Community discussions

MikroTik App

Search found 4205 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 15
by mkx
Fri May 29, 2020 9:34 am
Forum: Beginner Basics
Topic: SFP+ no link
Replies: 2
Views: 348

Re: SFP+ no link

Mikrotik equipment is quite picky about SFP/SFP+ modules ... odds are high that modules you tried are fairly different and draw of luck gave working pair of modules. In principle it should not be a problem to use "long distance" SFPs on shorter fibre routes. The distance mark on SFPs indicates the p...
by mkx
Mon May 25, 2020 6:26 pm
Forum: Wireless Networking
Topic: Setting Time in Capac from main router. [SOLVED]
Replies: 6
Views: 683

Re: Setting Time in Capac from main router. [SOLVED]

Why thank you. Brilliant you are!!
Hail Anav, the guru of ours!
by mkx
Mon May 25, 2020 4:19 pm
Forum: SwOS
Topic: CSS326-24G-2S+ VLAN and sharing
Replies: 2
Views: 327

Re: CSS326-24G-2S+ VLAN and sharing

Essentially you're running two LAN networks, company and home. And any device (printer, NAS, ...) can only be part of one network. So if you want connectivity from another network, there has to be a router between the networks. Simple switch can not do it and VLANs don't help here if devices (printe...
by mkx
Mon May 25, 2020 4:07 pm
Forum: General
Topic: I Can't Port Forward
Replies: 33
Views: 3532

Re: I Can't Port Forward

As @anav noticed ... if shown config is full config, then your router is vulnerable like hell. If that's so, take device off the net and netinstall it. Even if it's not, reset unit to factory default settings and configure it from defaults. Only change and/or add minimum what's needed and be sure it...
by mkx
Mon May 25, 2020 3:03 pm
Forum: General
Topic: I Can't Port Forward
Replies: 33
Views: 3532

Re: I Can't Port Forward

If your Mikrotik is configured properly and according to default configuration policy, you should select in-interface-list=WAN as criterion in NAT configuration. You can verify if the interface list selection is right for you if you check (existing) NAT rule for outgoing traffic ... default is chain...
by mkx
Mon May 25, 2020 9:14 am
Forum: SwOS
Topic: 2.5 / 5 Gig Supported in SwOS?
Replies: 2
Views: 328

Re: 2.5 / 5 Gig Supported in SwOS?

Link shows up at 10 gig and not 2.5 Gig Speed reported by /interface ethernet monitor for SFP/SFP+ ports is speed with which SFP module communicates with RB. Speed between SFP module and its link peer can be different and one has to get information about that via DDC link ... which can be (as you n...
by mkx
Mon May 25, 2020 9:07 am
Forum: Wireless Networking
Topic: Setting Time in Capac from main router. [SOLVED]
Replies: 6
Views: 683

Re: Setting Time in Capac from main router. [SOLVED]

(router has NTP client set and has correct date and time)

Router has to act as NTP server ... and for that extra package ntp has to be installed.
by mkx
Mon May 25, 2020 9:05 am
Forum: General
Topic: WAN on bridge with LAN
Replies: 8
Views: 1001

Re: WAN on bridge with LAN

Your idea is a completely valid. Only a remark about your setup code: consider adding settings frame-types=admit-only-vlan-tagged ingress-filtering=yes to /interface bridge port, these should add security.
by mkx
Mon May 25, 2020 8:53 am
Forum: Beginner Basics
Topic: How to setup VLANs?
Replies: 5
Views: 778

Re: How to setup VLANs?

That means that you can only create VLANs controlled by the CPU chip (software based instead of HW accelerated / offloaded. That means that you need to create a bridge interface per VLAN and only one bridge interface can give you wired speed. The first quoted sentence is true. The second one is not...
by mkx
Sat May 23, 2020 10:43 pm
Forum: Beginner Basics
Topic: How to downgrade RouterOS from v6.46.6 to v6.45.1 ? [SOLVED]
Replies: 12
Views: 1468

Re: How to downgrade RouterOS from v6.46.6 to v6.45.1 ? [SOLVED]

@mkx, you seem not to understand the problem.
As I wrote ... waste of my time.
by mkx
Sat May 23, 2020 9:53 pm
Forum: Beginner Basics
Topic: How to downgrade RouterOS from v6.46.6 to v6.45.1 ? [SOLVED]
Replies: 12
Views: 1468

Re: How to downgrade RouterOS from v6.46.6 to v6.45.1 ? [SOLVED]

As I explained in the other thread (which you partially ignored and I'll return to ignoring you after this post as it seems waste of my time writing you very concrete advices which you then largely ignore): you can download "Extra packages" ZIP file which is easy to verify after download. Then extra...
by mkx
Sat May 23, 2020 4:05 pm
Forum: Beginner Basics
Topic: The extra packages in RouterOS [SOLVED]
Replies: 21
Views: 2048

Re: The extra packages in RouterOS [SOLVED]

In current ROS there's bundle of packages which is what you get by downloading "Main package". You can not uninstall individual packages if installed with bundle, you can only disable them. But you can "unbundle" ROS by installing different version of ROS, but taking necessary packages from ZIP down...
by mkx
Sat May 23, 2020 1:11 pm
Forum: Beginner Basics
Topic: The extra packages in RouterOS [SOLVED]
Replies: 21
Views: 2048

Re: The extra packages in RouterOS [SOLVED]

When you put package files into proper place in device and reboot device, it will instal packages ... if extra packages versions match system package ... or if new system package version is newer than currently installed. If you want to install older version, you have to run /system package downgrad...
by mkx
Thu May 21, 2020 12:02 am
Forum: Beginner Basics
Topic: Changing Manufacturer and Model Name [SOLVED]
Replies: 8
Views: 1074

Re: Changing Manufacturer and Model Name [SOLVED]

Im going to send you a t-shirt

Me too ... pretty please?
by mkx
Wed May 20, 2020 11:52 pm
Forum: Beginner Basics
Topic: Changing Manufacturer and Model Name [SOLVED]
Replies: 8
Views: 1074

Re: Changing Manufacturer and Model Name [SOLVED]

Quite likely your ISP is not querying your device at all, but rather they use IMEI number of modem which gets communicated between modem and network as part of handshake to establish mutual trust. IMEI, similarly to MAC, carries information about device manufacturer and device model. And no, it seem...
by mkx
Wed May 20, 2020 9:21 pm
Forum: RouterOS v7 BETA
Topic: Is it possible to install 7.0 beta on an x86 server
Replies: 16
Views: 2836

Re: Is it possible to install 7.0 beta on an x86 server

More likely something doesn't get loaded correctly. Mind that BIOS/UEFI can't load linux kernel directly, there has to be intermediate loader (such as grub). If something fails (either BIOS loading intermediate or intermediate loading kernel), random things happen (most often machine reset). Which m...
by mkx
Wed May 20, 2020 7:29 pm
Forum: Beginner Basics
Topic: Bridging vs Switching on CRS3xx series? [SOLVED]
Replies: 10
Views: 1315

Re: Bridging vs Switching on CRS3xx series? [SOLVED]

The problem here is Mikrotik's parlance. We have "bridge" as "ports connected through a switch" and "bridging", as "moving one ethernet datagram from one interface to another, through the CPU". Actually Mikrotik wants you to forget about switches inside their devices ... they do bridges and some po...
by mkx
Wed May 20, 2020 7:27 pm
Forum: Beginner Basics
Topic: Bridging vs Switching on CRS3xx series? [SOLVED]
Replies: 10
Views: 1315

Re: Bridging vs Switching on CRS3xx series? [SOLVED]

But then Mikrotik bridges are not simple switches. Switching implies all ports are based on same L1 technology (i.e. wired ethernet) while mikrotik bridges can span different technologies (e.g. wireless interfaces, lte interfaces, vlan pseudo-interfaces, ...). Besides, wikipedia article about bridgi...
by mkx
Wed May 20, 2020 12:01 am
Forum: RouterBOARD hardware
Topic: CCR2004-1G-12S+2XS with more RAM ?
Replies: 14
Views: 2811

Re: CCR2004-1G-12S+2XS with more RAM ?

i don't get it somehow - the box is supposed to have 4gig ram, but reports only less than 1,8g to the ros6:
Memory size detected at slightly less than 2GB is typical for 32-bit linux kernel (non-PAE). I guess ROSv7 on these devices will be 64-bit.
by mkx
Mon May 18, 2020 12:03 am
Forum: Beginner Basics
Topic: Help needed on VLAN for hAP ac2
Replies: 9
Views: 1158

Re: Help needed on VLAN for hAP ac2

Also I understand mkx wanted to be paid ... Just to be clear: you misunderstood me completely by hanging on the inutial 15% if my reply and ignoring the rest where I clearly wrote I was ready to help you to get over some hurdles ... In post preceeding I actually gave you some advice about how to pr...
by mkx
Sun May 17, 2020 5:52 pm
Forum: Beginner Basics
Topic: Help needed on VLAN for hAP ac2
Replies: 9
Views: 1158

Re: Help needed on VLAN for hAP ac2

Please, can anyone here really help? If I was to write you configuration script, I'd have to charge you with consultancy fee ... I can help you learn by giving you advices (and by pointing out mistakes you might make, but for that you'd have to post configuration you came up so far) for free. It's ...
by mkx
Sun May 17, 2020 5:50 pm
Forum: Beginner Basics
Topic: Help needed on VLAN for hAP ac2
Replies: 9
Views: 1158

Re: Help needed on VLAN for hAP ac2

I suggest you to go with the "Router-Switch-AP (all in one)" example from the tutorial, just leave out wireless config other than config for wlan1. Problems you're having with the tutorial example are because your unit has two physical wireless interfaces (2.4GHz wlan1 and 5GHz wlan2). Which means t...
by mkx
Sun May 17, 2020 5:35 pm
Forum: Beginner Basics
Topic: Random connection dropping vol2
Replies: 38
Views: 5333

Re: Random connection dropping vol2

no difference .... if you manually set MAC address on bridge first. And even then you might experience (transitional) loss of connectivity because management MAC may change this way or another. If you connect to RB via IP (and IP address setup survives changes in L2 configuration of your RB), you m...
by mkx
Sun May 17, 2020 2:57 pm
Forum: Beginner Basics
Topic: Correct way to add VLANs to Bridge
Replies: 1
Views: 284

Re: Correct way to add VLANs to Bridge

The picture shows vlan interface as part of bridge ... but actually they should (an are) not be added, they are added automatically.

If you haven't already, read through this fine tutorial.
by mkx
Sun May 17, 2020 2:54 pm
Forum: Beginner Basics
Topic: Help needed on VLAN for hAP ac2
Replies: 9
Views: 1158

Re: Help needed on VLAN for hAP ac2

Read through this fine tutorial.
by mkx
Sun May 17, 2020 1:04 am
Forum: General
Topic: Unreachable route that should be reachable [SOLVED]
Replies: 2
Views: 517

Re: Unreachable route that should be reachable [SOLVED]

If you use addresses in usual notation, then the smallest usable network on mikrotik is /30: one network address, one broadcast address and two host addresses. To mimick a point-to-point connection over ethernet, you should set it like this: add address=80.67.167.169/32 network=80.67.167.168 interfa...
by mkx
Sat May 16, 2020 7:00 pm
Forum: General
Topic: Need help with understanding the Vlan Configuration on Switch
Replies: 4
Views: 1019

Re: Need help with understanding the Vlan Configuration on Switch

There are a few "dialects" of /interface ethernet switch config, it depends on switch chip type. There are a few documents describing the way to configure it in any of "dialects". If you have trouble configuring things on a particular device model, show us non-working config and we might share a tho...
by mkx
Sat May 16, 2020 4:48 pm
Forum: Beginner Basics
Topic: 'Lost' default MAC address
Replies: 47
Views: 4973

Re: 'Lost' default MAC address

Does 'Media disconnected' in this case mean the PIX-LINK device or something more? Media disconected means either that the cable is not connected on either end, or cable is broken, or ethernet on either end is not working properly. If you can verify that cable is fine and PC's ethernet is fine, and...
by mkx
Sat May 16, 2020 11:53 am
Forum: Beginner Basics
Topic: RB960PGS-PB output power conversion
Replies: 3
Views: 430

Re: RB960PGS-PB output power conversion

From the product description page : It also supports passive PoE input and passive or 802.3af/at PoE output. Ethernet ports 2-5 can power other PoE capable devices with the same voltage as applied to the unit . Less power adapters and cables to worry about! It can power 802.3at and af mode B compati...
by mkx
Fri May 15, 2020 10:01 pm
Forum: General
Topic: Router stopped working suddenly: powering off and on does not help
Replies: 9
Views: 1178

Re: Router stopped working suddenly: powering off and on does not help

I have taken another backup of the router from system backup and that is all that I can do at this stage.
Make text export of config ... binary backup is only usable (with ceveat) on same model of routers.
by mkx
Fri May 15, 2020 12:07 am
Forum: Beginner Basics
Topic: NIC PCIe bottleneck
Replies: 5
Views: 801

Re: NIC PCIe bottleneck

I don't think there is.
by mkx
Thu May 14, 2020 9:05 pm
Forum: Beginner Basics
Topic: NIC PCIe bottleneck
Replies: 5
Views: 801

Re: NIC PCIe bottleneck

Depends on driver ... either starts throttling using flow control ... or simply drops frames.
by mkx
Thu May 14, 2020 8:58 pm
Forum: General
Topic: drop forward invalid issue
Replies: 2
Views: 508

Re: drop forward invalid issue

My guess: routing triangle. When phone, unaware of wireguard tunnel, contacts a remote server, packet goes: phone - cap (transparently) - rb (routing) - wireguard-gw - ... and on the way back ... - wireguard-gw - cap (transparently) - phone ... skipping the rb4011 and thus screwing its connection tr...
by mkx
Thu May 14, 2020 8:41 pm
Forum: Beginner Basics
Topic: Different LAN VS VLAN solution
Replies: 2
Views: 435

Re: Different LAN VS VLAN solution

As one of your LANs is connected to dingle interface, then whatever RB roes with it is routing. And whrn it comes to routing, there is no difference between your current config and VLAN-based config. The only benefit of using VLANs would be when multipke LAN segments shared same physical infrastruct...
by mkx
Mon May 11, 2020 5:47 pm
Forum: General
Topic: VLAN filtering on a sigle bridge problem
Replies: 6
Views: 715

Re: VLAN filtering on a sigle bridge problem

Ingress filtering is only enabled on eth19 (and bridge interface), the rest of ports don't have it set.

