Community discussions

MikroTik App

Search found 716 matches

by mutluit
Tue Jul 07, 2020 12:40 am
Forum: General
Topic: Performance Problem ?
Replies: 4
Views: 667

Re: Performance Problem ?

Is your 10G interface listed under WAN? (/interface list member print)
Without seeing your config settings nobody really can help. One needs to see the settings of the involved interfaces, incl. all the involved IPs, as well the route table etc.
by mutluit
Tue Jul 07, 2020 12:36 am
Forum: General
Topic: export tool bug inquiry
Replies: 3
Views: 500

Re: export tool bug inquiry

In the export tools there appears to be a bug in the Interfaces section. Some of the ports that were set for faster speeds than 100mbps get set to 100mbps. Is that something that has already been reported and is being looked into? Which device and which firmware version? Can the interface handle fa...
by mutluit
Sun Jul 05, 2020 2:35 pm
Forum: Scripting
Topic: Extracting last SMS number [SOLVED]
Replies: 6
Views: 1019

Re: Extracting last SMS number [SOLVED]

More research suggests /tool sms inbox get $i phone doesn't use the index so using my count - 1 method won't work . However `/tool sms inbox find` still returns nothing Try this: :global lastIx ([:len /tool sms inbox] - 1) :global lastNum [/tool sms inbox get number=$lastIx phone] :put $lastNum ......
by mutluit
Sun Jul 05, 2020 3:35 am
Forum: Scripting
Topic: Extracting last SMS number [SOLVED]
Replies: 6
Views: 1019

Re: Extracting last SMS number [SOLVED]

More research suggests /tool sms inbox get $i phone doesn't use the index so using my count - 1 method won't work . However `/tool sms inbox find` still returns nothing Try this: :global lastIx (:len [/tool sms inbox] - 1) :global lastNum [/tool sms inbox get number=$lastIx phone] :put $lastNum ......
by mutluit
Sun Jul 05, 2020 2:34 am
Forum: Beginner Basics
Topic: Basic bandwidth limiting
Replies: 7
Views: 1104

Re: Basic bandwidth limiting

The following CLI command limits both upload and download to 1Mbps for clients in LAN 192.168.128.0/24 behind ether3: /queue simple add name=myRateLimiting target=192.168.128.0/24 max-limit=1M/1M dst=ether3 with "print" you can see it with the other fields it has, for example: print Flags: X - disab...
by mutluit
Sun Jul 05, 2020 1:36 am
Forum: Beginner Basics
Topic: Use Hosting ip to my server for home Solutions?
Replies: 1
Views: 269

Re: Use Hosting ip to my server for home Solutions?

Is this for just a few select TCP/UDP ports, or do you rather want redirect/forward much more traffic to your home server(s)? If your home IP(s) is/are really static then that's an advantage, but then one wonders why you need the IPs from the hoster? Because you could just enter your static home IP ...
by mutluit
Sun Jul 05, 2020 1:17 am
Forum: Beginner Basics
Topic: All SFP+ traffic is routed across 1Gb ethernet
Replies: 1
Views: 289

Re: All SFP+ traffic is routed across 1Gb ethernet

Check your routes on that device ( /ip route print ).

Best is to issue the following command, and then download the file (export-hs.rsc) and post its content:
/export file=export-hs hide-sensitive
by mutluit
Sun Jul 05, 2020 12:45 am
Forum: General
Topic: Inbound SMS run script pass number [SOLVED]
Replies: 7
Views: 1143

Re: Inbound SMS run script pass number [SOLVED]

See https://shop.duxtel.com.au/article_info.php?articles_id=25 It says: RouterOS lists such modems as serial port that appears in '/port print' listing. The following command can be issued to send SMS: /tool sms send port=port dst-smsc=smsc message=message Example: /tool sms send port=usb3 "04XXXXXX...
by mutluit
Sat Jul 04, 2020 6:22 pm
Forum: General
Topic: User restricted to serial login
Replies: 2
Views: 468

Re: User restricted to serial login

I'm looking to create a user that can only login via the serial interface. (console port) I thought about setting its allowed address to 0.0.0.0/32. That should at least prohibit any IP connection attemps, right? Would this still allow MAC connections? We'll probably disable that, so that's fine. I...
by mutluit
Sat Jul 04, 2020 3:32 pm
Forum: General
Topic: Inbound SMS run script pass number [SOLVED]
Replies: 7
Views: 1143

Re: Inbound SMS run script pass number [SOLVED]

I'm trying to write a script so when the Mikrotik receives an SMS it runs the script, gathers some information from the Mikrotik, and then sends an SMS back to the number that sent the request. Is there any way to pass the phone number of the incoming message to the script so it can be used within ...
by mutluit
Sat Jul 04, 2020 3:14 pm
Forum: General
Topic: Weird perfomance! [SOLVED]
Replies: 8
Views: 1390

Re: Weird perfomance! [SOLVED]

For CRS3xx the docs say that currently HW Offloading is effective only on one bridge.
Not sure whether this applies to your CRS model(s) as well, so check the docs.
by mutluit
Fri Jul 03, 2020 11:43 pm
Forum: General
Topic: Hacking attempt from AVM WAN router to hosts in LAN ? [SOLVED]
Replies: 2
Views: 639

Re: Hacking attempt from AVM WAN router to hosts in LAN ? [SOLVED]

The AVM Fritz devices use a check on port 80 to see if a PC has a web server running to show it in its web interface: The FRITZ!Box uses TCP port 80 to check regularly whether computers or other devices connected to the FRITZ!Box offer web services accessible over HTTP, such as a user interface. Th...
by mutluit
Fri Jul 03, 2020 10:57 pm
Forum: General
Topic: Hacking attempt from AVM WAN router to hosts in LAN ? [SOLVED]
Replies: 2
Views: 639

Hacking attempt from AVM WAN router to hosts in LAN ? [SOLVED]

Hi, network security analysts, what do you make up of this? : I've activated logging for the default firewall rule that says in its comment field "defconf: drop all from WAN not DSTNATed". And in the log I find the following very suspicious entries. For orientation: the WAN router is an AVM router w...
by mutluit
Fri Jul 03, 2020 4:06 am
Forum: Beginner Basics
Topic: What stops me from reaching the web interface?
Replies: 1
Views: 325

Re: What stops me from reaching the web interface?

You should post the output of:
/ip export hide-sensitive
by mutluit
Fri Jul 03, 2020 3:55 am
Forum: Beginner Basics
Topic: IP conflict on WAN interface
Replies: 1
Views: 188

Re: IP conflict on WAN interface

Check this:
https://wiki.mikrotik.com/wiki/Manual:Interface/PPPoE
"It is advised not to use static IP addresses or DHCP on the same interfaces as PPPoE for obvious security reasons."

verify with this:
/ip address print

or in GUI under IP / Addresses
by mutluit
Fri Jul 03, 2020 3:19 am
Forum: General
Topic: Port mode access on crs3xx ether type 0x88a8
Replies: 1
Views: 408

Re: Port mode access on crs3xx ether type 0x88a8

Hello everyone, I'm trying to put a crs328 port in access mode and it doesn't work when ether type = 0x88a8 could someone help me with this situation? What is not working, what are the symptoms, which firmware and version? I myself don't use VLAN, but IMO it should be something like this: :global m...
by mutluit
Wed Jul 01, 2020 10:31 pm
Forum: General
Topic: Traffic Generator - Big vs small packets (strange) results
Replies: 7
Views: 1027

Re: Traffic Generator - Big vs small packets (strange) results

@dadox, can you briefly describe what is so puzzling for you?

Update: ok, got it: you mean the difference between Tx and Rx packets in the 2nd table...
Easy explanation: some "TCP resend" packets occured, that's IMO normal.
Similar differences are present also in 1st table, maybe you overlooked them.
by mutluit
Wed Jul 01, 2020 9:12 pm
Forum: General
Topic: Traffic generated by the switch doesn't respect VRF segregation
Replies: 4
Views: 753

Re: Traffic generated by the switch doesn't respect VRF segregation

The whole point of a VRF is to have separate routing tables, different virtual routing instances. I am not fully into mikrotik way of thinking but this behavior sounds more like a bug to be honest... And my understanding is that this happens since router OS doesn't really use different routing tabl...
by mutluit
Wed Jul 01, 2020 8:08 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 62
Views: 7143

Re: LAN to LAN forwarding [SOLVED]

Glad to see that @Diresta's problem of transparent port-forwarding within the same LAN has been solved by using iptables' port-forwarding function on the old server(s). It would have functioned also centrally on a Linux router with iptables as shown in posting #41 https://forum.mikrotik.com/viewtopi...
by mutluit
Tue Jun 30, 2020 11:13 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 62
Views: 7143

Re: LAN to LAN forwarding [SOLVED]

No, it doesn't work here, though I haven't tried other ROS versions. Such a task should be doable centrally on a router or switch with just a few firewall rules, nothing more. You OTOH seem to say one needs to reconfigure the net. Never mind, I've seen enough and experienced enough. You clearly sti...
by mutluit
Tue Jun 30, 2020 10:56 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 62
Views: 7143

Re: LAN to LAN forwarding [SOLVED]

@xvo, FYI: here's a solution using iptables on a linux router with a bridge. It reads "Port forwarding between bridged interfaces": https://askubuntu.com/questions/720207/port-forwarding-between-bridged-interfaces It's a similar problem-case: moving services from one host to another host in same LA...
by mutluit
Tue Jun 30, 2020 9:33 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 62
Views: 7143

Re: LAN to LAN forwarding [SOLVED]

But you have to admit that it's not satisfactorily if it works as wished/intended from other LANs and WAN, but not from inside the same LAN. One has to question why ROS can't handle that, don't you agree? I would classify that as a bug, or at least as a shortcoming or as a missing capability... And...
by mutluit
Tue Jun 30, 2020 7:29 pm
Forum: Beginner Basics
Topic: Improve my set-up (extend WiFi and host a server)
Replies: 2
Views: 383

Re: Improve my set-up (extend WiFi and host a server)

ISP ===> Router in the attic ===> hAP lite 1 (office) ===> hAP lite 2 (living room) 2. Make the web server on my main PC accessible from outside (I want to host a Foundry VTT game) For the above you need to find out the port number(s) (0 to 65535) and their protocol (tcp, udp etc.) [ie. in your cas...
by mutluit
Tue Jun 30, 2020 6:54 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 62
Views: 7143

Re: LAN to LAN forwarding [SOLVED]

The problem with RouterOS seems to be that port-forwarding using DNAT/SNAT within the same LAN seems not possible. In my experiments here so far port-forwarding in ROS works only for clients from other LANs as well from the WAN side, but not from inside the same LAN. It's not a RouterOS problem. Ac...
by mutluit
Tue Jun 30, 2020 12:22 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 62
Views: 7143

Re: LAN to LAN forwarding [SOLVED]

@Diresta, which RouterOS version does your device have? And can you post the output of this: /interface export hide-sensitive And: together with the new servers will also the old servers be online at the same time during the transition phase? If yes, and if your servers do have iptables, then you co...
by mutluit
Tue Jun 30, 2020 6:36 am
Forum: General
Topic: Intermittent timeout when trying to ssh or webfig into CRS328
Replies: 1
Views: 305

Re: Intermittent timeout when trying to ssh or webfig into CRS328

Take 1 of the ports out of the bridge, give it an IP/mask (for example 192.168.128.254/24, ie. creating a new LAN 192.168.128.0/24), and attach a host to that port, and try ssh & webfig from that host to that new gateway IP (ie. login to the CRS via this new gateway IP). Of course with the above exa...
by mutluit
Tue Jun 30, 2020 3:40 am
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 62
Views: 7143

Re: LAN to LAN forwarding [SOLVED]

I don't exactly understand what is that thing, that is working, for you have only one host on your LAN in your example. And even if there is a thing, and it is actually working, how is it supposed to continue to work after you put two hosts on one dumb switch?! These two hosts will connect to each ...
by mutluit
Tue Jun 30, 2020 3:29 am
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 62
Views: 7143

Re: LAN to LAN forwarding [SOLVED]

@Sob, your solution is very interesting, but unfortunately in current beta8 it hangs in a loop so that the router reboots endlessly :-( I suspect it is the masquerade rule with src-addr and dst-addr equal. But if it works well with stable/long-term version than it could indeed be the solution for th...
by mutluit
Mon Jun 29, 2020 9:52 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 62
Views: 7143

Re: LAN to LAN forwarding [SOLVED]

@xvo, "that thing..." gave me a good laugh. Might be a solution, but that will mean all clients will have to be reconfigured to point to WAN address and not internal address of server Hmm. yes, you are right. But I think that problem is solvable too. I'll check. Update: I now tested using a dumb sw...
by mutluit
Mon Jun 29, 2020 9:34 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 62
Views: 7143

Re: LAN to LAN forwarding [SOLVED]

I don't exactly understand what is that thing, that is working, for you have only one host on your LAN in your example. And even if there is a thing, and it is actually working, how is it supposed to continue to work after you put two hosts on one dumb switch?! These two hosts will connect to each ...
by mutluit
Mon Jun 29, 2020 9:02 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 62
Views: 7143

Re: LAN to LAN forwarding [SOLVED]

ATTN everybody! I now have found a solution. Will post it shortly. But it works only if no bridge is configured in RouterOS :-( Could be a ROS bug... Then how exactly did you create a Layer 2 Broadcast Domain if you configured no Bridge ? Just assign an IP to the router port, for example ether2: 19...
by mutluit
Mon Jun 29, 2020 8:38 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 62
Views: 7143

