Community discussions

MikroTik App

Search found 705 matches

by erlinden
Fri Mar 05, 2021 7:57 pm
Forum: General
Topic: Routing Problem
Replies: 11
Views: 554

Re: Routing Problem

Can you please show your /ip routes?
by erlinden
Wed Mar 03, 2021 6:38 pm
Forum: Beginner Basics
Topic: MikroTik WAP
Replies: 5
Views: 253

Re: MikroTik WAP

Why don't you stop posting messages if you can't give an interesting answer? That's the second question I am also interested in. As far as I know this is a forum and anav is not part of the helpdesk (correct me if I'm wrong). And a forum is for starting discussions, not a place to just drop questio...
by erlinden
Tue Mar 02, 2021 5:09 pm
Forum: Wireless Networking
Topic: cAP ac only has 1 tx chain, but 2 rx chains [SOLVED]
Replies: 14
Views: 603

Re: cAP ac only has 1 tx chain, but 2 rx chains [SOLVED]

I'm using a recent cAP ac with 6.49beta11, and a hEX S also with 6.49beta11. Currently I'm running LTS (6.47.9) which works best for me. Why are you running beta? Could be beta related (though I have no clue). Great addition, biomesh. I alreay wondered why there was a /caps-man interface section in...
by erlinden
Tue Mar 02, 2021 4:51 pm
Forum: Wireless Networking
Topic: cAP ac only has 1 tx chain, but 2 rx chains [SOLVED]
Replies: 14
Views: 603

Re: cAP ac only has 1 tx chain, but 2 rx chains [SOLVED]

What version Routerboard and firmware are you running?
Haven't seen the L2MTU size set before (except in very old configuration examples), do you need it? I prefer to use as much default as possible, leave everything (i.e. L2MTU) empty, etc
by erlinden
Tue Mar 02, 2021 10:06 am
Forum: Wireless Networking
Topic: cAP ac only has 1 tx chain, but 2 rx chains [SOLVED]
Replies: 14
Views: 603

Re: cAP ac only has 1 tx chain, but 2 rx chains [SOLVED]

Can you please share your configuration?
/caps-man export

I'm sure the cAP ac is capable of two streams (up and down), might be a configuration thing.

In regards to your expectations...500Mbps is a bit enthousiastic.
by erlinden
Thu Feb 25, 2021 10:47 am
Forum: Wireless Networking
Topic: Network Mesh?? How To?
Replies: 5
Views: 279

Re: Network Mesh?? How To?

It is REALLY easy to find out the SSID of a hidden network. Though conceptionally it sounds better to make it hidden.
Transmission power can be set in de Advanced mode of the wireless interface.
by erlinden
Thu Feb 25, 2021 8:39 am
Forum: Forwarding Protocols
Topic: vpn public ip cant ping
Replies: 6
Views: 433

Re: vpn public ip cant ping

Having a Windows machine publicly available is not really good practice security wise. You better only forward ports that are absolutely necessary. And...start running a VPN server on your router for management purposes and making resources available. By the way, to show your config use /export hide...
by erlinden
Thu Feb 25, 2021 8:31 am
Forum: Wireless Networking
Topic: Network Mesh?? How To?
Replies: 5
Views: 279

Re: Network Mesh?? How To?

Lots of recommendations here: - don't use hidden SSID, it really makes no sense at all - besides SSID and password, the security settings have to be identical - as mentioned above, always use non-overlapping channels - optimize transmission power, "as low as possible" (especially in the 2....
by erlinden
Tue Feb 23, 2021 6:57 pm
Forum: Wireless Networking
Topic: cAP AC Access Points... best quick set? (resolved with no quick set as best option, but solution provided) [SOLVED]
Replies: 22
Views: 988

Re: cAP AC Access Points... best quick set? [SOLVED]

Sounds like it is not in caps mode, by default it is not broadcasting any SSID's.

From Winbox you can put it in caps mode as well:
viewtopic.php?t=148207
by erlinden
Tue Feb 23, 2021 12:00 pm
Forum: Beginner Basics
Topic: help please
Replies: 10
Views: 439

Re: help please

Though I fully agree, erkexzcx, first we have to know if this is unwanted.
by erlinden
Tue Feb 23, 2021 9:22 am
Forum: Beginner Basics
Topic: help please
Replies: 10
Views: 439

Re: help please

I read port 25 and 587, looks like someone/something is trying to connect to it. Do you have a mail server behind the router? Unfortunately your screenshot isn't showing the source IP address clearly, therefor can't say who is doing this. If you are not running a mailserver, you might want to blokck...
by erlinden
Sun Feb 21, 2021 6:48 pm
Forum: Wireless Networking
Topic: Band Steering implementation?
Replies: 74
Views: 24463

Re: Band Steering implementation?

I think there are not many good working implementations of bandsteering. Besides, any modern device will choose 5G over 2.4G, especially if you tweak the TX power. Any effort on implementing this would be a total waste of time in my opinion. While there are so many other relevant implementations tha...
by erlinden
Sat Feb 20, 2021 5:21 pm
Forum: General
Topic: Can't Make New NAT Rules Work [SOLVED]
Replies: 13
Views: 516

Re: Can't Make New NAT Rules Work [SOLVED]

Can you please share your NAT rules (/ip firewall nat export)? Do you have the default filter rules (while you are at it: /ip firewall filter export)?
by erlinden
Thu Feb 18, 2021 3:28 pm
Forum: General
Topic: NAT https with aditional port
Replies: 3
Views: 204

Re: NAT https with aditional ports

This can be handled by /ip firewall nat:
add action=dst-nat chain=dstnat comment="Port translation (or any other comment)" dst-address-list=[fill in the public IP address] dst-port=443 log=yes protocol=tcp to-addresses=[fill in the private IP address] to-ports 9152
by erlinden
Tue Feb 16, 2021 2:27 pm
Forum: Beginner Basics
Topic: Upgrade path from 6.40.5
Replies: 3
Views: 184

Re: Upgrade path from 6.40.5

I would:
  • Make a full export (/export file=anynameyoulike *))
  • Reset device
  • Upgrade to latest version
  • Import the export file
*) Do not forget to copy the export to a computer
by erlinden
Sun Feb 14, 2021 2:13 pm
Forum: General
Topic: Help 3 router one behind the other
Replies: 4
Views: 331

Re: Help 3 router one behind the other

Why?

In my opinion it makes absolutely no sense (based on the supplied information) to have it configured like this.
Why not configure your MikroTiks as accesspoints with build in switches?
by erlinden
Sat Feb 13, 2021 9:27 pm
Forum: SwOS
Topic: CRS 112 Slow Throughput
Replies: 17
Views: 897

Re: CRS 112 Slow Throughput

Better share a complete configuration, can you please share yours (by /export hide-sensitive file=anynameyoulike)?
And...did you check the URL posted before: https://wiki.mikrotik.com/wiki/Manual:C ... s_examples
Because that exactly describes how this CRS112 should be configured.
by erlinden
Sat Feb 13, 2021 8:48 am
Forum: General
Topic: created VLAN but cannot route through to internet from it.
Replies: 4
Views: 252

Re: created VLAN but cannot route through to internet from it.

Please read this tutorial very carefully, it is the best resource (in my opinion) on VLAN and RouterOS:
viewtopic.php?t=143620
by erlinden
Fri Feb 12, 2021 10:34 am
Forum: General
Topic: Home Network is Failing
Replies: 10
Views: 579

Re: Home Network is Failing

I switched to LTS, currently version 6.47.9. Great performance, might help you as well.
by erlinden
Thu Feb 11, 2021 11:58 am
Forum: Beginner Basics
Topic: Confused how to do VLAN Firewall filters? [SOLVED]
Replies: 8
Views: 445

Re: Confused how to do VLAN Firewall filters? [SOLVED]

Volgens mij volstaat het om de volgende regel aan te maken:
add action=drop chain=forward comment="Block guest network except WAN" in-interface=GUEST_VLAN out-interface-list=!WAN
Herewith my guest network is blocked from any other network (VLAN), WAN is allowed
by erlinden
Wed Feb 10, 2021 9:10 pm
Forum: Beginner Basics
Topic: hAP AC Lite Setup as Access Point Only
Replies: 3
Views: 309

Re: hAP AC Lite Setup as Access Point Only

That is a perfect approach, don't forget to configure the wireless interfaces (WPA2/AES, fixed channels, correct bandwidths, country code, etc.).
by erlinden
Wed Feb 10, 2021 10:35 am
Forum: Beginner Basics
Topic: Need some advice for a Mikrotik beginner
Replies: 3
Views: 291

Re: Need some advice for a Mikrotik beginner

And your question is?
What is your definition of 'better'?
And what is your definition of mesh?
by erlinden
Tue Feb 09, 2021 4:03 pm
Forum: Announcements
Topic: v6.47.9 [long-term] is released!
Replies: 65
Views: 12775

Re: v6.47.9 [long-term] is released!

Got it installed on my RB4011/CRS112/2xcAP ac/wAP ac (coming from 6.478.1), will monitor. Upgrade went very smooth!
by erlinden
Tue Feb 09, 2021 8:37 am
Forum: Beginner Basics
Topic: hAP AC Lite Setup as Access Point Only
Replies: 3
Views: 309

Re: hAP AC Lite Setup as Access Point Only

Answers:

1. It depends on what you prefer to use (I never use Quickset), but the result is the same. You probably have firewall rules, but they are not hit.
2. you can do a lot of security improvements, but the question is what is required (for you).
by erlinden
Mon Feb 08, 2021 10:14 am
Forum: RouterBOARD hardware
Topic: "fcs error on link", every day
Replies: 10
Views: 522

Re: "fcs error on link", every day

First thing I notice is that the SFP's have different wavelengths...sure that will work?
What RouterOS version are you running?
by erlinden
Sun Feb 07, 2021 11:31 am
Forum: Beginner Basics
Topic: Need help with port openings
Replies: 5
Views: 383

Re: Need help with port openings

Still in doubt whether I should help you or not (and especially if you are helped by getting the ports in place). By the choice of ports I'm not convinced of sufficient knowledge about security (let alone that port 20 FTP should be set outbound instead of inbound). Besides, there are tons of tutoria...
by erlinden
Fri Feb 05, 2021 2:58 pm
Forum: Wireless Networking
Topic: No wlan interface
Replies: 1
Views: 222

Re: No wlan interface

It might be caused by the fact that the hEX S doesn't have wireless interfaces.
To "solve" this you might want to consider getting an RB with wireless interfaces, like a hAP AC2 (or 3).
by erlinden
Wed Feb 03, 2021 1:45 pm
Forum: Beginner Basics
Topic: Help please!
Replies: 7
Views: 514

Re: Help please!

Can you please first share your configuration (via terminal):

/export hide-sensitive file=anynameyoulike
by erlinden
Wed Feb 03, 2021 1:00 pm
Forum: Beginner Basics
Topic: Help please!
Replies: 7
Views: 514

Re: Help please!

Could not resolve DNS name...that means that there is a problem with DNS. Is the device connected to a network? Did it get a proper IP address? Does it have Internet access? I thought this might be easy. Welcome to MikroTik ;-) Tip: Instead of a cry for help, please use a proper description as title...
by erlinden
Tue Feb 02, 2021 9:01 pm
Forum: General
Topic: website responds ping but does not navigate
Replies: 6
Views: 483

Re: website responds ping but does not navigate

ICMP doens't say anything about webserver (though the webserver could theoretically respond to the ICMP request).
Can you please share the websites you encounter problems.

Things that come to my mind:
  • IPv6
  • DNS
  • Block
by erlinden
Tue Feb 02, 2021 8:59 pm
Forum: Beginner Basics
Topic: My last hope.
Replies: 10
Views: 763

Re: My last hope.

