Community discussions

MikroTik App

Search found 769 matches

by mutluit
Sun Mar 28, 2021 5:26 pm
Forum: RouterOS v7 BETA
Topic: Possible error in DNS canonical name handling
Replies: 7
Views: 638

Re: Possible error in DNS canonical name handling

@msatter, as you already stated, with such cloud servers the underlying IP to a domain varies depending on the region/country etc. I'm getting this: :put [:resolve www.edn.com] 2.23.78.15 The question now is how to find the record that contains this IP, as it usually is not exactly the same IP but o...
by mutluit
Sun Mar 28, 2021 4:51 pm
Forum: RouterOS v7 BETA
Topic: Possible error in DNS canonical name handling
Replies: 7
Views: 638

Re: Possible error in DNS canonical name handling

Address list uses resolved IP addresses (repeats resolving after DNS record TTL expires so it keeps IP address semi-uptodate) ... since ultimate destination is some akamai cloud address, it could be same IP address is whitelisted for some other domain. If you want to block according to FQDN, you ei...
by mutluit
Sun Mar 28, 2021 3:58 pm
Forum: RouterOS v7 BETA
Topic: Possible error in DNS canonical name handling
Replies: 7
Views: 638

Re: Possible error in DNS canonical name handling

The CNAME is indeed the cause of this. Looking at Pi-hole it will block www.edn.com.edgekey.net if it is in a list used to block domains. They use Whitelisting and that will match the domain you type and will ignore blocking and you will access that domain. RouterOS DNS will resolve in one go, as i...
by mutluit
Sun Mar 28, 2021 2:48 pm
Forum: RouterOS v7 BETA
Topic: Possible error in DNS canonical name handling
Replies: 7
Views: 638

Possible error in DNS canonical name handling

I'm using the DNS in my router (hAP ac^2 with RouterOS 7.1beta3). I'm by default blocking all outgoing (as well incoming) traffic, I do allow it only by explicitly adding the address to an "allow" list. This works fine, but today I experienced this funny problem: the address www.edn.com ge...
by mutluit
Tue Nov 10, 2020 7:35 pm
Forum: RouterOS v7 BETA
Topic: Why DNS-record updates not working?
Replies: 16
Views: 935

Re: Why DNS-record updates not working?

So client first resolves the name to get address, and then it connects to that address. There's no direct relation between that, in a way that router can see (there goes your previous idea that router could check for connection failures). I think the problem in RouterOS can be solved as follows: af...
by mutluit
Tue Nov 10, 2020 6:57 pm
Forum: RouterOS v7 BETA
Topic: Why DNS-record updates not working?
Replies: 16
Views: 935

Re: Why DNS-record updates not working?

There's no need to blame DNS server in RouterOS - that works as expected and is completely unrelated to your problem. The address list is something completely different, and it can not be use (reliably) the way you expect it. Maybe it's just an address list issue, not DNS. I'm using the address lis...
by mutluit
Tue Nov 10, 2020 5:01 pm
Forum: RouterOS v7 BETA
Topic: Why DNS-record updates not working?
Replies: 16
Views: 935

Re: Why DNS-record updates not working?

But that is how things work. What do you think this should work like? After each connection failure, RouterOS should check whether the IP/domain is covered in its local DNS, and if yes, then check/verify whether its A record is still valid... Because: currently I have manually to do these 2 damn st...
by mutluit
Tue Nov 10, 2020 4:54 pm
Forum: RouterOS v7 BETA
Topic: Why DNS-record updates not working?
Replies: 16
Views: 935

Re: Why DNS-record updates not working?

The domain has a time to live (ttl) of 299 seconds. RouterOS caches the record for this time, see / ip dns cache.
This is correct behavior and should not be changed.
But this is not user-friendly. I mean just think practically....
by mutluit
Tue Nov 10, 2020 4:37 pm
Forum: RouterOS v7 BETA
Topic: Why DNS-record updates not working?
Replies: 16
Views: 935

Why DNS-record updates not working?

Hi, imagine this real scenario: for example the domain consent.youtube.com has one IP, but it changes often (like a dynamic IP, but I rather think YT changes the f*cking IP intentionally). When the IP changes then the DNS server in RouterOS still gives the old, now invalid, IP, which of course isn't...
by mutluit
Tue Nov 10, 2020 1:47 pm
Forum: RouterOS v7 BETA
Topic: Error: DNS adding domain name with Umlaut [SOLVED]
Replies: 10
Views: 818

Re: Error: DNS adding domain name with Umlaut [SOLVED]

You have to use IDN encoding. Try this: xn--allestrungen-9ib.de
Thanks! This seems to work. But I wonder how to figure/decipher/decode/understand this.
by mutluit
Tue Nov 10, 2020 1:32 pm
Forum: RouterOS v7 BETA
Topic: Error: DNS adding domain name with Umlaut [SOLVED]
Replies: 10
Views: 818

Error: DNS adding domain name with Umlaut [SOLVED]

Hi,
how do I add this domain name "allestörungen.de" to the DNS (into an allow list)?
The problem is: the domain name has an Umlaut ("ö"), but in the MiktoTik console it's not possible to type that character :-(
Has this been fixed in recent MiktoTik OS versions?
Thx
by mutluit
Sat Jul 18, 2020 1:51 am
Forum: Beginner Basics
Topic: hAP ac2 – slow transfer speed between vlans
Replies: 14
Views: 3861

Re: hAP ac2 – slow transfer speed between vlans

I too had experienced similar dropping performance problems with the same router. The reason was non-optimal firewall rules. After fixing it the performance came back to about 950 Mbps from previous about 250 Mbps. WAN/LAN as well LAN/LAN as well sameLAN. I would suggest to try the following rules a...
by mutluit
Sat Jul 18, 2020 12:48 am
Forum: RouterOS v7 BETA
Topic: Traffic to blocked address still succeeds. Why? A bug?
Replies: 24
Views: 5413

Re: Traffic to blocked address still succeeds. Why? A bug?

But remember, MITM = bad. Whole point of HTTPS (or generally SSL/TLS) is to protect data, which includes preventing MITM. Client needs to be sure that it got exactly what server sent and nobody tampered with it. Or if someone did, client can detect it. When you do MITM, you take this away. Proxy us...
by mutluit
Fri Jul 17, 2020 10:03 pm
Forum: RouterOS v7 BETA
Topic: Traffic to blocked address still succeeds. Why? A bug?
Replies: 24
Views: 5413

Re: Traffic to blocked address still succeeds. Why? A bug?

Maybe a little bit off-topic, I apologize in advance, but just for the sake of completeness: Since the web proxy " privoxy " was mentioned many times in this thread: I just found some brand new important information regarding http s -traffic that says this: Privoxy now has the ability to a...
by mutluit
Fri Jul 17, 2020 7:25 pm
Forum: RouterOS v7 BETA
Topic: Traffic to blocked address still succeeds. Why? A bug?
Replies: 24
Views: 5413

Re: Traffic to blocked address still succeeds. Why? A bug?

Here's an example with URL https://www.tomshardware.com/ that explains my said method of "block all outbound by default": The log below is of the said web proxy privoxy (using "debug 512" in its config for this log format). Initially my firewall blocks it (code 503) as I haven't ...
by mutluit
Fri Jul 17, 2020 5:22 pm
Forum: RouterOS v7 BETA
Topic: Traffic to blocked address still succeeds. Why? A bug?
Replies: 24
Views: 5413

Re: Traffic to blocked address still succeeds. Why? A bug?

Privoxy cannot decrypt https, no. It cannot look in your HTML or in your URL. But then I wonder how this is then technically working. The proxy is in the middle, it is the one that connects to the remote. That's at least what I was assuming. So, then I wonder what happens next. Can you elaborate? T...
by mutluit
Fri Jul 17, 2020 5:06 pm
Forum: RouterOS v7 BETA
Topic: Traffic to blocked address still succeeds. Why? A bug?
Replies: 24
Views: 5413

Re: Traffic to blocked address still succeeds. Why? A bug?

@pe1chl, maybe we are talking of different things. I just mean for example the said proxy server privoxy. Do you mean it can't decrypt https? As I'm new to it, I really don't know; I just am thinking that it very well can decrypt HTML pages it gets via https. There are several forms of proxy methods...
by mutluit
Fri Jul 17, 2020 4:49 pm
Forum: RouterOS v7 BETA
Topic: Traffic to blocked address still succeeds. Why? A bug?
Replies: 24
Views: 5413

Re: Traffic to blocked address still succeeds. Why? A bug?

@pe1chl, correct me, but I think you are talking of two-way authentication via certs.
But I know of no public site where this is used, in 99+% only the server side is authenticated by the certs, but not the user side.
by mutluit
Fri Jul 17, 2020 4:35 pm
Forum: RouterOS v7 BETA
Topic: Traffic to blocked address still succeeds. Why? A bug?
Replies: 24
Views: 5413

Re: Traffic to blocked address still succeeds. Why? A bug?

MikroTik is not in this game as its layer 7 mechanism is a toy [because it cannot do decryption] so all https traffic cannot be inspected. Perhaps in the near future MikroTik will have a 3rd gen engine --- this is not a cheap en devour. That problem of encrypted traffic (https) is IMO easily solvab...
by mutluit
Fri Jul 17, 2020 3:39 pm
Forum: RouterOS v7 BETA
Topic: Traffic to blocked address still succeeds. Why? A bug?
Replies: 24
Views: 5413

Re: Traffic to blocked address still succeeds. Why? A bug?

You will have to live with the fact that makers of systems are moving more and more towards setups where a network administrator cannot filter or block the traffic! In the past, you could filter on port numbers, redirect traffic to some ports to other destinations (DNS port 53), peek in traffic to ...
by mutluit
Fri Jul 17, 2020 1:38 pm
Forum: RouterOS v7 BETA
Topic: Traffic to blocked address still succeeds. Why? A bug?
Replies: 24
Views: 5413

Re: Traffic to blocked address still succeeds. Why? A bug?

any proxy is generally very powerful because it actually processes the request (therefore it understands exactly what is being requested and returned) but https proxies are also serious security threat - for HTTPS or generally SSL encrypted traffic (nowadays majority of internet traffic) you need t...
by mutluit
Fri Jul 17, 2020 12:24 pm
Forum: RouterOS v7 BETA
Topic: Traffic to blocked address still succeeds. Why? A bug?
Replies: 24
Views: 5413

Re: Traffic to blocked address still succeeds. Why? A bug?

Force the DNS resolver to a server you have under control and null the blocked domains out there. What about the proxies " privoxy " (http/https proxy) and " Pi-hole " (DNS proxy): can these be used for this problem? Privoxy I'm already using since a few days now, but haven't st...
by mutluit
Fri Jul 17, 2020 5:33 am
Forum: RouterOS v7 BETA
Topic: Traffic to blocked address still succeeds. Why? A bug?
Replies: 24
Views: 5413

Re: Traffic to blocked address still succeeds. Why? A bug?

@Sob, thanks for the explanation. I now see the underlying problem. You said "That's the problem with this kind of blocking." So, does this statement imply that there is (or even are) some other blocking methods possible for this problem case? I can force all clients to use the same one DN...
by mutluit
Fri Jul 17, 2020 2:55 am
Forum: RouterOS v7 BETA
Topic: Traffic to blocked address still succeeds. Why? A bug?
Replies: 24
Views: 5413

Traffic to blocked address still succeeds. Why? A bug?

I have the address "android.clients.google.com" in the address-lists "deny" and "deny_nolog", and two firewall rules to drop all packets to all the IPs behind that address. Still, occassionally it happens that the blocking isn't working! Why? What's the reason? Btw. how...
by mutluit
Tue Jul 14, 2020 9:57 pm
Forum: RouterOS v7 BETA
Topic: Feature Request: show also "action" in log line
Replies: 0
Views: 639

Feature Request: show also "action" in log line

I'm currently working on the firewall and miss the fact that the log line does not show the action.
Of course one can add an own comment via log-prefix="...", but IMO it would be better if action=... would be printed by default in the log line.
by mutluit
Sat Jul 11, 2020 6:01 pm
Forum: General
Topic: Cant login after security measures
Replies: 3
Views: 995

Re: Cant login after security measures

Hi everyone, I've just set up most of the security steps suggested en Mikrotik wiki https://wiki.mikrotik.com/wiki/Manual:Securing_Your_Router#RouterOS_services Left ssh and winbox service, each one in differents ports ( not the standard ones ) . Works well yesterday but today I receive this messag...
by mutluit
Sat Jul 11, 2020 5:40 pm
Forum: General
Topic: Local domain with Mikrotik
Replies: 5
Views: 2616

Re: Local domain with Mikrotik

The problem I have is that they must specify the port to this url, thus leaving http://turno.sys :3010 I just want to type http://turno.sys and have mikrotik take care of indicating this port 3010 Use port 80 instead of 3010, then it will work. With other port numbers this cannot work. http uses po...
by mutluit
Sat Jul 11, 2020 11:07 am
Forum: General
Topic: Cannot download at 10 gbps [SOLVED]
Replies: 23
Views: 4505

Re: Cannot download at 10 gbps [SOLVED]

