Community discussions

MikroTik App

Search found 2478 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 9
by erlinden
Thu Oct 03, 2024 10:16 pm
Forum: General
Topic: Switch bleeding tagged multicast/broadcast frames from other vlan. Bug?
Replies: 6
Views: 206

Re: Switch bleeding tagged multicast/broadcast frames from other vlan. Bug?

/interface ethernet switch vlan
add independent-learning=yes ports=ether1,switch1-cpu switch=switch1 vlan-id=90
add independent-learning=yes ports=ether2,ether3,ether4,ether5,switch1-cpu switch=switch1 vlan-id=100
Sure the independent-learning is required?
by erlinden
Thu Oct 03, 2024 5:22 pm
Forum: Beginner Basics
Topic: How to reach WG client from LAN
Replies: 6
Views: 173

Re: How to reach WG client from LAN

Sure, just add a firewall filter rule on the forward chain.
by erlinden
Thu Oct 03, 2024 4:16 pm
Forum: General
Topic: Ether6 on RB5009 only working with 100 Mbps. Hardware fault?
Replies: 7
Views: 263

Re: Ether6 on RB5009 only working with 100 Mbps. Hardware fault?

Last step you could take befor RMA-ing it is using netinstall to do a fresh install.
by erlinden
Thu Oct 03, 2024 3:05 pm
Forum: General
Topic: Ether6 on RB5009 only working with 100 Mbps. Hardware fault?
Replies: 7
Views: 263

Re: Ether6 on RB5009 only working with 100 Mbps. Hardware fault?

Nothing in the config explaining this behavior? Like a fixed linkspeed?
by erlinden
Thu Oct 03, 2024 1:49 pm
Forum: General
Topic: No DHCP IP for VLAN on Wifi and eth port [SOLVED]
Replies: 1
Views: 89

Re: No DHCP IP for VLAN on Wifi and eth port [SOLVED]

What is the purpose of having a single VLAN?
Have you seen this "Bible of VLAN":
viewtopic.php?t=143620
by erlinden
Thu Oct 03, 2024 1:45 pm
Forum: SwOS
Topic: Can't Upgrade SWos out of SWos [SOLVED]
Replies: 4
Views: 191

Re: Can't Upgrade SWos out of SWos [SOLVED]

8) 8)
by erlinden
Thu Oct 03, 2024 1:26 pm
Forum: General
Topic: system,error,critical router was rebooted without proper shutdown
Replies: 2
Views: 202

Re: system,error,critical router was rebooted without proper shutdown

How often do you power off your device?
For me, power interruption is pretty critical.
by erlinden
Thu Oct 03, 2024 1:22 pm
Forum: SwOS
Topic: Can't Upgrade SWos out of SWos [SOLVED]
Replies: 4
Views: 191

Re: Can't Upgrade SWos out of SWos [SOLVED]

Have you tried using a different browser (and/or in-private mode)?
What device are you referring to?
by erlinden
Thu Oct 03, 2024 9:55 am
Forum: Beginner Basics
Topic: i need help with this error
Replies: 4
Views: 192

Re: i need help with this error

The amount of services you make avaiable publically is a bit worrying. Both through port forward but also on the router itself. Chances are that devices becomes (or already is) compromised...big red flag. I.e.: add action=accept chain=input dst-port=11337 protocol=tcp add action=accept chain=input d...
by erlinden
Wed Oct 02, 2024 2:41 pm
Forum: Wireless Networking
Topic: Unable to connect on 2.4GHZ 802.11n - any suggestions
Replies: 1
Views: 81

Re: Unable to connect on 2.4GHZ 802.11n - any suggestions

security setting are WPA/WPA2/WPA3
Why not leave it open?

Have you tried with WPA2-PSK only? And is the bandwidth set to 20MHz. And preferably frequency set to: 2412, 2437 or 2462?
by erlinden
Wed Oct 02, 2024 10:32 am
Forum: General
Topic: The mysteries of RouterOS
Replies: 5
Views: 223

Re: The mysteries of RouterOS

It's a real headache at times, isn't it?
Learning is...
by erlinden
Wed Oct 02, 2024 9:22 am
Forum: Beginner Basics
Topic: RB760IGS, can't connect to/ping websites/ DNS
Replies: 1
Views: 115

Re: RB760IGS, can't connect to/ping websites/ DNS

Can you share the config for that?
/export file=anynameyoulike
Remove serial and any other private info and post between code tags by using the </> button.
by erlinden
Tue Oct 01, 2024 5:29 pm
Forum: SwOS
Topic: Install SwOS on RouterOS [SOLVED]
Replies: 10
Views: 36650

Re: Install SwOS on RouterOS [SOLVED]

Not, as far as I know.
Though giving a lot of options, you don't have to use them...
by erlinden
Mon Sep 30, 2024 5:12 pm
Forum: General
Topic: How to force filter DNS
Replies: 4
Views: 210

Re: How to force filter DNS

The NAT rule is the main thing as a catch-all queries, if this shouldn't work, why does it work? Because the client is using 1) DNS servers supplied through DHCP or 2) public DNS servers that are intercepted by the rules. As soon as the client uses DoH or DoT (as @pe1chl mentioned), the requests ar...
by erlinden
Mon Sep 30, 2024 12:15 pm
Forum: Wireless Networking
Topic: CapsMan setup on ax2 & 2x cAP AX 7.15.3 with vlans
Replies: 11
Views: 554

Re: CapsMan setup on ax2 & 2x cAP AX 7.15.3 with vlans

Appart from using ether5 instead of wlan5 (typo?), indeed all you have to do is:
/interface bridge port
add bridge=bridge1 interface=ether5 pvid=10

# optional

/interface bridge vlan 
add bridge=BR1 tagged=bridge1 untagged=ether5 vlan-ids=10
by erlinden
Mon Sep 30, 2024 10:56 am
Forum: Beginner Basics
Topic: Slow internet when change IP pool address and DHCP server
Replies: 5
Views: 281

Re: Slow internet when change IP pool address and DHCP server

This shouldn't happen, as you understand. Did you change from 192.168.88.x to 192.168.0.x? Did you change on 3 locations: /ip address /ip dhcp-server network /ip pool Can you share your config after changing the subnet? /export hide-sensitive file=anynameyoulike Remove serial and any other private i...
by erlinden
Mon Sep 30, 2024 10:27 am
Forum: Beginner Basics
Topic: [SOLVED] Cannot connect to RB5009 V7.16
Replies: 5
Views: 305

Re: Cannot connect to RB5009 V7.16

Have you tried/are you familiair with netinstall?
https://help.mikrotik.com/docs/display/ROS/Netinstall
by erlinden
Mon Sep 30, 2024 9:42 am
Forum: Announcements
Topic: v7.16 [stable] is released!
Replies: 289
Views: 39198

Re: v7.16 [stable] is released!

I really hope this doesn't mean I once again have to set up everything from scratch.
Pretty sure you created an export, just in case this happens!? Especially after previous event...
by erlinden
Mon Sep 30, 2024 9:26 am
Forum: Wireless Networking
Topic: CAPsMAN
Replies: 9
Views: 538

Re: CAPsMAN

It helps when you speak out your doubts. If the current setup is working for you...leave it as it is. If the SSID per accesspoint is intended...leave it as it is. If there is anything you want to change, explain. I.e. roaming has some requirements; single SSID (and security and same subnet) is one o...
by erlinden
Sun Sep 29, 2024 7:10 pm
Forum: Wireless Networking
Topic: CapsMan setup on ax2 & 2x cAP AX 7.15.3 with vlans
Replies: 11
Views: 554

Re: CapsMan setup on ax2 & 2x cAP AX 7.15.3 with vlans

Sure...go ahead.

Like: share config:
/export file=anynameyoulike
Remove the serial and any other private info.

You did read the documentation?
https://help.mikrotik.com/docs/display/ ... ionexample:
by erlinden
Sun Sep 29, 2024 7:09 pm
Forum: Wireless Networking
Topic: Legacy wifi client does not connect to AX AP
Replies: 5
Views: 328

Re: Legacy wifi client does not connect to AX AP

Wpa-psk is not safe, betternot iuse it (opr use no encryption at all.
Probably (my best guess) is the 40MHz bandwidth, the entire bandwidth of 2.4GHz band is...40MHz. Not sure if that is configured in the CAPsMAN...Reconsider using encryption and bandwidth.
by erlinden
Sun Sep 29, 2024 10:11 am
Forum: Wireless Networking
Topic: CAPsMAN
Replies: 9
Views: 538

Re: CAPsMAN

by erlinden
Sat Sep 28, 2024 12:12 pm
Forum: Wireless Networking
Topic: cAP ax performance and problems
Replies: 32
Views: 13466

Re: cAP ax performance and problems

Wall mounted cAP AX running 7.17beta2, didn't bother getting of the couch to get any closer to the accesspoint(which will improve speed). Configured very basic with CAPsMAN. As client I'm using the Intel(R) Wi-Fi 6 AX200 using driver version 23.70.2.3. https://1drv.ms/i/s!AqxQT9uqCMGovOdPYVfk7Y5q9G9...
by erlinden
Sat Sep 28, 2024 11:03 am
Forum: Wireless Networking
Topic: Mikrotik cAP ax and tp-link SG2016P switch between - CAPsMAN problem, no network
Replies: 2
Views: 331

Re: Mikrotik cAP ax and tp-link SG2016P switch between - CAPsMAN problem, no network

Config is far from complete, hence vey difficult to advice.

In the documentation is a lot of information. I would start without VLAN and add that later.
https://help.mikrotik.com/docs/display/ ... iFiCAPsMAN
by erlinden
Sat Sep 28, 2024 10:56 am
Forum: General
Topic: rb4011 v7.9.2 Need downgrade but I cant
Replies: 4
Views: 296

Re: rb4011 v7.9.2 Need downgrade but I cant

Before importing the backup script, have you made sure that the device is reset with "No Default Configuration" is checked and wifi devices are enabled? You can also do the config with the script file line by line through terminal. At least you get feedback on where the script file is fail...
by erlinden
Sat Sep 28, 2024 10:51 am
Forum: Beginner Basics
Topic: DNS provider with malicious blocking
Replies: 3
Views: 332

Re: DNS provider with malicious blocking

Basically three approaches:

- use external DNS server with this functionality
- use internal DNS server with this functionality
- use AdList *)

*) https://help.mikrotik.com/docs/display/ ... DNS-Adlist
by erlinden
Fri Sep 27, 2024 5:18 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 256
Views: 21492

Re: v7.17beta [testing] is released!

Got it running, besides from working (as expected) I really like the Auth Type and Band in Wifi Registration!
by erlinden
Fri Sep 27, 2024 8:54 am
Forum: Wireless Networking
Topic: cAP ax performance and problems
Replies: 32
Views: 13466

Re: cAP ax performance and problems

I have been playing with Mikrotik OS since 2005.
And after 19 years you decided to create an account just to post this message...sure.
by erlinden
Fri Sep 27, 2024 8:41 am
Forum: Beginner Basics
Topic: Capsman on two ax2
Replies: 1
Views: 248

Re: Capsman on two ax2

Funny you missed i.e. this video:
https://www.youtube.com/watch?v=bHotZT41w3E
by erlinden
Fri Sep 27, 2024 8:39 am
Forum: Wireless Networking
Topic: CAPsMAN
Replies: 9
Views: 538

Re: CAPsMAN

I think that everything and more is possible by using CAPsMAN. Any specific doubts you have?
by erlinden
Thu Sep 26, 2024 4:31 pm
Forum: Announcements
Topic: Newsletter #120 | September 2024
Replies: 54
Views: 7488

Re: Newsletter #120 | September 2024

I absolutely love Winbox 4, have it running on both Windows and Debian!
by erlinden
Thu Sep 26, 2024 12:17 pm
Forum: General
Topic: Wireguard
Replies: 5
Views: 673

Re: Wireguard

Sooo many questions, so little information.

