Community discussions

MikroTik App

Search found 166 matches

by rkrisi
Wed Mar 06, 2024 10:13 am
Forum: General
Topic: [openvpn][udp]Authenticate/Decrypt packet error: bad packet ID (may be a replay)
Replies: 0
Views: 324

[openvpn][udp]Authenticate/Decrypt packet error: bad packet ID (may be a replay)

Dear All, We are using openVPN several years ago with a growing number of clients. Right now, around ~30-40 clients. We want to transfer to UDP protocol, we were only using TCP mode because of lack of support in previous RouterOS releases. I have configured a second openvpn server instance on differ...
by rkrisi
Tue Jan 30, 2024 5:35 pm
Forum: General
Topic: OpenLDAP login with RADIUS [SOLVED]
Replies: 2
Views: 715

Re: OpenLDAP login with RADIUS [SOLVED]

MSCHAP will definitely work against plaintext credentials, if your setup does not it is most likely a FreeRADIUS configuration error - run it with debugging enabled and look at the logs. Depending on how your password changing is implemented you should be able to incorporate something which will st...
by rkrisi
Wed Jan 24, 2024 9:46 am
Forum: General
Topic: OpenLDAP login with RADIUS [SOLVED]
Replies: 2
Views: 715

OpenLDAP login with RADIUS [SOLVED]

Dear All, I want to implement login for network admins through our OpenLDAP database. I have configured FreeRadius for this purpose and configured RADIUS on the router. However login is not working as MikroTik is using mschap protocol for login and obviously in openldap we don't have NT-Password or ...
by rkrisi
Wed Jul 19, 2023 1:41 am
Forum: Wireless Networking
Topic: Default config for Wireless Wire Cube Pro - CubeG-5ac60aypair
Replies: 12
Views: 2687

Re: Default config for Wireless Wire Cube Pro - CubeG-5ac60aypair

I would also be interested in how 5 Ghz backup is configured in default pair config
Answer is here: viewtopic.php?t=170983#p841316
by rkrisi
Tue Jul 18, 2023 6:30 pm
Forum: Wireless Networking
Topic: Default config for Wireless Wire Cube Pro - CubeG-5ac60aypair
Replies: 12
Views: 2687

Re: Default config for Wireless Wire Cube Pro - CubeG-5ac60aypair

I would also be interested in how 5 Ghz backup is configured in default pair config
by rkrisi
Wed May 31, 2023 8:20 pm
Forum: Announcements
Topic: v7.9.2 [stable] is released!
Replies: 72
Views: 26444

Re: v7.9.2 [stable] is released!

Most of us dont have a rocket ship to get there so keep dreaming. OVPN, is like a zit that wont go away....... Lance it cauterize it etc............ And yes HOLVOE, once we get rid of the useless OVPN code, there will be tons of room, for Zerotrust Cloudflare tunnel WITHIN ROS , let alone as an opt...
by rkrisi
Wed May 31, 2023 5:31 pm
Forum: Announcements
Topic: v7.9.2 [stable] is released!
Replies: 72
Views: 26444

Re: v7.9.2 [stable] is released!

I have multiple problems with RB4011 since v7.8. After some time, the bridge ports stop sending any packets, router is inaccessible. This might be solved with this one (from 7.10rc1): *) bridge - fixed HW offloading for vlan-filtered bridge on devices with multiple switches (introduced in v7.8 ); Ho...
by rkrisi
Wed May 10, 2023 6:54 pm
Forum: General
Topic: Multiple Wireless stations [SOLVED]
Replies: 2
Views: 608

Re: Multiple Wireless stations [SOLVED]

If I understand that you want to use a station to connect to multiple router with different ssids and passwords. You can use the connect tab under wireless tables to define the ssids and passwords. Just leave the wireless interface with generic info and no ssid.
Yes, thanks, I will try this!
by rkrisi
Wed May 10, 2023 1:50 am
Forum: General
Topic: Multiple Wireless stations [SOLVED]
Replies: 2
Views: 608

Multiple Wireless stations [SOLVED]

Dear Community! I want to create a config, where I define more Virtual Wireless interfaces (all in station mode) with different SSID and Password, and the router should connect to any of them available. However I'm not able to do it this way. If the main interface is a station, it will not become ac...
by rkrisi
Wed Apr 19, 2023 12:34 am
Forum: General
Topic: Place VPN client connection in seperate VRF
Replies: 21
Views: 3392

Re: Place VPN client connection in seperate VRF

Everything you've (rkrisi) asked has been completely clear. It may be because I have spent a lot of time working with management VRFs in the past, and understand their role in segregating overlapping private IP address space (customer IP vs management IP). My familiarity comes from working on such ...
by rkrisi
Mon Feb 13, 2023 2:24 pm
Forum: Beginner Basics
Topic: Hex S doesn't show any details for the SFP module on v7.3.1
Replies: 14
Views: 1996

Re: Hex S doesn't show any details for the SFP module on v7.3.1



I'm using 7.7
and where did you write it?
Nowhere. I'm not the original author of this post. I missed that the title says 7.3.1
by rkrisi
Sun Feb 12, 2023 5:29 pm
Forum: Beginner Basics
Topic: Hex S doesn't show any details for the SFP module on v7.3.1
Replies: 14
Views: 1996

Re: Hex S doesn't show any details for the SFP module on v7.3.1

Same problem for me. Just updated a hexS. On RouterOS 6 all details were visible. On RouterOS 7 everything is blank... Link is OK.
Why you still to use RouterOS 7.3.1????
I'm using 7.7
by rkrisi
Sun Feb 12, 2023 3:49 pm
Forum: Beginner Basics
Topic: Hex S doesn't show any details for the SFP module on v7.3.1
Replies: 14
Views: 1996

Re: Hex S doesn't show any details for the SFP module on v7.3.1

Same problem for me. Just updated a hexS. On RouterOS 6 all details were visible. On RouterOS 7 everything is blank... Link is OK.
by rkrisi
Tue Jan 17, 2023 5:23 pm
Forum: Announcements
Topic: v7.7 [stable] is released!
Replies: 357
Views: 114399

Re: v7.7 [stable] is released!

I have experienced several messages like "private-dhcp offering lease 192.168.111.50 for 94:EA:32:35:52:98 without success" after upgrading to 7.7. The result was that the clients were unable to access the network nor Internet. Clients are mostly connected via CAP managed APs. This happen...
by rkrisi
Fri Jan 06, 2023 8:12 am
Forum: General
Topic: Place VPN client connection in seperate VRF
Replies: 21
Views: 3392

Re: Place VPN client connection in seperate VRF

Same answer put CHR on that VPS and run wireguard through the CHR on VPS............... get rid of openvpn No VRF required........... I still can't understand your answers. This is a working system, not a hobby project where I can change anything I want. And also I still can't understand how this w...
by rkrisi
Fri Jan 06, 2023 8:09 am
Forum: General
Topic: Place VPN client connection in seperate VRF
Replies: 21
Views: 3392

Re: Place VPN client connection in seperate VRF

Yes, exactly what I would like to achieve! Thanks for your diagram. However I did not find any working solution for this. I'm open to other options as well, but the "client" networks behind these routers usually include several subnets, sometimes even overlapping with my VPN subnet. That'...
by rkrisi
Thu Jan 05, 2023 3:35 pm
Forum: General
Topic: Place VPN client connection in seperate VRF
Replies: 21
Views: 3392

Re: Place VPN client connection in seperate VRF

Ahh and when you say VPS, is it a specific type of server? What can be hosted on it? do not overcomplicate the setup i guess the setup is something like this: 28-12-2022_MTforum_ovpnclientInVrf.png AFAIU the OP just wants to have the remote mgmt tunnel in its own "mgmt vrf" on the router ...
by rkrisi
Mon Nov 14, 2022 1:23 pm
Forum: General
Topic: Place VPN client connection in seperate VRF
Replies: 21
Views: 3392

Re: Place VPN client connection in seperate VRF

Once again what you state is more confusing then helpful. What do you mean mikrotik has to be the client side? The client side to what...... A. do you mean the MT router Wireguard has a publicly accessible WANIP and thus can be used as a server? B. do you mean that the MT router is a client and doe...
by rkrisi
Sat Nov 12, 2022 8:43 pm
Forum: General
Topic: Place VPN client connection in seperate VRF
Replies: 21
Views: 3392

Re: Place VPN client connection in seperate VRF

You are correct, I have no clue how your network is cobbled together or why. Seems pretty simple to me, use the VPN capability in MT and drop this ovpnserver. Done! I can change to any kind of VPN, but it has to be a client on the Mikrotik side, because these routers are usually behind a CGNAT or d...
by rkrisi
Sat Nov 12, 2022 8:16 pm
Forum: General
Topic: Place VPN client connection in seperate VRF
Replies: 21
Views: 3392

