Community discussions

MikroTik App

Search found 6694 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 23
by mkx
Tue Oct 26, 2021 4:49 pm
Forum: General
Topic: IGMP Snooping with VLANs
Replies: 2
Views: 114

Re: IGMP Snooping with VLANs

I'm guessing: bridge interface is used as IGMP querier. If bridge interface has PVID set (by default it's PVID=1), then IGMP queries will be sent to VLAN ID 1. If the rest of L2 configuration doesn't mention VLAN 1, then those queries will be discarded by bridge the switch-like entity due to lack of...
by mkx
Tue Oct 26, 2021 2:19 pm
Forum: General
Topic: providing NTP server by using DHCPv6?
Replies: 8
Views: 419

Re: providing NTP server by using DHCPv6?

What kind of DHCPv6 client are you running? If you have a linux machine handy, you can try running dhclient manually ... you can specify the list of options to request from DHCP server.
by mkx
Tue Oct 26, 2021 2:07 pm
Forum: General
Topic: reset configuration doesnt deploy fw rules
Replies: 6
Views: 236

Re: reset configuration doesnt deploy fw rules

hey mks dont take it personally I'm not. The thing is that I was trying to teach OP how to catch fish. But then somebody came by and dropped lots of fish. And the problem is that in a few years time somebody will stumble upon this post and take the config ... but at that time we might have a much b...
by mkx
Tue Oct 26, 2021 1:54 pm
Forum: RouterOS v7 BETA
Topic: Looking for Docker container ideas for RouterOS
Replies: 5
Views: 318

Re: Looking for Docker container ideas for RouterOS

The list of services that might be run in containers is endless. Just compile list of services that people mentioned in numerous wish-list posts. The problem is that most (if not all) RB devices are not really fit for running (full-blown) containers either due to RAM shortage or due to storage short...
by mkx
Mon Oct 25, 2021 10:51 pm
Forum: Beginner Basics
Topic: bridges and VLANs - why?
Replies: 18
Views: 797

Re: bridges and VLANs - why?

Regarding L2 (VLANs) your setup seems fine to me. And I won't bother with L3 too much as I lack knowledge about your networks (and intentions).
by mkx
Mon Oct 25, 2021 10:37 pm
Forum: Beginner Basics
Topic: bridges and VLANs - why?
Replies: 18
Views: 797

Re: bridges and VLANs - why?

Is this causing me issues because I am using the default vlan1 which is untagged versus tagged? It is indeed. frame-types=admit-only-vlan-tagged is appropriate setting for trunk (tagged-only) ports while in your case where ports are hybrid (a few tagged VLANs and untagged) you should leave setting ...
by mkx
Mon Oct 25, 2021 10:25 pm
Forum: General
Topic: reset configuration doesnt deploy fw rules
Replies: 6
Views: 236

Re: reset configuration doesnt deploy fw rules

Here you go; Do you think I couldn't post this? But that's a rotten favour to OP: defaults evolve and admin, operating "pro" router, should have a smaller "lab" unit handy ... any mikrotik costing 30 euro will do. And that's my main message to owners of "pro" line of r...
by mkx
Mon Oct 25, 2021 7:55 pm
Forum: Wireless Networking
Topic: Slave SSID/VLAN not working with CAPsMAN and local forwarding
Replies: 6
Views: 342

Re: Slave SSID/VLAN not working with CAPsMAN and local forwarding

CAP devices which are configured into CAPsMAN "slavery" by using button push are not VLAN aware. If you want to run VLANs in your network, then you have to configure wired part of CAPs manually. CAPsMAN only takes care of wireless interfaces. And, BTW, explicit use of VLAN ID 1 is generall...
by mkx
Mon Oct 25, 2021 7:40 pm
Forum: Beginner Basics
Topic: virtual wifi interface can't connect internet
Replies: 20
Views: 3846

Re: virtual wifi interface can't connect internet

Your Mikrotik currently doesn't interact with traffic on wireless, it only passes it between ether1 and wireless interfaces. If wireless user is able to connect mikrotik, then it's going via main gateway and you have to block unwanted traffic there.
by mkx
Mon Oct 25, 2021 7:21 pm
Forum: Beginner Basics
Topic: bridges and VLANs - why?
Replies: 18
Views: 797

Re: bridges and VLANs - why?

My last question is - is there a way I could make the sfp+ a trunk port without changing my current config?

Very probably ... but can't say for sure without seeing your current config (text export) ... at least everything under /interface.
by mkx
Mon Oct 25, 2021 7:06 pm
Forum: General
Topic: reset configuration doesnt deploy fw rules
Replies: 6
Views: 236

Re: reset configuration doesnt deploy fw rules

These are both devices from "pro" line and come with blank default firewall filters. It is somehow expected that these powerful units won't run simple SOHO networks and a knowledgeable admin will know better than defaults. I suggest you to get any of "toy" Mikrotiks and execute /...
by mkx
Mon Oct 25, 2021 6:57 pm
Forum: General
Topic: Multiple PTRs for same IP in ROS Static DNS
Replies: 1
Views: 101

Re: Multiple PTRs for same IP in ROS Static DNS

In my not so limited history with DNS I never saw DNS server returning more than one PTR record for single IP address. And I always worked with full-featured DNS servers. So this behaviour doesn't seem to be ROS-specific in any way. What you could do (and still wouldn't seem weird) is to create mult...
by mkx
Sun Oct 24, 2021 7:31 pm
Forum: General
Topic: Routing without bridge [SOLVED]
Replies: 12
Views: 561

Re: Routing without bridge [SOLVED]

The solution most tightly solving your original problem would be solution C described by @ConnyMercier ... If done correctly it would cause performance hit for VoIP gateway traffic (but not the rest .. not directly at least). It would also depend on VoIP gateway being connected to ether2 (but so doe...
by mkx
Sat Oct 23, 2021 9:51 pm
Forum: Wireless Networking
Topic: Slave SSID/VLAN not working with CAPsMAN and local forwarding
Replies: 6
Views: 342

Re: Slave SSID/VLAN not working with CAPsMAN and local forwarding

Your device has a messy mix of default configuration (which has ether1 as WAN interface, egress traffic is NATed, ingress traffic is firewalled) and of your attempt to make cAP a complex AP without routing and firewalling. My suggestion: reset cAP to no config (you'll have to use winbox to connect t...
by mkx
Sat Oct 23, 2021 9:35 pm
Forum: General
Topic: Route WAN network to VLAN
Replies: 3
Views: 192

Re: Route WAN network to VLAN

Ether1 should become access port of common bridge (with PVID=100 set). Port towards switch should be hybrid (untagged for LAN and tagged for VID 100). You need vlan interface with VLAN ID 100 anchored to bridge. Then you have to move WAN setup (DHCP client or static IP address or whatever) from ethe...
by mkx
Sat Oct 23, 2021 8:20 pm
Forum: Beginner Basics
Topic: How do I uninstall unneeded packages [SOLVED]
Replies: 4
Views: 278

Re: How do I uninstall unneeded packages [SOLVED]

You can't uninstall packages which were installed as a part of bundle. You can "unbundle" installation by uploading individual packages - they are available in extra package file available from download.mikrotik.com. You can't do it with same ROS version because unbundling is done as part ...
by mkx
Sat Oct 23, 2021 1:04 pm
Forum: Beginner Basics
Topic: bridges and VLANs - why?
Replies: 18
Views: 797

Re: bridges and VLANs - why?

v7 on RB5009 doesn't offer L3 HW offload yet and it's not officially on the roadmap yet. AFAIK it was mentioned tgat used switch chip does support L3 functionality so it may be possible to do it in ROS. When it does, then it'll be benefitial to convert your current setup to bridge ... and for better...
by mkx
Sat Oct 23, 2021 12:49 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 42909

Re: v7.1rc4 [development] is released!

Not true for those who have bought any of the more recent products that will only run 7.x. If one has a v7-only device, then they should stick to 7.0.5 (or whatever device came with) and wait for 7.1 stable. I've noticed only a few complaints about stability of factory-default 7.0.x, most complaint...
by mkx
Fri Oct 22, 2021 9:34 pm
Forum: Beginner Basics
Topic: bridges and VLANs - why?
Replies: 18
Views: 797

Re: bridges and VLANs - why?

You can configure any MT device (with multiple interfaces) running ROS as a hybrid switch/router (or as pure switch/bridge) and for the switch personality is realized through bridge function.

In ROAS case (or subnet per interface case) using bridge doesn't make any sense.
by mkx
Fri Oct 22, 2021 6:41 pm
Forum: Beginner Basics
Topic: virtual wifi interface can't connect internet
Replies: 20
Views: 3846

Re: virtual wifi interface can't connect internet

Since the device is not border gateway and assuming management access via untagged is trusted, you can safely disable/remove all firewall rules. Or to be on the safe side leave the rules for chain=input ... I'm wondering if this setting is needed: /ip dns set allow-remote-requests=yes servers=10.10....
by mkx
Fri Oct 22, 2021 3:04 pm
Forum: Wireless Networking
Topic: [SXT LTE6] Explain to me this PoE mystery
Replies: 6
Views: 383

Re: [SXT LTE6] Explain to me this PoE mystery

Personally I'd stop trying to power the RBSXT5nDr2 from your 802.3 af/at PoE switch because RBSXT5nDr2 is certified to work with supply voltages between 8V and 32V while 802.3 af/at specifies 48V. It can kill your SXT. That is if the link is actually about your SXT (you wrote SXT LTE6, which probabl...
by mkx
Fri Oct 22, 2021 2:57 pm
Forum: General
Topic: providing NTP server by using DHCPv6?
Replies: 8
Views: 419

Re: providing NTP server by using DHCPv6?

When doing wireshark traces, do you see DHCPv6 client requesting for those options?
by mkx
Fri Oct 22, 2021 2:51 pm
Forum: General
Topic: Possible to request LAN IP, through DHCP client ?
Replies: 4
Views: 268

Re: Possible to request LAN IP, through DHCP client ?

To clarify a bit what @holvoetn wrote: when a device gets connected to certain L2 network (ethernet or wireless) and is configured to use DHCP to get IP details (address, gateway, DNS servers, etc.), it might include preferred IP address. It will most certainly do it when re-newing DHCP lease, but m...
by mkx
Fri Oct 22, 2021 2:38 pm
Forum: Beginner Basics
Topic: virtual wifi interface can't connect internet
Replies: 20
Views: 3846

Re: virtual wifi interface can't connect internet

Post your current config just to be sure we see what device is running. Execute /export hide-sensitive file=anynameyouwish , fetch the resulting file, open it with text editor and copy-paste contents here inside [ code] [/code] environment. What you posted so far is series of commands you are suppos...
by mkx
Fri Oct 22, 2021 8:39 am
Forum: RouterBOARD hardware
Topic: CRS112-8P-4S-IN - To Buy or Not to Buy (in 2021)
Replies: 7
Views: 629

Re: CRS112-8P-4S-IN - To Buy or Not to Buy (in 2021)

Kudos to @ConnyMercier for bothering to do the measurements ... but those measurements are questionable at least. From figures I assume measurements were done on the high-voltage side of PA (hence low PF figures) which includes also low conversion efficiency of PA under low load. The measurements sh...
by mkx
Fri Oct 22, 2021 8:29 am
Forum: RouterOS v7 BETA
Topic: what's the relationship between wireguard and packet sniffer? [SOLVED]
Replies: 1
Views: 341

Re: what's the relationship between wireguard and packet sniffer? [SOLVED]

When sniffer starts, fasttrack is disabled. Which means that your fasttrack rule doesn't take into account that traffic flowing through wireguard tunnel should not be fasttracked or else it gets sent out through wrong interface (the physical WAN interface).
by mkx
Fri Oct 22, 2021 8:26 am
Forum: Beginner Basics
Topic: Configuring Subnet of WAN IPs for NAT
Replies: 4
Views: 251

Re: Configuring Subnet of WAN IPs for NAT

The first thing about using multiple IPs on single interface is answer to the question: how does link peer (i.e. ISP router) deliver packets using those IP addresses? Are they routed towards your router (i.e. your router has IP address outside of that /27 subnet and ISP router is using that address ...
by mkx
Fri Oct 22, 2021 8:20 am
Forum: Beginner Basics
Topic: Multiple ports in a VLAN
Replies: 3
Views: 259

Re: Multiple ports in a VLAN

Regarding the second failure, the terminal is informing you that you have already created an interface called "vlan40". And the reason is that VLAN port membership is configured in a very different way. I suggest you to go through this very fine tutorial , it explains how to deal with VLA...
by mkx
Thu Oct 21, 2021 7:23 pm
Forum: Beginner Basics
Topic: virtual wifi interface can't connect internet
Replies: 20
Views: 3846

Re: virtual wifi interface can't connect internet

OK, so ether1 is supposed to allow only tagged frames on ingress. Which VLAN (10 or 15) is supposed to allow management access? As it is now, RB can be accessed over ether1 using untagged access.
by mkx
Thu Oct 21, 2021 3:46 pm
Forum: General
Topic: Are the settings of the Vlan for the 1100AHx4 router correct and what are the correct settings?
Replies: 5
Views: 339

Re: Are the settings of the Vlan for the 1100AHx4 router correct and what are the correct settings?

As to the low performance: you might want to run sniffer to see if router imposes some delay. The other thing to check is actual ethernet port speed (execute /interface ethernet monitor LAN once and verify that actual rate is as expected/wanted.
by mkx
Thu Oct 21, 2021 3:42 pm
Forum: General
Topic: Are the settings of the Vlan for the 1100AHx4 router correct and what are the correct settings?
Replies: 5
Views: 339

Re: Are the settings of the Vlan for the 1100AHx4 router correct and what are the correct settings?

