Community discussions

MikroTik App

Search found 1127 matches

by pcunite
Thu Oct 29, 2020 11:57 pm
Forum: RouterBOARD hardware
Topic: Purchasing a RouterBOARD Router/AP. Questions.
Replies: 1
Views: 82

Re: Purchasing a RouterBOARD Router/AP. Questions.

To many variables. Also consider the hAP AC2.
by pcunite
Mon Oct 26, 2020 5:10 pm
Forum: Scripting
Topic: Mikrotik Scripting needs to be useful! Requests!
Replies: 5
Views: 279

Re: Mikrotik Scripting needs to be useful! Requests!

Agree, I wish there was a proper onboard API to control them.
by pcunite
Sun Oct 25, 2020 2:47 am
Forum: Beginner Basics
Topic: Problems with vlan interface [SOLVED]
Replies: 2
Views: 270

Re: Problems with vlan interface [SOLVED]

Good to hear. The 2011 units are under powered.
by pcunite
Fri Oct 23, 2020 8:25 pm
Forum: General
Topic: CCR2004-1G-12S+2XS - ATT Residential Fiber Termination via ONT
Replies: 2
Views: 227

Re: CCR2004-1G-12S+2XS - ATT Residential Fiber Termination via ONT

A discussion with interested individuals is occurring here.
by pcunite
Fri Oct 23, 2020 2:08 am
Forum: General
Topic: PSA: Trickbot is using compromised Mikrotik devices. Secure your routers reachable from the internet.
Replies: 18
Views: 1084

Re: PSA: Trickbot is using compromised Mikrotik devices. Secure your routers reachable from the internet.

Unfortunately that is inconclusive. The CVE says "6.41.3 through 6.46.5, and 7.x through 7.0 Beta5" which would potentially include 6.46.1. Unfortunately I've never seen MT publish their software development hierarchy so I'm not sure. Additionally, they haven't posted any further details at https:/...
by pcunite
Thu Oct 22, 2020 11:44 pm
Forum: General
Topic: PSA: Trickbot is using compromised Mikrotik devices. Secure your routers reachable from the internet.
Replies: 18
Views: 1084

Re: PSA: Trickbot is using compromised Mikrotik devices. Secure your routers reachable from the internet.

All MikroTik routers should be running
6.47.4 [stable]
6.46.6 [long-term]
or 7.0beta6 [testing]
due to CVE-2020-11881

Please confirm 6.46.1 (stable) is unaffected.
by pcunite
Thu Oct 22, 2020 12:49 am
Forum: Wireless Networking
Topic: What MT boxes can support spectral scan? - Cheap spectrum analyzer instead? [SOLVED]
Replies: 23
Views: 1297

Re: What MT boxes can support spectral scan? - Cheap spectrum analyzer instead? [SOLVED]

To run the scan on Groove there are prerequisites

Thanks for sharing. To confirm, can't scan on 5Ghz via Winbox? Have to use Dude?
by pcunite
Sat Oct 17, 2020 6:34 am
Forum: General
Topic: HAP AC Wired and Wireless VLAN CPU optimisation
Replies: 8
Views: 361

Re: HAP AC Wired and Wireless VLAN CPU optimisation

Sure, but does the RB3011 have wifi? I think he wants devices at both sites to provide wifi!

Sorry, yes the hAP AC2 would be better in his scenario.
by pcunite
Fri Oct 16, 2020 12:54 am
Forum: General
Topic: HAP AC Wired and Wireless VLAN CPU optimisation
Replies: 8
Views: 361

Re: HAP AC Wired and Wireless VLAN CPU optimisation

MikroTik has too many SKUs. For 100mb service, consider the RB3011 or better the RB4011. Hang the Wifi AP's off available ports.
by pcunite
Wed Sep 23, 2020 4:46 pm
Forum: Beginner Basics
Topic: AT&T FTTH, VLANs, CapsMAN Full Config
Replies: 15
Views: 796

Re: AT&T FTTH, VLANs, CapsMAN Full Config

Appreciate the great effort here. You have put the work into this. The information about how to configure these devices needs to be more open, more clear, and easily digestible. This will help to move that forward. An entire topic should be spent on Service Discovery between VLANs, I should think.
by pcunite
Wed Sep 23, 2020 4:15 pm
Forum: Announcements
Topic: Newsletter 97 (September 2020)
Replies: 86
Views: 13668

Re: Newsletter 97 (September 2020)

Excellent videos! Good to see the team and the products, puts a human touch behind the brand. Please consider making a 16 port PoE switch as described.
by pcunite
Tue Sep 08, 2020 11:39 pm
Forum: Beginner Basics
Topic: Using RouterOS to VLAN your network
Replies: 144
Views: 79318

Re: Using RouterOS to VLAN your network

... getting some pushback of late on the use of pvid and the associated bridge vlan settings ... personally I think its clearer when configuring and reading to have the bridge vlan settings visible. Is there any downside to RELYING on the dynamically generated settings? This is why I initially show...
by pcunite
Tue Sep 01, 2020 3:27 pm
Forum: RouterBOARD hardware
Topic: 16 port short depth PoE switch
Replies: 9
Views: 687

Re: 16 port short depth PoE switch

No, not RB4011 again ... They really should produce one device with two different cases (IN and RM), just like they did with RB2011 or certain models of CCR1009... The ears on the RB4011 are bad, yes. However, the one that ships with the CRS112 is really nice. But yes, a pure rack-mount would be ap...
by pcunite
Mon Aug 31, 2020 9:22 pm
Forum: RouterBOARD hardware
Topic: 16 port short depth PoE switch
Replies: 9
Views: 687

Re: 16 port short depth PoE switch

A crs318-16P-2S+ would be great. I would like it in an "IN" desktop form factor, although I am sure a RM version would be popular too.

They could make some ears to accommodate us both. I think it is a needed SKU.
by pcunite
Sat Aug 29, 2020 6:07 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 211
Views: 255079

Re: Using RouterOS to QoS your network - 2020 Edition

@pcunite thanks for doing this. I've noticed a few things that I'd like your input on. @blurrybird, >>why you are detecting VoIP by just blanket accepting 10,000+ ports? The original article was created a long time ago. The VoIP equipment I used at the time used those range of ports. I think it is ...
by pcunite
Fri Aug 28, 2020 11:28 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

I can no longer recommend the RB4011 as I've been getting the issue described here with it hitting 100% CPU, freezing up, etc. I'm at very low load (residential), but still happens what seems like once a month now. Going back to the CCR1009 that I didn't sell, yet, along with the switch. Sorry to h...
by pcunite
Fri Aug 28, 2020 11:25 pm
Forum: RouterBOARD hardware
Topic: 16 port short depth PoE switch
Replies: 9
Views: 687

16 port short depth PoE switch

I need an improved CRS112-8P-4S-IN rackmount switch. I see that the netPower 16P is close to what I would want, hardware wise, but in an incompatible design for my needs. The CRS328-24P-4S+RM is too big. Any news of a possible CRS328-16P-4S+RM on the horizon?
by pcunite
Fri Aug 28, 2020 11:12 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 211
Views: 255079

Re: Using RouterOS to QoS your network - 2020 Edition

I have been wading thru this thread since the 2013 beginning looking for a "final" recommended way to provide the QoS to make a couple of VOIP phones to work. But that appears not to be. My configuration, as shown, is what you are looking for. It works. I use it on multiple networks. Don't worry ab...
by pcunite
Fri Jul 03, 2020 12:15 am
Forum: Beginner Basics
Topic: RB3011 Second Switch as another router
Replies: 2
Views: 517

Re: RB3011 Second Switch as another router

Absolutely, that is the purpose of this hardware. If you have a speed issue, as pointed out, then you can make adjustments. Keep everything on the same switch group if you can, then it can hit the CPU to get out to WAN. If you need to hit the other bridge, I don't think it will be that bad for one o...
by pcunite
Sat Jun 27, 2020 12:17 am
Forum: Announcements
Topic: MikroTik newsletter May 2020 (#95)
Replies: 50
Views: 27726

Re: MikroTik newsletter May 2020 (#95)

I just find out that netPower 16P is CRS318-16P-2S+OUT. So, we suggest mikrotik can release CRS318-16P-2S+IN-2HnD.

Yes, this could be the update to the CRS112-8P-4S-IN.
by pcunite
Thu Jun 25, 2020 6:54 pm
Forum: General
Topic: Cert cannot be imported on IOS13
Replies: 4
Views: 1028

Re: Cert cannot be imported on IOS13

Things have changed with iOS 13 and macOS 10.15. Study the link. You can use a tool like CertManEX to create these new types or openssl.
by pcunite
Sun May 31, 2020 2:15 am
Forum: Wireless Networking
Topic: Additional Security for Wifi Devices.
Replies: 5
Views: 1036

Re: Additional Security for Wifi Devices.

You can be as restrictive as you feel you need to be. What is the threat vector? Are you protecting access from neighbors (don't have valid access credentials) or clients within (do have credentials)? * Turn the power down to prevent signals escaping the home. Use more low power units to fill in gap...
by pcunite
Thu May 21, 2020 10:01 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

Official Response from MT Support: How would you expect to treat VLAN-ID 0 packets in RouterOS? Should we allow the users to configure a special-purpose VLAN interface that accepts these packets? How should RouterOS respond - with or without VLAN-ID 0 header? Glad to see them thinking about it. I d...
by pcunite
Wed May 20, 2020 10:38 pm
Forum: Beginner Basics
Topic: Assign unique DHCP server to an AP?
Replies: 3
Views: 614

Re: Assign unique DHCP server to an AP?

Study VLAN techniques as noted in my signature.
by pcunite
Fri May 15, 2020 1:37 am
Forum: General
Topic: Dot1x Client improper start frame version
Replies: 2
Views: 1064

Re: Dot1x Client improper start frame version

Thank you.
by pcunite
Thu May 14, 2020 12:06 am
Forum: RouterBOARD hardware
Topic: What is your opinion of Mikrotik routers?
Replies: 3
Views: 1044

Re: What is your opinion of Mikrotik routers?

I like how they use just enough power to accomplish the goal. I didn't want big beefy hardware, unless I needed it. Take the RB4011 for example, handles 1G fiber service just fine on small networks.
by pcunite
Thu May 14, 2020 12:02 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

The best option would be for the bridge to be able to strip VLAN 0, but isn't that something MT needs to fix?

Its not so much a fix, as it is additional functionality we want.
by pcunite
Fri May 08, 2020 10:12 pm
Forum: RouterBOARD hardware
Topic: RB5011
Replies: 40
Views: 10724

Re: RB5011

+2
Make two case options, a proper rack-mount, and a nice desktop version.
by pcunite
Fri May 08, 2020 10:10 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

I want to clarify with some information provided to me. The ATT Residential RG sends all outgoing packets as 802.1p (tagged with VLAN 0). Their Commercial gateways sends all outgoing packets as 802.1q PVID 2 (tagged with VLAN 2). These are not always enforced, as I understand it. My residential 1G f...
by pcunite
Fri May 08, 2020 6:51 pm
Forum: RouterBOARD hardware
Topic: CCR2004-1G-12S+2XS with more RAM ?
Replies: 15
Views: 4161

Re: CCR2004-1G-12S+2XS with more RAM ?

Can someone measure its idle power usage? Preferably with one or two 10g ports connected (optical sfp+ or DAC).
Also, how loud is it under low load circumstances?

I would like to know as well. Also, if I disconnect the fans, or redundant power, can I get the power usage down?
by pcunite
Fri May 08, 2020 6:37 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

... for CCRs, what model switches have people been using in front it to take care of the vlan 0 tagging?

