Community discussions

MikroTik App

Search found 102 matches

by Lokamaya
Tue Dec 03, 2024 10:35 pm
Forum: General
Topic: Two ports bridged and the rest in a second bridge. No internet second bridge [SOLVED]
Replies: 9
Views: 662

Re: Two ports bridged and the rest in a second bridge. No internet second bridge [SOLVED]

My suggestion are:

1. If you only have 1 internet connection, remove bridgeWAN
2. Change dhcp client for WAN to ether1
3. Move ether2 and wifi1 into bridgeLAN
4. Set ip pool for bridgeLAN to 192.168.111.20-192.168.111.245
by Lokamaya
Tue Dec 03, 2024 9:22 pm
Forum: General
Topic: Two ports bridged and the rest in a second bridge. No internet second bridge [SOLVED]
Replies: 9
Views: 662

Re: Two ports bridged and the rest in a second bridge. No internet second bridge [SOLVED]

bridgeWAN port member: ether1, ether2, wifi1 bridgeLAN port member: ether3, ether4, ether5, ether6, ether7, ether8, sfp1 /interface list member add comment=defconf interface=bridgeLAN list=LAN add comment=defconf interface=ether1 list=WAN Its seem you only have 1 internet connection through ether1, ...
by Lokamaya
Tue Dec 03, 2024 9:04 pm
Forum: General
Topic: Two ports bridged and the rest in a second bridge. No internet second bridge [SOLVED]
Replies: 9
Views: 662

Re: Two ports bridged and the rest in a second bridge. No internet second bridge [SOLVED]

# 2024-12-03 12:20:04 by RouterOS 7.13.5 /ip pool add name=dhcp ranges=192.168.88.100-192.168.111.10 /ip dhcp-server add address-pool=dhcp interface=bridgeLAN lease-time=10m name=defconf ... /ip address add address=192.168.111.1/24 comment=defconf interface=bridgeLAN network=192.168.111.0 /ip dhcp-...
by Lokamaya
Tue Dec 03, 2024 6:45 pm
Forum: General
Topic: RB5009UPr+S+IN Ports "Uknown" when setting up PPPoE Client
Replies: 2
Views: 272

Re: RB5009UPr+S+IN Ports "Uknown" when setting up PPPoE Client

Never heard of "unknown" port problem. And this is a new device.

Can you post a winbox snapshot of it?
by Lokamaya
Tue Dec 03, 2024 6:29 pm
Forum: General
Topic: Doing VLANs properly
Replies: 2
Views: 304

Re: Doing VLANs properly

How many router do you have on your network? A diagram would be nice, something like the diagram below.
OSPF2.png
by Lokamaya
Tue Dec 03, 2024 3:22 am
Forum: General
Topic: Lightning Strike and Switch Lost Connection (temporarily)
Replies: 6
Views: 1058

Re: Lightning Strike and Switch Lost Connection (temporarily)

I have all of my networking equipment and sensitive devices on UPS and overvoltage protection.
Yes. After the incident, it was felt that all equipment need to be secured with UPS and overvoltage.
by Lokamaya
Thu Nov 28, 2024 3:15 am
Forum: General
Topic: Lightning Strike and Switch Lost Connection (temporarily)
Replies: 6
Views: 1058

Lightning Strike and Switch Lost Connection (temporarily)

Lightning struck the power line and caused all the equipment, including all the computers, restarted. No damage, but two switches (CSS-326) in different rooms lost connection to the computers. After the switches were restarted, the connection was restored. These switches connected to main router wit...
by Lokamaya
Fri Nov 22, 2024 8:42 am
Forum: Beginner Basics
Topic: Help DNS approach to Faster Browsing
Replies: 25
Views: 1873

Re: Help DNS approach to Faster Browsing

Why do you have specified forward-fasttract for tcp/udp on port 53 only? I don's see any need for it, because all dhcp dns-server pointing to the router. And I think it is better to move forward/drop to the last row of the firewall filter. ... /ip firewall filter add action=drop chain=forward connec...
by Lokamaya
Sun Nov 17, 2024 4:20 am
Forum: General
Topic: DNS suddenly stopped working only for one subnet
Replies: 4
Views: 841

Re: DNS suddenly stopped working only for one subnet

Your firewall filter is a little bit off. I think you should work on it and sort it based on its chain: input first, than forward. Some of forward-drop chain to ether1 can be simplified by using address-list. The address-list is missing from the configuration above. I can not figure out what it is a...
by Lokamaya
Sun Nov 17, 2024 3:00 am
Forum: Useful user articles
Topic: GNS3, Proxmox and MikroTik
Replies: 0
Views: 339

GNS3, Proxmox and MikroTik

Hopefully useful. GNS3 Installation in Proxmox by Divgitally on Youtube:
https://www.youtube.com/watch?v=UfqjqigS-OM

Sorry if this has already been posted on other thread.
by Lokamaya
Sat Nov 16, 2024 2:31 pm
Forum: General
Topic: VLAN confusion
Replies: 19
Views: 944

Re: VLAN confusion

In the past, before vlan was known, we needed many physical ports to deploy many subnets, i.e. each subnet attached to a specific port.

With vlan, we can deploy many subnets on few ports.
by Lokamaya
Sat Nov 16, 2024 2:25 pm
Forum: Beginner Basics
Topic: Difference between two Interface Lists
Replies: 19
Views: 1815

Re: Difference between two Interface Lists

If your vlans are in the bridge, simply use LAN for default firewall rule.

