Community discussions

MikroTik App

Search found 632 matches

by CGGXANNX
Tue Apr 29, 2025 2:12 pm
Forum: General
Topic: Can mikrotik user manager distribute vlan id for wired devices. [SOLVED]
Replies: 11
Views: 801

Re: Can mikrotik user manager distribute vlan id for wired devices. [SOLVED]

Yes, the RB260GS is the cheapest MikroTik device that allows you to have individual VLAN per port (access port). However, it runs SwOS which means it does not support 802.1x and you won't be able to assign dynamic VLAN on it ports based on MAC address or username/password/certificates. If you only n...
by CGGXANNX
Tue Apr 29, 2025 1:24 am
Forum: General
Topic: Can mikrotik user manager distribute vlan id for wired devices. [SOLVED]
Replies: 11
Views: 801

Re: Can mikrotik user manager distribute vlan id for wired devices. [SOLVED]

There is no hack. If a client device is not VLAN aware, then there must be VLAN supports at the edge of the network that device is connected to. All your access points are actually switches , just wireless switches instead of wired ethernet switches. A WiFi client connecting to a SSID is somewhat an...
by CGGXANNX
Mon Apr 28, 2025 7:28 am
Forum: General
Topic: Can mikrotik user manager distribute vlan id for wired devices. [SOLVED]
Replies: 11
Views: 801

Re: Can mikrotik user manager distribute vlan id for wired devices. [SOLVED]

If currently most of your LAN network is behind the powerline adapter connected to a single ethernet port of the CCR2004 then unfortunately you cannot activate the dot1x server on the CCR2004 on that port, because it will turn that port into an access port of a single VLAN once a device has authenti...
by CGGXANNX
Mon Apr 28, 2025 6:27 am
Forum: Beginner Basics
Topic: Primary gateway with static ip address not activating
Replies: 22
Views: 1471

Re: Primary gateway with static ip address not activating

No, the target scope of the "main" route (through the canary address) should be +1 of the "narrow" route, and this latter +1 of scope, (and scopes can be all the same like 10), It may not be strictly speaking 100% correct, but it is easy to remember. i.e.: Strictly speaking you ...
by CGGXANNX
Mon Apr 28, 2025 2:09 am
Forum: General
Topic: Can mikrotik user manager distribute vlan id for wired devices. [SOLVED]
Replies: 11
Views: 801

Re: Can mikrotik user manager distribute vlan id for wired devices. [SOLVED]

Did you try applying this: https://help.mikrotik.com/docs/spaces/ROS/pages/328090/Dot1X#Dot1X-Server And the usual RADIUS attributes for VLAN assignment (Tunnel-Type, Tunnel-Medium-Type, Tunnel-Private-Group-ID) should also work: https://help.mikrotik.com/docs/spaces/ROS/pages/328090/Dot1X#Dot1X-Por...
by CGGXANNX
Sun Apr 27, 2025 5:55 am
Forum: Beginner Basics
Topic: One place to view connected devices?
Replies: 3
Views: 590

Re: One place to view connected devices?

I think people on the forum used to add a rule to Kid Control for this kind of monitoring: /ip kid-control add name=monitor mon=0s-1d tue=0s-1d wed=0s-1d thu=0s-1d fri=0s-1d sat=0s-1d sun=0s-1d Data are available in the Devices table. But there is no bridge port / interface, and the counters only co...
by CGGXANNX
Sun Apr 27, 2025 12:36 am
Forum: General
Topic: L009UiGS dropping SFP randomly
Replies: 10
Views: 2819

Re: L009UiGS dropping SFP randomly

I had the same issue but only if 10G was advertised. If I remove 10G from my advertised speeds, I immediately get an IP -- but I only sync at 1G, not 2.5G which I would expect for my 1.5G plan. I have been using a G-010S-P from ALCATELLUCENT (should be similar enough to your G-010S-A) since a coupl...
by CGGXANNX
Fri Apr 25, 2025 9:57 am
Forum: Beginner Basics
Topic: Stops Responding [SOLVED]
Replies: 10
Views: 2543

Re: Stops Responding [SOLVED]

In your configuration, when you turn on "VLAN Filtering" on the bridge, most of the ports of the bridge (for example ether2 or ether4) are access port of the VLAN 1 (reason: they have PVID=1 and Frame-Types is admit-all which are the default value, you've also added those ports to the unta...
by CGGXANNX
Thu Apr 24, 2025 1:47 pm
Forum: Beginner Basics
Topic: dst-nat is not working after switching from PPPoE to DHCP Client [SOLVED]
Replies: 2
Views: 1330

Re: dst-nat is not working after switching from PPPoE to DHCP Client [SOLVED]

Your new ISP probably puts you behind CGNAT https://en.wikipedia.org/wiki/Carrier-grade_NAT, which means you no longer have a public IP address. To confirm this, compare the IP address listed under IP -> Addresses for ether1 with what sites like https://ifconfig.me/ display to you. If they don't mat...
by CGGXANNX
Wed Apr 23, 2025 11:20 pm
Forum: Beginner Basics
Topic: WG road warrior cannot access LAN [SOLVED]
Replies: 2
Views: 1988

Re: WG road warrior cannot access LAN [SOLVED]

What are devices in your LAN (192.168.88.0/24) running? If they are running Windows then by default they won't answer ping from other subnets. If you are trying to ping the specific server at 192.168.88.117 then with your current config that won't work neither (because of the routing configuration).
by CGGXANNX
Wed Apr 23, 2025 10:30 pm
Forum: Beginner Basics
Topic: Hex refresh download speed
Replies: 25
Views: 2326

Re: Hex refresh download speed

also the port works only with autonegotiation (1G full duplex), manual setting 1G T-full turns off the port.

Auto-negotiation is required for 1G BASE-T https://en.wikipedia.org/wiki/Gigabit_E ... 1000BASE-T
by CGGXANNX
Wed Apr 23, 2025 10:13 pm
Forum: Beginner Basics
Topic: Stops Responding [SOLVED]
Replies: 10
Views: 2543

Re: Stops Responding [SOLVED]

/interface bridge vlan is mapped in WinBox to what you see in the Bridge -> VLANs table. Currently the "bridge" interface (which implicitly is VLAN 1) is the interface that has the management IP address that allows you to reach the switch with the IP address 172.21.9.10. When you use that...
by CGGXANNX
Wed Apr 23, 2025 10:02 pm
Forum: Beginner Basics
Topic: Stops Responding [SOLVED]
Replies: 10
Views: 2543

Re: Stops Responding [SOLVED]

You need to change this entry /interface bridge vlan add bridge=bridge tagged=bridge untagged=ether2,ether4,sfp-sfpplus2,ether8,ether7,ether5 vlan-ids=1 And move " bridge " to be member of the untagged list instead of the tagged list. Also " bridge " should not be member of the u...
by CGGXANNX
Tue Apr 22, 2025 8:59 pm
Forum: General
Topic: Allow for some devices, Internet access for 1 hour each day [SOLVED]
Replies: 18
Views: 2831

Re: Allow for some devices, Internet access for 1 hour each day [SOLVED]

And here is the 1h daily limitation from my tests: /user-manager limitation add name=one-hour-per-day reset-counters-interval=daily uptime-limit=1h /user-manager profile add name=daily-1h name-for-users="1h daily access" validity=unlimited /user-manager profile-limitation add limitation=on...
by CGGXANNX
Tue Apr 22, 2025 8:53 pm
Forum: General
Topic: Allow for some devices, Internet access for 1 hour each day [SOLVED]
Replies: 18
Views: 2831

Re: Allow for some devices, Internet access for 1 hour each day [SOLVED]

I could configure everything as in your screenshoots. When I connect a client to hotspot, I get to the screen to write credentials, and get "Radius Server is not responding" I just did not install the certificate. the "Radius server is not responding" message is because of the c...
by CGGXANNX
Mon Apr 21, 2025 10:32 pm
Forum: Beginner Basics
Topic: Pihole on MikroTik Container with IPv4 and IPv6 support
Replies: 4
Views: 660

Re: Pihole on MikroTik Container with IPv4 and IPv6 support

No! I've made a type in my previous post with the out-interface-list that should be WAN instead of LAN. Once corrected, NAT in this case is only needed if the container needs to go directly to the internet (for example for upstream DNS lookup) and you don't have additional GUA addresses announced on...
by CGGXANNX
Mon Apr 21, 2025 9:42 pm
Forum: Beginner Basics
Topic: Pihole on MikroTik Container with IPv4 and IPv6 support
Replies: 4
Views: 660

Re: Pihole on MikroTik Container with IPv4 and IPv6 support

There is no problem with assigning IPv6 static address to container. You can give the container a static ULA if you don't have static GUA prefixes. * Go to https://www.unique-local-ipv6.com/ and get a random /48 prefix. For example fd72​ :​ 1a93​ :​ 454c​ ::​ /48. * Add fd72​ :​ 1a93​ :​ 454c​ ::​ 1...
by CGGXANNX
Sun Apr 20, 2025 6:45 am
Forum: Beginner Basics
Topic: Hairpin NAT with dynamic WAN IP [SOLVED]
Replies: 12
Views: 2858

Re: Hairpin NAT with dynamic WAN IP [SOLVED]

Sorry, I am an old school software developer and it's just a habit for me to think about implementation details and low level inefficiency and your script will cause more unnecessary operations (especially writes and memory allocations/deallocations) while holding locks multiple times, that can be m...
by CGGXANNX
Sat Apr 19, 2025 10:18 pm
Forum: Beginner Basics
Topic: Hairpin NAT with dynamic WAN IP [SOLVED]
Replies: 12
Views: 2858

Re: Hairpin NAT with dynamic WAN IP [SOLVED]

The way you update the address list entry triggers two modifications of the list. For data structures heavily optimized for lookup/read performance, modifications are always orders of magnitudes more expensive. Each modification probably needs to lock global data structures (lock the whole firewall ...
by CGGXANNX
Sat Apr 19, 2025 9:29 pm
Forum: Beginner Basics
Topic: Hairpin NAT with dynamic WAN IP [SOLVED]
Replies: 12
Views: 2858

Re: Hairpin NAT with dynamic WAN IP [SOLVED]

Maybe something like this in the PPP Profile's On-Up: :local interfaceName "pppoe-out1"; :local addressListName "WAN_IP"; :local comment "WAN IP" :local wanIP [/ip address get [find interface=$interfaceName] address]; /ip firewall address-list remove [find list=$address...
by CGGXANNX
Fri Apr 18, 2025 7:46 am
Forum: Beginner Basics
Topic: IPTV issues during intensive tasks
Replies: 25
Views: 1520

Re: IPTV issues during intensive tasks

Looking at the updated topology, my guess is that accessing the NAS from the Server and transferring files probably produces some additional small percentage of broadcast or multicast traffic. The problem is that when you are transferring at 10Gbps (or even at only 2Gbps), a small percentage might s...
by CGGXANNX
Fri Apr 18, 2025 1:00 am
Forum: General
Topic: Allow for some devices, Internet access for 1 hour each day [SOLVED]
Replies: 18
Views: 2831

Re: Allow for some devices, Internet access for 1 hour each day [SOLVED]

FYI I just redid the test configuration and it worked as expected, client loses access to the internet after one hour (and some minutes depending on the interim update interval setting). Some notes: * Please be aware that the hotspot wizard expects an unconfigured interface, you should either set as...
by CGGXANNX
Thu Apr 17, 2025 11:41 pm
Forum: General
Topic: HTTPS-redirect with RoS 7.5 - bad news for hotspots...
Replies: 14
Views: 8811

Re: HTTPS-redirect with RoS 7.5 - bad news for hotspots...

I just did more tests and support for RFC 7710 and RFC 8910 is automatically enabled but Windows does not use it at the moment. It works very well with Android.
by CGGXANNX
Thu Apr 17, 2025 7:16 pm
Forum: General
Topic: "Make static ip" turns off internet access, LAN is ok
Replies: 2
Views: 451

Re: "Make static ip" turns off internet access, LAN is ok

The MAC address in the static DHCP lease is wrong, should be 00:01:2E:64:F0:65 instead of 00:01:2E:64:F0:66.

Edit that entry, clear Client ID (by pressing the triangle button) and change the MAC address to 00:01:2E:64:F0:65.
by CGGXANNX
Thu Apr 17, 2025 4:29 pm
Forum: General
Topic: Allow for some devices, Internet access for 1 hour each day [SOLVED]
Replies: 18
Views: 2831

Re: Allow for some devices, Internet access for 1 hour each day [SOLVED]

I'm curious, how does the hotspot place restrictions? Isn't it using MAC addresses behind the scenes? What if a client changes their MAC address and reconnects as basically a new user? Last time I tested Hotspot together with User Manager, the Hotspot setup created new chains and dynamic rules in t...
by CGGXANNX
Thu Apr 17, 2025 3:59 pm
Forum: Beginner Basics
Topic: IPTV issues during intensive tasks
Replies: 25
Views: 1520

Re: IPTV issues during intensive tasks

Are the workstation and the server in different VLANs? But you've mentioned trace route producing only one hop, so probably not.
by CGGXANNX
Thu Apr 17, 2025 2:39 pm
Forum: General
Topic: Allow for some devices, Internet access for 1 hour each day [SOLVED]
Replies: 18
Views: 2831

Re: Allow for some devices, Internet access for 1 hour each day [SOLVED]

It should work with hotspot too. You can do a test setup yourself. What you need is: * Install User Manager and set it up with Profiles, Limitations, Profile-Limitations, User Groups, Users, User-Profiles. Don't forget to check Use Profiles in the UM settings. * In UM, add the one "Router"...
by CGGXANNX
Wed Apr 16, 2025 10:26 pm
Forum: General
Topic: Allow for some devices, Internet access for 1 hour each day [SOLVED]
Replies: 18
Views: 2831

Re: Allow for some devices, Internet access for 1 hour each day [SOLVED]

They does not want to specify one specific hour, they want to users to have 1 hour, whenever each user want Is this possible? How? It's possible with User Manager and WPA Enterprise like I wrote above, but the Access Points must be compatible with RouterOS with regards to Change-of-Authorization (C...
by CGGXANNX
Wed Apr 16, 2025 9:42 pm
Forum: General
Topic: Allow for some devices, Internet access for 1 hour each day [SOLVED]
Replies: 18
Views: 2831

Re: Allow for some devices, Internet access for 1 hour each day [SOLVED]

This is actually one perfect use-case for WPA2-Enterprise/WPA3-Enterprise with PEAP/MSCHAPv2 and User Manager acting as RADIUS server. No worry about devices having random MAC address, because each user/device has their own username & password. But you'll need access points with WPA2-Enterprise/...
by CGGXANNX
Wed Apr 16, 2025 2:35 pm
Forum: General
Topic: hEX refresh and Verizon FIOS Slow Upload Speed
Replies: 26
Views: 7803

Re: hEX refresh and Verizon FIOS Slow Upload Speed

First, there is no reasons why you cannot enable flow control on the ethernet port when you use other QoS mechanism such as Queues, that is not related. Second, whether flow control is enabled or not on OpenWrt depends on the chipset/network adapter. You need to add ethtool and run it with the param...
by CGGXANNX
Wed Apr 16, 2025 2:01 pm
Forum: Beginner Basics
Topic: How to connect/ping from a lan to RouterOS after boot !!??
Replies: 6
Views: 781

Re: How to connect/ping from a lan to RouterOS after boot !!??

