Community discussions

Search found 880 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 18
by pcunite
Thu Feb 21, 2019 3:05 pm
Forum: General
Topic: Three vlans at home on MT hap ac2 - best practice?
Replies: 5
Views: 97

Re: Three vlans at home on MT hap ac2 - best practice?

Study the article in my signature.
by pcunite
Thu Feb 21, 2019 5:33 am
Forum: General
Topic: Force Wifi users only get ip from its AP DHCP server [SOLVED]
Replies: 3
Views: 105

Re: Force Wifi users only get ip from its AP DHCP server [SOLVED]

My understanding is that sure, if the MikroTik bridge is in the middle, you can use bridge filter. However, all on the same switch, you'll need to use the new DHCP Snooping feature.
by pcunite
Thu Feb 21, 2019 1:50 am
Forum: RouterBOARD hardware
Topic: LTAP is here?
Replies: 1
Views: 77

Re: LTAP is here?

March 7th can't keep all its secrets from us.
by pcunite
Wed Feb 20, 2019 8:05 pm
Forum: Beginner Basics
Topic: Overall Satisfaction with MikroTik Routers
Replies: 1
Views: 160

Re: Overall Satisfaction with MikroTik Routers

Welcome to your new nightmare! Haha! Seriously though, they are pretty cool. Enjoy.
by pcunite
Wed Feb 20, 2019 4:59 pm
Forum: General
Topic: CCR1036-12G-4S and rx-jabber problem
Replies: 2
Views: 144

Re: CCR1036-12G-4S and rx-jabber problem

When trying to track down weird errors, do the following, then report your success.

  • backup your export: export file=CCR1036.rsc
  • upgrade firmware, and also the factory-firmware
  • reset configuration to no default configuration
  • apply export file slowly back in
by pcunite
Tue Feb 19, 2019 9:47 pm
Forum: Wireless Networking
Topic: Point 2 Point -2000M Boat Races
Replies: 4
Views: 184

Re: Point 2 Point -2000M Boat Races

Looking into this, out of curiosity, it seems that this pdf would indicate (scroll down to maximum distance comparison) the LHG 5 would be sufficient. Here are some others. It uses MIPSBE, so none of the Arm issues. This covers PTP, now what else do you need?
by pcunite
Tue Feb 19, 2019 9:32 pm
Forum: Wireless Networking
Topic: Point 2 Point -2000M Boat Races
Replies: 4
Views: 184

Re: Point 2 Point -2000M Boat Races

Sounds like a neat project. I don't have a lot of experience in that area to say.
by pcunite
Tue Feb 19, 2019 8:20 pm
Forum: General
Topic: Voice Quality Issue
Replies: 2
Views: 228

Re: Voice Quality Issue

Robotic and choppy could be hardware CPU related. Which product are you using and what is total bandwidth from your ISP?
by pcunite
Tue Feb 19, 2019 8:14 pm
Forum: General
Topic: Routing SIP to specific WAN
Replies: 2
Views: 274

Re: Routing SIP to specific WAN

To add to what vklpt said, set the RTP range. You'll need at least two ports per simultaneous active phone call.
by pcunite
Tue Feb 19, 2019 8:08 pm
Forum: General
Topic: Mikrotik VLANs and skinning rabbits
Replies: 8
Views: 262

Re: Mikrotik VLANs and skinning rabbits

Several of us forum members have put our heads together and have come up with this. Please read is slowly and with a cup of coffee. Also, throw away everything you know about MikroTik and VLANs as you read it. If you have any trouble afterwards, help can be provided.
by pcunite
Sun Feb 17, 2019 4:23 pm
Forum: General
Topic: AVOIDING VLAN1 ON BRIDGE????
Replies: 35
Views: 1185

Re: AVOIDING VLAN1 ON BRIDGE????

