Community discussions

Search found 661 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 14
by gotsprings
Tue Mar 19, 2019 1:43 pm
Forum: Scripting
Topic: EOIP + IPSEC Update Local IP
Replies: 0
Views: 24

EOIP + IPSEC Update Local IP

Needed this the other day. In Eoip Tunnel you can define the far point (remote-address) to use IPCloud. But the local address does not. This will grab the local WAN IP and add it to a EoIP tunnel with the word "Tunnel" in the name. /system script add dont-require-permissions=no name=EoipUpdate owner...
by gotsprings
Tue Mar 19, 2019 1:33 pm
Forum: Scripting
Topic: How to really make backups (by script) ?
Replies: 15
Views: 493

Re: How to really make backups (by script) ?

I always hated the fact that people could easily steal you scripts with passwords in them. (dyndns)
by gotsprings
Mon Mar 18, 2019 3:53 pm
Forum: Scripting
Topic: Script & Schedule for Network on & off [SOLVED]
Replies: 6
Views: 219

Re: Script & Schedule for Network on & off [SOLVED]

Figured this out when I was working on caps-man. When you have to disable the SSID across more than one radio... that code made life much easier.
by gotsprings
Fri Mar 15, 2019 9:53 pm
Forum: Scripting
Topic: Script & Schedule for Network on & off [SOLVED]
Replies: 6
Views: 219

Re: Script & Schedule for Network on & off [SOLVED]

Then this would kill it :log info "Turning OFF Training." /interface disable [find name~"Training"] :log info "Training DOWN." This would bring it back up. :log info "Turning ON Training." /interface enable [find name~"Training"] :log info "Training UP." You can get fancy with if then and time of da...
by gotsprings
Fri Mar 15, 2019 2:25 pm
Forum: Scripting
Topic: Script & Schedule for Network on & off [SOLVED]
Replies: 6
Views: 219

Re: Script & Schedule for Network on & off [SOLVED]

You could do this several ways...
A simple way to "learn" or "start" would be to make 2 scripts and 2 schedules.
One enables the INTERFACES
One disables the INTERFACES

What are the names of the virtual interfaces?
by gotsprings
Fri Mar 15, 2019 2:59 am
Forum: General
Topic: 6.44.1 Broke Stuff Need to Downgrade to 6.44
Replies: 4
Views: 362

Re: 6.44.1 Broke Stuff Need to Downgrade to 6.44

The device is not properly setting connections as new then established. So it flags the connection as invalid. Then the router drops it on the next pass at invalid or dumps it on my drop all.

Been using this firewall for a couple of years now. This is new behavior.
by gotsprings
Fri Mar 15, 2019 1:21 am
Forum: General
Topic: 6.44.1 Broke Stuff Need to Downgrade to 6.44
Replies: 4
Views: 362

6.44.1 Broke Stuff Need to Downgrade to 6.44

Updated a CCR1009 and hAP AC2 from 6.44 to 6.44.1 Lots of connections are suddenly getting dropped by my DROP INVALID Forwarding rule. Pings between the 2 routers on VPN show timeouts that never did before. How can I downgrade and hAP AC when the Files Directory doesn't show enough space to put in t...
by gotsprings
Fri Mar 15, 2019 12:00 am
Forum: General
Topic: ROS 6.44 - VPN L2TP not working
Replies: 20
Views: 1146

Re: ROS 6.44 - VPN L2TP not working

Upgrading 6.44.1 broke my firewall forwarding chains.
by gotsprings
Thu Mar 14, 2019 10:38 pm
Forum: Announcements
Topic: v6.44.1 [stable] is released!
Replies: 52
Views: 6036

Re: v6.44.1 [stable] is released!

Updated hAP AC2 and CCR1009 from 6.44 to 6.44.1 I am seeing a lot of dropped Forwarded packets as INVALID. These are packets that should have hit the New connection from a local device in the address list. But are getting dropped. Also IPSEC connection between offices is now dropping pings. Call fro...
by gotsprings
Thu Mar 14, 2019 2:38 am
Forum: General
Topic: Harpin NAT between two VLANs
Replies: 34
Views: 858

Re: Harpin NAT between two VLANs

I don't know why people always use in-interface for port forwarding, it will bite them sooner or later. :) Because they saw it in some youtube tutorial, which was made on basis of having dynamic WAN address (e.g. PPPoE or DHCP) ... and if that's so, one can not really use dst-address as dst-nat cri...
by gotsprings
Wed Mar 13, 2019 3:50 am
Forum: General
Topic: Harpin NAT between two VLANs
Replies: 34
Views: 858

Re: Harpin NAT between two VLANs

No in interface.