Switch chip features can only be used for passing traffic between ports served by same switch and within same VLAN. So if you used two trunk ports with same VLAN settings (e.g. ether3 in addition to ether2), then switch chip could move traffic between ether2 and ether3 and that traffic would not be ...
by mkx
Thu Oct 21, 2021 3:35 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 42909

Re: v7.1rc4 [development] is released!

Youtube tutorial is done by a random MT user. Answer above by @mrz is given by Mikrotik employee. So there are two questions:
  1. whom are you ging to trust on this?
  2. is Mikrotik responsible for fixing the tutorial?
by mkx
Thu Oct 21, 2021 12:05 pm
Forum: General
Topic: Is it possible to conceal MT’s MAC address?
Replies: 6
Views: 369

Re: Is it possible to conceal MT’s MAC address?

If traffic between wireless client and ISP modem is routed by MT (possibly including NAT), then ISP modem will not see wireless client's MAC address. If MT is acting as router (between ISP network and any LAN subnets), then ISP modem will only ever see router's MAC address. And that's what happens w...
by mkx
Thu Oct 21, 2021 11:50 am
Forum: General
Topic: Routing without bridge [SOLVED]
Replies: 12
Views: 561

Re: Routing without bridge [SOLVED]

You've opened a can of worms ... Devices on your "normal" 192.168.0.0/24 subnet will always try to communicate with addresses from same subnet (these include 192.168.0.10 and 192.168.0.250) directly. Since they don't get response with dst-MAC-address (because those two IP addresses are beh...
by mkx
Thu Oct 21, 2021 8:30 am
Forum: General
Topic: Are the settings of the Vlan for the 1100AHx4 router correct and what are the correct settings?
Replies: 5
Views: 339

Re: Are the settings of the Vlan for the 1100AHx4 router correct and what are the correct settings?

Which problems exactly are you facing? Without knowing them we're just shooting in the dark. One thing that doesn't seem right is MAC address assigned to bridge OUT, which is not valid localy administered MAC address . As to the rest of VLAN-specific config: since ether2 is the only port member of b...
by mkx
Wed Oct 20, 2021 8:24 am
Forum: General
Topic: Asking for VLAN setup advices
Replies: 4
Views: 296

Re: Asking for VLAN setup advices

For the network size you mentioned IMO the proper direction would be to invest into a decent router. While cAP ac is not bad at all, a more capable unit is my recommendation. RB4011 should have enough power to comfortably perform all the necessary routing. RB4011 uses RTL8367 switch chips (two of th...
by mkx
Wed Oct 20, 2021 8:15 am
Forum: Beginner Basics
Topic: use security profile on another router
Replies: 2
Views: 295

Re: use security profile on another router

You can use CAPsMAN ... it's main task (and strength) is to provision CAP's wireless interface(s) which includes security profiles and more. The only constraint is that all involved devices are ROS devices. With some minor tinkering it is possible to make CAPsMAN provision wireless on very device ru...
by mkx
Tue Oct 19, 2021 10:25 pm
Forum: Wireless Networking
Topic: hap ac3 - worse than hap lite?
Replies: 15
Views: 1375

Re: hap ac3 - worse than hap lite?

I use TPLINK eap245 and 660 for my home wifi for example.

I thought we had a deal ... you were supposed to throw your eap245 in azimuth direction of 59° real hard and I'll catch it ...
by mkx
Tue Oct 19, 2021 10:14 pm
Forum: Wireless Networking
Topic: Bridging 3 NetMetal ac²
Replies: 5
Views: 266

Re: Bridging 3 NetMetal ac²

The most important thing is to select correct wireless mode for all 3 devices. B should be set as "ap-bridge" (if it's set as "bridge", then it only accepts single client) and A and C should be set as "station-bridge" (any other station-* mode will not allow properly tr...
by mkx
Tue Oct 19, 2021 6:52 pm
Forum: Wireless Networking
Topic: Bridging 3 NetMetal ac²
Replies: 5
Views: 266

Re: Bridging 3 NetMetal ac²

B should be AP and A and C should be CPEs.

A CPE can not connect to multiple APs. Even if B was running virtual wlan interface the whole setup would not run if A and C don't use exactly the same frequency and channel layout.
by mkx
Tue Oct 19, 2021 6:37 pm
Forum: Beginner Basics
Topic: virtual wifi interface can't connect internet
Replies: 20
Views: 3846

Re: virtual wifi interface can't connect internet

Let me fix it for you:

/ip address
add 10.10.0.68/24 interface=ether1BR1

/interface list member
add interface=ether1BR1 list=BASIS

More about different bridge personalities.
by mkx
Tue Oct 19, 2021 3:55 pm
Forum: General
Topic: Allow WinBox broadcast on WAN interface
Replies: 6
Views: 306

Re: Allow WinBox broadcast on WAN interface

I guess @OP is trying to get MNDP working on WAN interface. Which is IMO very stupid idea, but @OP might have a valid reason for doing it (e.g. in block of flats, every flat has its own MT router managed by landlord via WAN interface).
by mkx
Tue Oct 19, 2021 2:33 pm
Forum: General
Topic: GRE tunnel does not receive 224.0.0.5
Replies: 3
Views: 263

Re: GRE tunnel does not receive 224.0.0.5

I guess you need to configure multicast routing on both ends to have multicasts pass the GRE tunnel.
by mkx
Tue Oct 19, 2021 8:21 am
Forum: General
Topic: GRE tunnel does not receive 224.0.0.5
Replies: 3
Views: 263

Re: GRE tunnel does not receive 224.0.0.5

Shooting in the dark: check MTU settings of all involved interfaces (the LAN interfaces, bridge and GRE tunnel interface) as well as multicast packet sizes. I'm not sure if ROS fragments multicast packets (I'm guessing it's not).
by mkx
Tue Oct 19, 2021 8:11 am
Forum: RouterOS v7 BETA
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 42909

Re: v7.1rc4 [development] is released!

unrelated: I predict for the next release we have v7.2RC1 or v7.2beta1 (testing) with move up to 5.10.x LTS kernel Why do you think MT will jump from 7.1rc4 to 7.2beta1? The usual version path is beta -> rc -> release and I don't see any reason to skip release version with 7.1 series. And I don't t...
by mkx
Mon Oct 18, 2021 6:55 pm
Forum: RouterBOARD hardware
Topic: mAP2n only one wireless chain [SOLVED]
Replies: 6
Views: 628

Re: mAP2n only one wireless chain [SOLVED]

As @hectae explained: mAP2n has single wireless chain. The "2n" part of the device name refers to wireless capabilities and it translates to "2.4GHz radio supporting 802.11n, single chain".
by mkx
Sun Oct 17, 2021 10:36 pm
Forum: General
Topic: VLAN correct config
Replies: 5
Views: 375

Re: VLAN correct config

You should read this article to better understand different bridge personalities.
by mkx
Sun Oct 17, 2021 8:00 pm
Forum: RouterBOARD hardware
Topic: RB2011UiAS-2HnD-IN and SPF modules unrecognizable
Replies: 3
Views: 1359

Re: RB2011UiAS-2HnD-IN and SPF modules unrecognizable

First of all, upgrade RB2011 at least to latest long-term ROS version (at this time 6.48.5, but beware of some issues reported by some users so you may want to go for 6.47.10). Then get SFP modules know to be compatible with your device. Mikrotik has SFP compatibility list (which includes only MT's ...
by mkx
Sun Oct 17, 2021 7:44 pm
Forum: General
Topic: Eth1 as WAN port with DHCP regardless IP
Replies: 3
Views: 343

Re: Eth1 as WAN port with DHCP regardless IP

If I paraphrase what @anav wrote: router can not have two interfaces (between which it sould route traffic) with same network address.

Usually one doesn't have much influence on what IP address comes on WAN side of SOHO router, hence one has to adjust LAN side in case of conflicts.
by mkx
Sun Oct 17, 2021 7:31 pm
Forum: Beginner Basics
Topic: Where in firewall rules the Fasttrack should be [SOLVED]
Replies: 5
Views: 527

Re: Where in firewall rules the Fasttrack should be [SOLVED]

Rules #1-#5 are chain=input and fast track doesn't apply. Then there is traffic which should not be fast tracked as it absolutely has to be processed before being router further, such as IPsec traffic. So your fattrack rule, being third in chain=forward, seems to be in the right spot.
by mkx
Fri Oct 15, 2021 2:33 pm
Forum: RouterBOARD hardware
Topic: Connecting FSP 150-GE102Pro to RouterBoard 4011iGS
Replies: 8
Views: 763

Re: Connecting FSP 150-GE102Pro to RouterBoard 4011iGS

What you see in port #3 of ADVA is a SFP module. What kind of optical patch cable you need and what kind of SFP module for RB4011 depends on what kind of SFP is in ADVA right now. Pull it out and read the label (post the picture of it if you can't make the meaning yourself). Yes, you should get a SF...
by mkx
Thu Oct 14, 2021 4:13 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS+ and Port 1 issue
Replies: 2
Views: 438

Re: RB4011iGS+ and Port 1 issue

Also run
/interface ethernet monitor ether1 once
and post result.
by mkx
Thu Oct 14, 2021 3:52 pm
Forum: Beginner Basics
Topic: Voice VLAN / DHCP issues
Replies: 8
Views: 656

Re: Voice VLAN / DHCP issues

Also, I assumed that since the Voice VLAN was a sub interface of the bridge, and the bridge is the LAN No, firewall interface lists are about interfaces which bear IP setup (i.e. IP address). Doesn't care about physical layout, it's pure about "logical" interface. And in your case it's Vo...
by mkx
Thu Oct 14, 2021 8:29 am
Forum: Beginner Basics
Topic: Voice VLAN / DHCP issues
Replies: 8
Views: 656

Re: Voice VLAN / DHCP issues

As far as reviewing that firewall rule; that is what we want isn't it? We don't want people being able to access the router from the WAN interface ... WAN interface and !LAN interface is not the same in your case ... you've got interface Voice which is neither WAN nor LAN. And DHCP server for voice...
by mkx
Wed Oct 13, 2021 10:56 pm
Forum: General
Topic: VLAN on CCR2004-16G-2S+
Replies: 1
Views: 299

Re: VLAN on CCR2004-16G-2S+

Should i create a bridge with all ports except the WAN port Yes. What I care most about is throughput between the sfp+ ports. Should I just skip using the ethernet ports? Official test results indicate that the device is capable of bridging at around 20Gbps (give or take, depending on exact traffic...
by mkx
Wed Oct 13, 2021 10:40 pm
Forum: Beginner Basics
Topic: RSTP or HW offload on a RB4011iGS+
Replies: 5
Views: 517

Re: RSTP or HW offload on a RB4011iGS+

The problem with MT documentation is that it mostly documents state of art according to most recent ROS version at the moment of writing/updating (and documentation is not necessarily always up-to-date) and often doesn't mention version when certain feature got implemented. In particular: RT switch ...
by mkx
Wed Oct 13, 2021 6:59 pm
Forum: General
Topic: How to create IPv6 subnet with prefix delegation
Replies: 2
Views: 352

Re: How to create IPv6 subnet with prefix delegation

In addition to what @biomesh wrote ... there's a gotcha when dealing with IPv6 prefixes: many devices (Mikrotiks included) can only work with /64 prefixes on interfaces. If ISP gives out smaller prefixes (e.g. /60 or /56), then everything is fine and dandy. However, some ISPs only give out /64 prefi...
by mkx
Mon Oct 11, 2021 8:44 pm
Forum: Wireless Networking
Topic: hap ac3 - worse than hap lite?
Replies: 15
Views: 1375

Re: hap ac3 - worse than hap lite?

...but try and explain to user that "more bars doesn't have anything to do with wifi quality".... It's like listening to the music sitting close to big speakers. You do not hear better ... It's only louder ... that is why it has no sense to be close to the speakers during concerts :) Agre...
by mkx
Sat Oct 09, 2021 8:48 pm
Forum: General
Topic: 3rd party plugins
Replies: 3
Views: 434

Re: 3rd party plugins

No, ROS doesn't support 3rd party plugins.

ROSv7 will support running containers, but that might not help solving your problem.
by mkx
Fri Oct 08, 2021 10:23 pm
Forum: General
Topic: Firewall Drop Invalid
Replies: 4
Views: 452

Re: Firewall Drop Invalid

From performance point of view one should place rules matching most packets higher. Normally "established,related" rule would match vast majority of packets. For sure one has to observe rule order when different rules might match same packet and the rule which is supposed to be executed mu...
by mkx
Fri Oct 08, 2021 9:00 am
Forum: Wireless Networking
Topic: WIFI bridge & vlan
Replies: 2
Views: 544

Re: WIFI bridge & vlan

It's quite likely you won't be able to make it using AP and client form different vendor as bridging is not standard 802.11 feature. You can read more about it in this article. Using different SSIDs for different VLANs doesn't change things much.
by mkx
Fri Oct 08, 2021 8:42 am
Forum: Beginner Basics
Topic: Can restore a RB951G from a RB951 backup?
Replies: 1
Views: 403

Re: Can restore a RB951G from a RB951 backup?

