Community discussions

Search found 119 matches

by ebreyit
Mon Aug 05, 2019 12:04 pm
Forum: General
Topic: PWR-Line AP
Replies: 48
Views: 8234

Re: PWR-Line AP

I like that you've finally gone with a clover leaf power connector rather than a country specific plug, makes for easy use in all countries without a specific socket version. Puzzled why you left out RouterOS, as mentioned it has so many possibilities. My wish list for future expansion on this would...
by ebreyit
Wed Apr 03, 2019 3:05 pm
Forum: Beginner Basics
Topic: TVIP / IGMP help required please
Replies: 9
Views: 956

Re: TVIP / IGMP help required please

Previous info I have posted on the topic here https://forum.mikrotik.com/viewtopic.php?t=119226#p587497 I have used this with a number of YouView boxes on TalkTalk and BT. It might be that your missing the Multicast group IP's rule in your firewall. Post you full config from an export here instead o...
by ebreyit
Wed Mar 20, 2019 9:44 pm
Forum: RouterBOARD hardware
Topic: LoRaWAN support
Replies: 42
Views: 7848

Re: LoRaWAN support

viewtopic.php?f=2&t=146240
&
https://www.thethingsnetwork.org/forum/ ... eway/23612


[/quote]

so where is more info about the pic....
[/quote]
by ebreyit
Wed Mar 20, 2019 5:12 pm
Forum: General
Topic: Mikrotik User Meeting 2019 Vienna report - ENGLISH SUBTITLES
Replies: 6
Views: 1217

Re: Mikrotik User Meeting 2019 Vienna report - ENGLISH SUBTITLES

Might be good to see a unit come out with GPS built in as well, plus maybe an extra mPCIe slot which could support LTE or additional WiFi (e.g. 5GHz) That would be very useful for shorter term/ad hoc deployments and other scenarios. The GPS would ensure the IOT network would always know the correct ...
by ebreyit
Thu Feb 21, 2019 12:52 am
Forum: Wireless Networking
Topic: CAPsMan Wifi - Prevent network scan
Replies: 4
Views: 504

Re: CAPsMan Wifi - Prevent network scan

How many caps have you got connected..? /ip address add address=192.168.111.1/24 interface=ether2 network=192.168.111.0 That should be on bridge1 as ether2 is a bridge port Try using bridge split horizon instead of bridge firewall to isolate ports. Any bridge port with a split horizon can only commu...
by ebreyit
Wed Feb 20, 2019 11:22 am
Forum: Wireless Networking
Topic: CAPsMan Wifi - Prevent network scan
Replies: 4
Views: 504

Re: CAPsMan Wifi - Prevent network scan

Hi, Drop your config here so we can take a look to see what's going on. It might be that on that specific AP clients can't see each other, but, it's able to see other clients on the same L2 segment (clients on other AP's) if bridge horizon or another form of isolation is not employed. This can happe...
by ebreyit
Tue Jan 29, 2019 6:28 pm
Forum: General
Topic: PWR-Line AP
Replies: 48
Views: 8234

Re: PWR-Line AP

I've just contacted one of my distributors regarding availability and delivery in the UK. I was told that this product won't be coming to the UK as Mikrotik have no interest in marketing this product in the UK. Can someone from Mikrotik please confirm if this is the case? I've repeatedly asked for ...
by ebreyit
Mon Sep 17, 2018 12:05 pm
Forum: Beginner Basics
Topic: CCR1009-8G-1S-1S+, Smart card and Certificates
Replies: 10
Views: 3983

Re: CCR1009-8G-1S-1S+, Smart card and Certificates

Here's some info that I've found Going to order one of the SmartCafe and ACOSJ Cards once the supplier has some in to try and will post the results. Would be nice if Mikrotik could provide some more information such as any cards they've tested along with any Java Card/GlobalPlatform minimum version ...
by ebreyit
Fri Jun 22, 2018 11:35 am
Forum: General
Topic: IPsec Hardware acceleration on CHR?
Replies: 9
Views: 1867

Re: IPsec Hardware acceleration on CHR?

server CPU supports AES-NI? Xeon D-1541 ( https://ark.intel.com/products/91199/Intel-Xeon-Processor-D-1541-12M-Cache-2_10-GHz ) ESXI extension pass-through is not disabled Image attached of CPU-Z running on a guest in the same Host showing the AES-NI Also I'm assuming that if GCM has been hardware ...
by ebreyit
Fri Jun 22, 2018 1:24 am
Forum: Beginner Basics
Topic: Trying to change a cheap TP-Link router for a cheap MikroTik one
Replies: 22
Views: 2259

Re: Trying to change a cheap TP-Link router for a cheap MikroTik one

Please post config here

One possible omission is forgetting to add a NAT rule
by ebreyit
Fri Jun 22, 2018 12:28 am
Forum: General
Topic: IPsec Hardware acceleration on CHR?
Replies: 9
Views: 1867

Re: IPsec Hardware acceleration on CHR?

Im seeing this also. ESXI V6 CHR RouterOS 6.42.4 If I set the proposal to aes-256 gcm I get the hardware flag and CPU stays low If I set it to aes-256 cbc or ctr then there is no hardware flag and CPU rises. Has anyone seen aes-265 ctr or cbc work on a CHR...? I'd like to get it running as I have a ...
by ebreyit
Fri Oct 27, 2017 6:06 pm
Forum: Wireless Networking
Topic: VLANS over wireless link
Replies: 4
Views: 623

Re: VLANS over wireless link

Provided the netmetals are set to AP Bridge and Station Bridge it will be transparent and VLAN's will cross it fine.
by ebreyit
Fri Oct 27, 2017 5:58 pm
Forum: General
Topic: Help! Upgrade blew away all my packages
Replies: 9
Views: 973

Re: Help! Upgrade blew away all my packages

I've had this happen on quite a few upgrades, especially going from 6.3x to 6.4x firmwares.

On some I've been able to downgrade, then re-upgrade has work correctly.

