Community discussions

Search found 94 matches

by ashpri
Wed Oct 02, 2019 6:03 am
Forum: Beginner Basics
Topic: Increase Idle timeout instead of using http/mac-cookie [SOLVED]
Replies: 1
Views: 309

Increase Idle timeout instead of using http/mac-cookie [SOLVED]

My hotspot constantly asks the user to login multiple times a day, even when mac-cookie (or http-cookie) is set to 7 days. I am thinking I can get around the the above issue by disabling mac/http-cookie and increasing idle time (or keepalive timeout) to 7 days. Is there anything I need to watch out ...
by ashpri
Tue Sep 10, 2019 6:24 am
Forum: Beginner Basics
Topic: Slow 5GHz transfer rate
Replies: 2
Views: 528

Re: Slow 5GHz transfer rate

Disclaimer: I am not an expert in this. Look here: https://www.wlanpros.com/mcs-index-charts/, at the 1 Spatial Stream (top) section. Why 1SS? Because the HapACLite has 1 antenna (tx/rx chain) in the 5ghz band. It seems like your channel width setting went from 80mhz (MCS7 325) to 20mhz wide (MCS8 8...
by ashpri
Tue Sep 10, 2019 5:36 am
Forum: Beginner Basics
Topic: Understanding acmin-mac (mtik devices mac changes after reboot)
Replies: 3
Views: 387

Re: Understanding acmin-mac (mtik devices mac changes after reboot)

Thank you for your reply. It seems to be hugely impractical to manually enter the admin-mac for each device in a large network. I must be missing something. How do other admins with a large number of mtik devices monitor their device up/down status reliably. ----- This is an example of my netwatch f...
by ashpri
Mon Sep 09, 2019 10:32 am
Forum: Beginner Basics
Topic: Understanding acmin-mac (mtik devices mac changes after reboot)
Replies: 3
Views: 387

Understanding acmin-mac (mtik devices mac changes after reboot)

I have 20-30 Mikrotik devices in my network, APs and Switches. I use tool>netwatch to monitor their up/down status. The issue is on some (not all) of the devices, from time to time for what seems to be no reason at all, when the AP/Switch reboots, their bridge mac changes and therefore it would get ...
by ashpri
Tue Aug 20, 2019 3:26 am
Forum: Beginner Basics
Topic: CAPSMAN: CAP Setting for Local vs CAPSMAN Forwarding, with vlans
Replies: 3
Views: 469

Re: CAPSMAN: CAP Setting for Local vs CAPSMAN Forwarding, with vlans

If your infrastructure (switch, router) has your vlans already set up on the uplinks to the CAPs you only have to switch to "local-forwarding=yes" in your capsman configuration. The vlan<->port association is done by the CAP on the bridge that you assign in /interface wireless cap (2. question). An...
by ashpri
Sun Aug 18, 2019 5:13 am
Forum: Beginner Basics
Topic: CAPSMAN: CAP Setting for Local vs CAPSMAN Forwarding, with vlans
Replies: 3
Views: 469

CAPSMAN: CAP Setting for Local vs CAPSMAN Forwarding, with vlans

This is how I have my CAPs setup for "CAPSMAN forwarding" scenario. VLAN assignment per SSID is working well. /interface bridge add name=bridge1 /interface vlan add interface=bridge1 name=VL03 vlan-id=3 add interface=bridge1 name=VL05 vlan-id=5 add interface=bridge1 name=VL10 vlan-id=10 /interface b...
by ashpri
Mon Jun 17, 2019 4:16 pm
Forum: Wireless Networking
Topic: Connection Rate Setting
Replies: 0
Views: 323

Connection Rate Setting

I have the following settings on my Unifi APs which has served me well. A Unifi Mesh Pro was stable serving 260 users with this setting, with the default settings it would crash. zz1.png Is the following mikrotik rates similar to the above's 2G section? zz3.png I'm not sure what do to with the HT, V...
by ashpri
Sun Jun 16, 2019 5:57 am
Forum: Wireless Networking
Topic: CAPSMan + freeradius + VLAN per User
Replies: 15
Views: 2189

Re: CAPSMan + freeradius + VLAN per User

I know exactly what's happening now. This is the issue:

zz3.png

If I have 200 CAPs, I have to add all 200 CAP Interfaces manually to the bridge? This doesn't seem like the normal Mikrotik way. I must be missing something.
by ashpri
Sun Jun 16, 2019 5:01 am
Forum: Wireless Networking
Topic: CAPSMan + freeradius + VLAN per User
Replies: 15
Views: 2189

Re: CAPSMan + freeradius + VLAN per User

JACKPOT! With a manually created SSID (Virtual AP), the radius properly authenticates the user and places the user in the right vlan. The only issue is I had to ipconfig/release and /renew when switching between different users in different vlans. In production, this should not be an issue. As I sus...
by ashpri
Sun Jun 16, 2019 3:05 am
Forum: Wireless Networking
Topic: CAPSMan + freeradius + VLAN per User
Replies: 15
Views: 2189

Re: CAPSMan + freeradius + VLAN per User

Thank you for your response Dorian. I will post that data soon. I am not sure this is even a radius issue. I am now testing with Tekradius LT as instructed here https://mum.mikrotik.com/presentations/CN16/presentation_3107_1461137144.pdf. I have bypassed DHCP and placed a static address 192.168.86.1...
by ashpri
Sat Jun 15, 2019 7:26 pm
Forum: Wireless Networking
Topic: CAPSMan + freeradius + VLAN per User
Replies: 15
Views: 2189

Re: CAPSMan + freeradius + VLAN per User

Might it have to do with the fact that the radius server is on vlan86 while the client (as instructed by freeradius) is to be on vlan60? The dhcp server is on the mikrotik router, as is capsman. The client is logging in from a cap. Might a firewall rule (or something) be blocking the dhcp offers fro...
by ashpri
Fri Jun 14, 2019 6:15 pm
Forum: Wireless Networking
Topic: CAPSMan + freeradius + VLAN per User
Replies: 15
Views: 2189