Please provide network diagram, purpose of the VPN and an export of the current config:
/export file=anynameyoulike
Remove serial and any other private info, post in between code tags by using the </> button.
by erlinden
Thu Sep 26, 2024 9:57 am
Forum: Wireless Networking
Topic: No Connection to CAPsMAN [SOLVED]
Replies: 17
Views: 2400

Re: No Connection to CAPsMAN [SOLVED]

Good find! You are very welcome, enjoy it!
by erlinden
Thu Sep 26, 2024 9:54 am
Forum: General
Topic: CCR1009 v7.16
Replies: 2
Views: 260

Re: CCR1009 v7.16

Anything in the log that might be of help? I.e. enough free disk space?
by erlinden
Wed Sep 25, 2024 10:16 pm
Forum: Announcements
Topic: v7.16 [stable] is released!
Replies: 289
Views: 39198

Re: v7.16 [stable] is released!

Can have someone any solution for this?
Do you have VLAN ID 1 configured?
Anything in the logging?
Or better, share your config?
/export file=anynameyoulike
Remove serial and any other private info.

I have the same MikroTik and this didn't happen for me.
by erlinden
Wed Sep 25, 2024 5:26 pm
Forum: Wireless Networking
Topic: No Connection to CAPsMAN [SOLVED]
Replies: 17
Views: 2400

Re: No Connection to CAPsMAN [SOLVED]

The reboot is not necessary for implementing CAPsMAN, it's just for clean up purposes.
Do you still have the config of the hAP ac2? Then it would be sufficient to just import the /interface wifi part of that device (ewxcepot for any local config).
by erlinden
Wed Sep 25, 2024 4:24 pm
Forum: Wireless Networking
Topic: No Connection to CAPsMAN [SOLVED]
Replies: 17
Views: 2400

Re: No Connection to CAPsMAN [SOLVED]

Aaah...sorry it took me this long :oops: :oops: :oops: You have the wireless package installed and are configuring the old CAPsMAN: /caps-man Remove the wireless package, it's useless. Then, follow the guide: #create a security profile /interface wifi security add authentication-types=wpa3-psk name=...
by erlinden
Wed Sep 25, 2024 3:58 pm
Forum: Wireless Networking
Topic: No Connection to CAPsMAN [SOLVED]
Replies: 17
Views: 2400

Re: No Connection to CAPsMAN [SOLVED]

By disabling the accept rule is disabled (and it is no longer accepting traffic). Instead, enable it and remove the in-interface. Again...just for testing. You can enable logging to see which traffic is passing that rule.
by erlinden
Wed Sep 25, 2024 3:48 pm
Forum: Wireless Networking
Topic: No Connection to CAPsMAN [SOLVED]
Replies: 17
Views: 2400

Re: No Connection to CAPsMAN [SOLVED]

You are absolutely right, @mkx!

Checked everything (I could), I doubt if this rule is correct:
add action=accept chain=input comment="admin access" in-interface=Bridge-LAN \
    src-address=192.168.0.0/24
Can you, at least as a test, remove the in-interface?
by erlinden
Wed Sep 25, 2024 3:24 pm
Forum: Wireless Networking
Topic: No Connection to CAPsMAN [SOLVED]
Replies: 17
Views: 2400

Re: No Connection to CAPsMAN [SOLVED]

add action=accept chain=input comment=\
    "defconf: accept to local loopback (for CAPsMAN)" disabled=yes \
    dst-address=127.0.0.1
Sure this has to be disabled?
by erlinden
Wed Sep 25, 2024 3:01 pm
Forum: General
Topic: Switch UNIFI whit Mikrotik
Replies: 8
Views: 1245

Re: Switch UNIFI whit Mikrotik

Then I think the IP configuration of the switch is incorrect. Doesn't explain why devices connected to the switch don't receive IP addresses. Have you already asked on the Unifi forum? Update The IP assignment is done through reservation (static lease). Hence the misinterpretation. On what port is t...
by erlinden
Wed Sep 25, 2024 2:26 pm
Forum: General
Topic: Switch UNIFI whit Mikrotik
Replies: 8
Views: 1245

Re: Switch UNIFI whit Mikrotik

Can the controller be reached from anywhere other in the network? It could be a route that is missing, could also be a misconfigured gateway on the switch. And what controller are the accesspoints configured to?
by erlinden
Wed Sep 25, 2024 1:40 pm
Forum: General
Topic: Switch UNIFI whit Mikrotik
Replies: 8
Views: 1245

Re: Switch UNIFI whit Mikrotik

This is a Unifi thing, set the controller IP address fixed through CLI:
set-inform http://[IP address of controller]:8080/inform
Your firewall rules have changed, order is a bit messed up and the forward chain is not complete. Please reconsider the current rules.
by erlinden
Wed Sep 25, 2024 12:41 pm
Forum: General
Topic: Switch UNIFI whit Mikrotik
Replies: 8
Views: 1245

Re: Switch UNIFI whit Mikrotik

Do you set the Unifi Controller address manually on the switch (or is it supplied through DHCP)? Does any other device get an IP address from the RB4011 (when directly connected to the RB)? Do you use VLAN's? Can you share the RB's config /expoort file=anynameyoulike Remove serial and any other priv...
by erlinden
Tue Sep 24, 2024 10:47 am
Forum: Announcements
Topic: v7.16 [stable] is released!
Replies: 289
Views: 39198

Re: v7.16 [stable] is released!

All my static leases for other Mikrotik devices got messed up after update to 7.16.
Have you set fixed Admin MAC Address on the bridge for these devices?

For me, upgrade went well on all devices (coming from either 7.16 RC5 or 7.15.3):
RB4011
hEX S
hAP AX 2
cAP AX
cAP XL ac
wAP ac
by erlinden
Tue Sep 24, 2024 8:47 am
Forum: Wireless Networking
Topic: Display connected WiFi clients?
Replies: 2
Views: 334

Re: Display connected WiFi clients?

Depends on the wifi driver you are using:

wifi-qcom(-ac)
/interface/wifi/registration-table/

wifiwave2

/interface/wifiwave2/registration-table/

wireless
/interface/wireless/registration-table/

All can be accessed through menu items and cli.
by erlinden
Mon Sep 23, 2024 5:01 pm
Forum: Beginner Basics
Topic: limit internet access
Replies: 1
Views: 332

Re: limit internet access

On your forward chain (in pseudo code):
  • allow access to specific site (by IP address?) for single device (by fixed IP address?).
  • drop everything else
by erlinden
Mon Sep 23, 2024 3:59 pm
Forum: General
Topic: Segregate an internal Wireguard server
Replies: 16
Views: 726

Re: Segregate an internal Wireguard server

So you want to forward the remote users to a stand alone Wireguard server?
by erlinden
Mon Sep 23, 2024 3:31 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1271
Views: 231329

Re: 📣 WinBox 4 is here 📣

My best guess would be a security policy of some kind. Would that be possible? Have you tried asking support?
by erlinden
Mon Sep 23, 2024 3:15 pm
Forum: Beginner Basics
Topic: mikrotik as DHCP server with external DHCP Relay [SOLVED]
Replies: 3
Views: 455

Re: mikrotik as DHCP server with external DHCP Relay [SOLVED]

You should bind the DHCP servers to each VLAN's interface (/interface vlan) instead of binding it to the bridge.

Can you share your config?
/export file=anynameyoulike
Remove serial and any other private info.
by erlinden
Mon Sep 23, 2024 3:03 pm
Forum: Announcements
Topic: 📣 WinBox 4 is here 📣
Replies: 1271
Views: 231329

Re: 📣 WinBox 4 is here 📣

What OS are you using, @Hakens? I assume Windows, as you are referring to taskmanager. Is it shown on the taskbar? Where is the executable located? Have you tried removing it and afterwards, download it again (and start it from the Downloads folder)? I ran into the (different) problem that the windo...
by erlinden
Mon Sep 23, 2024 12:11 pm
Forum: General
Topic: Struggling with VLAN configuration (egress works but not ingress)
Replies: 16
Views: 864

Re: Struggling with VLAN configuration (egress works but not ingress)

On port level you have three options: Per port you have three options: - Trunk (where all VLAN ID's will be tagged) - Accessport (where one VLAN ID will be untagged) - Hybrid (which is a combi of trunk and access) Here you find some more info and examples: https://help.mikrotik.com/docs/display/ROS/...
by erlinden
Mon Sep 23, 2024 10:23 am
Forum: Wireless Networking
Topic: iOS 18 Wi-Fi connectivity issue [SOLVED]
Replies: 71
Views: 4300

Re: iOS 18 Wi-Fi connectivity issue [SOLVED]

- .encryption=ccmp,gcmp,ccmp-256,gcmp-256. Is this something WinBox sets? Or is this on purpose? I found that @normis gave this as advice: 2) in "configuration" tab add one config template, that is all you need. don't enter anything else except SSID name and wireless password (select WPA2...
by erlinden
Sun Sep 22, 2024 12:10 pm
Forum: Beginner Basics
Topic: WiFi Setup for Access Point
Replies: 10
Views: 827

Re: WiFi Setup for Access Point

Perhaps the interfaces are disabled?
by erlinden
Fri Sep 20, 2024 10:34 am
Forum: General
Topic: Trunk / Hybrid port - private VLAN for 1 VLAN only
Replies: 3
Views: 509

Re: Trunk / Hybrid port - private VLAN for 1 VLAN only

Intervlan communication can be blocked on a router. By default it will be accepted.
What router are you using?

Please consider not using VLAN ID 1, better assign a VLAN ID explicitely (except for ID 1).
by erlinden
Thu Sep 19, 2024 1:16 pm
Forum: Wireless Networking
Topic: iOS 18 Wi-Fi connectivity issue [SOLVED]
Replies: 71
Views: 4300

Re: iOS 18 Wi-Fi connectivity issue [SOLVED]

Same iPhone, upgraded to iOS 18; nothing changed with WiFi on ax^3.
Then it might be helpfull to share your (wireless) config :D
/interface wifi export
Remove serial and any other private info.
by erlinden
Thu Sep 19, 2024 11:56 am
Forum: General
Topic: Samsung TV - wifi working, ethernet does not [SOLVED]
Replies: 5
Views: 658

Re: Samsung TV - wifi working, ethernet does not [SOLVED]

Does the TV get an IP address? Is the light of the port on?

The config would be helpfull:
/export file=anynameyoulike
Remove serial and any other private info.
by erlinden
Thu Sep 19, 2024 10:49 am
Forum: Wireless Networking
Topic: iOS 18 Wi-Fi connectivity issue [SOLVED]
Replies: 71
Views: 4300

Re: iOS 18 Wi-Fi connectivity issue [SOLVED]

I remember some Apple devices (at least in the past) could have issues with mixed languages on APs within the same SSID domain.
What do you mean with mixed languages?
by erlinden
Thu Sep 19, 2024 9:36 am
Forum: Beginner Basics
Topic: only 1 lan device via wireguard
Replies: 3
Views: 547

Re: only 1 lan device via wireguard

Have you added the wireguard interface to the LAN interface list?
Made any changes to the firewall (forward chain)?
by erlinden
Thu Sep 19, 2024 9:29 am
Forum: Wireless Networking
Topic: Wifi wave 2 capsman not working lik old capsman
Replies: 1
Views: 364

Re: Wifi wave 2 capsman not working lik old capsman

If you are referring to CAPsMAN forwarding mode, you are correct. From the documentation: "WifiWave2 CAPsMAN only passes wireless configuration to the CAP, all forwarding decisions are left to the CAP itself - there is no CAPsMAN forwarding mode." and "WiFi CAPsMAN only passes wireles...
by erlinden
Thu Sep 19, 2024 9:25 am
Forum: Wireless Networking
Topic: iOS 18 Wi-Fi connectivity issue [SOLVED]
Replies: 71
Views: 4300

Re: iOS 18 Wi-Fi connectivity issue [SOLVED]

I have had lots of problems when setting encryption to everything except TKIP (Android and Windows). Can you give it a try (assuming you use Winbox) by unselecting everything, and collaps the encryption part?
by erlinden
Wed Sep 18, 2024 4:49 pm
Forum: Wireless Networking
Topic: iOS 18 Wi-Fi connectivity issue [SOLVED]
Replies: 71
Views: 4300

Re: iOS 18 Wi-Fi connectivity issue [SOLVED]

Can someone point me to instructions for enabling wireless debug logging?
/system logging rules
Add Topics :debug & wireless, Actions: memory.