There are no configuration changes to be made on the MikroTik device, only on the pfSense router, and that modification only needs to be done once. Did you try to apply what I wrote on post #2? Namely: * pfSense has interface VLAN88, configured with 192.168.88.10/24 (no gateway needed). * On pfSense...
by CGGXANNX
Wed Apr 16, 2025 7:40 am
Forum: General
Topic: hEX refresh and Verizon FIOS Slow Upload Speed
Replies: 26
Views: 7803

Re: hEX refresh and Verizon FIOS Slow Upload Speed

No, the problem is because your router is ignoring the pause frames sent by the ONT. The ONT can not keep up with the 1 Gbps rate that the router is pumping to it. Before its buffers are completely filled up the ONT uses flow control (by sending pause frames) to tell the MikroTik router to slow down...
by CGGXANNX
Wed Apr 16, 2025 6:16 am
Forum: General
Topic: hEX refresh and Verizon FIOS Slow Upload Speed
Replies: 26
Views: 7803

Re: hEX refresh and Verizon FIOS Slow Upload Speed

In such cases, where the uplink (300 Mbps) is slower than the speed of the ethernet (ports) in the LAN (1 Gbps) the solution might actually be to turn on flow control on all the MikroTik router's ethernet ports on the affected path. Flow control is per default off on MikroTik devices so you can try ...
by CGGXANNX
Tue Apr 15, 2025 4:49 pm
Forum: General
Topic: 2kbps DNS-Resolution Spam for cloud.mikrotik.com from detect-interface feature
Replies: 9
Views: 896

Re: 2kbps DNS-Resolution Spam for cloud.mikrotik.com from detect-interface feature

The problem is that when using the mobile MikroTik app, there is a very intriguing text right on the homepage saying that "Internet detect" is disabled. And after tapping on it, just another tap is enough to have Detect Internet turned on. And mobile users also quickly learn that Detect In...
by CGGXANNX
Tue Apr 15, 2025 11:00 am
Forum: General
Topic: Whats the point of this default FW rule?
Replies: 25
Views: 3805

Re: Whats the point of this default FW rule?

The quoted passage mentions the RAW rules because the whole page is to be applied as an example configuration, and if you scroll to the bottom of the page https://help.mikrotik.com/docs/spaces/ROS/pages/328513/Building+Advanced+Firewall#BuildingAdvancedFirewall-IPv4RAWRules There's the rule that doe...
by CGGXANNX
Fri Apr 11, 2025 12:19 am
Forum: Scripting
Topic: RouterOS Bug - Why Do These Simple Scripts Break? Cause of Mysterious "value:" Prompt?
Replies: 20
Views: 2684

Re: RouterOS Bug - Why Do These Simple Scripts Break? Cause of Mysterious "value:" Prompt?

Stop calling it a bug and read the doc please https://help.mikrotik.com/docs/spaces/ROS/pages/47579229/Scripting#Scripting-Functions. The :return command is only defined for returning a function value from within a function . Which means it requires a value as argument, and the text content of a scr...
by CGGXANNX
Thu Apr 10, 2025 11:03 pm
Forum: Beginner Basics
Topic: PPPOE with static IP
Replies: 20
Views: 1708

Re: PPPOE with static IP

* If it shows pppoe-out1 as not ready, then it means that your PPPoE setup currently cannot be dialed successfully. You can open the Log and will probably see a lot of pppoe dialing attempts that fail. One of the reasons might be that your username or password is not correct. You'll get more details...
by CGGXANNX
Thu Apr 10, 2025 10:44 pm
Forum: General
Topic: Why can I not install rose-storage package
Replies: 8
Views: 2171

Re: Why can I not install rose-storage package

EDIT 2: Thank you, Amm0. Contributions such as yours should be automatically included in the "official" MikroTik guides as standard. People who use MikroTik deal with issues often on an ad-hoc basis and wish to find quick, efficient solutions. It's has been documented after 7.18 was relea...
by CGGXANNX
Thu Apr 10, 2025 6:35 pm
Forum: Beginner Basics
Topic: PPPOE with static IP
Replies: 20
Views: 1708

Re: PPPOE with static IP

* You go to IP -> Firewall -> NAT tab. Look for the rule that says Action: masquerade Chain: srcnat. Double click to open it. Find the dropdown box with the caption Out. Interface and change the value from ether1 to pppoe-out1 . That should fix your problem. * Alternatively, if you want to do it wit...
by CGGXANNX
Thu Apr 10, 2025 4:04 pm
Forum: Beginner Basics
Topic: PPPOE with static IP
Replies: 20
Views: 1708

Re: PPPOE with static IP

You need to update your srcnat masquerade rule to use pppoe-out1 as out-interface. Or alternatively do like the defconf firewall, add pppoe-out1 (and ether1 if you plan to access the management of the modem/converter device) to an interface list WAN and change the masquerade rule to use out-interfac...
by CGGXANNX
Thu Apr 10, 2025 3:21 am
Forum: General
Topic: Need a nat rule
Replies: 11
Views: 992

Re: Need a nat rule

how does the router know that 10.72.22.200 should be assigned to the device About this point: This address can be whatever IP address, even from subnets not managed by the router, it can be 3.4.5.6 for example. The only requirement is that on the remote WireGuard client device (a phone for example)...
by CGGXANNX
Thu Apr 10, 2025 1:50 am
Forum: Beginner Basics
Topic: DoH Mullvad/Yandex
Replies: 15
Views: 8389

Re: DoH Mullvad/Yandex

If your router has enough free RAM and storage space (about 60MB each), you can abuse cloudflared running in a container to be able to use any DoH provider, including Mullvad: doh-cloudflared.png In this example with Mullvad, the command line parameter is: proxy-dns --port 5053 --upstream https://dn...
by CGGXANNX
Wed Apr 09, 2025 11:35 pm
Forum: Beginner Basics
Topic: How to connect/ping from a lan to RouterOS after boot !!??
Replies: 6
Views: 781

Re: How to connect/ping from a lan to RouterOS after boot !!??

On your pfSense router you'll need to add an Outbound NAT rule on the VLAN88 interface. The goal is to translate the source address of the packets going out of this interface (to the RouterOS device) to 192.168.88.10 (the IP address of pfSense on the interface). On the rule, you only need to keep th...
by CGGXANNX
Wed Apr 09, 2025 10:22 pm
Forum: General
Topic: Need a nat rule
Replies: 11
Views: 992

Re: Need a nat rule

@anav because in OP's original config the subnet 192.168.0.0/24 (or any other smaller subnet enough to encompass 192.168.0.97) doesn't exist yet on his router. The router did not know how to route to destination 192.168.0.97, other than to forward everything to the default destination 0.0.0.0/0 rout...
by CGGXANNX
Wed Apr 09, 2025 3:17 pm
Forum: General
Topic: failing to masquerade on VLAN interface
Replies: 3
Views: 588

Re: failing to masquerade on VLAN interface

You need to check whether your device has L3HW support for NAT and FastTrack. There's a couple of tables near the bottom of that page I linked above that categorize the devices. Only those with DX4000 and DX8000 switch chip, and the CCR and RDS devices support that. If that not supported, then on yo...
by CGGXANNX
Wed Apr 09, 2025 1:40 pm
Forum: General
Topic: Slow transfer speed but not on Ookla speedtest
Replies: 8
Views: 850

Re: Slow transfer speed but not on Ookla speedtest

It really looks like your ISP is "cheating" with well-known speed test services while throttling normal traffic (including to lesser-known test sites like Real-Debrid). What if you use your browser to go to YouTube and watch a 4K video, while turning on the "Stats for nerds" in t...
by CGGXANNX
Wed Apr 09, 2025 12:49 pm
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 2081

Re: Basic VLAN config question (again)

I am sorry that I did not use the term that you defined in your article @sindy. My "CPU port" is not the specific term that you only used for the hardware switch. For me the bridge (hardware offload by a switch chip or only software based is not important) has ports, including real physica...
by CGGXANNX
Wed Apr 09, 2025 2:11 am
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 2081

Re: Basic VLAN config question (again)

Yes, it works with all the cases you listed. This frame-types setting on the bridge interface is actually the setting for the "port" persona of bridge, where the bridge is the CPU port, in the same category as ether1, ether2, sfp1, etc... Even the tab in in WinBox has the same options as t...
by CGGXANNX
Wed Apr 09, 2025 1:45 am
Forum: Forwarding Protocols
Topic: BGP route has incorrect "immediate gateway"
Replies: 4
Views: 787

Re: BGP route has incorrect "immediate gateway"

Yes, it's as I expected. You can read more about nexthop lookup here: https://help.mikrotik.com/docs/spaces/ROS/pages/328084/IP+Routing#IPRouting-NexthopLookup When looking for the next hop for the route with destination 192.168.100.0/24 gateway 10.32.1.2 (the one at the bottom of the screenshot), t...
by CGGXANNX
Wed Apr 09, 2025 12:58 am
Forum: General
Topic: Need a nat rule
Replies: 11
Views: 992

Re: Need a nat rule

Your previous attempts did not work because the router didn't know that it should forward frames destined for 192.168.0.97 to ether2. By adding the IP address (and the network address, if you want you can also use 192.168.0.98/24 as address and 192.168.0.0 as network) to the interface vlan-cameras, ...
by CGGXANNX
Wed Apr 09, 2025 12:43 am
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 2081

Re: Basic VLAN config question (again)

The first error. 1. is quoting from your config in post #18 and is WRONG ( do not use the bridge itself to set frames ) IMHO if OP has a VLAN-only configuration, with no IP address configured on the interface "bridge", then setting frame-types=admit-only-vlan-tagged is the correct way, an...
by CGGXANNX
Wed Apr 09, 2025 12:24 am
Forum: General
Topic: Need a nat rule
Replies: 11
Views: 992

Re: Need a nat rule

Is that ether2 port part of a bridge (slave port) or outside of any bridges (standalone interface)? You'll need to add an IP address first /ip address # choose only one of the three following! add address=192.168.0.98 interface=ether2 network=192.168.0.97 # only if ether2 is standalone port! add add...
by CGGXANNX
Wed Apr 09, 2025 12:07 am
Forum: General
Topic: Slow transfer speed but not on Ookla speedtest
Replies: 8
Views: 850

Re: Slow transfer speed but not on Ookla speedtest

Can you also test with https://www.fast.com (Netflix) and https://real-debrid.com/speedtest (multiple locations but download only)?
by CGGXANNX
Tue Apr 08, 2025 10:29 pm
Forum: Forwarding Protocols
Topic: BGP route has incorrect "immediate gateway"
Replies: 4
Views: 787

Re: BGP route has incorrect "immediate gateway"

Can you make the Scope and Target Scope columns visible in the table too?
by CGGXANNX
Tue Apr 08, 2025 7:36 pm
Forum: General
Topic: This "Sorry but the board is temporarily unavailable, please try again in a few minutes." is getting old.
Replies: 48
Views: 7436

Re: This "Sorry but the board is temporarily unavailable, please try again in a few minutes." is getting old.

XenForo is not that different from PHPBB for scalability (PHP and MySQL, no multiple servers). Also it's paid (plus addons), Discourse is more suited for modern problems and is free. I don't think citing PHP as disadvantage really works, because modern PHP is much more performant than Ruby (which w...
by CGGXANNX
Tue Apr 08, 2025 3:52 pm
Forum: General
Topic: failing to masquerade on VLAN interface
Replies: 3
Views: 588

Re: failing to masquerade on VLAN interface

If your router supports L3HW NAT, you need to turn off lw-hw-offloading on the two WAN ports, while enabling them on the rest of the ports. Before making the change on the ports, l3-hw-offloading on the switch chip must be turned off first. Afterward it has to be re-enabled. And you also need to cor...
by CGGXANNX
Tue Apr 08, 2025 1:10 pm
Forum: General
Topic: This "Sorry but the board is temporarily unavailable, please try again in a few minutes." is getting old.
Replies: 48
Views: 7436

Re: This "Sorry but the board is temporarily unavailable, please try again in a few minutes." is getting old.

Could you maybe also consider XenForo? It's not free, for self-host it costs a couple of hundred $ once and yearly $60 for upgrades. But the UX is closer to traditional forum software, while still supporting modern features, and performance is really good on forums with > 1 million user accounts.
by CGGXANNX
Tue Apr 08, 2025 3:08 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 9549

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

It's the loopback interface, that can be used since 7.14 https://forum.mikrotik.com/viewtopic.php?t=202612 *) system - expose "lo" and "vrf" interfaces; One of the use-cases is to replace the need for adding dummy bridge interfaces if you want extra internal IP addresses for the ...
by CGGXANNX
Tue Apr 08, 2025 1:36 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 9549

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

And now the interesting bit. Create a bridge with a /30 address: i had some free time to do a couple of tests today, and this point can be further simplified: we can just add a /32 address to the lo interface. No needs for the extra dummy bridge and the two separate IP addresses for src-nat and dst...
by CGGXANNX
Sun Apr 06, 2025 12:23 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 192354

Re: v7.19beta [testing] is released!

