Community discussions

Search found 774 matches

by gotsprings
Mon Oct 14, 2019 9:18 pm
Forum: Wireless Networking
Topic: Buying new Routerboard - need your recommendations
Replies: 13
Views: 1388

Re: Buying new Routerboard - need your recommendations

So I still don't know what to buy. Want RB4011 for wireless. Currently have CCr1009-7G-1C-PC + 2x UniFi Pro. CCR will sell. Maybe will stay with RB4011 as main router and wifi + RB962UiGS for wifi in another room? The 4011 has had problems with SFP+ port and with WiFi interfaces. I would hold off o...
by gotsprings
Thu Oct 10, 2019 11:57 pm
Forum: General
Topic: Slow connection via mikrotik
Replies: 17
Views: 2123

Re: Slow connection via mikrotik

Probably that default config problem where the DHCP-SERVER has no DNS entry.
by gotsprings
Thu Oct 10, 2019 9:25 pm
Forum: Wireless Networking
Topic: Audience vs Eero?
Replies: 24
Views: 3440

Re: Audience vs Eero?

A bit more tricky is going to be the setup / config, specially if you will use 3 AP Wifi interfaces (and not as MESH). Which 5Ghz network will a client select if you have 2 with same SSID at two different channels? Or create 2 or 3 different SSID? Running two 5GHz channels with same SSID in the sam...
by gotsprings
Thu Oct 10, 2019 5:17 pm
Forum: Wireless Networking
Topic: Audience vs Eero?
Replies: 24
Views: 3440

Re: Audience vs Eero?

Distros in the US are sending out "we have Audience in stock". But still not seeing anyone saying... "Yes I have used it... And..." Everybody is waiting for you to share the experience :wink: # While I used to LOVE TESTING STUFF OUT AND BEING FIRST... Not getting paid, and ending up holding the bag...
by gotsprings
Thu Oct 10, 2019 1:39 pm
Forum: Wireless Networking
Topic: Audience vs Eero?
Replies: 24
Views: 3440

Re: Audience vs Eero?

Distros in the US are sending out "we have Audience in stock".

But still not seeing anyone saying... "Yes I have used it... And..."
by gotsprings
Tue Oct 08, 2019 7:41 pm
Forum: RouterBOARD hardware
Topic: RB4011: wlan1 disabling itself
Replies: 260
Views: 33780

Re: RB4011: wlan1 disabling itself

We believe we have fixed the issue, but that particular fix has not yet been released. Wait for the next beta please. FORTUNATELY... I only have one in the field and it has not exhibited this particular problem. Could the fact that I am in the US have something to do with it? The reports of the wif...
by gotsprings
Tue Oct 08, 2019 7:31 pm
Forum: General
Topic: IGMP Snooping on the new bridge implementation (6.41 +)
Replies: 4
Views: 2264

Re: IGMP Snooping on the new bridge implementation (6.41 +)

What was the outcome of this?
by gotsprings
Wed Oct 02, 2019 10:02 pm
Forum: Wireless Networking
Topic: Audience vs Eero?
Replies: 24
Views: 3440

Re: Audience vs Eero?

What is Eero? :shock: mesh WiFi https://eero.com/ I have 2 in bridge mode. Excellent wireless coverage. I did order Audience to give it a try. Eero is what the guy who has NO BUSINESS AT ALL TOUCHING A NETWORK, is bringing into a commercial install. .... Rather confused why you quoted me and posted...
by gotsprings
Wed Oct 02, 2019 4:45 pm
Forum: Wireless Networking
Topic: Audience vs Eero?
Replies: 24
Views: 3440

Re: Audience vs Eero?

What is Eero? :shock: mesh WiFi https://eero.com/ I have 2 in bridge mode. Excellent wireless coverage. I did order Audience to give it a try. Eero is what the guy who has NO BUSINESS AT ALL TOUCHING A NETWORK, is bringing into a commercial install. Sparky, "I use this all the time." Me, "YEAH IN H...
by gotsprings
Tue Oct 01, 2019 9:09 pm
Forum: Wireless Networking
Topic: Audience vs Eero?
Replies: 24
Views: 3440

Audience vs Eero?

That seems to be the product its built to compete with.

Anyone done the comparisons yet?
by gotsprings
Tue Oct 01, 2019 1:57 pm
Forum: Wireless Networking
Topic: received disassoc sending station leaving (8)
Replies: 59
Views: 38861

Re: received disassoc sending station leaving (8)

I see this problem the same day I configure the router. Now on some jobs the problem pops up a few days after I have left. Those ones... disabling the radio interface sometimes cures it. But the jobs where I see those messages right away... I have to change manufactures. Too many lost hours and clie...
by gotsprings
Mon Sep 30, 2019 11:41 pm
Forum: Wireless Networking
Topic: received disassoc sending station leaving (8)
Replies: 59
Views: 38861

Re: received disassoc sending station leaving (8)

I have the same similar issue “disconnected, received disassoc: sending station leaving”. I have not found a fix for this problem but I think I have a workaround that has solved this issue. Wrote a script and add it to the scheduler as shown below: /system scheduler add interval=1w name=Recycle-Cap...
by gotsprings
Sun Sep 29, 2019 9:19 pm
Forum: Wireless Networking
Topic: Is Mikrotik Wireless support a different department?
Replies: 10
Views: 1412

Re: Is Mikrotik Wireless support a different department?

Logged into my one and only restaurant/bar Caps-System, in the middle of an American Football Game. (They agreed to be the Guinea Pigs when they compared the cost to the Ruckus System at their other store.) 3 cAP AC and 1 hAP AC2 as the main router. I might as well have 2.4 turned off. 2.4 only clie...
by gotsprings
Sun Sep 29, 2019 9:08 pm
Forum: Wireless Networking
Topic: Running CAP on a hAP AC2 as the controller (Bug?)
Replies: 3
Views: 560

Re: Running CAP on a hAP AC2 as the controller (Bug?)

A problem I seem to have nailed down... If I set up caps-man on the hAP AC2 and then tell its wireless interface to JOIN THE CAP... All SSIDs start transmitting and the configuration looks like the other caps. I ve configured many many routers as capsman manager with their own WiFi joining as a cap...
by gotsprings
Sat Sep 21, 2019 3:30 pm
Forum: Wireless Networking
Topic: Mikrotik Audience Availability
Replies: 17
Views: 2189

Re: Mikrotik Audience Availability

Chechito: Environments where there are other wireless networks is when it really crumbles. I have managed to keep 50 clients connected to a cAP AC or hAP AC. But if there is a lot of wireless around you that isn't your... You get all sorts of disconnect messages. Anuser: Private PSK is a function of...
by gotsprings
Sat Sep 21, 2019 3:20 pm
Forum: General
Topic: Port forwarding
Replies: 4
Views: 515

Re: Port forwarding

They are not going to set up a VPN. If they have dynamic servers... Find out if they have a domain. You could resolve the domain and have a script punch it into the src-address when a change happens. Or with the addition of address lists... You can put the domain in there and it will resolve it as o...
by gotsprings
Fri Sep 20, 2019 6:50 pm
Forum: General
Topic: Port forwarding
Replies: 4
Views: 515

Re: Port forwarding

If the port doesn't change between WAN and LAN... you don't need to-ports=38880-38884 As for the compliance scans... SOB was asking if those ports need to be open to the whole world or only the POS servers? For example... at one of my bars, they used an online ordering company. This was before door ...
by gotsprings
Fri Sep 20, 2019 5:05 pm
Forum: Wireless Networking
Topic: Mikrotik Audience Availability
Replies: 17
Views: 2189

Re: Mikrotik Audience Availability

2 months??? wAP ACs took nearly a year to get stable numbers. In that specific case, a special situation is presented, which was the incorporation of a new ipq4xxx platform and a massive support for the ARM architecture Are you sure you are talking about wAP ac and not cAP ac ? The wAP ac is MIPSBE...
by gotsprings
Thu Sep 19, 2019 7:35 pm
Forum: Wireless Networking
Topic: Mikrotik Audience Availability
Replies: 17
Views: 2189

Re: Mikrotik Audience Availability

take it with a grain of salt

new devices comes with their own issues, and take some time to be resolved

i recommend to wait at least 2 months after introduction to market, to include a new device in a serious project
2 months??? wAP ACs took nearly a year to get stable numbers.
by gotsprings
Thu Sep 19, 2019 7:15 pm
Forum: Wireless Networking
Topic: hAP AC2+cAP AC Roaming is a joke
Replies: 35
Views: 4181

Re: hAP AC2+cAP AC Roaming is a joke

I won't pretend my Mikrotik Caps systems can touch My Ruckus systems.

but that kick below -87 in the access-list, is one of the easier tweaks that HELPED with roaming.
by gotsprings
Thu Sep 19, 2019 7:12 pm
Forum: Wireless Networking
Topic: Buying new Routerboard - need your recommendations
Replies: 13
Views: 1388

Re: Buying new Routerboard - need your recommendations

Love Tik for routing... but when it comes to wireless... not so much. If you have a connection faster than about 300M, you are going to want to look at other vendors for the wireless.

Also if you are in a very dense WiFi environment... other manufactures handle interference better than Tik.
by gotsprings
Thu Sep 19, 2019 6:50 pm
Forum: Wireless Networking
Topic: hAP AC2+cAP AC Roaming is a joke
Replies: 35
Views: 4181

Re: hAP AC2+cAP AC Roaming is a joke

Adding a rule to the access list to kick devices below 87... really helped the roaming on my installs.
/caps-man access-list
add action=accept interface=any signal-range=-87..120
add action=reject interface=any signal-range=-120..-88
by gotsprings
Thu Sep 19, 2019 4:50 pm
Forum: Wireless Networking
Topic: Running CAP on a hAP AC2 as the controller (Bug?)
Replies: 3
Views: 560

Running CAP on a hAP AC2 as the controller (Bug?)

I have a bunch of cAPs installs out there and have a pretty good template to apply to my routers to function as the router and controller. I set up the caps configurations to allow client to client forwarding and local forwarding. After putting caps man on the primary router... I log into each cAP A...
by gotsprings
Tue Aug 27, 2019 9:35 pm
Forum: General
Topic: Double VPN
Replies: 7
Views: 751

Re: Double VPN

I think you need to set the IP address that the VPN client comes in as. Then firewall rules will dictate what clients can then reach the next subnet. If I understood the diagram... its not VPN from one site to another... but a wired connection. If that is the case... you have one feed from the first...
by gotsprings
Tue Aug 27, 2019 9:13 am
Forum: General
Topic: Double VPN
Replies: 7
Views: 751

Re: Double VPN

Whenever I see oVPN in a Mikrotik thread... I stop reading. OpenVPN has been crippled in Mikrotik for like 10 years now.
by gotsprings
Mon Aug 26, 2019 3:35 am
Forum: General
Topic: Access Port From Lan With Wan IP
Replies: 21
Views: 2180

Re: Access Port From Lan With Wan IP

I didn't read the whole thing..

When local net goes back to local net on local interface.... That is what the hairpin Nat rule needs to have.
by gotsprings
Mon Aug 26, 2019 2:48 am
Forum: General
Topic: Double VPN
Replies: 7
Views: 751

Re: Double VPN

A company's office doesn't have a public IP address. My office does. I have the Far office calling my Office over L2TP. The route between them is 2 points. On each router... I have a route that points to the l2tp route. Encryption engine grabs the traffic before it goes over the tunnel. I vpn to my ...
by gotsprings
Fri Aug 23, 2019 5:23 pm
Forum: Wireless Networking
Topic: Is Mikrotik Wireless support a different department?
Replies: 10
Views: 1412

Re: Is Mikrotik Wireless support a different department?

And please keep in mind lots of users have posted about the constant connect disconnects that show up as station leaving... Or what ever it was. And people have reported that one for years to no avail. In the case of this ticket... I had another problem with Mikrotik wireless that I took the time to...
by gotsprings
Fri Aug 23, 2019 2:06 pm
Forum: Wireless Networking
Topic: Is Mikrotik Wireless support a different department?
Replies: 10
Views: 1412

Re: Is Mikrotik Wireless support a different department?

The conclusion is that a particularly high interference is causing your issue. How do you think this can be easily/quickly fixed by us? Normis, As I, and a other people on this forum have found... It's not that uncommon an occurrence. And an immediate fix is to replace the Mikrotik wireless with an...
by gotsprings
Fri Aug 23, 2019 1:40 pm
Forum: Wireless Networking
Topic: 2.4 4-way handshake timeout
Replies: 11
Views: 1533

Re: 2.4 4-way handshake timeout

Tech in the field (related to owner, so I was out ranked) insisted on putting in the cap AC he had in his truck. In the days since. Customer has been pounding him with complaints for the last week. Calling everyday. We get into the configuration and try to adjust things... But this is another site w...
by gotsprings
Fri Aug 23, 2019 1:34 pm
Forum: Wireless Networking
Topic: Is Mikrotik Wireless support a different department?
Replies: 10
Views: 1412

Re: Is Mikrotik Wireless support a different department?