@benc1337, can you test also the performance of this setup on the router: 10G_MacbookPro <--> 10G_WAN(sfp-sfpplus1) <--> 10G_LAN(sfp-sfpplus2) <--> 10G_NAS It seems IP of WAN is missing. WAN and the LAN bridge should each have their own IPs [they then serve as the gateway address for the attached cl...
by mutluit
Fri Jul 10, 2020 9:36 pm
Forum: RouterOS v7 BETA
Topic: bug in beta8: firewall address-list in Webfig gets permanently sorted
Replies: 0
Views: 561

bug in beta8: firewall address-list in Webfig gets permanently sorted

Observed in beta8: This Webfig page http://192.168.88.1/webfig/#IP:Firewall.Address_Lists is permanently sorting the list. It's unnecessary, doesn't make any sense, and eats up CPU cycles. It should be re-sorted only if a change to the list happens. In my case I'm maintaining the list manually, ie. ...
by mutluit
Fri Jul 10, 2020 8:46 pm
Forum: General
Topic: Cannot download at 10 gbps [SOLVED]
Replies: 23
Views: 4505

Re: Cannot download at 10 gbps [SOLVED]

Normis, am I way off base here, or should I send you to jail??? ;-) LOL :-). Yes, you're off base. It's not the physical interfaces, but the number of data streams like TCP sessions that matters. Across the Internet, you don't need to have 10G to run into this; that's why things like BitTorrent and...
by mutluit
Fri Jul 10, 2020 8:27 pm
Forum: RouterOS v7 BETA
Topic: v7 and mellanox 100G connectX5 MT27800
Replies: 4
Views: 1761

Re: v7 and mellanox 100G connectX5 MT27800

any news about v7 supporting 100G port modules by mellanox connectX5 with chipset MT27800? I see on the speed interface configuration we can only choose 40gbps; any update on supporting also 100G cards? I saw offers of such 100G cards, even dual-port for about $390. The card uses PCIe 3.0 x8: https...
by mutluit
Fri Jul 10, 2020 7:48 pm
Forum: RouterOS v7 BETA
Topic: Feature Request: firewall: besides remote IP:port log optionally also its hostname
Replies: 2
Views: 828

Re: Feature Request: firewall: besides remote IP:port log optionally also its hostname

I'm not sure if this should be done on the Mikrotik itself. Again wasting valuable cpu-cycles on this. If you have a large(r) infrastructure I don't think you are going to look at the logs through Winbox or Webfig but you are going to push these logs into something else (eg. Splunk) or some custom ...
by mutluit
Fri Jul 10, 2020 7:27 pm
Forum: General
Topic: Mikrotik CRS125-24G Speed Problem
Replies: 13
Views: 2516

Re: Mikrotik CRS125-24G Speed Problem

Folks, sorry, I'm suddenly having similar performance problems like the OP :-( I can swear I had about 950 Mbps download speed in the past, but now getting only about 250 Mbps :-( I don't know what the reason is, but suspect firewall and/or the latest beta8 I'm using. Update: hmm. I now remember I p...
by mutluit
Fri Jul 10, 2020 5:58 pm
Forum: General
Topic: Cannot download at 10 gbps [SOLVED]
Replies: 23
Views: 4505

Re: Cannot download at 10 gbps [SOLVED]

Maybe your firewall rules on your CCR are not optimal. See this posting for verifcation and fixing:
viewtopic.php?f=2&t=163454&p=805142#p805135
by mutluit
Fri Jul 10, 2020 5:39 pm
Forum: General
Topic: Mikrotik CRS125-24G Speed Problem
Replies: 13
Views: 2516

Re: Mikrotik CRS125-24G Speed Problem

Your Huawei Router is connected to what port? If it is connected to ether1 your CRS is not working as switch but additional router. Disable DHCP server, plug the Huawei Router to any other port and try again. Hmm. I would suggest to have each device have its own LAN, ie. 2 independent local IP netw...
by mutluit
Fri Jul 10, 2020 5:19 pm
Forum: General
Topic: Mikrotik CRS125-24G Speed Problem
Replies: 13
Views: 2516

Re: Mikrotik CRS125-24G Speed Problem

In the firewall your first two rules should be like these: /ip firewall filter add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related add action=accept chain=forward comment="defconf: accept established,related, untracked" ...
by mutluit
Fri Jul 10, 2020 4:44 pm
Forum: RouterOS v7 BETA
Topic: Feature Request: firewall: besides remote IP:port log optionally also its hostname
Replies: 2
Views: 828

Feature Request: firewall: besides remote IP:port log optionally also its hostname

The current format of logging is as follows ("R1" and "TEST" are user specified strings): Jul 10 15:15:02 192.168.xxx.xxx firewall,info R1: TEST forward: in:ether2 out:ether1, src-mac xx:xx:xx:xx:xx:xx, proto TCP (SYN), 192.168.xxx.xxx:56620->137.xxx.xxx.xxx:443, len 52 It would ...
by mutluit
Fri Jul 10, 2020 4:12 pm
Forum: Beginner Basics
Topic: Proxy connect in log
Replies: 4
Views: 992

Re: Proxy connect in log

I don't know the official answer, but I guess it just means the proxy has got the request (ie. the job, order, task) to connect to the specified remote site. You could do a small experiment by first connecting to an existing page of a site, and then attempting to connect to a non-existing page of th...
by mutluit
Thu Jul 09, 2020 10:44 pm
Forum: Beginner Basics
Topic: How to set uplink port on CRS305-1G-4S+? Why is POE not working?
Replies: 1
Views: 489

Re: How to set uplink port on CRS305-1G-4S+? Why is POE not working?

2) I get very low speeds towards my NAS. It is as if the switch were using the ETH/Boot port as the uplink instead of the SFP+4 port. How do I tell the switch to only use ETH/Boot for management, and port SFP+4 for uplink to core switch? It surely is a routing problem. For an analysis at least the ...
by mutluit
Thu Jul 09, 2020 10:18 pm
Forum: RouterOS v7 BETA
Topic: Add RTL8125B driver request
Replies: 3
Views: 1562

Re: Add RTL8125B driver request

Indeed a very interesting piece of hardware. The CPU is 4C/4T:
https://ark.intel.com/content/www/us/en ... 0-ghz.html
by mutluit
Thu Jul 09, 2020 9:50 pm
Forum: RouterOS v7 BETA
Topic: Feature or Bugfix Request: ip firewall addess-list import shall not abort when dupe seen [SOLVED]
Replies: 4
Views: 1493

Feature or Bugfix Request: ip firewall addess-list import shall not abort when dupe seen [SOLVED]

Observed in beta8: Currently when importing addresses into "/ip firewall address-list" the import aborts with an error message when it sees a dupe address that already is in the list. This behavior of aborting the importing process is unnecessary, IMO even incorrect. It rather shall simply...
by mutluit
Thu Jul 09, 2020 7:01 pm
Forum: Beginner Basics
Topic: Proxy connect in log
Replies: 4
Views: 992

Re: Proxy connect in log

Which device, which firmware & version, and what do you mean by "proxy log" and "proxy connect"?
Just post a sanitized excerpt from the log for analysis.
by mutluit
Thu Jul 09, 2020 6:17 pm
Forum: General
Topic: Web server is up, but not responding.
Replies: 5
Views: 1161

Re: Web server is up, but not responding.

It could be also an issue with the local firewall on the PC.
by mutluit
Thu Jul 09, 2020 12:03 pm
Forum: General
Topic: 50mbps down / 100 mpbs up wifi ac2
Replies: 5
Views: 1242

Re: 50mbps down / 100 mpbs up wifi ac2

The ac^2 has 2 bands: wlan1: 2.4GHz and wlan2: 5GHz
In my region wlan2 is about twice faster than wlan1.
Ie. you should test the wlan interfaces individually.
by mutluit
Wed Jul 08, 2020 8:46 pm
Forum: General
Topic: crs326
Replies: 1
Views: 350

Re: crs326

Any related entries in the log?
Maybe an heat issue. Check the temperature.
by mutluit
Wed Jul 08, 2020 8:33 pm
Forum: General
Topic: SMS receive 'allowed-number' multiple numbers [SOLVED]
Replies: 9
Views: 2071

Re: SMS receive 'allowed-number' multiple numbers [SOLVED]

The following gets accepted, but don't know whether it works in practice: /tool sms set allowed-number="+447xxxxxxxxx,+447xxxxxxxx" "/tool/sms print" says then: ... allowed-number: +447xxxxxxxxx,+447xxxxxxxx ... OTOH entering the numbers via the GUI interface one by one does the ...
by mutluit
Wed Jul 08, 2020 7:57 pm
Forum: General
Topic: Web server is up, but not responding.
Replies: 5
Views: 1161

Re: Web server is up, but not responding.

Maybe an issue with the web-browser. Try another one. Hmm. I see you already tried curl. Then it seems to be a firewall issue, IMO. Check the rules under "/ip firewall filter" etc. And if applicable also those under "/interface ethernet switch rule" for ACL rules. You can also ad...
by mutluit
Wed Jul 08, 2020 7:08 pm
Forum: General
Topic: Weird Routing problems [SOLVED]
Replies: 10
Views: 2068

Re: Weird Routing problems [SOLVED]

Please Nobody? Don't have experience with CapsMan. Without CapsMan I assign the wlanX a gateway IP, then the client can ping the others. Of course under DHCPServer / Networks one has to list the network(s) of the wlanX. If the client has more than one interface then maybe it's trying to go over the...
by mutluit
Wed Jul 08, 2020 6:54 pm
Forum: General
Topic: SFP+RJ10 - What am I doing Wrong??
Replies: 13
Views: 2350

Re: SFP+RJ10 - What am I doing Wrong??

The interface print doesn't show anything useful, what were you expecting??
I will try to play with this today and get the mac add answers for you.
"/interface print" should list all interfaces (etherX plus MACs, etc.).
Either you had a typo, or your device is totally broken.
by mutluit
Wed Jul 08, 2020 6:00 pm
Forum: General
Topic: SEPARATING TCP AND UDP ON EACH ISP
Replies: 1
Views: 922

Re: SEPARATING TCP AND UDP ON EACH ISP

I have 2 ISPs, and my design is to have Load balance and failover config on my RB3011, the condition i made is this; TCP (Browsing) is going to ISP1 while UDP (which of course Streaming Videos) is going to ISP2 Which public streaming service uses UDP ? The three I know (youtube, netflix, amazon-pri...
by mutluit
Wed Jul 08, 2020 5:10 pm
Forum: General
Topic: Looking for address-list of google and amazon [SOLVED]
Replies: 0
Views: 527

Looking for address-list of google and amazon [SOLVED]

Has someone an address-list of all IP-blocks of google and amazon? Update: Found a list and a generic method by querying the SPF records in DNS: All actual Google ipv4 and ipv6 adresses based on Google's SPF records: https://md5calc.com/google/ip Same method should be applicable with any such compan...
by mutluit
Wed Jul 08, 2020 4:51 pm
Forum: Beginner Basics
Topic: Basic Country blocking
Replies: 1
Views: 400

Re: Basic Country blocking

If you include "src-address=!local" in the blocking rule that uses the src-address-list then it should exclude local users. ie. something like that: add action=drop chain=input comment="Drop all traffic from addresses on \"CountryIPBlocks\" address list" \ src-address-l...
by mutluit
Wed Jul 08, 2020 3:51 pm
Forum: Beginner Basics
Topic: Open Access to TikApp
Replies: 6
Views: 1488

Re: Open Access to TikApp

How do i allow access to the box from lan without needs to port knock?
Grant access to the service for the allowed clients. There are many methods possible: firewall settings, services settings, user settings, depending on the port/service. You haven't stated what port or service it is.
by mutluit
Wed Jul 08, 2020 3:23 pm
Forum: Beginner Basics
Topic: Getting mixed speeds on CRS305-1G-4S+IN
Replies: 3
Views: 1734

Re: Getting mixed speeds on CRS305-1G-4S+IN

@saudkh, for such tests you should create a lab environment: unplug WAN, use static IPs, and connect the 2 PCs to the switch and do your iperf tests. For such a test your both PCs should better be in the same LAN. If it still doesn't work, then post your config: "/export hide-sensitive file=con...
by mutluit
Tue Jul 07, 2020 12:40 am
Forum: General
Topic: Performance Problem ?
Replies: 4
Views: 1043

Re: Performance Problem ?

Is your 10G interface listed under WAN? (/interface list member print)
Without seeing your config settings nobody really can help. One needs to see the settings of the involved interfaces, incl. all the involved IPs, as well the route table etc.
by mutluit
Tue Jul 07, 2020 12:36 am
Forum: General
Topic: export tool bug inquiry
Replies: 4
Views: 934

Re: export tool bug inquiry

In the export tools there appears to be a bug in the Interfaces section. Some of the ports that were set for faster speeds than 100mbps get set to 100mbps. Is that something that has already been reported and is being looked into? Which device and which firmware version? Can the interface handle fa...
by mutluit
Sun Jul 05, 2020 2:35 pm
Forum: Scripting
Topic: Extracting last SMS number [SOLVED]
Replies: 9
Views: 1974

Re: Extracting last SMS number [SOLVED]

More research suggests /tool sms inbox get $i phone doesn't use the index so using my count - 1 method won't work . However `/tool sms inbox find` still returns nothing Try this: :global lastIx ([:len /tool sms inbox] - 1) :global lastNum [/tool sms inbox get number=$lastIx phone] :put $lastNum ......
by mutluit
Sun Jul 05, 2020 3:35 am
Forum: Scripting
Topic: Extracting last SMS number [SOLVED]
Replies: 9
Views: 1974

Re: Extracting last SMS number [SOLVED]

More research suggests /tool sms inbox get $i phone doesn't use the index so using my count - 1 method won't work . However `/tool sms inbox find` still returns nothing Try this: :global lastIx (:len [/tool sms inbox] - 1) :global lastNum [/tool sms inbox get number=$lastIx phone] :put $lastNum ......
by mutluit
Sun Jul 05, 2020 2:34 am
Forum: Beginner Basics
Topic: Basic bandwidth limiting
Replies: 14
Views: 2340

Re: Basic bandwidth limiting

The following CLI command limits both upload and download to 1Mbps for clients in LAN 192.168.128.0/24 behind ether3: /queue simple add name=myRateLimiting target=192.168.128.0/24 max-limit=1M/1M dst=ether3 with "print" you can see it with the other fields it has, for example: print Flags:...
by mutluit
Sun Jul 05, 2020 1:36 am
Forum: Beginner Basics
Topic: Use Hosting ip to my server for home Solutions?
Replies: 2
Views: 535

Re: Use Hosting ip to my server for home Solutions?

