Community discussions

Search found 2963 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 60
by pukkita
Wed Mar 06, 2019 6:41 pm
Forum: General
Topic: The "bridge"
Replies: 2
Views: 208

Re: The "bridge"

if I've just 3 segments , e.g. DMZ, WAN, LAN in different networks, so none of them is bridged, why is there always a "bridge" involved? Because that's the way you build the "segments". Before 6.42 you had the option of either build a L2 segment by creating a bridge (by software, using CPU) or by u...
by pukkita
Mon Feb 25, 2019 1:28 pm
Forum: General
Topic: Max throughput for this RB
Replies: 4
Views: 677

Re: Max throughput for this RB

64k is the best for gauging of raw CPU power, but again, it depends on the chores the router is carrying away, if you'll be using fasttrack or not, etc.
by pukkita
Thu Jan 03, 2019 1:47 pm
Forum: Beginner Basics
Topic: RB4011iGS+5HacQ2HnD-IN-US first time troubles
Replies: 14
Views: 870

Re: RB4011iGS+5HacQ2HnD-IN-US first time troubles

Which port are you using to connect to it? Have you tried a port other than ether1? (as ether1 is usually WAN and so, firewalled on default config)? Do you see it on winbox neighbors tab? Can you connect to it from winbox if you double click on the MAC field while in neighbors tab? If you can't, wha...
by pukkita
Sun Dec 23, 2018 11:43 am
Forum: SwOS
Topic: CSS326-24G-2S+ does not accept dhcp-provided IP!?
Replies: 2
Views: 323

Re: CSS326-24G-2S+ does not accept dhcp-provided IP!?

Does the CRS326 have a ip > DHCP Client entry setup? Looks like it's running a DHCP Server (not client)...

If so, disable DHCP Server, and set a DCHP Client on top of the bridge interface where all ports are.
by pukkita
Wed Nov 28, 2018 10:21 am
Forum: RouterBOARD hardware
Topic: Can anyone help me identify this routerboard?
Replies: 2
Views: 407

Re: Can anyone help me identify this routerboard?

That's not a Routerboard, but what looks like a PC Engines Alix 2 Series board based on a 2D3 from mid 2000's. Wireless card is a 12+ year old ROS supported one, a CM9 (Atheros AR5213). Have one 2D2 still bouncing around, hw reliability vs an all-integrated routerboards is a joke (logical, this is a...
by pukkita
Wed Nov 14, 2018 10:44 am
Forum: Beginner Basics
Topic: Am I hacked?
Replies: 2
Views: 430

Re: Am I hacked?

Check your firewall (IP > Firewall > Filter) Your symptoms are the typical when being used as a DNS spoof amplification attack. If your wan port is not protected from Internet, attackers start querying your router DNS server pretending to be someone else, who gets blasted with your (and hundreds of ...
by pukkita
Wed Oct 31, 2018 12:00 pm
Forum: RouterBOARD hardware
Topic: cAP Lite Powers on but inaccessible.
Replies: 5
Views: 902

Re: cAP Lite Powers on but inaccessible.

Could be a damaged reset switch. I'd try a netinstall , try with the reset switch, keep it pressed, apply power, wait until cAP appears on netinstall. Alternatively, if reset switch doesn't seem to work, look for a reset pad on the PCB, short it with a screwdriver or something, power it on, and keep...
by pukkita
Wed Oct 17, 2018 2:24 pm
Forum: General
Topic: Trouble connecting u-boot to a RB922
Replies: 5
Views: 228

Re: Trouble connecting u-boot to a RB922

Update: I've found a work-around, but I'd still like to know what's going on here. If I change the RB922 configuration from /ip address add address=192.168.3.73/24 interface=ether1 to /interface bridge add name=bridge-lan /interface bridge port add bridge=bridge-lan interface=ether1 /ip address add...
by pukkita
Wed Oct 17, 2018 2:21 pm
Forum: General
Topic: Trouble connecting u-boot to a RB922
Replies: 5
Views: 228

Re: Trouble connecting u-boot to a RB922

If I connect Orange Pi and RB922 with a straight ethernet cable, I can see the link coming up on the RB922 (100M-half), but u-boot can't ping the RB922 and tftp times out. That's the first thing I'll troubleshoot, why half duplex? try issuing some "ip link" commands or whatever appropiate for the O...
by pukkita
Sun Sep 30, 2018 2:49 pm
Forum: General
Topic: DNS utilization
Replies: 15
Views: 4264

Re: DNS utilization

To recap in the meanwhile it gets to the Wiki: Concurrent Simultaneous Requests is now settable DNS Servers (RouteOS DNS Client Settings): goes through them sequentially passing on to the next only if it doesn't receive an answer (fails). Further clarification regarding this on the wiki would be gre...
by pukkita
Tue Sep 25, 2018 6:23 pm
Forum: Wireless Networking
Topic: WAP ac 5GHz issues with iPhone XS
Replies: 142
Views: 14107

Re: WAP ac 5GHz issues with iPhone XS

Just tested an EU XS with a hAP AC 6.40.9, works flawlessly, 100/115 MBps using 5GHz AC 40MHz.

