Community discussions

MikroTik App

Search found 14414 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 49
by mkx
Fri Jun 13, 2025 3:14 pm
Forum: MikroTik hardware questions
Topic: Chateau LTE6,LTE18, 5Gax End Of Sales soon ?
Replies: 1
Views: 210

Re: Chateau LTE6,LTE18, 5Gax End Of Sales soon ?

The problematic devices are all ARM ac devices, so they are running wifi-qcom-ac driver package. The SquashFS file has size of 2744320 bytes (uncompressed size is around 7.6MB). There are a two firmware directories for different WiFi hardware, one is for IPQ4018/4019 and the other for QCA9984. Uncom...
by mkx
Fri Jun 13, 2025 2:32 pm
Forum: Beginner Basics
Topic: GP & CSA for Mikrotik devices
Replies: 7
Views: 4710

Re: GP & CSA for Mikrotik devices

# 24 : The user usually is not able to follow or understand multiple information in a single post, so either he only considers the first one or the last one ignores all the previous ones. Hmmm, true. The other extreme case is: user comes with a problem, a few random users of forum respond, each wit...
by mkx
Fri Jun 13, 2025 9:00 am
Forum: MikroTik hardware questions
Topic: CRS320-8P-8B-4S+ "controller issue" and "PSU1 removed from the slot"
Replies: 2
Views: 748

Re: CRS320-8P-8B-4S+ "controller issue" and "PSU1 removed from the slot"

There were similar reports ... and it often turned out that the I2C bus got locked by some attached device (mostly it was a not-very-well-supported SFP module with DDM) ... and communication between router's management function and hardware modules was interrupted making management function to panic...
by mkx
Fri Jun 13, 2025 8:48 am
Forum: Wireless Networking
Topic: 5 GHz signal difference issue on hAP AC3
Replies: 9
Views: 1388

Re: 5 GHz signal difference issue on hAP AC3

The temperature reaches 60° Celsius in the hottest days. While both hAP ac3 and wAP ax are specced for operation in environment temperature up to 70°C (so they won't just stop working during your summer heat waves), such a high environment temperature does mean that device ages much faster than nor...
by mkx
Fri Jun 13, 2025 8:20 am
Forum: General
Topic: ether1 flapping and 1 Gbit negotiation fails on LHGG LTE6 with verified cabling
Replies: 9
Views: 580

Re: ether1 flapping and 1 Gbit negotiation fails on LHGG LTE6 with verified cabling

However, the customer already had an electrician check it, and according to his measurements, the cable was deemed to be “in good condition” ... I've seen a good deal of "qualified electricians" doing disastrous UTP cable work ... so I wouldn't take electrician's word as pure gold ... spe...
by mkx
Wed Jun 11, 2025 10:18 pm
Forum: Wireless Networking
Topic: LTE Setup in German jungle [SOLVED]
Replies: 5
Views: 691

Re: LTE Setup in German jungle [SOLVED]

B20, mentioned in your screenshot, is 800MHz band. None of Miktotik's antennas are particularly good at sub-GHz frequencies (to put it mildly). And I imagine there isn't any usable signal in higher frequency bands (B3-1800MHz, B1-2100MHz, B7-2600MHz, etc) or else your ATL would already be using it. ...
by mkx
Wed Jun 11, 2025 2:39 pm
Forum: Wireless Networking
Topic: hAP in station mode fails to connect to CAPsMAN-controlled SSID due to VLAN assignment error
Replies: 3
Views: 577

Re: hAP in station mode fails to connect to CAPsMAN-controlled SSID due to VLAN assignment error

As @holvoetn mentioned (but in mismatched context): wifi-qcom-ac doesn't support working with VLANs ... so it also can't carry over VLAN setting when station does roaming (e.g. FT). In a nutshell: when you have wifi-qcom-ac device in a mix, you can't use any of fancy VLAN features (e.g. setting vid ...
by mkx
Wed Jun 11, 2025 2:11 pm
Forum: MikroTik hardware questions
Topic: CRS112-8P-4S PoE out to passive and af/at simultaneously ?
Replies: 7
Views: 669

Re: CRS112-8P-4S PoE out to passive and af/at simultaneously ?

None of MT PoE devices regulate voltage, all of them work as "voltage in - voltage out". So it's not possible to have mix of PoE clients connected at the same time. Only a few rare MT devices accept two power inputs of different voltage and it is then possible to select which voltage to ap...
by mkx
Wed Jun 11, 2025 1:48 pm
Forum: General
Topic: [6.49.18] DHCP relay don't fowrard NAK response from DHCP server
Replies: 3
Views: 592

Re: [6.49.18] DHCP relay don't fowrard NAK response from DHCP server

If it's indeed bug in DHCP relay, then it's highly unlikely to get it fixed in ROS v6. So what I'd do is to upgrade one of devices (the expendable one) to v7 (7.19.1 at this time) and see if DHCP relay in v7 behaves equally wrong (IIRC there were some entries related to DHCP in change logs ... I did...
by mkx
Wed Jun 11, 2025 8:38 am
Forum: Wireless Networking
Topic: CAPsMAN and CAP on 3x hAP ax2 router.
Replies: 13
Views: 925

Re: CAPsMAN and CAP on 3x hAP ax2 router.

When running new wifi-qcom drivers (as opposed to old wireless drivers), CAPsMAN settings are under /interface/wifi ... e.g. /interface/wifi/capsman . If things are set "according to the book" (i.e. using proper profiles), then settings are shared between CAPsMAN (for provisioning remote C...
by mkx
Wed Jun 11, 2025 8:29 am
Forum: General
Topic: [6.49.18] DHCP relay don't fowrard NAK response from DHCP server
Replies: 3
Views: 592

Re: [6.49.18] DHCP relay don't fowrard NAK response from DHCP server

Which MT device is running DHCP relay? Which ROS version is running on said device? You could verify that DHCP relay is indeed "eating" DHCP NACK responses by running /tool/sniffer (with filters appropriate set) on said MT device ... if everything is fine, you should see DHCP packets at le...
by mkx
Tue Jun 10, 2025 9:30 pm
Forum: Virtualization
Topic: CHR license for Air Gap virtual infrastructure
Replies: 7
Views: 2054

Re: CHR license for Air Gap virtual infrastructure

I need a Mikrotik rock solid documentation

In this case you'll have to ask directly MT via official support channels ... this forum is not one of them.
by mkx
Tue Jun 10, 2025 9:26 pm
Forum: Announcements
Topic: v7.20beta [testing] is released!
Replies: 203
Views: 40042

Re: v7.20beta [testing] is released!

Difference between beta and RC is very small ... RC is beta that developers consider to be almost ready for release. Neither are stable and RC doesn't have to be any better than preceeding betas. Active development still goes on during beta testing, it's just that focus shifts (or at least should IM...
by mkx
Tue Jun 10, 2025 7:56 pm
Forum: Beginner Basics
Topic: winbox, managing TWO mikrotik routers in cascade [SOLVED]
Replies: 6
Views: 915

Re: winbox, managing TWO mikrotik routers in cascade [SOLVED]

I can always see and manage the main router from winbox, but not the second router. It does not even appear on the list. Winbox builds the list of compatible devices using broadcast packets. The problem is that this only works inside same IP subnet (i.e. switched ethernet network). But you have a r...
by mkx
Tue Jun 10, 2025 8:01 am
Forum: Beginner Basics
Topic: Fasttrack breaks streaming service
Replies: 16
Views: 1510

Re: Fasttrack breaks streaming service

So those ports are trunks. You have to decide: either ports ether7, ether17, ether 22 and ether24 are untagged for VLAN 69 ... in which case they should keep PVID settings (customer-vid=0 new-customer-vid=69) but should not be set as tagged ports on egress. Or they are tagged ports for VLAN 69 ... ...
by mkx
Mon Jun 09, 2025 12:02 pm
Forum: General
Topic: echo: system,error,critical could not save configuration changes, not enough storage space available.
Replies: 68
Views: 27725

Re: echo: system,error,critical could not save configuration changes, not enough storage space available.

mAP is MIPSBE ... and routeros packages for architectures anything but ARM/ARM64 are quite a bit smaller. Probably also due to smaller number of supported device models (which may require different drivers). Or perhaps due to smaller executables for those platforms ... I'd expect packages for 64-bit...
by mkx
Mon Jun 09, 2025 11:58 am
Forum: General
Topic: DHCP server settigns, Networks tab
Replies: 18
Views: 1582

Re: DHCP server settigns, Networks tab

This setup was working fine for about 20 years with Windows/ISA and is working fine for 3 years with Mikrotik (albeit with Windows DHCP) - VPN clients receive addresses in the range 172.6.0.31-40, LAN clients receive addresses in the range 172.6.0.1-254 (with the exclusion of 31-40) and can communi...
by mkx
Mon Jun 09, 2025 11:50 am
Forum: General
Topic: Bridge as tagged port in bridge
Replies: 3
Views: 660

Re: Bridge as tagged port in bridge

More generally: bridge port is a CPU-facing port created automatically with every bridge ... and it functions the same way as the rest of bridge ports. It's special because it's created and added implicitly and carries the same name as bridge switch-like entity, again named with same name as the swi...
by mkx
Mon Jun 09, 2025 8:41 am
Forum: General
Topic: Redirecting outgoing connection to an internal server
Replies: 5
Views: 1636

Re: Redirecting outgoing connection to an internal server

Maybe it had nothing to do with the bridges at all and more to do with being on a different subnet? This. If internal server and internal client are not in same IP subnet, then hair-pin NAT is not necessary. Because they have to "talk" via your router anyway and firewall is able to un-do ...
by mkx
Sun Jun 08, 2025 3:40 pm
Forum: Beginner Basics
Topic: 4/5G connection to Wifi long range, on solar
Replies: 12
Views: 1532

Re: 4/5G connection to Wifi long range, on solar

Back in time, when I worked as radio engineer for incumbent MNO, we had very good experience when using yagi or log-periodic "beasts" for the "low-band" wireless broadband. Such as Iskra P-40 MIMO (for a multi-band variant, look at their antennas with model name P56 or higher). T...
by mkx
Sun Jun 08, 2025 2:22 pm
Forum: General
Topic: /32 Subnet
Replies: 14
Views: 1379

Re: /32 Subnet

Nope. It sends traffic appropriate according to network address. /31 does this, /32 does not If you statically add i.e. IP address of 10.0.0.1 with network address of 10.1.1.2 onto an interface, you will not be able to communicate. You will need to manually add a route saying that 10.1.1.2 is on i....
by mkx
Sun Jun 08, 2025 1:05 pm
Forum: General
Topic: /32 Subnet
Replies: 14
Views: 1379

Re: /32 Subnet

/32 sends to 'the interface' its on with no regard for subnet Nope. It sends traffic appropriate according to network address. Which is true also when using "normal" subnet masks, like /24. The big difference is that when using "normal" subnets, the network address is calculated...
by mkx
Sun Jun 08, 2025 12:37 pm
Forum: General
Topic: ICMP Traceroute to VLAN Interface not working correctly
Replies: 4
Views: 929

Re: ICMP Traceroute to VLAN Interface not working correctly

Your device has two switch chips built in ... you're setting port 10 under /interface ethernet switch port ... but you want to check (using print command) that it actually belongs to same switch chip (i.e. is it switch 1 -cpu) as other (ether) ports. Other than that: your router does respond to ICMP...
by mkx
Sat Jun 07, 2025 10:23 am
Forum: General
Topic: High CPU usage on single core (Supermicro Server, ROS 7.18.2) - likely SNAT issue
Replies: 34
Views: 3434

Re: High CPU usage on single core (Supermicro Server, ROS 7.18.2) - likely SNAT issue

If there is a CPU-load-balancing issue with ixgbe that somehow also only gets triggered when paired with connection tracking ...

Just a random idea: could it be triggered (or made much worse) due to fasttracking? Having it active does affect how NIC drivers work ...
by mkx
Sat Jun 07, 2025 10:16 am
Forum: General
Topic: ICMP Traceroute to VLAN Interface not working correctly
Replies: 4
Views: 929

Re: ICMP Traceroute to VLAN Interface not working correctly

Please post your interface configuration (/interface/export) for us to see how exactly did you "inject" VLAN configuration.
by mkx
Fri Jun 06, 2025 1:11 pm
Forum: Announcements
Topic: Newsletter #125
Replies: 117
Views: 21167

Re: Newsletter #125

What like a Lada, yes I know there are starving children in the world as well, ... ... and there are (abundant) number of ICT equipnent vendors who already offer what you're looking for. We can't know what's MT's business decission but so far it seems that they're focusing on "small hatchbacks...
by mkx
Fri Jun 06, 2025 12:33 pm
Forum: Announcements
Topic: Newsletter #125
Replies: 117
Views: 21167

Re: Newsletter #125

Yes most of our 'Home' pc/server stuff is all 2.5Gbps, Most BB services here are moving or beta testing 2GB internet services as well. In most of the world, a small hatchback is a standard car for vast majority of users. In some other areas (or shoukd I put it in singular), a mini van / SUV cross-o...
by mkx
Fri Jun 06, 2025 11:25 am
Forum: Beginner Basics
Topic: 4/5G connection to Wifi long range, on solar
Replies: 12
Views: 1532

Re: 4/5G connection to Wifi long range, on solar

If you find you can do -65dB or better using higher frequencies with the ATL, then they might hold. -65dB is the lowest I would go for LTE if I were connecting into a PTP link. There are two dignal strength quantities in LTE: RSSI (which includes all the signal in the used frequency channel and is ...
by mkx
Fri Jun 06, 2025 10:44 am
Forum: Announcements
Topic: Newsletter #125
Replies: 117
Views: 21167