Just to be sure, the RB receives a public IP address?
Are you gaming through Wifi or through cable?
by erlinden
Tue Feb 02, 2021 4:40 pm
Forum: General
Topic: NEW STABLE VERSION 6.47.3 DOES NOT RECEIVE IP FOR INTERFACE AT 10 mbps?
Replies: 2
Views: 241

Re: NEW STABLE VERSION 6.47.3 DOES NOT RECEIVE IP FOR INTERFACE AT 10 mbps?

Luckily you managed to disengage the Caps-Lock key in the end. Actually, that caused additional confusion (as m = milli)... @Holden1: Without proper information it will be difficult. Can you al least share the configuration? /export hide-sensitive file=anynameyoulike By default all ports should be ...
by erlinden
Tue Feb 02, 2021 3:07 pm
Forum: Wireless Networking
Topic: CAPsMAN / Local forwarding - Roaming Apple devices
Replies: 1
Views: 275

Re: CAPsMAN / Local forwarding - Roaming Apple devices

Do you have both 2.4G and 5G radios enabled? It could be caused by too high TX Power on the 2.4G radio.
Perhaps you can share your CAPsMAN configuration: /caps-man export hide-sensitive file=anynameyoulike
by erlinden
Tue Feb 02, 2021 12:23 pm
Forum: Beginner Basics
Topic: Route VLAN to seperate public IP
Replies: 1
Views: 199

Re: Route VLAN to seperate public IP

My guess would be by having three masquerade rules.
Here is a topic that can be helpful:
viewtopic.php?t=142214
by erlinden
Tue Feb 02, 2021 11:00 am
Forum: Beginner Basics
Topic: My last hope.
Replies: 10
Views: 763

Re: My last hope.

Do you experience the same problems when your computer is connected directly to the Netgear (by cable!)? Why would you use multiple routers (NAT after NAT)?
by erlinden
Mon Feb 01, 2021 2:22 pm
Forum: Forwarding Protocols
Topic: public ip ping
Replies: 4
Views: 466

Re: public ip ping

For responding to ping, you have to have this line in your firewall filter rules: /ip firewall filter add action=accept chain=input comment="accept ICMP" protocol=icmp What do you mean by you can ping your gateway...is this from the internal network? i dont have firewall i dont know whats ...
by erlinden
Thu Jan 28, 2021 12:40 pm
Forum: General
Topic: Can´t get routing to work [SOLVED]
Replies: 7
Views: 343

Re: Can´t get routing to work [SOLVED]

ok I understand, but then I have to reconfigure ASUS Wlan to be an AP instead of an router. In AP Mode NAT is not required. Is that correct ?
Correct, there are a lot of reasons why you don't want multiple NAT in your network (and you have found one of them ;-)).
by erlinden
Thu Jan 28, 2021 12:30 pm
Forum: General
Topic: Can´t get routing to work [SOLVED]
Replies: 7
Views: 343

Re: Can´t get routing to work [SOLVED]

yes the ASUS Router is configured as router, therefore NAT is active and required.
There is your problem: because of NAT on the Asus, all traffic is blocked (as should be) from WAN to LAN. Please reread my earlier reply.
by erlinden
Thu Jan 28, 2021 12:14 pm
Forum: General
Topic: Can´t get routing to work [SOLVED]
Replies: 7
Views: 343

Re: Can´t get routing to work [SOLVED]

You have to allow these requests in the Asus router. Is NAT required on the Asus?
by erlinden
Thu Jan 28, 2021 11:28 am
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 154
Views: 101532

Re: Using RouterOS to VLAN your network

Is that correct? Yes I tried to implement the great tutorial, unfortunately I get an error when defining the WAN IP # Yellow WAN facing port with IP Address provided by ISP /ip address add interface=ether1 address=a.a.a.a/aa network=a.a.a.0 get me this error back "error while running run-after...
by erlinden
Wed Jan 27, 2021 3:50 pm
Forum: General
Topic: Hex S & cAP ac - Powered with PoE?
Replies: 4
Views: 311

Re: Hex S & cAP ac - Powered with PoE?

Have been using Hex S with cAP ac (powered by the Hex S) for some time now...without any problems. I would first check cable, what exact cable is in between the two? Can you try with a short patch cable in between?
by erlinden
Wed Jan 27, 2021 10:18 am
Forum: General
Topic: pptp vpn client cannot connect
Replies: 6
Views: 6220

Re: pptp vpn client cannot connect

Topci Author, did you find a solution?
In those nearly 7 years he probably did...
Hope you are not overthinking PPTP!?
by erlinden
Tue Jan 26, 2021 9:29 am
Forum: General
Topic: CAPSMAN + cap VLAN + namagement vlan
Replies: 7
Views: 559

Re: CAPSMAN + cap VLAN + namagement vlan

Just add multiple frequencies: https://dub01pap001files.storage.live.com/y4mMev_QoU1Pr8O977z6UYHvcvyRmUTIRdjnX-6uT52GNTbotLyhmI6LB2k-Dlln68OtSExaE56N8Vzwci6GWE-8vyUT65PSxzc6akjYHaKgLLMXKR4V1h1-IQnb1R2LaNUw6gyky_pZxQfj41u-vTtEzzeS_Dyg4EK5Iskk9RT9_bG3KPHeEEiVohVPaelxwTj?width=376&height=270&cr...
by erlinden
Tue Jan 26, 2021 9:11 am
Forum: Wireless Networking
Topic: Can't get only 40MHz 2.4GHz
Replies: 2
Views: 329

Re: Can't get only 40MHz 2.4GHz

As far as I know by using extension channels you are able to choose for 40MHz bandwidth. And depending on the selected extension channel (Ce or eC) you can manually select the combined channels used (where XX gives you random channels). You can explain both the use case and the problems you are runn...
by erlinden
Mon Jan 25, 2021 9:47 am
Forum: General
Topic: Migration from CCR1016 to CCR1036
Replies: 1
Views: 172

Re: Migration from CCR1016 to CCR1036

Configuration can be exported using /export file=mycurrentconfig (or any other name you like).
This export can be imported into a different Routerboard, passwords won't be exported unfortunately (and I think users aren't as well).
by erlinden
Sun Jan 24, 2021 4:47 pm
Forum: General
Topic: CAPSMAN + cap VLAN + namagement vlan
Replies: 7
Views: 559

Re: CAPSMAN + cap VLAN + namagement vlan

Please use the code tags (from the menu, select "brackets") to make it more readable. First thing I would change is using a single bridge with VLAN filtering on it (both on the CAPsMAN and the CAP). Assign IP addresses to the VLAN interfaces. Don't use auto frequencies, ever. You can add c...
by erlinden
Thu Jan 21, 2021 2:43 pm
Forum: General
Topic: DDoS story, or WARNING: use 'conection-limit' with caution!
Replies: 144
Views: 78742

Re: DDoS story, or WARNING: use 'conection-limit' with caution!

Yep, they are designed to pass good traffic for further processing by firewall
Thank you very much Chupaka, all I had to do is add the internal DNS server to the list that iukatech quoted. It is now working!
by erlinden
Thu Jan 21, 2021 2:17 pm
Forum: General
Topic: DDoS story, or WARNING: use 'conection-limit' with caution!
Replies: 144
Views: 78742

Re: DDoS story, or WARNING: use 'conection-limit' with caution!

01/13/2021 Still works like a charm on the newer firm as we just went through the same issue
Do these rules have to be at the top of the firewall?
by erlinden
Thu Jan 21, 2021 10:06 am
Forum: General
Topic: dhcp1 offering lease xxx.xxx.xxx.xxx for xx:xx:xx:xx:xx:xx without success
Replies: 3
Views: 230

Re: dhcp1 offering lease xxx.xxx.xxx.xxx for xx:xx:xx:xx:xx:xx without success

Where is the DHCP client on the RB3011 connected to?
Can you please share the config of the RB3011: /export hide-sensitive file=anynameyoulike
by erlinden
Wed Jan 20, 2021 5:28 pm
Forum: Beginner Basics
Topic: NAT not working...
Replies: 45
Views: 2744

Re: NAT not working...

Masquerade is for handling NAT.
by erlinden
Wed Jan 20, 2021 2:06 pm
Forum: Beginner Basics
Topic: NAT not working...
Replies: 45
Views: 2744

Re: NAT not working...

OK have done it.
Will be a problem with the disabled Masquerade? Is needed to delete it or it can be disabled?
Disabled is disabled...so it won't interfere.

Is both masquerade and port forwarding working now?
by erlinden
Wed Jan 20, 2021 11:45 am
Forum: Beginner Basics
Topic: Dividing one routerboard making it two separate wan routers
Replies: 6
Views: 435

Re: Dividing one routerboard making it two separate wan routers

Like the Hex S has port 1 as WAN and the other ports a LAN, does this mean that this is a hardware or is it just a convenience marking on the case. Convenience only, you can have any port(s) as WAN port. It just requires the proper configuration. Agree with @quackyo, I would actually use VLAN's (bu...
by erlinden
Wed Jan 20, 2021 10:41 am
Forum: RouterBOARD hardware
Topic: hAP ac³
Replies: 31
Views: 3844

Re: hAP ac³

Did you found any solution to that problem or I purchased a dummy wifi router with big antennas?
Can you please share your config?
/interface wireless export hide-sensitive file=anythingyoulike
by erlinden
Tue Jan 19, 2021 4:08 pm
Forum: Beginner Basics
Topic: NAT not working...
Replies: 45
Views: 2744

Re: NAT not working...

Can you change
add action=masquerade chain=srcnat src-address=10.0.10.0/24
add action=masquerade chain=srcnat disabled=yes src-address=10.20.11.0/24
to:
add chain=srcnat action=masquerade out-interface-list=WAN
by erlinden
Tue Jan 19, 2021 3:44 pm
Forum: Beginner Basics
Topic: NAT not working...
Replies: 45
Views: 2744

Re: NAT not working...

I have change it to the WAN, but no change. Its the same.
Can you please post your configuration here:
/export hide-sensitive file=anythingyoulike
by erlinden
Tue Jan 19, 2021 1:51 pm
Forum: Beginner Basics
Topic: NAT not working...
Replies: 45
Views: 2744

Re: NAT not working...

Ok and what should I choose in the out. Interface (list)? - LAN, Wan, all, dynamic, none and static
You can choose either the interface "Orange Optic" or the interface list WAN (assuming the interface is added tot the list as WAN).
by erlinden
Tue Jan 19, 2021 12:15 pm
Forum: Beginner Basics
Topic: NAT not working...
Replies: 45
Views: 2744

Re: NAT not working...

