm
Forum: General
Topic: High CPU utilization on CRS354
Replies: 15
Views: 1943

Re: High CPU utilization on CRS354

I have CRS354-48G-4S+2Q+. CPU utilization is 100% every time. Ethernet is about 30% Networking is 45% Bridging is 25%. Some mac addresses (about half) in "interface ethernet switch host print" command i see behind switch1-cu interface. Does it mean that traffic going to servers with mac a...
by Buckeye
Thu Jul 06, 2023 7:22 am
Forum: Beginner Basics
Topic: ping don't work when dhcp lease
Replies: 4
Views: 1491

Re: ping don't work when dhcp lease

I've seen quite a bit of DHCP issues because of time mismatches. What type of DHCP issues have you seen because of time mismatches, and how did you determine that it was the time mismatch that caused the error? I thought that rfc2131 section-3.3 Interpretation and representation of time values cove...
by Buckeye
Thu Jul 06, 2023 2:47 am
Forum: Beginner Basics
Topic: VLAN on WAN port [SOLVED]
Replies: 3
Views: 4072

Re: VLAN on WAN port [SOLVED]

It seems to me @anav left out the command to actually create the vlan interface with the /interface vlan command. Then you will need to use whatever name you created for your WAN vlan interface (the example @anav provided used VlanWAN, my example used wan_107). You will need to use vlan-id=101 (not ...
by Buckeye
Thu Jul 06, 2023 1:14 am
Forum: General
Topic: Forum moderation volunteers
Replies: 238
Views: 45254

Re: Forum moderation volunteers

Air Force One must then have routers installed with ROS 7.10 for quite some time.

They now have a special stairs in the back of the plane. Far away from the routers in the front of the plane. Hope it helps.
That flew over my head until I realized the context.
by Buckeye
Wed Jul 05, 2023 9:01 pm
Forum: RouterOS beta
Topic: Hex: No DHCP IP address acquired on WAN interface
Replies: 41
Views: 7831

Re: Hex: No DHCP IP address acquired on WAN interface

Some of the ISP replies seem strange. Why is it often sending to: 217.19.17.85.67 > 217.19.19.188 and The issue appears to be that the ISP sends the DHCP replies to the assigned address, rather than to the broadcast address. The router does not process these because it does not have that address ye...
by Buckeye
Wed Jul 05, 2023 8:11 am
Forum: General
Topic: Forum moderation volunteers
Replies: 238
Views: 45254

Re: Forum moderation volunteers

both post you are referring are from newly created accounts, a factor that you are not taking into account That's correct, I did not take that into consideration. And I also did not do a google image search to see if the diagram was lifted from somewhere else to give credibility to the post. But th...
by Buckeye
Wed Jul 05, 2023 7:07 am
Forum: General
Topic: Forum moderation volunteers
Replies: 238
Views: 45254

Re: Forum moderation volunteers

… Posts are starting to disappear for no reason.... Now let's see if they start accusing me on Reddit without even telling me, this time they can't blame me, let's see if Reddit users convince you on someone else.... https://forum.mikrotik.com/viewtopic.php?t=197438#p1010594 https://forum.mikrotik....
by Buckeye
Tue Jul 04, 2023 11:51 pm
Forum: Beginner Basics
Topic: mac or ip based vlan (or manual assignment)
Replies: 6
Views: 1835

Re: mac or ip based vlan (or manual assignment)

Yeah, IP based was just throwing a random suggestion out there for simply manually assigning a device to a specific vlan after it connects. My question was really just to see if there was any way to do it but it seems not. The reason I said I didn't understand what you meant by IP based vlan, is th...
by Buckeye
Tue Jul 04, 2023 9:35 am
Forum: Beginner Basics
Topic: VLAN not work upgrade os 6 to 7
Replies: 5
Views: 1528

Re: VLAN not work upgrade os 6 to 7

Please help. Did you understand what @anav wrote? You are using bridge ports as if they were L3 interfaces, and that is a misconfiguration. See IP address in bridge or etherX . Once you add an ethernet port to a bridge device, you should not try to use layer 3 commands with the ethernet port; L3 co...
by Buckeye
Tue Jul 04, 2023 2:12 am
Forum: Beginner Basics
Topic: mac or ip based vlan (or manual assignment)
Replies: 6
Views: 1835

Re: mac or ip based vlan (or manual assignment)

Unless you intend to have all devices in the same vlan, using a dumb switch isn't recommended, because a dumb switch offers no real separation of devices. Also, to use mac or protocol based vlans requires a managed switch above the "smart switch" variety, that are usually vlan aware but no...
by Buckeye
Fri Jun 30, 2023 11:52 pm
Forum: General
Topic: Bridge VLAN-Filter Offload broken on hEXr3?
Replies: 35
Views: 4551

Re: Bridge VLAN-Filter Offload broken on hEXr3?

Did they acknowledge as a known issue on the MT7621 based devices (with MT7530 like switch ASIC) as well as the MT7531 switch ASIC in the hAP ax lite? I also found this [net-next,4/6] net: dsa: mt7530: Add the support of MT7531 switch and this CONFIG_NET_DSA_MT7530: MediaTek MT7530 and MT7531 Ethern...
by Buckeye
Fri Jun 30, 2023 10:22 am
Forum: General
Topic: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]
Replies: 45
Views: 5905

Re: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]

I don't think either the hap ax2 or hap ax3 switch chips are currently supported for HW vlan-filtering, so the bridge vlan-filtering is already done in the CPU, although I am surprised that the behavior would be different in the software implementation (other than the L2 forwarding performance and C...
by Buckeye
Fri Jun 30, 2023 9:45 am
Forum: General
Topic: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]
Replies: 45
Views: 5905

Re: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]

I already came to the point STP needed to be disabled on the AXLite -bridge (otherwise no access via trunk, only via mgmt port I isolated from bridge) but clients still can not connect. @skyhawk reported a similar problem (not exactly the same) on a hEX that uses a similar switch ASIC. If intereste...
by Buckeye
Fri Jun 30, 2023 8:39 am
Forum: General
Topic: Bridge VLAN-Filter Offload broken on hEXr3?
Replies: 35
Views: 4551

Re: Bridge VLAN-Filter Offload broken on hEXr3?

The Switch Features chart indicates hAP ax lite uses a MT7531 switch chip. That's a different model, but the same vendor as the MT7621 in my hEXr3. I wonder if there'd be any benefit opening a support ticket to make sure they're aware the issue affects both chips? Another indication that the switch...
by Buckeye
Fri Jun 30, 2023 8:29 am
Forum: General
Topic: Bridge VLAN-Filter Offload broken on hEXr3?
Replies: 35
Views: 4551

Re: Bridge VLAN-Filter Offload broken on hEXr3?

Probably worth reporting it. They will want Supout.rif files from both ends. What is the on the other end of the link? Is it a MikroTik device as well (not that it has to be, just that if it is, it may be easier for them to reproduce the problem). I have a hex S (also based on the MT7621) and I had ...
by Buckeye
Fri Jun 30, 2023 5:18 am
Forum: General
Topic: Bridge VLAN-Filter Offload broken on hEXr3?
Replies: 35
Views: 4551

Re: Bridge VLAN-Filter Offload broken on hEXr3?

This post reminded me of another recent post about a hap ax lite. VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] Take a read through that thread, there are at least some things you can look at. That it works when you disable HW makes me think it ma...
by Buckeye
Thu Jun 29, 2023 9:53 am
Forum: Beginner Basics
Topic: Several VLANs per port
Replies: 18
Views: 1858

Re: Several VLANs per port

Although I have heard about Windows not ignoring tagged frames, I will say that I use multiple window 10 pro PCs connected to "hybrid" links, and they only "see" the untagged frames. The PC I am using right now is connected to a "hybrid" link, and it gets its ip address...
by Buckeye
Thu Jun 29, 2023 9:32 am
Forum: Beginner Basics
Topic: Several VLANs per port
Replies: 18
Views: 1858

Re: Several VLANs per port

What MikroTik device do you have? How many ports does it have? Does it have a built in switch? How many ports are currently in use? How many wired devices need to connect to each "vlan"? If you have two vlans, the "best" solution would involve a vlan aware switch with enough port...
by Buckeye
Thu Jun 29, 2023 8:53 am
Forum: Beginner Basics
Topic: Several VLANs per port
Replies: 18
Views: 1858

Re: Several VLANs per port

The MikroTik forum isn't the best place to get help for UniFi problems. Try https://community.ui.com/tags/unifi-wireless/questions
by Buckeye
Wed Jun 28, 2023 5:19 am
Forum: General
Topic: Forum moderation volunteers
Replies: 238
Views: 45254

Re: Forum moderation volunteers

No matter what you do, there are some dissatisfied people. In Poland we say: No matter how you turn around, the ass is always in the back. That's funny that I thought it meant "you never see you own faults", or something like "it's hard to see the dirt on your own face". But you...
by Buckeye
Tue Jun 27, 2023 10:46 pm
Forum: RouterBOARD hardware
Topic: hEX Router Reset button broke off
Replies: 16
Views: 5622

Re: hEX Router Reset button broke off

finding the correct part is going to be the biggest problem. That's a small switch, and most right angle switches have multiple posts that go through solder through holes; it appears this must be surface mount (based on the picture of the other side of the board, but it may be hiding under the micro...
by Buckeye
Mon Jun 26, 2023 3:21 am
Forum: RouterBOARD hardware
Topic: hEX Router Reset button broke off
Replies: 16
Views: 5622

Re: hEX Router Reset button broke off

(but at the same time, if he touch the board, it's no longer under warranty) What is your definition of touch? Does that also apply to the CCR2004-1G-2XS-PCIe that has part of the board protruding? There are no "seals to break", so unless you left visible evidence, how would they even kno...
by Buckeye
Sun Jun 25, 2023 11:47 pm
Forum: General
Topic: Using VLANs without managed switch?
Replies: 10
Views: 1830

Re: Using VLANs without managed switch?

Assuming you have a wired connection to your TV and only a single ethernet cable already running from the RB4011 to the room where the TV is, and if you want to have access to multiple subnets from different devices in the TV room, and have each subnet work correctly with dhcp, then you will need a ...
by Buckeye
Sun Jun 25, 2023 1:59 pm
Forum: General
Topic: Using VLANs without managed switch?
Replies: 10
Views: 1830

Re: Using VLANs without managed switch?

I tried to setup vlan 111 to bridge. All ports are in bridge. Connected my laptop to the unmanaged switch, still getting wrong IP address (not from subnet of VLAN) That is because your TV is not vlan-aware, so it is ignoring vlan 111 tagged frames. If the TV is getting an IP from what you referred ...
by Buckeye
Sun Jun 25, 2023 1:51 pm
Forum: General
Topic: Using VLANs without managed switch?
Replies: 10
Views: 1830

Re: Using VLANs without managed switch?

Which MikroTik router do you have? You can probably connect your TV to a different port on the router, but then you will need a dedicated cable from the router to the TV. And you will need to either remove the port connected to the TV from the bridge, or for a bit more flexibility, you can configure...
by Buckeye
Sun Jun 25, 2023 12:55 pm
Forum: General
Topic: Using VLANs without managed switch?
Replies: 10
Views: 1830

Re: Using VLANs without managed switch?

