Community discussions

Search found 1338 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 27
by mkx
Tue Jan 22, 2019 3:03 pm
Forum: Wireless Networking
Topic: CAP ac
Replies: 4
Views: 172

Re: CAP ac

And why 2.4 GHz band goes down with this action?
If you do wireless scanning with some device (i.e. smart phone) while the problem occurs, do you actually see 2.4GHz signal disappear? Or is it just wifi client loosing connectivity for a few seconds (until it connects to 2.4GHz AP)?
by mkx
Tue Jan 22, 2019 2:55 pm
Forum: General
Topic: Sofware VLAN/Bridge on RuterOS explained.
Replies: 39
Views: 4778

Re: Sofware VLAN/Bridge on RuterOS explained.

How do people create pretty network diagrams? @Jotne uses Visio. Others use ASCII art (and lots of imagination) :wink: Questions: the cable between box-1 and box-2 would have vlan-less, untagged traffic for normal users, and vlan-50-tagged traffic for guest users? is possible to have box-1 do DHCP ...
by mkx
Tue Jan 22, 2019 2:45 pm
Forum: General
Topic: Mark the traffic for YouTube, Facebook, etc.
Replies: 22
Views: 1573

Re: Mark the traffic for YouTube, Facebook, etc.

{primevideo}
add chain=prerouting action=jump jump-target=moveTOstep 2 dst-port=443 in-interface-list=lan\
connection-mark=no-mark protocol=tcp tls-host=*.primevideo.com.com
Isn't this one dot-com (bubble) too many?

Or is primevideo.com (single .com) from completely unrelated can of worms?
by mkx
Tue Jan 22, 2019 2:32 pm
Forum: General
Topic: Disabling packages on CRS326
Replies: 3
Views: 88

Re: Disabling packages on CRS326

I guess you might want to have security, it offers the following functions: IPSEC, SSH, Secure WinBox ... possibly Webfig over https as well.

If you don't use those (personally I find ssh valuable), then you can omit security (and dhcp) as well.
by mkx
Tue Jan 22, 2019 2:26 pm
Forum: Beginner Basics
Topic: Invalid DHCP server
Replies: 6
Views: 172

Re: Invalid DHCP server

Inaccessibility of your RB right after you enable bridge is caused by FW rule /ip firewall filter add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN Because suddenly firewall sees incoming packets not from ether1 but from bridge1. The very same omissio...
by mkx
Tue Jan 22, 2019 12:17 pm
Forum: General
Topic: Disabling packages on CRS326
Replies: 3
Views: 88

Re: Disabling packages on CRS326

My guess is that for switch (plus management access over static IPv4 address), minimum list of packages is this: system security (requires dhcp as dependency because of IPsec, I hate it) Note that by default, ROS comes as a bundle of packages and you can only disable packages, you can not uninstall ...
by mkx
Tue Jan 22, 2019 12:01 pm
Forum: Wireless Networking
Topic: wAP LTE in Sweden
Replies: 3
Views: 115

Re: wAP LTE in Sweden

.... Anyways the net result is around 20Mbps throughput. I have also used directional 14dBi antennas .... 20 Mbit on LTE is a bit low. I would like to be able to push around 40 Mbit .... When talking about LTE speeds one has to keep a few things in mind: as @Petri already observed, carriers are of ...
by mkx
Tue Jan 22, 2019 11:05 am
Forum: RouterBOARD hardware
Topic: Mikrotik mUPS
Replies: 1
Views: 160

Re: Mikrotik mUPS

Specifications declare PoE in input Voltage range 12-28V ... so powering it with 48V is out of question. Chances are that it's actually a passive PoE unit meaning it's not 802.3af (standard PoE) compatible ...
by mkx
Tue Jan 22, 2019 9:24 am
Forum: RouterBOARD hardware
Topic: Strange POE information.
Replies: 1
Views: 99

Re: Strange POE information.

so, it cannot support 802.3at as min is 25.50 W for this standard. There's 802.3at Type 1 with maximum current of 350mA and there's 802.3at Type 2 "PoE+" with maximum current of 600mA. PSE conforming to the former is supposed to provide up to 15.40W (that's at 44V). My source of information might d...
by mkx
Tue Jan 22, 2019 8:53 am
Forum: Wireless Networking
Topic: CAP ac
Replies: 4
Views: 172

Re: CAP ac

Probably DFS ... detecting (spurious?) radars.
by mkx
Tue Jan 22, 2019 8:51 am
Forum: Wireless Networking
Topic: Mikrotik AP & Switch Question's
Replies: 1
Views: 69

