Community discussions

Search found 110 matches

by Exiver
Thu Oct 17, 2019 4:10 pm
Forum: General
Topic: Is there an new exploit going around?
Replies: 50
Views: 6119

Re: Is there an new exploit going around?

We do have about 10 routers exposing their SSH service directly to the internet without any restrictions. They are running version 6.42.9, 6.44.5 and 6.44.2. None of those routers has been hit. But we do not have any other services running, everything is disabled except SSH. Leads me to the conclusi...
by Exiver
Tue Oct 01, 2019 9:47 pm
Forum: Beginner Basics
Topic: ISP Setup
Replies: 9
Views: 1074

Re: ISP Setup

I really dont want to offend you - but it looks like you are not that experienced with MikroTik. If you are trying to setup a ISP grade network i would strongly recommend you to contact a consultant.
by Exiver
Mon Sep 30, 2019 8:57 pm
Forum: General
Topic: MikroTik ignoring DHCP Discover Requests from devices
Replies: 11
Views: 1282

Re: MikroTik ignoring DHCP Discover Requests from devices

Im sorry - i have missed your configuration. It looks like you have set "authorative=after-2sec-delay" to your client vlans. This means the router will ignore all dhcp-requests from a device if the requests are not coming in bigger time intervals than 2 seconds. If we look at your screenshots it see...
by Exiver
Mon Sep 30, 2019 8:12 pm
Forum: General
Topic: MikroTik ignoring DHCP Discover Requests from devices
Replies: 11
Views: 1282

Re: MikroTik ignoring DHCP Discover Requests from devices

From an external view your setup is relatively complex. This means without seeing your configuration it would be just a guess into the blue. And that does not help at all since it just wastes your and our time ;-) If you expect help - post your complete configuration.
by Exiver
Mon Sep 30, 2019 8:08 pm
Forum: Beginner Basics
Topic: Static DNS server replies not handled as "related" by firewall
Replies: 12
Views: 928

Re: Static DNS server replies not handled as "related" by firewall

Can you please share your full /export hide-sensitive ? How are these dns requests made? By clients with router set as DNS-Server or directly from client to google-dns (or others)?
by Exiver
Mon Sep 23, 2019 5:52 pm
Forum: Beginner Basics
Topic: how to deny traffic in one direction ?
Replies: 3
Views: 337

Re: how to deny traffic in one direction ?

You have already enabled Connection Tracking which is needed to achieve this goal. Your firewall rules should look for example like this: add chain=forward action=accept connection-state=new,established,related in-interface=ether1 out-interface=ether2 src-address=1.1.1.10 dst-address=2.2.2.10 commen...
by Exiver
Fri Sep 20, 2019 12:02 pm
Forum: Scripting
Topic: Hello, everyone, my ROS is far away, the power of ROS is cut off by the bad guys. I want to add a script to detect ROS
Replies: 6
Views: 911

Re: Hello, everyone, my ROS is far away, the power of ROS is cut off by the bad guys. I want to add a script to detect R

You could use the Scheduler: https://wiki.mikrotik.com/wiki/Manual:System/Scheduler Setup a scheduler like this: add name=reboot-notification start-time=startup interval=0 on-event="/tool e-mail send from=\"admin@yourmikrotik.com\" to=\"notifications@yourdomain.com\" subject=\"Device rebootet\" body...
by Exiver
Thu Sep 19, 2019 1:17 pm
Forum: Scripting
Topic: Policy required to re-"provision" CAPs.
Replies: 4
Views: 511

Re: Policy required to re-"provision" CAPs.

Learned something new, thanks. Since we are using only action=create-enabled i didnt know about the restrictions for dynamic interfaces. But maybe lambert is using static interfaces already? Disabling and enabling works great for us, even within scripts ;-)
by Exiver
Thu Sep 19, 2019 12:59 pm
Forum: Scripting
Topic: Policy required to re-"provision" CAPs.
Replies: 4
Views: 511

Re: Policy required to re-"provision" CAPs.

Or just disable them and re-enable them later when needed?

/cap interface disable [find where configuration="guest-cfg"]
/cap interface enable [find where configuration="guest-cfg"]
by Exiver
Tue Sep 17, 2019 1:48 pm
Forum: Beginner Basics
Topic: Unable to open port forwarding
Replies: 4
Views: 537

Re: Unable to open port forwarding

Which ip address is assigned to the MikroTiks WAN-port (lte)?
Can you please show us your full configuration (/export hide-sensitive) - as Sob mentioned the "in-interface" option is most likely blocking the wanted behavior.
by Exiver
Fri Sep 13, 2019 12:00 pm
Forum: General
Topic: Restrict Clients based on number of mac(devices) on IP
Replies: 1
Views: 237

Re: Restrict Clients based on number of mac(devices) on IP

If you are not in the same L2-network you can not tell how many devices are sitting behind that customers CPE router.
by Exiver
Thu Sep 12, 2019 5:52 pm
Forum: RouterBOARD hardware
Topic: Hardware bandwidth limitation? [SOLVED]
Replies: 16
Views: 1567

Re: Hardware bandwidth limitation? [SOLVED]

How are you testing the speed? Are you using direct http-downloads or some specific tools? Is there any other traffic flowing through the hap ac^2? The switch chipset is limited to 2Gbit when transferring data to or from the CPU.
by Exiver
Thu Sep 12, 2019 5:23 pm
Forum: RouterBOARD hardware
Topic: Hardware bandwidth limitation? [SOLVED]
Replies: 16
Views: 1567

Re: Hardware bandwidth limitation? [SOLVED]

There are a few options to check your processors usage. First one would be the Profiler: https://wiki.mikrotik.com/wiki/Manual:Tools/Profiler As second option you could check the cpu usage with /system resource cpu print interval=0.5 The profiler may be even able to tell you where the bottleneck is....
by Exiver
Thu Sep 12, 2019 5:08 pm
Forum: RouterBOARD hardware
Topic: Hardware bandwidth limitation? [SOLVED]
Replies: 16
Views: 1567