The external IP is what you need.
A separate rule deals with local-address list to local-address list on Local interface.
by gotsprings
Tue Mar 12, 2019 8:56 pm
Forum: General
Topic: Harpin NAT between two VLANs
Replies: 34
Views: 858

Re: Harpin NAT between two VLANs

Gotta use the EXTERNAL IP... interface won't do it.

Like SOB put it...
/ip firewall nat
add chain=dstnat dst-address=<public IP> protocol=tcp dst-port=80,443 action=dst-nat to-adresses=192.168.100.x

PUBLIC IP.
by gotsprings
Tue Mar 12, 2019 1:35 pm
Forum: General
Topic: Harpin NAT between two VLANs
Replies: 34
Views: 858

Re: Harpin NAT between two VLANs

If you mean the srcnat rule with same src/dst-address=<LAN subnet>/<mask> used with hairpin NAT, that's not needed here. It's needed when client thinks that it communicates with some external address, but server would see client's real address from same subnet, would reply directly and that would n...
by gotsprings
Tue Mar 12, 2019 5:17 am
Forum: General
Topic: Harpin NAT between two VLANs
Replies: 34
Views: 858

Re: Harpin NAT between two VLANs

If you go lazy and do the DNS thing... You can only port forward to one IP. Not good if you have different services on different devices.

Sob left out the
Subenet back on subnet on interface rule.
by gotsprings
Mon Mar 11, 2019 11:45 pm
Forum: General
Topic: Harpin NAT between two VLANs
Replies: 34
Views: 858

Re: Harpin NAT between two VLANs

Export your
/IP firewall nat
by gotsprings
Mon Mar 11, 2019 3:19 am
Forum: General
Topic: Ring hardware and Mikrotik [SOLVED]
Replies: 6
Views: 616

Re: Ring hardware and Mikrotik [SOLVED]

I'm using CAPSMAN and set Group-key-update to 01:00:00 and have had no luck with 2 doorbells. aes and WAP WPA2 on with now a shorter 8 character password. No issues connecting with any other device. Anyone else have experience? The device says has a problem connecting to the Internet. Seems like it...
by gotsprings
Sun Mar 10, 2019 7:31 pm
Forum: RouterBOARD hardware
Topic: Sierra MC7455 solutions?
Replies: 2
Views: 180

Re: Sierra MC7455 solutions?

The MoFi is averaging around 30M downloads sitting on my desk.
by gotsprings
Sun Mar 03, 2019 6:21 pm
Forum: RouterBOARD hardware
Topic: Sierra MC7455 solutions?
Replies: 2
Views: 180

Sierra MC7455 solutions?

I got a wAP R-LTE US Kit. Got it working but some US frequencies seem to be missing. I like the form factor... but would really prefer having access to the US bands that i can with the https://www.sierrawireless.com/products-and-solutions/embedded-solutions/products/mc7455/ I bought a MoFi 4500 and ...
by gotsprings
Mon Feb 25, 2019 6:13 am
Forum: Wireless Networking
Topic: wAP LTE US - Carriers?
Replies: 5
Views: 745

Re: wAP LTE US - Carriers?

Thanks for the replies. No Verizon coverage is going to be a deal breaker for me, so I ordered a Sierra Wireless MC7455 card. Will RouterOS recognize this, or is there a way to install drivers? Kind of late... But that same wAP LTE KIT-US I used on T-Mobile. Is now running on Verizon wireless. I ha...
by gotsprings
Sat Feb 23, 2019 5:12 pm
Forum: RouterBOARD hardware
Topic: 3rd party LTE modems known working?
Replies: 11
Views: 618

Re: 3rd party LTE modems known working?

I never tried with the M2M plans from T-Mobile. I only did a prepaid plan for proof of concept. It showed me that I would have to mount the wAP R OUTSIDE to get a signal with T-Mobile. Keeping that in my back pocket for the next time one client I know of on AutoPay screws up his verizon account again.
by gotsprings
Fri Feb 22, 2019 8:35 pm
Forum: RouterBOARD hardware
Topic: 3rd party LTE modems known working?
Replies: 11
Views: 618

Re: 3rd party LTE modems known working?