Have 3 vlans at home. For example, basic LAN devices has no vlan. Want to set VLAN 111 to TV device. My connection is: routerboard -> tplink switch (unmanaged) - port 1 TV, port 2 computer. So I want to set VLAN 111 TV only. What is your definition of a vlan? Because it seems your definition is dif...
by Buckeye
Sun Jun 25, 2023 7:36 am
Forum: General
Topic: This should be easy
Replies: 17
Views: 1766

Re: This should be easy

I have an ordinary home network consisting of modem and gateway, which does ordinary home things 'fine' / okay adequately. I have no good reason to change it, and it would be difficult / inconvenient and possibly costly to try. But, the firewall is basic, and I want to give my servers additional pr...
by Buckeye
Sun Jun 25, 2023 7:12 am
Forum: General
Topic: This should be easy
Replies: 17
Views: 1766

Re: This should be easy

For someone complaining about things that should be easy, you don't seem to care much about making it easy for others to help. 1. Your title means nothing. Most people will just skip it because if you don't put enough effort into making the title relevant, it is a good indicator that the post wont' ...
by Buckeye
Sun Jun 25, 2023 6:54 am
Forum: RouterBOARD hardware
Topic: hEX Router Reset button broke off
Replies: 16
Views: 5622

Re: hEX Router Reset button broke off

Did you contact the seller? The switch shouldn't just "fall off the board". Do you have a photo? Here are photos of the what the RB750Gr3 mother board looks like: from https://www.roc-noc.com/mikrotik/routerboard/hEX/RB750Gr3.html https://www.roc-noc.com/images/D/rb750Gr3_l_1200px.png comp...
by Buckeye
Fri Jun 23, 2023 2:26 am
Forum: General
Topic: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]
Replies: 45
Views: 5905

Re: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]

Thanks for updating the title to make it easier to find in the future. I have this thread saved in my useful links spreadsheet. I am trying to think of a way that we could have narrowed this down faster. Does the Spanning Tree Protocol Monitoring display give any clues when you switch between HW an ...
by Buckeye
Thu Jun 22, 2023 7:08 am
Forum: General
Topic: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]
Replies: 45
Views: 5905

Re: VLAN-Trunk not working [SOLVED]

@thn80 Thanks for your good documentation of the issue. I haven't seen the issue you saw with my hEX S, but the "trunk" link was a bit different on my setup, and the other end of the trunk link was a Ubiquiti ER-X with the vlan-aware switch0. And the ER-X doesn't support RSTP on the switch...
by Buckeye
Wed Jun 21, 2023 3:44 am
Forum: General
Topic: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]
Replies: 45
Views: 5905

Re: VLAN-Trunk not working [SOLVED]

If you still have the "setup", and have not cycled power, are there any hints in the output of log/print ? Also just to validate that setting the pvid on the trunk port to 99 does not affect the outcome, can you manually change the pvid of ether3 back to vlan 1, because it was questioned i...
by Buckeye
Tue Jun 20, 2023 10:53 pm
Forum: General
Topic: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]
Replies: 45
Views: 5905

Re: VLAN-Trunk not working [SOLVED]

@thn80 good detective work. The gif "movie" is pretty convincing that you have found the root cause of the problem. BTW, for others if you want to save the .gif after you click on "Play GIF 3.2MB", while it is playing, right click on playing image and same image as. Turning on/of...
by Buckeye
Tue Jun 20, 2023 1:57 am
Forum: General
Topic: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]
Replies: 45
Views: 5905

Re: VLAN-Trunk not working [SOLVED]

@sindy @tdw @mkx @Sob or any others that don't mind getting into the nitty gritty details of vlans and MikroTik vlan-filtering bridge. Do any of you see any reason why the config should not work? And why it would work for a short time shortly after link status change from down to up, but then stop w...
by Buckeye
Tue Jun 20, 2023 1:47 am
Forum: General
Topic: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]
Replies: 45
Views: 5905

Re: VLAN-Trunk not working [SOLVED]

@thn80 it appears you have configured ether5 on the hapax2 as a vlan 10 access port. (evidence output of [thomas@hapax2] > /interface/bridge/port/print detail Flags: X - disabled, I - inactive; D - dynamic; H - hw-offload 0 I interface=ETH5_MGMT bridge=bridge_primary priority=0x80 path-cost=10 inter...
by Buckeye
Tue Jun 20, 2023 12:09 am
Forum: General
Topic: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]
Replies: 45
Views: 5905

Re: VLAN-Trunk not working [SOLVED]

If there is someone else with a hap ax lite that is using vlans with the vlan filtering bridge with one bridge port tagged and another untagged ( using same vlan id ), can you report that it works? And also what version of firmware you are using on the hap ax lite with working vlans?
by Buckeye
Tue Jun 20, 2023 12:04 am
Forum: General
Topic: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]
Replies: 45
Views: 5905

Re: VLAN-Trunk not working [SOLVED]

One odd observation: The hap ax2 sees the LLDP packets from the hap ax lite, but the hap ax lite isn't seeing the LLDP from the hap ax2 (reference of info for my observation: output of /ip/neighbor/print detail On hap ax lite: [thomas@MikroTik] > /ip/neighbor/print detail 0 interface=ETH4_MGMT,bridg...
by Buckeye
Mon Jun 19, 2023 2:42 am
Forum: General
Topic: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]
Replies: 45
Views: 5905

Re: VLAN-Trunk not working [SOLVED]

@thn80 thanks, that is a much easier config to deal with. What things if any were removed (i.e. not shown in the configs posted, if anything was sanitized out)? You are not setting mac addresses on any of the interfaces are you? How many interfaces does your PC have? If multiple adapters, are they d...
by Buckeye
Sun Jun 18, 2023 10:20 am
Forum: General
Topic: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]
Replies: 45
Views: 5905

Re: VLAN-Trunk not working [SOLVED]

You said it will use the default PVID=1 in case nothing is configured via console, but what is the difference between the default PVID=1 and my PVID=99 if the Frame Type is set to "admit only VLAN tagged"? In both cases it should simply be a number that is not used, right? (Just for my un...
by Buckeye
Sun Jun 18, 2023 3:26 am
Forum: General
Topic: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]
Replies: 45
Views: 5905

Re: VLAN-Trunk not working [SOLVED]

I tried to simply remove the PVID, but without an PVID the error message "Error in PVID - decimal number in range [1;4094] expected!" appears. I don't think you are telling us the whole story. Copy and paste exactly what you typed, and error message as it appeared. if you entered pvid wit...
by Buckeye
Sat Jun 17, 2023 11:53 pm
Forum: General
Topic: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]
Replies: 45
Views: 5905

Re: VLAN-Trunk not working [SOLVED]

So far I searched for some hours and stupidly cannot find the problem :-? . The configuration is - maybe - a little bit messed up or overcomplicated at the moment, because of the fact this MikroTik device is my playground. But I don't want to reset it to the defaults and start over again, instead I...
by Buckeye
Sat Jun 17, 2023 10:51 am
Forum: General
Topic: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]
Replies: 45
Views: 5905

Re: VLAN-Trunk not working [SOLVED]

add bridge=bridge_primary frame-types=admit-only-untagged-and-priority-tagged \ interface=ETH4_MGMT pvid=10 add bridge=bridge_primary frame-types=admit-only-vlan-tagged interface=\ ETH3_DOWNSTREAM_TRUNK pvid=99 Shot in the dark, but is ETH3_DOWNSTREAM_TRUNK pvid=99 causing the problem? The way I'm ...
by Buckeye
Sat Jun 17, 2023 10:12 am
Forum: General
Topic: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]
Replies: 45
Views: 5905

Re: VLAN-Trunk not working [SOLVED]

The following looks suspect to me: ETH4_MGMT is part of the bridge, and should be getting access via VLAN_10_MGMT, /interface list member add interface=ETH4_MGMT list=mgmt_allowed_interfaces add interface=VLAN_10_MGMT list=mgmt_allowed_interfaces It is hard to follow your firewall rules, I would try...
by Buckeye
Sat Jun 17, 2023 9:44 am
Forum: General
Topic: VLAN-Trunk not working [SOLVED - incorrect BPDU filtering on hAP ax lite HW offloaded trunk ports] [SOLVED]
Replies: 45
Views: 5905

Re: VLAN-Trunk not working [SOLVED]

what is connected to ether3? Is it vlan aware?
by Buckeye
Fri Jun 16, 2023 2:19 am
Forum: RouterOS beta
Topic: Zerotier to Mipsbe??
Replies: 109
Views: 38204

Re: Zerotier to Mipsbe??

Ubiquiti MIPS especially caught my attention. Also OpenWRT X86-64/MIPS/PPC. The ER-X is based on the same SoC as the hEX, but the ER-X has 256MB of flash in addition to 256MB of RAM. The hEX has 256MB of RAM, but the hEX flash is limited to a paltry 16MB, although it does have an SD slot, but as fa...
by Buckeye
Thu Jun 15, 2023 9:53 pm
Forum: RouterBOARD hardware
Topic: New to Mikrotik - Hex S or something else?
Replies: 15
Views: 8475

Re: New to Mikrotik - Hex S or something else?

I think that the primary thing that affects gaming is latency and jitter, not throughput.
by Buckeye
Thu Jun 15, 2023 9:51 pm
Forum: RouterBOARD hardware
Topic: New to Mikrotik - Hex S or something else?
Replies: 15
Views: 8475

Re: New to Mikrotik - Hex S or something else?

If you have the hEX, try it and see if it meets your needs. The hEX will probably be fast enough for you real needs. If you lived near the autobaun, would you only buy a Bugatti Chiron so you could get the "full potential" of the road? Then after you have used the hEX and if you determine ...
by Buckeye
Thu Jun 15, 2023 2:19 am
Forum: Beginner Basics
Topic: Basic VLAN and 802.1q trunks
Replies: 7
Views: 2258

Re: Basic VLAN and 802.1q trunks

I am trying to understand why you want a second bridge "device". You talk about wanting management to have a different (probably standard 1500) MTU. A vlan interface (created with /interface vlan) is similar to a Cisco SVI vlan interface, and it is the CPU's connection to a specific vlan o...
by Buckeye
Wed Jun 14, 2023 10:23 pm
Forum: Beginner Basics
Topic: help or documentation about bridge vlan filtering
Replies: 8
Views: 1380

Re: help or documentation about bridge vlan filtering

Asking if the hEX is sufficient for your use case without describing what your use case is won't get you useful answers. Why did you specifically ask about the hEX? And by hEX do you mean RB750Gr3? If you already have the hEX, I would try it to see if it is sufficient. It will be faster than the CPU...
by Buckeye
Tue Jun 13, 2023 11:37 pm
Forum: General
Topic: rb5009 and hardware offloading confusion
Replies: 9
Views: 2436

Re: rb5009 and hardware offloading confusion

Your main point in the first paragraph or your OP seemed to be a concern that the 10Gb link would be a bottleneck. I see all ports are behind the 88E6393X switch chip at 10G, so CPU routing on this platform is going to be limited to 5G FDX or 10G Aggregate since data has to pass in and out that 10G ...
by Buckeye
Tue Jun 13, 2023 1:44 am
Forum: RouterBOARD hardware
Topic: New Hardware SPOILER!!! [RB L009UiGS-2HaxD] [SOLVED]
Replies: 48
Views: 15985