Re: Newsletter #125

At home I have 1Gbps WAN. I have a small server which serves media (e.g. HD movies coded at 10Mbps average and sound clips coded at up to 300kbps) to one TV and one home cinema. It also works as (low utilization) torrent peer and web server for a few hobby projects. I have s few wired laptops, avera...
by mkx
Thu Jun 05, 2025 7:39 pm
Forum: Beginner Basics
Topic: Ready to start my custom firewall rules journey [SOLVED]
Replies: 43
Views: 3336

Re: Ready to start my custom firewall rules journey [SOLVED]

What is untracked? I know what established and related are but I don't know what untracked traffic is. Packets that are not tracked by connection tracking machinery. ROS supports tracking IPv4 and IPv6, in theory there could be other protocols routed ... but not in practice as ROS doesn't support a...
by mkx
Thu Jun 05, 2025 7:11 pm
Forum: Wireless Networking
Topic: SXTsq5ax not showing channels below 5500
Replies: 8
Views: 1279

Re: SXTsq5ax not showing channels below 5500

The "indoor" per regulations is about trandmitting on certsin frequencies outdoors ... without having building walls as signal attenuators. And wireless station does transmit at same frequency as AP and at same EIRP levels. Can even transmit larger share of time than AP depending on share ...
by mkx
Thu Jun 05, 2025 3:34 pm
Forum: Wireless Networking
Topic: SXTsq5ax not showing channels below 5500
Replies: 8
Views: 1279

Re: SXTsq5ax not showing CPE mode

SXTsq5ax is declared as "outdoor CPE" ... which in MT parlance might mean that it can only use frequencies, marked for outdoor or any use (as opposed to indoor-only use). So do check, what /interface/wifi/radio/reg-info country=<your country> number=0 shows. It might show that lower part o...
by mkx
Thu Jun 05, 2025 3:00 pm
Forum: Wireless Networking
Topic: ros7 wireless hw-Info ? [SOLVED]
Replies: 7
Views: 1485

Re: ros7 wireless hw-Info ? [SOLVED]

Deleting a post here has never worked (for me). I always get a page with Error 505. ¯\_(ツ)_/¯
It did work a few years ago ... IIRC MT upgraded PHPBB and deleting posts doesn't work afterwards.
by mkx
Thu Jun 05, 2025 2:58 pm
Forum: Wireless Networking
Topic: SXTsq5ax not showing channels below 5500
Replies: 8
Views: 1279

Re: SXTsq5ax not showing CPE mode

Check which frequencies are used by hAP ac and compare it to the list of frequenices allowed on SXT for your particular country setting. Not every device supports the same set of frequencies and not in every country. Just checked on my AX device (wAP ax) - controlled by capsman but never the less - ...
by mkx
Thu Jun 05, 2025 2:13 pm
Forum: Beginner Basics
Topic: No Internet Access After Setting Up NAT on hAP ac²
Replies: 2
Views: 778

Re: No Internet Access After Setting Up NAT on hAP ac²

I'm new to MikroTik and still learning how to use RouterOS. I just got a hAP ac² and followed a few tutorials to set up NAT and basic firewall rules, but now none of the connected devices can access the internet. [snip] Can anyone suggest what I might have missed? I'd really appreciate your help! A...
by mkx
Thu Jun 05, 2025 8:24 am
Forum: Wireless Networking
Topic: SXTsq5ax not showing channels below 5500
Replies: 8
Views: 1279

Re: SXTsq5ax not showing CPE mode

QuickSet is pretty incomplete in ROS v7 with regards to configuration profiles. So unfortunately, you're on your own here.
by mkx
Wed Jun 04, 2025 8:26 pm
Forum: MikroTik hardware questions
Topic: RB2011UAS_RM SFP module compatibility
Replies: 4
Views: 938

Re: RB2011UAS_RM SFP module compatibility

Check versions of both RouterOS (system->packages) and RouterBoot (system->routerboard) ... I'm willing to bet they are not the same on both devices ... and the one which works with module has newer versions installed. "nearly the same" doesn't count.
by mkx
Wed Jun 04, 2025 5:42 pm
Forum: Announcements
Topic: v7.20beta [testing] is released!
Replies: 203
Views: 40042

Re: v7.20beta [testing] is released!

This is probably the only thing I find irksome with the 1mbit limit ....

If it irks you that much, then scratch yourself (with a $45 license). It's not fair to expect that MT will scratch you.
by mkx
Wed Jun 04, 2025 3:54 pm
Forum: General
Topic: Routing + transparent Vlan
Replies: 8
Views: 1177

Re: Routing + transparent Vlan

... VLAN1000 (or any other number) untagged. Regarding "any other number": range for VLAN number is 0-4095 (a 12-bit unsigned integer). However, to avoid problems, usable range is from 2 to 4094 (both included). Syntactically it is correct also to use 1 but since it's used in default conf...
by mkx
Wed Jun 04, 2025 3:45 pm
Forum: General
Topic: Cluster of errors: does this point to HW failure? [SOLVED]
Replies: 6
Views: 1541

Re: Cluster of errors: does this point to HW failure? [SOLVED]

Also do monitor disk usage on those 16MB flash devices. If free space drops below 100kB (or something like that, depends on complexity of configuration), then there's danger of getting device into a no-change state (because running config can no longer be written to flash before the old one gets era...
by mkx
Wed Jun 04, 2025 3:37 pm
Forum: Beginner Basics
Topic: HDMI over IP/ Switch configs? [SOLVED]
Replies: 16
Views: 2156

Re: HDMI over IP/ Switch configs? [SOLVED]

I am not sure to understand how the NVR buzzer works (how it can be heard from the kitchen), is it *somehow* extended to the kitchen (or the sound has to go through the Cat5/6 link and goes to the monitor speaker)? The "IP KVM"s I'm familiar with can transport over ethernet the following:...
by mkx
Wed Jun 04, 2025 3:24 pm
Forum: Beginner Basics
Topic: How many VLANs are should you create?
Replies: 7
Views: 1262

Re: How many VLANs are should you create?

You really have to think about it yourself. You can go overboard and assign one VLAN per device. If you don't limit connectivity between VLANs using firewall inside router, then all devices will be able to communicate with all others ... unless some on-device firewall blocks it because it sees commu...
by mkx
Wed Jun 04, 2025 7:22 am
Forum: General
Topic: Idea toward MikroTik licensing for development
Replies: 23
Views: 2360

Re: Idea toward MikroTik licensing for development

Funny how you mention "Software without subscriptions". But yet, MikroTik sells Level4-6 licenses, along with CHR licenses.. I'm not native English speaker, so it may be my poor understanding ... but isn't purchase (one-time payment ... in MT case with life-time support) a bit different t...
by mkx
Tue Jun 03, 2025 5:10 pm
Forum: Wireless Networking
Topic: Capsman V2 Wifi no tx-power, only max-Tx-power ? [SOLVED]
Replies: 13
Views: 1658

Re: Capsman V2 Wifi no tx-power, only max-Tx-power ? [SOLVED]

... but we've moved on from my original question ... ... because the answer was given (Tx power depends on actual Tx frequency used so you'll have to manage frequencies manually to optimize coverage). But some of us, forum members, are close to chatterboxes so we tend to continue with discussion ev...
by mkx
Tue Jun 03, 2025 2:45 pm
Forum: Beginner Basics
Topic: is it me, or is it the wAP ax?
Replies: 47
Views: 3862

Re: is it me, or is it the wAP ax?

Cellular (GSM/LTE/5G) people get away with such things because their radios are synchronized to one another - either they are in the same device/chassis or they use a precision GPS clock. And up until 5G (even in LTE) these systems used FDD - Frequency Division Duplex ... with duplex gab large enou...
by mkx
Tue Jun 03, 2025 2:36 pm
Forum: General
Topic: Issue: WebFig Graphs stop loading after ~1 month uptime
Replies: 3
Views: 933

Re: Issue: WebFig Graphs stop loading after ~1 month uptime

I’m using a CCR1072 with RouterOS v6.49.10 (long-term), and I’ve been consistently running into this issue: It could be device-speciffic issue (i.e. tied to CCR1xxx family of devices). Other than that, I'm running a few devices with ROS 6.49.18 (latest long-term), all with uptimes beyond 31 days .....
by mkx
Mon Jun 02, 2025 10:04 pm
Forum: General
Topic: Cluster of errors: does this point to HW failure? [SOLVED]
Replies: 6
Views: 1541

Re: Cluster of errors: does this point to HW failure? [SOLVED]

LHGG LTE6 kit is s device with 16MB storage ... and thus prone to starvation and random problems. The likelyhood of happening it is increasing with rising version number as ROS gets some belly fat with each release.
by mkx
Mon Jun 02, 2025 9:53 pm
Forum: Beginner Basics
Topic: What is the default IP pool? [SOLVED]
Replies: 7
Views: 5102

Re: What is the default IP pool? [SOLVED]

/ip pool add name=default-dhcp ranges=192.168.88.10-192.168.88.254 this? Yes, but I don't think that that is the default because that's what I changed it to. No, this is default. BTW, you can always check default config of your device and running ROS version by executing command /system/default-con...
by mkx
Mon Jun 02, 2025 3:55 pm
Forum: Wireless Networking
Topic: Mikrotik ax3 Wifi
Replies: 10
Views: 2314

Re: Mikrotik ax3 Wifi

... like a wise man once said: "More gain usually means more interference. For consumer wifi the thing that limits wifi performance is never a lack of transmission power." That "wise man" obviously didn't know/think about country limitations ... which are expressed as EIRP ... a...
by mkx
Mon Jun 02, 2025 6:27 am
Forum: General
Topic: wAP coverage -- picture included
Replies: 51
Views: 7807

Re: wAP coverage -- picture included

Country regulations - EIRP limitations - won't allow a device with directional radiation pattern to provide higher signal level than a (high Tx power) omnidirectional one - in the rirection of highest antenna gain. However, directional device will support higher uplink speeds because station Tx powe...
by mkx
Sun Jun 01, 2025 7:56 pm
Forum: General
Topic: wAP coverage -- picture included
Replies: 51
Views: 7807

Re: wAP coverage -- picture included

I agree that MT's marketing and quick reference documents could be much better. Like not resorting to "poetic" descriptions when technical data doesn't agree ("access point that looks beautiful on both walls and ceilings" versus antenna radiation patterns). And like publishing al...
by mkx
Sun Jun 01, 2025 4:46 pm
Forum: General
Topic: wAP coverage -- picture included
Replies: 51
Views: 7807

Re: wAP coverage -- picture included

Grok and ChatGPT disagree. They say "wAP" means wireless access point. I suspect Grok & ChatGPT are wrong as all access points are wireless. When an esteemed member of MT support team says something and LLMs disagree ... then in my mind there's no doubt who to trust ... And your wordi...
by mkx
Sun Jun 01, 2025 1:38 pm
Forum: Beginner Basics
Topic: Client Don't Have Internet Access on E50UG [SOLVED]
Replies: 3
Views: 1308

Re: Client Don't Have Internet Access on E50UG [SOLVED]

I figured NAT rule might work on port level but now I've learned it got to be done on interface level. Considering that NAT is L3 operation (works on IP addresses and optionally on TCP/UDP ports) it's got to be on interface level (the router/firewall property which carries IP address). You can have...
by mkx
Sat May 31, 2025 10:54 pm
Forum: Beginner Basics
Topic: is it me, or is it the wAP ax?
Replies: 47
Views: 3862

Re: is it me, or is it the wAP ax?

As for the higher frequencies on 5Ghz, any posted range to stick to, in your experience? Stick to U-NII-1 and U-NII-2 ... so up to and including channel 136 for 20MHz channels, 132 for 40MHz channels and 116 for 80MHz channels (that's center frequencies 5680, 5660 and 5580 MHz respectively). Lower ...
by mkx
Sat May 31, 2025 10:32 am
Forum: General
Topic: Hex-S trunk port works, access ports do not.
Replies: 8
Views: 1509

Re: Hex-S trunk port works, access ports do not.

Adding to post by @itimo01 above: the other thing is the bug about handling VLANs between switch chip and CPU, addressed by 7.20beta: *) bridge - added dynamic tagged entry named “switch-cpu” in scenarios where the same VLAN spans multiple switch chips or is used on both HW and SW ports; Doesn't men...
by mkx
Fri May 30, 2025 1:47 pm
Forum: Announcements
Topic: v7.19.1 [stable] is released!
Replies: 410
Views: 79922

Re: v7.19.1 [stable] is released!

