Community discussions

Search found 540 matches

  • 1
  • 2
by 2frogs
Fri Sep 20, 2019 9:30 am
Forum: Beginner Basics
Topic: WAN's seem happy, but no Internet Access
Replies: 2
Views: 358

Re: WAN's seem happy, but no Internet Access

/ip firewall filter
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
    connection-state=established,related
You will need to disable fasttrack as it will break mangle rules.
by 2frogs
Fri Sep 20, 2019 9:06 am
Forum: Beginner Basics
Topic: Trouble Forwarding Ports [SOLVED]
Replies: 2
Views: 371

Re: Trouble Forwarding Ports [SOLVED]

Have you set the cable modem to forward the ports to the mikrotik? I see references to a 192.168.1.1 address in a couple of locations that I am assuming is your cable router. If your mikrotik is getting DHCP from 192.168.1.1 and has an 192.168.1.xxx IP, you will have to forward those ports on the ca...
by 2frogs
Fri Sep 20, 2019 8:36 am
Forum: Beginner Basics
Topic: Setup VPN with Mikrotik
Replies: 6
Views: 910

Re: Setup VPN with Mikrotik

add action=accept chain=input dst-port=1723 comment="accept PPTP" protocol=tcp This needs to go either above or below the "defcon: accept ICMP" because the order matters. Also, chain=input is for any thing going to the router itself. And chain=forward is anything being forwarded by the router (WAN ...
by 2frogs
Fri Sep 20, 2019 8:07 am
Forum: Beginner Basics
Topic: Licensing question, demo
Replies: 2
Views: 361

Re: Licensing question, demo

https://wiki.mikrotik.com/wiki/Manual:License https://wiki.mikrotik.com/wiki/Manual:CHR#Free_licenses In short the x86 version has a 24hr demo (level 0) or a very limited demo (level 1.) The CHR has a free version, limited to 1mpbs/interface. Or 60 day trial mode for any CHR License Levels (P1, P10,...
by 2frogs
Fri Sep 20, 2019 7:49 am
Forum: Forwarding Protocols
Topic: Port forwarding dynamic IP [SOLVED]
Replies: 3
Views: 509

Re: Port forwarding dynamic IP [SOLVED]

/ip firewall nat add chain=dstnat dst-address=!192.168.88.1 dst-port=80 protocol=tcp dst-address-type=local to-address=192.168.88.253 You can enable the DDNS under IP>Cloud and use the DDNS to access the device. You could also use the DDNS to do the dstnat: /ip firewall address-list add address=you...
by 2frogs
Sun Sep 15, 2019 1:22 am
Forum: Wireless Networking
Topic: wireless bridge problems
Replies: 2
Views: 500

Re: wireless bridge problems

On the RBMetal, change mode=bridge to mode=ap-bridge, mode=bridge only allows 1 connected client. /interface wireless set [ find default-name=wlan1 ] band=5ghz-a/n channel-width=20/40mhz-Ce \ disabled=no hide-ssid=yes mode=ap-bridge security-profile=profile1 ssid=\ <SSID HERE> wps-mode=disabled
by 2frogs
Tue Sep 10, 2019 6:04 am
Forum: Wireless Networking
Topic: Bit confused by the existence of the hAP AC Lite?
Replies: 15
Views: 1381

Re: Bit confused by the existence of the hAP AC Lite?

One use case would be vdsl2 areas where the 2.4ghz bands are overcrowded and all but unusable. Another would be for wireless internet providers that use 2.4ghz bands to distribute internet, they can provide a router they can set to not interfere with the channel they are using to connect that client.
by 2frogs
Sat Sep 07, 2019 4:40 pm
Forum: Beginner Basics
Topic: Somehow im blind
Replies: 5
Views: 753

Re: Somehow im blind

First issue is that the LAN IP address should be on the bridge interface since it is the master and ether2 is slaved to it.

Second, is that your NAT rule has your IP scope on src-address-list instead of src-address. You could define an address-list and use that instead.
by 2frogs
Tue Sep 03, 2019 5:14 am
Forum: Wireless Networking
Topic: Hotspot woes, users having to keep signing in
Replies: 1
Views: 293

Re: Hotspot woes, users having to keep signing in

Usually seeing the same MAC with multiple IPs is caused from having a pool set in the hotspot or from having dhcp lease times set too short. Setting a IP pool in the hotspot will create a 1:1 NAT for devices that have a static IP. And sometimes it will NAT devices that received a IP from the dhcp se...
by 2frogs
Sat Aug 17, 2019 4:34 am
Forum: Beginner Basics
Topic: can only get a dynamic ip on bridge interface
Replies: 10
Views: 885

Re: can only get a dynamic ip on bridge interface

If you plug your computer into the cable that is on ether1, does it get an IP address. If it does, make sure it is not in the same range as your router (ie 192.168.88.0/24). I don't see anything in config that would prevent it from obtaining an IP.
by 2frogs
Thu Aug 15, 2019 9:41 pm
Forum: Beginner Basics
Topic: New to Mikrotik trying to setup portforwarding for letsencrypt nginx on unraid server
Replies: 26
Views: 2678

Re: New to Mikrotik trying to setup portforwarding for letsencrypt nginx on unraid server

On CRS, navigate to IP>Addresses. Or
/ip address remove [find address="192.168.88.1/24"]
The address is most likely a left-over from the default config.
by 2frogs
Thu Aug 15, 2019 7:08 pm
Forum: Beginner Basics
Topic: New to Mikrotik trying to setup portforwarding for letsencrypt nginx on unraid server
Replies: 26
Views: 2678

Re: New to Mikrotik trying to setup portforwarding for letsencrypt nginx on unraid server

Since you have a dhcp-client on bridge, just remove the 192.168.88.1/24 address
by 2frogs
Thu Aug 15, 2019 3:08 pm
Forum: Beginner Basics
Topic: New to Mikrotik trying to setup portforwarding for letsencrypt nginx on unraid server
Replies: 26
Views: 2678

Re: New to Mikrotik trying to setup portforwarding for letsencrypt nginx on unraid server

Change: add action=masquerade chain=srcnat comment=LetsencrypLocal dst-address=192.168.88.254 \ dst-port=180,1443 protocol=tcp to add action=masquerade chain=srcnat comment=Hairpin NAT dst-address=192.168.88.0/24 src-address=192.168.88.0/24 as SOB suggested as it is universal. Do you have any static...
by 2frogs
Wed Aug 14, 2019 6:03 pm
Forum: Beginner Basics
Topic: New to Mikrotik trying to setup portforwarding for letsencrypt nginx on unraid server
Replies: 26
Views: 2678

Re: New to Mikrotik trying to setup portforwarding for letsencrypt nginx on unraid server

And you have flushed dns on your device?
What is doing or not doing?
Can you provide:
/ip firewall nat export
by 2frogs
Mon Aug 12, 2019 9:02 pm
Forum: General
Topic: Simple Queue not working unless torch is running
Replies: 2
Views: 384

Re: Simple Queue not working unless torch is running

Try disabling the fast-track firewall rules.
by 2frogs
Sun Aug 11, 2019 5:44 am
Forum: Beginner Basics
Topic: New to Mikrotik trying to setup portforwarding for letsencrypt nginx on unraid server
Replies: 26
Views: 2678

Re: New to Mikrotik trying to setup portforwarding for letsencrypt nginx on unraid server

@sebastia

I believe you missed that the server is on ports 180 & 1443. Static DNS entries will not work in this case as it points to ports 80 & 443.
by 2frogs
Sat Aug 10, 2019 3:21 pm
Forum: Beginner Basics
Topic: New to Mikrotik trying to setup portforwarding for letsencrypt nginx on unraid server
Replies: 26
Views: 2678

Re: New to Mikrotik trying to setup portforwarding for letsencrypt nginx on unraid server

Instead of the DNS trick, try correcting your dst-nat rules. If you have a static IP: /ip firewall nat add action=dst-nat chain=dstnat comment=Letsencrypt dst-port=80 dst-address=your.external.ip.address protocol=tcp to-addresses=192.168.88.245 to-ports=180 add action=dst-nat chain=dstnat comment=Le...
by 2frogs
Thu Aug 08, 2019 9:10 pm
Forum: Beginner Basics
Topic: wifi speed - 2 clients only
Replies: 2
Views: 443

Re: wifi speed - 2 clients only

What you are seeing is normal. The data rate is the combined theoretically possible rate for upload and download. Since the AP and Client can only send or receive and do so to a single device at a time it will half the data rate. And as you noticed, if you connect a second device and try to download...
by 2frogs
Thu Aug 08, 2019 4:28 pm
Forum: Beginner Basics
Topic: MikroTik wAP as wireless client?
Replies: 4
Views: 995

Re: MikroTik wAP as wireless client?

The best way to set it up is to use Winbox to reset without default and configure it manually. Once you have reset the wAP, you will have to connect to it using it MAC Address. Now you can setup a bridge and add ether1 and wlan1 to it. And now configure wlan1 to be a station with the proper SSID and...
by 2frogs
Thu Aug 08, 2019 7:45 am
Forum: Wireless Networking
Topic: Hotspot Mikrotik Customization
Replies: 2
Views: 501

Re: Hotspot Mikrotik Customization

The Hotspot Trial user is perfect for what you want. You can edit the default login.html to remove the login box and use the trial user link as the "click here" to agree. https://wiki.mikrotik.com/wiki/Manual:Hotspot_Introduction https://wiki.mikrotik.com/wiki/Manual:IP/Hotspot https://wiki.mikrotik...
by 2frogs
Thu Aug 08, 2019 7:30 am
Forum: Scripting
Topic: Failover script to call another script
Replies: 1
Views: 336

Re: Failover script to call another script

So if you put these in terminal they run, but not from the script? /system script run firewall-to-backup /system script run firewall-to-main You could also change from using in/out-interface to interface-list and not have to change the firewall rules at all: /interface list add comment=defconf name=...
by 2frogs
Thu Aug 08, 2019 6:33 am
Forum: Beginner Basics
Topic: simultaneous user logins
Replies: 2
Views: 466

Re: simultaneous user logins

/tool user-manager user set [find shared-users=unlimited] shared-users=1
by 2frogs
Thu Aug 01, 2019 6:35 am
Forum: General
Topic: Very simple VLAN
Replies: 16
Views: 1453

Re: Very simple VLAN

You mentioned untagging/tagging is why I suggested a bridge. But yes, you can put the IP and DHCP Server directly on vlan1. And you can then remove the bridge port for vlan1 as it is not needed.
by 2frogs
Thu Aug 01, 2019 5:16 am
Forum: Beginner Basics
Topic: VPN problem between local LAN and VPN clients
Replies: 3
Views: 557

Re: VPN problem between local LAN and VPN clients

Do you have a static route to your LAN set on the Synology and a static route to the Synology from the Router?
by 2frogs
Thu Aug 01, 2019 4:59 am
Forum: General
Topic: Very simple VLAN
Replies: 16
Views: 1453

Re: Very simple VLAN

I believe you need to create a new bridge for the vlan and add IP and DHCP Server to the new bridge. Then change the bridge port for vlan1 to the new bridge. /interface bridge add name=vlan1-bridge /interface bridge port add bridge=vlan1-bridge interface=vlan1 The rest of your config should remain t...
by 2frogs
Wed Jul 31, 2019 4:30 pm
Forum: Wireless Networking
Topic: Help with a wireless backbone
Replies: 3
Views: 616

Re: Help with a wireless backbone

You will need to use vlans, but having two networks in both buildings should not be a problem. There are many tutorials and examples on this forum and elsewhere. You will need a clan capable switch. Or if you only need a few ports and it is indoors you can use something like an hAP-AC/hAP-AC2 and br...
by 2frogs
Wed Jul 31, 2019 2:33 am
Forum: Wireless Networking
Topic: Help with a wireless backbone
Replies: 3
Views: 616

Re: Help with a wireless backbone

I would use the Wireless Wire to bridge the buildings as it can provide wire speeds.
by 2frogs
Tue Jul 30, 2019 5:35 am
Forum: General
Topic: Mikrotik Mobile App [SOLVED]
Replies: 2
Views: 482

Re: Mikrotik Mobile App [SOLVED]

The app uses the Winbox port to connect. You can specify the correct port in the address field of app like; 192.168.88.1:1234
by 2frogs
Fri Jul 26, 2019 2:23 pm
Forum: Wireless Networking
Topic: Faile to add queue
Replies: 1
Views: 285