Re: CAPSMan + freeradius + VLAN per User

Reviving an old but relevant thread. I've followed everything in this thread as well as https://forum.mikrotik.com/viewtopic.php?t=51817, https://forum.mikrotik.com/viewtopic.php?t=140239, https://forum.mikrotik.com/viewtopic.php?f=7&t=109431, https://forum.mikrotik.com/viewtopic.php?t=124596, https...
by ashpri
Fri Jun 14, 2019 12:25 pm
Forum: Wireless Networking
Topic: Wi-fi RADIUS Assigned VLAN based on user/password, troubleshooting help
Replies: 5
Views: 524

Re: Wi-fi RADIUS Assigned VLAN based on user/password, troubleshooting help

The setting seems basic enough. There are 2 settings below. The top is WPA2-EAP for radius assigned VLAN, with the DHCP issue. The bottom is WPA2-PSK, with no DHCP issue. Both serving the same vlan. ----- /caps-man configuration add datapath.bridge=bridge1 mode=ap datapath.vlan-mode=use-tag name="RA...
by ashpri
Fri Jun 14, 2019 8:05 am
Forum: Wireless Networking
Topic: Wi-fi RADIUS Assigned VLAN based on user/password, troubleshooting help
Replies: 5
Views: 524

Re: Wi-fi RADIUS Assigned VLAN based on user/password, troubleshooting help

I've discovered the problem isn't freeradius at all.

The error is the client isn't getting proper dhcp lease in the vlan assigned by the radius server. What could I be missing.

zz4.jpg
by ashpri
Thu Jun 13, 2019 1:31 pm
Forum: Wireless Networking
Topic: Wi-fi RADIUS Assigned VLAN based on user/password, troubleshooting help
Replies: 5
Views: 524

Re: Wi-fi RADIUS Assigned VLAN based on user/password, troubleshooting help

I have reviewed that post and others with similar topics before posting this thread. I did not find a solution, but I will go through that post again. I did a test with radlogin (radius test client) from another pc and this is the result: zz1.png Is that response acceptable? I am assuming it is the ...
by ashpri
Thu Jun 13, 2019 9:01 am
Forum: Wireless Networking
Topic: Wi-fi RADIUS Assigned VLAN based on user/password, troubleshooting help
Replies: 5
Views: 524

Wi-fi RADIUS Assigned VLAN based on user/password, troubleshooting help

Goal: Have a single ssid authenticated by radius, with vlans assigned based on username/password. Succeeded: - I've managed to get FreeRADIUS working with my router. My AP is a HAPAC2 (as CAP). - Authentication with freeradius works great. Issue: I cannot get the radius server to assign vlan. I hav...
by ashpri
Wed Jun 12, 2019 5:39 pm
Forum: Wireless Networking
Topic: Radius Assigned VLAN using user manager for wifi users
Replies: 0
Views: 317

Radius Assigned VLAN using user manager for wifi users

Is this possible?

I've searched for some guides and most uses external radius servers.

Thank you
by ashpri
Mon Jun 10, 2019 5:26 am
Forum: Beginner Basics
Topic: CPU % while using RB750Gr3 as vlan enabled switch
Replies: 2
Views: 290

CPU % while using RB750Gr3 as vlan enabled switch

Just relating my experience. I am using a HEX (RB750Gr3) purely as a vlan enabled switch in my production environment. I had a choice to use bridge vlan (no hardware offload) or switch chip vlan (hardware offload). I was concerned that using bridge vlan would max the cpu (and reduce performance). I ...
by ashpri
Wed Jun 05, 2019 4:23 am
Forum: Beginner Basics
Topic: guest wifi + VLAN confusion
Replies: 7
Views: 804

Re: guest wifi + VLAN confusion

This is how I set vlan on my bridge (minus the dhcp and firewall rules, to keep it simple): /interface bridge add name=bridge1 protocol-mode=none vlan-filtering=yes /interface ethernet set [ find default-name=ether1 ] comment="UPLINK - TRUNK" set [ find default-name=ether2 ] comment="DOWNLINK - TRUN...
by ashpri
Tue Jun 04, 2019 9:23 am
Forum: RouterBOARD hardware
Topic: RB750Gr3 - Report and questions
Replies: 112
Views: 33014

Re: RB750Gr3 - Report and questions

I can confirm that as of today, the HEX (RB750GR3) with v6.44.3 cannot yet implement vlan in switch chip (with hardware offloading).

I have a HAPAC2 with switch chip vlan enabled and the same settings does not work on the HEX.
by ashpri
Tue Jun 04, 2019 3:47 am
Forum: Beginner Basics
Topic: Confused with PASSTHROUGH YES/NO in Mangle
Replies: 7
Views: 612

Re: Confused with PASSTHROUGH YES/NO in Mangle

So, if a packet matches a rule early on in the mangle rules BUT................ will also need to be processed again by lets say 10 mangle rules later, then the first rule that packet is involved in MUST have passthrough=yes?? Noted and thanks. The ?? threw me off, thanks for clarifying they were r...
by ashpri
Mon Jun 03, 2019 3:24 am
Forum: Beginner Basics
Topic: Confused with PASSTHROUGH YES/NO in Mangle
Replies: 7
Views: 612

Re: Confused with PASSTHROUGH YES/NO in Mangle

Thank you. I've read and understood all that. The clarification I need is, and I should have been clearer on this, whether the PASSTHROUGH=NO in Packet Marking Rules 5-8 stops Packet Marking Rule 9 from processing. It shouldn't, since Packet Marking Rule 9 is based on a different connection mark tha...
by ashpri
Sat Jun 01, 2019 2:02 am
Forum: Beginner Basics
Topic: Confused with PASSTHROUGH YES/NO in Mangle
Replies: 7
Views: 612