If you wan to manage each vlan in firewall, for example block certain vlan, use it carefully.
by Lokamaya
Sat Nov 16, 2024 9:27 am
Forum: General
Topic: Dual WAN LTE (Main) + Cable (Secondary) [SOLVED]
Replies: 10
Views: 979

Re: Dual WAN LTE (Main) + Cable (Secondary) [SOLVED]

If it has been tested and runs well, you can go with that configuration.

Try by unplugging the cable from ether1 and see if the the route to WAN1 disabled as expected.
by Lokamaya
Fri Nov 15, 2024 4:55 pm
Forum: Beginner Basics
Topic: Mikrotik Certificate
Replies: 3
Views: 580

Re: Mikrotik Certificate

Does your domain/subdomain already pointing to your public ip-address?
by Lokamaya
Fri Nov 15, 2024 4:22 pm
Forum: General
Topic: DNS suddenly stopped working only for one subnet
Replies: 4
Views: 841

Re: DNS suddenly stopped working only for one subnet

Why do you set DNS servers to itself? 192.168.1.1 /ip dhcp-server network add address=192.168.1.0/24 dns-server=192.168.1.1 gateway=192.168.1.1 ... /ip dns set allow-remote-requests=yes servers=192.168.1.1 Try changing to public dns /ip dns set allow-remote-requests=yes servers=8.8.8.8,8.8.4.4
by Lokamaya
Fri Nov 15, 2024 2:08 pm
Forum: General
Topic: Routing rule VS mangle mark routing
Replies: 20
Views: 8708

Re: Routing rule VS mangle mark routing

Great point. Agree..
by Lokamaya
Fri Nov 15, 2024 1:03 pm
Forum: General
Topic: Dual WAN LTE (Main) + Cable (Secondary) [SOLVED]
Replies: 10
Views: 979

Re: Dual WAN LTE (Main) + Cable (Secondary) [SOLVED]

This is the basic of dual WAN using LTE on lte1 port and DHCP on ether1 as fallback. /ip dns set allow-remote-requests=yes servers=1.1.1.1,1.0.0.1 /interface lte set [ find default-name=lte1 ] name=lte1-WAN1 #WAN1: disable DNS /interface lte apn set [ find default=yes ] use-network-apn=no use-peer-d...
by Lokamaya
Fri Nov 15, 2024 11:51 am
Forum: General
Topic: Routing rule VS mangle mark routing
Replies: 20
Views: 8708

Re: Routing rule VS mangle mark routing

An easier way is simply add :
dst-address-type=!local
I tried it on Router OS v7.16, but it doesn't seem to work as I expected.
by Lokamaya
Fri Nov 15, 2024 11:15 am
Forum: General
Topic: Routing rule VS mangle mark routing
Replies: 20
Views: 8708

Re: Routing rule VS mangle mark routing

Here how I approached it with Mangle and Table Rule : /interface list add name=WAN add name=LAN add name=MGMT #WAN2, WAN3, WAN4 using DHCP /ip dhcp-client #add interface=ether1-WAN1 use-peer-dns=no use-peer-ntp=no add-default-route=no add interface=ether2-WAN2 use-peer-dns=no use-peer-ntp=no add-def...
by Lokamaya
Fri Nov 15, 2024 10:38 am
Forum: General
Topic: Routing rule VS mangle mark routing
Replies: 20
Views: 8708

Re: Routing rule VS mangle mark routing

Tested several configuration, and there are some approach to address this issues with its own pros and cons. 1. Totally using Tables Rule. Pros: simple when dealing with few vlan/subnet, auto-block vlan/subnet i.e. can not ping each other, etc. Cons: more vlan more headache, and need to work out to ...
by Lokamaya
Wed Nov 13, 2024 7:17 pm
Forum: General
Topic: DHCP Design
Replies: 4
Views: 421

Re: DHCP Design

In my environment, I have 4 routers providing a Guest network for 15k users.
Never though having 15k users :shock:
Almost swept 192.168.0.0/18 subnet
by Lokamaya
Tue Nov 12, 2024 11:02 am
Forum: General
Topic: packet filter by content
Replies: 8
Views: 915

Re: packet filter by content

This more looks like to be DNS hijacking
8)
by Lokamaya
Tue Nov 12, 2024 10:53 am
Forum: General
Topic: 3 wan 3 subnets
Replies: 5
Views: 484

Re: 3 wan 3 subnets

#Create a bridge for LAN /interface bridge add name=bridge1 /interface bridge port add bridge=bridge1 interface=ether4 add bridge=bridge1 interface=ether5 add bridge=bridge1 interface=ether6 #Create 2 lists: WAN & LAN /interface list add name=WAN add name=LAN /interface list member add list=WAN...
by Lokamaya
Tue Nov 12, 2024 10:03 am
Forum: General
Topic: 3 wan 3 subnets
Replies: 5
Views: 484

Re: 3 wan 3 subnets

Are you on Router OS 6 or 7?
And how each WAN connect to internet? Using DHCP or PPPoE?
by Lokamaya
Mon Nov 11, 2024 1:09 pm
Forum: Beginner Basics
Topic: Completely lost with regards to VLANs
Replies: 8
Views: 681

Re: Completely lost with regards to VLANs

Second, connect the sfp port from UDM to Mikrotik.