Generally binary backups should only be restored on very same unit that produced backups. The reason is that binary backup contains also MAC addresses and running two units with same MAC addresses in same network will cause trouble even if those devices are of exactly the same hardware model. The pr...
by mkx
Fri Oct 01, 2021 1:01 pm
Forum: Beginner Basics
Topic: NAT rule, parameter: "to-address" in Winbox ... where ?
Replies: 26
Views: 1366

Re: NAT rule, parameter: "to-address" in Winbox ... where ?

action=redirect is a special case of DST NAT : redirect - replaces destination port of an IP packet to one specified by to-ports parameter and destination address to one of the router's local addresses As with all other magical actions (e.g. masquerade) one doesn't have much control over what exactl...
by mkx
Fri Oct 01, 2021 12:26 am
Forum: RouterBOARD hardware
Topic: hex S poe-out issue
Replies: 2
Views: 824

Re: hex S poe-out issue

Are you running latest long-term or stable ROS version? Could be there's some bug-fix or improvement regarding PoE out ...
by mkx
Fri Oct 01, 2021 12:20 am
Forum: Wireless Networking
Topic: 12 volt to power hap ac3
Replies: 4
Views: 662

Re: 12 volt to power hap ac3

@Hominidae had power wire resistance in mind ... the higher the current, the higher loss (and voltage drop). Which is a thing well worth considering when powering device over ethernet wires (due to their high resistance due to low cross-section and length) but not so much when using normal power ada...
by mkx
Fri Oct 01, 2021 12:14 am
Forum: General
Topic: Guest network as VLAN tagged for one port
Replies: 9
Views: 1767

Re: Guest network as VLAN tagged for one port

As soon as you configure the "preferred way" that will disappear and everything will be software switched... ROS v7 brings HW accelerated VLAN bridge operations to RB4011 ... just wanted to mention it :wink: I'm a bit confused by /interface bridge vlan section ... Did you have a chance to...
by mkx
Fri Oct 01, 2021 12:02 am
Forum: Beginner Basics
Topic: url filtering on ssl traffic through Web Proxy Configuration
Replies: 15
Views: 1514

Re: url filtering on ssl traffic through Web Proxy Configuration

In case, you did it already using squid... If you configure client's browsers to explicitly use proxy servers (such as squid), then browser explicitly contacts proxy and fully expects proxy to handle connections towards content servers. So in this case browsers don't expect to handshake with e.g. w...
by mkx
Thu Sep 30, 2021 11:50 pm
Forum: Beginner Basics
Topic: physical DMZ in routing mode [SOLVED]
Replies: 7
Views: 879

Re: physical DMZ in routing mode [SOLVED]

All firewall rules in ROS can be as selective as you wish (almost). E.g. if you have a look at NAT properties , most of properties are "selectors" meaning they are used to select packets on which the rule to act. Only a few are "actions" meaning they define what NAT rule will act...
by mkx
Thu Sep 30, 2021 11:37 pm
Forum: Announcements
Topic: Newsletter 102
Replies: 30
Views: 15951

Re: Newsletter 102

Three steps: create textual export of current configuration. Execute command /export file=myexport and fetch file off device. Note that this is not backup , which creates binary (and encrypted) file of which contents can not be easily examined. Make a note about users and their passwords, export doe...
by mkx
Thu Sep 30, 2021 2:36 pm
Forum: Beginner Basics
Topic: physical DMZ in routing mode [SOLVED]
Replies: 7
Views: 879

Re: physical DMZ in routing mode [SOLVED]

The scenario can be done in the way similar to the following: create a new bridge (e.g. named WAN-bridge), add physical ports used for both ISP connection and DMZ configure router's WAN IP settings (address, gateway) on WAN-bridge interface manually disable HW offload on ports of this bridge: /inter...
by mkx
Thu Sep 30, 2021 12:45 pm
Forum: Beginner Basics
Topic: 1:1 NAT working as espected only when torch is enabled
Replies: 7
Views: 773

Re: 1:1 NAT working as espected only when torch is enabled

A 100/100Mbps connection ona a RB4011iGS+ with an IPSEC VPN onboard will be bottlenecked without fasttrack or could I leave it disabled? IPsec itself puts a lot of burden on router (OK, some ciphers can be offloaded to hardware). And make sure traffic which is supposed to get into IPsec tunnel does...
by mkx
Wed Sep 29, 2021 5:15 pm
Forum: Beginner Basics
Topic: Block local IP's fails [SOLVED]
Replies: 11
Views: 1108

Re: Block local IP's fails [SOLVED]

Both IPs are in same IP subnet, so basically they'll try to talk to each other directly, without involving their gateway. If traffic between the two devices is forced to pass router (i.e. they are connected to different ports of your mikrotik), then you can do something by using bridge filters ... a...
by mkx
Wed Sep 29, 2021 5:04 pm
Forum: General
Topic: Configuring IPv6 in IPv4 network
Replies: 4
Views: 461

Re: Configuring IPv6 in IPv4 network

In theory you should be able to get it done by following this manual: https://wiki.mikrotik.com/wiki/Manual:I ... 29_tunnels

I can't say whether it really works as my ISP offers both IPv4 and IPv6 ...
by mkx
Wed Sep 29, 2021 1:35 pm
Forum: General
Topic: Bridging VLANs only (and not untagged traffic)
Replies: 3
Views: 459

Re: Bridging VLANs only (and not untagged traffic)

When adding a port to vlan-enabled bridge, you can always set what types of frames are admitted. E.g. frame-types=admit-only-vlan-tagged ingress-filtering=yes will only admit tagged frames on ingress.
by mkx
Wed Sep 29, 2021 8:10 am
Forum: Beginner Basics
Topic: 1:1 NAT working as espected only when torch is enabled
Replies: 7
Views: 773

Re: 1:1 NAT working as espected only when torch is enabled

Depending on how exactly your firewall filter rules look like (the config snippet you posted doesn't seem to be complete) you might be able to fasttrack some traffic. But beware that fasttracked traffic doesn't get mangled.
by mkx
Tue Sep 28, 2021 11:50 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS+RM with SFP to RJ45 Copper Transceiver Module
Replies: 8
Views: 1425

Re: RB4011iGS+RM with SFP to RJ45 Copper Transceiver Module

The difference is you can get the 0.5m fs.com DAC for 10€ while 2x SFP+ LC module and a fibre to connect them will be 60-100€. A pair of optical transcievers indeed cost more than 10€, but they are less than 60-100€ (FS lists 850nm SFP+ modules for less than 20€ a piece, 2m patch cord is less than ...
by mkx
Tue Sep 28, 2021 11:39 pm
Forum: Wireless Networking
Topic: capsman local forwarding clarification
Replies: 7
Views: 1038

Re: capsman local forwarding clarification

If you ask me that is a bug in ROS because the bridge must not keep the MAC address if it was taken from a now inactive interface but should choose another one from the active interface list? Indeed bridge should be selecting another MAC if "donor" interface is removed from bridge. Unless...
by mkx
Tue Sep 28, 2021 10:11 am
Forum: RouterBOARD hardware
Topic: Outdoor RouterBoard
Replies: 4
Views: 1425

Re: Outdoor RouterBoard

IMO it would be very useful if somebody (hint: MT staff) posted temperature specifications for SoC in use (Marvel Prestera DX226S) ... the "tested environment temperature" information (I guess that brochure item "Operating temperature" is about this) is great, but there are alway...
by mkx
Mon Sep 27, 2021 6:43 pm
Forum: Beginner Basics
Topic: Hex s redirect traffic or port forwarding
Replies: 23
Views: 1334

Re: Hex s redirect traffic or port forwarding

In terms of order, does the DST NAT rule have to be located before the new srcnat rule. Rule ordering (top to bottom) applies here as well. If both srcnat rules are orthogonal, then rule order doesn't affect the result (but it might slightly affect performance). In particular case of OP srcnat rule...
by mkx
Mon Sep 27, 2021 6:35 pm
Forum: General
Topic: MikroTIK on Raspberry PI 4 B
Replies: 3
Views: 477

Re: MikroTIK on Raspberry PI 4 B

The only "generic" hardware platform, supported by RouterOS, is x86 ... either CHR or "bare metal" (the later being quite severely limited by the lack of drivers for modern peripherials).
by mkx
Mon Sep 27, 2021 6:22 pm
Forum: Beginner Basics
Topic: Hex s redirect traffic or port forwarding
Replies: 23
Views: 1334

Re: Hex s redirect traffic or port forwarding

Okay, can I ask you when the stock market will crash

Whenever you'll have most of your money invested ...
by mkx
Mon Sep 27, 2021 6:07 pm
Forum: Beginner Basics
Topic: Hex s redirect traffic or port forwarding
Replies: 23
Views: 1334

Re: Hex s redirect traffic or port forwarding

If CNC gadget doesn't use a router as gateway, then it can't send replies back to outer network. Which means our beloved router has to fake return address so that CNC gadget thinks it's talking to router when it's not. Perhaps CNC gadget even does talk to gateway, but mikrotik doesn't gave the right...
by mkx
Mon Sep 27, 2021 3:55 pm
Forum: General
Topic: HW offload bridging
Replies: 24
Views: 1542

Re: HW offload bridging

I can only find basic VLAN setups in that link. I am trying to bridge multiple interfaces together. Have you seen my other post?

Have a look at this document. Might hint you in the right direction.
by mkx
Mon Sep 27, 2021 3:38 pm
Forum: General
Topic: IPIP / DDNS / IPSEC / Routing
Replies: 2
Views: 375

Re: IPIP / DDNS / IPSEC / Routing

SO i wanted to implemant IPIP Tunnel so i can Route into thes Interfaces. I got the fact that IPIP can create his own IPSEC Tunnel but not with DDNS, so i decided to use my own IPSEC connections. What exactly do you mean by "IPIP can create own IPSEC Tunnel but not with DDNS"? I'm running...
by mkx
Mon Sep 27, 2021 3:19 pm
Forum: Beginner Basics
Topic: Hex s redirect traffic or port forwarding
Replies: 23
Views: 1334

Re: Hex s redirect traffic or port forwarding

So the relevant stuff about NAT is currently this: /ip firewall nat add action=src-nat chain=srcnat out-interface=ether1 to-addresses=192.168.51.138 add action=dst-nat chain=dstnat dst-address=192.168.51.138 dst-port=102 protocol=tcp to-addresses=192.168.0.102 It is very likely that CNC gadget doesn...
by mkx
Sun Sep 26, 2021 2:52 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 42909

Re: v7.1rc4 [development] is released!

Supported v7.1rc4 Wave2 for MIPSBE?
How many mipsbe devices come with mentioned wireless chip and 256MB RAM? Not to mention that mipsbe CPUs are mostly too weak even to maintain full-speed ac wireless.
by mkx
Sat Sep 25, 2021 12:13 am
Forum: Wireless Networking
Topic: wifi devices hop between access points
Replies: 6
Views: 741

Re: wifi devices hop between access points

This log, IMO, indicates that wireless client is misbehaving. It's disconnecting from perfect cell (signal strength of -57 dBm is nothing to frown at) in less than a second to connect to a 18 dB weaker cell?

I don't know if you can do something about it though.
by mkx
Fri Sep 24, 2021 7:46 pm
Forum: Wireless Networking
Topic: wifi devices hop between access points
Replies: 6
Views: 741

Re: wifi devices hop between access points

I'm wondering if the "Access List" feature could help so I can allow a client only to connect to the closest AP. I think that would be possible but what would likely happen in reality? The client would see the other wifi and would try to switch but then is not accepted. I assume it would ...
by mkx
Fri Sep 24, 2021 7:35 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 42909

Re: v7.1rc4 [development] is released!

Font, displaying instructions, should be friendlier...
by mkx
Fri Sep 24, 2021 3:21 pm
Forum: Wireless Networking
Topic: wifi devices hop between access points
Replies: 6
Views: 741

Re: wifi devices hop between access points

Roaming between APs is completely up to wireless client. Usually they roam from one AP to another when other AP's signal gets better than signal of current AP. Seems like some don't apply no hysteresis (meaning: new AP should be at least a few dB better than current) which makes roaming a bit less &...
by mkx
Fri Sep 24, 2021 2:52 pm
Forum: General
Topic: CRS and wire-speed?
Replies: 2
Views: 446

Re: CRS and wire-speed?

Yes. Unless something is configured incorrectly.
by mkx
Fri Sep 24, 2021 2:50 pm
Forum: General
Topic: dst-nat and src-nat on same connection
Replies: 9
Views: 700

Re: dst-nat and src-nat on same connection

I don't think I can help you any more without seeing complete configuration of "mikrotik second" ... I don't have clear picture of what's configured and I can't imagine how 192.168.1.2 ended up in DST-NAT output you showed in one of previous posts. Unless that was from "mikrotik maste...
by mkx
Fri Sep 24, 2021 2:34 pm
Forum: Beginner Basics
Topic: Hex s redirect traffic or port forwarding
Replies: 23
Views: 1334

Re: Hex s redirect traffic or port forwarding

The information missing from your post is: does router know it's supposed to handle packets targeting 192.168.51.150? What is router's own address in that particular subnet? Generally adding DST-NAT rule doesn't make router handle additional addresses. To spare us from guessing, post full text confi...
by mkx
Thu Sep 23, 2021 9:47 pm
Forum: General
Topic: Hardware for 10Gbps bandwidth test
Replies: 5
Views: 630

Re: Hardware for 10Gbps bandwidth test

For connecting fibres and SFPs use a small 10Gbps switch, e.g. a CRS305 (one RJ45 SFP+ module to connect laptop and optical SFP+ module appropriate for fibre connections). Most modern switches support wire-speed switching so switch should not be bottleneck in this test setup.
by mkx
Thu Sep 23, 2021 9:34 pm
Forum: General
Topic: dst-nat and src-nat on same connection
Replies: 9
Views: 700

Re: dst-nat and src-nat on same connection

You should trace (use sniffer tool) packets to see what happens with them on "mikrotik second" ... the info seems to indicate that packets do arrive at "mikrotik second" ... but what does hapen to them? Do you have other NAT rules active? Rules get matched from top to bottom, in ...
by mkx
Thu Sep 23, 2021 9:24 pm
Forum: General
Topic: Change macaddress to lte interface.
Replies: 19
Views: 1076

Re: Change macaddress to lte interface.

