Community discussions

MikroTik App

Search found 5457 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 19
by mkx
Sat Mar 06, 2021 3:46 pm
Forum: General
Topic: make the source's IP address visible in an external DNS filter?
Replies: 2
Views: 136

Re: make the source's IP address visible in an external DNS filter?

Simplest config would be if you directed clients to use 10.10.10.1 as their DNS server. In that case you don't need any of shown NAT rules, single rule performing SRC-NAT for traffic towards WAN would do (a limited version of your current last rule). If your clients are configured to use whatever DN...
by mkx
Sat Mar 06, 2021 3:30 pm
Forum: Announcements
Topic: WinBox v3.27 released!
Replies: 98
Views: 18084

Re: WinBox v3.27 released!

They're provisioning everything on their RADIUS server ...
by mkx
Sat Mar 06, 2021 3:26 pm
Forum: General
Topic: VLAN setup for CCR1016 and CRS226
Replies: 8
Views: 425

Re: VLAN setup for CCR1016 and CRS226

1. Port-based VLAN versus bridge vlan filtering depends whether you want to use device as router/switch combo or as plain router. The guy in video is using leftmost device as plain router and bridge is not needed at all. If you want to use multiple ports on CCR to carry same (V)LAN, then you should ...
by mkx
Fri Mar 05, 2021 11:28 pm
Forum: RouterBOARD hardware
Topic: S-RJ01 SFP Module in RB4011iGS+ flapping
Replies: 2
Views: 165

Re: S-RJ01 SFP Module in RB4011iGS+ flapping

Known issue with most (if not all) RJ45 SFP modules is excessive heating due to high power needed to transmit data at 1Gbps through UTP cable. Long stretch (70 metres) adds to the problem. RB4011 being passively cooled device adds (big time) as well. I suggest you to keep using the ether1 port until...
by mkx
Fri Mar 05, 2021 11:52 am
Forum: RouterBOARD hardware
Topic: What sort of write speeds should I expect from a modern SDXC card in my CCR1009-8G-1S-1S+?
Replies: 3
Views: 250

Re: What sort of write speeds should I expect from a modern SDXC card in my CCR1009-8G-1S-1S+?

How are you using the SD card? Over network using CIFS? CIFS server is known to be slow in ROS, RB device is not intended to replace NAS device.
by mkx
Fri Mar 05, 2021 11:48 am
Forum: Wireless Networking
Topic: Wireless Network Error (Urgent issue)
Replies: 1
Views: 103

Re: Wireless Network Error (Urgent issue)

Investigate if RF channels, used for links 1-2, 3-4 and 5-6 overlap. Note that it's not enough that these use different channel numbers, it is necessary that there's no overlap of channels used. Use this document to verify frequency ranges used by individual channels (depending on channel width).
by mkx
Fri Mar 05, 2021 11:34 am
Forum: General
Topic: Omnitik AC PoE injector voltage
Replies: 4
Views: 261

Re: Omnitik AC PoE injector voltage

so I'm guessing additional load increases the power requirement It does. It is "only a few watts", but that can mean that voltage drop on the UTP cable becomes just a tad too big. As you're powering the gear off a battery, you may want to do some measurements of efficiency of the DC upcon...
by mkx
Fri Mar 05, 2021 11:06 am
Forum: Beginner Basics
Topic: Weird LTE and ADSL setup, is it possible?
Replies: 8
Views: 344

Re: Weird LTE and ADSL setup, is it possible?

Your case is slightly different then the case from your links as both paths are completely separate (not the case with second link) and have pretty different characteristics (not the case with first link). You may get better results if using policy-based routing.
by mkx
Thu Mar 04, 2021 9:05 pm
Forum: General
Topic: 100mb port slowing down 1000mb port
Replies: 3
Views: 256

Re: 100mb port slowing down 1000mb port

Not sure if buffer on switch is per-port or is it common for while switch chip. If it's later, then a slow port can exhaust buffer making faster ports suffer.
by mkx
Thu Mar 04, 2021 8:55 pm
Forum: General
Topic: NVMe and X86
Replies: 4
Views: 310

Re: NVMe and X86

v7 will have much better support for most of hardware, including x64, support for more than 2GB RAM (also on CCR2004 IIRC), many more supported peripherials under i386/x64 (storage devices, 10Gbps+ NICs, broadband USB sticks, ...). Could well be that lack of x64 support in v6 is due to proprietary d...
by mkx
Thu Mar 04, 2021 6:12 pm
Forum: Beginner Basics
Topic: CCR2004 Beginner inter-VLAN Routing and upstream LAN questions
Replies: 14
Views: 686

Re: CCR2004 Beginner inter-VLAN Routing and upstream LAN questions

It seems a workable configuration, possibly something will pop up when you try to actually use it ;-) Another question: does the LAN GW (@10.13.2.1) know about CCR2004 being gateway for subnets 172.26.11.0/24, 172.26.12.0/24 and 172.26.13.0/24? If it doesn't, you'll have to configure some NAT on CCR...
by mkx
Thu Mar 04, 2021 9:17 am
Forum: Beginner Basics
Topic: CRS317 trunk VLAN configuration help
Replies: 5
Views: 268

Re: CRS317 trunk VLAN configuration help

One thing: switch (and you're using CRS317 as a switch) doesn't need VLAN interfaces for all VLANs that are passed between switched ports. Meaning you only need interface for management LAN (in your case that's ether1 used as MGMT interface ), but you don't need any of vlan 26xx-* interfaces. For OO...
by mkx
Thu Mar 04, 2021 9:06 am
Forum: Beginner Basics
Topic: CCR2004 Beginner inter-VLAN Routing and upstream LAN questions
Replies: 14
Views: 686

Re: CCR2004 Beginner inter-VLAN Routing and upstream LAN questions

You still have a problem: both WAN and MGMT interfaces are members of same IP subnet but the interfaces are not members of same L2 subnet (which is usually necessary). /interface ethernet set [ find default-name=ether1 ] name=MGMT /ip address add address=10.13.2.13/24 interface=MGMT network=10.13.2....
by mkx
Thu Mar 04, 2021 1:16 am
Forum: Beginner Basics
Topic: CCR2004 Beginner inter-VLAN Routing and upstream LAN questions
Replies: 14
Views: 686

Re: CCR2004 Beginner inter-VLAN Routing and upstream LAN questions

There are L2 ports , which are bridged together to single L2 (ethernet) domain. All member ports have to use same max MTU size (not to overrun some interface). Bridge switches ethernet frames between member ports according to MAC table. There are L3 interfaces which carry IP (or IPv6) addresses. Rou...
by mkx
Thu Mar 04, 2021 12:47 am
Forum: Wireless Networking
Topic: Anyone who successfully install wifiwave2 on cAP ac with 256M RAM ?
Replies: 9
Views: 484

Re: Anyone who successfully install wifiwave2 on cAP ac with 256M RAM ?

There was a discussion about required HW for wave2 drivers and disk size larger than 16MB was IIRC one of them. Supported devices (Audience, hAP ac3) have 128MB storage ...
by mkx
Thu Mar 04, 2021 12:36 am
Forum: Beginner Basics
Topic: Setting up 1Gbps MGMT port on CRS317 and CCR2004 for out of band management
Replies: 6
Views: 282

Re: Setting up 1Gbps MGMT port on CRS317 and CCR2004 for out of band management

What @joegoldman wrote, is advanced stuff. According to the network topology chart you don't need any advanced stuff (you only have one upstream gateway from CCR2004 so no VRFs or other bells and whistles).
by mkx
Thu Mar 04, 2021 12:31 am
Forum: Beginner Basics
Topic: CCR2004 Beginner inter-VLAN Routing and upstream LAN questions
Replies: 14
Views: 686

Re: CCR2004 Beginner inter-VLAN Routing and upstream LAN questions

Your setup as per network diagram would actually work without any bridge. You actually set up things that way, you just don't know what to do with bridge. Just omit all setup under /interface bridge . And in order for MGMT to work, you'd have to rename interface ether1 to MGMT: /interface ethernet s...
by mkx
Wed Mar 03, 2021 11:56 pm
Forum: Beginner Basics
Topic: Setting up 1Gbps MGMT port on CRS317 and CCR2004 for out of band management
Replies: 6
Views: 282

Re: Setting up 1Gbps MGMT port on CRS317 and CCR2004 for out of band management

If you don't go into some advanced stuff, then ROS will route through interfaces with appropriate IP address set. E.g. if you have bridge1 with sfp-sfpplus1,sfp-sfpplus2 and sfp-sfpplus3, bridge2 with sfp-sfpplus4,sfp-sfpplus5 and sfp-sfpplus6 and ether1 (for OOB management), then you will probably ...
by mkx
Wed Mar 03, 2021 10:01 pm
Forum: RouterBOARD hardware
Topic: New CRS328-16P-4S+RM rumors
Replies: 5
Views: 435

Re: New CRS328-16P-4S+RM rumors

Not gonna happen. With that port spec, it would be CRS320-16P-4S+RM.
by mkx
Wed Mar 03, 2021 9:56 pm
Forum: Wireless Networking
Topic: Anyone who successfully install wifiwave2 on cAP ac with 256M RAM ?
Replies: 9
Views: 484

Re: Anyone who successfully install wifiwave2 on cAP ac with 256M RAM ?

Surely log has something regarding failed package installation?
by mkx
Wed Mar 03, 2021 9:44 pm
Forum: General
Topic: NVMe and X86
Replies: 4
Views: 310

Re: NVMe and X86

ROSv6 is based on linux kernel which pre-dates NVMe hardware, so I don't think ROSv6 will ever work off NVMe. ROSv7 might work, though it's in late alpha / early beta stage.
by mkx
Wed Mar 03, 2021 9:37 pm
Forum: Beginner Basics
Topic: Seperating one part of the network. [SOLVED]
Replies: 10
Views: 507

Re: Seperating one part of the network. [SOLVED]

If you only want to isolate LAN beyond ether2, then only perform steps I listed for ether2. E.g. remove ether2 from bridge, set IP address from a new IP subnet to ether2, add DHCP server on ether2 (with appropriate settings for selected subnet), add appropriate firewall rules which will block connec...
by mkx
Wed Mar 03, 2021 9:27 pm
Forum: Beginner Basics
Topic: Setting up 1Gbps MGMT port on CRS317 and CCR2004 for out of band management
Replies: 6
Views: 282

Re: Setting up 1Gbps MGMT port on CRS317 and CCR2004 for out of band management

In ROS, every interface (ethernet, SFP, wireless, tunel endpoints, ...) can be used either standalone or as bridge port. Management interface on CRS317 will appear as ether1 and you can set up L3 settings for management lan directly on ether1. I guess you'll want SFP+ ports (appearing as sfp-sfpplus...
by mkx
Wed Mar 03, 2021 6:11 pm
Forum: General
Topic: Possible fix for hAP ac2 rebooting randomly
Replies: 111
Views: 23168

Re: Possible fix for hAP ac2 rebooting randomly

I didn't see my hAP ac2 reboot since 6.43.something. I've always had ntp package installed and active. I'm also using IPsec (implicitly, I'm running ipip tunnels). Current uptime with 6.47.9 is 20 days (since I upgraded ROS).
by mkx
Wed Mar 03, 2021 6:00 pm
Forum: Beginner Basics
Topic: Seperating one part of the network. [SOLVED]
Replies: 10
Views: 507

Re: Seperating one part of the network. [SOLVED]

It would, but his current setup is default which "only" drops everything from WAN. I was writing task list according to his current config, not according to your golden standard.
by mkx
Wed Mar 03, 2021 4:33 pm
Forum: Beginner Basics
Topic: Seperating one part of the network. [SOLVED]
Replies: 10
Views: 507

Re: Seperating one part of the network. [SOLVED]

You did not clarify about how dumb switches in buildings are connected to RB4011. Assuming each of those switches is connected to individual ethernet ports of RB4011 and assuming you want to run one subnet per building, then: construct 4 subnet pools for DHCP servers remove appropriate ethernet port...
by mkx
Wed Mar 03, 2021 10:04 am
Forum: Beginner Basics
Topic: Seperating one part of the network. [SOLVED]
Replies: 10
Views: 507

Re: Seperating one part of the network. [SOLVED]

Network diagram is needed indeed. The simplest network topology with one subnet per building and one building per RB4011 ethernet port does not require smart switches and VLANs, some reconfiguration of RB4011 will do. However if you want to segment networks in the buildings (or have flexible configu...
by mkx
Wed Mar 03, 2021 9:56 am
Forum: Beginner Basics
Topic: Setting Up Nat (Properly)
Replies: 1
Views: 147

Re: Setting Up Nat (Properly)

The src-nat rules are "too greedy": add action=src-nat chain=srcnat src-address=192.168.1.0/24 to-addresses=xxx.xxx.xxx.250 add action=src-nat chain=srcnat src-address=192.168.2.0/24 to-addresses=xxx.xxx.xxx.252 add action=src-nat chain=srcnat src-address=10.0.0.0/24 to-addresses=xxx.xxx.x...
by mkx
Wed Mar 03, 2021 9:42 am
Forum: RouterOS v7 BETA
Topic: v7.1beta4 [development] is released!
Replies: 185
Views: 24159

Re: v7.1beta4 [development] is released!