I was expecting an masquerade rule with an Out. Interface (List) specified. And I think the src-address can be left empty.
Are you sure you want to have your DNS server publicly available?
by erlinden
Mon Jan 18, 2021 9:38 am
Forum: Beginner Basics
Topic: querry on mikrotik hotspot status page
Replies: 2
Views: 234

Re: querry on mikrotik hotspot status page

If you want to use an name instead of using IP address, you will have to solve this by DNS. And...that's about it, I think.
by erlinden
Mon Jan 18, 2021 9:16 am
Forum: General
Topic: help
Replies: 7
Views: 546

Re: help

Can you please share your config: /export hide-sensitive file=anythingyoulike?
by erlinden
Mon Jan 18, 2021 9:14 am
Forum: Wireless Networking
Topic: Capsman issues
Replies: 1
Views: 220

Re: Capsman issues

Would be very helpful if you could share the config of the CAPsMAN here:
/export hide-sensitive file=anythingyoulike

What is the CPU usage on the CAPsMAN?
by erlinden
Sun Jan 17, 2021 5:20 pm
Forum: General
Topic: Full disk on empty router hAP ac^2
Replies: 4
Views: 451

Re: Full disk on empty router hAP ac^2

What is the fix-space package? And why is the version different from your ROS?
by erlinden
Sat Jan 16, 2021 10:54 pm
Forum: The User Manager
Topic: DHCP server problem
Replies: 12
Views: 12474

Re: DHCP server problem

@Buelo, Kid Control is MAC Address based. You might run into problems because a lot of devices are using random MAC addresses for privacy purposes. @borislav, can you share your config ( /export hide-sensitive file=anythingyoulike )? Only situation where I ran into DHCP problems, it was because of m...
by erlinden
Fri Jan 15, 2021 8:59 pm
Forum: Wireless Networking
Topic: WIFI - Poor Performance on RBwAPG-5HacT2HnD
Replies: 3
Views: 463

Re: WIFI - Poor Performance on RBwAPG-5HacT2HnD

Indeed it is difficult to configure wireless properly, it requires a steep learning curve. From your configuration I see a lot is either wrong or missing. Beside, your firmware is outdated, you will get much better performance on the LTS (stable has some problems with the RB3011). For the 5G radio p...
by erlinden
Fri Jan 15, 2021 4:53 pm
Forum: Beginner Basics
Topic: MikroTik 328-24P-4S+RM as a router? [SOLVED]
Replies: 3
Views: 282

Re: MikroTik 328-24P-4S+RM as a router? [SOLVED]

The RB4011 will handle Gigabit just fine, unlike the crs328_24p_4s.
See also: https://mikrotik.com/product/crs328_24p ... estresults
by erlinden
Fri Jan 15, 2021 12:42 pm
Forum: Beginner Basics
Topic: Crs 112 Proplem
Replies: 8
Views: 458

Re: Crs 112 Proplem

Then why are you trying to run SQL statements?
Can you reset with the option "No Default Configuration"?
Can you post the contents of /file (/file print or screenshot)?
by erlinden
Fri Jan 15, 2021 12:18 pm
Forum: Beginner Basics
Topic: Crs 112 Proplem
Replies: 8
Views: 458

Re: Crs 112 Proplem

Sure you want to you use your switch as database server?
by erlinden
Fri Jan 15, 2021 12:14 pm
Forum: Beginner Basics
Topic: NAT Loopback / DNS
Replies: 9
Views: 645

Re: NAT Loopback / DNS

Indeed Hairpin NAT or a proper DNS configuration. Wonder what services on the NAS you would like to publish to the Internet. There might be a better way.
by erlinden
Thu Jan 14, 2021 10:20 am
Forum: General
Topic: Site-to-site VPN with dynamic DNS
Replies: 3
Views: 294

Re: Site-to-site VPN with dynamic DNS

I would use IPSEC, here is a great blogpost I found (and am using):
https://blog.pessoft.com/2016/05/29/mik ... s-and-nat/
by erlinden
Thu Jan 14, 2021 8:55 am
Forum: The User Manager
Topic: Mikrotik app [SOLVED]
Replies: 3
Views: 353

Re: Mikrotik app [SOLVED]

Why would you want the port changed?
by erlinden
Wed Jan 13, 2021 12:29 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 324
Views: 62212

Re: v6.48 [stable] is released!

any ideas why upgrade causes full of errors regarding IKE2 rekey?
search.php?keywords=rekey&t=171035&sf=msgonly
by erlinden
Tue Jan 12, 2021 5:19 pm
Forum: General
Topic: How to setup Mikrotik router and TTL
Replies: 14
Views: 1038

Re: How to setup Mikrotik router and TTL

Can you please share the configuration (/export hide-sensitive file=anythingyoulike)?
What have you tried, what are you trying and what problems are you running into?
by erlinden
Mon Jan 11, 2021 3:51 pm
Forum: General
Topic: Migrate from 1100 to 3011
Replies: 2
Views: 215

Re: Migrate from 1100 to 3011

Export is the best option, make sure that the 3011 is Reset to Defaults with No Default Configuration before importing the export file. Be aware (please check the export file before importing it into the 3011) that the 1100 has more ethernet ports than the 3011. You will have to remove them from the...
by erlinden
Mon Jan 11, 2021 3:38 pm
Forum: General
Topic: Limiting time in mikrotik for employees
Replies: 2
Views: 214

Re: Limiting time in mikrotik for employees

Because you treat your employees like kids...try kid control ;-)
First part was a little joke, kid control will do this just fine.
by erlinden
Mon Jan 11, 2021 1:17 pm
Forum: Wireless Networking
Topic: Mikrotik AP using 40Mhz but not find on the AP on the Ubiquiti station??
Replies: 4
Views: 320

Re: Mikrotik AP using 40Mhz but not find on the AP on the Ubiquiti station??

@bwpl, agree at first sight...it is actually the second (802.11n/green) column shown in the table on your URL.
by erlinden
Mon Jan 11, 2021 11:06 am
Forum: Wireless Networking
Topic: Mikrotik AP using 40Mhz but not find on the AP on the Ubiquiti station??
Replies: 4
Views: 320

Re: Mikrotik AP using 40Mhz but not find on the AP on the Ubiquiti station??

I think it should work if you set the frequency to 5785 MHz (which is channel 157) and extension channel to Ce (to combine it with 161). In what country are you? See also: https://www.silextechnology.com/hs-fs/hubfs/Blog_Images/5GHz_40MHz%20Channel%20Update%20for%20UK.png?width=954&height=410&am...
by erlinden
Thu Jan 07, 2021 6:55 pm
Forum: Beginner Basics
Topic: Speed of internet not working on RB951G-2HnD
Replies: 9
Views: 737

Re: Speed of internet not working on RB951G-2HnD

Be aware that this RB is not really new...ther CPU usage is a good indicator that something is limiting.
Do you use queues? Can you share your config?
/export hide-sensitive file=anythingyoulike
by erlinden
Thu Jan 07, 2021 5:46 pm
Forum: Beginner Basics
Topic: Speed of internet not working on RB951G-2HnD
Replies: 9
Views: 737

Re: Speed of internet not working on RB951G-2HnD

I would expect better results...how are you testing? What is the CPU usage on the RB while testing? Anything special in your configuration?
by erlinden
Thu Jan 07, 2021 9:52 am
Forum: General
Topic: mikrotik audience best wireless performance
Replies: 2
Views: 236

Re: mikrotik audience best wireless performance

Perhaps you can share your configuration?
/export hide-sensitive flie=anythingyoulike (and place the outcome between [])
by erlinden
Thu Jan 07, 2021 9:30 am
Forum: General
Topic: DHCP client on bridge interface with a VLAN DHCP not working
Replies: 2
Views: 295

Re: DHCP client on bridge interface with a VLAN DHCP not working

It should be working...can you please share your configs: /export hide-sensitive file=anythingyoulike?
And please use the [] tags to make it readable.
by erlinden
Mon Jan 04, 2021 2:58 pm
Forum: Beginner Basics
Topic: FTP connecting from WAN without open port on router
Replies: 10
Views: 710

Re: FTP connecting from WAN without open port on router

Do you have UPnP enabled?
By default everything is blocked unless a port is forwarded.
by erlinden
Mon Jan 04, 2021 9:26 am
Forum: Wireless Networking
Topic: Force users to swap to 5Ghz
Replies: 5
Views: 671

Re: Force users to swap to 5Ghz

There is a TX Power setting in CAPsMAN.
by erlinden
Sun Jan 03, 2021 10:32 pm
Forum: General
Topic: vlan over multriple mikrotik devices
Replies: 2
Views: 337

Re: vlan over multriple mikrotik devices

Please read this great tutorial:
viewtopic.php?t=143620
by erlinden
Sun Jan 03, 2021 12:46 am
Forum: Beginner Basics
Topic: Enable 5Ghz band for wifi
Replies: 6
Views: 632

Re: Enable 5Ghz band for wifi

Did you read it at all?
Using RouterOS to VLAN your network
by erlinden
Sun Jan 03, 2021 12:29 am
Forum: Beginner Basics
Topic: Enable 5Ghz band for wifi
Replies: 6
Views: 632

Re: Enable 5Ghz band for wifi

There is no 5G radio in this device, hence it is missing.
There is a great tutorial on VLAN, just use the search option or Google.

Here you go: viewtopic.php?p=781603
by erlinden
Sat Jan 02, 2021 1:40 pm
Forum: General
Topic: Mikrotik Error when generating external PDF file
Replies: 10
Views: 1966

Re: Mikrotik Error when generating external PDF file

Hey, I have the same ptroblem, but I'm not that handy with stuff like this, so I just feel lost at the moment.
Open a new topic with your specific environment and all the information that is relevant. Unless you are also failing on trying to export pdf and have a compromised RB.
by erlinden
Fri Jan 01, 2021 3:55 pm
Forum: General
Topic: Guest Wifis for two separate VLANs
Replies: 10
Views: 673

Re: Guest Wifis for two separate VLANs

Agree, but then I would need (in my special setup) an additional pieces of hardware "combining" vlan 10 and guest-vlan for internet access... I tried to avoid it and with my setup described in second post I was able to do so :) If only a router could do this... Can you please give an over...
by erlinden
Fri Jan 01, 2021 2:07 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 324
Views: 62212

Re: v6.48 [stable] is released!

I absolute love the wireless improvement I'm experiencing. More stability and higher speeds. Unfortunately I noticed periodic "link down", strangely enough only between my RB4011 and my CRS112-8P-4S. This is not occurring between the RB4011 and a cAP ac and not between CRS112-8P-4S and the...
by erlinden
Thu Dec 31, 2020 1:22 pm
Forum: Wireless Networking
Topic: cAP ac power consumption
Replies: 7
Views: 986

Re: cAP ac power consumption

It states "Max power consumption" which is different from consuming 13 Watt. My cAP ac is consuming below 5 Watt, both WLAN's and one LAN active.
by erlinden
Wed Dec 30, 2020 12:09 pm
Forum: General
Topic: Guest Wifis for two separate VLANs
Replies: 10
Views: 673

Re: Guest Wifis for two separate VLANs

Can't you just make two additional VLAN's for the Guest network?
With four VLAN's you will be able to separate (or share) any combination of sharing/blocking you like.
by erlinden
Tue Dec 29, 2020 1:11 pm
Forum: General
Topic: Can't see my Mikrotik hAP ac in Winbox
Replies: 8
Views: 1628

Re: Can't see my Mikrotik hAP ac in Winbox

You might want to check how to perform a factory reset, @paul4:
https://wiki.mikrotik.com/wiki/Manual:Reset
by erlinden
Sun Dec 27, 2020 10:17 am
Forum: General
Topic: DHCP lease unsuccessful after upgrade to 6.48 [SOLVED]
Replies: 10
Views: 887

Re: DHCP lease unsuccessful after upgrade to 5.48 [SOLVED]

I have configured my VLANs in a different way, I configured all VLANs on the bridge instead of on the interface:
viewtopic.php?t=143620
by erlinden
Sat Dec 26, 2020 10:07 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 324
Views: 62212

Re: v6.48 [stable] is released!

Yes, that's what should be set to none IMHO.
Look at first line, dh-group=modp4096 is used for dh in phase 1 and for PFS in phase 2.
Thanks, saved my day! Got it working!!
by erlinden
Sat Dec 26, 2020 5:35 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 324
Views: 62212

Re: v6.48 [stable] is released!

With IKEv2 the pfs group is inherited from phase 1, have a look at dh group in profiles. Perfect forward secret should be used even if set to none in proposals. Correct me if I am wrong, but I think you should set pfs-group to none in proposals on all devices for IKEv2. My current settings: /ip ips...
by erlinden
Fri Dec 25, 2020 10:59 am
Forum: Wireless Networking
Topic: Inconsistent speed HAP AC2 vs HAP Lite
Replies: 35
Views: 2442

Re: Inconsistent speed HAP AC2 vs HAP Lite

Make sure you are using local forwarding, not CAPsMAN forwarding. You will get the highest data rate with local forwarding. CAPsMAN forwarding involves tunneling all traffic back to the CAPsMAN which adds a lot of overhead. Local forwarding is a CAPsMAN setting, you'll find it in the "Datapath...
by erlinden
Thu Dec 24, 2020 9:00 pm
Forum: Beginner Basics
Topic: Changing internet provider
Replies: 3
Views: 403

Re: Changing internet provider

No, it does not depend...
Well, actually...