If you want to make adjustment to sfp port on Unifi side, go to Device > Port Setting. But I think leave it as default (except you know what you are doing).

If you already setup Unifi properly, feel free to ask on Mikrotik side.
by Lokamaya
Mon Nov 11, 2024 1:02 pm
Forum: Beginner Basics
Topic: Completely lost with regards to VLANs
Replies: 8
Views: 681

Re: Completely lost with regards to VLANs

First, I guess you already know how to setup VLAN on Unifi Network Controller (Setting > Networks). As mentioned by Anav and Jaclaz, don't use VLAN ID 1, use another number. Example: - name=vlan 100 - vlan id= 100 - ip-address=192.168. 100 .1 - netmask=24 (then generate address, see picture) Capture...
by Lokamaya
Mon Nov 11, 2024 11:17 am
Forum: Beginner Basics
Topic: how to achieve this setup?
Replies: 4
Views: 511

Re: how to achieve this setup?

a. create a bridge with only eth7 & 8 which will connect the TPLINK router and switch for network 192.168.0.0
Why do you need a bridge? Do you mean bonding?

Deco X7 has 1 x 2,5Gb RJ45 and 2 x 1Gb RJ45
Rb5009 has 1 x 2,5Gb Rj45 (on eth1), 7 x 1Gb RJ45 (including eth7 and eth8) and 1x SFP+
by Lokamaya
Sat Nov 09, 2024 3:21 pm
Forum: Scripting
Topic: Update Cloudflare DNS with script
Replies: 5
Views: 3377

Re: Update Cloudflare DNS with script

... found the first error is coming where the current IP address for WAN is being retrieved. # Update Cloudflare DNS IPv4 address script :local ip4new [/ip address get [/ip address find interface=$wanif] address] :set ip4new [:pick [:tostr $ip4new] 0 [:find [:tostr $ip4new] "/"]] How your...
by Lokamaya
Sat Nov 09, 2024 2:33 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1587
Views: 393161

Re: 📣 WinBox 4 is here 📣

Feature request: I would like to have a note inside Winbox xD

When I leave unfinish configuration, I want my friend who come later know what he has to do.
by Lokamaya
Sat Nov 02, 2024 12:33 pm
Forum: General
Topic: Lets Encrypt
Replies: 40
Views: 2088

Re: Lets Encrypt

I used SCP and uploaded both r10 and r11 to /data/unifi-core/config, rebooted the UDM, and Chrome still shows the DANGEROUS page in red. It's seem you have to upload the .crt and .key file manually to UDM. Please see here: https://community.ui.com/questions/UDM-Pro-SSL-Certificates/e83b07a7-bbb3-45...
by Lokamaya
Sat Nov 02, 2024 11:46 am
Forum: Beginner Basics
Topic: Virtualized VLANs (for Proxmox) [SOLVED]
Replies: 12
Views: 5385

Re: Virtualized VLANs (for Proxmox) [SOLVED]

Setting pvid= is irrelevant with frame-types=admit-only-vlan-tagged as untagged packets are discarded. Yes, it's what is expected. The default Proxmox network interface with bridge-vlan-aware look like this: auto lo iface lo inet loopback iface enp0s25 inet manual auto vmbr0 iface vmbr0 inet static...
by Lokamaya
Sat Nov 02, 2024 1:29 am
Forum: General
Topic: Lets Encrypt
Replies: 40
Views: 2088

Re: Lets Encrypt

The thing is that the choice between R10 and R11 is random, so the fact that your certificate is signed using R10 doesn't mean that @josephny's one will be too; actually, it even doesn't mean that your next one will be signed using R10. Oh I see. So, we have to check it on our browser by clicking t...
by Lokamaya
Sat Nov 02, 2024 12:57 am
Forum: General
Topic: Lets Encrypt
Replies: 40
Views: 2088

Re: Lets Encrypt

@Lokamaya, how do you know it is r10 in particular and not r11? I can't see that in the error message. I try it on my Mikrotik router using your script: #PREPARATION /ip/firewall/address-list/ add address=acme-v02.api.letsencrypt.org list=lets-encrypt /ip/firewall/mangle/ add chain=postrouting src-...
by Lokamaya
Sat Nov 02, 2024 12:26 am
Forum: General
Topic: Lets Encrypt
Replies: 40
Views: 2088

Re: Lets Encrypt

It is little bit tricky on unifi line because all folder are protected by "sudo" except the home/user dir. I only have UCK-G2+, so I can not confirm where the folder is on UDM. First upload the file to home_dir or user_dir using SCP or SFTP (WinSCP or similar), then use SSH to copy the fil...
by Lokamaya
Fri Nov 01, 2024 11:21 pm
Forum: General
Topic: Lets Encrypt
Replies: 40
Views: 2088

Re: Lets Encrypt

On UDM, upload r10.pem to /data/unifi-core/config/
by Lokamaya
Fri Nov 01, 2024 6:11 pm
Forum: General
Topic: Lets Encrypt
Replies: 40
Views: 2088

Re: Lets Encrypt

I leave a comment and come back later when I need it. Thanks.
by Lokamaya
Wed Oct 30, 2024 8:22 pm
Forum: General
Topic: CRS326 - SWoS or RoS
Replies: 2
Views: 306