Re: Hardware bandwidth limitation? [SOLVED]

Great, now we can see what you have configured. To understand your problem better there are a few things you need to clear up: - Are you connected to one of the ether2-ether5 ports and you are trying to measure the internet speed or are you testing your internal network speed? - Since you have "use-...
by Exiver
Thu Sep 12, 2019 4:34 pm
Forum: RouterBOARD hardware
Topic: Hardware bandwidth limitation? [SOLVED]
Replies: 16
Views: 1567

Re: Hardware bandwidth limitation? [SOLVED]

Nobody is able to guess what you have really configured. If you refuse to post the actual configuration everyone will be only able to guess thus consuming your and our time.. So please be so gentle and post your configuration export (/export hide-sensitive)
by Exiver
Mon Aug 26, 2019 11:33 pm
Forum: Forwarding Protocols
Topic: EoIP no RX on main side of the bridge
Replies: 5
Views: 495

Re: EoIP no RX on main side of the bridge

Im not 100percent sure but on one router (main device) you are using 192.168.30.15 as local address while this address is bound to the bridge you are binding the eoip tunnel to. Sounds logical wrong to me - can you try to set this local address to your main routers wan address? If that doesnt work p...
by Exiver
Mon Aug 26, 2019 2:47 pm
Forum: Forwarding Protocols
Topic: EoIP no RX on main side of the bridge
Replies: 5
Views: 495

Re: EoIP no RX on main side of the bridge

Without seeing your configuration no one can really tell you whats wrong here ;-)
by Exiver
Fri Aug 23, 2019 2:01 pm
Forum: General
Topic: ROS cant reach the internet, Local clients can
Replies: 3
Views: 483

Re: ROS cant reach the internet, Local clients can

Can you please provide more information? Draw a network diagram and please show us the whole configuration ;)
by Exiver
Fri Aug 23, 2019 12:17 pm
Forum: Beginner Basics
Topic: Dual Wan configuration on same switch
Replies: 5
Views: 586

Re: Dual Wan configuration on same switch

The logic behind my example is that you add different clients to different named address lists (wan1 and wan2). Afterwards you mark all packets coming from addresses on list wan1 with a wan1-routing mark. The same is done to addresses from list wan2. Afterwards you can define which upstream should t...
by Exiver
Thu Aug 22, 2019 7:00 pm
Forum: RouterBOARD hardware
Topic: [hAP ac2] None of ethernet port work
Replies: 9
Views: 1184

Re: [hAP ac2] None of ethernet port work

In our provisioning process some hap ac lites and recently a few hap ac 2s were "bricked" after installing them via Flashfig. They showed the same behavior (LEDs not showing up, sometimes the ethernet link flaps sometimes you do not see anything from the device when connected to either a switch or d...
by Exiver
Thu Aug 22, 2019 5:14 pm
Forum: RouterBOARD hardware
Topic: Cisco SFP Copper Module - link-up, but no connection
Replies: 2
Views: 397

Re: Cisco SFP Copper Module - link-up, but no connection

Can you try to set the speed on your laptops side manually to 1000Mbit-full? We have seen links where one side reported as up (but only with fibre) and the other side does not see anything. That heavily depends on the configuration of both sides speeds and flow control if you do not use auto negotia...
by Exiver
Thu Aug 22, 2019 2:28 pm
Forum: Beginner Basics
Topic: Dual Wan configuration on same switch
Replies: 5
Views: 586

Re: Dual Wan configuration on same switch

Please dont forget that people here are spending their free time to support other users and - in this case - you. So you cannot really demand that people will tell you "how to configure your router properly", but you may ask for help. As anav has stated: This setup is not that uncommon and could be ...
by Exiver
Mon Aug 12, 2019 7:32 pm
Forum: General
Topic: Backup config for bulk deployment
Replies: 2
Views: 365

Re: Backup config for bulk deployment

How do these Backups look like? If you have set mac addresses on bridges or interfaces manually these will be exported (and imported) as well. You could either remove those entries (/interface ethernet ...) from your backups or reset the ports automatically after you have imported the backup via a s...
by Exiver
Mon Aug 12, 2019 7:27 pm
Forum: General
Topic: Allow traffic between isolated subnets? [SOLVED]
Replies: 8
Views: 713

Re: Allow traffic between isolated subnets? [SOLVED]

Depends on your other firewall configuration but most likely you are missing the return path - means right now you are allowing ips from 10.8.0.0/23 to send packets to 10.6.0.151. But if 10.6.0.151 wants to answer any packet it will be dropped by your deny-rule. Setup a second rule with something li...
by Exiver
Mon Aug 12, 2019 7:22 pm
Forum: Beginner Basics
Topic: Port Group Isolation [SOLVED]
Replies: 5
Views: 741

Re: Port Group Isolation [SOLVED]

Yes your configuration is logically correct. You may need to check whether the Switch allows you to use Hardware Offloading ( https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#Bridge_Hardware_Offloading ) on two different bridges on the same switch chipset. If it does not you may see performanc...
by Exiver
Mon Aug 12, 2019 4:40 pm
Forum: Beginner Basics
Topic: vpn between 2 sites for printers
Replies: 1
Views: 283

Re: vpn between 2 sites for printers

The good news is: Every MikroTik device running RouterOS is able to make use of different VPN-methods (IPSEC, Openvpn[tcp only], SSTP, L2TP and so on). If your only purpose is to connect multiple printers together you wont need that much speed going over your VPN - but if you are unsure what your de...
by Exiver
Mon Aug 12, 2019 4:36 pm
Forum: Beginner Basics
Topic: Using VPN for only RDP (3389)
Replies: 2
Views: 369

Re: Using VPN for only RDP (3389)

You should go with the ip-firewall configuration under /ip firewall filter. Best way is to block everything and allow only protocols and ports you want to be accessed. That means you can filter everything except clients source-address to your RDP servers destination address and port (as well as the ...
by Exiver
Mon Aug 12, 2019 2:04 pm
Forum: Announcements
Topic: v6.45.3 [stable] is released!
Replies: 90
Views: 25423

Re: v6.45.3 [stable] is released!

