Community discussions

MikroTik App

Search found 577 matches

  • 1
  • 2
by solar77
Mon Oct 12, 2020 12:20 pm
Forum: Beginner Basics
Topic: Help with setting up hAP ac lite
Replies: 1
Views: 124

Re: Help with setting up hAP ac lite

not 100% clear what you trying to do but here is my assumption: connect the hAP AC Lite to an existing wifi connect xbox etc. to the hAP AC by wire here is what you need to do on the hAP AC: 1. remove wlan1 or wlan 2 from the local bridge. which one? depending what the existing wiFi is. if it is 2.4...
by solar77
Mon Oct 12, 2020 12:10 pm
Forum: Beginner Basics
Topic: Dual ISP - Need One PC on the Secondary FailOver [SOLVED]
Replies: 15
Views: 526

Re: Dual ISP - Need One PC on the Secondary FailOver [SOLVED]

@Sob
thank you for detailed explanation! That's why I keep coming back to this forum !
by solar77
Fri Oct 09, 2020 12:51 pm
Forum: Beginner Basics
Topic: Trying to understand my LTE Kit6 vs my ISP's ZTE modem
Replies: 2
Views: 135

Re: Trying to understand my LTE Kit6 vs my ISP's ZTE modem

I had SXT LTE6 doing the same but it was on a previous firmware. I've changed to SXT LTE4 at same location it stay connected on without any issue.
but I remember reading it here that this bug is fixed in the most recent firmware. Will see what others say.
by solar77
Fri Oct 09, 2020 12:00 pm
Forum: Beginner Basics
Topic: Dual ISP - Need One PC on the Secondary FailOver [SOLVED]
Replies: 15
Views: 526

Re: Dual ISP - Need One PC on the Secondary FailOver [SOLVED]

I'd think this should also work?
/ip firewall mangle
add action=route chain=prerouting passthrough=no route-dst=gateway_ISP2 src-address=IP_of_PC
by solar77
Fri Oct 09, 2020 11:53 am
Forum: Beginner Basics
Topic: Dual ISP - Need One PC on the Secondary FailOver [SOLVED]
Replies: 15
Views: 526

Re: Dual ISP - Need One PC on the Secondary FailOver [SOLVED]

Something like this should do the trick:
/ip route rule
add action=lookup interface=<your new special vlan> table=<routing table containing default route to secondary ISP>
I have learned something new today! thank you!
by solar77
Fri Oct 09, 2020 10:56 am
Forum: Beginner Basics
Topic: Can't access hosts via certain ports from a computer connected to an hEX-S
Replies: 15
Views: 459

Re: Can't access hosts via certain ports from a computer connected to an hEX-S

the problem is certainly the hEX-s. without looking at your config. it's very difficult to guess what might have gone wrong. as soon as you mentioned "I can successfully connect to the hEX-S and machines behind it, just not the other way around.", it started sound like a dst-nat issue. if you setup ...
by solar77
Tue Sep 29, 2020 2:26 pm
Forum: General
Topic: Malware on Mikrotik output chain?
Replies: 1
Views: 183

Malware on Mikrotik output chain?

we have been informed by our ISP that there are Malware attached originated from our public IP. Dst IP are only few so I've added them to a list and added firewall rule in forward, output and Mangle - Postrouting chain , trying to catch which LAN IP is doing this /ip firewall filter add action=add-s...
by solar77
Tue Jun 16, 2020 1:55 pm
Forum: Beginner Basics
Topic: Miktotik scripting get/print bytes from specific rules
Replies: 1
Views: 470

Re: Miktotik scripting get/print bytes from specific rules

:local variable [/ip firewall mangle get number=1 bytes] :log info $variable; this gives you the value on rule number 1. you can also use find where and use a condition to find a rule but make sure the result is only one rule, otherwise the logic breaks down here: you cannot assign mutiple values t...
by solar77
Sun Jun 14, 2020 1:24 pm
Forum: Beginner Basics
Topic: DHCP clients join VLAN [SOLVED]
Replies: 2
Views: 649

Re: DHCP clients join VLAN [SOLVED]

by solar77
Thu Jun 11, 2020 10:38 pm
Forum: General
Topic: Feature requests
Replies: 1279
Views: 290073

Re: Feature requests

Imagine you have a service for users from your own country only. this is was nearly my user-case. a local WISP. and at one point it was very attempting to do so to fence off all failed authentication to our VPN service. Most of them are from one country. However, I realized that we cannot just bloc...
by solar77
Thu Jun 11, 2020 10:17 pm
Forum: Beginner Basics
Topic: Hairpin with port forwarding
Replies: 14
Views: 1991

Re: Hairpin with port forwarding

the Mikrotik Doc seems new. will have a nose around later on. but as for hairpin explanation, the old wiki does a better job :-)
by solar77
Thu Jun 11, 2020 8:15 pm
Forum: General
Topic: Feature requests
Replies: 1279
Views: 290073

Re: Feature requests

good firewall rule stops attacks, picks up IP of attacker, keep them in your Address List for as long as you want and block all future attacks from the same IP.
I'd like to see the IP cloud to include a function so that we can all share these IP address. that would be nice!
by solar77
Thu Jun 11, 2020 6:11 pm
Forum: General
Topic: Routerboard FTTH 1Gbps
Replies: 3
Views: 545

Re: Routerboard FTTH 1Gbps

check the Test Result section of each product on Mikrotik website.
for example
https://mikrotik.com/product/rb4011igs_ ... estresults
by solar77
Thu Jun 11, 2020 5:00 pm
Forum: Forwarding Protocols
Topic: Selective routing with failover in MikroTik - How?
Replies: 2
Views: 695

Re: Selective routing with failover in MikroTik - How?

2nd non-routing export. I am here because anav messaged me... scenario A, I suggest to use bounding, which respond to line failure quickly, unlike OSPF scenario B. I think I would use OSPF and let it figure out the best path but BGP , from what I understand, would be quicker to recover in the event ...
by solar77
Thu Jun 11, 2020 12:39 pm
Forum: Beginner Basics
Topic: Hairpin with port forwarding
Replies: 14
Views: 1991

Re: Hairpin with port forwarding

@anav I think he wants to use the same public IP to reach the server, whether the laptop is connected to the LAN, or on another internet connection.

as mentioned hairpin NAT address this exact issue. if Steve's video is not clear enough, here is more detail:
https://wiki.mikrotik.com/wiki/Hairpin_NAT
by solar77
Wed Jun 10, 2020 9:11 pm
Forum: Beginner Basics
Topic: 2 WANs, switching when there's no Internet
Replies: 4
Views: 927

Re: 2 WANs, switching when there's no Internet

looks like you did not specify scope and target-scope

have a look here:
viewtopic.php?f=23&t=157048

and more details here
https://wiki.mikrotik.com/wiki/Manual:U ... attributes
by solar77
Wed Jun 10, 2020 7:56 pm
Forum: Beginner Basics
Topic: Hairpin with port forwarding
Replies: 14
Views: 1991

Re: Hairpin with port forwarding

good video tutorial
https://www.youtube.com/watch?v=_kw_bQyX-3U&t=177s

or specify in-interface (to be your WAN interface) on your dst-nat rule so you don't mess up LAN connection to the private IP.
by solar77
Wed Jun 10, 2020 2:44 pm
Forum: Beginner Basics
Topic: Redundant WAN, Prefer ether1 over wlan1
Replies: 25
Views: 2388

Re: Redundant WAN, Prefer ether1 over wlan1

thank you for the test as well!
by solar77
Wed Jun 10, 2020 12:40 pm
Forum: Beginner Basics
Topic: Redundant WAN, Prefer ether1 over wlan1
Replies: 25
Views: 2388

Re: Redundant WAN, Prefer ether1 over wlan1

glad it worked for you. I got my head stuck in trying to figure out the routing part, only realized bounding is the answer as I type up the last reply.

it would interesting to find how smooth the fail-over is and test if it causes noticeable drop in voip call or online gaming.
by solar77
Tue Jun 09, 2020 7:19 pm
Forum: Beginner Basics
Topic: Site to Site VPN with one router behind NAT
Replies: 3
Views: 670

Re: Site to Site VPN with one router behind NAT

Q: Is it possible to make a VPN between those two, so that MIKROTIK 2 initialize connection to MIKROTIK 1, and Yes, even if the hotel blocks / throttles VPN, you can still use SSTP between Mikrotiks. using port 443, they could not block it. More advanced firewall can, but realy don't think a Hotel h...
by solar77
Tue Jun 09, 2020 6:11 pm
Forum: Beginner Basics
Topic: LTE6 Setup / Config
Replies: 2
Views: 570

Re: LTE6 Setup / Config

sorry my crystal ball isn't working today, won't be able to help unless you tell me what you need help with. :lol:
also there is no need to post the same question mutiple times.
by solar77
Tue Jun 09, 2020 2:24 pm
Forum: Beginner Basics
Topic: Redundant WAN, Prefer ether1 over wlan1
Replies: 25
Views: 2388

Re: Redundant WAN, Prefer ether1 over wlan1

static route should work , mikrotik need 3 things to get wan interface working: route, correct IP on the interface and NAT. I will setup a lab test and see how to get it working. no pint me trying suggesting something I am not 100% sure. in the meantime, I think a simple bounding would definitely wo...
by solar77
Sun Jun 07, 2020 1:42 pm
Forum: General
Topic: SXTsq_Lite2 with RB2011 setup [SOLVED]
Replies: 11
Views: 2269

Re: SXTsq_Lite2 with RB2011 setup [SOLVED]

what is the negative impact of leaving it with srcnat set as masquerade on the RB2011 check if the traffic counter on this rule is increasing, if yes, it is "effective" and bascaly it means your outgoing traffic is still NATed into the WAN address of the RB2011. in plain words, this rule changes yo...
by solar77
Fri Jun 05, 2020 4:52 pm
Forum: General
Topic: PPOE user disconnecting [SOLVED]
Replies: 7
Views: 1167

Re: PPOE user disconnecting [SOLVED]

torch the interface and you can see what these traffic is that is the source and destination IP , port etc. when in winbox, right click on the interface , then select torch as for firewall , default firewall rule is pretty good out of the box. basically, on input chain, you accept established and re...
by solar77
Fri Jun 05, 2020 1:55 pm
Forum: General
Topic: two pppoe connections, question?
Replies: 7
Views: 1200

Re: two pppoe connections, question?

so if I understand correctly, you have two pppoe account, through two ports on the same device (a modem?). yes the CRS326 can be used to establish two pppoe connections and use them as you described. However, CRS326 is an exlent switch, but less of a router. Its routing capacity is limited. looking ...
by solar77
Fri Jun 05, 2020 12:54 pm
Forum: Beginner Basics
Topic: Signaling other computers when a specific amount of runtime is left in a connected UPS
Replies: 2
Views: 605

Re: Signaling other computers when a specific amount of runtime is left in a connected UPS

https://wiki.mikrotik.com/wiki/Manual:System/UPS

once connected, you need a script to monitor min-runtime and send email , unless you have SNMP to monitor your network devices.
by solar77
Fri Jun 05, 2020 12:38 pm
Forum: Beginner Basics
Topic: Redundant WAN, Prefer ether1 over wlan1
Replies: 25
Views: 2388

Re: Redundant WAN, Prefer ether1 over wlan1

I guess this is something to do with the fact both DHCP client share the same gateway, and DHCP server. so when the route changes, the gateway 192.168.144.254 remains the same So they are connecting to the same router for Internet access ? I assume you want some redundancy if ether1 fails. in this c...
by solar77
Fri Jun 05, 2020 11:50 am
Forum: General
Topic: SXTsq_Lite2 with RB2011 setup [SOLVED]
Replies: 11
Views: 2269

Re: SXTsq_Lite2 with RB2011 setup [SOLVED]

If you only want to use the RB2011 as a switch , NAT needs to be disabled on the RB2011. disable firewall rule, remove all NAT rule add all port to one bridge and enable hardware offloading, beware there are two switch chips on the RB2011. The left 5 Gigabit ports are on one switch chip and the 5 x ...
by solar77
Thu Jun 04, 2020 9:50 pm
Forum: General
Topic: SXTsq_Lite2 with RB2011 setup [SOLVED]
Replies: 11
Views: 2269

Re: SXTsq_Lite2 with RB2011 setup [SOLVED]

I'd agree. Unless there is another reason, you don't need two routers both being "router". you might think the RB2011 is more capable as a router and leaving the SXT just to be CPE. But look at the spec, SXT lite2 actually has got better CPU, same RAM, less storage (yes but you don't really need it)...
by solar77
Thu Jun 04, 2020 9:10 pm
Forum: Beginner Basics
Topic: Redundant WAN, Prefer ether1 over wlan1
Replies: 25
Views: 2388

