Community discussions

MikroTik App

Search found 159 matches

by dalami
Thu Apr 04, 2024 9:25 pm
Forum: Wireless Networking
Topic: hAP AX3 5G range troubleshooting
Replies: 62
Views: 3074

Re: hAP AX3 5G range troubleshooting

I was really hoping to see some more responses from other AX3 owners. As it is...I'm probably going to box these up soon. Now the question is what do I replace them with. Roll the dice to see if replacement AX3's work? Or look elsewhere? I *want* to use MT devices...but I've seen too many posts from...
by dalami
Thu Apr 04, 2024 9:00 pm
Forum: Wireless Networking
Topic: hAP AX3 5G range troubleshooting
Replies: 62
Views: 3074

Re: hAP AX3 5G range troubleshooting

It was worth trying - though I did before. It's not a CAPs issue. I manually applied the settings, disabled everything CAPs, exported the config to compare against what you provided...and the resulting 5g worked, or didn't, just the same.
by dalami
Thu Apr 04, 2024 8:48 pm
Forum: Wireless Networking
Topic: hAP AX3 5G range troubleshooting
Replies: 62
Views: 3074

Re: hAP AX3 5G range troubleshooting

Is there something I need to do for this to overwrite my existing setup? Wipe to default? Doing the import it stops with "failure: already have interface with such name".
by dalami
Thu Apr 04, 2024 7:39 pm
Forum: Wireless Networking
Topic: hAP AX3 5G range troubleshooting
Replies: 62
Views: 3074

Re: hAP AX3 5G range troubleshooting

The modem is in my back room - about 50' away from AX3. Again - this has only been present a few days and the AX3 performance has been unaltered. PLEASE disregard its existence - other than the fact that this "free" modem is able to push a 5G signal throughout my home while my AX3 can't se...
by dalami
Thu Apr 04, 2024 7:16 pm
Forum: Wireless Networking
Topic: hAP AX3 5G range troubleshooting
Replies: 62
Views: 3074

Re: hAP AX3 5G range troubleshooting

Sorry. There's the "Scan" button in winbox, and "Freq. Usage" button. You wanna look for "NF" column in "Freq. Usage" and take note of what it's saying. Here's mine: Ok. Here's frequency usage: frequse.png And here's a scan. scan.png Note the "strong&quo...
by dalami
Thu Apr 04, 2024 7:01 pm
Forum: Wireless Networking
Topic: hAP AX3 5G range troubleshooting
Replies: 62
Views: 3074

Re: hAP AX3 5G range troubleshooting

I do have hap ax3. Thank you - I'm glad to have an on-topic response. In addition since in 7.X release have band steering/roaming, you better disable the 2.4G Wifi interface completely to avoid that the AP pushes your clients onto 2.4Ghz (I found the settings for steering are all over the place and...
by dalami
Thu Apr 04, 2024 2:31 am
Forum: Wireless Networking
Topic: hAP AX3 5G range troubleshooting
Replies: 62
Views: 3074

Re: hAP AX3 5G range troubleshooting

Of course. And when I go outside my home - I don't see my hAP 5G. So my beloved MT device is certainly "weaker" than other offerings.
by dalami
Thu Apr 04, 2024 1:06 am
Forum: Wireless Networking
Topic: hAP AX3 5G range troubleshooting
Replies: 62
Views: 3074

Re: hAP AX3 5G range troubleshooting

There's also another possible explanation, which is high noise floor. Please try and measure it with frequency scan tool . Not sure what I'm looking for. Are there lots of other networks visible from my neighbors? Yes. Which makes it all the more annoying - I can see my next door neighbors' 5G netw...
by dalami
Wed Apr 03, 2024 7:21 am
Forum: Wireless Networking
Topic: hAP AX3 5G range troubleshooting
Replies: 62
Views: 3074

Re: hAP AX3 5G range troubleshooting

Have the same router model. Same problem with 5Ghz wifi. <...> And no option to manually chose channels from list and force routed pick what I want, not what it decides is good. Please start a new thread if you need help with basic Mikrotik wifi config - I want to keep this one focused on a specifi...
by dalami
Wed Apr 03, 2024 7:17 am
Forum: Wireless Networking
Topic: hAP AX3 5G range troubleshooting
Replies: 62
Views: 3074

Re: hAP AX3 5G range troubleshooting

Just installed 7.15B9. It seems like it's actually, if only slightly, improved the TX. Where before I never saw better than -60db in my chair I'm now seeing it reach -55db. Something I didn't state previously - while watching in a wifi analyzer the 5G network will periodically disappear. Don't know ...
by dalami
Wed Apr 03, 2024 1:57 am
Forum: Wireless Networking
Topic: hAP AX3 5G range troubleshooting
Replies: 62
Views: 3074

Re: hAP AX3 5G range troubleshooting

Winbox status shows TX 28.
Sitting in my usual chair, about 50 feet away, through a wall or two, the 2G network shows a fairly constant -46db, 5G shows a fluctuating -60 to -70db.
Moving out of the far room, down the hall, to within 10' open line-of-sight, I see -30db@2G, -45db@5G.
by dalami
Tue Apr 02, 2024 10:27 pm
Forum: Wireless Networking
Topic: hAP AX3 5G range troubleshooting
Replies: 62
Views: 3074

Re: hAP AX3 5G range troubleshooting

Sure. This is not a CAPSMan issue, not a firewall issue, not a queue issue. Again - for me 2G works fine while 5G has no range. The Android devices that can't connect 20 feet away do connect 6 feet away.
by dalami
Tue Apr 02, 2024 10:03 pm
Forum: Wireless Networking
Topic: hAP AX3 5G range troubleshooting
Replies: 62
Views: 3074

hAP AX3 5G range troubleshooting

I'm starting a new thread because the previous one is marked "Solved" - and it degenerated slightly. Please let's focus on the particular issue here - at least some hAP AX3 units appear to have extremely limited range. I'm operating on the assumption that MT designed, tested, and produced ...
by dalami
Tue Apr 02, 2024 8:49 pm
Forum: Wireless Networking
Topic: hAP ax3 wireless problem [SOLVED]
Replies: 144
Views: 16956

Re: hAP ax3 wireless problem [SOLVED]

Since it was asked for:

Model C53UiG+5HPaxD2HPaxD
Serial HER09CFZ59Y / HER09DGXRFS
Factory Firmware 7.8
Upgraded Firmware 7.14.2

Both of these units have unusable 5G.
by dalami
Mon Apr 01, 2024 7:05 pm
Forum: General
Topic: Appropriate router for 2G internet routing
Replies: 11
Views: 738

Re: Appropriate router for 2G internet routing

Slight revision. My current link is 2G down/100M up via cable/DOCSIS. I can run a queue tree on the upload without problems. It's only when I try to run on the download/bridge interface that my 2G gets throttled down to 1.2G. Since the real limiting factor, for my use case, will be upload sharing I ...
by dalami
Mon Apr 01, 2024 7:43 am
Forum: General
Topic: Appropriate router for 2G internet routing
Replies: 11
Views: 738

Re: Appropriate router for 2G internet routing

CPU doesn't get above 50% - maybe not even 40% - but the speed is cut in half regardless.
by dalami
Mon Apr 01, 2024 3:20 am
Forum: General
Topic: Forcing source ip and/or route
Replies: 3
Views: 299

Re: Forcing source ip and/or route

Interesting. In the process of sanitizing my export I found some garbage filter rules. Removing those was probably a good thing. Now that I've done that, and re-activated the src-nat & routing... It almost works. Or at least - now traffic from the office server fails to reach the cloud server wh...
by dalami
Mon Apr 01, 2024 2:56 am
Forum: General
Topic: Appropriate router for 2G internet routing
Replies: 11
Views: 738

Re: Appropriate router for 2G internet routing

Playing with my shiny new RB5009 - it will indeed pass the full 2G (actually, 2.2G) I'm getting from the cable provider. That with fasttrack enabled. However, the instant I enable a queue of any kind the speedtest drops to 1.2G maximum. While I probably don't need any QoS - I was hoping to optimize,...
by dalami
Sun Mar 31, 2024 9:37 am
Forum: General
Topic: Forcing source ip and/or route
Replies: 3
Views: 299

Forcing source ip and/or route

I'm not sure how to properly express this. I had a problem that I tried to solve with various combinations of src-nat and routing policy, failed, and then fixed it by doing it properly - which means configuring the clients directly instead of trying to use network magic. But I *want* to learn networ...
by dalami
Fri Mar 29, 2024 4:41 am
Forum: General
Topic: Appropriate router for 2G internet routing
Replies: 11
Views: 738