I had to downgrade to RouterOS v 7.18.2 from 7.19.x
I certainly hope you did save supout.rif file while device was running 7.19.1 and you opened trouble ticket with MT support.
by mkx
Fri May 30, 2025 1:45 pm
Forum: Announcements
Topic: Newsletter #125
Replies: 117
Views: 21167

Re: Newsletter #125

Does this help ? https://tiktube.com/w/gwMqv7r2AwB3zLAoeWP7FT It only talks about the new connectivity app. No explanation on how to use another ISP besides Mikrotik . Mikrotik is not ISP, it's equipment vendor. When using device with eSIM, it has to be provisioned even with the first MNO to whose ...
by mkx
Thu May 29, 2025 11:55 pm
Forum: General
Topic: Disabled DNAT Rule Still Passing Traffic
Replies: 4
Views: 807

Re: Disabled DNAT Rule Still Passing Traffic

When fasttrack is active for certain connection, then most of packets belonging to that connection won't be processed by normal firewall rules, instead they will be handled by special (fasttrack) functions. Which means that changing rules won't affect the connection. You have to remove "infring...
by mkx
Thu May 29, 2025 3:40 pm
Forum: MikroTik hardware questions
Topic: Running out of space on hAP ac2 [SOLVED]
Replies: 97
Views: 58116

Re: Running out of space on hAP ac2 [SOLVED]

(my hAP ac2 with wireless and working only as an access point now has about 850kB free) If one wants to squeeze a bit more life out of hAP ac2, then IMO it's better to use it without any wireless/wifi drivers ... i.e. as wired-only router. It performs marvelously, much better than hEX refresh (or L...
by mkx
Thu May 29, 2025 3:28 pm
Forum: General
Topic: [Feature Request]: 'run-after-reboot'
Replies: 8
Views: 1523

Re: [Feature Request]: 'run-after-reboot'

Except for "run this only after next restart", wouldn't scheduler entry with "start-time=startup" and without setting "interval" do the trick? The problem with running commands "as quickly as possible" can be that hardware might not be fully initialized at the...
by mkx
Thu May 29, 2025 2:29 pm
Forum: Wireless Networking
Topic: 5 GHz signal difference issue on hAP AC3
Replies: 9
Views: 1388

Re: 5 GHz signal difference issue on hAP AC3

The phones and the laptops in the room (less than 3-5 m from the router) see the 5 GHz network at very good signal levels: -45 to -55, but when they connect, the registration table shows their signals at much worse level, -78 to -88 Registration table shows signal levels, measured by AP on client's...
by mkx
Thu May 29, 2025 2:22 pm
Forum: General
Topic: CCR2004-1G-12S+2XS [SOLVED]
Replies: 1
Views: 1210

Re: CCR2004-1G-12S+2XS [SOLVED]

The list of packages now shows all packages available for device's architecture. Your router is ARM and there are plethora of different ARM devices. For example: there's wifi-qcom package available, your router does not have required hardware (AX-generation of wifi cards) ... but it's listed. And yo...
by mkx
Thu May 29, 2025 2:16 pm
Forum: Beginner Basics
Topic: Hex E50UG
Replies: 103
Views: 8776

Re: Hex E50UG

If NIC buffer is problem, needs queues and flow-control or whatever, then how do you explain mirolm’s report of “it works fine for me”? He did not indicate he had to do anything at all special… When it comes to buffers timing is pretty important. In certain cases timing of the link partner might be...
by mkx
Thu May 29, 2025 2:13 pm
Forum: Beginner Basics
Topic: Hex E50UG
Replies: 103
Views: 8776

Re: Hex E50UG

One could conclude that MT does not conduct UPLOAD tests at all when producing throughput tests on their charts. I say this because one might assume they use ether1 for testing and this issue would have been discovered long ago, prior to distribution. Or it could be that they only look at cumulativ...
by mkx
Thu May 29, 2025 2:02 pm
Forum: Beginner Basics
Topic: Question about CRS326-24g [SOLVED]
Replies: 11
Views: 1971

Re: Question about CRS326-24g [SOLVED]

The answer is similar to the question "I have my Windows fully configured. Will I loose my configuration if I switch to Linux?". Yes, settings won't be carried over to the other OS. With some luck ROS settings will remain intact while running SwOS and if you decide to revert back to ROS, y...
by mkx
Wed May 28, 2025 7:23 pm
Forum: General
Topic: Wi‑Fi 7 / 802.11be
Replies: 133
Views: 58499

Re: Wi‑Fi 7 / 802.11be

If you use FO network provider's ONT which offers a 10Gbps RJ45 port, then you need one on your edge device (router, switch) as well. Whether it's provided as built-in ethernet port or by using RJ45 SFP+ module doesn't really matter from functionality point of view. But, as you wrote yourself, SFP+ ...
by mkx
Wed May 28, 2025 7:09 pm
Forum: General
Topic: Please work on power consumption of CRS310-8G+-2S+-IN
Replies: 2
Views: 1283

Re: Please work on power consumption of CRS310-8G+-2S+-IN

Product page says that max power consumption without attachments (e.g. without SFP+ modules inserted) can be up to 21W. So what you see is definitely inside expected values. I highly doubt that any (noteworthy) power consumption reduction is possible by changes in software. I checked a random Taiwa...
by mkx
Tue May 27, 2025 10:46 am
Forum: General
Topic: Wi‑Fi 7 / 802.11be
Replies: 133
Views: 58499

Re: Wi‑Fi 7 / 802.11be

My personal opinion is that whatever ONT is provided by FO infrastructure owner should be good enough for the service you're subscribed to. And having provider's ONT in place you can argue with provider if the service is not adequate (by temporarily connecting an unrelated equipment for troubleshoot...
by mkx
Mon May 26, 2025 10:46 pm
Forum: General
Topic: Wi‑Fi 7 / 802.11be
Replies: 133
Views: 58499

Re: Wi‑Fi 7 / 802.11be

AFAIK none of current Mikrotik devices come with fiber ports built-in ... the plethora of devices, which eventually support FO, require installation of appropriate SFP/SFP+ module. Vast majority of single-mode SFP modules are intended to be used with blue optical connectors. And as I mentioned, find...
by mkx
Sun May 25, 2025 1:25 pm
Forum: General
Topic: blue led of CSS610-8G
Replies: 10
Views: 1717

Re: blue led of CSS610-8G

A change to Router OS isn't possible? There was no answer to this question yet... No, on C S S devices SwOS is the only option. Main difference between C R S devices and C S S is that the later lack general-purpose CPU (and storage and RAM), capable of running a more complex OS (while L2 capabiliti...
by mkx
Sun May 25, 2025 1:20 pm
Forum: General
Topic: Wi‑Fi 7 / 802.11be
Replies: 133
Views: 58499

Re: Wi‑Fi 7 / 802.11be

I have a question about the SFP+ port. My provider uses GPON technology to connect a fiber optic cable with a SC/APC (green) connector, hence on the router for direct connection to avoid intermediate equipment (media converter) there must be a corresponding port, also marked green with SC/APC. What...
by mkx
Sun May 25, 2025 1:04 pm
Forum: General
Topic: Question about Mixed MTUs
Replies: 4
Views: 1382

Re: Question about Mixed MTUs

Changing L3 MTU on internet links is particularly tricky ... because 1500 bytes is a global de-facto standard. If you use large MTU on your link but next hop link (or even server your client is connecting) uses standard MTU, then somebody will either have to fragment packets (which most of times mea...
by mkx
Sat May 24, 2025 11:32 pm
Forum: General
Topic: hap ax3
Replies: 18
Views: 5715

Re: hap ax3

If radios get damnaged due to antennas not being attached, then the dammage would be on analog side of wifi chip, in particular to the RF power amplifier. And I don't think that low-cost devices include supervision of that part (it'd require measuring Tx power using a dedicated un-corelated circuitr...
by mkx
Sat May 24, 2025 11:16 pm
Forum: General
Topic: Question about Mixed MTUs
Replies: 4
Views: 1382

Re: Question about Mixed MTUs

L3 MTU (as in: IP MTU) has to be the same for every single device in same IP subnet ... in your case that includes ISP's router handling that /21 address space. Which likely means that you'll have to conform to whatever your ISP is using (and my bet would be on 1500 bytes + VLAN overhead). BTW, L3 M...
by mkx
Wed May 21, 2025 3:44 pm
Forum: General
Topic: Best VLAN Design for 2000+ PPPoE Users
Replies: 8
Views: 1723

Re: Best VLAN Design for 2000+ PPPoE Users

If you decided to use VLANs, then use one VLAN per PPPoE user. You can use 4094 VLANs. I wouldn't configure that many PPPoE servers on a single device though. Max sustainable number depends on particular device type and max rate per user, probably a few hundred users per (powerful) device is reallis...
by mkx
Fri May 16, 2025 2:30 pm
Forum: General
Topic: Repeatedly adding IPv6 default routing entries
Replies: 6
Views: 1370

Re: Repeatedly adding IPv6 default routing entries

Use DHCPv6 to obtain a delegated prefix only. Some ISPs require the WAN address to also be obtained with DHCPv6, rather than SLAAC, on IPoE connections. ... and in such case configure DHCPv6 client to require both prefix and address in a single handshake (set request=prefix,address on DHCPv6 client...
by mkx
Thu May 15, 2025 11:00 pm
Forum: General
Topic: How to upgrade routerOS from command line (ssh) and local routeros-7.18.2-arm64.npk file?
Replies: 11
Views: 3275

Re: How to upgrade routerOS from command line (ssh) and local routeros-7.18.2-arm64.npk file?

Also: when uploading upgrade packages (NPKs) manually, it's your responsibility to upload all the required packages. For many devices, uploading single file (named e.g. routeros-7.18.2-arm.npk) is enough, some require additional packages (such as wifi driver pack). Those package files are distribute...
by mkx
Thu May 15, 2025 10:53 pm
Forum: General
Topic: PoE Switch recommendation
Replies: 11
Views: 1897

Re: PoE Switch recommendation

Product page for NetPower 16p says: Device itself does not have an onboard voltage converter. You need 24V PSU to have 24V PoE out and/or 48V PSU to have 48V PoE out (IEEE 802.3 at/af). * Power supply is NOT included with the product. You are welcome to use your preferred power option, like battery...
by mkx
Thu May 15, 2025 10:50 pm
Forum: General
Topic: ISP CCR2216 L3HW-Offloading Issues
Replies: 63
Views: 11468

Re: ISP CCR2216 L3HW-Offloading Issues

It seems that basically you can either do L3HW routing or L3HW fasttracking ... but not both. And the reason is as already hinted by @chechito: when L3HW engine takes care of a packet, it's no longer seen by CPU. But CPU has to see packets in order to correctly perform connection tracking, which is ...
by mkx
Thu May 15, 2025 10:40 pm
Forum: General
Topic: VLANs between CCR and CRS328
Replies: 3
Views: 1161

Re: VLANs between CCR and CRS328

The problem is that I want to declare VLAN ID 80 on ports 3 and 4 of the CRS328 so that those ports function as access mode for the segment range corresponding to VLAN 80. So far, I haven't been able to get it working. Did you check this tutorial? https://forum.mikrotik.com/viewtopic.php?t=143620 Y...
by mkx
Thu May 15, 2025 8:01 pm
Forum: Wireless Networking
Topic: ltAP with EM12-G slow LTE
Replies: 2
Views: 1119

Re: ltAP with EM12-G slow LTE

Start off by explaining what is your definition of "slow LTE". Also check what kind of connection has LTE card with LTE network: RSRP, RSRQ, SINR, band, band width, etc. Also try to test during small hours, public wireless networks can be pretty congested at times and statistics is saying ...
by mkx
Thu May 15, 2025 7:54 pm
Forum: General
Topic: PoE Switch recommendation
Replies: 11
Views: 1897

Re: PoE Switch recommendation

Does this apply to both the CRS318-16P-2S+OUT as well as the crs328_24p_4s_rm? The former is half the price of the latter. It does apply to both. But for netpower you need to purchase two power adapters (with MSRP of $18 each making price difference a bit less) and the rest of hassles mentioned. An...
by mkx
Thu May 15, 2025 7:43 pm
Forum: Beginner Basics
Topic: Devices are not able to connect to wifi
Replies: 3
Views: 1475

Re: Devices are not able to connect to wifi

Error 2 is not yet completely fixed. Issue is that although SSID has multiple security methods assigned (wpa2, wpa3) fallback to wpa2 if devices dont support wpa3 doenst work reliable. That's not the problem with AP, it's a problem with client device. AP broadcasts capability values and it's up to ...
by mkx
Thu May 15, 2025 6:37 pm
Forum: General
Topic: L3-HW vs IPv6 Fasttrack [SOLVED]
Replies: 1
Views: 1281

Re: L3-HW vs IPv6 Fasttrack [SOLVED]

L3HW fasttrack can only make a difference on devices running firewall. If you use your CCR as "plain" router, "simple" L3HW should be enough.
by mkx
Thu May 15, 2025 6:31 pm
Forum: Wireless Networking
Topic: WiFi Capsman and VLAN
Replies: 1
Views: 1010

Re: WiFi Capsman and VLAN

Which device model is used as CAp? There are 3 different possibilities, each requires slightly differen VLAN setup.

Also post config of capsman section of CAPsMAN device and full config of a CAP device.
by mkx
Thu May 15, 2025 6:25 pm
Forum: General
Topic: PoE Switch recommendation
Replies: 11
Views: 1897

Re: PoE Switch recommendation

I guess that at least part of price premium can be explained/excused by dual PoE-out nature: each port can either act as 802.3 af/at PoE port or as passive PoE port (at 26V), it's software-selectable. So ideal if one has to power a mix of MT devices and standard 802.3 af/at devices. All of that by u...
by mkx
Wed May 14, 2025 11:35 am
Forum: Beginner Basics
Topic: VLANs on WAN [SOLVED]
Replies: 6
Views: 1984

Re: VLANs on WAN [SOLVED]

Hm, but looking at OP's config export, they have a hEX refresh (E50UG), which means with ether1 being the WAN port, putting it in the bridge will still result in everything involving that port using the CPU (no HW offload), including VLAN filtering and bridging. Yes, it will use CPU. But when addin...
by mkx
Wed May 14, 2025 8:57 am
Forum: Beginner Basics
Topic: VLANs on WAN [SOLVED]
Replies: 6
Views: 1984

Re: VLANs on WAN [SOLVED]

why configure the vlan using bridge filtering whilst this kind of device the vlan should be config in switch menu? or the vlan tagged interface could also attach directly to ether1, i'm just curious thanks! Whether to use switch menu or bridge mostly depends on device model. Some older devices (tho...
by mkx
Tue May 13, 2025 6:32 pm
Forum: General
Topic: Impossible to get more than 5.5GBit on a switch to switch link. Tx Drops. [SOLVED]
Replies: 42
Views: 5246

Re: Impossible to get more than 5.5GBit on a switch to switch link. Tx Drops. [SOLVED]

What's the length of Cat6 cable connecting both switches?
by mkx
Tue May 13, 2025 6:25 pm
Forum: General
Topic: Upgrading Memory and Routing Table Limit
Replies: 3
Views: 1163

Re: Upgrading Memory and Routing Table Limit

Additionally: L3HW offloaded routing (and fasttracking) is bound to on-chip memory (and not to on-board RAM) which can't be changed. And the routing table limits are thus hard limits. If L3HW offload can't deal with all the different routes, CPU has to perform routing for those excess destinations ....
by mkx
Tue May 13, 2025 6:13 pm
Forum: General
Topic: RB760iGS new CAPSMAN
Replies: 20
Views: 2616

Re: RB760iGS new CAPSMAN

Also beware that wAP ax does not provide omni-directional wifi coverage, front-to-back ratio is around 20dB and main lobe beam width is around 60°. Which makes wAP ax ideal for placing in a corner of a square room or on the short wall of rectangular room. Or, if placed inside a house/flat, off-cente...
by mkx
Tue May 13, 2025 8:39 am
Forum: Wireless Networking
Topic: Problem with Ros7 WiFi Capsman
Replies: 16
Views: 2227

Re: Problem with Ros7 WiFi Capsman

When using CAPsMAN to provision a CAP, also virtual APs have to be set-up via CAPsMAN. No local configuration of wireless should be necessary (except perhaps VLANs on wifi-qcom -ac -driven devices). By default, virtual APs are made members of same bridge as master interface. If you want to separate ...
by mkx
Tue May 13, 2025 8:37 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 641
Views: 299820

Re: v7.18.2 [stable] is released!