Re: LAN to LAN forwarding [SOLVED]

Ok, here's the said solution: Solution for port forwarding for both WAN-to-LAN as well LAN-to-LAN (incl. inside same LAN): On my router (hAP ac^2 with RouterOS 7.0beta8) with no NAT (ie. as 2nd router) now the following solution works: IP of WAN interface (ether1): 192.168.254.253/24 IP of ether2 (i...
by mutluit
Mon Jun 29, 2020 8:23 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 62
Views: 7143

Re: LAN to LAN forwarding [SOLVED]

ATTN everybody!
I now have found a solution. Will post it shortly. But it works only if no bridge is configured in RouterOS :-( Could be a ROS bug...
by mutluit
Mon Jun 29, 2020 6:21 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 62
Views: 7143

Re: LAN to LAN forwarding [SOLVED]

@sindy, I'm looking for a solution for port-forwarding from lanIP1:port to lanIP2:port within the same LAN. Is there a solution available for this (simpler) problem?
Ie. connections to 192.168.88.12:8512/tcp shall be (on the router) redirected to 192.168.88.11:8511
by mutluit
Mon Jun 29, 2020 5:12 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 62
Views: 7143

Re: LAN to LAN forwarding [SOLVED]

Port forwarding from wanIP:port to lanIP:port works.
What the OP wants to know is how to port forward from internal lanIP1:port to internal lanIP2:port .
Me too interested in the solution. :-)
by mutluit
Mon Jun 29, 2020 4:10 pm
Forum: RouterOS v7 BETA
Topic: beta8 bug: "scp" hangs
Replies: 0
Views: 195

beta8 bug: "scp" hangs

"ssh" login to the router (hAP ac^2) is ok. But copying a file from PC to the router using the "scp" command starts the copying, but it then hangs. On the router a temporary file name is created with size 0 bytes. (15:00:53) xxx@yyy:~/tmp$ scp -p22 test.rsc admin@192.168.127.254:/ admin@192.168.127....
by mutluit
Mon Jun 29, 2020 3:29 pm
Forum: Beginner Basics
Topic: Export / Import
Replies: 3
Views: 975

Re: Export / Import

Via GUI you can do System/ResetConfiguration and specify the import script in the field "Run After Reset". But see also this thread for possible problems: https://forum.mikrotik.com/viewtopic.php?t=123656 Thank you very much - I will try in the next days :-) Regarding " problems " ... I will put th...
by mutluit
Sun Jun 28, 2020 6:28 pm
Forum: Beginner Basics
Topic: Export / Import
Replies: 3
Views: 975

Re: Export / Import

I exported all data from my wAP #1, adapted the data inside the file and now I would like to import the data in my wAP #2 ... Is there any possibility to do it through the current/running setup on #2 or is there some need to reset #2 first and then to import afterwards ? Via GUI you can do System/R...
by mutluit
Sun Jun 28, 2020 5:52 pm
Forum: General
Topic: What network cards does RouterOS support?
Replies: 1
Views: 478

Re: What network cards does RouterOS support?

Good afternoon. Please tell me the link to the page where i can find a list of network cards for stable work with RouterOS. What max speed do you mean? Is this intended for server or workstation/PC? For upto Gigabit Ethernet I think you can take any of the common ones in the market (HP, IBM, Dell, ...
by mutluit
Sun Jun 28, 2020 5:05 pm
Forum: General
Topic: Strange problem with Internet
Replies: 8
Views: 1324

Re: Strange problem with Internet

I couldn't find whats wrong and my ISP told us that everything is fine with the line. Asking around someone suggested me to use the following rules on mikrotik chain=forward action=change-mss new-mss=1418 passthrough=yes tcp-flags=syn protocol=tcp out-interface=ether11-wan1 tcp-mss=1419-65535 log=n...
by mutluit
Sun Jun 28, 2020 4:28 pm
Forum: General
Topic: Gateway issue?
Replies: 4
Views: 764

Re: Gateway issue?

How many LANs do you have? Gateway functions upwards, not downwards. Since according to your drawing your server is connected to both routers, then it already must use two gateways. Just specify the IP of the router interface/bridge for each respective interface on the server. Normally such two rout...
by mutluit
Sun Jun 28, 2020 4:18 pm
Forum: RouterOS v7 BETA
Topic: beta5 bug: '/export verbose' hangs [SOLVED]
Replies: 10
Views: 2584

Re: beta5 bug: '/export verbose' hangs [SOLVED]

This error seems to be fixed in later versions. In 7.0beta8 it's not present (tested on router hAP ac^2).
by mutluit
Sun Jun 28, 2020 4:07 pm
Forum: RouterOS v7 BETA
Topic: beta5 bug: http Webfig downloading .txt files not working
Replies: 1
Views: 668

Re: beta5 bug: http Webfig downloading .txt files not working

That same error is present also in 7.0beta8 (tested on router hAP ac^2).
by mutluit
Sun Jun 28, 2020 3:55 pm
Forum: RouterOS v7 BETA
Topic: beta8 bug: ACL redirect-to-cpu breaks bridge
Replies: 1
Views: 439

Re: beta8 bug: ACL redirect-to-cpu breaks bridge

Error persist even when explicitly specifying "new-dst-ports=switch1-cpu", ie.:
add comment="redirect_all_traffic_to_cpu" ports=$myPorts redirect-to-cpu=yes switch=switch1 new-dst-ports=switch1-cpu disabled=no
by mutluit
Sat Jun 27, 2020 9:13 pm
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3136

Re: ACL firewall problem (missing L2 EtherType)

Only now, as looking for the difference between your setup and mine, I have noticed that you are setting the rules using ROS 7.0beta8 - it can only be seen in the export header, you don't mention that anywhere in the text. On long-term (6.45.9), I've just tried the following rules: [me@MyTik] > int...
by mutluit
Sat Jun 27, 2020 9:06 pm
Forum: RouterOS v7 BETA
Topic: beta8 bug: ACL redirect-to-cpu breaks bridge
Replies: 1
Views: 439

beta8 bug: ACL redirect-to-cpu breaks bridge

If one has as one of the very first switch ACL rules a "redirect-to-cpu all traffic" then the bridge stops functioning. Let's say bridge has own IP and has the members ether1, ether2, ether3, ether4. Then the following ACL rule will make the bridge inoperational so that attached PCs cannot ping each...
by mutluit
Sat Jun 27, 2020 4:28 am
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3136

Re: ACL firewall problem (missing L2 EtherType)

More insights:

Besides mac-protocol=arp also mac-protocol=ip has problems, as it does not map to its EtherType 0x0800.

This means one needs both the name variant as well the number variant when adding these rules into the rule table.

About the reasons one can only speculate...
by mutluit
Sat Jun 27, 2020 3:26 am
Forum: General
Topic: bridge filter CRS326
Replies: 6
Views: 1229

Re: bridge filter CRS326

Yes switch rules with new-dst-ports="" are working (packets successfully dropped), but this is ingress packets. I'm trying to block output packets. You can do that via src-address (IP address/Mask) Ie. via the mask you can cover all your LAN... See the ACL table in one of the links I had posted.
by mutluit
Sat Jun 27, 2020 2:43 am
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3136

Re: ACL firewall problem (missing L2 EtherType)

Open a ticket and send tech support a 'supout' along with your documented evidence and hopefully they will respond. My question is ,,,, will this 'bug' affect normal usage? I already did enough, made them aware of a severe bug and even located the bug. I'm not going to make any more. Enough is enou...
by mutluit
Sat Jun 27, 2020 2:19 am
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3136

Re: ACL firewall problem (missing L2 EtherType)

New insights: Both are necessary! arp via name as well via number. Then this can only mean that "arp by name" uses another essential (undocumented) EtherType. Otherwise it does not make any sense, IMO. Unless there is a memory problem caused by "double free'ing", "use after free", or overwriting oth...
by mutluit
Sat Jun 27, 2020 1:05 am
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3136

Re: ACL firewall problem (missing L2 EtherType)

@sindy, I understand, it's really mysterious. Here's another mystery to add to the confusion list: in my print list the rule #41 gets interpreted as another "802.2" though it has a totally different EthType (0x0008). The correct "802.2" has EtherType 0x0004 (rule #19 and #2 in the print list). I thi...
by mutluit
Sat Jun 27, 2020 12:49 am
Forum: General
Topic: L2 ACL on NetPower 16P via ROS
Replies: 2
Views: 591

Re: L2 ACL on NetPower 16P via ROS

@kowal, take a look at this thread as there are some ACL examples:
viewtopic.php?f=2&t=162887
by mutluit
Fri Jun 26, 2020 11:47 pm
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3136

Re: ACL firewall problem (missing L2 EtherType)

It's strange. On my hAP ac² (running 6.45.9), if I add the rule with mac-protocol=0x0806 , it is both print ed and export ed with mac-protocol=arp , i.e. the conversion seems to work both ways. So I don't get why in your case there is a difference in behaviour when you add it as "arp" and when you ...
by mutluit
Fri Jun 26, 2020 11:00 pm
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3136

Re: ACL firewall problem (missing L2 EtherType)

ATTN MikroTik developers & ACL users: After some lengthy testing, the error finally has been found! : The endian-error is with the mac-protocol "arp" (EtherType 0x0806). It can be an endian-error or a simple parsing error from the string "arp" to the right EthType numeric value, maybe mixed up with...
by mutluit
Fri Jun 26, 2020 8:24 pm
Forum: General
Topic: Problem 10G CRS317-1G-16S+RM and SFP+ direct attach cable (S+DA0001, S+DA0003)
Replies: 10
Views: 1832

Re: Problem 10G CRS317-1G-16S+RM and SFP+ direct attach cable (S+DA0001, S+DA0003)

@nickkk, I can just suggest this: use iperf on PCs for performance tests, not the integrated traffic generators on the routers or switches as this creates additional CPU load which then is missing for the device itself to perform its routing/switching job. And: do the test first w/o VLAN, and on a s...
by mutluit
Fri Jun 26, 2020 7:22 pm
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3136

Re: ACL firewall problem (missing L2 EtherType)

A wild guess here... there is a bug in the bridge filter rules, where the bytes in the 16-bit values of the ethertype field in the 802.1Q headers are swapped on some CPU architectures, and arm (which is the architecture of hAP ac²) is one of these whereas mipsbe is not affected by that; however, th...
by mutluit
Fri Jun 26, 2020 4:57 pm
Forum: General
Topic: Problem 10G CRS317-1G-16S+RM and SFP+ direct attach cable (S+DA0001, S+DA0003)
Replies: 10
Views: 1832

Re: Problem 10G CRS317-1G-16S+RM and SFP+ direct attach cable (S+DA0001, S+DA0003)

Is it true that two CRS317-1G-16S+RM devices are involved in this test? Why not testing on a single device first? If really two are involved, then they better should be in their own LAN (ie. IP should be something like 192.168.88.1/24 and the other should be 192.168.89.1/24). At least for the testin...
by mutluit
Fri Jun 26, 2020 2:54 pm
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3136

Re: ACL firewall problem (missing L2 EtherType)

It seems there is a bug in ACL b/c I did use the "Tools / PacketSniffer" tool over interfaces=all, but all the mac-protocols it lists are already present in the ACL... Packet Sniffer runs on CPU, not hardware. You will need to temporarily disable hardware acceleration on the port(s) that you wish t...
by mutluit
Fri Jun 26, 2020 1:17 am
Forum: General
Topic: i need help: Lost Vlan Admin HELP HELP
Replies: 1
Views: 798

Re: i need help: Lost Vlan Admin HELP HELP

If multiple ports of it have IPs, just try to connect to each IP via Winbox or Webfig.
If possible also by connecting the PC to the right port, if the above step don't work.
by mutluit
Fri Jun 26, 2020 12:58 am
Forum: RouterOS v7 BETA
Topic: beta8: possible bug in switch rules (ACL)
Replies: 0
Views: 425

beta8: possible bug in switch rules (ACL)

I encountered a possible bug with ACL usage: it is not possible to use a final rule which says "block all other". Details here:
viewtopic.php?f=2&t=162887
by mutluit
Thu Jun 25, 2020 11:58 pm
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3136

Re: ACL firewall problem (missing L2 EtherType)

I've now added all documented mac-protocols I could find in the wiki pages, ie. mac-protocol (802.2 | arp | homeplug-av | ip | ipv6 | ipx | lldp | loop-protect | mpls-multicast | mpls-unicast | packing-compr | packing-simple | pppoe | pppoe-discovery | rarp | service-vlan | vlan) And the behavior is...
by mutluit
Thu Jun 25, 2020 9:08 pm
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3136

ACL firewall problem (missing L2 EtherType)

On router hAP ac^2 I monitored the traffic using "Tools / Torch" in the GUI and added all observed L2 EtherTypes via ACL into the rule table of the switch-chip. But as soon as I activate the last rule by setting disabled=no then Internet stops functioning. What other EtherType is highly likely missi...
by mutluit
Thu Jun 25, 2020 6:31 pm
Forum: Beginner Basics
Topic: NAT WAN to subnet [SOLVED]
Replies: 9
Views: 1621

Re: NAT WAN to subnet [SOLVED]

On the router you can assign multiple networks to a port, yes. But how do you attach the end-user devices to that port? Surely you must be using a switch for this. But then the switch cannot handle such 2 networks, unless it's a managed switch and you can tell the switch the same that you told the r...
by mutluit
Thu Jun 25, 2020 5:40 pm
Forum: Beginner Basics
Topic: NAT WAN to subnet [SOLVED]
Replies: 9
Views: 1621

