Community discussions

Search found 437 matches

  • 1
  • 2
by solar77
Wed Jun 12, 2019 7:07 pm
Forum: Beginner Basics
Topic: i need to help
Replies: 2
Views: 277

Re: i need to help

what is your internet speed? what is the distance between wired AP and repeaters ? do you have line of sight? what is the number of clients you expect to connect on each AP? what package you wish to provide to your customers? the equipment choice will be very diffierent , depending all these things....
by solar77
Fri May 17, 2019 3:11 pm
Forum: Beginner Basics
Topic: mikrotik as a manageable switch
Replies: 1
Views: 303

Re: mikrotik as a manageable switch

to be honest sir, you don't come across as knowing much about networking. My best advice is to hire a consultant to set up the network for you. I may be expensive at the start but the long term it is going to cheaper, less time consuming, and avoid possible problems for customers, in summary, good f...
by solar77
Sun May 12, 2019 10:19 pm
Forum: Beginner Basics
Topic: Simple Queues vs Queue Tree
Replies: 3
Views: 698

Re: Simple Queues vs Queue Tree

you should add rate limit in their PPPoE Profile, this will create dynamic simple queue as soon as the PPPoE session is established.
by solar77
Fri May 10, 2019 11:06 pm
Forum: Beginner Basics
Topic: Tunnel to cloud server while preserving local IP addresses
Replies: 1
Views: 223

Re: Tunnel to cloud server while preserving local IP addresses

Establish an VPN connection between the Mikrotik and the cloud server. which is the serve and which is the client is up to you.
by solar77
Wed May 01, 2019 12:22 pm
Forum: General
Topic: VLAN - hybrid port - untagged VLAN 1
Replies: 11
Views: 815

Re: VLAN - hybrid port - untagged VLAN 1

thanks ava, good reading. in particular there is a link within the text, to "Manual:Layer2 misconfiguration"
by solar77
Tue Apr 30, 2019 2:27 pm
Forum: General
Topic: VLAN - hybrid port - untagged VLAN 1
Replies: 11
Views: 815

Re: VLAN - hybrid port - untagged VLAN 1

that I think is to give the CPU (Router) access to your managed VLAN
I have not tried it yet but that's my understanding.
by solar77
Mon Apr 29, 2019 5:02 pm
Forum: General
Topic: VLAN - hybrid port - untagged VLAN 1
Replies: 11
Views: 815

Re: VLAN - hybrid port - untagged VLAN 1

hi, I have only started to look at VLAN recently . My understanding is that, the switch VLAN only comes into consideration if you wish to have hardware offload for VLAN (the traffic between VLAN ports would be near wire speed because the swhich chip feature support this). note on the wiki: For devic...
by solar77
Mon Apr 29, 2019 4:07 pm
Forum: Wireless Networking
Topic: hAP ac2 as bridge and CAP
Replies: 6
Views: 743

Re: hAP ac2 as bridge and CAP

you can use a virtual wlan interface to be the AP. then add this interface to your LAN bridge for example, now I add wlan5 as a AP while I am using wlan1 as station /interface wireless set [ find default-name=wlan1 ] band=2ghz-b/g/n disabled=no distance=indoors frequency=2462 frequency-mode=regulato...
by solar77
Mon Apr 29, 2019 3:32 pm
Forum: General
Topic: VLAN - hybrid port - untagged VLAN 1
Replies: 11
Views: 815

Re: VLAN - hybrid port - untagged VLAN 1

https://wiki.mikrotik.com/wiki/Manual:Basic_VLAN_switching#Other_devices_with_built-in_switch_chip is for VLAN on RB3011 but I think you can still use bridge VLAN as well. also check this https://wiki.mikrotik.com/wiki/Manual:Switch_Router#VLAN_switching so you will need to add VLAN to the bridge an...
by solar77
Sat Apr 20, 2019 8:16 pm
Forum: Beginner Basics
Topic: Need quick and east non-payment redirect for a single customer
Replies: 6
Views: 476

Re: Need quick and east non-payment redirect for a single customer

as suggested by flynno, easy way would be contact the customer and get paid, instead of spending time on a solution that you only need for few days. PS: you can make her IP static on the DHCP server so it is the same IP every time. you can argue that she could then change IP to another static IP but...
by solar77
Wed Apr 17, 2019 10:53 am
Forum: Beginner Basics
Topic: Rebooting mikrotik in certain time and turn on without resetting whole counters
Replies: 1
Views: 140

Re: Rebooting mikrotik in certain time and turn on without resetting whole counters

create a schedule and excut script , like this one (instead of reboot, you shutdown)
viewtopic.php?t=19985

don't think you can schedule it to switch on again.
however, you can schedule it to disable all it's ports and enable again.
by solar77
Wed Apr 17, 2019 10:47 am
Forum: Beginner Basics
Topic: Bridging WiFi client with DHCP and the rest
Replies: 2
Views: 225

Re: Bridging WiFi client with DHCP and the rest

what I'm trying to achieve is a router that connects over third party wifi APs and if none are available, it will fall back to LTE. you are looking for " dual WAN fail-over". Many many tutorial and posts avaiable but starts from wiki https://wiki.mikrotik.com/wiki/Advanced_Routing_Failover_without_...
by solar77
Tue Apr 16, 2019 7:01 pm
Forum: Beginner Basics
Topic: Best practices to copy config from one device to another
Replies: 3
Views: 343

Re: Best practices to copy config from one device to another

Hi, having done it few times, I'd suggest export is the way to go. backup is meant to be for the same router. best practice, 1. to make sure the destination router is on the same firmware level as the master router. 2. you would want to check the config over, remove any MAC address. unfortunately if...
by solar77
Sun Apr 14, 2019 10:41 pm
Forum: General
Topic: hotspot can't drop wifi client after session time finished
Replies: 4
Views: 380

Re: hotspot can't drop wifi client after session time finished

1. How to make redirection to local auth page automatically, without filling any address in the browser after the session time would stopped? 2. How to make full dissconection from wifi, after session time stops? 1. I don't think you can. redirection means re-directing something the user has filled...
by solar77
Sun Apr 07, 2019 2:27 pm
Forum: General
Topic: i need help with queue's
Replies: 5
Views: 357

Re: i need help with queue's

disable fastrack and test again. FastTracked packets bypass firewall, connection tracking, simple queues, queue tree with parent=global, ip traffic-flow(restriction removed in 6.33), IP accounting, IPSec, hotspot universal client, VRF assignment, so it is up to administrator to make sure FastTrack d...
by solar77
Sat Apr 06, 2019 4:57 pm
Forum: Beginner Basics
Topic: PPTP problems
Replies: 6
Views: 569

Re: PPTP problems

I would not think the CPU usage on any of the router would be too high? RB3011 should be able to handle 200Mbps VPN with ease. sorry I am not sure what the problem might be so the following is pure guess work: check for MTU isue so make sure, on both point 2 and point 3, MTU is correct and change MS...
by solar77
Sat Apr 06, 2019 3:19 pm
Forum: Beginner Basics
Topic: vlan by mac
Replies: 2
Views: 339

Re: vlan by mac

Dynamic VLAN Assignment with RADIUS and CAPsMAN Configuration Example
https://mum.mikrotik.com/presentations/ ... 137144.pdf

hope this helps.
by solar77
Sat Apr 06, 2019 12:18 pm
Forum: Beginner Basics
Topic: Help with hAP AC Lite basic config
Replies: 2
Views: 291

Re: Help with hAP AC Lite basic config

connect to the router from port 5,
remove port 2 to port 4 from local bridge (default name would be "bridge")
create a bridge. say "uplink", then add port 1 to port 4 to it
disable default DHCP client on port 1
done
by solar77
Sat Apr 06, 2019 12:09 pm
Forum: Beginner Basics
Topic: PPTP Issues
Replies: 13
Views: 870

Re: PPTP Issues

I may give that a go, for the time being, I just re integrated my asus router and put my modem in bridge mode. So im hoping my ASUS router will allow me to open up the protocol that I need for L2TP-IPSec!! if your ISP modem can be in bridge mode, then why not use the Mikrotik behind it, instead of ...
by solar77
Fri Apr 05, 2019 12:10 pm
Forum: General
Topic: i need help with queue's
Replies: 5
Views: 357

Re: i need help with queue's

queue rule seems fine to me.
do you have fast track enabled in firewall?
by solar77
Fri Apr 05, 2019 11:06 am
Forum: Beginner Basics
Topic: PPTP Issues
Replies: 13
Views: 870

Re: PPTP Issues

for l2tp + ipsec, you will need /ip firewall filter add chain=input protocol=udp port=1701,500,4500 add chain=input protocol=ipsec-esp your ISP router is probably not capable of allowing protocol so this won't work. I have not tried but it might work without ipsec. and SSTP requires certificate if y...
by solar77
Thu Apr 04, 2019 8:55 pm
Forum: Beginner Basics
Topic: PPTP Issues
Replies: 13
Views: 870

Re: PPTP Issues

for PPTP, you will need to forward TCP 1723 and protocol 47 (GRE) to the Mikrotik
where SSTP only requires port 443
by solar77
Thu Apr 04, 2019 8:05 pm
Forum: General
Topic: i need help with queue's
Replies: 5
Views: 357

Re: i need help with queue's

please can you show your queue rules with
queue export
by solar77
Thu Apr 04, 2019 1:59 pm
Forum: General
Topic: DHCP: one IP address - multiple MAC address ?
Replies: 5
Views: 411

Re: DHCP: one IP address - multiple MAC address ?

May I ask why you wish to assigne one IP address to a user? I am not aware of any way to do this with Mikrotik DHCP server but you might be able to do it with hotspot. where the same user authentication will always get the same IP from the hotspot pool. The laptop will get different IP on wirelss, e...
by solar77
Thu Apr 04, 2019 1:08 pm
Forum: Beginner Basics
Topic: Bridge 2 vlans
Replies: 7
Views: 513

Re: Bridge 2 vlans

can i do this with just one router?? possibaly yes, if you can physcally have the hex router at the same location Aruba switch. so that network 1 is plugged in one port and network 2 is plugged in another. this way the hex will handle the inter-vlan routing. or if you have a router uplink from the ...
by solar77
Wed Apr 03, 2019 9:18 pm
Forum: Beginner Basics
Topic: Block traffic between VLAN
Replies: 8
Views: 572

Re: Block traffic between VLAN

thanks Sob for further explaination . Much appreciated!
by solar77
Wed Apr 03, 2019 6:25 pm
Forum: Beginner Basics
Topic: Block traffic between VLAN
Replies: 8
Views: 572

Re: Block traffic between VLAN

@Sob, thanks for the correction.

if each subnet / vlan is masqueraded behind the IP of it's interface. would this rule block traffic between them?
by solar77
Wed Apr 03, 2019 12:30 pm
Forum: Beginner Basics
Topic: Block traffic between VLAN
Replies: 8
Views: 572

Re: Block traffic between VLAN

I think this will block traffic between any IP that is assigned to a local interface, except within the same bridge
/ip firewall filter
add chain=forward src-address-type=local dst-address-type=local action=drop
by solar77
Tue Apr 02, 2019 7:37 pm
Forum: Beginner Basics
Topic: Force local IP to use specific wan on load balancing
Replies: 15
Views: 837

Re: Force local IP to use specific wan on load balancing

keep a backup config each step of the way . so you can always reset the router to factory default and come back to your latest backup again. This made me been very brave in my early days with Mikrotik
by solar77
Tue Apr 02, 2019 6:58 pm
Forum: Beginner Basics
Topic: PPTP problems
Replies: 6
Views: 569

Re: PPTP problems

what is the actual throughput without VPN between point 2 and point 3? when i connect point3 to point2 that is connected to point1 do you mean a client from Point 3, connect to the VPN server at Point 1, but the link is via point 2? if yes, is Point 2 just a bridge? do you have fast forward enabled?
by solar77
Tue Apr 02, 2019 6:33 pm
Forum: Beginner Basics
Topic: Force local IP to use specific wan on load balancing
Replies: 15
Views: 837

Re: Force local IP to use specific wan on load balancing

Glad it worked. opening all these UDP port and the word P2P seems be a "risky game" :-) I'd suggest to put this device in it's own VLAN so whoever has access to it, cannot access anything else on your network. PS: use good measure to protect your router as well. close down services you don't need, u...
by solar77
Tue Apr 02, 2019 6:01 pm
Forum: Beginner Basics
Topic: Force local IP to use specific wan on load balancing
Replies: 15
Views: 837

Re: Force local IP to use specific wan on load balancing

it does seem to bypass policy based routing, I am not sure why but hopefully someone can tell me in this thread.

what port forwarding do you have to do? is it to the Nintendo ? this rule should only affect traffic originated from this particular IP address.
by solar77
Tue Apr 02, 2019 5:50 pm
Forum: Beginner Basics
Topic: Disable all services except api, how to start www or ssh or telnet?
Replies: 1
Views: 206

Re: Disable all services except api, how to start www or ssh or telnet?

you can see use Winbox to access the device by using it's MAC address.

you will need to to connect to the router directly by network cable, you should see it comes up in Neighbors tag.
by solar77
Tue Apr 02, 2019 5:04 pm
Forum: Beginner Basics
Topic: Force local IP to use specific wan on load balancing
Replies: 15
Views: 837

Re: Force local IP to use specific wan on load balancing

It would normally work but I am not 100% in your case because you already have PCC.