But when I dig in topic then I found a https://www.etsi.org/deliver/etsi_ts/124300_124399/124322/13.00.00_60/ts_124322v130000p.pdf 6.3.2 EFTF procedures EFTF procedures are only used in conjunction with IMS . Most oftenly used service of IMS is VoLTE - VoIP implementation which is native voice serv...
by mkx
Thu Sep 23, 2021 2:55 pm
Forum: General
Topic: dst-nat and src-nat on same connection
Replies: 9
Views: 700

Re: dst-nat and src-nat on same connection

To better understand what @tdw wrote, have a look at packet flow description . And: all properties of SRC-NAT and DST-NAT conmmands, except to-addresses and to-ports, are "matching" properties. Which means that they are used to selectively pick packets which will get changed. The two menti...
by mkx
Thu Sep 23, 2021 8:45 am
Forum: RouterBOARD hardware
Topic: LtAP WLAN1 MMCX PCB socket Antenna selection
Replies: 5
Views: 1751

Re: LtAP WLAN1 MMCX PCB socket Antenna selection

AFAIK antenna connectors are connected in parallel to internal wifi antennae. And it's been mentioned multiple times by MT staff that on most device models these antennae connectors are not actually meant to connect external antennae, they are rather test points used in production process. Seems LtA...
by mkx
Thu Sep 23, 2021 8:25 am
Forum: Wireless Networking
Topic: CAPsMAN: manual channel selection and DFS
Replies: 3
Views: 675

Re: CAPsMAN: manual channel selection and DFS

I'm only guessing here ... However, if I select both DFS and non-DFS channels (e.g: "5500,5660,5180"), both APs will immediately pick the non-DFS channel even if it's already crowded by other APs. Vast majority of users are unaware of DFS woes and freak out when they start APs and they don...
by mkx
Thu Sep 23, 2021 8:12 am
Forum: Beginner Basics
Topic: Im new with Mikrotik and i want to configure css326-24g-2s+rm for wan connection
Replies: 2
Views: 438

Re: Im new with Mikrotik and i want to configure css326-24g-2s+rm for wan connection

To put information by @ConnyMercier in another words: CSS326 is a decent managed switch, but can not perform any of router's tasks ... so it can't run DHCP server, it can't route, it can't be firewall, it can't perform NAT ... nothing.
by mkx
Thu Sep 23, 2021 8:09 am
Forum: General
Topic: Hardware for 10Gbps bandwidth test
Replies: 5
Views: 630

Re: Hardware for 10Gbps bandwidth test

None of mikrotik hardware is capable of neither generating nor ingesting 10Gbps speed test data. This holds true even for CHR/x86 running on powerful hardware. One of problems with btest is that it uses single core and iperf (de-facto standard for high-speed testing) needs to run multiple concurrent...
by mkx
Wed Sep 22, 2021 8:47 pm
Forum: General
Topic: Virtual-ethernet on Mikrotik Chr
Replies: 3
Views: 403

Re: Virtual-ethernet on Mikrotik Chr

You may want to start by reading CHR manual which covers also installation.
by mkx
Wed Sep 22, 2021 3:58 pm
Forum: General
Topic: Virtual-ethernet on Mikrotik Chr
Replies: 3
Views: 403

Re: Virtual-ethernet on Mikrotik Chr

"on x86 architecture you have to have kvm package installed" On download page under RouterOS - x86, locate "Extra packages" (the top one, there are currently listed two rows with the same description) for your exact ROS version. Inside there's "kvm-<version>.npk", inst...
by mkx
Wed Sep 22, 2021 12:19 pm
Forum: Wireless Networking
Topic: Client can connect to 5GHz only after disabling 802.11ac
Replies: 8
Views: 958

Re: Client can connect to 5GHz only after disabling 802.11ac

While you're preparing configuration export as per instructions by @rextended, you might want to check how is property band of wireless interface set ... for maximum compatibility and flexibility it should be set to 5ghz-a/n/ac ... or if you don't have legacy 5GHz wireless clients, it can be set to ...
by mkx
Wed Sep 22, 2021 12:08 pm
Forum: General
Topic: Nat of indirectly connected network
Replies: 5
Views: 712

Re: Nat of indirectly connected network

Default SRC-NAT rule /ip firewall nat add action=masquerade chain=srcnat comment="defconf: masquerade" \ ipsec-policy=out,none out-interface-list=WAN should be able to properly NAT anything going out via WAN interface regardless the src-address. If you want to get some concrete advice, pos...
by mkx
Wed Sep 22, 2021 11:59 am
Forum: RouterOS v7 BETA
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 42909

Re: v7.1rc4 [development] is released!

Strange story, but I found that now default antenna gain is 2db but previously was 0 db and now there is no option on WInbox to change antenna gain. hap ac lite. Check please is it only for me? This is an old story, didn't start with v7. Antenna gain information is used in calculations about maximu...
by mkx
Wed Sep 22, 2021 8:22 am
Forum: RouterOS v7 BETA
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 42909

Re: v7.1rc4 [development] is released!

I would suggest opening a GitHub project (or similar) to manage issues and milestones. This would make things easier once it is up and running Being a positive person I'm pretty sure MT is using some sort of change tracking in ROS (e.g. GitHub), but their business decision is to keep pretty silent ...
by mkx
Tue Sep 21, 2021 7:19 pm
Forum: General
Topic: VLAN Help on a CRS326 Switch [SOLVED]
Replies: 3
Views: 401

Re: VLAN Help on a CRS326 Switch [SOLVED]

/interface bridge port add bridge=bri1 frame-types=admit-only-untagged-and-priority-tagged \ interface=Uplink /interface bridge vlan add bridge=bri1 untagged=Uplink,bri1 vlan-ids=1 add bridge=bri1 tagged=Uplink,ether1 vlan-ids=10 add bridge=bri1 tagged=Uplink untagged=ether2 vlan-ids=30 add bridge=...
by mkx
Tue Sep 21, 2021 5:06 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS+RM with SFP to RJ45 Copper Transceiver Module
Replies: 8
Views: 1425

Re: RB4011iGS+RM with SFP to RJ45 Copper Transceiver Module

Instead of short DAC cable one can use optical connection as well. Use supported SFP+ module on each side (can be different make as well), they only have to match on optical side (i.e. multi-mode 850nm). And use optical patch cord with appropriate length. Optical SFP+ modules also consume quite low ...
by mkx
Tue Sep 21, 2021 4:57 pm
Forum: General
Topic: Need help on rb750gr3 about maximum lan connection
Replies: 40
Views: 1884

Re: Need help on rb750gr3 about maximum lan connection

What Wireless Routers are you using as (im assuming are acting as Access Point / switches and not routers ) OP provided network schema in post #13 above ... a comment there indicates wireless gadgets are used in router mode. Their WAN sides are all in same network, knit together using dumb switches.
by mkx
Tue Sep 21, 2021 11:02 am
Forum: Wireless Networking
Topic: Devices cannot connect to both APs
Replies: 10
Views: 1070

Re: Devices cannot connect to both APs

/interface bridge vlan add bridge=bridge1 tagged=ether1,bridge1 untagged=ether2,ether3,ether4,ether5 \ vlan-ids=100 add bridge=bridge1 tagged=ether1, wlan3 wlan1,wlan2 vlan-ids=101 add bridge=bridge1 tagged=ether1 untagged=wlan4 vlan-ids=102 add bridge=bridge1 tagged=ether1 untagged=wlan3 vlan-ids=...
by mkx
Tue Sep 21, 2021 10:36 am
Forum: General
Topic: Need help on rb750gr3 about maximum lan connection
Replies: 40
Views: 1884

Re: Need help on rb750gr3 about maximum lan connection

But as said, the "congestion" may be a consequence of intentional shaping ... Either that or the modem (being residential type) might have problems with NATing large number of concurrent connections (ROS limits depend on device's RAM size). You could rule this out if you could (temporaril...
by mkx
Mon Sep 20, 2021 6:24 pm
Forum: General
Topic: Only 100Mbps full-duplex speed on 1Gbps port
Replies: 5
Views: 439

Re: Only 100Mbps full-duplex speed on 1Gbps port

Also 100Mbps full duplex works without any problem (which also requires the 4 pairs right?)

Nope, 100BaseTx (including full-duplex) uses only 2 pairs.
by mkx
Mon Sep 20, 2021 6:13 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 42909

Re: v7.1rc4 [development] is released!

Still slow paste of code.

Emulation of tty at 2400 baud?
by mkx
Mon Sep 20, 2021 12:59 pm
Forum: Wireless Networking
Topic: CAps configuration
Replies: 6
Views: 745

Re: CAps configuration

Maybe i will try a single pool, but that could mess with my IoTs.... What people mostly do is to have multiple wireless networks with different SSIDs and using different VLANs on wired backbone. Then each of networks has it's own IP subnet. Those wireless networks actually share same wireless infra...
by mkx
Mon Sep 20, 2021 12:54 pm
Forum: Beginner Basics
Topic: Remove port 5 from the bridge
Replies: 9
Views: 823

Re: Remove port 5 from the bridge

You can remove it. In CLI run the following command: /interface bridge port remove [ find interface=ether5 ] Then proceed by configuring IP settings on ether5. In case if you want to control/limit connectivity between your current LAN and the new one you'll have to add some firewall filter rules, yo...
by mkx
Mon Sep 20, 2021 12:38 pm
Forum: RouterOS v7 BETA
Topic: IPv6 response connection state new,invalid
Replies: 7
Views: 786

Re: IPv6 response connection state new,invalid

I've no idea about queues, so perhaps somebody else will chime in.
by mkx
Mon Sep 20, 2021 12:09 pm
Forum: RouterOS v7 BETA
Topic: IPv6 response connection state new,invalid
Replies: 7
Views: 786

Re: IPv6 response connection state new,invalid

Your IPv6 firewall config is IMO a mess. Not sure what you want to do with all of those mangle rules. But they might interfere with connection tracking machinery state ... if you can, disable all of them to check if your (simplified) setup still doesn't work right. BTW, does your ISP require your WA...
by mkx
Mon Sep 20, 2021 11:52 am
Forum: RouterBOARD hardware
Topic: can CCR2004-16G-2S+ downgrade to v6 ?
Replies: 10
Views: 1785

Re: can CCR2004-16G-2S+ downgrade to v6 ?

Maybe so, but it "DOESN't" say that on the downloads page !! Overly cryptic !! The fact is that it is not possible to downgrade ROS version below the factory installed. On any ROS device. It is true that this fact is not printed in large friendly letters on every device box, but this fact...
by mkx
Mon Sep 20, 2021 11:38 am
Forum: RouterBOARD hardware
Topic: save Logs to WD NAS SERVER
Replies: 1
Views: 789

Re: save Logs to WD NAS SERVER

It doesn't seem you could. RouterOS supports a few different actions for logs, the interesting ones in your case are disk and remote . The disk action needs disk mapped in RouterOS and that's generally only possible for local disks, e.g. if disk is USB. Not an option in your case as RB4011 doesn't h...
by mkx
Mon Sep 20, 2021 11:16 am
Forum: RouterOS v7 BETA
Topic: IPv6 response connection state new,invalid
Replies: 7
Views: 786

Re: IPv6 response connection state new,invalid

It's hard to understand what's going on without you providing some more detailed information, such as relevant pieces of configuration (/interface - both configuration and running values - and /ipv6 subtrees) and contents of log (to see what exactly is logged).
by mkx
Mon Sep 20, 2021 11:13 am
Forum: General
Topic: CCR1016-12G Network issues
Replies: 3
Views: 624

Re: CCR1016-12G Network issues

- some machines cannot go out to the internet without having the public IP installed on the machine (configuring the public IP in the network settings), this completely bypasses Mikrotik firewall, no logs for the NAT rule (which is correctly setup) Ports ether1, 3, 4, 5, 6, 7, 8, 9, 10, 11 and 12 a...
by mkx
Mon Sep 20, 2021 9:10 am
Forum: General
Topic: Bind Webfig and ssh to a vlan
Replies: 11
Views: 710

Re: Bind Webfig and ssh to a vlan

As mentioned in your other thread, your L2 (bridge and VLAN) setup is wrong. While it might work for you, it's bound to create problems sooner or later. So it's up to you to either invest some time to study ROS (yes, learning curve is very steep from beginning) and do it right (we'll help you learni...
by mkx
Mon Sep 20, 2021 9:07 am
Forum: Wireless Networking
Topic: Low WiFi speeds on hAP ac²
Replies: 17
Views: 1549

Re: Low WiFi speeds on hAP ac²

I have an Audience running that wifi driver. I know that currently ROS v7 is RC (with quality somewhere in between alpha and beta) and wifiwave2 driver quality is on the same level. But I wrote: People who did test the upcoming wifiwave2 driver, confirmed that it both increases obtainable throughpu...
by mkx
Sun Sep 19, 2021 9:01 pm
Forum: General
Topic: Inter VLAN filtering fom VLAN A to VLAN B
Replies: 23
Views: 1172

Re: Inter VLAN filtering fom VLAN A to VLAN B

Can we rewind a bit? OP asked teo very well articulated questions: How do I achieve inter VLAN filtering with a Mikrotik router? Can it be done at wire speed? Answer to first question: using IP firewall. Router needs to have connectivity to all VLANs, then it will use "usual" IP firewall t...
by mkx
Sun Sep 19, 2021 8:56 pm
Forum: General
Topic: Inter VLAN filtering fom VLAN A to VLAN B
Replies: 23
Views: 1172

Re: Inter VLAN filtering fom VLAN A to VLAN B

I think you're kicking in wrong direction here. CCR can't offload anything because it doesn't have needed and supported hardware. CRS might offliad something if it was used as L3 switch/router.
by mkx
Sun Sep 19, 2021 7:50 pm
Forum: Wireless Networking
Topic: CAps configuration
Replies: 6
Views: 745

Re: CAps configuration

Curious how do you say multiple networks don't roam nicely? When client decides that current BSSID (AP running certain SSID) signal is not good enough, it looks around for another feasible AP. If it finds another AP running same SSID, it will roam which means it'll expect all the IP settings to rem...
by mkx
Sun Sep 19, 2021 7:32 pm
Forum: Wireless Networking
Topic: Accesspoint only with VLANs
Replies: 17
Views: 1244

Re: Accesspoint only with VLANs

What would you like to achieve? learn how to do it properly even if it takes a while get somebody write a few lines of config so you can copy-paste them and be done If it's a), then read the tutorial I linked and try to really understand. Play a bit until you understand it, without trying (for now) ...
by mkx
Sun Sep 19, 2021 7:23 pm
Forum: General
Topic: Inter VLAN filtering fom VLAN A to VLAN B
Replies: 23
Views: 1172

Re: Inter VLAN filtering fom VLAN A to VLAN B

Do pray tell which L3 limited features could the Switch do with RoS7, that would offload the router..........

