Community discussions

Search found 176 matches

by Pea
Sat Mar 02, 2019 9:53 am
Forum: Announcements
Topic: v6.44 [stable] is released!
Replies: 219
Views: 26286

Re: v6.44 [stable] is released!

This is not a bug, it tells you that you must install DHCP package now, read carefully the change list:
*) upgrade - made security package depend on DHCP package
by Pea
Thu Feb 28, 2019 8:11 pm
Forum: Beginner Basics
Topic: Best Practice -> Wireless Bridge and AP
Replies: 1
Views: 187

Re: Best Practice -> Wireless Bridge and AP

I do not know if this is the best, but it is reliable and simple wireless connection with Mikrotik on both ends: On your Mikrotik AP_01: /interface wireless set mode=ap-bridge ssid=YOUR-SSID wds-default-bridge=bridge-local wds-mode=static-mesh /interface wireless wds add disabled=no master-interface...
by Pea
Tue Feb 26, 2019 10:18 pm
Forum: Announcements
Topic: v6.44 [stable] is released!
Replies: 219
Views: 26286

Re: v6.44 [stable] is released!

*) capsman - always accept connections from loopback address; Hi, I tested but I still need input firewall rule to accept router IP to get working CAP on the same board as CAPsMAN: /ip firewall filter add action=accept chain=input protocol=udp dst-address="router IP" src-address="router IP" /caps-ma...
by Pea
Sun Feb 24, 2019 10:01 am
Forum: General
Topic: Hotspot Apple Login Page HELP!
Replies: 19
Views: 1016

Re: Hotspot Apple Login Page HELP!

We're in 2019 and mobile operators sell 50GB/month for 5€, who needs hotspots anymore?
And which mobile operators? :)
Czech Vodafone 50GB for about 97€/month
by Pea
Fri Feb 22, 2019 10:13 pm
Forum: Beginner Basics
Topic: Having no luck connecting MacBooks to the APs
Replies: 1
Views: 129

Re: Having no luck connecting MacBooks to the APs

1) Do not use space in SSID, do "ScottsTest" or "Scotts-Test" (iOS devices had problem with space in SSID, this could be the case) 2) try band=5ghz- a/n/ac 3) try authentication-types=wpa 2 -psk and mode=dynamic-keys 4) try preamble-mode= both or reset wireless to default and then connect and only t...
by Pea
Tue Feb 19, 2019 8:06 am
Forum: General
Topic: Public IP Address Blacklisted
Replies: 4
Views: 292

Re: Public IP Address Blacklisted

1) update RouterOS
2) your firewall is open and wrong on input chain
3) rework your firewall in style: accept only needed, drop all else

Or do "/ip firewall export" or better "/export hide-sensitive" and post here for advises (screenshot is not sufficient)
by Pea
Mon Feb 18, 2019 9:46 pm
Forum: Wireless Networking
Topic: CAPsMAN and different protocol networks [SOLVED]
Replies: 4
Views: 411

Re: CAPsMAN and different protocol networks [SOLVED]

1) The Band/Frequency will be different in both configurations 2) The Hw. Supported Modes (you can use gn for 2.4GHz or ac for 5GHz) and Master Configuration will be different in both provisionings Based on those provisioning rules will CAPsMAN send correct configuration to CAP interface. Example: /...
by Pea
Mon Feb 18, 2019 12:59 am
Forum: Wireless Networking
Topic: CAPsMAN and different protocol networks [SOLVED]
Replies: 4
Views: 411

Re: CAPsMAN and different protocol networks [SOLVED]

Make 2 configurations (2.4 and 5GHz) for 2 provisioning rules with different hw-supported-modes=
by Pea
Sun Feb 17, 2019 1:32 pm
Forum: Wireless Networking
Topic: Activate WPS on hAC
Replies: 6
Views: 290

Re: Activate WPS on hAC

Push-button WPS seems secure, but the vulnerability being that anyone with physical access to the AP could push the button and connect, even if they didn't know the Wi-Fi pass.
by Pea
Sat Feb 16, 2019 9:43 pm
Forum: Wireless Networking
Topic: Activate WPS on hAC
Replies: 6
Views: 290

Re: Activate WPS on hAC

You need to define which interface to set:
/interface wireless set wlan1 wps-mode=push-button
Recommendation: Do not use insecure WPS and keep it disabled.
by Pea
Sat Feb 16, 2019 1:49 pm
Forum: Beginner Basics
Topic: Finding a firewalled connection [SOLVED]
Replies: 4
Views: 325

Re: Finding a firewalled connection [SOLVED]

For home use with public IP you normally get few thousands hits per month.
Try instead of your final drop rule use this reject rule and see if hits get reduced after time:
add action=reject chain=input reject-with=icmp-admin-prohibited
by Pea
Sat Feb 16, 2019 9:46 am
Forum: Beginner Basics
Topic: Where can I download Winbox 3.12
Replies: 2
Views: 270

Re: Where can I download Winbox 3.12

Always use latest version, only for specific needs:
https://download.mikrotik.com/routeros/ ... winbox.exe
by Pea
Fri Feb 15, 2019 12:58 am
Forum: Beginner Basics
Topic: hAPlite bridge to CAPsMAN wirelessly?
Replies: 4
Views: 272

Re: hAPlite bridge to CAPsMAN wirelessly?

