Community discussions

MikroTik App

Search found 6489 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 22
by holvoetn
Fri Oct 04, 2024 4:47 pm
Forum: General
Topic: cloudflare fights off a record amount of DDoS traffic, mikrotik one of the main culprits
Replies: 5
Views: 580

Re: cloudflare fights off a record amount of DDoS traffic, mikrotik one of the main culprits

You need to be correct with your references. The company’s investigation traced the campaign to a hacker-controlled botnet made up of hijacked internet devices, including Asus and MikroTik routers, DVRs, and web servers. It doesn't say Mikrotik (nor Asus) is one of the MAIN culprits. It doesn't say ...
by holvoetn
Fri Oct 04, 2024 12:02 pm
Forum: Announcements
Topic: v7.16 [stable] is released!
Replies: 292
Views: 41358

Re: v7.16 [stable] is released!

Not good news.... I use 44 piece cap AC with qcom-ac (more VLAN and ~70 piece wifi client with 802.11r fast BSS transitions ( roaming), routeros 7.15.3 and 7.16rc1-5). After 7-10 days runs out the cap's memory. I am on 8+ days and RAM is declining indeed. I have not enabled graphing so I can't proo...
by holvoetn
Thu Oct 03, 2024 9:09 pm
Forum: General
Topic: Device got hacked 1 min after connected to internet
Replies: 51
Views: 3879

Re: Device got hacked 1 min after connected to internet

I get your point and I do agree default inactive interface is the best way, security-wise.
But it may be inconvenient for some to enable it again :D
by holvoetn
Thu Oct 03, 2024 8:56 pm
Forum: General
Topic: Device got hacked 1 min after connected to internet
Replies: 51
Views: 3879

Re: Device got hacked 1 min after connected to internet

Maybe reading a bit carefully won't hurt ... In some cases removing SIM from slot is not convenient ... then providing simple script to netinstall with command which disables lte1 interface is the way... Convenience is a factor which has a huge impact towards lowering security. Human factor BTW is ...
by holvoetn
Thu Oct 03, 2024 8:21 pm
Forum: General
Topic: Device got hacked 1 min after connected to internet
Replies: 51
Views: 3879

Re: Device got hacked 1 min after connected to internet

You can always install without SIM being present.
Result: no LTE.

Mission accomplished.
by holvoetn
Wed Oct 02, 2024 10:15 pm
Forum: Beginner Basics
Topic: hAP ax^3 2.4G wifi doesn't work
Replies: 14
Views: 457

Re: hAP ax^3 2.4G wifi doesn't work

Please post config of wifi part.
by holvoetn
Wed Oct 02, 2024 9:52 pm
Forum: RouterBOARD hardware
Topic: RB5009UG+S+IN <=> XQ+BC0003-XS+ <=> CRS504-4XQ-IN?
Replies: 1
Views: 124

Re: RB5009UG+S+IN <=> XQ+BC0003-XS+ <=> CRS504-4XQ-IN?

Why do you put a 100Gb -> 4x25Gb breakout cable in a router with only 10Gb as max on SFP+ port ?
You read the specs for CRS504 but not for RB5009 ?

Use a simple DAC and it will connect at 10Gb, I would think.
by holvoetn
Wed Oct 02, 2024 9:42 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 317
Views: 26102

Re: v7.17beta [testing] is released!

Adding: this part from changelog 7.16 *) container - clear VETH address on container exit and mark interface as running only when VETH is in use; ...is not yet implemented in 7.17b2. It's not in the changelog so no surprise but it's one of the things which set me off initially when troubleshooting d...
by holvoetn
Wed Oct 02, 2024 9:23 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 317
Views: 26102

Re: v7.17beta [testing] is released!

Any hints in log? Missing exec. Only thing which shows in log after start and then immediately stop. At first sight (quickly logged in via wireguard during lunch break) disk is mounted correctly (it did cause problems in the past with some USB3 drives on Rb5009 but it seems it gets recognized ok no...
by holvoetn
Wed Oct 02, 2024 3:05 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 317
Views: 26102

Re: v7.17beta [testing] is released!

Were do I need to look then ? Any hints in log? Missing exec. Only thing which shows in log after start and then immediately stop. At first sight (quickly logged in via wireguard during lunch break) disk is mounted correctly (it did cause problems in the past with some USB3 drives on Rb5009 but it ...
by holvoetn
Wed Oct 02, 2024 2:59 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 317
Views: 26102

Re: v7.17beta [testing] is released!

If your containers stopped working after upgrade to 7.17, it might not be related to device mode at all.
I never said it was related to device mode.
However it is related to ROS 7.17beta... and that's what this thread is about, no ?

I will troubleshoot this evening.
by holvoetn
Wed Oct 02, 2024 2:17 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 317
Views: 26102

Re: v7.17beta [testing] is released!

Nothing should happen, on my ax3 everything is working. Do you have an issue ? It's not ok on my RB5009. None of my containers start (iperf, openspeedtest, pi-hole) and yesterday I noticed a couple of drops during Teams calls (never saw that happening before). Will troubleshoot later this evening.
by holvoetn
Wed Oct 02, 2024 12:56 pm
Forum: General
Topic: Ovpn hardware acceleration
Replies: 2
Views: 127

Re: Ovpn hardware acceleration

Consider moving to Wireguard.
Purely CPU (= no HW offload) and yet WAY faster then all the rest (sometimes even faster then HW offloaded ipsec on same HW)
by holvoetn
Tue Oct 01, 2024 9:41 am
Forum: Wireless Networking
Topic: External antenna for hap ax lite
Replies: 3
Views: 183

Re: External antenna for hap ax lite

Instead of damaging hAP AX Lite, why not use L23UGSR-5HaxD2HaxD and start from there ?
It has connectors for attaching antenna to it.

Or do you need the ether ports as well ?
by holvoetn
Tue Oct 01, 2024 8:16 am
Forum: Announcements
Topic: v7.16 [stable] is released!
Replies: 292
Views: 41358

Re: v7.16 [stable] is released!

My CRS310-8G+2S+ simply refuses to upgrade from 7.12.2. The arm package is there, but it doesn't get picked up on reboot. Most likely space issues because moving from 7.12.x going higher, will probably also install wireless. On a switch ... :shock: (on the CRS devices I upgraded, I saw it each time...
by holvoetn
Mon Sep 30, 2024 6:55 pm
Forum: RouterBOARD hardware
Topic: Extending the SMD LED
Replies: 3
Views: 200

Re: Extending the SMD LED

I would think ... light pipes ?
by holvoetn
Mon Sep 30, 2024 6:53 pm
Forum: General
Topic: Struggling with VLANs on MikroTik CRS305
Replies: 9
Views: 569

Re: Struggling with VLANs on MikroTik CRS305

And to close everything on a more light tone:

Mikrotik admin rules:
1) You do not use VLAN1
2) You DO NOT use VLAN1
3) You do not use Quickset
4) You do not use detect internet
5)...
by holvoetn
Mon Sep 30, 2024 5:16 pm
Forum: General
Topic: hexS with PoE 20°C warmer?
Replies: 7
Views: 295

Re: hexS with PoE 20°C warmer?

65° is not "preoccupying", but it is right on the border of "temperatures I won't run my electronics at for long periods, if I can avoid it". Consumer grade equipment can run without any issues at 70C, industry grade goes to 85C or so. Military grade can surpass 120C. I would be...
by holvoetn
Mon Sep 30, 2024 12:13 pm
Forum: Beginner Basics
Topic: Missing WLAN in OS 7 [SOLVED]
Replies: 12
Views: 5751

Re: Missing WLAN in OS 7 [SOLVED]

You're mixing up two things...

I see references to AX devices yet wireless package.
So what are you exactly trying to do ?
by holvoetn
Mon Sep 30, 2024 12:02 pm
Forum: Announcements
Topic: v7.16 [stable] is released!
Replies: 292
Views: 41358

Re: v7.16 [stable] is released!

*) wifi-qcom-ac - improved memory allocating process; I'm afraid this is not fixed yet. cAP AC, reboot after 2d22h due to kernel failure. PRTG monitoring shows increasing memory usage until reboot happens. Back to daily scheduled reboot for now 8) I already have an open ticket, will send autosupout...
by holvoetn
Sat Sep 28, 2024 2:52 pm
Forum: Wireless Networking
Topic: Mikrotik cAP ax and tp-link SG2016P switch between - CAPsMAN problem, no network
Replies: 2
Views: 340

Re: Mikrotik cAP ax and tp-link SG2016P switch between - CAPsMAN problem, no network

You need full L2 and udp access.

Q:
2 versions of capsman with 1 ap each ? Why ???
by holvoetn
Sat Sep 28, 2024 2:48 pm
Forum: Beginner Basics
Topic: One network hidden, one visible
Replies: 3
Views: 265

Re: One network hidden, one visible

Are you sure there is no time out because of radar detection ( DFS check) ?
Can take up to 15 minutes.
by holvoetn
Sat Sep 28, 2024 2:44 pm
Forum: Wireless Networking
Topic: cAP ax performance and problems
Replies: 32
Views: 13495

Re: cAP ax performance and problems

When testing using internal iperf server, I frequently see 700-ish on AX devices.
by holvoetn
Sat Sep 28, 2024 10:05 am
Forum: Beginner Basics
Topic: I am a software engineer who is new to all these
Replies: 6
Views: 448

Re: I am a software engineer who is new to all these

As a SW engineer you _should_ know clearly defined specs are paramount before starting any development. Otherwise you start but you will never know when it ends nor where it ends. So ... what exactly is required to be done ? 1 line is not enough. A small drawing of the network setup clearly indicati...
by holvoetn
Sat Sep 28, 2024 9:58 am
Forum: Wireless Networking
Topic: No connection to CAPsMAN
Replies: 7
Views: 454

Re: No connection to CAPsMAN

It's a bit misleading since the same screens are used for local and capsman controlled interfaces. The ones marked with L should be locally managed since MT themselves clearly mentioned capsman CAN NOT control local interfaces. What is indicated as manager on those 2 radios marked with L ? My guess ...
by holvoetn
Sat Sep 28, 2024 12:18 am
Forum: General
Topic: rb4011 v7.9.2 Need downgrade but I cant
Replies: 4
Views: 309

Re: rb4011 v7.9.2 Need downgrade but I cant

Adapt script to ROS7.
Not much else you can do about it...
by holvoetn
Fri Sep 27, 2024 6:05 pm
Forum: General
Topic: Not getting forum email notifications anymore
Replies: 3
Views: 262

Re: Not getting email notifications

It has been on and off for a good part of the year, indeed.

I already made it a habit to go to user control panel and then check subscriptions.
by holvoetn
Fri Sep 27, 2024 4:29 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 317
Views: 26102

Re: v7.17beta [testing] is released!

And just before the weekend ... :lol:
by holvoetn
Fri Sep 27, 2024 3:18 pm
Forum: General
Topic: Any plan for Mikrotk to upgrade its travel router ?
Replies: 11
Views: 961

Re: Any plan for Mikrotk to upgrade its travel router ?

If on 2ghz, then distribute to devices in the room with 5ghz and of course the reverse. Obviously you are not familiar with the power of ROS and using virtual AP interfaces :shock: mAP and mAP Lite also only have 2GHz radio. They can be used for those cases just fine using virtual AP interfaces.
by holvoetn
Fri Sep 27, 2024 12:51 pm
Forum: General
Topic: Any plan for Mikrotk to upgrade its travel router ?
Replies: 11
Views: 961

Re: Any plan for Mikrotk to upgrade its travel router ?

hAP AX lite LTE and if needed battery pack.
Covered for at least 10h straight ...