Re: NAT WAN to subnet [SOLVED]

It is simply impossible to have two /24 IP networks on the same router port (that's IP routing 101, first lesson :-)). Either use a separate router port for each, or change the mask from /24 to /21 for example, and attach a dumb switch to the router port and attach the end-user devices to that switc...
by mutluit
Thu Jun 25, 2020 2:54 pm
Forum: RouterOS v7 BETA
Topic: beta8 says "#error exporting /routing/policy/selection"
Replies: 0
Views: 317

beta8 says "#error exporting /routing/policy/selection"

When doing /export in beta8 then there is a section in the output that says "#error exporting /routing/policy/selection"
Device: hAP ac^2 (ARM) upgraded from 6.47 to 7.0beta8 (development)
by mutluit
Thu Jun 25, 2020 4:29 am
Forum: Beginner Basics
Topic: Pool Segment diferent WAN
Replies: 7
Views: 1062

Re: Pool Segment diferent WAN

In posting #2 I gave you the answer: IP / DHCP Server in GUI.
by mutluit
Thu Jun 25, 2020 12:39 am
Forum: Beginner Basics
Topic: NAT WAN to subnet [SOLVED]
Replies: 9
Views: 1621

Re: NAT WAN to subnet [SOLVED]

It should work. But your device (PC?) must be attached to the right interface on the router... Can you ping the 192.168.5.21 from the router? From other PC? And what does "/ip route print" say? And what does "/interface print" say? It seems the problem is rooted in the fact that you renamed the inte...
by mutluit
Thu Jun 25, 2020 12:27 am
Forum: Beginner Basics
Topic: Pool Segment diferent WAN
Replies: 7
Views: 1062

Re: Pool Segment diferent WAN

Sorry im mean ISP(Internet providers).
Still doesn't make much sense in this context.
Are you meaning your own DHCP server for your LAN, or do you rather mean DHCP server of your ISP?
by mutluit
Wed Jun 24, 2020 11:48 pm
Forum: Beginner Basics
Topic: Pool Segment diferent WAN
Replies: 7
Views: 1062

Re: Pool Segment diferent WAN

Should be possible. Define 2 pools in IP/Pools, and assign each in /IP/DHCP Server to the wanted interface.
I don't know what you mean by "WAN", normally the interfaces "etherX" and "wlanX" are used for such assignments.
by mutluit
Wed Jun 24, 2020 11:12 pm
Forum: General
Topic: Ping Issue!
Replies: 13
Views: 1996

Re: Ping Issue!

For your PC the gateway should be the LAN IP of your router (or if the router interface where your PC is attached to has an own IP, then that IP).
For your router the gateway should be the IP of its uplink.
by mutluit
Wed Jun 24, 2020 10:02 pm
Forum: General
Topic: bridge filter CRS326
Replies: 6
Views: 1229

Re: bridge filter CRS326

@gklpnd, I have no experience with VRRP. I would suggest to experiment with a simple "normal" TCP traffic to/from a TCP port, for example by using an iperf server and a client. Then you will have gained more experience and can apply it to VRRP etc. All ACL rules have an implicit "action=accept", exc...
by mutluit
Wed Jun 24, 2020 7:31 pm
Forum: General
Topic: bridge filter CRS326
Replies: 6
Views: 1229

Re: bridge filter CRS326

FYI: the traffic of ports that have Hardware Offloading enabled, does not pass thru the normal firewall locations ("CPU firewall"), but is handled within the " switch chip " using ACL rules . Ie. you should use ACL rules. There is also a rule which allows to " redirect-to-cpu " : then the packet wil...
by mutluit
Tue Jun 23, 2020 10:20 pm
Forum: Wireless Networking
Topic: I WANT TO CONNECT 2 MIKROTIK AP RBwAP2nND WIRELESSLY AND DISTRIBUE WIRELESS INTERNET CONNECTIVITY FROM 2 nd AP RBw AP2
Replies: 10
Views: 1259

Re: I WANT TO CONNECT 2 MIKROTIK AP RBwAP2nND WIRELESSLY AND DISTRIBUE WIRELESS INTERNET CONNECTIVITY FROM 2 nd AP RBw

the router os is station mode. when I connect the router os by cable on my PC the ethernet light of the pc and the router lights up but winbox does not detect the router. the pc address is 192.168.88.6 through the browser I can't. What is the gateway IP address on your PC? It should be the IP of yo...
by mutluit
Tue Jun 23, 2020 5:22 pm
Forum: General
Topic: Different DHCP pools on ports from 192.168.1.0/21 network?
Replies: 4
Views: 576

Re: Different DHCP pools on ports from 192.168.1.0/21 network?

@CarsonGrey, it can work as you described. You just need to set a route from ether6 to the bridge, ie. make an entry under "/ip route",
or simply add ether6 to the bridge as well.
by mutluit
Tue Jun 23, 2020 4:53 pm
Forum: Wireless Networking
Topic: I WANT TO CONNECT 2 MIKROTIK AP RBwAP2nND WIRELESSLY AND DISTRIBUE WIRELESS INTERNET CONNECTIVITY FROM 2 nd AP RBw AP2
Replies: 10
Views: 1259

Re: I WANT TO CONNECT 2 MIKROTIK AP RBwAP2nND WIRELESSLY AND DISTRIBUE WIRELESS INTERNET CONNECTIVITY FROM 2 nd AP RBw

ok but currently my biggest problem is that i can't reset the access point. I tried several times the manual reset but it does not pass I also can't get access to the access point interface. is there a solution to recover my equipment? Have you also changed the IP of your PC to 192.168.88.9 for exa...
by mutluit
Tue Jun 23, 2020 2:00 pm
Forum: Wireless Networking
Topic: I WANT TO CONNECT 2 MIKROTIK AP RBwAP2nND WIRELESSLY AND DISTRIBUE WIRELESS INTERNET CONNECTIVITY FROM 2 nd AP RBw AP2
Replies: 10
Views: 1259

Re: I WANT TO CONNECT 2 MIKROTIK AP RBwAP2nND WIRELESSLY AND DISTRIBUE WIRELESS INTERNET CONNECTIVITY FROM 2 nd AP RBw

I want to extend the wifi in an area where there is no cable so I want to connect AP in station mode repeat the wifi Then you need to add AP functionality to the station as said via a virtual wlan3. But I think you cannot use the same SSID, you need to use a different one. But, it is also possible ...
by mutluit
Tue Jun 23, 2020 1:40 pm
Forum: Wireless Networking
Topic: I WANT TO CONNECT 2 MIKROTIK AP RBwAP2nND WIRELESSLY AND DISTRIBUE WIRELESS INTERNET CONNECTIVITY FROM 2 nd AP RBw AP2
Replies: 10
Views: 1259

Re: I WANT TO CONNECT 2 MIKROTIK AP RBwAP2nND WIRELESSLY AND DISTRIBUE WIRELESS INTERNET CONNECTIVITY FROM 2 nd AP RBw

It is possible to use both devices as APs, even if the 2nd is in station mode. To be able to wirelessly connect to the station, you need to add a virtual wlan (ie. wlan3) as "ap bridge" to it and configure it accordingly (with own SSID etc). Why do you need to operate 2 wireless routers in such a co...
by mutluit
Tue Jun 23, 2020 1:28 pm
Forum: Beginner Basics
Topic: Using WLAN1 as WAN
Replies: 6
Views: 967

Re: Using WLAN1 as WAN

@ge0rgi, as @CZFan also said, you can create or change the WAN port yourself in GUI / Interfaces / Interface List. Doing it in CLI is possible too.
by mutluit
Tue Jun 23, 2020 1:05 pm
Forum: Beginner Basics
Topic: Can I do one wlan nat & other wlan as AP for Airplay discovery
Replies: 10
Views: 1502

Re: Can I do one wlan nat & other wlan as AP for Airplay discovery

There are multiple solutions possible: 1) Give the WAN port an IP from the same subnet (192.168.0.y), disable NAT on hAP, connect the WAN port (usually ether1) of hAP to the other router, configure wlan so that it gives via DHCP IP addresses from the same subnet 192.168.0.z 2) Set the hAP into Bridg...
by mutluit
Mon Jun 22, 2020 9:17 pm
Forum: General
Topic: Forwarding UDP traffic to 2 destinations
Replies: 2
Views: 509

Re: Forwarding UDP traffic to 2 destinations

Normal iptables has a TEE target with which it is possible. Don't know if that's available also in RouterOS, but there was a discussion 4 years ago: https://forum.mikrotik.com/viewtopic.php?t=105166 Some MT router and switch models can mirror user-defined packets via ACL rules, but don't know whethe...
by mutluit
Mon Jun 22, 2020 8:04 pm
Forum: General
Topic: View configured static routes
Replies: 11
Views: 1575

Re: View configured static routes

Thanks - yes I am aware of the possibility to display this information using the CLI. My question was - is it possible using winbox?
Yes, IP / Routes in GUI. Those with "S" are the static ones, which also can be edited.
by mutluit
Mon Jun 22, 2020 7:45 pm
Forum: Wireless Networking
Topic: hAP ac^2: Q on passwords and wireless speed
Replies: 18
Views: 2136

Re: hAP ac^2: Q on passwords and wireless speed

Names I use are like
wAP1_2, wAP1_5, wAP2_2, wAP2_5, hAP_2, hAP2_5 for the 2.4 and 5 GHz radio's.
@bpwl, where do you define that? Is it the "Name" field on the wlan interface page, or a different field?
by mutluit
Mon Jun 22, 2020 7:23 pm
Forum: Wireless Networking
Topic: station bridge
Replies: 0
Views: 339

station bridge

I can connect via wlan to an AP by setting the wlan to "station" or "station bridge" mode (both devices are MT hAP ac^2 with RouterOS v6.47). I wonder what the difference between "station" and "station bridge" is. What are the capabilities of these modes? When should one use which mode? Is there a d...
by mutluit
Mon Jun 22, 2020 7:07 pm
Forum: Beginner Basics
Topic: Can I do one wlan nat & other wlan as AP for Airplay discovery
Replies: 10
Views: 1502

Re: Can I do one wlan nat & other wlan as AP for Airplay discovery

Sorry, but I still don't think anybody understands what you really want to achieve.
Your question should be short and precise.
Sorry, I can't help as I don't understand the problem. Maybe someone else can help.
It's really frustrating to read such imprecise postings.
by mutluit
Mon Jun 22, 2020 6:53 pm
Forum: Wireless Networking
Topic: hAP ac^2: Q on passwords and wireless speed
Replies: 18
Views: 2136

Re: hAP ac^2: Q on passwords and wireless speed

Hi, I have same router and want to figure out one thing. What is Radio name? What value should it has? Should it be equal to MAC address? Yes, MAC of the other side w/o the colons, and only If two MikroTik wireless devices connect to each other. In other cases (for example if a smartphone connects ...
by mutluit
Sun Jun 21, 2020 1:11 pm
Forum: General
Topic: Wireless traffic counters
Replies: 3
Views: 913

Re: Wireless traffic counters

Excellent. Thanks. It wasn't covered in the Wiki that I could find, although the CLI command you provided had occurred to me. It didn't work because I tried /interface wlan1 reset-counters which is wrong. A tip: in CLI you can press TAB at any valid location (ie. before or after a word) and it will...
by mutluit
Sat Jun 20, 2020 8:17 pm
Forum: General
Topic: Wireless traffic counters
Replies: 3
Views: 913

Re: Wireless traffic counters

Is there any way to reset the Interface>>Wireless>>Traffic TX/RX bytes/packet/drops/errors counters such as can be done with the ETH and Bridge interfaces? In CLI you can do the following: /interface reset-counters wlan1 It seems in GUI it's not possible for wireless interfaces, or was forgotten to...
by mutluit
Sat Jun 20, 2020 7:47 pm
Forum: Beginner Basics
Topic: Open port 443 for a device on the LAN
Replies: 6
Views: 1062

Re: Open port 443 for a device on the LAN

I've figure out how to open the port broadly. Now when I go to yougetsignal.com it says the port is open. Just not sure how secure this is and if there's a better way? I set the Chain to input > Protocol TCP > Any. Port 443. The security must be provided by the service itself, ie. by the applicatio...
by mutluit
Sat Jun 20, 2020 7:26 pm
Forum: Beginner Basics
Topic: Basic config no internet no local network
Replies: 2
Views: 609

Re: Basic config no internet no local network

Nowadays many applications don't work without Internet connection.
Having a local DNS server is good for caching, but it can't solve the problem since it too needs Internet connection to its uplink servers (ie. 8.8.8.8 etc. are in Internet).
by mutluit
Sat Jun 20, 2020 6:54 pm
Forum: Beginner Basics
Topic: I can't open ports
Replies: 4
Views: 923

Re: I can't open ports

For easy understanding you better should make a drawing of your network. Since you seem to be using 2 routers, then it could be that you have a "Double NAT Problem". On which of the routers do you have NAT enabled? You should have NAT enabled only on the WAN router, and disable it on all other devic...
by mutluit
Sat Jun 20, 2020 6:00 pm
Forum: Beginner Basics
Topic: Use MikroTik as second router
Replies: 13
Views: 1858

Re: Use MikroTik as second router

If you can not set ISP router in bridge mode, you will have double NAT, but other than that, most stuff should work. I have a similar setup like the OP, but the difference is that I let only run DNS server and NTP server (time server) on the WAN router, everything else runs on the 2nd router. There...
by mutluit
Sat Jun 20, 2020 6:28 am
Forum: Wireless Networking
Topic: Please help me with my 14Km link. [SOLVED]
Replies: 3
Views: 985

Re: Please help me with my 14Km link. [SOLVED]

https://en.wikipedia.org/wiki/Antenna_gain#Example_calculation Looks like some rocket science :-) See also https://www.simplewifi.com/pages/antenna-basics According to their table it seems for your 14km you need a "Parabolic Grid 24 dBi Directional Antenna", or better. But they also say "As a rule o...
by mutluit
Fri Jun 19, 2020 3:45 am
Forum: Wireless Networking
Topic: Connecting two LANs via two WLANs
Replies: 0
Views: 349

Connecting two LANs via two WLANs

I'll soon perform this WLAN experiment: connecting two LANs via two WLANs using basic IP routing (ie. w/o any tunneling): WLAN1(.132.254/24) WLAN2(.142.254/24) | | WAN1 --------- R1 R2 ------------ WAN2 | | LAN1(.131.254/24) LAN2(.141.254/24) Routers R1 and R2 are not cable-connected with each other...
by mutluit
Fri Jun 19, 2020 2:32 am
Forum: General
Topic: Network loop?
Replies: 6
Views: 1464

Re: Network loop?