Appropriate router for 2G internet routing

Having just switched ISP's I now have a (theoretical) 2 gig connection. My existing Hex S, with it's 1G ethernet ports, obviously can't handle this. Would the RB5009UG+S+in be an appropriate upgrade here? I do have firewall rules that need to be used - this will be a router/firewall, not just a swit...
by dalami
Thu Mar 28, 2024 4:05 am
Forum: General
Topic: Purchasing on Amazon
Replies: 11
Views: 647

Purchasing on Amazon

I'm a US integrator and I have accounts with multiple US distributors. I've been buying Mikrotik from them. In the past, the pricing was comparable with Amazon - except for shipping. Now, it seems whoever is selling through Amazon is actually cheaper than the "approved" US distributors - p...
by dalami
Wed Jan 17, 2024 6:14 am
Forum: Wireless Networking
Topic: hAP ax3 wireless problem [SOLVED]
Replies: 144
Views: 16956

Re: hAP ax3 wireless problem [SOLVED]

/interface/wifi> monitor 0
state: running
channel: 5200/ax/eCee
registered-peers: 0
authorized-peers: 0
tx-power: 25
available-channels: 5200/ax/eCee
by dalami
Wed Jan 17, 2024 1:15 am
Forum: Wireless Networking
Topic: hAP ax3 wireless problem [SOLVED]
Replies: 144
Views: 16956

Re: hAP ax3 wireless problem [SOLVED]

I have a "Carsifi" - a wireless android auto adapter. It's about 1" wide, 2" long, and a 1/4" high. It's in my truck, parked outside on my driveway. Inside my house, through multiple walls, I see a 5G wifi signal from that device. While my AX3 half the distance half the wall...
by dalami
Mon Jan 15, 2024 9:45 am
Forum: Wireless Networking
Topic: hAP ax3 wireless problem [SOLVED]
Replies: 144
Views: 16956

Re: hAP ax3 wireless problem [SOLVED]

Should we start a new thread on this since this one is marked solved?
by dalami
Mon Jan 15, 2024 7:34 am
Forum: Wireless Networking
Topic: hAP ax3 wireless problem [SOLVED]
Replies: 144
Views: 16956

Re: hAP ax3 wireless problem [SOLVED]

I still have no idea if I'm on to anything or not. I tried playing with the orientation - sometimes it seemed to help and sometimes not. Which has been my whole experience with the two AX3's I've tried - their 5G range seems abysmal no matter what. Just for fun, I pulled off the pair of 3" ante...
by dalami
Mon Jan 15, 2024 6:03 am
Forum: Wireless Networking
Topic: hAP ax3 wireless problem [SOLVED]
Replies: 144
Views: 16956

Re: hAP ax3 wireless problem [SOLVED]

I just tried something - and please tell me it's not this.

Separate from forcing the channel selection (5785) - I turned one antenna horizontal leaving the other vertical. I'm not saying it's great - but somehow this made a *huge* difference is range and operation for this AX3.
by dalami
Mon Jan 15, 2024 5:42 am
Forum: Wireless Networking
Topic: hAP ax3 wireless problem [SOLVED]
Replies: 144
Views: 16956

Re: hAP ax3 wireless problem [SOLVED]

I've been fighting the same range issue. Being in the same (central) room - 5G works great. Go down the hallway...signal dies. My old hAP ac, which I thought this was replacing, filled the whole house without issue. Is there anything that can address this via software? The 2G signal seems great. Cur...
by dalami
Thu Dec 21, 2023 2:22 am
Forum: Beginner Basics
Topic: Add xAP to existing network [SOLVED]
Replies: 2
Views: 675

Re: Add xAP to existing network [SOLVED]

Thanks!
by dalami
Thu Dec 21, 2023 1:06 am
Forum: Beginner Basics
Topic: Add xAP to existing network [SOLVED]
Replies: 2
Views: 675

Add xAP to existing network [SOLVED]

This should be an obvious one - but just because I've found ways to make it work doesn't mean I'm doing it right. Given an existing wired network and I want to add a wireless AP - what is the "correct" way to setup that new AP? Assuming some flavor of a hAP, where the new device includes m...
by dalami
Mon Dec 18, 2023 1:50 am
Forum: Announcements
Topic: v7.13.5 [stable] is released!
Replies: 909
Views: 265416

Re: v7.13 [stable] is released!

That helps! Thank you.
by dalami
Mon Dec 18, 2023 1:10 am
Forum: Announcements
Topic: v7.13.5 [stable] is released!
Replies: 909
Views: 265416

Re: v7.13 [stable] is released!

Is there a list of devices that require/support the "wifi-qcom-ac" package? Should the "wireless" package be uninstalled first?
by dalami
Mon Nov 13, 2023 9:29 pm
Forum: RouterBOARD hardware
Topic: Cannot login to hAP ax3
Replies: 3
Views: 1926

Re: Cannot login to hAP ax3

Thank you. The combination of "hidden" and previous experience with Mikrotik devices made it so I was not expecting such.
by dalami
Mon Nov 13, 2023 9:15 pm
Forum: RouterBOARD hardware
Topic: Cannot login to hAP ax3
Replies: 3
Views: 1926

Cannot login to hAP ax3

Just bought a new unit. Connecting via Winbox, I should say attempting to connect, results in "wrong username or password". I'm using the typical default, "admin", and blank password. I'm trying both MAC and IP connect. I've (I think) reset the router several times (unplugged pow...
by dalami
Tue Jun 13, 2023 10:31 am
Forum: Beginner Basics
Topic: Wireguard for external gateway
Replies: 3
Views: 534

Re: Wireguard for external gateway

I don't understand. Are you saying I need to run srcnet on the lan interface of the mAP? The IoT device just receives DHCP from the mAP and there's nothing else I can configure on it.
by dalami
Tue Jun 13, 2023 6:43 am
Forum: Beginner Basics
Topic: Wireguard for external gateway
Replies: 3
Views: 534

Wireguard for external gateway

I'm asking this question more as a general theory question - since I think I've fought with this before and I don't know if I'm missing something in practice or if my basic theory is wrong. IoT device connected to a mAP. IoT uses mAP as gateway. mAP connected to internet through 3rd-party router. mA...
by dalami
Sun Jun 11, 2023 9:59 pm
Forum: General
Topic: Trying to make a sneaky VPN [SOLVED]
Replies: 17
Views: 2695

Re: Trying to make a sneaky VPN [SOLVED]

Port knocking on TCP ports is as easy as using /tool fetch url="http://ip.to.be.knocked:port-to-be-knocked/some-bogus-file-name" , and port knocking on UDP ports is as easy as using resolve some.bogus.string.with.dots server=ip.to.be.knocked port=port-to-be-knocked . But there are limitat...
by dalami
Sun Jun 11, 2023 10:57 am
Forum: RouterOS beta
Topic: Feature request: port knock client
Replies: 1
Views: 1955

Feature request: port knock client

Having a minimal port knock client available for scripting would be quite helpful.
by dalami
Sun Jun 11, 2023 10:53 am
Forum: General
Topic: Trying to make a sneaky VPN [SOLVED]
Replies: 17
Views: 2695

Re: Trying to make a sneaky VPN [SOLVED]

Obviously I'm a nefarious character up to no good. I'm a vendor contracted to provide a service which requires internet access. The customer has either a 3rd party or separate corporate department (unclear to me at this time) that administers the firewall. The service I provide is both requested by ...
by dalami
Sun Jun 11, 2023 6:44 am
Forum: General
Topic: Trying to make a sneaky VPN [SOLVED]
Replies: 17
Views: 2695

Re: Trying to make a sneaky VPN [SOLVED]

Thank you but none of this answers my question. Is there a way to perform a "knock" from within RouterOS?
by dalami
Sun Jun 11, 2023 12:07 am
Forum: General
Topic: Trying to make a sneaky VPN [SOLVED]
Replies: 17
Views: 2695

Re: Trying to make a sneaky VPN [SOLVED]

I install the mAP on the customer site to give me a gateway to access equipment behind it. So for sites that don't have a blocking firewall configuring wireguard is a piece of cake. But for this one I need a way to tunnel through that third party firewall hence my desire to initiate port knocking fr...
by dalami
Sat Jun 10, 2023 10:58 pm
Forum: General
Topic: Trying to make a sneaky VPN [SOLVED]
Replies: 17
Views: 2695

Trying to make a sneaky VPN [SOLVED]

I'm trying to get around a 3rd-party firewall that blocks non HTTP traffic. I have a mAP installed on the customer's network and I typically have such devices connect to my server via Wireguard - but the traffic is blocked by their firewall. And I'm having difficulties working with the corporate fir...
by dalami
Sat Jun 03, 2023 3:27 am
Forum: General
Topic: Is a catchall src-nat good or bad?
Replies: 3
Views: 405

Is a catchall src-nat good or bad?

