Community discussions

MikroTik App

Search found 203 matches

by BrateloSlava
Mon Apr 15, 2024 1:00 pm
Forum: Forwarding Protocols
Topic: Single-hop BFD session is not restored after reboot or power outage
Replies: 6
Views: 631

Re: Single-hop BFD session is not restored after reboot or power outage

As far as I can see from the documentation:
Features not yet supported
  • echo mode
  • enabling BFD for ip route gateways
  • authentication
by BrateloSlava
Fri Mar 22, 2024 9:34 pm
Forum: Beginner Basics
Topic: second switch for /29
Replies: 2
Views: 326

Re: second switch for /29

You, at least, wrote a model of the switch and drew some kind of diagram, of what you want to get.
by BrateloSlava
Thu Mar 21, 2024 7:33 pm
Forum: Announcements
Topic: v7.15beta [testing] is released!
Replies: 503
Views: 126079

Re: v7.15beta [testing] is released!

Why not remove, for example, Mesh from the ROS for ARM?
Surely it will be possible to gain a little in the size of the image.
by BrateloSlava
Fri Mar 01, 2024 7:13 pm
Forum: Announcements
Topic: v7.14.3 [stable] is released!
Replies: 585
Views: 140454

Re: v7.14 [stable] is released!

Good afternoon. Today, when trying to update one hAP ac2 from 7.13.5 to 7.14, I received this out of memory error. Screenshot_log_error.png After which I conducted two experiments with installing ROS via Netinstall. Two packages are installed on the router: - routeros-7.14-arm.npk - wifi-qcom-ac-7.1...
by BrateloSlava
Wed Feb 14, 2024 9:00 am
Forum: Beginner Basics
Topic: Cannot upgrade hAP ac2 7.7 to 7.11.2
Replies: 2
Views: 351

Re: Cannot upgrade hAP ac2 7.7 to 7.11.2

Try force closing the application and clearing its cache. ROS 7.11.2 has long been archived.
by BrateloSlava
Mon Feb 12, 2024 1:26 pm
Forum: Announcements
Topic: v7.14rc [testing] is released!
Replies: 176
Views: 49610

Re: v7.14rc [testing] is released!

*) wifi-qcom - improved memory allocating process;
Is this update only for wifi-qcom or also for wifi-qcom-ac?
by BrateloSlava
Fri Feb 02, 2024 10:42 pm
Forum: General
Topic: Queue and Fasttrack
Replies: 15
Views: 1038

Re: Queue and Fasttrack

You would not need this kind of "complex queue tree" when using CAKE queue (with diffserv).
I confess honestly. All my attempts to adjust this CAKE queue - only resulted, that the speed test is dropping by half. Even in the same simple configuration (one WAN interface and local bridge).
by BrateloSlava
Thu Feb 01, 2024 9:12 pm
Forum: General
Topic: Queue and Fasttrack
Replies: 15
Views: 1038

Re: Queue and Fasttrack

pls not! this qos script is not meant for fqcodel/cake.
Are you sure about this? Because my version of this script works great. In 10 places exactly. :)
by BrateloSlava
Thu Feb 01, 2024 8:46 am
Forum: General
Topic: Queue and Fasttrack
Replies: 15
Views: 1038

Re: Queue and Fasttrack

@vanadiel
Read this - FastTrack-Friendly QoS Script
by BrateloSlava
Wed Jan 24, 2024 10:43 am
Forum: Wireless Networking
Topic: Apple devices won't connect
Replies: 11
Views: 1446

Re: Apple devices won't connect

1. I don’t have hAP ax3, so I’m copying the example settings from the only place, where one hAP ac3 is installed. The majority - have long switched to several WiFi points and CAPsMAN. Or for products from other manufacturers. 2. When you, like me in some places, have a very noisy airwaves (more than...
by BrateloSlava
Tue Jan 23, 2024 3:59 pm
Forum: Wireless Networking
Topic: Apple devices won't connect
Replies: 11
Views: 1446

Re: Apple devices won't connect

Explain: do devices disconnect from the 5 GHz network and connect to the 2.4 GHz network? Or are they completely disconnected from the WiFi network?

Show the logs, please.
by BrateloSlava
Mon Jan 22, 2024 5:15 pm
Forum: Wireless Networking
Topic: Apple devices won't connect
Replies: 11
Views: 1446

Re: Apple devices won't connect

I copied similar data from one of the routers. Try it by analogy. Currently 6 Apple devices (2 laptops and 4 phones) are connected to the network and are functioning normally. [admin@rt-oleg] > /interface/wifi/actual-configuration/print 0 name="wifi1" l2mtu=1560 mac-address=2C:C8:1B:XX:XX:...
by BrateloSlava
Mon Jan 22, 2024 5:05 pm
Forum: Wireless Networking
Topic: MESH and sonoff devices
Replies: 3
Views: 598

Re: MESH and sonoff devices

About WiFi and Sonoff devices. I have 15 relays that control the heaters. For Sonoff I had to organize a separate WiFi network with a separate controller. In order to separate the “slow” Sonoff from other devices - laptops and phones. For Sonoff I use a controller on the "wireless" package...
by BrateloSlava
Sat Jan 13, 2024 7:43 pm
Forum: General
Topic: IPv6 configuration /64
Replies: 26
Views: 3327

Re: IPv6 configuration /64

I compared my settings on my working router with yours. Everything is set up the same way. The only thing is that I have one more line of settings:
/ipv6 settings set accept-router-advertisements=yes max-neighbor-entries=2048
And my firewall rules are different from yours.
by BrateloSlava
Sat Jan 13, 2024 12:30 pm
Forum: General
Topic: IPv6 configuration /64
Replies: 26
Views: 3327

Re: IPv6 configuration /64

@ abbio90 1. For firewall settings, use the recommendations in the official documentation . At least in the basic version. 2. Show the output of such a command from your main router. Do not specify any additional parameters in this command. ping 2606:4700:4700::1001 count=5 3. Show the output of suc...
by BrateloSlava
Wed Jan 10, 2024 9:29 am
Forum: General
Topic: IPv6 configuration /64
Replies: 26
Views: 3327

Re: IPv6 configuration /64

good morning, today they are assigning me another subnet in order to avoid the overlap encountered. Question, but can I divide the /64 that I have as a pool to advertise towards the LAN into two /96 pools, one towards the LAN bridge and one towards an ether other than the bridge? Using a calculator...
by BrateloSlava
Tue Jan 09, 2024 11:13 pm
Forum: General
Topic: IPv6 configuration /64
Replies: 26
Views: 3327

Re: IPv6 configuration /64

To be honest, I have not seen configurations in which the WAN interface advertises addresses to the local network.
by BrateloSlava
Tue Jan 09, 2024 10:40 pm
Forum: General
Topic: IPv6 configuration /64
Replies: 26
Views: 3327

Re: IPv6 configuration /64

Error 1. Your messages indicate either different addresses or incorrect ones. 2. If you are given a pool 2a0d:b287:ec00:52b4::/64 , then the address for your interface that goes to the provider cannot be 2a0d:b287:ec00:52b4::1 Because this address already belongs to your pool. You can assign addres...
by BrateloSlava
Tue Jan 09, 2024 9:30 pm
Forum: General
Topic: IPv6 configuration /64
Replies: 26
Views: 3327

Re: IPv6 configuration /64

as already mentioned the address assigned by the provider is
If all the data is known, substitute it into the commands, that I wrote earlier.
And check.
by BrateloSlava
Tue Jan 09, 2024 5:43 pm
Forum: General
Topic: IPv6 configuration /64
Replies: 26
Views: 3327

Re: IPv6 configuration /64

In the meantime, thank you for your valuable response. I'm not an IPv6 expert. In any case, I was given an indication of the /64 assigned and which gateway it is. At this point the doubt remains as to which subnet to indicate in the IP address and whether I should take the address from the pool or ...
by BrateloSlava
Tue Jan 09, 2024 5:32 pm
Forum: General
Topic: IPv6 configuration /64
Replies: 26
Views: 3327

Re: IPv6 configuration /64

just curious, does "/ipv6/neighbor/print" show anything reachable?
To whom is your question addressed? :lol:
by BrateloSlava
Tue Jan 09, 2024 9:29 am
Forum: General
Topic: IPv6 configuration /64
Replies: 26
Views: 3327

Re: IPv6 configuration /64

Where do you get this /48 prefix from? You were given a network with the /64 prefix. And to which interface are you trying to assign an address? Here is an example of the settings, how it was done for me where the range of addresses was given to me manually. WAN address and gateway /ipv6 address add...
by BrateloSlava
Mon Jan 08, 2024 10:11 pm
Forum: General
Topic: IPv6 configuration /64
Replies: 26
Views: 3327

Re: IPv6 configuration /64

@ abbio90 You are confusing something with the addresses. Network /48 is 2001:abcd:abcd::/48 The address range of this network is from 2001:abcd:abcd:0:0:0:0:0 to 2001:abcd:abcd:ffff:ffff:ffff:ffff:ffff The /48 network contains 65536 /64 networks When setting up a router, the WAN interface address i...
by BrateloSlava
Tue Nov 28, 2023 11:44 am
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 92932

Re: v7.13beta [testing] is released!

After full restart of all caps "busy" went away. All good for now.
Unfortunately, rebooting “fixes” the problem only partially - temporarily. And when she next appears is not clear.
by BrateloSlava
Tue Nov 28, 2023 8:15 am
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 92932

Re: v7.13beta [testing] is released!

A "busy" error occurs spontaneously when connecting wireless points to the controller. There is no dependence. I'm returning to beta1.
by BrateloSlava
Mon Nov 27, 2023 4:05 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 92932

Re: v7.13beta [testing] is released!

There is no WiFi network after the update. Screenshot from the controller.
Operation is restored after two reboots of the wireless points and the controller.
by BrateloSlava
Tue Nov 21, 2023 6:34 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 92932

Re: v7.13beta [testing] is released!

@iustin @Simonej
As already written earlier, VLAN support is only through bridge ports.
by BrateloSlava
Tue Nov 21, 2023 3:12 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 92932

Re: v7.13beta [testing] is released!

Trying to understand how 802.11ac CAP device interfaces should be configured now...

So far I have not encountered any problems with this (create-dynamic-enabled) configuration.
by BrateloSlava
Sat Nov 18, 2023 6:18 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 92932

Re: v7.13beta [testing] is released!

