Community discussions

MikroTik App

Search found 4774 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 16
by mkx
Tue Oct 27, 2020 9:56 am
Forum: General
Topic: GRE Tunnel with Hap ac3 LTE
Replies: 11
Views: 301

Re: GRE Tunnel with Hap ac3 LTE

I've seen mobile operators assigning public IPs to LTE devices but NATing them to other public IPs anyway.
And I've seen mobile operators assigning public IP addresses to LTE devices and not doing any NAT, but still running firewall and DPI systems on behalf of their users.
by mkx
Tue Oct 27, 2020 9:21 am
Forum: RouterBOARD hardware
Topic: RB912 health is abnormal !!
Replies: 4
Views: 198

Re: RB912 health is abnormal !!

I've no idea what your RB912 is really getting. Some decent multimeter should tell.
Also inspect the power source, whatever it is ... is it some PoE switch, is it PoE injector with some "weird" power adapter?
by mkx
Tue Oct 27, 2020 9:08 am
Forum: General
Topic: WLAN / Bridge / Vlan filtering / ARP issue
Replies: 7
Views: 220

Re: WLAN / Bridge / Vlan filtering / ARP issue

Seems like @OP did not hear ya as well ... so I had to repeat it, perhaps @OP will go read the article and hopefully start over again. This time properly.
by mkx
Tue Oct 27, 2020 12:18 am
Forum: General
Topic: WLAN / Bridge / Vlan filtering / ARP issue
Replies: 7
Views: 220

Re: WLAN / Bridge / Vlan filtering / ARP issue

@yoanm: VLANs in your config are not the way VLANs should be done in post 6.42-days. Have a look at this tutorial: https://forum.mikrotik.com/viewtopic.php?t=143620 RB750r2 has a switch chip built in and if device was switching traffic between ethernet interfaces it woukd benefit from configuring VL...
by mkx
Tue Oct 27, 2020 12:13 am
Forum: Beginner Basics
Topic: vlan on switch [SOLVED]
Replies: 3
Views: 133

Re: vlan on switch [SOLVED]

A good tutorial about VLANs in RouterOS: https://forum.mikrotik.com/viewtopic.php?t=143620 Depending on switch type the resulting configuration might not be wirespeed, but it should get you moving. After you get acquainted to VLANs, you can reconfigure switch for higher performance (VLAN switching i...
by mkx
Tue Oct 27, 2020 12:01 am
Forum: RouterBOARD hardware
Topic: RB912 health is abnormal !!
Replies: 4
Views: 198

Re: RB912 health is abnormal !!

Verify power supply voltage, unit is rated up to 30V and what you see is somewhat out of spec. Such supply voltage (if not killing your device) might explain high temperature as it keeps voltage regulators at their limit.
by mkx
Mon Oct 26, 2020 8:56 pm
Forum: RouterBOARD hardware
Topic: RB951G-2HND - improve wifi range.
Replies: 2
Views: 207

Re: RB951G-2HND - improve wifi range.

This unit has more or less omnidirectional antennae, do turning it around won't make any noticeable difference. Range of 40 metres is pretty much what can be expected (or even more than expected, most products declare 30m range in open area). High interference from 200 APs you can detect make things...
by mkx
Mon Oct 26, 2020 8:26 pm
Forum: Beginner Basics
Topic: Schedule Question [SOLVED]
Replies: 4
Views: 206

Re: Schedule Question [SOLVED]

Another idea: if that port doesn't need any communication (not even other LAN hosts, such as NAS or DLNA server or printer or ...), then you can simply disable the ssid port. That'll break any ongoing connection as well. Brutally too.
by mkx
Mon Oct 26, 2020 8:21 pm
Forum: Beginner Basics
Topic: Forward/NAT DNS packages
Replies: 1
Views: 159

Re: Forward/NAT DNS packages

NAT on "different site" should do DST-NAT which you probably configured ... but it should do SRC-NAT as well. If SRC-NAT is not done, then replies from DNS server go back to your site directky, but there they're eitger filtered by ISP, or more likely by your MT as they return from unexpected remote ...
by mkx
Mon Oct 26, 2020 1:34 pm
Forum: General
Topic: strange missing 1s every 3s after upgrade to 6.47.6 [SOLVED]
Replies: 6
Views: 275

Re: strange missing 1s every 3s after upgrade to 6.47.6 [SOLVED]

only this one? Did this actually start with upgrade? Or was it present with previous ROS versions (but you did not notice it)? Obvious reason for that happening is CPU frequency way off what router thinks it should be (e.g. 20% slower than it should be). I'm not entirely sure how CPU frequency gets...
by mkx
Mon Oct 26, 2020 12:28 pm
Forum: Beginner Basics
Topic: Complete reset on CRS125-24G-1S-RM
Replies: 2
Views: 102

Re: Complete reset on CRS125-24G-1S-RM

When connecting to CRS (or any ROS device) after factory reset, device expects management connection through first copper interface (ether1). After initial setup is done, management connection is usually possible on all other interfaces except for ether1. Not sure how this correlates with what you s...
by mkx
Mon Oct 26, 2020 12:21 pm
Forum: General
Topic: strange missing 1s every 3s after upgrade to 6.47.6 [SOLVED]
Replies: 6
Views: 275

Re: strange missing 1s every 3s after upgrade to 6.47.6 [SOLVED]

When you were upgrading ROS, did you upgrade routerboot as well? Sometimes there are (tiny) discrepancies between (old) routerboot and modern ROS which are only resolved by upgrading routerboot to modern version (shipped with ROS itself), which has to be followed by reboot of device (sorry for that)...
by mkx
Sun Oct 25, 2020 7:51 pm
Forum: General
Topic: VLAN switch and bridge combination - advice please [SOLVED]
Replies: 16
Views: 539

Re: VLAN switch and bridge combination - adwise please [SOLVED]

I was under the impression that off-loading to switch chip was the preferred way, especially on CRS series... Is that wrong understanding? (otherwise I do not see the point of having that feature at all) So given that question, is using the bridge vlan the right way to go, or should I try to achiev...
by mkx
Sun Oct 25, 2020 5:57 pm
Forum: Beginner Basics
Topic: firewall filter with internet allow unauthorized LAN trafic
Replies: 11
Views: 465

Re: firewall filter with internet allow unauthorized LAN trafic

in future , i will use this order /ip firewall filter add action=accept chain=input comment="protection" connection-state=established,related add action=drop chain=input comment="protection" connection-state=invalid add action=accept chain=input comment="protection" in-interface=bridge-trunk src-ad...
by mkx
Sun Oct 25, 2020 1:07 pm
Forum: General
Topic: Two wan with in the same subnet
Replies: 19
Views: 656

Re: Two wan with in the same subnet

@Sob and @sindy, thanks for clarifying thing for me. I'm just mad at @anav since he knew the answer already but he kept silent forcing you two guys to answer me ;-) Makes total sense to me: ARP could well be handled by interface driver itself with little help from IP (or any other L3) stack. Indeed ...
by mkx
Sun Oct 25, 2020 12:48 pm
Forum: Beginner Basics
Topic: 750G download speed very slow
Replies: 17
Views: 482

Re: 750G download speed very slow

This is not default setup, it seems that it was transferred over from old config. You have to reset it to factory default. Log in via WebFix (using web browser), click "Quick Set" button top right, then click "Reset configuration" in lower right area. Reboot device (if it doesn't do it itself). Then...
by mkx
Sun Oct 25, 2020 12:44 am
Forum: General
Topic: VLAN switch and bridge combination - advice please [SOLVED]
Replies: 16
Views: 539

Re: VLAN switch and bridge combination - adwise please [SOLVED]

I'd say you have naming clash: on CRS in capsman configuration you set datapath.bridge=bridge while bridge on RB952 is named bridge1 ... and with local forwarding enabled datapath.bridge refers to bridge on CAP device, not on capsman device.
by mkx
Sun Oct 25, 2020 12:26 am
Forum: General
Topic: Two wan with in the same subnet
Replies: 19
Views: 656

Re: Two wan with in the same subnet

Instead, trust the machine: [me@myTik] > ip arp print where address in 192.168.6.0/24 Flags: X - disabled, I - invalid, H - DHCP, D - dynamic, P - published, C - complete # ADDRESS MAC-ADDRESS INTERFACE 0 C 192.168.6.6 48:8F:5A:BC:14:20 bridge.lte.6 1 DC 192.168.6.1 48:8F:5A:BC:14:20 bridge.lte.6 I...
by mkx
Sat Oct 24, 2020 8:50 pm
Forum: General
Topic: Two wan with in the same subnet
Replies: 19
Views: 656

Re: Two wan with in the same subnet

And when Mikrotik wants to send the packet, it uses IP address and interface as search criteria in the query to the ARP table ... I'll have to trust you on that. When looking at diagrams on packet flow manual page I can't find the box which includes reference to in-interface for outgoing packet (AR...
by mkx
Sat Oct 24, 2020 4:43 pm
Forum: General
Topic: Two wan with in the same subnet
Replies: 19
Views: 656

Re: Two wan with in the same subnet

Once I'll learn Spanish
Sometimes it hits me that @anav must be a Vogon. ;-)
by mkx
Sat Oct 24, 2020 4:42 pm
Forum: General
Topic: Two wan with in the same subnet
Replies: 19
Views: 656

Re: Two wan with in the same subnet

@sindy, just a short question (or rather request for clarification): how does MT in conjunction with router B handle this situation? Let's say routerB's own ARP cache for 192.168.1.210 expires but needs its MAC address to deliver some packet in downstream. It will send ARP request, and part of ARP r...
by mkx
Sat Oct 24, 2020 4:19 pm
Forum: Beginner Basics
Topic: public nat ip problem
Replies: 4
Views: 187

Re: public nat ip problem

/export hide-sensitive file=anynameyouwish

I was saving heavy guns for next step ... right now I assume OP has some too broad src-nat rule in action.
by mkx
Sat Oct 24, 2020 4:16 pm
Forum: General
Topic: Two wan with in the same subnet
Replies: 19
Views: 656

Re: Two wan with in the same subnet

I have to ask, what is the purpose of two modems from the same ISP?
OP clearly stated it's two ISPs but both are handing out addresses from same (private) IP subnet.
by mkx
Sat Oct 24, 2020 4:07 pm
Forum: General
Topic: Wildcard DNS
Replies: 15
Views: 734

Re: Wildcard DNS

Not sure what you're doing, so let's stick to MT cloud and some third party DNS with CNAME. So when you have ddns-enabled=yes , then your router will update corresponding DNS entry (xxxxxxxx.sn.mynetname.net) automatically. And that A record comes with TTL of 60 seconds. If some caching DNS server r...
by mkx
Sat Oct 24, 2020 3:34 pm
Forum: General
Topic: Wildcard DNS
Replies: 15
Views: 734

Re: Wildcard DNS

Interesting, I have a dynu hostname and c-name it to the cloud name of mikrotik. Are you saying that the IP of dynu will not be updated Actually client asks a series of questions to get to final answer. First question will resolve CNAME to cloudname, independent query will resolve cloudname to IP. ...
by mkx
Sat Oct 24, 2020 3:21 pm
Forum: General
Topic: Wildcard DNS
Replies: 15
Views: 734

Re: Wildcard DNS

For using * or CNAME records on a domain there often is a conflict because there also need to be NS records not matched by those wildcards/CNAMEs and that makes most convenient usages impossible. Most of time no extra NS records are needed. NS recorss are needed if authoritative DNS server delegate...
by mkx
Sat Oct 24, 2020 3:00 pm
Forum: Beginner Basics
Topic: public nat ip problem
Replies: 4
Views: 187

Re: public nat ip problem

Post all NAT rules - execute /ip firewall nat export and copy-paste the output here (inside [code] [/code] block).
by mkx
Sat Oct 24, 2020 12:39 pm
Forum: Beginner Basics
Topic: How do you configuree the cloud router switch so you can access to its configuration from the LAN ? [SOLVED]
Replies: 4
Views: 236

Re: How do you configuree the cloud router switch so you can access to its configuration from the LAN ? [SOLVED]

can it be the bridge port ? Or should I take one from the switch? I'm not sure what kind of scenario you have in your mind. But anyway, if you're thinking about management VLAN, then configuring switch to use that VLAN for management is separate isssue from configuring all LAN gear for you to be ab...
by mkx
Fri Oct 23, 2020 10:25 pm
Forum: Beginner Basics
Topic: InterVLAN Routing
Replies: 10
Views: 447

Re: InterVLAN Routing

Sure. Whatever fits you. Just remember: WAN is no different than any of LANs when it comes to switching, the only entity making it fundamentally different is firewall. Nope, not even routing is that different, default is only English word for 0.0.0.0/0 which is a really large L AN with really short ...
by mkx
Fri Oct 23, 2020 10:06 pm
Forum: Beginner Basics
Topic: 750G download speed very slow
Replies: 17
Views: 482

Re: 750G download speed very slow

When upgrade already how to configure the firewall for more protecting for LAN and router. As I already wrote: default config which comes with recent versions of ROS, is decent config. Just be sure that "Keep old configuration" is not checked . As result, your device will be as if it came out of fa...
by mkx
Fri Oct 23, 2020 10:01 pm
Forum: Beginner Basics
Topic: InterVLAN Routing
Replies: 10
Views: 447

Re: InterVLAN Routing

Okay so what you are saying in plain english is that there may be cases where you want to route the ISP traffic coming from their ONT/MODEM to several ROS routers.

Not route, switch. Inside a VLAN.
by mkx
Fri Oct 23, 2020 9:58 pm
Forum: General
Topic: VLAN switch and bridge combination - advice please [SOLVED]
Replies: 16
Views: 539

Re: VLAN switch and bridge combination - adwise please [SOLVED]

Everything correct above if you replace "GRE" by "EoIP".

