Community discussions

MikroTik App

Search found 249 matches

by biomesh
Sun Feb 07, 2021 1:04 am
Forum: Beginner Basics
Topic: CRS312-4C+8XG-RM Slow Speed / can’t change to SWOs
Replies: 17
Views: 1040

Re: CRS312-4C+8XG-RM Slow Speed / can’t change to SWOs

A serial console cable is probably your best bet at this time. You should be able to get to the boot loader and choose routeros.
by biomesh
Sat Jan 30, 2021 2:59 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS+ TX Pauses.
Replies: 9
Views: 899

Re: RB4011iGS+ TX Pauses.

The correlation between the small frame sizes and counts is probably correct as pause frames are generally small.

Cha0s mentored this is how flow control works. The numbers are not that high, but if you don't like it, just disable it on your devices (routers and switches).
by biomesh
Mon Jan 04, 2021 3:41 pm
Forum: General
Topic: LAN speed issue
Replies: 15
Views: 856

Re: LAN speed issue

You might want to post your config on the crs210 devices. If you are hitting the cpu, then that would explain the ~300Mbps cap.
by biomesh
Sun Jan 03, 2021 5:15 pm
Forum: General
Topic: Upgrading from TP-Link T2600G-28TS
Replies: 1
Views: 198

Re: Upgrading from TP-Link T2600G-28TS

I replaced this switch with a crs326-24g-2s+IN. I am using ros not swos. They definitely boot faster than the 5+ minutes it takes for the tp-link switch.
by biomesh
Fri Jan 01, 2021 9:12 pm
Forum: Wireless Networking
Topic: cAP ac power consumption
Replies: 7
Views: 977

Re: cAP ac power consumption

My cap acs run between 3.5-4 watts during normal operation.
by biomesh
Sun Dec 27, 2020 2:52 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 324
Views: 61388

Re: v6.48 [stable] is released!

Are these gigaset devices having issues with the lldp med options added?

My asterisk, grandstream, and obihai (polycom) devices all work fine.
by biomesh
Thu Dec 24, 2020 2:48 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 324
Views: 61388

Re: v6.48 [stable] is released!

I upgraded the following without any issues:

Crs326-24g-2s+ (with lacp bond), crs317, ccr1009, cap ac, wap ac, hap ac2, hap mini, chr, rb921gs.
by biomesh
Sat Dec 19, 2020 3:15 am
Forum: Beginner Basics
Topic: Mikro + Asterix + One Way Audio
Replies: 4
Views: 405

Re: Mikro + Asterix + One Way Audio

In my experience, you don't need to forward any port if you have a sip trunk in asterisk that is registered. If your Nat settings are off in asterisk, then that is your real issue. An asterisk sip trace or a packet trace of the sip and rtp network traffic will help you identify what is being sent. C...
by biomesh
Mon Dec 14, 2020 1:55 pm
Forum: Beginner Basics
Topic: How to set 12:00 midnight time in Kid Control?
Replies: 5
Views: 559

Re: How to set 12:00 midnight time in Kid Control?

While not the best solution, could you not set a scheduler script to pause kid control then re-enable it a minute(or two) later.
by biomesh
Sun Dec 13, 2020 3:01 pm
Forum: RouterBOARD hardware
Topic: crs317 routeros/switchos wrong fan readings? [SOLVED]
Replies: 6
Views: 760

Re: crs317 routeros/switchos wrong fan readings? [SOLVED]

Sometimes there is a hardware revision shown (if there is one). The documentation - from what I found - only showed the cpu temp sensor.

At this point you should contact mikrotik support to see what they say.
by biomesh
Sun Dec 13, 2020 4:13 am
Forum: RouterBOARD hardware
Topic: crs317 routeros/switchos wrong fan readings? [SOLVED]
Replies: 6
Views: 760

Re: crs317 routeros/switchos wrong fan readings? [SOLVED]

Sounds like there could be a new hardware revision for the crs317. The current specs pdf does show operating temperature changes from September.

It would be best to confirm with mikrotik support.

What does /system/routerboard/print show?
by biomesh
Sat Dec 12, 2020 2:23 pm
Forum: RouterBOARD hardware
Topic: crs317 routeros/switchos wrong fan readings? [SOLVED]
Replies: 6
Views: 760

Re: crs317 routeros/switchos wrong fan readings? [SOLVED]

Some devices will have multiple sensors or sensor output. Both my ccr1009 and crs317 have cpu temp and device temp while my other crs devices have only cpu temp. My crs317 shows: Device temp Cpu temp Fan speed for each fan(if they are running) Psu status for each power supply If you do not see all o...
by biomesh
Fri Dec 11, 2020 8:20 pm
Forum: General
Topic: DNS problem - with Kasa smart plugs
Replies: 29
Views: 1773

Re: DNS problem - with Kasa smart plugs

I don't think it is a capsman issue, but I just wanted to mention that option in case it helped. I have client-to-client forwarding enabled. Per the wiki: client-to-client-forwarding -- controls if client-to-client forwarding between wireless clients connected to interface should be allowed, in loca...
by biomesh
Fri Dec 11, 2020 6:43 pm
Forum: General
Topic: DNS problem - with Kasa smart plugs
Replies: 29
Views: 1773

Re: DNS problem - with Kasa smart plugs

If you have client to client forwarding enabled in capsman then I am sure this is a tplink issue. I tried to duplicate everything you had but mine worked with no pings from the device at all. The firmware doesn't seem to be common between their products so it could be a defect on their side.
by biomesh
Fri Dec 11, 2020 2:37 pm
Forum: General
Topic: DNS problem - with Kasa smart plugs
Replies: 29
Views: 1773

Re: DNS problem - with Kasa smart plugs

You mentioned capsman - are you using local forwarding or capsman forwarding?

I am also guessing that you updated the firmware on the plugs as well. (it normally does this when you first set them up)
by biomesh
Fri Dec 11, 2020 12:11 am
Forum: General
Topic: DNS problem - with Kasa smart plugs
Replies: 29
Views: 1773

Re: DNS problem - with Kasa smart plugs

You might want to use the tplink tools here to see if the plug is reporting anything odd:

https://github.com/softScheck/tplink-smartplug
by biomesh
Thu Dec 10, 2020 5:15 pm
Forum: General
Topic: DNS problem - with Kasa smart plugs
Replies: 29
Views: 1773

Re: DNS problem - with Kasa smart plugs

- Packet 2: I see a 10 minute lease time in the trace. Most devices will not operate well with such a low lease time. I suggest to make it at least a few hours or a day. - Packets 43 & 48: The device cannot ping 8.8.8.8. This could be due to your firewall settings or it could be your ISP. I can ...
by biomesh
Wed Dec 09, 2020 9:47 pm
Forum: General
Topic: DNS problem - with Kasa smart plugs
Replies: 29
Views: 1773

Re: DNS problem - with Kasa smart plugs

I am running the latest stable on all of my devices (routers/swicthes/APs) 6.47.8. I have been using these devices for a long time, so I doubt it is a firmware issue on the routeros side. If you can get a lan trace of one of the kasa devices of about 10-15 minutes it should give you a good idea. You...
by biomesh
Wed Dec 09, 2020 8:10 pm
Forum: General
Topic: DNS problem - with Kasa smart plugs
Replies: 29
Views: 1773

Re: DNS problem - with Kasa smart plugs

Also look at this post - the kasa devices don't like certain subnets:

viewtopic.php?f=2&t=165458#p813598

Stick with 192.168.x.x subnets.
by biomesh
Wed Dec 09, 2020 8:07 pm
Forum: General
Topic: DNS problem - with Kasa smart plugs
Replies: 29
Views: 1773

Re: DNS problem - with Kasa smart plugs

Do you have any firewall rules that restrict traffic for these devices and DNS traffic?

I have over 20 tp-link kasa devices(103/105) that work fine - but I don't restrict the devices. If my DNS servers are down, then the plugs will be in "local" only mode.
by biomesh
Mon Dec 07, 2020 2:59 pm
Forum: General
Topic: 951-2n: router reports about only advertising 10Mbps support
Replies: 1
Views: 202

Re: 951-2n: router reports about only advertising 10Mbps support

This is going to be due to an issue with your cables between the devices. It could just be the rj45 connector or something else. If you can use a different cable and/or plug into another device (switch) - it can help narrow down the issue. There is a slim chance it is an issue with the physical port...
by biomesh
Wed Dec 02, 2020 2:57 am
Forum: Wireless Networking
Topic: wpa_supplicant
Replies: 3
Views: 445

Re: wpa_supplicant

Can you try without the key_mgmt option?
by biomesh
Mon Nov 23, 2020 10:37 pm
Forum: Beginner Basics
Topic: CRS 317-1G-16M+RM WITH CISCO DAC SFP-H10GB-CU3M
Replies: 4
Views: 337

Re: CRS 317-1G-16M+RM WITH CISCO DAC SFP-H10GB-CU3M

I use the MCX311A-XCAT with 10Gtek SFP+ DACs on the CRS317 and CRS309 with no issues.
by biomesh
Mon Nov 23, 2020 10:35 pm
Forum: Wireless Networking
Topic: CAPSMAN issue (cAP ac & CRS326-24G-2S+) - wlan interfaces not coming up
Replies: 11
Views: 571

Re: CAPSMAN issue (cAP ac & CRS326-24G-2S+) - wlan interfaces not coming up

The vlans should not be created on the caps(the only exception would be to create a management vlan interface). The capsman provisioning will tag packets on those SSIDs with the vlan tag based on your datapath config. You don't need to set the tx/rx chains - if you leave it at defaults both chains a...
by biomesh
Mon Nov 23, 2020 7:04 pm
Forum: Wireless Networking
Topic: Capsman - Security Question
Replies: 3
Views: 334

Re: Capsman - Security Question

You can also require a peer certificate. This way only authorized devices can be provisioned.
by biomesh
Mon Nov 23, 2020 7:00 pm
Forum: Wireless Networking
Topic: CAPSMAN issue (cAP ac & CRS326-24G-2S+) - wlan interfaces not coming up
Replies: 11
Views: 571

Re: CAPSMAN issue (cAP ac & CRS326-24G-2S+) - wlan interfaces not coming up

First off, I would get rid of the rates config. This is going to complicate things before you get the basics working. I would set the channels to only be band 5ghz-n/ac. You will rarely see any 5ghz a devices. You are also not using local forwarding on the datapaths, which means that the capsman dev...
by biomesh
Wed Nov 18, 2020 1:01 am
Forum: General
Topic: Having issues with WAP AC AP [SOLVED]
Replies: 13
Views: 670

Re: Having issues with WAP AC AP [SOLVED]

I think if you boot into caps mode with the reset button you have to login and confirm the default config for that mode. If you reboot, it goes back to the default AP mode. As for a default config, here is what I use: /interface bridge add admin-mac=C4:AD:34:EE:BB:AA auto-mac=no name=bridge1 priorit...
by biomesh
Tue Nov 17, 2020 5:32 am
Forum: General
Topic: Having issues with WAP AC AP [SOLVED]
Replies: 13
Views: 670

Re: Having issues with WAP AC AP [SOLVED]

You hold the reset button for 10 seconds (led will turn solid) to put the device into cap mode. Personally I would get a working generic config and copy that config to each of the caps - reset without default config and have it run your custom default config. The config would include your bridge, ca...
by biomesh
Mon Nov 16, 2020 8:45 pm
Forum: General
Topic: MikroTik HAP AC2 fails to link 1Gbps
Replies: 17
Views: 914

Re: MikroTik HAP AC2 fails to link 1Gbps

I would just use another cable and plug it into another device close to your hap ac2 to see if it connects correctly. If it does, it is most likely a cable/rj45 issue.
by biomesh
Mon Nov 16, 2020 8:34 pm
Forum: General
Topic: Where does the Traffic Flow? Cap AC via local forwarding
Replies: 2
Views: 294

Re: Where does the Traffic Flow? Cap AC via local forwarding

At least on my devices, you won't see the traffic go over the bridge other than management traffic. Especially with local forwarding, most of your traffic will be on ether1 and your wlan interfaces.
by biomesh
Mon Nov 16, 2020 7:16 pm
Forum: General
Topic: Multiple VLANs on a single Router Port.
Replies: 11
Views: 1024

Re: Multiple VLANs on a single Router Port.

a. bridge has vlans only and does not function DHCP itself, I dont see a conflict/ b. bridge has vlans AND IS ALSO giving dhcp itself............. What happens when I connect a computer to etherport 5?? Does it get DHCP from the 192.168.10.x subnet or the bridge subnet?? A request that is not tagge...
by biomesh
Mon Nov 09, 2020 12:08 am
Forum: Beginner Basics
Topic: mikrotik router os limit
Replies: 2
Views: 283

Re: mikrotik router os limit

My guess is low memory or disk space.
by biomesh
Mon Oct 26, 2020 1:34 pm
Forum: SwOS
Topic: Noob POE Question
Replies: 1
Views: 272

Re: Noob POE Question

It just means it can be powered by a switch or injector with sufficient power. If you do get passive poe out devices, injectors are generally less safe as they don't do as many checks (or none at all) on the connected devices, unlike switches. Switches normally default to checking the line before su...
by biomesh
Fri Oct 16, 2020 6:16 am
Forum: Wireless Networking
Topic: CAPsMAN Access list
Replies: 5
Views: 457

Re: CAPsMAN Access list

There is a ssid regex option that you can use to apply certain rules in the access list to certain networks. You don't have to specify a Mac address either. You could have an accept rule for all devices in your guest ssid and limit your main network with accept rules for that ssid with only defined ...
by biomesh
Wed Oct 14, 2020 3:06 pm
Forum: Beginner Basics
Topic: 10GB Issues...
Replies: 6
Views: 733

Re: 10GB Issues...