Several new firmwares have been released... Gave them a try... Problem is still there.

Now I get to start all over learning another wifi vendor.
by gotsprings
Thu Aug 22, 2019 5:52 pm
Forum: General
Topic: [Feature Request] Winbox and netinstall 64 Bit versions - URGENT
Replies: 21
Views: 3602

Re: [Feature Request] Winbox and netinstall 64 Bit versions - URGENT

Isn't chromebook a Chrome browser based device? Webfig is the answer then
After years of Winbox... Webfig ain't even close.

And can't you install "apps" in Chromebook?
by gotsprings
Thu Aug 22, 2019 3:01 pm
Forum: General
Topic: [Feature Request] Winbox and netinstall 64 Bit versions - URGENT
Replies: 21
Views: 3602

Re: [Feature Request] Winbox and netinstall 64 Bit versions - URGENT

Give me Winbox on a Chromebook... (Asked for this years ago.)
by gotsprings
Thu Aug 22, 2019 2:33 pm
Forum: General
Topic: VPN
Replies: 1
Views: 319

Re: VPN

The client should be setting their VPN to NOT SEND ALL TRAFFIC, if you don't want them sending their traffic over your ISP.

If you put a firewall rules in their to deny their traffic access to the WAN... That would get them to disconnect or at least look up split tunneling VPN.
by gotsprings
Thu Aug 22, 2019 1:56 pm
Forum: Wireless Networking
Topic: LTE based internet and WiFi network at home
Replies: 11
Views: 1238

Re: LTE based internet and WiFi network at home

Tom, WAP LTE is 10/100 on the Ethernet port and 2.4 on the radio. Compounding the problems in the US, is the Cellular radio doesn't work with Band 13. This is the most common band used by Verizon. The configuration of the cellular is not "straight up". I wasted too much time on this... Just pay for ...
by gotsprings
Tue Aug 20, 2019 1:35 pm
Forum: Wireless Networking
Topic: received disassoc sending station leaving (8)
Replies: 59
Views: 38861

Re: received disassoc sending station leaving (8)

Use a different manufacture for wireless and just forget about Mikrotik wireless.

This "glitch" has been observed and reported for years at this point.

Get over it and move on.
by gotsprings
Tue Aug 20, 2019 1:30 pm
Forum: Announcements
Topic: Future of LTE products, user feedback requested
Replies: 86
Views: 19931

Re: Future of LTE products, user feedback requested

+1 for Band 13 (US Verizon)
The reason I only have one in the field.
by gotsprings
Tue Aug 20, 2019 1:28 pm
Forum: Wireless Networking
Topic: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi
Replies: 288
Views: 61039

Re: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi

i have another problem with wifi. it seemes to drop speed tenfold after several days of working without reboot. reboot solves wifi speed problem but again only for several days. help needed :( Write a simple scheduler and and script to reboot it every 48 hours. Professionally... We put a stop on Mi...
by gotsprings
Mon Jul 29, 2019 8:29 pm
Forum: Announcements
Topic: v6.45.2 [stable] is released!
Replies: 206
Views: 35898

Re: v6.45.2 [stable] is released!

Upgraded a cAP AC to 6.45.2 Reset Configuration Like I normally do... but this site was not a CAP install. /system reset-configuration UNIT CAME UP AS A ROUTER. wAP AC has always done this. This was the first time I have seen a cAP AC do this. Had to have tech on site connect to the local SSID to ge...
by gotsprings
Fri Jul 12, 2019 10:13 pm
Forum: Wireless Networking
Topic: wAP LTE US - Carriers?
Replies: 21
Views: 2218

Re: wAP LTE US - Carriers?

We used to use Cradlepoint but there's limited space in these device boxes, hence the move to using Routerboards since we're tunneling back to HQ anyway. The LTE card is perfect for this application. We might try a MVNO that utilizes Verizon and see if they will be more flexible in their accomodati...
by gotsprings
Thu Jul 11, 2019 9:14 pm
Forum: Wireless Networking
Topic: Equipment for the conference room
Replies: 6
Views: 953

Re: Equipment for the conference room

1 Cradlepoint CBA850LP6-NA Cellular Modem. 1 Mikrotik hAP AC2 Router. 2 Power Dsine 3501-GAC POE injectors. 2 Ruckus R510 Wireless Access points. The Cellular connection to the outside world will be the choke point. But the Ruckus Wireless Antennas are much better suited for having that many clients...
by gotsprings
Thu Jul 11, 2019 1:46 pm
Forum: General
Topic: Please add basic portScan tool ( port scanner scan )
Replies: 31
Views: 9836

Re: Please add basic portScan tool ( port scanner scan )

Bump. This sounds like what I am trying to do. I want to know if a device service is still running. Like checking a printer if 9100 is responding. In my case I have a device that responds to pings. Webserver works. But a service on 51510 stops responding as confirmed by Digital Loggers autoping agai...
by gotsprings
Wed Jul 10, 2019 4:22 am
Forum: Wireless Networking
Topic: wAP LTE US - Carriers?
Replies: 21
Views: 2218

Re: wAP LTE US - Carriers?

Yup... A static IP follows the Sim card. I have taken one Sim that was setup with a static IP and moved it between 3 modems. The only issue I could think might bite you... The APN for Verizon Static is geographic. If you went to another geographic area... You may need to change the APN. In the DC m...
by gotsprings
Tue Jul 09, 2019 3:46 am
Forum: Wireless Networking
Topic: wAP LTE US - Carriers?
Replies: 21
Views: 2218

Re: wAP LTE US - Carriers?

Yup... A static IP follows the Sim card. I have taken one Sim that was setup with a static IP and moved it between 3 modems. The only issue I could think might bite you... The APN for Verizon Static is geographic. If you went to another geographic area... You may need to change the APN. In the DC me...
by gotsprings
Mon Jul 08, 2019 9:35 pm
Forum: Wireless Networking
Topic: wAP LTE US - Carriers?
Replies: 21
Views: 2218

Re: wAP LTE US - Carriers?

I know I'm a little late to the party on this thread - I'm also trying to activate some Microtik LTE boards - this is the R11e-LTE-US boards and our Verizon rep tells us the IMEI "pattern" that Microtik is assigned isn't "registered" with Verizon so their sales and provisioning systems sees the IME...
by gotsprings
Sun Jul 07, 2019 4:49 am
Forum: Wireless Networking
Topic: received disassoc sending station leaving (8)
Replies: 59
Views: 38861

Re: received disassoc sending station leaving (8)


This time...
"We were able to reproduce the problem. (Blah blah blah). We don't currently have a Fix."
When did you get this anwser?
June 10th.
by gotsprings
Sun Jul 07, 2019 4:43 am
Forum: RouterBOARD hardware
Topic: RB4011: wlan1 disabling itself
Replies: 260
Views: 33780

Re: RB4011: wlan1 disabling itself

I miss the good old days when Mikrotik Routed...
And Ubnt did wireless...

It's when one tried to do the other that things start to fall apart.
by gotsprings
Fri Jul 05, 2019 3:11 am
Forum: Wireless Networking
Topic: received disassoc sending station leaving (8)
Replies: 59
Views: 38861

Re: received disassoc sending station leaving (8)

I got a good capture of Caps-man not allowing connections. Wrote up a what how and when for Mikrotik. They actually investigated it. All my prior interactions with Mikrotik about wireless have been pointless. One suggestion email per month with no resolution. This time... "We were able to reproduce ...
by gotsprings
Fri Jul 05, 2019 2:40 am
Forum: Announcements
Topic: Future of LTE products, user feedback requested
Replies: 86
Views: 19931

Re: Future of LTE products, user feedback requested

Need a gigabit interface and Sierra wireless modem.
by gotsprings
Mon Jul 01, 2019 7:30 pm
Forum: Scripting
Topic: Script to clear all firewall connections
Replies: 2
Views: 553

Re: Script to clear all firewall connections

This
/ip firewall connection remove [find]
I have this exact command in my netwatch when it checks if the Primary ISP's DNS server is there AFTER RECURSIVE ROUTING.

So it CLEARS all connections whether flipping too or away from the Primary ISP.
by gotsprings
Mon Jul 01, 2019 7:13 pm
Forum: Scripting
Topic: Monitoring a Port help?
Replies: 1
Views: 365

Monitoring a Port help?

I have a device that locks up. Send pings to it and it still replies. Bring up its webserver... that works too. So I need a script to look at a specific service port TCP 51510 I would like to make something like this... :if ([/ping 172.16.16.16 count=5] > 3) do={ :log info "It's Up" } else={ :log in...
by gotsprings
Mon Jul 01, 2019 1:44 pm
Forum: Wireless Networking
Topic: 2.4 4-way handshake timeout
Replies: 11
Views: 1533

Re: 2.4 4-way handshake timeout

Amazon seems to have a steady flow of Ruckus at ~50% off retail.
by gotsprings
Mon Jun 17, 2019 6:59 am
Forum: General
Topic: RouterBoard Webserver Stop Responding
Replies: 5
Views: 490

Re: RouterBoard Webserver Stop Responding

Support got back to me a few weeks later. They duplicated the problem by logging into the webserver from more than one IP. No fix yet.

Work around... Disable and reenable webserver under /IP services.
by gotsprings
Sun Jun 16, 2019 3:14 pm
Forum: Wireless Networking
Topic: Is Mikrotik Wireless support a different department?
Replies: 10
Views: 1412

Re: Is Mikrotik Wireless support a different department?

Could you please provide your ticket number? Now that the issue has been clearly identified and reproduced... What sort of time table can we expect for a fix? I am sure installers and integrators would love to see some sort of progress reports. The people I answer too are pretty annoyed, looking at...
by gotsprings
Thu Jun 13, 2019 5:53 am
Forum: Wireless Networking
Topic: 2.4 4-way handshake timeout
Replies: 11
Views: 1533

Re: 2.4 4-way handshake timeout

I had exactly the same story on a big event with 12 sxt sq lite 2, it was awe full, i tried basically everything, for 5 hours, then i just moved to another brand then it worked... I was also using CAPsMAN. I am interested to know why that can happen Thank you Because some vendors can deal with inte...
by gotsprings
Mon Jun 10, 2019 1:02 pm
Forum: Wireless Networking
Topic: 2.4 4-way handshake timeout
Replies: 11
Views: 1533

Re: 2.4 4-way handshake timeout

Got email from Mikrotik. Explained the problem and how to reproduce it.

They did... And don't currently have a fix.

So high density with interference... If you see 4-way handshake time out in Caps-man...

Don't fight it. Don't mess with support. Just buy the Ruckus radio and move on.
by gotsprings
Mon Jun 10, 2019 12:54 pm
Forum: General
Topic: GoogleFiber
Replies: 16
Views: 1253

Re: GoogleFiber

Gave up weeks ago and seteled for DMZ mode.

Found Google service at this location to be "questionable" at best.
by gotsprings
Thu Jun 06, 2019 1:51 am
Forum: Wireless Networking
Topic: Is Mikrotik Wireless support a different department?
Replies: 10
Views: 1412

Re: Is Mikrotik Wireless support a different department?

Could you please provide your ticket number? My most recent one... 2019052522002091 Generated MAY 25th... has not received a single response yet. I provided the rif file in the initial email. I then provided a copy paste of the log as the problem was being observed. Here is the thread that went wit...
by gotsprings
Wed Jun 05, 2019 3:23 pm
Forum: Wireless Networking
Topic: Is Mikrotik Wireless support a different department?
Replies: 10
Views: 1412

Is Mikrotik Wireless support a different department?

If I have a problem with Mikrotik wireless... I send support files to support and hear nothing. Weeks and even months go by. The last time I got a reply on a wireless issue... I got one email per month with "suggestions". I type suggestions... Because they were NOT solutions. It was, "try this"... I...
by gotsprings
Wed Jun 05, 2019 3:11 pm
Forum: Wireless Networking
Topic: 2.4 4-way handshake timeout
Replies: 11
Views: 1533

Re: 2.4 4-way handshake timeout

For anyone keeping score... Still no email from Mikrotik support.
by gotsprings
Tue Jun 04, 2019 8:23 pm
Forum: Wireless Networking
Topic: 2.4 4-way handshake timeout
Replies: 11
Views: 1533

Re: 2.4 4-way handshake timeout

Did the Ruckus work? I've never seem something like this, are you sure there is no jammer nearby? Jammers don't show in any of the WiFi protocol scans.
I struggle to recall an install in the last 10 years that it hasn't.
by gotsprings
Mon Jun 03, 2019 12:37 am
Forum: RouterBOARD hardware
Topic: RB4011 wireless performance?
Replies: 26
Views: 3714

Re: RB4011 wireless performance?