That's it.

Can you share the wireless part of the config? Just to check current settings.
by erlinden
Wed Sep 18, 2024 2:56 pm
Forum: Beginner Basics
Topic: Lost permisions on router
Replies: 11
Views: 692

Re: Lost permisions on router

Make an export if possible, that will help you reconfigure after netinstall.
by erlinden
Wed Sep 18, 2024 2:07 pm
Forum: Wireless Networking
Topic: CAPsMAN & CAP-AX Wireless issues
Replies: 10
Views: 689

Re: CAPsMAN & CAP-AX Wireless issues

Use fixed channels and lower their transmission power on the 2.4GHz radios .
Second best, add reselect-interval to let the radios periodically scan for best frequencies.
by erlinden
Wed Sep 18, 2024 9:38 am
Forum: Beginner Basics
Topic: Upgrading router, Wireguard not working
Replies: 4
Views: 437

Re: Upgrading router, Wireguard not working

The keys are useless in regards to the problem, but very usefull for unethical stuff.
by erlinden
Tue Sep 17, 2024 11:12 pm
Forum: Wireless Networking
Topic: CAPsMAN & CAP-AX Wireless issues
Replies: 10
Views: 689

Re: CAPsMAN & CAP-AX Wireless issues

Decrease to a max of 4 SSID's per radio.
by erlinden
Tue Sep 17, 2024 6:31 pm
Forum: Wireless Networking
Topic: CAPsMAN specific time connection [SOLVED]
Replies: 5
Views: 514

Re: CAPsMAN specific time connection [SOLVED]

No problem:

Use /system scheduler for the scheduling part and /sysstem/script for enabling/disabling the wifi interface.
by erlinden
Tue Sep 17, 2024 6:28 pm
Forum: General
Topic: Development of Wifi (qcom-ac) over Wireless
Replies: 15
Views: 1163

Re: Development of Wifi (qcom-ac) over Wireless

Without a doubt...use the wifi-qcom-ac driver. I have zero problems with Android and FT (as well as WPA3, I just disabled WPA3 for the time being). It all comes to configuration, you might want to give us the opportunity to help you get it to work. /export show-sensitive file=anynameyoulike Remove s...
by erlinden
Tue Sep 17, 2024 11:02 am
Forum: Wireless Networking
Topic: Guide: CAPsMAN configuration with management VLAN (RouterOS 7.14.3)
Replies: 14
Views: 4819

Re: Guide: CAPsMAN configuration with management VLAN (RouterOS 7.14.3)

Thanks for this post! I switched my hybrid ports to trunk ports on all devices (router/switches/accesspoints). Ran into the problem that from time to time management IP addresses were assigned to mobile devices. Hope this improves my situation.
by erlinden
Mon Sep 16, 2024 11:48 am
Forum: Wireless Networking
Topic: Capsman loosing connection when connected through switch
Replies: 30
Views: 1671

Re: Capsman loosing connection when connected through switch

Could it be roaming related? Do you have RSTP configured?
by erlinden
Mon Sep 16, 2024 11:31 am
Forum: Wireless Networking
Topic: Capsman loosing connection when connected through switch
Replies: 30
Views: 1671

Re: Capsman loosing connection when connected through switch

One VLAN? What is the purpose of having a single VLAN?
Can you share the config?
/export file=anynameyoulike
Remove serial and any other private info and post between code tags by using the </> button.
by erlinden
Sun Sep 15, 2024 4:50 pm
Forum: Wireless Networking
Topic: capsman roaming
Replies: 1
Views: 335

Re: capsman roaming

Running both 5GHz radios on the same frequency is terrible for roaming. As well your 2.4GHz radios might transmit on the same frquency...

Next, accesslist rules I prefer to order as filter rules: specify what is accepted, block (reject) what isn't on the end of the chain.
by erlinden
Fri Sep 13, 2024 10:17 am
Forum: Wireless Networking
Topic: Queue Capsman
Replies: 3
Views: 317

Re: Queue Capsman

Get the export:
/export file=anynameyoulike
Remove serial and any other private info, post in between code tags by using the </> button.
by erlinden
Fri Sep 13, 2024 8:44 am
Forum: RouterBOARD hardware
Topic: RB5009 Port Lockup
Replies: 4
Views: 511

Re: RB5009 Port Lockup

The things I noticed is that you have two bridges, please remove bridge1-Public, it serves no purpose. Are you sure you want to have all ports on the same bridge? Could there be a loop in the network? Could you provide a network diagram? My first guess would be introducing spanning tree protocol: ht...
by erlinden
Thu Sep 12, 2024 5:42 pm
Forum: RouterBOARD hardware
Topic: RB5009 Port Lockup
Replies: 4
Views: 511

Re: RB5009 Port Lockup

Can you share the config, just to rule out anything on that part?
/export file=anynameyoulike
Remove serial and any other private info and post in between code tags by using the </> button.
by erlinden
Thu Sep 12, 2024 3:12 pm
Forum: General
Topic: VLANs unable to do DNS lookup [SOLVED]
Replies: 5
Views: 577

Re: VLANs unable to do DNS lookup [SOLVED]

You might want to change this: add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN into: add action=accept chain=input comment="allow access from LAN" in-interface-list=LAN add action=accept chain=input comment="DNS from VLAN&qu...
by erlinden
Wed Sep 11, 2024 10:03 am
Forum: General
Topic: Adding a second /24 network troubles
Replies: 7
Views: 473

Re: Adding a second /24 network troubles

Any reason why you are not using 10.172.12.0/23 ?
by erlinden
Wed Sep 11, 2024 8:41 am
Forum: Beginner Basics
Topic: Connecting hAP ac3 and cAP ax - Setup Help Needed [SOLVED]
Replies: 2
Views: 382

Re: Connecting hAP ac3 and cAP ax - Setup Help Needed [SOLVED]

I would use CAPsMAN, that will give you the option to manage the network with one device. There are some thing to make it work great: Use latest stable, currently 7.15.3 Install wifi-qcom-ac on the hAP ac3 (instead of wireless package) Set the cAP ax into CAPS Mode Resources on this topic: https://m...
by erlinden
Wed Sep 11, 2024 8:29 am
Forum: General
Topic: Fixed IP for Switch Port
Replies: 2
Views: 325

Re: Fixed IP for Switch Port

Perhaps having a DHCP scope consisting of a single IP address can do this for you? Bind the DHCP server to this interface (port) and set a short lease time.
by erlinden
Tue Sep 10, 2024 6:06 pm
Forum: Beginner Basics
Topic: HAP AC3 as CapsMan for 2x HAP AX2
Replies: 5
Views: 420

Re: HAP AC3 as CapsMan for 2x HAP AX2

There is only one correct CAPsMAN version managing ax (wifi-qom) devices. This is part of RouterOS version 7.13 and up.
No need to install anything additional (like wifi-qcom-ac or wireless) for having CAPsMAN.
by erlinden
Tue Sep 10, 2024 2:42 pm
Forum: Beginner Basics
Topic: HAP AC3 as CapsMan for 2x HAP AX2
Replies: 5
Views: 420

Re: HAP AC3 as CapsMan for 2x HAP AX2

Very good combination, the wifi-qcom-ac is only beneficial if you need wireless on your hAP ac3. Otherwise, @infabo mentioned, you can uninstall it.
by erlinden
Tue Sep 10, 2024 11:36 am
Forum: General
Topic: How to stop/block pinging from outsider
Replies: 3
Views: 372

Re: How to stop/block pinging from outsider

If I recall correctly however, ping (ICMP) is allowed inbound by default. I prefer to block this via firewall rule.
Actually, ICMP traffic is accepted. It is used for more then ping only.
by erlinden
Tue Sep 10, 2024 10:22 am
Forum: General
Topic: IOT devices won't connect using VLAN [SOLVED]
Replies: 4
Views: 653

Re: IOT devices won't connect using VLAN [SOLVED]

I have found this: /interface bridge vlan add bridge=bridge comment=Gasten tagged=bridge vlan-ids=30 add bridge=bridge comment=IOT tagged=bridge vlan-ids=20 I would expect to see VLAN filtering on the port(s) as well. Currently the VLAN config is incomplete. Is there a trunk/hybrid port to the switc...
by erlinden
Tue Sep 10, 2024 8:57 am
Forum: Wireless Networking
Topic: Wifi core and repeaters config - Setup issue
Replies: 10
Views: 758

Re: Wifi core and repeaters config - Setup issue

For feedback or help, the config is required:
/export file=anynameyoulike
Remove serial and any other private info.

There is no option to run wired? Wireless backhaul is consuming a lot (at least halve) of your wireless bandwidth.
by erlinden
Mon Sep 09, 2024 4:24 pm
Forum: Wireless Networking
Topic: Capsman beginner help
Replies: 2
Views: 292

Re: Capsman beginner help

If you run the wifi-qcom-ac package on the cAP ac (instead of the wireless package) you should be fine. Here you can find the documentation: https://help.mikrotik.com/docs/display/ROS/WiFi#WiFi-CAPsMAN-CAPsimpleconfigurationexample: Could you add the ouput of this command as well? /interface/wifi ex...
by erlinden
Mon Sep 09, 2024 12:53 pm
Forum: Wireless Networking
Topic: CAPsMAN - Problem unable to see Radios
Replies: 3
Views: 477

Re: CAPsMAN - Problem unable to see Radios

I would like to advise you to reset the CAP to CAPS Mode:
https://help.mikrotik.com/docs/display/UM/cAP+XL+ac
by erlinden
Mon Sep 09, 2024 11:29 am
Forum: Beginner Basics
Topic: how to forward port for wireguard tunnel
Replies: 1
Views: 242

Re: how to forward port for wireguard tunnel

This explenation, which is part of the official MikroTik documentation, will explain exactely how to configure this setup:
https://help.mikrotik.com/docs/display/ ... uardtunnel
by erlinden
Thu Sep 05, 2024 3:57 pm
Forum: General
Topic: IOT devices won't connect using VLAN [SOLVED]
Replies: 4
Views: 653

Re: IOT devices won't connect using VLAN [SOLVED]

Can you share the config?
/export file=anynameyoulike
Remove serial and any other private info and post between code tags by using the </> button.
by erlinden
Wed Sep 04, 2024 5:17 pm
Forum: General
Topic: Mikrotik Vlan
Replies: 2
Views: 304

Re: Mikrotik Vlan

Can you share the config:
/export file=anynameyoulike
Remove serial and post between code tags by using the </> button.

Also, here is a great reference when it comes to VLAN:
viewtopic.php?t=143620
by erlinden
Wed Sep 04, 2024 4:05 pm
Forum: Wireless Networking
Topic: Slow WiFi [SOLVED]
Replies: 31
Views: 2571

Re: Slow WiFi [SOLVED]

If no VLAN's are involved, the D-Link will do just fine (assuming it has gigabit ports). The cAP ac does handle the wifi-qcom-ac pretty well (in my experience), though I red someone having out of memory problems (therefor a daily reboot was introduced). Haven't seen that problem myself (uptime over ...
by erlinden
Wed Sep 04, 2024 11:28 am
Forum: Wireless Networking
Topic: Legacy and new CAPsMan on the same x86 device
Replies: 6
Views: 886

Re: Legacy and new CAPsMan on the same x86 device

Can someone help?
Depends on how you want it to work exactly. Fyi, legacy supports CAPsMAN forwarding, wifi-qcom(-ac) doesn't.
by erlinden
Wed Sep 04, 2024 9:24 am
Forum: Beginner Basics
Topic: Email Spams problem due to malware in some device in the network
Replies: 3
Views: 400

Re: Email Spams problem due to malware in some device in the network

And how can i disable the port for everyone else
Add a drop rule on the forward chain that drops everything else:
add action=drop chain=forward
Make sure this rule is at the end of your rules.

