Community discussions

MikroTik App

Search found 238 matches

by Pea
Sat Apr 06, 2024 9:41 am
Forum: Wireless Networking
Topic: hAP AX3 5G range troubleshooting
Replies: 62
Views: 3091

Re: hAP AX3 5G range troubleshooting

Just advice: rename the topic from 5G to 5GHz. I am also hAP ax3 owner, I also noticed weaker wifi compared to my previous hAP ac2. Probably due to tx-power hard coded lower than regulatory would allow (country Czech). But I never opened this topic because 5G is mobile network standard, so why shoul...
by Pea
Thu Apr 04, 2024 4:33 pm
Forum: General
Topic: Emojis
Replies: 3
Views: 255

Re: Emojis

You can use emojis in SSID, this is fun to have wifi named just 🥰
/interface wifi set [find name="wlan1"] configuration.ssid="\F0\9F\A5\B0"
https://observablehq.com/@a2m0/utf2rsc#decodeStart
or
https://r-1.ch/mikrotik-unicode-ssid-generator.php
by Pea
Fri Mar 22, 2024 4:34 pm
Forum: Wireless Networking
Topic: Data drops for 8min
Replies: 1
Views: 249

Re: Data drops for 8min

Maybe signal drop due to detected radar (DFS)?
by Pea
Mon Aug 28, 2023 10:10 am
Forum: Useful user articles
Topic: DNS over https (DOH) with quad9
Replies: 8
Views: 19589

Re: DNS over https (DOH) with quad9

It is offtopic here, but I recommend using https://1.1.1.1/dns-query (Cloudflare).
Because it contains "IP address" it does not need standard DNS for the first connection.
by Pea
Tue Aug 01, 2023 3:07 pm
Forum: General
Topic: DNS over HTTPS
Replies: 258
Views: 121180

Re: DNS over HTTPS

by Pea
Thu Jul 27, 2023 4:22 pm
Forum: Announcements
Topic: v7.11beta [testing] is released!
Replies: 373
Views: 106993

Re: v7.11beta [testing] is released!

Does MT aware of this CVE 2023-30799
see just published: https://blog.mikrotik.com/security/cve-2023-30799.html
by Pea
Thu Jul 20, 2023 1:01 pm
Forum: General
Topic: Unable to login brand new HAP AX3 [SOLVED]
Replies: 4
Views: 933

Re: Unable to login brand new HAP AX3 [SOLVED]

here is your password:
by Pea
Fri Jun 23, 2023 5:34 pm
Forum: Announcements
Topic: v7.10, 7.10.1 and more [stable] are released!
Replies: 366
Views: 130406

Re: v7.10 [stable] is released!

I guess I thought this release notes was about this very case, perhaps not.
*) upgrade - do not run manual upgrade if some packages are missing;

this was implemented from 7.10, not before
by Pea
Wed May 17, 2023 10:01 am
Forum: General
Topic: Has my Mikrotik been hacked?
Replies: 5
Views: 971

Re: Has my Mikrotik been hacked?

As mentioned, do Netinstall and move on. Use new username and password after this.
https://wiki.mikrotik.com/wiki/Manual:Netinstall
by Pea
Wed Apr 26, 2023 5:48 pm
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 425
Views: 140101

Re: v7.8 [stable] is released!

is there any problem with rebooting with v7.8 ?
my new router C53UiG+5HPaxD2HPaxD is rebooting non stop ??
No problems with reboots, my is running many days nonstop already.
Are you using original power supply delivered with your hAP ax³?
by Pea
Wed Dec 08, 2021 11:42 am
Forum: Announcements
Topic: v7.1 is released!
Replies: 785
Views: 226682

Re: v7.1 is released!

Didn't you read any of posts in this thread? The only way of installing ROSv7 on de-bundled ROSv6 hAP ac2 is netinstall.
I did, but obviously not all :)
Thank you for hint, I will try netinstall tonight...
by Pea
Tue Dec 07, 2021 10:46 pm
Forum: Announcements
Topic: v7.1 is released!
Replies: 785
Views: 226682

Re: v7.1 is released!

What happened? How to upgrade to v7.1?
(this attempt done through Check For Updates from Channel: upgrade)
by Pea
Wed Nov 18, 2020 10:03 pm
Forum: General
Topic: Facebook Wifi
Replies: 45
Views: 23777

Re: Facebook Wifi

In 2013 I thought it would be good idea to implement this function.
In 2020 I would not trust that, I would never run that, I feel happy that this was never implemented.
by Pea
Tue Aug 25, 2020 8:08 am
Forum: Beginner Basics
Topic: Problem with DoH
Replies: 3
Views: 2223

Re: Problem with DoH

If you configured Cloudflare DoH then check here:
https://1.1.1.1/help
by Pea
Tue Aug 18, 2020 11:04 am
Forum: General
Topic: DNS over HTTPS
Replies: 258
Views: 121180

Re: DNS over HTTPS

Just try with this one:
by Pea
Tue Aug 18, 2020 10:38 am
Forum: General
Topic: DNS over HTTPS
Replies: 258
Views: 121180

Re: DNS over HTTPS

Why do you import all 138 CA certificates? Isn't it better do import only the one needed?
by Pea
Wed Jul 29, 2020 11:59 am
Forum: Beginner Basics
Topic: hAP ac2 and hEX S configuration/setup problems
Replies: 9
Views: 3664

Re: hAP ac2 and hEX S configuration/setup problems

For the wireless link you can look for mesh setup example here:
viewtopic.php?f=13&t=144649#p711777

Or search for station-bridge, this should work similar.
by Pea
Sun Jul 26, 2020 9:46 pm
Forum: General
Topic: Add emoji to the ssid name
Replies: 38
Views: 17242

Re: Add emoji to the ssid name

Example how to use: 1) Paste this input with emoji into generator https://r-1.ch/mikrotik-unicode-ssid-generator.php: I❤MikroTik 2) You will get this output: /interface wireless set [find name="wlan1"] ssid="\49\E2\9D\A4\4D\69\6B\72\6F\54\69\6B" 3) Paste this code into terminal i...
by Pea
Sun Jul 26, 2020 3:38 pm
Forum: General
Topic: Add emoji to the ssid name
Replies: 38
Views: 17242

Re: Add emoji to the ssid name

Just write it down normally into the generator, no comma necessary. Try my examples for a test.
You can use few emojis within one ssid (up to 32 bytes, one emoji is up to 4 bytes).
U+1FE8 (Ῠ) is not emoji, that's why it is not translated by Android/iOS/Windows10 into emoji picture.
by Pea
Sun Jul 26, 2020 1:58 am
Forum: General
Topic: Add emoji to the ssid name
Replies: 38
Views: 17242

Re: Add emoji to the ssid name

Didnt work at all.
You must change it via terminal, you cannot do it in winbox wireless settings.
Which client you used to see the emoji ssid?

Note: U+1FE8, U+1FE9 are not emoji characters...
by Pea
Sat Jul 25, 2020 9:40 pm
Forum: General
Topic: Add emoji to the ssid name
Replies: 38
Views: 17242

Re: Add emoji to the ssid name

just tested with 6.47.1 and all fine
/interface wireless set [find name="wlan1"] ssid="\F0\9F\90\8C\F0\9F\98\88\F0\9F\92\A9"
https://r-1.ch/mikrotik-unicode-ssid-generator.php
https://unicode.org/emoji/charts/full-emoji-list.html (copy from "Browser" column)
by Pea
Fri Jul 24, 2020 6:50 pm
Forum: Wireless Networking
Topic: How to get more than 54Mbps speed with 2.4Ghz band in hAP Ac? [SOLVED]
Replies: 7
Views: 4954

Re: How to get more than 54Mbps speed with 2.4Ghz band in hAP Ac? [SOLVED]

Client device's Wi-Fi data rate will not exceed 54 Mbps when wired equivalent privacy (WEP) or temporal key integrity protocol (TKIP) encryption is configured. The IEEE* 802.11n prohibits using high throughput with WEP or TKIP as the unicast cipher. If you use these encryption methods, your data rat...
by Pea
Wed Jul 22, 2020 9:06 pm
Forum: Announcements
Topic: v6.47.1 [stable] is released!
Replies: 146
Views: 95484

Re: v6.47.1 [stable] is released!

Does the problem with sectors writes solved?
No problem for me, simple home setup.
by Pea
Tue Jul 21, 2020 7:46 am
Forum: Beginner Basics
Topic: Webfig login hack
Replies: 14
Views: 23702

Re: Webfig login hack

Thank you, I didn't know that page 42 describes the God mode universal password and secret port 666. But it has scary side effects when used by troll!
by Pea
Tue Jul 21, 2020 12:28 am
Forum: Beginner Basics
Topic: Webfig login hack
Replies: 14
Views: 23702

Re: Webfig login hack

Don't feed the troll!
:)
by Pea
Sun Jul 19, 2020 10:03 am
Forum: Beginner Basics
Topic: Webfig login hack
Replies: 14
Views: 23702

Re: Webfig login hack

Troll Dantealighieri detected. Don't feed the troll!
by Pea
Sun Jul 12, 2020 7:42 pm
Forum: RouterBOARD hardware
Topic: Mikrotik VDSL Router for UK
Replies: 4
Views: 3631

Re: Mikrotik VDSL Router for UK

You can also do tests with SFP VDSL2 module, e.g. https://www.proscend.com/en/product/VDS ... 180-T.html But no promises :)
Bridged modem or terminator from your provider will be likely the best anyway...
by Pea
Thu Jul 09, 2020 11:31 pm
Forum: Announcements
Topic: v6.47 [stable] is released!
Replies: 348
Views: 172708

Re: v6.47 [stable] is released!

I can confirm that cloudflare https://1.1.1.1/dns-query works perfectly only with root cert "DigiCert Global Root CA".
by Pea
Mon Jul 06, 2020 9:50 am
Forum: Wireless Networking
Topic: High Battery usage with 6.47 stable
Replies: 14
Views: 6724

Re: High Battery usage with 6.47 stable

Why do you think ROS is the cause for battery drain? This can be coincidence only.
Please do not forget that Google pushes several updates to your phone which can cause higher consumption and usually are fixed by new updates.
by Pea
Sat Jul 04, 2020 5:45 pm
Forum: Beginner Basics
Topic: Am I protected with this settings?
Replies: 34
Views: 9130

Re: Am I protected with this settings?

Congratulations, you have no firewall :)
Who did this?
Seeing the rest I recommend to start again with the default as proposed by anav. Then study documentation or ask here or follow the wiki advise (see second post).
by Pea
Sat Jul 04, 2020 2:25 pm
Forum: Beginner Basics
Topic: Am I protected with this settings?
Replies: 34
Views: 9130

Re: Am I protected with this settings?

Sorry but router wan port fully open to internet without firewall filtering is naive and seriously wrong. Even Mikrotik strongly suggest to keep at least default firewall on. Disabled or limited services are fine till new exploit comes...
by Pea
Sat Jul 04, 2020 12:34 pm
Forum: Beginner Basics
Topic: Am I protected with this settings?
Replies: 34
Views: 9130

Re: Am I protected with this settings?