1. May i know how to get into /system/device-mode/ to adjust the CPU frequency, please? It seems to me that it's a CLI-only setting. I can't find it neither in WebFig (7.18.2) nor in legacy WinBox (3.41). And the new WinBox (4.0beta20) doesn't work for me, Linux version insists on having GL extensi...
by mkx
Mon May 12, 2025 2:56 pm
Forum: General
Topic: What os / browser / version do you use for this forum ?
Replies: 11
Views: 2055

Re: What os / browser / version do you use for this forum ?

Short version: this isn't about the client software but the poor decisions that your network administrator did in managing a dual wan setup. Why would that be ? If other sites do work correctly this one not, than i guess problem is here or not ? As you confirmed yourself, using same OS/browser/vers...
by mkx
Mon May 12, 2025 9:27 am
Forum: General
Topic: RB760iGS new CAPSMAN
Replies: 20
Views: 2616

Re: RB760iGS new CAPSMAN

None of pictures from previous post are visible to me.
by mkx
Mon May 12, 2025 9:25 am
Forum: General
Topic: RSTP Root bridge calculation
Replies: 5
Views: 1889

Re: RSTP Root bridge calculation

I have in the back of may mind (but can't find a reference to it) that ultimate bridge priority gets defined by merging the following fields: <VLAN ID> <STP priority> <bridge MAC address> When everybody is in the same VLAN, the deciding factor is STP priority ... if additionally everybody has same S...
by mkx
Sun May 11, 2025 12:02 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 641
Views: 299820

Re: v7.18.2 [stable] is released!

I don't think upgrade of backup routerboot (factory firmware) has anything to do with available flash space.. nope, it definitely does ..take a second look at my picture Not sure what your picture is saying. What I do know is that not all devices are supported gor upgrading factory firmware (my Aud...
by mkx
Sun May 11, 2025 11:52 am
Forum: Wireless Networking
Topic: SXTLTE6 Kit POE powering question...
Replies: 1
Views: 1110

Re: SXTLTE6 Kit POE powering question...

Product page of SXT LTE6 kit does indicate that unit is capable of PoE daisy-chaining with max PoE out up to 19W (0.4A PoE-out limit when powered with 30V+ PoE-in ... when powered with 48V calculation yields those 19W). It's explicitly stating "max power consumption 21W, max power consumption ...
by mkx
Sun May 11, 2025 11:30 am
Forum: General
Topic: GPERx4 vs mAntbox?!
Replies: 1
Views: 1093

Re: GPERx4 vs mAntbox?!

None of MT PoE gear will guess/regulate voltage ... it's "what comes in, goes out". Now: specs on product page are often incomplete (if not misleading) to people not familiar with PoE gotchas. Because PoE is not one single thing (standard 802.3 af/at/bt), there are many. All MT gear so far...
by mkx
Sun May 11, 2025 11:05 am
Forum: General
Topic: Inbound Proxy?
Replies: 5
Views: 2303

Re: Inbound Proxy?

Hello, sorry for bumping this. Have you managed to do it OP?
Reply in post #2 is still true.
by mkx
Sun May 11, 2025 11:01 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 641
Views: 299820

Re: v7.18.2 [stable] is released!

..[CUT].. Remember when something goes wrong during the upgrade, your device is bricked. And do not bother trying to upgrade 16MB flash devices .. I don't think upgrade of backup routerboot (factory firmware) has anything to do with available flash space ... one uploads the package to device (in ca...
by mkx
Sat May 10, 2025 2:54 pm
Forum: MikroTik hardware questions
Topic: Netinstall on RM3011 Fails need help (technical questions)
Replies: 95
Views: 14156

Re: Netinstall on RM3011 Fails need help (technical questions)

Yeah, that does look worth a try.
Did you? What were results?
by mkx
Sat May 10, 2025 10:09 am
Forum: General
Topic: RB760iGS new CAPSMAN
Replies: 20
Views: 2616

Re: RB760iGS new CAPSMAN

Every ROS device running v7.13 or higher has "new" CAPsMAN available in core ROS package. What device are you using as CAPsMAN client? Generations of CAPsMAN sever and client have to match (the new CSPsMAN works only with clients running wifi-qcom* drivers and likewise the old CAPsMAN only...
by mkx
Fri May 09, 2025 10:09 pm
Forum: General
Topic: Rollback to old web GUI
Replies: 5
Views: 1547

Re: Rollback to old web GUI

That mini rant brings me to a question: how can I roll back to the previous, legacy web GUI? You don't get to choose web GIU style, there's only one shipped with ROS version. So if you want legacy web GUI, then you have to downgrade ROS to version with legacy web GUI (could be somewhere around 7.16...
by mkx
Fri May 09, 2025 9:54 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 641
Views: 299820

Re: v7.18.2 [stable] is released!

Note that the procedure to update the backup bootloader at https://help.mikrotik.com/docs/spaces/ROS/pages/40992878/RouterBOARD#RouterBOARD-Protectedbootloader has now been updated to support version 7.18.2 Doc says it's universal ... but doesn't seem to be that universal ... it fails on my Audienc...
by mkx
Fri May 09, 2025 6:36 pm
Forum: Beginner Basics
Topic: Multiple DNS servers
Replies: 6
Views: 1675

Re: Multiple DNS servers

Since you're running "real" DNS server on a dedicated device in your LAN, you may as well use same device to run DHCP server ... and set it to update DNS records for DHCP hosts. This way you'll skip using one mediocre ROS service (DHCP server is not bad but it's not great either) and one b...
by mkx
Fri May 09, 2025 11:31 am
Forum: General
Topic: RSTP Root bridge calculation
Replies: 5
Views: 1889

Re: RSTP Root bridge calculation

Does your setup involve VLANs? VLANs can screw bridge priorities ... if not configured properly.
by mkx
Fri May 09, 2025 11:20 am
Forum: General
Topic: Assistance with CGNAT, L3HW Offloading on CCR2216
Replies: 9
Views: 1767

Re: Assistance with CGNAT, L3HW Offloading on CCR2216

connection tracking table full Fasttrack HW table utilization 100% The connection tracking table doesn't depend solely on number of "CGNAT users" but also on activity of those users (total connection tracking table length is sum of all connections of all users). And yes, HW table is typic...
by mkx
Thu May 08, 2025 6:44 pm
Forum: MikroTik hardware questions
Topic: CRS520-4XS-16XQ-RM and Higher power optics
Replies: 2
Views: 1370

Re: CRS520-4XS-16XQ-RM and Higher power optics

I suggest you to contact MT support directly. Either through web page https://mikrotik.com/support or via e-mail support@mikrotik.com (this forum is not official means of support, it's more like an AAA group of MT users). If you get any useful snswer, pkease rrmember to come back and post it ... for...
by mkx
Thu May 08, 2025 6:34 pm
Forum: General
Topic: New CCR2004-1G-12S+2XS, management/ether1 question
Replies: 3
Views: 1231

Re: New CCR2004-1G-12S+2XS, management/ether1 question

Ether1/mgmt port on this router is connected directly to CPU with a dedicated 1Gbps link. SFP+/SFP28 ports are handled through PIPE (some sort of port extender), sharing 2x25Gbps bandwidth. As shown by block diagram: https://cdn.mikrotik.com/web-assets/product_files/CCR2004-1G-12Splus2XS_200459.png ...
by mkx
Thu May 08, 2025 6:23 pm
Forum: General
Topic: DHCP - how to set primary DNS
Replies: 4
Views: 1460

Re: DHCP - how to set primary DNS

A bit of DNS theory: DNS doesn't know concept of "primary" or "secondary" server, in principle all are equal. Setting DNS server addresses in DHCP server config might make DHCP server to place those DNS addresses in a particular order inside DHCP lease metadata, but DHCP client c...
by mkx
Thu May 08, 2025 9:00 am
Forum: Wireless Networking
Topic: 'ax hardware 'speed limit'
Replies: 51
Views: 7373

Re: 'ax hardware 'speed limit'

I can get 470Mbps on 40Mhz. However, if I bump that up to 80 Mhz I get slightly less. What are signal strengths reported by both sides? Beware that doubling the bandwidth (from 40MHz to 80MHz) will decrease signal strength by 3dB. And if signal strengths are not great (read: above -60dBm or so). th...
by mkx
Thu May 08, 2025 8:25 am
Forum: Beginner Basics
Topic: Apparent traffic leak from access ports
Replies: 6
Views: 1763

Re: Apparent traffic leak from access ports

I have each switch configured with one bridge that carries all VLANs (1-4094). At the bridge level, VLAN Filtering and Ingress filtering is enabled, and Frame Types is set to "admit only tagged" [snip] The only access port is my PC, and the access port is set to PVID 1337 (since it's VLAN...
by mkx
Wed May 07, 2025 11:00 am
Forum: MikroTik hardware questions
Topic: RB951Ui-2HnD replacement - hEX refresh?
Replies: 3
Views: 1414

Re: RB951Ui-2HnD replacement - hEX refresh?

ether1 is not connected to switch chip, it's rather connected to CPU directly. Which means it behaves differently than the rest of ports. When device is used in router mode it's practically required to use ether1 as WAN interface. And it has some quirks when it comes to congestion handling (one dire...
by mkx
Wed May 07, 2025 9:15 am
Forum: Wireless Networking
Topic: Wireless disconnection messages explained!
Replies: 99
Views: 222053

Re: Wireless disconnection messages explained!

The off-shore "omni directional" device might experience lots of interference. And if that device is running in AP mode (you didn't specify this aspect) it might refuse to select any of channels due to that. If this is indeed the case, then you may get it work better if the on-shore device...
by mkx
Wed May 07, 2025 9:11 am
Forum: MikroTik hardware questions
Topic: Netinstall on RM3011 Fails need help (technical questions)
Replies: 95
Views: 14156

Re: Netinstall on RM3011 Fails need help (technical questions)

The download file would likely work fine on your RB3011 ... but if insisting on using netinstall version which matches wanted ROS version it would limit you to ROS v6.48.6 (which is not even latest v6 long-term). If you'd use that version of netinstall to install any other ROS version, then you're b...
by mkx
Wed May 07, 2025 9:07 am
Forum: MikroTik hardware questions
Topic: RB951Ui-2HnD replacement - hEX refresh?
Replies: 3
Views: 1414

Re: RB951Ui-2HnD replacement - hEX refresh?

Hi, I've currently got a RB951Ui-2HnD that I'm running as a router for my home network (with wireless turned off - just running a single Unifi AP currently). It's running DHCP and DNS for my network, plus doing firewalling/routing duties for IPv4/IPv6. I'm thinking of upgrading, but I'm not 100% su...
by mkx
Sat Apr 26, 2025 8:14 pm
Forum: Announcements
Topic: Newsletter #124
Replies: 29
Views: 24125

Re: Newsletter #124

However, the strong interference isn't really correct. I was talking about AGC of Rx preamplifier. The gain is automatically set according to strongest signal received (in worst case in the whole band, in best case in actual Rx frequency window). Strong interference will cause AGC to reduce gain an...
by mkx
Sat Apr 26, 2025 12:13 pm
Forum: Announcements
Topic: Newsletter #124
Replies: 29
Views: 24125

Re: Newsletter #124

OFDMA is part of 802.11ax standard. And as such it only works when both AP and station are ax (won't do any good if station is ac only). And will only be able to do something when interference is reasonably strong (not much stronger than received useful signal ... so it doesn't overwhelm receiver's...
by mkx
Sat Apr 26, 2025 12:09 pm
Forum: Beginner Basics
Topic: hEX refresh/ as Switch ->Pros & Cons?
Replies: 37
Views: 5002

Re: hEX refresh/ as Switch ->Pros & Cons?