Looks like device specific, definitely pointing to the iphone.

To rule everything out, Is System > Routerboard Current Firmware same version as Upgrade one?
by pukkita
Fri Sep 21, 2018 8:51 pm
Forum: General
Topic: After upgrade firmware 6.40.5, Can't change admin's group to full
Replies: 6
Views: 581

Re: After upgrade firmware 6.40.5, Can't change admin's group to full

But I do see someone who is cruising around the forum looking for virtually irrelevant things to answer. I expect you're trying to "big yourself up" and up your post count for whatever reason. That's the only reason I can see for the post, unless you're just bored of course. And then you try and be...
by pukkita
Thu Sep 06, 2018 12:30 pm
Forum: Beginner Basics
Topic: Can't connect to Groove AC [SOLVED]
Replies: 2
Views: 265

Re: Can't connect to Groove AC [SOLVED]

Ether port on the Groove comes as WAN port on default config, and thus is firewalled. Try this: 1.- Connect to its wireless. 2.- On winbox, go to neighbor tab. Double click on the MAC address, you should be able to connect. 3.- Once you can log in, reset it to no defaults. 4.- Set it up per your lik...
by pukkita
Wed Sep 05, 2018 1:23 pm
Forum: Beginner Basics
Topic: Problems updating
Replies: 2
Views: 200

Re: Problems updating

Which specific device? Does it have a serial port?
by pukkita
Tue Sep 04, 2018 8:38 pm
Forum: General
Topic: Can´t feed PoE accesspoint
Replies: 3
Views: 256

Re: Can´t feed PoE accesspoint

Yes, if using the stock Power adapter.
by pukkita
Sun Sep 02, 2018 11:47 am
Forum: General
Topic: Point point connection - SXT 5HnD and SXT 5nd r2 lite 5
Replies: 1
Views: 205

Re: Point point connection - SXT 5HnD and SXT 5nd r2 lite 5

Try this: On the Station (SXT5 Lite r2): 1.- Go to Bridge. 2.- Remove unknown port 3.- Add wlan1 port to the bridge Cannot say for sure as I'm missing some details about your config, but once you do that Layer 2 between both networks should be fixed, try pinging between any devices (but the antennas...
by pukkita
Sun Sep 02, 2018 11:27 am
Forum: General
Topic: Can´t feed PoE accesspoint
Replies: 3
Views: 256

Re: Can´t feed PoE accesspoint

RB2011 PoE Out is Passive only, not af nor at, you can't use a RB2011 to power the HP. Captura de pantalla 2018-09-02 a las 10.25.05.png You need to either get an standalone PoE af injector, or use a different Router which supports PoE Out af/at, like an hEX PoE Captura de pantalla 2018-09-02 a las...
by pukkita
Sat Sep 01, 2018 11:26 am
Forum: General
Topic: POE Problem
Replies: 14
Views: 1744

Re: POE Problem

Yes, in all cases they were providing power to wap ac Do same 2011 port powers a 100BT device fine? I've experienced that, specifically when powering gigabit AC devices from 100BT PoE out ports. First time with a 951Ui and a Netbox. Something "broke" on the 951Ui which wasn't able to power a gigabi...
by pukkita
Fri Aug 31, 2018 12:20 pm
Forum: General
Topic: DHCP Static Assigned IP Issue [SOLVED]
Replies: 3
Views: 613

Re: DHCP Static Assigned IP Issue [SOLVED]

However we noticed for all devices which we have set the static DHCP IP for, it will NOT show up in the DHCP Server (under leases). When we tried to manually add a lease for it by adding the IP with its MAC Address, it is always having the "waiting" status. DHCP Server will inspect the ARP table fo...
by pukkita
Thu Aug 30, 2018 11:10 am
Forum: Wireless Networking
Topic: 6.42.7 LTE Scan Broken
Replies: 3
Views: 461