Re: Faile to add queue

From Terminal run this command:
/export hide-sensitive file=export
Download and edit the export.rsc using a text editor to remove any public ips or identifying information and paste using the code wrapper [ code][ /code].
by 2frogs
Fri Jul 26, 2019 2:11 pm
Forum: General
Topic: Ovpn server on separate pool cannot reach lan
Replies: 4
Views: 404

Re: Ovpn server on separate pool cannot reach lan

Try adding this to the top of your mangle rules:
/ip firewall mangle
add action=accept chain=prerouting dst-address=10.255.255.0/24 in-interface=bridge
I believe your rules are too loose and catching any traffic from your LAN to VPN IP ranges.
by 2frogs
Thu Jul 25, 2019 7:35 am
Forum: General
Topic: Need to set up access to NAS openvpn
Replies: 45
Views: 2729

Re: Need to set up access to NAS openvpn

Thought I would let you know that L2TP/IPSec is not any better. I have a TS-431XeU with AnnapurnaLabs Alpine AL-314 32-bit ARM® Cortex-A15 quad-core 1.7GHz processor and 10-11MB/s is all it will do at 40% CPU usage. QVPN represents only 10% CPU usage.
by 2frogs
Tue Jul 23, 2019 12:15 am
Forum: Wireless Networking
Topic: 6 x 60G AP Sectors Area Configuration Thread
Replies: 5
Views: 639

Re: 6 x 60G AP Sectors Area Configuration Thread

Separation will do wonders too. Both horizontal and vertical. Any radio device back to back on a mast is usually a bad idea. 2-3 meters vertically and 1 horizontal is about minimal in my opinion.
by 2frogs
Mon Jul 22, 2019 9:25 pm
Forum: General
Topic: Can't access Winbox from VPN - OpenVpn
Replies: 4
Views: 386

Re: Can't access Winbox from VPN - OpenVpn

/ip firewall filter 
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
This rule, since no interfaces are listed and it is above the drop rule (they are processed in order), allows pings from any where.
by 2frogs
Mon Jul 22, 2019 9:02 pm
Forum: General
Topic: Can't access Winbox from VPN - OpenVpn
Replies: 4
Views: 386

Re: Can't access Winbox from VPN - OpenVpn

This rule is blocking access: /ip firewall filter add action=drop chain=input comment="defconf: drop all not coming from LAN" \ in-interface-list=!LAN Your VPN is not included in interface-list. You can add it under /ppp profiles: /ppp profile add local-address=192.168.1.1 name=Ovpn-profile remote-a...
by 2frogs
Sat Jul 20, 2019 3:52 am
Forum: Beginner Basics
Topic: RBwAPG-60ad IP Settings
Replies: 1
Views: 408

Re: RBwAPG-60ad IP Settings

The bridge is the correct place for the dhcp-client as it is the master interface. It looks like the quick-set is broken, but since it is based off of simple scripts it is limited in functionality and should not be used passed initial setup anyway.
by 2frogs
Sat Jul 20, 2019 3:05 am
Forum: Scripting
Topic: am i missing something???
Replies: 2
Views: 538

Re: am i missing something???

:if ([:len [/ip ipsec policy find dst-address=10.0.0.0/16]]=0) do={:put "Not Found" } else={:put "Found"} Or :if ([:len [/ip ipsec policy find dst-address=10.0.0.0/16]]>0) do={:put "Found"} el se={:put "Not Found"} A missing value is not 0, it is null and ROS scripts can't handle nulls. But you can...
by 2frogs
Fri Jul 19, 2019 4:13 am
Forum: General
Topic: hair pin when out interface has different address
Replies: 8
Views: 606

Re: hair pin when out interface has different address

I am sorry, I either miss read your original setup or confused it with another. You don't even need the ddns hack. Use dst-address=192.168.1.252. /ip firewall nat add chain=srcnat action=src-nat protocol=tcp src-address=10.0.1.0/24 dst-address=192.168.1.252 to-address=10.0.1.1 out-interface=bridge d...
by 2frogs
Thu Jul 18, 2019 8:13 pm
Forum: General
Topic: hair pin when out interface has different address
Replies: 8
Views: 606

Re: hair pin when out interface has different address

Yes, you can use the DDNS you already have setup.
by 2frogs
Wed Jul 17, 2019 8:18 pm
Forum: General
Topic: hair pin when out interface has different address
Replies: 8
Views: 606

Re: hair pin when out interface has different address

On your 10.0.1.1, enable the built in DDNS. Now add your DDNS URL to an address-list with a name like My_IP. You now use dst-address-list in place of dst-address in the hair-pin nat tutorials.

You can also use the DDNS URL to access your server without having to know your current IP.
by 2frogs
Wed Jul 17, 2019 2:13 pm
Forum: General
Topic: A difficault question about CLI [SOLVED]
Replies: 3
Views: 433

Re: A difficault question about CLI [SOLVED]

In Terminal, the [TAB] key can be your friend! :)

It can auto complete command and list: directories, commands and variables
by 2frogs
Tue Jul 16, 2019 3:23 pm
Forum: Beginner Basics
Topic: connection state question [SOLVED]
Replies: 13
Views: 1110

Re: connection state question [SOLVED]

Correct! It is already accepted!
by 2frogs
Tue Jul 16, 2019 2:42 pm
Forum: Beginner Basics
Topic: connection state question [SOLVED]
Replies: 13
Views: 1110

Re: connection state question [SOLVED]

The default for the firewall filter is to accept. If you remove all rules, everything would be accepted. If you only add chain=forward action=drop, then all being forwarded would be dropped. Now change that rule to include in-interface=ether1 and now only forwards coming from ether1 are being droppe...
by 2frogs
Tue Jul 16, 2019 2:21 pm
Forum: General
Topic: A difficault question about CLI [SOLVED]
Replies: 3
Views: 433

Re: A difficault question about CLI [SOLVED]

unset
/ip firewall nat unset [find action=masquerade] out-interface
by 2frogs
Tue Jul 16, 2019 3:33 am
Forum: General
Topic: Redirecting Problems [SOLVED]
Replies: 3
Views: 460

Re: Redirecting Problems [SOLVED]

That is correct, you need both rules.
by 2frogs
Mon Jul 15, 2019 3:02 am
Forum: General
Topic: Port Forwarding Not Working but Shows Packets
Replies: 11
Views: 900

Re: Port Forwarding Not Working but Shows Packets

@anav
hmm, so glad we can agree it could be done with a single rule:
"And your Filter rule need to be for chain=forward: (or enable the default drop rule)"
by 2frogs
Sat Jul 13, 2019 11:45 pm
Forum: General
Topic: Mikrotik Web Interface not accesible via VPN on remote router
Replies: 5
Views: 665

Re: Mikrotik Web Interface not accesible via VPN on remote router

Or add script to ppp profile to add/remove the interface when you login/logout: on-up=/interface list member add list="LAN" interface=[/interface get [find type=l2tp-in && dynamic=yes] name] on-down=/interface list member remove [find interface!="bridge" && list="LAN"] Or you can also set l2tp serve...
by 2frogs
Sat Jul 13, 2019 4:28 am
Forum: General
Topic: Redirecting Problems [SOLVED]
Replies: 3
Views: 460

Re: Redirecting Problems [SOLVED]

You also need a src-nat:
/ip firewall nat
add action=src-nat chain=srcnat src-address=192.168.0.0/24 dst-address=192.168.0.4 to-address=192.168.0.1
by 2frogs
Sat Jul 13, 2019 1:46 am
Forum: Wireless Networking
Topic: Can I use NV2 and "normal" Wifi on the same device?
Replies: 4
Views: 541

Re: Can I use NV2 and "normal" Wifi on the same device?

The Wireless Wire is basically 2 WAP 60G AP, just pre-configured as PtP pair (they can be reconfigured). They have a 60 degree beam width, so depending on the lay out it could cover your end points. There is also a WAP 60Gx3 AP that can cover 180 degrees.
https://mikrotik.com/product/wap_60gx3_ap
by 2frogs
Fri Jul 12, 2019 9:25 pm
Forum: Wireless Networking
Topic: Can I use NV2 and "normal" Wifi on the same device?
Replies: 4
Views: 541

Re: Can I use NV2 and "normal" Wifi on the same device?

You can not use 802.11 and NV2 at same time. A dedicated point to point or point to multi-point would be better than trying to use an AP that has other wireless users on it. Have you seen: https://mikrotik.com/product/wap_60g_ap https://mikrotik.com/product/wireless_wire These should be able to conn...
by 2frogs
Fri Jul 12, 2019 9:09 pm
Forum: General
Topic: Port Forwarding Not Working but Shows Packets
Replies: 11
Views: 900

Re: Port Forwarding Not Working but Shows Packets

Your NAT rules do not need a to-port unless your are changing ports. They should look like this: /ip firewall nat add action=dst-nat chain=dstnat comment="ALA USG VPN" dst-port=500 in-interface=ether1-gateway log=yes protocol=udp to-addresses=10.0.1.89 add action=dst-nat chain=dstnat comment="ALA US...
by 2frogs
Fri Jul 12, 2019 8:24 pm
Forum: General
Topic: Mikrotik Web Interface not accesible via VPN on remote router
Replies: 5
Views: 665

Re: Mikrotik Web Interface not accesible via VPN on remote router

There are actually major differences between the 2 routers when you consider the firewall rules. On Router 1, the default drop for input is dropping all from ether1, which is your WAN. By default it is accepting from all other ports including all other ethers, wlans, bridges, l2tp ,etc. /ip firewall...
by 2frogs
Fri Jul 12, 2019 6:35 pm
Forum: Beginner Basics
Topic: Log File [SOLVED]
Replies: 4
Views: 666

Re: Log File [SOLVED]

Yes
/log print file=log.txt
A remote syslog might b a better option depending on intended use.
https://wiki.mikrotik.com/wiki/Manual:System/Log
by 2frogs
Wed Jul 10, 2019 11:18 pm
Forum: General
Topic: Very high sector writes
Replies: 24
Views: 1396

Re: Very high sector writes

Most likely a partially failed update or some corruption in OS.
by 2frogs
Wed Jul 10, 2019 5:38 am
Forum: General
Topic: Help with IP-> Filter needed
Replies: 2
Views: 274

Re: Help with IP-> Filter needed

Create a address-list name=payment_gateway and add www.some.paymentsystem.com and dns ip to it.
Now add dst-address-list!=payment_gateway to both of your rules. The "!" means "not".

This should work for http, but I don't think it will for https...
by 2frogs
Wed Jul 10, 2019 3:05 am
Forum: Beginner Basics
Topic: Scripting distance of routes [SOLVED]
Replies: 8
Views: 791

Re: Scripting distance of routes [SOLVED]

Is x.x.x.x a unique ID or do you have multiple with gateway=x.x.x.x? Copy and paste the following in Terminal: /ip route add dst-address=1.2.3.4/32 gateway=1.2.3.4 distance=5; :if ([/ip route get [find gateway=1.2.3.4] distance]=5) do={:put "True"} else={:put "False"}; ##Should have output of "True"...
by 2frogs
Tue Jul 09, 2019 7:45 pm
Forum: Beginner Basics
Topic: Scripting distance of routes [SOLVED]
Replies: 8
Views: 791

Re: Scripting distance of routes [SOLVED]

Spacing maybe!?!? This works for me:
:if ([/ip route [find gateway=x.x.x.x] distance]=2) do={:log error “True”}
by 2frogs
Sat Jul 06, 2019 3:25 am
Forum: General
Topic: Very high sector writes
Replies: 24
Views: 1396

Re: Very high sector writes

/system logging
add topics=debug
Have tried disabling this?
by 2frogs
Thu Jul 04, 2019 3:48 am
Forum: Scripting
Topic: Script to disable Wlan when no user are logged on
Replies: 8
Views: 876

Re: Script to disable Wlan when no user are logged on

No, no, no. The WLAN will automatically turn on as soon as someone connects to it. It's so obvious. OK! :mrgreen: /system scheduler add interval=10m name=wlan1-auto-on/off on-event=":if ([/interface wireless get wlan1 disabled]=yes) do={\r\ \n:log info \"Checking for Wireless Users\"\r\ \n; /interf...
by 2frogs
Sun Jun 30, 2019 6:07 pm
Forum: Wireless Networking
Topic: Hotspot without pass
Replies: 1
Views: 511

