Community discussions

MikroTik App

Search found 283 matches

by holvoetn
Sun Nov 28, 2021 5:46 pm
Forum: RouterOS v7 BETA
Topic: Hotspot and Radius / volume limit doesn't work ?
Replies: 2
Views: 229

Re: Hotspot and Radius / volume limit doesn't work ?

Found it: pool does not have to be set in Hotspot Servers. But ALSO NOT in User profiles. IP is the same now. So that's sorted out. Strange effect of suddenly being cut after disconnect/connect and surpassing limits still present. Again, functionally still ok from my point of view (really don't want...
by holvoetn
Sun Nov 28, 2021 5:08 pm
Forum: RouterOS v7 BETA
Topic: Hotspot and Radius / volume limit doesn't work ?
Replies: 2
Views: 229

Re: Hotspot and Radius / volume limit doesn't work ?

191 views yet zero replies ... Oh well. Took one step back: only config with CAPSMAN and HOTSPOT. Omitted Radius part to simplify and get the basics (and I understood there is a rather low limit on the number of active users when using built-in Radius although 20 might still be more then enough for ...
by holvoetn
Sun Nov 28, 2021 12:31 pm
Forum: Beginner Basics
Topic: What does contry "etsy" mean?
Replies: 3
Views: 223

Re: What does contry "etsy" mean?

ETSI and ANSI
Two quite old standardization organisations...
by holvoetn
Sat Nov 27, 2021 6:36 pm
Forum: RouterOS v7 BETA
Topic: New User Manager in RouterOS v7
Replies: 132
Views: 80173

Re: New User Manager in RouterOS v7

You enabled it on 2 places ?
Hotspot server radius
And User Manager incoming

Out of the top of my head...
Correction:
User manager settings - set to enabled
Radius - Incoming - set to accept
And Hotspot - Server Profiles - Use Radius

So it's 3 places you need to visit.
by holvoetn
Sat Nov 27, 2021 9:48 am
Forum: RouterOS v7 BETA
Topic: New User Manager in RouterOS v7
Replies: 132
Views: 80173

Re: New User Manager in RouterOS v7

You enabled it on 2 places ?
Hotspot server radius
And User Manager incoming

Out of the top of my head...
by holvoetn
Fri Nov 26, 2021 8:00 pm
Forum: Beginner Basics
Topic: Getting a wired printer onto the wireless network
Replies: 8
Views: 419

Re: Getting a wired printer onto the wireless network

Nope.
Out of the top of my head. Start with cpe and then you need to digg into the detailed settings.
Don't go back to quick set once you change stuff there.
by holvoetn
Wed Nov 24, 2021 11:05 pm
Forum: Beginner Basics
Topic: Getting a wired printer onto the wireless network
Replies: 8
Views: 419

Re: Getting a wired printer onto the wireless network

Sorry, i forgot to say i need to silver this with CAP AC;)
Rather overkill solution ...

Mode = Station or station-pseudobridge, I would say. Only 1 device allowed on the eth-link.
by holvoetn
Wed Nov 24, 2021 8:20 pm
Forum: General
Topic: Route loses its gateway everytime it disconnects - v6.49
Replies: 3
Views: 325

Re: Route loses its gateway everytime it disconnects - v6.49

Add a netwatch to monitor the "other side" every couple of minutes or so.
Should keep the connection active.
by holvoetn
Wed Nov 24, 2021 8:17 pm
Forum: Wireless Networking
Topic: CAP Ac Ethernet ports not detected
Replies: 3
Views: 217

Re: CAP Ac Ethernet ports not detected

Already tried connecting computer with Winbox on ethernet 2 ?
Does it emit default WiFi SSID ?
by holvoetn
Wed Nov 24, 2021 6:19 pm
Forum: Beginner Basics
Topic: Getting a wired printer onto the wireless network
Replies: 8
Views: 419

Re: Getting a wired printer onto the wireless network

Even cheaper, mAP Lite.
One less ethernet port (hence also no PoE out) but for the rest identical to mAP yet almost half the price.
by holvoetn
Wed Nov 24, 2021 6:10 pm
Forum: Wireless Networking
Topic: capsman WPS accept
Replies: 3
Views: 217

Re: capsman WPS accept

I understand the practical requirement.

WPS was first invented by Cisco in 2006, I believe ?
Nowadays it's considered one of the FIRST things you need to disable to protect your network.
There is a reason it has been left out of CAPSMAN.
I highly doubt it will ever get in (or back in if it ever was).
by holvoetn
Wed Nov 24, 2021 2:39 pm
Forum: Wireless Networking
Topic: capsman WPS accept
Replies: 3
Views: 217

Re: capsman WPS accept

Personally I never connect a printer using Wifi if wired is possible. It's not reliable, whatever supplier the AP comes from. Almost default I disable everything related to Wifi on printers for another reason: the amount of traffic which get enabled nowadays standard on a printer using wifi is incre...
by holvoetn
Tue Nov 23, 2021 7:52 pm
Forum: Announcements
Topic: v6.49.1 [stable] is released!
Replies: 126
Views: 17065

Re: v6.49.1 [stable] is released!

I think it will check for a combination of things like "the /ip socks facility is enabled", "an SSTP client is configured", "a scheduled job is present" etc. When it matches the pattern for malware, the flag status is enabled. Then it should also be possible to change ...
by holvoetn
Tue Nov 23, 2021 5:43 pm
Forum: RouterOS v7 BETA
Topic: Hotspot and Radius / volume limit doesn't work ?
Replies: 2
Views: 229

Hotspot and Radius / volume limit doesn't work ?

Hi, Config for lab environment: mAP as CAPSMAN, 7.1rc6 mAPLite as CAP, 7.1rc6 Ultimate target is to transfer the setup to a SXT LTE acting as CAPSMAN and 2 CAPs devices for Guest access in a vacation home in France which is for rent part of the year but has limited LTE volume (90Gb per month). mAP i...
by holvoetn
Tue Nov 23, 2021 10:38 am
Forum: Scripting
Topic: "Firmware upgraded successfully..." from script
Replies: 10
Views: 538

Re: "Firmware upgraded successfully..." from script

What's the added value besides the fact you DO have the ability to know that Upgrade+Reboot is needed (or possible instead of needed, depending on who's looking at it) ? Upgrade and Reboot is to be considered here as an entity. I agree it should be possible to have those two as separate status, but ...
by holvoetn
Mon Nov 22, 2021 4:20 pm
Forum: Scripting
Topic: "Firmware upgraded successfully..." from script
Replies: 10
Views: 538

Re: "Firmware upgraded successfully..." from script

Conceptually:
Current-firmware <> upgrade-firmware -> upgrade.

In your example:
6.49 <> 6.49.1, so upgrade would be required.

Given all recent mishaps, is it a good idea to do this automagically ??
by holvoetn
Mon Nov 22, 2021 4:15 pm
Forum: Beginner Basics
Topic: Avoiding double NAT Fritzbox + CCR2004
Replies: 18
Views: 662

Re: Avoiding double NAT Fritzbox + CCR2004

Double NAT is not the problem.

Double port forward.
Once on Fritz towards a dedicated port on CCR.
Then again on CCR towards server.
by holvoetn
Mon Nov 22, 2021 12:17 pm
Forum: Wireless Networking
Topic: mAP lite speed issues
Replies: 16
Views: 1293

Re: mAP lite speed issues

Reading of temperature is not visible ?
But >57C is not normal, no.
by holvoetn
Sun Nov 21, 2021 11:47 pm
Forum: Wireless Networking
Topic: mAP lite speed issues
Replies: 16
Views: 1293

Re: mAP lite speed issues

My map lite does not get any near hot. So I would say that melting the adhesive tape is unusual ROFL
Same here.
Setting up a test environment for something with map as capsman and lite as caps and just clocked 60mbps on that map lite.
by holvoetn
Sat Nov 20, 2021 7:53 pm
Forum: RouterOS v7 BETA
Topic: New User Manager in RouterOS v7
Replies: 132
Views: 80173

Re: New User Manager in RouterOS v7

7.1rc6 Mac Authentication is working fine for me with a ZyXEL XGS1930 Switch however there are no Sessions showing also in the users section I am not showing any Uptime. Anyone else had any issues? Been toying with um on 7.1rc6 and I'm seeing similar issues. No accounting, no data. Hosts does show ...
by holvoetn
Fri Nov 19, 2021 5:10 pm
Forum: Announcements
Topic: v6.49.1 [stable] is released!
Replies: 126
Views: 17065

Re: v6.49.1 [stable] is released!

My "Core" Router CRS326-24S+2Q+ (MIBSBE) will be updated later.....when I´ll get a downtime.
Don't push your luck ... :lol:
by holvoetn
Fri Nov 19, 2021 4:26 pm
Forum: General
Topic: Firewall filter rule ignored?
Replies: 13
Views: 731

Re: Firewall filter rule ignored?

How I understood: Rules are evaluated top to bottom (disregarding jumps for sake of clarity). So it's indeed logical to put the most heavy used ones on top. For personal clarity you can keep the related ones together. Some reordering might be needed though if your device gets to its limits. Raw rule...
by holvoetn
Fri Nov 19, 2021 4:17 pm
Forum: General
Topic: Slow internet when modem connected to mikrotik [SOLVED]
Replies: 11
Views: 687

Re: Slow internet when modem connected to mikrotik [SOLVED]

Oops, I missed your previous replies about the masquerade.
Since you did full reset, can you drop full config again ?
/export hide-sensitive file=anynameyouwish
by holvoetn
Fri Nov 19, 2021 3:44 pm
Forum: General
Topic: Slow internet when modem connected to mikrotik [SOLVED]
Replies: 11
Views: 687

Re: Slow internet when modem connected to mikrotik [SOLVED]

And yet it has to be searched in that domain (I could be wrong but I'd like to be sure). 70M is in the range of what can be reached on a 100M link. The fact you get 700M when directly connected, should then correspond to 1G. And link is to be defined as end to end. The slowest part is what will defi...
by holvoetn
Fri Nov 19, 2021 3:09 pm
Forum: General
Topic: Slow internet when modem connected to mikrotik [SOLVED]
Replies: 11
Views: 687

Re: Slow internet when modem connected to mikrotik [SOLVED]

Speed on your ethernet ports seems to be limited to 100M ? Which eth port you use for connecting Zte ? set [ find default-name=ether1 ] name=ether1-master-IMAX speed=100Mbps set [ find default-name=ether2 ] mac-address=D4:CA:6D:DE:82:0D speed=100Mbps set [ find default-name=ether3 ] mac-address=D4:C...
by holvoetn
Wed Nov 17, 2021 11:37 pm
Forum: Forwarding Protocols
Topic: Best VPN tunnel for SQL connection between 2 offices
Replies: 7
Views: 541

Re: Best VPN tunnel for SQL connection between 2 offices

2 mikrotiks under your own control and wireguard. How more private can you get it ?
by holvoetn
Wed Nov 17, 2021 9:22 pm
Forum: RouterOS v7 BETA
Topic: [bug?]Wireguard does work with same interface with many peers
Replies: 6
Views: 673

Re: [bug?]Wireguard does work with same interface with many peers

Have the peers the same public (peer) key?
Shouldn't be possible to create a second peer with the same public key. An error should be presented.
The jury is still out if THAT behavior is a bug or a feature :lol:
by holvoetn
Wed Nov 17, 2021 9:17 pm
Forum: Forwarding Protocols
Topic: Best VPN tunnel for SQL connection between 2 offices
Replies: 7
Views: 541

Re: Best VPN tunnel for SQL connection between 2 offices

Fastest is Wireguard if a VPN truly is needed. It claims to be 50% faster then OpenVPN. But ... caveat ... only available in ROS7 version which still has not reached release state (however, Wireguard works stable as a rock on ROS7 !) But I would first look into that LTE connection. 10/10 is really n...
by holvoetn
Tue Nov 16, 2021 5:46 pm
Forum: Beginner Basics
Topic: They bruteforce me, how to blacklist ?
Replies: 6
Views: 594

Re: They bruteforce me, how to blacklist ?