Re: 6.42.7 LTE Scan Broken

I'm a bit new here and used to Redhat's bugzilla/etc. How do I easily find out if there is an issue Mikrotik is already fixing or if it is something that a post like this could be useful for? Sure, check Mikrotik Changelog Section . Searching the forum may lead to interesting findings, or as you ju...
by pukkita
Wed Aug 29, 2018 12:36 pm
Forum: RouterBOARD hardware
Topic: SXTsq 5 ac Level4 licence AP? [SOLVED]
Replies: 2
Views: 332

Re: SXTsq 5 ac Level4 licence AP? [SOLVED]

Yes, it is possible. No differences hardware-wise.
by pukkita
Mon Aug 27, 2018 11:09 am
Forum: General
Topic: Remote management of SXT LTEs
Replies: 3
Views: 336

Re: Remote management of SXT LTEs

Yes, you could go VPS and use CHR; if you prefer having your own on a NOC or Office, couldn't agree more: an hEX or hEX S are ideal, seem to be conceived with this duty in mind: generous RAM, powerful dual core processor, MicroSD... while drawing very little power, taking little space and generating...
by pukkita
Sun Aug 26, 2018 11:21 am
Forum: General
Topic: Remote management of SXT LTEs
Replies: 3
Views: 336

Re: Remote management of SXT LTEs

I would set up a VPN "hub" for those SXT LTE to call home possibly using SSTP; you can dial into the hub and by RoMON or L3 manage any of the SXT LTEs.

This also opens the possibility of running a dude server on the hub, to (mass) monitor and manage the SXT LTEs.
by pukkita
Thu Aug 23, 2018 12:14 am
Forum: Announcements
Topic: v6.40.9 [bugfix] is released!
Replies: 56
Views: 13132

Re: v6.40.9 [bugfix] is released!

6.40.8 is vulnerable to this? yes, check 6.40.9 changelog (or 6.42.7) again , CVE was added afterwards, guess due to coordination? late addition?. MAJOR CHANGES IN v6.40.9: ---------------------- !) security - fixed vulnerabilities CVE-2018-1156, CVE-2018-1157, CVE-2018-1158, CVE-2018-1159; -------...
by pukkita
Wed Aug 22, 2018 11:57 am
Forum: General
Topic: POE Problem
Replies: 14
Views: 1744

Re: POE Problem

Alex, were the 2011 powering AC CPEs?

Ondrej, did you include a supout.rif file taken while the problem was happening? do so...
by pukkita
Tue Aug 21, 2018 1:33 pm
Forum: General
Topic: What is ARP-published feature for?
Replies: 24
Views: 8561

Re: What is ARP-published feature for?

Not sure If I understood your scenario. 10.1.1.2 is a Caching DNS server? if so, let's say it's MAC is AA:BB:CC:DD:EE:FF. You need to publish the entry with the MAC of the real device having 10.1.1.2, on the interface where the queries will come. /ip arp add interface=hosting address=10.1.1.2 mac-ad...
by pukkita
Tue Aug 21, 2018 1:22 pm
Forum: General
Topic: POE Problem
Replies: 14
Views: 1744

Re: POE Problem

I see... agree with you, definitely looks like the hAP ac2 power draw at boot kicks the power draw protection. Which ROS version on the hEX? Firmware? (system > Routerboard?) This could be either a hardware limitation on the hEX S, or maybe something fixable by upgrading POE firmware, as it was the ...
by pukkita
Tue Aug 21, 2018 1:10 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: RB1200 Killed after updating to 6.4
Replies: 3
Views: 909

Re: RB1200 Killed after updating to 6.4

Christian, that RB1200 has some age... leaving a device for so long without upgrading rises a lot the chances of problems, moreso if the device (hardware) is old. How Old is it? ten years? ;) Looks to me like a damaged main booter. To fix: 1.- Connect a serial console to it, so that you can reach th...
by pukkita
Tue Aug 21, 2018 12:13 pm
Forum: General
Topic: WAN to LAN NAT based on subdomain via DDNS!!!
Replies: 1
Views: 253

Re: WAN to LAN NAT based on subdomain via DDNS!!!

I've also setup the IP/Cloud feature but the DNS name is a little hard to remember! Use IP > Cloud. Purchase a domain, say my domain.com Setup as many CNAMEs on that domain pointing to the ip > cloud FQDN. From here onwards, no DNS query is gonna "resolve" to a port AFAIK; to manipulate based on re...
by pukkita
Sun Aug 19, 2018 1:47 pm
Forum: Wireless Networking
Topic: WISP setup & IP Pools!
Replies: 2
Views: 499

Re: WISP setup & IP Pools!