Cleanest fix is netinstall though.,
by ebreyit
Thu Oct 26, 2017 12:56 am
Forum: Beginner Basics
Topic: Need some help with a network design
Replies: 4
Views: 517

Re: Need some help with a network design

Are the cable modems just operating in bridge mode..? with the Mikrotik connecting to the internet using PPPoE. Essentially the Cable modems could all be connected to the Switch, each one given a different vlan and then all trunked over one physical ethernet to the Mikrotik. You would only then need...
by ebreyit
Wed Oct 18, 2017 3:19 pm
Forum: Beginner Basics
Topic: Help me stop MAC spoofing
Replies: 37
Views: 7653

Re: Help me stop MAC spoofing

yes i kinda understand now and yes its wifi-based . there are a lot of routers that you can't connect to when your MAC is changed it will always say that the wifi password is wrong even if its right. can we use that feature in Nano station ? it will be like the best thing to stop spoofing I think y...
by ebreyit
Tue Oct 17, 2017 6:01 pm
Forum: Beginner Basics
Topic: Using MikroTik AP with a different brand of router?
Replies: 3
Views: 532

Re: Using MikroTik AP with a different brand of router?

Hi, Try to describe in more detail the sort of setup/configuration you imagine. Mikrotik gear in most cases works fine with other vendors depending on what your trying to achieve. The 'lite' AP's only have a level 3 license, so unless you upgrade them to level 4 they can only be used as PtP bridges ...
by ebreyit
Sat Oct 07, 2017 2:05 pm
Forum: Beginner Basics
Topic: Help me stop MAC spoofing
Replies: 37
Views: 7653

Re: Help me stop MAC spoofing

I'm not sure a band aid based on a response from here is going to solve your problem. If this is causing you real issues, you need to spend some time thinking about your current strategy and do some research on a number of possible solutions to the security and accountability issues you are facing. ...
by ebreyit
Fri Oct 06, 2017 2:54 pm
Forum: General
Topic: New Outdoor Wi-Fi deployment
Replies: 5
Views: 608

Re: New Outdoor Wi-Fi deployment

How many clients
How far will the furthest client be from the pole
how far is each pole from each other
client bandwidth expectations
available bandwidth in your backhaul

the more information you give, the better informed the answer will be as there are so many variables and choices
by ebreyit
Fri Oct 06, 2017 2:01 pm
Forum: Beginner Basics
Topic: Help me stop MAC spoofing
Replies: 37
Views: 7653

Re: Help me stop MAC spoofing

Disable client forwarding on WiFi networks and use bridge horizon
by ebreyit
Tue Sep 26, 2017 12:49 am
Forum: General
Topic: Hotspot Redirection
Replies: 1
Views: 322

Re: Hotspot Redirection

Is there an issue with how it's configured now..?
by ebreyit
Tue Sep 26, 2017 12:48 am
Forum: General
Topic: Hotspot login redirection sometimes not working on clients - dns cache
Replies: 2
Views: 431

Re: Hotspot login redirection sometimes not working on clients - dns cache

Are you sure it's a DNS issue not clients trying to access https sites..? What's the exact message you see on the client devices.
by ebreyit
Sat Sep 23, 2017 10:43 pm
Forum: Beginner Basics
Topic: Block Websites but allow for some selected clients
Replies: 2
Views: 430

Re: Block Websites but allow for some selected clients

Use address lists and firewall rules, many examples in the forum
by ebreyit
Sat Sep 23, 2017 10:27 pm
Forum: Beginner Basics
Topic: mikrotik hotspot user login from other normal router [SOLVED]
Replies: 3
Views: 461

Re: mikrotik hotspot user login from other normal router [SOLVED]

Access for hotspot is based on Mac address and the only one the mikrotik can see is the WAN mac of the other routers.

If you need them to have unique access then they need to be on the layer 2 network created by the Mikrotik hotspot
by ebreyit
Wed Sep 20, 2017 12:02 pm
Forum: Beginner Basics
Topic: EoIP with public IP
Replies: 11
Views: 1596

Re: EoIP with public IP

Admin ports should not be directly open via Public IP.

Either use port knocking or a VPN to manage the router from the Internet
by ebreyit
Wed Sep 20, 2017 12:00 pm
Forum: Beginner Basics
Topic: User Manager
Replies: 8
Views: 881

Re: User Manager

As suggested, users get wise to enabling BitTorrent encryption etc which will make layer 7 efforts far less or completely in-effective, savvy users may even start to use VPN to hide the traffic You're better off approaching this from a QoS point of view, prioritising certain traffic leaving bulk tra...
by ebreyit
Fri Sep 15, 2017 2:45 pm
Forum: General
Topic: Block sites by list using Layer7 Protocol
Replies: 3
Views: 7871

Re: Block sites by list using Layer7 Protocol

Use Firewall Address List to drop traffic, not layer 7

viewtopic.php?f=13&t=71370&p=617829#p617829
by ebreyit
Thu Sep 14, 2017 7:01 pm
Forum: Beginner Basics
Topic: Blocking sites and other stuff
Replies: 1
Views: 427

Re: Blocking sites and other stuff

Firewall address list supports domain names and dynamically adds IP entry to same address list. Provided you use the Mikrotik as the DNS server it will always server up the same IP address/s of the specified domains and subsequently drop the traffic Add address to block as follows ip firewall addres...
by ebreyit
Thu Sep 14, 2017 6:54 pm
Forum: Beginner Basics
Topic: how to assign 2 Private IP address [SOLVED]
Replies: 3
Views: 482

Re: how to assign 2 Private IP address [SOLVED]

Assign the Addresses to the respective ports

Create a DHCP server on each port to distribute addresses in the relevant range

Create a firewall rule to drop traffic from each lan trying to access the other.
by ebreyit
Thu Sep 14, 2017 6:49 pm
Forum: Beginner Basics
Topic: one hotspot user gives access to all other devices [SOLVED]
Replies: 2
Views: 517

Re: one hotspot user gives access to all other devices [SOLVED]

ShadeOfSpirit sounds spot on to me. If the Alfa is acting as a router with NAT enabled then the Hotspot is only seeing the mac address of the Alfa device and allows Internet access to all traffic coming from that mac. I use this trick myself when away from home using one of the smaller RouterBoard d...
by ebreyit
Thu Sep 14, 2017 6:42 pm
Forum: Beginner Basics
Topic: Route all traffic down L2TP VPN
Replies: 9
Views: 6212

Re: Route all traffic down L2TP VPN

Also do a trace route to 8.8.8.8 from the pc and post results here
by ebreyit
Thu Sep 14, 2017 6:13 pm
Forum: Beginner Basics
Topic: Route all traffic down L2TP VPN
Replies: 9
Views: 6212

Re: Route all traffic down L2TP VPN

Export your config and drop a copy here.

