Community discussions

MUM Europe 2020

Search found 38 matches

by alexvdbaan
Wed May 15, 2019 6:59 pm
Forum: General
Topic: iframe issue at MTU 1500
Replies: 1
Views: 385

iframe issue at MTU 1500

Hi guys, Today I have runned into a weird issue at a clients network. We have a fiber connection onsite with a pppoe connection that supports RFC4638/MTU 1500 frames. Since we deliver a multitenant network each client is hosted in its own vlan. Today a client reported issues with a squarespace websi...
by alexvdbaan
Wed May 08, 2019 8:20 pm
Forum: Wireless Networking
Topic: Hotspot+dynamic vlanned Capsman
Replies: 3
Views: 535

Re: Hotspot+dynamic vlanned Capsman

Since it looks like your setup is a little bit more complex i would go with the "easy" way. Add a second virtual configuration to your access points either with or without passphrase (WPA-Personal AND/OR WPA2-Personal) and setup access lists with mac-address matching rules. https://wiki.mikrotik.co...
by alexvdbaan
Fri May 03, 2019 4:39 pm
Forum: Wireless Networking
Topic: Hotspot+dynamic vlanned Capsman
Replies: 3
Views: 535

Hotspot+dynamic vlanned Capsman

Goodafternoon, My company is currently supporting a coworking space with several locations. Each location has roughly 30 separate units that host individual companies. We use a full MikroTik network stack assisted with the Kaplansoft TekRadius software to provide a wlan with dynamically assigned vla...
by alexvdbaan
Fri Sep 14, 2018 4:10 pm
Forum: Announcements
Topic: v6.43 [current] is released!
Replies: 148
Views: 31439

Re: v6.43 [current] is released!

@MikroTik support, do you have any feedback on the question below? bridge - add dynamic CAP interface to tagged ports if "vlan-mode=use-tag" is enabled; Great work MT team! I was wondering if you could elaborate on the dynamic vlan function? I can see that the Caps interfaces are included in the bri...
by alexvdbaan
Mon Sep 10, 2018 1:22 pm
Forum: Announcements
Topic: v6.43 [current] is released!
Replies: 148
Views: 31439

Re: v6.43 [current] is released!

bridge - add dynamic CAP interface to tagged ports if "vlan-mode=use-tag" is enabled; Great work MT team! I was wondering if you could elaborate on the dynamic vlan function? I can see that the Caps interfaces are included in the bridge and that the active interfaces are tagged in the dynamic vlan e...
by alexvdbaan
Sat Sep 01, 2018 8:29 am
Forum: General
Topic: POE Problem
Replies: 14
Views: 3709

Re: POE Problem

Alex, were the 2011 powering AC CPEs?
Yes, in all cases they were providing power to wap ac
by alexvdbaan
Fri Aug 24, 2018 8:38 pm
Forum: General
Topic: RB3011 Switch VLAN Access Port Issue
Replies: 5
Views: 878

Re: RB3011 Switch VLAN Access Port Issue

Chris,

You mention bridge but you don't show your /interface export. Could you please add a full export?

Thanks, Alex
by alexvdbaan
Thu Aug 23, 2018 10:03 pm
Forum: General
Topic: Convert .json Office 365 IP range to address list
Replies: 3
Views: 826

Re: Convert .json Office 365 IP range to address list

When I get back in, I'll see if I can put together a script for this.
That would be great, thanks in advance.
by alexvdbaan
Thu Aug 23, 2018 4:00 pm
Forum: General
Topic: Convert .json Office 365 IP range to address list
Replies: 3
Views: 826

Convert .json Office 365 IP range to address list

Goodafternoon, I am trying to find a way to automate adress-list creation from the published IP ranges from Microsoft Office 365 services. Microsoft delivers an online json presentation that can also be downloaded. Was hoping that one of you might have some script or solution for this? Thanks, Alex
by alexvdbaan
Tue Aug 21, 2018 4:55 pm
Forum: General
Topic: POE Problem
Replies: 14
Views: 3709

Re: POE Problem

I have several clients with RB2011 and poe port broken. Thought it was a coincidence but it appears to be that the poe is shutting down more often than not.
by alexvdbaan
Sun Aug 19, 2018 11:45 pm
Forum: General
Topic: secure VLAN trunk between /interface switch and /interface bridge setup [SOLVED]
Replies: 1
Views: 362

Re: secure VLAN trunk between /interface switch and /interface bridge setup [SOLVED]

