Community discussions

MikroTik App

Search found 1857 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 7
by sebastia
Wed Jun 11, 2025 8:40 pm
Forum: General
Topic: double-hop Wireguard
Replies: 13
Views: 957

Re: double-hop Wireguard

have you tried defining default gateway within wg for u1 & u2, as respectively c1 & c2?

hence routes that get pushed to the wg peers:
https://help.mikrotik.com/docs/spaces/R ... uard-Peers
by sebastia
Mon Jun 09, 2025 7:39 pm
Forum: Beginner Basics
Topic: How connect to a Bridgged modem with a Hex ?
Replies: 4
Views: 949

Re: How connect to a Bridgged modem with a Hex ?

Have you tried their help ? https://support.mobilevikings.be/hc/en-us/articles/15963730456081-How-can-I-configure-my-modem-in-bridge-mode Clearly stated: ppp needed (for bbox3) you should probably copy your current ppp config before switching might also be relevant: https://support.mobilevikings.be/...
by sebastia
Mon Jun 09, 2025 12:25 am
Forum: Beginner Basics
Topic: Fasttrack breaks streaming service
Replies: 16
Views: 1801

Re: Fasttrack breaks streaming service

Hi

As you probably already noticed in some of the post, it's all about the configuration of the hardware.

Hence if you want some help, also post your current config + some hints on what is what.

/export minus passes / sensitive stuff
by sebastia
Sat Jun 07, 2025 5:14 pm
Forum: General
Topic: Outgoing unsolicited traffic to 5351/udp
Replies: 1
Views: 764

Re: Outgoing unsolicited traffic to 5351/udp

FYI: looks like related to zerotier node
by sebastia
Sat Jun 07, 2025 4:34 pm
Forum: General
Topic: Outgoing unsolicited traffic to 5351/udp
Replies: 1
Views: 764

Outgoing unsolicited traffic to 5351/udp

Hi Noticed this in firewall logs: 2025-06-07T14:57:31.237416+02:00 firewall.home firewall,info fw2ext: in:(unknown 0) out:e1_ext, connection-mark:FT connection-state:new proto UDP, <pub_ip>:34829-><pub_gw>:5351, len 30 2025-06-07T14:57:31.487536+02:00 firewall.home firewall,info fw2ext: in:(unknown ...
by sebastia
Thu Jun 05, 2025 11:49 pm
Forum: Beginner Basics
Topic: Force traffic from main site to other remote sites
Replies: 10
Views: 4333

Re: Force traffic from main site to other remote sites

Have you looked at the article...? I have a main site and two other remote sites. The remote sites are connect with GRE over IPSec to the main site and everyone can talk to each other. In the main site I have two VMs and I want one of the VMs traffic to go trough the tunnel and get on the internet u...
by sebastia
Thu Jun 05, 2025 11:34 pm
Forum: General
Topic: ROMON in 7.19.1
Replies: 20
Views: 2440

Re: ROMON in 7.19.1

Not yet on .1. FYI, on 7.19 still works for me, even cross version, to v6.
by sebastia
Thu Jun 05, 2025 11:23 pm
Forum: Beginner Basics
Topic: internet LTE backup
Replies: 3
Views: 1025

Re: internet LTE backup

Hey Option two is definitely an option. I'm doing it myself... Not that hard either: * configure vlan on LTE kit * configure LTE with passthrough #for v6: /interface vlan add interface=ether1 name=vXXX vlan-id=XXX /interface lte apn set [ find default=yes ] apn=<apn> authentication=pap passthrough-i...
by sebastia
Wed Jun 04, 2025 7:22 pm
Forum: General
Topic: Routing + transparent Vlan
Replies: 8
Views: 1279

Re: Routing + transparent Vlan

A picture is worth a thousand words...
by sebastia
Sun Jun 01, 2025 10:24 pm
Forum: Beginner Basics
Topic: Hex E50UG
Replies: 103
Views: 9278

Re: Hex E50UG

Moral of the story "Don't buy brand new hw"? This is the least intelligent thing that has been posted in this thread. Give me a break. Well thank you It is "funny" and playful, in this all but optimal customer experience. But one does need some intelligence to see that ... oh we...
by sebastia
Sat May 31, 2025 7:54 pm
Forum: Beginner Basics
Topic: Hex E50UG
Replies: 103
Views: 9278

Re: Hex E50UG

Moral of the story "Don't buy brand new hw"?
by sebastia
Sat May 31, 2025 7:30 pm
Forum: General
Topic: Certificate CRL
Replies: 0
Views: 1052

Certificate CRL

Hi I've noticed that in /certificate menu it's possible to add/define CRL. I'm not sure why it's there, as certificates define CRL themselves: a certificate can contain CRL url for verification (alternative method is OCSP). Ex: certificate of this forum site, defines a CRL and it's enclosed in it, a...
by sebastia
Sat May 31, 2025 12:00 pm
Forum: General
Topic: Hex-S trunk port works, access ports do not.
Replies: 8
Views: 1773

Re: Hex-S trunk port works, access ports do not.

Be warned that this is not a recommended configuration, as all bridge traffic will be passed on to cpu. Depending on the volume of the traffic that might become a bottleneck.
by sebastia
Fri May 30, 2025 9:39 pm
Forum: General
Topic: New Hex S (2025)
Replies: 17
Views: 3707

Re: New Hex S (2025)

it seems like a winner in several aspects Not sure... If you look at the theoretical (!) throughput numbers (https://mikrotik.com/product/hex_s_2025#fndtn-testresults) It can "only" hit 1.4Gb/s. In practice will probably be less. Hence that 2.5Gb port is kind of overkill for routing useca...
by sebastia
Wed May 28, 2025 8:29 pm
Forum: Beginner Basics
Topic: Correc routing mark
Replies: 8
Views: 1963

Re: Correc routing mark

Thx for sharing :-)
by sebastia
Wed May 28, 2025 8:26 pm
Forum: Beginner Basics
Topic: Force traffic from main site to other remote sites
Replies: 10
Views: 4333

Re: Force traffic from main site to other remote sites

...Just by setting up routes, the traffic does not get forced trough the IPSec/GRE tunnel.
Sure it does, that's what the _core_ role of routing is

Have a closer look at the linked article, mangling is ONE of the options, not the only one. Which one is best will depend on your criteria...
by sebastia
Wed May 28, 2025 8:23 pm
Forum: Beginner Basics
Topic: Hex E50UG
Replies: 103
Views: 9278

Re: Hex E50UG

Please try and hopefully confirm. Then default config could then be updated as well...
by sebastia
Mon May 26, 2025 1:18 pm
Forum: MikroTik hardware questions
Topic: L009 cpu frequency
Replies: 18
Views: 2312

Re: L009 cpu frequency

and the Chinese copy of this TP-link https://www.cudy.com/products/gs108e-1-0 is only $27 and that's sad.
:lol: , china coping itself...
by sebastia
Mon May 26, 2025 1:17 pm
Forum: MikroTik hardware questions
Topic: L009 cpu frequency
Replies: 18
Views: 2312

Re: L009 cpu frequency

For all those "it's a switch" statements...

If you look closely ;-) at the product offering website of Mikrotik, you will find L009 here:

https:// mikrotik.com/products/group/ethernet-routers

The switches are under
https:// mikrotik.com/products/group/switches

Thank you
by sebastia
Mon May 26, 2025 12:52 pm
Forum: General
Topic: RB5009 L009 shoes for wall mounting
Replies: 2
Views: 1035

Re: RB5009 L009 shoes for wall mounting

"shoe" fits on the metal base section, on both sides
by sebastia
Mon May 26, 2025 2:58 am
Forum: General
Topic: RB5009 L009 shoes for wall mounting
Replies: 2
Views: 1035

RB5009 L009 shoes for wall mounting

Hi

If considering wall mounting a RB5009 or L009, these might come in handy.

https://www.thingiverse.com/thing:7048327

Regards
by sebastia
Mon May 26, 2025 1:44 am
Forum: MikroTik hardware questions
Topic: L009 cpu frequency
Replies: 18
Views: 2312

Re: L009 cpu frequency

L009 is fixed, to 800MHz (x2)

My point: platforms react differently to other forms of load and don't behave in same manner
by sebastia
Mon May 26, 2025 1:35 am
Forum: General
Topic: v7.19 ssh login stucks with F1 for help
Replies: 5
Views: 1460

Re: v7.19 ssh login stucks with F1 for help

any other out-of-band methods available? serial?
have you tried rebooting again (via dc methods)?

looks like some troubleshooting / post-mortem will be needed, as 7.19 had quite some changes, including for ssh
by sebastia
Sun May 25, 2025 6:28 pm
Forum: MikroTik hardware questions
Topic: L009 cpu frequency
Replies: 18
Views: 2312

Re: L009 cpu frequency

Thx, one can always learn something new... From my experience these tests are not representative: no queueing, no natting, no mangling, no vlans, ... And these are all applicable to (most) real-world scenarios. If we look at the numbers: L009 is supposed to do about 80k-ish of packets /s. @Chechito ...
by sebastia
Sun May 25, 2025 1:14 pm
Forum: General
Topic: v7.19 ssh login stucks with F1 for help
Replies: 5
Views: 1460

Re: v7.19 ssh login stucks with F1 for help

Hey

bit low on details / context

changelog does mention some changes: https://mikrotik.com/download/changelogs
by sebastia
Sun May 25, 2025 1:00 pm
Forum: Beginner Basics
Topic: Correc routing mark
Replies: 8
Views: 1963

Re: Correc routing mark

Hey

the split is currently done based on dst-address, for that to work well you need to have knowledge of all involved addresses.
Seems as you miss some still for reddit and paramount, as when you forward all over vpn it does work.

So either update the dst-address list or use another discriminator.
by sebastia
Sun May 25, 2025 2:20 am
Forum: MikroTik hardware questions
Topic: L009 cpu frequency
Replies: 18
Views: 2312

Re: L009 cpu frequency

off course, is a common misconception, there are to compare devices, not to be representative of some scenario

the possible scenarios are infinite
If the tests are not representative of real-world use-cases, how should I have used these as devices are not being compared in tests that matter?
by sebastia
Sun May 25, 2025 12:53 am
Forum: MikroTik hardware questions
Topic: L009 cpu frequency
Replies: 18
Views: 2312

Re: L009 cpu frequency

Thank you for your feedback. I do get the impression that you skimmed mostly over previous posts... I didn't own 2011, does nostalgia apply then? about pricing, homework and so forth, I did write this "For a specific use-case I've selected L009, as it matches the needs." and "...but w...
by sebastia
Sat May 24, 2025 8:28 pm
Forum: MikroTik hardware questions
Topic: L009 cpu frequency
Replies: 18
Views: 2312

Re: L009 cpu frequency

agreed, it's a promising platform with this unfortunate limitation
by sebastia
Sat May 24, 2025 4:08 pm
Forum: MikroTik hardware questions
Topic: L009 cpu frequency
Replies: 18
Views: 2312

Re: L009 cpu freqency

So went bing-ing ;-)

Found this: https://www.wolfchip.com/qualcomm/ipq-5 ... -01-0.html

up to 1.4GHz ...
ARM Cortex-A53 (hence 64bit)

Hence, intentional limitation ...?
1 or 1.2 GHz with such a massive heatsink should be easy
by sebastia
Sat May 24, 2025 3:46 pm
Forum: MikroTik hardware questions
Topic: L009 cpu frequency
Replies: 18
Views: 2312