After upgrading old RB2011 to 7.19 beta7, can't upload anything any longer (e.g. can't upgrade to beta8). File list empty. Scripts that create backups fail. What's up with that? Check System -> Users: Is there any other user groups than full / read / write . Does the group full still have all check...
by CGGXANNX
Sat Apr 05, 2025 1:33 am
Forum: Beginner Basics
Topic: Question about interface lists
Replies: 9
Views: 1218

Re: Question about interface lists

I would assume that DHCP traffic from the VLAN to the router is blocked just like the winbox traffic. But it is not. All my VLAN clients successfully get an IP address from the router. Why? :o Because DHCP uses raw sockets and is not affected by the /ip firewall filter table's rules. You can read t...
by CGGXANNX
Fri Apr 04, 2025 1:26 pm
Forum: General
Topic: Help needed: Poor download speed and semi frequent drops
Replies: 7
Views: 1154

Re: Help needed: Poor download speed and semi frequent drops

I'm curious what IGMP snooping does, is it security related? No, it's not related to security. Turning on IGMP Snooping helps reduce the amount bandwidth used on the ports (like ether1, ether2, sfp1, etc...) of the bridge/switch if there is a lot of multicast traffic. Without IGMP Snooping, if you ...
by CGGXANNX
Thu Apr 03, 2025 8:05 pm
Forum: General
Topic: ipv6 ND and vlan leaks [SOLVED]
Replies: 14
Views: 3520

Re: ipv6 ND and vlan leaks [SOLVED]

Is the laptop directly connected to the RB4011? (on ether2 or ether8?) Or is this plugged to the Aruba 2915 switch?
by CGGXANNX
Wed Apr 02, 2025 9:34 pm
Forum: General
Topic: What hardware to buy?
Replies: 3
Views: 617

Re: What hardware to buy?

What should I consider buying to achieve the goals listed below? I’d like them to simply enter a username and password on their devices—without needing to configure pre-shared keys, secrets, or other advanced settings. Is that possible? I have no experience with using MikroTik WiFi hardwares in the...
by CGGXANNX
Wed Apr 02, 2025 8:45 pm
Forum: General
Topic: Redirect DNS, but with IPv6? [SOLVED]
Replies: 6
Views: 7524

Re: Redirect DNS, but with IPv6? [SOLVED]

How do I include a SLACC based IPv6. You'll need to write some script. In the same script that you have where you extract the IP address from the /ipv6 neighbor entry, add some code that update the to-address attribute of the dstnat rule (you can set a comment on the rule and then look for it by co...
by CGGXANNX
Wed Apr 02, 2025 7:35 pm
Forum: General
Topic: Public DNS to private IP
Replies: 44
Views: 2635

Re: Public DNS to private IP

That device asks its DNS server (192.168.0.1) and that DNS server tells the device to go and ask the DNS server at a completely different location (for example, 192.168.2.1). The DNS server (192.168.0.1) doesn't tell the device to go ask the other server. The DNS server performs the lookup itself ,...
by CGGXANNX
Wed Apr 02, 2025 4:13 pm
Forum: General
Topic: [Bug-Fix-Request] DHCP-Option 82 on hEX S not disable HW-Forward by default
Replies: 13
Views: 3508

Re: [Bug-Fix-Request] DHCP-Option 82 on hEX S not disable HW-Forward by default

Re-reading the OP and he/she has the setup where sfp1 is part of the bridge, and the tests are done between sfp1 and other ethernet ports. Which means even with DHCP Snooping disabled, those tests were never hardware offloaded , because sfp1 is outside of the switch chip and is always handled by the...
by CGGXANNX
Wed Apr 02, 2025 11:48 am
Forum: General
Topic: RouterOS blatantly ignores pref-src. Can this really be a bug?
Replies: 92
Views: 9549

Re: RouterOS blatantly ignores pref-src. Can this really be a bug?

Of course only specifying the dst-port for the dst-nat rules will also nat the intended connections. This however also has the effect of natting every packet that is udp/13231, and so no one who uses this port will be able to correctly communicate with anyone if their traffic is routed by your devi...
by CGGXANNX
Wed Apr 02, 2025 1:45 am
Forum: General
Topic: Help needed: Poor download speed and semi frequent drops
Replies: 7
Views: 1154

Re: Help needed: Poor download speed and semi frequent drops

You should NOT enable IGMP Snooping (nor DHCP Snooping) on the hEX S. Doing so will disable hardware offload on the bridge, switching and VLAN filtering will need to be done entirely by the main CPU and even L2 traffic will all need to share the single 1Gbps link to the main CPU (the other link is u...
by CGGXANNX
Wed Apr 02, 2025 12:58 am
Forum: Beginner Basics
Topic: DHCP server for VLAN not working [SOLVED]
Replies: 5
Views: 5506

Re: DHCP server for VLAN not working [SOLVED]

The "bridge" CPU port is not shown in the tagged list for the VLANs under /interface bridge vlan. Did you turn on the VLAN Filtering checkbox for bridge?
by CGGXANNX
Wed Apr 02, 2025 12:45 am
Forum: General
Topic: fq_codel/CAKE stories? [SOLVED]
Replies: 30
Views: 16129

Re: fq_codel/CAKE stories? [SOLVED]

someone *please* tell me this is a sick April Fools joke :(

It's not https://github.com/LibreQoE/LibreQoS/pu ... 2770436543

RIP Dave :(.
by CGGXANNX
Tue Apr 01, 2025 10:17 pm
Forum: General
Topic: Leaking of IPv6 prefix that's not present on Router
Replies: 10
Views: 1273

Re: Leaking of IPv6 prefix that's not present on Router

@Larsa I think OP posted the screenshot above your post. Router lifetime is 0, which means other devices will not use the Apple TV as default router, and there is no advertise prefix. I think the Apple TV only announces the route so that it becomes default target for the fdf7:ffab:feed::/64 subnet. ...
by CGGXANNX
Mon Mar 31, 2025 11:21 pm
Forum: General
Topic: Leaking of IPv6 prefix that's not present on Router
Replies: 10
Views: 1273

Re: Leaking of IPv6 prefix that's not present on Router

Unfortunately, if the prefix is the deprecated one as I wrote, then you either need to wait for about a month (the default "valid lifetime" setting value) since the last time that prefix was really "preferred" (non-deprecated) or reboot the router :(. Reducing /ipv6 nd prefix def...
by CGGXANNX
Mon Mar 31, 2025 9:36 pm
Forum: General
Topic: Leaking of IPv6 prefix that's not present on Router
Replies: 10
Views: 1273

Re: Leaking of IPv6 prefix that's not present on Router

On your client devices, are the addresses with that prefix listed as "deprecated"? For Windows, run ipconfig /all , for Linux run ip addr , for *BSD (probably macOS too) run ifconfig , and see if deprecated is shown next to the address. If that's the case, then it's the normal behavior for...
by CGGXANNX
Mon Mar 31, 2025 8:41 pm
Forum: Beginner Basics
Topic: internet speed
Replies: 8
Views: 1068

Re: internet speed

Which access points are you using? Do they have a full Gbps link to the router or only fast ethernet (100 Mbps)? Are WiFi clients connected to 5 GHz or 2.4 GHz channels?
by CGGXANNX
Mon Mar 31, 2025 8:19 pm
Forum: General
Topic: ipv6 ND and vlan leaks [SOLVED]
Replies: 14
Views: 3520

Re: ipv6 ND and vlan leaks [SOLVED]

Can you try to disable IGMP Snooping? First, when you have multiple tagged VLANs, special handling with the multicast querier is needed if IGMP Snooping is to be enabled https://help.mikrotik.com/docs/spaces/ROS/pages/59277403/Bridge+IGMP+MLD+snooping#BridgeIGMP/MLDsnooping-IGMPsnoopingconfiguration...
by CGGXANNX
Mon Mar 31, 2025 7:06 am
Forum: General
Topic: User Manager isn't sending NAS-Identifier
Replies: 3
Views: 729

Re: User Manager isn't sending NAS-Identifier

Yes, and I also mentioned above in the screenshot that NAS-Identifier is one of the standard attributes. But MikroTik reasoning was that User-Manager supports CoA with MikroTik devices and that was enough. To be fair, not all AP manufacturers require NAS-Identifier to be sent with CoA messages (UM C...
by CGGXANNX
Mon Mar 31, 2025 6:18 am
Forum: General
Topic: User Manager isn't sending NAS-Identifier
Replies: 3
Views: 729

Re: User Manager isn't sending NAS-Identifier

This is a known issue, and I've filled a support request (SUP-163983) last year about it: user-man-sup-163983.png Unfortunately, MikroTik has refused to make the change and closed the ticket, this was their answer: user-man-sup-163983-2.png I've since made a new attempt and suggested an alternative ...
by CGGXANNX
Sun Mar 30, 2025 11:46 pm
Forum: Beginner Basics
Topic: Constant high outbound traffic from ether1
Replies: 14
Views: 1543

Re: Constant high outbound traffic from ether1

The rule add chain=input action=drop in-interface-list=!LAN comment="defconf: drop all not coming from LAN" is the important one that protects your router against abuses from the Internet. Do not remove it! Of the five rules that I posted above, only the CAPsMAN rule is optional (in case y...
by CGGXANNX
Sun Mar 30, 2025 11:40 pm
Forum: Beginner Basics
Topic: VPN with relay on a VPS - working around the CGNAT
Replies: 15
Views: 1796

Re: VPN with relay on a VPS - working around the CGNAT

If you mean the Neighbors tab on the login page of WinBox, the listing requires broadcast and will not work over WireGuard. And of course, MAC WinBox also does not work over WireGuard.
by CGGXANNX
Sun Mar 30, 2025 11:35 pm
Forum: Beginner Basics
Topic: Constant high outbound traffic from ether1
Replies: 14
Views: 1543

Re: Constant high outbound traffic from ether1

To access the router remotely, you should configure a VPN, like WireGuard (you can also use the built-in Back-To-Home feature https://help.mikrotik.com/docs/spaces/ROS/pages/197984280/Back+To+Home which does the WG setup for you). From the outside you establish the VPN tunnel (for instance, install ...
by CGGXANNX
Sun Mar 30, 2025 11:18 pm
Forum: Beginner Basics
Topic: Constant high outbound traffic from ether1
Replies: 14
Views: 1543

Re: Constant high outbound traffic from ether1

Please restore the input rules of the defconf firewall. It's not enough to just disable those services that you listed. For instance, your router accepts remote DNS requests and DNS amplification attack (https://www.cloudflare.com/learning/ddos/dns-amplification-ddos-attack/) is a thing! Here are th...
by CGGXANNX
Sun Mar 30, 2025 10:18 pm
Forum: General
Topic: VPN and IPTV (multicast)
Replies: 4
Views: 1450

Re: VPN and IPTV (multicast)

Have you considered UDPXY (it's extremely lightweight and run great in container on RouterOS, I use it on my RB5009 and hAP ac² with only 128MB RAM)? It will introduce a few seconds delay to the streams but other than that, it works well, even for watching IPTV channels on the go over WireGuard. I n...
by CGGXANNX
Fri Mar 28, 2025 1:40 pm
Forum: Beginner Basics
Topic: socks 5 to wireguard
Replies: 3
Views: 1082

Re: socks 5 to wireguard

You can just run a socks5 server in container (I previously did tests with this one and it's lightweight and works fine https://hub.docker.com/r/serjs/go-socks5-proxy), then use routing rules to steer the outgoing connections of that container's IP address through WG.
by CGGXANNX
Fri Mar 28, 2025 1:32 pm
Forum: General
Topic: Devices in same VLAN not reachable [SOLVED]
Replies: 3
Views: 8605

Re: Devices in same VLAN not reachable [SOLVED]

* If you want ether3-server_switch to be a trunk port of VLAN 20, then the PVID set on that port it wrong, you should change it back to 1 and set Frame Types to admit-only-vlan-tagged . * But if you want ether3-server_switch to be a normal access port of VLAN 20 then keep PVID as 20, but set Frame T...
by CGGXANNX
Thu Mar 27, 2025 10:26 pm
Forum: General
Topic: IPv6 Setup Weirdness [SOLVED]
Replies: 25
Views: 10366

Re: IPv6 Setup Weirdness [SOLVED]

That ULA prefix on the IOT interface might be the result of some device in that VLAN announcing itself as router. Now that the OP has established that that he needs add-default-route=yes in his DHCPv6 client setting, the router no longer has a reason to have /ipv6 settings accept-router-advertisemen...
by CGGXANNX
Thu Mar 27, 2025 9:04 pm
Forum: Wireless Networking
Topic: VLANs with wifi-qcom-ac
Replies: 16
Views: 2092

Re: VLANs with wifi-qcom-ac

This post has the recent (7.18.1) measurements with Bridge VLAN Filtering that I made on my hAP ac² (also compared to the setup with /interface ethernet switch), no WiFi interfaces though. https://forum.mikrotik.com/viewtopic.php?t=215359#p1132188 Bridging between two ports at wirespeed with Bridge ...
by CGGXANNX
Thu Mar 27, 2025 7:35 pm
Forum: General
Topic: [Routing/Firewall] Mixed network mikrotik - Ubiquiti
Replies: 13
Views: 1834

Re: [Routing/Firewall] Mixed network mikrotik - Ubiquiti

Good luck with your endeavor mixing LAN WAN VLAN and whatever between the UniFi and MikroTik network then. As I said, static leases for the APs in MikroTik DHCP server, static lease / IP address for the host machine that from time-to-time runs the controller software. There is nothing special about ...
by CGGXANNX
Thu Mar 27, 2025 1:56 pm
Forum: Containers
Topic: Routing from container to multiple internet connections Topic is solved
Replies: 6
Views: 3065

Re: Routing from container to multiple internet connections Topic is solved

Can your program select the source IP address for its outgoing connections? You can add multiple IP addresses (from the same subnet) to the VETH interface, and they'll be added to the ethernet interface inside the container. If your program is able to pick which of those to use as source IP address,...
by CGGXANNX
Thu Mar 27, 2025 1:26 pm
Forum: General
Topic: [Routing/Firewall] Mixed network mikrotik - Ubiquiti
Replies: 13
Views: 1834

Re: [Routing/Firewall] Mixed network mikrotik - Ubiquiti

My Linux VM only runs a couple of times a month, when I want to check for firmware updates. I only need the VM because I need WireGuard to run together with the controller to give it access to the remote locations (If I had run the controller directly on my PC I would need to run WG on my PC too, wh...
by CGGXANNX
Thu Mar 27, 2025 12:36 pm
Forum: General
Topic: [Routing/Firewall] Mixed network mikrotik - Ubiquiti
Replies: 13
Views: 1834

Re: [Routing/Firewall] Mixed network mikrotik - Ubiquiti

You don't need to run the controller 24/7. Only when you need to change the configuration or upgrade firmware. I have networks with UniFi APs and RouterOS routers in different locations and just use a small Linux VM where the controller is installed that I only occasionally start up. And I even mana...
by CGGXANNX
Thu Mar 27, 2025 12:05 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 13114

Re: My recent VLAN fiasco [SOLVED]

I have never needed to manually maintain /interface/bridge/vlan table for access ports, ever. I literally just change 'pvid=' per bridge member in /interface/bridge/port, and ROS has always created [D]ynamic entries for those VLANs in the table you reference if they don't exist, and if the VLAN is ...
by CGGXANNX
Thu Mar 27, 2025 8:45 am
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 48
Views: 13114

Re: My recent VLAN fiasco [SOLVED]

I'm not aware of anything that has changed in RouterOS since the new bridge interface with VLAN filtering was introduced in (I think?) 6.41 up through 7.18 that makes setting vlan-filtering=yes on the bridge any more or less safe on any particular version. So I'm not entirely clear what the referen...
by CGGXANNX
Wed Mar 26, 2025 6:59 pm
Forum: Beginner Basics
Topic: Can't get VLAN trunk working
Replies: 10
Views: 1308

Re: Can't get VLAN trunk working

Hm, on the Mokerlink, did you go to "Configuration > VLAN -> 802.1Q VID" and set the PVID for the ports? Port 1 should have PVID 30 Port 2 should have PVID 31 Port 3 should have PVID 32 Port 8 should have PVID 29 And while you are there, change Accepted Frame Type of those ports to only un...
by CGGXANNX
Wed Mar 26, 2025 4:15 pm
Forum: General
Topic: Hairpin Nat for a downstream router? or other options.
Replies: 8
Views: 1317

Re: Hairpin Nat for a downstream router? or other options.

