Community discussions

MikroTik App

Search found 13230 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 45
by mkx
Thu Nov 14, 2024 8:31 pm
Forum: Wireless Networking
Topic: CAPsMam + VLAN on wifi-qcom-ac enviroment where CAPsMam it self has Wifi
Replies: 1
Views: 45

Re: CAPsMam + VLAN on wifi-qcom-ac enviroment where CAPsMam it self has Wifi

The intention is that local wifi interfaces are not provisiobed by CAPsMAN (running on same device). With new wifi, CAPsMAN and local wifi setup share same configuration profiles, one can apply same profile (e.g. security) both to CAPsMAN and local interfaces. Local radios will still work with other...
by mkx
Thu Nov 14, 2024 8:22 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 654
Views: 129122

Re: v7.17beta [testing] is released!

Just guessing: you have to set address-pool to some existing pool for DHCPv6 server to hand out addresses (seems like it uses prefix-pool only to hand out prefixes). And quite likely you have to provide a pool with same prefix length as is used on interface (and probably router's address on that int...
by mkx
Thu Nov 14, 2024 8:09 pm
Forum: General
Topic: cannot remove directory
Replies: 12
Views: 14258

Re: cannot remove directory

I have the same problem. I once used a netinstall a few months ago and after flashing a different version of RouterOS, it left this flash folder (disk) and I can't remove it. It takes up all the space - 16MB and I can't install new certificates due to lack of space. Normally the root of storage, as...
by mkx
Thu Nov 14, 2024 7:22 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 654
Views: 129122

Re: v7.17beta [testing] is released!

Hmmm ... what does /interface/wifi/radio/reg-info country=Czech show on your device? On my audience (running 7.15.3) it says ranges: 2402-2482/20 5170-5250/23/indoor 5250-5330/23/indoor/dfs 5490-5710/30/dfs Which more or less corresponds with limits from "your" document). BTW numbers in ab...
by mkx
Thu Nov 14, 2024 6:36 pm
Forum: Wireless Networking
Topic: Feasibility of CAPsMAN VLAN and VPN Configuration on Point to Multi-Point with RB4011iGS+RM [SOLVED]
Replies: 18
Views: 2563

Re: Feasibility of CAPsMAN VLAN and VPN Configuration on Point to Multi-Point with RB4011iGS+RM [SOLVED]

Two things which poke my eyes: disable detect-internet at least on PtMP devices ... I'd disable it on all devices since you're trying to configure things properly yourself. Function detect-internet may help in case when user connects WAN to a wrong ether port. But it also have potential to royally m...
by mkx
Thu Nov 14, 2024 6:20 pm
Forum: General
Topic: Bonding 802.3ad
Replies: 8
Views: 283

Re: Bonding 802.3ad

According to my experience, Tx hash policies on both ends of bond don't have to be the same. Receiver will accept frames no matter via which bond link they arrive. It'll only use Tx hash policy (as configured locally) when selecting between (working) links members of same bond for Tx. So it will be ...
by mkx
Thu Nov 14, 2024 5:32 pm
Forum: General
Topic: Sonos bridge RX looped packet.
Replies: 1
Views: 79

Re: Sonos bridge RX looped packet.

The problem is that Sonos mesh obviously doesn't care about hetwork loops (neither do unmanaged switches). All managed switches know about xSTP (most have it enabled by default) and those can block one of links creating a loop.
by mkx
Thu Nov 14, 2024 5:23 pm
Forum: General
Topic: CCR2004 sudden PSU1+PSU2+fan failed
Replies: 2
Views: 186

Re: CCR2004 sudden PSU1+PSU2+fan failed

Any SFP with DDC plugged in (and being queried about their state)? IIRC it's been mentioned that there's a I2C bus which connects all internal monitored parts (power supplies and fans) as well as DDC buses of SFP cages. And if any of those devices block I2C bus for too long, ROS can not poll statuse...
by mkx
Thu Nov 14, 2024 5:13 pm
Forum: General
Topic: CRS112-8P low voltage error for 24V POE devices
Replies: 5
Views: 187

Re: CRS112-8P low voltage error for 24V POE devices

Indeed MT PoE offering is pretty inconsistent ... but there are a few rare devices which fare a tad better: CRS328-24P-4S+ has internal dual-voltage power supply and offers per-port selectable voltage (24V passive PoE or 48V 802.3 af/at) ... unfortunately it has limit if around 24W per port CRS320-8...
by mkx
Thu Nov 14, 2024 9:57 am
Forum: Beginner Basics
Topic: Time problem all the time
Replies: 4
Views: 191

Re: Time problem all the time

Check settings in Cloud ... since you have NTP client running (hopefully it shows status synchronized), you should disable time option in cloud settings.

BTW, if you're running NTP only to keep time on router current, you can disable NTP server function.
by mkx
Thu Nov 14, 2024 9:55 am
Forum: General
Topic: CRS112-8P low voltage error for 24V POE devices
Replies: 5
Views: 187

Re: CRS112-8P low voltage error for 24V POE devices

Yes. CRS doesn't regulate voltage internally, it only passes whatever supplied. CRS112 is one of few MT devices with dual power input, allowing to select voltage for PoE-out. If one of inputs is missing, corresponding PoE-out voltage is missing as well.
by mkx
Thu Nov 14, 2024 9:43 am
Forum: RouterBOARD hardware
Topic: VLAN BRidge switch chip NAT Only using one core RB 3011 UiAS RM [SOLVED]
Replies: 36
Views: 3057

Re: VLAN BRidge switch chip NAT Only using one core RB 3011 UiAS RM [SOLVED]

Contrast this to the RB3011 where the only way to have hardware offloaded VLANs is to perform the configuration directly on the switch chips. But because each of the two switch chips of the RB3011 has no knowledge of the other one, there is no mechanism in the switch chip configuration to refer to ...
by mkx
Thu Nov 14, 2024 9:25 am
Forum: General
Topic: Bonding 802.3ad
Replies: 8
Views: 283

Re: Bonding 802.3ad

When bond does hash (and based on hash value selects bond link to transmit frame), it takes whatever info configured: L2 - MAC address of source and destination L3 - IP address of source and destination L4 - source and destination port (if L4 protocol, e.g TCP or UDP) uses them. So with L2+L3 any pa...
by mkx
Thu Nov 14, 2024 9:22 am
Forum: General
Topic: VLAN config: RB2011UiAS-2HnD to L009UiGS-2HaxD
Replies: 3
Views: 136

Re: VLAN config: RB2011UiAS-2HnD to L009UiGS-2HaxD

Bridge port has to be tagged member of any VLANs which there are corresponding vlan interfaces.
by mkx
Thu Nov 14, 2024 8:28 am
Forum: General
Topic: Bonding 802.3ad
Replies: 8
Views: 283

Re: Bonding 802.3ad

L3+L4 is less common tho, but it should work good between two mikrotiks L3+L4 can spread traffic between one pair of devices to both bond links ... if devices use multiple connections in parallel. However, a single connection (e.g. single file transfer using SMB - windows file sharing) will still o...
by mkx
Wed Nov 13, 2024 4:50 pm
Forum: General
Topic: Routeros V7.15.3 randomly deleted users once a day.
Replies: 16
Views: 565

Re: Routeros V7.15.3 randomly deleted users once a day.