@pcunite: The only thing I'd change ... I'd allow ICMP in chain=input also from WAN I'll make a step sideways now: sometimes hybrid (trunk with native) is a necessity, but only when such port is facing other network or a particular device requiring such setup. Right, I always allow for ICMP. That w...
by pcunite
Sun Feb 17, 2019 3:58 pm
Forum: General
Topic: Hotspot status.html
Replies: 8
Views: 622

Re: Hotspot status.html

The value is still static. Then with META tags or JavaScript, you'll have to reload the page because it seems the embedded web server does not send down new data. If there is another way to query with JavaScript, I don't know how. If we could AJAX a php file, but I don't think we can. Maybe with Ja...
by pcunite
Sun Feb 17, 2019 3:41 am
Forum: RouterBOARD hardware
Topic: crs317-1g-16s-rm Fault LED
Replies: 3
Views: 223

Re: crs317-1g-16s-rm Fault LED

I'm not familiar with SwOS, but if you can turn on the additional logging options as shown here, perhaps you can see something.
by pcunite
Sun Feb 17, 2019 12:17 am
Forum: General
Topic: AVOIDING VLAN1 ON BRIDGE????
Replies: 35
Views: 1185

Re: AVOIDING VLAN1 ON BRIDGE????

@mkx,
Here is what I hope to be the final version of the Router.rsc file. Everything look okay? I'll update all other examples to follow suit, taking out pvid=1. I want to focus on the Security section now. Might take a month or more.

# Web: https://forum.mikrotik.com/viewtopic.php?t=143620
by pcunite
Sat Feb 16, 2019 8:04 pm
Forum: RouterBOARD hardware
Topic: RB4011 twin-tray 1U
Replies: 7
Views: 500

Re: RB4011 twin-tray 1U

The RB4011 is a nice platform. The fact that they made a WiFi version tells me that this iteration might be locked-in. However, they could release other variants to accommodate you. You might benefit from simply modding it yourself (take the board out and put it in a custom case).
by pcunite
Sat Feb 16, 2019 7:56 pm
Forum: General
Topic: vlan bridge config is PITA - improvement suggestions
Replies: 2
Views: 218

Re: vlan bridge config is PITA - improvement suggestions

If you're doing this very frequently, there would be gains to scripting it all, for sure. Someone could even make a web-based GUI to export it all for us.
by pcunite
Sat Feb 16, 2019 7:53 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: RB4011 - SFP Link Flapping once per second
Replies: 2
Views: 175

Re: RB4011 - SFP Link Flapping once per second

There is an issue with the RB4011 and SFP modules, currently being worked out.
by pcunite
Sat Feb 16, 2019 7:51 pm
Forum: Beginner Basics
Topic: MultiSSID AccessPoint with tagged VLAN problem
Replies: 18
Views: 534

Re: MultiSSID AccessPoint with tagged VLAN problem

Thanks for this Information. But why did nobody mention that it is better, from a performance perspective, to use the Switch chips? Because it is in everyone's interest for MikroTik to have an API that does it all for us, that abstracts away the hardware differences. That is what I'm learning. I ha...
by pcunite
Sat Feb 16, 2019 3:57 am
Forum: General
Topic: Config Review - Security Conscience Home User
Replies: 19
Views: 880

Re: Config Review - Security Conscience Home User

I'm not sure how I feel yet, but the idea is that if you have a service listening on a non-standard port, the slow moving port scanners (who are doing 21, 25, etc) will eventually find it. So, if you see a port 21 attempt, and you don't host FTP, well, you can block that IP from doing anything else ...
by pcunite
Fri Feb 15, 2019 10:11 pm
Forum: General
Topic: AVOIDING VLAN1 ON BRIDGE????
Replies: 35
Views: 1185

Re: AVOIDING VLAN1 ON BRIDGE????

1) True trunk ports frame-types should be set to admit-only-vlan-tagged . 2) On ingress, untagged frames will be dropped. So, pvid setting is ignored and could be set to anything. 3) On egress, pvid setting doesn't matter at all, it's the untagged section of /interface bridge vlan which defines it....
by pcunite
Fri Feb 15, 2019 7:32 pm
Forum: General
Topic: AVOIDING VLAN1 ON BRIDGE????
Replies: 35
Views: 1185

Re: AVOIDING VLAN1 ON BRIDGE????