That's interesting, because /ip firewall nat add action=masquerade chain=srcnat comment="HairPin Nat" connection-mark=test-mark dst-address=192.168.1.9 out-interface-list=LAN src-address=192.168.1.0/24 Should actually not be able to catch anything that /ip firewall nat add action=masquerad...
by CGGXANNX
Wed Mar 26, 2025 4:09 pm
Forum: Beginner Basics
Topic: Can't get VLAN trunk working
Replies: 10
Views: 1308

Re: Can't get VLAN trunk working

Interesting. Are you currently connected to port #2 of the Mokelink? According to the screenshot, you are on port 6. Port 6 has no connectivity to the CCR2004.
by CGGXANNX
Wed Mar 26, 2025 2:55 pm
Forum: Beginner Basics
Topic: Can't get VLAN trunk working
Replies: 10
Views: 1308

Re: Can't get VLAN trunk working

The settings on your Molkerlink is currently wrong. A port cannot have multiple VLANs untagged at the same time. Edit the entry for VLAN 1 and remove ports 1, 2, 3, 8, 9 (set to Not Member).
by CGGXANNX
Wed Mar 26, 2025 2:09 am
Forum: General
Topic: Hairpin Nat for a downstream router? or other options.
Replies: 8
Views: 1317

Re: Hairpin Nat for a downstream router? or other options.

For hairpin NAT, your DSTNAT rule cannot use in-interface=ether5 anymore. You will need to replace this rule /ip firewall nat add action=dst-nat chain=dstnat comment="Nat for my server" dst-port=5467 in-interface=ether5 protocol=tcp to-addresses=192.168.1.9 to-ports=5467 with /ip firewall ...
by CGGXANNX
Wed Mar 26, 2025 12:37 am
Forum: General
Topic: VLANs (not) understood
Replies: 11
Views: 1393

Re: VLANs (not) understood

"corresponding entry?" The entry in /interface bridge vlan , with the VLAN ID matching the PVID of the bridge (under /interface bridge), and that has "bridge" in its untagged list. The entry that (if you have not explicitly done it yourself) is automatically created if the bridg...
by CGGXANNX
Tue Mar 25, 2025 11:37 pm
Forum: General
Topic: VLANs (not) understood
Replies: 11
Views: 1393

Re: VLANs (not) understood

Yes. And that's the reason why if you add a VLAN interface to /interface vlan with interface=bridge then "bridge" needs to be in the tagged list of that VLAN ID. Since a few versions RouterOS dynamically adds that to the /interface bridge vlan table for you if you did not do it explicitly....
by CGGXANNX
Tue Mar 25, 2025 11:07 pm
Forum: General
Topic: fasttrack x86
Replies: 26
Views: 5986

Re: fasttrack x86

You only need two back-to-back newlines for all cases. No space needed.
by CGGXANNX
Tue Mar 25, 2025 10:58 pm
Forum: General
Topic: VLANs (not) understood
Replies: 11
Views: 1393

Re: VLANs (not) understood

Yes, and those frames that come to the CPU port (bridge) tagged, you "use" them by adding corresponding interfaces under /interface vlan with interface=bridge . Those interfaces pick the frames with the corresponding VLAN ID tagged (from the CPU port) and strip the tags so that they can be...
by CGGXANNX
Tue Mar 25, 2025 10:37 pm
Forum: General
Topic: [Bug-Fix-Request] DHCP-Option 82 on hEX S not disable HW-Forward by default
Replies: 13
Views: 3508

Re: [Bug-Fix-Request] DHCP-Option 82 on hEX S not disable HW-Forward by default

Also, please note that for the devices with those switch chip (RB5009, CCR2004-16G-2S+, L009), although turning on DHCP Snooping keeps hardware offload on the bridge, it will however make fast path non-functional on the bridge, and it affects fasttrack too. If you have a WAN port outside of the brid...
by CGGXANNX
Tue Mar 25, 2025 9:57 pm
Forum: General
Topic: Beginner VLAN questions
Replies: 32
Views: 3001

Re: Beginner VLAN questions

Oh, and this (on RB3011)

/interface vlan
add interface="lacp_src=rb3011UiAS_dst=crs326-24g-2s+" name=vlan99 vlan-id=99

should be

/interface vlan
add interface=bridge1 name=vlan99 vlan-id=99
by CGGXANNX
Tue Mar 25, 2025 9:48 pm
Forum: General
Topic: Hairpin Nat for a downstream router? or other options.
Replies: 8
Views: 1317

Re: Hairpin Nat for a downstream router? or other options.

First, if you control the DNS resolver used by most client devices in your network (you announce the DNS server via DHCP and the DNS server is hosted internally), then you should make that DNS server rewriting the DNS record of the domain to the local IP address of the service's host. With that most...
by CGGXANNX
Tue Mar 25, 2025 9:27 pm
Forum: General
Topic: Help needed: Choosing an alternative for CCR2216
Replies: 26
Views: 5444

Re: Help needed: Choosing an alternative for CCR2216

I think you need to set l3-hw-offloading of the ports of that VLAN to no (under /interface/ethernet/switch/port)

See https://help.mikrotik.com/docs/spaces/R ... figuration
by CGGXANNX
Tue Mar 25, 2025 8:48 pm
Forum: General
Topic: Beginner VLAN questions
Replies: 32
Views: 3001

Re: Beginner VLAN questions

On your RB3011UiAS you are missing the bridge1 port as tagged port of the VLAN entry. This line: /interface bridge vlan add bridge=bridge1 tagged="lacp_src=rb3011UiAS_dst=crs326-24g-2s+" vlan-ids=\ 99 should become: /interface bridge vlan add bridge=bridge1 tagged="lacp_src=rb3011UiAS...
by CGGXANNX
Tue Mar 25, 2025 8:36 pm
Forum: General
Topic: VLANs (not) understood
Replies: 11
Views: 1393

Re: VLANs (not) understood

For example: "/interface bridge vlan add bridge=bridge tagged=ether1 untagged=bridge vlan-id=10" means that bridge will allow frames with vlan-id=10 to leave the router through ether1 with its vlan tag intact. And, will allow vlan-id=1- frames to egress the router on the bridge port after...
by CGGXANNX
Tue Mar 25, 2025 8:18 pm
Forum: Beginner Basics
Topic: WireGuard with CloudFlare DNS [SOLVED]
Replies: 21
Views: 10009

Re: WireGuard with CloudFlare DNS [SOLVED]

Your redirect rules for intercepting DNS53 are ok. However nowadays many devices and applications (modern web browsers, for instance) support DNS over TLS (DoT), DNS over HTTPS (DoH) and DNS over QUIC (DoQ), which means if you really want to force your kids' devices to use the designated DNS resolve...
by CGGXANNX
Tue Mar 25, 2025 7:14 pm
Forum: Announcements
Topic: New exciting features for storage
Replies: 176
Views: 24692

Re: New exciting features for storage

PM963 are PCIe 3.0 x4. With two lanes data transfer at about 2 GB/s is still possible. See: https://en.wikipedia.org/wiki/PCI_Expre ... ison_table
by CGGXANNX
Tue Mar 25, 2025 6:45 pm
Forum: Beginner Basics
Topic: WireGuard with CloudFlare DNS [SOLVED]
Replies: 21
Views: 10009

Re: WireGuard with CloudFlare DNS [SOLVED]

Regarding accessing Home Assistant using domain name: The optimal way is what you are actually doing, by having the local DNS resolver rewriting the DNS record to the local LAN IP address (instead of the public IP address). That's best for performance, because the devices in the same LAN subnet and ...
by CGGXANNX
Tue Mar 25, 2025 9:56 am
Forum: General
Topic: In case of WAN1-LAN1 and WAN2-LAN2 connections, routing between LAN1 and LAN2 [SOLVED]
Replies: 2
Views: 7825

Re: In case of WAN1-LAN1 and WAN2-LAN2 connections, routing between LAN1 and LAN2 [SOLVED]

Because you are using routing rules to do the WAN1-LAN1 and WAN2-LAN2 force-routing, add this following rule to the top of the routing rule table should re-enable routing between LAN1 and LAN 2 /routing rule add action=lookup disabled=no min-prefix=0 table=main Again, this rule must be above the two...
by CGGXANNX
Tue Mar 25, 2025 9:23 am
Forum: Beginner Basics
Topic: When is connection-nat-state applied (default firewall rule)?
Replies: 13
Views: 2416

Re: When is connection-nat-state applied (default firewall rule)?

I recognize that DST-NAT occurs at the end of the PREROUTING chain, but is the dstnat attribute set for both explicit static DNAT rules, as well as implicit ones set up by SNAT? Or is dstnat only set when matching explicit DNAT rules for something like port forwarding? You can simply open the IP ->...
by CGGXANNX
Mon Mar 24, 2025 10:50 pm
Forum: Beginner Basics
Topic: When is connection-nat-state applied (default firewall rule)?
Replies: 13
Views: 2416

Re: When is connection-nat-state applied (default firewall rule)?

Bearing in mind that there's implicit ultimate rule in every chain (action=accept), the above rule can be re-written into pair of rules: It's not quite correct, the second rule should be: /ip/firewall/filter add chain=forward action=drop in-interface-list=WAN to produce something similar to the ori...
by CGGXANNX
Sun Mar 23, 2025 12:38 pm
Forum: General
Topic: VLAN question about tagging bridge or ether1
Replies: 16
Views: 1547

Re: VLAN question about tagging bridge or ether1

First off all you are doing it wrong, in HEX there's a different way to configure VLAN what you are doing is for CRS3XX Try this https://www.youtube.com/watch?v=Rj9aPoyZOPo No if he is using the RB750Gr3 with RouterOS 7 then what the OP does is the correct way (but ingress-filtering should be set t...
by CGGXANNX
Sat Mar 22, 2025 7:14 pm
Forum: General
Topic: hAP ac2 vs ax2 or ax3 ethernet performance
Replies: 8
Views: 1855

Re: hAP ac2 vs ax2 or ax3 ethernet performance

For the hAP ax² and ax³ currently there is no performance difference if you create additional bridges, because there is no hardware offload to lose. Usually with the other devices only one bridge can be hardware offloaded, and MikroTik advice is normally to only create one bridge per switch chip. Bu...
by CGGXANNX
Sat Mar 22, 2025 7:01 pm
Forum: General
Topic: hAP ac2 vs ax2 or ax3 ethernet performance
Replies: 8
Views: 1855

Re: hAP ac2 vs ax2 or ax3 ethernet performance

It's slower in those particular kind of benchmarks because in RouterOS 7 the route cache is no longer available. You can read more from this thread, especially the posts by @raimondsp: https://forum.mikrotik.com/viewtopic.php?p=882867#p882429 https://forum.mikrotik.com/viewtopic.php?p=882867#p882867...
by CGGXANNX
Sat Mar 22, 2025 11:41 am
Forum: General
Topic: hAP ac2 vs ax2 or ax3 ethernet performance
Replies: 8
Views: 1855

Re: hAP ac2 vs ax2 or ax3 ethernet performance

Be aware that the hAP ac² numbers are RouterOS 6 numbers and you'll need to deduct 25% or so when doing comparisons with the two other RouterOS 7 (out of factory) devices. Look at the hEX RB750Gr3 as an example, before the hEX refresh was announced the old hEX boasted values of 385 Mbps in that spec...
by CGGXANNX
Fri Mar 21, 2025 8:11 pm
Forum: Beginner Basics
Topic: WireGuard with CloudFlare DNS [SOLVED]
Replies: 21
Views: 10009

Re: WireGuard with CloudFlare DNS [SOLVED]

I can't believe it. Same problem again!!! Can't connect from outside. Nothing has changed! I'm going to open a support issue. Wireguard implementation is far from being solid. EDIT I moved from this peer config: add allowed-address=192.168.0.3/28 comment=FLUSHRO2 interface=wireguard1 name=wg1 publi...
by CGGXANNX
Fri Mar 21, 2025 8:05 pm
Forum: Beginner Basics
Topic: WireGuard with CloudFlare DNS [SOLVED]
Replies: 21
Views: 10009

Re: WireGuard with CloudFlare DNS [SOLVED]

I didn't bother to read your full config or the whole thread, but using /28 in your allowed-address entries of the peers is simply wrong, and is exactly the reason why only one device can connect at the same time. Please in all the peer entries under /interface wireguard peers change /28 in the allo...
by CGGXANNX
Fri Mar 21, 2025 9:24 am
Forum: Beginner Basics
Topic: CCR2004-1G-12S+2XS - Slow Speeds Compared to Old CRS125 [SOLVED]
Replies: 4
Views: 8013

