Community discussions

MikroTik App

Search found 885 matches

by gotsprings
Fri May 29, 2020 3:39 pm
Forum: General
Topic: DNS Failover
Replies: 16
Views: 5086

Re: DNS Failover

Set the Mikrotik to use a DNS other than piehole... Like 8.8.8.8, 1.1.1.1. Then in your DHCP server... Set the DNS value under network to be piehole, Mikrotik. If piehole doesn't work... The client will ask the Mikrotik. I tried this and it doesn't work Can you tell where it fails? Is it that the p...
by gotsprings
Thu May 28, 2020 10:12 pm
Forum: General
Topic: CRS354-48P-4S+2Q+ traffic problem on ports 1 to 8
Replies: 21
Views: 3432

Re: CRS354-48P-4S+2Q+ traffic problem on ports 1 to 8

this switch is cheap for the capabilities it has, but for broken hardware its too much... If it doesn't work... it doesn't mater what it costs. Also... they finally admitted there is "just nothing they can do about" busy airtime. So I stopped using their wireless radios. Routing... Love THEM. ANYTH...
by gotsprings
Thu May 28, 2020 12:49 pm
Forum: General
Topic: DNS Failover
Replies: 16
Views: 5086

Re: DNS Failover

Set the Mikrotik to use a DNS other than piehole... Like 8.8.8.8, 1.1.1.1. Then in your DHCP server... Set the DNS value under network to be piehole, Mikrotik. If piehole doesn't work... The client will ask the Mikrotik. I tried this and it doesn't work Can you tell where it fails? Is it that the p...
by gotsprings
Wed May 27, 2020 12:57 pm
Forum: General
Topic: Help with AirPrint network printer over VPN on the same subnet
Replies: 6
Views: 753

Re: Help with AirPrint network printer over VPN on the same subnet

Broadcasts don't work over VPN. So unless you use EoIP from Tik to Tik... You are not going to see the printer via airprint. Now if you can set the IP address of that printer on your device... That would work.
by gotsprings
Wed May 27, 2020 12:49 pm
Forum: SwOS
Topic: CSS326-24G-2S+RM hangs until power cycle
Replies: 89
Views: 19142

Re: CSS326-24G-2S+RM hangs until power cycle

I meant: would a CRS326 running RouterOS be a more stable solution?
Changing vendors would be "more stable".

Mikrotik can route... But man... Switching and wireless is absolutely not in the same league.
by gotsprings
Mon May 25, 2020 6:34 pm
Forum: Wireless Networking
Topic: cAP AC limited to channel 36 only in standalone mode? [SOLVED]
Replies: 5
Views: 714

Re: cAP AC limited to channel 36 only in standalone mode? [SOLVED]

We'll check that out... Once you change indoor to any, you get the upper frequencies.
by gotsprings
Mon May 25, 2020 4:21 pm
Forum: Wireless Networking
Topic: cAP AC limited to channel 36 only in standalone mode? [SOLVED]
Replies: 5
Views: 714

cAP AC limited to channel 36 only in standalone mode? [SOLVED]

I have worked on caps-man for some time now. Today I needed to take my home wireless AP out as it's needed for a commercial install. Still had a cAP AC in my trunk. So it seemed a good time to put it back online. Unit was defaulted and rather than. Setup cap... I set it up as an Access Point. Went i...
by gotsprings
Mon May 25, 2020 3:42 pm
Forum: Wireless Networking
Topic: Fastest WiFi possible with MikroTik
Replies: 5
Views: 1173

Re: Fastest WiFi possible with MikroTik

Thanks for the replies. Decided to sell the Mikrotik gear on eBay and use something else - routers and switches are great from MikroTik but wireless is terrible IMO. "Terrible" is a bit much. When it comes to routing... I am confident I can beat a Tik into what I need. When it comes to wireless... ...
by gotsprings
Mon May 25, 2020 3:34 pm
Forum: Wireless Networking
Topic: Mesh Network for two neighboring houses
Replies: 1
Views: 304

Re: Mesh Network for two neighboring houses

Use a wireless wire for a PtP link. I got nearly 950Megs over a wireless connection with that product. Would definitely try it to link the buildings.
by gotsprings
Thu May 21, 2020 4:28 pm
Forum: Wireless Networking
Topic: Mikrotik AC Access Point cap ac
Replies: 36
Views: 4173

Re: Mikrotik AC Access Point cap ac

And this is "swatting a fly with a SHOTGUN"... but here is a little tip to help out if you have 2.4 radios doing this to you... First... Once you set up caps-man... NAME ALL YOUR RADIOS SOMETHING WITH 2.4 IN IT. (i.e. : caps-man interface name=Router_2.4) /system scheduler add interval=1d name=2.4dr...
by gotsprings
Thu May 21, 2020 4:18 pm
Forum: Wireless Networking
Topic: Mikrotik AC Access Point cap ac
Replies: 36
Views: 4173

Re: Mikrotik AC Access Point cap ac

BPWL. That system on main street was only listed as it was obvious. But as also stated in that post... Lots of standard US HOME deployments. Places where I wouldn't call interference "that high". Problems are less frequent... But still occurs. Now here... 2 cAP ACs will run about $140. The step to $...
by gotsprings
Thu May 21, 2020 4:14 pm
Forum: Wireless Networking
Topic: Mikrotik AC Access Point cap ac
Replies: 36
Views: 4173

Re: Mikrotik AC Access Point cap ac

So your main point is a 240$ AP from Rukus is better than a 50$ AP from MK? My point is maybe you were trying to use the MK in a setup they were never meant to support ( heavy noise, lots of clients) ? Because I have 3 CAP ACs at home with capsman and around 30 Wifi Clients and I have yet to see an...
by gotsprings
Wed May 20, 2020 2:33 pm
Forum: Wireless Networking
Topic: Mikrotik AC Access Point cap ac
Replies: 36
Views: 4173

Re: Mikrotik AC Access Point cap ac

Gotsprings, in very particular cases we will see issues with all vendors. People are buying Tiks and thinking they will get cheap Ciscos or Arubas. They will not, especially discussing Wifi. As people say here, MK is great for routing, mediocre for WIFI. But I prefer to have everything from the sam...
by gotsprings
Tue May 19, 2020 8:23 pm
Forum: Wireless Networking
Topic: Audience vs Eero?
Replies: 40
Views: 10127

Re: Audience vs Eero?

That seems to be the product its built to compete with. Anyone done the comparisons yet? In the Mesh world and for busy home networks, based on my field experiences nobody beats Netgear RBKxx systems -- NOBODY period FULL Stop Ruckus --- The only manufacturer that has successfully exploited Spatial...
by gotsprings
Tue May 19, 2020 3:48 pm
Forum: Wireless Networking
Topic: Audience vs Eero?
Replies: 40
Views: 10127

Re: Audience vs Eero?

I gave the audience a few months... Same old quirks here and there. Shutting of a radio was new to me. I have seen Tik radios stop accepting clients until rebooted... but actually disabled and stopped transmitting the SSID... that was new. R610 was on sale for $270. Couldn't pass that up. Configured...
by gotsprings
Tue May 19, 2020 3:30 pm
Forum: Wireless Networking
Topic: CAPS Local Forwarding
Replies: 1
Views: 219

Re: CAPS Local Forwarding

Are you saying that your Router is Running Caps-Man? Thats fine if it is... (Most common deployment I would think.) the firewall will function at your router like normal. If you have LOCAL FORWARDING unchecked... all traffic is tunneled back to the Caps-Man Controller. This cause a considerable slow...
by gotsprings
Tue May 19, 2020 3:19 pm
Forum: General
Topic: slow vpn connection two venues
Replies: 13
Views: 1258

Re: slow vpn connection two venues

Because you can't fast track and actually have to route and use encryption, for what you asked But the configuration shows neither - fasttracking cannot speed up anything as the firewall is not there at all, and encryption is not used either. Do I read it right that the main WAN is PPPoE? I can't g...
by gotsprings
Tue May 19, 2020 3:04 pm
Forum: Wireless Networking
Topic: Mikrotik AC Access Point cap ac
Replies: 36
Views: 4173

Re: Mikrotik AC Access Point cap ac

Tech Lord... Point 2 about stability... With Tik Radios... In noisy environments radios will just stop accepting clients and will continue doing this until rebooted. Then devices can connect for some amount of time again. Until its time to reboot again. My work around was to keep a printer on the sa...
by gotsprings
Tue May 19, 2020 2:39 pm
Forum: General
Topic: slow vpn connection two venues
Replies: 13
Views: 1258

Re: slow vpn connection two venues

Because you can't fast track and actually have to route and use encryption, for what you asked
by gotsprings
Tue May 19, 2020 2:38 pm
Forum: General
Topic: Bypass speed isp via VPN Mikrotik?
Replies: 3
Views: 473

Re: Bypass speed isp via VPN Mikrotik?

Can you use a VPN to go faster than your current internet speed?
Is that what you asked?

If so, in short... No.
by gotsprings
Tue May 19, 2020 2:09 pm
Forum: Wireless Networking
Topic: Mikrotik AC Access Point cap ac
Replies: 36
Views: 4173

Re: Mikrotik AC Access Point cap ac

Once again... The cost savings are not equal to the drop in performance.

Also as stated in another post... I picked up a Ruckus R610 for $270 US. It absolutely beats the Audience that sat in the same spot for several months. Throughput. Number of clients. Connectivity. It's just not close.
by gotsprings
Tue May 19, 2020 1:58 pm
Forum: General
Topic: slow vpn connection two venues
Replies: 13
Views: 1258

Re: slow vpn connection two venues

2011 is way to slow to hit 600 for just straight NAT. Pick up an hAP AC2. Much better processor and IPSec acceleration built in.
by gotsprings
Mon May 18, 2020 7:44 am
Forum: General
Topic: slow vpn connection two venues
Replies: 13
Views: 1258

Re: slow vpn connection two venues

Which model?
by gotsprings
Mon May 18, 2020 7:41 am
Forum: General
Topic: Port Priority
Replies: 13
Views: 1781

Re: Port Priority

Limit bandwidth of the others
by gotsprings
Sun May 17, 2020 4:33 pm
Forum: Wireless Networking
Topic: MikroTik Audience slow speed WiFi, why?
Replies: 26
Views: 4548

Re: MikroTik Audience slow speed WiFi, why?

A ruckus R710 is a pretty dated unit. An R510 or R610 is newer and I would take a R610 over the R710 anyday.

Now lets also skip the B--L$h!+. Ruckus has been on Promo for nearly 2 years. The $650 R510 is readily available on Amazon for ~$250. AND STOMPS ALL OVER THE AUDIENCE.
by gotsprings
Sun May 17, 2020 4:16 pm
Forum: Wireless Networking
Topic: Mikrotik AC Access Point cap ac
Replies: 36
Views: 4173

Re: Mikrotik AC Access Point cap ac

I was incredibly excited when caps-man first came out. I spent months tweaking and coming up with some really neat stuff. Mimicking features found in wireless systems costing 10-20 times more. But... I was wasting a TREMENDOUS amount of time on some pretty bad radios. You can tweak Mikrotik wireless...
by gotsprings
Sun May 17, 2020 3:52 pm
Forum: Wireless Networking
Topic: CAPSsMAN performace issue (compared to an autonomous config on the same hardware)
Replies: 6
Views: 838

Re: CAPSsMAN performace issue (compared to an autonomous config on the same hardware)

Local forwarding will improve performance. However the radios themselves are "performance limited" compared to other manufactures.
by gotsprings
Sun May 17, 2020 3:35 pm
Forum: Wireless Networking
Topic: how to adjust tx power for caps in capsman
Replies: 1
Views: 243

Re: how to adjust tx power for caps in capsman

/caps-man interface channel tx-power
by gotsprings
Sun May 17, 2020 3:09 pm
Forum: Scripting
Topic: Script to control uptime [SOLVED]
Replies: 36
Views: 3719

Re: Script to control uptime [SOLVED]

by gotsprings
Sun May 10, 2020 7:20 pm
Forum: Wireless Networking
Topic: WIFI 6 Roadmap
Replies: 22
Views: 11317

Re: WIFI 6 Roadmap

Mikrotik wireless has been sub par all the way back in AC v1 the AC V2 devices have been plagued with constant issues relating to connection and throughput. Caps-man is incredible on paper. But in the wild... It's cost me a lot of money. Giving up and going back to another vendor was coslty... But w...
by gotsprings
Wed May 06, 2020 5:45 pm
Forum: SwOS
Topic: CSS326-24G-2S+RM hangs until power cycle
Replies: 89
Views: 19142

Re: CSS326-24G-2S+RM hangs until power cycle

I followed another thread about this for a while but ultimately gave up. The Ubnt Edgeswitch I swapped in has experienced zero lockups and has not been rebooted in several months.
by gotsprings
Wed May 06, 2020 4:53 pm
Forum: Wireless Networking
Topic: hAP AC2, cAP AC, CAPsMAN and Google Smart Home
Replies: 10
Views: 2173

Re: hAP AC2, cAP AC, CAPsMAN and Google Smart Home

Do you see the dreaded 4-way Hand Shake time out in the logs?
by gotsprings
Wed May 06, 2020 4:21 pm
Forum: Wireless Networking
Topic: Basic WiFi roaming in SoHo
Replies: 5
Views: 1029

Re: Basic WiFi roaming in SoHo

Multiple APs should be on separate channels.
by gotsprings
Wed May 06, 2020 4:05 pm
Forum: Wireless Networking
Topic: Help in Configuration of CAPsMAN
Replies: 3
Views: 781

Re: Help in Configuration of CAPsMAN

Local forwarding will take a large load off your network.