I've no other idea, perhaps some smart guys will pop by ...
by mkx
Mon May 11, 2020 4:29 pm
Forum: General
Topic: VLAN filtering on a sigle bridge problem
Replies: 6
Views: 715

Re: VLAN filtering on a sigle bridge problem

Does anyone have any idea what would be wrong with the configuration?
Not without actually seeing the configuration.
by mkx
Mon May 11, 2020 4:20 pm
Forum: General
Topic: Mikrotik hAP ac2 fasttrack speed limit ?
Replies: 2
Views: 636

Re: Mikrotik hAP ac2 fasttrack speed limit ?

The problem with low-end devices is exactly what you found out: processing takes some tiny amount of time and thus limits throughput of a single connection even though there's ample CPU power available. If you would test with multiple parallel connections, you might find out that cumulative throughp...
by mkx
Mon May 11, 2020 1:02 pm
Forum: Beginner Basics
Topic: Internet Detect Feature stopped working
Replies: 2
Views: 374

Re: Internet Detect Feature stopped working

I recommend against using internet detect feature ... it doesn't add any usable information if admin knows which interface is WAN ...
by mkx
Mon May 11, 2020 12:53 pm
Forum: Beginner Basics
Topic: hAP ac2 - type of VLAN implementation
Replies: 6
Views: 906

Re: hAP ac2 - type of VLAN implementation

Disable the /interface detect-internet, it's total and utter crap. Probably this setting is screwing you up. Because otherwise router doesn't add any interface to any list all by itself.
by mkx
Mon May 11, 2020 12:46 pm
Forum: Beginner Basics
Topic: CRS125 - PPPoE - NAT
Replies: 11
Views: 1498

Re: CRS125 - PPPoE - NAT

... if I export this configuration and import it in the original Mikrotik (which is level 5), will it work? It should work if you really export (not backup). But then it's tiny details: are both firewalls similar enough? After all, PPPoE client setup is pretty straight forward. It's firewall (filte...
by mkx
Sat May 09, 2020 6:06 pm
Forum: Beginner Basics
Topic: Router Speed 1/3 of Direct Connection to Modem
Replies: 12
Views: 1582

Re: Router Speed 1/3 of Direct Connection to Modem

Bottleneck is the fact that CRS devices are switches with low-capacity L3 functionality. Meaning they can route and firewall, but nowhere near wirespeed. If you want to get decent routing speed, get a router. A low-cost candidate device is hAP ac2 (you can disable wireless) ... or a RB450Gx4 - prici...
by mkx
Sat May 09, 2020 5:45 pm
Forum: Beginner Basics
Topic: Router Speed 1/3 of Direct Connection to Modem
Replies: 12
Views: 1582

Re: Router Speed 1/3 of Direct Connection to Modem

Actually the routing speed you're getting is more or less what your CRS is capable of. Any higher routing speed would mean sacrificing security (firewall) ... which might be fine for routing between two LAN subnets without any limitations about connectivity (i.e. simple routing, no firewall), but wh...
by mkx
Sat May 09, 2020 5:31 pm
Forum: Beginner Basics
Topic: CRS125 - PPPoE - NAT
Replies: 11
Views: 1498

Re: CRS125 - PPPoE - NAT

it has no firewall rules to speak of and not safe at all noted, any set of minimal rules? A pointer to a tutorial? Good starting point is to take latest config export, then reset config on CRS to factory defaults, enable PPPoE (using QuickSet) and after that do minimum number of small changes if us...
by mkx
Sat May 09, 2020 5:12 pm
Forum: RouterBOARD hardware
Topic: RB962UiGS-5HacT2HnT (hAP ac) problem with PoE!
Replies: 4
Views: 660

Re: RB962UiGS-5HacT2HnT (hAP ac) problem with PoE!

Then why is this Poe passive? What devices can I power? I thought this "hap ac" supports "802. 3af" Thanks. Standard for PoE (802.3af/at/bt) requires some (pretty simple) "data" exchange between PSE (power provider) and PD (power consumer) for PSE to start providing power. Passive PoE OTOH does not...
by mkx
Fri May 08, 2020 1:52 pm
Forum: General
Topic: [Bug?/Issue] VLAN aware Bridge + Bridge NAT
Replies: 7
Views: 1271

Re: [Bug?/Issue] VLAN aware Bridge + Bridge NAT

... bytes are swapped not shifted. I have neither hardware to test nor test case ... so, could it have something to do with big-endina VS. little-endian architecture? We all know that ethernet is big-endian, but some of our routers are little-endian... So perhaps someone developing this part of UI ...
by mkx
Fri May 08, 2020 10:30 am
Forum: General
Topic: How to drop established coonections
Replies: 4
Views: 616

Re: How to drop established coonections

So to make the action=reject rule work on packets belonging to already established connections, you have to place if before (above) the action=accept connection-state=...,established,... one. There's the tricky part: fast-track. To effectively control packets of certain connection(s), those connect...
by mkx
Fri May 08, 2020 10:00 am
Forum: Beginner Basics
Topic: Internet Not Full-Speed [SOLVED]
Replies: 20
Views: 3397

Re: Internet Not Full-Speed [SOLVED]

One of the things I have an issue with is your WANIP status. Do you have a dynamic or static WANIP?? The reason I ask is your NAT rules show a mismatch. The sourcenat rules are setup for a dynamic WANIP and your dstnat rules are setup for a static FIXED WANIP?? I know that there are users strongly ...
by mkx
Thu May 07, 2020 4:16 pm
Forum: General
Topic: Intelligent port forwarding rule
Replies: 10
Views: 1366

Re: Intelligent port forwarding rule

Is there a (not overly complex) way to achive this in ROS? There are no "smart" ways of configuring NAT. You could configure it using some script ... but you'd still end up with N NAT rules. So even if the job would be done using a script, I'd run the script on some linux PC and copy-paste the resu...
by mkx
Thu May 07, 2020 4:11 pm
Forum: Beginner Basics
Topic: hAP ac2 - type of VLAN implementation
Replies: 6
Views: 906

Re: hAP ac2 - type of VLAN implementation

Don't even think about variant 1 ... it's deprecated way of doing it on devices without switch chips before bridge became VLAN aware (ROS 6.42 or something). I'm running variant 3 on my own RBD52G due to the following reasons: my ISP uses PPPoE for internet connectivity, it is terminated on my RBD52...
by mkx
Thu May 07, 2020 3:52 pm
Forum: Beginner Basics
Topic: hAP ac2 with USB external disc
Replies: 5
Views: 2437

Re: hAP ac2 with USB external disc

For sure a 320GB 2.5" Samsung external HDD is usable...
It is. But the performance is below any acceptable level and even then it bogs down whole router. These devices simply are not meant to be NAS devices. The sooner you'll accept it, he better.
by mkx
Tue May 05, 2020 7:41 pm
Forum: Beginner Basics
Topic: 'Lost' default MAC address
Replies: 47
Views: 4973

Re: 'Lost' default MAC address

Your repeaters (02-09-5b) are not known in the website.

And can not be, those MAC addresses are locally administered MAC addresses and can be used freely (as long as they are unique within ethernet broadcast domain).
by mkx
Tue May 05, 2020 6:57 pm
Forum: General
Topic: VLAN Tagging CPU Load
Replies: 6
Views: 1140

Re: VLAN Tagging CPU Load

These devices don't have switch chips.
Which devices?
OP mentioned hypervisor in initial post. So I guess he's asking about CHR and indeed CHR doesn't have switch chip.
by mkx
Tue May 05, 2020 6:08 pm
Forum: Beginner Basics
Topic: Internet Not Full-Speed [SOLVED]
Replies: 20
Views: 3397

Re: Internet Not Full-Speed [SOLVED]

I think setting MTU size will do. But this is experimental. Sure. But apart from special cases (such as you described), reducing packet sizes means lower throughput, both due to higher load on any devices processing those packets (routers, firewalls, ...) and due to higher share of packet headers o...
by mkx
Tue May 05, 2020 6:01 pm
Forum: Beginner Basics
Topic: Internet Not Full-Speed [SOLVED]
Replies: 20
Views: 3397

Re: Internet Not Full-Speed [SOLVED]

I only have 12 IP filter rules which according to the data sheet https://mikrotik.com/product/RB750Gr3#fndtn-testresults should mean it'll still operate at full speed. I guess I could get rid of a few of them but don't know how that will impact the security of my system? When fast-track is in use (...
by mkx
Tue May 05, 2020 5:20 pm
Forum: Beginner Basics
Topic: Inter Vlan Routing
Replies: 27
Views: 3212

Re: Inter Vlan Routing

It would be a total waste for me I would have to get 12 sfp+ cages (from sfp+ to 1Gig ethernet). But why am I still salivating?? You're salivating for the very same reason why Øveraasen TV 2200 is subject of your dreams while in reality all you need is a basic Snow Joe. ;-) Haha, how did you know I...
by mkx
Tue May 05, 2020 12:22 am
Forum: Beginner Basics
Topic: What is the use of interface lists in VLAN firewall
Replies: 5
Views: 1069

Re: What is the use of interface lists in VLAN firewall

Btw, if you check the packet flow diagram, you'll see that traffic enters bridge as vlan and leaves bridge accordingly. It's not very clear from documentation, but bridge in ROS has two, quite distinct, personalities: switch-like entity which forwards frames between member ports. If vlan-filtering=...
by mkx
Tue May 05, 2020 12:16 am
Forum: Beginner Basics
Topic: What is the use of interface lists in VLAN firewall
Replies: 5
Views: 1069

Re: What is the use of interface lists in VLAN firewall

Vlan interface, created in /interface vlan , is overlaid over underlying interface ... in your case that's bridge interface ... and bridge interface is CPU's access to bridge - the switch-like entity. When it comes to traffic in VLAN 7 between ether2 and ether10 ... one of those ports is in-interfac...
by mkx
Mon May 04, 2020 11:30 pm
Forum: Beginner Basics
Topic: New House - Hardware recommendation
Replies: 9
Views: 1411

Re: New House - Hardware recommendation

You should be aware of the fact that inter-VLAN communication needs a router and CRS3xx is essentially not a router. Meaning that RB4011 wouldn't only be your internet gateway/router/firewall, it would be inter-VLAN router as well. With its routing capacity around 2.5 Gbps it would become single bot...
by mkx
Mon May 04, 2020 11:20 pm
Forum: Beginner Basics
Topic: What is the use of interface lists in VLAN firewall
Replies: 5
Views: 1069

Re: What is the use of interface lists in VLAN firewall

There's a fundamental error in your setup: all of L2 setup is about bridge interface being tagged member of VLAN with VID=7, but you set bridge with pvid=7 , which is wrong because it's setting bridge interface as untagged member of same VLAN. Set pvid on bridge (back to default) to value of pvid=1 ...
by mkx
Mon May 04, 2020 9:13 pm
Forum: Beginner Basics
Topic: CISCO ACL TO MIKROTIK?
Replies: 4
Views: 853

Re: CISCO ACL TO MIKROTIK?

But if the two rules are true.......... WHY WOULD ONE NOT JUST MAKE IT ONE SUBNET??????
To limit amount of broadact traffic?
by mkx
Mon May 04, 2020 9:11 pm
Forum: Beginner Basics
Topic: Inter Vlan Routing
Replies: 27
Views: 3212

Re: Inter Vlan Routing

It would be a total waste for me I would have to get 12 sfp+ cages (from sfp+ to 1Gig ethernet). But why am I still salivating??