Confused with PASSTHROUGH YES/NO in Mangle

I have been following a guide in the forum as well as on youtube to setup Queue Tree QOS. Everything is working, I just don't quite understand passthrough completely. Aim: 1. To split overall bandwidth to: hotspot (higher priority and bandwidth) and office downloads (lower priority and bandwidth). 2...
by ashpri
Sat Jun 01, 2019 1:03 am
Forum: Beginner Basics
Topic: 6.44.3 not installing
Replies: 2
Views: 354

Re: 6.44.3 not installing

I had a HAPACLITE with this same issue. I had to do a netinstall. A note with netinstall, I had to disable all other ethernet interfaces on my PC (including eth interfaces for virtual machine software), except the one connected to the mtik.
by ashpri
Thu May 30, 2019 3:56 pm
Forum: Beginner Basics
Topic: Do I need the following firewall rules for CAPSMAN? [SOLVED]
Replies: 2
Views: 429

Re: Do I need the following firewall rules for CAPSMAN? [SOLVED]

This is to accept CAP from the same board where runs CAPsMAN.

Ah, that's right. Thank you. Now I remember why I have this rule.
by ashpri
Wed May 29, 2019 3:43 am
Forum: Beginner Basics
Topic: Do I need the following firewall rules for CAPSMAN? [SOLVED]
Replies: 2
Views: 429

Do I need the following firewall rules for CAPSMAN? [SOLVED]

Following some guide in the forum, I ended up with this firewall rule in the process of setting up CAPSMAN (my router is my capsman): /ip firewall filter add action=accept chain=input comment="IN - CAPSMAN Local" dst-address-list=\ "Loop Local" dst-port=5246,5247 protocol=udp src-address-list=\ "Loo...
by ashpri
Wed May 29, 2019 3:25 am
Forum: Beginner Basics
Topic: Are these redundant dns firewall rules?
Replies: 2
Views: 431

Are these redundant dns firewall rules?

I have this rule in my firewall (following a firewall guide): /ip firewall filter add action=accept chain=input comment="IN - Accept DNS Request" dst-port=53 in-interface-list=LAN protocol=tcp add action=accept chain=input comment="IN - Accept DNS Request" dst-port=53 in-interface-list=LAN protocol=...
by ashpri
Tue May 28, 2019 4:01 pm
Forum: Beginner Basics
Topic: Slow throughput (<100Mbps) between 2 Gbit Routers being used as switch
Replies: 4
Views: 398

Re: Slow throughput (<100Mbps) between 2 Gbit Routers being used as switch

So I put the Powerbox Pro (acting as switch) between a CCR1016-12G and a HAPAC2, and ran the bandwidth test again. Simultaneous TCP Tx/Rx yields roughly 320Mbps/320Mbps. HAPAC2 @ 100% CPU, CCR at 10% CPU. Test limited by HAPAC2 CPU. One way (CCR = test source) yields roughly 800Mbps (Rx) and 920Mbps...
by ashpri
Fri May 24, 2019 9:14 am
Forum: Beginner Basics
Topic: Slow throughput (<100Mbps) between 2 Gbit Routers being used as switch
Replies: 4
Views: 398

Re: Slow throughput (<100Mbps) between 2 Gbit Routers being used as switch

I put a PBPro as a switch in-between a HAPAC2 (source) and another PBPro (target). As you mentioned, the PBPro acting as a switch (middle) has low CPU @ 2%. However since the speed test target is another PBPro, its CPU (@ 100%) is limiting the result, whereas the HAPAC2's CPU hovers between 15-25%. ...
by ashpri
Fri May 24, 2019 6:59 am
Forum: Beginner Basics
Topic: Slow throughput (<100Mbps) between 2 Gbit Routers being used as switch
Replies: 4
Views: 398

Slow throughput (<100Mbps) between 2 Gbit Routers being used as switch

This is a repost. I deleted my original post. I thought I made an error in the testing, but I did not. Throughput test between 2 Powerbox Pro routers used as a switch (I plan to use them as outdoor Gbit POE switches). Simple setup (no other config, zero firewall rules): /interface bridge add name=br...
by ashpri
Tue May 21, 2019 11:40 am
Forum: Beginner Basics
Topic: FQDN for Mikrotik update server for hotspot walled garden bypass
Replies: 1
Views: 219

FQDN for Mikrotik update server for hotspot walled garden bypass

What is the FQDN for the mikrotik update server? I would like to make a walled garden bypass for my hotspot, so APs can update themselves without having to be bypassed.

I've added mikrotik.com and download.mikrotik.com. Is this enough?

Thanks.
by ashpri
Mon May 20, 2019 6:13 pm
Forum: Beginner Basics
Topic: Multiple ISP usage question
Replies: 3
Views: 309

Re: Multiple ISP usage question

This is all I did for 2 ISP failover and it seems to work fine. Experts correct me if I am wrong. ISP1 is main, ISP2 is failover. They key is in the Distance set in /ip route. /interface ethernet set [ find default-name=ether1 ] comment="To Switch" set [ find default-name=ether2 ] comment="ISP1" set...
by ashpri
Mon May 20, 2019 5:31 pm
Forum: Beginner Basics
Topic: Local vs Capsman forwarding for CAPs
Replies: 3
Views: 395

Re: Local vs Capsman forwarding for CAPs

You need a bridge with the VLANs on it. It doesn't have to be VLAN-aware, so it is possible to combine CAP with hardware switched ethernet ports. As the CAP is likely to have a single managment IP on one VLAN you don't need any firewall rules on the CAP as all the VLAN encapsulated traffic is passe...
by ashpri
Mon May 20, 2019 5:41 am
Forum: Beginner Basics
Topic: Local vs Capsman forwarding for CAPs
Replies: 3
Views: 395

Local vs Capsman forwarding for CAPs

Are the following true, if local forwarding for caps is enabled? 1. In a wifi network with multiple vlans (internal vlan and guest hotspot vlan), each cap would need to have a vlan enabled bridge and inter-vlan drop rules set on the firewall. 2. For the guest hotspot vlan, I would need to set guest ...
by ashpri
Mon May 20, 2019 3:57 am
Forum: Beginner Basics
Topic: Help with VLAN and separate WLAN's [SOLVED]
Replies: 8
Views: 650

Re: Help with VLAN and separate WLAN's [SOLVED]

Why do you need multiple router boxes? I have one Mtik router in my office with multiple vlans. APs are mikrotik and unifi. Switches are mikrotik and unifi as well.