It seems fine with me.

Wait, sorry. I've been tired lately. Shouldn't both be set to:
frame-types=admit-only-untagged-and-priority-tagged

They are both Access ports, so you can hook your laptop in direct.
by pcunite
Fri Feb 15, 2019 5:18 pm
Forum: General
Topic: AVOIDING VLAN1 ON BRIDGE????
Replies: 35
Views: 1185

Re: AVOIDING VLAN1 ON BRIDGE????

I'm with @anav regarding ether7 on router. Make it a dedicated access port for management VLAN, the same as is port ether24 on switch. @mkx, Would you confirm this update? Is this what it needs to be now? Verify no tags on ingress, set to 99, on egress, remove tag. #Router: # Optional: Change ether...
by pcunite
Fri Feb 15, 2019 3:02 pm
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 18
Views: 3634

Re: DHCP Offering Lease Without Success

Does not help ... no change .. still receiving warnings

Same for me, issue still remains.
by pcunite
Fri Feb 15, 2019 3:01 pm
Forum: General
Topic: Hotspot status.html
Replies: 8
Views: 622

Re: Hotspot status.html

I apologize, remove these lines:

// if sUPTIME is not parsed, show current time, simply for testing
sUPTIME = new Date();
by pcunite
Fri Feb 15, 2019 5:22 am
Forum: General
Topic: Hardware for 6000 concurrent users
Replies: 9
Views: 554

Re: Hardware for 6000 concurrent users

I'll investigate with the customer about web filtering.

Try these guys, CleanBrowsing.org, simple and easy to use.
by pcunite
Fri Feb 15, 2019 5:20 am
Forum: General
Topic: Hotspot status.html
Replies: 8
Views: 622

Re: Hotspot status.html

Replace status.html with the contents of this HTML. <!DOCTYPE html> <html lang="en"> <head> <title>Status Page</title> <meta charset="utf-8" /> <meta name="viewport" content="width=device-width, initial-scale=1.0" /> <meta http-equiv="pragma" content="no-cache" /> <meta http-equiv="expires" content=...
by pcunite
Fri Feb 15, 2019 2:18 am
Forum: RouterBOARD hardware
Topic: Why people pair UBNT APs with MikroTik routers?
Replies: 55
Views: 23146

Re: Why people pair UBNT APs with MikroTik routers?

But all the complains about ARM are wireless related, right? A pure router (a true CCR) could do well, couldn't it? The 4011 has some problems with the FSP+ ports - but they are chipset related, not CPU related. Or I am missing something?

I'm loving the RB4011. I don't use the WiFi model.
by pcunite
Thu Feb 14, 2019 11:06 pm
Forum: General
Topic: AVOIDING VLAN1 ON BRIDGE????
Replies: 35
Views: 1185

Re: AVOIDING VLAN1 ON BRIDGE????

I have two possible updates for the VLAN tutorial. Modifying the first RoaS example, I've converted it to a pure VLAN implementation, also setting up maximum VLAN security options. The firewall is left open to the LAN side (or rather the VLAN). Locked it down as you please.

Thoughts?
by pcunite
Thu Feb 14, 2019 3:00 pm
Forum: General
Topic: AVOIDING VLAN1 ON BRIDGE????
Replies: 35
Views: 1185

Re: AVOIDING VLAN1 ON BRIDGE????

If untagged frames are allowed across trunk ports, then some VLAN renumbering can happen (usually this is not desirable) when pvid settings on trunk ports are not consistent. One could argue that the bridge's pvid setting defines which is "native" VLAN. At the end of the day, having some "native" V...
by pcunite
Thu Feb 14, 2019 2:42 pm
Forum: General
Topic: Guide to (possibly) hack RouterOS ... If yes please protect it
Replies: 10
Views: 658

Re: Guide to (possibly) hack RouterOS ... If yes please protect it

As long as you have physical access to the device, there is always some way to get in ... What that means, together with root access is obvious - devices may be potentially infected so deep that even netinstall will be unable to wipe it. True, I think MikroTik's reputation is fine. Apple, and their...
by pcunite
Thu Feb 14, 2019 1:09 am
Forum: Forwarding Protocols
Topic: VLAN - how to?
Replies: 1
Views: 217

Re: VLAN - how to?