10Gtek dacs work great between my crs326, crs317, and ccr1009.

They are not expensive at all.
by biomesh
Tue Oct 13, 2020 1:51 pm
Forum: General
Topic: single ipv6 /64 range
Replies: 21
Views: 921

Re: single ipv6 /64 range

Comcast rolled out ipv6 to end users many years ago. They provide an address for the wan interface and a prefix. The default prefix size is a /64 since most users don't have multiple subnets or complicated networks. Comcast also offers a /60 for those who need it by use of a prefix hint. This is a g...
by biomesh
Wed Oct 07, 2020 5:25 pm
Forum: SwOS
Topic: CSS610-8G-2S+IN - SWOS 2.12rc2 Upgrade missing
Replies: 15
Views: 2466

Re: CSS610-8G-2S+IN - SWOS 2.12rc2 Upgrade missing

SWOS in my experience, is different on every hardware platform. The crs3xx/css3xx series are the closest to "normal" switch config options/interface. I prefer routeros on the switches since many times swos has limitations and the releases are far and few between. I know that this specific ...
by biomesh
Mon Oct 05, 2020 4:31 am
Forum: Wireless Networking
Topic: ACCESS LIST vs CONNECT LIST
Replies: 11
Views: 1250

Re: ACCESS LIST vs CONNECT LIST

I normally leave it to 10 seconds unless you want to give a client more time on that ap if they seem to drift in and out of range, or if they stay at the signal limit often.
by biomesh
Sun Oct 04, 2020 3:36 pm
Forum: Wireless Networking
Topic: ACCESS LIST vs CONNECT LIST
Replies: 11
Views: 1250

Re: ACCESS LIST vs CONNECT LIST

Capsman access lists are a bit different. The rules are always checked sequentially. I would not use overlapping ranges unless there is other criteria used. So for your example, the following should work. For capsman, it is easier to just add the allow rules first and reject rules at the bottom. You...
by biomesh
Sun Oct 04, 2020 4:27 am
Forum: Wireless Networking
Topic: ACCESS LIST vs CONNECT LIST
Replies: 11
Views: 1250

Re: ACCESS LIST vs CONNECT LIST

The phone could disconnect and reconnect immediately if it meets the requirements in the access list. If it does not meet the requirements but had bad logic it could keep trying to connect and fail until the signal is within the access list range again. I have some 'smart' plugs that are anything bu...
by biomesh
Sat Oct 03, 2020 8:05 pm
Forum: Announcements
Topic: v6.47.4 [stable] is released!
Replies: 68
Views: 16586

Re: v6.47.4 [stable] is released!

It worked for me a week or so ago when I deployed a new cap ac. You need to make sure the config is stored in the /flash directory to make sure it is available after the reset. I used 6.47.4. I confirm this no longer works. run-after-reset is now broken. Also flashfig is now broken and will not exec...
by biomesh
Thu Oct 01, 2020 3:08 pm
Forum: General
Topic: Is there a problem with IP Cloud? [SOLVED]
Replies: 20
Views: 1274

Re: Is there a problem with IP Cloud? [SOLVED]

Do the devices all share the same ISP?

All of my tests have been on Comcast, from various locations on their network.
by biomesh
Wed Sep 30, 2020 10:27 pm
Forum: General
Topic: Is there a problem with IP Cloud? [SOLVED]
Replies: 20
Views: 1274

Re: Is there a problem with IP Cloud? [SOLVED]

I just connected to a RB751G (8 years old) that had never had ip cloud enabled - running 6.47.3 and it updated fine.
by biomesh
Wed Sep 30, 2020 10:20 pm
Forum: General
Topic: Is there a problem with IP Cloud? [SOLVED]
Replies: 20
Views: 1274

Re: Is there a problem with IP Cloud? [SOLVED]

I have a CCR1009 which is almost 5 years old and it has been updating fine - I keep it current, so at one point was on 6.33 or earlier.
by biomesh
Wed Sep 30, 2020 10:07 pm
Forum: General
Topic: Is there a problem with IP Cloud? [SOLVED]
Replies: 20
Views: 1274

Re: Is there a problem with IP Cloud? [SOLVED]

I used the packet sniffer and when you enable ip cloud on a new device it sends one udp packet to one of the addresses resolved by cloud2.mikrotik.com on port 15252. In my case it is sending data to 159.148.172.251 and 159.148.172.201. I tried on two different cap ac devices. Once the request is mad...
by biomesh
Wed Sep 30, 2020 9:33 pm
Forum: General
Topic: Is there a problem with IP Cloud? [SOLVED]
Replies: 20
Views: 1274

Re: Is there a problem with IP Cloud? [SOLVED]

I have a new cap ac that was shipped with 6.44 and updated it to 6.47.4 before resetting the config into caps mode. I just ran the following and it worked fine.
/ip cloud set ddns-enabled=yes 
by biomesh
Wed Sep 30, 2020 8:07 pm
Forum: Beginner Basics
Topic: capAC being Ornery!
Replies: 13
Views: 598

Re: capAC being Ornery!

Devices without a console port can be tough - that is why if I can get one with a console port, I will get that - even if it costs more.
by biomesh
Wed Sep 30, 2020 7:11 pm
Forum: Beginner Basics
Topic: capAC being Ornery!
Replies: 13
Views: 598

Re: capAC being Ornery!

Here are the key points of the config from the ref............. Base vlan = management vlan # Purple Trunk. L2 switching only, Bridge not needed as tagged member (except BASE_VLAN) set bridge=BR1 tagged=ether1 [find vlan-ids=10] set bridge=BR1 tagged=ether1 [find vlan-ids=20] set bridge=BR1 tagged=...
by biomesh
Wed Sep 30, 2020 4:39 pm
Forum: Beginner Basics
Topic: capAC being Ornery!
Replies: 13
Views: 598

Re: capAC being Ornery!

I see where at one point I had a vlan interface - I must have been testing something on that cap - my other caps don't have that interface. Here is a better example. I set the pvid of ether1 to 70 to match the bridge where I actually have vlan 70 tagged on ether1 to avoid a ghost vlan1 since I allow...
by biomesh
Wed Sep 30, 2020 4:21 pm
Forum: Beginner Basics
Topic: capAC being Ornery!
Replies: 13
Views: 598

Re: capAC being Ornery!

I also just tested enabling ingress-filtering=yes on all of my "static" interfaces: bridge, ether1 and ether2 and did not have any issues. I am the only one who configures my network, so I make sure the vlan config matches between the switch and the cap. The ingress-filtering would only im...
by biomesh
Wed Sep 30, 2020 3:49 pm
Forum: Beginner Basics
Topic: capAC being Ornery!
Replies: 13
Views: 598

Re: capAC being Ornery!

Vlan 70 is my wifi management vlan. I don't use vlan interfaces as my bridge address uses dhcp and I set the bridge pvid ( to 70). My dynamic vlan from capsman is added to the config once provisioned. I don't use vlan 1 in my network at all. This is indeed for cap ac as this config is running on fiv...
by biomesh
Wed Sep 30, 2020 1:21 pm
Forum: Beginner Basics
Topic: capAC being Ornery!
Replies: 13
Views: 598

Re: capAC being Ornery!

Is there something different with the switch port the new ap is connected to? Nothing obvious stands out to me, so I would personally check the switch next. I have a basic config I push to all of my cap acs - but it is meant for use by capsman. It uses a dhcp client on the bridge(which is untagged) ...
by biomesh
Tue Sep 29, 2020 12:01 am
Forum: RouterBOARD hardware
Topic: hAP ac2 vs. cAP ac, CAP only usage
Replies: 10
Views: 818

Re: hAP ac2 vs. cAP ac, CAP only usage

Cap AC is really designed to be mounted on a wall or ceiling, and is only powered via POE - it also has POE out on ether2. It comes with extra mounting hardware and an extra cover along with the POE injector. The Hap ac2 has more ethernet ports and a usb port. It can be mounted on the wall, but is p...
by biomesh
Mon Sep 28, 2020 9:43 pm
Forum: SwOS
Topic: RTSP usage
Replies: 2
Views: 422

Re: RTSP usage

It is beneficial if you need redundant links between switches or to detect loops on the network. If neither of those apply to you - you can disable it.
by biomesh
Sat Sep 26, 2020 5:53 am
Forum: SwOS
Topic: Disconnects
Replies: 3
Views: 598

Re: Disconnects

There is a known issue with swos 2.12 with flow control. Your ports can go into a paused state. The easiest fix is to just disable rx and tx flow control on all ports.

If the actual sfp is disappearing, this could be a different issue.
by biomesh
Sun Sep 20, 2020 6:08 pm
Forum: General
Topic: CCR2004 poor bridge performance
Replies: 23
Views: 1630

Re: CCR2004 poor bridge performance

What is the mtu on the client side?
by biomesh
Sat Sep 19, 2020 5:27 pm
Forum: General
Topic: Issues with multiple bonded links in a bridge
Replies: 1
Views: 219

Re: Issues with multiple bonded links in a bridge

Are the bond interfaces in the bridge or are the slave ports? Only the bond interfaces and your one server port (6) should be in the bridge.
by biomesh
Tue Sep 15, 2020 1:28 pm
Forum: General
Topic: CRS326/CRS317 provision failing [SOLVED]
Replies: 8
Views: 582

Re: CRS326/CRS317 provision failing [SOLVED]

Along with the previous suggestion, I would recommend a console cable (if the device supports it - which a crs326 does) or copy over the rsc file and do a resset-configuration and set it to no default config, no backup, and have it run the rsc after reset. It basically means you copy a file and run ...
by biomesh
Tue Sep 15, 2020 12:44 am
Forum: SwOS
Topic: SwOS Update Broke SFP+ Compatibility on CRS305-1G-4S+
Replies: 3
Views: 500

Re: SwOS Update Broke SFP+ Compatibility on CRS305-1G-4S+

Can you see if disabling all flow control on the interfaces helps? 2.12 has an issue where flow control is not working correctly and can cause some links to remain "stuck" with pause frames.
by biomesh
Mon Sep 14, 2020 9:48 pm
Forum: General
Topic: CRS CRS354-48G-4S+2Q+RM does not boot [SOLVED]
Replies: 4
Views: 353

Re: CRS CRS354-48G-4S+2Q+RM does not boot [SOLVED]

Those ports are only useful if the device boots. If it is stuck at the RouterBoot menu, you would really need a console cable.
by biomesh
Mon Sep 14, 2020 9:19 pm
Forum: General
Topic: CRS CRS354-48G-4S+2Q+RM does not boot [SOLVED]
Replies: 4
Views: 353

Re: CRS CRS354-48G-4S+2Q+RM does not boot [SOLVED]

If you have a console cable, you should be able to see the Routerboot menu and use the backup bootloader or choose other boot options.

https://wiki.mikrotik.com/wiki/Manual:RouterBOOT
by biomesh
Sat Sep 12, 2020 5:45 pm
Forum: SwOS
Topic: CSS106-1G-4P-1S (RB260GSP) link speed changing [SOLVED]
Replies: 4
Views: 370

Re: CSS106-1G-4P-1S (RB260GSP) link speed changing [SOLVED]

If the port was flapping, it could be due to an issue with some rstp configs in swos 2.12 - you can try 2.11 to see if that helps.
by biomesh
Sat Sep 12, 2020 5:10 pm
Forum: Wireless Networking
Topic: mantbox 19s VS mant19s
Replies: 1
Views: 246

Re: mantbox 19s VS mant19s

The mantbox includes an integrated router board and is all you would need for connectivity. The mant is only the antenna.
by biomesh
Sat Sep 12, 2020 4:09 pm
Forum: RouterOS v7 BETA
Topic: TLS handshake failed when relaying via smtp.gmail.com [SOLVED]
Replies: 22
Views: 1537

Re: TLS handshake failed when relaying via smtp.gmail.com [SOLVED]

I still use smtp.gmail.com with tls(port 587) a user with an app password and never have imported certs to get this to work. I have a scheduled script that emails me exports once a week and it works fine. I have a feeling this is due to 2fa or an incomplete user name. I have a service account that I...
by biomesh
Sat Sep 12, 2020 3:37 pm
Forum: SwOS
Topic: CSS106-1G-4P-1S (RB260GSP) link speed changing [SOLVED]
Replies: 4
Views: 370

Re: CSS106-1G-4P-1S (RB260GSP) link speed changing [SOLVED]

Most likely bad cabling or connections somewhere. I have this issue with one of my ports in my house, but it isn't limited to Mikrotik products.