One vlan for office, one for guest. One cannot see the other once they are segregated via vlan with proper firewall rules.
by ashpri
Sun May 19, 2019 12:33 pm
Forum: Beginner Basics
Topic: VPN into a VLAN (Working, SSTP) [SOLVED]
Replies: 3
Views: 421

Re: VPN into a VLAN (Working, SSTP) [SOLVED]

In addition, instead of PPTP which is old and supposedly insecure, I've managed to utilise SSTP via another acid-reflux-free guide:
http://www.dr0u.com/mikrotik-setup-sstp ... 10-client/
by ashpri
Sun May 19, 2019 7:30 am
Forum: Beginner Basics
Topic: VPN into a VLAN (Working, SSTP) [SOLVED]
Replies: 3
Views: 421

Re: VPN into a VLAN (not working) [SOLVED]

I may be wrong but try enabling "Proxy-Arp" on the interface that the VLAN is attached to.

That did it! Thank you. No acid reflux after all.
by ashpri
Sun May 19, 2019 3:16 am
Forum: Beginner Basics
Topic: VPN into a VLAN (Working, SSTP) [SOLVED]
Replies: 3
Views: 421

VPN into a VLAN (Working, SSTP) [SOLVED]

On my mikrotik router, I have VLAN3 reserved for network device mgmt. Address Pool: 172.16.2.50-172.16.3.254 Since Romon doesn't work in a unifi switch environment, I need to login into the vlan for network devices, to manage my mikrotik switches and APs in the office, remotely. My steps in creating...
by ashpri
Sun May 19, 2019 2:24 am
Forum: Beginner Basics
Topic: Use router as switch (switch chip), bridge needed? [SOLVED]
Replies: 6
Views: 651

Re: Use router as switch (switch chip), bridge needed? [SOLVED]

Configure as a "hybrid" port with VLAN98 untagged and the other VLANs tagged, see https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#VLAN_Example_2_.28Trunk_and_Hybrid_Ports.29 . Note this is only possible on gigabit switch chips (QCA8337, Atheros8327). Be aware that management for UniFi de...
by ashpri
Sun May 19, 2019 2:06 am
Forum: Beginner Basics
Topic: Use router as switch (switch chip), bridge needed? [SOLVED]
Replies: 6
Views: 651

Re: Use router as switch (switch chip), bridge needed? [SOLVED]

Thank you for the link. That seems to work in the lab, although I have not tested every permutation of possible real condition. This is that I did, as a guide for others. To summarise, what I am trying to do is use a HAPAC2 and POWERBOX-PRO as a VLAN enabled switch, using the speed of switch chip, b...
by ashpri
Thu May 16, 2019 5:05 pm
Forum: Beginner Basics
Topic: Use router as switch (switch chip), bridge needed? [SOLVED]
Replies: 6
Views: 651

Use router as switch (switch chip), bridge needed? [SOLVED]

I am using a HAPAC2 (Atheros 8327 switch chip) purely as a switch, in a VLAN environment. The reason I am using the switch chip, correct me if I am wrong, is my understanding that enabling vlans on the bridge will disable hardware offloading and will reduce the throughput of the HAPAC2 as a switch s...
by ashpri
Thu May 09, 2019 4:36 pm
Forum: Beginner Basics
Topic: HAP AC LITE will not update firmware from 6.43.4 to 6.44.3 (or any other fw)
Replies: 2
Views: 323

Re: HAP AC LITE will not update firmware from 6.43.4 to 6.44.3 (or any other fw)

Is there something in log? It's not flash ("HDD") size, if it was, it wouldn't be possible to upgrade any of these new 16MB device. Upgrade on these uses RAM. I will check the log thanks. I didn't think to look there. I did a netinstall at the end. This was also frought with issues until I: (1) Dis...
by ashpri
Wed May 08, 2019 6:21 pm
Forum: Beginner Basics
Topic: HAP AC LITE will not update firmware from 6.43.4 to 6.44.3 (or any other fw)
Replies: 2
Views: 323

HAP AC LITE will not update firmware from 6.43.4 to 6.44.3 (or any other fw)

My router cannot update from 6.43.4 to 6.44.3 I've done a check for update, the new firmware downloaded and the unit rebooted, it comes back to 6.43.4 after reboot (instead of updating to 6.44.3). I've reset the unit to no-default-config, including manually downloading the npk file and uploading it ...
by ashpri
Mon May 06, 2019 5:10 pm
Forum: Beginner Basics
Topic: ROS Level 4 hotspot active user
Replies: 3
Views: 244

Re: ROS Level 4 hotspot active user

When it reaches the user limit, I can think of 3 possibilities:
(1) prevent new logins, or
(2) drop the oldest logged in, or
(3) drop the oldest and inactive logged in (unlikely but I would be pleasantly surprised if it behaves this way)
by ashpri
Mon May 06, 2019 4:46 pm
Forum: Beginner Basics
Topic: ROS Level 4 hotspot active user
Replies: 3
Views: 244

ROS Level 4 hotspot active user

ROS Level 4 License limits the hotspot active user to 200.

My organisation can have up to 300 active users, however at any time only less than 100 has active rx/tx traffic.