Typically, our standard default install will have a masquerade rule on the outbound interface of a router. Sometimes, when using static IP's, we can use an explicit src-nat instead of a masquerade. I *think* this isn't terribly controversial. Now, if I add a tunnel, say Wireguard for argument's sake...
by dalami
Mon Apr 17, 2023 12:25 am
Forum: General
Topic: Endpoint-Dependent NAT vs. Endpoint-Independent NAT
Replies: 1
Views: 1930

Re: Endpoint-Dependent NAT vs. Endpoint-Independent NAT

See "endpoint-independent-nat" and "randomize-port".
by dalami
Sat Nov 26, 2022 5:19 am
Forum: Beginner Basics
Topic: Route internet through Wireguard [SOLVED]
Replies: 13
Views: 1560

Re: Route internet through Wireguard [SOLVED]

I would say this is embarrassing - except I'm used to displaying my stupidity. Especially on this forum. The particular form my stupidity has taken now was revealed (at least partially) by your logging instructions. Since I saw absolutely no traffic for my actual use (VNC, which means TCP to port 59...
by dalami
Fri Nov 25, 2022 11:55 pm
Forum: Beginner Basics
Topic: Route internet through Wireguard [SOLVED]
Replies: 13
Views: 1560

Re: Route internet through Wireguard [SOLVED]

Maybe I found something...or not. The target IP I'm trying to reach has some kind of firewall protections itself (it's a 3rd-party service out of my control) and only lets specific IP's in. Which is why I need to route my traffic through my current hEX IP. It also doesn't respond to ping - but when ...
by dalami
Fri Nov 25, 2022 11:44 pm
Forum: Beginner Basics
Topic: Route internet through Wireguard [SOLVED]
Replies: 13
Views: 1560

Re: Route internet through Wireguard [SOLVED]

First srcnat rule covers traffic to internet. Second is useless, because it would take subset of traffic already handled by first. Third affects everything else passing through router, so connections between local and VPN subnets, forwarded ports if you have any, etc. It shouldn't be needed. If you...
by dalami
Fri Nov 25, 2022 8:21 am
Forum: Beginner Basics
Topic: Route internet through Wireguard [SOLVED]
Replies: 13
Views: 1560

Re: Route internet through Wireguard [SOLVED]

New firewall. First - all my src-nat has condensed to: add action=src-nat chain=srcnat comment="Should be last srcnat rule. non-IPSec to Internet NAT to public IP" ipsec-policy=\ out,none out-interface=ether1-Internet to-addresses=<my.external.ip> add action=src-nat chain=srcnat comment=&q...
by dalami
Fri Nov 25, 2022 8:14 am
Forum: Beginner Basics
Topic: Route internet through Wireguard [SOLVED]
Replies: 13
Views: 1560

Re: Route internet through Wireguard [SOLVED]

You need to sort out the IP address usage so it more coherent for your wireguard as I think this is your major issue. Proposing since you have this in the correct format to keep the hex at The MT client device has a wireguard address of 10.23.1.1/24 OKAY now give the ubunut address= 10.23. 1 . 2 ( ...
by dalami
Fri Nov 25, 2022 7:13 am
Forum: Beginner Basics
Topic: Route internet through Wireguard [SOLVED]
Replies: 13
Views: 1560

Re: Route internet through Wireguard [SOLVED]

From your collection of srcnat rules, all you should need is just one, and its #7. It covers access from anywhere to internet, so including from remote 10.23.2.x peer. So it should work. Perhaps something you deleted wasn't as irrelevant as you thought? First of all - thank you for your response. I...
by dalami
Thu Nov 24, 2022 9:34 pm
Forum: Beginner Basics
Topic: Route internet through Wireguard [SOLVED]
Replies: 13
Views: 1560

Route internet through Wireguard [SOLVED]

Not only is this not working - I don't understand *why* it is not working. There's obviously something basic here I don't get. Please use whatever size hammer is required to drive the point into my thick head. I have an office network with a hEX that behaves quite nicely. This has a static IP connec...
by dalami
Thu Aug 25, 2022 11:22 pm
Forum: RouterOS beta
Topic: Wireguard logging with comments
Replies: 1
Views: 2342

Wireguard logging with comments

Can you consider adding the comment for peer entries to log lines? It's a lot easier for this human to find "Customer #4" than it is "asd8f76908asd7gfhlk23b...". Using the existing logging definition structure, possibly by adding a topic of "wireguard+comment" or "...
by dalami
Sat Jul 30, 2022 4:38 am
Forum: General
Topic: Wireguard auto-start [SOLVED]
Replies: 1
Views: 918

Wireguard auto-start [SOLVED]

I recall at least one comment that current/recent versions won't initiate Wireguard connections without disabling/enabling the peer. Does anyone have a script they use that might run every x minutes to verify the VPN connection and if not present toggle the peer?
by dalami
Fri Jul 22, 2022 3:12 am
Forum: Announcements
Topic: v7.4 [stable] is released!
Replies: 224
Views: 55740

Re: v7.4 [stable] is released!

I have a pair of hAP lites that I upgraded to 7.2rc4 a few months ago - I don't remember using Netinstall but maybe I just suppressed the memory. I just purchased another one, running 6.47.9, and it appears there isn't enough free disk space to upload the package via Winbox. The /files area is empty...
by dalami
Fri Jul 22, 2022 2:19 am
Forum: RouterOS beta
Topic: Current UPS support
Replies: 3
Views: 3238

Re: Current UPS support

I saw that - but there's been limited comments for recent versions and many of them negative. I was hoping for something better.
by dalami
Fri Jul 22, 2022 12:42 am
Forum: RouterOS beta
Topic: Current UPS support
Replies: 3
Views: 3238

Re: Current UPS support

Can anyone comment on using a USB connected UPS with current routers? Preferably non-APC offerings - particularly Eaton or CyberPower?
by dalami
Fri Jul 15, 2022 11:38 pm
Forum: RouterOS beta
Topic: Current UPS support
Replies: 3
Views: 3238

Current UPS support

The documentation for the UPS package is a little sparse but only mentions the APC product line as being supported. I've read elsewhere about other brands being used successfully. Is this package based on the "Network UPS Tools" project and should therefore support any UPS of the adopted v...
by dalami
Tue Jul 12, 2022 12:55 am
Forum: General
Topic: mAP lite not working with Wireguard [SOLVED]
Replies: 16
Views: 1866

Re: mAP lite not working with Wireguard [SOLVED]

Unlike other VPN types, Wireguard is by default silent. If there's no traffic trying to use its interface, it does not try to contact peers (unless you set keepalive for them).
That was it! Thank you!
by dalami
Tue Jul 12, 2022 12:09 am
Forum: General
Topic: mAP lite not working with Wireguard [SOLVED]
Replies: 16
Views: 1866

Re: mAP lite not working with Wireguard [SOLVED]

I don't understand. My problem is the wireguard interface never even attempts to begin handshaking. This isn't a routing/address/firewall/bridge problem - at least to my ignorant eyes. The wireguard service simply appears to never actually start. This is not my first wireguard setup, nor my first Mi...
by dalami
Mon Jul 11, 2022 11:45 pm
Forum: General
Topic: mAP lite not working with Wireguard [SOLVED]
Replies: 16
Views: 1866

Re: mAP lite not working with Wireguard [SOLVED]

Internet access for ML is fine. It has working DNS, resolves hostnames, and can ping without issue. I have toggled peers and wireguard interface repeatedly - no change.
by dalami
Mon Jul 11, 2022 11:30 pm
Forum: General
Topic: mAP lite not working with Wireguard [SOLVED]
Replies: 16
Views: 1866

Re: mAP lite not working with Wireguard [SOLVED]

If I was having problems fowarding/communicating between interfaces then I'd agree. But my problem is the wireguard interface never initiates communication to the peer. I've never seen that before.
by dalami
Mon Jul 11, 2022 10:59 pm
Forum: General
Topic: mAP lite not working with Wireguard [SOLVED]
Replies: 16
Views: 1866

Re: mAP lite not working with Wireguard [SOLVED]

Correct. That will be the final config. But first I need wireguard working regardless - it shouldn't matter whether the internet connection is wired or wireless.
by dalami
Mon Jul 11, 2022 10:52 pm
Forum: General
Topic: mAP lite not working with Wireguard [SOLVED]
Replies: 16
Views: 1866

Re: mAP lite not working with Wireguard [SOLVED]

How are you planning to use this device with wireguard ? To connect what to where ? The ML will act as a wireless adapter/bridge for a IoT appliance that has an ethernet port. There's existing wifi in the building. Things I'm already missing: - no bridge ? - your wireguard interface does have a pri...
by dalami
Mon Jul 11, 2022 10:17 pm
Forum: General
Topic: mAP lite not working with Wireguard [SOLVED]
Replies: 16
Views: 1866

mAP lite not working with Wireguard [SOLVED]

Here follows the output of "/export": # jul/11/2022 12:12:36 by RouterOS 7.4rc2 # software id = AP1J-KID8 # # model = RBmAPL-2nD # serial number = FACA0F65D6AA /interface wireless set [ find default-name=wlan1 ] ssid=MikroTik /interface wireguard add listen-port=13231 mtu=1420 name=wiregua...
by dalami
Mon Jul 11, 2022 9:44 pm
Forum: Announcements
Topic: v7.4rc is released!
Replies: 116
Views: 30580

Re: v7.4rc is released!