Re: Place VPN client connection in seperate VRF

The requirement is clear, something like winbox in remotely via the iphone over wireguard, where the incoming admin can connect to the router. What makes you think this has anything to do with VRF??? A normal wireguard connection and knowledge of firewall rules will meet the requirements! To spell ...
by rkrisi
Sat Nov 12, 2022 7:07 pm
Forum: General
Topic: Place VPN client connection in seperate VRF
Replies: 21
Views: 3392

Re: Place VPN client connection in seperate VRF

Yes, VRF seems like a clean solution but often it is just a little bit too limited... and the configuration is incoherent. You always need to check the manual because in some places you specify VRF separately, in other places you can use address@vrf notation. Still, all services operate in a single...
by rkrisi
Fri Nov 11, 2022 6:52 pm
Forum: General
Topic: Place VPN client connection in seperate VRF
Replies: 21
Views: 3392

Re: Place VPN client connection in seperate VRF

When your use of VRF is just a direction you took for this, and not some mandatory situation, you can achieve the same thing using a firewall forward rule. Drop any forward traffic towards that interface. Your management traffic towards the router will only appear in input and output chains, not in...
by rkrisi
Wed Nov 09, 2022 7:18 pm
Forum: General
Topic: Place VPN client connection in seperate VRF
Replies: 21
Views: 3392

Re: Place VPN client connection in seperate VRF

When your use of VRF is just a direction you took for this, and not some mandatory situation, you can achieve the same thing using a firewall forward rule. Drop any forward traffic towards that interface. Your management traffic towards the router will only appear in input and output chains, not in...
by rkrisi
Wed Nov 09, 2022 4:51 pm
Forum: General
Topic: Place VPN client connection in seperate VRF
Replies: 21
Views: 3392

Place VPN client connection in seperate VRF

Hi all! I want to make a VPN connection from a router for management purposes. So I want to place this VPN in a seperate VRF, so that the VPN cannot be accessed from the router interfaces, the VPN is only there to connect to it remotely. I have created the ovpn-client as usual, and created a VRF tab...
by rkrisi
Wed Nov 09, 2022 3:43 pm
Forum: General
Topic: Help in setting up VRF routing [SOLVED]
Replies: 2
Views: 1187

Re: Help in setting up VRF routing [SOLVED]

Thanks for everyone!

My initial config and idea was right, but it did not work first because some old VRF with the same name was stuck in the router.

Recreating the VRF with different name solved all problems
by rkrisi
Wed Oct 19, 2022 5:35 pm
Forum: General
Topic: Help in setting up VRF routing [SOLVED]
Replies: 2
Views: 1187

Help in setting up VRF routing [SOLVED]

Hi all! I have an RB4011 router and a hexS switch. RB4011 does routing, hexS only provides switch access ports to hosts. Uplink internet is connected to RB4011 directly. I want to add a second (LTE) backup connection to the network. Since RB4011 does not have any LTE and USB interface (and also loca...
by rkrisi
Mon Sep 26, 2022 9:30 pm
Forum: General
Topic: Branding package confusion [SOLVED]
Replies: 2
Views: 1063

Re: Branding package confusion [SOLVED]

It seems that the default configuration works. It was just a mistake by me (some used list interface groups were not created before). Also the logo is now shows the new one after a reset. The login page also works after a reset. So concluding my post, the 'Read this first' instructions says that the...
by rkrisi
Mon Sep 26, 2022 12:58 pm
Forum: General
Topic: Branding package confusion [SOLVED]
Replies: 2
Views: 1063

Branding package confusion [SOLVED]

Hi everyone! I have tried to create a full branding package for our managed devices. This is what I have done: Created an ASCII logo - works, always visible in the terminal Created a "mikrotik_logo.png" file and uploaded to Webfig logo. This works, but the resulting logo was too large. I h...
by rkrisi
Wed Aug 31, 2022 11:40 am
Forum: General
Topic: openVPN only router access
Replies: 4
Views: 530

Re: openVPN only router access

So you have overlapping subnets? That makes it more difficult, but probably still doable using another routing table. Either using some semi-manual config for VPN client (I don't use RouterOS as OpenVPN client, so I'm not sure if that's possible) or using VRF (I'm not the best friend with that eith...
by rkrisi
Thu Aug 25, 2022 1:34 pm
Forum: General
Topic: openVPN only router access
Replies: 4
Views: 530

Re: openVPN only router access

Unless you're after something special, there's mighty tool called firewall, it can allow access to tunnel from router and block any attempts from elsewhere. Well the mighty tool called firewall will not work here. I want the router to forward packets to the default gateway from clients even if it i...
by rkrisi
Wed Aug 24, 2022 3:04 pm
Forum: General
Topic: openVPN only router access
Replies: 4
Views: 530

openVPN only router access

Hi!

Is it possible to configure openVPN client on Mikrotik router so that only the router can access the routed VPN subnet?

Like deleting the route from the routing table, but only allow that particular router to access that subnet.

Thanks!
by rkrisi
Mon Jun 27, 2022 7:50 pm
Forum: General
Topic: Route LTE traffic in VLAN
Replies: 1
Views: 584

Route LTE traffic in VLAN

Dear Community! I have a fallback LTE device connected to one of my Mikrotik switch (it is connected to the switch because of signal strength and bandwidth and not directly to the router - also my router RB4011 does not have a USB). So the scheme looks like this: LTE Modem -> hex S switch -> RB4011 ...
by rkrisi
Thu Mar 31, 2022 9:24 pm
Forum: General
Topic: DHCP client script on ROS6 [SOLVED]
Replies: 2
Views: 1782

Re: DHCP client script on ROS6 [SOLVED]

Thanks solved! Use this: :log warning ("New ISP Gateway: " . $"gateway-address") :log warning ("New ISP IP: " . $"lease-address") To find such problems, put the script in /system scripts and do: /system script print where name="yourscript" Broken hig...
by rkrisi
Thu Mar 31, 2022 1:47 pm
Forum: General
Topic: DHCP client script on ROS6 [SOLVED]
Replies: 2
Views: 1782

DHCP client script on ROS6 [SOLVED]

Hi everyone, I have a router with a specific DHCP client script: :log warning "Setting new IP addresses from DHCP-client"; :if ($"bound"=1) do={ :log warning "Setting new IP addresses from DHCP-client"; /ip firewall address-list remove [/ip firewall address-list find li...
by rkrisi
Thu Mar 10, 2022 2:27 pm
Forum: General
Topic: RouterOS 7 Bridge VLAN/DHCP client issue after upgrade
Replies: 23
Views: 6846

Re: RouterOS 7 Bridge VLAN/DHCP client issue after upgrade

I have used the dhcp client/bridge combo for quite some time on crs3xx switches. It worked flawlessly in the 6.x and 7.x versions until 7.2rc2/3. I reported the issue with support and in my report pointed out that switching to tagged/vlan interface config did indeed work. Both methods have their us...
by rkrisi
Wed Mar 09, 2022 2:44 pm
Forum: General
Topic: RouterOS 7 Bridge VLAN/DHCP client issue after upgrade
Replies: 23
Views: 6846

Re: RouterOS 7 Bridge VLAN issue after upgrade

In a VLAN setup the bridge interface should never get a direct IP. Thats a nogo ! IPs should only be distributed on the VLAN IP Interfaces directly ! See https://administrator.de/contentid/367186 for a detailed example. Unfortunately German but the describing screenshots are pretty self explaining....
by rkrisi
Wed Mar 09, 2022 10:28 am
Forum: General
Topic: RouterOS 7 Bridge VLAN/DHCP client issue after upgrade
Replies: 23
Views: 6846

Re: RouterOS 7 Bridge VLAN issue after upgrade

Is the extract still accurate in this post ? I have an RB760iGS in a lab environment with v7.2rc4, and I could try loading from a clean state to see if I can reproduce what you see. I would use my ER-X as the "router" with dhcp server. # mar/06/2022 20:54:33 by RouterOS 7.2rc4 # model = R...
by rkrisi
Mon Mar 07, 2022 2:37 am
Forum: General
Topic: RouterOS 7 Bridge VLAN/DHCP client issue after upgrade
Replies: 23
Views: 6846

Re: RouterOS 7 Bridge VLAN issue after upgrade

I had a little time to experiment with this. So I turned off hw offload for all bridge ports first. Then I tried to update to 7.1.3. Same as before, only minor change is that the device got an IP address through the DHCP client! But nothing else worked. Even after this, I was unable to ping the rout...
by rkrisi
Sun Mar 06, 2022 12:55 am
Forum: General
Topic: RouterOS 7 Bridge VLAN/DHCP client issue after upgrade
Replies: 23
Views: 6846