What is mikrotik's algorithm if you exceed the active user limit for the license level. Who gets dropped first.
by ashpri
Mon May 06, 2019 9:43 am
Forum: Beginner Basics
Topic: DHCP Server conflict (same address pool)
Replies: 4
Views: 454

Re: DHCP Server conflict (same address pool)

Thank you, I've fixed it. I forgot to add an address for the VLAN interface, which prompted the DHCP server error. I'm basically trying to merge an old hotspot network running on an old bridge, with a flat network, connected to ether3 on the router, to a vlan on a new bridge, connected to ether2 on ...
by ashpri
Sun May 05, 2019 6:06 am
Forum: Beginner Basics
Topic: DHCP Server conflict (same address pool)
Replies: 4
Views: 454

Re: DHCP Server conflict (same address pool)

Thank you for the follow up. ether1: WAN ether2: new LAN (vlan split between office and hotspot), bridge2 ether3: old hotspot lan (flat network), bridge1 I would like to merge the old hotspot lan running on ether3 to the new network on ether2. The new hotspot on ether2 has a different subnet than th...
by ashpri
Sat May 04, 2019 8:50 am
Forum: Beginner Basics
Topic: DHCP Server conflict (same address pool)
Replies: 4
Views: 454

DHCP Server conflict (same address pool)

See the following image:

zz1.jpg

The DHCP server "VL98 DHCP" gives a redline error on start. No error message pops up in the log.
Could it be because it shares the same address pool as the DHCP Server called "dhcp1"?
by ashpri
Tue Feb 19, 2019 4:02 pm
Forum: Beginner Basics
Topic: Does EOIP need both ends to be visible [SOLVED]
Replies: 1
Views: 242

Does EOIP need both ends to be visible [SOLVED]

I will be testing site to site EOIP, however one side is behind a NAT and I can't get my isp to port forward to the mikrotik.

Is EOIP possible in this scenario?
by ashpri
Tue Feb 19, 2019 4:47 am
Forum: Beginner Basics
Topic: set up vlan with switch chip [SOLVED]
Replies: 20
Views: 1649

Re: set up vlan with switch chip [SOLVED]

This is what I did on my HAPAC2 VLAN config using switch chip (not bridge). As I understand it, if I use vlans using bridge, I believe it disables hardware offloading to the switch chip, and therefore may reduce performance. I would like to use the HAPAC2 only as a switch therefore I set the vlan on...
by ashpri
Thu Feb 14, 2019 12:41 pm
Forum: Beginner Basics
Topic: ROMON Troubleshooting [SOLVED]
Replies: 3
Views: 407

Re: ROMON Troubleshooting [SOLVED]

That means 3 replies are received per each request. 0 reply per each request = 100% loss 1 reply per each request = 0% loss 2 replies per each request = -100% loss 3 replies per each request = -200% loss I know the number like this does not make sense, however, there is no other way to summarize pa...
by ashpri
Thu Feb 14, 2019 2:16 am
Forum: Beginner Basics
Topic: ROMON Troubleshooting [SOLVED]
Replies: 3
Views: 407

Re: ROMON Troubleshooting [SOLVED]

Anyone? No one has ever had issues with not seeing devices in ROMON? Researching further, it seems to be related to this thread https://forum.mikrotik.com/viewtopic.php?t=99208 And this thread in the ub forums https://community.ubnt.com/t5/EdgeSwitch/ES-24-250W-and-Mikrotik-RoMON-failure/td-p/131397...
by ashpri
Wed Feb 06, 2019 9:45 am
Forum: Beginner Basics
Topic: ROMON Troubleshooting [SOLVED]
Replies: 3
Views: 407

ROMON Troubleshooting [SOLVED]

I have 2 kinds of MTIK devices behind my main MTIK router. 1. MTIK device that is in the default VLAN, ROMON works. 2. MTIK device that is in VLAN 03, ROMON does not work. For device #2, mac-ping from TOOLS > ROMON results in timeout, but mac-ping from IP > NEIGHBORS works but shows a -200% packet l...
by ashpri
Sun Dec 23, 2018 1:50 am
Forum: Beginner Basics
Topic: Automatic update of ROS packages, Routerboard then Reboot
Replies: 1
Views: 483

Automatic update of ROS packages, Routerboard then Reboot

I have this script to auto-update the ROS packages, then auto-update Routerboard FW and finally do a reboot. Based on https://www.youtube.com/watch?v=3zYBvRxp_lg and the wiki. ---------- /system scheduler add interval=1d name="Check for Update" on-event="/system package update\r\ \ncheck-for-updates...
by ashpri
Fri Dec 21, 2018 12:26 pm
Forum: Beginner Basics
Topic: CAPSMAN vs Unifi Controller (user review)
Replies: 2
Views: 1272

CAPSMAN vs Unifi Controller (user review)

We have both mikrotik and unifi APs in the organisation. We have been using unifi APs much longer. We've only been using capsman for a week or so. Simple observations: 1. If we need to mesh APs, we use unifi. Unifi can adopt an AP wirelessly and they will automatically mesh and provision. Configurin...
by ashpri
Tue Dec 11, 2018 6:12 am
Forum: Beginner Basics
Topic: Mikrotik PT(M)P tx/rx low speed. Best Practice.
Replies: 0
Views: 250

Mikrotik PT(M)P tx/rx low speed. Best Practice.

I have several HAP-AC2 and CAP-AC around the house to repeat wifi signals. I am separating the radios. 2ghz is for user connections, 5ghz is for the inter-AP backbone. I am trying to understand why TX and RX rates differ for the same AP and how I can improve their connection rates. See the following...
by ashpri
Mon Dec 10, 2018 3:31 pm
Forum: Beginner Basics
Topic: Failed connecting LAN device via wireless [SOLVED]
Replies: 2
Views: 327

Re: Failed connecting LAN device via wireless [SOLVED]

Use mode station-bridge for the client router. If you're running CAPsMAN on the main router, then you should go for station-pseudobridge as CAPsMAN unfortunately doesn't support the MikroTik-proprietary bridge extensions. -Chris I am using CAPSMAN on the main Router-A to provision its built-in 2G a...
by ashpri
Mon Dec 10, 2018 1:03 pm
Forum: Beginner Basics
Topic: Failed connecting LAN device via wireless [SOLVED]
Replies: 2
Views: 327