5Ghz doesn't through objects very well.
by gotsprings
Wed Apr 15, 2020 11:54 am
Forum: General
Topic: Feature Request: IP Multicast Routing/mDNS/Zeroconf/Bonjour
Replies: 22
Views: 14831

Re: Feature Request: IP Multicast Routing/mDNS/Zeroconf/Bonjour

Bumping this up the request list too.
by gotsprings
Wed Mar 04, 2020 9:16 pm
Forum: Wireless Networking
Topic: DPSK Dynamic WPA2 PSK support [SOLVED]
Replies: 8
Views: 4538

Re: DPSK Dynamic WPA2 PSK support [SOLVED]

The more I use Mikrotik wireless... The more I love Ruckus.

If you need a solution... RUCKUS.
If you don't mind a hobby... Mikrotik.

This is completely the opposite of Mikrotik routing.
by gotsprings
Wed Mar 04, 2020 12:37 am
Forum: Wireless Networking
Topic: Audience vs Eero?
Replies: 40
Views: 10127

Re: Audience vs Eero?

Audience shut off its 2.4 radio.

No idea when or why it did that. Generated a support file while the problem was happening. Got an email several days later asking me to make another support file if it happens again.

Yeah... Back to Ruckus thanks.
by gotsprings
Mon Feb 24, 2020 9:30 pm
Forum: General
Topic: Ip Nat
Replies: 7
Views: 1722

Re: Ip Nat

From my limited knowledge its a really cool and easy way to add two separate locations and make one of them 'part of the others LAN'.
EOIP... Its like stretching a long cable between 2 tiks. EVERYTHING goes across it.
by gotsprings
Mon Feb 24, 2020 9:24 pm
Forum: General
Topic: WiFi Calling Problems
Replies: 8
Views: 2048

Re: WiFi Calling Problems

I'm having issues on a hAP ac with WiFi calling. Call will connect for about 15 seconds before the person on the other end is unable to hear my voice while I can still hear theres. I've read the forums and others having issues but have been unable to find a solution. I'm running on ROS 6.45.8. I've...
by gotsprings
Sat Feb 08, 2020 11:10 pm
Forum: General
Topic: mikrotik-nordvpn
Replies: 6
Views: 1201

Re: mikrotik-nordvpn

Ovpn on Mikrotik is a non starter for connecting to other hardware. Mikrotik's version of OpenVPN is the older TCP protocol. Pretty sure Nord is going to use UDP. You can run the 7 series testing software from my understanding, which has Ovpn UDP support. So 11 years late and still in beta. No than...
by gotsprings
Sat Feb 08, 2020 5:46 am
Forum: General
Topic: New RouterOS / Mikrotik user - A few glaring missing features / bugs...
Replies: 4
Views: 992

Re: New RouterOS / Mikrotik user - A few glaring missing features / bugs...

Love Tik for routing and had to give up OVPN when I moved to Mikrotik... 10 years ago. Ovpn was messed up then and still not useable Tik wireless... I wish is worked better. But I have been burned too many times. Ruckus brought their prices down and I don't have any problems with them. So I have giv...
by gotsprings
Sat Feb 08, 2020 5:39 am
Forum: General
Topic: RouterOS as a basic webserver
Replies: 7
Views: 1667

Re: RouterOS as a basic webserver

Get a raspberry pi and put it on the network.
by gotsprings
Sat Feb 08, 2020 5:30 am
Forum: General
Topic: DNS resolution on router
Replies: 2
Views: 770

Re: DNS resolution on router

/IP firewall export
by gotsprings
Sat Feb 08, 2020 5:24 am
Forum: General
Topic: mikrotik-nordvpn
Replies: 6
Views: 1201

Re: mikrotik-nordvpn

Ovpn on Mikrotik is a non starter for connecting to other hardware. Mikrotik's version of OpenVPN is the older TCP protocol. Pretty sure Nord is going to use UDP.
by gotsprings
Mon Jan 13, 2020 10:33 pm
Forum: SwOS
Topic: CSS326-24G-2S+RM hangs until power cycle
Replies: 89
Views: 19142

Re: CSS326-24G-2S+RM hangs until power cycle

My CRS328 is still passing packets. Powering devices. But it is gone from the DHCP server. Doesn't show up in a network scan. But winbox finds it at 192.168.88.1. Webpage is not reachable at 192.168.88.1

Anything I can do to get diagnostic info to Mikrotik?
by gotsprings
Thu Jan 09, 2020 9:17 pm
Forum: SwOS
Topic: FCS error on link
Replies: 14
Views: 4345

Re: FCS error on link

@gotsprings - if the issue seems only related to SwOS and there are no cable/module issue, please report this on https://help.mikrotik.com/servicedesk/ or send an email to support@mikrotik.com EdPa I have not been able to keep my system online for more than a few days due to power issues in my area...
by gotsprings
Sun Jan 05, 2020 5:07 am
Forum: General
Topic: Possible fix for hAP ac2 rebooting randomly
Replies: 103
Views: 16737

Re: Possible fix for hAP ac2 rebooting randomly

Sure it's not a voltage thing or something else rebooting? I have some pretty intricate settings on a few hAP AC2s that have had several months of uptimes. I never messed with the processor speed. I always updated routerOS and firmware. I have had some issues with cap radios on the running cap. But ...
by gotsprings
Sat Jan 04, 2020 4:32 pm
Forum: Scripting
Topic: Script repeat in script?
Replies: 0
Views: 1688

Script repeat in script?

Just cant remember if I have seen this somewhere. So i want to improve on the autoping of my webpower switch. What I want to do is ping 2 hosts and if both hosts return 3 pings or better take NO action and repeat in 5 minutes. Else Take action and run script in 8 minutes. /system script add dont-req...
by gotsprings
Sat Jan 04, 2020 3:49 pm
Forum: Scripting
Topic: [ask] Auto detect public ip and generate dstnat rule
Replies: 7
Views: 2364

Re: [ask] Auto detect public ip and generate dstnat rule

Here are a few ways to get the public IP address Pick IP From Route (add WAN to your WAN connection name. ie. ether1-WAN) :global Stat [/ip route get [find gateway~"WAN"] pref-src] Pick IP from Address (add WAN to your WAN connection name. ie. ether1-WAN) :global OnEtherSub [/ip address get [find in...
by gotsprings
Thu Jan 02, 2020 4:03 pm
Forum: SwOS
Topic: FCS error on link
Replies: 14
Views: 4345

Re: FCS error on link

There is also the fact that I ran the switch with routerOS for several weeks without incident.
by gotsprings
Tue Dec 31, 2019 4:37 am
Forum: SwOS
Topic: FCS error on link
Replies: 14
Views: 4345

Re: FCS error on link

I would expect a bad cable to be a problem right away... Not several days later.

Especially not after the same cable and router attached to another switch didn't have this issue.

Yup... Found the other thread...
viewtopic.php?t=142969
by gotsprings
Mon Dec 30, 2019 11:10 pm
Forum: SwOS
Topic: FCS error on link
Replies: 14
Views: 4345

Re: FCS error on link

The FCS error was what the router was reporting when the switch was locked up. That cable had been used before with another manufacture's switch, and the switch never locked up. The cable is a direct connect type where the modules that go into the router and switch are part of the cable. I was hopin...
by gotsprings
Mon Dec 30, 2019 7:22 pm
Forum: SwOS
Topic: FCS error on link
Replies: 14
Views: 4345

Re: FCS error on link

During lockup...
It still provided POE to a hAP AC2 and to a 5 port 260
What does this mean ?
It means that it's POE was still active despite the fact that the switch seemed completely locked up.
by gotsprings
Mon Dec 30, 2019 7:21 pm
Forum: SwOS
Topic: FCS error on link
Replies: 14
Views: 4345

Re: FCS error on link

I guess you are using the CRS328-24P-4S+ switch, are you using the latest SwOS version?
CRS328-24P-4S+RM running switch OS, latest version.
by gotsprings
Mon Dec 30, 2019 6:06 am
Forum: Beginner Basics
Topic: How do I redirect from one IP to another?
Replies: 10
Views: 1699

Re: How do I redirect from one IP to another?

Use what I gave you and change the IPs to match your needs.
by gotsprings
Sun Dec 29, 2019 11:39 pm
Forum: SwOS
Topic: FCS error on link
Replies: 14
Views: 4345

Re: FCS error on link

Unit had been in operation for a few weeks at this point.

During lockup...
It still provided POE to a hAP AC2 and to a 5 port 260.
by gotsprings
Sun Dec 29, 2019 10:32 pm
Forum: SwOS
Topic: FCS error on link
Replies: 14
Views: 4345

FCS error on link

My network completely stopped. Couldn't get anything to work. Couldn't statically set an IP and reach the router. Rebooted router. nope. Noticed even my caps had stopped transmitting. Rebooted switch. Everything came back. Looked at the log from my router... Sfp-sfpplus1 fcs error on link After rebo...
by gotsprings
Sun Dec 29, 2019 5:03 pm
Forum: General
Topic: IP cloud DDNS doesn't work after upgrade RouterOS
Replies: 15
Views: 3303

Re: IP cloud DDNS doesn't work after upgrade RouterOS

Saw the same thing coming from BELOW 6.40.8 to above. I could ping cloud2 and everything. I messaged support but due to time differences and it being a production environment... unit came out. Got a reply a few days later... but field tech threw the unit away... it was a CRS125 from his truck that w...
by gotsprings
Sun Dec 29, 2019 4:53 pm
Forum: General
Topic: Does anyone know if a fully updated Mikrotik Device is going to be vulnerable to this?
Replies: 9
Views: 1844

Re: Does anyone know if a fully updated Mikrotik Device is going to be vulnerable to this?

I swear i remember an article more than a year ago, about holding the connection open to 8291 and using it to probe Tik Networks.

It was the next "big thing" after Slingshot.
by gotsprings
Sun Dec 29, 2019 4:49 pm
Forum: General
Topic: OVPN mikrotik to mikrotik, no IPs
Replies: 1
Views: 458

Re: OVPN mikrotik to mikrotik, no IPs

Mikrotik's Version of OVPN has been abandoned for years. When I first started with RouterOS 10 years ago... OpenVPN was the first thing I had to "Give up on," using Mikrotik. I think i can find the exact post where I asked about OVPN being updated to work with THEN CURRENT standards. "Next RouterOS ...
by gotsprings
Sun Dec 29, 2019 4:44 pm
Forum: General
Topic: Mikrotik mobile app: connect to multiple devices at the same time
Replies: 1
Views: 437

Re: Mikrotik mobile app: connect to multiple devices at the same time

I get nervous using a touchscreen with Winbox.

I think it would be up to the device on if it would let you open multiple instances of the App.
by gotsprings
Sun Dec 29, 2019 4:41 pm
Forum: Beginner Basics
Topic: Connect to Camera in Hotspot from Management Network
Replies: 3
Views: 1062

Re: Connect to Camera in Hotspot from Management Network

Put a filter forwarding rule to allow connections from the MAIN network to the HotSpot Network above the drop rule?
by gotsprings
Sun Dec 29, 2019 4:39 pm
Forum: Beginner Basics
Topic: CAPs MAN and Firewall
Replies: 3
Views: 1234

Re: CAPs MAN and Firewall

Do you actually need MESH... since you capitalized it... that means you are planning not to wire some of your Access Points?
by gotsprings
Sun Dec 29, 2019 4:14 pm
Forum: Beginner Basics
Topic: How do I redirect from one IP to another?
Replies: 10
Views: 1699

Re: How do I redirect from one IP to another?

