Community discussions

MikroTik App

Search found 14114 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 48
by mkx
Thu Mar 27, 2025 2:26 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 41
Views: 2066

Re: My recent VLAN fiasco [SOLVED]

In principle you don't want to set bridge port as tagged member of a VLAN if you don't intend CPU to interact with that VLAN over that bridge. [...] So I'm eager to hear use case for such setup. Huh? That's just not true. .... Let's take a very simple example: a guest WiFi network in a small office...
by mkx
Thu Mar 27, 2025 10:46 am
Forum: Wireless Networking
Topic: VLANs with wifi-qcom-ac
Replies: 3
Views: 292

Re: VLANs with wifi-qcom-ac

Depending on amount of other tasks that hAP ac2 has to perform, loosing bridge HW offload may not cause loss of wirespeed (on wired ports). Quite a while ago (I guess it was in 6.47 times) I did some tests and found out that hAP ac2 was able to bridge two ethernet ports at wirespeed with HW offload ...
by mkx
Thu Mar 27, 2025 10:34 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 508
Views: 134095

Re: v7.18.2 [stable] is released!

So it works as expected and is maxing out your 1Gbps link as the CrystalDiskMark is represented in MB/s vs Mbps which is a good thing ... and it's a black magic (pun intended) as to why it only works at half speed when SMB client is MAC device. Personally I wouldn't consider 50MB/s (give or take) &...
by mkx
Thu Mar 27, 2025 10:31 am
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 41
Views: 2066

Re: My recent VLAN fiasco [SOLVED]

What I take this changelog entry to mean is, on 7.16 or newer, if you create an /interface/vlan interface with a bridge as the parent interface, it will simply also add your bridge as a tagged member under /interface/bridge/vlan of whatever VLAN-ID you set in your vlanX interface. Sounds like a nic...
by mkx
Thu Mar 27, 2025 10:19 am
Forum: General
Topic: Upgrading CAPsMAN from 7.12.1 to 7.18.2
Replies: 3
Views: 225

Re: Upgrading CAPsMAN from 7.12.1 to 7.18.2

I've got CAPsMAN running in x86_64 hardware. Here, I've got 4 cAP ax devices connected. It's currently in 7.12.1 environment. In CAPsMAN, I've got 3 packages installed. 1. routeros 2. user-manager 3. wifiwave2 When I click "Download&Install" button, I get below error. wifi-qcom-ac-7.1...
by mkx
Thu Mar 27, 2025 10:05 am
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 41
Views: 2066

Re: My recent VLAN fiasco [SOLVED]

Since 7.16 we have this: *) bridge - added dynamic tagged entry when VLAN interface is created on vlan-filtering bridge; That removes the risk of forgetting to add the bridge CPU port to the "tagged" list of VLANs (which in older versions means no L3 access to the router through those VLA...
by mkx
Thu Mar 27, 2025 9:58 am
Forum: General
Topic: Beginner VLAN questions
Replies: 16
Views: 781

Re: Beginner VLAN questions

is capsman known to interfere with bridges/vlans? If that's a problem I'm happy to remove it. It's not. WiFi only attaches to bridge (on CAP device), when it comes to VLANs there might be a complication if CAP is running wifi-qcom -ac driver. Running CAPsMAN definitely doesn't affect the way wired ...
by mkx
Wed Mar 26, 2025 9:25 pm
Forum: Wireless Networking
Topic: L41G-2axD wifi Power
Replies: 8
Views: 457

Re: L41G-2axD wifi Power

Presence of LTE modem has nothing to do with WiFi Tx power. But I'll be damned: I went to check reg-info for Australia on different wifi devices, all running ROS 7.18.2. As I already mentioned, on Audience regulatory limit is set at 20dBm. But when checking on wAP ax I was mighty surprised, there re...
by mkx
Wed Mar 26, 2025 8:53 pm
Forum: General
Topic: Which switch?
Replies: 20
Views: 894

Re: Which switch?

Any reason to choose 1 over the other?
If nothing else helps, ask your personal numerologist :lol:

List of features of used switch chips is more or less the same, so it really is the dilemma between 8 extra ports and 8 PoE++ ports.
by mkx
Wed Mar 26, 2025 12:16 pm
Forum: Wireless Networking
Topic: L41G-2axD wifi Power
Replies: 8
Views: 457

Re: L41G-2axD wifi Power

Do not forget that WiFi is a two-way protocol, so actual speed also depends on client device's capabilities ... Indeed. Device's Tx power can limit upload speeds, but I guess this is not a huge issue (until the asymmetry is not too big) because most wireless stations use data in asymmetrical manner...
by mkx
Wed Mar 26, 2025 9:27 am
Forum: Wireless Networking
Topic: L41G-2axD wifi Power
Replies: 8
Views: 457

Re: L41G-2axD wifi Power

Actual transmitted power depends on: chipset capability (e.g. hAP ax lite can do up to 22dBm, but it gets reduced with higher interface speeds - more complex modulation schemes require tighter power control and seems that most WiFi chips are not capable of doing it at highest Tx power, hence Tx powe...
by mkx
Wed Mar 26, 2025 9:09 am
Forum: General
Topic: VLANs (not) understood
Replies: 11
Views: 598

Re: VLANs (not) understood

I am very interested to understand why we use the term "personality." You can call them "functionality" if you wish. But, as already mentioned, term "bridge" is overloaded with (actually) 3 distinct features with only vague connection (but they are strongly connected)....
by mkx
Tue Mar 25, 2025 9:08 pm
Forum: Wireless Networking
Topic: L41G-2axD wifi Power
Replies: 8
Views: 457

Re: L41G-2axD wifi Power

On my Audience, running 7.18.2, country regulatory limit for 2.4GHz band (which is all what hAP ax lite has) for Australia is the same as for Italy (and the rest of ETSI countries) ... which is 20dBm EIRP. Alas, Brazil has limit at 30dBm ... making Copacabana my place of choice for 2.4GHz band.
by mkx
Tue Mar 25, 2025 8:53 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 41
Views: 2066

Re: My recent VLAN fiasco [SOLVED]

As a bonus, many of them do not differentiate vlan 1 tagged and untagged traffic correctly. Something like this: /interface/bridge add name=bridge vlan-filtering=yes frame-types=admit-all pvid=1 /interface/bridge/port add bridge=bridge interface=ether1 frame-types=admit-all pvid=1 add bridge=bridge...
by mkx
Tue Mar 25, 2025 8:29 pm
Forum: General
Topic: VLANs (not) understood
Replies: 11
Views: 598

Re: VLANs (not) understood

1) ADD BRIDGE: "/interface/bridge add" creates a bridge with one or two roles (sometimes the word used is "personality"): (1) Switch-like and/or (2) bridge-between-CPU-and-switch (understood as #2 role when property includes "interface," "tagged," or "un...
by mkx
Tue Mar 25, 2025 8:12 pm
Forum: General
Topic: router->switch and VLAN routing
Replies: 4
Views: 324

Re: router->switch and VLAN routing

But, if the (wireless or wired) smartTVs are on VLAN10, and wifi users are on VLAN20, then am I right that for those users to use an app on their smartphones then (1) inter-vlan routing is necessary, and (2) this inter-vlan routing must take place on the RB5009? Same question for printers. Routers ...
by mkx
Tue Mar 25, 2025 8:20 am
Forum: SwOS
Topic: 5Gbps link speed
Replies: 3
Views: 343

Re: 5Gbps link speed

Perhaps someone from Mikrotik can comment on this officially?

Only if you open support ticket with Mikrotik ... e.g. by sending e-mail to support@mikrotik.com .
by mkx
Tue Mar 25, 2025 8:00 am
Forum: Beginner Basics
Topic: When is connection-nat-state applied (default firewall rule)?
Replies: 13
Views: 1347

Re: When is connection-nat-state applied (default firewall rule)?

It's not quite correct, the second rule should be:
Right. Thanks for correcting me.
by mkx
Mon Mar 24, 2025 6:29 pm
Forum: General
Topic: L7 filtering only working occasionally
Replies: 10
Views: 407

Re: L7 filtering only working occasionally

Agree with @sindy that point #1 might not be critical. But makes me think: is it possible that L7 matcher keeps collecting packets before breaking connection long enough for (web) server to log request from client ... but connection gets broken before the whole L7 interaction is finished? I'd guess ...
by mkx
Mon Mar 24, 2025 6:04 pm
Forum: Beginner Basics
Topic: VLAN Help
Replies: 12
Views: 901

Re: VLAN Help

Though that did make me look again, and I'm going to take out these rules Blocking the whole of ICMP can cause troubles (like breaking PMTUD) ... ICMP is much more than "echo request" and "echo reply". And blocking "echo request" is "security through obscurity&quo...
by mkx
Mon Mar 24, 2025 2:52 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 298
Views: 76048

Re: v7.19beta [testing] is released!

Regarding the package file size on 16MB devices. Is there a current 'best practice' for this? I havn't actually had a significant problem until now but I could not load wifiwave2 drivers on any 16MB devices with latest firmware. Would start by uninstalling Wireless, but there's just not enough spac...
by mkx
Mon Mar 24, 2025 2:44 pm
Forum: General
Topic: L7 filtering only working occasionally
Replies: 10
Views: 407

Re: L7 filtering only working occasionally

There are at least two reasons for L7 filters not to work as expected: filters only work on individual packets. If the matcher string is (inconveniently) broken into two successive packets, then matcher won't match that. It is unlikely that URL would exceed normal value of MTU (which is at or almost...
by mkx
Mon Mar 24, 2025 8:41 am
Forum: Beginner Basics
Topic: When is connection-nat-state applied (default firewall rule)?
Replies: 13
Views: 1347

Re: When is connection-nat-state applied (default firewall rule)?

/ip firewall filter add chain=forward action=drop connection-state=new connection-nat-state=!dstnat in-interface-list=WAN comment="defconf: drop all from WAN not DSTNATed" The idea is to drop all packets, which represent a new connection, in chain=forward, surviving rules so far, except f...
by mkx
Sun Mar 23, 2025 10:03 am
Forum: Beginner Basics
Topic: VLAN Help
Replies: 12
Views: 901

Re: VLAN Help

Per vlan you should have the bridge tagged as well I'm a bit confused on that part as I'm not quite sure what you mean. More direction would be greatly appreciated. In ROS bridge has multiple (more or less distinct) functions, one is CPU-facing bridge port and you have to configure it properly to a...
by mkx
Sat Mar 22, 2025 10:53 pm
Forum: Wireless Networking
Topic: RBmAP2nD as repeater/extender ? [SOLVED]
Replies: 7
Views: 1420

Re: RBmAP2nD as repeater/extender ? [SOLVED]

I've noticed majority of his devices are older and only use 2.4ghz :( He's getting around -60dBm to -70dBm . The basic idea of a "well performing WiFi repeater" is to use separate radios for serving local clients and for linking to upstream AP. It's easiest to run those radios in differen...
by mkx
Sat Mar 22, 2025 12:49 pm
Forum: General
Topic: How I Spent My Upgrade Time
Replies: 8
Views: 644

Re: How I Spent My Upgrade Time

Imagine having a single button called “Check for updates” that would do all that for you. Crazy, huh? yes, indeed! A single button that checks for updates and lets you choose which version you wish you upgrade to would be super fab! Imagine that it already exists! With a gotcha: it doesn't read you...
by mkx
Sat Mar 22, 2025 10:55 am
Forum: Wireless Networking
Topic: RBmAP2nD as repeater/extender ? [SOLVED]
Replies: 7
Views: 1420

Re: RBmAP2nD as repeater/extender ? [SOLVED]

wAP ac or wAP ax might in your case work a bit better because of mild directivity of built-in antennas. But that won't do miracles. In any case, go to your neighbours and measure signal if your current AP at the spot where you'd place the WiFi repeater. Whatever you'll see, it'll be the base line an...
by mkx
Fri Mar 21, 2025 7:29 pm
Forum: Wireless Networking
Topic: RBmAP2nD as repeater/extender ? [SOLVED]
Replies: 7
Views: 1420

Re: RBmAP2nD as repeater/extender ? [SOLVED]

They're about 250 feet away with minimal obstructions between our properties. This is very far (even without any obstructions in between) for usual APs with omnidirectional antennas, intended to cover full circke around APs with radius of around 10m/30ft. You want to build point-to-point (PtP) link...
by mkx
Fri Mar 21, 2025 2:48 pm
Forum: General
Topic: RB4011iGS+5HacQ2HnD-IN end of life?
Replies: 5
Views: 1276

Re: RB4011iGS+5HacQ2HnD-IN end of life?

Let a router be a router, let an access point be an access point.