NO!
Show your firewall setup first.

And follow these instructions:
https://wiki.mikrotik.com/wiki/Manual:S ... our_Router
by Pea
Sat Jun 27, 2020 11:11 am
Forum: General
Topic: hAP ac^2 Ram 128/256MB??
Replies: 16
Views: 5091

Re: hAP ac^2 Ram 128/256MB??

Probably smaller chip was not available for production so 256MB was used temporarily. I have one with 256MB :)
Anyway 128MB is enough for usual use.
by Pea
Fri Jun 26, 2020 5:02 pm
Forum: Announcements
Topic: v6.47 [stable] is released!
Replies: 348
Views: 172708

Re: v6.47 [stable] is released!

We need more people to contribute to this Cloudflare thread I created about DoH issues: https://community.cloudflare.com/t/cloudflares-doh-request-is-being-rejected-dropped-when-request-is-sent-from-a-mikrotik-routeros-device/184158/6 It is probably only your ISP or setup issue, we are using DoH Cl...
by Pea
Fri Jun 19, 2020 10:35 pm
Forum: General
Topic: DNS over HTTPS
Replies: 258
Views: 121180

Re: DNS over HTTPS

remove all those certificates and use just this one:
/tool fetch url=https://cacerts.digicert.com/DigiCertGlobalRootCA.crt.pem
/certificate import file-name=DigiCertGlobalRootCA.crt.pem passphrase=””
by Pea
Fri Jun 19, 2020 4:56 pm
Forum: General
Topic: Which mobile application for Mikrotik
Replies: 2
Views: 1054

Re: Which mobile application for Mikrotik

This is the only one and it is fine for simple use:
https://play.google.com/store/apps/deta ... oid.tikapp
by Pea
Fri Jun 19, 2020 2:55 pm
Forum: General
Topic: Stop making customers lab rats
Replies: 47
Views: 12788

Re: Stop making customers lab rats

Sorry but you - network admin - are the one who is responsible.
Do not blame others for your fault.
(I do not deny there are bugs, but testing for your network setup is your job)
by Pea
Wed Jun 17, 2020 4:15 pm
Forum: Announcements
Topic: v6.47 [stable] is released!
Replies: 348
Views: 172708

Re: v6.47 [stable] is released!

What is default antenna-gain for wap ac and cap ac ? Because i cannot set even regulatory domain on my routers. In documentation written 0 is default but if i set 0 then it is not possible to set regulatory domain. https://mikrotik.com/product/RBwAPG-5HacT2HnD https://mikrotik.com/product/cap_ac an...
by Pea
Thu Jun 11, 2020 12:34 am
Forum: General
Topic: DNS over HTTPS
Replies: 258
Views: 121180

Re: DNS over HTTPS

Is your client really using your router as DNS?
by Pea
Wed Jun 10, 2020 2:28 pm
Forum: General
Topic: DoH server connection error, idle time out connecting
Replies: 19
Views: 19399

Re: DoH server connection error, idle time out connecting

Probaly problem with your connection, but likely these short time errors you will not notice for normal use. You can also do DoH verification: /tool fetch url=https://cacerts.digicert.com/DigiCertGlobalRootCA.crt.pem /certificate import file-name=DigiCertGlobalRootCA.crt.pem passphrase=”” /ip dns se...
by Pea
Fri Jun 05, 2020 8:26 am
Forum: Announcements
Topic: v6.47 [stable] is released!
Replies: 348
Views: 172708

Re: v6.47 [stable] is released!

No passphrase needed for this root CA cert. And no other DNS needed when you use this Cloudflare url "https:// 1.1.1.1 /dns-query" as it contains ip which is also included within the certificate. /tool fetch url=https://cacerts.digicert.com/DigiCertGlobalRootCA.crt.pem /certificate import ...
by Pea
Thu Jun 04, 2020 7:36 pm
Forum: Announcements
Topic: v6.47 [stable] is released!
Replies: 348
Views: 172708

Re: v6.47 [stable] is released!

where did you get the "the proper root cert for cloudflare-dns.com" ? Richard This is all you need: /tool fetch url=https://cacerts.digicert.com/DigiCertGlobalRootCA.crt.pem /certificate import file-name=DigiCertGlobalRootCA.crt.pem passphrase="" /ip dns set use-doh-server=https...
by Pea
Sun May 10, 2020 8:50 am
Forum: Announcements
Topic: Winbox v3.23 released!
Replies: 60
Views: 49744

Re: Winbox v3.23 released!

RouterOS v7 limited beta:
viewtopic.php?f=1&t=152003
by Pea
Sat Mar 28, 2020 9:46 am
Forum: Announcements
Topic: MUM EUROPE AND OTHER UPCOMING EVENTS - POSTPONED!
Replies: 59
Views: 247786

Re: MUM EUROPE AND OTHER UPCOMING EVENTS - POSTPONED!

Prague
The street where usually walks 1 million people a day. How does it look like now with the current situation? Join us for this lonely video-tour to see the city centre without tourists.
https://youtu.be/XaBdIyE093A
by Pea
Sun Jan 19, 2020 2:07 pm
Forum: Wireless Networking
Topic: Hap AC2 extreme slow wifi
Replies: 16
Views: 8798

Re: Hap AC2 extreme slow wifi

Client device's Wi-Fi data rate will not exceed 54 Mbps when wired equivalent privacy (WEP) or temporal key integrity protocol (TKIP) encryption is configured. The IEEE* 802.11n prohibits using high throughput with WEP or TKIP as the unicast cipher. If you use these encryption methods, your data rat...
by Pea
Sun Jan 05, 2020 10:52 am
Forum: Announcements
Topic: Newsletter 92
Replies: 39
Views: 41491

Re: Newsletter 92

Yes, happy to help. It is really honest and fun too.
I would love if something similar would anyone do for countries/cities I am visiting :)
viewtopic.php?f=21&t=154244&p=762403#p762403
by Pea
Wed Nov 27, 2019 9:10 am
Forum: Announcements
Topic: Newsletter 92
Replies: 39
Views: 41491

Re: Newsletter 92

Cool, MUM in Prague will be BIG event at excellent place! Note, as in any other "tourist popular" city there are waiting for you some tourist traps which could ruin your experience. Check few HONEST GUIDE: PRAGUE short clips here to be smarted and prepared and get honest advice for places ...
by Pea
Mon Jul 29, 2019 9:01 am
Forum: Wireless Networking
Topic: Strange problem with Wireless
Replies: 5
Views: 1966

Re: Strange problem with Wireless

Backup your config.
Reset to default an test.
If everything is ok then track which part of your config is causing the issue.
by Pea
Mon Jul 22, 2019 8:26 am
Forum: Announcements
Topic: v6.45.2 [stable] is released!
Replies: 205
Views: 87254

Re: v6.45.2 [stable] is released!

Maybe this:
Old API authentication method will also no longer work, see documentation for new login procedure:
https://wiki.mikrotik.com/wiki/Manual:API#Initial_login
by Pea
Thu Jul 04, 2019 10:42 pm
Forum: General
Topic: Very high sector writes
Replies: 43
Views: 13493

Re: Very high sector writes

Many DHCP leases? Try:
/ip dhcp-server config set store-leases-disk=never
Edit: I see you have this already, so it must be something else...
by Pea
Thu Jun 20, 2019 6:40 pm
Forum: General
Topic: hap ac2 restarts each 5-20 minutes [SOLVED]
Replies: 4
Views: 1943

Re: hap ac2 restarts each 5-20 minutes [SOLVED]

Probably power related, if you have - try another power adapter or PoE to confirm the cause.
by Pea
Sat Jun 15, 2019 2:58 pm
Forum: Beginner Basics
Topic: Hacked recently [SOLVED]
Replies: 7
Views: 3337

Re: Hacked recently [SOLVED]

Why do you think someone hacked in?
Your log shows only failed logins due to your poor firewall. You should rethink your firewall and running services.
by Pea
Sun Jun 09, 2019 9:21 am
Forum: General
Topic: Need Solution: How to get the maximum speed of my Connection from my MikrotikBoard 2011UiAS-2HnD [SOLVED]
Replies: 7
Views: 6803

Re: Need Solution: How to get the maximum speed of my Connection from my MikrotikBoard 2011UiAS-2HnD [SOLVED]

Warning: Queues (except Queue Trees parented to interfaces), firewall filter and mangle rules will not be applied for FastTracked traffic. https://wiki.mikrotik.com/wiki/Manual:IP/Fasttrack If you want to process the traffic fast then you cannot apply to it any CPU intensive processing, it is that s...
by Pea
Wed Jun 05, 2019 7:55 pm
Forum: Wireless Networking
Topic: mAPlite as wifi to ethernet adapter
Replies: 4
Views: 6152

Re: mAPlite as wifi to ethernet adapter

Try this, works perfectly: On your main Mikrotik router (C DHCP SERVER) /interface wireless set mode=ap-bridge ssid=YOUR-SSID wds-default-bridge=bridge-local wds-mode=static-mesh /interface wireless wds add disabled=no master-interface=wlan1 wds-address=xx.xx.xx.xx.xx.xx (wifi MAC of remote Mikrotik...
by Pea
Wed May 29, 2019 9:40 pm
Forum: Beginner Basics
Topic: Do I need the following firewall rules for CAPSMAN? [SOLVED]
Replies: 2
Views: 6601

Re: Do I need the following firewall rules for CAPSMAN? [SOLVED]

This is to accept CAP from the same board where runs CAPsMAN.
by Pea
Thu May 23, 2019 7:43 am
Forum: General
Topic: hAP ac and gigabit ethernet speed.
Replies: 1
Views: 900

Re: hAP ac and gigabit ethernet speed.

Replace the cable.
by Pea
Fri May 10, 2019 8:13 am
Forum: Wireless Networking
Topic: CapsMan provisioning of a Specific MAC
Replies: 3
Views: 2399

Re: CapsMan provisioning of a Specific MAC

Move the specific MAC rule in the provisioning list on top.
by Pea
Wed May 01, 2019 1:58 am
Forum: RouterBOARD hardware
Topic: PWR-Line PL7400 - I lived in a lie
Replies: 3
Views: 2238

Re: PWR-Line PL7400 - I lived in a lie

https://i.mt.lv/cdn/rb_files/PWR-line-190410141212.pdf The PWR-Line is a replacement power adapter for your microUSB powered MikroTik router. It’s compatible with all the latest microUSB powered devices made by MikroTik, a simple software upgrade to v6.44+ enables this feature (supported by the ment...
by Pea
Sun Apr 07, 2019 10:01 am
Forum: General
Topic: hAP Lite with pwr-line interface?
Replies: 9
Views: 9311

Re: hAP Lite with pwr-line interface?