Quick search, see this post for reference. https://forum.mikrotik.com/viewtopic.php?t=149256#p734754 Add the IP port being used for PPTP (TCP/1723 ?). Successful logins might also appear on that level 1 list but as long as they are successful, they should never hit level 2. Otherwise play with the t...
by holvoetn
Tue Nov 16, 2021 12:14 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8326

Re: Mikrotik router Hacked!!!

So you can expect this to be implemented, and you will need to keep an administration of the default passwords of all equipment you have in service. Of course you should still change the password to something you only know yourself. But as you indicate, you might need the default password after the...
by holvoetn
Tue Nov 16, 2021 8:18 am
Forum: General
Topic: Static IP not working
Replies: 3
Views: 392

Re: Static IP not working

Dynamic entries are not shown in export. Export and then print of one of my device's addresses. Notice the difference, with print the dynamic entry is shown. With export not. [xyz@mAPLite92] /ip/address> export # nov/16/2021 07:16:56 by RouterOS 7.1rc5 # software id = IFN6-V3SY # # model = RBmAPL-2n...
by holvoetn
Mon Nov 15, 2021 9:30 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8326

Re: Mikrotik router Hacked!!!

Memories of long gone times seeing such clip again ...
by holvoetn
Mon Nov 15, 2021 9:00 pm
Forum: General
Topic: To MT: Keep accounting (v7.x)
Replies: 32
Views: 2244

Re: To MT: Keep accounting (v7.x)

There are tons of inconsistent between WinBox and CLI. Here is one that do irritate me. Add/Edit/Delete a user: Winbox: System->User Cli: /user Why in the world are user in Cli not under /system user ???? Try to find modem settings in CLI for LTE device if under Winbox it's to be found under interf...
by holvoetn
Mon Nov 15, 2021 7:52 pm
Forum: General
Topic: Brute passwords of microtik devices from the local network, how to identify malware?
Replies: 9
Views: 880

Re: Brute passwords of microtik devices from the local network, how to identify malware?

What worries me... with different user accounts.
You got a bug. I think...
by holvoetn
Mon Nov 15, 2021 5:15 pm
Forum: Beginner Basics
Topic: Is Mikrotik hAP lite RB941-2ND classic only for experts?
Replies: 1
Views: 437

Re: Is Mikrotik hAP lite RB941-2ND classic only for experts?

Mikrotik adept since march. There is a STEEP learning curve but once you get the foundation, a whole new world opens if you see what can be done with these things. And it's not needed to learn all at once. Stick to the basics first, gradually add a domain you want to get more acquainted with. E.g. I...
by holvoetn
Mon Nov 15, 2021 5:05 pm
Forum: Beginner Basics
Topic: Connect 2 Mikrotik Router network with Ethernet Cable
Replies: 8
Views: 520

Re: Connect 2 Mikrotik Router network with Ethernet Cable

I was writing a post in more or less the same style.
So yeah, that's how I would do it too.
by holvoetn
Mon Nov 15, 2021 3:16 pm
Forum: General
Topic: Netwatch ISP failover email notification [SOLVED]
Replies: 4
Views: 477

Re: Netwatch ISP failover email notification [SOLVED]

Delay needs to be added BEFORE tool email ...

First wait. Then send.

And simply
:delay 20

No brackets needed.
by holvoetn
Mon Nov 15, 2021 2:02 pm
Forum: General
Topic: Netwatch ISP failover email notification [SOLVED]
Replies: 4
Views: 477

Re: Netwatch ISP failover email notification [SOLVED]

It may indeed be pure logic. If you want to have a delay: hard coded :delay <whatevertimeinsecondsyouwant> Nicer (concept): - wait until a certain URL can be resolved (with timeout to avoid infinite wait) - then send the mail I don't have any examples at hand but there should be some floating around...
by holvoetn
Sun Nov 14, 2021 9:26 pm
Forum: Scripting
Topic: how to reboot the device without using watchdog?
Replies: 2
Views: 391

Re: how to reboot the device without using watchdog?

Just /system reboot, I would think ?

Take into account there can be a lot of reasons why connection is lost, your device might reboot quite often !
by holvoetn
Sun Nov 14, 2021 12:16 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8326

Re: Mikrotik router Hacked!!!

of course not that it will be hacked but just sayin..........
Never say never.
Plenty of people had that same thought.
It would never happen to them, always to others.
by holvoetn
Fri Nov 12, 2021 8:52 pm
Forum: Wireless Networking
Topic: SXT LTE Dual Sim - Auto switching between SIMs?
Replies: 3
Views: 574

Re: SXT LTE Dual Sim - Auto switching between SIMs?

See lte wiki.
There is a whole section on dual sim usage.
by holvoetn
Fri Nov 12, 2021 4:10 pm
Forum: Announcements
Topic: v6.49 [stable] is released!
Replies: 240
Views: 49809

Re: v6.49 [stable] is released!

Disagree.
Even for test devices, use a proper way to track passwords.
Plenty of freeware tools available for that purpose.

Even to prevent accidental usage of such test device in real networks and then leaving the door wide open.
by holvoetn
Fri Nov 12, 2021 9:46 am
Forum: RouterBOARD hardware
Topic: RB3011 Hack
Replies: 3
Views: 756

Re: RB3011 Hack

Exactly.
And do it completely disconnected from the rest of your network.

Only the router, eth cable and a computer with netinstall.
I read somewhere it could sometimes help to put a switch in between if netinstall doesn't find your device after several tries.
Also disconnected from the rest !!
by holvoetn
Fri Nov 12, 2021 9:30 am
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8326

Re: Mikrotik router Hacked!!!

While I do agree it is very troublesome how such a router can be locked, let's not forget the root cause.

Unauthorized admin access into your network.
Nothing Mikrotik can do about that.

Already found the source for that backdoor ?
Or it might sooner or later happen again !
by holvoetn
Thu Nov 11, 2021 10:06 pm
Forum: Wireless Networking
Topic: New provider, cannot send SMS
Replies: 5
Views: 602

Re: New provider, cannot send SMS

Had similar problem when changing from prepaid BE sim to monthly FR sim, also SXT LTE. Home in Belgium I could send SMS. In France roaming I could send SMS. Switched to local FR sim for permanent setup and all of a sudden nada. Turned out I needed to enable that option in my user settings page on th...
by holvoetn
Thu Nov 11, 2021 8:13 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8326

Re: Mikrotik router Hacked!!!

From what I understood. Twice yes.

Houston, we have a probleem.
by holvoetn
Thu Nov 11, 2021 6:28 pm
Forum: General
Topic: Public IP blacklisted by BBC Amazon and Netflix
Replies: 20
Views: 1153

Re: Public IP blacklisted by BBC Amazon and Netflix

Block everything.
Someone is going to complain :lol:
by holvoetn
Thu Nov 11, 2021 5:00 pm
Forum: General
Topic: Public IP blacklisted by BBC Amazon and Netflix
Replies: 20
Views: 1153

Re: Public IP blacklisted by BBC Amazon and Netflix

Conceptual problem...
How can your own IP be blacklisted if you use a VPN ?
Isn't the purpose of a VPN to obfuscate just that ??
by holvoetn
Thu Nov 11, 2021 4:27 pm
Forum: General
Topic: Public IP blacklisted by BBC Amazon and Netflix
Replies: 20
Views: 1153

Re: Public IP blacklisted by BBC Amazon and Netflix

Advise customers to move away from windscribe as its use is blocking access to NETFLIX for all users..... ??? Since when do people care about others especially if they are negatively affected themselves ? Doesn't work that way... My suggestion would also be to block Windscribe. Maybe with some web ...
by holvoetn
Thu Nov 11, 2021 11:59 am
Forum: Beginner Basics
Topic: Just configure mAP Lite as an AP!
Replies: 7
Views: 949

Re: Just configure mAP Lite as an AP!

If you select any config, ethernet will ALWAYS be considered WAN so blocked by firewall.
Best to go via wifi on those devices.

And it will disconnect every time you change something on that wifi.

If you do reset clearing out all config, then eth is the only option.
by holvoetn
Thu Nov 11, 2021 11:01 am
Forum: Wireless Networking
Topic: R11e-LTE6 modem firmware changelog
Replies: 5
Views: 2723

Re: R11e-LTE6 modem firmware changelog

Not that I am aware off. Upgrade is always latest version. Did upgrade yesterday on sxt lte, no problems noticed. No improvements either. But I use it for quite simple purpose, nothing advanced or taxing. Only 3G, max 10mb and I am already happy. ADSL service where that device is used is max 2mb so...
by holvoetn
Wed Nov 10, 2021 8:30 pm
Forum: General
Topic: RBSXTR&R11e-LTE6 disconnects randomly
Replies: 3
Views: 707

Re: RBSXTR&R11e-LTE6 disconnects randomly

V029 seems to be out.

No change log or something alike to be found.
by holvoetn
Mon Nov 08, 2021 1:43 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc6 [development] is released!
Replies: 146
Views: 26720

Re: v7.1rc6 [development] is released!

No container package? Didn't mentioned in the changelog.
Was already removed for 7.1rc5.
Being worked on.

Stick with 7.1rc4 if you need it for now.
by holvoetn
Mon Nov 08, 2021 1:08 pm
Forum: RouterOS v7 BETA
Topic: Defect: Cannot add Wireguard Peers with same key to different WireGuard Interfaces
Replies: 8
Views: 1020

Re: Defect: Cannot add Wireguard Peers with same key to different WireGuard Interfaces

I read the spec yesterday evening again, specifically paying attention to listening port and public key. And it seems you are correct. There is nothing mentioned. Nevertheless, personally I still think it is illogical to have multiple peers using the same key and going to the SAME ip ( and same allo...
by holvoetn
Sun Nov 07, 2021 8:52 pm
Forum: General
Topic: DHCP Relay?
Replies: 5
Views: 498

Re: DHCP Relay?

Or put the Mikrotik as first and only device connected to that router. That port as DHCP client or fixed IP. The rest of the network will then be handled by your Tik and its DHCP server. The first router needs to be able to forward ports if needed for your purposes or put Tik in DMZ. My home config ...
by holvoetn
Sun Nov 07, 2021 8:33 pm
Forum: Beginner Basics
Topic: hAP ac2 wireless connection drops
Replies: 14
Views: 1199

Re: hAP ac2 wireless connection drops

There's only one thing left to think about - how the hell simple tp-link router kept working for days without a problem five years ago? It had detachable antennas and I guess that there were fewer APs around, but anyway... The answer has been given. The second PS. PS I don't know if using a Powerli...
by holvoetn
Sun Nov 07, 2021 10:10 am
Forum: General
Topic: Admin password - CRS125-24G-1S
Replies: 3
Views: 454

Re: Admin password - CRS125-24G-1S

And use a password manager or similar solution for such cases. ( a Post-It on the device or next to your computer is NOT a good alternative ...)
Don't ever assume you will remember.
by holvoetn
Sun Nov 07, 2021 10:02 am
Forum: General
Topic: openVPN pritave key help?
Replies: 4
Views: 516

Re: openVPN pritave key help?

You say you created the ovpn yourself AND it works from command line. That's already a good point. Where is that ovpn file located on your computer ? When you go to windows Ovpn client, there is an option to import. Point it to the location of your working ovpn file. Did you already export the neede...
by holvoetn
Sat Nov 06, 2021 10:10 pm
Forum: RouterOS v7 BETA
Topic: Defect: Cannot add Wireguard Peers with same key to different WireGuard Interfaces
Replies: 8
Views: 1020

Re: Defect: Cannot add Wireguard Peers with same key to different WireGuard Interfaces

Nonono... Each combination ip/port generates a unique public key for the interface. You can on the other side not have multiple peers with the same public key on the same device. That would mean you have multiple peers going to the SAME interface. It does not make sense ! 2 interfaces with same IP b...
by holvoetn
Fri Nov 05, 2021 6:50 pm
Forum: RouterOS v7 BETA
Topic: Defect: Cannot add Wireguard Peers with same key to different WireGuard Interfaces
Replies: 8
Views: 1020

Re: Defect: Cannot add multiple Wirguard Peers on same IP

Just for giggles ... took your config and entered it in a mAP Lite I have lying here without WG configured. Here is the export. # nov/05/2021 17:47:03 by RouterOS 7.1rc5 # software id = IFN6-V3SY # # model = RBmAPL-2nD /interface wireguard add listen-port=13234 mtu=1420 name=Wireguard_Spain_via_UK a...
by holvoetn
Fri Nov 05, 2021 5:15 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8326

Re: Mikrotik router Hacked!!!