In my case it is an rj45 connector that needs to be replaced. I can jiggle it and get it to stay at 1G, so not a priority to fix.
by biomesh
Wed Sep 09, 2020 11:07 pm
Forum: General
Topic: Packet Sniffer and Wireshark
Replies: 5
Views: 523

Re: Packet Sniffer and Wireshark

I use this method all of the time - I am using the current versions of both. If your tzsp port matches between ROS and Wireshark it should decode everything normally. If you want to just get your traffic that is streamed, make sure you use a capture filter and not a display filter( i.e. "udp po...
by biomesh
Sat Sep 05, 2020 6:12 pm
Forum: Beginner Basics
Topic: Mikrotik router behind Comcast business modem with dynamic IPv6
Replies: 59
Views: 2554

Re: Mikrotik router behind Comcast business modem with dynamic IPv6

The default (from the default config from an rb931) is none. I don't think this is enabled default. If you use quickset or set it manually it is enabled.
by biomesh
Sat Sep 05, 2020 5:16 pm
Forum: Beginner Basics
Topic: Mikrotik router behind Comcast business modem with dynamic IPv6
Replies: 59
Views: 2554

Re: Mikrotik router behind Comcast business modem with dynamic IPv6

/interface detect-internet detect-interface-list=none
by biomesh
Sat Sep 05, 2020 5:13 pm
Forum: Beginner Basics
Topic: hAP ac^2 - higher upload speed than download
Replies: 14
Views: 915

Re: hAP ac^2 - higher upload speed than download

It looks like you have some channels set to tx-power of 11. That isn't extremely high, but if you might want to try it a bit lower just to check performance and range.
by biomesh
Sat Sep 05, 2020 3:20 pm
Forum: Beginner Basics
Topic: Mikrotik router behind Comcast business modem with dynamic IPv6
Replies: 59
Views: 2554

Re: Mikrotik router behind Comcast business modem with dynamic IPv6

For those with the odd behavior of not being able to connect after some time you might want to set all detect-internet interfaces to none.
by biomesh
Sat Sep 05, 2020 3:02 pm
Forum: Beginner Basics
Topic: hAP ac^2 - higher upload speed than download
Replies: 14
Views: 915

Re: hAP ac^2 - higher upload speed than download

First off the tx power should not be negative. Normally in capsman you would configure tx power on the channel config and that would be it. You have it set on the cap configuration as well which would override the channel config. So the value 25 is the one being used. It is pretty high though. You m...
by biomesh
Fri Sep 04, 2020 11:47 pm
Forum: Beginner Basics
Topic: Mikrotik router behind Comcast business modem with dynamic IPv6
Replies: 59
Views: 2554

Re: Mikrotik router behind Comcast business modem with dynamic IPv6

Bridge mode means that the router should get a dynamic address. If you have a static allocation your gateway would have to be in router/gateway mode. DHCP should work if the gateway device is actually handing out a DHCP address. Run the packet sniffer to see if dhcp requests are being sent and how t...
by biomesh
Fri Sep 04, 2020 3:09 pm
Forum: Beginner Basics
Topic: How should I set up for access points?
Replies: 4
Views: 357

Re: How should I set up for access points?

The disc lite5 ac is a ptp cpe device, not deigned as an ap. If looking for dial band with gigabit interfaces stick with the wap ac, cap ac or hap ac2.
by biomesh
Fri Sep 04, 2020 4:24 am
Forum: Beginner Basics
Topic: Mikrotik router behind Comcast business modem with dynamic IPv6
Replies: 59
Views: 2554

Re: Mikrotik router behind Comcast business modem with dynamic IPv6

If you do run into any issues, I would focus on your firewall rules. Disable the vlan restricting ones then enable one by one until you find the culprit.
by biomesh
Fri Sep 04, 2020 3:25 am
Forum: Beginner Basics
Topic: Mikrotik router behind Comcast business modem with dynamic IPv6
Replies: 59
Views: 2554

Re: Mikrotik router behind Comcast business modem with dynamic IPv6

Are you connecting to the router ip for that subnet, or a different vlan? You have firewall rules blocking inter vlan traffic.
by biomesh
Wed Sep 02, 2020 2:12 pm
Forum: Wireless Networking
Topic: [Help] Mikrotik CAPsMAN Wireless download speed max 200Mb, but PC's /Mobile's link speed is 866Mbps
Replies: 50
Views: 3335

Re: [Help] Mikrotik CAPsMAN Wireless download speed max 200Mb, but PC's /Mobile's link speed is 866Mbps

I don't really see anything wrong with the config, but I would definitely see if capsman forwarding is your issue. Check the cpu on your ap and router while doing iperf speed tests. You might want to see if you have overlapping channels too close to one another since you are using 80MHz channels. Ma...
by biomesh
Wed Sep 02, 2020 1:14 pm
Forum: Wireless Networking
Topic: [Help] Mikrotik CAPsMAN Wireless download speed max 200Mb, but PC's /Mobile's link speed is 866Mbps
Replies: 50
Views: 3335

Re: [Help] Mikrotik CAPsMAN Wireless download speed max 200Mb, but PC's /Mobile's link speed is 866Mbps

In real life (no matter what hardware you use) you will generally get up to 1/2 the transfer speeds with regards to your link speeds.

As for your config, can you post an export from your capsman manager device? This provides more details to be able to help.
by biomesh
Mon Aug 31, 2020 11:24 pm
Forum: RouterBOARD hardware
Topic: 16 port short depth PoE switch
Replies: 9
Views: 903

Re: 16 port short depth PoE switch

If they do make a IN version, they should have the case large enough for 40mm fans instead of the 30mm space for the crs326-24g-2s+IN. Raspberry pi fans are pretty much the only common offering in that size.
by biomesh
Mon Aug 31, 2020 5:02 pm
Forum: RouterBOARD hardware
Topic: 16 port short depth PoE switch
Replies: 9
Views: 903

Re: 16 port short depth PoE switch

A crs318-16P-2S+ would be great. I would like it in an "IN" desktop form factor, although I am sure a RM version would be popular too.
by biomesh
Sun Aug 30, 2020 5:35 am
Forum: RouterBOARD hardware
Topic: USB Data Lines hAP mini (RB931-2nD)
Replies: 3
Views: 352

Re: USB Data Lines hAP mini (RB931-2nD)

According to the quick guide they are power only:

https://i.mt.lv/cdn/product_files/hAP-m ... 190504.pdf
by biomesh
Fri Aug 28, 2020 9:45 pm
Forum: General
Topic: Can't add a DHCP server pool error 6.47.2
Replies: 4
Views: 510

Re: Can't add a DHCP server pool error 6.47.2

Are you out of disk space? I see extra packages installed in the first screenshot and your export references user-manager (with errors) and it doesn't show the pool you created.
by biomesh
Fri Aug 28, 2020 6:34 pm
Forum: Beginner Basics
Topic: Mikrotik router behind Comcast business modem with dynamic IPv6
Replies: 59
Views: 2554

Re: Mikrotik router behind Comcast business modem with dynamic IPv6

If there is a dhcp server on the modem / combo box it should provide an address. You might want to also update to a current version as 6.42.11 is very old - it looks to be a dev build anyway. There have been dhcp client related fixes since then, so you could be hitting an old bug. Also be aware that...
by biomesh
Fri Aug 28, 2020 3:54 pm
Forum: General
Topic: DHCP issue with Win 10 clients
Replies: 4
Views: 305

Re: DHCP issue with Win 10 clients

Update your dhcp server from /ip dhcp-server add add-arp=yes address-pool=pool1 delay-threshold=5m disabled=no interface=\ br_lan lease-script="" lease-time=10m name=server1 use-radius=no to /ip dhcp-server add add-arp=yes address-pool=pool1 authoritative=yes disabled=no interface=\ br_lan...
by biomesh
Fri Aug 28, 2020 2:15 pm
Forum: Beginner Basics
Topic: How to set IP address to switch while using VLANs?
Replies: 15
Views: 915

Re: How to set IP address to switch while using VLANs?

For the switches if you use static addresses you need to make sure you use vlan interfaces assigned to the bridge and set those interfaces and the bridge as being tagged for the respective vlan. Add an ip to the vlan interface and set the route. I prefer to use dhcp on a management vlan that is rest...
by biomesh
Fri Aug 28, 2020 2:02 pm
Forum: General
Topic: DHCP issue with Win 10 clients
Replies: 4
Views: 305

Re: DHCP issue with Win 10 clients

Sounds like a config issue as it works partially. Please post your config so we can see how it is configured.
by biomesh
Fri Aug 28, 2020 1:56 pm
Forum: Wireless Networking
Topic: Make CAPSMAN-Setup VLAN-aware (mac-adress based) [SOLVED]
Replies: 8
Views: 715

Re: Make CAPSMAN-Setup VLAN-aware (mac-adress based) [SOLVED]

The problem with the station pseudobridge mode is that they don't work well with dhcp clients due to the Mac translation. Station pseudobridge clone mode will help if you only have one dhcp client on that device. It is best to statically assign ip addresses to client devices (the printers in your ca...
by biomesh
Fri Aug 28, 2020 1:36 pm
Forum: Beginner Basics
Topic: Mikrotik router behind Comcast business modem with dynamic IPv6
Replies: 59
Views: 2554

Re: Mikrotik router behind Comcast business modem with dynamic IPv6

It's probably not really in bridge mode then. On the dslreports forums in the past people have reported many issues with those devices (normally smc devices). You are better off buying/trying a standard modem on the business class supported modem list and get the modem activated on the account. This...
by biomesh
Fri Aug 28, 2020 6:06 am
Forum: Beginner Basics
Topic: Mikrotik router behind Comcast business modem with dynamic IPv6
Replies: 59
Views: 2554

Re: Mikrotik router behind Comcast business modem with dynamic IPv6

Is the Comcast device a modem only or is it a business class modem/router combo device? If it is a combo device then you need to call Comcast support and put it in bridged mode. I looked at the config quickly and didn't see any reason to not get a valid address, so it looks like you might be dealing...
by biomesh
Fri Aug 28, 2020 3:54 am
Forum: Beginner Basics
Topic: Mikrotik router behind Comcast business modem with dynamic IPv6
Replies: 59
Views: 2554

Re: Mikrotik router behind Comcast business modem with dynamic IPv6

Post your config. I have been using both ipv4 and ipv6 since Comcast began supporting ipv6(quite a number of years ago). The dynamic ip should be an ipv4 though and you should also get a ipv6 address and a prefix (/64 or /60). If you are switching between routers, be sure to reboot the modem as they...
by biomesh
Wed Aug 26, 2020 10:48 pm
Forum: General
Topic: TP Link Smart Plug Minis Not Keeping Connection to TP Link Cloud [SOLVED]
Replies: 8
Views: 1206

Re: TP Link Smart Plug Minis Not Keeping Connection to TP Link Cloud [SOLVED]

Your lease time is 10 minutes, so the plug is going to try and renew the least at the 50% time left mark - 5 minutes. Unless you have a lot of unique devices coming and going on that vlan/subnet you can dramatically increase the lease time for DHCP addresses. Perhaps there is a code issue with the p...
by biomesh
Wed Aug 26, 2020 10:10 pm
Forum: General
Topic: TP Link Smart Plug Minis Not Keeping Connection to TP Link Cloud [SOLVED]
Replies: 8
Views: 1206

Re: TP Link Smart Plug Minis Not Keeping Connection to TP Link Cloud [SOLVED]

I just ran a sniffer trace on the plug right next to me and I don't see the same results. You will need to look at the packet details/decodes in wireshark to see what request/response was made to help determine what the issue is. If you want to upload/post your packet capture then myself and perhaps...
by biomesh
Wed Aug 26, 2020 7:34 pm
Forum: General
Topic: TP Link Smart Plug Minis Not Keeping Connection to TP Link Cloud [SOLVED]
Replies: 8
Views: 1206

Re: TP Link Smart Plug Minis Not Keeping Connection to TP Link Cloud [SOLVED]

The only issues I have had with the TP-Link smart plugs have been due to the DNS server(s) being down. I don't have them on their own IOT vlan though. They only connect to 2.4G wireless so 5G wireless should have no bearing. I would configure the packet sniffer to forward traffic to wireshark on you...
by biomesh
Wed Aug 26, 2020 2:02 pm
Forum: General
Topic: CRS326-24S+2Q 200 MBit/s Maxout
Replies: 6
Views: 639

Re: CRS326-24S+2Q 200 MBit/s Maxout

Looking at your config you are only switching 2 ports - the qsfp+ ports. Everything else is going through the cpu. The bond interfaces need to be added to the bridge as well. Any bonded slave interface will not be in the bridge but only the bond interface itself. Any other standard interface should ...
by biomesh
Tue Aug 25, 2020 2:47 am
Forum: General
Topic: CRS326-24S+2Q 200 MBit/s Maxout
Replies: 6
Views: 639

Re: CRS326-24S+2Q 200 MBit/s Maxout

Your config is way off. The config really needs to be mainly done via the bridge.

https://wiki.mikrotik.com/wiki/Manual:C ... s_switches

Here is the link for vlans with bonds on the crs3xx series.

https://wiki.mikrotik.com/wiki/Manual:C ... with_Bonds
by biomesh
Wed Aug 19, 2020 7:54 pm
Forum: Wireless Networking
Topic: CAPs-MAN issues
Replies: 3
Views: 705

Re: CAPs-MAN issues

Make sure extension-channel=disabled. By default they are enabled.
by biomesh
Wed Aug 19, 2020 4:25 pm
Forum: Wireless Networking
Topic: CAP interface MAC
Replies: 10
Views: 736

Re: CAP interface MAC

I have the same results as mkx. I have provisioning rules for all caps though. I set the identity on each cap to let capsman set the correct channel and config for each radio/cap instead of any manual creation or configuration on each cap.
by biomesh
Tue Aug 18, 2020 5:47 am
Forum: General
Topic: Wireless unable to connect to Internet...
Replies: 9
Views: 1261

Re: Wireless unable to connect to Internet...