Perhaps you forgot the situation that the ISP requires a PPPoE configuration?
Or it requires VLAN configuration on the WAN side (in case of fiber)?
And there might be more situations that a change is required.
by erlinden
Thu Dec 24, 2020 4:05 pm
Forum: Beginner Basics
Topic: Changing internet provider
Replies: 3
Views: 403

Re: Changing internet provider

It depends... What medium (cable/xDSL/Fibre), current and future? Do you have any other hardware involved on being able to connect to the Internet (like a modem)? If so, what modem do you currently have (from your current provider)? What modem will you get from your new provider? How is the router c...
by erlinden
Thu Dec 24, 2020 3:54 pm
Forum: Beginner Basics
Topic: Upgrade via a LAN port [SOLVED]
Replies: 4
Views: 502

Re: Upgrade via a LAN port [SOLVED]

THere are multiple ways to upgrade your device:
https://wiki.mikrotik.com/wiki/Manual:U ... g_RouterOS
by erlinden
Thu Dec 24, 2020 12:37 pm
Forum: Wireless Networking
Topic: Inconsistent speed HAP AC2 vs HAP Lite
Replies: 35
Views: 2442

Re: Inconsistent speed HAP AC2 vs HAP Lite

What speed is the client connected on both CAP's?
by erlinden
Wed Dec 23, 2020 10:03 pm
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 324
Views: 62212

Re: v6.48 [stable] is released!

I see the following error in the log (every 30 min): IPsec-SA expired before finishing rekey Haven't seen this issue in the current LTS and the 6.47.x releases. Found this answer in the topic, hope it helps: https://forum.mikrotik.com/viewtopic.php?f=2&t=159536&p=783686&hilit=IPsec+SA+ex...
by erlinden
Wed Dec 23, 2020 1:22 pm
Forum: RouterBOARD hardware
Topic: seek help
Replies: 5
Views: 407

Re: seek help

What is the current state of the RB?
Is the device running?

Are you aware of using Netinstall (as last resort)?
https://wiki.mikrotik.com/wiki/Manual:Netinstall
by erlinden
Wed Dec 23, 2020 12:21 pm
Forum: RouterBOARD hardware
Topic: seek help
Replies: 5
Views: 407

Re: seek help

If you run into problems, you might want:
  1. export your configuration (/export file=anythingyoulike)
  2. Save file to local computer
  3. Reset RB to defaults
  4. Upgrade
  5. upload config file
  6. import your configuration (/import file=anythingyoulike)
Do you get any errors (check in the log)?
by erlinden
Tue Dec 22, 2020 9:32 am
Forum: General
Topic: RB3011UIAS-RM: how to make it tag VLANs?
Replies: 5
Views: 541

Re: RB3011UIAS-RM: how to make it tag VLANs?

Please read this tutorial carefully...it helped me a lot understanding VLAN:
viewtopic.php?t=143620
by erlinden
Tue Dec 22, 2020 9:10 am
Forum: Beginner Basics
Topic: Server access through firewall
Replies: 6
Views: 530

Re: Server access through firewall

Can you please post your complete firewall configuration (/ip firewall export)?
by erlinden
Tue Dec 22, 2020 8:44 am
Forum: Wireless Networking
Topic: Signal Range
Replies: 3
Views: 393

Re: Signal Range

It is the signal strength of the client, measured on the CAP.
Think here you can find some good (additional) information:
https://help.mikrotik.com/docs/display/ROS/CAPsMAN
by erlinden
Mon Dec 21, 2020 3:38 pm
Forum: General
Topic: Different DHCP ranges with Mikrotik with Cisco AiroNet [SOLVED]
Replies: 17
Views: 1125

Re: Different DHCP ranges with Mikrotik with Cisco AiroNet [SOLVED]

So...you want to configure the Cisco AiroNet? Can you please share your routers config (/export hide-sensitive file=anythingyoulike)?
On what port is the AiroNet connected? Assuming the AiroNet is wired connected to the router!?
by erlinden
Mon Dec 21, 2020 3:03 pm
Forum: Beginner Basics
Topic: Server name resolution over L2TP
Replies: 3
Views: 351

Re: Server name resolution over L2TP

What DNS server IP do clients get on the VPN?
by erlinden
Sun Dec 20, 2020 12:56 pm
Forum: The Dude
Topic: Hide delete icon in network maps
Replies: 5
Views: 504

Re: Hide delete icon in network maps

Is the map created by this user or by another user?
And, as I don't know anything about Dude, are there any Dude settings in regards to this?

And to be honest...not much time to upgrade, it is all about priorities. In my opinion, the problem your describing is of less importance.
by erlinden
Sun Dec 20, 2020 9:16 am
Forum: Wireless Networking
Topic: CAPsMan handling devices moving around a home
Replies: 3
Views: 447

Re: CAPsMan handling devices moving around a home

Instead of adding an additional cAP, you might want to consider introducing VLAN's. Where you can have a standard VLAN and an additional VPN VLAN. That would make any additional hardware (for this purpose) unnecessary. If you want to find out more about VLAN (I'm using it for guest network and IoT),...
by erlinden
Sun Dec 20, 2020 9:11 am
Forum: The Dude
Topic: Hide delete icon in network maps
Replies: 5
Views: 504

Re: Hide delete icon in network maps

Not a direct answer to your question...why are you still running this version? It is 2,5 years old and I'm pretty sure there are some vulnerabilities in this version.
by erlinden
Sun Dec 20, 2020 12:32 am
Forum: RouterBOARD hardware
Topic: New wapAC
Replies: 4
Views: 573

Re: New wapAC

Disadvantage of the dual chain is that triple chain clients will perform less in comparison with the old wAP ac.
But in my opinion the improvements outweigh this drawback.
by erlinden
Sun Dec 20, 2020 12:27 am
Forum: Wireless Networking
Topic: Better home CAPsMAN setup?
Replies: 3
Views: 526

Re: Better home CAPsMAN setup?

A way to improve roaming experience is by lowering transmission power. To start with, set the 2G radios 7dB lower than 5G radios.
Next, extension channels (5G) can be better set to Ceee instead of XXXX because you have better control.
by erlinden
Fri Dec 18, 2020 11:07 pm
Forum: Beginner Basics
Topic: CAPsMAN or not? [SOLVED]
Replies: 2
Views: 342

Re: CAPsMAN or not? [SOLVED]

Central management, which is definitely an advantage. I switched from CAPsMAN to local configuration which is more stable in my experience. Big disadvantage of CAPsMAN is when rebooting the router (or other device that is running CAPsMAN) the entire wireless network drops. There seems to be an optio...
by erlinden
Fri Dec 18, 2020 9:58 am
Forum: General
Topic: TCP retransmissions & low performance while bridging
Replies: 5
Views: 626

Re: TCP retransmissions & low performance while bridging

I prefer (and I thought it was recommended) to use a single bridge with filters, see also this great tutorial:
viewtopic.php?t=143620

Not sure if it is completely related, but it is at least worth the try.
by erlinden
Wed Dec 16, 2020 9:27 am
Forum: Beginner Basics
Topic: Trouble setting up port forwarding
Replies: 14
Views: 1094

Re: Trouble setting up port forwarding

Do you see any hits on the rule? Are port forwards supported by your ISP (especially because of the two IP addresses)?
In addition, you might want to test without the dst-address.
by erlinden
Wed Dec 16, 2020 9:06 am
Forum: Beginner Basics
Topic: Trouble setting up port forwarding
Replies: 14
Views: 1094

Re: Trouble setting up port forwarding

My rule looks like this: add action=dst-nat chain=dstnat dst-port=[public port] in-interface-list=WAN protocol=tcp src-address=[public IP] to-addresses=[private IP] to-ports=[private port] [public port]: the port that the remote computer will connect to [public IP]: the public IP address that is all...
by erlinden
Tue Dec 15, 2020 12:07 pm
Forum: General
Topic: Mikrotik Vlan configuration - recommended config
Replies: 6
Views: 417

Re: Mikrotik Vlan configuration - recommended config

That is the correct approach. Please this (really good) tutorial on VLAN's:
viewtopic.php?t=143620
by erlinden
Tue Dec 15, 2020 10:15 am
Forum: Beginner Basics
Topic: setting up router with two AP
Replies: 7
Views: 479

Re: setting up router with two AP

I’ve got it running and both seem to be transmitting ok but will the wireless device automatically switch to the strongest signal? Depending on the threshold of the device, the device will search for the strongest signal. To prevent that it will connect to the 2.4G radio, make sure it's transmissio...
by erlinden
Tue Dec 15, 2020 8:47 am
Forum: Wireless Networking
Topic: slow wifi speed via 5Ghz - RBcAPGi-5acD2nD
Replies: 3
Views: 464

Re: slow wifi speed via 5Ghz - RBcAPGi-5acD2nD

The 866Mbps is the maximum connection speed that a client can get. In the wireless registration tab you can see the speed of the connection (together with some more information). At what speed is your client connected? There is also some tweaking to do on the settings: Use fixed channel (and be awar...
by erlinden
Fri Dec 11, 2020 12:48 pm
Forum: RouterBOARD hardware
Topic: RB3011 took hit from the storm [SOLVED]
Replies: 4
Views: 824

Re: RB3011 took hit from the storm [SOLVED]

It would really surprise me if, by replacing the chip, the Routerboard will work again. But always good to give it a try!
by erlinden
Fri Dec 11, 2020 10:43 am
Forum: RouterBOARD hardware
Topic: 10 second reset does not put CapAC into CAP mode!!
Replies: 7
Views: 1030

Re: 10 second reset does not put CapAC into CAP mode!!

Alternatively you can Reset Configuration and choose CAPS Mode from there.
by erlinden
Fri Dec 11, 2020 10:41 am
Forum: Wireless Networking
Topic: CAPsMAN and local AP settings
Replies: 13
Views: 1498

Re: CAPsMAN and local AP settings

Good question and as far as I know only CAPsMAN settings are used for the CAP's. Meaning there are some settings missing...
by erlinden
Thu Dec 10, 2020 5:32 pm
Forum: General
Topic: Vlan Tagging not working (/interface bridge vlan) [SOLVED]
Replies: 3
Views: 534

Re: Vlan Tagging not working (/interface bridge vlan) [SOLVED]

VLAN1 is default vlan and therefor should not be used.
For more information on VLAN's, please read this topic: viewtopic.php?t=143620
by erlinden
Thu Dec 10, 2020 10:58 am
Forum: Beginner Basics
Topic: on premise website as https
Replies: 7
Views: 589

Re: on premise website as https

would it be possible that all infos i entern to the website will be encrypted or secure? even if its internal? that's why I'm asking how to make my internal website use https There is no difference between internally hosted and externally hosted websites when it comes to encryption. What webserver ...
by erlinden
Thu Dec 10, 2020 10:28 am
Forum: Beginner Basics
Topic: on premise website as https
Replies: 7
Views: 589

Re: on premise website as https

I prefer to have all my internal run services resolved to the internal (private) IP address. Let's assume: your server has IP 192.168.88.2 your website is called www.clydie.local All you have to do is: run a DNS server (MikroTik is running it by default) have all clients resolve through this DNS ser...
by erlinden
Thu Dec 10, 2020 9:36 am
Forum: Beginner Basics
Topic: on premise website as https
Replies: 7
Views: 589

Re: on premise website as https

HTTPS requires a certificate. A very good (and free) supplier is Let's Encrypt: https://letsencrypt.org/
Are you referring to a website you are hosting on a server? What is the relation with MikroTik?
by erlinden
Wed Dec 09, 2020 10:27 am
Forum: Beginner Basics
Topic: Slow LAN transfer speeds through RB4011. [SOLVED]
Replies: 5
Views: 453

Re: Slow LAN transfer speeds through RB4011. [SOLVED]

I would start by testing network speed with iPerf.
by erlinden
Tue Dec 08, 2020 6:30 pm
Forum: General
Topic: Block access to specific IPs
Replies: 3
Views: 398

Re: Block access to specific IPs

InterVLAN traffic is possible by default. You have to add firewall rules to block any inter VLAN traffic.
Something like:
add action=drop chain=forward comment="Block intervlan traffic" in-interface=VLAN1 out-interface-list=VLAN2
by erlinden
Tue Dec 08, 2020 10:48 am
Forum: Beginner Basics
Topic: L2PT server won't work - Local clients won't connect
Replies: 4
Views: 406

Re: L2PT server won't work - Local clients won't connect

Could be DNS related, how is the domain name translated? And did you (in case of public IP address) configure NAT loopback?
by erlinden
Mon Dec 07, 2020 5:34 pm
Forum: Beginner Basics
Topic: Mikrotik DHCP server is assigning multiply IP addresses for the same MAC address. Why it happens?
Replies: 5
Views: 541

Re: Mikrotik DHCP server is assigning multiply IP addresses for the same MAC address. Why it happens?