Here is an example I use for DNS traffic on a Bar's Guest Network... Guest DHCP server hands out OPENDNS Family DNS servers to DHCP-Clients. If the people on that try to get creative and put in their own DNS servers to bypass that filter... they get caught be these. /ip firewall nat add action=dst-n...
by gotsprings
Fri Dec 27, 2019 4:31 pm
Forum: Beginner Basics
Topic: Router Recommendation
Replies: 11
Views: 2242

Re: Router Recommendation

I also stay with the 3011 over the 4011.

Too many reports about 4011 with wifi radios shutting down And I did see the SFP+ port shut down once in my test unit.
by gotsprings
Fri Dec 27, 2019 3:38 pm
Forum: Beginner Basics
Topic: Bandwidth Upgrade Problem
Replies: 4
Views: 1169

Re: Bandwidth Upgrade Problem

The RB2011 has a 2.4 only radio, from 2011. Or my favorite fact... When first released, the difference in price between the WiFi and non wifi unit was 1 dollar. Replace the whole thing with a hAP AC2. The wireless radios are AC MU-MIMO. They seem to top out right around 300Megs on the 5Gig radio. An...
by gotsprings
Fri Dec 27, 2019 2:59 pm
Forum: Beginner Basics
Topic: PC behind RB can't connect to VPN server
Replies: 9
Views: 1902

Re: PC behind RB can't connect to VPN server

On RB I have PPTP VPN server, open ports for applications.....everything works OK except outgoing connection to remote PPTP VPN server from PC behind RB.
Does anybody know why?
/IP firewall filter export
by gotsprings
Thu Dec 26, 2019 3:26 pm
Forum: Beginner Basics
Topic: get Alert by email on new Device [SOLVED]
Replies: 18
Views: 4364

Re: get Alert by email on new Device [SOLVED]

www.domotz.com

Email, alert on your phone, and log.
by gotsprings
Thu Dec 26, 2019 2:38 pm
Forum: Beginner Basics
Topic: New router config problem - no LAN to WAN trafic
Replies: 7
Views: 1514

Re: New router config problem - no LAN to WAN trafic

Don't know what sort of speed you pay for... But I would recommend putting a managed switch in front of the router to handle the 10VLAN tagging for you. Noticed a significant slowdown when I ran into a Google fiber install that needed VLAN2 on the WAN port. If I had an RB260GS handy... I bet it woul...
by gotsprings
Thu Dec 26, 2019 2:26 pm
Forum: Scripting
Topic: Bulk change mikrotik password
Replies: 2
Views: 1686

Re: Bulk change mikrotik password

Upload an rsc file with the auto option?
by gotsprings
Sun Dec 22, 2019 9:42 pm
Forum: Wireless Networking
Topic: Multiple SSID on HAP AC2 capsman - can't get it to work
Replies: 34
Views: 5010

Re: Multiple SSID on HAP AC2 capsman - can't get it to work

Remember... I sent the support file to Mikrotik and this was the reply... Hello, When virtual AP is added to the CAPsMAN, it should be manually added to the bridge, because the virtual interfaces do not follow provisioning rules. Best regards, Viesturs R. Now let's look at that... When controlled by...
by gotsprings
Sat Dec 21, 2019 11:21 pm
Forum: Wireless Networking
Topic: Multiple SSID on HAP AC2 capsman - can't get it to work
Replies: 34
Views: 5010

Re: Multiple SSID on HAP AC2 capsman - can't get it to work

What do you seriously not get? The virtual APs are added dynamically. They are not added to the bridge. I added to the post to try to help someone solve a problem... And I posted how I was seeing something repeatable that seemed related. You just keep calling me wrong or implying I should bow down t...
by gotsprings
Sat Dec 21, 2019 5:51 pm
Forum: Wireless Networking
Topic: Multiple SSID on HAP AC2 capsman - can't get it to work
Replies: 34
Views: 5010

Re: Multiple SSID on HAP AC2 capsman - can't get it to work

@gotsprings
You are using local mode forwarding or caps man forward mode?

Sent from my Moto Z3 Play using Tapatalk
Local Forwarding... always local forwarding... Covered again and again in this thread.

Yes... using local forwarding.
by gotsprings
Sat Dec 21, 2019 5:27 pm
Forum: Scripting
Topic: Is an interface active? checker
Replies: 0
Views: 1649

Is an interface active? checker

I needed to run a script when a interface became active... This became the base of it. :local "Interface-1" [/interface get [find name=ether1] running] :local "Interface-2" [/interface get [find name=ether2] running] Based my script on the true / false nature of the output. Might help someone else a...
by gotsprings
Sat Dec 21, 2019 4:30 pm
Forum: Scripting
Topic: Feature request: tool/fetch new property - no-log
Replies: 8
Views: 3292

Re: Feature request: tool/fetch new property - no-log

I got around this by using resolve. I resolve my public IP address. And make that a local variable. Then I compare that variable to what I pick off IP cloud or route pref-source. This cuts down on sending unnecessary traffic to my name server provider. And NOTHING GETS WRITTEN TO MY LOG UNTIL... I s...
by gotsprings
Sat Dec 21, 2019 3:38 pm
Forum: Wireless Networking
Topic: Multiple SSID on HAP AC2 capsman - can't get it to work
Replies: 34
Views: 5010

Re: Multiple SSID on HAP AC2 capsman - can't get it to work

It is added as a slave configuration in provisioning. That's what this has all been about. I seriously don't know if it's a language thing... Or you are trying to be rude. But here it is is plain English. I have multiple configurations under caps man. In provisioning... I have 1 config as the main. ...
by gotsprings
Tue Dec 17, 2019 1:11 pm
Forum: Wireless Networking
Topic: Multiple SSID on HAP AC2 capsman - can't get it to work
Replies: 34
Views: 5010

Re: Multiple SSID on HAP AC2 capsman - can't get it to work

After manually adding the interfaces to the bridge... Updating Router OS broke it. Generated a support file and sent it to Mikrotik. Readded the interfaces manually, then received this reply. Hello, When virtual AP is added to the CAPsMAN, it should be manually added to the bridge, because the virtu...
by gotsprings
Fri Dec 06, 2019 10:18 pm
Forum: General
Topic: server DHCP and mikrotik
Replies: 4
Views: 730

Re: server DHCP and mikrotik

:global MainInterface [/ip dhcp-server get number=0 interface] /interface vlan add name="VLAN101" interface=$MainInterface vlan-id=101 /ip pool add name="Pool 101" range=192.168.101.100-192.168.101.150 /ip dhcp-server add address-pool="Pool 101" authoritative=after-2sec-delay disabled=no interface=...
by gotsprings
Wed Dec 04, 2019 1:07 pm
Forum: General
Topic: server DHCP and mikrotik
Replies: 4
Views: 730

Re: server DHCP and mikrotik

You need to include more about your topology.
by gotsprings
Wed Dec 04, 2019 1:04 pm
Forum: Wireless Networking
Topic: Change network
Replies: 5
Views: 1755

Re: Change network

Use Winbox Connect your computer directly to the Mikrotik Set a static IP on your computer of 192.168.88.88 Open winbox and select Neighbors The Tik should show up via IP and MAC address. CIick on the MAC address and it will populate in winbox Hit connect Navigate to /IP address Select the IP addres...
by gotsprings
Wed Dec 04, 2019 3:38 am
Forum: Wireless Networking
Topic: Multiple SSID on HAP AC2 capsman - can't get it to work
Replies: 34
Views: 5010

Re: Multiple SSID on HAP AC2 capsman - can't get it to work

Did you add bridge in the data path?

I don't.
by gotsprings
Sun Dec 01, 2019 9:04 pm
Forum: Wireless Networking
Topic: Multiple SSID on HAP AC2 capsman - can't get it to work
Replies: 34
Views: 5010

Re: Multiple SSID on HAP AC2 capsman - can't get it to work

Ok i ll give it a try and let you know... By the way when you already have a good router, i mean a powerful one just go with capsman forwarding... Am not really sure why you use local forwarding so much.... That would be Mikrotik staff. When I was getting crap numbers from cAP AC, Mikrotik support ...
by gotsprings
Sun Dec 01, 2019 8:51 pm
Forum: Wireless Networking
Topic: Multiple SSID on HAP AC2 capsman - can't get it to work
Replies: 34
Views: 5010

Re: Multiple SSID on HAP AC2 capsman - can't get it to work

Thanks for the comments, checked the provided doc, couldn't see anything that I hadn't already done. I'm not using separate VLANs, I just want the new SSID in the existing single VLAN set up. If you don't want to use vlan what is the point to have multiple SSID? I have a wireless printer that has q...
by gotsprings
Sun Dec 01, 2019 5:56 pm
Forum: Wireless Networking
Topic: Multiple SSID on HAP AC2 capsman - can't get it to work
Replies: 34
Views: 5010

Re: Multiple SSID on HAP AC2 capsman - can't get it to work

@gotsprings i ll give it a try tomorrow and i will let you know... What is your ROS version by the way ? 6.45.7. But I have noticed this for a little while now. I had an install with 3 cAP AC and a hAP AC2 as the router. I got complaints about people not being able to connect. After painfully worki...
by gotsprings
Sun Dec 01, 2019 2:27 pm
Forum: General
Topic: One public address per LAN
Replies: 16
Views: 1942

Re: One public address per LAN

If I have a /29 IP address on the WAN...
I assign them to the WAN interface.
I put the proper gateway in routes.
Then I use address-lists and src-nat to, to send different traffic over the different IPs.
Pretty sure the default for an interface is "arp enabled".

Did I miss something?
by gotsprings
Sun Dec 01, 2019 11:33 am
Forum: Wireless Networking
Topic: Multiple SSID on HAP AC2 capsman - can't get it to work
Replies: 34
Views: 5010

Re: Multiple SSID on HAP AC2 capsman - can't get it to work

It slows the throughput to garbage It depends, but in general terms i do not agree... I have in production capsman with local forwarding mode as well and never seen such behavior... Why do you manually add the interfaces inside the bridge? This is not how its done! You go to wireless cap bridge and...
by gotsprings
Sun Dec 01, 2019 12:27 am
Forum: Wireless Networking
Topic: Multiple SSID on HAP AC2 capsman - can't get it to work
Replies: 34
Views: 5010

Re: Multiple SSID on HAP AC2 capsman - can't get it to work

TO MAKE THIS CLEAR... I only observe this when the CAPS-MAN is running in the same device that I am trying to control as a cap. If its on a router or other device... all caps work just fine with virtual APs or SLAVE configs. I ve made many many capsman configurations. But so that i can be sure that...
by gotsprings
Sat Nov 30, 2019 7:41 pm
Forum: Wireless Networking
Topic: Multiple SSID on HAP AC2 capsman - can't get it to work
Replies: 34
Views: 5010

Re: Multiple SSID on HAP AC2 capsman - can't get it to work

Thanks for the comments, checked the provided doc, couldn't see anything that I hadn't already done.

I'm not using separate VLANs, I just want the new SSID in the existing single VLAN set up.
That's what I was typing... Add the second WLAN to your bridge.
by gotsprings
Sat Nov 30, 2019 4:16 pm
Forum: Wireless Networking
Topic: Multiple SSID on HAP AC2 capsman - can't get it to work
Replies: 34
Views: 5010

Re: Multiple SSID on HAP AC2 capsman - can't get it to work

TO MAKE THIS CLEAR... I only observe this when the CAPS-MAN is running in the same device that I am trying to control as a cap. If its on a router or other device... all caps work just fine with virtual APs or SLAVE configs. THIS HAPPENS 100/100 across 4 different test routers that have caps-man run...
by gotsprings
Sat Nov 30, 2019 4:13 pm
Forum: General
Topic: Port 8000 forwarding for HIKVISION camera not working
Replies: 7
Views: 1082

Re: Port 8000 forwarding for HIKVISION camera not working

/ip firewall Nat export
by gotsprings
Sat Nov 30, 2019 3:50 pm
Forum: General
Topic: One public address per LAN
Replies: 16
Views: 1942

Re: One public address per LAN

I'm afraid you may have to set arp=proxy-arp on the WAN interface if the all the public addresses are from the same subnet attached to the WAN interface.
I don't think I have ever had to do that.
by gotsprings
Sat Nov 30, 2019 3:02 pm
Forum: General
Topic: is this possible
Replies: 25
Views: 2061

Re: is this possible


In fact, in such a setup you need a router to allow communication between the VLANs, not to block it.
Yup... That right there. If no switch is layer 3 or a router... You are not getting from one subnet to the others.