Is this for just a few select TCP/UDP ports, or do you rather want redirect/forward much more traffic to your home server(s)? If your home IP(s) is/are really static then that's an advantage, but then one wonders why you need the IPs from the hoster? Because you could just enter your static home IP ...
by mutluit
Sun Jul 05, 2020 1:17 am
Forum: Beginner Basics
Topic: All SFP+ traffic is routed across 1Gb ethernet
Replies: 3
Views: 542

Re: All SFP+ traffic is routed across 1Gb ethernet

Check your routes on that device ( /ip route print ).

Best is to issue the following command, and then download the file (export-hs.rsc) and post its content:
/export file=export-hs hide-sensitive
by mutluit
Sun Jul 05, 2020 12:45 am
Forum: General
Topic: Inbound SMS run script pass number [SOLVED]
Replies: 8
Views: 1989

Re: Inbound SMS run script pass number [SOLVED]

See https://shop.duxtel.com.au/article_info.php?articles_id=25 It says: RouterOS lists such modems as serial port that appears in '/port print' listing. The following command can be issued to send SMS: /tool sms send port=port dst-smsc=smsc message=message Example: /tool sms send port=usb3 "04X...
by mutluit
Sat Jul 04, 2020 6:22 pm
Forum: General
Topic: User restricted to serial login
Replies: 2
Views: 674

Re: User restricted to serial login

I'm looking to create a user that can only login via the serial interface. (console port) I thought about setting its allowed address to 0.0.0.0/32. That should at least prohibit any IP connection attemps, right? Would this still allow MAC connections? We'll probably disable that, so that's fine. I...
by mutluit
Sat Jul 04, 2020 3:32 pm
Forum: General
Topic: Inbound SMS run script pass number [SOLVED]
Replies: 8
Views: 1989

Re: Inbound SMS run script pass number [SOLVED]

I'm trying to write a script so when the Mikrotik receives an SMS it runs the script, gathers some information from the Mikrotik, and then sends an SMS back to the number that sent the request. Is there any way to pass the phone number of the incoming message to the script so it can be used within ...
by mutluit
Sat Jul 04, 2020 3:14 pm
Forum: General
Topic: Weird perfomance! [SOLVED]
Replies: 8
Views: 1927

Re: Weird perfomance! [SOLVED]

For CRS3xx the docs say that currently HW Offloading is effective only on one bridge.
Not sure whether this applies to your CRS model(s) as well, so check the docs.
by mutluit
Fri Jul 03, 2020 11:43 pm
Forum: General
Topic: Hacking attempt from AVM WAN router to hosts in LAN ? [SOLVED]
Replies: 2
Views: 1066

Re: Hacking attempt from AVM WAN router to hosts in LAN ? [SOLVED]

The AVM Fritz devices use a check on port 80 to see if a PC has a web server running to show it in its web interface: The FRITZ!Box uses TCP port 80 to check regularly whether computers or other devices connected to the FRITZ!Box offer web services accessible over HTTP, such as a user interface. Th...
by mutluit
Fri Jul 03, 2020 10:57 pm
Forum: General
Topic: Hacking attempt from AVM WAN router to hosts in LAN ? [SOLVED]
Replies: 2
Views: 1066

Hacking attempt from AVM WAN router to hosts in LAN ? [SOLVED]

Hi, network security analysts, what do you make up of this? : I've activated logging for the default firewall rule that says in its comment field "defconf: drop all from WAN not DSTNATed". And in the log I find the following very suspicious entries. For orientation: the WAN router is an AV...
by mutluit
Fri Jul 03, 2020 4:06 am
Forum: Beginner Basics
Topic: What stops me from reaching the web interface?
Replies: 1
Views: 547

Re: What stops me from reaching the web interface?

You should post the output of:
/ip export hide-sensitive
by mutluit
Fri Jul 03, 2020 3:55 am
Forum: Beginner Basics
Topic: IP conflict on WAN interface
Replies: 1
Views: 376

Re: IP conflict on WAN interface

Check this:
https://wiki.mikrotik.com/wiki/Manual:Interface/PPPoE
"It is advised not to use static IP addresses or DHCP on the same interfaces as PPPoE for obvious security reasons."

verify with this:
/ip address print

or in GUI under IP / Addresses
by mutluit
Fri Jul 03, 2020 3:19 am
Forum: General
Topic: Port mode access on crs3xx ether type 0x88a8
Replies: 1
Views: 586

Re: Port mode access on crs3xx ether type 0x88a8

Hello everyone, I'm trying to put a crs328 port in access mode and it doesn't work when ether type = 0x88a8 could someone help me with this situation? What is not working, what are the symptoms, which firmware and version? I myself don't use VLAN, but IMO it should be something like this: :global m...
by mutluit
Wed Jul 01, 2020 10:31 pm
Forum: General
Topic: Traffic Generator - Big vs small packets (strange) results
Replies: 7
Views: 1342

Re: Traffic Generator - Big vs small packets (strange) results

@dadox, can you briefly describe what is so puzzling for you? Update: ok, got it: you mean the difference between Tx and Rx packets in the 2nd table... Easy explanation: some "TCP resend" packets occured, that's IMO normal. Similar differences are present also in 1st table, maybe you overl...
by mutluit
Wed Jul 01, 2020 9:12 pm
Forum: General
Topic: Traffic generated by the switch doesn't respect VRF segregation
Replies: 4
Views: 1082

Re: Traffic generated by the switch doesn't respect VRF segregation

The whole point of a VRF is to have separate routing tables, different virtual routing instances. I am not fully into mikrotik way of thinking but this behavior sounds more like a bug to be honest... And my understanding is that this happens since router OS doesn't really use different routing tabl...
by mutluit
Wed Jul 01, 2020 8:08 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 63
Views: 10167

Re: LAN to LAN forwarding [SOLVED]

Glad to see that @Diresta's problem of transparent port-forwarding within the same LAN has been solved by using iptables' port-forwarding function on the old server(s). It would have functioned also centrally on a Linux router with iptables as shown in posting #41 https://forum.mikrotik.com/viewtopi...
by mutluit
Tue Jun 30, 2020 11:13 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 63
Views: 10167

Re: LAN to LAN forwarding [SOLVED]

No, it doesn't work here, though I haven't tried other ROS versions. Such a task should be doable centrally on a router or switch with just a few firewall rules, nothing more. You OTOH seem to say one needs to reconfigure the net. Never mind, I've seen enough and experienced enough. You clearly sti...
by mutluit
Tue Jun 30, 2020 10:56 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 63
Views: 10167

Re: LAN to LAN forwarding [SOLVED]

@xvo, FYI: here's a solution using iptables on a linux router with a bridge. It reads "Port forwarding between bridged interfaces": https://askubuntu.com/questions/720207/port-forwarding-between-bridged-interfaces It's a similar problem-case: moving services from one host to another host ...
by mutluit
Tue Jun 30, 2020 9:33 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 63
Views: 10167

Re: LAN to LAN forwarding [SOLVED]

But you have to admit that it's not satisfactorily if it works as wished/intended from other LANs and WAN, but not from inside the same LAN. One has to question why ROS can't handle that, don't you agree? I would classify that as a bug, or at least as a shortcoming or as a missing capability... And...
by mutluit
Tue Jun 30, 2020 7:29 pm
Forum: Beginner Basics
Topic: Improve my set-up (extend WiFi and host a server)
Replies: 2
Views: 611

Re: Improve my set-up (extend WiFi and host a server)

ISP ===> Router in the attic ===> hAP lite 1 (office) ===> hAP lite 2 (living room) 2. Make the web server on my main PC accessible from outside (I want to host a Foundry VTT game) For the above you need to find out the port number(s) (0 to 65535) and their protocol (tcp, udp etc.) [ie. in your cas...
by mutluit
Tue Jun 30, 2020 6:54 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 63
Views: 10167

Re: LAN to LAN forwarding [SOLVED]

The problem with RouterOS seems to be that port-forwarding using DNAT/SNAT within the same LAN seems not possible. In my experiments here so far port-forwarding in ROS works only for clients from other LANs as well from the WAN side, but not from inside the same LAN. It's not a RouterOS problem. Ac...
by mutluit
Tue Jun 30, 2020 12:22 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 63
Views: 10167

Re: LAN to LAN forwarding [SOLVED]

@Diresta, which RouterOS version does your device have? And can you post the output of this: /interface export hide-sensitive And: together with the new servers will also the old servers be online at the same time during the transition phase? If yes, and if your servers do have iptables, then you co...
by mutluit
Tue Jun 30, 2020 6:36 am
Forum: General
Topic: Intermittent timeout when trying to ssh or webfig into CRS328
Replies: 1
Views: 486

Re: Intermittent timeout when trying to ssh or webfig into CRS328

Take 1 of the ports out of the bridge, give it an IP/mask (for example 192.168.128.254/24, ie. creating a new LAN 192.168.128.0/24), and attach a host to that port, and try ssh & webfig from that host to that new gateway IP (ie. login to the CRS via this new gateway IP). Of course with the above...
by mutluit
Tue Jun 30, 2020 3:40 am
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 63
Views: 10167

Re: LAN to LAN forwarding [SOLVED]

I don't exactly understand what is that thing, that is working, for you have only one host on your LAN in your example. And even if there is a thing, and it is actually working, how is it supposed to continue to work after you put two hosts on one dumb switch?! These two hosts will connect to each ...
by mutluit
Tue Jun 30, 2020 3:29 am
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 63
Views: 10167

Re: LAN to LAN forwarding [SOLVED]

@Sob, your solution is very interesting, but unfortunately in current beta8 it hangs in a loop so that the router reboots endlessly :-( I suspect it is the masquerade rule with src-addr and dst-addr equal. But if it works well with stable/long-term version than it could indeed be the solution for th...
by mutluit
Mon Jun 29, 2020 9:52 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 63
Views: 10167

Re: LAN to LAN forwarding [SOLVED]

@xvo, "that thing..." gave me a good laugh. Might be a solution, but that will mean all clients will have to be reconfigured to point to WAN address and not internal address of server Hmm. yes, you are right. But I think that problem is solvable too. I'll check. Update: I now tested using...
by mutluit
Mon Jun 29, 2020 9:34 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 63
Views: 10167

Re: LAN to LAN forwarding [SOLVED]

I don't exactly understand what is that thing, that is working, for you have only one host on your LAN in your example. And even if there is a thing, and it is actually working, how is it supposed to continue to work after you put two hosts on one dumb switch?! These two hosts will connect to each ...
by mutluit
Mon Jun 29, 2020 9:02 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 63
Views: 10167

Re: LAN to LAN forwarding [SOLVED]

ATTN everybody! I now have found a solution. Will post it shortly. But it works only if no bridge is configured in RouterOS :-( Could be a ROS bug... Then how exactly did you create a Layer 2 Broadcast Domain if you configured no Bridge ? Just assign an IP to the router port, for example ether2: 19...
by mutluit
Mon Jun 29, 2020 8:38 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 63
Views: 10167

Re: LAN to LAN forwarding [SOLVED]

Ok, here's the said solution: Solution for port forwarding for both WAN-to-LAN as well LAN-to-LAN (incl. inside same LAN): On my router (hAP ac^2 with RouterOS 7.0beta8) with no NAT (ie. as 2nd router) now the following solution works: IP of WAN interface (ether1): 192.168.254.253/24 IP of ether2 (i...
by mutluit
Mon Jun 29, 2020 8:23 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 63
Views: 10167

Re: LAN to LAN forwarding [SOLVED]

ATTN everybody!
I now have found a solution. Will post it shortly. But it works only if no bridge is configured in RouterOS :-( Could be a ROS bug...
by mutluit
Mon Jun 29, 2020 6:21 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 63
Views: 10167

Re: LAN to LAN forwarding [SOLVED]

@sindy, I'm looking for a solution for port-forwarding from lanIP1:port to lanIP2:port within the same LAN. Is there a solution available for this (simpler) problem?
Ie. connections to 192.168.88.12:8512/tcp shall be (on the router) redirected to 192.168.88.11:8511
by mutluit
Mon Jun 29, 2020 5:12 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 63
Views: 10167

Re: LAN to LAN forwarding [SOLVED]

Port forwarding from wanIP:port to lanIP:port works.
What the OP wants to know is how to port forward from internal lanIP1:port to internal lanIP2:port .
Me too interested in the solution. :-)
by mutluit
Mon Jun 29, 2020 4:10 pm
Forum: RouterOS v7 BETA
Topic: beta8 bug: "scp" hangs
Replies: 0
Views: 537

beta8 bug: "scp" hangs

"ssh" login to the router (hAP ac^2) is ok. But copying a file from PC to the router using the "scp" command starts the copying, but it then hangs. On the router a temporary file name is created with size 0 bytes. (15:00:53) xxx@yyy:~/tmp$ scp -p22 test.rsc admin@192.168.127.254:...
by mutluit
Mon Jun 29, 2020 3:29 pm
Forum: Beginner Basics
Topic: Export / Import [SOLVED]
Replies: 4
Views: 1558

Re: Export / Import [SOLVED]

Via GUI you can do System/ResetConfiguration and specify the import script in the field "Run After Reset". But see also this thread for possible problems: https://forum.mikrotik.com/viewtopic.php?t=123656 Thank you very much - I will try in the next days :-) Regarding " problems &quo...
by mutluit
Sun Jun 28, 2020 6:28 pm
Forum: Beginner Basics
Topic: Export / Import [SOLVED]
Replies: 4
Views: 1558

Re: Export / Import [SOLVED]

I exported all data from my wAP #1, adapted the data inside the file and now I would like to import the data in my wAP #2 ... Is there any possibility to do it through the current/running setup on #2 or is there some need to reset #2 first and then to import afterwards ? Via GUI you can do System/R...
by mutluit
Sun Jun 28, 2020 5:52 pm
Forum: General
Topic: What network cards does RouterOS support?
Replies: 1
Views: 703

Re: What network cards does RouterOS support?