Thanks for correcting me.
by mkx
Fri Oct 23, 2020 9:56 pm
Forum: General
Topic: What does the advantage put the router before firewall and internet?
Replies: 7
Views: 307

Re: What does the advantage put the router before firewall and internet?

How can you prove we are not in a simulation???

But I know we are in a simulation, there's serious literature prooving it. Vogons are about to start building that hyperspace bypass ...
by mkx
Fri Oct 23, 2020 9:45 pm
Forum: General
Topic: VLAN switch and bridge combination - advice please [SOLVED]
Replies: 16
Views: 539

Re: VLAN switch and bridge combination - adwise please [SOLVED]

Questions: 1) What is your recommendation for overall setup, given the target scenario? 2) Is it possible to combine VLAN methods (switch/bridge) on one device (e.g. physical ports VLANs via switch chip and bonds/caps via bridge VLAN), or do I have to choose one and stick with it? (my undestanding ...
by mkx
Fri Oct 23, 2020 9:25 pm
Forum: General
Topic: What does the advantage put the router before firewall and internet?
Replies: 7
Views: 307

Re: What does the advantage put the router before firewall and internet?

Just imagine if your ISP gets hacked ....
For that matter, internet got hacked when DARPA let in businesses back in early 1990's.
by mkx
Fri Oct 23, 2020 9:18 pm
Forum: General
Topic: Wildcard DNS
Replies: 15
Views: 734

Re: Wildcard DNS

Forget about it and move on, no point in bitching around. Little optimism please ... I didn't say that nobody should make a feature request (not that such request would get my ++ anyway), I just wrote that currently DNS server in ROS is pretty much useless and looking for ways around is futile. One...
by mkx
Fri Oct 23, 2020 9:10 pm
Forum: General
Topic: netmetal ac2 crash with sfp
Replies: 2
Views: 160

Re: netmetal ac2 crash with sfp

SFP can draw quite some power. Depending on length and quality of UTP cable between power injector and netmetal it could mean that netmetal draws power high enough to drop voltage below minimum accepted. If you're using supplied power adapter (48V 0.95A), then this shouldn't really happen, but who k...
by mkx
Fri Oct 23, 2020 9:05 pm
Forum: General
Topic: No NTP sync on PTP devices
Replies: 7
Views: 357

Re: No NTP sync on PTP devices

If RB960 can communicate with netmetals (or you can communicate with them via RB960), then you can set up NTP server on RB960 (install ntp-X.XX.X-mipsbe.npk from Extra packages, available from downloads.mikrotik.com ... just be sure npk version matches ROS version installed on RB960) and then config...
by mkx
Fri Oct 23, 2020 8:56 pm
Forum: Beginner Basics
Topic: 750G download speed very slow
Replies: 17
Views: 482

Re: 750G download speed very slow

Setup is dangerous because firewall is virtually non-existant, not protecting neither router itself nor LAN. Setup is dangerous because router is running ancient version of ROS (5.4). Setup is slow because it's got queues set up which are CPU intensive and your device is no speed monster. My suggest...
by mkx
Fri Oct 23, 2020 8:37 pm
Forum: Beginner Basics
Topic: how to limit my web-proxy for only internet use
Replies: 1
Views: 95

Re: how to limit my web-proxy for only internet use

You should construct rules, similar to firewall rules, in /ip proxy access . Instructions are here . I don't have any experience with proxy, but from documentation I presume you should set something like this: /ip proxy access add action=allow src-address=<LAN v4 address>/<mask> #add action=allow sr...
by mkx
Fri Oct 23, 2020 8:29 pm
Forum: Beginner Basics
Topic: InterVLAN Routing
Replies: 10
Views: 447

Re: InterVLAN Routing

For a standard setup, there is no requirement to identify the WAN with a VLAN. For a stadard setup, there's no requirement for any VLAN whatsoever. However, if one configures router in ROS (Router On a Stick) manner, it is vital to get WAN to router tagged. Why would one want to do it? Well, in my ...
by mkx
Fri Oct 23, 2020 9:30 am
Forum: Beginner Basics
Topic: How do you configuree the cloud router switch so you can access to its configuration from the LAN ? [SOLVED]
Replies: 4
Views: 236

Re: How do you configuree the cloud router switch so you can access to its configuration from the LAN ? [SOLVED]

If you're going to use CRS as normal switch (and will be running ROS as opposed to SwOS, some units are capable of running both), then you have two options: if you trust your LAN devices and users (sometimes that trust is not warranted), then you can configure all ports on CRS to single bridge. Then...
by mkx
Fri Oct 23, 2020 8:56 am
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 282
Views: 71362

Re: v7.1beta2 [development] is released!

Can we expect the next beta version today as it is a Friday and over 2 months since the last beta release?
We've got 6.47.6 yesterday. And it wasn't even Friday. I think that's enough for this weekend ;-)
by mkx
Fri Oct 23, 2020 8:54 am
Forum: Announcements
Topic: v6.47.6 [stable] is released!
Replies: 31
Views: 5287

Re: v6.47.6 [stable] is released!

Is this an error message or an critical message.
It's a critical error ;-) With value 2 (2 and 3 binary and-ed together).
by mkx
Fri Oct 23, 2020 12:24 am
Forum: General
Topic: No NTP sync on PTP devices
Replies: 7
Views: 357

Re: No NTP sync on PTP devices

It is enough to allow protocol=udp dst-port=123 (and the default accept established,related ). Entering pool.ntp.org may or may not be fine, because firewall will resolve name to IP address(es) at some moment in time, possibly taking only single IP address. Ntp client will possibly resolve that to o...
by mkx
Fri Oct 23, 2020 12:09 am
Forum: Beginner Basics
Topic: IPIP Routing
Replies: 7
Views: 232

Re: IPIP Routing

Router 1: (192.168.1.1) 0.0.0.0/0 192.168.2.1 10.0.1.0/24 192.168.2.6 Router 2: (10.0.1.150) 0.0.0.0/0 10.0.1.151 192.168.1.0/24 10.0.1.151 Router 3: (10.0.1.151) 0.0.0.0/0 196.xxx.xxx.xxx (IP Gateway Internet) 192.168.1.0/24 192.168.2.6 On router3 the route towards 192.168.1.0/24 is set on direct ...
by mkx
Thu Oct 22, 2020 9:47 pm
Forum: General
Topic: Wildcard DNS
Replies: 15
Views: 734

Re: Wildcard DNS

There are numerous cases showing that DNS server, built into ROS, is severely limited. It is not a replacement for proper DNS server if anything but limited number of plain simple records are in the play. In case of wildcard entries ... well, it doesn't work on ROS. Fullstop. Forget about it and mov...
by mkx
Thu Oct 22, 2020 9:33 pm
Forum: Beginner Basics
Topic: IPIP Routing
Replies: 7
Views: 232

Re: IPIP Routing

Right. And now the big question: how are routes set on all 3 routers?
by mkx
Thu Oct 22, 2020 6:34 pm
Forum: Beginner Basics
Topic: IPIP Routing
Replies: 7
Views: 232

Re: IPIP Routing

It's all about properly set routes. Your topology sketch misses quite some information, complete IP address data for starters (e.g. each link, either physical or IPIP, has two addresses, one on each end) and without it it's hard to guess what routes have to be set.
by mkx
Thu Oct 22, 2020 6:25 pm
Forum: RouterOS v7 BETA
Topic: CRS3xx L3HW offloading MTU problem
Replies: 13
Views: 1029

Re: CRS3xx L3HW offloading MTU problem

From another topic: viewtopic.php?f=1&t=167507

It seems that usual hardware has problems creating enough PPS to fill the link.
by mkx
Thu Oct 22, 2020 9:51 am
Forum: General
Topic: No NTP sync on PTP devices
Replies: 7
Views: 357

Re: No NTP sync on PTP devices

Nothing much to be done on PtP nodes, NTP needs IP connectivity with server ... But there are two possibilities: set up a NTP server, which can synchronize to precision time sources (either a high quality source, such as GPS receiver, or to internet NTP servers), and serves clients inside management...
by mkx
Tue Oct 20, 2020 10:59 pm
Forum: Beginner Basics
Topic: How to access other network device through Mikrotik [SOLVED]
Replies: 7
Views: 347

Re: How to access other network device through Mikrotik [SOLVED]

Let's assume you have radio connected to ether1, which is also parent device of pppoe-client. For running pppoe-client ether1 doesn't need any IP address, but for connecting to radio it does. And let's assume router setup is pretty much default, which uses interface lists in firewall and NAT rules. ...
by mkx
Tue Oct 20, 2020 7:01 pm
Forum: Beginner Basics
Topic: Blocked SMPT port 25
Replies: 12
Views: 443

Re: Blocked SMPT port 25

I'm with @anav: firewall is bloated. You should simplify it. If you insist on current settings, then become a network expert who knows what the goal of this firewall. Default on SOHO devices (I'm not sure if your device falls into this category) is pretty sane and one of first rules in chain=forward...
by mkx
Mon Oct 19, 2020 9:18 pm
Forum: Beginner Basics
Topic: Pi-Hole and Mikrotik - DNS - Pi-hole only show my router’s IP address
Replies: 12
Views: 508

Re: Pi-Hole and Mikrotik - DNS - Pi-hole only show my router’s IP address

If we put in hard entries such as 1.1.1.1 and 1.0.0.01 and then as last entry the lan subnetgateway as an entry, then the router will only use entered IP DNS settings (lets say we had 8.8.8.8 in there) and its cache, if the hard entries are not providing DNS returns?? (put in another way, is order ...
by mkx
Mon Oct 19, 2020 7:57 pm
Forum: General
Topic: Mikrotik block access to Microsoft Outlook 365 account
Replies: 8
Views: 404

Re: Mikrotik block access to Microsoft Outlook 365 account

That's almost craziest firewall filter ruleset I've seen so far. And without any effect for that matter. Anyway, if you want RB to act as ethernet switch, start off from an empty config, create a bridge and add all ethernet ports to it. No other bridge settings, no IP address, nothing. At this point...
by mkx
Mon Oct 19, 2020 7:43 pm
Forum: General
Topic: IPv6 DualStack over PPPoE
Replies: 1
Views: 114

Re: IPv6 DualStack over PPPoE

Try to run DHCPv6 client on PPPoE interface and request a prefix: /ipv6 dhcp-client add add-default-route=yes interface=pppoe-out1 pool-name=ipv6 request=prefix The pppoe interface will get a LL address which is enough for routing traffic. You can assign some global address to your LAN interface: /i...
by mkx
Mon Oct 19, 2020 3:43 pm
Forum: Beginner Basics
Topic: DHCP on physical interface comes out invalid using Wizard
Replies: 6
Views: 227

Re: DHCP on physical interface comes out invalid using Wizard

DHCP server can definitely run off a physical interface. It can run off a VLAN interface and probably some other types as well.
by mkx
Mon Oct 19, 2020 11:20 am
Forum: General
Topic: VLAN DHCP on MAIN router not working to WLAN on AP [SOLVED]
Replies: 13
Views: 482

Re: VLAN DHCP on MAIN router not working to WLAN on AP [SOLVED]

Since you didn't post full configuration, only a few screenshots, we can only guess. You can post full config: execute /export hide-sensitive from terminal window and copy-paste the output.

Other than that: I guess vlan20 interface should not be member of bridge bridge-Staff.
by mkx
Mon Oct 19, 2020 9:57 am
Forum: Wireless Networking
Topic: CAPsMAN DHCP for virtual AP's
Replies: 4
Views: 220

Re: CAPsMAN DHCP for virtual AP's

There are numerous definitions of MAC addresses and radio names in your config ... I don't think that's necessary in your case (with single CAP device). It may be necessary if there are multiple CAPs in play and some (or all) of them should get specific settings (which is done in /caps-man provision...
by mkx
Mon Oct 19, 2020 9:38 am
Forum: General
Topic: Router OS v6.45.7 Routing Question
Replies: 2
Views: 126

Re: Router OS v6.45.7 Routing Question

Are subnet masks set correctly on the VMs as well? What does /192 written as suffix of IP addresses on the topology chart? According to mikrotik route printout, you should be using /26 netmask everywhere. If it is left to default (/8 is default for 10.x.y.z addresses), then devices will try to bypas...
by mkx
Mon Oct 19, 2020 9:16 am
Forum: Beginner Basics
Topic: Each port of mikrotik is separate from others
Replies: 7
Views: 310

Re: Each port of mikrotik is separate from others

Default setting on SOHO Mikrotiks is to have ether2-etherX (where X is the last ether port, mostly that's ether5) in a bridge which means these ports act as being part of a switch. If you want to assign individual IP addresses to each of ports, then you have to remove ports from the bridge. Doing it...
by mkx
Mon Oct 19, 2020 9:09 am
Forum: Beginner Basics
Topic: DHCP on physical interface comes out invalid using Wizard
Replies: 6
Views: 227

Re: DHCP on physical interface comes out invalid using Wizard

I can't see anything wrong in your config. Except for netmask=xx attribute of /ip dhcp-server network , default value is empty (set to 0) and instructs ROS to take netmask from address. I'd go for a good power-cycle of the unit. If it doesn't get any better, then export configuration, do a factory r...
by mkx
Sun Oct 18, 2020 11:35 pm
Forum: Wireless Networking
Topic: CAPsMAN DHCP for virtual AP's
Replies: 4
Views: 220

Re: CAPsMAN DHCP for virtual AP's

You have a few problems in config. You showed config from CAPsMAN device, I can only guess if prerequisite config from CAP device matches. One is this: /caps-man datapath add arp=enabled bridge=bridge_guest client-to-client-forwarding=yes \ local-forwarding=yes name=datapath_guest Does bridge_guest ...
by mkx
Sun Oct 18, 2020 10:10 pm
Forum: Beginner Basics
Topic: DHCP on physical interface comes out invalid using Wizard
Replies: 6
Views: 227