Re: CRS326 - SWoS or RoS

I would still go for ROS since it is A LOT more flexible then SWOS.
I agree. ROS for CRS326.
And you need to upgrade it to v7+. The CPU only count 1 on v6, while on ROS v7+ its count 2.
by Lokamaya
Wed Oct 30, 2024 7:55 pm
Forum: General
Topic: NEW Public Bandwith Test Server
Replies: 60
Views: 90281

Re: NEW Public Bandwith Test Server

> /tool bandwidth-test protocol=tcp \ direction=receive address=87.121.0.45 \ user="neterra" password="neterra" \ duration=20s status: done testing duration: 21s rx-current: 221.2Mbps rx-10-second-average: 293.5Mbps rx-total-average: 259.2Mbps random-data: no direction: receive ...
by Lokamaya
Wed Oct 30, 2024 7:29 pm
Forum: Beginner Basics
Topic: Virtualized VLANs (for Proxmox) [SOLVED]
Replies: 12
Views: 5385

Re: Virtualized VLANs (for Proxmox) [SOLVED]

#Bridge
/interface bridge
add frame-types=admit-only-vlan-tagged name=bridge1 vlan-filtering=yes
...

#Bridge Port: Facing to Proxmox
/interface bridge port
add bridge=bridge frame-types=admit-only-vlan-tagged interface=ether2 pvid=4094
by Lokamaya
Wed Oct 30, 2024 7:22 pm
Forum: Beginner Basics
Topic: Virtualized VLANs (for Proxmox) [SOLVED]
Replies: 12
Views: 5385

Re: Virtualized VLANs (for Proxmox) [SOLVED]

You need a trunk port on both router and proxmox Got it working with single NIC on my Proxmox server. This tutorial and "How To Create VLANs in Proxmox For a Single NIC" on Youtube make me understand why we need "admit-only-vlan-tagged" and add "pvid=4094" to the bridg...
by Lokamaya
Mon Oct 28, 2024 11:26 am
Forum: Containers
Topic: Container "Traefik" (on RB5009)
Replies: 11
Views: 11677

Re: Container "Traefik" (on RB5009)

I don't know if this helps anyone, but I got Traefik to work on an RB1100 (which is actually ARM32) using this image: https://hub.docker.com/_/traefik
I have to try this. Thanks Amm0
by Lokamaya
Mon Oct 28, 2024 2:25 am
Forum: General
Topic: DNS adlist: Is whitelisting possible?
Replies: 7
Views: 2442

Re: DNS adlist: Is whitelisting possible?

Currently whitelist is available on latest 7.17beta2. For now, I just add static DNS for specific domain. For example, if I want to whitelist "googleadservices.com": 1. Disable specific list from adlist 2. Open terminal > ping googleadservices.com 3. Add the ip to static DNS /ip/dns/static...
by Lokamaya
Sun Oct 27, 2024 9:09 am
Forum: General
Topic: How to route packets from private to public ip
Replies: 2
Views: 305

Re: How to route packets from private to public ip

I don't have experience with public/private ip. But, do you consider using netmap rather than dst-nat?
by Lokamaya
Sat Oct 26, 2024 12:28 pm
Forum: General
Topic: 7.16 logging email not sent immediately after boot
Replies: 13
Views: 2330

Re: 7.16 logging email not sent immediately after boot

I'll use Netwatch, not Logging, for sending email for the time being until it is resolved. And add "start up delay" into it.
by Lokamaya
Sat Oct 26, 2024 12:13 pm
Forum: General
Topic: DoH: New DNS Server Certificate and SSL Error
Replies: 2
Views: 392

Re: DoH: New DNS Server Certificate and SSL Error

Yes, some Quad9 ip or server seems still not get the proper certificate.
by Lokamaya
Sat Oct 26, 2024 12:00 pm
Forum: General
Topic: How to block YouTube effectively
Replies: 44
Views: 18374

Re: How to block YouTube effectively

The Adlist (and similar service like PiHole) requires DNS from our Tix/PiHole. Still the Adlist can't block client who uses custom DNS or PVN, but who can?
by Lokamaya
Sat Oct 26, 2024 11:50 am
Forum: General
Topic: How to block YouTube effectively
Replies: 44
Views: 18374

Re: How to block YouTube effectively

On ROS 7.14, I choose Adlist (Adblock) from Mikrotik. First, create a new GitHub project, i.e. "MyTube Blocker" Then, add MyTube Blocker list to Adlist Lastly, update MyTube Blocker regularly through GitHub project When we need to access Youtube temporarily just disable "MyTube Blocke...
by Lokamaya
Sat Oct 26, 2024 11:25 am
Forum: General
Topic: DoH: New DNS Server Certificate and SSL Error
Replies: 2
Views: 392

DoH: New DNS Server Certificate and SSL Error

After two days of trying to solve the SSL error problem on DoH, it finally worked normally again. I use Quad9 DNS service for this feature. I also tried Cloudflare and NextDNS (free up to 300K queries) just to find out which is the shortest hop from my place. But in the last few days suddenly the lo...
by Lokamaya
Wed Mar 27, 2024 2:36 pm
Forum: General
Topic: Cannot Format USB Flash Drive
Replies: 4
Views: 3999

Re: Cannot Format USB Flash Drive

Sometime creating an empty folder or file inside the empty flashdrive would solve the problem. Or format the flashdrive in ext4 format.
by Lokamaya
Mon Mar 25, 2024 8:06 am
Forum: Beginner Basics
Topic: Vlan across two Bridges? [SOLVED]
Replies: 6
Views: 4944

Re: Vlan across two Bridges? [SOLVED]

You could send a VLAN between two bridges, but that would involve bridge stacking, something like this:
I just know this is possible. Thanks.
by Lokamaya
Mon Mar 25, 2024 1:42 am
Forum: General
Topic: Strange issue with srd/dst address type 'local'
Replies: 6
Views: 2218

Re: Strange issue with srd/dst address type 'local'

I tested it on Mangle chain prerouting: dst-address-type=local or src-address-type=local. Its seem that on prerouting only one known, either source or destination.