Re: Mikrotik AP & Switch Question's

Question 1: can I feed the Ap's from any brand of switch Like a Cisco SG300 PoE Switch? Question 2: can I run switchOS and still run AP's off of it? Question 3: will this model run the AP's or cAP CRS-317-1G-16S+RM in switchOS mode? Question 4: if 1-3 are yes then can I run the AP's via the Cisco's...
by mkx
Tue Jan 22, 2019 8:39 am
Forum: Wireless Networking
Topic: android devices chooses 2.4Ghz over 5Ghz on hAP ac^2
Replies: 13
Views: 480

Re: android devices chooses 2.4Ghz over 5Ghz on hAP ac^2

It doesn't matter if you are in the same room. With equal distance and receiver the signal strength difference will be 6dB. Not entirely true, building materials generally attenuate higher frequencies much more than lower frequencies. So the rule of 6dB might be quite right for open space / single ...
by mkx
Tue Jan 22, 2019 8:24 am
Forum: Wireless Networking
Topic: How to for a guest network that can't access the internal network
Replies: 14
Views: 438

Re: How to for a guest network that can't access the internal network

Post complete configuration (in terminal windows execute /export hide-sensitive and copy-paste output in [ code] ... [ /code] environment).
by mkx
Tue Jan 22, 2019 8:14 am
Forum: Beginner Basics
Topic: DST NAT on 3 Mikrotiks
Replies: 2
Views: 107

Re: DST NAT on 3 Mikrotiks

Whether you have to create 3 DST-NAT rules or not largely depends on topology and configuration of your whole network. Ideally create a simple chart showing your different LAN segments and briefly describe what are your goals. It might turn out that your current setup is over complicated ...
by mkx
Tue Jan 22, 2019 8:09 am
Forum: Beginner Basics
Topic: Invalid DHCP server
Replies: 6
Views: 172

Re: Invalid DHCP server

It didn't occur to me that every interface need to have an ip address assigned. In my mind I only needed one to target the device (routeros) but the other one was just like a port on a switch, which don't usually have their own addresses. You need IP address on all interfaces which take part in L3 ...
by mkx
Mon Jan 21, 2019 10:46 pm
Forum: General
Topic: Drop forward rules NOT worked between devices connected via Wi-Fi
Replies: 4
Views: 151

Re: Drop forward rules NOT worked between devices connected via Wi-Fi

Hmm I thought version 6.43.8 got rid of slave and master interface configurations?? It did. But if some device started life pre-6.40 and received upgrades, then upgrade script didn't change names of interfaces. Only setting master-port=ether2-master on all slave ports was removed ... @Anastasia: ar...
by mkx
Mon Jan 21, 2019 10:36 pm
Forum: General
Topic: Mangle Dilemma: PassThrough Vs Jump
Replies: 3
Views: 136

Re: Mangle Dilemma: PassThrough Vs Jump

I'm sure that more knowledgeable people will pass by and share their wisdom. I'll just drop my 5 cents ... so you can decide not to agree with me by not picking those 5 cents :wink: Jump and passthrough are different stuff so it's not either-either. There are cases, where one has to perform a series...
by mkx
Mon Jan 21, 2019 8:33 pm
Forum: Beginner Basics
Topic: RB2011 slow internet even with fasttrack
Replies: 68
Views: 3747

Re: RB2011 slow internet even with fasttrack

In new time you simply add all 10 ports to the same bridge. Regardless, bridge will only see traffic sent towards it through switch1-cpu and switch2-cpu "interfaces" (those are actually old master-ports). The new bridge implementation doesn't mess with /interface ethernet switch settings unless you ...
by mkx
Mon Jan 21, 2019 8:04 pm
Forum: General
Topic: HW-offloaded VLANs with option vlan-mode=secure in switch1-cpu port (hAP ac)
Replies: 3
Views: 193

Re: HW-offloaded VLANs with option vlan-mode=secure in switch1-cpu port (hAP ac)

Your last configuration is against all good ROS practices ... to put it mildly :wink: Transfers between ports ether2 and ether5 (both are members of same untagged (V)LAN) won't be HW offloaded, and that's exactly why you're trying to configure stuff using /interface ethernet switch vlan and not /int...
by mkx
Mon Jan 21, 2019 3:49 pm
Forum: Beginner Basics
Topic: RB2011 slow internet even with fasttrack
Replies: 68
Views: 3747

