Community discussions

MikroTik App

Search found 1358 matches

by andriys
Thu Oct 15, 2020 9:13 pm
Forum: RouterBOARD hardware
Topic: hAP ac³
Replies: 22
Views: 1558

Re: hAP ac³

Do not mix up the antenna gain and the signal strength. When using a high gain antenna your router has to reduce tx power to stay withing the legal boundaries, so the max signal strength you get is the same. However the effective coverage is usually better, thanks to a better sensitivity on reception.
by andriys
Thu Oct 15, 2020 1:14 pm
Forum: Beginner Basics
Topic: How to send PM to other user (ie. privately contacting a user)? [SOLVED]
Replies: 17
Views: 2803

Re: How to send PM to other user (ie. privately contacting a user)? [SOLVED]

I noticed the PM is now disabled again. Was it that bad being enabled?
by andriys
Thu Oct 15, 2020 12:19 pm
Forum: RouterOS v7 BETA
Topic: 7.1. betta 2 RB4011iGS + Procurve 2810-24G (J9021A) = 10Mbit on Ethernet port
Replies: 4
Views: 302

Re: 7.1. betta 2 RB4011iGS + Procurve 2810-24G (J9021A) = 10Mbit on Ethernet port

Are you sure this is a 7.1beta specific problem? I.e. can you confirm there's no such problem with v6? Also please check you cables. From my own experience, these old HP 2810 series switches are very sensitive to even slight cabling problems, and fallback to 10M half-duplex (or does not work at all ...
by andriys
Sun Oct 11, 2020 4:06 pm
Forum: RouterBOARD hardware
Topic: Hex gr3 suddenly lost power
Replies: 5
Views: 268

Re: Hex gr3 suddenly lost power

If it's just 3 month old, is RMA an option?
by andriys
Fri Oct 09, 2020 1:02 pm
Forum: General
Topic: ECMP balancing sometimes breaks TCP connection
Replies: 9
Views: 392

Re: ECMP balancing sometimes breaks TCP connection

When a packet with destination 10.10.10.0/24 gets in the mikrotik router, ECMP computes a hash based on Source Address, Destination Address, Protocol, Source Port, Destination Port, and that decides whether the packet is sent to gateway 10.20.20.2 or 10.20.20.3, right? Not quite. According to this ...
by andriys
Thu Oct 08, 2020 1:02 pm
Forum: General
Topic: Why I can't download latest version RouterOS from mikrotik.com/download?
Replies: 8
Views: 282

Re: v6.47.4 [stable] is released!

Certificate is OK
Wrong certificate, erlinden was asking about the certificate from download.mikrotik.com, i.e. the one from the page giving the error.

P.S. This is getting pretty off-topic, I'm going to move this whole conversation into a separate thread... Done!
by andriys
Thu Oct 08, 2020 12:41 pm
Forum: General
Topic: Why I can't download latest version RouterOS from mikrotik.com/download?
Replies: 8
Views: 282

Re: v6.47.4 [stable] is released!

@Delsey Downloads work fine for me. I specifically tried the link from your screenshots, it works as expected, no certificate errors whatsoever.

This may be either a CDN problem in your region, or a sing of an ongoing attack (like MITM, DNS poisoning, etc).
by andriys
Thu Oct 08, 2020 11:27 am
Forum: General
Topic: Mikrotik routers - Firewall?
Replies: 9
Views: 409

Re: Mikrotik routers - Firewall?

OpenWRT on Mikrotik as a MetaRouter
Metarouter is not supported on hEX S (as well as any other model with SPI flash).
by andriys
Thu Oct 08, 2020 11:09 am
Forum: General
Topic: Why I can't download latest version RouterOS from mikrotik.com/download?
Replies: 8
Views: 282

Re: v6.47.4 [stable] is released!

mikrotik.com/dowload
Perhaps because you missed N in dowNload?
by andriys
Wed Oct 07, 2020 11:16 pm
Forum: Wireless Networking
Topic: Mikrotik Cat12 router
Replies: 1
Views: 138

Re: Mikrotik Cat12 router

Are you asking about Chateau LTE12? Beware that it is only compatible with RouterOS7, which is still beta (and will likely remain in beta for quite some time). Otherwise, I cannot think of any major drawbacks.
by andriys
Wed Oct 07, 2020 11:12 pm
Forum: General
Topic: Mikrotik routers - Firewall?
Replies: 9
Views: 409

Re: Mikrotik routers - Firewall?

I assume you are asking about hEX S (RB760iGS). That is a full-featured router running RouterOS. You can read more about the software here and here. It is pretty powerful and will likely cover most (if not all) your needs.
by andriys
Tue Oct 06, 2020 5:32 pm
Forum: Scripting
Topic: Mikrotik hotspot is unfriendly with Node.js [SOLVED]
Replies: 14
Views: 520

Re: Mikrotik hotspot is unfriendly with Node.js [SOLVED]

Is there any difficulties to implement an external link and provide access to a routerOS through API? Nothing too fancy. The API description is here . At the bottom of that page there is a list of third party clients in different languages. You should enable the API first in the /ip service menu, s...
by andriys
Tue Oct 06, 2020 4:26 pm
Forum: Scripting
Topic: Mikrotik hotspot is unfriendly with Node.js [SOLVED]
Replies: 14
Views: 520

Re: Mikrotik hotspot is unfriendly with Node.js [SOLVED]

And to your original question. Have you seen the Customizing Hotspot page on the wiki? Specifically, the "External authentication" section may be of interest to you. And if you don't feel like passing a (temporary) username/password pair in a redirect back to the router, you can consider doing manua...
by andriys
Tue Oct 06, 2020 4:01 pm
Forum: Scripting
Topic: Mikrotik hotspot is unfriendly with Node.js [SOLVED]
Replies: 14
Views: 520

Re: Mikrotik hotspot is unfriendly with Node.js [SOLVED]

I tried to open the link in Yandex with a VPN - eventually it's been opened. Well, Ukraine blocks a range of Russian's IP addresses who knows it might be the reason. Just checked, works fine for me. Tried opening that page via several ISPs here in Kharkiv, no problems at all. It's probably the brow...
by andriys
Mon Oct 05, 2020 11:06 am
Forum: Beginner Basics
Topic: Installation of hotspot fails
Replies: 1
Views: 199

Re: Installation of hotspot fails

Please check the /system package menu, the package may be installed, but disabled.
by andriys
Thu Sep 24, 2020 10:47 am
Forum: RouterBOARD hardware
Topic: hAP ac³ switch chip?
Replies: 11
Views: 1055

Re: hAP ac³ switch chip?

The Block Diagram for this device says the switch chip is QCA8327.
by andriys
Wed Sep 23, 2020 12:27 pm
Forum: General
Topic: IPSec - routing problem
Replies: 9
Views: 631

Re: IPSec - routing problem

1. routing
2. firewall
3. NAT
4. IPSec policy
This is a pretty incomplete sequence. Please see the packet flow diagrams
by andriys
Wed Sep 23, 2020 10:29 am
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 125
Views: 49990

Re: v6.48beta [testing] is released!

All I am saying is, that those who have enough switches that will benefit from a single management plane, will almost certainly need HA features to go with it. My friends have an office here with 200+ client ports, with all cable runs going into a single rack with five 48-port access switches (some...
by andriys
Mon Sep 21, 2020 9:49 pm
Forum: Beginner Basics
Topic: How to Setup hap ac2 are router w/o wifi
Replies: 3
Views: 179

Re: How to Setup hap ac2 are router w/o wifi

And once you do anything outside of QuickSet never attempt to use QuickSet again- that has a great potential of ruining your running configuration.
by andriys
Mon Sep 21, 2020 9:45 pm
Forum: General
Topic: CCR2004 poor bridge performance
Replies: 23
Views: 1110

Re: CCR2004 poor bridge performance

As far as I understand packets belonging to a single TCP stream are always bound to a single CPU core, no matter if it's routing or bridging. This is done to avoid packet reordering (which used to be a huge problem when CCR series devices were first introduced several years ago).
by andriys
Sat Sep 19, 2020 10:23 am
Forum: Beginner Basics
Topic: Port fowarding to unraid openvpn
Replies: 15
Views: 513

Re: Port fowarding to unraid openvpn

Screenshots are (almost) useless, please post configuration export (run /export hide-sensitive from the command line) instead.
by andriys
Thu Sep 10, 2020 9:01 am
Forum: General
Topic: slow speeds according to btest
Replies: 1
Views: 152

Re: slow speeds according to btest

btest itself is very heavy on CPU, this is a well known issue, which has nothing to do with the actual routing performance of your devices. Search the forum again, this has been discussed tons of times.
by andriys
Sat Jun 06, 2020 12:22 am
Forum: RouterOS v7 BETA
Topic: v7.0beta8 [development] is released!
Replies: 180
Views: 64927

Re: v7.0beta8 [development] is released!

What do I use then to get traffic data from each client that I do use in Splunk for MikroTik?
NetFlow is an obvious choice for that kind of data.
by andriys
Sun May 31, 2020 10:59 pm
Forum: Beginner Basics
Topic: Problems with hapac2 5ghz wifi is flapping
Replies: 7
Views: 1555

Re: Problems with hapac2 5ghz wifi is flapping

Sounds like a DFS (radar detection) in action. Check your logs to check if that is the case.
by andriys
Sun May 31, 2020 10:54 pm
Forum: General
Topic: capsman keep WiFi up when capsman unavailable?
Replies: 15
Views: 2735

Re: capsman keep WiFi up when capsman unavailable?

This will be a deal-breaker for MANY people, I'd go so far as to say for the majority of people. Not sure about the majority, we successfully use CAPsMAN in the office, where 24x7 is not a requirement, so that's not a deal breaker for us at all. But you are right, in some cases (like hotel installa...
by andriys
Sun May 31, 2020 10:44 pm
Forum: Wireless Networking
Topic: Any description of Beaforming occurrences debug information?
Replies: 11
Views: 2267

Re: Any description of Beaforming occurrences debug information?

Please read carefully https://forum.mikrotik.com/viewtopic.php?f=7&t=161563&p=796943#p796661 Right, I've read it again. Please find my comments on it below. So its either Beamforming or Spatial Multiplexing .... normally part of the wireless driver packaging Well... Yes, spatial multiplexing is the...
by andriys
Sat May 30, 2020 11:26 pm
Forum: Wireless Networking
Topic: Any description of Beaforming occurrences debug information?
Replies: 11
Views: 2267

Re: Any description of Beaforming occurrences debug information?

Nowhere did I state that Spatial Multiplexing is Beamforming .... grrrr
Then what was your reference to 802.11 and MIMO about?
by andriys
Sat May 30, 2020 10:03 pm
Forum: Wireless Networking
Topic: Any description of Beaforming occurrences debug information?
Replies: 11
Views: 2267

Re: Any description of Beaforming occurrences debug information?

Beamforming began to appear in routers back in 2008, with the advent of the 802.11n Wi-Fi standard. 802.11n was the first version of Wi-Fi to support multiple-input multiple-output, or MIMO, technology, which beamforming needs in order to send out multiple overlapping signals. Nope. Spatial multipl...
by andriys
Fri May 29, 2020 9:58 pm
Forum: Wireless Networking
Topic: Any description of Beaforming occurrences debug information?
Replies: 11
Views: 2267

Re: Any description of Beaforming occurrences debug information?

OP was asking specifically about 60G devices, where beamforming IS available (at least on some devices like wAP 60G).

On a broader term, MIMO neither implies nor requires beamforming. Only MU-MIMO does. And none of the Mikrotik devices currently support MU-MIMO, that is a well-known fact.
by andriys
Wed May 27, 2020 7:31 pm
Forum: Announcements
Topic: Winbox v3.24 released!
Replies: 106
Views: 57337

Re: Winbox v3.24 released!