Also do a tracert/traceroute from your PC to the VPN's IP and post the results here
by ebreyit
Thu Sep 14, 2017 4:09 pm
Forum: Beginner Basics
Topic: Route all traffic down L2TP VPN
Replies: 9
Views: 6212

Re: Route all traffic down L2TP VPN

This is a bit rough and ready and may contain mistakes but should point you in the right direction. This is also not the only way it could be done and may not be the best Add IP addresses you want to route via the VPN to an address list /ip firewall address-list add address=192.168.88.254 list=OutVp...
by ebreyit
Thu Sep 14, 2017 12:30 am
Forum: Beginner Basics
Topic: using SXT lite 5 in 5ghz
Replies: 1
Views: 302

Re: using SXT lite 5 in 5ghz

If it's able to connect to a 2.4GHz network then it's not an SXT lite 5..
by ebreyit
Thu Sep 14, 2017 12:17 am
Forum: Beginner Basics
Topic: Route all traffic down L2TP VPN
Replies: 9
Views: 6212

Re: Route all traffic down L2TP VPN

It might be how you have srcnat set up and/or whether the server at the other side knows how to route back to your lan IP (192.168.88.254) If the packets from your local lan (192.168.88.254) are only natted when they leave your router for the internet (0.0.0.0/0 or it's interface) then your lan IP w...
by ebreyit
Tue Sep 12, 2017 11:21 pm
Forum: Beginner Basics
Topic: PPPoE - What am I doing wrong?
Replies: 5
Views: 1132

Re: PPPoE - What am I doing wrong?

If not already enabled add pppoe and ppp in system>logging to show more information about the connection attempt. If that doesn't show enough add debug. Hopefully that will give more of a clue as to the cause of the issue
by ebreyit
Tue Sep 12, 2017 11:13 pm
Forum: Beginner Basics
Topic: how to force VPN (PPTP) over certain interface?
Replies: 2
Views: 1263

Re: how to force VPN (PPTP) over certain interface?

Use routing marks.

Mark the traffic intended for the IP of the remote VPN endpoint such that in the routing table you route it via the intended WAN connection (The LTE Connection)
by ebreyit
Mon Sep 11, 2017 2:06 am
Forum: Beginner Basics
Topic: Layer 7 facebook block
Replies: 29
Views: 146599

Re: Layer 7 facebook block

Firewall address list supports domain names and dynamically adds IP entry to same address list. Provided you use the Mikrotik as the DNS server it will always server up the same IP address/s of the specified domains and subsequently drop the traffic Add address as follows ip firewall address-list ad...
by ebreyit
Mon Sep 11, 2017 1:46 am
Forum: Beginner Basics
Topic: SQL Brute Force Filter
Replies: 1
Views: 483

Re: SQL Brute Force Filter

My advice is don't leave SQL open to the Internet, even if you change the port it'll still be found and brute force login attempts will continue.

If you need remote access to the SQL server use a vpn
by ebreyit
Tue Aug 22, 2017 11:43 pm
Forum: General
Topic: Marking MS Update packets
Replies: 3
Views: 2581

Re: Marking MS Update packets

Some of the domains for windows update can be found @ https://technet.microsoft.com/en-gb/library/bb693717.aspx You can add these to address list in the firewall and use that to mark packets. You would probably also need to use the Layer 7 approach you're also looking into to catch the new inter PC ...
by ebreyit
Tue Aug 22, 2017 10:59 pm
Forum: General
Topic: Mass netinstall
Replies: 7
Views: 1141

Re: Mass netinstall

FlashFig is available for Mass config. https://wiki.mikrotik.com/wiki/Manual:Flashfig your issue might be the fact that factory reset reverts back to Mikrotik default not your own th.ough
by ebreyit
Fri Aug 18, 2017 12:44 am
Forum: Beginner Basics
Topic: LAN isolation?
Replies: 7
Views: 1052

Re: LAN isolation?

If you want them isolated why put them on the same bridge..?
by ebreyit
Thu Aug 17, 2017 11:55 pm
Forum: General
Topic: REST API v7 Make Our Day ! +1 it Please
Replies: 17
Views: 5942

Re: REST API v7 Make Our Day ! +1 it Please

+1 for rest

I think you'd probably find a lot more developers taking interest in producing apps and integrations for Miktorik products if implemented
by ebreyit
Tue Jun 06, 2017 4:55 pm
Forum: Announcements
Topic: v6.39.2 [current]
Replies: 122
Views: 34544

Re: v6.39.2 [current]

ebreyit - Client is not changed within this version. maybe you did by accident change something in QuickSet? I don't use quickset. original version 6.39.1 upgrade to 6.39.2 via system > packages on reboot pppoe-client was there but contained no settings as If I had just gone to create new one Other...
by ebreyit
Tue Jun 06, 2017 3:26 pm
Forum: Announcements
Topic: v6.39.2 [current]
Replies: 122
Views: 34544

Re: v6.39.2 [current]

I just popped this on a ccr1009 and it removed all the settings from my main pppoe client interface preventing it from connecting to the internet.
by ebreyit
Wed Apr 12, 2017 12:23 pm
Forum: General
Topic: Bonding over LT2P or similar
Replies: 3
Views: 781

Re: Bonding over LT2P or similar

EOIP will provide the required Layer 2. Push some data through once it's all up to make sure it's configured properly as EOIP is stateless.