Re: RB2011 slow internet even with fasttrack

Unrelated, but never the less: I glued to 6.40.9 because it is the latest version, which uses master/slave port config instead of Hw offloading. I'm using 6.44beta54 on my RB951G configured with traditional /interface ethernet setup, including VLANs in hardware ... and things work just fine. E.g. VL...
by mkx
Sun Jan 20, 2019 7:36 pm
Forum: RouterBOARD hardware
Topic: increase value sectors write since reboot in ROS 6.36.2
Replies: 5
Views: 909

Re: increase value sectors write since reboot in ROS 6.36.2

One setting that results in very different number of writes to nand, is
/tool graphing
set store-every=
Shortest is 5 min, longest is 24 hours. Difference in number of writes is 288-times.
by mkx
Sun Jan 20, 2019 7:29 pm
Forum: General
Topic: MIMO, chains
Replies: 3
Views: 175

Re: MIMO, chains

I was not aware MT equipment was MIMO cap able???? MIMO (Multiple Input Multiple Output) is standard term for the same thing as MT is doing using multiple chains. If MT device is declared to be 802.11n (or ac) capable and has 2 or more Tx/Rx chains, it's doing 2x2MIMO (or 4x4 in case of RB4011 on 5...
by mkx
Sun Jan 20, 2019 7:20 pm
Forum: Beginner Basics
Topic: Upgrade after a long time
Replies: 3
Views: 113

Re: Upgrade after a long time

I don't see any reason why upgrade should break things for you. Config is just the way it is supposed to be in most recent ROS versions.
by mkx
Sun Jan 20, 2019 7:14 pm
Forum: General
Topic: MIMO, chains
Replies: 3
Views: 175

Re: MIMO, chains

If you don't know better, use all available chains for both Tx and Rx and let HW and SW to make best out of it. There were some ROS versions with some problems regarding this setting. So upgrade to latest version of your liking (long term is 6.42.11, stable is 6.43.8 ) and enable everything in this ...
by mkx
Sun Jan 20, 2019 7:10 pm
Forum: General
Topic: Unable to reach a hand full of web sites...
Replies: 2
Views: 129

Re: Unable to reach a hand full of web sites...

Depending on ROS version and original FW config it is quite possible that your router got hacked. Export current config to text file (/export file=config.txt), save that file to your computer. Then netinstall the router (google for exact procedure) and start configuring it from default rules. Depend...
by mkx
Sun Jan 20, 2019 6:57 pm
Forum: Beginner Basics
Topic: Upgrade after a long time
Replies: 3
Views: 113

Re: Upgrade after a long time

The big difference between 6.40 and 6.43 is in the way how ethernet ports are handled. If you post here part of your running config (/interface export ... I don't think there are sensitive settings in this section) we can express our opinions about probability for things to break during upgrade...
by mkx
Sun Jan 20, 2019 6:03 pm
Forum: RouterBOARD hardware
Topic: Please recommend router as bridge for 3000 concurrent users [SOLVED]
Replies: 9
Views: 567

Re: Please recommend router as bridge for 3000 concurrent users [SOLVED]

Just a minor correction: If each user gets 1Mbps (1 million bits per second) and a typical packet is 1KB (1 thousand bits) then that is 1,000 packets a second. 1kB is 1000 bytes or 8000 bits. So 1Mbps using 1kB packets yields 125 pps (packets per second). Per user. I'd be interested to see some real...
by mkx
Sun Jan 20, 2019 1:42 pm
Forum: Wireless Networking
Topic: android devices chooses 2.4Ghz over 5Ghz on hAP ac^2
Replies: 13
Views: 480

Re: android devices chooses 2.4Ghz over 5Ghz on hAP ac^2

There are apps for android that, when installed on mobile, push device to 5GHz band even if signal strength is lower than on 2.4GHz. One example is Wifi 5 . Worked for me nicely on an old Galaxy S4, which highly preferred 2.4GHz WiFi if left alone. Some comments about the Wifi 5 program. 1. It's no...
by mkx
Sun Jan 20, 2019 11:57 am
Forum: Beginner Basics
Topic: Can ping router, but cannot ping or connect to WAN
Replies: 31
Views: 855

Re: Can ping router, but cannot ping or connect to WAN

Change interface carrying LAN address running command /ip address set [ find address="192.168.88.1/24" ] interface=bridge You may loose connection to RB after that ... hopefully only temporarily. Setting MTU of PPPoE interface is kind of black magic and I wouldn't be surprised if the same setting gi...
by mkx
Sun Jan 20, 2019 11:46 am
Forum: General
Topic: RB4011iGS+RM - optimal config?
Replies: 1
Views: 172

Re: RB4011iGS+RM - optimal config?