Re: Hotspot without pass

Use Hotspot with Trial User enabled. You can set your limits by time and/or data and have it reset after a defined period. Now edit/replace login.html the following code and users will be logged in automatically. <!DOCTYPE html> <html> <head> <meta http-equiv="refresh" content="0; url=$(link-login-o...
by 2frogs
Fri Jun 28, 2019 12:10 am
Forum: Wireless Networking
Topic: Gateway for AP-Bridge, no DHCP
Replies: 2
Views: 606

Re: Gateway for AP-Bridge, no DHCP

With all ports bridged it does not need a gateway for the clients. It acts like a switch and passes connection through it. It does need a default route for the router itself to connect to the internet. Adding one would allow your NTP Client to work. Should look something like: /ip route add dst-addr...
by 2frogs
Thu Jun 27, 2019 7:25 am
Forum: Beginner Basics
Topic: Simulation two WAN with one ISP
Replies: 4
Views: 721

Re: Simulation two WAN with one ISP

Use Virtual Machine software (I use VirtualBox) to setup 2 Virtual CHR's. You need 2 virtual ethernet interfaces for each. They need minimal setup: ##Gateway1 /ip address add address=192.168.100.1/24 interface=ether2 network=192.168.100.0 /ip dhcp-client add disabled=no interface=ether1 /ip firewall...
by 2frogs
Wed Jun 26, 2019 4:12 pm
Forum: General
Topic: Best Way to Isolate Bridges to Reach Each Other's IPs
Replies: 26
Views: 1492

Re: Best Way to Isolate Bridges to Reach Each Other's IPs

If you are using the default firewall rules, you could change the default forward drop rule to: /ip firewall filter add chain=forward connection-nat-state=dstnat in-interface=WAN action=accept add chain=forward out-interface=!WAN action=drop And if you are not doing DST-NAT or UPNP, you can omit the...
by 2frogs
Wed Jun 26, 2019 4:10 pm
Forum: General
Topic: Best Way to Isolate Bridges to Reach Each Other's IPs
Replies: 26
Views: 1492

Re: Best Way to Isolate Bridges to Reach Each Other's IPs

Edit: post duplicated.
by 2frogs
Wed Jun 12, 2019 8:23 pm
Forum: Beginner Basics
Topic: set up second WAN/ISP temporarily
Replies: 8
Views: 584

Re: set up second WAN/ISP temporarily

Here is the correct code: /ip firewall mangle add action=mark-connection chain=forward comment="ISP1-In" in-interface=ether1 new-connection-mark="ISP1-In" add action=mark-connection chain=forward comment="ISP2-In" in-interface=ether2 new-connection-mark="ISP2-In" add action=mark-routing chain=prerou...
by 2frogs
Wed Jun 12, 2019 3:07 pm
Forum: Beginner Basics
Topic: set up second WAN/ISP temporarily
Replies: 8
Views: 584

Re: set up second WAN/ISP temporarily

Oops, I copy/paste wrong section of code. Correct it as @sebastia stated. Sorry for my mistakes!
by 2frogs
Wed Jun 12, 2019 6:58 am
Forum: Beginner Basics
Topic: RBwAPG-60ad distance =0.0 ?
Replies: 10
Views: 704

Re: RBwAPG-60ad distance =0.0 ?

One device has metal casing to give more focus.
So, have you tried without the metal casing?
by 2frogs
Wed Jun 12, 2019 6:53 am
Forum: Scripting
Topic: Script to disable Wlan when no user are logged on
Replies: 8
Views: 876

Re: Script to disable Wlan when no user are logged on

Put this in scheduler:
:if ( [ :len [/interface wireless registration find] ] <= 0 ) do={ /interface wireless disable wlan1; :log info "No Wireless Users - Wireless Disabled";}
by 2frogs
Wed Jun 12, 2019 6:02 am
Forum: General
Topic: Make Hotspot Usernames for different APs
Replies: 3
Views: 238

Re: Make Hotspot Usernames for different APs

You will need to put the LAN and all 3 AP's on separate VLAN's. Then create a Hotspot Server for each VLAN. Then on each Username, you can specify which Server that Username is for.
by 2frogs
Wed Jun 12, 2019 3:31 am
Forum: Beginner Basics
Topic: set up second WAN/ISP temporarily
Replies: 8
Views: 584

Re: set up second WAN/ISP temporarily

You need to mark connections coming in to each WAN and then make routing mark based on those connections: /ip firewall mangle add action=mark-connection chain=input comment="ISP1-In" in-interface=ether1 new-connection-mark="ISP1-In" add action=mark-connection chain=input comment="ISP2-In" in-interfa...
by 2frogs
Tue Jun 11, 2019 8:03 pm
Forum: Beginner Basics
Topic: Block acces to a New router
Replies: 2
Views: 330

Re: Block acces to a New router

Use Winbox to connect using MAC Address. Most likely the default firewall rules is blocking IP access.
by 2frogs
Wed Jun 05, 2019 2:55 am
Forum: Wireless Networking
Topic: AP and 2 repeaters in one line [SOLVED]
Replies: 2
Views: 472

Re: AP and 2 repeaters in one line [SOLVED]

Add the MAC of the other Basebox in /interface wireless access-list with forward=no and authentication=no. Do this on both.
by 2frogs
Sun Jun 02, 2019 4:51 am
Forum: Wireless Networking
Topic: LHG 60GHz Wireless Wire [SOLVED]
Replies: 3
Views: 500

Re: LHG 60GHz Wireless Wire [SOLVED]

I made the same mistake and tried to reconfigure them as you did. I ended up having to reset to default and swapping the units. I wonder if the slave in the set is only capable of being CPE.
by 2frogs
Tue May 28, 2019 6:49 pm
Forum: Beginner Basics
Topic: crs125-24g-1s-2hnd 100% cpu load when i am doing speedtest
Replies: 6
Views: 542

Re: crs125-24g-1s-2hnd 100% cpu load when i am doing speedtest

See the comment in the speedtest result as shown in your screenshots. CRS devices are intended to be used as hardware switches - they can do some routing and provide some services but the as CPU is not powerful you cannot use them to do wirespeed routing, for example. In my case, i ma talking about...
by 2frogs
Tue May 28, 2019 4:38 am
Forum: Beginner Basics
Topic: Hacker trying to log in - firewall default
Replies: 4
Views: 475

Re: Hacker trying to log in - firewall default

That is correct, although you do not need the forward rule because your default forward drop rule drops all forwarded traffic unless it is in dst-nat: /ip firewall filter add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new...
by 2frogs
Tue May 28, 2019 2:59 am
Forum: Beginner Basics
Topic: Hacker trying to log in - firewall default
Replies: 4
Views: 475

Re: Hacker trying to log in - firewall default

You do not have the default firewall. It should include the following: /ip firewall filter add action=accept chain=input connection-state=established,related,untracked comment="DEFAULT: Accept established, related, and untracked traffic." add action=drop chain=input connection-state=invalid comment=...
by 2frogs
Mon Apr 08, 2019 1:04 am
Forum: Wireless Networking
Topic: hAP ac^2 won't pass IPs
Replies: 8
Views: 632

Re: hAP ac^2 won't pass IPs

On both the hAP and wAP, use WISP AP from quickset after reset from no-default. After you configure the wireless, select Mode=Bridge, Address Acquisition=Automatic, Bridge All LAN Ports=yes and hit apply. After a couple seconds hit Apply again and it should now have IP from your RB3011. You can now ...
by 2frogs
Wed Apr 03, 2019 3:54 pm
Forum: Beginner Basics
Topic: How do I manage WISP AP via WebUI?
Replies: 6
Views: 710

Re: How do I manage WISP AP via WebUI?

I suspect the IP Address is not on the right interface. In winbox, ip>addresses, be sure that the IP is on interface=bridge (or the name of your bridge.)
by 2frogs
Thu Mar 28, 2019 3:14 am
Forum: Beginner Basics
Topic: Confused about VPN local IP
Replies: 2
Views: 306

Re: Confused about VPN local IP

Quickset sets up the VPN using a separate subnet (192.168.89.0/24) than the default (192.168.88.0/24). You change it to the IP and subnet of the router if you wish. It is not advisable to use Quickset past the initial setup, especially if changes where made outside of Quickset. It relies on a basic ...
by 2frogs
Wed Mar 27, 2019 4:47 am
Forum: General
Topic: Hotpot users
Replies: 7
Views: 423

Re: Hotpot users

No need to remove dhcp, but you will need to change:
ip/address
ip/pool
ip/dhcp-server/network

And any firewall, nat or mangle rules rules...
by 2frogs
Tue Mar 26, 2019 6:25 pm
Forum: General
Topic: Hotpot users
Replies: 7
Views: 423

Re: Hotpot users

Sorry, I misunderstood! There is no performance issues with leaving the device powered on. Some changes are better facilitated with restart. Changing the IP scope is one of them. But RouterOS boots fast, less than a minute even while upgrading firmware. And yes you can change IP to /16 if not alread...
by 2frogs
Tue Mar 26, 2019 12:27 pm
Forum: General
Topic: Hotpot users
Replies: 7
Views: 423

Re: Hotpot users

No, I have devices that are powered off daily when not in use. The only issue I have had is them being powered off while updating. This requires the Net Instal tool to recover.
by 2frogs
Tue Mar 26, 2019 3:32 am
Forum: General
Topic: Hotpot users
Replies: 7
Views: 423

Re: Hotpot users

keepalive-timeout=10m

Restarting the router will reset all hotspot user data and remove the mac-cookies. Otherwise, there are no issues with restarting or leaving it powered off for length of time.
by 2frogs
Mon Mar 25, 2019 10:12 pm
Forum: Beginner Basics
Topic: Output, postrouting or forward?
Replies: 3
Views: 300

Re: Output, postrouting or forward?

Input/Output rules are to/from the router itself. And generally, prerouting is used if a routing decision is to be made by he mangle rule. Most other rules will use forward.
by 2frogs
Mon Mar 25, 2019 9:34 pm
Forum: General
Topic: Hotspot uptime not updated when router is off
Replies: 1
Views: 177

Re: Hotspot uptime not updated when router is off

The data is stored in RAM and not DISK. This is why it is reset after each reboot. You can search for scripts to save the data to disk or use User Manager.
by 2frogs
Mon Mar 25, 2019 9:25 pm
Forum: Beginner Basics
Topic: Master interface
Replies: 1
Views: 249

Re: Master interface

You did not mention what Mikrotik device you are using, but some devices only have a Level 3 License and will only work as a Station (CPE) or wireless Bridge to a single device (PtP).
by 2frogs
Mon Mar 25, 2019 7:58 pm
Forum: General
Topic: wAP AC reaching out to 159.148.172.226:80 every hour
Replies: 10
Views: 753

Re: wAP AC reaching out to 159.148.172.226:80 every hour

Does it have the Detect Internet set?
by 2frogs
Fri Mar 22, 2019 6:30 am
Forum: Beginner Basics
Topic: Can't connect to web interface internal
Replies: 10
Views: 593

Re: Can't connect to web interface internal

/ip firewall address-list add address=127.0.0.1 list=allow-ip /ip firewall filter add action=drop chain=input comment=\ "You can say thanks on the WebMoney Z399578297824" dst-port=\ 8778,8728,8729,22,23,80,443,8291 protocol=tcp src-address-list=blacklist add action=accept chain=input comment=\ "Ple...
by 2frogs
Thu Mar 21, 2019 10:30 pm
Forum: Beginner Basics
Topic: Can't connect to web interface internal
Replies: 10
Views: 593

Re: Can't connect to web interface internal

Use WinBox; https://download.mikrotik.com/routeros/ ... winbox.exe
In the Neighbors Tab, click on the MAC of the device and it will load in the Connect To field. Enter your credentials below it.
by 2frogs
Thu Mar 21, 2019 1:00 pm
Forum: Beginner Basics
Topic: Can't connect to web interface internal
Replies: 10
Views: 593

Re: Can't connect to web interface internal

IP>Services, this is where you enable/disable, set port # and can set IP's for access. If it is enabled there and your still not able to connect, you will need to check your firewall rules IP>Firewall>Filter to be sure access is not being blocked there. Provide /export if you need any further assist...
by 2frogs
Wed Mar 20, 2019 2:58 pm
Forum: Scripting
Topic: Sounding the beeper when a LAN device pings the router
Replies: 2
Views: 394

Re: Sounding the beeper when a LAN device pings the router

/ip firewall filter add action=accept chain=input comment=pingcatch in-interface-list=LAN log=yes \ log-prefix=Ping protocol=icmp /system scheduler add interval=1s name=pingbeep on-event=":global pingcont;\r\ \n:if ([:len \$pingcont]=>0) do={:set \$pingcont [/ip firewal filter ge nd comment=\"pingc...
by 2frogs
Sat Mar 16, 2019 5:35 pm
Forum: Wireless Networking
Topic: PoE vs Outlet power
Replies: 1
Views: 300

Re: PoE vs Outlet power

As long as your POE is providing the max power draw for each device, then there should be no difference between POE and Power Supply.
by 2frogs
Sat Mar 16, 2019 5:28 pm
Forum: General
Topic: Mangle rules
Replies: 4
Views: 346

Re: Mangle rules

by 2frogs
Tue Mar 12, 2019 4:16 pm
Forum: Scripting
Topic: How to really make backups (by script) ?
Replies: 15
Views: 961

Re: How to really make backups (by script) ?