I am running winbox (32-bit) under wine on a Debian system.
Maybe it behaves differently on a native Windows system?
Sounds plausible. I run Winbox (64-bit) natively on Win10. And (simply out of curiosity) I have just tested 32-bit version, which also works fine for me.
by andriys
Wed May 27, 2020 2:44 pm
Forum: Announcements
Topic: Winbox v3.24 released!
Replies: 106
Views: 57337

Re: Winbox v3.24 released!

open a window like "IP firewall filters" in a router that is in active use, and make sure the hit-counts of firewall rules are being displayed (and changing all the time). Now, position the mouse over a header separator and keep mouse button pressed to attempt to move the separator to set the colum...
by andriys
Mon May 25, 2020 12:17 am
Forum: General
Topic: 35(!) FATAL ERRORS inside the "MikroTik News" web page https://wiki.mikrotik.com/wiki/MikroTik_News
Replies: 2
Views: 790

Re: More than 40(!) FATAL ERRORS inside the "MikroTik News" web page ( https://wiki.mikrotik.com/wiki/MikroTik_News )

Au contraire. MK has a superior QC department. They created the "obsessive compulsive TRAP".
Looks like it found a victim already.
I like these a lot! Please keep posting! :)
by andriys
Sun May 24, 2020 12:09 pm
Forum: Wireless Networking
Topic: 4k over wifi
Replies: 35
Views: 5663

Re: 4k over wifi

Interesting!!! I have to dig deeper in this WMM. WMM priority when received over WLAN how is it marked? DSCP (TOS) or MKT priority? Have you seen this article on the wiki: https://wiki.mikrotik.com/wiki/Manual:WMM ? If the priority is maintained in the MKT, then with the default config only priorit...
by andriys
Thu May 21, 2020 1:37 pm
Forum: General
Topic: PPP - Active Connections - Old Connections Can't be Removed
Replies: 1
Views: 440

Re: PPP - Active Connections - Old Connections Can't be Removed

I struggled to find a Support section or separate Support forum
This is a community forum, for support please look here: https://mikrotik.com/support.
by andriys
Thu May 21, 2020 1:32 pm
Forum: RouterBOARD hardware
Topic: CRS326--CRS326, SFP+ only ~700mbit via 10gbit link. Slow performance or bottleneck?
Replies: 7
Views: 1570

Re: CRS326--CRS326, SFP+ only ~700mbit via 10gbit link. Slow performance or bottleneck?

Connection was plug-and-play, 10Gbit link speed is up, however winbox bandwidth test shows speeds lower than gigabit (500-750mbps). Your device is a switch. It can work as a router, but that router is pretty weak. Basically, while switch hardware is powerful enough to forward L2 traffic between all...
by andriys
Wed May 20, 2020 11:36 am
Forum: Announcements
Topic: Winbox v3.24 released!
Replies: 106
Views: 57337

Re: Winbox v3.24 released!

With Log window opened, minimize WinBox, then Restore. Log is always reverted to the beginning. Anyone else seeing this? Yes, the same here Just tried it on several routers, but only see this behavior on a single device. A differentiating factor appears to be the number of records kept in the log. ...
by andriys
Mon May 18, 2020 9:04 pm
Forum: General
Topic: IKEv2 site-2-site: Lost connection after 30 minutes [SOLVED]
Replies: 7
Views: 1513

Re: IKEv2 site-2-site: Lost connection after 30 minutes [SOLVED]

30 minutes sound like failed rekeying.
OP says phase 2 SA lifetime is 8h. Why would it rekey after just 30 minutes at all?
by andriys
Mon May 18, 2020 8:46 pm
Forum: Beginner Basics
Topic: VLAN Bridge - Trunk with Wireless Wire "bridge port received packet with own address"
Replies: 15
Views: 2356

Re: VLAN Bridge - Trunk with Wireless Wire "bridge port received packet with own address"

No, you should not ignore them. They most likely indicate a problem, but the reason is elsewhere.
by andriys
Mon May 18, 2020 8:28 pm
Forum: General
Topic: capsman keep WiFi up when capsman unavailable?
Replies: 15
Views: 2735

Re: capsman keep WiFi up when capsman unavailable?

What you want is not possible. In CAPsMAN it is manager that always handles client authentication, no matter what forwarding mode is in use. That's by design.
by andriys
Mon May 18, 2020 8:24 pm
Forum: Beginner Basics
Topic: VLAN Bridge - Trunk with Wireless Wire "bridge port received packet with own address"
Replies: 15
Views: 2356

Re: VLAN Bridge - Trunk with Wireless Wire "bridge port received packet with own address"

I found something on the second devide. On that bridge and ether1 got the same MAC-Adress.
That is normal, as expected, and is not the cause of your problem.
by andriys
Mon May 18, 2020 8:21 pm
Forum: RouterOS v7 BETA
Topic: V7 questions?
Replies: 34
Views: 7774

Re: V7 questions?

I need access to Linux for running own code written in C/C++ to implement the low-level part for an own high-performing advanced central firewall on switch devices (not router).
Good luck!.. :)
by andriys
Mon May 18, 2020 1:21 pm
Forum: Announcements
Topic: v6.45.9 [long-term] is released!
Replies: 83
Views: 63726

Re: v6.45.9 [long-term] is released!

just 7 days uptime, free memory down from 80Mb to 65Mb
That is not an indication of memory leak on its own. Does the memory usage keep growing? How does it look over time? Do you have a graph to show?
by andriys
Sun May 17, 2020 8:59 pm
Forum: Beginner Basics
Topic: Removing VLAN 0 802.1p tags on CRS112?
Replies: 3
Views: 820

Re: Removing VLAN 0 802.1p tags on CRS112?

I don't know if it is possible to strip the priority tags on your switch, but am very curious why do you need to do that at all?
by andriys
Sat May 16, 2020 6:11 pm
Forum: Beginner Basics
Topic: Access a device Mikrotik
Replies: 4
Views: 1158

Re: Access a device Mikrotik

Provided I understood what you mean by "remotely" correctly, you cannot in general do that. Addressing any device by its MAC address is only possible within its own broadcast domain (i.e. "local network"). Having said that, if you have another RouterOS powered device in the same network, you can use...
by andriys
Sat May 16, 2020 6:03 pm
Forum: General
Topic: No internet via non-main routing tables if missing default route on main [SOLVED]
Replies: 21
Views: 2937

Re: No internet via non-main routing tables if missing default route on main [SOLVED]

However I suppose that my question still stands though, about why adding a bogus default gateway to main routing table, corrects the timeouts? Sorry, what I wrote above describes rp-filter=strict , not loose . I have just edited my message to correct this. For loose to pass packet it is only necess...
by andriys
Sat May 16, 2020 3:23 pm
Forum: General
Topic: No internet via non-main routing tables if missing default route on main [SOLVED]
Replies: 21
Views: 2937

Re: No internet via non-main routing tables if missing default route on main [SOLVED]

Ok, it's pretty clear what's going on now. Your routing works as expected. It is not your outgoing ICMP echo-request packets (pings) that are being mis-routed and/or discarded, but rather incoming ICMP echo-reply packets get rejected by your rp-filter . The rp-filter=strict works by checking if the ...
by andriys
Sat May 16, 2020 2:23 pm
Forum: Beginner Basics
Topic: RB960PGS-PB output power conversion
Replies: 3
Views: 658

Re: RB960PGS-PB output power conversion

I would like an official answer from the mikrotik support This is a community forum, please write to support@ directly if you need an "official answer". From the product description it would seem a simple passtrought of the power supply, therefore the conversion does not take place and it is not po...
by andriys
Sat May 16, 2020 2:11 pm
Forum: Wireless Networking
Topic: Mikrotik AC Access Point cap ac
Replies: 38
Views: 5714

Re: Mikrotik AC Access Point cap ac

I have no time or interest dog this dead horse (my Cap AC) at the moment, but I'll keep monitoring this forum, as maybe some posts their helpful findings Yes, just keep monitoring. Your other message (now removed) has been reported as a personal assault, and I find that report legitimate. So now yo...
by andriys
Sat May 16, 2020 2:02 pm
Forum: The Dude
Topic: Issues installing The Dude
Replies: 8
Views: 1545

Re: Issues installing The Dude

1. Package upgrade and install on all SPI-flash devices is always done in RAM. You should always upload all .npk files to the root directory, not /flash. 2. What's the point in installing The Dude server on your switch? It has only 16MB flash and no options for external storage (like USB port or SD ...
by andriys
Sat May 16, 2020 1:05 pm
Forum: Wireless Networking
Topic: No 5GHz on cAP ac
Replies: 3
Views: 646

Re: No 5GHz on cAP ac

Please reset your wlan2 interface to defaults with /interface wireless reset-configuration wlan2 , then change just two parameters- set country to the proper value and frequency to 5180 (due to DFS requirements, when frequency is set tot 5260 or higher you will have to wait for at least 1 minute [an...
by andriys
Sat May 16, 2020 12:56 pm
Forum: Wireless Networking
Topic: Mikrotik AC Access Point cap ac
Replies: 38
Views: 5714

Re: Mikrotik AC Access Point cap ac

Almost any Chinese device cost less then Mikrotik and performs better.
Please, please, please, go buy one and stop complaining here! It is cheaper and works better for you, so what's the point in doing what you are doing?
by andriys
Sat May 16, 2020 12:53 pm
Forum: Wireless Networking
Topic: Mikrotik AC Access Point cap ac
Replies: 38
Views: 5714

Re: Mikrotik AC Access Point cap ac

I'm wondering are these success stories false or why in this forum and also other forums contain more problems than praises? You do understand that happy users do not generally spend their time writing to forums how satisfied they are, don't you? They just use their devices. Unhappy ones come here ...
by andriys
Sat May 16, 2020 11:39 am
Forum: General
Topic: Custom --log-level in firewall rules or filtering on log file actions...
Replies: 2
Views: 655

Re: Custom --log-level in firewall rules or filtering on log file actions...

I'd use log-prefix as a differentiator, then do the actual filtering of the messages on the syslog server.
by andriys
Fri May 15, 2020 9:21 pm
Forum: Beginner Basics
Topic: Metal5SHPn-US on a sailboat...
Replies: 3
Views: 765

Re: Metal5SHPn-US on a sailboat...

Since the model of my Metal is missing the 2 (5SHPn and not a 52SHP-n) can I safely assume it is not capable of 2.4Ghz?
Yes, that's correct. Your device is 5GHz only.
More product specs here: https://mikrotik.com/product/RBMetal5SHPn
by andriys
Fri May 15, 2020 9:15 pm
Forum: The Dude
Topic: Issues installing The Dude
Replies: 8
Views: 1545

Re: Issues installing The Dude

What's in the log after reboot?
Also are you installing The Dude client or The Dude server?
by andriys
Fri May 15, 2020 6:05 pm
Forum: Wireless Networking
Topic: [SOLVED] Wi-Fi Broadcast ARP/UDP unexpectedly throttled/blocked
Replies: 15
Views: 2687

Re: Wi-Fi Broadcast ARP/UDP unexpectedly throttled/blocked

Players on the same Wi-Fi can always see each other.
Can you elaborate on this "same Wi-Fi" thing please? Do you mean associated with the same CAP in your CAPsMAN?
by andriys
Fri May 15, 2020 4:40 pm
Forum: Wireless Networking
Topic: [SOLVED] Wi-Fi Broadcast ARP/UDP unexpectedly throttled/blocked
Replies: 15
Views: 2687

Re: Wi-Fi Broadcast ARP/UDP unexpectedly throttled/blocked

Did you happen to disable the default-forwarding property on your wireless interface? Or forwarding property for a particular client via access list? Just guessing...
by andriys
Fri May 15, 2020 1:39 pm
Forum: Beginner Basics
Topic: [Swich + router] configuration
Replies: 7
Views: 1237

Re: [Swich + router] configuration

What are your speed requirements? The easiest way to configure what you want is to use two bridges, but you device can only have one hardware-accelerated bridge. If your WAN is relatively slow I'd say go this way, with LAN bridge with hardware acceleration and WAN bridge in software. Another way wou...
by andriys
Wed May 13, 2020 11:48 am
Forum: RouterOS v7 BETA
Topic: List of devices which will run v7?
Replies: 3
Views: 1565

Re: List of devices which will run v7?