Re: RouterOS 7 Bridge VLAN issue after upgrade

The original configuration using setting a PVID on the bridge-to-CPU interface making it an access port is absolutely fine, others may not have realised this is not your router and so does not require all of the VLANs trunked to the CPU. You can test the hardware-offloaded switching hypothesis by s...
by rkrisi
Sat Mar 05, 2022 2:38 pm
Forum: General
Topic: RouterOS 7 Bridge VLAN/DHCP client issue after upgrade
Replies: 23
Views: 6846

Re: RouterOS 7 Bridge VLAN issue after upgrade

@rkrisi starting from v7.1rc5 bridge vlan filtering is done using the switch chip in MT7621 devices, from the 7.1rc5 changelog: *) bridge - added HW offload support for vlan-filtering on MT7621 switch chip (hEX, hEX S, RBM33G, RBM11G, LtAP); Prior to that release (including RouterOS 6) bridge vlan ...
by rkrisi
Sat Mar 05, 2022 2:37 pm
Forum: General
Topic: RouterOS 7 Bridge VLAN/DHCP client issue after upgrade
Replies: 23
Views: 6846

Re: RouterOS 7 Bridge VLAN issue after upgrade

Is the "trunk link" connected to ether1 using a native vlan 10? i.e. a "hybrid" in MikroTik terminology. If so, make a backup (because I have not tried this myself) and copy it to a pc you can restore from. Also export and save. Go into safe mode, just in case you loose connecti...
by rkrisi
Sun Feb 27, 2022 10:47 pm
Forum: General
Topic: RouterOS 7 Bridge VLAN/DHCP client issue after upgrade
Replies: 23
Views: 6846

Re: RouterOS 7 Bridge VLAN issue after upgrade

Hard to say because you provided an incomplete config posting. All the rules work together so if you leave some out, I would only be guessing............ default PVID is 1, and it should be left so. If you do use vlans, then use vlans and the bridge should do nothing else but be the bridge. You hav...
by rkrisi
Sun Feb 27, 2022 9:31 pm
Forum: General
Topic: RouterOS 7 Bridge VLAN/DHCP client issue after upgrade
Replies: 23
Views: 6846

Re: RouterOS 7 Bridge VLAN issue after upgrade

I would never use pvid other than the default for the bridge, not sure why you do that?? In any case you need to tag the bridge in bridgevlan settings. /interface bridge vlan add bridge=bridge tagged=ether1, bridge untagged=ether4,ether5 vlan-ids=10 add bridge=bridge tagged=ether1, bridge untagged=...
by rkrisi
Thu Feb 24, 2022 7:12 pm
Forum: General
Topic: RouterOS 7 Bridge VLAN/DHCP client issue after upgrade
Replies: 23
Views: 6846

RouterOS 7 Bridge VLAN/DHCP client issue after upgrade

I have a fairly simple config which works great on RouterOS 6. Upgrading to RouterOS 7, breaks this config, no IP address is obtained through the trunk VLAN port, no communication (also access-port connected devices cannot communicate). What might be wrong, needs to be changed? # feb/24/2022 00:00:0...
by rkrisi
Mon Sep 20, 2021 1:41 pm
Forum: General
Topic: Only 100Mbps full-duplex speed on 1Gbps port
Replies: 5
Views: 3294

Re: Only 100Mbps full-duplex speed on 1Gbps port

I have tried this cable outside the wall (though it is much shorter) with a different socket (not that in-wall socket I have everywhere), that one worked perfectly with 1Gbps speed. That's the answer. You have a cable/socket hardware problem. Make sure your cable and socket are 1Gbps compatible and...
by rkrisi
Mon Sep 20, 2021 1:26 pm
Forum: General
Topic: Only 100Mbps full-duplex speed on 1Gbps port
Replies: 5
Views: 3294

Only 100Mbps full-duplex speed on 1Gbps port

Dear Community! I have wired my home and in some rooms the link is only 100Mbps full-duplex instead 1Gbps full-duplex. On the both end of the link, there are Mikrotik devices (and confirmed that both can do 1Gbps speed). One side: RB4011 Other side: hexS FTP Cat6 cable used in wall. In other rooms w...
by rkrisi
Mon May 10, 2021 10:42 am
Forum: RouterBOARD hardware
Topic: Are the antennas on the RB4011 detachable?
Replies: 5
Views: 3242

Re: Are the antennas on the RB4011 detachable?

Can you remove the antennas from the housing? I mean I know that the cable can't be removed, but can you fully remove the antennas, so that the housing would look like an RB4011 without wifi?
by rkrisi
Wed Apr 14, 2021 12:38 pm
Forum: General
Topic: Block openVPN failed logins
Replies: 2
Views: 1372

Block openVPN failed logins

Dear Community! It is possible to somehow block IP addresses when they failed to login through openVPN after X times? I can see in the log that sometimes from random IP address they try to connect through openVPN. The only problem is that from the log I can only see that a 'TCP connection estabilish...
by rkrisi
Sun Jan 31, 2021 5:58 pm
Forum: General
Topic: Validate Mikrotik config scripts
Replies: 3
Views: 1323

Re: Validate Mikrotik config scripts

Install hyperv and a chr. Suits your case.
I thought about this, but I hoped that there are easier methods. Anyway I will try this, thanks!
by rkrisi
Sat Jan 30, 2021 9:29 pm
Forum: General
Topic: Validate Mikrotik config scripts
Replies: 3
Views: 1323

Validate Mikrotik config scripts

Hi Everyone! We are using several Mikrotik devices in our network and more and more installed every day. Usually I have to write the config scripts without the access to an actual Mikrotik hardware. I thought about it would be great if I could somehow validate these hand written configs without real...
by rkrisi
Sun Dec 06, 2020 6:41 pm
Forum: General
Topic: openVPN can't access client subnet [SOLVED]
Replies: 3
Views: 1489

Re: openVPN can't access client subnet [SOLVED]

Solved. Needed to add an iptables MASQUERADE for the RPI:
iptables -t nat -A POSTROUTING -d (here your local network) -j MASQUERADE
by rkrisi
Fri Sep 18, 2020 5:56 pm
Forum: Useful user articles
Topic: Advanced Routing Failover without Scripting
Replies: 268
Views: 136990

Re: Advanced Routing Failover without Scripting

Correct
Thanks for your help!
by rkrisi
Fri Sep 18, 2020 3:17 pm
Forum: Useful user articles
Topic: Advanced Routing Failover without Scripting
Replies: 268
Views: 136990

Re: Advanced Routing Failover without Scripting

So why did you use routing marks in the original post in the first place? Because that config was for traffic balancing. Failover scenario can be greatly simplified, as you can see :) However this way, I need to update at least GW1_IP in case it changes... What is the best way to do this? DHCP clie...
by rkrisi
Tue Sep 15, 2020 10:18 pm
Forum: Announcements
Topic: v6.46.7 [long-term] is released!
Replies: 45
Views: 26655

Re: v6.46.7 [long-term] is released!

Can I downgrade to this from 6.47 without losing the config?
Yes, make a backup to feel more comfortable anyways
The problem is not the backups (they are done automatically every day), but that these devices are in a remote location, so I can't access them physically.
by rkrisi
Tue Sep 15, 2020 9:20 pm
Forum: Announcements
Topic: v6.46.7 [long-term] is released!
Replies: 45
Views: 26655

Re: v6.46.7 [long-term] is released!

Can I downgrade to this from 6.47 without losing the config?
by rkrisi
Wed Sep 02, 2020 1:57 pm
Forum: Useful user articles
Topic: Advanced Routing Failover without Scripting
Replies: 268
Views: 136990

Re: Advanced Routing Failover without Scripting

Can I use multiple CheckingHosts here? If yes, how? Sure, just add a route to a new checking host and add default route via that host. One of those default routes will be active. Also is it possible to send Email when the failover link becomes active? You need some external script to check, for exa...
by rkrisi
Tue Sep 01, 2020 1:50 pm
Forum: Useful user articles
Topic: Advanced Routing Failover without Scripting
Replies: 268
Views: 136990

Re: Advanced Routing Failover without Scripting

So why did you use routing marks in the original post in the first place? Because that config was for traffic balancing. Failover scenario can be greatly simplified, as you can see :) However this way, I need to update at least GW1_IP in case it changes... What is the best way to do this? DHCP clie...
by rkrisi
Tue Sep 01, 2020 12:29 pm
Forum: Useful user articles
Topic: Advanced Routing Failover without Scripting
Replies: 268
Views: 136990