Re: CCR2004-1G-12S+2XS - Slow Speeds Compared to Old CRS125 [SOLVED]

For anything >= 1G base-T you need Auto Negotiation turned on. You can try to force it to 1Gbps on both ports by removing the advertised rates, leaving only "1G base T full" and see if the problem is still there. Normally this would have been a typical case where flow control could help (t...
by CGGXANNX
Fri Mar 21, 2025 8:37 am
Forum: General
Topic: PHPbb Prosilver has problem
Replies: 28
Views: 2996

Re: PHPbb Prosilver has problem

Yes, others will probably encounter the issue too if they cleared their browser cache. There is a problem with the forum server since a couple of days. Large transfers are stopped in the middle (usually with connection reset or partial content error). As a result, if the resources are not yet cached...
by CGGXANNX
Fri Mar 21, 2025 7:24 am
Forum: General
Topic: IPv6 Fastpath on 7.18
Replies: 10
Views: 3430

Re: IPv6 Fastpath on 7.18

Yes, you'll need both rules. Also, as documented by @EdPa from MikroTik, some bridge settings like DHCP Snooping cause fast path to be ineffective, as a result, fasttrack will also not work on that bridge (shown as active but the counters do not increase), in those cases you'll only get "partia...
by CGGXANNX
Thu Mar 20, 2025 10:19 pm
Forum: Beginner Basics
Topic: CCR2004-1G-12S+2XS - Slow Speeds Compared to Old CRS125 [SOLVED]
Replies: 4
Views: 8013

Re: CCR2004-1G-12S+2XS - Slow Speeds Compared to Old CRS125 [SOLVED]

If possible, try turning on flow control on both the SFP+ interfaces.
by CGGXANNX
Thu Mar 20, 2025 4:02 am
Forum: General
Topic: Weekly VLAN confusion post
Replies: 18
Views: 2129

Re: Weekly VLAN confusion post

For this topic, where VLAN Filtering is the goal, Fast Forward's status is irrelevant, it would be inactive anyway.
by CGGXANNX
Wed Mar 19, 2025 9:59 pm
Forum: General
Topic: Blocking the "standard"/most common DNS-over-HTTPS servers
Replies: 15
Views: 2061

Re: Blocking the "standard"/most common DNS-over-HTTPS servers

Maybe you can use the IP address list from here and manually & periodically update the address list in RouterOS https://github.com/crypt0rr/public-doh-servers
by CGGXANNX
Wed Mar 19, 2025 9:55 pm
Forum: General
Topic: DHCP Client declining a DHCP offer
Replies: 6
Views: 1359

Re: DHCP Client declining a DHCP offer

Additionally, a /ip dhcp-server network entry is missing.
by CGGXANNX
Wed Mar 19, 2025 4:03 pm
Forum: General
Topic: Route marked inactive when gateway is reachable.
Replies: 5
Views: 1095

Re: Route marked inactive when gateway is reachable.

Yes, the part that I linked to specifically mentioned the changes from v6 to v7 regarding scope and nexthop (and the reasons).
by CGGXANNX
Wed Mar 19, 2025 8:59 am
Forum: General
Topic: Weekly VLAN confusion post
Replies: 18
Views: 2129

Re: Weekly VLAN confusion post

OK, let's do this in correct order and one step at a time. Correct order: /interface bridge add /interface bridge port add /interface bridge vlan add /interface vlan add Do we agree on this? I would say this is better /interface bridge add /interface vlan add + configure IP address + DHCP server + ...
by CGGXANNX
Wed Mar 19, 2025 7:56 am
Forum: General
Topic: IPv6 dynamically allocated pool's valid-lifetime
Replies: 2
Views: 961

Re: IPv6 dynamically allocated pool's valid-lifetime

For this reason (and others, like when you make modification to a vlan or bridge interface, the interface immediately gets new prefix from the pool) I've been setting valid lifetime and preferred lifetime on all of my routers to only 10 minutes. Then I would have to deal with wrong prefixes for at m...
by CGGXANNX
Wed Mar 19, 2025 6:46 am
Forum: General
Topic: Route marked inactive when gateway is reachable.
Replies: 5
Views: 1095

Re: Route marked inactive when gateway is reachable.

You need to set the target-scope value of the dst-address=63.116.158.80/30 gateway=63.116.158.74 route to be at least the scope value of the dst-address=63.116.158.74/32 gateway=vlan44_vrrp route. Read more about it here https://help.mikrotik.com/docs/spaces/ROS/pages/328084/IP+Routing#IPRouting-Nex...
by CGGXANNX
Tue Mar 18, 2025 9:50 am
Forum: General
Topic: forum guru status
Replies: 27
Views: 3047

Re: forum guru status

Here is a handy guide for Australia. Is that far enough? https://wifiwizardofoz.com/wp-content/uploads/australian_802.11_eirp_transmit_power_limits.pdf 4W on 2.4, up to 4W on 5, depending on band. That table has the EIRP (≈ transmit power + antenna gain) values though. The US will allow 4W EIRP for...
by CGGXANNX
Mon Mar 17, 2025 8:05 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 326
Views: 553516

Re: Using RouterOS to VLAN your network

That screenshot is from my main router, and it has been like that since ages and all VLANs work without issue :). For this tab, "bridge" acts as a port (like etherX, where you have the same tab with the same options) and setting Frame Types here only affect the "bridge" port, whi...
by CGGXANNX
Mon Mar 17, 2025 7:41 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 584
Views: 220579

Re: v7.18.2 [stable] is released!

i am using the hAP ac² as a wired only router too, with neither wireless nor wifi-qcom-ac installed. As such it's much better at routing than both the hEX 750Gr3 (3x faster) and the hEx refresh E50UG (1.5x faster), by having true 4 ARM cores instead of 2. IPsec and WireGuard are faster on the hAP ac...
by CGGXANNX
Mon Mar 17, 2025 6:53 pm
Forum: MikroTik hardware questions
Topic: Switch product requests
Replies: 3
Views: 1113

Re: Switch product requests

And here is the one with 8×2.5G and 2 SFP+ that you can use for 10G https://mikrotik.com/product/crs310_8g_2s_in.
by CGGXANNX
Mon Mar 17, 2025 6:46 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 326
Views: 553516

Re: Using RouterOS to VLAN your network

I think the goal is not to have any unwanted VLAN ID appearing in the /interface bridge vlan table. Ingress filtering should be turned on for all ports, including "bridge", then you can keep 1 as the PVID of "bridge" but here you should also set frame-types to admit-only-vlan-tag...
by CGGXANNX
Mon Mar 17, 2025 6:18 pm
Forum: Beginner Basics
Topic: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492
Replies: 107
Views: 16089

Re: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492

Normally the file without platform suffix, the one named routeros-7.18_ab244.npk is for x86 (same naming convention as on https://mikrotik.com/download).
by CGGXANNX
Mon Mar 17, 2025 11:03 am
Forum: MikroTik hardware questions
Topic: RouterOS questions
Replies: 7
Views: 1814

Re: RouterOS questions

Can RouterOS do the following: Auto register DHCPv4 and v6 dynamic leases in DNS Auto register DHCPv4 and v6 fixed leases in DNS Currently it's possible with DHCPv4, but you need to write a script and execute it with the "lease-script" property of the DHCPv4 server instance, and add the h...
by CGGXANNX
Mon Mar 17, 2025 10:24 am
Forum: Beginner Basics
Topic: Port forwarding working from the "outside" not working from the "inside" [SOLVED]
Replies: 2
Views: 8599

Re: Port forwarding working from the "outside" not working from the "inside" [SOLVED]

You'll need to put this dstnat rule (with xxx.xxx.xxx.xxx being your fixed ISP provided address) before the existing dstnat rule: /ip firewall nat add action=dst-nat chain=dstnat dst-address=xxx.xxx.xxx.xxx dst-port=22 protocol=tcp to-addresses=192.168.xxx.xxx to-ports=6022 Note: you need both rules...
by CGGXANNX
Sun Mar 16, 2025 2:11 pm
Forum: General
Topic: Reading test results [SOLVED]
Replies: 3
Views: 9143

Re: Reading test results [SOLVED]

That rule of thumb is quite accurate if you take the default configuration (with the firewall rules from MIkroTik) and disable the fasttrack rule (or before 7.18 when you use the default config with IPv6, because fasttrack was not available). If your configuration can actively make use of fasttrack,...
by CGGXANNX
Sat Mar 15, 2025 3:49 pm
Forum: The User Manager
Topic: DHCP on Vlan [SOLVED]
Replies: 5
Views: 9872

Re: DHCP on Vlan [SOLVED]

You didn't even read the posts that @erlinden linked for you? Please read that first. Where is your bridge? Your L009 has a good switch chip with hardware offload for VLAN Filtering. You should create one unique bridge over ether2-ether8 and sfp1, but keep ether1 out of that bridge. Then configure B...
by CGGXANNX
Sat Mar 15, 2025 7:28 am
Forum: Wireless Networking
Topic: Unifi access point
Replies: 16
Views: 3541

Re: Unifi access point

Do your old router and the new MikroTik one have the same LAN subnet? If not there's probably somewhere in the UniFi controller setting where old addresses/address range are hardcoded. First update both the UniFi controller (on Windows) as well as the firmware of the access points to the latest avai...
by CGGXANNX
Fri Mar 14, 2025 10:58 am
Forum: General
Topic: ipv6 fixed prefix router advertisements
Replies: 9
Views: 1561

Re: ipv6 fixed prefix router advertisements

they route over the dynamic address. So, at the moment you dial PPPoE and configure DHCPv6 client over that pppoe-out interface and get the dynamic IPv6 prefix? And they give you via email the extra fixed /48 prefix? Normally because you use PPPoE the ISP can just use your end of the PPPoE connecti...
by CGGXANNX
Fri Mar 14, 2025 2:37 am
Forum: General
Topic: Feature Request: LetsEncrypt certs via DNS Challenge
Replies: 10
Views: 1884

Re: Feature Request: LetsEncrypt certs via DNS Challenge

I have CNAME records pointing to the xxx.sn.mynetname.net of my routers and enable-ssl-certificate dns-name=my.own.domain has always been working (of course port 80 must be temporarily opened and www also has to be temporarily enabled). Generated certs work for www-ssl, SSTP and User Manager, althou...
by CGGXANNX
Thu Mar 13, 2025 5:26 pm
Forum: Wireless Networking
Topic: Wrong DHCP with VLANs
Replies: 9
Views: 1845

Re: Wrong DHCP with VLANs

About switchAttempt.rsc (I've only looked at that file), if you want to use the BASE_MGMT vlan interface you need to set secure mode (under /interface ethernet switch port ) on the switch1-cpu port too, not only the 5 ethernet ports. And for the hEX PoE with QCA8337 you should turn on indepenent-lea...
by CGGXANNX
Thu Mar 13, 2025 10:14 am
Forum: General
Topic: Bridge VLAN Filtering Problem
Replies: 24
Views: 3119

Re: Bridge VLAN Filtering Problem

I've investigated further and it looks like maybe @LdB's issues and the issues encountered in my tests might not be the same! First to answer jbl42: I have DHCP snooping disabled on the RB5009 since https://forum.mikrotik.com/viewtopic.php?t=212754&start=300#p1118102, and because of this detail ...
by CGGXANNX
Wed Mar 12, 2025 6:35 pm
Forum: General
Topic: Bridge VLAN Filtering Problem
Replies: 24
Views: 3119

Re: Is this a bug or something not documented

Hi Anav, It appears to make no sense to you because really in this case the MikroTik devices (at least my RB5009 as well as OP's devices) are not acting as expected with regards to DHCP traffics. The OP (and I in the tests) want the MikroTik device to act as a switch, its job should only be to pass ...
by CGGXANNX
Wed Mar 12, 2025 1:23 pm
Forum: General
Topic: Bridge VLAN Filtering Problem
Replies: 24
Views: 3119

Re: Is this a bug or something not documented

I can reproduce this behavior. However, in my case, even adding the VLAN as /interface vlan entry with bridge as parent doesn't help. Test config were: A. ether1 as hybrid port, with VLAN 124 tagged. ether5 as access port of VLAN 124. No /interface vlan entry configured for VLAN 124. /interface brid...
by CGGXANNX
Tue Mar 11, 2025 9:11 pm
Forum: General
Topic: dhcp server accounting radius - important info missing
Replies: 4
Views: 2669

Re: dhcp server accounting radius - important info missing

I think the data is not available because the DHCP server does not keep track of such information (packet and byte counters) for each lease. It's also logical that it cannot do that because normally traffic between devices on the same layer 2 (same subnet) is not visible to the router, only to the s...
by CGGXANNX
Tue Mar 11, 2025 8:12 pm
Forum: General
Topic: IPv4 FastTrack bypasses queues? [SOLVED]
Replies: 3
Views: 6866

Re: IPv4 FastTrack bypasses queues [SOLVED]

It's clearly stated in the docs https://help.mikrotik.com/docs/spaces/ROS/pages/328227/Packet+Flow+in+RouterOS#PacketFlowinRouterOS-FastTrack FastTrack packets bypass firewall, connection tracking, simple queues , queue tree with parent=global, ip traffic-flow, IP accounting, IPSec, hotspot universa...
by CGGXANNX
Tue Mar 11, 2025 1:56 pm
Forum: General
Topic: Wireguard Keeps trying to reconnect
Replies: 16
Views: 4261

Re: Wireguard Keeps trying to reconnect

This is still happening for me in 7.18.1.

Enable the "Responder" checkbox for the affected peer in RouterOS.
by CGGXANNX
Tue Mar 11, 2025 1:21 pm
Forum: General
Topic: How to force "Actual MTU" on PPPoE client [SOLVED]
Replies: 21
Views: 20623

Re: How to force "Actual MTU" on PPPoE client [SOLVED]

There is no need to change MTU for any ethernet interface at all, VLAN or not. What important is only the L2MTU value, which should be at least 1508 (L2MTU for VLAN interfaces are already automatically reduced by 4 bytes). For most MikroTik hardware that's the case by default. To have IPv4 TCP MSS a...
by CGGXANNX
Mon Mar 10, 2025 11:38 pm
Forum: General
Topic: hEX PoE (bridge mode) is only a switch ?
Replies: 17
Views: 3431

Re: hEX PoE (bridge mode) is only a switch ?

