Community discussions

Search found 437 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 9
by solar77
Wed Jun 12, 2019 7:07 pm
Forum: Beginner Basics
Topic: i need to help
Replies: 2
Views: 240

Re: i need to help

what is your internet speed? what is the distance between wired AP and repeaters ? do you have line of sight? what is the number of clients you expect to connect on each AP? what package you wish to provide to your customers? the equipment choice will be very diffierent , depending all these things....
by solar77
Fri May 17, 2019 3:11 pm
Forum: Beginner Basics
Topic: mikrotik as a manageable switch
Replies: 1
Views: 262

Re: mikrotik as a manageable switch

to be honest sir, you don't come across as knowing much about networking. My best advice is to hire a consultant to set up the network for you. I may be expensive at the start but the long term it is going to cheaper, less time consuming, and avoid possible problems for customers, in summary, good f...
by solar77
Sun May 12, 2019 10:19 pm
Forum: Beginner Basics
Topic: Simple Queues vs Queue Tree
Replies: 3
Views: 541

Re: Simple Queues vs Queue Tree

you should add rate limit in their PPPoE Profile, this will create dynamic simple queue as soon as the PPPoE session is established.
by solar77
Fri May 10, 2019 11:06 pm
Forum: Beginner Basics
Topic: Tunnel to cloud server while preserving local IP addresses
Replies: 1
Views: 198

Re: Tunnel to cloud server while preserving local IP addresses

Establish an VPN connection between the Mikrotik and the cloud server. which is the serve and which is the client is up to you.
by solar77
Wed May 01, 2019 12:22 pm
Forum: General
Topic: VLAN - hybrid port - untagged VLAN 1
Replies: 11
Views: 664

Re: VLAN - hybrid port - untagged VLAN 1

thanks ava, good reading. in particular there is a link within the text, to "Manual:Layer2 misconfiguration"
by solar77
Tue Apr 30, 2019 2:27 pm
Forum: General
Topic: VLAN - hybrid port - untagged VLAN 1
Replies: 11
Views: 664

Re: VLAN - hybrid port - untagged VLAN 1

that I think is to give the CPU (Router) access to your managed VLAN
I have not tried it yet but that's my understanding.
by solar77
Mon Apr 29, 2019 5:02 pm
Forum: General
Topic: VLAN - hybrid port - untagged VLAN 1
Replies: 11
Views: 664

Re: VLAN - hybrid port - untagged VLAN 1

hi, I have only started to look at VLAN recently . My understanding is that, the switch VLAN only comes into consideration if you wish to have hardware offload for VLAN (the traffic between VLAN ports would be near wire speed because the swhich chip feature support this). note on the wiki: For devic...
by solar77
Mon Apr 29, 2019 4:07 pm
Forum: Wireless Networking
Topic: hAP ac2 as bridge and CAP
Replies: 6
Views: 637

Re: hAP ac2 as bridge and CAP

you can use a virtual wlan interface to be the AP. then add this interface to your LAN bridge for example, now I add wlan5 as a AP while I am using wlan1 as station /interface wireless set [ find default-name=wlan1 ] band=2ghz-b/g/n disabled=no distance=indoors frequency=2462 frequency-mode=regulato...
by solar77
Mon Apr 29, 2019 3:32 pm
Forum: General
Topic: VLAN - hybrid port - untagged VLAN 1
Replies: 11
Views: 664

Re: VLAN - hybrid port - untagged VLAN 1

https://wiki.mikrotik.com/wiki/Manual:Basic_VLAN_switching#Other_devices_with_built-in_switch_chip is for VLAN on RB3011 but I think you can still use bridge VLAN as well. also check this https://wiki.mikrotik.com/wiki/Manual:Switch_Router#VLAN_switching so you will need to add VLAN to the bridge an...
by solar77
Sat Apr 20, 2019 8:16 pm
Forum: Beginner Basics
Topic: Need quick and east non-payment redirect for a single customer
Replies: 6
Views: 433