Nobody really needs 5GHz when out in the field (to be honest: I don't). Besides, that LTE connection can not fill that pipe, so why bother ?
400Mbps on 2.4GHz is already plenty.
by holvoetn
Fri Sep 27, 2024 12:46 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1282
Views: 234814

Re: 📣 WinBox 4 is here 📣

Never use whatever beta when you can not afford breakdowns ...
by holvoetn
Fri Sep 27, 2024 12:45 pm
Forum: General
Topic: My new hAP ax lite LTE6 looses its lte after a few days
Replies: 27
Views: 1343

Re: My new hAP ax lite LTE6 looses its lte after a few days

Really ?

www.mikrotik.com
tab Support
Contact Support

Or send mail to support@mikrotik.com
by holvoetn
Fri Sep 27, 2024 11:41 am
Forum: General
Topic: My new hAP ax lite LTE6 looses its lte after a few days
Replies: 27
Views: 1343

Re: My new hAP ax lite LTE6 looses its lte after a few days

First, contact support with supout.rif, if you haven't already.
Personally I had to contact them already a couple of times for LTE issues with beta SW and usually they are pretty responsive.
by holvoetn
Fri Sep 27, 2024 11:36 am
Forum: Announcements
Topic: Newsletter #120 | September 2024
Replies: 54
Views: 8218

Re: Newsletter #120 | September 2024

Also (but that's my controlling nature)
test results with nice round figures (ending on all 0's), are usually an indication it hasn't been tested at all.
These are no real test results as far as I can see. Too bad someone did not notice this before publishing them.
by holvoetn
Fri Sep 27, 2024 10:15 am
Forum: Announcements
Topic: Newsletter #120 | September 2024
Replies: 54
Views: 8218

Re: Newsletter #120 | September 2024

Those results do look very bad
As if they, somehow, only tested the 1Gbps MGMT port?
... and didn't pay attention that those test results are not what they were expected to be ?
I mean, why have 4x10Gb ports if the device is only capable of moving 2Gbps in total ?
by holvoetn
Fri Sep 27, 2024 9:42 am
Forum: Wireless Networking
Topic: CAPsMAN
Replies: 9
Views: 558

Re: CAPsMAN

The 1M € question ...

Rephrased:
Why do you think you need to move to capsman if it works now ?
What do you think (from watching all those YT videos) you can use to your benefit which you currently don't have with your current setup ?
by holvoetn
Fri Sep 27, 2024 9:36 am
Forum: Announcements
Topic: v7.16 [stable] is released!
Replies: 292
Views: 41358

Re: v7.16 [stable] is released!

powered by power supply or Poe?
PoE from a 4011.
Updated device FW as well to 7.16 ?
Already 2 users with POE issues which were solved after performing FW upgrade as well.
by holvoetn
Thu Sep 26, 2024 12:18 pm
Forum: General
Topic: rb4011 v7.9.2 Need downgrade but I cant
Replies: 4
Views: 309

Re: rb4011 v7.9.2 Need downgrade but I cant

You can not downgrade below factory firmware version.
What does your device show using System / Routerboard ?
by holvoetn
Thu Sep 26, 2024 7:20 am
Forum: General
Topic: Struggling with VLANs on MikroTik CRS305
Replies: 9
Views: 569

Re: Struggling with VLANs on MikroTik CRS305

First thing which comes to mind:
Usage of untagged vlan 1.

Some brands accept it. Some don't.

Best to avoid vlan1 completely.
by holvoetn
Wed Sep 25, 2024 9:52 pm
Forum: Announcements
Topic: v7.16 [stable] is released!
Replies: 292
Views: 41358

Re: v7.16 [stable] is released!

@pe1chl
Did you also upgrade FW on that device ?
I've seen a similar report, I think, which was solved when fw was upgraded.
by holvoetn
Wed Sep 25, 2024 5:23 pm
Forum: Wireless Networking
Topic: No Connection to CAPsMAN [SOLVED]
Replies: 17
Views: 2688

Re: No Connection to CAPsMAN [SOLVED]

As a side note: whenever you change something in firewall rules, clear connections table or restart. Or it might take a while before you see the effect. But wireless/wifi-qcom confusion is going to be the winner here. As of ROS7.13, you don't even need to load wifi-qcom driver anymore for capsman co...
by holvoetn
Wed Sep 25, 2024 3:43 pm
Forum: Announcements
Topic: v7.16 [stable] is released!
Replies: 292
Views: 41358

Re: v7.16 [stable] is released!

There was a memory leak as well on cap ac when using wifi-qcom-ac drivers.
Testing since yesterday, no results yet ( before it would go OOM after almost 2 days).
by holvoetn
Tue Sep 24, 2024 8:50 pm
Forum: General
Topic: Wishes for 7.17 beta
Replies: 11
Views: 740

Re: Wishes for 7.17 beta

On one side you are right, but on the other - if you asking something for years for a really huge enterprise - why not just create your own log proxy to convert it to whatever you want? I understand the request but I'm in this camp as well given the time passed. -Get version -Apply translation as n...
by holvoetn
Tue Sep 24, 2024 6:47 pm
Forum: Beginner Basics
Topic: Can't WOL using 3rd party apps
Replies: 4
Views: 429

Re: Can't WOL using 3rd party apps

From what I understood, WOL uses UDP magic packet so it HAS to be on the same subnet or it gets blocked.

You could perhaps look into this thread where a possible workaround was suggested:
viewtopic.php?t=182266
by holvoetn
Tue Sep 24, 2024 6:31 pm
Forum: RouterBOARD hardware
Topic: 5g outdoor as a backup connection
Replies: 7
Views: 622

Re: 5g outdoor as a backup connection

You could ask sales@mikrotik.com but they usually don't provide a lot of info on their roadmap.
Maybe your distributor could have some more leverage to obtain this info ?
by holvoetn
Tue Sep 24, 2024 5:23 pm
Forum: General
Topic: Segregate an internal Wireguard server
Replies: 16
Views: 751

Re: Segregate an internal Wireguard server

From what I understand he wants to have users using a wireguard server NOT on RB5009.
So a different server.

Hence port forward and be done with it.
by holvoetn
Tue Sep 24, 2024 5:10 pm
Forum: General
Topic: Re: Winbox 3.40 Downloading Descriptors
Replies: 6
Views: 1968

Re: Winbox 3.40 Downloading Descriptors

I am also having this issue, and I'm seeing many threads about this same issue. Bold statement, where is the proof ? I haven't seen it being reported here that often. I don't read all threads but if there were many, I would probably have noticed. I'm pretty sure if there were so many threads, suppo...
by holvoetn
Tue Sep 24, 2024 4:45 pm
Forum: General
Topic: Struggling with VLANs on MikroTik CRS305
Replies: 9
Views: 569

Re: Struggling with VLANs on MikroTik CRS305

You may want to read, review and digest this excellent post, considered to be the DE FACTO VLAN bible for ROS:
viewtopic.php?t=143620
by holvoetn
Tue Sep 24, 2024 4:42 pm
Forum: RouterBOARD hardware
Topic: CRS354-48P-4S+2Q+ PoE issues
Replies: 1
Views: 234

Re: CRS354-48P-4S+2Q+ PoE issues

Have you checked total output on all POE ports ?
Maximum is 27A at 26V OR 13.2A at 53V

How much current is being drawn by those Hikvision cameras ?
From spec of CRS354
Max out per port output (input 18-30 V) 1000 mA
Max out per port output (input 30-57 V) 570 mA
by holvoetn
Tue Sep 24, 2024 3:59 pm
Forum: General
Topic: Segregate an internal Wireguard server
Replies: 16
Views: 751

Re: Segregate an internal Wireguard server

But that's not what I asked about. I do not want to terminate these Wireguard users on the RB5009 (see earlier post).
In that case apply simple port forward towards the server which will accept these wireguard users.
And be smart and use another port then the one you already have in use.
by holvoetn
Tue Sep 24, 2024 2:33 pm
Forum: Announcements
Topic: v7.16 [stable] is released!
Replies: 292
Views: 41358

Re: v7.16 [stable] is released!

Is it normal for CAPSMAN not to show traffic from the CAPs? I've upgraded, things work but I only see traffic on the individual CAPs but not on CAPSMAN. If wifiwave2 capsman, that's already the case since start of wave2 capsman, many, MANY moons ago ... Or are you referring to legacy wireless capsm...
by holvoetn
Tue Sep 24, 2024 1:37 pm
Forum: Wireless Networking
Topic: Guest wifi over vlan not working
Replies: 4
Views: 360

Re: Guest wifi over vlan not working

2 tabs to the left.

Bridge / ports

You may want to review this excellent guide (and defacto bible regarding VLAN on ROS):
viewtopic.php?t=143620

Section related to access point.
by holvoetn
Tue Sep 24, 2024 11:54 am
Forum: Wireless Networking
Topic: Guest wifi over vlan not working
Replies: 4
Views: 360

Re: Guest wifi over vlan not working

You did not add wifi interfaces to bridge/port ?
They should be added as untagged, not the VLAN itf itself.
by holvoetn
Tue Sep 24, 2024 10:17 am
Forum: Announcements
Topic: v7.16 [stable] is released!
Replies: 292
Views: 41358

Re: v7.16 [stable] is released!

There has been a rather large period of beta and rc testing.

For some there are too much changes.
For some there are never enough changes.

It's never good for everyone everytime.
by holvoetn
Tue Sep 24, 2024 8:12 am
Forum: Beginner Basics
Topic: WiFi Setup for Access Point
Replies: 10
Views: 829

Re: WiFi Setup for Access Point

It seems you are correct, they didn't bring over all examples from the old wiki environment ... (to say it more accurate: I couldn't find them in the Help pages, only on old Wiki) See here: https://wiki.mikrotik.com/wiki/Manual:TOC Section wireless, right column with examples. There you can find the...
by holvoetn
Mon Sep 23, 2024 10:43 am
Forum: General
Topic: EG18-EA LTE Modems
Replies: 2
Views: 329

Re: EG18-EA LTE Modems

Best to ask support or sales.
MT staff does visit this forum from time to time but not that often and certainly not all posts.

support@...
sales@...
by holvoetn
Sun Sep 22, 2024 6:15 pm
Forum: General
Topic: MASTER INTERFACE UNKNOWN
Replies: 7
Views: 3537

Re: MASTER INTERFACE UNKNOWN

I was tempted for 5 seconds to simply delete this post but... 1 installing packages is dead simple, if done in the correct way. 2 setting up wifi should not be too hard if you follow help pages. Even default config already helps a lot ( although sub optimal). 3 maybe you need to look in the mirror ?...
by holvoetn
Sun Sep 22, 2024 6:03 pm
Forum: RouterBOARD hardware
Topic: RB5009UPr+S+IN PoE-out on half ports only
Replies: 6
Views: 609

Re: RB5009UPr+S+IN PoE-out on half ports only

Which part of that quote is not clear ?

Can be controlled per port independently.
by holvoetn
Sun Sep 22, 2024 5:43 pm
Forum: RouterBOARD hardware
Topic: ax3, no ethernet, no wifi signal
Replies: 2
Views: 391

Re: ax3, no ethernet, no wifi signal

Wireless will not work on AX line.
by holvoetn
Sun Sep 22, 2024 4:45 pm
Forum: Beginner Basics
Topic: WiFi Setup for Access Point
Replies: 10
Views: 829

Re: WiFi Setup for Access Point

Dropping the ros file directly, was the odd way. If you followed upgrade path, it would have first upgraded to 7.13.2. And the next upgrade wireless would automatically have been split ( something which was prepared in the background with 7.13.x). Help pages still have all examples and settings for ...
by holvoetn
Sun Sep 22, 2024 1:32 pm
Forum: Beginner Basics
Topic: WiFi Setup for Access Point
Replies: 10
Views: 829

Re: WiFi Setup for Access Point

Looks like you upgraded in an odd way then because normally that wireless package should have come nicely in the regular upgrade process.

But now you need to choose first:
legacy wireless - add wireless package
wave2 wifi - add wifi-qcom-ac
by holvoetn
Sun Sep 22, 2024 1:29 pm
Forum: Announcements
Topic: v7.16rc [testing] is released!
Replies: 362
Views: 112313

Re: v7.16rc [testing] is released!