Problem solved. I manually added the bridge on my router with STP enabled. As soon as I disabled STP on the bridge my ping kept going while enabling vlan-mode=secure
by alexvdbaan
Sun Aug 19, 2018 8:22 pm
Forum: General
Topic: secure VLAN trunk between /interface switch and /interface bridge setup [SOLVED]
Replies: 1
Views: 362

secure VLAN trunk between /interface switch and /interface bridge setup [SOLVED]

Hi guys, Today I setting up various vlan scenario's between MT devices that have full hardware offloading (CRS3xx switches) and devices that either don't support it. I have setup a small router to host vlans and transport those to my CRS326. In my first test I setup vlan filtering on my router to tr...
by alexvdbaan
Mon Jul 16, 2018 9:49 am
Forum: Announcements
Topic: Winbox v3.16 released!
Replies: 63
Views: 30814

Re: Winbox v3.16 released!

The problem with "Click Reconnect, then Winbox window disappears and after exactly 30 seconds automatically disconnect from device with Connection lost window appearing again" still persist (first time spotted in v3.14 https://forum.mikrotik.com/viewtopic.php?f=21&t=134940&start=50#p665710) same......
by alexvdbaan
Thu Jun 28, 2018 4:07 pm
Forum: General
Topic: CRS326/8 untagged to tagged translation
Replies: 2
Views: 501

CRS326/8 untagged to tagged translation

Hi Guys,

One of my clients VOIP vendors delivers their CPE with an interface with untagged voip traffic. They would like us to translate that untagged traffic to vlan 100. Does anyone have experience with this port based translation in the vlan aware bridge setup?

Thanks,

Alex
by alexvdbaan
Mon May 07, 2018 10:21 am
Forum: General
Topic: CapsMAN Dynamic Radius VLAN's with bridged VLAN filtering
Replies: 3
Views: 977

Re: CapsMAN Dynamic Radius VLAN's with bridged VLAN filtering

I have setup a HAP ac with CapsMAN locally setup, external radius and various vlan's. When I tag the wireless interfaces in the bridge it all works. Unfortunately I cannot get the setup to work on the clients premises by simply adding the wireless interfaces to the tagged interface list. Hope that o...
by alexvdbaan
Sun May 06, 2018 12:13 am
Forum: General
Topic: CapsMAN Dynamic Radius VLAN's with bridged VLAN filtering
Replies: 3
Views: 977

Re: CapsMAN Dynamic Radius VLAN's with bridged VLAN filtering

This post: viewtopic.php?f=2&t=133821provided me with a good hint, simply adding the dynamically assigned capsman interfaces to the tagged list. I have setup a test on a hap ac and that worked. I will let you know if the customer site will also be successful.
by alexvdbaan
Sat May 05, 2018 3:49 pm
Forum: General
Topic: CapsMAN Dynamic Radius VLAN's with bridged VLAN filtering
Replies: 3
Views: 977

CapsMAN Dynamic Radius VLAN's with bridged VLAN filtering

Hey guys, This question came up after attempts to make this config even 'better'. I quote the better because the setup is working according to client spec but it would be nice to get it done the way I like. So hope to gain some valuable insights and suggestions from the forum. Network is a multi-ten...
by alexvdbaan
Tue Dec 12, 2017 11:54 am
Forum: Announcements
Topic: v6.41rc [release candidate] is released! New bridge implementation!
Replies: 561
Views: 130591

Re: v6.41rc [release candidate] is released! New bridge implementation!

Sure thing! /interface bridge add fast-forward=no igmp-snooping=no name=bridge priority=0x1000 protocol-mode=none vlan-filtering=yes The docs I referenced uses pvid=1 for the bridge and for holding the VLANs, so my bridge sets no pvid. Instead, I've assigned the IP directly to a VLAN Thanks bjornr,...
by alexvdbaan
Mon Dec 11, 2017 2:35 pm
Forum: Announcements
Topic: v6.41rc [release candidate] is released! New bridge implementation!
Replies: 561
Views: 130591

Re: v6.41rc [release candidate] is released! New bridge implementation!

Hi bjornr, If I look at your setup it seems that the primary difference is that you also list your bridge as tagged in the vlan port settings. Could you share your bridge default vlan setting? Mine is: /interface bridge add admin-mac=64:D1:54:DA:33:50 auto-mac=no name=#master protocol-mode=none pvid...
by alexvdbaan
Mon Dec 11, 2017 1:29 pm
Forum: Announcements
Topic: v6.41rc [release candidate] is released! New bridge implementation!
Replies: 561
Views: 130591

Re: v6.41rc [release candidate] is released! New bridge implementation!