You haven't mentioned what the log is currently mentioning.
/system logging action
...

We are actually waiting to see output of /log/print (anything which looks weird and a few lines before weird lines to get some context).
by mkx
Wed Nov 13, 2024 4:45 pm
Forum: General
Topic: RBmAPL-2nD admin access to ethernet
Replies: 10
Views: 282

Re: RBmAPL-2nD admin access to ethernet

It boils down to this: interface lists work for interfaces ... and interfaces are the L3 entities (anything with IP address set). In case when one creates a bridge, adds a few L2 entities (ethernet ports, wifi interfaces, etc.), those L2 entities should never be used directly as L3 stuff (this is th...
by mkx
Wed Nov 13, 2024 4:32 pm
Forum: Wireless Networking
Topic: 60GHZ link doesn't agree.
Replies: 4
Views: 250

Re: 60GHZ link doesn't agree.

It's actually shooting under / between the branches.

Good. So the problem won't happen in Spring of 2025, it'll happen in Spring of 2026 :wink:
by mkx
Wed Nov 13, 2024 4:31 pm
Forum: Wireless Networking
Topic: Wave2 - Bridge.Ports vs. Wifi.Datapath
Replies: 28
Views: 8667

Re: Wave2 - Bridge.Ports vs. Wifi.Datapath

In case when I connect AP's as a wireless bridge with trunk - no questions about it. I would put specific wlan interface in "admit all" mode. But for users WiFi I would like to avoid it. Well ... what you'd like in this case doesn't correspond with what you can. And since it's up to perso...
by mkx
Wed Nov 13, 2024 4:24 pm
Forum: General
Topic: RBmAPL-2nD admin access to ethernet
Replies: 10
Views: 282

Re: RBmAPL-2nD admin access to ethernet

2 - check LAN interface list, both ether1 and ether2 should be there 3 - add all interfaces to bridge (ether1/2 and wifi itf) Actually ... bridge interface should be member of interface list. Individual ports (ether1 and ether2), members of bridge, don't have to be members of any interface list.
by mkx
Wed Nov 13, 2024 1:57 pm
Forum: General
Topic: RB5009 and VLANs
Replies: 13
Views: 437

Re: RB5009 and VLANs

Brief comments: # FIXME: Do I need to explicitly set this? # /interface/ethernet/switch set 0 l3-hw-offloading=yes No. Where did you get this from ? Certainly not from the VLAN guide... I think it's default with recent v7 ... even if device actually doesn't support L3HW which makes this setting irr...
by mkx
Wed Nov 13, 2024 12:18 pm
Forum: General
Topic: Questions about LAN setup [SOLVED]
Replies: 1
Views: 93

Re: Questions about LAN setup [SOLVED]

yes ... just hAP ac2 can't be powered from wAP ax (wAP ax doesn't have PoE-out) yes ... included PoE adapter is "PoE injector" which is plugged between switch and powered device. It is transparent for data passing between both sides. yes ... if hAP ac2 will be running wifi-qcom-ac package...
by mkx
Wed Nov 13, 2024 12:11 pm
Forum: General
Topic: Force DNS request [SOLVED]
Replies: 8
Views: 390

Re: Force DNS request [SOLVED]


Yes, this would help ... but you'd have to constantly update the list of DoH servers ... so it's a moving target.
by mkx
Wed Nov 13, 2024 12:10 pm
Forum: General
Topic: Routeros V7.15.3 randomly deleted users once a day.
Replies: 16
Views: 565

Re: Routeros V7.15.3 randomly deleted users once a day.

In such a case it _might_ also be worthwhile to export config, netinstall device and then re-apply config again.

With emphasis being "export ... re-apply config" ... which is very different from "backup ... restore".
by mkx
Wed Nov 13, 2024 12:08 pm
Forum: Beginner Basics
Topic: How to firewall when behind ISP modem
Replies: 13
Views: 413

Re: How to firewall when behind ISP modem

I have started from ground up, so I'm not using the defconf of the MT. IMO this is a pretty bad decision. Default MT firewall is quite good and allows for easy adaptation (e.g. for using PPPoE instead of DHCP client as WAN "technology"). It also allows to make adjustments (e.g for port fo...
by mkx
Wed Nov 13, 2024 12:03 pm
Forum: Announcements
Topic: v7.16.1 [stable] is released!
Replies: 421
Views: 111934

Re: v7.16.1 [stable] is released!

Will I loose the capsman configuration ? It is a possibility. As far as I remember wifiwave2 config structure is pretty close (if not the same) as the (new) wifi config structure. So even if you'll have to manually upgrade configuration after you upgrade ROS, it shouldn't be a big problem. Export (...
by mkx
Wed Nov 13, 2024 9:11 am
Forum: Wireless Networking
Topic: 60GHZ link doesn't agree.
Replies: 4
Views: 250

Re: 60GHZ link doesn't agree.

Distance is measured as round-trip time and difference of 9 m roughly translates to 30 nano seconds. I slightly doubt that timing resolution in WiFi chip is any better than this. RTT is measured by each radio independently ... so there can be slight differences. Other link properties are dynamic and...
by mkx
Wed Nov 13, 2024 8:58 am
Forum: General
Topic: Routeros V7.15.3 randomly deleted users once a day.
Replies: 16
Views: 565

Re: Routeros V7.15.3 randomly deleted users once a day.

Also check how much free space is on flash storage ... You didn't mention device model but some devices have tiny flash storage (16MB or even a bit less) and depending on amount of packages installed and complexity of configuration it may run out of space, which may cause ROS to loose configuration ...
by mkx
Wed Nov 13, 2024 8:55 am
Forum: General
Topic: about forward in cross switch chips?
Replies: 6
Views: 304

Re: about forward in cross switch chips?

MT doesn't provide separate documentation for particular device models. Several documents do include sections, which only apply to particular hardware, but often this is indicated in a way not really obvious to users not intimately familiar with devices (e.g. often they indicate that some section ap...
by mkx
Wed Nov 13, 2024 8:49 am
Forum: General
Topic: untagg multiple VLAN on ether port
Replies: 14
Views: 434

Re: untagg multiple VLAN on ether port

As already explained: you can't have multiple VLANs untagged on single port and having bidirectional communication (with exception of somehow implementing MAC VLAN which tags ingress packets based on source MAC addresses). I recommend you to rethink the network topology ... best would be to install ...
by mkx
Wed Nov 13, 2024 7:06 am
Forum: General
Topic: about forward in cross switch chips?
Replies: 6
Views: 304

Re: about forward in cross switch chips?