There are information about windows malware, that knows how to connect to MT router with default password and make a configuration changes to add it to botnet. So admin: no password to local network are not safe anymore. Well this has to be changed by MikroTik anyway, as it will be forbidden to sel...
by holvoetn
Fri Nov 05, 2021 5:09 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 26059

Re: v7.1rc5 [development] is released!

- MMIPS is not the same as MIPS
- the total size of flash is not the same as the minimal size of a partition (the systems with 16MB flash have some special handling for that)
I know. But why am I able to get into that section and get out some details if it's not applicable ?
Not consistent.
by holvoetn
Fri Nov 05, 2021 4:08 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 26059

Re: v7.1rc5 [development] is released!

https://help.mikrotik.com/docs/display/ROS/Partitions ..... Maybe outdated, hopefully :) Something else wrong there too then (better worded: inconsistent) Minimum partition sizes: 32MB on MIPS 40MB on PowerPC 48MB on TILE But on Hex (which is MMIPS) [xyz@MTHex] /partitions> print detail Flags: A - ...
by holvoetn
Fri Nov 05, 2021 3:52 pm
Forum: General
Topic: trying to write output to Log
Replies: 1
Views: 283

Re: trying to write output to Log

Why would you want to write a complete file to the log ?
Mail seems to be the most correct process IMHO.

Once your mail environment is correctly setup (tool email)
you can use this in script:
/tool e-mail send to="<your-email>" subject="<your subject>" body=$outFile
by holvoetn
Fri Nov 05, 2021 2:12 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 26059

Re: v7.1rc5 [development] is released!

Where can I download the previous version of development channel build? I can't find it on the download archive page. It only have long-term and stable releases.
Copy download link and edit url.
Why would you use previous versions ? Unless it's for Container package ?
by holvoetn
Fri Nov 05, 2021 8:30 am
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8326

Re: Mikrotik router Hacked!!!

So IF he effectively net-installed an infected one, deploy 6.47/6.48/6.49 on it, create strong usernames/password and lockdown services and it STILL gets infected ?! Very strange story and probably we are not getting the full context here... This can only mean (I think) one way or the other the mal...
by holvoetn
Fri Nov 05, 2021 7:49 am
Forum: Scripting
Topic: Is it possible to make script to update domain record everytime when pppoe is connected?
Replies: 9
Views: 795

Re: Is it possible to make script to update domain record everytime when pppoe is connected?

Theoretically
Firewall rule to drop the request going over the "wrong" interface.
Then it will never be received by Ddns service, and then it can not be changed the wrong way.
by holvoetn
Thu Nov 04, 2021 11:09 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8326

Re: Mikrotik router Hacked!!!

I know.
Still learning that part too :lol:
by holvoetn
Thu Nov 04, 2021 10:30 pm
Forum: General
Topic: openVPN pritave key help?
Replies: 4
Views: 516

Re: openVPN pritave key help?

You used these instructions or similar ? https://openvpn.net/cloud-docs/user-imports-received-profile-into-connect-client/ How did you download that file on your computer ? I would think that file is to be found in your Downloads folder if it is a standard Windows installation. Look there when you w...
by holvoetn
Thu Nov 04, 2021 10:06 pm
Forum: Beginner Basics
Topic: Why is my CAPsMAN network not as good as I hope for?
Replies: 25
Views: 2669

Re: Why is my CAPsMAN network not as good as I hope for?

Whatever equipment you put after it, you can always use the Tik.
You just need to figure out which ports to open to where and which direction.

I got my first Mikrotik somewhere around March.
It's amazing what you can do with these things.
So much to learn ...
by holvoetn
Thu Nov 04, 2021 9:00 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8326

Re: Mikrotik router Hacked!!!

Adding an analogy, maybe it will become more clear:

Water is pouring from the tap, sink is spilling over.
What do you do first ?
Clean up the spilled water or close the tap ?

Right now it looks like you're only cleaning... you'll keep doing that until you close the tap.
by holvoetn
Thu Nov 04, 2021 5:52 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8326

Re: Mikrotik router Hacked!!!

A bit harsh but it does boil down to this, yes.

<removed part, anav already said the same>
by holvoetn
Thu Nov 04, 2021 4:31 pm
Forum: General
Topic: Merge 2 ISP bandwidth into one
Replies: 9
Views: 778

Re: Merge 2 ISP bandwidth into one

Thats funny, never seen load balancing for dual wan setups or more, without mangling.
Here is one such example..............

https://mum.mikrotik.com/presentations/US12/steve.pdf
Damn, that was a VERY interesting document !
Thanks for sharing.
by holvoetn
Thu Nov 04, 2021 3:06 pm
Forum: Scripting
Topic: Is it possible to make script to update domain record everytime when pppoe is connected?
Replies: 9
Views: 795

Re: Is it possible to make script to update domain record everytime when pppoe is connected?

Thank you guys! I use Linux so WinBox doesn't work for me. I see DDNS in WebFig, but it seems unable to update whenever pppoe connection is established. Because the ip changes every time. And to be honest, I still prefer my own domain name which is prettier :-P If you're a Linux guy, use terminal :...
by holvoetn
Thu Nov 04, 2021 12:43 pm
Forum: Scripting
Topic: Is it possible to make script to update domain record everytime when pppoe is connected?
Replies: 9
Views: 795

Re: Is it possible to make script to update domain record everytime when pppoe is connected?

Good morning
RouterOS comes with a free DDNS service, maybe easier to use it instead of scripting.

Winbox - IP - Cloud - Enable DDNS. DNS name will become visible on the bottom of that dialog.

Alternative using terminal: /ip cloud set ddns-enabled=yes
Then print and you will see your DDNS name.
by holvoetn
Thu Nov 04, 2021 10:00 am
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 138
Views: 8326

Re: Mikrotik router Hacked!!!

It does look like someone has had (still has ?) access to your device. What I would do: - Block all external access to that device (pull the WAN cable out, sorry for that but it's needed) - remove that script and schedule - review any other script/auto-setting/whatever still available in Files - rev...
by holvoetn
Wed Nov 03, 2021 2:26 pm
Forum: General
Topic: DHCP acting weird
Replies: 10
Views: 692

Re: DHCP acting weird

They are connecting to GUEST and NX MGMT (which as you see is not a VLAN but on a dedicated physical port)
Eth5 -> interface vlan35 -> GUEST
So your wireless (Ubiquity ?) AP devices are set up to work via vlan35 ?

Or am I missing something quite obvious here ?
by holvoetn
Wed Nov 03, 2021 2:15 pm
Forum: General
Topic: 7.0.4 Upgrade Path
Replies: 7
Views: 552

Re: 7.0.4 Upgrade Path

Again, your own choice. For me it runs stable. I have read reports of others having quite some issues with it (in domains I don't use). I could suggest to go for it and see what it gives. Downgrade if needed but I am not sure how that's going to work out with this special 7.0.4 release. Do a search ...
by holvoetn
Wed Nov 03, 2021 1:57 pm
Forum: General
Topic: DHCP acting weird
Replies: 10
Views: 692

Re: DHCP acting weird

What VLAN are your Apple devices connecting to ?
by holvoetn
Wed Nov 03, 2021 1:55 pm
Forum: General
Topic: 7.0.4 Upgrade Path
Replies: 7
Views: 552

Re: 7.0.4 Upgrade Path

If there are no urgent reasons (read: something REALLY does not work), stay on the version you are now. 7.1rc5 is (though indicated RC as in Release Candidate) to be considered beta for some features. I have it on most of my devices and for what I use, there is zero downtime (apart from self-inflict...
by holvoetn
Wed Nov 03, 2021 1:38 pm
Forum: Wireless Networking
Topic: Mikrotik Cap ac setup
Replies: 5
Views: 701

Re: Mikrotik Cap ac setup

As indicated.

3th option: put the cable in ether2, then you may see it again in Winbox.
(I am not 100% sure port2 is default part of LAN but I think it is).
by holvoetn
Wed Nov 03, 2021 1:32 pm
Forum: Beginner Basics
Topic: Trying to setup Wireguard on MikroTik
Replies: 4
Views: 647

Re: Trying to setup Wireguard on MikroTik

(everything Wireguard interests me a lot ...but still a lot to learn) Surely this can not be correct. That's not an address but a subnet ? IP -> Addresses: Address: 10.0.0.0/24 Network: 10.0.0.0 Interface: wireguard1 May be easier to post your config: /export hide-sensitive file=anynameyouwishbecaus...
by holvoetn
Mon Nov 01, 2021 6:02 pm
Forum: Beginner Basics
Topic: system,error,critical login failure for user admin from IP via web
Replies: 13
Views: 1339

Re: system,error,critical login failure for user admin from IP via web

And to make it complete: same error/behavior on 6.49 (cAP ac and Cap), same authentication error for user admin (account which also on those devices is not present) 16:59:59 system,info,account user xyz logged in from 10.255.255.3 via web 17:00:07 system,error,critical login failure for user admin f...
by holvoetn
Mon Nov 01, 2021 5:54 pm
Forum: Beginner Basics
Topic: system,error,critical login failure for user admin from IP via web
Replies: 13
Views: 1339

Re: system,error,critical login failure for user admin from IP via web

Same here. Still learning a ton about Mikrotik stuff. So I do keep an eye on the logs as well from time to time. The issue: reload on webfig page results in authentication error from user admin, EVEN IF that user does not exist !! Really empty login page is shown with account of last user already pr...
by holvoetn
Mon Nov 01, 2021 5:24 pm
Forum: Beginner Basics
Topic: system,error,critical login failure for user admin from IP via web
Replies: 13
Views: 1339

Re: system,error,critical login failure for user admin from IP via web

And we have a winner ... As soon as I hit reload in webfig using F5 (didn't do it before), the faulty log entry appears. Definitely some error on that wegpage ! What is ALSO strange ... the error comes from user admin (I notice it since I have REMOVED admin on my setup. Much safer ...) 16:20:49 syst...
by holvoetn
Mon Nov 01, 2021 4:48 pm
Forum: Beginner Basics
Topic: system,error,critical login failure for user admin from IP via web
Replies: 13
Views: 1339

Re: system,error,critical login failure for user admin from IP via web

I am not saying you're not seeing what you see, I just don't. Logged in and out a couple of times, I don't get what you see. 15:45:15 system,info,account user xyz logged in from 192.168.2.106 via web 15:45:58 system,info,account user xyz logged out from 192.168.2.106 via web 15:46:06 system,info,acc...
by holvoetn
Mon Nov 01, 2021 2:21 pm
Forum: Beginner Basics
Topic: system,error,critical login failure for user admin from IP via web
Replies: 13
Views: 1339

Re: system,error,critical login failure for user admin from IP via web

Hex with 7.1rc5: I'm not seeing this, only user logged in from web Cap Ac with 6.49: Not seeing it there either, same log entry as above (login from web) Must be something local since both show the same behavior for you yet I am not seeing it with the same ROS versions ... already tried a different ...
by holvoetn
Mon Nov 01, 2021 9:52 am
Forum: Scripting
Topic: pptp Api [SOLVED]
Replies: 11
Views: 1036

Re: pptp Api [SOLVED]

(never done any API programming but have programmed in quite some languages in the past, so I can understand most of what I see :) ) Terminal / scripting / API are 3 (related but different) things. For API only /interface/pptp-client/print will work, as in : give you the required info. Check this: h...
by holvoetn
Mon Nov 01, 2021 9:41 am
Forum: Scripting
Topic: pptp Api [SOLVED]
Replies: 11
Views: 1036

Re: pptp Api [SOLVED]

In terminal it will work.
For scripting you need to add "once" since the script will not be able to handle the continuous info coming back.
That's why it only has to run ONCE.
/interface pptp-client monitor 0 once

API is another thing ...
by holvoetn
Mon Nov 01, 2021 9:06 am
Forum: Scripting
Topic: pptp Api [SOLVED]
Replies: 11
Views: 1036

Re: pptp Api [SOLVED]

Which ROS version are you using ? From the message I assume you are running this from a script ? There should also be a number to indicate which entry you want to monitor. E.g. "/interface pptp-client monitor 0", that will show a constant monitoring for that entry. Use "/interface ppt...
by holvoetn
Sun Oct 31, 2021 4:26 pm
Forum: General
Topic: Default username password of ROS 7.1 RC5
Replies: 3
Views: 538

Re: Default username password of ROS 7.1 RC5

From Wiki
A default Customer with login admin and empty password is created when the User Manager package is installed for the first time.
by holvoetn
Sun Oct 31, 2021 12:43 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 26059

Re: v7.1rc5 [development] is released!

