Community discussions

Search found 2569 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 52
by mkx
Sat Aug 17, 2019 6:24 pm
Forum: Beginner Basics
Topic: Routing both lan and wan on one interface
Replies: 1
Views: 187

Re: Routing both lan and wan on one interface

It is possible and I'm sure there are many ways to do it. From L2 (connectivity) point of view, you can use separate VLANs to separate different networks (WAN v.s. LAN) passing the same wire. From L3 point kf view, you may want to consider if firewalling the WAN-addressed virtual server should be do...
by mkx
Sat Aug 03, 2019 9:19 pm
Forum: General
Topic: Transparent NAT
Replies: 5
Views: 474

Re: Transparent NAT

Most LTE modems playing smart by doing NAT themselves are not configurable enough to do netmap-style of NAT ... even if they do, you should find a way to configure that on the LTE modem thingy, nothing to be done on RB. And since you want to perform NAT on CCR in a smart way, you can't do netmap-sty...
by mkx
Sat Aug 03, 2019 7:31 pm
Forum: RouterBOARD hardware
Topic: CRS112x strange issue [SOLVED]
Replies: 7
Views: 787

Re: CRS112x strange issue [SOLVED]

How are PCs set-up ... IP address, subnet mask, default gateway? Is there a DHCP server involved or you set them up manually?
by mkx
Sat Aug 03, 2019 5:07 pm
Forum: RouterBOARD hardware
Topic: CRS112x strange issue [SOLVED]
Replies: 7
Views: 787

Re: CRS112x strange issue [SOLVED]

Did you tey to reboot CRS after change of IP? It shouldn't matter, but who knows ...

Does /interface bridge port print show 'H' in flags column for ether and sfp ports?
by mkx
Sat Aug 03, 2019 2:35 pm
Forum: Beginner Basics
Topic: Access DSL modem in "bridge mode" behind Mikrotik [SOLVED]
Replies: 12
Views: 1048

Re: Access DSL modem in "bridge mode" behind Mikrotik [SOLVED]

When you're testing ping from PfSense, does counter of the appropriate masquerade rule increase?
by mkx
Sat Aug 03, 2019 1:04 pm
Forum: Beginner Basics
Topic: Not showing IP on connected devices [SOLVED]
Replies: 13
Views: 952

Re: Not showing IP on connected devices [SOLVED]

Please post output of command /export hide-sensitive (run it from a command window) ... and obfuscate public addresses ... paste it inside [code][/code] environment for better readability.

No need for verbosity, but do post complete setup, sometimes problems are hidden elsewhere.
by mkx
Sat Aug 03, 2019 12:58 pm
Forum: Beginner Basics
Topic: Two VLANs in a bridge or two bridges
Replies: 2
Views: 361

Re: Two VLANs in a bridge or two bridges

Option with two bridges allows HW offload on ether ports of one of bridges (probably you want this on LAN bridge), while single-bridge-multiple-VLAN does not if VLANs are configured on bridge.. If functionality-wise you're happy with your current setup, then you should stick to it. If you stick to t...
by mkx
Sat Aug 03, 2019 12:30 pm
Forum: Beginner Basics
Topic: Access DSL modem in "bridge mode" behind Mikrotik [SOLVED]
Replies: 12
Views: 1048

Re: Access DSL modem in "bridge mode" behind Mikrotik [SOLVED]

Does PfSense know about 172.16.2.0/24? Or it treats it as "normal" WAN address?

Can your RB ping Vigor?
by mkx
Sat Aug 03, 2019 10:19 am
Forum: General
Topic: Very simple VLAN
Replies: 16
Views: 1279

Re: Very simple VLAN

Thanks - and is there a simple way to "tie" the two subnets together so that everything (including broadcast) works across them both? Subnets and common broadcast domains don't go together. Unless you know well what you're doing ... but then you wouldn't be asking this particular question here ...
by mkx
Sat Aug 03, 2019 10:16 am
Forum: Beginner Basics
Topic: Port Forward/Passthrough
Replies: 5
Views: 408

Re: Port Forward/Passthrough

By default, connections from LAN to WAN are not restricted in any way. The only requirement us a working SRC-NAT configuration (which is there by default on SOHO models as well unless WAN connectivity type is a non-common one). You're mentioning a /25 WAN subnet which indicates a non-common setup (f...
by mkx
Fri Aug 02, 2019 7:39 pm
Forum: Beginner Basics
Topic: Routing between bridged interfaces and a port [SOLVED]
Replies: 1
Views: 297

Re: Routing between bridged interfaces and a port [SOLVED]

Router needs IP address for each subnet it should be routing to/from.