I'd say it's the issue with linux kernel and drivers and as such not very likely to go away in ROS. I checked on my ubuntu desktop, running linux kernel 5.4 on CPU with 4 cores (and HT). Most peripherials (e.g. built-in USB hub, ethernet NIC, sound card, ...) see their interrupts served by same logi...
by mkx
Tue Mar 02, 2021 11:35 pm
Forum: Wireless Networking
Topic: CAPsMAN - CAPs are re-connecting in different intervals and timeout during re-connect with CAPsMAN [SOLVED]
Replies: 6
Views: 5147

Re: CAPsMAN - CAPs are re-connecting in different intervals and timeout during re-connect with CAPsMAN [SOLVED]

This is one of default firewall filter rules, present in SOHO line in 6.47.9:
/ip firewall filter 
add chain=input action=accept dst-address=127.0.0.1 comment="defconf: accept to local loopback (for CAPsMAN)"
by mkx
Tue Mar 02, 2021 8:51 pm
Forum: Beginner Basics
Topic: RouterOS - Newbie CCR1009-7G-1C-1S+
Replies: 12
Views: 572

Re: RouterOS - Newbie CCR1009-7G-1C-1S+

To use the 10G sfp to connect to my switch instead of ether2 do I need to somehow add it to the bridge?

Yes, add sfp-sfpplus1 to bridge local. After that you'll be able to replace ethernet connection with SFP.
by mkx
Mon Mar 01, 2021 11:40 pm
Forum: Beginner Basics
Topic: RouterOS - Newbie CCR1009-7G-1C-1S+
Replies: 12
Views: 572

Re: RouterOS - Newbie CCR1009-7G-1C-1S+

Doesn't look like. But examination of textual export would tell. Execute /export hide-sensitive file=anynameyouwish in terminal windiw, fetch resulting file and copy-paste contents into [ code] [/code] block (square brackets icon just above post editing window). You may want to skim through config a...
by mkx
Mon Mar 01, 2021 10:11 pm
Forum: Beginner Basics
Topic: RouterOS - Newbie CCR1009-7G-1C-1S+
Replies: 12
Views: 572

Re: RouterOS - Newbie CCR1009-7G-1C-1S+

First answer to question #3: it happens, but it's not normal. It means that firewall does not block these connection attempts so you actually see attempts (hopefully it stays at attempts). And that means you have to do something about firewall. If you just started off with configuring your router, t...
by mkx
Mon Mar 01, 2021 9:08 pm
Forum: Wireless Networking
Topic: WIFI 6 Roadmap
Replies: 80
Views: 41610

Re: WIFI 6 Roadmap

If that really works all around, wifi will be irrelevant in the next decade. It does work if user only cares about internet and there's LOS between device and base station (forget about 600Mbps when in toilet or wine cellar). OTOH if one has home LAN with services reserved for LAN users, wifi will ...
by mkx
Mon Mar 01, 2021 7:05 pm
Forum: General
Topic: How to advertise dynamic ipv6 prefix recieved from dhcpv6
Replies: 8
Views: 438

Re: How to advertise dynamic ipv6 prefix recieved from dhcpv6

Seems quite right to me. What I see on my LAN: router's link-local address is passed as IPv6 src address (dst address is ff02::1 which means "all nodes" according to RFC4291) ... and it seems that SLAAC clients take this address as proper default gateway. setting "Router lifetime (s)&...
by mkx
Mon Mar 01, 2021 6:17 pm
Forum: Beginner Basics
Topic: IP range can ping its range and another but other range cant ping another range but can ping its range
Replies: 6
Views: 260

Re: IP range can ping its range and another but other range cant ping another range but can ping its range

These settings won't allow device to route between subnets, it's switching between ethernet interfaces. Instead, you should end up with configuration like this: /ip address add interface=ether3 address=192.168.8.42/24 # adjust address to what other devices in 192.168.8.0/24 expect add interface=ethe...
by mkx
Mon Mar 01, 2021 2:49 pm
Forum: Beginner Basics
Topic: IP range can ping its range and another but other range cant ping another range but can ping its range
Replies: 6
Views: 260

Re: IP range can ping its range and another but other range cant ping another range but can ping its range

If the only functionality you need is routing between two subnets, then current config is overly complicated and in large part simply wrong (e.g. both interfaces are bridged while they shouldn't be, you have SRC-NAT enabled, ...). Fetch winbox, then reset router to no configuration. Connect using wi...
by mkx
Mon Mar 01, 2021 2:15 pm
Forum: Beginner Basics
Topic: IP range can ping its range and another but other range cant ping another range but can ping its range
Replies: 6
Views: 260

Re: IP range can ping its range and another but other range cant ping another range but can ping its range

With router having addresses properly set[*] on two interfaces (and having proper network mask set, in your case subnet mask is most probably /24 in both cases) and without anything in firewall, router will pass all packets between both subnets ... if those packets arrive at router, which implies pr...
by mkx
Sat Feb 27, 2021 3:36 pm
Forum: Beginner Basics
Topic: Disable Use default gateway on remote network - cant ping internal network
Replies: 3
Views: 250

Re: Disable Use default gateway on remote network - cant ping internal network

I don't think Mikrotik (if that's your local router) has anything to do with it, it's your VPN which is greedy taking over all of traffic. Many VPN setups do it, excuse is that if a PC becomes member of another LAN (via VPN), it should not become potential bridge between both LANs. Depending on VPN ...
by mkx
Sat Feb 27, 2021 1:33 pm
Forum: Beginner Basics
Topic: Disable Use default gateway on remote network - cant ping internal network
Replies: 3
Views: 250

Re: Disable Use default gateway on remote network - cant ping internal network

Run command /ip route print with gateway setting enabled and disabled and see what is tge difference.
by mkx
Sat Feb 27, 2021 12:51 am
Forum: General
Topic: Restore binary backup of RB751G to RB962
Replies: 1
Views: 169

Re: Restore binary backup of RB751G to RB962

No way. Binary backup can only be restored on same model ... and even that is not recomended due to some settings which override HW properties of "receiver" (e.g. interface MAC addresses). Which means you have to re-do the config on your new router anyway. If you had text export from RB751...
by mkx
Fri Feb 26, 2021 9:13 pm
Forum: RouterBOARD hardware
Topic: Block diagram bandwidth
Replies: 1
Views: 201

Re: Block diagram bandwidth

Interconnects are (almost) always full-duplex.
by mkx
Fri Feb 26, 2021 8:32 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta4 [development] is released!
Replies: 185
Views: 24159

Re: v7.1beta4 [development] is released!

Betas in v7 line come out quite infrequently. I expect most of new functionality in v6 to land in v7 betas soon. However in v7 quite a few old functions from v6 are missing and I guess development in v6 and in v7 is not parallel at the moment.
by mkx
Wed Feb 24, 2021 11:55 pm
Forum: Wireless Networking
Topic: cAP AC Access Points... best quick set? (resolved with no quick set as best option, but solution provided) [SOLVED]
Replies: 22
Views: 988

Re: cAP AC Access Points... best quick set? [SOLVED]

So it seems there isn't a quick-set that would entirely fit your requirements. What you can do is start off with quick-set which serms closest to what you require and make remaining changes manually. I don't have much experience with quick-set, but it seems that "Home Dual AP" is close. I'...
by mkx
Wed Feb 24, 2021 11:46 pm
Forum: Announcements
Topic: v6.48.1 [stable] is released!
Replies: 100
Views: 19441

Re: v6.48.1 [stable] is released!

I'd replace cable connecting RB and UBNT ... marginal cable can cause lowering the negotiated speed.
by mkx
Wed Feb 24, 2021 10:51 pm
Forum: General
Topic: Add cooling fan to CRS-326-24P-2S+ ?
Replies: 50
Views: 2482

Re: Add cooling fan to CRS-326-24P-2S+ ?

It's the matter of controlling air flow. If there are only "suckers" at one side, then air will escape the unit everywhere. If you have a "sucker" and a "pusher", then air will mostly flow between the two fans. If device case and device internals are designed to force a...
by mkx
Wed Feb 24, 2021 4:18 pm
Forum: Beginner Basics
Topic: VLAN-Problems [SOLVED]
Replies: 18
Views: 1035

Re: VLAN-Problems [SOLVED]

I would expect DLAN to be transparent for VLANs (as is a dumb switch, only requirement is support for 1504 byte MTU). To rule this out, try to connect AP directly to ether3 of your mikrotik. If it still doesn't work, then its configuration mismatch. If it works with direct connection but doesn't wit...
by mkx
Wed Feb 24, 2021 11:26 am
Forum: Wireless Networking
Topic: Wireless VLAN Bridge
Replies: 2
Views: 167

Re: Wireless VLAN Bridge

If I understand you right, then AP sends tagged packets over wifi? The idea is this: wlan interface happily passes tagged frames, you just have to deal with tags on bridge. The wlan interface should not be configured with any of vlan-related properties, those are onky necessary if wlan interface its...
by mkx
Wed Feb 24, 2021 11:05 am
Forum: RouterOS v7 BETA
Topic: v7.1beta4 [development] is released!
Replies: 185
Views: 24159

Re: v7.1beta4 [development] is released!

Only if logs are sent elsewhere (not to memory), such as disk or network syslog server.
by mkx
Tue Feb 23, 2021 10:40 pm
Forum: Beginner Basics
Topic: Command Line....?
Replies: 2
Views: 175

Re: Command Line....?

Complete configuration tree is possible to get by executing /export (with optional parameters, such as verbose or terse or ... Use [tab] key to get printout of posible parameters).

If you're asking about (scripting) commands, then I don't know a way of getting complete list of commands ...
by mkx
Tue Feb 23, 2021 3:54 pm
Forum: Beginner Basics
Topic: help please
Replies: 10
Views: 439

Re: help please

Filter rules are matched from top to bottom. You want to push your blocking rule high on the list.

I've already explained the ports in my previous post.
by mkx
Tue Feb 23, 2021 3:51 pm
Forum: RouterBOARD hardware
Topic: recommendation to x86 hardware?
Replies: 3
Views: 276

Re: recommendation to x86 hardware?

If you intend to install ROS on bare metal, then you better wait for ROS v7. It will come with greatly improved support for modern NICs. If you intend to run CHR, then HW support is up to Hypervisor you're going to use. In any case I'd go for CPU with smaller number of high-performance CPU cores ......
by mkx
Tue Feb 23, 2021 3:40 pm
Forum: Beginner Basics
Topic: help please
Replies: 10
Views: 439

Re: help please

Port numbers are always the same on server's side (and are standard/well known). Port numbers on clients' side (source port in your case) are random and different each time, this is completely normal. What makes thing suspicious is number of clients conecting from same IP subnet, sometimes it indica...
by mkx
Tue Feb 23, 2021 3:33 pm
Forum: Wireless Networking
Topic: cAP AC Access Points... best quick set? (resolved with no quick set as best option, but solution provided) [SOLVED]
Replies: 22
Views: 988

Re: cAP AC Access Points... best quick set? [SOLVED]

Just to mention (even though it might be obvious): for CAPsMAN configuration you need wired connection between router and cAP.
by mkx
Tue Feb 23, 2021 3:28 pm
Forum: General
Topic: hAP-ac2 vs hAP-ac3 vs Audience wifi perfomance
Replies: 3
Views: 1510

Re: hAP-ac2 vs hAP-ac3 vs Audience wifi perfomance

The rumour goes that antennae of hAP ac3 are only uglier versions of those of hAP ac2 ... that performance is similar. Audience is a completely different beast on 5GHz though. It has two 5GHz radis, one is dual-stream and one is true quad-stream (MIMO 4x4). They can be used at the same time as they ...
by mkx
Tue Feb 23, 2021 3:19 pm
Forum: Wireless Networking
Topic: cAP AC Access Points... best quick set? (resolved with no quick set as best option, but solution provided) [SOLVED]
Replies: 22
Views: 988

Re: cAP AC Access Points... best quick set? [SOLVED]

Step #3 is done on cAP ac ... if cAP ac doesn't have wlan, then I don't know anything.
by mkx
Tue Feb 23, 2021 1:37 pm
Forum: General
Topic: too many packet per second with this outpu input: in:ether1 out:(unknown 0), src-mac , proto UDP, ->ip:53, len 71
Replies: 10
Views: 475

Re: too many packet per second with this outpu input: in:ether1 out:(unknown 0), src-mac , proto UDP, ->ip:53, len 71

It's about DNS service (UDP port 53) and should be blocked for internet connections. Default firewall blocks it already. It's not clear if these log lines are from a drop rule (which is then fine and you should stop logging it) or they are from accept rule which means you allowed those connections. ...
by mkx
Tue Feb 23, 2021 1:24 pm
Forum: General
Topic: Best low end poe-out switch?
Replies: 5
Views: 265

Re: Best low end poe-out switch?

As others mentioned: Mikrotik doesn't offer cheap switches with multiple PoE-out ports. So you'll probably have to look elsewhere. If you're after cheaper switch (CSS family in mikrotik world) with simple web-ui management and without L3 capabilities, then mikrotik might not be optimal choice anyway...
by mkx
Tue Feb 23, 2021 1:16 pm
Forum: Beginner Basics
Topic: help please
Replies: 10
Views: 439

Re: help please

It seems a whole /24 subnet of source addresses: 45.142.120.0/24 ... and occasionally some other src-address ... if this is gateway to a typical home network, then dst-ports are suspicious: plain sever-to-server SMTP (TCP port 25) and SMTP submission (TCP 587). If OP is not running kind of public em...
by mkx
Tue Feb 23, 2021 1:07 pm
Forum: Beginner Basics
Topic: Basic routing
Replies: 11
Views: 712

Re: Basic routing

If the command above fixes the problem, then proper solution (assuming most of firewall setup is default) is to add interface VLAN1425 to WAN interface list ... same as pppoe-out1. After that remove the setting above, it should not be necessary anymore.
by mkx
Mon Feb 22, 2021 11:58 pm
Forum: General
Topic: Best low end poe-out switch?
Replies: 5
Views: 265

Re: Best low end poe-out switch?

