Community discussions

MikroTik App

Search found 514 matches

  • 1
  • 2
by solar77
Fri May 29, 2020 12:48 pm
Forum: Beginner Basics
Topic: [solved] dhcp-client at WAN is stuck with status searching [SOLVED]
Replies: 9
Views: 1148

Re: [solved] dhcp-client at WAN is stuck with status searching [SOLVED]

Glad you found the fix. Sorry I find it a bit funny, the problem was that you named a Mikrotik hEX "hex"... :lol: :lol: :lol:
by solar77
Thu May 28, 2020 5:54 pm
Forum: Beginner Basics
Topic: [solved] dhcp-client at WAN is stuck with status searching [SOLVED]
Replies: 9
Views: 1148

Re: dhcp-client at WAN is stuck with status searching [SOLVED]

hostname and clientid are standared. this is to say what the DHCP server would look for when give IP address looks like the DHCP server is actively refusing to give 192.168.1.10 to ether2 of the Mikrotik please check and ensure there is not another client , either static or DHCP, on the same router ...
by solar77
Thu May 28, 2020 1:40 pm
Forum: Beginner Basics
Topic: Router Public IP
Replies: 2
Views: 259

Re: Router Public IP

@kohral good writing work. I actually enjoyed reading it. althrough I am not 100% clear on what you meant by The remaining two external static IPs are makes not available for pings. So after every reboot router randomly changes its public IP and Zabbix gets error that "ICMP ping is unavailable" but ...
by solar77
Thu May 28, 2020 1:16 pm
Forum: Beginner Basics
Topic: [solved] dhcp-client at WAN is stuck with status searching [SOLVED]
Replies: 9
Views: 1148

Re: dhcp-client at WAN is stuck with status searching [SOLVED]

interesting problem and I don't have an answer to. maybe some of the options in DHCP client but that's pure guess.

what if you give it an static IP, would it hold it without fail?
by solar77
Thu May 28, 2020 12:53 pm
Forum: Beginner Basics
Topic: three newbie questions
Replies: 23
Views: 2664

Re: three newbie questions

few things you have to understand: 1. firewall filter rules are inspected and actioned from top to bottom. so order is important. once the traffic matches one rule, it will be actioned accordingly and the reset of the rules will not apply this probably answers Question 4. 2. also , for the same reas...
by solar77
Thu May 28, 2020 12:33 pm
Forum: Beginner Basics
Topic: Deny ip PUBLIC traffic
Replies: 10
Views: 1552

Re: Deny ip PUBLIC traffic

try add this to the top of your firewall filter rules add action=drop chain=forward-from-internet comment=IPTEST log-prefix="IP MAIL BLOCK" \ src-address-list=IP_TEST not sure why you are using this jump rule but all the other rules on forward chain are still unchainged, so they will not apply to fo...
by solar77
Thu May 28, 2020 12:19 pm
Forum: Beginner Basics
Topic: How to pass through to router via public IP
Replies: 20
Views: 2154

Re: How to pass through to router via public IP

good to know. but in this case, even he assign local IP to DDNS record, he still won't be able to access his wAP LTE remotely (from the internet)
the simple way to get this to work, is that you need to buy a public IP from the ISP
by solar77
Wed May 27, 2020 4:57 pm
Forum: Beginner Basics
Topic: How to pass through to router via public IP
Replies: 20
Views: 2154

Re: How to pass through to router via public IP

indeed, the screen capture shows he is behind NAT and the last line gives the answer: "remote connection may not work"
looks like he's got an private IP from the ISP, normal for mobile network.
by solar77
Wed May 27, 2020 4:04 pm
Forum: Beginner Basics
Topic: How to pass through to router via public IP
Replies: 20
Views: 2154

Re: How to pass through to router via public IP

Please read my previous suggestion, in this very post! before we get into the practical method of accessing the router, either by VPN or port-forwarding, do you have a public accessible IP address? It does not seems to be the case by the look of it. from your post: 84.15.182.234, belongs to ISP:Bite...
by solar77
Tue May 26, 2020 6:13 pm
Forum: Beginner Basics
Topic: Accessing 4G modem with no public IP
Replies: 1
Views: 282

Re: Accessing 4G modem with no public IP

we do this at work. the solution is that we use a Mikrotik VPN server, where a number of 4G Mikrotik would connect to. our office router also VPN into the same server and we are able to access any of the 4G modem or router behind satellite connections. if you want to access the 4G modem from a PC wh...
by solar77
Tue May 26, 2020 6:01 pm
Forum: Beginner Basics
Topic: Restart a device via R J45 port?
Replies: 1
Views: 291

Re: Restart a device via R J45 port?

My question is: Is it possible to restart the endpoint device which has a link with router ( RJ 45 cable between) via RouterOs or Winbox? Mikrotik routerOS has build-in SSH and Telnet client, so if your endpoint device can be restarted via either, then you can do this from the Mikrotik. Further, I ...
by solar77
Fri May 22, 2020 9:00 pm
Forum: Beginner Basics
Topic: Ideas for S2S with internet centralization [SOLVED]
Replies: 5
Views: 926

Re: Ideas for S2S with internet centralization [SOLVED]

what is the upload capacity at HQ? as this will also limit the download capacity for your Branch. assuming it's more than 10 Mbps. hardware looks fine to me but other experts feel free to comment. as for mangle, you could look at https://wiki.mikrotik.com/wiki/Per-Traffic_Load_Balancing#Step_3_-_Usi...
by solar77
Fri May 22, 2020 8:52 pm
Forum: Beginner Basics
Topic: Deny ip PUBLIC traffic
Replies: 10
Views: 1552

Re: Deny ip PUBLIC traffic

you need to also drop these traffic on Forward chain, that is where traffic is flowing through the router, in this case, from the Internet, through the router, to your server. The input chain, is traffic that is heading to the router itself , for example, traffic heading to the VPN server on the rou...
by solar77
Fri May 22, 2020 1:04 pm
Forum: Beginner Basics
Topic: Ideas for S2S with internet centralization [SOLVED]
Replies: 5
Views: 926

Re: Ideas for S2S with internet centralization [SOLVED]

your plan is do-able and might be easier than you think. lets assume few things: site A (HQ) and site B (Branch) both has static IP and good internet connection, not just download but also upload bandwidth as well. What is good? depending on your application. also to do IPSec you need good performan...
by solar77
Fri May 22, 2020 12:21 pm
Forum: Beginner Basics
Topic: How to pass through to router via public IP
Replies: 20
Views: 2154

Re: How to pass through to router via public IP

thank you for letting us know it's working. Many poster won't feedback on our suggestions which is a shame.
not important to vote a solution, it's not like we would get paid for it :lol:
by solar77
Thu May 21, 2020 2:29 pm
Forum: Beginner Basics
Topic: Changing Manufacturer and Model Name [SOLVED]
Replies: 8
Views: 1074

Re: Changing Manufacturer and Model Name [SOLVED]

I assume OP is concerned that the mobile mobile carrier only allows him to use the SIM in a smart device, not tethered, not in a 4G modem. one of the things they can do is to detect change in TTL, which will decrease after traffic going through a router. then the fix is to increase TTL by 1 or set T...
by solar77
Thu May 21, 2020 1:42 pm
Forum: Beginner Basics
Topic: How to pass through to router via public IP
Replies: 20
Views: 2154

Re: How to pass through to router via public IP

Greetings to Mikrotik user from Ho Chi Minh City! Once pppoe established, interface <pppoe-out1> has local address: 100.91.214.57 and remote address: 100.123.1.62. The dynamic public ip: 183.80.67.230 looks like you don't have a public IP, the one you are using, is shared between a number of users o...
by solar77
Thu May 21, 2020 1:28 pm
Forum: Beginner Basics
Topic: Joining 2 networks
Replies: 19
Views: 2044

Re: Joining 2 networks

I would not use the Cisco if it is only 100Mbps. The RB2011 surely will do better than that. My guess is that you can reach 200 Mbps to 400 Mbps throughput: https://mikrotik.com/product/RB2011UiAS-2HnD-IN#fndtn-testresults so a user case is important here, for example, if you have large amount of da...
by solar77
Tue May 19, 2020 6:45 pm
Forum: Beginner Basics
Topic: Splitting up ports
Replies: 14
Views: 1497

Re: Splitting up ports

en..in this scenario I would use a wsAP ac lite, or a gigabit port version when it comes Lets say for some reason I do need to connect 4 devices over SFP, I'd get 4 x SPE to Base-T dongles. is it the BASE-T side goes to the device and the SPE side goes to one pair of UTP / STP cable that leads to th...
by solar77
Tue May 19, 2020 5:24 pm
Forum: Beginner Basics
Topic: Does RouterOS block NTP traffic by default?
Replies: 19
Views: 1582

Re: Does RouterOS block NTP traffic by default?

yes I was expecting the Src port to be a random port, just like when you use web service at 80 or 443, the traffic would be leaving your private IP from port xxxx. windows 10 PC is connecting to time.windows.com I have setup my mikroitk as : /system ntp client set enabled=yes server-dns-names=2.uk.p...
by solar77
Tue May 19, 2020 5:13 pm
Forum: Beginner Basics
Topic: Splitting up ports
Replies: 14
Views: 1497

Re: Splitting up ports

who said this converter will be in the server room? SPE is new to me, just watched few page and video. it seems to be the technology for industrial IoT use. no point for me to guess what should and what would I'd be interested to know how you managed to split a Ethernet connection and how the perfor...
by solar77
Tue May 19, 2020 4:58 pm
Forum: Beginner Basics
Topic: Does RouterOS block NTP traffic by default?
Replies: 19
Views: 1582

Re: Does RouterOS block NTP traffic by default?

@mutluit
192.168.90.98:123 is my PC, which would be an NTP client
also I tested setup the NTP client within Mikrotik, log shows the Mikrotik also use Src Port 123 as well.
by solar77
Tue May 19, 2020 4:39 pm
Forum: Beginner Basics
Topic: Splitting up ports
Replies: 14
Views: 1497

Re: Splitting up ports

SPE, single pair ethernet, seem interesting but I'd expect some sort of converter to do the job. When it connected to the Mikrotik, it would just like adding a L2 switch to a Mikrotik ethernet port?
by solar77
Tue May 19, 2020 3:55 pm
Forum: Beginner Basics
Topic: Does RouterOS block NTP traffic by default?
Replies: 19
Views: 1582

Re: Does RouterOS block NTP traffic by default?

No Mikrotik does not block NTP by default yes Mikrotik seems to want to use 123 as Src. Port. Interesting.... to check Mikrotik has send NTP packat from your PC, add a filrewall rule to show what's going on: in terminal add: /ip firewall filter add action=accept chain=forward dst-port=123 log=yes pr...
by solar77
Tue May 19, 2020 3:21 pm
Forum: Beginner Basics
Topic: Joining 2 networks
Replies: 19
Views: 2044

Re: Joining 2 networks

OK....I assumed these two are in different locations, then both ADSL routers can VPN into the same Mikrotik which can forward traffic from one subnet to another. However, both routers needs to be able to do static routing as well so normal traffic would not have to through VPN if they where in the s...
by solar77
Mon May 18, 2020 3:30 pm
Forum: Beginner Basics
Topic: Admin access via the internet
Replies: 14
Views: 1737

Re: Admin access via the internet

before even getting into DDNS and VPN, lets start from the basics, how do you get your Internet? this lead to another question, do you have a public facing IP address? even dynamically (this is where DDNS could work for you) ? if you are on a 4G / LTE network, most likely, you get a private IP from ...
by solar77
Mon May 18, 2020 2:07 pm
Forum: Beginner Basics
Topic: Joining 2 networks
Replies: 19
Views: 2044

Re: Joining 2 networks

I have left my crystal ball in the office...

what OP want, is site to site VPN, hence the suggestion.
by solar77
Mon May 18, 2020 1:51 pm
Forum: Beginner Basics
Topic: LHG lte6 dns/link issues
Replies: 6
Views: 785

Re: LHG lte6 dns/link issues

what if you un-tick B3 and use B7 only. top speed will be slower but hopefully less disconnection,.
there seems to be frequent speed drops and disconnection issues reported on the forum,
by solar77
Sun May 17, 2020 8:09 pm
Forum: Beginner Basics
Topic: Joining 2 networks
Replies: 19
Views: 2044

Re: Joining 2 networks

this is what you need:
https://wiki.mikrotik.com/wiki/Manual:I ... sec_tunnel

have a go and let us know if you run into problems

One of your Mikrotik router needs static Public IP, or at least have DDNS setup so it can be reached from the Internet.
by solar77
Sun May 17, 2020 7:24 pm
Forum: Beginner Basics
Topic: Variable 4G download speeds with Vodafone UK
Replies: 6
Views: 916

Re: Variable 4G download speeds with Vodafone UK

yes band 20 is what I'd expect. do you notice any signal differences when speed were slow? when it is slow , if you put the SIM in the phone, do you get roughly the same speed? does your television mast move in strong wind? sorry it is a pain to do / check all these but there is no obvious answer to...
by solar77
Fri May 15, 2020 12:29 pm
Forum: Beginner Basics
Topic: Unifi Controller Nightmare !
Replies: 2
Views: 601

Re: Unifi Controller Nightmare !