Good afternoon. Please tell me the link to the page where i can find a list of network cards for stable work with RouterOS. What max speed do you mean? Is this intended for server or workstation/PC? For upto Gigabit Ethernet I think you can take any of the common ones in the market (HP, IBM, Dell, ...
by mutluit
Sun Jun 28, 2020 5:05 pm
Forum: General
Topic: Strange problem with Internet
Replies: 8
Views: 1625

Re: Strange problem with Internet

I couldn't find whats wrong and my ISP told us that everything is fine with the line. Asking around someone suggested me to use the following rules on mikrotik chain=forward action=change-mss new-mss=1418 passthrough=yes tcp-flags=syn protocol=tcp out-interface=ether11-wan1 tcp-mss=1419-65535 log=n...
by mutluit
Sun Jun 28, 2020 4:28 pm
Forum: General
Topic: Gateway issue?
Replies: 4
Views: 986

Re: Gateway issue?

How many LANs do you have? Gateway functions upwards, not downwards. Since according to your drawing your server is connected to both routers, then it already must use two gateways. Just specify the IP of the router interface/bridge for each respective interface on the server. Normally such two rout...
by mutluit
Sun Jun 28, 2020 4:18 pm
Forum: RouterOS v7 BETA
Topic: beta5 bug: '/export verbose' hangs [SOLVED]
Replies: 10
Views: 3646

Re: beta5 bug: '/export verbose' hangs [SOLVED]

This error seems to be fixed in later versions. In 7.0beta8 it's not present (tested on router hAP ac^2).
by mutluit
Sun Jun 28, 2020 4:07 pm
Forum: RouterOS v7 BETA
Topic: beta5 bug: http Webfig downloading .txt files not working
Replies: 1
Views: 994

Re: beta5 bug: http Webfig downloading .txt files not working

That same error is present also in 7.0beta8 (tested on router hAP ac^2).
by mutluit
Sun Jun 28, 2020 3:55 pm
Forum: RouterOS v7 BETA
Topic: beta8 bug: ACL redirect-to-cpu breaks bridge
Replies: 1
Views: 784

Re: beta8 bug: ACL redirect-to-cpu breaks bridge

Error persist even when explicitly specifying "new-dst-ports=switch1-cpu", ie.:
add comment="redirect_all_traffic_to_cpu" ports=$myPorts redirect-to-cpu=yes switch=switch1 new-dst-ports=switch1-cpu disabled=no
by mutluit
Sat Jun 27, 2020 9:13 pm
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3830

Re: ACL firewall problem (missing L2 EtherType)

Only now, as looking for the difference between your setup and mine, I have noticed that you are setting the rules using ROS 7.0beta8 - it can only be seen in the export header, you don't mention that anywhere in the text. On long-term (6.45.9), I've just tried the following rules: [me@MyTik] > int...
by mutluit
Sat Jun 27, 2020 9:06 pm
Forum: RouterOS v7 BETA
Topic: beta8 bug: ACL redirect-to-cpu breaks bridge
Replies: 1
Views: 784

beta8 bug: ACL redirect-to-cpu breaks bridge

If one has as one of the very first switch ACL rules a "redirect-to-cpu all traffic" then the bridge stops functioning. Let's say bridge has own IP and has the members ether1, ether2, ether3, ether4. Then the following ACL rule will make the bridge inoperational so that attached PCs cannot...
by mutluit
Sat Jun 27, 2020 4:28 am
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3830

Re: ACL firewall problem (missing L2 EtherType)

More insights:

Besides mac-protocol=arp also mac-protocol=ip has problems, as it does not map to its EtherType 0x0800.

This means one needs both the name variant as well the number variant when adding these rules into the rule table.

About the reasons one can only speculate...
by mutluit
Sat Jun 27, 2020 3:26 am
Forum: General
Topic: bridge filter CRS326
Replies: 6
Views: 1511

Re: bridge filter CRS326

Yes switch rules with new-dst-ports="" are working (packets successfully dropped), but this is ingress packets. I'm trying to block output packets. You can do that via src-address (IP address/Mask) Ie. via the mask you can cover all your LAN... See the ACL table in one of the links I had ...
by mutluit
Sat Jun 27, 2020 2:43 am
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3830

Re: ACL firewall problem (missing L2 EtherType)

Open a ticket and send tech support a 'supout' along with your documented evidence and hopefully they will respond. My question is ,,,, will this 'bug' affect normal usage? I already did enough, made them aware of a severe bug and even located the bug. I'm not going to make any more. Enough is enou...
by mutluit
Sat Jun 27, 2020 2:19 am
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3830

Re: ACL firewall problem (missing L2 EtherType)

New insights: Both are necessary! arp via name as well via number. Then this can only mean that "arp by name" uses another essential (undocumented) EtherType. Otherwise it does not make any sense, IMO. Unless there is a memory problem caused by "double free'ing", "use after ...
by mutluit
Sat Jun 27, 2020 1:05 am
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3830

Re: ACL firewall problem (missing L2 EtherType)

@sindy, I understand, it's really mysterious. Here's another mystery to add to the confusion list: in my print list the rule #41 gets interpreted as another "802.2" though it has a totally different EthType (0x0008). The correct "802.2" has EtherType 0x0004 (rule #19 and #2 in th...
by mutluit
Sat Jun 27, 2020 12:49 am
Forum: General
Topic: L2 ACL on NetPower 16P via ROS
Replies: 2
Views: 799

Re: L2 ACL on NetPower 16P via ROS

@kowal, take a look at this thread as there are some ACL examples:
viewtopic.php?f=2&t=162887
by mutluit
Fri Jun 26, 2020 11:47 pm
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3830

Re: ACL firewall problem (missing L2 EtherType)

It's strange. On my hAP ac² (running 6.45.9), if I add the rule with mac-protocol=0x0806 , it is both print ed and export ed with mac-protocol=arp , i.e. the conversion seems to work both ways. So I don't get why in your case there is a difference in behaviour when you add it as "arp" and...
by mutluit
Fri Jun 26, 2020 11:00 pm
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3830

Re: ACL firewall problem (missing L2 EtherType)

ATTN MikroTik developers & ACL users: After some lengthy testing, the error finally has been found! : The endian-error is with the mac-protocol "arp" (EtherType 0x0806). It can be an endian-error or a simple parsing error from the string "arp" to the right EthType numeric va...
by mutluit
Fri Jun 26, 2020 8:24 pm
Forum: General
Topic: Problem 10G CRS317-1G-16S+RM and SFP+ direct attach cable (S+DA0001, S+DA0003)
Replies: 10
Views: 2185

Re: Problem 10G CRS317-1G-16S+RM and SFP+ direct attach cable (S+DA0001, S+DA0003)

@nickkk, I can just suggest this: use iperf on PCs for performance tests, not the integrated traffic generators on the routers or switches as this creates additional CPU load which then is missing for the device itself to perform its routing/switching job. And: do the test first w/o VLAN, and on a s...
by mutluit
Fri Jun 26, 2020 7:22 pm
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3830

Re: ACL firewall problem (missing L2 EtherType)

A wild guess here... there is a bug in the bridge filter rules, where the bytes in the 16-bit values of the ethertype field in the 802.1Q headers are swapped on some CPU architectures, and arm (which is the architecture of hAP ac²) is one of these whereas mipsbe is not affected by that; however, th...
by mutluit
Fri Jun 26, 2020 4:57 pm
Forum: General
Topic: Problem 10G CRS317-1G-16S+RM and SFP+ direct attach cable (S+DA0001, S+DA0003)
Replies: 10
Views: 2185

Re: Problem 10G CRS317-1G-16S+RM and SFP+ direct attach cable (S+DA0001, S+DA0003)

Is it true that two CRS317-1G-16S+RM devices are involved in this test? Why not testing on a single device first? If really two are involved, then they better should be in their own LAN (ie. IP should be something like 192.168.88.1/24 and the other should be 192.168.89.1/24). At least for the testin...
by mutluit
Fri Jun 26, 2020 2:54 pm
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3830

Re: ACL firewall problem (missing L2 EtherType)

It seems there is a bug in ACL b/c I did use the "Tools / PacketSniffer" tool over interfaces=all, but all the mac-protocols it lists are already present in the ACL... Packet Sniffer runs on CPU, not hardware. You will need to temporarily disable hardware acceleration on the port(s) that ...
by mutluit
Fri Jun 26, 2020 1:17 am
Forum: General
Topic: i need help: Lost Vlan Admin HELP HELP
Replies: 1
Views: 1000

Re: i need help: Lost Vlan Admin HELP HELP

If multiple ports of it have IPs, just try to connect to each IP via Winbox or Webfig.
If possible also by connecting the PC to the right port, if the above step don't work.
by mutluit
Fri Jun 26, 2020 12:58 am
Forum: RouterOS v7 BETA
Topic: beta8: possible bug in switch rules (ACL)
Replies: 0
Views: 759

beta8: possible bug in switch rules (ACL)

I encountered a possible bug with ACL usage: it is not possible to use a final rule which says "block all other". Details here:
viewtopic.php?f=2&t=162887
by mutluit
Thu Jun 25, 2020 11:58 pm
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3830

Re: ACL firewall problem (missing L2 EtherType)

I've now added all documented mac-protocols I could find in the wiki pages, ie. mac-protocol (802.2 | arp | homeplug-av | ip | ipv6 | ipx | lldp | loop-protect | mpls-multicast | mpls-unicast | packing-compr | packing-simple | pppoe | pppoe-discovery | rarp | service-vlan | vlan) And the behavior is...
by mutluit
Thu Jun 25, 2020 9:08 pm
Forum: General
Topic: ACL firewall problem (missing L2 EtherType)
Replies: 17
Views: 3830

ACL firewall problem (missing L2 EtherType)

On router hAP ac^2 I monitored the traffic using "Tools / Torch" in the GUI and added all observed L2 EtherTypes via ACL into the rule table of the switch-chip. But as soon as I activate the last rule by setting disabled=no then Internet stops functioning. What other EtherType is highly li...
by mutluit
Thu Jun 25, 2020 6:31 pm
Forum: Beginner Basics
Topic: NAT WAN to subnet [SOLVED]
Replies: 9
Views: 2296

Re: NAT WAN to subnet [SOLVED]

On the router you can assign multiple networks to a port, yes. But how do you attach the end-user devices to that port? Surely you must be using a switch for this. But then the switch cannot handle such 2 networks, unless it's a managed switch and you can tell the switch the same that you told the r...
by mutluit
Thu Jun 25, 2020 5:40 pm
Forum: Beginner Basics
Topic: NAT WAN to subnet [SOLVED]
Replies: 9
Views: 2296

Re: NAT WAN to subnet [SOLVED]

It is simply impossible to have two /24 IP networks on the same router port (that's IP routing 101, first lesson :-)). Either use a separate router port for each, or change the mask from /24 to /21 for example, and attach a dumb switch to the router port and attach the end-user devices to that switc...
by mutluit
Thu Jun 25, 2020 2:54 pm
Forum: RouterOS v7 BETA
Topic: beta8 says "#error exporting /routing/policy/selection"
Replies: 0
Views: 663

beta8 says "#error exporting /routing/policy/selection"

When doing /export in beta8 then there is a section in the output that says "#error exporting /routing/policy/selection"
Device: hAP ac^2 (ARM) upgraded from 6.47 to 7.0beta8 (development)
by mutluit
Thu Jun 25, 2020 4:29 am
Forum: Beginner Basics
Topic: Pool Segment diferent WAN
Replies: 7
Views: 1354

Re: Pool Segment diferent WAN

In posting #2 I gave you the answer: IP / DHCP Server in GUI.
by mutluit
Thu Jun 25, 2020 12:39 am
Forum: Beginner Basics
Topic: NAT WAN to subnet [SOLVED]
Replies: 9
Views: 2296

Re: NAT WAN to subnet [SOLVED]

It should work. But your device (PC?) must be attached to the right interface on the router... Can you ping the 192.168.5.21 from the router? From other PC? And what does "/ip route print" say? And what does "/interface print" say? It seems the problem is rooted in the fact that ...
by mutluit
Thu Jun 25, 2020 12:27 am
Forum: Beginner Basics
Topic: Pool Segment diferent WAN
Replies: 7
Views: 1354

Re: Pool Segment diferent WAN

Sorry im mean ISP(Internet providers).
Still doesn't make much sense in this context.
Are you meaning your own DHCP server for your LAN, or do you rather mean DHCP server of your ISP?
by mutluit
Wed Jun 24, 2020 11:48 pm
Forum: Beginner Basics
Topic: Pool Segment diferent WAN
Replies: 7
Views: 1354

Re: Pool Segment diferent WAN

Should be possible. Define 2 pools in IP/Pools, and assign each in /IP/DHCP Server to the wanted interface.
I don't know what you mean by "WAN", normally the interfaces "etherX" and "wlanX" are used for such assignments.
by mutluit
Wed Jun 24, 2020 11:12 pm
Forum: General
Topic: Ping Issue!
Replies: 13
Views: 2464

Re: Ping Issue!