You're salivating for the very same reason why Øveraasen TV 2200 is subject of your dreams while in reality all you need is a basic Snow Joe. ;-)
by mkx
Mon May 04, 2020 8:39 pm
Forum: General
Topic: DHCP IPv6 over pppoe "Deutsche Telekom" not working
Replies: 3
Views: 875

Re: DHCP IPv6 over pppoe "Deutsche Telekom" not working

I guess, if I'd like an IPv6 Address for my Mikrotik I have to assign it to a link lokal interface or something? Your router will have a few IPv6 addresses, one per LAN interface. They get assigned from pool. In theory one could have control over which address out of prefix is actually assigned, bu...
by mkx
Mon May 04, 2020 8:28 pm
Forum: Beginner Basics
Topic: Inter Vlan Routing
Replies: 27
Views: 3212

Re: Inter Vlan Routing

For better inter-VLAN routing performance you need a better router. Until a CCR2004 arrives (it's right behind the corner), you might want to look at RB4011. It's got single SFP+ interface (in addition to several 1Gbps ethernet ports) and should be able to route around 2.5Gbps.
by mkx
Sun May 03, 2020 11:02 pm
Forum: General
Topic: SFP working in hEX-s but not in the 4011
Replies: 13
Views: 1971

Re: SFP working in hEX-s but not in the 4011

RB4011 has SFP+ port (10Gbps) while hEX S has SFP port (1 Gbps). So it might be necessary to manually set port speed to 1Gbps on RB4011 to start communicating with the SFP module. What you see in SFP status is likely read out of DDC port and that's out-of-band ... so yes, quite likely SFP synchroniz...
by mkx
Sun May 03, 2020 10:54 pm
Forum: General
Topic: How to limit Vlans inside bridges without using IPs
Replies: 6
Views: 1310

Re: How to limit Vlans inside bridges without using IPs

I'm not sure if I understand your question right ... but anyway: VLANs are below IP and switch (or bridge part of MT router which acts as a switch) can forward frames between different ports (depending on configuration of course) without having IP address in that VLAN.
by mkx
Sun May 03, 2020 10:39 pm
Forum: General
Topic: DHCP IPv6 over pppoe "Deutsche Telekom" not working
Replies: 3
Views: 875

Re: DHCP IPv6 over pppoe "Deutsche Telekom" not working

Different telekom, but using PPPoE as well ... here are my settings: /ipv6 dhcp-client # requesting only prefix ... address not needed, link-local is used for pppoe-out1 interface add add-default-route=yes interface=pppoe-out1 pool-name=pool.iov6 request=prefix use-peer-dns=no # IPv6 address pool no...
by mkx
Sun May 03, 2020 10:25 pm
Forum: Beginner Basics
Topic: CAP no longer accessible (winbox or webfig)
Replies: 1
Views: 579

Re: CAP no longer accessible (winbox or webfig)

Connect a PC to a switched port on RB4011 (so there's no routing between PC and cAP ac) and use MAC connection in winbox. Alternatively connect PC directly to cAP ac (use cAP ac' cable usually connecting it to RB4011).
by mkx
Sun May 03, 2020 4:23 pm
Forum: Beginner Basics
Topic: no IPv6 connection from LAN
Replies: 1
Views: 550

Re: no IPv6 connection from LAN

Default setup on Mikrotik SOHO routers is that they don't support IPv6 at all (with ROS v6 that is). One has to install IPv6 package, available in extra packages from MT's download page. Beware that after installing package, IPv6 config is empty and that includes IPv6 firewall. You'll have to manual...
by mkx
Sun May 03, 2020 12:11 pm
Forum: Beginner Basics
Topic: mikrotik x 2 - one address in the LAN
Replies: 24
Views: 2876

Re: mikrotik x 2 - one address in the LAN

But still switching between routers takes about 3-5 seconds. The telephone conversation during this time is interrupted. One thing to check: does the device keep the same LAN IP address after it switches over to another AP or band? Anyhow, even if transition period (for changing serving AP) is only...
by mkx
Sun May 03, 2020 12:04 pm
Forum: RouterBOARD hardware
Topic: CRS305-1G-4S+IN mounted under desk possible?
Replies: 1
Views: 551

Re: CRS305-1G-4S+IN mounted under desk possible?

Be very careful ... I wouldn't block any of ventilation grilles, specially not the ones on top surface right over the SFP cages ... it is known that SFP modules get hot and when they're hot, they might perform unstably. Judging from the pictures I wouldn't mount the switch rotated upside-down, I mig...
by mkx
Sun May 03, 2020 11:57 am
Forum: General
Topic: ASK[Email]
Replies: 9
Views: 1291

Re: ASK[Email]

I was almost offline for half a year and the world hasn't stopped rotating :)

Earth is spinning all right, but the world we live in slowed down almost to a halt. I think you should accept your share of responsibility for that :wink:
by mkx
Sun May 03, 2020 11:44 am
Forum: Beginner Basics
Topic: Internet on mikrotik router
Replies: 8
Views: 1212

Re: Internet on mikrotik router

Double NAT in principle means double firewall (I know, firewall and NAT don't go not necessarily together, but on SOHO devices they do) ... so you get two layers of security and you start to aporoach the onion-like layered security. But this only works if you carefully configure both firewalls. If y...
by mkx
Sun May 03, 2020 11:29 am
Forum: Beginner Basics
Topic: Cant get Band 20 4G.....i KNOW ITS THERE
Replies: 5
Views: 1054

Re: Cant get Band 20 4G.....i KNOW ITS THERE

very strange........... RSRP (if your signal strength numbers are this) of -115dBm is about absolute minimum for LTE to work at all. And it only allows low throughput (up to Mbps or so), furthermore link won't be stable (a few dB higher loss due to bad weather and you loose the link). For the very ...
by mkx
Sun May 03, 2020 11:19 am
Forum: Announcements
Topic: v6.46.6 [stable] is released!
Replies: 67
Views: 28575

Re: v6.46.6 [stable] is released!

The problem is actually flapping of ether1 port ... now you only have to find out why is that happening.
by mkx
Sun May 03, 2020 12:36 am
Forum: Beginner Basics
Topic: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]
Replies: 56
Views: 6193

Re: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]

However subnet 192.168.254.0/24 and subnet 192.168.0.0/17 need routing to communicate, unless some devices have a different (e.g. /16) subnet defined, or something else is used to make them connect directly. OP's post #28 includes some ASCII-art LAN scheme and there's a router between both subnets....
by mkx
Sun May 03, 2020 12:31 am
Forum: Beginner Basics
Topic: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]
Replies: 56
Views: 6193

Re: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]

Dear Jotne, yes, I just want to use this device as a switch. So then be so kind and just tell me how to turn the firewall on for this switch.
So you decided to completely ignore my last post (just below @jotne's you're quoting). Fine, remind me to add you on my ignore list as well ...
by mkx
Sun May 03, 2020 12:17 am
Forum: Beginner Basics
Topic: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]
Replies: 56
Views: 6193

Re: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]

If I understand your LAN setup, then currently CRS is switching not routing. And while it's switching, none of traffic hits firewall. If you really want to use your swirch as firewall, you have to: disable HW offload ... it is done per-port in /interface bridge port by setting hw=no This setting wil...
by mkx
Sat May 02, 2020 11:45 pm
Forum: Beginner Basics
Topic: Cant get Band 20 4G.....i KNOW ITS THERE
Replies: 5
Views: 1054

Re: Cant get Band 20 4G.....i KNOW ITS THERE

Depends on particular LHG you've got ... but so far every Mikrotik LTE antenna I checked had lousy gain for low bands (B20 and B8 ... something between 0 and 5 dBi) and decent to good gain for high bands (B3 around 15 dBi, even higher for B1 and B7).

The difference in gain is significant.
by mkx
Sat May 02, 2020 4:52 pm
Forum: Beginner Basics
Topic: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]
Replies: 56
Views: 6193

Re: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]

When fast-track is enabled, then counters don't account for majority of traffic in forward chain ... that's how effective is shortcut called fast-track.
by mkx
Sat May 02, 2020 4:37 pm
Forum: Beginner Basics
Topic: Trying to understand default configuration of hAP2
Replies: 3
Views: 649

Re: Trying to understand default configuration of hAP2

A few aspects: ether1 is not part of bridge meaning that devices connected to bridged interfaces and devices connected to ether1 can not communicate directly, they have to use router as gateway ether1 receives specific configuration depending on ISP requirements (either DHCP client or PPPoE client o...
by mkx
Sat May 02, 2020 4:25 pm
Forum: Beginner Basics
Topic: Inter Vlan Routing
Replies: 27
Views: 3212

Re: Inter Vlan Routing

Mikrotik publishes performance test results for every device. Surf to product list , select your device and click "Test results". There are different sections for different functionality, when it comes to routing (any kind, including inter-VLAN), look at Ethernet test results table, rows Routing. In...
by mkx
Sat May 02, 2020 4:05 pm
Forum: Beginner Basics
Topic: problems figuring out dhcp rules and ip address change
Replies: 3
Views: 604

Re: problems figuring out dhcp rules and ip address change

I thought my message was clear: change IP addressing of your LAN. Verify that everything works with new IP addresses. Only then add address to router which will allow it to communicate with modem. As to the src-nat rule: it might actually work as it is. We'll think about it when we determine necessi...
by mkx
Sat May 02, 2020 1:08 pm
Forum: Beginner Basics
Topic: problems figuring out dhcp rules and ip address change
Replies: 3
Views: 604

Re: problems figuring out dhcp rules and ip address change

For changing IP config on router, use winbox with MAC connectivity ... when winbox is started, click MAC address of your router in the "discovered devices" tab. This was changing router's IP settings won't break managmenet connection. Re. IP addressing: as I can see, you're currently receiving publi...
by mkx
Sat May 02, 2020 12:24 pm
Forum: General
Topic: can't connect to hEX S after factory reset / netinstall
Replies: 8
Views: 1224

Re: can't connect to hEX S after factory reset / netinstall

/system interface How sure are you of that command ? Not very sure. Here's the guide, it seemed to go OK aside from the very first part. I'm testing it right now to confirm it's working as expected. https://github.com/hallzhallz/Articles/tree/master/2020-04-25%20Mikrotik%20hEX%20S This guide seems ...
by mkx
Sat May 02, 2020 12:19 pm
Forum: Beginner Basics
Topic: Vlan Filtering
Replies: 8
Views: 1357

Re: Vlan Filtering

So I dont unterstand why this does not work..
Because it's pretty much wrong.

Read through this fine tutorial.
by mkx
Sat May 02, 2020 12:06 am
Forum: Wireless Networking
Topic: NTP client time sync
Replies: 11
Views: 1809

Re: NTP client time sync

As you probably know, you can check status of NTP client using /system ntp client print ... the DHCP-asigned NTP server IP address should appear in the output. If it's not, then the use-peer-ntp option doesn't work (I don't use DHCP assigned addresses for vital network appliances so I don't have exp...
by mkx
Fri May 01, 2020 11:59 pm
Forum: Beginner Basics
Topic: 'Lost' default MAC address
Replies: 47
Views: 4973

Re: 'Lost' default MAC address

Probably you can't change MAC address without first connecting to the unit. Depending on how the unit was set up you might be able to connect to it using different interfaces (e.g. wireless versus ethernet). If the unit was reasonably secured, then probably the only solution is to reset configuratio...
by mkx
Fri May 01, 2020 11:07 pm
Forum: General
Topic: can't connect to hEX S after factory reset / netinstall
Replies: 8
Views: 1224

Re: can't connect to hEX S after factory reset / netinstall

/system interface
But it says "bad command interface, row1 column9" or something like that.
I've been using ROS for quite a few years and quoted command did not exist in my era. So it must be some kind of an error. Can you qoute some part from the guide to see the context?
by mkx
Fri May 01, 2020 10:59 pm
Forum: Beginner Basics
Topic: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]
Replies: 56
Views: 6193

Re: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]

@msatter, I fully agree. I also find articles and posts, where authors use shorthened commands, most annoying. It hurts readability a lot and I guess it only serves authors to position themselves as some hotshots. @mutluit: if I knew your background, I would word my posts only slightly differently. ...
by mkx
Fri May 01, 2020 2:05 pm
Forum: Beginner Basics
Topic: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]
Replies: 56
Views: 6193

Re: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]

FIrewall is always used for traffic being routed ... meaning between different IP subnets. Generally yes, but I would say that a firewall can also be used inside a closed environment within just the same one subnet, without any uplink. Do you think this doesn't make any sense? IMO it very well does...
by mkx
Fri May 01, 2020 1:37 pm
Forum: Wireless Networking
Topic: hAP ac lite router will not connect wifi printer to network
Replies: 6
Views: 1408

Re: hAP ac lite router will not connect wifi printer to network

The building owner has chosen to pay for an FTP connection and provides tenants with connection via wifi. He provides the hAP ac lite device so that we can set up our own individual LANs. So if I understand this right: the hAP ac lite is client to landlord's wireless system to provide you with inte...
by mkx
Fri May 01, 2020 1:20 pm
Forum: Wireless Networking
Topic: hap ac lite can't connect to another AP
Replies: 21
Views: 2784

Re: hap ac lite can't connect to another AP

Just a minor remark: There is a possible problem with DHCP client on a bridge. .... Some brands of DHCP servers may struggle with the fact that the ARP entry and DHCP entry has different MAC addresses for the same IP address, what is not a conflict for DHCP packets. In station-pseudobridge-clone mod...
by mkx
Fri May 01, 2020 1:09 pm
Forum: Beginner Basics
Topic: Slowness for the first few seconds then fast on download
Replies: 17
Views: 2223

Re: Slowness for the first few seconds then fast on download

connection tracking: one thing different with fast-track, is that it bypass connection tracking, No, it doesn't, fast track only works for packets belonging to marked connections (see description of fasttrack ) and those are marked by connection tracking machinery. Which means router still has to p...
by mkx
Fri May 01, 2020 12:54 pm
Forum: General
Topic: One power supply for 2 devices [SOLVED]
Replies: 9
Views: 1332

Re: One power supply for 2 devices [SOLVED]

If devices are inter-connected with conductive cables, then they are not truly galvanicly isolated. And conductive cables include UTP cables. If you want to galvanically isolate devices, then you need to use a stretch of optical cable on interconnect ... and certainly use separate power adapters, po...
by mkx
Fri May 01, 2020 12:29 pm
Forum: Beginner Basics
Topic: Slowness for the first few seconds then fast on download
Replies: 17
Views: 2223

Re: Slowness for the first few seconds then fast on download

Slow speeds at the start of a download and then higher speeds after some time is not a bug of the router, it is a feature of TCP. Certainly you're right about that. However it doesn't explain the difference between behaviours OP observed ... the sending server cannot know that fasttrack is running ...
by mkx
Thu Apr 30, 2020 11:31 pm
Forum: General
Topic: Apps having internet connection with reject and drop firewall rule [SOLVED]
Replies: 10
Views: 2223

Re: Apps having internet connection with reject and drop firewall rule [SOLVED]

Perhaps explanation about why some services continued to work after you added the block rule: 1 ;;; TEST chain=forward action=reject reject-with=icmp-network-unreachable src-mac-address=iPhone's MAC addr. log=no log-prefix="" 9 ;;; defconf: fasttrack chain=forward action=fasttrack-connection connect...
by mkx
Thu Apr 30, 2020 5:09 pm
Forum: Beginner Basics
Topic: 2 LAN Cables from Mikrotik to Switch
Replies: 24
Views: 3193

Re: 2 LAN Cables from Mikrotik to Switch

There's a nice article on wikipedia about different bonding modes. Read it, it'll answer all your questions.