The EOIP links should show up as available slaves under bonding in the interface menu of Winbox

Then try a mode like balance-rr.
by ebreyit
Mon Apr 10, 2017 9:27 am
Forum: General
Topic: Bonding over LT2P or similar
Replies: 3
Views: 781

Re: Bonding over LT2P or similar

Bonding requires a layer 2 connection. L2TP/IPSEC is providing a layer 3 connection
by ebreyit
Sun Apr 09, 2017 9:34 pm
Forum: Wireless Networking
Topic: Recommendation for small travel router?
Replies: 2
Views: 758

Re: Recommendation for small travel router?

The wAP ac might also be worth looking at. It's got higher power and more chains so would be beneficial in helping to get reception in fringe areas. Plus it already comes with a power injector so that you can place the unit where you need it. Just need to carry a length of RJ45. I've used one config...
by ebreyit
Sun Mar 26, 2017 12:10 pm
Forum: Beginner Basics
Topic: IP address automatically obtained
Replies: 2
Views: 388

Re: IP address automatically obtained

Export the configs for both routers and post them here so that we can see what's going on.
by ebreyit
Wed Mar 08, 2017 3:16 pm
Forum: Beginner Basics
Topic: Proper way for IPTV routing
Replies: 2
Views: 4807

Re: Proper way for IPTV routing

Here's some info from https://community.bt.com/t5/YouView-Boxes/Extra-IPTV-channels-working-on-Mikrotik-750G-router-a-short/td-p/1137730 Although it's for a different set top box the principal is the same with other services. I've used it successfully myself to connect IPTV STB's to ISP's Multicast ...
by ebreyit
Mon Mar 06, 2017 12:16 am
Forum: Beginner Basics
Topic: Newbie with a motorhome needs a clue.
Replies: 5
Views: 1066

Re: Newbie with a motorhome needs a clue.

Many of the RouterBoards have USB so you can pop in a 3G or LTE modem. The Hap ac lite and the Hap ac both have USB ports and would fit the bill. Just check compatibility first and make sure you're running a recent RouterOS version. Mikrotik also produces an SXT LTE ( https://routerboard.com/RBSXTLT...
by ebreyit
Sun Mar 05, 2017 11:55 pm
Forum: Beginner Basics
Topic: Why does PPPoE Dialer MTU affects IP assignment from ISP?
Replies: 1
Views: 425

Re: Why does PPPoE Dialer MTU affects IP assignment from ISP?

Do a packet capture of the connections as the PPPoE is initiating in both circumstances and start a conversation with your ISP.
by ebreyit
Sun Feb 19, 2017 9:29 pm
Forum: Beginner Basics
Topic: VPN between Mikrotik and MS Server
Replies: 2
Views: 437

Re: VPN between Mikrotik and MS Server

How much traffic / bandwidth do you see the link using..?

Personally I'd prefer Mikrotik both sides
by ebreyit
Sun Jul 24, 2016 10:06 pm
Forum: Wireless Networking
Topic: Very unusual wifi behavior on a 1,000 seater theater deployment using 9 GrooveA 52HPn, 2 SXT 2, and 1 wAP 2nD
Replies: 15
Views: 2084

Re: Very unusual wifi behavior on a 1,000 seater theater deployment using 9 GrooveA 52HPn, 2 SXT 2, and 1 wAP 2nD

Some very interesting articles by one chap on this subject worth reading. http://www.sniffwifi.com/2010/12/setting-data-rates-just-dont-do-it.html http://www.sniffwifi.com/2012/04/phones-on-wlan.html http://www.sniffwifi.com/2012/11/back-to-basics-again.html http://www.sniffwifi.com/2013/03/roam-lik...
by ebreyit
Tue Apr 26, 2016 2:37 pm
Forum: General
Topic: NetData realtime stats
Replies: 0
Views: 1331

NetData realtime stats

Has anyone taken a look at NetData. http://netdata.firehol.org/ https://github.com/firehol/netdata/wiki/snmp.node.js Have got a version running on my Asustor NAS and it looks nice. When I get a chance I might try popping it on a system and using the SNMP Data Collector to query some Mikrotik gear.
by ebreyit
Tue Apr 12, 2016 5:25 pm
Forum: Beginner Basics
Topic: internet for a restaurant or cafe shop
Replies: 13
Views: 2570

Re: internet for a restaurant or cafe shop

Which Routerboard device have you purchased
by ebreyit
Mon Feb 01, 2016 11:57 pm
Forum: The Dude
Topic: The Dude, work continues: v6.35rc test builds.
Replies: 103
Views: 34750

Re: The Dude, work continues: v6.35rc test builds.

missing dude-6.35rc2.npk

Also getting this when trying to update CCR from system \ packages in winbox 3.1
by ebreyit
Wed Jan 20, 2016 10:43 am
Forum: General
Topic: 6.34 release candidate version topic!
Replies: 201
Views: 42822

Re: 6.34 release candidate version topic!

Is there anything else I can send you to be able to track this down? If you experience version related issues, then please send supout file from your router to support@mikrotik.com. File must be generated while router is not working as suspected or after crash. Think they get everything they need f...
by ebreyit
Tue Dec 15, 2015 5:45 pm
Forum: General
Topic: WISP core router configuration
Replies: 14
Views: 2570

Re: WISP core router configuration

It's a tough one, but, there are some good comments in the thread so far. Have to agree that you need to fully understand the network topology and configuration before you go messing (from end to end). It's a ball ache of a job but the more info you have before you start to alter anything the less l...
by ebreyit
Tue Dec 15, 2015 5:20 pm
Forum: Scripting
Topic: Karma Hotspot
Replies: 1
Views: 545

Re: Karma Hotspot

Try to find out if it's possible to login via a URL (with token or encoded credentials as part of the URL)
by ebreyit
Sun Nov 29, 2015 11:03 pm
Forum: General
Topic: RB2011 10% CPU with initial configuration
Replies: 4
Views: 488

Re: RB2011 10% CPU with initial configuration

Try disabling the LCD.
by ebreyit
Thu Nov 26, 2015 12:53 pm
Forum: General
Topic: 6.34 release candidate version topic!
Replies: 201
Views: 42822

Re: 6.34 release candidate version topic!