You should post your config for analysis, ie in CLI:
/export hide-sensitive file=export-hs
and then see in /Files for the file...
by mutluit
Fri Jun 19, 2020 2:01 am
Forum: Beginner Basics
Topic: New to Mikrotik - Config Help FW [SOLVED]
Replies: 12
Views: 2123

Re: New to Mikrotik - Config Help FW [SOLVED]

It is already on the first post as attachment :D
Ok, I see.
But come on, man, are you joking? :-) This is a full-blown very complex configuration, not a basic/initial configuration.
Sorry, I'm out. Maybe someone else can take a look.
by mutluit
Fri Jun 19, 2020 1:53 am
Forum: Beginner Basics
Topic: New to Mikrotik - Config Help FW [SOLVED]
Replies: 12
Views: 2123

Re: New to Mikrotik - Config Help FW [SOLVED]

Which router do you have and which OS and version does it have?
If it has RouterOS then you should post the output of this CLI command:
/ip export hide-sensitive
by mutluit
Fri Jun 19, 2020 1:38 am
Forum: Beginner Basics
Topic: New to Mikrotik - Config Help FW [SOLVED]
Replies: 12
Views: 2123

Re: New to Mikrotik - Config Help FW [SOLVED]

To simplify things I would suggest to use two routers in series, then on the border router you would have NAT, and on the inner router disable NAT (and this step simplifies all the rest). Firewall chains: input: traffic destined to the router itself output: traffic from the router itself forward: th...
by mutluit
Fri Jun 19, 2020 1:23 am
Forum: Beginner Basics
Topic: Hardware advice, small company network
Replies: 4
Views: 621

Re: Hardware advice, small company network

These are big infrastructure changes. IMO you better should consult a professional network consultant, preferably a MikroTik certified one. No, I'm not :-) Tell him/her also how fast your WAN link is, how your LAN is structured (#networks, #subnets), whether VLAN is used etc., ie. the usual things n...
by mutluit
Thu Jun 18, 2020 8:20 pm
Forum: General
Topic: Lan security
Replies: 5
Views: 961

Re: Lan security

Dot1x is used when we have mikrotik switch .
Is there any solution When 30 clients are connected to a hub and the hub is connected to mikrotik router interface
So, you are concerned of security, but are using a hub (instead of a switch) for 30 clients?
What hub model is it?
by mutluit
Thu Jun 18, 2020 7:59 pm
Forum: Wireless Networking
Topic: Suggested Config for car based LtAP mini LTE and 2x hAPac
Replies: 2
Views: 704

Re: Suggested Config for car based LtAP mini LTE and 2x hAPac

@azharuddin, is your posting anyhow in the slightest related to the question at all, or did I miss something?
Looks to me like a bot-reply :-)
by mutluit
Thu Jun 18, 2020 7:51 pm
Forum: Wireless Networking
Topic: What settings in WIRELESS will affect CAPSMAN
Replies: 2
Views: 895

Re: What settings in WIRELESS will affect CAPSMAN

What settings in WIRELESS(command: /interface wireless) will affect CAPSMAN ?
Take a look at viewtopic.php?f=7&t=162494
There are the configs of both posted.
by mutluit
Thu Jun 18, 2020 5:35 pm
Forum: General
Topic: API Document for latest Router OS Version
Replies: 1
Views: 376

Re: API Document for latest Router OS Version

We are trying to integrate our Mikrotik router CCR1036-8G-2S+ with Bandwidth manager router of 24online server and they have requested us to provide them with API document of Mikrotik router of current router OS version any that is available. https://wiki.mikrotik.com/wiki/Manual:API It says "This ...
by mutluit
Thu Jun 18, 2020 5:22 pm
Forum: General
Topic: Mac Address Range
Replies: 1
Views: 525

Re: Mac Address Range

Is there a way in the firewall to filter by a MAC address range? Say all the MAC addresses owned by Company X? At some locations in the config, like the ACL, one indeed can specify MAC/subnet, see for example https://wiki.mikrotik.com/wiki/Manual:CRS3xx_series_switches#Port_Security /interface ethe...
by mutluit
Thu Jun 18, 2020 5:06 pm
Forum: General
Topic: Join to multicast group
Replies: 1
Views: 377

Re: Join to multicast group

Search "MikroTik multicast"
See for example this: https://www.premitel.uk/consultancy/exp ... uterboard/
by mutluit
Thu Jun 18, 2020 4:53 pm
Forum: General
Topic: Lan security
Replies: 5
Views: 961

Re: Lan security

1.Is there any way to limit dhcp server to assign ip for clients that are authenticated ,not all the clients that are physically connected? 2.If not is it possible to prevent connecting unknown computers to lan? Is mac filter the only way? 3.What about user manage? Is it possible to authenticat cli...
by mutluit
Thu Jun 18, 2020 4:16 pm
Forum: General
Topic: How can I find out the reason for NAK?
Replies: 5
Views: 842

Re: How can I find out the reason for NAK?

Hi there. I faced a problem recently. SVI of my switch doesn't get IP-address via DHCP server on my Mikrotik 951Ui-2nD (6.42.1). Although it gets IP-address via ISC-DHCP server. I've watched the log but can't find the reason of NAK. How can I do that? P.S. Attached log from mikrotik. For analysis y...
by mutluit
Thu Jun 18, 2020 3:34 pm
Forum: General
Topic: RouterOS changed IP address association without input
Replies: 1
Views: 338

Re: RouterOS changed IP address association without input

I had similar encounters :-)
I've documented it here: viewtopic.php?f=2&t=162506&p=801039#p801039
by mutluit
Thu Jun 18, 2020 1:51 pm
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 4171

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

And about Quick Set, one should better not use it at all after any change done outside of it. Indeed, it was also the reason for the late wlan2 problem: the "/ip address" list was messed up: had 2 different gateway entries for ether2 . This happens if one tries on the QuickSet page to fix the LAN I...
by mutluit
Thu Jun 18, 2020 2:56 am
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 4171

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

Btw, a warning: one better should not use (ie. fill) the "Guest Network" entries under QuickSet as it again creates the bridge and puts all interfaces into it... :-) I just had tried it out, but since it didn't function I reverted everything back, but now it seems wlan2 is no more functioning as cli...
by mutluit
Thu Jun 18, 2020 2:45 am
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 4171

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

"Bridge1" is no router , it is functioning as a switch. There are no routing decisions in the switch Bridge1. Bridge1 is just another interface to the router, and for the router it fully replaces ether1,wlan1 and wlan2. The Bridge1/switch is making one single LAN (broadcast domain) with the combina...
by mutluit
Thu Jun 18, 2020 2:39 am
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 4171

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

There were two configs. Original with individual interfaces and no bridge. And then exploring dead ends with bridge that did something, but no that much, because the main problem (missing gateway) was still present. I 'll rest my case. No more comments. This first model was made based on an earlier...
by mutluit
Wed Jun 17, 2020 8:26 pm
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 4171

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

SOLVED! Thanks @Sob! As he said in https://forum.mikrotik.com/viewtopic.php?f=2&t=162506&p=800866#p800866, entries under "/ip dhcp-server network" were missing. After adding it there and removing the bridge and reactivating DHCP pools for wlan1 and wlan2 (192.168.132.0/24 and 192.168.133.0/24), and ...
by mutluit
Wed Jun 17, 2020 7:44 pm
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 4171

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

It's the client device that needs default gateway. When it gets config from dhcp, it would be: /ip dhcp-server network add address=192.168.254.0/24 gateway=192.168.254.253 <other options> But you don't have anything like that. Not that it's completely correct, because .253 is on this router, but as...
by mutluit
Wed Jun 17, 2020 7:25 pm
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 4171

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

@Sob, the DHCP server is only for wlan clients; all other devices have manually configured static IP and gateway (and DNS server etc.).

@bpwl, see bridge1 in routing table: ether1, wlan1, wlan2 use that for their routing decision, IMO. The bridge1 was added by ROS itself to the routing table.
by mutluit
Wed Jun 17, 2020 6:43 pm
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 4171

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

Where is default gateway for 192.168.254.x clients, don't they have any? If not, then 192.168.254.0/24 is all they can access, nothing else. This is the routing table. IIRC only record #4 was defined manually by me, the rest is auto-generated by RouterOS: [admin2@MikroTik-AP] > /ip route print Flag...
by mutluit
Wed Jun 17, 2020 6:39 pm
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 4171

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

I don't see addresses to be assigned to wlan1 and wlan2. As said in a prev posting, the gateway addresses for wlanX (.132.254 and .133.254) in my OP I had to remove for this latest partial-working solution (actually it didn't make any difference whether they continued existing or not). The wlan cli...
by mutluit
Wed Jun 17, 2020 6:10 pm
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 4171

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

Is there perhaps anything else you have in your config? Maybe posting the whole thing could help. Because none of the routers I have ever seen cared whether inteterface is ether or wlan, and I don't see why there should be any difference. Below is the "/export hide-sensitive file=export-hs". The co...
by mutluit
Wed Jun 17, 2020 5:33 pm
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 4171

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

or to continue ... Can a wlan1 device be pinged from the router itself or from another wlan1 device? And of course the reverse route must exist in the wlan1 device with router as gateway. Pinging wlan clients from all devices connected to the same subnet on ether1 (ie. 192.168.254.x) works, as well...
by mutluit
Wed Jun 17, 2020 3:50 pm
Forum: RouterOS v7 BETA
Topic: Feature Request For Centrally Handling All Authentication Failures
Replies: 2
Views: 480

Feature Request For Centrally Handling All Authentication Failures

Proposal/FeatureRequest For Centrally Handling All Authentication Failures For Banning And/Or Executing A Script Each AuthFailure should be sent to an AuthFailureSystem similar to the firewall, but much simpler: add error-source=serviceId error-category=... error-code=... action=ban ban-duration=......
by mutluit
Wed Jun 17, 2020 2:53 pm
Forum: Scripting
Topic: How to get SrcIP address from PPTP Auth failure log?
Replies: 4
Views: 2305

Re: How to get SrcIP address from PPTP Auth failure log?

Any ideas how to get SRC IP from failed PPTP authentication parsing log files?
The IP is in the previous log line "TCP connection established from ..."
by mutluit
Wed Jun 17, 2020 2:04 pm
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 4171

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

Your latest post indicates that indeed it's what @sob wrote: ... and if they have own firewalls, they must allow pings from other subnet. There is no firewall issue. As already said: etherX to etherY works w/o any problems with just default/automatic routing settings on the router, and firewall on ...
by mutluit
Wed Jun 17, 2020 6:50 am
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 4171

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

I could achieve only a partial solution which allows to ping/connect to the wlan-client only from the WAN-side (ether1). For this to work I had to do these steps: 1.) Create a bridge "bridge1" and put WAN, (ether1), wlan1, wlan2 into it. 2.) Create an IP Pool for the DHCP Server with an IP range fro...
by mutluit
Wed Jun 17, 2020 6:19 am
Forum: Scripting
Topic: Script for If enivorment = then do
Replies: 14
Views: 1830

Re: Script for If enivorment = then do

Hi It works just curios why this won't work inside system scripts work at the console if run as script use /import says invalid URL not sure how to debug that i assume it same URL it pull for from $configserver not sure why won't run as a script any suggestions? { :global provisionedstatus false :i...
by mutluit
Wed Jun 17, 2020 2:08 am
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 4171

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

That's how IP subnets work. If you connect device with address 192.168.131.3 to any other interface than ether5, it can't work, because as the router sees it, any 192.168.131.x is connected to ether5 and it won't look for it anywhere else. Also, device looking for 192.168.131.254 won't succeed on a...
by mutluit
Wed Jun 17, 2020 1:37 am
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 4171

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

If clients connected to wlan1 or wlan2 have this router (i.e. 192.168.132.254 or 192.168.133.254) as default gateway (or have routes to other subnets) and they answer pings from these subnets (it's not blocked by their firewalls), this tiny piece of config doesn't explain why it shouldn't work. Goo...
by mutluit
Wed Jun 17, 2020 1:01 am
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 4171

RouterOS illogical behavior with wireless interfaces [SOLVED]