Read up some IP routing basics ... when you do, don't skip the part with multiple routers in same network, this is the part where fun begins.
by mkx
Fri Aug 02, 2019 2:32 pm
Forum: Beginner Basics
Topic: Router for 1Gbit Wan from Mikrotik (What model?)
Replies: 4
Views: 599

Re: Router for 1Gbit Wan from Mikrotik (What model?)

CRS line are switches with L3 functionality. It's fine to use them with ROS as switches (you don't have to boot SwOS for that). You should go for RB line, such as RB750Gr3 (which probably barely reaches your requirements) or some faster model (those typically come with bigger number of ports) such a...
by mkx
Thu Aug 01, 2019 5:41 pm
Forum: General
Topic: CRS317-1G-16S+RM as storage switch
Replies: 4
Views: 528

Re: CRS317-1G-16S+RM as storage switch

CRSes will be as good as any other managed switch with regard to iSCSI...
by mkx
Thu Aug 01, 2019 3:10 pm
Forum: RouterBOARD hardware
Topic: GPeR question
Replies: 14
Views: 1518

Re: GPeR question

I can see a communication noise happening around here. How about MT guys writing a few lines of technical description about GPeR ... what is it, how it works. Doesn't really have to disclose some patented technology ... I guess it's about a fairly simple (electrical) signal shaper with some DC bypas...
by mkx
Thu Aug 01, 2019 12:33 pm
Forum: RouterBOARD hardware
Topic: RouterBOARD naming
Replies: 47
Views: 22982

Re: RouterBOARD naming

1. I prefer the classic or Hex-S (!) style :-)

Say hello to Flintstones next time you meet them :wink:

Black is new white :lol:
by mkx
Thu Aug 01, 2019 12:30 pm
Forum: RouterBOARD hardware
Topic: 1100x4 unexpected downgrade
Replies: 4
Views: 391

Re: 1100x4 unexpected downgrade

This could happen if NAND was partitioned (for fall-back) and the backup partition never got updated (neither ROS nor config). The mechanism is such that routerboot starts device from the other partition if there's an error making RB to reboot. Power outage counts as such (personally I don't think p...
by mkx
Thu Aug 01, 2019 12:24 pm
Forum: Wireless Networking
Topic: Long range connection
Replies: 17
Views: 1285

Re: Long range connection

Other technologies like 4G use a lot more power and they can do it. Just a tad of nitpicking: user's equipment in 4G operates at similar Tx powers as WiFi (max Tx power at around 20dBm) and also uses similarly shitty antennae (with gain around 0dBi) ... the difference is in the base stations: those...
by mkx
Thu Aug 01, 2019 7:02 am
Forum: Beginner Basics
Topic: No internet on LAN - hex rb750gr3 with E3372
Replies: 12
Views: 974

Re: No internet on LAN - hex rb750gr3 with E3372

So did you try to add lte1 interface to WAN interface list? Did it do the trick or not?
by mkx
Wed Jul 31, 2019 10:20 pm
Forum: Beginner Basics
Topic: No internet on LAN - hex rb750gr3 with E3372
Replies: 12
Views: 974

Re: No internet on LAN - hex rb750gr3 with E3372

None of your routing information/config is there?? Probably because all of it is dynamic. /ip route print and /ip address print would reveal lots of things. Before posting output of these commands do obfuscate public IP addresses ... but do it consistently so that it will be obvious what belongs to...
by mkx
Wed Jul 31, 2019 3:49 pm
Forum: Beginner Basics
Topic: NAT is blocking the acess to that port when active
Replies: 2
Views: 311

Re: NAT is blocking the acess to that port when active

Probably your DST-NAT rule is too general. Execute command /ip firewall nat export in a terminal window and post result here.
by mkx
Tue Jul 30, 2019 11:25 pm
Forum: General
Topic: NAT to a local server
Replies: 25
Views: 1687