Use export. Upload export.rsc. Do /system reset-configuration no-defaults=yes run-after-reset=export.rsc.

This will reset device without default values and import the new settings.
by 2frogs
Mon Mar 11, 2019 9:20 pm
Forum: Beginner Basics
Topic: After configuration when connecting all ports no internet connection
Replies: 4
Views: 261

Re: After configuration when connecting all ports no internet connection

This seems to me a DNS or NAT issue. Your NAT rule, although unconventional, should work. I would lean more to DNS. Is the CCR able to resolve DNS it’s self? If you change the DNS server from 192.168.1.1 to 8.8.8.8, does it browse better?
by 2frogs
Wed Mar 06, 2019 3:38 am
Forum: Beginner Basics
Topic: Can't login via WinBox
Replies: 3
Views: 240

Re: Can't login via WinBox

If you are attempting to connect using ether 2-5, then this is your issue: /interface list member add comment="Org LAN Bridge2" interface=Bridge2 list=LAN add comment="ISP WAN" interface=Ether1-WAN list=WAN /ip firewall filter add action=drop chain=input comment="defconf: drop all not coming from LA...
by 2frogs
Tue Mar 05, 2019 8:25 pm
Forum: General
Topic: dynamic ip in a dst-nat rule
Replies: 5
Views: 279

Re: dynamic ip in a dst-nat rule

I prefer this nat rule over using the ddns shown in the video.
add action=dst-nat chain=dstnat dst-address-type=local dst-address=!192.168.40.1(or router ip) dst-port=80,443  to-addresses=192.168.40.13
by 2frogs
Sun Feb 24, 2019 9:21 pm
Forum: General
Topic: Hotspot detect user ap
Replies: 3
Views: 476

Re: Hotspot detect user ap

I would use separate VLANs for each AP and create a Server for each VLAN with different Server Profiles.
by 2frogs
Sat Feb 23, 2019 3:29 am
Forum: General
Topic: Road Warrior setup using IKEv2 with RSA authentication with client internet over office pulic IP
Replies: 1
Views: 318

Re: Road Warrior setup using IKEv2 with RSA authentication with client internet over office pulic IP

There should be a setting in your phones vpn settings to send all traffic through the vpn. This is controlled on client side.
by 2frogs
Sat Feb 23, 2019 3:13 am
Forum: Beginner Basics
Topic: disable PPPoE connections go to html page
Replies: 4
Views: 538

Re: disable PPPoE connections go to html page

You could use the Hotspot. In ip-bindings, set your active customers IP's to bypass. Now do as @joegoldman suggest and change their IP to a Hotspot IP and they will get captured by the Hotspot and served the login.html page.
by 2frogs
Sat Feb 23, 2019 2:43 am
Forum: Wireless Networking
Topic: point to point low throughput!
Replies: 7
Views: 942

Re: point to point low throughput!

-30 is too strong of a signal. Reduce the power on both to maintain a -50 on both. 35Mbps is about the max you can expect from the NanoStation5.
by 2frogs
Sat Feb 23, 2019 1:03 am
Forum: General
Topic: Simple home setup - wireless roaming between APs
Replies: 7
Views: 5773

Re: Simple home setup - wireless roaming between APs

No, -79 would be correct. -81 will fall between -120 and -80 and therefore conflict.
by 2frogs
Sat Feb 23, 2019 12:17 am
Forum: Wireless Networking
Topic: Selection guide for PtP links Ranges?
Replies: 10
Views: 576

Re: Selection guide for PtP links Ranges?

I would look more at a PtMP antenna for your fixed site. That would make aiming only critical from the temporary location. Especially if the location could change each time.
by 2frogs
Fri Feb 22, 2019 11:23 pm
Forum: Beginner Basics
Topic: Firewall rules
Replies: 4
Views: 753

Re: Firewall rules

You can delete these, DNS alone is a nominal traffic; /ip firewall filter add action=fasttrack-connection chain=forward comment="Fasstrack DNS TCP" \ dst-port=53 protocol=tcp add action=fasttrack-connection chain=forward comment="Fasttrack DNS UPD" \ dst-port=53 protocol=udp And add this if your CPU...
by 2frogs
Fri Feb 22, 2019 8:49 pm
Forum: Wireless Networking
Topic: Selection guide for PtP links Ranges?
Replies: 10
Views: 576

Re: Selection guide for PtP links Ranges?

Actually the chart shows the range for the which the max data-rate can be obtained. The fading red line is the maximum distance for the lowest data-rate.
by 2frogs
Fri Feb 22, 2019 8:26 pm
Forum: Beginner Basics
Topic: Firewall rules
Replies: 4
Views: 753

Re: Firewall rules

If you are new to networking, you should not change the default firewall rule. The default firewall are sufficient for home users.
by 2frogs
Fri Feb 22, 2019 6:44 pm
Forum: General
Topic: Accidentally updated router firmware to long term 6.42.12
Replies: 2
Views: 382

Re: Accidentally updated router firmware to long term 6.42.12

i would do a netinstall and the attempt a restore from backup.
by 2frogs
Thu Feb 21, 2019 10:33 pm
Forum: Beginner Basics
Topic: station-pseudobridge L3 bridge to non MikroTik?
Replies: 6
Views: 579

Re: station-pseudobridge L3 bridge to non MikroTik?

I believe I want station-pseudobridge and I am aware of the L2 limitations but as this is a IP routed network should still be possible? https://wiki.mikrotik.com/wiki/Manual:Wireless_Station_Modes This indicates station-pseudobridge is for a single client. A bridge is not a routed network. Got it w...
by 2frogs
Tue Jan 08, 2019 12:47 am
Forum: General
Topic: Plink script
Replies: 7
Views: 771

Re: Plink script

In your example, “;” is still required at the end of the first line. It stands for “New Line.” Not true anymore "New Line" works nice. No need for ; anymore. Only if you like more commands on one line. https://wiki.mikrotik.com/wiki/Manual:Scripting The end of command line is represented by the tok...
by 2frogs
Mon Jan 07, 2019 10:11 pm
Forum: General
Topic: Plink script
Replies: 7
Views: 771

Re: Plink script

In your example, “;” is still required at the end of the first line. It stands for “New Line.”
by 2frogs
Fri Dec 21, 2018 1:29 pm
Forum: Beginner Basics
Topic: Brute Forse SSH blacklist
Replies: 5
Views: 591

Re: Brute Forse SSH blacklist

I know but I want to be able to access from anywhere and that is not possible if you use whitelist. Actually, Port Knocking allows for this. https://wiki.mikrotik.com/wiki/Port_Knocking But, the short answer is to add an accept for an Source IP before your brute force. Or edit brute force to includ...
by 2frogs
Thu Dec 20, 2018 7:54 pm
Forum: General
Topic: Hotspot with mac-login, external captive portal and RADIUS auth - How to force a second auth request
Replies: 12
Views: 1293

Re: Hotspot with mac-login, external captive portal and RADIUS auth - How to force a second auth request

This can be done with login time-out. However, 10-30 seconds would cause "Already Authorizing, retry later error" if the RADIUS is not done the first authentication request or if the authentication process is still in progress. Actually this has no effect on the OP’s issue, it does take the removal...
by 2frogs
Thu Dec 20, 2018 7:52 am
Forum: General
Topic: Hotspot with mac-login, external captive portal and RADIUS auth - How to force a second auth request
Replies: 12
Views: 1293

Re: Hotspot with mac-login, external captive portal and RADIUS auth - How to force a second auth request

Another solution is a script to kick any host that is not authorized that runs every 10-30 seconds. Maybe combine this with a delayed redirect of equal time.
by 2frogs
Thu Dec 20, 2018 7:42 am
Forum: General
Topic: Hotspot with mac-login, external captive portal and RADIUS auth - How to force a second auth request
Replies: 12
Views: 1293

Re: Hotspot with mac-login, external captive portal and RADIUS auth - How to force a second auth request

Not sure it would be any more of a hole than them simply changing their MAC to the same as another user.... shared-user=1 will help prevent this.
by 2frogs
Thu Dec 20, 2018 6:36 am
Forum: General
Topic: Hotspot with mac-login, external captive portal and RADIUS auth - How to force a second auth request
Replies: 12
Views: 1293

Re: Hotspot with mac-login, external captive portal and RADIUS auth - How to force a second auth request

Yeah, OK. I do recall this behavior and it is easy to reproduce. Create a disable user with MAC of device. Open browser to be caught by portal, then enable user. Now try browsing again and still get caught by portal. Kick host and will login on next attempt. You can login using the MAC as user. Redi...
by 2frogs
Wed Dec 19, 2018 4:21 pm
Forum: General
Topic: Hotspot with mac-login, external captive portal and RADIUS auth - How to force a second auth request
Replies: 12
Views: 1293

Re: Hotspot with mac-login, external captive portal and RADIUS auth - How to force a second auth request

The client should simply be able to browse to web page again to be authenticated. Or you could redirect to a non-walled-garden page as the last step in your payment process. All login processes require a http request. The Hotspot will only resend authorization request if it has not received a respon...
by 2frogs
Tue Dec 11, 2018 10:45 pm
Forum: General
Topic: Mikrotik Port Scanner -> Filezilla (21) Problem
Replies: 7
Views: 676

Re: Mikrotik Port Scanner -> Filezilla (21) Problem

Do you have the FTP service enabled and on port 21 of the router? What other firewall rules do you have?
/ip firewall filter export
by 2frogs
Tue Dec 11, 2018 8:05 pm
Forum: General
Topic: Mikrotik Port Scanner -> Filezilla (21) Problem
Replies: 7
Views: 676

Re: Mikrotik Port Scanner -> Filezilla (21) Problem

in /ip firewall filter -> add chain=input protocol=tcp psd=21,3s,3,1 action=add-src-to-address-list address-list="port scanners" address-list-timeout=2w comment="Port scanners to list” disabled=no This is correct! chain=input is for traffic going to the router itself. https://i.ibb.co/8PcZr6h/1.jpg...
by 2frogs
Tue Dec 11, 2018 6:54 pm
Forum: General
Topic: Mikrotik Port Scanner -> Filezilla (21) Problem
Replies: 7
Views: 676

Re: Mikrotik Port Scanner -> Filezilla (21) Problem

Your screenshot suggests you have the rule on chain=forward instead of chain=input...
by 2frogs
Sun Dec 09, 2018 8:45 pm
Forum: General
Topic: Incorrect firewall behavious
Replies: 13
Views: 719

Re: Incorrect firewall behavious

@sebastia

You have miss understood the problem of the OP! He has a forward rule to explicitly allow the dst-nat port. And the problem he is having is when that rule was disabled, he is still able to reach the port. The answer is what I provided. The default drop rule is allowing this traffic.
by 2frogs
Sun Dec 09, 2018 6:08 pm
Forum: General
Topic: Incorrect firewall behavious
Replies: 13
Views: 719

Re: Incorrect firewall behavious

/ip firewall add action=drop chain=forward comment="drop unvanted local traffic" connection-nat-state=!dstnat connection-state=new in-interface=ether10-WAN This is the default drop rule! Any connection coming from WAN would first be New and therefore dropped, unless it is a connection in NAT that i...
by 2frogs
Sun Dec 09, 2018 3:41 pm
Forum: General
Topic: Incorrect firewall behavious
Replies: 13
Views: 719

Re: Incorrect firewall behavious

add action=drop chain=forward comment="drop unvanted local traffic" connection-nat-state=!dstnat connection-state=new in-interface=ether10-WAN This rule allows any DSTNAT rules through the firewall. Remove the connection-nat-state=!dstnat if you only want to specifically allow this traffic with ind...
by 2frogs
Sun Dec 09, 2018 5:52 am
Forum: Scripting
Topic: Type "nothing" [SOLVED]
Replies: 15
Views: 1507

Re: Type "nothing" [SOLVED]