Re: L009 cpu freqency

Did you already test if the device as-is performs according to your needs ?
did indeed, it's doing its thing, but with little to no headroom, hence the question. Would like some (more) peace of mind, that if anything ...

and indeed the reference (previous) was running v6.
by sebastia
Sat May 24, 2025 3:37 pm
Forum: General
Topic: Test configurations details
Replies: 2
Views: 944

Re: Test configurations details

thx for feedback

given the wording, i did expect a connection-less, fire-and-forget "dump packets as long as enough pass" way of testing
...which is everything but what I use in real life (mainly ipv4/6 tcp)

but hoping to discover some hints on optimal / most efficient configuration(s)
by sebastia
Sat May 24, 2025 3:29 pm
Forum: General
Topic: Mangle rule for forward traffic on secondary routing table [SOLVED]
Replies: 24
Views: 2891

Re: Mangle rule for forward traffic on secondary routing table [SOLVED]

addition of in-interface(-list) is an optimisation but you still need to enable both -> remove "disabled=yes" disabling fasttrack will do the trick, but a bit harsh for the rest, unless perf is not an issue... a simple alternative method is to fasttrack traffic going to WAN1 only all that ...
by sebastia
Sat May 24, 2025 2:41 pm
Forum: MikroTik hardware questions
Topic: L009 cpu frequency
Replies: 18
Views: 2312

L009 cpu frequency

Hi For a specific use-case I've selected L009, as it matches the needs. I'm a bit concerned though that the cpu; it is a bit underpowered. The predecessor of this platform, 2011, had the ability to adjust cpu clock speed. Given the massive heatsink and cpu operational temp, barely above room temp, i...
by sebastia
Sat May 24, 2025 11:55 am
Forum: General
Topic: Test configurations details
Replies: 2
Views: 944

Test configurations details

Hi Miktrotik usually displays for their products a "Test results" page / tab with performance / throughput of item in different configurations. Ex: https://mikrotik.com/product/RB750r2#fndtn-testresults What I'm wondering is if these hardware configurations are documented / are public / ca...
by sebastia
Fri May 23, 2025 8:05 pm
Forum: General
Topic: Mangle rule for forward traffic on secondary routing table [SOLVED]
Replies: 24
Views: 2891

Re: Mangle rule for forward traffic on secondary routing table [SOLVED]

lets go in order: see also https://help.mikrotik.com/docs/spaces/ROS/pages/328227/Packet+Flow+in+RouterOS#PacketFlowinRouterOS-FlowofRoutedPacket ip fw mangle: both needed but disabled -> NOK + update second (mark-routing) to include your internal in-interface, so only marking when going to WAN (gue...
by sebastia
Thu May 22, 2025 8:59 pm
Forum: General
Topic: Mangle rule for forward traffic on secondary routing table [SOLVED]
Replies: 24
Views: 2891

Re: Mangle rule for forward traffic on secondary routing table [SOLVED]

please also post rest of /ip firewall config as it's relevant

(or just the full config minus sensitive stuff)
by sebastia
Wed May 21, 2025 11:12 pm
Forum: General
Topic: Firewall: Allow access to device on specific ports only
Replies: 2
Views: 1000

Re: Firewall: Allow access to device on specific ports only

sure, it possible.

In firewall, in the forward chain, you'll need to allow traffic from wg to that server and the specific set of port. block all else (catch all rule).
by sebastia
Wed May 21, 2025 11:10 pm
Forum: General
Topic: Which modems support eSIM [SOLVED]
Replies: 13
Views: 3493

Re: Which modems support eSIM [SOLVED]

It's new/fresh... Probably best to contact support then, as bugs are ironed out
by sebastia
Wed May 21, 2025 11:05 pm
Forum: General
Topic: Which modems support eSIM [SOLVED]
Replies: 13
Views: 3493

Re: Which modems support eSIM [SOLVED]

Have you noticed the note?

RouterOS version: 7.18+
by sebastia
Wed May 21, 2025 7:35 pm
Forum: General
Topic: SRC-NAT setup issue
Replies: 2
Views: 1004

Re: SRC-NAT setup issue

I guessing we havn''t seen the full nat table yet, have we?
by sebastia
Wed May 21, 2025 7:20 pm
Forum: Beginner Basics
Topic: Mikrotik with LTE to ethernet
Replies: 9
Views: 2245

Re: Mikrotik with LTE to ethernet

you say it like you've never worked for support, translating from human to techspeak :) everybody is lazy and writes/tells minimum-minimorum of information, expecting others sharing same context and common sense... which is not that common.
I love it :lol:
by sebastia
Wed May 21, 2025 12:45 am
Forum: General
Topic: Mangle rule for forward traffic on secondary routing table [SOLVED]
Replies: 24
Views: 2891

Re: Mangle rule for forward traffic on secondary routing table [SOLVED]

Now the router responds correctly even on the secondary WAN, with the exception of Wireguard.

Furthermore, I would like to make the firewall reachable from the secondary WAN, regardless of whether the primary WAN was Up or not.
These seem to contradict each other?
by sebastia
Wed May 21, 2025 12:37 am
Forum: General
Topic: Mangle rule for forward traffic on secondary routing table [SOLVED]
Replies: 24
Views: 2891

Re: Mangle rule for forward traffic on secondary routing table [SOLVED]

Correct, but once a packet matches the fasttrack rule, no other rules are processed
it effectively works as "accept all"
not quite true, see previous link

agreed for the rest
by sebastia
Tue May 20, 2025 9:06 pm
Forum: General
Topic: Mangle rule for forward traffic on secondary routing table [SOLVED]
Replies: 24
Views: 2891

Re: Mangle rule for forward traffic on secondary routing table [SOLVED]

good catch on the "forward" chain Just to correct/clarify: fasttracking doesn''t disable firewall, it optimises it https://help.mikrotik.com/docs/spaces/ROS/pages/130220087/Connection+tracking#Connectiontracking-FastTrack further you can exclude all marked packets from fasttrack once a con...
by sebastia
Tue May 20, 2025 8:29 pm
Forum: General
Topic: Dedicated ISP for VoIP
Replies: 5
Views: 1457

Re: Dedicated ISP for VoIP

There is still a problem with this setup. You meant to say, "I've extra/new requirements..." right? When the Gateway IP address for the dedicated VoIP network is not the active default route, the route back does not work Indeed, not configured for that. How can i get this config working, ...
by sebastia
Tue May 20, 2025 8:05 pm
Forum: General
Topic: Mangle rule for forward traffic on secondary routing table [SOLVED]
Replies: 24
Views: 2891

Re: Mangle rule for forward traffic on secondary routing table [SOLVED]

Hi some feedback: Wireguard seems to always follow the main routing table, I don't understand why. currently wg will use main table, so if wan1 is up (distance=1), it will use it, if wan1 not there, it will use wan2 (distance=2) Switching may require purging conntrack data, some have observed. In th...
by sebastia
Mon May 19, 2025 7:21 pm
Forum: General
Topic: All interfaces link down on max load (950MB-1gb) [SOLVED]
Replies: 24
Views: 3426

Re: All interfaces link down on max load (950MB-1gb) [SOLVED]

well done

that 2011 is quite a capable hardware, in right context and with right config
by sebastia
Sun May 18, 2025 10:42 pm
Forum: General
Topic: All interfaces link down on max load (950MB-1gb) [SOLVED]
Replies: 24
Views: 3426

Re: All interfaces link down on max load (950MB-1gb) [SOLVED]

Last thing to fix: is that the dhcp client from bridge-base can't get address. Looks like everything behind ether 3 can't see this mikrotik as well. https://help.mikrotik.com/docs/spaces/ROS/pages/15302988/Switch+Chip+Features#SwitchChipFeatures-Tagged add bridge1-cpu to vlan1 create vlan on bridge...
by sebastia
Sun May 18, 2025 10:34 pm
Forum: General
Topic: All interfaces link down on max load (950MB-1gb) [SOLVED]
Replies: 24
Views: 3426

Re: All interfaces link down on max load (950MB-1gb) [SOLVED]

Looks good...

Some improvements:
* eth1 & eth4 are access ports for vlan 1?
if so best to define it as such in /interface ethernet switch port, just as for port 3

* if you have strict vlan filtering (in switch chip), you probably also want independent-learning=yes
by sebastia
Sun May 18, 2025 7:21 pm
Forum: General
Topic: CHR nat masquerade performance
Replies: 35
Views: 3755

Re: awfull nat masquerade performance

@NathanA
I admire your patience.
by sebastia
Sun May 18, 2025 7:08 pm
Forum: General
Topic: All interfaces link down on max load (950MB-1gb) [SOLVED]
Replies: 24
Views: 3426

Re: All interfaces link down on max load (950MB-1gb) [SOLVED]

if you post your current config, someone can suggest fine-tuning ...
by sebastia
Sun May 18, 2025 3:17 pm
Forum: General
Topic: All interfaces link down on max load (950MB-1gb) [SOLVED]
Replies: 24
Views: 3426

Re: All interfaces link down on max load (950MB-1gb) [SOLVED]

(I don't have 2011, hence can't test) Based on docs, as mentioned, this chip requires special config: https://help.mikrotik.com/docs/spaces/ROS/pages/15302988/Switch+Chip+Features#SwitchChipFeatures-PortSettings set default-vlan-id for access ports -> eth2 needs vlan 5 set /interface ethernet switch...
by sebastia
Sun May 18, 2025 1:24 pm
Forum: General
Topic: All interfaces link down on max load (950MB-1gb) [SOLVED]
Replies: 24
Views: 3426

Re: All interfaces link down on max load (950MB-1gb) [SOLVED]

based on your feedback I understood that: * eth2 is access port for ISP * eth3 is tagged for vlan 5 to server /interface vlan -> remove name=vlan-cosmos vlan-id=5 because no need to access vlan 5 on router /interface bridge port -> remove interface=vlan-cosmos -> assign interface=ether2 to bridge-ba...
by sebastia
Sun May 18, 2025 12:41 pm
Forum: General
Topic: All interfaces link down on max load (950MB-1gb) [SOLVED]
Replies: 24
Views: 3426

Re: All interfaces link down on max load (950MB-1gb) [SOLVED]

hyper-v VM interface: is that the eth3 comment=SERVER-FSG?
is that a tagged or untagged / access port?
there is no need for vlan 5 access on router?
by sebastia
Sat May 17, 2025 11:11 pm
Forum: General
Topic: All interfaces link down on max load (950MB-1gb) [SOLVED]
Replies: 24
Views: 3426

Re: All interfaces link down on max load (950MB-1gb) [SOLVED]

current config of vlan is not in line with switch chip recommendations, see links before
I would start with that

and then also upgrade to latest version, if still there -> support ticket
and if not solved, downgrade to v6, as there some reported ok
by sebastia
Sat May 17, 2025 8:46 pm
Forum: General
Topic: All interfaces link down on max load (950MB-1gb) [SOLVED]
Replies: 24
Views: 3426

Re: All interfaces link down on max load (950MB-1gb) [SOLVED]

Given that https://mikrotik.com/product/RB2011UiAS-2HnD-IN#fndtn-specifications https://cdn.mikrotik.com/web-assets/product_files/Block-RB2011UAS-2HnD_130546.pdf https://help.mikrotik.com/docs/spaces/ROS/pages/15302988/Switch+Chip+Features add bridge=bridge-base hw=no I suspect all bridge traffic is...
by sebastia
Sat May 17, 2025 1:37 pm
Forum: General
Topic: Redundancy based on L2HW / LACP cluster of two CCR2116-12G-4S+ routers
Replies: 12
Views: 2463