That NVR has 10/100Mbps ethernet interfaces ... both for cameras and LAN. So hEX will have to handle 100Mbps full duplex at most. It'll do it without a sweat. Even if L2 HW offload for some reason doesn't kick in.
by mkx
Sat Apr 26, 2025 9:52 am
Forum: Beginner Basics
Topic: DNS Issue
Replies: 11
Views: 3234

Re: DNS Issue

Rules by @MTNick do the job just fine. Just beware of raw rules performance: while raw rules appear as a economical solution (raw rules are evaluated before connection tracking machinery does the job ... which is a single most expensive feature run by firewall), but raw rules are evaluated for every...
by mkx
Fri Apr 25, 2025 9:55 pm
Forum: Wireless Networking
Topic: Multi-passphrase VLAN issue [SOLVED]
Replies: 3
Views: 1385

Re: Multi-passphrase VLAN issue [SOLVED]

Just guessing ... I think that wifiX bridge ports should be set as tagged members of relevant VLANs ... all that are used in multi-passphrase configuration.
by mkx
Fri Apr 25, 2025 5:52 pm
Forum: Beginner Basics
Topic: Help setting up IPv6
Replies: 12
Views: 3164

Re: Help setting up IPv6

Use DHCPv6 client and configure it to receive a prefix on WAN interface. Also configure it with pool name. After you receive a pool into the pool named in configuration, you'll be able to assign IPv6 addresses from this pool to router's LAN interfaces. This will in turn allow router to announce appr...
by mkx
Fri Apr 25, 2025 9:15 am
Forum: General
Topic: Defeated by VLAN issue [SOLVED]
Replies: 9
Views: 2139

Re: Defeated by VLAN issue [SOLVED]

I don't understand the ingress filtering option. From what I read with ingress filtering turned on non VLAN tagged packets will be ignored. How is this option different on the bridge and port pages? Does it have any effect when frame types is set to admit all? Properties pvid, ingress-filtering (an...
by mkx
Thu Apr 24, 2025 8:49 am
Forum: MikroTik hardware questions
Topic: Mikrotik 4G purchase advises
Replies: 11
Views: 2391

Re: Mikrotik 4G purchase advises

Why expensive android tablets with omnidirectional antennas inside behaves BETTER than all 4G modems I had? Probably because those tablets use most recent 4G and 5G modems with much better ability to perform "Carrier Aggregation". Vast majority of cell towers nowdays use multiple frequenc...
by mkx
Thu Apr 24, 2025 8:29 am
Forum: Wireless Networking
Topic: Mikrotip AP and Wireless client with bridge, missing DHCP leases on Ethernet
Replies: 1
Views: 1059

Re: Mikrotip AP and Wireless client with bridge, missing DHCP leases on Ethernet

There is no such thing as "cross-vendor standard wireless bridging" which would be required for wifi bridge to act as a transparent connection between two wired "islands" (similar to UTP cable between two switches). Read more about it in this article . It's about use case where s...
by mkx
Thu Apr 24, 2025 8:18 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 641
Views: 299820

Re: v7.18.2 [stable] is released!

Must be config dependent. No issues on my rb750gr3. But it's being used practically as switch, so no special config or even routing. I wrote that my gr3 worked fine for about 1 hour until the data transfer started via the connected l2tp over ipsec. So this really doesn't happen everywhere and not a...
by mkx
Wed Apr 23, 2025 11:07 pm
Forum: Wireless Networking
Topic: NetBox 5 AX not visible to legacy devices (LHG5/SXT 5 ac) — how to connect?
Replies: 1
Views: 1129

Re: NetBox 5 AX not visible to legacy devices (LHG5/SXT 5 ac) — how to connect?

• Is there a compatibility issue between wifiwave2 AP mode and older MikroTik clients? Yes. True "station-bridge" mode is not possible if AP and station are using different generations of wifi/wireless driver. One possibility is to try with station-pseudobridge (but has some limitations)....
by mkx
Wed Apr 23, 2025 10:42 pm
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 4117

Re: AX3 as basic AP/switch

With all due respect: you started a few topics in last few weeks/months where we tried to explain a few "basics" with many plain English words (as far as we, non-native speakers, could) where you didn't understand explanation put forward using "tech talk" phrases. Part of reasons...
by mkx
Wed Apr 23, 2025 10:07 pm
Forum: Beginner Basics
Topic: Default firewall configuration and nmap outputs [SOLVED]
Replies: 46
Views: 6280

Re: Default firewall configuration and nmap outputs [SOLVED]

But you're right the default includes "untracked" — that is not in the normal default configuration, It is in normal default configuration, just checked my hAP ac2 running 7.18.2. "untracked" is accepted both for chain=input and chain=forward (the later by the non-fasttracked ru...
by mkx
Wed Apr 23, 2025 9:50 pm
Forum: MikroTik hardware questions
Topic: Mikrotik 4G purchase advises
Replies: 11
Views: 2391

Re: Mikrotik 4G purchase advises

No apparent reason if not - maybe - that the furthest tower was installed more recently and thus had "better/faster" devices than the nearer one. More likely: the closer, elevated, tower covers more subscribers and is thus much more utilized. Hence less radio resources available for each ...
by mkx
Wed Apr 23, 2025 8:34 pm
Forum: Beginner Basics
Topic: Default firewall configuration and nmap outputs [SOLVED]
Replies: 46
Views: 6280

Re: Default firewall configuration and nmap outputs [SOLVED]

I took another IP range from provider and did same nmap scan.
Does WAN IP address, shown on your RB, by any chance fall into range between 100.64.0.0 and 100.127.255.255? This is CGNAT address range and is not universally routable.
by mkx
Wed Apr 23, 2025 8:31 pm
Forum: Beginner Basics
Topic: Default firewall configuration and nmap outputs [SOLVED]
Replies: 46
Views: 6280

Re: Default firewall configuration and nmap outputs [SOLVED]

I already stated it couple of times. I run nmap from internet, from another computer, from another ISP towards Mikrotik. Do you know what CGNAT is ? And to determine what you can do to see if that is the what causes the problem. Even if MNO doesn't use CGNAT (which is becoming a rarity), it still m...
by mkx
Wed Apr 23, 2025 8:23 pm
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 4117

Re: AX3 as basic AP/switch

My hope is also that these discussions help develop the language to use to communicate more effectively about these topics. I hate to disappoint you, but the language is already developed, established and wildly used ... one simply has to learn it. Pretty much the same as every toddler has to learn...
by mkx
Wed Apr 23, 2025 8:07 pm
Forum: General
Topic: L2MTU vs MTU and Bridge MTU
Replies: 1
Views: 962

Re: L2MTU vs MTU and Bridge MTU

MTU: maximum size of IP packet (including headers). All IP devices in same IP subnet (as defined with IP address/netmask pair) must use same MTU. If not, then packets larger than MTU setting will be dropped by receiver (smaller packets are fine). Mind tgat no IP packet fragmentation takes place for ...
by mkx
Wed Apr 23, 2025 7:49 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 226878

Re: v7.19beta [testing] is released!

I hope, MikroTik Team will backport this fix to a near future 7.18.3 release also. I wouldn't count on it. When released, 7.19 will immediatelly become "stable" release ("stealing" the title from 7.18.2) ... and there is no "long term" release which would warrant backp...
by mkx
Wed Apr 23, 2025 6:16 pm
Forum: Beginner Basics
Topic: Default firewall configuration and nmap outputs [SOLVED]
Replies: 46
Views: 6280

Re: Default firewall configuration and nmap outputs [SOLVED]

Can you post output of
/interface/list/member/export

And indicate which interface is actually connecting your internet.
by mkx
Wed Apr 23, 2025 6:04 pm
Forum: Beginner Basics
Topic: Switch gets IP address from every VLAN DHCP server
Replies: 8
Views: 4177

Re: Switch gets IP address from every VLAN DHCP server

That logic seems to me more awkward to implement compared to just a dropdown list (or input box) to specify VLAN ID. As already said: it depends on switch vendor's "ingenuity". E.g. my D-link has "L2 features" -> "VLAN" -> "Management VLAN" and there I can en...
by mkx
Wed Apr 23, 2025 3:44 pm
Forum: Beginner Basics
Topic: Default firewall configuration and nmap outputs [SOLVED]
Replies: 46
Views: 6280

Re: Default firewall configuration and nmap outputs [SOLVED]

add action=dst-nat chain=dstnat comment="zabbix-agent dst-port=10650 in-interface-list=WAN log=yes log-prefix=\ nat-zbx-agent-zabbix-win-hp protocol=tcp src-address=x.x.x.x to-addresses=192.168.8.251 to-ports=10050 If your post is actually copy-paste of actual dst-nat rule, then everything, in...
by mkx
Wed Apr 23, 2025 3:37 pm
Forum: Beginner Basics
Topic: Switch gets IP address from every VLAN DHCP server
Replies: 8
Views: 4177

Re: Switch gets IP address from every VLAN DHCP server

Switches I've seen so far (not many models, I admit) have option to select "management VLAN" ... and if set properly, switch would then only receive IP from the correct VLAN. If the option is not set, then switch might try to obtain IP address from all VLANs it detects (or is configured wi...
by mkx
Wed Apr 23, 2025 3:07 pm
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 4117

Re: AX3 as basic AP/switch

I suppose, therefore, that the diagram (the original, not my monstrousity) shows the 5022/5022 connections to the switch chip component of the 6010 ... Diagram shows physical connections between 5022/5052 parts and main chip. Which part of it (CPU or switch chip) is not clear and it would only be p...
by mkx
Wed Apr 23, 2025 2:52 pm
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 4117

Re: AX3 as basic AP/switch

As @anav already hinted: the red box should enclose everything on the left side of its current extents and on the right side (including those tridents on the far right side of amplifiers ... they denote wifi antennas).

The rest is right.
by mkx
Wed Apr 23, 2025 2:21 pm
Forum: General
Topic: Weird ICMP latency between 2 networks
Replies: 3
Views: 913

Re: Weird ICMP latency between 2 networks

Sometimes it's good to write up problem, your brain will figure it out eventually. And the crucial detail (WLAN being in the mix) was missing from your initial description. If you didn't get to the right conclusion yourself, somebody else might have spotted the reason ... but only in case when all ...
by mkx
Wed Apr 23, 2025 11:47 am
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 4117

Re: AX3 as basic AP/switch

For clarification of one aspect of the origin and intent of my quesiton: I was thinking specifically about whether frames between wifi and etherports could exclusively use the switch chip. That is, the use of a dumb switch would not be applicable. You can always have a look at block diagram of a pa...
by mkx
Wed Apr 23, 2025 9:23 am
Forum: Beginner Basics
Topic: Default firewall configuration and nmap outputs [SOLVED]
Replies: 46
Views: 6280

Re: Default firewall configuration and nmap outputs [SOLVED]

Just a thought: it could be that your public address is not actually completely transparently presented to you. I have static public IP address (via PPPoE) and in my case, nmap scan from internet side shows a few ports open. Apart from the expected ones (which I explicitly configured in my router) i...
by mkx
Wed Apr 23, 2025 8:22 am
Forum: Beginner Basics
Topic: Basic NAT configuration using WebFig
Replies: 3
Views: 1256

Re: Basic NAT configuration using WebFig

At the point that an unsolicited connection request to TCP port 22 comes into your router from the outside, "src-address" is the IP of the host making the SSH connection attempt to your server, and "dst-address" is your router's WAN IP. So if you want the rule to trigger when a ...
by mkx
Tue Apr 22, 2025 10:14 pm
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 4117

Re: AX3 as basic AP/switch

I use my ax3 with vlan filtering .......
... which is done by software/CPU, so no HW offloading. Hence no problems snd high CPU load (but still wirespeed).
by mkx
Tue Apr 22, 2025 9:55 pm
Forum: General
Topic: AX3 as basic AP/switch
Replies: 45
Views: 4117

Re: AX3 as basic AP/switch

Is ASIC the same as the switch chip?

For the sake of argument: yes.
by mkx
Tue Apr 22, 2025 8:10 am
Forum: Beginner Basics
Topic: How to access CRS-cpu via two bridges !!??
Replies: 16
Views: 1980

Re: How to access CRS-cpu via two bridges !!??

About this setup, I do not regard it as bells and wissels. Objectively your setup is not very special indeed. But from the hurdles you're describing it seems you're not very well versed in ROS. So having multiple "independent" connections from a switch upstream, doing some routing, etc. ....
by mkx
Mon Apr 21, 2025 9:12 pm
Forum: Beginner Basics
Topic: How to access CRS-cpu via two bridges !!??
Replies: 16
Views: 1980

Re: How to access CRS-cpu via two bridges !!??

No I do not think a loop is possible. In my network there are multiple vlans. RSTP is unaware of VLANs. It's a protocol directly on ethernet and if two bridges/switches are connected using multiple links, even of they are trunks for distict VLANs, RSTP will detect a loop. I'd recommend you to simpl...
by mkx
Mon Apr 21, 2025 3:33 pm
Forum: Beginner Basics
Topic: How to access CRS-cpu via two bridges !!??
Replies: 16
Views: 1980

Re: How to access CRS-cpu via two bridges !!??

Try to connect actual PC directly to the management port. The way connections are shown on image they possibly make a loop ... if "pfSense & switches" allow that. And RSTP (enabled by default on ROS bridges) will break the loop by disabling one of links forming a loop, by default the s...
by mkx
Mon Apr 21, 2025 1:22 pm
Forum: Beginner Basics
Topic: How to access CRS-cpu via two bridges !!??
Replies: 16
Views: 1980

Re: How to access CRS-cpu via two bridges !!??

But in short: /interface/bridge is sbout swich-lije entity (called brudge), its ports including CPU-facing btidge port. And VLANs allowed accross those pirrs. /interface/vlan is about CPU ability to interact with tagged VLANs whichever CPU interface it might be, eithrr etherX inzetdsces, bridge, etc...
by mkx
Mon Apr 21, 2025 1:13 pm
Forum: Beginner Basics
Topic: How to access CRS-cpu via two bridges !!??
Replies: 16
Views: 1980

Re: How to access CRS-cpu via two bridges !!??

Another good tutorial which explains different bridge "personalities": viewtopic.php?t=173692
by mkx
Mon Apr 21, 2025 10:16 am
Forum: Beginner Basics
Topic: How to access CRS-cpu via two bridges !!??
Replies: 16
Views: 1980

Re: How to access CRS-cpu via two bridges !!??

I suggest you to go through this tutorial about VLANing using ROS device: viewtopic.php?t=143620

It may clear some misconceptions you might have.
by mkx
Sun Apr 20, 2025 10:12 pm
Forum: Beginner Basics
Topic: How to access CRS-cpu via two bridges !!??
Replies: 16
Views: 1980

Re: How to access CRS-cpu via two bridges !!??