Here is some food for your twisted mind.
by mkx
Sun Sep 19, 2021 7:17 pm
Forum: RouterBOARD hardware
Topic: can CCR2004-16G-2S+ downgrade to v6 ?
Replies: 10
Views: 1785

Re: can CCR2004-16G-2S+ downgrade to v6 ?

CCR2004-1G-12S+2XS - Size of RAM in RouterOS v6 1792MB ECC / RouterOS v7 4GB ECC [sarcasm] So when I install v7 on a CCR2004-1G-12S-2XS, little Latvian gremlins sneak in with additional RAM? And do they take it away if I downgrade to v6 again? But chips on board say they're 4GB all the time? [/sarc...
by mkx
Sun Sep 19, 2021 7:11 pm
Forum: RouterBOARD hardware
Topic: RBGPOE max power
Replies: 6
Views: 988

Re: RBGPOE max power

Sure gadgets do get aged
Many think electronics do not age ... :lol:

They're right, electronics don't age. They either become obsolete (and get replaced) or they simply blow up (and get replaced).
by mkx
Sun Sep 19, 2021 7:02 pm
Forum: RouterBOARD hardware
Topic: RBGPOE max power
Replies: 6
Views: 988

Re: RBGPOE max power

Well ... nobody's gonna offer their neck to put under axe for long-term functionality. Sure gadgets do get aged. Aging means capacitors might leak (which might mean lower sustained voltage ... with 50V supply voltage it might lead to loss of smoke). Aging means corrosion, corroded contacts mean high...
by mkx
Sun Sep 19, 2021 6:44 pm
Forum: Wireless Networking
Topic: Accesspoint only with VLANs
Replies: 17
Views: 1244

Re: Accesspoint only with VLANs

The traffic coming to the wireless interface is already tagged, or at least that is how it is considered... If you see my example earlier, the wifi interface is set to accept only VLAN tagged, although the incoming traffic from the wireless clients is not Tagged ofcorse.. I think that has to do wit...
by mkx
Sun Sep 19, 2021 6:33 pm
Forum: Wireless Networking
Topic: CAps configuration
Replies: 6
Views: 745

Re: CAps configuration

First thing you have to decide is whether all APs form single large network or each runs their own. If each runs their own, then they'll run in routing mode, but roaming won't work (not nicely that is), so in this case you better set them with different SSIDs. CAPsMAN is out of question in this case...
by mkx
Sun Sep 19, 2021 6:20 pm
Forum: General
Topic: CRS312-4C+8XG L2 VLAN slow performance [Fixed]
Replies: 8
Views: 517

Re: CRS312-4C+8XG L2 VLAN slow performance, misconfiguration?

I removed eht9 from the non-existant bridge and this make it.

How's fan speed now under load?
by mkx
Sun Sep 19, 2021 6:16 pm
Forum: General
Topic: Inter VLAN filtering fom VLAN A to VLAN B
Replies: 23
Views: 1172

Re: Inter VLAN filtering fom VLAN A to VLAN B

What @zacharias wants to hide from @anav (by not saying it out loud) is the fact that any device running ROS can be a router. This includes switch CRS312-4C+8XG ... which can do (limited set of) L3 tasks wirespeed if running v7.1. I guess that (accompanied with a glass of Canadian rye) is making @an...
by mkx
Sun Sep 19, 2021 4:00 pm
Forum: RouterBOARD hardware
Topic: RBGPOE max power
Replies: 6
Views: 988

Re: RBGPOE max power

RBGPOE doesn't deliver power, it only passes power. I guess power limit on PoE-out devices is due to ability to power-off/power-on the port and to select output voltage (if device has two power inputs) and both imply some active circuit. RBGPOE has none. Max voltage depends on isolation class of ele...
by mkx
Sun Sep 19, 2021 3:48 pm
Forum: Wireless Networking
Topic: Accesspoint only with VLANs
Replies: 17
Views: 1244

Re: Accesspoint only with VLANs

No, no, no ... you've got VLANs wrong again. Here's a good tutorial about VLANs in RouterOS. Regarding starting from scratch: there's winbox (windows binary, but works well under wine in linux and macOS) which can connect to device via MAC (no IP necessary). A great tool for configuring devices when...
by mkx
Sun Sep 19, 2021 3:27 pm
Forum: General
Topic: Poor inter-vlan routing and High "Networking" CPU usage on RB5009
Replies: 20
Views: 1452

Re: Poor inter-vlan routing and High "Networking" CPU usage on RB5009

A prime example of changing landscape is VLAN support on RB4011. Traditionally the only way was the software way (bridge vlan-filtering), nothing was possible through /interface ethernet switch (unlike vast majority of switch-chip equipped MT devices). With 7.1rc1 this happened: * added bridge HW of...
by mkx
Sun Sep 19, 2021 1:47 pm
Forum: General
Topic: Poor inter-vlan routing and High "Networking" CPU usage on RB5009
Replies: 20
Views: 1452

Re: Poor inter-vlan routing and High "Networking" CPU usage on RB5009

RB5009 doesn't support L3 HW offloading, only CRS309 does.
by mkx
Sun Sep 19, 2021 1:21 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS+RM with SFP to RJ45 Copper Transceiver Module
Replies: 8
Views: 1425

Re: RB4011iGS+RM with SFP to RJ45 Copper Transceiver Module

Answer to Q3: ether1 power from Cisco switch PoE The RB4011iGS+RM doesn't support IEEE 802.3XX PoE It only supports Passive PoE with an input Voltage between 18-57 V If you connect it, it probably won't work But it might. @normis explained in one post that RB4011 does negotiate 802.3 af/at PoE on i...
by mkx
Sun Sep 19, 2021 1:04 pm
Forum: Wireless Networking
Topic: Accesspoint only with VLANs
Replies: 17
Views: 1244

Re: Accesspoint only with VLANs

There are multiple ways of dealing with multiple-SSID-per-radio situation. But if we want to stick to VLAN-way, then the most "politically correct" way is to use bridge with vlan-filtering=yes . In this case you don't set anything regarding VLANs on wireless interfaces (neither master nor ...
by mkx
Sun Sep 19, 2021 11:32 am
Forum: General
Topic: Inter VLAN filtering fom VLAN A to VLAN B
Replies: 23
Views: 1172

Re: Inter VLAN filtering fom VLAN A to VLAN B

As per initial post of this thread: OP wants some limitations on connectivity between VLANs. Which means firewall (with fairly simple rules) is involved. While CRS can do fasttracking in hardware, it comes with some serious limitations. If they get hit, performance drop will be dramatic and in this ...
by mkx
Sun Sep 19, 2021 11:24 am
Forum: Beginner Basics
Topic: Real DMZ on second IP range
Replies: 15
Views: 1152

Re: Real DMZ on second IP range

So did you check network settings on virtual servers? Check network settings on vswitch as well, it should allow connectivity between vhosts.
by mkx
Sun Sep 19, 2021 11:16 am
Forum: RouterOS v7 BETA
Topic: v6.48.7 hap ac2 admin ghost [SOLVED]
Replies: 3
Views: 962

Re: v6.48.7 hap ac2 admin ghost [SOLVED]

Where did you get version 6.48.7? It wasn't from from official download site for sure ...
by mkx
Sat Sep 18, 2021 10:50 pm
Forum: General
Topic: Inter VLAN filtering fom VLAN A to VLAN B
Replies: 23
Views: 1172

Re: Inter VLAN filtering fom VLAN A to VLAN B

With v7 of RoS some Tik switches will have the capability to do NEAR line speed forwarding … unfortunately the switch then OP SELECTED CANNOT DO IT.

Mikrotik's documentation says it does. (OP mentioned CRS312-4C+8XG )
by mkx
Sat Sep 18, 2021 10:35 pm
Forum: Beginner Basics
Topic: Real DMZ on second IP range
Replies: 15
Views: 1152

Re: Real DMZ on second IP range

So you have ether11 and ether12 bridged for the DMZ in question (and ether12 is actually disabled). I don't see error which would force servers to communicate via gateway. Since router isn't running DHCP server for that subnet I assume servers have IP settings configured manually. So I'm asking you ...
by mkx
Sat Sep 18, 2021 5:06 pm
Forum: General
Topic: Need help on rb750gr3 about maximum lan connection
Replies: 40
Views: 1884

Re: Need help on rb750gr3 about maximum lan connection

@OP: where do you enforce the 20Mbps limit: on wireless routers or on hEX? Anyways, the fact that hEX CPU liad resched 90% during speedtest indicates that it's underpowered for workload it has to deal with. My personal opinion is that router should not have load more than 50% long enough for me to n...
by mkx
Sat Sep 18, 2021 5:00 pm
Forum: General
Topic: Need help on rb750gr3 about maximum lan connection
Replies: 40
Views: 1884

Re: Need help on rb750gr3 about maximum lan connection

I'm not that much concerned about IP address space[*] (each wireless router performs NAT by its own, main router again and ISP modem again), but what bothers me is potential congestion of wifi bands. Are those wireless routers all operating on 2.4GHz? How far from each other are they? Take your smar...
by mkx
Sat Sep 18, 2021 12:15 pm
Forum: Beginner Basics
Topic: **HELP NEEDED** RB750Gr3- Load balancing and Failover configuration
Replies: 16
Views: 1413

Re: **HELP NEEDED** RB750Gr3- Load balancing and Failover configuration

then possibility of only one ISP line being used is around one in a thousand. Right ... But not impossible. If somebody has too much time and is checking performance every few seconds (or has enabled graphing), then seeing this happen now and then is a reality and might trigger some sort of anxiety...
by mkx
Fri Sep 17, 2021 10:08 pm
Forum: General
Topic: Route ALL NTP traffic over a specific WAN [SOLVED]
Replies: 30
Views: 1486

Re: Route ALL NTP traffic over a specific WAN [SOLVED]

HW offloaded routing (inter LAN or inter-VLAN, doesn't matter) is being in development (ROS v7.1) and only for CRS3xx models.

HW offloaded switching/bridging is to certain extent possible on all devices with switch chip, the way it should be configured varies between device models.
by mkx
Fri Sep 17, 2021 10:03 pm
Forum: Beginner Basics
Topic: Need help on rb750gr3 about maximum lan connection
Replies: 4
Views: 484

Re: Need help on rb750gr3 about maximum lan connection

OP started two identical threads, this is the other one: viewtopic.php?f=2&t=178631
Let's continue thrre, shall we?
by mkx
Fri Sep 17, 2021 9:13 pm
Forum: Beginner Basics
Topic: Real DMZ on second IP range
Replies: 15
Views: 1152

Re: Real DMZ on second IP range

Oh the joys of (great)parenthood ...
by mkx
Fri Sep 17, 2021 9:10 pm
Forum: Beginner Basics
Topic: **HELP NEEDED** RB750Gr3- Load balancing and Failover configuration
Replies: 16
Views: 1413

Re: **HELP NEEDED** RB750Gr3- Load balancing and Failover configuration

If things are all working right then seeing sharing ratios different than 200:200 is matter of statistics. As I explained it is most probable to see even ratio, but some odd ratios are possible but you should not see that too often. Since we're talking about two ISPs with different backbone and peer...
by mkx
Fri Sep 17, 2021 8:58 pm
Forum: General
Topic: Route ALL NTP traffic over a specific WAN [SOLVED]
Replies: 30
Views: 1486

Re: Route ALL NTP traffic over a specific WAN [SOLVED]

None of RB devices (your IPQ4019-based RB450Gx4 is not excluded) can HW offload bridge vlan-filtering in ROS v6. In ROSv7 things might change (RB4011 was mentioned, but uses completely different SoC). If you want VLAN operations done by switch chip, you have to configure things under /interface ethe...
by mkx
Fri Sep 17, 2021 8:51 pm
Forum: General
Topic: Need help on rb750gr3 about maximum lan connection
Replies: 40
Views: 1884

Re: Need help on rb750gr3 about maximum lan connection

How many users are served by humble RB750Gr3? I'd first check two resources while you observe problems: CPU load (run CPU profiler to see load of individual CPU cores and which process uses most of it) and number of connections tracked (see output of /ip firewall connection tracking print ). Another...
by mkx
Fri Sep 17, 2021 5:51 pm
Forum: General
Topic: Route ALL NTP traffic over a specific WAN [SOLVED]
Replies: 30
Views: 1486

Re: Route ALL NTP traffic over a specific WAN [SOLVED]

One drawback of using IP address list instead of mangling NTP traffic is that all traffic towards those targets will use alternative WAN, non-NTP traffic as well. Some NTP servers share their IP addresses with other services (the most famous NTP servers don't). Plus, if I understand the latest conce...
by mkx
Fri Sep 17, 2021 5:42 pm
Forum: Beginner Basics
Topic: **HELP NEEDED** RB750Gr3- Load balancing and Failover configuration
Replies: 16
Views: 1413

Re: **HELP NEEDED** RB750Gr3- Load balancing and Failover configuration

It seems impossible ...
Not impossible. But probability of it happen is 1 divided by 2 to the power of (N-1) (where N is number of active torrent peers). E.g. if number of active torrent peers is 11, then possibility of only one ISP line being used is around one in a thousand.
by mkx
Fri Sep 17, 2021 5:36 pm
Forum: Beginner Basics
Topic: Real DMZ on second IP range
Replies: 15
Views: 1152

Re: Real DMZ on second IP range

I guess we need a script for guessing indeed :wink:

@anav, feeling dizzy yet?
by mkx
Fri Sep 17, 2021 5:34 pm
Forum: RouterOS v7 BETA
Topic: CRS317-1G-16+ on 7.1rc3: IPFix with wrong timestamp, terrible InterVLAN Routing performance
Replies: 8
Views: 1227

Re: CRS317-1G-16+ on 7.1rc3: IPFix with wrong timestamp, terrible InterVLAN Routing performance

Circular reference: vlan1 marked as a tagged interface of bridge1, but bridge1 is the interface under vlan1.