Can you post the text export of the relevant settings for your VLAN 312, both the "bridge" and the "switch" settings, so that I can maybe understand how the "normal" bridge ones are translated into the switch ones? Those settings were temporary, so I am not able to use...
by CGGXANNX
Mon Mar 10, 2025 8:13 am
Forum: General
Topic: hEX PoE (bridge mode) is only a switch ?
Replies: 17
Views: 3431

Re: hEX PoE (bridge mode) is only a switch ?

As promised, here are some test results from my hAP ac². Two wired PCs are connected directly to ports ether2 and ether5 of the router and run iperf3 (in one direction). * First the bridge as configured by defconf is used. No VLAN is configured. 10.14.2.0/24 is the subnet of the bridge. CPU usage is...
by CGGXANNX
Sun Mar 09, 2025 4:20 pm
Forum: General
Topic: Why does FastTrack cause super-slow TCP connections for some devices?
Replies: 13
Views: 2404

Re: Why does FastTrack cause super-slow TCP connections for some devices?

Only on some high-end CCR/CRS models is fasttrack hardware offloaded. On most MikroTik's devices, including cheaper CRS and anything <= CCR2004, it's a software mechanism. As for why the accept rule is needed: It's explained in the docs: https://help.mikrotik.com/docs/spaces/ROS/pages/328227/Packet+...
by CGGXANNX
Sat Mar 08, 2025 7:37 pm
Forum: General
Topic: iOS and MacOS clients lose IPv6 connectivity
Replies: 28
Views: 4588

Re: iOS and MacOS clients lose IPv6 connectivity

Ah yes, can you try to do as @mkx wrote and turn on Multicast Enhancement in the SSID profiles (WiFi) for your UniFi APs? I thought that it was by default turned on so in my old post suggested to try to toggle it off. But I just checked, and the default setting for Multicast Enhancement is off for n...
by CGGXANNX
Fri Mar 07, 2025 11:08 pm
Forum: General
Topic: WAN-capable ports on routers [SOLVED]
Replies: 24
Views: 8578

Re: WAN-capable ports on routers [SOLVED]

Don't forget to read about the hardware limitations of the DX8000 chips in the CCR2216. Namely it has only 4K entries for NAT and 4.5K fasttrack connections. If your network has more concurrent connections to the WAN then the rest will not be hardware offloaded. That's why the fasttrack rule has the...
by CGGXANNX
Fri Mar 07, 2025 10:53 pm
Forum: General
Topic: hEX PoE (bridge mode) is only a switch ?
Replies: 17
Views: 3431

Re: hEX PoE (bridge mode) is only a switch ?

Yes, it mostly affects the switching functionality. Like when you have your NAS connected to one port of the router (maybe behind other switches), and your PC on another port (also maybe behind other switches), and both devices are in the same layer 2 network (same VLAN, same subnet let's say 192.16...
by CGGXANNX
Fri Mar 07, 2025 10:40 pm
Forum: General
Topic: WAN-capable ports on routers [SOLVED]
Replies: 24
Views: 8578

Re: WAN-capable ports on routers [SOLVED]

Thank you for your detailed response, it is very useful. I just wanted to clarify something: it seems like L009 became a distraction, as somebody else in the thread mentioned it as an example, but this is not the router I have. I have CCR2216-1G-12XS-2XQ and CCR2004-1G-12S+2XS, does everything you ...
by CGGXANNX
Fri Mar 07, 2025 9:40 pm
Forum: General
Topic: hEX PoE (bridge mode) is only a switch ?
Replies: 17
Views: 3431

Re: hEX PoE (bridge mode) is only a switch ?

For normal WAN - LAN usage there might be not much difference, because the offloading of the switch chip is not really being used, the CPU has to do most of the work moving packets between the off-bridge WAN port and any other on-bridge LAN ports. In case the LAN use VLAN then the switch chip might ...
by CGGXANNX
Fri Mar 07, 2025 4:42 pm
Forum: General
Topic: WAN-capable ports on routers [SOLVED]
Replies: 24
Views: 8578

Re: WAN-capable ports on routers [SOLVED]

Their marketing values are the one in the 1518 columns :). The 25-rule-1518-byte value can probably never be achieved in real life when there are meaningful firewall filters with fasttrack unavailable . That is where the "marketing" is and where they are overselling it. Usually, most speed...
by CGGXANNX
Fri Mar 07, 2025 11:55 am
Forum: General
Topic: ROS v7 Radius Dictionary?
Replies: 4
Views: 1458

Re: ROS v7 Radius Dictionary?

User Manager in ROS7 is MikroTik's implementation of a RADIUS server, mostly to be used with devices running RouterOS as acting the RADIUS clients. That may be why it has the custom MikroTik attributes pre-defined.
by CGGXANNX
Fri Mar 07, 2025 11:48 am
Forum: General
Topic: ROS v7 Radius Dictionary?
Replies: 4
Views: 1458

Re: ROS v7 Radius Dictionary?

If you have the User-Manager package installed, you can see the definition of this custom attribute: mikrotik-switching-filter.png Alternatively, the IDs are also available in this section of the documentation: https://help.mikrotik.com/docs/spaces/ROS/pages/2555940/User+Manager#UserManager-Attributes
by CGGXANNX
Fri Mar 07, 2025 11:24 am
Forum: General
Topic: WAN-capable ports on routers [SOLVED]
Replies: 24
Views: 8578

Re: WAN-capable ports on routers [SOLVED]

The 25 rules 512 bytes value is representative for cases where fasttrack cannot be actively used. Like when using mangle mark-routing, or on previous RouterOS versions when using IPv6. For normal configs that can take advantage of fasttrack, throughputs nearer to the fast path value is achievable, a...
by CGGXANNX
Fri Mar 07, 2025 9:58 am
Forum: General
Topic: WAN-capable ports on routers [SOLVED]
Replies: 24
Views: 8578

Re: WAN-capable ports on routers [SOLVED]

Thank you for advice, but may I ask why would it better to load CPU with all WAN-bound traffic? Provided that I can (and routinely do) make all ports assigned to LAN as a separate bridge anyway and never include WAN port into that bridge? Wouldn't it be better to use one port from the hardware offl...
by CGGXANNX
Fri Mar 07, 2025 9:33 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 584
Views: 220579

Re: v7.18.1 [stable] is released!

/interface ovpn-server server add mac-address=[...] name=ovpn-server1 While it's disabled by default, I would prefer default config and especially updates not to create bogus interfaces. This happened because in 7.17 supports for multiple OVPN server instances were introduced. In previous version t...
by CGGXANNX
Fri Mar 07, 2025 9:20 am
Forum: General
Topic: iOS and MacOS clients lose IPv6 connectivity
Replies: 28
Views: 4588

Re: iOS and MacOS clients lose IPv6 connectivity

Can you try to reduce these values to 10 minutes and toggle network connectivity on the affected client devices (wifi off/on, cable out/in): ipv6-nd-lifetime.png Those were actually the old default values, but now the default values in newer RouterOS are very high (30 days and 7 days). On all of my ...
by CGGXANNX
Thu Mar 06, 2025 9:23 pm
Forum: Beginner Basics
Topic: Hex DHCPv6 client stuck at "searching..." with Xfinity/Comcast [SOLVED]
Replies: 2
Views: 6295

Re: Hex DHCPv6 client stuck at "searching..." with Xfinity/Comcast [SOLVED]

The order of the rules in the filter firewall is important because within the same chain (in this case "input") the rules are processed from top to bottom. Currently your rule with the comment "Replaces defconf rule for DHCPv6 client prefix delegation..." sits at the bottom of th...
by CGGXANNX
Thu Mar 06, 2025 7:56 pm
Forum: General
Topic: hEX PoE (bridge mode) is only a switch ?
Replies: 17
Views: 3431

Re: hEX PoE (bridge mode) is only a switch ?

When configuring the bridge and VLANs on the hEX PoE, don't forget that it has a QCA8337 switch chip connecting the five ethernet ports. Which means to configure the VLANs you should use the /interface ethernet switch menu instead of Bridge VLAN Filtering. See: https://help.mikrotik.com/docs/spaces/...
by CGGXANNX
Thu Mar 06, 2025 7:39 pm
Forum: General
Topic: Bad performance with CRS310-8G+2S+IN working at 2.5Gbps [SOLVED]
Replies: 21
Views: 8281

Re: Bad performance with CRS310-8G+2S+IN working at 2.5Gbps [SOLVED]

Did you try enabling flow control on the ethernet ports of the CRS310 (at least on ether1 and ether8 according to your diagram)? Looking at this: 2.5-1G-flow.png Ethernet frames travelling along the green path might reach a rate of 2.5Gbps to arrive at the Fritz!box. From there the orange path can o...
by CGGXANNX
Thu Mar 06, 2025 6:42 am
Forum: General
Topic: WAN-capable ports on routers [SOLVED]
Replies: 24
Views: 8578

Re: WAN-capable ports on routers [SOLVED]

Please note that some router models, such as the L009UiGS-RM https://cdn.mikrotik.com/web-assets/product_files/L009UiGS-RM_230555.png, has a good switch chip with hardware offload connecting most of the ports, and one (usually ether1) or a few ports connecting directly to the CPU. In such cases it w...
by CGGXANNX
Thu Mar 06, 2025 4:52 am
Forum: Beginner Basics
Topic: Re: Setting Up Policy-Based Routing with Mikrotik Hex Refresh for Selective VPN Traffic [SOLVED]
Replies: 51
Views: 13968

Re: Setting Up Policy-Based Routing with Mikrotik Hex Refresh for Selective VPN Traffic [SOLVED]

If the NAS only accept connections to it from the same subnet as itself, then one possible "solution" is to masquerade the connections from vlan20 to the NAS, with a NAT firewall rule: chain=srcnat action=masquerade src-address=192.168.20.0/24 dst-address-list=NAS_DEVICES. Where NAS_DEVICE...
by CGGXANNX
Wed Mar 05, 2025 9:35 pm
Forum: Beginner Basics
Topic: Re: Setting Up Policy-Based Routing with Mikrotik Hex Refresh for Selective VPN Traffic [SOLVED]
Replies: 51
Views: 13968

Re: Setting Up Policy-Based Routing with Mikrotik Hex Refresh for Selective VPN Traffic [SOLVED]

... but it still shows my local IP :( Don't forget to check whether the fasttrack rule in the Filter table has the connection-mark=no-mark really applied. After that, check the followings: * In IP -> Route, is the flag AS shown next to the route with destination 0.0.0.0/0 in the USE_WG table? * In ...
by CGGXANNX
Wed Mar 05, 2025 8:56 pm
Forum: Beginner Basics
Topic: Re: Setting Up Policy-Based Routing with Mikrotik Hex Refresh for Selective VPN Traffic [SOLVED]
Replies: 51
Views: 13968

Re: Setting Up Policy-Based Routing with Mikrotik Hex Refresh for Selective VPN Traffic [SOLVED]

At quick glance you are missing a route in the main table, step #13 of my previous post. What is shown as (step 13) in your file is actually #14 from my post. Also the command that you use to modify the fasttrack rule look for rule with comment "defconf: fasttrack rule". Are you sure that ...
by CGGXANNX
Wed Mar 05, 2025 4:13 pm
Forum: General
Topic: Why does FastTrack cause super-slow TCP connections for some devices?
Replies: 13
Views: 2404

Re: Why does FastTrack cause super-slow TCP connections for some devices?

It is written everywhere in the Mikrotik docs, that fasttrack only works on main routing table.

It's compatible when connections are put into routing tables other than "main" too, but that must be done with routing rules, not with mangle rules.
by CGGXANNX
Wed Mar 05, 2025 2:22 pm
Forum: General
Topic: Why does FastTrack cause super-slow TCP connections for some devices?
Replies: 13
Views: 2404

Re: Why does FastTrack cause super-slow TCP connections for some devices?

One of the possible causes is that you have mangle mark-routing rules that put packets of a connection in a routing table other than "main", but did not try to exclude those connection from the fasttrack rule.
by CGGXANNX
Wed Mar 05, 2025 2:06 pm
Forum: General
Topic: My Mikrotik is sometimes incredible slow, need help.
Replies: 19
Views: 2640

Re: My Mikrotik is sometimes incredible slow, need help.

He has all ethernet ports set to 100Mbps. I don't know if it's deliberate. But auto-negotiation seems to still be enabled.
by CGGXANNX
Wed Mar 05, 2025 1:53 pm
Forum: General
Topic: My Mikrotik is sometimes incredible slow, need help.
Replies: 19
Views: 2640

Re: My Mikrotik is sometimes incredible slow, need help.

This is the doc for RouterOS 6 https://wiki.mikrotik.com/Manual:IP/Fasttrack. You'll need the two firewall rules under the Initial configuration section. As well as this:

  • FastPath and Route cache is enabled under IP/Settings
by CGGXANNX
Wed Mar 05, 2025 1:45 pm
Forum: General
Topic: My Mikrotik is sometimes incredible slow, need help.
Replies: 19
Views: 2640

Re: My Mikrotik is sometimes incredible slow, need help.

At least you can try to enable fasttrack?
by CGGXANNX
Tue Mar 04, 2025 6:24 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 584
Views: 220579

Re: v7.18.1 [stable] is released!