Virtualization would be my best guess.
But...why Windows 7? This OS is really outdated.
by erlinden
Mon Dec 07, 2020 12:59 pm
Forum: General
Topic: What is main differences between stable and long-term? [SOLVED]
Replies: 9
Views: 13367

Re: What is main differences between stable and long-term? [SOLVED]

Currently I have 6.47.8 Stable and I want ro know if I can change to 6.46.8 Long term directly from Winbox without loose my configuration. It is safe ? it is a good ideea ? Or should I remain on Stable? Why? Really...why? You can export to a configuration file that will contain near all configurati...
by erlinden
Sun Dec 06, 2020 11:41 am
Forum: Beginner Basics
Topic: travel router
Replies: 14
Views: 1382

Re: travel router

I think this blog post is a great example to start with: https://www.justinho.com/blog/2017/07/15/hap-ac-lite.html It can perform, just as any other Routerboard, everything you require. Just don't expect too much of it performance wise. To help you a bit further, can you please share your current co...
by erlinden
Fri Dec 04, 2020 2:44 pm
Forum: General
Topic: Problem with admin password
Replies: 2
Views: 264

Re: Problem with admin password

Reset the device and reconfigure it (or import from configuration backup).
by erlinden
Fri Dec 04, 2020 1:35 pm
Forum: General
Topic: "antenna gain" missing in 6.46.8?
Replies: 38
Views: 3330

Re: "antenna gain" missing in 6.46.8?

Isn't it also the only way to reduce TX Power? By specifying a higher antenna gain? Yes, there are situations where you might want to lower TX Power.
No, it is not. In advanced mode on your wireless interface you can specify TX Power. No need (anymore) to use the gain setting.
by erlinden
Fri Dec 04, 2020 9:49 am
Forum: General
Topic: Vlan Interface Drops?
Replies: 2
Views: 252

Re: Vlan Interface Drops?

Can you please share your configuration: /export hide-sensitive file=anythingyoulike
How do you do VLAN filtering?
by erlinden
Fri Dec 04, 2020 9:20 am
Forum: General
Topic: "antenna gain" missing in 6.46.8?
Replies: 38
Views: 3330

Re: "antenna gain" missing in 6.46.8?

Why?
I assume because 1) most Mikrotik devices have fixed antennas (with corresponding gain) and 2) it is no longer required for "tx power abuse", as tx power can be set manually.
by erlinden
Thu Dec 03, 2020 11:42 am
Forum: Beginner Basics
Topic: Help to define 2x cAP AC to achieve WiFi bridge + WiFi distribution [SOLVED]
Replies: 14
Views: 842

Re: Help to define 2x cAP AC to achieve WiFi bridge + WiFi distribution [SOLVED]

I used this blogpost to configure my travel router. I think it will answer all of your questions on the "wireless bridge" site:
https://www.justinho.com/blog/2017/07/1 ... -lite.html
by erlinden
Wed Dec 02, 2020 6:11 pm
Forum: General
Topic: segmenting with VLAN's
Replies: 4
Views: 251

Re: segmenting with VLAN's

Fairly simple:

- trunk ports should be tagged
- accessports should be untagged *)

It is not necessary to mark untagged explicitly as they are dynamically added (configured by the pvid in /interface bridge port).

Please also read this post carefully: viewtopic.php?t=143620
by erlinden
Wed Dec 02, 2020 12:30 pm
Forum: General
Topic: MY Windows Show Primary DNS Problem
Replies: 2
Views: 268

Re: MY Windows Show Primary DNS Problem

Can you please share:
  • your ipconfig /all output
  • your config: /export hide-sensitive file=anythingyoulike
by erlinden
Tue Dec 01, 2020 10:06 am
Forum: Beginner Basics
Topic: Can not ping 8.8.8.8 from VLAN. no internet. New to Vlan's Help
Replies: 13
Views: 1037

Re: Can not ping 8.8.8.8 from VLAN. no internet. New to Vlan's Help

I thought that the pvid on the bridge could be left set to 1, not sure if it is of any influence?
Could you please add <code></code> tags (with square brackets) to make your config more readable?

Are you familiar with this topic:
viewtopic.php?t=143620
by erlinden
Mon Nov 30, 2020 6:37 pm
Forum: General
Topic: decrease TX-Power
Replies: 13
Views: 7590

Re: decrease TX-Power

I added channels with the corresponding TX Power setting. Might be a bit hard in a big environment, but for my three accesspoints it works great!
/caps-man channel
by erlinden
Thu Nov 26, 2020 5:32 pm
Forum: Wireless Networking
Topic: CAPsMan on RB4011 + CAP AC
Replies: 15
Views: 2098

Re: CAPsMan on RB4011 + CAP AC

In case of a single unit the central management purpose is a bit contradicting. It is introducing some overhead, I think (my opinion) when you have over 2 CAPS-es it makes sense to use CAPsMAN.
by erlinden
Thu Nov 26, 2020 12:04 pm
Forum: Announcements
Topic: v6.47.8 [stable] is released!
Replies: 56
Views: 13204

Re: v6.47.8 [stable] is released!

Upgrade went smooth...really interested in the "arm - improved system stability"!
by erlinden
Wed Nov 25, 2020 1:47 pm
Forum: Beginner Basics
Topic: No way to get safe wpa wireless working on hapac2 [SOLVED]
Replies: 10
Views: 709

Re: No way to get safe wpa wireless working on hapac2 [SOLVED]

Very strange, are you sure about the key?
Could you please post /export hide-sensitive file=anythingyoulike?
by erlinden
Wed Nov 25, 2020 1:15 pm
Forum: Beginner Basics
Topic: No way to get safe wpa wireless working on hapac2 [SOLVED]
Replies: 10
Views: 709

Re: No way to get safe wpa wireless working on hapac2 [SOLVED]

I would:
  • only use WPA2
  • set channel manually
  • only use Ceee as channel width
  • set country
  • upgrade firmware
  • never ever use quick set
by erlinden
Wed Nov 25, 2020 10:11 am
Forum: Wireless Networking
Topic: EAP245 + hAP ac^2
Replies: 4
Views: 495

Re: EAP245 + hAP ac^2

I always choose channels manually. Don't like auto...
by erlinden
Wed Nov 25, 2020 9:50 am
Forum: Wireless Networking
Topic: EAP245 + hAP ac^2
Replies: 4
Views: 495

Re: EAP245 + hAP ac^2

Besides SSID and password, you have to make sure that encryption is identical (WA+PA2/AES only).
Channels should never overlap. And make sure that tx power is optimized.
by erlinden
Mon Nov 23, 2020 11:24 am
Forum: Wireless Networking
Topic: CAPSMAN issue (cAP ac & CRS326-24G-2S+) - wlan interfaces not coming up
Replies: 11
Views: 578

Re: CAPSMAN issue (cAP ac & CRS326-24G-2S+) - wlan interfaces not coming up

Can you please share your /caps-man export hide-sensitive?
Are you using DFS channels? That could explain why not all radios are up.
by erlinden
Sun Nov 22, 2020 2:49 pm
Forum: General
Topic: Problems getting VLANs between two Mikrotik devices
Replies: 14
Views: 788

Re: Problems getting VLANs between two Mikrotik devices

Your trunk port (the one between the Audience and the cAP ac) should be a trunk port. Therefor, on /interface bridge port this port should be be marked on the bridge with default pvid 1 and VLAN tagged only). Same on the trunk port of the cAP ac. Please check again the samples I provided. On /interf...
by erlinden
Sun Nov 22, 2020 2:32 pm
Forum: General
Topic: decrease TX-Power
Replies: 13
Views: 7590

Re: decrease TX-Power

Proper way to set TX power is by setting TX power ;-)

On the WLAN interface, enable 'advanced mode' and select the Tx Power tab. Here you can set the Tx Power Mode and corresponding power.
Don't forget to configure country code first.
by erlinden
Sat Nov 21, 2020 12:05 pm
Forum: General
Topic: Problems getting VLANs between two Mikrotik devices
Replies: 14
Views: 788

Re: Problems getting VLANs between two Mikrotik devices

Your wish... /interface bridge add name=bridge-LAN protocol-mode=none vlan-filtering=yes /interface ethernet set [ find default-name=ether1 ] name=ether1-wan set [ find default-name=ether2 ] name=ether2-nas set [ find default-name=ether3 ] name=ether3-solar set [ find default-name=ether5 ] name=ethe...
by erlinden
Sat Nov 21, 2020 11:33 am
Forum: General
Topic: Problems getting VLANs between two Mikrotik devices
Replies: 14
Views: 788

Re: Problems getting VLANs between two Mikrotik devices

I spent an hour reading this and still got nowhere. I know how VLANs work, I just dont know how to implement in routerOS. To summarize your wishes: You want to have a trunk between the two devices You want to separate your network into 3 VLAN's (and perhaps an additional management lan?) Here is a ...
by erlinden
Sat Nov 21, 2020 10:29 am
Forum: Wireless Networking
Topic: Can't exceed 200mbps on WiFi cAP ac
Replies: 5
Views: 833

Re: Can't exceed 200mbps on WiFi cAP ac

In addition to your settings I also set things like rates and WMM spupport: set [ find default-name=wlan2 ] band=5ghz-a/n/ac basic-rates-a/g=12Mbps \ channel-width=20/40/80mhz-Ceee country=netherlands disabled=no frequency=\ 5500 mode=ap-bridge rate-set=configured security-profile=Profile \ ssid=MY-...
by erlinden
Sat Nov 21, 2020 10:14 am
Forum: General
Topic: Problems getting VLANs between two Mikrotik devices
Replies: 14
Views: 788

Re: Problems getting VLANs between two Mikrotik devices

This topic taught me a lot about VLAN's on MikroTik devices:
viewtopic.php?t=143620
by erlinden
Fri Nov 20, 2020 2:46 pm
Forum: General
Topic: Upgrade 6.45.9 to 6.47.8 truble
Replies: 5
Views: 572

Re: Upgrade 6.45.9 to 6.47.8 truble

Did you perform a router reset (with default configuration)? What routerboard are you using? Are you sure that it is 6.47.8? I thought that 6.47.7 was the latest (stable) release!? Or did you mean 6.46.8, which is the latest LTS? Can you please share you config: /export hide-sensitive file=anythingy...
by erlinden
Fri Nov 20, 2020 10:47 am
Forum: Beginner Basics
Topic: How to test HAP ac RB962UiGS-5HacT2Hnt [SOLVED]
Replies: 1
Views: 465

Re: How to test HAP ac RB962UiGS-5HacT2Hnt [SOLVED]

I think by resetting it to defaults you should be able to test all interfaces (wired and wireless).
Perhaps do a RouterOS and firmware update to check if memory is working as well..
by erlinden
Wed Nov 18, 2020 7:01 pm
Forum: Beginner Basics
Topic: Configure CAP AC with external DHCP server [SOLVED]
Replies: 5
Views: 545

Re: Configure CAP AC with external DHCP server [SOLVED]

Seems you are trying to configure your accesspoint as a router.
According to the manual all you have to do is press the reset button for 5 seconds and it should have default accesspoint configuration. After this, you can configure the wireless part as required.
by erlinden
Tue Nov 17, 2020 3:40 pm
Forum: Beginner Basics
Topic: Help with Firewall Rule
Replies: 3
Views: 315

Re: Help with Firewall Rule

Though I fully agree with anav...this is still a forum.