Section about Linux bonding driver is the most interesting (as this is essentially what ROS does).
by mkx
Thu Apr 30, 2020 3:53 pm
Forum: Beginner Basics
Topic: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]
Replies: 56
Views: 6193

Re: Is there a "use-ip-firewall" setting also for non-bridge setup? [SOLVED]

FIrewall is always used for traffic being routed ... meaning between different IP subnets. The use-ip-firewall=yes option only affects traffic passing bridge which would otherwise skip CPU (because it is within same IP subnet). Regarding mismatch between reality and documentation: if you think that ...
by mkx
Thu Apr 30, 2020 2:04 pm
Forum: Beginner Basics
Topic: 2 LAN Cables from Mikrotik to Switch
Replies: 24
Views: 3193

Re: 2 LAN Cables from Mikrotik to Switch

So a thought came, what if 2 switches (desktop grade) are linked by 2 cables, would there be an increase in bandwidth between the 2 switches. As explained by posters in previous posts: this only works if both switches support bonding with the same bonding strategy (803.2ad is the most likely candid...
by mkx
Thu Apr 30, 2020 1:51 pm
Forum: General
Topic: Can't update - could not resolve DNS name error [SOLVED]
Replies: 12
Views: 2116

Re: Can't update - could not resolve DNS name error [SOLVED]

Two things to be done on cAP ac:
  1. Configure default route in /ip route using main router's LAN IP address as gateway
  2. Configure DNS servers in /ip dns ... use same IP addresses as usual LAN clients use
by mkx
Thu Apr 30, 2020 8:28 am
Forum: RouterBOARD hardware
Topic: hEX S + SFP+ in the near future?
Replies: 1
Views: 843

Re: hEX S + SFP+ in the near future?

hEX S hardware is too weak to deal with 10Gbps speeds (that SFP+ offers). It would need better CPU and possibly better switch chip. All of that is available in RB4011 (there's also same device with wireless built-in). It is bulkier though.
by mkx
Thu Apr 30, 2020 8:20 am
Forum: General
Topic: SFP details missing in RB4011 vs RB2011
Replies: 2
Views: 845

Re: SFP details missing in RB4011 vs RB2011

Which ROS version is RB2011 running? And which version of routerboot? You can check the later in /system routerboard print?
by mkx
Wed Apr 29, 2020 11:52 pm
Forum: RouterBOARD hardware
Topic: Just going to leave this here...
Replies: 139
Views: 23702

Re: Just going to leave this here...

@lapsio: nicely written. Too bad @vortex won't get past the first paragraph ...
by mkx
Wed Apr 29, 2020 11:42 pm
Forum: General
Topic: Different DHCP pools on ports from 192.168.1.0/21 network
Replies: 18
Views: 2418

Re: Different DHCP pools on ports from 192.168.1.0/21 network

So I guess you tried my suggestion in post #10 above and it didn't work?
by mkx
Wed Apr 29, 2020 11:38 pm
Forum: General
Topic: Work not evenly distributed among the multiple CPU cores
Replies: 7
Views: 1438

Re: Work not evenly distributed among the multiple CPU cores

I'll guess: the unclassified includes idle time. But I may well be wrong.
by mkx
Wed Apr 29, 2020 11:34 pm
Forum: Beginner Basics
Topic: Mikrotik SXT LTE6 LAN Speed Connect up to 300 Mbps in downlink The LAN interface card is only 100Mbs!
Replies: 2
Views: 803

Re: Mikrotik SXT LTE6 LAN Speed Connect up to 300 Mbps in downlink The LAN interface card is only 100Mbs!

You can perceive things like that. But more likely, with many LTE users around, you'll hardly see actual throughput hit 100Mbps ... 300Mbps is theoretical peak which can be achieved if signal level is perfect and you're the lone user of both cells used in CA. In reality there will be many users in t...
by mkx
Wed Apr 29, 2020 10:59 pm
Forum: RouterOS v7 BETA
Topic: VLANs on switch chip
Replies: 2
Views: 1065

Re: VLANs on switch chip

@huntah, thanks for reply. Previous to posting my OP I also tried with vlan-header=leave-as-is ... worked just the same as with my posted setting. However if I tried to set vlan-mode=secure or vlan-mode=check , I lost access to device's CPU. From official manual : fallback - checks tagged traffic ag...
by mkx
Wed Apr 29, 2020 8:19 pm
Forum: Wireless Networking
Topic: NTP client time sync
Replies: 11
Views: 1809

Re: NTP client time sync

The add-on package has to match ROS architecture and version (to the last digit). Anything in log after reboot? It should have some information about package - either that it was installed or some complaint about how the package was inappropriate.
by mkx
Wed Apr 29, 2020 8:13 pm
Forum: Beginner Basics
Topic: Firewall: Locked out myself. What was the reason? [SOLVED]
Replies: 23
Views: 2434

Re: Firewall: Locked out myself. What was the reason? [SOLVED]

I feel relaxed since we started to have a pub chatter ...

I was attempting to demonstrate that one can leave MACWINBOX up and running and still feel secure from other LAN users.

Sorry anav, this is a recent addition to your original statement ... which changes your standpoint infinitely.
by mkx
Wed Apr 29, 2020 8:09 pm
Forum: General
Topic: Different DHCP pools on ports from 192.168.1.0/21 network
Replies: 18
Views: 2418

Re: Different DHCP pools on ports from 192.168.1.0/21 network

Device which routes traffic between subnets (e.g. between different VLANs) can of course account that traffic. However, VLANs are only one of ways to separate subnets (another one is having separate physical subnets). But regardless the L2 (or L2.5) technology, as long as there are devices within sa...
by mkx
Wed Apr 29, 2020 8:02 pm
Forum: General
Topic: Auto updating ROS - yeah or nay?
Replies: 7
Views: 1268

Re: Auto updating ROS - yeah or nay?

Since you explicitly asked me to donate my 5 cents ... I've nothing to add to @sindy's endless wisdom.
by mkx
Wed Apr 29, 2020 7:58 pm
Forum: General
Topic: Different DHCP pools on ports from 192.168.1.0/21 network
Replies: 18
Views: 2418

Re: Different DHCP pools on ports from 192.168.1.0/21 network

I have software that is analyzing , blocking, sniffing traffic based on ip address group. I will connect to different port different departments (i want to have traffic report for all department, not for specific pc) Ah, I forgot to add: whatever magic you do, within L2 network (whatever the extent...
by mkx
Wed Apr 29, 2020 7:51 pm
Forum: Beginner Basics
Topic: Firewall: Locked out myself. What was the reason? [SOLVED]
Replies: 23
Views: 2434

Re: Firewall: Locked out myself. What was the reason? [SOLVED]

Good practice is to limit mac access to winbox to only the interface the admin uses not necessarily all lan interfaces...........

And place a sentry near the device to prevent some trespassing by to plug their gear into management port.

Or get out of paranoia mode and use some common sense.
by mkx
Wed Apr 29, 2020 6:39 pm
Forum: Beginner Basics
Topic: 3G USB modem on hAP ac2 [SOLVED]
Replies: 5
Views: 961

Re: 3G USB modem on hAP ac2 [SOLVED]

Last word of caution: your router currently doesn't have any firewall whatsoever. It is an easy target for hackers and you should really implement some. My suggestion: check the default firewall filter rules, they are very decent starting point. However, before implementing those rules you have to p...
by mkx
Wed Apr 29, 2020 6:25 pm
Forum: Wireless Networking
Topic: NTP client time sync
Replies: 11
Views: 1809

Re: NTP client time sync

You don't have to install ntp package if you only want to set time on the router itself, ROS includes sntp client in system package. If you want to set up router as NTP server, then install ntp package from extra packages (available as ZIP file from download.mikrotik.com)
by mkx
Wed Apr 29, 2020 6:19 pm
Forum: General
Topic: Different DHCP pools on ports from 192.168.1.0/21 network
Replies: 18
Views: 2418

Re: Different DHCP pools on ports from 192.168.1.0/21 network

The problem with your plan is the following: DHCP is a L2 protocol meaning that you can only have one DHCP server per ethernet segment. Which is fine as you plan to segment your network off separate ports of your router. However, devices belonging to same L3 network expect to freely communicate with...
by mkx
Wed Apr 29, 2020 6:09 pm
Forum: General
Topic: hAP ac³ LTE6 kit use case?
Replies: 6
Views: 1016

Re: hAP ac³ LTE6 kit use case?

IMHO fixed wireless broadband without using a big (ugly) antenna should be banned by constitution. In some countries, it's the reverse, use of the network designed to serve mobile users to provide service for fixed equipment was even prohibited by telecommunication law Probably you're right, but qu...
by mkx
Wed Apr 29, 2020 5:47 pm
Forum: Beginner Basics
Topic: 3G USB modem on hAP ac2 [SOLVED]
Replies: 5
Views: 961

Re: 3G USB modem on hAP ac2 [SOLVED]

This rule
/ip firewall nat
add action=masquerade chain=srcnat out-interface=ppp-out1 src-address=192.168.88.1
only covers router's own address ... remove the last part (src-address), it should be like this:
add action=masquerade chain=srcnat out-interface=ppp-out1
by mkx
Wed Apr 29, 2020 5:40 pm
Forum: Beginner Basics
Topic: Firewall: Locked out myself. What was the reason? [SOLVED]
Replies: 23
Views: 2434

Re: Firewall: Locked out myself. What was the reason? [SOLVED]

That's not that important as I'm still just learning and also experimenting. Well, be everybody's guest and do whatever pleases you ... I've always found learning by starting from solid cases to be the best. Study default firewall filter rule set, try to understand what each and every line does and...
by mkx
Wed Apr 29, 2020 5:36 pm
Forum: General
Topic: Filter rule is accepted, but dst-nat not working
Replies: 6
Views: 2397

Re: Filter rule is accepted, but dst-nat not working

Post the config (/ip firewall nat export and anything related, e.g. address lists and/or interface lists) and let us examine it ...
by mkx
Wed Apr 29, 2020 5:24 pm
Forum: General
Topic: PPPoE client connected but no internet [SOLVED]
Replies: 10
Views: 1977

Re: PPPoE client connected but no internet [SOLVED]

ROS runing on your device is ancient. Upgrade it to latest available for your device (globally that would be 6.46.x, I'm not sure if your vintage RB750 is still supported). Probably you'd be better off setting dial-on-demand=no on pppoe-client configuration. And enable your last firewall rule (drop ...
by mkx
Wed Apr 29, 2020 5:21 pm
Forum: General
Topic: hAP ac³ LTE6 kit use case?
Replies: 6
Views: 1016

Re: hAP ac³ LTE6 kit use case?

Wouldn't a better solution be a hAP ac2 with an outdoor mounted wAP LTE modem for fail-over, aggregation, or simple broadband connection? I have the same opinion, provided that the LTE modem used in the hAP ac³ is a plug-in one which will be available also for use in the wAP LTE kit. But some peopl...
by mkx
Wed Apr 29, 2020 5:09 pm
Forum: General
Topic: Work not evenly distributed among the multiple CPU cores
Replies: 7
Views: 1438

Re: Work not evenly distributed among the multiple CPU cores

/tool profile cpu=all
by mkx
Wed Apr 29, 2020 5:03 pm
Forum: Beginner Basics
Topic: Firewall: Locked out myself. What was the reason? [SOLVED]
Replies: 23
Views: 2434

Re: Firewall: Locked out myself. What was the reason? [SOLVED]

This one: 5 ;;; drop all invalid dstIPs chain=input action=drop dst-address-list=bogon_IPs because ... [admin2@MikroTik] /ip/firewall/filter> /ip firewall/address-list/print Columns: LIST, ADDRESS, CREATION-TIME # LIST ADDRESS CREATION-TIME ;;; RFC6890 2 bogon_IPs 192.168.0.0/16 apr/29/2020 14:33:28...
by mkx
Wed Apr 29, 2020 4:56 pm
Forum: Beginner Basics
Topic: 3G USB modem on hAP ac2 [SOLVED]
Replies: 5
Views: 961

Re: 3G USB modem on hAP ac2 [SOLVED]

Make sure you have the following: in step #3 you have to configure /ip dhcp-server network ... you need an entry with minimum of the following attributes: address=192.168.88.0/24 dns-server=8.8.8.8,1.1.1.1 gateway=192.168.88.1 netmask=24 in step #6 you need to check add-default-route As you did not ...
by mkx
Wed Apr 29, 2020 10:48 am
Forum: General
Topic: Work not evenly distributed among the multiple CPU cores
Replies: 7
Views: 1438

Re: Work not evenly distributed among the multiple CPU cores

Interrupt handling is not relevant information to judge how general load is distributed among CPU cores. My experience goes that interrupt handling depends on HW architecture as well, many x86 hosts service interrupts on a few distinct CPU cores, some even by core 0. If you want to see if second cor...
by mkx
Wed Apr 29, 2020 10:30 am
Forum: Beginner Basics
Topic: TP Link Repeater RE450 not assigning IP address
Replies: 10
Views: 3740

Re: TP Link Repeater RE450 not assigning IP address

Can you please point to wiki on how to set up a wireless repearer/bridge with mikrotik routers? Must be 802.11 protocol so non-mikrotik devices can connect to the same wifi networks This wiki article discusses different WiFi client modes available on ROS devices. What you're after is the following:...
by mkx
Tue Apr 28, 2020 10:53 pm
Forum: RouterOS v7 BETA
Topic: V7 questions?
Replies: 33
Views: 6159

Re: V7 questions?