1. I don't know which exactly manual you're reading. But: RB4011 doesn't really belong in the group of devices mentioned. It's using RTL8367 switch chips and it didn't support VLAN switching configured by switch configuration (under /interface/ethernet/switch), the menu didn't exist. One could only ...
by mkx
Wed Nov 13, 2024 6:53 am
Forum: General
Topic: Force DNS request [SOLVED]
Replies: 8
Views: 390

Re: Force DNS request [SOLVED]

I think the problem is DOH, if I do a torch I see requests towards 8.8.8.8:443. so AdGuard is skipped. How do I manage these requests to process everything from AdGuard?

You don't manage DoH requests, you live with it.
by mkx
Tue Nov 12, 2024 7:29 pm
Forum: General
Topic: untagg multiple VLAN on ether port
Replies: 14
Views: 434

Re: untagg multiple VLAN on ether port

Only one vlan go pass untagged leaving ether 2 and that is predicated upon the pvid setting at /interface bridge port Wrong. Correct would be: All configured VLANs pass untagged leaving ether2 but only one VLAN offers bidirectional communication. Just because you don't see use case for something do...
by mkx
Tue Nov 12, 2024 7:22 pm
Forum: Wireless Networking
Topic: Feasibility of CAPsMAN VLAN and VPN Configuration on Point to Multi-Point with RB4011iGS+RM [SOLVED]
Replies: 18
Views: 2563

Re: Feasibility of CAPsMAN VLAN and VPN Configuration on Point to Multi-Point with RB4011iGS+RM [SOLVED]

6.40 is ancient and can miss some functionality. I highly recommend you to upgrade to 6.49.17 (latest v6). I understand you may struggle but IMO this is essential. And yes, netinstall is a almost certainly a must (lack of space likely indicates remnants of unwanted config and/or unnecessary files on...
by mkx
Tue Nov 12, 2024 7:11 pm
Forum: General
Topic: untagg multiple VLAN on ether port
Replies: 14
Views: 434

Re: untagg multiple VLAN on ether port

but also want to untagg VLAN-20 & (native VLAN-1) traffic on the ether port. Your main problem so far is that VLAN 20 is only mentioned in VLAN interface creation. Bridge doesn't kniw about VLAN 20, so it won't pass it between CPU and other bridge ports ... and other bridge ports are not config...
by mkx
Tue Nov 12, 2024 2:19 pm
Forum: Wireless Networking
Topic: Feasibility of CAPsMAN VLAN and VPN Configuration on Point to Multi-Point with RB4011iGS+RM [SOLVED]
Replies: 18
Views: 2563

Re: Feasibility of CAPsMAN VLAN and VPN Configuration on Point to Multi-Point with RB4011iGS+RM [SOLVED]

Did you manage to set up your PtMP into transparent operation? After this is done, you can add configuration to transparently pass 802.1Q headers (VLANs). Or you can decide not to go with VLANs and keep the whole network (all 3 sites) as one flat LAN. In any case, CAPsMAN / CAP configuration is exac...
by mkx
Tue Nov 12, 2024 2:13 pm
Forum: Wireless Networking
Topic: Wave2 - Bridge.Ports vs. Wifi.Datapath
Replies: 28
Views: 8667

Re: Wave2 - Bridge.Ports vs. Wifi.Datapath

I wonder why this bothers you? Let’s say I have obsessive-compulsive disorder ) My vision of an ideal world (mainly came from years of configuring various Cisco networks) is that user access edge should be always in “access mode”, that is tagged traffic should be avoided at all cost on access ports...
by mkx
Tue Nov 12, 2024 2:08 pm
Forum: Beginner Basics
Topic: Is sniffer cpu-port forbidden?
Replies: 1
Views: 121

Re: Is sniffer cpu-port forbidden?

switchX-cpu is a switch port and doesn't exist outside of /interface/ethernet/switch scope. Ether ports are (in ROS) different as ROS does have capability to work with individual switched ports (as if they were stand-alone interfaces). If you have a bridge and has any of there ports (run by that par...
by mkx
Tue Nov 12, 2024 2:04 pm
Forum: General
Topic: Discovering rogue DHCP source WAN IP
Replies: 7
Views: 297

Re: Discovering rogue DHCP source WAN IP

We only see the mac address and LAN ip of the device, is there a way to trace the source WAN IP or route over the radio link, at least this way we could work out who it might be. You can't see IP address of your device because (apart from acting as a switch) it doesn't collaborate in malicious acti...
by mkx
Tue Nov 12, 2024 1:56 pm
Forum: General
Topic: sfp-ignore-rx-los doesn't stick (and what exactly does it do?)
Replies: 2
Views: 1237

Re: sfp-ignore-rx-los doesn't stick (and what exactly does it do?)

It's not bug, it's how get works. Like this:
:put [ /interface/ethernet/get sfp-sfpplus1 sfp-ignore-rx-los ]
by mkx
Tue Nov 12, 2024 1:53 pm
Forum: General
Topic: Force DNS request [SOLVED]
Replies: 8
Views: 390

Re: Force DNS request [SOLVED]

3. if LAN clients are on same subnet as pi-hole, then you need to implement the SRC NAT part of hairpin NAT
by mkx
Tue Nov 12, 2024 1:51 pm
Forum: General
Topic: about forward in cross switch chips?
Replies: 6
Views: 304

Re: about forward in cross switch chips?

When traffic is bridged between both switch chip port groups, there are two bottlenecks: 2.5Gbps interconnect between switch chip and CPU ... if cumulative traffic between ether ports of single switch chip and the rest of RB4011 would exceed 2.5Gbps, then this will slow things down CPU processing p...
by mkx
Tue Nov 12, 2024 1:38 pm
Forum: General
Topic: MikroTik v.7.16.1 CAPsMAN, datapath doesn't work
Replies: 5
Views: 872

Re: MikroTik v.7.16.1 CAPsMAN, datapath doesn't work

Settings from CAPsMAN (datapath as well) are applied on CAP device. In your setup, you're setting /interface wifi configuration add country=Serbia datapath.bridge=bridge2 disabled=no mode=ap name=cfg1 security.ft=yes .ft-mobility-domain=0x1 .ft-over-ds=yes ssid="EF WiFi" but CAP device onl...
by mkx
Tue Nov 12, 2024 12:33 pm
Forum: Announcements
Topic: v7.16.1 [stable] is released!
Replies: 421
Views: 111934

Re: v7.16 [stable] is released!