Unifi APs need DHCP server on the same network, so it can get an IP address to start with. you also need the PC running the controller, to be on the same network, so it can see the discovery package, sent by the APs. so you should have both the AC Lite and the PC, connected to the LAN side of the Mi...
by solar77
Thu May 14, 2020 10:53 pm
Forum: Beginner Basics
Topic: Connection Dropping
Replies: 2
Views: 397

Re: Connection Dropping

The fact that you sometimes get good speed, means your NAT setup is correct. otherwise it would not work at all. I would personally use the SXT as a router and the other MT as WiFi access point but that's just me. It's just a personal thing and also I'd likely to power up the SXT from ether 5 of the...
by solar77
Thu May 14, 2020 10:35 pm
Forum: Beginner Basics
Topic: simple queue
Replies: 7
Views: 1159

Re: simple queue

consider this: when PC1 want 1Mbps and PC2 want 7 Mbps CZFan's approach will allow both PC to get the bandwidth they needed Yours, however, because both PCs are active, the queue system would give PC1 1Mpbs and limit PC2 to 5Mbps, while there are 4 Mbps that you are paying for with your hard-earned ...
by solar77
Thu May 14, 2020 3:13 pm
Forum: Beginner Basics
Topic: Variable 4G download speeds with Vodafone UK
Replies: 6
Views: 916

Re: Variable 4G download speeds with Vodafone UK

Vodafone's words of wisdom are that the SIM has been registered on their network as 2G and therefore is the cause of the problem
You can easy check this ,just look at the LTE interface status on the LHG, it should say Evolved 3G (LTE)

What band are you on?
by solar77
Tue May 12, 2020 4:31 pm
Forum: Beginner Basics
Topic: Variable 4G download speeds with Vodafone UK
Replies: 6
Views: 916

Re: Variable 4G download speeds with Vodafone UK

few possibilities: 1. more vodafone users are now connected to the same mast . Voda is offering unlimited SIMs so naturally these users would be "open tap" all the way 2. check your signal on the LHG, there is a chance the dish had moved slightly and you are not getting a good enough signal. some po...
by solar77
Tue May 12, 2020 4:02 pm
Forum: Beginner Basics
Topic: Flight Simulator Steam Edition (FSX) port forwarding
Replies: 2
Views: 467

Re: Flight Simulator Steam Edition (FSX) port forwarding

at first glance, your dst-nat rules, should have your WAN interface as their " in-interface", which is traffic coming from the Internet.

you have set "in-interface" to be your bridge, this is the reason
this will also forward their traffic on those ports to my PC
by solar77
Tue May 12, 2020 3:27 pm
Forum: Beginner Basics
Topic: PCQ shared bandwidth EXCEPT 1 PC
Replies: 1
Views: 538

Re: PCQ shared bandwidth EXCEPT 1 PC

Mark traffic to and from 192.168.104.114 with a different packet mark and set up queue tree accordingly. personally I would use simple queue, one queue with target of 192.168.104.114 (6M/4M), above the general PCQ rule (10M/10M). Mikrotik apply simple queue from the top to bottom this should work. s...
by solar77
Tue May 12, 2020 2:32 pm
Forum: Beginner Basics
Topic: DMZ IP adress assign
Replies: 1
Views: 479

Re: DMZ IP adress assign

you could try adding a source nat rule so traffic from the DMZ PC is masqueraded to 176.76.240.18

for example:
/ip firewall nat
add action=src-nat chain=srcnat out-interface=WAN src-address=192.168.1.5 to-addresses=176.76.240.18
where 192.168.1.5 is the IP of your DMZ PC
by solar77
Mon May 11, 2020 1:36 pm
Forum: Beginner Basics
Topic: Address range in firewall address list
Replies: 14
Views: 1406

Re: Address range in firewall address list

https://wiki.mikrotik.com/wiki/Manual:I ... dress_list

you can also do 192.168.1.10-192.168.1.20 , for example
 /ip firewall filter add chain=forward src-address=192.168.1.10-192.168.1.20 action=drop  
by solar77
Mon May 04, 2020 12:42 am
Forum: Beginner Basics
Topic: mikrotik x 2 - one address in the LAN
Replies: 24
Views: 2877

Re: mikrotik x 2 - one address in the LAN

thanks andriys I've been reading on SCA and yes the theory is that, if the whole network "pretends" to be a single AP then there is no "roaming" , the client is associated with the controller which will hand client devices over without it knowing. However, the reason I suggested the access list is o...
by solar77
Sun May 03, 2020 8:18 pm
Forum: Beginner Basics
Topic: mikrotik x 2 - one address in the LAN
Replies: 24
Views: 2877

Re: mikrotik x 2 - one address in the LAN

@andriys
so how do seamless roaming work in enterprise wifi networks? does it actively disconnect one client and in the hope it will come back to the strongest signal it can discover? or there is a more intelligent way so the AP tells the client devise more about when and who to switch over next?
by solar77
Sun May 03, 2020 12:02 pm
Forum: Beginner Basics
Topic: mikrotik x 2 - one address in the LAN
Replies: 24
Views: 2877

Re: mikrotik x 2 - one address in the LAN

when the client device is stationary, it should not be switching between APs. if you are talking about roaming, (walking through the building, disconnecting from one AP as the signal is too weak and re-connect to another AP), you will have a period of disconnection. seamless roaming, is a term where...
by solar77
Sat May 02, 2020 4:56 pm
Forum: Beginner Basics
Topic: mikrotik x 2 - one address in the LAN
Replies: 24
Views: 2877

Re: mikrotik x 2 - one address in the LAN

I'd start by removing access list, your device will decide when it's the best time to disconnect from a signal reduce transmit power, by increasing Antenna gain on 2.4GHz radio (so the Mikortik is told there is an more sensitive antenna, therefore reduce the transmit power) keep the 5G radio the sam...
by solar77
Fri May 01, 2020 9:02 pm
Forum: Beginner Basics
Topic: mikrotik x 2 - one address in the LAN
Replies: 24
Views: 2877

Re: mikrotik x 2 - one address in the LAN

yes these steps looks correct. what it will look like switching between wireless networks for these two mikrotik? the subnet 192.168.20.0/24, exist on the following physical interfaces as they are all connected and belongs to the same bridge on 1st Mikrotik : ehter 2 to ethe5 and wlan1 and wlan2 on ...
by solar77
Fri May 01, 2020 7:58 pm
Forum: Beginner Basics
Topic: mikrotik x 2 - one address in the LAN
Replies: 24
Views: 2877

Re: mikrotik x 2 - one address in the LAN

In contrast, mikrotik has created a new subnet 192.168.20.0/24. I would like it to stay that way. I would like two mikrotiki to form a separate network 192.168.20.0. so your first Mikrotik gets 192.168.10.2 on ether1 and its LAN subnet is 192.168.20.0/24 and you want the 2nd Mikrotik to stay in 192...
by solar77
Fri May 01, 2020 7:20 pm
Forum: Beginner Basics
Topic: mikrotik x 2 - one address in the LAN
Replies: 24
Views: 2877

Re: mikrotik x 2 - one address in the LAN

sounds like all you have to do is make the Mikrotik a switch + WiFi access point, then you will have one only subnet, all your IP address on the LAN will be in 192.168.20.0/24 I assume that your home router is doing the NAT, DHCP server, DNS server etc. so on both mikrotik, disable NAT, disable DHCP...
by solar77
Fri May 01, 2020 1:23 pm
Forum: Beginner Basics
Topic: Slowness for the first few seconds then fast on download
Replies: 17
Views: 2224

Re: Slowness for the first few seconds then fast on download

just tested on a cCR1009, Mikrotik bandwidth test TCP, 1Gbps uplink,
no difference with or without fast-track
by solar77
Fri May 01, 2020 12:53 pm
Forum: Beginner Basics
Topic: Slowness for the first few seconds then fast on download
Replies: 17
Views: 2224

Re: Slowness for the first few seconds then fast on download

interesting. i am thinking of two things: MTU , but this should have nothing to do with fast-track connection tracking: one thing different with fast-track, is that it bypass connection tracking, would this somehow slow down the process of speed testing server establish mutiple streams? that's why I...
by solar77
Fri May 01, 2020 12:45 pm
Forum: Beginner Basics
Topic: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]
Replies: 56
Views: 6193

Re: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]

run
/ ip firewall export
from Mikrotik Terminal
by solar77
Fri May 01, 2020 12:36 pm
Forum: General
Topic: How to adapt dual LTE / DSL balance over day due to COVID home workers (over) loading LTE network
Replies: 5
Views: 1174

Re: How to adapt dual LTE / DSL balance over day due to COVID home workers (over) loading LTE network

you can also try this https://forum.mikrotik.com/viewtopic.php?t=132233 using Mikrotik bandwidth test result and then save the outcome as global variable, use it to adjust your routing / queue downside is speed test along with live internet traffic is not accurate, I don't think you want to stop all...
by solar77
Fri May 01, 2020 11:32 am
Forum: Beginner Basics
Topic: Reverse SSH Tunnel
Replies: 2
Views: 765

Re: Reverse SSH Tunnel

yes you can. using the same principle, use Mikrotik as a router, (or even just within the customer LAN network) run a VPN client (PPTP, SSTP, L2TP, up to you) from customer site to a VPN server which you have access to, by doing this, you have access from the VPN server to the VPN client (Mikrotik a...
by solar77
Fri May 01, 2020 10:59 am
Forum: Beginner Basics
Topic: Slowness for the first few seconds then fast on download
Replies: 17
Views: 2224

Re: Slowness for the first few seconds then fast on download

The only problem is that you're not helping a newbie Looks like my humorous intention has not been understood so well, nonetheless, stay safe and keep the spirit up! while this issue is interesting, it does not actually cause a problem for OP. if your curiosity won't let this go, I'd suggest two th...
by solar77
Thu Apr 30, 2020 5:51 pm
Forum: Beginner Basics
Topic: 2 LAN Cables from Mikrotik to Switch
Replies: 24
Views: 3193

Re: 2 LAN Cables from Mikrotik to Switch

thanks @mkx and @pe1chl quick check on the wiki answers most of my question but thanks for more details on the topic for someone else reading this: layer-2-and-3 - This policy uses a combination of layer2 and layer3 protocol information to generate the hash. Uses XOR of hardware MAC addresses and IP...
by solar77
Thu Apr 30, 2020 5:05 pm
Forum: Beginner Basics
Topic: 2 LAN Cables from Mikrotik to Switch
Replies: 24
Views: 3193

Re: 2 LAN Cables from Mikrotik to Switch

I've actualy setup a lab test (once has some spare time during lockdown) : RB2011 (eth9 and eth10) to hAP ac Lite (eth1 and eth2) so each link is 100Mbps BUT, I can only get 98Mps udp between the two when using 802.3ad when testing with udp, 140Mbps TCP with balance-rr, 190Mbps UDP and 140Mbps TCP h...
by solar77
Thu Apr 30, 2020 2:02 pm
Forum: Beginner Basics
Topic: Slowness for the first few seconds then fast on download
Replies: 17
Views: 2224

Re: Slowness for the first few seconds then fast on download

the problem is the lockdonw, all man seek every opportunity to "work" and avoid doing house work. that's exactly what I am doing right now.
by solar77
Thu Apr 30, 2020 2:00 pm
Forum: Beginner Basics
Topic: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]
Replies: 56
Views: 6193

Re: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]

https://wiki.mikrotik.com/wiki/Manual:Packet_Flow this is really fundamental if you want to understand how it works. Look me a while and still not 100%. my understanding for use-ip-firewall, is bridged traffic, by default, does not go through the firewall. by ticking this box, you asking such traffi...
by solar77
Thu Apr 30, 2020 12:27 pm
Forum: Beginner Basics
Topic: 2 LAN Cables from Mikrotik to Switch
Replies: 24
Views: 3193

Re: 2 LAN Cables from Mikrotik to Switch

assuming bounding between two Mikrotiks should not have such problem?
by solar77
Thu Apr 30, 2020 11:39 am
Forum: Beginner Basics
Topic: Vlan through pptp behind ISP router??
Replies: 1
Views: 637

Re: Vlan through pptp behind ISP router??