And like xvo posted...
I see managed switches when I see this diagram.
by gotsprings
Sat Nov 30, 2019 2:53 pm
Forum: General
Topic: The sad state of OpenVPN
Replies: 12
Views: 2178

Re: The sad state of OpenVPN

Back when I was "all about open source"... I used OVPN all day. When I moved to Mikrotik... I found a all but deserted protocol. I asked about OVPN being brought up to modern standards... And there was chatter about "next router OS release..." That was ~10 years ago. If you want to use OVPN... Don't...
by gotsprings
Sat Nov 30, 2019 1:21 pm
Forum: Scripting
Topic: Script to reboot phones
Replies: 2
Views: 2092

Re: Script to reboot phones

How about recursive routing for the 2 ISPs? That eliminates the need to change distances dynamically. Also you can query if a route is active or not. Then make your script work on If active then, else then. You could alternatively set a static route to a host using your primary ISP and firewall it f...
by gotsprings
Sat Nov 30, 2019 1:00 pm
Forum: Wireless Networking
Topic: Simple Wireless Bridge for a 50-100m point-to-point connection
Replies: 21
Views: 2278

Re: Simple Wireless Bridge for a 50-100m point-to-point connection

I am still looking at the CCR1009-7G-1C-1S+ as the router for a restaurant???

Then he mentions overkill for a radio?
by gotsprings
Sat Nov 30, 2019 12:53 pm
Forum: Wireless Networking
Topic: Can Wireless Wire substitute gap in fibre from isp? [SOLVED]
Replies: 4
Views: 2275

Re: Can Wireless Wire substitute gap in fibre from isp? [SOLVED]

Clear line of site and proper aim is a must thou.
by gotsprings
Sat Nov 30, 2019 12:50 pm
Forum: Wireless Networking
Topic: WiFi Clients to MT AP - directly or via hAP ac
Replies: 3
Views: 1492

Re: WiFi Clients to MT AP - directly or via hAP ac

You mean hAP AC2?

That could allow for better airtime usage, in theory.
by gotsprings
Sat Nov 30, 2019 12:47 pm
Forum: Wireless Networking
Topic: Multiple SSID on HAP AC2 capsman - can't get it to work
Replies: 34
Views: 5010

Re: Multiple SSID on HAP AC2 capsman - can't get it to work

On the device running as Caps-Man... Slave SSIDs don't get added to the bridge by default.

Open bridge and add the ports.

I have seen this on several units now.
by gotsprings
Sat Nov 30, 2019 2:47 am
Forum: Wireless Networking
Topic: Audience vs Eero?
Replies: 40
Views: 10127

Re: Audience vs Eero?

Finally got one in for testing.

Used the quickset screen to match my wifi settings... Swapped my R510 out.

Unit uses standard POE so it lit right up where the ruckus had been.
19 devices connected.

Will follow up.
by gotsprings
Thu Nov 14, 2019 5:43 am
Forum: General
Topic: Design Help changing an EdgeSwitch to a Layer3 Switch
Replies: 4
Views: 782

Re: Design Help changing an EdgeSwitch to a Layer3 Switch

Took some WAGs today and it appears I have the edgeswitch routing.
by gotsprings
Wed Nov 13, 2019 8:38 pm
Forum: Wireless Networking
Topic: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi
Replies: 294
Views: 78181

Re: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi

RouterOS v6.46beta59 has fixes for wireless. Do they fix your performance problems with hap ac2?
(Not with CAPSMAN, this is full of bugs)
Which Bugs exactly in caps-man?
by gotsprings
Tue Nov 12, 2019 2:23 pm
Forum: General
Topic: Design Help changing an EdgeSwitch to a Layer3 Switch
Replies: 4
Views: 782

Design Help changing an EdgeSwitch to a Layer3 Switch

Looking for some help on an install that I have been thrown into. I could bore you with the story but here are the important parts. 5 subnets 192.168.1.0/24, 192.168.10.0/24,192.168.20.0/24,192.168.30.0/24,192.168.40.0/24 They have all Ubiquiti EdgeSwitches. No problem... I set up a hAP AC2 with the...
by gotsprings
Mon Oct 14, 2019 9:18 pm
Forum: Wireless Networking
Topic: Buying new Routerboard - need your recommendations
Replies: 14
Views: 3772

Re: Buying new Routerboard - need your recommendations

So I still don't know what to buy. Want RB4011 for wireless. Currently have CCr1009-7G-1C-PC + 2x UniFi Pro. CCR will sell. Maybe will stay with RB4011 as main router and wifi + RB962UiGS for wifi in another room? The 4011 has had problems with SFP+ port and with WiFi interfaces. I would hold off o...
by gotsprings
Thu Oct 10, 2019 11:57 pm
Forum: General
Topic: Slow connection via mikrotik
Replies: 18
Views: 2901

Re: Slow connection via mikrotik

Probably that default config problem where the DHCP-SERVER has no DNS entry.
by gotsprings
Thu Oct 10, 2019 9:25 pm
Forum: Wireless Networking
Topic: Audience vs Eero?
Replies: 40
Views: 10127

Re: Audience vs Eero?

A bit more tricky is going to be the setup / config, specially if you will use 3 AP Wifi interfaces (and not as MESH). Which 5Ghz network will a client select if you have 2 with same SSID at two different channels? Or create 2 or 3 different SSID? Running two 5GHz channels with same SSID in the sam...
by gotsprings
Thu Oct 10, 2019 5:17 pm
Forum: Wireless Networking
Topic: Audience vs Eero?
Replies: 40
Views: 10127

Re: Audience vs Eero?

Distros in the US are sending out "we have Audience in stock". But still not seeing anyone saying... "Yes I have used it... And..." Everybody is waiting for you to share the experience :wink: # While I used to LOVE TESTING STUFF OUT AND BEING FIRST... Not getting paid, and ending up holding the bag...
by gotsprings
Thu Oct 10, 2019 1:39 pm
Forum: Wireless Networking
Topic: Audience vs Eero?
Replies: 40
Views: 10127

Re: Audience vs Eero?

Distros in the US are sending out "we have Audience in stock".

But still not seeing anyone saying... "Yes I have used it... And..."
by gotsprings
Tue Oct 08, 2019 7:41 pm
Forum: RouterBOARD hardware
Topic: RB4011: wlan1 disabling itself [SOLVED]
Replies: 302
Views: 58991

Re: RB4011: wlan1 disabling itself [SOLVED]

We believe we have fixed the issue, but that particular fix has not yet been released. Wait for the next beta please. FORTUNATELY... I only have one in the field and it has not exhibited this particular problem. Could the fact that I am in the US have something to do with it? The reports of the wif...
by gotsprings
Tue Oct 08, 2019 7:31 pm
Forum: General
Topic: IGMP Snooping on the new bridge implementation (6.41 +)
Replies: 4
Views: 3118

Re: IGMP Snooping on the new bridge implementation (6.41 +)

What was the outcome of this?
by gotsprings
Wed Oct 02, 2019 10:02 pm
Forum: Wireless Networking
Topic: Audience vs Eero?
Replies: 40
Views: 10127

Re: Audience vs Eero?

What is Eero? :shock: mesh WiFi https://eero.com/ I have 2 in bridge mode. Excellent wireless coverage. I did order Audience to give it a try. Eero is what the guy who has NO BUSINESS AT ALL TOUCHING A NETWORK, is bringing into a commercial install. .... Rather confused why you quoted me and posted...
by gotsprings
Wed Oct 02, 2019 4:45 pm
Forum: Wireless Networking
Topic: Audience vs Eero?
Replies: 40
Views: 10127

Re: Audience vs Eero?

What is Eero? :shock: mesh WiFi https://eero.com/ I have 2 in bridge mode. Excellent wireless coverage. I did order Audience to give it a try. Eero is what the guy who has NO BUSINESS AT ALL TOUCHING A NETWORK, is bringing into a commercial install. Sparky, "I use this all the time." Me, "YEAH IN H...
by gotsprings
Tue Oct 01, 2019 9:09 pm
Forum: Wireless Networking
Topic: Audience vs Eero?
Replies: 40
Views: 10127

Audience vs Eero?

That seems to be the product its built to compete with.

Anyone done the comparisons yet?
by gotsprings
Tue Oct 01, 2019 1:57 pm
Forum: Wireless Networking
Topic: received disassoc sending station leaving (8)
Replies: 77
Views: 51747

Re: received disassoc sending station leaving (8)

I see this problem the same day I configure the router. Now on some jobs the problem pops up a few days after I have left. Those ones... disabling the radio interface sometimes cures it. But the jobs where I see those messages right away... I have to change manufactures. Too many lost hours and clie...
by gotsprings
Mon Sep 30, 2019 11:41 pm
Forum: Wireless Networking
Topic: received disassoc sending station leaving (8)
Replies: 77
Views: 51747

Re: received disassoc sending station leaving (8)

I have the same similar issue “disconnected, received disassoc: sending station leaving”. I have not found a fix for this problem but I think I have a workaround that has solved this issue. Wrote a script and add it to the scheduler as shown below: /system scheduler add interval=1w name=Recycle-Cap...
by gotsprings
Sun Sep 29, 2019 9:19 pm
Forum: Wireless Networking
Topic: Is Mikrotik Wireless support a different department?
Replies: 10
Views: 2449

Re: Is Mikrotik Wireless support a different department?

Logged into my one and only restaurant/bar Caps-System, in the middle of an American Football Game. (They agreed to be the Guinea Pigs when they compared the cost to the Ruckus System at their other store.) 3 cAP AC and 1 hAP AC2 as the main router. I might as well have 2.4 turned off. 2.4 only clie...
by gotsprings
Sun Sep 29, 2019 9:08 pm
Forum: Wireless Networking
Topic: Running CAP on a hAP AC2 as the controller (Bug?)
Replies: 3
Views: 1283

Re: Running CAP on a hAP AC2 as the controller (Bug?)

A problem I seem to have nailed down... If I set up caps-man on the hAP AC2 and then tell its wireless interface to JOIN THE CAP... All SSIDs start transmitting and the configuration looks like the other caps. I ve configured many many routers as capsman manager with their own WiFi joining as a cap...
by gotsprings
Sat Sep 21, 2019 3:30 pm
Forum: Wireless Networking
Topic: Mikrotik Audience Availability
Replies: 17
Views: 3570

Re: Mikrotik Audience Availability

Chechito: Environments where there are other wireless networks is when it really crumbles. I have managed to keep 50 clients connected to a cAP AC or hAP AC. But if there is a lot of wireless around you that isn't your... You get all sorts of disconnect messages. Anuser: Private PSK is a function of...
by gotsprings
Sat Sep 21, 2019 3:20 pm
Forum: General
Topic: Port forwarding
Replies: 4
Views: 908

Re: Port forwarding

They are not going to set up a VPN. If they have dynamic servers... Find out if they have a domain. You could resolve the domain and have a script punch it into the src-address when a change happens. Or with the addition of address lists... You can put the domain in there and it will resolve it as o...
by gotsprings
Fri Sep 20, 2019 6:50 pm
Forum: General
Topic: Port forwarding
Replies: 4
Views: 908

Re: Port forwarding

If the port doesn't change between WAN and LAN... you don't need to-ports=38880-38884 As for the compliance scans... SOB was asking if those ports need to be open to the whole world or only the POS servers? For example... at one of my bars, they used an online ordering company. This was before door ...
by gotsprings
Fri Sep 20, 2019 5:05 pm
Forum: Wireless Networking
Topic: Mikrotik Audience Availability
Replies: 17
Views: 3570

Re: Mikrotik Audience Availability

2 months??? wAP ACs took nearly a year to get stable numbers. In that specific case, a special situation is presented, which was the incorporation of a new ipq4xxx platform and a massive support for the ARM architecture Are you sure you are talking about wAP ac and not cAP ac ? The wAP ac is MIPSBE...
by gotsprings
Thu Sep 19, 2019 7:35 pm
Forum: Wireless Networking
Topic: Mikrotik Audience Availability
Replies: 17
Views: 3570

Re: Mikrotik Audience Availability

take it with a grain of salt

new devices comes with their own issues, and take some time to be resolved

i recommend to wait at least 2 months after introduction to market, to include a new device in a serious project
2 months??? wAP ACs took nearly a year to get stable numbers.
by gotsprings
Thu Sep 19, 2019 7:15 pm
Forum: Wireless Networking
Topic: hAP AC2+cAP AC Roaming is a joke [SOLVED]
Replies: 63
Views: 16092

Re: hAP AC2+cAP AC Roaming is a joke [SOLVED]

I won't pretend my Mikrotik Caps systems can touch My Ruckus systems.

but that kick below -87 in the access-list, is one of the easier tweaks that HELPED with roaming.
by gotsprings
Thu Sep 19, 2019 7:12 pm
Forum: Wireless Networking
Topic: Buying new Routerboard - need your recommendations
Replies: 14
Views: 3772

Re: Buying new Routerboard - need your recommendations

Love Tik for routing... but when it comes to wireless... not so much. If you have a connection faster than about 300M, you are going to want to look at other vendors for the wireless.