... best practice is to use MAC of the first ethernet interface that is part of the bridge ... While this might be one of best approaches, it's not flawless ... if one removes "first ethernet interface" from bridge and forgets to change bridge MAC address, it's possible that some problems...
by mkx
Tue Nov 12, 2024 12:28 pm
Forum: Announcements
Topic: v7.17beta [testing] is released!
Replies: 654
Views: 129122

Re: v7.17beta [testing] is released!

MikroTik should probably revise the policy on having default configuration? While it can be understood that a CCR does not have a "forward" firewall (and "NAT"), for sure it should always have an "input" firewall. So it does not hurt to have an example of that in the d...
by mkx
Mon Nov 11, 2024 9:03 pm
Forum: RouterBOARD hardware
Topic: RB951Ui-2HnD port Running (R- flag) without cable connected to it
Replies: 5
Views: 333

Re: RB951Ui-2HnD port Running (R- flag) without cable connected to it

What to do to resolve the issue?

Throw RB951 in trash can?
by mkx
Mon Nov 11, 2024 9:00 pm
Forum: Wireless Networking
Topic: Wave2 - Bridge.Ports vs. Wifi.Datapath
Replies: 28
Views: 8667

Re: Wave2 - Bridge.Ports vs. Wifi.Datapath

But I didn't like the fact that with usage of datapath I got a tagged wireless traffic

I wonder why this bothers you?
by mkx
Mon Nov 11, 2024 8:33 pm
Forum: Beginner Basics
Topic: how to achieve this setup?
Replies: 4
Views: 280

Re: how to achieve this setup?

You cannot have the rb5009 providing separate subnets without double NAT ...
You can. But TPlink has to perform NAT also for "alien" subnets on LAN side ... and I've no idea if that's possible or not.
by mkx
Mon Nov 11, 2024 2:35 pm
Forum: Beginner Basics
Topic: Configuring wireless on wAP R from zero
Replies: 15
Views: 552

Re: Configuring wireless on wAP R from zero

Also, I don't really understand the logic of the "update ROS first, then upgrade firmware at next reboot": https://forum.mikrotik.com/viewtopic.php?t=199442 As I wrote in the last post of linked topic, FWF files (containing routerboot images) are inside ROS disk image. Generally installer...
by mkx
Sun Nov 10, 2024 10:27 pm
Forum: Wireless Networking
Topic: Feasibility of CAPsMAN VLAN and VPN Configuration on Point to Multi-Point with RB4011iGS+RM [SOLVED]
Replies: 18
Views: 2563

Re: Feasibility of CAPsMAN VLAN and VPN Configuration on Point to Multi-Point with RB4011iGS+RM [SOLVED]

By setting both spoke devices to station instead of station-bridge mode things get less transparent. So I wonder why you can't set these devices into station-bridge ... what is error message? Seeing CCQ considerably less than say 90 (100 would be ideal) while link is in use means trouble for the lin...
by mkx
Sun Nov 10, 2024 10:12 pm
Forum: Beginner Basics
Topic: CRS354-48P-4S+2Q+RM Performance Issues with Light Load
Replies: 5
Views: 314

Re: CRS354-48P-4S+2Q+RM Performance Issues with Light Load

CRS line of devices are switches ... by running ROS they can route but at fairly low speed. If running recent versions of ROS v7, certain configurations can offload routing and some firewalling to switch chip, increasing routed throughput a lot. Have a look at documentation: https://help.mikrotik.co...
by mkx
Sun Nov 10, 2024 4:21 pm
Forum: General
Topic: Periodic connectivity issues to external WinBox
Replies: 15
Views: 490

Re: Periodic connectivity issues to external WinBox

... if L3 hashing policy is used by them

L3 hashing depends on IP addresses (src and dst) so multiple connections (different ports) will always pass same LACP member. Only if L3+L4 hashing is used, then different connections (different src/dst port numbers) might take different LACP members.
by mkx
Sun Nov 10, 2024 1:48 pm
Forum: Beginner Basics
Topic: Configuring wireless on wAP R from zero
Replies: 15
Views: 552

Re: Configuring wireless on wAP R from zero

Some "essential" new ROS features require routerboot upgrade. Such as device-mode. (IIRC there were no such changes in ROS v6, routerboot changes were only necessary when hardware initialization had some problems). Also to boot ROS v7, one had to run some minimum version of routerboot (som...
by mkx
Sun Nov 10, 2024 1:02 pm
Forum: Beginner Basics
Topic: Move Configuration
Replies: 6
Views: 231

Re: Move Configuration

Is there a guide I could follow that helps me to setup WiFi?

Not a guide, but refrence manual for WiFi config: https://help.mikrotik.com/docs/spaces/R ... 59120/WiFi
by mkx
Sun Nov 10, 2024 12:57 pm
Forum: Beginner Basics
Topic: Configuring wireless on wAP R from zero
Replies: 15
Views: 552

Re: Configuring wireless on wAP R from zero

... although personally I use the later ... Couldn't that be called "preaching virtue but practicing vice"? :shock: Nope, not in case of routerboot upgrades ... I've never imposed (ever so mildly) suggestion in any direction in any of my posts (I'll buy you a beer or any other beverage of...
by mkx
Sun Nov 10, 2024 12:48 pm
Forum: General
Topic: Datasheet for new improved hEX?
Replies: 66
Views: 5741

Re: Datasheet for new improved hEX?

do any of ARM devices have IPsec acceleration working yet? It's not just a matter of the CPU architecture. I know. IPsec can as well depend on some particular CPU instructions ... which may or may not be present in some particular CPU implementation ... this seems to be the case. OTOH necesary inst...
by mkx
Sun Nov 10, 2024 12:17 pm
Forum: RouterBOARD hardware
Topic: Support for external LTE antennas
Replies: 11
Views: 972

Re: Support for external LTE antennas

If you don't mind "antenna connector surgery" and ugly-looking antennas on the outer building facade (or on roof top), then Iskra P-60 5G antenna set might fit the needs. They come with 5m or 10m of antenna cable, SMA connectors attached. And their gain is very decent for most of supported...
by mkx
Sun Nov 10, 2024 11:51 am
Forum: Wireless Networking
Topic: nRAYG-60 True Speed
Replies: 5
Views: 247

Re: nRAYG-60 True Speed

... if I'm reading the calculations correctly? Yup. And that's "required clearance" at the middle of link, it's less closer to either antenna. But it's a good rule of thumb to have such clearance along the whole length of link. Beware of trees, they (or at least some of them :wink:) tend ...
by mkx
Sun Nov 10, 2024 11:46 am
Forum: Beginner Basics
Topic: Move Configuration
Replies: 6
Views: 231