Do you have access to the Huawei router? if yes, forward PPTP port to your Mikrotik and setup PPTP server on MT. you need forward port 1723 and also Protocal GRE (47) if you don't have access to the Huawei, then the only thing you can do is setup VPN client from your MT to a VPN server 3rd location ...
by solar77
Thu Apr 30, 2020 11:20 am
Forum: Beginner Basics
Topic: Mikrotik PPPOE server, wireless router as PPPOE dialer/client
Replies: 3
Views: 871

Re: Mikrotik PPPOE server, wireless router as PPPOE dialer/client

my best guess would be authentication, encryption or something in your PPP profile does not match that of the ASUS.
sorry cannot be more specific without actualy seeing the device config
by solar77
Thu Apr 30, 2020 11:15 am
Forum: Beginner Basics
Topic: 2 LAN Cables from Mikrotik to Switch
Replies: 24
Views: 3193

Re: 2 LAN Cables from Mikrotik to Switch

if you were to get another switch. get a Mikrotik CRS and setup bounding.
out of curiosity, what is the reason for such topology?
by solar77
Thu Apr 30, 2020 10:46 am
Forum: Beginner Basics
Topic: Help setting up EE 4g. on LHG LTE 4G
Replies: 10
Views: 1853

Re: Help setting up EE 4g. on LHG LTE 4G

I am also in scotland. don't worry, we will get you set up. few information needed: APN you can check this on the internet : https://kenstechtips.com/index.php/mobile-internet-apn-settings user/pass: in many cases the SIM will register without this. step by step: 1. open webfig 2. find Interfaces on...
by solar77
Wed Apr 29, 2020 6:16 pm
Forum: Beginner Basics
Topic: Port Forwading
Replies: 2
Views: 613

Re: Port Forwading

port forwarding can be done by using dst nat. https://wiki.mikrotik.com/wiki/Manual:IP/Firewall/NAT#Destination_NAT this is relatively easy to do but you are exposing yourself to the hacker world. if you have to do this, at least allowing only known IP address to access. VPN is a lot more secure. ru...
by solar77
Wed Apr 29, 2020 6:10 pm
Forum: Beginner Basics
Topic: Accessing ROS with Winbox over internet
Replies: 6
Views: 1160

Re: Accessing ROS with Winbox over internet

looking at "warning: Router is behind a NAT. Remote connection might not work." this is saying your LTE interface has not got a public IP address and only been given a private IP by your mobile network opeartor. This is very common with many mobile networks, unless you have requested an public IP (a...
by solar77
Wed Mar 04, 2020 4:37 pm
Forum: General
Topic: VPN client/server resources access issue
Replies: 1
Views: 1297

Re: VPN client/server resources access issue

could be a number of reasons, depending on your config but most commonly , if you can ping the VPN router but no the workstation on it's LAN side, that is because the remote client is unable to get ARPs from workstations. The solution is to set up proxy-arp on the local interface. /interface etherne...
by solar77
Tue Mar 03, 2020 1:31 pm
Forum: General
Topic: Recursive route faiover WITH bandwidth check
Replies: 1
Views: 1094

Re: Recursive route faiover WITH bandwidth check

a heavier test could be Flood ping but it is not reliable enough to check bandwidth

you can schedule a script to run bandwidth test
viewtopic.php?t=132233
and then switch between WAN interface
by solar77
Tue Mar 03, 2020 10:54 am
Forum: Beginner Basics
Topic: DHCPDISCOVER and DHCPOFFER spam on DHCP server from Mikrotik router
Replies: 10
Views: 2470

Re: DHCPDISCOVER and DHCPOFFER spam on DHCP server from Mikrotik router

in the config file posted, you have
/ip dhcp-server
add address-pool=default-dhcp interface=bridge name=defconf
this enables DHCP server on your bridge, which is now part of your LAN.

disable it
 /ip dhcp-server set defconf disabled=yes 
by solar77
Tue Mar 03, 2020 10:46 am
Forum: Beginner Basics
Topic: Different IP Address Segment [SOLVED]
Replies: 3
Views: 2521

Re: Different IP Address Segment [SOLVED]

how come if I connect to a Modem with IP 192.168.0.1 with DHCP server on, my Mikrotik can still broadcast wifi, connected cellphones / pc's have ip addresses of 192.168.0.x. and able to surf the web. if i am reading correctly, your wifi clients has ip 192.168.0.x so it's on the same range as your D...
by solar77
Tue Feb 25, 2020 6:56 pm
Forum: Beginner Basics
Topic: Get all login failures
Replies: 1
Views: 1197

Re: Get all login failures

log print where message ~"user"   
in Terminal
by solar77
Wed Jan 15, 2020 12:37 pm
Forum: Beginner Basics
Topic: SXT LTE6 Kit drops internet (EE UK)
Replies: 9
Views: 1562

Re: SXT LTE6 Kit drops internet (EE UK)

Image
https://ibb.co/4sn34zd
this is the band, cell ID etc. I'd say that's good.
by solar77
Wed Jan 15, 2020 11:04 am
Forum: Beginner Basics
Topic: SXT LTE6 Kit drops internet (EE UK)
Replies: 9
Views: 1562

Re: SXT LTE6 Kit drops internet (EE UK)

than you so much SiB for your help!
is there a way to disable CA and just use primary band? I can accept a slower connection as long as it stays connected.
by solar77
Tue Jan 14, 2020 11:20 pm
Forum: Beginner Basics
Topic: SXT LTE6 Kit drops internet (EE UK)
Replies: 9
Views: 1562

Re: SXT LTE6 Kit drops internet (EE UK)

this time it connected for about 3 hours , then connection dropped again. here is the log 20:34:39 lte,async,raw lte1: sent AT+CFUN? 20:34:39 lte,async,raw lte1: rcvd +CFUN: 1 20:34:39 lte,async,raw lte1: sent AT+COPS? 20:34:39 lte,async,raw lte1: rcvd +COPS: 0,2,"23430",9 20:39:31 lte,async,raw +CR...
by solar77
Tue Jan 14, 2020 5:54 pm
Forum: Beginner Basics
Topic: SXT LTE6 Kit drops internet (EE UK)
Replies: 9
Views: 1562

Re: SXT LTE6 Kit drops internet (EE UK)

thanks SiB for your time! I've got all the scrip for switch SIM etc, it works just fine on Vodafone SIM but EE SIM keeps dropping off. I am not expert in LTE connections so hope you can see what the issue is from the Log. EE signal seems fine to me. the script logged this before switching to Vodafon...
by solar77
Tue Jan 14, 2020 5:10 pm
Forum: Wireless Networking
Topic: Sxt LTE 4g+ Cat6>
Replies: 43
Views: 8546

Re: Sxt LTE 4g+ Cat6>

hi @SiB, any chance you could have a look this?
viewtopic.php?f=13&t=156164&p=769883#p769883
by solar77
Tue Jan 14, 2020 4:46 pm
Forum: Beginner Basics
Topic: SXT LTE6 Kit drops internet (EE UK)
Replies: 9
Views: 1562

Re: SXT LTE6 Kit drops internet (EE UK)

@SiB ?
by solar77
Tue Jan 14, 2020 2:18 pm
Forum: Beginner Basics
Topic: SXT LTE6 Kit drops internet (EE UK)
Replies: 9
Views: 1562

SXT LTE6 Kit drops internet (EE UK)

I have recently installed an SXT LTE6 Kit . EE SIM in slot A and Vodafone SIM in slot B. what i have added to the default config: Netwatch with script to monitor internet drops and to switching APN Profile and SIM Slot . VPN connection is just there for me to get remote acess. Normal Internet traffi...
by solar77
Wed Jun 12, 2019 7:07 pm
Forum: Beginner Basics
Topic: i need to help
Replies: 2
Views: 457

Re: i need to help

what is your internet speed? what is the distance between wired AP and repeaters ? do you have line of sight? what is the number of clients you expect to connect on each AP? what package you wish to provide to your customers? the equipment choice will be very diffierent , depending all these things....
by solar77
Fri May 17, 2019 3:11 pm
Forum: Beginner Basics
Topic: mikrotik as a manageable switch
Replies: 1
Views: 481

Re: mikrotik as a manageable switch

to be honest sir, you don't come across as knowing much about networking. My best advice is to hire a consultant to set up the network for you. I may be expensive at the start but the long term it is going to cheaper, less time consuming, and avoid possible problems for customers, in summary, good f...
by solar77
Sun May 12, 2019 10:19 pm
Forum: Beginner Basics
Topic: Simple Queues vs Queue Tree
Replies: 3
Views: 1461

Re: Simple Queues vs Queue Tree

you should add rate limit in their PPPoE Profile, this will create dynamic simple queue as soon as the PPPoE session is established.
by solar77
Fri May 10, 2019 11:06 pm
Forum: Beginner Basics
Topic: Tunnel to cloud server while preserving local IP addresses
Replies: 1
Views: 404

Re: Tunnel to cloud server while preserving local IP addresses

Establish an VPN connection between the Mikrotik and the cloud server. which is the serve and which is the client is up to you.
by solar77
Wed May 01, 2019 12:22 pm
Forum: General
Topic: VLAN - hybrid port - untagged VLAN 1
Replies: 11
Views: 2518

Re: VLAN - hybrid port - untagged VLAN 1

thanks ava, good reading. in particular there is a link within the text, to "Manual:Layer2 misconfiguration"
by solar77
Tue Apr 30, 2019 2:27 pm
Forum: General
Topic: VLAN - hybrid port - untagged VLAN 1
Replies: 11
Views: 2518

Re: VLAN - hybrid port - untagged VLAN 1

that I think is to give the CPU (Router) access to your managed VLAN
I have not tried it yet but that's my understanding.
by solar77
Mon Apr 29, 2019 5:02 pm
Forum: General
Topic: VLAN - hybrid port - untagged VLAN 1
Replies: 11
Views: 2518

Re: VLAN - hybrid port - untagged VLAN 1

hi, I have only started to look at VLAN recently . My understanding is that, the switch VLAN only comes into consideration if you wish to have hardware offload for VLAN (the traffic between VLAN ports would be near wire speed because the swhich chip feature support this). note on the wiki: For devic...
by solar77
Mon Apr 29, 2019 4:07 pm
Forum: Wireless Networking
Topic: hAP ac2 as bridge and CAP
Replies: 6
Views: 1218

Re: hAP ac2 as bridge and CAP

you can use a virtual wlan interface to be the AP. then add this interface to your LAN bridge for example, now I add wlan5 as a AP while I am using wlan1 as station /interface wireless set [ find default-name=wlan1 ] band=2ghz-b/g/n disabled=no distance=indoors frequency=2462 frequency-mode=regulato...
by solar77
Mon Apr 29, 2019 3:32 pm
Forum: General
Topic: VLAN - hybrid port - untagged VLAN 1
Replies: 11
Views: 2518

Re: VLAN - hybrid port - untagged VLAN 1

https://wiki.mikrotik.com/wiki/Manual:Basic_VLAN_switching#Other_devices_with_built-in_switch_chip is for VLAN on RB3011 but I think you can still use bridge VLAN as well. also check this https://wiki.mikrotik.com/wiki/Manual:Switch_Router#VLAN_switching so you will need to add VLAN to the bridge an...
by solar77
Sat Apr 20, 2019 8:16 pm
Forum: Beginner Basics
Topic: Need quick and east non-payment redirect for a single customer
Replies: 6
Views: 792

Re: Need quick and east non-payment redirect for a single customer

as suggested by flynno, easy way would be contact the customer and get paid, instead of spending time on a solution that you only need for few days. PS: you can make her IP static on the DHCP server so it is the same IP every time. you can argue that she could then change IP to another static IP but...
by solar77
Wed Apr 17, 2019 10:53 am
Forum: Beginner Basics
Topic: Rebooting mikrotik in certain time and turn on without resetting whole counters
Replies: 1
Views: 247

Re: Rebooting mikrotik in certain time and turn on without resetting whole counters

create a schedule and excut script , like this one (instead of reboot, you shutdown)
viewtopic.php?t=19985

don't think you can schedule it to switch on again.
however, you can schedule it to disable all it's ports and enable again.
by solar77
Wed Apr 17, 2019 10:47 am
Forum: Beginner Basics
Topic: Bridging WiFi client with DHCP and the rest
Replies: 2
Views: 425

Re: Bridging WiFi client with DHCP and the rest

what I'm trying to achieve is a router that connects over third party wifi APs and if none are available, it will fall back to LTE. you are looking for " dual WAN fail-over". Many many tutorial and posts avaiable but starts from wiki https://wiki.mikrotik.com/wiki/Advanced_Routing_Failover_without_...
by solar77
Tue Apr 16, 2019 7:01 pm
Forum: Beginner Basics
Topic: Best practices to copy config from one device to another
Replies: 3
Views: 548