Failed connecting LAN device via wireless [SOLVED]

Hello all. I have a simple problem. I have looked at many guides. I must be missing something simple somewhere. From what I am reading, connecting a LAN device (in another room) to an existing network with wifi (all mikrotik), is as simple as activating the WLAN interface on STATION mode and connect...
by ashpri
Sun Dec 02, 2018 6:07 pm
Forum: Beginner Basics
Topic: Deploy and manage PTMP endpoints via CAPSMAN
Replies: 0
Views: 270

Deploy and manage PTMP endpoints via CAPSMAN

Is it possible to (1) initial-deploy and (2) manage the endpoint of a PTMP link (WAP AC 2 & WAP AC 3 in the following image) via CAPSMAN?


zz1.png

Thank you.
by ashpri
Thu Nov 29, 2018 2:34 pm
Forum: Beginner Basics
Topic: Hotspot doesn't work when attached to slave member of bridge (VLAN)
Replies: 1
Views: 342

Re: Hotspot doesn't work when attached to slave member of bridge (VLAN)

I found the problem. If I disable "Use IP Firewall For VLAN", everything works as it should. Reading https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge, "use-ip-firewall-for-vlan" is described thus : Send bridged VLAN traffic to also be processed by IP/Firewall. This property is required in case...
by ashpri
Thu Nov 29, 2018 8:57 am
Forum: Beginner Basics
Topic: Hotspot doesn't work when attached to slave member of bridge (VLAN)
Replies: 1
Views: 342

Hotspot doesn't work when attached to slave member of bridge (VLAN)

Hi guys, I have bridge1 with many vlans, one of which is the guest VLAN. I created a hotspot and tagged it to the guest VLAN interface. zz1.png When clients connect to SSID with VLAN99, they get the IP Address just fine, so I know the DHCP server works. When Hotspot is disabled, clients can access t...
by ashpri
Mon Nov 26, 2018 4:39 am
Forum: Beginner Basics
Topic: Why use user manager over hotspot
Replies: 1
Views: 230

Why use user manager over hotspot

I am testing Mikrotik's hotspot feature. So far I foresee that all our organisation's needs are served by hotspot without having to use user-manager. The biggest advantage of user manager, that I can see, is splitting up mikrotik administration (winbox) and hotspot-user administration (web-browser),...
by ashpri
Mon Nov 26, 2018 4:01 am
Forum: Beginner Basics
Topic: Hotspot logic: MAC login vs ip binding [SOLVED]
Replies: 2
Views: 345

Re: Hotspot logic: MAC login vs ip binding [SOLVED]

If the device does not touch port 80 (http), then MAC login will not work. If opening a web browser for the device to connect is not an issue, then it is up to preference.

I see. Thank you.

What is Mikrotik's suggested best practice?
by ashpri
Sun Nov 25, 2018 4:16 pm
Forum: Beginner Basics
Topic: Hotspot logic: MAC login vs ip binding [SOLVED]
Replies: 2
Views: 345

Hotspot logic: MAC login vs ip binding [SOLVED]

Hypothetical case: I have 10 devices which need to access the internet without having to authenticate to the hotspot.

Should I set these 10 devices to login as MAC-based user or use ip-binding (bypass).
by ashpri
Sun Nov 25, 2018 10:12 am
Forum: The User Manager
Topic: Radius Server is not responding with Hotspot
Replies: 15
Views: 29046

Re: Radius Server is not responding with Hotspot

So, I was having this problem for the last couple days.. Its true, that the UM works if you use the public interface address, however, mine was a DHCP client address, and would have been complicated to manage. TLDR; I needed an accept rule to make the 127.0.0.1 UM host work locally. /ip firewall fi...
by ashpri
Fri Nov 02, 2018 4:00 am
Forum: Beginner Basics
Topic: Mangle. Where do you draw the line between connection and packet marks
Replies: 1
Views: 412

Mangle. Where do you draw the line between connection and packet marks

Following online guides, in mangle, I have: 1. Guest vlan download connection mark 2. Office vlan download connection mark 3. Upload connection mark for all vlans 4. After those connection marks, there are the corresponding packet marks. 5. Then more packet marks prioriting browsing, youtube, downlo...
by ashpri
Fri Oct 26, 2018 6:30 am
Forum: General
Topic: HotSpot/Vlan/DHCP Issues
Replies: 14
Views: 1996

Re: HotSpot/Vlan/DHCP Issues

Hello Anyone else experience is this as well? I am, with Hap AC Lite on ROS 6.43.4. The router is connected to an office switch and a public area switch (both Unifi US-24-250W devices). The 5 APs are all Unifi. 1 Native mgmt vlan and 7 tagged vlans. I have tried: 1. Making sure admin mac is enabled...
by ashpri
Wed Oct 24, 2018 3:52 am
Forum: Beginner Basics
Topic: Bandwidth Management (Queue Tree) for Office and Hotspot.
Replies: 1
Views: 739

Re: Bandwidth Management (Queue Tree) for Office and Hotspot.

This is the mangle rule for those curious. https://i.imgur.com/3CA2E5X.png Observed oddities: Since I don't need the upload children in the Q-Tree, I disabled mangle rules AU2,3,4,5 (look in comments). When I do this, packet marks for youtube (HD3 & OD3) do not work (for both office and hotspot), th...
by ashpri
Wed Oct 24, 2018 3:34 am
Forum: Beginner Basics
Topic: Bandwidth Management (Queue Tree) for Office and Hotspot.
Replies: 1
Views: 739

Bandwidth Management (Queue Tree) for Office and Hotspot.