There are plenty of other devices (including pretty powerful ones) with a small 16M flash. The problems with upgrading hAP lite are due to its RAM size, not flash.
by andriys
Tue May 12, 2020 6:31 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 125
Views: 14411

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Those are general routing and firewall facilities, not really related to wireless. In case you are satisfied with the (wired) routing performance, I don't think tweaking those will make any difference for you. But you can try, of course, and see/decide for yourself.
by andriys
Tue May 12, 2020 3:07 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 125
Views: 14411

Re: Wi-Fi performance bad on RB4011 - possible misconfig

This seems work in some conditions only, at least for me the 20/40 Ce gives better speed than 20 only.
You wrote in another thread, that you don't have neighbors nearby and that the spectrum is free from other networks at your place. So, of course if does!
by andriys
Tue May 12, 2020 2:46 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 125
Views: 14411

Re: Wi-Fi performance bad on RB4011 - possible misconfig

I did not state that you could not use 20MHz channel with MIMO .... You did, actually. Let me cite you: To get performance the MIMO client and MIMO server must talk MIMO and that means at minimum 2 x 2 streams .... not 1x2 or 1x1 ... but 2x2 .... in MikroTik speak streams = chains. so if you want b...
by andriys
Tue May 12, 2020 2:29 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 125
Views: 14411

Re: Wi-Fi performance bad on RB4011 - possible misconfig

so my contribution here is to state that 2.4Ghz 20Mhz channel width is absolutely wrong WRONG wrong from a performance perspective and from a MIMO perspective. How does one relate to another? :) You can use 20MHz channel and still use MIMO. All those spatial streams operate in the same channel(s).
by andriys
Tue May 12, 2020 1:19 am
Forum: Announcements
Topic: v6.45.9 [long-term] is released!
Replies: 83
Views: 63726

Re: v6.45.9 [long-term] is released!

Lastly, are you able to upgrade firmware on your wAP ac normally.
Absolutely. Upgraded RouterOS on all 8 units from CAPsMAN, and once they all came back online rebooted once again to upgrade RouterBOOT (they all have /system routerboard settings set auto-upgrade=yes). All went smoothly.
by andriys
Tue May 12, 2020 12:03 am
Forum: Announcements
Topic: v6.45.9 [long-term] is released!
Replies: 83
Views: 63726

Re: v6.45.9 [long-term] is released!

MTeeker That must be something specific to your particular unit. We have 8 wAP ac units here also running as CAPs, successfully upgraded all of them to 6.45.9 from 6.45.8 two days ago (both RouterOS and RouterBOOT), no problems so far. You wrote "Back down to Stable V6.46.6", so I guess you tried s...
by andriys
Mon May 11, 2020 7:14 pm
Forum: RouterBOARD hardware
Topic: 10 GIG version of HEX
Replies: 7
Views: 1599

Re: 10 GIG version of HEX

by andriys
Mon May 11, 2020 12:58 am
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 125
Views: 14411

Re: Wi-Fi performance bad on RB4011 - possible misconfig

Looking at the registration table, which client should I look at? At the one you use for testing. For example my phone which is quite far away from the router has: -60dbm Signal Strength and RX rate 585Mbps Tx rate 351Mbps, but still speedtest shows around 150Mbps speed. - Analyze the whole TX/RX-r...
by andriys
Sun May 10, 2020 11:33 pm
Forum: Beginner Basics
Topic: Hap ac2 second Wireless interface not working
Replies: 5
Views: 966

Re: Hap ac2 second Wireless interface not working

It reappeared later on after a reboot and then disappeared again.
Sounds like a DFS (radar detection) in action. What's the interface status?
by andriys
Sun May 10, 2020 8:33 pm
Forum: Wireless Networking
Topic: Wi-Fi performance bad on RB4011 - possible misconfig
Replies: 125
Views: 14411

Re: Wi-Fi performance bad on RB4011 - possible misconfig

What's your client device? It is possible that the speed is limited by the capabilities of your client, not the AP.
Can you show what's in the registration table (/interface wireless registration-table print stats) during the test?
by andriys
Sun May 10, 2020 1:41 pm
Forum: Wireless Networking
Topic: [SOLVED] Wi-Fi Broadcast ARP/UDP unexpectedly throttled/blocked
Replies: 15
Views: 2687

Re: Wi-Fi Broadcast ARP/UDP unexpectedly throttled/blocked

Or does it re-send every broadcast/multicast packet to every connected client? Yes, it does. I thought that the "convert multicast to unicast" thing that some other manufacturers do will only handle multicast in conjunction with the IGMP snooping that they do As far as I know, Mikrotik implemented ...
by andriys
Sun May 10, 2020 1:37 pm
Forum: Beginner Basics
Topic: Recommendation for CAPsMAN router device
Replies: 4
Views: 1005

Re: Recommendation for CAPsMAN router device

How much traffic (including inter-VLAN communication) are you going to route?
by andriys
Sat May 09, 2020 6:16 pm
Forum: Wireless Networking
Topic: [SOLVED] Wi-Fi Broadcast ARP/UDP unexpectedly throttled/blocked
Replies: 15
Views: 2687

Re: Wi-Fi Broadcast ARP/UDP unexpectedly throttled/blocked

The only thing that I would add to what pe1chl already said is that broadcast traffic in wireless networks is always sent using the basic data rate (i.e. the slowest allowed data rate for the given network), so sending a lot of broadcast traffic will significantly degrade the performance of the whol...
by andriys
Sat May 09, 2020 1:18 pm
Forum: Wireless Networking
Topic: CapsMan with mikrotik Vs Wireless mikrotik only?
Replies: 21
Views: 2951

Re: CapsMan with mikrotik Vs Wireless mikrotik only?

In my cause my country Not Found with list, So i selected the Installation "indoor" Those two (country and installation type) are complementary, meaning that installation type does not work at all without country being specified. I guess when running your AP without CAPsMAN your obvious choice was ...
by andriys
Sat May 09, 2020 12:40 pm
Forum: Wireless Networking
Topic: CapsMan with mikrotik Vs Wireless mikrotik only?
Replies: 21
Views: 2951

Re: CapsMan with mikrotik Vs Wireless mikrotik only?

You don't need to put anything in there, the max allowed is used by default.
by andriys
Fri May 08, 2020 1:45 pm
Forum: Wireless Networking
Topic: Cap AC wifi speed is terrible bad.
Replies: 80
Views: 11730

Re: Cap AC wifi speed is terrible bad.

Just a couple of messages above you said you are not an expert in wireless and complained that WiFi does not work as expected out of the box. And now you complain about advanced configuration options no being available. Are you just trolling? Edit: PS. And, by the way, band steering is an ugly hack,...
by andriys
Thu May 07, 2020 6:51 pm
Forum: Announcements
Topic: v6.45.9 [long-term] is released!
Replies: 83
Views: 63726

Re: v6.45.9 [long-term] is released!

*) chr - fixed graceful shutdown execution on Hyper-V (introduced in v6.46);
How comes 6.45.9 contains a fix for something introduced in 6.46? In case the bug was "backported" from 6.46 it would be good to know what 6.45.x versions are affected.
by andriys
Tue May 05, 2020 10:03 pm
Forum: Beginner Basics
Topic: CRS112 traffic slow issue, with negotiation?
Replies: 8
Views: 1713

Re: CRS112 traffic slow issue, with negotiation?

Check your cables.
by andriys
Tue May 05, 2020 7:07 pm
Forum: Beginner Basics
Topic: CRS112 traffic slow issue, with negotiation?
Replies: 8
Views: 1713

Re: CRS112 traffic slow issue, with negotiation?

Anyone know why gigabit ethernet would not work with auto-negotiate disabled? My understanding is that for 1G (and faster) copper links it is not only connection speed that needs to be negotiated, but also the line needs to be tested and some other TX/RX parameters then needs to be negotiated and/o...
by andriys
Tue May 05, 2020 6:55 pm
Forum: General
Topic: VLAN Tagging CPU Load
Replies: 6
Views: 1337

Re: VLAN Tagging CPU Load

IIRC, VLAN tagging is a software-based operation.
Not necessarily. Lots of switches out there do in hardware.

These devices don't have switch chips.
Which devices?
by andriys
Tue May 05, 2020 1:58 pm
Forum: General
Topic: CCR1072 running out of CPU, what next for a PPPoE ISP?
Replies: 10
Views: 1236

Re: CCR1072 running out of CPU, what next for a PPPoE ISP?

The rules defining the simple queues are matched like firewall rules, one by one from the top until first match, for every single packet, so it may slow down the packet processing significantly. It used to be the case in RouterOS v5, but since early v6 it is not the case anymore. Simple queues are ...
by andriys
Mon May 04, 2020 9:19 pm
Forum: Beginner Basics
Topic: 'Lost' default MAC address
Replies: 47
Views: 5724

Re: 'Lost' default MAC address

2. The only Winbox facility on the MikroTik webpage I downloaded was software
What software? WinBox itself? WinBox is just a configuration tool for RouterOS powered devices. You cannot use it for anything else. :)
by andriys
Mon May 04, 2020 5:42 pm
Forum: General
Topic: RouterOS identifies CCR1009-7G-1C-1S+PC as CCR1009-7G-1C-1S+ [SOLVED]
Replies: 3
Views: 1287

Re: RouterOS identifies CCR1009-7G-1C-1S+PC as CCR1009-7G-1C-1S+ [SOLVED]

I believe it is normal. I've just check a CCR1009-8G-1S-1S+-PC of mine, it is also reported to be CCR1009-8G-1S-1S+ in RouterOS.
by andriys
Mon May 04, 2020 1:41 pm
Forum: Wireless Networking
Topic: hap AC2
Replies: 5
Views: 1356

Re: hap AC2

When searching for the network, make sure you are using wlan2 interface on you hAP ac².
by andriys
Mon May 04, 2020 12:35 pm
Forum: Wireless Networking
Topic: Cap AC wifi speed is terrible bad.
Replies: 80
Views: 11730

Re: Cap AC wifi speed is terrible bad.

Faulty unit, perhaps.
I have two, tested one (see results above), works as expected. My environment is moderately crowded.
by andriys
Mon May 04, 2020 12:03 pm
Forum: Wireless Networking
Topic: Cap AC wifi speed is terrible bad.
Replies: 80
Views: 11730

Re: Cap AC wifi speed is terrible bad.

but link is free, and I'm the only user.
It's wireless. I.e. it uses shared medium and is pretty susceptible to interference. So, you never know when it is really free...
by andriys
Sun May 03, 2020 9:44 pm
Forum: Beginner Basics
Topic: mikrotik x 2 - one address in the LAN
Replies: 24
Views: 3273

Re: mikrotik x 2 - one address in the LAN

@miloxdan, You do not configure wireless interfaces on either of your devices. You first configure CAPsMAN (the manager) on one of them, then enable CAP mode for all wireless interfaces on both. SSID, security profile, channels, etc. - everything is configured in a single place (on the manager). Hav...
by andriys
Sun May 03, 2020 9:23 pm
Forum: Beginner Basics
Topic: mikrotik x 2 - one address in the LAN
Replies: 24
Views: 3273

Re: mikrotik x 2 - one address in the LAN

so how do seamless roaming work
SCA (Single Channel Architecture). Basically the whole network "pretends" to be a single AP, so there's no roaming from the wireless client point of view at all.
And it has nothing to do with "enterprise wifi networks".
by andriys
Sun May 03, 2020 9:19 pm
Forum: Beginner Basics
Topic: WAN Access Webfig with HTTPS
Replies: 2
Views: 818

Re: WAN Access Webfig with HTTPS

Is that possible to Access Webfig with HTTPS Get yourself a certificate for your domain, import it on your Mikrotik device, then enable "www-ssl" service with the following command: /ip service set [ find name="www-ssl" ] disabled=no certificate="<cert_name>" You may also need to adjust your firewa...
by andriys
Sun May 03, 2020 6:58 pm
Forum: Beginner Basics
Topic: mikrotik x 2 - one address in the LAN
Replies: 24
Views: 3273

Re: mikrotik x 2 - one address in the LAN

that is, the access list to delete? I also have a delay of 3-5 seconds without an access list. Roaming is always a client's responsibility. If your client devices are old and cannot roam nicely there's nothing you can do on the AP side to improve that (except, possibly, switching to another brand t...
by andriys
Sun May 03, 2020 6:18 pm
Forum: Beginner Basics
Topic: mikrotik x 2 - one address in the LAN
Replies: 24
Views: 3273

Re: mikrotik x 2 - one address in the LAN

in your setup, probably worth trying to setup access list on the APs, so it actively disconnect the client , instead of waiting for the client device to disconnect This is the worst ever advice, but people still keep suggesting it over and over again... When you forcibly disconnect a client you are...
by andriys
Sun May 03, 2020 6:13 pm
Forum: General
Topic: Moving config from RB951G-2HnD to RB4011
Replies: 19
Views: 2881

Re: Moving config from RB951G-2HnD to RB4011

I can put the config up here if the problem is not obvious.
Please, do it.
by andriys
Sun May 03, 2020 3:24 pm
Forum: Beginner Basics
Topic: Slowness for the first few seconds then fast on download
Replies: 17
Views: 2792

Re: Slowness for the first few seconds then fast on download

That pic is pretty useless, as it hides too many of the essential bits of configuration. If you want/need to share your configuration you should post the output of the /export hide-sensitive command instead.
by andriys
Sun May 03, 2020 12:30 am
Forum: Wireless Networking
Topic: Cap AC wifi speed is terrible bad.
Replies: 80
Views: 11730

Re: Cap AC wifi speed is terrible bad.