Re: Need quick and east non-payment redirect for a single customer

as suggested by flynno, easy way would be contact the customer and get paid, instead of spending time on a solution that you only need for few days. PS: you can make her IP static on the DHCP server so it is the same IP every time. you can argue that she could then change IP to another static IP but...
by solar77
Wed Apr 17, 2019 10:53 am
Forum: Beginner Basics
Topic: Rebooting mikrotik in certain time and turn on without resetting whole counters
Replies: 1
Views: 128

Re: Rebooting mikrotik in certain time and turn on without resetting whole counters

create a schedule and excut script , like this one (instead of reboot, you shutdown)
viewtopic.php?t=19985

don't think you can schedule it to switch on again.
however, you can schedule it to disable all it's ports and enable again.
by solar77
Wed Apr 17, 2019 10:47 am
Forum: Beginner Basics
Topic: Bridging WiFi client with DHCP and the rest
Replies: 2
Views: 206

Re: Bridging WiFi client with DHCP and the rest

what I'm trying to achieve is a router that connects over third party wifi APs and if none are available, it will fall back to LTE. you are looking for " dual WAN fail-over". Many many tutorial and posts avaiable but starts from wiki https://wiki.mikrotik.com/wiki/Advanced_Routing_Failover_without_...
by solar77
Tue Apr 16, 2019 7:01 pm
Forum: Beginner Basics
Topic: Best practices to copy config from one device to another
Replies: 3
Views: 302

Re: Best practices to copy config from one device to another

Hi, having done it few times, I'd suggest export is the way to go. backup is meant to be for the same router. best practice, 1. to make sure the destination router is on the same firmware level as the master router. 2. you would want to check the config over, remove any MAC address. unfortunately if...
by solar77
Sun Apr 14, 2019 10:41 pm
Forum: General
Topic: hotspot can't drop wifi client after session time finished
Replies: 4
Views: 332

Re: hotspot can't drop wifi client after session time finished

1. How to make redirection to local auth page automatically, without filling any address in the browser after the session time would stopped? 2. How to make full dissconection from wifi, after session time stops? 1. I don't think you can. redirection means re-directing something the user has filled...
by solar77
Sun Apr 07, 2019 2:27 pm
Forum: General
Topic: i need help with queue's
Replies: 5
Views: 325

Re: i need help with queue's

disable fastrack and test again. FastTracked packets bypass firewall, connection tracking, simple queues, queue tree with parent=global, ip traffic-flow(restriction removed in 6.33), IP accounting, IPSec, hotspot universal client, VRF assignment, so it is up to administrator to make sure FastTrack d...
by solar77
Sat Apr 06, 2019 4:57 pm
Forum: Beginner Basics
Topic: PPTP problems
Replies: 6
Views: 519

Re: PPTP problems

I would not think the CPU usage on any of the router would be too high? RB3011 should be able to handle 200Mbps VPN with ease. sorry I am not sure what the problem might be so the following is pure guess work: check for MTU isue so make sure, on both point 2 and point 3, MTU is correct and change MS...
by solar77
Sat Apr 06, 2019 3:19 pm
Forum: Beginner Basics
Topic: vlan by mac
Replies: 2
Views: 315

Re: vlan by mac

Dynamic VLAN Assignment with RADIUS and CAPsMAN Configuration Example
https://mum.mikrotik.com/presentations/ ... 137144.pdf

hope this helps.
by solar77
Sat Apr 06, 2019 12:18 pm
Forum: Beginner Basics
Topic: Help with hAP AC Lite basic config
Replies: 2
Views: 263

Re: Help with hAP AC Lite basic config

connect to the router from port 5,
remove port 2 to port 4 from local bridge (default name would be "bridge")
create a bridge. say "uplink", then add port 1 to port 4 to it
disable default DHCP client on port 1
done
by solar77
Sat Apr 06, 2019 12:09 pm
Forum: Beginner Basics
Topic: PPTP Issues
Replies: 13
Views: 792