I think I am seeing something similar. I have a wireguard interface with two peers defined on it. I seems like only one of them will work at any given time. This setup was fine with rc4 on my rb5009. Currently I created a second interface to handle the second peer, which works for now. Server side,...
by holvoetn
Sun Oct 31, 2021 11:13 am
Forum: Beginner Basics
Topic: add a static IP in the DHCP list? [SOLVED]
Replies: 8
Views: 970

Re: add a static IP in the DHCP list? [SOLVED]

Or use the dynamic lease, make static and then set the desired IP.
Then you don't need to fiddle with the MAC address.
by holvoetn
Sun Oct 31, 2021 9:32 am
Forum: General
Topic: Can a lost IPSEC client cert be recovered?
Replies: 1
Views: 361

Re: Can a lost IPSEC client cert be recovered?

I guess that's the advantage AND disadvantage of these certificates. Very secure but you're so out of luck when you misplace it. Unless you do not have any other way to connect to that device, I'd say it's time to get packing and leave. In the mean time, work on your backups, on DIFFERENT places. An...
by holvoetn
Sun Oct 31, 2021 9:27 am
Forum: RouterOS v7 BETA
Topic: wireguard everything through dyndns
Replies: 19
Views: 1267

Re: wireguard everything through dyndns

Glad you got it sorted out.
by holvoetn
Sun Oct 31, 2021 1:29 am
Forum: RouterOS v7 BETA
Topic: wireguard everything through dyndns
Replies: 19
Views: 1267

Re: wireguard everything through dyndns

Ping the other side of the tunnel's WG-IP address.
I always use that as reference.
by holvoetn
Sun Oct 31, 2021 1:19 am
Forum: Wireless Networking
Topic: SXT LTE Simcard not inserted error
Replies: 6
Views: 645

Re: SXT LTE Simcard not inserted error

If the SIM slot is on the outer limits of the spec (too open) and the SIM itself is on the inner limits (too thin), there will be some space. Space which might result in the contacts not being properly seated on the SIM. Not sure how you are going to fix that reliably with some spray. Even today it'...
by holvoetn
Sun Oct 31, 2021 1:05 am
Forum: RouterOS v7 BETA
Topic: wireguard everything through dyndns
Replies: 19
Views: 1267

Re: wireguard everything through dyndns

I got an SXT LTE setup like that way down in France (though I do not route ALL traffic home). Also mAP and mAP Lite as road warrior devices. Even there, not everything goes home (only towards my local subnet) but that's changed with only one entry :lol: Just wondering ... how did you determine the t...
by holvoetn
Sun Oct 31, 2021 12:12 am
Forum: RouterOS v7 BETA
Topic: wireguard everything through dyndns
Replies: 19
Views: 1267

Re: wireguard everything through dyndns

(I see anav is confused as well) My guess: We're talking about a Mikrotik device here in some sort of road warrior mode ? The MT is mobile and you want it to 'phone home' through wireguard ? For future: use export with hide-sensitive... all your connection info is visible. Couple of remarks from my ...
by holvoetn
Sat Oct 30, 2021 8:23 pm
Forum: Wireless Networking
Topic: SXT LTE Simcard not inserted error
Replies: 6
Views: 645

Re: SXT LTE Simcard not inserted error

I have several hundred of these outdoor units, would like to avoid the tape option. Hoping a gel or spray had been thought of and tested. Why ? that tape trick is already as old as the existence of SIM cards and is still applicable today for some situations. It get's even better, if you make the ta...
by holvoetn
Sat Oct 30, 2021 4:22 pm
Forum: General
Topic: mAP Lite won't netinstall - no BOOTP pkts
Replies: 9
Views: 2459

Re: mAP Lite won't netinstall - no BOOTP pkts

I have another mAP lite which I could netinstall (not sure anymore if I did... will test again this weekend) Finished some testing using mAP and mAP Lite, monitored the interface with Wireshark. With mAP I saw BOOTP packets being send over the ethernet interface. Netinstall however was not picking ...
by holvoetn
Sat Oct 30, 2021 12:00 pm
Forum: General
Topic: mAP Lite won't netinstall - no BOOTP pkts
Replies: 9
Views: 2459

Re: mAP Lite won't netinstall - no BOOTP pkts

My ethernet port works for usual operation, just netinstall is non-functional. Wanted to upgrade to RouterOS 7.1rc5, but it reports " not enough space for upgrade ", thus wanted to netinstall. Odd. Even with a bust eth port I was able to perform the upgrade to 7.1rc3, 4 and 5 over WiFi. S...
by holvoetn
Sat Oct 30, 2021 10:44 am
Forum: RouterBOARD hardware
Topic: Can you load config between routers?
Replies: 4
Views: 950

Re: Can you load config between routers?

It does work between identical units and I have used it in places that have identical primary and secondary units so that there is a cold spare ready if needed. The devices are never identical. MAC addresses are ALWAYS different. So be careful even when moving configs between devices with the same ...
by holvoetn
Sat Oct 30, 2021 10:40 am
Forum: General
Topic: Multi ISP when one down
Replies: 4
Views: 489

Re: Multi ISP when one down

I know its the configuration thus my reason for posting.

Any idea where the issue is.
Unless you SHOW your config, how are we supposed to know ?
Nobody here has a crystal ball...

Terminal: /export hide-sensitive file=<anynameyouwish>
Copy contents of that file between Code quotes.
by holvoetn
Sat Oct 30, 2021 9:00 am
Forum: General
Topic: mAP Lite won't netinstall - no BOOTP pkts
Replies: 9
Views: 2459

Re: mAP Lite won't netinstall - no BOOTP pkts

Same. I'm guessing the ethernet port is bust on mine since factory reset and wifi still works. Ethernet does not. Managed to configure it using wifi only (challenging !!) as road warrior vpn device. Not touching the config on that thing anymore apart from Routeros upgrades to test and adding Wifi ss...
by holvoetn
Sat Oct 30, 2021 8:51 am
Forum: RouterOS v7 BETA
Topic: wireguard everything through dyndns
Replies: 19
Views: 1267

Re: wireguard everything through dyndns

Use dynamic dns service to "fix' the changing ip address on the other side. Use that name as endpoint. You may are may not have that already covered. Then set your 0.0.0.0/0 route for wg to the wg interface itself with a distance lower then the default ( you may have to look for that default to...
by holvoetn
Sat Oct 30, 2021 12:04 am
Forum: Wireless Networking
Topic: wlan1 and wlan2 missing after restore a backup file [SOLVED]
Replies: 7
Views: 937

Re: wlan1 and wlan2 missing after restore a backup file [SOLVED]

Since when does RB5009 have any of wireless hardware?
Basics first...
Beautiful catch.

Big applause !!!
by holvoetn
Fri Oct 29, 2021 8:54 pm
Forum: Wireless Networking
Topic: wlan1 and wlan2 missing after restore a backup file [SOLVED]
Replies: 7
Views: 937

Re: wlan1 and wlan2 missing after restore a backup file [SOLVED]

terminal /system default-configuration print file=defaultsettings Check file defaultsettings.rsc Does that show config for wlan interfaces ? If yes, extract that part for wireless reconfiguration. But that's what should happen when you factory reset (after factory reset, you did NOT continue with &q...
by holvoetn
Fri Oct 29, 2021 8:33 pm
Forum: RouterOS v7 BETA
Topic: wireguard everything through dyndns
Replies: 19
Views: 1267

Re: wireguard everything through dyndns

You may try to describe as much as you want but it will be a lot easier if you open a terminal: /export hide-sensitive file=<anynameyouwish> And then post the contents of that file between Code quotes. A lot easier for anyone to see what your config looks like. PS and yes, most likely there will be ...
by holvoetn
Fri Oct 29, 2021 8:28 pm
Forum: Wireless Networking
Topic: wlan1 and wlan2 missing after restore a backup file [SOLVED]
Replies: 7
Views: 937

Re: wlan1 and wlan2 missing after restore a backup file [SOLVED]

Restoring a config from a device with different HW is usually a bad idea.

Having said that, already tried a simple factory reset ?
It should get you the default config back.
by holvoetn
Fri Oct 29, 2021 7:12 pm
Forum: General
Topic: interface is bandlimited, but I don't know why
Replies: 11
Views: 655

Re: interface is bandlimited, but I don't know why

Not everything is visible in Winbox.
I use terminal and export more and more to catch things like that.
by holvoetn
Fri Oct 29, 2021 5:47 pm
Forum: General
Topic: Brute passwords of microtik devices from the local network, how to identify malware?
Replies: 9
Views: 880

Re: Brute passwords of microtik devices from the local network, how to identify malware?

It seems to be the same IP address each time ? Check log files which MAC received that IP address. Is it always the same device ? My take (others will surely have much better ideas) Check in your IP leases which device has that MAC address. If there is some malware spoofing the IP, it should have a ...
by holvoetn
Fri Oct 29, 2021 4:45 pm
Forum: General
Topic: interface is bandlimited, but I don't know why
Replies: 11
Views: 655

Re: interface is bandlimited, but I don't know why

Isn't it logical if this is set ? bandwidth=5M/10M Why is that parameter even used on any of the interfaces ? It should be bandwidth=unlimited/unlimited. Unless you have a specific reason to limit ?? Wiki: https://wiki.mikrotik.com/wiki/Manual:Interface/Ethernet bandwidth (integer/integer; Default: ...
by holvoetn
Fri Oct 29, 2021 9:13 am
Forum: Wireless Networking
Topic: Disable/enable SSIDs from CAPsMAN (with local forwarding mode)
Replies: 10
Views: 985

Re: Disable/enable SSIDs from CAPsMAN (with local forwarding mode)

Either you manage through capsman, only one place to be but then you can not manage anything locally. Or you manage everything yourself but then it needs to be done on each device separately. If you only have a limited number of APs, you could go for the second option. I read somewhere the rule of t...
by holvoetn
Fri Oct 29, 2021 8:05 am
Forum: RouterBOARD hardware
Topic: mAP lite vs wAP
Replies: 4
Views: 942

Re: mAP lite vs wAP

Logically thinking, yes.
If range is an issue, look for devices with antenna.
You can always try first with map lite, it doesn't cost much.
by holvoetn
Fri Oct 29, 2021 6:46 am
Forum: RouterOS v7 BETA
Topic: Wireguard use Hostname in endpoint
Replies: 8
Views: 2116

Re: Wireguard use Hostname in endpoint

can you please share your "small netwatch script" ? :D Sure. Very basic but does what it needs to do. 10.255.255.1 is the IP of the "server". When that's not visible, WG is down or not active yet. And I know I shouldn't use peer numbers but there is only 1 peer on that device. C...
by holvoetn
Thu Oct 28, 2021 9:20 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 26059

Re: v7.1rc5 [development] is released!

*) leds - adjust "system-led" color based on cellular connection technology on Chateau devices;
*) wireless - adjusted antenna gain on Chateau devices;
Do I need to write support, to get additional context to these changes?
That or waiting for documentation to get updated.
by holvoetn
Thu Oct 28, 2021 9:20 am
Forum: General
Topic: router send data to Mikrotik?
Replies: 11
Views: 740

Re: router send data to Mikrotik?