I prefer the "allow specific traffic and drop everything else" way of thinking.
by erlinden
Tue Sep 03, 2024 5:38 pm
Forum: Beginner Basics
Topic: Email Spams problem due to malware in some device in the network
Replies: 3
Views: 400

Re: Email Spams problem due to malware in some device in the network

Allow on Source Address List, with dst port 587, protocol 6 (tcp), on the forward chain. This should be sufficient information...
by erlinden
Tue Sep 03, 2024 4:13 pm
Forum: Beginner Basics
Topic: Stuck in new setup
Replies: 6
Views: 820

Re: Stuck in new setup

Now I see...you don't want to have your IP address of the accesspoint in the same range as the office IP. Normally (I assumed because of the VLAN ID) you would have a management VLAN where you do the IP assignement of all hardware involved. To get it to work you can set the BAS_VLAN to ID 100. Not s...
by erlinden
Tue Sep 03, 2024 3:25 pm
Forum: Beginner Basics
Topic: Stuck in new setup
Replies: 6
Views: 820

Re: Stuck in new setup

Looks like MGT and CORP VLAN are messed up. I.e. the different network ranges are incorrect. Start with a basic setup and follow the topic by the letter. Then make changes as desired.

In regards to no access, are you using Winbox? Does it show up on discovery?
by erlinden
Tue Sep 03, 2024 8:44 am
Forum: General
Topic: netinstall ethernet port of hap ax3?
Replies: 4
Views: 482

Re: netinstall ethernet port of hap ax3?

Did you follow this wiki step by step?
https://wiki.mikrotik.com/wiki/Manual:Netinstall

As far as I know all ax devices are v7. Any reason for wanting to run v6?
by erlinden
Tue Sep 03, 2024 8:03 am
Forum: General
Topic: Which firmware is better, V6 or V7
Replies: 4
Views: 631

Re: Which firmware is better, V6 or V7

Gentlemen, what is the difference between firmware V6 and V7, which is better?
better?
by erlinden
Mon Sep 02, 2024 10:13 pm
Forum: General
Topic: hap ax3 random wireless disconnects
Replies: 104
Views: 9614

Re: hap ax3 random wireless disconnects

Yes, I know. And I'll tell my corporate laptop it should disconnect more often :D
by erlinden
Mon Sep 02, 2024 10:09 pm
Forum: Scripting
Topic: DuckDNS on Mikrotik
Replies: 1
Views: 419

Re: DuckDNS on Mikrotik

If you post an export of your config, we can have a look:
/export file=anynameyoulike
Post the content here without serial and any other private info en place it in between code tags by using the </> button.
by erlinden
Mon Sep 02, 2024 10:01 pm
Forum: General
Topic: hap ax3 random wireless disconnects
Replies: 104
Views: 9614

Re: hap ax3 random wireless disconnects

Would be beneficial if all people with problems share their config (at least the /interface/wifi part) to validate settings. Additional tip: when going up and down in versions you might run into some strange problems. Actually, I did...hence some steps that might be of use. I would advise (in case y...
by erlinden
Mon Sep 02, 2024 9:55 pm
Forum: Beginner Basics
Topic: capsman stops working after 7.14 upgrade [SOLVED]
Replies: 4
Views: 1894

Re: capsman stops working after 7.14 upgrade [SOLVED]

And in addition to @holvoetn complete answer: when upgrading through CAPsMAN, all packages are required (and installed). Manual upgrade is, as far as I know, the only way to miss packages.
by erlinden
Mon Sep 02, 2024 4:30 pm
Forum: SwOS
Topic: RB260GS login shows error after reset
Replies: 2
Views: 1419

Re: RB260GS login shows error after reset

Could it be a cache problem? Have you tried using an InPrivate session?
by erlinden
Fri Aug 30, 2024 11:48 am
Forum: General
Topic: CAPsMAN, RB4011-RB960PGS-cAP AX/wAP ac [SOLVED]
Replies: 16
Views: 1467

Re: CAPsMAN, RB4011-RB960PGS-cAP AX/wAP ac [SOLVED]

Removing and adding the slave interfaces did the trick...working as expected and befor.
Will stick to MikroTik longer.
by erlinden
Fri Aug 30, 2024 11:26 am
Forum: General
Topic: Wifi Interface with no channel
Replies: 6
Views: 499

Re: Wifi Interface with no channel

It is indeed, hence you should install the wireless-7.xx.x-mipsbe.npk package (which is located in the \MIPSBE\Extra packages file.
by erlinden
Fri Aug 30, 2024 10:37 am
Forum: General
Topic: CAPsMAN, RB4011-RB960PGS-cAP AX/wAP ac [SOLVED]
Replies: 16
Views: 1467

Re: CAPsMAN, RB4011-RB960PGS-cAP AX/wAP ac [SOLVED]

I did configure it with VLAN on the bridge, and the HOME network is working perfectly with VLAN ID 50, GUEST on VLAN ID 51 isn't (actually, it created interfaces dynamically with VLAN ID 1 for the GUEST network, hence there were MGT VLAN IP addresses assigned, as that is the untagged VLAN on eth0 of...
by erlinden
Thu Aug 29, 2024 8:14 pm
Forum: General
Topic: CAPsMAN, RB4011-RB960PGS-cAP AX/wAP ac [SOLVED]
Replies: 16
Views: 1467

Re: CAPsMAN, RB4011-RB960PGS-cAP AX/wAP ac [SOLVED]

Thanks as well, @mkx. Really appreciate your help! This is my current config: /interface bridge add admin-mac=xxxxxxxxxxxx auto-mac=no name=bridge-lan /interface ethernet set [ find default-name=ether1 ] name=ether1-trunk set [ find default-name=ether2 ] name=ether2-camera-rechts set [ find default-...
by erlinden
Thu Aug 29, 2024 5:39 pm
Forum: General
Topic: CAPsMAN, RB4011-RB960PGS-cAP AX/wAP ac [SOLVED]
Replies: 16
Views: 1467

Re: CAPsMAN, RB4011-RB960PGS-cAP AX/wAP ac [SOLVED]

Ok, I have adjusted as you configured it and removed the learning part.
Will monitor if this is of any help...thanks!
by erlinden
Thu Aug 29, 2024 5:16 pm
Forum: Beginner Basics
Topic: Default SOHO Firewall Rules
Replies: 10
Views: 847

Re: Default SOHO Firewall Rules

The default rules are enough for protection. Because your picture is no showing (better post /ip/firewall export), it is hard to say what you did. And I'm not going to read some website.
by erlinden
Thu Aug 29, 2024 3:33 pm
Forum: General
Topic: CAPsMAN, RB4011-RB960PGS-cAP AX/wAP ac [SOLVED]
Replies: 16
Views: 1467

Re: CAPsMAN, RB4011-RB960PGS-cAP AX/wAP ac [SOLVED]

The only thing I see in your config that jumps out at me is the independent-learning value.
Thanks gotsprings !

Another difference I notice is that you have switch1-cpu added to all your /interface ethernet switch vlan
May I ask what is the purpose of that?
by erlinden
Thu Aug 29, 2024 1:43 pm
Forum: Wireless Networking
Topic: Recommendations for replacement for Ubiquiti Picostation
Replies: 13
Views: 977

Re: Recommendations for replacement for Ubiquiti Picostation

Can you please add the requirements (apart from being outside and handling 20 caravans)?
by erlinden
Thu Aug 29, 2024 1:02 pm
Forum: General
Topic: CAPsMAN, RB4011-RB960PGS-cAP AX/wAP ac [SOLVED]
Replies: 16
Views: 1467

Re: CAPsMAN, RB4011-RB960PGS-cAP AX/wAP ac [SOLVED]

Bringing this topic back to live. I made all the adjustments to get rid of the VLAN ID = 1 necessity. All is working well, except for wireless and VLAN. For some reason I see in ARP and DHCP (leases) that wireless clients do sometimes get both IP addresses from the HOME or Guest VLAN AND the MGT VLA...
by erlinden
Thu Aug 29, 2024 9:23 am
Forum: General
Topic: CRS3X Switches and storm control/LoopProtect
Replies: 2
Views: 386

Re: CRS3X Switches and storm control/LoopProtect

This could very well be a user problem. Could you share the switch's config?
/export file=anynameyoulike
Remove serial and any other private info and place in between code tags by using the </> button.
by erlinden
Thu Aug 29, 2024 9:21 am
Forum: Beginner Basics
Topic: Need assistance with VLAN Firewall and NAT rules
Replies: 6
Views: 781

Re: Need assistance with VLAN Firewall and NAT rules

Your life would be much easier if you choose to go VLAN all the way. Lots of (correct) and great examples can be found in this topic: https://forum.mikrotik.com/viewtopic.php?t=143620 In regards to the firewall, you could consider allowing explicitely and dropping everything else. Just make sure tha...
by erlinden
Thu Aug 29, 2024 9:17 am
Forum: General
Topic: CapXL simple VLAN tagging [SOLVED]
Replies: 15
Views: 1152

Re: CapXL simple VLAN tagging [SOLVED]

Sorry for missing the link. And thanks @jadaz!

The explanation of any setting can be found here:
https://help.mikrotik.com/docs/display/ROS/WiFi
by erlinden
Wed Aug 28, 2024 4:14 pm
Forum: Beginner Basics
Topic: Wireguard Persistent keep alive, Responder
Replies: 5
Views: 599

Re: Wireguard Persistent keep alive, Responder

Keepalive should be set on the "client" peer (as well as the is-responder).
by erlinden
Wed Aug 28, 2024 1:04 pm
Forum: Beginner Basics
Topic: Wireguard Persistent keep alive, Responder
Replies: 5
Views: 599

Re: Wireguard Persistent keep alive, Responder

From the documentation: is-responder (yes | no; Default: no) Specifies if peer is intended to be connection initiator or only responder. Should be used on WireGuard devices that are used as "servers" for other devices as clients to connect to. Otherwise router will all repeatedly try to co...
by erlinden
Wed Aug 28, 2024 12:37 pm
Forum: Wireless Networking
Topic: Slow WiFi [SOLVED]
Replies: 31
Views: 2571

Re: Slow WiFi [SOLVED]

If a wired conneciton is fast, then it is not related to the routing part of the router. I also notice that the 2.4GHz radio is broadcasting on channels 1, 3 and 6. In an ideal world (funny in the 2.4GHz context) you would only use channels 1, 6 and 11. Might want to configure frequencies 2412, 2437...
by erlinden
Wed Aug 28, 2024 11:41 am
Forum: Wireless Networking
Topic: NV2 on AX
Replies: 6
Views: 1110

Re: NV2 on AX

Not only that, but the new capsman is not compatible with the older one. So if you have older devices and you buy a new one, you are SOL. Bit harsh, there are two paths you can walk in this use case: - if only ARM devices involved, upgrade them with the wifi-qcom-ac driver. - it is possible to run ...
by erlinden
Wed Aug 28, 2024 11:37 am
Forum: Wireless Networking
Topic: Ether: bridge port receiving packet with its own MAC address [SOLVED]
Replies: 19
Views: 1698

Re: Ether: bridge port receiving packet with its own MAC address [SOLVED]

Can you add both the logging and the config?
/export file=anynameyoulike
Remove serial and any other private info, post in between code tags by using the </> button.
by erlinden
Wed Aug 28, 2024 11:27 am
Forum: General
Topic: Dynamic DNS [SOLVED]
Replies: 12
Views: 999

Re: Dynamic DNS [SOLVED]

You have to come up with your requirements first. If you are aiming for 99.99% uptime, there might be better solutions.
I can tell you it is working perfectly for me, and that might give you the impression it is perfect for you too. But again, only you can tell.
by erlinden
Wed Aug 28, 2024 11:02 am
Forum: General
Topic: Dynamic DNS [SOLVED]
Replies: 12
Views: 999

Re: Dynamic DNS [SOLVED]

So, "down a couple of times" during a period of years can be considered acceptable, right?
Is it acceptable to you? That is all that matters.
by erlinden
Wed Aug 28, 2024 9:41 am
Forum: General
Topic: Dynamic DNS [SOLVED]
Replies: 12
Views: 999

Re: Dynamic DNS [SOLVED]

Have been using it for years. Setup is very easy (checkbox), I noticed that the service has been down a couple of times.
by erlinden
Wed Aug 28, 2024 9:14 am
Forum: General
Topic: CapXL simple VLAN tagging [SOLVED]
Replies: 15
Views: 1152

Re: CapXL simple VLAN tagging [SOLVED]

You would need to implement VLAN filtering on the bridge.
If you read this topic, you can find the AccessPoint.rsc which contains an example. In this example, all wifi interfaces are VLAN filtered, you just have to make the guest wifi interfaces so called "access ports".
by erlinden
Tue Aug 27, 2024 6:05 pm
Forum: Wireless Networking
Topic: Big Campus Networking help
Replies: 2
Views: 367

Re: Big Campus Networking help

It depends, especially as these requirements are far from complete.