Ask wojo
by pcunite
Fri May 08, 2020 6:47 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

I'm surprised the hEX/RB750Gr3 isn't recommended especially for people on 300/300 or 100/100. Does it not work well with wpa_supplicant despite having a switch chip?

Recommended just means what most have reported success with. Since the RB4011 is known to work, it is therefore, recommended.
by pcunite
Thu May 07, 2020 11:43 pm
Forum: General
Topic: hAP ac2 board in a difference case?
Replies: 6
Views: 1342

Re: hAP ac2 board in a difference case?

If anyone has an .stl for the RB750 / hEX case, would you mind sharing?

I would like a square case for the cAP AC too.
by pcunite
Thu May 07, 2020 11:42 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

Both? The Bridge Method and the Supplicant Method?

I was referring to the Supplicant Method, only the RB4011 is recommended.
by pcunite
Thu May 07, 2020 6:31 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS, turn off blue LED, still not possible?
Replies: 2
Views: 1043

Re: RB4011iGS, turn off blue LED, still not possible?

What happens when you use a Sharpie pen on it?
by pcunite
Thu May 07, 2020 6:25 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

I have the BGW210 and I was able to downgrade the modem back to firmware 1.0.29 and extracted the keys and certs, then upgraded it back to firmware 2.6.4 and it works fine. My MikroTik router is the CRS125-24G-1S-2HnD ... how do I do that with this router? Only the RB4011 is recommended at this time.
by pcunite
Thu May 07, 2020 6:02 pm
Forum: General
Topic: hAP ac2 board in a difference case?
Replies: 6
Views: 1342

Re: hAP ac2 board in a difference case?

So, I picked up a hEX and ... the boards are identical size and layout - ports, power, usb, LEDs, etc. The hAP board will fit very nicely into the hEX case for anyone interested :-).

Really? Nice find! I had not thought of that. When you say hEX, you mean this one?
by pcunite
Wed Apr 29, 2020 4:25 pm
Forum: Announcements
Topic: MikroTik newsletter May 2020 (#95)
Replies: 50
Views: 27726

Re: MikroTik newsletter May 2020 (#95)

Good to see a desktop version of the CRS3XX line. I need the CRS112-8P-4S-IN upgraded to the CRS3xx hardware and have 16 ports, rackmount or desktop (short depth PoE switch).
by pcunite
Sun Apr 19, 2020 8:33 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 211
Views: 255079

Re: Using RouterOS to QoS your network - 2020 Edition

@pcunite No worries. I'll see if I can rerun the test graphs with the updated baseline when office reopens. I've seen some weird packet issues when using RED for the defaults. So, I've gone back to SFQ for default but use RED for the bulky flows. The behavior of RED as default causes the VoIP queue...
by pcunite
Fri Apr 17, 2020 4:58 pm
Forum: Announcements
Topic: Winbox v3.23 released!
Replies: 60
Views: 29283

Re: Winbox v3.23 released!

Does not preserve chosen interior window sizing and spacing after selecting Session / Save. Windows 10, 125DPI.
by pcunite
Fri Apr 17, 2020 4:16 pm
Forum: Beginner Basics
Topic: No IP Address Acquired
Replies: 30
Views: 6999

Re: No IP Address Acquired

If upstream hardware requires 802.1p, then that ability is not configurable with MikroTik, yet. Instead, you'll need to place a Cisco switch in front of the MikroTik and have it set the bits on the outgoing packets.
by pcunite
Thu Apr 16, 2020 10:46 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 211
Views: 255079

Re: Using RouterOS to QoS your network - 2020 Edition

Set parent queues to have a bucket-size of 0.005. Changed the default queue to sfq . (Using red gave similar performance, but multiple downloads seemed less fair). Rationale for the 0.005 size is to copy CoDel as much as possible. @bharrisau, I've have tested your feedback and have made changes to ...
by pcunite
Tue Apr 14, 2020 6:26 pm
Forum: General
Topic: VLAN offloading
Replies: 25
Views: 4189

Re: VLAN offloading

The hAP ac is a very under powered device. The hAP ac2 is much better for just about everyone not doing something crazy. I use both at different locations. The bugs on the hAP ac2, my understanding, can be avoided if using the pure software approach to VLANs (if doing vlans). Don't try to use the sw...
by pcunite
Tue Apr 14, 2020 6:21 pm
Forum: Beginner Basics
Topic: Packet Priority
Replies: 3
Views: 1662

Re: Packet Priority

See my signature. Note that your hAP ac is under-powered for QoS tasks.
by pcunite
Tue Apr 14, 2020 5:51 pm
Forum: General
Topic: Does QOS on Wan/Download work?
Replies: 9
Views: 2001

Re: Does QOS on Wan/Download work?

You are asking a lot in one post. I'll respond to your conversation points. Have more: It is always ideal to have a faster router and a bigger pipe to manage incoming packets. If you can, always have more available to you than what will ever be sent to you. If applications don't play by the rules, t...
by pcunite
Thu Apr 09, 2020 8:23 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 211
Views: 255079

Re: Using RouterOS to prioritize (Qos) traffic for a Class C

Do you need to mark the connection before mark the packet? Yes/No/Why? Please add some words about this in your second post where you talk about marking. How to use RouterOS to accomplish a task vs. how RouterOS itself works are two different concepts. I only focus on the former. However, everyone ...
by pcunite
Tue Apr 07, 2020 8:34 pm
Forum: Wireless Networking
Topic: Additional AP
Replies: 11
Views: 2923

Re: Additional AP

If you know and understand MikroTik, it is the better option. However, there are situations to where MikroTik (circa 2020) offerings are not the best: Over 50 clients per AP 100Mbps plus data requirements per connected client You will not get the fastest WiFi speed from current MikroTik hardware. In...
by pcunite
Mon Apr 06, 2020 6:56 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS+ 802.1Q VLANs
Replies: 4
Views: 2431

Re: RB4011iGS+ 802.1Q VLANs

This device is expressly created for the purpose of using the CPU and vlans. You should configure it that way.
by pcunite
Fri Mar 27, 2020 1:53 pm
Forum: Wireless Networking
Topic: rb4011 wireless version setting / reboot automatically
Replies: 29
Views: 6311

Re: rb4011 wireless version setting / reboot automatically

I know it is frustrating. The non-wifi model is a great product. Not sure what is happening on the other SKU. I do think it would help to have clear documentation on how to setup the various options. Its possible to create a unwise configuration. The software will happily let you do it.
by pcunite
Sat Mar 21, 2020 4:04 am
Forum: General
Topic: SSL certificate for mynetname domain
Replies: 10
Views: 2561

Re: SSL certificate for mynetname domain

Own certificates are ok, but for own use (personal or some closed group). They are useless for services that have random visitors, because they would have to trust your CA to be able to verify them.

Of course ...
by pcunite
Sat Mar 21, 2020 12:46 am
Forum: General
Topic: Not much of help here
Replies: 2
Views: 1077

Re: Not much of help here

It is fairly commercial here, especially related to the HotSpot feature.
by pcunite
Sat Mar 21, 2020 12:44 am
Forum: General
Topic: SSL certificate for mynetname domain
Replies: 10
Views: 2561

Re: SSL certificate for mynetname domain

I like using my own certificates. To do this, you'll need to create a self-signed Root certificate. Then create all your end entity certs signed by your root. Install your entity certs as normal. Then export the Root, without its private key (in X509v3 DER or PEM format) and install that on all comp...
by pcunite
Fri Mar 13, 2020 11:37 pm
Forum: Announcements
Topic: Winbox v3.22 released!
Replies: 117
Views: 51048

Re: Winbox v3.22 released!

I would still very much like to see the following changes: - easier widget for selection of columns (a modal panel with checkmarks for all possible columns in a "square" layout where multiple checkmarks can be toggled before clicking OK) Agreed, takes way to much effort to deselect all the FP* colu...
by pcunite
Fri Mar 06, 2020 3:23 pm
Forum: General
Topic: Today - Linus tech tips, MIKROTIK !!!!!
Replies: 3
Views: 2606

Re: Today - Linus tech tips, MIKROTIK !!!!!

Have you gotten around to creating such a series? I'm a home user and looking into using MikroTik. Good to have you here! MikroTik's are a lot of fun. If you get frustrated, we'll try to help. I have not produced the series because I would need compensation for such an endeavor. It takes a very lon...
by pcunite
Sun Mar 01, 2020 3:23 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

@pcunite What about this? However, my concern is that in other posts, I saw that the "bridge" method ATT offers out of the box forces you to use their small NAT tables on the ATT gateway ... is that still the case with this "dumb bridge" method? The bridge method, as shown at the beginning of this ...
by pcunite
Sat Feb 29, 2020 10:45 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

is the only advantage of going with the supplicant method to prevent having the actual ATT Gateway powered on and active at all times?

Basically, yes. If you are willing to keep the ATT RG powered up, then its a very good method.
by pcunite
Tue Feb 25, 2020 5:34 am
Forum: General
Topic: Prioritise Voip traffic using simple queues
Replies: 2
Views: 1211

Re: Prioritise Voip traffic using simple queues

I'm not familiar with simple Queues, never used them. You can see my signature for how I handle this.
by pcunite
Tue Feb 18, 2020 1:35 am
Forum: Scripting
Topic: Find External IP ?
Replies: 18
Views: 48884

Re: Find External IP ?

I had a need to do this recently. Here is a full working example that posts JSON to a PHP server and then emails the data. Apply this to your router # Install this script and name it "GetIPAddress" # Enable the scheduler to run once a day and also on boot /system scheduler add name=RunGetIPAddress1 ...
by pcunite
Mon Feb 17, 2020 10:28 pm
Forum: Beginner Basics
Topic: Using RouterOS to VLAN your network
Replies: 144
Views: 79318

Re: Using RouterOS to VLAN your network

in the topic Switch with a separate router (RoaS), what is the difference between the Switch Config file and the Router Config file?

The two files are the configurations for the two hardware devices that will be in use. One a switch, the other a router.
by pcunite
Fri Feb 14, 2020 3:14 pm
Forum: General
Topic: Large blacklists for firewall
Replies: 4
Views: 1552

Re: Large blacklists for firewall

11K should be fine. I have 4,000 on an RB3011 and its no trouble. Use RAW rules something like this: /ip firewall raw add action=drop chain=prerouting disabled=yes in-interface=ether1 src-address-list=PortScanners add action=add-src-to-address-list address-list=PortScanners address-list-timeout=2w c...
by pcunite
Fri Feb 14, 2020 3:05 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

I can't get a lease. Applied fallback VLAN and it still doesn't work. The RB750Gr3 uses a MT7621 switch chip . The Atheros8227 chips need fallback mode set. For the other types, you might try a different setting. Until MikroTik has a consistent firmware across the hardware lines, we will have to gu...
by pcunite
Wed Feb 12, 2020 5:34 pm
Forum: General
Topic: VLAN for Security Cameras HowTo
Replies: 3
Views: 1365

Re: VLAN for Security Cameras HowTo

I use a similar setup too. Read the article mkx linked to. It will tell you all you need to know. After that, you'll make custom firewall rules. I allow IP Cameras to access NTP servers and nothing else, for example. Take time to really study the article. It won't waste your time.
by pcunite
Mon Feb 10, 2020 4:23 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

I tried this on an RB4011 using certs from an NVG510. Unfortunately I kept getting "rejected" after "authenticating", I did make sure I set the clock properly.