I'm not sure what's your definition of "low end". CRS328-24P-4S+RM seems to be the cheapest device offering 24 PoE out ports ...
by mkx
Mon Feb 22, 2021 7:04 pm
Forum: Beginner Basics
Topic: DELETE THIS TICKET [SOLVED]
Replies: 13
Views: 632

Re: see device on separate network [SOLVED]

Actually yes, both networks use IP 192.168.0.1 as gateway. Apart from suggestion by @anay (which is not out of place at all) ... so you have single Mikrotik router separating (at least) two LAN subnets and WAN? If you don't want to follow anav's advice, then you'll have to post current config of ro...
by mkx
Mon Feb 22, 2021 5:33 pm
Forum: Beginner Basics
Topic: DELETE THIS TICKET [SOLVED]
Replies: 13
Views: 632

Re: see device on separate network [SOLVED]

There's one major trouble: hospital network (192.168.0.0/16) "contains" pharmacy's network (192.168.41.0/24). If those are really network addresses in use, you'll have to perform NAT on mikrotik and for that you need to know details about communication between server and PC. The other prob...
by mkx
Sun Feb 21, 2021 10:29 pm
Forum: General
Topic: UDP Broadcast beetween two Bridge-Interfaces
Replies: 1
Views: 132

Re: UDP Broadcast beetween two Bridge-Interfaces

Your VLAN setup seems completeley screwed to me. I suggest you to slowly go through this tutorial . Other than that: one of most important points in dividing network to VLANs is to contain broadcast traffic within single subnet. If you need raspi to listen to Davis broadcasts, then raspi should be m...
by mkx
Sat Feb 20, 2021 4:24 pm
Forum: Wireless Networking
Topic: DHCP client on wlan not getting address [solved]
Replies: 3
Views: 299

Re: DHCP client on wlan not getting address [solved]

When using ROS device as wireless client, it doesn't matter what options you have enabled (e.g. tkip, b/g, ...) because client can not force AP to work in certain way, client has to follow AP's setup to certain degree and AP preferences overrule client's if both support same features. So if you disa...
by mkx
Wed Feb 17, 2021 10:01 pm
Forum: General
Topic: IPv6 and NAT - how I changed my mind
Replies: 31
Views: 13783

Re: IPv6 and NAT - how I changed my mind

At what point will I slowly convert? Will it first be my IP address given to me by the ISP is an IPV6 address and my LAN is IPV4? After that??? As stated I dont want my fridge IPV6 address to be accessible outside my router, unless talking to the fridge company cloud I suppose. Conceptually IPv6 is...
by mkx
Tue Feb 16, 2021 8:59 pm
Forum: Beginner Basics
Topic: Factory software downgrade
Replies: 1
Views: 163

Re: Factory software downgrade

There is no way to install ROS version lower than version installed in factory.
by mkx
Tue Feb 16, 2021 2:46 pm
Forum: Beginner Basics
Topic: Upgrade path from 6.40.5
Replies: 3
Views: 184

Re: Upgrade path from 6.40.5

I would: Make a full export ( /export file=anynameyoulike *) ) Reset device Upgrade to latest version Import the export file *) Do not forget to copy the export to a computer I'd do it differently: Make a full export ( /export file=anynameyoulike *) ) Upgrade to latest long-term version Reset devic...
by mkx
Tue Feb 16, 2021 1:52 pm
Forum: Beginner Basics
Topic: Confused why NAT not working..
Replies: 3
Views: 236

Re: Confused why NAT not working..

I think the show stopper is that firewall filter does not include rule which actually allows DST-NATed connections. Constructing DST-NAT rules is not enough in Mikrotik world (mind that this has its merits). Default configuration has a rule (the last in list) which combines allowing dst-nat-ed conne...
by mkx
Tue Feb 16, 2021 10:27 am
Forum: General
Topic: L2TP/IPSec VPN performance on 1G links
Replies: 4
Views: 366

Re: L2TP/IPSec VPN performance on 1G links

It seems that all CCR1009 have same CPU built in and I would assume that they all feature same HW encryption device with same performance. So you can have a look at performance tables of some other CCR1009. Performance table for CCR1009-7G-1C-1S+ indicates that realistic max IPsec throughput for sin...
by mkx
Tue Feb 16, 2021 10:13 am
Forum: Beginner Basics
Topic: speed-test between CCR2004 and CCR1009
Replies: 4
Views: 342

Re: speed-test between CCR2004 and CCR1009

/tool speed-test is quite heavy on router's CPU and can easily be bottleneck itself. So if you really want to check VPN throughput, use PCs connected to each router and run iperf test through routers and connection between them. Other than that, both CCR2004 and CCR1009 support HW encryption for VP...
by mkx
Mon Feb 15, 2021 9:21 pm
Forum: General
Topic: DHCP Client
Replies: 15
Views: 4319

Re: DHCP Client

I'm not saying DHCP client in ROS is bug free. I'm just saying that regarding re-lease timer ROS DHCP client works according to RFC and that @sjafka was looking at wrong symptom (which is clearly explained by RFC linked by @tippenring). IMO the only problematic thing was you laughing at @tippenring ...
by mkx
Mon Feb 15, 2021 8:35 pm
Forum: Beginner Basics
Topic: Rb4011+IPv6 from ISP - Problem
Replies: 6
Views: 403

Re: Rb4011+IPv6 from ISP - Problem

If you can access your router via IPv6 from some internet site, then IPv6 is fine between your ISP and your router. If at the same you can't access (ping) LAN devices, then it's most probably due to device's own firewall. If you can access your router from some intetnet sites, but not from the other...
by mkx
Mon Feb 15, 2021 8:23 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta4 [development] is released!
Replies: 185
Views: 24159

Re: v7.1beta4 [development] is released!

I can uderstand everybody who decide not to install beta version, it's their gear, their time, their life. But why bitching about quality of betas (or lack of it)? Either accept the lack of quality of betas and proceed to test (reporting issues etc.) or stop testing and shut up about it.
by mkx
Mon Feb 15, 2021 8:16 pm
Forum: General
Topic: Mikrotik multiple VLAN's
Replies: 2
Views: 175

Re: Mikrotik multiple VLAN's

Your RB960PGS is running ancient ROS version. Do yourself a favour and 1) create asciii export of configuration executing /export file=anynameyouwish , 2) transfer resulting file to managemrnt PC, 3) upgeade to latest long-term (currently 6.47.9) 4) reset to factory defaults and 5) re-do whatever ve...
by mkx
Mon Feb 15, 2021 8:05 pm
Forum: General
Topic: One or more bridges?
Replies: 6
Views: 361

Re: One or more bridges?

I think it's one bridge per switch chip, not per device You're right. I just didn't want to go too much in details as only a few models feature two switch chips (RB2011, RB3011 and RB4011) and with those one has to be extremely careful to create bridges not spanning ports from different switch chip...
by mkx
Mon Feb 15, 2021 7:46 pm
Forum: General
Topic: DHCP Client
Replies: 15
Views: 4319

Re: DHCP Client

Here's how DHCP works per https://www.ietf.org/rfc/rfc2131.txt
Lol, this is a bit stupid, refer to a RFC is a to easy answer.

If you refuse to read RFC which explains why MT behaviour is correct, then perhaps Mikrotik is not right selection for you.
by mkx
Mon Feb 15, 2021 7:34 pm
Forum: General
Topic: CRS328 Switch Create Vlans issue [SOLVED]
Replies: 6
Views: 429

Re: CRS328 Switch Create Vlans issue [SOLVED]

Example command as below. set bridge=BR1 tagged=BR1 [find vlan-ids=10] Now the vlan is functionable, but when I export and check the configuration file. I can't see the above command in it. The command is essentially included in the command below: /interface bridge vlan add bridge=bridge1 tagged=br...
by mkx
Mon Feb 15, 2021 7:30 pm
Forum: General
Topic: How to advertise dynamic ipv6 prefix recieved from dhcpv6
Replies: 8
Views: 438

Re: How to advertise dynamic ipv6 prefix recieved from dhcpv6

Forget about DHCPv6 server on MT. ND advertises prefix which corresponds to IPv6 address set to corresponding router interface. For example: # let's assume you have two LANs connected to ether2 and ether3 respectively /ipv6 address add address=::1 from-pool=internode interface=ether2 add address=::1...
by mkx
Mon Feb 15, 2021 7:18 pm
Forum: Beginner Basics
Topic: VLAN-Problems [SOLVED]
Replies: 18
Views: 1035

Re: VLAN-Problems [SOLVED]

Tagged+untagged (a.k.a. hybrid) : ingress-filtering=no OR frame-types=admit-all ingress-filtering=yes

It actually should be the later (with ingress filtering enabled) to enforce ingress filtering acording to allowed VLANs as configured in /interface bridge vlan ...
by mkx
Mon Feb 15, 2021 7:12 pm
Forum: Beginner Basics
Topic: Rb4011+IPv6 from ISP - Problem
Replies: 6
Views: 403

Re: Rb4011+IPv6 from ISP - Problem

Csn you ping router itself from internet? E.g. ping 2a10:f300:1:1::1 ? You're pinging a LAN host which may have its own firewall blocking pings. It may have multiple IPv6 addresses in use and is not replying to pings on most of them ... You can verify addresses actually in use by router running /ipv...
by mkx
Mon Feb 15, 2021 12:39 pm
Forum: Announcements
Topic: v6.47.9 [long-term] is released!
Replies: 65
Views: 12757

Re: v6.47.9 [long-term] is released!

If cable connecting hEX PoE and camera is long, then detecton/negotiation can fail due to excessive cable resistence. In such case forcing PoE out can help but it also depends on voltage drop over cable, 802.3 af/at requires at least 37V at PD (camera).
by mkx
Mon Feb 15, 2021 12:34 pm
Forum: General
Topic: One or more bridges?
Replies: 6
Views: 361

Re: One or more bridges?

You did not mention device model you have in mind. Anyway: CRS3xx are switches. These work best if using single bridge because only one bridge per device can be HW offloaded. The same is true for all other MT devices with switch chips built in, even though some devices have relatively fast CPUs ther...
by mkx
Mon Feb 15, 2021 12:25 pm
Forum: Beginner Basics
Topic: NAT not working...
Replies: 45
Views: 2744

Re: NAT not working...

Is possible to tell me which changes do you suggest on the network by the new configuration? I didn't have anything in particular on my mind. Nowdays it's common to have a few IoT gadgets in the household and generally its good practice to keep those in separate (V)LAN heavily firewalled in all dir...
by mkx
Sun Feb 14, 2021 5:52 pm
Forum: RouterBOARD hardware
Topic: RB960PGS PoE short-circuit
Replies: 3
Views: 311

Re: RB960PGS PoE short-circuit

I suggest to have PoE set to off on all ports where peer does not expect to be PoE powered. Checks done to verify that remote device is PoE client are pretty basic for passive PoE and can fail quite easily. And if RB960PGS wrongly decides to power remote end with 48 volts, it can cause damage on bot...
by mkx
Sun Feb 14, 2021 5:41 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta4 [development] is released!
Replies: 185
Views: 24159

Re: v7.1beta4 [development] is released!

Did you know that /export verbose works when /export doesn't? For me that was a great discovery! No, I did not and I agree it's worth mentioning. However, issue with running export (without any options) had been reported many times so far it's really stale by now and because it did not get fixed it...
by mkx
Sun Feb 14, 2021 5:24 pm
Forum: General
Topic: CRS328 Switch Create Vlans issue [SOLVED]
Replies: 6
Views: 429

Re: CRS328 Switch Create Vlans issue [SOLVED]

It's not clear to me how duties are shared between both MT devices and where BGP enters the game. You did not mention the other device's model, but CRS328 is not a router, it's a switch. Sure it can route but performance is next to none (compared to switching performance). Anyway, have a look at thi...
by mkx
Sun Feb 14, 2021 5:16 pm
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 66
Views: 38253

Re: DHCP Offering Lease Without Success

why is that functionality ( set disable-running-check=yes on wireless interfaces ) not turned OFF by default and furthermore why has not the wifi guru himself, "bpwl", not recommended this setting (if he has I missed it unfortunately) It's not turned off probably for the same reason bridg...
by mkx
Sun Feb 14, 2021 12:57 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta4 [development] is released!
Replies: 185
Views: 24159

Re: v7.1beta4 [development] is released!

I wish MT acknowledged the problem so that not everybody (and their dog) reports it as some great discovery.
It would be even better if the problem was fixed ASAP even though this problem probably doesn't affect normal device operation.
by mkx
Sun Feb 14, 2021 12:53 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta4 [bug] export hangs / slow [SOLVED]
Replies: 1
Views: 313

Re: v7.1beta4 [bug] export hangs / slow [SOLVED]

I also noticed that /system/backup/save dont-encrypt=yes name=foo is even faster than any export. ROS v6 is like this as well and it's easy to explain: backup file is a mere a collection of binary configuration, I guess a combination of memory dumps (or may be not) and pre-existing binary configura...
by mkx
Sun Feb 14, 2021 12:42 pm
Forum: SwOS
Topic: CRS 112 Slow Throughput
Replies: 17
Views: 897

Re: CRS 112 Slow Throughput

When ports are members of a bridge, the frames are forwarded via select egress ports depending on (learned or statically set) MAC table. Which means that most frames egress only relevant port and only a few (broadcast, multicast and yet unknown unicast destination) frames are egressing all member po...
by mkx
Sun Feb 14, 2021 12:24 pm
Forum: RouterBOARD hardware
Topic: CCR possibility for plugin card based on Raspberry Pi
Replies: 1
Views: 223

Re: CCR possibility for plugin card based on Raspberry Pi

Since such a general-purpose plugin would require a complete pass-through (both configuration and traffic), so why bother to build-in such an add-on board? Use standard interfaces (such as 1000Base-Tx) and be done with it. Making option to build-in such a solution would open a huge can of worms and ...
by mkx
Sun Feb 14, 2021 12:13 pm
Forum: General
Topic: CRS3XX Graphing
Replies: 1
Views: 223

Re: CRS3XX Graphing

I don't think you can get per-VLAN statistics for fully hw-offloaded ports ...
by mkx
Sun Feb 14, 2021 12:10 pm
Forum: General
Topic: CCR1036 capacity
Replies: 3
Views: 321

Re: CCR1036 capacity

Run CPU profiler to see if some CPU cores are maxed out. 25% average CPU load could as well be 9 CPU cores at 100% while others are idle.
by mkx
Sat Feb 13, 2021 11:05 pm
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 66
Views: 38253

Re: DHCP Offering Lease Without Success

@mkx Plausible explanation. Does this still apply if I'm using capsman and local forwarding?