Re: Move Configuration

Are you sure your original device was hAP ax2 snd not hAP a c 2? With event of ax devices ROS now includes new wifi driver and config is under /interface/wifi . Older devices ran wireless driver (with config under /interface/wireless ) and some ac devices could run either of drivers (with default be...
by mkx
Sun Nov 10, 2024 11:34 am
Forum: Beginner Basics
Topic: Configuring wireless on wAP R from zero
Replies: 15
Views: 552

Re: Configuring wireless on wAP R from zero

Now #6 might be added as either: 6) You set automatic updates for routerboard firmware but not for ROS. or 6) You do not set automatic updates. Since your rules are intended "for dummies" (seasoned MT admins already live by these rules, right?), I'd go for the former ... although personal...
by mkx
Sun Nov 10, 2024 11:30 am
Forum: Beginner Basics
Topic: Move Configuration
Replies: 6
Views: 231

Re: Move Configuration

No simple way. Exported config depends on packages installed and builds on defaults. But also includes some of default config. So best chance to apply config from export is to start from no config on "recipient" ... and likely there will still be lines which will fail. And if they fail, yo...
by mkx
Sun Nov 10, 2024 11:24 am
Forum: General
Topic: Datasheet for new improved hEX?
Replies: 66
Views: 5741

Re: Datasheet for new improved hEX?

Then why are ipsec features listed as being tied to mt7621 on MT Help pages related to IPSEC ? MT7621 is a SoC ... which includes CPU (MMIPS architecture), switch chip and some other things. EN7562CT is a SoC as well ... which includes CPU (ARM architecture), switch chip (which is specced as EN7562...
by mkx
Sun Nov 10, 2024 11:12 am
Forum: General
Topic: inter vlan routing in CSS 326 24G
Replies: 6
Views: 250

Re: inter vlan routing in CSS 326 24G

CSS is strictly a switch, it can't do any routing. You'll have connect both routers together. You can use CSS and create an "interconnection" VLAN if you will, but both routers would then have to "speak" VLAN at least for interconnection VLAN. Or connect both touters with direct ...
by mkx
Sun Nov 10, 2024 10:56 am
Forum: General
Topic: Datasheet for new improved hEX?
Replies: 66
Views: 5741

Re: Datasheet for new improved hEX?

I expect IPSEC performance will be at least on par, if not better (since same MT7621 is included). Your expectation may be correct, but it's based on wrong premise. IPsec acceleration depends on CPU features or included accelerators ... but not on switch chip emulation. The new SoC EN7562CT include...
by mkx
Sun Nov 10, 2024 10:40 am
Forum: Beginner Basics
Topic: Request for Assistance with Load Balancing Configuration Between MikroTik Router and BDCOM Switch
Replies: 2
Views: 394

Re: Request for Assistance with Load Balancing Configuration Between MikroTik Router and BDCOM Switch

Look into 802.3ad bonding (a.k.a LACP). This has to be configured (and, above all, supported) on both sides. Bonds work best if all bond members use same speed. And beware that 802.3ad doesn't provide any mode which evenly distributes traffic between bond members "no matter what", it's alw...
by mkx
Sun Nov 10, 2024 10:29 am
Forum: Beginner Basics
Topic: How to forward traffic to the router behind Mikrotik
Replies: 2
Views: 450

Re: How to forward traffic to the router behind Mikrotik

Perhaps: configure CHR with firewall rules (and SRC NAT rule) according to defaults for SoHo MT devices (they were posted a few times in last year or two in some posts on this forum, use your favourite search engine to find them). Those defaults generally offer decent base for customization ... Then...
by mkx
Sun Nov 10, 2024 10:18 am
Forum: Beginner Basics
Topic: Configuring wireless on wAP R from zero
Replies: 15
Views: 552

Re: Configuring wireless on wAP R from zero

One addition: list by @amm0 in bullet #7 mentions QuickSet ... IMO it's worth mentioning that if user did anything according to bullets 3-11 outside of QuickSet (which is very likely), then use of QuickSet is a very avanturistic act since it can revert some of changes (but not all) and hence end res...
by mkx
Sat Nov 09, 2024 9:08 pm
Forum: General
Topic: Mikrotik GPON SFP Optimization
Replies: 10
Views: 460

Re: Mikrotik GPON SFP Optimization

If I'm wrong, please correct me then. If the PPPoE authentication is removed, logically, the product would only function like a switch and wouldn't be unnecessarily burdened.
If L3HW is configured, then your CRS could even route at wirespeed ... but yes, PPPoE is a deal-breaker here.
by mkx
Sat Nov 09, 2024 9:02 pm
Forum: General
Topic: Mikrotik GPON SFP Optimization
Replies: 10
Views: 460

Re: Mikrotik GPON SFP Optimization

The unclear thing is that they are using the same device with a 10 Gbps network. Probably as 10Gbps switch ... Thre's another thing: L3HW offload, which allows CRS3xx to route at wire speed. But it has many constraints. Read more at: https://help.mikrotik.com/docs/spaces/ROS/pages/62390319/L3+Hardw...
by mkx
Sat Nov 09, 2024 8:50 pm
Forum: General
Topic: Mikrotik GPON SFP Optimization
Replies: 10
Views: 460

Re: Mikrotik GPON SFP Optimization

SwitchOS offers only switching, no routing. But you probably need a router between internet and LAN. Regarding optimization: which part of my previous post is not clear to you? And a coment on "high-end device": a switch with MSRP of around $200 is hardly a high-end device. If retailers in...
by mkx
Sat Nov 09, 2024 7:56 pm
Forum: Wireless Networking
Topic: nRAYG-60 True Speed
Replies: 5
Views: 247

Re: nRAYG-60 True Speed

In theory link performance depends on how obstructed is Fresnel zone. Which is widest at the link midpoint and gets narrow at both antennas. Which means that for best performance clear direct line of sight is not enough, even some vicinity has to be obstruction-free. OTOH for link that has "som...
by mkx
Sat Nov 09, 2024 7:37 pm
Forum: Wireless Networking
Topic: Feasibility of CAPsMAN VLAN and VPN Configuration on Point to Multi-Point with RB4011iGS+RM [SOLVED]
Replies: 18
Views: 2563

Re: Feasibility of CAPsMAN VLAN and VPN Configuration on Point to Multi-Point with RB4011iGS+RM [SOLVED]

The difference between license level 3 and 4 (when it comes to radio) is that level 3 device can only be connected to one peer ... so any of station modes or bridge (but not ap-bridge). In PtMP scenario this means it can only be "spoke", not "hub". As to the rest of performance t...
by mkx
Sat Nov 09, 2024 7:31 pm
Forum: Wireless Networking
Topic: CAPs compability issues
Replies: 1
Views: 110