Edit:
Btw, it works on Mangle chain=input, dst-address-type=local or src-address-type=local
by Lokamaya
Sat Mar 23, 2024 5:49 pm
Forum: RouterBOARD hardware
Topic: Free up storage of CRS326 (16Mb)
Replies: 7
Views: 2709

Re: Free up storage of CRS326 (16Mb)

There is a bug in RouterOS v6 installed on CRS326. The CPU only count 1, while on RouterOS v7+ its count 2.
by Lokamaya
Sat Mar 23, 2024 5:39 pm
Forum: RouterBOARD hardware
Topic: CRS326-24G-2S+RM 0 bytes free of flash memory - can't restore flash space
Replies: 5
Views: 3615

Re: CRS326-24G-2S+RM 0 bytes free of flash memory - can't restore flash space

I am upgrading to RouterOS 14.1 and got 3500Kb of free storage. Here what I did viewtopic.php?t=206130

Best,
Lokamaya
by Lokamaya
Sat Mar 23, 2024 5:32 pm
Forum: RouterBOARD hardware
Topic: Free up storage of CRS326 (16Mb)
Replies: 7
Views: 2709

Free up storage of CRS326 (16Mb)

CRS326-24G-2S+ is a dual OS switch, equipped with 16Mb of storage. This makes the storage fill up quickly, especially when upgrading RouterOS from version 6 to 7.7. After several months of experiencing a lack of storage and not being able to upgrade or downgrade, this week I finally got a backup swi...
by Lokamaya
Mon Mar 18, 2024 6:23 am
Forum: Beginner Basics
Topic: Invalid TCP incoming packets with ACK,FIN,PSH, invalid outgoing with RST [SOLVED]
Replies: 4
Views: 6502

Re: Invalid TCP incoming packets with ACK,FIN,PSH, invalid outgoing with RST [SOLVED]

Got the same problem. For packets incoming from LAN, I add "reject: tcp reset" just before the default invalid filter. /ip firewall filter add action=reject chain=forward connection-state=invalid out-interface-list=WAN protocol=tcp reject-with=tcp-reset tcp-flags=!syn add action=drop chain...
by Lokamaya
Mon Mar 18, 2024 1:29 am
Forum: Wireless Networking
Topic: Unifi Network Controller via Mikrotik Wireless Setup
Replies: 2
Views: 1241

Re: Unifi Network Controller via Mikrotik Wireless Setup

Yes, Anav... need time to draw a complete diagram. Hopefully in the near future.

In short, there are two approaches: client have its own DHCP server, or everything is centralized. Currently I use the first approach on my setup.
by Lokamaya
Mon Mar 18, 2024 1:24 am
Forum: General
Topic: Ubiquiti EdgeRouter vs MikroTik
Replies: 3
Views: 13556

Re: Ubiquiti EdgeRouter vs MikroTik

Interesting. Thank you.

I just home and office user with small network. Never touch EdgeRouter, but quite familiar with EdgeSwitch (and SwOS). Once I had an USG, but now I prefer Mikrotik.
by Lokamaya
Sat Mar 16, 2024 6:09 pm
Forum: Wireless Networking
Topic: Unifi Network Controller via Mikrotik Wireless Setup
Replies: 2
Views: 1241

Unifi Network Controller via Mikrotik Wireless Setup

Hi all, This is my first experience working with the Mikrotik wireless LAN and Unifi network controller system. My setup is quite simple. I just want to give internet access to clients in different buildings, while managing the Unifi access point centrally. And I'm quite happy with the results. Wire...
by Lokamaya
Fri Sep 30, 2022 12:49 pm
Forum: Forwarding Protocols
Topic: Ping Timed out but having internet
Replies: 4
Views: 5200

Re: Ping Timed out but having internet

Login to RouterOS using IP or MacAddress?
by Lokamaya
Wed Sep 28, 2022 12:44 pm
Forum: General
Topic: Multi-WAN's Policy Based Routing on RouterOS v7.5 (A Simplest Way)
Replies: 12
Views: 12987

Re: Multi-WAN's Policy Based Routing on RouterOS v7.5 (A Simplest Way)

So, the best practice is to let the VLAN_MGMT remain in the main table.
by Lokamaya
Wed Sep 28, 2022 12:32 pm
Forum: General
Topic: Multi-WAN's Policy Based Routing on RouterOS v7.5 (A Simplest Way)
Replies: 12
Views: 12987

Re: Multi-WAN's Policy Based Routing on RouterOS v7.5 (A Simplest Way)