All variables have to be declared that are used in the script, global or not, declared in other scripts or not.
by 2frogs
Fri Dec 07, 2018 4:33 am
Forum: Beginner Basics
Topic: RouterOS not loading at static IP
Replies: 3
Views: 447

Re: RouterOS not loading at static IP

I will admit I do not use webfig for any major configurations for this very reason. It is still in development and really only intended for basic changes and preconfigured changes using the quickset (although some of those do not work correctly either.) The need of removing all unused settings, incl...
by 2frogs
Thu Dec 06, 2018 10:00 pm
Forum: Wireless Networking
Topic: 2.4ghz casi ciega en sxt
Replies: 2
Views: 367

Re: 2.4ghz casi ciega en sxt

hello to all I have a problem with several equipment mikrotik model slex litle5ac dualband the problem is that it does not see well the signals at 2.4ghz, however close they are the best one sees it at -70db meanwhile another signal 5ghz if it looks perfect up to -40 from the same position because ...
by 2frogs
Thu Dec 06, 2018 9:48 pm
Forum: Beginner Basics
Topic: RouterOS not loading at static IP
Replies: 3
Views: 447

Re: RouterOS not loading at static IP

Before you change the IP address, create your bridge first. Then assign the static IP to the bridge. Now you should be able to add the ether and wlan to bridge and still access it. When you add the ether/wlan to the bridge it becomes the slave to it and can not have an IP attached to them. And inste...
by 2frogs
Thu Nov 29, 2018 8:32 am
Forum: Beginner Basics
Topic: Plex port forwarding
Replies: 7
Views: 2335

Re: Plex port forwarding

I removed the port in NAT rule, so now it looks like: add action=dst-nat chain=dstnat comment="Plex port forwarding" in-interface=ether1 protocol=tcp to-addresses=\192.168.1.18 to-ports=32400 No, you remove the wrong port. Your rule should be what I posted for you! If that still does not work, make...
by 2frogs
Thu Nov 29, 2018 7:28 am
Forum: Beginner Basics
Topic: Different speeds to the same router.
Replies: 3
Views: 457

Re: Different speeds to the same router.

CPU usage is most likely the cause as it only uses a single core. This bandwidth tool should not be used as an accurate measure.
by 2frogs
Thu Nov 29, 2018 7:23 am
Forum: Beginner Basics
Topic: NAT problem with 2 WANs
Replies: 3
Views: 426

Re: NAT problem with 2 WANs

by 2frogs
Thu Nov 29, 2018 7:03 am
Forum: Beginner Basics
Topic: Plex port forwarding
Replies: 7
Views: 2335

Re: Plex port forwarding

What firewall filter rules do you have? Should have an accept rule for either port 32400 or for connection-nat-state=dst (or the default drop with connection-state-nat=!dst.) Are you double NATted? Your NAT rule should work, although you do no need to specify the to-port unless you need to change th...
by 2frogs
Thu Nov 29, 2018 6:53 am
Forum: General
Topic: Queue Tree Upload
Replies: 15
Views: 1779

Re: Queue Tree Upload

On your mangle rules, use chain=forward... /ip firewall mangle add action=mark-packet chain=forward comment="WAN Zuleitung" in-interface=\ ether1 new-packet-mark=wan_gesamt_up passthrough=no add action=mark-packet chain=forward comment="WAN Zuleitung" \ new-packet-mark=wan_gesamt_down out-interface=...
by 2frogs
Mon Nov 26, 2018 3:08 pm
Forum: Beginner Basics
Topic: Why use user manager over hotspot
Replies: 1
Views: 232

Re: Why use user manager over hotspot

To me the bigger benefit would be that users can create their own account/voucher paid/free and more easily maintain their account.
by 2frogs
Mon Nov 26, 2018 2:15 pm
Forum: Wireless Networking
Topic: 2x PTP
Replies: 2
Views: 472

Re: 2x PTP

2x PtP is the best option. With PtMP with the AP in middle you will loose 50% of the speed and double the latency as the AP can only communicate with one endpoint at a time. At the mast site, physically separate the 2 devices as much as possible within reason. Use channels as far apart as possible. ...
by 2frogs
Mon Nov 26, 2018 12:57 am
Forum: Beginner Basics
Topic: Hotspot logic: MAC login vs ip binding [SOLVED]
Replies: 2
Views: 345

Re: Hotspot logic: MAC login vs ip binding [SOLVED]

If the device does not touch port 80 (http), then MAC login will not work. If opening a web browser for the device to connect is not an issue, then it is up to preference.
by 2frogs
Wed Nov 21, 2018 3:13 am
Forum: Beginner Basics
Topic: need help to deal with simple port forwarding
Replies: 8
Views: 533

Re: need help to deal with simple port forwarding

That’s correct!
* netmap - creates a static 1:1 mapping of one set of IP addresses to another one. Often used to distribute public IP addresses to hosts on private networks
https://wiki.mikrotik.com/wiki/Manual:IP/Firewall/NAT
by 2frogs
Tue Nov 20, 2018 11:41 pm
Forum: Beginner Basics
Topic: need help to deal with simple port forwarding
Replies: 8
Views: 533

Re: need help to deal with simple port forwarding

Use action=dst-nat, netmap is intended to do a 1:1 nat between an ip or between sets of multiple ips. Between 2 ips it acts more like an DMZ where it would be port for port. DST-nat is for forwarding either a single port or multiple ports to a device and can be used to forward different ports to dif...
by 2frogs
Mon Oct 22, 2018 6:08 am
Forum: General
Topic: Problem with IP address
Replies: 1
Views: 352

Re: Problem with IP address

The WIKI shows a list of variables that are available for the “on-login” scripts.
https://wiki.mikrotik.com/wiki/Manual:IP/Hotspot/User


List of available variables:

$user
$username (alternative var name for $user)
$address
$"mac-address"
$interface
by 2frogs
Wed Oct 17, 2018 6:56 am
Forum: Beginner Basics
Topic: How to write dynamic command line?
Replies: 4
Views: 423

Re: How to write dynamic command line?

Using auto-mac, the MAC can change after a reboot. Not so great if you are using the MAC for static lease or for other hard coded settings.
by 2frogs
Wed Oct 17, 2018 4:59 am
Forum: General
Topic: Script permissions
Replies: 4
Views: 3175

Re: Script permissions

For some time now:
viewtopic.php?t=134538

In short, Netwatch can only execute scripts with "write, read, test, reboot" policies. Remove all other policies from your scripts.
by 2frogs
Wed Oct 17, 2018 4:19 am
Forum: Beginner Basics
Topic: How to write dynamic command line?
Replies: 4
Views: 423

Re: How to write dynamic command line?

You was nearly there with your code.
/interface bridge
add admin-mac=[/interface ethernet get [find where name="ether1"] mac-address] auto-mac=no name=mybridge
by 2frogs
Tue Oct 16, 2018 7:25 pm
Forum: Wireless Networking
Topic: CPE Router mode connects to AP but get no IP address
Replies: 18
Views: 3917

Re: CPE Router mode connects to AP but get no IP address

It is my understanding that “station-pseudobridge” expects the CPE to be a “bridge” and not a “router”. This would allow a device connected to ether1 to obtain an IP directly from the AP while having it’s MAC translated to the wlan MAC of the CPE.
by 2frogs
Mon Oct 15, 2018 9:34 pm
Forum: Wireless Networking
Topic: CPE Router mode connects to AP but get no IP address
Replies: 18
Views: 3917

Re: CPE Router mode connects to AP but get no IP address

Change the wireless mode from “station-pseudobridge” to “station”.
by 2frogs
Sun Oct 07, 2018 6:48 pm
Forum: General
Topic: Virus on Mikrotik (?) + formatting (?) router
Replies: 3
Views: 585

Re: Virus on Mikrotik (?) + formatting (?) router

This is what happened to you:
viewtopic.php?t=133533

And I would recommend the added step of doing a Netinstall to insure your device is clean.
https://wiki.mikrotik.com/wiki/Manual:Netinstall
by 2frogs
Wed Oct 03, 2018 4:19 pm
Forum: General
Topic: Specific WAN IP per user group
Replies: 2
Views: 255

Re: Specific WAN IP per user group

/ip firewall nat
add chain=srcnat out-interface-list=WAN src-address-list=group1 action=srcnat to-address=45.45.45.2
add  chain=srcnat out-interface-list=WAN src-address-list=group2 action=srcnat to-address=45.45.45.3
And then disable/remove default masquerade rule.
by 2frogs
Sat Sep 29, 2018 5:27 pm
Forum: General
Topic: add new user login from cli [SOLVED]
Replies: 1
Views: 323

Re: add new user login from cli [SOLVED]

/user add name=user1 group=group1 password=password123
https://mikrotik.com/documentation/manu ... Users.html
by 2frogs
Wed Sep 05, 2018 3:52 pm
Forum: General
Topic: IP-MAC Binding does not work
Replies: 1
Views: 380

Re: IP-MAC Binding does not work

IP delegation is handled by the DHCP Server and the Address Pool set for it. Under DHCP Lease in DHCP Server is where you make a lease static. IP Binding binds a IP and/or MAC to a specific Hotspot or All. And allows you to Bypass, Block or capture that IP and/or MAC on that Hotspot.
by 2frogs
Wed Aug 22, 2018 4:24 pm
Forum: General
Topic: Hotspot Flag AD and AH with same Mac Address
Replies: 2
Views: 400

Re: Hotspot Flag AD and AH with same Mac Address

In both /ip hotspot server and user profile set address-pool=none. You will still get an address from the DHCP server.

If this does not resolve both issues, you may need to increase your DHCP lease-time a bit!
by 2frogs
Tue Aug 21, 2018 3:41 pm
Forum: Beginner Basics
Topic: No internet [SOLVED]
Replies: 6
Views: 577

Re: No internet [SOLVED]

Does your modem hand out DHCP or did you forget to setup a PPPoE-Client on the Mikrotik?
by 2frogs
Tue Aug 21, 2018 2:52 pm
Forum: General
Topic: export dhcp lease with only hostname
Replies: 1
Views: 459

Re: export dhcp lease with only hostname

If I understood correctly, this is what you need.
/ip dhcp-server lease print where hostname=“pc” file=$n
by 2frogs
Sun Aug 19, 2018 5:16 pm
Forum: Beginner Basics
Topic: I need help but not sure what help to ask for...
Replies: 12
Views: 1006

Re: I need help but not sure what help to ask for...

After resetting the mAP and then login with Winbox, you have an option to remove current configuration. Or even better, at some point Reset-Configuration was added to System menu, just check mark "No Default Configuration" and click "Reset Configuration".
by 2frogs
Sun Aug 19, 2018 2:42 pm
Forum: Beginner Basics
Topic: I need help but not sure what help to ask for...
Replies: 12
Views: 1006

Re: I need help but not sure what help to ask for...

It looks like the Quick-set is not doing it's job correctly. if you are familiar with Winbox, I would suggest resetting the mAP without a configuration. Then connect to it with Winbox using the MAC address (it should show in the Neighbors tab). Once connected, you can paste the following in a New Te...
by 2frogs
Sun Aug 19, 2018 6:22 am
Forum: Beginner Basics
Topic: I need help but not sure what help to ask for...
Replies: 12
Views: 1006

Re: I need help but not sure what help to ask for...

Hi thanks for the help 2frogs , atm i have done a factory reset on the nano , then did the following : Set the ip to 192.168.2.1 set the dhcp range to 192.168.2.2 >>>> 192.168.2.254 When the nano is connected to the laptop via Ethernet / power supply i am able to connect to it ok on 192.168.2.1 and...
by 2frogs
Sat Aug 18, 2018 6:40 am
Forum: Beginner Basics
Topic: I need help but not sure what help to ask for...
Replies: 12
Views: 1006

Re: I need help but not sure what help to ask for...