Thanks, but still no success! If we consider the configuration that Santi70 published, I would also change this for “old” devices: add band=2ghz-ax disabled=no frequency=2462 name=channel11x width=20mhz to add band=2ghz-n disabled=no frequency=2462 name=channel11x width=20mhz Because it uses exactl...
by BrateloSlava
Sat Nov 18, 2023 2:20 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 92932

Re: v7.13beta [testing] is released!

/interface wifi security add authentication-types=wpa2-psk,wpa3-psk disabled=no management-protection=allowed name=secWPA3 wps=disable Try to changed to /interface wifi security add authentication-types=wpa-psk,wpa2-psk disabled=no management-protection=allowed name=secWPA3 wps=disable to support y...
by BrateloSlava
Fri Nov 17, 2023 6:20 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 92932

Re: v7.13beta [testing] is released!

somehow sad and pathetic this has to be told to people (or even those who refer to themselfes as network engineers) We put together a test version and made a mistake. There are always two ways to solve a problem: simple and difficult. Difficult - we take everything back and take each device somewhe...
by BrateloSlava
Fri Nov 17, 2023 9:10 am
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 92932

Re: v7.13beta [testing] is released!

One day this will be resolved, but not in Winbox 3.x Currently, through the standard means of checking the firmware version in the selected update channel, it is only possible to “upgrade” the firmware version. For devices with a small amount of internal memory, for example hAP ac2, there is no opt...
by BrateloSlava
Thu Nov 16, 2023 9:02 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 92932

Re: v7.13beta [testing] is released!

We have managed to reproduce the memory leak introduced in beta2 release. We will fix it as soon as possible. It is caused by opened WinBox sessions. The memory leak on beta2 is not only due to connections via Winbox. Even simple monitoring through Dude also causes leaks. According to my observatio...
by BrateloSlava
Thu Nov 16, 2023 7:09 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 92932

Re: v7.13beta [testing] is released!

For mixed CAPSMAN setups (qcom-ac and qcom), does it matter which package is installed on the CAPSMAN? For now I kept my RB4011 on 7.12/wifiwave2, but I cannot get VLAN-s working on hap ac2 and wap ac and I can't even connect to the same SSID that works without problems on the hap ax2 with the same...
by BrateloSlava
Thu Nov 16, 2023 3:42 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 92932

Re: v7.13beta [testing] is released!

On the wireless→wifi (wave2) migration, did anyone write a guide? Or is the recommendation to rebuild from scratch, and look at all the settings? (I understand the limitations for ac devices/VLANs and datapath changes. I'm asking in general, what should one pay attention to when migrating.) Did you...
by BrateloSlava
Wed Nov 15, 2023 9:55 am
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 92932

Re: v7.13beta [testing] is released!

Good afternoon. I set up a test network at home on 7.13. The CAPsMAN controller was installed on RB750Gr3, access points - cAP ac, wAP ac. Configurations were exported using the command " export compact terse show-sensitive file " Access points: /interface wifi channel add band=2ghz-n disa...
by BrateloSlava
Sun Oct 01, 2023 12:24 pm
Forum: Beginner Basics
Topic: Connect Internet LAN and Smart Home LAN
Replies: 3
Views: 1211

Re: Connect Internet LAN and Smart Home LAN

As for me, the first option that comes to mind is to try to organize, for example, a separate Wi-Fi network for access to smart home devices. You buy a device that can be a Wi-Fi access point, connect it with a cable to the smart home network. Set up a Wi-Fi network on this device. Clients of this w...
by BrateloSlava
Sun Oct 01, 2023 12:11 pm
Forum: General
Topic: qBittorrent opened 1400+ UPNP Sessions [SOLVED]
Replies: 6
Views: 1963

Re: qBittorrent opened 1400+ UPNP Sessions [SOLVED]

It seems to me that this question does not belong to this forum. You should read this and ask similar questions here.
by BrateloSlava
Wed Sep 20, 2023 12:11 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 275
Views: 506992

Re: Using RouterOS to QoS your network - 2020 Edition

How this can be adjusted for 2 bridges - one for homelan and another one for guestlan? Especially for options when you have several WAN or LAN interfaces, or when you use a VLAN, I slightly modified the original script. For example, when using VLAN, it is necessary to mark packets on VLAN interface...
by BrateloSlava
Mon Aug 28, 2023 2:48 pm
Forum: Scripting
Topic: FastTrack-Friendly QoS Script
Replies: 61
Views: 39276

Re: FastTrack-Friendly QoS Script

For my needs, I modified the script, which is posted in the first message. The new option adds the described rule to the firewall and allows multiple incoming and outgoing interfaces. Separate setting of speed limits is also possible. The work of the script with IPv6 is not changed and works, IMHO, ...
by BrateloSlava
Fri Aug 25, 2023 9:56 pm
Forum: Scripting
Topic: FastTrack-Friendly QoS Script
Replies: 61
Views: 39276

Re: FastTrack-Friendly QoS Script

Quick question if i wanted to prioritize SIP and RTP packets, 5060,5061 udp and 10000-20000 udp up to prioity 1 what would be the best approach to this? For example, you can insert packet marking rules for the desired ports and place these rules before the ones, that this script sets. Screenshot_Ru...
by BrateloSlava
Wed Mar 29, 2023 9:19 am
Forum: Beginner Basics
Topic: HAP AC2 reset problem
Replies: 5
Views: 625

Re: HAP AC2 reset problem

Did you decide to reset because the router stopped booting normally? That is, after turning on the power, did the router blink its lights and reboot itself?
by BrateloSlava
Sun Mar 12, 2023 8:09 pm
Forum: Useful user articles
Topic: How to: Edge router and BNG optimization for ISPs Topic is solved
Replies: 68
Views: 90190

Re: How to: Edge router and BNG optimization for ISPs Topic is solved

Please explain, what is the meaning of such a MTU replacement? The final (home) users will still be 1500. For example, to install 9000 on the server, NAS and switch, through which you will do backup, I still understand. And just change on all devices - I don’t understand what the point is.
by BrateloSlava
Thu Mar 09, 2023 10:22 pm
Forum: Beginner Basics
Topic: CRS112-8G-4S: problem with Trunk to CCR1016-12G
Replies: 7
Views: 1037

Re: CRS112-8G-4S: problem with Trunk to CCR1016-12G

I understand correctly, that all these devices have the same ROS and firmware version? You have almost a classic scheme for this switch. As in the example . It is not clear, why everything works fine for you with CRS112-8P-4S and does not work with CRS112-8G-4S. I have CRS112-8P-4S and it copes with...
by BrateloSlava
Mon Mar 06, 2023 8:29 pm
Forum: General
Topic: DDoS story, or WARNING: use 'conection-limit' with caution!
Replies: 168
Views: 112151

Re: DDoS story, or WARNING: use 'conection-limit' with caution!

Remove the link, its detected as a threat and shuts the browser down cold.
Link 2 - original source
by BrateloSlava
Mon Mar 06, 2023 8:04 pm
Forum: General
Topic: DDoS story, or WARNING: use 'conection-limit' with caution!
Replies: 168
Views: 112151

Re: DDoS story, or WARNING: use 'conection-limit' with caution!

It is possible, that this service is already known to the users of this forum. I found it by accident. Free and paid check of your DDOS protection. With free checks, my home router (hAP ax3) coped well. But, after several checks in a row, my ISP disconnected me for 20 minutes. "Protected" ...
by BrateloSlava
Mon Feb 27, 2023 1:46 pm
Forum: Useful user articles
Topic: IPS/IDS with SELK
Replies: 23
Views: 8598

Re: IPS/IDS with SELK

It not blocks traffic based on invalid TCP, UDP, whatever - it blocks traffic from e.g. known bad hosts automatically. Also it does deep inspection and stops any malicous traffic which you in general would allow on a firewall level - e.g. TCP/443 for you webserver. If a bad bot would like to try so...
by BrateloSlava
Mon Feb 27, 2023 1:34 pm
Forum: Useful user articles
Topic: IPS/IDS with SELK
Replies: 23
Views: 8598

Re: IPS/IDS with SELK

SELKS is an IDS/IPS while T-Pot is a Honeypot I still don't understand why this is necessary. How to block "extra" traffic with built-in tools is well done here - How to ***really*** block invalid ICMP, TCP, UDP packets and others + this . And no additional resources are needed for Debian...
by BrateloSlava
Mon Feb 27, 2023 9:35 am
Forum: Useful user articles
Topic: IPS/IDS with SELK
Replies: 23
Views: 8598

Re: IPS/IDS with SELK

And what are the differences from the already finished "set" - T-Pot
by BrateloSlava
Fri Feb 17, 2023 10:39 am
Forum: RouterOS beta
Topic: Not Kiev, it's Kyiv (Continuation of the question)
Replies: 9
Views: 3074

Re: Not Kiev, it's Kyiv (Continuation of the question)

It turns out that this is not a "bug", but a "feature". :shock:
I chose the name, hop - and it itself changed to another. :lol:
by BrateloSlava
Thu Feb 16, 2023 3:50 pm
Forum: RouterOS beta
Topic: Not Kiev, it's Kyiv (Continuation of the question)
Replies: 9
Views: 3074

Not Kiev, it's Kyiv (Continuation of the question)

I would like to continue this topic - Not Kiev, it's Kyiv . The topic was closed, but the issue has not been fully resolved. Set the "correct" time zone name before.png We perform the following sequence of actions: Uncheck "Time Zone Autodetect" Press "Apply" Check &quo...
by BrateloSlava
Sat Jan 21, 2023 3:49 pm
Forum: Announcements
Topic: v7.8beta [testing] is released!
Replies: 307
Views: 76598

Re: v7.8beta [testing] is released!

9 cAP ac. Only two of them have 10% free space. The rest - from 5% to 8%. There are no user files in the memory of access points.
3 hAP ac2. Everyone has similar problems with free space.

On all devices, version 7.5 was installed via netinstall, then the usual update.
by BrateloSlava
Fri Jan 13, 2023 7:18 pm
Forum: General
Topic: DNS forwarding - multiple DNS servers?
Replies: 3
Views: 5585

Re: DNS forwarding - multiple DNS servers?