Re: DHCP on physical interface comes out invalid using Wizard

Post configuration as output running /export hide-sensitive from command line. It's hard to guess what's exact running config you've got.
by mkx
Sun Oct 18, 2020 8:10 pm
Forum: Beginner Basics
Topic: Building LAN from scratch: 4 mikrotiks - 4 networks
Replies: 15
Views: 447

Re: Building LAN from scratch: 4 mikrotiks - 4 networks

Where did you see VLANs in original post? Ah, I forgot about MTUNA certificate :lol: But you're right ... @digger, please describe the network layout you'd like to have and we may be able to give you some good advice. Surely what you sketched can fly with some static routes on each of involved route...
by mkx
Sun Oct 18, 2020 7:30 pm
Forum: Beginner Basics
Topic: Building LAN from scratch: 4 mikrotiks - 4 networks
Replies: 15
Views: 447

Re: Building LAN from scratch: 4 mikrotiks - 4 networks

I'm not sure if Mikrotik supports /31 but I thought I'd mention it. It doesn't. You need to use pair of /32 addresses with network specified as the "opposite" one. And it works like a charm. The best thing about using /32 addressing: if a router has multiple such links, it doesn't have to have diff...
by mkx
Sun Oct 18, 2020 4:09 pm
Forum: Beginner Basics
Topic: Building LAN from scratch: 4 mikrotiks - 4 networks
Replies: 15
Views: 447

Re: Building LAN from scratch: 4 mikrotiks - 4 networks

Sure. But then it makes perfect sense to sell/return 2 of the 3 hEXes and buy 3 managed switches instead (or even one managed and two unmanaged will do), and use hEX for routing only. Sure. I'd go for managed switches, that way topology can be changed from star-like (as OP currently plans it) to an...
by mkx
Sun Oct 18, 2020 3:30 pm
Forum: Beginner Basics
Topic: Building LAN from scratch: 4 mikrotiks - 4 networks
Replies: 15
Views: 447

Re: Building LAN from scratch: 4 mikrotiks - 4 networks

RB760iGS won't be good as switches in vlan setup - they lack hardware vlan support, so there will be no benefit in performance compared to routed network. Performance-wise you're right. Configuration-wise, VLANs and centralized routing config is much simpler than distributed routing. Plus it would ...
by mkx
Sun Oct 18, 2020 3:16 pm
Forum: Beginner Basics
Topic: Cannot understand my link speed. Is it 10Mbps or 100Mbps?
Replies: 2
Views: 209

Re: Cannot understand my link speed. Is it 10Mbps or 100Mbps?

Auto Negotiation: done Rate: 10Mbps Full Duplex: [unchecked] This is information about interface status at some certain moment . If there are glitches on the cable connection, then both ends will do renegotiation at every glitch ... and possibly in between (to upgrade settings if everything is fine...
by mkx
Thu Oct 15, 2020 8:42 pm
Forum: General
Topic: HAP AC Wired and Wireless VLAN CPU optimisation
Replies: 8
Views: 353

Re: HAP AC Wired and Wireless VLAN CPU optimisation

On theory gAP ac has better wlan (3 chains for each band) than hAP ac2 (2 chains for each band). OTOH hAP ac2 has much better CPU. Which means that if you get a hAP ac2 you should use it as router and existing hAP ac as wireless AP, not the other way around. Re. HW offloaded VLANs: @sindy explained ...
by mkx
Thu Oct 15, 2020 1:56 pm
Forum: Beginner Basics
Topic: Redirect specific domains to specific interface
Replies: 3
Views: 171

Re: Redirect specific domains to specific interface

If you have more than one WAN address, then this should be done by configuring DNS records for your domain to use different WAN IP addresses for different (for internet users virtual) hosts. Router, as device accepting connections initiated by internet clients, can not do anything to redirect them, ...
by mkx
Thu Oct 15, 2020 1:37 pm
Forum: Beginner Basics
Topic: Ilo4 Access over Internet trough Mikrotik Router Firewall
Replies: 5
Views: 359

Re: Ilo4 Access over Internet trough Mikrotik Router Firewall

iLO works over http/https, so you need to forward appropriate ports. Beware that there might be some parts inside iLO which might omit returning the port part of URL when constructing a follow URL so if you're going to forward non-standard port (e.g. port 12345 on WAN side to port 443 on iLO IP addr...
by mkx
Wed Oct 14, 2020 6:27 pm
Forum: Beginner Basics
Topic: Home User RouterOS Consultancy - Uber for MikroTik
Replies: 10
Views: 562

Re: Home User RouterOS Consultancy - Uber for MikroTik

(at least I didn't get paid yet)
I almost got paid once ... a spanish guy was so thankfull for my advice he wanted to pay me. He was mentioning paypal which I don't use, so instead he made a donation to MSF.
by mkx
Wed Oct 14, 2020 8:28 am
Forum: General
Topic: Out of disk space - upgrading hAP Lite from v6.35 to v6.35.2
Replies: 42
Views: 14982

Re: Out of disk space - upgrading hAP Lite from v6.35 to v6.35.2

I fully agree that on a typical SOHO device a few packages have no place to be installed as factory default. These include: mpls, routing and hotspot, they are clearly advanced stuff that vast majority of users will never need. In addition, these are quite probably not necessary for router to be ini...
by mkx
Wed Oct 14, 2020 8:21 am
Forum: General
Topic: Multiple hotspot profiles on multiple VLAN interfaces on a bridge
Replies: 17
Views: 609

Re: Multiple hotspot profiles on multiple VLAN interfaces on a bridge

If I take from post by @dpsguard out everything I don't really understand (and some more), then what remains is: Can we have multiple VLANs (for isolation) on a common bridge ... but still part of the same large subnet? Then this doesn't make much sense to me. So you're saying that you want to have ...
by mkx
Wed Oct 14, 2020 8:09 am
Forum: General
Topic: Ethernet Connection Error
Replies: 3
Views: 219

Re: Ethernet Connection Error

What is device connected to ether1 port on such mikrotiks? Did you check for potential cable and connector defects?
How about earthing of devices on both ends of link? Could be that there's some spurious current flowing through that cable disturbing data transfers ...
by mkx
Wed Oct 14, 2020 8:05 am
Forum: Beginner Basics
Topic: 10GB Issues...
Replies: 6
Views: 553

Re: 10GB Issues...

Could be that either of Mikrotiks is not really compatible with DAC you're using. Mikrotik devices (and SFPs for that matter) seem to be notorial about incomplete SFP/DAC compatibility (even Mikrotik's own SFPs and DACs are compatible with all of their devices). So you may want to try different bran...
by mkx
Tue Oct 13, 2020 6:49 pm
Forum: General
Topic: NAT with a specific IP external
Replies: 8
Views: 310

Re: NAT with a specific IP external

Attempt to position @anav: simple fact is that (firewall part of) router as part of connection tracking checks every incoming packet whether it's part of NATed connection. An I mean every, regardless source and destination. Let's assume subnets 192.168.60.0/24, 192.168.61.0/24 and 192.168.90.0/24 ca...
by mkx
Tue Oct 13, 2020 4:59 pm
Forum: General
Topic: single ipv6 /64 range
Replies: 21
Views: 657

Re: single ipv6 /64 range

[/end of unplanned rant]
Where's the start of it? ;-)
by mkx
Tue Oct 13, 2020 4:49 pm
Forum: General
Topic: NAT with a specific IP external
Replies: 8
Views: 310

Re: NAT with a specific IP external

I thought that the to-address thing was to tell the NAT where to send all the traffic, but masking it as the IP that I have in ip-address declared in the bridge, at least that is how I have always used it to redirect internet ports to the local network , did not know this function @sindy already wr...
by mkx
Tue Oct 13, 2020 4:37 pm
Forum: General
Topic: Vlan not working for me,
Replies: 13
Views: 529

Re: Vlan not working for me,

So one would assume that all the etherport (2,3,4) are trunk ports in that they are carrying [snip] My question is how do devices attached to the ports handle it? Per diagram in original post, only ether2 is connected ... to unifi switch which is supposed to split that trunk to a few access ports. ...
by mkx
Tue Oct 13, 2020 4:21 pm
Forum: Beginner Basics
Topic: Home User RouterOS Consultancy - Uber for MikroTik
Replies: 10
Views: 562

Re: Home User RouterOS Consultancy - Uber for MikroTik

Anav, that's the list of professional taxi drivers which charge starting fee, by minute, by mile and by coffee. OP is after friendly uber drivers who will do everything for a beer. Yup, that's you.
by mkx
Tue Oct 13, 2020 1:43 pm
Forum: General
Topic: NAT with a specific IP external
Replies: 8
Views: 310

Re: NAT with a specific IP external

How about his: Create an address list of allowed VPN addresses to access the another network /ip firewall address-list add address=192.168.90.xx list=VPNto61 add address=192.168.90.yy list=VPNto61 ... Add src-nat rule which will do the address translation: /ip firewall nat add action=src-nat chain=s...
by mkx
Tue Oct 13, 2020 1:00 pm
Forum: Beginner Basics
Topic: Blocked SMPT port 25
Replies: 12
Views: 443

Re: Blocked SMPT port 25

I just have 3 rules about port 25 on filter : logchain, action=accept and the action drop What about the rest of filter rules? As I wrote, they might be interfering without being obvious to you (and we might spot the problem because we don't have our minds set to what rules are meant to be doing). ...
by mkx
Tue Oct 13, 2020 12:52 pm
Forum: General
Topic: single ipv6 /64 range
Replies: 21
Views: 657

Re: single ipv6 /64 range

whats the smallest range we can offer to customers then? IMHO /60 is reasonable, specially so if one of /64 is needed for WAN address which then leaves a few /64 for their LAN use (allowing them to run 3 subnets). As @pe1chl mentioned, /56 is not unheard of, I'm getting /56 which is entirely for me...
by mkx
Tue Oct 13, 2020 11:58 am
Forum: Beginner Basics
Topic: Firewall rule question
Replies: 2
Views: 136

Re: Firewall rule question

Setting attributes to empty string is not the same as not setting them at all. So your first filter rule on PPPoE-connected router should almost identical to the one on statis IP router except for the in-interface: add action=accept chain=input connection-state=established,related in-interface=pppoe...
by mkx
Tue Oct 13, 2020 11:50 am
Forum: Beginner Basics
Topic: Blocked SMPT port 25
Replies: 12
Views: 443

Re: Blocked SMPT port 25

Two things: apart from the firewall fiter rules you showed, do you have anything else in firewall config which might interfer? An other NAT (SRC or DST) rules (if yes, please post all of them, they might be set in a way that they interfere but in a way not obvious to you) or filter rules blocking it...
by mkx
Mon Oct 12, 2020 11:24 pm
Forum: RouterBOARD hardware
Topic: CCR2004 packet loss
Replies: 21
Views: 1032

Re: CCR2004 packet loss

Do you experience packet loss in both directions equllky or is one direction distinctively worse?

I'd expect problems in packet direction 10G->1G where quite some buffering occurs and enabled flow control should help a lot (another matter is whether flow control actually works).
by mkx
Mon Oct 12, 2020 11:05 pm
Forum: General
Topic: Chained infrastructure
Replies: 5
Views: 291

Re: Chained infrastructure

If you're going to do throughput measurements, stay away from (ROS built-in) bandwidth test, it's a CPU hog and doesn't show real life performance. Use a couple of laptops running iperf, possibly using multiple parallel streams ...
by mkx
Mon Oct 12, 2020 6:03 pm
Forum: General
Topic: SFTP uploads to remote SFTP server [SOLVED]
Replies: 6
Views: 389

Re: SFTP uploads to remote SFTP server

So for me the path is relative to the chroot directory.
So root is not absolute. OTOH you having chroot environment are fully aware of different breeds of paths while many users are not ... obviously.
by mkx
Mon Oct 12, 2020 5:59 pm
Forum: Beginner Basics
Topic: extending hAP lite with another AP: CAPsMAN + VLAN, or?
Replies: 4
Views: 218

Re: extending hAP lite with another AP: CAPsMAN + VLAN, or?

I have two RB951Gs and I'm running one off CAPsMAN (local forwarding and VLANs) and one stand-alone, just for fun.
by mkx
Mon Oct 12, 2020 3:24 pm
Forum: General
Topic: SFTP uploads to remote SFTP server [SOLVED]
Replies: 6
Views: 389

Re: SFTP uploads to remote SFTP server

The path set in /tool fetch url=... is rather absolute path from server's root (not from users home directory).
by mkx
Mon Oct 12, 2020 12:03 pm
Forum: General
Topic: Chained infrastructure
Replies: 5
Views: 291

Re: Chained infrastructure

I expect that for passing the VLANs to wirelles I need to bridge virtual wlan with hw bridge from th switch, am I right? Actually you need bridge if you want to span your LAN segment to anything but wired ethernet ports. And (if configuration doesn't abuse inconsistencies in ROS) you need bridge al...
by mkx
Sun Oct 11, 2020 11:54 pm
Forum: General
Topic: Chained infrastructure
Replies: 5
Views: 291

Re: Chained infrastructure

Yes, any Mikrotik AP with at least two wired ports is capable of doing this. The only real question is the level of performance possible to get and that depends on devices' HW capacity. VLAN configuration should definitely be done using switch chip capabilities as this part of manual describes it. ...
by mkx
Sun Oct 11, 2020 10:29 pm
Forum: Beginner Basics
Topic: Replace config
Replies: 2
Views: 149

Re: Replace config

backup option always creates some binary files, so you can't really check what's in them. To export all config in readable format, execute /export file=anynameyouwant.txt from commant window (ssh session will do). Then transfer resulting file to your computer.
by mkx
Fri Oct 09, 2020 11:43 pm
Forum: RouterBOARD hardware
Topic: LtAP mini external antenna ....querie !
Replies: 6
Views: 283

Re: LtAP mini external antenna ....querie !