Re: Redundant WAN, Prefer ether1 over wlan1

@dke yes I understand what your request is. I think, with distance on ether1 set to 1 and distance on wlan1 set to 2, as long as ether1 is running, Mikrotik will route all traffic through ether1. this is what you want yes? you will see both route showing up in routing table and both can be dynamic /...
by solar77
Thu Jun 04, 2020 5:41 pm
Forum: Beginner Basics
Topic: ltAp .. assign APN to Sim Slot ... howto ?
Replies: 12
Views: 1151

Re: ltAp .. assign APN to Sim Slot ... howto ?

human, you want them all do you? 8) unless you know exactly when it will be disconnected, there is always a chance the swap will be triggered by this disconnection. you can add another script, check which slot is active and force the system to use your main SIM, run this every 12 hours. again, plan ...
by solar77
Thu Jun 04, 2020 3:56 pm
Forum: General
Topic: PPOE user disconnecting [SOLVED]
Replies: 7
Views: 1167

Re: PPOE user disconnecting [SOLVED]

OK, next
check pppoe client has correct authentication and credential

turn on ppp in system - logging, see more details as of why it won't establish a connection.
by solar77
Thu Jun 04, 2020 3:38 pm
Forum: Beginner Basics
Topic: Redundant WAN, Prefer ether1 over wlan1
Replies: 25
Views: 2388

Re: Redundant WAN, Prefer ether1 over wlan1

no need to enforce, once you see the correct route is black, that means it's active, and that's what the route for your internet uplink. the other fail-over route, is blue, and while it is reachable, no traffic is routed towards this gateway. to test, just type what is my ip address on google, it te...
by solar77
Thu Jun 04, 2020 2:25 pm
Forum: Beginner Basics
Topic: 192.168.88.1 Shows Unreasonable [SOLVED]
Replies: 28
Views: 3048

Re: 192.168.88.1 Shows Unreasonable [SOLVED]

no problem. remember the change the password and make backup.
by solar77
Thu Jun 04, 2020 2:08 pm
Forum: Beginner Basics
Topic: ltAp .. assign APN to Sim Slot ... howto ?
Replies: 12
Views: 1151

Re: ltAp .. assign APN to Sim Slot ... howto ?

Glad to help.
by solar77
Thu Jun 04, 2020 1:42 pm
Forum: General
Topic: SXTsq_Lite2 with RB2011 setup [SOLVED]
Replies: 11
Views: 2269

Re: SXTsq_Lite2 with RB2011 setup [SOLVED]

two things I have picked up: 1. both the sXT and the RB2011 are using the same LAN subnet. so for the RB2011, the WAN gateway is 192.168.88.x and the LAN subnet is also 192.168.88.0/24 I would change one of the subnet to something different. 2. on the RB2011, you are using bridge1 as your WAN interf...
by solar77
Thu Jun 04, 2020 1:21 pm
Forum: General
Topic: PPOE user disconnecting [SOLVED]
Replies: 7
Views: 1167

Re: PPOE user disconnecting [SOLVED]

sounds like poor / unstable wifi connection between the client and the router.
try connect by network cable to see what happens.
by solar77
Thu Jun 04, 2020 1:00 pm
Forum: Beginner Basics
Topic: EE SIM [SOLVED]
Replies: 25
Views: 4910

Re: EE SIM [SOLVED]

Hi there CStech, I was wondering could you explain how I would go about changing the APN for the EE Sim Card in The LTX,

Regards
kmac
see this post
by solar77
Thu Jun 04, 2020 12:56 pm
Forum: Beginner Basics
Topic: Redundant WAN, Prefer ether1 over wlan1
Replies: 25
Views: 2388

Re: Redundant WAN, Prefer ether1 over wlan1

Routes shows two 0.0.0.0/0 routes
Yes it will do this as both are available. but in Winbox you will see one is black (active) and one is blue (inactive)
by solar77
Thu Jun 04, 2020 12:49 pm
Forum: Beginner Basics
Topic: ltAp .. assign APN to Sim Slot ... howto ?
Replies: 12
Views: 1151

Re: ltAp .. assign APN to Sim Slot ... howto ?

/tool netwatch add down-script=":log warning \" Internet Down swapSIM\";\r\ \n/system script run swapSIM;\r\ \n" host=8.8.8.8 interval=30m timeout=2s up-script=":log warning \" Internet Up \";" where swapSIM is the name of the script I find it more manageable this way, instead of dump all the scrip...
by solar77
Thu Jun 04, 2020 12:36 pm
Forum: Beginner Basics
Topic: ltAp .. assign APN to Sim Slot ... howto ?
Replies: 12
Views: 1151

Re: ltAp .. assign APN to Sim Slot ... howto ?

i use netwatch, so if a ping to external IP address, say 8.8.8.8, is more than 100ms, I swap SIM. I set the interval to 30 minutes but you can set it how you like it, just remember the swap itself would take few minutes, depending how quickly the other SIM can register on the network, so you don't w...
by solar77
Thu Jun 04, 2020 12:11 pm
Forum: Beginner Basics
Topic: ltAp .. assign APN to Sim Slot ... howto ?
Replies: 12
Views: 1151

Re: ltAp .. assign APN to Sim Slot ... howto ?

this is the script I use to swap SIM when the internet is down, sort of fail-over. #get SIM info and swap :local sim set $sim [/system routerboard modem get sim-slot]; :if ($sim = "a") do={ :log warning "SIM A is active, now switching to B"; /interface set lte1 disabled=no; :delay 1; /interface lte ...
by solar77
Thu Jun 04, 2020 11:26 am
Forum: Beginner Basics
Topic: 192.168.88.1 Shows Unreasonable [SOLVED]
Replies: 28
Views: 3048

Re: 192.168.88.1 Shows Unreasonable [SOLVED]

in this case I would suggest to reset the Mikrotik and re-configure.
by solar77
Thu Jun 04, 2020 11:25 am
Forum: Beginner Basics
Topic: ltAp .. assign APN to Sim Slot ... howto ?
Replies: 12
Views: 1151

Re: ltAp .. assign APN to Sim Slot ... howto ?

I do this with script . create APN profile for each SIM and the script would swap slot as well as assign correct APN .
otherwise , as soon as you change one of them remotely, you have no Internet.
by solar77
Thu Jun 04, 2020 10:42 am
Forum: Beginner Basics
Topic: 192.168.88.1 Shows Unreasonable [SOLVED]
Replies: 28
Views: 3048

Re: 192.168.88.1 Shows Unreasonable [SOLVED]

have you tried to connect a laptop directly to the LAN port of the POE injector, open winbox, do you see the Mikrotik appear on neighbors section ? this way you bypass Tenda and on the same Layer2 network as the Mikrotik, it should show up on neighbors section and you can connect to Mikrotik devices...
by solar77
Wed Jun 03, 2020 6:49 pm
Forum: Beginner Basics
Topic: Set multipe DHCP severs on Bridged Interface
Replies: 9
Views: 1513

Re: Set multipe DHCP severs on Bridged Interface

good luck.
let us know if you have a problem
by solar77
Wed Jun 03, 2020 6:00 pm
Forum: Beginner Basics
Topic: Set multipe DHCP severs on Bridged Interface
Replies: 9
Views: 1513

Re: Set multipe DHCP severs on Bridged Interface

first I can tell you how to do it. then I explain why you shouldn't do it. first take these port out of the bridge assign IP address to each port, 192.168.2.1/24, for example create DHCP server on each port by this point, you have achieved what you were asked for and Mikrotik will allow communicatio...
by solar77
Wed Jun 03, 2020 2:06 pm
Forum: Beginner Basics
Topic: 192.168.88.1 Shows Unreasonable [SOLVED]
Replies: 28
Views: 3048

Re: 192.168.88.1 Shows Unreasonable [SOLVED]

connect a laptop directly to the router and see if you can see the Mikrotik in winbox's neighbors section ? if yes, click on the MAC address . this does not require an correct IP address to be used. Please connect a laptop directly to the LAN port of the POE injector, open winbox, do you see the Mi...
by solar77
Wed Jun 03, 2020 1:57 pm
Forum: Beginner Basics
Topic: How to pass through to router via public IP
Replies: 30
Views: 4067

Re: How to pass through to router via public IP

@AidasA My dear friend, the forum is where people give general advice, rather than do it for you. I can offer more details but it worries me, when you say you don't know how to create a VPN. I can see that you lack basic understanding to the Mikrotik and strongly suggest start searching on Mikrotik ...
by solar77
Wed Jun 03, 2020 1:18 pm
Forum: Beginner Basics
Topic: LHG LTE6 kit - how to find BTS id number and bandwith I'm currently using?
Replies: 4
Views: 698

Re: LHG LTE6 kit - how to find BTS id number and bandwith I'm currently using?

@SiB
I will be at MUMEUROPE Prague on ?? ?? 202?
interesting 8)
why not have a virtual MUM?
by solar77
Tue Jun 02, 2020 9:11 pm
Forum: Beginner Basics
Topic: How to pass through to router via public IP
Replies: 30
Views: 4067

Re: How to pass through to router via public IP

What I suppose to do if I get a private IP to my SIM, means Mikrotik and public IP address which is shared?:( then you set up the whole VPN topology, basically the Mikrotik LTE start the VPN as a client, then you can access the client from the VPN server side. not worth doing for only a few, in my ...
by solar77
Tue Jun 02, 2020 7:50 pm
Forum: Beginner Basics
Topic: 192.168.88.1 Shows Unreasonable [SOLVED]
Replies: 28
Views: 3048

Re: 192.168.88.1 Shows Unreasonable [SOLVED]

connect a laptop directly to the router and see if you can see the Mikrotik in winbox's neighbors section ? if yes, click on the MAC address .
this does not require an correct IP address to be used.
by solar77
Tue Jun 02, 2020 5:40 pm
Forum: Beginner Basics
Topic: characteristics for a pop router, and opinion about first design for a new wisp
Replies: 3
Views: 551

Re: characteristics for a pop router, and opinion about first design for a new wisp

check Mikrotik official website, each product has a test result section, I generaly see the routing 25 filter rule 512 bytes more close to real throughput: I would say the RB4011 should fit if your budget is tight but would suggest a basic CCR for your core network. https://mikrotik.com/product/rb40...
by solar77
Tue Jun 02, 2020 4:48 pm
Forum: Beginner Basics
Topic: How to pass through to router via public IP
Replies: 30
Views: 4067

Re: How to pass through to router via public IP

PS: try not share your own public IP on the forum. None of us need to know this information and I'd suggest you to double check your firewall before using this IP. :) on second thought, when you mentioned that you are using 100s SIMs, do you need remote access to all of them? If yes, the cost implic...
by solar77
Tue Jun 02, 2020 4:45 pm
Forum: Beginner Basics
Topic: How to pass through to router via public IP
Replies: 30
Views: 4067

Re: How to pass through to router via public IP

this command is to be used in Terminal . can be accessed either via winbox, or webfig yes you need a static IP but essentially you need an public IP that is assigned to the Mikrotik router, meaning this IP belongs to you, even temporarily. what will direct access to your Mikrotik router: static publ...
by solar77
Tue Jun 02, 2020 4:32 pm
Forum: Beginner Basics
Topic: 192.168.88.1 Shows Unreasonable [SOLVED]
Replies: 28
Views: 3048

Re: 192.168.88.1 Shows Unreasonable [SOLVED]

it could be a number of things.but first and easiest is to download winbox and try access the Mikrotik
failing that, use ssh or telnet

I can't help thinking your son might also be on this forum. that would be funny :lol: :lol:

once you get into it, make an backup and change the password.
by solar77
Tue Jun 02, 2020 4:18 pm
Forum: Beginner Basics
Topic: LHG LTE6 kit - how to find BTS id number and bandwith I'm currently using?
Replies: 4
Views: 698

Re: LHG LTE6 kit - how to find BTS id number and bandwith I'm currently using?