Mikrotik wireless is THE REASON I get complaints. They can route and I love the routing. But the switches and more specifically the wireless is not up to it. Cheap is great... And it can fit some (I mean basic installs), but as a professional... I can't play around with thing for weeks. Hard limits ...
by gotsprings
Mon Jun 03, 2019 12:27 am
Forum: RouterBOARD hardware
Topic: RB4011: wlan1 disabling itself
Replies: 260
Views: 33780

Re: RB4011: wlan1 disabling itself

Mikrotik can route... Much Like a Sony TV looks incredible.

But a Sony speaker is a piece of $h!+.
by gotsprings
Mon Jun 03, 2019 12:07 am
Forum: Wireless Networking
Topic: Mikrotik RB4011iGS+5HacQ2HnD and WiFi 802.11AC crash interface
Replies: 30
Views: 4042

Re: Mikrotik RB4011iGS+5HacQ2HnD and WiFi 802.11AC crash interface

While I have about 150 Mikrotiks out there as wireless devices... I just can't do it anymore. Just a waste of my time trying to get support to figure out what wrong with their gear. Much like I would never expect a Sony speaker to be worth a $h!+... Mikrotik wireless has let me down too many times a...
by gotsprings
Sun Jun 02, 2019 11:54 pm
Forum: Wireless Networking
Topic: Mikrotik WLAN & CAPsMAN - Bad download perfomance
Replies: 47
Views: 5431

Re: Mikrotik WLAN & CAPsMAN - Bad download perfomance

Done a bunch of Caps-man installs at this point. Found a lot of "hard limits"... That Mikrotik wireless is "crippled by". As long as I stayed with in the lines... Most installs went ok. Have better than 300 Meg's WAN to LAN. No Mikrotik wireless. Really busy wireless airtime. No Mikrotik wireless. I...
by gotsprings
Sun Jun 02, 2019 11:42 pm
Forum: Wireless Networking
Topic: wAP LTE experience
Replies: 5
Views: 751

Re: wAP LTE experience

Used one. Tried on several Wireless providers. Issues with remote access on any of them...

Gave up and tried mofi.

Back to cradlepoint now.
by gotsprings
Sun Jun 02, 2019 11:39 pm
Forum: Wireless Networking
Topic: Large Apartment, no Ethernet
Replies: 28
Views: 1904

Re: Large Apartment, no Ethernet

There are mesh products you may have to look into, from other vendors.
by gotsprings
Sun Jun 02, 2019 11:36 pm
Forum: Wireless Networking
Topic: 2.4 4-way handshake timeout
Replies: 11
Views: 1533

Re: 2.4 4-way handshake timeout

Still nothing from support.
by gotsprings
Mon May 27, 2019 8:01 am
Forum: RouterBOARD hardware
Topic: hAP ac hangs with bad client (962UiGS-5HacT2HnT)
Replies: 5
Views: 709

Re: hAP ac hangs with bad client (962UiGS-5HacT2HnT)

Post your wireless settings.
by gotsprings
Mon May 27, 2019 7:59 am
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 2
Views: 636

Re: RB4011

Try all the resets listed in the directions.

Last resort... Netinstall.
by gotsprings
Mon May 27, 2019 7:41 am
Forum: RouterBOARD hardware
Topic: RB4011: wlan1 disabling itself
Replies: 260
Views: 33780

Re: RB4011: wlan1 disabling itself

I ran a RB4011 at home as a wireless access point only, for about a month. While it suffered from the same... "Can't go faster than about 300M on speed tests..." (This has been the case with every Mikrotik Wireless I have tried.) I can't think of a time when the 5G was not accepting clients. I set t...
by gotsprings
Mon May 27, 2019 7:10 am
Forum: Wireless Networking
Topic: RB962UiGS-5HacT2HnT low wifi performance
Replies: 2
Views: 536

Re: RB962UiGS-5HacT2HnT low wifi performance

It would seem you are coming to the same findings I am. I can't get a single test to break 330 using Mikrotik Wireless. wAP AC, cAP AC, hAP AC, RB4011. This is a consistent thing. It's to the point now where I tell people flat out... "If your internet speed is above 250M we will not be able to use M...
by gotsprings
Sun May 26, 2019 10:58 am
Forum: Wireless Networking
Topic: 2.4 4-way handshake timeout
Replies: 11
Views: 1533

Re: 2.4 4-way handshake timeout

Took cAP out of caps-mode. Same result. Well sort of. Log file showed unicast key time out. Went back to caps mode and added an unencrypted SSID. Devices connected for about 10 seconds. Then I got a disconnected for extensive data loss. Looked up several old posts tagged with extensive data loss. Th...
by gotsprings
Sat May 25, 2019 5:47 pm
Forum: Wireless Networking
Topic: 2.4 4-way handshake timeout
Replies: 11
Views: 1533

2.4 4-way handshake timeout

This seems to have come back on me. Router OS is 6.44.3 on hEX and cAP AC devices on the 2.4 radio are disconnecting from the wifi. Log into the router and check the logs and see... (MAC of Devices) disconnect 4-way handshake timeout Devices on 5Gig radio do not show this error. Last time I reported...
by gotsprings
Thu May 02, 2019 5:10 pm
Forum: General
Topic: GoogleFiber
Replies: 16
Views: 1253

Re: GoogleFiber

Support just got back to me and set to set the chain in Mangle to OUTPUT. That seems odd. Hello, In RouterOS you can set QoS priority 3 to outgoing VLAN packets using this rule: /ip firewall mangle add chain=output out-interface=GoogleVLAN action=set-priority new-priority=3 Best regards, Follow up ...
by gotsprings
Tue Apr 30, 2019 8:12 pm
Forum: General
Topic: GoogleFiber
Replies: 16
Views: 1253

Re: GoogleFiber

Support just got back to me and set to set the chain in Mangle to OUTPUT.

That seems odd.
Hello,

In RouterOS you can set QoS priority 3 to outgoing VLAN packets using this rule:

/ip firewall mangle
add chain=output out-interface=GoogleVLAN action=set-priority new-priority=3

Best regards,
by gotsprings
Sun Apr 28, 2019 10:10 pm
Forum: General
Topic: GoogleFiber
Replies: 16
Views: 1253

Re: GoogleFiber

That is correct, you got an IP without that line active so you could also omit that line.
but I think we are discussing a 3011 here, right?
Correct
by gotsprings
Sun Apr 28, 2019 10:09 pm
Forum: General
Topic: GoogleFiber
Replies: 16
Views: 1253

Re: GoogleFiber

Also check if your ethernet interface negotiates to the correct speed and duplex.
Status shows as Unknown.
by gotsprings
Sat Apr 27, 2019 2:09 pm
Forum: General
Topic: GoogleFiber
Replies: 16
Views: 1253

Re: GoogleFiber

That is correct, you got an IP without that line active so you could also omit that line.

Can't test because I am not even on the same continent. ;-)
Thanks for the help.

Will get someone on site to check it.
by gotsprings
Sat Apr 27, 2019 1:48 pm
Forum: General
Topic: GoogleFiber
Replies: 16
Views: 1253

Re: GoogleFiber

So in Mangle they want this? /ip firewall mangle add chain=forward out-interface=GoogleVLAN action=set-priority \ new-priority=3 comment="All other traffic with priority 3" I added it and released the DHCP-Client and got a new address. Now if I could get a bandwidth test server to let me connect.
by gotsprings
Sat Apr 27, 2019 1:26 pm
Forum: General
Topic: GoogleFiber
Replies: 16
Views: 1253

GoogleFiber

First install with GoogleFiber. After looking into several documents I found that Small Business accounts ABSOLUTELY could remove the Google Router and go straight to their own router. The install I was working on was residential so Google refused to "click that switch" or help me get around the nee...
by gotsprings
Fri Apr 26, 2019 3:01 pm
Forum: RouterBOARD hardware
Topic: Sierra MC7455 solutions?
Replies: 4
Views: 701

Re: Sierra MC7455 solutions?

Using the WAP-R with T-Mobile and Verizon... Never saw better than about 11M. I have tucked tail and given in. At 579 dollars US... the CBA850 is my standard once again. Its not worth my time for the performance hits and issues I had with the MoFi. Won't "play with the WAP-R" anymore, until they get...
by gotsprings
Mon Apr 22, 2019 1:36 pm
Forum: General
Topic: RouterBoard Webserver Stop Responding
Replies: 5
Views: 490

Re: RouterBoard Webserver Stop Responding

rebooted the RB3011 running 6.44 and the webserver is working again.

Support...

Could you please take a look at the file I sent.
by gotsprings
Sat Apr 20, 2019 2:24 pm
Forum: General
Topic: DNS Failover
Replies: 8
Views: 1352

Re: DNS Failover

Set the Mikrotik to use a DNS other than piehole... Like 8.8.8.8, 1.1.1.1.

Then in your DHCP server... Set the DNS value under network to be piehole, Mikrotik.

If piehole doesn't work... The client will ask the Mikrotik.
by gotsprings
Fri Apr 19, 2019 10:19 pm
Forum: General
Topic: Make external IP address accessible on secondary port
Replies: 8
Views: 536

Re: Make external IP address accessible on secondary port

Dumb switch and both routers being independent won't go well with the requirement to control other router's bandwidth (on first router, as I undertand it).
Which should be done per router.

But let's face it... This could / should all be done on one router.
by gotsprings
Fri Apr 19, 2019 3:08 pm
Forum: General
Topic: LTE failover just doesn't work properly
Replies: 2
Views: 299

Re: LTE failover just doesn't work properly

I use recursive routing and ping one if the DNS servers with netwatch. When it goes down... I use the connections flush method. Works perfectly.
by gotsprings
Fri Apr 19, 2019 2:51 pm
Forum: General
Topic: Make external IP address accessible on secondary port
Replies: 8
Views: 536

Re: Make external IP address accessible on secondary port

Put a dumb switch infront of the two Mikrotiks. $30 or less.
by gotsprings
Fri Apr 19, 2019 2:30 pm
Forum: General
Topic: RouterBoard Webserver Stop Responding
Replies: 5
Views: 490

Re: RouterBoard Webserver Stop Responding

Sent a support file to Mikrotik about 8 days ago.

What gives?
by gotsprings
Mon Apr 15, 2019 3:24 pm
Forum: General
Topic: IKEv2 Dual WAN Setup not possible? (2:1 relation) [SOLVED]
Replies: 18
Views: 1047

Re: IKEv2 Dual WAN Setup not possible? (2:1 relation) [SOLVED]

@gotsprings yeah it would be great if routeros had something like mesh tunneling or "SD-VPN". something like tinc would be great, but before that, ovpn with udp ;) I meant... SUBSCRIBE TO BIG LEAF'S Service. I only dealt with them on one install so far. The customer found them himself. BigLeaf take...
by gotsprings
Fri Apr 12, 2019 12:53 pm
Forum: Wireless Networking
Topic: wAP LTE US - Carriers?
Replies: 21
Views: 2218

Re: wAP LTE US - Carriers?

Thanks for the replies. No Verizon coverage is going to be a deal breaker for me, so I ordered a Sierra Wireless MC7455 card. Will RouterOS recognize this, or is there a way to install drivers? Kind of late... But that same wAP LTE KIT-US I used on T-Mobile. Is now running on Verizon wireless. I ha...
by gotsprings
Thu Apr 11, 2019 8:00 pm
Forum: Wireless Networking
Topic: Cap AC, Hap AC2 or UniFi?
Replies: 38
Views: 10386

Re: Cap AC, Hap AC2 or UniFi?

I'm actually very happy with the hAP ac2. My home is of wood construction, is single story, and about 185 m^2. We have a couple of tablets, a couple of smartphones, a couple of laptops, and an Amazon Fire stick on the TV. We occasionally have house guests that add another 1 or 2 phones and perhaps ...
by gotsprings
Thu Apr 11, 2019 4:45 pm
Forum: General
Topic: RouterBoard Webserver Stop Responding
Replies: 5
Views: 490

RouterBoard Webserver Stop Responding

I have 2 RB3011s that the webserver seems to have stopped responding. Winbox works. I can put a firewall rule in as a pass through and see the connection come in. But I see no response. Both running 6.44 Anyone seen something like this before? (I normally turn off the webserver... but this site requ...
by gotsprings
Thu Mar 28, 2019 11:27 pm
Forum: General
Topic: Port forwarding to two pcs for RDP
Replies: 12
Views: 855

Re: Port forwarding to two pcs for RDP

@anav: Give it a break with in-interface, dst-address is fine. Sorry I usually talk myself through config rules. Where are you coming from my sweet little packet and so forth . :-) Is there a situation where stating in-interface=eth-1 wan could be a problem (not including multi-wan setups)?? Yes......
by gotsprings
Thu Mar 28, 2019 3:19 pm
Forum: General
Topic: Port forwarding to two pcs for RDP
Replies: 12
Views: 855

Re: Port forwarding to two pcs for RDP

OVPN has been "Broken" on Mikrotik for as long as I have been working on Tiks.