I have like this:
/ip dns static add forward-to=172.22.1.3 regexp=".*duos\\.loc" type=FWD
/ip dns static add forward-to=172.22.1.2 regexp=".*duos\\.loc" type=FWD
by BrateloSlava
Fri Jan 13, 2023 7:10 pm
Forum: General
Topic: Disk cleanup without reinstalling the OS
Replies: 0
Views: 1550

Disk cleanup without reinstalling the OS

I have a couple dozen devices with 16MB of memory - cAP ac, wAP ac, hAP ac2. When I tried to upgrade from 7.6 to 7.7, I noticed that there was no free space. Example: system/resource/print uptime: 37m26s version: 7.6 (stable) build-time: Oct/17/2022 10:55:40 factory-software: 6.45.9 free-memory: 53....
by BrateloSlava
Thu Dec 29, 2022 3:56 pm
Forum: Wireless Networking
Topic: Not getting the needed wifi speed over Mikrotik [SOLVED]
Replies: 16
Views: 3326

Re: Not getting the needed wifi speed over Mikrotik [SOLVED]

Try reading this section. The question about the speed of the wireless network is on every page.
by BrateloSlava
Sun Nov 27, 2022 9:57 pm
Forum: Wireless Networking
Topic: Wifi Wave2 on RB4011iGS+5HacQ2HnD
Replies: 44
Views: 12698

Re: Wifi Wave2 on RB4011iGS+5HacQ2HnD

I understand correctly? Will the new wireless drivers (and the new capsman) only be compatible with the new wifi 6 hardware? And in the future there will be two "branches" of ROS - for wifi 6 devices and for the "rest of the old"?
by BrateloSlava
Fri Nov 25, 2022 9:07 pm
Forum: Wireless Networking
Topic: House wifi6 network with Mikrotik AX or Audience
Replies: 29
Views: 6924

Re: House wifi6 network with Mikrotik AX or Audience

If you dont matter the big antennas on hAP AX3 i think is a good idea
Given that the ax2 model may have problems with heat dissipation and because of this, the processor frequency in this model is reduced - I would recommend the ax3 model. which has no such problems.
by BrateloSlava
Fri Nov 25, 2022 10:45 am
Forum: Wireless Networking
Topic: House wifi6 network with Mikrotik AX or Audience
Replies: 29
Views: 6924

Re: House wifi6 network with Mikrotik AX or Audience

If you have such an opportunity to create everything from scratch, I recommend abandoning the idea of ​​using a router with built-in wifi. And use only wireless access points. And put the rest of the network equipment somewhere in a separate place. And, if possible, use another manufacturer as a sup...
by BrateloSlava
Sun Nov 20, 2022 10:18 pm
Forum: Wireless Networking
Topic: cAP AC + CAPsMAN - transmission speed not as high as it can be
Replies: 28
Views: 2832

Re: cAP AC + CAPsMAN - transmission speed not as high as it can be

I'd set that option to default (which is "add-arp=no") and see if it helps. Bingo! A completely unexpected result. Many thanks to @ mkx for the tip. I use "ARP reply-only" in some places, so I use the "Add ARP For Leases" setting in the DHCP server. This option has nev...
by BrateloSlava
Sat Nov 19, 2022 4:49 pm
Forum: Wireless Networking
Topic: cAP AC + CAPsMAN - transmission speed not as high as it can be
Replies: 28
Views: 2832

Re: cAP AC + CAPsMAN - transmission speed not as high as it can be

@ Ca6ko As I wrote earlier, in the case when all access points are connected to one router or one switch, there are no problems. The problem arises when there is a cascade of switches. Moreover, this chain of switches has branchings. And somewhere in these chains, access points are connected. A wire...
by BrateloSlava
Sat Nov 19, 2022 1:19 pm
Forum: Wireless Networking
Topic: cAP AC + CAPsMAN - transmission speed not as high as it can be
Replies: 28
Views: 2832

Re: cAP AC + CAPsMAN - transmission speed not as high as it can be

@ mkx I assembled a "small and simple network" at home according to scheme #3. Before that, everything worked for me according to scheme #1. The access points were directly connected to the router, and the rest of the devices worked through the CRS326 switch. hAP ac3 (172.22.99.254) as rou...
by BrateloSlava
Fri Nov 18, 2022 6:19 pm
Forum: Wireless Networking
Topic: cAP AC + CAPsMAN - transmission speed not as high as it can be
Replies: 28
Views: 2832

Re: cAP AC + CAPsMAN - transmission speed not as high as it can be

@ zett93 Show me, please, full text configuration of your AP. Without serial numbers and etc. With bridge and VLANs info. And a question along the way. When you enable "local forwarding" mode for access points, do wireless clients not get IP addresses from DHCP server? @ mkx Most likely I ...
by BrateloSlava
Fri Nov 18, 2022 3:31 pm
Forum: Beginner Basics
Topic: Rb4011 switch all to sfp
Replies: 5
Views: 965

Re: Rb4011 switch all to sfp

As far as I know, such devices are VERY critical to the quality of the cable and its length.

H!fiber 10G SFP+ RJ45
by BrateloSlava
Fri Nov 18, 2022 1:47 pm
Forum: Wireless Networking
Topic: cAP AC + CAPsMAN - transmission speed not as high as it can be
Replies: 28
Views: 2832

Re: cAP AC + CAPsMAN - transmission speed not as high as it can be

There are several options for placing access points on the network.
Schematically, I displayed them in this figure.
In option #3, the "local forwarding" mode didn't work for me anywhere.

netdiag-lan-and-wifi-ap.png


An example of option #3 is a building with several floors.
by BrateloSlava
Fri Nov 18, 2022 1:08 pm
Forum: Beginner Basics
Topic: Rb4011 switch all to sfp
Replies: 5
Views: 965

Re: Rb4011 switch all to sfp

Also write the model of the optical module you have installed.
by BrateloSlava
Thu Nov 17, 2022 6:00 pm
Forum: General
Topic: lte firmware
Replies: 5
Views: 1056

Re: lte firmware

Screenshot_lte.png
by BrateloSlava
Thu Nov 17, 2022 5:09 pm
Forum: General
Topic: Getting 789 errors when trying to access outside VPN's
Replies: 2
Views: 474

Re: Getting 789 errors when trying to access outside VPN's

Have you tried making any changes that can be found through the search?
by BrateloSlava
Thu Nov 17, 2022 11:03 am
Forum: Beginner Basics
Topic: Add a additional dynamic CAP interface to existing CAPsMAN configuration
Replies: 1
Views: 630

Re: Add a additional dynamic CAP interface to existing CAPsMAN configuration

Firstly. Make a backup before making changes. Stop CAPsMAN. Remove all wireless interface names from existing bridges. On the router itself and on the access point. Further. The CAPsMAN configuration, that you have set up, does not have a description of the parameters for frequencies in the 2.4 and ...
by BrateloSlava
Sat Nov 12, 2022 9:58 pm
Forum: General
Topic: Possible attack
Replies: 8
Views: 3028

Re: Possible attack

by BrateloSlava
Fri Nov 11, 2022 1:52 pm
Forum: Beginner Basics
Topic: Load Balancing through 2 L2TP Tunnel
Replies: 3
Views: 806

Re: Load Balancing through 2 L2TP Tunnel

Show your current settings in text format. Export them and remove all confidential information from the resulting file. The task has a simple solution if you have two "white" IP addresses at home and on the remote side. In this case, organize two EOIP channels and combine them into boundin...
by BrateloSlava
Thu Nov 03, 2022 5:21 pm
Forum: Beginner Basics
Topic: Reject DHCP lease [SOLVED]
Replies: 4
Views: 1286

Re: Reject DHCP lease [SOLVED]

If you receive an address from the 192.168.100.0 subnet, is the global network available? Or rather, not even so. See, what gateway address your router is getting on the 192.168.100.0 network. I understand, that this address will be available only if there is no access to the global network. Therefo...
by BrateloSlava
Tue Nov 01, 2022 12:46 pm
Forum: General
Topic: Have 2 CapAc. It's better to use CAPSMAN or not? [SOLVED]
Replies: 5
Views: 1204

Re: Have 2 CapAc. It's better to use CAPSMAN or not? [SOLVED]

I can’t say how it is for anyone, but the use of "local forwarding" normally works for me only on "simple" network building schemes. In the case. when access points are "scattered" over the network and located behind several switches, everything works much easier, if th...
by BrateloSlava
Tue Nov 01, 2022 12:31 pm
Forum: General
Topic: How can i Convert my Cisco config to Mikrotik rb4011
Replies: 3
Views: 648

Re: How can i Convert my Cisco config to Mikrotik rb4011

If you draw a diagram of your network, indicate which router interfaces are responsible for what, what subnets, vlans you have, etc. In this case, we can help you here. To study Cisco configuration - is not in this forum.
by BrateloSlava
Sun Oct 30, 2022 7:44 pm
Forum: Forwarding Protocols
Topic: OSPF 2 routers with 2 isp
Replies: 8
Views: 2241

Re: OSPF 2 routers with 2 isp

Take a look at the official documentation - Load Balancing
by BrateloSlava
Sun Oct 30, 2022 7:29 pm
Forum: Wireless Networking
Topic: CAPsMAN unknown mikrotik devices
Replies: 2
Views: 513

Re: CAPsMAN unknown mikrotik devices

Manual:Simple CAPsMAN setup

For security reasons specify on which interfaces to listen to CAPs
/caps-man manager interface
set [ find default=yes ] forbid=yes
add disabled=no interface=bridge
by BrateloSlava
Sun Oct 30, 2022 4:35 pm
Forum: Forwarding Protocols
Topic: OSPF 2 routers with 2 isp
Replies: 8
Views: 2241

Re: OSPF 2 routers with 2 isp

Example for first router (ROS 6.x): /interface list add name=WAN /interface list add name=LAN /interface list member add interface=ether1 list=WAN /interface list member add interface=ether2 list=WAN /interface list member add interface=bridge1 list=LAN ### ISP1 /ip address add address=10.10.10.2/24...
by BrateloSlava
Sun Oct 30, 2022 1:58 am
Forum: Forwarding Protocols
Topic: OSPF 2 routers with 2 isp
Replies: 8
Views: 2241

Re: OSPF 2 routers with 2 isp

It is not difficult for me to write a ready-made configuration for you. However, I suggest you try to figure it out. An example request for a search server - https://www.google.com/search?q=router+with+two+isp+connections+mikrotik&oq=router+with+two+isp+connections+mikrotik Or - https://www.goog...
by BrateloSlava
Wed Oct 26, 2022 4:07 pm
Forum: General
Topic: Firewall Rules - Efficient or not?
Replies: 7
Views: 1094

Re: Firewall Rules - Efficient or not?

The general rule for a firewall - at the beginning we describe allowing rules. And at the end - the rules for blocking all chains. There are a lot of extra rules that are associated with DNS traffic. You just need to block incoming traffic on the right ports from the WAN. It is necessary to try to ...
by BrateloSlava
Wed Oct 26, 2022 1:41 pm
Forum: Forwarding Protocols
Topic: OSPF 2 routers with 2 isp
Replies: 8
Views: 2241

Re: OSPF 2 routers with 2 isp

New User Pathway To Config Success

I think, that if you carefully read what is stated in this topic ... Many questions will disappear.