Don't tell me ... you'd also add "let a NAS be a NAS, let a switch be a switch"?
by mkx
Fri Mar 21, 2025 9:23 am
Forum: Wireless Networking
Topic: TTL ANTI TETHERING
Replies: 3
Views: 459

Re: TTL ANTI TETHERING

and my current setup is hotspot with ttl 1 so no one can share the wifi from thier phone...or tether.. my problem is i have a extra access point and setup to repeater through wireless mode. while i repeat the signal through wifi the repeater device cant provide internet cuz of the ttl set to 1. so ...
by mkx
Fri Mar 21, 2025 9:05 am
Forum: General
Topic: Netmetal ax antenna
Replies: 19
Views: 1041

Re: Netmetal ax antenna

I am still hoping that someone from Mikrotik will chime in here and state that none of that is necessary and that the Netmetal is indeed designed to be weatherproof with the HGO antennas attached to the top. Even if they do it ... there are number of reports about problems with water ingress in ano...
by mkx
Fri Mar 21, 2025 8:38 am
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 41
Views: 2066

Re: My recent VLAN fiasco [SOLVED]

I was not suspecting it could have such an influence on other ports and other settings. The chain of dependencies goes like this: L3MTU has to be lower than L2MTU with maximum possible size (L2MTU - additional L2 overhead). With plain ethernet, there's no additional L2 overhead and with standard IP...
by mkx
Thu Mar 20, 2025 3:28 pm
Forum: General
Topic: Syslog to remote host stops working after reboot
Replies: 3
Views: 355

Re: Syslog to remote host stops working after reboot

Is it possible to set IP address instead of FQDN in remote property? The problem could be that logging is set-up before interfaces are enabled and thus resolving FQDN fails ... and that router doesn't re-try resolving it until configuration is re-done. BTW, it might help if you simply disabled/enabl...
by mkx
Thu Mar 20, 2025 3:22 pm
Forum: General
Topic: Weekly VLAN confusion post
Replies: 18
Views: 1190

Re: Weekly VLAN confusion post

I started it to (1) vent and (2) beg for help due to the massive cognitive-pain being caused by VLANs. You're asking questions ... and there are two ways of answering, each appropriate to two distinct goals of asking those questions: simple "yes" or "no" or perhaps a simple &quo...
by mkx
Thu Mar 20, 2025 3:13 pm
Forum: General
Topic: Switching capability
Replies: 3
Views: 413

Re: Switching capability

I'm not sure about what you mean by "different switching capability"? If you look at test results (Switching -> Non blocking Layer 2 throughput) you can see that both devices do wire-speed switching except for small frames (64-byte) where they peak at certain rate of packets (PPS). AFAIK s...
by mkx
Thu Mar 20, 2025 1:27 pm
Forum: General
Topic: Netmetal ax antenna
Replies: 19
Views: 1041

Re: Netmetal ax antenna

But is the Netmetal okay using HGO antennas screwed to the SMA connectors at the top with the device located outdoors? Even if connectors on netmetal itself won't leak water into the case, I'd be wary of connector corrosion as well. And water ingress into connectors themselves. For long-term optima...
by mkx
Thu Mar 20, 2025 1:19 pm
Forum: General
Topic: My recent VLAN fiasco [SOLVED]
Replies: 41
Views: 2066

Re: My recent VLAN fiasco [SOLVED]

Also as an aside, there is absolutely no reason to set the MTU of your VLANs to 1496. Don't do that, either. The L2MTU of the ethernet interfaces can more than handle the additional 4 bytes for the VLAN tag / ethertype prefixed to each tagged frame. I am pretty sure, I did not manually set those MT...
by mkx
Thu Mar 20, 2025 9:27 am
Forum: General
Topic: Wi‑Fi 7 / 802.11be
Replies: 117
Views: 46777

Re: Wi‑Fi 7 / 802.11be

Wi-Fi 7 (It says Quad-Band. Personally, no clue what that means) If one runs radio in, e.g. 80+80MHz (with frequency and slave-frequency properties properly set), then this counts as two bands. In 3GPP (mobile broadband, such as 4G or 5G, calls this "non-contiguous multi-carrier intra band CA)...
by mkx
Thu Mar 20, 2025 9:11 am
Forum: General
Topic: Weekly VLAN confusion post
Replies: 18
Views: 1190

Re: Weekly VLAN confusion post

For this topic, where VLAN Filtering is the goal, Fast Forward's status is irrelevant, it would be inactive anyway. When omitted from /interface bridge the fast-forward value defaults to yes so adding fast-forward=no is at least prudent and sometimes necessary. As written in manual, for fast-forwar...
by mkx
Thu Mar 20, 2025 8:55 am
Forum: General
Topic: Netmetal ax antenna
Replies: 19
Views: 1041

Re: Netmetal ax antenna

I think that for outdoor use it's recommended to use antennas with (short) jumper cables, which should be pretty flexible ... and use netmetal's cap again. Like this: https://www.linkshop.gr/images/thumbnails/460/460/detailed/3/MikroTik_Routerboard_NetMetal_5-5HPacD-NM-2.jpg (the blue wires on pictu...
by mkx
Thu Mar 20, 2025 8:50 am
Forum: General
Topic: DHCP Client declining a DHCP offer
Replies: 6
Views: 568

Re: DHCP Client declining a DHCP offer

In /ip/dhcp-server/network the address property should be set to network address and subnet mask. You're using 192.168.1.0/24 ... The point of this setting is to match DHCP lease address and add corresponding additional settings ... and is used when there are multiple subnets (or DHCP address pools)...
by mkx
Wed Mar 19, 2025 10:37 pm
Forum: Wireless Networking
Topic: 60GHZ link doesn't agree.
Replies: 11
Views: 4084

Re: 60GHZ link doesn't agree.

Is it possible that devices got slightly rotated on their mounting supports? E.g. wood swells/shrinks if humidity changes for longer period of time (during winter with low temperatures absolute humidity is low and wood dries). Or strong wind can move device, clamped to a pole .. either due to sheer ...
by mkx
Wed Mar 19, 2025 3:52 pm
Forum: Beginner Basics
Topic: Home network/lab upgrade question
Replies: 7
Views: 579

Re: Home network/lab upgrade question

If CRS will be used as purely L2 device (VLAN-enabled switch), then SwOS is perfectly fine (if it runs without any problems that is). If you want to use any of L3 features, then you have to run ROS on it. Performance-wise, if configuration under ROS is correct, OS choice should not matter, in both c...
by mkx
Wed Mar 19, 2025 11:24 am
Forum: General
Topic: NetINstall will not work [SOLVED]
Replies: 5
Views: 1336

Re: NetINstall will not work [SOLVED]

As soon as I select the CRS the ROS file is removed.

This sounds as mismatch in device architecture (the one reported by device to netinstall and the one of the npk file). CRS317-1G-16S+ is arm (the 32-bit one, not arm64).
by mkx
Wed Mar 19, 2025 11:19 am
Forum: General
Topic: Weekly VLAN confusion post
Replies: 18
Views: 1190

Re: Weekly VLAN confusion post

Trying with another words: "/interface bridge vlan" defines egress (leaving) behavior ... what tagged= and untagged= means Ethernet frames, transmitted by (e.g.) RJ45 port over UTP cable, have certain structure. First come some low-level bits, then comes header, then comes payload and fram...
by mkx
Wed Mar 19, 2025 8:33 am
Forum: General
Topic: IPv6 vs IPv4 - estimate general performance?
Replies: 2
Views: 412

Re: IPv6 vs IPv4 - estimate general performance?

Generally IPv4 and IPv6 have independent paths across the globe. So sometimes paths will be same, sometimes one of them will be longer than the other. I don't think there's a systematic difference though. Regarding ping times: first of all, they are only indicative as devices usually process ICMP pa...
by mkx
Wed Mar 19, 2025 8:17 am
Forum: General
Topic: Repeated disconnects on WAN (ether1)
Replies: 10
Views: 831

Re: Repeated disconnects on WAN (ether1)

Owning a private vehicle, let along driving one, is a capital offense in NYC.

It sure is capital offense ... since NYC is capital of republic of NY ... ummm, what? No republic of NY and NYC is not a capital of anything? In what weird place do you live? :wink:
by mkx
Tue Mar 18, 2025 10:08 pm
Forum: General
Topic: force a reboot when storage is full
Replies: 2
Views: 472

Re: force a reboot when storage is full

... I will to if needed ...
Unfortunately it is needed. And if you can't make config or installation slimer, then the problem will re-occur.
by mkx
Tue Mar 18, 2025 6:34 pm
Forum: Beginner Basics
Topic: Please Help Recover my 951g-2hnd Mikrotik [SOLVED]
Replies: 9
Views: 2036

Re: Please Help Recover my 951g-2hnd Mikrotik [SOLVED]

Regardless the instructions in my previous post: be prepared for failure. It cpuld well be that your RB951G reached the end of its flash disk life and if that is so, no amount of netinstalling will get it healthy again. I realky don't like the number of "total sector writes" being that low...
by mkx
Tue Mar 18, 2025 6:18 pm
Forum: Beginner Basics
Topic: Please Help Recover my 951g-2hnd Mikrotik [SOLVED]
Replies: 9
Views: 2036

Re: Please Help Recover my 951g-2hnd Mikrotik [SOLVED]

I guess that netinstall, being fragile, is best run on "bare metal" computer. Many forum users reported that linux (CLI) version is a bit less problematic. You can try booting your computer from a USB disk in "live demo" mode (or whatever it's called) and run netinstall from ther...
by mkx
Tue Mar 18, 2025 6:01 pm
Forum: Wireless Networking
Topic: Station Bridge v 7.18.2
Replies: 3
Views: 731

Re: Station Bridge v 7.18.2

wifi-qcom-ac does support bridge configuration ... it's just not compatible with wireless' bridge mode. And no, wireless package support for radio hardware ends at AC-class devices. You can't install it on AX-class device such as L22UGS-5H AX D2H AX D. station-pseudobridge doesn't require any specia...
by mkx
Tue Mar 18, 2025 5:49 pm
Forum: Beginner Basics
Topic: Please Help Recover my 951g-2hnd Mikrotik [SOLVED]
Replies: 9
Views: 2036

Re: Please Help Recover my 951g-2hnd Mikrotik [SOLVED]

Well ... files section, by default, should contain a couple of directories at least (pub/ and skins/), yours is empty. It's hard to tell what's wrong. I'd go for netinstall.
by mkx
Tue Mar 18, 2025 5:29 pm
Forum: Beginner Basics
Topic: Please Help Recover my 951g-2hnd Mikrotik [SOLVED]
Replies: 9
Views: 2036

Re: Please Help Recover my 951g-2hnd Mikrotik [SOLVED]

When trying to upload files, are you logged in as user with admin rights? Can you change any other setting (e.g. disable WAN port)? If the answer to first question is yes and to second question no, then your router is "owned", hacked ... and you no longer have admin rights. The only way ou...
by mkx
Mon Mar 17, 2025 8:11 pm
Forum: Wireless Networking
Topic: Station Bridge v 7.18.2
Replies: 3
Views: 731

Re: Station Bridge v 7.18.2

Which package do you have installed on SXTSQ 5 AC: wireless or wifi-qcom-ac? Your mANTBox ax 15s runs wifi-qcom and that one is not compatible with wireless when it comes to various *-bridge modes. OTOH, SXTSQ 5 AC has only 16MB flash which is pretty tight for routeros+wifi-qcom-ac when ROS is 7.18....
by mkx
Mon Mar 17, 2025 7:47 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 508
Views: 134095

Re: v7.18.2 [stable] is released!

hAP ac2 without wireless or wifi-qcom-ac is not a reasonably expected use of that device. Normally you would buy a hEX for that use-case. Well, for 33% of price increase one gets 300% faster device (when comparing RBD52G and RB750Gr3) ... OK, with half of RAM, but mine is one of the early ones with...
by mkx
Mon Mar 17, 2025 7:16 pm
Forum: General
Topic: CRS520 hw-offloading problem
Replies: 19
Views: 1052

Re: CRS520 hw-offloading problem

The green, blue and red can be actually single bridge. The orange is a complication as @lurker wrote. To me it's moot as to why it's necessary to use two different VLANs from "the lower SwitchY" to CRS if they are eventually merged into same broadcast domain.
by mkx
Mon Mar 17, 2025 6:55 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 508
Views: 134095

Re: v7.18.2 [stable] is released!

16 MB devices should not be used as routers any more. For me, hAP ac2 without wireless or wifi-qcom-ac works great as router. With around 2MB flash free. But with admittedly pretty simple config. So it's not "not as router" or "not as AP", rather it's "pretty barebone"...
by mkx
Mon Mar 17, 2025 3:35 pm
Forum: General
Topic: forum guru status
Replies: 27
Views: 1789

Re: Guru?!?!?

I will but, one should not think that more slaps are better!!
https://www.youtube.com/watch?v=IhJQp-q ... xhcA%3D%3D
:lol:
by mkx
Mon Mar 17, 2025 3:25 pm
Forum: General
Topic: NetMetal AX vs. Netbox 5 AX
Replies: 19
Views: 1124

Re: NetMetal AX vs. Netbox 5 AX

The circle with 3db smaller radius is a circle with half the radius, which is what I have drawn (there are two circles drawn over the image, one with Dia 1 and one with Dia 0.5). No, you drew circle with maximum gain (+7dBi) and circle with approx -12dBi (so 19dB difference in power which is factor...
by mkx
Mon Mar 17, 2025 1:52 pm
Forum: General
Topic: CRS520 hw-offloading problem
Replies: 19
Views: 1052

Re: CRS520 hw-offloading problem

Unfortunately I need to return the box to supplier since my set up needs multiple bridges. Do you care to elaborate the need? So far I can only think of a single case when more than one bridge would be needed (when VLANs are in use, two distinct subnets use same VID and switch admin doesn't have an...
by mkx
Mon Mar 17, 2025 1:48 pm
Forum: General
Topic: forum guru status
Replies: 27
Views: 1789

Re: Guru?!?!?

That is to say, there appears to be a bug in the member ranking system.