Re: Advanced Routing Failover without Scripting

"gateway=etherN" works not the same as with point-to-point interfaces, and definitely not as you expect. Don't use this. Gateways are static So use gateway IPs in gateway= parameter, that's exactly what you need. Yes, sorry I forgot that this would only work with point-to-point interfaces...
by rkrisi
Mon Aug 31, 2020 6:59 pm
Forum: Useful user articles
Topic: Advanced Routing Failover without Scripting
Replies: 268
Views: 136990

Re: Advanced Routing Failover without Scripting

If your gateways are static (I didn't see any situations where they are not), just disable adding the default route. If they are not, you may use DHCP Client Script to update your routes with correct gateways. Gateways are static, I have 2 dedicated uplink gateway, but it's IP addresses are not sta...
by rkrisi
Mon Aug 31, 2020 2:25 pm
Forum: Useful user articles
Topic: Advanced Routing Failover without Scripting
Replies: 268
Views: 136990

Re: Advanced Routing Failover without Scripting

I have tried setting the routes as described in the first post, but it did not work. Later from the thread I realized that I would need to setup mangle rules for this to work. You don't need routing marks at all: /ip route add dst-address=CheckingHost gateway=GW_MAIN_IP scope=10 add distance=1 gate...
by rkrisi
Mon Aug 31, 2020 1:39 am
Forum: Useful user articles
Topic: Advanced Routing Failover without Scripting
Replies: 268
Views: 136990

Re: Advanced Routing Failover without Scripting

I would need to have a failover link in my setup. Reading through this thread, I'm a little bit confused and I was unable to use this in my setup. Can someone help me? Is this a good way to go? What I would need: I have 2 uplinks (ether) and I would need if the first (main) goes down to route all tr...
by rkrisi
Sun Aug 30, 2020 12:45 pm
Forum: General
Topic: Configure dual WAN with dynamic IPs
Replies: 8
Views: 2260

Re: Configure dual WAN with dynamic IPs

Interface can be gateway only when it's point to point type, because there's only one device on the other end and it receives everything. Ethernet can have many different devices connected at the same time, so traffic must be sent to gateway's MAC address (which router gets automaticaly from IP add...
by rkrisi
Sun Aug 30, 2020 1:38 am
Forum: General
Topic: Configure dual WAN with dynamic IPs
Replies: 8
Views: 2260

Re: Configure dual WAN with dynamic IPs

Dynamic default route doesn't check gateway. You can change that with routing filters: https://forum.mikrotik.com/viewtopic.php?p=605415#p605415 But even if gateway is reachable, it still doesn't guarantee that internet will work, because there can be something broken futher in ISP's network. Well ...
by rkrisi
Sun Aug 30, 2020 1:06 am
Forum: General
Topic: Configure dual WAN with dynamic IPs
Replies: 8
Views: 2260

Re: Configure dual WAN with dynamic IPs

Actually, I wasn't reading carefully. If you'd be interested only in changing default route distance, DHCP client has default-route-distance parameter, so you can just set it there and you don't need anything else. If you want better detection whether connections works or not, you may try e.g. Adva...
by rkrisi
Sat Aug 29, 2020 10:52 pm
Forum: General
Topic: Configure dual WAN with dynamic IPs
Replies: 8
Views: 2260

Re: Configure dual WAN with dynamic IPs

You can use dhcp lease script to update routes: https://wiki.mikrotik.com/wiki/Manual:IP/DHCP_Client#Lease_script_example If it looks complicated, it can be made much simpler: https://forum.mikrotik.com/viewtopic.php?p=748218#p748218 Thanks this looks great! However sometimes the dhcp client not lo...
by rkrisi
Sat Aug 29, 2020 10:14 pm
Forum: General
Topic: Configure dual WAN with dynamic IPs
Replies: 8
Views: 2260

Configure dual WAN with dynamic IPs

Dear Community! I want to configure my router to use 2 WAN connection and the second should be used only when the first and main WAN is not reachable. However I'm stuck with the current config: [*] Both WAN uses dynamic IPs, so I can't set default routes manually as most guide says [*] I need dhcp c...
by rkrisi
Tue Aug 25, 2020 11:31 am
Forum: General
Topic: openVPN can't access client subnet [SOLVED]
Replies: 3
Views: 1489

Re: openVPN can't access client subnet [SOLVED]

Is there a route back from client subnet to your subnet? if not, there must be. If not the device in client subnet tries to reply through default gateway. Yes there is! If I try to ping anything from this client to my subnet, it works correctly. However the routes looks a little suspicious, I don't...
by rkrisi
Tue Aug 25, 2020 12:12 am
Forum: General
Topic: openVPN can't access client subnet [SOLVED]
Replies: 3
Views: 1489

openVPN can't access client subnet [SOLVED]

Dear Community! I have an openVPN server configured on a RB4011 router. Everything works perfectly, except one thing: I want to access one of the clients subnet, but I can't get it to work. The VPN subnet is 10.0.98.0/24 The client subnet is 192.168.1.0/24 I have added a static route to 192.168.1.0/...
by rkrisi
Mon Aug 24, 2020 1:40 pm
Forum: General
Topic: CAPsMAN with Wireless Repeater [SOLVED]
Replies: 11
Views: 5429

Re: CAPsMAN with Wireless Repeater [SOLVED]

It is possible to run multiple virtual wireless interfaces on top of single physical interface with CAPsMAN just like it's possible with local configuration. In provisioning part, use comma-separated list in slave-configurations= property. The only gotcha with CAPsMAN is when one wants to configure...
by rkrisi
Fri Aug 21, 2020 6:23 pm
Forum: General
Topic: CAPsMAN with Wireless Repeater [SOLVED]
Replies: 11
Views: 5429

Re: CAPsMAN with Wireless Repeater [SOLVED]

CAPsMAN needs to control whole wireless interface (physical/primary and virtual APs). With setup wanted by @OP there's a typical chicken&egg problem: device needs primary wireless interface up&running to connect to CAPsMAN so CAPsMAN can not really configure that interface anymore. So no, w...
by rkrisi
Thu Aug 20, 2020 9:14 am
Forum: General
Topic: CAPsMAN with Wireless Repeater [SOLVED]
Replies: 11
Views: 5429

Re: CAPsMAN with Wireless Repeater [SOLVED]

Well it seems you can't run CAPsMAN on virtual Wireless interfaces... and also you can't create station config in capsman...
by rkrisi
Thu Jul 16, 2020 3:57 pm
Forum: General
Topic: CAPsMAN with Wireless Repeater [SOLVED]
Replies: 11
Views: 5429

Re: CAPsMAN with Wireless Repeater [SOLVED]

This is my current caps-man config on the manager: /caps-man channel add band=2ghz-g/n control-channel-width=20mhz frequency=2422 name=channel_2ghz add band=5ghz-a/n/ac frequency=5500 name=channel_5ghz /caps-man datapath add local-forwarding=yes name=datapath1 /caps-man security add authentication-t...
by rkrisi
Thu Jul 16, 2020 11:34 am
Forum: General
Topic: CAPsMAN with Wireless Repeater [SOLVED]
Replies: 11
Views: 5429

Re: CAPsMAN with Wireless Repeater [SOLVED]

I have tried setting up this way, but I lost access to the AP.
I don't know what I did wrong, it would be great if somehow I could use CAPsMAN as I would like...
by rkrisi
Thu Jul 16, 2020 11:33 am
Forum: General
Topic: PIM between VLANs [SOLVED]
Replies: 4
Views: 3023

Re: PIM between VLANs [SOLVED]

It seems that I had other problems in my network setup, so not the PIM configuration was incorrect.
Anyway for my use-case an IGMP proxy was enough which is much easier to configure.
by rkrisi
Thu Jul 09, 2020 3:57 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

For me it is also more important to have a stable connection rather than a faster one but with some hiccups. However comparing range and overall wireless stability, my old router performed the same way (no real wireless disconnection problems or whatsoever) - it had other problems, that's why I chan...
by rkrisi
Wed Jul 08, 2020 8:39 pm
Forum: General
Topic: Setting up Avahi Reflector in Mikrotik [SOLVED]
Replies: 29
Views: 23604

Re: Setting up Avahi Reflector in Mikrotik [SOLVED]

Finally solved this! So from Mikrotik perspective, everything was set up properly. You might need IGMP proxy for some devices, but no need for PIM (some suggested that IGMP is not enough, even though every guide says it uses IGMP), just a simple IGMP-Proxy setup will do. I have switched from avahi t...
by rkrisi
Wed Jul 08, 2020 2:07 am
Forum: General
Topic: Setting up Avahi Reflector in Mikrotik [SOLVED]
Replies: 29
Views: 23604

Re: Setting up Avahi Reflector in Mikrotik [SOLVED]