P.S.
As for me, I would solve your problem through traffic marking.
by BrateloSlava
Tue Oct 25, 2022 11:20 pm
Forum: General
Topic: CRS326-24S+2Q high cpu usage throttling network. Probably user config error
Replies: 15
Views: 1606

Re: CRS326-24S+2Q high cpu usage throttling network. Probably user config error

Quick follow up q before I look at this. This still doesn't explain the high CPU usage? What in the current config is so wrong that it causes this? And in what way is it wrong? I'm not sure exactly what you want to achieve from this switch. :lol: Low CPU load + maximum performance is only possible ...
by BrateloSlava
Tue Oct 25, 2022 9:24 pm
Forum: General
Topic: CRS326-24S+2Q high cpu usage throttling network. Probably user config error
Replies: 15
Views: 1606

Re: CRS326-24S+2Q high cpu usage throttling network. Probably user config error

If you need to route traffic from one network to another, then a switch is not the best choice. You just need a router. /interface list add name=LAN /interface list add name=WAN /interface vlan add comment="*** VLAN132 ***" interface=sfp-sfpplus24 name=vlan132 vlan-id=132 /ip address add a...
by BrateloSlava
Tue Oct 25, 2022 6:39 pm
Forum: General
Topic: CRS326-24S+2Q high cpu usage throttling network. Probably user config error
Replies: 15
Views: 1606

Re: CRS326-24S+2Q high cpu usage throttling network. Probably user config error

I looked at your configuration from the first post. It has errors. For example, you have enabled VLAN as a port in a bridge.

Draw a diagram of how you would like the network to work and how you would like to configure your switch.
by BrateloSlava
Tue Oct 25, 2022 6:09 pm
Forum: Forwarding Protocols
Topic: OSPF 2 routers with 2 isp
Replies: 8
Views: 2241

Re: OSPF 2 routers with 2 isp

I have 2 routers ...
Make an export of the current configuration. In text format. Remove all private information from there. And post it here.
by BrateloSlava
Tue Oct 25, 2022 5:55 pm
Forum: General
Topic: CRS326-24S+2Q high cpu usage throttling network. Probably user config error
Replies: 15
Views: 1606

Re: CRS326-24S+2Q high cpu usage throttling network. Probably user config error

But to enable the offloading in the current setup did not help.

Show
/interface/bridge/port/print

Look - Layer2 misconfiguration

Bridges on a single switch chip
by BrateloSlava
Tue Oct 25, 2022 5:46 pm
Forum: General
Topic: CRS326-24S+2Q high cpu usage throttling network. Probably user config error
Replies: 15
Views: 1606

Re: CRS326-24S+2Q high cpu usage throttling network. Probably user config error

is beeter to use a single bridge IMHO, one bridge is not the "best" solution. This is - the "only" solution. Only in single bridge mode will hardware offloading start working. This CPU has poor performance for such tasks, so the entire load must be handled by the switching chip....
by BrateloSlava
Mon Oct 24, 2022 2:03 pm
Forum: General
Topic: hap ac2 died after updating to 7.6? [SOLVED]
Replies: 5
Views: 1591

Re: hap ac2 died after updating to 7.6? [SOLVED]

IMHO, if the router reboots on its own - it is not in the correct (netinstall) mode. Perhaps - you need to hold down the reset button longer. https://help.mikrotik.com/docs/pages/viewpage.action?pageId=16351533#heading-Buttonsandjumpers Some topics: https://forum.mikrotik.com/viewtopic.php?t=168465 ...
by BrateloSlava
Mon Oct 24, 2022 1:01 pm
Forum: General
Topic: hap ac2 died after updating to 7.6? [SOLVED]
Replies: 5
Views: 1591

Re: hap ac2 died after updating to 7.6? [SOLVED]

"Messed up" the boot order on this (hAP ac2) router. Only Netinstall will help. Just yesterday I had a similar problem with hAP ac3, that arose due to a power failure. Try holding the reset button for 15 seconds until the indicator shows that the router is in netinstall mode. Then - reconn...
by BrateloSlava
Thu Oct 13, 2022 11:56 pm
Forum: General
Topic: Switch CRS112-8P-4S as a media converter [SOLVED]
Replies: 42
Views: 4401

Re: Switch CRS112-8P-4S as a media converter [SOLVED]

The problem has a completely normal solution. The load on the central processor did not exceed 25% with uTP traffic of 400 Mbps in one direction. Higher speeds could not be tested due to the limitations of the routers that I used. To test, I assembled the following kit: - Mikrotik hAP ac2 router (mt...
by BrateloSlava
Tue Oct 04, 2022 9:46 pm
Forum: Announcements
Topic: Newsletter 108
Replies: 84
Views: 46843

Re: Newsletter 108

... 3) No mistake, the hAP ax2 is clocked lower than hAP ax3, due to better cooling in the larger case of hAP ax3
Thanks for the info
by BrateloSlava
Tue Oct 04, 2022 1:44 pm
Forum: Announcements
Topic: Newsletter 108
Replies: 84
Views: 46843

Re: Newsletter 108

Screenshot_compare.png

Is this a mistake in the description or do both of these two routers support automatic CPU frequency change?
by BrateloSlava
Sat Oct 01, 2022 1:37 pm
Forum: General
Topic: Switch CRS112-8P-4S as a media converter [SOLVED]
Replies: 42
Views: 4401

Re: Switch CRS112-8P-4S as a media converter [SOLVED]

The question is whether it is worth the effort, i.e. whether management/monitoring of the device via IP is necessary or whether one-time configuration using the serial console is sufficient. @sindy It seems, that the answer to this question becomes fundamental in my problem. :) I'll do some more ex...
by BrateloSlava
Fri Sep 30, 2022 11:27 pm
Forum: General
Topic: Switch CRS112-8P-4S as a media converter [SOLVED]
Replies: 42
Views: 4401

Re: Switch CRS112-8P-4S as a media converter [SOLVED]

# sep/30/2022 10:06:24 by RouterOS 6.49.6 # software id = SZII-F003 # # model = CRS112-8P-4S /interface bridge add name=bridge1 protocol-mode=none /interface bridge port add bridge=bridge1 interface=sfp9 /interface bridge port add bridge=bridge1 interface=ether1 /interface bridge port add bridge=br...
by BrateloSlava
Fri Sep 30, 2022 8:16 pm
Forum: General
Topic: Switch CRS112-8P-4S as a media converter [SOLVED]
Replies: 42
Views: 4401

Re: Switch CRS112-8P-4S as a media converter [SOLVED]

@tangent Careful observation of the switch showed the fallacy of the solution that I wrote above. Everything works well, the load on the CPU is low. Until you start adding a separate port to manage the switch. That is, as long as I controlled the switch through the console port, everything worked p...
by BrateloSlava
Sat Sep 24, 2022 7:36 pm
Forum: General
Topic: Switch CRS112-8P-4S as a media converter [SOLVED]
Replies: 42
Views: 4401

Re: Switch CRS112-8P-4S as a media converter [SOLVED]

@BrateloSlava, what happens to CPU usage if you put that one "/ip firewall connection tracking..." rule back in? @tangent At the moment I have no way to check it. Only - next week. /ip firewall connection tracking set icmp-timeout=30s tcp-close-wait-timeout=1m tcp-established-timeout=1h t...
by BrateloSlava
Sat Sep 24, 2022 4:30 pm
Forum: General
Topic: Switch CRS112-8P-4S as a media converter [SOLVED]
Replies: 42
Views: 4401

Re: Switch CRS112-8P-4S as a media converter [SOLVED]

Solution is wrong: # Create new bridge /interface bridge add name=bridge1 protocol-mode=none /interface bridge port add bridge=bridge1 interface=sfp9 hw=yes /interface bridge port add bridge=bridge1 interface=ether1 hw=yes /interface bridge port add bridge=bridge1 interface=sfp10 hw=yes /interface ...
by BrateloSlava
Sat Sep 24, 2022 1:02 pm
Forum: General
Topic: Switch CRS112-8P-4S as a media converter [SOLVED]
Replies: 42
Views: 4401

Re: Switch CRS112-8P-4S as a media converter [SOLVED]

Currently, I have found CRS106-1C-5S - a certain analogue of my office switch (CRS112-8P-4S) and I am doing experiments on it. I make all settings through the console port. Some observations: I would like to note that, immediately after a "clean" installation of ROS via Netinstall, the CPU...
by BrateloSlava
Thu Sep 22, 2022 11:43 pm
Forum: General
Topic: Switch CRS112-8P-4S as a media converter [SOLVED]
Replies: 42
Views: 4401

Re: Switch CRS112-8P-4S as a media converter [SOLVED]

So maybe try the same first - disconnect the ISP-related ports and try to download an upgrade file using /tool fetch url=https://download.mikrotik.com/routeros/7.5/routeros-7.5-mipsbe.npk using the management bridge, watching the CPU load during the process. Some problem - free internal memory Scre...
by BrateloSlava
Thu Sep 22, 2022 8:18 pm
Forum: General
Topic: Switch CRS112-8P-4S as a media converter [SOLVED]
Replies: 42
Views: 4401

Re: Switch CRS112-8P-4S as a media converter [SOLVED]

... press the D key to take a snapshot. And then post three subsequent snapshots for each bridge. @sindy New rule /interface bridge filter add action=passthrough chain=input disabled=yes dst-mac-address=01:00:00:00:00:00/01:00:00:00:00:00 in-bridge=bridge-Maxnet add action=passthrough chain=input d...
by BrateloSlava
Thu Sep 22, 2022 8:05 pm
Forum: General
Topic: Switch CRS112-8P-4S as a media converter [SOLVED]
Replies: 42
Views: 4401

Re: Switch CRS112-8P-4S as a media converter [SOLVED]

@rextended
The documentation for this switch (CRS1xx/2xx series switches) has an ACL rules section. Is it possible that using these rules it is necessary to filter traffic between ports? Allow forwarding what you want and discard the rest.
by BrateloSlava
Thu Sep 22, 2022 4:39 pm
Forum: General
Topic: Switch CRS112-8P-4S as a media converter [SOLVED]
Replies: 42
Views: 4401

Re: Switch CRS112-8P-4S as a media converter [SOLVED]