Re: Redundancy based on L2HW / LACP cluster of two CCR2116-12G-4S+ routers

Hi

Have you tried to research on https://help.mikrotik.com/docs/?

quick search gave multiple hits...
by sebastia
Sat May 17, 2025 1:32 pm
Forum: General
Topic: All interfaces link down on max load (950MB-1gb) [SOLVED]
Replies: 24
Views: 3426

Re: All interfaces link down on max load (950MB-1gb) [SOLVED]

Hi

you should at least provide config info ... (see forum notes on /export) We do not have a "cristal ball"
by sebastia
Wed May 14, 2025 11:57 pm
Forum: General
Topic: Dedicated ISP for VoIP
Replies: 5
Views: 1457

Re: Dedicated ISP for VoIP

Hey does the cloud bpx use specific ip(s) (ranges)? then you could selectively direct traffic to these over the separate uplink. Make sure that uplink does not have a default route defined, so it won't become fail-over connection. this could be even in the main routing table /ip/route/add dst-addres...
by sebastia
Wed May 14, 2025 12:27 am
Forum: General
Topic: NAT & GRE
Replies: 1
Views: 1147

Re: NAT & GRE

Hi what is the goal of this two? /ip firewall filter add action=accept chain=forward dst-address=10.2.0.0/26 out-interface=test src-address=1.1.2.2 /ip firewall nat add action=src-nat chain=srcnat out-interface=test src-address=10.2.0.0/26 to-addresses=1.1.2.2 that's to vpn server and using it's pub...
by sebastia
Tue May 13, 2025 11:55 pm
Forum: General
Topic: Upload speed problem
Replies: 5
Views: 1623

Re: Upload speed problem

by sebastia
Tue May 13, 2025 11:25 pm
Forum: General
Topic: Overlapping IP in a site-to-site VPN
Replies: 7
Views: 1728

Re: Overlapping IP in a site-to-site VPN

maybe yet simpler:
(your site)
route rule to force over wg
(other site)
dnat to .1 (target)

-> spread complexity
by sebastia
Tue May 13, 2025 12:34 am
Forum: General
Topic: Overlapping IP in a site-to-site VPN
Replies: 7
Views: 1728

Re: Overlapping IP in a site-to-site VPN

On second thought, natting and routing rule might collide:
not sure when routing rule is evaluated, but if after prerouting, where natting is done
it will not have right effect
https://help.mikrotik.com/docs/spaces/R ... OS-Forward
pls verify
by sebastia
Tue May 13, 2025 12:22 am
Forum: General
Topic: Overlapping IP in a site-to-site VPN
Replies: 7
Views: 1728

Re: Overlapping IP in a site-to-site VPN

Regarding your example: remove /ip firewall mangle add action=mark-routing chain=prerouting dst-address=10.0.0.2 in-interface=vlan101 new-routing-mark=143 passthrough=no change /routing rule add action=lookup disabled=no routing-mark=143 table=143 to /routing rule add action=lookup disabled=no dst-a...
by sebastia
Mon May 12, 2025 11:51 pm
Forum: General
Topic: vlan translation
Replies: 1
Views: 1311

Re: vlan translation

by sebastia
Mon May 12, 2025 11:47 pm
Forum: General
Topic: Two same subnets in difrient location
Replies: 2
Views: 1290

Re: Two same subnets in difrient location

An alternative (and simple) solution: a dedicate "bridge" link, bridging the two switch domains.
by sebastia
Mon May 12, 2025 11:38 pm
Forum: General
Topic: Tunnel performance
Replies: 1
Views: 1327

Re: Tunnel performance

Hey It's a discouraged practice to perform bandwidth tests involving the subjects themselves for load generation; meaning have other instances, not the routers, do the load test. Also, as you hinted, a tunnel will have lower mtu. that should be accounted for at source and target, to avoid fragmentat...
by sebastia
Mon May 12, 2025 11:23 pm
Forum: General
Topic: Overlapping IP in a site-to-site VPN
Replies: 7
Views: 1728

Re: Overlapping IP in a site-to-site VPN

Hey

In this particular case, you could remove the "mangle" rule with extended route rule which would include the dst-adr.

And another appraoch: have second site mulit-homed, with 2nd non coliding ip.
by sebastia
Mon May 12, 2025 12:09 am
Forum: General
Topic: 10G link works fine for a day then breaks until interface disabled/enabled
Replies: 5
Views: 1627

Re: 10G link works fine for a day then breaks until interface disabled/enabled

Have you considered a DAC? will be cooler and less power hungry
Example: https://mikrotik.com/product/s_ao0005
by sebastia
Sun May 11, 2025 11:33 pm
Forum: General
Topic: Multiple OVPN servers, one per ether port
Replies: 2
Views: 1140

Re: Multiple OVPN servers, one per ether port

Hey

Sure, it's possible, each instance of OpenVPN, could be limited at the level of firewall to specific access only.

see:
https://help.mikrotik.com/docs/spaces/R ... 55/OpenVPN and
https://help.mikrotik.com/docs/spaces/R ... 574/Filter
by sebastia
Sun May 11, 2025 10:00 pm
Forum: General
Topic: Per-IP WAN traffic statistics
Replies: 54
Views: 35859

Re: Per-IP WAN traffic statistics

Please remind me, is Kid controls usage of simple queues, and by extension this script, compatible with "fast-track"-ing?

Thx
by sebastia
Sun May 11, 2025 7:56 pm
Forum: General
Topic: Winbox loosing connection
Replies: 6
Views: 2197

Re: Winbox loosing connection

Hey

That's like "needle in the haystack" ...

Please be more specific: how do you connect, from to, any additional observations about the system? what is happing on crs when you do loos connectivity? is the loss at random or some specific situations? and so on...
by sebastia
Fri Mar 12, 2021 1:16 pm
Forum: MikroTik hardware questions
Topic: hEX block diagram
Replies: 47
Views: 22738

Re: hEX block diagram

I you want some assistance or information you should be a bit more polite. Most of us on this forum are not here because we are paid for it. And how would you explain it then, considering that this test goes right against the results of your tests number 2 & 4 from you first post here??? both we...
by sebastia
Fri Mar 12, 2021 12:54 pm
Forum: MikroTik hardware questions
Topic: hEX block diagram
Replies: 47
Views: 22738

Re: hEX block diagram

The 1Gb/s links are full duplex.
Just for posteriority, this is NOT the case: Mikrotik always reports full bandwidth over all directions -> that 1Gb/s is shared for both directions!
(as supported by your own tests)
by sebastia
Fri Mar 12, 2021 12:49 pm
Forum: MikroTik hardware questions
Topic: hEX block diagram
Replies: 47
Views: 22738

Re: hEX block diagram

1) If we are talking about 5 independent ports: the two 1Gbps links will be used, as needed. There is no hard assignment of a link to a group os ports.
Don't believe that to be the case: I think the port attribution of all independent links is fixed, (but I haven't tested it...)
by sebastia
Fri Mar 12, 2021 12:44 pm
Forum: MikroTik hardware questions
Topic: hEX block diagram
Replies: 47
Views: 22738

Re: hEX block diagram

in tests 1 & 3 you don't go to cpu, but are using the hardware switching in the switch chip (= off-loading) -> hence the limitations of the link to cpu don't apply and you get full bandwidth of the 1Gb/s connection / port

So how about that admission :-D ?
by sebastia
Fri Mar 12, 2021 12:18 pm
Forum: MikroTik hardware questions
Topic: hEX block diagram
Replies: 47
Views: 22738

Re: hEX block diagram

you are using it (1Gb/s) already!

see second test:
Image
Tx + Rx ~1Gb/s for ports ether1 & ether4

the 1Gb/s from diagram is TOTAL bandwidth available, for BOTH sending and receiving

I expect an apology now ;-)
by sebastia
Thu Jun 25, 2020 9:23 pm
Forum: General
Topic: DNS forward based on domain name [SOLVED]
Replies: 41
Views: 30697

Re: DNS forward based on domain name [SOLVED]

Just noticed it myself in changelog :-)
Good news indeed

Although regex has been mentioned before by staff to be heavy
by sebastia
Wed Nov 27, 2019 11:05 am
Forum: Wireless Networking
Topic: R11e-LTE6 field-test
Replies: 4
Views: 2956

Re: R11e-LTE6 field-test

Thx.

Interesting info. A bit early, as you only got it, but I would like to hear your findings on link / connection stability.
by sebastia
Tue Nov 19, 2019 4:15 pm
Forum: General
Topic: Add DNS over HTTPS (DoH) support
Replies: 130
Views: 120796

Re: Add DNS over HTTPS (DoH) support

For the time being, we have to look to other platforms, ex dnsmasq
by sebastia
Tue Nov 19, 2019 4:10 pm
Forum: General
Topic: Is there an new exploit going around?
Replies: 57
Views: 25450

Re: Is there an new exploit going around?

In a way, the affected owners should be thankful for the wake-up call and that the payload was so benign!
Any updates / new events on the topic?
by sebastia
Tue Nov 19, 2019 3:22 pm
Forum: Wireless Networking
Topic: R11e-LTE6 field-test
Replies: 4
Views: 2956

R11e-LTE6 field-test

Hey

I'm looking for any and all feedback on field-testing of R11e-LTE6.
Please share your findings.

Kind regards
Sebastian
by sebastia
Tue Nov 19, 2019 2:31 pm
Forum: Beginner Basics
Topic: hAP lite
Replies: 11
Views: 3375

Re: hAP lite

Have a look here wrt L7 config: https://www.youtube.com/watch?v=RtFZKvLKgD0
(+ changes as suggested by mkx)
by sebastia
Tue Nov 19, 2019 2:27 pm
Forum: Beginner Basics
Topic: RB941-2nD and bridge filter feature
Replies: 8
Views: 1945

Re: RB941-2nD and bridge filter feature

Next to "use-ip-firewall=yes" one could also just add bridge rules under /interface bridge filter.
by sebastia
Sat Oct 26, 2019 7:39 pm
Forum: General
Topic: Can somebody explain scope and target scope?
Replies: 46
Views: 31542

Re: Can somebody explain scope and target scope?

Have a look here too: https://wiki.mikrotik.com/wiki/Manual:I ... hop_lookup

Scope is linked to routing configuration: 10 for local, 30 for static, ...
Target scope is that as well, and by specifying target one can define how next hop can be looked up.
by sebastia
Thu Oct 24, 2019 12:20 pm
Forum: RouterOS beta
Topic: Scope of v7.0
Replies: 6
Views: 5656

Re: Scope of v7.0

Is there a high-level roadmap? Could you share it?
by sebastia
Thu Oct 24, 2019 12:13 pm
Forum: RouterOS beta
Topic: Scope of v7.0
Replies: 6
Views: 5656

Re: Scope of v7.0

is the current beta functionality-wise complete
No, BGP and MPLS are not even enabled.
Thx for reaction. Disabled routing was mentioned with beta1, so that was a given / known. But what about the rest? Once bugs are ironed out and routing added, will that be v7.0?
by sebastia
Wed Oct 23, 2019 7:31 pm
Forum: RouterOS beta
Topic: Torrent client
Replies: 59
Views: 43523

Re: Torrent client

removed in beta3...
by sebastia
Wed Oct 23, 2019 7:30 pm
Forum: RouterOS beta
Topic: Scope of v7.0
Replies: 6
Views: 5656

Scope of v7.0

Hi Mikrotik

Is the scope of the first release of v7 covered by current beta? In other words is the current beta functionality-wise complete?