Can't login via linux MAC-Telnet 0.4.4. after update to this version. Connecting to.......done Login failed, incorrect username or password ROS log: echo: system,error,critical login failure for user admin from XX:XX:XX:XX:XX:XX via mac-telnet. The password is correct. Seems like you did not read t...
by Exiver
Thu Aug 08, 2019 8:07 pm
Forum: Wireless Networking
Topic: MAP2n as Travel Router Configuration Assistance
Replies: 18
Views: 1695

Re: MAP2n as Travel Router Configuration Assistance

We do provide LAN based access in at least one hotel here in Germany (additional to wifi) ;o) But you are right this is not really common i guess. You can give it a try - even in your home network. Set the SSID on wlan1 to your private SSID at home, change the psk-passphrase and check whether it wor...
by Exiver
Thu Aug 08, 2019 7:55 pm
Forum: Wireless Networking
Topic: MAP2n as Travel Router Configuration Assistance
Replies: 18
Views: 1695

Re: MAP2n as Travel Router Configuration Assistance

You could definitely do that. But there are a few things that need to be changed: -> Add a second bridge called something like "external" and change the name of the existing bridge from "bridge" to something more intuitive like "internal" -> Remove "ether1" from the first bridge and add "ether1" and...
by Exiver
Thu Aug 08, 2019 6:20 pm
Forum: Beginner Basics
Topic: Mikrotik Router Management via Web App
Replies: 2
Views: 432

Re: Mikrotik Router Management via Web App

You could check if Mikrotik API is suitable for the commands you want to execute on the router (https://wiki.mikrotik.com/wiki/Manual:API). API implementations are out there for at least PHP, Pearl and Python (most likely for more programming languages, just google it). If that does not fit your nee...
by Exiver
Thu Aug 08, 2019 6:11 pm
Forum: Wireless Networking
Topic: MAP2n as Travel Router Configuration Assistance
Replies: 18
Views: 1695

Re: MAP2n as Travel Router Configuration Assistance

There are a few things to mention here: -> It doesnt matter if the router has two or one radio - but it looks like you have already configured a slave wifi interface (wlan2). -> Set the mode for wlan1 to "station" -> Set the mode for wlan2 to "ap-bridge" and delete entries "wds-default-bridge" and "...
by Exiver
Thu Aug 08, 2019 5:48 pm
Forum: Wireless Networking
Topic: CapsMan with two SSID and two Bridge
Replies: 1
Views: 318

Re: CapsMan with two SSID and two Bridge

As always: post your configuration. Otherwise people can just guess and that wont help you that much ;-)
by Exiver
Thu Aug 08, 2019 5:45 pm
Forum: General
Topic: Migrating self signed CA
Replies: 7
Views: 1162

Re: Migrating self signed CA

@wolfktl pls post your whole configuration (Original Router, Backup Router and Client) - otherwise its just a guess into the blue..

-> /export hide-sensitive
by Exiver
Mon Jul 15, 2019 7:25 pm
Forum: Wireless Networking
Topic: how to send AT commands to EC25 LTE modem in LTAP Mini
Replies: 6
Views: 781

Re: how to send AT commands to EC25 LTE modem in LTAP Mini

In RouterOS v6.39 and newer the EC25-MiniPCIe module can be configured as a LTE Interface which can support local IP address from modem. Use this AT command to enable it and after that reset the module: at+qcfg="usbnet",1 Source: https://wiki.mikrotik.com/wiki/Cellular_Quectel_modems_01#Summary It ...
by Exiver
Sat Jun 22, 2019 3:28 pm
Forum: Wireless Networking
Topic: CAPsMAN 5GHz wireless channel problems
Replies: 11
Views: 10919

Re: CAPsMAN 5GHz wireless channel problems

@Kampfwurst:
Please open a new thread with your hardware details and configuration. A few things have changed between 6.34 and 6.44
by Exiver
Fri Jun 07, 2019 12:20 pm
Forum: General
Topic: OpenVPN GUI 2.4.7 can't connect openvpn server
Replies: 7
Views: 881

Re: OpenVPN GUI 2.4.7 can't connect openvpn server

Did you read your Clients log file? Fri Jun 07 10:10:59 2019 VERIFY ERROR: depth=0, error=self signed certificate: CN=myCa Fri Jun 07 10:10:59 2019 OpenSSL: error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed You have set myCa as server certificate on your mikrotik i...
by Exiver
Fri Jun 07, 2019 12:30 am
Forum: General
Topic: Pfsense to Mikrotik ipsec tunnel one way traffic
Replies: 1
Views: 243

Re: Pfsense to Mikrotik ipsec tunnel one way traffic

Post your configs. Everything else will only lead to guessing and that does not really help ;-) There are a few things you could check with that error but they all depend on configurations of your routerboard and pfsense.
by Exiver
Tue Jun 04, 2019 12:07 am
Forum: Beginner Basics
Topic: NAT problem?
Replies: 12
Views: 745

Re: NAT problem?

