Community discussions

MikroTik App

Search found 1740 matches

by erlinden
Fri Dec 01, 2023 11:34 am
Forum: Forwarding Protocols
Topic: RDP not working in lan
Replies: 2
Views: 132

Re: RDP not working in lan

As all interfaces are on the same bridge, from a computer perspective this connection is through a switch (so no firewall involved). DHCP reservations are beneficial for the IP addresses but not necessary. I would expect to find the solution in the notebook, is this network a so called "private...
by erlinden
Thu Nov 30, 2023 9:43 am
Forum: General
Topic: Clients not able to browse internet running a CCR2004-16G-2S
Replies: 2
Views: 220

Re: Clients not able to browse internet running a CCR2004-16G-2S

Id on not agree with the above: /ip dhcp-server network add address=192.168.1.0/24 dns-server=192.168.1.1 gateway=192.168.1.1 netmask=24 Can a wireless client ping any public IP at all? Does the DNS server resolve names correctly while connected wireless? Can you please remove serial and place the c...
by erlinden
Tue Nov 28, 2023 3:12 pm
Forum: Announcements
Topic: Newsletter #115 | November 2023
Replies: 11
Views: 3411

Re: Newsletter #115 | November 2023

Nice!
by erlinden
Mon Nov 27, 2023 9:25 pm
Forum: RouterBOARD hardware
Topic: RB750GR3 worth to cahnge to RB3011UiAS-RM
Replies: 5
Views: 499

Re: RB750GR3 worth to cahnge to RB3011UiAS-RM

But my configuration can't have fast track
Because?
Can you share your config?
/export file=anynameyoulike
Remove serial and any other private information and post between code tabs, using the </> button
by erlinden
Mon Nov 27, 2023 9:34 am
Forum: Announcements
Topic: v7.12.1 [stable] is released!
Replies: 238
Views: 57819

Re: v7.12.1 [stable] is released!

Can you share the config, @oldunixguy?
/export file=anynameyoulike
Remove serial and any other private information and place the ouptu between code tags with the </> button.

CLI not the better option for you?
by erlinden
Fri Nov 24, 2023 10:54 am
Forum: Beginner Basics
Topic: Set a network to having the same SSID across the APs?
Replies: 3
Views: 315

Re: Set a network to having the same SSID across the APs?

Share config (of the CRS):
/export file=anynameyoulike
Remove serial and any other private information (and place the output here between code tags </> button)

Have you followed this tutorial:
https://help.mikrotik.com/docs/pages/vi ... Id=1409149
by erlinden
Wed Nov 22, 2023 2:42 pm
Forum: Wireless Networking
Topic: Cap AX: Windows Clients: "Can't connect to this network"
Replies: 18
Views: 1230

Re: Cap AX: Windows Clients: "Can't connect to this network"

Still back at square one. Device not detected on Router. Master: Unknown
How did that MAC address get there?
by erlinden
Wed Nov 22, 2023 11:15 am
Forum: General
Topic: hEX upgrade to version 7
Replies: 2
Views: 267

Re: hEX upgrade to version 7

On this forum :D

Can you please share your V7 config:
/export file=anynameyoulike
Remove serial and any other private information. And please place the output between code tags, that is the </> button.
by erlinden
Tue Nov 21, 2023 9:12 pm
Forum: Beginner Basics
Topic: can not activate www-ssl service [SOLVED]
Replies: 6
Views: 395

Re: can not activate www-ssl service [SOLVED]

Have you tried rebooting?
by erlinden
Tue Nov 21, 2023 8:43 pm
Forum: Beginner Basics
Topic: can not activate www-ssl service [SOLVED]
Replies: 6
Views: 395

Re: can not activate www-ssl service [SOLVED]

Do you perhaps have a port forward on port 443?
Anything in the logging?
by erlinden
Tue Nov 21, 2023 8:26 pm
Forum: General
Topic: Questions about (basic) firewall
Replies: 9
Views: 960

Re: Questions about (basic) firewall

Have you found this topic yet:
viewtopic.php?t=180838

@anav is well known on this forum for both his firewall knowledge as well as his communication skills
by erlinden
Tue Nov 21, 2023 2:38 pm
Forum: Wireless Networking
Topic: hap ax3 wifi problem
Replies: 3
Views: 394

Re: hap ax3 wifi problem

A virtual interface uses the same frequency as its master. Per radio there is only one frequency possible. Did you do a complete config of the virtual interface (at least SSID)? Can you share your config? /export file=anynameyoulike Remove serial and any other private information. And place the expo...
by erlinden
Tue Nov 21, 2023 10:13 am
Forum: General
Topic: Firewall FIlter DROP rule [SOLVED]
Replies: 2
Views: 392

Re: Firewall FIlter DROP rule [SOLVED]

Ending with a "drop all" is a very nice approach: it will force you to think about what you want to allow. In regards to your firewall rules: I prefer to first set all rules on the input chain and then on the forward chain. Just for readability (is that correct English?). The order is of i...
by erlinden
Tue Nov 21, 2023 10:05 am
Forum: General
Topic: DHCP problem with Chinese wireless repeater connected to Mikrotik AP
Replies: 6
Views: 820

Re: DHCP problem with Chinese wireless repeater connected to Mikrotik AP

Can you please share your config, just to make sure...?
/export file=anynameyoulike
Remove serial and any other private information, and place the output here between code tags (</> button)
by erlinden
Fri Nov 17, 2023 12:23 pm
Forum: Announcements
Topic: v6.49.10 [long-term] is released!
Replies: 32
Views: 73464

Re: v6.49.10 [long-term] is released!

That is because LTS and stable are on the same version (but there might be a difference in build number which is not the same as version). Just ignore it. Or not.
by erlinden
Fri Nov 17, 2023 10:39 am
Forum: Announcements
Topic: v7.12.1 [stable] is released!
Replies: 238
Views: 57819

Re: v7.12 [stable] is released!

i can not add new cap to existed old capsMan
cAP ac or cAP ax? For the latter you will have to wait for v7.13 (currently beta) to be able.
by erlinden
Wed Nov 15, 2023 4:50 pm
Forum: Beginner Basics
Topic: 7.13 Beta 5Ghz issue (hap ax2)
Replies: 15
Views: 873

Re: 7.13 Beta 5Ghz issue (hap ax2)

Looks like it fixed the issue. But now I have a weaker signal (
Is that a problem? Your accesspoint is probably still sending with higher signal than the mobile device.
Stronger is not always better...
by erlinden
Wed Nov 15, 2023 4:40 pm
Forum: Beginner Basics
Topic: Need advice for home network with RB1100 and CRS125
Replies: 2
Views: 237

Re: Need advice for home network with RB1100 and CRS125

A1. Is your modem a router as well: YES = sell RB1100/NO = Modem, Router, Switch, wAP A2. A router needs a firewall, especially when publically available (public IP address) A3. A switch is a switch, no router -> no firewall A4. Default firewall rules are sufficient A5. SSID per network, VLAN is a v...
by erlinden
Fri Nov 10, 2023 5:51 pm
Forum: General
Topic: Mikrotik 4011 ethernet 6-10 link down
Replies: 2
Views: 601

Re: Mikrotik 4011 ethernet 6-10 link down

Have been running my RB4011 with nearly all versions...never had this problem. Can you share your config (just to be sure)? /export file=anynameyoulike Remove serial and any other private information, and place it in between code tags: </> Have you tried using a different power supply? Could it be r...
by erlinden
Thu Nov 09, 2023 4:13 pm
Forum: Announcements
Topic: v7.12.1 [stable] is released!
Replies: 238
Views: 57819

Re: v7.12 [stable] is released!

RB4011, hAP ax2, hEX S, wAP ac and cAP ac upgraded, no problems for me.
by erlinden
Thu Nov 09, 2023 12:04 pm
Forum: Wireless Networking
Topic: CapsmMan / AirServer
Replies: 6
Views: 719

Re: CapsmMan / AirServer

Everyone can use Google translate: Hello folks, I'll try it in German first because I probably won't be able to describe the problem clearly in English. I have a WiFi environment with 14 access points (CAP AC and CAP XL) and an RB5009 as Capsman. The illumination with Tamo showed that I had no space...
by erlinden
Thu Nov 09, 2023 11:13 am
Forum: General
Topic: crs309 poor 10gb performance
Replies: 28
Views: 1791

Re: crs309 poor 10gb performance

What is the processor consumption while performing a speedtest?
by erlinden
Tue Nov 07, 2023 5:50 pm
Forum: Beginner Basics
Topic: version 7.12.rc6, enabling the DHCP server on a VLAN interface does not work properly.
Replies: 3
Views: 504

Re: version 7.12.rc6, enabling the DHCP server on a VLAN interface does not work properly.

Yes it does.

By which I mean:
  • can you explain what you are running into exactely?
  • can you share relevant config?
/export file=anynameyoulike
Remove serial and any other private information. And please use the </> tag!
by erlinden
Tue Nov 07, 2023 5:47 pm
Forum: General
Topic: They are attacking me?
Replies: 13
Views: 1048

Re: They are attacking me?

You can't stop users for getting around security. Reason I block port 853 is because it was used by a Huawei smartphone (out of the box).
by erlinden
Tue Nov 07, 2023 5:29 pm
Forum: General
Topic: They are attacking me?
Replies: 13
Views: 1048

Re: They are attacking me?

I think you indeed have to add the interface list to prefend that anyone (from the Internet) can use your router to get to the DNS server (94.140.14.15). So it is solved. Therefor no attack, just abuse of an incorrect firewall config. As well you might want to consider closing port 853 (DNS over TLS...
by erlinden
Tue Nov 07, 2023 5:19 pm
Forum: General
Topic: They are attacking me?
Replies: 13
Views: 1048

Re: They are attacking me?

I think your family is attacking you... :D What do you think these two lines do? add action=dst-nat chain=dstnat comment="DNS ADGUARD FAMILY UDP" dst-port=53 in-interface-list=USUARIOS protocol=udp to-addresses=94.140.14.15 to-ports=53 add action=dst-nat chain=dstnat comment="DNS ADGU...
by erlinden
Tue Nov 07, 2023 8:45 am
Forum: General
Topic: How to secure the environment?
Replies: 20
Views: 1497

Re: How to secure the environment?

Isn't there an easier way than vlans to segregate traffic by which SSID users connect to?
Sure, get seperate hardware and a second internet connection.
by erlinden
Mon Nov 06, 2023 2:04 pm
Forum: General
Topic: How to secure the environment?
Replies: 20
Views: 1497

Re: How to secure the environment?

Is there an easier way to secure my environment? If you have seen this topic: https://forum.mikrotik.com/viewtopic.php?t=143620 and find it over your head, you should consider getting external help. As, based on your information, you might not be the man for the job. My tip (if you still want to do...
by erlinden
Fri Nov 03, 2023 2:13 pm
Forum: RouterBOARD hardware
Topic: Hap AX2 max CPU temp
Replies: 7
Views: 2440

Re: Hap AX2 max CPU temp

My AX2 has 55C when idle, is it okay?
Just checked, around 53C here.
by erlinden
Fri Nov 03, 2023 10:08 am
Forum: Announcements
Topic: v6.49.10 [long-term] is released!
Replies: 32
Views: 73464

Re: v6.49.10 [long-term] is released!

@Numlock, if you change Channel to long term, is this still happening?
by erlinden
Fri Nov 03, 2023 9:56 am
Forum: Wireless Networking
Topic: hap3 low WiFi speed [SOLVED]
Replies: 8
Views: 956

Re: hap3 low WiFi speed [SOLVED]

  • Don't ever use WPA-PSK, use WPA2-PSK only.
  • Don't use legacy protocols, use 802.11n on 2.4GHz and 802.11n/ac on 5GHz
  • Don't use 40MHz bandwidth on the 2.4GHz radio, unless you live in the middle of nowhere
Then test again.