Re: CAPs compability issues

Device running ROSv7 version 7.13+ with wireless package installed (ot contains legacy capsman) can act as capsman for both legacy and modern APs. But with a few gotchas: if capsman also has wireless interfaces, then it better requires legacy drivers (generally this means pre v7 device) because driv...
by mkx
Sat Nov 09, 2024 7:16 pm
Forum: General
Topic: Mikrotik GPON SFP Optimization
Replies: 10
Views: 460

Re: Mikrotik GPON SFP Optimization

Your basic error is in believing that CRS326-24G-2S+RM is a decent router. In reality it's a switch which has (a fairly slow) CPU and when device runs ROS (it can run SwitchOS as well) it can route. And based on official test results you're getting very decent routing speeds for this device.
by mkx
Sat Nov 09, 2024 5:04 pm
Forum: Wireless Networking
Topic: nRAYG-60 True Speed
Replies: 5
Views: 247

Re: nRAYG-60 True Speed

No, ethernet ports are 1Gbps. "Aggregate speed" is a marketing BS buzzword ... effectively saying that port is full-duplex and can transfer at 1Gbps in both directions simultaneously. Wireless, OTOH, is half-duplex with large "direction switching" overhead ... so in reality (real...
by mkx
Sat Nov 09, 2024 4:33 pm
Forum: General
Topic: DNS Cache issue
Replies: 3
Views: 214

Re: DNS Cache issue

How are LAN devices configured ... to use adguard directly or to use router? This config is likely buried in DHCP server config.
by mkx
Sat Nov 09, 2024 4:30 pm
Forum: RouterBOARD hardware
Topic: RB3011 really broken?
Replies: 8
Views: 376

Re: RB3011 really broken?

@holvoetn now you started to nitpick. Who cares about performance if it looks this great?

If @jvanhambelgium cared about performance, then he wouldn't even think about fixing RB3011 (6x routing speed at 80% power consumption).
by mkx
Sat Nov 09, 2024 4:24 pm
Forum: General
Topic: Remove/change user-agent of a client?
Replies: 2
Views: 142

Re: Remove/change user-agent of a client?

This is entirely L7 operation. And ROS can not rewrite L7 information. With encrypted traffic (httpS) ROS even doesn't see this information, let alone can it manipulate encrypted information. A decent proxy server (browsers would have to be configured to use one) could rewrite this information ... b...
by mkx
Sat Nov 09, 2024 4:16 pm
Forum: General
Topic: Datasheet for new improved hEX?
Replies: 66
Views: 5741

Re: Datasheet for new improved hEX?

So it seems that hEX, with refresh, got degraded from a decent 5-port ethernet switch to a decent 4-port ethernet switch with management port :lol:
by mkx
Sat Nov 09, 2024 1:05 pm
Forum: RouterBOARD hardware
Topic: RB3011 really broken?
Replies: 8
Views: 376

Re: RB3011 really broken?

... brand new shiny RB5009
They may be shiny, but fun level is anywhere near what RB3011 provides: full 1U dimension, LCD display, two switch chips, etc. Only colour comes near RB3011's black :lol:
by mkx
Sat Nov 09, 2024 12:59 pm
Forum: Wireless Networking
Topic: Radio drops out occationally
Replies: 8
Views: 351

Re: Radio drops out occationally

Is there any way I can log those events?
I'm not sure. I some related tings (such as "received packet with own MAC address" or something like that) are logged even by default, not sure if there are some more extensive loggings available for STP.
by mkx
Sat Nov 09, 2024 12:10 pm
Forum: Wireless Networking
Topic: Radio drops out occationally
Replies: 8
Views: 351

Re: Radio drops out occationally

Logs are saying that there are some STP events which cause bridge to block wifi2 interface ... and 7 seconds later traffic resumes. As I wrote, those events don't necessarily originate from either of wifi bridge members, they could start somewhere else and got propagated across other switches and br...
by mkx
Sat Nov 09, 2024 11:44 am
Forum: RouterBOARD hardware
Topic: RB3011 really broken?
Replies: 8
Views: 376

Re: RB3011 really broken?

So ... what else is there to try execept for the trashcan ?

Replace RAM?
by mkx
Sat Nov 09, 2024 11:40 am
Forum: Wireless Networking
Topic: Radio drops out occationally
Replies: 8
Views: 351

Re: Radio drops out occationally

Is there any chance that you actually have some loop in your network? Not necessarily directly on either of these two wireless devices?

Another possibility is that there's an actual bug (in combination between L23UGSR and recent ROS), but only MT can tell that.
by mkx
Sat Nov 09, 2024 11:31 am
Forum: General
Topic: Where is my DHCPv6 clients ! ?
Replies: 5
Views: 327

Re: Where is my DHCPv6 clients ! ?

Do you have "detect-internet" active on any device other than "none"?
by mkx
Sat Nov 09, 2024 10:55 am
Forum: General
Topic: Datasheet for new improved hEX?
Replies: 66
Views: 5741

Re: Datasheet for new improved hEX?

That doesn't seem right if it's the 2024 model. Not really, basic switch chip functionality didn't change since ages ago. And Qualcomm does the same: my Audience uses IPQ4018 SoC ... and switch chip reported is Atheros-8327. My venerable RB951G uses discrete ethernet switch chip type ... Atheros-83...
by mkx
Fri Nov 08, 2024 9:13 pm
Forum: General
Topic: Issues with bandwidth [SOLVED]
Replies: 19
Views: 891

Re: Issues with bandwidth [SOLVED]

bandwidth test is very CPU intensive, in your case slow CPU is bottle neck. You realky should test throughput through switches. Using two computers and running iperf3 between them is pretty common way of testing. I guess the only issue here is to get hold on two computers which are actually capable ...
by mkx
Fri Nov 08, 2024 8:41 pm
Forum: General
Topic: Issues with bandwidth [SOLVED]
Replies: 19
Views: 891

Re: Issues with bandwidth [SOLVED]

How do you test bandwidth? By running bandwidth test function on switches them selves?
by mkx
Fri Nov 08, 2024 8:35 pm
Forum: Wireless Networking
Topic: wAP ax?
Replies: 226
Views: 24522

Re: wAP ax?