Ok I might have found the problem and maybe someone could help me with a correct avahi reflector config IGMP forwarding is really needed, though looking at Wireshark a simple IGMP Proxy setup is enough, no need to mess with PIM. The problem seems to be with avahi-reflector, but I don't know what is ...
by rkrisi
Tue Jul 07, 2020 12:51 pm
Forum: General
Topic: Setting up Avahi Reflector in Mikrotik [SOLVED]
Replies: 29
Views: 23604

Re: Setting up Avahi Reflector in Mikrotik [SOLVED]

Sorry I spaced post those filters rules.... I will try to get at it when I get home. That is strange the new device cannot work. What is the igmp all for? It seems that some device don't just use mDNS but also IGMP to discover devices. Even Chromecast for Chrome mentions that IGMP is also needed. M...
by rkrisi
Sun Jul 05, 2020 9:47 pm
Forum: General
Topic: Setting up Avahi Reflector in Mikrotik [SOLVED]
Replies: 29
Views: 23604

Re: Setting up Avahi Reflector in Mikrotik [SOLVED]

It seems that on a new device even on my private vlan the Chromecasts won't work. On my private vlan everything is accessible and for debugging purposes now everything is also allowed from the IoT network, but still I can't get this to work. I have downloaded a Bonjour Browser which lists the mDNS t...
by rkrisi
Sun Jul 05, 2020 8:12 pm
Forum: General
Topic: PIM between VLANs [SOLVED]
Replies: 4
Views: 3023

Re: PIM between VLANs [SOLVED]

All of the IGMP groups are excluded and I don't know why. It should be forward right? (So that these igmp groups will be present in all vlan v2E vlan_iot 224.0.0.2 0.0.0.0 4m12s v2E vlan_iot 224.0.0.13 0.0.0.0 4m12s v2E vlan_iot 224.0.0.22 0.0.0.0 4m6s v2E vlan_iot 224.0.1.187 0.0.0.0 4m5s v2E vlan_...
by rkrisi
Sun Jul 05, 2020 1:13 am
Forum: General
Topic: PIM between VLANs [SOLVED]
Replies: 4
Views: 3023

Re: PIM between VLANs [SOLVED]

I'm still lost with this as I did not find any great example how you could use PIM between VLANs on the same router. Would be great if someone could help me so that from one VLAN the multicast will be forwarded to all other VLANs as well.
by rkrisi
Fri Jul 03, 2020 7:55 pm
Forum: General
Topic: Setting up Avahi Reflector in Mikrotik [SOLVED]
Replies: 29
Views: 23604

Re: Setting up Avahi Reflector in Mikrotik [SOLVED]

Well, you might be right, so I would try this. You mean to allow traffic only to that device? But: It was the input chain rule which caused Chromecast devices to appear. So I added a rule to the input chain, not forward which allows access to the whole network from guest network. The reflector has ...
by rkrisi
Fri Jul 03, 2020 5:34 pm
Forum: General
Topic: Setting up Avahi Reflector in Mikrotik [SOLVED]
Replies: 29
Views: 23604

Re: Setting up Avahi Reflector in Mikrotik [SOLVED]

So the progress is: Chromecast devices work fully on my main network. Guest network does not seem to work, even with mDNS reflection. On Guest network everything is blocked except WAN traffic. As soon as I enable the vlan_guest network to access everything, devices appear. I don't know what I need ...
by rkrisi
Fri Jul 03, 2020 4:30 pm
Forum: General
Topic: Setting up Avahi Reflector in Mikrotik [SOLVED]
Replies: 29
Views: 23604

Re: Setting up Avahi Reflector in Mikrotik [SOLVED]

So the progress is: Chromecast devices work fully on my main network. Guest network does not seem to work, even with mDNS reflection. On Guest network everything is blocked except WAN traffic. As soon as I enable the vlan_guest network to access everything, devices appear. I don't know what I need t...
by rkrisi
Fri Jul 03, 2020 4:01 pm
Forum: General
Topic: PIM between VLANs [SOLVED]
Replies: 4
Views: 3023

Re: PIM between VLANs [SOLVED]

Well this seems to work, but I'm not sure if it is right or not: 0 Rv2 vlan_iot pim igmp 1 Rv2 vlan_guest pim igmp 2 Rv2 vlan_private pim igmp 3 DR register pim RP: 0 10.0.1.2 static 192
by rkrisi
Mon Jun 29, 2020 4:24 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

I see lots of reference to theoretical speeds, 867, 1300, etc............. Remember its marketing hype as those are two way added speeds. The most ludicrous is the term ooh aahh 1750 which is adding both 2.4 and 5ghz two way streams 450+1300. Or 867+300 = ~1200 on the packaging. Consider 1300 for e...
by rkrisi
Mon Jun 29, 2020 4:22 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

This is a post about Wifi problem, is your question still Wifi related? If so you CAN NOT test Wifi connection with Ookla Speedtest. Well you can, but your results do not say anything about the Wifi, but about the complete system. So the only way to do this is test Wifi connection between the AP an...
by rkrisi
Mon Jun 29, 2020 1:41 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Well, another observation through longer time... It seems that only speedtest is slow(er), using P2P connection (like torrent client) is much faster, even on my personal computer 15m away from the router. Speedtest (does not matter which - ookla, fast.com, etc... or even local iperf) usually gives 1...
by rkrisi
Thu Jun 25, 2020 1:25 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Exactly. AP RX rates I get >1000Mbps with MacPro 3x3 but on AP TX I rarely go over the 800Mbps rates... So client UL is a but better than DL. On the 2x2 client I get 800mbps rates on both Rx and Tx. PS: I keep AMPDU priority as default (only "1" checked). I see bad performance when enabli...
by rkrisi
Thu Jun 25, 2020 12:58 am
Forum: General
Topic: CAPsMAN with Wireless Repeater [SOLVED]
Replies: 11
Views: 5429

Re: CAPsMAN with Wireless Repeater [SOLVED]

I have found this presentation which seems to do the same (even RB751 is the same :D ) https://mum.mikrotik.com/presentations/MN17/presentation_4441_1497864498.pdf But I might want to get some infos from you, if this is really possible and it would work similar as now (but I would be able to manage ...
by rkrisi
Thu Jun 25, 2020 12:49 am
Forum: General
Topic: CAPsMAN with Wireless Repeater [SOLVED]
Replies: 11
Views: 5429

CAPsMAN with Wireless Repeater [SOLVED]

Dear Community, Right now I have a second router (RB751) configured as a Wireless repeater. Basically the range for handheld devices are great this 2.4GHz based repeater is only needed for IoT devices cause they have a really low range. I wonder if I can set this up (the second AP only has one wirel...
by rkrisi
Thu Jun 25, 2020 12:44 am
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

I implicitly assumed this, but to be sure, I use 80 MHz capable clients.
You can check in the Wireless "registration" tab that they do receive and sent with 80 Mhz
and 2 spatial stream.
Same clients here (I get around 800Mbps Rx rate 80Mhz/2SP/SGI)
by rkrisi
Wed Jun 24, 2020 2:31 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Setup: - Near range (2meter) between client and AP - iperf3 on Android / MacOS - iperf3 on Rasp4 with Ethernet connected to RB4011 - RB4011 4x4 ROS 6.46.6, reset to default, 20/40/80MHz channel and Wifi security added (to avoid also anyone connecting to the unit) - Add also the country in Wifi inte...
by rkrisi
Tue Jun 23, 2020 5:06 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

I also did some tests on the RB4011 5 GHz performance this weekend (using ROS 6.47). It looks like it does not like to transmit data. Using iperf3 over the wifi-connection, the RB4011 was able to receive about 300 MBit/s from a 2x2 client (Intel AC7260), but it only managed to send 80 Mbit/s back t...
by rkrisi
Tue Jun 16, 2020 1:38 pm
Forum: General
Topic: Setup WDS with 2 AP
Replies: 7
Views: 7906

Re: Setup WDS with 2 AP

But basically this will work as a client from the perspective that it will connect to the router ask for it's DHCP address, etc...? you can setup static IP for second AP if this needed, if you talking about WiFi clients - it will work without any extra setup (DNS (but you can set it for receiving f...
by rkrisi
Tue Jun 16, 2020 1:12 am
Forum: General
Topic: Setup WDS with 2 AP
Replies: 7
Views: 7906

Re: Setup WDS with 2 AP

I don't have experience in WDS myself, but just stumbled over this wiki page https://wiki.mikrotik.com/wiki/WDS_repeater_example There are also some YT videos: https://www.youtube.com/watch?v=s6PEDtf5qDQ Thanks I have found these (forgot to mention), but if you have a look at my previous reply, you...
by rkrisi
Tue Jun 16, 2020 1:11 am
Forum: General
Topic: Setup WDS with 2 AP
Replies: 7
Views: 7906