At what speed is the testdevice connected to the router?
by erlinden
Thu Nov 02, 2023 4:55 pm
Forum: Beginner Basics
Topic: SFP Help
Replies: 4
Views: 549

Re: SFP Help

Will you have an AON or an XG-PON connection (assuming you will have fibre)?
by erlinden
Thu Nov 02, 2023 1:20 pm
Forum: Wireless Networking
Topic: Low speed CAp LITE [SOLVED]
Replies: 5
Views: 693

Re: Low speed CAp LITE [SOLVED]

At what speed (rate) is the phone wirelessly connected to the router?
What speed do you expect?
How crowded is the 2.4GHz band (use the scan option of the Mikrotik)?
by erlinden
Wed Nov 01, 2023 6:19 pm
Forum: RouterBOARD hardware
Topic: RB 1100 Parou todas as funções depois de uma atualização.
Replies: 3
Views: 489

Re: RB 1100 Parou todas as funções depois de uma atualização.

Google Translate (https://translate.google.com/?hl=nl&sl=auto&tl=en&op=translate): Good morning everyone, I'm new here, I needed the new WireGuard function that was released in version 7.11 so I decided to update my RB 1100 to the stable version 7.11.2. When updating the RB it simply tur...
by erlinden
Wed Nov 01, 2023 1:39 pm
Forum: Beginner Basics
Topic: port forwarding not working on RB3011
Replies: 8
Views: 1027

Re: port forwarding not working on RB3011

Your rule is basically a drop all rule (which is fine by itself), hence everything from WAN is dropped. If you want to be able to port forward, you have to accept for specific ports, something like: add action=accept chain=forward dst-address=192.168.1.254 dst-port=59010 log=yes log-prefix="POR...
by erlinden
Wed Nov 01, 2023 11:19 am
Forum: Wireless Networking
Topic: Add cAP with all interfaces to main network [SOLVED]
Replies: 2
Views: 553

Re: Add cAP with all interfaces to main network [SOLVED]

Sounds like you have your CAP currently configured as router...why? Not completely clear what you try to accomplish, but it would make more sense (in my opinion) to configure the CAP as CAP (through either reset or Quick Set): https://help.mikrotik.com/docs/display/UM/cAP#:~:text=Reset%20button,-The...
by erlinden
Mon Oct 30, 2023 2:43 pm
Forum: Beginner Basics
Topic: CAPsMAN ROS v6 and v7
Replies: 5
Views: 567

Re: CAPsMAN ROS v6 and v7

What exactely do you mean by V7 device? The "real" difference is being either a wifiwave2 device...or not.
by erlinden
Sun Oct 29, 2023 5:51 pm
Forum: General
Topic: OpenVPN connection Cannot establised, error msg: TLS error: Handshake TImed out
Replies: 3
Views: 868

Re: OpenVPN connection Cannot establised, error msg: TLS error: Handshake TImed out

Did you configure the openvpn_client (that's one of the reasons it is preferred to have the config instead, as a lot of info is missing). Why did you open the port? Assuming you want to connect the router to the office? /export file=anynameyoulike Just remove serial and any other private information.
by erlinden
Thu Oct 26, 2023 2:13 pm
Forum: General
Topic: L2TP Client not connecting
Replies: 5
Views: 654

Re: L2TP Client not connecting

Using Windows Server 2012 is wrong in itself...but I guest that is not the question.
How is the client configured?
And how is the server configured?
/export file=anynameyoulike
Make sure to remove serial and any other private information.
by erlinden
Thu Oct 26, 2023 10:09 am
Forum: SwOS
Topic: CRS106-1C-5S SWOS
Replies: 5
Views: 3785

Re: CRS106-1C-5S SWOS

What are you trying to accomplish functionally, @fxwireless?
by erlinden
Tue Oct 24, 2023 5:00 pm
Forum: Beginner Basics
Topic: IoT/guest network on hAP ax lite [SOLVED]
Replies: 13
Views: 1444

Re: IoT/guest network on hAP ax lite [SOLVED]

Depends on your requirements, if you can supply them first?
by erlinden
Tue Oct 24, 2023 4:57 pm
Forum: General
Topic: Opening SSH port to CCR2004 [SOLVED]
Replies: 3
Views: 806

Re: Opening SSH port to CCR2004 [SOLVED]

I think we all have been there :D
Glad it is solved!
by erlinden
Tue Oct 24, 2023 4:01 pm
Forum: General
Topic: Opening SSH port to CCR2004 [SOLVED]
Replies: 3
Views: 806

Re: Opening SSH port to CCR2004 [SOLVED]

Not working is a bit arbitrary, what exactely is not working and how do you test it?

Seems the port forward you created is correct, did you change anything in the default firewall?
Could you please add your config?
/export file=anynameyoulike
Remove serial and any other pricate information.
by erlinden
Tue Oct 24, 2023 1:09 pm
Forum: Wireless Networking
Topic: hAP ax2 randomly drops WiFi SSIDs (both 2,4 and 5Ghz)
Replies: 126
Views: 20909

Re: hAP ax2 randomly drops WiFi SSIDs (both 2,4 and 5Ghz)

Strange, as I find it rock stable (running at my parents house). My used config: /interface wifiwave2 channel add band=5ghz-ax disabled=no frequency=5260,5300,5500,5540,5580,5620,5660 name=CH5G width=20/40mhz-Ce add band=2ghz-ax disabled=no frequency=2412,2437,2460 name=CH2.4G width=20mhz /interface...
by erlinden
Tue Oct 24, 2023 9:53 am
Forum: Wireless Networking
Topic: How to turn off 2.4G WiFi signal
Replies: 3
Views: 746

Re: How to turn off 2.4G WiFi signal

Disabling the interface should turn off the radio. Are you sure your test method is correct?
by erlinden
Tue Oct 24, 2023 8:36 am
Forum: General
Topic: RB5009 can't get automatic IP from WAN.
Replies: 4
Views: 838

Re: RB5009 can't get automatic IP from WAN.

When using PPPoE you don't need an (additional) DHCP client. That is handled by the PPPoE client itself. Or is IP supplied through DHCP?
Can you share config of both routers? And what do you mean by "My PPPoE and Static are working fine"?
by erlinden
Tue Oct 24, 2023 8:29 am
Forum: Wireless Networking
Topic: Getting hex s and cap ax to play nicely together
Replies: 2
Views: 670

Re: Getting hex s and cap ax to play nicely together

Configure the eth1 (assuming that is the port you connect your cAP ax with) as trunk port (as well) and do VLAN filtering on the bridge. Then you are good to go.

For VLAN reference, please use this great tutorial:
viewtopic.php?t=143620
by erlinden
Mon Oct 23, 2023 8:38 pm
Forum: General
Topic: RB5009 PoE out constant cycling [SOLVED]
Replies: 7
Views: 1181

Re: RB5009 PoE out constant cycling [SOLVED]

So absolutely nothing has changed except the RB5009?
How did you configure POE? auto on/forced on? If not the latter, can you give that a try?
by erlinden
Sun Oct 22, 2023 3:28 pm
Forum: Beginner Basics
Topic: WIFI VLAN on ax^2
Replies: 4
Views: 900

Re: WIFI VLAN on ax^2

Lol...never ever use VLAN id 1, it is already in use implicitely. Anything higher than 1 will do (though it is probably limited). In regards to using VLAN (this is a must read tutorial): https://forum.mikrotik.com/viewtopic.php?t=143620 In regards to asking for support, instead of posting screenshot...
by erlinden
Sun Oct 22, 2023 1:42 pm
Forum: General
Topic: VLAN Issues
Replies: 13
Views: 1494

Re: VLAN Issues

From your configuration I assume you are using 3 networks:
  • "Corporate": 192.168.88.1/24
  • stelzer.local
  • smarthome.local
Corporate (as I call it) will use default vlan id (which is 1). Better, in my opinion, is to give it an explicit vlan id as well.
In line with the examples...
by erlinden
Sun Oct 22, 2023 1:36 pm
Forum: Wireless Networking
Topic: cAP ax find not CAPsMAN and get no config [SOLVED]
Replies: 5
Views: 1206

Re: cAP ax find not CAPsMAN and get no config [SOLVED]

You are running the "old" CAPsMAN while the cAP ax only supports the wifiwave2 CAPsMAN. No backward compatibility, will never come (I think I red that). You will need to install wifiwave2 on the RB5009 and configure it from there: https://help.mikrotik.com/docs/display/ROS/WifiWave2#WifiWa...
by erlinden
Sun Oct 22, 2023 12:02 am
Forum: General
Topic: VLAN Issues
Replies: 13
Views: 1494

Re: VLAN Issues

I prefer to use VLAN all the way, no hybrid/implicit VLAN's. That would mean that you add an additional VLAN.
In your config I missed the DHCP servers for the VLAN's, is that on purpose?

Btw, you didn't follow the tutorial completely.
by erlinden
Fri Oct 20, 2023 10:39 am
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 83739

Re: v7.12rc is released!

Upgrading from v6.9x to 7.12rc2 all bgp, mpls, ospf settimg all missing.

Thx
What did you expect...just upgrade and continue? You just moved to a new major version!
by erlinden
Fri Oct 20, 2023 10:35 am
Forum: Beginner Basics
Topic: Queue
Replies: 2
Views: 654

Re: Queue

Can you please share your current config, bit hard to understand the situation:
/export file=anynameyoulike
Remove serial and any other private information.
by erlinden
Thu Oct 19, 2023 5:18 pm
Forum: Scripting
Topic: For ISP: How to ***really*** block invalid ICMP, TCP, UDP packets and others (ver. 2021)
Replies: 21
Views: 67810

Re: For ISP: How to ***really*** block invalid ICMP, TCP, UDP packets and others (ver. 2021)

Really love this post, turns out my provider is not blocking a lot.... As well as my GS accesspoints turned out to broadcast a lot to 224.0.0.120. One thing: add action=log chain=prerouting log=yes log-prefix="Not TCP protocol" protocol=!tcp Because the action=log , you don't have to do lo...
by erlinden
Thu Oct 19, 2023 5:15 pm
Forum: RouterBOARD hardware
Topic: Switch with poe & SFP
Replies: 10
Views: 1182

Re: Switch with poe & SFP

The RB960PGS does support 12-57 V (802.3af/at) as POE in:
https://mikrotik.com/product/RB960PGS

So if you are able to provide it with 48V on the POE in port it will do (at a lesser price than the RB5009).

@mkx, am I missing something?
by erlinden
Thu Oct 19, 2023 5:08 pm
Forum: General
Topic: (Resolved) NTP & DNS clients not working .. just firewall misconfig
Replies: 23
Views: 1432

Re: NTP & DNS clients broken v7.11.2

What exactely do you mean by "do not work"?
Could this be Audience or config related?
by erlinden
Wed Oct 18, 2023 9:55 am
Forum: RouterBOARD hardware
Topic: crs326 access problem [SOLVED]
Replies: 5
Views: 1398

Re: crs326 access problem [SOLVED]

The config would help:
/export file=anynameyoulike
Make sure to remove serial and any other private information
by erlinden
Tue Oct 17, 2023 4:46 pm
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 83739

Re: v7.12rc is released!

Can't upgrade through the MikroTik App, and in Winbox I'm missing the "Donwload and Install" button.

After switching channels, I was able to install. Works perfectly (as it did before on the RC1 as well).
by erlinden
Tue Oct 17, 2023 11:07 am
Forum: General
Topic: Firewall: ICMP is not blocked
Replies: 1
Views: 542

Re: Firewall: ICMP is not blocked

I thought that the "connection-state=established,related" was for all established connections. Could it be that there is a connection from the LAN to the device?