Thx
by sebastia
Mon Oct 21, 2019 2:42 pm
Forum: General
Topic: Queue priority and limits
Replies: 4
Views: 2998

Re: Queue priority and limits

priority is always active: queue tokens are used for packets from highest to lowest prio. Once pipe is full / tokens are exhausted and priority queues are full, new packets get dropped In effect, if bandwidth is not scarce, all packets are transmitted and one could say that priority is irrelevant, a...
by sebastia
Mon Oct 21, 2019 2:38 pm
Forum: General
Topic: OpenVPN routing
Replies: 4
Views: 3100

Re: OpenVPN routing

Most likely because of this in openvpn config

redirect-gateway def1
by sebastia
Sun Oct 20, 2019 5:10 pm
Forum: General
Topic: Feature request: connection nat mismatch detection
Replies: 4
Views: 2310

Re: Feature request: connection nat mismatch detection

Update on the implementation above with bridge filter rules: Event though the bridge rules are added for a specific "out-bridge", in my case being the LTE bridge, the rules are evaluated for all bridges. This generates additional load and throughput limitation on the main high bandwidth li...
by sebastia
Sun Oct 20, 2019 2:07 pm
Forum: General
Topic: OpenVPN routing
Replies: 4
Views: 3100

Re: OpenVPN routing

Hi Problem is with the routing indeed the first line shouldn't be there Destination Gateway Genmask Flags Metric Ref Use Iface 0.0.0.0 0.0.0.0 0.0.0.0 U 50 0 0 tun0 I would suggest to not let the client set any gateway, and nat outgoing traffic to clients, on the vpn server (so src-nat then), to it'...
by sebastia
Sat Oct 19, 2019 11:49 pm
Forum: General
Topic: High CPU Usage on CCR 1036-12G-4S
Replies: 4
Views: 4782

Re: High CPU Usage on CCR 1036-12G-4S

Have a look here https://mum.mikrotik.com/presentations/MX17/presentation_4265_1495639302.pdf But why not start with this: * masquerade: don't use as you have static ip's -> to be replaced (whenever an ip is lost all connections linked to that will need to be dropped, meaning scanning ALL connection...
by sebastia
Sat Oct 19, 2019 11:23 pm
Forum: General
Topic: IP ARP Issue.
Replies: 2
Views: 1302

Re: IP ARP Issue.

if it's only 1 of 8 failing, I would be looking AT that failing ap. Is it up-to-date and so on...
by sebastia
Sat Oct 19, 2019 11:15 pm
Forum: General
Topic: Queue priority and limits
Replies: 4
Views: 2998

Re: Queue priority and limits

And the total limit is defined at the parent level, all children "borrow" from parent:

/queue tree add limit-at=0 max-limit=5000000 name=ether1 parent=ether1
by sebastia
Sat Oct 19, 2019 11:08 pm
Forum: General
Topic: Slow OpenVPN [SOLVED]
Replies: 6
Views: 5003

Re: Slow OpenVPN [SOLVED]

Do you have a backup or export of your "good" config?
by sebastia
Fri Oct 18, 2019 9:17 pm
Forum: Beginner Basics
Topic: connect with OpenVPNClient
Replies: 1
Views: 1158

Re: connect with OpenVPNClient

Hi

Communicating using your home ip is indeed possible. What you would need to ensure is that all traffic at the vpn client side is routed over the vpn / towards the vpn server endpoint.

Software functionality for all tiks is same, and so any tik can do that.
by sebastia
Mon Sep 23, 2019 10:34 pm
Forum: Beginner Basics
Topic: LTE passthrough winbox issue
Replies: 6
Views: 10857

Re: LTE passthrough winbox issue

in your case the vlan / mgmt traffic is caring same mac as passthrough, and hence gets hijacked by lte interface.

in current setup you'll need a bridge with other mac for the vlan

OR

reverse the config: mgmt over "plain" eth and passthrough over vlan without extra bridge
by sebastia
Wed Sep 18, 2019 11:06 pm
Forum: Beginner Basics
Topic: Configuration help. Is this possible?
Replies: 4
Views: 1918

Re: Configuration help. Is this possible?

Hi

While CRS305 technically can do what you propose, it's not meant to do that: it can do pppoe but not at speed, as it's not fast enough on cpu side.
by sebastia
Wed Sep 18, 2019 6:37 pm
Forum: MikroTik hardware questions
Topic: GPER usage questions
Replies: 34
Views: 12099

Re: GPER usage questions

I didn't say I agree with all comments there ;-)
by sebastia
Wed Sep 18, 2019 12:10 am
Forum: MikroTik hardware questions
Topic: GPER usage questions
Replies: 34
Views: 12099

Re: GPER usage questions

by sebastia
Wed Sep 18, 2019 12:00 am
Forum: General
Topic: scrnat rule configuration
Replies: 2
Views: 1942

Re: scrnat rule configuration

Hi

Src-nat and dst-nat are locate in different chains and are executed at different times, dst-nat before routing & src-nat after routing. One can't interfere with the other.

List your full firewall config if you need further assistance (/export hide-sensitive)
by sebastia
Tue Sep 17, 2019 11:47 pm
Forum: Beginner Basics
Topic: Difference in setting dhcp options
Replies: 1
Views: 1212

Re: Difference in setting dhcp options

server=available for all networks configurations
network=only that network

see also manual: https://wiki.mikrotik.com/wiki/Manual:I ... CP_Options
by sebastia
Tue Sep 17, 2019 11:34 pm
Forum: General
Topic: Block Multicast
Replies: 3
Views: 2708

Re: Block Multicast

Have a look at http://www.firewall.cx/networking-topics/general-networking/107-network-multicast.html or https://www.cisco.com/c/dam/en/us/products/collateral/ios-nx-os-software/ip-multicast/prod_presentation0900aecd80310883.pdf Drop: drop frames to the multicast mac range drop frames with ip protoc...
by sebastia
Tue Sep 17, 2019 10:21 pm
Forum: MikroTik hardware questions
Topic: GPER usage questions
Replies: 34
Views: 12099

Re: GPER usage questions

Thx for the info
by sebastia
Sun Sep 15, 2019 1:06 pm
Forum: Scripting
Topic: ppp profile -> scripts .... run as certain user
Replies: 9
Views: 6681

Re: ppp profile -> scripts .... run as certain user

ssh-exec has been added in 6.45.1 (viewtopic.php?t=149786&hilit=ssh-exec), and CAN be called from scripts!
by sebastia
Sun Sep 15, 2019 12:56 pm
Forum: Beginner Basics
Topic: Not working. What am i missing!?
Replies: 7
Views: 2732

Re: Not working. What am i missing!?

Looks ok.
Post full conifg (/export hide-sensitive), maybe something else is interfering.
by sebastia
Thu Sep 12, 2019 5:37 pm
Forum: General
Topic: Redundant routers/switches
Replies: 11
Views: 4429

Re: Redundant routers/switches

I'm not sure, but as I know, LACP cannot be set when there is only 1 connection between switches (sw1->sw3 and sw2->sw3). How to set LACP in this scenario?
I was thinking LACP between Hyper-V & SW3.
by sebastia
Thu Sep 12, 2019 2:52 pm
Forum: General
Topic: Redundant routers/switches
Replies: 11
Views: 4429

Re: Redundant routers/switches

Since the Hyper-V is in teaming mode... https://www.vembu.com/blog/configure-nic-teaming-hyper-v/ If Hyper-V ports algorithm is used with Switch Independent teaming mode, the virtual switch can register the MAC addresses of the virtual adapters on separate physical adapters which statically balances...
by sebastia
Thu Sep 12, 2019 2:34 pm
Forum: General
Topic: Redundant routers/switches
Replies: 11
Views: 4429

Re: Redundant routers/switches

Hey

SW3 should be in bridge mode, as both sw1-2 may be active at any time.

Just a remark: the SW3 is a "single point of failure" in that design.
by sebastia
Mon Sep 09, 2019 9:08 pm
Forum: General
Topic: Is the RB3011 a good fit?
Replies: 8
Views: 3330

Re: Is the RB3011 a good fit?

Hey

For general usage, it will do just fine: https://mikrotik.com/product/rb4011igs_ ... estresults
L2TP: don't expect that vpn will be at full speed
bridge: see
by sebastia
Mon Sep 09, 2019 6:38 pm
Forum: General
Topic: IPv4 over IPv6 Tunnel
Replies: 2
Views: 2285

Re: IPv4 over IPv6 Tunnel

Hey

have you tried pinging from B to A?

What is the routing table at SXT LTE like?
by sebastia
Sun Sep 08, 2019 1:51 pm
Forum: Beginner Basics
Topic: RB750, Pi-Hole and cross interface communication
Replies: 37
Views: 8477

Re: RB750, Pi-Hole and cross interface communication

add address=192.168.1.0/24 dns-server=192.168.10.2,1.1.1.1 gateway=192.168.1.254 netmask=24 -> why don't you specify your pi-hole only here? add address=192.168.1.0/24 dns-server=192.168.10.2 gateway=192.168.1.254 netmask=24 try this instead /ip firewall filter add action=accept chain=input comment=...
by sebastia
Sun Sep 08, 2019 1:02 pm
Forum: Forwarding Protocols
Topic: RB 3011UiAS dynamic routes missing for VLANS [SOLVED]
Replies: 4
Views: 11667

Re: RB 3011UiAS dynamic routes missing for VLANS [SOLVED]

Hey

Maybe some config issue, list your config for review (/export hide-sensitive).
by sebastia
Sat Sep 07, 2019 10:45 pm
Forum: Beginner Basics
Topic: RB750, Pi-Hole and cross interface communication
Replies: 37
Views: 8477

Re: RB750, Pi-Hole and cross interface communication

add action=accept chain=forward in-interface= bridge out-interface="eht1 Internet"
is enough

for filter table
output = traffic from router itself
(other were correct)
by sebastia
Sat Sep 07, 2019 1:34 pm
Forum: Beginner Basics
Topic: RB750, Pi-Hole and cross interface communication
Replies: 37
Views: 8477

Re: RB750, Pi-Hole and cross interface communication

these are not needed as dns is on another network
You can force any DNS request to use your DNS by using dst-nat
you're out of context, read last few posts. hint: i've commented on the src-nat!
by sebastia
Sat Sep 07, 2019 1:31 pm
Forum: Beginner Basics
Topic: Somehow im blind
Replies: 5
Views: 2315

Re: Somehow im blind

What are you missing, in your opinion? It could be a working config.
by sebastia
Sat Sep 07, 2019 12:33 pm
Forum: General
Topic: Wireless redundate link with bonding
Replies: 15
Views: 5263

Re: Wireless redundate link with bonding

Can also add a device each side of the wireless devices then use RSTP
will a wireless bridge pass the xSTP related frames?
by sebastia
Sat Sep 07, 2019 12:30 pm
Forum: Beginner Basics
Topic: RB750, Pi-Hole and cross interface communication
Replies: 37
Views: 8477

Re: RB750, Pi-Hole and cross interface communication

The reason for the Masquerade and DNAT rules are to force any and all DNS query to the Pi that is running PiHole, it's a content blocker based on DNS filter lists. these are not needed as dns is on another network As far as I understand, setting the DNS under IP--> DNS Settings will auto assign the...
by sebastia
Sat Sep 07, 2019 12:15 am
Forum: Beginner Basics
Topic: RB750, Pi-Hole and cross interface communication
Replies: 37
Views: 8477