Many of forum members had the same thought when @anav became Guru :wink:
by mkx
Mon Mar 17, 2025 12:23 pm
Forum: General
Topic: NetMetal AX vs. Netbox 5 AX
Replies: 19
Views: 1124

Re: NetMetal AX vs. Netbox 5 AX

Try applying the 0.5 circle on that pattern image, and you will see that (according to the half power definition) it is apparently an omnidirectional (which it isn't). The definition talks about "main lobe" ... and each antenna has exactly one main lobe, on your diagram the one pointing d...
by mkx
Mon Mar 17, 2025 12:14 pm
Forum: General
Topic: Mikrotik SUCKS
Replies: 104
Views: 30655

Re: Mikrotik SUCKS

I tend to agree with @tombs. I see MT stuff as a cross-over between serious stuff (e.g. cisco) and cheap home-rated stuff (e.g. Dlink), which takes good things from each of worlds. Do I use it at home? Yes, absolutely, and I'm happy with feature set and prices. Would I use it in corporate environmen...
by mkx
Mon Mar 17, 2025 12:08 pm
Forum: General
Topic: Request for Latest Modified Kernel Source Code and Ongoing Updates under GPL License
Replies: 38
Views: 2463

Re: Request for Latest Modified Kernel Source Code and Ongoing Updates under GPL License

@Josephny ask a good question - even if the "why" is immaterial under GPL Another benefit, is that tools like GitHub (or any static code analyzer) can be used to "double check" that the specific patches don't contain obvious vulnerabilities. Of course that only forks if vendor p...
by mkx
Mon Mar 17, 2025 12:03 pm
Forum: Beginner Basics
Topic: mikrotik stuck on 100Mb [SOLVED]
Replies: 14
Views: 5280

Re: mikrotik stuck on 100Mb [SOLVED]

Oh my ... So you need to fast-track DNS connections. Since normal clients will only connect DNS server when they need to resolve FQDN into IP address (and that's not even necessary for each connection, e.g web browsers tend to open multiple parallel connections towards the same server ... and perhap...
by mkx
Sun Mar 16, 2025 10:04 pm
Forum: General
Topic: NetMetal AX vs. Netbox 5 AX
Replies: 19
Views: 1124

Re: NetMetal AX vs. Netbox 5 AX

I would say that while interference from 120* extremely close neighbor antennas is typically not the problem It can be depending on geometry. Devices don't like "being shouted at" and two close APs operating on same frequency will be shouting at each other. APs, operating on diffetent fre...
by mkx
Sun Mar 16, 2025 9:48 pm
Forum: General
Topic: NetMetal AX vs. Netbox 5 AX
Replies: 19
Views: 1124

Re: NetMetal AX vs. Netbox 5 AX

It is debatable whether is 90° or more like 120*. Not really. By definition (see wikipedia article width/height of antenna beam is defined by width/height of main lobe, which is the angle at which radiated power drops to half of maximum (i.e. 3dB lower than max). And judging from the radiation patt...
by mkx
Sun Mar 16, 2025 8:59 pm
Forum: General
Topic: Request for Latest Modified Kernel Source Code and Ongoing Updates under GPL License
Replies: 38
Views: 2463

Re: Request for Latest Modified Kernel Source Code and Ongoing Updates under GPL License

You can recompile the kernel to update or load third-party software and hardware drivers. Don't forget that kernel features need to be configured and/or coupled with userland tools and services. Those are not bound by GPL covering kernel. So it would be extremely hard to replace kernel and still ha...
by mkx
Sun Mar 16, 2025 11:00 am
Forum: Wireless Networking
Topic: DHCPv4 fails to assign IP address over WiFi on 7.17.0/1/2
Replies: 2
Views: 2097

Re: DHCPv4 fails to assign IP address over WiFi on 7.17.0/1/2

The default configuration has /interface/wifi/channel/add name=5GHz width=20/40/80/160mhz I doubt that default config would include bits not supported by hardware. Default config (you can always check it by running /system/default-configuration/print ) in my wAP ax has channel.band=5ghz-ax channel....
by mkx
Sat Mar 15, 2025 9:26 pm
Forum: General
Topic: Reading test results [SOLVED]
Replies: 3
Views: 2492

Re: Reading test results [SOLVED]

The rule you're mentioning is "rule of thumb". But it comes with disclaimer: actual performance very much depends on actual confuguration and it's possible that actual performance will be a lot higher than the rule of thumb estimation. I believe that MT considers hEX refresh a true gigabit...
by mkx
Sat Mar 15, 2025 9:06 pm
Forum: General
Topic: RB411 downgrade kernel panic
Replies: 8
Views: 648

Re: RB411 downgrade kernel panic

Make sure that you'll be operating within frequencies allowed in your country. For example, in ETSI countries GSM/LTE/5G uses frequencies around the 900MHz WiFi (band 8: 880MHz – 915MHz and 925MHz – 960MHz) ... and you really don't want to interfere with mobile networks, you may receive a visit of o...
by mkx
Sat Mar 15, 2025 1:48 pm
Forum: MikroTik hardware questions
Topic: Inquiry on NVMe over TCP & NVMe over RDMA/RoCE on MikroTik Rose Storage Server
Replies: 1
Views: 514

Re: Inquiry on NVMe over TCP & NVMe over RDMA/RoCE on MikroTik Rose Storage Server

The product you're asking about (RDS) is not yet wildely available. So normal users don't have experience with it. And this forum is user-user forum, it's not official MT means of support or marketing. Which means that to get answers to your questions, you should contact MT support directly (e.g. vi...
by mkx
Sat Mar 15, 2025 1:23 pm
Forum: MikroTik hardware questions
Topic: Mikrotik CRS317-1G-16S+RM - These 16MB only Flash Devices are driving me Crazy
Replies: 2
Views: 590

Re: Mikrotik CRS317-1G-16S+RM - These 16MB only Flash Devices are driving me Crazy

... Wireless (that gets/got installed automatically and is updated together with RouterOS ?). That's a remnant of pre-7.13 setup where contents of modern "wireless" package were integral part of routeros package. Upgrader inside ROS is not particularly smart so it can't drtermine if some ...
by mkx
Sat Mar 15, 2025 1:11 pm
Forum: Wireless Networking
Topic: CAPsMAN instructions result in "Invalid value in Master"
Replies: 57
Views: 7398

Re: CAPsMAN instructions result in "Invalid value in Master"

2) The CLI really did not like "2g-probe-delay=yes" and I can't find the option in the GUI either. *shrug* You never posted full config ... with the initial "comment" lines ... so the actual ROS versions runing on your CAPsMAN and CAP are not known. The property 2g-probe-delay i...
by mkx
Sat Mar 15, 2025 12:57 pm
Forum: Wireless Networking
Topic: No default steering neighbour group with CAPsMAN [SOLVED]
Replies: 34
Views: 13682

Re: No default steering neighbour group with CAPsMAN [SOLVED]

Wireless clients always decide on their own when to abandon old BSSID. The benefit of having proper roaming set up on infrastructure side is a) clients get a list of "good roaming candidates" so they can measure other BSSIDs faster - no need to read SSID names on all supported WiFi channel...
by mkx
Sat Mar 15, 2025 12:23 pm
Forum: General
Topic: Cannot change back the CPU frequency [SOLVED]
Replies: 14
Views: 8579

Re: Cannot change back the CPU frequency [SOLVED]

I can only confirm that on my LHG 5ac the problem persists on 7.18.2: I'm not sure your post illustrates the persistence of the problem. The way things are supposed to work: print of routerboard settings will didpkay warning if CPU frequency is not set to default. And setting CPU frequency on ROS v...
by mkx
Sat Mar 15, 2025 11:40 am
Forum: General
Topic: RB411 downgrade kernel panic
Replies: 8
Views: 648

Re: RB411 downgrade kernel panic

I'd go with v6 ... some of later versions (6.49.x). If those wireless chipsets are supported by that ROS version, they should be most stable. I wouldn't expect too much of performance using 900MHz WiFi ... depending on country there's between 1MHz and 8MHz if bandwidth available (in some countries e...
by mkx
Sat Mar 15, 2025 11:24 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 508
Views: 134095

Re: v7.18.2 [stable] is released!

QQ: is it safe to upgrade routerboard firmware to v7.18.2 in RB4011? In the past I've had stability issues and I've found that "firmware" 7.7 to be behaving okay. I don't see too many reports regarding instability of recent ROS/routerboard versions on RB4011 ... so your observations might...
by mkx
Sat Mar 15, 2025 11:03 am
Forum: Beginner Basics
Topic: Multiple bridges for multiple switch chips on CCR2004-16G-2S+?
Replies: 9
Views: 702

Re: Multiple bridges for multiple switch chips on CCR2004-16G-2S+?

Regarding HW offload: there are two places with similar setting ... bridge and individual ports. In case there are more bridges than switch chips or of port layout doesn't follow physical layout, then ROS will decide which bridge will be offloaded (and which won't). Sometimes such automatic decissio...
by mkx
Sat Mar 15, 2025 10:50 am
Forum: Beginner Basics
Topic: DoH Mullvad/Yandex
Replies: 12
Views: 6032

Re: DoH Mullvad/Yandex

My guess: supporting H2 blows the ROS bundle out of 16MB flash.
This can be allocated as a separate option or package or made disabled by default with a warning that by enabling ...

Installed but disabled feature still occupies flash storage ... which is the only point of post by @infabo
by mkx
Sat Mar 15, 2025 10:44 am
Forum: Beginner Basics
Topic: DoH Mullvad/Yandex
Replies: 12
Views: 6032

Re: DoH Mullvad/Yandex

How about starting support for HTTP2 ? Mind that whichever HTTP version is supported in ROS, it's only used for management (and proxy). It doesn't affect ability to route "unknown" protocols. So I have a question: what benefits does HTTP/2 have over HTTP/1.1 (with TLS1.3) in context of ma...
by mkx
Fri Mar 14, 2025 10:23 pm
Forum: General
Topic: RB411 downgrade kernel panic
Replies: 8
Views: 648

Re: RB411 downgrade kernel panic

There are two distinct pieces of software in Routerboard devices: routerboot, referred as "firmware" ... in PC world this is like BIOS/UEFI /system/routerboard routerOS, referred as "software" ... in PC world this is like Windows or Linux /system/resources Up until around 6.45 ea...
by mkx
Fri Mar 14, 2025 9:55 pm
Forum: General
Topic: RB411 downgrade kernel panic
Replies: 8
Views: 648

Re: RB411 downgrade kernel panic

Devices concieved in last 10 years have minimum ROS version set. I'm pretty sure RB4011 can't run anything older than around 6.40 (or a bit newer), anything older will almost definitely lack some drivers or even lack support for CPU architecture. I'm actually surprised that netinstall allowed you to...
by mkx
Fri Mar 14, 2025 5:59 pm
Forum: Wireless Networking
Topic: No default steering neighbour group with CAPsMAN [SOLVED]
Replies: 34
Views: 13682

Re: No default steering neighbour group with CAPsMAN [SOLVED]

Steering only works for radios, controlled by same entity. That can be two radios (on individual device with dual-band support) or many radios if controlled by CAPsMAN.
by mkx
Fri Mar 14, 2025 5:55 pm
Forum: General
Topic: EoIP and MTU
Replies: 13
Views: 3223

Re: EoIP and MTU

Just set IPIP tunnel's property mtu to 1500 ... it'll handle the necessary fragmentation and defragmentation (on the receiver side) just fine.
by mkx
Fri Mar 14, 2025 5:47 pm
Forum: Beginner Basics
Topic: Multiple bridges for multiple switch chips on CCR2004-16G-2S+?
Replies: 9
Views: 702

Re: Multiple bridges for multiple switch chips on CCR2004-16G-2S+?

If one configures single bridge and VLANs span both switch chips ... then sure, CPU will work a bit to pass frames between both switch chips. Other than that this setup should not pose a bottleneck as both CPU-switch interconnects are 10Gbps (while each switch chip runs 8x 1Gbps port). So yes, sugge...
by mkx
Fri Mar 14, 2025 5:36 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 508
Views: 134095

Re: v7.18.2 [stable] is released!

And I'd say that all multi-byte characters (UTF-8 or any other multi-byte encoding) are problematic as well. Guys do you have a comprehensive list about it? Regarding characters: just take the basic US ASCII characters ... and exclude the characters mentioned by @pe1chl ... and you should be safe. ...
by mkx
Fri Mar 14, 2025 3:28 pm
Forum: General
Topic: hAP ax3 issues with wireless after upgrade
Replies: 23
Views: 2207

Re: hAP ax3 issues with wireless after upgrade

Reselect might choose a different Control channel, still the same frequencies. Technically 80MHz channel on e.g. AX is one 20MHz "full featured" channel (marked with C in ROS) plus supplemental channels (adjacent, which side depends on actual channel layout; marked with e in ROS). And the...
by mkx
Fri Mar 14, 2025 2:35 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 508
Views: 134095

Re: v7.18.2 [stable] is released!

In any system that involves things like scripting languages, web interfaces, etc I at least avoid these characters all the time: @ % " $ & # + < > (space) That never hurts even when it is not really necessary. And I'd say that all multi-byte characters (UTF-8 or any other multi-byte encodi...
by mkx
Fri Mar 14, 2025 10:45 am
Forum: General
Topic: ipv6 fixed prefix router advertisements
Replies: 9
Views: 723

Re: ipv6 fixed prefix router advertisements

I'm out of ideas ...
by mkx
Fri Mar 14, 2025 9:15 am
Forum: Wireless Networking
Topic: CAPsMAN instructions result in "Invalid value in Master"
Replies: 57
Views: 7398

Re: CAPsMAN instructions result in "Invalid value in Master"

I guess it's time to clean up the CAPsMAN configuration ... all of it. I strongly recommend you to use profiles properly. And to set things explicitly instead of leaving them on defaults, ROS sometimes makes poor decisions if let on auto. E.g. /interface wifi channel add frequency=5500 name=5GHz-550...
by mkx
Fri Mar 14, 2025 8:41 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 508
Views: 134095

Re: v7.18.2 [stable] is released!

For what it matters, the passwords I'm using there is very strong and come with a very special characters, so maybe the upgrade didn't appreciate some of those special characters ... It could be the issue between GUI and ROS regarding character coding. IIRC MT is doing some minor tweaks in this reg...
by mkx
Fri Mar 14, 2025 8:18 am
Forum: General
Topic: RouterOS License Level 2?
Replies: 3
Views: 572

Re: RouterOS License Level 2?