I never had roaming station on WDS link.
But I guess it should be possible to set AP with wds-mode=dynamic-mesh which allows WDS links with devices (mode=station-wds) by creating required entries dynamically.
by Pea
Wed Feb 13, 2019 12:06 am
Forum: Wireless Networking
Topic: Country settings for Japan
Replies: 2
Views: 173

Re: Country settings for Japan

Maybe this helps:
/interface wireless info country-info japan
by Pea
Tue Feb 12, 2019 12:34 am
Forum: Beginner Basics
Topic: hAPlite bridge to CAPsMAN wirelessly?
Replies: 4
Views: 272

Re: hAPlite bridge to CAPsMAN wirelessly?

Connect your hAPlite by WDS to your router. Then all should work the same as cable connection.
by Pea
Thu Feb 07, 2019 10:44 pm
Forum: Beginner Basics
Topic: Different DNS to different Mac addresses
Replies: 3
Views: 202

Re: Different DNS to different Mac addresses

/ip dhcp-server lease add address=10.0.0.1 mac-address=XX:XX:XX:XX:XX:XX ... /ip firewall address-list add address=10.0.0.1 list="my known devices" ... /ip firewall nat add action=dst-nat chain=dstnat dst-port=53 protocol=udp src-address-list="my known devices" to-addresses=1.1.1.1 add action=dst-n...
by Pea
Thu Feb 07, 2019 10:35 pm
Forum: RouterBOARD hardware
Topic: New routerboot firmware
Replies: 12
Views: 1038

Re: New routerboot firmware

Yes, these are 2 different things:
1) RouterOS update - go to "System/Packages" menu, click on "Check for Updates"
2) Firmware (bootloader) upgrade - go to "System/Routerboard" menu and click "Upgrade"
The version number of Router OS and Firmware is synchronised now.
by Pea
Wed Feb 06, 2019 8:21 am
Forum: General
Topic: [RB951G-2HnD] 300Mbps Internet bottleneck
Replies: 6
Views: 578

Re: [RB951G-2HnD] 300Mbps Internet bottleneck

1. Do not open SSH and Winbox to wild internet (use e.g. address list, VPN, port knock)
2. Use Fast track for better throughput https://wiki.mikrotik.com/wiki/Manual:IP/Fasttrack
3. Consider router upgrade
by Pea
Sun Feb 03, 2019 9:56 am
Forum: General
Topic: Performance of Mikrotik 951G-2HnD
Replies: 10
Views: 537

Re: Performance of Mikrotik 951G-2HnD

*) All tests are done with Xena Networks specialized test equipment (XenaBay),and done according to RFC2544 (Xena2544) Max throughput is determined with 30+ second attempts with 0,1% packet loss tolerance in 64, 512, 1518 byte packet sizes Test results show device maximum performance, and are reache...
by Pea
Sun Feb 03, 2019 9:40 am
Forum: RouterBOARD hardware
Topic: For real, what is with these blinding power leds?
Replies: 11
Views: 949

Re: For real, what is with these blinding power leds?

Black tape is your friend to reduce LED brightness of whatever anytime :D
by Pea
Sat Feb 02, 2019 10:07 pm
Forum: General
Topic: Performance of Mikrotik 951G-2HnD
Replies: 10
Views: 537

Re: Performance of Mikrotik 951G-2HnD

Maybe Fasttrack rule missing in your firewall?
https://wiki.mikrotik.com/wiki/Manual:IP/Fasttrack
/ip firewall filter add chain=forward action=fasttrack-connection connection-state=established,related
/ip firewall filter add chain=forward action=accept connection-state=established,related
by Pea
Sat Feb 02, 2019 9:18 pm
Forum: RouterBOARD hardware
Topic: New routerboot firmware
Replies: 12
Views: 1038

Re: New routerboot firmware

Your firmware is already upgraded. Move on.
by Pea
Sat Feb 02, 2019 8:40 pm
Forum: Beginner Basics
Topic: Wireless station - bridge - to lan not working [SOLVED]
Replies: 10
Views: 541

Re: Wireless station - bridge - to lan not working [SOLVED]