Would it be possible for command interpreter to detect such circular references? They seem to be quite frequent for inexperienced users ...
by mkx
Fri Sep 17, 2021 3:26 pm
Forum: General
Topic: Route ALL NTP traffic over a specific WAN [SOLVED]
Replies: 30
Views: 1486

Re: Route ALL NTP traffic over a specific WAN [SOLVED]

(NTP is one of the protocol than for be full compliant want also the src port 123) AFAIK neither src-port nor dst-port have to be exactly 123. There are two kinds of NTP applications: applications running as service/daemon and usually work as clients (to lower stratum servers) as well as servers (t...
by mkx
Fri Sep 17, 2021 3:18 pm
Forum: Wireless Networking
Topic: Low WiFi speeds on hAP ac²
Replies: 17
Views: 1549

Re: Low WiFi speeds on hAP ac²

OP wrote in OP: I need one of the multi-anthena access points supporting multiple streams. Is there a MikroTik product that would suite my needs? Audience with stable ROS v7 (with wifiwave2 driver) would quite probably satisfy the needs and is a Mikrotik product. None of TPlinks you're mentioning an...
by mkx
Fri Sep 17, 2021 3:14 pm
Forum: General
Topic: CCR2004-16G-2S+ with RouterOS 7.0.4 [SOLVED]
Replies: 1
Views: 507

Re: CCR2004-16G-2S+ with RouterOS 7.0.4 [SOLVED]

ROS 7.0.4 is a device-specific (non-beta) version and is reported to be pretty stable on devices which they have it available and installed. Whether it's stable enough for use in production environment it's up to your decision (based on extensive lab testing). Beware that ROS version installed on yo...
by mkx
Fri Sep 17, 2021 3:10 pm
Forum: General
Topic: Route ALL NTP traffic over a specific WAN [SOLVED]
Replies: 30
Views: 1486

Re: Route ALL NTP traffic over a specific WAN [SOLVED]

Why would use mangle. @ishanjain clearly stated that he doesn't control which NTP servers are used by clients. The only clear way of determining that a packet should be routed via alternative path is thus matching against certain properties (protocol=udp and dst-port=123) for packets about to leave...
by mkx
Fri Sep 17, 2021 3:02 pm
Forum: General
Topic: Bridge different VLANs together [SOLVED]
Replies: 6
Views: 922

Re: Bridge different VLANs together [SOLVED]

Where are the different vlans. I assume OP knows pretty much exactly what he wants and linux commands make sense in context of what he wrote. So essentially OP needed a linux2ROS translator ... not something we expect you to be :-P In the context of what OP asked, your suggestion of Thus simple ONE...
by mkx
Fri Sep 17, 2021 2:44 pm
Forum: Beginner Basics
Topic: Real DMZ on second IP range
Replies: 15
Views: 1152

Re: Real DMZ on second IP range

mkx stop guessing, its driving me crazy..........

Let me guess: you never liked guesswork? :-P
by mkx
Fri Sep 17, 2021 2:40 pm
Forum: Beginner Basics
Topic: same sim card: different performance between mobile and SXT LTE6 kit
Replies: 5
Views: 763

Re: same sim card: different performance between mobile and SXT LTE6 kit

Another possibility: MNO throttles traffic depending on device's IMEI (MSB are device model specific). Not many (still) do it though.

And no, generally it is impossible to change IMEI (and generally it's forbidden to do it).
by mkx
Fri Sep 17, 2021 2:22 pm
Forum: General
Topic: Bridge different VLANs together [SOLVED]
Replies: 6
Views: 922

Re: Bridge different VLANs together [SOLVED]

The idea in ROS is the same, but slightly different syntax: /interface vlan add interface=ether2 name=e2v10 vlan-id=10 add interface=ether2 name=e2v20 vlan-id=20 add interface=ether3 name=e3v222 vlan-id=222 /interface bridge add name=br222 /interface bridge port add bridge=br222 interface=e2v10 add ...
by mkx
Fri Sep 17, 2021 12:25 pm
Forum: General
Topic: Scheduler stops executing script
Replies: 22
Views: 1491

Re: Scheduler stops executing script

Scripts are running fine! 100%. The only problem is, that the scheduler does not try to run them after some thousand successful runs. This is also visible at "next-run" in scheduler, which is in the past in that case. Since problem seems to be connected to internal state of your router an...
by mkx
Fri Sep 17, 2021 11:38 am
Forum: Wireless Networking
Topic: Low WiFi speeds on hAP ac²
Replies: 17
Views: 1549

Re: Low WiFi speeds on hAP ac²

People who did test the upcoming wifiwave2 driver, confirmed that it both increases obtainable throughput as well as reduces throughput fluctuations. Which is something to look forward, however there's no published ETA for ROS v7.1. It seems very likely that hAP ac3 will be supported, RB4011 (wirele...
by mkx
Fri Sep 17, 2021 11:07 am
Forum: RouterOS v7 BETA
Topic: v7.1rc3 [development] is released!
Replies: 172
Views: 22673

Re: v7.1rc3 [development] is released!

The irq info contains name which driver sets and doesn't bear any special meaning. It really depends on what driver servicing certain interrupt line sets. And I'd guess it's the very same driver loaded on both IPQ4018 and IPQ4019 SoCs and then driver is intelligent enough to initialize whatever hard...
by mkx
Fri Sep 17, 2021 10:55 am
Forum: Beginner Basics
Topic: CRS317-1G-16S+RM HELP REQUESTED!
Replies: 23
Views: 1629

Re: CRS317-1G-16S+RM HELP REQUESTED!

Just one more correction needed: the last item is numbered as bullet #7 while it should be #9.
by mkx
Fri Sep 17, 2021 9:19 am
Forum: RouterBOARD hardware
Topic: Wireless menu and wlan devices missing after update of SXTs to 6.48.4
Replies: 3
Views: 923

Re: Wireless menu and wlan devices missing after update of SXTs to 6.48.4

I have 2 of the older SXTs and after updating to RouterOS 6.48.4 I can no longer access any wireless features. Verify the list of installed packages after upgrade ... under /system packages . Version number of all installed packages should match version number of system package. There should be a n...
by mkx
Fri Sep 17, 2021 9:13 am
Forum: RouterOS v7 BETA
Topic: v7.1rc3 [development] is released!
Replies: 172
Views: 22673

Re: v7.1rc3 [development] is released!

Later I will unscrew board from enclosure and see if its IPQ-4018 or IPQ 4019-based. Even if ROS says IPQ4019 on board you should have an IPQ4018 according to the official specs, I have opened my hAP ac2 and it's an IPQ4018. Where exactly does ROS report exact SoC in the device? On my hAP ac2 the m...
by mkx
Fri Sep 17, 2021 9:00 am
Forum: Announcements
Topic: Mēris botnet information
Replies: 55
Views: 32572

Re: Mēris botnet information

Default configuration (on devices that come with default) on recent ROS versions includes this: # Establish proper interface list membership /interface list member add list=LAN interface=bridge comment="defconf" add list=WAN interface=ether1 comment="defconf" # block access to ro...
by mkx
Fri Sep 17, 2021 8:43 am
Forum: Beginner Basics
Topic: Real DMZ on second IP range
Replies: 15
Views: 1152

Re: Real DMZ on second IP range

First off: are the two servers supposed to communicate with each other a) through firewall or b) are they allowed to communicate directly? If it's b), then they should be able to communicate even if they are connected to a dumb switch. Hence you should check if they have proper IP settings, speciall...
by mkx
Fri Sep 17, 2021 8:34 am
Forum: Beginner Basics
Topic: CRS317-1G-16S+RM HELP REQUESTED!
Replies: 23
Views: 1629

Re: CRS317-1G-16S+RM HELP REQUESTED!

I suggest executing step #8 (setting admin password) right after step #3 (reconnecting after configuration reset). This step should thus become new step #4. It is extremely dangerous to get router connected to internet without first having at least admin password set. It would be advisable to make s...
by mkx
Thu Sep 16, 2021 11:28 pm
Forum: Beginner Basics
Topic: **HELP NEEDED** RB750Gr3- Load balancing and Failover configuration
Replies: 16
Views: 1413

Re: **HELP NEEDED** RB750Gr3- Load balancing and Failover configuration

When benchmarking using torrent, you should get net throughput very close to sum of both ISP throughputs because torrent uses maaany concurrent connections to many peers which is ideal for your kind of load balancing.The exact result still depends on how peers perform though. For streaming you will ...
by mkx
Thu Sep 16, 2021 11:25 pm
Forum: Beginner Basics
Topic: CRS317-1G-16S+RM HELP REQUESTED!
Replies: 23
Views: 1629

Re: CRS317-1G-16S+RM HELP REQUESTED!

There are two ways to configure switches in the MT world.

For CRS3xx (OP mentioned CRS317), only the first one is the right one.
by mkx
Thu Sep 16, 2021 9:36 pm
Forum: General
Topic: Audit my input firewall
Replies: 54
Views: 2685

Re: Audit my input firewall

add action=drop chain=output comment="Drop Access to WebUI" protocol=tcp src-port=80 It's similar to add action=drop chain=input comment="Drop Access to WebUI" protocol=tcp dst-port=80 but acts s packet later. The second rule drops even initial packet (SYN packet, the first step...
by mkx
Thu Sep 16, 2021 7:50 pm
Forum: General
Topic: Audit my input firewall
Replies: 54
Views: 2685

Re: Audit my input firewall

... is hard to think something that Router generate for bad purpose...

Not that hard ... but that would probably mean router was hacked and we really need to protect router from getting hacked in the first place. Hence high importance of quality input filters.
by mkx
Thu Sep 16, 2021 6:09 pm
Forum: General
Topic: Why firewall rules are so important...
Replies: 12
Views: 1540

Re: Why firewall rules are so important...

You do realize this is not a oppionion debate.

Obviously it is.
by mkx
Thu Sep 16, 2021 6:04 pm
Forum: General
Topic: Why firewall rules are so important...
Replies: 12
Views: 1540

Re: Why firewall rules are so important...

The point is that router's management access (any kind) should not be wildly open. Period. Guess what, many management processors built in servers (BMC, iLO, whatever vendor calls them) have http(s) access and show firmware release on login page. The fact server's got physical management interface w...
by mkx
Thu Sep 16, 2021 5:51 pm
Forum: General
Topic: Help... for IP address scheme with multiple router
Replies: 2
Views: 354

Re: Help... for IP address scheme with multiple router

Hint: RB951 snd RB4011 don't have to act as routers at all, they can be used simply as switches and/or AP in the way that all other hosts (regardless how they're connnected to these two devices) are part of same subnetwork. Hence plea for high-level overview of wishes/requirements and we'll give you...
by mkx
Thu Sep 16, 2021 8:34 am
Forum: Beginner Basics
Topic: **HELP NEEDED** RB750Gr3- Load balancing and Failover configuration
Replies: 16
Views: 1413

Re: **HELP NEEDED** RB750Gr3- Load balancing and Failover configuration

If you want to get some advice, you'll have to be more verbose on what exactly doesn't feel right. At least my crystall ball is out of order today.
by mkx
Wed Sep 15, 2021 9:26 pm
Forum: Beginner Basics
Topic: CRS312-4C+8XG-RM 10G switch fan noise
Replies: 3
Views: 572

Re: CRS312-4C+8XG-RM 10G switch fan noise

If noise is an issue for you, and having it in living room it clearly is, then you should definitely go for a passively cooled switch. You can also decide to run RouterOS but it doesn't guarantee that fans will be silent at all times, it just has a tad better temperature and fan control. If you are ...
by mkx
Wed Sep 15, 2021 9:18 pm
Forum: General
Topic: Audit my input firewall
Replies: 54
Views: 2685

Re: Audit my input firewall

@anav 8)

Now can I have a docker containainer that automatically selects the right IP subnet mask please. :-)
but... i do not understand... really....