IPSec works well.

You should do an export of your firewall. As I stated above... your PAT (Port Address Translation) in the NAT chain "looked right".
by gotsprings
Wed Mar 27, 2019 10:13 pm
Forum: General
Topic: IKEv2 - Road Warrior (NAT Workaround)
Replies: 50
Views: 6340

Re: IKEv2 - Road Warrior (NAT Workaround)

ANAV As I put in that other thread you comment in. I wrote that script to UPDATE THE LOCAL IP ADDRESS ON EACH ROUTER. The EoIP tunnel configuration accepts the IP cloud address and updates it with in 70 seconds on a change. The script I wrote needs a scheduler to run it. But it checks to see if the ...
by gotsprings
Wed Mar 27, 2019 6:50 pm
Forum: General
Topic: LTE passthrough over EoIP
Replies: 16
Views: 1105

Re: LTE passthrough over EoIP

Hey gotsprings Question: my lte suffers from frequent lte disconnects, which most of the time the modem resolves itself, but sometimes it can't and I need to recycle (stop-start) lte interface to resume connectivity. That the reason why I have netwatch to monitor remote ip. Do you experience simila...
by gotsprings
Wed Mar 27, 2019 6:48 pm
Forum: Beginner Basics
Topic: Confused about VPN local IP
Replies: 2
Views: 305

Re: Confused about VPN local IP

I don't use quickset...

But from what you posted... looks like it is setting up the VPN connection to get a 192.168.89.0/24 address.

If this was allowed in the firewall... you would be able to reach your local network unless SPECIFICALLY blocked.
by gotsprings
Wed Mar 27, 2019 6:44 pm
Forum: General
Topic: Providing Internet access to VLANs
Replies: 21
Views: 1195

Re: Providing Internet access to VLANs

I would say to not use interface lists and try doing the firewall with interfaces or address lists.

Its more than doable.
by gotsprings
Wed Mar 27, 2019 6:39 pm
Forum: General
Topic: vpn for office netwrok only? [SOLVED]
Replies: 5
Views: 419

Re: vpn for office netwrok only? [SOLVED]

You are welcome.

You might want to select my answer as accepted so others can find it quickly.
by gotsprings
Wed Mar 27, 2019 6:35 pm
Forum: General
Topic: Port forwarding to two pcs for RDP
Replies: 12
Views: 855

Re: Port forwarding to two pcs for RDP

Those look right.
by gotsprings
Wed Mar 27, 2019 6:32 pm
Forum: General
Topic: IKEv2 - Road Warrior (NAT Workaround)
Replies: 50
Views: 6340

Re: IKEv2 - Road Warrior (NAT Workaround)

@gotsprings, does IP cloud address of home router get updated automatically if the IP changes or does one need a script for that?/ @sindy remind me to call you when I try ipsec related setups. I managed to get ikev2 working on my iphone....... pretty pleased with that. IP Cloud updates every 60 sec...
by gotsprings
Wed Mar 27, 2019 6:28 pm
Forum: General
Topic: Cloud IPs need to be blocked
Replies: 13
Views: 1075

Re: Cloud IPs need to be blocked

/ip firewall address-list add address=81.198.87.240 list=ipCLOUD add address=159.148.147.229 list=ipCLOUD /ip firewall filter add action=drop chain=output dst-address-list=ipCLOUD place-before=1 add action=drop chain=forward dst-address-list=ipCLOUD place-before=1 /ip dns cache flush That should bl...
by gotsprings
Wed Mar 27, 2019 6:21 pm
Forum: General
Topic: IP Cloud
Replies: 37
Views: 8172

Re: IP Cloud

Hello, I am using Mikrotik on the vessels behind satellite modem with very limited data usage such as 50Mbyte per month. So each MBbye cost the customers extra US$s. We just allow e-mail IPs on the firewall I have seen on satellite POP, we have a lot of request from our satellite modem to 81.198.87...
by gotsprings
Wed Mar 27, 2019 5:21 pm
Forum: General
Topic: How to route (assign) two Public IP's on same segment /29 and keep connectivity
Replies: 18
Views: 1059

Re: How to route (assign) two Public IP's on same segment /29 and keep connectivity

If you have more than 1 PUBLIC IP... you have to use src-nat in your firewall NAT chain. NOT Masquerade. Lets use this an example... ISP issues you... xxx.xxx.229.105/29 Gateway as xxx.xxx.229.110 You would connect one connection from the WAN MODEM to one port on your router... say ether1. You would...
by gotsprings
Wed Mar 27, 2019 4:22 pm
Forum: General
Topic: Firewall rules: dst-limit invert
Replies: 10
Views: 487

Re: Firewall rules: dst-limit invert

Why not use queues?
by gotsprings
Wed Mar 27, 2019 4:19 pm
Forum: General
Topic: vpn for office netwrok only? [SOLVED]
Replies: 5
Views: 419

Re: vpn for office netwrok only? [SOLVED]

If I understood... You VPN to the Office using a OPERATING SYSTEMS OS. But you don't want to SEND ALL YOUR TRAFFIC to the Office network, then on to the internet? In Apple there is a Tick Mark for "send all traffic over VPN Connection". In Windws there is a Tick Mark for "use default gateway on remo...
by gotsprings
Wed Mar 27, 2019 3:57 pm
Forum: General
Topic: IKEv2 - Road Warrior (NAT Workaround)
Replies: 50
Views: 6340

Re: IKEv2 - Road Warrior (NAT Workaround)

I have 2 connections at my office. 1 RCN Cable Modem 1000/25M With a Public IP address. 2 ATT Cellular Backup Modem. 25/25M with a carrier grade NAT address. SO my solution was to set up a L2TP tunnel to my cohorts office. The L2TP tunnel does not use encryption... as it would fail if behind NAT whe...
by gotsprings
Wed Mar 27, 2019 3:41 pm
Forum: General
Topic: vpn for office netwrok only? [SOLVED]
Replies: 5
Views: 419

Re: vpn for office netwrok only? [SOLVED]

You need to allow the VPN'd client to reach the internet and BLOCK access to the subnets you don't want it reaching. Mostly handled in /ip firewall filter. Rule 11 lets you access 192.168.44.0/24 network Rule 12 lets you access 192.168.40.0/24 network Rule 13 BLOCKS you from any other network. SO un...
by gotsprings
Wed Mar 27, 2019 3:38 pm
Forum: General
Topic: LTE passthrough over EoIP
Replies: 16
Views: 1105

Re: LTE passthrough over EoIP

]/interface lte apn add apn=NE01.VZWSTATIC default-route-distance=1 name=VerizonIPPass \ passthrough-interface=ether1 passthrough-mac=auto Once I did that on the WAP-R LTE Kit... the external IP passed to what ever device I connected. If you look at the APN... I am in the North East Part of the US....
by gotsprings
Tue Mar 26, 2019 8:44 pm
Forum: Scripting
Topic: EOIP + IPSEC Update Local IP
Replies: 2
Views: 326

Re: EOIP + IPSEC Update Local IP

When you setup EOIP... You have to have an entry for Local IP and Far IP. You can place the IP cloud information in the tunnel config. However... the LOCAL IP will RESOLVE AT THE TIME you OK the tunnel. So if the local address changes... the tunnel's encryption will fail. This will update the local ...
by gotsprings
Thu Mar 21, 2019 5:08 am
Forum: Scripting
Topic: Script & Schedule for Network on & off [SOLVED]
Replies: 8
Views: 671

Re: Script & Schedule for Network on & off [SOLVED]

Connect a client and it will turn black?
by gotsprings
Tue Mar 19, 2019 1:43 pm
Forum: Scripting
Topic: EOIP + IPSEC Update Local IP
Replies: 2
Views: 326

EOIP + IPSEC Update Local IP

Needed this the other day. In Eoip Tunnel you can define the far point (remote-address) to use IPCloud. But the local address does not. This will grab the local WAN IP and add it to a EoIP tunnel with the word "Tunnel" in the name. /system script add dont-require-permissions=no name=EoipUpdate owner...
by gotsprings
Tue Mar 19, 2019 1:33 pm
Forum: Scripting
Topic: How to really make backups (by script) ?
Replies: 15
Views: 954

Re: How to really make backups (by script) ?

I always hated the fact that people could easily steal you scripts with passwords in them. (dyndns)
by gotsprings
Mon Mar 18, 2019 3:53 pm
Forum: Scripting
Topic: Script & Schedule for Network on & off [SOLVED]
Replies: 8
Views: 671

Re: Script & Schedule for Network on & off [SOLVED]

Figured this out when I was working on caps-man. When you have to disable the SSID across more than one radio... that code made life much easier.
by gotsprings
Fri Mar 15, 2019 9:53 pm
Forum: Scripting
Topic: Script & Schedule for Network on & off [SOLVED]
Replies: 8
Views: 671

Re: Script & Schedule for Network on & off [SOLVED]

Then this would kill it :log info "Turning OFF Training." /interface disable [find name~"Training"] :log info "Training DOWN." This would bring it back up. :log info "Turning ON Training." /interface enable [find name~"Training"] :log info "Training UP." You can get fancy with if then and time of da...
by gotsprings
Fri Mar 15, 2019 2:25 pm
Forum: Scripting
Topic: Script & Schedule for Network on & off [SOLVED]
Replies: 8
Views: 671

Re: Script & Schedule for Network on & off [SOLVED]

You could do this several ways...
A simple way to "learn" or "start" would be to make 2 scripts and 2 schedules.
One enables the INTERFACES
One disables the INTERFACES

What are the names of the virtual interfaces?
by gotsprings
Fri Mar 15, 2019 2:59 am
Forum: General
Topic: 6.44.1 Broke Stuff Need to Downgrade to 6.44
Replies: 4
Views: 580

Re: 6.44.1 Broke Stuff Need to Downgrade to 6.44

The device is not properly setting connections as new then established. So it flags the connection as invalid. Then the router drops it on the next pass at invalid or dumps it on my drop all.

Been using this firewall for a couple of years now. This is new behavior.
by gotsprings
Fri Mar 15, 2019 1:21 am
Forum: General
Topic: 6.44.1 Broke Stuff Need to Downgrade to 6.44
Replies: 4
Views: 580

6.44.1 Broke Stuff Need to Downgrade to 6.44

Updated a CCR1009 and hAP AC2 from 6.44 to 6.44.1 Lots of connections are suddenly getting dropped by my DROP INVALID Forwarding rule. Pings between the 2 routers on VPN show timeouts that never did before. How can I downgrade and hAP AC when the Files Directory doesn't show enough space to put in t...
by gotsprings
Fri Mar 15, 2019 12:00 am
Forum: General
Topic: ROS 6.44 - VPN L2TP not working
Replies: 23
Views: 5654

Re: ROS 6.44 - VPN L2TP not working

Upgrading 6.44.1 broke my firewall forwarding chains.
by gotsprings
Thu Mar 14, 2019 10:38 pm
Forum: Announcements
Topic: v6.44.1 [stable] is released!
Replies: 86
Views: 18573

Re: v6.44.1 [stable] is released!

Updated hAP AC2 and CCR1009 from 6.44 to 6.44.1 I am seeing a lot of dropped Forwarded packets as INVALID. These are packets that should have hit the New connection from a local device in the address list. But are getting dropped. Also IPSEC connection between offices is now dropping pings. Call fro...
by gotsprings
Thu Mar 14, 2019 2:38 am
Forum: General
Topic: Harpin NAT between two VLANs
Replies: 34
Views: 1373

Re: Harpin NAT between two VLANs

I don't know why people always use in-interface for port forwarding, it will bite them sooner or later. :) Because they saw it in some youtube tutorial, which was made on basis of having dynamic WAN address (e.g. PPPoE or DHCP) ... and if that's so, one can not really use dst-address as dst-nat cri...
by gotsprings
Wed Mar 13, 2019 3:50 am
Forum: General
Topic: Harpin NAT between two VLANs
Replies: 34
Views: 1373

Re: Harpin NAT between two VLANs

No in interface.

The external IP is what you need.
A separate rule deals with local-address list to local-address list on Local interface.
by gotsprings
Tue Mar 12, 2019 8:56 pm
Forum: General
Topic: Harpin NAT between two VLANs
Replies: 34
Views: 1373

Re: Harpin NAT between two VLANs

Gotta use the EXTERNAL IP... interface won't do it.