Re: NAT to a local server

When setting in-interface=bridge NAT should stop working for connections from WAN ...
by mkx
Tue Jul 30, 2019 11:11 pm
Forum: Wireless Networking
Topic: How to get signal-strength from wireless card
Replies: 3
Views: 405

Re: How to get signal-strength from wireless card

Signal strength has its meaning for the receiving party. When device is in station mode, it only talks to single peer and signal strength of that peer is a fairly good indication of the two-way connection quality. When device is in ap mode (any of them), it's talking to many peers and none of them c...
by mkx
Tue Jul 30, 2019 5:31 pm
Forum: General
Topic: Calculating Power Consumption for POE
Replies: 2
Views: 355

Re: Calculating Power Consumption for POE

cAP ac supports PoE-out ... connected PoE client would count as attachment. Some other devices feature USB ports which can be used to connect some power-hungry peripherials, such as LTE modems or flash sticks... Or miniPCIe slots to add wireless or LTE interfaces ... All of those count as attachments.
by mkx
Tue Jul 30, 2019 5:22 pm
Forum: General
Topic: Router OS in GSM environment
Replies: 2
Views: 351

Re: Router OS in GSM environment

Routeros is about data (IP in particular) routing. If you're talking about VoIP, then many people did it. If you're talking about GSM circuit-switched voice, then ROS won't help you. Not many GSM chipsets support digital voice break-out ... and even if some does, it is 64kbps ADPCM or something simi...
by mkx
Mon Jul 29, 2019 11:16 pm
Forum: RouterBOARD hardware
Topic: GPeR question
Replies: 14
Views: 1518

Re: GPeR question

1) Of course it matters (and two port has nothing to do with it) Really ... what's the big difference between 2-port ethernet hub and 2-port ethernet switch? And yes, port count has everything to do with it. Instead of forwarding frame to the other port because forwarding table (MAC address list) o...
by mkx
Mon Jul 29, 2019 5:49 pm
Forum: General
Topic: PPPoE Client as main Link 3G as Backup
Replies: 1
Views: 242

Re: PPPoE Client as main Link 3G as Backup

How about searching for mikrotik dual wan failover using your favourite internet search page? One of top results is this manual page, seems promissing to me.
by mkx
Mon Jul 29, 2019 5:35 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Possible security breach
Replies: 12
Views: 4639

Re: Possible security breach

Old thread, I know, but I think its worth bumping. I had same thing happen to me. There were 2 ptty scripts in my scheduler. I had my router exposed to WAN with default username only a matter of minutes but didnt notice the script until a few days later. I deleted scripts, the admin user, the new r...
by mkx
Sun Jul 28, 2019 2:38 pm
Forum: General
Topic: Login failure for user Radius via api
Replies: 3
Views: 421

Re: Login failure for user Radius via api

API login method has changed.
by mkx
Sun Jul 28, 2019 2:33 pm
Forum: Beginner Basics
Topic: Vlan config and bridging
Replies: 3
Views: 476

Re: Vlan config and bridging

There are many points where things might have turned wrong way. Post output of /export hide-sensitive after you've mangled any remaining sensitive data such as public IP addresses ...
by mkx
Sat Jul 27, 2019 11:18 pm
Forum: Beginner Basics
Topic: Fixed IP using VLANs. How?
Replies: 1
Views: 275

Re: Fixed IP using VLANs. How?

IMHO LAN infrastructure devices should for very same reason have their IP addresses set statically.
by mkx
Fri Jul 26, 2019 8:59 pm
Forum: Wireless Networking
Topic: Wifi equipment for 70m distance behind windows
Replies: 14
Views: 1007

Re: Wifi equipment for 70m distance behind windows

Powering is not a problem...i have power outlet on balcony. A what to use for device in building 1? I'm not sure if supplied power adapter is weatherproof as well ... For the building1 any routerboard with 2.4GHz wireless would do. In absence of other ideas/reasons I'd go with second wAP ac (for no...
by mkx
Fri Jul 26, 2019 8:52 pm
Forum: General
Topic: How debug L2 and IP firewall?
Replies: 4
Views: 400

Re: How debug L2 and IP firewall?