@BrateloSlava , instead of running /tool sniffer , it is probably more useful to add the following bridge filter rules: interface bridge filter add chain=input in-bridge=bridge-name dst-mac-address=ff:ff:ff:ff:ff:ff/ff:ff:ff:ff:ff:ff action=passthrough interface bridge filter add chain=input in-bri...
by BrateloSlava
Thu Sep 22, 2022 8:47 am
Forum: General
Topic: Switch CRS112-8P-4S as a media converter [SOLVED]
Replies: 42
Views: 4401

Re: Switch CRS112-8P-4S as a media converter [SOLVED]

/interface ethernet switch port-isolation set ether1 forwarding-override=sfp9 set sfp9 forwarding-override=ether1 set ether2 forwarding-override=ether3,sfp10 set ether3 forwarding-override=ether2,sfp10 set sfp10 forwarding-override=ether2,ether3 The main idea is clear. Although these port isolation...
by BrateloSlava
Wed Sep 21, 2022 11:12 pm
Forum: General
Topic: Switch CRS112-8P-4S as a media converter [SOLVED]
Replies: 42
Views: 4401

Re: Switch CRS112-8P-4S as a media converter [SOLVED]

Why use two cable to connect same ISP on RB4011??? Probably the problem is also on other side that the cable are on loop.... Why another cable to connect back the RB4011??? 4 cable for do the work of two???... Two providers. The first - provides one IP address, the second - two. Two addresses - for...
by BrateloSlava
Wed Sep 21, 2022 2:00 pm
Forum: General
Topic: Switch CRS112-8P-4S as a media converter [SOLVED]
Replies: 42
Views: 4401

Re: Switch CRS112-8P-4S as a media converter [SOLVED]

The results of the experiments are negative. Note 1 : I strongly recommend, that you have a console cable for recovery at hand, when experimenting with setting up switch chips. Current (initial) configuration: 3 bridges. The first is provider 1 (2 ports), the second is provider 2 (3 ports), the thi...
by BrateloSlava
Sun Sep 18, 2022 11:22 pm
Forum: Beginner Basics
Topic: SSTP with EoIP
Replies: 4
Views: 659

Re: SSTP with EoIP

Why not use wireguard
Most likely because, for many, it is easier to configure L2TP / SSTP
by BrateloSlava
Sun Sep 18, 2022 10:59 pm
Forum: Beginner Basics
Topic: SSTP with EoIP
Replies: 4
Views: 659

Re: SSTP with EoIP

  • Why is the word EoIP in the title of the topic?
  • Make an export in text format settings. Remove private information from the file and post it here.
by BrateloSlava
Wed Sep 14, 2022 11:18 pm
Forum: General
Topic: Switch CRS112-8P-4S as a media converter [SOLVED]
Replies: 42
Views: 4401

Re: Switch CRS112-8P-4S as a media converter [SOLVED]

... What I don't like about the setup is that STP is permitted on the bridge - depending on how paranoid the ISP admins are, you may or may not break their own spanning tree topology by making your CRS a root bridge. So I'd rather disable it on the bridge(s) completely. The current config file look...
by BrateloSlava
Wed Sep 14, 2022 9:23 pm
Forum: General
Topic: Switch CRS112-8P-4S as a media converter [SOLVED]
Replies: 42
Views: 4401

Re: Switch CRS112-8P-4S as a media converter [SOLVED]

It's your device, it's your problem ... I'm not going to argue with you.

I didn't mean that your answer is a mistake. I meant that ROS 7.5 contains a bug.
by BrateloSlava
Wed Sep 14, 2022 8:12 pm
Forum: General
Topic: Switch CRS112-8P-4S as a media converter [SOLVED]
Replies: 42
Views: 4401

Re: Switch CRS112-8P-4S as a media converter [SOLVED]

Screenshot_HO.png
It is possible, that this is a mistake.
by BrateloSlava
Wed Sep 14, 2022 5:41 pm
Forum: General
Topic: Switch CRS112-8P-4S as a media converter [SOLVED]
Replies: 42
Views: 4401

Switch CRS112-8P-4S as a media converter [SOLVED]

The connection diagram looks like this: two optical connections to two Internet providers are connected to the SFP9 and SFP10 ports of the CRS112-8P-4S switch CRS112-8P-4S has two bridges - SFP9+Ether1=Bridge-ISP1, SFP10+Ether2+Ether3=Bridge-ISP2 _Office.png That is, CRS112-8P-4S is used as a media ...
by BrateloSlava
Tue Sep 13, 2022 8:37 pm
Forum: Scripting
Topic: Removing an IP address from one list in another list [SOLVED]
Replies: 2
Views: 1090

Re: Removing an IP address from one list in another list [SOLVED]

The solution looks very simple. Thank you so much. :)
by BrateloSlava
Tue Sep 13, 2022 5:47 pm
Forum: Scripting
Topic: Removing an IP address from one list in another list [SOLVED]
Replies: 2
Views: 1090

Removing an IP address from one list in another list [SOLVED]

There is a list of DNS names of routers, that are considered trusted. The list name is AllowedIP . The list is filled with DNS names because the provider allocates dynamic IP addresses. DNS names of this list = IP -> Cloud -> DNS Name. There is a dynamic list of IP addresses, that are temporarily bl...
by BrateloSlava
Wed Aug 31, 2022 5:06 pm
Forum: Announcements
Topic: v7.5 [stable] is released!
Replies: 219
Views: 69594

Re: v7.5 [stable] is released!

*) capsman - added randomized range option for "reselect-interval" parameter (CLI only);
Example, please.
by BrateloSlava
Thu Aug 25, 2022 6:50 pm
Forum: Scripting
Topic: Black list for failed login to IPSec VPN
Replies: 62
Views: 34189

Re: Black list for failed login to IPSec VPN

Is it possible to modify the script by adding a check, that the blocked IP address is not in the exclusion list? I will answer myself. It is enough to slightly change this line: :if ([:len [/ip fire addr find where list=IPSEC address=$logIp]] < 1) do={ To this: :if ([:len [/ip fire addr find where ...
by BrateloSlava
Tue Aug 23, 2022 10:22 pm
Forum: General
Topic: IPSec - phase1 negotiation failed due to time up
Replies: 1
Views: 8582

IPSec - phase1 negotiation failed due to time up

In a highly simplified form, the network diagram looks like this: net-diag.jpg All routers have their own local networks. "Main" routers have 3 Internet connections. All routers build 2 VPN connections for redundancy. The third Internet connections of the "main" routers perform s...
by BrateloSlava
Wed Aug 17, 2022 11:09 am
Forum: Beginner Basics
Topic: Filter rule
Replies: 5
Views: 602

Re: Filter rule

Install a DHCP server. Create a range of IP addresses, that can access the Internet. Bind the IP address to the MAC of the device, that connects and receives the address.
by BrateloSlava
Tue Aug 16, 2022 12:01 pm
Forum: Beginner Basics
Topic: Filter rule
Replies: 5
Views: 602

Re: Filter rule

You will be able to block something only, when you learn to distinguish between devices. For example, allocate a separate range of IP addresses for phones. And for this range already perform some kind of blocking. But you will not be able to determine in any way, which application from this device i...
by BrateloSlava
Tue Aug 16, 2022 10:55 am
Forum: Wireless Networking
Topic: wifi2 android key handshake timeout
Replies: 5
Views: 1967

Re: wifi2 android key handshake timeout

Export the settings in the text format of your router. Delete all private information. Post it here on the forum. In code tags.
by BrateloSlava
Mon Aug 15, 2022 9:52 pm
Forum: Forwarding Protocols
Topic: OSPF over L2TP not establishing after ROS7 upgrade. [SOLVED]
Replies: 6
Views: 2955

Re: OSPF over L2TP not establishing after ROS7 upgrade. [SOLVED]

  1. In the 7th version, the name of the interface most often does not need to be specified.
  2. Do you have similar settings on both sides of the vpn tunnel?
by BrateloSlava
Sun Aug 14, 2022 6:21 pm
Forum: Forwarding Protocols
Topic: Name Servers in DNS Static
Replies: 5
Views: 3680

Re: Name Servers in DNS Static

Export the router settings in text format, delete all private information and put it here in code tags. Without this, no one can help you. Just in case, I'll show you how I did it. Until I understand, this is what you need or not. /ip dns set allow-remote-requests=yes cache-max-ttl=5m max-concurrent...
by BrateloSlava
Sun Aug 14, 2022 6:06 pm
Forum: Forwarding Protocols
Topic: OSPF over L2TP not establishing after ROS7 upgrade. [SOLVED]
Replies: 6
Views: 2955

Re: OSPF over L2TP not establishing after ROS7 upgrade. [SOLVED]

Changes in OSPF settings, that occurred during the transition from version 6 to version 7, have been discussed on the forum several times already. I recommend deleting your current settings and doing the following: /routing id add disabled=no id=172.22.99.254 name=id-slava select-dynamic-id="&q...
by BrateloSlava
Sun Aug 14, 2022 5:57 pm
Forum: General
Topic: DDoS protection
Replies: 2
Views: 839

Re: DDoS protection

I recommend you take a look at this
by BrateloSlava
Thu Aug 11, 2022 10:53 pm
Forum: Wireless Networking
Topic: Weird behavior with CAPsMAN (low rates when clients connected to WiFi)
Replies: 7
Views: 1604

Re: Weird behavior with CAPsMAN (low rates when clients connected to WiFi)

Which vendor did u decide to go? Just curious

The equipment is a bit of a different price range. Producer - Ruckus Wireless.
by BrateloSlava
Mon Aug 08, 2022 6:01 pm
Forum: Beginner Basics
Topic: Migration from hAP-ac2 to RB5009ug vlan question [SOLVED]
Replies: 9
Views: 1347

Re: Migration from hAP-ac2 to RB5009ug vlan question [SOLVED]

There is no difference in settings for VLAN filtering at the bridge level. In your case, another switch chip model will not affect. The only thing is, that there is no Wi-Fi on the new router, so the settings will need to be changed a little.
by BrateloSlava
Mon Aug 08, 2022 4:35 pm
Forum: Scripting
Topic: Black list for failed login to IPSec VPN
Replies: 62
Views: 34189

Re: Black list for failed login to IPSec VPN

Is it possible to modify the script by adding a check, that the blocked IP address is not in the exclusion list? There are several trusted routers, that are interconnected via IPIP(EOIP)+IpSec. Periodically, a situation arises, when the connections between these routers are interrupted and the proce...
by BrateloSlava
Sun Aug 07, 2022 3:09 pm
Forum: Beginner Basics
Topic: wifi does not work
Replies: 7
Views: 2672