I'd suggest to try
 
 /ip firewall mangle
 add chain=prerouting src-address=IP_of _ Nintendo dst-address-type=!local action=route dst-address=gateway_WAN2
by solar77
Sat Mar 23, 2019 10:17 pm
Forum: General
Topic: How much Support RB3011
Replies: 12
Views: 955

Re: How much Support RB3011

use fast track on forward chain, established and connected traffic.

https://mikrotik.com/product/RB3011UiAS ... estresults
this is some indication for you.
by solar77
Fri Mar 22, 2019 6:51 pm
Forum: Beginner Basics
Topic: How to renew ip address when reconnecting pppoe
Replies: 5
Views: 457

Re: How to renew ip address when reconnecting pppoe

I am little confused here. when you say "some ips that are attacked ", I assume they are public IP address so you have a pool of public IP, they are not static to individual PPPoE client, and you want each PPPoE client to pick up a different public IP each time they connect? I'd think proper / more ...
by solar77
Fri Mar 22, 2019 6:43 pm
Forum: Beginner Basics
Topic: Port forward on port 8080
Replies: 14
Views: 680

Re: Port forward on port 8080

The alternative is post nothing.

Why's this such a dreadful option?
Ha .... :lol:

sorry, in the business of helping OP. if the dst-nat rule has no traffic passing through, you need to check why the traffic is not reaching. complete config would give us more idea
by solar77
Fri Mar 22, 2019 1:55 pm
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 35
Views: 9312

Re: DHCP Offering Lease Without Success

I have followed up another device on this network having similar issue. It is also a Nintendo device. Here is my thought: I have hotspot running so it can connect to wiFi (both devices has -60dBm signal level and low channel utilisation ) but they cannot authenticate on the hotspot portal. /ip hotsp...
by solar77
Fri Mar 22, 2019 11:56 am
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 35
Views: 9312

Re: DHCP Offering Lease Without Success

@ pe1chl thanks for reply. I am looking into it a bit more: more often than not, before an "offering lease without success" error, Mikrotik repeately deassign and assigne DHCP over and over this happens to a range of devices. I did consider an wireless connection issue but my question is: this netwo...
by solar77
Fri Mar 22, 2019 10:50 am
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 35
Views: 9312

Re: DHCP Offering Lease Without Success

having this issue as well. first thought it was caused by my Unifi APs but now it seems to be pointing towards Mikrotik. It is now affecting non Apple devices (so far 2 x windows 10 laptops, one of which is ASUS).
I am running CCR1009, ROS 6.43

any one has a fix yet?
by solar77
Fri Mar 15, 2019 4:29 pm
Forum: Beginner Basics
Topic: Firewall rules
Replies: 6
Views: 495

Re: Firewall rules

ok I see what you mean now. So the URL will just be an Internal IP if you connected to it from LAN.
somehow i think the OP is using IP address not URL though
I set up the camera live view application from the outside IP address
by solar77
Fri Mar 15, 2019 11:53 am
Forum: Beginner Basics
Topic: Hotspot Bypass
Replies: 9
Views: 577

Re: Hotspot Bypass

It's not the repeater does not have access to the internet, it's the app (the device where the app is running on) does not see the repeater.
by default hotspot client does not see other clients and LAN network.
by solar77
Thu Mar 14, 2019 7:08 pm
Forum: General
Topic: Topology for cotteges
Replies: 8
Views: 581

Re: Topology for cotteges

we have done similar projects, using both Ubiquiti products and mikrotik, and combination of both. Here is my contribution: 1. if you have the option, go with fibre. search posts here for reasons but when you do a new install and running cables anyway, use fibre. 2.lets focus on Mikrotik, you can us...
by solar77
Thu Mar 14, 2019 6:23 pm
Forum: Beginner Basics
Topic: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?
Replies: 23
Views: 1296

Re: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?

Isn't it supposed to work just by creating some firewall rules ? Not really, you need NAT rule and routing rule. Because load balancing by definition seems more than what I need now, I just need to separate them in a fixed way. Its the type of load balancing where part of your network uses one conn...
by solar77
Thu Mar 14, 2019 3:04 pm
Forum: Beginner Basics
Topic: Hotspot Bypass
Replies: 9
Views: 577

Re: Hotspot Bypass

not sure why you want to do this but you can.
add the MAC address of any device within your Local Area Network, in IP - Hotspot - IP Bindings
then set the Type to "bypassed"
by solar77
Thu Mar 14, 2019 1:37 pm
Forum: Beginner Basics
Topic: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?
Replies: 23
Views: 1296

Re: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?

the bridge is created by the router on default. it's normally the LAN ports all joined under this bridge. now you have 2 x PPPoE session, what you need is load-balancing. it's been discussed often on the forum. and there is a document you can read first to get the idea https://wiki.mikrotik.com/wiki...
by solar77
Wed Mar 13, 2019 1:44 pm
Forum: Beginner Basics
Topic: Trying to make service available from VPN
Replies: 6
Views: 357

Re: Trying to make service available from VPN

not sure why you cannot use 10.10.10.0/28 range as VPN Local address, I don't think it matters but happy to learn otherwise. in my view, you can use either 192.168.78.1 or 10.10.10.1 as local IP for VPN. use the matching pool . double check you have Add Default route and user peer DNS on the DHCP cl...
by solar77
Tue Mar 12, 2019 5:13 pm
Forum: General
Topic: What is the best method to connect between 2 routers? and How?
Replies: 8
Views: 469

Re: What is the best method to connect between 2 routers? and How?

Plug one ethernet cable into a port on one router and plug the other end of the ethernet cable on the other router.
Sorry I laughed. :lol: that is exactly what came to my mind on reading the subject, even before got to the actuall post itself....
by solar77
Tue Mar 12, 2019 5:09 pm
Forum: Beginner Basics
Topic: Trying to make service available from VPN
Replies: 6
Views: 357

Re: Trying to make service available from VPN

very interesting case so I will kick start. It might take me few attempt to get it working but I'd think it's possible. first try to set the VPN in the way that local address is that of the ether5, and VPN pool is in the same range as that of the Cisco box. when connected via VPN, the laptop should ...
by solar77
Tue Mar 12, 2019 4:56 pm
Forum: Beginner Basics
Topic: Hotspot wifi and Lan users
Replies: 13
Views: 885

Re: Hotspot wifi and Lan users

Vlan id = 2 has been created on Switch to differ AP's from LAN users. Mikrotik router CCR a hotpsot created with dhcp server and pool 10.5.50.0/24 on Ethernet 3 wifi users cannot access the hotspot dhcp pool and get ip address. I can see that the hotspot is on ether3 but it needs to be on VLAN2. th...
by solar77
Tue Mar 12, 2019 2:24 pm
Forum: Beginner Basics
Topic: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?
Replies: 23
Views: 1296

Re: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?

Glad it's moving forward. Note you DIY trick would void warranty on both the ISP modem and the Mikrotik. is getting another 2 x modem from the ISP possible? because you do have another 2 account and it should come with a modem. Even not, I'd suggest you try to connect to their firbre first and see w...
by solar77
Tue Mar 12, 2019 1:55 pm
Forum: Beginner Basics
Topic: Firewall rules
Replies: 6
Views: 495

Re: Firewall rules

@sebastia I don't think DNS catch is going to work . Steveocee is right and the OP needs hairping nat. client send packet to IP of camera, get changed to internal IP of camera, return traffic has source IP of Internal camera IP. client device drops it because it's does not much the dst-ip of origina...
by solar77
Mon Mar 11, 2019 10:50 pm
Forum: Beginner Basics
Topic: After configuration when connecting all ports no internet connection
Replies: 4
Views: 256

Re: After configuration when connecting all ports no internet connection

/ip firewall nat
add action=masquerade chain=srcnat
missing out-interface=

first test if the router itself can ping 8.8.8.8, then the router can resolve a dns name, before you move on to other things.
by solar77
Mon Mar 11, 2019 7:43 pm
Forum: Beginner Basics
Topic: Hotspot wifi and Lan users
Replies: 13
Views: 885

Re: Hotspot wifi and Lan users

if both the lan and wifi network are connected to the same layer 2 switch, you will not be able to stop the traffic going between. can you connect desktop PCs to the rouer so those ports can have the 192.168.22.0/24 only? and wifi on other ports or through swich? if you cannot physically bring all b...
by solar77
Mon Mar 11, 2019 4:49 pm
Forum: Beginner Basics
Topic: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?
Replies: 23
Views: 1296

Re: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?

very lucky man to have 3 x 1Gbps fibre. Contact your ISP and see if they allow you to remove the modem and just use the Mikrotik. and if yes, what SFP module they would recommend (muti-mode, or single mode). So the fibre feed can go straight into the Mikrotik. It's likely you can do this as you alre...
by solar77
Mon Mar 11, 2019 4:07 pm
Forum: Beginner Basics
Topic: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?
Replies: 23
Views: 1296

Re: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?

that's an interesting case. Yes I believe you can have 3 x PPPoE running on the Mikrotik and load-balancing them . you don't need VLAN. hardware selection depends on the uplink speed but most Mikrotik routers come with the same router OS, same feature, so even the basic model will do ospf, BGP, VLAN...
by solar77
Mon Mar 11, 2019 2:40 pm
Forum: Beginner Basics
Topic: Hotspot wifi and Lan users
Replies: 13
Views: 885

Re: Hotspot wifi and Lan users

Answer: the main router can be a hotspot server. there is no need for the 2nd Mikrotik to be there if that's the only job it does. create a separate subnet on the ports where th WiFi AP is connected to. use VLAN if you want but it's not a must. so you will have bridge_lan and bridge_wifi, for exampl...
by solar77
Mon Mar 11, 2019 1:28 pm
Forum: Beginner Basics
Topic: Hotspot wifi and Lan users
Replies: 13
Views: 885

Re: Hotspot wifi and Lan users

topology ?
by solar77
Sat Mar 09, 2019 11:51 am
Forum: General
Topic: VLAN across PPPoE clients
Replies: 7
Views: 368

Re: VLAN across PPPoE clients

@Redmor
thanks for advice. any chance you could post relevant config for doing the VLAN over EOIP?
also can you force MTU to be 1500? L2 is needed as the Monitor can only be discovered by the Panel, we cannot tell the monitor where the Panel is.
by solar77
Fri Mar 08, 2019 11:18 pm
Forum: General
Topic: VLAN across PPPoE clients
Replies: 7
Views: 368

Re: VLAN across PPPoE clients

I'd expect some direction from the helpful people here by now...or are we all in the pub?
by solar77
Fri Mar 08, 2019 8:35 pm
Forum: Beginner Basics
Topic: HELP: how to per ip shaping?
Replies: 10
Views: 595

Re: HELP: how to per ip shaping?

it might be that you have other rules kicking in once the speed is set to 50/50 my suggestion, as in previous post, is to change Rate in both pcq-download-default and pcq-upload-default then add simple queue, with nothing else, just use the PCQ as in add name=LAN_PCQ queue=pcq-upload-default/pcq-dow...
by solar77
Fri Mar 08, 2019 6:15 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 2807