Re: PPTP Issues

I may give that a go, for the time being, I just re integrated my asus router and put my modem in bridge mode. So im hoping my ASUS router will allow me to open up the protocol that I need for L2TP-IPSec!! if your ISP modem can be in bridge mode, then why not use the Mikrotik behind it, instead of ...
by solar77
Fri Apr 05, 2019 12:10 pm
Forum: General
Topic: i need help with queue's
Replies: 5
Views: 325

Re: i need help with queue's

queue rule seems fine to me.
do you have fast track enabled in firewall?
by solar77
Fri Apr 05, 2019 11:06 am
Forum: Beginner Basics
Topic: PPTP Issues
Replies: 13
Views: 792

Re: PPTP Issues

for l2tp + ipsec, you will need /ip firewall filter add chain=input protocol=udp port=1701,500,4500 add chain=input protocol=ipsec-esp your ISP router is probably not capable of allowing protocol so this won't work. I have not tried but it might work without ipsec. and SSTP requires certificate if y...
by solar77
Thu Apr 04, 2019 8:55 pm
Forum: Beginner Basics
Topic: PPTP Issues
Replies: 13
Views: 792

Re: PPTP Issues

for PPTP, you will need to forward TCP 1723 and protocol 47 (GRE) to the Mikrotik
where SSTP only requires port 443
by solar77
Thu Apr 04, 2019 8:05 pm
Forum: General
Topic: i need help with queue's
Replies: 5
Views: 325

Re: i need help with queue's

please can you show your queue rules with
queue export
by solar77
Thu Apr 04, 2019 1:59 pm
Forum: General
Topic: DHCP: one IP address - multiple MAC address ?
Replies: 5
Views: 375

Re: DHCP: one IP address - multiple MAC address ?

May I ask why you wish to assigne one IP address to a user? I am not aware of any way to do this with Mikrotik DHCP server but you might be able to do it with hotspot. where the same user authentication will always get the same IP from the hotspot pool. The laptop will get different IP on wirelss, e...
by solar77
Thu Apr 04, 2019 1:08 pm
Forum: Beginner Basics
Topic: Bridge 2 vlans
Replies: 7
Views: 466

Re: Bridge 2 vlans

can i do this with just one router?? possibaly yes, if you can physcally have the hex router at the same location Aruba switch. so that network 1 is plugged in one port and network 2 is plugged in another. this way the hex will handle the inter-vlan routing. or if you have a router uplink from the ...
by solar77
Wed Apr 03, 2019 9:18 pm
Forum: Beginner Basics
Topic: Block traffic between VLAN
Replies: 8
Views: 505

Re: Block traffic between VLAN

thanks Sob for further explaination . Much appreciated!
by solar77
Wed Apr 03, 2019 6:25 pm
Forum: Beginner Basics
Topic: Block traffic between VLAN
Replies: 8
Views: 505

Re: Block traffic between VLAN

@Sob, thanks for the correction.

if each subnet / vlan is masqueraded behind the IP of it's interface. would this rule block traffic between them?
by solar77
Wed Apr 03, 2019 12:30 pm
Forum: Beginner Basics
Topic: Block traffic between VLAN
Replies: 8
Views: 505

Re: Block traffic between VLAN

I think this will block traffic between any IP that is assigned to a local interface, except within the same bridge
/ip firewall filter
add chain=forward src-address-type=local dst-address-type=local action=drop
by solar77
Tue Apr 02, 2019 7:37 pm
Forum: Beginner Basics
Topic: Force local IP to use specific wan on load balancing
Replies: 15
Views: 736

Re: Force local IP to use specific wan on load balancing

keep a backup config each step of the way . so you can always reset the router to factory default and come back to your latest backup again. This made me been very brave in my early days with Mikrotik
by solar77
Tue Apr 02, 2019 6:58 pm
Forum: Beginner Basics
Topic: PPTP problems
Replies: 6
Views: 519