I would disable wpa2-eap, change the group and unicast ciphers to aes-ccm, and set the channel width to 20 mhz only. You might also want to specify a channel instead of auto.
by biomesh
Sat Aug 08, 2020 10:46 pm
Forum: Announcements
Topic: SwOS version 2.12 released!
Replies: 89
Views: 48091

Re: SwOS version 2.12 released!

Hi all, unfortunately have to confirm major problems with 2.12. Updating 2 CS106-5G-1S nearly wrecked my network. Took me a day to figure out I had to turn off RSTP on all Ports to make it work again. I can confirm that rstp does not work with 2.12 on the cs106-1g-4p-1s as well. It works fine on th...
by biomesh
Mon Aug 03, 2020 12:38 am
Forum: Wireless Networking
Topic: CAPsMAN different boards at 2.4 and 5Ghz one SSID
Replies: 7
Views: 1403

Re: CAPsMAN different boards at 2.4 and 5Ghz one SSID

You will generally have two provisioning rules at a minimum for a dual band radio. One for 2.4 and one for 5 GHz radiios. Just specify the correct settings for each radio and keep the ssid the same if that is what you want.
by biomesh
Thu Jul 30, 2020 2:24 pm
Forum: General
Topic: cAP Ac wall mounting question [SOLVED]
Replies: 3
Views: 847

Re: cAP Ac wall mounting question [SOLVED]

To have the cable run out the side of the cap ac, there are two molded u shaped sections next to the Ethernet connections that can be removed (gently with needle nosed pliers).

I don't know if that counts to you as being modded, but that is what they are for.
by biomesh
Fri Jul 24, 2020 1:40 pm
Forum: Wireless Networking
Topic: How to get more than 54Mbps speed with 2.4Ghz band in hAP Ac? [SOLVED]
Replies: 7
Views: 1643

Re: How to get more than 54Mbps speed with 2.4Ghz band in hAP Ac? [SOLVED]

Enable wmm support, that should help. The link rate is locked to a max of 54Mbps if it is disabled.
by biomesh
Thu Jul 23, 2020 11:36 pm
Forum: Wireless Networking
Topic: Multiple SSIDs in Capsman whit manual added interfaces [SOLVED]
Replies: 10
Views: 2171

Re: Multiple SSIDs in Capsman whit manual added interfaces [SOLVED]

Can you explain why provisioning rules won't work in your config to provision the virtual APs? For each radio that is managed by capsman, you really need to manage it via capsman, otherwise you are defeating the purpose of using capsman.
by biomesh
Wed Jul 22, 2020 1:03 am
Forum: Announcements
Topic: SwOS version 2.12 released!
Replies: 89
Views: 48091

Re: SwOS version 2.12 released!

@k6ccc - You are right, just tested with my css326. In the past with other switches I have had to set it to active. I set mine to active or passive, either way it worked for my lacp based lag.
by biomesh
Tue Jul 21, 2020 3:13 pm
Forum: Announcements
Topic: SwOS version 2.12 released!
Replies: 89
Views: 48091

Re: SwOS version 2.12 released!

For lag config you would set both sides to active to have them participate in the group. One of the changes in this version was to allow lag to work with only one member active. While there could be an issue with how much membership traffic is sent, this is really a config issue on your end.
by biomesh
Sat Jul 18, 2020 6:15 pm
Forum: Announcements
Topic: SwOS version 2.12 released!
Replies: 89
Views: 48091

Re: SwOS version 2.12 released!

Have you tried to disable flow control Rx and tx on all routers/switches on the sfp+ interfaces?
by biomesh
Fri Jul 17, 2020 2:59 pm
Forum: Beginner Basics
Topic: hAP ac2 – slow transfer speed between vlans
Replies: 14
Views: 3718

Re: hAP ac2 – slow transfer speed between vlans

@mkx - My point was just going to have the hap ac2 as just a router (1 wan, 1 Lan) and have it only do the routing between vlans (and wan). This was to see if the performance was better than with the switch/bridge config.
by biomesh
Fri Jul 17, 2020 1:55 pm
Forum: Beginner Basics
Topic: hAP ac2 – slow transfer speed between vlans
Replies: 14
Views: 3718

Re: hAP ac2 – slow transfer speed between vlans

@mkx I agree with you 100%. The question is if the extra load from the bridging is causing the extra load. If he were to handle vlan tagging on the switch and just do a 'router on a stick' config would that get the performance where it needs to be?
by biomesh
Fri Jul 17, 2020 12:01 am
Forum: Beginner Basics
Topic: hAP ac2 – slow transfer speed between vlans
Replies: 14
Views: 3718

Re: hAP ac2 – slow transfer speed between vlans

You have vlan filtering enabled on your bridge which disables hardware offloading on the hap ac2. https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_Hardware_Offloading You should really be doing the vlan tagging/filtering on your css326. It is swos, so there is no bridge config, just vla...
by biomesh
Sun Jul 12, 2020 2:50 am
Forum: General
Topic: Monthly Reboot
Replies: 3
Views: 1029

Re: Monthly Reboot

How about 30d 00:00:00
by biomesh
Sun Jun 28, 2020 3:13 pm
Forum: Announcements
Topic: v6.47 [stable] is released!
Replies: 349
Views: 107308

Re: v6.47 [stable] is released!

For those having issues flushing the dns cache, from my experience, this is due to a winbox bug IMO. If I have a large cache (a few mb) then through winbox the cache will never clear. If I run a /ip dns cache flush, it works. I also tested with disabling remote requests, flush cache, and enabling re...
by biomesh
Fri Mar 17, 2017 1:48 pm
Forum: Beginner Basics
Topic: RB450G Performance Issues
Replies: 5
Views: 908

Re: RB450G Performance Issues

Since you don't have any firewall rules enabled, I would disable remote access to dns.
/ip dns
set allow-remote-requests=no servers=172.16.10.10
by biomesh
Wed Jun 22, 2016 2:35 pm
Forum: Wireless Networking
Topic: CAPsMAN APs conflict
Replies: 2
Views: 692

Re: CAPsMAN APs conflict

You might want to drop the power levels on the APs so the clients don't try to roam as much.
by biomesh
Thu Jun 16, 2016 4:10 pm
Forum: General
Topic: IPv6 link-local address
Replies: 2
Views: 1294

Re: IPv6 link-local address

I would suggest using unique local addresses vs link-local addresses at this point if you need to add a static address.  It would be the fd00::/8 range.
by biomesh
Mon May 23, 2016 11:43 pm
Forum: General
Topic: CCR1009 Memory Leak
Replies: 6
Views: 1363

Re: CCR1009 Memory Leak

If you are getting supout.rif's, you should email that to mikrotik support (support[at]mikrotik.com:) - since this is a user based support forum, it does not help us. You can post your device's config export (/export) so we can see what could be the issue. I would start by emailing support directly ...
by biomesh
Mon May 23, 2016 6:30 pm
Forum: General
Topic: CCR1009 Memory Leak
Replies: 6
Views: 1363

Re: CCR1009 Memory Leak

You will have to provide more details - ROS version, post your config, etc. Myself and plenty others use a CCR1009 with no memory leak issues, so this must be a version/config issue.
by biomesh
Fri Mar 18, 2016 2:50 pm
Forum: General
Topic: Quickset & CCR1009-8G-1S-1S+
Replies: 8
Views: 1105

Re: Quickset & CCR1009-8G-1S-1S+

I have seen this, but it has never been an issue for me since I do not use quickset for this device.

If you have an urgent issue or would like something addressed by MikroTik, you should email support.
by biomesh
Thu Mar 03, 2016 5:31 pm
Forum: General
Topic: CCR1009-8G-1S Replacement
Replies: 12
Views: 1582

Re: CCR1009-8G-1S Replacement

The RB3011 series uses an ARM processor, which is still a work in progress. You are better off just using another CCR1009 model or better.
by biomesh
Thu Mar 03, 2016 6:14 am
Forum: General
Topic: CCR1009-8G-1S Replacement
Replies: 12
Views: 1582

Re: CCR1009-8G-1S Replacement

Why not just use one of the other ccr1009 models?

They do have a passive cooling model which is probably the closest upgrade. The other two models (passive or active cooling) cost more and have extra features.
by biomesh
Wed Mar 02, 2016 7:26 pm
Forum: RouterBOARD hardware
Topic: CCR1009-8G-1S-1S+PC system healt voltage problem, current and power usage is missing
Replies: 3
Views: 1080

Re: CCR1009-8G-1S-1S+PC system healt voltage problem, current and power usage is missing

Mine looks accurate - make sure you have updated firmware (/system routerboard upgrade). I am on firmware 3.27. /system health print cpu-overtemp-check: yes cpu-overtemp-threshold: 100C cpu-overtemp-startup-delay: 1m voltage: 23.7V current: 611mA temperature: 38C cpu-temperature: 45C power-consumpti...
by biomesh
Fri Feb 26, 2016 5:07 pm
Forum: General
Topic: Poor performance of Cloud Core Router - CCR1009-8G-1S-1S+
Replies: 2
Views: 1213

Re: Poor performance of Cloud Core Router - CCR1009-8G-1S-1S+

I may not be an expert, in what you are trying to do, but it sounds like you expect the router to be a voip SBC. These are specialized devices for voip which can handle the load you are giving them which also include some firewalling capabilities. The SIP ALG in most routers are very basic and shoul...
by biomesh
Wed Feb 24, 2016 5:32 pm
Forum: Beginner Basics
Topic: Comcast and IPv6 Basic Config
Replies: 7
Views: 3697

Re: Comcast and IPv6 Basic Config

Most of these configs that have been posted are for a standard docsis 3 modem, not one of the business gateways. The gateways have their own quirks and most of the time lots of bugs. Unless you need static IPs, I would ditch the gateway and buy your own modem.
by biomesh
Tue Feb 23, 2016 11:23 pm
Forum: Beginner Basics
Topic: Comcast and IPv6 Basic Config
Replies: 7
Views: 3697

Re: Comcast and IPv6 Basic Config

Here is my config. I changed the interface names to match yours. This also includes my firewall settings. /ipv6 address add address=::1 from-pool=comcast_ipv6 interface=bridge /ipv6 dhcp-client add add-default-route=yes interface= pool-name=comcast_ipv6 prefix-hint=::/60 request=address,prefix use-p...
by biomesh
Wed Jan 27, 2016 3:11 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 221130

Re: Cloud Hosted Router

Juanvi, you can use the vmware provided tool vmware-vdiskmanager for the pre deployment resizing.
by biomesh
Wed Dec 09, 2015 8:23 pm
Forum: Virtualization
Topic: Cloud Hosted Router
Replies: 583
Views: 221130

Re: Cloud Hosted Router

Looks good - Now I am just waiting for the licensing to be enabled for purchase. Will there be any way to convert prepaid standard keys (level 4/5/6) to a CHR equivalent license?
by biomesh
Wed Nov 04, 2015 5:00 pm
Forum: Beginner Basics
Topic: RB2011 Comcast & Surfboard SB6141 WAN Speed
Replies: 5
Views: 908

Re: RB2011 Comcast & Surfboard SB6141 WAN Speed

The 2011 should be able to handle up to ~200 Mbps depending on the config. The 6141 should really have not bearing on this, with the exception of what type of service you have with comcast. If you have residential, you will only get 1 IPv4 address, but you can get multiple IPv6 prefixes (limited by ...
by biomesh
Wed Jul 15, 2015 7:18 pm
Forum: Beginner Basics
Topic: Getting a /128 on Comcast
Replies: 2
Views: 977

Re: Getting a /128 on Comcast

You don't need the /128 address to work with comcast. You will need to make sure you assign an address to your internal interface and you should set up ND too. Here is my IPv6 config that I have been using with comcast for probably a year. /ipv6 address add address=::1 from-pool=comcast_ipv6 interfa...
by biomesh
Sat Sep 27, 2014 12:31 am
Forum: General
Topic: RB2011UiAS-2HnD-IN CPU bottleneck
Replies: 14
Views: 4208

Re: RB2011UiAS-2HnD-IN CPU bottleneck

You hit the cpu limit for nat/conntrack for this device. A ccr or RB1100AHx2 would be the device you would need to get gigabit speeds.