Like SOB put it...
/ip firewall nat
add chain=dstnat dst-address=<public IP> protocol=tcp dst-port=80,443 action=dst-nat to-adresses=192.168.100.x

PUBLIC IP.
by gotsprings
Tue Mar 12, 2019 1:35 pm
Forum: General
Topic: Harpin NAT between two VLANs
Replies: 34
Views: 1373

Re: Harpin NAT between two VLANs

If you mean the srcnat rule with same src/dst-address=<LAN subnet>/<mask> used with hairpin NAT, that's not needed here. It's needed when client thinks that it communicates with some external address, but server would see client's real address from same subnet, would reply directly and that would n...
by gotsprings
Tue Mar 12, 2019 5:17 am
Forum: General
Topic: Harpin NAT between two VLANs
Replies: 34
Views: 1373

Re: Harpin NAT between two VLANs

If you go lazy and do the DNS thing... You can only port forward to one IP. Not good if you have different services on different devices.

Sob left out the
Subenet back on subnet on interface rule.
by gotsprings
Mon Mar 11, 2019 11:45 pm
Forum: General
Topic: Harpin NAT between two VLANs
Replies: 34
Views: 1373

Re: Harpin NAT between two VLANs

Export your
/IP firewall nat
by gotsprings
Mon Mar 11, 2019 3:19 am
Forum: General
Topic: Ring hardware and Mikrotik [SOLVED]
Replies: 6
Views: 904

Re: Ring hardware and Mikrotik [SOLVED]

I'm using CAPSMAN and set Group-key-update to 01:00:00 and have had no luck with 2 doorbells. aes and WAP WPA2 on with now a shorter 8 character password. No issues connecting with any other device. Anyone else have experience? The device says has a problem connecting to the Internet. Seems like it...
by gotsprings
Sun Mar 10, 2019 7:31 pm
Forum: RouterBOARD hardware
Topic: Sierra MC7455 solutions?
Replies: 4
Views: 701

Re: Sierra MC7455 solutions?

The MoFi is averaging around 30M downloads sitting on my desk.
by gotsprings
Sun Mar 03, 2019 6:21 pm
Forum: RouterBOARD hardware
Topic: Sierra MC7455 solutions?
Replies: 4
Views: 701

Sierra MC7455 solutions?

I got a wAP R-LTE US Kit. Got it working but some US frequencies seem to be missing. I like the form factor... but would really prefer having access to the US bands that i can with the https://www.sierrawireless.com/products-and-solutions/embedded-solutions/products/mc7455/ I bought a MoFi 4500 and ...
by gotsprings
Mon Feb 25, 2019 6:13 am
Forum: Wireless Networking
Topic: wAP LTE US - Carriers?
Replies: 21
Views: 2218

Re: wAP LTE US - Carriers?

Thanks for the replies. No Verizon coverage is going to be a deal breaker for me, so I ordered a Sierra Wireless MC7455 card. Will RouterOS recognize this, or is there a way to install drivers? Kind of late... But that same wAP LTE KIT-US I used on T-Mobile. Is now running on Verizon wireless. I ha...
by gotsprings
Sat Feb 23, 2019 5:12 pm
Forum: RouterBOARD hardware
Topic: 3rd party LTE modems known working?
Replies: 11
Views: 1026

Re: 3rd party LTE modems known working?

I never tried with the M2M plans from T-Mobile. I only did a prepaid plan for proof of concept. It showed me that I would have to mount the wAP R OUTSIDE to get a signal with T-Mobile. Keeping that in my back pocket for the next time one client I know of on AutoPay screws up his verizon account again.
by gotsprings
Fri Feb 22, 2019 8:35 pm
Forum: RouterBOARD hardware
Topic: 3rd party LTE modems known working?
Replies: 11
Views: 1026

Re: 3rd party LTE modems known working?

I need a steady stream of packets that end up being ~4-6GB The $10 2GB plan just doesn't cut it and the 6GB plan is too expensive. M2M SIMs are a perfect fit, if I can find a modem that is allowed on that network and is mikrotik compatible. You need 4-6Gigs a month and $25 is too much? Wow. I stumb...
by gotsprings
Fri Feb 22, 2019 8:09 pm
Forum: General
Topic: Public-Mikrotik-Bandwidth-Test-Server(s)
Replies: 574
Views: 418563

Re: Public-Mikrotik-Bandwidth-Test-Server(s)

Info - I just updated the 207.32.194.24 btest server from 6.43.11 to 6.43.12

North Idaho Tom Jones
THANK YOU!!!
by gotsprings
Tue Feb 19, 2019 5:15 pm
Forum: RouterBOARD hardware
Topic: 3rd party LTE modems known working?
Replies: 11
Views: 1026

Re: 3rd party LTE modems known working?

T-Mobile’s M2M service doesn’t work though. It’s imei filtered and the mikrotik LTE card isn’t on the approved list.
So get the $10 a month plan?

https://prepaid.t-mobile.com/plan-detai ... e-internet
by gotsprings
Tue Feb 19, 2019 12:47 pm
Forum: RouterBOARD hardware
Topic: 3rd party LTE modems known working?
Replies: 11
Views: 1026

Re: 3rd party LTE modems known working?

https://mikrotik.com/product/wap_lte_kit_us I can confirm that this unit works with T-Mobile in the US. I had to set the APN to /interface lte apn add apn=fast.t-mobile.com default-route-distance=1 passthrough-interface=\ ether1 passthrough-mac=auto add apn=fast.t-mobile.com default-route-distance=1...
by gotsprings
Tue Feb 19, 2019 12:16 pm
Forum: Wireless Networking
Topic: Problem with 5GHz frequency - CAPsMAN
Replies: 7
Views: 1290

Re: Problem with 5GHz frequency - CAPsMAN

/caps-man channel
add band=5ghz-a/n/ac control-channel-width=20mhz extension-channel=Ceee \
    frequency=5180 name="Channel 36 80mhz"
    
Try that
by gotsprings
Fri Feb 15, 2019 4:44 pm
Forum: RouterBOARD hardware
Topic: RouterBOARD wAP R-2nD Winbox From WAN
Replies: 2
Views: 456

Re: RouterBOARD wAP R-2nD Winbox From WAN

After bunches of emails and support files... I got nothing.

Switched out unit to a MoFi modem feeding a hAP AC2. No Problem with remote connection.
by gotsprings
Wed Feb 13, 2019 4:06 am
Forum: General
Topic: Ring hardware and Mikrotik [SOLVED]
Replies: 6
Views: 904

Re: Ring hardware and Mikrotik [SOLVED]

I have a hAP AC2 running as just a wireless access point. I have a ring connected to it on 5.0 Ghz. No real problems keeping it connected. I have the group key at 5 mins. WPA2 AES. Its been on for about 45 days now.
by gotsprings
Mon Feb 11, 2019 8:01 pm
Forum: General
Topic: Need a bit of help with VPN + additional info/question
Replies: 3
Views: 387

Re: Need a bit of help with VPN + additional info/question

Well then you need to resolve those IPs and punch them in on changes.
"Scripting"
by gotsprings
Mon Feb 11, 2019 6:55 pm
Forum: Wireless Networking
Topic: One SSID with Access-list mode
Replies: 4
Views: 374

Re: One SSID with Access-list mode

Seems you would want a SSID and ports per apartment. Then have the "public SSID" run across all the hardware?
by gotsprings
Mon Feb 11, 2019 6:38 pm
Forum: General
Topic: Need a bit of help with VPN + additional info/question
Replies: 3
Views: 387

Re: Need a bit of help with VPN + additional info/question

If one of the routers lacks a public IP... connect that one using L2TP then setup a encryption inside that connection.
by gotsprings
Mon Feb 11, 2019 5:19 pm
Forum: Wireless Networking
Topic: SXT LTE query
Replies: 4
Views: 432

Re: SXT LTE query

I mean I bought a static public IP so I could reach the device remotely.

Works with Cradlepoint as a modem to a TIk.

But using the Mikrotik wAP LTE as modem and router... It's showing the one IP as the IP and the gateway. A remote connection hits then drops. Makes my remote management a problem.
by gotsprings
Mon Feb 11, 2019 12:54 pm
Forum: Wireless Networking
Topic: Automatically connect to best signal AP
Replies: 2
Views: 486

Re: Automatically connect to best signal AP

/interface wireless security-profiles

Then you need to select the security profile for each wireless network you want to connect to.
by gotsprings
Mon Feb 11, 2019 12:43 pm
Forum: Wireless Networking
Topic: Wireless Wire - expected throughput?
Replies: 8
Views: 957

Re: Wireless Wire - expected throughput?

Got 975M on my tests over short distances. But a difference being that the line of site MEANS line of site. Off axis the throughput disappeared completely even at short range. So AIM and a clean LOS is key.
by gotsprings
Mon Feb 11, 2019 12:39 pm
Forum: Wireless Networking
Topic: SXT LTE query
Replies: 4
Views: 432

Re: SXT LTE query

If its anything like the wAP LTE I am testing... its meant to work like a cellular modem. The one I am testing has problems with the gateway its picking up. So it not allowing remote connections. Making it unsuitable for the application I was planning for it. I emailed support and am looking for a C...
by gotsprings
Sat Feb 09, 2019 9:59 pm
Forum: RouterBOARD hardware
Topic: RouterBOARD wAP R-2nD Winbox From WAN
Replies: 2
Views: 456

Re: RouterBOARD wAP R-2nD Winbox From WAN

I found out that when the wAP LTE connects to the cellular provider (Verizon) it does get the Static IP From the ISP. Problem is that it gets the static IP and doesn't set a gateway that is one number higher than the static IP. Cradlepoints receive the IP from Verizon and show the IP as /29 IP = xxx...
by gotsprings
Thu Feb 07, 2019 11:35 pm
Forum: RouterBOARD hardware
Topic: RouterBOARD wAP R-2nD Winbox From WAN
Replies: 2
Views: 456

RouterBOARD wAP R-2nD Winbox From WAN

I am testing a wAP R-2nD as a replacement for our CradlePoint installs. I have the unit configured like a home router with wireless 2.4 bridged to the ethernet port and LTE modem setup as the WAN. I can reach the internet and browse normally. However i noticed that I can't get winbox to load when I ...
by gotsprings
Wed Jan 30, 2019 10:16 pm
Forum: Beginner Basics
Topic: Portforwarding not workin over pppoe
Replies: 3
Views: 270

Re: Portforwarding not workin over pppoe

Copy and past this whole thing in a New Terminal Window using RIGHT CLICK (Your mouse buttons) Copy and Paste. DO NOT USE CTRL+C and CTRL+P /ip cloud set ddns-enabled=yes /ip firewall address-list add address=192.168.88.0/24 list=GotSprings /ip firewall nat add action=masquerade chain=srcnat comment...
by gotsprings
Wed Jan 30, 2019 9:58 pm
Forum: Wireless Networking
Topic: Looking for a mikrotik router Model that supports DNAT
Replies: 8
Views: 666

Re: Looking for a mikrotik router Model that supports DNAT

Something like /ip firewall nat add action=dst-nat chain=dstnat comment="Redirect Guest DNS" dst-address=!192.168.x.x \ dst-port=53 protocol=udp src-address-list=Local to-addresses=192.168.x.x and mkv was correct. have the dhcp server tell the clients to use your piehole... (Kind of sounds rude when...
by gotsprings
Mon Jan 28, 2019 9:00 pm
Forum: Beginner Basics
Topic: Portforwarding not workin over pppoe
Replies: 3
Views: 270

Re: Portforwarding not workin over pppoe

That rule doesn't look like it is meant for external connections. add action=dst-nat chain=dstnat dst-port=81 in-interface=bridge protocol=tcp \ to-addresses=192.168.88.1 to-ports=80 That rule would take a request on port 81 coming from the bridge (Local interface) and forward it to 192.168.88.1 por...
by gotsprings
Mon Jan 28, 2019 8:34 pm
Forum: Beginner Basics
Topic: Route all traffic through NordVPN?
Replies: 19
Views: 9271

Re: Route all traffic through NordVPN?

OVPN has not worked on port 1194 for about 10 years now.

Also as for using those VPN services to "side step" geolocation... providers update their blacklists from time to time too.
by gotsprings
Mon Jan 28, 2019 7:16 pm
Forum: Wireless Networking
Topic: Looking for a mikrotik router Model that supports DNAT
Replies: 8
Views: 666

Re: Looking for a mikrotik router Model that supports DNAT

I'm using DHCP-Server option 6 to forward all DHCP clients DNS to the PI-Hole server. /ip dhcp-server option print # NAME CODE VALUE RAW-VALUE 0 PIHole 6 '192.168.x.x' c0a80032 Where 192.168.x.x is the PI-Hole address. Would be even easier to put it in /ip dhcp-server network add address=192.168.2....
by gotsprings
Mon Jan 28, 2019 4:14 pm
Forum: General
Topic: VPN Issue
Replies: 1
Views: 236

Re: VPN Issue

/ip firewall filter
export
by gotsprings
Mon Jan 28, 2019 4:13 pm
Forum: Wireless Networking
Topic: Mikrotik AP & Switch Question's [SOLVED]
Replies: 5
Views: 550

Re: Mikrotik AP & Switch Question's [SOLVED]

Thanks Guys Wish I would Have found MikroTIK be for I started buying Cisco. Not that there is any thing wrong with cisco.
Maybe I may Ebay my Switch's and pick up a 48Port Poe MikroTiK
There are no 48 port Mikrotik switches.