The config regarding ether1 is mighty weird ... it's added as port to the "grand" bridge, srt as access port of VLAN 88. Then you have br10 which is configured as tagged member of VLAN 10 of "grand bridge" but it's not even set as port of same bridge?? A side note: ROS can HW off...
by mkx
Sun Apr 20, 2025 9:41 pm
Forum: General
Topic: Controller Bridge and Port Extender: removed from RouterOS since v7.18.
Replies: 2
Views: 1030

Re: Controller Bridge and Port Extender: removed from RouterOS since v7.18.

'Controller Bridge and Port Extender', but it seems too late as the help pages seem to suggest this function has been removed from OS7.18. What's replaced it, if anything? Or is there another way of achieving the same? Nothing replaced it. The concept is a (very poor) approximation to switch stacki...
by mkx
Sun Apr 20, 2025 9:24 pm
Forum: Beginner Basics
Topic: How to access CRS-cpu via two bridges !!??
Replies: 16
Views: 1980

Re: How to access CRS-cpu via two bridges !!??

As you noted, frames are passed (switched) only between ports of same bridge. Having two bridges in same device is (from L2 perspective) the same as having two devices. But I wonder: if sole purpose of the second bridge is to give emergency management access via the sole bridge port (ether1), then y...
by mkx
Sun Apr 20, 2025 9:13 pm
Forum: Beginner Basics
Topic: IPTV issues during intensive tasks
Replies: 29
Views: 3486

Re: IPTV issues during intensive tasks

I believe this is due to L3HW being disabled across the board
Again: if enabling L3HW oflload will solve your issue, then your CRSes are not configured as switches.
by mkx
Sat Apr 19, 2025 11:53 am
Forum: MikroTik hardware questions
Topic: hAP ac2 revisions
Replies: 11
Views: 2780

Re: hAP ac2 revisions

I actually had previously been aware of the "INTL/US" products that are the non-locked, non-US devices (always wireless, since this is about FCC regulations) yet packaged with a US power adapter, but had forgotten about it. NEMA power plugs are used in countries other than USA and Canada ...
by mkx
Sat Apr 19, 2025 11:32 am
Forum: General
Topic: Issue with 2.4GHz Wi-Fi on hAP ax² After Upgrade to RouterOS 7.18.1 [SOLVED]
Replies: 19
Views: 10534

Re: Issue with 2.4GHz Wi-Fi on hAP ax² After Upgrade to RouterOS 7.18.1 [SOLVED]

Received signal strength (-62dB) indicates that "interferer" is either "ordinary AP" physically placed very close to your hAP ax2 ... or a high-gain PtP link (probably operating at illegsl Tx power levels) with line betwern link peers going right through your hAP ax2. And either ...
by mkx
Sat Apr 19, 2025 11:18 am
Forum: General
Topic: Why would RB4011iGS+RM start beeping randomly?
Replies: 7
Views: 1326

Re: Why would RB4011iGS+RM start beeping randomly?

Is there anything that would be causing this?

Nothing in logs, not even suspicious log-ins? A script which does something to leds?
by mkx
Sat Apr 19, 2025 11:11 am
Forum: Beginner Basics
Topic: IPTV issues during intensive tasks
Replies: 29
Views: 3486

Re: IPTV issues during intensive tasks

/export terse CRS504.rsc

Please, don't use terse, my eyes hurt when reading terse output. Ordinary export will do just fine.
by mkx
Fri Apr 18, 2025 4:52 pm
Forum: Beginner Basics
Topic: IPTV issues during intensive tasks
Replies: 29
Views: 3486

Re: IPTV issues during intensive tasks

Switches should not experience any significant CPU load. As you see CPU pegged at 100%, this means your switches are misconfigured.
by mkx
Fri Apr 18, 2025 8:55 am
Forum: General
Topic: Can't DMZ to a server in LAN [SOLVED]
Replies: 5
Views: 3102

Re: Can't DMZ to a server in LAN [SOLVED]

I didn't see anything obviously wrong ... but I don't know much about using multiple routing talbes, so I can't comment on that aspect of your confiugration. Checks done so far: When I ping PUBLIC_IP.67 from outside the network, with tcpdump on both machines (mine and the 10.190.0.12) ICMP is fine, ...
by mkx
Thu Apr 17, 2025 7:34 pm
Forum: General
Topic: Can't DMZ to a server in LAN [SOLVED]
Replies: 5
Views: 3102

Re: Can't DMZ to a server in LAN [SOLVED]

Post actual configuration, not a novel.
by mkx
Wed Apr 16, 2025 8:54 pm
Forum: General
Topic: 2kbps DNS-Resolution Spam for cloud.mikrotik.com from detect-interface feature
Replies: 9
Views: 1571

Re: 2kbps DNS-Resolution Spam for cloud.mikrotik.com from detect-interface feature

How could I recommend a router to anyone for enterprise use if it introduces unintended, undocumented behavior that can easily take hours to rule out? Well ... whether you intended it or not, you had feature called "detect internet" enabled. And based on feature name and using common sens...
by mkx
Tue Apr 15, 2025 10:41 pm
Forum: Beginner Basics
Topic: Capsman Master-Slave Configuration
Replies: 21
Views: 6045

Re: Capsman Master-Slave Configuration

But why?

Because wifi-qcom-ac drivers are missing some crucial functionalities ... which were missing also in wifi-qcom but were eventually implemented there. MT keeps acting deaf to our pleads to implement them in wifi-qcom-ac as well.
by mkx
Tue Apr 15, 2025 9:09 am
Forum: SwOS
Topic: Which xmit-hash-policy do SWOS use for dynamic LAG?
Replies: 2
Views: 1430

Re: Which xmit-hash-policy do SWOS use for dynamic LAG?

Manual says "... load balancing based on Layer2, Layer3 and Layer4 hashing". Not specifically for "dynamic" LAG, but I'd take that it applies to both LAG modes. So L3+L4 hash ...
by mkx
Tue Apr 15, 2025 9:06 am
Forum: General
Topic: Whats the point of this default FW rule?
Replies: 25
Views: 4777

Re: Whats the point of this default FW rule?

chain=forward action=drop connection-state=new connection-nat-state=!dstnat in-interface-list=WAN "We are dropping all non-dstnated IPv4 packets to protect direct attacks on the clients if the attacker knows the internal LAN network. Typically this rule would not be necessary since RAW filters...
by mkx
Mon Apr 14, 2025 9:56 pm
Forum: Wireless Networking
Topic: Is there any good way to sniff 802.11 frames for troubleshooting?
Replies: 1
Views: 877

Re: Is there any good way to sniff 802.11 frames for troubleshooting?

You'll want to sniff beacons because most of interesting data is broadcast ... try to filter according to BSSIDs that belong to your WiFi network to reduce amount of chatter. Ony when your station decides to roam there will be some unicast exchange with old and new APs.
by mkx
Mon Apr 14, 2025 9:34 pm
Forum: Beginner Basics
Topic: turn PowerBox Pro into PoE Switch powered by NVR out [SOLVED]
Replies: 25
Views: 3775

Re: turn PowerBox Pro into PoE Switch powered by NVR out [SOLVED]

Typically rated power of a device is only used during certain periods of time, one being powering-up. The problem in your case might be just that: if PowerBox Pro enables PoE-out for both connected cameras (you said you'll connect 2) at the same time and they both hit the peak usage at the same time...
by mkx
Mon Apr 14, 2025 8:36 pm
Forum: Beginner Basics
Topic: NTP Client triggers max permanent peer count message
Replies: 4
Views: 1078

Re: NTP Client triggers max permanent peer count message

My ROS installations generally have 2 servers configured and up to 7.18.2 I never saw such error logged.
by mkx
Mon Apr 14, 2025 8:34 pm
Forum: Beginner Basics
Topic: Question about unknown IP address trying to connect though capsman
Replies: 11
Views: 1755

Re: Question about unknown IP address trying to connect though capsman

These are custom firewall rules ... the ones you don't even look at :wink:

I didn't even bother looking past these two rules ... make me think I'd be looking at some pretty butchered firewall setup.
by mkx
Mon Apr 14, 2025 8:31 pm
Forum: Beginner Basics
Topic: turn PowerBox Pro into PoE Switch powered by NVR out [SOLVED]
Replies: 25
Views: 3775

Re: turn PowerBox Pro into PoE Switch powered by NVR out [SOLVED]

PoE Max. Power Per Port 25W This gives you power budget for PowerBox Pro and all connected cameras. PowerBox Pro is specced at 6W max (it might have typical consuption a Watt or two less). So around 20W will remain for powering attached cameras. What is rated power consumption of those? And don't f...
by mkx
Mon Apr 14, 2025 8:18 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 3261

Re: Using CRS326 as a switch

"L3HW routing" would be fine as well :), but it can be confusing, I invented the "almost switching" just for having it in the order of speed: But it's confusing ... as @mbovenka wrote: routing is routing bexause it's L3 function. And switching is switching because it's L2 functi...
by mkx
Mon Apr 14, 2025 7:59 pm
Forum: General
Topic: How does Mac Telnet and VLAN’s work together?
Replies: 1
Views: 810

Re: How does Mac Telnet and VLAN’s work together?

MAC telnet (application) works only with ethernet frames without VLAN tags (I suspect it's using ethertype 0x0800 IPv4(. So it can't be used off bridge which is trunk port, VLAN interface(s) are needed to strip/add VLAN tags.
by mkx
Mon Apr 14, 2025 7:41 pm
Forum: Beginner Basics
Topic: Question about unknown IP address trying to connect though capsman
Replies: 11
Views: 1755

Re: Question about unknown IP address trying to connect though capsman

The top two firewall filter rules: /ip firewall filter add action=passthrough chain=input dst-port=5246 in-interface=ether1 \ in-interface-list=WAN log=yes protocol=udp add action=passthrough chain=input dst-port=5247 in-interface=ether1 \ in-interface-list=WAN log=yes protocol=udp They explicitly a...
by mkx
Mon Apr 14, 2025 8:34 am
Forum: Beginner Basics
Topic: likely hitting software-based routing limits [SOLVED]
Replies: 23
Views: 5380

Re: likely hitting software-based routing limits [SOLVED]

On the other hand CRS520-4XS-16XQ-RM ... switch with so powerful CPU that even beeing "a switch", the traffic throughput may satisfy datacenter needs. It might. But it would likely collide with expectations ... which usually are "wirespeed routing" and if routing on CRS520 is do...
by mkx
Mon Apr 14, 2025 8:28 am
Forum: Beginner Basics
Topic: NTP Client triggers max permanent peer count message
Replies: 4
Views: 1078

Re: NTP Client triggers max permanent peer count message

How many NTP servers are configured in /system/ntp/client? I don't know if there's a limit in RouterOS's NTP implementation, but I don't think more than 3 quality servers are necessary (3 is kind of a minimum to form a meaningful quorum).
by mkx
Mon Apr 14, 2025 8:25 am
Forum: Beginner Basics
Topic: Question about unknown IP address trying to connect though capsman
Replies: 11
Views: 1755

Re: Question about unknown IP address trying to connect though capsman

Well, the fact that logs are written by CAPsMAN (topic caps,info) indicates that firewall of your router is not effective. Default firewall setup would block attempts to connect to CAPsMAN through WAN port and CAPsMAN would not even see those attempts. If there were log entries about that, they woul...
by mkx
Mon Apr 14, 2025 8:21 am
Forum: Beginner Basics
Topic: turn PowerBox Pro into PoE Switch powered by NVR out [SOLVED]
Replies: 25
Views: 3775

Re: turn PowerBox Pro into PoE Switch powered by NVR out [SOLVED]

Set dhcp client to bridge Plug ethernet cable from NVR in powerbox port 1 Just for the record: you have to connect NVR to port ether1 because it's the PoE-in port. With the outlined configuration, all the ports are equal regarding ethernet traffic (and hence IP traffic). E.g. DHCP client would be a...
by mkx
Sun Apr 13, 2025 3:50 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 3261

Re: Using CRS326 as a switch

3) VLAN routing is a handled by the bridge (and therefore a switching function). Switch doesn't do any routing ... and "VLAN routing" is either "routing" or "VLAN switching" (depending on the way you abuse phrase VLAN routing). If you're talking about the later, then s...
by mkx
Sun Apr 13, 2025 1:53 pm
Forum: General
Topic: Using CRS326 as a switch
Replies: 36
Views: 3261

Re: Using CRS326 as a switch

In short: any RouterOS device, which has more than a single IP address configured (used only for management), can eventually become a router. So a switch should never have more than one IP address configured, if configuring additional IP address solves a traffic problem, it means that switch became ...
by mkx
Sat Apr 12, 2025 2:42 pm
Forum: Wireless Networking
Topic: How to update CAP from CAPsMAN v2?
Replies: 5
Views: 1502

Re: How to update CAP from CAPsMAN v2?

Does this mean that there is no automated solution to download the required files (wifi-qcom-7.18.2-arm64.npk) to the CAPsMAN v2 device? Do I have to do it manually? And also before updating the CAPsMAN v2 device? No, there's no automated way of downloading additional packages to capsman device. I ...
by mkx
Fri Apr 11, 2025 9:31 pm
Forum: Wireless Networking
Topic: How to update CAP from CAPsMAN v2?
Replies: 5
Views: 1502

Re: How to update CAP from CAPsMAN v2?