Re: Best practices to copy config from one device to another

Hi, having done it few times, I'd suggest export is the way to go. backup is meant to be for the same router. best practice, 1. to make sure the destination router is on the same firmware level as the master router. 2. you would want to check the config over, remove any MAC address. unfortunately if...
by solar77
Sun Apr 14, 2019 10:41 pm
Forum: General
Topic: hotspot can't drop wifi client after session time finished
Replies: 4
Views: 641

Re: hotspot can't drop wifi client after session time finished

1. How to make redirection to local auth page automatically, without filling any address in the browser after the session time would stopped? 2. How to make full dissconection from wifi, after session time stops? 1. I don't think you can. redirection means re-directing something the user has filled...
by solar77
Sun Apr 07, 2019 2:27 pm
Forum: General
Topic: i need help with queue's
Replies: 5
Views: 525

Re: i need help with queue's

disable fastrack and test again. FastTracked packets bypass firewall, connection tracking, simple queues, queue tree with parent=global, ip traffic-flow(restriction removed in 6.33), IP accounting, IPSec, hotspot universal client, VRF assignment, so it is up to administrator to make sure FastTrack d...
by solar77
Sat Apr 06, 2019 4:57 pm
Forum: Beginner Basics
Topic: PPTP problems
Replies: 6
Views: 884

Re: PPTP problems

I would not think the CPU usage on any of the router would be too high? RB3011 should be able to handle 200Mbps VPN with ease. sorry I am not sure what the problem might be so the following is pure guess work: check for MTU isue so make sure, on both point 2 and point 3, MTU is correct and change MS...
by solar77
Sat Apr 06, 2019 3:19 pm
Forum: Beginner Basics
Topic: vlan by mac
Replies: 2
Views: 482

Re: vlan by mac

Dynamic VLAN Assignment with RADIUS and CAPsMAN Configuration Example
https://mum.mikrotik.com/presentations/ ... 137144.pdf

hope this helps.
by solar77
Sat Apr 06, 2019 12:18 pm
Forum: Beginner Basics
Topic: Help with hAP AC Lite basic config
Replies: 2
Views: 425

Re: Help with hAP AC Lite basic config

connect to the router from port 5,
remove port 2 to port 4 from local bridge (default name would be "bridge")
create a bridge. say "uplink", then add port 1 to port 4 to it
disable default DHCP client on port 1
done
by solar77
Sat Apr 06, 2019 12:09 pm
Forum: Beginner Basics
Topic: PPTP Issues
Replies: 13
Views: 1229

Re: PPTP Issues

I may give that a go, for the time being, I just re integrated my asus router and put my modem in bridge mode. So im hoping my ASUS router will allow me to open up the protocol that I need for L2TP-IPSec!! if your ISP modem can be in bridge mode, then why not use the Mikrotik behind it, instead of ...
by solar77
Fri Apr 05, 2019 12:10 pm
Forum: General
Topic: i need help with queue's
Replies: 5
Views: 525

Re: i need help with queue's

queue rule seems fine to me.
do you have fast track enabled in firewall?
by solar77
Fri Apr 05, 2019 11:06 am
Forum: Beginner Basics
Topic: PPTP Issues
Replies: 13
Views: 1229

Re: PPTP Issues

for l2tp + ipsec, you will need /ip firewall filter add chain=input protocol=udp port=1701,500,4500 add chain=input protocol=ipsec-esp your ISP router is probably not capable of allowing protocol so this won't work. I have not tried but it might work without ipsec. and SSTP requires certificate if y...
by solar77
Thu Apr 04, 2019 8:55 pm
Forum: Beginner Basics
Topic: PPTP Issues
Replies: 13
Views: 1229

Re: PPTP Issues

for PPTP, you will need to forward TCP 1723 and protocol 47 (GRE) to the Mikrotik
where SSTP only requires port 443
by solar77
Thu Apr 04, 2019 8:05 pm
Forum: General
Topic: i need help with queue's
Replies: 5
Views: 525

Re: i need help with queue's

please can you show your queue rules with
queue export
by solar77
Thu Apr 04, 2019 1:59 pm
Forum: General
Topic: DHCP: one IP address - multiple MAC address ?
Replies: 5
Views: 704

Re: DHCP: one IP address - multiple MAC address ?

May I ask why you wish to assigne one IP address to a user? I am not aware of any way to do this with Mikrotik DHCP server but you might be able to do it with hotspot. where the same user authentication will always get the same IP from the hotspot pool. The laptop will get different IP on wirelss, e...
by solar77
Thu Apr 04, 2019 1:08 pm
Forum: Beginner Basics
Topic: Bridge 2 vlans
Replies: 7
Views: 718

Re: Bridge 2 vlans

can i do this with just one router?? possibaly yes, if you can physcally have the hex router at the same location Aruba switch. so that network 1 is plugged in one port and network 2 is plugged in another. this way the hex will handle the inter-vlan routing. or if you have a router uplink from the ...
by solar77
Wed Apr 03, 2019 9:18 pm
Forum: Beginner Basics
Topic: Block traffic between VLAN
Replies: 8
Views: 1053

Re: Block traffic between VLAN

thanks Sob for further explaination . Much appreciated!
by solar77
Wed Apr 03, 2019 6:25 pm
Forum: Beginner Basics
Topic: Block traffic between VLAN
Replies: 8
Views: 1053

Re: Block traffic between VLAN

@Sob, thanks for the correction.

if each subnet / vlan is masqueraded behind the IP of it's interface. would this rule block traffic between them?
by solar77
Wed Apr 03, 2019 12:30 pm
Forum: Beginner Basics
Topic: Block traffic between VLAN
Replies: 8
Views: 1053

Re: Block traffic between VLAN

I think this will block traffic between any IP that is assigned to a local interface, except within the same bridge
/ip firewall filter
add chain=forward src-address-type=local dst-address-type=local action=drop
by solar77
Tue Apr 02, 2019 7:37 pm
Forum: Beginner Basics
Topic: Force local IP to use specific wan on load balancing
Replies: 15
Views: 1882

Re: Force local IP to use specific wan on load balancing

keep a backup config each step of the way . so you can always reset the router to factory default and come back to your latest backup again. This made me been very brave in my early days with Mikrotik
by solar77
Tue Apr 02, 2019 6:58 pm
Forum: Beginner Basics
Topic: PPTP problems
Replies: 6
Views: 884

Re: PPTP problems

what is the actual throughput without VPN between point 2 and point 3? when i connect point3 to point2 that is connected to point1 do you mean a client from Point 3, connect to the VPN server at Point 1, but the link is via point 2? if yes, is Point 2 just a bridge? do you have fast forward enabled?
by solar77
Tue Apr 02, 2019 6:33 pm
Forum: Beginner Basics
Topic: Force local IP to use specific wan on load balancing
Replies: 15
Views: 1882

Re: Force local IP to use specific wan on load balancing

Glad it worked. opening all these UDP port and the word P2P seems be a "risky game" :-) I'd suggest to put this device in it's own VLAN so whoever has access to it, cannot access anything else on your network. PS: use good measure to protect your router as well. close down services you don't need, u...
by solar77
Tue Apr 02, 2019 6:01 pm
Forum: Beginner Basics
Topic: Force local IP to use specific wan on load balancing
Replies: 15
Views: 1882

Re: Force local IP to use specific wan on load balancing

it does seem to bypass policy based routing, I am not sure why but hopefully someone can tell me in this thread.

what port forwarding do you have to do? is it to the Nintendo ? this rule should only affect traffic originated from this particular IP address.
by solar77
Tue Apr 02, 2019 5:50 pm
Forum: Beginner Basics
Topic: Disable all services except api, how to start www or ssh or telnet?
Replies: 1
Views: 359

Re: Disable all services except api, how to start www or ssh or telnet?

you can see use Winbox to access the device by using it's MAC address.

you will need to to connect to the router directly by network cable, you should see it comes up in Neighbors tag.
by solar77
Tue Apr 02, 2019 5:04 pm
Forum: Beginner Basics
Topic: Force local IP to use specific wan on load balancing
Replies: 15
Views: 1882

Re: Force local IP to use specific wan on load balancing

It would normally work but I am not 100% in your case because you already have PCC.

I'd suggest to try
 
 /ip firewall mangle
 add chain=prerouting src-address=IP_of _ Nintendo dst-address-type=!local action=route dst-address=gateway_WAN2
by solar77
Sat Mar 23, 2019 10:17 pm
Forum: General
Topic: How much Support RB3011
Replies: 12
Views: 1244

Re: How much Support RB3011

use fast track on forward chain, established and connected traffic.

https://mikrotik.com/product/RB3011UiAS ... estresults
this is some indication for you.
by solar77
Fri Mar 22, 2019 6:51 pm
Forum: Beginner Basics
Topic: How to renew ip address when reconnecting pppoe
Replies: 5
Views: 744

Re: How to renew ip address when reconnecting pppoe

I am little confused here. when you say "some ips that are attacked ", I assume they are public IP address so you have a pool of public IP, they are not static to individual PPPoE client, and you want each PPPoE client to pick up a different public IP each time they connect? I'd think proper / more ...
by solar77
Fri Mar 22, 2019 6:43 pm
Forum: Beginner Basics
Topic: Port forward on port 8080
Replies: 14
Views: 1444

Re: Port forward on port 8080

The alternative is post nothing.

Why's this such a dreadful option?
Ha .... :lol:

sorry, in the business of helping OP. if the dst-nat rule has no traffic passing through, you need to check why the traffic is not reaching. complete config would give us more idea
by solar77
Fri Mar 22, 2019 1:55 pm
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 44
Views: 20141

Re: DHCP Offering Lease Without Success

I have followed up another device on this network having similar issue. It is also a Nintendo device. Here is my thought: I have hotspot running so it can connect to wiFi (both devices has -60dBm signal level and low channel utilisation ) but they cannot authenticate on the hotspot portal. /ip hotsp...
by solar77
Fri Mar 22, 2019 11:56 am
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 44
Views: 20141

Re: DHCP Offering Lease Without Success

@ pe1chl thanks for reply. I am looking into it a bit more: more often than not, before an "offering lease without success" error, Mikrotik repeately deassign and assigne DHCP over and over this happens to a range of devices. I did consider an wireless connection issue but my question is: this netwo...
by solar77
Fri Mar 22, 2019 10:50 am
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 44
Views: 20141

Re: DHCP Offering Lease Without Success

having this issue as well. first thought it was caused by my Unifi APs but now it seems to be pointing towards Mikrotik. It is now affecting non Apple devices (so far 2 x windows 10 laptops, one of which is ASUS).
I am running CCR1009, ROS 6.43

any one has a fix yet?
by solar77
Fri Mar 15, 2019 4:29 pm
Forum: Beginner Basics
Topic: Firewall rules
Replies: 6
Views: 700

Re: Firewall rules

ok I see what you mean now. So the URL will just be an Internal IP if you connected to it from LAN.
somehow i think the OP is using IP address not URL though
I set up the camera live view application from the outside IP address
by solar77
Fri Mar 15, 2019 11:53 am
Forum: Beginner Basics
Topic: Hotspot Bypass [SOLVED]
Replies: 9
Views: 1373

Re: Hotspot Bypass [SOLVED]

It's not the repeater does not have access to the internet, it's the app (the device where the app is running on) does not see the repeater.
by default hotspot client does not see other clients and LAN network.
by solar77
Thu Mar 14, 2019 7:08 pm
Forum: General
Topic: Topology for cotteges
Replies: 8
Views: 862

Re: Topology for cotteges

we have done similar projects, using both Ubiquiti products and mikrotik, and combination of both. Here is my contribution: 1. if you have the option, go with fibre. search posts here for reasons but when you do a new install and running cables anyway, use fibre. 2.lets focus on Mikrotik, you can us...
by solar77
Thu Mar 14, 2019 6:23 pm
Forum: Beginner Basics
Topic: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?
Replies: 23
Views: 2772

Re: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?