Detect Internet enabled? https://help.mikrotik.com/docs/display/ROS/Detect+Internet Very good catch ! Internet WAN interfaces that can reach cloud.mikrotik.com using UDP protocol port 30000 can obtain this state. Reachability is checked every minute. If a cloud is not reached for 3 minutes, the sta...
by holvoetn
Thu Oct 28, 2021 9:18 am
Forum: Beginner Basics
Topic: Bandwidth Test Question
Replies: 4
Views: 590

Re: Bandwidth Test Question

Adding to previous answers: have a look at this project. Requires one additional device on your network (or you can run it in some Docker, I suppose). Raspberry PI (or alike) monitoring all traffic on your network and providing bandwidth info. Might be some good starting point ? https://www.technica...
by holvoetn
Thu Oct 28, 2021 8:45 am
Forum: Scripting
Topic: Auto speed test for multi VPN
Replies: 10
Views: 1499

Re: Auto speed test for multi VPN

Don't underestimate the impact from testing those tunnels each half hour. If you're on a volume-limited line, it eats away of your available volume ! And the fact that during switch-over, you WILL loose your connection for whatever you are running. What actually is missing here: what are you trying ...
by holvoetn
Wed Oct 27, 2021 11:36 pm
Forum: Scripting
Topic: Auto speed test for multi VPN
Replies: 10
Views: 1499

Re: Auto speed test for multi VPN

Ping to the other end of the VPNs
If it succeeds, the tunnels are up.
Choose the fastest respons.
by holvoetn
Wed Oct 27, 2021 7:28 pm
Forum: Wireless Networking
Topic: mAP lite speed issues
Replies: 16
Views: 1293

Re: mAP lite speed issues

As requested, please post config.

I have a mAP lite lying as test on my desk and can get 50Mb without issues next to it.
Even 2 THICK walls and 8m further, I still get over 10Mb.

Keep in mind though, these things are effectively intended for close range use.
by holvoetn
Wed Oct 27, 2021 4:43 pm
Forum: General
Topic: router send data to Mikrotik?
Replies: 11
Views: 740

Re: router send data to Mikrotik?

Really strange then. If it really is such a problem: add firewall rule to drop everything going to that IP address (and log for later inspection) and see what stops working. Maybe someone else can give better ideas to determine what's causing this but I don't see any other way. Other option: drop yo...
by holvoetn
Wed Oct 27, 2021 2:01 pm
Forum: General
Topic: router send data to Mikrotik?
Replies: 11
Views: 740

Re: router send data to Mikrotik?

Should be with a script.
by holvoetn
Wed Oct 27, 2021 1:21 pm
Forum: General
Topic: router send data to Mikrotik?
Replies: 11
Views: 740

Re: router send data to Mikrotik?

Have you automatic check for updates activated ? That would also be a valid reason.

EDIT: just checked. When I manually go checking for updates, I see in that same range address 159.148.147.204 appearing in the connections list.
So it could be something as simple as that.
by holvoetn
Tue Oct 26, 2021 9:40 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 26059

Re: v7.1rc5 [development] is released!

Are you sure you want to upgrade a device so far away from you? 😁 Normally I would not but this time risk is low. I'll be on site 2 weeks from now and apart from some tenants next week who never had it before, nobody uses that internet access for now. So next week power will be on again and then it...
by holvoetn
Tue Oct 26, 2021 9:37 pm
Forum: General
Topic: Netinstall
Replies: 1
Views: 269

Re: Netinstall

Check this thread:
viewtopic.php?t=139614

Pay attention to info in posts 7, 11 and definitely 15.
by holvoetn
Tue Oct 26, 2021 9:08 pm
Forum: Announcements
Topic: WinBox v3.31 released!
Replies: 61
Views: 31278

Re: WinBox v3.31 released!

Hi I have winbox 3.31 when I plug into my RB5009 on the first port, nothing happend..I must plug into port 3 and its ok...But previous I had on port 1. Is there any special port on winbox? Because I don't know, how to logg into routerboard from another port.. Thanks For most Routerboard devices por...
by holvoetn
Tue Oct 26, 2021 9:00 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 26059

Re: v7.1rc5 [development] is released!

Upgraded 2 mAP Lites, 1 mAP and 1 Hex (all from 7.1rc4), no issues whatsoever. 1 SXT LTE still to do but someone 930km further South switched off the power for that device :? In rc4 and before the Wireguard interface was selectable as a bridge port - you could add it as a port on bridge, but it woul...
by holvoetn
Tue Oct 26, 2021 4:46 pm
Forum: Beginner Basics
Topic: Recording changes to the config to a log
Replies: 5
Views: 589

Re: Recording changes to the config to a log

And Safe mode.
If some setting causes things to break, it will be noticeable rather fast (usually at the same time as the "Oops"-moment).

Safe mode will then revert things back on its own.
by holvoetn
Tue Oct 26, 2021 2:16 pm
Forum: RouterOS v7 BETA
Topic: Looking for Docker container ideas for RouterOS
Replies: 5
Views: 944

Re: Looking for Docker container ideas for RouterOS

Agree with mkx. Most RouterBoards are not suited for this purpose because of RAM, storage (some boards don't even allow external storage), processing power. Which does not mean it can not be done. But it's not because something can be done, it might not be better done using something else. Looking a...
by holvoetn
Tue Oct 26, 2021 12:20 pm
Forum: Announcements
Topic: v6.49 [stable] is released!
Replies: 240
Views: 49809

Re: v6.49 [stable] is released!

It may be a good idea to turn off auto-upgrade until this mystery has been solved. For anything business-critical, it's always a good idea whatever equipment or supplier. Just as with Windows Updates. No way these get rolled in without some weeks passing by. Urgent security upgrades being the only ...
by holvoetn
Mon Oct 25, 2021 8:33 pm
Forum: General
Topic: How do I combine the speed of 4 ADSL lines into one?
Replies: 13
Views: 784

Re: How do I combine the speed of 4 ADSL lines into one?

Adding to this... if you have one connection which would require 5Mb, you're already stuck. You can saturate 1 stream of 4Mb but not beyond since that connection can not be cut in pieces. If however you have 4 connections of (let's say) 3Mb, you can send them each onto one line, that should theoreti...
by holvoetn
Sun Oct 24, 2021 5:47 pm
Forum: Beginner Basics
Topic: How do I uninstall unneeded packages [SOLVED]
Replies: 4
Views: 807

Re: How do I uninstall unneeded packages [SOLVED]

I noticed there's a package called "iot". What is this mused for?
iot = Internet Of Things
Most likely to interact with these devices or alike: https://mikrotik.com/products/group/iot-products
by holvoetn
Sat Oct 23, 2021 7:58 pm
Forum: General
Topic: Start time switch/bridge -Hap AC Lite
Replies: 2
Views: 359

Re: Start time switch/bridge -Hap AC Lite

Every device startup time can be different.
I have e.g. a mAP Lite which boots in 15 seconds.
Not sure when the bridge comes active though ...

Logically thinking during those first seconds nothing will happen putting your system at risk.
Or is that not your concern ?
by holvoetn
Sat Oct 23, 2021 10:10 am
Forum: General
Topic: Will NATted wireguard work?
Replies: 22
Views: 1831

Re: Will NATted wireguard work?

I dare to say that conclusion is pretty premature. Some important info is missing which you are not showing and unless I missed it, you have not provided that information, not even after having been requested to do so multiple times. It was requested first here by anav: Please draw a network diagram...
by holvoetn
Fri Oct 22, 2021 6:32 pm
Forum: General
Topic: Will NATted wireguard work?
Replies: 22
Views: 1831

Re: Will NATted wireguard work?

Sweet ! Totally overlooked that section.
by holvoetn
Fri Oct 22, 2021 6:08 pm
Forum: General
Topic: Will NATted wireguard work?
Replies: 22
Views: 1831

Re: Will NATted wireguard work?

Assuming you're talking about a smartphone as remote client, this is what I have: Endpoint: Internal IP address of the client device since the external IP makes no sense, it's dynamic. In my case 10.255.255.6 Endpoint port: the UDP port your itf listens to but this is open for discussion whether thi...
by holvoetn
Fri Oct 22, 2021 3:58 pm
Forum: General
Topic: Possible to request LAN IP, through DHCP client ?
Replies: 4
Views: 468

Re: Possible to request LAN IP, through DHCP client ?

@mkx
Thanks for the added clarity and corrections.
This way I can also (re)learn things. Wasn't aware anymore of the ARP-process (has been too long since I learned OSI-model and related stuff ... that's over 30 years away)
by holvoetn
Fri Oct 22, 2021 3:54 pm
Forum: General
Topic: Will NATted wireguard work?
Replies: 22
Views: 1831

Re: Will NATted wireguard work?

From your screenshots in your very first post I see you did not specify an endpoint address nor port for the WG peer on "server". I know there is still some discussion ongoing about the need for that but can you fill in IP of endpoint and the required port ? The allowed address for the pee...
by holvoetn
Fri Oct 22, 2021 1:40 pm
Forum: Beginner Basics
Topic: Trouble logging into MikroTik hAP ac² (that has been reset to factory defaults)
Replies: 2
Views: 469

Re: Trouble logging into MikroTik hAP ac² (that has been reset to factory defaults)

How do you make connection to the device ?
Ethernet (which port, don't use eth1) or Wifi ?
What IP address does your PC get when connected ?

Those can also be indications if factory reset was applied or not.
Already tried the previous credentials too ?

Netinstall is the final option but should work.
by holvoetn
Fri Oct 22, 2021 1:31 pm
Forum: Wireless Networking
Topic: [SXT LTE6] Explain to me this PoE mystery
Replies: 6
Views: 865

Re: [SXT LTE6] Explain to me this PoE mystery

I have an SXT LTE device powered by a TP-Link TL-SG105PE. It can provide a bit more power then your Dlink device from what I see. That same switch also powers a cAP AC and cAP Lite. No power injector or whatsoever needed with 20m cable as longest. Maybe stating the obvious but are you sure you plugg...
by holvoetn
Fri Oct 22, 2021 1:08 pm
Forum: Wireless Networking
Topic: Disable/enable SSIDs from CAPsMAN (with local forwarding mode)
Replies: 10
Views: 985

Re: Disable/enable SSIDs from CAPsMAN (with local forwarding mode)

Interface configuration can indeed not be enabled/disabled. Provisioning rule however can be. If you can make a separate provisioning rule for that specific need, it should be possible to toggle its status. I am not a fan of deleting but that's me. A disabled rule tells you a lot more then something...
by holvoetn
Fri Oct 22, 2021 9:30 am
Forum: General
Topic: Possible to request LAN IP, through DHCP client ?
Replies: 4
Views: 468

Re: Possible to request LAN IP, through DHCP client ?

Unclear what you are trying to achieve... Anyhow, when a client requests a lease from the DHCP server, 2 possibilities in most cases: 1- no fixed assignment - a free IP from the pool is taken and given back to the device to use 2- fixed assignment on the DHCP server matching the clients MAC address ...
by holvoetn
Fri Oct 22, 2021 8:52 am
Forum: Beginner Basics
Topic: Purple lines on traffic graph
Replies: 2
Views: 499

Re: Purple lines on traffic graph

I suspect that it is red and blue mixing to give purple.

So Tx and Rx at the same time give purple.
Exactly that.
by holvoetn
Thu Oct 21, 2021 11:10 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 46240

Re: v7.1rc4 [development] is released!

I am sick of "netinstall resolves it". It is like "format c:/" on old windows 98/xp systems.
Format c: gave usually an "oops" moment...
by holvoetn
Thu Oct 21, 2021 9:31 pm
Forum: Beginner Basics
Topic: WLAN Password WAP-R [SOLVED]
Replies: 5
Views: 784

Re: WLAN Password WAP-R [SOLVED]

Life can be simple :lol:
by holvoetn
Thu Oct 21, 2021 8:35 pm
Forum: Beginner Basics
Topic: WLAN Password WAP-R [SOLVED]
Replies: 5
Views: 784

Re: WLAN Password WAP-R [SOLVED]

You missed some parts of the screenshots anav provided.