Did you change this?
You need to use Station pseudo bridge
by Pea
Sat Feb 02, 2019 7:56 pm
Forum: RouterBOARD hardware
Topic: New routerboot firmware
Replies: 12
Views: 1038

Re: New routerboot firmware

Factory Firmware is what was originally loaded at factory. You can ignore this. Installed version is under Current Firmware.
by Pea
Sat Feb 02, 2019 4:29 pm
Forum: Wireless Networking
Topic: wireless network with authentication of user+password [SOLVED]
Replies: 5
Views: 409

Re: wireless network with authentication of user+password [SOLVED]

IMHO it's not illegal to change a MAC address.
It's only illegal to change a MAC address to do something illegal.
by Pea
Sat Feb 02, 2019 3:10 pm
Forum: General
Topic: How to set different wireless channels on router used as extender?
Replies: 3
Views: 287

Re: How to set different wireless channels on router used as extender?

Both options are possible, but this is my point of view: 2.4GHz indoor PtP: will reach longer distance and through more obstacles, only one 2.4GHz channel occupied by the link 5GHz indoor PtP: better throughput, but on longer distance or more walls weak signal, two 2.4GHz channels occupied by APs fo...
by Pea
Sat Feb 02, 2019 2:27 pm
Forum: Wireless Networking
Topic: CAPsMAN not adding dynamically interfaces to bridge
Replies: 4
Views: 224

Re: CAPsMAN not adding dynamically interfaces to bridge

local-forwarding=no => the interface is part of bridge on the CAPsMAN, the interface shows as disabled on CAP
local-forwarding=yes => the interface stays as part of bridge on the CAP
by Pea
Sat Feb 02, 2019 2:21 pm
Forum: Wireless Networking
Topic: wireless network with authentication of user+password [SOLVED]
Replies: 5
Views: 409

Re: wireless network with authentication of user+password [SOLVED]

First connect by laptop and login with username and password.
Then change your Mikrotik wlan1 MAC to your laptop MAC.
And then try to connect your Mikrotik as client to the wifi network.
by Pea
Sat Feb 02, 2019 2:15 pm
Forum: General
Topic: How to set different wireless channels on router used as extender?
Replies: 3
Views: 287

Re: How to set different wireless channels on router used as extender?

For best performance I recommend to connect both by Ethernet cable if somehow possible.
Or upgrade to dual band routers and use 2.4GHz only to connect both wirelessly and use the 5GHz for wifi sharing.
by Pea
Fri Feb 01, 2019 12:17 am
Forum: General
Topic: DNS Flag Day
Replies: 2
Views: 327

Re: DNS Flag Day

Did you read the website briefly?
There is no reason to worry if you are an Internet user without your own domain name. This change is affecting you only indirectly and you do not need to take any other steps.
by Pea
Thu Jan 31, 2019 8:57 pm
Forum: Wireless Networking
Topic: CAPsMAN and multiSSID
Replies: 1
Views: 248

Re: CAPsMAN and multiSSID

Try this:
  • Create a new configuration for the VirtualAP
  • Specify the new configuration in Provisioning rule as Slave configuration
  • Remove all CAP interfaces
  • Initiate Manual Provisioning on all the CAPs
by Pea
Thu Jan 31, 2019 8:42 pm
Forum: Wireless Networking
Topic: High ping to router HAP AC2
Replies: 33
Views: 1602

Re: High ping to router HAP AC2

Did you try to reset to factory default and test? What was the result?
You are connected via 2.4GHz or 5GHz?
Did you try to change channel?
by Pea
Wed Jan 30, 2019 12:03 am
Forum: Beginner Basics
Topic: How to connect remote device into the LAN over WiFi? [SOLVED]
Replies: 7
Views: 349

Re: How to connect remote device into the LAN over WiFi? [SOLVED]

Remote device keep on auto, it will act as client and take frequency from AP. If you do not have any 802.11b only device (and you probably don't) try this: /interface wireless set band=2ghz-g/n channel-width=20mhz bridge-mode=disabled country="your country" distance=indoors frequency-mode=regulatory...
by Pea
Tue Jan 29, 2019 12:45 am
Forum: Beginner Basics
Topic: How to connect remote device into the LAN over WiFi? [SOLVED]
Replies: 7
Views: 349

Re: How to connect remote device into the LAN over WiFi? [SOLVED]

Sure, WPA2-PSK as security profile and optionally disable PMKID. Simplified description: Run your secured WiFi normally on your router, add settings for WDS, add static WDS interface with MAC of second device. On other device start without any setup. Add bridge and DHCP client on bridge. Add securit...
by Pea
Mon Jan 28, 2019 9:44 pm
Forum: Beginner Basics
Topic: How to connect remote device into the LAN over WiFi? [SOLVED]
Replies: 7
Views: 349

Re: How to connect remote device into the LAN over WiFi? [SOLVED]

You can use your wlan1 as WAN port and wireless mode station-pseudobridge on remote Mikrotik. Do not forget to synchronise time of remote device. Or below is what I use reliably with Mikrotik on both ends: On your Mikrotik router /interface wireless set mode=ap-bridge ssid=YOUR-SSID wds-default-brid...
by Pea
Sun Jan 27, 2019 10:45 pm
Forum: Announcements
Topic: v6.43.8 [stable] is released!
Replies: 169
Views: 28098

Re: v6.43.8 [stable] is released!