You might just want to let the at&t router do the nat unless you want to spend $350-$425 on a new MT router.
by biomesh
Mon Jun 09, 2014 9:17 pm
Forum: General
Topic: v6.14 released
Replies: 115
Views: 29525

Re: v6.14 released

Some good changes here, including the new "ip cloud" menu
What exactly is the point of "ip cloud" when you cannot remember your dns name?
If you have your own domain, just create cname records that point to your serial number dynamic dns records hosted by mikrotik.
by biomesh
Thu Jun 05, 2014 11:39 pm
Forum: Forwarding Protocols
Topic: Cant bridge IPX traffic (novell)
Replies: 8
Views: 2391

Re: Cant bridge IPX traffic (novell)

As for IPX, NCP (which is the only common protocol that was used with IPX/SPX) had TCP/IP support added almost 20 years ago.
by biomesh
Thu May 22, 2014 9:13 pm
Forum: General
Topic: Crashplan Cloud Backup eating all bandwidth - QoS help
Replies: 4
Views: 2361

Re: Crashplan Cloud Backup eating all bandwidth - QoS help

Here are my queues. They give voip traffic the highest priority, any regular traffic the next highest priority and crashplan traffic the lowest priority. You would need to adjust to your environment (limit, max-limit, parent, etc) /queue type set 0 pfifo-limit=500 add kind=pcq name=pcq-crashplan-upl...
by biomesh
Tue May 20, 2014 10:15 pm
Forum: General
Topic: Crashplan Cloud Backup eating all bandwidth - QoS help
Replies: 4
Views: 2361

Re: Crashplan Cloud Backup eating all bandwidth - QoS help

You would have to add a mangle rule to mark the packets like /ip firewall mangle add action=mark-packet chain=postrouting comment=crashplan dscp=2 new-packet-mark=crashplan passthrough=no You would then just need to set up queues to make the traffic low priority. The issue with QOS on windows is tha...
by biomesh
Tue Apr 15, 2014 7:11 pm
Forum: RouterBOARD hardware
Topic: RB951-2n memory size reported incorrectly by routerOS?
Replies: 5
Views: 1710

Re: RB951-2n memory size reported incorrectly by routerOS?

Looks like you got a CPU bump as well. By default it have 300 mhz but you can overclock to 400 mhz. I have a few of the original ones, and you can only set them to 360 MHz (default) or 240 MHz. For a while, they had 400/300 and I think 240 options, but due to some stability issues with the original...
by biomesh
Tue Apr 15, 2014 5:34 pm
Forum: RouterBOARD hardware
Topic: RB951-2n memory size reported incorrectly by routerOS?
Replies: 5
Views: 1710

Re: RB951-2n memory size reported incorrectly by routerOS?

Looks like you got a CPU bump as well.
by biomesh
Sat Mar 29, 2014 7:24 pm
Forum: Beginner Basics
Topic: Can't get IP from ISP
Replies: 7
Views: 1765

Re: Can't get IP from ISP

Comcast provides an ipv4 address on all connections and ipv6 on most. The person you talked to was incorrect. You need to reset the cable modem so that it will see the mac address of the new router. Residential comcast connections only provide one ipv4 address and it is restricted by the cable modem...
by biomesh
Wed Mar 26, 2014 7:24 pm
Forum: General
Topic: No record of ICMP traffic on interfaces in 6.11
Replies: 2
Views: 1390

Re: No record of ICMP traffic on interfaces in 6.11

Most likely it is a gateway device, not just a modem. It does a 1 to 1 NAT for the static IPs. I would check the settings on it to disable all firewall rules and ICMP handling so that way the 450G will see the traffic.
by biomesh
Tue Mar 04, 2014 5:19 pm
Forum: General
Topic: Feature Request: Remote Packet Capture Protocol
Replies: 6
Views: 3394

Re: Feature Request: Remote Packet Capture Protocol

https://www.wireshark.org/docs/wsug_html_chunked/ChCapInterfaceRemoteSection.html The Remote Packet Capture Protocol service must first be running on the target platform before Wireshark can connect to it. The easiest way is to install WinPcap from http://www.winpcap.org/install/default.htm on the ...
by biomesh
Tue Mar 04, 2014 3:43 pm
Forum: General
Topic: Feature Request: Remote Packet Capture Protocol
Replies: 6
Views: 3394

Re: Feature Request: Remote Packet Capture Protocol

If you have a request for a different implementation, it would be best to include the different options that would work better for you.
Personally, tzsp had worked fine for my needs.

Sent from my Nexus 7 using Tapatalk
by biomesh
Tue Mar 04, 2014 3:35 pm
Forum: General
Topic: Feature Request: Remote Packet Capture Protocol
Replies: 6
Views: 3394

Re: Feature Request: Remote Packet Capture Protocol

You can do this already.

http://wiki.mikrotik.com/wiki/Ethereal/Wireshark

Follow the directions in the wiki and set the display filter in wireshark to tzsp.


Sent from my Nexus 7 using Tapatalk
by biomesh
Mon Feb 24, 2014 8:12 pm
Forum: RouterBOARD hardware
Topic: New hardware - mAP
Replies: 154
Views: 60508

Re: New hardware - mAP

Product presentation: http://mum.mikrotik.com/presentations/IT14/it14.pdf New brochure with mAP and others: http://download2.mikrotik.com/2014-Q1.pdf Why reduce NAND on RB850Gx2 compared to RB450G ?? JF. I hope the 400Mhz in the brochure is a typo. The MUM presentation lists the CPU as 500MHz. The ...
by biomesh
Sat Feb 22, 2014 11:28 pm
Forum: General
Topic: US VoIP Service Providers ??
Replies: 3
Views: 1308

Re: US VoIP Service Providers ??

The ones that pcunite mentioned are good along with anveo.com

Sent from my Nexus 7 using Tapatalk
by biomesh
Wed Jan 29, 2014 9:28 pm
Forum: General
Topic: What's new in 6.8rc1
Replies: 106
Views: 27076

Re: What's new in 6.8rc1

Dial on demand does not work on the RC that was released briefly this morning. A L2TP (and sstp) client that worked in previous releases (6.6 and earlier including 5.x) would not start. The interface did work if dial on demand was deactivated and was started manually.
by biomesh
Thu Dec 26, 2013 11:40 pm
Forum: RouterBOARD hardware
Topic: RB110AHx2 disk
Replies: 4
Views: 1723

Re: RB110AHx2 disk

According to the brochures, the 12 core CCR devices have 512 mb of nand and the 36 core versions have 1gb of nand.

Sent from my Nexus 7 using Tapatalk 4
by biomesh
Sat Dec 21, 2013 12:09 am
Forum: General
Topic: [FEATURE REQUEST] DHCPv6-PD IA-PD Support
Replies: 16
Views: 4498

Re: [FEATURE REQUEST] DHCPv6-PD IA-PD Support

I also did some testing with the sniffer. From what I see, if you have a lease, but release, and the router tries to renew, Comcast sends two advertisements back, the /60 you asked for, and your existing lease, in my case, a /64. What it does is set preference for the leases, the /60 you asked for ...
by biomesh
Thu Dec 19, 2013 12:21 am
Forum: General
Topic: [FEATURE REQUEST] DHCPv6-PD IA-PD Support
Replies: 16
Views: 4498

Re: [FEATURE REQUEST] DHCPv6-PD IA-PD Support

Interesting. I actually was thinking about running a sniffer on it to see. The guy @ comcast I'm working with indicates their systems should accept a release, specifically I'll quote him as saying, "I can delete that PD for you, your client isn’t doing a full release\renew.. I see this a lot.....
by biomesh
Tue Dec 17, 2013 5:47 pm
Forum: General
Topic: Packets lost
Replies: 5
Views: 2396

Re: Packets lost

Fragmenting packets will always put an extra load on the system. UDP is also stateless. Can you set your application that generates the traffic to use a max size that will not cause the fragmentation to occur?
by biomesh
Mon Dec 16, 2013 5:34 pm
Forum: General
Topic: [FEATURE REQUEST] DHCPv6-PD IA-PD Support
Replies: 16
Views: 4498

Re: [FEATURE REQUEST] DHCPv6-PD IA-PD Support

Interesting. I actually was thinking about running a sniffer on it to see. The guy @ comcast I'm working with indicates their systems should accept a release, specifically I'll quote him as saying, "I can delete that PD for you, your client isn’t doing a full release\renew.. I see this a lot.....
by biomesh
Mon Dec 16, 2013 5:42 am
Forum: General
Topic: [FEATURE REQUEST] DHCPv6-PD IA-PD Support
Replies: 16
Views: 4498

Re: [FEATURE REQUEST] DHCPv6-PD IA-PD Support

I have considered that, but frankly disabling IPv6 till the lease expires is a sorry excuse for a workaround to the router not releasing the lease properly. I expect the person I'm working with will be able to get it taken care of sometime tomorrow, and if not I'll try disabling IPv6. If you look a...
by biomesh
Sun Dec 15, 2013 11:42 pm
Forum: General
Topic: [FEATURE REQUEST] DHCPv6-PD IA-PD Support
Replies: 16
Views: 4498

Re: [FEATURE REQUEST] DHCPv6-PD IA-PD Support

If this is Comcast, just disable the client for four days then re-enable it. This worked for me since their lease time is four days.

Sent from my Nexus 7 using Tapatalk 4
by biomesh
Fri Dec 13, 2013 11:01 pm
Forum: General
Topic: [FEATURE REQUEST] DHCPv6-PD IA-PD Support
Replies: 16
Views: 4498

Re: [FEATURE REQUEST] DHCPv6-PD IA-PD Support

It was added in 6.5 and currently it is not in the wiki or changelogs.
by biomesh
Thu Dec 05, 2013 11:32 pm
Forum: Scripting
Topic: Strange bug (?) in ROS 6.7
Replies: 4
Views: 1597

Re: Strange bug (?) in ROS 6.7

It looks like when the find command returns without data, it is evaluated as 0 so it would print the address on the interface with index 0.

It happens at least on 6.6 and 6.7 - I didn't test on any earlier 6.x versions. It works as expected on 5.25.

Looks like a bug to me.
by biomesh
Thu Dec 05, 2013 12:49 am
Forum: Beginner Basics
Topic: DHCPv6 from cable co. now what
Replies: 25
Views: 6884

Re: DHCPv6 from cable co. now what

Looking at your router - the default gateway is unreachable.

Not sure if there is anything you can do - comcast will provide a /60-/64 prefix as well as a /128 for the external wan interface. It could be that your provider is doing something different than comcast.
by biomesh
Wed Dec 04, 2013 10:13 pm
Forum: Beginner Basics
Topic: DHCPv6 from cable co. now what
Replies: 25
Views: 6884

Re: DHCPv6 from cable co. now what

Have you tried a ping -6 ipv6.Google.com to see if that works?
You don't have to have a DNS server on ipv6 to actually resolve aaaa records.
Disable your firewall rules temporarily to see if things start to work then.

Sent from my SAMSUNG-SGH-I747 using Tapatalk
by biomesh
Wed Dec 04, 2013 8:54 pm
Forum: Beginner Basics
Topic: DHCPv6 from cable co. now what
Replies: 25
Views: 6884

Re: DHCPv6 from cable co. now what

Of course thank you for your effort on this :) Yea use peer DNS is default on the client. I played with it all again, still not handing out DNS. So does that mean the ISP is not handing out a IPv6 DNS server IP ? The DHCPv6 client does not seem to have a status that shows if it got DNS from the ISP...
by biomesh
Wed Dec 04, 2013 7:39 pm
Forum: Beginner Basics
Topic: DHCPv6 from cable co. now what
Replies: 25
Views: 6884

Re: DHCPv6 from cable co. now what

My script should work - it works on a few devices I have here.