Upload all the relevant packages (base routeros and necessary optional packages, such as wifi-qcom) for all relevant architectures (ARM, ARM64) to capsman device ... I recomend you to create a dedicated folder on flash storage). Then set package-path to the correct folder and set upgrade-policy to s...
by mkx
Fri Apr 11, 2025 9:21 pm
Forum: Wireless Networking
Topic: Integration of Wave2 to existing CAPSMAN
Replies: 5
Views: 1835

Re: Integration of Wave2 to existing CAPSMAN

Yes, radio stats are available on capsman ... but with wifi drivers amount of stats is small compared to wireless stats.
by mkx
Thu Apr 10, 2025 10:11 pm
Forum: Wireless Networking
Topic: LHGG LTE6 - Band selection WinBox
Replies: 3
Views: 1069

Re: LHGG LTE6 - Band selection WinBox

Mobile broadband networks (LTE, 5G) don't work the way you seem to think. There are two major modes: idle and active. When device is in idle mode, device can choose to "listen" to any cell it wants (but has to perform Tracking Area Update if it selects to listen to cell which is in differe...
by mkx
Thu Apr 10, 2025 9:37 pm
Forum: Wireless Networking
Topic: cfg check: is encryption enabled?
Replies: 2
Views: 1189

Re: cfg check: is encryption enabled?

Wireless bridge is the same as normal AP/station. And AP setting security.mode affects encryption. It's pretty easy to enable it ... set mode=dynamic-keys , authentication-types to e.g. "wpa2-psk" and set wpa2-pre-shared-key ... first on remote side of link (if managing over same link) and...
by mkx
Wed Apr 09, 2025 8:38 pm
Forum: Wireless Networking
Topic: Vlans over 60Ghz PTMP link [SOLVED]
Replies: 13
Views: 3584

Re: Vlans over 60Ghz PTMP link [SOLVED]

No special config, just static ip set, but can't reach them.
If this statement is about cube devices ... then they need at least default route set with UDM's address as gateway. Without this setting (and probably DNS settings as well) it's not possible to use built-in package upgrader ...
by mkx
Wed Apr 09, 2025 8:31 am
Forum: MikroTik hardware questions
Topic: l009uigs-2haxd-in , sfp+ rj45 2,5gpbs
Replies: 1
Views: 1133

Re: l009uigs-2haxd-in , sfp+ rj45 2,5gpbs

Try to set sfp-sfpplus1 port speed to 2.5Gbps and disable autonegotiation. But it could be you won't be able to make things work ... Mikrotik devices are notorious for poor support for SFP modules (including RJ45 ones) and it's best to get a module which is known to work well with your particular Mi...
by mkx
Wed Apr 09, 2025 8:28 am
Forum: Wireless Networking
Topic: Vlans over 60Ghz PTMP link [SOLVED]
Replies: 13
Views: 3584

Re: Vlans over 60Ghz PTMP link [SOLVED]

I'm sorry, I don't follow the layout of your network. You may want to make a simple diagram of your network (router, PTMP link devices, wireguard) ...
by mkx
Wed Apr 09, 2025 8:26 am
Forum: Wireless Networking
Topic: Help to create a mesh network using mANTBox ax 15s
Replies: 3
Views: 3954

Re: Help to create a mesh network using mANTBox ax 15s

Ideally you want to have "the middle" mANTbox configured as AP and the other two as station-bridge ... you'll have the least problems. Mind that AP doesn't have to be closest to router, it can be anywhere ... L2 traffic flows symmetrical over a WiFi connection, only L1 control is done by A...
by mkx
Wed Apr 09, 2025 8:10 am
Forum: Beginner Basics
Topic: Mikrotik CRS326-24s+2q+rm won't work after RoterOS 7.12.1 Upgrade
Replies: 9
Views: 1597

Re: Mikrotik CRS326-24s+2q+rm won't work after RoterOS 7.12.1 Upgrade

Just to get things straight: ... download and deploy the latest available RouterOS. I believe it was 7.12.1 Actually the latest version marked as stale is the 7.18.2. If original ROS version on device was <= 7.11, then upgrader built in ROS will first upgrade to 7.12(.1) ... only upgrader in 7.12 wi...
by mkx
Tue Apr 08, 2025 6:57 pm
Forum: General
Topic: Slow transfer speed but not on Ookla speedtest
Replies: 8
Views: 1438

Re: Slow transfer speed but not on Ookla speedtest

If speedtest is fast, but nothing else is fast - your ISP is limiting you and setting an exception on speedtest :) Common practice in some areas You are reading my mind :-) They say they don't. Of course they are saying that. Does your local telecommunication regulatory agency (probably Bundesnetza...
by mkx
Tue Apr 08, 2025 6:49 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 641
Views: 299820

Re: v7.18.2 [stable] is released!

You missed the point, there was no warnings before upgrade or i ever touched CPU freq on this fresh unpacked device , its the upgrade which changed freq or whatever it did and now complains about "it self" The upgrade didn´t change frequency. I can't say about this particular device, but ...
by mkx
Tue Apr 08, 2025 3:57 pm
Forum: General
Topic: How to root out loops (noted on WiFi LAN) [SOLVED]
Replies: 4
Views: 2332

Re: How to root out loops (noted on WiFi LAN) [SOLVED]

If you sniff the broadcast traffic, does src-mac-address tell you anything? Likewise src-IP-address?
by mkx
Tue Apr 08, 2025 3:54 pm
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 3139

Re: Basic VLAN config question (again)

This one:
/interface vlan
add comment=vlan32 interface=ether1 name=vlan32 vlan-id=32
It should be interface=bridge ... it took me 0 seconds (recognized it while reading config).
by mkx
Tue Apr 08, 2025 3:50 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 641
Views: 299820

Re: v7.18.2 [stable] is released!

Is this normal behavior or bug? Good morning. Yes, since 7.17 one has to allow routerboard uder /system/device-mode to be able to change anything under /system/routerboard ... which includes CPU frequency. Before you join the choir: there were lenghty and loud complaints about extensive use of devi...
by mkx
Tue Apr 08, 2025 8:52 am
Forum: MikroTik hardware questions
Topic: heX vs hEX Refresh pricing
Replies: 6
Views: 1870

Re: heX vs hEX Refresh pricing

I understand about MSRP, my question was more oriented to the real market picture that I see I guess that "real market picture" depends both on MT's policy (do they drop their own device prices after a while or not) and your local distributors (do they tend to keep prices high "just ...
by mkx
Tue Apr 08, 2025 8:42 am
Forum: Wireless Networking
Topic: Integration of Wave2 to existing CAPSMAN
Replies: 5
Views: 1835

Re: Integration of Wave2 to existing CAPSMAN

With old capsman, you have local-forwarding=no ... which means that all traffic for all CAPs' radios will be handled by CAPsMAN's cap interfaces and bridge. This mode of forwarding is not available in wave2 capsman. Instead all traffic will be handled by CAP's bridge. In order to transport traffic o...
by mkx
Tue Apr 08, 2025 8:30 am
Forum: General
Topic: Redirecting a static IP user to the service disconnection page.
Replies: 1
Views: 561

Re: Redirecting a static IP user to the service disconnection page.

RouterOS version 5.21 is hopelessly outdated.

You may want to upgrade to some more recent version. Which one would be optimal depends very much on model of your device. So which one is it?
by mkx
Mon Apr 07, 2025 7:56 pm
Forum: MikroTik hardware questions
Topic: Default power grid voltage for Mikrotik devices
Replies: 10
Views: 2221

Re: Default power grid voltage for Mikrotik devices

How could I know if the device is locked to US wireless channels/power? Mikrotik adds a "-US" in product code. Example: product page of hAP ac² mentions US variant ... product code is not mentioned, but other sources know US variant by code RBD52G-5HacD2HnD-TC -US (as opposed to "sim...
by mkx
Mon Apr 07, 2025 6:38 pm
Forum: MikroTik hardware questions
Topic: heX vs hEX Refresh pricing
Replies: 6
Views: 1870

Re: heX vs hEX Refresh pricing

Mikrotik never changes MSRP of a device ... not even when being discontinued. I have no idea what happens to real price (distributors paying to Mikrotik) and it's up to distributors to do something about it if they are left with warehouse full of obsolete devices. And your right is to choose between...
by mkx
Mon Apr 07, 2025 6:15 pm
Forum: Beginner Basics
Topic: netPower Lite 7R / can NVR PoE power this switch? [SOLVED]
Replies: 10
Views: 2963

Re: netPower Lite 7R / can NVR PoE power this switch? [SOLVED]

should I be worried that the power BOx Pro will try to power my PC and burn it? In theory all kinds of PoE perform (sometimes minimalistic) check if connected device is PoE compatible or not, and if connected device doesn't respond according to protocol, PoE switch won't provide power. But in pract...
by mkx
Mon Apr 07, 2025 3:40 pm
Forum: General
Topic: DHCP in Bridge Mode (revisited)
Replies: 8
Views: 1677

Re: DHCP in Bridge Mode (revisited)

Regarding access from management subnet to other subnets, you have these rules: /ip firewall filter add action=accept chain=forward comment="forward - established - accept" \ connection-state=established add action=accept chain=forward comment="forward - related - accept" \ conne...
by mkx
Mon Apr 07, 2025 12:03 pm
Forum: Beginner Basics
Topic: netPower Lite 7R / can NVR PoE power this switch? [SOLVED]
Replies: 10
Views: 2963

Re: netPower Lite 7R / can NVR PoE power this switch? [SOLVED]

PowerBox Pro has a decent switch chip built in which controls ether1-ether5. So those ports can be used as a switch without bothering CPU (if you need VLANs, you'll have to configure VLAN under /interface/ethernet, not under bridge). https://cdn.mikrotik.com/web-assets/product_files/RB960PGS-PB_1711...
by mkx
Sun Apr 06, 2025 9:37 pm
Forum: MikroTik hardware questions
Topic: Mikrotik Router with 2.5 Gbps
Replies: 4
Views: 1496

Re: Mikrotik Router with 2.5 Gbps

I think the only "compact" Mikrotik router that supports multi-gig routing, is CCR2004-16G-2S+PC. The price is not that compact (but that's subjective depending on magnitude of one's cash flow).
by mkx
Sun Apr 06, 2025 9:30 pm
Forum: MikroTik hardware questions
Topic: Default power grid voltage for Mikrotik devices
Replies: 10
Views: 2221

Re: Default power grid voltage for Mikrotik devices

When sourcing wireless devices from abroad, one has to be careful about devices intended for US market ... they are often locked to channels and power allowed in US. Even if powered by EU or UK external power adapters :wink: Devices sold elsewhere are "international" out from factory (but ...
by mkx
Sun Apr 06, 2025 9:08 pm
Forum: Beginner Basics
Topic: netPower Lite 7R / can NVR PoE power this switch? [SOLVED]
Replies: 10
Views: 2963

Re: netPower Lite 7R / can NVR PoE power this switch? [SOLVED]

I don't think that any of MT's switches can provide PoE to connected devices while being powered via PoE. All of switches require powering via power jack (if using external power adapters) to provide PoE due to required high power source.
by mkx
Sun Apr 06, 2025 8:59 pm
Forum: Beginner Basics
Topic: netPower Lite 7R / can NVR PoE power this switch? [SOLVED]
Replies: 10
Views: 2963

Re: netPower Lite 7R / can NVR PoE power this switch? [SOLVED]

I doubt it. The 7R (R stands for "reverse") model can be powered by multiple PoE sources and can provide PoE one powered device (connected to ether8). On top of it, it's passive PoE which is not really compatible with standard PoE.
by mkx
Sun Apr 06, 2025 7:31 pm
Forum: General
Topic: Difference between hAP ac2 RBD52G-5HacD2HnD-TC and RBD52G-5HacD2HnD
Replies: 7
Views: 1321

Re: Difference between hAP ac2 RBD52G-5HacD2HnD-TC and RBD52G-5HacD2HnD

My older 256MB devices have 6.40.5 (2017-10-31) as the default version

So it seems like there were multiple (at least two) batches of 256MB RAM hAP ac2 ... my device has factory firmware 6.42.3 (ROS changelog says it's release time was 2018-May-24 09:20).
by mkx
Sun Apr 06, 2025 7:23 pm
Forum: Wireless Networking
Topic: Vlans over 60Ghz PTMP link [SOLVED]
Replies: 13
Views: 3584

Re: Vlans over 60Ghz PTMP link [SOLVED]

...BUT I can't ping or get in to the cube60's from network? Why? do I have to make some vlan config on the cube's to get this working?