/interface lte info lte1 once
type this in the Mikrotik terminal
by solar77
Tue Jun 02, 2020 3:03 pm
Forum: Beginner Basics
Topic: [Problem] Firewall block for everyone except one ip adress [SOLVED]
Replies: 1
Views: 560

Re: [Problem] Firewall block for everyone except one ip adress [SOLVED]

create accept rule for this IP address and drag it above all the block rules
by solar77
Mon Jun 01, 2020 3:04 pm
Forum: Beginner Basics
Topic: How to pass through to router via public IP
Replies: 30
Views: 4067

Re: How to pass through to router via public IP

get the static public IP, open up port forwarding to your base station as per this example: https://wiki.mikrotik.com/wiki/Manual:IP/Firewall/NAT#Port_forwarding_to_internal_FTP_server something like this, and change hte protocol to UDP if that is the case. /ip firewall nat add chain=dstnat dst-addr...
by solar77
Fri May 29, 2020 12:48 pm
Forum: Beginner Basics
Topic: [solved] dhcp-client at WAN is stuck with status searching [SOLVED]
Replies: 11
Views: 2832

Re: [solved] dhcp-client at WAN is stuck with status searching [SOLVED]

Glad you found the fix. Sorry I find it a bit funny, the problem was that you named a Mikrotik hEX "hex"... :lol: :lol: :lol:
by solar77
Thu May 28, 2020 5:54 pm
Forum: Beginner Basics
Topic: [solved] dhcp-client at WAN is stuck with status searching [SOLVED]
Replies: 11
Views: 2832

Re: dhcp-client at WAN is stuck with status searching [SOLVED]

hostname and clientid are standared. this is to say what the DHCP server would look for when give IP address looks like the DHCP server is actively refusing to give 192.168.1.10 to ether2 of the Mikrotik please check and ensure there is not another client , either static or DHCP, on the same router ...
by solar77
Thu May 28, 2020 1:40 pm
Forum: Beginner Basics
Topic: Router Public IP
Replies: 2
Views: 483

Re: Router Public IP

@kohral good writing work. I actually enjoyed reading it. althrough I am not 100% clear on what you meant by The remaining two external static IPs are makes not available for pings. So after every reboot router randomly changes its public IP and Zabbix gets error that "ICMP ping is unavailable" but ...
by solar77
Thu May 28, 2020 1:16 pm
Forum: Beginner Basics
Topic: [solved] dhcp-client at WAN is stuck with status searching [SOLVED]
Replies: 11
Views: 2832

Re: dhcp-client at WAN is stuck with status searching [SOLVED]

interesting problem and I don't have an answer to. maybe some of the options in DHCP client but that's pure guess.

what if you give it an static IP, would it hold it without fail?
by solar77
Thu May 28, 2020 12:53 pm
Forum: Beginner Basics
Topic: three newbie questions [SOLVED]
Replies: 27
Views: 4269

Re: three newbie questions [SOLVED]

few things you have to understand: 1. firewall filter rules are inspected and actioned from top to bottom. so order is important. once the traffic matches one rule, it will be actioned accordingly and the reset of the rules will not apply this probably answers Question 4. 2. also , for the same reas...
by solar77
Thu May 28, 2020 12:33 pm
Forum: Beginner Basics
Topic: Deny ip PUBLIC traffic
Replies: 10
Views: 1922

Re: Deny ip PUBLIC traffic

try add this to the top of your firewall filter rules add action=drop chain=forward-from-internet comment=IPTEST log-prefix="IP MAIL BLOCK" \ src-address-list=IP_TEST not sure why you are using this jump rule but all the other rules on forward chain are still unchainged, so they will not apply to fo...
by solar77
Thu May 28, 2020 12:19 pm
Forum: Beginner Basics
Topic: How to pass through to router via public IP
Replies: 30
Views: 4067

Re: How to pass through to router via public IP

good to know. but in this case, even he assign local IP to DDNS record, he still won't be able to access his wAP LTE remotely (from the internet)
the simple way to get this to work, is that you need to buy a public IP from the ISP
by solar77
Wed May 27, 2020 4:57 pm
Forum: Beginner Basics
Topic: How to pass through to router via public IP
Replies: 30
Views: 4067

Re: How to pass through to router via public IP

indeed, the screen capture shows he is behind NAT and the last line gives the answer: "remote connection may not work"
looks like he's got an private IP from the ISP, normal for mobile network.
by solar77
Wed May 27, 2020 4:04 pm
Forum: Beginner Basics
Topic: How to pass through to router via public IP
Replies: 30
Views: 4067

Re: How to pass through to router via public IP

Please read my previous suggestion, in this very post! before we get into the practical method of accessing the router, either by VPN or port-forwarding, do you have a public accessible IP address? It does not seems to be the case by the look of it. from your post: 84.15.182.234, belongs to ISP:Bite...
by solar77
Tue May 26, 2020 6:13 pm
Forum: Beginner Basics
Topic: Accessing 4G modem with no public IP
Replies: 1
Views: 543

Re: Accessing 4G modem with no public IP

we do this at work. the solution is that we use a Mikrotik VPN server, where a number of 4G Mikrotik would connect to. our office router also VPN into the same server and we are able to access any of the 4G modem or router behind satellite connections. if you want to access the 4G modem from a PC wh...
by solar77
Tue May 26, 2020 6:01 pm
Forum: Beginner Basics
Topic: Restart a device via R J45 port?
Replies: 1
Views: 482

Re: Restart a device via R J45 port?

My question is: Is it possible to restart the endpoint device which has a link with router ( RJ 45 cable between) via RouterOs or Winbox? Mikrotik routerOS has build-in SSH and Telnet client, so if your endpoint device can be restarted via either, then you can do this from the Mikrotik. Further, I ...
by solar77
Fri May 22, 2020 9:00 pm
Forum: Beginner Basics
Topic: Ideas for S2S with internet centralization [SOLVED]
Replies: 5
Views: 1450

Re: Ideas for S2S with internet centralization [SOLVED]

what is the upload capacity at HQ? as this will also limit the download capacity for your Branch. assuming it's more than 10 Mbps. hardware looks fine to me but other experts feel free to comment. as for mangle, you could look at https://wiki.mikrotik.com/wiki/Per-Traffic_Load_Balancing#Step_3_-_Usi...
by solar77
Fri May 22, 2020 8:52 pm
Forum: Beginner Basics
Topic: Deny ip PUBLIC traffic
Replies: 10
Views: 1922

Re: Deny ip PUBLIC traffic

you need to also drop these traffic on Forward chain, that is where traffic is flowing through the router, in this case, from the Internet, through the router, to your server. The input chain, is traffic that is heading to the router itself , for example, traffic heading to the VPN server on the rou...
by solar77
Fri May 22, 2020 1:04 pm
Forum: Beginner Basics
Topic: Ideas for S2S with internet centralization [SOLVED]
Replies: 5
Views: 1450

Re: Ideas for S2S with internet centralization [SOLVED]

your plan is do-able and might be easier than you think. lets assume few things: site A (HQ) and site B (Branch) both has static IP and good internet connection, not just download but also upload bandwidth as well. What is good? depending on your application. also to do IPSec you need good performan...
by solar77
Fri May 22, 2020 12:21 pm
Forum: Beginner Basics
Topic: How to pass through to router via public IP
Replies: 30
Views: 4067

Re: How to pass through to router via public IP

thank you for letting us know it's working. Many poster won't feedback on our suggestions which is a shame.
not important to vote a solution, it's not like we would get paid for it :lol:
by solar77
Thu May 21, 2020 2:29 pm
Forum: Beginner Basics
Topic: Changing Manufacturer and Model Name [SOLVED]
Replies: 8
Views: 1934

Re: Changing Manufacturer and Model Name [SOLVED]

I assume OP is concerned that the mobile mobile carrier only allows him to use the SIM in a smart device, not tethered, not in a 4G modem. one of the things they can do is to detect change in TTL, which will decrease after traffic going through a router. then the fix is to increase TTL by 1 or set T...
by solar77
Thu May 21, 2020 1:42 pm
Forum: Beginner Basics
Topic: How to pass through to router via public IP
Replies: 30
Views: 4067

Re: How to pass through to router via public IP

Greetings to Mikrotik user from Ho Chi Minh City! Once pppoe established, interface <pppoe-out1> has local address: 100.91.214.57 and remote address: 100.123.1.62. The dynamic public ip: 183.80.67.230 looks like you don't have a public IP, the one you are using, is shared between a number of users o...
by solar77
Thu May 21, 2020 1:28 pm
Forum: Beginner Basics
Topic: Joining 2 networks
Replies: 19
Views: 2490

Re: Joining 2 networks

I would not use the Cisco if it is only 100Mbps. The RB2011 surely will do better than that. My guess is that you can reach 200 Mbps to 400 Mbps throughput: https://mikrotik.com/product/RB2011UiAS-2HnD-IN#fndtn-testresults so a user case is important here, for example, if you have large amount of da...
by solar77
Tue May 19, 2020 6:45 pm
Forum: Beginner Basics
Topic: Splitting up ports
Replies: 14
Views: 1831

Re: Splitting up ports

en..in this scenario I would use a wsAP ac lite, or a gigabit port version when it comes Lets say for some reason I do need to connect 4 devices over SFP, I'd get 4 x SPE to Base-T dongles. is it the BASE-T side goes to the device and the SPE side goes to one pair of UTP / STP cable that leads to th...
by solar77
Tue May 19, 2020 5:24 pm
Forum: Beginner Basics
Topic: Does RouterOS block NTP traffic by default? [SOLVED]
Replies: 23
Views: 3256

Re: Does RouterOS block NTP traffic by default? [SOLVED]

yes I was expecting the Src port to be a random port, just like when you use web service at 80 or 443, the traffic would be leaving your private IP from port xxxx. windows 10 PC is connecting to time.windows.com I have setup my mikroitk as : /system ntp client set enabled=yes server-dns-names=2.uk.p...
by solar77
Tue May 19, 2020 5:13 pm
Forum: Beginner Basics
Topic: Splitting up ports
Replies: 14
Views: 1831

Re: Splitting up ports

who said this converter will be in the server room? SPE is new to me, just watched few page and video. it seems to be the technology for industrial IoT use. no point for me to guess what should and what would I'd be interested to know how you managed to split a Ethernet connection and how the perfor...
by solar77
Tue May 19, 2020 4:58 pm
Forum: Beginner Basics
Topic: Does RouterOS block NTP traffic by default? [SOLVED]
Replies: 23
Views: 3256

Re: Does RouterOS block NTP traffic by default? [SOLVED]

@mutluit
192.168.90.98:123 is my PC, which would be an NTP client
also I tested setup the NTP client within Mikrotik, log shows the Mikrotik also use Src Port 123 as well.
by solar77
Tue May 19, 2020 4:39 pm
Forum: Beginner Basics
Topic: Splitting up ports
Replies: 14
Views: 1831

Re: Splitting up ports

SPE, single pair ethernet, seem interesting but I'd expect some sort of converter to do the job. When it connected to the Mikrotik, it would just like adding a L2 switch to a Mikrotik ethernet port?
by solar77
Tue May 19, 2020 3:55 pm
Forum: Beginner Basics
Topic: Does RouterOS block NTP traffic by default? [SOLVED]
Replies: 23
Views: 3256

Re: Does RouterOS block NTP traffic by default? [SOLVED]

No Mikrotik does not block NTP by default yes Mikrotik seems to want to use 123 as Src. Port. Interesting.... to check Mikrotik has send NTP packat from your PC, add a filrewall rule to show what's going on: in terminal add: /ip firewall filter add action=accept chain=forward dst-port=123 log=yes pr...
by solar77
Tue May 19, 2020 3:21 pm
Forum: Beginner Basics
Topic: Joining 2 networks
Replies: 19
Views: 2490

Re: Joining 2 networks

OK....I assumed these two are in different locations, then both ADSL routers can VPN into the same Mikrotik which can forward traffic from one subnet to another. However, both routers needs to be able to do static routing as well so normal traffic would not have to through VPN if they where in the s...
by solar77
Mon May 18, 2020 3:30 pm
Forum: Beginner Basics
Topic: Admin access via the internet
Replies: 14
Views: 2189

Re: Admin access via the internet

before even getting into DDNS and VPN, lets start from the basics, how do you get your Internet? this lead to another question, do you have a public facing IP address? even dynamically (this is where DDNS could work for you) ? if you are on a 4G / LTE network, most likely, you get a private IP from ...
by solar77
Mon May 18, 2020 2:07 pm
Forum: Beginner Basics
Topic: Joining 2 networks
Replies: 19
Views: 2490

Re: Joining 2 networks

I have left my crystal ball in the office...

what OP want, is site to site VPN, hence the suggestion.
by solar77
Mon May 18, 2020 1:51 pm
Forum: Beginner Basics
Topic: LHG lte6 dns/link issues
Replies: 6
Views: 1118

Re: LHG lte6 dns/link issues

what if you un-tick B3 and use B7 only. top speed will be slower but hopefully less disconnection,.
there seems to be frequent speed drops and disconnection issues reported on the forum,
by solar77
Sun May 17, 2020 8:09 pm
Forum: Beginner Basics
Topic: Joining 2 networks
Replies: 19
Views: 2490

Re: Joining 2 networks

this is what you need:
https://wiki.mikrotik.com/wiki/Manual:I ... sec_tunnel

have a go and let us know if you run into problems

One of your Mikrotik router needs static Public IP, or at least have DDNS setup so it can be reached from the Internet.
by solar77
Sun May 17, 2020 7:24 pm
Forum: Beginner Basics
Topic: Variable 4G download speeds with Vodafone UK
Replies: 6
Views: 1231

Re: Variable 4G download speeds with Vodafone UK

yes band 20 is what I'd expect. do you notice any signal differences when speed were slow? when it is slow , if you put the SIM in the phone, do you get roughly the same speed? does your television mast move in strong wind? sorry it is a pain to do / check all these but there is no obvious answer to...
by solar77
Fri May 15, 2020 12:29 pm
Forum: Beginner Basics
Topic: Unifi Controller Nightmare !
Replies: 2
Views: 811

Re: Unifi Controller Nightmare !