... as a Virtual Machine (CHR) on ESXi, KVM, HyperV (and I think Xen too).
According to official docs works under VirtualBox as well.
by mkx
Tue Apr 28, 2020 10:20 pm
Forum: RouterOS v7 BETA
Topic: VLANs on switch chip
Replies: 2
Views: 1065

VLANs on switch chip

On a RB951G I have VLANs configured "the old school" way - on the switch chip. In ROS v6 this setup works great and is fully HW-offloaded. I can't get the same/similar setup work on v7 at all. Initially I tried to upgrade from 6.45.7, but after reboot the device did not come back to the network. Min...
by mkx
Tue Apr 28, 2020 6:23 pm
Forum: Beginner Basics
Topic: bytes up/down calculated wrong
Replies: 6
Views: 1041

Re: bytes up/down calculated wrong

Queues and fast-track are mutually exclusive. So you have to disable fasttrack ... by default there's a rule in /ip firewall filter with action=fasttrack-connection chain=forward . Disable that rule and then wait for connections to die off (when a connection is fast-tracked, it can't be un-fast-trac...
by mkx
Mon Apr 27, 2020 11:35 pm
Forum: Beginner Basics
Topic: Configuring the Firewall in RouterOS [SOLVED]
Replies: 38
Views: 5056

Re: Configuring the Firewall in RouterOS [SOLVED]

Your chain=input is not complete ... some vital rules are commented out, but you didn't replace them with your own like you did for chain=forward . Which means that router with such firewall is an easy target for an attacker. You did not show it in posted fragment, so it's not possible to guess if i...
by mkx
Mon Apr 27, 2020 11:22 pm
Forum: Wireless Networking
Topic: NTP client time sync
Replies: 11
Views: 1809

Re: NTP client time sync

I'll qoute myself: NTP stands for Network Time Protocol. So when there's no network connectivity, you don't have precise time. Now ... you might fing some way of giving routers a tiny connectivity towards some NTP server (DHCP serving private IP address should do the trick) while still requiring PPP...
by mkx
Mon Apr 27, 2020 10:46 pm
Forum: Beginner Basics
Topic: Configuring the Firewall in RouterOS [SOLVED]
Replies: 38
Views: 5056

Re: Configuring the Firewall in RouterOS [SOLVED]

Beware of the fact that rules are executed from top to bottom. Which means that any rules below add chain=forward connection-nat-state=!dstnat connection-state=new in-interface-list=WAN action=drop # drop all from WAN not DNATed are useless as they very likeky won't get hit at all. And make yourself...
by mkx
Mon Apr 27, 2020 9:18 pm
Forum: Beginner Basics
Topic: Basic VLAN Setup
Replies: 22
Views: 3202

Re: Basic VLAN Setup

My guess: if you add switch1-cpu interface to vlan members (in /interface ethernet switch vlan), then you should also set it as tagged (/interface ethernet switch egress-vlan-tag ... who knows what is default, probably untagged ...
by mkx
Mon Apr 27, 2020 6:04 pm
Forum: Wireless Networking
Topic: NTP client time sync
Replies: 11
Views: 1809

Re: NTP client time sync

NTP stands gor Network Time Protocol. So when there's no network connectivity, you don't have precise time. Apart from that: router's internal clock keeps running even without internet, it's just not very precise any more. Such devices loose or gain up to a few seconds a day (most are better than th...
by mkx
Mon Apr 27, 2020 5:54 pm
Forum: Wireless Networking
Topic: capsman 2.4Ghz 40Mhz Turbo hAP lite?
Replies: 11
Views: 1830

Re: capsman 2.4Ghz 40Mhz Turbo hAP lite?

@mkx personally i will never use 40Mhz channel width to any CapsMan setup in the 2.4Ghz Band... Well, what you personally do is your business and nobody (except regulator's inspectors) can force you to do otherwise. However, when you try to help other users, you can only nicely suggest they set thi...
by mkx
Mon Apr 27, 2020 5:47 pm
Forum: Beginner Basics
Topic: How to send PM to other user (ie. privately contacting a user)? [SOLVED]
Replies: 13
Views: 1786

Re: How to send PM to other user (ie. privately contacting a user)? [SOLVED]

I just wrote a PM, The header says "Sent" plus datetime, but it is placed in the Outbox folder. What is the "Sent messages" folder for? It's empty in my case. In similar forums the message stays in Outbox until receiver opens it. While message is in Outbox, sender can still edit it (and possibly de...
by mkx
Mon Apr 27, 2020 5:37 pm
Forum: General
Topic: Basic vlan layer 2 config on CRS317-1G-16S+ [SOLVED]
Replies: 8
Views: 2388

Re: Basic vlan layer 2 config on CRS317-1G-16S+ [SOLVED]

The first command configures ingress behaviour while the second one configures egress behaviour. Both commands are not entirely independant of each other though, setting ingress-filtering=yes establishes the dependency. Another important setting is frame-types= ... It is possible to set interface to...
by mkx
Mon Apr 27, 2020 4:36 pm
Forum: Beginner Basics
Topic: How to send PM to other user (ie. privately contacting a user)? [SOLVED]
Replies: 13
Views: 1786

Re: How to send PM to other user (ie. privately contacting a user)? [SOLVED]

best I can do right now is a CHR license

Send them to @anav and he might squeeze some mapple syrup from them :lol:

But I wouldn't mind getting one :wink:
by mkx
Mon Apr 27, 2020 4:34 pm
Forum: Beginner Basics
Topic: Can't ping between subnets
Replies: 11
Views: 1576

Re: Can't ping between subnets

Well, OP never mentioned which device type he's using. If it's from the pro-line (CCR, CRS3xx, RB1xxx), then it comes with empty default config and OP can't really revert to default config.

But then configuring those devices requires pro-admin who knows his job ...
by mkx
Mon Apr 27, 2020 4:25 pm
Forum: General
Topic: making sure the main router manage all connection?
Replies: 25
Views: 3500

Re: making sure the main router manage all connection?

Take a look at VLANs as already suggested ... using VLANs you can split your network into separate parts and configure it so that only main router can pass traffic between different VLANs. It is not that complicated (about the same as capsman) ... You'll need it for your VMs as you already mentioned
by mkx
Mon Apr 27, 2020 4:05 pm
Forum: Beginner Basics
Topic: Basic VLAN Setup
Replies: 22
Views: 3202

Re: Basic VLAN Setup

Yeah, I couldn't begin to guess I don't really know this architecture. But I tested adding it back and as soon as I did it stopped working again. As others mentioned, switch shouldn't be doing that. So I'm guessing some other config is causing it. But one can't do any more guessing without you post...
by mkx
Mon Apr 27, 2020 4:00 pm
Forum: Beginner Basics
Topic: Bridge each vlan
Replies: 2
Views: 667

Re: Bridge each vlan

What in particular do you want to do? Because bridge without interfaces means nothing ...
by mkx
Sun Apr 26, 2020 10:54 pm
Forum: Wireless Networking
Topic: capsman 2.4Ghz 40Mhz Turbo hAP lite?
Replies: 11
Views: 1830

Re: capsman 2.4Ghz 40Mhz Turbo hAP lite?

My bad for not noticing the "turbo 40MHz", I (perhaps wrongly) assumed OP wanted to use 20+20 mode (which is usual these days) and had issues configuring that. And I assumed OP used that particular wording for no special reason. Re use of 2.4GHz: the problem about many articles (not just about netwo...
by mkx
Sun Apr 26, 2020 8:29 pm
Forum: RouterBOARD hardware
Topic: Just going to leave this here...
Replies: 139
Views: 23702

Re: Just going to leave this here...

@vortex: do us a favour and flatter yourself for not being a typical home or small office user. Stop claiming that your desires are typical SOHO requirements ... because they're not. You can call yourself a very advanced user who wants performance which is currently meant for HPC facilities and data...
by mkx
Sun Apr 26, 2020 8:06 pm
Forum: Wireless Networking
Topic: capsman 2.4Ghz 40Mhz Turbo hAP lite?
Replies: 11
Views: 1830

Re: capsman 2.4Ghz 40Mhz Turbo hAP lite?

Well, @zacharias, there are many clients that support 40MHz channels on 2.4GHz. And not everybody lives in city centres where everybody (including their dogs) run at least one AP on 2.4 GHz. There are also suburban/rural users where house to house distance (counting also wall attenuation) actually e...
by mkx
Sun Apr 26, 2020 7:50 pm
Forum: RouterBOARD hardware
Topic: Just going to leave this here...
Replies: 139
Views: 23702

Re: Just going to leave this here...

That's fine. None of that is typically done in the home or small offices. But it is done in small closed research groups of up to that size. Research groups can't be considered typical SOHO groups. Hence they don't use SOHO gear ... even if it's the same devices, when they use them they are instrum...
by mkx
Sun Apr 26, 2020 7:48 pm
Forum: RouterBOARD hardware
Topic: Just going to leave this here...
Replies: 139
Views: 23702

Re: Just going to leave this here...

It was not me who called a 4k-11k router SOHO. No, you didn't do it directly. However, you're very vocal at claiming 40Gbps is a minimum for contemporary SOHO[*] ... I'm just extrapolating that over current gear prices. [*] I'm not talking about special uses such as set forward by @mutluit ... and ...
by mkx
Sun Apr 26, 2020 7:25 pm
Forum: General
Topic: Need advice on firewall rules
Replies: 10
Views: 1651

Re: Need advice on firewall rules

Your selection of knowledge sources is not entirely wrong, just ditch the "random online tutorials". But it's the order you used which made your config a weird mess. So start off with default config and only change or add things you know you need. And things you understand. Official docs should help...
by mkx
Sun Apr 26, 2020 7:09 pm
Forum: Beginner Basics
Topic: 2 WANs possible with CRS326-24G-2S+ with RouterOS ? [SOLVED]
Replies: 8
Views: 1709

Re: 2 WANs possible with CRS326-24G-2S+ with RouterOS ? [SOLVED]

On every products page you will find a "Test Results" section that shows the performance of the Device... ... but while looking at those numbers, don't take the biggest one as relevant for average real-life use. Many of us on this forum find the number in "Routing - 25 ip filter rules - 512 byte pa...
by mkx
Sun Apr 26, 2020 3:42 pm
Forum: Beginner Basics
Topic: Lease Expiry Causing DHCP Critical Error [SOLVED]
Replies: 23
Views: 3336

Re: Lease Expiry Causing DHCP Critical Error [SOLVED]

You could set filter to follow UDP packets with dst-port either 67 or 68 ... any address and any direction.

"hockey sock full of ..." :lol:
by mkx
Sun Apr 26, 2020 3:36 pm
Forum: RouterBOARD hardware
Topic: Just going to leave this here...
Replies: 139
Views: 23702

Re: Just going to leave this here...

I agree with you there must be a huge market for devices like that. Everyone in the SOHO business would want or need some. What @vortex seems to be implying is that such devices should come with SOHO price tag - and I fully agree at this point. Absolute number (and currency symbol) varies from mark...
by mkx
Sun Apr 26, 2020 3:25 pm
Forum: Wireless Networking
Topic: Two antennas at act as dual Polarity
Replies: 5
Views: 1234

Re: Two antennas at act as dual Polarity

Do you think I will see an improvement in throughput/performance of system, or even an increase in signal levels to/from CPEs? That highly depends on the CPEs and environment configuration between AP and CPEs. Improvement in signal strength can be anything between zero (with single-pol clients alre...
by mkx
Sun Apr 26, 2020 2:56 pm
Forum: Beginner Basics
Topic: Lease Expiry Causing DHCP Critical Error [SOLVED]
Replies: 23
Views: 3336

Re: Lease Expiry Causing DHCP Critical Error [SOLVED]

Ideally you'd start wireshark before initial address acquisition and then keep running it until after next address acquisition ... if run with appropriate filters it should show all DHCP-related handshakes including unsuccessfull tries. And if trace shows some mis-behaviour of ISP's core nodes, that...
by mkx
Sun Apr 26, 2020 12:03 pm
Forum: General
Topic: Fasttrack not working.
Replies: 18
Views: 2819

Re: Fasttrack not working.