I think you should properly separate ether2 from the rest of LAN on L2 by removing ether2 from brudge and then assure needed communication by routing and firewalling. You'd need separate subnet (probably a /30 would do) for connection between RB and the "untrusted network"'s gateway. If you go this ...
by mkx
Fri Jul 26, 2019 7:25 pm
Forum: General
Topic: How debug L2 and IP firewall?
Replies: 4
Views: 400

Re: How debug L2 and IP firewall?

  1. Are you testing connectivity from LAN device from one subnet towards router's address in another subnet or you're testing between LAN devices?
  2. Post complete configuration (output of command /export hide-sensitive and obfuscate sensitive data, such as public IP address)
by mkx
Fri Jul 26, 2019 7:09 pm
Forum: Wireless Networking
Topic: Wifi equipment for 70m distance behind windows
Replies: 14
Views: 1007

Re: Wifi equipment for 70m distance behind windows

If we set aside problem with powering (wireless powering wasn't seriously developed ever since Tesla failed to extort more money from J.P.Morgan), a wAP ac would make a good wireless hop.

As both hops (2.4 and 5GHz) would essentially be point-to-point, I'd configure them as nstreme bridges.
by mkx
Fri Jul 26, 2019 4:21 pm
Forum: Beginner Basics
Topic: VLAN 1003 über eigenen Switchport
Replies: 2
Views: 274

Re: VLAN 1003 über eigenen Switchport

Depends on how things are set up currently. If AP tags the traffic itself, then you can set port vlan security so that on ingress it only accepts tagged frames. A random passer-by won't know it needs to tag packets so for him the port will seem useless. If one knows to tag frames with correct VID, h...
by mkx
Fri Jul 26, 2019 1:51 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Feature requests
Replies: 1111
Views: 196048

Re: Feature requests

Need feature to detect if device have poe-out interfaces - now any poe-command (even print command) causes error in script if HW doesn't have poe-out interfaces... I don't know how to script it, but possibility is available already: /interface print where type=pppoe-out pppoe has no relation to poe...
by mkx
Fri Jul 26, 2019 1:49 pm
Forum: Wireless Networking
Topic: Wifi equipment for 70m distance behind windows
Replies: 14
Views: 1007

Re: Wifi equipment for 70m distance behind windows

If the reason for avoiding LAN cables is fear for interference from power lines to UTP cables or fear for some power surges, then you could use fibre connection between the "main wireless hop" (building-2-building) and their hAP ac2 ... dumb media converters supporting multi-mode fibre and 10/100 Mb...
by mkx
Fri Jul 26, 2019 1:41 pm
Forum: Wireless Networking
Topic: Intel Wireless Cards for ROS
Replies: 2
Views: 266

Re: Intel Wireless Cards for ROS

As far as I understand, x86 is not actively developed anymore ... hence no new drivers. Hence no support for newer hardware. MT suggests to switch over to CHR ... for one thing MT down't have to develop tons of drivers, VM abstraction layer takes care of that. With ROS7 things might change - who kno...
by mkx
Fri Jul 26, 2019 1:24 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Feature requests
Replies: 1111
Views: 196048

Re: Feature requests

Need feature to detect if device have poe-out interfaces - now any poe-command (even print command) causes error in script if HW doesn't have poe-out interfaces...

I don't know how to script it, but possibility is available already: /interface print where type=pppoe-out
by mkx
Thu Jul 25, 2019 10:43 pm
Forum: General
Topic: VLAN issue
Replies: 8
Views: 631

Re: VLAN issue

My thinking: ports ether23 and ether24 are set up equally. As VLANs seemingly work as they should on ether24 (Sonicwall trunk ... when connecting to different access ports computer becomes part of correct VLAN) - you might want to verify this by connecting Sonicwall to ether23 ... it serms that CRSe...
by mkx
Thu Jul 25, 2019 10:34 pm
Forum: Beginner Basics
Topic: Significant Speed Issues with MikroTik [SOLVED]
Replies: 18
Views: 1372

Re: Significant Speed Issues with MikroTik [SOLVED]