Just bought a mAP lite to connect a remote site. Naturally, first thing I did after unpacking it was to upgrade to 7.4rc2. Technically, I upgraded to latest version of 6 (whatever that was), then to 7.3.1, then to 7.4. Actually, the first problem was having plugged the mAP lite into my primary route...
by dalami
Sun Jun 05, 2022 2:34 am
Forum: General
Topic: Public-Mikrotik-Bandwidth-Test-Server(s)
Replies: 1009
Views: 1126380

Re: Public-Mikrotik-Bandwidth-Test-Server(s)

Hi Tony,

Thank you for making this resource available. I'm in Las Vegas, Nevada. My office receives service from a WISP called lv.net. I'm contracted for 25M/5M - and it looks like that's what I'm getting.
by dalami
Sun Jun 05, 2022 2:15 am
Forum: RouterOS beta
Topic: some quick comments on configuring cake
Replies: 285
Views: 103404

Re: some quick comments on configuring cake

Your target has no data, and simple queuing does not take effect. /queue simple add limit-at=940M/143M max-limit=950M/146M name=CAKE queue=cake-down/cake-up \ target=pppoe-out1 My "target" is should have been set (ether1) - don't know why it didn't show up in the command line (it was set ...
by dalami
Thu Jun 02, 2022 4:16 pm
Forum: RouterOS beta
Topic: some quick comments on configuring cake
Replies: 285
Views: 103404

Re: some quick comments on configuring cake

Disclaimer - I'm barely a dabbler when it comes to this stuff and I'm still not comfortable with some of the jargon and abbreviations. But I'm trying. I have a RB760iGS (hEX S) (256MB RAM) that is my office's gateway/firewall/router. Our internet is provided via a WISP - they're using Ubiquiti equip...
by dalami
Fri Apr 22, 2022 10:41 pm
Forum: General
Topic: Non-service based mesh wireguard
Replies: 7
Views: 1089

Re: Non-service based mesh wireguard

Yes and yes. So starting over - I have Wireguard setup now with two servers/routers and multiple remotes. I would like to be able to, from my remote, access any other remote and transparently use whichever server provides the optimum connection. Is this possible - preferably using a single network? ...
by dalami
Fri Apr 22, 2022 10:03 pm
Forum: General
Topic: Non-service based mesh wireguard
Replies: 7
Views: 1089

Re: Non-service based mesh wireguard

So - from a routing standpoint, having two routers in the same network doesn't work? Or is that what policy-based routing is for? I understand, I think, *how* to implement multiple networks as you described. So each remote is going to have two IP's? I just would prefer the elegance of a single endpo...
by dalami
Fri Apr 22, 2022 1:07 am
Forum: General
Topic: Non-service based mesh wireguard
Replies: 7
Views: 1089

Non-service based mesh wireguard

As the subject indicates - options such as Tailscale or Zerotier aren't what I'm asking about. This is actually more of a basic networking/routing question. I presently have a physical office server with a static IP. Impressive I know. Additionally I have a subscribed cloud server. I'm playing with ...
by dalami
Fri Nov 05, 2021 1:53 am
Forum: General
Topic: Problem - IPSec (IKEv2) between same subnet
Replies: 0
Views: 710

Problem - IPSec (IKEv2) between same subnet

I'm attempting to create a Mikrotik IPSec (IKEv2) link between my office LAN and a customer's LAN. Because I setup my LAN during my earliest network apprentice days - we're on 192.168.0.0/24. And my customer...has an experienced network admin who has chosen for their LAN: 192.168.0.0/24. I can't cha...
by dalami
Sun Oct 31, 2021 6:28 am
Forum: General
Topic: Can a lost IPSEC client cert be recovered?
Replies: 1
Views: 579

Can a lost IPSEC client cert be recovered?

I have (had) a IKEv2 connection from a remote site to my router. The remote is also a Mikrotik device. At some point I reset my router to default - while not having properly made a backup first. Brilliant of me wasn't it? So the remote site continues to try to connect to me. And I get the "unab...
by dalami
Sun Oct 24, 2021 5:53 am
Forum: General
Topic: Routing without bridge [SOLVED]
Replies: 12
Views: 3568

Re: Routing without bridge [SOLVED]

I still want to learn how to solve my original setup - but as I did gain access I decided to go the easy way and use a different IP range for the VoIP server to router connection. Things seems to be working now - thanks for the help.
by dalami
Thu Oct 21, 2021 10:33 pm
Forum: General
Topic: Multiple connection marks - or mixing connections, packets, and routing marks
Replies: 0
Views: 655

Multiple connection marks - or mixing connections, packets, and routing marks

Reading and reading - some articles and posts make more sense than others. It feels like the preferred method, where applicable, is to use connection marks for "serious" decision making and then simple connection mark matching afterwards. Sounds reasonable. But... Previously I've just used...
by dalami
Thu Oct 21, 2021 9:55 pm
Forum: General
Topic: Routing without bridge [SOLVED]
Replies: 12
Views: 3568

Re: Routing without bridge [SOLVED]

Getting closer...and what's nice is I *almost* exactly sort of kind of not really but maybe in a small way understand not only the how but the why. Enabling proxy-arp on the bridge allows my LAN clients to reach 192.168.0.10. Enabling proxy-arp on the interface allows the VoIP server to reach 192.16...
by dalami
Thu Oct 21, 2021 9:21 am
Forum: General
Topic: Routing without bridge [SOLVED]
Replies: 12
Views: 3568

Re: Routing without bridge [SOLVED]

Actually - I should correct one assumption I made above. I have OSPF running as well - and the LAN server I tested from also has OSPF. So the 192.168.0.10 route got pushed to that server - which allowed it to ping. My other workstations that only have 192.168.0.1 as their gateway are unable to ping ...
by dalami
Thu Oct 21, 2021 9:06 am
Forum: General
Topic: Routing without bridge [SOLVED]
Replies: 12
Views: 3568

Re: Routing without bridge [SOLVED]

I'm close. I don't know how - but I'm close. I found a page for routing with the same subnet - I tried to adapt from that. Here's the relevant lines - I think (with ether2 now removed from bridge). /ip address add address=192.168.0.1/24 comment="Primary LAN" interface=bridge network=192.16...
by dalami
Thu Oct 21, 2021 3:56 am
Forum: General
Topic: Routing without bridge [SOLVED]
Replies: 12
Views: 3568

Re: Routing without bridge [SOLVED]

Thinking...experimenting... To answer your question - the VoIP server is manually configured to be 192.168.0.250, gateway 192.168.0.1. I've tried deactivating the port from the bridge - playing with various rules things don't quite work. Then I realized...having removed the port from the bridge - wh...
by dalami
Thu Oct 21, 2021 3:23 am
Forum: General
Topic: Routing without bridge [SOLVED]
Replies: 12
Views: 3568

Re: Routing without bridge [SOLVED]

Thank you for being gentle. So, for solution "E" - two networks - do I have to do anything besides just removing the port from the bridge? My LAN is on subnet 192.168.0.0/24. The router is 192.168.0.1, and the misbehaving VoIP is setup on 192.168.0.250. All I needed to do for internet acce...
by dalami
Thu Oct 21, 2021 2:46 am
Forum: General
Topic: Routing without bridge [SOLVED]
Replies: 12
Views: 3568

Routing without bridge [SOLVED]

Have to think my way through this - not easy while sitting down. Too much pressure on the brain. If it matters I'm using a Hex S / RB760iGS as my gateway router. Port 1 is from my ISP. Port 2 goes to my VoIP server. And SFP1 goes to other networking devices starting with a CRS. Port 1 is presently b...
by dalami
Sat May 22, 2021 4:58 am
Forum: Beginner Basics
Topic: Is an example available for VoIP with PC? [SOLVED]
Replies: 17
Views: 5280

Re: Is an example available for VoIP with PC? [SOLVED]

Ok. I finally did it. At least at the moment - hopefully things are still working next week... This is the definitive way of accomplishing hybrid MAC-based VLAN . I'm declaring that officially - so any mistakes (impossible!) need to be critiqued and corrected. If anything here is wrong, inefficient,...
by dalami
Sat Feb 20, 2021 1:46 am
Forum: RouterOS beta
Topic: Winbox Wireguard Columns
Replies: 0
Views: 1098

Winbox Wireguard Columns

Please add the other peer fields, such as "current-endpoint-address", "current-endpoint-port", "rx", "tx", and most importantly "last-handshake" to Winbox. I can only see those via a terminal and "print detail" - which it makes it difficult...
by dalami
Fri Nov 13, 2020 2:21 am
Forum: General
Topic: IPSec is working - now how should I have done it?
Replies: 9
Views: 1644

Re: IPSec is working - now how should I have done it?

