Community discussions

Search found 65 matches

  • 1
  • 2
by carl0s
Fri Jul 12, 2019 12:55 am
Forum: General
Topic: bridge tx/rx numbers double WiFi numbers
Replies: 1
Views: 206

Re: bridge tx/rx numbers double WiFi numbers

anyone?
by carl0s
Wed Jul 10, 2019 7:17 pm
Forum: General
Topic: bridge tx/rx numbers double WiFi numbers
Replies: 1
Views: 206

bridge tx/rx numbers double WiFi numbers

Hi. Using Capsman. I've noticed this before, but just wanted to ask.. when the internet is being used, and the Tx for the WiFi (virtual i/f from capsman v2) is showing 10Mbps to a laptop, and the PPPoE Internet on eth1-gateway is Rx for the same connection @10Mbps, then why does the bridge, which co...
by carl0s
Wed Apr 03, 2019 4:50 pm
Forum: General
Topic: email FROM:<> always blank
Replies: 1
Views: 156

Re: email FROM:<> always blank

I'm sorry, I just noticed in the release notes for 6.44.1 there is a fix!
by carl0s
Wed Apr 03, 2019 4:49 pm
Forum: General
Topic: email FROM:<> always blank
Replies: 1
Views: 156

email FROM:<> always blank

Hi. I have set up email with a FROM: inside winbox. I have tried both an email address, and <an email address>, and have enabled debugging. I have set it to alert me of Account actions, so that I get a notification if somebody logs in. This seems like a good idea! but always, routeros is sending MAI...
by carl0s
Thu Jan 03, 2019 6:51 pm
Forum: General
Topic: IP CLOUD is down
Replies: 61
Views: 10017

Re: IP CLOUD is down

Does this have anything to do with the weird DNS problem I had on a wapAC during this period? It would not resolve a .net domain name, but would resolve a .co.uk that is on the same public DNS servers (ns.123-reg.co.uk) I had to put a static entry into the DNS on the routerboard, because the hostnam...
by carl0s
Sat Sep 22, 2018 2:42 am
Forum: General
Topic: restore back to identical devices never works :(
Replies: 28
Views: 1628

Re: restore back to identical devices never works :(

Like I said, did anyone reported these problems to support? Only now, with this thread to you. Hopefully you can put it on the agenda 😊 Write to support, specify what configuration you had on the router when you created backup (preferably generate supout file) then restore backup and generate anoth...
by carl0s
Sat Sep 22, 2018 2:38 am
Forum: General
Topic: restore back to identical devices never works :(
Replies: 28
Views: 1628

Re: restore back to identical devices never works :(

Regardless of whatever the official stance is from Mikrotik, some sort of useful backup/restore which doesn't require a plain-text config export, and/or have vital pieces missing, would be a very useful feature to help in disaster recovery. Instead, it seems like the best option is to keep a pre-con...
by carl0s
Sat Sep 22, 2018 2:22 am
Forum: General
Topic: DNS forward based on domain name
Replies: 18
Views: 3859

Re: DNS forward based on domain name

No? Still No, Mikrotik??

FFS it would be able 3 lines of code for your developers :(
by carl0s
Thu Sep 20, 2018 2:18 am
Forum: General
Topic: restore back to identical devices never works :(
Replies: 28
Views: 1628

Re: restore back to identical devices never works :(

Like I said, did anyone reported these problems to support?
Only now, with this thread to you. Hopefully you can put it on the agenda 😊
by carl0s
Thu Sep 20, 2018 2:16 am
Forum: General
Topic: RouterOS making unaccounted outbound winbox connections [SOLVED]
Replies: 64
Views: 28741

Re: RouterOS making unaccounted outbound winbox connections [SOLVED]

Another important check is:

check if you have static entrien on IP/DNS/Static

i found DNS A Record and CNAME to fake mikrotik download site

maybe for download an altered version of routeros
That's a really interesting one. I hadn't thought to check that!
by carl0s
Wed Sep 19, 2018 12:11 am
Forum: General
Topic: RouterOS making unaccounted outbound winbox connections [SOLVED]
Replies: 64
Views: 28741

Re: RouterOS making unaccounted outbound winbox connections [SOLVED]

Just check in System -> Schedule. There will be a schedule to run a script every minute that continues to allow the hackers in. Remove the script from System -> scripts too. SOCKS proxy has probably been enabled. turn that off. check there are no new users added under System -> users change the pass...
by carl0s
Tue Sep 18, 2018 11:59 pm
Forum: General
Topic: restore back to identical devices never works :(
Replies: 28
Views: 1628