Following work from the guys at Mikrotik I can confirm that RFC4638 1500MTU via PPPoE on standard UK FTTC connections is now working with 6.34rc9 Tested on CCR1009, SXT SA5, and a RB2011 so far with ECI B-FOCuS, and Huawei HG612 Modems (as supplied by OpenReach, unmodified) Tested on 4 Entanet accou...
by ebreyit
Mon Nov 16, 2015 10:10 pm
Forum: General
Topic: IPV6 on wlan not working plus subnetting /56 prefix
Replies: 3
Views: 970

Re: IPV6 on wlan not working plus subnetting /56 prefix

Hi, Can you post an export of your config and a diagram of your network so that it will be easier to see what's gong on. I use an ISP for a number of clients that gives out /56 IPv6 and have been using a mixture of mipsbe and CCR's without issue for some time. Usually break it up into 256 /64's to k...
by ebreyit
Thu Oct 08, 2015 2:45 pm
Forum: Wireless Networking
Topic: Very unusual wifi behavior on a 1,000 seater theater deployment using 9 GrooveA 52HPn, 2 SXT 2, and 1 wAP 2nD
Replies: 15
Views: 2084

Re: Very unusual wifi behavior on a 1,000 seater theater deployment using 9 GrooveA 52HPn, 2 SXT 2, and 1 wAP 2nD

Dense deployments are tricky things. As bad as this turned out, hopefully you've manage to learn a lot and made some good observations. Key points (some as mentioned above): 2.4G has only 3 non-overlaping channels 1 - 6 - 11 (some countries you may also get 14 but it's close to 11) In the UK we have...
by ebreyit
Tue Oct 06, 2015 5:26 pm
Forum: General
Topic: Feature request: CAPsManager - roaming
Replies: 79
Views: 22739

Re: Feature request: CAPsManager - roaming

Reviving this one as more vendors are adding this now. can Mikrotik add 802.11r, 802.11k and 802.11v to CAPsMan https://support.apple.com/en-gb/HT202628 https://documentation.meraki.com/MR/WiFi_Basics_and_Best_Practices/802.11k_and_802.11r_Overview http://www.cisco.com/c/en/us/td/docs/wireless/contr...
by ebreyit
Sun Oct 04, 2015 11:34 pm
Forum: General
Topic: IGMP Snooping
Replies: 137
Views: 59479

Re: IGMP Snooping

+1 for IGMP snooping
by ebreyit
Sun Oct 04, 2015 12:31 pm
Forum: Beginner Basics
Topic: Mikrotik 951G-2HnD and Samsung TV problem
Replies: 30
Views: 9997

Re: Mikrotik 951G-2HnD and Samsung TV problem

Sounds very similar to the issue mikrotik devices had with the UK's openreach FTTC modems.

Not sure if it was a hardware or firmware fix from mikrotik to fix in the end though.

Might be worth inquiring.
by ebreyit
Mon Sep 21, 2015 1:28 am
Forum: Beginner Basics
Topic: Packet Of Disconnect
Replies: 2
Views: 511

Re: Packet Of Disconnect

is a tunnel to/from the radius server/network not possible...?
by ebreyit
Fri Jul 10, 2015 5:26 pm
Forum: Announcements
Topic: 6.30 released
Replies: 180
Views: 42053

Re: 6.30 released

Torrent link http://www.mikrotik.com/download/routeros-ALL-6.30.torrent is ready ...but no seeders, yet... Seeding away merrily now from my Kimsufi box We don't even list the torrent on the download page, so fixes were not applied to it. Please download from our homepage Why the move away from Torr...
by ebreyit
Wed Jul 01, 2015 1:00 am
Forum: General
Topic: How does the client choose which DHCP server to get an address from?
Replies: 4
Views: 739

Re: How does the client choose which DHCP server to get an address from?

Easiest way is to connect TP-Link to a different port on the RB2011. Create a separate lan on that port with it's own IP subnet and DHCP server, set relevant NAT/masqarading rules etc to allow internet access. The finally either set a blackhole rule in routing or use the firewall to prevent the 2nd ...
by ebreyit
Tue Jun 30, 2015 2:36 pm
Forum: Beginner Basics
Topic: Not able to browse all sites properly
Replies: 10
Views: 2236

Re: Not able to browse all sites properly

Hi, Also try disabling MRRU then playing with the MTU, MRU settings again. I've come across a few PPPoE connections where having it enabled caused havoc or the connection just didn't plain work, the second I disabled it and restarted the PPPoE session things just fell into place. It may not work for...
by ebreyit
Tue Jun 30, 2015 2:28 pm
Forum: Beginner Basics
Topic: EoIP for IPTV with STB at remote location
Replies: 3
Views: 1385

Re: EoIP for IPTV with STB at remote location

Pop a Kodi (Formerly XBMC) box somewhere with loads of content on it (all scraped with TheMovieDB or TVDB etc etc) , enable upnp then get remote MT boxes setup same as you have just done and they will see the remote Kodi server (once you add it as a UPnp source) and be able to stream content from it...
by ebreyit
Tue Jun 30, 2015 2:15 pm
Forum: Beginner Basics
Topic: EoIP for IPTV with STB at remote location
Replies: 3
Views: 1385

Re: EoIP for IPTV with STB at remote location

Hi,
Export your current config (from both ends), post them here and I'll take a look.