You're not asking for help, but for someone to provide the whole (non trivial) setup for free, soo... wouldn't sweat waiting for that to happen, if ever. One thing is asking about specific issues, doubts etc on a user community forum, and a very different one is dropping a "I am a company and want t...
by pukkita
Sat Aug 18, 2018 12:08 pm
Forum: General
Topic: POE Problem
Replies: 14
Views: 1744

Re: POE Problem

Other Mikrotik PoE switches can output up to 1A per port. Don't know the specific case for the hEX S as is a recent device and not a word about output limits on its last port on the specs, so it may be the case... Again, this is the Maximum power draw by hAP ac2, won't be surprised if average draw i...
by pukkita
Thu Aug 16, 2018 11:59 am
Forum: Beginner Basics
Topic: Port Forwarding for the beginner
Replies: 8
Views: 4495

Re: Port Forwarding for the beginner

Bestinwifi: please change your IPSec secret, you published enough details for someone to try brute forcing VPN accounts on your router... already edited your SN/soft id.
by pukkita
Wed Aug 15, 2018 4:07 pm
Forum: General
Topic: POE Problem
Replies: 14
Views: 1744

Re: POE Problem

hEX S max power draw = 11W hAP ac2 max power draw = 15W Total maximum power draw = 26W. hEX S PSU is 24V @ 1.2A = 28W. Tight, but these are maximum power draw values. Have you tried powering the hAP ac2 on its own to see if is still unstable? How long is the cable going to the hAP ac2? Yes, you can ...
by pukkita
Tue Aug 14, 2018 12:48 pm
Forum: Beginner Basics
Topic: Mikrotik SPF + unable to get full bandwidth
Replies: 5
Views: 576

Re: Mikrotik SPF + unable to get full bandwidth

Bandwidth test tool is useless for SFP+. won't reach more than 2Gb ever.

Use iperf and two PCs...
by pukkita
Sat Aug 11, 2018 12:13 pm
Forum: RouterBOARD hardware
Topic: CRS317 NAT + routing capacity
Replies: 3
Views: 438

Re: CRS317 NAT + routing capacity

By using fasttrack, you will be able to get higher throughput, but I seriously doubt a CRS317 could reach 1Gbps of routed/natted traffic even with fasttrack enabled, guess a more realistic figure will be around 250-500Mbps max, though I never tested. Do not underestimate the hEX, it's a little mean ...
by pukkita
Sat Aug 11, 2018 11:46 am
Forum: Beginner Basics
Topic: IP/Services is all disabled [SOLVED]
Replies: 2
Views: 376

Re: IP/Services is all disabled [SOLVED]

Doesn't it appear on Neighbors tab of Winbox? If so, click on the router Mac-address to connect via Mac-winbox.

If it doesn't, you can gain access to the 3011 in order to reenable networking services by using the Serial Console port, RJ45 on the back of the RB3011.
by pukkita
Fri Aug 10, 2018 12:13 pm
Forum: General
Topic: IP Cloud
Replies: 113
Views: 63265

Re: IP Cloud

You can't AFAIK, dns name is made up from Routerboard serial.
by pukkita
Fri Aug 10, 2018 12:01 pm
Forum: RouterBOARD hardware
Topic: CRS317 NAT + routing capacity
Replies: 3
Views: 438

Re: CRS317 NAT + routing capacity

Your assumptions are correct, this is a programmable switch, whose CPU provides auxiliary functions, but it's not conceived to route 1Gbps. And no, specs mean that with traffic flowing to/from all ports, the device is capable to route 1270Mbps overall (not each port), if all packets were sized 1518 ...
by pukkita
Thu Aug 02, 2018 10:10 pm
Forum: General
Topic: How to display full time in the winbox log
Replies: 14
Views: 996

Re: How to display full time in the winbox log

sid5632, no rudeness, even your gratuitous one, is allowed here.