As for DNS, you can set the option
use-peer-dns=yes
on the dhcp-client command.
by biomesh
Wed Dec 04, 2013 7:11 pm
Forum: Beginner Basics
Topic: DHCPv6 from cable co. now what
Replies: 25
Views: 6884

Re: DHCPv6 from cable co. now what

Try this first (adjust the interface to match your internal interface name)
/ipv6 address add from-pool=ipv6_pool interface=ether2 advertise=yes
This is using the method Janisk mentioned.
by biomesh
Wed Dec 04, 2013 6:09 pm
Forum: Beginner Basics
Topic: DHCPv6 from cable co. now what
Replies: 25
Views: 6884

Re: DHCPv6 from cable co. now what

If you have comcast (or another provider that supports prefixes larger than a /64) then you can add the prefix-hint option to the /ipv6 dhcp-client command like /ipv6 dhcp-client add add-default-route=yes interface=external pool-name=ipv6_pool prefix-hint=::/60 This option was added in ROS 6.5 and c...
by biomesh
Wed Dec 04, 2013 4:08 pm
Forum: Beginner Basics
Topic: DHCPv6 from cable co. now what
Replies: 25
Views: 6884

Re: DHCPv6 from cable co. now what

It was for personal preference, (to use a ::1/64 address as the router address) but I found that if I did use the from-pool option and removed that address, it also removed the pool. This is not good since it was a /60 pool handing out /64 prefixes. I will stick with my setup for now. I am running R...
by biomesh
Wed Dec 04, 2013 6:32 am
Forum: Beginner Basics
Topic: DHCPv6 from cable co. now what
Replies: 25
Views: 6884

Re: DHCPv6 from cable co. now what

Try something like /ipv6 dhcp-client add add-default-route=yes interface=external pool-name=ipv6_pool /ipv6 firewall filter add chain=input connection-state=established add chain=input connection-state=related add chain=input dst-port=546 in-interface=external protocol=udp src-port=547 add action=dr...
by biomesh
Fri Nov 29, 2013 4:53 pm
Forum: General
Topic: [already in] DHCPv6 client prefix length prefererence
Replies: 2
Views: 1543

This was added in 6.5. The option is prefix-hint for the /ipv6 dhcp-client option. It is command line only at this point.

/ipv6 dhcp-client
add add-default-route=yes interface=external pool-name=ipv6_pool prefix-hint=::/60

Sent from my Nexus 7 using Tapatalk 4
by biomesh
Mon Nov 11, 2013 7:52 pm
Forum: Forwarding Protocols
Topic: Lots of unreplied dns connection
Replies: 12
Views: 7140

Re: Lots of unreplied dns connection

You need to have a "drop the rest" rule on both the input and forward chains.
by biomesh
Mon Nov 11, 2013 1:50 am
Forum: General
Topic: Need Help with IPv6
Replies: 5
Views: 1778

Re: Need Help with IPv6

The screen shots look okay. What do your ipv6 routes look like?
by biomesh
Wed Oct 30, 2013 8:16 pm
Forum: General
Topic: bonding rr - not using all available capacity
Replies: 5
Views: 1689

Re: bonding rr - not using all available capacity

nope. mt 750gl is powerfull enough.
Do you get the same results through the 750gl without the bonding enabled?

If you are just doing routing, the 750gl might be able to handle this(not sure), but with the firewall enabled, I doubt it.
by biomesh
Fri Oct 18, 2013 12:27 am
Forum: General
Topic: 6.5 released!
Replies: 185
Views: 76586

Re: 6.5 released!

Upgraded my 450G from 6.4 to 6.5 with no issues.
by biomesh
Thu Oct 03, 2013 11:36 pm
Forum: General
Topic: RB750GL for big house - configuration
Replies: 16
Views: 4669

Re: RB750GL for big house - configuration

10 mbit is very conservative. You can handle 30mbit easily with a basic config 951-2n which is less powerful then the 750GL. I think it depends if you use queues, proxy, etc which will use more cpu. The more complex you get, the less bandwidth the hardware will be able to handle. This bandwidth we a...
by biomesh
Sat Sep 28, 2013 12:44 am
Forum: Forwarding Protocols
Topic: Policy Base Routing problem
Replies: 10
Views: 5370

Re: Policy Base Routing problem

I would change your content criteria and perhaps see if any traffic will work over your vpn connection. If you remove the content option and set the src-address to just one IP address, see if you can get it to work. This would just mean you need a better way to identify the traffic.
by biomesh
Fri Sep 27, 2013 6:04 pm
Forum: Forwarding Protocols
Topic: Policy Base Routing problem
Replies: 10
Views: 5370

Re: Policy Base Routing problem

Here is the wiki sample /ip firewall mangle add chain=prerouting src-address=192.168.150.0/24 content=facebook action=mark-routing new-routing-mark=Through_VPN /interface pptp-client add connect-to=My VPN Connection allow=pap,chap,mschap1,mschap2 name="My VPN" user=Reza Moghadam password=R...
by biomesh
Wed Sep 25, 2013 6:05 pm
Forum: Forwarding Protocols
Topic: Policy Base Routing problem
Replies: 10
Views: 5370

Re: Policy Base Routing problem

You should make sure your vpn connection works before trying the PBR. From your first post, it looks like you just copied from the wiki - which is just an example. You will need to replace a lot of information in the example with your VPN IP address, credentials, along with your subnet, packet marki...
by biomesh
Tue Sep 24, 2013 2:38 pm
Forum: RouterBOARD hardware
Topic: RB44Ge bracket profile problem
Replies: 3
Views: 1426

Re: RB44Ge bracket profile problem

I received both with mine. You might want to check with your distributor if you did not get yours.

Sent from my Nexus 7 using Tapatalk 4
by biomesh
Fri Sep 06, 2013 1:22 am
Forum: General
Topic: How to optimize RB951G CPU usage?
Replies: 10
Views: 4443

Re: How to optimize RB951G CPU usage?

I would take a backup of your config and run with the default rules that come with the device when using quickset. See if/how the performance differs.
by biomesh
Tue Aug 06, 2013 5:12 pm
Forum: General
Topic: DNS configuration via DHCPv6
Replies: 6
Views: 2930

Re: DNS configuration via DHCPv6

Are there plans to allow for different IPv6 DNS servers for each DHCP server network? With the way the feature is implemented right now, you cannot hand out only the address of your local caching nameserver(s). You could add the local nameservers to the list of the servers used as forwarders by the ...
by biomesh
Wed May 29, 2013 8:04 pm
Forum: General
Topic: L2tp/IPSEC performance blows?
Replies: 19
Views: 6666

Re: L2tp/IPSEC performance blows?

i dont want to use 3des, thats the point of this, the performance blows on that windows also supports aes-128 sha1, by default which im being told has much better performance i need this to work under aes 128, not 3des i already had that working The phase I encryption is only for the keys being pas...
by biomesh
Wed May 29, 2013 7:14 pm
Forum: General
Topic: L2tp/IPSEC performance blows?
Replies: 19
Views: 6666

Re: L2tp/IPSEC performance blows?

Change /ip ipsec peer add enc-algorithm=aes-128 generate-policy=yes hash-algorithm=sha1 \ nat-traversal=yes secret=1234 to /ip ipsec peer add exchange-mode=main-l2tp enc-algorithm=3des generate-policy=yes hash-algorithm=sha1 \ nat-traversal=yes secret=1234 This is only for phase I of the l2tp connec...
by biomesh
Tue May 28, 2013 11:00 pm
Forum: General
Topic: L2tp/IPSEC performance blows?
Replies: 19
Views: 6666

Re: L2tp/IPSEC performance blows?

Looks like you are missing a proposal. Try something like the following: /ip ipsec proposal set [ find default=yes ] auth-algorithms=sha1 disabled=no enc-algorithms=\ aes-128 lifetime=30m name=default pfs-group=none /ip ipsec peer add address=0.0.0.0/0 auth-method=pre-shared-key dh-group=modp1024 di...
by biomesh
Sat May 25, 2013 3:53 pm
Forum: General
Topic: L2tp/IPSEC performance blows?
Replies: 19
Views: 6666

Re: L2tp/IPSEC performance blows?

What is your l2tp Server max mru set to? You might want to try 1420 instead of 1460. Post your config if it didn't help.
by biomesh
Fri May 03, 2013 10:20 pm
Forum: Beginner Basics
Topic: Clients not gettting IPv6 - Tunnelbroker Service
Replies: 17
Views: 8945

Re: Clients not gettting IPv6 - Tunnelbroker Service

Forget DHCPv6, in RouterOS it only supports prefixes so far, not individual addresses. To see RAs on Windows, you can use some packet capture tool, e.g. Wireshark with "icmpv6.type==134" filter. Edit: And since you can't use DHCPv6, you definitely want managed-address-configuration=no. Go...
by biomesh
Fri May 03, 2013 4:22 pm
Forum: Beginner Basics
Topic: Clients not gettting IPv6 - Tunnelbroker Service
Replies: 17
Views: 8945

Re: Clients not gettting IPv6 - Tunnelbroker Service

Yes I want to use DHCPv6 for my clients. In your config you had nd disabled=yes. My intention is simple. I want my clients to get IPV6 address so that they can browse over IPv6 web addresses. Which config should I follow? You misread my config - my default ND entry is disabled. I have a separate ND...
by biomesh
Thu May 02, 2013 4:20 pm
Forum: Beginner Basics
Topic: Clients not gettting IPv6 - Tunnelbroker Service
Replies: 17
Views: 8945

Re: Clients not gettting IPv6 - Tunnelbroker Service

Yes I want to use DHCPv6 for my clients. In your config you had nd disabled=yes. My intention is simple. I want my clients to get IPV6 address so that they can browse over IPv6 web addresses. Which config should I follow? You misread my config - my default ND entry is disabled. I have a separate ND...
by biomesh
Thu May 02, 2013 6:51 am
Forum: Beginner Basics
Topic: Clients not gettting IPv6 - Tunnelbroker Service
Replies: 17
Views: 8945

Re: Clients not gettting IPv6 - Tunnelbroker Service

Still DHCPv6 not working on clients. My New Config: /ipv6 dhcp-server add address-pool=pool1 authoritative=after-2sec-delay disabled=no interface=\ LAN lease-time=3d name=server1 /ipv6 pool add name=pool1 prefix=2001:470:19:1292::/64 prefix-length=64 /ipv6 address add address=2001:470:18:1292::2/64...
by biomesh
Wed May 01, 2013 8:48 pm
Forum: Beginner Basics
Topic: Clients not gettting IPv6 - Tunnelbroker Service
Replies: 17
Views: 8945

Re: Clients not gettting IPv6 - Tunnelbroker Service

Try this: /ipv6 address add address=2001:470:18:1292::2/64 advertise=no interface=IPV6 add address=2001:470:19:1292::1/64 interface=LAN /ipv6 nd set [ find default=yes ] disabled=yes add advertise-dns=yes interface=LAN managed-address-configuration=yes mtu=1480 other-configuration=yes ra-delay=5s \ ...
by biomesh
Wed May 01, 2013 5:14 pm
Forum: Beginner Basics
Topic: Clients not gettting IPv6 - Tunnelbroker Service
Replies: 17
Views: 8945

Re: Clients not gettting IPv6 - Tunnelbroker Service

I followed your config, but no luck. Please see my changed config [admin@MikroTik] /ipv6 address> print Flags: X - disabled, I - invalid, D - dynamic, G - global, L - link-local # ADDRESS FROM-POOL INTERFACE ADVERTISE 0 G 2001:470:18:1292::2/64 IPV6 no 1 G 2001:470:19:1292::1/64 WAN no 2 DL fe80::c...
by biomesh
Mon Apr 29, 2013 11:53 pm
Forum: General
Topic: v5.25 released
Replies: 52
Views: 18815

Re: v5.25 released

After the 5.25 update I got the following message and had to delete/reimport my certificates (and update the sstp server): 15:49:21 sstp,error server certificate change failed: could not load private key (6) 15:49:31 sstp,error server certificate change failed: could not load private key (6) No othe...
by biomesh
Fri Apr 26, 2013 10:51 pm
Forum: General
Topic: Dual Access PPTP, L2TP on the Mikrotik??? It is very sad.
Replies: 25
Views: 29047

Re: Dual Access PPTP, L2TP on the Mikrotik??? It is very sad

You should have two default routes. One using policy based routing for your internal interfaces, one for your external interface. The wan interface will have the address from your ISP, and this will have the default route without the policy based routing. All of the ISP local traffic will be routed ...
by biomesh
Fri Apr 26, 2013 9:39 pm
Forum: General
Topic: Dual Access PPTP, L2TP on the Mikrotik??? It is very sad.
Replies: 25
Views: 29047

Re: Dual Access PPTP, L2TP on the Mikrotik??? It is very sad

You might get more replies if this were in english. But if you want to force specific traffic to go over the pptp connection, you might want to look at the following: http://wiki.mikrotik.com/wiki/Policy_Base_Routing /ip firewall Mangle add chain=prerouting src-address=10.64.83.0/24 action=mark-rout...
by biomesh
Tue Apr 09, 2013 8:51 pm
Forum: RouterBOARD hardware
Topic: CLOUD CORE ROUTER
Replies: 1374
Views: 1056798

Re: CLOUD CORE ROUTER

Then blame your distributor - in all official announcements MT informed that this is "pre-production batch for those who wanna try it before full production" You can't have RouterOS v5 , cause this is completely new CPU architecture that didn't exist before v6 Taken from : http://routerbo...
by biomesh
Sun Mar 10, 2013 6:08 am
Forum: RouterBOARD hardware
Topic: RouterBoard 951-2n Reliabillity
Replies: 5
Views: 2891

Re: RouterBoard 951-2n Reliabillity

I don't think that this device was designed to only be an AP only. It is being sold as a small office or home router and AP. The specs on this device are sufficient for most small buildings with limited wireless device access and moderate internet speeds. I have had one of these providing 16/3 inter...
by biomesh
Tue Feb 26, 2013 5:41 am
Forum: Wireless Networking
Topic: OmniTIK UPA-5HnD help -- Cant get Wireless to work
Replies: 8
Views: 2763

Re: OmniTIK UPA-5HnD help -- Cant get Wireless to work

I would start off by specifying the wireless protocol to 802.11 and most likely you will also want to set the encryption to aes rather than tkip. I also don't see your ssid in the export, but that could be due to the unspecified protocol.