Any reason why you don't have untracked there as well (per default)?
by erlinden
Mon Oct 16, 2023 12:00 pm
Forum: Beginner Basics
Topic: VPN L2tp connection problem [SOLVED]
Replies: 10
Views: 9791

Re: VPN L2tp connection problem [SOLVED]

Would be usefull to have some information:
  • current config: /export file=anynameyoulike --> Make sure to remove serial and any other private information
  • Client OS
  • Client configuration
In addition you might want to test a non-functioning client on a functioning site.
by erlinden
Thu Oct 12, 2023 1:54 pm
Forum: Beginner Basics
Topic: hEX PoE lite default + vlan
Replies: 9
Views: 1272

Re: hEX PoE lite default + vlan

Go VLAN all the way, once understanding the concept you won't ever go back.

If you need support, just share your current config:
/export file=anynameyoulike
Remove the serial and any other private information (like public IP).
by erlinden
Thu Oct 12, 2023 12:07 pm
Forum: General
Topic: Wireguard site to multi site
Replies: 5
Views: 947

Re: Wireguard site to multi site

My best guess would be a missing route on Location C.
And compliments to @rplant for his other comments.
by erlinden
Thu Oct 12, 2023 9:23 am
Forum: Beginner Basics
Topic: Remove slave on the port. [SOLVED]
Replies: 3
Views: 786

Re: Remove slave on the port. [SOLVED]

Can you please elaborate on this:
My objective is to remove the slave to setup my port forwarding.
It's either me missing the purpose or you missing the concept.
by erlinden
Thu Oct 12, 2023 8:36 am
Forum: Wireless Networking
Topic: Cap-wifi has no internet connection [SOLVED]
Replies: 5
Views: 1093

Re: Cap-wifi has no internet connection [SOLVED]

Anything in the logging that could give a hint?
by erlinden
Mon Oct 09, 2023 3:11 pm
Forum: Wireless Networking
Topic: Mikrotik hAP AX3 very bad Wi-Fi performance and coverage
Replies: 31
Views: 4388

Re: Mikrotik hAP AX3 very bad Wi-Fi performance and coverage

Where to find such paramaters.......gain tx power?
In the documentation:
https://help.mikrotik.com/docs/display/ROS/WifiWave2
by erlinden
Sun Oct 08, 2023 3:13 pm
Forum: Beginner Basics
Topic: DHCP server not responding in VLAN
Replies: 4
Views: 689

Re: DHCP server not responding in VLAN

What is missing (and what I would expect): /interface bridge vlan add bridge=bridge-lan tagged=bridge-lan untagged=[hardware wifi interface],sfp1 vlan-ids=30 And afterwards activate vlan filtering on the bridge In regards to either or not upgrading...you must have seen the security updates because o...
by erlinden
Sun Oct 08, 2023 1:30 pm
Forum: Beginner Basics
Topic: DHCP server not responding in VLAN
Replies: 4
Views: 689

Re: DHCP server not responding in VLAN

When going for VLAN, do VLAN all the way: https://forum.mikrotik.com/viewtopic.php?t=143620 You created a VLAN (vlan30-wifi) but nothing is configured to it. 6.44.3??? 6.49.10 is the latest LTS at this moment, you might want to upgrade. Any reason for not having a firewall? I assume (at least hope) ...
by erlinden
Sun Oct 08, 2023 12:19 pm
Forum: General
Topic: site-to-site azure-mikrotik
Replies: 7
Views: 791

Re: site-to-site azure-mikrotik

Depends on the Huawei:
- Place the MikroTik in the Huawei's DMZ
- Configure the Huawei as bridge (no NAT)
- Port forward all necessary ports from Huawei to the MikroTik
by erlinden
Sun Oct 08, 2023 12:11 pm
Forum: Wireless Networking
Topic: CAPsMAN Registration Table Device IP or Hostname
Replies: 6
Views: 5155

Re: CAPsMAN Registration Table Device IP or Hostname

Arent static IP showing as well on DHCP leases?
I assume configured on the client, IP reservations are shown indeed.
by erlinden
Sat Oct 07, 2023 11:47 am
Forum: General
Topic: RB4011 "Internal error: Oops: 17 [#1] SMP ARM" [SOLVED]
Replies: 8
Views: 1583

Re: RB4011 "Internal error: Oops: 17 [#1] SMP ARM" [SOLVED]

is there an archive for older versions?
You have seen the v6 section (where there is a Netinstall for 6.49.10)?
by erlinden
Fri Oct 06, 2023 4:17 pm
Forum: Containers
Topic: PiHole Not Blocking Ads, but otherwise working
Replies: 19
Views: 2122

Re: PiHole Not Blocking Ads, but otherwise working

/ip dhcp-server network
add address=10.160.100.0/24 dns-server=10.160.100.1 gateway=10.160.100.1
Clients will use the router as DNS server, so it depends on the DNS IP addresses configured in RouterOS.
Why not set the DNS server to your PiHole server within the /ip dhcp-server network config.
by erlinden
Fri Oct 06, 2023 10:04 am
Forum: Wireless Networking
Topic: CAP AX - problem with setting
Replies: 16
Views: 1332

Re: CAP AX - problem with setting

Be aware that there are two CAPsMAN versions, one for the older devices and one for Wifiwave2 compatible devices.
You won't be able to combine the two.
by erlinden
Wed Oct 04, 2023 9:35 am
Forum: Beginner Basics
Topic: Added a second network but it's not working (RESOLVED)
Replies: 3
Views: 591

Re: Added a second network but it's not working

You probably haven't added this Test network to the LAN Interface List.
Can you share your config to check:
/export file=anynameyoulike
Be sure to remove serial and any other private information.
by erlinden
Tue Oct 03, 2023 10:57 pm
Forum: Beginner Basics
Topic: Connect to WiFi, Bridge to Ethernet (DHCP)
Replies: 18
Views: 1850

Re: Connect to WiFi, Bridge to Ethernet (DHCP)

Add bridge, then add all interfaces (wireless as well) to this bridge.
Make sure that the DHCP client is attached to the bridge and...you are done.

If that doesn't work, please share the config (and remove serial and any other private information):
/export file=anynameyoulike
by erlinden
Tue Oct 03, 2023 6:57 pm
Forum: Wireless Networking
Topic: CAPSMANv2 multiple DHCP Servers for Subnet Issue
Replies: 3
Views: 525

Re: CAPSMANv2 multiple DHCP Servers for Subnet Issue

Use vlan's, only single bridge required:

viewtopic.php?t=143620
by erlinden
Sun Oct 01, 2023 2:32 pm
Forum: Wireless Networking
Topic: CAP with Wifiwave2
Replies: 6
Views: 824

Re: CAP with Wifiwave2

I think the "CAP" refers to its mode. Only hAP ax2 and hAP ax3 involved.

@keskol: is this your complete configuration? Is the C53UiG+5HPaxD2HPaxD public facing? I'm missing the firewall part.

And why ffs use UPnP :roll:
by erlinden
Sun Oct 01, 2023 11:35 am
Forum: General
Topic: qBittorrent opened 1400+ UPNP Sessions [SOLVED]
Replies: 6
Views: 990

Re: qBittorrent opened 1400+ UPNP Sessions [SOLVED]

UPnP is where it started (is it required?) and qBittorrent finished it. I would expect that there are some options in qBittorrent to limit these sessions. Using torrent feels like something from the past...at least for me.
by erlinden
Wed Sep 27, 2023 6:18 pm
Forum: SwOS
Topic: RB260GSP but 802.3af/at version
Replies: 13
Views: 1150

Re: RB260GSP but 802.3af/at version

You can use the RB960PGS:
https://mikrotik.com/product/RB960PGS
by erlinden
Tue Sep 26, 2023 9:41 am
Forum: Beginner Basics
Topic: problem with nat port forwarding UDP port
Replies: 12
Views: 1066

Re: problem with nat port forwarding UDP port

chain=input action=log connection-nat-state="" protocol=udp in-interface=uplink-vlan400 dst-port=514 log=no log-prefix="" I think that this rule, at least the chain, is not correct as you want to forward (hence you should use the forward chain). Do you have this rule? add action...
by erlinden
Mon Sep 25, 2023 3:00 pm
Forum: Wireless Networking
Topic: Mikrotik Router rb4011igs+5hacq2hnd-in can handle 80 concurrent wireless users
Replies: 5
Views: 767

Re: Mikrotik Router rb4011igs+5hacq2hnd-in can handle 80 concurrent wireless users

Do you mean 80 or 800? And what is your definition of "handle"?

I think that around 30 devices per radio is a good startingpoint. But depends on the consumption per device.

Perhaps you can add some additional information about the use case?
by erlinden
Mon Sep 25, 2023 10:55 am
Forum: Beginner Basics
Topic: Mikrotik and coaxial output
Replies: 7
Views: 892

Re: Mikrotik and coaxial output

No.
by erlinden
Mon Sep 25, 2023 10:25 am
Forum: Wireless Networking
Topic: Unable to use 80-160MHz wide channels on 5GHz WiFi
Replies: 20
Views: 1806

Re: Unable to use 80-160MHz wide channels on 5GHz WiFi

What radio scan are you using? I think your device is not completely configured. I.e. you didn't specify country code on the 5GHz radio. With a rate of 780 Mbps your device is using 80MHz width... In regards to getting 160MHz (bigger is not always better, I prefer to use 40MHz on the 5GHz radios mys...
by erlinden
Mon Sep 25, 2023 9:57 am
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 150783

Re: v7.11.2 [stable] is released!

It's the default config, which comes with AX³, you know. Mikrotik must handle it with no excuses.
>dhcp-client on ether1 failed to add 0.0.0.0/0 route to 192.168.1.1: std failure: timeout (13)
Default is 192.168.88.1
by erlinden
Sat Sep 23, 2023 12:20 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 150783

Re: v7.11.2 [stable] is released!

What a nonsense, didn't expect this bullshit from mikrotik.
Mikrotik can't handle users and their sometimes exotic configs. Not saying this is the case with you...just saying that this is not caused by RouterOS v7.11.2.
by erlinden
Fri Sep 22, 2023 10:33 pm
Forum: Forwarding Protocols
Topic: Help migrating BGP from v6.43.7 to v7.11
Replies: 8
Views: 959

Re: Help migrating BGP from v6.43.7 to v7.11

Defenitely would like to see the config. Sure it is not compromised? Your RotuerOS version is...well...updated...a lot.
by erlinden
Thu Sep 21, 2023 1:36 pm
Forum: Beginner Basics
Topic: IP Address
Replies: 5
Views: 665

Re: IP Address

How can DEFINE the address as FIXED?
This is a rhetorical question:
If you DEFINE the address as FIXED in config, what do you think it will be ?
by erlinden
Wed Sep 20, 2023 11:58 am
Forum: Beginner Basics
Topic: vlans and wifi with two separate internet routers [SOLVED]
Replies: 9
Views: 1192

Re: vlans and wifi with two separate internet routers [SOLVED]

With a router you can handle the failover automatically, only challenge is disabling wireless on the Starlink router when it's link is down. Any way to replace the starlink router with a Mikrotik? Then you can keep the switch.
by erlinden
Wed Sep 20, 2023 11:05 am
Forum: Beginner Basics
Topic: vlans and wifi with two separate internet routers [SOLVED]
Replies: 9
Views: 1192

Re: vlans and wifi with two separate internet routers [SOLVED]

In either way I would change the RB260GSP for a router.
by erlinden
Wed Sep 20, 2023 9:36 am
Forum: General
Topic: Mikrotik cant access Internet but Clients can
Replies: 3
Views: 378

Re: Mikrotik cant access Internet but Clients can

If you share your config we can do some additional checking...I was not expecting the necessity of a filter rule on the input chain for having access to the internet.
by erlinden
Tue Sep 19, 2023 5:54 pm
Forum: Wireless Networking
Topic: Can't connect CAP AX using capsman
Replies: 36
Views: 2254

Re: Can't connect CAP AX using capsman

CAP as the CAP AX ? I havent done anything to it.
Indeed, just to be sure...