If anyone is still interested, I had some free time today, so I got one of my cAP ac s off the shelf and did some tests. The device was updated to 6.46.6, configuration was reset, then I configured it as an AP (not router) and ran some tests. I am consistently getting about 90/90 on my mobile and ab...
by andriys
Sun May 03, 2020 12:22 am
Forum: Beginner Basics
Topic: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]
Replies: 56
Views: 7561

Re: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]

This is really confusing b/c my device is in Bridge Mode (all interfaces in same one bridge), and I have the said use-ip-firewall setting not enabled, and I have placed my firewall stuff under "/ip firewall filter", but the firewall is still functioning (!), (although not that perfect, or even corr...
by andriys
Sat May 02, 2020 1:28 pm
Forum: General
Topic: Problem Hardware Offload on CRS326-24G-2S+
Replies: 4
Views: 965

Re: Problem Hardware Offload on CRS326-24G-2S+

You have two bridges, and currently only a single bridge can be hardware-offloaded on CRS3xx series devices. This is clearly documented here.

Why do you need two separate bridges?
by andriys
Fri May 01, 2020 11:16 pm
Forum: General
Topic: VPN Tunnel [SOLVED]
Replies: 7
Views: 2027

Re: VPN Tunnel [SOLVED]

Andriys i've tried your advice but it doesn't anything.
Please confirm you placed your new policy before/above the old one. The order of policies is important.
by andriys
Fri May 01, 2020 8:30 pm
Forum: General
Topic: VPN Tunnel [SOLVED]
Replies: 7
Views: 2027

Re: VPN Tunnel [SOLVED]

The source and destination networks in your IPsec policy overlap. That does not look good to me, and also explains why you cannot ping gateway. The easiest solution will be to exclude your local network from the tunnel with the following command (make sure this new policy is placed above your existi...
by andriys
Fri May 01, 2020 7:35 pm
Forum: General
Topic: VPN Tunnel [SOLVED]
Replies: 7
Views: 2027

Re: VPN Tunnel [SOLVED]

My telepath is not available right now, sorry. :)
Please post your current configuration (/ip ipsec export hide-sensitive), otherwise nobody will be able to help you.
by andriys
Fri May 01, 2020 7:29 pm
Forum: Beginner Basics
Topic: What is the Best Practice for detecting/preventing unauthorized devices in LAN?
Replies: 24
Views: 3180

Re: What is the Best Practice for detecting/preventing unauthorized devices in LAN?

@andriys, you have got the terminology of client wrong No, I have not. You were talking about RADIUS client . That has nothing to do with supplicant and other IEEE 802.1X stuff. Strictly speaking, RADIUS is not even a requirement for 802.1X, any other protocol capable of encapsulating EAP can theor...
by andriys
Fri May 01, 2020 7:21 pm
Forum: General
Topic: MAC telnet from terminal stopped working in new versions
Replies: 10
Views: 2767

Re: MAC telnet from terminal stopped working in new versions

The authentication procedure changed significantly in 6.43. That change affects everything, including MAC-server. I am not aware of any third-party MAC-telnet clients that are compatible with the new versions of RouterOS.
by andriys
Fri May 01, 2020 7:13 pm
Forum: Wireless Networking
Topic: hap ac lite can't connect to another AP
Replies: 21
Views: 3495

Re: hap ac lite can't connect to another AP

i'm not that expert on this "low level" networking stuff as i'm not doing it for a living. it's quite complicated. Well, you insisted on something that's impossible in reality being "the core operation mode for wifi". I tried to explain why that assertion is not true. in the meantime i tried: -stat...
by andriys
Fri May 01, 2020 6:54 pm
Forum: Beginner Basics
Topic: What is the Best Practice for detecting/preventing unauthorized devices in LAN?
Replies: 24
Views: 3180

Re: What is the Best Practice for detecting/preventing unauthorized devices in LAN?

You are getting it wrong. RADIUS is just a protocol, RADIUS server is (to a great extent) just a special credentials database. Is it possible with RADIUS to authenticate with these 2 or 3 credentials: MAC and/or IP plus a password for the device/interface itself, but without involving/managing/using...
by andriys
Fri May 01, 2020 6:20 pm
Forum: Wireless Networking
Topic: hap ac lite can't connect to another AP
Replies: 21
Views: 3495

Re: hap ac lite can't connect to another AP

is this some new limitation with new ac devices? No, it is a fundamental limitation of the whole set of 802.11 protocol suite. it's the core operation mode for wifi equipment. No, it is not. of course we can bridge interfaces, and use wifi in station mode. Bridging is essentially a way to forward t...
by andriys
Fri May 01, 2020 5:47 pm
Forum: General
Topic: cAP ac reset not possible after netinstall
Replies: 6
Views: 1649

Re: cAP ac reset not possible after netinstall

That's why i tryed to delete tho whole Thread. Obviously without any luck.
Would you like me to delete it for you? :)
by andriys
Fri May 01, 2020 5:30 pm
Forum: Beginner Basics
Topic: Slowness for the first few seconds then fast on download
Replies: 17
Views: 2792

Re: Slowness for the first few seconds then fast on download

We haven't seen the actual configuration that OP uses, so the following is just a wild guess. Some packets are still going slow path even for fasttracked connections, that's why documentation says that an explicit "accept" rule for otherwise fasttracked connections is a requirement. Potential absenc...
by andriys
Fri May 01, 2020 5:20 pm
Forum: General
Topic: Moving config from RB951G-2HnD to RB4011
Replies: 19
Views: 2881

Re: Moving config from RB951G-2HnD to RB4011

Do you use certificates in your CAPsMAN and VPN configuration? Certificates are not part of the exportable configuration and should be copied separately.
by andriys
Fri May 01, 2020 1:40 pm
Forum: General
Topic: Feature request: IPSec Lifetime in second integer format
Replies: 2
Views: 918

Re: Feature request: IPSec Lifetime in second integer format

What you want is already possible via both WinBox and CLI. I'm a bit surprise you cannot do that in WebFig. As a workaround, I'd suggest you switching to a Terminal view in WebFig and adding your IPsec profiles and proposals from there.
by andriys
Fri May 01, 2020 1:34 pm
Forum: General
Topic: can't connect to hEX S after factory reset / netinstall
Replies: 8
Views: 1526

Re: can't connect to hEX S after factory reset / netinstall

Have you tried connecting by MAC?
Can you see your device on the "Neighbors" tab on Login dialog in WinBox?
by andriys
Thu Apr 30, 2020 11:58 pm
Forum: Wireless Networking
Topic: hap ac lite can't connect to another AP
Replies: 21
Views: 3495

Re: hap ac lite can't connect to another AP

This does not change the fact that the DHCP Client should get an IP address without problems... Have a look at the screenshots posted- DHCP client is on the bridge interface, so (provided DHCP server is only accessible over wireless) there's no way it will work. As for the station-pseudobridge, sho...
by andriys
Thu Apr 30, 2020 11:31 pm
Forum: Wireless Networking
Topic: hap ac lite can't connect to another AP
Replies: 21
Views: 3495

Re: hap ac lite can't connect to another AP

it's station mode
...
all interfaces are in bridge.
You cannot bridge wireless interface in station mode. You can configure that, obviously, but it won't work. Try using station-pseudobridge (or station-pseudobridge-clone), but beware of the limitations.
by andriys
Thu Apr 30, 2020 9:40 pm
Forum: Wireless Networking
Topic: Audience in USA - 160mhz WLAN3
Replies: 12
Views: 2937

Re: Audience in USA - 160mhz WLAN3

On the Audience in the united states3 country setting, the only available frequencies for WLAN3 are 5745-5825. Audience has two separate 5G radios. One can only operate in 5180-5320, whereas the other can only operate in 5500-5825. You cannot use 160MHz on wlan3, but you may have better luck on wla...
by andriys
Thu Apr 30, 2020 12:49 pm
Forum: General
Topic: Slow speed through gre+ipsec tunnel
Replies: 11
Views: 3760

Re: Slow speed through gre+ipsec tunnel

Same behaviour observed in CCR1072 and a few dozen IPsec tunnels in a road warrior configuration Your case is apparently different. The original problem reported here was about GRE+IPsec combination (and it was even mentioned later that EoIP+IPsec is unaffected). Yours is road-warrior case, and so ...
by andriys
Thu Apr 30, 2020 12:33 pm
Forum: Beginner Basics
Topic: Slowness for the first few seconds then fast on download
Replies: 17
Views: 2792

Re: Slowness for the first few seconds then fast on download

but the catch was CPU would hit 40% and sometime higher on my RB4011.
What's the problem with that?
by andriys
Wed Apr 29, 2020 9:56 pm
Forum: General
Topic: Fasttrack not working.
Replies: 18
Views: 3243

Re: Fasttrack not working.

Hey, man, don't you have nothing else interesting to do but "nerving" people with such IMO childish nitpickings? :-) You posted to this thread cross-referencing your other thread. They have similar topics, but otherwise are completely unrelated. Before posting here you even failed to notice that th...
by andriys
Mon Apr 27, 2020 9:20 pm
Forum: Wireless Networking
Topic: Wifi power hap ap2?
Replies: 3
Views: 1269

Re: Wifi power hap ap2?

+10dBm means 10x more (and -10dBm means 10x less).
That's logarithmic scale, so +3dBm approx means twice as much (-3dBm approx twice as little).
Conversion tables and online calculators can be googled easily.
by andriys
Mon Apr 27, 2020 8:23 pm
Forum: Wireless Networking
Topic: Wifi power hap ap2?
Replies: 3
Views: 1269

Re: Wifi power hap ap2?

Check the "Wireless specifications" table on the product page out. You are asking about the values in the "Transmit" column (27dBm == 500mW).
by andriys
Mon Apr 27, 2020 6:24 pm
Forum: Useful user articles
Topic: ipsec vpn, routing through tunnel and wake tunnel
Replies: 3
Views: 1707

Re: ipsec vpn, routing through tunnel and wake tunnel

1) I am unable to ping device from a terminal session on the Mikrotik, I am unable to work out what the profess of routing packets from within the Mikrotik to have then directed to the VPN. I have created a NAT run to accept the packets as routed and thus not NAT them. But I am getting nowhere. IPs...
by andriys
Wed Apr 15, 2020 6:13 pm
Forum: General
Topic: Authentication & Accounting interim-update=5m
Replies: 2
Views: 1298

Re: Authentication & Accounting interim-update=5m

This is not Mikrotik-specific stuff, you could have just google before asking. Even wikipedia knows what RADIUS interim updates are. And it is not applicable to authorization, by the way, it is purely accounting-related.
by andriys
Wed Apr 15, 2020 12:22 pm
Forum: Scripting
Topic: Why command "fetch" doesn't wait for output?
Replies: 5
Views: 2013

Re: Why command "fetch" doesn't wait for output?

However, the fetch command does not wait for "OK".
It does. You don't see it in console because the result goes to file by default. RTFM here, please: Tools/Fetch.
As to checking what was returned, read this section specifically: Return value to a variable.
by andriys
Tue Apr 14, 2020 9:55 pm
Forum: General
Topic: Cannot establish IKEV1 tunnel to Cisco ASA 5516x
Replies: 1
Views: 1034

Re: Cannot establish IKEV1 tunnel to Cisco ASA 5516x

Please have a look at this thread: https://forum.mikrotik.com/viewtopic.php?f=2&t=159475. I believe that should be a good starting point in understanding the basics. For your situation, however, it is going to be more like a traditional road-warrior, not lan-to-lan VPN. So in comparison to what's di...
by andriys
Mon Apr 13, 2020 1:33 pm
Forum: Beginner Basics
Topic: P2p check box in RouterOS v6.46.5
Replies: 1
Views: 981

Re: P2p check box in RouterOS v6.46.5

The p2p matcher is no longer supported. It had not been really working for a long time and was finally completely removed in RouterOS 6.39 (almost 3 years ago).
by andriys
Mon Apr 13, 2020 11:36 am
Forum: Beginner Basics
Topic: Collecting daily/monthly usage stats?
Replies: 8
Views: 2907

Re: Collecting daily/monthly usage stats?