This setup also works great with UPnP/DNLA across remote links once you get it going, provided you have sufficient Upload capacity at the source.
by ebreyit
Tue Jun 30, 2015 2:03 pm
Forum: Beginner Basics
Topic: Mikrotik 951G-2HnD and Samsung TV problem
Replies: 30
Views: 9997

Re: Mikrotik 951G-2HnD and Samsung TV problem

Can you export your router config and post it here. it will make it easier to see what's going on.
by ebreyit
Mon Mar 23, 2015 11:14 pm
Forum: RouterBOARD hardware
Topic: Outdoor dual band 2.4/5G a/b/g/n/ac 2x2x2mimo device
Replies: 7
Views: 2415

Re: Outdoor dual band 2.4/5G a/b/g/n/ac 2x2x2mimo device

+1 for indoor and outdoor
by ebreyit
Fri Mar 20, 2015 12:26 pm
Forum: RouterBOARD hardware
Topic: Wi-Fi in very long building
Replies: 7
Views: 1345

Re: Wi-Fi in very long building

Leaky feeder cable will grab the interference from all around and also will make all the clients to share one ap radio. This is not enough advantageous according to my opinion. That depends entirely on what the OP intends to use it for and the number of active clients he wishes to serve. Either RBM...
by ebreyit
Mon Mar 16, 2015 3:47 pm
Forum: RouterBOARD hardware
Topic: Wi-Fi in very long building
Replies: 7
Views: 1345

Re: Wi-Fi in very long building

What about Leaky Feeder Cable (http://en.wikipedia.org/wiki/Leaky_feeder)
by ebreyit
Wed Mar 04, 2015 1:28 am
Forum: General
Topic: How to block hotspot ip scanners (like Fing App)
Replies: 5
Views: 2205

Re: How to block hotspot ip scanners (like Fing App)

Client or Wireless isolation only prevents stations (clients) on the same AP from communicating with each other, it does nothing to protect devices downstream of the AP, i.e. wireless clients/stations connected to other AP's or the rest of your network infrastructure. In wisp deployments PPPoE is em...
by ebreyit
Tue Mar 03, 2015 12:13 pm
Forum: General
Topic: Need advise to Mikrotik router that able to do bonding
Replies: 1
Views: 454

Re: Need advise to Mikrotik router that able to do bonding

Hi, The Mikrotik cannot be used to bind two unrelated ISP's into a single aggregate connection. Options: 2 (or more) connections from the same ISP who are able to provide an MLPPP PPPoE connection. This would provide a sum total of all the available bandwidth. http://wiki.mikrotik.com/wiki/Manual:ML...
by ebreyit
Thu Feb 12, 2015 8:03 pm
Forum: Wireless Networking
Topic: Wireless protocols
Replies: 2
Views: 653

Re: Wireless protocols

Wireless protocol is exclusive, per radio. RB921UAGS has only 1 Radio

You have to choose which one to use. 802.11, NV2, Nstream etc.

If set to nv2-nstreme-802.11 then it sticks to which ever gets connected first
by ebreyit
Sat Feb 07, 2015 10:40 am
Forum: Wireless Networking
Topic: HotSpot HTML Pages Scenario
Replies: 3
Views: 792

Re: HotSpot HTML Pages Scenario

Pipped me to the post czolo
by ebreyit
Sat Feb 07, 2015 10:05 am
Forum: Beginner Basics
Topic: Lắp Mạng Internet FPT Tiền Giang
Replies: 16
Views: 2767

Re: Why is unable to load website

Hi RazorMK, use the following, making sure that where I have set ether1 you set it to the interface where you connect to your isp. /ip firewall mangle add action=change-mss chain=forward new-mss=1400 in-interface=ether1 protocol=tcp tcp-flags=syn tcp-mss=1401-65535 add action=change-mss chain=forwar...
by ebreyit
Fri Feb 06, 2015 10:56 pm
Forum: Scripting
Topic: script send email as user login into routerboard
Replies: 24
Views: 8478

Re: script send email as user login into routerboard

I use the logging function to email when a user logs into the routerboard. Setup email, in the tools menu, the under logging create a new action, type email. Then, add a new logging rule. Topic: Account, Action 'Your new emailing action' Now try logging in from winbox and you should receive an email.
by ebreyit
Thu Feb 05, 2015 10:32 am
Forum: Beginner Basics
Topic: Lắp Mạng Internet FPT Tiền Giang
Replies: 16
Views: 2767

Re: Why is unable to load website

Even though you're not on PPPoE, MTU could still be the issue somewhere. As a check, get the IP for the server you're failing to connect to and ping from the router with just the normal settings. Provided you get a reply you can proceed by setting the packet size to 1500 and check the 'Don't Fragmen...
by ebreyit
Wed Feb 04, 2015 9:58 am
Forum: Beginner Basics
Topic: Doing both DHCP with NAT and just static routing
Replies: 7
Views: 900

Re: Doing both DHCP with NAT and just static routing

Can you export a copy of your current config (pop it in a code block on here) and perhaps a diagram or two showing us what you have, followed by what you would like. That will make it easier for others to provide feedback and comment on your proposal.
by ebreyit
Tue Feb 03, 2015 1:59 am
Forum: General
Topic: Block Application on mobile - Youtube
Replies: 3
Views: 2390

Re: Block Application on mobile - Youtube

Create an access point on a Mikrotik router. Connect you phone and use the Youtube app.
Meanwhile, use torch and/or the packet sniffer (in conjunction with https://www.wireshark.org/) to analyze the traffic.
That should give you plenty of information to get on with trying to block it.
by ebreyit
Mon Feb 02, 2015 3:30 pm
Forum: Beginner Basics
Topic: Problem of Quality of service
Replies: 1
Views: 649

Re: Problem of Quality of service

Please don't multipost the same question in multiple forums. it all becomes very fragmented otherwise

Please post here your full config output from Export (in a code block for easier reading), that will make it easier for people to feedback on your actual configuration.
by ebreyit
Sun Feb 01, 2015 9:44 pm
Forum: Beginner Basics
Topic: CRS124 24 and vlans
Replies: 1
Views: 628

Re: CRS124 24 and vlans

Hi,
Please export your config so that your exact setup can be seen.
by ebreyit
Sun Feb 01, 2015 9:30 pm
Forum: Beginner Basics
Topic: Public IP WAN IP Per a Physical Interface
Replies: 2
Views: 615

Re: Public IP WAN IP Per a Physical Interface

Hi,
Please post an export of your config so that we can see the exact setup.
by ebreyit
Sun Feb 01, 2015 9:26 pm
Forum: Beginner Basics
Topic: Lắp Mạng Internet FPT Tiền Giang
Replies: 16
Views: 2767