A cat4 modem can do up to 100/50 Mbps (DL/UL) in a 20MHz cell, regardless the frequency band. That's theoretical maximum, in reality throughput is lower mainly due to 2 reasons: 1) cell load (air time is shared between active users, you can't do much about that) and 2) less than optimal radio condit...
by mkx
Fri Oct 09, 2020 11:08 pm
Forum: RouterBOARD hardware
Topic: LtAP mini external antenna ....querie !
Replies: 6
Views: 283

Re: LtAP mini external antenna ....querie !

Wording of lables on an LTE modem sounds odd to me. Traditionally only single radio stream was used, hence only one antenna was needed. However, many antennae are polarized and if polarization planes of transmitting antenna (e.g. mobile phone) and receiving antenna (e.g. cell tower) are orthogonal, ...
by mkx
Fri Oct 09, 2020 8:47 pm
Forum: RouterBOARD hardware
Topic: LtAP mini external antenna ....querie !
Replies: 6
Views: 283

Re: LtAP mini external antenna ....querie !

LTE modem R11e-LTE has two antenna connectors, main and aux ... and both have to be connected to two antenne (either that's two yagi or log-periodic antennae, mounted at 90 degree angle for different polarization to maximize MIMO effect) or two ports of a MIMO antenna. Both ports are used for downli...
by mkx
Fri Oct 09, 2020 8:35 pm
Forum: General
Topic: SMB access problem from two different ip classes
Replies: 11
Views: 461

Re: SMB access problem from two different ip classes

How do you access the share on Qnap, using its name (e.g. \\qnap\share)? If so, does it work if you access the share using its IP address (i.e. \\192.168.0.55\share)? SMB uses NMB protocol for resolving names. Unlike DNS it is not centralized[*], it uses broadcasts and those don't pass routers. [*] ...
by mkx
Fri Oct 09, 2020 6:46 pm
Forum: Beginner Basics
Topic: How to get connected without any assigned IP to device?
Replies: 3
Views: 200

Re: How to get connected without any assigned IP to device?

WinBox can't connect to SwOS device, such device is only displayed on the list of discovered devices.
by mkx
Fri Oct 09, 2020 6:40 pm
Forum: RouterBOARD hardware
Topic: Hex gr3 suddenly lost power
Replies: 5
Views: 276

Re: Hex gr3 suddenly lost power

I've tested the power adapater and there is a voltage coming out so it means that it is no the adapter.
Try with another power adapter never the less ... marginal power adapter may be able to produce correct voltage when unloaded but drops when load is applied.
by mkx
Fri Oct 09, 2020 11:53 am
Forum: General
Topic: Connection NAT state srcnat?
Replies: 9
Views: 444

Re: Connection NAT state srcnat?

/ip firewall filter add action=log chain=forward connection-nat-state=!srcnat dst-address=192.168.120.95 log-prefix=OUT out-interface=ether1 protocol=tcp src-port=80 /ip firewall nat add action=masquerade chain=srcnat ipsec-policy=out,none out-interface=ether1 add action=dst-nat chain=dstnat dst-po...
by mkx
Fri Oct 09, 2020 11:17 am
Forum: Beginner Basics
Topic: Access mikrotik router behind a modem
Replies: 6
Views: 273

Re: Access mikrotik router behind a modem

Post full config of your router ... execute /export hide-sensitive and copy-paste results here (inside [code] [/code] environment for better readability). It could well be some other firewall rule which is interfering and it's hard to tell without seeing it all.
by mkx
Fri Oct 09, 2020 11:04 am
Forum: Beginner Basics
Topic: RBcAPGi-5acD2nD disable LAN rules
Replies: 2
Views: 113

Re: RBcAPGi-5acD2nD disable LAN rules

You can disable certain bridge port using command /interface bridge port set [ find interface=ether2 ] disabled=yes ... or disabled=no to enable it again. Use that in a scheduled script ... This completely disables bridge port, also for LAN traffic. If you want to disable only internet access for de...
by mkx
Fri Oct 09, 2020 10:59 am
Forum: Beginner Basics
Topic: IPV6 Firewall [SOLVED]
Replies: 55
Views: 1694

Re: IPV6 Firewall [SOLVED]

Do you get a full house if you test on www.ipv6-test.com ? It is possible to get full house, I get it on one of my hosts ... but that's linux server with statically assigned IPv6 address and properly configured DNS records. For LAN host which gets IPv6 address via SLAAC, I only get 17/20. It says "...
by mkx
Wed Oct 07, 2020 10:51 pm
Forum: RouterBOARD hardware
Topic: Serial Console connected, but no response visible
Replies: 2
Views: 183

Re: Serial Console connected, but no response visible

With the RB3011 I dont see any response, means the putty window remains black. But the connection is established, because I can login by typing 'admin' and 2x<return>. It could be that connections in 3011's RJ45 console port are flakey and that pin 3 (TxD) does not properly connect to the RJ45 conn...
by mkx
Wed Oct 07, 2020 9:59 pm
Forum: Beginner Basics
Topic: rb4011igs+rm VLANs with one Internet Access [SOLVED]
Replies: 5
Views: 249

Re: rb4011igs+rm VLANs with one Internet Access [SOLVED]

I want to divide my home network into two segments: LAN1: 192.168.1.10/24 and LAN2: 192.168.1.20/24. These two networks must be separeted
BTW: these two addresses are in the same /24 subnet ... you should use something like 192.168.10.0/24 and 192.168.20.0/24 ...
by mkx
Wed Oct 07, 2020 12:02 pm
Forum: General
Topic: Connection NAT state srcnat?
Replies: 9
Views: 444

Re: Connection NAT state srcnat?

My issue isn't really with invalid packets, but with private addresses leaking out. Supposedly they leak out because the packets are invalid, and so do not get srcnated. I want to either prevent anything that's not srcnated from going out on the WAN interface (which I thought would be doable using ...
by mkx
Wed Oct 07, 2020 11:52 am
Forum: General
Topic: SFP/SFP+ confuzion [SOLVED]
Replies: 10
Views: 687

Re: SFP/SFP+ confuzion [SOLVED]

It is possible that SFP module is simply not compatible with CCR. Mikrotik's SFP compatibility matrix indicates that even some Mikrotik's own SFP modules are not compatible with all Mikrotik devices, so I'd expect third party modules to be even less compatible.
by mkx
Wed Oct 07, 2020 9:10 am
Forum: General
Topic: Having a hard time setting up "router on a stick" with RB4011 and CRS326 [SOLVED]
Replies: 2
Views: 288

Re: Having a hard time setting up "router on a stick" with RB4011 and CRS326 [SOLVED]

On CRS access (untagged) ports should have pvid set. E.g. /interface bridge port set [ find default-name=ether4 ] pvid=10 and repeat the above for all ports listed as untagged in /interface bridge vlan . After you do it, you may omit listing ports as untagged, they get added automatically (listing t...
by mkx
Tue Oct 06, 2020 11:51 pm
Forum: RouterBOARD hardware
Topic: PowerBox Pro and 48 V 2 A 96 W
Replies: 1
Views: 138

Re: PowerBox Pro and 48 V 2 A 96 W

Yes, brochure is pretty explicit about that. RBGPOE injector is rated at 2A, so things should work just fine.
by mkx
Tue Oct 06, 2020 11:40 pm
Forum: RouterBOARD hardware
Topic: hAP ac2 vs. cAP ac, CAP only usage
Replies: 10
Views: 603

Re: hAP ac2 vs. cAP ac, CAP only usage

You're right in saying we should be tolerant to different opinions. The problem in this discussion as I see it is that you're using cAP ac quite differently from its intended use (CAPsMAN-driven AP) and your arguments about design deficiencies are thus more or less void. Yes, it is possible to use d...
by mkx
Tue Oct 06, 2020 11:11 pm
Forum: Beginner Basics
Topic: RouterOS/SwitchOS Test Result Questions
Replies: 6
Views: 282

Re: RouterOS/SwitchOS Test Result Questions

SwOS can only do switching while ROS can do switching, bridging and routing. Routing is obviously a completely different thing, but difference berween bridging and switching is moot. If one considers only wired ethernet ports, then in Mikrotik world the difference boils down to single thing: bridgin...
by mkx
Tue Oct 06, 2020 10:26 pm
Forum: Wireless Networking
Topic: SXT LTE - Any way to display modulation in use?
Replies: 5
Views: 234

Re: SXT LTE - Any way to display modulation in use?

Modulation varies wildly in LTE. Theoretically every RB (chunk of OFDM tones) could use different modulation during same TTI (there are 25 RBs within 5MHz carrier). This is not common though, but it does change between TTIs. As TTIs in 4G are 1ms in duration, it would be impossible to show exact mod...
by mkx
Tue Oct 06, 2020 10:16 pm
Forum: Wireless Networking
Topic: CAPsMAN - Local-Forwarding - how to choose bridge
Replies: 11
Views: 515

Re: CAPsMAN - Local-Forwarding - how to choose bridge

Show /capsman export so we can see what exactly you configured ...
by mkx
Tue Oct 06, 2020 10:11 pm
Forum: Beginner Basics
Topic: RB4011 VLAN + unifi [SOLVED]
Replies: 14
Views: 521

Re: RB4011 VLAN + unifi [SOLVED]

Erm, no. There is nothing preventing SSIDs or switch ports being assigned to the untagged network in UniFi, in fact you have to explicitly assign them to be tagged. Then its not a switch its an abomination following no standards. Exactly which standards prohibit that behaviour? Standards cast in st...
by mkx
Tue Oct 06, 2020 10:08 pm
Forum: Beginner Basics
Topic: Trying to set up cAP ac as a simple bridge
Replies: 4
Views: 223

Re: Trying to set up cAP ac as a simple bridge

Include :delay 10s on top of configuration script.

The problem: when script gets run, not all HW is initialized yet. So some objects (e.g. ether1 interface) are not available when script refers to them. And script breaks at that point.
by mkx
Tue Oct 06, 2020 9:32 am
Forum: Wireless Networking
Topic: CAPsMAN - Local-Forwarding - how to choose bridge
Replies: 11
Views: 515

Re: CAPsMAN - Local-Forwarding - how to choose bridge

It's your choice.

However, since introduction of VLAN-enabled bridges (somewhere in version 6.41 IIRC) there is no (main-stream) technical reason to run more than one bridge per MT device. And there are things that don't play well when there are multiple bridges (as you noticed yourself).
by mkx
Tue Oct 06, 2020 8:37 am
Forum: General
Topic: miss CRS305-1G-4S+IN with POE OUT
Replies: 1
Views: 145

Re: miss CRS305-1G-4S+IN with POE OUT

So how exactly can PoE out work on a device with single RJ-45 port (which is used as PoE in)? SFP ports don't do PoE in any direction.
by mkx
Tue Oct 06, 2020 8:32 am
Forum: General
Topic: Bonding balance-alb
Replies: 2
Views: 174

Re: Bonding balance-alb

When bonding layer has to decide which member to use for transmitting next packet, it uses some kind of algorithm to decide. In addition it is often (if not always) desirable that packets belonging to same L4 connection (TCP most notably, UDP as well) pass same member link due to timing reasons (to ...
by mkx
Tue Oct 06, 2020 12:21 am
Forum: General
Topic: VLANs on WAN port
Replies: 10
Views: 511

Re: VLANs on WAN port

@anav, you finally became a mentalist?
by mkx
Tue Oct 06, 2020 12:11 am
Forum: Wireless Networking
Topic: CAPSMAN add another wifi SSID only on slave node
Replies: 2
Views: 152

Re: CAPSMAN add another wifi SSID only on slave node

You can provision specific configuration to specific CAP device by adding rules in /capsman provisioning like this: add action=create-dynamic-enabled master-configuration=cfg1 radio-mac=E6:8D:8C:49:EE:4A slave-configurations=cfg2 Be sure the additional rule is placed above the general one you curren...
by mkx
Tue Oct 06, 2020 12:04 am
Forum: Wireless Networking
Topic: CAPsMAN - Local-Forwarding - how to choose bridge
Replies: 11
Views: 515

Re: CAPsMAN - Local-Forwarding - how to choose bridge

Again: do you have some particular reason for running multiple bridges on a RB device?