On my router (hAP ac^2) with RouterOS v6.47 I'm using all ports as gateways for independent LANs. For this I removed the default bridge and made each port a gateway of its LAN, ie like this: /ip address print Flags: X - disabled, I - invalid, D - dynamic # ADDRESS NETWORK INTERFACE 0 192.168.254.253...
by mutluit
Tue Jun 16, 2020 6:37 pm
Forum: Beginner Basics
Topic: virtual wifi interface can't connect internet
Replies: 6
Views: 881

Re: virtual wifi interface can't connect internet

Maybe this video can help:
Mikrotik Tutorial no: 22 - Creating Multiple WIFI SSID for VLAN based Network
https://www.youtube.com/watch?v=i-qQo06ow7Y
by mutluit
Tue Jun 16, 2020 5:14 pm
Forum: Beginner Basics
Topic: DNS not resolving domain names
Replies: 8
Views: 1187

Re: DNS not resolving domain names

@anav, IMO there is ZERO need for VLAN with routers, especially not in home environment as well not in a corporate LAN. VLAN might be maybe good for carriers, ie. ISPs with L2 switches only...
by mutluit
Tue Jun 16, 2020 4:56 pm
Forum: Beginner Basics
Topic: DNS not resolving domain names
Replies: 8
Views: 1187

Re: DNS not resolving domain names

Yes, my computers get theirs IPs via DHCP, including DNS server. They don't have static IPs. The result of nslookup google.com is: DNS request timed out. timeout was 2 seconds. Server: UnKnown Address: 8.8.8.8 This indicates that the DNS server setting on the PC is wrong or couldn't be set / get. T...
by mutluit
Tue Jun 16, 2020 4:28 pm
Forum: General
Topic: DST-nat to not directly connected network (VPN without NAT)
Replies: 4
Views: 642

Re: DST-nat to not directly connected network (VPN without NAT)

I'm trying to do a DST-nat to a network that is behind another mikrotik connected using a VPN (and using a direct route, no nat, to the mikrotik from where I'm trying to setup the DST-nat), but I'm getting a strange (or not so strange) behavior where the second mikrotik is trying to answer the requ...
by mutluit
Tue Jun 16, 2020 4:14 pm
Forum: Beginner Basics
Topic: DNS not resolving domain names
Replies: 8
Views: 1187

Re: DNS not resolving domain names

Hi friends, Can any one help me to understand why my computers behind the mikrotik router cannot resolve domain names? here is my config: Do your computers get their IPs via DHCP? If they have static IPs then you have to specify the DNS server manually on the PCs. What is the output of this command...
by mutluit
Tue Jun 16, 2020 4:07 pm
Forum: Beginner Basics
Topic: Never see my ISP IP on the site I'm watching
Replies: 5
Views: 1080

Re: Never see my ISP IP on the site I'm watching

Problem description is insufficient, more data needed.
by mutluit
Tue Jun 16, 2020 3:46 pm
Forum: Scripting
Topic: Controlling USB power
Replies: 4
Views: 785

Re: Controlling USB power

@MariusL, I think you should make an official Feature Request. And/or if you think the current version has a bug then post a bug report. Per this page https://wiki.mikrotik.com/wiki/Manual:USB_Features currently the USB powering-off can be done only for a duration of user-specified time (or default ...
by mutluit
Tue Jun 16, 2020 3:28 pm
Forum: Scripting
Topic: read and store variable
Replies: 1
Views: 381

Re: read and store variable

by mutluit
Tue Jun 16, 2020 2:58 pm
Forum: Scripting
Topic: Controlling USB power
Replies: 4
Views: 785

Re: Controlling USB power

I would suggest to use a global counter (inc / dec), and trigger the alarm only if that counter is for example >= 2.

And I think it's caused by this command in your script:
/system routerboard usb power-reset duration=1d
Ie. 1d is then too short, you should set it much higher.
by mutluit
Tue Jun 16, 2020 2:34 pm
Forum: Beginner Basics
Topic: Data rates decrease to 6.5
Replies: 1
Views: 413

Re: Data rates decrease to 6.5

Can you post the output of this command in CLI (change the name "wlan1" if yours is different, pressing TAB there shows the name of yours):
/interface wireless monitor wlan1 once

And this:
/interface wireless export hide-sensitive
by mutluit
Mon Jun 15, 2020 5:13 pm
Forum: General
Topic: Setup WDS with 2 AP
Replies: 7
Views: 1183

Re: Setup WDS with 2 AP

I don't have experience in WDS myself, but just stumbled over this wiki page https://wiki.mikrotik.com/wiki/WDS_repeater_example

There are also some YT videos: https://www.youtube.com/watch?v=s6PEDtf5qDQ
by mutluit
Mon Jun 15, 2020 4:59 pm
Forum: Wireless Networking
Topic: hAP lite wireless performance?
Replies: 8
Views: 1306

Re: hAP lite wireless performance?

According to specs at https://mikrotik.com/product/RB941-2nD it has wireless 2.4 GHz max data rate 300 Mbit/s.
But the 4 Ethernet ports are 100 Mbit/s.
So 75 Mbit/s should be possible with it.
by mutluit
Mon Jun 15, 2020 4:54 pm
Forum: Wireless Networking
Topic: Add new Wireless network and redirect internet to USB modem
Replies: 1
Views: 260

Re: Add new Wireless network and redirect internet to USB modem

What USB modem is it (vendor, model etc)?
by mutluit
Mon Jun 15, 2020 4:17 pm
Forum: Wireless Networking
Topic: Help changing wireless wire default ip address
Replies: 2
Views: 512

Re: Help changing wireless wire default ip address

Which device is it?

Normally you change it via the QuickSet tab in the GUI.
(But then it can happen that you need to change the IP of your PC to the same subnet. Ie. know well what you are doing.)

What do you mean by master and slave?
by mutluit
Mon Jun 15, 2020 12:08 am
Forum: General
Topic: Problem with ports
Replies: 3
Views: 597

Re: Problem with ports

Maybe one of the devices gets too hot? Maybe too much dust on the device?
If possible test also with a replacement device.
by mutluit
Sun Jun 14, 2020 11:27 pm
Forum: General
Topic: Intermittent loss of packets.............argg
Replies: 28
Views: 4463

Re: Intermittent loss of packets.............argg

Both are off on mine, I changed it to auto for both on my vlan bell cconnection and there was no change in packet loss to the gateway of the ISP. After running for about 1.5 hours, both were sitting at about 50% Then I think iperf is your best friend... :-) I think I would get rid of VLAN and use p...
by mutluit
Sun Jun 14, 2020 9:29 pm
Forum: General
Topic: Intermittent loss of packets.............argg
Replies: 28
Views: 4463

Re: Intermittent loss of packets.............argg

Here's a screenshot. At least for the WAN port the "Tx Flow Control" and "Rx Flow Control" should be set to "Auto" or "Yes". On my device I've set them all to Auto. Auto Negotiation is by default enabled. Of course such packets (in and out) must not be blocked by a firewall rule, meaning these have ...
by mutluit
Sun Jun 14, 2020 8:43 pm
Forum: General
Topic: Intermittent loss of packets.............argg
Replies: 28
Views: 4463

Re: Intermittent loss of packets.............argg

not seeing a place to inspect or modify that? In firewall or ACL accept these L2 packets. I am afraid it may not be that easy. Ethernet flow control packets are usually processed by the hardware itself on a very low level, so it is a challenge to even capture them, let alone processing them using s...
by mutluit
Sun Jun 14, 2020 8:06 pm
Forum: General
Topic: Intermittent loss of packets.............argg
Replies: 28
Views: 4463

Re: Intermittent loss of packets.............argg

not seeing a place to inspect or modify that? In firewall or ACL accept (don't block) these L2 packets. For example I have in one of my devices these ACL rules: add switch=switch1 ports=$myPorts mac-protocol=0x8808 comment="L2 Ethernet flow control" add switch=switch1 ports=$myPorts mac-protocol=80...
by mutluit
Sun Jun 14, 2020 7:06 pm
Forum: General
Topic: ppp interface configuration parameters, APN Type, MVNO type, MVNO value
Replies: 2
Views: 560

Re: ppp interface configuration parameters, APN Type, MVNO type, MVNO value

Have you tried Advanced Mode, and also therein in profile?
by mutluit
Sun Jun 14, 2020 6:50 pm
Forum: General
Topic: config export - section "/ip dhcp-server" printed twice
Replies: 1
Views: 339

Re: config export - section "/ip dhcp-server" printed twice

I think this is not a real error, b/c you can "add" items anytime to any section, as well pick single items from any section in any order.
Of course it would be better if in such an export everything would be grouped correctly under single header.
by mutluit
Sun Jun 14, 2020 6:15 pm
Forum: General
Topic: Intermittent loss of packets.............argg
Replies: 28
Views: 4463

Re: Intermittent loss of packets.............argg

You should ensure that on your device Ethernet frame control (EtherType 0x8808) is operational/activated.
by mutluit
Sun Jun 14, 2020 3:35 pm
Forum: Scripting
Topic: tikpp - a C++17 API library
Replies: 1
Views: 306

Re: tikpp - a C++17 API library

Thx, looks very interesting for C++ users like me :-)
by mutluit
Sun Jun 14, 2020 3:16 pm
Forum: Scripting
Topic: Script for If enivorment = then do
Replies: 14
Views: 1830

Re: Script for If enivorment = then do

Hi Am try to figure out how to make a script that runs download file based on that status of environment value here is the current code am try to get work :global configserver "http://192.168.1.187//$macaddress/temp.rsc" :global "provisioned-status" "no" :if (($provisioned-status="no")) do={/tool f...
by mutluit
Sun Jun 14, 2020 2:57 pm
Forum: Wireless Networking
Topic: Wireless network stopped working
Replies: 1
Views: 273

Re: Wireless network stopped working

Which OS version does it have?
by mutluit
Sun Jun 14, 2020 2:48 pm
Forum: Wireless Networking
Topic: Bridge on wireless
Replies: 2
Views: 411

Re: Bridge on wireless

You can specify the IP range in the "pool" settings. In RouterOS see "/ip pool" either in GUI or CLI. Your ISP router surely has similar settings where you can define the IP pool. Normally you should have only 1 DHCP server active. You can instead also assign IPs manually to some or all ports/device...
by mutluit
Sun Jun 14, 2020 2:26 pm
Forum: RouterOS v7 BETA
Topic: hAP ac^2 doesn't boot after update to ROS7.0b8
Replies: 1
Views: 594

Re: hAP ac^2 doesn't boot after update to ROS7.0b8

Hello. I have router hAP ac^2. There was installed 6.45. There was no config at all (rest. and then press delete config). I upload routeros-7.0beta8-arm.npk to router and reboot it. Now it doesn't boot at all. I trid start netinstall, and power up with holding reset. after 5 sec USR begins blinking...
by mutluit
Sun Jun 14, 2020 1:37 pm
Forum: General
Topic: Intermittent loss of packets.............argg
Replies: 28
Views: 4463

Re: Intermittent loss of packets.............argg

Does the game use UDP? Packet loss is normal with UDP. For example if a buffer is full then new UDP packets simply will be dropped, unlike with TCP. See also https://forum.mikrotik.com/viewtopic.php?t=112449 and https://forum.mikrotik.com/viewtopic.php?t=50110 Enabling Ethernet flow control could ma...
by mutluit
Sat Jun 13, 2020 10:44 pm
Forum: Beginner Basics
Topic: raw forwarding
Replies: 1
Views: 432

Re: raw forwarding

You need to do it also in the other direction... :-)
by mutluit
Sat Jun 13, 2020 10:10 pm
Forum: General
Topic: ISP Router Setup
Replies: 2
Views: 732

Re: ISP Router Setup

I would keep NAT on R1 (ie. the WAN router) and disable NAT on all other routers. Yes, you can reduce firewall on R1 and do it on the other routers. (FYI: you can have firewall anywhere, even on PCs) For automatic IP/gateway assignment for clients (ie. for their "WAN" side), you can have DHCP-server...
by mutluit
Sat Jun 13, 2020 5:50 pm
Forum: Beginner Basics
Topic: How to measure and improve RouterBOARD performances when connected to a FTTH ISP ?
Replies: 2
Views: 387

Re: How to measure and improve RouterBOARD performances when connected to a FTTH ISP ?