Isn't it supposed to work just by creating some firewall rules ? Not really, you need NAT rule and routing rule. Because load balancing by definition seems more than what I need now, I just need to separate them in a fixed way. Its the type of load balancing where part of your network uses one conn...
by solar77
Thu Mar 14, 2019 3:04 pm
Forum: Beginner Basics
Topic: Hotspot Bypass [SOLVED]
Replies: 9
Views: 1373

Re: Hotspot Bypass [SOLVED]

not sure why you want to do this but you can.
add the MAC address of any device within your Local Area Network, in IP - Hotspot - IP Bindings
then set the Type to "bypassed"
by solar77
Thu Mar 14, 2019 1:37 pm
Forum: Beginner Basics
Topic: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?
Replies: 23
Views: 2772

Re: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?

the bridge is created by the router on default. it's normally the LAN ports all joined under this bridge. now you have 2 x PPPoE session, what you need is load-balancing. it's been discussed often on the forum. and there is a document you can read first to get the idea https://wiki.mikrotik.com/wiki...
by solar77
Wed Mar 13, 2019 1:44 pm
Forum: Beginner Basics
Topic: Trying to make service available from VPN
Replies: 6
Views: 584

Re: Trying to make service available from VPN

not sure why you cannot use 10.10.10.0/28 range as VPN Local address, I don't think it matters but happy to learn otherwise. in my view, you can use either 192.168.78.1 or 10.10.10.1 as local IP for VPN. use the matching pool . double check you have Add Default route and user peer DNS on the DHCP cl...
by solar77
Tue Mar 12, 2019 5:13 pm
Forum: General
Topic: What is the best method to connect between 2 routers? and How?
Replies: 8
Views: 694

Re: What is the best method to connect between 2 routers? and How?

Plug one ethernet cable into a port on one router and plug the other end of the ethernet cable on the other router.
Sorry I laughed. :lol: that is exactly what came to my mind on reading the subject, even before got to the actuall post itself....
by solar77
Tue Mar 12, 2019 5:09 pm
Forum: Beginner Basics
Topic: Trying to make service available from VPN
Replies: 6
Views: 584

Re: Trying to make service available from VPN

very interesting case so I will kick start. It might take me few attempt to get it working but I'd think it's possible. first try to set the VPN in the way that local address is that of the ether5, and VPN pool is in the same range as that of the Cisco box. when connected via VPN, the laptop should ...
by solar77
Tue Mar 12, 2019 4:56 pm
Forum: Beginner Basics
Topic: Hotspot wifi and Lan users
Replies: 13
Views: 1938

Re: Hotspot wifi and Lan users

Vlan id = 2 has been created on Switch to differ AP's from LAN users. Mikrotik router CCR a hotpsot created with dhcp server and pool 10.5.50.0/24 on Ethernet 3 wifi users cannot access the hotspot dhcp pool and get ip address. I can see that the hotspot is on ether3 but it needs to be on VLAN2. th...
by solar77
Tue Mar 12, 2019 2:24 pm
Forum: Beginner Basics
Topic: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?
Replies: 23
Views: 2772

Re: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?

Glad it's moving forward. Note you DIY trick would void warranty on both the ISP modem and the Mikrotik. is getting another 2 x modem from the ISP possible? because you do have another 2 account and it should come with a modem. Even not, I'd suggest you try to connect to their firbre first and see w...
by solar77
Tue Mar 12, 2019 1:55 pm
Forum: Beginner Basics
Topic: Firewall rules
Replies: 6
Views: 700

Re: Firewall rules

@sebastia I don't think DNS catch is going to work . Steveocee is right and the OP needs hairping nat. client send packet to IP of camera, get changed to internal IP of camera, return traffic has source IP of Internal camera IP. client device drops it because it's does not much the dst-ip of origina...
by solar77
Mon Mar 11, 2019 10:50 pm
Forum: Beginner Basics
Topic: After configuration when connecting all ports no internet connection
Replies: 4
Views: 429

Re: After configuration when connecting all ports no internet connection

/ip firewall nat
add action=masquerade chain=srcnat
missing out-interface=

first test if the router itself can ping 8.8.8.8, then the router can resolve a dns name, before you move on to other things.
by solar77
Mon Mar 11, 2019 7:43 pm
Forum: Beginner Basics
Topic: Hotspot wifi and Lan users
Replies: 13
Views: 1938

Re: Hotspot wifi and Lan users

if both the lan and wifi network are connected to the same layer 2 switch, you will not be able to stop the traffic going between. can you connect desktop PCs to the rouer so those ports can have the 192.168.22.0/24 only? and wifi on other ports or through swich? if you cannot physically bring all b...
by solar77
Mon Mar 11, 2019 4:49 pm
Forum: Beginner Basics
Topic: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?
Replies: 23
Views: 2772

Re: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?

very lucky man to have 3 x 1Gbps fibre. Contact your ISP and see if they allow you to remove the modem and just use the Mikrotik. and if yes, what SFP module they would recommend (muti-mode, or single mode). So the fibre feed can go straight into the Mikrotik. It's likely you can do this as you alre...
by solar77
Mon Mar 11, 2019 4:07 pm
Forum: Beginner Basics
Topic: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?
Replies: 23
Views: 2772

Re: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?

that's an interesting case. Yes I believe you can have 3 x PPPoE running on the Mikrotik and load-balancing them . you don't need VLAN. hardware selection depends on the uplink speed but most Mikrotik routers come with the same router OS, same feature, so even the basic model will do ospf, BGP, VLAN...
by solar77
Mon Mar 11, 2019 2:40 pm
Forum: Beginner Basics
Topic: Hotspot wifi and Lan users
Replies: 13
Views: 1938

Re: Hotspot wifi and Lan users

Answer: the main router can be a hotspot server. there is no need for the 2nd Mikrotik to be there if that's the only job it does. create a separate subnet on the ports where th WiFi AP is connected to. use VLAN if you want but it's not a must. so you will have bridge_lan and bridge_wifi, for exampl...
by solar77
Mon Mar 11, 2019 1:28 pm
Forum: Beginner Basics
Topic: Hotspot wifi and Lan users
Replies: 13
Views: 1938

Re: Hotspot wifi and Lan users

topology ?
by solar77
Sat Mar 09, 2019 11:51 am
Forum: General
Topic: VLAN across PPPoE clients
Replies: 7
Views: 568

Re: VLAN across PPPoE clients

@Redmor
thanks for advice. any chance you could post relevant config for doing the VLAN over EOIP?
also can you force MTU to be 1500? L2 is needed as the Monitor can only be discovered by the Panel, we cannot tell the monitor where the Panel is.
by solar77
Fri Mar 08, 2019 11:18 pm
Forum: General
Topic: VLAN across PPPoE clients
Replies: 7
Views: 568

Re: VLAN across PPPoE clients

I'd expect some direction from the helpful people here by now...or are we all in the pub?
by solar77
Fri Mar 08, 2019 8:35 pm
Forum: Beginner Basics
Topic: HELP: how to per ip shaping?
Replies: 10
Views: 1153

Re: HELP: how to per ip shaping?

it might be that you have other rules kicking in once the speed is set to 50/50 my suggestion, as in previous post, is to change Rate in both pcq-download-default and pcq-upload-default then add simple queue, with nothing else, just use the PCQ as in add name=LAN_PCQ queue=pcq-upload-default/pcq-dow...
by solar77
Fri Mar 08, 2019 6:15 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 4988

Re: load-balancing don't work

@WeWiNet Thanks for tips. This is only a trial for me to see how it would work out. If I was using it, yes fail-over will have to be there. . I am still not clear where the DNS traffic from the router itself goes , I think this is what this rule is for but not tested and I am using 8.8.8.8 on local ...
by solar77
Fri Mar 08, 2019 6:06 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 4988

Re: load-balancing don't work

SOLAR, both the WIKI and Steve Discher show that rule as a prerouting chain BUT IN_INTERFACE=WAN ????? The MUM2019 presentation shows that as input chain BUT IN_INTERFACE=WAN. Can i surmize that you are using bridge because you are simply simulating wan input??? I like your logic. ALL rules with ma...
by solar77
Fri Mar 08, 2019 6:00 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 4988

Re: load-balancing don't work

@plisken my config can work at 2 wan as well, just remove anything to do with wan3 and change PCC to 2/0 and 2/1 the only reason I did not do a whole router export is I've used it to test vlan staff before and there are many unrelated code left. what I did was step by step: get each of wan connectio...
by solar77
Fri Mar 08, 2019 5:12 pm
Forum: Beginner Basics
Topic: Help with WAN bandwidth limiting
Replies: 12
Views: 923

Re: Help with WAN bandwidth limiting

it's rx/tx , I think, so upload or download depending on that interface / target you apply it to.
by solar77
Fri Mar 08, 2019 3:42 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 4988

Re: load-balancing don't work

Note 6, when winbox into the uplink router (Router 1 broadcasting 3 SSID), it used wan2, when I open 2nd winbox session, it still use the same wan2, so the bandwidth doubles, then I opened 3rd, 4th winbox, they all use the same wan2, with increasing bandwidth flowing. this shows the both address opt...
by solar77
Fri Mar 08, 2019 3:33 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 4988

Re: load-balancing don't work

Right, I've done it myself. Its working and here is what I did: my set up is not a real multiple WAN but 3 virtual wlan interface ( AP Bridge modem, broadcasting 3 SSID) from Mikrotik hAP, wihch has Internet access. Each SSID has it's own network: 10.10.1.0/24, 10.10.2.0/24, 10.10.3.0/24 Tested each...
by solar77
Thu Mar 07, 2019 8:57 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 4988

Re: load-balancing don't work

I had the input chain question this morning, ha ha ! what I did was create a rule on my own router, on prerouting chian, in-interface is WAN, which I thought won't have any traffic. but it did, as all traffic heading to my WAN ip, it get translated (NATed) into my LAN IP. which then get marked with ...
by solar77
Thu Mar 07, 2019 6:54 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 4988

Re: load-balancing don't work

nice presentation, well you making me doubt myself. however, it's not complete identical. check page 22, the route section, the presentation has 4 rules, the 1st two has identical distance, both been set o 1, and using routing mark. This is part of the load balancing route. then the next two rules, ...
by solar77
Thu Mar 07, 2019 4:56 pm
Forum: General
Topic: VLAN across PPPoE clients
Replies: 7
Views: 568

Re: VLAN across PPPoE clients

I will be doing some tests on option 1 which seems to be less of a hassle. will report back.
any comments are welcome in the meantime.
by solar77
Thu Mar 07, 2019 3:34 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 4988

Re: load-balancing don't work

I have not used PCC but compare your config with https://wiki.mikrotik.com/wiki/Manual:PCC the example does not use passthrough=yes, without understand all your config, i suspect some of the traffic got marked twice because of this. then the result would be only WAN2_conn is left and that's why all ...
by solar77
Thu Mar 07, 2019 11:52 am
Forum: Beginner Basics
Topic: HELP: how to per ip shaping?
Replies: 10
Views: 1153

Re: HELP: how to per ip shaping?

as suspected, it's TCP traffic on port 80 so you cannot limit bandwidth per protocol or port. don't set PCQ to 0, in winbox, go into queue , queue type, find pcq-download-default and pcq-upload-default, apply rate of your choice. then in simple queue, do this add name=LAN_PCQ queue=pcq-upload-defaul...
by solar77
Thu Mar 07, 2019 11:33 am
Forum: General
Topic: VLAN across PPPoE clients
Replies: 7
Views: 568

Re: VLAN across PPPoE clients

anyone?
by solar77
Wed Mar 06, 2019 10:24 pm
Forum: General
Topic: VLAN across PPPoE clients
Replies: 7
Views: 568

Re: VLAN across PPPoE clients

sorry R1 at the bottom should really be R3. my mistake.
by solar77
Wed Mar 06, 2019 10:02 pm
Forum: General
Topic: Backup WAN allow WInbox connection always
Replies: 1
Views: 249

Re: Backup WAN allow WInbox connection always

you can get this routing mark by adding a mangle rule on the Input chain to mark the connection, then on the output chain to add routing mark to this connection so traffic comes in from interface=wan2, dst-port=8291, protocal=tcp, gets marked by a connection mark, then the return traffic will still ...
by solar77
Wed Mar 06, 2019 5:09 pm
Forum: General
Topic: VLAN across PPPoE clients
Replies: 7
Views: 568

VLAN across PPPoE clients

trying to get L2 connectivity between PPPoE clients so that the intercom Panel can see the monitor (IPV6 only, cannot set an IPv4 address to it). attached a drawing to show what we have. basically R1 is our core network, running a PPPoE server. R2, R3, R4 is customer site, running PPPoE client, then...
by solar77
Wed Mar 06, 2019 3:55 pm
Forum: General
Topic: QoS and Limit bandwidth
Replies: 3
Views: 600

Re: QoS and Limit bandwidth

I'd think using IP is better as the whole queue solutionis simpler, all your target can be catolorised by IP address the email, the server (assuming behind a public IP or interanl IP even) these two would be set with higher priority and higher Limit-at value then you can have PCQ for your LAN subnet...
by solar77
Wed Mar 06, 2019 12:10 pm
Forum: General
Topic: How to get on mikrotik list of arp records at port.
Replies: 3
Views: 478

Re: How to get on mikrotik list of arp records at port.