This is the goal https://i.imgur.com/wcmNLI8l.png Is this the correct Queue tree implementation to achieve the goal? https://i.imgur.com/5V16CsVl.png Questions, comments: 1. I've disabled the child items to upload, since uploads never reach the max limit of 100mbps, so a simple PCQ of all upload tra...
by ashpri
Tue Oct 23, 2018 3:38 am
Forum: Beginner Basics
Topic: Slow Ethernet
Replies: 5
Views: 1229

Re: Slow Ethernet

by ashpri
Mon Oct 22, 2018 5:54 pm
Forum: Beginner Basics
Topic: Slow Ethernet
Replies: 5
Views: 1229

Re: Slow Ethernet

Thoughts:
1. If you used Mtik's prebuilt configuration, what mode did you pick.
2. The link to your ISP's router is plugged into ether1 (the wan port in your config) in your Mtik?
by ashpri
Mon Oct 22, 2018 4:44 pm
Forum: Beginner Basics
Topic: Is my mangle rule correct (it seems to mostly work)
Replies: 0
Views: 360

Is my mangle rule correct (it seems to mostly work)

I followed this youtube guide https://www.youtube.com/watch?v=3zJrNOUDNrc, and others, and resulted in this mangle rule: /ip firewall mangle "Connection marking and packet marking for overall downloads" add action=mark-connection chain=forward in-interface-list=WAN new-connection-mark=client.dw.con ...
by ashpri
Mon Oct 22, 2018 4:29 pm
Forum: Beginner Basics
Topic: Slow Ethernet
Replies: 5
Views: 1229

Re: Slow Ethernet

I am new to Mtik as well. I will take a chance at helping you identify your issue.

If you go to Bridge > Port, click on each ether interface, and see whether hardware offload is checked.

2018-10-22 21_25_14-Window.png

Can you post your bridge port and interface list.
by ashpri
Mon Oct 22, 2018 3:19 pm
Forum: General
Topic: How to choose router (which cpu/ram) for hotel [SOLVED]
Replies: 9
Views: 1072

Re: How to choose router (which cpu/ram) for hotel [SOLVED]

Would the RB1100AHx4 be also sufficient for a 300mbps Uplink? If you go to its page, pick Test Results and you will see the throughput. https://mikrotik.com/product/rb1100ahx4#fndtn-testresults I've attached it here to ease your search. zz1.png I don't quite know how to translate this to my scenari...
by ashpri
Mon Oct 22, 2018 2:57 pm
Forum: General
Topic: How to choose router (which cpu/ram) for hotel [SOLVED]
Replies: 9
Views: 1072

Re: How to choose router (which cpu/ram) for hotel [SOLVED]

I suggest RB1100AHx4, almost same hardware than RB4011, redundant PSU and RouterOS license level 6. You are right. After upgrading ROS level 5 to 6 in the RB4011, it will cost more than the RB1100AHx4, and does not come with redundant PSU. I was going to order the RB4011 tomorrow, your advice is ti...
by ashpri
Mon Oct 22, 2018 4:27 am
Forum: Beginner Basics
Topic: Simple Port Forwarding Question [SOLVED]
Replies: 1
Views: 440

Simple Port Forwarding Question [SOLVED]

I have a port forwarding rule set as per the left image. It works fine.

Is there a security risk in blanking the "Dst Address" field? The ip address of ether2-wan is currently static, I would like to make it dynamic.

zz3.png
by ashpri
Sun Oct 21, 2018 2:47 am
Forum: General
Topic: How to choose router (which cpu/ram) for hotel [SOLVED]
Replies: 9
Views: 1072

Re: How to choose router (which cpu/ram) for hotel [SOLVED]

RB4011 for you! Thank you. My experience with Mtik is only a week. It looks like the winbox interface and ROS code is the same across all devices. The code sections (so far) that will be part of my deployment include interface, bridge, vlan, dhcp server, firewall, nat, mangle, queue trees. I am tes...
by ashpri
Sat Oct 20, 2018 12:01 pm
Forum: Beginner Basics
Topic: What is discover mactel mac-winbox line, in interface list member [SOLVED]
Replies: 2
Views: 1231

Re: What is discover mactel mac-winbox line, in interface list member [SOLVED]

1. If I remember correctly, on blank config all of this is allowed on all static interfaces, which is not very good for security. 2. But I strongly advise to have neighbour discovery and mac-winbox configured at least for one of the LAN ports - to have an emergency access to the router on L2 in cas...
by ashpri
Sat Oct 20, 2018 10:13 am
Forum: General
Topic: Mass Managing Mikrotik
Replies: 11
Views: 2047

Re: Mass Managing Mikrotik

I am not aware of any "product" that will manage a large network of devices. I am thinking of publishing my system, but I haven't gotten around to developing a web interface for it yet. It currently runs/updates via the command line on the virtual machine that it resides on. In my limited experienc...
by ashpri
Sat Oct 20, 2018 9:07 am
Forum: Beginner Basics
Topic: What is discover mactel mac-winbox line, in interface list member [SOLVED]
Replies: 2
Views: 1231

What is discover mactel mac-winbox line, in interface list member [SOLVED]

What is the significance of the following lines. It was there by default from ROS configured as dual-band home AP. /interface list member add interface="wlan1 - 2.4g" list=discover add interface="wlan2 - 5g" list=discover add interface=ether2 list=discover add interface=ether3 list=discover add inte...
by ashpri
Sat Oct 20, 2018 6:31 am
Forum: General
Topic: How to choose router (which cpu/ram) for hotel [SOLVED]
Replies: 9
Views: 1072

Re: How to choose router (which cpu/ram) for hotel [SOLVED]

I've been reading that QOS and Firewall consume the most CPU. What about RAM? Source: viewtopic.php?f=2&t=93518&hilit=ram Just to add: 1. I foresee my firewall rules to be simple. 2. There will be no (or very little, less than 10) VPN connections inbound. 3. We are not running any servers in-house t...
by ashpri
Sat Oct 20, 2018 6:30 am
Forum: General
Topic: How to choose router (which cpu/ram) for hotel [SOLVED]
Replies: 9
Views: 1072

How to choose router (which cpu/ram) for hotel [SOLVED]