Re: New Hardware SPOILER!!! [RB L009UiGS-2HaxD] [SOLVED]

My guess is that ax isn't going to make much difference for IoT devices. For your use case and two choices you gave (although you don't specify which hap ax you are talking about, there are 3 (lite, 2, and 3). If choosing between hap ax2 and L009 I would choose hap ax2. I posted this about tradeoffs...
by Buckeye
Mon Jun 12, 2023 10:26 pm
Forum: Beginner Basics
Topic: Beginner VLAN setup question(s) [SOLVED]
Replies: 48
Views: 6588

Re: Beginner VLAN setup question(s) [SOLVED]

Unfi is a strange beast, at least their APs expect, as the default, the management subnet untagged and the data vlans tagged. This is probably to support all the folks that just want to plug in one network to their AP, ( management subnet = data subnet = single SSID wlan ) In which case there are n...
by Buckeye
Sat Jun 10, 2023 6:40 am
Forum: Announcements
Topic: Official Discord
Replies: 18
Views: 29318

Re: Official Discord

Oh I get it, the gap will be filled in when they add Zerotrust Cloudflare tunnel as an options package for all devices.
MikroTik Mikro Tip Host a webserver on your router using CONTAINERS! mentions Cloudflare tunnels, so let Druvis know your feelings about it with a comment.
by Buckeye
Sat Jun 10, 2023 4:56 am
Forum: Beginner Basics
Topic: Outbound from 5060 port
Replies: 8
Views: 1806

Re: Outbound from 5060 port

See rfc5737 , IPv4 Address Blocks Reserved for Documentation there are three /24's reserved for documentation and examples. Using these makes it clear that they are meant to replace global addresses. It is easy to do, just use a text editor and do a global replace of the first 3 octets of you global...
by Buckeye
Sat Jun 10, 2023 12:38 am
Forum: General
Topic: Twice NAT example
Replies: 12
Views: 1662

Re: Twice NAT example

Overlapping subnets is not a good long term solution. It will cause confusion to people at both sites, because to get it to work you have to make each site believe the other is on a different network than they are locally. Consider people trying to access the server from the other location, and they...
by Buckeye
Sat Jun 03, 2023 3:14 am
Forum: Announcements
Topic: EDITED Forum THEME / SKIN change
Replies: 92
Views: 13517

Re: EDITED Forum THEME / SKIN change

For completeness, here is how to change from Canvas
Where to find control panel in Canvas.png
Where to find Board Preferences in Canvas.png
How to select style in Canvas.png
by Buckeye
Sat Jun 03, 2023 12:05 am
Forum: Announcements
Topic: EDITED Forum THEME / SKIN change
Replies: 92
Views: 13517

Re: EDITED Forum THEME / SKIN change

I don't know what this "blue" theme is called, but it's broken, I can't access control panel.
If you are referring to prosilver, here is how:
Where to find control panel in phpBB.png
Where to find Board Preferences in phpBB.png
How to select board style and date format phpBB.png
by Buckeye
Fri Jun 02, 2023 11:58 am
Forum: Announcements
Topic: EDITED Forum THEME / SKIN change
Replies: 92
Views: 13517

Re: EDITED Forum THEME / SKIN change

Thanks for at least giving us some choice. I still prefer Allan Style - SUBSILVER to prosilver, but I prefer prosilver to Canvas, and I have reset to prosilver.
by Buckeye
Thu Jun 01, 2023 11:03 pm
Forum: Announcements
Topic: EDITED Forum THEME / SKIN change
Replies: 92
Views: 13517

Re: EDITED Forum THEME / SKIN change

It seems requests for previous choice are falling on deaf ears.
by Buckeye
Mon May 29, 2023 10:20 pm
Forum: General
Topic: How to remove one or more NAT layers from my internal network?
Replies: 31
Views: 2367

Re: Accessing internet without NAT?

@Aymen1986 It seems you don't understand the purpose of NAT or the difference between private and public ip addresses.

Watch this layman's guide to NAT. How Network Address Translation Works by PieterExplainsTech (a 2012 video, but still one of the best layman's explanation I am aware of).
by Buckeye
Mon May 29, 2023 10:07 pm
Forum: Beginner Basics
Topic: Block communication between multiple ports
Replies: 9
Views: 1409

Re: Block communication between multiple ports

To do what you are asking (whether it is really what you want/need) you will need to use switches that have port isolation as an option. For example, see Port Isolation for how a MikroTik 24 port switch running SwOS can be configured. Assuming you want to do everything on the RB2011 which has multip...
by Buckeye
Mon May 29, 2023 9:10 am
Forum: Forwarding Protocols
Topic: using static routes to overide BGP and OSPF internally
Replies: 8
Views: 2779

Re: using static routes to overide BGP and OSPF internally

If I put a static route 0.0.0.0/0 to the far end tunnel address on the ATT circuit the router immediately drops the two tunnels and they cycle 1 sec. down, 1 sec up 1 sec. down etc and the tunnels are unusable. If i put a 0.0.0.0/1 route, everything works fine (except we are missing 1/2 of the inte...
by Buckeye
Mon May 29, 2023 6:36 am
Forum: Beginner Basics
Topic: Best configuration for my setup. Vlan, bridge…?
Replies: 7
Views: 1332

Re: Best configuration for my setup. Vlan, bridge…?

IMHO, OP wants partial router-on-a-stick config. You are guessing. Without more info, that's all that is possible. Part of the reason for pushing back to the OP for more clarification, is because just by trying to explain it, he will get a better understanding of what he doesn't know, and where he ...
by Buckeye
Mon May 29, 2023 3:14 am
Forum: Beginner Basics
Topic: Best configuration for my setup. Vlan, bridge…?
Replies: 7
Views: 1332

Re: Best configuration for my setup. Vlan, bridge…?

I'm a bit lost in all this So are we. When posting, you need to think like a successful fisherman, and use enticing bait instead of dangling an empty hook into the water and expecting to get any nibbles. What have you tried? What was your expectation and how was it different than the result? What r...
by Buckeye
Sun May 28, 2023 11:28 am
Forum: Beginner Basics
Topic: Bridging 2 VLAN's does not seem to work.
Replies: 1
Views: 403

Re: Bridging 2 VLAN's does not seem to work.

Not sure exactly how you have things configured or wired. I don't think you should use two bridges.

Read through this thread that may be helpful VLAN Passthrough from WAN port to LAN bridge (specific port)

If it isn't you will need to post a network diagram and a sanitized export of your config.
by Buckeye
Fri May 26, 2023 12:19 am
Forum: Announcements
Topic: EDITED Forum THEME / SKIN change
Replies: 92
Views: 13517

Re: EDITED Forum THEME / SKIN change

Is the "Select all" from a code block working for anyone? It only sends me to the top of the topic.. I don't think that this ever worked anyway.. It hasn't worked since I became active again in Mar 2022. I reported it here: Code: Select all does not select text in code block It was one re...
by Buckeye
Tue May 23, 2023 10:40 am
Forum: Announcements
Topic: EDITED Forum THEME / SKIN change
Replies: 92
Views: 13517

Re: EDITED Forum THEME / SKIN change

What is the surprise for next week? No more access to ROS v6.
by Buckeye
Tue May 23, 2023 10:36 am
Forum: Announcements
Topic: EDITED Forum THEME / SKIN change
Replies: 92
Views: 13517

Re: EDITED Forum THEME / SKIN change

I agree, some of us like functionaltiy over "modern clean" look. If we wanted simple user interface with no view into details, we would get Ubitquiti UDM routers. Are you trying to complete with Google/Android and changing things "just because we can"? First you took away Allan S...
by Buckeye
Mon May 22, 2023 11:05 am
Forum: General
Topic: Any info about this ? ZDI-23-710 CVE-2023-32154
Replies: 48
Views: 9012

Re: Any info about this ? ZDI-23-710 CVE-2023-32154

These events are then financed by selling the vulnerabilities on the darknet?, so it is obvious that they mysteriously do not communicate the vulnerabilities efficiently... If they fix them immediately, they earn less or nothing... There have been cases of "insider trading", like this Rog...
by Buckeye
Mon May 22, 2023 10:44 am
Forum: General
Topic: Any info about this ? ZDI-23-710 CVE-2023-32154
Replies: 48
Views: 9012

Re: Any info about this ? ZDI-23-710 CVE-2023-32154

Sorry but this is also false, MikroTik was not directly involved in this event or prize.
Edit: that is about the PwnToronto event.
Yes, making any assumptions of validity of what you read/see on the internet is a dangerous activity. But it is one reason I like to include the source I am quoting.
by Buckeye
Mon May 22, 2023 10:38 am
Forum: General
Topic: Any info about this ? ZDI-23-710 CVE-2023-32154
Replies: 48
Views: 9012

Re: Any info about this ? ZDI-23-710 CVE-2023-32154

They sent a screenshot of an email, but it is not clear whether it was actually sent out, or if they did not get "mail delivery failure" in return. I agree, a screen shot isn't too hard to create "after the fact" either. I also agree that a single mail doesn't qualify as "e...
by Buckeye
Mon May 22, 2023 10:18 am
Forum: General
Topic: Any info about this ? ZDI-23-710 CVE-2023-32154
Replies: 48
Views: 9012

Re: Any info about this ? ZDI-23-710 CVE-2023-32154

This is interesting: https://nakedsecurity.sophos.com/2022/12/12/pwn2own-toronto-54-hacks-63-new-bugs-1-million-in-bounties/ Excerpt: The devices put forward by their vendors, and the prize money offered for successful hacks, looked like this: ---snip--- HACK A SOHO ROUTER.. AND WIN: TPLink AX1800 $...
by Buckeye
Mon May 22, 2023 10:06 am
Forum: General
Topic: Any info about this ? ZDI-23-710 CVE-2023-32154
Replies: 48
Views: 9012

Re: Any info about this ? ZDI-23-710 CVE-2023-32154

I just searched for MikroTik security disclosure and did find this page. Responsible disclosure of discovered vulnerabilities And it has been there at least since 3-Dec-2022. You can verify this on the wayback machine https://web.archive.org/web/20221203224140/https://mikrotik.com/supportsec So it s...
by Buckeye
Mon May 22, 2023 12:23 am
Forum: Wireless Networking
Topic: Guest Network Unable to get out to Internet
Replies: 7
Views: 1844

Re: Guest Network Unable to get out to Internet

Before suggesting fixes, you need to have a reasonable plan. Then the configuration should be much easier. What was the sequence you used to configure your router, and what guides/documentation did you use? I would suggest going back and rethinking your whole config, because it is far from "sta...
by Buckeye
Sun May 21, 2023 10:29 pm
Forum: Wireless Networking
Topic: Guest Network Unable to get out to Internet
Replies: 7
Views: 1844

Re: Guest Network Unable to get out to Internet

You added an interface (vlan21_guest), but have not added it to any list. When you say you can't get to the net, do you mean that ping 1.1.1.1 does not work? Or do you mean that ping one.one.one.one does not work? If these are windows host on the guest network, what does cmd command line show for ip...
by Buckeye
Sun May 21, 2023 10:14 pm
Forum: General
Topic: Basic Firewall Question
Replies: 13
Views: 1112

Re: Basic Firewall Question

There is nothing like Juniper commit confirmed (or vyatta commit-confirm) if that is what you are referring to (built in).