What's in between the router and the cAP ax?
by erlinden
Tue Sep 19, 2023 5:49 pm
Forum: Wireless Networking
Topic: Can't connect CAP AX using capsman
Replies: 36
Views: 2254

Re: Can't connect CAP AX using capsman

So much to improve...but lets focus on the current problem.
Can you share the CAP config as well?
by erlinden
Tue Sep 19, 2023 4:21 pm
Forum: Wireless Networking
Topic: Can't connect CAP AX using capsman
Replies: 36
Views: 2254

Re: Can't connect CAP AX using capsman

Time for some next stepping...can you provide configs from both CAPsMAN and CAPS?
/export file=anynameyoulike
Make sure to remove serial and any other private information like public IP.
by erlinden
Tue Sep 19, 2023 3:08 pm
Forum: Wireless Networking
Topic: Can't connect CAP AX using capsman
Replies: 36
Views: 2254

Re: Can't connect CAP AX using capsman

Solid green I assume?
Did the cAP ax request/get an IP address?
by erlinden
Tue Sep 19, 2023 2:59 pm
Forum: Wireless Networking
Topic: Can't connect CAP AX using capsman
Replies: 36
Views: 2254

Re: Can't connect CAP AX using capsman

Just to be sure...you did reset the cAP ax to CAP mode?
by erlinden
Tue Sep 19, 2023 2:11 pm
Forum: Wireless Networking
Topic: Can't connect CAP AX using capsman
Replies: 36
Views: 2254

Re: Can't connect CAP AX using capsman

As far as I know it requires a reboot.

Aah...you found out. Did you download:
https://download.mikrotik.com/routeros/ ... 7.11.2.zip

It has to be the arm64 package...
by erlinden
Tue Sep 19, 2023 1:20 pm
Forum: Wireless Networking
Topic: Can't connect CAP AX using capsman
Replies: 36
Views: 2254

Re: Can't connect CAP AX using capsman

For AX devices you have to use a different CAPsMAN:
https://help.mikrotik.com/docs/display/ ... ve2CAPsMAN
by erlinden
Tue Sep 19, 2023 12:14 pm
Forum: General
Topic: Winbox 3.39, ROS7.11.2: IPv6 Route window; no BGP-Tab
Replies: 2
Views: 324

Re: Winbox 3.39, ROS7.11.2: IPv6 Route window; no BGP-Tab

You (don't) mean the /routing/bgp tab?
by erlinden
Tue Sep 19, 2023 8:25 am
Forum: Wireless Networking
Topic: New CapAX - config sanity check requested
Replies: 8
Views: 942

Re: New CapAX - config sanity check requested

/system routerboard settings
set auto-upgrade=yes
I prefer to decide when to upgrade and where to.
by erlinden
Sun Sep 17, 2023 6:28 pm
Forum: General
Topic: Mikrotik cAp ax does not have 2.4GHz interface?
Replies: 16
Views: 1205

Re: Mikrotik cAp ax does not have 2.4GHz interface?

I would:
  • Uninstall wifiwav2 package and install it next
  • Reset, no default configuration
  • Netinstall
  • RMA
by erlinden
Sun Sep 17, 2023 5:00 pm
Forum: General
Topic: Mikrotik cAp ax does not have 2.4GHz interface?
Replies: 16
Views: 1205

Re: Mikrotik cAp ax does not have 2.4GHz interface?

At least the MAC address is incorrect...can you correct that?
by erlinden
Sun Sep 17, 2023 2:59 pm
Forum: General
Topic: Wifi access list
Replies: 7
Views: 1605

Re: Wifi access list

by erlinden
Wed Sep 13, 2023 4:19 pm
Forum: Beginner Basics
Topic: Setting up 2 VLANs and Inter-VLAN Routing
Replies: 7
Views: 1146

Re: Setting up 2 VLANs and Inter-VLAN Routing

My (first) reply:

- don't use vlan id = 1
- use a single bridge and add vlan filtering
- upgrade to latest LTS: 6.49.8
- read this :-D : viewtopic.php?t=143620 (great explenation and examples)
by erlinden
Wed Sep 13, 2023 10:30 am
Forum: RouterBOARD hardware
Topic: 5 port poe switch
Replies: 4
Views: 1286

Re: 5 port poe switch

If these are all the requirements:
https://mikrotik.com/product/crs112_8p_4s_in
by erlinden
Wed Sep 13, 2023 9:45 am
Forum: Scripting
Topic: /ip ipsec policy on ROS 6.44.5
Replies: 7
Views: 1107

Re: /ip ipsec policy on ROS 6.44.5

Not (completely related), any specific reason for running this version?
by erlinden
Mon Sep 11, 2023 5:39 pm
Forum: General
Topic: Reject Private IP DHCP Offer
Replies: 6
Views: 1048

Re: Reject Private IP DHCP Offer

Based on my feeling: nope.
I would think of either doing some scripting (IP change?) or getting a different ISP.
What ISP do you have? And how do you currently "reject" the private IP address offer?
by erlinden
Mon Sep 11, 2023 5:25 pm
Forum: General
Topic: Reject Private IP DHCP Offer
Replies: 6
Views: 1048

Re: Reject Private IP DHCP Offer

Can you explain a bit more?
by erlinden
Sun Sep 10, 2023 8:59 pm
Forum: Beginner Basics
Topic: Advanced wifi bridge
Replies: 5
Views: 1167

Re: Advanced wifi bridge

Also beginners can use the help pages:

https://help.mikrotik.com/docs/display/ ... UI+example
by erlinden
Sun Sep 10, 2023 8:43 pm
Forum: Wireless Networking
Topic: Multiple hap ax2 issues...
Replies: 47
Views: 4465

Re: Multiple hap ax2 issues...

What's up with the L2MTU? I haven't set it myself...
by erlinden
Sun Sep 10, 2023 10:00 am
Forum: Beginner Basics
Topic: Please help login in mikrotik [SOLVED]
Replies: 3
Views: 1287

Re: Please help login in mikrotik [SOLVED]

Turn off VPN or set DNS server to auto on client..
by erlinden
Sat Sep 09, 2023 12:28 am
Forum: General
Topic: Help please [SOLVED]
Replies: 13
Views: 1510

Re: Help please [SOLVED]

Must read (and it is great):

viewtopic.php?t=143620
by erlinden
Sat Sep 09, 2023 12:13 am
Forum: Beginner Basics
Topic: DhCp cliant searching
Replies: 5
Views: 1202

Re: DhCp cliant searching

Are you using Winbox?

/Interface/Detect Internet -> select all to "none"
by erlinden
Fri Sep 08, 2023 11:20 pm
Forum: General
Topic: Disable the interface address assigned by dhcp
Replies: 7
Views: 983

Re: Disable the interface address assigned by dhcp

An export of your config says more than thousand words:
/export file=anynameyoulike
Remove serial and any other private information like public IP.

And use code tags to make it readable.
by erlinden
Fri Sep 08, 2023 10:48 pm
Forum: Wireless Networking
Topic: Router RB3011 + cAP ax + CAPSMAN
Replies: 3
Views: 1102

Re: Router +

Thanks for your repply. Do you have a video of this process?
A video of me answering your question...?

:lol:

Surely there are tons of (crappy) videos on YouTube. All the info you need is in the two supplied links. Feel free to do some investigation yourself.
by erlinden
Fri Sep 08, 2023 10:17 pm
Forum: Beginner Basics
Topic: DhCp cliant searching
Replies: 5
Views: 1202

Re: DhCp cliant searching

Disable Internet detection and try again:

https://help.mikrotik.com/docs/display/ ... t+Internet
by erlinden
Fri Sep 08, 2023 10:16 pm
Forum: Beginner Basics
Topic: OS 7.11 and old Mikrotik HAP lite
Replies: 8
Views: 1589

Re: OS 7.11 and old Mikrotik HAP lite

DON'T INSTALL RouterOS v7 (on this device, I do love it)!

Why...your hAP lite is underpowered, though it will run and is supported.
If you really need some functionality not present in v6, you should get new hardware.
by erlinden
Fri Sep 08, 2023 10:06 pm
Forum: Wireless Networking
Topic: Router RB3011 + cAP ax + CAPSMAN
Replies: 3
Views: 1102

Re: Router +

  1. Install Wifiwave2 on your RB3011
  2. Configure CAPsMAN: https://help.mikrotik.com/docs/display/ ... ve2CAPsMAN
  3. Consider using VLAN to seperate networks: viewtopic.php?t=143620
by erlinden
Fri Sep 08, 2023 10:02 pm
Forum: General
Topic: HAP AX3 Something is eating my upload bandwitch
Replies: 7
Views: 1028

Re: HAP AX3 Something is eating my upload bandwitch

I have to think now how to give acces from the outside for some services to have connection to my IP from notebook and smartphone.
Like a VPN connection :D
by erlinden
Tue Sep 05, 2023 9:41 am
Forum: Wireless Networking
Topic: Multiple hap ax2 issues...
Replies: 47
Views: 4465

Re: Multiple hap ax2 issues...

In addition to the above remarks: Besides channel als set channelwidth explicitely (I set it to Ce at my parents house, this device is rocksolid on 7.11.2...including Wifi). Also cosider setting DTIM to 3 (Apple's preferred setting). While you are at it...also change DHCP lease time to something hig...
by erlinden
Mon Sep 04, 2023 5:50 pm
Forum: Wireless Networking
Topic: ac clients do not see ax network
Replies: 11
Views: 2074

Re: ac clients do not see ax network

Good question, it would be absolutely phenomenal if one can answer this question without additional information:
/export file=anynameyoulike
Remove serial and any other private information like public IP.
by erlinden
Mon Sep 04, 2023 5:46 pm
Forum: Beginner Basics
Topic: My device not stable after update
Replies: 5
Views: 1361

Re: My device not stable after update

Do you know what version it was running befor the upgrade?
Have you followed the wiki on Netinstall?

https://wiki.mikrotik.com/wiki/Manual:Netinstall
by erlinden
Mon Sep 04, 2023 4:59 pm
Forum: Beginner Basics
Topic: High CPU load (100%)
Replies: 5
Views: 2224

Re: High CPU load (100%)

Default rules (which is a bit better then your current rule set): /ip firewall filter add chain=input action=accept connection-state=established,related,untracked comment="defconf: accept established,related,untracked" add chain=input action=drop connection-state=invalid comment="defc...
by erlinden
Mon Sep 04, 2023 2:14 pm
Forum: Beginner Basics
Topic: First time setup (almost) complete, sanity check please?
Replies: 12
Views: 2085

Re: First time setup (almost) complete, sanity check please?

While you have the chance: use VLAN ID's above 1 (also for the home/corporate/whatever network). In regards to your question: On the forward chain make all allowed traffic explicit (by adding allow filter rules) and end the forward chain with block all. The same for the input chain (be aware that ac...
by erlinden
Mon Sep 04, 2023 2:09 pm
Forum: Wireless Networking
Topic: Multiple hap ax2 issues...
Replies: 47
Views: 4465

Re: Multiple hap ax2 issues...

Have this exact device installed at my parents: rock solid. Can you share your config to make sure you have optimized settings?
/export file=anynameyoulike
Remove serial and any other private information like public IP.