The certs from the NVG510 work for VDSL, but not for fiber service.
by pcunite
Wed Feb 05, 2020 7:09 pm
Forum: General
Topic: 2 Mikrotik Fails in a week reputation tarnished, major opportunity for MT
Replies: 6
Views: 1221

Re: 2 Mikrotik Fails in a week reputation tarnished, major opportunity for MT

What I find so frustrating, and the OP no doubt too, is the lack of documentation for all of these various use cases. It takes a while for a big tree to fall, but when it does, there is no stopping it. Hopefully, MikroTik will think about their brand and the collection of us who really are the face ...
by pcunite
Wed Feb 05, 2020 3:16 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 211
Views: 255079

Re: Using RouterOS to QoS your network - 2020 Edition

Set the two parent queues (UP and DOWN) to have a bucket-size of 0.005. Create a bulkUp queue of kind PCQ, set the pcq-limit to 11*[upload rate in Mbps] (100ms of upload bandwidth) and the pcq-total-limit to 10 times that. Select all 4 classifier options. Create a bulkDown queue of kind sqf. Change...
by pcunite
Wed Feb 05, 2020 3:12 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 211
Views: 255079

Re: Using RouterOS to QoS your network - 2020 Edition

Shouldn't the topic be moved to viewforum.php?f=23?

I'm okay with that. Please keep the original url and redirect it to whatever the new one will be. Also, remove many of the old posts that don't advance the topic, since the new 2020 edition for example.
by pcunite
Fri Jan 31, 2020 5:56 am
Forum: General
Topic: VLAN separation [SOLVED]
Replies: 2
Views: 1568

Re: VLAN separation [SOLVED]

Study the link in my signature until you can quote it from memory. Then ... you will have mastered VLAN separation.
by pcunite
Sat Jan 25, 2020 10:00 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 211
Views: 255079

Re: Using RouterOS to prioritize (Qos) traffic for a Class C

what about when there are several LAN interfaces?

There are several ways, in RouterOS, to combine several things into one. Maybe VLAN, maybe interface lists, maybe address lists. Its up to you. Then you simply mangle them and send them to the queue.
by pcunite
Thu Jan 23, 2020 4:16 pm
Forum: Announcements
Topic: v6.46.2 [stable] is released!
Replies: 121
Views: 34645

Re: v6.46.2 [stable] is released!

Pride comes before a fall. Companies much larger than MikroTik have had to learn this valuable lesson. One more time ... please hire a Product Manager who understands your users.
by pcunite
Wed Jan 22, 2020 3:17 pm
Forum: RouterBOARD hardware
Topic: Update on CRS354 Switches? (moved post)
Replies: 13
Views: 4646

Re: Update on CRS354 Switches? (moved post)

poe variant ???

This is a short depth model, very useful. PoE would be larger and needed too for IP Camera rollouts.
by pcunite
Tue Jan 21, 2020 5:03 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

This is amazing. 802.1x method was incredibly easily once converted to .pem.

Enjoy! It is a really nice solution.
by pcunite
Tue Jan 21, 2020 5:02 am
Forum: RouterBOARD hardware
Topic: Recent batch PSU Failures
Replies: 5
Views: 2973

Re: Recent batch PSU Failures

It is useful for the community to know. Yes, do let MikroTik know directly. They probably source these power supply units and do not make them themselves.
by pcunite
Tue Jan 21, 2020 4:57 am
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 211
Views: 255079

Re: Using RouterOS to QoS your network - 2020 Edition

do you prefer to put highest priority 1 (in my situation game : Apex) to fast track?

Fast Track is CPU usage mitigation technique. Queuing is a bandwidth utilization technique. Different goals. If the CPU can handle it, you need to use Queue technique only.
by pcunite
Mon Jan 20, 2020 10:00 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 211
Views: 255079

Re: Using RouterOS to QoS your network - 2020 Edition

#DOWN
add name=DOWN max-limit=1M parent=LAN queue=default
# UP
add name=UP max-limit=100k parent=WAN queue=default

I will still get : Download Mbps 9.68, Upload Mbps 0.56

How is this possible?

You can not use Fast Track and Queues Tree together.
by pcunite
Mon Jan 20, 2020 5:32 pm
Forum: Announcements
Topic: v6.46.2 [stable] is released!
Replies: 121
Views: 34645

Re: v6.46.2 [stable] is released!

Can anyone post reasonable reason why it's important? Verification that file is downloaded is plain strange.

It breaks the user experience "feedback" expected in the GUI. If I drag'n drop a file into the Files menu, I expect to see something present after the upload progress bar.
by pcunite
Sat Jan 18, 2020 5:07 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

... is buying the certs themselves possible or do I need to specifically buy a NVG510 ... ?

You can purchase certs off eBay.
by pcunite
Fri Jan 17, 2020 7:22 pm
Forum: RouterBOARD hardware
Topic: Update on CRS354 Switches? (moved post)
Replies: 13
Views: 4646

Re: Update on CRS354 Switches? (moved post)

Miro, a South African distributor for MikroTik has this PDF on their website.

Nice find.
by pcunite
Fri Jan 17, 2020 7:09 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

Thank you for your hard work, I want to report a possible bug or perhaps it's AT&T causing this, but lately I can't even go past seven days of uptime before getting "rebinding" or "searching". I then need to restart the router and AT&T Gateway. Since I work night-shift my wife has been inconvenienc...
by pcunite
Tue Jan 14, 2020 2:56 am
Forum: General
Topic: How to change Queue Tree max-limit using scheduler scripts? [SOLVED]
Replies: 1
Views: 667

Re: How to change Queue Tree max-limit using scheduler scripts? [SOLVED]

Post your question under the Scripting section. There is an active group that likes to do that.
by pcunite
Fri Jan 10, 2020 4:15 pm
Forum: Beginner Basics
Topic: Change network name [SOLVED]
Replies: 7
Views: 3147

Re: Change network name [SOLVED]

You'll need to do so in the Registry.
by pcunite
Thu Jan 09, 2020 1:26 am
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 211
Views: 255079

Re: Using RouterOS to QoS your network - 2020 Edition

How to add some TCP ports and prioritize them as VOIP? can I simply do this and it will be enough? Please study the example more closely. VoIP packets on your network will not be the same as others. Using Mangle , you will choose what you need to mark. It could be via IP Address, standard SIP or RT...
by pcunite
Wed Jan 08, 2020 7:42 pm
Forum: General
Topic: Traffic shaping and VLAN's
Replies: 6
Views: 2297

Re: Traffic shaping and VLAN's

I have updated my articles on traffic shaping (QoS). See the link in my signature.
by pcunite
Tue Jan 07, 2020 4:59 pm
Forum: Wireless Networking
Topic: PTMP and VLANS
Replies: 2
Views: 1654

Re: PTMP and VLANS

It is not clear what you are asking for. See the VLAN article in my signature.
by pcunite
Tue Jan 07, 2020 12:49 am
Forum: General
Topic: CCR1009-7G Refuses to Route to Internet
Replies: 2
Views: 875

Re: CCR1009-7G Refuses to Route to Internet

Post the output (between code tags) of export file="myExport.rsc".
by pcunite
Sat Jan 04, 2020 3:18 am
Forum: General
Topic: VLANs setup (the new way)
Replies: 24
Views: 5214

Re: VLANs setup (the new way)

For the purposes of hooking up a PC on port 4 when needed for management, yes I'd thought leaving it as untagged on VLAN 99 as no-one else will have physical access to this and it was purely a quick way should I be locked out.

Just make ether4 an Access port for VLAN 99.
by pcunite
Fri Jan 03, 2020 10:20 pm
Forum: General
Topic: VLANs setup (the new way)
Replies: 24
Views: 5214

Re: VLANs setup (the new way)

Thanks for the reply, I took the "bridge PVID" part from here . And the wiki is also extremely confusing. If you look closely they are showing you multiple ways to setup management access. You don't truly want to connect to the switch with untagged traffic, do you? In the article you will see that ...
by pcunite
Fri Jan 03, 2020 6:43 pm
Forum: General
Topic: VLANs setup (the new way)
Replies: 24
Views: 5214

Re: VLANs setup (the new way)

Beautiful diagram. I love to see nicely put together information. I am grateful to mkx, sindy, and others for helping me to create the article. I'm not good at editing configurations, and I'm in a rush at the moment, so they'll have to chime in on this one. Something that caught my eye is that your ...
by pcunite
Thu Jan 02, 2020 6:04 pm
Forum: General
Topic: RB4011iGS+RM plus CAP AC - VLANs in the home
Replies: 17
Views: 2437

Re: RB4011iGS+RM plus CAP AC - VLANs in the home

Do you use interface lists more than address lists because of performance? I don't know which is more performant. But I must admit a hate with Address Lists and seeing all those ungainly things showing up there without a way to put them into neat little folders. I would assume, not having access to...
by pcunite
Thu Jan 02, 2020 5:53 pm
Forum: General
Topic: RB4011iGS+RM plus CAP AC - VLANs in the home
Replies: 17
Views: 2437

Re: RB4011iGS+RM plus CAP AC - VLANs in the home

Do you have a more secure example? I'm not the authority on firewall rules. An example would look something like this: # Sample INPUT example limiting Router exposure from the LAN (VLAN) /ip firewall filter add chain=input action=accept connection-state=established,related comment="Allow Estab & Re...
by pcunite
Thu Jan 02, 2020 5:30 pm
Forum: Scripting
Topic: New C++ Connector | MikrotikPlus
Replies: 2
Views: 2167

Re: Brand new C++ Connector

Thank you. I always like to see a C++ implementation of something. Really shows you what is needed and easier to translate to other options too. I don't have a need right now for this, but might in the future.
by pcunite
Thu Jan 02, 2020 5:11 am
Forum: General
Topic: RB4011iGS+RM plus CAP AC - VLANs in the home
Replies: 17
Views: 2437

Re: RB4011iGS+RM plus CAP AC - VLANs in the home

I've taken to downloading all of your examples and putting them in vscode with the MikroTik extension in tabs. ... the "Learn MikroTik book I bought" suggests blowing away the default firewall config and using some of their examples which are slightly different ... they drop invalid connections fir...
by pcunite
Wed Jan 01, 2020 8:04 pm
Forum: General
Topic: RB4011iGS+RM plus CAP AC - VLANs in the home
Replies: 17
Views: 2437

Re: RB4011iGS+RM plus CAP AC - VLANs in the home

Current Issues I'm trying to solve: internet access on management vlan, printer on vlan60 talk to vlan10, learn better firewall rules All equipment should be on its own VLAN which I call the Base ( MGMT ) VLAN. Do this before you do anything else, and have a PC plugged into this VLAN so you can adm...
by pcunite
Tue Dec 31, 2019 5:11 am
Forum: General
Topic: RB4011iGS+RM plus CAP AC - VLANs in the home
Replies: 17
Views: 2437

Re: RB4011iGS+RM plus CAP AC - VLANs in the home

How the heck do you get into this thing?

Isn't it fun? : - )

Plug your PC and cAP AC into a switch. Manually assign the PC an .88 network (192.168.88.123). Reset the cAP AC. When it boots back up, you can connect to it via IP or MAC.
by pcunite
Tue Dec 31, 2019 2:28 am
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 211
Views: 255079

Re: Using RouterOS to prioritize (Qos) traffic for a Class C net

I have a question to ask the admins (how do we private message you and talk about the forums)? I am planning on rewriting this article. What is the best course of action to maintain the link (which is pinned and also maybe linked elsewhere)? I would like for all posts to be deleted except for the fi...
by pcunite
Tue Dec 31, 2019 2:09 am
Forum: General
Topic: RB4011iGS+RM plus CAP AC - VLANs in the home
Replies: 17
Views: 2437

Re: RB4011iGS+RM plus CAP AC - VLANs in the home

Now for my questions with the cAP AC. I would like to have wifi on vlans. Do I need CAPSMan? For the RB4011, do I need to get rid of the default vlan of 0 on interface ethernet switch port? Assuming you are following this guide , set the cAP AC exactly as demonstrated in the article. Always think o...
by pcunite
Sun Dec 29, 2019 11:25 pm
Forum: Beginner Basics
Topic: Recommend way to block Ads with Mikrotik
Replies: 33
Views: 23484

Re: Recommend way to block Ads with Mikrotik

I found the free DNS servers at AdGuard to be very good. They seem to have more locations and the roundtrip is only 50ms. They also have some "family friendly" DNS servers which may interest some households.