Which network? 192.168.1.0/24 ?
by mkx
Sun Apr 06, 2025 7:08 pm
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 3139

Re: Basic VLAN config question (again)

It will check if ingress port is member of VLAN that ingressing frame belongs to. As per your example: on ether1 if ingressing frame is tagged with VID=32, then it'll be accepted. If, OTOH, ingressing frame is tagged with e.g. VID=666, then it will be dropped (because ether1 is not set as member of...
by mkx
Sun Apr 06, 2025 7:04 pm
Forum: General
Topic: Difference between hAP ac2 RBD52G-5HacD2HnD-TC and RBD52G-5HacD2HnD
Replies: 7
Views: 1321

Re: Difference between hAP ac2 RBD52G-5HacD2HnD-TC and RBD52G-5HacD2HnD

The 256MB report themselves as "-TC" I have one 256MB unit and it identifies itself as model: RBD52G-5HacD2HnD (no -TC) ... that's in /system/routerboard and in output of /export ... is there any other location where device identifies itself? It does have -TC on device sticker though. I a...
by mkx
Sun Apr 06, 2025 4:27 pm
Forum: General
Topic: DHCP IP Assignments
Replies: 1
Views: 647

Re: DHCP IP Assignments

Is there a reason why it starts from the highest and not the lowest (.2)? No, there's no actual reason. All addresses in DHCP pool are equal. Server could assign leases randomly ... but that would require more CPU resources (choosing a random number, verifying that address is not taken as per DHCP ...
by mkx
Sun Apr 06, 2025 4:17 pm
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 3139

Re: Basic VLAN config question (again)

"When ingresss-filtering=YES, port will actually look at VLAN ID of ingressing frame and will drop frames where VID is not one of port's VLANs (as configured under bridge/vlan)." What parameter exactly in the bridge/vlan config is checked to see if a frame can ingress? It will check if in...
by mkx
Sun Apr 06, 2025 3:19 pm
Forum: General
Topic: DHCP in Bridge Mode (revisited)
Replies: 8
Views: 1677

Re: DHCP in Bridge Mode (revisited)

You're trying to upgrade from which to which version? If version difference is minor, then what you're seeing might be due to some bug. If the difference between original and new ROS version (e.g. upgrade from v6 to v7), then it could be incompatibility of your particular configuration. You might wa...
by mkx
Sun Apr 06, 2025 1:37 pm
Forum: General
Topic: Poor WLAN performance RB4011igs
Replies: 23
Views: 2815

Re: Poor WLAN performance RB4011igs

As I wrote: when radio is controlled by capsman, then ROS on cap doesn't really know what's going on. In reality running monitor on such radio should just refuse to output anything.
by mkx
Sun Apr 06, 2025 1:14 pm
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 3139

Re: Basic VLAN config question (again)

Yes. Just add the ingress-filtering=yes and you're golden.
by mkx
Sun Apr 06, 2025 12:36 pm
Forum: Beginner Basics
Topic: Configuring Separate Ethernet for Wi-Fi [SOLVED]
Replies: 11
Views: 3730

Re: Configuring Separate Ethernet for Wi-Fi [SOLVED]

@Dangles: post (sanitized and anonymized) output of /export ... so we can see what exactly is configured.
by mkx
Sun Apr 06, 2025 12:33 pm
Forum: Beginner Basics
Topic: Internet connection lost when set to Static Address Aquisition
Replies: 2
Views: 1082

Re: Internet connection lost when set to Static Address Aquisition

Is there a way to make this work with static settings? Thank you for your help. Not likely. It could well be that ISP's router has settings which require it's downstream clients to acquire address via DHCP (yes, that's possible ... also on ROS devices). If you want to by-pass ISP's DNS servers, the...
by mkx
Sat Apr 05, 2025 5:18 pm
Forum: General
Topic: Device got hacked 1 min after connected to internet
Replies: 57
Views: 10574

Re: Device got hacked 1 min after connected to internet

Latest devices like hEXs have a custom password from factory, this should be normal for all devices. Yes, those devices are for kids, hence they come preconfigured with (safe and sane) defaults. CCR, on the other hand, is device for professionals ... who know better than rush down the wrong lane.
by mkx
Sat Apr 05, 2025 4:48 pm
Forum: General
Topic: Poor WLAN performance RB4011igs
Replies: 23
Views: 2815

Re: Poor WLAN performance RB4011igs

I don't remember how exactly those things are related in old capsman ... but there's always chance of seeing some setting in configuration export which is actually ignored/overriden ... so you should check output of monitor command, excuted on "controlling entity" ... that's capsman device...
by mkx
Sat Apr 05, 2025 4:04 pm
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 3139

Re: Basic VLAN config question (again)

Basically that's it for ether1, it would work. But using VLANs is also about segregation of traffic belonging to different VLANs and enforcing that connected devices stick to their designated VLANs. The big problem is ingress, egress is configured on bridge and connected devices can't do much about ...
by mkx
Sat Apr 05, 2025 3:11 pm
Forum: General
Topic: Basic VLAN config question (again)
Replies: 31
Views: 3139

Re: Basic VLAN config question (again)

Is my understanding correct?

Yes.

Of course you need corresponding config for ether1 under bridge/port and appropriate config of bridge port (but that's not subject of this topic, right?)
by mkx
Sat Apr 05, 2025 2:49 pm
Forum: General
Topic: Poor WLAN performance RB4011igs
Replies: 23
Views: 2815

Re: Poor WLAN performance RB4011igs

guest wlan is only on RB4011, so it should work also ? I'm pretty sure that either forwarding on RB4011 doesn't make any difference ... traffic will end up in wireless interface on RB4011 in any case. Regarding provisioning of radios on RB4011: legacy capsman gladly works with local radios just fin...
by mkx
Sat Apr 05, 2025 1:43 pm
Forum: General
Topic: Poor WLAN performance RB4011igs
Replies: 23
Views: 2815

Re: Poor WLAN performance RB4011igs

can i try it for one AP first ? Sure you can. ... and most of the wifi traffic goes through the AP of the rb4011 which is capsman ... does that still make a performance difference ? Yes. The most slowdown, caused by capsman-forwarding, is due to processing overhead of tunneling all traffic between ...
by mkx
Sat Apr 05, 2025 1:26 pm
Forum: Beginner Basics
Topic: Configuring Separate Ethernet for Wi-Fi [SOLVED]
Replies: 11
Views: 3730

Re: Configuring Separate Ethernet for Wi-Fi [SOLVED]

Alternatively, it may be possible to do this with hardware switch rules on the Hap AC2 ... No, switch chip in this case would not help. It only kicks in when passing traffic directly between two ethernet ports and that's what @OP doesn't want (as far he explained in opening post). Yes, it would be ...
by mkx
Sat Apr 05, 2025 1:09 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 226878

Re: v7.19beta [testing] is released!

Routerboard firmware (mostly) up-to-date? Does another reboot change anything? no idea how to check firmware. /system/routerboard/print If it shows upgrade-firmware and it's notably newer than current-firmware, then upgrade it. Since quite many versions ago, routerboard firmware is shipped together...
by mkx
Sat Apr 05, 2025 12:03 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 525
Views: 226878

Re: v7.19beta [testing] is released!

What's up with that?

Routerboard firmware (mostly) up-to-date? Does another reboot change anything?
by mkx
Sat Apr 05, 2025 10:56 am
Forum: General
Topic: echo: system,error,critical could not save configuration changes, not enough storage space available.
Replies: 68
Views: 27725

Re: echo: system,error,critical could not save configuration changes, not enough storage space available.

However only if one first installs latest beta. So it doesn't help devices, running older ROS versions, already in the "doomed" state.
by mkx
Sat Apr 05, 2025 10:54 am
Forum: General
Topic: DHCP in Bridge Mode (revisited)
Replies: 8
Views: 1677

Re: DHCP in Bridge Mode (revisited)

"bridge mode" means that ports are switched ... and thus members of same L2 broadcast domain. And in vast majority of cases this means single IP subnet.
by mkx
Sat Apr 05, 2025 10:51 am
Forum: General
Topic: Poor WLAN performance RB4011igs
Replies: 23
Views: 2815

Re: Poor WLAN performance RB4011igs

The bridge port listing shows nothing which would concern me regarding switch over to local-forwarding=yes ...
by mkx
Fri Apr 04, 2025 8:39 pm
Forum: General
Topic: Poor WLAN performance RB4011igs
Replies: 23
Views: 2815

Re: Poor WLAN performance RB4011igs

I checked config of RB4011 and one of CAPs (bad). It seems that it should be possible to go with local-forwarding=yes setting. You do have added the cap-* interfaces to several interface lists, but it doesn't seem to me that you're then using those interface lists ... apart from using WLAN-any and W...
by mkx
Fri Apr 04, 2025 5:58 pm
Forum: Wireless Networking
Topic: Vlans over 60Ghz PTMP link [SOLVED]
Replies: 13
Views: 3584

Re: Vlans over 60Ghz PTMP link [SOLVED]

🤔 hmmm…. Untagged vlan 1 on edgeswitch port 1? Really sure about that? This is the trunk that goes through The cube 60 from downlink vlan 1 on udm…. No, I'm not sure about that, I'd be sure if I'd ever have to deal with edgeswitch myself. But based on my (limited) experience, I'd definitely try tha...
by mkx
Fri Apr 04, 2025 3:17 pm
Forum: General
Topic: Poor WLAN performance RB4011igs
Replies: 23
Views: 2815

Re: Poor WLAN performance RB4011igs

Just a quick answer to the question ... I'll review the configs later.

station-roaming is enabled by default. But, as I already explained: it's irrelevant for device running in AP mode ... and CAP device is running in AP mode.
by mkx
Fri Apr 04, 2025 8:51 am
Forum: Wireless Networking
Topic: Vlans over 60Ghz PTMP link [SOLVED]
Replies: 13
Views: 3584

Re: Vlans over 60Ghz PTMP link [SOLVED]

Ubiquiti UDM PRO with native "default" vlan on port 3. (also made networks for vlan 500 and 1000) When (almost) any vendor says it's "native" VLAN ... this means that frames on wire side of port are untagged, but get tagged on ingress and untagged on egress, so on internal bridg...
by mkx
Fri Apr 04, 2025 8:37 am
Forum: General
Topic: RouterOS License Level 2?
Replies: 8
Views: 2848

Re: RouterOS License Level 2?

Since ROS support for hardware is mediocre at best, it's better to go with CHR, running in a VM. Such setup does impose a slight performance hit. Debatable that it is "better" in 100% of cases, and so I'm very thankful that MT continues to offer the non-CHR version of ROS for x86/x64. Buy...
by mkx
Fri Apr 04, 2025 8:30 am
Forum: General
Topic: RouterOS License Level 2?
Replies: 8
Views: 2848

Re: RouterOS License Level 2?

License levels 0-6 only apply to MT's own hardware and all of their hardware comes installed with license level at least 3 (most devices 5, some 4, some 6). Well this is of course not true. If you want to license a non-virtualized x86 install, those also get the older-style, non-transferable (bound...
by mkx
Fri Apr 04, 2025 8:20 am
Forum: General
Topic: Help needed: Poor download speed and semi frequent drops
Replies: 7
Views: 1867

Re: Help needed: Poor download speed and semi frequent drops

And enable ingress-filtering on all the bridge ports (it's the default value in RouterOS 7). I'm on 7.18.2 and all my ingress filters are no. I think that flow control by default is disabled on most devices. RB951Ui-2HnD running ROS v6 has both Rx and Tx flow control disabled (and since setting is ...
by mkx
Thu Apr 03, 2025 11:33 pm
Forum: General
Topic: Poor WLAN performance RB4011igs
Replies: 23
Views: 2815

Re: Poor WLAN performance RB4011igs

I asked for full config ... capsman and wireless config is not enough to answer your question about going for local forwarding. station-roaming setting is only relevant if device is operating in station mode, your devices are operating in ap mode. radio-mac property in capsman is used to match a par...
by mkx
Thu Apr 03, 2025 3:18 pm
Forum: General
Topic: Poor WLAN performance RB4011igs
Replies: 23
Views: 2815

Re: Poor WLAN performance RB4011igs

Do you have single SSID per radio on CAP ... which is then made full member of LAN? If that's so, then it should be enough to simply change to "local-forwarding=yes". As you can see, I'm guessing a bit. If you can post full config from CAPsMAN and from one of CAP devices, we can check and ...
by mkx
Thu Apr 03, 2025 3:15 pm
Forum: General
Topic: station v station-bridge mode
Replies: 9
Views: 2090

Re: station v station-bridge mode

Are the wifiwave2 available for most devices? We have LHG 2, LHG5 and Sxt radios for clients.

wifi(wave2) drivers are available for all AX (and newer) devices. They are also available for ARM-based AC devices, but LHG2, LHG5 or SXT Lite5 are neither.
by mkx
Thu Apr 03, 2025 3:08 pm
Forum: General
Topic: MikroTik RB5009 setting up remotely first time
Replies: 55
Views: 5656

Re: MikroTik RB5009 setting up remotely first time

Given that RB5009 server starts with 192.168.88.1 if we assign the ISP router in diagram to do be on same segment meaning the isp router dhcp server also assigns rb5009 a address of 192.168.88.X in wan port will that solve the issue and then once we open the wan port for remote management we change...
by mkx
Thu Apr 03, 2025 9:25 am
Forum: General
Topic: Poor WLAN performance RB4011igs
Replies: 23
Views: 2815

Re: Poor WLAN performance RB4011igs

It depends on how your "house" LAN is done. If it's "flat" LAN (i.e. only switches used, all devices use same IP subnet), then you don't have to change anything, wireless clients will still receive DHCP leases from central DHCP server, they will still use same gateway router, etc...
by mkx
Thu Apr 03, 2025 9:06 am
Forum: Beginner Basics
Topic: Returning Newbie :) - Optimizing Bandwidth Config
Replies: 9
Views: 2586

Re: Returning Newbie :) - Optimizing Bandwidth Config

EDIT: By "ring topology" I ment the four switches connection (purple), not the whole thing going out. That would be true if the bottom two switches would not have any special configuration of "purple" ports. If those ports are configured as LACP bond, then those ports don't crea...
by mkx
Thu Apr 03, 2025 8:59 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 641
Views: 299820

Re: v7.18.2 [stable] is released!

I'm curious if I enable ping watchdog, if that reboots the cAPs faster. My experience is that ping watchdog reboots device real fast ... when pings start to fail. Beware that it'll trip also when "reference" device becomes unavailable for some reason. The question remains whether pings wi...
by mkx
Wed Apr 02, 2025 6:24 pm
Forum: General
Topic: echo: system,error,critical could not save configuration changes, not enough storage space available.
Replies: 68
Views: 27725

Re: echo: system,error,critical could not save configuration changes, not enough storage space available.

Sorry to say this, but your responses were not helpful. Personally, I would have preferred no reply over the kind of answer I received. My redponse to @OP was to netinstall device. You later chimed in with claim that there's bug in flash handling in ROS (etc.) about which I expressed my doubts. Oth...
by mkx
Wed Apr 02, 2025 6:11 pm
Forum: General
Topic: [Bug-Fix-Request] DHCP-Option 82 on hEX S not disable HW-Forward by default
Replies: 13
Views: 4268

Re: [Bug-Fix-Request] DHCP-Option 82 on hEX S not disable HW-Forward by default

* If I disable hardware offload, ..... This result is reproducibly better than the same tests with hardware offload enabled! My guess is that on the RB750Gr3 not using the switch chip gives two 1Gbps links from the CPU to the ports (my tests are between ether2 and ether3), why with hardware offload...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 49