I'd expect it does, but I'm not sure.
by mkx
Sat Feb 13, 2021 6:38 pm
Forum: Beginner Basics
Topic: Splitting Ports into Seperate Isolated Networks
Replies: 25
Views: 1446

Re: Splitting Ports into Seperate Isolated Networks

As I explained: connections (including pings) from any client (any of subnets, internet included) to any of router's IP addresses is handled by chain=input. So if you have as last rule in input chain one dropping everything, and none of preceeding rules allow that particular connection, then pinging...
by mkx
Sat Feb 13, 2021 6:24 pm
Forum: Beginner Basics
Topic: NAT not working...
Replies: 45
Views: 2744

Re: NAT not working...

Backups are not portable between devices. Not really between devices of same model, much less between different models. Importing exported config is more likely to succeed, but it's not recomended either. The recomended approach seems to be to export config from the old device, then open it in text ...
by mkx
Sat Feb 13, 2021 3:50 pm
Forum: RouterBOARD hardware
Topic: Netinstall from a ROS device?
Replies: 5
Views: 279

Re: Netinstall from a ROS device?

Given fragility of netinstall process which is likely to fail even with direct UTP connection between netinstall server and routerboard device ... it would surprise me if this would work. I'm not saying it's not possible though ...
by mkx
Sat Feb 13, 2021 3:39 pm
Forum: Beginner Basics
Topic: NAT not working...
Replies: 45
Views: 2744

Re: NAT not working...

The router you have is old and slow. Check official test results ... the most real-life numbers are usually under "Routing - 25 ip filter rules - 512 byte [packet size]". As you have 1Gbps internet connection, you'll need a newer and faster device. Search for one through product pages and ...
by mkx
Sat Feb 13, 2021 11:31 am
Forum: RouterBOARD hardware
Topic: Netinstall from a ROS device?
Replies: 5
Views: 279

Re: Netinstall from a ROS device?

No, there's no netinstall tool for ROS.
by mkx
Sat Feb 13, 2021 10:24 am
Forum: Beginner Basics
Topic: Splitting Ports into Seperate Isolated Networks
Replies: 25
Views: 1446

Re: Splitting Ports into Seperate Isolated Networks

Is that correct?
Yes.

I concur that ROS learning curve is steep indeed. It helps if newbie has good knowledge of how linux kernel works but that's not common at all.
by mkx
Sat Feb 13, 2021 12:28 am
Forum: Beginner Basics
Topic: Splitting Ports into Seperate Isolated Networks
Replies: 25
Views: 1446

Re: Splitting Ports into Seperate Isolated Networks

But my question is... if MKX's original rule using the forward chain can't block a ping between the two networks how does it block any other network traffic? What am I missing in my understanding. It has been explained a few times before, but I'll try to do it again. Packet passing router[*] in any...
by mkx
Fri Feb 12, 2021 8:31 pm
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 66
Views: 38253

Re: DHCP Offering Lease Without Success

@anav went fly-fishing to a pond. As no fish cared to bite, he fixed it by going to fish market instead.
by mkx
Fri Feb 12, 2021 8:25 pm
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 66
Views: 38253

Re: DHCP Offering Lease Without Success

When wireless interface has no clients connected, it toggles port state to "not running". When first client connects afterwards, interface state toggles to running. This in turn trips xSTP to check for loops and before check finishes, no traffic can pass that bridge port. Time necessary fo...
by mkx
Fri Feb 12, 2021 7:56 pm
Forum: Beginner Basics
Topic: Networking Strucutre [SOLVED]
Replies: 20
Views: 1203

Re: Networking Strucutre [SOLVED]

There are a few errors in your configuration: /ip address add address=10.38.25.31/16 interface=ether1 network=10.38.0.0 add address=192.168.214.1/24 interface=ether5 network=192.168.214.0 # The following two lines should be removed add address=10.38.25.31 interface=ether1 network=10.38.25.31 add add...
by mkx
Wed Feb 10, 2021 12:30 pm
Forum: Beginner Basics
Topic: Networking Strucutre [SOLVED]
Replies: 20
Views: 1203

Re: Networking Strucutre [SOLVED]

In the linked page, note the "routing subnet" between router1 and router2 ... it is important and makes life of both routers easier. The thing is that in usual SOHO networks router1 runs a stateful firewall as well ... and this firewall can trip if it doesn't see traffic in both directions...
by mkx
Wed Feb 10, 2021 11:03 am
Forum: Beginner Basics
Topic: Need some advice for a Mikrotik beginner
Replies: 3
Views: 291

Re: Need some advice for a Mikrotik beginner

If you have wires all over place, then you probably don't need to have "mesh" ... "mesh" usually means that wireless APs use wireless both to connect towards router and to serve clients. If you have wires everywhere, then you'll just connect APs to wires and run them as normal AP...
by mkx
Wed Feb 10, 2021 10:10 am
Forum: Beginner Basics
Topic: Networking Strucutre [SOLVED]
Replies: 20
Views: 1203

Re: Networking Strucutre [SOLVED]

What is server's default gateway IP address? You can only route traffic from Sophos network via MT is either server or its default gateway know to use RB as gateway towards Sophos network.
by mkx
Wed Feb 10, 2021 9:16 am
Forum: Beginner Basics
Topic: Networking Strucutre [SOLVED]
Replies: 20
Views: 1203

Re: Networking Strucutre [SOLVED]

Check firewall on the Computer ... some OSes (Windows most notably) consider anything but it's own subnet to be evil internet and block pings originating from other networks.
by mkx
Wed Feb 10, 2021 9:12 am
Forum: Beginner Basics
Topic: Splitting Ports into Seperate Isolated Networks
Replies: 25
Views: 1446

Re: Splitting Ports into Seperate Isolated Networks

It's what @tdw wrote: when packet arrives at some ROS interface, ROS first determines which chain to use. And if packet's destination address is any of router's own addresses (in-interface is not considered when determining chain, neither is src-address), it will be handled by chain=input regardless...
by mkx
Tue Feb 09, 2021 8:19 pm
Forum: General
Topic: CRS354 remove interface=all from bridge
Replies: 3
Views: 237

Re: CRS354 remove interface=all from bridge

What happens if you add individual interfaces first and remove interface=all at the end? You can check actual bridge port list (and flags) by running /interface bridge port print at each step to see if things progress in desired direction. Another possibility would be to add at least one of individu...
by mkx
Tue Feb 09, 2021 4:37 pm
Forum: Beginner Basics
Topic: which rules prevents access to services on the mikrotik? [SOLVED]
Replies: 4
Views: 293

Re: which rules prevents access to services on the mikrotik? [SOLVED]

which of these rules prevents access to services on the mikrotik itself (winbox, webfig, ssh etc)? None actually. Default firewall filter rules have this stanza et the end of rules for chain=input : add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-l...
by mkx
Tue Feb 09, 2021 2:02 pm
Forum: General
Topic: How to Ping Chateau from outside / Passthrough or IP problem? [SOLVED]
Replies: 4
Views: 334

Re: How to Ping Chateau from outside / Passthrough or IP problem? [SOLVED]

Many MNOs protect their mobile clients (not really known for their security) using a firewall. Even if client's IP address is not NATed, it is still subject to firewall rules. And very often those firewall rules are pretty restrictive.
by mkx
Tue Feb 09, 2021 9:58 am
Forum: General
Topic: Slow ports
Replies: 1
Views: 130

Re: Slow ports

Why can I not get the full throughput to the internet?? Because RB2011 is an old and (for today's standards) slow router. Check official test results and concentrate on number in "Routing 25 -> ip filter rules -> 512 byte [packet size]" which seems to be the most relevant for real-life us...
by mkx
Tue Feb 09, 2021 9:43 am
Forum: Beginner Basics
Topic: Basic configuration problems
Replies: 5
Views: 390

Re: Basic configuration problems

One error in the script: # OFFICE VLAN interface creation, IP assignment, and DHCP service /ip address add interface=OFFICE_VLAN address= 11 .0.10.1/24 And I guess you do have a DNS server running @ IP address 10.0.0.1 ... Without knowing the full context, IP setup seems messy. And you're surely awa...
by mkx
Mon Feb 08, 2021 8:41 pm
Forum: Beginner Basics
Topic: do I need to setup a bridge?
Replies: 3
Views: 295

Re: do I need to setup a bridge?

If you're doing it optimally (single bridge with vlan-filtering=yes), then whatever you'd do differently you'd loose performance.
by mkx
Mon Feb 08, 2021 7:28 pm
Forum: Wireless Networking
Topic: Config 3g/4g modem on rb962
Replies: 4
Views: 230

Re: Config 3g/4g modem on rb962

In RouterOS no, it is not possible to load custom drivers or any other part of software.
by mkx
Mon Feb 08, 2021 7:23 pm
Forum: Beginner Basics
Topic: Cisco AP Autonomout Mode VLAN issue on one VLAN [SOLVED]
Replies: 17
Views: 984

Re: Cisco AP Autonomout Mode VLAN issue on one VLAN [SOLVED]

Right you are, it should be admit-all ... which is default and thus is not shown in your configuration export. Regarding GUEST-AP: I don't see anything wrong in hAP lite configuration, tagged frames with VID=20 should pass it. If GUEST-AP on hAP lite works fine, then I would suspect configuration on...
by mkx
Mon Feb 08, 2021 7:11 pm
Forum: General
Topic: Is RouterOS and (routing in general) still faster on routers than on dedicated computer ? [SOLVED]
Replies: 13
Views: 1167

Re: Is RouterOS and (routing in general) still faster on routers than on dedicated computer ? [SOLVED]

I don't even want to imagine how a 1U sounds like :D Like a small jet plane taking off (the large jets are louder, but their noise is more bearable for me). When talking about servers in SOHO environments, one should not forget about power consumption. A decent server has idle power consumption wel...
by mkx
Mon Feb 08, 2021 6:59 pm
Forum: Beginner Basics
Topic: do I need to setup a bridge?
Replies: 3
Views: 295

Re: do I need to setup a bridge?

Bridge is something like a switch. So if machines are in same VLAN / IP subnet, then you want ports bridged/switched. If machines are in different VLANs / IP subnets, then you can't do anything else than routing and for that ports have to be treated as separate interfaces, each having own IP address...
by mkx
Mon Feb 08, 2021 5:05 pm
Forum: Beginner Basics
Topic: Cisco AP Autonomout Mode VLAN issue on one VLAN [SOLVED]
Replies: 17
Views: 984

Re: Cisco AP Autonomout Mode VLAN issue on one VLAN [SOLVED]

I did not write that the solution shared was a no-go (I wouldn't post it at all, I'd let somebody else do it), I just wrote my opinion about the right (best) solution. But that's only my opinion and surely not everybody agrees.
by mkx
Mon Feb 08, 2021 5:01 pm
Forum: General
Topic: Wireless - spectral history to a file
Replies: 2
Views: 182

Re: Wireless - spectral history to a file

If APold is client to APnew, it will communicate occasionally. If the devices are physically really close, then their Tx power is too high and will mutually overpower each others receiver. Client overpowering APs receiver means lots of interference for whole APs wireless network. If you want to use ...
by mkx
Mon Feb 08, 2021 4:46 pm
Forum: Beginner Basics
Topic: Cisco AP Autonomout Mode VLAN issue on one VLAN [SOLVED]
Replies: 17
Views: 984

Re: Cisco AP Autonomout Mode VLAN issue on one VLAN [SOLVED]

Can you please help me in that direction?

I already did ... either copy-paste the code to terminal window or change setting through GUI. I'm not fluent in ciscogibberish, so I couldn't guide you towards all-tagged setup.
by mkx
Mon Feb 08, 2021 4:35 pm
Forum: Beginner Basics
Topic: Cisco AP Autonomout Mode VLAN issue on one VLAN [SOLVED]
Replies: 17
Views: 984

Re: Cisco AP Autonomout Mode VLAN issue on one VLAN [SOLVED]

@tdw pointed out that frame-types=admit-only-vlan-tagged could not work because ether2 is configured with VLAN10 untagged & VLAN20 tagged. My needs are that a device connecting on the Cisco would, depending on the SSID (SOHO or GUEST) be restricted to the particular VLAN. Stressing that my unde...
by mkx
Mon Feb 08, 2021 3:46 pm
Forum: Wireless Networking
Topic: Config 3g/4g modem on rb962
Replies: 4
Views: 230

Re: Config 3g/4g modem on rb962

If an USB device appears under /system routerboard usb this doesn't mean ROS has a driver for it. ROSv6 has pretty limited support for peripherials, specially modern ones. Reason being that current ROS is based on outdated linux kernel (and I guess quite some then-existing drivers are omitted from R...
by mkx
Mon Feb 08, 2021 2:27 pm
Forum: Beginner Basics
Topic: Splitting Ports into Seperate Isolated Networks
Replies: 25
Views: 1446

Re: Splitting Ports into Seperate Isolated Networks

Superwhat? It must be some Yankee stuff again, I'm surprised you Canadiens fall for it so often. ;-)
by mkx
Mon Feb 08, 2021 2:09 pm
Forum: General
Topic: Upgrade Router OS/Firmware from CLI [SOLVED]
Replies: 3
Views: 245

Re: Upgrade Router OS/Firmware from CLI [SOLVED]

No, ROS doesn't reboot automatically, you'll have to do it manually. Or not, with mature devices routerboot firmware mostly doesn't change at all between ROS versions so there's no need for immediate reboot. When device reboots next time, it'll run updated routerboot as well. If you run into some tr...
by mkx
Mon Feb 08, 2021 2:04 pm
Forum: General
Topic: Copy Traffic Port Mirrotong in Router OS
Replies: 1
Views: 125

Re: Copy Traffic Port Mirrotong in Router OS

It doesn't seem to be possible to have port mirroring with software bridge. You might get some useful idea from this topic: viewtopic.php?t=131332
by mkx
Mon Feb 08, 2021 1:54 pm
Forum: Beginner Basics
Topic: NAT not working...
Replies: 45
Views: 2744

Re: NAT not working...