Tab Security profiles - select default
Authentication types: only WPA2 PSK
And fill in a password in the field which says "WPA2 pre-shared key"
by holvoetn
Thu Oct 21, 2021 3:14 pm
Forum: RouterOS v7 BETA
Topic: wAPac-wAPac WDS forwarding stops after some time
Replies: 5
Views: 1352

Re: wAPac-wAPac WDS forwarding stops after some time

Send all required info to support@mikrotik.com.
Ticket will be created and if it something trivial (or already fixed ?), you may get a temp version to try out.

See How to report issues in v7 beta
viewtopic.php?t=152006
by holvoetn
Thu Oct 21, 2021 3:10 pm
Forum: RouterOS v7 BETA
Topic: OSPF entry added automagically after upgrade
Replies: 3
Views: 721

Re: OSPF entry added automagically after upgrade

I understand what you are saying but: - I still have some ROS6-devices running with a customer and they effectively show a default area and backbone in OSPF settings. So that part makes perfect sense. - All the mentioned devices from above were upgraded from 6.x to 7beta to 7.1rc etc etc.. So if I f...
by holvoetn
Thu Oct 21, 2021 12:35 pm
Forum: RouterOS v7 BETA
Topic: OSPF entry added automagically after upgrade
Replies: 3
Views: 721

OSPF entry added automagically after upgrade

Just as an info in case someone else sees this happening: SXT LTE after upgrade from 7.1rc2 to rc4, all of a sudden an OSPF entry was added, an entry which made the device do something (and fail, probably because of huge incomplete setup). I only noticed this week when reviewing the log files on tha...
by holvoetn
Thu Oct 21, 2021 11:05 am
Forum: Beginner Basics
Topic: L2TP over modem
Replies: 2
Views: 441

Re: L2TP over modem

Reverse your VPN or see if you can have a pivot point with fixed IP (Other Mikrotik router with fixed IP, public VPN service, ... ?). I've had to do this as well when I made an L2TP connection between a CGNAT SXT LTE device and my home Hex. Later switched to SSTP and moved on now to Wireguard (less ...
by holvoetn
Thu Oct 21, 2021 9:39 am
Forum: Beginner Basics
Topic: Block access to a printer
Replies: 2
Views: 481

Re: Block access to a printer

Most logical way would be security group in Active Directory so only THAT person can see that printer. Alternative (depending on printer): security on the printer itself ? If it has to be done in Mikrotik, how I would do it: Since you know the user MAC address - assign a fixed IP And then it's only ...
by holvoetn
Thu Oct 21, 2021 6:44 am
Forum: General
Topic: VPN access via ISP router
Replies: 1
Views: 308

Re: VPN access via ISP router

Being behind an ISP router is not an issue provided the required channels are free to be used. Which VPN protocol do you plan to use ? Is the required port opened in your Miktrotik firewall ? Are you sure ? Did you test ? If not, you can not pass a closed door ... It could help to export your config...
by holvoetn
Wed Oct 20, 2021 7:39 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

Yeah !!

<High Five to anav and sindy!>
by holvoetn
Tue Oct 19, 2021 10:58 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

1) Winbox - interfaces - there is a button "detect Internet". Open it and set everything to none.
2) Winbox - IP - DHCP-server - tab DHCP. Most likely there is a grayed line. Select it and make it active (blue tick mark on top)
by holvoetn
Tue Oct 19, 2021 10:45 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

In the last export, there is disabled=yes on the /ip dhcp-server row. Change that to disable=no . And do not attempt to attach a dhcp client to the LTE interface, it is not necessary. Good catch on the DHCP-server ! Re: dhcp-client: I do agree it is not needed normally (it's not needed on my SXT LT...
by holvoetn
Tue Oct 19, 2021 10:39 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

DHCP-client seems to be missing again on lte1 interface ?
Can you check /ip addresses print ?
by holvoetn
Tue Oct 19, 2021 10:36 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

BTW LOOOVE the way you simply copy-paste the names for the exports :lol:
by holvoetn
Tue Oct 19, 2021 10:32 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

Wild idea (it has caused me some troubles already in the past as well, it just popped in): what is the current time on your device ? How off is it from the real time ? Because I do not see any setting on your device which would sync time with whatever. And if the time difference is too much, I have ...
by holvoetn
Tue Oct 19, 2021 10:14 pm
Forum: General
Topic: Blocking Blogspot.com ? [SOLVED]
Replies: 17
Views: 976

Re: Blocking Blogspot.com ? [SOLVED]

I have it as a docker container on a Synology NAS. It has not too much processor impact, from what I can see. Well, keep it running on your NAS ? This is how I run it over here, Pihole on my 918+ NAS and running fine for years now. DNS-traffic on the Mikrotik is intercepted and delivered to the Pih...
by holvoetn
Tue Oct 19, 2021 10:10 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

Okok, how should I proceed now? Is there any solution to the problem at all :(
Final export with all latest settings please.
/export verbose hide-sensitive file=youknowthedrill
by holvoetn
Tue Oct 19, 2021 9:45 pm
Forum: General
Topic: Blocking Blogspot.com ? [SOLVED]
Replies: 17
Views: 976

Re: Blocking Blogspot.com ? [SOLVED]

I read layer 7 filtering can be indeed quite performance hungry.

Wild question ...
Would PiHole running in a docker container on ROS 7.1rc4 be less of a performance hit ?
I have it as a docker container on a Synology NAS. It has not too much processor impact, from what I can see.
by holvoetn
Tue Oct 19, 2021 9:15 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

There has to be something rather stupid preventing DHCP from handing out IP leases ...
It's the only thing missing.
by holvoetn
Tue Oct 19, 2021 8:51 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

I hope you changed that MAC address yourself and it was not set like that ?
Still no IP address on PC ?
by holvoetn
Tue Oct 19, 2021 7:50 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

/interface bridge print please ? I am comparing your latest export with my config and your bridge looks REALLY simple. Too simple. Your config: /interface bridge add name=bridge Mine (I removed MAC address): /interface bridge add admin-mac=XX:XX:XX:XX:XX:XX ageing-time=5m arp=enabled arp-timeout=aut...
by holvoetn
Tue Oct 19, 2021 6:51 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

Oh and please:
/ip dns
set allow-remote-requests=yes

Set to no !
by holvoetn
Tue Oct 19, 2021 6:44 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

No, not yet. The circuit board is permanently installed and I didn't want to remove the circuit board separately. Can I configure the whole system without the circuit board? Sure you can do it without the circuit board connected. It was just a question to be sure the ethernet client does not get a ...
by holvoetn
Tue Oct 19, 2021 6:36 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

Unfortunately, this is the only solution for the circuit board ... No problem. I assume you will have looked into your options. I am connected to the router via wifi, otherwise I cannot control it via Winbox. Or am I wrong? Also here, no problem but I still don't get why your PC is not getting an I...
by holvoetn
Tue Oct 19, 2021 6:11 pm
Forum: General
Topic: Allow WinBox broadcast on WAN interface
Replies: 6
Views: 460

Re: Allow WinBox broadcast on WAN interface

I guess @OP is trying to get MNDP working on WAN interface. Which is IMO very stupid idea, but @OP might have a valid reason for doing it (e.g. in block of flats, every flat has its own MT router managed by landlord via WAN interface). Actually it's something like this. The WAN interfaces of severa...
by holvoetn
Tue Oct 19, 2021 6:06 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 46240

Re: v7.1rc4 [development] is released!

So, is the download server for dev release down? Trying to update a RB 850Gx2 (PPC) with the dev release, but winbox keeps saying "calculating download size" and hangs on that. While trying any other package option (long-term, stable, testing) they all download fluently. Something I'm mis...
by holvoetn
Tue Oct 19, 2021 5:54 pm
Forum: Beginner Basics
Topic: Help for a beginner
Replies: 5
Views: 574

Re: Help for a beginner

Considering the circumstances, how would I reset it? I don’t have mikrotik hardware if that changes anything.
What device or environment are we talking here ?
by holvoetn
Tue Oct 19, 2021 3:52 pm
Forum: General
Topic: Blocking Blogspot.com ? [SOLVED]
Replies: 17
Views: 976

Re: Blocking Blogspot.com ? [SOLVED]

Hello. I would like to block the users in my networks from accessing their private blogs in blogspot.com, since it turns out they are most of time spending there, and this angry the boss quite a bit. Anyway I've tried the solution by adding blogspot.com to the address list, and then drop the traffi...
by holvoetn
Tue Oct 19, 2021 2:22 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

Also this is an interface, so try to add either lte apn to the wan interface as a member and eplus /interface l te apn set [ find default=yes ] apn=internet.eplus.de authentication=pap name= eplus \ user=eplus Can either be added below as a WAN member ( I know you tried eplus before but give it ano...
by holvoetn
Tue Oct 19, 2021 2:16 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

What confuses me is that the lTE seems to have a 10. xx address, the LAN is on 192.168.x.x BUt the PC gets 169.254 ??? Regardless of the WAN situation the PC should simply get a proper LANIP from the router??? Makes perfect sense if the PC does not get a DHCP lease. Then Windows will default to 169...
by holvoetn
Tue Oct 19, 2021 2:14 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

@to55603 Your last statement I sort of disagree. I also have a solar panel tracking system at home and it's nicely connected to my Wifi-network. Just had to make sure to give it a fixed IP to be sure, that's all (open dynamic lease and make it static, as easy as that). But could be your tracking sys...
by holvoetn
Tue Oct 19, 2021 12:49 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

Strange, DHCP client on lte-interface is gone again ?? You did a reboot after the firmware upgrade ? That DHPC setting has clearly not been saved ... hmmm ... First reaction would be to do again: /ip dhcp-client add default-route-distance=5 disabled=no interface=lte1 See if IP address comes in on lt...
by holvoetn
Tue Oct 19, 2021 12:13 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

Can you export your latest config again please ?
We're getting close.
by holvoetn
Tue Oct 19, 2021 12:13 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

Other remark: from that lte info lte1 once dump I see you're still on firmware V015. Could be there is already a newer firmware available. Check if new firmware is available for your device /interface lte firmware-upgrade lte1 If so: /interface lte firmware-upgrade lte1 upgrade=yes And after success...
by holvoetn
Tue Oct 19, 2021 12:09 pm
Forum: Beginner Basics
Topic: Help for a beginner
Replies: 5
Views: 574

Re: Help for a beginner

Winbox MAC access might still work but I doubt it if all interfaces are REALLY disabled (why on Earth would you do that ???). Factory reset would be my first choice then as well. Netinstall is too much of a hassle and yields the same result. And hopefully you saved your config prior to making that d...
by holvoetn
Tue Oct 19, 2021 12:03 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

Now we're talking !

You have a PC connected to LAN ? Does it get an IP address from WAP-R ?
Can it access internet ?
by holvoetn
Tue Oct 19, 2021 11:50 am
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

Aha !
An IP address on LTE1 interface !!

What does /ip route show now ?
by holvoetn
Tue Oct 19, 2021 9:49 am
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

I still find it mighty strange there is no IP address for the lte interface, no default route, nada ... From terminal, what does this give ? /interface lte print and /interface lte info lte1 once There is also no DHCP client. But it shouldn't be, that should come automatically. However ... can you t...
by holvoetn
Mon Oct 18, 2021 11:04 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

Maybe basics first...
Does that SIM card work in another device ?
Because it should give an IP address on successful connection and I do not see it coming.
by holvoetn
Mon Oct 18, 2021 9:01 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

Drop the authentication comment.
It seems it has to be PAP for eplus. Just checked on their site.
by holvoetn
Mon Oct 18, 2021 8:56 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

@to55603
can you also provide screenshots of LTE interface - status and LTE interface - cellular ?
by holvoetn
Mon Oct 18, 2021 8:53 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]



Why not ? It's a name like any other.
Or would you prefer "becauseanavsaidso" ? :lol:
I prefer........... holvoshoulddriveavolvo
Used to drive Audi. Now a Jag (never again. Other story ...).