Unifi APs need DHCP server on the same network, so it can get an IP address to start with. you also need the PC running the controller, to be on the same network, so it can see the discovery package, sent by the APs. so you should have both the AC Lite and the PC, connected to the LAN side of the Mi...
by solar77
Thu May 14, 2020 10:53 pm
Forum: Beginner Basics
Topic: Connection Dropping
Replies: 2
Views: 591

Re: Connection Dropping

The fact that you sometimes get good speed, means your NAT setup is correct. otherwise it would not work at all. I would personally use the SXT as a router and the other MT as WiFi access point but that's just me. It's just a personal thing and also I'd likely to power up the SXT from ether 5 of the...
by solar77
Thu May 14, 2020 10:35 pm
Forum: Beginner Basics
Topic: simple queue
Replies: 7
Views: 1449

Re: simple queue

consider this: when PC1 want 1Mbps and PC2 want 7 Mbps CZFan's approach will allow both PC to get the bandwidth they needed Yours, however, because both PCs are active, the queue system would give PC1 1Mpbs and limit PC2 to 5Mbps, while there are 4 Mbps that you are paying for with your hard-earned ...
by solar77
Thu May 14, 2020 3:13 pm
Forum: Beginner Basics
Topic: Variable 4G download speeds with Vodafone UK
Replies: 6
Views: 1231

Re: Variable 4G download speeds with Vodafone UK

Vodafone's words of wisdom are that the SIM has been registered on their network as 2G and therefore is the cause of the problem
You can easy check this ,just look at the LTE interface status on the LHG, it should say Evolved 3G (LTE)

What band are you on?
by solar77
Tue May 12, 2020 4:31 pm
Forum: Beginner Basics
Topic: Variable 4G download speeds with Vodafone UK
Replies: 6
Views: 1231

Re: Variable 4G download speeds with Vodafone UK

few possibilities: 1. more vodafone users are now connected to the same mast . Voda is offering unlimited SIMs so naturally these users would be "open tap" all the way 2. check your signal on the LHG, there is a chance the dish had moved slightly and you are not getting a good enough signal. some po...
by solar77
Tue May 12, 2020 4:02 pm
Forum: Beginner Basics
Topic: Flight Simulator Steam Edition (FSX) port forwarding
Replies: 2
Views: 669

Re: Flight Simulator Steam Edition (FSX) port forwarding

at first glance, your dst-nat rules, should have your WAN interface as their " in-interface", which is traffic coming from the Internet.

you have set "in-interface" to be your bridge, this is the reason
this will also forward their traffic on those ports to my PC
by solar77
Tue May 12, 2020 3:27 pm
Forum: Beginner Basics
Topic: PCQ shared bandwidth EXCEPT 1 PC
Replies: 1
Views: 729

Re: PCQ shared bandwidth EXCEPT 1 PC

Mark traffic to and from 192.168.104.114 with a different packet mark and set up queue tree accordingly. personally I would use simple queue, one queue with target of 192.168.104.114 (6M/4M), above the general PCQ rule (10M/10M). Mikrotik apply simple queue from the top to bottom this should work. s...
by solar77
Tue May 12, 2020 2:32 pm
Forum: Beginner Basics
Topic: DMZ IP adress assign
Replies: 1
Views: 657

Re: DMZ IP adress assign

you could try adding a source nat rule so traffic from the DMZ PC is masqueraded to 176.76.240.18

for example:
/ip firewall nat
add action=src-nat chain=srcnat out-interface=WAN src-address=192.168.1.5 to-addresses=176.76.240.18
where 192.168.1.5 is the IP of your DMZ PC
by solar77
Mon May 11, 2020 1:36 pm
Forum: Beginner Basics
Topic: Address range in firewall address list
Replies: 14
Views: 1790

Re: Address range in firewall address list

https://wiki.mikrotik.com/wiki/Manual:I ... dress_list

you can also do 192.168.1.10-192.168.1.20 , for example
 /ip firewall filter add chain=forward src-address=192.168.1.10-192.168.1.20 action=drop  
by solar77
Mon May 04, 2020 12:42 am
Forum: Beginner Basics
Topic: mikrotik x 2 - one address in the LAN
Replies: 24
Views: 3286

Re: mikrotik x 2 - one address in the LAN

thanks andriys I've been reading on SCA and yes the theory is that, if the whole network "pretends" to be a single AP then there is no "roaming" , the client is associated with the controller which will hand client devices over without it knowing. However, the reason I suggested the access list is o...
by solar77
Sun May 03, 2020 8:18 pm
Forum: Beginner Basics
Topic: mikrotik x 2 - one address in the LAN
Replies: 24
Views: 3286

Re: mikrotik x 2 - one address in the LAN

@andriys
so how do seamless roaming work in enterprise wifi networks? does it actively disconnect one client and in the hope it will come back to the strongest signal it can discover? or there is a more intelligent way so the AP tells the client devise more about when and who to switch over next?
by solar77
Sun May 03, 2020 12:02 pm
Forum: Beginner Basics
Topic: mikrotik x 2 - one address in the LAN
Replies: 24
Views: 3286

Re: mikrotik x 2 - one address in the LAN

when the client device is stationary, it should not be switching between APs. if you are talking about roaming, (walking through the building, disconnecting from one AP as the signal is too weak and re-connect to another AP), you will have a period of disconnection. seamless roaming, is a term where...
by solar77
Sat May 02, 2020 4:56 pm
Forum: Beginner Basics
Topic: mikrotik x 2 - one address in the LAN
Replies: 24
Views: 3286

Re: mikrotik x 2 - one address in the LAN

I'd start by removing access list, your device will decide when it's the best time to disconnect from a signal reduce transmit power, by increasing Antenna gain on 2.4GHz radio (so the Mikortik is told there is an more sensitive antenna, therefore reduce the transmit power) keep the 5G radio the sam...
by solar77
Fri May 01, 2020 9:02 pm
Forum: Beginner Basics
Topic: mikrotik x 2 - one address in the LAN
Replies: 24
Views: 3286

Re: mikrotik x 2 - one address in the LAN

yes these steps looks correct. what it will look like switching between wireless networks for these two mikrotik? the subnet 192.168.20.0/24, exist on the following physical interfaces as they are all connected and belongs to the same bridge on 1st Mikrotik : ehter 2 to ethe5 and wlan1 and wlan2 on ...
by solar77
Fri May 01, 2020 7:58 pm
Forum: Beginner Basics
Topic: mikrotik x 2 - one address in the LAN
Replies: 24
Views: 3286

Re: mikrotik x 2 - one address in the LAN

In contrast, mikrotik has created a new subnet 192.168.20.0/24. I would like it to stay that way. I would like two mikrotiki to form a separate network 192.168.20.0. so your first Mikrotik gets 192.168.10.2 on ether1 and its LAN subnet is 192.168.20.0/24 and you want the 2nd Mikrotik to stay in 192...
by solar77
Fri May 01, 2020 7:20 pm
Forum: Beginner Basics
Topic: mikrotik x 2 - one address in the LAN
Replies: 24
Views: 3286

Re: mikrotik x 2 - one address in the LAN

sounds like all you have to do is make the Mikrotik a switch + WiFi access point, then you will have one only subnet, all your IP address on the LAN will be in 192.168.20.0/24 I assume that your home router is doing the NAT, DHCP server, DNS server etc. so on both mikrotik, disable NAT, disable DHCP...
by solar77
Fri May 01, 2020 1:23 pm
Forum: Beginner Basics
Topic: Slowness for the first few seconds then fast on download
Replies: 17
Views: 2813

Re: Slowness for the first few seconds then fast on download

just tested on a cCR1009, Mikrotik bandwidth test TCP, 1Gbps uplink,
no difference with or without fast-track
by solar77
Fri May 01, 2020 12:53 pm
Forum: Beginner Basics
Topic: Slowness for the first few seconds then fast on download
Replies: 17
Views: 2813

Re: Slowness for the first few seconds then fast on download

interesting. i am thinking of two things: MTU , but this should have nothing to do with fast-track connection tracking: one thing different with fast-track, is that it bypass connection tracking, would this somehow slow down the process of speed testing server establish mutiple streams? that's why I...
by solar77
Fri May 01, 2020 12:45 pm
Forum: Beginner Basics
Topic: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]
Replies: 56
Views: 7622

Re: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]

run
/ ip firewall export
from Mikrotik Terminal
by solar77
Fri May 01, 2020 12:36 pm
Forum: General
Topic: How to adapt dual LTE / DSL balance over day due to COVID home workers (over) loading LTE network
Replies: 5
Views: 1408

Re: How to adapt dual LTE / DSL balance over day due to COVID home workers (over) loading LTE network

you can also try this https://forum.mikrotik.com/viewtopic.php?t=132233 using Mikrotik bandwidth test result and then save the outcome as global variable, use it to adjust your routing / queue downside is speed test along with live internet traffic is not accurate, I don't think you want to stop all...
by solar77
Fri May 01, 2020 11:32 am
Forum: Beginner Basics
Topic: Reverse SSH Tunnel
Replies: 2
Views: 1237

Re: Reverse SSH Tunnel

yes you can. using the same principle, use Mikrotik as a router, (or even just within the customer LAN network) run a VPN client (PPTP, SSTP, L2TP, up to you) from customer site to a VPN server which you have access to, by doing this, you have access from the VPN server to the VPN client (Mikrotik a...
by solar77
Fri May 01, 2020 10:59 am
Forum: Beginner Basics
Topic: Slowness for the first few seconds then fast on download
Replies: 17
Views: 2813

Re: Slowness for the first few seconds then fast on download

The only problem is that you're not helping a newbie Looks like my humorous intention has not been understood so well, nonetheless, stay safe and keep the spirit up! while this issue is interesting, it does not actually cause a problem for OP. if your curiosity won't let this go, I'd suggest two th...
by solar77
Thu Apr 30, 2020 5:51 pm
Forum: Beginner Basics
Topic: 2 LAN Cables from Mikrotik to Switch
Replies: 24
Views: 3795

Re: 2 LAN Cables from Mikrotik to Switch

thanks @mkx and @pe1chl quick check on the wiki answers most of my question but thanks for more details on the topic for someone else reading this: layer-2-and-3 - This policy uses a combination of layer2 and layer3 protocol information to generate the hash. Uses XOR of hardware MAC addresses and IP...
by solar77
Thu Apr 30, 2020 5:05 pm
Forum: Beginner Basics
Topic: 2 LAN Cables from Mikrotik to Switch
Replies: 24
Views: 3795

Re: 2 LAN Cables from Mikrotik to Switch

I've actualy setup a lab test (once has some spare time during lockdown) : RB2011 (eth9 and eth10) to hAP ac Lite (eth1 and eth2) so each link is 100Mbps BUT, I can only get 98Mps udp between the two when using 802.3ad when testing with udp, 140Mbps TCP with balance-rr, 190Mbps UDP and 140Mbps TCP h...
by solar77
Thu Apr 30, 2020 2:02 pm
Forum: Beginner Basics
Topic: Slowness for the first few seconds then fast on download
Replies: 17
Views: 2813

Re: Slowness for the first few seconds then fast on download

the problem is the lockdonw, all man seek every opportunity to "work" and avoid doing house work. that's exactly what I am doing right now.
by solar77
Thu Apr 30, 2020 2:00 pm
Forum: Beginner Basics
Topic: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]
Replies: 56
Views: 7622

Re: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]

https://wiki.mikrotik.com/wiki/Manual:Packet_Flow this is really fundamental if you want to understand how it works. Look me a while and still not 100%. my understanding for use-ip-firewall, is bridged traffic, by default, does not go through the firewall. by ticking this box, you asking such traffi...
by solar77
Thu Apr 30, 2020 12:27 pm
Forum: Beginner Basics
Topic: 2 LAN Cables from Mikrotik to Switch
Replies: 24
Views: 3795

Re: 2 LAN Cables from Mikrotik to Switch

assuming bounding between two Mikrotiks should not have such problem?
by solar77
Thu Apr 30, 2020 11:39 am
Forum: Beginner Basics
Topic: Vlan through pptp behind ISP router??
Replies: 1
Views: 789

Re: Vlan through pptp behind ISP router??