Re: load-balancing don't work

@WeWiNet Thanks for tips. This is only a trial for me to see how it would work out. If I was using it, yes fail-over will have to be there. . I am still not clear where the DNS traffic from the router itself goes , I think this is what this rule is for but not tested and I am using 8.8.8.8 on local ...
by solar77
Fri Mar 08, 2019 6:06 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 2807

Re: load-balancing don't work

SOLAR, both the WIKI and Steve Discher show that rule as a prerouting chain BUT IN_INTERFACE=WAN ????? The MUM2019 presentation shows that as input chain BUT IN_INTERFACE=WAN. Can i surmize that you are using bridge because you are simply simulating wan input??? I like your logic. ALL rules with ma...
by solar77
Fri Mar 08, 2019 6:00 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 2807

Re: load-balancing don't work

@plisken my config can work at 2 wan as well, just remove anything to do with wan3 and change PCC to 2/0 and 2/1 the only reason I did not do a whole router export is I've used it to test vlan staff before and there are many unrelated code left. what I did was step by step: get each of wan connectio...
by solar77
Fri Mar 08, 2019 5:12 pm
Forum: Beginner Basics
Topic: Help with WAN bandwidth limiting
Replies: 12
Views: 574

Re: Help with WAN bandwidth limiting

it's rx/tx , I think, so upload or download depending on that interface / target you apply it to.
by solar77
Fri Mar 08, 2019 3:42 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 2807

Re: load-balancing don't work

Note 6, when winbox into the uplink router (Router 1 broadcasting 3 SSID), it used wan2, when I open 2nd winbox session, it still use the same wan2, so the bandwidth doubles, then I opened 3rd, 4th winbox, they all use the same wan2, with increasing bandwidth flowing. this shows the both address opt...
by solar77
Fri Mar 08, 2019 3:33 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 2807

Re: load-balancing don't work

Right, I've done it myself. Its working and here is what I did: my set up is not a real multiple WAN but 3 virtual wlan interface ( AP Bridge modem, broadcasting 3 SSID) from Mikrotik hAP, wihch has Internet access. Each SSID has it's own network: 10.10.1.0/24, 10.10.2.0/24, 10.10.3.0/24 Tested each...
by solar77
Thu Mar 07, 2019 8:57 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 2807

Re: load-balancing don't work

I had the input chain question this morning, ha ha ! what I did was create a rule on my own router, on prerouting chian, in-interface is WAN, which I thought won't have any traffic. but it did, as all traffic heading to my WAN ip, it get translated (NATed) into my LAN IP. which then get marked with ...
by solar77
Thu Mar 07, 2019 6:54 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 2807

Re: load-balancing don't work

nice presentation, well you making me doubt myself. however, it's not complete identical. check page 22, the route section, the presentation has 4 rules, the 1st two has identical distance, both been set o 1, and using routing mark. This is part of the load balancing route. then the next two rules, ...
by solar77
Thu Mar 07, 2019 4:56 pm
Forum: General
Topic: VLAN across PPPoE clients
Replies: 7
Views: 368

Re: VLAN across PPPoE clients

I will be doing some tests on option 1 which seems to be less of a hassle. will report back.
any comments are welcome in the meantime.
by solar77
Thu Mar 07, 2019 3:34 pm
Forum: General
Topic: load-balancing don't work
Replies: 49
Views: 2807

Re: load-balancing don't work

I have not used PCC but compare your config with https://wiki.mikrotik.com/wiki/Manual:PCC the example does not use passthrough=yes, without understand all your config, i suspect some of the traffic got marked twice because of this. then the result would be only WAN2_conn is left and that's why all ...
by solar77
Thu Mar 07, 2019 11:52 am
Forum: Beginner Basics
Topic: HELP: how to per ip shaping?
Replies: 10
Views: 595

Re: HELP: how to per ip shaping?

as suspected, it's TCP traffic on port 80 so you cannot limit bandwidth per protocol or port. don't set PCQ to 0, in winbox, go into queue , queue type, find pcq-download-default and pcq-upload-default, apply rate of your choice. then in simple queue, do this add name=LAN_PCQ queue=pcq-upload-defaul...
by solar77
Thu Mar 07, 2019 11:33 am
Forum: General
Topic: VLAN across PPPoE clients
Replies: 7
Views: 368

Re: VLAN across PPPoE clients

anyone?
by solar77
Wed Mar 06, 2019 10:24 pm
Forum: General
Topic: VLAN across PPPoE clients
Replies: 7
Views: 368

Re: VLAN across PPPoE clients

sorry R1 at the bottom should really be R3. my mistake.
by solar77
Wed Mar 06, 2019 10:02 pm
Forum: General
Topic: Backup WAN allow WInbox connection always
Replies: 1
Views: 123

Re: Backup WAN allow WInbox connection always

you can get this routing mark by adding a mangle rule on the Input chain to mark the connection, then on the output chain to add routing mark to this connection so traffic comes in from interface=wan2, dst-port=8291, protocal=tcp, gets marked by a connection mark, then the return traffic will still ...
by solar77
Wed Mar 06, 2019 5:09 pm
Forum: General
Topic: VLAN across PPPoE clients
Replies: 7
Views: 368

VLAN across PPPoE clients

trying to get L2 connectivity between PPPoE clients so that the intercom Panel can see the monitor (IPV6 only, cannot set an IPv4 address to it). attached a drawing to show what we have. basically R1 is our core network, running a PPPoE server. R2, R3, R4 is customer site, running PPPoE client, then...
by solar77
Wed Mar 06, 2019 3:55 pm
Forum: General
Topic: QoS and Limit bandwidth
Replies: 3
Views: 349

Re: QoS and Limit bandwidth

I'd think using IP is better as the whole queue solutionis simpler, all your target can be catolorised by IP address the email, the server (assuming behind a public IP or interanl IP even) these two would be set with higher priority and higher Limit-at value then you can have PCQ for your LAN subnet...
by solar77
Wed Mar 06, 2019 12:10 pm
Forum: General
Topic: How to get on mikrotik list of arp records at port.
Replies: 3
Views: 254

Re: How to get on mikrotik list of arp records at port.

if it is a slave port of a master, ARP table will probably show the MACs under the master port anyway. It's L2 connectivity
by solar77
Wed Mar 06, 2019 11:56 am
Forum: General
Topic: problem with DHCP
Replies: 2
Views: 163

Re: problem with DHCP

I'd suggest to put your RB750 in router mode.
so the DHCP client on ether1 will pick up address from the SXT and DHCP server on Local bridge (include ether2 to ether5) will issue address to your own clients, with the DHCP server on the 750, you can set static DHCP entry as you wish.
by solar77
Wed Mar 06, 2019 10:48 am
Forum: Beginner Basics
Topic: HELP: how to per ip shaping?
Replies: 10
Views: 595

Re: HELP: how to per ip shaping?

first of all /queue type set 5 pcq-rate=47M set 6 pcq-rate=50M by default these two are not PCQ so please double check, make sure you have configured pcq-download-default and pcq-upload-default by check from winbox, make sure the rate is set. secondly /queue simple add max-limit=47M/50M name=Interne...
by solar77
Wed Mar 06, 2019 10:42 am
Forum: Beginner Basics
Topic: mikrotik bridge mode
Replies: 6
Views: 459

Re: mikrotik bridge mode

can you do a export hide-sensitive on the Mikrotik and show us the result? suspect something else is causing the issue. alternatively, reset the router and untick "default configuration". this will wipe all the config out of the Mikrotik, then you only do two things: add two interface into the bridg...
by solar77
Tue Mar 05, 2019 7:10 pm
Forum: Beginner Basics
Topic: Help with WAN bandwidth limiting
Replies: 12
Views: 574

Re: Help with WAN bandwidth limiting

ha ha avav, that makes the two of us. :D I am more into traffic management and know less about routing. there is always something new to pick up when I visit this forum. Keeps working fun.
by solar77
Tue Mar 05, 2019 5:32 pm
Forum: Beginner Basics
Topic: Help with WAN bandwidth limiting
Replies: 12
Views: 574

Re: Help with WAN bandwidth limiting

@anav I don't think limiting sessions is a solution here. if you watch under firewall - > connections, and do a speed test, such as speedtest.net, you will find it likes to use TCP port 80 over multiple connections. Some streaming services will do the same, (where I thought they should use UDP ). so...
by solar77
Tue Mar 05, 2019 2:33 pm
Forum: Beginner Basics
Topic: Help with WAN bandwidth limiting
Replies: 12
Views: 574

Re: Help with WAN bandwidth limiting

Hi Anav, no the PO wants limit the WAN bandwidth as a whole so that the keep-alive packets (assuming from the isp) to the vdsl modem does not get dropped.
So limiting upload to 1.8Mbps would probably enough. So the queue is applied to the PPPoE interface.

that's my understanding anyway.
by solar77
Tue Mar 05, 2019 2:13 pm
Forum: Beginner Basics
Topic: Extending home network with additional mikrotik APs.
Replies: 6
Views: 715

Re: Extending home network with additional mikrotik APs.

The wSAP AC Lite is an alternative. It gives you 2 additional Ethernet ports (include 1 x passive POE out) and it fits into standard wall power sockets (US). but wifi coverage is probably not as good as the cAP AC.
by solar77
Tue Mar 05, 2019 1:42 pm
Forum: Beginner Basics
Topic: HELP: how to per ip shaping?
Replies: 10
Views: 595

Re: HELP: how to per ip shaping?

Please can you do
/queue export
just want to see how your PCQ is set up.
by solar77
Tue Mar 05, 2019 1:38 pm
Forum: Beginner Basics
Topic: Help with WAN bandwidth limiting
Replies: 12
Views: 574

Re: Help with WAN bandwidth limiting

you are over doing it. the tutorials are probably policy based bandwidth limiting where one type of traffic gets x amount of bandwidth. you don't need this. all you need is to create a simple queue , /queue simple add max-limit=1M/2M name="bandwidth limit" target=pppoe-interface this example limits ...
by solar77
Tue Mar 05, 2019 1:25 pm
Forum: Beginner Basics
Topic: 2 connections, 1 vpn. need vpn to bypass one of the connections, need urgent help.
Replies: 1
Views: 96

Re: 2 connections, 1 vpn. need vpn to bypass one of the connections, need urgent help.

1st of all, try use SSTP (port 443 )instead of PPTP. SSTP is harder to block. My 4G connections blocks PPTP but I can use SSTP. secondly, I'd suggest to create mangle rule to add routing mark on all traffic with destination address to your VPN server, then add manual routing entry, so traffic with t...
by solar77
Tue Mar 05, 2019 1:13 pm
Forum: Beginner Basics
Topic: Two Mikrortik with same WAN
Replies: 9
Views: 427

Re: Two Mikrortik with same WAN

Is the ISP modem a router or a bridge. Can it be a bridge?
by solar77
Tue Mar 05, 2019 1:07 pm
Forum: Beginner Basics
Topic: mikrotik bridge mode
Replies: 6
Views: 459

Re: mikrotik bridge mode

remove 192.168.1.1/24 on ether1, that IP is likely to be the modem itself.
and try again.
by solar77
Tue Mar 05, 2019 11:35 am
Forum: Beginner Basics
Topic: Noob default route question
Replies: 8
Views: 484

Re: Noob default route question

@vecernik87
thanks. I now know the cause for some of our problems. It's good to have an informative posts like yours and that's what keeps get me back to this forum.
by solar77
Sat Feb 02, 2019 7:36 pm
Forum: Beginner Basics
Topic: Hotspot + pppoe in 1 port
Replies: 7
Views: 537

Re: Hotspot + pppoe in 1 port

the answer is put them in VLANs.
by solar77
Fri Feb 01, 2019 5:48 pm
Forum: Beginner Basics
Topic: Failover Issue [SOLVED]
Replies: 14
Views: 1042

Re: Failover Issue [SOLVED]

hi anav 1st question, to the best of my knowledge, not really. and cannot think why it should be any differences. Masquerade is basically source nat but only change the src-ip to that of the out-interface. 2nd, I believe you can do /ip firewall connection tracking set enabled=no which is easy to add...
by solar77
Fri Feb 01, 2019 4:29 pm
Forum: Beginner Basics
Topic: Hotspot + pppoe in 1 port
Replies: 7
Views: 537