Re: Setup WDS with 2 AP

simple case for repeater: main AP - create WDS: wds mode - dynamic, wlan1 mode - AP bridge secondary AP (repeater) - wlan1 mode - wds slave with same SSID, security profile settings, channel (auto also work) Yes this is what I thought, but I had no time to try it out (it is rather risky and I don't...
by rkrisi
Mon Jun 15, 2020 12:16 pm
Forum: General
Topic: Setup WDS with 2 AP
Replies: 7
Views: 7906

Re: Setup WDS with 2 AP

Also I really don't know which WDS type should be used here. I assume dynamic, but it will also allow for clients to connect to that AP? Or dynamic mesh what needs to be used here?
I could not find any documentation on this...
by rkrisi
Sun Jun 14, 2020 8:09 pm
Forum: General
Topic: Setting up Avahi Reflector in Mikrotik [SOLVED]
Replies: 29
Views: 23604

Re: Setting up Avahi Reflector in Mikrotik [SOLVED]

Kudos to you for sticking with the thread and posting updates! I am installing all Unifi equipment, but dont want to leave RouterOS behind. My project is to break up my network into LAN, IoT & NoT. Right now I am dumping all VLANs to the LAN network. I have implemented policies restricting traf...
by rkrisi
Sun Jun 14, 2020 8:02 pm
Forum: General
Topic: Setup WDS with 2 AP
Replies: 7
Views: 7906

Setup WDS with 2 AP

Dear community! I have a secondary Mikrotik Router which works now just as a Wireless client and some wired-only clients connected to this AP (unfortunately I don't have wired access there and some devices only supports wired Ethernet connection - that's why this is needed). I want to enable WDS on ...
by rkrisi
Sun Jun 14, 2020 7:53 pm
Forum: General
Topic: Setting up Avahi Reflector in Mikrotik [SOLVED]
Replies: 29
Views: 23604

Re: Setting up Avahi Reflector in Mikrotik [SOLVED]

I'm unfortunately stuck with this. mDNS reflection seems to be working fine, printers, AirPlay devices shows up correctly on every VLAN immediately and works as it should. Though Chromecast devices and Spotify Connect devices don't seem to be working flawlessly. So these devices may need additional...
by rkrisi
Fri Jun 12, 2020 2:37 pm
Forum: General
Topic: Setting up Avahi Reflector in Mikrotik [SOLVED]
Replies: 29
Views: 23604

Re: Setting up Avahi Reflector in Mikrotik [SOLVED]

I'm unfortunately stuck with this. mDNS reflection seems to be working fine, printers, AirPlay devices shows up correctly on every VLAN immediately and works as it should. Though Chromecast devices and Spotify Connect devices don't seem to be working flawlessly. So these devices may need additional ...
by rkrisi
Thu Jun 11, 2020 4:44 pm
Forum: General
Topic: PIM between VLANs [SOLVED]
Replies: 4
Views: 3023

PIM between VLANs [SOLVED]

Dear Community! I would need to setup PIM to work on my network (lots of devices use IGMP multicast packets to discover each other and other similar multicast methods...). I have one router (RB4011) configured with more VLANs, each VLAN has it's own subnet. I have tried setting up PIM and adding an ...
by rkrisi
Sat May 23, 2020 12:23 am
Forum: General
Topic: OpenVPN with VLANs
Replies: 25
Views: 9970

Re: OpenVPN with VLANs

Finally I was able to get this working.
Basically I needed to add a firewall rule that explicitly says to forward packets originated from the BASE interface (this is where I added the ovpn bindings).
Now everything works as it should.

Thanks for your help!
by rkrisi
Fri May 22, 2020 2:38 am
Forum: General
Topic: OpenVPN with VLANs
Replies: 25
Views: 9970

Re: OpenVPN with VLANs

You can only have one server binding per username - if the same username is used more than once you end up with the server binding plus additional dynamic interfaces <ovpn-someuser-1>, <ovpn-someuser-2>, etc. If a connection is interrupted you can end up with the user connected via a dynamic interf...
by rkrisi
Fri May 22, 2020 12:03 am
Forum: General
Topic: OpenVPN with VLANs
Replies: 25
Views: 9970

Re: OpenVPN with VLANs

That rule is for the outer tunnel, not the inner tunnelled traffic. As discussed in post #4 with having firewall rules referring to the lists 'BASE', 'VLAN', 'BASE+VLAN' the open VPN server interface has to be added to these if you wish the VPN traffic to use the rules. Having interface-list=VLAN i...
by rkrisi
Thu May 21, 2020 9:14 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 25
Views: 9970

Re: OpenVPN with VLANs

Local is server, remote is client. For point-to-point interfaces you can have the same local address on multiple interfaces. VLANs are not the issue, they only have significance for layer 2 ethernet. IP routes are automatically added to the routing table ( /ip route print or Winbox, IP > Routes), o...
by rkrisi
Thu May 21, 2020 8:18 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 25
Views: 9970

Re: OpenVPN with VLANs

I have set everything, different pool for ovpn, removed DNS server as well. Connected, got an IP from the specified pool. However now even when I try to ping a local device from remote device, it does not respond. The other way, from local to remote works... I might think that vlan filtering has to ...
by rkrisi
Thu May 21, 2020 8:10 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 25
Views: 9970

Re: OpenVPN with VLANs

There is nowhere to enter an interface in /ip pool - just a pool name, addresses and an optional next pool. So, based on your config, something along the lines of: /ip pool add name=pool_ovpn ranges=10.0.98.10-10.0.98.254 ... /ppp profile add dns-server=10.0.0.3 interface-list=VLAN local-address=10...
by rkrisi
Thu May 21, 2020 6:27 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 25
Views: 9970

Re: OpenVPN with VLANs

I don't know what is causing the problem. Tried different setups. It is odd that you got to a point where you had some connectivity and then lost it. I might not understand your question, but if this is the question: The remote client has an IP address from a completely different subnet (172.XX...)...
by rkrisi
Tue May 19, 2020 2:00 am
Forum: General
Topic: OpenVPN with VLANs
Replies: 25
Views: 9970

Re: OpenVPN with VLANs

Nothing immediately jumps out. Is the Open VPN client connecting from an address within the IP range you are trying to tunnel? I've never tried it myself to see if handles this situation. Also, IIRC there have been comments about /internet detect-internet causing odd behaviour so it may be worth re...
by rkrisi
Sun May 17, 2020 5:41 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 25
Views: 9970

Re: OpenVPN with VLANs

Per my previous email either add routing statements to the OpenVPN client configuration file route 10.0.0.0 255.255.0.0 vpn_gateway OR change the Mikrotik VPN server /interface ovpn-server server set auth=sha1 certificate=server cipher=aes256 default-profile=ppp_private enabled=yes netmask=16 requi...
by rkrisi
Sun May 17, 2020 12:45 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 25
Views: 9970

Re: OpenVPN with VLANs

Is the OpenVPN client another Mikrotik or a Windows/Linux machine? You may have missed the point of what @tdw wrote - it is not enough to add the routes towards your Mikrotik LAN subnets to the routing table of the client machine's kernel, you also have to add them to the openvpn configuration file...
by rkrisi
Sun May 17, 2020 3:10 am
Forum: General
Topic: OpenVPN with VLANs
Replies: 25
Views: 9970

Re: OpenVPN with VLANs

Ok thanks for clearing this up for me. Now I can access the 10.0.99.0/24 subnet from which the address is given to the interface, but not other subnets, though I have created an address list with 10.0.0.0/16 and added it under the /ppp profile address-list option. Should I need to do anything else ...
by rkrisi
Sun May 17, 2020 1:00 am
Forum: General
Topic: OpenVPN with VLANs
Replies: 25
Views: 9970

Re: OpenVPN with VLANs

The Mikrotik OpenVPN implementation is shoehorned into their PPP model, and it does not quite fit, so some of the PPP profile settings have no meaning when used with the OpenVPN server - in particular setting bridge= under /ppp profile has no effect, this is used by PPP Bridge Control Protocol (BCP...
by rkrisi
Sat May 16, 2020 9:27 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 25
Views: 9970

Re: OpenVPN with VLANs

Not being able to access the router itself is likely to be firewall rules. Having the same VLAN ID on different bridges will not pass that traffic between bridges, are you looking to bridge or route traffic? Printing the bridge and PPP profile entries provides no useful information, post the output...
by rkrisi
Sat May 16, 2020 6:18 pm
Forum: General
Topic: OpenVPN with VLANs
Replies: 25
Views: 9970

OpenVPN with VLANs

Dear Community! I have a network seperated with VLANs. I wanted to enable openVPN server on this system, however I'm not able to get it working. Currently I can connect to the server both from inside and outside of the network and I get an IP from the specified pool, but I'm not able to access the l...
by rkrisi
Sat May 16, 2020 3:16 am
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