Also have look at IP Accounting.
by andriys
Mon Apr 13, 2020 11:26 am
Forum: Beginner Basics
Topic: Broken routing to 192.x.x.x IP addresses [SOLVED]
Replies: 4
Views: 2547

Re: Broken routing to 192.x.x.x IP addresses [SOLVED]

Don't try to change network, instead you should change your address to 192.168.88.1/24 (note /24 instead of /8 at the end).
by andriys
Mon Apr 13, 2020 10:46 am
Forum: Beginner Basics
Topic: PPPoE connection painfully slow on CRS109-8G router
Replies: 8
Views: 2023

Re: PPPoE connection painfully slow on CRS109-8G router

Faulty unit, perhaps. You wrote previously that it's firmware had previously "gone belly up". That incident and the unit's current slowness may as well have common roots.
by andriys
Sat Apr 11, 2020 11:18 pm
Forum: General
Topic: Mikrotik vpn with ikev1 set up
Replies: 13
Views: 3070

Re: Mikrotik vpn with ikev1 set up

Any quick easy set up guide for a generic IKEv1 setup? Good luck finding one! IKEv1 is so versatile it's impossible to write a guide that would cover all and every case possible. Once you know how IPsec works, it becomes pretty straightforward to configure an arbitrary tunnel. But you need to spent ...
by andriys
Sat Apr 11, 2020 5:18 pm
Forum: General
Topic: Severe port flapping on CRS328-24P-4S+ and CRS317-1G-16S+
Replies: 192
Views: 38456

Re: Severe port flapping on CRS328-24P-4S+ and CRS317-1G-16S+

Hey Mikrotik guys, where are you?
This is user forum. Support replies in some topics occasionally, but there's not guarantee they reply to your particular message. If you are looking for an official reply you should contact support@ and/or you supplier/distributor directly.
by andriys
Sat Apr 11, 2020 3:20 pm
Forum: Beginner Basics
Topic: Can you bridge a WLAN working as WAN with an ethernet interface
Replies: 21
Views: 3452

Re: Can you bridge a WLAN working as WAN with an ethernet interface

Well, there cannot be other way how it works. For proper bridging to work your AP and your station bridge should exchange frames with 4 MAC addresses (source, destination, sender, receiver), whereas the standard frame for station to AP communication contains only 3 MACs (because source and sender ar...
by andriys
Sat Apr 11, 2020 2:54 pm
Forum: Beginner Basics
Topic: Can you bridge a WLAN working as WAN with an ethernet interface
Replies: 21
Views: 3452

Re: Can you bridge a WLAN working as WAN with an ethernet interface

So, what would it be the Mikrotik equivalent? Station-bridge mode? No. Your ISP router is not a RouterOS-powered devices, as far I understand, so station-bridge won't work for you as expected. The only viable option is station-pseudobridge. I'm sure DD-WRT does the same, unless it talks to another ...
by andriys
Sat Apr 11, 2020 1:51 pm
Forum: RouterOS v7 BETA
Topic: mangle and routing-mark can not work for RouterOS v7
Replies: 9
Views: 3259

Re: mangle and routing-mark can not work for RouterOS v7

Have a look at the following two threads, you may find answers to your question there:
viewtopic.php?f=1&t=152314
viewtopic.php?f=1&t=154149
by andriys
Sat Apr 11, 2020 1:35 pm
Forum: Beginner Basics
Topic: Can you bridge a WLAN working as WAN with an ethernet interface
Replies: 21
Views: 3452

Re: Can you bridge a WLAN working as WAN with an ethernet interface

https://www.linksysinfo.org/index.php?threads/diffrence-between-client-and-client-bridge-mode.13563/ It seems that a DD-WRT router can do what a Mikrotik can't. Really? Your link talks about wireless in "client" mode vs wireless in "client-transparent-bridge" mode on DD-WRT. And that you can bridge...
by andriys
Sat Apr 11, 2020 1:31 pm
Forum: Beginner Basics
Topic: Can you bridge a WLAN working as WAN with an ethernet interface
Replies: 21
Views: 3452

Re: Can you bridge a WLAN working as WAN with an ethernet interface

Ofcorse you can add a wireless interface in Station mode inside your Bridge in case lets say you want to assign the address to the Bridge and not to just your wireless interface...
Why would one need to do that? What's the point?
by andriys
Sat Apr 11, 2020 12:44 am
Forum: Beginner Basics
Topic: Can you bridge a WLAN working as WAN with an ethernet interface
Replies: 21
Views: 3452

Re: Can you bridge a WLAN working as WAN with an ethernet interface

You cannot bridge wireless interface in station mode. You can, however, do that if you change the mode to station-bridge or station-pseudobridge . Please be aware, though, that these modes have their own limitation. You can read more about various wireless station modes on the wiki here: Wireless St...
by andriys
Sat Apr 11, 2020 12:34 am
Forum: General
Topic: Configuring ipsec on the cisco asa
Replies: 24
Views: 4196

Re: Configuring ipsec on the cisco asa

Is that all? Yep, that should be it. The new IPsec Policies - Status SA Src. Address: 0.0.0.0 Not to pay attention ? For a newly create policy that's normal. It should be changed to the real address once an SA for that policy is established (and that won't happen until the first packet matching tha...
by andriys
Fri Apr 10, 2020 5:58 pm
Forum: General
Topic: SIP Through IPSEC VPN Site to Site drops calls randomly
Replies: 30
Views: 5234

Re: SIP Through IPSEC VPN Site to Site drops calls randomly

Does your PBX write logs? Is there anything interesting in the logs?
What is the indicated termination cause for the dropped calls in question?
by andriys
Fri Apr 10, 2020 2:26 pm
Forum: Announcements
Topic: v6.46.5 [stable] is released!
Replies: 72
Views: 28837

Re: v6.46.5 [stable] is released!

[*]Unable to see skip DFS. Looked in wireless but where is it hiding? It is available in command line only, no support in WinBox nor WebFig yet. And next time you post something, would mind reading the whole thread to check if you question has already been answered , please? [*]At least on 5.8, whe...
by andriys
Fri Apr 10, 2020 1:54 pm
Forum: General
Topic: Configuring ipsec on the cisco asa
Replies: 24
Views: 4196

Re: Configuring ipsec on the cisco asa

NAT Traversal do not need to set? Is the dynamic IP on your Mikrotik routeable (i.e. "real")? In case it is NAT traversal is not needed. It stood for 5 minutes and earned. Now I'm trying to understand why. Probably was waiting for the first outgoing ESP packet from your Mikrotik. Check your firewal...
by andriys
Fri Apr 10, 2020 1:17 pm
Forum: General
Topic: Configuring ipsec on the cisco asa
Replies: 24
Views: 4196

Re: Configuring ipsec on the cisco asa

It seems to me that the NO NAT rules on Mikrotik are missing. Yep, that's what I meant when I wrote "make sure you have NAT-exempt rules in place". In terminal run the following: /ip firewall nat add place-before=0 chain=srcnat action=accept src-address=192.168.88.0/24 dst-address=192.168.x.0/24
by andriys
Fri Apr 10, 2020 11:35 am
Forum: General
Topic: Configuring ipsec on the cisco asa
Replies: 24
Views: 4196

Re: Configuring ipsec on the cisco asa

I don’t know how to change the level of detail through WinBox. I turn it on. On command line it would be /system logging add topics=ipsec,!packet,!debug action=remote . Should not be difficult to figure out how to do that in WinBox. host(send ping) - mikrotik ==== inet==== asa - host (answer ping) ...
by andriys
Fri Apr 10, 2020 10:41 am
Forum: Announcements
Topic: v6.46.5 [stable] is released!
Replies: 72
Views: 28837

Re: v6.46.5 [stable] is released!

In my country, in Ukraine, the U-NII-3 range is allowed, but there is no U-NII-3 range in the frequency list
It seems to be marked for outdoor use only here. Please change installation parameter to outdoor or any and see if those frequencies reappear.
by andriys
Thu Apr 09, 2020 11:49 pm
Forum: General
Topic: Configuring ipsec on the cisco asa
Replies: 24
Views: 4196

Re: Configuring ipsec on the cisco asa

Log attachments. ASA log looks good. Mikrotik log looks weird. First, please turn ipsec debug logging off, it's too noisy to be useful. Second, I noticed timestamps differ dramatically in ASA and Mikrotik logs. Why is that? IPsec Policy Status PH2 State: established Looks good. Ping to a remote net...
by andriys
Thu Apr 09, 2020 8:39 pm
Forum: General
Topic: Configuring ipsec on the cisco asa
Replies: 24
Views: 4196

Re: Configuring ipsec on the cisco asa

Well, that explains. That "software connections" dynamic-map entry does not have "match address" specified, so it matches everything. And it is of higher priority because of a lower sequence. So your ASA picks this dynamic map and expects ESP-3DES-SHA to be proposed, which does not match the ESP-AES...
by andriys
Thu Apr 09, 2020 5:21 pm
Forum: General
Topic: What is breaking my IPSec ?
Replies: 15
Views: 2934

Re: What is breaking my IPSec ?

Have you checked what's in the logs? Mind sharing it here?
by andriys
Thu Apr 09, 2020 3:34 pm
Forum: General
Topic: Configuring ipsec on the cisco asa
Replies: 24
Views: 4196

Re: Configuring ipsec on the cisco asa

Yes, I have other lan-to-lan tunnels to different static addresses and I can see how they get through. It seems to me that there is a search for subnets 192.168.x.0 192.168.88.0. But why not see: I'd interpret your ASA logs as "I see you have a matching dynamic map, but none of the proposals config...
by andriys
Tue Apr 07, 2020 12:39 pm
Forum: Beginner Basics
Topic: New Router buy
Replies: 13
Views: 2670

Re: New Router buy

The question still remains the same: is HAP Lite (or HAP ac Lite) worth the while for my needs? And, mostly, will this small devices handle with no hassle my connections? With some rather basic configuration hAP lite will cope with your 100M connection without problem (and the number of users does ...
by andriys
Mon Apr 06, 2020 8:41 pm
Forum: Beginner Basics
Topic: New Router buy
Replies: 13
Views: 2670

Re: New Router buy

I looked at both HAP Lite and HAP ac (which prices just double of HAP Lite). Double? It is actually about 6x more expensive. Are you sure you wrote the model names correctly? Anyways, in case you are looking for the cheapest device then hAP lite (or hAP lite TC ) should be fine. Otherwise I'd sugge...
by andriys
Mon Apr 06, 2020 7:50 pm
Forum: General
Topic: Fighting spam with a standard firewall
Replies: 10
Views: 2071

Re: Fighting spam with a standard firewall

Is something like this going to go?
Yep
by andriys
Mon Apr 06, 2020 3:44 pm
Forum: Beginner Basics
Topic: configure wAP 60G AP as repeater
Replies: 1
Views: 1100

Re: configure wAP 60G AP as repeater

Repeater mode is not supported for 60G, I believe.
by andriys
Mon Apr 06, 2020 3:42 pm
Forum: General
Topic: Fighting spam with a standard firewall
Replies: 10
Views: 2071

Re: Fighting spam with a standard firewall

Simply block port 25/tcp for all customers, only whitelist it for specific customers upon request. Nobody needs it nowadays, except a few people still running mail servers on premises.
by andriys
Mon Apr 06, 2020 12:56 pm
Forum: Scripting
Topic: How to collect statistics about VPN connections?
Replies: 4
Views: 1471

Re: How to collect statistics about VPN connections?

How does your RADIUS server stores the accounting information? Is there an option to store it in a relational DB? You would then be able to use simple SQL queries for aggregation and reporting.
by andriys
Mon Apr 06, 2020 12:28 pm
Forum: Scripting
Topic: How to collect statistics about VPN connections?
Replies: 4
Views: 1471

Re: How to collect statistics about VPN connections?

I would use RADIUS accounting to collect such statistics.
by andriys
Mon Apr 06, 2020 11:54 am
Forum: General
Topic: crs3xx - bridge filter - hw offloading?
Replies: 5
Views: 1738

Re: crs3xx - bridge filter - hw offloading?