Perhaps there is a Router God, that can see configurations over long distances?? haha nice jok, you are all right but i think at end i will solve it by putting new wifi router behind mikrotik and disable wifi from ISP thank you all for patience and understanding You could have posted your configura...
by Exiver
Mon Jun 03, 2019 7:37 pm
Forum: RouterBOARD hardware
Topic: hAP ac bricked
Replies: 5
Views: 932

Re: hAP ac bricked

We had several problems with hap ac lites (RB952Ui-5ac2nD) and some of them bootlooping after software upgrades. We normally do have protected-routerboot activated to avoid erased devices when customers really like to press reset buttons. We have learned a few things from this, since hap ac lite and...
by Exiver
Mon Jun 03, 2019 6:23 pm
Forum: General
Topic: Bonding 2 WANs problem
Replies: 2
Views: 208

Re: Bonding 2 WANs problem

Just a little bit more input after @IPATEAM has posted the correct link to give you more information about bonding. It looks like you would not really want bonded interfaces but some kind of loadbalancing. First: There is a little misunderstanding out there about having multiple uplinks on one route...
by Exiver
Mon Jun 03, 2019 4:53 pm
Forum: General
Topic: user ttl after vpn stop
Replies: 2
Views: 226

Re: user ttl after vpn stop

You should consider that you have posted as little information about your setup / configuration as possible. Others, who have not been involved with your setup may only guess right now since it could be everything or nothing. So please make sure you post everything which is needed (network diagram, ...
by Exiver
Wed May 22, 2019 7:58 pm
Forum: Wireless Networking
Topic: Trouble updating cAP version
Replies: 5
Views: 462

Re: Trouble updating cAP version

Please check whether Capsman or the Client has something about the upgrade in the systems log. Sometimes we have seen a message stating that upgrade was not possible.
by Exiver
Tue May 07, 2019 9:58 pm
Forum: Beginner Basics
Topic: Bridge interface not showing traffic [SOLVED]
Replies: 18
Views: 1474

Re: Bridge interface not showing traffic [SOLVED]

I think there is an error in your configuration. The external ip address of your router is bound to the physical interface "combo1" but this port is member of the bridge "bridge-wan". Can you please try to fix this (if you are remote you should consider doing that with safe mode). Additionally your ...
by Exiver
Tue May 07, 2019 9:19 pm
Forum: Beginner Basics
Topic: Port forwarding: in-interface (not working) vs in-interface-list/dst-address (working)?
Replies: 3
Views: 293

Re: Port forwarding: in-interface (not working) vs in-interface-list/dst-address (working)?

It looks like you are using a pppoe-connection. That means the active pppoe-connection is an additional "interface" on your router. ether1 is only the physical link but not the interface where your router receives the traffic coming from the internet. Thats why your interface-list works (ether1 AND ...
by Exiver
Tue May 07, 2019 9:14 pm
Forum: Beginner Basics
Topic: [Help] Probably Loop
Replies: 2
Views: 310

Re: [Help] Probably Loop

The error is written right there ;-) Loop means that your network has two or more ways to reach the destination. Normally you would use something like spanning-tree-protocol (or the faster version rstp) so that your switches or bridges know where to send the packages. That requires your network equi...
by Exiver
Tue May 07, 2019 8:59 pm
Forum: Wireless Networking
Topic: virtual wlan capsmanager
Replies: 5
Views: 448

Re: virtual wlan capsmanager

I was asking for the output of capsmanager because my guess is that the old "wlan2" interface is still listed there (but not visible on the cap since it is not active anymore). That means if capsman still knows about "wlan2" he will increment this number for your newly created interface and name it ...
by Exiver
Tue May 07, 2019 8:56 pm
Forum: Wireless Networking
Topic: CAPsMAN and CAP AC2 - 5Ghz stops working without any log message
Replies: 23
Views: 2085

Re: CAPsMAN and CAP AC2 - 5Ghz stops working without any log message

I think that looks good. Are you able to add the debug-cap rule on that cap which isnt working? We most likely need the part when it stops working so you could maybe log to a file and upload it after you see that its not working anymore?

debug-log rule would be topics=caps,debug
by Exiver
Tue May 07, 2019 8:52 pm
Forum: Wireless Networking
Topic: Requests wrong RSN group cipher
Replies: 10
Views: 1313

Re: Requests wrong RSN group cipher

Does the actual-interface-configuration show the applied changes? Can you please try to remove the network from one of these wifi-client-devices (for example the apple device 30:35:AD:AC:28:08) and readd it? Just to make sure we are not running after a ghost :)
by Exiver
Tue May 07, 2019 8:50 pm
Forum: General
Topic: L2TP + IPSec -> policy not found [SOLVED]
Replies: 5
Views: 447

Re: L2TP + IPSec -> policy not found [SOLVED]

0.0.0.0/1 or 128.0.0.0/1 is not working. To be honest i have never seen anyone using a netmask of 1. Why did you do that? dst-address should be 0.0.0.0/0 .... This is not the root cause of the issue. 0.0.0.0/1 covers "the lower half of the IPv4 internet", i.e. IP addresses from 0.0.0.0 to 127.255.2...
by Exiver
Tue May 07, 2019 12:19 pm
Forum: Wireless Networking
Topic: [CAPsMAN] Channel advise
Replies: 9
Views: 618

Re: [CAPsMAN] Channel advise

There are some things you can try to make your setup better. But that mostly relies on some kind of experience. I have learned much just from testing it out in our small lab and getting overwhelmed how difficult it can be in the real world ;-) What has really helped me are the presentations of MUMs ...
by Exiver
Tue May 07, 2019 12:27 am
Forum: Wireless Networking
Topic: [CAPsMAN] Channel advise
Replies: 9
Views: 618

Re: [CAPsMAN] Channel advise

Totally depends on the location of the caps. If they are all in the same room you wont have much fun. If you need a high density setup you could consider lowering the tx-power. But im not sure where this goes. If you have a specific question for a setup why dont you just ask it completly (for exampl...
by Exiver
Tue May 07, 2019 12:23 am
Forum: General
Topic: L2TP + IPSec -> policy not found [SOLVED]
Replies: 5
Views: 447

Re: L2TP + IPSec -> policy not found [SOLVED]

How is your router connected to the internet? Is it behind NAT? Is your IP a public or a private one? This is wrong: /ip ipsec policy set 0 dst-address=0.0.0.0/1 proposal=L2TP src-address=0.0.0.0/0 add dst-address=128.0.0.0/1 proposal=L2TP src-address=0.0.0.0/0 template=yes 0.0.0.0/1 or 128.0.0.0/1 ...
by Exiver
Tue May 07, 2019 12:13 am
Forum: Wireless Networking
Topic: [CAPsMAN] Channel advise
Replies: 9
Views: 618