I love GRE for Mikrotik to Mikrotik IPSec tunnels. [...] Mikrotik's GRE+IPSec implementation uses the default IPSec policy and profile. Because of this, if you have different versions of RouterOS, sometimes you have to tweak the default IPSec settings so they match. Other than reduced configuration...
by dalami
Fri Nov 13, 2020 2:17 am
Forum: General
Topic: IPSec is working - now how should I have done it?
Replies: 9
Views: 1644

Re: IPSec is working - now how should I have done it?

Your steps are OK but instead of doing a NAT you can just add a route. You add a route for the destination network via the tunnel, and traffic will just pass through that without being translated. Of course this assumes that the devices on each of the tunnel have their specific router as their defa...
by dalami
Fri Nov 13, 2020 2:13 am
Forum: General
Topic: Can packet sniffing be used to debug IPSec/routing?
Replies: 3
Views: 1521

Re: Can packet sniffing be used to debug IPSec/routing?

Maybe I should rephrase - I understand the IPSec communication itself is encrypted and I'm not really asking about the handshake negotiation. I'm asking about routing & policy decisions. Something that might reveal more than just a ping or traceroute showing "no response" - I don't kno...
by dalami
Thu Nov 12, 2020 8:28 am
Forum: General
Topic: IPSec is working - now how should I have done it?
Replies: 9
Views: 1644

IPSec is working - now how should I have done it?

After beating my head against a software wall (which is much more painful than a stone wall) - I finally got the remote access I needed functioning. However - I refuse to believe that the unholy union of software and setup I brought into being conforms to the will of Cerf & Kahn. So I beseech th...
by dalami
Thu Nov 12, 2020 3:54 am
Forum: General
Topic: Can packet sniffing be used to debug IPSec/routing?
Replies: 3
Views: 1521

Can packet sniffing be used to debug IPSec/routing?

I have my primary router configured as an IPSec listener for several IKEv2 remotes. Most of these work the way I want. One of them...I can establish a connection and the routers talk to each other but I cannot reach the LAN of the remote router. Obviously I've got something wrong but I can't see wha...
by dalami
Sat Oct 17, 2020 5:53 am
Forum: RouterBOARD hardware
Topic: US LTE recommendations [SOLVED]
Replies: 3
Views: 1223

Re: US LTE recommendations [SOLVED]

I appreciate the advice - and yes the signal strength is fine. Do you have any comments for my original questions?
by dalami
Sat Oct 17, 2020 12:16 am
Forum: RouterOS beta
Topic: v7.1beta2 [development] is released!
Replies: 385
Views: 154337

Re: v7.1beta2 [development] is released!

I learned something new again. Thanks! Yes - I'm sure the backup files were in the root level - though they were there previously during other reboots.
by dalami
Fri Oct 16, 2020 11:01 pm
Forum: RouterOS beta
Topic: v7.1beta2 [development] is released!
Replies: 385
Views: 154337

Re: v7.1beta2 [development] is released!

I just had my hAP AC2 powered down for a period (about 12 hours) - and on turning it back on I found it...wiped. Totally reset to default including wiping the file storage...where I had stored a couple backup configs. And being brilliant as usual I hadn't downloaded them for safekeeping. Given that ...
by dalami
Fri Oct 16, 2020 10:56 pm
Forum: RouterBOARD hardware
Topic: US LTE recommendations [SOLVED]
Replies: 3
Views: 1223

US LTE recommendations [SOLVED]

As usual, I'm confused by the many options available. I have a need for a simple LTE modem that will provide at least one ethernet connection. Wifi is a plus but not essential. I recently ordered a NetGear 1120LB for this application - haven't received or tried it yet but I thought I'd ask if my pre...
by dalami
Fri Oct 09, 2020 2:38 am
Forum: RouterOS beta
Topic: v7.1beta2 [development] is released!
Replies: 385
Views: 154337

Re: v7.1beta2 [development] is released!

Has anyone been able to restore normal/stable wifi operation on this beta? I loaded it on my home router for Wireguard - wifi is now useless. Fortunately I have a secondary wifi AP available. At least for the past few minutes - after performing a "/interface wireless reset-configuration" ...
by dalami
Fri Oct 09, 2020 2:22 am
Forum: RouterOS beta
Topic: v7.1beta2 [development] is released!
Replies: 385
Views: 154337

Re: v7.1beta2 [development] is released!

Has anyone been able to restore normal/stable wifi operation on this beta? I loaded it on my home router for Wireguard - wifi is now useless. Fortunately I have a secondary wifi AP available.
by dalami
Fri Aug 28, 2020 10:31 pm
Forum: General
Topic: Relative "costs" of firewall tests
Replies: 0
Views: 469

Relative "costs" of firewall tests

I remember seeing...somewhere...a list or table of the various tests, e.g. interface, dst-address, connection-type, etc. that ranked them according to the level of processing required. I don't remember if it was Mikrotik specific or if it was a generic iptables guide. Haven't been able to find it re...
by dalami
Fri Aug 28, 2020 7:53 pm
Forum: Beginner Basics
Topic: IPSec split include for external address [SOLVED]
Replies: 1
Views: 1338

Re: IPSec split include for external address [SOLVED]

The answer is - don't use the "notrack" chain option of the identity. Instead, leave that blank/unspecified and manually create srcnat rule(s) that handle the traffic as appropriate. The "old" way of setting up IPSec was to manually create an "accept" rule in the srcnat...
by dalami
Sun Aug 23, 2020 10:46 pm
Forum: Beginner Basics
Topic: Why is Mangle considered "bad"? [SOLVED]
Replies: 8
Views: 2054

Re: Why is Mangle considered "bad"? [SOLVED]

So...does use of Mangle completely negate Fasttrack? Or only for applicable connections/packets?

Does this mean that if QoS with queue trees is desired, fasttrack is (perhaps by definition) no longer usable?
by dalami
Sat Aug 22, 2020 12:06 pm
Forum: General
Topic: Feature requests
Replies: 1741
Views: 636529

Re: Feature requests

New request - add a new action to Firewall (probably under Filter)..."Run Script". Possible horrible security hole? Of course - like anything else. My first intended use case - via a port knock sequence, update the stored IP for an IPSec peer. An alternative solution for this use case - al...
by dalami
Fri Aug 21, 2020 9:18 pm
Forum: Beginner Basics
Topic: Why is Mangle considered "bad"? [SOLVED]
Replies: 8
Views: 2054

Why is Mangle considered "bad"? [SOLVED]

It seems like when Mangle based rules are proposed for further matching by NAT or Filter the responses are typically negative - avoid Mangle and implement the pattern matching directly in NAT and/or Filter. The comment is usually something like "now every packet has to be considered". I do...
by dalami
Thu Aug 20, 2020 1:06 am
Forum: Beginner Basics
Topic: IPSec split include for external address [SOLVED]
Replies: 1
Views: 1338

IPSec split include for external address [SOLVED]

I need to have an IPSec client, connecting to my Mikrotik IPSec server/router, reach an external IP address (not in my network). I added the remote address to the split include and it appears in the client's routing table. I am presently unable to reach the remote site via this method. I'm trying to...
by dalami
Mon Aug 10, 2020 11:10 pm
Forum: General
Topic: Hairpin NAT - I *think* I did it right!
Replies: 5
Views: 2456

Re: Hairpin NAT - I *think* I did it right!

Not sure about that for my case. With 192.168.0.0/24 served by the router, and 10.59.97.0/24 provided by my server at 192.168.0.2 running OpenVPN - if a local device connects to Wi-Fi and gets a 192.168.0.x/24 address, then connects to VPN and gets a 10.59.97.x/24 address - what happens when it trie...
by dalami
Mon Aug 10, 2020 10:44 pm
Forum: General
Topic: Is VLAN "all or nothing"?
Replies: 9
Views: 2701

Re: Is VLAN "all or nothing"?