Do you have access to the Huawei router? if yes, forward PPTP port to your Mikrotik and setup PPTP server on MT. you need forward port 1723 and also Protocal GRE (47) if you don't have access to the Huawei, then the only thing you can do is setup VPN client from your MT to a VPN server 3rd location ...
by solar77
Thu Apr 30, 2020 11:20 am
Forum: Beginner Basics
Topic: Mikrotik PPPOE server, wireless router as PPPOE dialer/client
Replies: 3
Views: 1089

Re: Mikrotik PPPOE server, wireless router as PPPOE dialer/client

my best guess would be authentication, encryption or something in your PPP profile does not match that of the ASUS.
sorry cannot be more specific without actualy seeing the device config
by solar77
Thu Apr 30, 2020 11:15 am
Forum: Beginner Basics
Topic: 2 LAN Cables from Mikrotik to Switch
Replies: 24
Views: 3795

Re: 2 LAN Cables from Mikrotik to Switch

if you were to get another switch. get a Mikrotik CRS and setup bounding.
out of curiosity, what is the reason for such topology?
by solar77
Thu Apr 30, 2020 10:46 am
Forum: Beginner Basics
Topic: Help setting up EE 4g. on LHG LTE 4G
Replies: 10
Views: 2512

Re: Help setting up EE 4g. on LHG LTE 4G

I am also in scotland. don't worry, we will get you set up. few information needed: APN you can check this on the internet : https://kenstechtips.com/index.php/mobile-internet-apn-settings user/pass: in many cases the SIM will register without this. step by step: 1. open webfig 2. find Interfaces on...
by solar77
Wed Apr 29, 2020 6:16 pm
Forum: Beginner Basics
Topic: Port Forwading
Replies: 2
Views: 768

Re: Port Forwading

port forwarding can be done by using dst nat. https://wiki.mikrotik.com/wiki/Manual:IP/Firewall/NAT#Destination_NAT this is relatively easy to do but you are exposing yourself to the hacker world. if you have to do this, at least allowing only known IP address to access. VPN is a lot more secure. ru...
by solar77
Wed Apr 29, 2020 6:10 pm
Forum: Beginner Basics
Topic: Accessing ROS with Winbox over internet
Replies: 6
Views: 1415

Re: Accessing ROS with Winbox over internet

looking at "warning: Router is behind a NAT. Remote connection might not work." this is saying your LTE interface has not got a public IP address and only been given a private IP by your mobile network opeartor. This is very common with many mobile networks, unless you have requested an public IP (a...
by solar77
Wed Mar 04, 2020 4:37 pm
Forum: General
Topic: VPN client/server resources access issue
Replies: 1
Views: 1374

Re: VPN client/server resources access issue

could be a number of reasons, depending on your config but most commonly , if you can ping the VPN router but no the workstation on it's LAN side, that is because the remote client is unable to get ARPs from workstations. The solution is to set up proxy-arp on the local interface. /interface etherne...
by solar77
Tue Mar 03, 2020 1:31 pm
Forum: General
Topic: Recursive route faiover WITH bandwidth check
Replies: 1
Views: 1171

Re: Recursive route faiover WITH bandwidth check

a heavier test could be Flood ping but it is not reliable enough to check bandwidth

you can schedule a script to run bandwidth test
viewtopic.php?t=132233
and then switch between WAN interface
by solar77
Tue Mar 03, 2020 10:54 am
Forum: Beginner Basics
Topic: DHCPDISCOVER and DHCPOFFER spam on DHCP server from Mikrotik router
Replies: 10
Views: 2712

Re: DHCPDISCOVER and DHCPOFFER spam on DHCP server from Mikrotik router

in the config file posted, you have
/ip dhcp-server
add address-pool=default-dhcp interface=bridge name=defconf
this enables DHCP server on your bridge, which is now part of your LAN.

disable it
 /ip dhcp-server set defconf disabled=yes 
by solar77
Tue Mar 03, 2020 10:46 am
Forum: Beginner Basics
Topic: Different IP Address Segment [SOLVED]
Replies: 3
Views: 3919

Re: Different IP Address Segment [SOLVED]

how come if I connect to a Modem with IP 192.168.0.1 with DHCP server on, my Mikrotik can still broadcast wifi, connected cellphones / pc's have ip addresses of 192.168.0.x. and able to surf the web. if i am reading correctly, your wifi clients has ip 192.168.0.x so it's on the same range as your D...
by solar77
Tue Feb 25, 2020 6:56 pm
Forum: Beginner Basics
Topic: Get all login failures
Replies: 1
Views: 1272

Re: Get all login failures

log print where message ~"user"   
in Terminal
by solar77
Wed Jan 15, 2020 12:37 pm
Forum: Beginner Basics
Topic: SXT LTE6 Kit drops internet (EE UK)
Replies: 9
Views: 2082

Re: SXT LTE6 Kit drops internet (EE UK)

Image
https://ibb.co/4sn34zd
this is the band, cell ID etc. I'd say that's good.
by solar77
Wed Jan 15, 2020 11:04 am
Forum: Beginner Basics
Topic: SXT LTE6 Kit drops internet (EE UK)
Replies: 9
Views: 2082

Re: SXT LTE6 Kit drops internet (EE UK)

than you so much SiB for your help!
is there a way to disable CA and just use primary band? I can accept a slower connection as long as it stays connected.
by solar77
Tue Jan 14, 2020 11:20 pm
Forum: Beginner Basics
Topic: SXT LTE6 Kit drops internet (EE UK)
Replies: 9
Views: 2082

Re: SXT LTE6 Kit drops internet (EE UK)

this time it connected for about 3 hours , then connection dropped again. here is the log 20:34:39 lte,async,raw lte1: sent AT+CFUN? 20:34:39 lte,async,raw lte1: rcvd +CFUN: 1 20:34:39 lte,async,raw lte1: sent AT+COPS? 20:34:39 lte,async,raw lte1: rcvd +COPS: 0,2,"23430",9 20:39:31 lte,async,raw +CR...
by solar77
Tue Jan 14, 2020 5:54 pm
Forum: Beginner Basics
Topic: SXT LTE6 Kit drops internet (EE UK)
Replies: 9
Views: 2082

Re: SXT LTE6 Kit drops internet (EE UK)

thanks SiB for your time! I've got all the scrip for switch SIM etc, it works just fine on Vodafone SIM but EE SIM keeps dropping off. I am not expert in LTE connections so hope you can see what the issue is from the Log. EE signal seems fine to me. the script logged this before switching to Vodafon...
by solar77
Tue Jan 14, 2020 5:10 pm
Forum: Wireless Networking
Topic: Sxt LTE 4g+ Cat6>
Replies: 43
Views: 11281

Re: Sxt LTE 4g+ Cat6>

hi @SiB, any chance you could have a look this?
viewtopic.php?f=13&t=156164&p=769883#p769883
by solar77
Tue Jan 14, 2020 4:46 pm
Forum: Beginner Basics
Topic: SXT LTE6 Kit drops internet (EE UK)
Replies: 9
Views: 2082

Re: SXT LTE6 Kit drops internet (EE UK)

@SiB ?
by solar77
Tue Jan 14, 2020 2:18 pm
Forum: Beginner Basics
Topic: SXT LTE6 Kit drops internet (EE UK)
Replies: 9
Views: 2082

SXT LTE6 Kit drops internet (EE UK)

I have recently installed an SXT LTE6 Kit . EE SIM in slot A and Vodafone SIM in slot B. what i have added to the default config: Netwatch with script to monitor internet drops and to switching APN Profile and SIM Slot . VPN connection is just there for me to get remote acess. Normal Internet traffi...
by solar77
Wed Jun 12, 2019 7:07 pm
Forum: Beginner Basics
Topic: i need to help
Replies: 2
Views: 580

Re: i need to help

what is your internet speed? what is the distance between wired AP and repeaters ? do you have line of sight? what is the number of clients you expect to connect on each AP? what package you wish to provide to your customers? the equipment choice will be very diffierent , depending all these things....
by solar77
Fri May 17, 2019 3:11 pm
Forum: Beginner Basics
Topic: mikrotik as a manageable switch
Replies: 1
Views: 590

Re: mikrotik as a manageable switch

to be honest sir, you don't come across as knowing much about networking. My best advice is to hire a consultant to set up the network for you. I may be expensive at the start but the long term it is going to cheaper, less time consuming, and avoid possible problems for customers, in summary, good f...
by solar77
Sun May 12, 2019 10:19 pm
Forum: Beginner Basics
Topic: Simple Queues vs Queue Tree
Replies: 3
Views: 1862

Re: Simple Queues vs Queue Tree

you should add rate limit in their PPPoE Profile, this will create dynamic simple queue as soon as the PPPoE session is established.
by solar77
Fri May 10, 2019 11:06 pm
Forum: Beginner Basics
Topic: Tunnel to cloud server while preserving local IP addresses
Replies: 1
Views: 496

Re: Tunnel to cloud server while preserving local IP addresses

Establish an VPN connection between the Mikrotik and the cloud server. which is the serve and which is the client is up to you.
by solar77
Wed May 01, 2019 12:22 pm
Forum: General
Topic: VLAN - hybrid port - untagged VLAN 1
Replies: 12
Views: 3881

Re: VLAN - hybrid port - untagged VLAN 1

thanks ava, good reading. in particular there is a link within the text, to "Manual:Layer2 misconfiguration"
by solar77
Tue Apr 30, 2019 2:27 pm
Forum: General
Topic: VLAN - hybrid port - untagged VLAN 1
Replies: 12
Views: 3881

Re: VLAN - hybrid port - untagged VLAN 1

that I think is to give the CPU (Router) access to your managed VLAN
I have not tried it yet but that's my understanding.
by solar77
Mon Apr 29, 2019 5:02 pm
Forum: General
Topic: VLAN - hybrid port - untagged VLAN 1
Replies: 12
Views: 3881

Re: VLAN - hybrid port - untagged VLAN 1

hi, I have only started to look at VLAN recently . My understanding is that, the switch VLAN only comes into consideration if you wish to have hardware offload for VLAN (the traffic between VLAN ports would be near wire speed because the swhich chip feature support this). note on the wiki: For devic...
by solar77
Mon Apr 29, 2019 4:07 pm
Forum: Wireless Networking
Topic: hAP ac2 as bridge and CAP
Replies: 6
Views: 1411

Re: hAP ac2 as bridge and CAP

you can use a virtual wlan interface to be the AP. then add this interface to your LAN bridge for example, now I add wlan5 as a AP while I am using wlan1 as station /interface wireless set [ find default-name=wlan1 ] band=2ghz-b/g/n disabled=no distance=indoors frequency=2462 frequency-mode=regulato...
by solar77
Mon Apr 29, 2019 3:32 pm
Forum: General
Topic: VLAN - hybrid port - untagged VLAN 1
Replies: 12
Views: 3881

Re: VLAN - hybrid port - untagged VLAN 1

https://wiki.mikrotik.com/wiki/Manual:Basic_VLAN_switching#Other_devices_with_built-in_switch_chip is for VLAN on RB3011 but I think you can still use bridge VLAN as well. also check this https://wiki.mikrotik.com/wiki/Manual:Switch_Router#VLAN_switching so you will need to add VLAN to the bridge an...
by solar77
Sat Apr 20, 2019 8:16 pm
Forum: Beginner Basics
Topic: Need quick and east non-payment redirect for a single customer
Replies: 6
Views: 970

Re: Need quick and east non-payment redirect for a single customer

as suggested by flynno, easy way would be contact the customer and get paid, instead of spending time on a solution that you only need for few days. PS: you can make her IP static on the DHCP server so it is the same IP every time. you can argue that she could then change IP to another static IP but...
by solar77
Wed Apr 17, 2019 10:53 am
Forum: Beginner Basics
Topic: Rebooting mikrotik in certain time and turn on without resetting whole counters
Replies: 1
Views: 332

Re: Rebooting mikrotik in certain time and turn on without resetting whole counters

create a schedule and excut script , like this one (instead of reboot, you shutdown)
viewtopic.php?t=19985

don't think you can schedule it to switch on again.
however, you can schedule it to disable all it's ports and enable again.
by solar77
Wed Apr 17, 2019 10:47 am
Forum: Beginner Basics
Topic: Bridging WiFi client with DHCP and the rest
Replies: 2
Views: 576