Here's an outline of a workaround by @rextended here with a possible implementation by @lukastribus here.
by Buckeye
Sun May 21, 2023 9:55 am
Forum: General
Topic: Any info about this ? ZDI-23-710 CVE-2023-32154
Replies: 48
Views: 9012

Re: Any info about this ? ZDI-23-710 CVE-2023-32154

Hopefully, this is a wakeup call that MikroTik needs to have a relationship with the vulnerability testings organizations, so things like this don't end up in junk mail. I am sure when they received the "final" notice, it was something like this xkcd students cartoon, but it didn't have as...
by Buckeye
Sun May 21, 2023 6:29 am
Forum: General
Topic: Any info about this ? ZDI-23-710 CVE-2023-32154
Replies: 48
Views: 9012

Re: Any info about this ? ZDI-23-710 CVE-2023-32154

If I do not remember bad the default on both v6 and v7 is accept-router-advertisements= yes-if-forwarding-disabled and forward=yes It seems that rextended has good memory, and so by default (at least on 7.8 ) you should not be vulnerable (based on @normis post ) because forward=yes Here is RB760iGS...
by Buckeye
Sat May 20, 2023 10:41 pm
Forum: General
Topic: CRS305 Windows File Transfer Speeds Stuck at 400-500MBs
Replies: 7
Views: 868

Re: CRS305 Windows File Transfer Speeds Stuck at 400-500MBs

Thanks for update on SMB problems on Win 11. I would investigate why windows updates are not being applied, as there are many security patches since Jan. When was last update applied? I thought that Windows update were supposed to now be cumulative, but there have been reports of things being missed...
by Buckeye
Sat May 20, 2023 10:16 am
Forum: Announcements
Topic: v7.9 [stable] is released!
Replies: 242
Views: 59297

Re: v7.9 [stable] is released!

Saturday humor: Reading this thread reminded me of several xkcd comics. They are meant for humor value only. Many of the bugs fixed in version 7.9 have been introduced in the 7.8 beta. And many errors seem to occur randomly. xkcd: New Bug xkcd: Fixing Problems Not xkcd, but relevant: 99 little bugs ...
by Buckeye
Sat May 20, 2023 4:57 am
Forum: General
Topic: Help please [SOLVED]
Replies: 8
Views: 1782

Re: Help please [SOLVED]

Try writing in Spanish, then translate it to English with an online translator. I can't understand the part about vlans and bonding. Is https://translate.google.com blocked in Cuba? If so, you can try using https://www.deepl.com/en/translator Translated with translate.google.com Intente escribir en ...
by Buckeye
Sat May 20, 2023 12:19 am
Forum: Beginner Basics
Topic: Can't get dst-nat to work
Replies: 17
Views: 2978

Re: Can't get dst-nat to work

Having multiple ip addresses on your ether1 interface complicates things.

Do a google search for mikrotik nat masquerade when exit interface has mulitple addresses there are many threads, I didn't read them because I don't have multiple addresses on my router's WAN.
by Buckeye
Fri May 19, 2023 9:56 pm
Forum: Beginner Basics
Topic: VLAN, Bridge and DHCP [SOLVED]
Replies: 4
Views: 3158

Re: VLAN, Bridge and DHCP [SOLVED]

...This wasn't part of the examples I was following including in the documentation at https://help.mikrotik.com/docs/display/ROS/Bridging+and+Switching#BridgingandSwitching-BridgeVLANFiltering The examples are showing how to configure the L2 parts. Here's the example that does have the bridge inclu...
by Buckeye
Fri May 19, 2023 9:31 pm
Forum: Beginner Basics
Topic: VLAN, Bridge and DHCP [SOLVED]
Replies: 4
Views: 3158

Re: VLAN, Bridge and DHCP [SOLVED]

I see you already figured it out while I was creating this. But you may still find it useful if you want to understand why, instead of just finding something that works. You need to create "connections" from the switch ASIC to the CPU. My guess is that you currently have Layer 2 connectivi...
by Buckeye
Fri May 19, 2023 6:08 am
Forum: General
Topic: CRS305 Windows File Transfer Speeds Stuck at 400-500MBs
Replies: 7
Views: 868

Re: CRS305 Windows File Transfer Speeds Stuck at 400-500MBs

MB or Mb? MegaBytes/sec or Megabits/sec

There are many variables.

You may want to review this reddit thread What should throughput speed speed for 10gbe file transfer? Jeff Geerling second to last post.
by Buckeye
Fri May 19, 2023 5:40 am
Forum: Beginner Basics
Topic: CPE and issue with resceving an IP
Replies: 10
Views: 2539

Re: CPE and issue with resceving an IP

So it seems now to be an issue between the printer and mikrotik and not the implementation itself?
Has the printer ever been able to obtain an IP address with dhcp from any dhcp server?
by Buckeye
Fri May 19, 2023 5:37 am
Forum: Beginner Basics
Topic: CPE and issue with resceving an IP
Replies: 10
Views: 2539

Re: CPE and issue with resceving an IP

First thing I would try is click the "always broadcast" in the dhcp server. See this post for what I mean. Probably won't change anything, but it is easy to do and undo. If that makes no difference, then more troubleshooting/testing will be needed. If you connect the printer directly to a ...
by Buckeye
Fri May 19, 2023 5:22 am
Forum: RouterBOARD hardware
Topic: RB5009 console port
Replies: 3
Views: 7801

Re: RB5009 console port

What speed does the RB5009 set the serial connection of the adapter it is connected to? 115200? What about flow control? The MikroTik help isn't real clear about using two serial adapters back to back. So if you got two of the USB to RS232 cisco Rj45 cables, and a "RJ45 8P8C modular coupler wit...
by Buckeye
Thu May 18, 2023 9:27 pm
Forum: Beginner Basics
Topic: Tag to untagged simple: RB2011UiAS FW7.6
Replies: 9
Views: 799

Re: Tag to untagged simple: RB2011UiAS FW7.6

I can't imagine the RB2011 couldn't handle this data-streams and the SG105E could. (there for in the old setup the RB2011 works fine) I want to use the RB2011 as a simple managed switch, so I don't have to throw them away. Why are you using the 100Mbps ports on the RB2011 instead of the 1Gbps ether...
by Buckeye
Thu May 18, 2023 2:02 am
Forum: Beginner Basics
Topic: Setup Help
Replies: 20
Views: 1725

Re: Setup Help

The settings on this board won't allow you to detete your post if something follows it. At least to me, that is the way it appears to work.
by Buckeye
Thu May 18, 2023 12:38 am
Forum: Beginner Basics
Topic: Setup Help
Replies: 20
Views: 1725

Re: Setup Help

That was my lab router, not the OPs. And there isn't anything connected to ether5 at the moment.
I was just showing the OP where the "Always Broadcast" was in newer versions of WinBox/ROS than the picture in the link to another thread I posted.
by Buckeye
Thu May 18, 2023 12:25 am
Forum: Beginner Basics
Topic: Tag to untagged simple: RB2011UiAS FW7.6
Replies: 9
Views: 799

Re: Tag to untagged simple: RB2011UiAS FW7.6

Here's the "universal" way, but won't be done in the switch chip on the RB2011 VLAN Example - Trunk and Access Ports How is the RB5009 connected to the RB2011? Is it connected to the same switch as the cameras? You wrote "I have multiply camera, three are connected through a RB2011 (s...
by Buckeye
Wed May 17, 2023 11:44 pm
Forum: Beginner Basics
Topic: Setup Help
Replies: 20
Views: 1725

Re: Setup Help

I will be surprised if this makes a difference, but you could try forcing the dhcp server to always use broadcasts. That's generally not the best, but in a small network you probably won't notice a difference. There are some devices that periodically poll to verify that devices are still there, and ...
by Buckeye
Wed May 17, 2023 6:50 pm
Forum: Announcements
Topic: FORUM MAINTENANCE: Password reset will be needed
Replies: 162
Views: 47729

Re: FORUM MAINTENANCE: Password reset will be needed

Allan Style - SUBSILVER is gone too, and it was the only one that would display dates of quotes (at least I think that is why I used it). It also had a link via the tiny uparrow to the post that the quote was from. (I see prosilver has this, but not the date, or the post # of quotes). Allan Style -...
by Buckeye
Wed May 17, 2023 3:46 am
Forum: Beginner Basics
Topic: Tag to untagged simple: RB2011UiAS FW7.6
Replies: 9
Views: 799

Re: Tag to untagged simple: RB2011UiAS FW7.6

Almost like you want, you need to move the trunk to ether1 and add ether2 as an access port. And adjust the vlans to the vlans you want. You should be able to figure it out from that example.
VLAN Example 1 (Trunk and Access Ports)
by Buckeye
Wed May 17, 2023 12:23 am
Forum: Beginner Basics
Topic: CPE and issue with resceving an IP
Replies: 10
Views: 2539

Re: CPE and issue with resceving an IP

You could try using the wireless repeater feature and then adding the ethernet ports to the bridge that got created.

See this thread Bridge an existing Wifi to LAN
by Buckeye
Tue May 16, 2023 11:24 pm
Forum: Beginner Basics
Topic: Can't get dst-nat to work
Replies: 17
Views: 2978

Re: Can't get dst-nat to work

I've got the following addresses (public IPs have been changed for privacy):
So you just use someone else's public IP? Why not use the IP addresses reserved for documentation and examples? See rfc5737.
TEST-NET-1 192.0.2.0/24
TEST-NET-2 198.51.100.0/24
TEST-NET-3 203.0.113.0/24
by Buckeye
Tue May 16, 2023 10:43 pm
Forum: Beginner Basics
Topic: Router VLAN/ NAT configuration
Replies: 5
Views: 1105

Re: Router VLAN/ NAT configuration

I also found this post, but I haven't figured out how it works yet.