Two reasons: 1. That will require additional config on the phones, and the VoIP server, and I don't know that I have control over that (actually, I do, I just would rather not fight it with my current provider). 2. Then only way to learn is to do - and I bought this Mikrotik equipment specifically t...
by dalami
Mon Aug 10, 2020 10:17 pm
Forum: General
Topic: Is VLAN "all or nothing"?
Replies: 9
Views: 2701

Re: Is VLAN "all or nothing"?

I'm almost, almost, almost there (theoretically - not functionally) - but I'm still lost on the actual config. So I will ask this: Given CRS112-8P-4S: ether1 - VoIP phone, MAC 00:a8:59:f6:b2:de, IP 192.168.11.141 - also a PC with 192.168.0.x ether4 - VoIP and VoIP DHCP server 192.168.11.1 MAC 00:E0:...
by dalami
Mon Aug 10, 2020 9:25 am
Forum: General
Topic: Is VLAN "all or nothing"?
Replies: 9
Views: 2701

Re: Is VLAN "all or nothing"?

If you need more than one switching device and you don't want to spend one interconnection cable and a pair of ports per port-based VLAN, you have to use the "tag based VLAN" approach, but you can still attach the tagged ends of /interface vlan only to the interconnect interfaces and make...
by dalami
Mon Aug 10, 2020 9:00 am
Forum: General
Topic: Hairpin NAT - I *think* I did it right!
Replies: 5
Views: 2456

Re: Hairpin NAT - I *think* I did it right!

The idea to make it clean by applying srcnat only to dstnatted connections is good, but the result is not that great: - Since each connection can have only one mark, it can easily conflict with some other use. But if you don't need it for anything else, then it's not a problem. - Mangle rules will ...
by dalami
Sun Aug 09, 2020 6:19 am
Forum: General
Topic: Hairpin NAT - I *think* I did it right!
Replies: 5
Views: 2456

Hairpin NAT - I *think* I did it right!

I just made some adjustments to my setup - that not only work but they feel right. Please tell me if this works for you or if there's a flaw somewhere... One of the issues with "hairpin NAT" is losing the external IP's. For my purposes that's a problem. I'm far less concerned about logging...
by dalami
Sun Aug 09, 2020 4:31 am
Forum: General
Topic: Is VLAN "all or nothing"?
Replies: 9
Views: 2701

Is VLAN "all or nothing"?

For a small network (less than 20 devices) - I have identified a single set of clients that I want to be segregated from the rest of the network. Can I make a single VLAN for those ports/MACs - without configuring VLAN for the remainder of the network? Or once I start down the VLAN path...do I need ...
by dalami
Thu Aug 06, 2020 11:16 pm
Forum: Beginner Basics
Topic: Forwarding traffic from Mikrotik to a SSH server
Replies: 9
Views: 6499

Re: Forwarding traffic from Mikrotik to a SSH server

I want to configure the mikrotik router to send traffic to a SSH server that is listening on port 2222 and I tried the /system ssh commands but they are for connection in client terminal mode. I have set forwarding-enabled both=yes to allow forwarding in both directions but I can't find out how to ...
by dalami
Thu Aug 06, 2020 5:57 pm
Forum: Beginner Basics
Topic: Forwarding traffic from Mikrotik to a SSH server
Replies: 9
Views: 6499

Re: Forwarding traffic from Mikrotik to a SSH server

The drawing explains the problem of connecting the mikrotik router via ssh to an access point that has an ssh server listening at the address 192.168.43.1:2222. For which I suppose that it would be necessary to activate an SSH client in the Mikrotik router to link it to the address 192.168.43.1:222...
by dalami
Thu Aug 06, 2020 8:46 am
Forum: Beginner Basics
Topic: Split include Windows IKEv2 client gets routes - but router policy is global [SOLVED]
Replies: 1
Views: 1189

Split include Windows IKEv2 client gets routes - but router policy is global [SOLVED]

I have several IPSec clients with copied configs connecting to my router. The Mikrotik devices connect as expected. The Windows 10 client - while it connects, the generates different policies from the policy template. Each of the Mikrotik clients generates a rule for each split network. But the Wind...
by dalami
Wed Aug 05, 2020 7:09 pm
Forum: Beginner Basics
Topic: Have filters match IPSEC policy vs connection/packets? [SOLVED]
Replies: 1
Views: 1292

Have filters match IPSEC policy vs connection/packets? [SOLVED]

Which is "better"? /ip firewall filter add action=accept chain=forward comment="accept in ipsec policy - must be before fasttrack" ipsec-policy=in,ipsec add action=accept chain=forward comment="accept out ipsec policy - must be before fasttrack" ipsec-policy=out,ipsec o...
by dalami
Wed Aug 05, 2020 6:52 pm
Forum: Beginner Basics
Topic: Winbox crashes when editing certain IPSEC Policies [SOLVED]
Replies: 4
Views: 3618

Re: Winbox crashes when editing certain IPSEC Policies [SOLVED]

What is your Winbox Version? No crash with v3.24 on on cAP ac v6.47.1
Really?! It's that simple?!

So embarrassed. I thought Winbox self-updated on connection to newer RouterOS versions - never thought I had to manually download from Webfig.

It's always the simple stuff...
by dalami
Wed Aug 05, 2020 7:44 am
Forum: Beginner Basics
Topic: Winbox crashes when editing certain IPSEC Policies [SOLVED]
Replies: 4
Views: 3618

Winbox crashes when editing certain IPSEC Policies [SOLVED]

I have a router with several policies and templates defined. I'm trying to edit them - but while *most* of the entries work without issue as soon as I try to edit one of the affected lines Winbox instantly closes. I can edit these lines via ssh or webfig - but the fact that Winbox crashes tells me s...
by dalami
Thu Jul 23, 2020 10:14 am
Forum: Beginner Basics
Topic: Should Proxy-Arp be enabled on bridges or interfaces?
Replies: 2
Views: 4019

Re: Should Proxy-Arp be enabled on bridges or interfaces?

Yes - multiple network connections. My primary router has both IPSEC and SSTP remote networks connected to it. The local connections are in a bridge for the LAN. I also have a remote site, connected to my main router via SSTP, which has devices connected in a bridge. I want to expose the remote addr...
by dalami
Thu Jul 23, 2020 8:15 am
Forum: Beginner Basics
Topic: Should Proxy-Arp be enabled on bridges or interfaces?
Replies: 2
Views: 4019

Should Proxy-Arp be enabled on bridges or interfaces?

With multiple interfaces in a bridge - should proxy-arp be enabled for each interface, or the bridge, or both?
by dalami
Tue Jul 21, 2020 2:43 am
Forum: General
Topic: ICMP, PMTU, and MSS - or why is HTTPS/TLS breaking
Replies: 0
Views: 838

ICMP, PMTU, and MSS - or why is HTTPS/TLS breaking

Would the following Filter rules compromise "proper" ICMP? If so, how should I configure to block "ping attacks" while allowing all good traffic? add action=accept chain=input comment="Allow limited pings" limit=50/5s,2:packet protocol=icmp add action=drop chain=input c...
by dalami
Tue Jul 14, 2020 9:38 pm
Forum: Beginner Basics
Topic: Secondary routes
Replies: 3
Views: 1653

Secondary routes

Having just fixed most of my self-inflicted wounds...I think I've almost figured out how much I don't know. So... I've now established both an IKEv2 and a SSTP connection between a remote MT router and my office MT router. They work...so far. But having two VPN's my hope is to able to poke at one wi...
by dalami
Fri Jun 26, 2020 10:56 pm
Forum: General
Topic: Redirect vs Dst-Nat - or port obfuscation
Replies: 3
Views: 2272

Re: Redirect vs Dst-Nat - or port obfuscation

That...doesn't make sense. It may be right - but it still doesn't make sense. 1) Isn't redirect by definition for a local destination only? 2) If I open port 22 in the filters - then port 22 is open to the internet which is exactly what I don't want to happen. Hmm...would the better choice be to hav...
by dalami
Fri Jun 26, 2020 9:09 pm
Forum: General
Topic: Redirect vs Dst-Nat - or port obfuscation
Replies: 3
Views: 2272

Redirect vs Dst-Nat - or port obfuscation

I *think* I understand the difference between dst-nat vs redirect: dst-nat forwards incoming requests to an external location while redirect is a special case for the localhost. Assuming that's the case, I again believe that if I want to expose a local service from the router on an alternate port th...
by dalami
Mon Jun 01, 2020 12:39 am
Forum: Beginner Basics
Topic: Is an example available for VoIP with PC? [SOLVED]
Replies: 17
Views: 5280