The information is too limited...what are you trying to accomplish (functionally)?
Are you trying to configure a port forward?

If so, please read this:
https://monovm.com/blog/port-forwarding-on-mikrotik/
by erlinden
Mon Nov 16, 2020 12:16 pm
Forum: General
Topic: security & router remote admin.
Replies: 6
Views: 388

Re: security & router remote admin.

Remote access to administer a MikroTik should only be possible through VPN (is my opinion).
by erlinden
Wed Nov 11, 2020 5:56 pm
Forum: General
Topic: CAPsMan and dividing 2.4 and 5 Ghz channels across multiple AP's
Replies: 6
Views: 1276

Re: CAPsMan and dividing 2.4 and 5 Ghz channels across multiple AP's

Depends on your exact configuration, can you please share your /caps-man export hide-sensitive file=anythingyoulike?
by erlinden
Wed Nov 11, 2020 11:34 am
Forum: Wireless Networking
Topic: Super slow WiFi speed on default configuration
Replies: 7
Views: 5387

Re: Super slow WiFi speed on default configuration

Hi. Did you ever figure this out? I'm sitting in the same boat at the moment.
I think the conclusion not to expect too much wirelessly of this device as it is 2.4GHz only answers your question...
by erlinden
Thu Nov 05, 2020 9:58 am
Forum: Wireless Networking
Topic: no internet but can internet [SOLVED]
Replies: 3
Views: 331

Re: no internet but can internet [SOLVED]

Your Windows machine is reporting "no internet" (and not your hAP AC Lite), you have to find out why. This topic (didn't read it completely) might describe your problem: https://techcommunity.microsoft.com/t5/windows-insider-program/system-reports-no-internet-despite-having-active-connecti...
by erlinden
Wed Nov 04, 2020 6:17 pm
Forum: Wireless Networking
Topic: Mikrotik RB4011iGS+5HacQ2HnD and WiFi 802.11 AC 160mhz [SOLVED]
Replies: 45
Views: 10633

Re: Mikrotik RB4011iGS+5HacQ2HnD and WiFi 802.11 AC 160mhz [SOLVED]

Please try using multiple streams (underneath with 8 streams in parallel):
iperf3 -c <ip address> -P 8
by erlinden
Tue Nov 03, 2020 1:39 pm
Forum: Announcements
Topic: v6.47.7 [stable] is released!
Replies: 45
Views: 11886

Re: v6.47.7 [stable] is released!

Might want to connect using the MAC address instead of IP.
Can you please share the config (/export hide-sensitive file=anythingyoulike) of this cAP ac?
by erlinden
Tue Nov 03, 2020 1:01 pm
Forum: Announcements
Topic: v6.47.7 [stable] is released!
Replies: 45
Views: 11886

Re: v6.47.7 [stable] is released!

after update to 6.47.7 there is no more access to web configuration of the device if it in bridge mode.
CAP ac
what to do?
Assuming you have a Windows machine available...have you tried using Winbox? Or, SSH?
by erlinden
Sat Oct 31, 2020 10:39 pm
Forum: General
Topic: limit bandwidth on ubiquiti or mikrotik?
Replies: 3
Views: 363

Re: limit bandwidth on ubiquiti or mikrotik?

I prefer to let my router perform routing functionality. Assuming you only use Ubiquiti as accesspoint(s), I would use queues. As you mention subnets...are you using VLAN's (already)?
by erlinden
Thu Oct 29, 2020 2:45 pm
Forum: Wireless Networking
Topic: Capsmann indicating "no supported channel" for 5Ghz
Replies: 4
Views: 269

Re: Capsmann indicating "no supported channel" for 5Ghz

Could be caused that you selected "outdoor" instead of "any". Think anything beyond channel 52 is indoor only. There is some more information on this to be found in one of the topics. All my configurations are set to any.
by erlinden
Thu Oct 29, 2020 2:31 pm
Forum: Wireless Networking
Topic: Capsmann indicating "no supported channel" for 5Ghz
Replies: 4
Views: 269

Re: Capsmann indicating "no supported channel" for 5Ghz

Did you set the country in the configuration?
by erlinden
Thu Oct 29, 2020 1:16 pm
Forum: Beginner Basics
Topic: CRS-328 Copy switch configuration [SOLVED]
Replies: 2
Views: 243

Re: CRS-328 Copy switch configuration [SOLVED]

Use the terminal:

/export file=switch
by erlinden
Wed Oct 28, 2020 5:24 pm
Forum: General
Topic: Randomly loosing connection with router from internet
Replies: 9
Views: 447

Re: Randomly loosing connection with router from internet

I prefer to have no forwards to any device in my network. If I have to connect to any service, I use VPN. My advise, especially on RDP, would be to close the port asap and configure VPN.
by erlinden
Wed Oct 28, 2020 12:47 pm
Forum: Beginner Basics
Topic: Install RouterOS in existing network
Replies: 1
Views: 185

Re: Install RouterOS in existing network

I would:
  • Reset the device, no default configuration
  • Create a bridge
  • Add all interfaces to the bridge
  • Add DHCP client to the bridge
After this, you can browse to the IP assigned to the RB.

What would you like to demonstrate?
by erlinden
Tue Oct 27, 2020 9:58 pm
Forum: Wireless Networking
Topic: Datapath
Replies: 6
Views: 443

Re: Datapath

Okay...makes sense. Does this require multiple bridges? Have you tried using a single bridge?
by erlinden
Tue Oct 27, 2020 5:24 pm
Forum: Wireless Networking
Topic: Datapath
Replies: 6
Views: 443

Re: Datapath

Can you please first explain what you are trying to accomplish?
And hidden SSID's...can remember the days they were useful, long time ago.
by erlinden
Mon Oct 26, 2020 2:56 pm
Forum: Beginner Basics
Topic: Connection lost - DHCP
Replies: 0
Views: 202

Connection lost - DHCP

I'm running an RB4011 as main router. Attached to it is a CRS112-8P-4S that is providing PoE to my Dahua camera. Every day I notice at least one (and sometimes more) connection lost/connection restored. This coincides with a DHCP deassigned followed by a DHCP assigned log message. Besides this, I no...
by erlinden
Mon Oct 26, 2020 8:48 am
Forum: Beginner Basics
Topic: RB CPU UTILIZATION
Replies: 2
Views: 396

Re: RB CPU UTILIZATION

I would first share your config with us...looks like a misconfiguration (why did you add a vlan to eth1?).
/export hide-sensitive file=anythingyoulike
by erlinden
Sun Oct 25, 2020 2:52 pm
Forum: Beginner Basics
Topic: 750G download speed very slow
Replies: 25
Views: 1203

Re: 750G download speed very slow

Not sure if the default configuration is correct, herewith the default firewall rules: /ip firewall filter add action=accept chain=input comment="accept established,related,untracked" connection-state=established,related,untracked add action=drop chain=input comment="drop invalid"...
by erlinden
Thu Oct 22, 2020 1:33 pm
Forum: Beginner Basics
Topic: Setup an OpenVPN server in Mikrotik @ Home
Replies: 4
Views: 352

Re: Setup an OpenVPN server in Mikrotik @ Home

You can choose the WAN interface-list instead of the public IP address (in the firewall). Your clients should connect to the cloud domain name. Not sure what OpenVPN is requiring in the configuration, but there are tons of samples and blogs about this topic.
by erlinden
Wed Oct 21, 2020 11:18 am
Forum: General
Topic: Mikrotik block access to Microsoft Outlook 365 account
Replies: 8
Views: 724

Re: Mikrotik block access to Microsoft Outlook 365 account

Ehm..."6.42.10"???
You might want to consider upgrading both devices?
by erlinden
Wed Oct 21, 2020 9:06 am
Forum: General
Topic: Slow internet throughput
Replies: 2
Views: 219

Re: Slow internet throughput

The router should be able to handle these speeds easily. Can you share your config ( /export hide-sensitive file=anythingyoulike )? Is the cable modem performing NAT as well? Do you get a public or private IP address on the RB? In case of private, does the WAN network segment differ from the LAN seg...
by erlinden
Tue Oct 20, 2020 1:23 pm
Forum: Wireless Networking
Topic: Laptop disconnects from wifi once an hour
Replies: 8
Views: 870

Re: Laptop disconnects from wifi once an hour

First thing I notice is that you are using 5GHz and 80MHz bandwidth. That is not really a problem, except the channels you are using are overlapping. Besides, when using extension channels configured as XXXX you have no clue what channels are used. I prefer to use these settings: Channel/Frequency/E...
by erlinden
Tue Oct 20, 2020 10:04 am
Forum: General
Topic: RB951G-2HnD reset issue
Replies: 10
Views: 580

Re: RB951G-2HnD reset issue

I found this topic, might explain the behavior:
viewtopic.php?t=114200

Does the reset button work again?
by erlinden
Mon Oct 19, 2020 5:16 pm
Forum: General
Topic: RB951G-2HnD reset issue
Replies: 10
Views: 580

Re: RB951G-2HnD reset issue

What about resetting it using the command /system reset-configuration?
And while you are at it...you might want to upgrade the RouterOS and firmware.
by erlinden
Mon Oct 19, 2020 10:21 am
Forum: General
Topic: NAT and Speed test
Replies: 1
Views: 173

Re: NAT and Speed test

To test network speed, you should use a tool like iPerf:
https://iperf.fr/

Why test NAT if the device will not perform any NAT tasks?
by erlinden
Thu Oct 15, 2020 10:33 am
Forum: Beginner Basics
Topic: how to configure https for my websites
Replies: 6
Views: 386

Re: how to configure https for my websites

I would expect something like this:

add action=dst-nat chain=dstnat dst-port=443 in-interface-list=WAN log=yes protocol=tcp to-addresses=192.168.10.X to-ports=443

Can you explain the meaning of your rules?
by erlinden
Wed Oct 14, 2020 8:56 pm
Forum: General
Topic: RB3011 system error critical
Replies: 5
Views: 397

Re: RB3011 system error critical

Have you tried telnet/ssh/web as well?
by erlinden
Mon Oct 12, 2020 9:06 am
Forum: Beginner Basics
Topic: extending hAP lite with another AP: CAPsMAN + VLAN, or?
Replies: 4
Views: 324

Re: extending hAP lite with another AP: CAPsMAN + VLAN, or?

I prefer to use CAPsMAN when configuring more than two accesspoints. In your case you might want to consider using VLAN's to seperate public and private. Please have a look at this great topic:
viewtopic.php?t=143620
by erlinden
Mon Oct 12, 2020 9:01 am
Forum: General
Topic: Vlan not working for me,
Replies: 13
Views: 732

Re: Vlan not working for me,

Please have a look at this topic:
viewtopic.php?t=143620

Besides...please don't use UPnP unless security is of no means to you.
by erlinden
Sat Oct 10, 2020 7:14 pm
Forum: Beginner Basics
Topic: Capsman no wifi interfaces show up
Replies: 2
Views: 205

Re: Capsman no wifi interfaces show up

First thing I notice is that you run the CAPsMAN manager on ether1, I have set it to all. Next to that...you are using VLAN's. I notice that you run a DHCP client on the CAP, but it is connected to a trunk port on the switch. CAPsMAN should work, but if you want to have an IP address assigned to the...
by erlinden
Fri Oct 09, 2020 3:57 pm
Forum: Wireless Networking
Topic: Wi-Fi signal does not appear
Replies: 2
Views: 341

Re: Wi-Fi signal does not appear

The 2.4G band is subject to interference, especially if you use 40MHz bandwidth. Only use 20MHz bandwidth and channel 1, 6 or 11 (as being the only non overlapping channels with this width). Set country and Frequency mode to regularity-domain. And don't use 802.11B...unless you have a really ancient...
by erlinden
Thu Oct 08, 2020 12:59 pm
Forum: Beginner Basics
Topic: I can't configure rb750
Replies: 6
Views: 414

Re: I can't configure rb750

If your computer is connected to port 1 (which is configured to be the WAN port in a default configuration), you won't be able to connect. Make sure it is connected to port 2 - 5. Other question remains...how do you reset the RB?
by erlinden
Thu Oct 08, 2020 12:36 pm
Forum: General
Topic: Why I can't download latest version RouterOS from mikrotik.com/download?
Replies: 8
Views: 431

Re: v6.47.4 [stable] is released!