Re: RB750, Pi-Hole and cross interface communication

why do you need this? add action=src-nat chain=srcnat comment="UDP DNS Masquerade Network" out-interface=bridge protocol=udp src-address=192.168.1.0/24 to-addresses=192.168.10.2 to-ports=53 add action=src-nat chain=srcnat comment="TCP DNS Masquerade Network" out-interface=bridge ...
by sebastia
Fri Sep 06, 2019 11:41 pm
Forum: Beginner Basics
Topic: RB750, Pi-Hole and cross interface communication
Replies: 37
Views: 8477

Re: RB750, Pi-Hole and cross interface communication

either that or ip stack is not correctly configured
list /export hide-sensitive
by sebastia
Fri Sep 06, 2019 10:36 pm
Forum: General
Topic: Wireless redundate link with bonding
Replies: 15
Views: 5263

Re: Wireless redundate link with bonding

that won't be immediate ;-)
by sebastia
Fri Sep 06, 2019 10:32 pm
Forum: General
Topic: Wireless redundate link with bonding
Replies: 15
Views: 5263

Re: Wireless redundate link with bonding

hint balance -> balances ;-) over both links

if you want active passive that's a different mode
the "immediate" hand over (subsecond) you can have with active-backup, see viewtopic.php?t=150820#p743780
by sebastia
Fri Sep 06, 2019 10:17 pm
Forum: General
Topic: Netinstall failing on Windows 10
Replies: 4
Views: 3460

Re: Netinstall failing on Windows 10

in my experience, netinstall can get "confused" when there are multiple interfaces active
by sebastia
Fri Sep 06, 2019 10:14 pm
Forum: Beginner Basics
Topic: RB750, Pi-Hole and cross interface communication
Replies: 37
Views: 8477

Re: RB750, Pi-Hole and cross interface communication

you have a problem with connectivity NOT dns resolution

you get an IP for a dns in each kind of test
but ping (icmp) and tcp don't get through..
by sebastia
Fri Sep 06, 2019 10:11 pm
Forum: General
Topic: Wireless redundate link with bonding
Replies: 15
Views: 5263

Re: Wireless redundate link with bonding

do you want an active-backup or active-active?
xor is the last one
by sebastia
Fri Sep 06, 2019 9:36 pm
Forum: Beginner Basics
Topic: RB750, Pi-Hole and cross interface communication
Replies: 37
Views: 8477

Re: RB750, Pi-Hole and cross interface communication

there is no problem, it's resolving
ping google.com [216.58.223.142]
by sebastia
Fri Sep 06, 2019 8:49 pm
Forum: Beginner Basics
Topic: RB750, Pi-Hole and cross interface communication
Replies: 37
Views: 8477

Re: RB750, Pi-Hole and cross interface communication

so your dns resolution works fine
by sebastia
Fri Sep 06, 2019 8:46 pm
Forum: General
Topic: Wireless redundate link with bonding
Replies: 15
Views: 5263

Re: Wireless redundate link with bonding

have a look at https://wiki.mikrotik.com/wiki/Manual:Interface/Bonding, and especially enable link monitoring, probably arp base
examples: https://wiki.mikrotik.com/wiki/Manual:Bonding_Examples
by sebastia
Fri Sep 06, 2019 8:24 pm
Forum: General
Topic: dst-limit possible problem
Replies: 4
Views: 2545

Re: dst-limit possible problem

only allow them at specified rate, drop rest
by sebastia
Fri Sep 06, 2019 8:15 pm
Forum: Beginner Basics
Topic: RouterBOARD 750P r2 - each interface in different network [SOLVED]
Replies: 2
Views: 1981

Re: RouterBOARD 750P r2 - each interface in different network [SOLVED]

in this config mgmt is only possible from "address=192.168.0.0/24"
none of the interfaces have this range, maybe routed from somewhere else (through ospf)?
by sebastia
Fri Sep 06, 2019 8:08 pm
Forum: General
Topic: Disabling/enabling SXT LTE web access via ssh
Replies: 1
Views: 1014

Re: Disabling/enabling SXT LTE web access via ssh

disable www & www-ssl ip services
by sebastia
Fri Sep 06, 2019 8:03 pm
Forum: Beginner Basics
Topic: RB750, Pi-Hole and cross interface communication
Replies: 37
Views: 8477

Re: RB750, Pi-Hole and cross interface communication

to verify dns functionality and limit the scope try testing with "ping" (udp dns) & "nslookup" (tcp dns). both do minimal functions.

if ping <some dns name> uses an ip -> udp dns works
if nslookup <some dns server> works -> tcp firewal / nat works
by sebastia
Fri Sep 06, 2019 7:53 pm
Forum: Forwarding Protocols
Topic: Routing problem.
Replies: 6
Views: 3556

Re: Routing problem.

don't see/have the details, but vpn needs to be src-nat, and if your internet uplink probably as well, so in that sense it might be
by sebastia
Fri Sep 06, 2019 5:55 pm
Forum: Forwarding Protocols
Topic: Routing problem.
Replies: 6
Views: 3556

Re: Routing problem.

for masq, out interface should be the vpn interface not ether1
don't use srcaddress list on the rule & just nat all going out over vpn -> less potential for issues
by sebastia
Fri Sep 06, 2019 4:23 pm
Forum: Forwarding Protocols
Topic: Routing problem.
Replies: 6
Views: 3556

Re: Routing problem.

The other side doesn't know your internal network, to resolve you need to setup src natting on your vpn interface (src-nat or masq)
by sebastia
Fri Sep 06, 2019 2:50 pm
Forum: Scripting
Topic: Parse ping result
Replies: 3
Views: 5420

Re: Parse ping result

Have a look at getRTT function here viewtopic.php?t=129294
by sebastia
Fri Sep 06, 2019 2:45 pm
Forum: General
Topic: Need help with DMZ config without access to the cameras IP and home automation devices by the WAN
Replies: 15
Views: 3829

Re: Need help with DMZ config without access to the cameras IP and home automation devices by the WAN

in that case you probably don't need any port forwarding as the camera's are connecting to cloud themselves (from inside to outside)? check it / consult documentation you'll need to verify how is the app finally connecting to the camera, through cloud or some other manner? If "some other" ...
by sebastia
Thu Sep 05, 2019 11:28 pm
Forum: General
Topic: Need help with DMZ config without access to the cameras IP and home automation devices by the WAN
Replies: 15
Views: 3829

Re: Need help with DMZ config without access to the cameras IP and home automation devices by the WAN

do you have some central management console / server?
and how to you "connect" the these devices from outside? directly or through some cloud feature?
by sebastia
Thu Sep 05, 2019 10:41 pm
Forum: General
Topic: Need help with DMZ config without access to the cameras IP and home automation devices by the WAN
Replies: 15
Views: 3829

Re: Need help with DMZ config without access to the cameras IP and home automation devices by the WAN

if you want to access each separately, then yes, port forward different ports to specific devices
by sebastia
Thu Sep 05, 2019 9:41 pm
Forum: General
Topic: Policy to block website in Mikrotik increase CPU
Replies: 16
Views: 4461

Re: Policy to block website in Mikrotik increase CPU

what is the /tool profile indicating?
could you share details on how the blocking works?
by sebastia
Thu Sep 05, 2019 9:36 pm
Forum: MikroTik hardware questions
Topic: CPU usage upto 90%
Replies: 2
Views: 2553

Re: CPU usage upto 90%

there was a presentation by Tik support on some frequent issues with pppoe servers: https://mum.mikrotik.com/presentations/ ... 948376.pdf
have a look if relevant for you
by sebastia
Thu Sep 05, 2019 9:25 pm
Forum: Beginner Basics
Topic: 1 interface, 2 vlans, prioritize Vlan2 95%
Replies: 8
Views: 2995

Re: 1 interface, 2 vlans, prioritize Vlan2 95%

how about vlan priority? https://wiki.mikrotik.com/wiki/Manual:W ... t_priority + shaping vlan2 to 95% of bandwidth
by sebastia
Thu Sep 05, 2019 9:08 pm
Forum: General
Topic: Need help with DMZ config without access to the cameras IP and home automation devices by the WAN
Replies: 15
Views: 3829

Re: Need help with DMZ config without access to the cameras IP and home automation devices by the WAN

/ip address add address=192.168.13.1/24 interface=ether2 network=192.168.13.0 => should be on brdige2 mikrotik doesn't have a dmz setting, needs to be done manually basically, any connection to the router which is "new" (so not part of existing connection from router) should be then dst-na...
by sebastia
Wed Sep 04, 2019 10:42 pm
Forum: General
Topic: Need help with DMZ config without access to the cameras IP and home automation devices by the WAN
Replies: 15
Views: 3829

Re: i have a problem, need help

post your config, as it's not clear what is what...
/export hide-sensitive (and replace any public ip's)
by sebastia
Wed Sep 04, 2019 5:07 pm
Forum: Beginner Basics
Topic: CCR to CRS using S+DA0001 [SOLVED]
Replies: 7
Views: 3020

Re: CCR to CRS using S+DA0001

Hey

On paper it sound all right, only there have been some reports of 317 instabilities when under full load. Then there are also people saying they are rock-solid...
by sebastia
Wed Sep 04, 2019 5:02 pm
Forum: General
Topic: Need help with DMZ config without access to the cameras IP and home automation devices by the WAN
Replies: 15
Views: 3829

Re: i have a problem, need help

And what is your question / request?
Also, post config in between < code > tags
by sebastia
Wed Sep 04, 2019 1:06 pm
Forum: General
Topic: Low Throughput on 2011 [SOLVED]
Replies: 5
Views: 2818

Re: Low Throughput on 2011 [SOLVED]

Hey * with fast-path disabled, fast-track will not work either * you'll need to exclude 88.200 from fasttrack, or manling for route mark will not work * You seem to have two wans? indihome + oxygen is oxygen some vpn for 88.200 only? * you have in config /interface pppoe-client add ac-name=BRAS3-D2-...
by sebastia
Wed Sep 04, 2019 12:46 pm
Forum: General
Topic: Tls host not work
Replies: 9
Views: 11530

Re: Tls host not work

I didn't try regex in content, but it does match on plain text.

For https, your current L7 will be working with TCP and SSL handshake which is still unencrypted data
by sebastia
Mon Sep 02, 2019 8:54 pm
Forum: General
Topic: OpenVPN move to another Board [SOLVED]
Replies: 6
Views: 8274

Re: OpenVPN move to another Board [SOLVED]

Hi

Normally one only import private key on target/server device. The public part can be distributed to the users of that server.