if it is a slave port of a master, ARP table will probably show the MACs under the master port anyway. It's L2 connectivity
by solar77
Wed Mar 06, 2019 11:56 am
Forum: General
Topic: problem with DHCP
Replies: 2
Views: 307

Re: problem with DHCP

I'd suggest to put your RB750 in router mode.
so the DHCP client on ether1 will pick up address from the SXT and DHCP server on Local bridge (include ether2 to ether5) will issue address to your own clients, with the DHCP server on the 750, you can set static DHCP entry as you wish.
by solar77
Wed Mar 06, 2019 10:48 am
Forum: Beginner Basics
Topic: HELP: how to per ip shaping?
Replies: 10
Views: 1153

Re: HELP: how to per ip shaping?

first of all /queue type set 5 pcq-rate=47M set 6 pcq-rate=50M by default these two are not PCQ so please double check, make sure you have configured pcq-download-default and pcq-upload-default by check from winbox, make sure the rate is set. secondly /queue simple add max-limit=47M/50M name=Interne...
by solar77
Wed Mar 06, 2019 10:42 am
Forum: Beginner Basics
Topic: mikrotik bridge mode
Replies: 6
Views: 626

Re: mikrotik bridge mode

can you do a export hide-sensitive on the Mikrotik and show us the result? suspect something else is causing the issue. alternatively, reset the router and untick "default configuration". this will wipe all the config out of the Mikrotik, then you only do two things: add two interface into the bridg...
by solar77
Tue Mar 05, 2019 7:10 pm
Forum: Beginner Basics
Topic: Help with WAN bandwidth limiting
Replies: 12
Views: 923

Re: Help with WAN bandwidth limiting

ha ha avav, that makes the two of us. :D I am more into traffic management and know less about routing. there is always something new to pick up when I visit this forum. Keeps working fun.
by solar77
Tue Mar 05, 2019 5:32 pm
Forum: Beginner Basics
Topic: Help with WAN bandwidth limiting
Replies: 12
Views: 923

Re: Help with WAN bandwidth limiting

@anav I don't think limiting sessions is a solution here. if you watch under firewall - > connections, and do a speed test, such as speedtest.net, you will find it likes to use TCP port 80 over multiple connections. Some streaming services will do the same, (where I thought they should use UDP ). so...
by solar77
Tue Mar 05, 2019 2:33 pm
Forum: Beginner Basics
Topic: Help with WAN bandwidth limiting
Replies: 12
Views: 923

Re: Help with WAN bandwidth limiting

Hi Anav, no the PO wants limit the WAN bandwidth as a whole so that the keep-alive packets (assuming from the isp) to the vdsl modem does not get dropped.
So limiting upload to 1.8Mbps would probably enough. So the queue is applied to the PPPoE interface.

that's my understanding anyway.
by solar77
Tue Mar 05, 2019 2:13 pm
Forum: Beginner Basics
Topic: Extending home network with additional mikrotik APs.
Replies: 6
Views: 1019

Re: Extending home network with additional mikrotik APs.

The wSAP AC Lite is an alternative. It gives you 2 additional Ethernet ports (include 1 x passive POE out) and it fits into standard wall power sockets (US). but wifi coverage is probably not as good as the cAP AC.
by solar77
Tue Mar 05, 2019 1:42 pm
Forum: Beginner Basics
Topic: HELP: how to per ip shaping?
Replies: 10
Views: 1153

Re: HELP: how to per ip shaping?

Please can you do
/queue export
just want to see how your PCQ is set up.
by solar77
Tue Mar 05, 2019 1:38 pm
Forum: Beginner Basics
Topic: Help with WAN bandwidth limiting
Replies: 12
Views: 923

Re: Help with WAN bandwidth limiting

you are over doing it. the tutorials are probably policy based bandwidth limiting where one type of traffic gets x amount of bandwidth. you don't need this. all you need is to create a simple queue , /queue simple add max-limit=1M/2M name="bandwidth limit" target=pppoe-interface this example limits ...
by solar77
Tue Mar 05, 2019 1:25 pm
Forum: Beginner Basics
Topic: 2 connections, 1 vpn. need vpn to bypass one of the connections, need urgent help.
Replies: 1
Views: 177

Re: 2 connections, 1 vpn. need vpn to bypass one of the connections, need urgent help.

1st of all, try use SSTP (port 443 )instead of PPTP. SSTP is harder to block. My 4G connections blocks PPTP but I can use SSTP. secondly, I'd suggest to create mangle rule to add routing mark on all traffic with destination address to your VPN server, then add manual routing entry, so traffic with t...
by solar77
Tue Mar 05, 2019 1:13 pm
Forum: Beginner Basics
Topic: Two Mikrortik with same WAN
Replies: 9
Views: 659

Re: Two Mikrortik with same WAN

Is the ISP modem a router or a bridge. Can it be a bridge?
by solar77
Tue Mar 05, 2019 1:07 pm
Forum: Beginner Basics
Topic: mikrotik bridge mode
Replies: 6
Views: 626

Re: mikrotik bridge mode

remove 192.168.1.1/24 on ether1, that IP is likely to be the modem itself.
and try again.
by solar77
Tue Mar 05, 2019 11:35 am
Forum: Beginner Basics
Topic: Noob default route question
Replies: 8
Views: 795

Re: Noob default route question

@vecernik87
thanks. I now know the cause for some of our problems. It's good to have an informative posts like yours and that's what keeps get me back to this forum.
by solar77
Sat Feb 02, 2019 7:36 pm
Forum: Beginner Basics
Topic: Hotspot + pppoe in 1 port
Replies: 7
Views: 942

Re: Hotspot + pppoe in 1 port

the answer is put them in VLANs.
by solar77
Fri Feb 01, 2019 5:48 pm
Forum: Beginner Basics
Topic: Failover Issue [SOLVED]
Replies: 14
Views: 1928

Re: Failover Issue [SOLVED]

hi anav 1st question, to the best of my knowledge, not really. and cannot think why it should be any differences. Masquerade is basically source nat but only change the src-ip to that of the out-interface. 2nd, I believe you can do /ip firewall connection tracking set enabled=no which is easy to add...
by solar77
Fri Feb 01, 2019 4:29 pm
Forum: Beginner Basics
Topic: Hotspot + pppoe in 1 port
Replies: 7
Views: 942

Re: Hotspot + pppoe in 1 port

that's easier to set up. In my view Hotspot is for users that come and go, like a hotel / shop scenario. PPPoE is more for fixed users who does not have to log in from every device under one account, and more suited in ISP type scenario.
by solar77
Fri Feb 01, 2019 4:20 pm
Forum: Beginner Basics
Topic: Failover Issue [SOLVED]
Replies: 14
Views: 1928

Re: Failover Issue [SOLVED]

or reset all connections as soon as you move to the 2nd connection, by disable / enable Connection Tracking.
by solar77
Fri Feb 01, 2019 4:16 pm
Forum: Beginner Basics
Topic: Failover Issue [SOLVED]
Replies: 14
Views: 1928

Re: Failover Issue [SOLVED]

Thanks for the reply. I went through the aforementioned article and other relevant articles. From my understanding after reading those, existing sessions (especially from ping or from the same website on the same browser) don't switch to the new ISP after the failover. I may be wrong. I think you a...
by solar77
Fri Feb 01, 2019 11:31 am
Forum: Beginner Basics
Topic: Hotspot + pppoe in 1 port
Replies: 7
Views: 942

Re: Hotspot + pppoe in 1 port

Interesting idea. Not tried but I'd imagine you will need VLAN so the PPPoE and Wireless network are separate. you can probably put them on the same interface without VLAN but that means running a DHCP server on this interface for hotspot users, while PPPoE users can also pick up an IP address from ...
by solar77
Fri Feb 01, 2019 11:20 am
Forum: Beginner Basics
Topic: Bandwidth Limited
Replies: 1
Views: 365

Re: Bandwidth Limited

difficult to guess without seeing the config. maybe do a export hide-sensitive and post here? few things on my mind: enable Fast forward on your bridge disable all firewall rule and queue, then test again. watch Tools - Profile while you test, see what is using your CPU. However I really don't think...
by solar77
Fri Feb 01, 2019 11:07 am
Forum: Beginner Basics
Topic: Failover Issue [SOLVED]
Replies: 14
Views: 1928

Re: Failover Issue [SOLVED]

your routing config: /ip route add distance=1 gateway=192.168.75.1 add distance=2 gateway=192.168.42.129 as long as the router can reach gateway IP (which does not mean there is internet connection beyond this gateway), the route will be available and distance=1 route (assuming that's your ADSL) is ...
by solar77
Mon Jan 28, 2019 11:19 am
Forum: Beginner Basics
Topic: output chain traffic routing
Replies: 0
Views: 408

output chain traffic routing

trying to keep the radius traffic from a router to use a fixed WAN interface without success. The network: OSPF enabled so the route to 0.0.0.0/0 is dynamically added by OSPF, there are two of them (10.10.0.241 and 249 being the gateways), so as a result I have ADo 0.0.0.0/0 10.10.0.241 110 10.10.0....
by solar77
Fri Jan 25, 2019 7:27 pm
Forum: Beginner Basics
Topic: I Need Help With VPN
Replies: 1
Views: 299

Re: I Need Help With VPN

do you have static routing in place at each router? sounds like you need: on Matriz /ip route add distance=1 dst-address=192.168.0.0/24 gateway=remote IP of your VPN connection, it would be 192.168.88.xx on the other router /ip route add distance=1 dst-address=192.168.88.0/24 gateway=remote IP of yo...
by solar77
Thu Jan 24, 2019 12:07 pm
Forum: Beginner Basics
Topic: ether1: Probably look (How to solve?)
Replies: 14
Views: 1922

Re: ether1: Probably look (How to solve?)

when we had similar issue on a wireless point to multi point link, it turned out to be someone copied the config between routers, thinking to chagne the IP of each router only. what he didn't realise is the MAC address of each interface were also in the config.....so all station routers ended up hav...
by solar77
Thu Jan 24, 2019 11:40 am
Forum: Beginner Basics
Topic: Firewall filter rules CCR-1009
Replies: 4
Views: 595

Re: Firewall filter rules CCR-1009

remember to keep your "allow established and related" filter rule on the top.
This ensure the return traffic from one VLAN to another is not dropped.
by solar77
Thu Jan 24, 2019 10:55 am
Forum: Beginner Basics
Topic: Firewall filter rules CCR-1009
Replies: 4
Views: 595

Re: Firewall filter rules CCR-1009

allow the connections first, and then block all other inter-vlan traffic. so you set up filter rule on forward chain, allow traffic from vlan 11 to server vlan 10 allow traffic from vlan 11 to address list (do this in ip firewall address lists) that contains 192.168.12.100-192.168.12.200 drop all tr...
by solar77
Thu Jan 24, 2019 10:35 am
Forum: Beginner Basics
Topic: one port only internet, no lan [SOLVED]
Replies: 20
Views: 2517

Re: one port only internet, no lan [SOLVED]

make sure this port is not part of the bridge with other LAN ports. otherwise traffic will not hit firewall unless you tells it to. set up separate IP Address, Network, DHCP server etc for this port. make sure traffic from this subnet is NATed. I would have a separate masquerade rule for each subnet...
by solar77
Wed Jan 23, 2019 7:15 pm
Forum: Beginner Basics
Topic: How to discover a remote device on the network ?
Replies: 6
Views: 713

Re: How to discover a remote device on the network ?

Do like your drawing. so here is my 12 pence : if you have to discover remote devices on router 2, make it a bridge, instead of a router. turn of DHCP on the TP Llink, connect a LAN port of router 2 to a LAN port of router 1. this is the only way to do it if you want to monitor inside of Router 2. s...
by solar77
Tue Jan 22, 2019 4:05 pm
Forum: Beginner Basics
Topic: Unify and mikrotik
Replies: 1
Views: 505

Re: Unify and mikrotik

I have the exact setup as you described. Unifi controller: set up 2 SSID, one with VLAN tag, on the Unifi Controller. I use Unifi switch as well so they will adjust to VLAN config on the controller but you just have to make sure the switch port which the Unifi AP plugs into is a trunk port. As the U...
by solar77
Tue Jan 22, 2019 10:28 am
Forum: Beginner Basics
Topic: Hotspot
Replies: 1
Views: 302

Re: Hotspot

http://bfy.tw/LuLg
have a look around and come back if you have specific question. I would recommend to use the Hotspot Setup within Mikrotik.

yes you can downgrade.
by solar77
Mon Jan 21, 2019 6:45 pm
Forum: Beginner Basics
Topic: L2TP/Ipsec ping issue
Replies: 1
Views: 320

Re: L2TP/Ipsec ping issue

did you set up static routing so the site-A router knows to route traffic to subnet of Site B to Gateway-B ?
by solar77
Mon Jan 21, 2019 6:42 pm
Forum: Beginner Basics
Topic: Information on models and configurations
Replies: 4
Views: 665

Re: Information on models and configurations

in addition to the above advice, - Is it possible to isolate the networks between them? If so how? yes, many ways, it's fun to search the forum before you ask someone to do it for you. - Are the product configuration options identical in all models? almost. unless you trying to use wireless or SFP o...
by solar77
Sat Jan 19, 2019 8:12 pm
Forum: General
Topic: How to copy a dynamic route?
Replies: 2
Views: 491

Re: How to copy a dynamic route?

in winbox, double check your dynamic route, then click copy. modify the copied rule as you wish, Click on OK.
by solar77
Fri Jan 18, 2019 7:07 pm
Forum: Beginner Basics
Topic: How to forward ports to multiple WAN interfaces?
Replies: 10
Views: 2132

Re: How to forward ports to multiple WAN interfaces?