How to allow two devices with same IP access internet
by Buckeye
Tue May 16, 2023 9:58 pm
Forum: Beginner Basics
Topic: Router VLAN/ NAT configuration
Replies: 5
Views: 1105

Re: Router VLAN/ NAT configuration

I am reasonably sure you will need a separate router between the RB2011 and each test device to provide NAT for each test device. Something like this post And you won't need a separate vlan for the connection from the RB2011 to the NAT routers, since the NAT routers will each have a unique address o...
by Buckeye
Tue May 16, 2023 9:32 am
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 45313

Re: Newsletter #113 | May 2023

People did not "used to" buy RB2011. They buy it today. A lot. L009 is similar, but better. At the same price. But you didn't really address why people are still buying it. As pointed out in the rest of the post you quoted. and as for drop in replacement this device isn't because it only ...
by Buckeye
Tue May 16, 2023 5:34 am
Forum: Beginner Basics
Topic: Several beginner questions about config
Replies: 1
Views: 455

Re: Several beginner questions about config

Can you explain what the purpose of the first rule in your firewall is? /ip firewall filter add action=passthrough chain=forward out-interface=ether3_WAN More importantly, it does not appear that you are using any stateful rules, i.e. rules for returning established and related traffic. Perhaps star...
by Buckeye
Tue May 16, 2023 5:24 am
Forum: Beginner Basics
Topic: Setup Help
Replies: 20
Views: 1725

Re: Setup Help

Maybe related, maybe not. R720 DHCP client bug
by Buckeye
Tue May 16, 2023 4:18 am
Forum: Beginner Basics
Topic: Setup Help
Replies: 20
Views: 1725

Re: Setup Help

In other words, if you plug a wired connection into one of the Ruckus switch ports, does that work correctly?
I haven't tried it as they are on the ceiling.
The Ruckus 10 port switch is on the ceiling?
by Buckeye
Tue May 16, 2023 4:16 am
Forum: Beginner Basics
Topic: Setup Help
Replies: 20
Views: 1725

Re: Setup Help

use 7d for 7 days.
by Buckeye
Tue May 16, 2023 1:05 am
Forum: Beginner Basics
Topic: Setup Help
Replies: 20
Views: 1725

Re: Setup Help

As mentioned, I extended the leases to 24 hours (would prefer never but can't find that option). I don't think this is really your problem, but you can make your leases longer than 23h59m. For example: [demo@RB760iGS-1] > /ip/dhcp-server/export # may/15/2023 18:01:30 by RouterOS 7.8 # software id =...
by Buckeye
Tue May 16, 2023 12:26 am
Forum: Beginner Basics
Topic: Setup Help
Replies: 20
Views: 1725

Re: Setup Help

It seems all your problems are related to the wifi connections. Is that correct? In other words, if you plug a wired connection into one of the Ruckus switch ports, does that work correctly? Are the Ruckus WAPs new? i.e when you had the Google OnHub was that what was providing wifi before? Does your...
by Buckeye
Mon May 15, 2023 2:26 am
Forum: General
Topic: eMMC memory
Replies: 7
Views: 1052

Re: eMMC memory

What made you ask that question?

What problem are you trying to solve?
by Buckeye
Sat May 13, 2023 3:32 am
Forum: General
Topic: SwOS port mirroring
Replies: 4
Views: 1360

Re: SwOS port mirroring

I don't have a CSS106-5G-1S switch, but the manual has this Forwarding and you should be able to select mirror to on the port connected to your wireshark device and then you can monitor another port's ingress and egress traffic and it should be copied to the mirror port.
by Buckeye
Fri May 12, 2023 11:19 pm
Forum: General
Topic: SwOS port mirroring
Replies: 4
Views: 1360

Re: SwOS port mirroring

Which switch model? Different SwOS switches have different places to configure mirroring.

Here is how I set up my CSS106-5G-1S for a wireshark tap.
by Buckeye
Fri May 12, 2023 8:44 pm
Forum: General
Topic: VLANs and trunk/access ports [SOLVED]
Replies: 6
Views: 21769

Re: VLANs and trunk/access ports [SOLVED]

Since you only want a single fail-safe port to work from, there is no need for a second bridge. Just remove the port from the bridge-shared bridge. You can name interfaces, if you want to remove the need to refer to it as ether5. Here 's the easy way to do that. You can do a google search for remove...
by Buckeye
Fri May 12, 2023 8:28 pm
Forum: General
Topic: VLANs and trunk/access ports [SOLVED]
Replies: 6
Views: 21769

Re: VLANs and trunk/access ports [SOLVED]

The @sindy post: RouterOS bridge mysteries explained that @mkx linked is excellent. When I was learning the MikroTik vlan-filtering bridge, it was one of the most helpful resources for me to wrap my head around how to logically map what the bridge "entity" was, coming from EdgeRouter X vla...
by Buckeye
Fri May 12, 2023 10:08 am
Forum: General
Topic: VLANs and trunk/access ports [SOLVED]
Replies: 6
Views: 21769

Re: VLANs and trunk/access ports [SOLVED]

on the access port, you need to define the vlan you want access to as pvid. (this is in the /interface bridge port stanza) for ether4 as an access port for vlan 10 /interface bridge port # Assigned bridges to ports add bridge=bridge_shared frame-types=admit-only-untagged-and-priority-tagged interfac...
by Buckeye
Fri May 12, 2023 7:50 am
Forum: Announcements
Topic: FORUM MAINTENANCE: Password reset will be needed
Replies: 162
Views: 47729

Re: FORUM MAINTENANCE: Password reset will be needed

Maintenance planned 0800-0900 EEST https://www.timeanddate.com/countdown/gaming?iso=20230513T08&p0=602&msg=Forum+maintenance&font=slab One day away. When should we stop posting? Will you first kick all users off, then do the backup and upgrade? And then backup before allowing users back...
by Buckeye
Fri May 12, 2023 7:33 am
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 45313

Re: Newsletter #113 | May 2023

I really just don't get what the real world use case is for the wireless version without it being dual band. I agree with you. Hopefully MikroTik had a good reason for making this config. @normis said that the RB2011 was still a best seller, so there are still places that cost is a primary factor. ...
by Buckeye
Thu May 11, 2023 11:37 pm
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 45313

Re: Newsletter #113 | May 2023

Yes, like you say, we already have RB4011 and RB5009. This is at the other end of the line up (the LOW COST model in similar form factor). except this isn't that... it's more expensive than both the hAP AC2 and hAP AC3 which is what it really competes with in performance. @normis didn't claim it wa...
by Buckeye
Thu May 11, 2023 11:02 am
Forum: Announcements
Topic: FORUM MAINTENANCE: Password reset will be needed
Replies: 162
Views: 47729

Re: FORUM MAINTENANCE: Password reset will be needed

I have used Discourse quite a bit and I find the search a lot better than phpBB.
I agree, search on phpbb could be improved a lot. Try to search for "v7.10" or v7+10, you will still get matches on many things you don't want. Maybe I just don't understand how to make the search work.
by Buckeye
Thu May 11, 2023 10:59 am
Forum: Announcements
Topic: FORUM MAINTENANCE: Password reset will be needed
Replies: 162
Views: 47729

Re: FORUM MAINTENANCE: Password reset will be needed

If we had stored passwords in the clear, there would be no need to reset ;)
Good point.
by Buckeye
Thu May 11, 2023 10:53 am
Forum: Announcements
Topic: FORUM MAINTENANCE: Password reset will be needed
Replies: 162
Views: 47729

Re: FORUM MAINTENANCE: Password reset will be needed

Be careful when/if you migrate that you don't break links to other threads in the forum itself. HPE migraged their ITRC forums and didn't "fixup" the links to internal threads. That left many dead links, with no good way to know what post they were even originally pointing to. After that f...
by Buckeye
Thu May 11, 2023 10:39 am
Forum: RouterBOARD hardware
Topic: New Hardware SPOILER!!! [RB L009UiGS-2HaxD] [SOLVED]
Replies: 48
Views: 15985

Re: New Hardware SPOILER!!! [RB L009UiGS-2HaxD] [SOLVED]

No HW encription, There may be hope, the hap ax lite is getting hw assisted ipsec in v7.10beta *) ipsec - added hardware acceleration support for IPQ-5010 (hAP ax lite); That's not the same chip as the L009 has (IPQ-5018), but they are probably closely related due to the similar performance numbers...
by Buckeye
Thu May 11, 2023 10:21 am
Forum: Announcements
Topic: FORUM MAINTENANCE: Password reset will be needed
Replies: 162
Views: 47729

Re: FORUM MAINTENANCE: Password reset will be needed

(this time, use something randomly generated). Hopefully you are not storing passwords in the clear. Not that is would matter to me, I use a password manager, and set long random passwords, different for each site. What is odd is your statement "this time, use something randomly generated"...
by Buckeye
Wed May 10, 2023 10:16 pm
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 45313

Re: Newsletter #113 | May 2023

- L009 series - the perfect RB2011 upgrade; First, thanks for getting the documentation links updated with block diagram, performance test, etc. Can someone be tasked with updating the Switch Chip Features Introduction documentation to include the 88E6190 switch ASIC? Maybe all that is required is ...
by Buckeye
Wed May 10, 2023 9:57 am
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 45313

Re: Newsletter #113 | May 2023

L009 is smart home switch with posibility to manage thorough 2,4Ghz nothing more. I would say it is a good competitor of the EdgeRouter 10x (which is a MediaTek MT7621 with an RTL8367 for the second set of 5 ethernet ports). Both have console ports, 512 MB RAM (but the ER-10X has 512 MB flash, not ...
by Buckeye
Wed May 10, 2023 8:56 am
Forum: Announcements
Topic: Newsletter #113 | May 2023
Replies: 103
Views: 45313

Re: Newsletter #113 | May 2023

I think the L009 is a perfect fit for homeowners that need more then the hex and not as much as the 5009, basically anyone with a 1 gig connection and with room to grow to a 2.5 gig connection. That's what my first impression was, until I looked at the CPU specs. A dual core 800Mhz Arm processor, w...
by Buckeye
Wed May 10, 2023 5:08 am
Forum: RouterBOARD hardware
Topic: New Hardware SPOILER!!! [RB L009UiGS-2HaxD] [SOLVED]
Replies: 48
Views: 15985

Re: New Hardware SPOILER!!! [RB L009UiGS-2HaxD] [SOLVED]

Until we see performance numbers, we won't really know how it compares to other models. The dual core 800Mhz is underwhelming, the console is nice, and the switch chip has enough ports to make vlan-filtering useful as a stand alone device. 2.5 Gb on the SFP won't be as useful for many users as a 2.5...
by Buckeye
Wed May 10, 2023 4:30 am
Forum: General
Topic: Bridge VLAN Filtering Question
Replies: 5
Views: 653

Re: Bridge VLAN Filtering Question

but even this a rusty nail, intended to show up on the north of your foot : )
I'm slow today. Can you explain what you meant by that?
by Buckeye
Wed May 10, 2023 1:28 am
Forum: General
Topic: what framework is webfig written in?
Replies: 20
Views: 1637

Re: what framework is webfig written in?

Something as complex as RouterOS also means that there will be exceptions and hacks needed for any existing framework, so many, that modifying anything takes more time than to make our own I realize this is drifting away from WebFig, but this post by @Larsa and the following post by @pe1chl discuss...
by Buckeye
Tue May 09, 2023 9:00 pm
Forum: General
Topic: what framework is webfig written in?
Replies: 20
Views: 1637

Re: what framework is webfig written in?

A little too young to have used punch cards, but I have seen them used and for years I carried unused punch cards for writing notes because they fit perfectly in a shirt pocket (yes, right behind the pocket protector with pens in it)... If they fit in your shirt pocket, they were probably the 96 co...
by Buckeye
Tue May 09, 2023 6:39 pm
Forum: General
Topic: Bridge VLAN Filtering Question
Replies: 5
Views: 653

Re: Bridge VLAN Filtering Question

I thought the main advantage was that it was a standard way to do it on ROS devices. It is configured the same independent of the hardware implementation. It isn't guaranteed to be hardware assisted, so there are some platforms that for maximum performance, you can't use the vlan-filtering bridge, b...
by Buckeye
Tue May 09, 2023 6:29 pm
Forum: General
Topic: what framework is webfig written in?
Replies: 20
Views: 1637

Re: what framework is webfig written in?