So your Cisco makes sense.
by gotsprings
Mon Jan 28, 2019 4:09 pm
Forum: Wireless Networking
Topic: CAPsMAN unable to manage its own Wireless interface
Replies: 16
Views: 3593

Re: CAPsMAN unable to manage its own Wireless interface

Had this working for several months now.

hAP AC2 is the main router and I wanted to add it to the cap config that it is running three cAP AC.
/interface wireless cap
set certificate=request discovery-interfaces=bridge enabled=yes interfaces=wlan1,wlan2
by gotsprings
Mon Jan 28, 2019 3:23 pm
Forum: Wireless Networking
Topic: Looking for a mikrotik router Model that supports DNAT
Replies: 8
Views: 666

Re: Looking for a mikrotik router Model that supports DNAT

pihole is a local dns server right?

You would set the dhcp-server to handout the pihole address to clients.

Then set up a rule to capture anything on port 53 and send it to your pihole server.

Any Tik should be able to do this.
by gotsprings
Wed Jan 23, 2019 9:59 pm
Forum: Wireless Networking
Topic: Cap AC, Hap AC2 or UniFi?
Replies: 38
Views: 10386

Re: Cap AC, Hap AC2 or UniFi?

Guys what can you say about roaming capability? Is this implemented in unifi is far better than mikrotik ones? Im consider which implement in my house.

Wysłane z mojego HTC 10 przy użyciu Tapatalka
Caps-Man can be MUCH MORE GRANULAR.
by gotsprings
Thu Jan 10, 2019 10:17 am
Forum: Wireless Networking
Topic: Cap AC, Hap AC2 or UniFi?
Replies: 38
Views: 10386

Re: Cap AC, Hap AC2 or UniFi?

The cAP AC and hAP AC2 top out right around 300 at point blank range. But the R510 will actually hit the 866M you should get from a 2x2 AC-MU radio. True, but this is coming at four times the price of a cAP AC/Unifi AC Lite making the comparison unrealistic. Like said by someone else, it is all abo...
by gotsprings
Tue Jan 08, 2019 11:58 pm
Forum: Wireless Networking
Topic: Cap AC, Hap AC2 or UniFi?
Replies: 38
Views: 10386

Re: Cap AC, Hap AC2 or UniFi?


Quite happy with the performance of the capAC inside the home but range in 5Ghz is markedly and expectedly less than 2.4ghz.
That's pretty typical of 5GHZ. It is faster, but doesn't go through much, or very far.
by gotsprings
Tue Jan 08, 2019 11:28 am
Forum: RouterBOARD hardware
Topic: RB4011 wireless performance?
Replies: 26
Views: 3714

Re: RB4011 wireless performance?

How many AP's do you plan to install? aside from a singular AP performance, it's probably more relevant to assess the controller function and features along with the radio performance. The controller function and features along with the client compatibility unfortunately go hard against mtk enterpr...
by gotsprings
Sat Jan 05, 2019 11:03 pm
Forum: RouterBOARD hardware
Topic: RB4011 wireless performance?
Replies: 26
Views: 3714

Re: RB4011 wireless performance?

At this moment bad, we tested 3 Intel Based AC Laptops and both are only able to connect to 54 MBit..... Kind of seems "par" for Mikrotik with wireless devices. They release them and it takes several months and routerOS/firmwares before they start showing acceptable results. I went through that wit...
by gotsprings
Sat Jan 05, 2019 11:01 pm
Forum: RouterBOARD hardware
Topic: RB4011 wireless performance?
Replies: 26
Views: 3714

Re: RB4011 wireless performance?

Double post
by gotsprings
Sat Jan 05, 2019 10:59 pm
Forum: RouterBOARD hardware
Topic: RB4011 wireless performance?
Replies: 26
Views: 3714

Re: RB4011 wireless performance?

Put OpenWRT on the wAP AC and with the newer Kernel and drivers you will get about 450MBit Is this something you can prove in a video or something? A post like that would blow up around here I should think. Might get some grease to the squeaky wheels. Like Cambium putting new OS's on Ubnt and Mikro...
by gotsprings
Sat Jan 05, 2019 6:01 pm
Forum: General
Topic: Cannot remotely connect via WinBox. [SOLVED]
Replies: 13
Views: 868

Re: Cannot remotely connect via WinBox. [SOLVED]

Below might be reason for your problem /tool mac-server mac-winbox set [ find default=yes ] disabled= yes That's for accessing Winbox via MAC address rather than IP. His first allow rule using port 8291 is for a TCP connection as an IP connection. If you see the proper PUBLIC IP on the WAN INTERFAC...
by gotsprings
Sat Jan 05, 2019 4:03 pm
Forum: RouterBOARD hardware
Topic: RB4011 wireless performance?
Replies: 26
Views: 3714

Re: RB4011 wireless performance?

At this moment bad, we tested 3 Intel Based AC Laptops and both are only able to connect to 54 MBit..... Kind of seems "par" for Mikrotik with wireless devices. They release them and it takes several months and routerOS/firmwares before they start showing acceptable results. I went through that wit...
by gotsprings
Sat Jan 05, 2019 2:32 pm
Forum: Wireless Networking
Topic: Cap AC, Hap AC2 or UniFi?
Replies: 38
Views: 10386

Re: Cap AC, Hap AC2 or UniFi?

I don't have experience with UBNT AP because the requirement of deploying UniFi controller on top of the APs doesn't fit with my purposes (home only as my business locations are Cisco centric). Nothing wrong with UniFi and I know it could be possible to do a "set and forget" setup but I like to kee...
by gotsprings
Sat Jan 05, 2019 2:07 pm
Forum: RouterBOARD hardware
Topic: RB4011 wireless performance?
Replies: 26
Views: 3714

Re: RB4011 wireless performance?

At this moment bad, we tested 3 Intel Based AC Laptops and both are only able to connect to 54 MBit..... Kind of seems "par" for Mikrotik with wireless devices. They release them and it takes several months and routerOS/firmwares before they start showing acceptable results. I went through that wit...
by gotsprings
Sat Jan 05, 2019 2:04 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88948

Re: Winbox vulnerability: please upgrade

I upgraded my router and it stopped working... Check if the update changed your master-slave settings to bridge. Thats the #1 thing I saw taking out routers who upgraded from below 6.40.8 to above it. Fixing the bridges and moving IP/DHCP-Server/Filter-Rules to use the new bridge interface got thin...
by gotsprings
Sat Jan 05, 2019 2:00 pm
Forum: RouterBOARD hardware
Topic: RB951G-2HnD Already in use, got hap ac2, what now?
Replies: 13
Views: 1179

Re: RB951G-2HnD Already in use, got hap ac2, what now?

Set up caps-man on the router. Set the config to use local forwarding. Have the local radios set up as caps, by setting the interfaces in wireless. Then Press and hold the reset button on the other unit as you power it up until is ends up in caps mode. Then you should see 4 radios list on the router...
by gotsprings
Sat Jan 05, 2019 3:15 am
Forum: RouterBOARD hardware
Topic: RB4011 wireless performance?
Replies: 26
Views: 3714

RB4011 wireless performance?

It would be great if there was a CAP with 4x4 AC-V2. But maybe some day... How is the wireless performance on the 4011 as JUST a wireless access point? The CEO is pushing hard to bring in Meraki. I would love to have a $250 Mikrotik kick the Crap out of the $1600 Wireless Access Point. The routing b...
by gotsprings
Fri Jan 04, 2019 6:25 pm
Forum: Wireless Networking
Topic: 30 day Turn Around Email Support Normis
Replies: 4
Views: 434

Re: 30 day Turn Around Email Support Normis

CZFan, This is a hardware issue that I can cure by switching to any one of several other wireless access points we have. I had emailed support about it when i found it repeatable. I got an email to update routerOS a few weeks later. Which I did. Problem was not solved. I emailed support again with m...
by gotsprings
Fri Jan 04, 2019 6:15 pm
Forum: Wireless Networking
Topic: 30 day Turn Around Email Support Normis
Replies: 4
Views: 434

Re: 30 day Turn Around Email Support Normis

Normis, When I send a request to support for a wireless radio (the 2.4 on a wAP AC) becoming "unavailable" until you restart it (but the 5.0 radio keeps right on going)... that's checking to see if something is a bug. Especially if there are several other units in the same install not showing the sa...
by gotsprings
Fri Jan 04, 2019 1:50 pm
Forum: Wireless Networking
Topic: 30 day Turn Around Email Support Normis
Replies: 4
Views: 434

30 day Turn Around Email Support Normis

I wanna use Mikrotik Caps-Man... but it doesn't perform nearly as well as competitive products. I keep trying to improve the performance but: The Manual for caps-man is clearly incomplete. When I email support with an issue and send support files... I get replies 30 days later. 30 DAYS LATER. That i...
by gotsprings
Fri Jan 04, 2019 1:30 pm
Forum: Wireless Networking
Topic: Caps-Man Multicast Helper and KeepAlive-Frames
Replies: 0
Views: 418

Caps-Man Multicast Helper and KeepAlive-Frames

https://wiki.mikrotik.com/wiki/Manual:CAPsMAN I was checking the caps-man manual, and I don't see reference to: KeepAlive-Frames. or Multicast-Buffering. in 6.43.8 I do see Multicast-Helper in winbox. But not Muticast-Buffering. There is an option for Keep-Alive Frames but no explanation in the manu...
by gotsprings
Thu Jan 03, 2019 5:56 pm
Forum: RouterBOARD hardware
Topic: CRS328-24P-4S+RM POE Problems
Replies: 5
Views: 961

Re: CRS328-24P-4S+RM POE Problems

Try a power cycle on the port:
/ interface ethernet poe etherX power-cycle
Unit still won't power up until I force POE to on. But the complaint in red is gone.
by gotsprings
Wed Jan 02, 2019 3:25 pm
Forum: Wireless Networking
Topic: Cap AC, Hap AC2 or UniFi?
Replies: 38
Views: 10386

Re: Cap AC, Hap AC2 or UniFi?

The Ruckus seem even more expensive.. I'm not sure if this isn't way overkill for my home (concrete house). I'm just trying to figure out whether I should get the Hap Ac or Ac2 and which Wireless AP (4 of them)... this is getting really difficult it seems :) Ruckus is more expensive that Mikrotik. ...
by gotsprings
Tue Jan 01, 2019 10:22 pm
Forum: Wireless Networking
Topic: Cap AC, Hap AC2 or UniFi?
Replies: 38
Views: 10386

Re: Cap AC, Hap AC2 or UniFi?

Dario.

When you configure a hAP AC2, cAP AC, and Rucks R510 exactly the same and swap them into the same spot one after the next... You would get it.

The cAP AC and hAP AC2 top out right around 300 at point blank range. But the R510 will actually hit the 866M you should get from a 2x2 AC-MU radio.
by gotsprings
Tue Jan 01, 2019 8:35 pm
Forum: Wireless Networking
Topic: Cap AC, Hap AC2 or UniFi?
Replies: 38
Views: 10386

Re: Cap AC, Hap AC2 or UniFi?

Mikrotik for routing. Ubnt for PtP links. Ruckus for Wireless Access Points. In wireless.. I can do a ton of stuff with Mikrotik wireless that I can't with Ubnt. But in straight throughput... The Ubnt is going to beat the Mikrotik and Ruckus is going to clobber both of them by a considerable margin....
by gotsprings
Sat Dec 29, 2018 4:20 pm
Forum: RouterBOARD hardware
Topic: CRS328-24P-4S+RM POE Problems
Replies: 5
Views: 961

Re: CRS328-24P-4S+RM POE Problems

Router OS 6.43.8. Matching firmware.
by gotsprings
Fri Dec 28, 2018 7:41 pm
Forum: RouterBOARD hardware
Topic: CRS328-24P-4S+RM POE Problems
Replies: 5
Views: 961

CRS328-24P-4S+RM POE Problems

Trying out my first 328. The POE seems kind of odd. I had a Wireless Wire Not Power Up on one port but it did on another. Then a UBNT CloudKey... plug it in and I get a "poe-out status: current_too_low" complaint. The unit won't power up until I set the port to POE Forced On and Voltage High. The er...
by gotsprings
Fri Dec 28, 2018 4:46 am
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88948

Re: Winbox vulnerability: please upgrade

When Mikrotik got rid of master slave... A BLIND update could really "screw some s__t up" on may configurations. And auto update would have resulted in disasterous results. That's what change logs are for, and why you read them before you hit UPDATE. An unmanaged device gets hacked after the install...
by gotsprings
Mon Dec 17, 2018 12:24 pm
Forum: General
Topic: /ip cloud Error: request time out
Replies: 5
Views: 798

Re: /ip cloud Error: request time out

Which RouterOS version are you using ? Cloud implementation has been updated recently, make sure you have a new version.
We have lots of routers out there with 6.40.8 BugFix. Is that release effected but this?