And where does the maximum number of accesspoints come from?
Why are you assigned with this task?
What is the budget?

Choosing hardware is the least difficult part of this job.
by erlinden
Tue Aug 27, 2024 5:39 pm
Forum: Wireless Networking
Topic: Slow WiFi [SOLVED]
Replies: 31
Views: 2571

Re: Slow WiFi [SOLVED]

Well, then start by describing the issue you need to resolve first.
The topic name might give an indication :D
But agreed, both problem description and the requirements are very welcome!
by erlinden
Tue Aug 27, 2024 5:19 pm
Forum: Wireless Networking
Topic: Slow WiFi [SOLVED]
Replies: 31
Views: 2571

Re: Slow WiFi [SOLVED]

Some feedback requires insights into the config:
/export file=anynameyoulike
Remove serial and any other private info and post here inbtween code tags by using the </> button.
by erlinden
Tue Aug 27, 2024 2:50 pm
Forum: General
Topic: VLAN and Passthrough
Replies: 3
Views: 506

Re: VLAN and Passthrough

A topic which is really going to help you:
viewtopic.php?t=143620
by erlinden
Mon Aug 26, 2024 7:43 pm
Forum: Wireless Networking
Topic: SA Query timeout
Replies: 115
Views: 24506

Re: SA Query timeout

Giving this a go! Disabled it on 5Ghz interface and switched back from WPA2/3 to WPA/WPA2.
Why use WPA (when you can use open)?
8)
by erlinden
Sun Aug 25, 2024 10:16 am
Forum: Beginner Basics
Topic: Stuck in new setup
Replies: 6
Views: 820

Re: Stuck in new setup

Better (best?) idea is using VLAN's. Please read this great topic to get loads of informations and examples:
viewtopic.php?t=143620
by erlinden
Sun Aug 25, 2024 12:30 am
Forum: Beginner Basics
Topic: New router but no 5GHz - broken?
Replies: 3
Views: 465

Re: New router but no 5GHz - broken?

Because the frequency isn't set, it could take up to 10 minutes until the 5GHz radio is broadcasting.
You can set the frequency to 5180 (channel 36) manually to avoid this situation.

Does the log give any info?
At what frequency is the radio broadcasting?
by erlinden
Sat Aug 24, 2024 5:59 pm
Forum: Wireless Networking
Topic: HAP AX2 no connection to CAPsMAN
Replies: 10
Views: 716

Re: HAP AX2 no connection to CAPsMAN

How do I enable the capsman server on one of the AX2? I dont see a Capman option to enable it and set certificate options.
https://help.mikrotik.com/docs/display/ ... ionexample:
by erlinden
Fri Aug 23, 2024 7:29 pm
Forum: Beginner Basics
Topic: New router but no 5GHz - broken?
Replies: 3
Views: 465

Re: New router but no 5GHz - broken?

Yeah...or misconfigured. You make it a bit challenging coming up with a reason with the little info you provide.
Can you post:
/export file=annameyoulike
Remove serial and any other private info.
by erlinden
Thu Aug 22, 2024 2:49 pm
Forum: Wireless Networking
Topic: Mikrotik or others on AX wifi access point
Replies: 168
Views: 9275

Re: Mikrotik or others on AX wifi access point

As I mentioned in the article above, I really don't understand it very well, but maybe I can write the config details here as soon as possible and get ideas from you. Thank you.
Sure, no problem. It would be really great to have the config of the cAP ac as well, just to compare.
by erlinden
Thu Aug 22, 2024 2:44 pm
Forum: Wireless Networking
Topic: Mikrotik or others on AX wifi access point
Replies: 168
Views: 9275

Re: Mikrotik or others on AX wifi access point

What makes you think it is better and what makes you think it is not. Might be interesting to lower transmission power to get better performance.
by erlinden
Thu Aug 22, 2024 11:32 am
Forum: General
Topic: Port 445 is open even though samba is disabled
Replies: 8
Views: 646

Re: Port 445 is open even though samba is disabled

Then it would be interesting to see your complete config:
/export file=anynameyoulike
Remove serial and any other private info.
by erlinden
Thu Aug 22, 2024 9:53 am
Forum: Announcements
Topic: v7.16rc [testing] is released!
Replies: 362
Views: 112168

Re: v7.16rc [testing] is released!

Standalone AP or using CAPsMan?
CAPsMAN:

RB4011, 2x RB960 (v6.49.13), 1x Powerbox Pro (v6.49.13), 2x cAP AX, 1x wAP ac
by erlinden
Wed Aug 21, 2024 4:37 pm
Forum: Announcements
Topic: v7.16rc [testing] is released!
Replies: 362
Views: 112168

Re: v7.16rc [testing] is released!

I ran into a problem with VLAN's: wireless clients got MGT VLAN addresses assigned as well as HOME VLAN addresses. Found out from looking at the DHCP leases and IP ARP entries. After downgrading to 7.15.3 the problem was solved.

Yes, all information was supplied to support.
by erlinden
Wed Aug 21, 2024 4:04 pm
Forum: General
Topic: CRS 317-1G-16S+ Inter-VLAN routing problems (Solved)
Replies: 3
Views: 683

Re: CRS 317-1G-16S+ Inter-VLAN routing problems

Don't use VLAN ID = 1 explicitely /interface vlan add comment="Core infrastructure/Management VLAN" interface=Bridge name=VLAN1 vlan-id=1 add comment="Servers' VLAN" interface=Bridge name=VLAN250 vlan-id=250 Also, I'm missing VLAN 3249 as part of the /interface vlan (while it is ...
by erlinden
Wed Aug 21, 2024 1:53 pm
Forum: General
Topic: VLAN considerations along with CapsMan
Replies: 20
Views: 1588

Re: VLAN considerations along with CapsMan

By using hybrid ports to the CAPs, one can leave them in defaults CAPS Mode. Only identity can be adjusted (if wanted).
by erlinden
Wed Aug 21, 2024 1:51 pm
Forum: General
Topic: manual winbox upgrade
Replies: 5
Views: 501

Re: manual winbox upgrade

Indeed, just replace the existing executable with the new one.
by erlinden
Wed Aug 21, 2024 1:34 pm
Forum: General
Topic: manual winbox upgrade
Replies: 5
Views: 501

Re: manual winbox upgrade

Winbox can be downloaded on the download page:
https://mikrotik.com/download

https://mt.lv/winbox64 (64 bit)
https://mt.lv/winbox (32 bit)
by erlinden
Wed Aug 21, 2024 12:13 pm
Forum: General
Topic: VLAN considerations along with CapsMan
Replies: 20
Views: 1588

Re: VLAN considerations along with CapsMan

One disadvantage of this config, @neki, is that you have to manually adjust the CAPs (as they expect to be able to reach the CAPsMAN untagged by default).
As far as I know, you can't enable bridge VLAN filtering on ax devices. Only on ac devices, using the wifi-qcom-ac driver, this is supported.
by erlinden
Wed Aug 21, 2024 11:30 am
Forum: Wireless Networking
Topic: Legacy and new CAPsMan on the same x86 device
Replies: 6
Views: 886

Re: Legacy and new CAPsMan on the same x96 device

From v7.13.x you get the "new" CAPsMAN (capable of managing ax devices) "for free". It is added in the menu under wifi. The documentation will give you some more insights: https://help.mikrotik.com/docs/display/ROS/WiFi#WiFi-WiFiCAPsMAN The "old" CAPsMAN is part of the ...
by erlinden
Tue Aug 20, 2024 5:46 pm
Forum: General
Topic: Router OS 7 on RBD52G-5HacD2HnD (hAP ac^2)
Replies: 3
Views: 673

Re: Router OS 7 on RBD52G-5HacD2HnD (hAP ac^2)

Downgrade is nearly as easy as upgrading: you have to manually copy the (current) packages to the router en press the downgrade button.
As always, make a complete export (/export file=anynameyoulike) that can be restored any time.
by erlinden
Tue Aug 20, 2024 2:30 pm
Forum: General
Topic: Canon network printing issues
Replies: 2
Views: 382

Re: Canon network printing issues

Bit of an assumption: connect everything to the MikroTik and you will be fine.
If not (possible), make a small network diagram including all clients.
by erlinden
Tue Aug 20, 2024 2:28 pm
Forum: Virtualization
Topic: BTH vpn
Replies: 3
Views: 585

Re: BTH vpn

Here you can find the official documentation including an example:
https://help.mikrotik.com/docs/display/ ... uardtunnel
by erlinden
Tue Aug 20, 2024 11:52 am
Forum: Beginner Basics
Topic: New to Mikrotik
Replies: 19
Views: 1378

Re: New to Mikrotik

Then I found out you have to install QCOM package. So might try updating again.
The disadvantage of upgrading manually is that you could miss an additional package.
You can add it later any time, just add package.

When upgrading automatically, this won't happen.
by erlinden
Mon Aug 19, 2024 5:22 pm
Forum: General
Topic: Low speed via CAPsMAN
Replies: 18
Views: 1323

Re: Low speed via CAPsMAN

It isn't...at least, it shouldn't be.
Please test with iPerf to get better insights on the wireless speed. Using speedtest does include a lot of (possible) influencing factors.

To get best performance, please consider using the wifi-qcom-ac driver.
by erlinden
Mon Aug 19, 2024 4:33 pm
Forum: General
Topic: I have problem with microtick 750GL
Replies: 1
Views: 367

Re: I have problem with microtick 750GL

Might be a cashing thingy...have you tried reinstalling winbox?
What RouterOS and what Winbox version are you using?
by erlinden
Mon Aug 19, 2024 12:10 pm
Forum: Beginner Basics
Topic: Some ports on switches are slow
Replies: 6
Views: 551

Re: Some ports on switches are slow

Are you using RouterOS or SwOS?
Can you share the config of the switch?