I've searched the forum for choosing the right router but I am still unclear. My condition: 1. I am deploying for a hotel of 200 rooms. 2. 5-ethernet interfaces on the router is sufficient (2 WAN (Main and Redundant) & 1 LAN). 3. Internet bandwidth is 100mbps (75 for guests, 25 for office). Commerci...
by ashpri
Thu Oct 18, 2018 4:21 am
Forum: Beginner Basics
Topic: WAN NAT Bridge and VLAN yes/no
Replies: 14
Views: 1940

Re: WAN NAT Bridge and VLAN yes/no

all examples here work with ONE bridge? https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#VLAN_Example_.231_.28Trunk_and_Access_Ports.29 is there a simple "rule" when more than one bridge is neded? Correct me if I am wrong, you shouldn't ever need more than one bridge (when it comes to setting...
by ashpri
Wed Oct 17, 2018 4:42 pm
Forum: General
Topic: Sofware VLAN/Bridge on RuterOS explained.
Replies: 59
Views: 16612

Re: Sofware VLAN/Bridge on RuterOS explained.

What a great thread. I hope my revival of it is relevant. I am failing in trying to set the new way of vlan bridging. I have followed your guide and this https://wiki.mikrotik.com/wiki/Manual:CAPsMAN_with_VLANs (v6.41+ way of vlan bridging). The problem is this code. /ip dhcp-server add address-pool...
by ashpri
Wed Oct 17, 2018 1:10 pm
Forum: Beginner Basics
Topic: WAN NAT Bridge and VLAN yes/no
Replies: 14
Views: 1940

Re: WAN NAT Bridge and VLAN yes/no

1. everey bridge is a separated sub-net, an there is per default no communication possible between this sub-nets and the firewall makes the communication possible.. or is it the other way round the firewall blocks the communication (with "drop all" or somthing similar?) 2. "bridge vlan filtering" t...
by ashpri
Wed Oct 17, 2018 1:56 am
Forum: Beginner Basics
Topic: WAN NAT Bridge and VLAN yes/no
Replies: 14
Views: 1940

Re: WAN NAT Bridge and VLAN yes/no

I don't know if this helps you. I am new to mikrotik. I got 5 vlans (me (yes I deserve my own vlan), family, kids, office, guest) working over a root ap (hap-ac2) running capsman and one cap (cap-ac). I followed this guide (https://www.youtube.com/watch?v=1ZJ-pM89N7o) to set up vlans and dhcp server...
by ashpri
Tue Oct 16, 2018 5:42 pm
Forum: Beginner Basics
Topic: Capsman Cap client unable to ping one another
Replies: 2
Views: 392

Re: Capsman Cap client unable to ping one another

Seems that in the provision for cap AC “Client to client forwarding” is set to “no”.

Problem solved. When I first received my Mikrotik I feel like I married a router with a thousand check-boxes and dropdown-lists. I knew one of those would make her happy, I just don't know which one. Thanks
by ashpri
Tue Oct 16, 2018 4:44 pm
Forum: Beginner Basics
Topic: Capsman Cap client unable to ping one another
Replies: 2
Views: 392

Capsman Cap client unable to ping one another

This is what I'm getting in my cap-ac. A able to ping B (and vice versa) A able to ping C (and vice versa) A, B & C able to ping HAP-AC2 and CAP-AC B cannot ping C (and vice versa). The message is "destination host unreachable" 2018-10-16 21_39_07-Book1 - Excel.png If A, B & C are clients of HAP-AC2...
by ashpri
Mon Oct 15, 2018 5:35 am
Forum: Beginner Basics
Topic: Capsman backbone over wifi working
Replies: 0
Views: 252

Capsman backbone over wifi working

I've been wondering this since I learned about capsman in mikrotik (my mikrotik experience has only been 2 days). Gateway/1st AP/capsman = hap-ac2 Repeater/cap = cap-ac I setup the cap-ac 5ghz-wlan in station mode (as a client of the hap-ac2) as the backbone link. Gave the 5ghz-wlan interface 88.2 a...
by ashpri
Mon Oct 15, 2018 2:06 am
Forum: Beginner Basics
Topic: How to setup repeater for wlan with multiple virtual ssid/vlans
Replies: 3
Views: 655

Re: How to setup repeater for wlan with multiple virtual ssid/vlans

Not in repeater mode, that works only for one SSID. You could trunk the traffic together over the Wifi link with VLAN and then separate on the repeater into the subnets with their SSID. It will then look as if the SSID are "repeated". It is basically two AP with each having same SSID and linked tog...
by ashpri
Mon Oct 15, 2018 1:55 am
Forum: Beginner Basics
Topic: Firewall works but doesn't feel right
Replies: 3
Views: 482

Re: Firewall works but doesn't feel right

Bridges involved?

Here is my bridge and port. Physical ports on the hap ac2 (eth1-5) are on default setting (on default lan 88.x). ether1 is WAN.

Image

Thank you
by ashpri
Sun Oct 14, 2018 3:02 pm
Forum: Beginner Basics
Topic: How to setup repeater for wlan with multiple virtual ssid/vlans
Replies: 3
Views: 655

How to setup repeater for wlan with multiple virtual ssid/vlans

I have multiple ssids setup on my 2.4ghz radio (guest, family, kids, office), each with its own subnet and in its own vlan. I've successfully setup the repeater using the "setup repeater" button on the 2nd AP, however I can only repeat a single ssid, and whichever ssid I choose does not get the ip a...
by ashpri
Sun Oct 14, 2018 8:29 am
Forum: Beginner Basics
Topic: Firewall works but doesn't feel right
Replies: 3
Views: 482

Firewall works but doesn't feel right

This is my first day with Mikrotik (hap ac2). So I followed this guide (https://www.youtube.com/watch?v=1ZJ-pM89N7o) and created several wifi VLANS (SSIDs: Family, Kids, Guest, Office, Staff). Each SSID has their own separate 192.168. address and dhcp server. Each VLAN only has 1 subnet. I want isol...