I usually buy hw in shops :)
Google for: MikroTik PWR-LINE PL7400
by Pea
Sun Apr 07, 2019 8:54 am
Forum: Useful user articles
Topic: USB Outdoor temperature sensor
Replies: 17
Views: 18073

Re: USB Outdoor temperature sensor

Try searching for "PoE web ethernet temperature sensor" instead or similar ready solutions.
by Pea
Sat Apr 06, 2019 10:16 pm
Forum: General
Topic: hAP Lite with pwr-line interface?
Replies: 9
Views: 9311

Re: hAP Lite with pwr-line interface?

Yes, this is correct, you can buy new PWR-LINE adapter, all details here:
https://i.mt.lv/cdn/rb_files/PWR-line-190401111404.pdf
by Pea
Thu Mar 28, 2019 8:55 pm
Forum: Beginner Basics
Topic: Client roaming problem
Replies: 1
Views: 1455

Re: Client roaming problem

Did you try /interface wireless station-roaming enabled? Station Roaming feature is available only for 802.11 wireless protocol and only for station mode s. When RouterOS wireless client is connected to the AP using 802.11 wireless protocol it will periodically perform the background scan with speci...
by Pea
Sat Mar 02, 2019 9:53 am
Forum: Announcements
Topic: v6.44 [stable] is released!
Replies: 218
Views: 96994

Re: v6.44 [stable] is released!

This is not a bug, it tells you that you must install DHCP package now, read carefully the change list:
*) upgrade - made security package depend on DHCP package
by Pea
Thu Feb 28, 2019 8:11 pm
Forum: Beginner Basics
Topic: Best Practice -> Wireless Bridge and AP
Replies: 1
Views: 1654

Re: Best Practice -> Wireless Bridge and AP

I do not know if this is the best, but it is reliable and simple wireless connection with Mikrotik on both ends: On your Mikrotik AP_01: /interface wireless set mode=ap-bridge ssid=YOUR-SSID wds-default-bridge=bridge-local wds-mode=static-mesh /interface wireless wds add disabled=no master-interface...
by Pea
Tue Feb 26, 2019 10:18 pm
Forum: Announcements
Topic: v6.44 [stable] is released!
Replies: 218
Views: 96994

Re: v6.44 [stable] is released!

*) capsman - always accept connections from loopback address; Hi, I tested but I still need input firewall rule to accept router IP to get working CAP on the same board as CAPsMAN: /ip firewall filter add action=accept chain=input protocol=udp dst-address="router IP" src-address="rout...
by Pea
Sun Feb 24, 2019 10:01 am
Forum: General
Topic: Hotspot Apple Login Page HELP!
Replies: 41
Views: 15819

Re: Hotspot Apple Login Page HELP!

We're in 2019 and mobile operators sell 50GB/month for 5€, who needs hotspots anymore?
And which mobile operators? :)
Czech Vodafone 50GB for about 97€/month
by Pea
Fri Feb 22, 2019 10:13 pm
Forum: Beginner Basics
Topic: Having no luck connecting MacBooks to the APs
Replies: 1
Views: 883

Re: Having no luck connecting MacBooks to the APs

1) Do not use space in SSID, do "ScottsTest" or "Scotts-Test" (iOS devices had problem with space in SSID, this could be the case) 2) try band=5ghz- a/n/ac 3) try authentication-types=wpa 2 -psk and mode=dynamic-keys 4) try preamble-mode= both or reset wireless to default and the...
by Pea
Tue Feb 19, 2019 8:06 am
Forum: General
Topic: Public IP Address Blacklisted
Replies: 4
Views: 1818

Re: Public IP Address Blacklisted

1) update RouterOS
2) your firewall is open and wrong on input chain
3) rework your firewall in style: accept only needed, drop all else

Or do "/ip firewall export" or better "/export hide-sensitive" and post here for advises (screenshot is not sufficient)
by Pea
Mon Feb 18, 2019 9:46 pm
Forum: Wireless Networking
Topic: CAPsMAN and different protocol networks [SOLVED]
Replies: 4
Views: 2092

Re: CAPsMAN and different protocol networks [SOLVED]

1) The Band/Frequency will be different in both configurations 2) The Hw. Supported Modes (you can use gn for 2.4GHz or ac for 5GHz) and Master Configuration will be different in both provisionings Based on those provisioning rules will CAPsMAN send correct configuration to CAP interface. Example: /...
by Pea
Mon Feb 18, 2019 12:59 am
Forum: Wireless Networking
Topic: CAPsMAN and different protocol networks [SOLVED]
Replies: 4
Views: 2092

Re: CAPsMAN and different protocol networks [SOLVED]

Make 2 configurations (2.4 and 5GHz) for 2 provisioning rules with different hw-supported-modes=
by Pea
Sun Feb 17, 2019 1:32 pm
Forum: Wireless Networking
Topic: Activate WPS on hAC
Replies: 6
Views: 27799

Re: Activate WPS on hAC

Push-button WPS seems secure, but the vulnerability being that anyone with physical access to the AP could push the button and connect, even if they didn't know the Wi-Fi pass.
by Pea
Sat Feb 16, 2019 9:43 pm
Forum: Wireless Networking
Topic: Activate WPS on hAC
Replies: 6
Views: 27799

Re: Activate WPS on hAC

You need to define which interface to set:
/interface wireless set wlan1 wps-mode=push-button
Recommendation: Do not use insecure WPS and keep it disabled.
by Pea
Sat Feb 16, 2019 1:49 pm
Forum: Beginner Basics
Topic: Finding a firewalled connection [SOLVED]
Replies: 4
Views: 2452

Re: Finding a firewalled connection [SOLVED]

For home use with public IP you normally get few thousands hits per month.
Try instead of your final drop rule use this reject rule and see if hits get reduced after time:
add action=reject chain=input reject-with=icmp-admin-prohibited
by Pea
Sat Feb 16, 2019 9:46 am
Forum: Beginner Basics
Topic: Where can I download Winbox 3.12
Replies: 2
Views: 7889

Re: Where can I download Winbox 3.12

Always use latest version, only for specific needs:
https://download.mikrotik.com/routeros/ ... winbox.exe
by Pea
Fri Feb 15, 2019 12:58 am
Forum: Beginner Basics
Topic: hAPlite bridge to CAPsMAN wirelessly? [SOLVED]
Replies: 3
Views: 1777

Re: hAPlite bridge to CAPsMAN wirelessly? [SOLVED]

I never had roaming station on WDS link.
But I guess it should be possible to set AP with wds-mode=dynamic-mesh which allows WDS links with devices (mode=station-wds) by creating required entries dynamically.
by Pea
Wed Feb 13, 2019 12:06 am
Forum: Wireless Networking
Topic: Country settings for Japan
Replies: 2
Views: 1524

Re: Country settings for Japan

Maybe this helps:
/interface wireless info country-info japan
by Pea
Tue Feb 12, 2019 12:34 am
Forum: Beginner Basics
Topic: hAPlite bridge to CAPsMAN wirelessly? [SOLVED]
Replies: 3
Views: 1777

Re: hAPlite bridge to CAPsMAN wirelessly? [SOLVED]

Connect your hAPlite by WDS to your router. Then all should work the same as cable connection.
by Pea
Thu Feb 07, 2019 10:44 pm
Forum: Beginner Basics
Topic: Different DNS to different Mac addresses
Replies: 4
Views: 3358

Re: Different DNS to different Mac addresses

/ip dhcp-server lease add address=10.0.0.1 mac-address=XX:XX:XX:XX:XX:XX ... /ip firewall address-list add address=10.0.0.1 list="my known devices" ... /ip firewall nat add action=dst-nat chain=dstnat dst-port=53 protocol=udp src-address-list="my known devices" to-addresses=1.1....
by Pea
Thu Feb 07, 2019 10:35 pm
Forum: RouterBOARD hardware
Topic: New routerboot firmware
Replies: 12
Views: 7223

Re: New routerboot firmware

Yes, these are 2 different things: 1) RouterOS update - go to "System/Packages" menu, click on "Check for Updates" 2) Firmware (bootloader) upgrade - go to "System/Routerboard" menu and click "Upgrade" The version number of Router OS and Firmware is synchronis...
by Pea
Wed Feb 06, 2019 8:21 am
Forum: General
Topic: [RB951G-2HnD] 300Mbps Internet bottleneck
Replies: 6
Views: 3145

Re: [RB951G-2HnD] 300Mbps Internet bottleneck

1. Do not open SSH and Winbox to wild internet (use e.g. address list, VPN, port knock)
2. Use Fast track for better throughput https://wiki.mikrotik.com/wiki/Manual:IP/Fasttrack
3. Consider router upgrade
by Pea
Sun Feb 03, 2019 9:56 am
Forum: General
Topic: Performance of Mikrotik 951G-2HnD
Replies: 21
Views: 3720

Re: Performance of Mikrotik 951G-2HnD

*) All tests are done with Xena Networks specialized test equipment (XenaBay),and done according to RFC2544 (Xena2544) Max throughput is determined with 30+ second attempts with 0,1% packet loss tolerance in 64, 512, 1518 byte packet sizes Test results show device maximum performance, and are reache...
by Pea
Sun Feb 03, 2019 9:40 am
Forum: RouterBOARD hardware
Topic: For real, what is with these blinding power leds?
Replies: 13
Views: 6627

Re: For real, what is with these blinding power leds?

Black tape is your friend to reduce LED brightness of whatever anytime :D
by Pea
Sat Feb 02, 2019 10:07 pm
Forum: General
Topic: Performance of Mikrotik 951G-2HnD
Replies: 21
Views: 3720

Re: Performance of Mikrotik 951G-2HnD

Maybe Fasttrack rule missing in your firewall?
https://wiki.mikrotik.com/wiki/Manual:IP/Fasttrack
/ip firewall filter add chain=forward action=fasttrack-connection connection-state=established,related
/ip firewall filter add chain=forward action=accept connection-state=established,related
by Pea
Sat Feb 02, 2019 9:18 pm
Forum: RouterBOARD hardware
Topic: New routerboot firmware
Replies: 12
Views: 7223

Re: New routerboot firmware

Your firmware is already upgraded. Move on.
by Pea
Sat Feb 02, 2019 8:40 pm
Forum: Beginner Basics
Topic: Wireless station - bridge - to lan not working [SOLVED]
Replies: 10
Views: 12282

Re: Wireless station - bridge - to lan not working [SOLVED]

Did you change this?
You need to use Station pseudo bridge
by Pea
Sat Feb 02, 2019 7:56 pm
Forum: RouterBOARD hardware
Topic: New routerboot firmware
Replies: 12
Views: 7223

Re: New routerboot firmware

Factory Firmware is what was originally loaded at factory. You can ignore this. Installed version is under Current Firmware.
by Pea
Sat Feb 02, 2019 4:29 pm
Forum: Wireless Networking
Topic: wireless network with authentication of user+password [SOLVED]
Replies: 9
Views: 11094

Re: wireless network with authentication of user+password [SOLVED]

IMHO it's not illegal to change a MAC address.
It's only illegal to change a MAC address to do something illegal.
by Pea
Sat Feb 02, 2019 3:10 pm
Forum: General
Topic: How to set different wireless channels on router used as extender?
Replies: 3
Views: 1300

Re: How to set different wireless channels on router used as extender?