Re: wifi does not work

I don't like default settings, so I would set it all up in a few steps. This is the base option. After verifying that everything is working as expected, you should optimize the WiFi channel selection and tweak the firewall rules a bit. Everything, that I wrote below, is given only as a general guide...
by BrateloSlava
Fri Aug 05, 2022 5:47 pm
Forum: General
Topic: WireGuard DualWan
Replies: 27
Views: 2346

Re: WireGuard DualWan

For a correct configuration, it is necessary to block the possibility of building a tunnel not from "your" interface. About route. Try to change, like this example: /ip route add check-gateway=ping disabled=no distance=50 dst-address=0.0.0.0/0 gateway=IP_of_GW1 routing-table=route-WAN-1 /i...
by BrateloSlava
Fri Aug 05, 2022 2:34 pm
Forum: General
Topic: WireGuard DualWan
Replies: 27
Views: 2346

Re: WireGuard DualWan

Am I understanding your settings correctly? 1. Office 1 has two internet connections. They are configured as a primary and a backup. Office 2 has one internet connection. 2. The main internet connection in Office 1 is not, for some reason, able to establish a VPN connection to Office 2. 3. You are t...
by BrateloSlava
Wed Aug 03, 2022 12:08 pm
Forum: Wireless Networking
Topic: Should I switch my APs from Ubiquiti to MT
Replies: 27
Views: 5646

Re: Should I switch my APs from Ubiquiti to MT

Question remains: will it work with capsman ? Given, that now the WAVE2 package is only for devices with 256 MB of RAM. Most likely some new version of CAPsMAN will appear. With support exclusively for new devices. For example - Wi-Fi 6 is only for devices with 1GB of RAM. And only for such devices...
by BrateloSlava
Wed Aug 03, 2022 11:47 am
Forum: Wireless Networking
Topic: Should I switch my APs from Ubiquiti to MT
Replies: 27
Views: 5646

Re: Should I switch my APs from Ubiquiti to MT

I am waiting for wifi6 from MT, then will learn capsman.
It should have been a long time ago to write what you need. :lol:

hAP AX2 (WiFi 6)
by BrateloSlava
Wed Aug 03, 2022 11:01 am
Forum: General
Topic: S-RJ01
Replies: 9
Views: 1104

Re: S-RJ01

I have discovered the problem, it will only communicate with gigabit ports on other devices ...
Apparently this module does not work with all devices. I tried to connect it to my old switch - Allied Telesis GS950/16. The result is negative. 1000X SFP Ports
by BrateloSlava
Tue Aug 02, 2022 12:49 pm
Forum: Beginner Basics
Topic: CAPsMAN with CAP onboard [SOLVED]
Replies: 11
Views: 1704

Re: CAPsMAN with CAP onboard [SOLVED]

About the use of VLAN in general. The implementation of VLAN on switch chips makes sense only on "real" switches. CRS type. Where hardware offloading really gives noticeable results. For home conditions, as well as for small offices - it makes no sense. Wi-Fi modules are not connected to s...
by BrateloSlava
Mon Aug 01, 2022 6:37 pm
Forum: General
Topic: How to disable udplite ?
Replies: 15
Views: 2360

Re: How to disable udplite ?

I also became interested. And I decided to turn it off.

Config:

[removed]

Where is the mistake?
Attempts to disable one at a time or all at once - the result is the same.
by BrateloSlava
Mon Aug 01, 2022 6:14 pm
Forum: General
Topic: Mikrotik routerboard 1036 hotspot, Users, User Profiles, Active, Host, ip Bindings How can I draw tables with Ms Excel e
Replies: 7
Views: 972

Re: Mikrotik routerboard 1036 hotspot, Users, User Profiles, Active, Host, ip Bindings How can I draw tables with Ms Exc

What does your question have to do with the problems of the devices of this manufacturer? Or to the difficulties with setting it up.
by BrateloSlava
Sun Jul 31, 2022 10:17 pm
Forum: Wireless Networking
Topic: Directional WiFi for car park
Replies: 18
Views: 2174

Re: Directional WiFi for car park

For example, Tesla is "very picky" about Wi-Fi in the parking space.
by BrateloSlava
Sun Jul 31, 2022 10:13 pm
Forum: Wireless Networking
Topic: Should I switch my APs from Ubiquiti to MT
Replies: 27
Views: 5646

Re: Should I switch my APs from Ubiquiti to MT

Yes, pure talker about nothing.
by BrateloSlava
Sun Jul 31, 2022 8:09 pm
Forum: Beginner Basics
Topic: how to reset factory 1100 ahx2 [SOLVED]
Replies: 7
Views: 1860

Re: how to reset factory 1100 ahx2 [SOLVED]

Is the router case sealed with a warranty seal or what?
by BrateloSlava
Sun Jul 31, 2022 8:03 pm
Forum: General
Topic: VLANs on a Bridge instead of Eth Interface?
Replies: 10
Views: 4940

Re: VLANs on a Bridge instead of Eth Interface?

If we already talk about performance, IMHO, you should solve the problem - VLAN via switch chips. I have significantly reduced the CPU load on the switches after such a transition. Currently, my device workflow is very similar to this - Manual:CRS1xx/2xx VLANs with Trunks . 2 gigabit channels to the...
by BrateloSlava
Sun Jul 31, 2022 6:58 pm
Forum: Wireless Networking
Topic: Should I switch my APs from Ubiquiti to MT
Replies: 27
Views: 5646

Re: Should I switch my APs from Ubiquiti to MT

... So back to my prior point... "It doesn't matter what it costs, if it doesn't work!" ...
The story you describe is certainly interesting. Another supplier ... I asked you to answer - what other (not MT or UniF) supplier of Wi-Fi equipment do you specifically recommend.
by BrateloSlava
Sat Jul 30, 2022 6:40 pm
Forum: Wireless Networking
Topic: Should I switch my APs from Ubiquiti to MT
Replies: 27
Views: 5646

Re: Should I switch my APs from Ubiquiti to MT

Why would you pay that much more for the router board to run that crap you could put on a cloud key for less??? At this time, for most installations, I don't plan to purchase anything other, than the RB5009UG+S+IN. Therefore, why not try connecting a USB flash drive. And don't try run a container o...
by BrateloSlava
Sat Jul 30, 2022 5:52 pm
Forum: Beginner Basics
Topic: Wireguard client to access LAN [SOLVED]
Replies: 3
Views: 3286

Re: Wireguard client to access LAN [SOLVED]

I don't see a rule, that allows access to the INPUT chain from your Wireguard interface.
;;; defconf: drop all not coming from LAN
      chain=input action=drop in-interface-list=!LAN 
by BrateloSlava
Sat Jul 30, 2022 5:24 pm
Forum: Wireless Networking
Topic: Should I switch my APs from Ubiquiti to MT
Replies: 27
Views: 5646

Re: Should I switch my APs from Ubiquiti to MT

It's annoying they are adding features like docker containers while still not fixing wifi issues.
A very useful thing for me for a future project of a new network is a Unifi Controller in a container on MT router. :lol:
by BrateloSlava
Sat Jul 30, 2022 4:47 pm
Forum: Beginner Basics
Topic: Accessing my Switch via VLAN
Replies: 22
Views: 1882

Re: Accessing my Switch via VLAN

/interface bridge vlan
add bridge=bridge tagged="bridge,ether24_opnsense2,ether23_opnsense1,ether21_SynoBond1,sfp-sfpplus3_proxmox,sfp-sfpplus1_wifi" untagged=ether2_nosbox,\
ether3_IPMI-edgebox,ether1_edgebox vlan-ids=10
Some errors. ether21_SynoBond1 is a part of Syno_Bond
by BrateloSlava
Sat Jul 30, 2022 4:42 pm
Forum: Wireless Networking
Topic: Should I switch my APs from Ubiquiti to MT
Replies: 27
Views: 5646

Re: Should I switch my APs from Ubiquiti to MT

I have two "places" that have almost the same number of Wi-Fi points. In both "places" there are external and internal access points. Option from Ubiquiti - it's set up once and forgot. But the version from MT - is associated with a constant "struggle". IMHO.
by BrateloSlava
Sat Jul 30, 2022 4:21 pm
Forum: Beginner Basics
Topic: Accessing my Switch via VLAN
Replies: 22
Views: 1882

Re: Accessing my Switch via VLAN

Sometimes. a big problem is to deal with the settings that are made through QuickSet. I don't like, it when I don't understand how it works. Or how it doesn't work. So, let's look at the configuration file. /interface bridge name=bridge vlan-filtering=yes We have a bridge, on which filtering is per...
by BrateloSlava
Sat Jul 30, 2022 3:18 pm
Forum: Beginner Basics
Topic: Accessing my Switch via VLAN
Replies: 22
Views: 1882

Re: Accessing my Switch via VLAN

I don't think so...
Please, write the name of the interface (port in the switch), that connects this switch to the router. That is, which port is uplinked.
by BrateloSlava
Sat Jul 30, 2022 12:40 pm
Forum: Beginner Basics
Topic: Accessing my Switch via VLAN
Replies: 22
Views: 1882

Re: Accessing my Switch via VLAN

Maybe I'm wrong, but you may add "bridge" interface as "tagged". As example: /interface bridge vlan add bridge=bridge1 tagged=bridge1,ether1 untagged=ether2 vlan-ids=19 One more thing. As far as I understand, you connect some ports with MTU 9000. IMHO, you need to increase L2MTU ...
by BrateloSlava
Sat Jul 30, 2022 10:53 am
Forum: General
Topic: Web server on remote location via SSTP
Replies: 4
Views: 1067

Re: Web server on remote location via SSTP

Does the ping command pass from the office network to the internal address of this server? Routing between local subnets of office and shop works? Let's assume, that the internal address of this server is 192.168.88.80. In this case, you need something like this on the router in the office: /ip fire...
by BrateloSlava
Fri Jul 29, 2022 11:02 pm
Forum: Wireless Networking
Topic: Slow speed (WiFi/LTE)
Replies: 12
Views: 1724

Re: Slow speed (WiFi/LTE)

by BrateloSlava
Fri Jul 29, 2022 10:06 pm
Forum: Beginner Basics
Topic: Accessing my Switch via VLAN
Replies: 22
Views: 1882

Re: Accessing my Switch via VLAN

It is unlikely, that anyone will be able to help you with anything, if you do not publish a backup copy of your switch settings in text form. By removing all non-public information from this backup.
by BrateloSlava
Fri Jul 29, 2022 7:47 pm
Forum: Beginner Basics
Topic: Help needed to configure VLANs using switch features [SOLVED]
Replies: 8
Views: 1505