Start an iperf server in LAN Connect an iperf client in WAN (for example running on a rented VPS of yours in Internet) to the above iperf server. Let it run 60 seconds or so, then you will get the answer. See also https://en.wikipedia.org/wiki/Iperf For LAN-internal speed testing (ie. testing local ...
by mutluit
Sat Jun 13, 2020 5:34 pm
Forum: General
Topic: Methods in connecting N router [SOLVED]
Replies: 14
Views: 2051

Re: Methods in connecting N router [SOLVED]

@Schime85, is Method C working in practice? I have my doubts :-)
It can only work if you use a netmask /23 or so, but not with /24.
by mutluit
Sat Jun 13, 2020 5:17 pm
Forum: General
Topic: Methods in connecting N router [SOLVED]
Replies: 14
Views: 2051

Re: Methods in connecting N router [SOLVED]

Without an intermediate unmanaged (dumb) switch you can't connect 3+ routers without eating up the remaining router ports. yes then take a 10 port router like rb4011 ... the focus lies in the methods not in hardware questions I still would prefer using an intermediate unmanaged switch as it simplif...
by mutluit
Sat Jun 13, 2020 5:11 pm
Forum: General
Topic: Methods in connecting N router [SOLVED]
Replies: 14
Views: 2051

Re: Methods in connecting N router [SOLVED]

Without an intermediate unmanaged (dumb) switch you can't connect 3+ routers without eating up the remaining router ports.
by mutluit
Sat Jun 13, 2020 4:11 pm
Forum: General
Topic: Methods in connecting N router [SOLVED]
Replies: 14
Views: 2051

Re: Methods in connecting N router [SOLVED]

I would suggest to use Method B. But the IPs must be in the same network at both sides, ie. one say has .254 and the other .253. Ie. in the same broadcast domain. 3+ routers you would connect together in series (much like the first 2) and in the same one network, not parallel :-) BUT: of course with...
by mutluit
Sat Jun 13, 2020 1:13 pm
Forum: General
Topic: 2x CRS354's connected via Q+, one continually reboots
Replies: 2
Views: 549

Re: 2x CRS354's connected via Q+, one continually reboots

Maybe a heat issue. Are all cooling fans ok?
What does "/system health print" say?
And: also what does "/system logging print" say?
by mutluit
Sat Jun 13, 2020 1:07 pm
Forum: General
Topic: I need to change WAN IP adress without breaking the ipsec tunnels
Replies: 2
Views: 360

Re: I need to change WAN IP adress without breaking the ipsec tunnels

Not sure whether this can help, but you can add additional IPs also to the current eth1.
by mutluit
Fri Jun 12, 2020 4:39 pm
Forum: General
Topic: Protected configuration of new router?
Replies: 13
Views: 1630

Re: Protected configuration of new router?

@RackKing, are you aware of the fact that any legitimate user with access to the router can issue the command "/export" in the CLI, or look in Webfig or in Winbox to see/get all the configuration? Do you want to allow only yourself to manage the device of the user? If yes, then just don't give the u...
by mutluit
Fri Jun 12, 2020 4:19 pm
Forum: General
Topic: No Internet on WIFI
Replies: 3
Views: 563

Re: No Internet on WIFI

What is your test client? A smartphone?
What does it say? Is the SSID listed, or can you add it manually?
by mutluit
Fri Jun 12, 2020 4:08 pm
Forum: General
Topic: AWS - CHR Dual WAN?
Replies: 1
Views: 278

Re: AWS - CHR Dual WAN?

Hello, Does anyone have a working config for CHR running in AWS with dual WAN? I would like to setup CHR at the edge of the VPC with 2 WAN interfaces with 2 Public IP addresses and 1 LAN interface. Thank you, Some general info: https://wiki.mikrotik.com/wiki/Manual:CHR_AWS_installation https://aws....
by mutluit
Fri Jun 12, 2020 3:47 pm
Forum: General
Topic: encrypted password for mikrotik config
Replies: 22
Views: 5907

Re: encrypted password for mikrotik config

@ngaleyev, do you know that passwords are not static but can (and should) be changed anytime by its user?... :-) Or is that not wanted by your org? Tip: you should always have at least 2 admin users configured (admin + company), in case the admin leaves the company, or suddenly dies in an accident o...
by mutluit
Fri Jun 12, 2020 3:26 pm
Forum: General
Topic: How to keep people from connecting PC instead of Access points or Cameras ?
Replies: 4
Views: 604

Re: How to keep people from connecting PC instead of Access points or Cameras ?

Use access restrictions on the devices itself if they have it. By MAC, IP, and strong password(s) . MAC and IP of course are not that secure as everybody on his access device can change them. To prevent unauthorized access via LAN/WAN: protect also on the router... And: if possible on the devices, u...
by mutluit
Fri Jun 12, 2020 3:00 pm
Forum: General
Topic: Port forwarding between two wan interface on same routerboard
Replies: 4
Views: 638

Re: Port forwarding between two wan interface on same routerboard

My purpose is: if someone access 10.100.11.11:3562, he can speed up access 1.1.1.1:53 via WAN2.
I guess you mean 8374 instead of 3562.

Problem description is now clear.
It normally should function.
by mutluit
Fri Jun 12, 2020 2:17 pm
Forum: General
Topic: Protected configuration of new router?
Replies: 13
Views: 1630

Re: Protected configuration of new router?

scp the rsc script to the device, ssh to the device, and import the rsc, then delete the rsc...
Instead of scp you can of course also use "/tool fetch ..." to download the rsc from your own server...
Of course the ssh service (default port 22) of the device must first be reachable from Internet...
by mutluit
Fri Jun 12, 2020 2:00 pm
Forum: General
Topic: Port forwarding between two wan interface on same routerboard
Replies: 4
Views: 638

Re: Port forwarding between two wan interface on same routerboard

The problem description is a little bit cryptic as one can't imagine what you try to achieve. Are you trying to do a kind of Load Balancing? And what do you mean by "random port"? I would replace the following add action=dst-nat chain=dstnat dst-address=10.200.22.22 dst-port=3562 \ in-interface=WAN2...
by mutluit
Fri Jun 12, 2020 1:37 pm
Forum: General
Topic: Hardware Upgrade
Replies: 4
Views: 674

Re: Hardware Upgrade

Hello everyone! The guys encountered such a problem, it is necessary to do an equipment update. At the moment, I need to raise the main channels to 20G or 40G. I have a network diagram that needs updating, please pick up ideas. How can I update the equipment on the Mikrotik vendor. I will be very g...
by mutluit
Fri Jun 12, 2020 1:12 pm
Forum: Beginner Basics
Topic: block communications of connected networks via route
Replies: 6
Views: 494

Re: block communications of connected networks via route

Thank you anav. I don't see why the question is confusing. Two networks on two interfaces should not communicate with each other. Anyway, I found how to do it. Instead of: /ip firewall filter add chain=forward src-address=192.168.10.0/24 dst-address=192.168.20.0/24 action=drop add chain=forward src...
by mutluit
Fri Jun 12, 2020 12:27 am
Forum: Beginner Basics
Topic: Hairpin with port forwarding
Replies: 14
Views: 1529

Re: Hairpin with port forwarding

I today made simple port-forwarding w/o any hairpin thing in the following thread https://forum.mikrotik.com/viewtopic.php?f=2&t=162321 I can use the WAN-IP:port from both the Internet as well from inside the LAN. I used this /ip firewall nat add chain=dstnat dst-address=192.168.1xx.xxx dst-port=xxx...
by mutluit
Thu Jun 11, 2020 11:38 pm
Forum: Beginner Basics
Topic: deleted
Replies: 0
Views: 440

Re: First MikroTik Deployment, Feedback, Questions

Sorry, can't comment on it as I'm not an expert on VLAN stuff. My deployment of it would have been by using pure basic IP routing :-) Much easier for me :-) Regarding remote administration: IMO it should be secure enough to use simple port-forwarding(s) on your WAN router to the ssh service of the d...
by mutluit
Thu Jun 11, 2020 11:13 pm
Forum: General
Topic: SFP+ operating only at 1Gbps
Replies: 1
Views: 253

Re: SFP+ operating only at 1Gbps

What devices / products are involved in that problem?
Does your other device have SFP+ or just SFP?
by mutluit
Thu Jun 11, 2020 9:28 pm
Forum: General
Topic: Unable to traceroute from MT
Replies: 2
Views: 352

Re: Unable to traceroute from MT

Seems to be a firewall issue. Maybe you are blocking UDP traffic.
I had a similar case in this thread: viewtopic.php?f=2&t=161938&p=797658
by mutluit
Thu Jun 11, 2020 8:35 pm
Forum: General
Topic: Feature requests
Replies: 1255
Views: 273181

Re: Feature requests

So I don't know whether using discrimination per country is racist, but it is definitely useless. My claim was: It is completely useless, and it tends to racism. It is useless for the reasons I described, and it tends to "let's block Nigeria because Nigerians are scammers. let's block Russia becaus...
by mutluit
Thu Jun 11, 2020 8:23 pm
Forum: General
Topic: Doing a simple port forwarding [SOLVED]
Replies: 7
Views: 703

Re: Doing a simple port forwarding [SOLVED]

Any time you have multiple ports or a range of ports, going to the same LANIP, it is an opportunity to create a single rule (assuming same protocol).
Yes, indeed, makes sense.
by mutluit
Thu Jun 11, 2020 8:13 pm
Forum: General
Topic: Doing a simple port forwarding [SOLVED]
Replies: 7
Views: 703

Re: Doing a simple port forwarding [SOLVED]

The port forwarding works ok:
iperf speed (iperf server in LAN, iperf client in Internet; Internet link is Gigabit):
[ ID] Interval        Transfer    Bandwidth       Reads   Dist(bin=16.0K)
[SUM] 0.00-10.09 sec  1.10 GBytes   938 Mbits/sec  89613    54856:34617:50:2:5:2:2:79
by mutluit
Thu Jun 11, 2020 7:14 pm
Forum: General
Topic: Doing a simple port forwarding [SOLVED]
Replies: 7
Views: 703

Re: Doing a simple port forwarding [SOLVED]

The inconsistencies come from the examples on this wiki page, which I had used: https://wiki.mikrotik.com/wiki/Manual:IP/Firewall/NAT#Port_mapping.2Fforwarding There "to-address=" and "to-port=" are given. The CLI says "to-addresses=" and "to-ports=", but seems to accept both variants. But I still w...
by mutluit
Thu Jun 11, 2020 6:49 pm
Forum: General
Topic: Doing a simple port forwarding [SOLVED]
Replies: 7
Views: 703

Re: Doing a simple port forwarding [SOLVED]

add chain=dst-nat action=dstnat protocol=tcp dst-port=xxxx,yyyy,zzzz to-addresses=192.168.88.5 add chain=dst-nat action=dstnat protocol=tcp dst-port=xxxx-yyyy to-addresses=192.168.88.5 (where xxxx-yyyy describes a range of 10 IPs) add chain=dst-nat action=dstnat protocol=tcp dst-port=xxxx-yyyy to-a...
by mutluit
Thu Jun 11, 2020 6:20 pm
Forum: General
Topic: Doing a simple port forwarding [SOLVED]
Replies: 7
Views: 703

Doing a simple port forwarding [SOLVED]

I have two routers in series. The 1st router does NAT, the 2nd router does not do NAT. On the 1st router I'm port-forwarding to the 2nd router, and on the following 2nd router with IP 192.168.1xx (its "WAN" port) I'm trying to port-forward it further to the final destination LAN-IP 192.168.2xx: . /s...
by mutluit
Thu Jun 11, 2020 3:39 am
Forum: General
Topic: CRS354, traffic sniffer, hardware offloading, port mirroring, rspan [SOLVED]
Replies: 4
Views: 892

Re: CRS354, traffic sniffer, hardware offloading, port mirroring, rspan [SOLVED]

You have some syntax errors: there must not be any blanks around the "=" sign...
by mutluit
Wed Jun 10, 2020 9:25 pm
Forum: General
Topic: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]
Replies: 19
Views: 2525

Re: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]

On the uplink router (ISP router) one has to set static routes to these LANs as otherwise pings to WAN/Internet from these LANs can't work as the return path would be unknown. In 99% of the cases (and in 100% if we are talking about home use) ISP won't care about you LAN's and won't set any static ...
by mutluit
Wed Jun 10, 2020 8:14 pm
Forum: Beginner Basics
Topic: What seperation method should I use? [SOLVED]
Replies: 12
Views: 1242

Re: What seperation method should I use? [SOLVED]

Maybe the following can give you some inspirations: https://forum.mikrotik.com/viewtopic.php?f=2&t=162190 It creates 5 independent LANs by using basic IP routing; no VLAN, no CAPSMAN involved. If you really mean 3 networks with 3 subnets each, then you need just a router with 3+ LAN ports plus 1 WAN...
by mutluit
Wed Jun 10, 2020 7:32 pm
Forum: Beginner Basics
Topic: Hairpin with port forwarding
Replies: 14
Views: 1529

Re: Hairpin with port forwarding

It is unclear what you mean by "outside". Do you mean Internet? From the Internet you cannot connect to such an internal/private IP like 192.168.x.x. Do you have a WAN router? Is there NAT enabled? If the answer to the above questions is Yes, and your device is one that is connected to that WAN rout...
by mutluit
Wed Jun 10, 2020 7:15 pm
Forum: RouterOS v7 BETA
Topic: hardware offload on other Marvell DX switches?
Replies: 8
Views: 1407

Re: hardware offload on other Marvell DX switches?

But isn't HW Offloading already present at least on all CRS3xx devices? My CRS326 and CRS305 do have it already (both use the Marvell 98dx3236 SoC): For L2 switching, yes. What the CRS317 can now do is L3 offloading: hardware-assisted routing. It makes the CRS317 twice as fast at IP routing (within...
by mutluit
Wed Jun 10, 2020 6:51 pm
Forum: RouterOS v7 BETA
Topic: hardware offload on other Marvell DX switches?
Replies: 8
Views: 1407

Re: hardware offload on other Marvell DX switches?