Re: PPTP problems

what is the actual throughput without VPN between point 2 and point 3? when i connect point3 to point2 that is connected to point1 do you mean a client from Point 3, connect to the VPN server at Point 1, but the link is via point 2? if yes, is Point 2 just a bridge? do you have fast forward enabled?
by solar77
Tue Apr 02, 2019 6:33 pm
Forum: Beginner Basics
Topic: Force local IP to use specific wan on load balancing
Replies: 15
Views: 736

Re: Force local IP to use specific wan on load balancing

Glad it worked. opening all these UDP port and the word P2P seems be a "risky game" :-) I'd suggest to put this device in it's own VLAN so whoever has access to it, cannot access anything else on your network. PS: use good measure to protect your router as well. close down services you don't need, u...
by solar77
Tue Apr 02, 2019 6:01 pm
Forum: Beginner Basics
Topic: Force local IP to use specific wan on load balancing
Replies: 15
Views: 736

Re: Force local IP to use specific wan on load balancing

it does seem to bypass policy based routing, I am not sure why but hopefully someone can tell me in this thread.

what port forwarding do you have to do? is it to the Nintendo ? this rule should only affect traffic originated from this particular IP address.
by solar77
Tue Apr 02, 2019 5:50 pm
Forum: Beginner Basics
Topic: Disable all services except api, how to start www or ssh or telnet?
Replies: 1
Views: 174

Re: Disable all services except api, how to start www or ssh or telnet?

you can see use Winbox to access the device by using it's MAC address.

you will need to to connect to the router directly by network cable, you should see it comes up in Neighbors tag.
by solar77
Tue Apr 02, 2019 5:04 pm
Forum: Beginner Basics
Topic: Force local IP to use specific wan on load balancing
Replies: 15
Views: 736

Re: Force local IP to use specific wan on load balancing

It would normally work but I am not 100% in your case because you already have PCC.

I'd suggest to try
 
 /ip firewall mangle
 add chain=prerouting src-address=IP_of _ Nintendo dst-address-type=!local action=route dst-address=gateway_WAN2
by solar77
Sat Mar 23, 2019 10:17 pm
Forum: General
Topic: How much Support RB3011
Replies: 12
Views: 907

Re: How much Support RB3011

use fast track on forward chain, established and connected traffic.

https://mikrotik.com/product/RB3011UiAS ... estresults
this is some indication for you.
by solar77
Fri Mar 22, 2019 6:51 pm
Forum: Beginner Basics
Topic: How to renew ip address when reconnecting pppoe
Replies: 5
Views: 408

Re: How to renew ip address when reconnecting pppoe

I am little confused here. when you say "some ips that are attacked ", I assume they are public IP address so you have a pool of public IP, they are not static to individual PPPoE client, and you want each PPPoE client to pick up a different public IP each time they connect? I'd think proper / more ...
by solar77
Fri Mar 22, 2019 6:43 pm
Forum: Beginner Basics
Topic: Port forward on port 8080
Replies: 14
Views: 602

Re: Port forward on port 8080

The alternative is post nothing.

Why's this such a dreadful option?
Ha .... :lol:

sorry, in the business of helping OP. if the dst-nat rule has no traffic passing through, you need to check why the traffic is not reaching. complete config would give us more idea
by solar77
Fri Mar 22, 2019 1:55 pm
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 31
Views: 7692

Re: DHCP Offering Lease Without Success

I have followed up another device on this network having similar issue. It is also a Nintendo device. Here is my thought: I have hotspot running so it can connect to wiFi (both devices has -60dBm signal level and low channel utilisation ) but they cannot authenticate on the hotspot portal. /ip hotsp...
by solar77
Fri Mar 22, 2019 11:56 am
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 31
Views: 7692

Re: DHCP Offering Lease Without Success

@ pe1chl thanks for reply. I am looking into it a bit more: more often than not, before an "offering lease without success" error, Mikrotik repeately deassign and assigne DHCP over and over this happens to a range of devices. I did consider an wireless connection issue but my question is: this netwo...
by solar77
Fri Mar 22, 2019 10:50 am
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 31
Views: 7692