I think your settings (auto-negotiation enabled and advertised all speeds) are fine. Also l2mtu of 1520 should be just fine for now. Just keep in mind to check all ethernet settings if something breaks ... The thing about ROS versions I mentioned: when upgrading ROS version, settings are not changed...
by mkx
Mon Feb 08, 2021 1:45 pm
Forum: Beginner Basics
Topic: Networking Strucutre [SOLVED]
Replies: 20
Views: 1203

Re: Networking Strucutre [SOLVED]

Well, I missed the fact you're using the device inside LAN. To achieve what you want it would best to configure device from scratch like this: Download winbox to your management PC connect management PC to router using one of ether2-ether5, run winbox and click MAC address of router to connect to it...
by mkx
Mon Feb 08, 2021 1:28 pm
Forum: Beginner Basics
Topic: Splitting Ports into Seperate Isolated Networks
Replies: 25
Views: 1446

Re: Splitting Ports into Seperate Isolated Networks

anav, my friend, I was trying to teach OP to catch a fish ... not to go to a supermarket to buy pre-fried fish sticks.
by mkx
Mon Feb 08, 2021 12:44 am
Forum: General
Topic: Upgrade Router OS/Firmware from CLI [SOLVED]
Replies: 3
Views: 245

Re: Upgrade Router OS/Firmware from CLI [SOLVED]

It is not possible to upgrade routerboot before device reboots to upgraded ROS version. The only corner that can be cut is to set /system routerboard settings set auto-upgrade=yes which saves administrator from executing /system routerboard upgrade after ROS upgrade. Another reboot is still necessary.
by mkx
Mon Feb 08, 2021 12:36 am
Forum: Beginner Basics
Topic: Networking Strucutre [SOLVED]
Replies: 20
Views: 1203

Re: Networking Strucutre [SOLVED]

Firewall is cripled beyond any usable protection simply because of first (top-most) rule allowing just any connection from WAN towards LAN.
by mkx
Mon Feb 08, 2021 12:30 am
Forum: Beginner Basics
Topic: Splitting Ports into Seperate Isolated Networks
Replies: 25
Views: 1446

Re: Splitting Ports into Seperate Isolated Networks

A bridge spans multiple ports. So you'll need two bridges, one spanning ether2 and ether3, the other spanning ether4 and ether5. Bridges come with implicitly created interfaces, which are members of same bridge. These interfaces allow ROS to interact with subnet. So you assign IP addresses to those ...
by mkx
Sun Feb 07, 2021 7:46 pm
Forum: General
Topic: invalid dhcp server on vlan interface
Replies: 10
Views: 657

Re: invalid dhcp server on vlan interface

1. **port** is a layer 2 concept. Anything that has a MAC address is an ethernet port. Phyisical interfaces: ether2, ether3 and ether4 are ports. The bridge itself is a port (it has a MAC address). The virtual interfaces vlan20 and vlan30 are also ports. Bridge itself is not a port. Bridge has two ...
by mkx
Sun Feb 07, 2021 6:10 pm
Forum: General
Topic: Is my IP blocked on Mikrotik servers, or is it my ISP being crap?
Replies: 1
Views: 192

Re: Is my IP blocked on Mikrotik servers, or is it my ISP being crap?

Does it only happen when router is trying to connect mikrotik servers or it happens from a PC behind the router as well? If you have a linux PC handy, you can try to see where connection breaks by running tcptraceroute (probably something similar exists for other OSes). For me some hops in Latvia fa...
by mkx
Sat Feb 06, 2021 11:51 pm
Forum: RouterBOARD hardware
Topic: 10G Fiber run of 700m, which SFP+ module and cable?
Replies: 6
Views: 643

Re: 10G Fiber run of 700m, which SFP+ module and cable?

Probably nowdays there is no good reason to use two fibre strands for a duplex connection. Historically there were numerous reasons for that, two pretty important were these: fibres used to have usably low attenuation in narrower wavelength bands around 1310 nm and around 1550 nm while attenuation i...
by mkx
Sat Feb 06, 2021 11:26 pm
Forum: Beginner Basics
Topic: Need suggestions for WAF features and http traffic rules
Replies: 2
Views: 279

Re: Need suggestions for WAF features and http traffic rules

There's the all-in-one approach where one box does it all. And there's "building blocks" approach where a few specialized boxes are used, each doing part of a job. Each approach has its pros and cons. Whatever you choose, if you want job done properly, you'll have to master the setup. Gene...
by mkx
Sat Feb 06, 2021 5:56 pm
Forum: Wireless Networking
Topic: wAP ac no IP on 5g [SOLVED]
Replies: 5
Views: 492

Re: wAP ac no IP on 5g [SOLVED]

I think you could disable MSTP on all APs ... and leave MSTP enabled on switches. You only need MSTP on "core" of your network, where loops can happen duue to redundant links. If, OTOH, you'd connect same AP to two of your core switches at the same time, you would have to run MSTP on APs a...
by mkx
Sat Feb 06, 2021 5:46 pm
Forum: General
Topic: Which mAP alternative with 5GHz and 802.3 af capabilities ?
Replies: 6
Views: 502

Re: Which mAP alternative with 5GHz and 802.3 af capabilities ?

The idea behind 802.3 af/at handshake is that PSE doesn't apply power to non-compliant PD. cAP ac is 802.3 af/at client, so that PoE injector happily provided power. cAP ac as PSE is not 802.3 af/at compliant, it can only work according to MT's proprierary passive PoE implementation. It is quite sim...
by mkx
Sat Feb 06, 2021 5:26 pm
Forum: Beginner Basics
Topic: NAT not working...
Replies: 45
Views: 2744

Re: NAT not working...

Usual execution of export command only shows settings different than bare minimum default. For ethernet ports current default ( export verbose ) is set [ find default-name=ether1 ] advertise=\ 10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full arp=enabled arp-timeout=auto \ auto-negotiation...
by mkx
Sat Feb 06, 2021 12:26 pm
Forum: Wireless Networking
Topic: wAP ac no IP on 5g [SOLVED]
Replies: 5
Views: 492

Re: wAP ac no IP on 5g [SOLVED]

There are two things you should check: any xSTP run on bridge causes quite some delay for bridge port to get enabled after it enters "running" state. For that reason its best to disable it unless you absolutely need it (e.g. your network topology is a ring-shaped for failovers). That being...
by mkx
Sat Feb 06, 2021 12:10 pm
Forum: Wireless Networking
Topic: CATm LTE via BG95-M2
Replies: 2
Views: 290

Re: CATm LTE via BG95-M2

There are two ways of getting said device work in ROS and they (most) probably both involve ROSv7 (so you probably should ask this question in subforum dedicated to v7): either driver for that device lands in mainstream linux kernel really soon (and MT devs pick it up before finalizing v7) or MT dec...
by mkx
Sat Feb 06, 2021 11:57 am
Forum: Beginner Basics
Topic: Blocking RAT
Replies: 1
Views: 241

Re: Blocking RAT

There is no way that normal L3/L4 firewall prevents malware from being installed on computers behind it. For that one would have to use proxy server (the non-transparrent one) which does full anti-malware (and antivirus) scan ... which is not really possible to do "on the fly" while file (...
by mkx
Fri Feb 05, 2021 2:54 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta4 [development] is released!
Replies: 185
Views: 24159

Re: v7.1beta4 [development] is released!

Will never test betas again ...

If you can't accept random things broken, then beta testing is not for you. No need to publicly announce that, we'll accept your decision regardless.
by mkx
Fri Feb 05, 2021 9:35 am
Forum: Announcements
Topic: v6.49beta [testing] is released!
Replies: 44
Views: 9172

Re: v6.49beta [testing] is released!

Will be there no further V6.48.XX versions?
From the doomed V6.48 straight to V6.49?
I would guess we will get a 6.48.1 today.
Yup. At around 16 hours EET (which is 14 hours UTC, do the maths for your own time zone yourselves).
by mkx
Fri Feb 05, 2021 9:30 am
Forum: Wireless Networking
Topic: Increase Output TX-power
Replies: 8
Views: 698

Re: Increase Output TX-power

However, you might fry the radio by going that low. Probably not. According to information from MT staffer, ROS picks lowest number of (card rates, country limit, manual Tx power setting) as Tx power at any rate used. So by setting antenna gain to 0 (and choosing country with most generous Tx power...
by mkx
Thu Feb 04, 2021 11:57 pm
Forum: General
Topic: Fibre/Ethernet bridge not passing Traffic
Replies: 3
Views: 323

Re: Fibre/Ethernet bridge not passing Traffic

You did not write anything about SFPs you're using. Mikrotik seems to be quite picky about supported SFPs. Here's official compatibility list: https://wiki.mikrotik.com/wiki/MikroTik ... lity_table
by mkx
Wed Feb 03, 2021 5:06 pm
Forum: RouterBOARD hardware
Topic: Is hEX PoE capable to power up hAP ac2 via PoE In?
Replies: 6
Views: 493

Re: Is hEX PoE capable to power up hAP ac2 via PoE In?

AFAIK all MT devices can do passive PoE (either IN or OUT if they are PoEout) even if quick specs say 802.3 af/at. OTOH MT devices won't do voltage conversion for PoE out. If they are powered with voltage outside normal 802.3 af/at range (44-57V), they'll provide PoE out without 802.3 af/at negotiat...
by mkx
Wed Feb 03, 2021 9:43 am
Forum: Announcements
Topic: v6.48 [stable] is released!
Replies: 324
Views: 62192

Re: v6.48 [stable] is released!

So MikroTik, please say .. something!
In case you missed it, in post #303 above Mikrotik did say something.
by mkx
Wed Feb 03, 2021 9:02 am
Forum: General
Topic: Is Mikrotik IP Address identifier/id fixed?
Replies: 1
Views: 206

Re: Is Mikrotik IP Address identifier/id fixed?

Not sure how ID property is used in API, but I suspect it's similar to CLI. In CLI ID property is dynamic and doesn't exist until elements are listed (e.g. with print command). Which means ID is useless in scripting, one has to use other means of selecting the right element (e.g. to change its prope...
by mkx
Wed Feb 03, 2021 8:56 am
Forum: General
Topic: Fibre/Ethernet bridge not passing Traffic
Replies: 3
Views: 323

Re: Fibre/Ethernet bridge not passing Traffic

Check, if SFPs in port7 and port8 actually establish a link ... The optical link is set for auto-negotiation which doesn't exactly work with optical SFPs, in ROS it is usually necessary to fix port speed to whatever remote end expects. OTOH you have autonegotation disabled on port8 (RJ45 SFP) which ...
by mkx
Tue Feb 02, 2021 10:56 pm
Forum: Wireless Networking
Topic: Any product recommendations for MikroTik wifi router?
Replies: 13
Views: 1124

Re: Any product recommendations for MikroTik wifi router?

m could be any of the following ?
miles
meters

also
molecules ( really really close stuff )
milk ( yea the white liquid stuff )
Sure. That's where context helps.

Anyway, even it might be off by a few orders of magnitude, your suggestion makes sense ... in different context ;-)
by mkx
Tue Feb 02, 2021 10:49 pm
Forum: Wireless Networking
Topic: Any product recommendations for MikroTik wifi router?
Replies: 13
Views: 1124

Re: Any product recommendations for MikroTik wifi router?

Yeah but Tom is a Yankee, its all square miles when you put in an "m" in there! ;-)

Well, Yankees are known not to know what units to use. Last time they tried to do anything coherent, they crashed Mars climate orbiter ...
by mkx
Tue Feb 02, 2021 6:04 pm
Forum: General
Topic: Mikrotik Bridge Port Extender - Cant reach PB
Replies: 5
Views: 483

Re: Mikrotik Bridge Port Extender - Cant reach PB

Since PE device doesn't do much (encapsulation of packets ingressing through extended ports and decapsulation of packets egressing through extended ports; and I certaily hope that's done in hardware), you don't really need any resource monitoring. I guess failing extended ports will show as such in ...
by mkx
Tue Feb 02, 2021 5:43 pm
Forum: General
Topic: Mikrotik Bridge Port Extender - Cant reach PB
Replies: 5
Views: 483

Re: Mikrotik Bridge Port Extender - Cant reach PB

When there was a discussion about port-extender functionality when it was first announced, MT staff confirmed that in such setup, PE device is completely brain-dead. Doesn't even switch traffic between own ports autonomously, everything passes via CB device. So I guess you don't really need neither ...
by mkx
Tue Feb 02, 2021 5:39 pm
Forum: General
Topic: Powering Mikrotik Using Ubiquiti 50V 60Watt POE
Replies: 2
Views: 255

Re: Powering Mikrotik Using Ubiquiti 50V 60Watt POE

What is Hikvision camera's rated power consumption? Omnitik has PoE out limitation to 450mA (at 30+ V) which at 50V translates to 22.5W ...
by mkx
Tue Feb 02, 2021 4:57 pm
Forum: General
Topic: VLAN Access Port on Access Point Issue (Hybrid Access Port) [SOLVED]
Replies: 11
Views: 949

Re: VLAN Access Port on Access Point Issue (Hybrid Access Port) [SOLVED]

I'm no expert for CAPsMAN, but from my limited experience ... you should not add wlan interfaces to the bridge explicitly, they get added automatically. Manual settings are probably not overriden, hence possibility for misbehaviour. If capsman datapath setting is local-forwarding=yes , then wlan int...
by mkx
Tue Feb 02, 2021 2:00 pm
Forum: General
Topic: After Hack are we clean ?
Replies: 6
Views: 655

Re: After Hack are we clean ?