Both options are possible, but this is my point of view: 2.4GHz indoor PtP: will reach longer distance and through more obstacles, only one 2.4GHz channel occupied by the link 5GHz indoor PtP: better throughput, but on longer distance or more walls weak signal, two 2.4GHz channels occupied by APs fo...
by Pea
Sat Feb 02, 2019 2:27 pm
Forum: Wireless Networking
Topic: CAPsMAN not adding dynamically interfaces to bridge
Replies: 4
Views: 2816

Re: CAPsMAN not adding dynamically interfaces to bridge

local-forwarding=no => the interface is part of bridge on the CAPsMAN, the interface shows as disabled on CAP
local-forwarding=yes => the interface stays as part of bridge on the CAP
by Pea
Sat Feb 02, 2019 2:21 pm
Forum: Wireless Networking
Topic: wireless network with authentication of user+password [SOLVED]
Replies: 9
Views: 11094

Re: wireless network with authentication of user+password [SOLVED]

First connect by laptop and login with username and password.
Then change your Mikrotik wlan1 MAC to your laptop MAC.
And then try to connect your Mikrotik as client to the wifi network.
by Pea
Sat Feb 02, 2019 2:15 pm
Forum: General
Topic: How to set different wireless channels on router used as extender?
Replies: 3
Views: 1300

Re: How to set different wireless channels on router used as extender?

For best performance I recommend to connect both by Ethernet cable if somehow possible.
Or upgrade to dual band routers and use 2.4GHz only to connect both wirelessly and use the 5GHz for wifi sharing.
by Pea
Fri Feb 01, 2019 12:17 am
Forum: General
Topic: DNS Flag Day
Replies: 3
Views: 1594

Re: DNS Flag Day

Did you read the website briefly?
There is no reason to worry if you are an Internet user without your own domain name. This change is affecting you only indirectly and you do not need to take any other steps.
by Pea
Thu Jan 31, 2019 8:57 pm
Forum: Wireless Networking
Topic: CAPsMAN and multiSSID
Replies: 1
Views: 1151

Re: CAPsMAN and multiSSID

Try this:
  • Create a new configuration for the VirtualAP
  • Specify the new configuration in Provisioning rule as Slave configuration
  • Remove all CAP interfaces
  • Initiate Manual Provisioning on all the CAPs
by Pea
Thu Jan 31, 2019 8:42 pm
Forum: Wireless Networking
Topic: High ping to router HAP AC2
Replies: 33
Views: 10826

Re: High ping to router HAP AC2

Did you try to reset to factory default and test? What was the result?
You are connected via 2.4GHz or 5GHz?
Did you try to change channel?
by Pea
Wed Jan 30, 2019 12:03 am
Forum: Beginner Basics
Topic: How to connect remote device into the LAN over WiFi? [SOLVED]
Replies: 7
Views: 3024

Re: How to connect remote device into the LAN over WiFi? [SOLVED]

Remote device keep on auto, it will act as client and take frequency from AP. If you do not have any 802.11b only device (and you probably don't) try this: /interface wireless set band=2ghz-g/n channel-width=20mhz bridge-mode=disabled country="your country" distance=indoors frequency-mode=...
by Pea
Tue Jan 29, 2019 12:45 am
Forum: Beginner Basics
Topic: How to connect remote device into the LAN over WiFi? [SOLVED]
Replies: 7
Views: 3024

Re: How to connect remote device into the LAN over WiFi? [SOLVED]

Sure, WPA2-PSK as security profile and optionally disable PMKID. Simplified description: Run your secured WiFi normally on your router, add settings for WDS, add static WDS interface with MAC of second device. On other device start without any setup. Add bridge and DHCP client on bridge. Add securit...
by Pea
Mon Jan 28, 2019 9:44 pm
Forum: Beginner Basics
Topic: How to connect remote device into the LAN over WiFi? [SOLVED]
Replies: 7
Views: 3024

Re: How to connect remote device into the LAN over WiFi? [SOLVED]

You can use your wlan1 as WAN port and wireless mode station-pseudobridge on remote Mikrotik. Do not forget to synchronise time of remote device. Or below is what I use reliably with Mikrotik on both ends: On your Mikrotik router /interface wireless set mode=ap-bridge ssid=YOUR-SSID wds-default-brid...
by Pea
Sun Jan 27, 2019 10:45 pm
Forum: Announcements
Topic: v6.43.8 [stable] is released!
Replies: 169
Views: 83073

Re: v6.43.8 [stable] is released!

Use manually non DSF channel (5200, 5220 or 5240). Problem solved.
by Pea
Sat Jan 26, 2019 11:26 pm
Forum: Beginner Basics
Topic: Capsman and his own CAP issue
Replies: 1
Views: 1115

Re: Capsman and his own CAP issue

You can try latest ROS beta which likely do not need below workaround anymore (I did not test this yet): *) capsman - always accept connections from loopback address; Otherwise this should fix it: /capsman manager interface set [find default=yes] forbid=no add forbid=yes interface=(here put interfac...
by Pea
Fri Jan 25, 2019 8:39 am
Forum: Wireless Networking
Topic: Does locking to CAPsMan leave the rest of the router alone? [SOLVED]
Replies: 2
Views: 1596

Re: Does locking to CAPsMan leave the rest of the router alone? [SOLVED]

The CAPsMAN takes care about wifi1 and/or wifi2 interfaces only. The rest of functionality and interfaces you can use and configure as you like.
by Pea
Tue Jan 22, 2019 12:18 am
Forum: Wireless Networking
Topic: CAPsMAN - How to force layer 2?
Replies: 11
Views: 11452

Re: CAPsMAN - How to force layer 2?

3) The worst: this is not documented anywhere besides user forums (it should be on CAPsMan manual to prevent people be fighting hours with something that isn´t going to work) https://wiki.mikrotik.com/wiki/Manual:Simple_CAPsMAN_setup#CAP_in_CAPsMAN But I agree that having firewall rule for CAP on C...
by Pea
Sun Jan 20, 2019 2:30 pm
Forum: Wireless Networking
Topic: android devices chooses 2.4Ghz over 5Ghz on hAP ac^2
Replies: 13
Views: 10335

Re: android devices chooses 2.4Ghz over 5Ghz on hAP ac^2

forgot to mention that this is one room condition - both phones, laptop and router are in one room max 3m away.
Ideal situation. Why you even use 2.4GHz? Stay with 5GHz only and problem solved.
by Pea
Sun Jan 20, 2019 9:57 am
Forum: General
Topic: Log in to router
Replies: 1
Views: 886

Re: Log in to router

This depends on your firewall rules. By default this is filtered.
by Pea
Fri Jan 18, 2019 4:58 pm
Forum: Wireless Networking
Topic: android devices chooses 2.4Ghz over 5Ghz on hAP ac^2
Replies: 13
Views: 10335

Re: android devices chooses 2.4Ghz over 5Ghz on hAP ac^2

Other option would be to setup different SSID for 5GHz. And never connect phone to your 2.4GHz :)
by Pea
Wed Jan 16, 2019 12:42 am
Forum: Beginner Basics
Topic: Recommended DNS Approach.
Replies: 4
Views: 2263

Re: Recommended DNS Approach.

redirect - replaces destination port of an IP packet to one specified by to-ports parameter and destination address to one of the router's local addresses
by Pea
Mon Jan 14, 2019 9:30 pm
Forum: Wireless Networking
Topic: CAPsMAN issue's
Replies: 9
Views: 2177

Re: CAPsMAN issue's

The 802.11n prohibits using high throughput with WEP or TKIP as the unicast cipher. If you use these encryption methods (for example, WEP, WPA-TKIP), your data rate will drop to 54 Mbps.
Use only WPA2-AES for full 802.11n speed.
by Pea
Fri Jan 11, 2019 2:10 pm
Forum: RouterBOARD hardware
Topic: hap lite not enough space for update [SOLVED]
Replies: 17
Views: 17091

Re: hap lite not enough space for update [SOLVED]

For standard home use you can remove safely all files and folders from File List
(flash folder cannot be removed but all sub folders yes)
by Pea
Thu Jan 10, 2019 7:40 pm
Forum: Wireless Networking
Topic: High ping to router HAP AC2
Replies: 33
Views: 10826

Re: High ping to router HAP AC2

There should be <1ms for ping even over wifi. What are you getting?
by Pea
Thu Jan 10, 2019 7:33 pm
Forum: RouterBOARD hardware
Topic: hap lite not enough space for update [SOLVED]
Replies: 17
Views: 17091

Re: hap lite not enough space for update [SOLVED]

try to reboot first to clean some memory...
by Pea
Mon Jan 07, 2019 12:47 am
Forum: Beginner Basics
Topic: chain -> input action -> drop [SOLVED]
Replies: 6
Views: 4381

Re: chain -> input action -> drop

When processing a chain, rules are taken from the chain in the order they are listed there from top to bottom. If a packet matches the criteria of the rule, then the specified action is performed on it, and no more rules are processed in that chain (the exception is the passthrough action). If a pac...
by Pea
Sun Jan 06, 2019 10:03 am
Forum: RouterBOARD hardware
Topic: RB951G-2HnD Already in use, got hap ac2, what now?
Replies: 13
Views: 3170

Re: RB951G-2HnD Already in use, got hap ac2, what now?

Separate configs are for various devices you want to manage from CAPsMAN. Then you push the correct config to the device. E.g. 2,4GHz only config to older 2,4GHz only CAP.
If all your CAP devices support the same standards you can have only one config.
by Pea
Sat Jan 05, 2019 10:02 pm
Forum: RouterBOARD hardware
Topic: RB951G-2HnD Already in use, got hap ac2, what now?
Replies: 13
Views: 3170

Re: RB951G-2HnD Already in use, got hap ac2, what now?

Hi, this file should answer your questions about CAPsMAN VirtualAP Setup, Dual Band CAP, CAPsMAN and CAP in one board:
https://mum.mikrotik.com/presentations/BR14/Uldis.pdf
(little outdated, November 2014, but still nice explaining)
by Pea
Sat Jan 05, 2019 10:25 am
Forum: Wireless Networking
Topic: how to download wireless-fp package?
Replies: 3
Views: 1650

Re: how to download wireless-fp package?

Use latest version of RouterOS.
The wireless-fp was long time ago replaced by standard wireless package which is included.
by Pea
Wed Jan 02, 2019 12:25 am
Forum: General
Topic: Has this remote ROOT exploit been patched??
Replies: 22
Views: 5128

Re: Has this remote ROOT exploit been patched??

Yes but this is likely not going to happen for home use :) Therefore it is IMHO useless at the end.
by Pea
Tue Jan 01, 2019 7:55 pm
Forum: General
Topic: Has this remote ROOT exploit been patched??
Replies: 22
Views: 5128

Re: Has this remote ROOT exploit been patched??