What would be the point of it? License levels 0-6 only apply to MT's own hardware and all of their hardware comes installed with license level at least 3 (most devices 5, some 4, some 6). x86 (bare metal) homelab mostly, but I realize that’s an edge case. Since ROS support for hardware is mediocre ...
by mkx
Fri Mar 14, 2025 8:10 am
Forum: General
Topic: ipv6 fixed prefix router advertisements
Replies: 9
Views: 723

Re: ipv6 fixed prefix router advertisements

That probably means that you have to set one IPv6 address from that prefix on your WAN interface. You're mentioning PPPoE, I'm not sure if you can set static IPv6 address on that interface, never tried. And then you'd have to set advertise=yes for that IPv6 address. I can see one problem (which migh...
by mkx
Thu Mar 13, 2025 8:04 pm
Forum: MikroTik hardware questions
Topic: Chateau Pro ax - Wi-Fi radio stops completely [failed to set country]
Replies: 18
Views: 3783

Re: Chateau Pro ax - Wi-Fi radio stops completely [failed to set country]

My advice: Get your Chateau Pro into working state (reboot or whatever it tskes), take supout file as reference (when it works). Then wait for Chateau Pro to fail again. Create another supout file. Then restart wifi interfaces (to see the dreaded message) and create the third supout file. When you h...
by mkx
Thu Mar 13, 2025 7:58 pm
Forum: MikroTik hardware questions
Topic: One of working VLAN stopped
Replies: 4
Views: 698

Re: One of working VLAN stopped

Let me check my crystall ball .... nah, I can't see anything, it's all foggy.

Sorry, you'll have to give us much more details. Preferrably actual device config as a starting point (and test case which shows the problem).
by mkx
Thu Mar 13, 2025 7:53 pm
Forum: General
Topic: ipv6 fixed prefix router advertisements
Replies: 9
Views: 723

Re: ipv6 fixed prefix router advertisements

it should work with prefix delegation, they route over the dynamic address.

in this case please elaborate on
From my provider i got an fixed ipv6 prefix ::/48
How exactly did you get that "fixed" prefix?
by mkx
Thu Mar 13, 2025 7:46 pm
Forum: Wireless Networking
Topic: CAPsMAN instructions result in "Invalid value in Master"
Replies: 57
Views: 7398

Re: CAPsMAN instructions result in "Invalid value in Master"

For IoT you'll have to add bridge port as tagged member of VLAN 6: /interface bridge vlan add bridge=bridge comment=IOT tagged= bridge, ether5,ether7 untagged=ether6 vlan-ids=6 If you want CRS to participate in GUEST VLAN (so far I don't see any need for it, your firewall handkes it), then you have ...
by mkx
Thu Mar 13, 2025 7:12 pm
Forum: Wireless Networking
Topic: Less detail on Tx/Rx Rate on hAP ax lite LTE
Replies: 6
Views: 740

Re: Less detail on Tx/Rx Rate on hAP ax lite LTE

Want it or not, there are very slim chances to get it changed. We've been complaining about missing features (including spectral scans, connection details, lack of nv2 and/or nstreme) ever since wifiwave2 existed ... and these features are still missing. To be fair, some were implemented (at least i...
by mkx
Thu Mar 13, 2025 7:01 pm
Forum: General
Topic: ipv6 fixed prefix router advertisements
Replies: 9
Views: 723

Re: ipv6 fixed prefix router advertisements

Ask your ISP about how is your fixed ::/48 being delivered to you (they might have mentioned a static IPv6 address to be set on router or something like that). The fact is that ISP's router needs to know your router's wan LLA to route your prefix towards you ... and setting addresses on your side do...
by mkx
Thu Mar 13, 2025 6:47 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 508
Views: 134095

Re: v7.18.2 [stable] is released!

ever upgraded a linux server? A milion times (literally). nearly every package is also downloaded via HTTP (e.g. in "apt upgrade"...) Not on my servers, I always edit sources.list and change http to https. Just to be clear: personally I don't see any issue with http for fetching packages....
by mkx
Thu Mar 13, 2025 9:04 am
Forum: General
Topic: No responce by SNMP
Replies: 10
Views: 2090

Re: No responce by SNMP

For chain=input, obviously out interface will always be unknown (because there isn't one). Your problem lies elsewhere but I don't know where. It could be the way SNMP engine works with clients, but I'm not using SNMP on my MT devices. Just a trivial check: you do have "action=accept chain=inpu...
by mkx
Thu Mar 13, 2025 8:57 am
Forum: General
Topic: Allow backup to memory
Replies: 4
Views: 503

Re: Allow backup to memory

Ah. In all my years of using ROS I never created backup without explicitly specifying file name...
by mkx
Thu Mar 13, 2025 8:38 am
Forum: Wireless Networking
Topic: CAPsMAN instructions result in "Invalid value in Master"
Replies: 57
Views: 7398

Re: CAPsMAN instructions result in "Invalid value in Master"

1. To add guest SSID, you have to set slave-configurations to appropriate items in wifi/provisioning ... I was trying to set it as a master on the 2.4 which isn't being used right now. I'd prefer that MAIN be only 5Ghz and GUEST be only 2.4Ghz. So is it "master" per frequency? Or is it &q...
by mkx
Thu Mar 13, 2025 8:31 am
Forum: Wireless Networking
Topic: Less detail on Tx/Rx Rate on hAP ax lite LTE
Replies: 6
Views: 740

Re: Less detail on Tx/Rx Rate on hAP ax lite LTE

So the new WiFi driver has less features that the old Wireless driver :-(

Yes. Get used to it.
by mkx
Thu Mar 13, 2025 8:29 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 508
Views: 134095

Re: v7.18.2 [stable] is released!

Is the upgrade packages are really downloaded via http? Why? Why not? If https is used, then client can verify authenticity of server it's talking to. Yes, npk files do have some verification built in (I believe that packages are digitally signed by MT so it's not trivial to alter the contents). Bu...
by mkx
Thu Mar 13, 2025 8:25 am
Forum: General
Topic: Allow backup to memory
Replies: 4
Views: 503

Re: Allow backup to memory

But I cannot create a "Backup" as it automatically tries to save the .backup file to flash, which fails when it hits 16/16MB. Are you sure about it? When I save backup, the resulting file ends up on the very same location as export does (which on devices with only 16MB flash and 64+MB RAM...
by mkx
Thu Mar 13, 2025 8:20 am
Forum: General
Topic: Bridge VLAN Filtering Problem
Replies: 24
Views: 1912

Re: Bridge VLAN Filtering Problem

I love how we are attacked for reporting a behaviour that seems odd and it takes a mikrotik and 10 minutes to test. The problem with discussion so far is that I still don't know which kind of device @OP was working with (and when I asked him to provide details, he outright rejected to give them). I...
by mkx
Thu Mar 13, 2025 8:09 am
Forum: General
Topic: RouterOS License Level 2?
Replies: 3
Views: 572

Re: RouterOS License Level 2?

What would be the point of it? License levels 0-6 only apply to MT's own hardware and all of their hardware comes installed with license level at least 3 (most devices 5, some 4, some 6). If you're thinking about CHR (to be run in virtual machine), then look one table lower ... license levels Free, ...
by mkx
Wed Mar 12, 2025 8:28 pm
Forum: Wireless Networking
Topic: Wifi Wave2 and CapsMan V 3
Replies: 3
Views: 571

Re: Wifi Wave2 and CapsMan V 3

VLANs were so simple with CapsMan V2. Are VLANs impossible with CapsMan V3? The problem lies in wifi-qcom-ac driver, which you had to use on hAP ac3 ... it doesn't support manipulations of VLAN tags. The other driver (wifi-qcom ... for AX and newer CAPs) does support manipulating VLANs in similar f...
by mkx
Wed Mar 12, 2025 4:26 pm
Forum: MikroTik hardware questions
Topic: Home use router with future thinking
Replies: 13
Views: 1077

Re: Home use router with future thinking

Why not to FTTH? Because it's for multi mode fiber and FTTH (or any MAN) uses single mode fiber. And there are a few technologies for WAN fiber: FTTH using two fiber cores (one per direction), most often used wavelength is 1310 nm ... BiDi FTTH, where single fiber core carries traffic in both direc...
by mkx
Wed Mar 12, 2025 4:17 pm
Forum: General
Topic: Upgrade or no (revisited)
Replies: 13
Views: 944

Re: Upgrade or no (revisited)

Should I upgrade to 7.18.x? ... Do we hold by the "if it's working, don't touch it" approach? As @anav already hinted: have a look at new features, introduced since your running ROS version. If your current setup is running fine ,then you don't really have to look at bug-fixes since any b...
by mkx
Wed Mar 12, 2025 12:29 pm
Forum: MikroTik hardware questions
Topic: hAP ax GPON ?
Replies: 20
Views: 1762

Re: Goon

here is information from an official source
https://box.mikrotik.com/f/1f880747e77346a3bf7f/

And this is a slightly different model according to the photo.
I'd say it's the same model. PDF contains a render, you showed a photo.
by mkx
Wed Mar 12, 2025 12:25 pm
Forum: Wireless Networking
Topic: CAPsMAN instructions result in "Invalid value in Master"
Replies: 57
Views: 7398

Re: CAPsMAN instructions result in "Invalid value in Master"

Manual provision can be done under /interface/wifi/capsman/remote-cap/provision to provision all radios associated with specific CAPs, it can also be done under /interface/wifi/radio/provision , to provision specific radios. Thanks for this ... I'll try it next time something won't be provisioned a...
by mkx
Wed Mar 12, 2025 12:20 pm
Forum: General
Topic: Bridge VLAN Filtering Problem
Replies: 24
Views: 1912

Re: Is this a bug or something not documented

You don't need my config Which I translate into: you don't need my help. Out of courtesy, here's explanation: if you have a problem and can't solve it yourself, then you're not really competent to decide which information is crucial for problem analysis and which is not. If you are sure I don't nee...
by mkx
Wed Mar 12, 2025 9:22 am
Forum: Wireless Networking
Topic: CAPsMAN instructions result in "Invalid value in Master"
Replies: 57
Views: 7398

Re: CAPsMAN instructions result in "Invalid value in Master"

Removing dynamic entry is not needed. Just reprovision. Same result but the way of handling it is different (re-apply versus destroying, I prefer the positive approach :lol: )
I'd probably do it as well ... but so far I didn't find the right command. Can you enlighten me?
by mkx
Wed Mar 12, 2025 9:17 am
Forum: General
Topic: Bridge VLAN Filtering Problem
Replies: 24
Views: 1912

Re: Is this a bug or something not documented

Can you post full config of the switch (redact sensitive information, like serial number, but don't overdo it)? And leave model number in it, some devices have some quirks due to hardware layout.
by mkx
Wed Mar 12, 2025 8:30 am
Forum: MikroTik hardware questions
Topic: hAP ax GPON ?
Replies: 20
Views: 1762

Re: GPON

... if the cost of this unit is between 18 to 20 USD ...

Not likely ... device looks like hEX refresh with wireless and GPON interface. And hEX refresh has MSRP of 60 USD.
by mkx
Wed Mar 12, 2025 8:26 am
Forum: General
Topic: Bridge VLAN Filtering Problem
Replies: 24
Views: 1912

Re: Is this a bug or something not documented

mkv you are correct ether 1 pvid should be 1 not 2 ... that doesn't change anything because on ether 1 device there is only vids 2, 5, 145 So to clarify the gateway 10.0.2.1 which has the DHCP comes in on VID 2 on ether 1 So you're saying that device, connected to ether1, talks tagged VLAN 2? In th...
by mkx
Wed Mar 12, 2025 7:08 am
Forum: Wireless Networking
Topic: CAPsMAN instructions result in "Invalid value in Master"
Replies: 57
Views: 7398

Re: CAPsMAN instructions result in "Invalid value in Master"

1. To add guest SSID, you have to set slave-configurations to appropriate items in wifi/provisioning ... And you'll have to make ether7 (interconnect between CAPsMAN and CAP) a hybrid port to allow it to pass tagged frames from guest wifi. Datapath for main also mentions tagging frames, ypu'll have ...
by mkx
Tue Mar 11, 2025 11:08 pm
Forum: Wireless Networking
Topic: Fast Transition between Mikrotik and OpenWRT devices
Replies: 3
Views: 647

Re: Fast Transition between Mikrotik and OpenWRT devices

802.11k/v instead should work among APs off different vendors. At least in theory. Alas in practice one should then manually set list of possible roaming targets (on the other vendor's equipment), but that in ROS is not possible (yet?). As it is now, CAPsMAN does it via steering groups (either auto...
by mkx
Tue Mar 11, 2025 10:57 pm
Forum: Wireless Networking
Topic: CAPsMAN instructions result in "Invalid value in Master"
Replies: 57
Views: 7398

Re: CAPsMAN instructions result in "Invalid value in Master"

OK, now you have basics working. If you want to add guest wifi network, then you'll have to add VLANs into the game. And that will involve: CAPsMAN device, all switches, main router and optionally CAP device. It seems that you have one switch which is CAPsMAN as well (so that brings down number of d...
by mkx
Tue Mar 11, 2025 10:25 pm
Forum: General
Topic: hAP ax3 issues with wireless after upgrade
Replies: 23
Views: 2207

Re: hAP ax3 issues with wireless after upgrade

As you are using the exact range of channel 36, no need to do a reselect. Since width property doesn't define channel layout any more (in old times that would be equivalent to setting XXXX), AP could reselect e.g. from 5180-Ceee to e.g. 5200-eCee. It does seem that MT jumped (or was, by using chips...
by mkx
Tue Mar 11, 2025 10:10 pm
Forum: General
Topic: Bridge VLAN Filtering Problem
Replies: 24
Views: 1912

Re: Is this a bug or something not documented

Configuration of ether1 is contradictory: /interface bridge port add bridge=bridge interface=ether1 pvid=2 /interface bridge vlan add bridge=bridge tagged=ether1 vlan-ids=2 So ether1 it will tag untagged frames with PVID on ingress but won't untag them on egress. It will accept tagged frames, tagged...
by mkx
Tue Mar 11, 2025 8:53 am
Forum: Wireless Networking
Topic: CAPsMAN instructions result in "Invalid value in Master"
Replies: 57
Views: 7398

Re: CAPsMAN instructions result in "Invalid value in Master"

So let's try to do some cleaning ... first on CAPsMAN device. We're still not focusing on correct radio provisioning, we're just focusing on getting CAP communicating with CAPsMAN. The red text with strikethrough are parts to be removed, green parts are to be added (or property value changed). /inte...
by mkx
Tue Mar 11, 2025 8:32 am
Forum: General
Topic: PPPoE Compatibility Issues with vBRAS/NFV
Replies: 24
Views: 2808

Re: PPPoE Compatibility Issues with vBRAS/NFV

It seems your ISP is "faking" MAC address of BRAS ... 00:00:5E is registered to "ICANN, IANA Department" ...
by mkx
Tue Mar 11, 2025 8:27 am
Forum: Beginner Basics
Topic: CRS 317-1G-16S+ Can't be seen on Network [SOLVED]
Replies: 3
Views: 2054

Re: CRS 317-1G-16S+ Can't be seen on Network [SOLVED]

Your CRS should behave same as other ROS devices with regard to reset button behaviour. Unless that was explicitly configured differently.
by mkx
Tue Mar 11, 2025 8:25 am
Forum: Beginner Basics
Topic: Firewall Filter Rules - Beginner Help
Replies: 8
Views: 984

Re: Firewall Filter Rules - Beginner Help

If it works for you, then yes, settings should be fine. As long as you make sure that interface list memberships are maintained properly (no, LAN on WAN interface lists aren't anything magical, it's up to device admin to maintain lists). I wonder though why you decided to ditch default setup and go ...
by mkx
Mon Mar 10, 2025 9:51 pm
Forum: MikroTik hardware questions
Topic: Metal 5shpn dead rf?
Replies: 1
Views: 497

Re: Metal 5shpn dead rf?