A hint: you can run VLANs entirely internal to AP if you don't want to run VLANs on wires between AP and the rest of LAN... I can elaborate but after you explain your use case.
by mkx
Mon Oct 05, 2020 11:54 pm
Forum: General
Topic: Best way to configure multi-SSID-AP with VLAN-breakout
Replies: 12
Views: 566

Re: Best way to configure multi-SSID-AP with VLAN-breakout

Confusing world for me. Things are not that confusing. It's simple: packet, coming untagged from wireless, has to be tagged and only once. It can either be tagged by wireless interface (by having vlan-mode=use-tag vlan-id=XX ) or by bridge (having pvid=XX set on member port wlan). If one decides to...
by mkx
Mon Oct 05, 2020 11:39 pm
Forum: General
Topic: Best way to configure multi-SSID-AP with VLAN-breakout
Replies: 12
Views: 566

Re: Best way to configure multi-SSID-AP with VLAN-breakout

@bpw, VLANs are indeed one of moot points in ROS. I've managed to get around by going strictly tagged inside device, which means management is on VLAN interface as well. E.g. instead of having this /interface bridge add name=bridge vlan-filtering=yes pvid=99 /interface bridge port add bridge=bridge ...
by mkx
Mon Oct 05, 2020 11:25 pm
Forum: General
Topic: [VLAN] Set a port to untagged using switch chip
Replies: 17
Views: 765

Re: [VLAN] Set a port to untagged using switch chip

I got slightly lost in this thread, so I'll just emphasize two things: don't mix VLAN configs in /interface bridge and /interface ethernet switch . Setting things in both sections messes things, might cancel out each other or bite your pet. In short: both sections are exclusive even if ROS doesn't m...
by mkx
Mon Oct 05, 2020 11:06 pm
Forum: General
Topic: VLANs on WAN port
Replies: 10
Views: 511

Re: VLANs on WAN port

Post config (/export hide-sensitive, optionally obfuscate sensible information) and describe which port connects to what.
by mkx
Mon Oct 05, 2020 10:16 pm
Forum: General
Topic: Best way to configure multi-SSID-AP with VLAN-breakout
Replies: 12
Views: 566

Re: Best way to configure multi-SSID-AP with VLAN-breakout

Almost ... except that your Only one bridge doesn't really work because it lacks

/interface bridge
set [ find name=bridge1 ] vlan-filtering=yes

And your don't configure vlan-mode=use-tag vlan-id=xxx on wireless interfaces since you have pvid set on corresponding bridge port.
by mkx
Mon Oct 05, 2020 10:06 pm
Forum: RouterOS v7 BETA
Topic: Apple devices not reconnecting to wifi
Replies: 7
Views: 876

Re: Apple devices not reconnecting to wifi

You definitely have DHCP issues if your device shows IP address 169.x.y.z ... whether that's basic problem or it's superimposed on top of lower layer problems (read: wireless connectivity) that's a thing to find out.
by mkx
Sun Oct 04, 2020 10:11 pm
Forum: Wireless Networking
Topic: CAPsMAN - Local-Forwarding - how to choose bridge
Replies: 11
Views: 515

Re: CAPsMAN - Local-Forwarding - how to choose bridge

Don't know about GUI but in CLI datapath has bridge property when local-forwarding set to either yes or no. I'm not sure how it's interpreted if set with local-forwarding, but I guess it's used on CAP as intended. But then ... with bridge being VLAN aware, rarely there's need to run more than one br...
by mkx
Sun Oct 04, 2020 10:10 am
Forum: RouterBOARD hardware
Topic: hAP ac2 vs. cAP ac, CAP only usage
Replies: 10
Views: 603

Re: hAP ac2 vs. cAP ac, CAP only usage

To be specific, quick guide for cAP ac (and related models) specifically instructs user to connect ether1 (via PoE injector) to ISP's device (to be used as WAN) and connect via wireless to configure the unit. But then, when everything else fails, why read the manual if one can complain on user forum?
by mkx
Sun Oct 04, 2020 9:56 am
Forum: Wireless Networking
Topic: ACCESS LIST vs CONNECT LIST
Replies: 11
Views: 442

Re: ACCESS LIST vs CONNECT LIST

The problem with Access list logic is that it relies on client device to keep trying to connect to the same AP again and again. If the client device is "smart", then it might remember it was kicked off from certain BSSID and doesn't try to connect to it again. Which is fine if it can connect to anot...
by mkx
Sat Oct 03, 2020 1:35 pm
Forum: General
Topic: Dark places in the RBcAPGi-5acD2nD / cAP ac rescue [SOLVED]
Replies: 5
Views: 544

Re: Dark places in the RBcAPGi-5acD2nD / cAP ac rescue [SOLVED]

This IMO explains why device was not accessible through the first port on default IP - and it seems as MikroTik bug - because manual Setup paragraph clearly state: "1. Connect your internet cable to the first port"! As @Sob already explained when MT gets its default configuration, it doesn't accept...
by mkx
Thu Oct 01, 2020 9:43 pm
Forum: Beginner Basics
Topic: Using Mikrotik Router as a Public IP Forwarder
Replies: 6
Views: 277

Re: Using Mikrotik Router as a Public IP Forwarder

Even though you don't intend to enforce firewall you can still have a look at it. If you're running recent ROS, execute /system default-configuration print on your RB750 and go through firewall settings. It might give you some ideas ...
by mkx
Thu Oct 01, 2020 9:30 pm
Forum: General
Topic: PPPoE and Multicast from one ethernet [SOLVED]
Replies: 3
Views: 368

Re: PPPoE and Multicast from one ethernet [SOLVED]

TL;DR: PPPoE client can actually run off a vlan interface. It might work like this: /interface bridge add name=BR1 vlan-filtering=yes /interface bridge port add bridge=BR1 interface=ether1 pvid=30 frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes add bridge=BR1 interface=ethe...
by mkx
Thu Oct 01, 2020 9:08 pm
Forum: Beginner Basics
Topic: Using Mikrotik Router as a Public IP Forwarder
Replies: 6
Views: 277

Re: Using Mikrotik Router as a Public IP Forwarder

The way you configured router is fine. Only thing to fix (it seems to work fine, but it actually is not done correctly) is to move router's WAN IP address from ether1 to bridge. Re NAT: usually there are numerous devices behind a router in a LAN and LAN devices use private IP addresses (e.g. 192.168...
by mkx
Thu Oct 01, 2020 5:08 pm
Forum: General
Topic: RB951G-2HnD, ether port is going up and down
Replies: 3
Views: 231

Re: RB951G-2HnD, ether port is going up and down

Could be that power adapter is playing games. Try to replace it with a new one. Supplied one is 12V 1A, but can be 24V 0.5A and anything in between.
by mkx
Thu Oct 01, 2020 4:57 pm
Forum: Beginner Basics
Topic: TP-Link router behind a MikroTik
Replies: 5
Views: 2284

Re: TP-Link router behind a MikroTik

Do you experience this too? Did you fix it? How?
Upgrade router to modern version of ROS (e.g. 6.47.4). Unless you're a troll, in that case keep running vulnerable version.
by mkx
Thu Oct 01, 2020 4:51 pm
Forum: Beginner Basics
Topic: Using Mikrotik Router as a Public IP Forwarder
Replies: 6
Views: 277

Re: Using Mikrotik Router as a Public IP Forwarder

How is L3 connectivity towards ISP done? Does ISP provide that /29 subnet, but reserves one address for their own router (and the rest of devices are supposed to use that IP address as gateway)? Or is that router gets own IP address (outside the mentioned /29 address block) and that address block ge...
by mkx
Thu Oct 01, 2020 4:35 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 282
Views: 71362

Re: v7.1beta2 [development] is released!

mkx BTW, anybody installing beta version (the thread is about v7.1beta) in any approximation of production environment is living on the cutting edge and deserves whatever hits him/her. but people with Chateau not have a way to go back to ros v6 bcs mtk give them only Ros7 and no way of installing v...
by mkx
Wed Sep 30, 2020 8:50 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta2 [development] is released!
Replies: 282
Views: 71362

Re: v7.1beta2 [development] is released!

Guys, stop telling everybody that they should wait for other people do testing of new release. If you do it long enough, nobody will test new release. BTW, anybody installing beta version (the thread is about v7.1beta) in any approximation of production environment is living on the cutting edge and ...
by mkx
Wed Sep 30, 2020 5:48 pm
Forum: Wireless Networking
Topic: Hotspot Problem with Iphone devices
Replies: 1
Views: 106

Re: Hotspot Problem with Iphone devices

You can't. Portable devices may choose to switch off wireless to save battery life and there's nothing on the AP to change that decision. Perhaps there some tweaking possible on portable device not to switch wireless off ... but expect notably shorter battery life. Not something you can do on random...
by mkx
Mon Sep 28, 2020 4:15 pm
Forum: General
Topic: CAPsMAN upgrade doubts
Replies: 6
Views: 419

Re: CAPsMAN upgrade doubts

I set the package path to "/disk1/upgrade" and the upgrade policy to suggest same version . Ok, understood. Somehow I thought that one could upgrade CAP with any version wanted. Well, the setting you mentioned in one of previous posts (quoted above) refers to ROS version running on CAPsMAN, not to ...
by mkx
Mon Sep 28, 2020 4:07 pm
Forum: Beginner Basics
Topic: hAP AC next model
Replies: 4
Views: 308

Re: hAP AC next model

Who knows when a new model of hAp ac² with SFP will be available? Wouldn't that be the existing "hAP AC" which is already available? No because hAP ac has old single-core QCA9558 CPU while hAP ac² has much newer 4-core IPQ-4018 CPU which dances circles around QCA9558 while doing some CPU-intensive ...
by mkx
Sun Sep 27, 2020 3:02 pm
Forum: Beginner Basics
Topic: changing my ether PoE-in port from 1 to 5 in mikrotik RB951Ui 2HnD using winbox
Replies: 2
Views: 170

Re: changing my ether PoE-in port from 1 to 5 in mikrotik RB951Ui 2HnD using winbox

PoE-in is enabled in hardware only on ether1 so it is not possible to change it elsewhere (the same is true for PoE-out being limited to ether5). So besides changing WAN port to ether5 (as per instructions by @bpwl) you'll have to use power jack to deliver power to the unit.
by mkx
Sun Sep 27, 2020 1:11 pm
Forum: RouterBOARD hardware
Topic: CRS328-24P-4S+RM installation of fan3 and fan4
Replies: 19
Views: 4896

Re: CRS328-24P-4S+RM installation of fan3 and fan4

At least 1U proliants have plenty of small-diameter fans, all running hard. Making those servers really loud beasts.
by mkx
Sun Sep 27, 2020 1:07 pm
Forum: Wireless Networking
Topic: Problem with static IP address / DHCP
Replies: 1
Views: 125

Re: Problem with static IP address / DHCP

How exactly did you configure static lease via GUI? It is quite easy to miss something (DHCP server logs mention offering address 192.168.88. 246 which is not what you configured). The easiest way is to let device obtain lease from dynamic pool, then find it on lease list, click "make static" and th...
by mkx
Sun Sep 27, 2020 12:39 pm
Forum: General
Topic: PWR-Line AP PL6411-2nD as a Home Wireless Router
Replies: 1
Views: 204

Re: PWR-Line AP PL6411-2nD as a Home Wireless Router

Since it's running full RouterOS there's no reason to believe this device couldn't be used as full home router/firewall. According to test results it should be able to route at (almost) wirespeed (which is 100Mbps). Since wireless operations are somehow CPU bound this may cause routing slowdowns dur...
by mkx
Sun Sep 27, 2020 12:30 pm
Forum: Beginner Basics
Topic: RB4011 SFP Port
Replies: 3
Views: 203

Re: RB4011 SFP Port

According to official SFP module compatibility matrix you should be fine when using either S-RJ01 (1Gbps SFP) or S+RJ10 (10Gbps SFP+). I recall some reports about autonegotiation problems when using these SFP modules so you may want to go through forum threads (I don't use these modules hence my int...
by mkx
Sat Sep 26, 2020 11:21 pm
Forum: General
Topic: Mikrotik to replace our faulty Cisco core switch
Replies: 6
Views: 515

Re: Mikrotik to replace our faulty Cisco core switch

What about this switch from Mikrotik. CRS312-4C+8XG-RM Do the Mikrotik switches actually do routing of vlan traffic? This switch has routing capacity of a few 100Mbps. As @tdw already mentioned, this number will sky-rocket with ROSv7. However ROSv7 unfortunately seems far from being production-read...
by mkx
Sat Sep 26, 2020 10:33 pm
Forum: Beginner Basics
Topic: CHR Router - 2 ISP Hetzner
Replies: 8
Views: 419

Re: CHR Router - 2 ISP Hetzner

Never did PBR myself, so hopefully someone experienced will drop by.

Your PM brought me here ... slightly faster than I'd come on my own.
by mkx
Sat Sep 26, 2020 10:27 pm
Forum: Wireless Networking
Topic: Extending multiple SSID with CAP
Replies: 21
Views: 1172

Re: Extending multiple SSID with CAP

For starters go through this this tutorial , it should explain the way VLANs should be done. When it comes to (virtual) wlan interfaces - you'll have one per SSID: add them as access ports to unified bridge (set appropriate PVID). Don't bother with vlan settings on wlan interfaces. As mentioned befo...
by mkx
Sat Sep 26, 2020 10:10 pm
Forum: General
Topic: CAPsMAN upgrade doubts
Replies: 6
Views: 419

Re: CAPsMAN upgrade doubts

It is fine to set /caps-man manager package-path to folder where npks reside. My successfull procedure is that when I want to upgrade the gear, I first download packages for architectures of CAPs and place them in correct folder on CAPsMAN. Then I start upgrade on CAPsMAN (usually I use usual proced...
by mkx
Sat Sep 26, 2020 9:16 pm
Forum: Beginner Basics
Topic: CHR Router - 2 ISP Hetzner
Replies: 8
Views: 419

Re: CHR Router - 2 ISP Hetzner

I guess you're after Policy Based Routing...
by mkx
Fri Sep 25, 2020 6:29 pm
Forum: General
Topic: SwitchOS on RB3011
Replies: 1
Views: 245

Re: SwitchOS on RB3011

Official product page does not list SwOS as available OS for this device.
by mkx
Fri Sep 25, 2020 6:11 pm
Forum: Wireless Networking
Topic: Extending multiple SSID with CAP
Replies: 21
Views: 1172

Re: Extending multiple SSID with CAP

Commands which work directly with hardware (e.g. switch chip) vary between devices according to switch chip class. And I don't see you mentioning type of main router. When it comes to HW offload: only wire2wire traffic can be offloaded to switch chip. If primary use of hAP ac devices will be wireles...
by mkx
Fri Sep 25, 2020 6:01 pm
Forum: Beginner Basics
Topic: Set bridge port pvid command [SOLVED]
Replies: 2
Views: 271

Re: Set bridge port pvid command [SOLVED]

I tried to "set" ether7 with
/interface bridge port
set interface=ether7 hw=yes pvid=30 comment ="IP Cameras"

Try this instead:
/interface bridge port
set [ find interface=ether7 ] hw=yes pvid=30 comment ="IP Cameras"
by mkx
Fri Sep 25, 2020 8:59 am
Forum: Beginner Basics
Topic: VLAN Client Isolation
Replies: 10
Views: 774