To help you with this, its beneficial to use standard terms. I think you're asking the following? You can see more examples in my signature. There is some setup not shown in the examples below. But, this is a start. Cisco Port 8 is a Trunk port. So, you want MikroTik port 8 to be Trunk? # Set ingres...
by pcunite
Thu Feb 14, 2019 12:31 am
Forum: General
Topic: AVOIDING VLAN1 ON BRIDGE????
Replies: 35
Views: 1185

Re: AVOIDING VLAN1 ON BRIDGE????

I'm tempted to reply to @pcunite's post saying that there is no such thing as native vlan ... it's either vlan or it is not. If vlan is a vlan, it's carrying vlan tag with numerical VID (no such number like native ). But I won't reply like this :wink: :-) Well, as I work on my Security section , th...
by pcunite
Wed Feb 13, 2019 11:06 pm
Forum: General
Topic: AVOIDING VLAN1 ON BRIDGE????
Replies: 35
Views: 1185

Re: AVOIDING VLAN1 ON BRIDGE????

Hello, sorry, I've been so busy. These questions are important and interesting.

So, you want a pure VLAN configuration, is that it? All networks and VLANs on your MikroTik without the Native VLAN being present?
by pcunite
Tue Feb 12, 2019 11:56 pm
Forum: Scripting
Topic: Visual Studio IDE 2017 RouterOS API C
Replies: 1
Views: 107

Re: Visual Studio IDE 2017 RouterOS API C

Thank you.
by pcunite
Tue Feb 12, 2019 4:08 pm
Forum: Beginner Basics
Topic: Building a home small lab
Replies: 1
Views: 141

Re: Building a home small lab

Am I right in thinking the smaller Mikrotik routers and switches pretty much do what the bigger ones do but obviously slower and have less ports. Well, not exactly. There are some differences . Comes down to what you want to do. I'm hoping MikroTik makes a small version of their CRS326 so I can hav...
by pcunite
Mon Feb 11, 2019 5:22 pm
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 18
Views: 3634

Re: DHCP Offering Lease Without Success

This option somehow "checked" even DHCP server has it "unchecked" so if you forgot to uncheck then static reservation broadcasts it.

I'm having this issue with one device in my network. Are you suggesting to check or uncheck it?
by pcunite
Sun Feb 10, 2019 10:19 pm
Forum: Beginner Basics
Topic: Using RouterOS to VLAN your network
Replies: 56
Views: 3712

Re: Using RouterOS to VLAN your network

Bridges need to be tagged members of a VLAN when device needs some L3 (mostly, could be L2 as well) interaction with said VLAN. Access Point doesn't, its job is to forward packets between L2 interfaces. Router does, it needs to shuffle packets on L3 through CPU. So yes, adding BR1 as tagged member ...
by pcunite
Sun Feb 10, 2019 6:24 am
Forum: Beginner Basics
Topic: Using RouterOS to VLAN your network
Replies: 56
Views: 3712

Re: Using RouterOS to VLAN your network

All example topics have now been posted. I recommend you use test hardware to try things out before implementing them in your main network. I've been using the hEX PoE lite and hAP ac lite units because they can be found cheaply and I can power them off each other easily. The two reserved posts I ha...
by pcunite
Sat Feb 09, 2019 9:47 pm
Forum: Beginner Basics
Topic: the magic of connection-state=new
Replies: 4
Views: 246

Re: the magic of connection-state=new

Forgive me, I don't have time to properly discuss this topic in depth, at the moment. I'm working on publishing (just did a moment ago) some more configuration files (the single Access Point one). However, to @anav , your opinion is valued and there maybe some merit to them. I'm not trying to teach ...
by pcunite
Sat Feb 09, 2019 4:31 pm
Forum: Beginner Basics
Topic: Using RouterOS to VLAN your network
Replies: 56
Views: 3712