If Tik is CA, only import private key.
for opvn server: only import private key
for opvn client: only import private client key
by sebastia
Mon Sep 02, 2019 8:46 pm
Forum: Beginner Basics
Topic: two networks with vlan in RB2011 and Groove
Replies: 2
Views: 1557

Re: two networks with vlan in RB2011 and Groove

hey

and how is the goove connected to 2011?
by sebastia
Mon Sep 02, 2019 3:37 pm
Forum: Beginner Basics
Topic: can I access mikrotik rb2011 through internet
Replies: 7
Views: 2174

Re: can I access mikrotik rb2011 through internet

do you have public ip on rb2011? check under "/ip address" in Winbox or through command "/ip address print"
by sebastia
Mon Sep 02, 2019 3:26 pm
Forum: Beginner Basics
Topic: can I access mikrotik rb2011 through internet
Replies: 7
Views: 2174

Re: can I access mikrotik rb2011 through internet

That depends on your isp infrastructure (do you have public ip assigned? any ports which are not blocked by isp?) and the configuration of the Tik (what firewall setting do you have there?).
by sebastia
Mon Sep 02, 2019 3:24 pm
Forum: MikroTik hardware questions
Topic: hAP AC2 for home use
Replies: 12
Views: 12090

Re: hAP AC2 for home use

Hi

Does that Mikrotik remain ISP's property?
by sebastia
Mon Sep 02, 2019 11:49 am
Forum: General
Topic: Tls host not work
Replies: 9
Views: 11530

Re: Tls host not work

that or the "content" packet matching in plain firewall
by sebastia
Sun Sep 01, 2019 12:35 pm
Forum: General
Topic: Tls host not work
Replies: 9
Views: 11530

Re: Tls host not work

I would expect not as it related to Transport Layer Security which is not used with plain http.
by sebastia
Sat Aug 31, 2019 11:48 pm
Forum: General
Topic: Quee Process High
Replies: 1
Views: 1141

Re: Quee Process High

Hey Do you have another system to test these changes? In this particular case I would take that "advise" with a HUGE grain of salt, or better yet: just ignore it... Simple queues are processed by multiple cpu cores, which spreads the load. Do you see that? Try monitoring with /tool profile...
by sebastia
Fri Aug 30, 2019 11:07 am
Forum: Scripting
Topic: mkdir function for easy folder creation [SOLVED]
Replies: 19
Views: 16031

Re: mkdir function for easy folder creation [SOLVED]

I am some shocked.
A script on 200+ lines is needed just to create a folder in RouterOS.
This is some MT should add a built in function.
You can always log in via FTP to create a folder and/or copy/move files.
which is exactly what the script does...

NOT a acceptable "solution"
by sebastia
Fri Aug 30, 2019 10:34 am
Forum: General
Topic: Problem ping different lan
Replies: 1
Views: 978

Re: Problem ping different lan

This is not Tik related! You should be a asking on Windows forums...

Hint: indicate in windows that the connection is "private"
by sebastia
Fri Aug 30, 2019 1:19 am
Forum: General
Topic: And now?
Replies: 3
Views: 1523

Re: And now?

I thought so ;-)
by sebastia
Thu Aug 29, 2019 11:56 pm
Forum: General
Topic: RB4011 "under clocking" at 533MHz / frequency scaling
Replies: 3
Views: 2511

Re: RB4011 "under clocking" at 533MHz / frequency scaling

busted ;-), I don't own a 4011... Good to know, thx

I meant low-power, based on actual usage: "Max power consumption 44 W"
that's not a lot
by sebastia
Thu Aug 29, 2019 11:49 pm
Forum: General
Topic: And now?
Replies: 3
Views: 1523

Re: And now?

simple, as a mitigation, firewall / filter the api port
by sebastia
Thu Aug 29, 2019 11:29 pm
Forum: Beginner Basics
Topic: VLAN between two routers. Can it work!? If so how?
Replies: 9
Views: 4640

Re: VLAN between two routers. Can it work!? If so how?

- to keep the high speed datastreams away form pfSense (intel Pentium) - to see if it was an option to use the internal router in state of pfSense -> a CRS can't route 10g of data either! -> not with a CRS * to save interfaces between pfSense and the CRS317 -> don't understand that one * to have a l...
by sebastia
Thu Aug 29, 2019 9:17 pm
Forum: Beginner Basics
Topic: VLAN between two routers. Can it work!? If so how?
Replies: 9
Views: 4640

Re: VLAN between two routers. Can it work!? If so how?

Hey CRS is not a router, so you shouldn't be using it as one. I would suggest to upgrade the pfsense to "the only router" status: * only bridge on CRS for "data" vlans -> you did say that pfsens is owner of these! if so, CRS should not route (nor firewall) * this means no ip on d...
by sebastia
Thu Aug 29, 2019 7:13 pm
Forum: General
Topic: RB4011 "under clocking" at 533MHz / frequency scaling
Replies: 3
Views: 2511

Re: RB4011 "under clocking" at 533MHz / frequency scaling

Hey cpu frequency settings requires a reboot to become active (part of boot configuration), so use of script would be limited. Impact-wise, functionally it should do exactly same thing, but slower... Anything running on cpu will be impacted: routing, queuing, firewall, ... Hardware based switching /...
by sebastia
Wed Aug 28, 2019 12:18 am
Forum: General
Topic: Suggestion: VPN over ICMP
Replies: 3
Views: 2664

Re: Suggestion: VPN over ICMP

Hello From high-level point of view, there would be little difference between udp. And high stream of large icmp packets would be a red flag on it's own. Furthermore, some networks / routers perform icmp "optimisation" / rate limiting, which would result in high packet loss. So far from st...
by sebastia
Tue Aug 27, 2019 10:58 am
Forum: General
Topic: Mark packet dont work like expected
Replies: 2
Views: 1058

Re: Mark packet dont work like expected

What is your goal? What did you expect?
by sebastia
Tue Aug 27, 2019 1:36 am
Forum: Scripting
Topic: Remove src-address via script... [SOLVED]
Replies: 2
Views: 8151

Re: Remove src-address via script... [SOLVED]

/ip firewall nat set [find where action="masquerade"] !src-address out-interface-list=WAN
by sebastia
Mon Aug 26, 2019 10:37 pm
Forum: Beginner Basics
Topic: Trouble with setting priorities
Replies: 8
Views: 5167

Re: Trouble with setting priorities

If you want to have good gaming experience, then indeed you'll need to limit total download from router to all networks together to less than what modem can do. Similar for upload, limit all upload traffic to less what modem can upload. 90-95% is a safe starting point. your wan is ether1, update con...
by sebastia
Mon Aug 26, 2019 7:40 pm
Forum: Beginner Basics
Topic: tag all untagged traffic - can't get it working
Replies: 12
Views: 4184

Re: tag all untagged traffic - can't get it working

Sniffing takes place "close" to physical layer, and tagging might not have happened yet. Have you tried sniffing a trunk port down the hill? Wrt config, there are few entries, see https://wiki.mikrotik.com/wiki/Manual:Switch_Chip_Features#Setup_Examples. Is the vlan 10 already defined unde...
by sebastia
Mon Aug 26, 2019 7:24 pm
Forum: General
Topic: Force NTP Client Update
Replies: 5
Views: 7366

Re: Force NTP Client Update

Hey

ntp client will determine on it's own how frequently it should poll the upstream server for time update. Usually it starts at 64s and backs down down to 1024s, once clocks are in sync and drift is under control.
by sebastia
Sat Aug 24, 2019 2:49 pm
Forum: Useful user articles
Topic: Whitelisting websites
Replies: 16
Views: 33581

Re: Whitelisting websites

Hoi
All connections start with dns resolution. Filter / control these and you'll be able to control what connections are made (for most part).
by sebastia
Sat Aug 24, 2019 12:11 pm
Forum: Beginner Basics
Topic: Trouble with setting priorities
Replies: 8
Views: 5167

Re: Trouble with setting priorities

Hey

Start with posting your current config (/export hide-sensitive), and indicate what you want to achieve: ip/port/bandwidth/...
by sebastia
Fri Aug 23, 2019 7:03 pm
Forum: SwOS
Topic: Failover capabilities with unmanaged switches involved [SOLVED]
Replies: 11
Views: 16357

Re: Failover capabilities with unmanaged switches involved [SOLVED]

You keep on stating that, but without any references to back up your case. I on the other hand have proven with above setups that it indeed is the case. When you state that, I'm not so sure if you know what is going on... why don't you then explain to us if you're so sure of yourself what is going o...
by sebastia
Fri Aug 23, 2019 3:57 pm
Forum: SwOS
Topic: Failover capabilities with unmanaged switches involved [SOLVED]
Replies: 11
Views: 16357

Re: Failover capabilities with unmanaged switches involved [SOLVED]

unmananged switches don't participate in lldp, as said before they don't even have own mac
even this works just fine in any direction and any link interruption
2+2switches.png
see also web: https://networkengineering.stackexchang ... e-switches
by sebastia
Fri Aug 23, 2019 12:30 pm
Forum: General
Topic: Bridge VLAN Configuration not being applied
Replies: 4
Views: 2080

Re: Bridge VLAN Configuration not being applied

good plan!
by sebastia
Fri Aug 23, 2019 12:28 pm
Forum: Beginner Basics
Topic: New User Questions
Replies: 1
Views: 1144

Re: New User Questions

Hey, welcome on the forum. hap ac did you connect port 1 to your network. That port if in default config designated Wan, and firewalled. best would be to disable dhcp server on the bridge, within RouterOs, change the ip of the bridge and connect one of these port to your internal network. hex which ...
by sebastia
Fri Aug 23, 2019 12:17 pm
Forum: SwOS
Topic: Failover capabilities with unmanaged switches involved [SOLVED]
Replies: 11
Views: 16357

Re: Failover capabilities with unmanaged switches involved [SOLVED]

And to remove any doubt, this one works just fine too
2+1switches.png
by sebastia
Fri Aug 23, 2019 11:57 am
Forum: SwOS
Topic: Failover capabilities with unmanaged switches involved [SOLVED]
Replies: 11
Views: 16357

Re: Failover capabilities with unmanaged switches involved [SOLVED]

I disagree, an unmanaged switch is essentially invisible on the wire, it just passes packets around and has no own mac. So the above network boils down to this: 2switches.png with STP enabled on both ends, on bridge level, auto fail-over will function # R1 /interface bridge add name=bridge /interfac...
by sebastia
Fri Aug 23, 2019 12:36 am
Forum: SwOS
Topic: Failover capabilities with unmanaged switches involved [SOLVED]
Replies: 11
Views: 16357

Re: Failover capabilities with unmanaged switches involved [SOLVED]

well, there are two in this setup CRS & CSS...
by sebastia
Thu Aug 22, 2019 5:33 pm
Forum: General
Topic: Hap Ac 2, not capable of 1Gbit transfer
Replies: 11
Views: 3373

Re: Hap Ac 2, not capable of 1Gbit transfer

The only thing that draw my attention was dhcp-snooping on bridge, but its supposed to be done in hardware on AR8327... some other thoughts * check that counters for FastPath are "moving" * check cpu usage during transfer * do you test with multiple streams? * check bridge ports have "...
by sebastia
Thu Aug 22, 2019 4:47 pm
Forum: General
Topic: Hap Ac 2, not capable of 1Gbit transfer
Replies: 11
Views: 3373

Re: Hap Ac 2, not capable of 1Gbit transfer

could you post the config?
by sebastia
Thu Aug 22, 2019 12:54 pm
Forum: General
Topic: Mikrotik CCR 1036 8G 2S+ Performance issue
Replies: 9
Views: 2503

Re: Mikrotik CCR 1036 8G 2S+ Performance issue

which version are you running? remember that there was a bug in ROS with regards to that;
Ros 6.45.1:
*) firewall - process packets by firewall when accepted by RAW with disabled connection tracking;
by sebastia
Thu Aug 22, 2019 12:20 pm
Forum: General
Topic: Mikrotik CCR 1036 8G 2S+ Performance issue
Replies: 9
Views: 2503

Re: Mikrotik CCR 1036 8G 2S+ Performance issue

Hey

Do you have connection tracking enabled?
was the ddos on ipv6? there was an issue with that not so long ago (implementation in ROS), with a patch release. do you have it?