... setting the order of those interfaces is something which is done by startup script. I don't think so ... script says :local ifcId [/interface wifi find where default-name=wifi1] set $ifcId configuration.mode=ap channel.band=2ghz-ax disabled=no ... So the script knows that wifi1 is 2GHz radio (....
by mkx
Fri Nov 08, 2024 8:12 pm
Forum: Wireless Networking
Topic: Radio drops out occationally
Replies: 8
Views: 351

Re: Radio drops out occationally

Anything in logs of both devices?
by mkx
Fri Nov 08, 2024 5:37 pm
Forum: Wireless Networking
Topic: wAP ax?
Replies: 226
Views: 24522

Re: wAP ax?

anyone noticed the order of wifi1/2 has been changed ... AGAIN ?? Wifi1 = 2Ghz Wifi2 = 5Ghz It may have something to do with the fact, that IPQ-5010 has only 2.4GHz WiFi built in SoC and that 5GHz radio is added by attaching separate radio chip to PCIe interface. Previous AX hardware (at least some...
by mkx
Fri Nov 08, 2024 2:47 pm
Forum: Beginner Basics
Topic: Minor problems with hac ac lite as a wireless client
Replies: 9
Views: 445

Re: Minor problems with hac ac lite as a wireless client

That's explain why I can't connect to the hap from the main network? I can't ping it either. I've no idea. It might be due to the fact that static IP address is set on wlan2 instead of bridge1? From winbox only the frequency can erase. You can set frequency=auto , band=5ghz-a/n/ac and channel-width...
by mkx
Fri Nov 08, 2024 12:05 pm
Forum: Beginner Basics
Topic: FTP Rules in Firewall are apparently wrong
Replies: 13
Views: 501

Re: FTP Rules in Firewall are apparently wrong

Which is more likely: you're working on the right solution and merely need to find the right way to express it, or every one of us opposing this plan of yours is wrong? The former ... because everybody is jealous seeing the great plan of @OP and nobody else ever thought of going that way. BTW, grea...
by mkx
Fri Nov 08, 2024 11:56 am
Forum: Beginner Basics
Topic: Minor problems with hac ac lite as a wireless client
Replies: 9
Views: 445

Re: Minor problems with hac ac lite as a wireless client

Added to discussion in my previous post I have another suggestion: when configuring wireless interface into any of station modes, don't "pin point" radio settings to anything. If AP decides to change its own running values, station may not be able to follow those changes. In particular: se...
by mkx
Fri Nov 08, 2024 11:15 am
Forum: General
Topic: Towards Optimization of Production Firewall Rules
Replies: 13
Views: 623

Re: Towards Optimization of Production Firewall Rules

I'll just jump on a fragment: Analyzer: #1101 add action=accept chain=forward in-interface=WAN protocol=udp dst-port=443 dst-address=<QUIC Server> #1102 add action=accept chain=forward in-interface=WAN protocol=udp dst-port=443 dst-address=!<QUIC Server> The second rule is using a "not" ma...
by mkx
Fri Nov 08, 2024 11:00 am
Forum: Beginner Basics
Topic: Minor problems with hac ac lite as a wireless client
Replies: 9
Views: 445

Re: Minor problems with hac ac lite as a wireless client

Any station mode, other than "station-bridge", has problems when transparent bridge between two wired islands is required. In particular: MAC address of wired computer is lost when frame is passing such wireless link and any service, which expects to see unique MAC address (DHCP server is ...
by mkx
Thu Nov 07, 2024 7:43 pm
Forum: Wireless Networking
Topic: Please Respond - About new CapsMan (wifi)
Replies: 4
Views: 289

Re: Please Respond - About new CapsMan (wifi)

Default cap config it's called bridgeLocal.

Interesting, I didn't know that.
by mkx
Thu Nov 07, 2024 7:38 pm
Forum: Beginner Basics
Topic: Help DNS approach to Faster Browsing
Replies: 22
Views: 771

Re: Help DNS approach to Faster Browsing

Authoritativity of servers depends on whether they are declared (by SOA and NS records) as such for certain domain(s). All other servers are caching servers. Like DNS server at 8.8.8.8 is caching server for mikrotik.com ... and servers of @TomjNorthIdaho are exactly the same in tthis respect. So a ...
by mkx
Thu Nov 07, 2024 7:31 pm
Forum: General
Topic: Issues with bandwidth [SOLVED]
Replies: 19
Views: 891

Re: Issues with bandwidth [SOLVED]

Basically you have 5 switches. Currently help.mikrotik.com doesn't work for me and I can't verify, but from the top of my head none are really good at L3 tasks (they do support L3 HW offload). Which device does have address 192.168.1.1, netgear?
by mkx
Thu Nov 07, 2024 7:14 pm
Forum: General
Topic: Router Rebooting Issue
Replies: 2
Views: 219

Re: Router Rebooting Issue

I'd say that if wireless router is rebooting (and it's not powered via PoE from your MT router), then it's likely an issue of wireless router. But my logic might be flawed, what do I know?
by mkx
Thu Nov 07, 2024 7:07 pm
Forum: Beginner Basics
Topic: Help DNS approach to Faster Browsing
Replies: 22
Views: 771

Re: Help DNS approach to Faster Browsing

I maintain my own dedicated Linux BIND DNS servers. North Idaho Tom Jones Are these servers authoritative? Authoritativity of servers depends on whether they are declared (by SOA and NS records) as such for certain domain(s). All other servers are caching servers. Like DNS server at 8.8.8.8 is cach...
by mkx
Thu Nov 07, 2024 8:34 am
Forum: Wireless Networking
Topic: Please Respond - About new CapsMan (wifi)
Replies: 4
Views: 289

Re: Please Respond - About new CapsMan (wifi)

Not going into details, but ... wifi CAPsMAN doesn't offer "capsman forwarding" ... which means that anything, defined in datapath, is applied on each CAP device. In particular: your setting /interface wifi datapath add bridge=Bridge-CAPsMAN-202 disabled=no name=DP-VoIP-WLAN means that CAP...
by mkx
Thu Nov 07, 2024 8:22 am
Forum: General
Topic: Issues with bandwidth [SOLVED]
Replies: 19
Views: 891

Re: Issues with bandwidth [SOLVED]

You'll have to be much more specific to get any valuable feedback: which device models, their intended use, add exported config. Generally: if "3 layer 2 48 ports" (assuming you're talking about some CRS switches) are running RouterOS (as opposed to running SwitchOS), then they can be conf...
by mkx
Thu Nov 07, 2024 8:14 am
Forum: General
Topic: Towards Optimization of Production Firewall Rules
Replies: 13
Views: 623

Re: Towards Optimization of Production Firewall Rules

Personally I tend to avoid the ! matchers ... yes, they can be useful, but when one starts combining multiple "NOT" criteria, they are a bit counterintuitive and thus prone for errors. Or if one wants to have multiple rules with similar matchers, the only difference being the "NOT&quo...
by mkx
Wed Nov 06, 2024 7:47 pm
Forum: General
Topic: Towards Optimization of Production Firewall Rules
Replies: 13
Views: 623