Oops...this was requested already...
by erlinden
Sat Sep 02, 2023 11:50 pm
Forum: General
Topic: Lost 2.4GHz AP visibility at AX2 [SOLVED]
Replies: 8
Views: 1533

Re: Lost 2.4GHz AP visibility at AX2 [SOLVED]

Current config looks like Russian roulette...it might work...or not.
You better set bandwidth to 20MHz (unless there are no other devices transmitting on the 2.4GHz band).
Next, you could better set the channel: either 2412, 2437 or 2462 (to have minimal interference.
by erlinden
Sat Sep 02, 2023 7:51 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 150783

Re: v7.11, 7.11.1 and more [stable] are released!

V7 is required for newer hardware. Has been sad before.
Running v7 in production requires knowledge of RouterOS and its limitations.
by erlinden
Fri Sep 01, 2023 10:29 am
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 150783

Re: v7.11 and 7.11.1 [stable] are released!

Tell me, please, what could be the reason? Haven't seen this behavior on any of my devices. Could you share your config to make sure that is ok? What MikroTik do you use? Do you have firmware upgraded as well? /export file=anynameyoulike Remove serial and any other private information like public IP.
by erlinden
Thu Aug 31, 2023 4:56 pm
Forum: General
Topic: RouterOS v6.49.5- IPv6 settings
Replies: 4
Views: 949

Re: RouterOS v6.49.5- IPv6 settings

Thanks
:D
hello friends
Welcome on the forum, you might want to create a new topic. Add you config to it to get some help::
/export file=anynameyoulike
Just remove serial and any other prive information like public IP
by erlinden
Thu Aug 31, 2023 2:38 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 150783

Re: v7.11 and 7.11.1 [stable] are released!

Why?
To check current settings and to give an explanation. You can provide only the wireless part.
by erlinden
Thu Aug 31, 2023 2:26 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 150783

Re: v7.11 and 7.11.1 [stable] are released!

Can you select channel 5300, @fragtion? That would make sense in case of 80MHz Ceee.
Can you please share your config:
/export file=anynameyoulike
Remove serial and any other private information like public IP.
by erlinden
Thu Aug 31, 2023 1:23 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 150783

Re: v7.11 and 7.11.1 [stable] are released!

What channel width are you using, @fragtion? If using 80 MHz, you might have to select extension channel eeCe or eeeC.
by erlinden
Thu Aug 31, 2023 12:27 pm
Forum: General
Topic: RouterOS v6.49.5- IPv6 settings
Replies: 4
Views: 949

Re: RouterOS v6.49.5- IPv6 settings

I think you have to add "Extra packages" manually (and to be specific: ipv6-6.49.5-arm.npk).
Might be better to upgrade (to LTS 6.49.8 or Stable 6.49.10) while you are at it.
by erlinden
Thu Aug 31, 2023 11:56 am
Forum: Beginner Basics
Topic: ETH7 -> to Guest VLAN
Replies: 6
Views: 1353

Re: ETH7 -> to Guest VLAN

It's up to you how to approach this. You could share your current config for better advice:
/export file=anynameyoulike
Remove serial and any private information (like public IP address).
by erlinden
Thu Aug 31, 2023 10:28 am
Forum: Beginner Basics
Topic: ETH7 -> to Guest VLAN
Replies: 6
Views: 1353

Re: ETH7 -> to Guest VLAN

I love working with VLAN's. In your case Corporate, Guest and Management (if required). Assuming you have MikroTik hardware (what hardware do you use?), this can be easily accomplished:

viewtopic.php?t=143620
by erlinden
Thu Aug 31, 2023 10:24 am
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 150783

Re: v7.11 and 7.11.1 [stable] are released!

Upgrade went smooth:

RB4011
hEX s
wAP ac
cAP ac
hAP ax2
by erlinden
Wed Aug 30, 2023 3:30 pm
Forum: General
Topic: Only P2P download speeds are slow
Replies: 3
Views: 2131

Re: Only P2P download speeds are slow

Did you add a port forward? By any chance have UPnP activated on the Tp-Link?
by erlinden
Wed Aug 30, 2023 1:37 pm
Forum: General
Topic: VLAN's Showing but not running or even down.
Replies: 3
Views: 967

Re: VLAN's Showing but not running or even down.

Either downgrade to v7.10.2 or disable fast path"
/interface bridge settings
set allow-fast-path=no
by erlinden
Wed Aug 30, 2023 12:55 pm
Forum: General
Topic: Setup VPN for remote access to PTP links
Replies: 2
Views: 870

Re: Setup VPN for remote access to PTP links

i can setup a vpn server on a mikrotik in my network for that on an random high-enough port like 60000. Up till the above sentence your question made perfect sense to me. I think a site-2-site vpn is a very nice solution and can be accomplished pretty easily. Wireguard (in case you can use RouterOS...
by erlinden
Wed Aug 30, 2023 11:08 am
Forum: General
Topic: HAP AC2 bricked
Replies: 7
Views: 1219

Re: HAP AC2 bricked

Have you followed the help page exactely?
https://help.mikrotik.com/docs/display/ROS/Netinstall

I.e., all network adapters disabled during your attempts (except for the one connected)?
by erlinden
Wed Aug 30, 2023 10:30 am
Forum: Beginner Basics
Topic: Trying to create DHCP server on VLAN [SOLVED]
Replies: 21
Views: 3041

Re: Trying to create DHCP server on VLAN [SOLVED]

I see that you configure eth2 with pvid, but eth3 not. While both are configured on the /bridge/port/vlan. Think you should at least have this corrected. Besides that, I don't see any reason why it is not working. Anything in the log?
by erlinden
Tue Aug 29, 2023 3:35 pm
Forum: Beginner Basics
Topic: logs warning message down all the port of switch chip2 on CCR 2004 16G
Replies: 2
Views: 1106

Re: logs warning message down all the port of switch chip2 on CCR 2004 16G

Because of misconfiguration.

May I suggest to aggregate all "your problems" into a single topic?
by erlinden
Tue Aug 29, 2023 3:31 pm
Forum: General
Topic: Block Network Access (mutual communication) between 2 VPN user on same VPN server but different network
Replies: 8
Views: 1226

Re: Block Network Access (mutual communication) between 2 VPN user on same VPN server but different network

Please work on your basic knowledge mate:
https://en.wikipedia.org/wiki/Private_network

As soon as you know the error AND have adjusted your firewall as requested in one of your other topics...I'm willing to help you gladly.
by erlinden
Tue Aug 29, 2023 3:05 pm
Forum: Forwarding Protocols
Topic: Access local web server with public IP with 443 port. 443 Port Forwarded not working
Replies: 7
Views: 1410

Re: Access local web server with public IP with 443 port. 443 Port Forwarded not working

Now I see...it is allowed only via bridge. Still...please consider going back to defaults (which will protect you a lot better) or even better...block everything on the end of both input and forwarch chain. Just be aware to allow everything you want explicitely. You are aware that you do not have an...
by erlinden
Tue Aug 29, 2023 2:36 pm
Forum: Forwarding Protocols
Topic: Access local web server with public IP with 443 port. 443 Port Forwarded not working
Replies: 7
Views: 1410

Re: Access local web server with public IP with 443 port. 443 Port Forwarded not working

May I ask who took care of this firewall? You might want to consider bringing it back to default...that saves a lot of time analyzing the problems you run into. While we are at it...if you place the export in between code tags </>, your post will become more readable. Will update my answer with reco...
by erlinden
Tue Aug 29, 2023 11:22 am
Forum: Forwarding Protocols
Topic: Access local web server with public IP with 443 port. 443 Port Forwarded not working
Replies: 7
Views: 1410

Re: Access local web server with public IP with 443 port. 443 Port Forwarded not working

Can you please share the config, instead of posting screenshots?
/export file=anynameyoulike
Make sure to remove serial and any other private information (like public IP).

Are your other port forwards working?
by erlinden
Tue Aug 29, 2023 11:18 am
Forum: Forwarding Protocols
Topic: L2TP VPN Server required on Mikrotik. (I have Public IP on ISP router and NAT on Mikrotik)
Replies: 5
Views: 1425

Re: L2TP VPN Server required on Mikrotik. (I have Public IP on ISP router and NAT on Mikrotik)

The same as on your MikroTik. I you have doubts about that....well....you do the math.
by erlinden
Tue Aug 29, 2023 11:01 am
Forum: Forwarding Protocols
Topic: L2TP VPN Server required on Mikrotik. (I have Public IP on ISP router and NAT on Mikrotik)
Replies: 5
Views: 1425

Re: L2TP VPN Server required on Mikrotik. (I have Public IP on ISP router and NAT on Mikrotik)

Port forward the correct port(s) from your ISP router to your MikroTik router. That's the only additional step you have to perform besides configuring your MikroTik router.
by erlinden
Mon Aug 28, 2023 6:14 pm
Forum: Wireless Networking
Topic: only Home AP Dual
Replies: 11
Views: 1796

Re: only Home AP Dual

Right it is mikrotik, but out of pure curiosity why there is only Home AP Dual?
I think Wifiwave2 devices are limitted from Quickset (think I red something about it) and perhaps (that's my assumption) this devices purpose is Home AP Dual (or CAPs).
by erlinden
Mon Aug 28, 2023 6:01 pm
Forum: General
Topic: Crs317 limit bandwidth
Replies: 1
Views: 951

Re: Crs317 limit bandwidth

Please share your config:
/export file=anynameyoulike
Make sure to remove serial and any other private information (like public IP).
by erlinden
Mon Aug 28, 2023 5:25 pm
Forum: Wireless Networking
Topic: only Home AP Dual
Replies: 11
Views: 1796

Re: only Home AP Dual

CAPsMAN (Wifiwave2) is an additional package and can be added to the router manually. I would, assuming the router is Mikrotik as well, go that way.

With all due respect...Quickset has another purpose and doesn't fit (in my opinion) to your use case.
by erlinden
Mon Aug 28, 2023 4:51 pm
Forum: General
Topic: (CRS317 and CRS305) per vlan
Replies: 1
Views: 836

Re: (CRS317 and CRS305) per vlan

Like having trunk ports on both switches?
https://wiki.mikrotik.com/wiki/Manual:C ... Based_VLAN

Please give some context...otherwise it is just a guessing game.
by erlinden
Mon Aug 28, 2023 4:24 pm
Forum: Wireless Networking
Topic: only Home AP Dual
Replies: 11
Views: 1796

Re: only Home AP Dual

If you have seven accesspoints you might want to consider CAPsMAN. Assusming you are going to use these at one site.

And at these numbers you shouldn't be using Quickset at all, but that is my opinion.
by erlinden
Mon Aug 28, 2023 12:38 pm
Forum: Wireless Networking
Topic: WiFi not giving access to internet [SOLVED]
Replies: 5
Views: 1745

Re: WiFi not giving access to internet [SOLVED]

RouterOS 6.42.6 Mmm...might be time to do an upgrade... authentication-types=wpa-psk,wpa2-psk Please don't use wpa-psk, only use (at least) wpa2-psk aes. /ip dhcp-server add address-pool=dhcp interface=ether2 name=dhcp1 add address-pool=dhcp_pool2 disabled=no interface=bridge name=dhcp2 /interface ...
by erlinden
Sun Aug 27, 2023 11:37 am
Forum: General
Topic: Why /interface/vlan interface responds to IP address from bridge or different VLAN interface [SOLVED]
Replies: 16
Views: 2134

Re: Why /interface/vlan interface responds to IP address from bridge or different VLAN interface [SOLVED]

Intervlan communication has to be blocked on firewall.

Better, configure the firewall what is allowed and block everything else (make sure you don't block access to the router completely).
by erlinden
Sun Aug 27, 2023 11:34 am
Forum: Beginner Basics
Topic: Single DHCP server for multiple VLANs?
Replies: 14
Views: 3456

Re: Single DHCP server for multiple VLANs?