Re: [CAPsMAN] Channel advise

As far as i know it will use the same algorithm to chose a channel like using the option "auto" for channel-frequency. If you set a list it will only chose from those entries but always chose the one capsman founds looking best suitable. It depends on the amount of other devices on these channels (m...
by Exiver
Mon May 06, 2019 11:46 pm
Forum: Wireless Networking
Topic: Requests wrong RSN group cipher
Replies: 10
Views: 1313

Re: Requests wrong RSN group cipher

I dont think this will be necessary on your client-devices (smartphones, tablets, computers and so on) but on your mikrotik cap-clients. Restarting the caps should be enough. You can always check if the changes have applied on your capsman with the command
/caps-man actual print detail
by Exiver
Mon May 06, 2019 11:40 pm
Forum: Wireless Networking
Topic: [CAPsMAN] Channel advise
Replies: 9
Views: 618

Re: [CAPsMAN] Channel advise

No. You should set a channel-list for your caps and not a single channel ;-) The capsman will decide which client uses which frequency. If you have a small amount of caps and you know the location you could maybe set the channels each for every access point. But as i said earlier i think its better ...
by Exiver
Mon May 06, 2019 11:38 pm
Forum: Wireless Networking
Topic: Requests wrong RSN group cipher
Replies: 10
Views: 1313

Re: Requests wrong RSN group cipher

As far as i can say: yes. You most likely need to re-provision the clients.

Ps.: Your wpa-passphrase is visible in both of your posts. You maybe want to remove it.
by Exiver
Mon May 06, 2019 11:20 pm
Forum: Wireless Networking
Topic: [CAPsMAN] Channel advise
Replies: 9
Views: 618

Re: [CAPsMAN] Channel advise

Its up to you. You can either set every channel for every access point by hand - or let capsman decide. If you decide to let capsman do the decision you could either set a channel-list (example 2,4ghz: 1,7,13 or 1,5,9,13 or whatevery you like) or just dont set any channels. For us the channel-lists ...
by Exiver
Mon May 06, 2019 11:15 pm
Forum: Wireless Networking
Topic: Requests wrong RSN group cipher
Replies: 10
Views: 1313

Re: Requests wrong RSN group cipher

@planetcaravan: Please dont use tkip as cipher if you are using only wpa/wpa2. Set encryption=aes-ccm and group-encryption=aes-ccm and check if that solves your problem. @others: We need to see your configuration. Otherwise we are just guessing into the blue which doesnt help you and just wastes eve...
by Exiver
Mon May 06, 2019 5:43 pm
Forum: General
Topic: Problem with certificate backup for SSTP
Replies: 21
Views: 1313

Re: Problem with certificate backup for SSTP

Glad to hear that it worked for you!
by Exiver
Mon May 06, 2019 5:14 pm
Forum: Beginner Basics
Topic: ROS Level 4 hotspot active user
Replies: 3
Views: 245

Re: ROS Level 4 hotspot active user

Im really sure (1) will happen - but as i said i never tried this ;-) But option (2) and (3) would use a different logic behind this check. Its more easy for the Router to check whether there are already 200 connections and just dont accept the next one until that number is < 200.
by Exiver
Mon May 06, 2019 4:55 pm
Forum: Beginner Basics
Topic: ROS Level 4 hotspot active user
Replies: 3
Views: 245

Re: ROS Level 4 hotspot active user

I have never tried but from logical side i would say no users can be logged in if there are already 200 active users in /ip hotspot active That means you could help yourself with a script which checks on a regularly basis if there are more than (just an example) 175 users connected. If its true you ...
by Exiver
Mon May 06, 2019 4:44 pm
Forum: Beginner Basics
Topic: Seeking Help for setting up Load Balancing for 2 WANS dynamic IPs
Replies: 2
Views: 251

Re: Seeking Help for setting up Load Balancing for 2 WANS dynamic IPs

You can use whatever ports you like. Since you are using the option to have master- and slave-ports you are most likely not on a newer firmware ( i guess they made the changes to the bridge somewhere on 6.40.xx or 6.42.xx) Maybe you should upgrade to the latest long-term (or stable?) software releas...
by Exiver
Mon May 06, 2019 4:37 pm
Forum: Wireless Networking
Topic: CAPsMAN and CAP AC2 - 5Ghz stops working without any log message
Replies: 23
Views: 2085

Re: CAPsMAN and CAP AC2 - 5Ghz stops working without any log message

Without giving us more input all we can do is just guessing what maybe could be wrong...

Please post the output of

-> on capsmanager:
/caps-man interface print detail

-> on cap-client
/int wire print detail
by Exiver
Mon May 06, 2019 3:24 pm
Forum: Wireless Networking
Topic: virtual wlan capsmanager
Replies: 5
Views: 448

Re: virtual wlan capsmanager

If i understand correctly your cap-client shows you the interface names under /interface wireless print ? I guess that happens when you change the configuration / provisioning rule on your capsman but you didnt delete the old interfaces. Can you check whether there are still "older" interfaces liste...
by Exiver
Mon May 06, 2019 3:20 pm
Forum: Wireless Networking
Topic: CAPsMAN and CAP AC2 - 5Ghz stops working without any log message
Replies: 23
Views: 2085

Re: CAPsMAN and CAP AC2 - 5Ghz stops working without any log message

Can you please check the "current-state" listed on interface-list printable with "/caps-man interfaces print detail" ? It should show you whether the access point is in state "running-ap" (thats the status you would want) or in some other status like radar-detection and so on..
by Exiver
Mon May 06, 2019 3:18 pm
Forum: Wireless Networking
Topic: Hotspot+dynamic vlanned Capsman
Replies: 3
Views: 418

Re: Hotspot+dynamic vlanned Capsman

Since it looks like your setup is a little bit more complex i would go with the "easy" way. Add a second virtual configuration to your access points either with or without passphrase (WPA-Personal AND/OR WPA2-Personal) and setup access lists with mac-address matching rules. https://wiki.mikrotik.com...
by Exiver
Fri May 03, 2019 6:39 pm
Forum: General
Topic: Configuration Reset - CAPS Mode
Replies: 2
Views: 479