I need a steady stream of packets that end up being ~4-6GB The $10 2GB plan just doesn't cut it and the 6GB plan is too expensive. M2M SIMs are a perfect fit, if I can find a modem that is allowed on that network and is mikrotik compatible. You need 4-6Gigs a month and $25 is too much? Wow. I stumb...
by gotsprings
Fri Feb 22, 2019 8:09 pm
Forum: General
Topic: Public-Mikrotik-Bandwidth-Test-Server(s)
Replies: 510
Views: 335154

Re: Public-Mikrotik-Bandwidth-Test-Server(s)

Info - I just updated the 207.32.194.24 btest server from 6.43.11 to 6.43.12

North Idaho Tom Jones
THANK YOU!!!
by gotsprings
Tue Feb 19, 2019 5:15 pm
Forum: RouterBOARD hardware
Topic: 3rd party LTE modems known working?
Replies: 11
Views: 618

Re: 3rd party LTE modems known working?

T-Mobile’s M2M service doesn’t work though. It’s imei filtered and the mikrotik LTE card isn’t on the approved list.
So get the $10 a month plan?

https://prepaid.t-mobile.com/plan-detai ... e-internet
by gotsprings
Tue Feb 19, 2019 12:47 pm
Forum: RouterBOARD hardware
Topic: 3rd party LTE modems known working?
Replies: 11
Views: 618

Re: 3rd party LTE modems known working?

https://mikrotik.com/product/wap_lte_kit_us I can confirm that this unit works with T-Mobile in the US. I had to set the APN to /interface lte apn add apn=fast.t-mobile.com default-route-distance=1 passthrough-interface=\ ether1 passthrough-mac=auto add apn=fast.t-mobile.com default-route-distance=1...
by gotsprings
Tue Feb 19, 2019 12:16 pm
Forum: Wireless Networking
Topic: Problem with 5GHz frequency - CAPsMAN
Replies: 5
Views: 315

Re: Problem with 5GHz frequency - CAPsMAN

/caps-man channel
add band=5ghz-a/n/ac control-channel-width=20mhz extension-channel=Ceee \
    frequency=5180 name="Channel 36 80mhz"
    
Try that
by gotsprings
Fri Feb 15, 2019 4:44 pm
Forum: RouterBOARD hardware
Topic: RouterBOARD wAP R-2nD Winbox From WAN
Replies: 2
Views: 290

Re: RouterBOARD wAP R-2nD Winbox From WAN

After bunches of emails and support files... I got nothing.

Switched out unit to a MoFi modem feeding a hAP AC2. No Problem with remote connection.
by gotsprings
Wed Feb 13, 2019 4:06 am
Forum: General
Topic: Ring hardware and Mikrotik [SOLVED]
Replies: 6
Views: 616

Re: Ring hardware and Mikrotik [SOLVED]

I have a hAP AC2 running as just a wireless access point. I have a ring connected to it on 5.0 Ghz. No real problems keeping it connected. I have the group key at 5 mins. WPA2 AES. Its been on for about 45 days now.
by gotsprings
Mon Feb 11, 2019 8:01 pm
Forum: General
Topic: Need a bit of help with VPN + additional info/question
Replies: 3
Views: 262

Re: Need a bit of help with VPN + additional info/question

Well then you need to resolve those IPs and punch them in on changes.
"Scripting"
by gotsprings
Mon Feb 11, 2019 6:55 pm
Forum: Wireless Networking
Topic: One SSID with Access-list mode
Replies: 4
Views: 240

Re: One SSID with Access-list mode

Seems you would want a SSID and ports per apartment. Then have the "public SSID" run across all the hardware?
by gotsprings
Mon Feb 11, 2019 6:38 pm
Forum: General
Topic: Need a bit of help with VPN + additional info/question
Replies: 3
Views: 262

Re: Need a bit of help with VPN + additional info/question

If one of the routers lacks a public IP... connect that one using L2TP then setup a encryption inside that connection.
by gotsprings
Mon Feb 11, 2019 5:19 pm
Forum: Wireless Networking
Topic: SXT LTE query
Replies: 4
Views: 273

Re: SXT LTE query

I mean I bought a static public IP so I could reach the device remotely.

Works with Cradlepoint as a modem to a TIk.