Nice find. Will give them a try.
by pcunite
Sat Dec 28, 2019 7:00 pm
Forum: Beginner Basics
Topic: Recommend way to block Ads with Mikrotik
Replies: 33
Views: 23484

Re: Recommend way to block Ads with Mikrotik

@stuartkoh

Thanks for the write-up.
by pcunite
Sat Dec 28, 2019 4:14 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

i have tested that with no better results. :(

Well, sorry to hear that. We need RouterOS to have better support for 802.1p tags is what this is coming down to.
by pcunite
Sat Dec 28, 2019 6:04 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

I have just tested a config on the 3011 and it don't seem to be able to get the vlan0 working like the rb4011 does. :(

You'll have to do something like this:

/interface ethernet switch port
set ether1 vlan-mode=fallback
by pcunite
Fri Dec 27, 2019 8:34 pm
Forum: Beginner Basics
Topic: Recommend way to block Ads with Mikrotik
Replies: 33
Views: 23484

Re: Recommend way to block Ads with Mikrotik

I think pi hole is the best way to block ads. The best $10 i ever spent. Check out this thread on reddit: Update: I understand now. A Pi Zero W is plugged into a MikroTik's USB port to get power and also act like an ethernet card. The MikroTik is this person's router, and they send DNS queries to t...
by pcunite
Fri Dec 27, 2019 6:07 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

Is this configuration specific to the RB4011 with the vlan0 att RG bypass or supplicant? /interface ethernet switch port set 0 default-vlan-id=0 set 1 default-vlan-id=0 etc... I don't follow your question. The default values on an RB4011, for whatever reason as determined by MikroTik, do set defaul...
by pcunite
Fri Dec 27, 2019 6:01 pm
Forum: SwOS
Topic: Replace the Cisco 3750G switch
Replies: 4
Views: 3104

Re: Replace the Cisco 3750G switch

MikroTik does not yet offer a real multilayer switch, not with any performance you are probably going to need. Look at the size, costs, and feature set of a Cisco, and you can understand their value for a given situation. The routing decision is made with higher cost ASIC circuits.
by pcunite
Fri Dec 27, 2019 5:29 pm
Forum: General
Topic: CRS328 low space
Replies: 3
Views: 861

Re: CRS328 low space

To get a little more space, only install the minimal number of packages, not the default firmware. This will free up a MB or two.
by pcunite
Wed Dec 25, 2019 9:33 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

After all I returned it and bought an RB4011. Wish everything works fine when I receive the new model.

I will help you!
: - )
by pcunite
Wed Dec 25, 2019 9:26 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

Someone, please test with a CCR1009 (the new one without any switch chips), and see how you fair.
by pcunite
Tue Dec 24, 2019 8:29 pm
Forum: General
Topic: Queue Setup
Replies: 3
Views: 904

Re: Queue Setup

You could have each class of customer on a different VLANs. ID 10 is for 10mb customers, ID 20 for 20mb service, and so on. However you want to classify them. How else will you distinguish the traffic coming into a single concentrator? You most certainly must have something in the packets.
by pcunite
Tue Dec 24, 2019 5:30 pm
Forum: General
Topic: Queue Setup
Replies: 3
Views: 904

Re: Queue Setup

I don't have practical experience in this area, however, it would be fun to theorize how to do it. Far more knowledge people are here. How many customers, what are your bandwidth plans, and will you be handing out public IPs? Concentration switch provides a port for every customer. MikroTik will soo...
by pcunite
Tue Dec 24, 2019 4:58 pm
Forum: General
Topic: hAP CPU usage
Replies: 10
Views: 1828

Re: hAP CPU usage

Why do you recommend the RB4011 but without wireless?

There is a very long thread about wifi, on the 5Ghz side, cutting out. Try one from a dealer you can return it to. I would prefer to recommend it if possible.
by pcunite
Tue Dec 24, 2019 4:17 pm
Forum: General
Topic: hAP CPU usage
Replies: 10
Views: 1828

Re: hAP CPU usage

Right now I only see one solution. I need a more powerful router. Would it be better to get an Ethernet router and a separate access point for wireless? Yes, at the moment separate out the Wifi, as MikroTik does not have a great all-in-one unit, today anyway. So, you're looking at getting the RB401...
by pcunite
Tue Dec 24, 2019 7:46 am
Forum: General
Topic: Can't get IP address - DHCP client ignores lease offer
Replies: 7
Views: 2026

Re: Can't get IP address - DHCP client ignores lease offer

I am working on this very issue here . Since you're bypassing the retail gateway, you'll need to process 802.1P packets. Ultimately we need MikroTik to enable us to use VLAN id 0, and set the 802.1p bits on egress. For now, you can support the ingress like so: # allow ingress packets with VLAN ID 0,...
by pcunite
Tue Dec 24, 2019 7:10 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

No Switch option, this is my menu. Okay, well that makes sense as their is no switch chip. Hmmm, I don't yet know how to accept anything over the WAN interface on the CCR1009. As wojo has explained, a carefully constructed bridge with vlan-filtering=yes should do it. But I don't know why it fails f...
by pcunite
Tue Dec 24, 2019 5:12 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

Thanks for the update. Need to find the equivalent of that command, if not I'm going to return this router. There is probably a way to process VLAN 0 with the CCR1009. I just don't own one to test. In the Winbox GUI (version 3.20), do you even have a Switch menu? Some of the older CCR's did have sw...
by pcunite
Mon Dec 23, 2019 11:36 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

Update When working with the Atheros8227 switch chip, you must set vlan-mode=fallback on the WAN port. This enabled me to get the hEX PoE to work. Therefore, it seems that on some MikroTik boards, they will drop ingress packets that have a VLAN id of 0. Thus, you must account for this. Of note, I o...
by pcunite
Mon Dec 23, 2019 9:41 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

Well, I have some more info. It seems that @jack2020 is correct, there can be a configuration to where a bare interface or even a bridge, will not be able to process EAPOL with a good certificate. Acting on wojo's switch chip theory, I am testing with a hEX Poe Lite . Just to see what would happen. ...
by pcunite
Mon Dec 23, 2019 6:03 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

Here is my configuration with my modification. I removed the real MAC address for this post.

For the wireshark output, please put the VLAN and DSCP values to the left of the Info column, so we can see them.
by pcunite
Mon Dec 23, 2019 5:05 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

I tried the bridge_ont option and for some reason my authorization fails, I think something is wrong with this certificate. On lines 14,18,21 the system ask for my real ip address? I include my wireshark image. Thanks with any idea. I also tried the configuration without the bridge and I have no re...
by pcunite
Sun Dec 22, 2019 10:44 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

I added DSCP into my Wireshark columns, and it shows CS6 level for all packets coming from the ONT.

I updated my capture post to show DSCP.
by pcunite
Sun Dec 22, 2019 10:00 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

One thought -- it looks like you are on a RB4011iGS+ ( block diagram ) which has two RTL8367 switch chips. The CCR1009-7G-1C-1S+PC ( block diagram ) does not have any. Perhaps that architecture is what allows for the processing of those VLAN 0 tagged packets, whereas in my situation, I have a raw C...
by pcunite
Sun Dec 22, 2019 4:50 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

Here is my capture. Please make one for your WAN interface, so we can compare. Go to Tools / Packet Sniffer . Under the General tab set the File Name to be something.pcap . Under the Filter tab, set the Interface , then Direction any . Then press Start . When done press Stop then download the file f...
by pcunite
Sun Dec 22, 2019 8:36 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

My time is correct and synced via NTP. Can you get some captures on the wire to see if your IP traffic is encapsulated with VLAN 0 by hooking up wireshark to the MikroTik. Replying to this again, going to take a break for now. However, please test the following: Do a System / Reset Configuration un...
by pcunite
Sun Dec 22, 2019 8:18 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

Yes, and it works! I'll will update the article now. Basically, follow the article, but set the clock, under System / Clock to be the correct time and date. Then reboot. Thereafter, you can unplug the cable, release/renew IP, turn off the interface, whatever, and it will re-auth correctly. My time ...
by pcunite
Sun Dec 22, 2019 8:08 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

Well, after going around and around with this, I was finally able to get it to work with only using ether1 . The system time must be correct. Set that, then reboot. And with just the interface (no bridge), you can disconnect the ONT ethernet cable or disable that interface, bring it back and it'll ...
by pcunite
Sun Dec 22, 2019 7:34 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

Well, after going around and around with this, I was finally able to get it to work with only using ether1. The system time must be correct. Set that, then reboot.
by pcunite
Sun Dec 22, 2019 5:09 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

I remove the WAN Bridge, ether1 is alone, the only bridge that I have is for the LAN. Do I need to remove the LAN_Bridge and create a new one for the LAN? No, the LAN side is fine. What we are doing is fairly advanced here. I understand it must be confusing for you. We are only talking about WAN in...
by pcunite
Sun Dec 22, 2019 5:03 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

I change the clock with right date and time, import the certificates again, use the one with KT with the DOTx . And the same message. Thanks Okay, I think what may have happened is that I too had a bridge, then took it out of the bridge. After that, is stays working. Please try wojo scripts. I will...
by pcunite
Sun Dec 22, 2019 4:34 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

Sadly with the new Mikrotik CCR1009 I'm still have the same message "Authenticaded without server" and no IP address. I also tried the script to verify the Dot1x status and no luck. Looking for any help. Thanks Yes, I just tested my system again (resetting everything for testing) and get the same e...
by pcunite
Sat Dec 21, 2019 5:13 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

I think I have authorization but for some reason I never get an ip address. The message that I received under the dot1.x is authenticated without server . Any idea? I'm very new to this, so I don't know all the edge cases yet. The Dot1x documentation mentions it and states access to the port is gra...
by pcunite
Sat Dec 21, 2019 5:04 pm
Forum: General
Topic: Help with VLANs on CRS125-24G-1S-2HnD
Replies: 26
Views: 3400

Re: Help with VLANs on CRS125-24G-1S-2HnD

The PoE injector supplied with cAP ac is a passive one. So, powering it from RB4011 should be fine ...

mkx is correct and is confirmed in this thread. The cAP AC can be powered from the passive PoE on the RB4011's ether10 port. Thank you, mkx.
by pcunite
Fri Dec 20, 2019 11:02 pm
Forum: General
Topic: Help with VLANs on CRS125-24G-1S-2HnD
Replies: 26
Views: 3400

Re: Help with VLANs on CRS125-24G-1S-2HnD

@jthompson333, I realized I have made a potently false statement. I power an hAP AC with my RB4011's port 10. The cAP AC, however, on its incoming port, appears to require 802.3af/at PoE. The output on the RB4011 is passive. So, you may in fact require an injector! Ugh, sorry about that. However, th...
by pcunite
Fri Dec 20, 2019 10:53 pm
Forum: General
Topic: Anybody ues AT&T Gigabit Fiber with Mikrotik RouterOS?
Replies: 89
Views: 17090

Re: Anybody ues AT&T Gigabit Fiber with Mikrotik RouterOS?