I see that L3 hardware offloading is supported only on the CRS317. But isn't HW Offloading already present at least on all CRS3xx devices? My CRS326 and CRS305 do have it already (both use the Marvell 98dx3236 SoC): For example CRS305 with old software: [admin2@CRS305] /system routerboard print rou...
by mutluit
Wed Jun 10, 2020 4:41 pm
Forum: General
Topic: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]
Replies: 19
Views: 2525

Re: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]

To summarize & conclude: I now have managed to configure each of the 5 Gigabit ports of the hAP ac^2 with an independent LAN, ie. 5 independent wired LANs in total (1x WAN + 4x LAN). For this to work the ports had to be removed from the bridge, and then the bridge itself removed as well. Each port p...
by mutluit
Wed Jun 10, 2020 3:26 pm
Forum: General
Topic: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]
Replies: 19
Views: 2525

Re: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]

Encountered a problem: as said: ether1 is WAN ether2 is LAN2 ether3 is LAN3 From LAN2 I can ping everything (WAN, LAN2, LAN3) well. But from LAN3 I can ping all but the WAN. Very mysterious IMO. The firewall is empty. Any diagnose tips/hints to look after? Update: SOLVED! A static route to LAN3 on t...
by mutluit
Wed Jun 10, 2020 3:01 pm
Forum: General
Topic: Forum giving ERROR 500 [SOLVED]
Replies: 17
Views: 1797

Re: Forum giving ERROR 500 [SOLVED]

Can you try the same from another browser in private mode? Ok, making this reply in an other browser (Firefox Linux) in a New Private Window... The result was: BLANK WINDOW with no text at all in the window. But the posting went through. But: the error did not happen when EDITING+POSTING the post.....
by mutluit
Wed Jun 10, 2020 2:46 pm
Forum: General
Topic: Forum giving ERROR 500 [SOLVED]
Replies: 17
Views: 1797

Re: Forum giving ERROR 500 [SOLVED]

Happens since about 2 days also in my Opera web browser in Linux. It says This page isn’t working forum.mikrotik.com is currently unable to handle this request. But the posting still goes thru. Ie. the above error message happens when making a posting. But the posting still gets posted successfully....
by mutluit
Wed Jun 10, 2020 2:44 pm
Forum: General
Topic: MikroTik notification server down?
Replies: 2
Views: 436

Re: MikroTik notification server down?

Are you talking about forum notifications or any other ones?
Forum notifications. Ie. if a reply happens to postings here where one participates.
by mutluit
Wed Jun 10, 2020 2:27 pm
Forum: General
Topic: MikroTik notification server down?
Replies: 2
Views: 436

MikroTik notification server down?

I think since yesterday I no longer get any email notifications, even though I should have got notifications about new postings in threads I'm subscribed to.
Anybody else missing such notifications?
Is maybe the Mikrotik server down or faulty?
by mutluit
Wed Jun 10, 2020 2:22 pm
Forum: General
Topic: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]
Replies: 19
Views: 2525

Re: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]

It works! :-) The Ubi ER has now been successfully replaced by this hAP. But performance tests not done yet. Hmm... wait.. I haven't changed the bridge settings yet, but it still works fine as it seems... :-) . I think you should start again with your configuration as it is potentially unsafe from ...
by mutluit
Tue Jun 09, 2020 8:23 pm
Forum: General
Topic: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]
Replies: 19
Views: 2525

Re: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]

It works! :-) The Ubi ER has now been successfully replaced by this hAP. But performance tests not done yet. Hmm... wait.. I haven't changed the bridge settings yet, but it still works fine as it seems... :-) But what I didn't know and learned by accident during this exercise: with "/ip address add ...
by mutluit
Tue Jun 09, 2020 6:43 pm
Forum: General
Topic: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]
Replies: 19
Views: 2525

Re: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]

I prefer to work with VLAN's, especially because of the control within the firewall. You might want to look at this tutorial: https://forum.mikrotik.com/viewtopic.php?t=143620 Thanks, but I feel myself not that fit yet for VLAN; I need some more time (some months) & studying until I'm fit for VLAN ...
by mutluit
Tue Jun 09, 2020 6:24 pm
Forum: General
Topic: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]
Replies: 19
Views: 2525

Re: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]

If all ports are removed from the bridge, should the now empty bridge still be kept in the config, or should it (the bridge itself) rather be removed? You can remove the bridge, as there is no longer any purpose in it. Ie. the generic question here is: should in RouterMode the WAN port be taken off...
by mutluit
Tue Jun 09, 2020 5:31 pm
Forum: General
Topic: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]
Replies: 19
Views: 2525

Re: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]

If all ports are removed from the bridge, should the now empty bridge still be kept in the config, or should it (the bridge itself) rather be removed? Btw, a correction to my drawing above: in this hAP the ports are named ether1 to ether5 plus wlan1 and wlan2, ie. there is no ether0. ether1 is in th...
by mutluit
Tue Jun 09, 2020 3:44 pm
Forum: General
Topic: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]
Replies: 19
Views: 2525

Re: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]

Yes, You can do it. Just remove the ports from the bridge.
Thanks.
Do you happen to know what happens to Hardware Offloading feature if I remove the ports from the bridge?
Or asked differently: what happens if I leave the ports in the bridge? Which negative effects can happen, if any?
by mutluit
Tue Jun 09, 2020 3:22 pm
Forum: General
Topic: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]
Replies: 19
Views: 2525

Using hAP ac^2 as a Multi-LAN-Router [SOLVED]

I wonder whether I can replace my Ubiquiti 3 port Gigabit router (all 3 ports are fully independent) with an hAP ac^2 ? The hAP ac^2 has 5 Gigabit ports (plus WiFi AP for 2.4GHz and 5GHz). Ie. it has 2 ports more than the Ubi. If we take 1 of the ports for WAN, can the remaining 4 ports be configure...
by mutluit
Tue Jun 09, 2020 10:52 am
Forum: Beginner Basics
Topic: AC2 max at 30% cpu load.
Replies: 2
Views: 512

Re: AC2 max at 30% cpu load.

MikroTik should use a Producer-Consumer model for creating and processing jobs or work-packages --> https://en.wikipedia.org/wiki/Producer–consumer_problem It seems the CPUs are instead statically bound to some fixed tasks. But IMO this better should be done in a dynamic fashion with the above job d...
by mutluit
Mon Jun 08, 2020 2:09 pm
Forum: Beginner Basics
Topic: Mikrotik bridge ports isolation
Replies: 1
Views: 557

Re: Mikrotik bridge ports isolation

I got ccr3xx switch. All ports are into bridge. HW offloading only possible on one bridge. Is there any way to make ONLY one switch port A send or receive packets from or to other switch port B in same bridge. Port B should be able communicate with other bridge ports, but port A should work only wi...
by mutluit
Thu Jun 04, 2020 5:08 pm
Forum: Wireless Networking
Topic: hAP ac^2: Q on passwords and wireless speed
Replies: 18
Views: 2136

Re: hAP ac^2: Q on passwords and wireless speed

I did not know your above message in your link, just saw it right now. No problem. I thought you did see it as your message was edited 7 minutes after my posting in that thread. :-) Like said, I did not know, or was not that interested in that problem then. . I hope your ComFast stick is 2x2 and ha...
by mutluit
Thu Jun 04, 2020 3:59 pm
Forum: Wireless Networking
Topic: hAP ac^2: Q on passwords and wireless speed
Replies: 18
Views: 2136

Re: hAP ac^2: Q on passwords and wireless speed

A new problem: the smartphone no longer recognizes the SSID in 5GHz (says "Not in range"), even after reverting the few changes I had done in RouterOS v6.47 (stable). Maybe I should reboot the AP. Update: now it's back again. So, then this means to me: after doing any changes in ROS it takes some t...
by mutluit
Thu Jun 04, 2020 3:27 pm
Forum: Wireless Networking
Topic: hAP ac^2: Q on passwords and wireless speed
Replies: 18
Views: 2136

Re: hAP ac^2: Q on passwords and wireless speed

A new problem: the smartphone no longer recognizes the SSID in 5GHz (says "Not in range"), even after reverting the few changes I had done in RouterOS v6.47 (stable). Maybe I should reboot the AP. Update: now it's back again. So, then this means to me: after doing any changes in ROS it takes some ti...
by mutluit
Thu Jun 04, 2020 3:02 pm
Forum: Wireless Networking
Topic: hAP ac^2: Q on passwords and wireless speed
Replies: 18
Views: 2136

Re: hAP ac^2: Q on passwords and wireless speed

To test these speed issues, I've at eBay just ordered this USB3 WiFi stick for my PC: "1300Mbps WLAN Wifi Adapter 2.4G/5G Wireless Dongle USB 3.0 Dual band stick" Manufacturer: COMFAST, Model: CF-812AC --> http://en.comfast.com.cn/index.php?m=content&c=index&a=show&catid=30&id=348 The ad says "1300 ...
by mutluit
Thu Jun 04, 2020 12:38 pm
Forum: Wireless Networking
Topic: hAP ac^2: Q on passwords and wireless speed
Replies: 18
Views: 2136

Re: hAP ac^2: Q on passwords and wireless speed

Webfig is ok for normal configuration (but when you mess it, only Windows tools like Winbox and Netinstall can recover the hap). The important thing is to never use quickset after initial setup. If you change anithing in Quickset after you get in trouble. Use only Webfig and Terminal for tuning and...
by mutluit
Thu Jun 04, 2020 12:34 pm
Forum: Wireless Networking
Topic: hAP ac^2: Q on passwords and wireless speed
Replies: 18
Views: 2136

Re: hAP ac^2: Q on passwords and wireless speed

Eureka! Of course it takes two to tango! :-) It seems my old Samsung phone cannot do more than about 72 or 75 Mbps in 2.4GHz and not more than 150Mbps in 5Ghz. I haven't verified or extensively tested that yet, but saw a YT video with these same values using a different/unknown AP. I should test the...
by mutluit
Thu Jun 04, 2020 11:57 am
Forum: Wireless Networking
Topic: Dual Band: How to assign individual password(s) to each SSID? [SOLVED]
Replies: 0
Views: 424

Dual Band: How to assign individual password(s) to each SSID? [SOLVED]

The dual band device hAP ac^2 has wlan1(2GHz) and wlan2(5GHz). One can assign each a different SSID, but it seems not possible to give each a different password, as the WPA/WPA2 passwords made in Webfig under Wireless/SecurityProtocols seem to be used/shared with all the wlanX services. Or is there ...
by mutluit
Thu Jun 04, 2020 11:19 am
Forum: Wireless Networking
Topic: hAP ac^2: Q on passwords and wireless speed
Replies: 18
Views: 2136

Re: hAP ac^2: Q on passwords and wireless speed

AFAIK, the password you set in QuickSet, you'll find it in Webfig, under Wireless/Security Profiles, as WPA/WPA2 preshared keys. You can check that is the same password by un-pressing the Hide Passwords button on the left-side menu Ok, good point for verification. Thx. . But it would be better to u...
by mutluit
Wed Jun 03, 2020 10:06 pm
Forum: Wireless Networking
Topic: hAP ac^2: Q on passwords and wireless speed
Replies: 18
Views: 2136

hAP ac^2: Q on passwords and wireless speed

I'm new to hAP ac^2 and have 2 questions: On the QuickSet page under the "Home AP Dual" settings there is this field: WiFi Password: ... And in Webfig under Wireless/SecurityProtocols WPA Pre-Shared Key: ... WPA2 Pre-Shared Key: ... Are these 3 password fields all distinct, or will the WPA/WPA2 pass...
by mutluit
Wed Jun 03, 2020 4:32 pm
Forum: RouterOS v7 BETA
Topic: beta5 bug: http Webfig downloading .txt files not working
Replies: 1
Views: 668

beta5 bug: http Webfig downloading .txt files not working

I'm connected via http to the Webfig of a local CRS326 and want to download some .txt files in /file to my PC,
but it's not working (nothing happens, no popup comes).
The same procedure with .key and .rsc files works fine.
Tested in browser Firefox 68.8.0esr (64-bit) on Linux.
by mutluit
Wed Jun 03, 2020 3:11 pm
Forum: RouterOS v7 BETA
Topic: Ac 2 never came back to life after update to ros7 [SOLVED]
Replies: 6
Views: 1628

Re: Ac 2 never came back to life after update to ros7 [SOLVED]

@markwien, thx for documenting the solution. I'll soon upgrade too. I had to Web Update to the latest testing ros6 and upgrade router os Firmware. After I uploaded ros 7.5 beta via netinstall. So, you updated both RouterOS and the firmware to the latest regular version, and then did a netinstall? Is...
by mutluit
Wed Jun 03, 2020 2:24 pm
Forum: General
Topic: Traceroute problem in one LAN [SOLVED]
Replies: 3
Views: 642

Re: Traceroute problem in one LAN [SOLVED]

traceroute on Linux sends UDP packets in the forward direction (unless you explicitly ask it to use another protocol), only the "TTL expired" backward notifications are ICMP. Mikrotik's /tool traceroute uses ICMP packets also in the forward direction by default. Hi, yes, indeed UDP was the cause. S...
by mutluit
Wed Jun 03, 2020 2:19 pm
Forum: General
Topic: Traceroute problem in one LAN [SOLVED]
Replies: 3
Views: 642

Re: Traceroute problem in one LAN [SOLVED]

SOLVED! The cause of the problem was that on the L3switch in ACL all UDP traffic was blocked. Ie. there was such a rule under "/interface/ethernet/switch/rule" : add switch=switch1 ports=$myPorts mac-protocol=ip protocol=udp comment="L3+4 UDP" disabled=yes And the last rule is: add switch=switch1 po...
by mutluit
Wed Jun 03, 2020 1:32 pm
Forum: General
Topic: Traceroute problem in one LAN [SOLVED]
Replies: 3
Views: 642

Traceroute problem in one LAN [SOLVED]