This is not the best example.
Why those rules open udp port 69 (TFTP)?
Also there is defined address list which won't be used later (the rule is after general drop)...
by Pea
Mon Dec 31, 2018 5:32 pm
Forum: General
Topic: under attack in port 32231? - help
Replies: 25
Views: 5132

Re: under attack in port 32231? - help

This simplification should explain the difference: Reject : someone comes to your address and try to open door of your house, but you tell him that it is well locked Drop : someone comes to your address but there is no house or door to open and he gives up after while (timeout) It is up to you what ...
by Pea
Mon Dec 31, 2018 9:23 am
Forum: General
Topic: Has this remote ROOT exploit been patched??
Replies: 22
Views: 5128

Re: Has this remote ROOT exploit been patched??

I am surprised that there was no default firewall. I really thought you removed it :) I am sorry.
And I am happy that you fixed it for your needs.
by Pea
Mon Dec 31, 2018 12:13 am
Forum: General
Topic: Has this remote ROOT exploit been patched??
Replies: 22
Views: 5128

Re: Has this remote ROOT exploit been patched??

But you can dual boot to RouterOS on this CRS and this should have default firewall. If not then it would be good idea to add it :)
by Pea
Sun Dec 30, 2018 1:10 pm
Forum: General
Topic: Has this remote ROOT exploit been patched??
Replies: 22
Views: 5128

Re: Has this remote ROOT exploit been patched??

it scared the hell out of me!!!
Yes, you do inappropriate configuration changes. Scary.
Study some basics about firewall and fix it.
If you don't want to study then reset your router to default to get firewall back.
by Pea
Sat Dec 29, 2018 12:28 am
Forum: General
Topic: RB951Ui WiFi stations sending station leaving
Replies: 3
Views: 1658

Re: RB951Ui WiFi stations sending station leaving

If this is a mobile device on your hotspot then this is rather normal, isn't it? Just a battery savings and therefore wifi switch off temporary on the mobile device.
Why do you think this is a problem?
by Pea
Fri Dec 28, 2018 6:40 pm
Forum: Wireless Networking
Topic: PWR-Line AP request for comment
Replies: 16
Views: 4674

Re: PWR-Line AP request for comment

As mentioned by Normis they sell them as single units.
You can buy one or two or... 8 or... 1000 or even more :)
by Pea
Fri Dec 28, 2018 1:28 pm
Forum: General
Topic: under attack in port 32231? - help
Replies: 25
Views: 5132

Re: under attack in port 32231? - help

There is better way than drop selectively not used ports:
1) accept only what you need
2) reject/drop everything else
That's it.
by Pea
Tue Dec 25, 2018 6:14 pm
Forum: Beginner Basics
Topic: HapAC2 as simple access point
Replies: 7
Views: 9001

Re: HapAC2 as simple access point

Disable DHCP server, put all ports to bridge, add DHCP client on bridge, modify firewall and nat.
It should work then.
by Pea
Fri Dec 21, 2018 6:19 pm
Forum: General
Topic: hAP Ac loops into no update. - UPDATE: bricked unit
Replies: 5
Views: 1849

Re: hAP Ac loops into no update.

You re mixing RouteOS update and Firmware upgrade. These are 2 different things.
Press the Download&Install button in Check For Updates window to update RouterOS.
After reboot you can press Upgrade button in Routerboard window to upgrade also the firmware.
by Pea
Sat Dec 15, 2018 12:01 am
Forum: Beginner Basics
Topic: Web filter for Childs
Replies: 7
Views: 3410

Re: Web filter for Childs

This is what I do. If you use Mikrotik DHCP server just make static DHCP lease for MAC address of iPad from Santa, then dstnat its DNS queries to e.g. OpenDNS FamilyShield: /ip dhcp-server lease add address=10.0.0.123 mac-address=AA:BB:CC:DD:EE:FF /ip firewall nat add action=dst-nat chain=dstnat dst...
by Pea
Wed Dec 12, 2018 8:23 am
Forum: General
Topic: PWR-Line AP
Replies: 49
Views: 17877

Re: PWR-Line AP

There will be RouterOS so many possibilities for setup are expected. It should be possible to simply disable wifi interface if not needed.
by Pea
Mon Dec 10, 2018 9:51 pm
Forum: Wireless Networking
Topic: PWR-Line AP request for comment
Replies: 16
Views: 4674

Re: PWR-Line AP request for comment

Not available yet, search for PL7411-2nD: The PWR-LINE AP is a wireless access point with a single Ethernet port , a built-in 802.11b/g/n WiFi radio and capability to connect to other PWR-LINE devices through the electrical lines in your premises. Details and pictures: https://i.mt.lv/cdn/rb_files/P...
by Pea
Wed Dec 05, 2018 9:16 pm
Forum: Announcements
Topic: v6.43.7 [stable] is released!
Replies: 53
Views: 33928

Re: v6.43.7 [stable] is released!

I will also share positive update results:
hAP ac, hAP ac lite, hAP ac², hAP lite, RB951
All fine, no problem.
by Pea
Wed Dec 05, 2018 1:39 am
Forum: Wireless Networking
Topic: hAPac2 wifi issue [SOLVED]
Replies: 6
Views: 4174

Re: hAPac2 wifi issue [SOLVED]

Is your SSID unique?
Or do you use something common as "Internet" or "wifi"? Then many devices will try to connect when they know this SSID.
by Pea
Sat Dec 01, 2018 1:35 am
Forum: General
Topic: PWR-Line AP
Replies: 49
Views: 17877

Re: PWR-Line AP

According to this shop PL7411-2nD will come 12.12.2018: https://www.wifihw.cz/default.asp?cls=stoitem&stiid=4329 Product code: PL7411-2nD CPU: QCA9533 CPU: nominal frequency 650 MHz PLC chipset: AR7420 Size of RAM: 64 MB Memory: 16 MB Flash 10/100 Ethernet ports: 1 Wireless Built-in: 2.4 GHz 802...
by Pea
Tue Nov 27, 2018 9:32 pm
Forum: Beginner Basics
Topic: How to update to separate packages? [SOLVED]
Replies: 2
Views: 1344

How to update to separate packages? [SOLVED]

What is the correct and clean procedure to update from main package to separate packages?
Just upload needed separate packages only of higher version and reboot?
by Pea
Tue Nov 27, 2018 9:23 pm
Forum: General
Topic: Backups disappear from router
Replies: 3
Views: 1756

Re: Backups disappear from router

https://wiki.mikrotik.com/wiki/Manual:System/File Warning: If device has a directory named "flash" in its file list, then files which you want to be kept after system reboot/power cycle must be stored within it. As anything outside of it is kept within a RAM disk and will be lost upon rebo...
by Pea
Wed Nov 21, 2018 9:33 pm
Forum: Wireless Networking
Topic: Devices does not see the wifi [SOLVED]
Replies: 12
Views: 7574

Re: Devices does not see the wifi [SOLVED]

Check the channel, some devices do not see 2.4g wifi channel 13 (e.g. Kindle Paperwhite)
by Pea
Fri Nov 16, 2018 9:27 pm
Forum: Beginner Basics
Topic: rookie Port Forward for PS4 [SOLVED]
Replies: 15
Views: 9114

Re: rookie Port Forward for PS4 [SOLVED]

Hi, did you noticed this warning? :) /system note set note="DEVICE HACKED - ACCOUNT admin HAD UNSAFE PASSWORD" and this is not your code, right? /system scheduler add interval=1d name=Auto113 on-event="/system reboot" policy=\ ftp,reboot,read,write,policy,test,password,sniff,sens...
by Pea
Sun Nov 11, 2018 9:54 am
Forum: Beginner Basics
Topic: How to Limit Internet Speed per IP? [SOLVED]
Replies: 3
Views: 5572

Re: How to Limit Internet Speed per IP? [SOLVED]

https://wiki.mikrotik.com/wiki/Manual:IP/Fasttrack Packet marking for fast processing. Warning: Queues (except Queue Trees parented to interfaces), firewall filter and mangle rules will not be applied for FastTracked traffic. Make exception in your Fasttrack firewall rule for the IP where you want t...
by Pea
Sun Sep 30, 2018 11:02 am
Forum: General
Topic: NTP client bug
Replies: 13
Views: 7156

Re: NTP client bug

I am just curious why you still try to use "Use Peer NTP" from your ISP while you know it is not working? :)
And did you try to contact your ISP to fix his DHCP NTP address setup?
by Pea
Thu Sep 20, 2018 8:14 am
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 85553

Re: v6.43.1 [stable] is released!

still cant change any user names.
introduced in 6.43.0
viewtopic.php?f=2&t=139091
by Pea
Thu Sep 13, 2018 12:51 am
Forum: General
Topic: Add emoji to the ssid name
Replies: 38
Views: 17242

Re: Add emoji to the ssid name

This link may help you to find suitable emoji:
https://unicode.org/emoji/charts/emoji-list.html
https://unicode.org/emoji/charts/full-emoji-list.html
/interface wireless set [find] ssid="\F0\9F\92\A3\F0\9F\92\A9"
😈
by Pea
Tue Aug 28, 2018 1:38 am
Forum: Announcements
Topic: v6.42.7 [current] is released!
Replies: 159
Views: 70204

Re: v6.42.7 [current] is released!

Just start reading!
[time=1535139686 user_id=118648]
how fix this please help me !
1. Please don't put questions not related to a specific release into the release topic, make new topic!
2. You are killing your router by Sector Writes, maybe logging on disc? Check your config, stop it! :)
by Pea
Fri Aug 24, 2018 11:38 pm
Forum: Announcements
Topic: v6.42.7 [current] is released!
Replies: 159
Views: 70204

Re: v6.42.7 [current] is released!

how fix this please help me ! 1. Please don't put questions not related to a specific release into the release topic 2. You are killing your router by Sector Writes, maybe logging on disc? Check your config, stop it! :) 3. You can try netinstall, helped me to recover bad blocks, just give it a try
by Pea
Thu Aug 23, 2018 8:52 am
Forum: Scripting
Topic: script for buttom mikrotik
Replies: 3
Views: 1225

Re: script for buttom mikrotik

And this is how to use the button with scripting:
https://wiki.mikrotik.com/wiki/Manual:R ... ode_button
by Pea
Sat Aug 11, 2018 10:56 am
Forum: RouterBOARD hardware
Topic: PWR-Line AP - when will be available?
Replies: 0
Views: 987

PWR-Line AP - when will be available?