Re: Help needed to configure VLANs using switch features [SOLVED]

Nope, I've tried this already. This example shows 3 tagged VLANs via ether2 and I would need both tagged and untagged traffic. Can't get this to work...
Apparently I don't understand something. :D Isn't that what you need?
Screenshot_hybrid.png
by BrateloSlava
Fri Jul 29, 2022 7:32 pm
Forum: Beginner Basics
Topic: Help needed to configure VLANs using switch features [SOLVED]
Replies: 8
Views: 1505

Re: Help needed to configure VLANs using switch features [SOLVED]

This does not answer the question. Show me which link shows how to pass both untagged and tagged traffic? :)
Maybe this - https://wiki.mikrotik.com/wiki/Manual:S ... rid_Ports)
by BrateloSlava
Fri Jul 29, 2022 6:15 pm
Forum: General
Topic: Routing Traffic Over PTMP [SOLVED]
Replies: 3
Views: 792

Re: Routing Traffic Over PTMP [SOLVED]

If everything works for you when connected by wire, then routes, etc. configured correctly. Check the operation of the radio part. 1. "Client isolation" is set to OFF on LTU Rocket? 2. Ping from MIkrotik "C" to LTU Rocket (from 192.168.1.252 to 192.168.1.254, as I understand) suc...
by BrateloSlava
Fri Jul 29, 2022 5:27 pm
Forum: Wireless Networking
Topic: Slow speed (WiFi/LTE)
Replies: 12
Views: 1724

Re: Slow speed (WiFi/LTE)

2. what is wrong with country, what is it correct to set? 3. What is superchannel, how to set correctly? :) 4. How do i find supported LTE channels? Try to set the settings like mine. Only in them you should change the country to "your own", etc. My mobile operator is Kyivstar. This is ho...
by BrateloSlava
Fri Jul 29, 2022 4:15 pm
Forum: Wireless Networking
Topic: Slow speed (WiFi/LTE)
Replies: 12
Views: 1724

Re: Slow speed (WiFi/LTE)

/interface wireless security-profiles set [ find default=yes ] authentication-types=wpa-psk,wpa2-psk mode=dynamic-keys supplicant-identity=MikroTik This ( wpa-psk ) is probably not needed. My "basic" settings for WiFi on this AP is: /interface wireless set [ find default-name=wlan1 ] adap...
by BrateloSlava
Fri Jul 29, 2022 2:31 pm
Forum: General
Topic: [AC2] Mikrotik v7 soft slow performance OpenVPN with WAN with VLAN
Replies: 2
Views: 1691

Re: [AC2] Mikrotik v7 soft slow performance OpenVPN with WAN with VLAN

I haven't done performance testing of the OVPN since the addition of hardware acceleration in version 7.2. However, prior to the release of this version, OVPN showed very poor performance results. You can find the practical results for this router when using other VPN protocols in the topic WireGuar...
by BrateloSlava
Fri Jul 29, 2022 12:50 pm
Forum: General
Topic: Block IP list - Performance toll | other solutions
Replies: 12
Views: 1876

Re: Block IP list - Performance toll | other solutions

Ohh... I see something on that picture... :cry:
Yes, I confess... 8) I use it wherever I can. Therefore, I did not hide it, because there is an effect. :D
by BrateloSlava
Fri Jul 29, 2022 12:44 pm
Forum: General
Topic: How to increase remote connection security
Replies: 5
Views: 624

Re: How to increase remote connection security

IMHO, any attempt at such port remapping is pointless. The new port number is determined very quickly and the penetration attempt continues. It is highly recommended to use VPN to access internal network resources.
by BrateloSlava
Fri Jul 29, 2022 12:29 pm
Forum: General
Topic: Block IP list - Performance toll | other solutions
Replies: 12
Views: 1876

Re: Block IP list - Performance toll | other solutions

Before do that, ask your provider if block already same IPs
On the routers, that I "look after", I definitely see the point in cutting off the excess.
Screenshot_RAW.png
by BrateloSlava
Fri Jul 29, 2022 12:02 pm
Forum: General
Topic: Block IP list - Performance toll | other solutions
Replies: 12
Views: 1876

Re: Block IP list - Performance toll | other solutions

@mkx, @chechito and @anav
Do I understand correctly, that you do not recommend using separate blocking rules for lists of IP addresses, which can be obtained, for example, here - https://github.com/firehol/blocklist-ipsets/.
For home routers.
by BrateloSlava
Thu Jul 28, 2022 9:38 pm
Forum: General
Topic: Block IP list - Performance toll | other solutions
Replies: 12
Views: 1876

Re: Block IP list - Performance toll | other solutions

Use RAW. Example:
/ip firewall raw add action=drop chain=prerouting in-interface-list=WAN src-address-list=blacklist
You can try reducing the list. https://tehnoblog.org/ip-tools/ip-address-aggregator/

As for me:
Screenshot_blacklisr_size.png
by BrateloSlava
Thu Jul 28, 2022 11:21 am
Forum: General
Topic: Wireguard roadwarrior to IPsec S2S
Replies: 9
Views: 898

Re: Wireguard roadwarrior to IPsec S2S

Please, show
/interface wireguard peers add allowed-address=
Server:
Allowed Address - here you should specify 0.0.0.0/0.
Client
AllowedIPs = 0.0.0.0/0
by BrateloSlava
Thu Jul 28, 2022 11:03 am
Forum: Wireless Networking
Topic: CAPSMAN WAP problem
Replies: 4
Views: 680

Re: CAPSMAN WAP problem

Please, post your latest config /export wihout any public IP and serial numbers, and passwords information.
by BrateloSlava
Thu Jul 28, 2022 10:56 am
Forum: General
Topic: SSTP Site-to-Site VPN
Replies: 1
Views: 709

Re: SSTP Site-to-Site VPN

Have you tried google searching for the phrase "mikrotik sstp site to site vpn"?
by BrateloSlava
Wed Jul 27, 2022 10:48 pm
Forum: Beginner Basics
Topic: RB2011, 2 VLANs & VPN [SOLVED]
Replies: 16
Views: 2011

Re: RB2011, 2 VLANs & VPN [SOLVED]

Do you want to get a ready-made configuration for the router? Without doing any work yourself?
by BrateloSlava
Wed Jul 27, 2022 3:23 pm
Forum: Forwarding Protocols
Topic: Control OSPF static redistribution (ROS v6 vs v7)
Replies: 11
Views: 5019

Re: Control OSPF static redistribution (ROS v6 vs v7)

@JoshDi It seems to me, that incoming and outgoing filters should be used only when fine-tuning is necessary. Therefore, in most cases, I refused this option: /routing filter rule add chain=ospf-out comment="redistribute default route - never, redistribute static routes - as type 1" disabl...
by BrateloSlava
Tue Jul 26, 2022 11:32 pm
Forum: Wireless Networking
Topic: 2.4 ghz AP for 2000 users
Replies: 8
Views: 1275

Re: 2.4 ghz AP for 2000 users

Very High Density 802.11ac Networks Validated Reference Design ...
A very expensive and very high performance solution to the problem of multiple WiFi connections.
by BrateloSlava
Tue Jul 26, 2022 10:17 pm
Forum: Forwarding Protocols
Topic: Control OSPF static redistribution (ROS v6 vs v7)
Replies: 11
Views: 5019

Re: Control OSPF static redistribution (ROS v6 vs v7)

As for me
/routing id add disabled=no id=172.22.1.254 name=id-tp select-dynamic-id=""
/routing ospf instance add disabled=no name=rt-tp originate-default=never redistribute=static router-id=id-tp
by BrateloSlava
Tue Jul 26, 2022 7:42 pm
Forum: Wireless Networking
Topic: 2.4 ghz AP for 2000 users
Replies: 8
Views: 1275

Re: 2.4 ghz AP for 2000 users

... If you have a 50m × 50m place it's not really that big, but 2000 users on 50m × 50m are too many...
Not even the best competitor can cover everything for 2000 users with a single device...
There is some kind of prison. :D
by BrateloSlava
Tue Jul 26, 2022 1:50 pm
Forum: General
Topic: WireGuard vs IPSec performance
Replies: 14
Views: 12856

Re: WireGuard vs IPSec performance

So how about IPSec? Have you tried that? From what I can see 2011 doesn't support hardware acceleration. Presumably it would be even worse for CPU usage than WireGuard.
2011 + IPSec
Screenshot-2011-ipsec-speed-10-12_mbit-cpu-83-percent.png
by BrateloSlava
Mon Jul 25, 2022 10:52 pm
Forum: General
Topic: WireGuard vs IPSec performance
Replies: 14
Views: 12856

Re: WireGuard vs IPSec performance

... It somewhat works if you stick with ROS6 + fasttrack, but that's about it.
It copes well with the switch + access point function in the 2.4 range. :)
by BrateloSlava
Mon Jul 25, 2022 4:42 pm
Forum: General
Topic: WireGuard vs IPSec performance
Replies: 14
Views: 12856

Re: WireGuard vs IPSec performance

I will say right away - 2011 and WireGuard = a big problem even with constant traffic of 10-15 Mbps. CPU usage is high. Screenshot_2011-wireguard.png Screenshot_2011-ipip-no-ipsec.png "Gradually" I'm changing the "outdated" 2011 to 4011, hAP ac2 and hAP ac3 in the offices. All of...
by BrateloSlava
Mon Jul 25, 2022 3:46 pm
Forum: General
Topic: multiple gateways in RouterOS 7 [SOLVED]
Replies: 3
Views: 3110

Re: multiple gateways in RouterOS 7 [SOLVED]

can you provide me with an example please? Example: /ip route add check-gateway=arp disabled=no distance=80 dst-address=0.0.0.0/0 gateway=1.1.1.254 /ip route add check-gateway=arp disabled=no distance=80 dst-address=0.0.0.0/0 gateway=2.2.2.254 /ip route add check-gateway=arp disabled=no distance=80...
by BrateloSlava
Mon Jul 25, 2022 2:11 pm
Forum: Wireless Networking
Topic: CapsMan on one of the APs?
Replies: 17
Views: 1983

Re: CapsMan on one of the APs?

The problem is that there are not enough access points for even coverage... Thanks for the answer. It looks like, you and I live in the same city. :lol: About my problems with WiFi, office and voice calls via messenger. As I wrote earlier - problems are exclusively with audio calls through instant ...
by BrateloSlava
Sat Jul 23, 2022 6:12 pm
Forum: Wireless Networking
Topic: CapsMan on one of the APs?
Replies: 17
Views: 1983

Re: CapsMan on one of the APs?