@pcunite, Great article. I've followed this thread for a while ... writing down the cleverness here isn't easy. I'd suggest adding a third option, that of getting a /29 public IP block (5 IPs) from AT&T and adding that to the article. This solution has worked well for me - with the key being to use...
by pcunite
Fri Dec 20, 2019 9:47 pm
Forum: General
Topic: Help with VLANs on CRS125-24G-1S-2HnD
Replies: 26
Views: 3400

Re: Help with VLANs on CRS125-24G-1S-2HnD

Do I need an injector to power the cAP AC? Will the RB4011iGS+RM power it on its own? Down the road, could I use the CRS as an extra switch? Just debating if I should try and eBay it. Port 10 on the RB4011 will power the cAP AC, which is how I use mine. Regarding the switch, sell it now. You only w...
by pcunite
Fri Dec 20, 2019 8:14 pm
Forum: General
Topic: Help with VLANs on CRS125-24G-1S-2HnD
Replies: 26
Views: 3400

Re: Help with VLANs on CRS125-24G-1S-2HnD

As my luck would have it, isp supplies is out of stock on the RB4011iGS+RM. Any other vendors you trust?

Baltic Networks and r0c-n0c are authorized dealers in the community.
by pcunite
Fri Dec 20, 2019 8:01 pm
Forum: Beginner Basics
Topic: What is the practical difference between cAP lite and cAP?
Replies: 5
Views: 1563

Re: What is the practical difference between cAP lite and cAP?

Is it not hilarious how many SKUs they have? I hope they retire them soon. I'm trying to see the difference because you asked. The price?

:-)
by pcunite
Fri Dec 20, 2019 7:42 pm
Forum: General
Topic: Help with VLANs on CRS125-24G-1S-2HnD
Replies: 26
Views: 3400

Re: Help with VLANs on CRS125-24G-1S-2HnD

Have you had good luck buying from amazon? I have bought a few units from ispsupplies in the past- just to get some support for warranty if needed. Yes, I really like ISP Supplies. Amazon makes me leery, although I have used equipment bought from them just fine. When you have settled on your new ha...
by pcunite
Fri Dec 20, 2019 7:37 pm
Forum: General
Topic: Anybody ues AT&T Gigabit Fiber with Mikrotik RouterOS?
Replies: 89
Views: 17090

Re: Anybody ues AT&T Gigabit Fiber with Mikrotik RouterOS?

Please read my new article on this subject. This thread is no longer current.
by pcunite
Fri Dec 20, 2019 4:30 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

Supplicant Method Overview: This option is the preferred way because the ATT RG can be stowed away while MikroTik hardware performs all necessary tasks. All that is required are valid certificates extracted from your ATT RG and a native supplicant client. MikroTik includes this client via their Dot...
by pcunite
Fri Dec 20, 2019 4:28 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Re: Bypassing AT&T Residential Gateways with MikroTik

Bridge Method Overview: If you know anything about this option, then you know it has gone by several names: dumb switch bypass, eap-proxy , VLAN bypass, and true bridge mode. Well, they all share a common configuration in that they allow the ATT RG to handle the EAP-TLS protocol . After that, the R...
by pcunite
Fri Dec 20, 2019 4:27 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 188
Views: 39317

Bypassing AT&T Residential Gateways with MikroTik

Title: Bypassing AT&T Residential Gateways with MikroTik Welcome: If you have AT&T FTTH service and would like to use your MikroTik hardware to its fullest potential, this article is for you. Discover how to connect directly to the Fiber ONT device, bypassing other middleware hardware. The AT&T pro...
by pcunite
Fri Dec 20, 2019 6:03 am
Forum: General
Topic: 802.1x / dot1x client not working when interface is on a bridge
Replies: 11
Views: 3094

Re: 802.1x / dot1x client not working when interface is on a bridge

Can you share your configuration (snippets of the important parts) here? It is indeed possible that something has changed in the latest releases! Exciting. Where I got stuck last time was I *had* to place the interface on the bridge to pull DHCP due to the VLAN 0 issue. What ISP do you have and do ...
by pcunite
Fri Dec 20, 2019 5:57 am
Forum: General
Topic: Help with VLANs on CRS125-24G-1S-2HnD
Replies: 26
Views: 3400

Re: Help with VLANs on CRS125-24G-1S-2HnD

Also, if there is no way to do this with this one box, then I'm open to getting a Hex PoE, along with a cAP AC, or some other setup. Well, my big issue is that the CRS125 is not powerful enough to handle anything that will hit the CPU on it, like the routing. Also, no 5Ghz channels. How many wired ...
by pcunite
Fri Dec 20, 2019 4:22 am
Forum: General
Topic: Help with VLANs on CRS125-24G-1S-2HnD
Replies: 26
Views: 3400

Re: Help with VLANs on CRS125-24G-1S-2HnD

I made a diagram of what I was trying to do.

Looks great. Give me time to put something together.
by pcunite
Thu Dec 19, 2019 10:48 pm
Forum: General
Topic: PoE switch for Dahua IP cameras
Replies: 12
Views: 1922

Re: PoE switch for Dahua IP cameras

If there is any other MikroTik solution, not as expensive as the 8 or 16 port switch option?

Yes, I use the hEX PoE at one particular location. You'll also need the 48POW.
by pcunite
Thu Dec 19, 2019 8:31 pm
Forum: General
Topic: Anybody ues AT&T Gigabit Fiber with Mikrotik RouterOS?
Replies: 89
Views: 17090

Re: Anybody ues AT&T Gigabit Fiber with Mikrotik RouterOS?

Thanks for the info, I need to buy a new one. Any progress with using wpa_supplicant (Dot1x) to completely remove the use of the AT&T RG gateway?

Yes, I have it working now. I will make a new thread showing how to do this.
by pcunite
Thu Dec 19, 2019 8:14 pm
Forum: General
Topic: 802.1x / dot1x client not working when interface is on a bridge
Replies: 11
Views: 3094

Re: 802.1x / dot1x client not working when interface is on a bridge

@wojo

I'm able to use ether1 and get Dot1x Cert status authenticated. Also DHCP client on ether1 pulled an IP, all without putting ether1 on a bridge. Everything seems to be working fine. Using firmware 6.46.1 on an RB4011. Can you update this thread with your success?
by pcunite
Wed Dec 18, 2019 11:51 pm
Forum: General
Topic: Help with VLANs on CRS125-24G-1S-2HnD
Replies: 26
Views: 3400

Re: Help with VLANs on CRS125-24G-1S-2HnD

Port 1 - i.e. ether1-gateway is hooked up to a Motorola cable modem.

How much Internet bandwidth are you working with?
by pcunite
Wed Dec 18, 2019 9:15 pm
Forum: General
Topic: Help with VLANs on CRS125-24G-1S-2HnD
Replies: 26
Views: 3400

Re: Help with VLANs on CRS125-24G-1S-2HnD

You are a very patient individual, and on those grounds, you've earned the right to some help. Here's the thing though. You shouldn't be using that hardware. That is were our conversation will begin. Now, let's see if that is true. Can you draw a diagram for us? I need to know where and how this dev...
by pcunite
Tue Dec 17, 2019 7:47 pm
Forum: Beginner Basics
Topic: Queue Tree with Child Queues [SOLVED]
Replies: 5
Views: 1733

Re: Queue Tree with Child Queues [SOLVED]

Make sure you don't have FastTrack enabled.
by pcunite
Tue Dec 17, 2019 7:26 pm
Forum: Beginner Basics
Topic: FTTH very slow download speed (upload ok)
Replies: 15
Views: 4760

Re: FTTH very slow download speed (upload ok)

... while doing speed tests the CPU never goes over 20% ... now 34Mbps is the limit?

What interface? Is your PC connected via Wifi?
by pcunite
Tue Dec 17, 2019 5:26 pm
Forum: General
Topic: VLAN configuration with 2 routers [SOLVED]
Replies: 1
Views: 507

Re: VLAN configuration with 2 routers [SOLVED]

MikroTik is very a very different but rewarding product. You'll need to devote about 100 hours to study their way of doing things. Start here. We'll chat again in about in two weeks.
by pcunite
Tue Dec 17, 2019 5:26 pm
Forum: Beginner Basics
Topic: Help setup the Internet connection
Replies: 7
Views: 1248

Re: Help setup the Internet connection

MikroTik is very a very different but rewarding product. You'll need to devote about 100 hours to study their way of doing things. Start here. We'll chat again in about in two weeks.
by pcunite
Tue Dec 17, 2019 5:21 pm
Forum: General
Topic: Today - Linus tech tips, MIKROTIK !!!!!
Replies: 3
Views: 2606

Re: Today - Linus tech tips, MIKROTIK !!!!!

Linus will help MikroTik to bring in a new demographic. They need home users, not just hard core networking guys. Could really use an intro tutorial for how to setup MikroTik in a home environment. Would be happy to produce such a series of articles. My first exposure to RouterOS was very confusing....
by pcunite
Tue Dec 17, 2019 4:41 pm
Forum: General
Topic: RB2011UiAS-RM slow throughput
Replies: 2
Views: 942

Re: RB2011UiAS-RM slow throughput

The RB2011 is a very under-powered device. Please upgrade to the RB3011 or RB4011.
by pcunite
Tue Dec 17, 2019 4:34 am
Forum: General
Topic: Which Mikrotik rack router is quiet for home use?
Replies: 3
Views: 818

Re: Which Mikrotik rack router is quiet for home use?

How much bandwidth do you have?
by pcunite
Mon Dec 16, 2019 8:42 pm
Forum: Beginner Basics
Topic: FTTH very slow download speed (upload ok)
Replies: 15
Views: 4760

Re: FTTH very slow download speed (upload ok)

The RB2011 does not have CPU power for your new Internet service. Please consider the RB4011.
by pcunite
Mon Dec 16, 2019 8:41 pm
Forum: General
Topic: port mapping outside to inside, but "preserve" destination address [SOLVED]
Replies: 13
Views: 1471

Re: port mapping outside to inside, but "preserve" destination address [SOLVED]

Is this a custom protocol or could you use something in the Service Ports nat helper section?
by pcunite
Mon Dec 16, 2019 5:27 pm
Forum: General
Topic: Anybody ues AT&T Gigabit Fiber with Mikrotik RouterOS?
Replies: 89
Views: 17090

Re: Anybody ues AT&T Gigabit Fiber with Mikrotik RouterOS?

I have the Mikrotik CRS109-8G-1S-2hNd , with AT&T fiber. The script works perfectly ... I have a problem with my connection. My Internet service is 300MB, when I do a speed test I only received 120MB, and the CPU is 100%. The CRS109 is very under-powered and you will need to consider something like...
by pcunite
Mon Dec 16, 2019 5:22 pm
Forum: General
Topic: Rb ah 1100 x2 Upgrade recommendations
Replies: 6
Views: 1411

Re: Rb ah 1100 x2 Upgrade recommendations

here is my router config Setting up firewall rules is a personal thing, so I won't tell you how to manage your packets. There are some things to understand about how to use hardware. I mean, do we make it easy on our routers or do we buy faster hardware? That's a personal decision. What does concer...
by pcunite
Sun Dec 15, 2019 8:45 pm
Forum: General
Topic: Rb ah 1100 x2 Upgrade recommendations
Replies: 6
Views: 1411

Re: Rb ah 1100 x2 Upgrade recommendations

To be honest, it’s pure speculation that the config is the cause. But I’m happy to send you my config to look at. Can I email it?

I meant that you should post it here (sanitized with sensitive information removed and IPs changed) so the forum can look at it as well.
by pcunite
Sun Dec 15, 2019 4:26 pm
Forum: General
Topic: Vlan/loop issue?
Replies: 3
Views: 919

Re: Vlan/loop issue?