Let's stay on topic here !!
by holvoetn
Mon Oct 18, 2021 8:49 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

Did you reboot your device after all these changes ? If that box was already ticked AND we still don't see a default address coupled to lte interface something is wrong. Before you do: Winbox - Files Backup "anynameyouwish" :lol: - don't encrypt (you can take care of that later if you want...
by holvoetn
Mon Oct 18, 2021 8:26 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

I didnt mean literally the file should be called anynameyouwish, I meant that you could use any name you desired for the file LOL
Why not ? It's a name like any other.
Or would you prefer "becauseanavsaidso" ? :lol:
by holvoetn
Mon Oct 18, 2021 8:24 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

I am not sure you need to frig with DHCP client, if you already have LTE client settings as a separate entity. if you do need dhcp client then the interface would be the LTE one NOT the wifi one. No, it's not needed. IP address should be provided through LTE interface. Default route as well. Interf...
by holvoetn
Mon Oct 18, 2021 7:22 pm
Forum: General
Topic: DHCP Network always 0.0.0.0/24 by Quick Set
Replies: 9
Views: 1062

Re: DHCP Network always 0.0.0.0/24 by Quick Set

I am not sure about that statement.
If I use a default Quickset on my Hex, it simply works.

I'll have a look later.
by holvoetn
Mon Oct 18, 2021 5:05 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

As Anav said (without the exclamation marks :) )

On your lasts screenshots, the one for DHCP server: remove the line in red with defconf. It is invalid now because wlan1 is part of the bridge.
You can not run a DHCP server on a slave interface.

And then provide your export again please.
by holvoetn
Mon Oct 18, 2021 2:30 pm
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]

(EDIT: already someone replied before me ... same lines of thinking) The config you posted before, is that the default config of the device ? The LTE + SIM card, is that your lte interface on your Mikrotik ? I will also assume that you want to have AND Ethernet-clients AND wlan-clients as being part...
by holvoetn
Sun Oct 17, 2021 9:01 pm
Forum: Scripting
Topic: mikrotik router scheduler working time
Replies: 6
Views: 781

Re: mikrotik router scheduler working time

Above solutions came to mind as well.
Don't forget to gracefully shut down your device before the juice is being cut rather abruptly !
:o
by holvoetn
Sun Oct 17, 2021 8:22 pm
Forum: General
Topic: Winbox
Replies: 3
Views: 384

Re: Winbox

I connect my CAP to router with ethernet using a PLC
Try direct cable.
PLC can sometimes give problems for this winbox MAC access (experienced it already myself)
by holvoetn
Sun Oct 17, 2021 1:41 pm
Forum: Beginner Basics
Topic: hAP AC lite VPN access behind ISP router
Replies: 4
Views: 507

Re: hAP AC lite VPN access behind ISP router

If that is not possible (Firewall,double nat, etc..) , you can always use a reverse VPN.

Insteed of your hAP ac lite being a VPN-Server,
Your device is a VPN-Client of a another device.
Which was the second part of my answer :lol:
by holvoetn
Sun Oct 17, 2021 1:32 pm
Forum: Beginner Basics
Topic: hAP AC lite VPN access behind ISP router
Replies: 4
Views: 507

Re: hAP AC lite VPN access behind ISP router

Depending on which vpn protocol you use, you do need to forward that port to your Mikrotik. Yes.

Or connect from the Tik outwards to another router where you can connect to.
by holvoetn
Sun Oct 17, 2021 12:26 pm
Forum: Beginner Basics
Topic: Where in firewall rules the Fasttrack should be [SOLVED]
Replies: 5
Views: 878

Re: Where in firewall rules the Fasttrack should be [SOLVED]

That's default configuration ?
It has to be there.

If you add input rules, put them above FastTrack.
by holvoetn
Sat Oct 16, 2021 2:56 pm
Forum: General
Topic: Make ssh/web reachable from VPN network [SOLVED]
Replies: 8
Views: 655

Re: Make ssh/web reachable from VPN network [SOLVED]

Errrmm... you opened everything now.
All not coming from Lan is blocked but coming from WAN is accepted now. Which is basically ... all accepted.

Second line should be this.
add action=drop chain=input comment="drop all coming from WAN" in-interface-list=WAN

Remove first line.
by holvoetn
Sat Oct 16, 2021 2:41 pm
Forum: Wireless Networking
Topic: hap ac3 - worse than hap lite?
Replies: 15
Views: 1899

Re: hap ac3 - worse than hap lite?

Capsman at this time, cannot manage radios using the wave2 package.
Ah ! That makes sense but will only be a matter of time.
by holvoetn
Sat Oct 16, 2021 2:39 pm
Forum: General
Topic: Make ssh/web reachable from VPN network [SOLVED]
Replies: 8
Views: 655

Re: Make ssh/web reachable from VPN network [SOLVED]

Maybe it's line 75 that's blocking the connection?
add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN
Yes. Change that to WAN. Don't forget to remove the NOT-tick.

And Safe Mode to be sure !
by holvoetn
Sat Oct 16, 2021 1:13 pm
Forum: General
Topic: Make ssh/web reachable from VPN network [SOLVED]
Replies: 8
Views: 655

Re: Make ssh/web reachable from VPN network [SOLVED]

Apart from the valid answer to post your config, in the default firewall rules only LAN interfaces are allowed to access through whatever. Is your VPN interface part of the LAN list ? Alternative (since some VPN interfaces have dynamic nature): change the relevant firewall rule from accepting only L...
by holvoetn
Sat Oct 16, 2021 12:34 pm
Forum: Wireless Networking
Topic: hap ac3 - worse than hap lite?
Replies: 15
Views: 1899

Re: hap ac3 - worse than hap lite?

Hello! I've run into the same issue and was initially very disappointed by the hap ac3 and made me appreciate my trusted old hap ac even more. In order to get much better wifi performance out of the hap ac3 you will need to install ROS v7 and the wifiwave2 package. This enables mu-mimo, beam formin...
by holvoetn
Sat Oct 16, 2021 12:01 pm
Forum: RouterOS v7 BETA
Topic: Wireguard use Hostname in endpoint
Replies: 8
Views: 2116

Re: Wireguard use Hostname in endpoint

I see both behaviors and I do use DDNS-endpoints as well. Sometimes it just works without further intervention (laptop and smartphone, always first time right). Sometimes it doesn't for what could be the DNS resolution reason (already seen it on mAP and mAP Lite whereas SXT LTE seems to work just fi...
by holvoetn
Sat Oct 16, 2021 10:08 am
Forum: Beginner Basics
Topic: WAP-R [SOLVED]
Replies: 82
Views: 3500

Re: WAP-R [SOLVED]


[3] How can I create a network diagram with Winbox? Unfortunately, I am not very familiar with Winbox.
Easiest is papier and pencil and a picture :lol:
by holvoetn
Fri Oct 15, 2021 2:11 pm
Forum: RouterBOARD hardware
Topic: hAP ac³
Replies: 42
Views: 8965

Re: hAP ac³

I was thinking of this from a Wisp point of view, ie, POE out for the antenna CPE, thanks anyway.
Right, in that case it does make sense indeed.
As stated, you can swap the ports easily but the printed info will effectively be out of sync then with the intended purpose.
by holvoetn
Fri Oct 15, 2021 12:01 pm
Forum: RouterBOARD hardware
Topic: hAP ac³
Replies: 42
Views: 8965

Re: hAP ac³

out of curiosity I bought a selection of the hAP routers to test as we are looking to deploy them to end user instead of the cheapie tp-link stuff which causes us a lot of headaches. I have a few questions: 1. Why is the PoE port NOT the Internet port on the ac3 router ? if this router is aimed at ...
by holvoetn
Thu Oct 14, 2021 8:34 pm
Forum: General
Topic: Will NATted wireguard work?
Replies: 22
Views: 1831

Re: Will NATted wireguard work?

/export hide-sensitive file=anynameyouwish WG export won't help us, and for upstreaming RB951 I won't do that. The problem is clear: packets are entered into WG server, but no output generated by WG server: neither new packets in output chain nor errors in log. That's totally wrong You're coming he...
by holvoetn
Tue Oct 12, 2021 6:24 pm
Forum: General
Topic: Log when a specific MAC connect ?
Replies: 8
Views: 513

Re: Log when a specific MAC connect ?

Damn, didn't know that.
Oh not to worry, there will be far too many opportunities to re-live that reality. :-)
:lol:
by holvoetn
Tue Oct 12, 2021 5:31 pm
Forum: General
Topic: Log when a specific MAC connect ?
Replies: 8
Views: 513

Re: Log when a specific MAC connect ?

If the connections are to your WAN from the Internet MAC addresses will not available.
Damn, didn't know that.
by holvoetn
Tue Oct 12, 2021 4:47 pm
Forum: General
Topic: Log when a specific MAC connect ?
Replies: 8
Views: 513

Re: Log when a specific MAC connect ?

My take: Depends on the size of your list. Firewall raw rule, prerouting, and then 1 rule per src MAC address with action log. Not sure you can use a list for MAC addresses ... but this creation process can be made easier a bit with some smart scripting. Isn't it more logical to log simply all conne...
by holvoetn
Tue Oct 12, 2021 3:41 pm
Forum: General
Topic: Wireguard proper server config
Replies: 35
Views: 2230

Re: Wireguard proper server config

Hi H. In the case of the smartphone, the endpoint can be any public IP provided by a. the wifi of the location one is in, or b. random generated by the cellular company. In the case of a fixed peer behind a Public IP (static or dynamic - I can use the endpoint of IP cloud if the main router or peer...
by holvoetn
Tue Oct 12, 2021 12:44 pm
Forum: General
Topic: DHCP Network always 0.0.0.0/24 by Quick Set
Replies: 9
Views: 1062

Re: DHCP Network always 0.0.0.0/24 by Quick Set

What device are you using ? And why don't you apply firewall on your router ? Export of config is easier then those screenshots. Not everything is shown. Anyhow, it's something which can easily be set manually. Network: 192.168.224.0/24 Gateway: whatever you need (but I think it should be 172.16.1.2...
by holvoetn
Tue Oct 12, 2021 8:59 am
Forum: General
Topic: Best Way of Blocking System In mikrotik
Replies: 2
Views: 389

Re: Best Way of Blocking System In mikrotik

Far from an expert but here is my take:
Layer-7 is rather heavy on your device.
IP addresses are never sure to be 100% correct (and can change).
So I'd say PI-Hole, that way it gets solved using DNS-blocking.

Interested to see other suggestions.
by holvoetn
Tue Oct 12, 2021 8:01 am
Forum: General
Topic: Wireguard proper server config
Replies: 35
Views: 2230

Re: Wireguard proper server config

/interface wireguard peers add allowed-address=10.20.50.2/32 endpoint-port=13231 interface=wgmt \ public-key="sensitive" If the peer is an android phone that will move around in a Roadwarrior fashion, you should not be setting the endpoint-port for it. Question: Why not ? As far as I unde...
by holvoetn
Tue Oct 12, 2021 7:50 am
Forum: General
Topic: Wireguard proper server config
Replies: 35
Views: 2230

Re: Wireguard proper server config

I asked before but I will repeat: In the drawing in post #10 of this thread you showed the WG port to be 51820. Is that the port which is forwarded towards your Mikrotik router ? Or is it supposed to be 13231 as you are showing now in all your config ? Or are ALL ports simply available on your route...
by holvoetn
Mon Oct 11, 2021 10:58 pm
Forum: Wireless Networking
Topic: mAP Lite positioning
Replies: 5
Views: 1033

Re: mAP Lite positioning

Never noticed anything different either way.

Does it matter that much ?
by holvoetn
Mon Oct 11, 2021 9:14 pm
Forum: General
Topic: Mikrotik hEX PoE (V 649) - OVPN Server
Replies: 1
Views: 295

Re: Mikrotik hEX PoE (V 649) - OVPN Server

Is the tunnel functional or not ?