Re: Using RouterOS to VLAN your network

... it would be just fine if we added connection-state=new to the second rule ... from a functionality point of view it wouldn't change a bit, but it'd show the real reason for having this rule. mkx has explained concisely how connection-state=new is really the highlight for the existence of anothe...
by pcunite
Sat Feb 09, 2019 2:27 am
Forum: Beginner Basics
Topic: QoS Tree VoIP problem
Replies: 42
Views: 1359

Re: QoS Tree VoIP problem

My cpu in normal usage shows 10-15%. When downloading a file, 50-70% usage. What kind of hardware must I buy to prioritize traffic? I bought a CRS109 only for QoS. Ι am very dissatisfied. I do understand your frustration. New comers to the MikroTik brand do not realize product differences, understa...
by pcunite
Sat Feb 09, 2019 1:28 am
Forum: Beginner Basics
Topic: Using RouterOS to VLAN your network
Replies: 56
Views: 3712

Re: Using RouterOS to VLAN your network

I don't have NEW in any of my rules, I don't see any in the default config, so where are you pulling this rectal pluck from? When a packet enters a chain , I want to know what interface it came in on. Next, I want to know where it is going. Using connection-state=new allows you to make a decision r...
by pcunite
Sat Feb 09, 2019 12:29 am
Forum: Beginner Basics
Topic: Using RouterOS to VLAN your network
Replies: 56
Views: 3712

Re: Using RouterOS to VLAN your network

(2) Add text explaining how oneliners can be used. example: /ip interface bridge vlan bridge=BR1 tagged=BR1,sfp1,sfp2 vlan-ids=10,20,30 (3) (a) Why not show ingressfiltering=yes ? (3) (b) Why not show pvid=xx admit frame types= ? A goal I have is to be verbose about VLAN concepts and brief about ot...
by pcunite
Fri Feb 08, 2019 8:36 pm
Forum: Beginner Basics
Topic: Using RouterOS to VLAN your network
Replies: 56
Views: 3712

Re: Using RouterOS to VLAN your network

Hi pcunite. Two questions: @anav, I have updated the configuration files. Please reexamine, and then ask your question again. Then, I'll give you a formal response. Yesterday evening, I had the opportunity to actually implement the config files on real hardware and made some adjustments. Question 1...
by pcunite
Fri Feb 08, 2019 8:34 pm
Forum: Beginner Basics
Topic: Using RouterOS to VLAN your network
Replies: 56
Views: 3712

Re: Using RouterOS to VLAN your network

I'll take this opportunity to open a discussion about how to deal with wifi "access ports" to vlans. There are two ways: vlan-mode=use-tag vlan-id=BLUE interface bridge subtree where wlan1 interface is an access port to a VLAN So what is the better (more understandable/readable) way to configure it...
by pcunite
Fri Feb 08, 2019 8:26 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: 802.11ac Wave2 Support?
Replies: 17
Views: 1112

Re: 802.11ac Wave2 Support?

The beta with iPhone fixes is not public yet. Please wait a little bit. it's being released today.

Thank you Normis. If you guys could a write up on what the juicy details were, that would be great.
by pcunite
Fri Feb 08, 2019 7:00 pm
Forum: Beginner Basics
Topic: Using RouterOS to VLAN your network
Replies: 56
Views: 3712

Re: Using RouterOS to VLAN your network

So do you mean wired or actually weird Thank you, no I actually mean weird (using because noun phrasing) because I find it confusing to have bridge access set this way at this point in the syntax. The stated reasons , explain why, but I feel that port vs bridge (the bridge is a virtual switch or co...
by pcunite
Fri Feb 08, 2019 4:50 pm
Forum: Beginner Basics
Topic: Using RouterOS to prioritize (Qos) traffic for a Class C net
Replies: 109
Views: 171621

Re: Using RouterOS to prioritize (Qos) traffic for a Class C net

I have a CRS109-8G. With ubiquity the result is much better.

I would not use the CRS109 for QoS tasks. Too under powered in my opinion. However, there are many variables.
  • 1
  • 2
  • 3
  • 4
  • 5
  • 18