Re: Configuration Reset - CAPS Mode

To be honest i have never tried this. But the caps mode should just have the advantage that the router is directly searching for a capsman server. Which firewall rules are applied needs to be tested tho. Do you need the caps mode or did you just ask because you have seen that option?
by Exiver
Fri May 03, 2019 5:45 pm
Forum: Beginner Basics
Topic: Reset Factory Default without pressing Reset button [SOLVED]
Replies: 4
Views: 462

Re: Reset Factory Default without pressing Reset button [SOLVED]

If you have phisical access and you dont want to use the reset button there is most likely no option to do that. Is there any reason you are not allowed to press the reset button? Netinstall would be one option - but that only works with pressing the button as well so..
by Exiver
Fri May 03, 2019 1:24 pm
Forum: Forwarding Protocols
Topic: vpn
Replies: 4
Views: 724

Re: vpn

You should just add the specific routes for both other networks. Example: Network #1: 192.168.0.0/24 (Router 192.168.0.1 has route to 192.168.1.0/24 via <l2tp-interface>) Network #2: 192.168.1.0/24 (Router 192.168.1.1 has route to 192.168.0.0/24 via <l2tp-interface>) Each VPN endpoints should have a...
by Exiver
Fri May 03, 2019 12:56 pm
Forum: General
Topic: Problem with certificate backup for SSTP
Replies: 21
Views: 1313

Re: Problem with certificate backup for SSTP

Thank you for your input, i think everything looks good here.

The following link is interesting for you:

viewtopic.php?t=88372

Did you set a CRL while creating these certificates? If yes, can you try it without CRL?
by Exiver
Thu May 02, 2019 4:06 pm
Forum: General
Topic: Problem with certificate backup for SSTP
Replies: 21
Views: 1313

Re: Problem with certificate backup for SSTP

Original post was about sstp (other author), kadety uses openvpn.
by Exiver
Thu May 02, 2019 3:05 pm
Forum: General
Topic: Problem with certificate backup for SSTP
Replies: 21
Views: 1313

Re: Problem with certificate backup for SSTP

Im not sure if you read what i have written or if you just skim through my messages. Right now i will try it once more, if you keep ignoring me i will not answer anymore. This sounds harsh - im sorry for that but its my free time and what we are doing here is wasting my and your time. No one wants t...
by Exiver
Thu May 02, 2019 2:35 am
Forum: Beginner Basics
Topic: Unknown device in ARP list with IP and without MAC
Replies: 8
Views: 671

Re: Unknown device in ARP list with IP and without MAC

The device is not in your network... Some other device has tested whether this ip is active or not. It seems to be not active. If you want to know which device asked for that ip you need to log arp messages on your L2 network and search them when somthing similar happens again..
by Exiver
Wed May 01, 2019 10:11 pm
Forum: General
Topic: Problem with certificate backup for SSTP
Replies: 21
Views: 1313

Re: Problem with certificate backup for SSTP

You missed the clients side logs... Thus guessing into the wild again: Is the Hostname on your server the same as on your original router? Must be since the certificate is only valid for identity "server_MK" so if your backup system has a different /system identity the client wont accept the server ...
by Exiver
Tue Apr 30, 2019 10:39 pm
Forum: General
Topic: Problem with certificate backup for SSTP
Replies: 21
Views: 1313

Re: Problem with certificate backup for SSTP

Can you please make sure that your date and time is set correct on both routers? Looks like a certificate problem - this may be caused by "not valid" certificates since your router shows in picture (2) that time is not set thus resulting in unix standard time (01.01.1970 00:00) Is that Log in pictur...
by Exiver
Tue Apr 30, 2019 6:24 pm
Forum: Beginner Basics
Topic: Unknown device in ARP list with IP and without MAC
Replies: 8
Views: 671

Re: Unknown device in ARP list with IP and without MAC

It doesnt mean that only your router tried to reach that address. Could be some device in another subnet for example. The timeout is expected since that device is not reachable. It was just to show you that the entry appears in dhcp-server leases with only "D"-Flag and without mac-address...
by Exiver
Tue Apr 30, 2019 1:17 pm
Forum: Beginner Basics
Topic: Unknown device in ARP list with IP and without MAC
Replies: 8
Views: 671

Re: Unknown device in ARP list with IP and without MAC

That happens when your router tries to reach that address but no device is answering (ARP)

You can easily try this out:

* Check /ip arp
* Try to ping an address which is not in use
* Check /ip arp again
by Exiver
Tue Apr 30, 2019 2:04 am
Forum: General
Topic: Problem with certificate backup for SSTP
Replies: 21
Views: 1313

Re: Problem with certificate backup for SSTP

You should understand that my howto steps werent in random order but i had a plan telling you so. After you have restored the configuration there is some setting relying on a certificate which is indeed there at this time. But if you delete it afterwards it wont be there - your settings are maybe sc...
by Exiver
Mon Apr 29, 2019 9:58 pm
Forum: General
Topic: Problem with certificate backup for SSTP
Replies: 21
Views: 1313

Re: Problem with certificate backup for SSTP

Hi Exiver, I have two CCR1016, firts in production and second in backup. Same Hardware end RouterOS 6.44.3. When I restore the backup, the certificates do not have the "K" of privete key, see. MK1.jpg After restore backup, I Export certificate of MK Production end import to backup (.crt and .KEY), ...
by Exiver
Mon Apr 29, 2019 5:45 pm
Forum: General
Topic: Problem with certificate backup for SSTP
Replies: 21
Views: 1313

Re: Problem with certificate backup for SSTP

Do you use the exact same configuration on the second hex as on the first one? Since OP has selected "Verify Server Address from Certificate" the DNS must match the second hex as well (so if you use another IP for the second router and the Hostname is different this wont work). @kadety: We need your...
by Exiver
Fri Apr 26, 2019 10:30 pm
Forum: Wireless Networking
Topic: Hotspot Configuration
Replies: 4
Views: 594