When will be available PWR-Line AP announced in April 2018?
by Pea
Tue Aug 07, 2018 10:14 pm
Forum: General
Topic: Hap AC2 RAM [SOLVED]
Replies: 13
Views: 5781

Re: Hap AC2 RAM [SOLVED]

The same here, but no complain :)

version: 6.42.6 (stable)
factory-software: 6.42.3
free-memory: 205.3MiB
total-memory: 233.2MiB

board-name: hAP ac^2
model: RBD52G-5HacD2HnD
by Pea
Tue Aug 07, 2018 8:41 am
Forum: RouterBOARD hardware
Topic: Advise on Mikrotik Routerboard Firmware
Replies: 4
Views: 1729

Re: Advise on Mikrotik Routerboard Firmware

Yes, this is all fine.
The firmware version increases (synchronize) now with ROS version. Even there is no update in the firmware.
(I do not know the reason why MikroTik made this change)
by Pea
Mon Aug 06, 2018 8:11 pm
Forum: General
Topic: How to block massive UDP traffic?
Replies: 1
Views: 876

Re: How to block massive UDP traffic?

port 53 :)
Search for DNS Amplification
And fix your firewall on input chain!
by Pea
Mon Aug 06, 2018 8:33 am
Forum: RouterBOARD hardware
Topic: Advise on Mikrotik Routerboard Firmware
Replies: 4
Views: 1729

Re: Advise on Mikrotik Routerboard Firmware

Currently you are running current-firmware 3.24.
You should upgrade to upgrade-firmware 6.42.6.
by Pea
Fri Aug 03, 2018 11:20 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 177163

Re: Winbox vulnerability: please upgrade

So what about version 6.40.8, is vulnerable or not? Could somebody from Mikrotik finally confirm it? Bugfix release tree Release 6.40.8 2018-04-24 What's new in 6.40.8 (2018-Apr-23 11:34): !) winbox - fixed vulnerability that allowed to gain access to an unsecured router; https://mikrotik.com/downl...
by Pea
Fri Aug 03, 2018 12:58 am
Forum: General
Topic: Mikrotik in the news..bad news
Replies: 56
Views: 15905

Re: Mikrotik in the news..bad news

Yes, last bugfix 6.40.8 is fine (+ change your passwords after upgrading, restore your configuration and inspect it for unknown settings, implement a good firewall)
What's new in 6.40.8 (2018-Apr-23 11:34):
!) winbox - fixed vulnerability that allowed to gain access to an unsecured router
by Pea
Sun Jul 15, 2018 8:25 pm
Forum: General
Topic: DNS server changed automatically [SOLVED]
Replies: 14
Views: 6905

Re: DNS server changed automatically [SOLVED]

Did you change all your passwords after update?
by Pea
Sun Jul 15, 2018 9:40 am
Forum: General
Topic: DNS server changed automatically [SOLVED]
Replies: 14
Views: 6905

Re: DNS server changed automatically [SOLVED]

You are running vulnerable version, so no surprise that someone can change your settings when they can get all your usernames and passwords.
It was mentioned in this topic, upgrade, change passwords, add firewall...
viewtopic.php?f=21&t=133533
by Pea
Thu Jul 12, 2018 11:20 pm
Forum: Beginner Basics
Topic: SSID for kids Zone with OpenDNS
Replies: 14
Views: 3935

Re: SSID for kids Zone with OpenDNS

This is what I do, working perfectly: Add static DHCP leases Create firewall FamilyShield list for required static IP addresses Add 2 dst-nat rules for the FamilyShield list to the OpenDNS address 8) /ip dhcp-server lease add address=10.0.0.xx comment="FamilyShield" mac-address=xx:xx:xx:xx...
by Pea
Thu Jun 28, 2018 11:10 pm
Forum: General
Topic: found this on my router today!
Replies: 3
Views: 1905

Re: found this on my router today!

Well, follow this advice for update and password change, proper firewall, etc.:
viewtopic.php?f=21&t=132499
viewtopic.php?f=21&t=133533
by Pea
Wed Jun 27, 2018 2:39 pm
Forum: General
Topic: Urgent Help Please! [SOLVED]
Replies: 7
Views: 2204

Re: Urgent Help Please! [SOLVED]

It will not happen if we could see all open windows within the Winbox as on this simulation:
by Pea
Wed Jun 27, 2018 12:18 am
Forum: General
Topic: Urgent Help Please! [SOLVED]
Replies: 7
Views: 2204

Re: Urgent Help Please! [SOLVED]

This happens when you have several terminals hidden behind other windows. Close some windows and you will find those eight terminals. And close them.
by Pea
Tue Jun 26, 2018 8:56 pm
Forum: Announcements
Topic: Winbox v3.15 released!
Replies: 20
Views: 22937

Re: Winbox v3.15 released!

It's a pity!
But good inspiration to MikroTik for Winbox improvement. Maybe someday :)

And next would be option to disable/remove Quick Set based on setup on router (e.g. /system routerboard settings quickset=disabled).
by Pea
Tue Jun 26, 2018 8:16 pm
Forum: Announcements
Topic: Winbox v3.15 released!
Replies: 20
Views: 22937

Re: Winbox v3.15 released!

Tell me how to get these window buttons there? I like it! But I do not have it :)
(I hope this is not a "photoshop" joke)
by Pea
Mon Jun 11, 2018 10:26 pm
Forum: Beginner Basics
Topic: Trying to block sites. Mild success.
Replies: 8
Views: 3781

Re: Trying to block sites. Mild success.

Hello, don' use layer 7, use this instead : /ip firewall filter add chain=forward dst-port=443 protocol=tcp tls-host=*.facebook.com action=reject add chain=forward dst-port=80 protocol=tcp tls-host=*.speedtest.net action=reject Hello. One question. Do I have to do something for the filter to take e...
by Pea
Mon Jun 04, 2018 9:43 pm
Forum: Wireless Networking
Topic: interface wireless set compression=yes - does this work? [SOLVED]
Replies: 3
Views: 3732

Re: interface wireless set compression=yes - does this work? [SOLVED]

I see, nothing interesting then...
I am setting it back to default "compression=no" :)
by Pea
Tue May 29, 2018 10:37 pm
Forum: Wireless Networking
Topic: interface wireless set compression=yes - does this work? [SOLVED]
Replies: 3
Views: 3732

interface wireless set compression=yes - does this work? [SOLVED]

I'm curious about this wireless option: interface wireless set compression=yes Wiki says: Setting this property to yes will allow the use of the hardware compression. Wireless interface must have support for hardware compression. Connections with devices that do not use compression will still work. ...
by Pea
Wed May 16, 2018 9:33 pm
Forum: RouterBOARD hardware
Topic: Not Work RB951g-2HnD
Replies: 1
Views: 983

Re: Not Work RB951g-2HnD

Maybe defective power adapter? Do you have any other to test?
by Pea
Wed May 09, 2018 8:46 pm
Forum: Wireless Networking
Topic: Connect Routerboard with hotel wifi
Replies: 7
Views: 3698

Re: Connect Routerboard with hotel wifi

If the hotel keeps login based on device MAC address:
1) Change your laptop MAC address to your router MAC address
2) Pass the login on your laptop
3) Change the laptop MAC address back to default/original
4) Switch on your router, fill the SSID and enjoy "own network" :)
by Pea
Tue May 01, 2018 10:20 am
Forum: General
Topic: 6.42.1 POE Overload
Replies: 12
Views: 5280

Re: 6.42.1 POE Overload

No, PoE works in 6.42.1 correctly for me same as with previous versions. Did you try to connect different device?
by Pea
Mon Apr 30, 2018 1:50 am
Forum: Beginner Basics
Topic: Firewall Rules: Block ICMP from WAN (PPPOE connection) [SOLVED]
Replies: 22
Views: 9514

Re: Firewall Rules: Block ICMP from WAN (PPPOE connection) [SOLVED]

I am just curious why you want to block ping? Anyway if you insist on it start with simple input icmp drop rule placed somewhere on top. If this works then do fine tuning in more detail. If this does not work then you are actually pinging different device (you modem - as you wrote that your WAN is e...
by Pea
Sun Apr 29, 2018 10:11 pm
Forum: Announcements
Topic: Winbox 3.13 released!
Replies: 59
Views: 42797

Re: Winbox 3.13 released!

Click on Neighbors card and then simply click on MAC address (or IP address) of the device you want to connect to...
by Pea
Fri Apr 27, 2018 6:18 pm
Forum: RouterBOARD hardware
Topic: Copper link longer than 100 meters
Replies: 16
Views: 4000

Re: Copper link longer than 100 meters

My experience beyond specifications is to keep the Ethernet cable as short as possible, as isolated as possible :)
Maximum is really about 100 metres then collision detection mechanisms "break" the link.
Use some repeater in the middle and you should be fine.
by Pea
Wed Apr 25, 2018 10:20 am
Forum: Announcements
Topic: Advisory: Vulnerability exploiting the Winbox port [SOLVED]
Replies: 203
Views: 259105

Re: Advisory: Vulnerability exploiting the Winbox port

Very nice tutorial on port knocking: http://blog.cactiusers.org/2009/04/17/m ... -knocking/
to: 9939781 - it is with Layer 7 packet sniffing if you insist on it :)
by Pea
Tue Apr 24, 2018 8:13 pm
Forum: Announcements
Topic: v6.42.1 [current]
Replies: 272
Views: 99270

Re: v6.42.1 [current]

pe1chl: yes, this is clear. The report about problem in this version is due to missing feedback in log after pressing the Upgrade button. This " Firmware upgraded successfully, please reboot for changes to take effect! " did not appear in log. And this is unusual. This information line was...
by Pea
Tue Apr 24, 2018 7:14 pm
Forum: Beginner Basics
Topic: don't write logs
Replies: 5
Views: 1748

Re: don't write logs

maybe...
did you try to check how many lines you have setup?
/system logging action print
look for "memory-lines= ..."

Or go to System / Logging / Actions / memory / Lines
by Pea
Tue Apr 24, 2018 5:43 pm
Forum: Announcements
Topic: v6.40.8 [bugfix] is released!
Replies: 35
Views: 37776

Re: v6.40.8 [bugfix] is released!

skullzaflare: see viewtopic.php?f=21&t=128915
Please, note that downgrading to previous RouterOS versions (below 6.41) will not restore "master-port" configuration, so use backups to restore configuration on downgrade.
by Pea
Tue Apr 24, 2018 9:25 am
Forum: Announcements
Topic: v6.42.1 [current]
Replies: 272
Views: 99270

Re: v6.42.1 [current]

Hi strods, this happened for the first time that log message about upgrade was missing completely. Unfortunately all my devices are upgraded already, so I cannot check if the warning was in System/Routerboard/Settings. But it was definitely missing in log. Now if I look into terminal I still see 2 l...
by Pea
Mon Apr 23, 2018 10:21 pm
Forum: Announcements
Topic: v6.42.1 [current]
Replies: 272
Views: 99270

Re: v6.42.1 [current]

The same with missing line in log "Firmware upgraded successfully, please reboot for changes to take effect!" happened to me today on RB951G-2HnD. Little scary on 50km away device :) Did the upgrade failed? Should I reboot or better not? Anyway I sent the reboot command - and all seems fin...
by Pea
Thu Apr 12, 2018 1:19 am
Forum: General
Topic: How to port forward without bridge mode
Replies: 2
Views: 1962

Re: How to port forward without bridge mode

You have very likely double NAT.
If you cannot use bridge mode on ISP router then try if setting DMZ is available there.
Or use IPv6 address of your computer for external access.
by Pea
Tue Apr 03, 2018 1:08 am
Forum: General
Topic: Any plans to make cross-platform WinBox?
Replies: 33
Views: 8185

Re: Any plans to make cross-platform WinBox?