Re: DHCP Offering Lease Without Success

having this issue as well. first thought it was caused by my Unifi APs but now it seems to be pointing towards Mikrotik. It is now affecting non Apple devices (so far 2 x windows 10 laptops, one of which is ASUS).
I am running CCR1009, ROS 6.43

any one has a fix yet?
by solar77
Fri Mar 15, 2019 4:29 pm
Forum: Beginner Basics
Topic: Firewall rules
Replies: 6
Views: 467

Re: Firewall rules

ok I see what you mean now. So the URL will just be an Internal IP if you connected to it from LAN.
somehow i think the OP is using IP address not URL though
I set up the camera live view application from the outside IP address
by solar77
Fri Mar 15, 2019 11:53 am
Forum: Beginner Basics
Topic: Hotspot Bypass
Replies: 9
Views: 507

Re: Hotspot Bypass

It's not the repeater does not have access to the internet, it's the app (the device where the app is running on) does not see the repeater.
by default hotspot client does not see other clients and LAN network.
by solar77
Thu Mar 14, 2019 7:08 pm
Forum: General
Topic: Topology for cotteges
Replies: 8
Views: 542

Re: Topology for cotteges

we have done similar projects, using both Ubiquiti products and mikrotik, and combination of both. Here is my contribution: 1. if you have the option, go with fibre. search posts here for reasons but when you do a new install and running cables anyway, use fibre. 2.lets focus on Mikrotik, you can us...
by solar77
Thu Mar 14, 2019 6:23 pm
Forum: Beginner Basics
Topic: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?
Replies: 23
Views: 1146

Re: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?

Isn't it supposed to work just by creating some firewall rules ? Not really, you need NAT rule and routing rule. Because load balancing by definition seems more than what I need now, I just need to separate them in a fixed way. Its the type of load balancing where part of your network uses one conn...
by solar77
Thu Mar 14, 2019 3:04 pm
Forum: Beginner Basics
Topic: Hotspot Bypass
Replies: 9
Views: 507

Re: Hotspot Bypass

not sure why you want to do this but you can.
add the MAC address of any device within your Local Area Network, in IP - Hotspot - IP Bindings
then set the Type to "bypassed"
by solar77
Thu Mar 14, 2019 1:37 pm
Forum: Beginner Basics
Topic: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?
Replies: 23
Views: 1146

Re: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?

the bridge is created by the router on default. it's normally the LAN ports all joined under this bridge. now you have 2 x PPPoE session, what you need is load-balancing. it's been discussed often on the forum. and there is a document you can read first to get the idea https://wiki.mikrotik.com/wiki...
by solar77
Wed Mar 13, 2019 1:44 pm
Forum: Beginner Basics
Topic: Trying to make service available from VPN
Replies: 6
Views: 332

Re: Trying to make service available from VPN

not sure why you cannot use 10.10.10.0/28 range as VPN Local address, I don't think it matters but happy to learn otherwise. in my view, you can use either 192.168.78.1 or 10.10.10.1 as local IP for VPN. use the matching pool . double check you have Add Default route and user peer DNS on the DHCP cl...
by solar77
Tue Mar 12, 2019 5:13 pm
Forum: General
Topic: What is the best method to connect between 2 routers? and How?
Replies: 8
Views: 433

Re: What is the best method to connect between 2 routers? and How?

Plug one ethernet cable into a port on one router and plug the other end of the ethernet cable on the other router.
Sorry I laughed. :lol: that is exactly what came to my mind on reading the subject, even before got to the actuall post itself....
by solar77
Tue Mar 12, 2019 5:09 pm
Forum: Beginner Basics
Topic: Trying to make service available from VPN
Replies: 6
Views: 332

Re: Trying to make service available from VPN

very interesting case so I will kick start. It might take me few attempt to get it working but I'd think it's possible. first try to set the VPN in the way that local address is that of the ether5, and VPN pool is in the same range as that of the Cisco box. when connected via VPN, the laptop should ...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 9