For your PC the gateway should be the LAN IP of your router (or if the router interface where your PC is attached to has an own IP, then that IP).
For your router the gateway should be the IP of its uplink.
by mutluit
Wed Jun 24, 2020 10:02 pm
Forum: General
Topic: bridge filter CRS326
Replies: 6
Views: 1511

Re: bridge filter CRS326

@gklpnd, I have no experience with VRRP. I would suggest to experiment with a simple "normal" TCP traffic to/from a TCP port, for example by using an iperf server and a client. Then you will have gained more experience and can apply it to VRRP etc. All ACL rules have an implicit "acti...
by mutluit
Wed Jun 24, 2020 7:31 pm
Forum: General
Topic: bridge filter CRS326
Replies: 6
Views: 1511

Re: bridge filter CRS326

FYI: the traffic of ports that have Hardware Offloading enabled, does not pass thru the normal firewall locations ("CPU firewall"), but is handled within the " switch chip " using ACL rules . Ie. you should use ACL rules. There is also a rule which allows to " redirect-to-cp...
by mutluit
Tue Jun 23, 2020 10:20 pm
Forum: Wireless Networking
Topic: I WANT TO CONNECT 2 MIKROTIK AP RBwAP2nND WIRELESSLY AND DISTRIBUE WIRELESS INTERNET CONNECTIVITY FROM 2 nd AP RBw AP2
Replies: 11
Views: 2087

Re: I WANT TO CONNECT 2 MIKROTIK AP RBwAP2nND WIRELESSLY AND DISTRIBUE WIRELESS INTERNET CONNECTIVITY FROM 2 nd AP RBw

the router os is station mode. when I connect the router os by cable on my PC the ethernet light of the pc and the router lights up but winbox does not detect the router. the pc address is 192.168.88.6 through the browser I can't. What is the gateway IP address on your PC? It should be the IP of yo...
by mutluit
Tue Jun 23, 2020 5:22 pm
Forum: General
Topic: Different DHCP pools on ports from 192.168.1.0/21 network?
Replies: 5
Views: 983

Re: Different DHCP pools on ports from 192.168.1.0/21 network?

@CarsonGrey, it can work as you described. You just need to set a route from ether6 to the bridge, ie. make an entry under "/ip route",
or simply add ether6 to the bridge as well.
by mutluit
Tue Jun 23, 2020 4:53 pm
Forum: Wireless Networking
Topic: I WANT TO CONNECT 2 MIKROTIK AP RBwAP2nND WIRELESSLY AND DISTRIBUE WIRELESS INTERNET CONNECTIVITY FROM 2 nd AP RBw AP2
Replies: 11
Views: 2087

Re: I WANT TO CONNECT 2 MIKROTIK AP RBwAP2nND WIRELESSLY AND DISTRIBUE WIRELESS INTERNET CONNECTIVITY FROM 2 nd AP RBw

ok but currently my biggest problem is that i can't reset the access point. I tried several times the manual reset but it does not pass I also can't get access to the access point interface. is there a solution to recover my equipment? Have you also changed the IP of your PC to 192.168.88.9 for exa...
by mutluit
Tue Jun 23, 2020 2:00 pm
Forum: Wireless Networking
Topic: I WANT TO CONNECT 2 MIKROTIK AP RBwAP2nND WIRELESSLY AND DISTRIBUE WIRELESS INTERNET CONNECTIVITY FROM 2 nd AP RBw AP2
Replies: 11
Views: 2087

Re: I WANT TO CONNECT 2 MIKROTIK AP RBwAP2nND WIRELESSLY AND DISTRIBUE WIRELESS INTERNET CONNECTIVITY FROM 2 nd AP RBw

I want to extend the wifi in an area where there is no cable so I want to connect AP in station mode repeat the wifi Then you need to add AP functionality to the station as said via a virtual wlan3. But I think you cannot use the same SSID, you need to use a different one. But, it is also possible ...
by mutluit
Tue Jun 23, 2020 1:40 pm
Forum: Wireless Networking
Topic: I WANT TO CONNECT 2 MIKROTIK AP RBwAP2nND WIRELESSLY AND DISTRIBUE WIRELESS INTERNET CONNECTIVITY FROM 2 nd AP RBw AP2
Replies: 11
Views: 2087

Re: I WANT TO CONNECT 2 MIKROTIK AP RBwAP2nND WIRELESSLY AND DISTRIBUE WIRELESS INTERNET CONNECTIVITY FROM 2 nd AP RBw

It is possible to use both devices as APs, even if the 2nd is in station mode. To be able to wirelessly connect to the station, you need to add a virtual wlan (ie. wlan3) as "ap bridge" to it and configure it accordingly (with own SSID etc). Why do you need to operate 2 wireless routers in...
by mutluit
Tue Jun 23, 2020 1:28 pm
Forum: Beginner Basics
Topic: Using WLAN1 as WAN
Replies: 6
Views: 1285

Re: Using WLAN1 as WAN

@ge0rgi, as @CZFan also said, you can create or change the WAN port yourself in GUI / Interfaces / Interface List. Doing it in CLI is possible too.
by mutluit
Tue Jun 23, 2020 1:05 pm
Forum: Beginner Basics
Topic: Can I do one wlan nat & other wlan as AP for Airplay discovery
Replies: 10
Views: 1922

Re: Can I do one wlan nat & other wlan as AP for Airplay discovery

There are multiple solutions possible: 1) Give the WAN port an IP from the same subnet (192.168.0.y), disable NAT on hAP, connect the WAN port (usually ether1) of hAP to the other router, configure wlan so that it gives via DHCP IP addresses from the same subnet 192.168.0.z 2) Set the hAP into Bridg...
by mutluit
Mon Jun 22, 2020 9:17 pm
Forum: General
Topic: Forwarding UDP traffic to 2 destinations
Replies: 2
Views: 616

Re: Forwarding UDP traffic to 2 destinations

Normal iptables has a TEE target with which it is possible. Don't know if that's available also in RouterOS, but there was a discussion 4 years ago: https://forum.mikrotik.com/viewtopic.php?t=105166 Some MT router and switch models can mirror user-defined packets via ACL rules, but don't know whethe...
by mutluit
Mon Jun 22, 2020 8:04 pm
Forum: General
Topic: View configured static routes
Replies: 11
Views: 2019

Re: View configured static routes

Thanks - yes I am aware of the possibility to display this information using the CLI. My question was - is it possible using winbox?
Yes, IP / Routes in GUI. Those with "S" are the static ones, which also can be edited.
by mutluit
Mon Jun 22, 2020 7:45 pm
Forum: Wireless Networking
Topic: hAP ac^2: Q on passwords and wireless speed
Replies: 18
Views: 2841

Re: hAP ac^2: Q on passwords and wireless speed

Names I use are like
wAP1_2, wAP1_5, wAP2_2, wAP2_5, hAP_2, hAP2_5 for the 2.4 and 5 GHz radio's.
@bpwl, where do you define that? Is it the "Name" field on the wlan interface page, or a different field?
by mutluit
Mon Jun 22, 2020 7:23 pm
Forum: Wireless Networking
Topic: station bridge
Replies: 0
Views: 985

station bridge

I can connect via wlan to an AP by setting the wlan to "station" or "station bridge" mode (both devices are MT hAP ac^2 with RouterOS v6.47). I wonder what the difference between "station" and "station bridge" is. What are the capabilities of these modes? When...
by mutluit
Mon Jun 22, 2020 7:07 pm
Forum: Beginner Basics
Topic: Can I do one wlan nat & other wlan as AP for Airplay discovery
Replies: 10
Views: 1922

Re: Can I do one wlan nat & other wlan as AP for Airplay discovery

Sorry, but I still don't think anybody understands what you really want to achieve.
Your question should be short and precise.
Sorry, I can't help as I don't understand the problem. Maybe someone else can help.
It's really frustrating to read such imprecise postings.
by mutluit
Mon Jun 22, 2020 6:53 pm
Forum: Wireless Networking
Topic: hAP ac^2: Q on passwords and wireless speed
Replies: 18
Views: 2841

Re: hAP ac^2: Q on passwords and wireless speed

Hi, I have same router and want to figure out one thing. What is Radio name? What value should it has? Should it be equal to MAC address? Yes, MAC of the other side w/o the colons, and only If two MikroTik wireless devices connect to each other. In other cases (for example if a smartphone connects ...
by mutluit
Sun Jun 21, 2020 1:11 pm
Forum: General
Topic: Wireless traffic counters
Replies: 3
Views: 1106

Re: Wireless traffic counters

Excellent. Thanks. It wasn't covered in the Wiki that I could find, although the CLI command you provided had occurred to me. It didn't work because I tried /interface wlan1 reset-counters which is wrong. A tip: in CLI you can press TAB at any valid location (ie. before or after a word) and it will...
by mutluit
Sat Jun 20, 2020 8:17 pm
Forum: General
Topic: Wireless traffic counters
Replies: 3
Views: 1106

Re: Wireless traffic counters

Is there any way to reset the Interface>>Wireless>>Traffic TX/RX bytes/packet/drops/errors counters such as can be done with the ETH and Bridge interfaces? In CLI you can do the following: /interface reset-counters wlan1 It seems in GUI it's not possible for wireless interfaces, or was forgotten to...
by mutluit
Sat Jun 20, 2020 7:47 pm
Forum: Beginner Basics
Topic: Open port 443 for a device on the LAN
Replies: 6
Views: 2282

Re: Open port 443 for a device on the LAN

I've figure out how to open the port broadly. Now when I go to yougetsignal.com it says the port is open. Just not sure how secure this is and if there's a better way? I set the Chain to input > Protocol TCP > Any. Port 443. The security must be provided by the service itself, ie. by the applicatio...
by mutluit
Sat Jun 20, 2020 7:26 pm
Forum: Beginner Basics
Topic: Basic config no internet no local network
Replies: 2
Views: 834

Re: Basic config no internet no local network

Nowadays many applications don't work without Internet connection.
Having a local DNS server is good for caching, but it can't solve the problem since it too needs Internet connection to its uplink servers (ie. 8.8.8.8 etc. are in Internet).
by mutluit
Sat Jun 20, 2020 6:54 pm
Forum: Beginner Basics
Topic: I can't open ports
Replies: 4
Views: 1269

Re: I can't open ports

For easy understanding you better should make a drawing of your network. Since you seem to be using 2 routers, then it could be that you have a "Double NAT Problem". On which of the routers do you have NAT enabled? You should have NAT enabled only on the WAN router, and disable it on all o...
by mutluit
Sat Jun 20, 2020 6:00 pm
Forum: Beginner Basics
Topic: Use MikroTik as second router
Replies: 13
Views: 2823

Re: Use MikroTik as second router

If you can not set ISP router in bridge mode, you will have double NAT, but other than that, most stuff should work. I have a similar setup like the OP, but the difference is that I let only run DNS server and NTP server (time server) on the WAN router, everything else runs on the 2nd router. There...
by mutluit
Sat Jun 20, 2020 6:28 am
Forum: Wireless Networking
Topic: Please help me with my 14Km link. [SOLVED]
Replies: 3
Views: 1636

Re: Please help me with my 14Km link. [SOLVED]

https://en.wikipedia.org/wiki/Antenna_gain#Example_calculation Looks like some rocket science :-) See also https://www.simplewifi.com/pages/antenna-basics According to their table it seems for your 14km you need a "Parabolic Grid 24 dBi Directional Antenna", or better. But they also say &q...
by mutluit
Fri Jun 19, 2020 3:45 am
Forum: Wireless Networking
Topic: Connecting two LANs via two WLANs
Replies: 0
Views: 638

Connecting two LANs via two WLANs

I'll soon perform this WLAN experiment: connecting two LANs via two WLANs using basic IP routing (ie. w/o any tunneling): WLAN1(.132.254/24) WLAN2(.142.254/24) | | WAN1 --------- R1 R2 ------------ WAN2 | | LAN1(.131.254/24) LAN2(.141.254/24) Routers R1 and R2 are not cable-connected with each other...
by mutluit
Fri Jun 19, 2020 2:32 am
Forum: General
Topic: Network loop?
Replies: 6
Views: 2607

Re: Network loop?