Neither does @anav :-P
by mkx
Wed Sep 15, 2021 5:36 pm
Forum: General
Topic: 2 separate networks - no internet access
Replies: 6
Views: 590

Re: 2 separate networks - no internet access

Im assuming your alluding to the fact that the network mask should match the IP Pool? No, I'm alluding that it's a jolly good idea that client IP settings (i.e. subnet mask received from DHCP server, which is defined in /ip dhcp-server network section) match IP settings of their gateway. IP pool is...
by mkx
Wed Sep 15, 2021 4:56 pm
Forum: Beginner Basics
Topic: Bandwith control on Fast Fibre
Replies: 2
Views: 726

Re: Bandwith control on Fast Fibre

Queues and fasttrack are mutually exclusive. But then your router might net be powerful enough to run firewalling without fasttrack at wire speed. I suggest you to disable fasttrack again and while traffic is bottlenecked, run /tool profile cpu=all to see if CPU is bottleneck[*] and if it is, verify...
by mkx
Wed Sep 15, 2021 4:46 pm
Forum: General
Topic: 2 separate networks - no internet access
Replies: 6
Views: 590

Re: 2 separate networks - no internet access

Oh suggest something like 22 will work, pulling any number out of a hat........ ;-p :

And that wisdom of yours has nothing to do with OP's setting in /ip dhcp-server network ... :wink:
by mkx
Wed Sep 15, 2021 4:44 pm
Forum: Beginner Basics
Topic: 2 separate networks - no internet access
Replies: 4
Views: 499

Re: 2 separate networks - no internet access

By the way I am a quick study!!
viewtopic.php?f=2&t=178542

You're my man :-)
by mkx
Wed Sep 15, 2021 4:07 pm
Forum: Beginner Basics
Topic: 2 separate networks - no internet access
Replies: 4
Views: 499

Re: 2 separate networks - no internet access

/ip address
add address=10.18.100.1/22 comment=Guest interface=ether3 network=10.18.100.0

Missing subnet mask implies subnet mask /32 which effectively disables all communication via this interface.

@anav, I'm deeply disappointed because you did not catch this error :wink:
by mkx
Wed Sep 15, 2021 1:10 pm
Forum: Wireless Networking
Topic: Low WiFi speeds on hAP ac²
Replies: 17
Views: 1549

Re: Low WiFi speeds on hAP ac²

In short: getting throughputs above 300 Mbps with your setup is pretty decent (but not great) result. Sure there are devices which do better (using similar hardware) and there are reports that wifiwave2 driver, which comes with ROSv7 (it's testing software) enables much better performance on certain...
by mkx
Tue Sep 14, 2021 11:28 pm
Forum: Wireless Networking
Topic: Unable to connect to hAC2 Wirelessly
Replies: 2
Views: 690

Re: Unable to connect to hAC2 Wirelessly

This problem is being dealt with in another thread, will just reply here for readers who might get here by chance. Something might be stripping the tag. No, it's not. OP has set vlan-mode=use-tag on wireless interfaces without explicitly setting vlan-id property. Implicit default setting is vlan-id=...
by mkx
Tue Sep 14, 2021 11:21 pm
Forum: General
Topic: Client isolation within VLAN and fast roaming
Replies: 43
Views: 2536

Re: Client isolation within VLAN and fast roaming

My new problem is: How can I gain access to a cAP ac in CAPs mode. The CAPsMAN device did assign it an IP (192.168.88.235). I tried to access it via SSH, Telnet and WebFig via Ethernet 1 to no avail. CAPsMAN only provisions wireless interfaces. The rest you have to do yourself (or some autoconfigur...
by mkx
Tue Sep 14, 2021 10:24 pm
Forum: RouterOS v7 BETA
Topic: PLEASE MikroTik made NetInstall version for Docker....
Replies: 41
Views: 3180

Re: PLEASE MikroTik made NetInstall version for Docker....

I assumed that and spent a LOT of time on it. I could only get a bridged mode of 172.17.0.0/16 to work and not a bridged mode to my local network. Well ... perhaps this docker container support indeed needs some polishing. IIRC docker (implicit) default networking uses bridge with 172.17.0.0/16 net...
by mkx
Tue Sep 14, 2021 3:55 pm
Forum: Beginner Basics
Topic: Traffic to management of MikroTik switches not going through
Replies: 25
Views: 1776

Re: Traffic to management of MikroTik switches not going through

Well ... as @anav already wrote: show us text export of configuration and we might be able to tell you where things went wrong. Without that we can only guess.
by mkx
Tue Sep 14, 2021 3:42 pm
Forum: RouterOS v7 BETA
Topic: PLEASE MikroTik made NetInstall version for Docker....
Replies: 41
Views: 3180

Re: PLEASE MikroTik made NetInstall version for Docker....

Getting netinstall to work in a container is not difficult when using host networking. When using bridge mode - which is the only mode I have seen on the examples for ROS it won't work. Why not? Configuration examples, prepared by Mikrotik, go like this: create bridge for docker set IP address on d...
by mkx
Tue Sep 14, 2021 3:25 pm
Forum: Beginner Basics
Topic: Traffic to management of MikroTik switches not going through
Replies: 25
Views: 1776

Re: Traffic to management of MikroTik switches not going through

Two things: I'm not going to look at some random screenshots. I suggest you to start using CLI real quick and post text export of configuration (execute /export hide-sensitive and copy-paste ouptut inside [ code] [/code] environment). Are you sure you want to mirror traffic originating from (and ter...
by mkx
Tue Sep 14, 2021 12:29 pm
Forum: Beginner Basics
Topic: Bridge an existing Wifi to LAN
Replies: 6
Views: 813

Re: Bridge an existing Wifi to LAN

Generally switching between 2.4GHz and 5GHz is done solely on basis of signal strength (current throughput does not count as decision criteria) and that's true for all wireless devices (OK, perhaps there are some advanced devices extending what WiFi 802.11 standard defines that can do it more intell...
by mkx
Tue Sep 14, 2021 12:24 pm
Forum: Beginner Basics
Topic: Traffic to management of MikroTik switches not going through
Replies: 25
Views: 1776

Re: Traffic to management of MikroTik switches not going through

For CRS3xx devices, port mirroring can be configured according to this manual.

I strongly suggest you to get the CLI access working ASAP.
by mkx
Tue Sep 14, 2021 12:10 pm
Forum: Beginner Basics
Topic: Devices connecting to the wireless are assigned vlan1 instead of intended VLAN
Replies: 4
Views: 557

Re: Devices connecting to the wireless are assigned vlan1 instead of intended VLAN

A few (minor) problems: /interface bridge add name=bridge1 pvid=100 vlan-filtering=yes /interface vlan add interface=bridge1 name=vlan100 vlan-id=100 /interface bridge vlan add bridge=bridge1 tagged=ether1,bridge1 untagged=ether2,ether3,ether4,ether5 vlan-ids=100 First configuration (setting PVID on...
by mkx
Tue Sep 14, 2021 8:16 am
Forum: Beginner Basics
Topic: Traffic to management of MikroTik switches not going through
Replies: 25
Views: 1776

Re: Traffic to management of MikroTik switches not going through

So when you get some command for CLI, you should be able to configure the same through GUI Well I tried port mirroring on both ingress and egress from the switch bridge to the sfp port, but there's no traffic. and that's pretty much what the guide said about CLI. Depending on which particular switc...
by mkx
Tue Sep 14, 2021 8:13 am
Forum: RouterOS v7 BETA
Topic: v7.1rc3 adds Docker (TM) compatible container support
Replies: 211
Views: 25467

Re: v7.1rc3 adds Docker (TM) compatible container support

Is https://hub.docker.com/r/frrouting/frr supported? Because it supports protocols that RouterOS doesn't? I wonder what's the point? Running container with routing engine ... on a router? Why not take a decent RPI (more RAM, user can choose decently sized storage) and run FRR there? Pair RPI with a...
by mkx
Mon Sep 13, 2021 11:24 pm
Forum: Beginner Basics
Topic: Traffic to management of MikroTik switches not going through
Replies: 25
Views: 1776

Re: Traffic to management of MikroTik switches not going through

I tried looking at the documentation but it's all for the terminal and not for the web, Webfig (I hope you're not still using QuickSet) has almost identical hierarchical structure as CLI. So when you get some command for CLI, you should be able to configure the same through GUI (both Webfig and Win...
by mkx
Mon Sep 13, 2021 7:21 pm
Forum: General
Topic: Is this type of filtering possible?
Replies: 4
Views: 510

Re: Is this type of filtering possible?

There's bridge setting use-ip-firewall (or something close to that). If it's set to yes and W offload is disabled for at least one of involved ports (so that traffic is handled by CPU), this setting makes bridge to push traffic through firewall rules (both raw and filter). Some properties are not av...
by mkx
Mon Sep 13, 2021 3:09 pm
Forum: SwOS
Topic: Configuration needed to pass iSCSI? Windows says 'connection failed'
Replies: 16
Views: 1618

Re: Configuration needed to pass iSCSI? Windows says 'connection failed'

@OP: since we're now talking about RouterOS problem, start a new thread in appropriate subforum (e.g. Beginner Basics).
by mkx
Mon Sep 13, 2021 3:08 pm
Forum: SwOS
Topic: Configuration needed to pass iSCSI? Windows says 'connection failed'
Replies: 16
Views: 1618

Re: Configuration needed to pass iSCSI? Windows says 'connection failed'

I was thinking of adding the "redact remaining sensitive data" sentence but then decided not to ... I assumed there wouldn't be much of sensitive data when device is configured as switch.
by mkx
Mon Sep 13, 2021 3:00 pm
Forum: Beginner Basics
Topic: Cannot SSH from LAN to outside devices - strange [SOLVED]
Replies: 8
Views: 797

Re: Cannot SSH from LAN to outside devices - strange [SOLVED]

The rule identified by @rextended ... you should change it to
add action=dst-nat chain=dstnat comment=SSH dst-port=22 protocol=tcp to-addresses=192.168.2.10 to-ports=22 in-interface-list=WAN
(added the in-interface-list property). Ditto for the wireguard port forwarding rule.
by mkx
Mon Sep 13, 2021 2:59 pm
Forum: SwOS
Topic: Configuration needed to pass iSCSI? Windows says 'connection failed'
Replies: 16
Views: 1618

Re: Configuration needed to pass iSCSI? Windows says 'connection failed'

It's RouterOS heh.

So you can post full config (run /export hide-sensitive from terminal window and copy-paste output into [code] [/code] environment) for review.
by mkx
Mon Sep 13, 2021 2:40 pm
Forum: Beginner Basics
Topic: Cannot SSH from LAN to outside devices - strange [SOLVED]
Replies: 8
Views: 797

Re: Cannot SSH from LAN to outside devices - strange [SOLVED]

The screenshot you posted does not tell enough of story. Post full config in text: execute /export hide-sensitive file=anynameyouwish inside terminal window, fetch resulting file, open it using text editor and copy-paste contents here ... inside [ code] [/code] environment. Before copy-paste check i...
by mkx
Mon Sep 13, 2021 2:35 pm
Forum: Beginner Basics
Topic: Bridge an existing Wifi to LAN
Replies: 6
Views: 813

Re: Bridge an existing Wifi to LAN

If you want to use both wireless interfaces to connect to same AP and use them in parallel, you're after bonding ... but that requires configuration on both ends. While bonding in RouterOS is pretty versatile, I'd be surprised if you could do it on AP of a random vendor.
by mkx
Mon Sep 13, 2021 11:09 am
Forum: Announcements
Topic: Mēris botnet information
Replies: 55
Views: 32572

Re: Mēris botnet information

CCR comes without any default configuration and that includes firewall. So it is essential to do all the configuration before ever exposing it to WAN. And that includes solid firewall rules which is not an easy task for novice ROS user.
by mkx
Mon Sep 13, 2021 11:07 am
Forum: SwOS
Topic: Configuration needed to pass iSCSI? Windows says 'connection failed'
Replies: 16
Views: 1618

Re: Configuration needed to pass iSCSI? Windows says 'connection failed'

iSCSI uses TCP for transport. Which means iSCSI initiator (client) has to be able to connect to iSCSI target (server) via IP. Typically both devices use usual IP routing information. QNAP only supports using TCP port number 3260 so verify that iSCSI initiator (windows) uses that port as destination ...
by mkx
Mon Sep 13, 2021 9:04 am
Forum: General
Topic: Is this type of filtering possible?
Replies: 4
Views: 510

Re: Is this type of filtering possible?