Also if you are in a very dense WiFi environment... other manufactures handle interference better than Tik.
by gotsprings
Thu Sep 19, 2019 6:50 pm
Forum: Wireless Networking
Topic: hAP AC2+cAP AC Roaming is a joke [SOLVED]
Replies: 63
Views: 16092

Re: hAP AC2+cAP AC Roaming is a joke [SOLVED]

Adding a rule to the access list to kick devices below 87... really helped the roaming on my installs.
/caps-man access-list
add action=accept interface=any signal-range=-87..120
add action=reject interface=any signal-range=-120..-88
by gotsprings
Thu Sep 19, 2019 4:50 pm
Forum: Wireless Networking
Topic: Running CAP on a hAP AC2 as the controller (Bug?)
Replies: 3
Views: 1283

Running CAP on a hAP AC2 as the controller (Bug?)

I have a bunch of cAPs installs out there and have a pretty good template to apply to my routers to function as the router and controller. I set up the caps configurations to allow client to client forwarding and local forwarding. After putting caps man on the primary router... I log into each cAP A...
by gotsprings
Tue Aug 27, 2019 9:35 pm
Forum: General
Topic: Double VPN
Replies: 7
Views: 1219

Re: Double VPN

I think you need to set the IP address that the VPN client comes in as. Then firewall rules will dictate what clients can then reach the next subnet. If I understood the diagram... its not VPN from one site to another... but a wired connection. If that is the case... you have one feed from the first...
by gotsprings
Tue Aug 27, 2019 9:13 am
Forum: General
Topic: Double VPN
Replies: 7
Views: 1219

Re: Double VPN

Whenever I see oVPN in a Mikrotik thread... I stop reading. OpenVPN has been crippled in Mikrotik for like 10 years now.
by gotsprings
Mon Aug 26, 2019 3:35 am
Forum: General
Topic: Access Port From Lan With Wan IP
Replies: 21
Views: 3204

Re: Access Port From Lan With Wan IP

I didn't read the whole thing..

When local net goes back to local net on local interface.... That is what the hairpin Nat rule needs to have.
by gotsprings
Mon Aug 26, 2019 2:48 am
Forum: General
Topic: Double VPN
Replies: 7
Views: 1219

Re: Double VPN

A company's office doesn't have a public IP address. My office does. I have the Far office calling my Office over L2TP. The route between them is 2 points. On each router... I have a route that points to the l2tp route. Encryption engine grabs the traffic before it goes over the tunnel. I vpn to my ...
by gotsprings
Fri Aug 23, 2019 5:23 pm
Forum: Wireless Networking
Topic: Is Mikrotik Wireless support a different department?
Replies: 10
Views: 2449

Re: Is Mikrotik Wireless support a different department?

And please keep in mind lots of users have posted about the constant connect disconnects that show up as station leaving... Or what ever it was. And people have reported that one for years to no avail. In the case of this ticket... I had another problem with Mikrotik wireless that I took the time to...
by gotsprings
Fri Aug 23, 2019 2:06 pm
Forum: Wireless Networking
Topic: Is Mikrotik Wireless support a different department?
Replies: 10
Views: 2449

Re: Is Mikrotik Wireless support a different department?

The conclusion is that a particularly high interference is causing your issue. How do you think this can be easily/quickly fixed by us? Normis, As I, and a other people on this forum have found... It's not that uncommon an occurrence. And an immediate fix is to replace the Mikrotik wireless with an...
by gotsprings
Fri Aug 23, 2019 1:40 pm
Forum: Wireless Networking
Topic: 2.4 4-way handshake timeout
Replies: 11
Views: 3223

Re: 2.4 4-way handshake timeout

Tech in the field (related to owner, so I was out ranked) insisted on putting in the cap AC he had in his truck. In the days since. Customer has been pounding him with complaints for the last week. Calling everyday. We get into the configuration and try to adjust things... But this is another site w...
by gotsprings
Fri Aug 23, 2019 1:34 pm
Forum: Wireless Networking
Topic: Is Mikrotik Wireless support a different department?
Replies: 10
Views: 2449

Re: Is Mikrotik Wireless support a different department?

Several new firmwares have been released... Gave them a try... Problem is still there.

Now I get to start all over learning another wifi vendor.
by gotsprings
Thu Aug 22, 2019 5:52 pm
Forum: General
Topic: [Feature Request] Winbox and netinstall 64 Bit versions - URGENT
Replies: 21
Views: 4773

Re: [Feature Request] Winbox and netinstall 64 Bit versions - URGENT

Isn't chromebook a Chrome browser based device? Webfig is the answer then
After years of Winbox... Webfig ain't even close.

And can't you install "apps" in Chromebook?
by gotsprings
Thu Aug 22, 2019 3:01 pm
Forum: General
Topic: [Feature Request] Winbox and netinstall 64 Bit versions - URGENT
Replies: 21
Views: 4773

Re: [Feature Request] Winbox and netinstall 64 Bit versions - URGENT

Give me Winbox on a Chromebook... (Asked for this years ago.)
by gotsprings
Thu Aug 22, 2019 2:33 pm
Forum: General
Topic: VPN
Replies: 1
Views: 539

Re: VPN

The client should be setting their VPN to NOT SEND ALL TRAFFIC, if you don't want them sending their traffic over your ISP.

If you put a firewall rules in their to deny their traffic access to the WAN... That would get them to disconnect or at least look up split tunneling VPN.
by gotsprings
Thu Aug 22, 2019 1:56 pm
Forum: Wireless Networking
Topic: LTE based internet and WiFi network at home
Replies: 11
Views: 2129

Re: LTE based internet and WiFi network at home

Tom, WAP LTE is 10/100 on the Ethernet port and 2.4 on the radio. Compounding the problems in the US, is the Cellular radio doesn't work with Band 13. This is the most common band used by Verizon. The configuration of the cellular is not "straight up". I wasted too much time on this... Just pay for ...
by gotsprings
Tue Aug 20, 2019 1:35 pm
Forum: Wireless Networking
Topic: received disassoc sending station leaving (8)
Replies: 77
Views: 51747

Re: received disassoc sending station leaving (8)

Use a different manufacture for wireless and just forget about Mikrotik wireless.

This "glitch" has been observed and reported for years at this point.

Get over it and move on.
by gotsprings
Tue Aug 20, 2019 1:30 pm
Forum: Announcements
Topic: Future of LTE products, user feedback requested
Replies: 137
Views: 40477

Re: Future of LTE products, user feedback requested

+1 for Band 13 (US Verizon)
The reason I only have one in the field.
by gotsprings
Tue Aug 20, 2019 1:28 pm
Forum: Wireless Networking
Topic: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi
Replies: 294
Views: 78181

Re: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi

i have another problem with wifi. it seemes to drop speed tenfold after several days of working without reboot. reboot solves wifi speed problem but again only for several days. help needed :( Write a simple scheduler and and script to reboot it every 48 hours. Professionally... We put a stop on Mi...
by gotsprings
Mon Jul 29, 2019 8:29 pm
Forum: Announcements
Topic: v6.45.2 [stable] is released!
Replies: 206
Views: 47825

Re: v6.45.2 [stable] is released!

Upgraded a cAP AC to 6.45.2 Reset Configuration Like I normally do... but this site was not a CAP install. /system reset-configuration UNIT CAME UP AS A ROUTER. wAP AC has always done this. This was the first time I have seen a cAP AC do this. Had to have tech on site connect to the local SSID to ge...
by gotsprings
Fri Jul 12, 2019 10:13 pm
Forum: Wireless Networking
Topic: wAP LTE US - Carriers?
Replies: 21
Views: 3690

Re: wAP LTE US - Carriers?

We used to use Cradlepoint but there's limited space in these device boxes, hence the move to using Routerboards since we're tunneling back to HQ anyway. The LTE card is perfect for this application. We might try a MVNO that utilizes Verizon and see if they will be more flexible in their accomodati...
by gotsprings
Thu Jul 11, 2019 9:14 pm
Forum: Wireless Networking
Topic: Equipment for the conference room
Replies: 6
Views: 1574

Re: Equipment for the conference room

1 Cradlepoint CBA850LP6-NA Cellular Modem. 1 Mikrotik hAP AC2 Router. 2 Power Dsine 3501-GAC POE injectors. 2 Ruckus R510 Wireless Access points. The Cellular connection to the outside world will be the choke point. But the Ruckus Wireless Antennas are much better suited for having that many clients...
by gotsprings
Thu Jul 11, 2019 1:46 pm
Forum: General
Topic: Please add basic portScan tool ( port scanner scan )
Replies: 47
Views: 18036

Re: Please add basic portScan tool ( port scanner scan )

Bump. This sounds like what I am trying to do. I want to know if a device service is still running. Like checking a printer if 9100 is responding. In my case I have a device that responds to pings. Webserver works. But a service on 51510 stops responding as confirmed by Digital Loggers autoping agai...
by gotsprings
Wed Jul 10, 2019 4:22 am
Forum: Wireless Networking
Topic: wAP LTE US - Carriers?
Replies: 21
Views: 3690

Re: wAP LTE US - Carriers?

Yup... A static IP follows the Sim card. I have taken one Sim that was setup with a static IP and moved it between 3 modems. The only issue I could think might bite you... The APN for Verizon Static is geographic. If you went to another geographic area... You may need to change the APN. In the DC m...
by gotsprings
Tue Jul 09, 2019 3:46 am
Forum: Wireless Networking
Topic: wAP LTE US - Carriers?
Replies: 21
Views: 3690

Re: wAP LTE US - Carriers?

Yup... A static IP follows the Sim card. I have taken one Sim that was setup with a static IP and moved it between 3 modems. The only issue I could think might bite you... The APN for Verizon Static is geographic. If you went to another geographic area... You may need to change the APN. In the DC me...
by gotsprings
Mon Jul 08, 2019 9:35 pm
Forum: Wireless Networking
Topic: wAP LTE US - Carriers?
Replies: 21
Views: 3690

Re: wAP LTE US - Carriers?

I know I'm a little late to the party on this thread - I'm also trying to activate some Microtik LTE boards - this is the R11e-LTE-US boards and our Verizon rep tells us the IMEI "pattern" that Microtik is assigned isn't "registered" with Verizon so their sales and provisioning systems sees the IME...
by gotsprings
Sun Jul 07, 2019 4:49 am
Forum: Wireless Networking
Topic: received disassoc sending station leaving (8)
Replies: 77
Views: 51747

Re: received disassoc sending station leaving (8)


This time...
"We were able to reproduce the problem. (Blah blah blah). We don't currently have a Fix."
When did you get this anwser?
June 10th.
by gotsprings
Sun Jul 07, 2019 4:43 am
Forum: RouterBOARD hardware
Topic: RB4011: wlan1 disabling itself [SOLVED]
Replies: 302
Views: 58991

Re: RB4011: wlan1 disabling itself [SOLVED]

I miss the good old days when Mikrotik Routed...
And Ubnt did wireless...