Re: VLAN Client Isolation

The only thing that I think comes close is the situation when you have WIFI users on the SAME SSID. In particular, one can only isolate wlan users from each other when they're using same B SSID ... meaning clients are connected to the very same AP. Such isolation doesn't work in environment where m...
by mkx
Thu Sep 24, 2020 4:20 pm
Forum: Wireless Networking
Topic: Extending multiple SSID with CAP
Replies: 21
Views: 1172

Re: Extending multiple SSID with CAP

So far I think I need to bin off my existing bridges, combine everything apart from WAN into one bridge, and then VLAN? Indeed. I like to think of VLAN as layer 2.5 ... so physical connections (ethernet, layer 2) get overlaid with L2.5 network which logically speaking has different layout than L2 n...
by mkx
Thu Sep 24, 2020 9:30 am
Forum: General
Topic: CCR1009-7G-1C-1S+PC Cloud Core Router max microSD card size
Replies: 5
Views: 489

Re: CCR1009-7G-1C-1S+PC Cloud Core Router max microSD card size

There are 3 main SD spec families: original SD, SDHC and SDXC ... while they are electrically compatible, they are not completely compatible on protocol level. Each comes with its maximum size: 2GB for original SD, 32GB for SDHC and 2TB for SDXC. They also come with different default files systems: ...
by mkx
Thu Sep 24, 2020 8:48 am
Forum: Beginner Basics
Topic: Can't add Unifi Switch
Replies: 4
Views: 319

Re: Can't add Unifi Switch

Did you check for any port settings mismatch? E.g. if Mikrotik is set to not do autonegotiation while Unifi does it, the link would likely fail to establish. Nowdays everything should be set to autonegotiation and most of time it would just work. If it doesn't, try to set port settings manually, jus...
by mkx
Wed Sep 23, 2020 3:51 pm
Forum: Announcements
Topic: Newsletter 97 (September 2020)
Replies: 86
Views: 13342

Re: Newsletter 97 (September 2020)

Finally you decided to add external antennas to routers, what happend to all the talk how they are not needed you where tell us all this years when we complained about poor signal? :D

Sush! Don't bring this out, they might decide not to do it for future devices.
by mkx
Wed Sep 23, 2020 3:19 pm
Forum: Wireless Networking
Topic: Extending multiple SSID with CAP
Replies: 21
Views: 1172

Re: Extending multiple SSID with CAP

VLAN is base of MTUNA :-)
by mkx
Wed Sep 23, 2020 3:08 pm
Forum: General
Topic: [FEATURE REQUEST] User Interface Overhaul?
Replies: 10
Views: 646

Re: [FEATURE REQUEST] User Interface Overhaul?

Both varieties of GUI closely follow CLI with regard to structure of configuration tree ... which makes it very convenient to exchange configuration advisories ... because it doesn't matter which xUI somebody uses. There have been some attempts to create simplified UI (such as QuickSet) which works ...
by mkx
Tue Sep 22, 2020 9:23 pm
Forum: General
Topic: Unable to update to 6.47.4 from 6.38.5
Replies: 1
Views: 245

Re: Unable to update to 6.47.4 from 6.38.5

Usually when update fails, there's something in logs about it. You may also want to check list of installed packages ... to verify there aren't any duplicates. There were times when one or another package would be installed twice and that would block upgrade. BTW, there were some bigger changes betw...
by mkx
Tue Sep 22, 2020 2:47 pm
Forum: Beginner Basics
Topic: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?
Replies: 26
Views: 4230

Re: Can Mikrotik / RouterOS do multiple PPPOE trough same WAN cable ?

For starters disable fasttrack rule in firewall filter rules. If it helps, then you'll have to change that rule to skip mangled packets ...
by mkx
Tue Sep 22, 2020 1:49 pm
Forum: General
Topic: [SOLVED] Cannot access forum.mikrotik.com in IPv6
Replies: 3
Views: 418

Re: Cannot access forum.mikrotik.com in IPv6

So how exactly is Mikrotik supposed to help if some third party (one of your upstream ISPs) breaks things in IPv6? Proper action would be to complain to your ISP with some traceroutes showing the point of failure.
by mkx
Tue Sep 22, 2020 1:42 pm
Forum: Wireless Networking
Topic: Extending multiple SSID with CAP
Replies: 21
Views: 1172

Re: Extending multiple SSID with CAP

You can do it even without using VLANs. When using CAPsMAN to provision APs it is possible to configure it in the way all traffic is tunneled to CAPsMAN device which then splits traffic into different IP subnets. What you do with individual subnets there is up to confing, you can bridge one with the...
by mkx
Tue Sep 22, 2020 10:49 am
Forum: General
Topic: Ripple20 - Treck stack vulnerabilities
Replies: 6
Views: 1079

Re: Ripple20 - Treck stack vulnerabilities

Does Mikrotik make use of the Treck stack on any of their hardware? Highly unlikely. ROS runs pretty stock Linux kernel with more or less stock IP stack which doesn't have any relation to Treck IP stack. In that regard, ROS is not embedded system, it's rather full-blown Linux device. SwOS is differ...
by mkx
Tue Sep 22, 2020 10:37 am
Forum: Beginner Basics
Topic: Adding a LAN Static IP box to a DHCP configured LAN
Replies: 2
Views: 244

Re: Adding a LAN Static IP box to a DHCP configured LAN

If your devices are statically set, then there's nothing you can do about resolving DNS names on router itself. You have to configure end devices with IP address of DNS server to use. You could enter IP address of your router as DNS server, (almost) everything is set up to allow that. There's a tiny...
by mkx
Tue Sep 22, 2020 8:11 am
Forum: Wireless Networking
Topic: LDF LTE6 work in USA?
Replies: 2
Views: 232

Re: LDF LTE6 work in USA?

Remember, sometimes workaround live longer then final setup :)
https://i.imgur.com/7CdIpKh.png

What a great solution ... ROFL
by mkx
Tue Sep 22, 2020 8:08 am
Forum: Wireless Networking
Topic: LHG-LTE6 CA of AT&T B2+B12 -or- AT&T B2+B17 not working
Replies: 7
Views: 549

Re: LHG-LTE6 CA of AT&T B2+B12 -or- AT&T B2+B17 not working

Just for the record: 3GPP Rel. 11 brings CoMP (Coordinated MultiPoint) which enables CA between different eNBs (read: different towers). This is like Dual Connectivity.. DC is next step from CoMP ... in CoMP there's only one scheduler involved (running in eNB serving PCC (primary carrier component)...
by mkx
Tue Sep 22, 2020 7:53 am
Forum: Announcements
Topic: v6.48beta [testing] is released!
Replies: 135
Views: 51896

Re: v6.48beta [testing] is released!

Another request for clarification: when reading Packet flow section of port extender description it is not entirely clear whether PE device actually switches frames between own ports (after physical port, associated with DST MAC, is known) on its own or all packets are forwarded to CB regardless the...
by mkx
Tue Sep 22, 2020 7:43 am
Forum: Announcements
Topic: WinBox v3.27 released!
Replies: 70
Views: 9166

Re: WinBox v3.27 released!

Also note that VLAN 0 is still rejected in v7 even though that is a valid value. .... When VLAN 0 is not going to be implemented there should be some flag that allows you to push an 802.1q tag with the current priority e.g. as an interface- or port setting. 0 is not a valid value to be set as VLAN ...
by mkx
Mon Sep 21, 2020 11:47 pm
Forum: SwOS
Topic: SWOS MTU
Replies: 5
Views: 3481

Re: SWOS MTU

There is no such thing as MTU negotiation. You're probably thinking about PMTUD which is IP layer function ... that's L3 while switches are L2 devices. Only routers contribute in PMTUD. HW can have MTU limits (switches included) and when deciding upon MTU value to be used inside an IP subnet one has...
by mkx
Mon Sep 21, 2020 11:18 pm
Forum: Wireless Networking
Topic: LHG-LTE6 CA of AT&T B2+B12 -or- AT&T B2+B17 not working
Replies: 7
Views: 549

Re: LHG-LTE6 CA of AT&T B2+B12 -or- AT&T B2+B17 not working

Big question is that all connection give you the same eNB Just for the record: 3GPP Rel. 11 brings CoMP (Coordinated MultiPoint) which enables CA between different eNBs (read: different towers). The feature has to be supported both by network and user's device ... I'm not sure if any of current Mik...
by mkx
Mon Sep 21, 2020 3:36 pm
Forum: General
Topic: CCR2004 poor bridge performance
Replies: 23
Views: 1144

Re: CCR2004 poor bridge performance

Above 1G I'm starting to encounter out-of-sequence frames. Which, if I understand things correctly, is the basic reason for single stream consuming single CPU ... much easier to get the timing right and not to introduce out-of-sequence frames due to different processing time on different CPU cores.
by mkx
Mon Sep 21, 2020 3:21 pm
Forum: General
Topic: Is it possible to create a static DHCP lease based on host name?
Replies: 3
Views: 333

Re: Is it possible to create a static DHCP lease based on host name?

Does anybody know if this is possible? The reason for needing this is that iOS 14 now randomizes the MAC addresses, but I would still like these devices to have fixed IP address on my own network without disabling the randomization. Can't you disable randomization for particular SSID only? It is po...
by mkx
Mon Sep 21, 2020 12:28 pm
Forum: Wireless Networking
Topic: Mikrotik wi-fi and Iphone = problem
Replies: 91
Views: 68687

Re: Mikrotik wi-fi and Iphone = problem

My problem was in the authentication type in my security profile. The iPad Pro doesn't like WPA2 EAP Did you actually have configured everything needed for EAP (EAP methods and other related settings)? If you did not, then it's not that IPad pro doesn't like it, more likely it prefers it and it sim...
by mkx
Mon Sep 21, 2020 12:18 pm
Forum: Wireless Networking
Topic: LHG-LTE6 CA of AT&T B2+B12 -or- AT&T B2+B17 not working
Replies: 7
Views: 549

Re: LHG-LTE6 CA of AT&T B2+B12 -or- AT&T B2+B17 not working

In LTE mobility is supposed to be driven by network ... based on terminal's measurement feedback. The same goes for CA component carrier selection. Client device can not force any of them. If device's feedback (e.g. measurements) indicate that, according to network settings, some channel on certain ...
by mkx
Mon Sep 21, 2020 11:55 am
Forum: Beginner Basics
Topic: Conecting between subnets
Replies: 1
Views: 109

Re: Conecting between subnets

Having two routers in your network complicates things a lot. The fact you can't put Nokia into bridge mode is a complication which mostly affect ability to port-forward external connections (i.e. if you are running a web server in your LAN and you wanted to allow external connections to it). The big...
by mkx
Mon Sep 21, 2020 11:47 am
Forum: Beginner Basics
Topic: bridge to serve multiple VLAN ?
Replies: 4
Views: 381

Re: bridge to serve multiple VLAN ?

As @bpw already mentioned, if your use scenario (with regards to CCR) is exactly as shown in network topology, then it would be slightly more resource-efficient to go without bridge. However, if you do choose bridge solution, then config you showed is missing quite a few important settings, such as ...
by mkx
Thu Sep 17, 2020 12:14 pm
Forum: Beginner Basics
Topic: Forward chain ipsec rule placement
Replies: 2
Views: 139

Re: Forward chain ipsec rule placement

And all of that because fasttrack causes packets to skip most of packet processing, which includes encapsulation/decapsulation of packets into/from IPsec tunnel ...
by mkx
Thu Sep 17, 2020 12:11 pm
Forum: Beginner Basics
Topic: Some probably dumb questions... [SOLVED]
Replies: 6
Views: 432

Re: Some probably dumb questions... [SOLVED]

Regarding "the changes are not necessary", does that mean they are bad changes, or just a waste of time? If you mean this: The previous computer tech was wanting to make these changes ... 1. Turn off UPnP, remote administration, ping,telnet,SSH, and HNAP; set ports to 'stealth'. 2. Change SSID and ...
by mkx
Wed Sep 16, 2020 8:35 am
Forum: RouterBOARD hardware
Topic: LtAP mini as gps ntp server
Replies: 3
Views: 245

Re: LtAP mini as gps ntp server

Could LtAP mini act as gps ntp server using built-in gps module ? Probably not because it takes much more than simple NMEA datagram reception to set NTP server's clock to precise time. AFAIK Mikrotik's GPS module lacks required interfaces (e.g. 1PPS interface), possibly NTP server lacks required dr...
by mkx
Wed Sep 16, 2020 8:07 am
Forum: General
Topic: Can't login here with my password from 12 September 2020
Replies: 4
Views: 339

Re: Can't login here with my password from 12 September 2020

I agree with @Znevna as well ... I'm using a weak password (according to password selection rules) and forum keeps accepting it (didn't have to change / refresh it). So it seems like password database actually got somehow damaged during works but that damage did not affect all forum users.
by mkx
Wed Sep 16, 2020 7:59 am
Forum: General
Topic: CRS326/CRS317 provision failing [SOLVED]
Replies: 8
Views: 403

Re: CRS326/CRS317 provision failing [SOLVED]

Is it not relevant that the static IP is on the bridge, and the DHCP client is not on the bridge? And that my only connection was to the DHCP client port? How could a second IP address on the same subnet cause issue if the link is down? The location of IP address (bridge vs. stand-alone ethernet po...
by mkx
Tue Sep 15, 2020 11:28 pm
Forum: General
Topic: CRS326/CRS317 provision failing [SOLVED]
Replies: 8
Views: 403

Re: CRS326/CRS317 provision failing [SOLVED]

If router has two IP addresses from same subnet, then it has two possible routes to reach target IP address. Mind that interface, used for inbound packets, does not define interface to be used for return packets. So yes, unless you configure some kind of routing priority[*], setting second IP addres...
by mkx
Tue Sep 15, 2020 4:01 pm
Forum: General
Topic: Feature requests
Replies: 1279
Views: 289986

Re: Feature requests

- MAC address (a value and a mask) In the light of MAC address randomization it becomes less and less useful... But that is in fact one of the the applications I have for it :-) Exactly. There are a few good use cases where client device MAC randomization doesn't make any sense and it's good to hav...
by mkx
Tue Sep 15, 2020 8:01 am
Forum: RouterBOARD hardware
Topic: 951G-2HnD too slow for 1Gbps connection?
Replies: 36
Views: 5710

Re: 951G-2HnD too slow for 1Gbps connection?