After upgrading my RB4011iGS+5HacQ2HnD from 7.15.1 to 7.16rc4 I noticed that apparently the default name of the wireless interfaces has been swapped. ... Is this an intentional change? I do not see it in the release notes. Of course keeping it like this could get confusing lateron, so maybe I shoul...
by holvoetn
Sun Sep 22, 2024 1:23 pm
Forum: Wireless Networking
Topic: Capsman loosing connection when connected through switch
Replies: 30
Views: 1706

Re: Capsman loosing connection when connected through switch

Most likely this one: add action=accept chain=input comment="CAPSMAN PORTS" port=5246,5247 \ protocol=udp It accepts capsman access from EVERYWHERE. Best to add in-interfacelist=LAN Then only LAN is allowed. But I agree, those firewall rules can benefit from a major overhaul ... quite some...
by holvoetn
Sun Sep 22, 2024 1:08 pm
Forum: Useful user articles
Topic: GESP POE IN problem - 100 Mpbs
Replies: 3
Views: 3959

Re: GESP POE IN problem - 100 Mpbs

It's not clearly listed but given size and cost, I would think passive POE and nothing else.
by holvoetn
Sun Sep 22, 2024 1:05 pm
Forum: Beginner Basics
Topic: WiFi Setup for Access Point
Replies: 10
Views: 829

Re: WiFi Setup for Access Point

Cap XL AC default comes with legacy wireless drivers. If you want to use wifi part of menu, that means wave2 drivers. So you need to remove wireless and load wifi-qcom-ac driver. Or stick with legacy wifi but then you need to use Wireless / Wireless part of the menu structure. Can you list which pac...
by holvoetn
Fri Sep 20, 2024 8:49 pm
Forum: General
Topic: Bios Battery to Mikrotik
Replies: 2
Views: 490

Re: Bios Battery to Mikrotik

Use a proper UPS, perhaps ?

Usually, on PCs, RTC is in a separate chip.
by holvoetn
Fri Sep 20, 2024 5:13 pm
Forum: General
Topic: Failover Mikrotik
Replies: 2
Views: 436

Re: Failover Mikrotik

Please post in English.
I have added a machine translated English version.

The whole forum is in English
Using 1 common language will help you get an answer a lot faster.
Also, search engines will be able to pick up your question (and responses) a lot easier in case others have the same issue.
by holvoetn
Fri Sep 20, 2024 8:23 am
Forum: General
Topic: RB5009 router "limiting" ALL Linux machines
Replies: 2
Views: 701

Re: RB5009 router "limiting" ALL Linux machines

Why is this marked as "Solved" ?
by holvoetn
Fri Sep 20, 2024 8:16 am
Forum: General
Topic: Pc not reachable [SOLVED]
Replies: 8
Views: 807

Re: Pc not reachable [SOLVED]

Firewall on PC is off ?
by holvoetn
Thu Sep 19, 2024 3:53 pm
Forum: Wireless Networking
Topic: Prefer DFS channels on hAP AX3
Replies: 3
Views: 501

Re: Prefer DFS channels on hAP AX3

Correct. You can specify the frequency range yourself but if it's only DFS range and DFS is detected, it's radio silence when that happens ... A bit logical those are not used that much, everyone tries to avoid them. BTW heavily congested ? You obviously need to take into account your client devices...
by holvoetn
Thu Sep 19, 2024 2:42 pm
Forum: General
Topic: Samsung TV - wifi working, ethernet does not [SOLVED]
Replies: 5
Views: 665

Re: Samsung TV - wifi working, ethernet does not [SOLVED]

If you do not specify it, it will be default untagged for the pvid linked to that port.
Best to specify it anyhow so it will show in export of config and gui-screens. Then you will most likely remember why you made that change 8)
by holvoetn
Thu Sep 19, 2024 1:29 pm
Forum: General
Topic: Samsung TV - wifi working, ethernet does not [SOLVED]
Replies: 5
Views: 665

Re: Samsung TV - wifi working, ethernet does not [SOLVED]

Ether5 is an access port so it should handle untagged frames coming in.
Your TV doesn't know a thing about VLAN.
So Ether5 needs to be untagged.

Normally for wifi-interfaces it should also be like this but the underlying wifi-driver may take care of that.
by holvoetn
Thu Sep 19, 2024 12:18 pm
Forum: Wireless Networking
Topic: iOS 18 Wi-Fi connectivity issue [SOLVED]
Replies: 71
Views: 4381

Re: iOS 18 Wi-Fi connectivity issue [SOLVED]

Only as a side note, ...(I simply cannot bear videos, but that's just me) ...
You're not alone.
I prefer a good old searchable manual anytime over whatever video which usually is a waste of time for the most part (to me).
by holvoetn
Thu Sep 19, 2024 10:57 am
Forum: Wireless Networking
Topic: iOS 18 Wi-Fi connectivity issue [SOLVED]
Replies: 71
Views: 4381

Re: iOS 18 Wi-Fi connectivity issue [SOLVED]

OT: it really bugs me that Apple require an A17 chip to enable ChatGPT integration in iOS 18. It’s so very typical of Apple always finding new ways to push people to upgrade their hardware. The same company which added a deliberate slowing down of older HW and it still surprises you ? What do you t...
by holvoetn
Thu Sep 19, 2024 9:51 am
Forum: Announcements
Topic: MikroTik Devices Controller
Replies: 374
Views: 256415

Re: MikroTik Devices Controller

Nothing.
You call native MacOS and Linux client "nothing" ?
by holvoetn
Thu Sep 19, 2024 8:12 am
Forum: General
Topic: Pc not reachable [SOLVED]
Replies: 8
Views: 807

Re: Pc not reachable [SOLVED]

If that PC is recent Windows, check firewall settings.
Default Windows doesn't allow incoming ping.
by holvoetn
Wed Sep 18, 2024 11:05 pm
Forum: General
Topic: Can anyone help me understand what is going on with my сAP ac
Replies: 4
Views: 447

Re: Can anyone help me understand what is going on with my сAP ac

My 0.02€ ... cAP AC is still being sold (just bought 8 for a new setup with a customer) and you can load wave2 drivers on them. I prefer the square package they come with over the round one. Fabulous decision from Mikrotik to have both in the box. cAP AX is more performant, absolutely no doubt there...
by holvoetn
Wed Sep 18, 2024 10:13 pm
Forum: RouterBOARD hardware
Topic: RB3011UiAS not utilizing both cores? [SOLVED]
Replies: 4
Views: 813

Re: RB3011UiAS not utilizing both cores? [SOLVED]

You could have mentioned that load balancing setup to start with. Rule of thumb to assess performance: look at test results, routing and 25 filter rules. That gives you an idea of the ballpark figure your device should be able to handle as a regular router. For RB3011 it shows 453Mbps (give or take)...
by holvoetn
Wed Sep 18, 2024 9:57 pm
Forum: Wireless Networking
Topic: CAPsMAN & CAP-AX Wireless issues
Replies: 10
Views: 698

Re: CAPsMAN & CAP-AX Wireless issues

Obviously you can leave everything to auto and use the controller to do its thing.
But it may result in a sub-optimal setup.
That's my personal view.

Mikrotik gives you the advantage to take all those things in your own hands and decide what frequency gets used where.
by holvoetn
Wed Sep 18, 2024 2:50 pm
Forum: Wireless Networking
Topic: sim not present with hAP ax lite LTE6 [SOLVED]
Replies: 12
Views: 784

Re: sim not present with hAP ax lite LTE6 [SOLVED]

At least here in Italy most "mobile" POS (Point of Sale) card readers come with their own (GSM or LTE, cannot say) modem and SIM (cannot say if physical SIM or e-sim) ... In Belgium we can choose for most suppliers (Atos Worldine, Ingenico, ...). BUT ... with nowadays obsession on isolati...
by holvoetn
Wed Sep 18, 2024 2:24 pm
Forum: Wireless Networking
Topic: CAPsMAN & CAP-AX Wireless issues
Replies: 10
Views: 698

Re: CAPsMAN & CAP-AX Wireless issues

My take: 1- Plan your channels, both on 2.4 and 5Ghz so they don't overlap. It helps to use drawings of building/floor. 2- try to avoid DFS channels _if possible_ 3- use provisioning rules so you KNOWN which channels get fixed assigned to which cap. You can also use regex expressions if you name you...
by holvoetn
Wed Sep 18, 2024 12:50 pm
Forum: Wireless Networking
Topic: sim not present with hAP ax lite LTE6 [SOLVED]
Replies: 12
Views: 784

Re: sim not present with hAP ax lite LTE6 [SOLVED]

Been there, done that. Normal clipped fingernails are not sufficient either to guide it further. I use flat end of a paperclip, even tip of a ballpoint pen can be used (but then you got the ink all over the side of that SIM :lol: ) Slightly perplexed why only Wi-Fi 6 on 2.4GHz but the need is only f...
by holvoetn
Wed Sep 18, 2024 10:03 am
Forum: RouterBOARD hardware
Topic: RB3011UiAS not utilizing both cores? [SOLVED]
Replies: 4
Views: 813

Re: RB3011UiAS not utilizing both cores? [SOLVED]

Use Tools / Profile to have at least an idea which service is causing the load.

Some services can be distributed to multiple cores, some are single-core.
It can also be a config issue (e.g. wrong VLAN setup where everything passes CPU instead of being HW offloaded).
by holvoetn
Tue Sep 17, 2024 4:13 pm
Forum: Wireless Networking
Topic: Connect to Hotel Wifi
Replies: 7
Views: 512

Re: Connect to Hotel Wifi

No way. You need two radios = 2 different wifi interfaces to do that. As indicated by bpwl, perfectly possible using main radio and virtual AP as slave. I also have mAP and mAP Lite using such setup for years. Only "drawback" is that your main wifi needs to be connected before slave will ...
by holvoetn
Tue Sep 17, 2024 3:23 pm
Forum: Beginner Basics
Topic: LHG LTE6 needs restart twice a day to work
Replies: 2
Views: 299

Re: LHG LTE6 needs restart twice a day to work

Upgrade to 7.15.3. There have been quite a bit of LTE fixes there.
I would try that first.
by holvoetn
Tue Sep 17, 2024 3:22 pm
Forum: General
Topic: Transfers between LAN and WLAN very slow
Replies: 2
Views: 284

Re: Transfers between LAN and WLAN very slow

So many factors at play ... I assume it's one flat network, no VLANs involved ? HEX S might indeed be the limiting factor when doing LAN to LAN. You can easily test this when testing using 2 ports on HEX S itself, you should get close to 950Mb then. How do you test ? Using internal iperf3 server ? I...
by holvoetn
Tue Sep 17, 2024 11:53 am
Forum: Wireless Networking
Topic: Capsman loosing connection when connected through switch
Replies: 30
Views: 1706

Re: Capsman loosing connection when connected through switch

Not realy sure what you mean with cap-mgmt connection. My main natwork is on primary VLAN (1) and CAPsMAN and CAPs communicate over this. I was already thinking it was going into this direction ... There is some internal joke between more seasoned users about some basic rules when using MT gear. It...
by holvoetn
Tue Sep 17, 2024 10:51 am
Forum: Wireless Networking
Topic: Capsman loosing connection when connected through switch
Replies: 30
Views: 1706

Re: Capsman loosing connection when connected through switch

Did you enable all needed VLAN handling on that switch ?
You have to add at least the needed VLANs for wifi channels and cap-mgmt connection.

About that RB5009 config ... why multiple bridges ? For docker I understand but the rest ? You're complicating things quite a bit this way.
by holvoetn
Tue Sep 17, 2024 9:20 am
Forum: Wireless Networking
Topic: Capsman loosing connection when connected through switch
Replies: 30
Views: 1706

Re: Capsman loosing connection when connected through switch

(I added some comments in my previous post, in case you missed it ...)
by holvoetn
Tue Sep 17, 2024 9:15 am
Forum: Wireless Networking
Topic: Capsman loosing connection when connected through switch
Replies: 30
Views: 1706

Re: Capsman loosing connection when connected through switch

I mean export of cap device which is not showing... is that the AX device or also an AC device ? And .. if you have a mix of wifi-qcom-ac (AC) and wifi-qcom (AX) devices, there are some things to take into consideration. You surely already had a decent look here ? https://help.mikrotik.com/docs/disp...
by holvoetn
Tue Sep 17, 2024 8:22 am
Forum: Wireless Networking
Topic: Capsman loosing connection when connected through switch
Replies: 30
Views: 1706

Re: Capsman loosing connection when connected through switch

Why do you have both capsman versions enabled on RB5009 ?
Are you sure the missing cap is not visible in the other controller environment ?
Are you sure ALL of your caps devices use wave2 drivers ?

It might also be best to have the export of the caps not showing.
by holvoetn
Mon Sep 16, 2024 10:19 pm
Forum: Wireless Networking
Topic: Capsman loosing connection when connected through switch
Replies: 30
Views: 1706

Re: Capsman loosing connection when connected through switch

I'll retake this request...