In the Quickset of the mAP 2, set it to WISP AP. This adds the Ethernet and Wireless interface to a bridge. Then set it to a static address outside the DHCP range you set on the Nanostation. Now when you connect them together and connect to the wireless of the mAP, you should have Internet and be ab...
by 2frogs
Thu Aug 16, 2018 5:15 am
Forum: Beginner Basics
Topic: Port forwarding for beginner
Replies: 6
Views: 566

Re: Port forwarding for beginner

You also need to change all in-interface= from “BT Modem” to ppoe-out1 in your ip/firewall/filter. And then either add ppoe-out1 to the interface-list=WAN or change your ip/firewall/nat masquerade to out-interface=ppoe-out1 instead of using the list.
by 2frogs
Tue Aug 07, 2018 2:46 pm
Forum: General
Topic: port forward from mikrotik router to mikrotik ap
Replies: 1
Views: 222

Re: port forward from mikrotik router to mikrotik ap

Do you have a default route on your AP’s?
/ip route add 0.0.0.0/0 gateway=(router ip)
by 2frogs
Wed Jul 11, 2018 4:32 pm
Forum: Wireless Networking
Topic: Hotspot not redirecting to login page
Replies: 4
Views: 8829

Re: Hotspot not redirecting to login page

Testing to google.com or any other site that redirects you to https:// will not work. You have to try accessing a http site that does not get redirected! Unrelated to your issue, having a pool set under /ip hotspot address-pool other than =none sets a NAT helper intended for devices with a static IP...
by 2frogs
Thu Jul 05, 2018 10:00 pm
Forum: Forwarding Protocols
Topic: NTP via not default port (server and client is mine)
Replies: 2
Views: 565

Re: NTP via not default port (server and client is mine)

Why not just manually configure NTP Client on both devices. Here is a guide: https://blog.ligos.net/2018-01-29/NTP-P ... rotik.html
by 2frogs
Tue Jul 03, 2018 3:45 pm
Forum: Beginner Basics
Topic: Portforwarding to mikritik and dchp behind other router
Replies: 6
Views: 564

Re: Portforwarding to mikritik and dchp behind other router

Firewall rule order matters! Move filter rule 7 above 6. You are currently dropping everything not established or related.
by 2frogs
Mon Jul 02, 2018 5:00 pm
Forum: Beginner Basics
Topic: Problem with binding LTE as gateway for HOtspot bridge
Replies: 1
Views: 275

Re: Problem with binding LTE as gateway for HOtspot bridge

Follow this guide, just replace the VPN with your LTE interface and remove the content=facebook and use dst-address=!<your hotspot ip scope>.
https://wiki.mikrotik.com/wiki/Policy_Base_Routing
by 2frogs
Thu Jun 28, 2018 11:59 pm
Forum: General
Topic: Help with Kinda Unresponsive 52HPn
Replies: 1
Views: 228

Re: Help with Kinda Unresponsive 52HPn

Are you not able to connect using the MAC address?
by 2frogs
Thu Jun 28, 2018 11:43 pm
Forum: Beginner Basics
Topic: Device appears with two MACs in hotspot [SOLVED]
Replies: 13
Views: 1222

Re: Device appears with two MACs in hotspot [SOLVED]

Do:
/interface bridge set 0 auto-mac=no
As it seems you can not just set admin-mac from terminal. You can set it from winbox also.
by 2frogs
Wed Jun 27, 2018 4:37 pm
Forum: Beginner Basics
Topic: cloud DDNS name issue with iPhone VPN settings?
Replies: 2
Views: 307

Re: cloud DDNS name issue with iPhone VPN settings?

Are you sure you copied it correctly? It works fine for me!
by 2frogs
Wed Jun 27, 2018 1:49 pm
Forum: Beginner Basics
Topic: Device appears with two MACs in hotspot [SOLVED]
Replies: 13
Views: 1222

Re: Device appears with two MACs in hotspot [SOLVED]

Bridge´s "admin-mac" is 00:00:5E:80:00:04, but it is only shown when I edit the bridge. Not in /interface bridge print or export, not in the hotspot. It should be visable in both print and export. 0 R name="Main" mtu=1500 actual-mtu=1500 l2mtu=1598 arp=enabled arp-timeout=auto mac-address=4C:5E:0C:...
by 2frogs
Tue Jun 26, 2018 11:27 pm
Forum: Wireless Networking
Topic: Users Not Being Directed to the Hotspot Login Screen
Replies: 6
Views: 1252

Re: Users Not Being Directed to the Hotspot Login Screen

Can the Mikrotik resolve DNS properly? Access internet?

Use /tools trace-route and see if it trace to google.com with “use dns” checked.
by 2frogs
Tue Jun 26, 2018 11:14 pm
Forum: Beginner Basics
Topic: Device appears with two MACs in hotspot [SOLVED]
Replies: 13
Views: 1222

Re: Device appears with two MACs in hotspot [SOLVED]

Post /export hide-sensitive.
by 2frogs
Tue Jun 26, 2018 8:36 pm
Forum: Wireless Networking
Topic: Users Not Being Directed to the Hotspot Login Screen
Replies: 6
Views: 1252

Re: Users Not Being Directed to the Hotspot Login Screen

There are several errors! 192.188.254.254 instead of 192.168.254.254.. No DNS under IP>DNS, all DNS request get redirected to the Mikrotik. DHCP lease-time needs to be in a number of hours or some devices (Apple) will not work. Set ip-pool=none in IP>Hotspot, devices will get IP Address from DHCP Se...
by 2frogs
Tue Jun 26, 2018 5:13 pm
Forum: Wireless Networking
Topic: Forcing my TV back to 5Ghz
Replies: 4
Views: 552

Re: Forcing my TV back to 5Ghz

Or you could just create VAP with different SSID’s for 2.4 and 5.8 in addition to the common SSI. And just connect to the 5.8 SSID.
by 2frogs
Sat Jun 23, 2018 8:09 pm
Forum: Wireless Networking
Topic: w60g
Replies: 6
Views: 873

Re: w60g

You are maxing out the CPU as it is not strong enough to generate the traffic and also pass it. And that bandwidth test only runs on a single core on multi-core CPU’s. Use iperf between 2 pc’s instead. Bit of a bold claim. A) he 816 drops on that link. Unless he's running 816 btest, this holds no w...
by 2frogs
Sat Jun 23, 2018 7:43 am
Forum: Forwarding Protocols
Topic: IP Rules/ NAT Setup for FTP - RouterOS v6.30.1
Replies: 10
Views: 2685

Re: IP Rules/ NAT Setup for FTP - RouterOS v6.30.1

For Passive Mode, you do have to forward the Passive Ports as well as the FTP Port.
by 2frogs
Sat Jun 23, 2018 6:12 am
Forum: General
Topic: Hotspot problem IOS 10.4
Replies: 3
Views: 437

Re: Hotspot problem IOS 10.4

Why do you have captive.apple.com in your walled-garden? iOS uses this url to see if the device is behind a captive portal. If it can access it, it will not pop up the login page.
by 2frogs
Sat Jun 23, 2018 5:26 am
Forum: Wireless Networking
Topic: w60g
Replies: 6
Views: 873

Re: w60g

You are maxing out the CPU as it is not strong enough to generate the traffic and also pass it. And that bandwidth test only runs on a single core on multi-core CPU’s. Use iperf between 2 pc’s instead.
by 2frogs
Wed Jun 20, 2018 5:31 am
Forum: Wireless Networking
Topic: FCC TX Power
Replies: 1
Views: 320

Re: FCC TX Power

It goes by total tx output. The number that really matters is the radiated power (antenna gain + tx power - losses). If you have the country set to US and Antenna Gain set to 14 in the Mikrotik settings, then you can leave the power settings to default and the device will control power.
by 2frogs
Tue Jun 19, 2018 2:38 am
Forum: Beginner Basics
Topic: Cannot login to Access point from home
Replies: 11
Views: 1386

Re: Cannot login to Access point from home

Well, there is a lot wrong with that config, but a possible cause for your troubles is the IP is on the wlan interface instead of the bridge.
/ip address add address=10.100.0.7/24 network=10.100.0.0 interface=bridge1
by 2frogs
Sun Jun 17, 2018 4:36 pm
Forum: Wireless Networking
Topic: Network File Sharing problemt
Replies: 6
Views: 737

Re: Network File Sharing problemt

Check to see if your network connection type is still Home.
http://www.dummies.com/computers/operat ... windows-7/
by 2frogs
Fri Jun 15, 2018 12:53 am
Forum: Scripting
Topic: How to hide output of "once"
Replies: 3
Views: 488

Re: How to hide output of "once"

viewtopic.php?t=94583
Have a look at this.
by 2frogs
Wed Jun 13, 2018 4:32 pm
Forum: Beginner Basics
Topic: How to get ipv6s from digitalocean vps?
Replies: 4
Views: 659

Re: How to get ipv6s from digitalocean vps?

I have seen tutorials for installing Mikrotik CHR on DigitalOcean droplet. Doing this then VPN to it might be a solution.
by 2frogs
Wed Jun 13, 2018 6:58 am
Forum: Beginner Basics
Topic: How to get ipv6s from digitalocean vps?
Replies: 4
Views: 659

Re: How to get ipv6s from digitalocean vps?

Not sure about from digital ocean, but you can from https://www.tunnelbroker.net/. There is a wiki to help you set it up. https://wiki.mikrotik.com/wiki/Manual:H ... e_for_Home
by 2frogs
Wed Jun 13, 2018 6:46 am
Forum: General
Topic: MT Router honeypot.
Replies: 20
Views: 2057

Re: MT Router honeypot.

In the meantime... I Believe the router is now infected with something. Its CPU is not 50-85% and im getting 2000 IPs in 4 hours hitting it.. I have not done much work to figure out whats going on yet. It does pass the "check packages" test.. Open DNS resolver most likely. Did you leave “Allow Remo...
by 2frogs
Wed Jun 13, 2018 6:30 am
Forum: Beginner Basics
Topic: Sending email from Tools/Netwatch [SOLVED]
Replies: 5
Views: 2507

Re: Sending email from Tools/Netwatch [SOLVED]

/tool e-mail send from="rieks@mt.lv" server="159.148.147.198" body="Router down" subject="Router at second floor is down" to="rieks@latnet.lv" port=25 user=rieks password=123abc start-tls=no
by 2frogs
Mon Jun 11, 2018 4:22 pm
Forum: Beginner Basics
Topic: Incorrect Upnp entries when using VLANs in a bridge. What's missing?
Replies: 5
Views: 549

Re: Incorrect Upnp entries when using VLANs in a bridge. What's missing?

I am guessing leaving just the Bridge doesn’t work either.

If not email support and include a supout. It looks to be treating the vlan as an external interface instead of internal...
by 2frogs
Mon Jun 11, 2018 3:29 pm
Forum: Beginner Basics
Topic: Incorrect Upnp entries when using VLANs in a bridge. What's missing?
Replies: 5
Views: 549

Re: Incorrect Upnp entries when using VLANs in a bridge. What's missing?

What happens when you add the Bridge to the upnp interface also?
by 2frogs
Wed Jun 06, 2018 8:24 am
Forum: Scripting
Topic: Run Script on Login of any user
Replies: 5
Views: 974

Re: Run Script on Login of any user

:do {:if ([/user active print count-only]>0) do={/system script run backup; :delay 30m;}} while=(true); It's not full proof, but works. Just schedule it at startup. If you are using the Dude, you will need to increase the 0 to 1. You can also increase it to 1 and test the script from winbox by open...
by 2frogs
Wed Jun 06, 2018 5:01 am
Forum: Scripting
Topic: Run Script on Login of any user
Replies: 5
Views: 974

Re: Run Script on Login of any user

If you set the backup names to the identity of the device and use unique identities, you should be able to do your backups nightly and will be over written on your server. I do this with nightly exports.
by 2frogs
Sat Jun 02, 2018 3:52 am
Forum: Beginner Basics
Topic: Make devices with different LANs Communicate
Replies: 6
Views: 540

Re: Make devices with different LANs Communicate

The picture doesn't make sense until you label the devices with the red arrows. You shouldn't have to do anything to make the 2 networks communicate if both subnets are defined on the same router. If they aren't talking, you are blocking it. You don't need to add any routes, they are already there ...
by 2frogs
Sat Jun 02, 2018 2:53 am
Forum: Beginner Basics
Topic: Make devices with different LANs Communicate
Replies: 6
Views: 540

Re: Make devices with different LANs Communicate

You just need to add some routes. Change the gateway to your bridges name:
/ip route
add distance=1 dst-address=10.11.128.0/24 gateway=bridge
add distance=1 dst-address=10.124.12.0/24 gateway=bridge
add distance=1 dst-address=124.15.25.0/24 gateway=bridge
by 2frogs
Sat Jun 02, 2018 2:22 am
Forum: Forwarding Protocols
Topic: sip phone being stopped at wan address
Replies: 7
Views: 917

Re: sip phone being stopped at wan address

Do you have a destination nat rule for you PBX? Something like:
/ip firewall nat add chain=dst-nat dst-address=192.168.20.10 protocol=tcp dst-port=5060 to-address=192.168.0.5
by 2frogs
Sat Jun 02, 2018 2:00 am
Forum: Beginner Basics
Topic: Wireless devices not getting internet with repeater mode.
Replies: 1
Views: 388

Re: Wireless devices not getting internet with repeater mode.