It's when one tried to do the other that things start to fall apart.
by gotsprings
Fri Jul 05, 2019 3:11 am
Forum: Wireless Networking
Topic: received disassoc sending station leaving (8)
Replies: 77
Views: 51747

Re: received disassoc sending station leaving (8)

I got a good capture of Caps-man not allowing connections. Wrote up a what how and when for Mikrotik. They actually investigated it. All my prior interactions with Mikrotik about wireless have been pointless. One suggestion email per month with no resolution. This time... "We were able to reproduce ...
by gotsprings
Fri Jul 05, 2019 2:40 am
Forum: Announcements
Topic: Future of LTE products, user feedback requested
Replies: 137
Views: 40477

Re: Future of LTE products, user feedback requested

Need a gigabit interface and Sierra wireless modem.
by gotsprings
Mon Jul 01, 2019 7:30 pm
Forum: Scripting
Topic: Script to clear all firewall connections
Replies: 2
Views: 1755

Re: Script to clear all firewall connections

This
/ip firewall connection remove [find]
I have this exact command in my netwatch when it checks if the Primary ISP's DNS server is there AFTER RECURSIVE ROUTING.

So it CLEARS all connections whether flipping too or away from the Primary ISP.
by gotsprings
Mon Jul 01, 2019 7:13 pm
Forum: Scripting
Topic: Monitoring a Port help?
Replies: 1
Views: 1034

Monitoring a Port help?

I have a device that locks up. Send pings to it and it still replies. Bring up its webserver... that works too. So I need a script to look at a specific service port TCP 51510 I would like to make something like this... :if ([/ping 172.16.16.16 count=5] > 3) do={ :log info "It's Up" } else={ :log in...
by gotsprings
Mon Jul 01, 2019 1:44 pm
Forum: Wireless Networking
Topic: 2.4 4-way handshake timeout
Replies: 11
Views: 3223

Re: 2.4 4-way handshake timeout

Amazon seems to have a steady flow of Ruckus at ~50% off retail.
by gotsprings
Mon Jun 17, 2019 6:59 am
Forum: General
Topic: RouterBoard Webserver Stop Responding
Replies: 5
Views: 833

Re: RouterBoard Webserver Stop Responding

Support got back to me a few weeks later. They duplicated the problem by logging into the webserver from more than one IP. No fix yet.

Work around... Disable and reenable webserver under /IP services.
by gotsprings
Sun Jun 16, 2019 3:14 pm
Forum: Wireless Networking
Topic: Is Mikrotik Wireless support a different department?
Replies: 10
Views: 2449

Re: Is Mikrotik Wireless support a different department?

Could you please provide your ticket number? Now that the issue has been clearly identified and reproduced... What sort of time table can we expect for a fix? I am sure installers and integrators would love to see some sort of progress reports. The people I answer too are pretty annoyed, looking at...
by gotsprings
Thu Jun 13, 2019 5:53 am
Forum: Wireless Networking
Topic: 2.4 4-way handshake timeout
Replies: 11
Views: 3223

Re: 2.4 4-way handshake timeout

I had exactly the same story on a big event with 12 sxt sq lite 2, it was awe full, i tried basically everything, for 5 hours, then i just moved to another brand then it worked... I was also using CAPsMAN. I am interested to know why that can happen Thank you Because some vendors can deal with inte...
by gotsprings
Mon Jun 10, 2019 1:02 pm
Forum: Wireless Networking
Topic: 2.4 4-way handshake timeout
Replies: 11
Views: 3223

Re: 2.4 4-way handshake timeout

Got email from Mikrotik. Explained the problem and how to reproduce it.

They did... And don't currently have a fix.

So high density with interference... If you see 4-way handshake time out in Caps-man...

Don't fight it. Don't mess with support. Just buy the Ruckus radio and move on.
by gotsprings
Mon Jun 10, 2019 12:54 pm
Forum: General
Topic: GoogleFiber
Replies: 16
Views: 2095

Re: GoogleFiber

Gave up weeks ago and seteled for DMZ mode.

Found Google service at this location to be "questionable" at best.
by gotsprings
Thu Jun 06, 2019 1:51 am
Forum: Wireless Networking
Topic: Is Mikrotik Wireless support a different department?
Replies: 10
Views: 2449

Re: Is Mikrotik Wireless support a different department?

Could you please provide your ticket number? My most recent one... 2019052522002091 Generated MAY 25th... has not received a single response yet. I provided the rif file in the initial email. I then provided a copy paste of the log as the problem was being observed. Here is the thread that went wit...
by gotsprings
Wed Jun 05, 2019 3:23 pm
Forum: Wireless Networking
Topic: Is Mikrotik Wireless support a different department?
Replies: 10
Views: 2449

Is Mikrotik Wireless support a different department?

If I have a problem with Mikrotik wireless... I send support files to support and hear nothing. Weeks and even months go by. The last time I got a reply on a wireless issue... I got one email per month with "suggestions". I type suggestions... Because they were NOT solutions. It was, "try this"... I...
by gotsprings
Wed Jun 05, 2019 3:11 pm
Forum: Wireless Networking
Topic: 2.4 4-way handshake timeout
Replies: 11
Views: 3223

Re: 2.4 4-way handshake timeout

For anyone keeping score... Still no email from Mikrotik support.
by gotsprings
Tue Jun 04, 2019 8:23 pm
Forum: Wireless Networking
Topic: 2.4 4-way handshake timeout
Replies: 11
Views: 3223

Re: 2.4 4-way handshake timeout

Did the Ruckus work? I've never seem something like this, are you sure there is no jammer nearby? Jammers don't show in any of the WiFi protocol scans.
I struggle to recall an install in the last 10 years that it hasn't.
by gotsprings
Mon Jun 03, 2019 12:37 am
Forum: RouterBOARD hardware
Topic: RB4011 wireless performance?
Replies: 26
Views: 5382

Re: RB4011 wireless performance?

Mikrotik wireless is THE REASON I get complaints. They can route and I love the routing. But the switches and more specifically the wireless is not up to it. Cheap is great... And it can fit some (I mean basic installs), but as a professional... I can't play around with thing for weeks. Hard limits ...
by gotsprings
Mon Jun 03, 2019 12:27 am
Forum: RouterBOARD hardware
Topic: RB4011: wlan1 disabling itself [SOLVED]
Replies: 302
Views: 58991

Re: RB4011: wlan1 disabling itself [SOLVED]

Mikrotik can route... Much Like a Sony TV looks incredible.

But a Sony speaker is a piece of $h!+.
by gotsprings
Mon Jun 03, 2019 12:07 am
Forum: Wireless Networking
Topic: Mikrotik RB4011iGS+5HacQ2HnD and WiFi 802.11AC crash interface
Replies: 31
Views: 7222

Re: Mikrotik RB4011iGS+5HacQ2HnD and WiFi 802.11AC crash interface

While I have about 150 Mikrotiks out there as wireless devices... I just can't do it anymore. Just a waste of my time trying to get support to figure out what wrong with their gear. Much like I would never expect a Sony speaker to be worth a $h!+... Mikrotik wireless has let me down too many times a...
by gotsprings
Sun Jun 02, 2019 11:54 pm
Forum: Wireless Networking
Topic: Mikrotik WLAN & CAPsMAN - Bad download perfomance
Replies: 47
Views: 8412

Re: Mikrotik WLAN & CAPsMAN - Bad download perfomance

Done a bunch of Caps-man installs at this point. Found a lot of "hard limits"... That Mikrotik wireless is "crippled by". As long as I stayed with in the lines... Most installs went ok. Have better than 300 Meg's WAN to LAN. No Mikrotik wireless. Really busy wireless airtime. No Mikrotik wireless. I...
by gotsprings
Sun Jun 02, 2019 11:42 pm
Forum: Wireless Networking
Topic: wAP LTE experience
Replies: 5
Views: 1185

Re: wAP LTE experience

Used one. Tried on several Wireless providers. Issues with remote access on any of them...

Gave up and tried mofi.

Back to cradlepoint now.
by gotsprings
Sun Jun 02, 2019 11:39 pm
Forum: Wireless Networking
Topic: Large Apartment, no Ethernet
Replies: 28
Views: 3148

Re: Large Apartment, no Ethernet

There are mesh products you may have to look into, from other vendors.
by gotsprings
Sun Jun 02, 2019 11:36 pm
Forum: Wireless Networking
Topic: 2.4 4-way handshake timeout
Replies: 11
Views: 3223

Re: 2.4 4-way handshake timeout

Still nothing from support.
by gotsprings
Mon May 27, 2019 8:01 am
Forum: RouterBOARD hardware
Topic: hAP ac hangs with bad client (962UiGS-5HacT2HnT)
Replies: 5
Views: 1206

Re: hAP ac hangs with bad client (962UiGS-5HacT2HnT)

Post your wireless settings.
by gotsprings
Mon May 27, 2019 7:59 am
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 2
Views: 953

Re: RB4011

Try all the resets listed in the directions.

Last resort... Netinstall.
by gotsprings
Mon May 27, 2019 7:41 am
Forum: RouterBOARD hardware
Topic: RB4011: wlan1 disabling itself [SOLVED]
Replies: 302
Views: 58991

Re: RB4011: wlan1 disabling itself [SOLVED]

I ran a RB4011 at home as a wireless access point only, for about a month. While it suffered from the same... "Can't go faster than about 300M on speed tests..." (This has been the case with every Mikrotik Wireless I have tried.) I can't think of a time when the 5G was not accepting clients. I set t...
by gotsprings
Mon May 27, 2019 7:10 am
Forum: Wireless Networking
Topic: RB962UiGS-5HacT2HnT low wifi performance
Replies: 2
Views: 955

Re: RB962UiGS-5HacT2HnT low wifi performance

It would seem you are coming to the same findings I am. I can't get a single test to break 330 using Mikrotik Wireless. wAP AC, cAP AC, hAP AC, RB4011. This is a consistent thing. It's to the point now where I tell people flat out... "If your internet speed is above 250M we will not be able to use M...
by gotsprings
Sun May 26, 2019 10:58 am
Forum: Wireless Networking
Topic: 2.4 4-way handshake timeout
Replies: 11
Views: 3223

Re: 2.4 4-way handshake timeout

Took cAP out of caps-mode. Same result. Well sort of. Log file showed unicast key time out. Went back to caps mode and added an unencrypted SSID. Devices connected for about 10 seconds. Then I got a disconnected for extensive data loss. Looked up several old posts tagged with extensive data loss. Th...
by gotsprings
Sat May 25, 2019 5:47 pm
Forum: Wireless Networking
Topic: 2.4 4-way handshake timeout
Replies: 11
Views: 3223

2.4 4-way handshake timeout

This seems to have come back on me. Router OS is 6.44.3 on hEX and cAP AC devices on the 2.4 radio are disconnecting from the wifi. Log into the router and check the logs and see... (MAC of Devices) disconnect 4-way handshake timeout Devices on 5Gig radio do not show this error. Last time I reported...
by gotsprings
Thu May 02, 2019 5:10 pm
Forum: General
Topic: GoogleFiber
Replies: 16
Views: 2095

Re: GoogleFiber

Support just got back to me and set to set the chain in Mangle to OUTPUT. That seems odd. Hello, In RouterOS you can set QoS priority 3 to outgoing VLAN packets using this rule: /ip firewall mangle add chain=output out-interface=GoogleVLAN action=set-priority new-priority=3 Best regards, Follow up ...
by gotsprings
Tue Apr 30, 2019 8:12 pm
Forum: General
Topic: GoogleFiber
Replies: 16
Views: 2095

Re: GoogleFiber

Support just got back to me and set to set the chain in Mangle to OUTPUT.

That seems odd.
Hello,

In RouterOS you can set QoS priority 3 to outgoing VLAN packets using this rule:

/ip firewall mangle
add chain=output out-interface=GoogleVLAN action=set-priority new-priority=3

Best regards,
by gotsprings
Sun Apr 28, 2019 10:10 pm
Forum: General
Topic: GoogleFiber
Replies: 16
Views: 2095

Re: GoogleFiber

That is correct, you got an IP without that line active so you could also omit that line.
but I think we are discussing a 3011 here, right?
Correct
by gotsprings
Sun Apr 28, 2019 10:09 pm
Forum: General
Topic: GoogleFiber
Replies: 16
Views: 2095

Re: GoogleFiber

Also check if your ethernet interface negotiates to the correct speed and duplex.
Status shows as Unknown.
by gotsprings
Sat Apr 27, 2019 2:09 pm
Forum: General
Topic: GoogleFiber
Replies: 16
Views: 2095

Re: GoogleFiber

That is correct, you got an IP without that line active so you could also omit that line.