Traceroute problem in one LAN PC1 has IP 192.168.20.1/17 (in LAN1) PC2 has IP 192.168.129.3/24 (in LAN2) Ie. each PC is in a different LAN. Currently we use just basic static IP routing; no VLAN, no tunneling protocols, no OSPF etc. . Network topology (simplified): WAN | Router1 | | Router2 Router3/...
by mutluit
Tue Jun 02, 2020 11:53 pm
Forum: Wireless Networking
Topic: Integrating hAP ac^2 into existing LAN [SOLVED]
Replies: 5
Views: 1296

Re: Integrating hAP ac^2 into existing LAN [SOLVED]

An important tip for new users of this device: UPDATE FIRMWARE AND OS! You have to update RouterOS to the latest stable version AND also the firmware to the latest stable version. Without these steps, you cannot use the Dual Band feature under "Home AP Dual" in QuickSet as it always switches back to...
by mutluit
Tue Jun 02, 2020 9:04 pm
Forum: RouterOS v7 BETA
Topic: Ac 2 never came back to life after update to ros7 [SOLVED]
Replies: 6
Views: 1628

Re: Ac 2 never came back to life after update to ros7 [SOLVED]

I too wanted to install the beta5 on that hAP ac^2 device, but after seeing this posting I of course stopped that plan (btw, @markwien thanks for sharing your negative experience as it warns other users to be careful). Anybody else having that same problem? Can a MikroTik developer / tester please g...
by mutluit
Tue Jun 02, 2020 8:36 pm
Forum: Wireless Networking
Topic: Integrating hAP ac^2 into existing LAN [SOLVED]
Replies: 5
Views: 1296

Re: Integrating hAP ac^2 into existing LAN [SOLVED]

Integrating it into an existing LAN by attaching it to an L3-switch somehow (ie. unexpectedly :-)) did not work, even after assigning the subnet address to the interface on the L3 switch where the AP was attached. So, finally I set up a new LAN 192.168.129.0/24 and put it there by attaching that AP ...
by mutluit
Tue Jun 02, 2020 6:31 pm
Forum: Wireless Networking
Topic: Integrating hAP ac^2 into existing LAN [SOLVED]
Replies: 5
Views: 1296

Re: Integrating hAP ac^2 into existing LAN [SOLVED]

Probably best to reset it to defaults and select AP Wisp or AP home (not sure of the options). Then go into winbox and make the necessary changes to fit into your network. Hello, I told you not to participate in MY discussions! You are in my IGNORE LIST! Your useless postings are never of any help,...
by mutluit
Tue Jun 02, 2020 4:41 pm
Forum: Wireless Networking
Topic: Integrating hAP ac^2 into existing LAN [SOLVED]
Replies: 5
Views: 1296

Integrating hAP ac^2 into existing LAN [SOLVED]

Got a new wireless AP ( https://mikrotik.com/product/hap_ac2 ) and need to integrate it into our local network 192.168.0.0/17. Currently we use just basic static IP routing; no VLAN, no tunneling protocols, no OSPF etc., also no DHCP yet. The current network is as follows: WAN <--> Router(192.168.12...
by mutluit
Tue Jun 02, 2020 12:52 pm
Forum: RouterBOARD hardware
Topic: PCIe 10G SFP+ NIC for PC/workstation (not server)
Replies: 5
Views: 1067

Re: PCIe 10G SFP+ NIC for PC/workstation (not server)

I'm using Mellanox ConnectX-3 Cards in normal PCs.
They work fine in Windows 10 and Linux, no extra software or cooling required.

Thank you for sharing your practical experience.
by mutluit
Mon Jun 01, 2020 9:59 pm
Forum: Beginner Basics
Topic: Replaced Zyxel with MikroTik - webserver on same network with dyndns not reachable anymore
Replies: 3
Views: 441

Re: Replaced Zyxel with MikroTik - webserver on same network with dyndns not reachable anymore

@olliraa, your server does have an internal IP, isn't it? Then just use that IP when connecting from intern (LAN), and use the DDNS name when connecting from extern (ie. WAN/Internet). And: your current setup uses a DMZ method. But IMO your server should better be attached to the hEX router, for hig...
by mutluit
Mon Jun 01, 2020 9:35 pm
Forum: Beginner Basics
Topic: Problems with hapac2 5ghz wifi is flapping
Replies: 7
Views: 1354

Re: Problems with hapac2 5ghz wifi is flapping

Sounds like a DFS (radar detection) in action. Check your logs to check if that is the case.

Is it possible in RouterOS to exclude such DFS channels?
by mutluit
Mon Jun 01, 2020 8:48 pm
Forum: Beginner Basics
Topic: firewall question about untracked packets [SOLVED]
Replies: 7
Views: 1098

Re: firewall question about untracked packets [SOLVED]

I think you are agreeing with my conclusion: that I don't need to add the "untracked" bit. Yes, in such a straightforward case one does not need the untracked flag. But there are other situations when it's indeed needed. Btw, in none of the examples in the links you supplied is "untracked" used. Fr...
by mutluit
Mon Jun 01, 2020 8:29 pm
Forum: Beginner Basics
Topic: firewall question about untracked packets [SOLVED]
Replies: 7
Views: 1098

Re: firewall question about untracked packets [SOLVED]

... Therefore, I don't think I need to add it per https://help.mikrotik.com/docs/display/ROS/First+Time+Configuration add chain=forward action=accept connection-state=established,related comment="accept established,related"; Is that a correct conclusion? Each of the 3 default chains input, output, ...
by mutluit
Sun May 31, 2020 7:17 pm
Forum: Scripting
Topic: Help with firewall
Replies: 12
Views: 1851

Re: Help with firewall

Have a few problem with vpn brute force i have added the ips to the firewall "/ip firewall filter add chain=input src-address=141.98.81.0/24 action=drop" and another ips (i also try this command on individual ips but i still get this is the logs) 18:34:47 pptp,info TCP connection established from 1...
by mutluit
Sun May 31, 2020 6:54 pm
Forum: Scripting
Topic: Accessing to ISP's modem with Scripting?
Replies: 3
Views: 912

Re: Accessing to ISP's modem with Scripting?

I have a relative "complicated' setup, am a noob with Mikrotik Scripting and want to know how to access to my modem to know their public IP. With this code I get a HTML report with the IP: curl -c /tmp/test --location --request POST 'http://192.168.1.1/login-login.cgi' --data-raw 'sessionKey=__&pas...
by mutluit
Sun May 31, 2020 5:49 pm
Forum: Beginner Basics
Topic: Missing HTTP packets [SOLVED]
Replies: 4
Views: 803

Re: Missing HTTP packets [SOLVED]

@Todd2, if the problem now got solved then you should mark posting #2 as the solution.
by mutluit
Sun May 31, 2020 3:54 pm
Forum: Beginner Basics
Topic: Is an example available for VoIP with PC?
Replies: 16
Views: 2366

Re: Is an example available for VoIP with PC?

Sorry - I just don't see it. Everything there is port based - nothing filters on MAC. So if a phone is connected to port ether2 on a switch, and a PC is connected to the phone, with the examples given both the phone and the PC will be in a VLAN - which is not the desired behavior. Hmm. since each i...
by mutluit
Sat May 30, 2020 11:08 pm
Forum: General
Topic: Log filtration
Replies: 2
Views: 572

Re: Log filtration

What device and/or service/application is this?
by mutluit
Sat May 30, 2020 11:06 pm
Forum: General
Topic: PPPoE server maximum performance.
Replies: 5
Views: 1163

Re: PPPoE server maximum performance.

@daan99, you should open a support ticket via https://help.mikrotik.com/servicedesk/
by mutluit
Sat May 30, 2020 8:53 pm
Forum: Beginner Basics
Topic: Is an example available for VoIP with PC?
Replies: 16
Views: 2366

Re: Is an example available for VoIP with PC?

Exactly the page I'm talking about - it mentions such a configuration but doesn't actually show it. Everything there is port-based which doesn't help. What do you mean by "...but doesn't actually show it"? Don't you see the commands there? FYI: It is done in the CLI, not in the GUI. To me the page ...
by mutluit
Sat May 30, 2020 6:10 pm
Forum: Beginner Basics
Topic: How to make Port knocking working on vpn/pptp connection ?
Replies: 7
Views: 1133

Re: How to make Port knocking working on vpn/pptp connection ?

Post your port-knocking code. For an analysis we would need all your firewall rules, ie. this output:
/ip firewall filter export hide-sensitive

An alternative method would be to change the VPN server port from the default 1194 to another port.
by mutluit
Sat May 30, 2020 5:25 pm
Forum: Beginner Basics
Topic: Use two WANs at same time (not Load Balancer)
Replies: 11
Views: 1794

Re: Use two WANs at same time (not Load Balancer)

See whether your specific case is covered among the many methods available here:
https://wiki.mikrotik.com/wiki/Load_Balancing
You say it's not LB, but it's still a kind of LB.
by mutluit
Sat May 30, 2020 5:15 pm
Forum: Beginner Basics
Topic: Is an example available for VoIP with PC?
Replies: 16
Views: 2366

Re: Is an example available for VoIP with PC?

The following page gives an example, says "We will have a vlan for voip and untagged data for the PC":
https://wiki.mikrotik.com/wiki/Vlans_on ... nvironment
by mutluit
Sat May 30, 2020 5:04 pm
Forum: Beginner Basics
Topic: How to make Port knocking working on vpn/pptp connection ?
Replies: 7
Views: 1133

Re: How to make Port knocking working on vpn/pptp connection ?

How to make Port knocking working on vpn/pptp connection ? I try this ( https://wiki.mikrotik.com/wiki/Port_Knocking ) but is not working on vpn/pptp connection Anyone could help ? Port knocking is intended and used primarily with normal/usual connections. I really don't see a reason why one would ...
by mutluit
Sat May 30, 2020 4:49 pm
Forum: Beginner Basics
Topic: Replacement Groove
Replies: 2
Views: 450

Re: Replacement Groove

Here you can find MikroTik Groove step-by-step setup guide :
https://seabits.com/mikrotik-groove-ste ... tup-guide/
by mutluit
Sat May 30, 2020 3:43 pm
Forum: Beginner Basics
Topic: How to create 2 networks CRS328-24P-4S+
Replies: 1
Views: 421

Re: How to create 2 networks CRS328-24P-4S+

Do you need independent LANs, or would it suffice to have a netmask like /21 : $ ipcalc 192.168.0.0/21 Address: 192.168.0.0 11000000.10101000.00000 000.00000000 Netmask: 255.255.248.0 = 21 11111111.11111111.11111 000.00000000 Wildcard: 0.0.7.255 00000000.00000000.00000 111.11111111 => Network: 192.1...
by mutluit
Sat May 30, 2020 2:32 pm
Forum: Beginner Basics
Topic: DNS based QOS not tied proportionally to interface bandwidth?
Replies: 1
Views: 488

Re: DNS based QOS not tied proportionally to interface bandwidth?

Have you considered this alternative: You could "offload" your traffic (and work) to a server of your own that is in the Internet, ie. a cheap VPS like these with 20 TB (or more) traffic per month: https://www.hetzner.de/cloud#pricing Maybe you can find even a cheaper provider in your own country or...
by mutluit
Sat May 30, 2020 2:14 pm
Forum: General
Topic: Very long ping times
Replies: 4
Views: 931

Re: Very long ping times

Which device has this IP 192.168.1.1, the router or the wireless AP?
Does your PC have also a cable connection to the local network?
It seems all or some of the ping packets are going over the wireless route.
Check your routings on all devices, incl. your PC.
by mutluit
Sat May 30, 2020 1:36 pm
Forum: General
Topic: DDos protection
Replies: 4
Views: 688

Re: DDos protection

@jay22, do you have a legal Terms of Service (ToS) agreement / contract with your clients? Therein you make them liable for any damages, for the extra-work, and for all the unnecessary headaches they cause :-) Some tips for such a ToS: - Disclose the rules and restrictions that your clients (incl. t...
by mutluit
Sat May 30, 2020 12:44 pm
Forum: General
Topic: PPPoE server maximum performance.
Replies: 5
Views: 1163

Re: PPPoE server maximum performance.

This can have other reasons like whether the server can deliver fast enough, and whether the client can accept and process fast enough. You should do performance tests with own iperf server in WAN and client in LAN, and vice-versa. Also testing iperf server/client in LAN going thru the CCR. FYI: in ...
by mutluit
Sat May 30, 2020 12:29 pm
Forum: General
Topic: Winbox login issue
Replies: 2
Views: 347

Re: Winbox login issue

Can you login via web browser? Ie. the "Webfig" interface. If it still isn't working then try another web browser like FireFox or Chrome. If it still isn't working then maybe you have restriction on from which IP the services can be accessed. Issue this in CLI: /ip service print and see whether the ...
by mutluit
Sat May 30, 2020 12:05 pm
Forum: General
Topic: DDos protection
Replies: 4
Views: 688

Re: DDos protection

Add also the dst-address of the said DNS servers, ie. accept those packets. In the firewall the order of the rules (ie. the rank, position) is important, ie. what comes at what position in what order. Another important point is whether you drop in the last rule of the input/output/forward chains all...
by mutluit
Sat May 30, 2020 11:48 am
Forum: General
Topic: Remote Access with Winbox stucks in login
Replies: 1
Views: 380

Re: Remote Access with Winbox stucks in login

Without seeing the config it's impossible to say anything. You have to open the port 8291/tcp in the firewall for access from WAN. But accessing the router in that way from the WAN is discouraged b/c of security considerations. See also https://forum.mikrotik.com/viewtopic.php?t=139716 Usually one u...