Re: Why is unable to load website

Most likely an MTU issue. I suggest adding the MTU/MSS Rules manually Alter the 'TCP MSS' and 'New TCP MSS' values accordingly till you can find the highest value that works all the time, I suggest no higher than 1492 though. IP Firewall Mangle 2 New Rules Rule No. 1 General Tab Chain: Forward Proto...
by ebreyit
Fri Jan 30, 2015 10:46 am
Forum: Beginner Basics
Topic: RB2011 slow speed
Replies: 42
Views: 10936

Re: Very low performance of RB2011

I can also confirm there is a noticeable drop in CPU if the LCD is disabled.
by ebreyit
Thu Jan 29, 2015 12:39 pm
Forum: Wireless Networking
Topic: Wireless network at home
Replies: 4
Views: 880

Re: Wireless network at home

Have you thought about HomePlug AV as a solution to placing AP's in remote locations within the property without additional wiring. Use PiggyBack HomePlug units if you can get them (better filtering) and consider using the newer AV2 units which utilise mimo to get the best speeds (or stability with ...
by ebreyit
Wed Jan 28, 2015 1:34 am
Forum: General
Topic: maximum number of users for a AP..
Replies: 14
Views: 2076

Re: maximum number of users for a AP..

How many people can fit in a room...? Neither question is able to bring forth a meaningful answer without further information. Even then, Mikrotik places no limits on how many clients can connect to an AP, but, just because you could connect hundreds doesn't means that's workable either. I read a ni...
by ebreyit
Fri Jan 23, 2015 11:25 am
Forum: Beginner Basics
Topic: Need to use a router to handle two independent DSL
Replies: 3
Views: 612

Re: Need to use a router to handle two independent DSL

Policy Based Routing is what your after

http://wiki.mikrotik.com/wiki/Policy_Base_Routing Gives an example, just ignore the content idetifier and mark the packets/connection based on IP/port
by ebreyit
Fri Jan 23, 2015 11:04 am
Forum: Beginner Basics
Topic: MLPPP Problems: 15mpbs + 15mpbs = 8mbps???
Replies: 3
Views: 1094

Re: MLPPP Problems: 15mpbs + 15mpbs = 8mbps???

Hi, I've found that if one of the connections is not stable it can cause issues. Make sure you're using a scheduled script to check for a dead PPPoE session such as the following, as the unstable connection may cause the connection to grind to a halt without causing a full disconnection. I typically...
by ebreyit
Fri Jan 23, 2015 10:39 am
Forum: Beginner Basics
Topic: Need to use a router to handle two independent DSL
Replies: 3
Views: 612

Re: Need to use a router to handle two independent DSL

Hi, If the current modem/routers don't work well as bridges then I would suggest that you get some modems that do work well as PPPoE bridges, e.g. the Vigor 120 for ADSL and maybe a Huawei HG612 or similar for the VDSL (can also do ADSL if you just get two of these). Trying to DMZ the the connection...
by ebreyit
Thu Jan 22, 2015 11:06 pm
Forum: General
Topic: RouterOS v6.25
Replies: 110
Views: 31871

Re: RouterOS v6.25

i confirm the same sstp bug! http://forum.mikrotik.com/viewtopic.php?f=2&t=78816&p=465171#p465042 I can also confirm issue with windows 8.1 sstp vpn clients following upgrade to 6.25. Error 619 reported by windows vpn client when trying to connect. Immediate downgrade back to 6.24 solved the issue....
by ebreyit
Fri Jan 16, 2015 6:19 pm
Forum: General
Topic: Winbox 3 beta
Replies: 243
Views: 119324

Re: Winbox 3

Differences in Winbox. In case you haven't noticed yet Winbox 3b3 isn't showing all of the new features added in the latest ROS, but they are visible in The older Winbox. In the link below you can see two screen shots I've sent to Mikrotik support (Ticket#2015010966000616) showing bits like Cap Nam...
by ebreyit
Mon Jan 12, 2015 12:34 am
Forum: General
Topic: SSTP tunnel firewall question
Replies: 3
Views: 1158

Re: SSTP tunnel firewall question

Hi kosztyua,
Can you paste in both of your configs here (export from cli) so that we can have a look at the whole picture.
Might just be something simple, I've often spent time ripping my hair out on things like this only to discover a subtle change is all that's required.
by ebreyit
Fri Jan 09, 2015 11:25 pm
Forum: Wireless Networking
Topic: How to implement client roaming between two or more CAPsMAN
Replies: 7
Views: 1982

Re: How to implement client roaming between two or more CAP

Hi,
Your diagram is a little ambiguous. are you using one or more CAPsMANs (CAP Managers)...?
by ebreyit
Fri Jan 09, 2015 11:18 pm
Forum: Wireless Networking
Topic: capsmanv1 and capsmanv2 problem with roaming
Replies: 6
Views: 3713

Re: capsmanv1 and capsmanv2 problem with roaming

Hi All, No script required, Access list will achieve what you are looking for. Checkout this post http://forum.mikrotik.com/viewtopic.php?f=1&t=91002&start=50#p459889 Important thing to remember is that you MUST have an accept rule to enter the client into the ACL so that you can control automatic d...
by ebreyit
Fri Jan 09, 2015 11:16 pm
Forum: Wireless Networking
Topic: CAPsMAN access list
Replies: 4
Views: 10000

Re: CAPsMAN access list

Hi All, No script required, Access list will achieve what you are looking for. Checkout this post http://forum.mikrotik.com/viewtopic.php?f=1&t=91002&start=50#p459889 Important thing to remember is that you MUST have an accept rule to enter the client into the ACL so that you can control automatic d...
by ebreyit
Fri Jan 09, 2015 11:08 pm
Forum: General
Topic: SSTP tunnel firewall question
Replies: 3
Views: 1158