I think the reason this has a high probability of appearing at reboot is because while the router is being rebooted, clients in the network are still firing DNS queries at it (everything requires address resolution and TTL are nowadays quite short). Normally the queries are made with UDP and are not...
by CGGXANNX
Tue Mar 04, 2025 11:58 am
Forum: Beginner Basics
Topic: Re: Setting Up Policy-Based Routing with Mikrotik Hex Refresh for Selective VPN Traffic [SOLVED]
Replies: 51
Views: 13968

Re: Setting Up Policy-Based Routing with Mikrotik Hex Refresh for Selective VPN Traffic [SOLVED]

I don't have time to produce a ready-to-copy-n-paste configuration for you, but this is the rough idea of the steps that you'll need. 1, Start from the default MikroTik configuration of your hEX refresh (the defconf ), with working main internet connection. 2, Create WireGuard interface (let's say w...
by CGGXANNX
Tue Mar 04, 2025 10:27 am
Forum: Beginner Basics
Topic: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492
Replies: 107
Views: 16089

Re: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492

so I have manually set MTU of ether1 to 1508. As ISP uses VLAN10 a VLAN interface was added for ether1 also with an MTU of 1508 You don't need to change/increase the MTU setting of the ethernet and VLAN interface underneath the PPPoE client interface. You only need to set Max MRU and Max MTU to 150...
by CGGXANNX
Tue Mar 04, 2025 10:07 am
Forum: Beginner Basics
Topic: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492
Replies: 107
Views: 16089

Re: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492

why does VyOS only go to 1492 instead of 1500 ??? For VyOS to set ppp-max-payload=1500 in the PADI message the OP will need to do the following: * Set mru and mtu on the pppoe interface to 1500 (E.g. set interfaces pppoe pppoe0 mru 1500 / set interfaces pppoe pppoe0 mtu 1500 ), or delete both (don'...
by CGGXANNX
Mon Mar 03, 2025 8:48 am
Forum: General
Topic: BOOTP/DHCP bypasses NAT firewall
Replies: 20
Views: 3252

Re: BOOTP/DHCP bypasses NAT firewall

Because DHCP use raw sockets. Here is some literature (from ISC DHCP but should also apply to MikroTik's implementation).
https://kb.isc.org/docs/aa-00378
by CGGXANNX
Sun Mar 02, 2025 7:15 pm
Forum: Beginner Basics
Topic: Wireguard - can not have active more than 1 peer [SOLVED]
Replies: 4
Views: 6855

Re: Wireguard - can not have active more than 1 peer [SOLVED]

You need to change the prefix length /24 in the allowed-address field (and client-address field too) of the peers to /32.
by CGGXANNX
Sat Mar 01, 2025 7:07 am
Forum: Announcements
Topic: New exciting features for storage
Replies: 176
Views: 24692

Re: New exciting features for storage

Even vanilla Btrfs RAID 1 can be a real headache, for example, if a disk intermittently disconnects or fails for some reason and then gets marked as unreliable. Restoring a Btrfs RAID 1 is a pretty complicated process and requires expert knowledge, as @Petch1 pointed out in another thread. In other...
by CGGXANNX
Sat Mar 01, 2025 6:56 am
Forum: General
Topic: iOS and MacOS clients lose IPv6 connectivity
Replies: 28
Views: 4588

Re: iOS and MacOS clients lose IPv6 connectivity

Because what you observed is common on configurations with IGMP Snooping enabled on hardware offloaded bridge (like my RB5009) when VLANs are in used. After some time, the MDB table no longer has the entries for the multicast addresses of the devices, as a result the router advertisement packets are...
by CGGXANNX
Sat Mar 01, 2025 6:40 am
Forum: General
Topic: iOS and MacOS clients lose IPv6 connectivity
Replies: 28
Views: 4588

Re: iOS and MacOS clients lose IPv6 connectivity

Do you have IGMP Snooping turned on on the router?
by CGGXANNX
Fri Feb 28, 2025 8:59 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2207
Views: 3761869

Re: 📣 WinBox 4 is here 📣

Thank you, yes, this new version is perfect download/file.php?id=72191
by CGGXANNX
Fri Feb 28, 2025 8:24 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2207
Views: 3761869

Re: 📣 WinBox 4 is here 📣

One thing in your design that needs improvement, and this was also an usability issue in WinBox 3, are these tiny buttons to add/remove items. They were always too small for me in WinBox 3 and difficult to hit even with the mouse (forget about touchscreen). tiny.png WinBox 4 actually improves in thi...
by CGGXANNX
Fri Feb 28, 2025 4:19 pm
Forum: General
Topic: PPPoE and MTU > 1488
Replies: 14
Views: 8954

Re: PPPoE and MTU > 1488

RFC 4638 and PPPoE with MTU 1500 work on all of my MikroTik devices. But I've seen multiple people (MikroTik forum in my country) using x86 having the same issue as himurae, where the MTU drops to 1480 because large LCP EchoReq packets cannot be sent. But threre are also people with x86 RouterOS whe...
by CGGXANNX
Thu Feb 27, 2025 10:33 am
Forum: General
Topic: HEX Refresh Slow HW Offloading
Replies: 4
Views: 2986

Re: HEX Refresh Slow HW Offloading

Do you have IGMP Snooping or DHCP Snooping enabled on the bridge?
by CGGXANNX
Thu Feb 27, 2025 9:03 am
Forum: Beginner Basics
Topic: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492
Replies: 107
Views: 16089

Re: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492

I guess another thing that you can try is to turn on the VLAN Aware checkbox in Proxmox on the Linux Bridge matching the interface used to dial PPPoE? It probably won't help much though. Another attempt that requires more work is to passthrough the network adapter (NIC Passthrough) instead of using ...
by CGGXANNX
Wed Feb 26, 2025 6:14 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 584
Views: 220579

Re: v7.18 [stable] is released!

If you have DHCP Snooping / IGMP Snooping turned on on the bridge, try to disable those features first. At least DHCP Snooping is confirmed by the updated documentation to cause fast-path to be non-working, which causes fasttrack to be useless on that bridge. https://help.mikrotik.com/docs/spaces/RO...
by CGGXANNX
Wed Feb 26, 2025 4:54 pm
Forum: Beginner Basics
Topic: Finally made DUAL WAN work!
Replies: 61
Views: 10036

Re: Finally made DUAL WAN work!

Interesting solution, Q 1 : but why do you use recursive scope can you test with defaults scope=10 target-scope=30 I believe... The default scopes was in the config at the start of my post from yesterday https://forum.mikrotik.com/viewtopic.php?t=215016#p1128526, you can see "30 _ 10 _ TEST1&q...
by CGGXANNX
Wed Feb 26, 2025 2:20 pm
Forum: Beginner Basics
Topic: Finally made DUAL WAN work!
Replies: 61
Views: 10036

Re: Finally made DUAL WAN work!

Okay CGG, I am down to this. /ip route { main table } add check-gateway=ping " dst-address=0.0.0.0/0 gateway=8.8.8.8 routing-table=main scope=10 target-scope=12 add dst-address=8.8.8.8/32 gateway=ISP1 Gateway routing-table=main scope=10 target-scope=11 +++++++++++++++++ add check-gateway=ping ...
by CGGXANNX
Wed Feb 26, 2025 10:49 am
Forum: Beginner Basics
Topic: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492
Replies: 107
Views: 16089

Re: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492

If you use Proxmox, can you try in Proxmox to increase the MTU value of: * The network device (ensXXXX) corresponding to the port connecting to the ISP * The corresponding Linux bridge over that port to, let's say 1540 (assuming the network adapter support jumbo frames)? Or are you using NIC passthr...
by CGGXANNX
Wed Feb 26, 2025 9:14 am
Forum: Beginner Basics
Topic: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492
Replies: 107
Views: 16089

Re: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492

You can only change L2MTU on MikroTik made devices. You have a x86 system with network adapters not in control of MikroTik so that is not possible. Do you run RouterOS directly on the mini PC or do you have a hypervisor in between?
by CGGXANNX
Tue Feb 25, 2025 10:47 pm
Forum: General
Topic: Recursive routing not working while using wireguard interface as gateway [SOLVED]
Replies: 12
Views: 10997

Re: Recursive routing not working while using wireguard interface as gateway [SOLVED]

You need to add a routing rule to make sure traffic goes through the "TEST1" table instead of the "main" table. For example: "/ip route rule add src-address=x.x.x.x/y action=lookup table=TEST1". This makes sure routing follows the specified table for the given source a...
by CGGXANNX
Tue Feb 25, 2025 10:30 pm
Forum: General
Topic: ip cloud address different from pppoe-out local address
Replies: 5
Views: 3041

Re: ip cloud address different from pppoe-out local address

Your ISP implements CGNAT https://en.wikipedia.org/wiki/Carrier-grade_NAT. You can either ask them to take you out of the CGNAT pool or use IPv6.
by CGGXANNX
Tue Feb 25, 2025 10:27 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 584
Views: 220579

Re: v7.18 [stable] is released!

The behavior with the incremented prefix was always there. If the interface (bridge, vlan, etc...) gets the address with the prefix from a pool, and you make any modifications to the interface (for instance toggling IGMP Snooping on the bridge interface or changing ARP mode on a VLAN interface), the...
by CGGXANNX
Tue Feb 25, 2025 10:17 pm
Forum: General
Topic: Can ping container from terminal but not PC
Replies: 4
Views: 2906

Re: Can ping container from terminal but not PC

Did you restart the container after changing 192.168.10.44/32 to 192.168.10.44/24?

You can run

/container/print

Note the number (for instance 0) then open the shell with that number

/container/shell 0

and try pinging 192.168.10.1 from there.
by CGGXANNX
Tue Feb 25, 2025 10:02 pm
Forum: Beginner Basics
Topic: Finally made DUAL WAN work!
Replies: 61
Views: 10036

Re: Finally made DUAL WAN work!

I tried this too, but I didn't manage to make it works. Sorry, I don't know why. I think this is the relevant section in the documentation: https://help.mikrotik.com/docs/spaces/ROS/pages/59965508/Policy+Routing For a user-created table to be able to resolve the destination, the main routing table ...
by CGGXANNX
Tue Feb 25, 2025 9:47 pm
Forum: General
Topic: Recursive routing not working while using wireguard interface as gateway [SOLVED]
Replies: 12
Views: 10997

Re: Recursive routing not working while using wireguard interface as gateway [SOLVED]

I think this is the relevant section in the documentation: https://help.mikrotik.com/docs/spaces/ROS/pages/59965508/Policy+Routing#PolicyRouting-RoutingTables With this warning and excerpt: For a user-created table to be able to resolve the destination, the main routing table should be able to resol...
by CGGXANNX
Tue Feb 25, 2025 9:16 pm
Forum: Beginner Basics
Topic: Finally made DUAL WAN work!
Replies: 61
Views: 10036

Re: Finally made DUAL WAN work!

Can you try to close the Route List dialog and open it again? Sometimes WinBox has problem refreshing the listed routes.
by CGGXANNX
Tue Feb 25, 2025 9:08 pm
Forum: General
Topic: Recursive routing not working while using wireguard interface as gateway [SOLVED]
Replies: 12
Views: 10997

Re: Recursive routing not working while using wireguard interface as gateway [SOLVED]

I updated my post above with the link to my other post where you can see that it works not only with WG interfaces (that 10.24.10.1 gateway), but also with other type of interfaces.
by CGGXANNX
Tue Feb 25, 2025 8:55 pm
Forum: General
Topic: Recursive routing not working while using wireguard interface as gateway [SOLVED]
Replies: 12
Views: 10997

Re: Recursive routing not working while using wireguard interface as gateway [SOLVED]

You should put the route with dst-address=8.8.4.4/32 in the main table. The "spain" table should only have one route with dst-address=0.0.0.0/0 gateway=8.8.4.4 check-gateway=ping. See this screenshot route-test-6.png from this post of mine yesterday https://forum.mikrotik.com/viewtopic.php...
by CGGXANNX
Tue Feb 25, 2025 7:55 pm
Forum: Beginner Basics
Topic: Finally made DUAL WAN work!
Replies: 61
Views: 10036

Re: Finally made DUAL WAN work!

The scripts worked well, but it was before I added recursive + PBR. Do you think that they can be modify for the new scenario? I have not taken a look at your whole configuration (@anav will probably do that and help you improve the config), only at the route table. With that I think your DHCP Clie...
by CGGXANNX
Tue Feb 25, 2025 6:40 pm
Forum: Beginner Basics
Topic: Finally made DUAL WAN work!
Replies: 61
Views: 10036

Re: Finally made DUAL WAN work!

Not sure how this line works exactly: /routing rule add action=lookup comment="ensure all local traffic is not captured by next rules" disabled=no min-prefix=0 table=main MikroTik was quite misleading when naming that parameter "min-prefix". The real thing under Linux is actuall...
by CGGXANNX
Tue Feb 25, 2025 1:09 pm
Forum: General
Topic: IPv6 addresses and equipment match
Replies: 3
Views: 3238

Re: IPv6 addresses and equipment match

The IPv6 Neighbors List now (in 7.18) has the Host name and Bridge port column (you can turn on the columns if they are not already visible).
by CGGXANNX
Tue Feb 25, 2025 10:47 am
Forum: Beginner Basics
Topic: Finally made DUAL WAN work!
Replies: 61
Views: 10036

Re: Finally made DUAL WAN work!

Looking at these diagrams (right "ROUTING" diagram as well as the chains below): https://help.mikrotik.com/docs/download/attachments/328227/PacketFlowDiagram_v6_b.svg?version=1&modificationDate=1570627617915&api=v2 https://help.mikrotik.com/docs/download/attachments/328227/Pfd.png?...
by CGGXANNX
Tue Feb 25, 2025 9:58 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 584
Views: 220579

Re: v7.18 [stable] is released!

My hAP ac² also went through the 7.18 betas, RCs, and final without issues. But it has no wifi packages installed and still has plenty of spaces.
by CGGXANNX
Tue Feb 25, 2025 9:53 am
Forum: Beginner Basics
Topic: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492
Replies: 107
Views: 16089

Re: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492

Yes, from the screenshots of the log, it looks like it happened like I described above. In the new log screenshots both ends of the tunnel now has agreed on MRU = 1492, after successful authentication your router send a test packet with 1484 bytes payload. Together with the LCP header and the Magic ...
by CGGXANNX
Tue Feb 25, 2025 9:37 am
Forum: General
Topic: IPv6 SLAAC bug or my misunderstanding of the concepts? [SOLVED]
Replies: 7
Views: 7745

Re: IPv6 SLAAC bug or my misunderstanding of the concepts? [SOLVED]

I am only guessing here, so probably others will have better explanations: Turning on IPv6 -> Settings -> IPv6 Forward makes the device become a router (can route packets). Turning it off makes the device only a normal host (a client) in the IPv6 network, maybe only to be used as a switch, NTP/DNS r...
by CGGXANNX
Tue Feb 25, 2025 5:45 am
Forum: Beginner Basics
Topic: Some of "Advanced Firewall Rules" cause problem in my local network [SOLVED]
Replies: 15
Views: 10346

Re: Some of "Advanced Firewall Rules" cause problem in my local network [SOLVED]

Same goes for ether1 the actual interface is either the pppoe one or the vlan one. That's not quite correct. Normally the ethernet interface (vlan or the port if no vlan is used) right underneath the PPPoE out connection still should be added to the WAN interface list, because usually over that por...
by CGGXANNX
Tue Feb 25, 2025 5:19 am
Forum: General
Topic: IPv6 SLAAC bug or my misunderstanding of the concepts? [SOLVED]
Replies: 7
Views: 7745

Re: IPv6 SLAAC bug or my misunderstanding of the concepts? [SOLVED]

Under Linux ip addr shows the valid & preferred lifetime left of the addresses, as well as the deprecated flag (if the address has been deprecated). The default lifetime setting values in RouterOS are set quite high (days and week). You can reduce those values if you usually do experiments on th...
by CGGXANNX
Tue Feb 25, 2025 4:34 am
Forum: General
Topic: IPv6 SLAAC bug or my misunderstanding of the concepts? [SOLVED]
Replies: 7
Views: 7745

Re: IPv6 SLAAC bug or my misunderstanding of the concepts? [SOLVED]

No, that's not what I normally experience. Please note that if you have very long lifetime values set under /ipv6 nd prefix default you'll need to unplug the network cable from the client devices/toggle their WiFi connection to see the SLAAC addresses of the device disappearing. Otherwise, the addre...
by CGGXANNX
Tue Feb 25, 2025 3:54 am
Forum: Beginner Basics
Topic: Finally made DUAL WAN work!
Replies: 61
Views: 10036

Re: Finally made DUAL WAN work!