Re: Bridging WiFi client with DHCP and the rest

what I'm trying to achieve is a router that connects over third party wifi APs and if none are available, it will fall back to LTE. you are looking for " dual WAN fail-over". Many many tutorial and posts avaiable but starts from wiki https://wiki.mikrotik.com/wiki/Advanced_Routing_Failover_without_...
by solar77
Tue Apr 16, 2019 7:01 pm
Forum: Beginner Basics
Topic: Best practices to copy config from one device to another
Replies: 3
Views: 717

Re: Best practices to copy config from one device to another

Hi, having done it few times, I'd suggest export is the way to go. backup is meant to be for the same router. best practice, 1. to make sure the destination router is on the same firmware level as the master router. 2. you would want to check the config over, remove any MAC address. unfortunately if...
by solar77
Sun Apr 14, 2019 10:41 pm
Forum: General
Topic: hotspot can't drop wifi client after session time finished
Replies: 4
Views: 828

Re: hotspot can't drop wifi client after session time finished

1. How to make redirection to local auth page automatically, without filling any address in the browser after the session time would stopped? 2. How to make full dissconection from wifi, after session time stops? 1. I don't think you can. redirection means re-directing something the user has filled...
by solar77
Sun Apr 07, 2019 2:27 pm
Forum: General
Topic: i need help with queue's
Replies: 5
Views: 668

Re: i need help with queue's

disable fastrack and test again. FastTracked packets bypass firewall, connection tracking, simple queues, queue tree with parent=global, ip traffic-flow(restriction removed in 6.33), IP accounting, IPSec, hotspot universal client, VRF assignment, so it is up to administrator to make sure FastTrack d...
by solar77
Sat Apr 06, 2019 4:57 pm
Forum: Beginner Basics
Topic: PPTP problems
Replies: 6
Views: 1162

Re: PPTP problems

I would not think the CPU usage on any of the router would be too high? RB3011 should be able to handle 200Mbps VPN with ease. sorry I am not sure what the problem might be so the following is pure guess work: check for MTU isue so make sure, on both point 2 and point 3, MTU is correct and change MS...
by solar77
Sat Apr 06, 2019 3:19 pm
Forum: Beginner Basics
Topic: vlan by mac
Replies: 2
Views: 600

Re: vlan by mac

Dynamic VLAN Assignment with RADIUS and CAPsMAN Configuration Example
https://mum.mikrotik.com/presentations/ ... 137144.pdf

hope this helps.
by solar77
Sat Apr 06, 2019 12:18 pm
Forum: Beginner Basics
Topic: Help with hAP AC Lite basic config
Replies: 2
Views: 549

Re: Help with hAP AC Lite basic config

connect to the router from port 5,
remove port 2 to port 4 from local bridge (default name would be "bridge")
create a bridge. say "uplink", then add port 1 to port 4 to it
disable default DHCP client on port 1
done
by solar77
Sat Apr 06, 2019 12:09 pm
Forum: Beginner Basics
Topic: PPTP Issues
Replies: 13
Views: 1493

Re: PPTP Issues

I may give that a go, for the time being, I just re integrated my asus router and put my modem in bridge mode. So im hoping my ASUS router will allow me to open up the protocol that I need for L2TP-IPSec!! if your ISP modem can be in bridge mode, then why not use the Mikrotik behind it, instead of ...
by solar77
Fri Apr 05, 2019 12:10 pm
Forum: General
Topic: i need help with queue's
Replies: 5
Views: 668

Re: i need help with queue's

queue rule seems fine to me.
do you have fast track enabled in firewall?
by solar77
Fri Apr 05, 2019 11:06 am
Forum: Beginner Basics
Topic: PPTP Issues
Replies: 13
Views: 1493

Re: PPTP Issues

for l2tp + ipsec, you will need /ip firewall filter add chain=input protocol=udp port=1701,500,4500 add chain=input protocol=ipsec-esp your ISP router is probably not capable of allowing protocol so this won't work. I have not tried but it might work without ipsec. and SSTP requires certificate if y...
by solar77
Thu Apr 04, 2019 8:55 pm
Forum: Beginner Basics
Topic: PPTP Issues
Replies: 13
Views: 1493

Re: PPTP Issues

for PPTP, you will need to forward TCP 1723 and protocol 47 (GRE) to the Mikrotik
where SSTP only requires port 443
by solar77
Thu Apr 04, 2019 8:05 pm
Forum: General
Topic: i need help with queue's
Replies: 5
Views: 668

Re: i need help with queue's

please can you show your queue rules with
queue export
by solar77
Thu Apr 04, 2019 1:59 pm
Forum: General
Topic: DHCP: one IP address - multiple MAC address ?
Replies: 5
Views: 920

Re: DHCP: one IP address - multiple MAC address ?

May I ask why you wish to assigne one IP address to a user? I am not aware of any way to do this with Mikrotik DHCP server but you might be able to do it with hotspot. where the same user authentication will always get the same IP from the hotspot pool. The laptop will get different IP on wirelss, e...
by solar77
Thu Apr 04, 2019 1:08 pm
Forum: Beginner Basics
Topic: Bridge 2 vlans
Replies: 7
Views: 858

Re: Bridge 2 vlans

can i do this with just one router?? possibaly yes, if you can physcally have the hex router at the same location Aruba switch. so that network 1 is plugged in one port and network 2 is plugged in another. this way the hex will handle the inter-vlan routing. or if you have a router uplink from the ...
by solar77
Wed Apr 03, 2019 9:18 pm
Forum: Beginner Basics
Topic: Block traffic between VLAN
Replies: 8
Views: 1339

Re: Block traffic between VLAN

thanks Sob for further explaination . Much appreciated!
by solar77
Wed Apr 03, 2019 6:25 pm
Forum: Beginner Basics
Topic: Block traffic between VLAN
Replies: 8
Views: 1339

Re: Block traffic between VLAN

@Sob, thanks for the correction.

if each subnet / vlan is masqueraded behind the IP of it's interface. would this rule block traffic between them?
by solar77
Wed Apr 03, 2019 12:30 pm
Forum: Beginner Basics
Topic: Block traffic between VLAN
Replies: 8
Views: 1339

Re: Block traffic between VLAN

I think this will block traffic between any IP that is assigned to a local interface, except within the same bridge
/ip firewall filter
add chain=forward src-address-type=local dst-address-type=local action=drop
by solar77
Tue Apr 02, 2019 7:37 pm
Forum: Beginner Basics
Topic: Force local IP to use specific wan on load balancing
Replies: 15
Views: 2687

Re: Force local IP to use specific wan on load balancing

keep a backup config each step of the way . so you can always reset the router to factory default and come back to your latest backup again. This made me been very brave in my early days with Mikrotik
by solar77
Tue Apr 02, 2019 6:58 pm
Forum: Beginner Basics
Topic: PPTP problems
Replies: 6
Views: 1162

Re: PPTP problems

what is the actual throughput without VPN between point 2 and point 3? when i connect point3 to point2 that is connected to point1 do you mean a client from Point 3, connect to the VPN server at Point 1, but the link is via point 2? if yes, is Point 2 just a bridge? do you have fast forward enabled?
by solar77
Tue Apr 02, 2019 6:33 pm
Forum: Beginner Basics
Topic: Force local IP to use specific wan on load balancing
Replies: 15
Views: 2687

Re: Force local IP to use specific wan on load balancing

Glad it worked. opening all these UDP port and the word P2P seems be a "risky game" :-) I'd suggest to put this device in it's own VLAN so whoever has access to it, cannot access anything else on your network. PS: use good measure to protect your router as well. close down services you don't need, u...
by solar77
Tue Apr 02, 2019 6:01 pm
Forum: Beginner Basics
Topic: Force local IP to use specific wan on load balancing
Replies: 15
Views: 2687

Re: Force local IP to use specific wan on load balancing

it does seem to bypass policy based routing, I am not sure why but hopefully someone can tell me in this thread.

what port forwarding do you have to do? is it to the Nintendo ? this rule should only affect traffic originated from this particular IP address.
by solar77
Tue Apr 02, 2019 5:50 pm
Forum: Beginner Basics
Topic: Disable all services except api, how to start www or ssh or telnet?
Replies: 1
Views: 467

Re: Disable all services except api, how to start www or ssh or telnet?

you can see use Winbox to access the device by using it's MAC address.

you will need to to connect to the router directly by network cable, you should see it comes up in Neighbors tag.
by solar77
Tue Apr 02, 2019 5:04 pm
Forum: Beginner Basics
Topic: Force local IP to use specific wan on load balancing
Replies: 15
Views: 2687

Re: Force local IP to use specific wan on load balancing

It would normally work but I am not 100% in your case because you already have PCC.

I'd suggest to try
 
 /ip firewall mangle
 add chain=prerouting src-address=IP_of _ Nintendo dst-address-type=!local action=route dst-address=gateway_WAN2
by solar77
Sat Mar 23, 2019 10:17 pm
Forum: General
Topic: How much Support RB3011
Replies: 12
Views: 1433

Re: How much Support RB3011

use fast track on forward chain, established and connected traffic.

https://mikrotik.com/product/RB3011UiAS ... estresults
this is some indication for you.
by solar77
Fri Mar 22, 2019 6:51 pm
Forum: Beginner Basics
Topic: How to renew ip address when reconnecting pppoe
Replies: 5
Views: 933

Re: How to renew ip address when reconnecting pppoe

I am little confused here. when you say "some ips that are attacked ", I assume they are public IP address so you have a pool of public IP, they are not static to individual PPPoE client, and you want each PPPoE client to pick up a different public IP each time they connect? I'd think proper / more ...
by solar77
Fri Mar 22, 2019 6:43 pm
Forum: Beginner Basics
Topic: Port forward on port 8080
Replies: 14
Views: 1896

Re: Port forward on port 8080

The alternative is post nothing.

Why's this such a dreadful option?
Ha .... :lol:

sorry, in the business of helping OP. if the dst-nat rule has no traffic passing through, you need to check why the traffic is not reaching. complete config would give us more idea
by solar77
Fri Mar 22, 2019 1:55 pm
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 53
Views: 29060

Re: DHCP Offering Lease Without Success

I have followed up another device on this network having similar issue. It is also a Nintendo device. Here is my thought: I have hotspot running so it can connect to wiFi (both devices has -60dBm signal level and low channel utilisation ) but they cannot authenticate on the hotspot portal. /ip hotsp...
by solar77
Fri Mar 22, 2019 11:56 am
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 53
Views: 29060

Re: DHCP Offering Lease Without Success

@ pe1chl thanks for reply. I am looking into it a bit more: more often than not, before an "offering lease without success" error, Mikrotik repeately deassign and assigne DHCP over and over this happens to a range of devices. I did consider an wireless connection issue but my question is: this netwo...
by solar77
Fri Mar 22, 2019 10:50 am
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 53
Views: 29060

Re: DHCP Offering Lease Without Success

having this issue as well. first thought it was caused by my Unifi APs but now it seems to be pointing towards Mikrotik. It is now affecting non Apple devices (so far 2 x windows 10 laptops, one of which is ASUS).
I am running CCR1009, ROS 6.43

any one has a fix yet?
by solar77
Fri Mar 15, 2019 4:29 pm
Forum: Beginner Basics
Topic: Firewall rules
Replies: 6
Views: 855

Re: Firewall rules

ok I see what you mean now. So the URL will just be an Internal IP if you connected to it from LAN.
somehow i think the OP is using IP address not URL though
I set up the camera live view application from the outside IP address
by solar77
Fri Mar 15, 2019 11:53 am
Forum: Beginner Basics
Topic: Hotspot Bypass [SOLVED]
Replies: 9
Views: 1973

Re: Hotspot Bypass [SOLVED]

It's not the repeater does not have access to the internet, it's the app (the device where the app is running on) does not see the repeater.
by default hotspot client does not see other clients and LAN network.
by solar77
Thu Mar 14, 2019 7:08 pm
Forum: General
Topic: Topology for cotteges
Replies: 8
Views: 1057

Re: Topology for cotteges

we have done similar projects, using both Ubiquiti products and mikrotik, and combination of both. Here is my contribution: 1. if you have the option, go with fibre. search posts here for reasons but when you do a new install and running cables anyway, use fibre. 2.lets focus on Mikrotik, you can us...
by solar77
Thu Mar 14, 2019 6:23 pm
Forum: Beginner Basics
Topic: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?
Replies: 26
Views: 4245

Re: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?