Please make some type of diagram. That might help you and us to reason about it.
by pcunite
Sun Dec 15, 2019 4:25 pm
Forum: General
Topic: rb4011 switch VLAN
Replies: 3
Views: 1413

Re: rb4011 switch VLAN

The RB4011 CPU is often powerful enough to switch your traffic. So, hardware offloading may not be a requirement for you. Is every port pushing 1G traffic all the time? Probably not. With regards to VLAN'ing, you can set it up as shown here.
by pcunite
Sun Dec 15, 2019 4:23 pm
Forum: Beginner Basics
Topic: Newbe HowTo VLAN + Mesh
Replies: 2
Views: 1072

Re: Newbe HowTo VLAN + Mesh

Okay, that's a big block of text there. Please make a diagram of your network. You don't need to mesh to handle roaming. Also restate a little bit what you're needing like this: I want to move to MikroTik for all my wireless AP units. How do I configure them when I don't have a MikroTik branded rout...
by pcunite
Sun Dec 15, 2019 4:18 pm
Forum: General
Topic: Rb ah 1100 x2 Upgrade recommendations
Replies: 6
Views: 1411

Re: Rb ah 1100 x2 Upgrade recommendations

Well, the CCR1009 line is where you might start looking. However, I'm interested to see your configuration and what makes it so complex as to require so much more CPU.
by pcunite
Sat Dec 14, 2019 9:22 pm
Forum: Wireless Networking
Topic: cAP AC 802.11N Problem
Replies: 10
Views: 3355

Re: cAP AC 802.11N Problem

My recommendation is to ignore the previous poster's off the mark suggestions. The OP is not stewpid ! He knows there is a 5ghz network available, if he SO CHOOSES to use it. Arg ... now I do agree he should use vLANS for his networks!! ;-p The OP has come to the right place. Indeed, when we are do...
by pcunite
Sat Dec 14, 2019 5:50 pm
Forum: Wireless Networking
Topic: cAP AC 802.11N Problem
Replies: 10
Views: 3355

Re: cAP AC 802.11N Problem

This should turn out to be a fun thread. Let's help you create the perfect configuration for your needs. You do not need to return the cAP AC. That is a benefit of MikroTik, it will let you tweak and tweak and tweak ! So, start over and tell us a little more. You only want to use 2.4Ghz? How do you ...
by pcunite
Sat Dec 14, 2019 2:50 am
Forum: Scripting
Topic: List number of connections per IP
Replies: 13
Views: 3458

Re: List number of connections per IP

Thanks, I'd like to avoid writing to a file.

Right, run my solution. It prints to the screen the way you wanted.
by pcunite
Sat Dec 14, 2019 1:42 am
Forum: Scripting
Topic: List number of connections per IP
Replies: 13
Views: 3458

Re: List number of connections per IP

Okay, this is not perfect, but does display the data the way you want. Note that variables are limited to 4096 bytes. So, you may have to loop this across a couple of different variables. { # Declare main variable to hold all the data we care about :local Data; /ip dhcp-server lease :foreach i in=[f...
by pcunite
Sat Dec 14, 2019 1:18 am
Forum: Scripting
Topic: List number of connections per IP
Replies: 13
Views: 3458

Re: List number of connections per IP

This line, although it should be a variable, instead prints the number of connections. :local con [/ip firewall connection print count-only where src-address~"$adr"]; Yes. And I did misspeak. It actually does store the result as a variable. What is happening, and that I don't know how to turn off, ...
by pcunite
Sat Dec 14, 2019 12:20 am
Forum: Scripting
Topic: List number of connections per IP
Replies: 13
Views: 3458

Re: List number of connections per IP

Hmmm, it looks like the output of print count-only can not be stored in a variable. { /ip dhcp-server lease :foreach i in=[find] do={ # declare and set variables :local adr "$[get value-name=address $i]"; :local host "$[get value-name=host-name $i]"; :local con [/ip firewall connection print count-o...
by pcunite
Fri Dec 13, 2019 10:20 pm
Forum: Scripting
Topic: List number of connections per IP
Replies: 13
Views: 3458

Re: List number of connections per IP

What you're looking for is Concatenation Operators.
by pcunite
Fri Dec 13, 2019 7:29 pm
Forum: General
Topic: DNS Cache
Replies: 21
Views: 3820

Re: DNS Cache

... not that Christmas tree of strange rules that end in nothing.

How seasonably of you!
by pcunite
Fri Dec 13, 2019 6:26 pm
Forum: Forwarding Protocols
Topic: Routing Issue : Redirect Host(New nexthop: Gateway IP)
Replies: 12
Views: 8981

Re: Routing Issue : Redirect Host(New nexthop: Gateway IP)

Although not good, but also learning with mistakes.

Same here. Still learning and don't know it all.
by pcunite
Fri Dec 13, 2019 6:00 pm
Forum: Forwarding Protocols
Topic: Routing Issue : Redirect Host(New nexthop: Gateway IP)
Replies: 12
Views: 8981

Re: Routing Issue : Redirect Host(New nexthop: Gateway IP)

Thank you for the diagram. Are all of these ip addresses for real, or just example ones you're providing us with? The x.x.0.5 router should be routing a different ip scheme behind it like 192.168. 88 .0. Otherwise, you will need to manually (I think) maintain an optimal route table. Change you netwo...
by pcunite
Fri Dec 13, 2019 5:12 am
Forum: General
Topic: Mikrotik Merchandise
Replies: 2
Views: 848

Re: Mikrotik Merchandise

I know ... it feels wrong to take their print resolution logos (press kit images), and make it yourself. "Where you'd get that cool MikroTik hoodie?!" ... "I created it myself from CustomHoodies dot com".
by pcunite
Thu Dec 12, 2019 11:04 pm
Forum: RouterBOARD hardware
Topic: MikroTik! Please, make G(E)PON ONU!
Replies: 11
Views: 6008

Re: MikroTik! Please, make G(E)PON ONU!

Anyone have any experience with XGS-PON? It will coming into an area I support. Hoping I won't have to use a gateway device. Media converter or a direct fiber link connection is the hope.
by pcunite
Thu Dec 12, 2019 6:53 pm
Forum: RouterBOARD hardware
Topic: 3+ Wired, Routable ports + Wifi
Replies: 3
Views: 2664

Re: 3+ Wired, Routable ports + Wifi

I don't want switched ports. I want real, routable ports. I don't want to use vlan tagging or anything like that to get around not having real routable ports. That's just the ugly software-equivalent of plugging in another usb-eth adapter. I want (the equivalent of) /dev/eth0, /dev/eth1, etc. witho...
by pcunite
Thu Dec 12, 2019 6:35 pm
Forum: General
Topic: Devices are not reliably responding to ARP requests / Wifi Power Saving
Replies: 11
Views: 2776

Re: Devices are not reliably responding to ARP requests / Wifi Power Saving

It's not uncommon - Cisco call it Unicast mode as documented here.

I wonder how this affects performance when a lot of clients are idling/sending on the AP.
by pcunite
Thu Dec 12, 2019 5:00 pm
Forum: General
Topic: 802.1x / dot1x client not working when interface is on a bridge
Replies: 11
Views: 3094

Re: 802.1x / dot1x client not working when interface is on a bridge

I'm able to successfully authenticate with a 802.1x server using RouterOS on a bare interface, but once that interface is a part of a bridge (with default settings) I cannot successfully complete the EAPOL process. I hope to work on this soon, to update my current procedure . Can you share your con...
by pcunite
Thu Dec 12, 2019 3:20 pm
Forum: Beginner Basics
Topic: CRS1xx/2xx suuuuuuuuuuuuucks. Help with configuring VLANs?
Replies: 4
Views: 1600

Re: CRS1xx/2xx suuuuuuuuuuuuucks. Help with configuring VLANs?

Until the CRS3xx style of switches has a valid offering across the full MikroTik product range, we still have to work with these older systems. I don't have time to create an exact configuration for you right now, however, here is how to do it. I probably setup my management network different from y...
by pcunite
Thu May 16, 2019 5:45 am
Forum: Announcements
Topic: v6.43.16 [long-term] is released!
Replies: 12
Views: 13432

Re: v6.43.16 [long-term] is released!

Fast fix, thanks MikroTik.
by pcunite
Tue Apr 30, 2019 7:32 pm
Forum: Beginner Basics
Topic: Setting up Port Isolation, in addition to web traffic logging/monitoring?
Replies: 4
Views: 696

Re: Setting up Port Isolation, in addition to web traffic logging/monitoring?

In addition to OpenDNS, also take a look at cleanbrowsing.org and their offering.
by pcunite
Fri Apr 26, 2019 8:49 pm
Forum: Announcements
Topic: v6.44.3 [stable] is released!
Replies: 123
Views: 45153

Re: v6.44.3 [stable] is released!

I have been running RB4011 for more than a month and never had this reported issue on wlan. Not even when there was no client connected to it for a few days. So it seems it is not happening on all units. Can you export your config (between code tags) for this thread to see what you might be doing d...
by pcunite
Fri Apr 26, 2019 8:46 pm
Forum: Wireless Networking
Topic: RB4011iGS+5HacQ2HnD-IN 5Ghz disappearing
Replies: 22
Views: 7516

Re: RB4011iGS+5HacQ2HnD-IN 5Ghz disappearing

I changed wlan1's MAC address, but this doesn't' fix the problem. 5Ghz still randomly disappearing. Log is clean.

You can't change it on your own, there is an internal problem. This is just a sign.
by pcunite
Fri Apr 26, 2019 2:56 pm
Forum: General
Topic: Feature Request: 802.1X over ethernet
Replies: 40
Views: 14149

Re: Feature Request: 802.1X over ethernet

Client side support added in 6.45beta37: /interface dot1x client

Thank you.
by pcunite
Fri Apr 26, 2019 2:55 pm
Forum: Wireless Networking
Topic: Hotspot Configuration
Replies: 4
Views: 1619

Re: Hotspot Configuration

There is an issue with iPhones and using the HotSpot 'address-pool' option. It is a NAT helper. Set it to none and see if your issue is resolved.
by pcunite
Fri Apr 26, 2019 2:52 pm
Forum: RouterBOARD hardware
Topic: RB4011: wlan1 disabling itself [SOLVED]
Replies: 302
Views: 70609

Re: RB4011: wlan1 disabling itself [SOLVED]

After today's 5ghz experiments, the following can be summarized: 1. switch chip does not work in bridge mode. 2. Mac adresss duplication on sfp and wlan1 3. curve driver for wlan1, does not work on 4 chains. 4. 160mhz not working. - This is superfluous, here 802.11ac does not work correctly. Excell...
by pcunite
Thu Apr 25, 2019 9:03 pm
Forum: Beginner Basics
Topic: wpa_supplicant on rb4011
Replies: 7
Views: 1599

Re: wpa_supplicant on rb4011

I use the RB4011 and am also looking forward to something like wpa_supplicant working. You can see my current work around at the moment here. Only recently has MikroTik announced support for something that might allow us to host our own certificates. It is not ready for use yet.
by pcunite
Thu Apr 25, 2019 8:49 pm
Forum: SwOS
Topic: VLan Type enabled vs strict
Replies: 3
Views: 2954

Re: VLan Type enabled vs strict

Why is so complicated to get VLANs right on SwOS? There should only exist 3 cases: Trunk, Hybrid (with a PVID), and Access. It should not be that hard.

I agree.
by pcunite
Tue Apr 23, 2019 9:25 pm
Forum: Beginner Basics
Topic: Noobish Requesting Help - VLANed home network [SOLVED]
Replies: 15
Views: 1756

Re: Noobish Requesting Help - VLANed home network [SOLVED]

Read through this post and find the example that mirrors your situation I'll look this through, initial review says it looks a lot like the posts and tutorials I've been reading, but I will always read more! This might be a good time to mention the Saddle Ridge Hoard : A couple found $10 million in...
by pcunite
Tue Apr 23, 2019 12:16 am
Forum: RouterBOARD hardware
Topic: CRS328-24P-4S+RM - 24x7 fans or temperature sensitive?
Replies: 64
Views: 18308

Re: CRS328-24P-4S+RM - 24x7 fans or temperature sensitive?