It is possible. When a RouterOS device is plugged between some device and the rest of network, it can be configured as a bridge (same L2 network). At the same time it can do some traffic filtering, bridge can enforce firewall settings. More in bridge firewall manual.
by mkx
Mon Sep 13, 2021 8:24 am
Forum: General
Topic: CRS317 Switch VLAN
Replies: 20
Views: 1308

Re: CRS317 Switch VLAN

As @biomesh already wrote ... IMO when bridge has vlan-filtering=yes set, then all traffic passes bridge (the switch-like entity) tagged. And frames get tags either a) because they enter bridge already tagged through trunk port or b) get tagged on ingress by bridge due to PVID setting. So if ether4 ...
by mkx
Mon Sep 13, 2021 8:06 am
Forum: RouterOS v7 BETA
Topic: Loosing configuration after reboot (7.1rc3)
Replies: 16
Views: 1931

Re: Loosing configuration after reboot (7.1rc3)

With a restart it downgrades. I used the button ‘downgrade’ in /system/packages to initiate the process. I’m not sure if a normal reboot would have done the trick as well.
No, it wouldn't. ROS doesn't downgrade unless explicitly instructed to do so.
by mkx
Sun Sep 12, 2021 10:10 pm
Forum: General
Topic: CRS317 Switch VLAN
Replies: 20
Views: 1308

Re: CRS317 Switch VLAN

Changing the PVID on the Bridge itself is all about the VID the untagged traffic will be assigned too... If for example an access port with PVID 201 and a Bridge with PVID 201 as well, access to that CPU/Device management will be successful through the untagged traffic between these ports... Settin...
by mkx
Sun Sep 12, 2021 10:06 pm
Forum: General
Topic: CRS317 Switch VLAN
Replies: 20
Views: 1308

Re: CRS317 Switch VLAN

Let's not get into theoretical discusions, it would be hijacking of the thread. For OP's case (judging from the network topology chart he posted) the problems with VLAN interface as bridge port will not happen. Ditto for the bridge PVID ... it was my suggestion based on my understanding if OP's prob...
by mkx
Sun Sep 12, 2021 9:22 pm
Forum: General
Topic: CRS317 Switch VLAN
Replies: 20
Views: 1308

Re: CRS317 Switch VLAN

@mkx, Not to forget: bridge has to have PVID set as well: The Bridge has already a PVID of 1, what would be the purpose of changing the PVID of the Bridge to something else ? If OP indeed wants to have ether4 tagged with VID 201 and the rest of ports untagged ... and he says he wants all PCs to com...
by mkx
Sun Sep 12, 2021 9:09 pm
Forum: Beginner Basics
Topic: New to Mikrotik
Replies: 55
Views: 3108

Re: New to Mikrotik

I stand corrected.
by mkx
Sun Sep 12, 2021 9:05 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc3 adds Docker (TM) compatible container support
Replies: 211
Views: 25467

Re: v7.1rc3 adds Docker (TM) compatible container support

How to mount a file instead of a folder ? You can't. The way linux works is that you can only mount a folder. Because mount point is always a folder. Usually application, run inside container, wants to open configuration file . So you'll have to prepare a folder containing configuration file and mo...
by mkx
Sun Sep 12, 2021 1:18 pm
Forum: General
Topic: is connection-tracking full ?
Replies: 5
Views: 588

Re: is connection-tracking full ?

6.45.7 at least I hope?
it is fixed after upgrading.

Not likely. Reboot associated to upgrade cleared connection tracking trable, but without shorthening some timeouts (the TCP established timeout in particular) the connection tracking table will fill up again in a few days.
by mkx
Sun Sep 12, 2021 1:14 pm
Forum: RouterOS v7 BETA
Topic: Feature Request : IPv6 Fasttrack
Replies: 35
Views: 4897

Re: Feature Request : IPv6 Fasttrack

I totally agree: IPv6 is a matter of present for everybody and should be trated and supported as such. No amount of turning blind eye will change that. While advanced features such as NATv6 would be nice to have, it's basic IPv6 support that has to be brought to higher level and it has to be done li...
by mkx
Sun Sep 12, 2021 1:11 pm
Forum: RouterOS v7 BETA
Topic: v7.1rc3 [development] is released!
Replies: 172
Views: 22673

Re: v7.1rc3 [development] is released!

Does anyone has experience with CRS125-24G-1S-2HnD and RouterOS 7.x ? If you're using CRS as a switch with configuration that allows full hardware offload, then you neither gain nor loose anything by upgrading. So far it was not shown that v7.1 exposes any new feature of switch chip which would pot...
by mkx
Sun Sep 12, 2021 11:56 am
Forum: General
Topic: How to find the origin of a Packet marks ? [SOLVED]
Replies: 6
Views: 691

Re: How to find the origin of a Packet marks ? [SOLVED]

Do a "/export" to file and search for it.
I don't have any tools to read exported ".backup" file.

/export command produces text output (commands usable in CLI). Binary files are output of /system backup command.
by mkx
Sun Sep 12, 2021 11:32 am
Forum: General
Topic: CRS317 Switch VLAN
Replies: 20
Views: 1308

Re: CRS317 Switch VLAN

On PC3 is only VLAN201 possible (no untagged). PC3 should communicate with PC1,PC2 and Router If you need ether4 tagged and the rest untagged, then configuration has to be the opposite of what you did ... ether4 without PVID set, the rest of ports (ether1..ether3) PVID set. The /interface bridge vl...
by mkx
Sun Sep 12, 2021 11:22 am
Forum: Beginner Basics
Topic: New to Mikrotik
Replies: 55
Views: 3108

Re: New to Mikrotik

I don't have any good ideas about RR not working, I've been using RR between linux hosts in the past. One gotcha I already mentioned: out-of-order delivery. TCP in theory should be able to deal with out-of-order packets (some TCP implementations are not exactly happy about it, reducing throughput an...
by mkx
Sat Sep 11, 2021 4:16 pm
Forum: Beginner Basics
Topic: New to Mikrotik
Replies: 55
Views: 3108

Re: New to Mikrotik

For bonding make sure you select bonding mode well supported by both link partners. CRS3xx series supports LACP (803.2ad) and RR modes in hardware (others include switch CPU meaning miserable throughputs). With 803.2ad, you have possibility to choose between different transmit-hash-policy settings w...
by mkx
Sat Sep 11, 2021 3:41 pm
Forum: General
Topic: Static IP address on every port with lease on demand [SOLVED]
Replies: 5
Views: 679

Re: Static IP address on every port with lease on demand [SOLVED]

I hope MikroTik will be smarter than TP-LINK with lease time. It's not entirely up to DHCP server (Mikrotik or TP-Link), it's up to DHCP client as well. RFC2131 defines granularity of 1 second for lease time and minimum lease time restriction was removed. DHCP clients might adhere to older RFC1541,...
by mkx
Sat Sep 11, 2021 3:29 pm
Forum: Beginner Basics
Topic: Mikrotik hAP lite and Pihole
Replies: 4
Views: 774

Re: Mikrotik hAP lite and Pihole

I guess we'll have to wait for containers built for low-memory boxes. Most containers nowdays don't care about RAM (and disk) requirements, some containers are too greedy to comfortably run on devices with only 32 MB RAM (such as hAP lite) of which half is already needed by ROS itself ... even if de...
by mkx
Sat Sep 11, 2021 3:17 pm
Forum: Beginner Basics
Topic: New to Mikrotik
Replies: 55
Views: 3108

Re: New to Mikrotik

Official performance numbers are here: https://mikrotik.com/product/ccr2004_1g_12s_2xs#fndtn-testresults If you go without any firewall rule, then I guess the relevant line will be Routing , none (fast path) configuration. And performance will probably be somewhere between the first and second colum...
by mkx
Fri Sep 10, 2021 8:56 pm
Forum: Wireless Networking
Topic: Is there a way I can use eSIM with Mikrotik?
Replies: 25
Views: 2170

Re: Is there a way I can use eSIM with Mikrotik?

Point taken.
by mkx
Fri Sep 10, 2021 8:43 pm
Forum: General
Topic: Is it possible to NAT/PAT this traffic?
Replies: 10
Views: 773

Re: Is it possible to NAT/PAT this traffic?

Right... What i don't understand is, if the clients uses a wrong port to connect to the database, why not correct that at the first place... That would certainly be correct approach ... but in certain circumstances it might not be possible. E.g. if the application in question is a legacy binary exe...
by mkx
Fri Sep 10, 2021 4:48 pm
Forum: General
Topic: Is it possible to NAT/PAT this traffic?
Replies: 10
Views: 773

Re: Is it possible to NAT/PAT this traffic?




Per OP's initial post, there's already a masquerade rule which should take care of source NAT of that particular connection as well. So no need to add a specific one.
If that is his WAN connection yes ...
He said his WAN network was 10.1.1.2/30 ...
by mkx
Fri Sep 10, 2021 4:43 pm
Forum: Wireless Networking
Topic: Is there a way I can use eSIM with Mikrotik?
Replies: 25
Views: 2170

Re: Is there a way I can use eSIM with Mikrotik?

not like mkx's which is just sterile controversy as always. You have right to have your own opinion about my posts, if you find them like that, you're free to ignore them. I'm just trying to give out as realistic and concrete posts as possible. There are some ideas floating around that simply fail ...
by mkx
Fri Sep 10, 2021 4:39 pm
Forum: General
Topic: Is it possible to NAT/PAT this traffic?
Replies: 10
Views: 773

Re: Is it possible to NAT/PAT this traffic?

You need to source NAT that connection

Per OP's initial post, there's already a masquerade rule which should take care of source NAT of that particular connection as well. So no need to add a specific one.
by mkx
Fri Sep 10, 2021 4:34 pm
Forum: General
Topic: Is it possible to NAT/PAT this traffic?
Replies: 10
Views: 773

Re: Is it possible to NAT/PAT this traffic?

You can dst-nat any connection, NAT machinery doesn't care about administrator's perception of what is LAN and what is WAN. It does its magic as long as packets in both directions pass router's CPU. Something like this: /ip firewall nat add chain=dstnat action=dst-nat dst-address=10.20.20.7 dst-port...
by mkx
Fri Sep 10, 2021 4:00 pm
Forum: General
Topic: When is 6.49 going to be released?
Replies: 16
Views: 1233

Re: When is 6.49 going to be released?

... you'll have to bite a bullet and get out of this beta mess.
If Mikrotik would me let escape the messed up Beta.

If Mikrotik allowed you to exit the beta without bothering, would you have to bite a bullet? :wink:
by mkx
Fri Sep 10, 2021 3:40 pm
Forum: Wireless Networking
Topic: Is there a way I can use eSIM with Mikrotik?
Replies: 25
Views: 2170

Re: Is there a way I can use eSIM with Mikrotik?

I just thought of a possible solution.

You're late. https://letmegooglethat.com/?q=sim+bank Not sure if prices are compatible with Mikrotik's prices.
by mkx
Fri Sep 10, 2021 3:26 pm
Forum: General
Topic: Do I need to contact support@mikrotik.com directly to get answers about the forum itself? [SOLVED]
Replies: 17
Views: 1492

Re: Do I need to contact support@mikrotik.com directly to get answers about the forum itself? [SOLVED]

Please, can someone explain why I have yesterday warning level [2] and now "Your warning level: [3]"???

Where do you see your warning score? I'm getting a feeling I'm being neglected ...
by mkx
Fri Sep 10, 2021 3:24 pm
Forum: General
Topic: hEX en ports all slaves but en1 & 2, how to send to freedom? [SOLVED]
Replies: 10
Views: 764

Re: hEX en ports all slaves but en1 & 2, how to send to freedom? [SOLVED]

So why don't you follow suggestion by @sindy and post configuration? We can have a look at what's configured and what not. Without seeing actual configuration of your hEX we can only guess endlessly.
by mkx
Fri Sep 10, 2021 3:22 pm
Forum: General
Topic: When is 6.49 going to be released?
Replies: 16
Views: 1233

Re: When is 6.49 going to be released?

Hmmm .. you can't downgrade from 6.49betaX to 6.48.4 without netinstalling device? And you can't get (at least most of) config exported to text file? If answer to both is NO, then I'm surprised. Don't get me wrong, I didn't say that 6.49 is a dead-end, only MT can declare such thing. I was just sayi...
by mkx
Fri Sep 10, 2021 12:10 pm
Forum: General
Topic: SSH Brute force Prevention [SOLVED]
Replies: 2
Views: 480

Re: SSH Brute force Prevention [SOLVED]

I guess most of (advanced) forum users agree that management access to router should be allowed in "allow few, block the rest" manner ... your firewall is in manner "block a few, allow the rest" which opens huge window of opportunity to try to hack it (by using a distributed crow...
by mkx
Fri Sep 10, 2021 11:58 am
Forum: General
Topic: When is 6.49 going to be released?
Replies: 16
Views: 1233

Re: When is 6.49 going to be released?

Your assumptions about thing being in development for certain amount of time becoming stable ... are just assumptions. While things do work like this usually, they don't have to. Dead-ends in development process are not unheard of and I'd completely understand if MT declares 6.49 a dead-end. I guess...
by mkx
Fri Sep 10, 2021 11:48 am
Forum: General
Topic: Do I need to contact support@mikrotik.com directly to get answers about the forum itself? [SOLVED]
Replies: 17
Views: 1492

Re: Do I need to contact support@mikrotik.com directly to get answers about the forum itself? [SOLVED]

Okay, well I can spare them the trouble as I have too much free time. I will only post if I have questions from now on. MKX needs more work to hone his support skills anyway ;-) Mabe we can cut a deal on this: I'll let you to provide support "behind the scenes" so you don't loose your pro...
by mkx
Fri Sep 10, 2021 11:36 am
Forum: General
Topic: Static IP address on every port with lease on demand [SOLVED]
Replies: 5
Views: 679

Re: Static IP address on every port with lease on demand [SOLVED]

It is not possible to do it without lease time because lease time is part of DHCP protocol. But you can get to the point where device plugged to particular port will have predictable IP address. With some cludge: remove all ether ports from bridge configure IP addresses directly on ether interfaces,...
by mkx
Fri Sep 10, 2021 11:22 am
Forum: General
Topic: hAP ac3 IPv6 firewall throughput issue
Replies: 3
Views: 468

Re: hAP ac3 IPv6 firewall throughput issue

... the routers CPU shows 25% use on both IPv4 and IPv6 during a speedtest Since hAP ac3 has a 4-core CPU, CPU load pegged at 25% likely indicates only single core is used. You can verify that by running CPU profiler during speedtesting. Make sure you're running speedtest with multi-thread option e...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 23