What versions of routerOS should be working with IP cloud?
by gotsprings
Mon Dec 17, 2018 12:19 pm
Forum: General
Topic: IP Cloud question
Replies: 26
Views: 1467

Re: IP Cloud question

Seen this since Friday. Would really appreciate and update.
by gotsprings
Thu Dec 13, 2018 2:28 pm
Forum: Scripting
Topic: Log entry of Caps-Man Clients at set intervals
Replies: 0
Views: 255

Log entry of Caps-Man Clients at set intervals

I was trying to come up with a script that could read the registration table from caps-man and output number of clients per SSID. So it would show up as 20:00:00 SSID Main=$Mclients SSID Guest=$Gclients 21:00:00 SSID Main=$Mclients SSID Guest=$Gclients Could be useful for seeing how many clients are...
by gotsprings
Tue Dec 11, 2018 6:42 pm
Forum: RouterBOARD hardware
Topic: CRS328-24P-4S+RM - 24x7 fans or temperature sensitive?
Replies: 64
Views: 9242

Re: CRS328-24P-4S+RM - 24x7 fans or temperature sensitive?

When I switched to SwitchOS the fans stayed on. After I updated the OS... they spun down.

Switched back to RouterOS and left it on over night on the bench. When I got here this morning... the fans are off.
by gotsprings
Tue Dec 11, 2018 12:15 am
Forum: Wireless Networking
Topic: cAP AC in CAPS-MODE throughput
Replies: 3
Views: 810

Re: cAP AC in CAPS-MODE throughput

Here is the CAP config. # dec/10/2018 17:15:44 by RouterOS 6.43.4 # software id = 5M5A-5I1M # # model = RouterBOARD cAP Gi-5acD2nD /interface bridge add admin-mac=CC:2D:E0:xx.xx.xx auto-mac=no comment=defconf name=bridge /interface wireless # managed by CAPsMAN # channel: 2412/20/gn(28dBm), SSID: No...
by gotsprings
Mon Dec 10, 2018 9:06 pm
Forum: Wireless Networking
Topic: cAP AC in CAPS-MODE throughput
Replies: 3
Views: 810

cAP AC in CAPS-MODE throughput

What sort of numbers are you actually getting over wireless? Using a CAP-AC in Caps-Man mode: My AC-MU 2x2 network card shows a connection of 866.7M in Windows. Screenshot 2018-12-10 13.55.58.png Caps-Man shows 866M the device connected at. Screenshot 2018-12-10 13.52.18.png Actual throughput seems ...
by gotsprings
Mon Dec 10, 2018 5:39 pm
Forum: RouterBOARD hardware
Topic: CRS328-24P-4S+RM - 24x7 fans or temperature sensitive?
Replies: 64
Views: 9242

Re: CRS328-24P-4S+RM - 24x7 fans or temperature sensitive?

Just hooked one up for testing. As soon as I applied power the fans spun up. After about 20 seconds... they stopped.
by gotsprings
Thu Nov 29, 2018 10:34 am
Forum: Wireless Networking
Topic: Capsman and automatic SSID configuration??
Replies: 3
Views: 478

Re: Capsman and automatic SSID configuration??

Why would you want to Cap-Man 50 unique SSIDs?

(If I understood the end result I might be able to help you make something.)
by gotsprings
Thu Nov 29, 2018 10:09 am
Forum: Wireless Networking
Topic: DPSK Dynamic WPA2 PSK support [SOLVED]
Replies: 6
Views: 1122

Re: DPSK Dynamic WPA2 PSK support [SOLVED]

Its been in there for years. Go into your access control list under wireless. You can generate/set per Mac address passwords. I took my dpsk file from my Zone Director and copy and pasted the passwords in to my access list. Result... The dpsk keys work on my Mikrotik wireless. Unplugged the ZD month...
by gotsprings
Wed Nov 14, 2018 12:19 am
Forum: Wireless Networking
Topic: Beginner's troubles with CAP AC
Replies: 10
Views: 945

Re: Beginner's troubles with CAP AC

Normis Look at a default router. hex hap whatever. /ip dhcp-server network Whats right there in the dns entry? As for comment about get someone to respond to my support tickets... they refer to 2.4 Radios suddenly deciding to go into a "stuck beacon" like mode. I have send support files a few times ...
by gotsprings
Wed Nov 14, 2018 12:12 am
Forum: Wireless Networking
Topic: Problem with wAP AC
Replies: 7
Views: 831

Re: Problem with wAP AC

For a cap...
/system package update install
/system routerboard upgrade
y
/system reboot
y
/system reset-configuration skip-backup=yes caps-mode=yes

Thats all that you should need to do on a cap.
:)
by gotsprings
Tue Nov 13, 2018 12:03 pm
Forum: Wireless Networking
Topic: Beginner's troubles with CAP AC
Replies: 10
Views: 945

Re: Beginner's troubles with CAP AC

Normis. How about you get someone to actually look into my support tickets. As for not using quickset. If you use quickset you will notice that /IP DHCP-server doesn't include DNS entries in the client info. Yesterday someone else used quickset to change the IP scope. When I logged in the ether-1 of...
by gotsprings
Tue Nov 13, 2018 3:00 am
Forum: Wireless Networking
Topic: Problem with wAP AC
Replies: 7
Views: 831

Re: Problem with wAP AC

Use quickset and set the IP scope. First thing you notice... No DNS entry in the DHCP-server.
by gotsprings
Tue Nov 13, 2018 2:59 am
Forum: Wireless Networking
Topic: Beginner's troubles with CAP AC
Replies: 10
Views: 945

Re: Beginner's troubles with CAP AC

Never ever use quickset!
by gotsprings
Mon Nov 12, 2018 3:53 pm
Forum: Wireless Networking
Topic: Wireless not working until reboot
Replies: 12
Views: 1449

Re: Wireless not working until reboot

No solution and no interest in replying from support.
by gotsprings
Mon Nov 12, 2018 3:25 pm
Forum: Wireless Networking
Topic: Problem with wAP AC
Replies: 7
Views: 831

Re: Problem with wAP AC

NEVER EVER USE QUICKSET!
by gotsprings
Mon Nov 12, 2018 3:24 pm
Forum: Wireless Networking
Topic: Beginner's troubles with CAP AC
Replies: 10
Views: 945

Re: Beginner's troubles with CAP AC

Routing is not enabled by default on a CAP AC. The default out of the box set up is as a WAP. So connect it to your router... and used it as a wireless access point.
by gotsprings
Thu Nov 08, 2018 2:59 pm
Forum: Wireless Networking
Topic: Wireless not working until reboot
Replies: 12
Views: 1449

Re: Wireless not working until reboot

Sumitted another ticket. They merged it with the last one then proceeded to ignore me again.
by gotsprings
Thu Nov 08, 2018 1:27 pm
Forum: Wireless Networking
Topic: received disassoc sending station leaving (8)
Replies: 59
Views: 38861

Re: received disassoc sending station leaving (8)

The support for wireless is non existent.

I have submitted multiple tickets and rarely get any response from Mikrotik.

I include logs and support files and still nothing.

Mikrotik can route... But I don't know what is up with the wireless.
by gotsprings
Wed Oct 03, 2018 9:06 pm
Forum: General
Topic: Router won't install update
Replies: 7
Views: 1562

Re: Router won't install update

Saw another with the same sort of issue. Replaced it rather than waste time.

When the 1st unit comes back to me... I will take a closer look. Field tech is going to swap for one I have at the office.
by gotsprings
Wed Oct 03, 2018 4:02 pm
Forum: General
Topic: Router won't install update
Replies: 7
Views: 1562

Re: Router won't install update

CRS125. 6.38
Router was hard reset from the button.
Router was defaulted with no config.
Firmware was placed in the files folder.
Wouldn't install it.

Replaced with another CRS125 RouterOS updated just fine.

Getting a 750GL with a similar problem dropped off at the office so i can check it out.
by gotsprings
Wed Oct 03, 2018 3:00 pm
Forum: General
Topic: Router won't install update
Replies: 7
Views: 1562

Router won't install update

Downloaded the latest firmware and placed it in the files menu.
Reboot.
Nothing... doesn't install.

Anyone else seeing this?
by gotsprings
Mon Sep 24, 2018 2:52 pm
Forum: Scripting
Topic: Turning off a set of Caps-Man radios
Replies: 0
Views: 264

Turning off a set of Caps-Man radios

Not sure what the mistake here was.... There are 4 Access Points being controlled by caps-man. /caps-man actual-interface-configuration disable [find configuration.ssid~"Guest"] Running that turned off the Virtual APs that provided the guest network However... it also turned off the WAN interface. T...
by gotsprings
Tue Sep 11, 2018 2:02 pm
Forum: Wireless Networking
Topic: wAP vs cAP ac vs hAP ac vs hAP ac2
Replies: 5
Views: 2056

Re: wAP vs cAP ac vs hAP ac vs hAP ac2

Been through the same thing... I finally have the hAP AC2 getting around 300Megs of throughput. When it first came out, it struggled with 30. LOTS OF FIRMWARE AND ROUTEROS VERSIONS IN BETWEEN. The hAP AC and wAP AC seem to be CPU limited to about 180Megs. The cAP AC at my office seems to sit right a...
by gotsprings
Sun Sep 09, 2018 4:08 pm
Forum: General
Topic: Anyone use their "Drop All" input rule to make a black list of addresses?
Replies: 7
Views: 842

Re: Anyone use their "Drop All" input rule to make a black list of addresses?

I have 2 rules at the top of the filter chain to dump ALL TRAFFIC from IPs that hit any port I deem "interesting" in mangle prerouting.
The mangle rule adds them to an address list for 24 hours.
Then the drop rule drops that address list at the top of the firewall chain.
by gotsprings
Sun Sep 09, 2018 4:03 pm
Forum: Wireless Networking
Topic: Caps-Man radio stops accepting clients until "bounced"
Replies: 3
Views: 523

Re: Caps-Man radio stops accepting clients until "bounced"

02:13:27 caps,info 00:1F:B8:20:3B:06@Kitchen2.4 reassociating 02:13:27 caps,info 00:1F:B8:20:3B:06@Kitchen2.4 connected, signal strength -82 02:16:24 caps,info 00:1F:B8:20:56:FE@Kitchen2.4 disconnected, received disassoc: sending station leaving (8) 02:28:42 caps,info 00:1F:B8:20:3A:59@NEW_LVR_2.4 r...
by gotsprings
Sun Sep 09, 2018 3:53 pm
Forum: Wireless Networking
Topic: Wireless not working until reboot
Replies: 12
Views: 1449

Re: Wireless not working until reboot

I have sent email to support and all I got was... try putting it in standalone.

I sent the support files and they didn't even look at it from what I can tell.
by gotsprings
Thu Sep 06, 2018 11:09 am
Forum: General
Topic: expressvpn problem
Replies: 13
Views: 4430

Re: expressvpn problem

First... Connect to the windows VPN. Do whatsmyip.org Disconnect windows VPN Connect to Mikrotik to VPN Do whatsmyip.org Do the numbers match? I found with expressnet... That they did not. Windows client was openVPN, and connected to a different server than the IPSec one. So if a service provider ba...
by gotsprings
Wed Sep 05, 2018 3:11 pm
Forum: General
Topic: expressvpn problem
Replies: 13
Views: 4430

Re: expressvpn problem

Does the express VPN client use THE SAME SERVER as the mikroitk? As I pointed out... some servers get banned from a service. I tried about a dozen servers before I found one that was not blocked by netflix. I was in the US... but the client "had heard about VPNS being safer." So he wanted us to make...
by gotsprings
Wed Sep 05, 2018 1:34 pm
Forum: General
Topic: expressvpn problem
Replies: 13
Views: 4430

Re: expressvpn problem

Use this as a basis... https://support.hidemyass.com/hc/en-us/articles/204558497-Mikrotik-Client-Setup Change the info to using expressVPN and l2tp+Ipsec. But this is what I used and it worked. The problem is that the servers would get banned again and you would need to try several servers to find o...
by gotsprings
Wed Sep 05, 2018 1:20 pm
Forum: General
Topic: expressvpn problem
Replies: 13
Views: 4430

Re: expressvpn problem

You need to make sure that all data is forced over the VPN connection. And that the client requesting the info from expressVPN DOES NOT HAVE A GPS UNIT IN IT / OR THE GPS IS SPOOFED OR TURNED OFF. (Dealt with this months ago.) After I got the expressVPN to work with l2tp+ipsec and a server that was ...
by gotsprings
Wed Sep 05, 2018 1:14 pm
Forum: Wireless Networking
Topic: Caps-Man radio stops accepting clients until "bounced"
Replies: 3
Views: 523

Caps-Man radio stops accepting clients until "bounced"

I have an install where there are 3 wAP ACs in a building. All 3 are set up in caps mode. All 2.4 radios have been assigned 20 mhz channels on non overlapping frequencies (1,6,11). devices in one part of the building will suddenly "stop working". Going into the caps-man router and looking at the log...
by gotsprings
Thu Aug 23, 2018 6:10 pm
Forum: Announcements
Topic: v6.40.9 [bugfix] is released!
Replies: 56
Views: 15201

Re: v6.40.9 [bugfix] is released!