Thanks, you may be right. But I'd be glad if @support will comment on this too...
Well, you should write to support then.
This is a user forum, consider yourself lucky if you get a response from them here on the forum. :)
by andriys
Mon Apr 06, 2020 11:40 am
Forum: General
Topic: Different Rate Between Firewall and Torch
Replies: 3
Views: 1299

Re: Different Rate Between Firewall and Torch

Please post the full /ip firewall filter export output. The order of the rules is important. The traffic you are watching may match another rule that is placed earlier than the one you are watching.
by andriys
Sun Apr 05, 2020 10:07 pm
Forum: Wireless Networking
Topic: How to connect a hap ac2 to an ISP router via wifi [SOLVED]
Replies: 16
Views: 4186

Re: How to connect a hap ac2 to an ISP router via wifi [SOLVED]

Can I do without it? I thought that NAT was necessary to separate my LAN (192.168.4.0/24) from ISP router's (192.168.0.0/24) Yes, you can. But you need to add a static route on your ISP router so it knows where to forward traffic destined to your 192.168.4.0/24 network to. Can I bridge the wireless...
by andriys
Sun Apr 05, 2020 2:54 pm
Forum: Wireless Networking
Topic: How to connect a hap ac2 to an ISP router via wifi [SOLVED]
Replies: 16
Views: 4186

Re: How to connect a hap ac2 to an ISP router via wifi [SOLVED]

So, if I have more than one client, station mode is the only reliable way to go in my case. Did I get it right? Yes, you got it right. What if I want just one client being connected to the ISP router via WIFI? In this case station-pseudobridge or station-pseudobridge-clone will work for you just fi...
by andriys
Sun Apr 05, 2020 1:32 pm
Forum: Wireless Networking
Topic: How to connect a hap ac2 to an ISP router via wifi [SOLVED]
Replies: 16
Views: 4186

Re: How to connect a hap ac2 to an ISP router via wifi [SOLVED]

Provided you have more then one client behind your Mikrotik router, you cannot really do that, unless your ISP router is also a Mikrotik product (in which case station-bridge mode is what you are looking for). Well, the station-pseudobridge mode may appear to work for you, but I doubt that MAC addre...
by andriys
Sun Apr 05, 2020 1:17 pm
Forum: Wireless Networking
Topic: How to connect a hap ac2 to an ISP router via wifi [SOLVED]
Replies: 16
Views: 4186

Re: How to connect a hap ac2 to an ISP router via wifi [SOLVED]

What would you like to achieve in the end?
by andriys
Sun Apr 05, 2020 12:25 pm
Forum: Beginner Basics
Topic: Auto reboot and alert if Mikrotik loses 4G signal
Replies: 3
Views: 1233

Re: Auto reboot and alert if Mikrotik loses 4G signal

The easiest thing you can do is to configure Watchdog to reboot your device when ping to a specific host stops working. Depending on what IP you choose to ping, however, that has a potential disadvantage of producing a lot of false positives. A somewhat more sophisticated way is to use Netwatch inst...
by andriys
Sat Apr 04, 2020 9:32 pm
Forum: Beginner Basics
Topic: mark-able package and filter
Replies: 1
Views: 1133

Re: mark-able package and filter

In short- you cannot.
by andriys
Sat Apr 04, 2020 8:39 pm
Forum: Wireless Networking
Topic: hAP AC2+cAP AC Roaming is a joke [SOLVED]
Replies: 69
Views: 23862

Re: hAP AC2+cAP AC Roaming is a joke [SOLVED]

Thats what a good source has told me... Am i wrong? Yes, you are. Release 6.35 wireless-rep - initial support for station roaming for station mode in 802.11 protocol; That has nothing to do with 802.11r. That was just the initial implementation of the ordinary roaming for mode=station. Before that ...
by andriys
Sat Apr 04, 2020 8:14 pm
Forum: Wireless Networking
Topic: hAP AC2+cAP AC Roaming is a joke [SOLVED]
Replies: 69
Views: 23862

Re: hAP AC2+cAP AC Roaming is a joke [SOLVED]

Mikrotik does support IEEE 802.11r-2008, fast Roaming, since 6.35 or something...
Really?
by andriys
Sat Apr 04, 2020 8:08 pm
Forum: Wireless Networking
Topic: cAP ac (wifi repeater) - issues with bandwidth
Replies: 21
Views: 3791

Re: cAP ac (wifi repeater) - issues with bandwidth

Can I do some additional tweaks/config or this is the expected bandwidth for this device?
This is kinda expected for a repeater, no matter what kind of device you are using.
by andriys
Sat Apr 04, 2020 7:51 pm
Forum: General
Topic: Configuring ipsec on the cisco asa
Replies: 24
Views: 4196

Re: Configuring ipsec on the cisco asa

Shared passwords (group passwords) are used for both L2L and RA IPsec VPNs (unless you are using certificate-base authentication for IKE, which you are not). On Mikrotik that's secret under /ip ipsec identity . Group name goes to my-id under the same menu. If you are configuring this from WinBox the...
by andriys
Sat Apr 04, 2020 12:28 pm
Forum: Beginner Basics
Topic: "Verify DoH Certificate" option [SOLVED]
Replies: 4
Views: 3795

Re: "Verify DoH Certificate" option [SOLVED]

Please learn how to use search on the forum. Your question has been asked and answered multiple times already.
by andriys
Sat Apr 04, 2020 10:34 am
Forum: General
Topic: Configuring ipsec on the cisco asa
Replies: 24
Views: 4196

Re: Configuring ipsec on the cisco asa

I understand that you must use the mode Aggressive on Mikrotik. <snip> Therefore, the tunnel initiator can only be Mikrotik. This mode is called Aggressive. Well, yes, yes and no. You are right in that that Aggressive mode is a requirement and that your Mikrotik box should always be initiator. Howe...
by andriys
Fri Apr 03, 2020 9:23 pm
Forum: General
Topic: Configuring ipsec on the cisco asa
Replies: 24
Views: 4196

Re: Configuring ipsec on the cisco asa

This is wrong: tunnel-group MT type ipsec-l2l For tunnel group of type ipsec-l2l the group name must be the peer's IP address. Check ASA's command reference for details. As I said in my previous message, since your another endpoint has dynamic IP address you have to use a road-warrior-like tunnel co...
by andriys
Fri Apr 03, 2020 2:52 pm
Forum: Beginner Basics
Topic: Dual GateWay!
Replies: 2
Views: 1303

Re: Dual GateWay!

I need Combined Two Speed , I Read about that but all solutions just load balancing. That's because load-balancing is the only thing you can do with your 2 channels, really... I mean you cannot use your two channels as a single "fat" channel, the only thing you can do is to distribute your traffic ...
by andriys
Fri Apr 03, 2020 1:03 pm
Forum: RouterBOARD hardware
Topic: RBD52G-5HacD2HnD auto negotiation problem [SOLVED]
Replies: 8
Views: 4699

Re: RBD52G-5HacD2HnD auto negotiation problem [SOLVED]

Auto-negotiation is mandatory in 1000BASE-T, various weird things are expected to happen if you try to turn it off.
by andriys
Fri Apr 03, 2020 12:56 pm
Forum: General
Topic: Configuring ipsec on the cisco asa
Replies: 24
Views: 4196

Re: Configuring ipsec on the cisco asa

isakmp policy is just half of the phase1 configuration, please show your cryptopmap configuration from ASA as well. Also please post the output of /ip ipsec export hide-sensitive from your Mikrotik. On a general note, since IP address on one side of you channel is dynamic (may change) you will have ...
by andriys
Fri Mar 27, 2020 1:15 pm
Forum: General
Topic: RB951N bug mikrotik DO DDOS attack
Replies: 2
Views: 982

Re: RB951N bug mikrotik DO DDOS attack

I can hardly read your Runglish... Try using proper Russian without any traces of slang before feeding it to Google translate (or whatever else you are using). Anyways. You wrote the firmware is current, however your screenshot says you are running RouterOS version 6.30.4. That is very far from bein...
by andriys
Thu Mar 26, 2020 3:04 pm
Forum: Scripting
Topic: HIDE USER
Replies: 7
Views: 2314

Re: HIDE USER

I don't wanna to see that message again.
Try blocking those connections using firewall filter rules instead.
by andriys
Thu Mar 26, 2020 2:11 pm
Forum: Scripting
Topic: HIDE USER
Replies: 7
Views: 2314

Re: HIDE USER

Your screenshot says connections were denied. So what's the problem?
by andriys
Thu Mar 26, 2020 12:34 pm
Forum: General
Topic: VLAN between two MT.
Replies: 4
Views: 1444

Re: VLAN between two MT.

I need guide how to configure this and where (in bridge section, in swich)
For your device this will be in both bridge and switch menus. Check out examples here: https://wiki.mikrotik.com/wiki/Manual:B ... witch_chip.
by andriys
Thu Mar 26, 2020 11:59 am
Forum: Wireless Networking
Topic: licenc ap mode
Replies: 5
Views: 1790

Re: licenc ap mode

If you only need to connect your two units together, then use bridge mode instead of ap-bridge . The former is limited to a single associated client, but they are the same otherwise (read more here ). In case you need to connect more than one client, however, you should buy proper hardware. The cost...
by andriys
Thu Mar 26, 2020 10:49 am
Forum: Announcements
Topic: Winbox v3.22 released!
Replies: 117
Views: 50811

Re: Winbox v3.22 released!

Or maybe, why is the legacy mode insecure? In legacy mode server identity validation is not implemented, thus making MITM attacks possible even if "Secure Mode" is enabled. The current implementation of the WinBox protocol was reported to use a flavor of SRP, so identity validation is now always mu...
by andriys
Wed Mar 25, 2020 6:43 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 125484

Re: v6.47beta [testing] is released!

All major web servers support TLS 1.3 already. Browsers too. It is NOT in the future. It's already being rolled out. It has started since 2018. You keep talking about TLS 1.3 whereas you really mean ESNI. TLS 1.3 is a requirement for ESNI, but not the other way round. Enabling ESNI for a particular...
by andriys
Fri Mar 20, 2020 3:51 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 125484

Re: v6.47beta [testing] is released!

@ErfanDL, it looks like you still need a "conventional" DNS server for bootstrapping...
by andriys
Tue Mar 17, 2020 10:40 pm
Forum: Announcements
Topic: Winbox v3.22 released!
Replies: 117
Views: 50811

Re: Winbox v3.22 released!

emils What's new in v3.22: *) added Legacy Mode (disabled by default) to allow using older, less secure connections to RouterOS older than v6.43; I still must run WinBox 6.4 for manage old ROS v5.26 who cannot be upgraded to v6.x family. What is WinBox 6.4? Anyways, RouterOS 5 requires WinBox DLLs ...
by andriys
Mon Mar 16, 2020 9:04 pm
Forum: Announcements
Topic: MikroTik newsletter March 2020 (#94)
Replies: 40
Views: 32634

Re: MikroTik newsletter March 2020 (#94)

  • HAP AC2 with 802.3af poe-input support (as cap ac does)
And at least one pass-through poe-out port please.
cAP ac? Almost the same hardware (well, without USB and with only 2 Ethernet ports), but with 802.3af/at and PoE pass-through. And has already been available for a while...
by andriys
Mon Dec 02, 2019 8:58 am
Forum: Beginner Basics
Topic: Disk Space changed from 128M to 16M [SOLVED]
Replies: 5
Views: 1235

Re: Disk Space changed from 128M to 16M [SOLVED]

Well, RB750 (first screenshot), RB750Gr2 (second screenshot) and RB750r2 (third screenshot) are three different models with distinct specs. The RB750Gr2 and RB750r2 have always had only 16MB available.
by andriys
Wed Nov 27, 2019 5:48 pm
Forum: General
Topic: Add DNS over HTTPS (DoH) support
Replies: 135
Views: 96198

Re: Add DNS over HTTPS (DoH) support

The only way I see is for RoS to intoduce DoH support and transparently resolve using DoH enabled DNS servers. DoH uses HTTP S as a transport, so transparent redirects are not gonna be possible. [*]DNS requests are not secure . DoH has nothing to do with security . Really nothing. Some believe it h...
by andriys
Wed Nov 27, 2019 5:34 pm
Forum: RouterBOARD hardware
Topic: can't login to MQS [SOLVED]
Replies: 3
Views: 6442

Re: can't login to MQS [SOLVED]

That PDF describes the behavior of the latest MQS firmware. Your device may have an older version installed (mine had). The default IP address and DHCP server settings may be different. Check what's specified in the printed material shipped with your particular device.
by andriys
Wed Nov 27, 2019 1:02 pm
Forum: RouterOS v7 BETA
Topic: how add multiple route tables, route rules in v7 beta [SOLVED]
Replies: 12
Views: 5522

Re: how add multiple route tables, route rules in v7 beta [SOLVED]

Yep, +1 for separate parameters. When being separate, parameters are somewhat self-documenting. At the very least it is immediately obvious the thing actually exists in this case.
by andriys
Wed Nov 13, 2019 1:52 pm
Forum: General
Topic: Is WPS supposed to work on RB MQS in AP mode? [SOLVED]
Replies: 5
Views: 1175

Re: Is WPS supposed to work on RB MQS in AP mode? [SOLVED]

Ok, I've just got a response from support.