But using the Mikrotik wAP LTE as modem and router... It's showing the one IP as the IP and the gateway. A remote connection hits then drops. Makes my remote management a problem.
by gotsprings
Mon Feb 11, 2019 12:54 pm
Forum: Wireless Networking
Topic: Automatically connect to best signal AP
Replies: 2
Views: 327

Re: Automatically connect to best signal AP

/interface wireless security-profiles

Then you need to select the security profile for each wireless network you want to connect to.
by gotsprings
Mon Feb 11, 2019 12:43 pm
Forum: Wireless Networking
Topic: Wireless Wire - expected throughput?
Replies: 8
Views: 674

Re: Wireless Wire - expected throughput?

Got 975M on my tests over short distances. But a difference being that the line of site MEANS line of site. Off axis the throughput disappeared completely even at short range. So AIM and a clean LOS is key.
by gotsprings
Mon Feb 11, 2019 12:39 pm
Forum: Wireless Networking
Topic: SXT LTE query
Replies: 4
Views: 273

Re: SXT LTE query

If its anything like the wAP LTE I am testing... its meant to work like a cellular modem. The one I am testing has problems with the gateway its picking up. So it not allowing remote connections. Making it unsuitable for the application I was planning for it. I emailed support and am looking for a C...
by gotsprings
Sat Feb 09, 2019 9:59 pm
Forum: RouterBOARD hardware
Topic: RouterBOARD wAP R-2nD Winbox From WAN
Replies: 2
Views: 290

Re: RouterBOARD wAP R-2nD Winbox From WAN

I found out that when the wAP LTE connects to the cellular provider (Verizon) it does get the Static IP From the ISP. Problem is that it gets the static IP and doesn't set a gateway that is one number higher than the static IP. Cradlepoints receive the IP from Verizon and show the IP as /29 IP = xxx...
by gotsprings
Thu Feb 07, 2019 11:35 pm
Forum: RouterBOARD hardware
Topic: RouterBOARD wAP R-2nD Winbox From WAN
Replies: 2
Views: 290

RouterBOARD wAP R-2nD Winbox From WAN

I am testing a wAP R-2nD as a replacement for our CradlePoint installs. I have the unit configured like a home router with wireless 2.4 bridged to the ethernet port and LTE modem setup as the WAN. I can reach the internet and browse normally. However i noticed that I can't get winbox to load when I ...
by gotsprings
Wed Jan 30, 2019 10:16 pm
Forum: Beginner Basics
Topic: Portforwarding not workin over pppoe
Replies: 3
Views: 182

Re: Portforwarding not workin over pppoe

Copy and past this whole thing in a New Terminal Window using RIGHT CLICK (Your mouse buttons) Copy and Paste. DO NOT USE CTRL+C and CTRL+P /ip cloud set ddns-enabled=yes /ip firewall address-list add address=192.168.88.0/24 list=GotSprings /ip firewall nat add action=masquerade chain=srcnat comment...
by gotsprings
Wed Jan 30, 2019 9:58 pm
Forum: Wireless Networking
Topic: Looking for a mikrotik router Model that supports DNAT
Replies: 8
Views: 477

Re: Looking for a mikrotik router Model that supports DNAT

Something like /ip firewall nat add action=dst-nat chain=dstnat comment="Redirect Guest DNS" dst-address=!192.168.x.x \ dst-port=53 protocol=udp src-address-list=Local to-addresses=192.168.x.x and mkv was correct. have the dhcp server tell the clients to use your piehole... (Kind of sounds rude when...
by gotsprings
Mon Jan 28, 2019 9:00 pm
Forum: Beginner Basics
Topic: Portforwarding not workin over pppoe
Replies: 3
Views: 182

Re: Portforwarding not workin over pppoe

That rule doesn't look like it is meant for external connections. add action=dst-nat chain=dstnat dst-port=81 in-interface=bridge protocol=tcp \ to-addresses=192.168.88.1 to-ports=80 That rule would take a request on port 81 coming from the bridge (Local interface) and forward it to 192.168.88.1 por...
by gotsprings
Mon Jan 28, 2019 8:34 pm
Forum: Beginner Basics
Topic: Route all traffic through NordVPN?
Replies: 17
Views: 3624

Re: Route all traffic through NordVPN?

OVPN has not worked on port 1194 for about 10 years now.