Could there be any queue active on the port (or VLAN)?
by erlinden
Mon Aug 19, 2024 9:28 am
Forum: General
Topic: Problem with connecting new cap ax to the Capsman
Replies: 19
Views: 2061

Re: Problem with connecting new cap ax to the Capsman

Looks like your CAPsMAN has some errors: /interface wifi provisioning add action=create-dynamic-enabled disabled=no master-configuration=*4 \ slave-configurations=*3 supported-bands=5ghz-ac add action=create-dynamic-enabled disabled=yes identity-regexp=.*AC.* \ master-configuration=*3 name-format=2G...
by erlinden
Mon Aug 19, 2024 9:16 am
Forum: General
Topic: Allowing a VLAN to Access WAN(Internet)
Replies: 6
Views: 1134

Re: Allowing a VLAN to Access WAN(Internet)

A complete export of /ip/firewall would be very helpfull. Even better...a complete export:
/export file=anynameyoulike
Remove serial and any other private info.
by erlinden
Sat Aug 17, 2024 6:23 pm
Forum: General
Topic: Problem with connecting new cap ax to the Capsman
Replies: 19
Views: 2061

Re: Problem with connecting new cap ax to the Capsman

The wireless interfaces look disabled, can you enable them?
by erlinden
Sat Aug 17, 2024 9:17 am
Forum: Wireless Networking
Topic: Issue with roaming
Replies: 4
Views: 575

Re: Issue with roaming

Happy to hear, you can mark your topic as solved. Will probably give me some karma points 8)
by erlinden
Sat Aug 17, 2024 9:14 am
Forum: Beginner Basics
Topic: WireGuard or OpenVPN [SOLVED]
Replies: 32
Views: 3772

Re: WireGuard or OpenVPN [SOLVED]

If the IPS is blocking the ports , and even if you play with 443 that will not help to establish connections. Not sure why is that,
Are you stating that on the same port and with same protocol OpenVPN will work while Wireguard does (sometimes) not?
by erlinden
Fri Aug 16, 2024 2:20 pm
Forum: General
Topic: Firmware Upgrade
Replies: 4
Views: 602

Re: Firmware Upgrade

Have you checked the log?
by erlinden
Fri Aug 16, 2024 1:55 pm
Forum: General
Topic: Firmware Upgrade
Replies: 4
Views: 602

Re: Firmware Upgrade

Incorrect cpu architecture? Bit more info would be usefull...
by erlinden
Fri Aug 16, 2024 1:00 pm
Forum: Wireless Networking
Topic: Issue with roaming
Replies: 4
Views: 575

Re: Issue with roaming

You can add "fast transition", which should make it more easy for clients to roam: /interface wifi security add authentication-types=wpa2-psk ft=yes ft-over-ds=yes name=JUJUMAESIN-SEC passphrase=[whatever you use] What signal does the client have when connected to the CAP instead of the ro...
by erlinden
Fri Aug 16, 2024 12:35 pm
Forum: General
Topic: Low speed via CAPsMAN
Replies: 18
Views: 1323

Re: Low speed via CAPsMAN

Signal is okay! Frequency was my mistake, please try eiher 5180 or leave it empty (for automatic selection). The latter will choose based on a scan.
by erlinden
Fri Aug 16, 2024 11:23 am
Forum: General
Topic: Low speed via CAPsMAN
Replies: 18
Views: 1323

Re: Low speed via CAPsMAN

Seems a bit low(er) than possible. What is the signal value?
Could you change frequency to 5120 (channel 36)?
Did you perform a frequency scan? Any other wifi networks that could be interferring?
by erlinden
Fri Aug 16, 2024 8:39 am
Forum: General
Topic: Low speed via CAPsMAN
Replies: 18
Views: 1323

Re: Low speed via CAPsMAN

If that is the device you test with...yes.
This information can be found either on /interface/wifi/registration (are you using Winbox?) or on the laptop (are you using Windows?).
by erlinden
Fri Aug 16, 2024 8:30 am
Forum: Wireless Networking
Topic: New CAPsMAN, VLAN and error with provisioning "--- SSID not set"
Replies: 16
Views: 1914

Re: New CAPsMAN, VLAN and error with provisioning "--- SSID not set"

I have found out several topics as well in cookbook, but it seems that it will be not for my setup, so I have to read and find something else.
Here in the documentation you can find it:
https://help.mikrotik.com/docs/display/ ... %22package:
by erlinden
Thu Aug 15, 2024 6:05 pm
Forum: General
Topic: Low speed via CAPsMAN
Replies: 18
Views: 1323

Re: Low speed via CAPsMAN

Can you post at what connection rate the client is connected?
by erlinden
Thu Aug 15, 2024 4:55 pm
Forum: General
Topic: Low speed via CAPsMAN
Replies: 18
Views: 1323

Re: Low speed via CAPsMAN

Can you set local-forwarding to true:

/caps-man datapath
add bridge=bridge-guest name=guest local-forwarding=yes
by erlinden
Thu Aug 15, 2024 1:43 pm
Forum: Wireless Networking
Topic: Mikrotik or others on AX wifi access point
Replies: 168
Views: 9275

Re: Mikrotik or others on AX wifi access point

Within days/weeks the wAP AX will be introduced. Which, if I understood correct, will be smaller.

Accorindg to @Normis:
wAP ax will be a very small device and is coming very very soon (question of days or weeks)
by erlinden
Thu Aug 15, 2024 1:02 pm
Forum: Wireless Networking
Topic: Missing wAP ax successor to wAP ac, what are outdoor AX WiFi alternatives?
Replies: 35
Views: 3595

Re: Missing wAP ax successor to wAP ac, what are outdoor AX WiFi alternatives?

wAP ax will be a very small device and is coming very very soon (question of days or weeks)
:-D :-D :-D
by erlinden
Thu Aug 15, 2024 12:08 pm
Forum: Wireless Networking
Topic: Connecting v6 Device to CAPsMAN v7 [SOLVED]
Replies: 3
Views: 977

Re: Connecting v6 Device to CAPsMAN v7 [SOLVED]

The new CAPsMAN does only support wifi-qcom and wifi-qcom-ac devices. The latter is supported on ac devices, using the ARM processor. Unfortunately, the RB951 is a MIPSBE device, hence you can't find it. If you want it to be managed by your switch, you have to add the wireless package and run two in...
by erlinden
Thu Aug 15, 2024 11:51 am
Forum: General
Topic: Low speed via CAPsMAN
Replies: 18
Views: 1323

Re: Low speed via CAPsMAN

Set extension-channel to either Ce (40MHz) or Ceee (80MHz) on the 5GHz radio to get higher conenction rates. You might as well let the CAPsMAN (actually the CAP) choose a channel itself, as is configured on the hAP ac3.
by erlinden
Thu Aug 15, 2024 9:54 am
Forum: General
Topic: Low speed via CAPsMAN
Replies: 18
Views: 1323

Re: Low speed via CAPsMAN

Why did you set bandwidth to 20MHz on the 5GHz radio? This will probably make a huge difference, when set to 80MHz (Ceee). No need to set VLAN ID 1 on the datapath. Instead of using "2412,2422,2432,2442,2462", you better use 2412,2437,2462 for non overlapping channels. When setting transmi...
by erlinden
Thu Aug 15, 2024 9:15 am
Forum: Beginner Basics
Topic: VLAN on Wifi - Have Unifi AP w no Cloud Key - will it work ? [SOLVED]
Replies: 5
Views: 824

Re: VLAN on Wifi - Have Unifi AP w no Cloud Key - will it work ?

Please elaborate , why are you asking this question on a other vendors forum? Seems to me this is a good question for the UBI forum (or perhaps you already asked there?). Or just join the MikroTik community (as I did) and get proper support. 8) I would expect that the Windows Unifi Controller/Docker...
by erlinden
Wed Aug 14, 2024 8:51 pm
Forum: Wireless Networking
Topic: New CAPsMAN, VLAN and error with provisioning "--- SSID not set"
Replies: 16
Views: 1914

Re: New CAPsMAN, VLAN and error with provisioning "--- SSID not set"

Well... Start by removing this radio MAC address: /interface wifi provisioning add action=create-enabled common-name-regexp="" disabled=no identity-regexp=\ "" master-configuration=config_internal_users radio-mac=00:00:00:00:00:00 \ slave-configurations=config_guests This will pr...
by erlinden
Wed Aug 14, 2024 5:11 pm
Forum: Scripting
Topic: Mac no asignada a dhcp
Replies: 2
Views: 410

Re: Mac no asignada a dhcp

English translation (thanks to Google): Hello, I want to make a foreach based on a list of IPs to check if they are assigned in the dhcp and take action to be positive No answers here...you might get some (paid) support here: https://mikrotik.com/consultants OR What have you done so far. What is wor...
by erlinden
Wed Aug 14, 2024 4:49 pm
Forum: Beginner Basics
Topic: Switch IP address at VLAN [SOLVED]
Replies: 6
Views: 1260

Re: Switch IP address at VLAN [SOLVED]

Can you share the config?
/export file=anynameyoulike
Remove serial and any other private info.
by erlinden
Wed Aug 14, 2024 4:11 pm
Forum: Beginner Basics
Topic: Can't change network
Replies: 11
Views: 814

Re: Can't change network

Can you show exactely what IP addresses should be available for DHCP? You are aware that you can configure multiple pools? In addition, can you please share your (relevant part of the) config: /export hide-sensitive file=anynameyoulike Remove serial and any other private info and post here between c...
by erlinden
Wed Aug 14, 2024 3:57 pm
Forum: Announcements
Topic: v7.16rc [testing] is released!
Replies: 362
Views: 112168

Re: v7.16rc [testing] is released!

Do you have examples on what changes you have made that weren't provisioned?
by erlinden
Wed Aug 14, 2024 3:46 pm
Forum: Beginner Basics
Topic: Can't change network
Replies: 11
Views: 814

Re: Can't change network

Have you changed the IP pool? This is where you define the IP addresses that are available.
by erlinden
Wed Aug 14, 2024 3:25 pm
Forum: Wireless Networking
Topic: WIFI 6 AX
Replies: 1
Views: 489

Re: WIFI 6 AX

Could you also show the provisioning?
https://help.mikrotik.com/docs/display/ ... ovisioning
by erlinden
Wed Aug 14, 2024 1:20 pm
Forum: General
Topic: modes and wifi
Replies: 5
Views: 820

Re: modes and wifi

First step, forget Quickset (except for initial config...but then, still forget it). Do it manually, you will get so much more options (besides the knowledge you gain). As soon as I change anything in Winbox, the configuration is gone, I have to repeat everything over and over. This shouldn't be the...
by erlinden
Wed Aug 14, 2024 10:42 am
Forum: RouterBOARD hardware
Topic: CRS328-24P-4S+RM wirespeed switching?
Replies: 3
Views: 588

Re: CRS328-24P-4S+RM wirespeed switching?

Are you refering to the part where this switch is (ab)used as router?
by erlinden
Wed Aug 14, 2024 9:41 am
Forum: Wireless Networking
Topic: Is there a guid for setting up multiple CAP AX with 1 controller
Replies: 5
Views: 665

Re: Is there a guid for setting up multiple CAP AX with 1 controller

Just follow this help page: https://help.mikrotik.com/docs/display/ROS/WiFi#WiFi-WiFiCAPsMAN My tips: - use fixed channels for the 5GHz channels, 40MHz bandwidth (by creating a config/provision rule per CAPS filtered by MAC address) - when not using EAP, use wpa2-psk only with CCMP (only) as encrypt...
by erlinden
Wed Aug 14, 2024 9:26 am
Forum: General
Topic: enable switch chip.. more bandwidth in use?
Replies: 2
Views: 484

Re: enable switch chip.. more bandwidth in use?

Can you show the config as well?
/export file=anynameyoulike
Remove serial and any other private info en post between code tags by using the </> button.
by erlinden
Wed Aug 14, 2024 9:25 am
Forum: Wireless Networking
Topic: WIFI connecting issues
Replies: 6
Views: 1051

Re: WIFI connecting issues

Can you give it a try with:

WPA2-PSK (only) and CCMP (as encryption)?
by erlinden
Tue Aug 13, 2024 1:46 pm
Forum: General
Topic: Frequent Crashes After Updates on MikroTik hAP ac3 – Seeking Solutions
Replies: 8
Views: 645

Re: Frequent Crashes After Updates on MikroTik hAP ac3 – Seeking Solutions

Really would like to have a peek at your config:
/export file=anynameyoulike
Remove serial and any other private info.
by erlinden
Tue Aug 13, 2024 10:55 am
Forum: Beginner Basics
Topic: CAPsMAN through Switch under VLAN [SOLVED]
Replies: 15
Views: 2379

Re: CAPsMAN through Switch under VLAN [SOLVED]

Are you running the CAP's in default CAPS Mode? Are the CAP's connected to a hybrid port (where MGT VLAN is untagged)? Would you be willing to share your config?