Re HW offload: one thing is setting (you get that with export command) while another thing is actual status (you get that with /interface bridge port print and actual HW ofload enabled is identified by 'H' displayed in flags column on the left). I somehow suspect that SFP+ interface won't show H the...
by mkx
Sun Jan 20, 2019 11:22 am
Forum: General
Topic: Which power for POE
Replies: 1
Views: 141

Re: Which power for POE

Depends on voltage requirements of both units. If both jnits accept it, go with higher voltage as it means lower current with lower loss on cables. Be sure to use power adapter with adequate current rating: add up rated power consumption of individual units and make sure power adapter rating is matc...
by mkx
Sun Jan 20, 2019 11:07 am
Forum: Beginner Basics
Topic: Can ping router, but cannot ping or connect to WAN
Replies: 31
Views: 855

Re: Can ping router, but cannot ping or connect to WAN

There are two things to change: Try to lower MTU on Unifi interface, 1492 might be too high. Start with something quite low (e.g. 1300) and if internet starts to work, gradually change it to higher values and see how high it can get. My PPPoE connection doesn't work with anything higher than 1480. p...
by mkx
Sun Jan 20, 2019 10:54 am
Forum: Beginner Basics
Topic: how to do Dynamic nat 100 private ip with /24 public ip
Replies: 10
Views: 363

Re: how to do Dynamic nat 100 private ip with /24 public ip

One of challenges is how to avoid entering 100 nat rules by hand.

The other could be (not expressed in OP) that public address pool might not be static (I don't know any reason for it but it's still possible).

We'll wait for @mukeshchaubey to describe use case.
by mkx
Sun Jan 20, 2019 10:49 am
Forum: Announcements
Topic: v6.42.11 [long-term] is released!
Replies: 41
Views: 4720

Re: v6.42.11 [long-term] is released!

@Normis wrote in another thread that partial dowloads get erased during reboot.
by mkx
Sat Jan 19, 2019 6:41 pm
Forum: Wireless Networking
Topic: How to access my nano bridge through mickrotik routerboard
Replies: 3
Views: 125

Re: How to access my nano bridge through mickrotik routerboard

If nano has, for example, IP address 12.23.34.45, then assign address 12.23.34.150/24 (and pray no other device nearby is using this address already) to ether1. To avoid possibility that you're creating address collision, at this point select another address from same subnet, ping it and if pings do...
by mkx
Sat Jan 19, 2019 6:32 pm
Forum: General
Topic: 2 WAN -> Unmanaged Switch -> MT Ether1
Replies: 2
Views: 126

Re: 2 WAN -> Unmanaged Switch -> MT Ether1

For starters, if your WAN peers don't do VLANs on access interfaces (they probably don't if things work if you don't mess with VLANs either), you can't make things work using unmanaged switch. You'll have to use managed, VLAN capable, switch. And second: you'll have to learn about VLANs, what they a...
by mkx
Sat Jan 19, 2019 6:24 pm
Forum: General
Topic: rb750Gr3 keeps rebooting
Replies: 14
Views: 474

Re: rb750Gr3 keeps rebooting

Under load?
by mkx
Sat Jan 19, 2019 6:18 pm
Forum: Beginner Basics
Topic: Can ping router, but cannot ping or connect to WAN
Replies: 31
Views: 855

Re: Can ping router, but cannot ping or connect to WAN

The export command is right, but vlan and pppoe config was not present. In order to have internet connectivity from your LAN you don't need any DST-NAT rules, only a single SRC-NAT. But let's continue narrowing down the issue: please run command /ping 8.8.8.8 count=4 If command will be successful, i...
by mkx
Sat Jan 19, 2019 6:05 pm
Forum: Wireless Networking
Topic: How to access my nano bridge through mickrotik routerboard
Replies: 3
Views: 125

Re: How to access my nano bridge through mickrotik routerboard

Assuming cable between the nano and your router is connected to port ether1 of your router (and hence pppoe client runs on ether1 as well), you can add IP address from nano's subnet to ether1. Then just check your firewall rules if communication with nano is allowed. You might find out that you can ...
by mkx
Sat Jan 19, 2019 3:58 pm
Forum: Wireless Networking
Topic: LTE modems - Compatibility list?
Replies: 4
Views: 213

Re: LTE modems - Compatibility list?