Edit: just noticed you don't have connection tracking enabled viewtopic.php?f=2&t=151403
by sebastia
Thu Aug 22, 2019 11:25 am
Forum: General
Topic: Discord question
Replies: 7
Views: 5274

Re: Discord question

hey, list your fill firewall rule set, for both ipv4 & ipv6. what I'm wondering: you have fasttrack dummy rule, but not fast track itself..., view is incomplete fasttrack will bypass most of ip processing for bigger part of packets of a connection, but on regular basis packets will be processed ...
by sebastia
Wed Aug 21, 2019 8:13 pm
Forum: Beginner Basics
Topic: Bridge untagged ether1 with tagged vlan3 on ether1.
Replies: 10
Views: 3562

Re: Bridge untagged ether1 with tagged vlan3 on ether1.

Anyway, once you put interfaces in a bridge, all configuration related to them needs to be done on the level of bridge. That includes ips, vlans, ... from the sound of it, you would want to bridge the vlans only, 3 and "1" (or another but untagged on ether1) If that's not enough, I would a...
by sebastia
Wed Aug 21, 2019 5:38 pm
Forum: Beginner Basics
Topic: Bridge untagged ether1 with tagged vlan3 on ether1.
Replies: 10
Views: 3562

Re: Bridge untagged ether1 with tagged vlan3 on ether1.

And what is the point of all that? These are still separate networks...

At least your footer is totally correct :-p
by sebastia
Wed Aug 21, 2019 3:16 pm
Forum: General
Topic: 2 wan load balancing with failover problems
Replies: 9
Views: 4734

Re: 2 wan load balancing with failover problems

is there a way to set 80/20 for example? Not directly, but you can achieve this by being creative: repeat a link multiple times, for 80/20, pretend you have 5 links each good for 20% of traffic: wan1,wan1,wan1,wan1,wan2 Another option, is bandwidth based load-balancing: https://forum.mikrotik.com/v...
by sebastia
Wed Aug 21, 2019 2:11 pm
Forum: General
Topic: 2 wan load balancing with failover problems
Replies: 9
Views: 4734

Re: 2 wan load balancing with failover problems

the default routes are only relevant in context of fail-over: each connection gets assigned to either Wan1 or Wan2 in mangling, only when that link is not up will the default be relevant. the current load balancing is 50/50 add action=mark-connection chain=prerouting connection-mark=no-mark \ dst-ad...
by sebastia
Wed Aug 21, 2019 1:05 pm
Forum: General
Topic: 2 wan load balancing with failover problems
Replies: 9
Views: 4734

Re: 2 wan load balancing with failover problems

you should remove fasttrack (action=fasttrack-connection, 3 instances), as it's not compatible with loadbalancing "add action=accept chain=prerouting comment=router dst-address-list=router" should be at the beginning of chain / before all LB logic your default routes should have different ...
by sebastia
Wed Aug 21, 2019 10:56 am
Forum: General
Topic: Moving rules from Filter to RAW cause better performance?
Replies: 7
Views: 4334

Re: Moving rules from Filter to RAW cause better performance?

as stated there("conntrack by default is most expensive RouterOS facility"), the high cost of/before "filter" table is the connection tracking logic. If it's disabled, it won't matter whether it's in raw or filter.
by sebastia
Wed Aug 21, 2019 10:53 am
Forum: Scripting
Topic: RoS functions cannot log when called from a Netwatch script
Replies: 5
Views: 3327

Re: RoS functions cannot log when called from a Netwatch script

actually that one ;-)
Since RouterOS v6.42 Netwatch is limited to read,write,test,reboot script policies.
To access global variables, "policy" right is needed
by sebastia
Wed Aug 21, 2019 10:48 am
Forum: Beginner Basics
Topic: Bridge untagged ether1 with tagged vlan3 on ether1.
Replies: 10
Views: 3562

Re: Bridge untagged ether1 with tagged vlan3 on ether1.

Let me rephrase: bridge is not what you are looking for = wrong in this case.

vlan3 & lan have different ip ranges so direct communication between devices is not possible -> a router between is needed to do the forwarding. A bridge will not solve that.
by sebastia
Tue Aug 20, 2019 11:19 pm
Forum: General
Topic: Slow Gbit speed with Mikrotik hex S
Replies: 15
Views: 9264

Re: Slow Gbit speed with Mikrotik hex S

If you swap the clients, do you also get "reverse" throughput? If so then I would start looking at the clients / software
by sebastia
Tue Aug 20, 2019 10:51 pm
Forum: General
Topic: Slow Gbit speed with Mikrotik hex S
Replies: 15
Views: 9264

Re: Slow Gbit speed with Mikrotik hex S

Hey

All port are independent, right? Not sure about the first transfer, but the second test is reaching physical limitation, as both ether1 & ether5 are on same data bus, which is limited to 1gbs.

see block diagram without switching: https://mikrotik.com/product/hex_s#fndtn-downloads
by sebastia
Tue Aug 20, 2019 10:20 pm
Forum: Scripting
Topic: RoS functions cannot log when called from a Netwatch script
Replies: 5
Views: 3327

Re: RoS functions cannot log when called from a Netwatch script

netwatch doesn't have enough permissions to invoke a global script, see note on https://wiki.mikrotik.com/wiki/Manual:Tools/Netwatch
by sebastia
Tue Aug 20, 2019 10:09 pm
Forum: General
Topic: 2 wan load balancing with failover problems
Replies: 9
Views: 4734

Re: 2 wan load balancing with failover problems

Hey

For starters, post your current config: /export hide-sensitive (in-between code tags)
by sebastia
Tue Aug 20, 2019 10:07 pm
Forum: Beginner Basics
Topic: 4G LTE Confusion
Replies: 3
Views: 1582

Re: 4G LTE Confusion

Hey SXT-4g support ONLY 4G. It will not connect over anything other. SXT-LTE support 4G+3G+2G. Regarding the speed, your phone will have a better modem (if any recent it will support Carrier Aggregation (~bonding for LTE)) than what is in SXT. So most likely you won't get similar rates. On the other...
by sebastia
Tue Aug 20, 2019 9:54 pm
Forum: Beginner Basics
Topic: Bridge untagged ether1 with tagged vlan3 on ether1.
Replies: 10
Views: 3562

Re: Bridge untagged ether1 with tagged vlan3 on ether1.

Hey

Why would you need the bridge anyway?
There is only one interface of each...
by sebastia
Tue Aug 20, 2019 9:46 pm
Forum: General
Topic: Bridge VLAN Configuration not being applied
Replies: 4
Views: 2080

Re: Bridge VLAN Configuration not being applied

a port without pvid would be a port with tagged traffic -> trunk port On https://wiki.mikrotik.com/wiki/Manual:Bridge_VLAN_Table doc says PVID - The Port VLAN ID is used for access ports to tag all ingress traffic with a specific VLAN ID. A dynamic entry is added in the bridge VLAN table for every P...
by sebastia
Tue Aug 20, 2019 9:40 pm
Forum: Beginner Basics
Topic: Routing traffic from specific src addresses through specific VPN gateways [SOLVED]
Replies: 4
Views: 3399

Re: Routing traffic from specific src addresses through specific VPN gateways [SOLVED]

Nice investiation - analysis - solution track. Congrats The answer to your question: when a connection is fasttrack-ed, some of it's packets are bypassing among others mangling, and in your case the special routing. The packets arriving at the destination are then discarded as coming from an unknown...
by sebastia
Tue Aug 20, 2019 12:55 pm
Forum: Scripting
Topic: Triggered execution? Interface up/down etc
Replies: 6
Views: 6500

Re: Triggered execution? Interface up/down etc

Hey

To my knowledge not directly. There is the netwatch, with up & down scripts, but it's no synchronous. It will not be triggered by event, but by (delayed) detection.
by sebastia
Tue Aug 20, 2019 12:52 pm
Forum: Beginner Basics
Topic: Routing traffic from specific src addresses through specific VPN gateways [SOLVED]
Replies: 4
Views: 3399

Re: Routing traffic from specific src addresses through specific VPN gateways [SOLVED]

Hey You should consider nat independent of routing: route decides how traffic should be forwarded, nat specifies if traffic leaving a particular interface should be changed. In your case: Routing /ip firewall mangle add action=mark-connection chain=prerouting connection-mark=no-mark ... passthrough=...
by sebastia
Mon Aug 19, 2019 11:46 pm
Forum: Beginner Basics
Topic: set Queue on ether2
Replies: 5
Views: 1832

Re: set Queue on ether2

please list your config: /export hide-sensitive
Also what do you want to limit? upload, download, both?
by sebastia
Sun Aug 18, 2019 1:08 am
Forum: Wireless Networking
Topic: LTE based internet and WiFi network at home
Replies: 11
Views: 4779

Re: LTE based internet and WiFi network at home

1. if you want to setup / test LTE AP, then yes you'll need a sim to get active LTE uplink 2. indeed 3. in short: it depends. strength of cell tower signal, interference (other users / towers) and quality of clients antenna, for transmissions in both directions. Wrt to wap lte, it's antenna doesn't ...
by sebastia
Fri Aug 16, 2019 7:40 pm
Forum: Wireless Networking
Topic: LTE based internet and WiFi network at home
Replies: 11
Views: 4779

Re: LTE based internet and WiFi network at home

Yes, all can. But if you specifically need wireless, have a look at wap lte kit.
by sebastia
Tue Aug 13, 2019 4:44 pm
Forum: General
Topic: VLAN or port isolation?
Replies: 18
Views: 13260

Re: VLAN or port isolation?

Yes it will be slower, if enabled.

But if you won't do vlan filtering on 4011 (= selective vlan bridging) that won't be a problem
by sebastia
Tue Aug 13, 2019 3:59 pm
Forum: General
Topic: VLAN or port isolation?
Replies: 18
Views: 13260

Re: VLAN or port isolation?

what do you mean by "Note that the 4011 doesn't doe vlan filtering in hardware."? It could make this any trouble? Or it's just for info?
If you enable "vlan-filtering=yes" on 4011, all vlans will need to pass over cpu. On CSS3xx it's in hardware.
by sebastia
Tue Aug 13, 2019 10:53 am
Forum: Beginner Basics
Topic: File download block?
Replies: 25
Views: 10268

Re: File download block?

With blocking of connection once a volume is reached one can block that connection, but the user can just resume the download with a new connection. So the net effect is slight delay. A more effective approach would be to slow down the connection once a volume has been reached: based on volume, assi...
by sebastia
Tue Aug 13, 2019 10:08 am
Forum: General
Topic: VLAN or port isolation?
Replies: 18
Views: 13260

Re: VLAN or port isolation?

Hi I would think that this will depend on the setting: are the networks / devices in these networks isolated or to they share same spaces port isolation might provide more guarantees from security point of view vlan are more flexible kind of port isolation dictates complexity of configuration: on ro...
by sebastia
Tue Aug 13, 2019 9:57 am
Forum: Beginner Basics
Topic: New to Mikrotik trying to setup portforwarding for letsencrypt nginx on unraid server
Replies: 26
Views: 10828

Re: New to Mikrotik trying to setup portforwarding for letsencrypt nginx on unraid server

Agreed with port number change, nat is needed.