And what You say about HEX S? Better? Worse? (I do not need wifi antenna inside) Not exactly worse. Just different. Nevertheless - slower: will cap at 800-900 in real-life scenarios. If you're extremely lucky. More likely hEX S won't go any faster than 400Mbps when routing/firewalling/NATing while ...
by mkx
Tue Sep 15, 2020 7:46 am
Forum: General
Topic: CRS326/CRS317 provision failing [SOLVED]
Replies: 8
Views: 403

Re: CRS326/CRS317 provision failing [SOLVED]

Does the provisioning fail if you copy-paste individual commands into command window? If yes, then you should be able to identify command which breaks config ... If no, then it might have something to do with timing of commands (e.g. command referring to item which is defined by preceding commands b...
by mkx
Mon Sep 14, 2020 8:56 pm
Forum: RouterBOARD hardware
Topic: 951G-2HnD too slow for 1Gbps connection?
Replies: 36
Views: 5710

Re: 951G-2HnD too slow for 1Gbps connection?

Check official test results, available for all devices. While absolute numbers don't quite resemble reality, they still show relative speed of devices. If one device is twice as fast in test, it will be approximately twice as fast in reality as well.
by mkx
Mon Sep 14, 2020 8:48 pm
Forum: General
Topic: VLANs on WAN port
Replies: 10
Views: 511

Re: VLANs on WAN port

Use VLAN-aware bridge with all ports members of it. This tutorial should explain things pretty well.
by mkx
Mon Sep 14, 2020 11:46 am
Forum: RouterBOARD hardware
Topic: power RB4011 via POE from CRS328-24P-4S+RM?
Replies: 2
Views: 232

Re: power RB4011 via POE from CRS328-24P-4S+RM?

To stay on the safe side (and keep away from frying anything in CRS328 or RB4011) you better don't use PoE in this combination. Power consumption of RB4011 will likely exceed CRS328's PoE out capability with your configuration (at least from time to time). If you really can't use supplied power adap...
by mkx
Mon Sep 14, 2020 11:30 am
Forum: Wireless Networking
Topic: UDP-Lite Video
Replies: 1
Views: 137

Re: UDP-Lite Video

It's really up to application. The main difference between "normal" UDP and UDP-lite is that damaged packets don't get dropped with UDP-lite. That application can do with damaged packets is up to application itself. The idea is that bit stream, as produced by application, has some redundancy built i...
by mkx
Mon Sep 14, 2020 11:12 am
Forum: Announcements
Topic: v6.46.7 [long-term] is released!
Replies: 43
Views: 9405

Re: v6.46.7 [long-term] is released!

Shouldn't we be seeing the changelog from 6.45.9 to 6.46.7 not from 6.46.6 ? Going up a major version in a long-term release should be looked over a bit more carefully before we take the plunge.
Yes, that would be logical.
Mikrotik fought the Logic and Mikrotik won.
by mkx
Mon Sep 14, 2020 9:19 am
Forum: General
Topic: Support 16GB Memory
Replies: 3
Views: 276

Re: Support 16GB Memory

Support Memory up to 16GB In RouterOS V6 like RouterOS V7 Don't hold your breath. Personally I'd much rather see MT devs focus on V7 advance than to try to backport everything to V6. BTW, RAM support is about kernel used in ROS and V6 uses ancient kernel. Possibly 32-bit only (on all platforms, inc...
by mkx
Mon Sep 14, 2020 9:06 am
Forum: General
Topic: Adding Routes with DHCP
Replies: 14
Views: 4557

Re: [SOLVED] Adding Routes with DHCP

it seems there is no option to mark as "true answer" for the question in the forum!

There is a way, but only user that started a topic can do it.
by mkx
Mon Sep 14, 2020 9:03 am
Forum: General
Topic: Hiding other devices
Replies: 3
Views: 272

Re: Hiding other devices

You can't really hide L2 devices on a L2 switched network. So if you really want to hide the rest of devices from certain device, you should contain that "offending" device to its own L2 network (think of VLAN) and then use similar L3 mechanisms (e.g. IP firewall) to limit connectivity between the "...
by mkx
Mon Sep 14, 2020 8:55 am
Forum: General
Topic: [Idea] Multiple or adjustable MTU size setting on interface
Replies: 1
Views: 172

Re: [Idea] Multiple or adjustable MTU size setting on interface

When thinking of MTU, one has to keep in mind that MTU is property of a whole L2 subnet, in case of WAN interface that includes upstream (ISP) device. Mismatched MTU size can mean breaking connectivity between devices with mismatched MTU settings, in case of WAN connection this means no internet. Ad...
by mkx
Mon Sep 14, 2020 8:43 am
Forum: General
Topic: PPPoE WAN to LAN
Replies: 7
Views: 408

Re: PPPoE WAN to LAN

My experience goes that IPv4 addresses provided via PPPoE are /32 ... and none other WAN IPs are usually routed through it. If they are, they are because of special arrangements with ISP, but client can't just make it magically work by configuring stuff on their own end. That is completely the oppo...
by mkx
Fri Sep 11, 2020 8:07 am
Forum: General
Topic: PPPoE WAN to LAN
Replies: 7
Views: 408

Re: PPPoE WAN to LAN

My experience goes that IPv4 addresses provided via PPPoE are /32 ... and none other WAN IPs are usually routed through it. If they are, they are because of special arrangements with ISP, but client can't just make it magically work by configuring stuff on their own end. Which means that you actuall...
by mkx
Thu Sep 10, 2020 9:26 am
Forum: RouterBOARD hardware
Topic: CRS354-48G-4S+2Q+ and VLAN
Replies: 1
Views: 184

Re: CRS354-48G-4S+2Q+ and VLAN

CRS switches, running RouterOS, are L3 devices. The way VLANs are configured on CRS3xx is very well described in this tutorial . Beware: CRS, being L3 device, will route between all interfaces with L3 setup (e.g. VLANs with IP address set). If you want to run DHCP server for some (or all) VLAN, that...
by mkx
Thu Sep 10, 2020 8:46 am
Forum: General
Topic: NEW STABLE VERSION 6.47.3 DOES NOT RECEIVE IP FOR INTERFACE AT 10 mbps
Replies: 3
Views: 320

Re: NEW STABLE VERSION 6.47.3 DOES NOT RECEIVE IP FOR INTERFACE AT 10 mbps

Did the ethernet link come up at all in 6.47? Execute /interface ethernet monitor <port name> once and check if auto-negotiation finished. Also check what speeds are advertised by RB (the advertising section) and what speeds are advertised by link partner ... and are there any overlapping speed/dupl...
by mkx
Wed Sep 09, 2020 3:36 pm
Forum: General
Topic: LTE dropouts
Replies: 8
Views: 1190

Re: LTE dropouts

Based on that, depending on how I decipher the numbers it could suggest it's toggling between these two modes: 6 registered for "SMS only", home network 9 registered for "CSFB not preferred", home network There are two ways of delivering SMSes in LTE network: CSFB way and data (native) way. At leas...
by mkx
Wed Sep 09, 2020 3:14 pm
Forum: General
Topic: Migration of CA
Replies: 11
Views: 729

Re: Migration of CA

I agree with you, it's only natural for people to use whatever is available. I blame ROS devs (or rather their management) to include such functionality. Back to topic: if one uses self-issued certificate for say OpenVPN connection, then I'd say it's done on enthusiast level and I don't see any reas...
by mkx
Wed Sep 09, 2020 2:06 pm
Forum: Beginner Basics
Topic: Using RouterOS to VLAN your network
Replies: 144
Views: 78700

Re: Using RouterOS to VLAN your network

In theory mismatched PVID doesn't necessarily break things. However, it is odd and good practice is to avoid it. When I first joined this forum, it was because I was abusing a feature, available in other vendor's managed switch, and I was asking how to do it in ROS. The feature I was asking about is...
by mkx
Tue Sep 08, 2020 7:07 pm
Forum: Beginner Basics
Topic: IP is leased but no internet access [SOLVED]
Replies: 7
Views: 379

Re: IP is leased but no internet access [SOLVED]

I still am not sure why this is the case. Any managed switch (other vendors as well) have IP address for management purpose. In Mikrotik world, all ROS devices by default have static IP address 192.168.88.1 on their LAN side (and on switches that's all ports) while SwOS devices are by default runni...
by mkx
Tue Sep 08, 2020 9:21 am
Forum: Wireless Networking
Topic: My mikrotik forgets the settings after reboot
Replies: 2
Views: 200

Re: My mikrotik forgets the settings after reboot

I guess you should contact support@mikrotik.com to seek advice.
by mkx
Tue Sep 08, 2020 8:53 am
Forum: Wireless Networking
Topic: DHCP all zeros 00:00:00:00:00:00 on MAC address
Replies: 4
Views: 405

Re: DHCP all zeros 00:00:00:00:00:00 on MAC address

Log: dhcp, warning Detected conflict by ICMP response for 10.0.70.72 This indicates an IP address conflict. How things work: DHCP client requests a DHCP lease. DHCP server decides upon IP address to lease and (optionally) checks if the IP address is in use (it may use ICMP echo request to do it). I...
by mkx
Tue Sep 08, 2020 8:29 am
Forum: General
Topic: How to remove 802.1Q header on "untagged" bridge egress
Replies: 25
Views: 1449

Re: How to remove 802.1Q header on "untagged" bridge egress

Just to clarify: I indeed DO want to keep it as VLAN ID 1, because it is the default. On my Dell N1124P switch, it uses VLAN ID 1 as the "untagged" VLAN. This is already exactly what I want. The trunk ports from the Dell to the Mikrotik have the VLANs and then by default VLAN ID 1 is used for untagg...
by mkx
Tue Sep 08, 2020 8:08 am
Forum: General
Topic: Migration of CA
Replies: 11
Views: 729

Re: Migration of CA

b) Ditch old CA, create new one I'll sound as a smart arse ... but why on earth everybody wants to run just everything on a modest router? Running CA (for whatever reason) on a simple linux PC is much more trouble free ... and CA doesn't have to be online 24/7 if one doesn't bother with certificate...
by mkx
Tue Sep 08, 2020 7:57 am
Forum: Beginner Basics
Topic: Untagged and tagged VLANs in RouterOS
Replies: 6
Views: 462

Re: Untagged and tagged VLANs in RouterOS

Why untagged vlan 30 on the ethernet interface with the ont?? Because @zorrua wants to pass WAN to IPTV device transparently (i.e. in switched manner) and he's using VLAN30 (on the link between router and switch) for that. ONT delivers it untagged and IPTV device wants it untagged as well. @zorrua ...
by mkx
Mon Sep 07, 2020 8:57 am
Forum: SwOS
Topic: Looking for a competitive Switch
Replies: 2
Views: 440

Re: Looking for a competitive Switch

It seems MT currently doesn't have product with 1:1 functionality compared to TPlink you're looking at. The closest is CRS326-24G-2S (it comes in both IN and RM cases), but has only 2 SFP ports (versus 4 on TPlink) and doesn't (yet) support routing in HW (TPlink calls this feature "L2+ feature - sta...
by mkx
Mon Sep 07, 2020 8:44 am
Forum: General
Topic: How to remove 802.1Q header on "untagged" bridge egress
Replies: 25
Views: 1449

Re: How to remove 802.1Q header on "untagged" bridge egress

Here is my config: /interface bridge port add bridge=bridge1-lan interface=ether3-plato /interface bridge vlan add bridge=bridge1-lan comment=lan tagged=ether1-switch,ether2-shop vlan-ids=1 add bridge=bridge1-lan comment=wanonly tagged=bridge1-lan,ether1-switch,ether2-shop vlan-ids=2 add bridge=bri...
by mkx
Fri Sep 04, 2020 11:40 pm
Forum: General
Topic: CRS328-24P and 10GB SFP (Bridge Mode) Bandwidth slow
Replies: 2
Views: 235

Re: CRS328-24P and 10GB SFP (Bridge Mode) Bandwidth slow

Bandwidth test consumes awfully lots of CPU power on devices running it. Hence it should not be used on weak devices with fast interfaces such as CRS328. You really should use separate devices to generate traffic (e.g. fast machines running iperf) connected like this: PC_1 <--10Gbps--> CRS328_1 <--1...
by mkx
Fri Sep 04, 2020 9:24 am
Forum: General
Topic: No dst-nat support for shifted portmap ranges?
Replies: 20
Views: 3238

Re: dst-nat 'to-port=start-end' range bug?

Seems it's been available since iptables 1.8.0 - https://lwn.net/Articles/759184/ Turns out (or, seems to, at least) that this is not a bug in RouterOS, but probably a limitation in some of its dependencies and/or implementation I guess Mikrotik staff will give you a definitive answer. However, ROS...
by mkx
Fri Sep 04, 2020 8:59 am
Forum: General
Topic: Question: How to convert my "old-style" bridges to "new-style" VLAN filter bridge [SOLVED]
Replies: 5
Views: 1535

Re: Question: How to convert my "old-style" bridges to "new-style" VLAN filter bridge [SOLVED]

I made one essential addition, which is to set the EOIP tunnel to untagged. Just for the record: if a bridge interface has pvid set in section /interface bridge port , then it's automatically added to list of untagged members of same VLAN in /interface bridge vlan . Hence your addition is good, it ...
by mkx
Fri Sep 04, 2020 8:53 am
Forum: Beginner Basics
Topic: IP is leased but no internet access [SOLVED]
Replies: 7
Views: 379

Re: IP is leased but no internet access [SOLVED]

There is no such thing as "unamanged MikroTik switch". So write a bit more about it: model, OS run and how it's configured. If it's left to default config, it may well interfere with the rest of your LAN.
by mkx
Fri Sep 04, 2020 8:23 am
Forum: Beginner Basics
Topic: Multiple subnets on one eth
Replies: 16
Views: 671

Re: Multiple subnets on one eth

can multiple vlans be configured on a single interface?