These days, I limit my "framework" to jQuery, and that only because my code is a third the size when I do it that way instead of programming straight to the wordy browser APIs. I am sure there are good reasons for not using a framework for WebFig, given it needs to run on tightly memory c...
by Buckeye
Tue May 09, 2023 4:21 am
Forum: General
Topic: Problems with printer on lan
Replies: 13
Views: 2287

Re: Problems with printer on lan

Please answer these questions: Does this problem only affect wifi (UniFi) clients? If so, then you should take your problem to the UI community forum. If you use a wired connection to the switch, and tell your pc not to use wifi, and to obtain an ip address via dhcp, what ip does it get? If appears ...
by Buckeye
Tue May 09, 2023 1:14 am
Forum: General
Topic: what framework is webfig written in?
Replies: 20
Views: 1637

Re: what framework is webfig written in?

Are you so brave to say that language on my avatar seems to be a bit unmaintained? :) :) :) My first intro to programming class was Fortran IV on an IBM SYS/3 (running single user mode) and using 80 column punch cards. Also had other classes in RPG II, Cobol and IBM SYS/3 assembler (none that I eve...
by Buckeye
Tue May 09, 2023 12:48 am
Forum: General
Topic: Problems with printer on lan
Replies: 13
Views: 2287

Re: Problems with printer on lan

In my pc, which is by network cable, I put a static ip inside the DHCP and the printer works perfectly. What exactly did you do? What ip address did you set it to? If you let it get its address via dhcp it should get an address from 192.168.3.x, if you do that does it work? If if does not, post the...
by Buckeye
Tue May 09, 2023 12:29 am
Forum: General
Topic: Problems with printer on lan
Replies: 13
Views: 2287

Re: Problems with printer on lan

You are going to need to provide more info than you have. Do you have wireshark installed on your laptop? If not, can you install it? What type of switch is the 48 port switch? Is it a managed switch with a span (cisco terminology) or mirror port ? That along with wireshark on your laptop connected ...
by Buckeye
Mon May 08, 2023 9:44 pm
Forum: Beginner Basics
Topic: Ping issues in same VLAN [SOLVED]
Replies: 5
Views: 1783

Re: Ping issues in same VLAN [SOLVED]

Started in Windows 7 if I recall. Still that way as far as I know on a fresh new install. Public vs Private vs Domain network does not matter - all three default to blocked for Ping. Stupid. One of several thing I change almost immediately on a new Windows install. I don't remember having to change...
by Buckeye
Mon May 08, 2023 9:22 pm
Forum: Beginner Basics
Topic: Ping issues in same VLAN [SOLVED]
Replies: 5
Views: 1783

Re: Ping issues in same VLAN [SOLVED]

Note that in current Windows installations, ping is blocked by default in the Windows firewall. I am not sure what "current" means, does that include Win 10 22H2? I think it may depend on whether you have the more restrictive "Public" profile (for use when connecting to untruste...
by Buckeye
Mon May 08, 2023 8:33 pm
Forum: General
Topic: what framework is webfig written in?
Replies: 20
Views: 1637

Re: what framework is webfig written in?

RouterOS is not made using any frameworks. Webfig is made from scratch / by hand That may have been the correct choice when it was written, but for new things going forward, for example in the hinted at MikroTik Devices Controller , I don't think it makes much sense. But it can lead to many later s...
by Buckeye
Sat May 06, 2023 8:41 pm
Forum: General
Topic: Sniffing traffic with port mirroring [SOLVED]
Replies: 4
Views: 11467

Re: Sniffing traffic with port mirroring [SOLVED]

Here is the relevant documentation: https://help.mikrotik.com/docs/display/ROS/Switch+Chip+Features#SwitchChipFeatures-PortMirroring I have never used this feature, I have a CSS106-5G-1S (RB260GS) with SwOS that I use as a network tap, and it is more flexible. Here's a youtube video (in Dutch?) Mikr...
by Buckeye
Sat May 06, 2023 7:45 pm
Forum: General
Topic: Sniffing traffic with port mirroring [SOLVED]
Replies: 4
Views: 11467

Re: Sniffing traffic with port mirroring [SOLVED]

Port mirroring is a switch ASIC feature, so I don't think you can mirror with an MT device without a switch. See Bridge-based port mirroring And mirroring is different than capturing. It is essentially a "tap" for another device that will capture the traffic (e.g. something running wiresha...
by Buckeye
Sat May 06, 2023 6:58 pm
Forum: General
Topic: Help Identifying Traffic
Replies: 7
Views: 686

Re: Help Identifying Traffic

Why uselessly autoquote yourself? Not intentional. I edited the post, phpbb won't allow me to delete it once there is a following post. (That's another difference between phpbb and other forum software I use). Also on image 7679, 7374, and.... 4? Was that for me? Here is an example of when quoting ...
by Buckeye
Sat May 06, 2023 4:33 am
Forum: General
Topic: Very slow speeds with VLANs
Replies: 7
Views: 2096

Re: Very slow speeds with VLANs

If you look at the CRS310-1G-5S-4S+IN block diagram everything should be done by the 98DX226S SoC with integrated CPU and line rate switch ASIC. That includes tagging/untagging on vlan 20. https://i.mt.lv/cdn/product_files/CRS310-1G-5S-4SIN_220936.png There is always the issue of compatibility betwe...
by Buckeye
Sat May 06, 2023 1:07 am
Forum: General
Topic: Help Identifying Traffic
Replies: 7
Views: 686

Re: Help Identifying Traffic

--- self quote removed to save space --- I really don't know exactly how this post got here. My guess is it was accidental. You may ask how could you accidentally make a post? That's a valid question. I post on this and the Ubiquiti forums frequently, and on Tom Lawrence's forum to a much lower ext...
by Buckeye
Sat May 06, 2023 1:04 am
Forum: General
Topic: Help Identifying Traffic
Replies: 7
Views: 686

Re: Help Identifying Traffic

You can use sniffer to capture only 7a7a ethertype (The sniffer uses name "MAC protocol") See Mikro Tip MikroTik packet sniffer basics at offset 01:33 You should be able to capture only 7a7a with this setting: Sniff 7a7a ethetype.png Then you should be able to see what mac addresses are in...
by Buckeye
Sat May 06, 2023 12:44 am
Forum: General
Topic: Problems with printer on lan
Replies: 13
Views: 2287

Re: Problems with printer on lan

I just did a google search using Konica bizhub C226i netmask 255.255.252.0 as the search query. The documentation isn't as clear as it could be, but if I understand it, it seems that the first option, Synchronize IP Address assumes that the netmask is /24 or 255.255.255.0 and only allows access from...
by Buckeye
Sat May 06, 2023 12:00 am
Forum: Useful user articles
Topic: NetInstall from the command line via an EL9 VM on macOS Topic is solved
Replies: 7
Views: 12812

Re: NetInstall from the command line via an EL9 VM on macOS Topic is solved

If for some reason one or more are true — that is, you really do have to set a static IP, switch the VM to the 192.168.88.1/24 subnet, and/or use a direct copper connection to make the Windows method work — I'm tempted to say it isn't worth it relative to mine even for folk a-scairt o' the CLI. All...
by Buckeye
Fri May 05, 2023 9:43 am
Forum: General
Topic: Very slow speeds with VLANs
Replies: 7
Views: 2096

Re: Very slow speeds with VLANs

It is easy to tell if other people can see your post. Just log out of the forum, and if you can see your post when you are not logged in, then other people can see it too. I don't have the equipment you have, so made no comment. But since you are wondering if your post was muted and want any feedbac...
by Buckeye
Fri May 05, 2023 7:29 am
Forum: Useful user articles
Topic: NetInstall from the command line via an EL9 VM on macOS Topic is solved
Replies: 7
Views: 12812

Re: NetInstall from the command line via an EL9 VM on macOS Topic is solved

I did try a dumb switch, and it did work, but that led me to the question, "Why?" I quickly tracked it down to the Trusted setting on bridge ports in my CRS328 Thanks for testing it and better, finding the root cause. Like you, I like to know why when things don't behave the way I expect ...
by Buckeye
Fri May 05, 2023 12:48 am
Forum: Useful user articles
Topic: NetInstall from the command line via an EL9 VM on macOS Topic is solved
Replies: 7
Views: 12812

Re: NetInstall from the command line via an EL9 VM on macOS Topic is solved

In your article it says: "The only trick that seems to matter is that you DO have to connect the Ethernet cable from the router straight into the host's copper Ethernet port. You can't put a switch between it and the router, not even a MikroTik brand switch." I am curious if you tried a no...
by Buckeye
Fri May 05, 2023 12:10 am
Forum: General
Topic: Problems with printer on lan
Replies: 13
Views: 2287

Re: Problems with printer on lan

I have a printer with fixed IP 192.168.0.116 Subnet mask 255.255.252.0 and the gateway: 192.168.0.222. Are you 100% sure the netmask on the printer is /22 (255.255.252.0) and not /24 (255.255.255.0)? Because if it was /24, I can see why you would be seeing the symptoms you describe. If you ping the...
by Buckeye
Thu May 04, 2023 4:23 am
Forum: General
Topic: Home network setup with multiple routers/aps, multiple VLANs, multiple WiFi networks and CAPsMAN
Replies: 14
Views: 3532

Re: Home network setup with multiple routers/aps, multiple VLANs, multiple WiFi networks and CAPsMAN

I have to agree with @djmuk, your post (and your other related threads Home network setup advice , VLANs and unmanaged switches ) is more like a Request for Proposal than something that can be easily answered on a forum. My suggestion is to use your "top floor" hAP ac2 as a lab router and ...
by Buckeye
Thu May 04, 2023 2:05 am
Forum: General
Topic: Something NEEDS to be done about the default passwords
Replies: 169
Views: 16582

Re: Something NEEDS to be done about the default passwords

it doesn't matter, in the initial configuration script just put it to nand-only, as it should be done. You have obviously thought this through. I have never needed to deploy MikroTik routers, but it seems that router boot is pretty flexible in what it allows. I did a google search for "MiktroT...
by Buckeye
Wed May 03, 2023 8:03 pm
Forum: General
Topic: Something NEEDS to be done about the default passwords
Replies: 169
Views: 16582

Re: Something NEEDS to be done about the default passwords

Okay, after a little investigation, the help page has been updated: Thanks for fixing the docs. Incorrect documentation is worse than no documentation. Thanks for making the Mikro Tip about FlashFig and all your other Mikro Tips as well. (Edit: Just notice you posted a new one to address the issue ...
by Buckeye
Wed May 03, 2023 2:40 am
Forum: General
Topic: Something NEEDS to be done about the default passwords
Replies: 169
Views: 16582

Re: Something NEEDS to be done about the default passwords

In Mass-config MikroTik with flashfig (what rextended linked above), Druvis shows using "system/routerboard/settings/set boot-device=flash-boot", perhaps because that leaves the router in a permanent "flashfig ready" state, and will probably generate fewer "support calls&quo...
by Buckeye
Tue May 02, 2023 9:35 am
Forum: General
Topic: VLAN Passthrough from WAN port to LAN bridge (specific port) [SOLVED]
Replies: 19
Views: 3042

Re: VLAN Passthrough from WAN port to LAN bridge (specific port) [SOLVED]