Re: Is an example available for VoIP with PC? [SOLVED]

So I return to my question - how do I configure the CRS1xx to use MAC based VLAN? WinBox shows options, the manual gives minimal descriptions, so I believe there is support for it - but I don't know where to start. Terms like PVID, SVID, CVID, have me quite confused. Ingress/egress are concepts I un...
by dalami
Sun May 31, 2020 11:28 pm
Forum: Beginner Basics
Topic: Is an example available for VoIP with PC? [SOLVED]
Replies: 17
Views: 5280

Re: Is an example available for VoIP with PC? [SOLVED]

The phone in question is a Polycom IP550 which has VLAN support. If necessary, I can manually set the VLAN id in the phone if that leads to a Mikrotik solution.
by dalami
Sun May 31, 2020 10:56 pm
Forum: Beginner Basics
Topic: IKEv2 for Android connects but no access
Replies: 0
Views: 1018

IKEv2 for Android connects but no access

I'm able to connect via Android (happens to be a Note 8 running Android 10) via the built-in VPN function with "IPSec IKEv2 RSA". However...while I'm able to ping my router from the phone I can't do anything else - can't access LAN, can't even see WebFig. I do notice the IP assigned to the...
by dalami
Sun May 31, 2020 10:41 pm
Forum: Beginner Basics
Topic: Is an example available for VoIP with PC? [SOLVED]
Replies: 17
Views: 5280

Re: Is an example available for VoIP with PC? [SOLVED]

First, thanks for the responses. Second, let me be clear that I'm not just a novice at VLAN - I've never configured one before. So some foundation concepts are still trying to sink into my tiny brain. The physical connection - these phones basically have built-in two port switches. One port (PoE) co...
by dalami
Sun May 31, 2020 7:18 am
Forum: Beginner Basics
Topic: Is an example available for VoIP with PC? [SOLVED]
Replies: 17
Views: 5280

Re: Is an example available for VoIP with PC? [SOLVED]

Sorry - I just don't see it. Everything there is port based - nothing filters on MAC. So if a phone is connected to port ether2 on a switch, and a PC is connected to the phone, with the examples given both the phone and the PC will be in a VLAN - which is not the desired behavior.
by dalami
Sat May 30, 2020 7:13 pm
Forum: Beginner Basics
Topic: Is an example available for VoIP with PC? [SOLVED]
Replies: 17
Views: 5280

Re: Is an example available for VoIP with PC? [SOLVED]

Exactly the page I'm talking about - it mentions such a configuration but doesn't actually show it. Everything there is port-based which doesn't help.
by dalami
Sat May 30, 2020 10:11 am
Forum: Beginner Basics
Topic: Is an example available for VoIP with PC? [SOLVED]
Replies: 17
Views: 5280

Is an example available for VoIP with PC? [SOLVED]

I've found mention of typical VoIP installations where the VoIP phone connects to the switch and a workstation connects to the phone. But I haven't found an actual configuration example for how to place the phones into a VLAN. I'm assuming this would be MAC-based VLAN - and I'm finding no documentat...
by dalami
Tue May 26, 2020 5:27 am
Forum: Beginner Basics
Topic: A desperate cry for help.
Replies: 5
Views: 2053

Re: A desperate cry for help.

You mentioned a couple of connections - I read "ethernet cable to Nvidia" and later "ethernet cable to TP-Link". You didn't specify if the same cable was being used. If the same cable - forget I asked. If different cables...might be just that simple.
by dalami
Tue May 26, 2020 5:20 am
Forum: Beginner Basics
Topic: Default Firewall Order
Replies: 6
Views: 2611

Re: Default Firewall Order

I'm focusing on your forward chain as that's what would be involved with the RDP stuff. And know that I consider myself a very dangerous amateur when it comes to this subject - I do not consider myself an authority in networks in general or Mikrotik in particular. An excerpt from my own firewall: ad...
by dalami
Tue May 26, 2020 4:38 am
Forum: General
Topic: CRS1xx CPU Load
Replies: 0
Views: 661

CRS1xx CPU Load

Once again I have a wonderful opportunity to display my ignorance. My primary internet router/gateway/firewall, a RB750GL, has a typical CPU Load of 4%. Now that I've added some more aggressive firewall filtering rules - I will see occasional spikes (less now that I've optimized the ordering) but ju...
by dalami
Mon May 25, 2020 12:45 am
Forum: General
Topic: RSTP status [SOLVED]
Replies: 3
Views: 5207

Re: RSTP status [SOLVED]

Thank you - but unless I'm not understanding what I'm looking at (which is likely) this doesn't answer my need. I've looked at that information, both in terminal and Winbox, and what I'm seeing is overall bridge status. I guess what I want to see is something that shows actual connections, like the ...
by dalami
Sun May 24, 2020 6:20 am
Forum: General
Topic: RSTP status [SOLVED]
Replies: 3
Views: 5207

RSTP status [SOLVED]

Is there a way of viewing the "status" of (R)STP? A way to show current traffic paths and identify misconfiguration?
by dalami
Sun May 24, 2020 6:18 am
Forum: General
Topic: CRS1xx DHCP port isolation
Replies: 1
Views: 1031

Re: CRS1xx DHCP port isolation

I think I've got it working - now I'll find what breaks. In the meantime - can anyone confirm if what I've done is "correct" and more importantly - is there a "better" way I should do it? First, I do NOT place the VoIP server port into the isolation group. I've left that at defau...
by dalami
Sun May 17, 2020 10:39 am
Forum: General
Topic: CRS1xx DHCP port isolation
Replies: 1
Views: 1031

CRS1xx DHCP port isolation

Having typed a small novel - I'll condense to what I think my actual question is: The example page for the CRS1xx shows how to limit DHCP. So given: ether1: VoIP server ether2-ether6: VoIP phones ether7-ether8: unused/spare/future sfp10: next switch/router/gateway Based on the example page, I think ...
by dalami
Sun May 10, 2020 3:01 am
Forum: General
Topic: Secondary IPSEC behind router? [SOLVED]
Replies: 1
Views: 1729

Secondary IPSEC behind router? [SOLVED]

I just purchased and began configuring an upgraded router/switch (going from RB750GL to hAP AC2). I initially tried backing up the current config and then restoring to the new - that went horribly. Probably totally due to my own ignorance and external cabling factors - but I digress. I now have the ...
by dalami
Sat May 09, 2020 6:41 am
Forum: RouterBOARD hardware
Topic: VoIP POE Switch Recommendation [SOLVED]
Replies: 1
Views: 7870

VoIP POE Switch Recommendation [SOLVED]

I had a Trendnet TPE-80WS running our phone network - after many years of faithful service it's died. Given my preference for RouterOS - I'm looking for a Mikrotik alternative. I need to drive between 3 and 5 phones with 802.3af. Two models that look interesting are the CRS112-8P-4S-IN and the RB960...
by dalami
Wed Jan 29, 2020 7:17 am
Forum: General
Topic: Layer 2 tunnel via IPSEC/IKEv2
Replies: 3
Views: 1741

Re: Layer 2 tunnel via IPSEC/IKEv2

Thank you - I'll look at EoIP again. What is the difference between using the existing IPSEC connections and configuring the EoIP interfaces with internal IP's compared with explicitly setting IPSEC secrets and external IP's in the EoIP interfaces?
by dalami
Tue Jan 28, 2020 2:56 am
Forum: Forwarding Protocols
Topic: Request for information - VPN & Routing [SOLVED]
Replies: 3
Views: 9891

Re: Request for information - VPN & Routing [SOLVED]

The answer here is OSPF requires multicast which IPSEC does not provide. So either a layer 2 tunnel needs to be established - or a simple workaround is configuring the necessary links within OSPF via NBMA to use unicast communication.
by dalami
Tue Jan 28, 2020 2:52 am
Forum: General
Topic: Layer 2 tunnel via IPSEC/IKEv2
Replies: 3
Views: 1741

Layer 2 tunnel via IPSEC/IKEv2

I've got working connections from multiple remotes to my primary router via IPSEC. Each remote peer is defined in "/ip ipsec" with their signatures, mode config, etc. The exchange modes are all "IKE2" - I don't know if that means my tunnels are IKEv2 or not. But I do seem to have...
by dalami
Tue Jan 28, 2020 2:43 am
Forum: General
Topic: Filtering IPSEC [SOLVED]
Replies: 4
Views: 1802

Re: Filtering IPSEC [SOLVED]