Re: Hotspot Configuration

Your config looks a little bit "unfinished" if im allowed to say that. You have one dhcp-server running on ether1 while having a dhcp client on the same interface? It looks like your uplink interface is indeed ether1 so this should be not needed. I guess the problem is occuring because of the two fo...
by Exiver
Fri Apr 26, 2019 10:14 pm
Forum: Wireless Networking
Topic: Capsman with 2 Provisioning configs
Replies: 1
Views: 251

Re: Capsman with 2 Provisioning configs

There are some howtos accessible via Google and there is the wiki article which explains how to setup a master/slave configuration: https://wiki.mikrotik.com/wiki/Manual:CAPsMAN#Examples There are different setups possible: Which router are you using as a capsman? I would suggest to setup the config...
by Exiver
Fri Apr 26, 2019 10:14 am
Forum: Wireless Networking
Topic: Hotspot Configuration
Replies: 4
Views: 594

Re: Hotspot Configuration

Please post your configuration:

/export hide-sensitive
by Exiver
Thu Apr 25, 2019 11:30 pm
Forum: General
Topic: Device Discovery question
Replies: 3
Views: 206

Re: Device Discovery question

Sorry i forgot something. The Neighbor Discovery Protocol.. My bad..

See:
https://wiki.mikrotik.com/wiki/Manual:I ... _discovery
by Exiver
Thu Apr 25, 2019 11:46 am
Forum: General
Topic: I'm unable to make flashfig work!
Replies: 7
Views: 579

Re: I'm unable to make flashfig work!

I remember that we had those problems as well. Our workaround was to setup a scheduler in the flashfig config file only. This scheduler adds an ip address, downloads the real config (and updated routeros via FTP), creates another scheduler and reboots. The new scheduler disables unneeded packages, a...
by Exiver
Thu Apr 25, 2019 2:17 am
Forum: General
Topic: Device Discovery question
Replies: 3
Views: 206

Re: Device Discovery question

There are different options to discover your router. First there is the Winbox Service (tcp 8291) - can be blocked by firewall (allow your management ip addresses and disallow everything else for example) Second there is the mac-winbox service which you can find under /tool mac-server mac-winbox . T...
by Exiver
Wed Apr 24, 2019 9:20 pm
Forum: General
Topic: I'm unable to make flashfig work!
Replies: 7
Views: 579

Re: I'm unable to make flashfig work!

[...] About the gateway configured, what do you mean? I only had configured the 192.168.2.1 ip in the pc's interface, because there is no gateway in that network.... I have seen MikroTik employes and wiki mentioning it multiple times. They tell you to set a gateway (even if there is none, you could...
by Exiver
Wed Apr 24, 2019 9:08 pm
Forum: Wireless Networking
Topic: CAPsMAN Certificate Issues
Replies: 2
Views: 412

Re: CAPsMAN Certificate Issues

We also observed this behavior with a few hap ac lites. Since we have over 1500 units deployed and it happened to about 10-20 we never bothered about it. You can import the capsman CA Certificate on your client and the error will be gone. I guess it happened after software updates but im not 100% su...
by Exiver
Tue Apr 23, 2019 2:39 pm
Forum: General
Topic: Failed to give out IP address: unknown pool
Replies: 4
Views: 284

Re: Failed to give out IP address: unknown pool

Never seen this error before.. Maybe you should do a /supout when this occurs again and send it to mikrotik support..
by Exiver
Tue Apr 23, 2019 2:38 pm
Forum: General
Topic: I'm unable to make flashfig work!
Replies: 7
Views: 579

Re: I'm unable to make flashfig work!

Please make sure, your host has the ip 192.168.2.1 and a gateway address set. Also make sure, the computer is not connected to another network (for example: we had problems when the used computer was also connected to a wireless network). Next would be to check your firewall settings (just disable i...
by Exiver
Tue Apr 23, 2019 2:33 pm
Forum: Wireless Networking
Topic: Hotspot Splash Page Not Loading Automatically
Replies: 1
Views: 313

Re: Hotspot Splash Page Not Loading Automatically

Please show us your firewall rules. Is the site opening when you try to access it directly (enter the IP-address in your browsers url bar)?
by Exiver
Tue Apr 23, 2019 1:40 pm
Forum: Wireless Networking
Topic: capsman cannot modify wireless Protocol (802.11,ns,nv2)
Replies: 2
Views: 252

Re: capsman cannot modify wireless Protocol (802.11,ns,nv2)

NV2 and nstream features are not working with capsman at the moment (not sure if mikrotik will introduce that feature later), see:
https://wiki.mikrotik.com/wiki/Manual:CAPsMAN#Overview
MISSING CAPsMAN features
[*]Nstreme AP support
[*]Nv2 AP support
[*]TBA
by Exiver
Tue Apr 16, 2019 6:29 pm
Forum: Wireless Networking
Topic: CAPsMAN Provisioning Issue
Replies: 4
Views: 515

Re: CAPsMAN Provisioning Issue

Okay, there are a few things which are odd in my opinion.. First: You specify the slave-configurations in your provisioning rule: /caps-man provisioning add action=create-dynamic-enabled master-configuration=VLAN1 name-format=prefix name-prefix=InoptimAP radio-mac=74:4D:28:12:9D:23 slave-configurati...
by Exiver
Tue Apr 16, 2019 4:27 pm
Forum: Wireless Networking
Topic: CAPsMAN Provisioning Issue
Replies: 4
Views: 515

Re: CAPsMAN Provisioning Issue

Can you please post your full capsman configuration as well as the caps client configurations?