I think check-gateway=ping is required in the two tables, otherwise the routes will still be marked as active (flag A) if the WAN are down. But we want to keep it compact, in the two special tables we only need one route each: add check-gateway=ping dst-address=0.0.0.0/0 gateway=8.8.8.8 routing-tabl...
by CGGXANNX
Mon Feb 24, 2025 9:48 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 584
Views: 220579

Re: v7.18 [stable] is released!

There was a bug in 7.17 where even with device-mode locking down RouterBOARD, people were able to change the CPU frequency once . I disagree, this bug was fixed in 7.17.2. It has been like that since forever. The changelog of the stable c.d release contains changes since the previous a.b release. V...
by CGGXANNX
Mon Feb 24, 2025 9:00 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 584
Views: 220579

Re: v7.18 [stable] is released!

With 16Mb flash device you can only watch new release notes and cry :) Free space after 7.16.2 netinstall with imported config (not backup): free-hdd-space: 396.0KiB ... Looks like Mikrotik doesn't test their releases on 16MB devices at all. My hAP AC2 has 0MB free after update to ROS 7.18 and now ...
by CGGXANNX
Mon Feb 24, 2025 8:52 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 584
Views: 220579

Re: v7.18 [stable] is released!

There was a bug in 7.17 where even with device-mode locking down RouterBOARD, people were able to change the CPU frequency once.
by CGGXANNX
Mon Feb 24, 2025 8:13 pm
Forum: Beginner Basics
Topic: Finally made DUAL WAN work!
Replies: 61
Views: 10036

Re: Finally made DUAL WAN work!

PBR is Policy-Based Routing and routing rules are also one of the different ways to implement PBR. Quoted from: https://help.mikrotik.com/docs/spaces/ROS/pages/59965508/Policy+Routing RouterOS implements several components that can be used to achieve said task: routing tables routing rules firewall ...
by CGGXANNX
Mon Feb 24, 2025 12:15 pm
Forum: Beginner Basics
Topic: Finally made DUAL WAN work!
Replies: 61
Views: 10036

Re: Finally made DUAL WAN work!

Oh I understand where you are coming from, just think its unnecessary, but will have to ascertain the logic/mechanism. I've setup some tests. 10.12.1.10 is a pingable host (WAN IP address of OpenWrt) on one of my VLAN, but obviously won't forward traffic, I'll use it as ISP-Gateway-IP . Now let's a...
by CGGXANNX
Mon Feb 24, 2025 10:48 am
Forum: Beginner Basics
Topic: Finally made DUAL WAN work!
Replies: 61
Views: 10036

Re: Finally made DUAL WAN work!

I have a question about ECMP, I've read that I might have a problem in using that approach for load balancing due to packets might use both ISP while having same source? Like in gaming or banking online. I'll try on reading about PCC when I have time. For both ECMP and PCC, all packets of the same ...
by CGGXANNX
Sun Feb 23, 2025 11:39 pm
Forum: Beginner Basics
Topic: Finally made DUAL WAN work!
Replies: 61
Views: 10036

Re: Finally made DUAL WAN work!

Let's say the router is connected to the LAN ports of two modem routers of two ISP. Which means the two WAN ethernet ports of the router are part of the two LANs of the ISP modems. Which means ISP1-gateway-IP and ISP2-gateway-IP are just some private addresses like 192.168.10.1 and 192.168.20.1. Bot...
by CGGXANNX
Sun Feb 23, 2025 11:06 pm
Forum: Beginner Basics
Topic: Finally made DUAL WAN work!
Replies: 61
Views: 10036

Re: Finally made DUAL WAN work!

But to check if the route is available or not it needs to ping 8.8.8.8 or 1.1.1.1. Only with something like pppoe-out1 you can rely on the interface name alone to see if the route is available. The interface can be up, but no addresses is pingable. So with add dst-address=0.0.0.0/0 gateway=ISP1-gate...
by CGGXANNX
Sun Feb 23, 2025 11:00 pm
Forum: Beginner Basics
Topic: Finally made DUAL WAN work!
Replies: 61
Views: 10036

Re: Finally made DUAL WAN work!

add dst-address=0.0.0.0/0 gateway =ISP1 -gateway-IP routing-table= useWAN1 add dst-address=0.0.0.0/0 gateway= ISP2 -gateway-IP routing-table= useWAN2 For these two you can reuse the two lines from the main table (with gateway 8.8.8.8 and 1.1.1.1 respectively, only routing table is changed) and it'l...
by CGGXANNX
Sun Feb 23, 2025 10:54 pm
Forum: Beginner Basics
Topic: Finally made DUAL WAN work!
Replies: 61
Views: 10036

Re: Finally made DUAL WAN work!

Do I need to set mangle rules, or will a small change to your setup above can do the trick? You don't need mangle rules. This only requires routing rules and is compatible with fasttrack: * Create two routing tables WAN1 and WAN2, each containing a default route using the corresponding gateway (in ...
by CGGXANNX
Sun Feb 23, 2025 6:52 pm
Forum: Beginner Basics
Topic: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492
Replies: 107
Views: 16089

Re: PPPOE MTU ALWAYS DEFAULTS TO 1480 INSTEAD OF 1492

Can you look further down in the log, after the authentication has been performed? There should be a relevant section where your router sent LCP EchoReq messages with <data len=xxxx> . Are there any rcvd LCP EchoRep lines after that? Looking at your screenshots it looks like the server side does sup...
by CGGXANNX
Sat Feb 22, 2025 12:54 am
Forum: General
Topic: PPPoE Server rejects MTU of 1540
Replies: 7
Views: 4306

Re: PPPoE Server rejects MTU of 1540

L2MTU should be raised as high as possible on every device in the network. They do not need to match, but there is zero justifiable reason NOT set it as high as it'll go There are reasons why it's not set arbitrarily high, and MikroTik even explained it here: https://www.youtube.com/watch?v=7a_z1jA...
by CGGXANNX
Fri Feb 21, 2025 2:02 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 33070

Re: v7.18rc [testing] is released!

That's why I wrote "should have already started". If they already started last year, then 6.6 would have been the right candidate (because 6.12 only came at the end of the year).
by CGGXANNX
Fri Feb 21, 2025 1:35 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 33070

Re: v7.18rc [testing] is released!

MikroTik should have already started migrating to 6.6.x, which is LTS and has all the storage improvements. The current OpenWrt is also on this branch. I think MikroTik currently use 5.6.3 because 5.6 is the first release that has WireGuard support in the kernel. Otherwise, they would have used an e...
by CGGXANNX
Fri Feb 21, 2025 12:31 pm
Forum: General
Topic: PPPoE Server rejects MTU of 1540
Replies: 7
Views: 4306

Re: PPPoE Server rejects MTU of 1540

Usually that's because RouterOS could not send a test LCP EchoReq message as large as the specified MTU after establishing the PPPoE connection, which causes it to drop MTU to 1480. And probably the message could not be sent because the produced ethernet frame is too large for the underlying layer 2...
by CGGXANNX
Thu Feb 20, 2025 10:01 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 33070

Re: v7.18rc [testing] is released!

I know, @pe1chl, but, mikrotik has special clamping feature that works without firewall mangle rule and with fasttrack/fastpath afaik. Thanks for your response anyway, i respect any opinion as we all are humans. Without respecting others we can not be respected That "Change TCP MSS" featu...
by CGGXANNX
Thu Feb 20, 2025 7:24 am
Forum: Beginner Basics
Topic: Anyone uses AI for their config?
Replies: 32
Views: 5974

Re: Anyone uses AI for their config?

No, the VLAN part is not good. Because the config uses Bridge VLAN Filtering and you have a hAP ac². The hAP ac² has hardware offload support for VLAN but not if you use Bridge VLAN Filtering. For this router you need to configure VLAN the old way, using the /interface ethernet switch menu. Follow t...
by CGGXANNX
Thu Feb 20, 2025 7:14 am
Forum: General
Topic: IPv6 on WAN interface
Replies: 8
Views: 3329

Re: IPv6 on WAN interface

The IPv6 address currently assigned to your router on the main LAN bridge can be used for this purpose. There is no need to add new interfaces and assign more addresses or to assign an address to the WAN interface from the pool. If you have multiple LAN interfaces, any of their currently assigned GU...
by CGGXANNX
Thu Feb 20, 2025 1:13 am
Forum: General
Topic: RouterOS 7.17+ IPv6 issue [SOLVED]
Replies: 7
Views: 6958

Re: RouterOS 7.17+ IPv6 issue [SOLVED]

Did you try turning off "add-default-route" on the /ipv6 dhcp-client entry? People on this forum have repeatedly said that that setting is a MikroTik's hack and should not be enabled (except for very rare cases). You already have accept-router-advertisements=yes under /ipv6 settings and sh...
by CGGXANNX
Thu Feb 20, 2025 12:37 am
Forum: General
Topic: adlist and dns server
Replies: 1
Views: 2708

Re: adlist and dns server

I've asked for HTTPS RR support (at that time adlist didn't exist yet, support was for caching and editing of static entries) on January 2024 and at that time this was MikroTik's answer to the support ticket: Hello, Thank you for contacting MikroTik Support. Your feature request has been noted! If t...
by CGGXANNX
Wed Feb 19, 2025 11:34 pm
Forum: General
Topic: Is package "wireless" needed on routers without any wireless interface ? [SOLVED]
Replies: 2
Views: 5543

Re: Is package "wireless" needed on routers without any wireless interface ? [SOLVED]

You don't need it for your RB5009. I have removed it from my RB5009 since 7.13 was first released. Removing it will remove the Wireless menu entry in WinBox but the WiFi entry stays. None of my routers have that package installed. The wireless package contains the wifi drivers for older chipsets (wh...
by CGGXANNX
Wed Feb 19, 2025 11:22 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 33070

Re: v7.18rc [testing] is released!

So not quite sure here whether it is, or isn't hardware offloaded :-) Those two are not the same thing. "Hardware Offload" is a setting that you can turn on or off to tell RouterOS whether you want hardware offloading to be enabled if possible . And Hw. Offload is the actual status whethe...
by CGGXANNX
Wed Feb 19, 2025 10:59 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 2207
Views: 3761869

Re: 📣 WinBox 4 is here 📣

Please keep developing native desktop apps. Even with the issues that I have had with WinBox 4 until now (many of which have been addressed), the experience was always miles better than any web-based apps. WinBox 4 was laggy (on Windows) at the beginning but still lags much less than WebFig. Try to ...
by CGGXANNX
Wed Feb 19, 2025 3:02 pm
Forum: The User Manager
Topic: User manager as radius to use on other access point
Replies: 10
Views: 6476

Re: User manager as radius to use on other access point

All the relevant ports 1812, 1813, 3799 are UDP (and not required to be listed under IP services), not TCP. Which means you cannot test with telnet. It's better for debugging to use packet sniffer like I posted above. To temporarily bypass possible blocking rules in your firewall configuration, you ...
by CGGXANNX
Wed Feb 19, 2025 11:47 am
Forum: The User Manager
Topic: User manager as radius to use on other access point
Replies: 10
Views: 6476

Re: User manager as radius to use on other access point

If no packet appears in the packet sniffer, and no log is being written in RouterOS then it might still be because it was blocked by the firewall. The default firewall config allows ICMP from everywhere, so ping still works if the router blocks everything else. If it's not the firewall, then maybe i...
by CGGXANNX
Wed Feb 19, 2025 11:02 am
Forum: General
Topic: Problems uploading files
Replies: 7
Views: 3376

Re: Problems uploading files

Ah I just saw that the flash directory is missing. Normally on devices with just 16MiB storage like this one, the internal storage is mounted under flash, and everything outside that folder is a RAM disk. Which means upgrade packages and everything you upload outside of flash should be on that RAM d...
by CGGXANNX
Wed Feb 19, 2025 10:47 am
Forum: General
Topic: Is PPPoE still slow?
Replies: 10
Views: 3311

Re: Is PPPoE still slow?

Your ax³ should have 4× the performance of the hEX RB750Gr3 (according to MikroTik's figures). When you did your test with iperf3, did you use the -P parameter, for example specifying -P 4? Because even without using PPPoE, packets of a single connection are only processed by a single core in Router...
by CGGXANNX
Wed Feb 19, 2025 9:09 am
Forum: General
Topic: Is PPPoE still slow?
Replies: 10
Views: 3311

Re: Is PPPoE still slow?

PPPoE on RouterOS uses single core (per PPPoE connection) but for your use case (PPPoE to ISP as WAN line) the performance overhead is negligible. The single thread processing only applies to the encapsulation/decapsulation of the PPPoE header, the rest like routing, NAT, firewall, etc,... are still...
by CGGXANNX
Wed Feb 19, 2025 8:20 am
Forum: General
Topic: Problems uploading files
Replies: 7
Views: 3376

Re: Problems uploading files

Check under System -> Users whether any account unknown to you are listed. Also check the Groups table to see if there is any group other than the three full / read / write. If the answer is positive, then your router might have been hacked. One of the common hacks add a new user group with full rig...