So as i read allot here i guess its not possible to assign one subnet to multiple vlans on an ether port.
Why would one assign one subnet to multiple VLANs?
by erlinden
Sun Aug 27, 2023 11:27 am
Forum: Beginner Basics
Topic: Configuration capsman on hex RB750GR3
Replies: 1
Views: 1105

Re: Configuration capsman on hex RB750GR3

What tutorials did you follow? Here is the official wiki: https://wiki.mikrotik.com/wiki/Manual:CAPsMAN If you want feedback, can you please share the current config? /export hide-sensitive file=anynameyoulike Remove serial and any other private info (like public IP). Update: CAP interfaces are adde...
by erlinden
Sun Aug 27, 2023 11:20 am
Forum: Wireless Networking
Topic: WiFi with Apple Products
Replies: 47
Views: 16938

Re: WiFi with Apple Products

Country code is for legislation purposes and probably something more. It is used to select the country you are in. Just to make sure... Is it limited to one device? Have you tried resetting Wifi or even the complete phone? And, perhaps better, removed and afterwards added the Wifi network on this Ap...
by erlinden
Sat Aug 26, 2023 12:20 pm
Forum: Wireless Networking
Topic: WiFi with Apple Products
Replies: 47
Views: 16938

Re: WiFi with Apple Products

Can you please help me, what else can i do ?
Using 40MHz on the 2.4GHz band is crap (unless...etc.). Set it to 20MHz.

Can you share your config on your previous device as well? Then we have something to compare.
by erlinden
Sat Aug 26, 2023 12:10 pm
Forum: Beginner Basics
Topic: LEOX LXT-010S-H SFP GPON
Replies: 10
Views: 2847

Re: LEOX LXT-010S-H SFP GPON

Most ISP's provide information on how to configure your own router...does your provider do that?
Can you show your config to be able to provide feedback (and sometimes a good laughter)?
/export file=anynameyoulike
Make sure tot remove serial and any other private information (like public IP).
by erlinden
Sat Aug 26, 2023 12:01 pm
Forum: Forwarding Protocols
Topic: Mikrotik Hap ax2 as Switch Mode
Replies: 2
Views: 1302

Re: Mikrotik Hap ax2 as Switch Mode

Tell the switch it's a router...that will do.
by erlinden
Fri Aug 25, 2023 2:22 pm
Forum: General
Topic: CRS1xx/2xx Port Based VLAN question
Replies: 3
Views: 1001

Re: CRS1xx/2xx Port Based VLAN question

Trunk and untagged is a bit of a contradiction.

Can you make a network diagram that contains your requirements?
Are you by any chance looking for hybrid ports?
by erlinden
Fri Aug 25, 2023 9:21 am
Forum: Wireless Networking
Topic: CAPsMAN not adding CAPs interfaces to VLAN
Replies: 9
Views: 2057

Re: CAPsMAN not adding CAPs interfaces to VLAN

CAPsMAN, running on hEX s, only important parts: /interface bridge add admin-mac=**-**-**-** auto-mac=no ingress-filtering=no name=bridge-LAN vlan-filtering=yes /interface vlan add interface=bridge-LAN name=2_VLAN vlan-id=60 add interface=bridge-LAN name=HOME_VLAN vlan-id=61 add interface=bridge-LAN...
by erlinden
Thu Aug 24, 2023 4:29 pm
Forum: Wireless Networking
Topic: CAPsMAN not adding CAPs interfaces to VLAN
Replies: 9
Views: 2057

Re: CAPsMAN not adding CAPs interfaces to VLAN

On the port that my Cap is connected to, I did:
  • MGT VLAN untagged
  • Corporate VLAN tagged
  • Guest VLAN tagged
That gave me the opportunity to leave the cap default (CAPS mode) and set VLAN in datapath.
I can share my config if that helps you?
by erlinden
Thu Aug 24, 2023 3:49 pm
Forum: Wireless Networking
Topic: cAP ac with router OS v7
Replies: 5
Views: 1297

Re: cAP ac with router OS v7

Running cAP ac in a domestic environment with RouterOS v7.11, no problems for me. Did a quick scan on the other topic but didn't see any exports from the config. Did see a lot of crappy settings in the screenshots. Two things I advice: Give V7.11 a chance Optimize your settings *) *) To get some adv...
by erlinden
Thu Aug 24, 2023 12:43 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 150783

Re: v7.11 [stable] is released!

Please elaborate @si458: vlan attached to bridge and vlan-filtering on the bridge? Perhaps share (part of) your config?
by erlinden
Thu Aug 24, 2023 12:26 pm
Forum: Wireless Networking
Topic: CAPsMAN not adding CAPs interfaces to VLAN
Replies: 9
Views: 2057

Re: CAPsMAN not adding CAPs interfaces to VLAN

RB4011: /caps-man datapath add client-to-client-forwarding=yes local-forwarding=yes name=datapath_home vlan-id=101 vlan-mode=use-tag add bridge=bridge client-to-client-forwarding=yes name=datapath_wifi vlan-id=101 vlan-mode=use-tag add bridge=bridge client-to-client-forwarding=yes name=datapath_iot ...
by erlinden
Thu Aug 24, 2023 9:49 am
Forum: Wireless Networking
Topic: Strange 2.4 ghz issue
Replies: 6
Views: 1580

Re: Strange 2.4 ghz issue

Couple of things to consider: wireless-protocol=nv2-nstreme-802.11 means you will connect with either another Mikrotik or something else. Why not use 802.11? authentication-types=wpa-psk,wpa2-psk group-ciphers=tkip,aes-ccm is beyond ancient. Change it to authentication-types= wpa2-psk group-ciphers=...
by erlinden
Wed Aug 23, 2023 5:46 pm
Forum: General
Topic: Slow TCP/UDP since 7.11 update on RB760iGS
Replies: 9
Views: 1317

Re: Slow TCP/UDP since 7.11 update on RB760iGS

i could go back to the old version but do you have enough information to fix the problem in future releases? or should i provide any thing which helps to fix it? The problem was already identified and solved (was informed today by mail). I expect a v7.11.1 release on short notice. In the linked thr...
by erlinden
Wed Aug 23, 2023 4:28 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 150783

Re: v7.11 [stable] is released!

its my settings Better to share your config: /export file=anynameyoulike Make sure to remove serial and any other private information (like public IP). In regards to your settings: nv2 nstreme is Mikrotik only Superchannel!? why post 5GHz radio while you experience problems with the 2.4GHz radio? B...
by erlinden
Wed Aug 23, 2023 12:59 pm
Forum: RouterBOARD hardware
Topic: hAP lite RB041-2nD how to update?
Replies: 6
Views: 2142

Re: hAP lite RB041-2nD how to update?

You are talking about a low end device that was introduced in 2015 (and probably earlier) that stil receives updates. What other brand does that? Did you buy the correct device (and are you expectations correct)? As mentioned...there is a workaround by using netinstall. If you stick to V6.x LTS, you...
by erlinden
Wed Aug 23, 2023 11:25 am
Forum: Forwarding Protocols
Topic: Simple port forwarding rule doesn't work
Replies: 23
Views: 2933

Re: Simple port forwarding rule doesn't work

What does "breaks everything" mean to you? Does your phone use the same DNS server as the Windows machine?
In regards to your remark about the firewall rules...if logging is activated on the firewall (drop) rule you might get an indication of the cause of not working.
by erlinden
Tue Aug 22, 2023 5:26 pm
Forum: General
Topic: Updated to ROS 7.10 now can't login via ssh
Replies: 6
Views: 1024

Re: Updated to ROS 7.10 now can't login via ssh

No problem, bit of advice: Order your firewall rules (especially when shared your Mikrotik friends on the forum), that (appart from the missing rule below) will make it more readable and maintainable. /ip firewall filter add action=accept chain=input comment="Accept established,related, untrack...
by erlinden
Tue Aug 22, 2023 4:52 pm
Forum: General
Topic: Updated to ROS 7.10 now can't login via ssh
Replies: 6
Views: 1024

Re: Updated to ROS 7.10 now can't login via ssh

The an export might be helpful:
/export file=anynameyoulike
Remove serial and any other private information (like public IP address).
by erlinden
Tue Aug 22, 2023 4:31 pm
Forum: General
Topic: Updated to ROS 7.10 now can't login via ssh
Replies: 6
Views: 1024

Re: Updated to ROS 7.10 now can't login via ssh

Can you login with Winbox on IP?
Anything relevant in the logging?
by erlinden
Tue Aug 22, 2023 11:11 am
Forum: Wireless Networking
Topic: AX wifi wave2 on CAP AX and HAP AX2 [SOLVED]
Replies: 17
Views: 2894

Re: AX wifi wave2 on CAP AX and HAP AX2 [SOLVED]

Nice! I like answers like yours.
by erlinden
Mon Aug 21, 2023 6:06 pm
Forum: Wireless Networking
Topic: AX wifi wave2 on CAP AX and HAP AX2 [SOLVED]
Replies: 17
Views: 2894

Re: AX wifi wave2 on CAP AX and HAP AX2 [SOLVED]

You are aware that there is a nice search option on this forum?
And if you want some in depth feedback, please share your config:
/export file=anynameyoulike
Make sure to remove serial and any private information (like public IP address)
by erlinden
Mon Aug 21, 2023 9:42 am
Forum: Forwarding Protocols
Topic: Simple port forwarding rule doesn't work
Replies: 23
Views: 2933

Re: Simple port forwarding rule doesn't work

Not sure if you removed it...do both the interface and the peer have public (and private) key implemented?
I assume it is not working on local network?

Follow the link I posted before, then it will work. And consider moving the wireguard firewall filter rule below the Drop invalid rule.
by erlinden
Sat Aug 19, 2023 2:53 pm
Forum: General
Topic: Please help! Creating 2nd Subnet for Wifi connected only
Replies: 2
Views: 815

Re: Please help! Creating 2nd Subnet for Wifi connected only

Sure...multiple ways to solve this.
I prefer using VLAN's (where you can even distinguish corporate and guest network):

viewtopic.php?t=143620

Update:
Looking at your hardware, two things:
by erlinden
Sat Aug 19, 2023 11:14 am
Forum: General
Topic: stop this warning for this specific message in logging
Replies: 3
Views: 787

Re: stop this warning for this specific message in logging

My advice: use VLAN's and use correct firewall settings.
by erlinden
Sat Aug 19, 2023 10:55 am
Forum: Beginner Basics
Topic: Login only with mac address + cannot update [SOLVED]
Replies: 3
Views: 1634

Re: Login only with mac address + cannot update [SOLVED]

Start over again...your current configuration has flaws. I.e., your firewall is lacking a lot and one of your networks has incorrect IP information. How...? https://wiki.mikrotik.com/wiki/Manual:Reset In summary: /system reset-configuration (from command line) System -> Reset Configuration (from Win...
by erlinden
Sat Aug 19, 2023 10:43 am
Forum: General
Topic: stop this warning for this specific message in logging
Replies: 3
Views: 787

Re: stop this warning for this specific message in logging

From the documentation (https://help.mikrotik.com/docs/display/ROS/Log): prefix (string; Default: ) prefix added at the beginning of log messages As far as I know you can't filter on the Message itself. Update: I see you already are working on solving the cause: https://forum.mikrotik.com/viewtopic....
by erlinden
Fri Aug 18, 2023 3:33 pm
Forum: Forwarding Protocols
Topic: Simple port forwarding rule doesn't work
Replies: 23
Views: 2933

Re: Simple port forwarding rule doesn't work

Do you have a Wireguard enabled?
Is it working locally (next step should be port check)?