Also as for using those VPN services to "side step" geolocation... providers update their blacklists from time to time too.
by gotsprings
Mon Jan 28, 2019 7:16 pm
Forum: Wireless Networking
Topic: Looking for a mikrotik router Model that supports DNAT
Replies: 8
Views: 477

Re: Looking for a mikrotik router Model that supports DNAT

I'm using DHCP-Server option 6 to forward all DHCP clients DNS to the PI-Hole server. /ip dhcp-server option print # NAME CODE VALUE RAW-VALUE 0 PIHole 6 '192.168.x.x' c0a80032 Where 192.168.x.x is the PI-Hole address. Would be even easier to put it in /ip dhcp-server network add address=192.168.2....
by gotsprings
Mon Jan 28, 2019 4:14 pm
Forum: General
Topic: VPN Issue
Replies: 1
Views: 158

Re: VPN Issue

/ip firewall filter
export
by gotsprings
Mon Jan 28, 2019 4:13 pm
Forum: Wireless Networking
Topic: Mikrotik AP & Switch Question's [SOLVED]
Replies: 5
Views: 390

Re: Mikrotik AP & Switch Question's [SOLVED]

Thanks Guys Wish I would Have found MikroTIK be for I started buying Cisco. Not that there is any thing wrong with cisco.
Maybe I may Ebay my Switch's and pick up a 48Port Poe MikroTiK
There are no 48 port Mikrotik switches.

So your Cisco makes sense.
by gotsprings
Mon Jan 28, 2019 4:09 pm
Forum: Wireless Networking
Topic: CAPsMAN unable to manage its own Wireless interface
Replies: 16
Views: 2241

Re: CAPsMAN unable to manage its own Wireless interface

Had this working for several months now.

hAP AC2 is the main router and I wanted to add it to the cap config that it is running three cAP AC.
/interface wireless cap
set certificate=request discovery-interfaces=bridge enabled=yes interfaces=wlan1,wlan2
by gotsprings
Mon Jan 28, 2019 3:23 pm
Forum: Wireless Networking
Topic: Looking for a mikrotik router Model that supports DNAT
Replies: 8
Views: 477

Re: Looking for a mikrotik router Model that supports DNAT

pihole is a local dns server right?

You would set the dhcp-server to handout the pihole address to clients.

Then set up a rule to capture anything on port 53 and send it to your pihole server.

Any Tik should be able to do this.
by gotsprings
Wed Jan 23, 2019 9:59 pm
Forum: Wireless Networking
Topic: Cap AC, Hap AC2 or UniFi?
Replies: 30
Views: 5032

Re: Cap AC, Hap AC2 or UniFi?

Guys what can you say about roaming capability? Is this implemented in unifi is far better than mikrotik ones? Im consider which implement in my house.

Wysłane z mojego HTC 10 przy użyciu Tapatalka
Caps-Man can be MUCH MORE GRANULAR.
by gotsprings
Thu Jan 10, 2019 10:17 am
Forum: Wireless Networking
Topic: Cap AC, Hap AC2 or UniFi?
Replies: 30
Views: 5032

Re: Cap AC, Hap AC2 or UniFi?

The cAP AC and hAP AC2 top out right around 300 at point blank range. But the R510 will actually hit the 866M you should get from a 2x2 AC-MU radio. True, but this is coming at four times the price of a cAP AC/Unifi AC Lite making the comparison unrealistic. Like said by someone else, it is all abo...
by gotsprings
Tue Jan 08, 2019 11:58 pm
Forum: Wireless Networking
Topic: Cap AC, Hap AC2 or UniFi?
Replies: 30
Views: 5032

Re: Cap AC, Hap AC2 or UniFi?


Quite happy with the performance of the capAC inside the home but range in 5Ghz is markedly and expectedly less than 2.4ghz.
That's pretty typical of 5GHZ. It is faster, but doesn't go through much, or very far.
by gotsprings
Tue Jan 08, 2019 11:28 am
Forum: RouterBOARD hardware
Topic: RB4011 wireless performance?
Replies: 24
Views: 1863

Re: RB4011 wireless performance?

How many AP's do you plan to install? aside from a singular AP performance, it's probably more relevant to assess the controller function and features along with the radio performance. The controller function and features along with the client compatibility unfortunately go hard against mtk enterpr...
by gotsprings
Sat Jan 05, 2019 11:03 pm
Forum: RouterBOARD hardware
Topic: RB4011 wireless performance?
Replies: 24
Views: 1863

Re: RB4011 wireless performance?

At this moment bad, we tested 3 Intel Based AC Laptops and both are only able to connect to 54 MBit..... Kind of seems "par" for Mikrotik with wireless devices. They release them and it takes several months and routerOS/firmwares before they start showing acceptable results. I went through that wit...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 14