LAN IP address is bound to ether2 which is slave device of bridge ... and that's wrong. Move it to bridge interface. Where would I change this setting? I found the WAN ethernet but according to winbox it is already linked to the bridge. Perhaps I am looking in the wrong spot? That would be in /ip a...
by mkx
Thu Jul 25, 2019 8:50 pm
Forum: Beginner Basics
Topic: Significant Speed Issues with MikroTik [SOLVED]
Replies: 18
Views: 1372

Re: Significant Speed Issues with MikroTik [SOLVED]

LAN IP address is bound to ether2 which is slave device of bridge ... and that's wrong. Move it to bridge interface. Any good reason to limit advertised speeds on ether ports only to 1000-full? Autonegotiation will select it if both link partners support it, negotiation of anything else indicates pr...
by mkx
Thu Jul 25, 2019 8:01 pm
Forum: Beginner Basics
Topic: How change to swos in fiberbox csr105
Replies: 3
Views: 335

Re: How change to swos in fiberbox csr105

Check it yourself, specs for all switches are here . I guess they call them switches even though they run ROS because their CPU is weak and unable of routing anywhere near wirespeed, but they feature decent switch chip capable of wirespeed switching. Anyway, on most dual-OS devices ROS offers same s...
by mkx
Thu Jul 25, 2019 7:54 pm
Forum: Beginner Basics
Topic: Significant Speed Issues with MikroTik [SOLVED]
Replies: 18
Views: 1372

Re: Significant Speed Issues with MikroTik [SOLVED]

First thing is to profile CPUs to get idea whether CPU is bottleneck ... and which subsystem is hit most.
by mkx
Thu Jul 25, 2019 7:29 pm
Forum: General
Topic: VLAN issue
Replies: 8
Views: 631

Re: VLAN issue

OK,I'll assume then the print-out is fine. What I just noticed: ether21 and ether22 are not set to be members of VLAN 100 (neither tagged nor untagged) on any of switches. Which explains why clients of third SSID don't get anything ... when AP is connected to any of ether21 or ether22 ports. It does...
by mkx
Thu Jul 25, 2019 4:57 pm
Forum: General
Topic: VLAN issue
Replies: 8
Views: 631

Re: VLAN issue

What you posted as output of /interface bridge vlan print doesn't correspond to how it should be configured (nor how you wanted it configured). The difference between /interface bridge vlan export and /interface bridge vlan print is that the former shows configuration directives and the later shows ...
by mkx
Thu Jul 25, 2019 4:52 pm
Forum: RouterBOARD hardware
Topic: HEX S RB760iGS → console mode...?
Replies: 4
Views: 401

Re: HEX S RB760iGS → console mode...?

You can use Woobm USB gadget to connect to router's console ... I can't vouch that it works with all RB devices but I haven't heard it doesn't either.
by mkx
Thu Jul 25, 2019 4:46 pm
Forum: Wireless Networking
Topic: Question use mikrotik equipment with unifi
Replies: 1
Views: 266

Re: Question use mikrotik equipment with unifi

For RB750Gr3 it's not so important the number of wireless clients, more important is how active those clients will be ... in particular number of open connections. If those clients will be decently non-active, they'd have a few thousand connections in total open at any given time ... which is not a ...
by mkx
Thu Jul 25, 2019 4:06 pm
Forum: General
Topic: VLAN issue
Replies: 8
Views: 631

Re: VLAN issue

One thing that strikes me odd: /interface bridge vlan add bridge=bridge tagged= " ether23-TRUNK,ether24-TRUNK,sfpplus1-TRUNK,sfpplus2-\ TRUNK,ether21-TRUNK,ether22-TRUNK " untagged= " ether1-VLAN10,ether2-VLAN10,e\ ther3-VLAN10,ether4-VLAN10,ether5-VLAN10,ether6-VLAN10,ether7-VLAN10,ether\ 8-VLAN10,...
by mkx
Thu Jul 25, 2019 4:00 pm
Forum: General
Topic: Multicast CPU Load Switch CRS328
Replies: 3
Views: 276

Re: Multicast CPU Load Switch CRS328

When I capturing with Wireshark, I see also the Multicast package on Members which are not subscriping the Multicast. So IGMP Snooping ist not working, is that right? Of course IGMP Snooping is activated. In our Cisco Enviroment its all working perfectly. IGMP snooping seems to be borken on Mikroti...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 52