You should post your config for analysis, ie in CLI:
/export hide-sensitive file=export-hs
and then see in /Files for the file...
by mutluit
Fri Jun 19, 2020 2:01 am
Forum: Beginner Basics
Topic: New to Mikrotik - Config Help FW
Replies: 12
Views: 2890

Re: New to Mikrotik - Config Help FW

It is already on the first post as attachment :D
Ok, I see.
But come on, man, are you joking? :-) This is a full-blown very complex configuration, not a basic/initial configuration.
Sorry, I'm out. Maybe someone else can take a look.
by mutluit
Fri Jun 19, 2020 1:53 am
Forum: Beginner Basics
Topic: New to Mikrotik - Config Help FW
Replies: 12
Views: 2890

Re: New to Mikrotik - Config Help FW

Which router do you have and which OS and version does it have?
If it has RouterOS then you should post the output of this CLI command:
/ip export hide-sensitive
by mutluit
Fri Jun 19, 2020 1:38 am
Forum: Beginner Basics
Topic: New to Mikrotik - Config Help FW
Replies: 12
Views: 2890

Re: New to Mikrotik - Config Help FW

To simplify things I would suggest to use two routers in series, then on the border router you would have NAT, and on the inner router disable NAT (and this step simplifies all the rest). Firewall chains: input: traffic destined to the router itself output: traffic from the router itself forward: th...
by mutluit
Fri Jun 19, 2020 1:23 am
Forum: Beginner Basics
Topic: Hardware advice, small company network
Replies: 4
Views: 1086

Re: Hardware advice, small company network

These are big infrastructure changes. IMO you better should consult a professional network consultant, preferably a MikroTik certified one. No, I'm not :-) Tell him/her also how fast your WAN link is, how your LAN is structured (#networks, #subnets), whether VLAN is used etc., ie. the usual things n...
by mutluit
Thu Jun 18, 2020 8:20 pm
Forum: General
Topic: Lan security
Replies: 5
Views: 1299

Re: Lan security

Dot1x is used when we have mikrotik switch .
Is there any solution When 30 clients are connected to a hub and the hub is connected to mikrotik router interface
So, you are concerned of security, but are using a hub (instead of a switch) for 30 clients?
What hub model is it?
by mutluit
Thu Jun 18, 2020 7:51 pm
Forum: Wireless Networking
Topic: What settings in WIRELESS will affect CAPSMAN
Replies: 2
Views: 1159

Re: What settings in WIRELESS will affect CAPSMAN

What settings in WIRELESS(command: /interface wireless) will affect CAPSMAN ?
Take a look at viewtopic.php?f=7&t=162494
There are the configs of both posted.
by mutluit
Thu Jun 18, 2020 5:35 pm
Forum: General
Topic: API Document for latest Router OS Version
Replies: 1
Views: 488

Re: API Document for latest Router OS Version

We are trying to integrate our Mikrotik router CCR1036-8G-2S+ with Bandwidth manager router of 24online server and they have requested us to provide them with API document of Mikrotik router of current router OS version any that is available. https://wiki.mikrotik.com/wiki/Manual:API It says "...
by mutluit
Thu Jun 18, 2020 5:22 pm
Forum: General
Topic: Mac Address Range
Replies: 1
Views: 764

Re: Mac Address Range

Is there a way in the firewall to filter by a MAC address range? Say all the MAC addresses owned by Company X? At some locations in the config, like the ACL, one indeed can specify MAC/subnet, see for example https://wiki.mikrotik.com/wiki/Manual:CRS3xx_series_switches#Port_Security /interface ethe...
by mutluit
Thu Jun 18, 2020 5:06 pm
Forum: General
Topic: Join to multicast group
Replies: 1
Views: 522

Re: Join to multicast group

Search "MikroTik multicast"
See for example this: https://www.premitel.uk/consultancy/exp ... uterboard/
by mutluit
Thu Jun 18, 2020 4:53 pm
Forum: General
Topic: Lan security
Replies: 5
Views: 1299

Re: Lan security

1.Is there any way to limit dhcp server to assign ip for clients that are authenticated ,not all the clients that are physically connected? 2.If not is it possible to prevent connecting unknown computers to lan? Is mac filter the only way? 3.What about user manage? Is it possible to authenticat cli...
by mutluit
Thu Jun 18, 2020 4:16 pm
Forum: General
Topic: How can I find out the reason for NAK?
Replies: 5
Views: 1140

Re: How can I find out the reason for NAK?

Hi there. I faced a problem recently. SVI of my switch doesn't get IP-address via DHCP server on my Mikrotik 951Ui-2nD (6.42.1). Although it gets IP-address via ISC-DHCP server. I've watched the log but can't find the reason of NAK. How can I do that? P.S. Attached log from mikrotik. For analysis y...
by mutluit
Thu Jun 18, 2020 3:34 pm
Forum: General
Topic: RouterOS changed IP address association without input
Replies: 1
Views: 467

Re: RouterOS changed IP address association without input

I had similar encounters :-)
I've documented it here: viewtopic.php?f=2&t=162506&p=801039#p801039
by mutluit
Thu Jun 18, 2020 1:51 pm
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 5241

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

And about Quick Set, one should better not use it at all after any change done outside of it. Indeed, it was also the reason for the late wlan2 problem: the "/ip address" list was messed up: had 2 different gateway entries for ether2 . This happens if one tries on the QuickSet page to fix...
by mutluit
Thu Jun 18, 2020 2:56 am
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 5241

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

Btw, a warning: one better should not use (ie. fill) the "Guest Network" entries under QuickSet as it again creates the bridge and puts all interfaces into it... :-) I just had tried it out, but since it didn't function I reverted everything back, but now it seems wlan2 is no more function...
by mutluit
Thu Jun 18, 2020 2:45 am
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 5241

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

"Bridge1" is no router , it is functioning as a switch. There are no routing decisions in the switch Bridge1. Bridge1 is just another interface to the router, and for the router it fully replaces ether1,wlan1 and wlan2. The Bridge1/switch is making one single LAN (broadcast domain) with t...
by mutluit
Thu Jun 18, 2020 2:39 am
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 5241

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

There were two configs. Original with individual interfaces and no bridge. And then exploring dead ends with bridge that did something, but no that much, because the main problem (missing gateway) was still present. I 'll rest my case. No more comments. This first model was made based on an earlier...
by mutluit
Wed Jun 17, 2020 8:26 pm
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 5241

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

SOLVED! Thanks @Sob! As he said in https://forum.mikrotik.com/viewtopic.php?f=2&t=162506&p=800866#p800866, entries under "/ip dhcp-server network" were missing. After adding it there and removing the bridge and reactivating DHCP pools for wlan1 and wlan2 (192.168.132.0/24 and 192.1...
by mutluit
Wed Jun 17, 2020 7:44 pm
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 5241

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

It's the client device that needs default gateway. When it gets config from dhcp, it would be: /ip dhcp-server network add address=192.168.254.0/24 gateway=192.168.254.253 <other options> But you don't have anything like that. Not that it's completely correct, because .253 is on this router, but as...
by mutluit
Wed Jun 17, 2020 7:25 pm
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 5241

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

@Sob, the DHCP server is only for wlan clients; all other devices have manually configured static IP and gateway (and DNS server etc.).

@bpwl, see bridge1 in routing table: ether1, wlan1, wlan2 use that for their routing decision, IMO. The bridge1 was added by ROS itself to the routing table.
by mutluit
Wed Jun 17, 2020 6:43 pm
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 5241

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

Where is default gateway for 192.168.254.x clients, don't they have any? If not, then 192.168.254.0/24 is all they can access, nothing else. This is the routing table. IIRC only record #4 was defined manually by me, the rest is auto-generated by RouterOS: [admin2@MikroTik-AP] > /ip route print Flag...
by mutluit
Wed Jun 17, 2020 6:39 pm
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 5241

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

I don't see addresses to be assigned to wlan1 and wlan2. As said in a prev posting, the gateway addresses for wlanX (.132.254 and .133.254) in my OP I had to remove for this latest partial-working solution (actually it didn't make any difference whether they continued existing or not). The wlan cli...
by mutluit
Wed Jun 17, 2020 6:10 pm
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 5241

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

Is there perhaps anything else you have in your config? Maybe posting the whole thing could help. Because none of the routers I have ever seen cared whether inteterface is ether or wlan, and I don't see why there should be any difference. Below is the "/export hide-sensitive file=export-hs&quo...
by mutluit
Wed Jun 17, 2020 5:33 pm
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 5241

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

or to continue ... Can a wlan1 device be pinged from the router itself or from another wlan1 device? And of course the reverse route must exist in the wlan1 device with router as gateway. Pinging wlan clients from all devices connected to the same subnet on ether1 (ie. 192.168.254.x) works, as well...
by mutluit
Wed Jun 17, 2020 3:50 pm
Forum: RouterOS v7 BETA
Topic: Feature Request For Centrally Handling All Authentication Failures
Replies: 2
Views: 896

Feature Request For Centrally Handling All Authentication Failures

Proposal/FeatureRequest For Centrally Handling All Authentication Failures For Banning And/Or Executing A Script Each AuthFailure should be sent to an AuthFailureSystem similar to the firewall, but much simpler: add error-source=serviceId error-category=... error-code=... action=ban ban-duration=......
by mutluit
Wed Jun 17, 2020 2:53 pm
Forum: Scripting
Topic: How to get SrcIP address from PPTP Auth failure log?
Replies: 5
Views: 2978

Re: How to get SrcIP address from PPTP Auth failure log?

Any ideas how to get SRC IP from failed PPTP authentication parsing log files?
The IP is in the previous log line "TCP connection established from ..."
by mutluit
Wed Jun 17, 2020 2:04 pm
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 5241

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

Your latest post indicates that indeed it's what @sob wrote: ... and if they have own firewalls, they must allow pings from other subnet. There is no firewall issue. As already said: etherX to etherY works w/o any problems with just default/automatic routing settings on the router, and firewall on ...
by mutluit
Wed Jun 17, 2020 6:50 am
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 5241

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

I could achieve only a partial solution which allows to ping/connect to the wlan-client only from the WAN-side (ether1). For this to work I had to do these steps: 1.) Create a bridge "bridge1" and put WAN, (ether1), wlan1, wlan2 into it. 2.) Create an IP Pool for the DHCP Server with an IP...
by mutluit
Wed Jun 17, 2020 6:19 am
Forum: Scripting
Topic: Script for If enivorment = then do
Replies: 14
Views: 2502

Re: Script for If enivorment = then do

Hi It works just curios why this won't work inside system scripts work at the console if run as script use /import says invalid URL not sure how to debug that i assume it same URL it pull for from $configserver not sure why won't run as a script any suggestions? { :global provisionedstatus false :i...
by mutluit
Wed Jun 17, 2020 2:08 am
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 5241

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

That's how IP subnets work. If you connect device with address 192.168.131.3 to any other interface than ether5, it can't work, because as the router sees it, any 192.168.131.x is connected to ether5 and it won't look for it anywhere else. Also, device looking for 192.168.131.254 won't succeed on a...
by mutluit
Wed Jun 17, 2020 1:37 am
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 5241

Re: RouterOS illogical behavior with wireless interfaces [SOLVED]

If clients connected to wlan1 or wlan2 have this router (i.e. 192.168.132.254 or 192.168.133.254) as default gateway (or have routes to other subnets) and they answer pings from these subnets (it's not blocked by their firewalls), this tiny piece of config doesn't explain why it shouldn't work. Goo...
by mutluit
Wed Jun 17, 2020 1:01 am
Forum: General
Topic: RouterOS illogical behavior with wireless interfaces [SOLVED]
Replies: 31
Views: 5241

RouterOS illogical behavior with wireless interfaces [SOLVED]

On my router (hAP ac^2) with RouterOS v6.47 I'm using all ports as gateways for independent LANs. For this I removed the default bridge and made each port a gateway of its LAN, ie like this: /ip address print Flags: X - disabled, I - invalid, D - dynamic # ADDRESS NETWORK INTERFACE 0 192.168.254.253...
by mutluit
Tue Jun 16, 2020 6:37 pm
Forum: Beginner Basics
Topic: virtual wifi interface can't connect internet
Replies: 10
Views: 2681

Re: virtual wifi interface can't connect internet

Maybe this video can help:
Mikrotik Tutorial no: 22 - Creating Multiple WIFI SSID for VLAN based Network
https://www.youtube.com/watch?v=i-qQo06ow7Y
by mutluit
Tue Jun 16, 2020 5:14 pm
Forum: Beginner Basics
Topic: DNS not resolving domain names
Replies: 8
Views: 3236

Re: DNS not resolving domain names

@anav, IMO there is ZERO need for VLAN with routers, especially not in home environment as well not in a corporate LAN. VLAN might be maybe good for carriers, ie. ISPs with L2 switches only...
by mutluit
Tue Jun 16, 2020 4:56 pm
Forum: Beginner Basics
Topic: DNS not resolving domain names
Replies: 8
Views: 3236

Re: DNS not resolving domain names

Yes, my computers get theirs IPs via DHCP, including DNS server. They don't have static IPs. The result of nslookup google.com is: DNS request timed out. timeout was 2 seconds. Server: UnKnown Address: 8.8.8.8 This indicates that the DNS server setting on the PC is wrong or couldn't be set / get. T...
by mutluit
Tue Jun 16, 2020 4:28 pm
Forum: General
Topic: DST-nat to not directly connected network (VPN without NAT)
Replies: 4
Views: 867

Re: DST-nat to not directly connected network (VPN without NAT)

I'm trying to do a DST-nat to a network that is behind another mikrotik connected using a VPN (and using a direct route, no nat, to the mikrotik from where I'm trying to setup the DST-nat), but I'm getting a strange (or not so strange) behavior where the second mikrotik is trying to answer the requ...
by mutluit
Tue Jun 16, 2020 4:14 pm
Forum: Beginner Basics
Topic: DNS not resolving domain names
Replies: 8
Views: 3236

Re: DNS not resolving domain names

Hi friends, Can any one help me to understand why my computers behind the mikrotik router cannot resolve domain names? here is my config: Do your computers get their IPs via DHCP? If they have static IPs then you have to specify the DNS server manually on the PCs. What is the output of this command...
by mutluit
Tue Jun 16, 2020 4:07 pm
Forum: Beginner Basics
Topic: Never see my ISP IP on the site I'm watching
Replies: 5
Views: 1319

Re: Never see my ISP IP on the site I'm watching

Problem description is insufficient, more data needed.
by mutluit
Tue Jun 16, 2020 3:46 pm
Forum: Scripting
Topic: Controlling USB power
Replies: 4
Views: 1168

Re: Controlling USB power

@MariusL, I think you should make an official Feature Request. And/or if you think the current version has a bug then post a bug report. Per this page https://wiki.mikrotik.com/wiki/Manual:USB_Features currently the USB powering-off can be done only for a duration of user-specified time (or default ...
by mutluit
Tue Jun 16, 2020 3:28 pm
Forum: Scripting
Topic: read and store variable
Replies: 1
Views: 578

Re: read and store variable

by mutluit
Tue Jun 16, 2020 2:58 pm
Forum: Scripting
Topic: Controlling USB power
Replies: 4
Views: 1168

Re: Controlling USB power

I would suggest to use a global counter (inc / dec), and trigger the alarm only if that counter is for example >= 2.