Must search here, if anyone has tested the serial connection to Mikrotik with Apple Silicon Mac and new OS.
The Serial > USB adapter cables are available and cheap but I wonder if there will be any driver issues.
It looks like @normis uses an Apple laptop. Maybe he could tell you.
by Buckeye
Tue May 02, 2023 7:46 am
Forum: General
Topic: VLAN Passthrough from WAN port to LAN bridge (specific port) [SOLVED]
Replies: 19
Views: 3042

Re: VLAN Passthrough from WAN port to LAN bridge (specific port) [SOLVED]

I forgot that the RB1100AHx4 has a serial console build in. That's the ultimate "get out of jail free" card, as long as you have an old school DB9 RS232 connector. The picture of the RB100AHx4 appears to have a old "PC" compatible DB9 with male pins, probably configured as DTE. T...
by Buckeye
Tue May 02, 2023 3:09 am
Forum: General
Topic: Vlan with Cisco
Replies: 9
Views: 1445

Re: Vlan with Cisco

I didnt say that the problem is exactly with mikrotik I jest needed help. But why are you asking about how to configure Cisco switches on a MikroTik forum? There are better places to find information about how to configure the Cisco switches. Since Cisco is the "defacto" standard, there i...
by Buckeye
Mon May 01, 2023 4:45 am
Forum: General
Topic: Vlan with Cisco
Replies: 9
Views: 1445

Re: Vlan with Cisco

One more note about vlans on Cisco. I am not a big fan of DTP (auto negotiation of trunking mode). If you search for DTP hacking you will see why. Most of your ports on the switch will normally be access ports and you should explicity set them for access mode. For the others, you should explicitly s...
by Buckeye
Mon May 01, 2023 3:26 am
Forum: General
Topic: Vlan with Cisco
Replies: 9
Views: 1445

Re: Vlan with Cisco

P.S, do I need to create vlan21 on cisco ? Use the non-config mode command: show vlan br It needs to show the vlans you are using. If they don't show up, you skipped Creating the VLAN in the VLAN Database If it shows both 1 and 21, then it should work. But notice how many ports are members of vlan ...
by Buckeye
Mon May 01, 2023 2:24 am
Forum: General
Topic: re-designing home network, how to replace the unifi switch [SOLVED]
Replies: 8
Views: 1326

Re: re-designing home network, how to replace the unifi switch [SOLVED]

Did the USW break, missing some feature you require, or do you just not want to have to configure the switch with the UniFi controller? You should be able to use the USW with the CCR2004-16S+2X, you will just need to use the vlan only mode when configuring the USW. Tom Lawrence (Lawrence Systems) us...
by Buckeye
Sun Apr 30, 2023 11:07 pm
Forum: General
Topic: re-designing home network, how to replace the unifi switch [SOLVED]
Replies: 8
Views: 1326

Re: re-designing home network, how to replace the unifi switch [SOLVED]

Current Home network is handled like this. 1 CCR2004-16S+2X that receives 2 incoming 1G link BGP multi homed .
You must be quite the enthusiast, or are you running a data center in your home?
by Buckeye
Sun Apr 30, 2023 10:52 pm
Forum: General
Topic: Vlan with Cisco
Replies: 9
Views: 1445

Re: Vlan with Cisco

Hint, you need to create "trunk" ports on the C3750 that allow both the untagged vlan (aka "Native vlan") and vlan21. These trunk ports need to be connected to each UAP and to ether5 of your MikroTik.

See Ed's article. He also has other useful vlan info. See his vlans-index.
by Buckeye
Sun Apr 30, 2023 10:34 pm
Forum: General
Topic: Vlan with Cisco
Replies: 9
Views: 1445

Re: Vlan with Cisco

I don't follow your troubleshooting conclusions. You said it was working when you connect the UAP-AC-LR to the MikroTik Router, but the tagged vlan no longer works when you introduce the Cisco 3750. Why do you think the problem is on the MikroTik side instead of the Cisco side? What do you get on th...
by Buckeye
Sun Apr 30, 2023 2:57 am
Forum: General
Topic: VLAN Passthrough from WAN port to LAN bridge (specific port) [SOLVED]
Replies: 19
Views: 3042

Re: VLAN Passthrough from WAN port to LAN bridge (specific port) [SOLVED]

If you haven't started work, and possibly locked yourself out, I would suggest configuring one of the ether ports on a different switch chip to do your configuration from. At a minimum the port you are working on should not be a member of the bridge that is associated with the RTL8367 that ether1-et...
by Buckeye
Sat Apr 29, 2023 1:50 am
Forum: General
Topic: Something NEEDS to be done about the default passwords
Replies: 169
Views: 16582

Re: Something NEEDS to be done about the default passwords

What is the significance of the /204/r4 at the end of the serial number on the label? Is the 204 a date code and r4 a revision level?
by Buckeye
Fri Apr 28, 2023 10:34 pm
Forum: General
Topic: IP routing question
Replies: 6
Views: 962

Re: IP routing question

Steep learning curve? It depends somewhat where you are starting from. For a few routers in one area without route redistribution it is not too bad, but it assumes you understand connected routes, how static routing works, e.g. how routes are chosen, what netmasks are, etc. If you do decide to go t...
by Buckeye
Fri Apr 28, 2023 9:38 pm
Forum: Beginner Basics
Topic: How to have a WAN port without a bridge?
Replies: 7
Views: 1710

Re: How to have a WAN port without a bridge?

There are two things I was trying to indicate, but was not clear about. And here I was complaining that your instructions were not clear, a bit ironic. The primary (but unfortuneately unstated) one is that you are clear about what the the problem is, what the intended solution concept is, and what n...
by Buckeye
Fri Apr 28, 2023 8:00 pm
Forum: General
Topic: VLAN Passthrough from WAN port to LAN bridge (specific port) [SOLVED]
Replies: 19
Views: 3042

Re: VLAN Passthrough from WAN port to LAN bridge (specific port) [SOLVED]

The way I would approach is one bridge. No vlan 4 interface, you don't want the connection to the "routing engine" for the TV vlan. Something like (not tested) (this is "internal wiring" only, firewall, interface lists, etc. not covered here). You will need to add ip addresses to...
by Buckeye
Fri Apr 28, 2023 2:29 am
Forum: General
Topic: Something NEEDS to be done about the default passwords
Replies: 169
Views: 16582

Re: Something NEEDS to be done about the default passwords

False, with flashfig, for example, you can blank admin password and proceed as usual for who have prepared some complex for first setup, or why not send instruction from flashfig to load directly the branding package with default config wanted, and reboot..... and is permanent, also after full rese...
by Buckeye
Thu Apr 27, 2023 11:09 pm
Forum: General
Topic: Something NEEDS to be done about the default passwords
Replies: 169
Views: 16582

Re: Something NEEDS to be done about the default passwords

Just wanted to add, that yes, you can launch Netinstall just by pushing it's button, no need to log in. Also Flashfig is even easier - it is on by default when you first (!) boot your device. For devices with a beeper, this is indicated by a chirping sound. It means you can Fllashfig a device in se...
by Buckeye
Thu Apr 27, 2023 12:49 am
Forum: General
Topic: RB4011iGS+RM with 7.8 unable for longterm downgrade
Replies: 4
Views: 1095

Re: RB4011iGS+RM with 7.8 unable for longterm downgrade

We received a new RB4011 with OS 7.8 pre-installed. Routerboard factory firmware is also 7.8 You should be able to downgrade to whatever the "factory-software" is. If it is 7.8, there must be a new hardware revision that is not compatible with older versions. If you need older versions, y...
by Buckeye
Thu Apr 27, 2023 12:37 am
Forum: General
Topic: How to speed up inter-VLAN routing?
Replies: 8
Views: 1889

Re: How to speed up inter-VLAN routing?

Here is what I was referring to about v7 and vlan-filtering See footnote three at bottom of table (concerning RTL8367) https://help.mikrotik.com/docs/display/ROS/Switch+Chip+Features#SwitchChipFeatures-Introduction 3. Bridge HW vlan-filtering was added in the RouterOS 7.1rc1 (for RTL8367) and 7.1rc5...
by Buckeye
Thu Apr 27, 2023 12:24 am
Forum: RouterBOARD hardware
Topic: Hardware advice home setup
Replies: 4
Views: 2192

Re: Hardware advice home setup

Product code RB962UiGS-5HacT2HnT Architecture MIPSBE CPU QCA9558 CPU core count 1 CPU nominal frequency 720 MHz Switch chip model QCA8337 The hAP AC is slower than the hEX S. You haven't said what the budget is, or how fast the fiber connection will be, or how much the monthly price of fiber is. (If...
by Buckeye
Thu Apr 27, 2023 12:06 am
Forum: General
Topic: How to speed up inter-VLAN routing?
Replies: 8
Views: 1889

Re: How to speed up inter-VLAN routing?

My understanding of inter-vlan (between vlans) means that it is going to be routed. And that's only done by the CPU on the RB4011. So no matter if the vlans are hardware offloaded on not, it won't make much difference to performance. I have a RB4011iGS+ that has been configured with VLANs. On ports ...
by Buckeye
Wed Apr 26, 2023 11:52 pm
Forum: Beginner Basics
Topic: How to have a WAN port without a bridge?
Replies: 7
Views: 1710

Re: How to have a WAN port without a bridge?

You want to remove ether5 from bridge-WAN, don't you? Just go to bridge->port and remove the interface from the bridge-WAN , then delete the bridge-WAN too if you want. That's it! You'd better use Winbox for that. I do think that @anav could make the instructions about how to do this a bit more cle...
by Buckeye
Wed Apr 26, 2023 2:43 am
Forum: Scripting
Topic: send MikroTik Notification via WhatsApp
Replies: 55
Views: 40664

Re: send MikroTik Notification via WhatsApp

added hidden link to one whatsapp apk...
size=1 on text? A very idiot...
You must have younger eyes than I do, or do you have selenium script to detect these?

BTW, why can't the forum software detect and disallow "hidden" links? (and possibly ban the user? especially on a first post).
by Buckeye
Tue Apr 25, 2023 10:20 am
Forum: General
Topic: Issues with Bridge VLAN Filtering setup
Replies: 9
Views: 2891

Re: Issues with Bridge VLAN Filtering setup

Here is another thread you may find interesting.

And this and the post following it are my interpretations (what I would change in @sindy's excellent RouterOS bridge mysteries explained post.
by Buckeye
Mon Apr 24, 2023 11:54 pm
Forum: General
Topic: Issues with Bridge VLAN Filtering setup
Replies: 9
Views: 2891

Re: Issues with Bridge VLAN Filtering setup

Without seeing the whole export, this is only a guess. You didn't add vlan11 to the LAN interface list. I think your original vlan setup looks like it should work. The bridge interface is sending untagged traffic over the "internal trunk link" to the integrated switch ASIC (assuming you ha...
by Buckeye
Mon Apr 24, 2023 10:52 pm
Forum: General
Topic: Something NEEDS to be done about the default passwords
Replies: 169
Views: 16582

Re: Something NEEDS to be done about the default passwords

Passwords are available in CSV format from the distributor accounts.
This seems like it would be a good solution for distributors, but what about a small ISP? And hopefully, the distributors only have the passwords for the routers they bought for resale, i.e. not all routers.
by Buckeye
Mon Apr 24, 2023 10:46 pm
Forum: Beginner Basics
Topic: Bridge interface in OSPF
Replies: 4
Views: 935

Re: Bridge interface in OSPF

I assume you were watching The Network Trips OSPF series? lol how did you know..!!?? yes exactly. The wording "Empty Bridge interface" is exactly what Wilmer called it. And I had just watched that within the last week. BTW, that is a good series in my opinion. There are some assumptions, ...
by Buckeye
Mon Apr 24, 2023 10:22 am
Forum: Beginner Basics
Topic: Behind another router-> how to setup?
Replies: 18
Views: 1518

Re: Behind another router-> how to setup?