At home I have 2 access points:cAP AC and wAP AC LTE6 Kit. And there are no noticeable problems. The signal strength of 2.4 GHz is 5 points lower than that of 5 GHz. Problems are observed in the office. The configuration of the rooms does not allow optimal placement of access points there. Employees...
by BrateloSlava
Sat Jul 16, 2022 9:56 pm
Forum: Wireless Networking
Topic: Best wireless AP for 500-1000 mbit MT connection.
Replies: 35
Views: 3837

Re: Best wireless AP for 500-1000 mbit MT connection.

I'm wondering... Will the thread starter try to achieve 100+ Mbps under ideal conditions? No walls between rooms, etc.?
by BrateloSlava
Thu Jul 07, 2022 10:11 am
Forum: General
Topic: RDP brute force prevention...
Replies: 6
Views: 1071

Re: RDP brute force prevention...

To be honest, it is useless to fight with the means of ROS against attempts to penetrate through redirected ports. IMHO, of course. I forced everyone to use VPN via L2TP / SSTP / ... Otherwise, all the protection work turned into hell. After connecting to a VPN, users, depending on their VPN profile...
by BrateloSlava
Sun Jul 03, 2022 5:52 pm
Forum: Forwarding Protocols
Topic: How to filter routes that are advertised via OSPF? [SOLVED]
Replies: 4
Views: 1306

Re: How to filter routes that are advertised via OSPF? [SOLVED]

I'm curious.. How does it "break" ospf? Does adjacency drop? Or just all OSPF routes disappear?
Special for you. :D
Before.png
After.png
by BrateloSlava
Sun Jul 03, 2022 10:42 am
Forum: Forwarding Protocols
Topic: How to filter routes that are advertised via OSPF? [SOLVED]
Replies: 4
Views: 1306

How to filter routes that are advertised via OSPF? [SOLVED]

There are several networks, that are connected via L2TP/SSTP/IPIP/etc. OSPF configured. ROS 7.3.1 Everything is fine. Some routers redistribute their static routes. Question : how can I set up filtering of these advertised routes on some routers? For example: there is a router R1 that redistributes ...
by BrateloSlava
Wed Jun 22, 2022 9:42 am
Forum: Announcements
Topic: v7.3 and v7.3.1 [stable] is released!
Replies: 269
Views: 81239

Re: v7.3 and v7.3.1 [stable] is released!

Not needed, IMO
Screenshot_hEX.png
by BrateloSlava
Tue Jun 21, 2022 8:34 pm
Forum: Announcements
Topic: v7.3 and v7.3.1 [stable] is released!
Replies: 269
Views: 81239

Re: v7.3 and v7.3.1 [stable] is released!

I used the instructions L3 Hardware Offloading for my CRS326-24G-2S+. ROS 7.3.1 After saving the configuration data in text form ( /export compact terse show-sensitive file=xxx ) , there is no information in the file about l3hw on all switch ports. Only data about switch: /interface ethernet switch ...
by BrateloSlava
Tue Jun 21, 2022 3:31 pm
Forum: Announcements
Topic: v7.3 and v7.3.1 [stable] is released!
Replies: 269
Views: 81239

Re: v7.3 and v7.3.1 [stable] is released!

Today I updated my CRS326-24G-2S+ to 7.3.1. Something wrong?

Info from site:
Screenshot_site.png
Info from WinBox:
Screenshot_winbox.png
by BrateloSlava
Mon May 30, 2022 2:30 pm
Forum: Announcements
Topic: MikroTik Devices Controller
Replies: 332
Views: 238960

Re: MikroTik Devices Controller

Dude has the ability to specify a "parent" for the current device. With centralized management, it is necessary to check the entire chain of "parents" before rebooting during an update. So, that there is no situation, when the "parent" has already downloaded the update ...
by BrateloSlava
Mon May 16, 2022 1:25 pm
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 81948

Re: v7.2.2 [stable] and v7.2.3 [stable] are released!

Good afternoon!
Just now I noticed, that the display of the CPU frequency is "lost" after update.
Screenshot_4011.png
by BrateloSlava
Wed Mar 30, 2022 8:45 am
Forum: Announcements
Topic: v7.1.4 and v7.1.5 is released!
Replies: 202
Views: 40113

Re: v7.1.4 and v7.1.5 is released!

How I upgraded my devices , which have 16 MB of internal memory , from version 6 to version 7. For example, cAP ac, hAP ac2 and etc. Made a backup. Text and binary. Disabled/stopped WiFi interfaces. Removed ALL packages from the device except these: dhcp, security and system. Updated to version 7 in...
by BrateloSlava
Sat Mar 26, 2022 8:21 am
Forum: Forwarding Protocols
Topic: Control OSPF static redistribution (ROS v6 vs v7)
Replies: 11
Views: 5019

Re: Control OSPF static redistribution (ROS v6 vs v7)

However, one problem remained. Host A (172.22.31.254, ROS 6.49.5). Host B (172.22.99.254, ROS 7.1.5). Ping from A to B - working. But ping from B to A - not. I will answer myself . :D Given, that on devices with version 6.49.5, I use the PTMP type - changing for devices with version 7.1.5 to PTMP B...
by BrateloSlava
Fri Mar 25, 2022 4:40 pm
Forum: Forwarding Protocols
Topic: Control OSPF static redistribution (ROS v6 vs v7)
Replies: 11
Views: 5019

Re: Control OSPF static redistribution (ROS v6 vs v7)

"redistribute=..." overrides filter decision now so try to unset that. Working. Thanks. However, one problem remained. Host A (172.22.31.254, ROS 6.49.5). Host B (172.22.99.254, ROS 7.1.5). Ping from A to B - working. But ping from B to A - not. I repeat, that everything worked before upd...
by BrateloSlava
Fri Mar 25, 2022 12:22 pm
Forum: Forwarding Protocols
Topic: Control OSPF static redistribution (ROS v6 vs v7)
Replies: 11
Views: 5019

Re: Control OSPF static redistribution (ROS v6 vs v7)

In my opinion, something broke in this (7.1.5) update. In version 7.1.3 this configuration worked correctly for me. /routing id add disabled=no id=172.22.99.254 name=id-slava select-dynamic-id="" /routing ospf instance add name=rt-slava out-filter-chain=ospf-out redistribute=connected rout...
by BrateloSlava
Wed Mar 23, 2022 5:26 pm
Forum: Announcements
Topic: v7.1.4 and v7.1.5 is released!
Replies: 202
Views: 40113

Re: v7.1.4 and v7.1.5 is released!

OSPF stopped working after upgrading from 7.1.3 to 7.1.5 By analyzing the text configuration, it was found that one line was "lost" on update. Like this. /routing id add disabled=no id=172.22.99.254 name=id-slava select-dynamic-id="" Therefore, the required parameter (router-id) ...
by BrateloSlava
Thu Mar 03, 2022 2:13 pm
Forum: Wireless Networking
Topic: MikroTik hAP ac3 stuck in NetInstall mode
Replies: 9
Views: 3505

Re: MikroTik hAP ac3 stuck in NetInstall mode

Does the computer from which the attempts are made have any configured vpn connections?
by BrateloSlava
Wed Feb 23, 2022 10:48 pm
Forum: Announcements
Topic: v7.1.3 is released!
Replies: 251
Views: 56918

Re: v7.1.3 is released!

RB951Ui-2HnD
Strange problem. I'm try to disable some service ports.
Screenshot_udplite.png
Screenshot_sctp.png
Screenshot_dccp.png
by BrateloSlava
Wed Feb 23, 2022 11:02 am
Forum: Announcements
Topic: v7.1.3 is released!
Replies: 251
Views: 56918

Re: v7.1.3 is released!

strods
BrateloSlava - What do you mean by "CPU speed"? Do you refer to CPU usage under SYstem/Resources menu?
I talk about this: System->RouterBOARD->Settings->CPU freq (missing on 4011, after update)
by BrateloSlava
Tue Feb 22, 2022 9:17 pm
Forum: Announcements
Topic: v7.1.3 is released!
Replies: 251
Views: 56918

Re: v7.1.3 is released!

RB4011iGS+. Cpu speed not showing after update from 7.1.2 to 7.1.3.
Other my device:
  • RBD53iG-5HacD2HnD (hAP ac3)
  • RB951G-2HnD
  • RB2011UiAS
  • RB2011UiAS-2HnD
  • RBcAPGi-5acD2nD (cAP ac)
  • RBD52G-5HacD2HnD (hAP ac2)
  • RB951Ui-2HnD
  • RB750Gr3 (hEX)
  • CCR1016-12G
  • RB3011UiAS-RM
look good after update
by BrateloSlava
Tue Nov 09, 2021 7:15 pm
Forum: Announcements
Topic: v6.49 [stable] is released!
Replies: 219
Views: 96678

Re: v6.49 [stable] is released!

Today employees brought me two RB2011UiAS-2HnD-INs from branches, which do not boot after updating to 6.49. Moreover, the packages update itself was successful, and the firmware update led to a crash. Previous version - 6.47.9. Recovery attempts were unsuccessful. The router is determined by the net...
by BrateloSlava
Wed Oct 13, 2021 8:01 pm
Forum: Announcements
Topic: v6.49 [stable] is released!
Replies: 219
Views: 96678

Re: v6.49 [stable] is released!

I decided to experiment and created several rules for the indicators. How can I delete them now?
From GUI - not work, from command line - not work.
by BrateloSlava
Sun Oct 10, 2021 1:16 pm
Forum: Announcements
Topic: v6.49 [stable] is released!
Replies: 219
Views: 96678

Re: v6.49 [stable] is released!

I have 5 devices RB2011. On the previous stable 6.48.4, they all displayed temperature and voltage correctly.
After update:
RB2011UiAS.png
RB2011UiAS-.png
RB2011UiAS-2HnD.png
And 3 4011 have no problem
4011-3.png
4011-2.png
4011-1.png
by BrateloSlava
Tue Sep 14, 2021 11:15 am
Forum: Useful user articles
Topic: Configuration to block users that tries to access router on non open port(s)
Replies: 86
Views: 25167

Re: 📌 Configuration to block users that tries to access router on non open port(s)

It might be a better idea to use a list of interfaces (WAN) rather than the interface name (ether1).
by BrateloSlava
Mon Aug 23, 2021 8:25 pm
Forum: Announcements
Topic: v6.48.4 [stable] is released!
Replies: 68
Views: 72893

Re: v6.48.4 [stable] is released!

CCR1016. Wrong voltage displayed.