Official test results are done on optimally configured devices which includes (working) fast-track. So if in your real-life scenario you're getting throughput of same order of magnitude as test result, then it means fast-track works. So yes, it seems that there's a minor bug in counters you're refer...
by mkx
Sun Apr 26, 2020 11:46 am
Forum: General
Topic: Accept established and related connections on Filter or Mangle?
Replies: 4
Views: 972

Re: Accept established and related connections on Filter or Mangle?

fast-track already does that. Only packets not fast-tracked enter usual firewall chain ... and depending on fast-track rule those packets are mostly belonging to new connections ... which are not that numerous. Or packets belonging to connections which require special treatment (e.g. are being mangl...
by mkx
Sun Apr 26, 2020 11:38 am
Forum: General
Topic: Need advice on firewall rules
Replies: 10
Views: 1651

Re: Need advice on firewall rules

My suggestion: reset firewall filter rules to default rule set, it is a very good starting point (pretty safe and pretty high performance) which you decided to throw away. You don't have to reset whole device, you can see default config by running command /system default-configuration print (make su...
by mkx
Sun Apr 26, 2020 12:40 am
Forum: RouterBOARD hardware
Topic: SOLVED : RB4011iGS+RM : Unable to get more than 250Mbps Internet connection
Replies: 34
Views: 5317

Re: RB4011iGS+RM : Unable to get more than 250Mbps Internet connection

I still need to figure why Chrome on my desktop caps at 200mbps though. So you found out that speedtest tests speed of the browser as well :wink: You can check if chrome happens to consume more CPU during tests ... or if it's running on single CPU core (whereas other browser runs on multiple) durin...
by mkx
Sun Apr 26, 2020 12:02 am
Forum: Beginner Basics
Topic: hAP AC Vs hAP AC2 without wireless performance
Replies: 5
Views: 1345

Re: hAP AC Vs hAP AC2 without wireless performance

hAP ac2 the newest of all three. Surprisingly prices of MT gear don't get lower when newer devices in the same segment get released... however prices of new devices are set according to market state at the launch time. Hence the weird state where older and less potent devices are higher priced than ...
by mkx
Sat Apr 25, 2020 11:51 pm
Forum: Wireless Networking
Topic: Two antennas at act as dual Polarity
Replies: 5
Views: 1234

Re: Two antennas at act as dual Polarity

If one antenna has horizontal polarization and the other one has vertical polarization, then this would be dual polarization setup when using both antennae. The inter-antenna distance doesn't matter when polarization is orthogonal. In fact antennae used in comercial mobile networks are mostly X-pola...
by mkx
Sat Apr 25, 2020 11:23 pm
Forum: Beginner Basics
Topic: Lease Expiry Causing DHCP Critical Error [SOLVED]
Replies: 23
Views: 3336

Re: Lease Expiry Causing DHCP Critical Error [SOLVED]

I have no access to the ISP modem, and neither does their useless tech support.
Not you, not them, so who has access ? :lol:
Probably @sindy :lol:
by mkx
Sat Apr 25, 2020 9:31 pm
Forum: Beginner Basics
Topic: Basic VLAN Setup
Replies: 22
Views: 3202

Re: Basic VLAN Setup

I assume all of the interface ports can be part of the same bridge? I saw one example online that was creating separate bridges, just wondering if this is necessary for some reason. Definitely go with single bridge. Use of multiple bridge is a) old school and b) not hardware accelerated ... Mind th...
by mkx
Sat Apr 25, 2020 9:12 pm
Forum: Beginner Basics
Topic: Multi Pools on DHCP Server
Replies: 2
Views: 832

Re: Multi Pools on DHCP Server

I have HP V1910-24G switch. It is L3 core switch, but doesn't have DHCP Server feature on it. So I must setup DHCP relay on all VLAN interfaces to my MikroTik. But i want to know if MikroTik router can provide multi pools on the same interface on MikroTik to VLAN interfaces HP V1910-24G). Another, ...
by mkx
Sat Apr 25, 2020 12:57 pm
Forum: Wireless Networking
Topic: Dune wi-fi connection to HAP AC2 troubles?
Replies: 1
Views: 830

Re: Dune wi-fi connection to HAP AC2 troubles?

Post full configuration of hAP ac2 ... open terminal window and execute command /export hide-sensitive ... and copy-paste results inside [code] [/code] environment. Redact any static public address and WiFi passwords (no need to redact SSIDs or MAC addresses).
by mkx
Sat Apr 25, 2020 12:51 pm
Forum: General
Topic: cAP ac reset not possible after netinstall
Replies: 6
Views: 1439

Re: cAP ac reset not possible after netinstall

Problem solved :)

The quoted post is completely useless. You should describe your solution to aide any future users with similar problem.
by mkx
Sat Apr 25, 2020 12:46 pm
Forum: Beginner Basics
Topic: How to unreserve and MAC address on an IP?
Replies: 5
Views: 1289

Re: How to unreserve and MAC address on an IP?

If you made DHCP lease reservation and you want host to start using dynamic lease, then click "remove" of lease. According to explanations in previous posts host will continue to use old IP address until it tries to renew the lease. At this moment DHCP server will either allow to further use same IP...
by mkx
Sat Apr 25, 2020 12:36 pm
Forum: Beginner Basics
Topic: Did I buy the wrong LTE Router?
Replies: 7
Views: 1585

Re: Did I buy the wrong LTE Router?

While RSRP (it's the cell's signal strength) difference between indoor (-93 dBm) and outdoor (79 dBm) is sensible one, it's RSRQ (signal quality) which is rather low. If it was the unrelated noise, tgen RSRQ should be lower (i.e. more negative) when RSRP gets higher. But the fact that RSRQ remains t...
by mkx
Sat Apr 25, 2020 12:08 pm
Forum: General
Topic: Fasttrack not working.
Replies: 18
Views: 2819

Re: Fasttrack not working.

I have 1Gbps WAN link and with current setup I can only get ~400/400Mbps.
Official test results indicate, that this device can't reach much more ... around 530 Mbps. Without working fast-track it can't do anything near this speed.
by mkx
Fri Apr 24, 2020 12:59 pm
Forum: Wireless Networking
Topic: hAP AC2, cAP AC, CAPsMAN and Google Smart Home
Replies: 10
Views: 2172

Re: hAP AC2, cAP AC, CAPsMAN and Google Smart Home

(can anyone tell me what's the different between IPQ4018 and IPQ4019?) Seems that 4018 misses some support for peripherial devices (most of which are not present in most of MT gadgets anyway) and possibility to select WiFi band on first WLAN interface (4018 has it fixed to 2.4GHz, 4019 seems to sup...
by mkx
Fri Apr 24, 2020 12:50 pm
Forum: General
Topic: Fasttrack not working.
Replies: 18
Views: 2819

Re: Fasttrack not working.

My take is that if counters on rule for enabling fasttrack in /ip firewall filter count traffic, then fasttrack is enabled and is working. BTW, /ip settings print show zero fasttrack packets as well. For checking the cause of high CPU load you should run profile ( /tool profile cpu=all ) and check w...
by mkx
Fri Apr 24, 2020 12:03 pm
Forum: Beginner Basics
Topic: dstnat rule executed on egress traffic [SOLVED]
Replies: 6
Views: 1668

Re: dstnat rule executed on egress traffic [SOLVED]

Your understanding is wrong. src-nat is mangling the src-address and src-port ... while dst-nat is mangling dst-address and dst-port. By that you mean ROS looking on the src part of the packet when using src-nat, and on the dst address when using dst-nat? Exactly. Which by itself makes rule half-ba...
by mkx
Thu Apr 23, 2020 6:24 pm
Forum: General
Topic: Can't access NAT of the same network
Replies: 4
Views: 1300

Re: Can't access NAT of the same network

You need hairpin NAT.
by mkx
Thu Apr 23, 2020 6:21 pm
Forum: General
Topic: ether2 excessive broadcasts/multicasts, probably a loop
Replies: 2
Views: 1020

Re: ether2 excessive broadcasts/multicasts, probably a loop

Post config of your RB ... in terminal window run command /export hide-sensitive ...
by mkx
Thu Apr 23, 2020 6:18 pm
Forum: General
Topic: HEX S Bridge VLAN setup - poor performance vlan to vlan (max. ~ 200 MBit/s)
Replies: 10
Views: 2225

Re: HEX S Bridge VLAN setup - poor performance vlan to vlan (max. ~ 200 MBit/s)

Either router needs a new admin or admin needs a new router... According to official test results (with a pinch of my experience) hEX S can route around 380 Mbps. But that's with 25 IP filter rules. OP has got 75 IP filter rules ... and 10 mangle rules which means that fast-track is out of picture (...
by mkx
Thu Apr 23, 2020 6:05 pm
Forum: General
Topic: CRS - Trunk-Port with all VLANs including those, which are not configured?
Replies: 1
Views: 807

Re: CRS - Trunk-Port with all VLANs including those, which are not configured?

You can do it like this (example is for ether1, but any ether / sfp / sfpplus ports can be set up the same way): /interface bridge port add bridge=bridge interface=ether1 frame-types=admit-only-vlan-tagged ingress-filtering=yes # this makes a trunk port - tagged only /interface bridge vlan add bridg...
by mkx
Thu Apr 23, 2020 5:53 pm
Forum: General
Topic: CRS317 not functioning with Avago SFP
Replies: 4
Views: 1316

Re: CRS317 not functioning with Avago SFP

Many devices from most vendors are more or less picky about SFP modules. Mikoritk prepared SFP compatibility list and you'll notice overwhelming lack of information about modules from other vendors. Which may be understandable, testing for interoperability is a huge task and there's no money for dev...
by mkx
Thu Apr 23, 2020 5:39 pm
Forum: Beginner Basics
Topic: POE Compability? [SOLVED]
Replies: 2
Views: 1338

Re: POE Compability? [SOLVED]

Specifications of SXTsq5 ac define powering voltage between 10 and 28 V. Implicitly this means that this device can not take 802.3af PoE (which is specced at 48V), it rather uses proprietary passive PoE (which RB960PGS can do if powered with supplied 24V power adapter). Specifications for wAP ac sa...
by mkx
Thu Apr 23, 2020 5:25 pm
Forum: Beginner Basics
Topic: dstnat rule executed on egress traffic [SOLVED]
Replies: 6
Views: 1668

Re: dstnat rule executed on egress traffic [SOLVED]

Which the wiki basically make a clear separation between ''dstnat chain'' to ''srcnat chain'' to my understanding, it means. srcnat - (Egress packets) - packet originated on LAN towards the WAN (LAN -> WAN) of course i don't forget the address translation process. dstnat - (Ingress packet) - packet...
by mkx
Thu Apr 23, 2020 5:15 pm
Forum: Beginner Basics
Topic: VLAN on ISP connection
Replies: 9
Views: 2111

Re: VLAN on ISP connection

@Zacharias, my suggestion was strictly for shown configuration which implies use of 3 ether ports (one for WAN, one for IPTV and one for LAN). Sure, if one wants to use 4 ports switched/bridged, then the config I proposed is not the best ... in that case I'd use single bridge which would include eth...
by mkx
Thu Apr 23, 2020 12:27 am
Forum: General
Topic: Getting VLAN to work between router and AP
Replies: 2
Views: 917

Re: Getting VLAN to work between router and AP

You'll have to set up VLANs on both devices properly. Setting vlan-id and use-tag on wAP is not enough.

I suggest you to go through this tutorial, it'll help you to see what has to be done in ROS. Hopefully you already undersrand basic concepts of VLANs ...
by mkx
Thu Apr 23, 2020 12:21 am
Forum: General
Topic: RB4011: Untagged Ports Overriden by Default VID1? [SOLVED]
Replies: 13
Views: 2190

Re: RB4011: Untagged Ports Overriden by Default VID1? [SOLVED]

Thank you everyone! I really appreciate your taking a look! Why do you need "admit-only-untagged-and-priority-tagged" on the ports in your case? This setting adds extra port security ... it will discard any tagged packets on ingress which othereise might get delivered somewhere. Settings in /interf...
by mkx
Thu Apr 23, 2020 12:03 am
Forum: General
Topic: Drop connections or drop packets?
Replies: 12
Views: 2182

Re: Drop connections or drop packets?

ROS firewall fakes connection state for UDP connections. Might not be as accurate as for statefull protocols, but helps to make constructing firewall filter rules easier. Probably helps for performance as well.
by mkx
Wed Apr 22, 2020 11:51 pm
Forum: Beginner Basics
Topic: to instal backup to another router
Replies: 12
Views: 2437

Re: to instal backup to another router

The export you're trying use is from quite old version of ROS (6.40) and sets some features not available in ROS versions past 6.42, such as this one set [ find default-name=ether3 ] master-port= ether2-master My suggestion is this: take the new device and start from default config. Then look at the...
by mkx
Wed Apr 22, 2020 11:43 pm
Forum: Beginner Basics
Topic: dstnat rule executed on egress traffic [SOLVED]
Replies: 6
Views: 1668

Re: dstnat rule executed on egress traffic [SOLVED]

At the last couple of weeks im working on wordpress site in my local lab, the site got to situation when i want to get others opinions so i had "port forward" any ingress traffic from WAN with dst-port 8080 using the following dstnat rule <snip> 1 ;;; enable remote access to wordpress chain=dstnat ...
by mkx
Wed Apr 22, 2020 11:34 pm
Forum: Beginner Basics
Topic: Restore "crashes" RB951G-2HnD
Replies: 10
Views: 1472

Re: Restore "crashes" RB951G-2HnD

Another way of dealing with your issue us to run command
/interface ethernet reset-mac-address
after restoration of "non-native" backup. I don't think there's similar command for resetting NAC of wlan interfaces ...
by mkx
Wed Apr 22, 2020 11:23 pm
Forum: Beginner Basics
Topic: VLAN on ISP connection
Replies: 9
Views: 2111

Re: VLAN on ISP connection

@mkx am trying to think how we could avoid the creation of 2 Bridges but i can't find something... I don't see where's the problem? Just a more tidy configuration... I never said there is a problem, relax @mkx :lol: Well, to make my own statement more clear: I'm all for single bridge. So I wonder w...
by mkx
Wed Apr 22, 2020 12:42 am
Forum: Wireless Networking
Topic: Multi VLAN + router on the stick
Replies: 7
Views: 1700

Re: Multi VLAN + router on the stick

For my taste, the channel is much too noisy ... -68 dBm (if I interpret the table right) of noise is screaming, should be lower than -90 dBm. And signal strength from AP (-30 dBm) is too high as well - you can have problems to understand somebody shouting at your ear even though distant listeners ca...
by mkx
Wed Apr 22, 2020 12:16 am
Forum: General
Topic: MacTelnet-Client
Replies: 8
Views: 1570

Re: MacTelnet-Client

Anyway, a working mac-telnet from linux terminal would be very handy.
Mikrotik, please share information about authentication mechanism. You do not need to provide any code, just share that information!
+1
by mkx
Wed Apr 22, 2020 12:15 am
Forum: General
Topic: 16 ports
Replies: 5
Views: 1313

Re: 16 ports

No idea about your requirements. E.g. those 16 ports, should they be copper RJ45 or SFP? Do you want to run ROS or SwOS? If ROS, any requirements about L3 capacity?
by mkx
Wed Apr 22, 2020 12:08 am
Forum: Beginner Basics
Topic: VLAN on ISP connection
Replies: 9
Views: 2111

Re: VLAN on ISP connection

@mkx am trying to think how we could avoid the creation of 2 Bridges but i can't find something...
I don't see where's the problem?
by mkx
Tue Apr 21, 2020 1:14 am
Forum: Beginner Basics
Topic: How to diagnose VLAN performance issues on RB3011
Replies: 21
Views: 3404

Re: How to diagnose VLAN performance issues on RB3011

There's /system profile cpu=all during hicups to see if some process is over-using resources. You can check the byte-counts on interfaces (if using GUI to connect there are nice graphs made from those numbers). Look into /log if there's something logged when problems appear ... perhaps some ether po...
by mkx
Tue Apr 21, 2020 1:10 am
Forum: General
Topic: 16 ports
Replies: 5
Views: 1313

Re: 16 ports

If you can't find a switch that suites you on this page, then you'll have to look at other vendors.
by mkx
Tue Apr 21, 2020 1:03 am
Forum: General
Topic: Drop connections or drop packets?
Replies: 12
Views: 2182

Re: Drop connections or drop packets?