Can you share the config?
/export file=anynameyoulike
Remove serial and any other private info and post between code tags by using the </> button.
by holvoetn
Mon Sep 16, 2024 3:56 pm
Forum: RouterOS beta
Topic: L3HW not working properly
Replies: 19
Views: 10852

Re: L3HW not working properly

I seem to remember a discussion about this exact problem a while ago (could be many moths ago) and @Normis acknowledged the bug. I'm pretty sure it was supposed to be fixed since then, but I've no idea in which version this was fixed (if at all). So if the problem happens on a recent v7, then this ...
by holvoetn
Mon Sep 16, 2024 11:41 am
Forum: Wireless Networking
Topic: Capsman loosing connection when connected through switch
Replies: 30
Views: 1706

Re: Capsman loosing connection when connected through switch

Does this also happen when you set in cap the specific IP address for capsman controller ?
by holvoetn
Sun Sep 15, 2024 3:40 pm
Forum: General
Topic: My new hAP ax lite LTE6 looses its lte after a few days
Replies: 27
Views: 1343

Re: My new hAP ax lite LTE6 looses its lte after a few days

For the moment I wouldn't update the RoS (unless you are missing some other feature implemented in later versions) and definitely not the firmware of the LTE thingy, given the issues reported on the mentioned thread that seems objectively worse than the ones you are reporting.: Quite a bit of LTE i...
by holvoetn
Sun Sep 15, 2024 3:34 pm
Forum: RouterBOARD hardware
Topic: hAP ax lite LTE - issues after modem FW upgrade to 16121.1034.00.01.01.05
Replies: 48
Views: 6705

Re: hAP ax lite LTE - issues after modem FW upgrade to 16121.1034.00.01.01.05

First upgrade to latest 7.15 branch and then see what happens.
You can also try 7.16rc, quite a lot of LTE issues have been addressed there. Or wait for 7.16 to become stable.
by holvoetn
Fri Sep 13, 2024 3:15 pm
Forum: General
Topic: HIDDEN Wifi Networks
Replies: 9
Views: 582

Re: HIDDEN Wifi Networks

I didn't explain this principle as answer to your original question because this is not a rule one can rely on. Because MAC addresses can be set manually to arbitrary values (I tend to collect some old, possibly broken, ethernet devices ... and re-use their MAC addresses for BSSIDs of virtual wifi ...
by holvoetn
Fri Sep 13, 2024 12:31 pm
Forum: RouterBOARD hardware
Topic: NetMetal ax / L23-UGSR — initial feedback from specs
Replies: 38
Views: 5782

Re: NetMetal ax / L23-UGSR — initial feedback from specs

Mikrotik HW is capable enough. The problem is there are way too many settings where you can goof up and then performance goes down the drain. That's the difference with cheapo devices which have a "good for most, set and forget but you can not change a lot" config. The strength and weaknes...
by holvoetn
Fri Sep 13, 2024 9:29 am
Forum: General
Topic: Backup and restore Containers
Replies: 4
Views: 384

Re: Backup and restore Containers

Valid question and I am curious too for the solution.

Have you already launched a ticket towards support ?
They should be able to tell how it needs to be done.
by holvoetn
Thu Sep 12, 2024 7:42 pm
Forum: General
Topic: Adding configurations to CAPSMAN
Replies: 4
Views: 293

Re: Adding configurations to CAPSMAN

Interesting entry here from Guntis (MT Staff) (and subsequent posts about the same topic): https://forum.mikrotik.com/viewtopic.php?p=1091327#p1091327 Basically, new configs should be pushed automatically. It could be on your PC the new SSID is not directly visible (I also observed it already both o...
by holvoetn
Thu Sep 12, 2024 1:49 pm
Forum: General
Topic: Firewall [SOLVED]
Replies: 3
Views: 662

Re: Firewall [SOLVED]

It might be better if you start a new topic AND provide A LOT more info on what exactly you are planning to do.

Other then that, a good start for reading/researching:
https://help.mikrotik.com/docs/display/ ... +Solutions
by holvoetn
Thu Sep 12, 2024 1:30 pm
Forum: Containers
Topic: Containers won't start after power loss
Replies: 8
Views: 7260

Re: Containers won't start after power loss

Both: are you sure after reboot the disk where the container is stored is still on the place where it needs to be ? (usually usb1) Some USB3 keys can after reboot only be accessed using USB2-protocol (a USB reset or delay when starting up the USB-interface solves it). If they start up as USB2, disk ...
by holvoetn
Thu Sep 12, 2024 1:21 pm
Forum: Beginner Basics
Topic: Caspman Config [SOLVED]
Replies: 21
Views: 1571

Re: Caspman Config [SOLVED]

Actually, you were referring to the fact ether2 cable should be removed from device :lol:

But I get what you wanted to say and your addition is (as usual) spot on.
by holvoetn
Thu Sep 12, 2024 9:41 am
Forum: Beginner Basics
Topic: Caspman Config [SOLVED]
Replies: 21
Views: 1571

Re: Caspman Config [SOLVED]

Default config has the rest of ether ports (and wireless) bridged and set as LAN ... from which management access to device is possible. Hence the suggestion to isntall ether2 cable as well (but that one should be removed after device comissioning if location is accessible to non-authorized people ...
by holvoetn
Thu Sep 12, 2024 9:03 am
Forum: Beginner Basics
Topic: Network traffic gets slower, when adding vlans
Replies: 27
Views: 1369

Re: Network traffic gets slower, when adding vlans

Wasn't something about this visible in log files ?
by holvoetn
Thu Sep 12, 2024 6:57 am
Forum: Beginner Basics
Topic: Caspman Config [SOLVED]
Replies: 21
Views: 1571

Re: Caspman Config [SOLVED]

Reset them to caps mode before handing over the devices.
That's what I do.

Alternatives
- always have ether2 connected as well to cable
- connect to device default wifi and then reset to caps mode
- pre configure device before it is being installed.
by holvoetn
Thu Sep 12, 2024 6:56 am
Forum: Wireless Networking
Topic: CAPS not showing in CAPsMAN
Replies: 7
Views: 527

Re: CAPS not showing in CAPsMAN

L22 uses wave2 radio.

That's the other capsman via wifi menu on your ccr.
Both versions can co-exist on the same controller.

But if there is only 1 wace2 device, why bother ? Set it up directly and reassess when you have multiple AX devices in your network.
by holvoetn
Wed Sep 11, 2024 11:10 pm
Forum: Beginner Basics
Topic: Caspman Config [SOLVED]
Replies: 21
Views: 1571

Re: Caspman Config [SOLVED]

Did you reset those cap ax to caps mode ?
Because if not, that would explain why you can not reach them straight away.
by holvoetn
Wed Sep 11, 2024 8:22 pm
Forum: Wireless Networking
Topic: CAPS not showing in CAPsMAN
Replies: 7
Views: 527

Re: CAPS not showing in CAPsMAN

For legacy capsman you do need wireless package on that ccr.

Again:
First choose.
Legacy capsman using old drivers or wave2 capsman with wave2 drivers ?
by holvoetn
Wed Sep 11, 2024 8:17 pm
Forum: Beginner Basics
Topic: Caspman Config [SOLVED]
Replies: 21
Views: 1571

Re: Caspman Config [SOLVED]

It DOES matter which cap device you use, as indicated above.

If you are unwilling to answer, then I am wasting my time here.
by holvoetn
Wed Sep 11, 2024 4:17 pm
Forum: Beginner Basics
Topic: Network traffic gets slower, when adding vlans
Replies: 27
Views: 1369

Re: Network traffic gets slower, when adding vlans

But ... but ...

ok, I'll accept because otherwise it may be considered contempt of court :lol:
by holvoetn
Wed Sep 11, 2024 1:07 pm
Forum: Wireless Networking
Topic: hAP ax3 - Low Wireless Strength
Replies: 7
Views: 1384

Re: hAP ax3 - Low Wireless Strength

Any input is appreciated
How can an hAP ax3 have WLAN interfaces? I expected wifi.
Well the config tells me it is an hAP ac3
Model number was also a clear indication :lol:
RBD53iG-5HacD2HnD = hAP AC3
by holvoetn
Wed Sep 11, 2024 12:15 pm
Forum: Beginner Basics
Topic: Network traffic gets slower, when adding vlans
Replies: 27
Views: 1369

Re: Network traffic gets slower, when adding vlans

4. Do NOT use quickset Small correction. 4. Do NOT use quickset unless you start from default config It can have its value for some users though I also admit it has been hugely neglected with the arrival of AX-devices (Or later versions of ROS ? Quite a bit of Quickset schemes which were present be...
by holvoetn
Tue Sep 10, 2024 9:19 pm
Forum: Wireless Networking
Topic: CAPS not showing in CAPsMAN
Replies: 7
Views: 527

Re: CAPS not showing in CAPsMAN

You are using old-style capsman and expect it to work with new-style wifi drivers ? That's not going to happen. One wireless driver across the board, no mix. 2 options: 1- Move everything to wave2-world: Remove wireless package from CCR1036 and setup everything under wifi menu tree. 2- Stick to lega...
by holvoetn
Tue Sep 10, 2024 8:41 pm
Forum: Beginner Basics
Topic: Caspman Config [SOLVED]
Replies: 21
Views: 1571

Re: Caspman Config [SOLVED]

Please be clear. Your first post says cAP XL. There is only cAP XL AC having "XL" in the name so we have to assume you are referring to that one. Then you say they use wifi-qcom (which is simply wrong for that device, it should use wifi-qcom-ac and then you have all the caveats I mentioned...
by holvoetn
Tue Sep 10, 2024 11:45 am
Forum: Beginner Basics
Topic: Capsman config, L009UiGS-2HaxD with L4 RBSXTsq2nD
Replies: 3
Views: 291

Re: Capsman config, L009UiGS-2HaxD with L4 RBSXTsq2nD

You can not have wireless package and working wifi interface on L009. You need to choose or move the wireless-capsman function to another device without AX radios. For AX devices (as of 7.13): Running both capsmans at the same time routeros + wireless Loses built-in cards See here: https://help.mikr...
by holvoetn
Tue Sep 10, 2024 11:28 am
Forum: Beginner Basics
Topic: Caspman Config [SOLVED]
Replies: 21
Views: 1571

Re: Caspman Config [SOLVED]

Just to clear some things out ... Are we talking about cAP AX devices or cAP XL AC devices ? Former are pure AX devices and should work when put in caps mode. Latter are AC devices and need wifi-qcom-ac package to be used with wave-capsman (under wifi menu structure) AND there are quite a bit of cav...
by holvoetn
Mon Sep 09, 2024 4:05 pm
Forum: General
Topic: Poor SFTP transfer speed to CCR2116 storage
Replies: 1
Views: 220

Re: Poor SFTP transfer speed to CCR2116 storage

Consider using ROSE package.
It's meant to be used for these cases.
https://help.mikrotik.com/docs/display/ROS/ROSE-storage
by holvoetn
Mon Sep 09, 2024 12:14 pm
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 655
Views: 256185

Re: v7.15.3 [stable] is released!

It might be a known issue.
Are you sure the disk has not been mounted as USB2 (and different label, e.g. disk2) ?
If so, USB reset should solve this issue.

Support is aware of the issue, it happens with some brands of USB disks.
No ETA yet on the solution.
by holvoetn
Sun Sep 08, 2024 2:42 pm
Forum: Beginner Basics
Topic: PING
Replies: 1
Views: 254

Re: PING

MOD COMMENT: Please only post in English.
It makes it a lot easier for everyone to read your question, it makes it easier for you to get responses, it makes it easier for searching this place.
I added the translation (using Google translate).
by holvoetn
Sat Sep 07, 2024 2:39 pm
Forum: General
Topic: Windows btest.exe super-duper slow
Replies: 3
Views: 1359

Re: Windows btest.exe super-duper slow

AFAIK that's needed when using UDP.
Using TCP it should try for maximum.