There is already linux style option - SSH CLI
;-)
If you like click with mouse in windows then it is time for Windows...
by Pea
Tue Apr 03, 2018 12:57 am
Forum: General
Topic: Can't upgrade Routerboard version
Replies: 9
Views: 8006

Re: Can't upgrade Routerboard version

What is in the log when you click on Upgrade button?
by Pea
Mon Mar 19, 2018 7:56 am
Forum: RouterBOARD hardware
Topic: hAP ac wireless light
Replies: 3
Views: 7560

Re: hAP ac wireless light

There are two LEDs for the wireless section and two LEDs for the 5th port section in the hAP ac (RB962UiGS-5HacT2HnT) case. The green wireless LED shows 2.4GHz wireless status and the red wireless LED shows 5GHz wireless status. Sometimes their blinking times match and colors blend together. The gr...
by Pea
Sat Feb 17, 2018 10:13 am
Forum: Beginner Basics
Topic: Mikrotik 951G-2HnD and Samsung TV problem
Replies: 43
Views: 40267

Re: Mikrotik 951G-2HnD and Samsung TV problem

I had seldom this problem with Samsung TV and Samsung BD player, not getting IP from DHCP. Only disconecting the Samsung device from power a connecting after a while fixed the problem. It must be some problem or incompatibility at Samsung side. I finaly fixed it by switching both devices to Sony bra...
by Pea
Fri Feb 16, 2018 10:50 pm
Forum: Announcements
Topic: v6.42rc [release candidate] is released!
Replies: 537
Views: 190728

Re: v6.42rc [release candidate] is released!

Already answered in this topic:
viewtopic.php?f=21&t=129034&start=150#p640819
by Pea
Tue Feb 06, 2018 9:31 pm
Forum: General
Topic: How to debug MTU size?
Replies: 7
Views: 18502

Re: How to debug MTU size?

Try this tool to debug the MTU values between you and a host:
https://elifulkerson.com/projects/mturoute.php
(I probably found this on this forum recommended by someone)
by Pea
Sun Jan 28, 2018 10:02 pm
Forum: Beginner Basics
Topic: Hairpin NAT with dynamic WAN IP
Replies: 2
Views: 6901

Re: Hairpin NAT with dynamic WAN IP

Thank you Steveocee, based on the tutorial I will try to use this now, Option C: /ip firewall nat add action=masquerade chain=srcnat comment="LAN to Server" dst-address=10.0.0.0/25 src-address=10.0.0.0/25 add action=masquerade chain=srcnat out-interface="PPPoE client" src-address...
by Pea
Wed Jan 24, 2018 10:14 pm
Forum: Beginner Basics
Topic: Hairpin NAT with dynamic WAN IP
Replies: 2
Views: 6901

Hairpin NAT with dynamic WAN IP

Hi, I would like to ask you to review my Hairpin NAT to internal server on 10.0.0.50 The WAN IP is dynamic (VDSL). I access my Server from Internet and also from LAN by using the domain name (WAN IP). Option A: /ip firewall nat add action=masquerade chain=srcnat out-interface="PPPoE client"...
by Pea
Wed Jan 17, 2018 11:54 pm
Forum: General
Topic: Two suggestions to improve Winbox
Replies: 3
Views: 1018

Re: Two suggestions to improve Winbox

#2: Just try "Copy" button...
by Pea
Tue Jun 27, 2017 9:53 pm
Forum: RouterBOARD hardware
Topic: RB493G, 60.0% Bad Blocks!!! What should I do now? [SOLVED]
Replies: 18
Views: 20234

Re: RB493G, 60.0% Bad Blocks!!! What should I do now? [SOLVED]

470k writes after 2 hours? You are likely killing the router by your settings.
Time for a new device... and setup with reduced writes to storage.
by Pea
Sat May 06, 2017 11:33 am
Forum: General
Topic: Local DNS
Replies: 6
Views: 2651

Re: Local DNS

Do you have your domain DNS/DDNS name registered with your WAN IP address? If yes, then you can do it with NAT. These 3 lines will make your web server accessible from internet and also from LAN by your domain name: /ip firewall filter add action=accept chain=forward comment="Accept dstnat pinh...
by Pea
Mon Oct 17, 2016 9:27 pm
Forum: RouterBOARD hardware
Topic: Ethernet port faulty?
Replies: 4
Views: 1900

Re: Ethernet port faulty?

The ether5 connector looks perfect, same as others ether1-4. So it seems it is hardware failure.
It is still in warranty, I will contact my dealer to exchange device.
by Pea
Sat Oct 15, 2016 12:25 am
Forum: RouterBOARD hardware
Topic: Ethernet port faulty?
Replies: 4
Views: 1900

Re: Ethernet port faulty?

I use only CAT6 cables.
For test I connected only one computer which negotiates with ether1-4 on 1G but when I move that only cable to ether5 it negotiates on 100M.
From my logic this cannot be caused by cable or connected device. Anyway I tested 3 gigabit devices and few cables with same result.
by Pea
Sat Oct 15, 2016 12:09 am
Forum: RouterBOARD hardware
Topic: Ethernet port faulty?
Replies: 4
Views: 1900

Ethernet port faulty?

Hi, I have RB951G-2HnD (v6.37.1, fw3.33), which has five Gigabit Ethernet ports. The ether1-4 (my WAN, LAN1-LAN3) sync on 1G normally. But ether5 (my LAN4) sync only on 100M (and negotiation takes longer). Attached screenshot shows log when I move one cable from ether2 (LAN1) to ether3 (LAN2)...to e...
by Pea
Fri Jul 22, 2016 9:59 pm
Forum: Announcements
Topic: MikroTik smartphone app (ex Tik-App)
Replies: 487
Views: 271671

Re: Tik App, MikroTik android utility ALPHA test

I confirm, Tik-App v0.0.33 does not work with 6.36 ROS, stuck on "Downloading plugins..." with Mikrotik RB951G-2HnD
by Pea
Sun Jul 17, 2016 9:46 am
Forum: General
Topic: Not enough disk space to perform update
Replies: 15
Views: 20676

Re: Not enough disk space to perform update

It should be enough to do reboot and then update.
How much free-memory you have after reboot?
Anyway 8,6MiB visible in your export should be good for update.
by Pea
Wed Jun 22, 2016 12:20 am
Forum: Beginner Basics
Topic: hairpin nat
Replies: 2
Views: 1299

Re: hairpin nat

Use this:
dst-address-type=local
Matches destination address if dst-address is assigned to one of router's interfaces.
by Pea
Wed Jun 01, 2016 8:18 am
Forum: Beginner Basics
Topic: RB951G + Omnitik + adsl modem router
Replies: 18
Views: 3684

Re: RB951G + Omnitik + adsl modem router

Just question:
Why you do not run PPPoE client on Mikrotik and your adsl router in bridge mode?
This should be imho easier and more obvious for setup.
by Pea
Sat May 07, 2016 9:03 pm
Forum: General
Topic: BTest Server for everyone?
Replies: 2
Views: 5432

Re: BTest Server for everyone?

Use search, it is easy to find this topic:
http://forum.mikrotik.com/viewtopic.php?p=527754
by Pea
Wed Apr 06, 2016 3:11 pm
Forum: Beginner Basics
Topic: allow access WebFig from public ip
Replies: 4
Views: 2980

Re: allow access WebFig from public ip

You can use Port Knocking to add actual address into allowed address list for WebFig access.
http://wiki.mikrotik.com/wiki/Port_Knocking
by Pea
Mon Apr 04, 2016 6:52 pm
Forum: General
Topic: Mikrotik is very bad in network Solutions. why ?
Replies: 11
Views: 5463

Re: Mikrotik is very bad in network Solutions. why ?

It's not like the AP can recognize a client radio's voice or anything... ;)
nice one :mrgreen:
by Pea
Thu Mar 31, 2016 11:33 pm
Forum: Beginner Basics
Topic: Very newbie firewall question
Replies: 6
Views: 1489

Re: Very newbie firewall question

I will jump here to get answer what is the best practise for the firewall last input rule: 1a - Pretend that there is nothing just black hole: add chain=input action=drop 1b - Shut the front door and lock it: add chain=input action=reject protocol=tcp reject-with=tcp-reset add chain=input action=rej...
by Pea
Tue Mar 29, 2016 9:27 pm
Forum: Beginner Basics
Topic: Public IP display problem
Replies: 28
Views: 6215

Re: Public IP display problem

Remove those 4 NAT rules: add action=masquerade chain=srcnat out-interface=all-ethernet add chain=dstnat dst-address-type=local dst-address=!192.168.0.0/16 action=jump jump-target=pinholes add chain=pinholes protocol=tcp dst-port=80,443 action=dst-nat to-address=192.168.1.198 add chain=pinholes pro...
by Pea
Tue Mar 29, 2016 4:30 pm
Forum: Announcements
Topic: Winbox3.4 released!
Replies: 53
Views: 34197

Re: Winbox3.4 released!

I think it was never there. Just write a comment and set Inline Comments in Settings and the comment column will show.
by Pea
Sun Mar 27, 2016 6:45 pm
Forum: Announcements
Topic: Winbox3.4 released!
Replies: 53
Views: 34197

Re: Winbox3.4 released!

Just tested:
Upload... button does not work, no popup, nothing.
The download option on file works. BUT no warning that file with same name already exists and existing file is overwritten!

Drag and drop works fine as before.
Winbox 3.4 on RB951G-2HnD
by Pea
Wed Mar 16, 2016 11:55 pm
Forum: Announcements
Topic: Winbox3.3 released!
Replies: 36
Views: 20221

Re: Winbox3.3 released!

Just small note: Maybe you can add higher resolution app icon... 8)
If you pin it on taskbar, you will have it with a good resolution ;)
Yes, pinned icon on taskbar looks nice.
But when I click it and Winbox is running it gets pixelated :shock:
by Pea
Mon Mar 14, 2016 9:02 pm
Forum: Announcements
Topic: Winbox3.3 released!
Replies: 36
Views: 20221

Re: Winbox3.3 released!

Just small note: Maybe you can add higher resolution app icon... 8)
by Pea
Tue Mar 01, 2016 9:46 pm
Forum: General
Topic: Upgrade issues.
Replies: 2
Views: 1208

Re: Upgrade issues.

This is answer to your question: What's new in 6.33.5 (2015-Dec-28 09:13): *) wireless - regular “wireless” package is now retired and replaced by "wireless-fp" and "wireless-cm2"; This means that in update you are trying to do is the old wireless package missing - intentionally....
by Pea
Sun Feb 21, 2016 8:27 pm
Forum: Beginner Basics
Topic: How does one setup hAP lite as a wireless client?
Replies: 2
Views: 8345

Re: How does one setup hAP lite as a wireless client?