What I'm doing - part experimenting and part really trying to understand this. In particular, the first thing I wanted working was OSPF. The second was being able to reliably gain access to hosts on either side of the tunnel. Part of that is implementing layer 2 connectivity in some fashion - not su...
by dalami
Mon Jan 27, 2020 11:15 pm
Forum: General
Topic: Filtering IPSEC [SOLVED]
Replies: 4
Views: 1802

Re: Filtering IPSEC [SOLVED]

That...made quite a bit of sense. But with that said:

For "full" implementation, do I need to have all three specified at a filter and NAT level?
by dalami
Mon Jan 27, 2020 4:45 am
Forum: Beginner Basics
Topic: [UPDATED] Bare IpSec: VPN reaches the local LAN, but not the other way round? Also, is my config sane? [SOLVED]
Replies: 11
Views: 6372

Re: [UPDATED] Bare IpSec: VPN reaches the local LAN, but not the other way round? Also, is my config sane? [SOLVED]

add action=masquerade chain=srcnat dst-address=!192.168.178.1 protocol=tcp src-address=192.168.178.0/24
Your 2nd masquerade line, for IPSEC traffic, only permits TCP. Try deleting the protocol reference.
by dalami
Mon Jan 27, 2020 4:31 am
Forum: General
Topic: Filtering IPSEC [SOLVED]
Replies: 4
Views: 1802

Filtering IPSEC [SOLVED]

What is the difference between the following? And what is the correct usage?
chain=input action=accept protocol=ipsec-esp in-interface=ether1-Internet
chain=input action=accept protocol=udp in-interface=ether1-Internet dst-port=500,4500
chain=input action=accept ipsec-policy=in,ipsec
by dalami
Mon Jan 27, 2020 4:07 am
Forum: Forwarding Protocols
Topic: Trying to understand routing & IPSEC
Replies: 1
Views: 2072

Trying to understand routing & IPSEC

I know I'm getting closer to overall understanding - but I'm stuck on this part. Remote location: bLookback bridge, no ports, static address 10.255.255.2 bInternet bridge, all physical ports, LAN 192.168.1.12/24 dynamically receives 10.21.3.3 to bInternet bridge via IPSEC known routes: 0 ADS dst-add...
by dalami
Tue Jan 14, 2020 12:33 am
Forum: Forwarding Protocols
Topic: Request for information - VPN & Routing [SOLVED]
Replies: 3
Views: 9891

Request for information - VPN & Routing [SOLVED]

I admit it - I'm a bit out of my depth. Like many small business owners I fulfill multiple roles - including IT network admin. And it's been a while since I last set things up. I do remember utilizing some website examples/tutorials and the wiki - but I'm not finding what I need. If I can get this f...
by dalami
Mon Dec 30, 2019 10:55 pm
Forum: Wireless Networking
Topic: Using hAP as wireless adapter [SOLVED]
Replies: 2
Views: 7847

Re: Using hAP as wireless adapter [SOLVED]

To do what you want, just use quickset to setup the device as CPE and select bridge mode. In the wireless menu you can scan the network and connect it.
Never used this function before - didn't know about it! Thank you!
by dalami
Fri Dec 27, 2019 10:53 pm
Forum: RouterBOARD hardware
Topic: mAP Lite 12vdc?
Replies: 7
Views: 4145

mAP Lite 12vdc?

How can I power the mAP Lite via 12VDC? Would I need a PoE injector?
by dalami
Fri Dec 27, 2019 10:30 pm
Forum: Wireless Networking
Topic: Using hAP as wireless adapter [SOLVED]
Replies: 2
Views: 7847

Using hAP as wireless adapter [SOLVED]

I've used Mikrotik for routing/switching for some time but I've never worked with the wireless. I started playing with a hAP and got quite confused - especially with CAPS. I've got an application where I need a wireless adapter. To be clear - an existing dedicated function product has a wired ethern...
by dalami
Tue Mar 14, 2017 2:03 am
Forum: Beginner Basics
Topic: Should fasttrack be used without a specified interface?
Replies: 1
Views: 912

Should fasttrack be used without a specified interface?

Normally I specify "In-interface" for my forward rules. Should I leave that off for fasttrack - and possibly the "global" foward for established/related?
by dalami
Wed Jan 11, 2017 9:40 pm
Forum: Wireless Networking
Topic: Short-range product recommendations [SOLVED]
Replies: 5
Views: 1795

Re: Short-range product recommendations [SOLVED]

Thanks again. I was wondering about the mANTbox... Is the primary difference between these, other than the obvious physical, the antenna shape and therefore the coverage area? So the mANTbox gives me an integrated wide-angle sector antenna, the SXT a more focused antenna, and the others give me the ...
by dalami
Wed Jan 11, 2017 2:18 am
Forum: Wireless Networking
Topic: Short-range product recommendations [SOLVED]
Replies: 5
Views: 1795

Re: Short-range product recommendations [SOLVED]

First of all, thanks for the response! As far as available spectrum & existing - they've got at least 7 AP's in that house, and I see at least two of them in the area in question. As I said before, they're all consumer-type AP's with the same SSID for pseudo-mesh operation. I just got some more ...
by dalami
Tue Jan 10, 2017 11:21 pm
Forum: Wireless Networking
Topic: Short-range product recommendations [SOLVED]
Replies: 5
Views: 1795

Short-range product recommendations [SOLVED]

Hi all! I've been a happy user of Mikrotik routers for a while - but I've never used Mikrotik wireless. Just didn't need it. Now...but the deep range of products available leaves me confused - I'm not sure where to start. I have a customer that will need to support some wireless cameras. I don't kno...
by dalami
Tue Jul 14, 2015 12:37 am
Forum: RouterBOARD hardware
Topic: RouterBOARD comparison [SOLVED]
Replies: 1
Views: 1495

RouterBOARD comparison [SOLVED]

Is there any existing resource for comparing RouterBOARDs from a processing standpoint? I don't just mean looking at the raw CPU Mhz/RAM - something more along the lines of how many NAT rules/queues can be applied for a given line speed? Something that would tell me - for a 10M connection, model X w...
by dalami
Sun Jun 21, 2015 10:58 am
Forum: RouterBOARD hardware
Topic: Recommended model(s) for 100M cable modem connection [SOLVED]
Replies: 3
Views: 1483

Re: Recommended model(s) for 100M cable modem connection [SOLVED]

That may actually do it! I'll run some more tests... Of course, with fast track, I'm not doing any queuing. The question becomes do I need to with this connection...probably not... So thank you for giving me what I needed (how to use what I already have) instead of what I wanted (something new to bu...
by dalami
Sun Jun 21, 2015 2:13 am
Forum: RouterBOARD hardware
Topic: Recommended model(s) for 100M cable modem connection [SOLVED]
Replies: 3
Views: 1483

Recommended model(s) for 100M cable modem connection [SOLVED]

I recently realized that my RB750GL is a limiting factor in my connection. I found this out after my ISP replaced the modem and got my connection up to full speed - and then I changed some items on my side, which included using hardwired Gigabit connections instead of wireless. I had a number of rul...
by dalami
Sat May 23, 2015 10:41 pm
Forum: Scripting
Topic: Clean old UPnP rules
Replies: 2
Views: 1877

Clean old UPnP rules

This is a script I currently use. I left some of my work in progress comments in place - I was experiementing with a few different ways of getting this to work. No guarantees - but it seems to be working for me. # This script attempts to keep the NAT table current by removing unused UPnP rules. # Th...
by dalami
Tue Mar 27, 2012 7:29 am
Forum: General
Topic: Router with DSL or Cablemodem - traffic shaping [SOLVED]
Replies: 1
Views: 1659

Router with DSL or Cablemodem - traffic shaping [SOLVED]

For supporting either a home or small office - is there any reason to setup queues on the LAN side to limit download speeds? Should the only queues be on the interface connected to the modem? My goal is to: 1. Maximize efficiency and throughput - take full advantage of whatever bandwidth is being pr...
by dalami
Mon Dec 12, 2011 10:14 am
Forum: General
Topic: Upload limiting works great - how do I limit downloads?
Replies: 2
Views: 976

Re: Upload limiting works great - how do I limit downloads?

Is my problem just a basic misunderstanding on networking principles? I've tried using the packet marks from the "upload" rules that match - based on src IP - and using those in the download queues. Looks like it's working correctly. Was I just overcomplicating it?
by dalami
Mon Dec 12, 2011 9:49 am
Forum: General
Topic: Upload limiting works great - how do I limit downloads?
Replies: 2
Views: 976

Upload limiting works great - how do I limit downloads?

Attached is a screen capture from WinBox. I've defined various mangle rules & queues - and my upload rules work great (although I don't know I'm necessarily doing things the "best" way - they do work). My problem is download - none of the rules I've tried seem to match any download tra...