Re: restore back to identical devices never works :(

Define "same type of device"? Backup was never intended to work between different HW models. You can restore backup reliably only on exactly the same HW model. I've used the word 'identical' a few times here. I even ensured the routerOS was the same version too. Identical model hardware - from the ...
by carl0s
Tue Sep 18, 2018 11:56 pm
Forum: General
Topic: restore back to identical devices never works :(
Replies: 28
Views: 1628

Re: restore back to identical devices never works :(

But when old HW is broken, fired or drowned in water problem is more complicated. Exactly. I starting taking backups of my customer's Mikrotik boxes some time ago. I was also hit with the RB450G capacitor failures ~5 or 7 years ago.. but.. these backups are basically useless aren't they. If the res...
by carl0s
Tue Sep 18, 2018 2:21 pm
Forum: General
Topic: restore back to identical devices never works :(
Replies: 28
Views: 1628

Re: restore back to identical devices never works :(

Define "same type of device"? Backup was never intended to work between different HW models. You can restore backup reliably only on exactly the same HW model. wAPac to wAPac. They look the same to me but who knows what goes on inside! I guess the backup has the interface configs tied to mac addres...
by carl0s
Tue Sep 18, 2018 1:12 pm
Forum: General
Topic: restore back to identical devices never works :(
Replies: 28
Views: 1628

Re: restore back to identical devices never works :(

this is turning into a really bad day for me now :( I restore the config - from same type of device running same firmware. It has hotspot enabled. when the new device boots, wlan is down, and ethernet I guess is blocking everything. I know it has an IP from my other router, but I can't get into it. ...
by carl0s
Tue Sep 18, 2018 12:52 pm
Forum: General
Topic: restore back to identical devices never works :(
Replies: 28
Views: 1628

restore back to identical devices never works :(

I have lots of hotspots to set up on wAPac Why does backup/restore never work :( They are both on the same version, I have even put an 'accept all' at the top of the configuration before doing the backup. I guess it's because interfaces don't match up, but that's really bad :( last time I had to do ...
by carl0s
Sat Jul 28, 2018 2:28 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: New IP cloud is coming.
Replies: 83
Views: 25319

Re: New IP cloud is coming.

Actually this would put the mikrotik in the middleman role. It has to be considered as unsafe. I understand that some people do not care about it, but I rather build my own management network instead of rely on services that I cannot control and that can do whatever I do not know what above what th...
by carl0s
Tue Jan 23, 2018 10:25 pm
Forum: General
Topic: DNS forward based on domain name
Replies: 18
Views: 3859

Re: DNS forward based on domain name

Received the EdgeRouter ER-X today. It's a tidy little box :-) the O/S looks nice. Quite a lot less power than Mikrotik / Winbox. However, there's the added flexibility of a full Linux bash shell! I have resisted 'the other side' even though everywhere I see a point-to-point wan (wireless ISP in the...
by carl0s
Mon Jan 22, 2018 7:20 pm
Forum: Wireless Networking
Topic: Xiaomi phone low Wifi TX rate [SOLVED]
Replies: 112
Views: 25836

Re: Xiaomi phone low Wifi TX rate [SOLVED]

Yes, some low end chinese phones have such issues. I suggest for now to use better phones, since we can't solve this issue quickly. These phones are known to have issues. We have checked this issue, and there is incompatibility with these chips and the RouterOS driver. We can't easily solve it, it ...
by carl0s
Mon Jan 22, 2018 2:34 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: CAPsMAN 6.41rc
Replies: 9
Views: 1485

Re: CAPsMAN 6.41rc

I have had this problem a lot too. It seems like the communication doesn't happen. Never used to happen, but happened to me frequently in the past year when setting them up. You can see "Managed by capsman", but you will see no channel selected or any configuration settings retrieved. I think I reso...
by carl0s
Mon Jan 22, 2018 2:26 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Any plans for SD WAN?
Replies: 17
Views: 7081

Re: Any plans for SD WAN?