Better share your current config (screenshots are unnecessary):
/export file=anynameyoulike
Remove serial and any prive information (like public IP).
by erlinden
Fri Aug 18, 2023 12:05 pm
Forum: Forwarding Protocols
Topic: Simple port forwarding rule doesn't work
Replies: 23
Views: 2933

Re: Simple port forwarding rule doesn't work

If you follow the guide (https://help.mikrotik.com/docs/display/ROS/WireGuard#WireGuard-Applicationexamples), you would have known there is no port forward involved. Forwarding means, forward traffic to other device. I assume you want to run a Wireguard server on your MikroTik? Unless you are runnin...
by erlinden
Wed Aug 16, 2023 11:35 pm
Forum: Scripting
Topic: Importing Wireless Access List (issues)
Replies: 1
Views: 911

Re: Importing Wireless Access List (issues)

Either check if the item exists or remove the current address list.
by erlinden
Wed Aug 16, 2023 11:33 pm
Forum: Beginner Basics
Topic: Please check my configs - first time setting up Mikrotik network. [SOLVED]
Replies: 12
Views: 1851

Re: Please check my configs - first time setting up Mikrotik network. [SOLVED]

Well, here are my two cents: get firewall back to original, lots of crap added get rid of upnp and disable it like...forever. And start getting ashamed while you want your router as save as possible get rid of auto-upgrade and disable it like...forever reboots are not necessary, you are using MikroT...
by erlinden
Wed Aug 16, 2023 10:44 pm
Forum: General
Topic: 2 Bridge on Mikrotik goes stuck
Replies: 4
Views: 863

Re: 2 Bridge on Mikrotik goes stuck

Before going in depth...why 2 bridges?
And can you share at least your config?
/export file=anynameyoulike
Don't forget to remove serial and any other private information (like public IP)
by erlinden
Wed Aug 16, 2023 4:14 pm
Forum: Beginner Basics
Topic: VLAN performance
Replies: 3
Views: 1008

Re: VLAN performance

Instead of watching the video (beware that there is lot of crap on YT), could you please share the config?
/export file=anynameyoulike
Remove serial and any private information (like public IP).
by erlinden
Wed Aug 16, 2023 11:22 am
Forum: General
Topic: DHCP Server not working properly?
Replies: 11
Views: 1028

Re: DHCP Server not working properly?

Would be helpful if you can share your config.
/export file=anynameyoulike
Don't forget to remove the serial and any other private information (like public IP address).
by erlinden
Wed Aug 16, 2023 10:55 am
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 150783

Re: v7.11 [stable] is released!

My RB4011 does not allow a device connected to bridge port on a specific vlan to reach to any other device on that vlan, unless I'm running "Torch" on the port.
SUP-125214
Sounds like my problem, where you able to ping it from the router?
SUP-125143
by erlinden
Tue Aug 15, 2023 5:19 pm
Forum: Announcements
Topic: v7.11.2 [stable] is released!
Replies: 348
Views: 150783

Re: v7.11 [stable] is released!

My bonding interface on the RB4011 was no longer working correctly. I was able to ping it from the router and the camera's could communicate (initiated by the NAS), but the corporate network could neither ping nor communicate through browser or native Synology app with the NAS. Config can be supplie...
by erlinden
Tue Aug 15, 2023 1:19 am
Forum: General
Topic: Management over tagged vlan
Replies: 1
Views: 549

Re: Management over tagged vlan

On any VLAN question...please start here: https://forum.mikrotik.com/viewtopic.php?t=143620 And in regards to this specific switch: https://help.mikrotik.com/docs/pages/viewpage.action?pageId=103841836 And if you want some specific feedback...start with sharing your config: /export file=anynameyouli...
by erlinden
Tue Aug 15, 2023 1:16 am
Forum: Beginner Basics
Topic: VLAN not working?
Replies: 17
Views: 1849

Re: VLAN not working?

On any VLAN question...please start here:
viewtopic.php?t=143620
by erlinden
Mon Aug 14, 2023 11:14 pm
Forum: General
Topic: RouterOS 7 VLAN Bug [SOLVED]
Replies: 16
Views: 1936

Re: RouterOS 7 VLAN Bug [SOLVED]

The address list entry approach as suggested by erlinden is a tad nicer. Agree :D But still...I doubt if this has worked before...assuming the config remained unchanged. The primary reason was mitigation of https://nvd.nist.gov/vuln/detail/CVE-2023-30799. I could have upgraded to 6.49.8 but I thoug...
by erlinden
Mon Aug 14, 2023 10:37 pm
Forum: General
Topic: RouterOS 7 VLAN Bug [SOLVED]
Replies: 16
Views: 1936

Re: RouterOS 7 VLAN Bug [SOLVED]

What is the reason for upgrading? Any particular reason? The first (and only) thing I notice is that I was expecting this line: add address=192.168.128.0/22 list=users This list is used in the firewall (which is in my opinion a bit unreadable...I'm still a fw-rooky). Could that be the reason for hav...
by erlinden
Sun Aug 13, 2023 10:45 am
Forum: Wireless Networking
Topic: A bit better WiFi security with per-user PSK? [SOLVED]
Replies: 62
Views: 7560

Re: A bit better WiFi security with per-user PSK? [SOLVED]

Random MAC is, as far as I know, not random after the wireless network is added to the device. Otherwise Kid Control wouldn't work (for me).
by erlinden
Sun Aug 13, 2023 10:42 am
Forum: General
Topic: Few VLANs stopped after reboot (detect internet issue) [SOLVED]
Replies: 3
Views: 1545

Re: Few VLANs stopped after reboot (detect internet issue) [SOLVED]

You might want to add a new topic and at least share your config:
/export file=anynameyoulike
Don't forget to remove serial and any other private information.
by erlinden
Sat Aug 12, 2023 11:58 am
Forum: General
Topic: Having Issue with using MultiWAN with RB450G
Replies: 16
Views: 1452

Re: Having Issue with using MultiWAN with RB450G

Thknk you shared the backup files instead of exporting the config (as anav mentioned).
by erlinden
Thu Aug 10, 2023 12:55 pm
Forum: Beginner Basics
Topic: CRS518-16XS-2XQ - pure VLAN switch with very high cpu usage [SOLVED]
Replies: 4
Views: 1472

Re: CRS518-16XS-2XQ - pure VLAN switch with very high cpu usage [SOLVED]

Though I'm not the most experienced VLAN user, I do know that it is best practice not to use VLAN id 1. You might want to change that (i.e. to 10 and the other id to 20) and see if that helps. Furthermore, though you might already have found it, herewith the documentation: https://help.mikrotik.com/...
by erlinden
Thu Aug 10, 2023 11:44 am
Forum: General
Topic: VLANs Not Acting As Expected
Replies: 5
Views: 902

Re: VLANs Not Acting As Expected

When it comes to VLAN, there is only one topic you have to read carefully:
viewtopic.php?t=143620

When using VLAN's, don't use VLAN id 1.
by erlinden
Wed Aug 09, 2023 11:04 am
Forum: Beginner Basics
Topic: VLANs access port - not restricted
Replies: 2
Views: 863

Re: VLANs access port - not restricted

When using VLAN's there is no use of having multiple bridges...just use a single bridge and do the VLAN filtering on there:
viewtopic.php?t=143620

And as k6ccc mentioned inter VLAN traffic should be blocked by the firewall.
by erlinden
Tue Aug 08, 2023 1:46 pm
Forum: Wireless Networking
Topic: Is Cap XL AC suitable for (protected) outdoor service ?
Replies: 5
Views: 1414

Re: Is Cap XL AC suitable for (protected) outdoor service ?

Maybe not the same form factor, but yes, some outdoor AX models are in the works
Can I pre-order at least 3?
:D

Really really really looking forward!
by erlinden
Sun Aug 06, 2023 10:54 pm
Forum: General
Topic: VLAN - losing conection
Replies: 2
Views: 623

Re: VLAN - losing conection

Just use a single bridge and do the VLAN filtering on there.
You probably want to take a look at this topic:

viewtopic.php?t=143620
by erlinden
Sun Aug 06, 2023 10:51 pm
Forum: Beginner Basics
Topic: LAN as tagged VLAN out WAN port for backbone (WAN and LAN on same port) [SOLVED]
Replies: 4
Views: 1167

Re: LAN as tagged VLAN out WAN port for backbone (WAN and LAN on same port) [SOLVED]

I would probably have both VLAN's tagged on eth1 (and do filtering on the bridge). Either way, you would have to use a managed switch to be able to do VLAN filtering.
by erlinden
Sat Aug 05, 2023 4:43 pm
Forum: Beginner Basics
Topic: Bridge/VLANs issues
Replies: 28
Views: 2730

Re: Bridge/VLANs issues

Hey Erlinden you be wrong dude...... Please stop spreading CRUD!! I was speaking about the /bridge/vlan screen in Winbox...there it will show only untagged interfaces if there is something attached to the interface. Like the screenshot from Yuval where ether6 is not shown at untagged on VLAN 13. Do...
by erlinden
Sat Aug 05, 2023 3:55 pm
Forum: Beginner Basics
Topic: vlan interoperability issues
Replies: 8
Views: 1216

Re: vlan interoperability issues

100.125.128.254/30 doesn't seem correct...is it?
by erlinden
Fri Aug 04, 2023 12:31 pm
Forum: Beginner Basics
Topic: Bridge/VLANs issues
Replies: 28
Views: 2730

Re: Bridge/VLANs issues

Untagged ports will only be shown if there is something connected to the port.

Can you show the latest config (instead of posting screenshots)?
by erlinden
Wed Aug 02, 2023 8:44 pm
Forum: RouterBOARD hardware
Topic: RB1100AHx2
Replies: 4
Views: 1836

Re: RB1100AHx2

Winbox
  • Files
  • Download all
  • Delete all that is downloaded
  • Upgrade
by erlinden
Wed Aug 02, 2023 8:10 pm
Forum: General
Topic: Forwarding Port 80 leads to the login page, not website [SOLVED]
Replies: 8
Views: 1374

Re: Forwarding Port 80 leads to the login page, not website [SOLVED]

You might want to share your config, so we can solve this:
/export file=anynameyoulike
by erlinden
Wed Aug 02, 2023 2:22 pm
Forum: SwOS
Topic: CRS328-24P-4S+ Tx Drop
Replies: 4
Views: 2018

Re: CRS328-24P-4S+ Tx Drop

Sure...after you provide some additional information:
  • what version were you running before?
  • had the same problem with previous OS?
  • what is the percentage drops in regards to the traffic?
  • is it on an interface (and have you checked wire?
  • what does your config look like?
by erlinden
Wed Aug 02, 2023 2:15 pm
Forum: Beginner Basics
Topic: Firewall rules to seperate some vLANs
Replies: 16
Views: 2030

Re: Firewall rules to seperate some vLANs

I got this from a guide which told to configure like this, everything seems working so what's wrong here?
What guide?
VLAN id 1 is a bad choice.
by erlinden
Wed Jul 26, 2023 10:02 am
Forum: General
Topic: Internet
Replies: 2
Views: 558

Re: Internet

First consider upgrading the device to LTS, currently 6.49.8. This to prefent any security incidents. In regards to your question: You might be able to determine it by the interface where the upload comes from. Are you using Winbox? Did the provider also supply information on what kind of traffic it...
by erlinden
Wed Jul 26, 2023 9:30 am
Forum: Wireless Networking
Topic: ax CAPsMAN configuration example
Replies: 15
Views: 2791

Re: ax CAPsMAN configuration example

Looks like you don't use out-of-the-box CAPS mode on the CAPS. Is this because you are using a trunk port in between the CAPsMAN and the CAPS?
by erlinden
Wed Jul 26, 2023 9:12 am
Forum: Beginner Basics
Topic: Network speed very poor
Replies: 10
Views: 1364

Re: Network speed very poor

Can you share the hAP ac3 config? Just to make sure...? And what RouterOS version are you running?
At what speed are all the devices connected to the hAP?
by erlinden
Tue Jul 25, 2023 3:13 pm
Forum: General
Topic: CCR2004-16G-2S+ cannot be upgraded because of Timeouts [SOLVED]
Replies: 6
Views: 1074

Re: CCR2004-16G-2S+ cannot be upgraded because of Timeouts [SOLVED]

You still might want to consider using a single bridge.