Isn't it supposed to work just by creating some firewall rules ? Not really, you need NAT rule and routing rule. Because load balancing by definition seems more than what I need now, I just need to separate them in a fixed way. Its the type of load balancing where part of your network uses one conn...
by solar77
Thu Mar 14, 2019 3:04 pm
Forum: Beginner Basics
Topic: Hotspot Bypass [SOLVED]
Replies: 9
Views: 1973

Re: Hotspot Bypass [SOLVED]

not sure why you want to do this but you can.
add the MAC address of any device within your Local Area Network, in IP - Hotspot - IP Bindings
then set the Type to "bypassed"
by solar77
Thu Mar 14, 2019 1:37 pm
Forum: Beginner Basics
Topic: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?
Replies: 26
Views: 4245

Re: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?

the bridge is created by the router on default. it's normally the LAN ports all joined under this bridge. now you have 2 x PPPoE session, what you need is load-balancing. it's been discussed often on the forum. and there is a document you can read first to get the idea https://wiki.mikrotik.com/wiki...
by solar77
Wed Mar 13, 2019 1:44 pm
Forum: Beginner Basics
Topic: Trying to make service available from VPN
Replies: 6
Views: 739

Re: Trying to make service available from VPN

not sure why you cannot use 10.10.10.0/28 range as VPN Local address, I don't think it matters but happy to learn otherwise. in my view, you can use either 192.168.78.1 or 10.10.10.1 as local IP for VPN. use the matching pool . double check you have Add Default route and user peer DNS on the DHCP cl...
by solar77
Tue Mar 12, 2019 5:13 pm
Forum: General
Topic: What is the best method to connect between 2 routers? and How?
Replies: 8
Views: 838

Re: What is the best method to connect between 2 routers? and How?

Plug one ethernet cable into a port on one router and plug the other end of the ethernet cable on the other router.
Sorry I laughed. :lol: that is exactly what came to my mind on reading the subject, even before got to the actuall post itself....
by solar77
Tue Mar 12, 2019 5:09 pm
Forum: Beginner Basics
Topic: Trying to make service available from VPN
Replies: 6
Views: 739

Re: Trying to make service available from VPN

very interesting case so I will kick start. It might take me few attempt to get it working but I'd think it's possible. first try to set the VPN in the way that local address is that of the ether5, and VPN pool is in the same range as that of the Cisco box. when connected via VPN, the laptop should ...
by solar77
Tue Mar 12, 2019 4:56 pm
Forum: Beginner Basics
Topic: Hotspot wifi and Lan users
Replies: 13
Views: 2680

Re: Hotspot wifi and Lan users

Vlan id = 2 has been created on Switch to differ AP's from LAN users. Mikrotik router CCR a hotpsot created with dhcp server and pool 10.5.50.0/24 on Ethernet 3 wifi users cannot access the hotspot dhcp pool and get ip address. I can see that the hotspot is on ether3 but it needs to be on VLAN2. th...
by solar77
Tue Mar 12, 2019 2:24 pm
Forum: Beginner Basics
Topic: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?
Replies: 26
Views: 4245

Re: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?

Glad it's moving forward. Note you DIY trick would void warranty on both the ISP modem and the Mikrotik. is getting another 2 x modem from the ISP possible? because you do have another 2 account and it should come with a modem. Even not, I'd suggest you try to connect to their firbre first and see w...
by solar77
Tue Mar 12, 2019 1:55 pm
Forum: Beginner Basics
Topic: Firewall rules
Replies: 6
Views: 855

Re: Firewall rules

@sebastia I don't think DNS catch is going to work . Steveocee is right and the OP needs hairping nat. client send packet to IP of camera, get changed to internal IP of camera, return traffic has source IP of Internal camera IP. client device drops it because it's does not much the dst-ip of origina...
by solar77
Mon Mar 11, 2019 10:50 pm
Forum: Beginner Basics
Topic: After configuration when connecting all ports no internet connection
Replies: 4
Views: 560

Re: After configuration when connecting all ports no internet connection

/ip firewall nat
add action=masquerade chain=srcnat
missing out-interface=

first test if the router itself can ping 8.8.8.8, then the router can resolve a dns name, before you move on to other things.
by solar77
Mon Mar 11, 2019 7:43 pm
Forum: Beginner Basics
Topic: Hotspot wifi and Lan users
Replies: 13
Views: 2680

Re: Hotspot wifi and Lan users

if both the lan and wifi network are connected to the same layer 2 switch, you will not be able to stop the traffic going between. can you connect desktop PCs to the rouer so those ports can have the 192.168.22.0/24 only? and wifi on other ports or through swich? if you cannot physically bring all b...
by solar77
Mon Mar 11, 2019 4:49 pm
Forum: Beginner Basics
Topic: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?
Replies: 26
Views: 4245

Re: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?

very lucky man to have 3 x 1Gbps fibre. Contact your ISP and see if they allow you to remove the modem and just use the Mikrotik. and if yes, what SFP module they would recommend (muti-mode, or single mode). So the fibre feed can go straight into the Mikrotik. It's likely you can do this as you alre...
by solar77
Mon Mar 11, 2019 4:07 pm
Forum: Beginner Basics
Topic: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?
Replies: 26
Views: 4245

Re: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?

that's an interesting case. Yes I believe you can have 3 x PPPoE running on the Mikrotik and load-balancing them . you don't need VLAN. hardware selection depends on the uplink speed but most Mikrotik routers come with the same router OS, same feature, so even the basic model will do ospf, BGP, VLAN...
by solar77
Mon Mar 11, 2019 2:40 pm
Forum: Beginner Basics
Topic: Hotspot wifi and Lan users
Replies: 13
Views: 2680

Re: Hotspot wifi and Lan users

Answer: the main router can be a hotspot server. there is no need for the 2nd Mikrotik to be there if that's the only job it does. create a separate subnet on the ports where th WiFi AP is connected to. use VLAN if you want but it's not a must. so you will have bridge_lan and bridge_wifi, for exampl...
by solar77
Mon Mar 11, 2019 1:28 pm
Forum: Beginner Basics
Topic: Hotspot wifi and Lan users
Replies: 13
Views: 2680

Re: Hotspot wifi and Lan users

topology ?
by solar77
Sat Mar 09, 2019 11:51 am
Forum: General
Topic: VLAN across PPPoE clients
Replies: 7
Views: 742

Re: VLAN across PPPoE clients

@Redmor
thanks for advice. any chance you could post relevant config for doing the VLAN over EOIP?
also can you force MTU to be 1500? L2 is needed as the Monitor can only be discovered by the Panel, we cannot tell the monitor where the Panel is.
by solar77
Fri Mar 08, 2019 11:18 pm
Forum: General
Topic: VLAN across PPPoE clients
Replies: 7
Views: 742

Re: VLAN across PPPoE clients

I'd expect some direction from the helpful people here by now...or are we all in the pub?
by solar77
Fri Mar 08, 2019 8:35 pm
Forum: Beginner Basics
Topic: HELP: how to per ip shaping?
Replies: 10
Views: 1496

Re: HELP: how to per ip shaping?

it might be that you have other rules kicking in once the speed is set to 50/50 my suggestion, as in previous post, is to change Rate in both pcq-download-default and pcq-upload-default then add simple queue, with nothing else, just use the PCQ as in add name=LAN_PCQ queue=pcq-upload-default/pcq-dow...
by solar77
Fri Mar 08, 2019 6:15 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 6419

Re: load-balancing don't work

@WeWiNet Thanks for tips. This is only a trial for me to see how it would work out. If I was using it, yes fail-over will have to be there. . I am still not clear where the DNS traffic from the router itself goes , I think this is what this rule is for but not tested and I am using 8.8.8.8 on local ...
by solar77
Fri Mar 08, 2019 6:06 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 6419

Re: load-balancing don't work

SOLAR, both the WIKI and Steve Discher show that rule as a prerouting chain BUT IN_INTERFACE=WAN ????? The MUM2019 presentation shows that as input chain BUT IN_INTERFACE=WAN. Can i surmize that you are using bridge because you are simply simulating wan input??? I like your logic. ALL rules with ma...
by solar77
Fri Mar 08, 2019 6:00 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 6419

Re: load-balancing don't work

@plisken my config can work at 2 wan as well, just remove anything to do with wan3 and change PCC to 2/0 and 2/1 the only reason I did not do a whole router export is I've used it to test vlan staff before and there are many unrelated code left. what I did was step by step: get each of wan connectio...
by solar77
Fri Mar 08, 2019 5:12 pm
Forum: Beginner Basics
Topic: Help with WAN bandwidth limiting
Replies: 12
Views: 1214

Re: Help with WAN bandwidth limiting

it's rx/tx , I think, so upload or download depending on that interface / target you apply it to.
by solar77
Fri Mar 08, 2019 3:42 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 6419

Re: load-balancing don't work

Note 6, when winbox into the uplink router (Router 1 broadcasting 3 SSID), it used wan2, when I open 2nd winbox session, it still use the same wan2, so the bandwidth doubles, then I opened 3rd, 4th winbox, they all use the same wan2, with increasing bandwidth flowing. this shows the both address opt...
by solar77
Fri Mar 08, 2019 3:33 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 6419

Re: load-balancing don't work

Right, I've done it myself. Its working and here is what I did: my set up is not a real multiple WAN but 3 virtual wlan interface ( AP Bridge modem, broadcasting 3 SSID) from Mikrotik hAP, wihch has Internet access. Each SSID has it's own network: 10.10.1.0/24, 10.10.2.0/24, 10.10.3.0/24 Tested each...
by solar77
Thu Mar 07, 2019 8:57 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 6419

Re: load-balancing don't work

I had the input chain question this morning, ha ha ! what I did was create a rule on my own router, on prerouting chian, in-interface is WAN, which I thought won't have any traffic. but it did, as all traffic heading to my WAN ip, it get translated (NATed) into my LAN IP. which then get marked with ...
by solar77
Thu Mar 07, 2019 6:54 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 6419

Re: load-balancing don't work

nice presentation, well you making me doubt myself. however, it's not complete identical. check page 22, the route section, the presentation has 4 rules, the 1st two has identical distance, both been set o 1, and using routing mark. This is part of the load balancing route. then the next two rules, ...
by solar77
Thu Mar 07, 2019 4:56 pm
Forum: General
Topic: VLAN across PPPoE clients
Replies: 7
Views: 742

Re: VLAN across PPPoE clients

I will be doing some tests on option 1 which seems to be less of a hassle. will report back.
any comments are welcome in the meantime.
by solar77
Thu Mar 07, 2019 3:34 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 6419

Re: load-balancing don't work

I have not used PCC but compare your config with https://wiki.mikrotik.com/wiki/Manual:PCC the example does not use passthrough=yes, without understand all your config, i suspect some of the traffic got marked twice because of this. then the result would be only WAN2_conn is left and that's why all ...
by solar77
Thu Mar 07, 2019 11:52 am
Forum: Beginner Basics
Topic: HELP: how to per ip shaping?
Replies: 10
Views: 1496

Re: HELP: how to per ip shaping?

as suspected, it's TCP traffic on port 80 so you cannot limit bandwidth per protocol or port. don't set PCQ to 0, in winbox, go into queue , queue type, find pcq-download-default and pcq-upload-default, apply rate of your choice. then in simple queue, do this add name=LAN_PCQ queue=pcq-upload-defaul...
by solar77
Thu Mar 07, 2019 11:33 am
Forum: General
Topic: VLAN across PPPoE clients
Replies: 7
Views: 742

Re: VLAN across PPPoE clients

anyone?
by solar77
Wed Mar 06, 2019 10:24 pm
Forum: General
Topic: VLAN across PPPoE clients
Replies: 7
Views: 742

Re: VLAN across PPPoE clients

sorry R1 at the bottom should really be R3. my mistake.
by solar77
Wed Mar 06, 2019 10:02 pm
Forum: General
Topic: Backup WAN allow WInbox connection always
Replies: 1
Views: 340

Re: Backup WAN allow WInbox connection always

you can get this routing mark by adding a mangle rule on the Input chain to mark the connection, then on the output chain to add routing mark to this connection so traffic comes in from interface=wan2, dst-port=8291, protocal=tcp, gets marked by a connection mark, then the return traffic will still ...
by solar77
Wed Mar 06, 2019 5:09 pm
Forum: General
Topic: VLAN across PPPoE clients
Replies: 7
Views: 742

VLAN across PPPoE clients

trying to get L2 connectivity between PPPoE clients so that the intercom Panel can see the monitor (IPV6 only, cannot set an IPv4 address to it). attached a drawing to show what we have. basically R1 is our core network, running a PPPoE server. R2, R3, R4 is customer site, running PPPoE client, then...
by solar77
Wed Mar 06, 2019 3:55 pm
Forum: General
Topic: QoS and Limit bandwidth
Replies: 3
Views: 735

Re: QoS and Limit bandwidth

I'd think using IP is better as the whole queue solutionis simpler, all your target can be catolorised by IP address the email, the server (assuming behind a public IP or interanl IP even) these two would be set with higher priority and higher Limit-at value then you can have PCQ for your LAN subnet...
by solar77
Wed Mar 06, 2019 12:10 pm
Forum: General
Topic: How to get on mikrotik list of arp records at port.
Replies: 3
Views: 672