EDIT: I stand corrected. Even for TCP you need set the limits.
Odd because it's not like that when using Tools/Bandwidth Test directly from Mikrotik device
by holvoetn
Fri Sep 06, 2024 11:03 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1282
Views: 234814

Re: 📣 WinBox 4 is here 📣

I found a bug
System - RouterBOARD - Settings, reverse order of CPU frequencies
Снимок экрана 2024-09-06 222410.png
Actually ... it is sorted alphabetically.
So reverse would be wrong as well.
by holvoetn
Fri Sep 06, 2024 11:00 pm
Forum: Beginner Basics
Topic: VPN quickset changes and how to undo
Replies: 2
Views: 496

Re: VPN quickset changes and how to undo

There are 2 most advised ways to recover from Quickset mishap:
1- reset to default and start over
2- reset to default and don't touch quickset ever again after using it once.

There is a 3th option for more seasoned users ... never use Quickset.
by holvoetn
Fri Sep 06, 2024 10:57 pm
Forum: Forwarding Protocols
Topic: Public IP forwarded to Mikrotik Router for WireGuard use
Replies: 1
Views: 373

Re: Public IP forwarded to Mikrotik Router for WireGuard use

Did you also allow input for that port on your wAP R ?
by holvoetn
Fri Sep 06, 2024 8:17 am
Forum: Beginner Basics
Topic: Speed test on the router like Ookla
Replies: 3
Views: 485

Re: Speed test on the router like Ookla

See here: Openspeedtest on Docker on your router. https://forum.mikrotik.com/viewtopic.php?t=190891 As always: don't use it to test the router itself. Running this test does take away some resources so it will skew the results. ALways test thorugh a device, not using the device to be tested. But you...
by holvoetn
Thu Sep 05, 2024 11:36 pm
Forum: Beginner Basics
Topic: LAN to LAN basics
Replies: 21
Views: 2309

Re: LAN to LAN basics

Where's The Hood now ?
by holvoetn
Thu Sep 05, 2024 9:03 pm
Forum: General
Topic: CRS326 wrong interface default-name?
Replies: 1
Views: 316

Re: CRS326 wrong interface default-name?

Where do you see this ? Exactly how did you get this output ? What ROS version ? I have 2 CRS326-24G-2S+ and none show this in the default script. # 2024-09-05 20:00:46 by RouterOS 7.15.1 # software id = J8K8-GJG5 # script: #| Welcome to RouterOS! #| 1) Set a strong router password in the System > U...
by holvoetn
Thu Sep 05, 2024 2:24 pm
Forum: General
Topic: DHCP is offered but not bound to Brother printers only [SOLVED]
Replies: 36
Views: 2198

Re: DHCP is offered but not bound to Brother printers only [SOLVED]

Nothing.

/interface bridge
add admin-mac=48:A9:8A:XX:YY:ZZ auto-mac=no comment=defconf frame-types=admit-only-vlan-tagged name=bridge vlan-filtering=yes
by holvoetn
Thu Sep 05, 2024 2:17 pm
Forum: General
Topic: DHCP is offered but not bound to Brother printers only [SOLVED]
Replies: 36
Views: 2198

Re: DHCP is offered but not bound to Brother printers only [SOLVED]

Once you set a port as trunk default can remain at 1, true, since the setting "Admit only VLAN tagged" overrules that anyhow. Access ports should be set to the pvid for the VLAN they are supposed to handle and "Only admit untagged ...". Nowhere else (besides trunk ports) I have p...
by holvoetn
Thu Sep 05, 2024 1:56 pm
Forum: Beginner Basics
Topic: Why am I unable to connect to SwOS via MAC address using Winbox?
Replies: 1
Views: 368

Re: Why am I unable to connect to SwOS via MAC address using Winbox?

Because SWOS is not ROS.
Winbox is a ROS tool.

You can see it but you can not connect to it using winbox, only using web browser.
by holvoetn
Thu Sep 05, 2024 1:43 pm
Forum: General
Topic: DHCP is offered but not bound to Brother printers only [SOLVED]
Replies: 36
Views: 2198

Re: DHCP is offered but not bound to Brother printers only [SOLVED]

From The unofficial official VLAN bible: https://forum.mikrotik.com/viewtopic.php?t=143620 A word of caution if you are thinking of using VLAN 1 in your network design. Most vendors use VLAN 1 as the native VLAN for their hardware. MikroTik uses VLAN 0. If you try to create a VLAN 1 scenario with Mi...
by holvoetn
Thu Sep 05, 2024 1:04 pm
Forum: General
Topic: lo iface in LAN list
Replies: 11
Views: 636

Re: lo iface in LAN list

And what traffic is being sent via lo ??
Can you use Tools/Torch to see what's going over that interface ?

Best not to add firewall rules without knowing where the traffic comes from or what it is being used for.
by holvoetn
Thu Sep 05, 2024 12:45 pm
Forum: General
Topic: lo iface in LAN list
Replies: 11
Views: 636

Re: lo iface in LAN list

You didn't specify for which device this is but for most there should already be an input accept for 127.0.0.1 from default firewall (for capsman).
That also covers lo.

In case you removed that rule, I suggest you put it back.
by holvoetn
Thu Sep 05, 2024 11:34 am
Forum: General
Topic: DHCP is offered but not bound to Brother printers only [SOLVED]
Replies: 36
Views: 2198

Re: DHCP is offered but not bound to Brother printers only [SOLVED]

Maybe there is a reason why I actively swap out Brother for HP printers with my client :?
(really, I do ...)
by holvoetn
Thu Sep 05, 2024 9:41 am
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 301
Views: 477610

Re: Using RouterOS to VLAN your network

I understand what you're aiming for but it's not that uncommon. I have a router with a CSS610 switch connected via SFP+ at home and still most of my router ports are trunk ports (only 1 access port, the 2.5Gb one for direct connection to my PC in my office and ofcourse the ISP uplink). I am not the ...
by holvoetn
Thu Sep 05, 2024 6:37 am
Forum: General
Topic: DHCP is offered but not bound to Brother printers only [SOLVED]
Replies: 36
Views: 2198

Re: DHCP is offered but not bound to Brother printers only [SOLVED]

Previously, before the guest network and VLAN configuration, printers connected without problems. So WPA3 can't be a problem. And yet ... try it. Plenty of problems with AX wifi which all of a sudden disappear when not using WPA3. If all other devices can connect on the new setting, there is no iss...
by holvoetn
Wed Sep 04, 2024 9:29 pm
Forum: Containers
Topic: VLess proxy tunnel on mikrotik via containers. Topic is solved
Replies: 27
Views: 32799

Re: VLess proxy tunnel on mikrotik via containers. Topic is solved

@user7780
Please use English as most will otherwise not be able to understand what you post.
Also for searching it's a nightmare when other languages are used.
by holvoetn
Wed Sep 04, 2024 9:24 pm
Forum: Beginner Basics
Topic: Help setting up cap AX [SOLVED]
Replies: 14
Views: 1238

Re: Help setting up cap AX [SOLVED]

I'm assuming there are ways to save and backup your good config if I want to test more stuff out? Yes. Binary backup (but can't really be transferred to other device). Simply restore and everything is back as it was. or export with show-sensitive on (not 100% complete export but most should be ther...
by holvoetn
Wed Sep 04, 2024 8:56 pm
Forum: Beginner Basics
Topic: Help setting up cap AX [SOLVED]
Replies: 14
Views: 1238

Re: Help setting up cap AX [SOLVED]

No it is not.
Big difference in usability.
by holvoetn
Wed Sep 04, 2024 4:37 pm
Forum: Wireless Networking
Topic: Slow WiFi [SOLVED]
Replies: 31
Views: 2589

Re: Slow WiFi [SOLVED]

The cAP ac does handle the wifi-qcom-ac pretty well (in my experience), though I red someone having out of memory problems (therefor a daily reboot was introduced). Haven't seen that problem myself (uptime over a couple of weeks). That would be me but that is using 7.16rc package. The issue has bee...
by holvoetn
Wed Sep 04, 2024 4:17 pm
Forum: Beginner Basics
Topic: Help setting up cap AX [SOLVED]
Replies: 14
Views: 1238

Re: Help setting up cap AX [SOLVED]

For better results, maybe disable WPA3, leave WPA2. I have much better experience with WPA2 on ax lineup.
For now, definitely better to skip WPA3, yes.
by holvoetn
Wed Sep 04, 2024 4:12 pm
Forum: Beginner Basics
Topic: Caspman Config [SOLVED]
Replies: 21
Views: 1571

Re: Caspman Config [SOLVED]

I only see config on RB5009.
Where is the config of one of the caps ?
by holvoetn
Wed Sep 04, 2024 3:50 pm
Forum: Beginner Basics
Topic: How communicate between router without involving WAN [SOLVED]
Replies: 7
Views: 895

Re: How communicate between router without involving WAN [SOLVED]

Shouldn't there also be
7. add ether5 on both routers to WAN interface list and remove from LAN (if present)

?
by holvoetn
Wed Sep 04, 2024 1:45 pm
Forum: Announcements
Topic: v7.16rc [testing] is released!
Replies: 362
Views: 112313

Re: v7.16rc [testing] is released!

I'm more into testing and moving forward and I accept consequences of doing so. Most of my client production devices are steady on 7.15.1. I'm not even moving them to 7.15.3 since it's not needed for me. A couple though I use for testing (where I know it doesn't hurt too much) and at home I always u...
by holvoetn
Wed Sep 04, 2024 1:19 pm
Forum: Announcements
Topic: v7.16rc [testing] is released!
Replies: 362
Views: 112313

Re: v7.16rc [testing] is released!

I'm not 100% sure anymore why I moved on to 7.16b/rc channel for that one device. Having been 2 weeks off in between can create that situation :lol: Now I think of it, I also have a wAP AC at home running 7.16rc, (same resources) no crashes there either. I have another AC2 running 7.15.1 and wave2, ...
by holvoetn
Wed Sep 04, 2024 12:01 pm
Forum: Announcements
Topic: v7.16rc [testing] is released!
Replies: 362
Views: 112313

Re: v7.16rc [testing] is released!

There was a possibility that if you use an ARM router with wireless that has 128 MB of RAM and is using wifi-qcom-ac package, not wireless, then simply router could run out of RAM resources causing the router to reboot. One of the reasons why I configured about a month ago a daily auto-reboot on 1 ...
by holvoetn
Wed Sep 04, 2024 11:51 am
Forum: Announcements
Topic: SwOS version 2.17 released!
Replies: 11
Views: 25843

Re: SwOS version 2.17 released!

css610 host mac addresses per vlan? anytime soon?
CSS610 uses SWOS Lite.
by holvoetn
Tue Sep 03, 2024 5:05 pm
Forum: Wireless Networking
Topic: Capsman V3
Replies: 7
Views: 719

Re: Capsman V3

If the provider blocks the tunnel, then the entire office is stuck. ... I just want to manage everything from one place without creating a big point of failure Your most important big point of failure is out of your control, so it seems. Besides, what will still work if the internet line is down ??...
by holvoetn
Tue Sep 03, 2024 4:36 pm
Forum: Beginner Basics
Topic: Caspman Config [SOLVED]
Replies: 21
Views: 1571

Re: Caspman Config [SOLVED]

The most logical answer: something is wrong in your setup. You saw that one coming, right ? :lol: Please post config of capsman controller and one of the caps. Terminal, /export file=anynameyouwish Move to text editor, remove any sensitive info (serial, public IP, passwds, ...) Post back here betwee...
by holvoetn
Tue Sep 03, 2024 4:34 pm
Forum: Wireless Networking
Topic: best way to isolate virtual APs
Replies: 7
Views: 598

Re: best way to isolate virtual APs

Best way: VLANs combined with firewall rules.