Show the certificate please. And also please check your date/time.
by erlinden
Thu Oct 08, 2020 9:42 am
Forum: Beginner Basics
Topic: I can't configure rb750
Replies: 6
Views: 414

Re: I can't configure rb750

What port on the RB do you connect to?
How do you reset the device?
by erlinden
Wed Oct 07, 2020 6:13 pm
Forum: Wireless Networking
Topic: Slow speed on mirkotik hap ac
Replies: 2
Views: 356

Re: Slow speed on mirkotik hap ac

Couple of things:
  • Set your TX Power higher, i.e. 2.4G @ 15 and 5G @ 20 (or leave both empty to have maximum TX Power)
  • Set country code
  • Set Basic rate to 12 and supported 12 and up
  • Set installation to Any
Hope this improves
by erlinden
Tue Oct 06, 2020 1:10 pm
Forum: General
Topic: XBOX and MikroTik RouterOS v6.47 (stable) NAT | UPDATE: VPN
Replies: 16
Views: 824

Re: XBOX and MikroTik RouterOS v6.47 (stable) NAT

On portforward I found this information:
https://portforward.com/efootball-pes-2020/

You have to forward a sh*tload of ports:
TCP: 3074
UDP: 88,500,3074,3544,4500,5730-5731,5739

Hope you are not running an L2TP VPN server?
by erlinden
Tue Oct 06, 2020 12:50 pm
Forum: General
Topic: XBOX and MikroTik RouterOS v6.47 (stable) NAT | UPDATE: VPN
Replies: 16
Views: 824

Re: XBOX and MikroTik RouterOS v6.47 (stable) NAT

Big LOL!

These ports should be open from within to the Internet, these shoud not be port forwarded (as I assume you did).
UPnP is evil...please don't use it...ever!

Though...some games do require port forwarded to the console (which sucks in my opinion).
What game(s) are giving you problems?
by erlinden
Tue Oct 06, 2020 11:22 am
Forum: Wireless Networking
Topic: MikroTik HAP AC2 - unable to get 867 Mbit/s on 5 Ghz - LOCAL network
Replies: 14
Views: 1394

Re: MikroTik HAP AC2 - unable to get 867 Mbit/s on 5 Ghz - LOCAL network

Sure your WiFi nic supports AC? Sounds to me like a 802.11n dual stream. Or did you set the hAP to n only?
by erlinden
Tue Oct 06, 2020 11:01 am
Forum: Beginner Basics
Topic: interVlan Routering with only routerBoard
Replies: 2
Views: 200

Re: interVlan Routering with only routerBoard

Default config, create VLAN interfaces, block any intervlan traffic except what you want.

But first, start reading this: viewtopic.php?t=143620
by erlinden
Tue Oct 06, 2020 9:43 am
Forum: Wireless Networking
Topic: CAPsMAN - Local-Forwarding - how to choose bridge
Replies: 11
Views: 812

Re: CAPsMAN - Local-Forwarding - how to choose bridge

In addition to @mkx: it is sufficient to configure the accesspoint(s) as CAP, after that you can do all configuration on the CAPsMAN.
by erlinden
Sat Oct 03, 2020 6:36 pm
Forum: Wireless Networking
Topic: Unifi AP VLAN and Mikrotik
Replies: 2
Views: 275

Re: Unifi AP VLAN and Mikrotik

Do you get an IP address from the correct pool? Did you add a second DHCP service for VLAN 30? Can you share the IP information that is provided on VLAN 30?
by erlinden
Fri Oct 02, 2020 2:44 pm
Forum: Scripting
Topic: Script doensn't working on a router without Wireless
Replies: 5
Views: 600

Re: Script doensn't working on a router without Wireless

Can wifistatus be set on a non wireless equiped device? It seems to me that it is a property on the wlan interface.
by erlinden
Fri Oct 02, 2020 12:13 pm
Forum: General
Topic: Wlan Security Profile [SOLVED]
Replies: 9
Views: 678

Re: Wlan Security Profile [SOLVED]

I see you are using nv2 as Wireless Protocol, is this device used for point-2-point connection?
by erlinden
Fri Oct 02, 2020 9:00 am
Forum: General
Topic: CapsMan and Caps
Replies: 5
Views: 372

Re: CapsMan and Caps

Could you please share your configuration? /export hide-sensitive file=anythingyoulike This customer would like to be able to go from one router to the other and not worry about having to reconnect. Is this the use case for using CAPsMAN? Because, in my opinion, you better not use CAPsMAN: it will t...
by erlinden
Thu Oct 01, 2020 2:09 pm
Forum: Wireless Networking
Topic: how to configure 2 WiFi networks ...
Replies: 1
Views: 206

Re: how to configure 2 WiFi networks ...

I prefer to use VLAN. Then you can create an additional virtual wlan interface and add vlan filtering. In the firewall you can choose how all traffic is routed.

Please read this topic carefully: viewtopic.php?t=143620
by erlinden
Wed Sep 30, 2020 10:47 am
Forum: Beginner Basics
Topic: Error with https sites
Replies: 6
Views: 397

Re: Error with https sites

That is like really strange, especially when your phone (connected to the same hotspot?) is working correctly.
Have you tried with Windows started in safe mode (with network support)?

Can you please share your config: /export hide-sensitive file=whateveryoulike?
by erlinden
Wed Sep 30, 2020 8:53 am
Forum: Wireless Networking
Topic: Sonos with Capsman not working
Replies: 20
Views: 1399

Re: Sonos with Capsman not working

Is the hAP ac working as router? Because then you have two networks...
by erlinden
Wed Sep 30, 2020 8:51 am
Forum: Beginner Basics
Topic: capAC being Ornery!
Replies: 13
Views: 598

Re: capAC being Ornery!

Can you please start by describing how you want your cap to function? I'm puzzled with some of the choices you made. And perhaps you can also upgrade RouterOS/firmware? And perhaps have a look at this (great) topic (specifically the access point part): https://forum.mikrotik.com/viewtopic.php?t=143620
by erlinden
Wed Sep 30, 2020 8:35 am
Forum: Wireless Networking
Topic: hAP ac lite unstable 5GHz link, group key exchange timeout
Replies: 2
Views: 313

Re: hAP ac lite unstable 5GHz link, group key exchange timeout

Could you please share your configuration:
/export hide-sensitive file=whatevernameyoulike
by erlinden
Tue Sep 29, 2020 9:46 pm
Forum: Beginner Basics
Topic: Error with https sites
Replies: 6
Views: 397

Re: Error with https sites

Please supply us with some decent information:
  • What error do you get?
  • Is your system date/time correct?
  • Is your system malware/spyware/anywhere ;-) free?
  • What is the output of Invoke-WebRequest -Uri "https://microsoft.com" in PowerShell (make sure you have elevated rights)?
by erlinden
Mon Sep 28, 2020 4:28 pm
Forum: Wireless Networking
Topic: tp-link extender not connecting to hAP ac lite
Replies: 8
Views: 632

Re: tp-link extender not connecting to hAP ac lite

Perhaps you can share your configuration?

/interface wireless export hide-sensitive

And how is WiFi configured on the modem/router?
by erlinden
Sun Sep 27, 2020 7:54 pm
Forum: General
Topic: Mikrotik v6.46.6 Issue
Replies: 2
Views: 289

Re: Mikrotik v6.46.6 Issue

It is just cosmetic and you are not alone:
viewtopic.php?f=2&t=166831
by erlinden
Sun Sep 27, 2020 11:38 am
Forum: General
Topic: 6.46.6 shows testing?
Replies: 2
Views: 321

Re: 6.46.6 shows testing?

by erlinden
Thu Sep 24, 2020 1:54 pm
Forum: General
Topic: Mikrotik RB4011iGS+5HacQ2HnD-IN slow transfer rates
Replies: 13
Views: 921

Re: Mikrotik RB4011iGS+5HacQ2HnD-IN slow transfer rates

Can you please share /interface wireless export hide-sensitive ? I'm still missing file transfer speed test while both Windows clients are connected directly. [Update] Something changed: Mikrotik removed "antenna gain" from the WinBox menu's in 6.47 and 7.0beta8. The only way to change the...
by erlinden
Wed Sep 23, 2020 11:59 am
Forum: General
Topic: Mikrotik RB4011iGS+5HacQ2HnD-IN slow transfer rates
Replies: 13
Views: 921

Re: Mikrotik RB4011iGS+5HacQ2HnD-IN slow transfer rates

Those are cable connections, like I said 50MB/s Windows to Windows. Sorry one last thing. I was looking at Antenna gain settings and I can not find them for the life of me. Can you point me in the right direction?- Directly connected means without the RB in between. Or did you mean without the RB y...
by erlinden
Wed Sep 23, 2020 11:22 am
Forum: General
Topic: Mikrotik RB4011iGS+5HacQ2HnD-IN slow transfer rates
Replies: 13
Views: 921

Re: Mikrotik RB4011iGS+5HacQ2HnD-IN slow transfer rates

Defaults (according to https://mikrotik.com/product/rb4011igs_5hacq2hnd_in):
2G = 3
5G = 3

What speeds do you get when you connect those devices directly via cable (you might want to set IP addresses)? Looks like there is no capping caused by your RB4011.
by erlinden
Wed Sep 23, 2020 10:30 am
Forum: General
Topic: Mikrotik RB4011iGS+5HacQ2HnD-IN slow transfer rates
Replies: 13
Views: 921

Re: Mikrotik RB4011iGS+5HacQ2HnD-IN slow transfer rates

Could you (also) use iPerf for testing the network speed?

Offtopic:
Your wireless settings could be optimized, i.e. antenna gain is incorrect, country code not set and there is a lot that benefits from a proper configuration.
by erlinden
Tue Sep 22, 2020 12:27 pm
Forum: Wireless Networking
Topic: Extending multiple SSID with CAP
Replies: 21
Views: 1783

Re: Extending multiple SSID with CAP

You can, if you use VLAN.

Why are you referring to CAPsMAN?
Replicating is no problem, subnetting is.
by erlinden
Thu Sep 17, 2020 1:04 pm
Forum: General
Topic: Very slow PPTP tunnel
Replies: 6
Views: 639

Re: Very slow PPTP tunnel

What speeds do you get when testing with two computers, using iPerf?
What Internet connection do you have at the vpn client device?

Can you please share your config with us (/export hide-sensitive file=whateveryoulike)?
by erlinden
Wed Sep 16, 2020 2:27 pm
Forum: General
Topic: ip dns error
Replies: 7
Views: 540

Re: ip dns error

Can you please share your config as well (/export hide-sensitive file=anythingyoulike)?
by erlinden
Wed Sep 16, 2020 2:16 pm
Forum: Wireless Networking
Topic: Can't connect to Wireless
Replies: 3
Views: 317

Re: Can't connect to Wireless

Are all security settings identical?