Re: Hotspot + pppoe in 1 port

that's easier to set up. In my view Hotspot is for users that come and go, like a hotel / shop scenario. PPPoE is more for fixed users who does not have to log in from every device under one account, and more suited in ISP type scenario.
by solar77
Fri Feb 01, 2019 4:20 pm
Forum: Beginner Basics
Topic: Failover Issue [SOLVED]
Replies: 14
Views: 1042

Re: Failover Issue [SOLVED]

or reset all connections as soon as you move to the 2nd connection, by disable / enable Connection Tracking.
by solar77
Fri Feb 01, 2019 4:16 pm
Forum: Beginner Basics
Topic: Failover Issue [SOLVED]
Replies: 14
Views: 1042

Re: Failover Issue [SOLVED]

Thanks for the reply. I went through the aforementioned article and other relevant articles. From my understanding after reading those, existing sessions (especially from ping or from the same website on the same browser) don't switch to the new ISP after the failover. I may be wrong. I think you a...
by solar77
Fri Feb 01, 2019 11:31 am
Forum: Beginner Basics
Topic: Hotspot + pppoe in 1 port
Replies: 7
Views: 537

Re: Hotspot + pppoe in 1 port

Interesting idea. Not tried but I'd imagine you will need VLAN so the PPPoE and Wireless network are separate. you can probably put them on the same interface without VLAN but that means running a DHCP server on this interface for hotspot users, while PPPoE users can also pick up an IP address from ...
by solar77
Fri Feb 01, 2019 11:20 am
Forum: Beginner Basics
Topic: Bandwidth Limited
Replies: 1
Views: 229

Re: Bandwidth Limited

difficult to guess without seeing the config. maybe do a export hide-sensitive and post here? few things on my mind: enable Fast forward on your bridge disable all firewall rule and queue, then test again. watch Tools - Profile while you test, see what is using your CPU. However I really don't think...
by solar77
Fri Feb 01, 2019 11:07 am
Forum: Beginner Basics
Topic: Failover Issue [SOLVED]
Replies: 14
Views: 1042

Re: Failover Issue [SOLVED]

your routing config: /ip route add distance=1 gateway=192.168.75.1 add distance=2 gateway=192.168.42.129 as long as the router can reach gateway IP (which does not mean there is internet connection beyond this gateway), the route will be available and distance=1 route (assuming that's your ADSL) is ...
by solar77
Mon Jan 28, 2019 11:19 am
Forum: Beginner Basics
Topic: output chain traffic routing
Replies: 0
Views: 262

output chain traffic routing

trying to keep the radius traffic from a router to use a fixed WAN interface without success. The network: OSPF enabled so the route to 0.0.0.0/0 is dynamically added by OSPF, there are two of them (10.10.0.241 and 249 being the gateways), so as a result I have ADo 0.0.0.0/0 10.10.0.241 110 10.10.0....
by solar77
Fri Jan 25, 2019 7:27 pm
Forum: Beginner Basics
Topic: I Need Help With VPN
Replies: 1
Views: 186

Re: I Need Help With VPN

do you have static routing in place at each router? sounds like you need: on Matriz /ip route add distance=1 dst-address=192.168.0.0/24 gateway=remote IP of your VPN connection, it would be 192.168.88.xx on the other router /ip route add distance=1 dst-address=192.168.88.0/24 gateway=remote IP of yo...
by solar77
Thu Jan 24, 2019 12:07 pm
Forum: Beginner Basics
Topic: ether1: Probably look (How to solve?)
Replies: 14
Views: 1495

Re: ether1: Probably look (How to solve?)

when we had similar issue on a wireless point to multi point link, it turned out to be someone copied the config between routers, thinking to chagne the IP of each router only. what he didn't realise is the MAC address of each interface were also in the config.....so all station routers ended up hav...
by solar77
Thu Jan 24, 2019 11:40 am
Forum: Beginner Basics
Topic: Firewall filter rules CCR-1009
Replies: 4
Views: 390

Re: Firewall filter rules CCR-1009

remember to keep your "allow established and related" filter rule on the top.
This ensure the return traffic from one VLAN to another is not dropped.
by solar77
Thu Jan 24, 2019 10:55 am
Forum: Beginner Basics
Topic: Firewall filter rules CCR-1009
Replies: 4
Views: 390

Re: Firewall filter rules CCR-1009

allow the connections first, and then block all other inter-vlan traffic. so you set up filter rule on forward chain, allow traffic from vlan 11 to server vlan 10 allow traffic from vlan 11 to address list (do this in ip firewall address lists) that contains 192.168.12.100-192.168.12.200 drop all tr...
by solar77
Thu Jan 24, 2019 10:35 am
Forum: Beginner Basics
Topic: one port only internet, no lan [SOLVED]
Replies: 20
Views: 1278

Re: one port only internet, no lan [SOLVED]

make sure this port is not part of the bridge with other LAN ports. otherwise traffic will not hit firewall unless you tells it to. set up separate IP Address, Network, DHCP server etc for this port. make sure traffic from this subnet is NATed. I would have a separate masquerade rule for each subnet...
by solar77
Wed Jan 23, 2019 7:15 pm
Forum: Beginner Basics
Topic: How to discover a remote device on the network ?
Replies: 6
Views: 463

Re: How to discover a remote device on the network ?

Do like your drawing. so here is my 12 pence : if you have to discover remote devices on router 2, make it a bridge, instead of a router. turn of DHCP on the TP Llink, connect a LAN port of router 2 to a LAN port of router 1. this is the only way to do it if you want to monitor inside of Router 2. s...
by solar77
Tue Jan 22, 2019 4:05 pm
Forum: Beginner Basics
Topic: Unify and mikrotik
Replies: 1
Views: 321

Re: Unify and mikrotik

I have the exact setup as you described. Unifi controller: set up 2 SSID, one with VLAN tag, on the Unifi Controller. I use Unifi switch as well so they will adjust to VLAN config on the controller but you just have to make sure the switch port which the Unifi AP plugs into is a trunk port. As the U...
by solar77
Tue Jan 22, 2019 10:28 am
Forum: Beginner Basics
Topic: Hotspot
Replies: 1
Views: 198

Re: Hotspot

http://bfy.tw/LuLg
have a look around and come back if you have specific question. I would recommend to use the Hotspot Setup within Mikrotik.

yes you can downgrade.
by solar77
Mon Jan 21, 2019 6:45 pm
Forum: Beginner Basics
Topic: L2TP/Ipsec ping issue
Replies: 1
Views: 203

Re: L2TP/Ipsec ping issue

did you set up static routing so the site-A router knows to route traffic to subnet of Site B to Gateway-B ?
by solar77
Mon Jan 21, 2019 6:42 pm
Forum: Beginner Basics
Topic: Information on models and configurations
Replies: 4
Views: 391

Re: Information on models and configurations

in addition to the above advice, - Is it possible to isolate the networks between them? If so how? yes, many ways, it's fun to search the forum before you ask someone to do it for you. - Are the product configuration options identical in all models? almost. unless you trying to use wireless or SFP o...
by solar77
Sat Jan 19, 2019 8:12 pm
Forum: General
Topic: How to copy a dynamic route?
Replies: 2
Views: 340

Re: How to copy a dynamic route?

in winbox, double check your dynamic route, then click copy. modify the copied rule as you wish, Click on OK.
by solar77
Fri Jan 18, 2019 7:07 pm
Forum: Beginner Basics
Topic: How to forward ports to multiple WAN interfaces?
Replies: 10
Views: 917

Re: How to forward ports to multiple WAN interfaces?

OK lets see. @anav if you have 3 NIC on the server, then you can route each IP to a chosen gateway but I cannot think of a way of doing it without mangle (which you are allergic to :-D because try add a static route, your dst-address is 0.0.0.0/0 and gateway is GatewayX, there is no way to add sourc...
by solar77
Fri Jan 18, 2019 4:41 pm
Forum: Beginner Basics
Topic: How to forward ports to multiple WAN interfaces?
Replies: 10
Views: 917

Re: How to forward ports to multiple WAN interfaces?

@mkx, yes it does make more sense now (even when I have not finished that tutorial video regarding Packet Flow). as you say, out-interface is a condition of such masquerade rule, not the outcome of it. Traffic is going out on that particular interface because routing engine tells it to. Now, out of ...
by solar77
Fri Jan 18, 2019 11:37 am
Forum: Beginner Basics
Topic: How to forward ports to multiple WAN interfaces?
Replies: 10
Views: 917

Re: How to forward ports to multiple WAN interfaces?

anav, I get what you are saying about making assumptions. yes that was an assumption in my part. it was made based on my "best guess", if not correct, then we can change the solution . second reason , is the mangle rules are needed whether it's a fail-over or load-balancing set up, in my humble opin...
by solar77
Thu Jan 17, 2019 3:19 pm
Forum: Beginner Basics
Topic: How to forward ports to multiple WAN interfaces?
Replies: 10
Views: 917

Re: How to forward ports to multiple WAN interfaces?

In addition to port forwarding (Dst NAT to your LAN IP, port), you will have to make sure the return traffic goes back to the WAN interface they come from. to do this , you mark the incoming connection, the use this mark to route traffic out to the same Interface. check load-balacing examples where ...
by solar77
Mon Jan 14, 2019 12:09 pm
Forum: Beginner Basics
Topic: cant access https website through VPN
Replies: 4
Views: 322

Re: cant access https website through VPN

you need NAT on the VPN interface too.
by solar77
Fri Jan 11, 2019 9:34 pm
Forum: Beginner Basics
Topic: How to recover password on CRS125-24G-15-IN
Replies: 2
Views: 209

Re: How to recover password on CRS125-24G-15-IN

PS: replacing the ADSL router should not break up the Internet connection.
you still have access to the old ADSL router yes? see what's the LAN configuration is and configure the same on the new router. It's possible that all you need is the correct IP range and gateway to be set.
by solar77
Fri Jan 11, 2019 9:32 pm
Forum: Beginner Basics
Topic: How to recover password on CRS125-24G-15-IN
Replies: 2
Views: 209

Re: How to recover password on CRS125-24G-15-IN

you are not going to like this: you cannot do this.
recovering password from a backup file, you will need a backup file first, which you don't.

you know it's going have to be reset to default and configure from scratch ... don't you? :mrgreen:
by solar77
Fri Jan 11, 2019 9:24 pm
Forum: Beginner Basics
Topic: Winbox remote connection
Replies: 5
Views: 791

Re: Winbox remote connection

if you can see packet match the accept rule (not seen your rule but I assume it's input chain, from your lan IP to wan IP on port 8291), the traffic is reaching it's distination but either the return path is not there or the return is not accepted by the laptop because it is coming from a different ...
by solar77
Wed Jan 09, 2019 7:52 pm
Forum: Beginner Basics
Topic: PPPoE Client Connection with specific Host-Uniq
Replies: 1
Views: 206

Re: PPPoE Client Connection with specific Host-Uniq

not sure about Host-uniq, seen a feature request so probably not available at the moment.

but as for seeing more PPPoE logs, use this
/system logging
add topics=pppoe
by solar77
Wed Jan 09, 2019 7:47 pm
Forum: Beginner Basics
Topic: gateway confusion
Replies: 2
Views: 325

Re: gateway confusion

many some IP address information on the topology?
do you have OSPF configured?
by solar77
Wed Jan 09, 2019 7:42 pm
Forum: Beginner Basics
Topic: Why my network is Reachable ???
Replies: 12
Views: 683

Re: Why my network is Reachable ???

these command are to be run from the terminal. If you use Winbox to access the router, Click New Terminal .
by solar77
Tue Jan 08, 2019 4:36 pm
Forum: Beginner Basics
Topic: chain -> input action -> drop [SOLVED]
Replies: 6
Views: 670

Re: chain -> input action -> drop

Answer to question 2, doesn't matter, the router will check every rule until it is matched with one of them. so the work load of the router is the same. Answer to question 3, my understanding is you don't have to open ports for a service if you access from LAN side. If you disable a service, this me...
by solar77
Tue Jan 08, 2019 4:11 pm
Forum: Beginner Basics
Topic: Queue
Replies: 2
Views: 234