Thanks! :-D
by erlinden
Tue Aug 13, 2024 10:44 am
Forum: Beginner Basics
Topic: CAPsMAN through Switch under VLAN [SOLVED]
Replies: 15
Views: 2379

Re: CAPsMAN through Switch under VLAN [SOLVED]

I agree except I ran into the problem that clients also received MGT VLAN IP addresses when connecting with a wifi-qcom-ac CAP. Then I started over following the CAPsMAN VLAN description in the help pages (https://help.mikrotik.com/docs/display/ROS/WiFi#WiFi-CAPsMAN-CAPVLANconfigurationexample:). Th...
by erlinden
Tue Aug 13, 2024 10:26 am
Forum: Beginner Basics
Topic: CAPsMAN through Switch under VLAN [SOLVED]
Replies: 15
Views: 2379

Re: CAPsMAN through Switch under VLAN [SOLVED]

For me it works when adding VLAN ID 1 on the switch.
by erlinden
Mon Aug 12, 2024 4:45 pm
Forum: General
Topic: Can't get UPnP to work in RouterOS 7.14.1 (Worked in RouterOS 6.x)
Replies: 17
Views: 1705

Re: Can't get UPnP to work in RouterOS 7.14.1 (Worked in RouterOS 6.x)

Can you post the ouput of:
/ip/upnp print
/ip/upnp/interfaces print
by erlinden
Mon Aug 12, 2024 3:26 pm
Forum: General
Topic: Cap devices only: "Check for updates" error - timeouts
Replies: 5
Views: 520

Re: Cap devices only: "Check for updates" error - timeouts

When using CAPsMAN you can push upgrades. Set package-path and place the packages in that path.
See here:

https://www.youtube.com/watch?v=1Ct6aJXTE5g
by erlinden
Mon Aug 12, 2024 2:48 pm
Forum: General
Topic: How can I access remotely MT behind a modem?
Replies: 13
Views: 778

Re: How can I access remotely MT behind a modem?

Can you change this rule, where the to port is the default Winbox port?

And change this rule in the firewall as well:
/ip firewall filter
add action=accept chain=input dst-port=8291 in-interface=ether1 protocol=tcp
by erlinden
Mon Aug 12, 2024 2:33 pm
Forum: General
Topic: How can I access remotely MT behind a modem?
Replies: 13
Views: 778

Re: How can I access remotely MT behind a modem?

Yes it is behind NAT and does not have a public IP address.
Did you do port forwarding on the NAT device as well?
by erlinden
Mon Aug 12, 2024 1:12 pm
Forum: General
Topic: How can I access remotely MT behind a modem?
Replies: 13
Views: 778

Re: How can I access remotely MT behind a modem?

I would prefer through VPN over making a service available publically.
Is your MT behind NAT, or does it have a publically available IP address?
Who removed all filter rules that are part of the default?
by erlinden
Mon Aug 12, 2024 11:39 am
Forum: Beginner Basics
Topic: Struggling to hard reset and provision cAP-2nD
Replies: 2
Views: 464

Re: Struggling to hard reset and provision cAP-2nD

If you can't access it after a reset (sure the credentials are correct?) and it won't go into CAPS Mode, you could consider to perform a netinstall:
https://help.mikrotik.com/docs/display/ROS/Netinstall
by erlinden
Sun Aug 11, 2024 2:28 pm
Forum: General
Topic: site-site Wiregaurd Setup
Replies: 13
Views: 910

Re: site-site Wiregaurd Setup

As the wireguard interface isn't part of the LAN interface list AND doesn't have an accept rule on the input chain, it is blocked (hence you can't ping it). You can test this by either adding an additional rule: /ip firewall filter add action=accept chain=input comment="defconf: accept ICMP&quo...
by erlinden
Sun Aug 11, 2024 2:14 pm
Forum: Beginner Basics
Topic: Weird filtering issue on 7.15.3
Replies: 2
Views: 484

Re: Weird filtering issue on 7.15.3

Enable logging on the drop rule to get insights why this rule isn't working.

I would expect the double quotes are the problem.
by erlinden
Sun Aug 11, 2024 11:26 am
Forum: Beginner Basics
Topic: First time hAP ax3 setup with VLANs, no traffic going upstream
Replies: 5
Views: 622

Re: First time hAP ax3 setup with VLANs, no traffic going upstream

These are the default firewall rules, with some irrelevant ones removed. :? If you want this device to work as router, you want a masquerade rule. But there is a lot more that is missing. If you want to have it working as switch, please read this great topic: https://forum.mikrotik.com/viewtopic.ph...
by erlinden
Sun Aug 11, 2024 10:07 am
Forum: Beginner Basics
Topic: CAPsMAN through Switch under VLAN [SOLVED]
Replies: 15
Views: 2379

Re: CAPsMAN through Switch under VLAN [SOLVED]

Aah, thanks for the explanation. You are referring to the old version (which is part of the wireless package), while TS is using the new version. The new version lacks the forwarding options.
by erlinden
Sun Aug 11, 2024 10:04 am
Forum: Beginner Basics
Topic: First time hAP ax3 setup with VLANs, no traffic going upstream
Replies: 5
Views: 622

Re: First time hAP ax3 setup with VLANs, no traffic going upstream

Besides a lot of firewall rules....VLAN filtering isn't enabled on the bridge.
by erlinden
Sun Aug 11, 2024 9:57 am
Forum: Wireless Networking
Topic: Too many interfaces for radio (CAPsMAN)
Replies: 3
Views: 471

Re: Too many interfaces for radio (CAPsMAN)

Seems to me that there are more SSID/interfaces configured than can be handled. A quick peek on your config will give better insights, can you pleas share it? /interface/wifi export file=anynameyoulike Remove serial and any other private info and post in between code tags by using the </> button.
by erlinden
Sun Aug 11, 2024 9:54 am
Forum: Beginner Basics
Topic: hAP ax3 with issues after reset
Replies: 8
Views: 1203

Re: hAP ax3 with issues after reset

My tips:
Change power supply (just to be sure)
Netinstall the device:
https://help.mikrotik.com/docs/display/ROS/Netinstall
by erlinden
Sun Aug 11, 2024 9:52 am
Forum: Wireless Networking
Topic: cAPs name in CAPsMan
Replies: 2
Views: 440

Re: cAPs name in CAPsMan

I have: - set identity on the CAP - use %I in the Name Format (as part of the provisioning From the documentation : name-format (string) Base string to use when constructing names of provisioned interfaces. Each new interface will be created by taking the base string and appending a number to the en...
by erlinden
Sat Aug 10, 2024 11:17 pm
Forum: Beginner Basics
Topic: CAPsMAN through Switch under VLAN [SOLVED]
Replies: 15
Views: 2379

Re: CAPsMAN through Switch under VLAN [SOLVED]

Local forwarding should be enabled on the datapaths because the AP is not directly connected behind the CAPsMAN Not sure what exactely you are referring to, but from the wiki: WiFi CAPsMAN only passes wireless configuration to the CAP, all forwarding decisions are left to the CAP itself - there is ...
by erlinden
Sat Aug 10, 2024 7:01 pm
Forum: General
Topic: CAPsMAN, RB4011-RB960PGS-cAP AX/wAP ac [SOLVED]
Replies: 16
Views: 1467

Re: CAPsMAN, RB4011-RB960PGS-cAP AX/wAP ac [SOLVED]

Yeah...as it seams. Remains the question...why should I add the "independent-learning=yes" for VLAN 1 on the switch?

And thanks for the addition, I added this indeed.
by erlinden
Sat Aug 10, 2024 5:56 pm
Forum: General
Topic: site-site Wiregaurd Setup
Replies: 13
Views: 910

Re: site-site Wiregaurd Setup

Checked your conig (better to place it inbetween code tags by using the </> button): /ip address add address=192.168.10.1/24 interface=" WG-HQ" network=192.168.10.0 Should be: /ip address add address=192.168.10.1/32 interface=" WG-HQ" network=192.168.10.0 AND /ip address add addr...
by erlinden
Sat Aug 10, 2024 4:55 pm
Forum: General
Topic: site-site Wiregaurd Setup
Replies: 13
Views: 910

Re: site-site Wiregaurd Setup

Mikrotik has a great explanation: https://help.mikrotik.com/docs/display/ROS/WireGuard#WireGuard-SitetoSiteWireGuardtunnel Did you add this part to the firewall as well (don't mind the used IP addresses...)? Additionally, it is possible that the "forward" chain restricts the communication ...
by erlinden
Sat Aug 10, 2024 1:48 pm
Forum: General
Topic: CAPsMAN, RB4011-RB960PGS-cAP AX/wAP ac [SOLVED]
Replies: 16
Views: 1467

CAPsMAN, RB4011-RB960PGS-cAP AX/wAP ac [SOLVED]

I need some VLAN help. I run a router with 2 VLAN's: 50 (HOME) and 51 (Guests). I use CAPsMAN to manage my 2 cAP AX and 1 wAP ac. One cAP AX is connected to the RB4011 directly, the second (and the wAP ac) are conencted through the RB 960PGS. All devices are connected through trunk ports (VLAN 50 an...
by erlinden
Thu Aug 08, 2024 6:52 pm
Forum: Beginner Basics
Topic: Wi-Fi connection randomly drops, then reconnects in seconds [SOLVED]
Replies: 21
Views: 2565

Re: Wi-Fi connection randomly drops, then reconnects in seconds [SOLVED]

Can you try setting encryption to, mbach:
encryption=ccmp,gcmp,ccmp-256,gcmp-256
And use wpa2-psk only.

And enable debug, wifi logging to get some additional information.
by erlinden
Thu Aug 08, 2024 11:12 am
Forum: General
Topic: HAP AX2 dead
Replies: 7
Views: 913

Re: HAP AX2 dead

by erlinden
Mon Aug 05, 2024 5:48 pm
Forum: Beginner Basics
Topic: tagged and untagged in one vlan table
Replies: 10
Views: 832

Re: tagged and untagged in one vlan table

The VLAN bible of Mikrotik:
viewtopic.php?t=143620

Thanks snippan for the addition. I just wanted to add it...
by erlinden
Mon Aug 05, 2024 1:38 pm
Forum: General
Topic: DoH configured but apparently not working
Replies: 3
Views: 566

Re: DoH configured but apparently not working

Did you succesfully import the certificate that is used? Anything in the log that might give an indication? Does it work if you (temporarily) disable certificate check?
Can you also check if https://1.1.1.1/dns-query does work?
by erlinden
Sun Aug 04, 2024 11:13 am
Forum: Wireless Networking
Topic: 7.15.x CAPsMAN Setup
Replies: 32
Views: 3977

Re: 7.15.x CAPsMAN Setup

OK so if I'm reading this page right, I have to do specific config on -each- CAP in order for wifi to work on a VLAN. No, you don't. What is shown is a config if you want to do it manually from scratch. If you either reset it to CAPS Mode through the reset button or the menu option it will give you...
by erlinden
Sat Aug 03, 2024 6:52 pm
Forum: Beginner Basics
Topic: wifi-qcom/AX manual WiFi uplink
Replies: 4
Views: 1182

Re: wifi-qcom/AX manual WiFi uplink

If memory serves me well, it shows that there are no clients connected to the radio.

Do you want to have feedback on your config?
/export file=anynameyoulike
Remove serial and any other private info.
by erlinden
Sat Aug 03, 2024 12:37 am
Forum: Wireless Networking
Topic: hAP ax3 wireless problem [SOLVED]
Replies: 174
Views: 37858

Re: hAP ax3 wireless problem [SOLVED]

What reasons could there be for the “Link downs” of a 5Ghz meter to trigger?
If you want some feedback, just share the config:
/export file=anynameyoulike
Remove serial and any other private info.
by erlinden
Fri Aug 02, 2024 11:23 pm
Forum: General
Topic: Hello, please help. DHCP Issues.
Replies: 1
Views: 525

Re: Hello, please help. DHCP Issues.