I can confirm when VLAN_MGMT changed from main table to rtab-WAN1 , I can not ping the DHCP modem (WAN2: 10.2.2.1) from outside the router. The WAN2 modem only accessible from inside the hEX router and its port. I still can access internet through WAN2 internet provider, but I can not access the mod...
by Lokamaya
Wed Sep 28, 2022 11:12 am
Forum: General
Topic: Multi-WAN's Policy Based Routing on RouterOS v7.5 (A Simplest Way)
Replies: 12
Views: 12987

Re: Multi-WAN's Policy Based Routing on RouterOS v7.5 (A Simplest Way)

I have a chance to test it on 4 WANs, 1 PPPoe and 3 DHCP. But have to make some wiring to the 3th and 4th internet provider, maybe in the weekend.
by Lokamaya
Wed Sep 28, 2022 11:05 am
Forum: General
Topic: WAN failover basics [SOLVED]
Replies: 3
Views: 1821

Re: WAN failover basics [SOLVED]

You can see this post viewtopic.php?t=189520
Just change the failover (distance: 200) to different distance.

Thanks
by Lokamaya
Wed Sep 28, 2022 10:34 am
Forum: General
Topic: Multi-WAN's Policy Based Routing on RouterOS v7.5 (A Simplest Way)
Replies: 12
Views: 12987

Re: Multi-WAN's Policy Based Routing on RouterOS v7.5 (A Simplest Way)

/routing table add disabled=no fib name=rtab-WAN2 /routing rule add interface=VLAN_20 action=lookup table=rtab-WAN2 add interface=ether5 action=lookup table=rtab-WAN2 add interface=VLAN_30 action=lookup-only-in-table table=rtab-WAN2 /ip route add distance=2 dst-address=0.0.0.0/0 gateway=200.10.10.1...
by Lokamaya
Tue Sep 27, 2022 9:22 pm
Forum: General
Topic: Multi-WAN's Policy Based Routing on RouterOS v7.5 (A Simplest Way)
Replies: 12
Views: 12987

Re: Multi-WAN's Policy Based Routing on RouterOS v7.5 (A Simplest Way)

(5) You really dont have a primary and secondary at the moment, both have same distance and you dont have check-gateway=ping on the primary. Recursive route is another homework. I'm just digesting this one and the "recursive" thing is too difficult to handle for the beginner like me. Whil...
by Lokamaya
Tue Sep 27, 2022 8:34 pm
Forum: General
Topic: Multi-WAN's Policy Based Routing on RouterOS v7.5 (A Simplest Way)
Replies: 12
Views: 12987

Re: Multi-WAN's Policy Based Routing on RouterOS v7.5 (A Simplest Way)

(1) Looking only at your routes, What is the purpose of the distance differences, need to understand your logic?? The differences is for fallback or failover. /ip route add distance=200 dst-address=0.0.0.0/0 gateway= 200.10.10.1 routing-table= main scope=30 target-scope=10 add distance=200 dst-addr...
by Lokamaya
Tue Sep 27, 2022 5:45 pm
Forum: General
Topic: Multi-WAN's Policy Based Routing on RouterOS v7.5 (A Simplest Way)
Replies: 12
Views: 12987

Re: Multi-WAN's Policy Based Routing on RouterOS v7.5 (A Simplest Way)

There are some ideas here........... viewtopic.php?t=182373
Thank you Anav. I've read that post and many others of your posts. You are my hero here and very helpful.
by Lokamaya
Tue Sep 27, 2022 5:16 pm
Forum: General
Topic: Multi-WAN's Policy Based Routing on RouterOS v7.5 (A Simplest Way)
Replies: 12
Views: 12987

Multi-WAN's Policy Based Routing on RouterOS v7.5 (A Simplest Way)

After struggling for several weeks to get dual-wan policy based routing running on RouterOs version 7.5, with the help of this forum and various trials, I finally found a solution. My basic question (as I asked here https://forum.mikrotik.com/viewtopic.php?t=189239): What is /routing/table/ and /rou...
by Lokamaya
Sun Sep 25, 2022 10:00 pm
Forum: Beginner Basics
Topic: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]
Replies: 25
Views: 6257

Re: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]

I'll post my finding in another thread.

Thanks
by Lokamaya
Sat Sep 24, 2022 11:28 pm
Forum: RouterBOARD hardware
Topic: CSS326-24G-2S+ & active cooling
Replies: 23
Views: 21931

Re: CSS326-24G-2S+ & active cooling

You only need 2 wires for DC: black (-) and red (+). Maybe you get different color combination, and its depend on your country. Computer fans has 2, 3 or 4 wires (mostly 12V). The first 2 for electricity, the 3th for sensor and fans speed, the 4th for other control like LED. So, no matter how many w...
by Lokamaya
Sat Sep 24, 2022 10:54 pm
Forum: RouterBOARD hardware
Topic: CSS326-24G-2S+ & active cooling
Replies: 23
Views: 21931

Re: CSS326-24G-2S+ & active cooling

The 24V fan is rare but I choose not to use 12V version because there will be more works to do. And I'm lucky to get four 24V DC fans with 3 wires. Here my list: 1. 24V DC fan 40mm x 40mm x 10mm 2. Screw Metal M3 - 12mm (my fan 10mm) 3. Nylon M3 Pilar Spacer PCB 4. Extra cable and cable's fan connec...
by Lokamaya
Sat Sep 24, 2022 10:46 pm
Forum: RouterBOARD hardware
Topic: CSS326-24G-2S+ & active cooling
Replies: 23
Views: 21931