You can mount two CRS112 in 1U right? Since they're exactly half U?

It measures 200mm wide (7.875 inch). Would be nice to have a 1U case that holds both.
by pcunite
Mon Apr 22, 2019 8:20 pm
Forum: RouterBOARD hardware
Topic: RB4011: wlan1 disabling itself [SOLVED]
Replies: 302
Views: 70609

Re: RB4011: wlan1 disabling itself [SOLVED]

I know its frustrating guys. I will say that the RB4011 router only model is very nice. The Wifi model, at the moment, is just not ready.
by pcunite
Mon Apr 22, 2019 8:18 pm
Forum: RouterBOARD hardware
Topic: CRS328-24P-4S+RM - 24x7 fans or temperature sensitive?
Replies: 64
Views: 18308

Re: CRS328-24P-4S+RM - 24x7 fans or temperature sensitive?

There is no any device with passive cooling from any vendor, right?

You might be better served with two CRS112. I use one for my PoE equipment. Very happy with it. Note you'll also need to purchase the 48POW or the 48V2A96W.
by pcunite
Fri Apr 19, 2019 7:10 pm
Forum: Beginner Basics
Topic: HotSpot with userman as login page
Replies: 9
Views: 1643

Re: HotSpot with userman as login page

It seems , however, once signup is done, you are immediately redirected to http://routerip/user that is a page you cannot find (to be edited) among files .... (am I wrong ?) Yes, sorry at the moment I'm out of pocket. But, I just wanted to give you confidence it can be done. There is a flow, I thin...
by pcunite
Fri Apr 19, 2019 6:18 pm
Forum: General
Topic: CRS326 + multiple vlans with hardware offloading and non-vlan ports
Replies: 5
Views: 1296

Re: CRS326 + multiple vlans with hardware offloading and non-vlan ports

Yeah, the dude pcunite needs to change his nick to be vlan unite ;-) more to the point, MT should pay him to do a proper user manual!! Thank you. I would be very happy to do the documentation. I think MikroTik has a great product with enthusiastic users on the forums. We form a team. Would love to ...
by pcunite
Thu Apr 18, 2019 10:03 pm
Forum: Wireless Networking
Topic: CAP AC Vs HAP AC2
Replies: 5
Views: 3408

Re: CAP AC Vs HAP AC2

An important difference - cAP AC has separate antennas for each chain /4/ and better wireless performance for that! hAP AC2 has 2 combined antennas for both frequencies!

Thank you, I answered too quickly before researching thoroughly.
by pcunite
Thu Apr 18, 2019 7:45 pm
Forum: Wireless Networking
Topic: CAP AC Vs HAP AC2
Replies: 5
Views: 3408

Re: CAP AC Vs HAP AC2

The cAP ac and hAP ac² are basically identical with regards to wifi clients. Their differences are that the hAP has ports and the cAP does not.
by pcunite
Thu Apr 18, 2019 7:35 pm
Forum: General
Topic: CRS328: Searching for infos / pointers about hardware COS DSCP
Replies: 8
Views: 1552

Re: CRS328: Searching for infos / pointers about hardware COS DSCP

Throughput rate limit is not QoS!!! I don't understand why they're talking about QoS in that way... To me, QoS is priority level. I saw VLAN-Priority in the documentation but didn't find anything about how the switch will effectively handle this (if at all). Okay, read this . Does this apply better?
by pcunite
Thu Apr 18, 2019 7:31 pm
Forum: Beginner Basics
Topic: HotSpot with userman as login page
Replies: 9
Views: 1643

Re: HotSpot with userman as login page

Just add a meta redirect tag at the top of the final landing page in the flow. There is also dst. Read here, it was very helpful to me.
by pcunite
Thu Apr 18, 2019 3:52 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 101405

Re: v6.45beta [testing] is released!

dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only); I hope I can use this to authenticate to AT&T fiber services directly. I'll need a certificate, but that's obtainable. @pcunite - Can you provide a pointer to how to obtain the certificate? Currently, Still need to ...
by pcunite
Thu Apr 18, 2019 3:06 pm
Forum: Beginner Basics
Topic: HotSpot with userman as login page
Replies: 9
Views: 1643

Re: HotSpot with userman as login page

it would be nice to do it all inside the same routerboard machine. Yes, it would. But there is no server side scripting on the MikroTik. You can do it all now on the MikroTik, but you can not process the data the user gives you. It's not about simply logging them in, don't you want to react to the ...
by pcunite
Thu Apr 18, 2019 12:39 am
Forum: General
Topic: CRS326 + multiple vlans with hardware offloading and non-vlan ports
Replies: 5
Views: 1296

Re: CRS326 + multiple vlans with hardware offloading and non-vlan ports

See the VLAN link in my signature. I've implemented it with great success in my environments.
by pcunite
Thu Apr 18, 2019 12:23 am
Forum: General
Topic: CRS328: Searching for infos / pointers about hardware COS DSCP
Replies: 8
Views: 1552

Re: CRS328: Searching for infos / pointers about hardware COS DSCP

I have only one long CAT6 cable link (so forget about 10 Gbps). ... I went to the switch menu "port" tab and tried to set "vlan mode" to "secure" (for the hEX router port): whatever i do in this menu end up with "VLAN mode not supported". So, for now it doesn't seem i can do hardware VLAN / QoS. An...
by pcunite
Wed Apr 17, 2019 9:17 pm
Forum: General
Topic: CRS328: Searching for infos / pointers about hardware COS DSCP
Replies: 8
Views: 1552

Re: CRS328: Searching for infos / pointers about hardware COS DSCP

I've never worked in a network that was so saturated that the Trunk port on a Switch was a place of contention for VoIP traffic. I always handle this at the Router. However, I'm sure there are those that need to think about this. I was planning to work on a 20+ IP camera network in which the plan wa...
by pcunite
Wed Apr 17, 2019 5:36 pm
Forum: Beginner Basics
Topic: HotSpot with userman as login page
Replies: 9
Views: 1643

Re: HotSpot with userman as login page

I'm doing this. User hits the Hotspot. I redirect them immediately to an external Linux server running PHP. That redirect, is a POST containing their MAC, IP, etc. The page their redirected to now asks for their email address. When they submit their email, I post them back to the HotSpot server usin...
by pcunite
Sat Apr 13, 2019 4:55 pm
Forum: General
Topic: What is your gaming config?
Replies: 2
Views: 1536

Re: Config Needed for 2011 gaming Router

You didn't state your bandwidth, but generally the RB2011 is not fast enough. Use the hAP AC2 or RB4011. Then you can throw QoS rules at it and it won't bog down under load.
by pcunite
Sat Apr 13, 2019 4:51 pm
Forum: Beginner Basics
Topic: Router for my new home!
Replies: 14
Views: 2184

Re: Router for my new home!

Recommending RB951Ui-2HnD in year 2019 is ridiculous. This model has been here for ages. It does not have gigabit ports, CPU has just one core, wifi is just 2.4GHz. RB951Ui-2nD is even worse ... They need to move these archaic models, and others, to the archive section. Confusing for newcomers to s...
by pcunite
Fri Apr 12, 2019 11:05 pm
Forum: Announcements
Topic: v6.45beta [testing] is released!
Replies: 305
Views: 101405

Re: v6.45beta [testing] is released!

!) dot1x - added support for IEEE 802.1X Port-Based Network Access Control (CLI only);

I hope I can use this to authenticate to AT&T fiber services directly. I'll need a certificate, but that's obtainable.
by pcunite
Wed Apr 10, 2019 5:37 am
Forum: Beginner Basics
Topic: Using RouterOS to VLAN your network
Replies: 144
Views: 79318

Re: Using RouterOS to VLAN your network

One thing MikroTik discusses that you don't mention is hybrid ports ... I believe they say this is not a safe way to operate security wise in conclusion but it wasn't clear. If you trust your equipment, yourself, and your end users, you can use hybrid ports. You're giving a device the ability to se...
by pcunite
Tue Apr 09, 2019 8:38 pm
Forum: General
Topic: Anybody ues AT&T Gigabit Fiber with Mikrotik RouterOS?
Replies: 89
Views: 17090

Re: Anybody ues AT&T Gigabit Fiber with Mikrotik RouterOS?

Do you still need to set the RG into bypass mode or should I reset that to defaults, too?

Don't know, I think it does not matter what the RG is doing if you intend to power it off. Disable the Wifi feature would be at least one suggestion.
by pcunite
Tue Apr 09, 2019 6:37 am
Forum: Beginner Basics
Topic: Need Help Configuring Hotspot & AP VLAN
Replies: 10
Views: 1527

Re: Need Help Configuring Hotspot & AP VLAN

So, would I apply this same configuration on the SWITCH? What would you recommend for the access points?

Access points follow the modern recommendation. The above example, is strictly for CRS1xx switches.
by pcunite
Thu Apr 04, 2019 4:40 pm
Forum: General
Topic: v6 RC and v7 BETA
Replies: 126
Views: 32404

Re: v6 RC and v7 BETA

All I can say is that development of v7 has picked up in the last few months, more than ever. While I can't promise anything stable, it is pretty safe to say, that some kind of public test release (like beta for specific platforms) could be expected this year. The chances of that happening are now ...
by pcunite
Thu Apr 04, 2019 7:01 am
Forum: Beginner Basics
Topic: Need Help Configuring Hotspot & AP VLAN
Replies: 10
Views: 1527

Re: Need Help Configuring Hotspot & AP VLAN

You are using a CRS1xx switch. Therefore VLAN configuration is different, at least for the time being, from what CRS3xx and faster processors can do. However, do read the post that anav linked for you. This way you will have the current and modern MikroTik recommendations in your head. It will make ...
by pcunite
Tue Apr 02, 2019 5:34 am
Forum: Wireless Networking
Topic: cAP-ac Throughput & High Ping Problems
Replies: 33
Views: 6912

Re: cAP-ac Throughput & High Ping Problems

I have also tried to manually decrease the TX power on the radios in the cAP-ac units, but when I do, I get an error that the feature is not supported.

This is done via the Antenna Gain setting.
by pcunite
Sat Mar 30, 2019 2:43 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 51081

Re: UKNOF 43 CVE

I want to reiterate what I've stated elsewhere: I believe that all modern software companies need to implement a certain type of business process, known as Lean-Agile . Bugs will happen, no reasonable person is upset about that. Rather it is the release cadence, release channel, and review process t...
by pcunite
Fri Mar 29, 2019 2:15 pm
Forum: General
Topic: Ring of switches and Vlans
Replies: 8
Views: 1512

Re: Ring of switches and Vlans

Make a list of every MAC address you have, on the interfaces. Then, you should probably set admin-mac to hard code something that will be unique.
by pcunite
Thu Mar 28, 2019 3:28 pm
Forum: General
Topic: UKNOF 43 CVE
Replies: 223
Views: 51081

Re: UKNOF 43 CVE

I highly recommend MikroTik look into implementing something like the Safe 4.5 Lean-Agile framework for their company. It will help to get a handle on the continuous release cycle that is their type of company. This is a business process for how to organize, coordinate, and manage simultaneous hardw...
by pcunite
Wed Mar 27, 2019 11:40 pm
Forum: RouterBOARD hardware
Topic: RB4011 Metal temperature is really hot
Replies: 52
Views: 15166

Re: RB4011 Metal temperature is really hot

I have the non-wifi model. System/Health reports 40C. Another model I manage shows the same.
by pcunite
Mon Mar 25, 2019 3:49 pm
Forum: Beginner Basics
Topic: CRS328-24P-4S+RM as an internet router
Replies: 6
Views: 1032

Re: CRS328-24P-4S+RM as an internet router

I want what you want, a true switch/router combo. But the CRS328 is not that. I mean, sure, for a really slow Internet connection it might handle it, but serious routing? No.
by pcunite
Mon Mar 25, 2019 3:43 pm
Forum: Announcements
Topic: Suggestions requested: general hotspot controller improvements in functionality
Replies: 11
Views: 7445

Re: Suggestions requested: general hotspot controller improvements in functionality

We are looking for ideas on how to improve our hotspot controller. How are you using the MikroTik Hotspot software? Have you encountered lack of a specific feature? I'm implementing a HotSpot for someone right now. For my needs, I would like a PHP processor (or some type of back-end scripting suppo...
by pcunite
Sat Mar 23, 2019 11:11 pm
Forum: RouterBOARD hardware
Topic: CRS328-24P-4S+RM idle power consumption
Replies: 5
Views: 3155

Re: CRS328-24P-4S+RM idle power consumption

I have been testing the 8 port CRS112-8P-4S-IN and its power characteristics with a P4400 Kill-A-Watt meter . Firmware 6.43.13 was installed. Using the included 28V 3.4A power adapter. Power draw 1) 4 watts, when powered on, nothing plugged into ports, the idle state. 2) 5 watts, when one PC plugged...
by pcunite
Mon Mar 18, 2019 5:08 am
Forum: General
Topic: Putty updated to 0.71
Replies: 12
Views: 1370

Re: Putty updated to 0.71

Where do I install the putty package on my winbox??