And I think it's caused by this command in your script:
/system routerboard usb power-reset duration=1d
Ie. 1d is then too short, you should set it much higher.
by mutluit
Tue Jun 16, 2020 2:34 pm
Forum: Beginner Basics
Topic: Data rates decrease to 6.5
Replies: 1
Views: 569

Re: Data rates decrease to 6.5

Can you post the output of this command in CLI (change the name "wlan1" if yours is different, pressing TAB there shows the name of yours):
/interface wireless monitor wlan1 once

And this:
/interface wireless export hide-sensitive
by mutluit
Mon Jun 15, 2020 5:13 pm
Forum: General
Topic: Setup WDS with 2 AP
Replies: 7
Views: 1835

Re: Setup WDS with 2 AP

I don't have experience in WDS myself, but just stumbled over this wiki page https://wiki.mikrotik.com/wiki/WDS_repeater_example

There are also some YT videos: https://www.youtube.com/watch?v=s6PEDtf5qDQ
by mutluit
Mon Jun 15, 2020 4:59 pm
Forum: Wireless Networking
Topic: hAP lite wireless performance?
Replies: 8
Views: 1973

Re: hAP lite wireless performance?

According to specs at https://mikrotik.com/product/RB941-2nD it has wireless 2.4 GHz max data rate 300 Mbit/s.
But the 4 Ethernet ports are 100 Mbit/s.
So 75 Mbit/s should be possible with it.
by mutluit
Mon Jun 15, 2020 4:54 pm
Forum: Wireless Networking
Topic: Add new Wireless network and redirect internet to USB modem
Replies: 1
Views: 459

Re: Add new Wireless network and redirect internet to USB modem

What USB modem is it (vendor, model etc)?
by mutluit
Mon Jun 15, 2020 4:17 pm
Forum: Wireless Networking
Topic: Help changing wireless wire default ip address
Replies: 2
Views: 786

Re: Help changing wireless wire default ip address

Which device is it?

Normally you change it via the QuickSet tab in the GUI.
(But then it can happen that you need to change the IP of your PC to the same subnet. Ie. know well what you are doing.)

What do you mean by master and slave?
by mutluit
Mon Jun 15, 2020 12:08 am
Forum: General
Topic: Problem with ports
Replies: 3
Views: 813

Re: Problem with ports

Maybe one of the devices gets too hot? Maybe too much dust on the device?
If possible test also with a replacement device.
by mutluit
Sun Jun 14, 2020 11:27 pm
Forum: General
Topic: Intermittent loss of packets.............argg
Replies: 28
Views: 5569

Re: Intermittent loss of packets.............argg

Both are off on mine, I changed it to auto for both on my vlan bell cconnection and there was no change in packet loss to the gateway of the ISP. After running for about 1.5 hours, both were sitting at about 50% Then I think iperf is your best friend... :-) I think I would get rid of VLAN and use p...
by mutluit
Sun Jun 14, 2020 9:29 pm
Forum: General
Topic: Intermittent loss of packets.............argg
Replies: 28
Views: 5569

Re: Intermittent loss of packets.............argg

Here's a screenshot. At least for the WAN port the "Tx Flow Control" and "Rx Flow Control" should be set to "Auto" or "Yes". On my device I've set them all to Auto. Auto Negotiation is by default enabled. Of course such packets (in and out) must not be blocked...
by mutluit
Sun Jun 14, 2020 8:43 pm
Forum: General
Topic: Intermittent loss of packets.............argg
Replies: 28
Views: 5569

Re: Intermittent loss of packets.............argg

not seeing a place to inspect or modify that? In firewall or ACL accept these L2 packets. I am afraid it may not be that easy. Ethernet flow control packets are usually processed by the hardware itself on a very low level, so it is a challenge to even capture them, let alone processing them using s...
by mutluit
Sun Jun 14, 2020 8:06 pm
Forum: General
Topic: Intermittent loss of packets.............argg
Replies: 28
Views: 5569

Re: Intermittent loss of packets.............argg

not seeing a place to inspect or modify that? In firewall or ACL accept (don't block) these L2 packets. For example I have in one of my devices these ACL rules: add switch=switch1 ports=$myPorts mac-protocol=0x8808 comment="L2 Ethernet flow control" add switch=switch1 ports=$myPorts mac-p...
by mutluit
Sun Jun 14, 2020 7:06 pm
Forum: General
Topic: ppp interface configuration parameters, APN Type, MVNO type, MVNO value
Replies: 2
Views: 780

Re: ppp interface configuration parameters, APN Type, MVNO type, MVNO value

Have you tried Advanced Mode, and also therein in profile?
by mutluit
Sun Jun 14, 2020 6:50 pm
Forum: General
Topic: config export - section "/ip dhcp-server" printed twice
Replies: 1
Views: 515

Re: config export - section "/ip dhcp-server" printed twice

I think this is not a real error, b/c you can "add" items anytime to any section, as well pick single items from any section in any order.
Of course it would be better if in such an export everything would be grouped correctly under single header.
by mutluit
Sun Jun 14, 2020 6:15 pm
Forum: General
Topic: Intermittent loss of packets.............argg
Replies: 28
Views: 5569

Re: Intermittent loss of packets.............argg

You should ensure that on your device Ethernet frame control (EtherType 0x8808) is operational/activated.
by mutluit
Sun Jun 14, 2020 3:35 pm
Forum: Scripting
Topic: tikpp - a C++17 API library
Replies: 1
Views: 605

Re: tikpp - a C++17 API library

Thx, looks very interesting for C++ users like me :-)
by mutluit
Sun Jun 14, 2020 3:16 pm
Forum: Scripting
Topic: Script for If enivorment = then do
Replies: 14
Views: 2502

Re: Script for If enivorment = then do

Hi Am try to figure out how to make a script that runs download file based on that status of environment value here is the current code am try to get work :global configserver "http://192.168.1.187//$macaddress/temp.rsc" :global "provisioned-status" "no" :if (($provisi...
by mutluit
Sun Jun 14, 2020 2:57 pm
Forum: Wireless Networking
Topic: Wireless network stopped working
Replies: 1
Views: 494

Re: Wireless network stopped working

Which OS version does it have?
by mutluit
Sun Jun 14, 2020 2:48 pm
Forum: Wireless Networking
Topic: Bridge on wireless
Replies: 2
Views: 656

Re: Bridge on wireless

You can specify the IP range in the "pool" settings. In RouterOS see "/ip pool" either in GUI or CLI. Your ISP router surely has similar settings where you can define the IP pool. Normally you should have only 1 DHCP server active. You can instead also assign IPs manually to some...
by mutluit
Sun Jun 14, 2020 2:26 pm
Forum: RouterOS v7 BETA
Topic: hAP ac^2 doesn't boot after update to ROS7.0b8
Replies: 1
Views: 965

Re: hAP ac^2 doesn't boot after update to ROS7.0b8

Hello. I have router hAP ac^2. There was installed 6.45. There was no config at all (rest. and then press delete config). I upload routeros-7.0beta8-arm.npk to router and reboot it. Now it doesn't boot at all. I trid start netinstall, and power up with holding reset. after 5 sec USR begins blinking...
by mutluit
Sun Jun 14, 2020 1:37 pm
Forum: General
Topic: Intermittent loss of packets.............argg
Replies: 28
Views: 5569

Re: Intermittent loss of packets.............argg

Does the game use UDP? Packet loss is normal with UDP. For example if a buffer is full then new UDP packets simply will be dropped, unlike with TCP. See also https://forum.mikrotik.com/viewtopic.php?t=112449 and https://forum.mikrotik.com/viewtopic.php?t=50110 Enabling Ethernet flow control could ma...
by mutluit
Sat Jun 13, 2020 10:44 pm
Forum: Beginner Basics
Topic: raw forwarding
Replies: 1
Views: 640

Re: raw forwarding

You need to do it also in the other direction... :-)
by mutluit
Sat Jun 13, 2020 10:10 pm
Forum: General
Topic: ISP Router Setup
Replies: 2
Views: 924

Re: ISP Router Setup

I would keep NAT on R1 (ie. the WAN router) and disable NAT on all other routers. Yes, you can reduce firewall on R1 and do it on the other routers. (FYI: you can have firewall anywhere, even on PCs) For automatic IP/gateway assignment for clients (ie. for their "WAN" side), you can have D...
by mutluit
Sat Jun 13, 2020 5:50 pm
Forum: Beginner Basics
Topic: How to measure and improve RouterBOARD performances when connected to a FTTH ISP ?
Replies: 2
Views: 579

Re: How to measure and improve RouterBOARD performances when connected to a FTTH ISP ?

Start an iperf server in LAN Connect an iperf client in WAN (for example running on a rented VPS of yours in Internet) to the above iperf server. Let it run 60 seconds or so, then you will get the answer. See also https://en.wikipedia.org/wiki/Iperf For LAN-internal speed testing (ie. testing local ...
by mutluit
Sat Jun 13, 2020 5:34 pm
Forum: General
Topic: Methods in connecting N router [SOLVED]
Replies: 14
Views: 2749

Re: Methods in connecting N router [SOLVED]

@Schime85, is Method C working in practice? I have my doubts :-)
It can only work if you use a netmask /23 or so, but not with /24.
by mutluit
Sat Jun 13, 2020 5:17 pm
Forum: General
Topic: Methods in connecting N router [SOLVED]
Replies: 14
Views: 2749

Re: Methods in connecting N router [SOLVED]

Without an intermediate unmanaged (dumb) switch you can't connect 3+ routers without eating up the remaining router ports. yes then take a 10 port router like rb4011 ... the focus lies in the methods not in hardware questions I still would prefer using an intermediate unmanaged switch as it simplif...
by mutluit
Sat Jun 13, 2020 5:11 pm
Forum: General
Topic: Methods in connecting N router [SOLVED]
Replies: 14
Views: 2749

Re: Methods in connecting N router [SOLVED]

Without an intermediate unmanaged (dumb) switch you can't connect 3+ routers without eating up the remaining router ports.
by mutluit
Sat Jun 13, 2020 4:11 pm
Forum: General
Topic: Methods in connecting N router [SOLVED]
Replies: 14
Views: 2749

Re: Methods in connecting N router [SOLVED]

I would suggest to use Method B. But the IPs must be in the same network at both sides, ie. one say has .254 and the other .253. Ie. in the same broadcast domain. 3+ routers you would connect together in series (much like the first 2) and in the same one network, not parallel :-) BUT: of course with...
by mutluit
Sat Jun 13, 2020 1:13 pm
Forum: General
Topic: 2x CRS354's connected via Q+, one continually reboots
Replies: 2
Views: 745

Re: 2x CRS354's connected via Q+, one continually reboots

Maybe a heat issue. Are all cooling fans ok?
What does "/system health print" say?
And: also what does "/system logging print" say?
by mutluit
Sat Jun 13, 2020 1:07 pm
Forum: General
Topic: I need to change WAN IP adress without breaking the ipsec tunnels
Replies: 2
Views: 503

Re: I need to change WAN IP adress without breaking the ipsec tunnels

Not sure whether this can help, but you can add additional IPs also to the current eth1.
by mutluit
Fri Jun 12, 2020 4:39 pm
Forum: General
Topic: Protected configuration of new router?
Replies: 13
Views: 1990

Re: Protected configuration of new router?

@RackKing, are you aware of the fact that any legitimate user with access to the router can issue the command "/export" in the CLI, or look in Webfig or in Winbox to see/get all the configuration? Do you want to allow only yourself to manage the device of the user? If yes, then just don't ...
by mutluit
Fri Jun 12, 2020 4:19 pm
Forum: General
Topic: No Internet on WIFI
Replies: 3
Views: 896

Re: No Internet on WIFI

What is your test client? A smartphone?
What does it say? Is the SSID listed, or can you add it manually?
by mutluit
Fri Jun 12, 2020 4:08 pm
Forum: General
Topic: AWS - CHR Dual WAN?
Replies: 1
Views: 485

Re: AWS - CHR Dual WAN?