The DE FACTO guide around here:
viewtopic.php?t=143620
by holvoetn
Tue Sep 03, 2024 4:33 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 301
Views: 477610

Re: Using RouterOS to VLAN your network

Shouldn't ONLY the sfp1 port in your diagram be purple in color? Apart from the WAN port that is yellow, shouldn't the remaining ports have no color? Based on the legend, the purple port stands for a trunk port on the router; so it doesn't seem to make sense to have so many trunk ports on the route...
by holvoetn
Tue Sep 03, 2024 4:14 pm
Forum: General
Topic: hap ax3 random wireless disconnects
Replies: 107
Views: 9754

Re: hap ax3 random wireless disconnects

And where is the surprise ... ?
After all, it's Microsoft we're referring to here :lol:
by holvoetn
Tue Sep 03, 2024 3:42 pm
Forum: General
Topic: hap ax3 random wireless disconnects
Replies: 107
Views: 9754

Re: hap ax3 random wireless disconnects

I get Intel AX200 driver updates by Windows Update. Why the heck are you downloading drivers manually from Intel's website???? On more then one occasion I noticed Intel drivers where NOT updated by Windows Update. So don't count on it. I also have been chasing wifi issues not too long ago in the pa...
by holvoetn
Tue Sep 03, 2024 3:36 pm
Forum: Wireless Networking
Topic: Capsman V3
Replies: 7
Views: 719

Re: Capsman V3

Same will happen using a fallback capsman controller ... or e.g. DFS channel detection.
You can never guarantee 100% wifi availability.
by holvoetn
Tue Sep 03, 2024 1:39 pm
Forum: Wireless Networking
Topic: Capsman V3
Replies: 7
Views: 719

Re: Capsman V3

At this point - no. Actually, yes. You can use "capsman or local" for the access points manager. If capsman is available, it will be used. If not, AP will revert to local settings (which are can be pretty identical to capsman settings, so rather easy to copy over once). Other then that, a...
by holvoetn
Tue Sep 03, 2024 8:52 am
Forum: General
Topic: netinstall ethernet port of hap ax3?
Replies: 4
Views: 483

Re: netinstall ethernet port of hap ax3?

It's impossible to run V6 on AX3.
You can not go below factory version and for all AX devices that's V7 (here at home I see 7.5 on AX3).

Added argument: wifi drivers needed for AX3 only run on V7.
by holvoetn
Mon Sep 02, 2024 9:01 pm
Forum: Beginner Basics
Topic: capsman stops working after 7.14 upgrade [SOLVED]
Replies: 4
Views: 1904

Re: capsman stops working after 7.14 upgrade [SOLVED]

Simple explanation... As of 7.13 wireless is removed from base package in favor of wave 2 drivers. This IS clearly mentioned in release notes. Not a lot seem to care to read those. If you follow the normal upgrade procedure, this will be handled automatically in background. If you upgrade manually r...
by holvoetn
Mon Sep 02, 2024 3:49 pm
Forum: Containers
Topic: Horrible container performance from 7.14 up to 7.15rc2
Replies: 29
Views: 6823

Re: Horrible container performance from 7.14 up to 7.15rc2

I discovered that using a "normal" USB3-Memory-Stick in a RB5009 slows down the performance massive. When running my project in a chr-environment it is very much faster. Be careful (expecially with RB5009) when using USB3 as storage. For some USB devices it will after reboot come back up ...
by holvoetn
Mon Sep 02, 2024 12:42 pm
Forum: General
Topic: wAPR-2nD LTE - registration denied with new modem QUECTEL EC2004-EU [SOLVED]
Replies: 5
Views: 996

Re: wAPR-2nD LTE - registration denied with new modem QUECTEL EC2004-EU [SOLVED]

The fact your Vodafone SIM is working on both modems, proves there is no HW problem. So there must be a config problem using WINDTRE SIM on the new modem. You can try with latest 7.16rc version, there have been some LTE related improvements in there. If that also doesn't work, best to contact support.
by holvoetn
Sun Sep 01, 2024 10:31 pm
Forum: General
Topic: Route wireguard peers through vxlan
Replies: 12
Views: 1244

Re: Route wireguard peers through vxlan

Contextually similar to this thread ...
viewtopic.php?t=210594
by holvoetn
Sun Sep 01, 2024 5:45 pm
Forum: RouterBOARD hardware
Topic: HAP AC3 vs AX3 Wifi
Replies: 5
Views: 1100

Re: HAP AC3 vs AX3 Wifi

If you use CAPsMAN, the main difference is the datapath config. AC3/2 don't support VLANID from datapath AX3/2 support VLANID from datapath I'm planned to replace all my AC devices with AX for easier config management. Small addition: If you keep using legacy wireless and legacy capsman, vlanid is ...
by holvoetn
Sun Sep 01, 2024 4:35 pm
Forum: General
Topic: Unable to get basic VXLAN tunnel to work over Wireguard
Replies: 5
Views: 610

Re: Unable to get basic VXLAN tunnel to work over Wireguard

Just an observation:
if your aim is to extend L2, why not use EOIP across wireguard ?
Connect both ends of the EOIP interface to their respective bridges and that should be more or less it (be careful with possible loops).
by holvoetn
Sun Sep 01, 2024 2:13 pm
Forum: General
Topic: RBcAPGi-5acD2nD - cpu not running at default frequency [SOLVED]
Replies: 2
Views: 584

Re: RBcAPGi-5acD2nD - cpu not running at default frequency [SOLVED]

Somewhere in earlier versions it was changed that CPU frequency should be set to auto.
Then the message will disappear.
by holvoetn
Fri Aug 16, 2024 7:25 pm
Forum: Beginner Basics
Topic: CAPsMAN through Switch under VLAN [SOLVED]
Replies: 15
Views: 2400

Re: CAPsMAN through Switch under VLAN [SOLVED]

Good job !
by holvoetn
Fri Aug 16, 2024 8:42 am
Forum: Beginner Basics
Topic: Assign ports to passthrough WAN [SOLVED]
Replies: 4
Views: 1104

Re: Assign ports to passthrough WAN [SOLVED]

Move bridge to WAN interface list.
by holvoetn
Thu Aug 15, 2024 7:43 pm
Forum: General
Topic: RB5009UG+S+IN - Rack options
Replies: 2
Views: 501

Re: RB5009UG+S+IN - Rack options

At first sight I would say it can be done since the standard 19" rack mount kit can be adjusted. I took a (rough) measurement on the breaking places on my mounted RB5009 (mounted in a 19" frame) and it comes out at just shy of 25.5 cm, that's 10". If you want to be 100% sure, ask supp...
by holvoetn
Thu Aug 15, 2024 1:39 pm
Forum: Wireless Networking
Topic: Mikrotik or others on AX wifi access point
Replies: 168
Views: 9441

Re: Mikrotik or others on AX wifi access point

It's a good ap (for the installations I use it for) but it's freaking big !!
by holvoetn
Wed Aug 14, 2024 11:35 pm
Forum: Beginner Basics
Topic: Assign ports to passthrough WAN [SOLVED]
Replies: 4
Views: 1104

Re: Assign ports to passthrough WAN [SOLVED]

Easiest might be to create a second bridge and bundle all WAN ports to it (that would be ether1, 4 and 5 in your case).
Move DHCP client from ether1 to the new bridge.
by holvoetn
Wed Aug 14, 2024 11:24 pm
Forum: Scripting
Topic: Script to delete al user active
Replies: 9
Views: 713

Re: Script to delete al user active

@Monster88
Don't post the same question multiple times, please.
I merged the two threads already containing responses and removed one which was still empty.

Carry on ...
by holvoetn
Wed Aug 14, 2024 4:07 pm
Forum: Beginner Basics
Topic: Can't change network
Replies: 11
Views: 825

Re: Can't change network

Again, basic IP (and again new info is being presented ...) /22 netmask starting from 10.0.8.0 results in IP range from 1.0.8.1 to 1.0.11.254 If you want to have 10.0.12.x and above included, you need to change your network topology (multiple subnets) or the netmask (wider range). E.g. /21 will resu...
by holvoetn
Wed Aug 14, 2024 3:00 pm
Forum: Beginner Basics
Topic: Can't change network
Replies: 11
Views: 825

Re: Can't change network

The way Mikrotik DHCP server works, it will assign addresses from its pool top-down. Has nothing to do with the network numbering. It makes no difference if the pool starts bottom-up or is handed out top-down. It doesn't change anything on how an IP network functions. So once again, where is the act...
by holvoetn
Wed Aug 14, 2024 2:47 pm
Forum: Beginner Basics
Topic: Can't change network
Replies: 11
Views: 825

Re: Can't change network

Basic IP

When you define an address using /22, 10.0.8.0 IS the network indicator for an address in the range 10.0.8.1 - 10.0.11.254.
This is 100% correct.

So what's the actual problem you have and why do you think you need to change this ?
by holvoetn
Tue Aug 13, 2024 7:09 pm
Forum: General
Topic: Frequent Crashes After Updates on MikroTik hAP ac3 – Seeking Solutions
Replies: 8
Views: 645

Re: Frequent Crashes After Updates on MikroTik hAP ac3 – Seeking Solutions

My first approach would be to netinstall to latest ROS6. Then import config block by block via terminal, don't restore from backup because you will bring the problems right back in. It's a working assumption for most experienced users here that after upgrade to upgrade to upgrade ... some blobs can ...
by holvoetn
Tue Aug 13, 2024 5:30 pm
Forum: Wireless Networking
Topic: Missing wAP ax successor to wAP ac, what are outdoor AX WiFi alternatives?
Replies: 35
Views: 3630

Re: Missing wAP ax successor to wAP ac, what are outdoor AX WiFi alternatives?

I know it's not relevant right now but wAP AX versions should be coming.
But over half a year it was already said "soon" ...
by holvoetn
Tue Aug 13, 2024 3:51 pm
Forum: General
Topic: Travel router possible?
Replies: 6
Views: 3608

Re: Travel router possible?

Can we use RouterOS and a Mikrotik device to become a travel router, i.e.[/b] - set up a Wireguard client which will route everything through that tunnel - let a laptop connect through ethernet/wifi - can also connect to eg hotel wifi and let other wifi devices connect to the tunnel - drop/block th...
by holvoetn
Tue Aug 13, 2024 2:33 pm
Forum: RouterBOARD hardware
Topic: Load balancer on a RB5009UPr+S+ for 3 connected devices
Replies: 7
Views: 1422

Re: Load balancer on a RB5009UPr+S+ for 3 connected devices

And why would we provide better info then ChatGPT ??
In all seriousness ... :shock:
by holvoetn
Tue Aug 13, 2024 1:13 pm
Forum: RouterBOARD hardware
Topic: hAP ax3 temperature at 58-60 degrees...
Replies: 24
Views: 3302

Re: hAP ax3 temperature at 58-60 degrees...

You can place AX3 in 2 ways. Logically thinking: airflow on AX3 is most optimal when placing it horizontally since all openings are on the large sides. Warm air goes out on top, cooler air gets automatically sucked in on the bottom. If you place it vertically, it will still cool sufficiently, just a...
by holvoetn
Tue Aug 13, 2024 12:42 pm
Forum: General
Topic: ssh connections per minute
Replies: 7
Views: 636

Re: ssh connections per minute

I understand but that's beyond my knowledge level ... I only can tell (from other data projects I work with where each day millions of data lines are retrieved) you should try to get your data as fast as possible, then process it afterwards. Hopefully someone will chime in providing more specific an...
by holvoetn
Tue Aug 13, 2024 11:58 am
Forum: The User Manager
Topic: User manager on CHR
Replies: 10
Views: 1684

Re: User manager on CHR

But a rather powerful home router, wouldn't you say ? 8)
by holvoetn
Tue Aug 13, 2024 11:22 am
Forum: General
Topic: ssh connections per minute
Replies: 7
Views: 636

Re: ssh connections per minute

I'm not sure you're getting my point ...

Instead of setting up 14 SSH connections for retrieving a single value on each connection, set up 1 SSH connection and get all 14 values in one go.
Should be faster.
by holvoetn
Tue Aug 13, 2024 11:04 am
Forum: Beginner Basics
Topic: CAPsMAN through Switch under VLAN [SOLVED]
Replies: 15
Views: 2400

Re: CAPsMAN through Switch under VLAN [SOLVED]

Are you running the CAP's in default CAPS Mode? Are the CAP's connected to a hybrid port (where MGT VLAN is untagged)? Would you be willing to share your config? 1- Starting from default but some changes: 1.1 added mgmt VLAN to bridge 1.2 changed CAPS discovery interface to mgmt VLAN. 1.3 enabled R...
by holvoetn
Tue Aug 13, 2024 10:52 am
Forum: Beginner Basics
Topic: CAPsMAN through Switch under VLAN [SOLVED]
Replies: 15
Views: 2400

Re: CAPsMAN through Switch under VLAN [SOLVED]

Assuming you have...what switch do you use, @holvoetn?
Mikrotik CSS610
by holvoetn
Tue Aug 13, 2024 10:33 am
Forum: Beginner Basics
Topic: CAPsMAN through Switch under VLAN [SOLVED]
Replies: 15
Views: 2400

Re: CAPsMAN through Switch under VLAN [SOLVED]

I have a similar config at home and don't use VLAN1 AT ALL.
My caps look for capsman manager on that specific mgmt VLAN (which is not 1).