Re: CSS326-24G-2S+ & active cooling

After reading this thread and found Eric Shewe (https://www.pickysysadmin.ca/2022/08/1 ... tallation/) post, I start hunting fans for my CRS and CSS. Here my results:


Capture-css.JPG
CSS326 45-47°C

Capture-crs.JPG
CRS326 49-50°C
by Lokamaya
Sat Sep 24, 2022 9:41 am
Forum: Scripting
Topic: How can I Get/Set Variable from JSON Parse Function? [SOLVED]
Replies: 6
Views: 9840

Re: How can I Get/Set Variable from JSON Parse Function? [SOLVED]

Thanks again. This is what I need.
I'am currently using ipinfo.io (json format) to get dynamic public ip.
by Lokamaya
Fri Sep 23, 2022 6:29 am
Forum: Scripting
Topic: How can I Get/Set Variable from JSON Parse Function? [SOLVED]
Replies: 6
Views: 9840

Re: How can I Get/Set Variable from JSON Parse Function? [SOLVED]

Thanks @rextended, its works.

I'll try it with more complex script to get dynamic public IP of my ISP and stored it on address list.
by Lokamaya
Thu Sep 22, 2022 5:40 pm
Forum: Scripting
Topic: How can I Get/Set Variable from JSON Parse Function? [SOLVED]
Replies: 6
Views: 9840

Re: How can I Get/Set Variable from JSON Parse Function? [SOLVED]

I have run the script and make JSONLoad as global variable.
Thanks
by Lokamaya
Thu Sep 22, 2022 5:33 pm
Forum: Scripting
Topic: How can I Get/Set Variable from JSON Parse Function? [SOLVED]
Replies: 6
Views: 9840

How can I Get/Set Variable from JSON Parse Function? [SOLVED]

Hi all, I have a json file with IP address and other data. I try to parse it with JParseFunctions (https://github.com/Winand/mikrotik-json-parser). The script running well on terminal, but I don't know how to make it works on /System/Scripts. Capture.JPG JSON code { "ip": "108.177.16....
by Lokamaya
Wed Sep 21, 2022 8:00 am
Forum: Beginner Basics
Topic: can not ping 8.8.8.8 from my MT router
Replies: 11
Views: 4455

Re: can not ping 8.8.8.8 from my MT router

192.168.2.1 is your modem, I guess. And 10.10.0.200 maybe a port forward or something in your modem...
by Lokamaya
Tue Sep 20, 2022 5:43 pm
Forum: Beginner Basics
Topic: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]
Replies: 25
Views: 6257

Re: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]

So everything works except the UNIFI?? Just finished the EdgeSwitch configuration, and have to dig deep into legacy interface to change trunk port from 1 to 99. Maybe this would be helpful for anyone: Switches > VLAN > Port Summary. Or, using CLI here https://help.ui.com/hc/en-us/articles/115002359...
by Lokamaya
Tue Sep 20, 2022 11:46 am
Forum: Beginner Basics
Topic: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]
Replies: 25
Views: 6257

Re: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]

I also not so sure. Back to mangle for the live RB.
by Lokamaya
Mon Sep 19, 2022 2:07 pm
Forum: Beginner Basics
Topic: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]
Replies: 25
Views: 6257

Re: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]

I guess these are both the same: src-address == interface (interface===in-interface, but be careful because src-address !== interface). There is no out-interface, only in-interface. Capture.JPG If we can write script like this, there will be no confusion where to look for routing table: /routing/rul...
by Lokamaya
Mon Sep 19, 2022 1:22 pm
Forum: Beginner Basics
Topic: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]
Replies: 25
Views: 6257

Re: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]

I even can not ping from any subnet to it's own gateway: ping 192.168.20.1 -> request timed out (from 192.168.20.x) ping 192.168.30.1 -> request timed out (from 192.168.30.x) So here the simplest solution with 3 lines of code: /routing/rule/ add dst-address=10.0.0.0/8 action=lookup-only-in-table tab...
by Lokamaya
Mon Sep 19, 2022 12:53 pm
Forum: Beginner Basics
Topic: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]
Replies: 25
Views: 6257

Re: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]

TRIVIA: RouterOS 7.5 I moved one Unifi AP to different subnet (192.168.10.10, vlan10) and try to adopt it from Unifi Controller (10.199.99.10, vlan99) but failed; Trying to ping the AP (192.168.10.10) from my PC (10.199.99.30, vlan99) also failed-> Request timed out ; Trying to ping the AP (192.168....
by Lokamaya
Sun Sep 18, 2022 10:43 am
Forum: Beginner Basics
Topic: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]
Replies: 25
Views: 6257

Re: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]

My hEX is running flawlessly right now.
Thank you Anav for your time. Bless you, keep happy and healthy.

