Community discussions

MikroTik App

Search found 21 matches

by fpawlak
Mon Nov 07, 2022 10:29 am
Forum: General
Topic: SXTsq 5 ac - missing wlan interface
Replies: 1
Views: 506

Re: SXTsq 5 ac - missing wlan interface

Hi,
so nobody has any idea? I've hoped that it can be solved without returning to the reseller.
So I will send it back, hoping they will excache those antennas.
by fpawlak
Fri Oct 21, 2022 12:54 pm
Forum: General
Topic: SXTsq 5 ac - missing wlan interface
Replies: 1
Views: 506

SXTsq 5 ac - missing wlan interface

Hi, I have a problem with two STXsq 5 ac - there are no WLAN interfaces. Devices are new, and the problem is from the beginning. I've already tried updating to the newest ROS(7.6), stable(6.49.7), netinstal, and configuration reset but nothing has helped. When booting, log shows the following: DefCo...
by fpawlak
Mon Mar 07, 2022 1:49 pm
Forum: General
Topic: Is still ipsec fasttrack bypass rule needed in ROS7
Replies: 3
Views: 2308

Is still ipsec fasttrack bypass rule needed in ROS7

Hi guys, simple question about ipsec and fasttrack. With ROS7+ do I still need to add 'bypass rule'? eg. /ip firewall mangle add action=mark-connection chain=forward comment="Mark IPsec" ipsec-policy=out,ipsec new-connection-mark=ipsec /ip firewall mangle add action=mark-connection chain=f...
by fpawlak
Mon Apr 12, 2021 8:55 pm
Forum: General
Topic: IKEv2 server ignores dhcp query on vlan interface
Replies: 14
Views: 2471

Re: IKEv2 server ignores dhcp query on vlan interface

I'd suggest you to create a supout.rif and open a support ticket at Mikrotik. You can refer to this topic in the ticket in addition to a brief description, but supout.rif is the first thing they ask for if you don't attach it straight away, no exceptions. I will do that :) Totally unrelated to the ...
by fpawlak
Mon Apr 12, 2021 12:45 pm
Forum: General
Topic: IKEv2 server ignores dhcp query on vlan interface
Replies: 14
Views: 2471

Re: IKEv2 server ignores dhcp query on vlan interface

No matter what the reasons are, the essence is that the IKEv2 VPN client needs to connect also from the server's LAN. YES According to your configuration excerpt, the responder peer listens at all addresses. Not exactly - I always have address=0.0.0.0/0 and local-address I've tried different config...
by fpawlak
Thu Apr 08, 2021 7:56 pm
Forum: General
Topic: IKEv2 for macOS clients with multiple networks behind the tunnel
Replies: 11
Views: 3962

Re: IKEv2 for macOS clients with multiple networks behind the tunnel

I'm simply stating the fact that IKEv2 seems to be broken in RouterOS when used with split-include, and that it only works with Windows clients by using a non-standard behavior of that specific client. I haven't tested Windows 10 client against other IKEv2 servers. But I think that Windows is not w...
by fpawlak
Thu Apr 08, 2021 12:52 pm
Forum: General
Topic: IKEv2 server ignores dhcp query on vlan interface
Replies: 14
Views: 2471

Re: IKEv2 server ignores dhcp query on vlan interface

Ok. So maybe I have to write it more simple what I have and what I want: Bridge.png Bridgeports.png /interface bridge add frame-types=admit-only-vlan-tagged ingress-filtering=yes name=br-LAN vlan-filtering=yes add name=br-WAN /interface bridge port add bridge=br-LAN frame-types=admit-only-vlan-tagge...
by fpawlak
Thu Apr 08, 2021 9:15 am
Forum: General
Topic: IKEv2 for macOS clients with multiple networks behind the tunnel
Replies: 11
Views: 3962

Re: IKEv2 for macOS clients with multiple networks behind the tunnel

I'm not sure if I understand your problem. Do you wonder why those two polices are different? In my opinion it is because of windows. As you can see in a fragment from wiki which I've quoted already Windows will always ignore networks received by split-include and request policy with destination 0.0...
by fpawlak
Wed Apr 07, 2021 4:34 pm
Forum: General
Topic: IKEv2 server ignores dhcp query on vlan interface
Replies: 14
Views: 2471

Re: IKEv2 server ignores dhcp query on vlan interface

Depending on the throughput required, you may try to add an auxiliary bridge interface, move the IP configuration from the VLAN interface to it, and make the VLAN interface a member port of this auxiliary bridge, while its tagged end will remain attached to the main bridge. Hi Sindy. I've read it c...
by fpawlak
Wed Apr 07, 2021 11:21 am
Forum: General
Topic: IKEv2 for macOS clients with multiple networks behind the tunnel
Replies: 11
Views: 3962

Re: IKEv2 for macOS clients with multiple networks behind the tunnel

Hi, I also was playing a little bit with IKEv2. As I know macOS has some limitations. In MikroTik wiki: https://wiki.mikrotik.com/wiki/Manual:IP/IPsec Known limitations Here is a list of known limitations by popular client software IKEv2 implementations. Windows will always ignore networks received ...
by fpawlak
Wed Apr 07, 2021 10:38 am
Forum: Wireless Networking
Topic: WiFi in packing hall - how to build it
Replies: 7
Views: 2287