If you go VLAN, do it all the way.
Which means don't use VLAN=1 anywhere.
by holvoetn
Tue Aug 13, 2024 10:07 am
Forum: General
Topic: PoE limit to 200mbps
Replies: 30
Views: 2454

Re: PoE limit to 200mbps

Don't test ON the devices themselves. They are not really suited CPU wise to handle that load. Your results will be too low because the local CPU most likely will not follow. You are also testing via your ISP. You don't know what the impact is there. Use 2 PCs within your network, one on each side o...
by holvoetn
Tue Aug 13, 2024 9:24 am
Forum: General
Topic: ssh connections per minute
Replies: 7
Views: 636

Re: ssh connections per minute

Just thinking ...
since your setup is local LAN hence all trusted devices, doesn't it make more sense to use a single connection which remains open instead of setting up the connection each and every time ?
It should be a lot faster.
by holvoetn
Tue Aug 13, 2024 8:19 am
Forum: The User Manager
Topic: User manager on CHR
Replies: 10
Views: 1684

Re: User manager on CHR

AX3 is level6.
So for less then 50% of an L6 license, you get the HW too.
You don't have to use the wifi part.
by holvoetn
Tue Aug 13, 2024 8:17 am
Forum: General
Topic: Zerotier and WireGuard [SOLVED]
Replies: 4
Views: 1586

Re: Zerotier and WireGuard [SOLVED]

As long as it works, it's ok but suboptimal.

You can specify in Zerotier Instance which interface(s) should be used.
If you leave it to all, it tries all. So don't use all if you do not want it to use WG.
by holvoetn
Fri Aug 09, 2024 5:20 pm
Forum: Wireless Networking
Topic: cAP ax, CRS112-8P-4S and CAPsMAN
Replies: 32
Views: 1620

Re: cAP ax, CRS112-8P-4S and CAPsMAN

Clear certificates on controller.

Personally I don't use certificates for capsman.
by holvoetn
Fri Aug 09, 2024 5:03 pm
Forum: Beginner Basics
Topic: Help with VLAN firewall rules and SMB transfer speed.
Replies: 11
Views: 923

Re: Help with VLAN firewall rules and SMB transfer speed.

Rats, I did check on the switch chip support but failed to see it couldn't handle VLAN offloading ... You could leave the default bridge/Vlan path and see if something can be done using switch chip features on that device. Not a standard approach but still possible. See here for some pointers: https...
by holvoetn
Fri Aug 09, 2024 4:41 pm
Forum: Beginner Basics
Topic: LAN to LAN basics
Replies: 21
Views: 2309

Re: LAN to LAN basics

For starters: nice drawing ! A lot of first posters never show something like it. It surely helps to get a better idea of what you want to do. Now that I'm actually getting my hands on it I can understand the various forum / reddit comments "RouterOS is quite powerful but quite difficult"....
by holvoetn
Fri Aug 09, 2024 4:25 pm
Forum: Forwarding Protocols
Topic: Connecting 2 Sites with VPN
Replies: 4
Views: 726

Re: Connecting 2 Sites with VPN

Can you make a small drawing of your setup and what you want to achieve ?
Because I'm not sure I fully understand what you want to do.
High level I get the idea but which building blocks you want to involve where is fuzzy.
by holvoetn
Fri Aug 09, 2024 3:15 pm
Forum: Beginner Basics
Topic: Help with VLAN firewall rules and SMB transfer speed.
Replies: 11
Views: 923

Re: Help with VLAN firewall rules and SMB transfer speed.

About this part: /interface bridge vlan add bridge=BR1 tagged=BR1 vlan-ids=100 add bridge=BR1 tagged=BR1 vlan-ids=200 add bridge=BR1 tagged=BR1 vlan-ids=99 Where are the interface ports being added to their respective VLAN as untagged members ? Shouldn't that be like this (I know, happens auto but I...
by holvoetn
Fri Aug 09, 2024 2:47 pm
Forum: Beginner Basics
Topic: Help with VLAN firewall rules and SMB transfer speed.
Replies: 11
Views: 923

Re: Help with VLAN firewall rules and SMB transfer speed.

I've run into two issues so far: 1. Time sync on windows hosts isn't working. Had to set up NTP client and server on the router and manually configure windows hosts to target the router as their NTP server. 2. During SMB file transfers between VLANs/ports, router CPU usage peaks at 30% and transfer...
by holvoetn
Fri Aug 09, 2024 1:34 pm
Forum: Beginner Basics
Topic: Please check my Config
Replies: 6
Views: 991

Re: Please check my Config

Because your wireguard interface is not accepted. Simple.

2 options:

add a specific rule to accept input via wireguard as interface
or
add wireguard to LAN interface list (most will do this since wireguard is VPN and conceptually, VPN should be the same trust level as LAN).
by holvoetn
Fri Aug 09, 2024 1:31 pm
Forum: General
Topic: EoIP+bridge Over WAN
Replies: 8
Views: 874

Re: EoIP+bridge Over WAN

What's the problem then ?
by holvoetn
Fri Aug 09, 2024 1:30 pm
Forum: Scripting
Topic: LTE Interface run after reset
Replies: 6
Views: 827

Re: LTE Interface run after reset

Try with the wait loop as referenced in the link by jaclaz.
Just checked again, it should wait for max 115 seconds which is just below that hard limit of 2 minutes.
But do put that part as last part of your script (or as far back as possible).
by holvoetn
Fri Aug 09, 2024 11:46 am
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 655
Views: 256185

Re: v7.15.3 [stable] is released!

What can I check ?
Log files as a start.
by holvoetn
Fri Aug 09, 2024 10:16 am
Forum: Beginner Basics
Topic: Please check my Config
Replies: 6
Views: 991

Re: Please check my Config

- In the context of "allow what's allowed, drop all the rest", adding addresses to address list for external parties trying to access your device via certain ports is waste of resources. If' it's not allowed, it get's dropped and be done with it. 6. so i just disable the block traffic fro...
by holvoetn
Fri Aug 09, 2024 9:31 am
Forum: Wireless Networking
Topic: Wi-Fi 2.4G limit 30mpbs
Replies: 17
Views: 1696

Re: Wi-Fi 2.4G limit 30mpbs

Do you have to use wpa on wifi ? It's a rather slow security protocol. Try to avoid if you can and only use wpa2. You still use auto frequency selection. Can be next reboot performance becomes a lot worse. Try to see which frequency is the least used and set your frequency manually. Why do you set n...
by holvoetn
Fri Aug 09, 2024 9:19 am
Forum: Beginner Basics
Topic: CAPsMAN Profile Switching
Replies: 3
Views: 740

Re: CAPsMAN Profile Switching

Putting in CAP mode reconfigures device permanently.
Putting in CAP mode using reset sequence, that is ...
You can also use the mode button to make a script which toggles both modes.
by holvoetn
Fri Aug 09, 2024 8:45 am
Forum: Beginner Basics
Topic: Please check my Config
Replies: 6
Views: 991

Re: Please check my Config

Quick comments: - change WG port. This is the default from Help pages. Not that it will cause any trouble for anyone not knowing public key but better use 2 locks on the door then 1. - why the long lease times on DHCP server ? Just wondering. - Your ZT network ID is exposed in the export. I removed ...
by holvoetn
Thu Aug 08, 2024 11:41 pm
Forum: Wireless Networking
Topic: Need Help for Wireless hat lx lite
Replies: 2
Views: 452

Re: Need Help for Wireless hat lx lite

Remove wireless
Add wifi-qcom
Reset to default.
by holvoetn
Thu Aug 08, 2024 10:40 pm
Forum: Wireless Networking
Topic: cAP ax, CRS112-8P-4S and CAPsMAN
Replies: 32
Views: 1620

Re: cAP ax, CRS112-8P-4S and CAPsMAN

If you use VLAN, your caps need to be able to use that same VLAN to reach CRS/capsman.
by holvoetn
Thu Aug 08, 2024 8:32 pm
Forum: Scripting
Topic: LTE Interface run after reset
Replies: 6
Views: 827

Re: LTE Interface run after reset

Yes !
On a smartphone search is not that easy...
by holvoetn
Thu Aug 08, 2024 8:27 pm
Forum: Scripting
Topic: LTE Interface run after reset
Replies: 6
Views: 827

Re: LTE Interface run after reset

I recently answered a similar post but can't find it back right now. Use fixed delay, can be up to 5 minutes ! Or check defconf script how they do it there. Waiting in a loop until lte itf is detected, then proceed or abort. But this should be the last part of your script since you need to take into...
by holvoetn
Thu Aug 08, 2024 7:02 pm
Forum: Beginner Basics
Topic: SWOS does Not Work [SOLVED]
Replies: 3
Views: 2009

Re: SWOS does Not Work [SOLVED]

Check this thread

No SwOS for CRS310-8G+2S+ ?
viewtopic.php?t=200859
by holvoetn
Thu Aug 08, 2024 6:33 pm
Forum: General
Topic: CAP ax - Admin Password Changes After "Reset in CAPS Mode" ?
Replies: 1
Views: 480

Re: CAP ax - Admin Password Changes After "Reset in CAPS Mode" ?

I set a new admin password, then go to System > Reset Configuration > "Reset in CAPS Mode" And did you also tick 'Keep users' ? If not ... reset to default it is. Quite logical. Be careful with sticker passwd. O, 0 Upper I, lower L Even when MAC address shows striked zero, O can be zero, ...
by holvoetn
Thu Aug 08, 2024 6:14 pm
Forum: RouterBOARD hardware
Topic: hAP ax lite
Replies: 95
Views: 21596

Re: hAP ax lite

just be wary, this is a USB-C 5V port, so it will not work with USB PD adapters, you need most likely a USB-A 5V adapter and A-to-C cable It sounds like this is not actually an USB-C port then and you should make that clear on the product page. All USB PD adapters can provide power to USB-C ports. ...
by holvoetn
Thu Aug 08, 2024 5:16 pm
Forum: General
Topic: Bandwidth limitation for VPN client
Replies: 3
Views: 579

Re: Bandwidth limitation for VPN client

Simple queue based on subnet or address, I would say.

https://help.mikrotik.com/docs/display/ROS/Queues
by holvoetn
Thu Aug 08, 2024 4:55 pm
Forum: Scripting
Topic: Disable the prompt from the terminal. [SOLVED]
Replies: 17
Views: 2277

Re: Disable the prompt from the terminal. [SOLVED]

Ah .. the good old saying

"In /dev/null nobody hears you scream"
by holvoetn
Thu Aug 08, 2024 3:49 pm
Forum: General
Topic: EoIP+bridge Over WAN
Replies: 8
Views: 874

Re: EoIP+bridge Over WAN

I've been kind of trying to avoid using IPSEC as the traffic inside the tunnel is already encrypted.
How ? EOIP on its own doesn't encrypt anything.
by holvoetn
Thu Aug 08, 2024 11:30 am
Forum: Wireless Networking
Topic: cAP ax, CRS112-8P-4S and CAPsMAN
Replies: 32
Views: 1620

Re: cAP ax, CRS112-8P-4S and CAPsMAN

However....in de web interface one cAP has "Wifi" and "Wireguard" greyed out. So there sure seems to be a slight difference. Do you have wifi-qcom package on that device ? It's needed as of 7.13. If it's not present, load that package, let it activate (reboot) and then reset the...
by holvoetn
Thu Aug 08, 2024 11:07 am
Forum: Beginner Basics
Topic: email blocking
Replies: 2
Views: 550

Re: email blocking

Your requirements are not really clear.
Sending mail ?
Receiving mail ?
Sending to ... ?
Receiving from ... ?

And how would you plan to do that with a router ?
Can't be done without specialized gear.