Really? Isn't it just a fancy sounding putting of cloud word everywhere? Nothing against, just asking what is it above a vpn? Yeah I don't get this either. SDR I get - software defined radio. And it makes sense too. Very powerful and useful. Sofware Defined WAN ? Well of course, it's always softwar...
by carl0s
Sun Jan 21, 2018 9:29 pm
Forum: General
Topic: DNS forward based on domain name
Replies: 18
Views: 3859

Re: DNS forward based on domain name

I have an ER-X. The GUI is definitely more "whiz bangy" and you use the web gui (or cli of course), not something like Winbox. MikroTik seems to do a lot more for your money software wise, but hey, if it doesn't support something that this one does, get it. It's a nice little machine. It's a lot of...
by carl0s
Sun Jan 21, 2018 5:53 pm
Forum: Wireless Networking
Topic: wapAc 802.11ac tx rate won't go above 54mbps
Replies: 3
Views: 617

Re: wapAc 802.11ac tx rate won't go above 54mbps

The above is an Intel 8260 card in my Thinkpad x1. My phone (Lg G5) was Ok. I altered some driver settings on my laptop (enabled U-APSD support, and enabled Throughput Booster, which were both disabled before), and now everything is back to normal. The thing is though, i'm not sure if they have real...
by carl0s
Sun Jan 21, 2018 5:40 pm
Forum: Wireless Networking
Topic: wapAc 802.11ac tx rate won't go above 54mbps
Replies: 3
Views: 617

wapAc 802.11ac tx rate won't go above 54mbps

Any ideas what's going on here? When I did my surveying and testing yesterday everything was great. Now today, no matter what I do, selecting channels, bandwidths manually (including superchannel for testing), I can not get tx rate above 54mbps. So my maximum bandwidth from internet is ~24mbps :( tx...
by carl0s
Sun Jan 21, 2018 1:53 pm
Forum: General
Topic: DNS forward based on domain name
Replies: 18
Views: 3859

Re: DNS forward based on domain name

It does do hw crypto offload for ~400mbps IPsec, and DNS conditional forwarders. That's all I need. They do udo openvpn but it's slow (25mbps) and I've never actually used openvpn anyway so that's not of interest to me. I just need IPsec and conditional DNS forwarder for the remote active-directory ...
by carl0s
Sun Jan 21, 2018 12:57 pm
Forum: General
Topic: DNS forward based on domain name
Replies: 18
Views: 3859

Re: DNS forward based on domain name

It looks like this will do what I need (with a simple dnsmasq cli option). I think it'll do openvpn UDP if you want too. It looks like an rb750gr3 with a different operating system. That hardware has AES acceleration. Not sure if this non-mikrotik o/s supports it yet though. https://www.eurodk.com/e...
by carl0s
Sat Jan 20, 2018 11:21 pm
Forum: General
Topic: DNS forward based on domain name
Replies: 18
Views: 3859

Re: DNS forward based on domain name

You probably know this thread . With its 10th anniversary drawing near, it would be nice present from MikroTik, if they finally implemented it. Otherwise I'll probably start losing hope. And no, you can't make your own packages. There are some tools to unpack .npk files, but not to create them. The...
by carl0s
Sat Jan 20, 2018 7:28 pm
Forum: General
Topic: DNS forward based on domain name
Replies: 18
Views: 3859

Re: DNS forward based on domain name

Mikrotik: can I build my own package and install that on RouterOS? I need conditional DNS forwarders.
by carl0s
Thu Dec 14, 2017 4:00 pm
Forum: General
Topic: IPSEC tunnel routing issue - help needed
Replies: 9
Views: 841

Re: IPSEC tunnel routing issue - help needed

You also need to exclude the IPSec subnets from the masquerade natting rule. there's a few articles about that. in my instance here, I have just set !192.168.88.0.24 in the destination address of my standard internet-masquerade src-nat rule. The preferred way though is to add an entry into the Firew...
by carl0s
Thu Dec 14, 2017 3:27 pm
Forum: General
Topic: IPSEC tunnel routing issue - help needed
Replies: 9
Views: 841

Re: IPSEC tunnel routing issue - help needed

Thank you carl0s, I see, so I don't have to worry if I don't see a route to that network in the routing table. I have one more thing that I can try to fix the issue. At the moments my ping to the dst-net time out. If you are pinging from the Mikrotik itself, make sure you set src-address so that it...
by carl0s
Thu Dec 14, 2017 2:47 pm
Forum: General
Topic: IPSEC tunnel routing issue - help needed
Replies: 9
Views: 841

Re: IPSEC tunnel routing issue - help needed

With the Mikrotik, IPSec does not create a virtual interface (many people requested it, but have to use IP in IP, L2TP, PPTP, etc instead), and you don't need to add any routes.