OK lets see. @anav if you have 3 NIC on the server, then you can route each IP to a chosen gateway but I cannot think of a way of doing it without mangle (which you are allergic to :-D because try add a static route, your dst-address is 0.0.0.0/0 and gateway is GatewayX, there is no way to add sourc...
by solar77
Fri Jan 18, 2019 4:41 pm
Forum: Beginner Basics
Topic: How to forward ports to multiple WAN interfaces?
Replies: 10
Views: 2132

Re: How to forward ports to multiple WAN interfaces?

@mkx, yes it does make more sense now (even when I have not finished that tutorial video regarding Packet Flow). as you say, out-interface is a condition of such masquerade rule, not the outcome of it. Traffic is going out on that particular interface because routing engine tells it to. Now, out of ...
by solar77
Fri Jan 18, 2019 11:37 am
Forum: Beginner Basics
Topic: How to forward ports to multiple WAN interfaces?
Replies: 10
Views: 2132

Re: How to forward ports to multiple WAN interfaces?

anav, I get what you are saying about making assumptions. yes that was an assumption in my part. it was made based on my "best guess", if not correct, then we can change the solution . second reason , is the mangle rules are needed whether it's a fail-over or load-balancing set up, in my humble opin...
by solar77
Thu Jan 17, 2019 3:19 pm
Forum: Beginner Basics
Topic: How to forward ports to multiple WAN interfaces?
Replies: 10
Views: 2132

Re: How to forward ports to multiple WAN interfaces?

In addition to port forwarding (Dst NAT to your LAN IP, port), you will have to make sure the return traffic goes back to the WAN interface they come from. to do this , you mark the incoming connection, the use this mark to route traffic out to the same Interface. check load-balacing examples where ...
by solar77
Mon Jan 14, 2019 12:09 pm
Forum: Beginner Basics
Topic: cant access https website through VPN
Replies: 4
Views: 502

Re: cant access https website through VPN

you need NAT on the VPN interface too.
by solar77
Fri Jan 11, 2019 9:34 pm
Forum: Beginner Basics
Topic: How to recover password on CRS125-24G-15-IN
Replies: 2
Views: 404

Re: How to recover password on CRS125-24G-15-IN

PS: replacing the ADSL router should not break up the Internet connection.
you still have access to the old ADSL router yes? see what's the LAN configuration is and configure the same on the new router. It's possible that all you need is the correct IP range and gateway to be set.
by solar77
Fri Jan 11, 2019 9:32 pm
Forum: Beginner Basics
Topic: How to recover password on CRS125-24G-15-IN
Replies: 2
Views: 404

Re: How to recover password on CRS125-24G-15-IN

you are not going to like this: you cannot do this.
recovering password from a backup file, you will need a backup file first, which you don't.

you know it's going have to be reset to default and configure from scratch ... don't you? :mrgreen:
by solar77
Fri Jan 11, 2019 9:24 pm
Forum: Beginner Basics
Topic: Winbox remote connection
Replies: 5
Views: 1069

Re: Winbox remote connection

if you can see packet match the accept rule (not seen your rule but I assume it's input chain, from your lan IP to wan IP on port 8291), the traffic is reaching it's distination but either the return path is not there or the return is not accepted by the laptop because it is coming from a different ...
by solar77
Wed Jan 09, 2019 7:52 pm
Forum: Beginner Basics
Topic: PPPoE Client Connection with specific Host-Uniq
Replies: 1
Views: 340

Re: PPPoE Client Connection with specific Host-Uniq

not sure about Host-uniq, seen a feature request so probably not available at the moment.

but as for seeing more PPPoE logs, use this
/system logging
add topics=pppoe
by solar77
Wed Jan 09, 2019 7:47 pm
Forum: Beginner Basics
Topic: gateway confusion
Replies: 2
Views: 479

Re: gateway confusion

many some IP address information on the topology?
do you have OSPF configured?
by solar77
Wed Jan 09, 2019 7:42 pm
Forum: Beginner Basics
Topic: Why my network is Reachable ???
Replies: 12
Views: 935

Re: Why my network is Reachable ???

these command are to be run from the terminal. If you use Winbox to access the router, Click New Terminal .
by solar77
Tue Jan 08, 2019 4:36 pm
Forum: Beginner Basics
Topic: chain -> input action -> drop [SOLVED]
Replies: 6
Views: 1506

Re: chain -> input action -> drop

Answer to question 2, doesn't matter, the router will check every rule until it is matched with one of them. so the work load of the router is the same. Answer to question 3, my understanding is you don't have to open ports for a service if you access from LAN side. If you disable a service, this me...
by solar77
Tue Jan 08, 2019 4:11 pm
Forum: Beginner Basics
Topic: Queue
Replies: 2
Views: 342

Re: Queue

1. make the DHCP leases static. so you know the IP of xxx is not going to change. 2. Optional, use Reply only on LAN bridge and add APR on DHCP lease to stop client configure their own static IP. don't use this if there is already static IP on your network. 3. create simple queue per IP without limi...
by solar77
Sun Jan 06, 2019 8:08 pm
Forum: Beginner Basics
Topic: Help me to protect my server please
Replies: 10
Views: 753

Re: Help me to protect my server please

the short answer is yes. what you need is automatic fail-over between 2 ISPs, many posts here and on wiki would give you the configuration needed. so I won't repeat here. one slight problem, would be that when you are on 2nd ISP, our public IP would change. Mikrotik have built in DDNS (under, IP- > ...
by solar77
Sun Jan 06, 2019 8:00 pm
Forum: Beginner Basics
Topic: Cant connect to new routher MikroTik 4011iGS+5HacQ2HnD
Replies: 3
Views: 482

Re: Cant connect to new routher MikroTik 4011iGS+5HacQ2HnD

1. if you know the LAN IP of your router, set your laptop to the same IP range and connect.
2. or , use Winbox, connect to any LAN interface of the router, it should see and allow you to connect using routers MAC address, without the need of IP address.
by solar77
Fri Dec 14, 2018 1:25 pm
Forum: Beginner Basics
Topic: How can i make my Lan stable (low ping latency) when my internet bandwidth is fully utilized
Replies: 2
Views: 493

Re: How can i make my Lan stable (low ping latency) when my internet bandwidth is fully utilized

simple solution would be add a gigabit switch between the AP, then connect the switch to the router. now, since this is a Mikrotik forum, what hardware and firmware version are you on? have you monitored the router CPU when internet is fully utilised? if it's high then router is too busy and conside...
by solar77
Fri Dec 14, 2018 12:55 pm
Forum: Beginner Basics
Topic: Web filter for Childs
Replies: 7
Views: 1251

Re: Web filter for Childs

I use Amazon Fire tablet to do exactly this....and it's a lot cheaper. but if Santa has already paid for the iPad, use OpenDNS and set youtube APP in restricted mode. Mikrotik Kid control seems also useful, but with a brief look, it seems provide schedule and bandwidth limits,rather than web filteri...
by solar77
Fri Dec 14, 2018 12:41 pm
Forum: Beginner Basics
Topic: NAT 2 PPPoE connections
Replies: 2
Views: 832

Re: NAT 2 PPPoE connections

I don't think you need another LAN. for your server to use PPPoE 2 only, you need * NAT masquerade 192.168.88.5 to PPPoE 2 * correct routing for both PPPoE 1 connection and PPPoE 2. this normally involve Mangle traffic from 192.168.88.5 with a routing mark then pick it up by a static routing entry t...
by solar77
Thu Nov 15, 2018 5:25 pm
Forum: Beginner Basics
Topic: ethernet over lte/usb
Replies: 6
Views: 1241

Re: ethernet over lte/usb

I want to connect an LTE modem to an RB951 that can assign the cellular network assigned Public dynamic IP address to the LTE interface of the Mikrotik, in order to create an IPSec VPN to an RB1100. so you have a RB951, connected or want to connect to a LTE modem, where is your RB1100? somewhere el...
by solar77
Fri Oct 12, 2018 8:32 pm
Forum: Beginner Basics
Topic: Moving config from RB1200 to RB1100AHX4
Replies: 2
Views: 495

Re: Moving config from RB1200 to RB1100AHX4

you have got it right. plus, upgrade the RB1200 to latest firmware, before export your config. upgrade the RB1100 to the latest so both are on the same version. I always past the script to the new device by blocks so I can easily spot anything was not executed correctly. it takes longer but at least...
by solar77
Fri Oct 12, 2018 11:57 am
Forum: General
Topic: Can my ISP access my Mikrotik Router and make changes?
Replies: 7
Views: 1140

Re: Can my ISP access my Mikrotik Router and make changes?

check if you have ssh enabled and mutiple user with Full Access. ISP can block your access to facebook / youtube on their part of the network, without having to access your router. Plus, it does not make any sence for them to do this. Remeber ISP is a business, time is money, why spend the time and ...
by solar77
Thu Oct 11, 2018 12:56 pm
Forum: Beginner Basics
Topic: PPTP VPN Protection
Replies: 9
Views: 1523

Re: PPTP VPN Protection

I would disable PPTP and only enable it when I need it. May not suit you but provide some protection. Limit what IP can access it as well if you can.

I being to think I have to do the same for winbox, login to ssh to enable winbox, when I need it.
by solar77
Thu Oct 11, 2018 12:53 pm
Forum: Beginner Basics
Topic: Looking up cloud.mikrotik.com every second
Replies: 19
Views: 5423

Re: Looking up cloud.mikrotik.com every second

I've checked on multiple routers we manage, there is no record of cloud.mikrotik.com so it either does not use this URL or it's used less freuqently.

Would be interesting to see if you can catch this traffic on using a firewall rule and see where it is coming from.
by solar77
Wed Oct 10, 2018 6:52 pm
Forum: Beginner Basics
Topic: Dynamic Queue
Replies: 4
Views: 663

Re: Dynamic Queue

I think it is the radius server which has to send an disconnect packet the router, then disconnect the active session. I am having trouble to get this working so ended up using a script remove all PPP connections at night, so when they come back, new profile would be applied.
by solar77
Wed Oct 10, 2018 5:54 pm
Forum: Beginner Basics
Topic: Netflix not working (unblocker or proxy)
Replies: 6
Views: 4598

Re: Netflix not working (unblocker or proxy)

you have not mentioned but I assumed that you have changed password and closed winbox port or at least limit access to it.

are you on a public IP? if yes, contact Netflix and get them to remove you from their blacklist.
by solar77
Wed Oct 03, 2018 3:48 pm
Forum: Beginner Basics
Topic: hap lite works fine but not reachable from LAN
Replies: 9
Views: 1132

Re: hap lite works fine but not reachable from LAN

not sure if you tried using winbox which should discover the Mikrotik if your laptop is on the same network. Also if you already have a home router, the Mikrotik does not have to be a router, it just needs to be a Layer2 switch with all it's ports, and WLAN interface joined into one bridge. also no ...
by solar77
Mon Oct 01, 2018 8:42 pm
Forum: Beginner Basics
Topic: Two LAN port failover
Replies: 2
Views: 824

Re: Two LAN port failover

RSTP is enabled on each port by default so I don't think connecting port and port 5 to the same switch would create a loop. Not tried myself though. make sure the switch has RSTP as well just to be safe. otherwise some sort of script would be useful, if ping IPofSwitch timeout, disable port 2 and th...
by solar77
Mon Oct 01, 2018 12:11 pm
Forum: General
Topic: CCTV DVR Port Forwarding [SOLVED]
Replies: 9
Views: 5806

Re: CCTV DVR Port Forwarding [SOLVED]

Your ISP router needs to forward these two ports to the Mikrotik router.
I assume that your connection is : Internet -> ISP router (in router mode) -> Mikrotik router.

so untill these ports are forwared on the ISP router, you won't be able to access the DVR from the Internet.
by solar77
Fri Sep 28, 2018 4:53 pm
Forum: Beginner Basics
Topic: Route specific IP traffic from LAN Subnet to WAN specific IP
Replies: 4
Views: 3099