These 3 devices are used for testing. Totally random screenshot, so I have not adjusted anything. Ok , rkrisi (Kristof) , thanks for sharing. There is normally a constant or even real time monitoring needed, but lets start with a little comment on this registration table. Elements to consider: - th...
by rkrisi
Wed May 13, 2020 9:26 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Can get up to 450mbps using btest in my hap ac2, this is my config if it helps /interface wireless security-profiles set [ find default=yes ] supplicant-identity=MikroTik add authentication-types=wpa2-psk disable-pmkid=yes eap-methods="" \ group-key-update=1h mode=dynamic-keys name=main s...
by rkrisi
Wed May 13, 2020 9:24 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

These 3 devices are used for testing. Totally random screenshot, so I have not adjusted anything. Ok , rkrisi (Kristof) , thanks for sharing. There is normally a constant or even real time monitoring needed, but lets start with a little comment on this registration table. Elements to consider: - th...
by rkrisi
Wed May 13, 2020 4:36 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

I come late to this thread and might not have read all of this. So my comment might be useless (or not). Noticed in the config given that you use not all Wifi 802.11 modes in 5G (only n and ac, but not a) I gave this advice as well on 2.4G in other threads, this something not to be done if you want...
by rkrisi
Wed May 13, 2020 4:35 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

These 3 devices are used for testing. Totally random screenshot, so I have not adjusted anything. Ok , rkrisi (Kristof) , thanks for sharing. There is normally a constant or even real time monitoring needed, but lets start with a little comment on this registration table. Elements to consider: - th...
by rkrisi
Wed May 13, 2020 12:19 am
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

These 3 devices are used for testing. Totally random screenshot, so I have not adjusted anything.
by rkrisi
Tue May 12, 2020 8:38 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Right now: Channel selection: 5500 MHz TX-power (via antenna gain): Current TX Power: Default - Antenna Gain 3dBi Bandwidth (40 or 80?): 20/40/80XXX So far so good. Channel is OK TX power and 80 MHz will do in this clean environment .Ceee would be more specific than XXXX. Interference is probably o...
by rkrisi
Tue May 12, 2020 6:23 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

You wrote in another thread, that you don't have neighbors nearby and that the spectrum is free from other networks at your place. So, of course if does! Yes, true, but the real (noticeable) difference for me is disabling route cache and fasttrack, then I can get sometimes almost 50% of the lan spe...
by rkrisi
Tue May 12, 2020 4:30 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

So as I said before, I did not bought this router because I only wanted to achieve 1Gbps Wi-Fi speed... But You started this thread because of the bad Wifi. :) Anyway, for all that You need (except WiFi), Mikrotik is perfect. I had RB750GL + Engenius accesspoints working fine in many years. So now ...
by rkrisi
Tue May 12, 2020 3:28 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

I don't think sitting 10cm from the router helps in any way. If it is configured incorrectly it will work incorrectly there also. If you have interference, you can have interference there also.. I don't think it's miss configured. You are getting less then half of the max speed. With fine tuning Yo...
by rkrisi
Tue May 12, 2020 2:49 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Around 10m away from the router, same room Have You made tests next to the router? As if You can't get decent speed next to the router, then the router is just bad and no matter You adjust, speed won't get better. But if next to the router speed is good, then adjusting router place, antennas etc, m...
by rkrisi
Tue May 12, 2020 2:48 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

How does one relate to another? :) You can use 20MHz channel and still use MIMO. All those spatial streams operate in the same channel(s). I did not state that you could not use 20MHz channel with MIMO .... I did state that if you want PERFORMANCE you must use 40Mhz ... performance means speed........
by rkrisi
Tue May 12, 2020 2:46 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

No I'm using iperf and speedtest tools also (like speedtest.net and fast.com) But I don't get you. What is different in real life? I have a lot of local devices which I can and have to access so these has nothing to do with WAN speed (copying files locally for example). Also if you have a slow WAN,...
by rkrisi
Tue May 12, 2020 2:09 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

WAN speed is not all. I also test it with iperf for example which tests real speed, not just some speedtest server speed. You are testing local network with iperf? If so, then if You are using mainly local network > wan, testing local network doesn't help You much, as real life is different. No I'm...
by rkrisi
Tue May 12, 2020 2:08 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

[
The router is laid down in my Living Room, from around 1.6m above ground (so it is not too high not too low - in my opinion - same location as my previous router).
And You are testing where?
Around 10m away from the router, same room
by rkrisi
Tue May 12, 2020 1:35 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Why do I have to proof myself. The content of my contributions should be just of value enough. And yes all my Mikrotiks are up to spec right now . I even get borred in checking. (Not a single glitch in the last 6 months, monitored continously with DUDE) Bottleneck is now elsewhere (100 Mbps etherne...
by rkrisi
Tue May 12, 2020 1:13 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Superchannel will not defeat DFS rules (anymore). The 10 minutes are indeed disturbing, but sometimes the lucky choices while everyone avoids those channels. You can see what those "auto" settings are doing. They are so selfisch to just spoil the whole spectrum by sitting in the middle of...
by rkrisi
Tue May 12, 2020 12:39 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Right now: Channel selection: 5500 MHz TX-power (via antenna gain): Current TX Power: Default - Antenna Gain 3dBi Bandwidth (40 or 80?): 20/40/80XXX Number of chains used (all 4 or 3 or 2?): All 4 chains are used on TX and RX as well. Max MCS rate (per chain): I could not find this setting anywhere....
by rkrisi
Tue May 12, 2020 12:33 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Thanks! I have already enabled the most needed ones. However if I remember it right, I was able to add not just inline comments, but normal ones. Anyway I have did some testing and it always seems to me that 5500 MHz selected as frequency is the best I could get. Just to get an overview of the netw...
by rkrisi
Tue May 12, 2020 11:34 am
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

If I have to say, I would say yes that the speed is just around 10% better with my old router, and compared to a few years back, it is much slower. But as I said, in general when you browse the internet or do anything even locally on the network it feels so much faster - and this is not just placeb...
by rkrisi
Tue May 12, 2020 10:50 am
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

My previous cheap router seemed really fast when I bought it several years back (even better than now). So after all this testing, Mikrotik speed is about 10% better, then old stock router does provide? Is the speed constantly better, or it just jumped one time (like said before, with Mikrotik, in ...
by rkrisi
Tue May 12, 2020 2:10 am
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Ok, the results seems great! 2.4GHz speed improved by choosing 20MHz only, now I was able to get 50Mbps max and around 35Mbps avg. Previously it was around 20-25Mbps max. Regarding 5GHz: you were right. I had to clear Secondary channel to turn it off. However the speed does not improved much. Seems...
by rkrisi
Tue May 12, 2020 1:30 am
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Ok, the results seems great! 2.4GHz speed improved by choosing 20MHz only, now I was able to get 50Mbps max and around 35Mbps avg. Previously it was around 20-25Mbps max. Regarding 5GHz: you were right. I had to clear Secondary channel to turn it off. However the speed does not improved much. Seems ...
by rkrisi
Tue May 12, 2020 12:23 am
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Tuning is tuning, and that is sometimes more an art than a science. But I love to do it. Getting 10 times better performance gives me the kick, and I achieved this many times in my live, on all sorts of systems. (Sometimes by doing unconventional things, after learning how things work inside. There...
by rkrisi
Tue May 12, 2020 12:11 am
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Thanks! So today I will try to disable secondary channel. If I remember correctly I have tried it but it came up with an error. The doc said I should put a 0 there to disable it. I will try that again. Unfortunately I don't want to disable a/n first. It would be my last option, because lot of older...
by rkrisi
Tue May 12, 2020 12:08 am
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

First, I get your frustration. I also don't like if I have to pay a lot of money for something which doesn't seem to work first as it should. I have accept the fact, that I made mistake, however, I'm honestly curious - can someone fine tune the device and if so, then with what config, as this will ...
by rkrisi
Mon May 11, 2020 9:31 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

As also others are having similar problems, for example: https://forum.mikrotik.com/viewtopic.php?f=13&t=138895 https://forum.mikrotik.com/viewtopic.php?f=2&t=158709 https://forum.mikrotik.com/viewtopic.php?f=7&t=157869 https://forum.mikrotik.com/viewtopic.php?f=2&t=157688 then If Y...
by rkrisi
Mon May 11, 2020 9:24 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Yes I have changed it from indoors to any! When looking at the current channel I can see: 5500/20-Ceee/ac/DP(24dBm)+5210/80/P(20dBm) So yes, you might be right about the Control channel, and I always get Ceee. So I should increase the antenna gain from 3dBi to 27dBi? Ps.: I already tried using freq...
by rkrisi
Mon May 11, 2020 2:15 pm
Forum: General
Topic: Setting up Avahi Reflector in Mikrotik [SOLVED]
Replies: 29
Views: 23604