Hi Guys, I have been playing around with the CRS326 and the new bridge implementation. I am quite happy with the direction of the new bridge, everything should become a lot easier. However as a few people before me have posted, getting it all to work with the current info on the wiki is challenging....
by alexvdbaan
Wed May 31, 2017 1:08 pm
Forum: The Dude
Topic: Show Capsman 2.4 & 5Ghz clients
Replies: 0
Views: 472

Show Capsman 2.4 & 5Ghz clients

Goodafternoon,

I have been trying to get a Dude Chart up and running that shows a label with 2.4Ghz Capsman connected clients and then the 5Ghz connected clients. Has any one of you already encountered this or have a suggestion on how I could implement this?

Thanks in advance,

Alex
by alexvdbaan
Sat Jan 07, 2017 1:17 pm
Forum: General
Topic: RoadWarrior VPN with certificate & Radius
Replies: 2
Views: 599

Re: RoadWarrior VPN with certificate & Radius

Hi Michael,

I have looked into Duo combined with their LDAP proxy but did not get this properly connected to the RADIUS facility in RouterOS. Have you managed to get it working on the RouterOS platform?

Alex
by alexvdbaan
Fri Jan 06, 2017 7:26 pm
Forum: General
Topic: RoadWarrior VPN with certificate & Radius
Replies: 2
Views: 599

RoadWarrior VPN with certificate & Radius

Hi Guys, I would like to make a VPN setup that allows RoadWarrior users to utilize the remote gateway public IP address to connect to cloud services. Currently an SSTP setup is running with Radius authentication, however an additional factor is required. What would be the best method to combine indi...
by alexvdbaan
Fri May 20, 2016 10:12 am
Forum: RouterBOARD hardware
Topic: wAP AC (General questions and experience)
Replies: 118
Views: 45667

Re: wAP AC (General questions and experience)

Hi guys, Is there anyone here with experience with the WAP ac hooked up to long (80+ meter) UTP CAT6 cable lengths? Reason why I'm asking is because we are planning a rollout where we want to use the WAP ac with cable lenghts of up to 85-90 meter. Since we will only hook up less than 5 AP's we wante...
by alexvdbaan
Fri Mar 11, 2016 3:44 pm
Forum: General
Topic: Slow speeds from CRS125
Replies: 57
Views: 4657

Re: Slow speeds from CRS125

You can find the solution here: http://forum.mikrotik.com/viewtopic.php?t=92711#p463429

You need to change your queue type settings from from only-hardware-queue to default-ethernet. That will do the trick, good luck

Alex
by alexvdbaan
Tue Mar 01, 2016 12:07 pm
Forum: General
Topic: Setup VyprVPN L2TP\IPSEC client with certificate
Replies: 3
Views: 2243

Setup VyprVPN L2TP\IPSEC client with certificate

Goodmorning everyone, I recently setup VyprVPN with my mikrotik device to function as upstream VPN tunnel for added privacy online. Currently I have the setup working with PPTP, this is unsecure so I would prefer to move to L2TP\IPSEC. VyperVPN supports this with their own certificate. So after I co...
by alexvdbaan
Thu Feb 04, 2016 11:44 pm
Forum: Wireless Networking
Topic: Missing frequency width options in capsman
Replies: 0
Views: 439

Missing frequency width options in capsman

Hi Guys, I recently purchased 2 hap ac lites for my home network and I am very happy with the results. Now I wanted to connect them to my Capsman setup but I noticed that certain options are missing in capsman. Currently I configured my ap's with the following parameters: 5Ghz-ac-only Frequency 5500...
by alexvdbaan
Fri Apr 10, 2015 9:39 am
Forum: General
Topic: NAT Routing, PrivateInternetAccess & PPTP VPN - Router OS v6.27
Replies: 14
Views: 5669

Re: NAT Routing, PrivateInternetAccess & PPTP VPN - Router OS v6.27

Hi whitie, Thanks for your rule suggestion, it does seem to work when I enable my address list rule back for my device. However sites like adobe.com and a Dutch one at5.nl still wont work. I will try and test with another PIA country configured. Also see if it makes a difference if I use the PIA app...
by alexvdbaan
Fri Apr 10, 2015 12:45 am
Forum: General
Topic: NAT Routing, PrivateInternetAccess & PPTP VPN - Router OS v6.27
Replies: 14
Views: 5669