Re: Route specific IP traffic from LAN Subnet to WAN specific IP

use mangle rule to mark-routing, apply this to the source IP you specify.
then add a routing rule that route all traffic with this routing mark , towards specific gateway of your IP.
by solar77
Thu Sep 27, 2018 6:39 pm
Forum: Beginner Basics
Topic: Can't connect to Mikrotik from outside
Replies: 9
Views: 3595

Re: Can't connect to Mikrotik from outside

accept tcp port 8291 on input chain, set in-interface to be your WAN interface, normally ether1.
However you want to limit access to this port by set source IP from which you allow only. Also make sure you are on latest firmware.
by solar77
Thu Sep 27, 2018 12:04 pm
Forum: Beginner Basics
Topic: Backup configuration before reset
Replies: 2
Views: 436

Re: Backup configuration before reset

plug into it and do you see it in Neighbors section of the Winbox?

can you access it from the WLAN side?

if both are no, it's prorbably time for factory reset....
by solar77
Thu Sep 27, 2018 11:51 am
Forum: Beginner Basics
Topic: Newbie question about bridge mode and management of the device in that mode. [SOLVED]
Replies: 8
Views: 1245

Re: Newbie question about bridge mode and management of the device in that mode. [SOLVED]

OK I still think the easy way so to have NAT on your WAP-LTE. However RoMon should work for you. Enable Romon on both the Wap and hex, make sure the hex can discover the Wap by RoMon. and then connecto to the Hex by "connect to RoMon", then you should see the MAC address of Wap, then it would allow ...
by solar77
Wed Sep 26, 2018 8:31 pm
Forum: Beginner Basics
Topic: Newbie question about bridge mode and management of the device in that mode. [SOLVED]
Replies: 8
Views: 1245

Re: Newbie question about bridge mode and management of the device in that mode. [SOLVED]

That's the point. I want NATting and other cpu intensive stuff to be done on hex, its faster, dualcore CPU (also adblock filtering, WAP LTE is low on RAM). So .... enabling discovery mode solves nothing, I've tried it. if you need NAT, change the Mikrotik to router mode. the default config would be...
by solar77
Wed Sep 26, 2018 11:13 am
Forum: Beginner Basics
Topic: Help Microtik
Replies: 5
Views: 712

Re: Help Microtik

I see that is new in my firewall. it's worrying that you don't seems to know about this firewall entry. possible it been hacked? or you share management of this router with someone else? let's hope you last fireall entry is a drop all on input chain. you have not shown NAT and Mangle rules but soun...
by solar77
Tue Sep 25, 2018 8:09 pm
Forum: Beginner Basics
Topic: How to Monitor specific Ip
Replies: 5
Views: 884

Re: How to Monitor specific Ip

even if you had a fireall rule to keepp all the dst-address of this IP, it won't mean much as many services are using cloudront and cloudflare server IPs so you ended up geting those.

there are some examples using traffic monitor but I never managed to get it working.
by solar77
Tue Sep 25, 2018 2:50 pm
Forum: Beginner Basics
Topic: wAP LTE kit setup
Replies: 3
Views: 4131

Re: wAP LTE kit setup

check from Interface and see if the LTE interface is running (it should have an R next ot it) I have not used this particular device but some other LTE kit requires you to connec the antenna to the PCB board, before doing so the LTE modem is not running therefore it won't even see any signal. there ...
by solar77
Tue Sep 25, 2018 2:46 pm
Forum: Beginner Basics
Topic: Mikrotik Repeater No Internet
Replies: 5
Views: 1629

Re: Mikrotik Repeater No Internet

same reset button,
power off
hold reset button
apply power
wait for 10 seconds
release reset button

or you can reset from winbox, System -> Reset Configuration
by solar77
Mon Sep 24, 2018 6:40 pm
Forum: Beginner Basics
Topic: Setting internet bandwidth limitation on CRS125-24G-1S-RM
Replies: 4
Views: 621

Re: Setting internet bandwidth limitation on CRS125-24G-1S-RM

/queue simple
add max-limit=2M/5M name=Test target=192.168.88.0/24
here is an example, apply this to your router, you limit all your LAN client to have 5Mbps download and 2Mbps upload.

there is a lot more you can do with Queue, Wiki
by solar77
Wed Sep 12, 2018 8:38 pm
Forum: Beginner Basics
Topic: Basics of Marking Connections
Replies: 1
Views: 305

Re: Basics of Marking Connections

for each mangle rule , you can set passthrough=yes. which means the router will check the rest of the rules and apply mark if the conditions are met. i am not 100% but I think the second time you mark the connection, the mark will be over-written. So you may have to mark different chains, e.g. pre-r...
by solar77
Wed Sep 12, 2018 7:46 pm
Forum: General
Topic: radius + Mikrotik won't disconnect expired PPPoE users
Replies: 11
Views: 1899

Re: radius + Mikrotik won't disconnect expired PPPoE users

Thanks for your help. We don't have DMA support so on our own in this case. Probably will try to start in debug mode and see if it sent is in the first place.
by solar77
Tue Sep 11, 2018 6:23 pm
Forum: Beginner Basics
Topic: Is it possible?
Replies: 1
Views: 479

Re: Is it possible?

possible? Yes easy? No with exsiting hardware, probably not. if some of your subnet shares the same physical interface, e.g a LAN port on the router, you need VLAN. then your network switch, need to understand the VLAN set up (so it needs to a managed switch) your WiFi controller and Accesss Point, ...
by solar77
Tue Sep 11, 2018 4:57 pm
Forum: General
Topic: radius + Mikrotik won't disconnect expired PPPoE users
Replies: 11
Views: 1899

Re: radius + Mikrotik won't disconnect expired PPPoE users

just checked radiusmanager.cfg file, it has Globle POD port for Mik as 1700 changed Mikrotik radius incoming port to 1700. also firewall rule port, tested to disconnect a client from DMA Radius manager, client not disconnected, firewall rule shows nothing comes in...0 bytes. add action=accept chain=...
by solar77
Tue Sep 11, 2018 2:29 pm
Forum: General
Topic: radius + Mikrotik won't disconnect expired PPPoE users
Replies: 11
Views: 1899

Re: radius + Mikrotik won't disconnect expired PPPoE users

Sorry for the delay in reporting back. The incoming states is all 0, I've set up a firewall rule to catch anything that comings into 3899 from Radius IP, nothing.
where do I check if the radius is configured to send disconnect message back?
I have a feeling I am getting closer...
by solar77
Tue Sep 11, 2018 11:35 am
Forum: Beginner Basics
Topic: I want to close all websites except for specific sites
Replies: 3
Views: 455

Re: I want to close all websites except for specific sites

one way, maybe. configure your PC's DNS, so the website you try to allow is pointed to the Mikrotik,on which you set up a Proxy, then forward traffic to the internet configure Mikrotik you drop all request on port 80, port 443, port 8080 etc. this stops anyother web access. think of if, block VPN po...
by solar77
Tue Sep 11, 2018 11:16 am
Forum: Beginner Basics
Topic: Unable to connect
Replies: 9
Views: 805

Re: Unable to connect

your problem is not about opening ports but likely to be your NAT rule. try add your wan interface to be the in-interface in your NAT rule. Or dst-address to be your public ip / router's wan IP.
if not working, post your NAT rule here
by solar77
Sat Sep 08, 2018 2:19 pm
Forum: Beginner Basics
Topic: manual added route doesn't work - need help
Replies: 3
Views: 557

Re: manual added route doesn't work - need help

try use IP address instead of interface as gateway in your manual rule.
by solar77
Sat Sep 08, 2018 2:17 pm
Forum: Beginner Basics
Topic: Howto setup internet access via vpn for one internal-client
Replies: 7
Views: 616

Re: Howto setup internet access via vpn for one internal-client

I'd suggest try to set 8.8.8.8 or 1.1.1.1 as DHCP server for your 192.168.88.0/24 clients, instead of 192.168.88.1. see if makes any difference.
you do this in IP - DHCP server - Network, I think.
by solar77
Thu Sep 06, 2018 6:42 pm
Forum: Beginner Basics
Topic: Wireless bridge 2 networks
Replies: 3
Views: 527

Re: Wireless bridge 2 networks

the two SXT-AC should have one interface connect to each subnet (assigne one IP within the subnet) and connect to each other on a different subnet, I'd suggest to use a /30. then set up routing between the two SXT-AC so they know where to forward traffic for each subnet. or this can be done by OSPF....
by solar77
Thu Sep 06, 2018 6:26 pm
Forum: Beginner Basics
Topic: How to hide web interface of router from internet?
Replies: 11
Views: 1176

Re: How to hide web interface of router from internet?

winbox 3.1.7 have one issue with me: reconnect to a device, it won't open it in new window.
by solar77
Thu Sep 06, 2018 6:24 pm
Forum: Beginner Basics
Topic: Got hacked, think I need help with configuring routerOS
Replies: 17
Views: 3627

Re: Got hacked, think I need help with configuring routerOS

after all upgrading and password changing. this would be a good start
https://wiki.mikrotik.com/wiki/Manual:S ... our_Router
close ports, services that you don't need;
lock down ports services you do need by allowing known IP as source IP.
by solar77
Thu Sep 06, 2018 5:58 pm
Forum: Beginner Basics
Topic: Facing problem in Hotspot
Replies: 2
Views: 363

Re: Facing problem in Hotspot

if you disable hotspot, would everything work?

how is your hotspot authentication set up?
by solar77
Thu Sep 06, 2018 3:56 pm
Forum: Beginner Basics
Topic: Howto setup internet access via vpn for one internal-client
Replies: 7
Views: 616

Re: Howto setup internet access via vpn for one internal-client

If i do a tracert from 192.168.88.123 i.e. to 8.8.8.8 or google.de it is working and the gateway 192.168.5.1 is used - but it's not possible to open a website in browser.. did you add routing for 192.168.5.0/24 to go out from l2tp-out1 ? if your trace route is working then the routing should be fin...
by solar77
Tue Aug 28, 2018 7:16 pm
Forum: General
Topic: Neflix IP ban
Replies: 4
Views: 1378

Re: Neflix IP ban

your NAT rule looks fine. if you do trace route, do you get the correct IP?
if it is correct and it still get band, you can contact netflix. I've done so recently and they have un-band our public IP.
We are not running any proxy nor VPN and only port open was 8291
by solar77
Tue Aug 28, 2018 6:34 pm
Forum: General
Topic: radius + Mikrotik won't disconnect expired PPPoE users
Replies: 11
Views: 1899

Re: radius + Mikrotik won't disconnect expired PPPoE users

Sorry not making it clear. I've had this set up working for a while. So PPPoE authentication works fine, Queue limit on Mikrotik is based on the set up on Radius. All good. but the users which goes over their data limit, were able to carry on at normal speed, until the connection drops and PPPoE aut...
by solar77
Tue Aug 28, 2018 4:01 pm
Forum: General
Topic: radius + Mikrotik won't disconnect expired PPPoE users
Replies: 11
Views: 1899

Re: radius + Mikrotik won't disconnect expired PPPoE users

Thanks /radius incoming set accept=yes also I have add action=accept chain=forward comment="Accept Radius" src-address=Ip of Radius add action=accept chain=input comment="Accept Radius" src-address=Ip of Radius reason for forward chain is there are other Mikrotiks connected behind this router as wel...
by solar77
Tue Aug 28, 2018 2:24 pm
Forum: General
Topic: radius + Mikrotik won't disconnect expired PPPoE users
Replies: 11
Views: 1899

radius + Mikrotik won't disconnect expired PPPoE users

the set up is DMA radius + Mikrotik. Mikrotik runs PPPoE server with "Use Radius" enabled. all runs fine apart from when PPPoE user goes over their allowed monthly data limit, it does show as Expired on radius but Mikrotik does not change the bandwidht limit on Queue unless the connection drops and ...
by solar77
Tue Aug 28, 2018 10:24 am
Forum: Beginner Basics
Topic: multiple subnets on multiple ports - make them talk.
Replies: 3
Views: 499

Re: multiple subnets on multiple ports - make them talk.

as Steveocee suggested, by default the Mikrotik should allow communication between its subnets unless there is a firewall rule stops that. by the look of your routing table, the router knows exactly where to forward packet if you wish to go to a particular subnet. without seeing your firewall rules,...
by solar77
Mon Aug 27, 2018 8:58 pm
Forum: Beginner Basics
Topic: Mangle, Queue and 2 ISPs
Replies: 5
Views: 797

Re: Mangle, Queue and 2 ISPs

No because those two rules would be based on routing marks which you can assign to different traffic.
  • 1
  • 2