Re: Setting up Avahi Reflector in Mikrotik [SOLVED]

Only other vendor (like Denon) devices don't show up in Spotify Connect. Google Chromecasts work fine. I need to fine tune this for Denon devices to work: https://denon-uk.custhelp.com/app/answers/detail/a_id/4717/~/network-requirements-for-heos I just need to enable igmp across vlan and these ports...
by rkrisi
Mon May 11, 2020 10:52 am
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Thank you very much! I know that some of this data is only makes sense if it is in real time, but I would happily share my config for experts to have a look at. Is the config I attached to my first post doesn't include all the config? /interface wireless shows: Flags: X - disabled, R - running 0 R ...
by rkrisi
Mon May 11, 2020 1:22 am
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Thanks for your detailed answer! Looking at the registration table, which client should I look at? Or should I conclude an average performance of the current setting? For example my phone which is quite far away from the router has: -60dbm Signal Strength and RX rate 585Mbps Tx rate 351Mbps, but st...
by rkrisi
Mon May 11, 2020 1:06 am
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Looking at the registration table, which client should I look at? At the one you use for testing. For example my phone which is quite far away from the router has: -60dbm Signal Strength and RX rate 585Mbps Tx rate 351Mbps, but still speedtest shows around 150Mbps speed. - Analyze the whole TX/RX-r...
by rkrisi
Mon May 11, 2020 12:48 am
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

I got an Audience which based on the same wireless chipset with RB4011, in 2x2 the max speed I got is about 470mbps, pretty good I must say, same speed with those IPQ4018/4019 based products like hAP ac2/cAP ac, and ping respond is best among all the APs I got (Aruba IAP-225/315, Ruckus R510, Ubiqu...
by rkrisi
Mon May 11, 2020 12:47 am
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

What's your client device? It is possible that the speed is limited by the capabilities of your client, not the AP. Can you show what's in the registration table ( /interface wireless registration-table print stats ) during the test? I don't think so. I have tried different devices. Basically my co...
by rkrisi
Mon May 11, 2020 12:44 am
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

@rkrisi Be a little patient and MikroTik will improve the wireless performance in your RB4011 .... it may take another 6 months ... patience is key My suggestion for you is to buy the Ubiquiti nanoHD access Point Connect that to your RB4011 and you will have superb performance beyond your wildest e...
by rkrisi
Mon May 11, 2020 12:43 am
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Maybe someone from MT can have some ideas what might be wrong. Don't be a masochist, thre is no fix. Been there, done that, read my (or use google and find thousands more) story - https://forum.mikrotik.com/viewtopic.php?f=7&t=160252 I have read this thread before... I'm not really happy with t...
by rkrisi
Sun May 10, 2020 9:55 pm
Forum: General
Topic: Setting up Avahi Reflector in Mikrotik [SOLVED]
Replies: 29
Views: 23604

Re: Setting up Avahi Reflector in Mikrotik [SOLVED]

Ok I think I have found the solution to this. As I have not found a simple guide to this, I provide it here, what worked for me: Basically followed this guide: http://chrisreinking.com/need-bonjour-across-vlans-set-up-an-avahi-gateway/ As for VLAN setup: set the port to tagged for every vlan, just a...
by rkrisi
Sun May 10, 2020 7:12 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Maybe someone from MT can have some ideas what might be wrong. Don't be a masochist, thre is no fix. Been there, done that, read my (or use google and find thousands more) story - https://forum.mikrotik.com/viewtopic.php?f=7&t=160252 I have read this thread before... I'm not really happy with t...
by rkrisi
Sun May 10, 2020 6:36 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Okay thanks! This router was pretty expensive and I hoped that I could get a decent speed with Wi-Fi. I saw here that lots of people have problems with it, but I never thought this is that common. In general I love MT products and its configurability (though I never had any Wi-Fi device before). Wha...
by rkrisi
Sun May 10, 2020 1:46 pm
Forum: General
Topic: Setting up Avahi Reflector in Mikrotik [SOLVED]
Replies: 29
Views: 23604

Re: Setting up Avahi Reflector in Mikrotik [SOLVED]

What I have tried: adding the interface of the RPI to the guest vlan as tagged and setting up a sub interface in RPI for the guest vlan. However the RPI did not get a valid address for that vlan, even after enabling DHCP for that sub interface
by rkrisi
Sat May 09, 2020 3:10 pm
Forum: General
Topic: Setting up Avahi Reflector in Mikrotik [SOLVED]
Replies: 29
Views: 23604

Setting up Avahi Reflector in Mikrotik [SOLVED]

Dear Community! For IoT devices I need to be able to route mDNS broadcast traffic through VLANs. I saw that this is only currently possible with an external server (or maybe a MetaRouter with OpenWRT, but unfortunately my router - RB4011 - doesn't support MetaRouter yet). Not a big problem, I alread...
by rkrisi
Sat May 09, 2020 2:50 am
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 131
Views: 31980

Wi-Fi performance bad on RB4011 - possible misconfig

Dear Community! I have bought a RB4011iGS+5HacQ2HnD-IN router. I was able to set up everything - got a little help in the forum here - everything working perfectly, except WLAN. I can get maxed out rates (the max I get from my ISP) on ether interfaces, but not on Wi-Fi. I hope that I could get at le...
by rkrisi
Fri May 08, 2020 10:05 pm
Forum: General
Topic: Simple VLAN setup - Please help!
Replies: 12
Views: 2966

Re: Simple VLAN setup - Please help!

No I highlighted them because they were missing in your original config. They are now good if you included them. Concur, only have to work on wifi speed and that is probably accomplished with some wifi tweaking. Thank you very much! The config now seems great for me, now I just have to fiddle with ...
by rkrisi
Fri May 08, 2020 8:27 pm
Forum: General
Topic: Simple VLAN setup - Please help!
Replies: 12
Views: 2966

Re: Simple VLAN setup - Please help!

Anyway, what is the problem with these? add bridge=vlan_bridge tagged=vlan_bridge untagged=wlan_atlas,wlan_fujijama,ether2,ether3,ether4,ether5,ether6,ether7,ether8 \ vlan-ids=10 add bridge=vlan_bridge tagged=vlan_bridge untagged=wlan_atlas_guest,wlan_fujijama_guest,ether9 vlan-ids=20 I mean you hig...
by rkrisi
Fri May 08, 2020 8:14 pm
Forum: General
Topic: Simple VLAN setup - Please help!
Replies: 12
Views: 2966

Re: Simple VLAN setup - Please help!

The FW rules are fine as they are. I just question why you give the VLAN full access to the router. I would not, I would eliminate that input chain rule. YOu need access as the admin and you have provided that with your BASE VLAN rule. I prefer to create an access list which includes the likely IPs...
by rkrisi
Fri May 08, 2020 8:02 pm
Forum: General
Topic: Simple VLAN setup - Please help!
Replies: 12
Views: 2966

Re: Simple VLAN setup - Please help!

In summary, So far I see most ports are access ports to devices that are not vlan aware on the private LAN, and ether 9 being a wired guest port??, eth10 a base port). You have an SFP port which is most likely a trunk port which may carry all three vlans? You have 4 wlans, two private (Atlas and fu...
by rkrisi
Fri May 08, 2020 7:15 pm
Forum: General
Topic: Simple VLAN setup - Please help!
Replies: 12
Views: 2966

Re: Simple VLAN setup - Please help!

As for wireless speed, there are a lot of possible issues (other wi-fi networks in the neighborhood are the first one to look at, the channel numbering is confusing, as in 2.4 GHz band the numbers are assigned to 5 MHz wide channels whilst 20 MHz wide ones are actually used as a minimum, newer devi...
by rkrisi
Fri May 08, 2020 6:14 pm
Forum: General
Topic: Simple VLAN setup - Please help!
Replies: 12
Views: 2966

Re: Simple VLAN setup - Please help!

Since you don't need VLAN tagging on ethernet ports, using a VLAN configuration is just one of possible approaches - the VLAN tag manipulation on wireless frames is done by the CPU in software anyway. So if you prefer to use the VLAN approach for the guest subnet, set vlan-mode of the virtual wirel...
by rkrisi
Fri May 08, 2020 12:00 pm
Forum: General
Topic: Simple VLAN setup - Please help!
Replies: 12
Views: 2966

Simple VLAN setup - Please help!

Hi everyone! I have bought a new RB4011iGS+5Hac router. I want to create multiple VLANs to seperate Guest network from my Private network. Ethernet ports on the router (except eth1 which is used as DHCP client to connect to my modem) should be an access port to my private VLAN (vlan_private). I have...