Re: Queue

1. make the DHCP leases static. so you know the IP of xxx is not going to change. 2. Optional, use Reply only on LAN bridge and add APR on DHCP lease to stop client configure their own static IP. don't use this if there is already static IP on your network. 3. create simple queue per IP without limi...
by solar77
Sun Jan 06, 2019 8:08 pm
Forum: Beginner Basics
Topic: Help me to protect my server please
Replies: 10
Views: 573

Re: Help me to protect my server please

the short answer is yes. what you need is automatic fail-over between 2 ISPs, many posts here and on wiki would give you the configuration needed. so I won't repeat here. one slight problem, would be that when you are on 2nd ISP, our public IP would change. Mikrotik have built in DDNS (under, IP- > ...
by solar77
Sun Jan 06, 2019 8:00 pm
Forum: Beginner Basics
Topic: Cant connect to new routher MikroTik 4011iGS+5HacQ2HnD
Replies: 3
Views: 320

Re: Cant connect to new routher MikroTik 4011iGS+5HacQ2HnD

1. if you know the LAN IP of your router, set your laptop to the same IP range and connect.
2. or , use Winbox, connect to any LAN interface of the router, it should see and allow you to connect using routers MAC address, without the need of IP address.
by solar77
Fri Dec 14, 2018 1:25 pm
Forum: Beginner Basics
Topic: How can i make my Lan stable (low ping latency) when my internet bandwidth is fully utilized
Replies: 2
Views: 342

Re: How can i make my Lan stable (low ping latency) when my internet bandwidth is fully utilized

simple solution would be add a gigabit switch between the AP, then connect the switch to the router. now, since this is a Mikrotik forum, what hardware and firmware version are you on? have you monitored the router CPU when internet is fully utilised? if it's high then router is too busy and conside...
by solar77
Fri Dec 14, 2018 12:55 pm
Forum: Beginner Basics
Topic: Web filter for Childs
Replies: 7
Views: 817

Re: Web filter for Childs

I use Amazon Fire tablet to do exactly this....and it's a lot cheaper. but if Santa has already paid for the iPad, use OpenDNS and set youtube APP in restricted mode. Mikrotik Kid control seems also useful, but with a brief look, it seems provide schedule and bandwidth limits,rather than web filteri...
by solar77
Fri Dec 14, 2018 12:41 pm
Forum: Beginner Basics
Topic: NAT 2 PPPoE connections
Replies: 2
Views: 520

Re: NAT 2 PPPoE connections

I don't think you need another LAN. for your server to use PPPoE 2 only, you need * NAT masquerade 192.168.88.5 to PPPoE 2 * correct routing for both PPPoE 1 connection and PPPoE 2. this normally involve Mangle traffic from 192.168.88.5 with a routing mark then pick it up by a static routing entry t...
by solar77
Thu Nov 15, 2018 5:25 pm
Forum: Beginner Basics
Topic: ethernet over lte/usb
Replies: 6
Views: 724

Re: ethernet over lte/usb

I want to connect an LTE modem to an RB951 that can assign the cellular network assigned Public dynamic IP address to the LTE interface of the Mikrotik, in order to create an IPSec VPN to an RB1100. so you have a RB951, connected or want to connect to a LTE modem, where is your RB1100? somewhere el...
by solar77
Fri Oct 12, 2018 8:32 pm
Forum: Beginner Basics
Topic: Moving config from RB1200 to RB1100AHX4
Replies: 2
Views: 337

Re: Moving config from RB1200 to RB1100AHX4

you have got it right. plus, upgrade the RB1200 to latest firmware, before export your config. upgrade the RB1100 to the latest so both are on the same version. I always past the script to the new device by blocks so I can easily spot anything was not executed correctly. it takes longer but at least...
by solar77
Fri Oct 12, 2018 11:57 am
Forum: General
Topic: Can my ISP access my Mikrotik Router and make changes?
Replies: 7
Views: 737

Re: Can my ISP access my Mikrotik Router and make changes?

check if you have ssh enabled and mutiple user with Full Access. ISP can block your access to facebook / youtube on their part of the network, without having to access your router. Plus, it does not make any sence for them to do this. Remeber ISP is a business, time is money, why spend the time and ...
by solar77
Thu Oct 11, 2018 12:56 pm
Forum: Beginner Basics
Topic: PPTP VPN Protection
Replies: 9
Views: 916

Re: PPTP VPN Protection

I would disable PPTP and only enable it when I need it. May not suit you but provide some protection. Limit what IP can access it as well if you can.

I being to think I have to do the same for winbox, login to ssh to enable winbox, when I need it.
by solar77
Thu Oct 11, 2018 12:53 pm
Forum: Beginner Basics
Topic: Looking up cloud.mikrotik.com every second
Replies: 16
Views: 3205

Re: Looking up cloud.mikrotik.com every second

I've checked on multiple routers we manage, there is no record of cloud.mikrotik.com so it either does not use this URL or it's used less freuqently.

Would be interesting to see if you can catch this traffic on using a firewall rule and see where it is coming from.
by solar77
Wed Oct 10, 2018 6:52 pm
Forum: Beginner Basics
Topic: Dynamic Queue
Replies: 4
Views: 527

Re: Dynamic Queue

I think it is the radius server which has to send an disconnect packet the router, then disconnect the active session. I am having trouble to get this working so ended up using a script remove all PPP connections at night, so when they come back, new profile would be applied.
by solar77
Wed Oct 10, 2018 5:54 pm
Forum: Beginner Basics
Topic: Netflix not working (unblocker or proxy)
Replies: 5
Views: 2377

Re: Netflix not working (unblocker or proxy)

you have not mentioned but I assumed that you have changed password and closed winbox port or at least limit access to it.

are you on a public IP? if yes, contact Netflix and get them to remove you from their blacklist.
by solar77
Wed Oct 03, 2018 3:48 pm
Forum: Beginner Basics
Topic: hap lite works fine but not reachable from LAN
Replies: 9
Views: 709

Re: hap lite works fine but not reachable from LAN

not sure if you tried using winbox which should discover the Mikrotik if your laptop is on the same network. Also if you already have a home router, the Mikrotik does not have to be a router, it just needs to be a Layer2 switch with all it's ports, and WLAN interface joined into one bridge. also no ...
by solar77
Mon Oct 01, 2018 8:42 pm
Forum: Beginner Basics
Topic: Two LAN port failover
Replies: 2
Views: 535

Re: Two LAN port failover

RSTP is enabled on each port by default so I don't think connecting port and port 5 to the same switch would create a loop. Not tried myself though. make sure the switch has RSTP as well just to be safe. otherwise some sort of script would be useful, if ping IPofSwitch timeout, disable port 2 and th...
by solar77
Mon Oct 01, 2018 12:11 pm
Forum: General
Topic: CCTV DVR Port Forwarding [SOLVED]
Replies: 9
Views: 3292

Re: CCTV DVR Port Forwarding [SOLVED]

Your ISP router needs to forward these two ports to the Mikrotik router.
I assume that your connection is : Internet -> ISP router (in router mode) -> Mikrotik router.

so untill these ports are forwared on the ISP router, you won't be able to access the DVR from the Internet.
by solar77
Fri Sep 28, 2018 4:53 pm
Forum: Beginner Basics
Topic: Route specific IP traffic from LAN Subnet to WAN specific IP
Replies: 4
Views: 1555

Re: Route specific IP traffic from LAN Subnet to WAN specific IP

use mangle rule to mark-routing, apply this to the source IP you specify.
then add a routing rule that route all traffic with this routing mark , towards specific gateway of your IP.
by solar77
Thu Sep 27, 2018 6:39 pm
Forum: Beginner Basics
Topic: Can't connect to Mikrotik from outside
Replies: 9
Views: 1595

Re: Can't connect to Mikrotik from outside

accept tcp port 8291 on input chain, set in-interface to be your WAN interface, normally ether1.
However you want to limit access to this port by set source IP from which you allow only. Also make sure you are on latest firmware.
by solar77
Thu Sep 27, 2018 12:04 pm
Forum: Beginner Basics
Topic: Backup configuration before reset
Replies: 2
Views: 314

Re: Backup configuration before reset

plug into it and do you see it in Neighbors section of the Winbox?

can you access it from the WLAN side?

if both are no, it's prorbably time for factory reset....
by solar77
Thu Sep 27, 2018 11:51 am
Forum: Beginner Basics
Topic: Newbie question about bridge mode and management of the device in that mode. [SOLVED]
Replies: 8
Views: 844

Re: Newbie question about bridge mode and management of the device in that mode. [SOLVED]

OK I still think the easy way so to have NAT on your WAP-LTE. However RoMon should work for you. Enable Romon on both the Wap and hex, make sure the hex can discover the Wap by RoMon. and then connecto to the Hex by "connect to RoMon", then you should see the MAC address of Wap, then it would allow ...
by solar77
Wed Sep 26, 2018 8:31 pm
Forum: Beginner Basics
Topic: Newbie question about bridge mode and management of the device in that mode. [SOLVED]
Replies: 8
Views: 844

Re: Newbie question about bridge mode and management of the device in that mode. [SOLVED]

That's the point. I want NATting and other cpu intensive stuff to be done on hex, its faster, dualcore CPU (also adblock filtering, WAP LTE is low on RAM). So .... enabling discovery mode solves nothing, I've tried it. if you need NAT, change the Mikrotik to router mode. the default config would be...
by solar77
Wed Sep 26, 2018 11:13 am
Forum: Beginner Basics
Topic: Help Microtik
Replies: 5
Views: 547

Re: Help Microtik

I see that is new in my firewall. it's worrying that you don't seems to know about this firewall entry. possible it been hacked? or you share management of this router with someone else? let's hope you last fireall entry is a drop all on input chain. you have not shown NAT and Mangle rules but soun...
by solar77
Tue Sep 25, 2018 8:09 pm
Forum: Beginner Basics
Topic: How to Monitor specific Ip
Replies: 5
Views: 643

Re: How to Monitor specific Ip

even if you had a fireall rule to keepp all the dst-address of this IP, it won't mean much as many services are using cloudront and cloudflare server IPs so you ended up geting those.

there are some examples using traffic monitor but I never managed to get it working.
by solar77
Tue Sep 25, 2018 2:50 pm
Forum: Beginner Basics
Topic: wAP LTE kit setup
Replies: 3
Views: 2599

Re: wAP LTE kit setup

check from Interface and see if the LTE interface is running (it should have an R next ot it) I have not used this particular device but some other LTE kit requires you to connec the antenna to the PCB board, before doing so the LTE modem is not running therefore it won't even see any signal. there ...
by solar77
Tue Sep 25, 2018 2:46 pm
Forum: Beginner Basics
Topic: Mikrotik Repeater No Internet
Replies: 5
Views: 993

Re: Mikrotik Repeater No Internet

same reset button,
power off
hold reset button
apply power
wait for 10 seconds
release reset button

or you can reset from winbox, System -> Reset Configuration
by solar77
Mon Sep 24, 2018 6:40 pm
Forum: Beginner Basics
Topic: Setting internet bandwidth limitation on CRS125-24G-1S-RM
Replies: 4
Views: 411

Re: Setting internet bandwidth limitation on CRS125-24G-1S-RM

/queue simple
add max-limit=2M/5M name=Test target=192.168.88.0/24
here is an example, apply this to your router, you limit all your LAN client to have 5Mbps download and 2Mbps upload.

there is a lot more you can do with Queue, Wiki
by solar77
Wed Sep 12, 2018 8:38 pm
Forum: Beginner Basics
Topic: Basics of Marking Connections
Replies: 1
Views: 219

Re: Basics of Marking Connections

for each mangle rule , you can set passthrough=yes. which means the router will check the rest of the rules and apply mark if the conditions are met. i am not 100% but I think the second time you mark the connection, the mark will be over-written. So you may have to mark different chains, e.g. pre-r...
by solar77
Wed Sep 12, 2018 7:46 pm
Forum: General
Topic: radius + Mikrotik won't disconnect expired PPPoE users
Replies: 11
Views: 1264

Re: radius + Mikrotik won't disconnect expired PPPoE users

Thanks for your help. We don't have DMA support so on our own in this case. Probably will try to start in debug mode and see if it sent is in the first place.
by solar77
Tue Sep 11, 2018 6:23 pm
Forum: Beginner Basics
Topic: Is it possible?
Replies: 1
Views: 336