On your capsmanager device:
 /cap export hide-sensitive
On the Client:
 /export hide-sensitive
by Exiver
Tue Mar 12, 2019 6:16 pm
Forum: Beginner Basics
Topic: Trying to make service available from VPN
Replies: 6
Views: 362

Re: Trying to make service available from VPN

Please do not set the ip addresses of your vpn (neither local nor the remote one) to one of the ips from the cisco net (10.10.10.0/28). You should just setup the vpn as you would do for a normal road-warrior routed setup (example: https://wiki.mikrotik.com/wiki/Manual:Interface/L2TP#Basic_L2TP.2FIpS...
by Exiver
Mon Mar 11, 2019 2:05 pm
Forum: Wireless Networking
Topic: 10Gb on RB2011 - bad idea?
Replies: 6
Views: 538

Re: 10Gb on RB2011 - bad idea?

Im not sure why this question gets posted here 1:1, after it was already answered on reddit:
It is a spamming account. Posts get edited and filled with spam links after a while.
Thanks for the clarification. I heard about this but never seen it tho.
by Exiver
Mon Mar 11, 2019 1:20 pm
Forum: Wireless Networking
Topic: 10Gb on RB2011 - bad idea?
Replies: 6
Views: 538

Re: 10Gb on RB2011 - bad idea?

Im not sure why this question gets posted here 1:1, after it was already answered on reddit:

https://www.reddit.com/r/mikrotik/comme ... _bad_idea/


RB2011 -> Only SFP -> no 10Gb/s
by Exiver
Fri Mar 01, 2019 1:05 pm
Forum: Beginner Basics
Topic: Ovpn from ubuntu failing
Replies: 1
Views: 280

Re: Ovpn from ubuntu failing

Please check whether the following link may help you since the error isnt that common:

http://blog.schmoigl-online.de/?p=787
by Exiver
Mon Feb 18, 2019 2:14 pm
Forum: Beginner Basics
Topic: DST Port over specific WAN
Replies: 2
Views: 212

Re: DST Port over specific WAN

Please post at least your filter / mangle rules and routes. Better would be the whole configuration - otherwise its just guessing.
by Exiver
Thu Feb 07, 2019 5:42 pm
Forum: Wireless Networking
Topic: Wireless Wire - expected throughput?
Replies: 8
Views: 967

Re: Wireless Wire - expected throughput?

I can confirm that Wireless Wire is indeed giving me full Gigabit capacity (~970M in both directions). Im using it in a setup where the links are about 70m away from each other. So you should be definitely good to got with the kit
by Exiver
Thu Jan 17, 2019 5:10 pm
Forum: General
Topic: LAN Connectivity Issues ccr1016-12g
Replies: 2
Views: 415

Re: LAN Connectivity Issues ccr1016-12g

First of all you need to provide more information, for example: What did you change when you implemented the CCR. Did you just add one lan cable from your old router(switch?) to the CCR? Please tell us, which configuration change was made to the existing network. And additionally it would be great t...
by Exiver
Thu Jan 10, 2019 7:43 pm
Forum: General
Topic: DHCP Setup on two ports
Replies: 7
Views: 498

Re: DHCP Setup on two ports

Its not possible to add the dhcp server on a bridged interface because those ports are logically connected like on a switch. That means the dhcp service on slave interface (ether6) would also listen on slave interface (ether7). That results into the problem that the service cannot distinguish from w...
by Exiver
Thu Jan 10, 2019 6:25 pm
Forum: Wireless Networking
Topic: Problems accessing wAP G-5HacT2HnD
Replies: 13
Views: 630

Re: Problems accessing wAP G-5HacT2HnD

Okay thats weird but maybe export hide-sensitive doesnt print everything interesting.

Can you please provide the output for

/ip service export
and
/ip firewall export

Please make sure you hide anything containing personal stuff like serial number of the router and so on.
by Exiver
Thu Jan 10, 2019 3:42 pm
Forum: Wireless Networking
Topic: Problems accessing wAP G-5HacT2HnD
Replies: 13
Views: 630

Re: Problems accessing wAP G-5HacT2HnD

There is a problem with your configuration. You added the wifi and the lan port to your bridge "bridge" /interface bridge add name=bridge [...] /interface bridge port add bridge=bridge interface=ether add bridge=bridge interface=wlan-2GHz add bridge=bridge interface=wlan-5GHz [...] Everything correc...
by Exiver
Fri Jul 29, 2016 6:26 pm
Forum: RouterBOARD hardware
Topic: wAP AC (General questions and experience)
Replies: 118
Views: 44405

Re: wAP AC (General questions and experience)

Almost.. You have to power it on while holding the Reset Button to allow yourself a configuration via the ethernet port. That takes much more time than just plugging it into our POE Switch and adding the config to multiple devices in one go.. Edit: Something else: There is most likely a problem with...
by Exiver
Fri Jul 29, 2016 5:02 pm
Forum: RouterBOARD hardware
Topic: wAP AC (General questions and experience)
Replies: 118
Views: 44405

Re: wAP AC (General questions and experience)

We ordered multiple of these wAP AC Devices. The configuration method is horrible in my opinion. Why change a good system to wifi configuration?? Whatever.. We have another problem: One Device is unresponsive right now. Its booting and after five seconds the "eth" and "pwr" LED turn off and a second...
by Exiver
Tue Jan 20, 2015 1:18 pm
Forum: Beginner Basics
Topic: Forward Port from VPN to internal Network
Replies: 1
Views: 524

Re: Forward Port from VPN to internal Network

Hey again,

after a week im trying to bump my post because after i posted it it needed almost a day to be activated by the moderators. I think it was already on the lower part of the site when everyone was able to see it. So my second try.

Thanks for your help ;-)
by Exiver
Sun Jan 11, 2015 12:57 am
Forum: Beginner Basics
Topic: Forward Port from VPN to internal Network
Replies: 1
Views: 524

Forward Port from VPN to internal Network

Hey guys, im new to mikrotik and now trying to configure my RB951Ui-2HnD properly. All ports from outside are blocked by my provider, so i have to use portfordwarding via my server. I set up the VPN with OpenVPN and its working without problems until here. I do a dstnat on my server who sends the pa...