The Mikrotik and Netgear are not compatible for that type of setup. You can run an network cable betwen them or setup the Mikrotik with a seperate network with the WAN being wlan1 in station mode.
by 2frogs
Wed May 30, 2018 3:54 pm
Forum: General
Topic: Hex PLUS
Replies: 15
Views: 1930

Re: Hex PLUS

I think you have it all wrong. Home/Home Office users do not need that much storage. Using blacklists is the wrong idea. You should be using whitelists. Only allowing trusted ip or temporarily allowing ips is what is need in these situations. Port knocking and trusted address list keeps requirements...
by 2frogs
Tue May 29, 2018 1:32 pm
Forum: Beginner Basics
Topic: VLAN for guests multiple VAP
Replies: 2
Views: 351

Re: VLAN for guests multiple VAP

Yes, create a bridge for your guest network. Add your guest IP and dhcp Server to that bridge. Then add your 2 vaps under bridge port. You will also need to add a firewall rule to block traffic between your networks.
by 2frogs
Mon May 28, 2018 11:59 pm
Forum: General
Topic: HAP Mini will not retain its settings.
Replies: 2
Views: 313

Re: HAP Mini will not retain its settings.

Do you by chance have safe-mode enabled?
by 2frogs
Sat May 26, 2018 4:16 am
Forum: General
Topic: Simple CALEA implementation?
Replies: 1
Views: 787

Re: Simple CALEA implementation?

The CALEA Server is simply a device running RouterOS with the CALEA Package installed. I would recommend a CHR instance, x86 or other device with an actual hard drive. The CALEA Package can be install from the Extra Packages .zip file from https://mikrotik.com/download .
by 2frogs
Wed May 23, 2018 2:49 am
Forum: Beginner Basics
Topic: What do i need to learn to become proficient quickly?
Replies: 20
Views: 1784

Re: What do i need to learn to become proficient quickly?

https://www.amazon.com/RouterOS-Example-2nd-B-W/dp/0692777083 This book helped me immensely! I would highly suggest buying you a device to test with before messing with production devices. To download your export file you can either drag & drop to your desktop or use an ftp program (if the device ha...
by 2frogs
Tue May 22, 2018 1:52 pm
Forum: General
Topic: Hwo to add guest Wifi? (with Mikrotik Cloud Router and hAp ac)
Replies: 1
Views: 384

Re: Hwo to add guest Wifi? (with Mikrotik Cloud Router and hAp ac)

You are most likely missing a src-nat. /ip firewall nat add chain=src-nat src-address=192.168.99.0/24 out-interface=bridge action=masquerade set out-interface to the bridge for your main network. To block access from guest to lan: /ip firewall filter add chain=forward src-address=192.168.99.0/24 dst...
by 2frogs
Thu May 17, 2018 2:56 am
Forum: General
Topic: Hotspot Problem with Apple IoS 11.3.1, is someone having the same problem?
Replies: 8
Views: 3012

Re: Hotspot Problem with Apple IoS 11.3.1, is someone having the same problem?

I just checked 5 different iOS 11.3.1 devices on ROS v6.42.1 and they all work fine. I use the trial feature for my guest network.
by 2frogs
Wed May 16, 2018 3:38 am
Forum: Scripting
Topic: Find and Replace within an existing script
Replies: 2
Views: 459

Re: Find and Replace within an existing script

You can update the current script using: /system script set [find name=scriptname] source=":local currentVPNServer [/interface ovpn-client get vpn-interface connect-to];:local newVPNServer [/resolve newend.point,com;:if ([:len [:toip \$newVPNServer]] > 0) do={:if ( != ) do={/interface ovpn-client s...
by 2frogs
Tue May 15, 2018 7:04 pm
Forum: General
Topic: Checking whether items are present
Replies: 14
Views: 976

Re: Checking whether items are present

Add a delay to the top of your script to allow time for all interfaces to initialize.
by 2frogs
Sun May 13, 2018 2:26 pm
Forum: Scripting
Topic: Print output for hotspot users
Replies: 3
Views: 1043

Re: Print output for hotspot users

/ip hotspot user print detail file=filename.txt
or
/ip hotspot user export file=filename.txt
Then you should be able to import the txt file into a spreadsheet or in the case of the export simply modify the script directly.
by 2frogs
Sat May 12, 2018 5:11 pm
Forum: Scripting
Topic: Logical operator "not in"
Replies: 5
Views: 657

Re: Logical operator "not in"

Well it didn’t show an error, but here you go:
/ppp active print count-only where (address in 203.0.113.0/24 and !(address in 203.0.113.0/27))
by 2frogs
Sat May 12, 2018 7:13 am
Forum: Scripting
Topic: Logical operator "not in"
Replies: 5
Views: 657

Re: Logical operator "not in"

 /ppp active print count-only where (address in 203.0.113.0/24 AND address in !203.0.113.0/27)
by 2frogs
Thu May 03, 2018 4:09 pm
Forum: Scripting
Topic: how to copy mac cookies from one hotspot to another hotspot?
Replies: 1
Views: 413

Re: how to copy mac cookies from one hotspot to another hotspot?

You can not manually add cookies or change their value. You can only find, print, or remove them.
by 2frogs
Thu May 03, 2018 6:01 am
Forum: Scripting
Topic: Route Checking before adding
Replies: 3
Views: 524

Re: Route Checking before adding

:if ([:len [/ip route find dst-address=0.0.0.0/0 and gateway=192.168.254.1]] >0) do={:log info "Route Exists";} else={/ip route add gateway=192.168.254.1 dst-address=0.0.0.0/0; :log info "Added Route";}
by 2frogs
Thu May 03, 2018 12:22 am
Forum: Wireless Networking
Topic: Multipoint wireless bridge with MikroTik SXT's
Replies: 11
Views: 1666

Re: Multipoint wireless bridge with MikroTik SXT's

Thanks! I just checked and the new one is Level 4. I'll make sure the other two are as well. Thanks for that!
Only the one used as an AP has to have Level 4, the connected Stations (CPE) can be Level 3.
by 2frogs
Thu May 03, 2018 12:16 am
Forum: Wireless Networking
Topic: Metal 9 and XR9
Replies: 1
Views: 467

Re: Metal 9 and XR9

Not compatible!
See:
viewtopic.php?t=86091
by 2frogs
Tue May 01, 2018 2:50 pm
Forum: Beginner Basics
Topic: 2 wan... switch between when no internet.
Replies: 12
Views: 2425

Re: 2 wan... switch between when no internet.

Netwatch
In learning RouterOS, Google is your friend! Just be leary of results not on official Mikrotik sites.
by 2frogs
Tue May 01, 2018 5:11 am
Forum: Beginner Basics
Topic: 2 wan... switch between when no internet.
Replies: 12
Views: 2425

Re: 2 wan... switch between when no internet.

For example I am unfamiliar with IP Route Set? "Set" is CLI Command that lets you set (or change) a parameters value. In this case we are setting distance=3 for IP>Route>the route with WAN1 in comments. How does distance=3 have to do with anything Serves the same purpose as the distance settings th...
by 2frogs
Tue May 01, 2018 2:39 am
Forum: Wireless Networking
Topic: Multipoint wireless bridge with MikroTik SXT's
Replies: 11
Views: 1666

Re: Multipoint wireless bridge with MikroTik SXT's

First check if you have License level 4 (System->License) in the SXT which will be the AP.
I forgot Mikrotik did this. This sucks!
by 2frogs
Tue May 01, 2018 1:35 am
Forum: Beginner Basics
Topic: Script for auto change SSID daily [SOLVED]
Replies: 5
Views: 1237

Re: Script for auto change SSID daily [SOLVED]

I had thought of later to just do a simple counter and had meant to post it for you, but I got side tracked and forgot! Here goes: /ip firewall address-list add address=1.1.1.1 comment=1 list=SSIDCounter /system scheduler add interval=1d name=schedule on-event=":local SSIDCounter [/ip firewall addre...
by 2frogs
Mon Apr 30, 2018 10:35 pm
Forum: Wireless Networking
Topic: Multipoint wireless bridge with MikroTik SXT's
Replies: 11
Views: 1666

Re: Multipoint wireless bridge with MikroTik SXT's

Thats correct! And it should be as simple as changing the mode on each side.
by 2frogs
Mon Apr 30, 2018 5:58 am
Forum: Beginner Basics
Topic: 2 wan... switch between when no internet.
Replies: 12
Views: 2425

Re: 2 wan... switch between when no internet.

/ip route add gateway=gateway1ip distance=1 comment=WAN1 add gateway=gateway2ip distance=2 comment=WAN2 add dst-address=8.8.8.8/32 gateway=gateway1ip /tool netwatch add down-script="/ip route set [find where comment=\"WAN1\"] distance=3;\r\ \n:log warning \"WAN1 down, switching to WAN2\"" host=8.8....
by 2frogs
Mon Apr 30, 2018 4:05 am
Forum: Beginner Basics
Topic: 2 wan... switch between when no internet.
Replies: 12
Views: 2425

Re: 2 wan... switch between when no internet.

That is not to difficult IP Route destination=0.0.0.0/0 gateway=gatewayIP (of primary WAN) ping gateway distance=1 (to be clear these are gateway IPs of the ISP, not the WANIP the ISP has assigned to your). destination=0.0.0.0/0 gateway=gatewayIP (of secondary WAN) distance=2 Thats it. Almost! You ...
by 2frogs
Fri Apr 27, 2018 4:30 pm
Forum: Beginner Basics
Topic: Allow trafic betwen different subnets.
Replies: 26
Views: 1897

Re: Allow trafic betwen different subnets.

Just a quick thought, since you are using a Cisco AP, it doesn't have any client-isolation or vlan filtering on it that is blocking vlan subnets from communicating does it?
by 2frogs
Fri Apr 27, 2018 4:24 pm
Forum: Beginner Basics
Topic: Script for auto change SSID daily [SOLVED]
Replies: 5
Views: 1237

Re: Script for auto change SSID daily [SOLVED]

You might provide more detail about what you want the SSID to change to. For example: /system scheduler add interval=1d name=schedule on-event=\ "/interface wireless set wlan1 ssid=(\"MySSID - \".[/system clock get date])" \ policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \ s...
by 2frogs
Fri Apr 27, 2018 2:55 pm
Forum: Beginner Basics
Topic: Allow trafic betwen different subnets.
Replies: 26
Views: 1897

Re: Allow trafic betwen different subnets.

I believe you need to enable vlan filtering on the bridge. By default, Mikrotik allows communications between any routed interfaces. You would have to use firewall rules to drop any traffic between LAN segments you did not want. https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_VLAN_Filt...
by 2frogs
Fri Apr 27, 2018 2:44 am
Forum: General
Topic: How to prevent block providers' redirection?
Replies: 8
Views: 623

Re: How to prevent block providers' redirection?

no, all done simply. It looks like redirection to the attention page where you can see information about lack of money. Their redirection accompanied with address line change... In this case, PAY for your service and do not try to steal it. I support having full access to whatever you want to reach...
by 2frogs
Thu Apr 26, 2018 2:17 pm
Forum: General
Topic: How to prevent block providers' redirection?
Replies: 8
Views: 623

Re: How to prevent block providers' redirection?