Re: Is it possible?

possible? Yes easy? No with exsiting hardware, probably not. if some of your subnet shares the same physical interface, e.g a LAN port on the router, you need VLAN. then your network switch, need to understand the VLAN set up (so it needs to a managed switch) your WiFi controller and Accesss Point, ...
by solar77
Tue Sep 11, 2018 4:57 pm
Forum: General
Topic: radius + Mikrotik won't disconnect expired PPPoE users
Replies: 11
Views: 1264

Re: radius + Mikrotik won't disconnect expired PPPoE users

just checked radiusmanager.cfg file, it has Globle POD port for Mik as 1700 changed Mikrotik radius incoming port to 1700. also firewall rule port, tested to disconnect a client from DMA Radius manager, client not disconnected, firewall rule shows nothing comes in...0 bytes. add action=accept chain=...
by solar77
Tue Sep 11, 2018 2:29 pm
Forum: General
Topic: radius + Mikrotik won't disconnect expired PPPoE users
Replies: 11
Views: 1264

Re: radius + Mikrotik won't disconnect expired PPPoE users

Sorry for the delay in reporting back. The incoming states is all 0, I've set up a firewall rule to catch anything that comings into 3899 from Radius IP, nothing.
where do I check if the radius is configured to send disconnect message back?
I have a feeling I am getting closer...
by solar77
Tue Sep 11, 2018 11:35 am
Forum: Beginner Basics
Topic: I want to close all websites except for specific sites
Replies: 3
Views: 325

Re: I want to close all websites except for specific sites

one way, maybe. configure your PC's DNS, so the website you try to allow is pointed to the Mikrotik,on which you set up a Proxy, then forward traffic to the internet configure Mikrotik you drop all request on port 80, port 443, port 8080 etc. this stops anyother web access. think of if, block VPN po...
by solar77
Tue Sep 11, 2018 11:16 am
Forum: Beginner Basics
Topic: Unable to connect
Replies: 9
Views: 610

Re: Unable to connect

your problem is not about opening ports but likely to be your NAT rule. try add your wan interface to be the in-interface in your NAT rule. Or dst-address to be your public ip / router's wan IP.
if not working, post your NAT rule here
by solar77
Sat Sep 08, 2018 2:19 pm
Forum: Beginner Basics
Topic: manual added route doesn't work - need help
Replies: 3
Views: 437

Re: manual added route doesn't work - need help

try use IP address instead of interface as gateway in your manual rule.
by solar77
Sat Sep 08, 2018 2:17 pm
Forum: Beginner Basics
Topic: Howto setup internet access via vpn for one internal-client
Replies: 7
Views: 448

Re: Howto setup internet access via vpn for one internal-client

I'd suggest try to set 8.8.8.8 or 1.1.1.1 as DHCP server for your 192.168.88.0/24 clients, instead of 192.168.88.1. see if makes any difference.
you do this in IP - DHCP server - Network, I think.
by solar77
Thu Sep 06, 2018 6:42 pm
Forum: Beginner Basics
Topic: Wireless bridge 2 networks
Replies: 3
Views: 374

Re: Wireless bridge 2 networks

the two SXT-AC should have one interface connect to each subnet (assigne one IP within the subnet) and connect to each other on a different subnet, I'd suggest to use a /30. then set up routing between the two SXT-AC so they know where to forward traffic for each subnet. or this can be done by OSPF....
by solar77
Thu Sep 06, 2018 6:26 pm
Forum: Beginner Basics
Topic: How to hide web interface of router from internet?
Replies: 11
Views: 795

Re: How to hide web interface of router from internet?

winbox 3.1.7 have one issue with me: reconnect to a device, it won't open it in new window.
by solar77
Thu Sep 06, 2018 6:24 pm
Forum: Beginner Basics
Topic: Got hacked, think I need help with configuring routerOS
Replies: 17
Views: 2744

Re: Got hacked, think I need help with configuring routerOS

after all upgrading and password changing. this would be a good start
https://wiki.mikrotik.com/wiki/Manual:S ... our_Router
close ports, services that you don't need;
lock down ports services you do need by allowing known IP as source IP.
by solar77
Thu Sep 06, 2018 5:58 pm
Forum: Beginner Basics
Topic: Facing problem in Hotspot
Replies: 2
Views: 248

Re: Facing problem in Hotspot

if you disable hotspot, would everything work?

how is your hotspot authentication set up?
by solar77
Thu Sep 06, 2018 3:56 pm
Forum: Beginner Basics
Topic: Howto setup internet access via vpn for one internal-client
Replies: 7
Views: 448

Re: Howto setup internet access via vpn for one internal-client

If i do a tracert from 192.168.88.123 i.e. to 8.8.8.8 or google.de it is working and the gateway 192.168.5.1 is used - but it's not possible to open a website in browser.. did you add routing for 192.168.5.0/24 to go out from l2tp-out1 ? if your trace route is working then the routing should be fin...
by solar77
Tue Aug 28, 2018 7:16 pm
Forum: General
Topic: Neflix IP ban
Replies: 4
Views: 923

Re: Neflix IP ban

your NAT rule looks fine. if you do trace route, do you get the correct IP?
if it is correct and it still get band, you can contact netflix. I've done so recently and they have un-band our public IP.
We are not running any proxy nor VPN and only port open was 8291
by solar77
Tue Aug 28, 2018 6:34 pm
Forum: General
Topic: radius + Mikrotik won't disconnect expired PPPoE users
Replies: 11
Views: 1264

Re: radius + Mikrotik won't disconnect expired PPPoE users

Sorry not making it clear. I've had this set up working for a while. So PPPoE authentication works fine, Queue limit on Mikrotik is based on the set up on Radius. All good. but the users which goes over their data limit, were able to carry on at normal speed, until the connection drops and PPPoE aut...
by solar77
Tue Aug 28, 2018 4:01 pm
Forum: General
Topic: radius + Mikrotik won't disconnect expired PPPoE users
Replies: 11
Views: 1264

Re: radius + Mikrotik won't disconnect expired PPPoE users

Thanks /radius incoming set accept=yes also I have add action=accept chain=forward comment="Accept Radius" src-address=Ip of Radius add action=accept chain=input comment="Accept Radius" src-address=Ip of Radius reason for forward chain is there are other Mikrotiks connected behind this router as wel...
by solar77
Tue Aug 28, 2018 2:24 pm
Forum: General
Topic: radius + Mikrotik won't disconnect expired PPPoE users
Replies: 11
Views: 1264

radius + Mikrotik won't disconnect expired PPPoE users

the set up is DMA radius + Mikrotik. Mikrotik runs PPPoE server with "Use Radius" enabled. all runs fine apart from when PPPoE user goes over their allowed monthly data limit, it does show as Expired on radius but Mikrotik does not change the bandwidht limit on Queue unless the connection drops and ...
by solar77
Tue Aug 28, 2018 10:24 am
Forum: Beginner Basics
Topic: multiple subnets on multiple ports - make them talk.
Replies: 3
Views: 364

Re: multiple subnets on multiple ports - make them talk.

as Steveocee suggested, by default the Mikrotik should allow communication between its subnets unless there is a firewall rule stops that. by the look of your routing table, the router knows exactly where to forward packet if you wish to go to a particular subnet. without seeing your firewall rules,...
by solar77
Mon Aug 27, 2018 8:58 pm
Forum: Beginner Basics
Topic: Mangle, Queue and 2 ISPs
Replies: 5
Views: 552

Re: Mangle, Queue and 2 ISPs

No because those two rules would be based on routing marks which you can assign to different traffic.
by solar77
Sat Aug 25, 2018 1:55 pm
Forum: Beginner Basics
Topic: Mangle, Queue and 2 ISPs
Replies: 5
Views: 552

Re: Mangle, Queue and 2 ISPs

I'd suggest to set distance to the same value for both ISPs, then mark routing for all traffic, so that you have "route_cameras" and "Others". then route both traffic to their own ISP based on routing mark.
by solar77
Tue Jun 26, 2018 12:11 pm
Forum: Beginner Basics
Topic: Winbox - is it possible?
Replies: 4
Views: 542

Re: Winbox - is it possible?

you can certainly run multiple instance of winbox but I've always done it from the same folder so they would load the same address list.
I guess if you have two folders for each then they should load whatever is local to them.
by solar77
Tue Jun 26, 2018 12:09 pm
Forum: Beginner Basics
Topic: Two ISP and dns monitoring
Replies: 6
Views: 615

Re: Two ISP and dns monitoring

first stop the spam, block any outgoing SMTP traffic that is not heading to your own email server and clean all your PCs

then using 8.8.8.8 or 1.1.1.1 as gatway to ping, instead of ISP gateway. see this
https://wiki.mikrotik.com/wiki/Advanced ... _Scripting
by solar77
Mon Jun 25, 2018 1:21 pm
Forum: Beginner Basics
Topic: Triple WAN VOIP Load Balancing
Replies: 8
Views: 812

Re: Triple WAN VOIP Load Balancing

before get to the Mikrotik configuration part, which I am sure will be taken care of, speak to your VOIP provider first. depending on the set up you have and where the PBX is located (local or cloud), it may not like, or even allow the 2nd public IP to register on the VOIP trunk side. Even registrat...
by solar77
Mon Jun 18, 2018 11:12 am
Forum: Beginner Basics
Topic: DHCP Server or Not
Replies: 3
Views: 445

Re: DHCP Server or Not

I'd set static IP to your core network and let the station radios at customer end pick up DHCP.
by solar77
Wed Jun 06, 2018 8:46 pm
Forum: Beginner Basics
Topic: n VLANs, allocated to x WAN
Replies: 9
Views: 758

Re: n VLANs, allocated to x WAN

there are always good way of doing things and better way of doing things. Most cases I am happy as long as it works :D
by solar77
Wed Jun 06, 2018 8:43 pm
Forum: Beginner Basics
Topic: Ping Stats
Replies: 2
Views: 308

Re: Ping Stats

not sure directly from terminal but you can use netwatch so script will run based on whether the ping exceed particular timeout
by solar77
Wed Jun 06, 2018 3:37 pm
Forum: Beginner Basics
Topic: n VLANs, allocated to x WAN
Replies: 9
Views: 758

Re: n VLANs, allocated to x WAN

I guess if you mark connection first then you don't have to inspect every packet on that connection to mark routing. More efficient
by solar77
Wed Jun 06, 2018 1:47 pm
Forum: Beginner Basics
Topic: n VLANs, allocated to x WAN
Replies: 9
Views: 758

Re: n VLANs, allocated to x WAN

in IP - Firewall - mangle, use In interface = VLANxx to mark connection , then mark Routing
use this routing mark in IP - Routing, to route traffic with such mark to ISP 2

Edited it need to be mark routing not mark packet, Sorry I was dealing with queues at the time.
by solar77
Sun Jun 03, 2018 12:27 pm
Forum: Beginner Basics
Topic: 3G fallover WHILE limiting usage...
Replies: 2
Views: 283

Re: 3G fallover WHILE limiting usage...

those "important" devices, can they be on static IP? if yes, then you put all of them into one address list,use this list when configure fail-over. Possibility uisng connection mark and then packet park etc. The static route for your fail-over connection only include those marked packet. So that no ...
by solar77
Sun Jun 03, 2018 11:57 am
Forum: Beginner Basics
Topic: Multiple WAN connections to one internal server
Replies: 1
Views: 308

Re: Multiple WAN connections to one internal server

should be possible: so you obviously need dst nat on each WAN interface into your internal server. Also mark incoming new connection from WAN1, then mark packet of this connection, then add static routing based on packet mark. This way, traffic comes in from WAN1 is marked, and it's related traffic ...
by solar77
Wed May 30, 2018 4:35 pm
Forum: Beginner Basics
Topic: HELP
Replies: 1
Views: 213

Re: HELP

port forwarding, or Dst NAT in Mikrotik terms:
https://wiki.mikrotik.com/wiki/Manual:I ... ernal_host
by solar77
Wed May 30, 2018 4:32 pm
Forum: Beginner Basics
Topic: VPN Access check box
Replies: 1
Views: 249