The packets head for the default route, but the IPSec policy matches the source/dst subnets, and does what it needs to do.
by carl0s
Thu Dec 14, 2017 2:37 pm
Forum: General
Topic: DNS forward based on domain name
Replies: 18
Views: 3859

DNS forward based on domain name

I'm completely bemused why there's no support (after many requests) for this: You enter a domain name in the DNS configuration, and then enter the ip address(es) of DNS servers to forward the requests for that domain to. The Mikrotik can cache it. What's the problem? Surely this could be coded in an...
by carl0s
Tue Dec 12, 2017 7:50 pm
Forum: General
Topic: VPN with high latency (220ms RTT)
Replies: 2
Views: 385

Re: VPN with high latency (220ms RTT)

I am experimenting with throttling the UK side, where we have 100mbps Internet and where the SMB server is located. I am trying to throttle it back to the ~5mbps that the far end can usually receive. i.e. packet pacing. What I am seeing is that Server 2016 is barely unusable, Server 2008 is OK but s...
by carl0s
Tue Dec 12, 2017 2:09 am
Forum: General
Topic: VPN with high latency (220ms RTT)
Replies: 2
Views: 385

VPN with high latency (220ms RTT)

Hi. We have 220ms R.T.T. between Malaysia and England. Any tips for VPN passing SMB? We're using pure IPSec (no l2tp or other tunnel). It's working, but on SMB in particular, it seems to transfer, then stall, then pick up again, then stall. Never getting more than ~3mbps out of a 10mbps line (in Mal...
by carl0s
Mon Dec 11, 2017 2:30 pm
Forum: General
Topic: IPSec failing when upstream ISP router has same private network 192.168.1.0/24
Replies: 7
Views: 448

Re: IPSec failing when upstream ISP router has same private network 192.168.1.0/24

actually, now it is all working..

but I don't think I have changed anything :(
by carl0s
Mon Dec 11, 2017 2:27 pm
Forum: General
Topic: IPSec failing when upstream ISP router has same private network 192.168.1.0/24
Replies: 7
Views: 448

Re: IPSec failing when upstream ISP router has same private network 192.168.1.0/24

weird.. yes it works from the Mikrotik itself! [admin@MikroTik] > /tool traceroute 192.168.1.1 src-address=192.168 # ADDRESS LOSS SENT LAST AVG BE 1 100% 10 timeout 2 192.168.1.1 0% 9 255.4ms 244.4 215
by carl0s
Mon Dec 11, 2017 2:15 pm
Forum: General
Topic: IPSec failing when upstream ISP router has same private network 192.168.1.0/24
Replies: 7
Views: 448

Re: IPSec failing when upstream ISP router has same private network 192.168.1.0/24

If you run traceroute from router itself, make sure you specify correct source-address. Otherwise in most cases trace is not matched by policy and sent via WAN interface with public src-address Thank you yes I was just going to say, the policy will only match LAN. It's strange that this has been wo...
by carl0s
Mon Dec 11, 2017 1:47 pm
Forum: General
Topic: IPSec failing when upstream ISP router has same private network 192.168.1.0/24
Replies: 7
Views: 448

Re: IPSec failing when upstream ISP router has same private network 192.168.1.0/24

Thanks I will look further. The trace route is from the Mikrotik itself though. Does this make a difference?
by carl0s
Mon Dec 11, 2017 1:37 pm
Forum: General
Topic: IPSec failing when upstream ISP router has same private network 192.168.1.0/24
Replies: 7
Views: 448

Re: IPSec failing when upstream ISP router has same private network 192.168.1.0/24

For additional clarification.. We have: Malaysia: [LAN] 192.168.88.0/24 Malaysia [WAN] 1.2.3.4/29, gateway 1.2.3.1 (provided by building manager) UK [LAN] 192.168.1.0/24 UK [WAN] x.x.x.x.x (our own subnet) if I try to ping 192.168.1.x from the Malaysia LAN, nothing works.. does not go through. Mikro...
by carl0s
Mon Dec 11, 2017 1:13 pm
Forum: General
Topic: IPSec failing when upstream ISP router has same private network 192.168.1.0/24
Replies: 7
Views: 448

IPSec failing when upstream ISP router has same private network 192.168.1.0/24

Hi. Strange one. i sent a Hexgr3 over to Malaysia and we have a nicely working IKEv2 IPSec vpn between there and here in the UK. Over the weekend, it looks like the Internet provider (actually the business centre) in Malaysia, has added a class-C 192.168.1.0/24 network onto the upstream router that ...
by carl0s
Mon Sep 04, 2017 6:53 pm
Forum: General
Topic: fasttrack and hotspot problem
Replies: 1
Views: 634

Re: fasttrack and hotspot problem

I think I see the same problem...