I assume that "add address=000.000.000.000/29 interface=ether1 network=000.000.000.000" is a masked line?
by erlinden
Tue Jul 25, 2023 9:58 am
Forum: Beginner Basics
Topic: Combined Trunk for ISP VLAN and internal VLAN
Replies: 5
Views: 942

Re: Combined Trunk for ISP VLAN and internal VLAN

Thanks again @mkx, will give it a try tonight. Your suggested approach is exactely how I configured my other router...can't explain how I came up with this approach...
by erlinden
Mon Jul 24, 2023 10:08 pm
Forum: Beginner Basics
Topic: Combined Trunk for ISP VLAN and internal VLAN
Replies: 5
Views: 942

Re: Combined Trunk for ISP VLAN and internal VLAN

Thanks for the fast feedback, @mkx. Just to clear things up: I didn't do a complete export (and am aware that all access ports can be configured untagged. What would be the reason for adding ether1 to the bridge as well? I would not expect any (untagged) traffic on it...correct? Still can add it of ...
by erlinden
Mon Jul 24, 2023 9:25 pm
Forum: Beginner Basics
Topic: Combined Trunk for ISP VLAN and internal VLAN
Replies: 5
Views: 942

Combined Trunk for ISP VLAN and internal VLAN

https://onedrive.live.com/embed?resid=A8C108AADB4F50AC%21989722&authkey=%21AKXuOW-VizRqICA&width=660&height=999999 MY ISP is using 2 VLAN's, one for Internet (VLAN 20) and one for IPTV (VLAN 30). I want my RB260 close to the fiber and install my hAP ax2 in the livingroom. That is peace ...
by erlinden
Mon Jul 24, 2023 10:07 am
Forum: General
Topic: Constant DHCP server assigning and deassigning
Replies: 5
Views: 593

Re: Constant DHCP server assigning and deassigning

I see this kind of behavior with both wireless and wired clients.
Both loose connection and upon reconnect they do a DHCP request. Is this happening?
by erlinden
Sat Jul 22, 2023 10:36 pm
Forum: General
Topic: What dynamic DNS are you using and why? (Free or not)
Replies: 12
Views: 5456

Re: What dynamic DNS are you using and why? (Free or not)

My guess would be that after nearly 6 years the TS found a working solution...
by erlinden
Fri Jul 21, 2023 11:03 pm
Forum: Beginner Basics
Topic: Connecting to RB2011 Router to ISP Router by WiFi [SOLVED]
Replies: 2
Views: 964

Re: Connecting to RB2011 Router to ISP Router by WiFi [SOLVED]

Possible...yes.
How: this great blogpost will surely be helpful:
https://www.justinho.com/blog/2017/07/1 ... -lite.html
by erlinden
Fri Jul 21, 2023 10:54 am
Forum: RouterOS beta
Topic: latest firmware problem with Rb760iGs
Replies: 5
Views: 1367

Re: latest firmware problem with Rb760iGs

Might be worth to check your config, just to make sure there are no faulty settings.
Can you share it?
/export file=anynameyoulike
by erlinden
Thu Jul 20, 2023 5:53 pm
Forum: General
Topic: Assigned Deassigned DHCP loop on guest wifi
Replies: 11
Views: 703

Re: Assigned Deassigned DHCP loop on guest wifi

Huge config...hence didn't check it all. Was expecting to see VLAN filtering on the bridge, there is none. Think it would be beneficial to clean some config (or at least explain the reason).

Did you also have a look at the debug logging for wireless (assuming it is available in CAPsMAN)?
by erlinden
Thu Jul 20, 2023 5:37 pm
Forum: Beginner Basics
Topic: Can't upgrade: ERROR: could not resolve dns name
Replies: 16
Views: 2679

Re: Can't upgrade: ERROR: could not resolve dns name

I would reset both CAPS's into CAPS mode as described here: https://help.mikrotik.com/docs/display/ROS/Reset+Button When using CAPsMAN, it is easier to upgrade via CAPsMAN (search for package-path and in Winbox search for the Upgrade button): https://help.mikrotik.com/docs/pages/viewpage.action?page...
by erlinden
Thu Jul 20, 2023 2:27 pm
Forum: Beginner Basics
Topic: !!!!!!!!!Newbies RouterOs no webfig from Wan [SOLVED]
Replies: 5
Views: 1165

Re: !!!!!!!!!Newbies RouterOs no webfig from Wan [SOLVED]

By default lots of services are available on the LAN interfaces. Enabling access to Webfig (or any other service) from WAN requires adjustments, but you don't want that!!!!!!!!!

If you want access from WAN, use VPN (v7.11RC6 has a great newbie compliant implemtantion for it).
by erlinden
Thu Jul 20, 2023 2:23 pm
Forum: General
Topic: RB931-2nD - use ROS v6 or v7?
Replies: 1
Views: 282

Re: RB931-2nD - use ROS v6 or v7?

Lot's of assumptions...why don't you give V7 a try? Don't expect too much performance though...

As an ISP I would use LTS, unless there is a usecase not to.
by erlinden
Wed Jul 19, 2023 11:16 am
Forum: General
Topic: Question: Howto prevent uPNP from priviledged port
Replies: 2
Views: 295

Re: Question: Howto prevent uPNP from priviledged port

What is the use for you of having UPnP enabled in the first place?
by erlinden
Wed Jul 19, 2023 10:29 am
Forum: Beginner Basics
Topic: Instructions for configuring the WireGuard interface on two routers to combine two Offices into a single network
Replies: 8
Views: 1900

Re: Instructions for configuring the WireGuard interface on two routers to combine two Offices into a single network

It's time for fine tuning. How to restrict traffic to only certain ports, like "Only 1560-1591 and 9999 are allowed"? Maybe someone will tell?
Firewall, block all forwarding and allow only the above.
by erlinden
Tue Jul 18, 2023 10:03 am
Forum: Wireless Networking
Topic: hAP ac 2GHz speed 10Mbits
Replies: 9
Views: 1532

Re: hAP ac 2GHz speed 10Mbits

Could be wireless saturation, especially when using legacy devices. You can test with only a single device connected, just to make sure that the radio isn't the problem. Because currently the links are at low speeds. Additionally, do some testing with different channels (2412, 2437, 2462) as @normis...
by erlinden
Mon Jul 17, 2023 11:32 am
Forum: Wireless Networking
Topic: hAP ac 2GHz speed 10Mbits
Replies: 9
Views: 1532

Re: hAP ac 2GHz speed 10Mbits

Can you share your adjusted config as well as an overview on the registrations:
/interface/wireless/registration-table/print
This will give an overview of all clients registered to the hAP ac.
by erlinden
Sun Jul 16, 2023 9:26 pm
Forum: Wireless Networking
Topic: hAP ac 2GHz speed 10Mbits
Replies: 9
Views: 1532

Re: hAP ac 2GHz speed 10Mbits

There are some improvements to make:
  • don't use auto channel
  • set 2.4GHz channel-width to 20MHz
  • set country code
  • don't use legacy protocols
  • don't use superchannel
Hope this gives some improvements.
by erlinden
Sat Jul 15, 2023 7:39 pm
Forum: Beginner Basics
Topic: Router kicks me out only on one phone
Replies: 5
Views: 1156

Re: Router kicks me out only on one phone

Share your config with your friends @thisforum and let them have a look at it. Sure it can be solved...
My best guess...still using an older security setting...but the export will show:
/export file=anynameyoulike
by erlinden
Fri Jul 14, 2023 3:16 pm
Forum: General
Topic: hAP AC^2 reboots unexpectedly
Replies: 4
Views: 721

Re: hAP AC^2 reboots unexpectedly

Can you share the config as well...hope you made some changes before importing?
Is this also occuring after performing a netinstall?
by erlinden
Fri Jul 14, 2023 9:17 am
Forum: SwOS
Topic: Need help to convert RouterOS to SwitchOS
Replies: 9
Views: 2551

Re: Need help to convert RouterOS to SwitchOS

Out of curiosity...why would you like to switch to SwOS?

What problem are you running into?
Have you seen this help page:
https://help.mikrotik.com/docs/pages/vi ... ionExample
by erlinden
Thu Jul 13, 2023 1:45 pm
Forum: General
Topic: Speed-test UDP Upload Slow
Replies: 9
Views: 740

Re: Speed-test UDP Upload Slow

Can you perform a test with two machines, using i.e. iperf?
by erlinden
Tue Jul 11, 2023 9:10 am
Forum: Wireless Networking
Topic: Connecting two different radio Wireless models
Replies: 4
Views: 1137

Re: Connecting two different radio Wireless models

Would like to see the config before replying:
/export file=anynameyoulike
Don't forget to remove serial and any other private information.
by erlinden
Tue Jul 11, 2023 8:34 am
Forum: General
Topic: RB4011iGS+ ether interfaces dropping
Replies: 2
Views: 323

Re: RB4011iGS+ ether interfaces dropping

Just to be sure...can you share your config?
And have you tried replacing the power supply (though I doubt it is related)?
What version RouterOS are you running?
Have you already tried a Netinstall?
by erlinden
Mon Jul 10, 2023 11:28 am
Forum: General
Topic: Different model in box and device [SOLVED]
Replies: 6
Views: 546

Re: Different model in box and device [SOLVED]

What does /system/routerboard/print say?
by erlinden
Sun Jul 09, 2023 11:44 am
Forum: General
Topic: [Solved] Wireguard S2S VPN - some websites open, some don't
Replies: 4
Views: 458

Re: [Solved] Wireguard S2S VPN - some websites open, some don't

Creating multiple topics doesn't help...:
viewtopic.php?t=197667
by erlinden
Sun Jul 09, 2023 11:42 am
Forum: Beginner Basics
Topic: Mikrotik IPTV VLAN IGMP configuration
Replies: 27
Views: 4024

Re: Mikrotik IPTV VLAN IGMP configuration

What is the use of the second bridge if a single bridge with vlan filtering is sufficient?
by erlinden
Sun Jul 09, 2023 11:34 am
Forum: General
Topic: Wireguard endpoint route using DDNS
Replies: 4
Views: 643

Re: Wireguard endpoint route using DDNS

You can use a name (instead of an IP address) for endpoint in your Wireguard Peer setup.
I'm using the Mikrotik DDNS name (/ip/cloud) for this purpose (it has to be enabled).

For adding a custom route you can use the Wireguard interface.
by erlinden
Fri Jul 07, 2023 3:38 pm
Forum: Wireless Networking
Topic: WiFi Slow
Replies: 3
Views: 1113

Re: WiFi Slow

On the 5GHz band you can use extension channels (up to 80MHz). You might want to do some testing will adjusting this parameter. You should be able to get up to 350-400Mbps.
by erlinden
Wed Jul 05, 2023 11:50 am
Forum: General
Topic: AL2 Firmware?
Replies: 8
Views: 692

Re: AL2 Firmware?

My RB4011 is showing the same firmware type (so nothing to be worried about I think).
by erlinden
Wed Jul 05, 2023 10:47 am
Forum: General
Topic: High CPU utilization on CRS354
Replies: 15
Views: 1472

Re: High CPU utilization on CRS354

You might want to try using the switch for vlan filtering:
https://help.mikrotik.com/docs/display/ ... NFiltering