I guess many MNOs will upgrade as high as possible, many features are SW only. The main problem with reaching high Cat in tge network is lack of available spectrum ... not many MNOs can dedicate more than 50-60MHz of band width to LTE ... which translates to something about 600Mbps in DL. Anything m...
by mkx
Sat Jan 19, 2019 3:52 pm
Forum: Wireless Networking
Topic: Link stopped working after upgrade
Replies: 2
Views: 130

Re: Link stopped working after upgrade

Would be great if Mikrotik also could make their products more robust when it comes to the radar detection. One of the two can be robust: either WISP link can be robust (but radar detection will be sluggish which won't go nicely with authorities) or radar detection can be robust (but link will be f...
by mkx
Sat Jan 19, 2019 3:34 pm
Forum: Beginner Basics
Topic: Can ping router, but cannot ping or connect to WAN
Replies: 31
Views: 855

Re: Can ping router, but cannot ping or connect to WAN

You have to add PPPoE interface to WAN interface list and remove ether1 from it: /interface list member add list=WAN interface=Unifi remove [ find list=WAN interface=ether1 ] NAT is configueed to masquerade everything going out of interfaces members of lust WAN, but your current WAN interface is not...
by mkx
Sat Jan 19, 2019 3:23 pm
Forum: General
Topic: rb750Gr3 keeps rebooting
Replies: 14
Views: 474

Re: rb750Gr3 keeps rebooting

I checked power supply and it's fine.

How did you check the power supply?
by mkx
Sat Jan 19, 2019 2:28 pm
Forum: General
Topic: HW-offloaded VLANs with option vlan-mode=secure in switch1-cpu port (hAP ac)
Replies: 3
Views: 193

Re: HW-offloaded VLANs with option vlan-mode=secure in switch1-cpu port (hAP ac)

Don't use vlan 1 as tagged ... it doesn't work with switch chips ... and works with SW vlan-filtering because vlan-id=1 is synonim for untagged.
by mkx
Sat Jan 19, 2019 12:51 pm
Forum: Beginner Basics
Topic: Can ping router, but cannot ping or connect to WAN
Replies: 31
Views: 855

Re: Can ping router, but cannot ping or connect to WAN

Ok, post complete output of the following commands /interface print detail /ip address print # replace last two numbers of your public address with e.g. .a.b so that it'll look like 86.61.a.b /ip route print # again perform public address mangling, consistently with previous command Hopefully we'll ...
by mkx
Sat Jan 19, 2019 12:40 pm
Forum: Beginner Basics
Topic: switching wan interface on hap ac lite [SOLVED]
Replies: 4
Views: 165

Re: switching wan interface on hap ac lite [SOLVED]

You also have to reconfigure bridge ports ... you don't want WAN and LAN traffic mixed on same bridge. So remove ether5 ftom bridge (and add ether1 if you want to use it as LAN port).
by mkx
Sat Jan 19, 2019 12:37 pm
Forum: Beginner Basics
Topic: How to forward ports to multiple WAN interfaces?
Replies: 10
Views: 323

Re: How to forward ports to multiple WAN interfaces?

If one (temporarily :wink:) keeps in mind, that action=masquerade is a special variant of action=src-nat ... then becomes clear that without stating out-interface router will masquerade (src-nat) all passing traffic. Which is harmless only in single scenario that I can think of: single WAN, single L...
by mkx
Fri Jan 18, 2019 4:32 pm
Forum: General
Topic: Help with DNS, Allow Remote Requests and Firewall
Replies: 8
Views: 364

Re: Help with DNS, Allow Remote Requests and Firewall

I have a Mikrotik with RouterOS version 6.41.2. I'm with @anav: upgrade to 6.42.11 (latest long-term currently) or 6.43.8 (latest stable) "IP" -> "DNS" -> "STATIC" -> "ADD NEW"... Then in those fields I typed Name -> "server1.local" and Adress -> "192.168.1.100" Thats about right. Also, (I dont kno...
by mkx
Fri Jan 18, 2019 4:18 pm
Forum: Beginner Basics
Topic: port forwarding
Replies: 2
Views: 103

Re: port forwarding

@anav is right: your WAN interface is (by the looks of it) RDS and should be used in dst-nat rules instead of ether1. Which is, most probably, only carrying PPPoE frames and bears no L3 (IP) configuration.
by mkx
Fri Jan 18, 2019 4:13 pm
Forum: Beginner Basics
Topic: How to forward ports to multiple WAN interfaces?
Replies: 10
Views: 323

Re: How to forward ports to multiple WAN interfaces?

@anav, you're close. But RB administrator has to keep in mind that there are a few processes running inside RB and those are pretty separate (don't interfere with each other). Connection tracking is a function of firewall (it helps to determine if a packet should pass FW or not). FW itself does not ...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 27