I'd check antenna cables ... for water ingress. That's the common thing between Rx and Tx (and antenna itself).
by mkx
Mon Mar 10, 2025 6:49 pm
Forum: General
Topic: PPPoE Compatibility Issues with vBRAS/NFV
Replies: 24
Views: 2808

Re: PPPoE Compatibility Issues with vBRAS/NFV

If you run
/interface/pppoe-client/monitor 0 once
then you'll see MAC address of BRAS (ac-mac) ... which might indicate venfor of BRAS. Some ISPs even disclose some technical info in ac-name (my ISP included "ASR9910" and name of their core location in ac-name).
by mkx
Mon Mar 10, 2025 6:31 pm
Forum: General
Topic: How do i lock the reset button form being reset?
Replies: 2
Views: 565

Re: How do i lock the reset button form being reset?

@sohrab: if you want to prevent reset button from wiping away the custom config, then you can construct "custom default" config and upload it while using netinstall (option "Configure script"): https://help.mikrotik.com/docs/spaces/R ... Netinstall
by mkx
Mon Mar 10, 2025 11:03 am
Forum: MikroTik hardware questions
Topic: NetMetal ax - help
Replies: 9
Views: 1024

Re: NetMetal ax - help

There's one big problem with settings: unless you try real hard, country regulations regarding Tx power will kick in. On 5GHz different channels have different limits, e.g. in ETSI countries 5170-5330MHz allow 23dBm, 5490-5730 allow 30dBm and 5730-5875 allow only 14dBm. And that's EIRP ... substract...
by mkx
Mon Mar 10, 2025 10:49 am
Forum: General
Topic: ROS 7.x and SSH login to other MT problem
Replies: 1
Views: 651

Re: ROS 7.x and SSH login to other MT problem

On my 7.18.1 devices, setting parameter user on ssh command does work (it does connect as another user on remote side ... but I'm using passwords to authenticate). Which opens a question about whether you properly installed public SSH key on RouterB. If you're running ssh command as user1 on routerA...
by mkx
Mon Mar 10, 2025 10:42 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 298
Views: 76048

Re: v7.19beta [testing] is released!

But after uploading the older routeros .npk into Files and running /system/packages/downgrade, and rebooting, the version does not change. Does anything with regard to this appear in /log ? One thing to worry: if you're downgrading, you have to upload .npk files for all packages installed ... for R...
by mkx
Mon Mar 10, 2025 9:15 am
Forum: MikroTik hardware questions
Topic: hAP ax GPON ?
Replies: 20
Views: 1762

Re: Goon

GPON - True or false.
Why the question?
by mkx
Mon Mar 10, 2025 9:13 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 298
Views: 76048

Re: v7.19beta [testing] is released!

Worse, I cannot downgrade.
If you upgraded to 7.19beta from 7.17.x or older, then you may have to properly set-up device mode prior to downgrading https://help.mikrotik.com/docs/spaces/R ... evice-mode
by mkx
Mon Mar 10, 2025 8:55 am
Forum: MikroTik hardware questions
Topic: NetMetal ax - help
Replies: 9
Views: 1024

Re: NetMetal ax - help

Searching for Mikrotik HGO yields this: https://mikrotik.com/product/hgo_antenna_out ... it's a mediocre omni-directional antenna, not fit for long range point-to-point links that @OP seems to want to build. I already explained the problem in another thread , but @OP doesn't seem to accept the reali...
by mkx
Mon Mar 10, 2025 8:44 am
Forum: Wireless Networking
Topic: CAPsMAN instructions result in "Invalid value in Master"
Replies: 57
Views: 7398

Re: CAPsMAN instructions result in "Invalid value in Master"

Which device's config is the one you posted in preceding post? You're mixing CAPsMAN and CAP config.

Why do you add bridgeLocal? I don't think it's needed on either device.
by mkx
Mon Mar 10, 2025 8:29 am
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 298
Views: 76048

Re: v7.19beta [testing] is released!

Can someone explain what does this mean? *) dhcpv4-server - "Relay-Agent-Information" (82) option moved at the end of option list in response packets; It's about structure of DHCP server's response packet ... some DHCP clients are sensitive regarding order in which different DHCP options ...
by mkx
Sun Mar 09, 2025 11:22 pm
Forum: MikroTik hardware questions
Topic: Chateau 5G ax antennas
Replies: 2
Views: 665

Re: Chateau 5G ax antennas

Product brochure says: We’ve made massive improvements to the wireless radio and antennas. Chateau 5G ax supports MIMO 4x4 on 5G and LTE. There are 6 built-in LTE/5G antennas. One pair of external antennas provides even better wireless network coverage in the largest homes, and the other - improved ...
by mkx
Sun Mar 09, 2025 11:10 pm
Forum: MikroTik hardware questions
Topic: Wireless wire as connection between modem and router
Replies: 2
Views: 590

Re: Wireless wire as connection between modem and router

Wireless wire pair acts as transparent UTP connection. So it should work for you. But (a big one): it needs line of sight ... which indoors is not always possible. Even if there are no permanent obstacles between both points, beware of people walking cross the link. IMO it's always better to try wit...
by mkx
Sun Mar 09, 2025 10:52 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 508
Views: 134095

Re: v7.18.1 [stable] is released!

/console/clear-history

I tried this on my hAP ac2 running 7.18.1 (without wifi or wireless). The effect: free-hdd-space went from 2492.0KiB to 2556.0KiB ... so 64KiB freed ... not too bad.
by mkx
Sun Mar 09, 2025 12:10 pm
Forum: MikroTik hardware questions
Topic: Wireless router with SFP+ port
Replies: 13
Views: 3023

Re: Wireless router with SFP+ port

You simply don't combine a 24 port switch with wireless. While it might have made some sense with 802.11n @2.4GHz, it certainly doesn't make sense for more modern standards (e.g. 802.11ax @5GHz) snd even less for oncoming standards (WiFi7 @6GHz) where it's a must to bring AP really close to station...
by mkx
Sun Mar 09, 2025 11:58 am
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 508
Views: 134095

Re: v7.18.1 [stable] is released!

cant upgrade .. have u found a solution without netinstall the device ?

There is no other solution. No free space ... game over. It's not possible even to cleanly reboot/shutdown device.
by mkx
Sun Mar 09, 2025 11:56 am
Forum: Wireless Networking
Topic: Mikrotik AX PTP Netmetal AX
Replies: 47
Views: 12894

Re: Mikrotik AX PTP Netmetal AX

... I connected Mikrotik Net Metal as with 2 HGO antennas out with a LAN cable. However, at 50m from this AP, at 5 GHz, my signal has a strength of -80 dBm, and according to the calculation it should be about -48 dBm. Using the mentioned setup it's impossible to see signal strength of -48dBm at tha...
by mkx
Sun Mar 09, 2025 11:40 am
Forum: Wireless Networking
Topic: CAPsMAN instructions result in "Invalid value in Master"
Replies: 57
Views: 7398

Re: CAPsMAN instructions result in "Invalid value in Master"

Any resetting of ROS device into "some other" mode will wipe most configuration. If your needs are outside some (simple) predefined use cases, then you're completely on your own. You can start off from a profile whuch is close to what you need and change it where it needs to be changed. AF...
by mkx
Sat Mar 08, 2025 6:09 pm
Forum: MikroTik hardware questions
Topic: RB951 does not start with poe-in
Replies: 5
Views: 4901

Re: RB951 does not start with poe-in

The test with RB2011 almost definitely proves that there's something weird going on with your RB951Ui ...
by mkx
Sat Mar 08, 2025 5:56 pm
Forum: General
Topic: RB1100AHx4 Dude edition it doesn't have graphics for memory and hdd?
Replies: 4
Views: 754

Re: RB1100AHx4 Dude edition it doesn't have graphics for memory and hdd?

Check settings under /tool/graphing/interface /tool/graphing/queue /tool/graphing/resource I think that if your management device is not on the lust of allowed addresses, it doesn't even see the graphing section. [edit] Hmmm, just checked ... availability of graphs for all 3 resource categories (CPU...
by mkx
Sat Mar 08, 2025 5:50 pm
Forum: General
Topic: mac telnet
Replies: 8
Views: 906

Re: mac telnet

winbox MAC connection can be controlled with settings under /tool/mac-server (MAC telnet and MAC winbox are configured separately) ... indeed default is allowed-interface-list=all , but it's easy to change it to anything else, including none (I've seen posts on this forum where posters claimed this ...
by mkx
Sat Mar 08, 2025 5:36 pm
Forum: Beginner Basics
Topic: Console Port Question
Replies: 4
Views: 718

Re: Console Port Question

All about serial ports on Routerboards: https://help.mikrotik.com/docs/spaces/R ... al+Console
by mkx
Sat Mar 08, 2025 1:34 pm
Forum: Beginner Basics
Topic: Sub-desired bandwidth performance [SOLVED]
Replies: 8
Views: 2439

Re: Sub-desired bandwidth performance [SOLVED]

One should never assume that any of devices will do its job wirespeed ... one should always check.
by mkx
Sat Mar 08, 2025 1:24 pm
Forum: General
Topic: NetMetal ax: Unable to Access WLAN Interfaces
Replies: 3
Views: 654

Re: NetMetal ax: Unable to Access WLAN Interfaces

The reason I want to access the wlan interfaces is to set the frequency-mode to superchannel and wireless-protocol to nv2, which are not available on the wifi interfaces. No other wireless protocol then 802.11 on AX devices. Any reason you want to use this? Also: ap-bridge mode (which in wifi is me...
by mkx
Sat Mar 08, 2025 1:20 pm
Forum: General
Topic: Connection to CAPsMAN suddenly interrupted
Replies: 13
Views: 2190

Re: Connection to CAPsMAN suddenly interrupted

BPDUs for STP and RSTP are untagged (because unlike MSTP, STP and RSTP are VLAN-agnostic). It's then up to switch-chip magic about how to deal with untagged frames (including BPDUs) so that they're delivered to (software) bridge ... untagged.

Of course, when VLANs are not used, this is not an issue.
by mkx
Sat Mar 08, 2025 1:13 pm
Forum: General
Topic: iOS and MacOS clients lose IPv6 connectivity
Replies: 28
Views: 3182

Re: iOS and MacOS clients lose IPv6 connectivity

Do you have multicast-enhance (or whatever the equivalent on your AP) enabled? RAs are technically multicast ... which is s problem with battery-powered WiFi clients (i.e. smart phones) which tend to switch off radios when idle to save battery life. APs transmit multicasts (and broadcasts) as they a...
by mkx
Sat Mar 08, 2025 12:48 pm
Forum: Beginner Basics
Topic: Sub-desired bandwidth performance [SOLVED]
Replies: 8
Views: 2439

Re: Sub-desired bandwidth performance [SOLVED]

Do you use same L3 (IP) MTU on both subnets (when talking about VLAN routing)? I don't think that L3HW can deal with different L3 MTUs. As I wrote: make sure that device uses L3HW offload for routing. Without using it, it can't do any decent throughput ... I'm actually (positively) surprised that yo...
by mkx
Sat Mar 08, 2025 11:57 am
Forum: Beginner Basics
Topic: Sub-desired bandwidth performance [SOLVED]
Replies: 8
Views: 2439

Re: Sub-desired bandwidth performance [SOLVED]

A few things: only one bridge can be handled in switch chip, the other will be handled by (slow) CPU. You can partition your switch by using vlan-filtering and assigning ports, belongong to different partitons, different PVID. Added benefit (or not) is ability to use trunk towards core router (over ...
by mkx
Fri Mar 07, 2025 9:58 pm
Forum: General
Topic: WAN-capable ports on routers [SOLVED]
Replies: 24
Views: 3870

Re: WAN-capable ports on routers [SOLVED]

Can you tell ignorant me why L3HW offload is important? It allows to use switch chip for routing (and some switches also fasttracking) which means routing/fasttracking can be done wirespeed without much load on CPU. Article about it: https://help.mikrotik.com/docs/spaces/ROS/pages/62390319/L3+Hardw...
by mkx
Fri Mar 07, 2025 9:08 pm
Forum: General
Topic: WAN-capable ports on routers [SOLVED]
Replies: 24
Views: 3870