Yes. That's the whole point of using VLANs.
by mkx
Wed Sep 02, 2020 9:27 pm
Forum: General
Topic: Can't route vlan
Replies: 2
Views: 201

Re: Can't route vlan

The way you configured VLANs on Dell is calling for trouble. Read through this tutorial and do it in modern way.
by mkx
Wed Sep 02, 2020 9:17 pm
Forum: General
Topic: Question: How to convert my "old-style" bridges to "new-style" VLAN filter bridge [SOLVED]
Replies: 5
Views: 1535

Re: Question: How to convert my "old-style" bridges to "new-style" VLAN filter bridge [SOLVED]

So traffic going through EOIP should go untagged? If so, create eoip as previously, but add it to "all VLAN" bridge like this: /interface bridge port add bridge=bridge interface=EOIP-HETZNER pvid=400 frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes The "excess" properties ar...
by mkx
Wed Sep 02, 2020 8:29 am
Forum: General
Topic: How set logs back to default? [SOLVED]
Replies: 3
Views: 293

Re: How set logs back to default? [SOLVED]

There are two places which configure logging: /system logging action and /system logging . The former is more general and sets destinations of log messages, while the later configure actual logs to be generated (and stored). By default, there are 4 entries in /system logging : [user@router] /system ...
by mkx
Wed Sep 02, 2020 8:11 am
Forum: Beginner Basics
Topic: CAPsMAN Local forwarding vs bridging all ports on the CAP
Replies: 3
Views: 322

Re: CAPsMAN Local forwarding vs bridging all ports on the CAP

The CAPsMAN setting local-forwarding governs the path traffic from wireless interface towards other (LAN) devices will take. If set to yes, then traffic will go via normal path (whatever configured) in each of CAP. The most usual path is that wireless interface is member of bridge and then the traff...
by mkx
Wed Sep 02, 2020 7:49 am
Forum: Beginner Basics
Topic: Capman Question
Replies: 1
Views: 142

Re: Capman Question

Both types of devices have same CPU, hence from performance point of view this criterion doesn't matter. My personal choice would be to configure all management features (DHCP server, CAPsMAN, ...) on main unit, which in your case is the SXT. The reason is simple: all of these services are points of...
by mkx
Tue Sep 01, 2020 4:49 pm
Forum: Wireless Networking
Topic: After enabling multicast-helper mt wireless bridges dont work anymore
Replies: 20
Views: 864

Re: After enabling multicast-helper mt wireless bridges dont work anymore

Let's verify the setup: you have AP, controlled by CAPsMAN. And then you have two wireless (client) devices, both connecting to before mentioned AP, each connecting a wired printer to the rest of network. I just hope you don't intend to provision the client wireless devices via CAPsMAN over the very...
by mkx
Tue Sep 01, 2020 2:30 pm
Forum: General
Topic: Question: How to convert my "old-style" bridges to "new-style" VLAN filter bridge [SOLVED]
Replies: 5
Views: 1535

Re: Question: How to convert my "old-style" bridges to "new-style" VLAN filter bridge [SOLVED]

You really should go through this excellent tutorial . But anyways: /interface bridge add name=bridge vlan-filtering=yes /interface ethernet set [ find default-name=ether1 ] disable-running-check=no name=SFP /interface bridge port add bridge=bridge interface=SFP /interface bridge vlan add bridge=bri...
by mkx
Tue Sep 01, 2020 2:11 pm
Forum: General
Topic: RouterOS Firewall configuration when using a bridge with multiple VLANs
Replies: 2
Views: 1247

Re: RouterOS Firewall configuration when using a bridge with multiple VLANs

When moving to a single bridge instead, I'm not sure how I would rewrite those rules. If I rewrote them using IP addresses, someone could set an IP to another VLAN and access a service they shouldn't, bypassing the firewall. What is the recommended approach in this case? As @mada3k already mentione...
by mkx
Tue Sep 01, 2020 2:07 pm
Forum: General
Topic: Limiting local bandwidth between ips (same subnet) [SOLVED]
Replies: 6
Views: 758

Re: Limiting local bandwidth between ips (same subnet) [SOLVED]

The cpu is 100% and the traffic is 90MBit from previous 900MBit. The question is, is it possible to put some firewall rule,masquarade,etc to make it fast as before? It might be possible (I wouldn't hope for miracle though, RB951G is no beast) ... but you have to post full config of your router (as ...
by mkx
Mon Aug 31, 2020 11:15 pm
Forum: RouterBOARD hardware
Topic: 16 port short depth PoE switch
Replies: 9
Views: 679

Re: 16 port short depth PoE switch

They could make some ears to accommodate us both. I think it is a needed SKU.

No, not RB4011 again ... They really should produce one device with two different cases (IN and RM), just like they did with RB2011 or certain models of CCR1009...
by mkx
Mon Aug 31, 2020 11:05 pm
Forum: General
Topic: Block access to inter-VLAN Router IPs
Replies: 13
Views: 432

Re: Block access to inter-VLAN Router IPs

What you want is achieved in the way @anav indicated and @sob further elaborated. A typical Mikrotik device running ROS performs two quite distinct functions: router Router with multiple interfaces (either physical, such as ethernet or wireless, or virtual, such as VLAN or IPIP or PPP*) configured w...
by mkx
Mon Aug 31, 2020 10:44 pm
Forum: Beginner Basics
Topic: [Q] how to add multiple firewall ip address in a single list?
Replies: 5
Views: 284

Re: [Q] how to add multiple firewall ip address in a single list?

Commands, posted by @mrz, create single address list with certain name and add multiple IP addresses (or, by defining subnet mask, rather multiple IP subnets). That address list can then be referred in certain firewall rules. If you describe a particular use case, we can show you how to use address ...
by mkx
Mon Aug 31, 2020 8:45 pm
Forum: SwOS
Topic: Loopback not working CRS305-1G-4S+IN
Replies: 5
Views: 342

Re: Loopback not working CRS305-1G-4S+IN

Unfortunately (or fortunately, depends on point of view) all Mikrotik routers are configured the same way. Indeed that way is not the easiest one, e.g. before mentioned hair-pin NAT can not be simply enabled, one has to configure a few NAT rules. If you feel you're not up to such tasks, then RouterO...
by mkx
Mon Aug 31, 2020 8:30 pm
Forum: General
Topic: Vlan between Cisco and Mikrotik
Replies: 5
Views: 325

Re: Vlan between Cisco and Mikrotik

Just configure multiple tagged VLANs on single port ... that's what trunk port is all about. And such concepts are mentioned (if not explained) in linked tutorial.
by mkx
Mon Aug 31, 2020 4:25 pm
Forum: General
Topic: Vlan between Cisco and Mikrotik
Replies: 5
Views: 325

Re: Vlan between Cisco and Mikrotik

For starters, follow the guide I linked. Your device has a fairly nice switch chip built in and you can change the setup later on to facilitate switch chip functionality if the performance of RB951U will not be good enough.
by mkx
Mon Aug 31, 2020 4:22 pm
Forum: RouterBOARD hardware
Topic: Adding a fan to CRS305-1G-4S+IN
Replies: 1
Views: 188

Re: Adding a fan to CRS305-1G-4S+IN

I guess if I solder into PoE rail (after transformer I guess) it should give me 48v to work with?

You'll get whatever you're powering the device with. Per spec it's anything between 12V and 57V ... but yes, if you power the device off a 802.3af/at PoE switch, it'll be around 48V.
by mkx
Mon Aug 31, 2020 4:13 pm
Forum: General
Topic: Vlan between Cisco and Mikrotik
Replies: 5
Views: 325

Re: Vlan between Cisco and Mikrotik

You can go through this tutorial to get idea about how VLANs are configured on Mikrotik. You did not mention which particular MT device type you're trying to configure so it might be that the way of configuring explained in linked tutorial will not be the fastest one, most of MT devices support VLAN...
by mkx
Mon Aug 31, 2020 9:05 am
Forum: SwOS
Topic: Loopback not working CRS305-1G-4S+IN
Replies: 5
Views: 342

Re: Loopback not working CRS305-1G-4S+IN

When you connect equipment directly to C5400X, you probably use separate port for NAS. Which might indicate that TP-Link supports hair-pin NAT only between different interfaces. In ROS world this would indicate partial implementation of functionality (without SRC-NAT part) which means that server (N...
by mkx
Mon Aug 31, 2020 8:51 am
Forum: RouterBOARD hardware
Topic: 16 port short depth PoE switch
Replies: 9
Views: 679

Re: 16 port short depth PoE switch

Any news of a possible CRS328-16P-4S+RM on the horizon?

Technically it would be a CRS320-16P-4S+RM ...
by mkx
Sun Aug 30, 2020 10:30 pm
Forum: General
Topic: Hap Ac2 CPU usage during speedtest.
Replies: 8
Views: 455

Re: Hap Ac2 CPU usage during speedtest.

That still leaves you 82% of CPU totally unused. Well, it's a 4-core CPU. A single-threaded load can cause 100% usage on one of these cores and you will only see 25% global CPU usage. Ookla speedtest nowdays is multi-stream, hence it should scale well on multi-core routers. I fully agree with @xvo ...
by mkx
Sun Aug 30, 2020 10:21 pm
Forum: General
Topic: Limiting local bandwidth between ips (same subnet) [SOLVED]
Replies: 6
Views: 758

Re: Limiting local bandwidth between ips (same subnet) [SOLVED]

Basic reason why it doesn't work for you is that traffic within same subnet is switched and not routed. In your particular case it's handled by switch chip of RB951G as indicated by the 'H' flag on your first screenshot (it means HW-offloaded). You might get things working, but you have to make sure...
by mkx
Sun Aug 30, 2020 8:38 pm
Forum: General
Topic: High CPU with VLAN<->LAN interactions
Replies: 3
Views: 291

Re: High CPU with VLAN<->LAN interactions

Go through ethernet routers in product page . Look at physical properties (e.g. number of ethernet ports and speed of thereof) and check Test results . Routing capacity is listed under Ethernet test results , the number which is closest to real-life performance[*] in majority of use cases is listed ...
by mkx
Fri Aug 28, 2020 6:17 pm
Forum: Beginner Basics
Topic: VLAN help
Replies: 8
Views: 463

Re: VLAN help

Wiki examples assume no pre-existing config. When you start off with device which already has some config, it is indeed a bit tougher. In your case, where ether1 is already member of a bridge, you should simply set [ find interface=ether1 ] pvid=10 .. Etc.
by mkx
Fri Aug 28, 2020 5:49 pm
Forum: Beginner Basics
Topic: Different DHCP Pool for VLANs
Replies: 4
Views: 345

Re: Different DHCP Pool for VLANs

Your VLAN setup is pretty much botched. Read through this tutorial, it should help set VLANs right.
by mkx
Tue Aug 25, 2020 8:07 pm
Forum: General
Topic: High CPU with VLAN<->LAN interactions
Replies: 3
Views: 291

Re: High CPU with VLAN<->LAN interactions

RB750UP is not really a speed monster. Which means its setup has to be really fine tuned to get decent performance.

I'd say that posting complete config (run /export hide-senditive and post all output) would allow us to see if there's something to improve.
by mkx
Tue Aug 25, 2020 8:00 pm
Forum: Beginner Basics
Topic: Hap ac lite wont reach given data by my isp
Replies: 4
Views: 220

Re: Hap ac lite wont reach given data by my isp

Even if device had 1Gbps interfaces, it is not powerful enough to route faster than something around 170Mbps (and that's with fairly simple firewall setup which enables fasttracking most of traffic).
by mkx
Tue Aug 25, 2020 7:38 pm
Forum: Wireless Networking
Topic: SSIDs with vlans and default SSID [SOLVED]
Replies: 1
Views: 205

Re: SSIDs with vlans and default SSID [SOLVED]

Real wlan interface has to be up&running for virtual ones to work. So why don't you change settings of real wlan interface to one of needed ones? You'll end up with one real wlan interface and one virtual wlan interface for total of 2 SSIDs.
by mkx
Tue Aug 25, 2020 7:34 pm
Forum: Wireless Networking
Topic: Support for 2.4GHz
Replies: 13
Views: 958

Re: Support for 2.4GHz

DHCP is basically an L2 service and there can only be one DHCP server (well, there can be multiple for redundancy, but their lease state should better be synchronized). But then ... seamless client mobility doesn't go with ability to locate client based on IP address. Even if it was possible to assi...
by mkx
Tue Aug 25, 2020 3:51 pm
Forum: Wireless Networking
Topic: hAP ac^2 Wi-fi signal -- clients prefers 2.4GHz than 5GHz
Replies: 17
Views: 851

Re: hAP ac^2 Wi-fi signal -- clients prefers 2.4GHz than 5GHz

New Android and Windows10 use by default now the option to "randomize" the MAC address for each Wifi connection. Did anybody bother to check the following: leave MAC address setting to dynamic (or random or whatever it's called), connect to wireless network and then roam from one AP to another AP w...
by mkx
Tue Aug 25, 2020 3:30 pm
Forum: Wireless Networking
Topic: Support for 2.4GHz
Replies: 13
Views: 958

Re: Support for 2.4GHz

Can I at least separate each hAP lite to a different subnet and use same SSID for all of them or it is not recommended? No. As I wrote: when wireless client roams to another AP with same SSID, it will not reconfigure IP settings. And if different AP is in different subnet, this will break client's ...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 16