Re: VPN Access check box

if you can access the server, log in to the server, run winbox and access Mikrotik from the server, undo the change you made earlier.
by solar77
Wed May 30, 2018 1:48 pm
Forum: Beginner Basics
Topic: I can install the config from RB951G-2HnD go to RB3011UiAS-RM ?
Replies: 2
Views: 311

Re: I can install the config from RB951G-2HnD go to RB3011UiAS-RM ?

not directly and not with backup.
you will have to export config files, check each line and then import to the new device.
the two devices should ideally be on the same firmware version as well.
by solar77
Wed May 30, 2018 12:57 pm
Forum: Beginner Basics
Topic: Basic help needed - restriction [SOLVED]
Replies: 3
Views: 367

Re: Basic help needed - restriction [SOLVED]

from one subet to other (its NATted)
i'ts not clear exactly what your network set up is so here is my best guess

use forward chain (traffic passing through the router) instead of input chain (traffic heading into the router itself)
by solar77
Wed May 30, 2018 12:37 pm
Forum: Beginner Basics
Topic: Cannot connect to other LAN via VPN
Replies: 8
Views: 745

Re: Cannot connect to other LAN via VPN

traffic towards 192.168.6.20 should be routed to 172.16.16.106, not 172.16.16.1
change your static routing at home router
by solar77
Tue May 29, 2018 2:53 pm
Forum: Beginner Basics
Topic: Access modem/router behind MikroTik hex
Replies: 1
Views: 287

Re: Access modem/router behind MikroTik hex

put ether1 to the bridge interface Don't, unless you use Mikrotik as a L2 switch instead of a router use dst NAT rule to port forwarding to the Internal IP of whatever devcies you wish to access behind Mikrotik. use this an a reference http://www.icafemenu.com/how-to-port-forward-in-mikrotik-router...
by solar77
Tue May 29, 2018 2:49 pm
Forum: Beginner Basics
Topic: mikrotik rb911-5hnd client
Replies: 11
Views: 887

Re: mikrotik rb911-5hnd client

make sure your password is correct and also the authentication type (in wireless, security profile) matches that of your AP.
by solar77
Tue May 29, 2018 2:27 pm
Forum: Beginner Basics
Topic: IPSEC Site - To - Site
Replies: 2
Views: 373

Re: IPSEC Site - To - Site

in Winbox, Tools- Profile tells you what is using your CPU
by solar77
Sat May 26, 2018 10:00 pm
Forum: Beginner Basics
Topic: Internet access via PPTP
Replies: 1
Views: 244

Re: Internet access via PPTP

few things are needed for your to access Internet: 1. route, in your case, if you enabled Add Default Route, in PPTP client, this shoudl be added for you. 2. NAT: or masquerade, this trancelate your LAN address to your WAN IP address, in your case it is whatever IP address you get from you VPN conne...
by solar77
Fri May 25, 2018 11:45 am
Forum: Beginner Basics
Topic: VDSL config please
Replies: 6
Views: 1001

Re: VDSL config please

Quite right. 50/20 is not bad at all, says someone lives 3 miles from nearest local exchange and currently posting via ADSL2..
Sorry I have not been very helpful but hopefully SPF setting information can help someone else that uses the 5311
by solar77
Fri May 25, 2018 11:21 am
Forum: Beginner Basics
Topic: Connecting two Networks
Replies: 3
Views: 383

Re: Connecting two Networks

what service on PC2 you need access to? if it is only one or two services such as web server or FTP server, or Remote Desktop, you could just do port forwarding to PC002 on the Mikrotik
by solar77
Tue May 22, 2018 10:44 pm
Forum: Beginner Basics
Topic: Mikrotik cloud remote access
Replies: 24
Views: 5517

Re: Mikrotik cloud remote access

oh well, party bus sounds good. power hopefully is not an issue if it is a bus. event the USP mesh is only 8.5 W but normally it would run at 3.5-4 W. 24V POE or 802.3af . 8w is nothing when there is already cameras, laser lights, Hi-Fi systems etc. Sorry if I am not thinking about the right kind of...
by solar77
Tue May 22, 2018 9:55 pm
Forum: Beginner Basics
Topic: Mikrotik cloud remote access
Replies: 24
Views: 5517

Re: Mikrotik cloud remote access

provided VPN server is already been set up on your office network (if not, provide the type of router ,then remote access by teamviewer should be able to set this up) after that, all you need to provide are public IP of your office network,or DDNS vpn user /pass config on the car mikroitk won't take...
by solar77
Tue May 22, 2018 6:12 pm
Forum: Beginner Basics
Topic: Mikrotik cloud remote access
Replies: 24
Views: 5517

Re: Mikrotik cloud remote access

@CZfan

just checked and I am not sure...something I'd consider a standard feature but never actually used.
by solar77
Tue May 22, 2018 4:21 pm
Forum: Beginner Basics
Topic: Mikrotik cloud remote access
Replies: 24
Views: 5517

Re: Mikrotik cloud remote access

I am happy to take a look for you if you already have VPN details to the office network etc. (this would be public IP of your office network, vpn type, vpn username and password) obviously don't post it here. PM me with teamviewer details. consider this as a good deed. however I am restricted by how...
by solar77
Tue May 22, 2018 3:35 pm
Forum: Beginner Basics
Topic: DNS problem when hotspot activated
Replies: 6
Views: 591

Re: DNS problem when hotspot activated

please can you post
export hide-sensitive 
?
by solar77
Tue May 22, 2018 2:31 pm
Forum: Beginner Basics
Topic: Mikrotik cloud remote access
Replies: 24
Views: 5517

Re: Mikrotik cloud remote access

semi detailed steps: 1. set up VPN from car Mikroitk to your office. make sure it's connected. but add without "Add Default route option" . many simple tutorial online and wiki can help you. try this PPTP VPN https://mikrotik.com/testdocs/ros/3.0/vpn/pptp.php (asuming your office router accept this ...
by solar77
Tue May 22, 2018 1:23 pm
Forum: Beginner Basics
Topic: DNS problem when hotspot activated
Replies: 6
Views: 591

Re: DNS problem when hotspot activated

is your hotspot DHCP pool correct? if it is diffirent from you LAN DHCP pool, does the hotspot pool get correctly NAted?
by solar77
Tue May 22, 2018 11:37 am
Forum: Beginner Basics
Topic: Routing from WAN to LAN
Replies: 9
Views: 4545

Re: Routing from WAN to LAN

glad you have found the issue. In most cases it's something simple but it's the process of fault finding that matters.
by solar77
Mon May 21, 2018 4:54 pm
Forum: Beginner Basics
Topic: Mikrotik cloud remote access
Replies: 24
Views: 5517

Re: Mikrotik cloud remote access

in addition to the port issue: for most 4G connection, you are either behind a NAT or any incoming connection (originated from the WAN) is blocked. you can tell if you use uplookup and then check against what you get on the LTE interface, if they are different. you are behind NAT. you either need a ...
by solar77
Mon May 21, 2018 3:25 pm
Forum: Beginner Basics
Topic: Routing from WAN to LAN
Replies: 9
Views: 4545

Re: Routing from WAN to LAN

sorry missed that bit. that was before my morning coffee... can you see the packets coming from WAN on your Mikrotik ? use add chain=forward action=log src-address=10.1.200.0/24 to catch the traffic. also I assume you can ping any IP on 10.1.200.0/24 from the LAN side of Mikrotik? Not sure what NAT:...
by solar77
Mon May 21, 2018 3:09 pm
Forum: Beginner Basics
Topic: What do i need to learn to become proficient quickly?
Replies: 20
Views: 1772

Re: What do i need to learn to become proficient quickly?

Unlike anav, I prefer multiple backups. so you can always go back to each stage of your testing config. My personal experience with safe mode is not great. I know how it should work but never worked that way for me.... as a result I have about 25 backups on my current RB951 and getting very good at ...
by solar77
Mon May 21, 2018 11:07 am
Forum: Beginner Basics
Topic: DNS problem when hotspot activated
Replies: 6
Views: 591

Re: DNS problem when hotspot activated

check what DNS do your hotspot clients get?
by solar77
Mon May 21, 2018 11:01 am
Forum: Beginner Basics
Topic: Routing from WAN to LAN
Replies: 9
Views: 4545

Re: Routing from WAN to LAN

but WAN clients cant access anything from LAN except the LAN-address of the Microtic itself. this is perfectly normal as they don't know where to forward traffic with dst-address to 10.1.100.0/17 network and traffic heading to this network will be dropped. WAN clients will have a gateway, their gat...
by solar77
Mon May 21, 2018 10:36 am
Forum: Beginner Basics
Topic: What do i need to learn to become proficient quickly?
Replies: 20
Views: 1772

Re: What do i need to learn to become proficient quickly?

Whilst having a play trying to restrict my work laptop and phone from accessing the network, i've managed to block them. They can connect to the network, but when i attempt to search for other devices or access the internet, nothing works. Unfortunately, i can't remember what i've done. What might ...
by solar77
Mon May 21, 2018 10:29 am
Forum: Beginner Basics
Topic: What do i need to learn to become proficient quickly?
Replies: 20
Views: 1772

Re: What do i need to learn to become proficient quickly?

MTCNA would be a good starting point. Forum can help you to sort a specific problem and point you to wards the right direction. But learning from scratch by yourself would take sometime and your company would benefit from having the training at least to get you the basics.
by solar77
Fri May 18, 2018 5:29 pm
Forum: Beginner Basics
Topic: RB2011 port remain 100Mbps [SOLVED]
Replies: 8
Views: 805

Re: RB2011 port remain 100Mbps [SOLVED]

Took me3 try to understand your last sentence. Definitely need a weekend ! Maybe another coffee before finishing off....
by solar77
Fri May 18, 2018 5:09 pm
Forum: Beginner Basics
Topic: RB2011 port remain 100Mbps [SOLVED]
Replies: 8
Views: 805

Re: RB2011 port remain 100Mbps [SOLVED]

thanks mkx, yes on webFig, status section, the 1000 Mbps is greyed out. Same in winbox, even the Ethernet section had selected 1000Mbps to be Advertised, in the status section only advertise up to 100 Mbps as the ports are only 100Mbps ports What got me was I was not expecting half the port on a RB2...
by solar77
Fri May 18, 2018 3:42 pm
Forum: Beginner Basics
Topic: VDSL config please
Replies: 6
Views: 1001

Re: VDSL config please

OK that cleared up things for me.
VDSL in SFP module, nice! but as the other post say, Fibre is popular and we have only few sites still use VDSL
by solar77
Fri May 18, 2018 3:33 pm
Forum: Beginner Basics
Topic: RB2011 port remain 100Mbps [SOLVED]
Replies: 8
Views: 805

Re: RB2011 port remain 100Mbps [SOLVED]

Indeed there is that. it's been a long and problematic week so hopefully it's gets better next week. This Mikrotik is doing the routing between two physically separated networks and ether10 is the only connecting point, allowing me the access CCTV cameras etc. There are 16 channels hence the need fo...
by solar77
Fri May 18, 2018 3:27 pm
Forum: General
Topic: How to capture Hotspot user log
Replies: 2
Views: 517

Re: How to capture Hotspot user log

interesting :D Look forward to the rest of it.
by solar77
Fri May 18, 2018 12:59 pm
Forum: Beginner Basics
Topic: RB2011 port remain 100Mbps [SOLVED]
Replies: 8
Views: 805

Re: RB2011 port remain 100Mbps [SOLVED]

So it is!
cannot believe I missed that...

still, port 6 and 10 have option to advertise 1000Mbps which is just misleading. Just checked on my RB951, it can advertise 1000 Mbps as well. Obviously it can't do that.
by solar77
Fri May 18, 2018 12:38 pm
Forum: Beginner Basics
Topic: RB2011 port remain 100Mbps [SOLVED]
Replies: 8
Views: 805

RB2011 port remain 100Mbps [SOLVED]

I have a RB2011 UiAS which the ethernet ports should be Gigabit. When I connect Ether10 to a NETGEAR GS752TP switch, the connection rate can only be 100Mbps when in Auto-Negotiation. I've replaced the cable between the two units with the patch cable that is known to support Gigabit (tested using my ...
by solar77
Fri May 18, 2018 12:15 pm
Forum: Beginner Basics
Topic: remove simple dynamic queue
Replies: 1
Views: 374