As I mentioned, /ip filter raw works more or less directly on packets without notion of connections. Then at some intermediate moment, there comes connection tracking which is a quite expensive operation. However, stateful firewalls have to do it and firewall in ROS is a stateful one. If you don't n...
by mkx
Mon Apr 20, 2020 9:43 pm
Forum: General
Topic: statick DHCP same IP for the same computer via ethernet or wifi
Replies: 10
Views: 1623

Re: statick DHCP same IP for the same computer via ethernet or wifi

I like the idea. Actually the computers I would like to assign static ips are linux machines, so I will give it a try. Beware that this idea probably fails miserably if both interfaces don't connect to same L2 network ... I guess the same idea can be used with dynamic address acquisition (over DHCP...
by mkx
Mon Apr 20, 2020 9:35 pm
Forum: General
Topic: Drop connections or drop packets?
Replies: 12
Views: 2182

Re: Drop connections or drop packets?

Filter in principle works on connection level. However .... ROS implements a feature called "fast track", which largely bypasses firewall functions for packets belonging to certain connections (depends on other parameters of enabler command, default setup is to use this feature for all established a...
by mkx
Mon Apr 20, 2020 8:29 pm
Forum: General
Topic: Drop connections or drop packets?
Replies: 12
Views: 2182

Re: Drop connections or drop packets?

Default SOHO setup does not bother with marking anything, just drops connection in /ip firewall filter...
by mkx
Mon Apr 20, 2020 8:22 pm
Forum: General
Topic: statick DHCP same IP for the same computer via ethernet or wifi
Replies: 10
Views: 1623

Re: statick DHCP same IP for the same computer via ethernet or wifi

sure there are some laptops that do it, but they have to run user-land software for that. Actually you can change the Metric of the Interface itself... If i set my ethernet card with Metric e.g. 20 and my wireless card with Metric 19 then the wireless card will be used as default... If the traffic ...
by mkx
Mon Apr 20, 2020 8:17 pm
Forum: Beginner Basics
Topic: SFP Port on Switch Level VLAN [SOLVED]
Replies: 8
Views: 1996

Re: SFP Port on Switch Level VLAN [SOLVED]

Maybe i should have posted the picture instead... :lol:

One picture tells more than a thousand words. Specially to illiterate. But then you posted link to block diagram of 2011 ... true it was before OP mentioned RB3011 as design taken as reference for all RB devices ....
by mkx
Mon Apr 20, 2020 8:15 pm
Forum: RouterBOARD hardware
Topic: Adding a cooling fan to CRS326
Replies: 39
Views: 5465

Re: Adding a cooling fan to CRS326

@mutluit: why do you believe some random posters on internet forums rather than user support of manufacturer of your device? Common knowledge[/url] about CPU temperatures these days too much bases on stories of PC overclockers. But physics (specially thermodynamics of solid materials) says that over...
by mkx
Mon Apr 20, 2020 7:46 pm
Forum: Wireless Networking
Topic: Trying to force carrier aggregation between two band 3 masts
Replies: 8
Views: 1812

Re: Trying to force carrier aggregation between two band 3 masts

Is there any command/anything I can do to attempt to make the two connect or something like that? Used frequency sub-bands, used by H3G in your neighbourhood, are not contigous (i.e. there's a gap between both sub bands). And @uldis wrote that R11e-LTE6 doesn't support non-contigous intra-band CA. ...
by mkx
Mon Apr 20, 2020 7:33 pm
Forum: General
Topic: statick DHCP same IP for the same computer via ethernet or wifi
Replies: 10
Views: 1623

Re: statick DHCP same IP for the same computer via ethernet or wifi

One problem with the concept of having single static IP address for multiple network interfaces of same device is that not all network devices actually automatically disable one interface when the other one gets connectivity ... sure there are some laptops that do it, but they have to run user-land ...
by mkx
Mon Apr 20, 2020 7:22 pm
Forum: General
Topic: MacTelnet-Client
Replies: 8
Views: 1570

Re: MacTelnet-Client

Winbox is not suitable for me, I am a Linux user, and wine is not very fond of. So why don't you use ssh to access routers? mactelnet has one single function which ssh doesn't: connectivity over MAC, which comes handy when IP setup gets south. But hopefully that's not very often and I (being a linu...
by mkx
Mon Apr 20, 2020 7:15 pm
Forum: Beginner Basics
Topic: SFP Port on Switch Level VLAN [SOLVED]
Replies: 8
Views: 1996

Re: SFP Port on Switch Level VLAN [SOLVED]

RB3011 is different beast. Block diagram of RB3011UiAS-RM https://i.mt.lv/cdn/rb_files/RB3011UiAS-160307123613.png shows that there are two interconnect lanes between CPU and switch chip ... however, the second interconnect line gets re-routed from switch chip to SFP if SFP module is inserted. Which...
by mkx
Sun Apr 19, 2020 11:54 pm
Forum: General
Topic: Which PCI-E SFP dual card is supported in ROS v6?
Replies: 1
Views: 805

Re: Which PCI-E SFP dual card is supported in ROS v6?

Whichever are supported by your favourite virtualisation platform.

It seems that for running on non-RB hardware MT currently only supports CHR (x86 variant of ROS explicitly intended to be run in a virtual machine). Things might change with advent of ROSv7, but I'm not holding my breathe.
by mkx
Sun Apr 19, 2020 11:49 pm
Forum: General
Topic: MacTelnet-Client
Replies: 8
Views: 1570

Re: MacTelnet-Client

It is maintained, but not all details about authentication are available. Read this for details:
https://github.com/haakonnessjoen/MAC-Telnet/issues/42

Thanks for the link. Makes things much more clear.
by mkx
Sun Apr 19, 2020 11:32 pm
Forum: General
Topic: MacTelnet-Client
Replies: 8
Views: 1570

Re: MacTelnet-Client

Currently available mactelnet-client doesn't support connections to ROS version 6.43 or newer. That ROS version brought change in how passwords are stored and change in logon procedures had to follow. mactelnet-client doesn't seem to be maintained, hence necessary change never got implemented. BTW, ...
by mkx
Sun Apr 19, 2020 5:27 pm
Forum: Beginner Basics
Topic: Query about 5GHz maximum speed RBD52G-5HacD2HnD [SOLVED]
Replies: 14
Views: 2262

Re: Query about 5GHz maximum speed RBD52G-5HacD2HnD [SOLVED]

Achievable speed largely depends on signal strength and quality ... and on other settings as well (e.g. channel width ... e.g. 20MHz vs. 80MHz). What does client device report as signal strength and signal to noise ratio?
by mkx
Sun Apr 19, 2020 5:22 pm
Forum: Beginner Basics
Topic: SFP Port on Switch Level VLAN [SOLVED]
Replies: 8
Views: 1996

Re: SFP Port on Switch Level VLAN [SOLVED]

Trying this out on RB2011 and I just noticed that the SFP port is not in the Switch Port. How do you configure it for VLAN? Flags: I - invalid # NAME SWITCH VLAN-MODE VLAN-HEADER DEFAULT-VLAN-ID 0 sfp1 switch1 disabled leave-as-is auto Are you sure it's not there? Mind that if you execute /interfac...
by mkx
Sun Apr 19, 2020 4:45 pm
Forum: Beginner Basics
Topic: Hardening access to device, but allowing ping from everywhere
Replies: 5
Views: 1199

Re: Hardening access to device, but allowing ping from everywhere

I don't understand the role of this device and its place in network layout (which I don't understand either). As far as I understand the setup, CRS is used as a LAN switch - all ports are bridged meaning all are member if same ethernet subnet. It also only has single IP address 192.168.88.1/17 (whic...
by mkx
Sun Apr 19, 2020 4:29 pm
Forum: RouterOS v7 BETA
Topic: Mysterious 564/tcp open port 7.0beta5
Replies: 38
Views: 6188

Re: Mysterious 564/tcp open port 7.0beta5

Are there bugs in these things? What do you think? Hint: we're talking about beta release in development branch, not about some LTS ultra-stable version. I'm not saying you shouldn't mention weird things, that's what beta releases are for. But don't get too surprised if you find some bug ....
by mkx
Sun Apr 19, 2020 4:27 pm
Forum: Announcements
Topic: v6.45.8 [long-term] is released!
Replies: 87
Views: 60533

Re: v6.45.8 [long-term] is released!

rotten information https://wiki.mikrotik.com/wiki/Manual:Peripherals If your post is about LTE modems ... then I guess the information on the page you linked is as acurate as it gets ... MT did not upgrade kernel used in ROS for a while and (sadly) new peripherials are not supported by a 9 year old...
by mkx
Sun Apr 19, 2020 2:20 pm
Forum: Announcements
Topic: v6.46.5 [stable] is released!
Replies: 72
Views: 25971

Re: v6.46.5 [stable] is released!

HAP AC2
After loading the router, 75 MB of memory is free, and after 4 days uptime, 55 MB of memory is free, I’ve cleaned the memory logs. Where did the memory leak?

Do you happen to build some address lists (with long timeouts)?
by mkx
Sun Apr 19, 2020 2:13 pm
Forum: Wireless Networking
Topic: Multi VLAN + router on the stick
Replies: 7
Views: 1700

Re: Multi VLAN + router on the stick

I dont understand what you meant by this: ... your VLAN setup is missing a lot, as it stands the whole device is mostly vlan-ignorant. Which means that after you implement the bare minimum changes, your setup might seem to work, but VLANs will be bleeding all over the place... If I understand corre...
by mkx
Sun Apr 19, 2020 2:03 pm
Forum: Wireless Networking
Topic: CAPsMAN radio not setting up correctly
Replies: 2
Views: 1033

Re: CAPsMAN radio not setting up correctly

A few problems with your config: in datapath setting, when using local-forwarding, the bridge= setting doesn't matter (AFAIK). And if it does, it refers to bridge on cAP device (not CAPsMAN) at the same time VLAN settings have to be in place on all involved devices (cAP, CAPsMAN, any switches in bet...
by mkx
Sun Apr 19, 2020 1:41 pm
Forum: Wireless Networking
Topic: Trying to force carrier aggregation between two band 3 masts
Replies: 8
Views: 1812

Re: Trying to force carrier aggregation between two band 3 masts

At least from what I was told, Three (Ireland) supports carrier aggregation between these 2 carriers on band 3 ...

I suggest you to email support@mikrotik.com with explicit question whether R11e-LTE6 (I guess that's the modem mounted in your device) supports "CA of non-contigous B3+B3" ...
by mkx
Sun Apr 19, 2020 1:25 pm
Forum: Beginner Basics
Topic: Vlan and bridge
Replies: 8
Views: 1676

Re: Vlan and bridge

High level LAN layout is not clear from your description ... e.g. for VoIP network, is RB acting as a router-on-a-stick and you connect all VoIP devices to some switch downstream from ether2? BTW, there's seemingly a leftover config line ... get rid of it: /interface ethernet switch vlan add indepen...
by mkx
Sun Apr 19, 2020 1:15 pm
Forum: Beginner Basics
Topic: ccr1036-12g-4s 2.5 /gb max throughput under NAT
Replies: 5
Views: 1514

Re: ccr1036-12g-4s 2.5 /gb max throughput under NAT

Cpu load remsins average 30 to 40 % Your device has 36 CPU cores, so average CPU load means nothing (e.g. a BGP exchange process can use 100% of single CPU and average CPU load would be less than 3% and yet routing tables wouldn't be updated any faster). Do a CPU profile: /tool profile cpu=all to s...
by mkx
Sun Apr 19, 2020 12:55 am
Forum: SwOS
Topic: CSS326 VLAN config problems, another topic :)
Replies: 1
Views: 1122

Re: CSS326 VLAN config problems, another topic :)

Do you have RSTP enabled on routers as well?
by mkx
Sun Apr 19, 2020 12:47 am
Forum: RouterBOARD hardware
Topic: cAP (lite) what use is fast wireless speed with 10/100 ethernet? [SOLVED]
Replies: 3
Views: 1790

Re: cAP (lite) what use is fast wireless speed with 10/100 ethernet? [SOLVED]

Also, please keep in mind that those advertised speeds of wifi are not even close to the real world numbers in any practical scenario. For example - 300Mbit of ac standart is measured at direct line of sight and at 1 meter from the router. Move away a room-lenght and/or place the router in the cupb...
by mkx
Sun Apr 19, 2020 12:29 am
Forum: RouterBOARD hardware
Topic: Adding a cooling fan to CRS326
Replies: 39
Views: 5465

Re: Adding a cooling fan to CRS326

It really looks like that they forgot to activate the second CPU core. Take a look at this Linux patchset documentation for this ARM CPU: Patch-set is vintage 2017, while linux kernel used in ROS v6 predates that (by a lot). So it just seems to me that MT did not back-port the patch. Linux kernel u...
by mkx
Sun Apr 19, 2020 12:15 am
Forum: General
Topic: Isolate Clients on same subnet [SOLVED]
Replies: 3
Views: 1545