Sent from my Nexus 7 using Tapatalk HD
by biomesh
Sat Feb 16, 2013 10:31 pm
Forum: General
Topic: hotspot with google account
Replies: 11
Views: 6078

Re: hotspot with google account

I think the ideal solution would be SAML v2 service provider support on the ros devices so that way you could authenticate against any trusted SAML v2 identity provider. You would have to configure the trust relationship so unknown users would not be an issue.
by biomesh
Tue Feb 12, 2013 11:11 pm
Forum: Beginner Basics
Topic: Cisco AnyConnect NAT Traversal
Replies: 1
Views: 3445

Re: Cisco AnyConnect NAT Traversal

I use the AnyConnect client with no issues. You will most likely need to look at the vpn client logs as well as the client config and configured routes(while it is connected) to determine if some of the vpn client settings conflict with your network configuration.
by biomesh
Wed Feb 06, 2013 6:16 pm
Forum: Beginner Basics
Topic: Can,t connect to Internet
Replies: 7
Views: 1730

Re: Can,t connect to Internet

I thought every port needed an IP?
No, the ports can be slaved or bridged - so if every device is on one network, your internal ports only need one address. The wan port would also need one as well.
by biomesh
Wed Feb 06, 2013 6:10 pm
Forum: Beginner Basics
Topic: Can,t connect to Internet
Replies: 7
Views: 1730

Re: Can,t connect to Internet

What is wrong with this setup? I do get an IP address and the system time is updated so I know have some contact with the outside world but I cant surf the web? # feb/06/2013 15:31:33 by RouterOS 5.22 # software id = TQBA-3U8S # /interface ethernet set 2 name=WAN set 3 name=LAN set 4 master-port=LA...
by biomesh
Mon Feb 04, 2013 7:30 pm
Forum: General
Topic: Licensing and first activation?
Replies: 3
Views: 811

Re: Licensing and first activation?

I have an Rb951-2n (with L4 license) that states it is upgradable to 7.x.

I would guess that it also would be upgradable to 7.x (due to the timeframe the hardware was released) but someone else with a RB2011L-RM should be able to verify for you.
by biomesh
Fri Jan 25, 2013 9:13 pm
Forum: General
Topic: My RB951-2n is non-functional
Replies: 17
Views: 6292

Re: My RB951-2n is non-functional

Once you netinstall it switch to port 2-5 then use winbox(via the mac) to configure it. When you set the IP via netinstall it sets that IP on port 1 which normally has all of the services firewalled.
by biomesh
Fri Jan 18, 2013 7:20 pm
Forum: General
Topic: RB751G-2HnD performance
Replies: 2
Views: 968

Re: RB751G-2HnD performance

Can you try the tests again, connecting to the same speedtest server for all three tests?
by biomesh
Mon Dec 17, 2012 4:32 pm
Forum: Beginner Basics
Topic: [5.22][DNS]dns cache ,Cache the html page content
Replies: 2
Views: 831

Re: [5.22][DNS]dns cache ,Cache the html page content

It looks like he added static A entries with html code.

To the original poster: DNS is only a name to ip address translation protocol - it has nothing to do with http, etc other than web browsers, etc use both protocols.
by biomesh
Thu Dec 06, 2012 8:57 pm
Forum: RouterBOARD hardware
Topic: Analog Telephone Adapter (ATA) for RB?
Replies: 5
Views: 2912

Re: Analog Telephone Adapter (ATA) for RB?

IMO, ATA functionality cannot be implemented easily without a good deal of work. I would suggest Obihai or Grandstream devices and just use tftp/ftp/http provisioning to manage the devices for your customers.
by biomesh
Fri Nov 16, 2012 4:33 pm
Forum: Scripting
Topic: Complete DELPHI API client: update 4
Replies: 69
Views: 44406

Re: Complete DELPHI API client: update 4

Works as expected on a 751G - I would have to agree with Chupaka and make sure the permissions are correct. If you are using an API to send these commands, they are probably being interpreted as being interactive. I would try to send the commands via the script interface. This could be done via a rs...
by biomesh
Fri Nov 16, 2012 5:00 am
Forum: Scripting
Topic: Complete DELPHI API client: update 4
Replies: 69
Views: 44406

Re: Complete DELPHI API client: update 4

I can try on a 751G tomorrow.

Sent from my Nexus 7 using Tapatalk 2
by biomesh
Thu Nov 15, 2012 6:58 pm
Forum: Scripting
Topic: Complete DELPHI API client: update 4
Replies: 69
Views: 44406

Re: Complete DELPHI API client: update 4

/system reboot in 5.21 requires interactive confirmation as does /system upgrade /system auto-upgrade requires interactive password Using ROS scripting you cannot respond to these requests, rendering all scripts that use these commands useless. The right way to fix the problem is eliminate the inte...
by biomesh
Wed Oct 24, 2012 8:44 pm
Forum: General
Topic: 5.21 released
Replies: 78
Views: 22065

Re: 5.21 released

What does it mean?: *) dns - fix empty response; I'm asking about it, because I have problems with MikroTik DNS long time. Maybe this fil will repair it, but what do You mean "empty response"?? Please MikroTik - what does this mean? My guess is that it is related to the truncated flag wit...
by biomesh
Fri Aug 10, 2012 9:12 pm
Forum: General
Topic: How to set up IPv6 on 5.19 and Windows 7?
Replies: 7
Views: 2632

Re: How to set up IPv6 on 5.19 and Windows 7?

Sorry, not BIND, but dhcpd from isc.org. Bind is the dns server and dhcpd is the DHCP server. That was my typo.

The DHCP server from isc.org would only be used to hand out the DHCP option to the clients, not the actual addresses (if you want to use autoconfig).
by biomesh
Fri Aug 10, 2012 8:07 pm
Forum: General
Topic: How to set up IPv6 on 5.19 and Windows 7?
Replies: 7
Views: 2632

Re: How to set up IPv6 on 5.19 and Windows 7?

You are getting the address via RA and I don't think that the windows ipv6 stack supports dns configuration except via static or DHCP, which is not available in the ROS implementation. (I use bind). You don't have to have ipv6 addressable dns servers, but it does help if you want full ipv6 support. ...
by biomesh
Fri Aug 10, 2012 6:31 pm
Forum: General
Topic: How to set up IPv6 on 5.19 and Windows 7?
Replies: 7
Views: 2632

Re: How to set up IPv6 on 5.19 and Windows 7?

This will probably work for you: /interface 6to4 add comment="HE IPv6 Tunnel" disabled=no local-address=78.130.165.174 mtu=\ 1280 name=sit1 remote-address=216.66.84.46 /ipv6 pool add name=clients prefix=2001:470:1f15:69c::/64 prefix-length=64 /ipv6 address add address=2001:470:1f14:69c::2/...
by biomesh
Thu Aug 09, 2012 8:38 pm
Forum: Beginner Basics
Topic: Pingable Static route unreachable. I'm baffled.
Replies: 8
Views: 9358

Re: Pingable Static route unreachable. I'm baffled.

Have you tried to set the preferred source on the 10.34.33.0/24 subnet to 10.34.17.44?

Could there also be a routing issue on the router at 10.34.17.62? It should of course be able to respond to pings, but might not route between subnets properly.
by biomesh
Tue Aug 07, 2012 11:19 pm
Forum: General
Topic: email not working in 5.19
Replies: 10
Views: 2297

Re: email not working in 5.19

/tool e-mail set address=173.194.77.108 from=mikrotik@mydomain.net password=emailpwd port=587 starttls=yes user=user@gmail.com /tool e-mail send to="user@gmail.com" body="Router email" subject="$[/system identity get name] $[/system clock get time] $[/system clock get date] ...
by biomesh
Tue Aug 07, 2012 4:46 pm
Forum: Wireless Networking
Topic: rb751-devices and getting good WiFi-Performance
Replies: 10
Views: 2992

Re: rb751-devices and getting good WiFi-Performance

I had the basic rate symptom - would not really call it an issue with a few cell phones where the Tx rate would stay at the basic rate. I just set configured supported and basic data rates to be 24 Mbps and up and the devices have no problems connecting at full N rates now.
by biomesh
Thu Jul 26, 2012 6:55 pm
Forum: General
Topic: Router not routing
Replies: 6
Views: 3115

Re: Router not routing

you cant have the same /16 on two different interfaces. the local machine will not send the traffic to the router for anything on that 192.168.x.x because it thinks its local. a machine will arp for anything in its own subnet instead of sending it to the default gateway. OK this makes sense, howeve...
by biomesh
Thu Jul 26, 2012 6:45 am
Forum: General
Topic: Router not routing
Replies: 6
Views: 3115

Re: Router not routing

Have you tried different masks? A /16 assumes everything is on the same physical network - which a bridge or a simple switch can handle.

From your example /24 masks would be more appropriate.

An export from your device can also help others see what your configure is.
by biomesh
Mon Jul 23, 2012 11:52 pm
Forum: General
Topic: Sector Writes on RB751G-2HnD
Replies: 8
Views: 2503

Re: Sector Writes on RB751G-2HnD

I see around 8.3 sector writes per second (on average). This is around 500 writes per hour. This 751G is used only as a basic AP for about 4-5 clients. I have not seen the high flash utilization yet, but this is more utilization than my 450G with graphing enabled.
by biomesh
Tue Jul 17, 2012 11:58 pm
Forum: General
Topic: SSTP/OVPN with Self-Signed Certificate
Replies: 3
Views: 3063

Re: SSTP/OVPN with Self-Signed Certificate

The CA public key will be required by the client. On the server, you will need the certificate public & private key including the public key trustchain up to the CA. This might not help too much though - you are better off looking at the wiki for more detailed directions. http://wiki.mikrotik.co...
by biomesh
Tue Jul 17, 2012 4:34 pm
Forum: RouterBOARD hardware
Topic: RB951 has potential USB!
Replies: 2
Views: 1493

Re: RB951 has potential USB!

The quick guide does mention that the RB951-2n does have usb, so that should be removed from the PDF.

I have been using the RB951-2n as a bridged AP for a few days and it has been running very well using 5.18.
by biomesh
Sun Jul 01, 2012 7:29 pm
Forum: Beginner Basics
Topic: NTP client set time [solved]
Replies: 4
Views: 38607

Re: NTP client set time

I installed the optional package. http://wiki.mikrotik.com/wiki/Manual:System/Time DOES NOT tell how to set the clock using the NTP client. If you configure and enable the ntp client it will set the time on the device: /system ntp client set enabled=yes mode=unicast primary-ntp=216.66.0.142 seconda...
by biomesh
Wed Jun 27, 2012 4:44 pm
Forum: General
Topic: hotspot Error timeout
Replies: 2
Views: 845

Re: hotspot Error timeout

I have no idea if this will work, but have you tried to change the value under /system identity ?
by biomesh
Wed Jun 27, 2012 4:37 pm
Forum: RouterBOARD hardware
Topic: Problem in RouterBoard 750GL
Replies: 11
Views: 3287

Re: Problem in RouterBoard 750GL

That is just letting you choose which address to connect to - your mikrotik device has an IPv4 and IPv6 address bound. Just choose one - they both go to the same device.
by biomesh
Mon Jun 25, 2012 7:39 pm
Forum: General
Topic: Mikrotik DNS server issues with Amazon S3 - low TTL 60sec
Replies: 118
Views: 50325

Re: Mikrotik DNS server issues with Amazon S3 - low TTL 60se

How much of your cache is in use? Mine is very low and I don't see the issue you are seeing - been running the batch file for two hours. The config is /ip dns export set allow-remote-requests=yes cache-max-ttl=1w cache-size=4096KiB \ max-udp-packet-size=4096 servers=208.67.222.222,208.67.220.220 /ip...
by biomesh
Mon Jun 11, 2012 7:02 pm
Forum: General
Topic: Feature Request: Please support enterprise virtualization.
Replies: 16
Views: 3813

Feature Request: Please support enterprise virtualization.

Not sure what version of vmware you are using but ros works great on vmware workstation 8. I am guessing the latest versions of esxi work too.