@Sob: not sure what would brake with DNSSEC, as the internal dns server, as an authoritative server, would present internal records with own signatures.
by sebastia
Sun Aug 11, 2019 12:05 am
Forum: MikroTik hardware questions
Topic: Power consumption difference - CSS326 / CRS326
Replies: 1
Views: 1929

Re: Power consumption difference - CSS326 / CRS326

Hey
...to have an identical hardware...
This is NOT the case, switch chip are different and with different capabilities: nand, ram, cpu
by sebastia
Sat Aug 10, 2019 5:23 pm
Forum: Beginner Basics
Topic: New to Mikrotik trying to setup portforwarding for letsencrypt nginx on unraid server
Replies: 26
Views: 10828

Re: New to Mikrotik trying to setup portforwarding for letsencrypt nginx on unraid server

@2frogs Split DNS configuration is standard practice in networks with internal and external addressing. It is a proper solution if internal resources need to accessed. The alternative "hairpin" is abusing natting, as two NAT's are needed, first redirect to internal destination (dst-nat) th...
by sebastia
Sat Aug 10, 2019 1:51 pm
Forum: Beginner Basics
Topic: New to Mikrotik trying to setup portforwarding for letsencrypt nginx on unraid server
Replies: 26
Views: 10828

Re: New to Mikrotik trying to setup portforwarding for letsencrypt nginx on unraid server

Hey # You don't need these add action=accept chain=forward dst-port=80 in-interface=pppoe-out1 protocol=tcp add action=accept chain=forward dst-port=443 in-interface=pppoe-out1 protocol=tcp add action=accept chain=forward comment="Allow Port Forwarding - DSTNAT" connection-nat-state=dstnat...
by sebastia
Sat Aug 10, 2019 4:43 am
Forum: General
Topic: lease-hostname lease script variable not working
Replies: 10
Views: 5377

Re: lease-hostname lease script variable not working

hey, try $"lease-hostname" instead
by sebastia
Sat Aug 10, 2019 4:29 am
Forum: General
Topic: vlan and bridge forward traffic to wds interfaces
Replies: 5
Views: 2703

Re: vlan and bridge forward traffic to wds interfaces

Don't know about the other vlans, but 20 should be carried only over ether5 + cpu, so # only to cpu & ether5 /interface ethernet switch vlan add ports=ether5,switch1-cpu switch=switch1 vlan-id=20 # add cpu port info /interface ethernet switch port set switch1-cpu vlan-header=leave-as-is vlan-mod...
by sebastia
Thu Aug 08, 2019 11:10 pm
Forum: MikroTik hardware questions
Topic: RBSXTR&R11e-LTE + Back Up Link
Replies: 2
Views: 2016

Re: RBSXTR&R11e-LTE + Back Up Link

Hi

No, you'll need to do it (ex: with script) yourself.
by sebastia
Thu Aug 08, 2019 10:50 pm
Forum: MikroTik hardware questions
Topic: Switch stacking?
Replies: 9
Views: 20395

Re: Switch stacking?

And how about connecting switches over fast(er) trunk ports? Ex: connect 2 CRS326/CSS326 over their SFP+ port(s) and as such generate a 48 port switching plane?
by sebastia
Thu Aug 08, 2019 1:44 pm
Forum: MikroTik hardware questions
Topic: WAN to LAN performance clarity sought...
Replies: 1
Views: 1778

Re: WAN to LAN performance clarity sought...

4011 + rack = 1100AHx4
by sebastia
Wed Aug 07, 2019 3:56 pm
Forum: General
Topic: Routing between VLAN & VLAN+VPN
Replies: 4
Views: 2383

Re: Routing between VLAN & VLAN+VPN

to start with, move "accept establish & related" to top of forward chain -> stateful part of firewall so rules for forward should be: 1. accept established / related 2. drop invalid 3 (rest) In the rest you can then control from where connections are allowed: ex lan -> guest is allowed...
by sebastia
Wed Aug 07, 2019 3:49 pm
Forum: Beginner Basics
Topic: Basic questions about Queues [SOLVED]
Replies: 5
Views: 3047

Re: Basic questions about Queues [SOLVED]

For queues to make sense you need to have a global maximum, if there is non, each subqueue can borrow without limit, and there won't be any prioritisation. such queue tree needs to be attached to independent interface, ex wan, lan. This can be "naked" interface, etherX, or a bridge groupin...
by sebastia
Wed Aug 07, 2019 3:42 pm
Forum: General
Topic: Router - AP with WIFI guest on VLAN don't work
Replies: 4
Views: 1876

Re: Router - AP with WIFI guest on VLAN don't work

So how can i receive untagged traffic in the bridge (to use local LAN) ...? untagged of ether5 will just be "forwarded" to bridge and cpu So how can i receive ... and tagged traffic (vlan-20) out of the bridge ? tagged will be received by vlan on the bridge Todo: migrate vlan to bridge mi...
by sebastia
Wed Aug 07, 2019 3:30 pm
Forum: General
Topic: vlan and bridge forward traffic to wds interfaces
Replies: 5
Views: 2703

Re: vlan and bridge forward traffic to wds interfaces

Have a look at this thread for general info: viewtopic.php?f=13&t=143620
and this wiki for switch based: https://wiki.mikrotik.com/wiki/Manual:S ... p_Examples
by sebastia
Tue Aug 06, 2019 8:07 pm
Forum: Beginner Basics
Topic: default wan
Replies: 7
Views: 2382

Re: default wan

If you can do, then the gateway will be explicit / unique. Right now that's not the case. Otherwise qualify the interface that should be used: gateway="IP%interface"
by sebastia
Tue Aug 06, 2019 7:46 pm
Forum: General
Topic: [ROS/Firewall] How to MANGLE by raw HEX bytes ? [SOLVED]
Replies: 10
Views: 2913

Re: [ROS/Firewall] How to MANGLE by raw HEX bytes ?

Try this: content="\03abc\03com" Just tried, no working. Working fine here (from terminal): /ip firewall mangle add action=passthrough chain=prerouting content="cnn\03com" dst-port=53 in-interface=e1_int log=yes log-prefix="DNS catch: " \ protocol=udp "ping cnn.co...
by sebastia
Tue Aug 06, 2019 1:38 pm
Forum: General
Topic: [ROS/Firewall] How to MANGLE by raw HEX bytes ? [SOLVED]
Replies: 10
Views: 2913

Re: [ROS/Firewall] How to MANGLE by raw HEX bytes ?

Try this:
content="\03abc\03com"
by sebastia
Tue Aug 06, 2019 1:31 am
Forum: General
Topic: Router - AP with WIFI guest on VLAN don't work
Replies: 4
Views: 1876

Re: Router - AP with WIFI guest on VLAN don't work

Hello

wrt hac
ether5 participates in bridge (is a slave): it cant operate as an independent interface: not for ip address, vlan, firewall, ...

* hence the vlan should be defined on bridge.
* vlan ip should be assigned to "vlan-guest" interface
by sebastia
Tue Aug 06, 2019 1:17 am
Forum: Beginner Basics
Topic: how to set time limit to dhcp client
Replies: 3
Views: 3636

Re: how to set time limit to dhcp client

Hey

If I got your question right, it's the "lease-time": duration of ip assignment.
by sebastia
Tue Aug 06, 2019 1:08 am
Forum: Wireless Networking
Topic: Bondig WIFI links 60G and 5G
Replies: 15
Views: 5236

Re: Bondig WIFI links 60G and 5G

Hoi

What kind of throughput do you get over the links?
by sebastia
Tue Aug 06, 2019 1:00 am
Forum: General
Topic: Routing between VLAN & VLAN+VPN
Replies: 4
Views: 2383

Re: Routing between VLAN & VLAN+VPN

Hey You're firewall rules: * add action=reject chain=forward comment="Reject HOME from GUEST" dst-address=192.168.5.0/24 reject-with=icmp-host-prohibited src-address=192.168.20.0/24 add action=reject chain=forward comment="Reject MGMT from GUEST" connection-state=new dst-address=...
by sebastia
Tue Aug 06, 2019 12:50 am
Forum: General
Topic: vlan and bridge forward traffic to wds interfaces
Replies: 5
Views: 2703

Re: vlan and bridge forward traffic to wds interfaces

Hey your vlan20 is "hosted" by bridge1, with all of it's interfaces. So any traffic over ether5 / vlan20 will be propagated to all possible participants. The config seems to be pre 6.41, right? Upgrade to post 6.41+ and depending on switch chip capabilities use brdige vlan or switch vlan f...
by sebastia
Tue Aug 06, 2019 12:29 am
Forum: Beginner Basics
Topic: PLEASE HELP - no luck getting it to work / CCR1009-7G-1C-1S+ [SOLVED]
Replies: 24
Views: 6722

Re: 10 hours - no luck getting WAN/INET to work (CCR1009-7G-1C-1S+) [SOLVED]

You don't seem to be very good at hiding addresses. ;)
lol
by sebastia
Tue Aug 06, 2019 12:22 am
Forum: General
Topic: interactive TV (Tet) over local network, picture "slideshow" [SOLVED]
Replies: 12
Views: 3925

Re: interactive TV (Tet) over local network, picture "slideshow" [SOLVED]

Hoi

The network is unclear, could you post a diagram?
by sebastia
Mon Aug 05, 2019 11:50 pm
Forum: MikroTik hardware questions
Topic: Router Issues
Replies: 1
Views: 1512

Re: Router Issues

Hey

Do you have access to it's management functionality? If you do, run "/export hide-sensitive" and paste it here between < code > code goes here </ code > tags.
by sebastia
Mon Aug 05, 2019 11:41 pm
Forum: Beginner Basics
Topic: default wan
Replies: 7
Views: 2382

Re: default wan

Hey, the recursive routing paths, map to same gateway .1.1
by sebastia
Sun Aug 04, 2019 2:07 am
Forum: General
Topic: Getting trouble while creating VLANs and bonding interface between an RB3011 and CRS328
Replies: 4
Views: 2577

Re: Getting trouble while creating VLANs and bonding interface between an RB3011 and CRS328

* proxy-arp, I don't remember when and why I activated this, could it be because of VPN or mDNS ? should I remove it ? * Ok that's what I tough, but that weren't mentioned in the how-to linked above. Will try a different config with this. * I followed the how-to above, and it adds bond to the bridg...
by sebastia
Sun Aug 04, 2019 1:08 am
Forum: General
Topic: Getting trouble while creating VLANs and bonding interface between an RB3011 and CRS328
Replies: 4
Views: 2577

Re: Getting trouble while creating VLANs and bonding interface between an RB3011 and CRS328

Hey There is an extensive vlan how-to on this forum, have a look. (https://forum.mikrotik.com/viewtopic.php?f=13&t=143620&hilit=vlan) Some remarks: * why need for proxy-arp on bridge? * vlan-filtering=yes (on non-CRS3xx hardware) is in software, if you want it hardware, you'll need to do it ...
by sebastia
Sun Aug 04, 2019 12:48 am
Forum: Beginner Basics
Topic: Multiple web addresses Behind router.
Replies: 3
Views: 3272

Re: Multiple web addresses Behind router.

Hey

firewall is ip based, not domain.

What you want to do is normally done on the webserver itself, as the requested domain is part of the request.
by sebastia
Sat Aug 03, 2019 8:24 pm
Forum: General
Topic: Transparent NAT
Replies: 5
Views: 2188

Re: Transparent NAT

Need NAT + LTE not enough for NAT -> NAT somewhere else -> pass-through is the ONLY option
  • 1
  • 2
  • 3
  • 4
  • 5
  • 7