Re: Isolate Clients on same subnet [SOLVED]

The communication within same subnet in principle doesn't pass IP firewall, it only passes bridge and if HW offloaded (most MT devices do it), it only passes switch chip. So if you want to isolate clients, you have to force all traffic to router's CPU by setting hw=no on all ports members of tge bri...
by mkx
Sat Apr 18, 2020 11:54 pm
Forum: Wireless Networking
Topic: CapsMan VLAN question
Replies: 8
Views: 1819

Re: CapsMan VLAN question

If they are indeed unmanaged switches i am pretty sure they will just forward everything and they will not drop any tagged traffic... If they're brain-damaged, they might drop some VLAN-tagged frames ... those exceeding size of 1500 bytes. Most modern dumb switches support MTU of 1504 bytes (4 extr...
by mkx
Sat Apr 18, 2020 11:50 pm
Forum: Wireless Networking
Topic: Multi VLAN + router on the stick
Replies: 7
Views: 1700

Re: Multi VLAN + router on the stick

You don't have the slave wlan interfaces connected to the rest of L2 network. Scrap the vlan interfaces vlan20, vlan 98 and vlan99. Add interfaces wlan3, wlan4 and wlan5 to bridge. And set vlan-mode=use-tag on wlan3 (I'm missing it). As I said: you didn't exactly understand the article about VLANs ....
by mkx
Sat Apr 18, 2020 11:16 pm
Forum: Wireless Networking
Topic: Trying to force carrier aggregation between two band 3 masts
Replies: 8
Views: 1812

Re: Trying to force carrier aggregation between two band 3 masts

But how can I make it connect to two band 3 masts? It's not possible due to many reasons, one is that it's not defined in 3GPP standards. It is possible to have 2CA intra-band, but operator has to use two carriers with different frequencies within same band and AFAIK that's only possible (standardi...
by mkx
Sat Apr 18, 2020 11:05 pm
Forum: Beginner Basics
Topic: ccr1036-12g-4s 2.5 /gb max throughput under NAT
Replies: 5
Views: 1514

Re: ccr1036-12g-4s 2.5 /gb max throughput under NAT

What does CPU profile say when CCR is fully loaded? Any particular process eating too much processor? You have 4-way bond, is the traffic evenly distributed over bond members?
by mkx
Sat Apr 18, 2020 11:02 pm
Forum: Beginner Basics
Topic: Basic VLAN setup on CRS317
Replies: 1
Views: 887

Re: Basic VLAN setup on CRS317

Read this tutorial, the second post (switch with a separate router) should be much like your use case.
Unlike most Mikrotik devices, your CRS will be full HW offloaded using such setup.
by mkx
Fri Apr 17, 2020 6:41 pm
Forum: Wireless Networking
Topic: CapsMan Slave Configuration question
Replies: 1
Views: 893

Re: CapsMan Slave Configuration question

HW parameters are always taken from master interface, hence you don't need to define them in configurations for slave interfaces.
by mkx
Fri Apr 17, 2020 6:19 pm
Forum: Wireless Networking
Topic: CAPsMAN config CAP how to use a "Channel List" [SOLVED]
Replies: 12
Views: 2663

Re: CAPsMAN config CAP how to use a "Channel List" [SOLVED]

Frequency lists are done like this: /caps-man channel add band=2ghz-g/n control-channel-width=20mhz extension-channel=XX frequency=2412,2432 name=channels24-lower add band=2ghz-g/n control-channel-width=20mhz extension-channel=XX frequency=2452,2472 name=channels24-upper CAP will auto-select frequen...
by mkx
Fri Apr 17, 2020 5:56 pm
Forum: Wireless Networking
Topic: Incorrect PIN locks the SIM - is it really impossible to solve?
Replies: 6
Views: 2244

Re: Incorrect PIN locks the SIM - is it really impossible to solve?

However, what I don't understand is, both SIMs have different PINs, and the LTE profile is the only object that contains a PIN parameter.

What keeps you from changing PIN on one of SIM cards?
by mkx
Fri Apr 17, 2020 5:50 pm
Forum: General
Topic: Question on connection and packet marking
Replies: 4
Views: 1250

Re: Question on connection and packet marking

Either first or second OP's mark rules doesn't do anything ... the rules differ only by comparing address list against dst-address or src-address respectively. But in both rules the critera includes out-interface=WAN ... and depending on contents of HighPriority address list (are those WAN addresses...
by mkx
Fri Apr 17, 2020 12:07 am
Forum: Wireless Networking
Topic: Multi VLAN + router on the stick
Replies: 7
Views: 1700

Re: Multi VLAN + router on the stick

I have read following VLAN article: https://forum.mikrotik.com/viewtopic.php?f=13&t=143620 You nay have read it, but judging from questions at the end of your post I have doubts you understood the article. Anyway, post configuration as printed using comnand /export hide-sensitive ... all of it, onl...
by mkx
Thu Apr 16, 2020 11:52 pm
Forum: General
Topic: cAP AC vs hEX PoE processing power
Replies: 4
Views: 1312

Re: cAP AC vs hEX PoE processing power

No, there isn't a product with identical features as hEX PoE but newer design. Either they are not same price range or they lack SFP or they lack proper PoE or ... And for the plans ... I'm not aware of any, but I'm generally ignorant about plans shown on powerpoint presentations. If I understand yo...
by mkx
Thu Apr 16, 2020 9:59 pm
Forum: General
Topic: cAP AC vs hEX PoE processing power
Replies: 4
Views: 1312

Re: cAP AC vs hEX PoE processing power

... why cAP AC (4 cores @ 716 MHz) has so much processing power in comparison to hEX PoE (1 core @ 800 MHz)?

cAP ac is a few years newer design than hEX PoE.
by mkx
Thu Apr 16, 2020 9:51 pm
Forum: General
Topic: L2pt connecting, internet access ok, i can ping router but cant access , neither lan pcs
Replies: 8
Views: 2193

Re: L2pt connecting, internet access ok, i can ping router but cant access , neither lan pcs

... if i disable the default firewall rule : Drop all not coming from LAN. How can i keep this rule up but i can work with L2PT ???? If the firewall filter rule is the problem: you can either add L2TP interface to the LAN interface list (but check if that's OK in all of Mikrotik's config) or you ca...
by mkx
Thu Apr 16, 2020 9:42 pm
Forum: General
Topic: Mikrotik behind router with no access to WAN's fileserver
Replies: 2
Views: 1056

Re: Mikrotik behind router with no access to WAN's fileserver

Assuming you left the RB at fairly default config, a pair of simple firewall rules should suffice. A pair for simpler setup, I'm sure a complex single rule would do as well: /ip firewall filter add chain=forward action=accept dst-address=193.30.80.133/32 add chain=forward action=drop dst-address=193...
by mkx
Thu Apr 16, 2020 12:46 am
Forum: Beginner Basics
Topic: Multiple VLAN, multiple SSID and one trunk with CISCO
Replies: 17
Views: 2759

Re: Multiple VLAN, multiple SSID and one trunk with CISCO

Because there's no "user" for frames with other VIDs ... vlan interface explicitly filters when frame passes from tagged side to untagged. Ok, got it.. Do you have any reference for this for a more in depth look? No, I don't have any referece on that. It's based on 25 years (I'm not kidding) of exp...
by mkx
Thu Apr 16, 2020 12:08 am
Forum: General
Topic: ppp-out default route disappears 1 second after interface is enabled
Replies: 31
Views: 4178

Re: ppp-out default route disappears 1 second after interface is enabled

I thought i can get net without NAT ... When using PPP interface through LTE modem, it behaves as transparent as it gets ... the PPP connection runs directly between ROS and ISP's core network. So if you get NATed in this case, then it's not modem's doing, it is what ISP does. On the other hand, wh...
by mkx
Wed Apr 15, 2020 11:06 pm
Forum: Beginner Basics
Topic: Multiple VLAN, multiple SSID and one trunk with CISCO
Replies: 17
Views: 2759

Re: Multiple VLAN, multiple SSID and one trunk with CISCO

then frames tagged with other VIDs or untagged frames will be discarded by ROS kernel driver. However, since there is no ingress filtering, how would those frames be discarded? Because there's no "user" for frames with other VIDs ... vlan interface explicitly filters when frame passes from tagged s...
by mkx
Mon Apr 13, 2020 11:38 pm
Forum: General
Topic: HAP AC2 ipv6 Routes list show bridge unreachable
Replies: 5
Views: 1491

Re: HAP AC2 ipv6 Routes list show bridge unreachable

If prefix, received from ISP, is indeed /64 ... and one of addresses out of that prefix is immediately used for WAN IPv6 address on ether1, then you're out of luck. Check that scenario. Yes, some ISPs are that cheap to only assign /64 to a home user (it should be something larger, e.g. /60 or /56). ...
by mkx
Mon Apr 13, 2020 10:39 pm
Forum: General
Topic: Have DHCP for AP but not for physical ports
Replies: 11
Views: 1695

Re: Have DHCP for AP but not for physical ports

@sindy: wouldn't bridge filter help? Only allow DHCPDISCOVER frames from AP's port and not from the others? It was my first thought, but it only allows to block incoming DHCP traffic on some physical ports and permit it on others, while the OP seeks protection from requests coming through the same ...
by mkx
Mon Apr 13, 2020 10:36 pm
Forum: SwOS
Topic: SWOS MTU
Replies: 2
Views: 2803

Re: SWOS MTU

One thing is hardware support for jumbo frames when switching between ports. And that one is not configurable, it's simply enabled and at switch-chip maximum, meaning that whatever frame size (up to HW limit) received on one port will be transmitted on another port as well. So devices, connected to ...
by mkx
Mon Apr 13, 2020 10:22 pm
Forum: General
Topic: HAP AC2 ipv6 Routes list show bridge unreachable
Replies: 5
Views: 1491

Re: HAP AC2 ipv6 Routes list show bridge unreachable

What happens if you set it like this:

/ipv6 address=::1 add from-pool=rogers-ipv6 interface=bridge
... or something else instead of ::1?


In addition, how big is address prefix, received from ISP? (/ipv6 pool print)
by mkx
Mon Apr 13, 2020 10:16 pm
Forum: General
Topic: Have DHCP for AP but not for physical ports
Replies: 11
Views: 1695

Re: Have DHCP for AP but not for physical ports

@sindy: wouldn't bridge filter help? Only allow DHCPDISCOVER frames from AP's port and not from the others?

I've no personal experience with bridge filters so I might be totally on the wrong track here.
by mkx
Mon Apr 13, 2020 10:02 pm
Forum: Beginner Basics
Topic: DHCP Server with Switch Level VLAN
Replies: 6
Views: 1644

Re: DHCP Server with Switch Level VLAN

Switch chip port switch1-cpu is yet another port on the switch chip, incidentally connected to router's CPU. From switch chip point of view, the logic about configuring is is exactly the same as when configuring ether ports: do(es) device(s) connected to that port need to communicate with the rest ...
by mkx
Mon Apr 13, 2020 9:42 pm
Forum: Beginner Basics
Topic: Multiple VLAN, multiple SSID and one trunk with CISCO
Replies: 17
Views: 2759

Re: Multiple VLAN, multiple SSID and one trunk with CISCO

If there are VLANs 100, 200 and 300 in the trunk and router has to route between them, router needs IP addresses in all of them. IP addresses are bound to vlan interfaces. Now, if a single ether interface is in the game, do we need intermediate layer of a bridge? I don't think so, it is perfectly fi...
by mkx
Mon Apr 13, 2020 9:13 pm
Forum: Beginner Basics
Topic: Unable to Connect to Other Device within the same LAN
Replies: 10
Views: 2360

Re: Unable to Connect to Other Device within the same LAN

Make sure all of your devices actually support 5GHz Wlan ...
by mkx
Mon Apr 13, 2020 9:09 pm
Forum: Beginner Basics
Topic: Multiple VLAN, multiple SSID and one trunk with CISCO
Replies: 17
Views: 2759

Re: Multiple VLAN, multiple SSID and one trunk with CISCO

I'd recomend to use hEX only as a router If you had to create a trunk port between Cisco and Mikrotik, as the initial plan of the OP, would you go with Bridge VLAN Filtering or Switch VLAN filtering ? With routing-only tasks it doesn't really matter ... the dilemma is only real when there are multi...
by mkx
Mon Apr 13, 2020 8:57 pm
Forum: Beginner Basics
Topic: DHCP Server with Switch Level VLAN
Replies: 6
Views: 1644

Re: DHCP Server with Switch Level VLAN

Yes, you do still have to use /interface vlan ... /interface vlan is about how ROS (the software running on main CPU) can interact with the network ... and has (almost) nothing to do with the way you configure L2 on the device (either on HW directly or on bridge with vlan-filtering enabled). BTW, yo...
by mkx
Mon Apr 13, 2020 6:23 pm
Forum: General
Topic: No syslog on critical alerts
Replies: 14
Views: 2169

Re: No syslog on critical alerts

My wild guess is that this message is generated so early after the reboot that the network connectivity has not established yet by that time. And since Mikrotik only supports syslog via UDP, there is no second chance for the message. I think this thinking is correct. And it extends to logging to di...
by mkx
Mon Apr 13, 2020 6:14 pm
Forum: General
Topic: DHCP Leases - Comment
Replies: 3
Views: 1092

Re: DHCP Leases - Comment

1. They are stored in the router

2. Delete the lease from the router. After current lease expires (or rather when lease age raches half of expiry time), device will try to renew the address and DHCP server will deny that, at the same time it'll offer another one from normal address pool.
  • 1
  • 2
  • 3
  • 4
  • 5
  • 15