Having said that , other than the fact that the hack could have happened before the backup , is three any other concern ? The hack very probably happened due to inadequate firewall settings. By simply restoring (mediocre) config you'll be vulnerable to same attack again. What you can do is to resto...
by mkx
Tue Feb 02, 2021 1:50 pm
Forum: General
Topic: Mikrotik cannot start, help I don't know what else to do
Replies: 2
Views: 301

Re: Mikrotik cannot start, help I don't know what else to do

Try to netinstall router. https://wiki.mikrotik.com/wiki/Manual:Netinstall Beware that netinstall is pretty fragile process and it easily fails. Which is not necessarily sign of router troubles. And when doing it, keep away from netinstall/ROS version 6.48, it seems to have quite a few nasty bugs. Y...
by mkx
Tue Feb 02, 2021 1:45 pm
Forum: RouterOS v7 BETA
Topic: v7.1beta3 [development] is released!
Replies: 262
Views: 43010

Re: v7.1beta3 [development] is released!

Do you guys know when the final version is out, shell we aim for the end on 2021?

We can aim at whatever we want, devs will surely move the target at their will (if they have a target at all).
by mkx
Mon Feb 01, 2021 3:20 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS+ TX Pauses.
Replies: 9
Views: 910

Re: RB4011iGS+ TX Pauses.

And another question to illuminated members - how can i know if router (eth driver) is supporting multi-queue-ethernet-default (mq pfifo).

I guess only support@mikrotik.com can tell you that. If you get any feedback, please share it with us.
by mkx
Mon Feb 01, 2021 3:05 pm
Forum: General
Topic: Share cable IPTV & Internet RB951G/CRS125
Replies: 26
Views: 13769

Re: Share cable IPTV & Internet RB951G/CRS125

  • But next to this, we've setup also PPPoE client, and set interface to vlan20

What does log show regarding PPPoE? Probably there's some error ... which doesn't relate to NAT.
by mkx
Mon Feb 01, 2021 2:56 pm
Forum: General
Topic: VLAN Access Port on Access Point Issue (Hybrid Access Port) [SOLVED]
Replies: 11
Views: 949

Re: VLAN Access Port on Access Point Issue (Hybrid Access Port) [SOLVED]

OK, so we need to treat MoCAs as kind of a dumb switch. Since you have one Tivo box connected directly to MoCA network, some untagged traffic has to pass MoCA. And if you want to have the other Tivo device member of same subnet, then yes, you have to pass VLAN 10 untagged over MoCA network. Which me...
by mkx
Mon Feb 01, 2021 12:23 am
Forum: RouterBOARD hardware
Topic: RB4011iGS+ TX Pauses.
Replies: 9
Views: 910

Re: RB4011iGS+ TX Pauses.

Sure it might be the case with congestion on other interfaces but that was not the case :-) How did you determine this? Just because router can route at speeds averaging above 1Gbps (that's what tests are telling) it doesn't mean it can do it at all times. And if ROS' IP stack can not ingest packet...
by mkx
Mon Feb 01, 2021 12:13 am
Forum: General
Topic: L2, L3 Firewall with different VLANs - bridge two vlans (intern, extern)
Replies: 7
Views: 526

Re: L2, L3 Firewall with different VLANs - bridge two vlans (intern, extern)

The basic idea of @BrainPain is to use RB4011 as router-on-a-stick[*] ... both WAN and LAN tagged with tagging of both being done by a switch (so don't worry about it). [*]only that he doesn't want RB4011 to do any routing, just transparrent firewalling. So he needs a bridge between WAN and LAN to m...
by mkx
Sun Jan 31, 2021 9:00 pm
Forum: General
Topic: L2, L3 Firewall with different VLANs - bridge two vlans (intern, extern)
Replies: 7
Views: 526

Re: L2, L3 Firewall with different VLANs - bridge two vlans (intern, extern)

Let's say you'll use ether1. You should use the interface in stand-alone mode (i.e. not enslaved to a bridge) and create appropriate vlan interfaces off it. Then bridge those interfaces and use bridge filters in similar manner as currently: /interface vlan add interface=ether1 name=extern vlan-id=10...
by mkx
Sun Jan 31, 2021 8:50 pm
Forum: General
Topic: VLAN Access Port on Access Point Issue (Hybrid Access Port) [SOLVED]
Replies: 11
Views: 949

Re: VLAN Access Port on Access Point Issue (Hybrid Access Port) [SOLVED]

"Visibility" of network devices is many times based on broadcasts ... and that only works inside single L2 domain which most of times is same as IP subnet. So you'll have to rethink your network layout and requirements of individual devices. From your explanations so far yor network layout...
by mkx
Sat Jan 30, 2021 10:28 pm
Forum: General
Topic: Ipsec required resource
Replies: 7
Views: 597

Re: Ipsec required resource

For any serious IPsec throughput you should look at devices with HW support for encryption. Those devices have IPsec throughput numbers stated in test result page, such as CCR1009-7G-1C-1S+ . When deciding on which device offers enough performance: seems that number for 512-byte packet sizes represe...
by mkx
Sat Jan 30, 2021 5:36 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS+ TX Pauses.
Replies: 9
Views: 910

Re: RB4011iGS+ TX Pauses.

I'm only surprised that such fast RB and still with pause frames. In the stats window it is shown that your router passed somewhere around 550M packets, of those 220M were pretty small packets (64-127 bytes). If you look at test results , you'll see that routing speed with small packets is around 3...
by mkx
Sat Jan 30, 2021 5:21 pm
Forum: Beginner Basics
Topic: Router setup with VLANs [SOLVED]
Replies: 10
Views: 999

Re: Router setup with VLANs [SOLVED]

What I want to know is what is connected to ports 3-9 with hybrid in mind?? (untagged for vlan 10, tagged for vlan20)?

IP phones with PC port usually require such setup. In this case for VLAN20 OP's router acts as a switch only, he mentioned separate SIP gateway.
by mkx
Sat Jan 30, 2021 5:14 pm
Forum: General
Topic: VLAN Access Port on Access Point Issue (Hybrid Access Port) [SOLVED]
Replies: 11
Views: 949

Re: VLAN Access Port on Access Point Issue (Hybrid Access Port) [SOLVED]

OK, se ether2 on router needs to be a trunk port tagged with VLAN 10, 20, 30, and 99 (because that's what AP expects). At the same time it needs to be untagged (member of any of VLANs for that matter) for MoCA administration. The thing is that single port can either be tagged or untagged member of c...
by mkx
Sat Jan 30, 2021 2:57 pm
Forum: Beginner Basics
Topic: Router setup with VLANs [SOLVED]
Replies: 10
Views: 999

Re: Router setup with VLANs [SOLVED]

Either set pvid=10 on bridge such as add name=BR1 protocol-mode=none pvid=10 to make bridge BR1 untagged member of VLAN 10 ... Or covert your L3 setup to tagged (i.e. add BR1 as tagged member of vlan 10 and move all router setup to PC_VLAN, adding said interface to LAN interface list allows to keep ...
by mkx
Sat Jan 30, 2021 12:25 pm
Forum: RouterBOARD hardware
Topic: hAP ac bricked?
Replies: 4
Views: 746

Re: hAP ac bricked?

Try to use another version of netinstall. In the past there were reports that some netinstall versions caused problems for some devices/users while other netinstall versions were fine. In addition, ROS version 6.48 seems to have a few bugs on its own.
by mkx
Sat Jan 30, 2021 11:55 am
Forum: General
Topic: VLAN Access Port on Access Point Issue (Hybrid Access Port) [SOLVED]
Replies: 11
Views: 949

Re: VLAN Access Port on Access Point Issue (Hybrid Access Port) [SOLVED]

Mikrotiks don't know anything about MoCAs ... if the setup works uf AP and router are connected directly by ethernet cable, then the problem is in MoCA devices ... not being transparent enough. The thing is tgat VLAN tags add 4 bytes of overhead to each ethernet frame so any device in the way must s...
by mkx
Sat Jan 30, 2021 12:31 am
Forum: Wireless Networking
Topic: Force client to specific AP...
Replies: 7
Views: 750

Re: Force client to specific AP...

It's strange. Could be some intermittent interference present on channel used by closest AP. As @Normis already wrote: wifi standard does not have anything about mobility hence AP can not force client to connect to another AP, it can only reject registration. But as many have learned, rejecting cli...
by mkx
Fri Jan 29, 2021 10:48 pm
Forum: General
Topic: Share cable IPTV & Internet RB951G/CRS125
Replies: 26
Views: 13769

Re: Share cable IPTV & Internet RB951G/CRS125

regarding the single chip, according to the board schema look like it has 3 wire chips No, these are only converters between QSGMII (interconnect protocol) and ethernet ... they are not switches. Only single block is marked with "Switch chip" and it spans 24 ethernet ports, SFP port and i...
by mkx
Fri Jan 29, 2021 9:59 pm
Forum: Beginner Basics
Topic: Router setup with VLANs [SOLVED]
Replies: 10
Views: 999

Re: Router setup with VLANs [SOLVED]

Dobrodošel na forum! # Because bridging can introduce network loops, # bridge implements various loop preventions mechanisms (STP, RSTP, MSTP). If your LAN layout physically doesn't allow network loops, it's best to disable it. At best ports will get live much faster after they get link up, xSTP tak...
by mkx
Fri Jan 29, 2021 6:19 pm
Forum: RouterBOARD hardware
Topic: hEx S: 802.3at in, passive out?
Replies: 3
Views: 406

Re: hEx S: 802.3at in, passive out?

To clarify a bit: hEX S can have two power sources connected: PoE in (which can be anything between 12V and 57V) or DC jack (with same voltage range). PoE in can be 802.3af/at as well. If both power sources have different voltages (e.g. 802.3af/at at 48V and provided 24V DC adapter), then the source...
by mkx
Fri Jan 29, 2021 5:58 pm
Forum: RouterBOARD hardware
Topic: Best router for Gigabit connection
Replies: 1
Views: 302

Re: Best router for Gigabit connection

For home installation, I'd go with RB4011. CCRs are good at larger number of concurrent connections but not so good at lower number of high throughput connections. In addition, CCR1009 price tag is twice the price tag of RB4011. Also, RB4011 has switch chips (not the greatest functional-wise though)...
by mkx
Fri Jan 29, 2021 5:54 pm
Forum: Wireless Networking
Topic: Force client to specific AP...
Replies: 7
Views: 750

Re: Force client to specific AP...

As @normis wrote, device will try to connect to any AP with same SSID. If you want to constrain certain client devices to certain APs, create SSIDs specifically for each AP (e.g. AP1, AP2, ...) and configure those devices to use appropriate SSID (e.g. configure IoT3 device to connect only to AP #2 b...
by mkx
Fri Jan 29, 2021 5:49 pm
Forum: Wireless Networking
Topic: Any product recommendations for MikroTik wifi router?
Replies: 13
Views: 1124

Re: Any product recommendations for MikroTik wifi router?

Good signal connection that cover 40 sqm.
...
I will use it for cafe.
Reading these two lines together makes me believe OP is writing about square metres ... and any AP positioned centrally will cover square of 7x7 metres just fine.
by mkx
Fri Jan 29, 2021 4:55 pm
Forum: General
Topic: Share cable IPTV & Internet RB951G/CRS125
Replies: 26
Views: 13769

Re: Share cable IPTV & Internet RB951G/CRS125

CRS125 has single switch chip. Which means only one of bridges you created can be HW offloaded. If you want to be deterministic about which one, you should set hw=no on the rest of bridges. My guess is that having HW offload on bridge-local would be more beneficial than on the bridge-dsl-iptv interf...
by mkx
Fri Jan 29, 2021 3:56 pm
Forum: General
Topic: MikroTik USB GPS for NTP service (work? which?)
Replies: 4
Views: 420

Re: MikroTik USB GPS for NTP service (work? which?)