Re: How to get on mikrotik list of arp records at port.

if it is a slave port of a master, ARP table will probably show the MACs under the master port anyway. It's L2 connectivity
by solar77
Wed Mar 06, 2019 11:56 am
Forum: General
Topic: problem with DHCP
Replies: 2
Views: 407

Re: problem with DHCP

I'd suggest to put your RB750 in router mode.
so the DHCP client on ether1 will pick up address from the SXT and DHCP server on Local bridge (include ether2 to ether5) will issue address to your own clients, with the DHCP server on the 750, you can set static DHCP entry as you wish.
by solar77
Wed Mar 06, 2019 10:48 am
Forum: Beginner Basics
Topic: HELP: how to per ip shaping?
Replies: 10
Views: 1496

Re: HELP: how to per ip shaping?

first of all /queue type set 5 pcq-rate=47M set 6 pcq-rate=50M by default these two are not PCQ so please double check, make sure you have configured pcq-download-default and pcq-upload-default by check from winbox, make sure the rate is set. secondly /queue simple add max-limit=47M/50M name=Interne...
by solar77
Wed Mar 06, 2019 10:42 am
Forum: Beginner Basics
Topic: mikrotik bridge mode
Replies: 6
Views: 794

Re: mikrotik bridge mode

can you do a export hide-sensitive on the Mikrotik and show us the result? suspect something else is causing the issue. alternatively, reset the router and untick "default configuration". this will wipe all the config out of the Mikrotik, then you only do two things: add two interface into the bridg...
by solar77
Tue Mar 05, 2019 7:10 pm
Forum: Beginner Basics
Topic: Help with WAN bandwidth limiting
Replies: 12
Views: 1214

Re: Help with WAN bandwidth limiting

ha ha avav, that makes the two of us. :D I am more into traffic management and know less about routing. there is always something new to pick up when I visit this forum. Keeps working fun.
by solar77
Tue Mar 05, 2019 5:32 pm
Forum: Beginner Basics
Topic: Help with WAN bandwidth limiting
Replies: 12
Views: 1214

Re: Help with WAN bandwidth limiting

@anav I don't think limiting sessions is a solution here. if you watch under firewall - > connections, and do a speed test, such as speedtest.net, you will find it likes to use TCP port 80 over multiple connections. Some streaming services will do the same, (where I thought they should use UDP ). so...
by solar77
Tue Mar 05, 2019 2:33 pm
Forum: Beginner Basics
Topic: Help with WAN bandwidth limiting
Replies: 12
Views: 1214

Re: Help with WAN bandwidth limiting

Hi Anav, no the PO wants limit the WAN bandwidth as a whole so that the keep-alive packets (assuming from the isp) to the vdsl modem does not get dropped.
So limiting upload to 1.8Mbps would probably enough. So the queue is applied to the PPPoE interface.

that's my understanding anyway.
by solar77
Tue Mar 05, 2019 2:13 pm
Forum: Beginner Basics
Topic: Extending home network with additional mikrotik APs.
Replies: 6
Views: 1218

Re: Extending home network with additional mikrotik APs.

The wSAP AC Lite is an alternative. It gives you 2 additional Ethernet ports (include 1 x passive POE out) and it fits into standard wall power sockets (US). but wifi coverage is probably not as good as the cAP AC.
by solar77
Tue Mar 05, 2019 1:42 pm
Forum: Beginner Basics
Topic: HELP: how to per ip shaping?
Replies: 10
Views: 1496

Re: HELP: how to per ip shaping?

Please can you do
/queue export
just want to see how your PCQ is set up.
by solar77
Tue Mar 05, 2019 1:38 pm
Forum: Beginner Basics
Topic: Help with WAN bandwidth limiting
Replies: 12
Views: 1214

Re: Help with WAN bandwidth limiting

you are over doing it. the tutorials are probably policy based bandwidth limiting where one type of traffic gets x amount of bandwidth. you don't need this. all you need is to create a simple queue , /queue simple add max-limit=1M/2M name="bandwidth limit" target=pppoe-interface this example limits ...
by solar77
Tue Mar 05, 2019 1:25 pm
Forum: Beginner Basics
Topic: 2 connections, 1 vpn. need vpn to bypass one of the connections, need urgent help.
Replies: 1
Views: 240

Re: 2 connections, 1 vpn. need vpn to bypass one of the connections, need urgent help.

1st of all, try use SSTP (port 443 )instead of PPTP. SSTP is harder to block. My 4G connections blocks PPTP but I can use SSTP. secondly, I'd suggest to create mangle rule to add routing mark on all traffic with destination address to your VPN server, then add manual routing entry, so traffic with t...
by solar77
Tue Mar 05, 2019 1:13 pm
Forum: Beginner Basics
Topic: Two Mikrortik with same WAN
Replies: 9
Views: 832

Re: Two Mikrortik with same WAN

Is the ISP modem a router or a bridge. Can it be a bridge?
by solar77
Tue Mar 05, 2019 1:07 pm
Forum: Beginner Basics
Topic: mikrotik bridge mode
Replies: 6
Views: 794

Re: mikrotik bridge mode

remove 192.168.1.1/24 on ether1, that IP is likely to be the modem itself.
and try again.
by solar77
Tue Mar 05, 2019 11:35 am
Forum: Beginner Basics
Topic: Noob default route question
Replies: 8
Views: 986

Re: Noob default route question

@vecernik87
thanks. I now know the cause for some of our problems. It's good to have an informative posts like yours and that's what keeps get me back to this forum.
by solar77
Sat Feb 02, 2019 7:36 pm
Forum: Beginner Basics
Topic: Hotspot + pppoe in 1 port
Replies: 7
Views: 1225

Re: Hotspot + pppoe in 1 port

the answer is put them in VLANs.
by solar77
Fri Feb 01, 2019 5:48 pm
Forum: Beginner Basics
Topic: Failover Issue [SOLVED]
Replies: 14
Views: 2558

Re: Failover Issue [SOLVED]

hi anav 1st question, to the best of my knowledge, not really. and cannot think why it should be any differences. Masquerade is basically source nat but only change the src-ip to that of the out-interface. 2nd, I believe you can do /ip firewall connection tracking set enabled=no which is easy to add...
by solar77
Fri Feb 01, 2019 4:29 pm
Forum: Beginner Basics
Topic: Hotspot + pppoe in 1 port
Replies: 7
Views: 1225

Re: Hotspot + pppoe in 1 port

that's easier to set up. In my view Hotspot is for users that come and go, like a hotel / shop scenario. PPPoE is more for fixed users who does not have to log in from every device under one account, and more suited in ISP type scenario.
by solar77
Fri Feb 01, 2019 4:20 pm
Forum: Beginner Basics
Topic: Failover Issue [SOLVED]
Replies: 14
Views: 2558

Re: Failover Issue [SOLVED]

or reset all connections as soon as you move to the 2nd connection, by disable / enable Connection Tracking.
by solar77
Fri Feb 01, 2019 4:16 pm
Forum: Beginner Basics
Topic: Failover Issue [SOLVED]
Replies: 14
Views: 2558

Re: Failover Issue [SOLVED]

Thanks for the reply. I went through the aforementioned article and other relevant articles. From my understanding after reading those, existing sessions (especially from ping or from the same website on the same browser) don't switch to the new ISP after the failover. I may be wrong. I think you a...
by solar77
Fri Feb 01, 2019 11:31 am
Forum: Beginner Basics
Topic: Hotspot + pppoe in 1 port
Replies: 7
Views: 1225

Re: Hotspot + pppoe in 1 port

Interesting idea. Not tried but I'd imagine you will need VLAN so the PPPoE and Wireless network are separate. you can probably put them on the same interface without VLAN but that means running a DHCP server on this interface for hotspot users, while PPPoE users can also pick up an IP address from ...
by solar77
Fri Feb 01, 2019 11:20 am
Forum: Beginner Basics
Topic: Bandwidth Limited
Replies: 1
Views: 441

Re: Bandwidth Limited

difficult to guess without seeing the config. maybe do a export hide-sensitive and post here? few things on my mind: enable Fast forward on your bridge disable all firewall rule and queue, then test again. watch Tools - Profile while you test, see what is using your CPU. However I really don't think...
by solar77
Fri Feb 01, 2019 11:07 am
Forum: Beginner Basics
Topic: Failover Issue [SOLVED]
Replies: 14
Views: 2558

Re: Failover Issue [SOLVED]

your routing config: /ip route add distance=1 gateway=192.168.75.1 add distance=2 gateway=192.168.42.129 as long as the router can reach gateway IP (which does not mean there is internet connection beyond this gateway), the route will be available and distance=1 route (assuming that's your ADSL) is ...
by solar77
Mon Jan 28, 2019 11:19 am
Forum: Beginner Basics
Topic: output chain traffic routing
Replies: 0
Views: 493

output chain traffic routing

trying to keep the radius traffic from a router to use a fixed WAN interface without success. The network: OSPF enabled so the route to 0.0.0.0/0 is dynamically added by OSPF, there are two of them (10.10.0.241 and 249 being the gateways), so as a result I have ADo 0.0.0.0/0 10.10.0.241 110 10.10.0....
by solar77
Fri Jan 25, 2019 7:27 pm
Forum: Beginner Basics
Topic: I Need Help With VPN
Replies: 1
Views: 369

Re: I Need Help With VPN

do you have static routing in place at each router? sounds like you need: on Matriz /ip route add distance=1 dst-address=192.168.0.0/24 gateway=remote IP of your VPN connection, it would be 192.168.88.xx on the other router /ip route add distance=1 dst-address=192.168.88.0/24 gateway=remote IP of yo...
by solar77
Thu Jan 24, 2019 12:07 pm
Forum: Beginner Basics
Topic: ether1: Probably look (How to solve?)
Replies: 14
Views: 2201

Re: ether1: Probably look (How to solve?)

when we had similar issue on a wireless point to multi point link, it turned out to be someone copied the config between routers, thinking to chagne the IP of each router only. what he didn't realise is the MAC address of each interface were also in the config.....so all station routers ended up hav...
by solar77
Thu Jan 24, 2019 11:40 am
Forum: Beginner Basics
Topic: Firewall filter rules CCR-1009
Replies: 4
Views: 747

Re: Firewall filter rules CCR-1009

remember to keep your "allow established and related" filter rule on the top.
This ensure the return traffic from one VLAN to another is not dropped.
by solar77
Thu Jan 24, 2019 10:55 am
Forum: Beginner Basics
Topic: Firewall filter rules CCR-1009
Replies: 4
Views: 747

Re: Firewall filter rules CCR-1009

allow the connections first, and then block all other inter-vlan traffic. so you set up filter rule on forward chain, allow traffic from vlan 11 to server vlan 10 allow traffic from vlan 11 to address list (do this in ip firewall address lists) that contains 192.168.12.100-192.168.12.200 drop all tr...
by solar77
Thu Jan 24, 2019 10:35 am
Forum: Beginner Basics
Topic: one port only internet, no lan [SOLVED]
Replies: 20
Views: 2944

Re: one port only internet, no lan [SOLVED]

make sure this port is not part of the bridge with other LAN ports. otherwise traffic will not hit firewall unless you tells it to. set up separate IP Address, Network, DHCP server etc for this port. make sure traffic from this subnet is NATed. I would have a separate masquerade rule for each subnet...
by solar77
Wed Jan 23, 2019 7:15 pm
Forum: Beginner Basics
Topic: How to discover a remote device on the network ?
Replies: 6
Views: 864

Re: How to discover a remote device on the network ?

Do like your drawing. so here is my 12 pence : if you have to discover remote devices on router 2, make it a bridge, instead of a router. turn of DHCP on the TP Llink, connect a LAN port of router 2 to a LAN port of router 1. this is the only way to do it if you want to monitor inside of Router 2. s...
by solar77
Tue Jan 22, 2019 4:05 pm
Forum: Beginner Basics
Topic: Unify and mikrotik
Replies: 1
Views: 596

Re: Unify and mikrotik

I have the exact setup as you described. Unifi controller: set up 2 SSID, one with VLAN tag, on the Unifi Controller. I use Unifi switch as well so they will adjust to VLAN config on the controller but you just have to make sure the switch port which the Unifi AP plugs into is a trunk port. As the U...
by solar77
Tue Jan 22, 2019 10:28 am
Forum: Beginner Basics
Topic: Hotspot
Replies: 1
Views: 373

Re: Hotspot

http://bfy.tw/LuLg
have a look around and come back if you have specific question. I would recommend to use the Hotspot Setup within Mikrotik.

yes you can downgrade.
  • 1
  • 2