I was solving the same setup. At the end successfully, works for weeks without problem :)
See my solution: http://forum.mikrotik.com/viewtopic.php ... 09#p518647
by Pea
Fri Feb 19, 2016 8:25 pm
Forum: General
Topic: Feature Request: filter for log viewer
Replies: 11
Views: 8403

Re: Feature Request: filter for log viewer

+1 for Winbox Log filter. Or colour highlight of search phrase at least :)
by Pea
Fri Feb 19, 2016 8:20 pm
Forum: General
Topic: Feature request: Make Quickset to be separate package
Replies: 78
Views: 17447

Re: Feature request: Make Quickset to be separate package

+1 please, Quickset to separate package if possible
by Pea
Sun Feb 14, 2016 9:01 pm
Forum: Beginner Basics
Topic: Restricting access to router before MikroTik, and WiFi not working as it should... help needed.
Replies: 14
Views: 2761

Re: Restricting access to router before MikroTik, and WiFi not working as it should... help needed.

Put your ADSL modem into BRIDGE mode. Then make PPPoE client in your Mikrotik to dial your ADSL.
Then your ADSL modem will be invisible for your customers.

telephone wire RJ11 <=> RJ11 bridge ADSL modem RJ45 <=> RJ45 WAN Mikrotik router
by Pea
Wed Feb 03, 2016 1:13 am
Forum: Wireless Networking
Topic: Wireless bridge [solved with WDS]
Replies: 6
Views: 17912

Re: Wireless bridge [solved with WDS]

As I described the " station-bridge " was not working for me. The reason stays unknown to me, there was no connection which always show in log as 4-way handshake timeout (15) . The WDS connection works from beginning excellently, perfectly suits my needs to share LAN ports connected wirele...
by Pea
Sun Jan 31, 2016 2:07 am
Forum: General
Topic: Basic steps to configure RB951G as a 5 port gigabit switch?
Replies: 21
Views: 6621

Re: Basic steps to configure RB951G as a 5 port gigabit switch?

If you want to disable wifi, you must disable wireless interface, not only LED indication.
/interface wireless
set [ find default-name=wlan1 ] disabled=yes
by Pea
Sat Jan 30, 2016 11:09 pm
Forum: Wireless Networking
Topic: Wireless bridge [solved with WDS]
Replies: 6
Views: 17912

Re: Wireless bridge - help

I had originally wds-mode=dynamic, it was working fine. But I failed many times to get right config, even once I must netinstall hAP :lol: And after each restart or disconnect there was created interface wds2, wds3, ...wds28.... I just do not like this much, so I switched to static :D My plan is to ...
by Pea
Sat Jan 30, 2016 4:45 pm
Forum: Wireless Networking
Topic: Wireless bridge [solved with WDS]
Replies: 6
Views: 17912

Re: Wireless bridge - help

Thank you for pointing me to direction to find solution. I had time today to play and test. However I didn't get "station bridge" working. I got permanent log for 4-way handshake timeout (15) and no connection at all. :( And I started to search what can be the cause of this problem. As far...
by Pea
Tue Jan 26, 2016 12:42 am
Forum: Wireless Networking
Topic: Wireless bridge [solved with WDS]
Replies: 6
Views: 17912

Wireless bridge [solved with WDS]

I need your help and advice for probably very simple setup: 1) I have configured router RB951G-2HnD doing the entire job (PPPoE to VDSL, NAT, DHCP, DNS, firewall, ipv6, wireless AP 802.11n, etc.). 2) Now I want to connect new RB941-2nD-TC (hAP lite) to my wireless AP and share this connection to its...
by Pea
Mon Jan 25, 2016 8:45 pm
Forum: RouterBOARD hardware
Topic: Mikrotik VDSL / DSL Modem?
Replies: 381
Views: 200683

Re: Mikrotik VDSL / DSL Modem?

+1

I want to get rid of ISP bridged VDSL modem :?
Or just a small black box with RJ11 on one side and RJ45 on other side (PoE powered) :D
by Pea
Thu Dec 31, 2015 1:03 am
Forum: General
Topic: RB951G-2HnD Drops wi-fi connections
Replies: 4
Views: 1971

Re: RB951G-2HnD Drops wi-fi connections

Also check what is your setup under /interface wireless max-station-count
by Pea
Sun Dec 13, 2015 2:48 pm
Forum: Wireless Networking
Topic: System critical error message in log window
Replies: 3
Views: 2741

Re: System critical error message in log window

Someone from US and UK is failing to login to your device via SSH and Telnet :D If you do not need ssh and telnet then go to services and disable ssh and telnet: /ip service set telnet disabled=yes set ssh disabled=yes If you need it then setup firewall rules to accept login from known adress list o...
by Pea
Wed Nov 18, 2015 9:33 pm
Forum: Announcements
Topic: 6.33 version released!
Replies: 139
Views: 56607

Re: 6.33 version released!

The mipsbe v6.33 and ntp package works fine.
Did you try to upload separate ntp-6.33-mipsbe.npk and reboot?
If yes, what was the log report?
by Pea
Sun Nov 15, 2015 11:38 am
Forum: General
Topic: Ways to make your router inaccessible
Replies: 5
Views: 1786

Re: Ways to make your router inaccessible

Once happened to me in Winbox to move input "drop all" rule to first place :lol:
by Pea
Thu Nov 05, 2015 11:47 pm
Forum: Beginner Basics
Topic: Dynamic ipv6 /64 assignment
Replies: 8
Views: 11183

Re: Dynamic ipv6 /64 assignment

Your ISP modem is xDSL? If yes, then put modem into bridge and configure everything in MikroTik router. 1) Start with DHCPv6 Client: /ipv6 dhcp-client add add-default-route=yes interface="PPPoE" pool-name=IPv6-pool use-peer-dns=no 2) Add DHCPv6 and address from pool to bridge-local: /ipv6 ...
by Pea
Wed Oct 28, 2015 11:33 pm
Forum: General
Topic: firewall/connections - what does the first column mean
Replies: 5
Views: 12099

Re: firewall/connections - what does the first column mean

Winbox can show you explanation as well - just keep mouse on this column and see popup.
by Pea
Sun Oct 18, 2015 9:06 pm
Forum: Beginner Basics
Topic: fasttrack dummy rule
Replies: 2
Views: 1727

Re: fasttrack dummy rule

Just reboot your router or wait till all fasttracked connections disappear.
by Pea
Thu Oct 01, 2015 12:26 am
Forum: Beginner Basics
Topic: IPv6 basic setup help
Replies: 4
Views: 1880

Re: IPv6 basic setup help

Hi Sob, now I got it, thank you for explanation.
I was confused by the same /64 prefix and unreachable route seemed to me unnecessary.
So I will ignore it and let it there :)
by Pea
Mon Sep 28, 2015 9:59 pm
Forum: Beginner Basics
Topic: IPv6 basic setup help
Replies: 4
Views: 1880

Re: IPv6 basic setup help

Thank you. But the #3 route is similar to #2 route which gets connected. So why there is another dynamic route created? 2 ADC 2a00:xxxx:yyyy:aaa::/64 bridge-local 0 3 DSU 2a00:xxxx:yyyy:aaa::/64 1 I have still no idea why they gave me second (WAN) IPv6/64 prefix, everything is working well only with...
by Pea
Sat Sep 26, 2015 12:53 am
Forum: Beginner Basics
Topic: IPv6 basic setup help
Replies: 4
Views: 1880

IPv6 basic setup help

I would like to ask you to revise my setting for IPv6 because this is new for me. I have very simple setup: ISP <=PPPoE=> VDSL modem (bridge) <=PPPoE client=> Mikrotik RB951G-2HnD <==> LAN+WiFi I got from my ISP this information for native IPv6: LAN: 2a00:xxxx:yyyy:aaa::/64 WAN: 2a00:xxxx:yyyy:aa8::...
by Pea
Sat Sep 12, 2015 1:18 pm
Forum: General
Topic: Mikrotik uploading massive amount of data without any computer attached
Replies: 6
Views: 4403

Re: Mikrotik uploading massive amount of data without any computer attached

Even if allow-remote-requests: no solved your problem you should secure your router by simple firewall rules: 1) Allow what you need (established, related, your LAN, pings) 2) Block everything else (this will also drop external DNS requests on port 53) Example rules: add chain=input comment="Ac...
by Pea
Sat Sep 05, 2015 9:36 am
Forum: Wireless Networking
Topic: Somebody trying to connect on my AP
Replies: 3
Views: 1266

Re: Somebody trying to connect on my AP

Do you have unique SSID?
Because if you have common (e.g. Internet) many devices will try to login when walking around because of previously stored login from other location.
Maybe SSID change will solve your problem.
by Pea
Tue Sep 01, 2015 12:06 am
Forum: General
Topic: What enables the wireless-fp package?
Replies: 6
Views: 2993

Re: What enables the wireless-fp package?

This is what I got when reading this forum: wireless - oldest package, discontinued? wireless-fp - new legacy package compared to previous has improved wireless driver, "wireless fast path" mode wireless-cm2 - CAPsMAN v2 support plus also has some improvements for newer 802.11ac and other ...
by Pea
Wed Aug 26, 2015 10:49 pm
Forum: General
Topic: protection at DDOS attack based on a bug in MikroTik routers
Replies: 18
Views: 4425

Re: protection at DDOS attack based on a bug in MikroTik routers

What is the problem with default config? /ip firewall { filter add chain=input action=accept protocol=icmp comment="default configuration" filter add chain=input action=accept connection-state=established in-interface=ether1-gateway comment="default configuration" filter add chai...
by Pea
Tue Aug 25, 2015 9:56 pm
Forum: Beginner Basics
Topic: DHCP and DNS
Replies: 3
Views: 1222

Re: DHCP and DNS

IP > DHCP Server > Networks > change DNS Servers address to 192.168.1.1
by Pea
Wed Aug 12, 2015 9:36 pm
Forum: Wireless Networking
Topic: this is my problem
Replies: 3
Views: 1380

Re: this is my problem

1) open tp-link administration page
2) click DHCP from menu
3) click Disable option
4) click Save button

clear enough?
by Pea
Mon Jul 27, 2015 9:46 pm
Forum: Beginner Basics
Topic: Slow internet with firewall.
Replies: 15
Views: 7487

Re: Slow internet with firewall.

If you do not use simple queues etc. you can enable Fasttrack to increase your speed (ROS 6.29 and newer). Just put this rule above other firewall rules: /ip firewall filter add chain=forward action=fasttrack-connection connection-state=established,related That Fasttrack is enabled you can check und...
by Pea
Sun Jul 26, 2015 9:17 pm
Forum: Beginner Basics
Topic: Slow internet with firewall.
Replies: 15
Views: 7487

Re: Slow internet with firewall.

Just click both established and related in WinBox...
by Pea
Fri Jul 17, 2015 11:29 pm
Forum: Beginner Basics
Topic: Hairpin NAT issue
Replies: 7
Views: 2600

Re: Hairpin NAT issue

I had exactly same issue when accessing home server by DNS name. First I was using static DNS but I must use port in browsers and there were issues with some mobile browsers. So I started to use masquerade for LAN access instead and everything is working perfect. (Only one small side effect - all ac...