MT support for GPS is partial ... in a sense that with supported GPS modules it is possible to obtain location. What doesn't work is to use GPS module as source for accurate time ... because it takes much more than reading NMEA0183 telegrams to get accurate time (time stamp precision in telegrams is...
by mkx
Tue Jan 26, 2021 10:57 pm
Forum: General
Topic: Poor performance of hEX S + PPPoE
Replies: 4
Views: 290

Re: Poor performance of hEX S + PPPoE

As for ipsec if I use the same entry criteria as above I see IPSEC speeds of 160-180. So in your case you are under a bit but not my that much and perhaps the type of ipsec you are using have is slower? OP is getting more than what you predict: he's running bi-directional test and getting 95Mbps Tx...
by mkx
Mon Jan 25, 2021 9:07 pm
Forum: General
Topic: APC SMT750U & CRS326-24G-2S+RM
Replies: 9
Views: 623

Re: APC SMT750U & CRS326-24G-2S+RM

Even if you did manage to connect it the behaviour may not be what you expect. If the Mikrotik is configured to shutdown on low battery warning and that occurs BUT the mains is restored before the UPS powers off the Mikrotik will still be in shutdown, it requires a power cycle to restart it. For th...
by mkx
Mon Jan 25, 2021 3:35 pm
Forum: General
Topic: X86 and RouterOS (to overcome speed problem)
Replies: 6
Views: 613

Re: X86 and RouterOS (to overcome speed problem)

All MT routers are slow when it comes to encryption ... apart from a few that support HW-assisted encryption but that is currently available for IPsec. And even those don't easily pass multi-100Mbps mark. So yes, probably you'll have to go with x86. But you'll have to benchmark yourself if the devic...
by mkx
Mon Jan 25, 2021 3:16 pm
Forum: General
Topic: Random Disconnections on all LAN Ports (RB3011)
Replies: 3
Views: 323

Re: Random Disconnections on all LAN Ports (RB3011)

Quite a few users reported port flapping on RB3011 when running ROS 6.48. The cure is to downgrade to ROS 6.47.8.
by mkx
Mon Jan 25, 2021 3:14 pm
Forum: General
Topic: Automatically enter in Safe Mode - Option on user group
Replies: 2
Views: 277

Re: Automatically enter in Safe Mode - Option on user group

Our team has repeated complaints of forgetting to activate Safe Mode as soon as it starts changing something in the box. Forgetting to toggle safe mode is a problem. As much as some admins are forgetting to enable safe mode before start of making changes they will forget to exit safe mode after cha...
by mkx
Sun Jan 24, 2021 5:54 pm
Forum: Beginner Basics
Topic: IPv6 address not persistent
Replies: 3
Views: 346

Re: IPv6 address not persistent

This works, both /64 networks are created. However, when I reboot the router, only the first address is still around, the second is gone. On the device with the static IP, routing stops working when rebooting the router. Generally it doesn't make much sense to give device multiple addresses from di...
by mkx
Sun Jan 24, 2021 12:41 pm
Forum: General
Topic: Mikrotik VLAN with Access Point Configuration [SOLVED]
Replies: 7
Views: 639

Re: Mikrotik VLAN with Access Point Configuration [SOLVED]

A few things: remove pvid setting from bridge move DHCP client from ether1 to interface vlan-20-private add interface vlan-20-private to LAN interface list (not that it actually matters in your particular setup but it's the right thing nonetheless) after DHCP client starts to work, remove static IP ...
by mkx
Sun Jan 24, 2021 12:32 pm
Forum: General
Topic: RB2011iL switch chips
Replies: 2
Views: 264

Re: RB2011iL switch chips

Assuming that by writing "group switch" you mean bridge ... you can either use two bridges, each covering ports from one of switch chips (both bridges will be HW offloaded) or you can use single bridge. You should be aware that either way, traffic passing from one switch to another will be...
by mkx
Sun Jan 24, 2021 12:26 pm
Forum: General
Topic: Transparent Bridge
Replies: 5
Views: 522

Re: Transparent Bridge

I don't think that will actually work without any hicups. 802.11 standards don't allow transparent wireless bridge between two wired islands. Most of vendors came up with their own standard extensions for that (Mikrotik included) but those are mutually incompatible and only work if wireless devices ...
by mkx
Sat Jan 23, 2021 10:35 pm
Forum: General
Topic: Mikrotik VLAN with Access Point Configuration [SOLVED]
Replies: 7
Views: 639

Re: Mikrotik VLAN with Access Point Configuration [SOLVED]

Unlike @CZFan I don't see an error in VLAN setup. However, according to configuration set, AP has static IP set (so it should be accessible within VLAN 20), but doesn't have default route set (enough for it to not have internet access) nor does it have DNS server set (even if it did have IP connecti...
by mkx
Sat Jan 23, 2021 5:46 pm
Forum: Wireless Networking
Topic: wlan slave down when wlan master disconnects (station bridge)
Replies: 11
Views: 742

Re: wlan slave down when wlan master disconnects (station bridge)

A better workaround would be to use a dual radio mikrotik. Not a workaroud, it should be actual solution. By using single radio both for connecting to wireless network and as access point, you're cripling the wireless network by using excessive air-time (more than twice compared to normal user). I ...
by mkx
Sat Jan 23, 2021 1:56 pm
Forum: General
Topic: Is RouterOS and (routing in general) still faster on routers than on dedicated computer ? [SOLVED]
Replies: 13
Views: 1167

Re: Is RouterOS and (routing in general) still faster on routers than on dedicated computer ? [SOLVED]

In MT world there are two types of "top end" routers (with third type emerging with ROSv7), all come with their own limitations: routers with large number of CPU cores (e.g. CCR1036 and CCR1072). They shine when large number of concurrent connections have to be handled. They suck if one wa...
by mkx
Sat Jan 23, 2021 1:13 pm
Forum: General
Topic: Dot1x and Reject-VLAN-ID
Replies: 9
Views: 702

Re: Dot1x and Reject-VLAN-ID

... when I connect a non-authenticated device, it puts me in some never-never land. I'm not on the guest VLAN according to Wireshark. DHCP Discover packets go unanswered. When I manually configure the Mikrotik interface for the "guest" VLAN and disable dot1x for that interface - I'm on th...
by mkx
Fri Jan 22, 2021 11:41 pm
Forum: General
Topic: RB4011iGS+5HacQ2HnD-IN Issues
Replies: 4
Views: 440

Re: RB4011iGS+5HacQ2HnD-IN WiFi CAP issue

Do you have any ideas?

Not without seeing complete (or most of) setup of RB4011.
by mkx
Fri Jan 22, 2021 9:46 pm
Forum: Wireless Networking
Topic: decrease transmit power
Replies: 12
Views: 931

Re: decrease transmit power

In capsman you can limit Tx power under /caps-man channel ... even if you currently have something there, you'll want to create a new one (possibly similar to the existing one), but with tx-power property set add name=lowpower tx-power=15 and then use that setting in /caps-man configuration as chann...
by mkx
Fri Jan 22, 2021 9:26 pm
Forum: General
Topic: APC SMT750U & CRS326-24G-2S+RM
Replies: 9
Views: 623

Re: APC SMT750U & CRS326-24G-2S+RM

My suggestion: just don't. As you already discovered, UPS support in ROS is not worth mentioning, plus UPS control from router doesn't add any value (to uncontrolled UPS).
by mkx
Fri Jan 22, 2021 9:23 pm
Forum: General
Topic: Continued hap ac2 memory and upgrade/package problems
Replies: 2
Views: 995

Re: Continued hap ac2 memory and upgrade/package problems

Looking at OP's screenshots I'd say that reason for his device not wanting to upgrade is package hotspot which seems to be installed twice - once as part of basic bundle and the other time as extra package. Upgrade procedure seems to not be able to deal with such installations. Way out is indeed net...
by mkx
Thu Jan 21, 2021 8:23 pm
Forum: Wireless Networking
Topic: decrease transmit power
Replies: 12
Views: 931

Re: decrease transmit power

I did not try it (nor do I have measurement tools to measure effects reliably), but @Normis wrote a topic post about setting Tx power: https://forum.mikrotik.com/viewtopic.php?t=170014#p834666 ... I've no reason not to believe in what a MT staffer writes and according to what he wrote, things are pl...
by mkx
Thu Jan 21, 2021 7:55 pm
Forum: General
Topic: Is there a way to log into admin panel if service on port 80 was accidentially turned off
Replies: 13
Views: 820

Re: Is there a way to log into admin panel if service on port 80 was accidentially turned off

It's not that MAC-telnet used by Winbox for MAX connections is plain text ... But yes, it's better to use some well known security protocols (such as IPsec or WireGuard) than some proprietary protocols that nobody knows what they are doing when working in hostile environment.
by mkx
Thu Jan 21, 2021 12:32 am
Forum: General
Topic: Why is not blocking an ip adress
Replies: 6
Views: 420

Re: Why is not blocking an ip adress

/ip firewall address-list
add address=1.2.3.4 address-list=blocked_addresses
add address=2.3.4.5 address-list=blocked_addresses
Yup, you can also add subnets as in your example.
by mkx
Wed Jan 20, 2021 11:53 pm
Forum: General
Topic: Xem tử vi 2021 tuổi Nhâm Thân chi tiết từng tháng
Replies: 2
Views: 246

Re: RouterOS Firewall configuration when using a bridge with multiple VLANs

Currently you have something like this: /interface bridge add name=bridge-vlan20 add name=bridge-vlan30 /interface vlan add interface=ether1 name=e1v20 vlan-id=20 add interface=ether2 name=e2v20 vlan-id=20 add interface=ether1 name=e1v30 vlan-id=30 /interface bridge port add bridge=bridge-vlan20 int...
by mkx
Wed Jan 20, 2021 11:37 pm
Forum: General
Topic: Why is not blocking an ip adress
Replies: 6
Views: 420

Re: Why is not blocking an ip adress

If you want to block just any traffic with select remote address(es), the most router-friendly way is to use raw filters:
/ip firewall raw
add chain=prerouting action=drop src-address-list=blocked_addresses
and fill /ip firewall address-list with banned addresses ...
by mkx
Wed Jan 20, 2021 11:26 pm
Forum: General
Topic: Updating limit-uptime using telnet [SOLVED]
Replies: 3
Views: 326

Re: Updating limit-uptime using telnet [SOLVED]

Never tried hotspot, but this might work for existing users:
/ip hotspot user set [ find name=user1 ] limit-uptime=20
by mkx
Wed Jan 20, 2021 11:20 pm
Forum: General
Topic: Wrong reported link speed in terminal
Replies: 1
Views: 186

Re: Wrong reported link speed in terminal

By executing /interface ethernet print .... you're getting actual static settings (similar but not exactly the same as /interface ethernet export). What you're after is output of command /interface ethernet monitor ether1 once ...
by mkx
Tue Jan 19, 2021 9:28 pm
Forum: Wireless Networking
Topic: wlan slave down when wlan master disconnects (station bridge)
Replies: 11
Views: 742

Re: wlan slave down when wlan master disconnects (station bridge)

No, slave wireless interface can not run if master is not running. I'd suggest you to return the new laptop due to lack of fundamental functionality (wired network connectivity) but you probably don't want to. So you'll have to get a USB (or TB or whatever wired peripherial connectivity available) e...
by mkx
Mon Jan 18, 2021 11:20 pm
Forum: Beginner Basics
Topic: Need help on how to install RouterOS on my server
Replies: 1
Views: 194

Re: Need help on how to install RouterOS on my server

There may be some guides (in form of books) by 3rd party writers, but Mikrotik only provides some sort of reference manual: https://help.mikrotik.com/docs/display/ROS/RouterOS https://wiki.mikrotik.com/wiki/Manual:TOC https://help.mikrotik.com/docs/display/UM/User+Manuals As to installation: I sugge...
by mkx
Mon Jan 18, 2021 11:11 pm
Forum: RouterOS v7 BETA
Topic: Feature Request: Bridge Joiner
Replies: 11
Views: 1223

Re: Feature Request: Bridge Joiner

Do you have an example? Something in line of this: /interface bridge add name=bridge_left add name=bridge_right add name=bridge_top /interface bridge port add bridge=bridge_left interface=ether1 add bridge=bridge_left interface=ether2 add bridge=bridge_left interface=ether3 # add bridge=bridge_righ...
by mkx
Sun Jan 17, 2021 8:24 pm
Forum: Beginner Basics
Topic: I tried to move ether2 out of bridge1 and somehow broke IPv4 [SOLVED]
Replies: 5
Views: 449

Re: I tried to move ether2 out of bridge1 and somehow broke IPv4 [SOLVED]

It seems that interface list members is hosed (at least bridge interface should be member of LAN interface lust and ether1 member of WAN interface list). However, I still suggest you to perform factory reset and re-do the necessary configuration adjustments. The main reason being: firewall (both IP ...
by mkx
Sun Jan 17, 2021 4:01 pm
Forum: RouterBOARD hardware
Topic: CRS 112-4G-8S: problem with packet loss and preformance
Replies: 4
Views: 2734

Re: CRS 112-4G-8S: problem with packet loss and preformance

Did you upgrade routerboot as well? (/system routerboard upgrade). And a decent (prolonged) power-off after that?
by mkx
Sun Jan 17, 2021 3:52 pm
Forum: Beginner Basics
Topic: Firewall: Invalid forward packets, unknown input [SOLVED]
Replies: 4
Views: 499

Re: Firewall: Invalid forward packets, unknown input [SOLVED]

invalid forward: in:bridge out:ether1, src-mac xx..., proto TCP (RST), 10.0.0.204:57914->23.3.109.12:443, len 40 invalid forward: in:bridge out:ether1, src-mac ...., proto TCP (ACK,FIN), 10.0.0.152:60806->54.173.8.102:80, len 52 Really depends on context ... It is expected to happen right after rou...
by mkx
Sun Jan 17, 2021 12:17 pm
Forum: RouterBOARD hardware
Topic: how CCR1036-8G-2S+EM can distribute 20Gbps downlink
Replies: 4
Views: 526

Re: how CCR1036-8G-2S+EM can distribute 20Gbps downlink

Again: in throughput tests, there is no uplink and downlink, it's traffic between ports, where all connected devices (to all ports) are equal peers communicating between each other. In your case, however, some devices (clients, those connected to 1Gbps ports) only communicate with devices connected ...
by mkx
Sun Jan 17, 2021 11:55 am
Forum: Beginner Basics
Topic: Need help setting up (VLAN?) [SOLVED]
Replies: 8
Views: 796

Re: Need help setting up (VLAN?) [SOLVED]

On all but CRS3xx devices bridge settings don't affect the way switch chip is configured. They (switch chip and bridge) act independently[*] but may mess with each other, hence best is to use one of them in "plain" configuration. Which in your case means you should not configure vlan-relat...
by mkx
Sun Jan 17, 2021 11:32 am
Forum: Beginner Basics
Topic: Accessing an hAP ac2 [SOLVED]
Replies: 5
Views: 487

Re: Accessing an hAP ac2 [SOLVED]