Use manually non DSF channel (5200, 5220 or 5240). Problem solved.
by Pea
Sat Jan 26, 2019 11:26 pm
Forum: Beginner Basics
Topic: Capsman and his own CAP issue
Replies: 1
Views: 166

Re: Capsman and his own CAP issue

You can try latest ROS beta which likely do not need below workaround anymore (I did not test this yet): *) capsman - always accept connections from loopback address; Otherwise this should fix it: /capsman manager interface set [find default=yes] forbid=no add forbid=yes interface=(here put interfac...
by Pea
Fri Jan 25, 2019 8:39 am
Forum: Wireless Networking
Topic: Does locking to CAPsMan leave the rest of the router alone? [SOLVED]
Replies: 2
Views: 190

Re: Does locking to CAPsMan leave the rest of the router alone? [SOLVED]

The CAPsMAN takes care about wifi1 and/or wifi2 interfaces only. The rest of functionality and interfaces you can use and configure as you like.
by Pea
Tue Jan 22, 2019 12:18 am
Forum: Wireless Networking
Topic: CAPsMAN - How to force layer 2?
Replies: 11
Views: 3158

Re: CAPsMAN - How to force layer 2?

3) The worst: this is not documented anywhere besides user forums (it should be on CAPsMan manual to prevent people be fighting hours with something that isn´t going to work) https://wiki.mikrotik.com/wiki/Manual:Simple_CAPsMAN_setup#CAP_in_CAPsMAN But I agree that having firewall rule for CAP on C...
by Pea
Sun Jan 20, 2019 2:30 pm
Forum: Wireless Networking
Topic: android devices chooses 2.4Ghz over 5Ghz on hAP ac^2
Replies: 13
Views: 731

Re: android devices chooses 2.4Ghz over 5Ghz on hAP ac^2

forgot to mention that this is one room condition - both phones, laptop and router are in one room max 3m away.
Ideal situation. Why you even use 2.4GHz? Stay with 5GHz only and problem solved.
by Pea
Sun Jan 20, 2019 9:57 am
Forum: General
Topic: Log in to router
Replies: 1
Views: 119

Re: Log in to router

This depends on your firewall rules. By default this is filtered.
by Pea
Fri Jan 18, 2019 4:58 pm
Forum: Wireless Networking
Topic: android devices chooses 2.4Ghz over 5Ghz on hAP ac^2
Replies: 13
Views: 731

Re: android devices chooses 2.4Ghz over 5Ghz on hAP ac^2

Other option would be to setup different SSID for 5GHz. And never connect phone to your 2.4GHz :)
by Pea
Wed Jan 16, 2019 12:42 am
Forum: Beginner Basics
Topic: Recommended DNS Approach.
Replies: 4
Views: 278

Re: Recommended DNS Approach.

redirect - replaces destination port of an IP packet to one specified by to-ports parameter and destination address to one of the router's local addresses
by Pea
Mon Jan 14, 2019 9:30 pm
Forum: Wireless Networking
Topic: CAPsMAN issue's
Replies: 9
Views: 584

Re: CAPsMAN issue's

The 802.11n prohibits using high throughput with WEP or TKIP as the unicast cipher. If you use these encryption methods (for example, WEP, WPA-TKIP), your data rate will drop to 54 Mbps.
Use only WPA2-AES for full 802.11n speed.
by Pea
Fri Jan 11, 2019 2:10 pm
Forum: RouterBOARD hardware
Topic: hap lite not enough space for update [SOLVED]
Replies: 16
Views: 1299

Re: hap lite not enough space for update [SOLVED]

For standard home use you can remove safely all files and folders from File List
(flash folder cannot be removed but all sub folders yes)
by Pea
Thu Jan 10, 2019 7:40 pm
Forum: Wireless Networking
Topic: High ping to router HAP AC2
Replies: 33
Views: 1602

Re: High ping to router HAP AC2

There should be <1ms for ping even over wifi. What are you getting?
by Pea
Thu Jan 10, 2019 7:33 pm
Forum: RouterBOARD hardware
Topic: hap lite not enough space for update [SOLVED]
Replies: 16
Views: 1299

Re: hap lite not enough space for update [SOLVED]

try to reboot first to clean some memory...