I thought it was a bridge problem, but disabling that fasttrack rule makes it start working again.

I've been here ages.. arrgh.
by carl0s
Wed Jun 21, 2017 11:49 am
Forum: RouterBOARD hardware
Topic: SSTP hardware acceleration?
Replies: 10
Views: 1902

Re: SSTP hardware acceleration?

from 6.39 changelog: *) ipsec - enable aes-ni on i386 and x64 for cbc, ctr and gcm modes; So yes, CHR will have increased AES performance if v6.39 is installed, but this only works with IPSec, not SSTP. It would be super cool if you guys would work on rebuilding the SSTP stuff to use the hardware c...
by carl0s
Tue May 23, 2017 1:49 pm
Forum: RouterBOARD hardware
Topic: Omnitik 5 AC. Concurrent 2.4 & 5GHz ?
Replies: 1
Views: 698

Omnitik 5 AC. Concurrent 2.4 & 5GHz ?

Hi. I know the Omnitik 5 (poe) AC has only a single radio - QCA9892 I read somewhere that this chip can do simultaneous 5GHz and 2.4GHz. Is this supported in the Omnitik 5 AC ? I am looking for a good AP for the middle of a building. This looks to have better antenna gain than the hAP AC, and same s...
by carl0s
Tue May 23, 2017 1:41 pm
Forum: RouterBOARD hardware
Topic: SSTP hardware acceleration?
Replies: 10
Views: 1902

Re: SSTP hardware acceleration?

Yes I did wonder the same. The hardware does encryption and usually with VPN types you can specify the encryption type, so long as we find one that is common between SSTP and what the hardware offers.. Anyway, yes, the Future... lots of things take a long time around here don't they :-) It's just th...
by carl0s
Fri May 05, 2017 11:32 pm
Forum: RouterBOARD hardware
Topic: SSTP hardware acceleration?
Replies: 10
Views: 1902

SSTP hardware acceleration?

Hi. The new affordable routers with 'IPSec hardware encryption acceleration' (RB750Gr3).

.. can the hardware acceleration work for SSTP as well? or only IPSec?
by carl0s
Fri Dec 02, 2016 10:32 pm
Forum: RouterBOARD hardware
Topic: hAP AC 20MHz 802.11n bad
Replies: 4
Views: 1024

Re: hAP AC 20MHz 802.11n bad

What does 'distance' actually change anyway?
ACK
Thanks.
by carl0s
Fri Nov 25, 2016 12:54 am
Forum: RouterBOARD hardware
Topic: hAP AC 20MHz 802.11n bad
Replies: 4
Views: 1024

Re: hAP AC 20MHz 802.11n bad

Oh look, the 5GHz has almost the same weird setting! it says 255Km!!

I think the firmware upgrade has done this ?

What does 'distance' actually change anyway?
Screenshot from 2016-11-24 22-52-48.png
by carl0s
Fri Nov 25, 2016 12:50 am
Forum: RouterBOARD hardware
Topic: hAP AC 20MHz 802.11n bad
Replies: 4
Views: 1024

Re: hAP AC 20MHz 802.11n bad

OK I found the problem, but I don't know how it happened.

'distance' was set to 250Km.

I changed it to indoors, and all is well.

Any idea how this would change? chrome auto-fill cockup while using webmin? a bug during upgrade to -rc ?
by carl0s
Fri Nov 25, 2016 12:35 am
Forum: RouterBOARD hardware
Topic: hAP AC 20MHz 802.11n bad
Replies: 4
Views: 1024

hAP AC 20MHz 802.11n bad

Hi. I seem to be having terrible trouble with 20MHz 802.11 "only N" from my hAP AC. It's like there is extreme interference, but I am using a HackRF to look at the spectrum, and I don't think there is any interference, although I am quite new to it so some of the peaks I am seeing may indeed be inte...
by carl0s
Wed Feb 24, 2016 12:17 am
Forum: RouterBOARD hardware
Topic: map2n not very good wifi
Replies: 9
Views: 2233

Re: map2n not very good wifi

I have tried mAP2n-lite now as well. This is dual-chain or whatever (300mbps on 802.11n).
It also finally supports proper PoE.
It's also tiny.

I have some issues with compatibility but I think I need to experiement with channel setup. I'm using CAPsMANv2.
  • 1
  • 2