Re: WAN-capable ports on routers [SOLVED]

Yes ... if switch chip supports L3 HW offload ... which switch chip in L009 doesn't. RTL8367, 88E6393X, 88E6191X, 88E6190 , MT7621, MT7531, EN7562CT switch chips can use HW offloaded vlan-filtering since RouterOS v7." @anav, pay attention to details. I was talking about L3 HW offload, VLANs ar...
by mkx
Fri Mar 07, 2025 3:51 pm
Forum: Beginner Basics
Topic: Device tests results - minimum value of "Mbps" for a single true 1Gbps connection [SOLVED]
Replies: 6
Views: 2830

Re: Device tests results - minimum value of "Mbps" for a single true 1Gbps connection [SOLVED]

But it extends futher: even if a device has "Mbps" value in "Test results" which exceeds (slightly?) the threshold (e.g. 1000), it doesn't necessarily mean that router is capable of push all the data through single port. Table column header says "all port test" and I se...
by mkx
Fri Mar 07, 2025 3:43 pm
Forum: General
Topic: CCR2004 sudden PSU1+PSU2+fan failed [SOLVED]
Replies: 13
Views: 5780

Re: CCR2004 sudden PSU1+PSU2+fan failed [SOLVED]

If a faulty gpon works, then the router that it works on, is garbage as it should be more discriminating. The whole thread is about compatibility between devices on different side of SFP cage. So CCR seems a bit more troublesome than some other RouterBoards. And GPON modules seem a bit more trouble...
by mkx
Fri Mar 07, 2025 9:39 am
Forum: General
Topic: WAN-capable ports on routers [SOLVED]
Replies: 24
Views: 3870

Re: WAN-capable ports on routers [SOLVED]

Wouldn't it be better to use one port from the hardware offload chip as a WAN port as long as I have it logically separated from the rest of the bridged LAN ports?
Yes ... if switch chip supports L3HW offload ... which switch chip in L009 doesn't.
by mkx
Fri Mar 07, 2025 9:18 am
Forum: Wireless Networking
Topic: CAPsMAN instructions result in "Invalid value in Master"
Replies: 57
Views: 7398

Re: CAPsMAN instructions result in "Invalid value in Master"

Your main problem is currently L2 setup - VLANs. /interface wifi capsman set enabled=yes interfaces=bridge package-path="" require-peer-certificate=no upgrade-policy=require-same-version You set capsman to listen for connections from CAPs on bridge ... but in your setup bridge interface do...
by mkx
Fri Mar 07, 2025 9:13 am
Forum: Wireless Networking
Topic: CAP - no connections to CAPSMan [SOLVED]
Replies: 6
Views: 2740

Re: CAP - no connections to CAPSMan [SOLVED]

/interface wifi capsman set enabled=yes package-path="" require-peer-certificate=no upgrade-policy=none The quoted part seems to be the only capsman-related config on your device. Which is very far from enough. You have to do everything under /interface/wifi ... the security, datapath, co...
by mkx
Thu Mar 06, 2025 11:07 pm
Forum: Wireless Networking
Topic: Wireless FT not working/available on older Wifi?
Replies: 3
Views: 784

Re: Wireless FT not working/available on older Wifi?

My experience is that some clients do properly roam (verified by checking logs on capsman), but auth type doesn't have ft- prefix after roaming is complete (and no, client doesn't disconnect/reconnect, it just roams). OTOH I see both ft-wpa2-psk and ft-wpa3-psk. Which all might indicate, that ft- pa...
by mkx
Thu Mar 06, 2025 4:48 pm
Forum: Wireless Networking
Topic: hAP ac lite selecting illegal frequency with scan list
Replies: 5
Views: 829

Re: hAP ac lite selecting illegal frequency with scan list

So I added a scan list of 5180-5720. First question, is this okay? No. You should enter it in Frequency property. But I'm wondering: you're mentioning "hAP ax" (which should be running wifi-qcom driver), but your screenshot shows "ap bridge" as AP mode (and that mode doesn't exi...
by mkx
Thu Mar 06, 2025 12:42 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 298
Views: 76048

Re: v7.19beta [testing] is released!

Certainly something to carefully look at and consider a netinstall!

Thanks for you considerations. Since devices work as intended, without any noticeable problems, I'll skip further actions (for now).
by mkx
Wed Mar 05, 2025 11:13 pm
Forum: Wireless Networking
Topic: Mounting 4 mANTBox ax 15s on a pole / mast
Replies: 1
Views: 776

Re: Mounting 4 mANTBox ax 15s on a pole / mast

In such scenario you better place some quality metal sheets between APs' backs ... and ground those metal sheets. Otherwise the back lobes of antennas will feed lots of interference from one transmitter to other receivers. Placing APs a few meters apart does the job nicely, spacing them vertically a...
by mkx
Wed Mar 05, 2025 11:07 pm
Forum: Wireless Networking
Topic: "not responding" - f.k.a. SA Query timeout
Replies: 370
Views: 85610

Re: "not responding" - f.k.a. SA Query timeout

You're allowed to use DFS channels as long as the device carries out the CAC check. If you live near a war zone, there will be plenty of actual radars around (even if you're hundreds of kms away from current front line) ... so CAC might never produce a working DFS channel. So it's better to avoid t...
by mkx
Wed Mar 05, 2025 11:02 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 298
Views: 76048

Re: v7.19beta [testing] is released!

... netinstalled device will jump from 1.1.1970... That's no longer true. With recent versions you can not go before release build date. Whatever. It's been a while since I last netinstalled a device (more than a couple of weeks for sure ;-) ). The point is: there's no need for initial time step to...
by mkx
Wed Mar 05, 2025 10:49 pm
Forum: Beginner Basics
Topic: The twelve Rules of Mikrotik Club
Replies: 53
Views: 8314

Re: The twelve Rules of Mikrotik Club

I think VLAN 1 is the default LAN for most routers supporting VLAN's. Besides, if I try not to use it (as in not assigb any bridges to VLAN1), I get locked out. Using VLAN 1 is somehow in same category as using QuickSet: it's fine if left alone. But when you start tinkering with settings, you bette...
by mkx
Wed Mar 05, 2025 10:38 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 298
Views: 76048

Re: v7.19beta [testing] is released!

Well, in your case it would have been valuable when you were warned because what happened is likely not what you intended! E.g. a device was powercycled without clean shutdown ... Nope, device was cleanly rebooted due to ROS upgrade. I can't explain the few hours jump myself, usually it is, as ever...
by mkx
Wed Mar 05, 2025 2:34 pm
Forum: General
Topic: My Mikrotik is sometimes incredible slow, need help.
Replies: 19
Views: 1563

Re: My Mikrotik is sometimes incredible slow, need help.

He has all ethernet ports set to 100Mbps. I don't know if it's deliberate. But auto-negotiation seems to still be enabled. That's a leftover from even older ROS versions when default setting was speed=100M-baseT-full ... with not so ancient versions, default changed to speed=1G-baseT-full , but run...
by mkx
Wed Mar 05, 2025 2:19 pm
Forum: Beginner Basics
Topic: Second IP range can't connect to Internet [SOLVED]
Replies: 5
Views: 848

Re: Second IP range can't connect to Internet

I guess I have to put an entry into IP:Routes, but don't know what it should look like. As for my understanding anything the router does not know should go to 192.168.88.1 – but it is not working. It goes both ways: Mikrotik4 has to know that default route is via 192.168.88.1 ... but Mikrotik1 has ...
by mkx
Wed Mar 05, 2025 2:15 pm
Forum: Beginner Basics
Topic: The twelve Rules of Mikrotik Club
Replies: 53
Views: 8314

Re: The twelve Rules of Mikrotik Club

Is OP saying not to use VLAN1 as in PVID1? Not use for what? Forwarding? Admin VLAN? Its confusing...
See? That's exactly why one should stay away from VLAN 1 in any incarnation (PVID, VID, anything).
by mkx
Wed Mar 05, 2025 2:10 pm
Forum: Announcements
Topic: v7.19beta [testing] is released!
Replies: 298
Views: 76048

Re: v7.19beta [testing] is released!

Well, actually a change of time-of-day is a very critical event, but one could argue that in a device without built-in clock it could be labeled a little less severe when the time adjustment is forward, and less than 5 minutes. When upgrading my fleet from 7.17.2 to 7.18.1 ... I saw time jump of a ...
by mkx
Wed Mar 05, 2025 9:09 am
Forum: General
Topic: Feature request: Select upgrade version from winbox
Replies: 1
Views: 812

Re: Feature request: Select upgrade version from winbox

... had to manually download and copy 7.17.2 version to them ( fortunately had enough space ) ... Regarding the space for upgrade packages, it's exactly the same regardless the method of upgrade (via ROS upgrader versus manual download), they are downloaded (or uploaded) to whatever is considered r...
by mkx
Tue Mar 04, 2025 11:59 am
Forum: Wireless Networking
Topic: CAPsMAN instructions result in "Invalid value in Master"
Replies: 57
Views: 7398

Re: CAPsMAN instructions result in "Invalid value in Master"

But that's my choice to do it this way.
Agree that it's a good way. And it seems that it's the correct way (considering that may people will likely end up using multiple APs and hence CAPsMAN).
by mkx
Tue Mar 04, 2025 10:39 am
Forum: Wireless Networking
Topic: CAPsMAN instructions result in "Invalid value in Master"
Replies: 57
Views: 7398

Re: CAPsMAN instructions result in "Invalid value in Master"

... in the spirit of learn to walk first, it does make sense to first have the basic wifi part digested before moving to capsman. I agree with the concept "walk first, run later". The only problem here is that it's possible to set up the whole config for local radio directly on /interface...
by mkx
Tue Mar 04, 2025 9:08 am
Forum: Wireless Networking
Topic: CAPsMAN instructions result in "Invalid value in Master"
Replies: 57
Views: 7398

Re: CAPsMAN instructions result in "Invalid value in Master"

But you may have to ask yourself WHY you want capsman setup ? If it's only for controlling 2 to 3 devices, don't bother. I think we have to revise the "it's only sensible to bother with CAPsMAN if there are 4 or more APs in game" stance. Ever since we got wifi (qcom / qcom-ac) with 802.11...
by mkx
Tue Mar 04, 2025 8:53 am
Forum: General
Topic: BOOTP/DHCP bypasses NAT firewall
Replies: 20
Views: 2007

Re: BOOTP/DHCP bypasses NAT firewall

To add to what @lurker888 wrote: Case 1 Using 'ether1': Winbox can still connect using the device's MAC address. DHCP-Client still retrieves leases, and DHCP-Server still provides leases. Winbox MAC access is another function which works directly with raw sockets ... so it escapes IP firewall. Unlik...
by mkx
Tue Mar 04, 2025 8:06 am
Forum: Beginner Basics
Topic: netinstall-cli hanging
Replies: 8
Views: 1298

Re: netinstall-cli hanging

... a callout on the netinstall-cli docs referencing at what point flashing has finished and when its safe to <C-c>. I generally agree that clearer description in docs would be welcome. However, it's (?) common knowledge that after device being netinstalled reboots, the process is over and done. Ne...
by mkx
Mon Mar 03, 2025 8:26 pm
Forum: General
Topic: BOOTP/DHCP bypasses NAT firewall
Replies: 20
Views: 2007

Re: BOOTP/DHCP bypasses NAT firewall

Are there any other parts of RouterOS that bypass Netfilter filter chains? DNS maybe?

No, DNS is completely normal IP (UDP or TCP) service. It's only DHCP that uses raw sockets.
by mkx
Mon Mar 03, 2025 2:29 pm
Forum: Wireless Networking
Topic: WIFI roaming for WPA3 broken again (somewhere from 7.17.1+- to 7.18beta5) (edit: solved)
Replies: 13
Views: 5468

Re: WIFI roaming for WPA3 broken again (somewhere from 7.17.1+- to 7.18beta5) (edit: solved)

Just wanted to report a success story: I just installed ROS 7.18.1 and have set 2g-probe-delay=yes ... I have a Huawei tablet, which otherwise stubbornly connects to 2.4GHz BSSID. After enabling the property (and kicking tablet off wireless) it connected to 5GHz BSSID.
by mkx
Mon Mar 03, 2025 2:25 pm
Forum: Announcements
Topic: v7.18.2 [stable] is released!
Replies: 508
Views: 134095

Re: v7.18.1 [stable] is released!