I leave the Unifi' thing for next day....
by Lokamaya
Sun Sep 18, 2022 10:36 am
Forum: Beginner Basics
Topic: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]
Replies: 25
Views: 6257

Re: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]

PART 03 (7) SOURCE NAT RULE is not configged properly , first there is no such interface as all-vlan, its bound to be a list anyway and I think you meant in-interface-list=VLANs add action=redirect chain=dstnat dst-port=53 in-interface=all-vlan protocol= udp Why only udp and not TCP ?? Done (8) Raw ...
by Lokamaya
Sun Sep 18, 2022 7:53 am
Forum: Beginner Basics
Topic: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]
Replies: 25
Views: 6257

Re: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]

PART 02 Oops you dont have all the vlans identified as members to your INTERFACE LIST entry ---> VLANs ?? (6) Lets fix your interface lists and firewall address list. USE of firewall address lists is BEST SUITED for when you have a few users in one subnet or across subnets or groups of users from wi...
by Lokamaya
Sun Sep 18, 2022 5:42 am
Forum: Beginner Basics
Topic: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]
Replies: 25
Views: 6257

Re: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]

PART 01 # 200+ = SENIOR HIGH SCHOOL - 192.168. 100 .0/24, 192.168.210.0/24 (teacher), 192.168.220.0/22 (student) should that not be .200 ? Typo. You are right, it's should be 200. (1) Okay I am not sure what you are doing with the management interface..........? Typically this is a vlan that only th...
by Lokamaya
Sun Sep 18, 2022 3:22 am
Forum: Beginner Basics
Topic: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]
Replies: 25
Views: 6257

Re: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]

I've been locked out from RB several time... tbh :shock:
by Lokamaya
Sun Sep 18, 2022 2:19 am
Forum: Beginner Basics
Topic: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]
Replies: 25
Views: 6257

Re: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]

Sweet, have some time to look at the config....... (will add as I read through and will state done when finished looking at it).

Amazing. I have to look into your suggestion line by line. I'll be back soon.
Thank you
by Lokamaya
Sat Sep 17, 2022 4:19 pm
Forum: Beginner Basics
Topic: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]
Replies: 25
Views: 6257

Re: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]

Awesome, now one needs to know the requirements or in your case how you expect to use the WAN connections. For example. a. wan1 primary and wan2 secondary b. load balanced PCC other less frequent options are c. wan1 primary and wan2 secondary but some user, groups of users, or subnet should use WAN...
by Lokamaya
Sat Sep 17, 2022 3:45 pm
Forum: Beginner Basics
Topic: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]
Replies: 25
Views: 6257

Re: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]

Here the network layout. CRS as a root bridge connected to 2 CSS switches in other buildings using SFP+ port in this ring topology. I've tried connected internet directly into CRS and make it as main router, but this device seem not suitable for routing and WAN (CPU load was high and I run out of di...
by Lokamaya
Sat Sep 17, 2022 3:44 pm
Forum: Beginner Basics
Topic: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]
Replies: 25
Views: 6257

Re: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]

Hi there, so let me understand this correctly.
The router connected to the internet is the CRS ?
hEX connected to internet
CRS for internal switching
by Lokamaya
Sat Sep 17, 2022 5:47 am
Forum: Beginner Basics
Topic: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]
Replies: 25
Views: 6257

Re: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]

Hi, thanks Anav... Here my RouterOS v7.5 setup on hEX RB750Gr3. This RB router connected directly to CRS326-24G-2S+ as the main switch-router. ############################################################################### # RouterOS 7.5 on hEX RB750Gr3 ##############################################...
by Lokamaya
Fri Sep 16, 2022 4:15 pm
Forum: Scripting
Topic: Useful scripts
Replies: 116
Views: 318552

Re: Useful scripts

I will try to get all the useful links to threads to look at when some script is needed, that is not yet in wiki or is in wiki, just to get them not buried under loads other posts. Check time of the post, to make some link to RouterOS version these where created for. New script for RouterOS v7, ple...
by Lokamaya
Fri Sep 16, 2022 4:00 pm
Forum: RouterBOARD hardware
Topic: CRS326 Got 2 Cores CPU with RoS v7.5
Replies: 0
Views: 679

CRS326 Got 2 Cores CPU with RoS v7.5

I found this interesting and maybe a bug. After upgrading to v7.5, I got 2 cores on my CRS326. With 2 cores, the CPU-Load drops drastically.

mikrotik-crs326v6.jpg

mikrotik-crs326v7.jpg

Thank you
by Lokamaya
Fri Sep 16, 2022 3:32 pm
Forum: Beginner Basics
Topic: RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]
Replies: 25
Views: 6257

RouterOS v7.5 Basic Question: /Routing/Rules [SOLVED]

Hi all, Just upgraded my hEX from v6.49 to v7.5 and found it is little bit different regarding dual ISP handling. I've read routing tutorial here https://help.mikrotik.com/docs/display/ROS/Routing and also some other examples on Youtube, but still don't get the basic concept of routing rules. Here s...
by Lokamaya
Tue Sep 06, 2022 1:26 am
Forum: Wireless Networking
Topic: lost configuration on every reboot
Replies: 9
Views: 6759

Re: lost configuration on every reboot

There is nothing wrong with the disk, but it is too small. Only 16Mb.
I lost part of firewall configuration and part of static DNS.

It's seem that that part remains in the memory and lost when I reboot the MK.


Capture.JPG
by Lokamaya
Tue Sep 06, 2022 1:16 am
Forum: Wireless Networking
Topic: lost configuration on every reboot
Replies: 9
Views: 6759

Re: lost configuration on every reboot

Me too. I'm using CRS326+24+2
by Lokamaya
Thu Nov 11, 2021 4:43 am
Forum: General
Topic: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch
Replies: 35
Views: 18519

Re: VLAN Trunk Between Mikrotik CCR and Ubiquiti EdgeSwitch

Send me an email, it is listed above.
I can not contact you at mike(at)43index.com.