Unless you changed default config you should be able to access hAP ac2 through its LAN interfaces ... in short these are interfaces which give you IP address in 192.168.88.0/24 subnet via DHCP. By default management access is blocked from WAN and your 192.168.1.0/24 subnet is WAN for hAP ac2. If you...
by mkx
Sun Jan 17, 2021 11:19 am
Forum: RouterOS v7 BETA
Topic: Feature Request: Bridge Joiner
Replies: 11
Views: 1223

Re: Feature Request: Bridge Joiner

You can already do it ... using another bridge.
by mkx
Sat Jan 16, 2021 4:46 pm
Forum: RouterBOARD hardware
Topic: RB4011, 260GS and SFP link [SOLVED]
Replies: 4
Views: 613

Re: RB4011, 260GS and SFP link [SOLVED]

XS-DA00001 supports 1Gbps (I'd be surprised if it wasn't as it's a passive DAC). What only matters is if devices on both ends support same rate at their SFP (plain/+/28) cages. (And whether they support passive DAC at all). SFP cage rate is usually not auto-negotiated ... it can adjust if active equ...
by mkx
Sat Jan 16, 2021 4:35 pm
Forum: RouterBOARD hardware
Topic: CCR1036-8G-2Splus vs i7 4790/ 16G RAM/ 64G ssd/ 2 sfp+
Replies: 1
Views: 287

Re: CCR1036-8G-2Splus vs i7 4790/ 16G RAM/ 64G ssd/ 2 sfp+

For BGP x64 server wins hands down. For routing of speed testong connections, x64 is probably faster. For routing/firewalling/etc of large number of concurrent connections, CCR may be faster still.
by mkx
Sat Jan 16, 2021 4:29 pm
Forum: RouterBOARD hardware
Topic: how CCR1036-8G-2S+EM can distribute 20Gbps downlink
Replies: 4
Views: 526

Re: how CCR1036-8G-2S+EM can distribute 20Gbps downlink

Is this the problem in hardware design? No, the problem is that you chose wrong device for your use case. Throughput tests are done so that ports are used bi-directionally and independently. Which means that diring tests device is routing between both 10Gbps interfaces full-duplex, which means 20Gb...
by mkx
Sat Jan 16, 2021 4:19 pm
Forum: Wireless Networking
Topic: Output Power too high
Replies: 1
Views: 312

Re: Output Power too high

I think you should communicate this directly with support@mikrotik.com ... probably they'll want supout files from both units (CAPsMAN manager and CAP device) to verify that CAP device is indeed transmitting at power higher than HW limit.
by mkx
Sat Jan 16, 2021 4:16 pm
Forum: Wireless Networking
Topic: Can't get DHCP on non-Mikrotik networks
Replies: 4
Views: 398

Re: Can't get DHCP on non-Mikrotik networks

DHCP client gets all the information from DHCP server. So if clients of your MT DHCP server don't get default route, you should configure DHCP server appropriately.
by mkx
Sat Jan 16, 2021 3:36 pm
Forum: RouterOS v7 BETA
Topic: Any chance to install ROS6 on Chateau 12?
Replies: 6
Views: 942

Re: Any chance to install ROS6 on Chateau 12?

Never tried myself with netinstall, but MT devices generally refuse to install ROS version lower than factory default. Reasoning behind it is that older versions of ROS may lack some vital drivers and would brick the device. Which can be a PITA sometimes if one wants slightly older ROS on an otherwi...
by mkx
Sat Jan 16, 2021 3:28 pm
Forum: Beginner Basics
Topic: Crs 112 Proplem
Replies: 8
Views: 458

Re: Crs 112 Proplem

The errors in log look like your device is running user manager . As there are errors, it could well be that configuration reset doesn't fix the problem. The best bet would be netinstall with no default config, after that configure bare minimum (e.g. bridge all port, minimal management access and ab...
by mkx
Sat Jan 16, 2021 3:22 pm
Forum: Beginner Basics
Topic: Need help setting up (VLAN?) [SOLVED]
Replies: 8
Views: 796

Re: Need help setting up (VLAN?) [SOLVED]

Basically forget about the vlan-header= setting While you can forget about the setting on said switch chips (BTW, I have one of them as well), the correct setting for access port (which should egress only untagged frames) is vlan-header=always-strip none the less. Regarding reset button: some devic...
by mkx
Sat Jan 16, 2021 3:12 pm
Forum: Beginner Basics
Topic: Mikrotik DHCP
Replies: 3
Views: 376

Re: Mikrotik DHCP

In addition: you should not judge by timers ... When things are clean (i.e. devices are all new to network, DHCP server did not lease any address from a pool yet), MT DHCP server will assign addresses sequentially. But address leases have predefined life time and clients have to renew leases. Normal...
by mkx
Fri Jan 15, 2021 11:15 am
Forum: Beginner Basics
Topic: NAT Loopback / DNS
Replies: 9
Views: 645

Re: NAT Loopback / DNS

Problem is, I can't use that same address to access the unit from within the same LAN.

You need hairpin NAT.
by mkx
Fri Jan 15, 2021 11:11 am
Forum: Beginner Basics
Topic: Crs 112 Proplem
Replies: 8
Views: 458

Re: Crs 112 Proplem

Log says your disk drive is full. You have to do something about it.
by mkx
Thu Jan 14, 2021 10:02 am
Forum: Wireless Networking
Topic: Can't get DHCP on non-Mikrotik networks
Replies: 4
Views: 398

Re: Can't get DHCP on non-Mikrotik networks

I've been having this oddball problem with my mANTbox 19s and Metal 52ac where when in station mode, they can't get DHCP on a network when the access point is not from Mikrotik. Just to verify: if you point a ROS wireless device to third-party AP as client, the ROS device itself can't get DHCP leas...
by mkx
Thu Jan 14, 2021 9:47 am
Forum: General
Topic: detect internet doesn't work on sfp4
Replies: 1
Views: 154

Re: detect internet doesn't work on sfp4

I don't have 1st hand experience ... the benefits of using this feature are moot. But anyway, this manual article explains prerequisites for individual states and how interfaces transition between the states. You may want to check manually if the check, needed for state "internet", succeed...
by mkx
Thu Jan 14, 2021 9:39 am
Forum: Beginner Basics
Topic: 2 vlans with NAT
Replies: 4
Views: 431

Re: 2 vlans with NAT

How and should I recognize VLANs 22 and 32 on Eth1? How should I configure NAT? How can I make leave route trough ETH5 and tagg it with VLAN 22, 32? If those were not tagged (somehow) on Eth1 input? When using VLANs in RouterOS, you have to start using vlan interfaces, these allow ROS to work with ...
by mkx
Wed Jan 13, 2021 8:48 pm
Forum: Beginner Basics
Topic: Need help setting up (VLAN?) [SOLVED]
Replies: 8
Views: 796

Re: Need help setting up (VLAN?) [SOLVED]

Regarding "independent-learning" bit, is this useful for anything but "same mac could appear on different ports" scenario? Some OSes (e.g. Linux) use same MAC address for all VLANs using same physical interface. In some circumstances (right now I don't remember an example, but w...
by mkx
Tue Jan 12, 2021 10:44 pm
Forum: General
Topic: High CPU Crs328
Replies: 4
Views: 390

Re: High CPU Crs328

What does /tool profile show, where does CPU spend most of cycles?
by mkx
Tue Jan 12, 2021 10:24 pm
Forum: Beginner Basics
Topic: Need help setting up (VLAN?) [SOLVED]
Replies: 8
Views: 796

Re: Need help setting up (VLAN?) [SOLVED]

So basically you want to have eth1 and eth2 switched as ISP "lan" and add to that a dedicated SSID on wlan. On the other hand you'd like to have eth3, eth4 and eth5 switched as LAN and add to that its own SSID? Prior to reconfiguration, I suggest you to make backup of device and copy backu...
by mkx
Sun Jan 10, 2021 10:34 pm
Forum: General
Topic: RB750Gr3 difference between workstation speedtest vs bandwitch test
Replies: 13
Views: 751

Re: RB750Gr3 difference between workstation speedtest vs bandwitch test

It has always been unclear to me what the method is to choose between the two modes. "with disabled switching" and "with enabled switching", what does it mean? I guess that switching case is when two or more ports are members of a bridge and thus switch traffic between ports. Th...
by mkx
Sun Jan 10, 2021 8:02 pm
Forum: General
Topic: RB2011UiAS-2HnD / Draytek Vigor 130 - PPPoE connection problems
Replies: 18
Views: 992

Re: RB2011UiAS-2HnD / Draytek Vigor 130 - PPPoE connection problems

Just shooting fish in a barrel: check if Drytek has PPPoE session active and if yes, disable it. Longer story: my ISP provides me with xDSL modem / router combo, which I tend to use in bridge mode. Internet service is provided via PPPoE and (due to having static address) there can only be one PPPoE ...
by mkx
Sun Jan 10, 2021 1:05 pm
Forum: Beginner Basics
Topic: Dynamic PCQ / Queue for varying bandwidth
Replies: 2
Views: 285

Re: Dynamic PCQ / Queue for varying bandwidth

PCQ can't work correctly if it doesn't know what is the limit. In theory it could learn about the limit by observing various transfer properties (achieved throughput, RTT of TCP packets, etc.), but it would be quite unreliable because transfer properties are affected by every single path part for ev...
by mkx
Sun Jan 10, 2021 12:51 pm
Forum: Beginner Basics
Topic: Setting a VLAN on a PPPOE connection.
Replies: 2
Views: 276

Re: Setting a VLAN on a PPPOE connection.

What do you do when one has to associate with a VLAN??????

Exactly according to your example.
by mkx
Sat Jan 09, 2021 2:49 pm
Forum: SwOS
Topic: MAC Address Change
Replies: 2
Views: 346

Re: MAC Address Change

Are you sure you need to change MAC address on a switch port? Ethernet MAC addresses come into play for higher-layer services (e.g. IP layer or PPPoE client service, cloning MAC on your RB4011 is actually such use), but such connection is passed transparently over ethernet switch / L2 bridge. So you...
by mkx
Sat Jan 09, 2021 2:38 pm
Forum: RouterBOARD hardware
Topic: wAP LTE Kit died after fell off a chair
Replies: 5
Views: 696

Re: wAP LTE Kit died after fell off a chair

poor production. So when you drop on your head from height of 1 meter, no healing is needed? I'd guess so based on your comment. I'm not sure about Mikrotik hardware, but many HW come with "shock rating" ... operating and non-operating, usually rating is around 1g ... so if such device fe...
by mkx
Sat Jan 09, 2021 2:17 pm
Forum: Beginner Basics
Topic: DHCP Client on CRS interface got IP once, then expired..
Replies: 8
Views: 564

Re: DHCP Client on CRS interface got IP once, then expired..

CRS behaves like a switch as long as it simply passes unaltered frames between its ether ports. When it starts to route (between VLANs and towards internet, when it performs other L3 duties such as DHCP client/server), then it's IP device. So if you have a device in one of VLANs with MTU of (say) 90...
by mkx
Sat Jan 09, 2021 2:02 pm
Forum: Wireless Networking
Topic: Maximum wifi bandwidth for Hap AC 2 [SOLVED]
Replies: 1
Views: 596

Re: Maximum wifi bandwidth for Hap AC 2 [SOLVED]

WiFi being TDMA half-duplex, every single device within certain area (defined by signal strength and reception sensitivity of AP) will share the bandwidth available. With 2x2 mimo (that's the number of chains) in 802.11ac theoretical maximum is 867Mbps. From that number it is necessary to substract ...
by mkx
Sat Jan 09, 2021 1:21 pm
Forum: Beginner Basics
Topic: DHCP Client on CRS interface got IP once, then expired..
Replies: 8
Views: 564

Re: DHCP Client on CRS interface got IP once, then expired..

One of problems is that single bridge (L2 interconnect) has ports members with different MTUs ... which is not exactly wrong per-se. L2 device does not perform segmentation, so all L3 interfaces and devices within single L3 sub-domain should use exactly same MTU value. The problem is that L3 interfa...
by mkx
Fri Jan 08, 2021 7:22 pm
Forum: Beginner Basics
Topic: Basic Understanding Bridge, VLAN, Switch, ... [SOLVED]
Replies: 23
Views: 1842

Re: Basic Understanding Bridge, VLAN, Switch, ... [SOLVED]

Well, I guess you thought out everything. So just go ahead and implement the LAN upgrade.
by mkx
Thu Jan 07, 2021 9:40 pm
Forum: General
Topic: IPIP Tunnel and inner IPv6 not working
Replies: 3
Views: 272

Re: IPIP Tunnel and inner IPv6 not working

You need ipip6 tunnel.
by mkx
Thu Jan 07, 2021 9:23 pm
Forum: Beginner Basics
Topic: Speed of internet not working on RB951G-2HnD
Replies: 9
Views: 735

Re: Speed of internet not working on RB951G-2HnD

The export only contains a fraction of configuration. Using leading slash is important. However, judging from that fragment I'd say it's running old version of ROS and/or config based on old defaults. As the device should be able to route something around 200Mbps (sum of all directions), I suggest t...
by mkx
Thu Jan 07, 2021 9:11 pm
Forum: Beginner Basics
Topic: LTE Linking to two towers??
Replies: 4
Views: 364

Re: LTE Linking to two towers??

Multi-tower support is there, but not all networks support it and not all CA-capable terminals support it. However, I don't think B20 intraband CA is supported at all (even for single-tower setups). And CA only works for cells usung different frequencies. LTE networks are SFN (single-frequency nerwo...
by mkx
Thu Jan 07, 2021 9:07 pm
Forum: Beginner Basics
Topic: VLAN on CRS354 device [SOLVED]
Replies: 1
Views: 206

Re: VLAN on CRS354 device [SOLVED]

Read through this tutorial, it will be HW offloaded on your CRS.
  • 1
  • 2
  • 3
  • 4
  • 5
  • 19