If your webserver on the Router is turned off... none of these CVEs are exploitable? Also the word "authenticated" was used a bunch of times. 1. Yes 2. It means that a RouterOS username and password must be known. The user must log in. Then they can cause www server to crash. Basically this applies...
by gotsprings
Thu Aug 23, 2018 1:28 pm
Forum: Announcements
Topic: v6.40.9 [bugfix] is released!
Replies: 56
Views: 15201

Re: v6.40.9 [bugfix] is released!

If your webserver on the Router is turned off... none of these CVEs are exploitable?
Also the word "authenticated" was used a bunch of times.
by gotsprings
Tue Aug 21, 2018 10:58 pm
Forum: Wireless Networking
Topic: [Solved] CAPsMAN - WAP AC - 5GHz - No Supported Band - United States 3 [SOLVED]
Replies: 13
Views: 11668

Re: [Solved] CAPsMAN - WAP AC - 5GHz - No Supported Band - United States 3 [SOLVED]

I get not "supported channel" when I try to set a 5ghz radio to a 2.4 frequency.
by gotsprings
Tue Aug 21, 2018 8:01 pm
Forum: Beginner Basics
Topic: Send specific traffic over LTE interface
Replies: 15
Views: 1845

Re: Send specific traffic over LTE interface

in mangle...

First you have to mark the connection as it came in.
Then you need to use that mark to mark routing.
Then you use that routing mark to output.

The a route that matches that routing mark.
by gotsprings
Mon Aug 20, 2018 2:38 pm
Forum: RouterBOARD hardware
Topic: hAP ac² Amazon USA Price
Replies: 13
Views: 1663

Re: hAP ac² Amazon USA Price

If you're in the US, Baltic Networks usually has pretty good deals, such as 10% or more off Mikrotik's MSRP. https://www.balticnetworks.com/mikrotik-hap-ac2-dual-band-desktop-ap-us.html It's out of stock right now but you can still pre-order. Baltic is my regular source for Tik. But they can be out...
by gotsprings
Mon Aug 20, 2018 1:16 pm
Forum: Beginner Basics
Topic: Send specific traffic over LTE interface
Replies: 15
Views: 1845

Re: Send specific traffic over LTE interface

You left out
/IP route
by gotsprings
Mon Aug 20, 2018 1:01 pm
Forum: RouterBOARD hardware
Topic: hAP ac² Amazon USA Price
Replies: 13
Views: 1663

Re: hAP ac² Amazon USA Price

That guy on Amazon only started gouging once noone had any stock.

Roc-Noc always lists the market price as higher than retail.
Not found of that sort of practice, so I don't order from them... anymore.
by gotsprings
Wed Aug 15, 2018 7:06 pm
Forum: Wireless Networking
Topic: Best LTE Router (based on your experience)
Replies: 10
Views: 1479

Re: Best LTE Router (based on your experience)

SXT has dual Sims. But no WiFi.
So SHOULD???
by gotsprings
Wed Aug 15, 2018 3:00 pm
Forum: Wireless Networking
Topic: Best LTE Router (based on your experience)
Replies: 10
Views: 1479

Re: Best LTE Router (based on your experience)

Thanks for update gotsprings!!! I was looking something modem/router 4g/lte based on mikrotik (2in1) for remote client to get connected to internet without dedicated 4g/lte modem + extra tik router. So i am guessing i will need to try same setup like you have and see how it goes. Hope it will work....
by gotsprings
Tue Aug 14, 2018 7:44 pm
Forum: Wireless Networking
Topic: DLI Web Power Switch Wireless Connection issues.
Replies: 1
Views: 317

Re: DLI Web Power Switch Wireless Connection issues.

So caps-man doesn't consider the unit disconnected. /caps-man registration-table> print stats 0 ;;; Digital Loggers interface=cap2 ssid="My SSID" mac-address=7C:E1:FF:02:35:85 tx-rate="43.3Mbps-20MHz/1S/SGI" rx-rate="65Mbps-20MHz/1S/SGI" rx-signal=-61 uptime=1d13h46m1s270ms packets=97101,114406 byte...
by gotsprings
Tue Aug 14, 2018 6:45 pm
Forum: Wireless Networking
Topic: wAP LTE US - Carriers?
Replies: 21
Views: 2218

Re: wAP LTE US - Carriers?

T-Mobile got me on 4G here in the DC Metro Area. Didn't give me any complaints about putting it on a prepaid plan. Used it on and off for the month and now its expired. I had to manually enter the APN info. Before I did, the connection seemed "flakey". Once I entered the T-Mobile info... I could eas...
by gotsprings
Tue Aug 14, 2018 6:30 pm
Forum: Wireless Networking
Topic: Best LTE Router (based on your experience)
Replies: 10
Views: 1479

Re: Best LTE Router (based on your experience)

Can we use RBwAPR-2nD&R11e-LTE as modem/router for 4G/LTE connection ? I bought one and tested it on T-Mobile in the US. After I added the APN... the unit connected to the T-Mobile Network and worked like any other Mikrotik router. I used the wireless on it and it was a typical 2.4 Ghz radio. I wen...
by gotsprings
Fri Aug 10, 2018 12:35 pm
Forum: Beginner Basics
Topic: DHCP Pass throught
Replies: 5
Views: 650

Re: DHCP Pass throught

If I understand this correctly.... The hAP is a "Wireless Bridge" to the UniFi WAP? You are using the 5Ghz radio to connect the hAP to the UniFi WAP's 5GHZ radio SSID? You want devices connected to the hAP to "get an IP from the UniFi router and be in that subnet"? Once you connect the hAP AC to the...
by gotsprings
Fri Aug 10, 2018 6:42 am
Forum: Wireless Networking
Topic: DLI Web Power Switch Wireless Connection issues.
Replies: 1
Views: 317

DLI Web Power Switch Wireless Connection issues.

I am a big fan of webpower switches for cycling locked up modems. They save me from so many phone calls. Digital Loggers has put out a webpower switch with a wireless interface. https://dlidirect.com/products/new-pro-switch Just out of curiosity... I put the DLI on my wireless network. (Just for pro...
by gotsprings
Fri Aug 10, 2018 6:17 am
Forum: Beginner Basics
Topic: Netwatch never invokes script
Replies: 3
Views: 840

Re: Netwatch never invokes script

One of the routerOS updates KILLED the ability to run a script from netwatch.

Solution... put the entire script in netwatch in the up or down field.
by gotsprings
Fri Aug 10, 2018 5:57 am
Forum: Beginner Basics
Topic: Open Ports
Replies: 7
Views: 853

Re: Open Ports

Export your firewall and maybe we can figure it out.

/ip firewall filter export
by gotsprings
Tue Aug 07, 2018 4:48 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88948

Re: Winbox vulnerability: please upgrade

- Implement a good firewall according to the article here: https://wiki.mikrotik.com/wiki/Manual:Securing_Your_Router When you setup a default NAT, it looks like that all service port are blocked from the outside. Do I still need to specify for where Windbox should be allowed? /ip service set winbo...
by gotsprings
Tue Aug 07, 2018 1:38 am
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88948

Re: Winbox vulnerability: please upgrade

Tippenring.

I was agreeing with you. The logs were proof that 2 different attackers had the password from before the upgrade
by gotsprings
Tue Aug 07, 2018 12:27 am
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88948

Re: Winbox vulnerability: please upgrade

Is there anymore detailed information than the old blog post? I've seen numerous routers running 6.40.8 bugfix get compromised in the last few days. Winbox was externally accessible. On Friday I updated a couple older routers that had not yet been compromised that weren't on 6.40.8 to 6.40.8, only ...
by gotsprings
Sun Aug 05, 2018 6:56 pm
Forum: Beginner Basics
Topic: VPN tunnel
Replies: 4
Views: 549

Re: VPN tunnel

Try EoIP and add routes to put traffic in the tunnel. Provides for better encryption and deals better with MTU.
by gotsprings
Sun Aug 05, 2018 3:57 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88948

Re: Winbox vulnerability: please upgrade

I made this to look for the common stuff. (Copy and paste into terminal.) ... Open you log and look at the results. If you have a result with "!" you might have a problem. That's not really usable, is it? Besides, you still need to fix it, and upgrade afterwards. Methinks, better to check and fix a...
by gotsprings
Sat Aug 04, 2018 1:33 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88948

Re: Winbox vulnerability: please upgrade

i have found one of my customers router infected. How can i clean it remote? I have changed the socks port to default and diabled. I have not found another user like admin. The passwort is changed. But in the files are the mikrotik.php. If i delete this, after 5 seconds its new. Firmware now is 6.4...
by gotsprings
Sat Aug 04, 2018 3:48 am
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88948

Re: Winbox vulnerability: please upgrade

I made this to look for the common stuff. (Copy and paste into terminal.) :if ([/ip socks get port] = 1080) do={:log info "Socks port is still Default."} else={:log info "Socks Port changed Possible infection!"} :if ([/ip socks get enabled] = false) do={:log info "Socks is not on."} else={:log info ...
by gotsprings
Wed Aug 01, 2018 12:55 pm
Forum: General
Topic: 185.153.198.228 Has been BUSY
Replies: 9
Views: 1080

Re: 185.153.198.228 Has been BUSY

anyone figure out the password for user="service"?
by gotsprings
Mon Jul 30, 2018 10:43 pm
Forum: Beginner Basics
Topic: Troublesome Firewall rule (NAT?)
Replies: 6
Views: 698

Re: Troublesome Firewall rule (NAT?)

In the NAT rule...
You didn't define a dst-address.

In the Filter rule...
That is a forwarding rule in the /ip firewall filter
input terminates at the router.
by gotsprings
Mon Jul 30, 2018 8:31 pm
Forum: General
Topic: 185.153.198.228 Has been BUSY
Replies: 9
Views: 1080

Re: 185.153.198.228 Has been BUSY

One of our clients had a couple of boards running older firmware, and we logged in to find SOCKS configured, a "call home" script running every 60 seconds, and an added firewall rule.

Nasty stuff.
So are you having to clear out a lot of socks settings?
by gotsprings
Mon Jul 30, 2018 3:53 am
Forum: Beginner Basics
Topic: Installed new router, no internet through wireless
Replies: 7
Views: 1634

Re: Installed new router, no internet through wireless

We're is bridge in all this?

The
iP
DHCP server
And other things must be bridged from wired to wireless.

/Interface bridge

Start there.
by gotsprings
Mon Jul 30, 2018 3:47 am
Forum: General
Topic: Feature Request: Tincvpn
Replies: 14
Views: 5331

Re: Feature Request: Tincvpn

I have waited 10 years for Open VPN to get proper emplimentation.
by gotsprings
Mon Jul 30, 2018 3:33 am
Forum: General
Topic: Replace 2011UiAS-2HnD with Hex S
Replies: 4
Views: 559

Re: Replace 2011UiAS-2HnD with Hex S

New terminal
/export file=leaving

Then download that file to you computer an open it in note pad. Edits made there allow for dumping into your new router.
by gotsprings
Mon Jul 30, 2018 3:18 am
Forum: Beginner Basics
Topic: MT Cloud not connecting
Replies: 2
Views: 394

Re: MT Cloud not connecting

Make sure you have a good DNS.
/IP DNS servers
by gotsprings
Mon Jul 30, 2018 3:09 am
Forum: Beginner Basics
Topic: Hairpin NAT not working
Replies: 8
Views: 1000

Re: Hairpin NAT not working

Masquarde traffic that comes from you local subnet back to your local subnet on the local interface.
by gotsprings
Sun Jul 29, 2018 6:48 am
Forum: Scripting
Topic: Speeding up July 23 cleanup
Replies: 0
Views: 184

Speeding up July 23 cleanup

(If this is not allowed... please delete.) Maybe this can help some others who are cleaning up after this July 23 wave of attacks. As stated... you need to update your router OS as stated in the change log. Updated RouterOS Then adjust the last line of this script.. The last line... change "admin" t...