I can confirm that ROS 7.18.1 on ARM uses around 200kB more of flash storage than 7.17.2 ... on hAP ac2 with only base (routeros) package installed.
by mkx
Fri Feb 28, 2025 10:17 pm
Forum: MikroTik hardware questions
Topic: RB4011iGS+5HacQ2HnD-IN vs RB4011iGS+RM Tested ambient temperature
Replies: 12
Views: 4244

Re: RB4011iGS+5HacQ2HnD-IN vs RB4011iGS+RM Tested ambient temperature

The problem of high ambient temperatures is that this means higher temperature of internal components. And higher component temperature means faster aging ... so even if device doesn't die immediately it may die "of old age" prematurely. Capacitors are specially prone to faster aging.
by mkx
Fri Feb 28, 2025 10:12 pm
Forum: MikroTik hardware questions
Topic: RB4011iGS+5HacQ2HnD-IN vs RB4011iGS+RM Tested ambient temperature
Replies: 12
Views: 4244

Re: RB4011iGS+5HacQ2HnD-IN vs RB4011iGS+RM Tested ambient temperature

My question is whether I can use it in an environment that can reach up to 50 degrees. When vendor provides some information, then it most of times means something. If MT says that wifi variant of RB4011 works in ambient temperatures up to 45°C, then it means it's likely that device will survive fo...
by mkx
Thu Feb 27, 2025 5:12 pm
Forum: General
Topic: Two logins to webfig
Replies: 3
Views: 2966

Re: Two logins to webfig

That's interesting. ROS is the same on all devices. I see the old webfig on two CAPs, and on one it switches by itself. Browser caches contents on "per server" basis. It never uses cached item, obtained from one server, on page served by another server. So if you're seeing mixed contents,...
by mkx
Wed Feb 26, 2025 3:59 pm
Forum: General
Topic: mikrotik script find mac address specific octet
Replies: 3
Views: 1787

Re: mikrotik script find mac address specific octet

Also 3, 7, B and F have private bit on... The "even" numbers are multicast MAC addresses ... so in principle should not be used by "normal" devices for unicast communication (which is vast majority) ... and "randomised MAC" is used in context of unicast communications....
by mkx
Wed Feb 26, 2025 3:40 pm
Forum: SwOS
Topic: sfp-sfpplus1 high temperature warning! [SOLVED]
Replies: 15
Views: 12112

Re: sfp-sfpplus1 high temperature warning! [SOLVED]

Overheating SFPs are rather a novelty (it really began with 10Gbps RJ-45 modules) ... and hopefully new generations will make the problem go away.
by mkx
Wed Feb 26, 2025 3:35 pm
Forum: Wireless Networking
Topic: Why no wifi 7 or lots of antenna for MIMO etc
Replies: 9
Views: 2617

Re: Why no wifi 7 or lots of antenna for MIMO etc

... in a 50 person office ... The problem with "50 person office" and 5-7GHz frequency band is that the higher the frequency the bigger signal loss ... and "50 person office" is large enough and has enough of obstacles that one needs multiple APs to provide coverage good enough ...
by mkx
Wed Feb 26, 2025 10:56 am
Forum: SwOS
Topic: sfp-sfpplus1 high temperature warning! [SOLVED]
Replies: 15
Views: 12112

Re: sfp-sfpplus1 high temperature warning! [SOLVED]

I don't know exactly, only judging from photographs ... but device seems to have majority of holes on the top surface and only little elsewhere. With fan covering all top holes, air is pushed out through (scarce) holes at other parts of device, so air speed might be relatively low. With smaller fan ...
by mkx
Wed Feb 26, 2025 10:31 am
Forum: General
Topic: Remove the glue on LtAP kit mini PCIe card antenna connectors
Replies: 2
Views: 1816

Re: Remove the glue on LtAP kit mini PCIe card antenna connectors

It's hot glue ... so you'll have to remove it physically, e.g. by using a scalpel or a similar knife.
by mkx
Wed Feb 26, 2025 10:26 am
Forum: General
Topic: IPv6 Fasttrack support
Replies: 4
Views: 4575

Re: IPv6 Fasttrack support

In short: IPv6 fasttrack is available since ROS v7.18.
by mkx
Wed Feb 26, 2025 10:23 am
Forum: General
Topic: Device mode versions and partisions
Replies: 5
Views: 2182

Re: Device mode versions and partisions

system upgraded to version Y7 (partition 1). This version Y7 has allowed versions: X10+, Y5+ If the partition 2 backup is made active and system rebooted, will it boot the X5 version on this partition? As far as I understand, the allowed versions setting is supposed to be about downgrade process (R...
by mkx
Tue Feb 25, 2025 5:54 pm
Forum: Beginner Basics
Topic: The twelve Rules of Mikrotik Club
Replies: 53
Views: 8314

Re: The twelve Rules of Mikrotik Club

... if STP comes into play then it has to be chosen properly if STP comes into play, then one really should set bridge priorities according to topology. One never knows when some "genious" will set MAC 01:00:00:00:00:00 to his bridge while bridge ports are set to default value of edge=aut...
by mkx
Mon Feb 24, 2025 10:23 pm
Forum: General
Topic: Why are threads for previous major releases being locked? [SOLVED]
Replies: 17
Views: 5518

Re: Why are threads for previous major releases being locked? [SOLVED]

New version is out = MT no longer wants to hear about bugs in previous one because they will not be hotfixing that one anymore = topic closed. Yeah, that’s my guess too: topic closed = branch closed . But I’m still not convinced about the actual when and why . Maybe it’s just as simple as there bei...
by mkx
Mon Feb 24, 2025 9:44 pm
Forum: Beginner Basics
Topic: VLANs via power line
Replies: 6
Views: 2466

Re: VLANs via power line

When it comes to "non-VLAN" switches (power-line devices are switches with one "weird" ethernet port) ... they will all happily pass VLAN tags (they are plain L2 devices and don't look into "ethertype" header, even less they look any further into payload) ... but they h...
by mkx
Sat Feb 22, 2025 10:04 pm
Forum: General
Topic: Firewall Rules for Home Router [SOLVED]
Replies: 11
Views: 7436

Re: Firewall Rules for Home Router [SOLVED]

Which device model is your Mikrotik?
by mkx
Sat Feb 22, 2025 9:17 pm
Forum: General
Topic: Firewall Rules for Home Router [SOLVED]
Replies: 11
Views: 7436

Re: Firewall Rules for Home Router [SOLVED]

Default firewall filter rules already block everything from WAN side. Do you have any reason not to stick to them? BTW, BTH is connection which in principle starts ftom your router if you enable BTH. Connection is done towards MT's servers and by doing that, you delegate care about a bit of your sec...
by mkx
Sat Feb 22, 2025 8:59 pm
Forum: Beginner Basics
Topic: Multiple address on same MAC - is this causing issues?
Replies: 1
Views: 2283

Re: Multiple address on same MAC - is this causing issues?

DHCP server (any of them) will re-assign address already assigned only to device with same client-id ... in principle it doesn't care about MAC address. I think that MAC address only matters to DHCP server if client doesn't provide client-id. So as long as your gadget is inventing new client-id, it ...
by mkx
Fri Feb 21, 2025 8:44 pm
Forum: Wireless Networking
Topic: Caps-Man with Wifi 6 connection problems
Replies: 12
Views: 3224

Re: Caps-Man with Wifi 6 connection problems

Offending devices are usually only using 2GHz bands.

Mine is dual-band device ... I created that "backwards compatibke" virtual SSID on 5GHz radio and device was happy with that.
by mkx
Fri Feb 21, 2025 8:34 pm
Forum: General
Topic: esim in 7.18rc
Replies: 32
Views: 5790

Re: esim in 7.18rc

It makes no sense to have released (and documented) a command that doesn't work on released hardware in a RC, Why? It's release candidate ROS ... and they might have a "release candidate HW" in their labs. Unlike RC software RC hardware doesn't hit the streets, it has to be full release. ...
by mkx
Fri Feb 21, 2025 8:22 pm
Forum: General
Topic: Question related to "RouterOS bridge mysteries explained"
Replies: 13
Views: 4968

Re: Question related to "RouterOS bridge mysteries explained"

edit: i have just tried your example with vlan234, but /interface/bridge/vlan/print says in vlan-ids column : 1 (vlan1) but then again i am using gns3 routeros 7.8 maybe it works different.. You have to pay attention to details: as @sindy already wrote: the example works since ROS version 7.16 ... ...
by mkx
Fri Feb 21, 2025 8:10 pm
Forum: Beginner Basics
Topic: No SSH/ping possible across the same VLAN [SOLVED]
Replies: 11
Views: 3017

Re: No SSH/ping possible across the same VLAN

On my tablet I have SSH client. There is no winbox for android. And I don't particularly like new webfig layout. Copy-paste works great in CLI (over ssh), it takes to run terminal window from inside winbox to do the same in winbox (and terminal features of terminal of winbox don't reach the ankles o...
by mkx
Fri Feb 21, 2025 7:26 pm
Forum: Beginner Basics
Topic: Bridges and VLAN
Replies: 26
Views: 5071

Re: Bridges and VLAN

Some of us like to have dedicated management VLAN. All devices have their management IP addresses in that VLAN, no DHCP server no nothing. Then, if you can afford, dedicate an access port on your switch where you can plug your management PC (and set network parameters manually). You can "plug&q...
by mkx
Fri Feb 21, 2025 6:19 pm
Forum: Beginner Basics
Topic: Bridges and VLAN
Replies: 26
Views: 5071

Re: Bridges and VLAN

PVE's and vms can access the internet by now (but on outgoing traffic they can ping devices in 192.168.178.1/24 subnet) but I guess that's only because of the pfSense firewall rules, I have to modify them. But from my 192.168.178.1/24 subnet, I cannot ping them (thats how I want it). You can add a ...
by mkx
Fri Feb 21, 2025 6:12 pm
Forum: Beginner Basics
Topic: No SSH/ping possible across the same VLAN [SOLVED]
Replies: 11
Views: 3017

Re: No SSH/ping possible across the same VLAN

IM confused, why are you trying to SSH between internal devices ...

Why not? ssh is legitimate protocol to use inside a LAN, I'm using it to configure all my MT gear.

And, BTW, @anav: the problem is in L2 config, non-working L6 is only a symptom/illustration.
by mkx
Fri Feb 21, 2025 6:02 pm
Forum: Beginner Basics
Topic: No SSH/ping possible across the same VLAN [SOLVED]
Replies: 11
Views: 3017

Re: No SSH/ping possible across the same VLAN

bridge config on hAP ax2 says: /interface bridge port add bridge=bridge interface=ether1 pvid=33 add bridge=bridge interface=ether2 pvid=33 add bridge=bridge interface=ether3 pvid=33 add bridge=bridge interface=ether4 pvid=33 add bridge=bridge interface=ether5 pvid=33 ... /interface bridge vlan add ...
by mkx
Fri Feb 21, 2025 5:51 pm
Forum: Beginner Basics
Topic: Bridges and VLAN
Replies: 26
Views: 5071

Re: Bridges and VLAN

There's a problem with ether23 bridge membership (bridge=*1D). I'm not sure that I understand your remaining issue. But will try anyway: When I remove the ether3-ether5 (+ had ether1 also tagged before) tagged ports it will get automatically untagged but then I don't have access from my pfSense vlan...
by mkx
Fri Feb 21, 2025 2:39 pm
Forum: Wireless Networking
Topic: Caps-Man with Wifi 6 connection problems
Replies: 12
Views: 3224

Re: Caps-Man with Wifi 6 connection problems

Turned on FT. Thermostats don't connect. The fact is that some clients barf on seeing some feature bits set ... even if they don't know about them. And will refuse to connect. The other day I had to use wifi on an old laptop (has Intel Centrino WiFi supporting abgn). It wouldn't connect to my WiFi ...
by mkx
Fri Feb 21, 2025 2:27 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215154

Re: v7.17.2 [stable] is released!

I cant reach by netinstall because of not linking on ports Failed upgrade of ROS doesn't affect ability to run netinstall by itself. Failed routerboard upgrade could ... but for this reason there's backup routerboot which can be invoked by pressing button during powering up the device. Backup route...
by mkx
Fri Feb 21, 2025 9:18 am
Forum: Beginner Basics
Topic: Router without Default Configuration does not always work!!!
Replies: 5
Views: 3150

Re: Router without Default Configuration do not always work!!!

The result initially worked and then I rebooted the router R2 again. The result was unsuccessful. Based on my past knowledge, I found it was missing a script as below: # Enable Remote DNS Requests /ip dns set allow-remote-requests=yes The DHCP server config is incomplete ... apart from the rule abo...
by mkx
Fri Feb 21, 2025 8:21 am
Forum: MikroTik hardware questions
Topic: 10V or 14V minimum on RB3011?
Replies: 9
Views: 2631

Re: 10V or 14V minimum on RB3011?

I'm having 900Mbps internet installed in a few weeks ... It's likely that RB3011 will be a bottle neck here. Offcial test results with a grain of common experience of forum users say, that RB3011 is able to comfortably route at speeds of around 500Mbps ("routing -> 25 Filter rules -> 512 byte ...
by mkx
Fri Feb 21, 2025 8:13 am
Forum: General
Topic: Recommended firmware for CCR1009-7G-1C-1S+
Replies: 1
Views: 2180

Re: Recommended firmware for CCR1009-7G-1C-1S+

6.49.18 unless you require any of new features introduced in (recent) v7 versions.
by mkx
Fri Feb 21, 2025 8:01 am
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 27461

Re: v7.18rc [testing] is released!

However, the native Debian underneath is able to do 1Gbps more on CM5 and 3Gbps more on N150 when running iperf3 tests, and both do it on a single core, vs. CHR in KVM/Qemu utilizing 80% of all four cores. It makes me wonder how much is virtualization overhead and how much is RouterOS. You have to ...
by mkx
Thu Feb 20, 2025 5:49 pm
Forum: Wireless Networking
Topic: hAP-ax3 vs cAP ax
Replies: 13
Views: 5118

Re: hAP-ax3 vs cAP ax

Adding many 5GHz APs with low Tx power (not to cover too big area) and mobility enabled. Set narrow channels (up to 40MHz) which gives you more non-overlapping channels for adjacent APs.

And above all, provision frequencies manually, don't let APs select them on their own.
by mkx
Thu Feb 20, 2025 5:39 pm
Forum: Wireless Networking
Topic: 7.13 WiFi-CAPsMAN, Access list to assign VLANs and FT issue [SOLVED]
Replies: 13
Views: 18818

Re: 7.13 WiFi-CAPsMAN, Access list to assign VLANs and FT issue [SOLVED]

... when enabling ft-preserve-vlanid=yes ... Do you use any feature which actually requires this setting? Such as: RADIUS which assigns VLAN ID per user or ACLs which assign VLAN ID per station or PPSK? This setting has potential to screw mobility while without it roaming action might succeed. And ...
by mkx
Thu Feb 20, 2025 3:40 pm
Forum: Beginner Basics
Topic: Bridges and VLAN
Replies: 26
Views: 5071

Re: Bridges and VLAN

You don't have to configure VLANs on fritz ... it's connected to access port of CRS ... which can switch it over to tagged port towards pfsense (and other LAN devices). And if you decide to go with another VID for main LAN, you'll again have plenty of access ports to that VLAN, just like you have a ...
by mkx
Thu Feb 20, 2025 2:56 pm
Forum: Beginner Basics
Topic: Anyone uses AI for their config?
Replies: 32
Views: 4207

Re: Anyone uses AI for their config?