Can't test because I am not even on the same continent. ;-)
Thanks for the help.

Will get someone on site to check it.
by gotsprings
Sat Apr 27, 2019 1:48 pm
Forum: General
Topic: GoogleFiber
Replies: 16
Views: 2095

Re: GoogleFiber

So in Mangle they want this? /ip firewall mangle add chain=forward out-interface=GoogleVLAN action=set-priority \ new-priority=3 comment="All other traffic with priority 3" I added it and released the DHCP-Client and got a new address. Now if I could get a bandwidth test server to let me connect.
by gotsprings
Sat Apr 27, 2019 1:26 pm
Forum: General
Topic: GoogleFiber
Replies: 16
Views: 2095

GoogleFiber

First install with GoogleFiber. After looking into several documents I found that Small Business accounts ABSOLUTELY could remove the Google Router and go straight to their own router. The install I was working on was residential so Google refused to "click that switch" or help me get around the nee...
by gotsprings
Fri Apr 26, 2019 3:01 pm
Forum: RouterBOARD hardware
Topic: Sierra MC7455 solutions?
Replies: 4
Views: 1228

Re: Sierra MC7455 solutions?

Using the WAP-R with T-Mobile and Verizon... Never saw better than about 11M. I have tucked tail and given in. At 579 dollars US... the CBA850 is my standard once again. Its not worth my time for the performance hits and issues I had with the MoFi. Won't "play with the WAP-R" anymore, until they get...
by gotsprings
Mon Apr 22, 2019 1:36 pm
Forum: General
Topic: RouterBoard Webserver Stop Responding
Replies: 5
Views: 833

Re: RouterBoard Webserver Stop Responding

rebooted the RB3011 running 6.44 and the webserver is working again.

Support...

Could you please take a look at the file I sent.
by gotsprings
Sat Apr 20, 2019 2:24 pm
Forum: General
Topic: DNS Failover
Replies: 16
Views: 5086

Re: DNS Failover

Set the Mikrotik to use a DNS other than piehole... Like 8.8.8.8, 1.1.1.1.

Then in your DHCP server... Set the DNS value under network to be piehole, Mikrotik.

If piehole doesn't work... The client will ask the Mikrotik.
by gotsprings
Fri Apr 19, 2019 10:19 pm
Forum: General
Topic: Make external IP address accessible on secondary port
Replies: 8
Views: 905

Re: Make external IP address accessible on secondary port

Dumb switch and both routers being independent won't go well with the requirement to control other router's bandwidth (on first router, as I undertand it).
Which should be done per router.

But let's face it... This could / should all be done on one router.
by gotsprings
Fri Apr 19, 2019 3:08 pm
Forum: General
Topic: LTE failover just doesn't work properly
Replies: 2
Views: 550

Re: LTE failover just doesn't work properly

I use recursive routing and ping one if the DNS servers with netwatch. When it goes down... I use the connections flush method. Works perfectly.
by gotsprings
Fri Apr 19, 2019 2:51 pm
Forum: General
Topic: Make external IP address accessible on secondary port
Replies: 8
Views: 905

Re: Make external IP address accessible on secondary port

Put a dumb switch infront of the two Mikrotiks. $30 or less.
by gotsprings
Fri Apr 19, 2019 2:30 pm
Forum: General
Topic: RouterBoard Webserver Stop Responding
Replies: 5
Views: 833

Re: RouterBoard Webserver Stop Responding

Sent a support file to Mikrotik about 8 days ago.

What gives?
by gotsprings
Mon Apr 15, 2019 3:24 pm
Forum: General
Topic: IKEv2 Dual WAN Setup not possible? (2:1 relation) [SOLVED]
Replies: 18
Views: 1963

Re: IKEv2 Dual WAN Setup not possible? (2:1 relation) [SOLVED]

@gotsprings yeah it would be great if routeros had something like mesh tunneling or "SD-VPN". something like tinc would be great, but before that, ovpn with udp ;) I meant... SUBSCRIBE TO BIG LEAF'S Service. I only dealt with them on one install so far. The customer found them himself. BigLeaf take...
by gotsprings
Fri Apr 12, 2019 12:53 pm
Forum: Wireless Networking
Topic: wAP LTE US - Carriers?
Replies: 21
Views: 3690

Re: wAP LTE US - Carriers?

Thanks for the replies. No Verizon coverage is going to be a deal breaker for me, so I ordered a Sierra Wireless MC7455 card. Will RouterOS recognize this, or is there a way to install drivers? Kind of late... But that same wAP LTE KIT-US I used on T-Mobile. Is now running on Verizon wireless. I ha...
by gotsprings
Thu Apr 11, 2019 8:00 pm
Forum: Wireless Networking
Topic: Cap AC, Hap AC2 or UniFi?
Replies: 38
Views: 15777

Re: Cap AC, Hap AC2 or UniFi?

I'm actually very happy with the hAP ac2. My home is of wood construction, is single story, and about 185 m^2. We have a couple of tablets, a couple of smartphones, a couple of laptops, and an Amazon Fire stick on the TV. We occasionally have house guests that add another 1 or 2 phones and perhaps ...
by gotsprings
Thu Apr 11, 2019 4:45 pm
Forum: General
Topic: RouterBoard Webserver Stop Responding
Replies: 5
Views: 833

RouterBoard Webserver Stop Responding

I have 2 RB3011s that the webserver seems to have stopped responding. Winbox works. I can put a firewall rule in as a pass through and see the connection come in. But I see no response. Both running 6.44 Anyone seen something like this before? (I normally turn off the webserver... but this site requ...
by gotsprings
Thu Mar 28, 2019 11:27 pm
Forum: General
Topic: Port forwarding to two pcs for RDP
Replies: 12
Views: 2269

Re: Port forwarding to two pcs for RDP

@anav: Give it a break with in-interface, dst-address is fine. Sorry I usually talk myself through config rules. Where are you coming from my sweet little packet and so forth . :-) Is there a situation where stating in-interface=eth-1 wan could be a problem (not including multi-wan setups)?? Yes......
by gotsprings
Thu Mar 28, 2019 3:19 pm
Forum: General
Topic: Port forwarding to two pcs for RDP
Replies: 12
Views: 2269

Re: Port forwarding to two pcs for RDP

OVPN has been "Broken" on Mikrotik for as long as I have been working on Tiks.

IPSec works well.

You should do an export of your firewall. As I stated above... your PAT (Port Address Translation) in the NAT chain "looked right".
by gotsprings
Wed Mar 27, 2019 10:13 pm
Forum: General
Topic: IKEv2 - Road Warrior (NAT Workaround)
Replies: 50
Views: 8901

Re: IKEv2 - Road Warrior (NAT Workaround)

ANAV As I put in that other thread you comment in. I wrote that script to UPDATE THE LOCAL IP ADDRESS ON EACH ROUTER. The EoIP tunnel configuration accepts the IP cloud address and updates it with in 70 seconds on a change. The script I wrote needs a scheduler to run it. But it checks to see if the ...
by gotsprings
Wed Mar 27, 2019 6:50 pm
Forum: General
Topic: LTE passthrough over EoIP
Replies: 16
Views: 2116

Re: LTE passthrough over EoIP

Hey gotsprings Question: my lte suffers from frequent lte disconnects, which most of the time the modem resolves itself, but sometimes it can't and I need to recycle (stop-start) lte interface to resume connectivity. That the reason why I have netwatch to monitor remote ip. Do you experience simila...
by gotsprings
Wed Mar 27, 2019 6:48 pm
Forum: Beginner Basics
Topic: Confused about VPN local IP
Replies: 2
Views: 566

Re: Confused about VPN local IP

I don't use quickset...

But from what you posted... looks like it is setting up the VPN connection to get a 192.168.89.0/24 address.

If this was allowed in the firewall... you would be able to reach your local network unless SPECIFICALLY blocked.
by gotsprings
Wed Mar 27, 2019 6:44 pm
Forum: General
Topic: Providing Internet access to VLANs
Replies: 21
Views: 3041

Re: Providing Internet access to VLANs

I would say to not use interface lists and try doing the firewall with interfaces or address lists.

Its more than doable.
by gotsprings
Wed Mar 27, 2019 6:39 pm
Forum: General
Topic: vpn for office netwrok only? [SOLVED]
Replies: 5
Views: 800

Re: vpn for office netwrok only? [SOLVED]

You are welcome.

You might want to select my answer as accepted so others can find it quickly.
by gotsprings
Wed Mar 27, 2019 6:35 pm
Forum: General
Topic: Port forwarding to two pcs for RDP
Replies: 12
Views: 2269

Re: Port forwarding to two pcs for RDP

Those look right.
by gotsprings
Wed Mar 27, 2019 6:32 pm
Forum: General
Topic: IKEv2 - Road Warrior (NAT Workaround)
Replies: 50
Views: 8901

Re: IKEv2 - Road Warrior (NAT Workaround)

@gotsprings, does IP cloud address of home router get updated automatically if the IP changes or does one need a script for that?/ @sindy remind me to call you when I try ipsec related setups. I managed to get ikev2 working on my iphone....... pretty pleased with that. IP Cloud updates every 60 sec...
by gotsprings
Wed Mar 27, 2019 6:28 pm
Forum: General
Topic: Cloud IPs need to be blocked
Replies: 13
Views: 1909

Re: Cloud IPs need to be blocked

/ip firewall address-list add address=81.198.87.240 list=ipCLOUD add address=159.148.147.229 list=ipCLOUD /ip firewall filter add action=drop chain=output dst-address-list=ipCLOUD place-before=1 add action=drop chain=forward dst-address-list=ipCLOUD place-before=1 /ip dns cache flush That should bl...
by gotsprings
Wed Mar 27, 2019 6:21 pm
Forum: General
Topic: IP Cloud
Replies: 41
Views: 18611

Re: IP Cloud

Hello, I am using Mikrotik on the vessels behind satellite modem with very limited data usage such as 50Mbyte per month. So each MBbye cost the customers extra US$s. We just allow e-mail IPs on the firewall I have seen on satellite POP, we have a lot of request from our satellite modem to 81.198.87...
by gotsprings
Wed Mar 27, 2019 5:21 pm
Forum: General
Topic: How to route (assign) two Public IP's on same segment /29 and keep connectivity
Replies: 18
Views: 2136

Re: How to route (assign) two Public IP's on same segment /29 and keep connectivity

If you have more than 1 PUBLIC IP... you have to use src-nat in your firewall NAT chain. NOT Masquerade. Lets use this an example... ISP issues you... xxx.xxx.229.105/29 Gateway as xxx.xxx.229.110 You would connect one connection from the WAN MODEM to one port on your router... say ether1. You would...
by gotsprings
Wed Mar 27, 2019 4:22 pm
Forum: General
Topic: Firewall rules: dst-limit invert
Replies: 10
Views: 877

Re: Firewall rules: dst-limit invert

Why not use queues?
by gotsprings
Wed Mar 27, 2019 4:19 pm
Forum: General
Topic: vpn for office netwrok only? [SOLVED]
Replies: 5
Views: 800

Re: vpn for office netwrok only? [SOLVED]

If I understood... You VPN to the Office using a OPERATING SYSTEMS OS. But you don't want to SEND ALL YOUR TRAFFIC to the Office network, then on to the internet? In Apple there is a Tick Mark for "send all traffic over VPN Connection". In Windws there is a Tick Mark for "use default gateway on remo...
by gotsprings
Wed Mar 27, 2019 3:57 pm
Forum: General
Topic: IKEv2 - Road Warrior (NAT Workaround)
Replies: 50
Views: 8901

Re: IKEv2 - Road Warrior (NAT Workaround)

I have 2 connections at my office. 1 RCN Cable Modem 1000/25M With a Public IP address. 2 ATT Cellular Backup Modem. 25/25M with a carrier grade NAT address. SO my solution was to set up a L2TP tunnel to my cohorts office. The L2TP tunnel does not use encryption... as it would fail if behind NAT whe...
by gotsprings
Wed Mar 27, 2019 3:41 pm
Forum: General
Topic: vpn for office netwrok only? [SOLVED]
Replies: 5
Views: 800

Re: vpn for office netwrok only? [SOLVED]

You need to allow the VPN'd client to reach the internet and BLOCK access to the subnets you don't want it reaching. Mostly handled in /ip firewall filter. Rule 11 lets you access 192.168.44.0/24 network Rule 12 lets you access 192.168.40.0/24 network Rule 13 BLOCKS you from any other network. SO un...
by gotsprings
Wed Mar 27, 2019 3:38 pm
Forum: General
Topic: LTE passthrough over EoIP
Replies: 16
Views: 2116