Hello, Does anyone have a working config for CHR running in AWS with dual WAN? I would like to setup CHR at the edge of the VPC with 2 WAN interfaces with 2 Public IP addresses and 1 LAN interface. Thank you, Some general info: https://wiki.mikrotik.com/wiki/Manual:CHR_AWS_installation https://aws....
by mutluit
Fri Jun 12, 2020 3:47 pm
Forum: General
Topic: encrypted password for mikrotik config
Replies: 22
Views: 6998

Re: encrypted password for mikrotik config

@ngaleyev, do you know that passwords are not static but can (and should) be changed anytime by its user?... :-) Or is that not wanted by your org? Tip: you should always have at least 2 admin users configured (admin + company), in case the admin leaves the company, or suddenly dies in an accident o...
by mutluit
Fri Jun 12, 2020 3:26 pm
Forum: General
Topic: How to keep people from connecting PC instead of Access points or Cameras ?
Replies: 6
Views: 1093

Re: How to keep people from connecting PC instead of Access points or Cameras ?

Use access restrictions on the devices itself if they have it. By MAC, IP, and strong password(s) . MAC and IP of course are not that secure as everybody on his access device can change them. To prevent unauthorized access via LAN/WAN: protect also on the router... And: if possible on the devices, u...
by mutluit
Fri Jun 12, 2020 3:00 pm
Forum: General
Topic: Port forwarding between two wan interface on same routerboard
Replies: 4
Views: 901

Re: Port forwarding between two wan interface on same routerboard

My purpose is: if someone access 10.100.11.11:3562, he can speed up access 1.1.1.1:53 via WAN2.
I guess you mean 8374 instead of 3562.

Problem description is now clear.
It normally should function.
by mutluit
Fri Jun 12, 2020 2:17 pm
Forum: General
Topic: Protected configuration of new router?
Replies: 13
Views: 1990

Re: Protected configuration of new router?

scp the rsc script to the device, ssh to the device, and import the rsc, then delete the rsc... Instead of scp you can of course also use "/tool fetch ..." to download the rsc from your own server... Of course the ssh service (default port 22) of the device must first be reachable from Int...
by mutluit
Fri Jun 12, 2020 2:00 pm
Forum: General
Topic: Port forwarding between two wan interface on same routerboard
Replies: 4
Views: 901

Re: Port forwarding between two wan interface on same routerboard

The problem description is a little bit cryptic as one can't imagine what you try to achieve. Are you trying to do a kind of Load Balancing? And what do you mean by "random port"? I would replace the following add action=dst-nat chain=dstnat dst-address=10.200.22.22 dst-port=3562 \ in-inte...
by mutluit
Fri Jun 12, 2020 1:37 pm
Forum: General
Topic: Hardware Upgrade
Replies: 4
Views: 907

Re: Hardware Upgrade

Hello everyone! The guys encountered such a problem, it is necessary to do an equipment update. At the moment, I need to raise the main channels to 20G or 40G. I have a network diagram that needs updating, please pick up ideas. How can I update the equipment on the Mikrotik vendor. I will be very g...
by mutluit
Fri Jun 12, 2020 1:12 pm
Forum: Beginner Basics
Topic: block communications of connected networks via route
Replies: 6
Views: 781

Re: block communications of connected networks via route

Thank you anav. I don't see why the question is confusing. Two networks on two interfaces should not communicate with each other. Anyway, I found how to do it. Instead of: /ip firewall filter add chain=forward src-address=192.168.10.0/24 dst-address=192.168.20.0/24 action=drop add chain=forward src...
by mutluit
Fri Jun 12, 2020 12:27 am
Forum: Beginner Basics
Topic: Hairpin with port forwarding
Replies: 14
Views: 2653

Re: Hairpin with port forwarding

I today made simple port-forwarding w/o any hairpin thing in the following thread https://forum.mikrotik.com/viewtopic.php?f=2&t=162321 I can use the WAN-IP:port from both the Internet as well from inside the LAN. I used this /ip firewall nat add chain=dstnat dst-address=192.168.1xx.xxx dst-port...
by mutluit
Thu Jun 11, 2020 11:38 pm
Forum: Beginner Basics
Topic: deleted
Replies: 0
Views: 673

Re: First MikroTik Deployment, Feedback, Questions

Sorry, can't comment on it as I'm not an expert on VLAN stuff. My deployment of it would have been by using pure basic IP routing :-) Much easier for me :-) Regarding remote administration: IMO it should be secure enough to use simple port-forwarding(s) on your WAN router to the ssh service of the d...
by mutluit
Thu Jun 11, 2020 11:13 pm
Forum: General
Topic: SFP+ operating only at 1Gbps
Replies: 1
Views: 377

Re: SFP+ operating only at 1Gbps

What devices / products are involved in that problem?
Does your other device have SFP+ or just SFP?
by mutluit
Thu Jun 11, 2020 9:28 pm
Forum: General
Topic: Unable to traceroute from MT
Replies: 2
Views: 530

Re: Unable to traceroute from MT

Seems to be a firewall issue. Maybe you are blocking UDP traffic.
I had a similar case in this thread: viewtopic.php?f=2&t=161938&p=797658
by mutluit
Thu Jun 11, 2020 8:35 pm
Forum: General
Topic: Feature requests
Replies: 1316
Views: 319742

Re: Feature requests

So I don't know whether using discrimination per country is racist, but it is definitely useless. My claim was: It is completely useless, and it tends to racism. It is useless for the reasons I described, and it tends to "let's block Nigeria because Nigerians are scammers. let's block Russia b...
by mutluit
Thu Jun 11, 2020 8:23 pm
Forum: General
Topic: Doing a simple port forwarding [SOLVED]
Replies: 7
Views: 1308

Re: Doing a simple port forwarding [SOLVED]

Any time you have multiple ports or a range of ports, going to the same LANIP, it is an opportunity to create a single rule (assuming same protocol).
Yes, indeed, makes sense.
by mutluit
Thu Jun 11, 2020 8:13 pm
Forum: General
Topic: Doing a simple port forwarding [SOLVED]
Replies: 7
Views: 1308

Re: Doing a simple port forwarding [SOLVED]

The port forwarding works ok:
iperf speed (iperf server in LAN, iperf client in Internet; Internet link is Gigabit):
[ ID] Interval        Transfer    Bandwidth       Reads   Dist(bin=16.0K)
[SUM] 0.00-10.09 sec  1.10 GBytes   938 Mbits/sec  89613    54856:34617:50:2:5:2:2:79
by mutluit
Thu Jun 11, 2020 7:14 pm
Forum: General
Topic: Doing a simple port forwarding [SOLVED]
Replies: 7
Views: 1308

Re: Doing a simple port forwarding [SOLVED]

The inconsistencies come from the examples on this wiki page, which I had used: https://wiki.mikrotik.com/wiki/Manual:IP/Firewall/NAT#Port_mapping.2Fforwarding There "to-address=" and "to-port=" are given. The CLI says "to-addresses=" and "to-ports=", but seem...
by mutluit
Thu Jun 11, 2020 6:49 pm
Forum: General
Topic: Doing a simple port forwarding [SOLVED]
Replies: 7
Views: 1308

Re: Doing a simple port forwarding [SOLVED]

add chain=dst-nat action=dstnat protocol=tcp dst-port=xxxx,yyyy,zzzz to-addresses=192.168.88.5 add chain=dst-nat action=dstnat protocol=tcp dst-port=xxxx-yyyy to-addresses=192.168.88.5 (where xxxx-yyyy describes a range of 10 IPs) add chain=dst-nat action=dstnat protocol=tcp dst-port=xxxx-yyyy to-a...
by mutluit
Thu Jun 11, 2020 6:20 pm
Forum: General
Topic: Doing a simple port forwarding [SOLVED]
Replies: 7
Views: 1308

Doing a simple port forwarding [SOLVED]

I have two routers in series. The 1st router does NAT, the 2nd router does not do NAT. On the 1st router I'm port-forwarding to the 2nd router, and on the following 2nd router with IP 192.168.1xx (its "WAN" port) I'm trying to port-forward it further to the final destination LAN-IP 192.168...
by mutluit
Thu Jun 11, 2020 3:39 am
Forum: General
Topic: CRS354, traffic sniffer, hardware offloading, port mirroring, rspan [SOLVED]
Replies: 4
Views: 1627

Re: CRS354, traffic sniffer, hardware offloading, port mirroring, rspan [SOLVED]

You have some syntax errors: there must not be any blanks around the "=" sign...
by mutluit
Wed Jun 10, 2020 9:25 pm
Forum: General
Topic: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]
Replies: 19
Views: 3267

Re: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]

On the uplink router (ISP router) one has to set static routes to these LANs as otherwise pings to WAN/Internet from these LANs can't work as the return path would be unknown. In 99% of the cases (and in 100% if we are talking about home use) ISP won't care about you LAN's and won't set any static ...
by mutluit
Wed Jun 10, 2020 8:14 pm
Forum: Beginner Basics
Topic: What seperation method should I use? [SOLVED]
Replies: 12
Views: 2017

Re: What seperation method should I use? [SOLVED]

Maybe the following can give you some inspirations: https://forum.mikrotik.com/viewtopic.php?f=2&t=162190 It creates 5 independent LANs by using basic IP routing; no VLAN, no CAPSMAN involved. If you really mean 3 networks with 3 subnets each, then you need just a router with 3+ LAN ports plus 1...
by mutluit
Wed Jun 10, 2020 7:32 pm
Forum: Beginner Basics
Topic: Hairpin with port forwarding
Replies: 14
Views: 2653

Re: Hairpin with port forwarding

It is unclear what you mean by "outside". Do you mean Internet? From the Internet you cannot connect to such an internal/private IP like 192.168.x.x. Do you have a WAN router? Is there NAT enabled? If the answer to the above questions is Yes, and your device is one that is connected to tha...
by mutluit
Wed Jun 10, 2020 7:15 pm
Forum: RouterOS v7 BETA
Topic: hardware offload on other Marvell DX switches?
Replies: 8
Views: 2451

Re: hardware offload on other Marvell DX switches?

But isn't HW Offloading already present at least on all CRS3xx devices? My CRS326 and CRS305 do have it already (both use the Marvell 98dx3236 SoC): For L2 switching, yes. What the CRS317 can now do is L3 offloading: hardware-assisted routing. It makes the CRS317 twice as fast at IP routing (within...
by mutluit
Wed Jun 10, 2020 6:51 pm
Forum: RouterOS v7 BETA
Topic: hardware offload on other Marvell DX switches?
Replies: 8
Views: 2451

Re: hardware offload on other Marvell DX switches?

I see that L3 hardware offloading is supported only on the CRS317. But isn't HW Offloading already present at least on all CRS3xx devices? My CRS326 and CRS305 do have it already (both use the Marvell 98dx3236 SoC): For example CRS305 with old software: [admin2@CRS305] /system routerboard print rou...
by mutluit
Wed Jun 10, 2020 4:41 pm
Forum: General
Topic: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]
Replies: 19
Views: 3267

Re: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]

To summarize & conclude: I now have managed to configure each of the 5 Gigabit ports of the hAP ac^2 with an independent LAN, ie. 5 independent wired LANs in total (1x WAN + 4x LAN). For this to work the ports had to be removed from the bridge, and then the bridge itself removed as well. Each po...
by mutluit
Wed Jun 10, 2020 3:26 pm
Forum: General
Topic: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]
Replies: 19
Views: 3267

Re: Using hAP ac^2 as a Multi-LAN-Router [SOLVED]

Encountered a problem: as said: ether1 is WAN ether2 is LAN2 ether3 is LAN3 From LAN2 I can ping everything (WAN, LAN2, LAN3) well. But from LAN3 I can ping all but the WAN. Very mysterious IMO. The firewall is empty. Any diagnose tips/hints to look after? Update: SOLVED! A static route to LAN3 on t...
by mutluit
Wed Jun 10, 2020 3:01 pm
Forum: General
Topic: Forum giving ERROR 500 [SOLVED]
Replies: 17
Views: 2681

Re: Forum giving ERROR 500 [SOLVED]

Can you try the same from another browser in private mode? Ok, making this reply in an other browser (Firefox Linux) in a New Private Window... The result was: BLANK WINDOW with no text at all in the window. But the posting went through. But: the error did not happen when EDITING+POSTING the post.....
by mutluit
Wed Jun 10, 2020 2:46 pm
Forum: General
Topic: Forum giving ERROR 500 [SOLVED]
Replies: 17
Views: 2681

Re: Forum giving ERROR 500 [SOLVED]

Happens since about 2 days also in my Opera web browser in Linux. It says This page isn’t working forum.mikrotik.com is currently unable to handle this request. But the posting still goes thru. Ie. the above error message happens when making a posting. But the posting still gets posted successfully....
by mutluit
Wed Jun 10, 2020 2:44 pm
Forum: General
Topic: MikroTik notification server down?
Replies: 2
Views: 640

Re: MikroTik notification server down?

Are you talking about forum notifications or any other ones?
Forum notifications. Ie. if a reply happens to postings here where one participates.
by mutluit
Wed Jun 10, 2020 2:27 pm
Forum: General
Topic: MikroTik notification server down?
Replies: 2
Views: 640

MikroTik notification server down?

I think since yesterday I no longer get any email notifications, even though I should have got notifications about new postings in threads I'm subscribed to.
Anybody else missing such notifications?
Is maybe the Mikrotik server down or faulty?