Re: WiFi in packing hall - how to build it

Guys thank you very much for your advice. If I may, I'll have more detailed questions. I can start with some 5GHz routerBOARDs which I have. But I'm not sure with which antennas should I try. So firstly should I start with standard omni antennas with some DIY shield to make the wifi wave very narrow...
by fpawlak
Tue Apr 06, 2021 9:13 am
Forum: Wireless Networking
Topic: WiFi in packing hall - how to build it
Replies: 7
Views: 2287

Re: WiFi in packing hall - how to build it

Hi,
I really need help. If you need more details please feel free to ask me. I thought I've written all, but maybe I've missed some. So please ask.
by fpawlak
Thu Apr 01, 2021 5:11 pm
Forum: General
Topic: IKEv2 server ignores dhcp query on vlan interface
Replies: 14
Views: 2471

Re: IKEv2 server ignores dhcp query on vlan interface

I've done the test with direct ingres port, still without success :(
Also, DHCP inform packet without src-mac address.
by fpawlak
Thu Apr 01, 2021 3:54 pm
Forum: General
Topic: IKEv2 server ignores dhcp query on vlan interface
Replies: 14
Views: 2471

Re: IKEv2 server ignores dhcp query on vlan interface

So I've added a third bridge - now I have 'Bridge LAN' 'Bridge WAN' and 'Bridge IKEv2' I've set up IKEv2 peer on IP assigned to 'Bridge IKEv2', and added dst-nat rules for UDP 500, 4500 and ipsec-esp to forward them to the IP of 'Bridge IKEv2'. I still can connect from WAN and LAN. But only on WAN p...
by fpawlak
Thu Apr 01, 2021 2:18 pm
Forum: General
Topic: IKEv2 server ignores dhcp query on vlan interface
Replies: 14
Views: 2471

Re: IKEv2 server ignores dhcp query on vlan interface

Sindy, thanks for your reply. Yes, I can grab DHCP inform - in both scenarios they are sent as broadcast to address 255.255.255.255:67. See below First one from VLAN - as you can see, after established SAs repeated DHCP packet without response 1.gif Second scenario - not from VLAN - after establishe...
by fpawlak
Tue Mar 30, 2021 11:50 am
Forum: Wireless Networking
Topic: WiFi in packing hall - how to build it
Replies: 7
Views: 2287

WiFi in packing hall - how to build it

Guys, I need your advice. I'm looking for some solution for WiFi infrastructure in our packing hall. Bellow, I enclose images of how it looks. Packing hall dimensions are 25m x 100m WhatsApp Image 2021-03-26 at 07.30.35 (1).jpeg WhatsApp Image 2021-03-26 at 07.30.35 (2).jpeg WhatsApp Image 2021-03-2...
by fpawlak
Mon Mar 29, 2021 11:03 pm
Forum: General
Topic: IKEv2 server ignores dhcp query on vlan interface
Replies: 14
Views: 2471

IKEv2 server ignores dhcp query on vlan interface

Hi guys. I have a problem with IKEv2 IPsec configuration. Normally when I have configured IKEv2/IPsec server peer on IP address assign to bridge interface. Windows 10 connects to this IP, ask for policy 0.0.0.0/0, then ask via dhcp option 249 for 'split-include' defined in mode config. -> Everything...
by fpawlak
Tue Feb 16, 2021 6:59 pm
Forum: General
Topic: IKEv2 -> VLANs filtering
Replies: 3
Views: 828

Re: IKEv2 -> VLANs filtering

Sindy thanks a lot for your quick response. It looks good :) So for main VLAN I can use identity with Auth. Method 'eap radius' so all domain users get access to the main VLAN. And for the rest VLANs I'll have to define separate identities for each user with Auth. Method different than 'eap radius' ...
by fpawlak
Tue Feb 16, 2021 5:14 pm
Forum: General
Topic: IKEv2 -> VLANs filtering
Replies: 3
Views: 828

IKEv2 -> VLANs filtering

Hi guys I've played a little with IKEv2. I'm able to connect to mikrotik router with IKEv2 (using 'digital signature' or 'eap radius'). Now I'm looking for some guides how can I filter access to specific VLANs from IKEv2 clients. I know that, I can add firewall rules like: #ALLOW VPN to VLAN10 add a...
by fpawlak
Wed Sep 02, 2020 10:30 am
Forum: General
Topic: How to connect switches and router - planing network architecture
Replies: 3
Views: 1681

Re: How to connect switches and router - planing network architecture

Guys, English is not my main language, but I hope more or less I have written understandably. I don't know which router should I choose for my network - CCR1009-7G-1C-1S+ or CCR2004-1G-12S+2XS. And how to connect it to switches. I've tried to describe my network and my needs. I've looked at block di...
by fpawlak
Wed Aug 26, 2020 6:46 pm
Forum: General
Topic: How to connect switches and router - planing network architecture
Replies: 3
Views: 1681

How to connect switches and router - planing network architecture

Hi Guys. Can you help me with planning of the architecture of company network? I'm using already CRS328-24P-4S+RM as switches, and RBcAPGi-5acD2nD as WiFi access points. But the question is how to connect together switches and then to the router in the best way. I'm using VLANs(office network, guest...