You're Warned.
by pukkita
Wed Aug 01, 2018 3:01 pm
Forum: Announcements
Topic: Security announcement blog
Replies: 119
Views: 29846

Re: Security announcement blog

Sure:
Captura de pantalla 2018-08-01 a las 14.00.23.png
by pukkita
Sun Jul 29, 2018 12:27 pm
Forum: Announcements
Topic: Security announcement blog
Replies: 119
Views: 29846

Re: Security announcement blog

We have made a blog, where we will publish the most important announcements regarding security and other topics.
Bookmark this link for Security related news:

https://blog.mikrotik.com/security/

Here is the RSS feed link:
https://blog.mikrotik.com/rss/?cat=security
Great!!! Killer idea!
by pukkita
Fri Jul 27, 2018 3:39 pm
Forum: Beginner Basics
Topic: Basic setup for router with multiple AP's [SOLVED]
Replies: 23
Views: 10056

Re: Basic setup for router with multiple AP's [SOLVED]

Nothing special, on router just make sure the ether port where the AP is connected is in the bridge where DHCP runs on.
by pukkita
Fri Jul 27, 2018 2:29 pm
Forum: RouterBOARD hardware
Topic: CCR 1036 stuck on Starting Kernel
Replies: 1
Views: 570

Re: CCR 1036 stuck on Starting Kernel

Get a serial cable ( see Wiki ) and connect to the console. Try a netinstall using ether1 to latest bugfix version. To rule out the reset pressing time lottery, you can set that via the serial console (set the boot device to ether boot) having access to the console will be really useful to troublesh...
by pukkita
Fri Jul 27, 2018 2:24 pm
Forum: Beginner Basics
Topic: Basic setup for router with multiple AP's [SOLVED]
Replies: 23
Views: 10056

Re: Basic setup for router with multiple AP's [SOLVED]

No difference, the approach is the same. Just config all the APs as wired/wireless switch as described . Configure the same SSID and security settings on all of them. As long as the Cisco cable going to the Mikrotik connects to an ethernet port belonging to the same bridge as the DHCP server for you...
by pukkita
Thu Jul 26, 2018 11:02 am
Forum: General
Topic: 2 WAN Port Forwarding with Multiple IP Public
Replies: 6
Views: 1488

Re: 2 WAN Port Forwarding with Multiple IP Public

I see... Agree with Sindy, this looks like a bug, your config looks fine to me with regards to being able to connect to other IPs but from the src/dst-natted ones. ROS version? Routerboard firmware version? How do you config the IPs, directly on the WAN interfaces (no private transit or loopback?) D...
by pukkita
Thu Jul 26, 2018 10:37 am
Forum: Beginner Basics
Topic: MikroTik wAP as wireless client?
Replies: 1
Views: 387

Re: MikroTik wAP as wireless client?

a wAP (or any Routerboard) can be be programmed to be whatever you want. Of course can be a wireless client. What it cannot be is a repeater (wireless client + Wireless AP at the same time) if the other device is not a Mikrotik. If your intention is placing the wAP as outdoors repeater with the Netg...
by pukkita
Wed Jul 25, 2018 1:42 pm
Forum: RouterBOARD hardware
Topic: Hap ac Lite Reset
Replies: 7
Views: 2219

Re: Hap ac Lite Reset

Even if it has been set, the method of keep pressing should work... are them under warranty?
by pukkita
Wed Jul 25, 2018 11:53 am
Forum: RouterBOARD hardware
Topic: Hap ac Lite Reset
Replies: 7
Views: 2219

Re: Hap ac Lite Reset

I have got it back to a stage on Winbox with it showing the MAC address IP of 0.0.0.0, Idenity - preconfig , Version 6.37.3 and board RB952Ui-5ac2nd. Following other threads, I have also attempted to use NetInstall and cannot get it to see the router. To be on the safe side I have attempted it on a...
by pukkita
Wed Jul 25, 2018 11:34 am
Forum: General
Topic: 2 WAN Port Forwarding with Multiple IP Public
Replies: 6
Views: 1488

Re: 2 WAN Port Forwarding with Multiple IP Public

For dual wan use you need to further use mangle to: - keep track of connections, so that what enters via one WAN, exits via the same one - Steer/balance traffic towards the two WANs Even if you aren't using both WANs for general internet traffic, (e.g. general traffic to Internet exits via a single ...
by pukkita
Tue Jul 24, 2018 6:09 pm
Forum: Beginner Basics
Topic: New cAP ac / cannot access webfig on 192.168.88.1 [SOLVED]
Replies: 4
Views: 821

Re: New cAP ac / cannot access webfig on 192.168.88.1 [SOLVED]

... I have problem setting up dual band, but that's another story (and maybe another question here after having exhausted what I can think of!) Solved! (how can I mark it as solved?) => OK, just found it! Thanks for marking it SOLVED! Re: dual band problem Looks like CAPsMAN provisioning setup issu...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 60