Re: LTE passthrough over EoIP

]/interface lte apn add apn=NE01.VZWSTATIC default-route-distance=1 name=VerizonIPPass \ passthrough-interface=ether1 passthrough-mac=auto Once I did that on the WAP-R LTE Kit... the external IP passed to what ever device I connected. If you look at the APN... I am in the North East Part of the US....
by gotsprings
Tue Mar 26, 2019 8:44 pm
Forum: Scripting
Topic: EOIP + IPSEC Update Local IP
Replies: 2
Views: 671

Re: EOIP + IPSEC Update Local IP

When you setup EOIP... You have to have an entry for Local IP and Far IP. You can place the IP cloud information in the tunnel config. However... the LOCAL IP will RESOLVE AT THE TIME you OK the tunnel. So if the local address changes... the tunnel's encryption will fail. This will update the local ...
by gotsprings
Thu Mar 21, 2019 5:08 am
Forum: Scripting
Topic: Script & Schedule for Network on & off [SOLVED]
Replies: 8
Views: 1406

Re: Script & Schedule for Network on & off [SOLVED]

Connect a client and it will turn black?
by gotsprings
Tue Mar 19, 2019 1:43 pm
Forum: Scripting
Topic: EOIP + IPSEC Update Local IP
Replies: 2
Views: 671

EOIP + IPSEC Update Local IP

Needed this the other day. In Eoip Tunnel you can define the far point (remote-address) to use IPCloud. But the local address does not. This will grab the local WAN IP and add it to a EoIP tunnel with the word "Tunnel" in the name. /system script add dont-require-permissions=no name=EoipUpdate owner...
by gotsprings
Tue Mar 19, 2019 1:33 pm
Forum: Scripting
Topic: How to really make backups (by script) ?
Replies: 15
Views: 2011

Re: How to really make backups (by script) ?

I always hated the fact that people could easily steal you scripts with passwords in them. (dyndns)
by gotsprings
Mon Mar 18, 2019 3:53 pm
Forum: Scripting
Topic: Script & Schedule for Network on & off [SOLVED]
Replies: 8
Views: 1406

Re: Script & Schedule for Network on & off [SOLVED]

Figured this out when I was working on caps-man. When you have to disable the SSID across more than one radio... that code made life much easier.
by gotsprings
Fri Mar 15, 2019 9:53 pm
Forum: Scripting
Topic: Script & Schedule for Network on & off [SOLVED]
Replies: 8
Views: 1406

Re: Script & Schedule for Network on & off [SOLVED]

Then this would kill it :log info "Turning OFF Training." /interface disable [find name~"Training"] :log info "Training DOWN." This would bring it back up. :log info "Turning ON Training." /interface enable [find name~"Training"] :log info "Training UP." You can get fancy with if then and time of da...
by gotsprings
Fri Mar 15, 2019 2:25 pm
Forum: Scripting
Topic: Script & Schedule for Network on & off [SOLVED]
Replies: 8
Views: 1406

Re: Script & Schedule for Network on & off [SOLVED]

You could do this several ways...
A simple way to "learn" or "start" would be to make 2 scripts and 2 schedules.
One enables the INTERFACES
One disables the INTERFACES

What are the names of the virtual interfaces?
by gotsprings
Fri Mar 15, 2019 2:59 am
Forum: General
Topic: 6.44.1 Broke Stuff Need to Downgrade to 6.44
Replies: 4
Views: 896

Re: 6.44.1 Broke Stuff Need to Downgrade to 6.44

The device is not properly setting connections as new then established. So it flags the connection as invalid. Then the router drops it on the next pass at invalid or dumps it on my drop all.

Been using this firewall for a couple of years now. This is new behavior.
by gotsprings
Fri Mar 15, 2019 1:21 am
Forum: General
Topic: 6.44.1 Broke Stuff Need to Downgrade to 6.44
Replies: 4
Views: 896

6.44.1 Broke Stuff Need to Downgrade to 6.44

Updated a CCR1009 and hAP AC2 from 6.44 to 6.44.1 Lots of connections are suddenly getting dropped by my DROP INVALID Forwarding rule. Pings between the 2 routers on VPN show timeouts that never did before. How can I downgrade and hAP AC when the Files Directory doesn't show enough space to put in t...
by gotsprings
Fri Mar 15, 2019 12:00 am
Forum: General
Topic: ROS 6.44 - VPN L2TP not working
Replies: 26
Views: 11265

Re: ROS 6.44 - VPN L2TP not working

Upgrading 6.44.1 broke my firewall forwarding chains.
by gotsprings
Thu Mar 14, 2019 10:38 pm
Forum: Announcements
Topic: v6.44.1 [stable] is released!
Replies: 86
Views: 25931

Re: v6.44.1 [stable] is released!

Updated hAP AC2 and CCR1009 from 6.44 to 6.44.1 I am seeing a lot of dropped Forwarded packets as INVALID. These are packets that should have hit the New connection from a local device in the address list. But are getting dropped. Also IPSEC connection between offices is now dropping pings. Call fro...
by gotsprings
Thu Mar 14, 2019 2:38 am
Forum: General
Topic: Harpin NAT between two VLANs
Replies: 34
Views: 2326

Re: Harpin NAT between two VLANs

I don't know why people always use in-interface for port forwarding, it will bite them sooner or later. :) Because they saw it in some youtube tutorial, which was made on basis of having dynamic WAN address (e.g. PPPoE or DHCP) ... and if that's so, one can not really use dst-address as dst-nat cri...
by gotsprings
Wed Mar 13, 2019 3:50 am
Forum: General
Topic: Harpin NAT between two VLANs
Replies: 34
Views: 2326

Re: Harpin NAT between two VLANs

No in interface.

The external IP is what you need.
A separate rule deals with local-address list to local-address list on Local interface.
by gotsprings
Tue Mar 12, 2019 8:56 pm
Forum: General
Topic: Harpin NAT between two VLANs
Replies: 34
Views: 2326

Re: Harpin NAT between two VLANs

Gotta use the EXTERNAL IP... interface won't do it.

Like SOB put it...
/ip firewall nat
add chain=dstnat dst-address=<public IP> protocol=tcp dst-port=80,443 action=dst-nat to-adresses=192.168.100.x

PUBLIC IP.
by gotsprings
Tue Mar 12, 2019 1:35 pm
Forum: General
Topic: Harpin NAT between two VLANs
Replies: 34
Views: 2326

Re: Harpin NAT between two VLANs

If you mean the srcnat rule with same src/dst-address=<LAN subnet>/<mask> used with hairpin NAT, that's not needed here. It's needed when client thinks that it communicates with some external address, but server would see client's real address from same subnet, would reply directly and that would n...
by gotsprings
Tue Mar 12, 2019 5:17 am
Forum: General
Topic: Harpin NAT between two VLANs
Replies: 34
Views: 2326

Re: Harpin NAT between two VLANs

If you go lazy and do the DNS thing... You can only port forward to one IP. Not good if you have different services on different devices.

Sob left out the
Subenet back on subnet on interface rule.
by gotsprings
Mon Mar 11, 2019 11:45 pm
Forum: General
Topic: Harpin NAT between two VLANs
Replies: 34
Views: 2326

Re: Harpin NAT between two VLANs

Export your
/IP firewall nat
by gotsprings
Mon Mar 11, 2019 3:19 am
Forum: General
Topic: Ring hardware and Mikrotik [SOLVED]
Replies: 6
Views: 1525

Re: Ring hardware and Mikrotik [SOLVED]

I'm using CAPSMAN and set Group-key-update to 01:00:00 and have had no luck with 2 doorbells. aes and WAP WPA2 on with now a shorter 8 character password. No issues connecting with any other device. Anyone else have experience? The device says has a problem connecting to the Internet. Seems like it...
by gotsprings
Sun Mar 10, 2019 7:31 pm
Forum: RouterBOARD hardware
Topic: Sierra MC7455 solutions?
Replies: 4
Views: 1228

Re: Sierra MC7455 solutions?

The MoFi is averaging around 30M downloads sitting on my desk.
by gotsprings
Sun Mar 03, 2019 6:21 pm
Forum: RouterBOARD hardware
Topic: Sierra MC7455 solutions?
Replies: 4
Views: 1228

Sierra MC7455 solutions?

I got a wAP R-LTE US Kit. Got it working but some US frequencies seem to be missing. I like the form factor... but would really prefer having access to the US bands that i can with the https://www.sierrawireless.com/products-and-solutions/embedded-solutions/products/mc7455/ I bought a MoFi 4500 and ...
by gotsprings
Mon Feb 25, 2019 6:13 am
Forum: Wireless Networking
Topic: wAP LTE US - Carriers?
Replies: 21
Views: 3690

Re: wAP LTE US - Carriers?

Thanks for the replies. No Verizon coverage is going to be a deal breaker for me, so I ordered a Sierra Wireless MC7455 card. Will RouterOS recognize this, or is there a way to install drivers? Kind of late... But that same wAP LTE KIT-US I used on T-Mobile. Is now running on Verizon wireless. I ha...
by gotsprings
Sat Feb 23, 2019 5:12 pm
Forum: RouterBOARD hardware
Topic: 3rd party LTE modems known working?
Replies: 11
Views: 1765

Re: 3rd party LTE modems known working?

I never tried with the M2M plans from T-Mobile. I only did a prepaid plan for proof of concept. It showed me that I would have to mount the wAP R OUTSIDE to get a signal with T-Mobile. Keeping that in my back pocket for the next time one client I know of on AutoPay screws up his verizon account again.
by gotsprings
Fri Feb 22, 2019 8:35 pm
Forum: RouterBOARD hardware
Topic: 3rd party LTE modems known working?
Replies: 11
Views: 1765

Re: 3rd party LTE modems known working?

I need a steady stream of packets that end up being ~4-6GB The $10 2GB plan just doesn't cut it and the 6GB plan is too expensive. M2M SIMs are a perfect fit, if I can find a modem that is allowed on that network and is mikrotik compatible. You need 4-6Gigs a month and $25 is too much? Wow. I stumb...
by gotsprings
Fri Feb 22, 2019 8:09 pm
Forum: General
Topic: Public-Mikrotik-Bandwidth-Test-Server(s)
Replies: 622
Views: 523088

Re: Public-Mikrotik-Bandwidth-Test-Server(s)

Info - I just updated the 207.32.194.24 btest server from 6.43.11 to 6.43.12

North Idaho Tom Jones
THANK YOU!!!
by gotsprings
Tue Feb 19, 2019 5:15 pm
Forum: RouterBOARD hardware
Topic: 3rd party LTE modems known working?
Replies: 11
Views: 1765

Re: 3rd party LTE modems known working?

T-Mobile’s M2M service doesn’t work though. It’s imei filtered and the mikrotik LTE card isn’t on the approved list.
So get the $10 a month plan?

https://prepaid.t-mobile.com/plan-detai ... e-internet
by gotsprings
Tue Feb 19, 2019 12:47 pm
Forum: RouterBOARD hardware
Topic: 3rd party LTE modems known working?
Replies: 11
Views: 1765

Re: 3rd party LTE modems known working?

https://mikrotik.com/product/wap_lte_kit_us I can confirm that this unit works with T-Mobile in the US. I had to set the APN to /interface lte apn add apn=fast.t-mobile.com default-route-distance=1 passthrough-interface=\ ether1 passthrough-mac=auto add apn=fast.t-mobile.com default-route-distance=1...
by gotsprings
Tue Feb 19, 2019 12:16 pm
Forum: Wireless Networking
Topic: Problem with 5GHz frequency - CAPsMAN
Replies: 7
Views: 2363

Re: Problem with 5GHz frequency - CAPsMAN

/caps-man channel
add band=5ghz-a/n/ac control-channel-width=20mhz extension-channel=Ceee \
    frequency=5180 name="Channel 36 80mhz"
    
Try that
by gotsprings
Fri Feb 15, 2019 4:44 pm
Forum: RouterBOARD hardware
Topic: RouterBOARD wAP R-2nD Winbox From WAN
Replies: 2
Views: 754

Re: RouterBOARD wAP R-2nD Winbox From WAN

After bunches of emails and support files... I got nothing.

Switched out unit to a MoFi modem feeding a hAP AC2. No Problem with remote connection.