Putty is a 3rd party utility that runs on Windows. You use it to connect to the SSH server instance on the MikroTik.
by pcunite
Sat Mar 16, 2019 12:01 am
Forum: General
Topic: HOTSPOT login https error
Replies: 11
Views: 2220

Re: HOTSPOT login https error

Could you share your configuration? I would be grateful.

See here in this post.
by pcunite
Fri Mar 15, 2019 5:50 pm
Forum: General
Topic: HOTSPOT login https error
Replies: 11
Views: 2220

Re: HOTSPOT login https error

Just make sure nothing is in the walled garden. As long as the user is using a modern browser or phone, they should get the prompt for the portal. This has been my experience too in testing. I only use HTTP CHAP and Cookie for my Hotspot server login settings, not HTTP(s). I will have more live exp...
by pcunite
Fri Mar 15, 2019 4:05 am
Forum: General
Topic: 6.44.1 Broke Stuff Need to Downgrade to 6.44
Replies: 4
Views: 1058

Re: 6.44.1 Broke Stuff Need to Downgrade to 6.44

When I'm testing, I like to update the MikroTik, update the firmware, them reset it without any configuration. Then I add back in my own script. That seems to fix issues others seem to have. Try that, then see if you still have found a bug.
by pcunite
Fri Mar 15, 2019 3:56 am
Forum: Beginner Basics
Topic: Hotspot wifi and Lan users
Replies: 13
Views: 2698

Re: Hotspot wifi and Lan users

Awesome, pcunite when complete and functioning, can you post the config of both please! Here you go. While creating this example, I also noticed some areas that might be confusing in my other VLAN examples. So, I'll be updating those to better show how the BASE_VLAN should be implemented, as I do h...
by pcunite
Wed Mar 13, 2019 6:50 pm
Forum: Beginner Basics
Topic: Hotspot wifi and Lan users
Replies: 13
Views: 2698

Re: Hotspot wifi and Lan users

I'm in the process of setting this up for someone. I prefer the use of a separate device to function as the Hotspot (captive portal) server. I'm using the hEX S for this purpose with an RB4011 as the main router. You need VLANs, of course, such that Guests accessing the Guest SSID are on a VLAN of t...
by pcunite
Fri Mar 08, 2019 4:13 am
Forum: The Dude
Topic: Crap on HAP AC2
Replies: 4
Views: 2367

Re: Crap on HAP AC2

Perhaps a bad unit or config? I have one working well.
by pcunite
Thu Mar 07, 2019 11:21 pm
Forum: Beginner Basics
Topic: Using RouterOS to VLAN your network
Replies: 144
Views: 79318

Re: Using RouterOS to VLAN your network

I lose connectivity to my cAP ACs and router, they no longer show up in Winbox. How do I ensure all devices are still reachable? Winbox accessibility and visibility are two different features that are possible with MikroTik products. When using VLANs, the Neighbor Discovery protocol will not show d...
by pcunite
Thu Mar 07, 2019 7:08 pm
Forum: Beginner Basics
Topic: Using RouterOS to VLAN your network
Replies: 144
Views: 79318

Re: Using RouterOS to VLAN your network

The rest of the discussion has not been resolved. Many are having problems trying to implement your examples and many issues stem from the lack of clarity on pvid=1 vs pvid=99 . In other words, what is being assigned to the bridge, and what affect it has on reaching devices such as router, switches...
by pcunite
Thu Mar 07, 2019 6:35 pm
Forum: General
Topic: Wireless Recommendation Wanted
Replies: 7
Views: 992

Re: Wireless Recommendation Wanted

The cAP AC and the hAP ac² are the best. The hAP has 5 ports if you need them. These units are not outdoor rated, if you need that you'll need to consider the wAP AC.
by pcunite
Thu Mar 07, 2019 6:15 pm
Forum: Beginner Basics
Topic: Using RouterOS to VLAN your network
Replies: 144
Views: 79318

Re: Using RouterOS to VLAN your network

1) What the heck is BASE_VLAN? 2) Why assign ether7 to be an access port? The BASE_VLAN is a special network for accessing the MikroTik hardware. A network consists of routers, switches, and APs, so if every device has a BASE_VLAN interface, you can Winbox them from this special MGMT network. The f...
by pcunite
Fri Mar 01, 2019 3:59 pm
Forum: Beginner Basics
Topic: Introduction to RouterOS documentation
Replies: 13
Views: 1493

Re: Introduction to RouterOS documentation

@csaunders72,

Pull up a chair and plan to stay awhile here in the forums. The documentation makes perfect sense, after several years of using the products. : - )
by pcunite
Sat Feb 23, 2019 9:09 pm
Forum: General
Topic: Hotspot Apple Login Page HELP!
Replies: 20
Views: 5040

Re: Hotspot Apple Login Page HELP!

We're in 2019 and mobile operators sell 50GB/month for 5€, who needs hotspots anymore?

Hotels, mainly. All those laptops and tablets. Clients want free wifi, so before they hit the internet, you've gotten see that login page.
by pcunite
Sat Feb 23, 2019 8:51 pm
Forum: Beginner Basics
Topic: Using RouterOS to VLAN your network
Replies: 144
Views: 79318

Re: Using RouterOS to VLAN your network

I made the big switch tonight using vlan11 vs. vlan1 for my homelan. However, I can no longer access my capacs to manage them. Remember we do not tag the bridge on the capac for some reason LOL. So why can I not, with my pc being on vlan11, use winbox to see capacs? I see the router just fine! It i...
by pcunite
Sat Feb 23, 2019 7:21 pm
Forum: General
Topic: Advanced VLAN setup HAP AC RouterOS
Replies: 9
Views: 1694

Re: Advanced VLAN setup HAP AC RouterOS

See the link in my signature. I also recommend you go with the RB4011, (the hAP ac² might work) so that you have enough CPU power to use the unit as a switch. It all depends on how much traffic goes from your PC to a local NAS or whatever.
by pcunite
Sat Feb 23, 2019 6:43 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 211
Views: 255079

Re: Using RouterOS to prioritize (Qos) traffic for a Class C net

Version 3, running smooth @bolean, How does this test compared to what you're doing? https://i.ibb.co/r2xSRfr/Queue-Tree3.png /queue tree # DOWN add name=DOWN max-limit=90M parent=BR_LAN queue=default add name="1. VOIP" packet-mark=VOIP parent=DOWN priority=1 queue=default add name="2. DNS" packet-...
by pcunite
Sat Feb 23, 2019 12:20 am
Forum: Wireless Networking
Topic: Point 2 Point -2000M Boat Races
Replies: 11
Views: 1753

Re: Point 2 Point -2000M Boat Races

In any case the distance is now down to 1000m, from 2000m.
So the 60Hz should work fine, but I am still offput by the difficulty in people managing to aim the bloody things.

I would think some sort of a geared head might help.
by pcunite
Fri Feb 22, 2019 7:41 pm
Forum: General
Topic: Accidentally updated router firmware to long term 6.42.12
Replies: 2
Views: 744

Re: Accidentally updated router firmware to long term 6.42.12

i would do a netinstall and the attempt a restore from backup.

This maybe what you have to do, first, do a system reset. Then load in your config file manually.
by pcunite
Fri Feb 22, 2019 4:09 pm
Forum: General
Topic: Security issue when Winbox exposed
Replies: 68
Views: 10655

Re: Security issue when Winbox exposed

We can only thank good people like the Tenable guys, who report to us first.

+1
by pcunite
Fri Feb 22, 2019 1:24 am
Forum: General
Topic: Three vlans at home on MT hap ac2 - best practice?
Replies: 20
Views: 2246

Re: Three vlans at home on MT hap ac2 - best practice?

So the solution from picture attached below is not possible to achieve, right?

Well, I'm suggesting you create two SSID names, Home and Home24G. Name them whatever you want.
by pcunite
Fri Feb 22, 2019 1:04 am
Forum: General
Topic: Three vlans at home on MT hap ac2 - best practice?
Replies: 20
Views: 2246

Re: Three vlans at home on MT hap ac2 - best practice?

This is what I have been asking since beginning. How to assign to correct VLAN via MAC or any other mechanism. Right, in the VLAN document (linked in my signature) this is shown using difference SSID values. You make as many SSID's (which are applied to virtual wlan interfaces) as you need, each on...
by pcunite
Thu Feb 21, 2019 6:20 pm
Forum: General
Topic: Unauthorized access to MikroTiK
Replies: 20
Views: 4268

Re: Unauthorized access to MikroTiK

My concern is that this latest exploit could make the news cycle again. MikroTik's documentation is very poor and does little to teach security best practices. We can blame customers for not becoming experts, but that will not fix MikroTik's reputation. If many of your customers are blowing their le...
by pcunite
Thu Feb 21, 2019 5:51 pm
Forum: General
Topic: Security issue when Winbox exposed
Replies: 68
Views: 10655

Re: Security issue when Winbox exposed

Fixed in 6.42.12, 6.43.12 and 6.44

Thank you, I was about to ask because I saw 6.42.1 used in the video. So, fixed 9 days ago. I see the line item: *) winbox - improvements in connection handling to router with open winbox service; I would not have caught that as being this serious.
by pcunite
Thu Feb 21, 2019 5:46 pm
Forum: General
Topic: Security issue when Winbox exposed
Replies: 68
Views: 10655

Re: Security issue when Winbox exposed

This, from surface reading the article, seems very serious. There should be full support and expected behavior for allowing Winbox to the world if it is password protected. I think a look from someone at MikroTik is appropriate.
by pcunite
Thu Feb 21, 2019 3:05 pm
Forum: General
Topic: Three vlans at home on MT hap ac2 - best practice?
Replies: 20
Views: 2246

Re: Three vlans at home on MT hap ac2 - best practice?

Study the article in my signature.
by pcunite
Thu Feb 21, 2019 5:33 am
Forum: General
Topic: Force Wifi users only get ip from its AP DHCP server [SOLVED]
Replies: 3
Views: 793

Re: Force Wifi users only get ip from its AP DHCP server [SOLVED]

My understanding is that sure, if the MikroTik bridge is in the middle, you can use bridge filter. However, all on the same switch, you'll need to use the new DHCP Snooping feature.
by pcunite
Thu Feb 21, 2019 1:50 am
Forum: RouterBOARD hardware
Topic: LTAP is here?
Replies: 2
Views: 1100

Re: LTAP is here?

March 7th can't keep all its secrets from us.