Good to hear you got it working again. The CRS306-1G-4S+IN isn't really meant to be used as a router, it is a switch with some router capabilities, and those router capabilities are there primarily for you to manage the switch. You would be much better off using the router in the UDM for inter-vlan ...
by Buckeye
Mon Apr 24, 2023 7:35 am
Forum: Beginner Basics
Topic: Bridge interface in OSPF
Replies: 4
Views: 935

Re: Bridge interface in OSPF

but what its mean to create such empty interface in mikrotik router..? what is the effect on the router itself..? lets forexample suppose that i create 1000 Bridge in the router, does that make scense..? It just creates a virtual interface that isn't tied to any port. And it is an interface that wi...
by Buckeye
Mon Apr 24, 2023 4:59 am
Forum: General
Topic: Something NEEDS to be done about the default passwords
Replies: 169
Views: 16582

Re: Something NEEDS to be done about the default passwords

Hang on a sec. Your plan is to have a mode where someone remote can blank out the configuration and provide a new one, including a new non-empty password, in order to get around a regulation passed to avoid having routers completely taken over by LAN worms? First, this would only affect new routers...
by Buckeye
Mon Apr 24, 2023 4:28 am
Forum: Beginner Basics
Topic: Behind another router-> how to setup?
Replies: 18
Views: 1518

Re: Behind another router-> how to setup?

When the switch is running SwOS, it doesn't even have a place to configure a gateway, as it uses a "simplified" mechanism that does not involve a gateway or network mask. It just swaps the source and destination mac addresses and ip addresses and ports in the L2, L3 and L4 headers. See thi...
by Buckeye
Mon Apr 24, 2023 4:18 am
Forum: Beginner Basics
Topic: Behind another router-> how to setup?
Replies: 18
Views: 1518

Re: Behind another router-> how to setup?

I note you dont mention gateway address As long as you are in the same subnet, the gateway isn't used. It can be set to any value. If network mask is 255.255.255.0 only the first three digits have to match to be on the same network/subnet. 192.168.88.1 and 192.168.88.213 are in the same subnet, so ...
by Buckeye
Mon Apr 24, 2023 2:04 am
Forum: Beginner Basics
Topic: Behind another router-> how to setup?
Replies: 18
Views: 1518

Re: Behind another router-> how to setup?

I would try manually setting your PC to 192.168.88.213 255.255.255.0 and then trying to browse to 192.168.88.1

Do you get a response then?
by Buckeye
Mon Apr 24, 2023 1:01 am
Forum: General
Topic: VLAN Passthrough from WAN port to LAN bridge (specific port) [SOLVED]
Replies: 19
Views: 3042

Re: VLAN Passthrough from WAN port to LAN bridge (specific port) [SOLVED]

In either case if you use a bridge or switch for the WAN connection, be sure you take steps to protect the management to trusted devices (I would not allow access from either vlan you are connecting to the WAN port). I would also use a vlan that you would not normally use for the WAN untagged vlan (...
by Buckeye
Mon Apr 24, 2023 12:56 am
Forum: General
Topic: VLAN Passthrough from WAN port to LAN bridge (specific port) [SOLVED]
Replies: 19
Views: 3042

Re: VLAN Passthrough from WAN port to LAN bridge (specific port) [SOLVED]

Do you have a preference on having to use your ISP App to control the Chromecast or would you rather use the set top box? How much do you want to learn about configuring vlans on the RB1100? If that is a goal then it may be worth pursuing, but if you don't want to learn (it will take a while, in all...
by Buckeye
Mon Apr 24, 2023 12:25 am
Forum: Beginner Basics
Topic: Behind another router-> how to setup?
Replies: 18
Views: 1518

Re: Behind another router-> how to setup?

How does the device show up in WinBoot?

Here are my 3 devices RB260GS (CSS106-5G-1S) and the two RouterOS devices (RB760iGS and RB5009)
WinBox.png
by Buckeye
Mon Apr 24, 2023 12:22 am
Forum: Beginner Basics
Topic: Behind another router-> how to setup?
Replies: 18
Views: 1518

Re: Behind another router-> how to setup?

Did you do the hold reset button before and while applying power method?

https://i.mt.lv/cdn/product_files/CRS30 ... 190756.pdf
by Buckeye
Sun Apr 23, 2023 10:23 pm
Forum: General
Topic: VLAN Passthrough from WAN port to LAN bridge (specific port) [SOLVED]
Replies: 19
Views: 3042

Re: VLAN Passthrough from WAN port to LAN bridge (specific port) [SOLVED]

@anav has a good question about why you need both the "trusted" LAN and the "unfiltered" TV vlan on the same port.
by Buckeye
Sun Apr 23, 2023 10:20 pm
Forum: General
Topic: VLAN Passthrough from WAN port to LAN bridge (specific port) [SOLVED]
Replies: 19
Views: 3042

Re: VLAN Passthrough from WAN port to LAN bridge (specific port) [SOLVED]

I am not sure if the RB1100 supports HW bridging when you are bridging multiple switch chips all in the same bridge. It would seem the CPU would be required for bridging any traffic between the switch chips.

I have only the RB760iGS and RB5009, and both of those have only a single switch ASIC.
by Buckeye
Sun Apr 23, 2023 10:10 pm
Forum: General
Topic: VLAN Passthrough from WAN port to LAN bridge (specific port) [SOLVED]
Replies: 19
Views: 3042

Re: VLAN Passthrough from WAN port to LAN bridge (specific port) [SOLVED]

I dug into Mikrotik Support site's documentation and the ROS packet flow diagram tells me that what I need to do cannot be done in L2. Decapsulation-routing decisions-encapsulation seems to be the way and this brings it to the L3. To keep it on L2 I could of course make a bridge also on WAN side wi...
by Buckeye
Sun Apr 23, 2023 9:41 pm
Forum: Beginner Basics
Topic: Behind another router-> how to setup?
Replies: 18
Views: 1518

Re: Behind another router-> how to setup?

Are you saying you tried the options in https://wiki.mikrotik.com/wiki/SwOS/CRS3xx#Dual_Boot

The only SwOS device I have is the RB260. And it shows up in winbox, but winbox won't connect to it. Use your web browser instead to connect to SwOS.
by Buckeye
Sun Apr 23, 2023 7:28 am
Forum: Beginner Basics
Topic: DHCP leasing to base address (offered, results without success)
Replies: 8
Views: 2602

Re: DHCP leasing to base address (offered, results without success)

/ip address add address=143.X.X.X/24 comment=" " interface= ether1 network=143.x.x.x /ip dhcp-client add comment=defconf interface= ether1 Is it valid to set a static address on an interface that is also a dhcp-client? I have never tried, but I would expect either one or the other. On Ubui...
by Buckeye
Sat Apr 22, 2023 11:59 pm
Forum: Beginner Basics
Topic: Revising VLAN Setup (New Equipment)
Replies: 12
Views: 1315

Re: Revising VLAN Setup (New Equipment)

You have setup the SWITCH in the wrong format............... (one for routers and not for switches). P. SWITCH CHIP VLANS Switch Chip Features - https://help.mikrotik.com/docs/display/ ... p+Features CRS1 / CRS2 -Switches - https://help.mikrotik.com/docs/pages/vi ... =103841835 CRS3 / CRS5 / CCR2 S...
by Buckeye
Sat Apr 22, 2023 8:15 am
Forum: Beginner Basics
Topic: Revising VLAN Setup (New Equipment)
Replies: 12
Views: 1315

Re: Revising VLAN Setup (New Equipment)

What is the what is removing the vlan tags? I assume Intel PROSet when you set a vlan id uses tagged frames when sending and untags them when received? Every port on the except sfp-sfpplus2 (which has pvid=51) has the default pvid=1. If you plug an RJ to SFP module into sfp-sfpplus2 does it get an a...
by Buckeye
Sat Apr 22, 2023 4:03 am
Forum: Beginner Basics
Topic: Revising VLAN Setup (New Equipment)
Replies: 12
Views: 1315

Re: Revising VLAN Setup (New Equipment)

Here is my current config. As it is now, I'm only able to connect to the bridge itself. Can't reach any of the VLANs, so I think that I messed up my filter rules.
How (from what device, connected to what port) are you trying to connect?
by Buckeye
Sat Apr 22, 2023 1:58 am
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 301
Views: 479030

Re: Using RouterOS to VLAN your network

The RB4011 is successfully running 3 VLAN's, getting the proper IP address and network. The HAP AC connects with 1 VLAN (the base). When I try to connect to one of the other WAP on the other VLAN's it does not get a IP address from the router. Using Winbox I can ping the different VLAN addresses on...
by Buckeye
Sat Apr 22, 2023 1:35 am
Forum: Beginner Basics
Topic: Is it mirror ports what I am looking for?
Replies: 14
Views: 2446

Re: Is it mirror ports what I am looking for?

In conclusion ...... Give a new member some slack and try to help him on what he asks and not <<force>> him to what he needs to study in general. I like to learn things when I need them and not read hundreds of pages just in case I ll need something. That is why I came here at first place. To ask a...
by Buckeye
Fri Apr 21, 2023 10:13 pm
Forum: Beginner Basics
Topic: Is it mirror ports what I am looking for?
Replies: 14
Views: 2446

Re: Is it mirror ports what I am looking for?

In addition to @sindy's first post in RouterOS bridge mysteries explained referenced by @mkx, you should read the thread Slow Hex file transfer speed , the discussion of frame-types starts with post #7 and goes through post #18 . I have never gotten any feedback from those posts, so perhaps my inter...
by Buckeye
Fri Apr 21, 2023 10:58 am
Forum: General
Topic: hex poe bridge SLOW
Replies: 5
Views: 535

Re: hex poe bridge SLOW

The only hEX I have is the RB760iG hEX S based on the MediaTek MT7621 SoC. The hEX PoE is based on the QCA8337 switch chip. I think the bridge can be hardware accellerated, but that it does not allow vlan-filtering to be hardware assited. See Hex PoE VLAN setup (are switch and bridge VLAN setups equ...
by Buckeye
Fri Apr 21, 2023 9:51 am
Forum: General
Topic: RB750Gr3 not accessable
Replies: 2
Views: 297

Re: RB750Gr3 not accessable

No guarantees, but perhaps try a different power supply.
by Buckeye
Fri Apr 21, 2023 2:02 am
Forum: General
Topic: Something NEEDS to be done about the default passwords
Replies: 169
Views: 16582

Re: Something NEEDS to be done about the default passwords

https://www.etsi.org/deliver/etsi_ts/103600_103699/103645/01.01.01_60/ts_103645v010101p.pdf Thank you! Those appear to be guidelines from 2019-02. Is this now a requirement? If so, when did it become law? So it oddly doesn't include routers (but it did say non-exhaustive list). Another odd omission...