Re: remove simple dynamic queue

the dynamic queue is created by hotspot profile which I assume you still need for limiting bandwdith for users.
if you have only one profile, you can use one PCQ rule so basically just balance between the users and limit them to a max value.
by solar77
Fri May 18, 2018 12:12 pm
Forum: Beginner Basics
Topic: VDSL config please
Replies: 6
Views: 1001

Re: VDSL config please

welcome to the forum! I am happy to help but not sure exactly what you require.
I assume you want to know the Mikrotik config when it's connected to the internet through VDSL modem? is the VDAL modem just a bridgte? do you have a static IP?
by solar77
Fri May 18, 2018 11:29 am
Forum: Beginner Basics
Topic: Problem connecting to a wireless network as a client. [SOLVED]
Replies: 4
Views: 449

Re: Problem connecting to a wireless network as a client. [SOLVED]

make sure frequency is correct (if you do a scan from Mikrotik and then select connect, it will pick up the correct frequency for you)
by solar77
Sat May 12, 2018 8:40 pm
Forum: Beginner Basics
Topic: Mikrotik Hotspot problem [SOLVED]
Replies: 11
Views: 2782

Re: Mikrotik Hotspot problem [SOLVED]

As soon as I create a new profile with the default address pool,
what is the address pool? is this address range masqueraded in IP - Firewall - NAT section?
by solar77
Fri May 11, 2018 3:48 pm
Forum: Beginner Basics
Topic: repeating / bridging hotels captive portal
Replies: 6
Views: 1275

Re: repeating / bridging hotels captive portal

even if hotel can add your MAC to the bypass list, yous still need the wireless client (connect to hotel wifi) and a AP (broadcast your own ssid) on the Mikroitk.
by solar77
Fri May 11, 2018 3:45 pm
Forum: Beginner Basics
Topic: repeating / bridging hotels captive portal
Replies: 6
Views: 1275

Re: repeating / bridging hotels captive portal

I'd expect this to work to be honest. Get your Mikrotik is setup as wireless station connecting to the hotel wifi, then your laptop connects the Mikrotik's LAN port, so at this point the wireless interface in Mikrotik is your WAN and the rest of the ports are LAN. try accessing the Internet from a b...
by solar77
Fri May 11, 2018 12:58 pm
Forum: Beginner Basics
Topic: Uh, can I think of the hAP ac as a wireless router?
Replies: 40
Views: 2917

Re: Uh, can I think of the hAP ac as a wireless router?

@szodiac

Have you broke it yet? keep backup files so that you can always come back to the last working state, something I've had to learn very quickly when started with Mikroitk.
by solar77
Fri May 11, 2018 12:55 pm
Forum: Beginner Basics
Topic: Uh, can I think of the hAP ac as a wireless router?
Replies: 40
Views: 2917

Re: Uh, can I think of the hAP ac as a wireless router?

Yes, it can be a wireless router.

Mikrotik will do everything the Netgear can and beyond.
even openvpn over udp? :)
well that would be ground breaking :-)
by solar77
Tue May 08, 2018 10:34 pm
Forum: Beginner Basics
Topic: Wirelessly extending network into another building
Replies: 9
Views: 833

Re: Wirelessly extending network into another building

nice illustration on exactly what you are asking
https://www.youtube.com/watch?v=SrW4OVa84O8
by solar77
Tue May 08, 2018 11:56 am
Forum: Beginner Basics
Topic: Need Router Suggestion
Replies: 4
Views: 442

Re: Need Router Suggestion

uplink speed? bridge speed required? (in case streaming camera across LAN) by "user" I assume that you mean a client device on the network or hotspot user? apart from just been a basic router, what other functions the Mikrotik needs to serve? special firewall rule, L7 filter rule, queue etc. etc. ha...
by solar77
Tue May 08, 2018 11:42 am
Forum: Beginner Basics
Topic: Uh, can I think of the hAP ac as a wireless router?
Replies: 40
Views: 2917

Re: Uh, can I think of the hAP ac as a wireless router?

Yes, it can be a wireless router.

Mikrotik will do everything the Netgear can and beyond.
by solar77
Mon May 07, 2018 12:37 pm
Forum: General
Topic: Float advertisement - How?
Replies: 7
Views: 2184

Re: Float advertisement - How?

well, Feklar's post makes sense. make a transpanrent Proxy at Mikroitk , redirection everything towards this, then at the proxy server, every http request is modified to include the banner in and the request URL as part of the Frame below. what was shown in the video though, the person has redirecte...
by solar77
Sat May 05, 2018 11:08 pm
Forum: General
Topic: LTE, no connection, missing route? [SOLVED]
Replies: 6
Views: 1230

Re: LTE, no connection, missing route? [SOLVED]

cannot have a dhcp-client on LTE interface? well, you can still set up static route for outboud traffic add dst-address=0.0.0.0/0 gateway=gateway of LTE connection (or just the LTE interface) Edit: just checked your config again, this route is already added, not sure why now.c Maybe change the gatew...
by solar77
Sat May 05, 2018 10:17 pm
Forum: General
Topic: LTE, no connection, missing route? [SOLVED]
Replies: 6
Views: 1230

Re: LTE, no connection, missing route? [SOLVED]

I have not used LTE routers but have a feeling this should be your problem
/ip dhcp-client
add comment=defconf dhcp-options=hostname,clientid disabled=no interface=ether1
change interface to your LTE interface and enable add default route.

give it a try
by solar77
Sat May 05, 2018 9:54 pm
Forum: Beginner Basics
Topic: hotspot double ip issue
Replies: 2
Views: 454

Re: hotspot double ip issue

it's not really an issue. the hotspot is doing what you tell it to do.
if you only want the DHCP adress, change the Address Pool to None, Hotspot -> Server and also User Profile
you will have one address.
by solar77
Sat May 05, 2018 6:29 pm
Forum: Beginner Basics
Topic: Configuring Mikrotik Router OS to access internet through my D-Link router [SOLVED]
Replies: 19
Views: 8348

Re: Configuring Mikrotik Router OS to access internet through my D-Link router [SOLVED]

you are welcome. It's nice to help a fellow learner as we all have to start somewhere.
by solar77
Sat May 05, 2018 5:51 pm
Forum: Beginner Basics
Topic: Configuring Mikrotik Router OS to access internet through my D-Link router [SOLVED]
Replies: 19
Views: 8348

Re: Configuring Mikrotik Router OS to access internet through my D-Link router [SOLVED]

it the D-link's WAN port is connected to the Mikroitk (known working) when the above screen is shown, then the D-Link is faulty. it's DHCP client is not picking up address from the Mikrotik when it should be able to.
by solar77
Sat May 05, 2018 4:44 pm
Forum: General
Topic: Block mikrotik cloud access from outside
Replies: 5
Views: 607

Re: Block mikrotik cloud access from outside

export your firewall config please
by solar77
Sat May 05, 2018 4:41 pm
Forum: General
Topic: Cannot Login to router by IP, but only by MAC
Replies: 15
Views: 7144

Re: Cannot Login to router by IP, but only by MAC

more info is needed but possibly
1. you don't have L2 connectivity to the router. this could be a mismatch of subnet mask for example.
2. access to router is blocked by it's firewall
by solar77
Sat May 05, 2018 4:28 pm
Forum: General
Topic: Float advertisement - How?
Replies: 7
Views: 2184

Re: Float advertisement - How?

1. it's bad practice
2. it cannot be done for HTTPS websites, which most sites are these days

Mikroitk has advertisement in Hotspot. https://wiki.mikrotik.com/wiki/Manual:H ... ertisement
by solar77
Sat May 05, 2018 4:11 pm
Forum: Beginner Basics
Topic: Grouping/Routing multiple WAN IP's into LAN IP's
Replies: 3
Views: 391

Re: Grouping/Routing multiple WAN IP's into LAN IP's

few ways of doing it. depends on how your LAN is set up. if you use PPPoE, simple, assign public IP to each user who needs public IP. keep the reset routed through one public IP. if not, I guess you have to either use mangle rule to mark routing per LAN IP, or group of LAN IP, create route per "rout...
by solar77
Sat May 05, 2018 3:55 pm
Forum: Beginner Basics
Topic: Configuring Mikrotik Router OS to access internet through my D-Link router [SOLVED]
Replies: 19
Views: 8348

Re: Configuring Mikrotik Router OS to access internet through my D-Link router [SOLVED]

factory default the D-Link. it should work as a standard router straight out of box. here is how it should physically connect together: plug the mikrotik's to D-Link's WAN port. when you pc connect to the LAN port of D-link, you should get an IP of 192.168.1.x or 192.168.0.x, don't connect the Mikro...
by solar77
Sat May 05, 2018 12:45 pm
Forum: Beginner Basics
Topic: prerouting mangle vs static route
Replies: 10
Views: 1699

Re: prerouting mangle vs static route

Hi Anav, the mangle rule is very specific for what I need. I need to send traffic towards one public IP address (unifi controller) via the office ADSL link while everything else, should go through the guest wifi ADSL. all WiFi client device is on a VLAN (172.16.0..0/22, no routing mark applied) and ...
by solar77
Fri May 04, 2018 10:35 pm
Forum: Beginner Basics
Topic: Forwarding broadcast traffic between two networks
Replies: 13
Views: 1748

Re: Forwarding broadcast traffic between two networks

@sob
would EOIP tunnel do the same thing here? passing boadcast traffic?
by solar77
Fri May 04, 2018 10:30 pm
Forum: Beginner Basics
Topic: prerouting mangle vs static route
Replies: 10
Views: 1699

Re: prerouting mangle vs static route

CZFans config in English: only mark new connections with a connection mark so less to do for the router, passthrough = no as the next rule needs to mark routing 2nd rule: every packet with that connection mark is cached by the 2nd rule, which marks routing with a new routing mark this is instead of ...
by solar77
Fri May 04, 2018 10:16 pm
Forum: Beginner Basics
Topic: Configuring Mikrotik Router OS to access internet through my D-Link router [SOLVED]
Replies: 19
Views: 8348

Re: Configuring Mikrotik Router OS to access internet through my D-Link router [SOLVED]

I tried to plug the Mikrotik SXT cable directly to my PC LAN port to check if I am able to connect to the internet or not. I found that the network is connected with internet access on ipv4 but no internet on ipv6, So I just tried to ping some website through cmd but nothing works. we already know ...
by solar77
Thu May 03, 2018 9:42 pm
Forum: Beginner Basics
Topic: Can't access web ui with VPN
Replies: 9
Views: 2543

Re: Can't access web ui with VPN

if you can ping the IP phone, the router is configured correctly. Silly question, you can access the yealink UI when connected to LAN correct? you can set up a firewall rule, with src-address to be your VPN remote address, dst-address=IP of Yeal link, action=passthrough, enable log, and watch the lo...
by solar77
Thu May 03, 2018 9:31 pm
Forum: Beginner Basics
Topic: Configuring Mikrotik Router OS to access internet through my D-Link router [SOLVED]
Replies: 19
Views: 8348

Re: Configuring Mikrotik Router OS to access internet through my D-Link router [SOLVED]

Another possibility is to set the SXT in bridge mode and then configure your D-Link as router with PPPOE on the D-Link?
His D-Link won't do PPPoE correctly. shown busy message
by solar77
Thu May 03, 2018 8:13 pm
Forum: Beginner Basics
Topic: Slow VLAN speed in one direction between two Mikrotik routers [SOLVED]
Replies: 4
Views: 988

Re: Slow VLAN speed in one direction between two Mikrotik routers [SOLVED]

good to know. VLAN settings are getting a bit consuming to me now.
by solar77
Thu May 03, 2018 7:49 pm
Forum: Beginner Basics
Topic: Configuring Mikrotik Router OS to access internet through my D-Link router [SOLVED]
Replies: 19
Views: 8348

Re: Configuring Mikrotik Router OS to access internet through my D-Link router [SOLVED]

OK now I get you. Your Mikrotik SXT looks fine. it's got internet access, and your PC, when it connect to the Ethernet port of the SXT, it should have Internet access. Now the D-Link. you can but you don't have to use it as a router. set it as a switch then you simply have 4 LAN ports and WiFi. all ...
  • 1
  • 2