They say that indeed MQS does not have a WPS server, only client. They also promised to amend the configuration UI (either renaming the WPS option or disabling it when in the AP mode) so it does not cause confusion.
by andriys
Mon Nov 11, 2019 8:02 pm
Forum: General
Topic: Is WPS supposed to work on RB MQS in AP mode? [SOLVED]
Replies: 5
Views: 1175

Re: Is WPS supposed to work on RB MQS in AP mode? [SOLVED]

To be clear what I'm asking about here... The MQS (RBMQS) is a "sysadmin helper"- an ESP32-based device, running its own (FreeRTOS-based?) firmware that does not appear to have anything in common with RouterOS. I ve not tested in an MQS to be honest but i don't see why it should not work... It may s...
by andriys
Mon Nov 11, 2019 6:00 pm
Forum: General
Topic: Is WPS supposed to work on RB MQS in AP mode? [SOLVED]
Replies: 5
Views: 1175

Is WPS supposed to work on RB MQS in AP mode? [SOLVED]

The question is basically in the subject. I've just got an RB MQS to play with. The available configuration options make me think WPS is there, but it does not appear to work in AP mode for me. I have noticed that in the default configuration WPS is only available in M2 (station mode) and is not ena...
by andriys
Sun Nov 10, 2019 5:30 pm
Forum: RouterOS v7 BETA
Topic: ROS 7 Wireless?
Replies: 19
Views: 8213

Re: ROS 7 Wireless?

Is it only me who thinks that a wAP ac is way more mature than a cAP ac?
No, you are not alone in this.
by andriys
Sun Nov 10, 2019 3:14 pm
Forum: Wireless Networking
Topic: NV2 licensing? Do any android/iOS device support NV2?
Replies: 8
Views: 2060

Re: NV2 licensing? Do any android/iOS device support NV2?

Actually I want to replace DECT cordless phones...
DECT means short range / indoors, right? What kind of problems are you going to solve using NV2 indoors?
by andriys
Sat Nov 09, 2019 3:26 pm
Forum: RouterOS v7 BETA
Topic: Poll: who wants to have a better /export ?
Replies: 17
Views: 4849

Re: Poll: who wants to have a better /export ?

I've voted for exporting certificates and SSH keys since, as Sob already pointed out, they are a significant part of the configuration, and I'd like them to be available when comparing different configuration revisions. However I'm completely with mada3k here in that only the public keys should be e...
by andriys
Mon Oct 21, 2019 11:42 pm
Forum: Wireless Networking
Topic: ARM devices and NV2 protocol
Replies: 622
Views: 95671

Re: ARM devices and NV2 protocol

hidden nodes
You do know about RTS/CTS and that it is off by default, right?
by andriys
Tue Oct 15, 2019 1:14 pm
Forum: Wireless Networking
Topic: CAPsMAN 5G and 2G network at same time
Replies: 11
Views: 3203

Re: CAPsMAN 5G and 2G network at same time

I would not recommend doing that at all. You force the client to roam when it is not yet ready to, and so make the switchover rather noticeable for the vast majority of clients. And doing so also means the clients leaving your zone of coverage will be out of service sooner.
by andriys
Mon Oct 14, 2019 11:46 pm
Forum: Announcements
Topic: v6.45.6 [stable] is released!
Replies: 59
Views: 43533

Re: v6.45.6 [stable] is released!

contact support, system failure, please send supout file to mikrotik support.
Have you done that already?
by andriys
Sat Oct 12, 2019 3:22 pm
Forum: General
Topic: Radius proxy
Replies: 1
Views: 801

Re: Radius proxy

Moved to "General" as "RouterOS v7 BETA" section is only for problem reporting.
See viewtopic.php?f=1&t=152006.
by andriys
Sat Oct 05, 2019 12:27 am
Forum: Wireless Networking
Topic: NV3
Replies: 125
Views: 20858

Re: NV3

@scampbell, Wireless Advanced Channels feature has a rather limited applicability, meaning just a small number of (mostly outdated) boards support it. Just check this out: Wireless hardware table.
by andriys
Fri Oct 04, 2019 6:15 pm
Forum: RouterBOARD hardware
Topic: Does CRS328-24P-4S+RM support 24v passive poe?
Replies: 20
Views: 6100

Re: Does CRS328-24P-4S+RM support 24v passive poe?

I installed some of these CRS328's on a site that already had wAPACs. They OVERHEATED and crashed a lot on 802.3af/at I have 4 wAP ac units powered by CRS328-24P-4S+RM which have been running just fine for months already. As of this writing the uptime of all the units is over 82 days, and the switc...
by andriys
Thu Oct 03, 2019 10:38 pm
Forum: Beginner Basics
Topic: Several isolated networks
Replies: 34
Views: 5844

Re: Several isolated networks

If I read the documentation correctly, the DNS servers that are statically configured under /ip dns are never used by DHCP server, however dynamic ones (i.e. those set by DHCP client, PPPoE client, etc) are. And this behavior can also be suppressed by setting dns-none option for a particular /ip dhc...
by andriys
Thu Oct 03, 2019 6:48 pm
Forum: General
Topic: configuration transfer from crs125 to crs326
Replies: 8
Views: 1411

Re: configuration transfer from crs125 to crs326

CRS3xx series devices differ a lot from the rest of CRS series devices. Here are some references to read:

Bridge Hardware Offloading
CRS3xx series switches manual
by andriys
Thu Oct 03, 2019 5:27 pm
Forum: Wireless Networking
Topic: station bridge / pseudobridge when bridges only 1 ip gets through
Replies: 7
Views: 2059

Re: station bridge / pseudobridge when bridges only 1 ip gets through

@Zacharias, station-bridge does not work with CAPsMAN controlled APs, that's the main problem OP is facing here. @genesispro, When the CAPsMAN was first introduced several years ago, I do remember multiple people asking about support of WDS, station-bridge, etc. here on the forum. If I understood th...
by andriys
Thu Oct 03, 2019 4:37 pm
Forum: General
Topic: configuration transfer from crs125 to crs326
Replies: 8
Views: 1411

Re: configuration transfer from crs125 to crs326

/export the existing configuration to a file, edit it if needed, then apply it to the new device. Read this: RouterOS Configuration Management . PS. If you have anything configured in the /switch menu on CRS125, you will not be able to transfer that to CRS326 automatically. Instead, you will have t...
by andriys
Thu Oct 03, 2019 4:33 pm
Forum: Wireless Networking
Topic: station bridge / pseudobridge when bridges only 1 ip gets through
Replies: 7
Views: 2059

Re: station bridge / pseudobridge when bridges only 1 ip gets through

What you described is indeed how station-pseudobridge works. These limitations are fundamental for the underlying wireless protocol stack. The station-bridge mode, on the other hand, should not have such limitations, however it only work when AP also runs Mikrotik RouterOS, and is not compatible wit...
by andriys
Thu Oct 03, 2019 1:07 pm
Forum: General
Topic: Extend dynamic VLANs to Wireless 802.1x
Replies: 5
Views: 1847

Re: Extend dynamic VLANs to Wireless 802.1x

Isn't this what you are looking for: Wireless / VLAN tagging?
by andriys
Wed Oct 02, 2019 9:17 pm
Forum: Beginner Basics
Topic: Slow Connection
Replies: 5
Views: 837

Re: Slow Connection

Post you current configuration. Also check what /tool profile shows at the time you test the speed.
by andriys
Wed Oct 02, 2019 9:14 pm
Forum: General
Topic: Vlan untagged and priority tagged doubt [SOLVED]
Replies: 2
Views: 1265

Re: Vlan untagged and priority tagged doubt [SOLVED]

where it says "and priority tagged", what does that means?
That means a packet with 802.1Q header that has VLAN ID field set to 0 (a reserved value that means VLAN ID is unspecified); however PCP and DEI fields are still in effect specifying priority, hence the name of the option.
by andriys
Wed Oct 02, 2019 12:22 pm
Forum: Virtualization
Topic: CHR - Firmware Upgrade [SOLVED]
Replies: 4
Views: 4229

Re: CHR - Firmware Upgrade [SOLVED]

Well, the error message clearly says that it's license that prevents the upgrade. And the only license preventing the upgrade is the expired trial. I'd suggest checking the license status and then writing to support@.
by andriys
Wed Oct 02, 2019 12:10 pm
Forum: Announcements
Topic: v6.46beta [testing] is released!
Replies: 150
Views: 76660

Re: v6.46beta [testing] is released!

after installing the latest beta to a RBM33G the RB is stuck in a reboot loop.
Such reports are kinda useless, unless you also specify what RouterOS version you were using before the upgrade.
by andriys
Wed Oct 02, 2019 12:06 pm
Forum: Virtualization
Topic: CHR - Firmware Upgrade [SOLVED]
Replies: 4
Views: 4229

Re: CHR - Firmware Upgrade [SOLVED]

The error message says it all. Once your trial period is over you can no longer upgrade your instance. You should have bought a suitable license (or switched to the free license, in case you are fine with its limitations) before the trial ends. See CHR Licensing.
by andriys
Wed Oct 02, 2019 11:54 am
Forum: RouterBOARD hardware
Topic: Connect serial port with ups usb
Replies: 3
Views: 1824

Re: Connect serial port with ups usb

I'm almost certain it's not possible. Certainly not possible with passive adapters.
by andriys
Wed Oct 02, 2019 12:11 am
Forum: General
Topic: Traffice Flow
Replies: 2
Views: 777

Re: Traffice Flow

TrafficFlow does not produce anything human-readable. You need a separate specialized software, usually called NetFlow Collector or NetFlow Analyzer, to collect, aggregate and display traffic flow data.

As a much simpler alternative, you can also consider using /ip accounting.
by andriys
Wed Oct 02, 2019 12:02 am
Forum: General
Topic: ROS updates to be put on homepage?
Replies: 4
Views: 1009

Re: ROS updates to be put on homepage?

I usually monitor the Announcements section of this forum for information about new releases. This is one of the first places the announcements are posted to most of the time. Another reason to monitor the forum for release announcements is it is usually a good idea to wait for possible regression r...
by andriys
Tue Oct 01, 2019 11:49 pm
Forum: General
Topic: IPSec Side-to-Side with Multiple Routen
Replies: 1
Views: 656

Re: IPSec Side-to-Side with Multiple Routen

An obvious alternative is some kind of tunneling protocol (like GRE) over IPsec.
But I still usually prefer to use pure policy-based IPsec whenever possible. What kind of software/hardware do your clients use?
by andriys
Tue Oct 01, 2019 11:40 pm
Forum: General
Topic: OVPN perfomance in v7
Replies: 1
Views: 841

Re: OVPN perfomance in v7

Renamed and moved to "General" as "RouterOS v7 BETA" section is only for problem reporting.
See viewtopic.php?f=1&t=152006.
by andriys
Tue Oct 01, 2019 3:36 pm
Forum: General
Topic: MFA for Mikrotik VPN
Replies: 3
Views: 1094

Re: MFA for Mikrotik VPN

AFAIK, it is not possible when using built-in authentication, however should be possible with some external RADIUS servers.
by andriys
Tue Oct 01, 2019 3:32 pm
Forum: The Dude
Topic: cAP ac for the dude server??
Replies: 3
Views: 2356

Re: cAP ac for the dude server??

cAP ac has only 16MB of flash, and has no means to extend the storage (there are no USB, SD or M.2 slots). So while technically you should be able to install and run the Dude server on cAP ac, you will not have enough space for even a minimal Dude DB, and so it will be effectively useless.
by andriys
Mon Sep 30, 2019 11:40 pm
Forum: Beginner Basics
Topic: help i have routerboard RB951Ui-2HnD need Cache web proxy
Replies: 11
Views: 1750