Sent from my BlackBerry 9800 using Tapatalk
by biomesh
Sun May 27, 2012 5:57 am
Forum: RouterBOARD hardware
Topic: RB751G-2HnD FCC delay
Replies: 6
Views: 1725

Re: RB751G-2HnD FCC delay

If an official update is available I would like to know what it is.
by biomesh
Thu May 17, 2012 5:01 pm
Forum: Beginner Basics
Topic: routing and NAT works for a /24 but not for a /16
Replies: 3
Views: 1093

Re: routing and NAT works for a /24 but not for a /16

A backup file won't help - you will need to provide either
(preferred - if you are on ROS 5.12 or later)

/export compact file=export

or

/export file=export

Attach the export.rsc that is created back to this thread.
by biomesh
Fri May 11, 2012 3:48 pm
Forum: General
Topic: What's with all the spam posts about food and tv?????
Replies: 23
Views: 2208

Re: What's with all the spam posts about food and tv?????

I'm not sure if it is possible, but set a higher delay between posts for users with a very low number of posts. Once they reach a threshold that a spammer wouldn't ever reach (or wait for) then remove the delay.
by biomesh
Wed May 09, 2012 4:59 pm
Forum: General
Topic: Intregrating Anti Virus
Replies: 21
Views: 25642

Re: Intregrating Anti Virus

AV in a router is pointless - if someone wanted to bypass network AV they could just encrypt the data or session. This is just the first and most obvious reason - there are plenty more.
by biomesh
Tue May 08, 2012 4:38 pm
Forum: Beginner Basics
Topic: RouterOS License on VMware Worksation
Replies: 4
Views: 1459

Re: RouterOS License on VMware Worksation

By image, he means the virtual machine you install the license on. Just be sure to back up the virtual machine so that way if the virtual machine/virtual disk is corrupt in some way you can just revert back to the original state.
by biomesh
Sat May 05, 2012 12:02 am
Forum: General
Topic: Intercepting DNS traffic?
Replies: 7
Views: 3881

Re: Intercepting DNS traffic?

little confused, the !outside is supposed to be what? *not* my internet connection interfaces? Yes, my external interface is labeled outside. I only intercept traffic that does not originate from my external interface and the source address would not be equal to your dns server. If those 2 conditio...
by biomesh
Fri May 04, 2012 11:34 pm
Forum: General
Topic: Intercepting DNS traffic?
Replies: 7
Views: 3881

Re: Intercepting DNS traffic?

little confused, the !outside is supposed to be what? *not* my internet connection interfaces? Yes, my external interface is labeled outside. I only intercept traffic that does not originate from my external interface and the source address would not be equal to your dns server. If those 2 conditio...
by biomesh
Fri May 04, 2012 8:59 pm
Forum: General
Topic: Intercepting DNS traffic?
Replies: 7
Views: 3881

Re: Intercepting DNS traffic?

Hello, I've been recently trying to "intercept" my clients DNS traffic and redirect it to our internal DNS server. (I know someones going to ask why, we have limited outgoing bandwidth, and we would like to try protecting our customers from malicious DNS hijackers, or at the very least st...
by biomesh
Tue May 01, 2012 11:06 pm
Forum: General
Topic: RouterOS Denial of Service exploit
Replies: 2
Views: 1839

Re: RouterOS Denial of Service exploit

You might want to look down a few threads to see that this has already been mentioned and that there are plenty of workarounds until there is an official fix.
by biomesh
Tue May 01, 2012 11:02 pm
Forum: General
Topic: ROS 5.15 RB 1100 DNS Vulnerability Note VU#800113
Replies: 1
Views: 1264

Re: ROS 5.15 RB 1100 DNS Vulnerability Note VU#800113

http://www.kb.cert.org/vuls/id/800113

after DNS scan from namebench(google app.) ....:: what is this?

Thanks
Just ran a scan against my RB450G with 5.15 and did not see that result. What options were enabled in namebench?
by biomesh
Sat Apr 14, 2012 12:11 am
Forum: General
Topic: [Request] Schedule a system reboot
Replies: 4
Views: 3579

Re: [Request] Schedule a system reboot

Without an interval set the task will run once. If you want this automated, an API connection to the routers to either reboot them manually or add/delete the reboot schedule is probably the easiest way.
by biomesh
Thu Apr 12, 2012 6:17 pm
Forum: General
Topic: DHCPv6 for home installations?
Replies: 37
Views: 14521

Re: DHCPv6 for home installations?

If you want to delegate the pool to the inside, there is not necessary the need to assign a IPv6 to the outside interface - the link local address would do. So if using DHCPv6 you should set it up with a pool name without initializing the pool... /ipv6 dhcp-client add interface=ext-if pool-name=ipv...
by biomesh
Thu Apr 12, 2012 4:01 am
Forum: General
Topic: DHCPv6 for home installations?
Replies: 37
Views: 14521

DHCPv6 for home installations?

I did some testing and the linksys/cisco consumer level device will request a prefix and an address. The address is assigned on the external interface and the prefix is assigned and advertises on the local network (with $PREFIX:: being the default lan gateway). Right now the routeros dhcpv6 client i...
by biomesh
Tue Apr 10, 2012 5:18 pm
Forum: General
Topic: DHCPv6 for home installations?
Replies: 37
Views: 14521

Re: DHCPv6 for home installations?

I have to do some testing, but there might be a bug. You should be able to allocate addresses from the pool that is assigned via the dhcpv6 client, but the pool is not accessible via the cli via preliminary testing. It is accessible via the gui. You can assign the default prefix to the wan address ...
by biomesh
Mon Apr 09, 2012 6:57 am
Forum: General
Topic: DHCPv6 for home installations?
Replies: 37
Views: 14521

Re: DHCPv6 for home installations?

I have to do some testing, but there might be a bug. You should be able to allocate addresses from the pool that is assigned via the dhcpv6 client, but the pool is not accessible via the cli via preliminary testing. It is accessible via the gui. You can assign the default prefix to the wan address b...
by biomesh
Sun Apr 08, 2012 6:26 pm
Forum: General
Topic: DHCPv6 for home installations?
Replies: 37
Views: 14521

Re: DHCPv6 for home installations?

You won't need a dhcpv6 server for this - just a dhcpv6 client(the pool option is there in case you do get a larger allocation like a /48 and need to handle your own delegation). Your wan interface will get the /64 allocation then you will advertise that /64 using (RAs/ND) on your internal network. ...
by biomesh
Sat Apr 07, 2012 4:24 pm
Forum: Beginner Basics
Topic: Simplest way to clone an RB750?
Replies: 12
Views: 4363

Re: Simplest way to clone an RB750?

You can just leave the word "compact" out of the command. You will end up with more data to validate but the format will be the same.
by biomesh
Sat Apr 07, 2012 5:56 am
Forum: Beginner Basics
Topic: Simplest way to clone an RB750?
Replies: 12
Views: 4363

Re: Simplest way to clone an RB750?

Make sure you are using at least version 5.12 and then run

/export compact file=backup

The data in the file is plain text.
by biomesh
Fri Apr 06, 2012 7:19 pm
Forum: RouterBOARD hardware
Topic: Gigabit port compatibility?
Replies: 12
Views: 2666

Re: Gigabit port compatibility?

I too have had terrible ethernet compatibility issues with the RB493G. Linksys PAP2T dual line VOIP phone adapters for example auto-negotiage 10 Mbps FDX , I have an old laptop that will only work at 10 Mbps HDX and requires autonegociate off or else it doesn't even register a link. I had to put a ...
by biomesh
Fri Mar 30, 2012 5:34 pm
Forum: Beginner Basics
Topic: How to send email -reg.
Replies: 7
Views: 2950

Re: How to send email -reg.

AUTH failure means you used the wrong password. Make sure your username is the full email address "user@gmail.com" and double check your password. If you still have errors, you might want to change your gmail password to make sure if complies with their new standards and perhaps leave out ...
by biomesh
Fri Mar 30, 2012 5:21 pm
Forum: Beginner Basics
Topic: Firewall issues passing traffic between VoIP switches.
Replies: 18
Views: 3331

Re: Firewall issues passing traffic between VoIP switches.

Not a cisco person, but if the voip devices just need to communicate with each other, you should just be able to change the default gw of each device to the RB750. The RB750 will route traffic between voip devices. If all devices on the network need to connect to the voip devices on both subnets, yo...
by biomesh
Thu Mar 29, 2012 9:04 pm
Forum: Beginner Basics
Topic: Firewall issues passing traffic between VoIP switches.
Replies: 18
Views: 3331

Re: Firewall issues passing traffic between VoIP switches.

Are the voip devices connected directly to the 750G or are they connected to a switch?

Can any other device on the 10.7.0 network connect to 10.7.3.x network via 10.7.0.1 as a default gw?
by biomesh
Thu Mar 29, 2012 8:42 pm
Forum: Beginner Basics
Topic: Firewall issues passing traffic between VoIP switches.
Replies: 18
Views: 3331

Re: Firewall issues passing traffic between VoIP switches.

That looks okay to me. Make sure no NAT or firewall rules are enabled. If you want them added later - test connectivity without them first then add rules slowly and test often. If this is an internal network - no nat or firewall rules will be needed.
by biomesh
Thu Mar 29, 2012 8:36 pm
Forum: Beginner Basics
Topic: How to send email -reg.
Replies: 7
Views: 2950

Re: How to send email -reg.

Are you using the GUI or the CLI?

If you are using the GUI - fill in every option - server(smtp.gmail.com), port(587), user(gmail email address), password, tls (checked), to, from, subject, and body.

The GUI interface doesn't always inherit the email values.
by biomesh
Thu Mar 29, 2012 8:11 pm
Forum: Beginner Basics
Topic: Firewall issues passing traffic between VoIP switches.
Replies: 18
Views: 3331

Re: Firewall issues passing traffic between VoIP switches.

Try: /ip address add address=10.7.0.4/24 disabled=no interface=ether1 network=10.7.0.0 /ip address add address=10.7.3.1/24 disabled=no interface=ether2 network=10.7.3.0 /ip route add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=10.7.0.1 scope=30 target-scope=10 Make sure your VOIP switches p...
by biomesh
Thu Mar 29, 2012 8:04 pm
Forum: Beginner Basics
Topic: Firewall issues passing traffic between VoIP switches.
Replies: 18
Views: 3331

Re: Firewall issues passing traffic between VoIP switches.

If the 750G is the router between subnets, you don't need any nat or firewall for routing. If you assign each interface an address, you will get a "dynamic" static route added. i.e. /ip address add address=10.7.0.2/24 disabled=no interface=ether2 network=10.7.0.0 /ip address add address=10...
by biomesh
Thu Mar 29, 2012 5:54 pm
Forum: Beginner Basics
Topic: Firewall issues passing traffic between VoIP switches.
Replies: 18
Views: 3331

Re: Firewall issues passing traffic between VoIP switches.

Have you tried the config without masquerading?

Have you tried torch or the packet sniffer to look at traffic between subnets? Lan traces can help identify issues you normally see.
by biomesh
Thu Mar 29, 2012 5:14 pm
Forum: Beginner Basics
Topic: How to send email -reg.
Replies: 7
Views: 2950

Re: How to send email -reg.

You are probably missing the port or setting tls=yes.... here is an example: /tool e-mail set address=173.194.77.108 from=mikrotik@your-domain.com password=gmailpwd port=587 user=username@gmail.com /tool e-mail send to=\"username@gmail.com\" body=\"email\" subject=\"\$[/syst...
by biomesh
Mon Mar 12, 2012 6:43 pm
Forum: General
Topic: NAT PROBLEM, HELP Require for New user!
Replies: 4
Views: 1108

Re: NAT PROBLEM, HELP Require for New user!

/ip firewall nat add action=dst-nat chain=dstnat disabled=no src-address=x.x.x.204 to-addresses=192.168.30.220 or if you only have one IP address, just use the interface(where the external interface is named 'outside'): /ip firewall nat add action=dst-nat chain=dstnat disabled=no in-interface=outsi...
by biomesh
Sat Mar 10, 2012 6:19 pm
Forum: RouterBOARD hardware
Topic: 450g slow with 5.14 and 2.39fw
Replies: 4
Views: 1659

Re: 450g slow with 5.14 and 2.39fw

You might want to check the Cpu speed to make sure it wasn't set to 100MHz instead of 680MHz.
by biomesh
Sun Feb 12, 2012 6:39 am
Forum: Beginner Basics
Topic: RB450G no link on ports 3-5
Replies: 3
Views: 900

Re: RB450G no link on ports 3-5

If you look at your configuration you have not specified the master port even though you have labeled them as slaves.
by biomesh
Sat Feb 11, 2012 10:19 pm
Forum: Beginner Basics
Topic: RB450G no link on ports 3-5
Replies: 3
Views: 900

Re: RB450G no link on ports 3-5

Can you provide an "/interface export" to let us know how your interfaces are configured?
by biomesh
Fri Feb 10, 2012 8:30 pm
Forum: Beginner Basics
Topic: Firewall logging (only dropped)
Replies: 2
Views: 12009

Re: Firewall logging (only dropped)

If your log rule matches your drop rule place it before the drop rule. You will also need to create a new logging rule (for the "firewall" topic) that will tell the system which action to take with the messages. I.e. if you have a syslog server, create a new logging action that points to s...