As for the duplicate error:
"Hello,

This error message does not have any impact on the VPN connection establishment, it simply warns you that the client sent duplicate message which some client software (for example Windows) do.

Best regards, Emils Z."
by holvoetn
Mon Oct 11, 2021 10:53 am
Forum: Beginner Basics
Topic: Is there a Chromecast/MikroTik checklist/FAQ?
Replies: 4
Views: 792

Re: Is there a Chromecast/MikroTik checklist/FAQ?

Check drop rules in fw first.

I have 2 Chromecast devices at home, didn't have to do anything special to make it work.
by holvoetn
Sun Oct 10, 2021 10:52 pm
Forum: General
Topic: Wireguard proper server config
Replies: 35
Views: 2230

Re: Wireguard proper server config

Posting your config between Code-tags is easier for everyone ... # oct/10/2021 20:57:46 by RouterOS 7.1rc4 # software id = BSM0-IT8B # # model = RBD53iG-5HacD2HnD # serial number = E7290XXXXXXX /interface bridge add admin-mac=08:55:31:XX:XX:XX auto-mac=no comment=defconf name=bridge /interface wirel...
by holvoetn
Sun Oct 10, 2021 10:20 pm
Forum: Beginner Basics
Topic: No DHCP IP through CAP
Replies: 5
Views: 851

Re: No DHCP IP through CAP

I am not 100% sure I understand what you mean with this: When the CAP comes up, it already contains a bridge called "bridgeLocal" which includes WLAN (still, there is no eth1 though). There is no "bridge" on the CAP, and the bridge which does exist does not include eth1. On any M...
by holvoetn
Sun Oct 10, 2021 9:49 pm
Forum: General
Topic: Wireguard proper server config
Replies: 35
Views: 2230

Re: Wireguard proper server config

Can you post your current configuration ?
/export hide-sensitive file=whatever

Then we can have a look.
by holvoetn
Sun Oct 10, 2021 8:17 pm
Forum: Announcements
Topic: WinBox v3.31 released!
Replies: 61
Views: 31278

Re: WinBox v3.31 released!

Ctrl= or Ctrl-
Better then messing with registry...
by holvoetn
Sun Oct 10, 2021 1:11 pm
Forum: General
Topic: unable to send mail using gmail (auth failed)?
Replies: 4
Views: 531

Re: unable to send mail using gmail (auth failed)?

You can still use the 2-Step-Verification if you create a specific gmail app password. https://support.google.com/accounts/answer/185833?hl=en
Right ! Missed that one ... still keeping the accounts separate, though :)
by holvoetn
Sun Oct 10, 2021 11:51 am
Forum: General
Topic: unable to send mail using gmail (auth failed)?
Replies: 4
Views: 531

Re: unable to send mail using gmail (auth failed)?

Have you enabled sending of email through less secure applications on your gmail account ? https://myaccount.google.com/lesssecureapps Be careful, this does NOT work if your Gmail account has 2-factor enabled. I use a separate gmail account for this sending of mails 1) to keep it out of my primary a...
by holvoetn
Sun Oct 10, 2021 10:49 am
Forum: Beginner Basics
Topic: No DHCP IP through CAP
Replies: 5
Views: 851

Re: No DHCP IP through CAP

What I do not understand is why the default bridge configuration does not include both the WLAN and Ethernet interfaces? It feels really dumb that the default CAP configuration does not bridge the two at all. Or perhaps the default configuration does not enable local-forwarding I guess (but then no...
by holvoetn
Sun Oct 10, 2021 12:05 am
Forum: General
Topic: winbox multiple interfaces?
Replies: 1
Views: 582

Re: winbox multiple interfaces?

Default it will not accept winbox access at the WAN ports which should be ether1.

Already tried all other ethernet ports ?
by holvoetn
Sat Oct 09, 2021 11:46 pm
Forum: General
Topic: Lte limited access
Replies: 2
Views: 409

Re: Lte limited access

Already tried reboot ?
II've seen it happening a couple of times too on sxt lte.
Usually reboot fixed it.

Usb reset of lte could be possible as well but my device is 930 km away which means a reboot is simpler and safer.
by holvoetn
Sat Oct 09, 2021 7:54 pm
Forum: Beginner Basics
Topic: Help - stuck on initial setup/install
Replies: 12
Views: 932

Re: Help - stuck on initial setup/install

I am afraid that you linked the same image two times.
That's to make sure we do not see any difference :lol:
by holvoetn
Sat Oct 09, 2021 7:53 pm
Forum: Beginner Basics
Topic: Help - stuck on initial setup/install
Replies: 12
Views: 932

Re: Help - stuck on initial setup/install

Check ip/dhcp/client
Did it get an IP address from your ISP on ether1 interface ?
And are you otherwise able to use the network behind your router from your PC (as in : internet available) ?
by holvoetn
Sat Oct 09, 2021 5:10 pm
Forum: Beginner Basics
Topic: Help - stuck on initial setup/install
Replies: 12
Views: 932

Re: Help - stuck on initial setup/install

All you plan to do is possible using Mikrotik. I admit, the learning curve is steep. MUCH steeper then any consumer grade equipment like TP-link or Netgear or ... I am still learning quite a bit myself almost daily. Luckily I love to learn :lol: But once you get to know it, you can do a TON more wit...
by holvoetn
Sat Oct 09, 2021 5:03 pm
Forum: General
Topic: router behind firewall, use vpn only to manage it
Replies: 7
Views: 654

Re: router behind firewall, use vpn only to manage it

That is amazing information Sindy, good pickup on the users 3G limitations.
Indeed, very well spotted !
It's the reason why I changed from L2TP/IPSec to SSTP and ultimately to Wireguard for my SXT setup.
by holvoetn
Sat Oct 09, 2021 5:00 pm
Forum: Beginner Basics
Topic: Help with setup
Replies: 1
Views: 536

Re: Help with setup

Start by setting the channel frequencies to auto instead of fixing to rule out any issues there. I see some discrepancies on the 2Ghz part, unless I am mistaking ? This: /caps-man channel add band=2ghz-onlyn control-channel-width=20mhz frequency=2412,2437,2462 \ name=channel2GHz secondary-frequency=...
by holvoetn
Sat Oct 09, 2021 4:52 pm
Forum: Scripting
Topic: Auto speed test for multi VPN
Replies: 10
Views: 1499

Re: Auto speed test for multi VPN

"Searched and thou shalt find"

viewtopic.php?t=140887
by holvoetn
Sat Oct 09, 2021 4:46 pm
Forum: General
Topic: DHCP Network always 0.0.0.0/24 by Quick Set
Replies: 9
Views: 1062

Re: DHCP Network always 0.0.0.0/24 by Quick Set

Strange question for a trainer ...

No, it's not normal.
What quickset were you using ?
Please post /export hide-sensitive file=whatever
by holvoetn
Sat Oct 09, 2021 4:35 pm
Forum: Beginner Basics
Topic: No DHCP IP through CAP
Replies: 5
Views: 851

Re: No DHCP IP through CAP

Is the bottom part the complete config of the hAP AC ? I don't see a datapath section for the Cap Lite, which makes me think it is missing on the CAPSMAN side. From Wiki:https://wiki.mikrotik.com/wiki/Manual:CAPsMAN#Datapath_Configuration Most of the datapath settings are used only when in manager f...
by holvoetn
Sat Oct 09, 2021 4:20 pm
Forum: Beginner Basics
Topic: Router route all AP traffic to Wan only
Replies: 13
Views: 1230

Re: Router route all AP traffic to Wan only

Unclear without more detailed info. From your picture I assume you AP is connected on the network part before your Mikrotik ? In that case all communication from AP to Tik is already blocked, since the incoming port of your router (eth1) is considered WAN and that one is blocked by default in the fi...
by holvoetn
Sat Oct 09, 2021 2:46 pm
Forum: Beginner Basics
Topic: Help - stuck on initial setup/install
Replies: 12
Views: 932

Re: Help - stuck on initial setup/install

Connect using Winbox using MAC address (requires direct connection to the device using Ethernet or Wifi) Might be you first need to set it back to factory conditions: hold reset while power on, until the leds start blinking (5 seconds ?) then release. Do you get an IP address from your ISP ? Check /...
by holvoetn
Sat Oct 09, 2021 2:40 pm
Forum: General
Topic: Wireguard proper server config
Replies: 35
Views: 2230

Re: Wireguard proper server config

OK, much clearer :D On new MT router, add firewall rule to allow port 51820 /ip/firewall/filter add chain=input action=accept protocol=udp in-interface-list=WAN dst-port=51820 log=no (or yes, your choice) Move that rule above the input drop rule which blocks everything coming from WAN (or !LAN, depe...
by holvoetn
Sat Oct 09, 2021 11:32 am
Forum: General
Topic: Wireguard proper server config
Replies: 35
Views: 2230

Re: Wireguard proper server config

I am a bit confused.
What device do you use as "entry point" to reach the Wireguard port (which ultimately needs to be forwarded one way or the other towards your MT router) ?
Is port forwarding functioning there ?
by holvoetn
Sat Oct 09, 2021 8:43 am
Forum: Wireless Networking
Topic: CAPSMAN Access Point Setup Questions (newbie)
Replies: 5
Views: 1061

Re: CAPSMAN Access Point Setup Questions (newbie)

From Wiki
 (/caps-man datapath)
datapath.bridge (list; Default: )	Bridge to which particular interface should be automatically added as port. Required only when local-forwarding is not used.
Without it, the Caps interface is not added to any bridge.
by holvoetn
Fri Oct 08, 2021 11:07 pm
Forum: General
Topic: Wireguard proper server config
Replies: 35
Views: 2230

Re: Wireguard proper server config

From my first post on this thread:

'Back in the days, when I managed old router (before mt) I just had to port forward, to my server with wireguard and all was fine. I suspect now is probably the same case.'
It is.
It is not because it is old school, it does not work anymore :D
by holvoetn
Fri Oct 08, 2021 11:05 pm
Forum: General
Topic: router behind firewall, use vpn only to manage it
Replies: 7
Views: 654

Re: router behind firewall, use vpn only to manage it

Got a setup like that with SXTLTE in France using Wireguard.
Works perfect.
For the subnet, you can use a complete /24 in private range if you want.
Just make sure one end of the tunnel has a fixed ip.
by holvoetn
Fri Oct 08, 2021 7:07 pm
Forum: General
Topic: Wireguard proper server config
Replies: 35
Views: 2230

Re: Wireguard proper server config

Hi back Questions: - I assume your left device is a RB SXT sqG-5acD. It has an external IP 192.168.100.249 and an internal IP in the 192.168.1.0-range ? - which device do you intend to have acting as "server" (which conceptually does not exist on WG, there are only peers) - can you reach t...
by holvoetn
Fri Oct 08, 2021 5:15 pm
Forum: RouterOS v7 BETA
Topic: Optimal config for Wireguard
Replies: 5
Views: 1836

Re: Optimal config for Wireguard

Apart from the discussion above ... Speed is pretty much defined by all intermediate steps to go from end to end. There is not much else to tweak. I have a 150 down/ 20(-ish) up connection at home. Where I usually work I have 80/80 Wireguard tunnel directing ALL traffic via home will never go beyond...
by holvoetn
Fri Oct 08, 2021 4:10 pm
Forum: RouterBOARD hardware
Topic: hap ac3 led lights explained
Replies: 2
Views: 1150

Re: hap ac3 led lights explained

Installed 2 of those this week for my customer. Have to go by memory since they are at least 50km away from where I am now :) The lights with the horizontal stripes correspond to eth-ports 1-5. The blue light in the middle is the WPS button (which I think you can not put out but you can disable the ...
by holvoetn
Fri Oct 08, 2021 3:40 pm
Forum: Forwarding Protocols
Topic: VPN Speed
Replies: 2
Views: 996

Re: VPN Speed

What VPN protocol do you use ? Additional encryption on top ? Not scientifically 100% correct but here is a test of the most VPN protocols using Mikrotik: https://rickfreyconsulting.com/mikrotik-vpns/ Depending on which protocol you use, you can be down to only 10% useable bandwidth. Edit: the faste...