Besides...your TP-Link can use some tweaking:
  • Only use WPA2/AES
  • For 2.4GHz only you channel 1, 6 or 11 (anything in between is overlapping)
  • Preferably don't use b: use g/n instead
by erlinden
Wed Sep 16, 2020 2:13 pm
Forum: Beginner Basics
Topic: Some probably dumb questions... [SOLVED]
Replies: 6
Views: 618

Re: Some probably dumb questions... [SOLVED]

There are no dumb questions...dumb choices though... Windows XP is ancient and Windows 7 is (less but still) ancient. You need to confront the computer tech with the fact that you are considering a no longer supprted OS (and he is not advicing Windows 10). In regards to your router ( for which you s...
by erlinden
Wed Sep 16, 2020 11:02 am
Forum: General
Topic: Terrible speeds over point to point 10G SFP+
Replies: 5
Views: 425

Re: Terrible speeds over point to point 10G SFP+

How do you test?
What exact CRS do you use?
What is the CPU usage while testing?
What RouterOS version are you running?
Can you share your config (/export hide-sensitive file=anythingyoulike)?
by erlinden
Fri Sep 11, 2020 8:41 am
Forum: Beginner Basics
Topic: RouterOS Upgrade question - hAP ac lite
Replies: 6
Views: 409

Re: RouterOS Upgrade question - hAP ac lite

If your client can connect to the Internet, I would expect the hAP ac Lite to be able as well. If you share your config (/export hide-sensitive) and share it here (between code tags) we can have a look. There are several ways to upgrade, please check this site: https://help.mikrotik.com/docs/display...
by erlinden
Thu Sep 10, 2020 1:50 pm
Forum: Announcements
Topic: Expected down time for this forum SEPT 11
Replies: 42
Views: 5605

Re: Expected down time for this forum SEPT 11

Thanks for the hears up but what should I do on my lunch and afternoon break now? ;)
If asking what not to do...don't change you config ;-)

Good luck team on the migration!
by erlinden
Thu Sep 10, 2020 11:52 am
Forum: Wireless Networking
Topic: RB4011iGS+5HacQ2Hnd and 160 MHz
Replies: 6
Views: 1079

Re: RB4011iGS+5HacQ2Hnd and 160 MHz

Does it work if you set it to channel 5500? What country did you set it to? What the status of the interface in CAPsMAN show as status?

Please...never ever use XXXXXXXX (instead of Ceeeeeee).
by erlinden
Tue Sep 08, 2020 12:42 pm
Forum: General
Topic: Receiving only 1 DNS server from DHCP [SOLVED]
Replies: 6
Views: 653

Re: Receiving only 1 DNS server from DHCP [SOLVED]

Can you also post an ipconfig /all from a client?
Is in /ip dhcp-client the option use-peer-dns checked?
by erlinden
Tue Sep 08, 2020 9:41 am
Forum: Wireless Networking
Topic: My mikrotik forgets the settings after reboot
Replies: 2
Views: 289

Re: My mikrotik forgets the settings after reboot

How do you make any changes to the settings? What firmware version are you running? What version of Winbox (assuming you are using Winbox)? Same behaviour if using SSH?
by erlinden
Mon Sep 07, 2020 2:51 pm
Forum: General
Topic: blocking windows update (both ipv4 and ipv6)
Replies: 6
Views: 1017

Re: blocking windows update (both ipv4 and ipv6)

Why do you want to block update traffic?
Have you considered using a WSUS server?
by erlinden
Mon Sep 07, 2020 2:28 pm
Forum: Wireless Networking
Topic: [Help] Mikrotik CAPsMAN Wireless download speed max 200Mb, but PC's /Mobile's link speed is 866Mbps
Replies: 50
Views: 3386

Re: [Help] Mikrotik CAPsMAN Wireless download speed max 200Mb, but PC's /Mobile's link speed is 866Mbps

I know that yours 400 mbps doesn't mean anything, since I've had 42-48 MB/s couple of months ago, then it degradated to 30 MB/s, now it's only 10MB/s - and nothing literally changed in the area these wAPs are operating! So just wait half-a-year when you have maximum 280mbps, afterwards firmware bug...
by erlinden
Mon Sep 07, 2020 12:59 pm
Forum: Wireless Networking
Topic: [Help] Mikrotik CAPsMAN Wireless download speed max 200Mb, but PC's /Mobile's link speed is 866Mbps
Replies: 50
Views: 3386

Re: [Help] Mikrotik CAPsMAN Wireless download speed max 200Mb, but PC's /Mobile's link speed is 866Mbps

P.S. And don't believe these ones upahead telling about 400-480 mbps - I've reached 750 mbps with wAP AC for 1300mbps client - but that was only !once, for a couple of minutes and I couldn't repeat that result, no matter what. Now it's only ~260-280 mbps, with the same client, same wifi card, same ...
by erlinden
Mon Sep 07, 2020 10:47 am
Forum: Wireless Networking
Topic: [Help] Mikrotik CAPsMAN Wireless download speed max 200Mb, but PC's /Mobile's link speed is 866Mbps
Replies: 50
Views: 3386

Re: [Help] Mikrotik CAPsMAN Wireless download speed max 200Mb, but PC's /Mobile's link speed is 866Mbps

maybe the time to change to orthers WiFi devices.
Not sure what requirements (and expectations) you have, I get a solid (little over) 400 Mbps on my cAP ac.
by erlinden
Sat Sep 05, 2020 10:07 pm
Forum: Beginner Basics
Topic: How do you change wlan1 from slave?
Replies: 2
Views: 250

Re: How do you change wlan1 from slave?

I have used this blog post a lot of times, this will help you:
https://www.justinho.com/blog/2017/07/1 ... -lite.html
by erlinden
Fri Sep 04, 2020 2:16 pm
Forum: Wireless Networking
Topic: CAPsMAN controller glitch: bandwith handicap
Replies: 6
Views: 485

Re: CAPsMAN controller glitch: bandwith handicap

I have some doubts about your accesslist, in comparison herewith mine: /caps-man access-list add action=accept allow-signal-out-of-range=10s disabled=no interface=any \ signal-range=-80..-10 ssid-regexp="" add action=reject allow-signal-out-of-range=10s disabled=no interface=any \ signal-r...
by erlinden
Fri Sep 04, 2020 1:22 pm
Forum: Beginner Basics
Topic: Routing
Replies: 4
Views: 429

Re: Routing

Please share your config:
/export hide-sensitive file=whateveryoulike
by erlinden
Fri Sep 04, 2020 1:20 pm
Forum: Wireless Networking
Topic: CAPsMAN controller glitch: bandwith handicap
Replies: 6
Views: 485

Re: CAPsMAN controller glitch: bandwith handicap

I would: Upgrade to 6.47.3 (for both router and accesspoints) test through iperf (I have no clue how you are currently testing?) share the configuration ( /export hide-sensitive file=anythingyoulike ) to be sure everything is set correctly And in addition: What do you mean by occasionaly? Is it solv...
by erlinden
Fri Sep 04, 2020 10:40 am
Forum: Wireless Networking
Topic: [Help] Mikrotik CAPsMAN Wireless download speed max 200Mb, but PC's /Mobile's link speed is 866Mbps
Replies: 50
Views: 3386

Re: [Help] Mikrotik CAPsMAN Wireless download speed max 200Mb, but PC's /Mobile's link speed is 866Mbps

Don't use wpa-psk as authentication-types. Ever. Only use wpa2-psk.
Don't use overlapping channels (also on 5GHz) and use specific extension channels (use Ceee instead of XXXX).
by erlinden
Fri Sep 04, 2020 10:35 am
Forum: Beginner Basics
Topic: How should I set up for access points?
Replies: 4
Views: 359

Re: How should I set up for access points?

I am nearly in your situation: RB4011 (no wireless), cAP ac's and wAP ac. I chose CAPsMAN as cenrtal manager and set all accesspoints in CAPs mode. Separation is done through VLAN. Perhaps have a look at this great tutorial:
viewtopic.php?t=143620
by erlinden
Thu Sep 03, 2020 2:13 pm
Forum: Announcements
Topic: v6.47.3 [stable] is released!
Replies: 50
Views: 11401

Re: v6.47.3 [stable] is released!

Flawless upgrade on:

RB4011iGS+RM
hEX S
cAP ac
wAP ac
CRS112-8P-4S-IN
by erlinden
Thu Sep 03, 2020 10:56 am
Forum: General
Topic: New router (CCR2004-1G-12S+2XS) - can't set up LAN
Replies: 12
Views: 865

Re: New router (CCR2004-1G-12S+2XS) - can't set up LAN

I'm used to working with a single bridge, together with multiple VLAN's. Perhaps you can start over and be inspired by this great tutorial:
viewtopic.php?t=143620
by erlinden
Tue Sep 01, 2020 6:05 pm
Forum: Beginner Basics
Topic: hAP ac^2 - higher upload speed than download
Replies: 14
Views: 919

Re: hAP ac^2 - higher upload speed than download

Please share your settings (/export hide-sensitive file=whateveryoulike)
by erlinden
Sat Aug 29, 2020 7:26 pm
Forum: General
Topic: MikroTik hAP ac times out HTTPS requests to a particular site [SOLVED]
Replies: 2
Views: 251

Re: MikroTik hAP ac times out HTTPS requests to a particular site [SOLVED]

Can you please supply the configuration (/export hide-sensitive file=whateveryoulike)?
Have you already checked anything (like tracert/test both wired and wireless/checked in the browser with F12 => developer tools/DNS/no VPN/no xxx-ware)?
by erlinden
Sat Aug 29, 2020 7:21 pm
Forum: General
Topic: Updating Stable channel to Long Term channel
Replies: 3
Views: 300

Re: Updating Stable channel to Long Term channel

As far as I know it is. I red about people first performing a reset of the configuration and either configure it manually or import the configuration. You can always try if you run into some strange behaviour.

Regarding stability, I use stable (currently 6.47.2) and for me it is very stable.
by erlinden
Sat Aug 29, 2020 4:31 pm
Forum: General
Topic: Updating Stable channel to Long Term channel
Replies: 3
Views: 300

Re: Updating Stable channel to Long Term channel

Why do you want to switch?

You can:
  • create an export
  • - upgrade (or downgrade, depending on how you like at it)
  • - perform an import if necessary
by erlinden
Wed Aug 26, 2020 1:20 pm
Forum: General
Topic: Receiving only 1 DNS server from DHCP [SOLVED]
Replies: 6
Views: 653

Re: Receiving only 1 DNS server from DHCP [SOLVED]

Can you please share:
/ip dhcp-server network export
by erlinden
Wed Aug 26, 2020 9:18 am
Forum: General
Topic: Ip address cannot be obtain via dhcp server on guest vlan [SOLVED]
Replies: 3
Views: 583

Re: Ip address cannot be obtain via dhcp server on guest vlan [SOLVED]

I think you should have a single bridge and add vlan filtering to that. See also:
viewtopic.php?t=143620
by erlinden
Tue Aug 25, 2020 12:32 pm
Forum: RouterBOARD hardware
Topic: MikroTik cAP ac - WiFi Hotsport not working
Replies: 1
Views: 268

Re: MikroTik cAP ac - WiFi Hotsport not working

Reset all (cAP ac's) as CAPs mode (https://wiki.mikrotik.com/wiki/Manual:Reset) and use CAPsMAN on the Hex. You should be able to connect to cAP ac with Winbox as well...
by erlinden
Tue Aug 25, 2020 12:26 pm
Forum: Wireless Networking
Topic: hAP ac^2 Wi-fi signal -- clients prefers 2.4GHz than 5GHz
Replies: 17
Views: 1405

Re: hAP ac^2 Wi-fi signal -- clients prefers 2.4GHz than 5GHz

Antenna gain should only be used for setting...antenna gain. Hence why it can't be set for most devices anymore.
Use the transmission power to set transmission power (and make sure it is set 7dBi lower than 5GHZ radio).
by erlinden
Tue Aug 25, 2020 11:35 am
Forum: General
Topic: DNS TIMEOUT
Replies: 6
Views: 472

Re: DNS TIMEOUT

It depends, but I'm sure you understand that by lack of any relevant information this question can't be answered...

Can you please share your MikroTik configuration (/export hide-sensitive)?