I just assumed that because this is a forum site, that I can just ask questions. In my book there's a difference between "I tried to do it this way but I have such problems" and "this is what AI told me to do, but it doesn't work, fix it so that it will work". In other words: I'...
by mkx
Thu Feb 20, 2025 2:51 pm
Forum: Beginner Basics
Topic: Bridges and VLAN
Replies: 26
Views: 5071

Re: Bridges and VLAN

ether9 as tagged member of VLAN 1 could be correct or wrong, depending on how exactly it's configured on pfsense side. If pfsense is configured explicitly to work with vlan-tagged frames for VLAN 1, then your latest CRS config is fine (but be careful to set pvid on ether to something other than 10 o...
by mkx
Thu Feb 20, 2025 2:27 pm
Forum: Beginner Basics
Topic: Bridges and VLAN
Replies: 26
Views: 5071

Re: Bridges and VLAN

The screen shot shows that none of bridge ports are tagged ... the "Current Tagged" column doesn't show any ports.
by mkx
Thu Feb 20, 2025 2:26 pm
Forum: Beginner Basics
Topic: hAP ac2 (ac^2) speed issue
Replies: 11
Views: 2714

Re: hAP ac2 (ac^2) speed issue

50%-60% of total 4 cores can mean at least 1 core is at 100% (if it was only that one you would reach 25% total). Tools / profile / all And then you will see all cores separately. Is 1 at or close to 100% ? Game over then. Yes. But there are other cores. What if ROS doesn't work the way you'd want ...
by mkx
Thu Feb 20, 2025 2:19 pm
Forum: Beginner Basics
Topic: Bridges and VLAN
Replies: 26
Views: 5071

Re: Bridges and VLAN

Isn't pfsenses port 1 already configures as trunk port as on my screenshot above?
Which screenshot? I don't recognize any screenshot to originate from pfsense.

If you're talking about CRS config ... then no, none of ports is trunk. They are all access, some to VLAN 10 and most to VLAN 1.
by mkx
Thu Feb 20, 2025 2:17 pm
Forum: Beginner Basics
Topic: Bridges and VLAN
Replies: 26
Views: 5071

Re: Bridges and VLAN

You have currently complication because you have two routers (fritz and pfsense) in your network. And if I understand you correctly only pfsense knows about PVE subnet. So when machines, which are part of main subnet (192.168.178.0/24) want to communicate with PVE subnet, they will use their default...
by mkx
Thu Feb 20, 2025 2:06 pm
Forum: Beginner Basics
Topic: does RB4011 support layer2 bonding?
Replies: 3
Views: 2059

Re: does RB4011 support layer2 bonding?

not sure, maybe static aggregation (user config), maybe dynamic aggregation( lacp protocol), which cisco switch supports both ways. ROS only supports statically configured bonds. 802.3ad is de-iure industry standard and it's supported on all Mikrotik devices. Only a few can offload that to switch c...
by mkx
Thu Feb 20, 2025 8:43 am
Forum: MikroTik hardware questions
Topic: high xt_misc CPU Usage on X86
Replies: 4
Views: 3121

Re: high xt_misc CPU Usage on X86

"several million PPS" is quite a lot. For example: CCR 2216 (which is more or less MT's flagship device) hits its perfromance ceiling at around 2.9Mpps (when routing and firewalling with CPU ... not when L3HW offload is effective). See official test results ... see row "Routing -> 25 ...
by mkx
Thu Feb 20, 2025 8:33 am
Forum: Wireless Networking
Topic: Hotspot multisite Issue with Netmetal AX (No AP Bridge Mode)
Replies: 1
Views: 1988

Re: Hotspot multisite Issue with Netmetal AX (No AP Bridge Mode)

However, when using a Netmetal AX (which lacks native AP Bridge mode) It's not that AX devices (running wifi-qcom drivers) lack "native AP bridge mode" ... they do have it (AP is simply set to AP mode, stations are set to station-bridge mode). The issue might be that bridge mode is incomp...
by mkx
Thu Feb 20, 2025 8:26 am
Forum: Beginner Basics
Topic: Bridges and VLAN
Replies: 26
Views: 5071

Re: Bridges and VLAN

I'm not sure if you have made conceptual decision: which device should do the routing between your two subnets? In principle you could have two routers in your network: main router which will route between your "LAN" subnets and edge router which will connect your network towards internet....
by mkx
Wed Feb 19, 2025 8:30 pm
Forum: Announcements
Topic: v7.17.2 [stable] is released!
Replies: 619
Views: 215154

Re: v7.17.2 [stable] is released!

It's been said that ssh in ROS is not based on OpenSSH. So in theory those vulnerabilities are not present in ROS. In practice they might or might not be ...
by mkx
Wed Feb 19, 2025 7:10 pm
Forum: General
Topic: Vlan tagging
Replies: 34
Views: 5148

Re: Vlan tagging

Use single bridge.
by mkx
Wed Feb 19, 2025 7:02 pm
Forum: General
Topic: Secrets in supout.rif
Replies: 16
Views: 4688

Re: Secrets in supout.rif

But using it means that supout.rif file is already uploaded to MT's site ... which I believe @teslasystems has his doubts about ...
No, I don't have any doubts that it's uploaded.
What I meant was that you had doubts about uploading supout.rif anywhere in complete form.
by mkx
Wed Feb 19, 2025 3:13 pm
Forum: General
Topic: Secrets in supout.rif
Replies: 16
Views: 4688

Re: Secrets in supout.rif

now there is the viewer directly on the mikrotik site
https://mikrotik.com/client/supout

But using it means that supout.rif file is already uploaded to MT's site ... which I believe @teslasystems has his doubts about ...
by mkx
Wed Feb 19, 2025 2:57 pm
Forum: Announcements
Topic: v7.18rc [testing] is released!
Replies: 145
Views: 27461

Re: v7.18rc [testing] is released!

Mikrotik team, please solve the problems regarding the network and leave features like storage, container and SMB which are completely unnecessary in routers and switches and can only cause instability. I don't know what's going on, but this is network equipment, not servers. I agree with You 1000%...
by mkx
Wed Feb 19, 2025 2:49 pm
Forum: Virtualization
Topic: Real Docker images for CHR to run in Containerlalb
Replies: 13
Views: 3980

Re: Real Docker images for CHR to run in Containerlalb

Full-featured and rock-solid? 99.999%? ... still trippin from the weekend? If we go down to personal level ... then it's somebody else who's trippin ... by requesting something really marginal (both in terms of usability and demand). Even if MT devs spend only 5 seconds to get you container image o...
by mkx
Wed Feb 19, 2025 11:23 am
Forum: Virtualization
Topic: Real Docker images for CHR to run in Containerlalb
Replies: 13
Views: 3980

Re: Real Docker images for CHR to run in Containerlalb

So please @mikrotik let us have our beloved CHR as a container image ... Please @mikrotik, concentrate on actual hardware and make ROS full-featured and rock-solid. 99.999% of us don't care about running ROS in network simulators. And we even less care about how heavy-weight might be running ROS in...
by mkx
Wed Feb 19, 2025 11:12 am
Forum: General
Topic: Problems uploading files
Replies: 7
Views: 2463

Re: Problems uploading files

But the flash folder is missing, which means that mechanism is somehow not working as intended ...

This mechanism is only available on devices with 64MB RAM or more. Which hAP lite doesn't have.
by mkx
Wed Feb 19, 2025 8:52 am
Forum: General
Topic: Vlan tagging
Replies: 34
Views: 5148

Re: Vlan tagging

The link between HP and CRS is trunk I assume. Which means that you need to set port 8 (as per diagram) on MT as tagged member of both VLANs, passed between HP and MT. BTW, if MT is used only as switch, then you only need bridge "CPU-facing port" member of management VLAN. It can be either...
by mkx
Wed Feb 19, 2025 8:43 am
Forum: General
Topic: RB4011 - best setup [SOLVED]
Replies: 6
Views: 6481

Re: RB4011 - best setup [SOLVED]

Just to make things clear: switch chip only really kicks in when switching (that's L2 operation) between ports, controlled by same switch chip. Example would be if you use ports ether8-ether10 as parts of LAN switch and device, connected to ether8, would communicate with device, connected to ether10...
by mkx
Wed Feb 19, 2025 8:31 am
Forum: General
Topic: Quality of life question
Replies: 12
Views: 2727

Re: Quality of life question

I wanna be an extra real man: How do I make full use of logs? Personally I just read logs whenever happens anything I feel I need to investigate. If I manage to get around the time line, then usually there are not too many log entries around that time so I tend not to filter out anything. Sometimes...
by mkx
Tue Feb 18, 2025 10:03 pm
Forum: Wireless Networking
Topic: Mikrotik AX PTP Netmetal AX
Replies: 47
Views: 12894

Re: Mikrotik AX PTP Netmetal AX

Given the current state of 5GHz congestion and interference, I genuinely don’t understand why MikroTik decided to remove NV2 support. It severely impacts performance in real-world scenarios. They didn't remove support, it wasn't there in wifi-qcom drivers ever. The legacy wireless driver was MT's i...
by mkx
Tue Feb 18, 2025 9:54 pm
Forum: Wireless Networking
Topic: Mikrotik Hap ax2 not working on 5Ghz
Replies: 8
Views: 3712

Re: Mikrotik Hap ax2 not working on 5Ghz

AX devices support (and sometimes prefer) the U-NNI-4 frequencies ... not every client supports those. If AP selects frequency not supported by client it's ad good as not transmitting. You can check which actual frequency uses AP by running /interface/wifi/monitor wifi1 or in GUI by clicking wifi1 i...
by mkx
Tue Feb 18, 2025 9:44 pm
Forum: Wireless Networking
Topic: Migrating from old CAPsMAN to new (hap ac2 -> hap ax2)
Replies: 11
Views: 3194

Re: Migrating from old CAPsMAN to new (hap ac2 -> hap ax2)

Nooo, not a million of bridges. You need to go with VLANs. Using a million of bridges might have been working with old CAPsMAN when capsman forwarding enabled. With new capsman there is no capsman forwarding and the only way of keeping traffic of separate SSIDs separate on wired part of network is b...
by mkx
Tue Feb 18, 2025 9:35 pm
Forum: General
Topic: TCP SYN Flood attack causing high cpu
Replies: 6
Views: 2651

Re: TCP SYN Flood attack causing high cpu

What are you doing that is attracting an attack??

Is just one-post-wait-immediate-reply-and-go-away user.

Nah, user still didn't recover from DoS attack ... due to still on-going attack he could not read replies to his post.
by mkx
Tue Feb 18, 2025 9:31 pm
Forum: General
Topic: Quality of life question
Replies: 12
Views: 2727

Re: Quality of life question

Is the behavior normal: By definition DHCP client has to assume network change when connection droos (even by s fraction of a second). So it'll do it's job. When it comes to logging: I don't think it's possible to configure logging so that it ignores certain device (e.g. certain MAC address) ... bu...
by mkx
Mon Feb 17, 2025 9:42 pm
Forum: General
Topic: SSH-forwarding vs. normal DNAT?
Replies: 9
Views: 2406

Re: SSH-forwarding vs. normal DNAT?

However why use SSH when you can use wireguard which has better security protocols........ Using ssh is often much simpler without too much of compromise on security: no special packet handling is needed (no NAT no nothing, ssh does it automatically) no routing setup needed no escalated permissions...
by mkx
Mon Feb 17, 2025 8:34 pm
Forum: General
Topic: SSH-forwarding vs. normal DNAT?
Replies: 9
Views: 2406

Re: SSH-forwarding vs. normal DNAT?

From ssh client point of view: local means that port X on client side is forwarded via ssh tunnel to 3rd party address and port ... and 3rd party means anywhere, can be e.g. 8.8.8.8 port 53 (this doesn't correlate to ssh tunnel endpoint). So traffic break out will be ssh server side. remote means th...
by mkx
Mon Feb 17, 2025 11:53 am
Forum: General
Topic: Firewall rules analysis
Replies: 110
Views: 14535

Re: Firewall rules analysis

add chain=forward action=drop in-interface-list=WAN connection-nat-state=!dstnat connection-state=new comment="defconf: drop all from WAN not DSTNATed" I see now that this rule (#6) expands to 5 separate rules, some of them drop and some accept. No, it doesn't ... it expands into 1 explic...
by mkx
Mon Feb 17, 2025 11:16 am
Forum: General
Topic: Why are these caught by "drop invalid"
Replies: 9
Views: 2534

Re: Why are these caught by "drop invalid"

Maybe it is enough to insert the new rule that accepts and does not log "invalid TCP ACK FIN/RST" states going to WAN? In principle such packets could be used to break other people's TCP connections. So I wouldn't add a rule which explicitly allows invalid packets. My point is that seeing...
by mkx
Mon Feb 17, 2025 9:20 am
Forum: Beginner Basics
Topic: Bridges and VLAN
Replies: 26
Views: 5071

Re: Bridges and VLAN

From performance point of view it doesn't matter if your CRS runs ROS or SwOS ... if you configure things under ROS right. ROS is more versatile ... and thus allows user to screw the config more easily. When mentioning multiple addresses, I was referring to this part of config: /ip dhcp-client add c...
by mkx
Sun Feb 16, 2025 9:45 pm
Forum: Beginner Basics
Topic: Bridges and VLAN
Replies: 26
Views: 5071

Re: Bridges and VLAN

But I'm still confused, because the "vlan10" interface (172.16.0.0/24) should not be able to ping my main routers ip address (192.168.178.24/1). Probably it's because ROS looks at packet and if destination address is any of its own, it will treat the packet the same regardless the ingress...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 48