Re: SSTP tunnel firewall question

Hi, The firewall is an ordered list of rules. to allow some traffic but block all else you will need to create specific 'allow' rules (specifying source and or destination by IP for example) higher up the list, followed immediately by your 'drop' rule. I would create these rules at the branches so t...
by ebreyit
Fri Jan 09, 2015 8:03 pm
Forum: General
Topic: Winbox 3 beta
Replies: 243
Views: 119324

Re: Winbox 3

Differences in Winbox. In case you haven't noticed yet Winbox 3b3 isn't showing all of the new features added in the latest ROS, but they are visible in The older Winbox. In the link below you can see two screen shots I've sent to Mikrotik support (Ticket#2015010966000616) showing bits like Cap Nami...
by ebreyit
Wed Dec 31, 2014 12:09 am
Forum: General
Topic: Winbox 3 beta
Replies: 243
Views: 119324

Re: Winbox 3

I am also now experiencing the issue with Winbox3 Beta 3 where in on Windows 7 64 machines I see the list of discovered decives, but no form fields. This just started int he last few days, and affects more than one machine. No changes on machines save for the last round of Windows Updates. https://...
by ebreyit
Tue Dec 16, 2014 11:43 am
Forum: Wireless Networking
Topic: Max Concurrent Clients for certain wireless devices
Replies: 3
Views: 2826

Re: Max Concurrent Clients for certain wireless devices

That's not an easy question to answer. Theoretically hundreds of clients could be registered but that does't mean it would be functional. regardless of chosen vendors equipment, factors such as antenna (both ends), los or lack of, fresnel zones, interference, neibouring wifi installations, distance ...
by ebreyit
Tue Dec 16, 2014 1:24 am
Forum: General
Topic: Please help choosing the right RouterBoard for small network
Replies: 9
Views: 1146

Re: Please help choosing the right RouterBoard for small net

Try the http://routerboard.com/RB951Ui-2HnD

It has a good price / performance balance

600MHz CPU (overclockable to 750MHz) and 128MB of RAM

On an 8Mbit connection it should be more than enough
by ebreyit
Mon Dec 15, 2014 8:39 am
Forum: Beginner Basics
Topic: Bonding 2 WAN Connections
Replies: 13
Views: 45405

Re: Bonding 2 WAN Connections

Hi, What countries are those interested in bonding in and what/who are your isp's..? If you are using the same isp and connecting with PPPoE then ask about MlPPP as Router OS has support for aggregating links through this. http://wiki.mikrotik.com/wiki/Manual:MLPPP_over_single_and_multiple_links Oth...
by ebreyit
Thu Dec 11, 2014 5:43 pm
Forum: Beginner Basics
Topic: Unifi Discovery
Replies: 6
Views: 2871

Re: Unifi Discovery

Hi, Which port are you plugging the unifi into on the 2011. I've had problems with a few pieces of equipment (openreach VDSL Modems mostly) which flap on the gigabit ports (1-5) but are solid on the 10/100 ports (6-10). Also have you tried making ports 2 and 6 masters for 3-5 and 7-10 respectivley, ...
by ebreyit
Thu Dec 11, 2014 10:40 am
Forum: General
Topic: CAPsMAN v2 ready for testing
Replies: 201
Views: 101448

Re: CAPsMAN v2 ready for testing

Great, that should work for you once switched as the list operates top to bottom.

re

i have access rule but it was secend, i change to first accept and then reject and check.

thx

bleblas
by ebreyit
Thu Dec 11, 2014 10:32 am
Forum: General
Topic: CAPsMAN v2 ready for testing
Replies: 201
Views: 101448

Re: CAPsMAN v2 ready for testing

Hi bleblas, If that is your only access list rule then it's not complete. As per the wiki and my code example you need to include an accepting rule first so that the client is included in the connected clients ACL, once there it can then be controlled by further rules which will disconnect clients w...
by ebreyit
Thu Dec 11, 2014 10:03 am
Forum: General
Topic: CAPsMAN v2 ready for testing
Replies: 201
Views: 101448

Re: CAPsMAN v2 ready for testing

Hi bleblas My experience is that if set correctly Access List will disconnect an existing client if signal drop below threshold if set correctly as per Wiki You should be seeing log entries stating that a client has disconnected, signal too weak! I then see it immediately register on the next AP (if...
by ebreyit
Thu Dec 11, 2014 12:17 am
Forum: General
Topic: CAPsMAN v2 ready for testing
Replies: 201
Views: 101448

Re: CAPsMAN v2 ready for testing

In multi-AP installations I've also been using the following to assist in nudging clients onto AP's whilst moving around. In most scenarios it works great. Some applications might suffer from the sudden drop off though (VOIP). Streaming has worked fine for me whilst jumping from one AP to another. P...
by ebreyit
Sun Oct 05, 2014 11:29 pm
Forum: General
Topic: win7 sstp clients ROS 6.7 or higher anyone
Replies: 2
Views: 529

Re: win7 sstp clients ROS 6.7 or higher anyone

Definitely working well 6.15 - 6.19. Not upgraded to 6.20 yet. Have the same CCR running site to site between a ccr and various other mikrotiks and site to client with windows 7, 8 and 8.1
by ebreyit
Thu Jul 10, 2014 2:24 am
Forum: Wireless Networking
Topic: Hotspot network. what AP to use?
Replies: 13
Views: 2383

Re: Hotspot network. what AP to use?

Hi aresmt, I think what Jarda is getting at, is that you need to provide a narrower scope of variables before you can expect a realistic answer, otherwise the question is to open and ambiguous to gain useful answers. Do you expect each client to utilise 100-200Mbps each, or, is that to be the max ba...
by ebreyit
Thu Jan 09, 2014 4:37 pm
Forum: RouterBOARD hardware
Topic: CCR and PPPoE with a Draytek Vigor 130
Replies: 2
Views: 3753

CCR and PPPoE with a Draytek Vigor 130

Recently trying to setup a CCR to connect to an ISP using Fully Bridged PPPoE utilising a Draytek Vigor 130. Issue: Even with all the vlan options turned off the Vigor seems to be tagging the PPPoE with VLAN ID 0 Findings: As the PADO comes back tagged with VLAN ID 0 it (the CCR) refuses to see the ...