From your config: /interface wireless security-profiles set [ find default=yes ] supplicant-identity=MikroTik add authentication-types=wpa-psk,wpa2-psk management-protection=allowed mode=\ dynamic-keys name=profile1 supplicant-identity=MikroTik Either remove wpa-psk or don't set any security. /inter...
by erlinden
Fri Aug 02, 2024 11:06 am
Forum: Wireless Networking
Topic: CAPSMAN issues managing many existing configured CAP-AC
Replies: 1
Views: 518

Re: CAPSMAN issues managing many existing configured CAP-AC

Looks like VLAN filtering is not enabled on the bridge. From the documentation: https://help.mikrotik.com/docs/pages/viewpage.action?pageId=46759946#WifiWave2(7.12andolder)-CAPsMAN-CAPVLANconfigurationexample: Here there is a distinction between 2.4GHz and 5GHz. Can you try to do the same? Are the S...
by erlinden
Tue Jul 30, 2024 10:52 am
Forum: Wireless Networking
Topic: hAP ax3 wireless problem [SOLVED]
Replies: 174
Views: 37858

Re: hAP ax3 wireless problem [SOLVED]

I hope the manufacturer will be able to fix all the errors and shortcomings of hAP ax3 with updates.
That would involve the users as well 8)

If you want some feedback, just share the config:
/export file=anynameyoulike
Remove serial and any other private info.
by erlinden
Tue Jul 30, 2024 10:49 am
Forum: General
Topic: how to identify which ip is infected and being used for a DDoS? [SOLVED]
Replies: 16
Views: 3187

Re: how to identify which ip is infected and being used for a DDoS? [SOLVED]

Turn it off and see if you can open the /ip/firewall/connections tab. That should be a good indication.
by erlinden
Tue Jul 30, 2024 10:47 am
Forum: Beginner Basics
Topic: Wi-Fi connection randomly drops, then reconnects in seconds [SOLVED]
Replies: 21
Views: 2565

Re: Wi-Fi connection randomly drops, then reconnects in seconds [SOLVED]

so it's unlikely that I misconfigured something. What could be the problem? What are some ways to troubleshoot this issue? By default WPA2 and WPA3 are enabled. That gave me a lot of problems. To troubleshoot (together with you): What RouterOS version are you running? Can you share the config? /exp...
by erlinden
Mon Jul 29, 2024 5:39 pm
Forum: Beginner Basics
Topic: Just installed and having troubles with DNS
Replies: 2
Views: 774

Re: Just installed and having troubles with DNS

/ip pool add name=default-dhcp ranges=192.168.88.10-192.168.88.254 /ip address add address=192.168.1.11/24 comment=defconf interface=bridge network=192.168.1.0 /ip dhcp-server network add address=192.168.0.0/24 comment=defconf dns-server=192.168.0.99 gateway=192.168.0.99 netmask=24 Looks like three...
by erlinden
Sun Jul 28, 2024 10:21 am
Forum: Announcements
Topic: v7.16beta [testing] is released!
Replies: 288
Views: 118329

Re: v7.16beta [testing] is released!

if u want to get to the trouble, then use the new CapsMan
Can you eleborate this? I'm onto the beta in my home environment (I know, just a small network). Haven't had any strange CAPsMAN things, at least for me it is working not any less stable than the stable version.
by erlinden
Fri Jul 26, 2024 3:25 pm
Forum: Wireless Networking
Topic: Netbox 5 AX Frequency Settings
Replies: 4
Views: 681

Re: Netbox 5 AX Frequency Settings

To use all frequencies, just buy another 10 (or something) Netboxes. Or understand how wifi is working.
Furthermore, why don't you want to set a country?
by erlinden
Fri Jul 26, 2024 3:15 pm
Forum: Wireless Networking
Topic: disconnecting wifi clients
Replies: 4
Views: 620

Re: disconnecting wifi clients

Are there more clients suffering from this?

You could add wireless debug logging to get some additional information.
Besides, can you perhaps share your config:
/export file=anynameyoulike
Remove serial and any other private info.
by erlinden
Thu Jul 25, 2024 7:33 pm
Forum: General
Topic: DoH certificate handshake failed (Quad9)
Replies: 7
Views: 935

Re: DoH certificate handshake failed (Quad9)

Could it be that the imported certificate is expired or renewed?
by erlinden
Thu Jul 25, 2024 7:10 pm
Forum: General
Topic: DoH certificate handshake failed (Quad9)
Replies: 7
Views: 935

Re: DoH certificate handshake failed (Quad9)

If you want to check "Verify DoH Certificate" (which you obviously do), you hwave to make sure the MikroTik has the Root CA installed.

Check this blog that explains the steps to get it to work:
https://www.shellhacks.com/mikrotik-dns ... loudflare/
by erlinden
Tue Jul 23, 2024 7:46 pm
Forum: Wireless Networking
Topic: 7.15.x CAPsMAN Setup
Replies: 32
Views: 3977

Re: 7.15.x CAPsMAN Setup

At least reset the accesspoint to CAPS Mode. Do you see any radios on /wifi/radios (that is on the CAPsMAN)?

Currently on smartphone, going through the config isn't easy.
by erlinden
Mon Jul 22, 2024 11:41 am
Forum: Beginner Basics
Topic: Allow Outgoing UDP TCP connections
Replies: 1
Views: 433

Re: Allow Outgoing UDP TCP connections

In a default situation the router won't block this (any) traffic outgoing.
Can you share your config (at least the /ip/firewall part)?
/ip/firewall export

or

/export file=anynameyoulike
Are you using LTE? Could be that the provider is blocking the traffic.
by erlinden
Sun Jul 21, 2024 11:58 pm
Forum: Beginner Basics
Topic: DNS issue hAP ax3 [SOLVED]
Replies: 2
Views: 2027

Re: DNS issue hAP ax3 [SOLVED]

Looks like the DNS server is disabled. To turn it on:
/ip dns
set allow-remote-requests=yes
by erlinden
Sun Jul 21, 2024 6:10 pm
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 655
Views: 256059

Re: v7.15 [stable] is released!

I was also getting the script error in my logs after upgrading to 7.15. "executing script from scheduler failed, please check it manually" The solution was to replace the word "system" with "routeros" Old - :set Var1 "$[/system package get system version]" Ne...
by erlinden
Sun Jul 21, 2024 6:02 pm
Forum: RouterBOARD hardware
Topic: wAP ac (RBwAPG-5HacT2HnD) rebooting every 10 seconds
Replies: 3
Views: 646

Re: wAP ac (RBwAPG-5HacT2HnD) rebooting every 10 seconds

Either get a new wAP ac or, if time wouldn't be of an issue, wait for a wAP ax.
by erlinden
Sun Jul 21, 2024 3:10 pm
Forum: General
Topic: MikroTik hAP ac2 cant login
Replies: 4
Views: 565

Re: MikroTik hAP ac2 cant login

Assuming you are using the wifi-qcom-ac driver:
https://help.mikrotik.com/docs/display/ROS/WiFi
by erlinden
Sat Jul 20, 2024 8:29 pm
Forum: Wireless Networking
Topic: The most arduous access point ever: hAP ax³
Replies: 48
Views: 2906

Re: The most arduous access point ever: hAP ax³

Use wpa2-aes only for the time being. And only ccmp. And turn on debug logging on wifi to get some more insights.
by erlinden
Sun Jul 14, 2024 10:52 am
Forum: Wireless Networking
Topic: wifi-qcom-ac package for wAP ac (mipsbe) [SOLVED]
Replies: 2
Views: 2508

Re: wifi-qcom-ac package for wAP ac (mipsbe) [SOLVED]

Wifi-qcom-ac is only supported on ARM devices.
by erlinden
Thu Jul 11, 2024 1:29 pm
Forum: Scripting
Topic: Routing rules for dynamic IP addresses
Replies: 16
Views: 3914

Re: Routing rules for dynamic IP addresses

I use address list, create a list (i.e. WAN-IP) and add the address (blahblah.sn.mynetname.net).
Then you can refer to the address list (with its name).
by erlinden
Thu Jul 11, 2024 10:52 am
Forum: General
Topic: Could not resolve dns name [SOLVED]
Replies: 5
Views: 2025

Re: Could not resolve dns name [SOLVED]

Does the switch have an IP address, gateway and access to the Internet?
Can you ping router/public DNS server?
by erlinden
Wed Jul 10, 2024 6:04 pm
Forum: The User Manager
Topic: cannot login to user manager
Replies: 3
Views: 816

Re: cannot login to user manager

Are there any files that remained on the filesystem? You might need to delete them manually.
Or better...netinstall it with the latest v6 LTS (currently 6.49.13)
by erlinden
Wed Jul 10, 2024 5:33 pm
Forum: Beginner Basics
Topic: Am I being port scanned?
Replies: 9
Views: 935

Re: Am I being port scanned?

If you are worried with security, you might want to reconsider this:
/ip upnp
set enabled=yes
/ip upnp interfaces
add interface=ether1 type=external
Ports are scanned, up to you if you want to have it logged...or not.
by erlinden
Wed Jul 10, 2024 5:13 pm
Forum: Beginner Basics
Topic: Am I being port scanned?
Replies: 9
Views: 935

Re: Am I being port scanned?

Also wanted to know why (default mikrotik rules) drop all not incoming from LAN supersede drop from wan not dstnated? It does not matter what order are they in, drop not dstnated is just not working. I also have hairpin NAT, might that be a problem? There is a difference between the input chain (ac...
by erlinden
Wed Jul 10, 2024 9:37 am
Forum: General
Topic: cache full, not storing since 7.14
Replies: 29
Views: 10217

Re: cache full, not storing since 7.14

Cache size is configurable, you might want to increase the memory (if you haven't tried already?):
/ip dns
set cache-size=20480KiB
by erlinden
Tue Jul 09, 2024 9:41 am
Forum: Announcements
Topic: v7.15.3 [stable] is released!
Replies: 655
Views: 256059

Re: v7.15.2 [stable] is released!

Something is wrong with the initial scan for 5 GHz. Every time at boot, the frequency is set to 5500 on all APs. This does not happen for 2.4 GHz where APs receive different frequencies. That is something that is bothering me as well. This frequency is checked for 1 min before used, hence this situ...
by erlinden
Tue Jul 09, 2024 9:37 am
Forum: Wireless Networking
Topic: wlan1: failed to select channel
Replies: 3
Views: 1016

Re: wlan1: failed to select channel

/interface wireless security-profiles set [ find default=yes ] supplicant-identity=MikroTik add authentication-types=wpa-psk,wpa2-psk,wpa-eap,wpa2-eap eap-methods="" \ group-ciphers=tkip,aes-ccm management-protection=allowed mode=dynamic-keys \ name=kokoriko supplicant-identity="&quo...
by erlinden
Mon Jul 08, 2024 5:40 pm
Forum: Wireless Networking
Topic: Capsman: AP Behavior on very basic config
Replies: 7
Views: 791

Re: Capsman: AP Behavior on very basic config

/caps-man channel add band=2ghz-b/g/n name=2g4 Does the above really make sense to you? All you do here is set the band, not the channels. Ie, you wnat to set: frequency=2412,2437,2462 I never use auto, I want to decide which frequency gets used. How do you handle this, a config per radio? How do y...
by erlinden
Mon Jul 08, 2024 2:41 pm
Forum: Wireless Networking
Topic: cap ax3 unable to connect to cap manager on RB751G
Replies: 8
Views: 751

Re: cap ax3 unable to connect to cap manager on RB751G

can wifi capsman be run on a mipsbe device?
Sure (comes with 7.13 and up), but it won't be able to manage its own wireless interfaces.
by erlinden
Sat Jul 06, 2024 10:04 am
Forum: Wireless Networking
Topic: Roaming not working
Replies: 4
Views: 744

Re: Roaming not working

Good that you have found the forum! More interesting information can be found on YouTube (though there is a lot of garbage on it as well). Make sure to follow MikorTik and have a lok at this video:

https://www.youtube.com/watch?v=37aff6d14Xk
by erlinden
Fri Jul 05, 2024 4:25 pm
Forum: General
Topic: Internet suddenly stopped working for inner network - [SOLVED]
Replies: 11
Views: 2496

Re: Internet suddenly stopped working for inner network - [SOLVED]

I think in the end that is most important.

In regards to doing wrong...your firewall config has some space for improvement. Being polite on this.
In addition, are you sure you want to have port 22 available publically?
Who manages this router? This due to the fact it is running 7.6.
by erlinden
Fri Jul 05, 2024 1:49 pm
Forum: General
Topic: General ISP IP question.. [SOLVED]
Replies: 2
Views: 1399

Re: General ISP IP question.. [SOLVED]

The answer is either 42 or NAT.
by erlinden
Thu Jul 04, 2024 12:47 pm
Forum: Beginner Basics
Topic: New dns addlist functionality and it doesn't work - I'm not even mad.
Replies: 9
Views: 2636

Re: New dns addlist functionality and it doesn't work - I'm not even mad.

Hmm, methinks someone is upset Italy crashed out of the EuroCup! ;-) Canada wasn't part of it in the first place :lol: Too bad my RB760iGS isn't able to download the file due to too little flash memory. Does anyone have a solution to that? Apart from downloading it as file and load it from file, as...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 9