You will need a VPN service. Some providers are from client devices only and others would allow you to configure your router for all or part of your to use the VPN. You will need to search for the best provider that fits your needs.
by 2frogs
Thu Apr 26, 2018 2:14 pm
Forum: General
Topic: HotSpot maintenance page / or disable at specific time
Replies: 1
Views: 302

Re: HotSpot maintenance page / or disable at specific time

Without knowing how your hotspot is setup, the best option I can think of is to modify a copy of the hotspot files to (or create a simple login.html) "This site down for maintenance" or whatever you want it to say. Then upload to a different folder than your normal hotspot files. Now create a new se...
by 2frogs
Thu Apr 26, 2018 1:24 am
Forum: General
Topic: Mikrotik keeps requesting for login information from users
Replies: 4
Views: 489

Re: Mikrotik keeps requesting for login information from users

A network diagram and
/export hide-sensitive
would be helpful.
by 2frogs
Thu Apr 26, 2018 12:14 am
Forum: Wireless Networking
Topic: Multipoint wireless bridge with MikroTik SXT's
Replies: 11
Views: 1666

Re: Multipoint wireless bridge with MikroTik SXT's

Use mode=ap bridge and mode=station wds. Follow this guide: https://wiki.mikrotik.com/wiki/PTP_Links_-_A_Step_By_Step_Guide You will have to change the current link you want to connect to first, before adding the new one. Change the furtherest one from you first, because the link while drop will you...
by 2frogs
Wed Apr 25, 2018 10:37 pm
Forum: Beginner Basics
Topic: Allow only one specified port to a LAN host
Replies: 8
Views: 667

Re: Allow only one specified port to a LAN host

/ip firewall filter add chain=forward src-address=192.168.88.100 out-interface=WAN protocol=tcp port=!5900 action=drop add chain=forward src-address=192.168.88.100 out-interface=WAN protocol=udp port=!5900 action=drop Can this be simplified by only using two rules?? If so, is it fair to say, that f...
by 2frogs
Wed Apr 25, 2018 9:32 pm
Forum: General
Topic: dhcp does not appear to traverse my bridge
Replies: 10
Views: 769

Re: dhcp does not appear to traverse my bridge

Fair enough, but reading that you see they are “Fundamentally” the same. They serve the same purpose, check the same boxes, and have the same outcome. And I would almost guarantee that at the core the are the same and use the same WDS protocols, but just done more transparently using the bridge/ sta...
by 2frogs
Wed Apr 25, 2018 8:19 pm
Forum: General
Topic: dhcp does not appear to traverse my bridge
Replies: 10
Views: 769

Re: dhcp does not appear to traverse my bridge

If you read the first paragraph of the link you provided it states there are several ways to accomplish a PtP. Your solution only works for PtP, where as mine would work also for PtMP where there are multiple device at each endpoint. Plus I have not seen a definition of station-bridge, it not in htt...
by 2frogs
Wed Apr 25, 2018 5:59 pm
Forum: Beginner Basics
Topic: Question about using VLANs to set up a guest network [SOLVED]
Replies: 20
Views: 2657

Re: Question about using VLANs to set up a guest network [SOLVED]

/interface bridge set protocol=none Again I am no expert, but it seems to me RSTP is broken on Mikrotik. Every time it gets set with/without vlans it breaks my network. It is possible that it is due to the mix of vendor (Ubiquiti PtMP) on my network and they are not playing nice together or what. A...
by 2frogs
Wed Apr 25, 2018 5:38 pm
Forum: General
Topic: dhcp does not appear to traverse my bridge
Replies: 10
Views: 769

Re: dhcp does not appear to traverse my bridge

You need to change your wireless settings to AP Bridge and Station WDS. Using just Station all MAC addresses get translated to the MAC of the station. The DHCP server will only assign 1 IP per MAC. This is why statically assigning IP’s work and DHCP doesn’t. https://wiki.mikrotik.com/wiki/PTP_Links_...
by 2frogs
Wed Apr 25, 2018 6:47 am
Forum: Beginner Basics
Topic: Question about using VLANs to set up a guest network [SOLVED]
Replies: 20
Views: 2657

Re: Question about using VLANs to set up a guest network [SOLVED]

BTW, you mentioned I could set up vaps on my other access point -- does that impact the performance of the access point much? We were so ecstatic about the performance of the Hap ACs that I was reluctant to try vaps at first, but if there is no real performance impact I will try that. None to minim...
by 2frogs
Wed Apr 25, 2018 6:04 am
Forum: Beginner Basics
Topic: Question about using VLANs to set up a guest network [SOLVED]
Replies: 20
Views: 2657

Re: Question about using VLANs to set up a guest network [SOLVED]

I was just testing more of your config, on your router /interface bridge settings set use-ip-firewall=yes use-ip-firewall-for-vlan=yes caused some weirdness. You can do: /interface bridge settings set use-ip-firewall=no use-ip-firewall-for-vlan=no or at least do no vlan. As far as your questions, I ...
by 2frogs
Wed Apr 25, 2018 5:09 am
Forum: Beginner Basics
Topic: Question about using VLANs to set up a guest network [SOLVED]
Replies: 20
Views: 2657

Re: Question about using VLANs to set up a guest network [SOLVED]

Do you by chance have a Static DHCP-Lease for the Windows computer with server=all?
by 2frogs
Wed Apr 25, 2018 3:15 am
Forum: General
Topic: Discovery Protocol only on specified interfaces
Replies: 7
Views: 842

Re: Discovery Protocol only on specified interfaces

@pe1chl
The Wiki was updated 12 February 2018 and includes interface-list.
by 2frogs
Wed Apr 25, 2018 3:03 am
Forum: General
Topic: Default firewall rules now block management over VPN
Replies: 3
Views: 530

Re: Default firewall rules now block management over VPN

Most likely the change was made for the Home Market where they are not using VPN for management. I can see also that VPN clients in an Enterprise Environment would not want their employees access to the management. But it also blocks you from using the router as DNS on VPN by default, which I have h...
by 2frogs
Tue Apr 24, 2018 7:51 pm
Forum: Beginner Basics
Topic: VPN clients cannot access router for DNS [SOLVED]
Replies: 4
Views: 499

Re: VPN clients cannot access router for DNS [SOLVED]

The following could work, however, I don't exactly know your current firewall configuration. #The firewall rules must be in the input chain port 53(TCP and UDP) #The interface(ether1) is your LAN /ip firewall filter add action=accept chain=input dst-port=53 in-interface=ether1 protocol=tcp add acti...
by 2frogs
Tue Apr 24, 2018 1:47 pm
Forum: Beginner Basics
Topic: Question about using VLANs to set up a guest network [SOLVED]
Replies: 20
Views: 2657

Re: Question about using VLANs to set up a guest network [SOLVED]

On your Router, change guest-bridge pvid=1 (or what default is) and vlan-filtering=no as we are un-tagging traffic coming to the bridge.
by 2frogs
Tue Apr 24, 2018 4:26 am
Forum: General
Topic: Quick set manual does not include "Basic AP"
Replies: 2
Views: 676

Re: Quick set manual does not include "Basic AP"

Not sure why you think "HomeAP" is misleading. It sets up the router for Home use... WispAP is all Interfaces Bridged (like Switch) with AP.. you would use this to add a second AP to a HomeAP! BasicAP seems to only let you change the Wifi Password, it show the SSID, if it has Internet Connectivity, ...
by 2frogs
Mon Apr 23, 2018 8:47 pm
Forum: General
Topic: Suppress DHCP Event in Log??
Replies: 4
Views: 451

Re: Suppress DHCP Event in Log??

Apple has issues with short lease times. You should use a minimal of 6hrs for apple things.
by 2frogs
Mon Apr 23, 2018 6:33 am
Forum: Beginner Basics
Topic: Disallow unknown logins from internet access
Replies: 8
Views: 760

Re: Disallow unknown logins from internet access

Changing ports will help with most. Using address-list and port knocker to limit access is even better.
by 2frogs
Mon Apr 23, 2018 6:29 am
Forum: General
Topic: when queue size 0..
Replies: 2
Views: 304

Re: when queue size 0..

viewtopic.php?t=66435

Doesn’t look like it is working like the wiki says. But it is from 2010...
by 2frogs
Mon Apr 23, 2018 5:55 am
Forum: Beginner Basics
Topic: Question about using VLANs to set up a guest network [SOLVED]
Replies: 20
Views: 2657

Re: Question about using VLANs to set up a guest network [SOLVED]

EDIT: are you saying I should leave the cloud switch configuration as is?
No, move all port back to your main bridge on all device as there should only be the one bridge on your ap's and switch. The router is only device with a second bridge. And there should be only one cable to each device.
by 2frogs
Mon Apr 23, 2018 5:22 am
Forum: Beginner Basics
Topic: Question about using VLANs to set up a guest network [SOLVED]
Replies: 20
Views: 2657

Re: Question about using VLANs to set up a guest network [SOLVED]

It seems to me this has been made more complicated than it should be. On your AP in wireless setting, use vlan-mode=use-tag & vlan-id=10 and add this port to your main bridge (same bridge as the rest of your interfaces). Then on the router, add VLAN interface with interface=bridge (again, your main ...
by 2frogs
Mon Apr 23, 2018 2:05 am
Forum: Beginner Basics
Topic: Getting Plex to play nice with firewall rules
Replies: 19
Views: 2348

Re: Getting Plex to play nice with firewall rules

Input/Output is any traffic going to or coming from the router itself. Winbox, Webfig, VPN, DNS.... etc. The Forward chain is any traffic that gets forwarded from one interface to another. This includes not only traffic from your LAN to Internet, but also LAN to LAN. https://wiki.mikrotik.com/wiki/M...
by 2frogs
Mon Apr 23, 2018 1:58 am
Forum: General
Topic: Traffic route through Virtual Wifi (station) mode [SOLVED]
Replies: 18
Views: 1157

Re: Traffic route though Virtual Wifi (station) mode [SOLVED]

This is what I meant: /ip route add gateway=192.168.43.1 routing-mark=WAN add gateway=<ether1 IP address> routing-mark=WAN /ip firewall mangle add action=mark-routing chain=prerouting dst-address=!10.0.0.0/24 \ new-routing-mark=3G passthrough=no src-address=10.0.0.8 add action=mark-routing chain=pre...
by 2frogs
Mon Apr 23, 2018 1:36 am
Forum: Beginner Basics
Topic: Getting Plex to play nice with firewall rules
Replies: 19
Views: 2348

Re: Getting Plex to play nice with firewall rules

Firewall rules are processed in order by chain and the fewer firewall rules packets have to go through, the lower the cpu usage. Usually you want the rules that will match the most packets first and this usually the Accept Rules. The Established & Related, which can be combined, should be at the top...
by 2frogs
Sun Apr 22, 2018 11:01 pm
Forum: General
Topic: Traffic route through Virtual Wifi (station) mode [SOLVED]
Replies: 18
Views: 1157

Re: Traffic route though Virtual Wifi (station) mode [SOLVED]

Actually, if you are using the router for DNS, disabling all default routes will cause the router to not be able to resolve DNS. Add a route for ether1 with a routing mark and then add another mangle rule for the whole 10.0.0.0/24 with the same routing mark. And then re-enable the add default route ...
by 2frogs
Sun Apr 22, 2018 10:47 pm
Forum: General
Topic: Traffic route through Virtual Wifi (station) mode [SOLVED]
Replies: 18
Views: 1157

Re: Traffic route though Virtual Wifi (station) mode [SOLVED]

You need that second route. Try changing your mangle to
/ip firewall mangle
add action=mark-routing chain=prerouting dst-address=!10.0.0.0/24 \
    new-routing-mark=3G passthrough=no src-address=10.0.0.8
by 2frogs
Sun Apr 22, 2018 10:08 pm
Forum: General
Topic: Traffic route through Virtual Wifi (station) mode [SOLVED]
Replies: 18
Views: 1157

Re: Traffic route though Virtual Wifi (station) mode [SOLVED]

Post the result of
/ip route export
by 2frogs
Sun Apr 22, 2018 9:50 pm
Forum: Beginner Basics
Topic: Allow only one specified port to a LAN host
Replies: 8
Views: 667

Re: Allow only one specified port to a LAN host

Replace the action=accept with action=drop in last rule
Oppps! I corrected it.
by 2frogs
Sun Apr 22, 2018 9:48 pm
Forum: General
Topic: Traffic route through Virtual Wifi (station) mode [SOLVED]
Replies: 18
Views: 1157

Re: Traffic route though Virtual Wifi (station) mode [SOLVED]

In your dhcp-client, uncheck add default route. Now add your own route.
/ip route add gateway=192.168.43.1 routing-mark=3G
Assuming the phones hotspot ip is 192.168.43.1.
by 2frogs
Sun Apr 22, 2018 9:10 pm
Forum: Beginner Basics
Topic: Port forwarding - please help !
Replies: 29
Views: 2039

Re: Port forwarding - please help !

I would recommend adding an accept for input from address list before the default drop rule you disabled and re-enable it.
by 2frogs
Sun Apr 22, 2018 9:01 pm
Forum: Beginner Basics
Topic: Allow only one specified port to a LAN host
Replies: 8
Views: 667

Re: Allow only one specified port to a LAN host

/ip firewall filter add chain=forward src-address=192.168.88.100 out-interface=WAN protocol=tcp port=5900 action=accept add chain=forward src-address=192.168.88.100 out-interface=WAN protocol=udp port=5900 action=accept add chain=forward src-address=192.168.88.100 out-interface=WAN action=drop You ...
  • 1
  • 2