Re: help i have routerboard RB951Ui-2HnD need Cache web proxy

You are not listening. Caching HTTPS traffic is not possible. Period.
by andriys
Sun Sep 29, 2019 7:20 pm
Forum: Beginner Basics
Topic: Wireless bridge+access point
Replies: 4
Views: 1009

Re: Wireless bridge+access point

most complex router and overall the most crappy designed user interface that I have encountered. It is complex. But it is also very versatile/flexible. And the interface is actully pretty well-thought, though everything beyond QuickSet is primarily meant to be used by network pros, or at least peop...
by andriys
Sun Sep 29, 2019 7:08 pm
Forum: Wireless Networking
Topic: 921GS-5HPacD r2 Superchanel [SOLVED]
Replies: 1
Views: 1386

Re: 921GS-5HPacD r2 Superchanel [SOLVED]

Superchannel won't work unless you have country set to no_country_set.
by andriys
Sun Sep 29, 2019 6:17 pm
Forum: Wireless Networking
Topic: NV3
Replies: 125
Views: 20858

Re: NV3

If you Reed my answer Then you See i die test From Wap.60G and not from the Omnitik
mistry7, If you were careful enough, you would see I was replying to mfr476, and not you. And looking at his/her screenshots I'd rather suggest he/she runs btest straight on the device being tested.
by andriys
Sun Sep 29, 2019 6:08 pm
Forum: Wireless Networking
Topic: CAPsMAN 5G and 2G network at same time
Replies: 11
Views: 3203

Re: CAPsMAN 5G and 2G network at same time

Not sure I understand your last question about "signal tuning".
by andriys
Sat Sep 28, 2019 7:51 pm
Forum: Wireless Networking
Topic: NV3
Replies: 125
Views: 20858

Re: NV3

The very first thing you should do is to stop using built-in btest tool (bandwidth test). It is known to be CPU hungry on its own. When testing bandwidth, always do it through device you test, and never to/from that device. Disclaimer: I am just pointing to an obvious mistake here. I'm not in any wa...
by andriys
Sat Sep 28, 2019 1:43 pm
Forum: General
Topic: {ASK} upgrading SXT
Replies: 7
Views: 1278

Re: {ASK} upgrading SXT

I'd do in at least several step, making sure none of the steps introduces more than one major change like wireless packages consolidation, master-port removal, etc.
by andriys
Fri Sep 27, 2019 9:57 pm
Forum: Wireless Networking
Topic: CAPsMAN 5G and 2G network at same time
Replies: 11
Views: 3203

Re: CAPsMAN 5G and 2G network at same time

OK, I see, makes sense. We are mostly using wAP acs in CAPsMAN setups, and those work great for us, so I didn't even considered a case with 5GHz radios failing on their own.
by andriys
Fri Sep 27, 2019 6:24 pm
Forum: Wireless Networking
Topic: CAPsMAN 5G and 2G network at same time
Replies: 11
Views: 3203

Re: CAPsMAN 5G and 2G network at same time

There is no "one solution suits all" approach possible here. I personally do what you basically described as option1: use the same SSID with reduced power. The only difference is I use reduced power for both 2GHz and 5GHz bands- coupled with a reasonable overlap between neighboring APs this gives us...
by andriys
Fri Sep 27, 2019 5:52 pm
Forum: General
Topic: USB UPS connected to RB4011 wifi version
Replies: 6
Views: 1520

Re: USB UPS connected to RB4011 wifi version

So I was wondering if CONSOLE port is same like serial port and can be used for talking to APC UPS ....
Yes, it is the same. Not sure if it can be safely used for talking to UPS though.
by andriys
Thu Sep 26, 2019 10:19 pm
Forum: General
Topic: Ability to Use Development Branch for v7 Betas [SOLVED]
Replies: 3
Views: 1327

Re: Ability to Use Development Branch for Betas [SOLVED]

Moved to "General" as "RouterOS v7 BETA" section is only for problem reporting.
See viewtopic.php?f=1&t=152006.
by andriys
Tue Sep 24, 2019 12:23 pm
Forum: Beginner Basics
Topic: IPSEC
Replies: 1
Views: 658

Re: IPSEC

2.8.9? Really? Why don't you upgrade?
by andriys
Mon Sep 23, 2019 12:14 pm
Forum: Announcements
Topic: Newsletter 91
Replies: 25
Views: 28587

Re: Newsletter 91

MQS looks interesting. Newsletter says the following:
  • Power it with a USB power bank and it will power your CPE over PoE, while you configure it

The question is, when MQS is power with a USB power bank only, what voltage can be expected on PoE output?
by andriys
Sat Sep 21, 2019 11:35 pm
Forum: Beginner Basics
Topic: Noob questions
Replies: 4
Views: 1069

Re: Noob questions

I am new to networking and I’ve learned on the field ... is mikrotik is a good choice ... ? I'd say it is, but that's pretty subjective. :) where learn everything I need ? Official documentation may be a good starting point. Also, I was wondering if the GUI is complete or if I’ll need to get my han...
by andriys
Sat Sep 21, 2019 11:22 pm
Forum: General
Topic: "pure" ipsec, how to deal with MTU?
Replies: 6
Views: 1248

Re: "pure" ipsec, how to deal with MTU?

You don't need to do anything about it. Just make sure you do not blindly block the ICMP traffic so PMTUD over your tunnels works.
by andriys
Sat Sep 21, 2019 1:58 pm
Forum: General
Topic: Fasttrack doesn't work (with VLAN) ?
Replies: 8
Views: 2182

Re: Fasttrack doesn't work (with VLAN) ?

Fasttrack works for firewall with connection tracking enabled. Which is pretty much default for routed traffic and it doesn't care about underlying interface types. As far as I understand FastTrack is built on top of FastPath and requires that the underlying interface supports it. And I guess FastP...
by andriys
Sat Sep 21, 2019 1:55 pm
Forum: Beginner Basics
Topic: Forwarding all WAN traffic untouched to 1 Ethernet port [SOLVED]
Replies: 4
Views: 1482

Re: Forwarding all WAN traffic untouched to 1 Ethernet port [SOLVED]

Should the Bridge Local also include the eth1 port?
No, it should not. Everything else looks correct.
by andriys
Sat Sep 21, 2019 1:52 pm
Forum: General
Topic: hEX PoE // Powersupply
Replies: 6
Views: 1473

Re: hEX PoE // Powersupply

Strange decision from Mikrotik to bundle 24V with PoE router, but ...
It is not surprising at all. I expect most people to be using this device to power other Mikrotik devices, and those are fine being powered by 24V Passive PoE.
by andriys
Sat Sep 21, 2019 1:48 pm
Forum: General
Topic: Virtual License
Replies: 1
Views: 600

Re: Virtual License

Read here: CHR Licensing.
by andriys
Sat Sep 21, 2019 1:46 pm
Forum: The Dude
Topic: RAM use
Replies: 6
Views: 3287

Re: RAM use

Yes, I guess it is to be expected. Dude appears to be a heavy and resource-demanding service.
by andriys
Fri Sep 20, 2019 8:59 am
Forum: Beginner Basics
Topic: Forwarding all WAN traffic untouched to 1 Ethernet port [SOLVED]
Replies: 4
Views: 1482

Re: Forwarding all WAN traffic untouched to 1 Ethernet port [SOLVED]

Create a new bridge, add Ethernet ports 1 and 24 do this bridge. At his point your STB should already start working. Now change the configuration to use newly added bridge as your WAN interace instead of ether1 (this should be changed literally everywhere- IP address assignment, if any, DHCP client,...
by andriys
Thu Sep 19, 2019 10:26 pm
Forum: Wireless Networking
Topic: Mikrotik Audience Availability
Replies: 17
Views: 3995

Re: Mikrotik Audience Availability

2 months??? wAP ACs took nearly a year to get stable numbers. In that specific case, a special situation is presented, which was the incorporation of a new ipq4xxx platform and a massive support for the ARM architecture Are you sure you are talking about wAP ac and not cAP ac ? The wAP ac is MIPSBE...
by andriys
Thu Sep 19, 2019 3:00 pm
Forum: General
Topic: Fasttrack doesn't work (with VLAN) ?
Replies: 8
Views: 2182

Re: Fasttrack doesn't work (with VLAN) ?

Just finished converting a setup with 2x HAP AC with latest stable firmware from Switch VLAN setup to new bridge VLAN setup. Why did you do that? HW accelerated bridge VLAN filtering is only supported on CRS3xx series switches. For the rest of the the routerboards you should keep using the /switch ...
by andriys
Tue Sep 17, 2019 3:35 pm
Forum: Wireless Networking
Topic: hAP AC2+cAP AC Roaming is a joke [SOLVED]
Replies: 69
Views: 23862

Re: hAP AC2+cAP AC Roaming is a joke [SOLVED]

No, with the more expensive systems that do "seamless roaming" it is the AP/controller that decides where the client is served. What you are referring to here is technically not a roaming, because in this case clients do not really roam, but are rather constantly talking to a single huge AP with sp...
by andriys
Mon Sep 16, 2019 10:44 am
Forum: RouterBOARD hardware
Topic: Switch ability of 962UiGS-5HacT2HnT
Replies: 10
Views: 2908

Re: Switch ability of 962UiGS-5HacT2HnT

Is this device even able to switch VLANs?
It is (see this page in the wiki). However the Bridge VLAN Filtering is currently only supported on CRS3xx series devices, and on hAP ac you are limited to Basic VLAN switching.
by andriys
Sun Sep 15, 2019 2:44 pm
Forum: RouterBOARD hardware
Topic: current (up-to-date) dual-band router
Replies: 3
Views: 2073

Re: current (up-to-date) dual-band router

I am looking for what is essentially meant to be a powerful 2.4 and 5ghz router for a somewhat large-ish home, the materials of which don't let wifi signals through very well. I'm ok working with repeaters if I have to, but would rather explore single-device solutions first. Based on this descripti...
by andriys
Sat Sep 14, 2019 5:01 pm
Forum: Wireless Networking
Topic: Capsman ? WDS ? Mesh ?
Replies: 6
Views: 5591

Re: Capsman ? WDS ? Mesh ?

Depends on your client device. Roaming is always a function of client. AP may assist, but it always up to the client to do the switchover.
by andriys
Sat Sep 14, 2019 2:19 pm
Forum: Wireless Networking
Topic: Capsman ? WDS ? Mesh ?
Replies: 6
Views: 5591

Re: Capsman ? WDS ? Mesh ?

WDS over ethernet ?
Huh? :)

Or just the same SSID on a different channel ?
Go this way. There's absolutely no need to do anything more complicated than this in your case.
by andriys
Thu Sep 12, 2019 1:02 pm
Forum: General
Topic: EOIP/IPSec traffic stopped after upgrade from 6.42.7
Replies: 1
Views: 596

Re: EOIP/IPSec traffic stopped after upgrade from 6.42.7

EOIP is based on the GRE protocol, and there were some GRE-related firewall fixes in 6.45. As a result (1) an invalid firewall config that used to work before the upgrade will no longer work; and (2) a new bug was introduced that incorrectly classifies GRE connection state as invalid in some cases (...
by andriys
Wed Sep 11, 2019 10:08 pm
Forum: RouterBOARD hardware
Topic: RB4011: wlan1 disabling itself [SOLVED]
Replies: 302
Views: 69931

Re: RB4011: wlan1 disabling itself [SOLVED]

I have it in auto.
I believe it tried to find a free channel and it was delayed.
In this case the delay is most certainly caused by DFS (radar detection). When a DFS-enforced channel is selected, a delay (before you see your SSID on air) of at least 10 minutes is always to be expected.
by andriys
Wed Sep 11, 2019 9:33 pm
Forum: General
Topic: Packet loss just on 443 port
Replies: 12
Views: 2313

Re: Packet loss just on 443 port

The proper way to deal with the PMTUD issues is not to change MTU on either side, but rather to make sure you do not drop (block) ICMP messages that should not be dropped. A rather widespread workaround is to use TCP MSS clamping on the router (which some people consider an ugly hack- and for a reas...
by andriys
Wed Sep 11, 2019 6:41 pm
Forum: RouterBOARD hardware
Topic: RB4011: wlan1 disabling itself [SOLVED]
Replies: 302
Views: 69931

Re: RB4011: wlan1 disabling itself [SOLVED]

I didn't see the 5GHz wireless.
Now work perfect, without any changes.
What channel do you use? Perhaps, "now" means "once radar detection is complete"? Just guessing.