Re: NAT Routing, PrivateInternetAccess & PPTP VPN - Router OS v6.27

Hi guys, Thanks for your work in this thread. I managed to get the NAT rules and my Private Internet VPn setup. However I have been noticing that some sites have been responsive and others simply wont reply any more. I have read online and on this forum to see what this could be. What would be a goo...
by alexvdbaan
Fri Apr 03, 2015 12:40 am
Forum: General
Topic: NAT Routing, PrivateInternetAccess & PPTP VPN - Router OS v6.27
Replies: 14
Views: 5669

Re: NAT Routing, PrivateInternetAccess & PPTP VPN - Router OS v6.27

Hi withie, I am experiencing exactly the same issue on my CRS125 with PIA using L2TP/IPSEC. I have used this tutorial https://www.youtube.com/watch?v=aIUTfiGkmzk to set everything up. I have tried the suggestion to add my public IP to a new address list. But that didnt work unfortunately. 2015-04-02...
by alexvdbaan
Thu Apr 02, 2015 4:40 pm
Forum: General
Topic: Centrally manage address list for multiple devices
Replies: 7
Views: 1311

Re:

You can also implement port knocking in case the automation fails for any reason.
Thanks jarda, This can be a very interesting fall-back. Do you have experience with this technique?
by alexvdbaan
Thu Apr 02, 2015 4:39 pm
Forum: General
Topic: Centrally manage address list for multiple devices
Replies: 7
Views: 1311

Re: Centrally manage address list for multiple devices

If you put the list on a well-known password-protected ssl-protected URL and use fetch to pull that to flash, then use the contents to generate the address list..
ZeroByte, thanks. I will give this a try.
by alexvdbaan
Thu Apr 02, 2015 4:13 pm
Forum: General
Topic: Very bad Speedtest.net results through Mikrotik equipment
Replies: 15
Views: 3233

Re: Very bad Speedtest.net results through Mikrotik equipment

Hi There,

I had the exact same issue on UPC and my CRS125. problem was solved by changing the queue type from hardware-only to default-ethernet. Works like a charm.

See: http://forum.mikrotik.com/viewtopic.php?f=3&t=94296

Gr Alex
by alexvdbaan
Thu Apr 02, 2015 12:37 am
Forum: General
Topic: Centrally manage address list for multiple devices
Replies: 7
Views: 1311

Centrally manage address list for multiple devices

Goodevening everyone, I work for an IT company in Amsterdam, we manage over 200 mikrotik firewall at our clients premises. I am currently busy with an ISP/IP address migration for roughly most of our clients. During the migration we are also looking at the device health (primarily RB450(G)'s), filte...
by alexvdbaan
Tue Mar 10, 2015 10:57 pm
Forum: RouterBOARD hardware
Topic: Lower ISP speeds after swapping 450G to CRS125-24G
Replies: 10
Views: 6222

Re: Lower ISP speeds after swapping 450G to CRS125-24G

Hi Quindor,

thank you for that suggestion, this solved my issue! I changed this setting on all my ports and it worked perfectly.

thanks for your help on this point

Alex
by alexvdbaan
Fri Feb 27, 2015 11:05 pm
Forum: RouterBOARD hardware
Topic: Lower ISP speeds after swapping 450G to CRS125-24G
Replies: 10
Views: 6222

Re: Lower ISP speeds after swapping 450G to CRS125-24G

HI Quindor, I changed my cable and testes again, I found that I didnt get higher than 35Mbit. I booted my 450G up and connected my modem, speedtest immediatly gave me the full 121Mb and 12Mb down and up. This would rule out my modem I would say. Perhaps I have a faulty ether-1 port, that I could tes...
by alexvdbaan
Tue Feb 24, 2015 7:06 pm
Forum: RouterBOARD hardware
Topic: Lower ISP speeds after swapping 450G to CRS125-24G
Replies: 10
Views: 6222

Re: Lower ISP speeds after swapping 450G to CRS125-24G

Hi Quindor, Thanks for your reply. Of course I can quickly swap a cable and I will definitely check out iperf so see my performance on the CRS125. However my feeling is that there is some other issue here. The cable has functioned over the last year and I do receive my normal connection speeds when ...
by alexvdbaan
Sun Feb 22, 2015 1:57 pm
Forum: RouterBOARD hardware
Topic: Lower ISP speeds after swapping 450G to CRS125-24G
Replies: 10
Views: 6222

Lower ISP speeds after swapping 450G to CRS125-24G

Hi everybody, I switched from a 450G to a CRS125, I experienced a massive drop in available bandwitch (normally 120Mb, now 30Mb) from my ISP (UPC, in the netherlands). I built the config up from scratch, I have added both configurations with this post. Can any one of you tell me if there is some har...