Besides, anyone opening a web browser can send/receive and nothing you can do about it ...
by holvoetn
Thu Aug 08, 2024 8:28 am
Forum: General
Topic: EoIP+bridge Over WAN
Replies: 8
Views: 874

Re: EoIP+bridge Over WAN

For intra-LAN traffic, no need to use anything else then EOIP on its own. When crossing WAN, one should really consider some encryption method. My personal preference is Wireguard since it's easier to setup for me. I have plenty of EOIP connections running over Wireguard using all sorts of devices (...
by holvoetn
Thu Aug 08, 2024 8:13 am
Forum: Beginner Basics
Topic: Bandwidth Test Low Results
Replies: 2
Views: 543

Re: Bandwidth Test Low Results

Good observation :D
by holvoetn
Thu Aug 08, 2024 8:10 am
Forum: Wireless Networking
Topic: Slaves-Static Problem with CAPsMAN VLAN and qcom-ac [SOLVED]
Replies: 15
Views: 2633

Re: Slaves-Static Problem with CAPsMAN VLAN and qcom-ac [SOLVED]

For us, It is either we start replacing the existing MikroTik AC devices with their new outdoor AX units -- which will require ALL new switching infrastructure [no more 802af standard], or we swap out for other vendor. Or wait for true wAP AX which surely will use 802af (like cap AX does). But that...
by holvoetn
Wed Aug 07, 2024 2:08 pm
Forum: RouterBOARD hardware
Topic: MikroTik LHG LTE6 kit + MikroTik R11eL-FG621-EA?
Replies: 2
Views: 563

Re: MikroTik LHG LTE6 kit + MikroTik R11eL-FG621-EA?

Modem is included in this kit.

But ... this model is discontinued (which does not mean it will not work !).
Maybe you should also have a look at LHGG LTE6 kit ?
https://mikrotik.com/product/product_ge ... 3_16_41_07
by holvoetn
Wed Aug 07, 2024 11:19 am
Forum: SwOS
Topic: RB260GS(CSS106-5G-1Sr2) - upgrade failed
Replies: 5
Views: 2018

Re: RB260GS(CSS106-5G-1Sr2) - upgrade filed

Best to contact support, maybe they can provide a solution.
support@mikrotik.com
by holvoetn
Wed Aug 07, 2024 10:36 am
Forum: General
Topic: Winbox: router not detected despite being on the same broadcast domain
Replies: 20
Views: 1354

Re: Winbox: router not detected despite being on the same broadcast domain

Save yourself and anyone else a bit of trouble and post your config ...
I just did. I posted just part of it to save time. If everything looks good. I will look elsewhere.
No, you did not.
Those are extracts from print statements. That's not config.

Use the instructions Larsa linked to.
by holvoetn
Wed Aug 07, 2024 9:13 am
Forum: General
Topic: Winbox: router not detected despite being on the same broadcast domain
Replies: 20
Views: 1354

Re: Winbox: router not detected despite being on the same broadcast domain

Save yourself and anyone else a bit of trouble and post your config ...
You can't learn if you are chasing your own tail.

Worst case (if your really don't want to show your config), reset to default and start over.
Take step by step and see where it stops working. That's where you went wrong then.
by holvoetn
Tue Aug 06, 2024 10:09 pm
Forum: Wireless Networking
Topic: Wireless Wire - Increase Throughput [SOLVED]
Replies: 4
Views: 2188

Re: Wireless Wire - Increase Throughput [SOLVED]

A cable is still easier and more efficient from cost and energy point of view...

You can even run 10Gb/s over cable if you really want.
Try that with wireless :lol:
by holvoetn
Tue Aug 06, 2024 10:08 pm
Forum: Beginner Basics
Topic: Forum has stopped sending email notifications
Replies: 3
Views: 751

Re: Forum has stopped sending email notifications

Already for quite a while...

Go to user control panel, tab subscriptions.
That's how I keep track of responses in subscribed threads now.

Edit: ah wait ... it starts working again ?
For how long ?
by holvoetn
Tue Aug 06, 2024 7:29 pm
Forum: The Dude
Topic: Where to download dude server. [SOLVED]
Replies: 2
Views: 2145

Re: Where to download dude server. [SOLVED]

Check extra packages for the device you want to install it on.
It's in there.
by holvoetn
Tue Aug 06, 2024 7:20 pm
Forum: Containers
Topic: Container usb3?
Replies: 15
Views: 4359

Re: Container usb3?

I already created a sup ticket in the past.
It was acknowledged and supposed to be fixed in a new version but no ETA.
by holvoetn
Tue Aug 06, 2024 6:55 pm
Forum: Wireless Networking
Topic: reliable names for wifi slave interfaces on CAP
Replies: 8
Views: 703

Re: reliable names for wifi slave interfaces on CAP

Use dynamic ports on bridge on cap
They will be added automatically.
by holvoetn
Tue Aug 06, 2024 12:46 pm
Forum: Beginner Basics
Topic: No incoming SMS
Replies: 7
Views: 1409

Re: No incoming SMS

That's a rather important piece of info you failed to mention the first time. You never even mentioned what device you have, which version it currently uses, ... Downgrade then if it worked before and make support ticket with all required info so it can be investigated. I understand you don't want t...
by holvoetn
Tue Aug 06, 2024 10:51 am
Forum: Containers
Topic: Container usb3?
Replies: 15
Views: 4359

Re: Container usb3?

Be aware there is a bug on RB5009 (I see it frequently on my device but haven't seen it yet on AX3) where after reboot USB starts up as USB2, not USB3. Again reboot or performing USB reset fixes that. But if this happens, then your speed will drop dramatically. It will also result in drive to be ren...
by holvoetn
Tue Aug 06, 2024 9:25 am
Forum: Beginner Basics
Topic: No incoming SMS
Replies: 7
Views: 1409

Re: No incoming SMS

Same suggestion as one post above you.
Post your config.
by holvoetn
Tue Aug 06, 2024 8:31 am
Forum: General
Topic: Port forwarding is not working
Replies: 1
Views: 415

Re: Port forwarding is not working

Some questions: - is 165.132.145.101 connected to the same network as your router or is it outside ? (WAN part) If inside, your dst-nat rule only allows incoming via sfp. If that PC is inside your network, it will never use that sfp-connection. - is traffic using port 2222 accepted to be forwarded o...
by holvoetn
Tue Aug 06, 2024 8:21 am
Forum: Wireless Networking
Topic: Capsman hap ax3 provisioning only master-config band and vlan-id to caps? [SOLVED]
Replies: 5
Views: 2168

Re: Capsman hap ax3 provisioning only master-config band and vlan-id to caps? [SOLVED]

Slave config will always follow the physical part of master. That's normal. You can play on slave part with ssid, security, fast transition, ... but not channel nor band, those will be taken from master. As for your second question: https://help.mikrotik.com/docs/display/ROS/WiFi#WiFi-CAPsMAN-CAPVLA...
by holvoetn
Tue Aug 06, 2024 8:12 am
Forum: Wireless Networking
Topic: Capsman Setup with hap ax2
Replies: 5
Views: 646

Re: Capsman Setup with hap ax2

First, use the correct documentation: https://help.mikrotik.com/docs/display/ROS/WiFi#WiFi-CAPsMAN-CAPVLANconfigurationexample: Second: if all your devices (cAP and controller) are AX2, there are no additional packages needed then what's needed to run the device standalone. Attention: packages have ...
by holvoetn
Mon Aug 05, 2024 7:25 pm
Forum: General
Topic: Wireguard clients can connect only after peer restart
Replies: 6
Views: 727

Re: Wireguard clients can connect only after peer restart

Can you please post again latest config as well as the one of 2 peers ?

Mask the keys. Just make sure it's clear where they are supposed to be the same.
by holvoetn
Mon Aug 05, 2024 6:21 pm
Forum: Wireless Networking
Topic: MAC authentication on hap ax3
Replies: 6
Views: 930

Re: MAC authentication on hap ax3

With some clever text manipulation (can even be done in Excel) you should be able to get all the lines populated for upload via terminal.
by holvoetn
Mon Aug 05, 2024 4:17 pm
Forum: Wireless Networking
Topic: MAC authentication on hap ax3
Replies: 6
Views: 930

Re: MAC authentication on hap ax3

It does if you foresee rules for known MAC addresses and then drop for all the rest.
Just like in firewall rules...
by holvoetn
Mon Aug 05, 2024 3:34 pm
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 118392

Re: v7.16beta [testing] is released!

Fixed.
by holvoetn
Mon Aug 05, 2024 11:43 am
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 118392

Re: v7.16beta [testing] is released!

Potential memory leak detected on cAP AC using wifi-qcom-ac drivers, resulting in kernel panic due to out of memory.
Simple AP config, 2 SSIDs, not even using VLANs on that device.

SUP-161244 created.
by holvoetn
Mon Aug 05, 2024 9:01 am
Forum: General
Topic: Wireguard clients can connect only after peer restart
Replies: 6
Views: 727

Re: Wireguard clients can connect only after peer restart

From your two examples:
10.8.0.2/32 and 10.8.0.3/32 respectively.

It's quite well explained in the Wireguard documentation.
https://help.mikrotik.com/docs/display/ ... uardtunnel
by holvoetn
Mon Aug 05, 2024 6:53 am
Forum: General
Topic: Wireguard clients can connect only after peer restart
Replies: 6
Views: 727

Re: Wireguard clients can connect only after peer restart

Is that your "server" config ? I suspect your problem is here: add allowed-address=0.0.0.0/0 If you use that on all peers, your "server" will not know what needs to go where. If one peer is active, there is no confusion. If a second one comes in using the same settings, it's chao...
by holvoetn
Sun Aug 04, 2024 4:24 pm
Forum: Wireless Networking
Topic: no_country_set netbox 5 ax
Replies: 2
Views: 746

Re: no_country_set netbox 5 ax

Not.
You need to select the correct country where you are using your device.
by holvoetn
Sun Aug 04, 2024 4:20 pm
Forum: Wireless Networking
Topic: MAC authentication on hap ax3
Replies: 6
Views: 930

Re: MAC authentication on hap ax3

I would think Access List.
by holvoetn
Sun Aug 04, 2024 3:44 pm
Forum: General
Topic: Increasing security of Mikrotik web page
Replies: 8
Views: 709

Re: Increasing security of Mikrotik web page

ROS 7.0beta3 ??
That's ... over 4 years old ? That version was released 2019-10-22.

Security step 1 already omitted.
by holvoetn
Sun Aug 04, 2024 3:37 pm
Forum: RouterBOARD hardware
Topic: How to intentionally make cable that will negotiate at 10 mbps?
Replies: 16
Views: 1814

Re: How to intentionally make cable that will negotiate at 10 mbps?

A simple mAP might be a cheaper alternative.
Can easily be battery powered too.

It has 2 Fast Ethernet ports and it runs ROS.
You can even be devious and change settings based on assignments/progress using Wifi.
by holvoetn
Sun Aug 04, 2024 2:39 pm
Forum: General
Topic: question about "wireguard responder"
Replies: 13
Views: 1485

Re: question about "wireguard responder"

It does result in a lot less log messages on the server side.
by holvoetn
Sun Aug 04, 2024 12:54 pm
Forum: General
Topic: What are the best practices for securing a MikroTik router from external threats?
Replies: 16
Views: 1461

Re: What are the best practices for securing a MikroTik router from external threats?

Actually, security always comes with some level of inconvenience. It's up to the admin to decide what he/she values most: convenience or security. Accept inconvenience then or get rid of humans ... :shock: we all should be quite aware the human factor (and it's accompanying need for convenience) is ...
by holvoetn
Sun Aug 04, 2024 12:48 pm
Forum: Containers
Topic: how to install debian os on mikrotik container?
Replies: 3
Views: 3913

Re: how to install debian os on mikrotik container?

CHR already runs in VM environment, right ?
Put your Linux right next to it. No need to run it in Docker then.
by holvoetn
Sat Aug 03, 2024 4:53 pm
Forum: General
Topic: Problem with connecting new cap ax to the Capsman
Replies: 19
Views: 2071

Re: Problem with connecting new cap ax to the Capsman

Try removing the channel.frequency parameter from the wifi configuration named cfg5ax . If that does not help, where exactly does My 5G on AX cAP's appears for a few seconds and disappears again happen? On the WiFi tab, on the radios tab, or somewhere else? Most likely DFS frequency gets selected (...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 22