Re: Towards Optimization of Production Firewall Rules

There is no magic in compilation and evaluation of firewall rules. They are strictly evaluated top-to-bottom, first matching executes. So the optimization trick is to reduce average number of rule evaluations (it was never explicitly stated whether all rules cost same CPU to evaluate or not, I'd exp...
by mkx
Wed Nov 06, 2024 7:08 pm
Forum: General
Topic: RB5009UG+S+ APC UPS Issues
Replies: 5
Views: 492

Re: RB5009UG+S+ APC UPS Issues

Could be that bug, which "freezes" display of UPS status, contributes to reboot as well. But anyway, I doubt you'll get any help about your problems on this forum, they don't seem to be due to configuration error, which is what we, fellow MT users, can help. But this forum is not one of of...
by mkx
Wed Nov 06, 2024 6:54 pm
Forum: Beginner Basics
Topic: Trying to wrap my head around VLANs
Replies: 17
Views: 1313

Re: Trying to wrap my head around VLANs

I just want to say that I have never been able to get a useful environment using VLANs. Well, VLAN is a tool ... Most people use tools because they have a task to do and certain tools fit the task perfectly (but one has to know different tools reasonably well to identify best tool for certain task)...
by mkx
Wed Nov 06, 2024 6:41 pm
Forum: Beginner Basics
Topic: Load balance between ether and wlan
Replies: 2
Views: 185

Re: Load balance between ether and wlan

Device with model name "RM950Ui-2HnD" doesn't exist. If, however, this is about RB951Ui-2HnD ... then it's an old and relatively slow device, ether ports are 100Mbps only, wireless is N so realistically around 100Mbps as well. CPU is no rocket either, it could route at around 200Mbps in si...
by mkx
Wed Nov 06, 2024 3:05 pm
Forum: General
Topic: wAP coverage -- picture included
Replies: 37
Views: 1691

Re: wAP coverage -- picture included

MIMO radios don't imply antenna layout. It's about making MIMO legs, transmitted over RF, distinguishable between each other as good as possible. Separate antenna ports ensure that ideally, the rest is up to antennas (and environment).
by mkx
Wed Nov 06, 2024 3:02 pm
Forum: General
Topic: RB5009UG+S+ APC UPS Issues
Replies: 5
Views: 492

Re: RB5009UG+S+ APC UPS Issues

Item #1 is a bug and you should report it to support@mikrotik.com

Item #2 ... did UPS provide power to RB's power adapter? If not, then it's a PEBKAC type of problem.
by mkx
Wed Nov 06, 2024 2:21 pm
Forum: General
Topic: Loopback interface sending DHCP broadcasts [SOLVED]
Replies: 7
Views: 440

Re: Loopback interface sending DHCP broadcasts [SOLVED]

Indeed MT failed to provide a good explanation so far. Below is my impression of it (it's limited as I disable the feature as soon as I remember doing it, which is around 2 seconds after I log in). From how it works (and from rare occasions when some MT staffer described some of it in some random fo...
by mkx
Wed Nov 06, 2024 2:05 pm
Forum: General
Topic: RB3011 White Blank Screen Issue on Startup [SOLVED]
Replies: 1
Views: 176

Re: RB3011 White Blank Screen Issue on Startup [SOLVED]

If it does function as a switch, then it does boot and applies come configuration. Which means you have to try harder to get it netinstalled (with current config wiped as well), process of netinstall is a pretty fragile and easily fails. If, when saying "blank white full screen", you're re...
by mkx
Wed Nov 06, 2024 2:00 pm
Forum: General
Topic: wAP coverage -- picture included
Replies: 37
Views: 1691

Re: wAP coverage -- picture included

What I don't understand is how the dual RP-SMA ports work? How does the AP (transceiver) look at those ports? Most probably those dual antenna ports are used for MIMO ... and for each MIMO leg (in WiFi they are called chains) one needs a separate antenna. Some antennas are dual-port (or MIMO) and a...
by mkx
Wed Nov 06, 2024 11:53 am
Forum: General
Topic: wAP coverage -- picture included
Replies: 37
Views: 1691

Re: wAP coverage -- picture included

There are such antennas, but they don't come cheap, are large and (some of them) look ugly. Antenna gain is generally proportional to antenna size and antenna size for given gain is generally proportional to wavelength. Which in essence means that at certain gain antenna for 2.4GHz has to be 2-times...
by mkx
Wed Nov 06, 2024 11:45 am
Forum: General
Topic: Loopback interface sending DHCP broadcasts [SOLVED]
Replies: 7
Views: 440

Re: Loopback interface sending DHCP broadcasts [SOLVED]

I then set it to detect only the interface with the Internet state. Actually ... after you do any kind of manual configuration (and you know which of interfaces will be connected to WAN) it's useless to have detect-internet enabled in any way. Because the only thing it could potentially do is screw...
by mkx
Wed Nov 06, 2024 11:41 am
Forum: General
Topic: VLANs - there has to be a simpler way!
Replies: 17
Views: 973

Re: VLANs - there has to be a simpler way!

I can understand your line of thought. However I guess that "VLAN wizard" will be out of scope of MT's tools for a while. The reason being: VLAN is feature which in principle spans whole LAN (or at least extensive parts), which includes several LAN infrastructure devices (possibly by diffe...
by mkx
Wed Nov 06, 2024 11:24 am
Forum: General
Topic: Router reset after reboot
Replies: 4
Views: 246

Re: Router reset after reboot

After netinstalling ... what did you do with configuration? Did you configure it from scratch? Or did you restore config from backup file? I configured from scratch, and yeah got deleted again when I just simply rebooted. This seems to me like a problem for support ticket. Contact MT support (you c...
by mkx
Wed Nov 06, 2024 11:16 am
Forum: Beginner Basics
Topic: Problem connecting my CCR2004-16G-2S+ to my CSR328-24P-4S+
Replies: 6
Views: 331

Re: Problem connecting my CCR2004-16G-2S+ to my CSR328-24P-4S+

First, a suggestion: winbox4 is still a beta software and has quite a few teething problems ... so try using winbox3 and see if it works better for you. Next: CCR config has quite a few problems, but a few are pretty grave: try to set MAC address to "LAN Bridge" manually. Principle is to t...
by mkx
Tue Nov 05, 2024 8:11 pm
Forum: Wireless Networking
Topic: LtAP, Verizon, Quectel EC-25AF no worky
Replies: 17
Views: 834

Re: LtAP, Verizon, Quectel EC-25AF no worky

... i.e. it's like GRUB so once RouterOS boots, I'd think it go away once boot.

It's not like grub, it's like BIOS or UEFI ... it initializes all hardware and can put it into some weird state which can't be remedied by drivers.
by mkx
Tue Nov 05, 2024 8:08 pm
Forum: General
Topic: Router reset after reboot
Replies: 4
Views: 246

Re: Router reset after reboot

After netinstalling ... what did you do with configuration? Did you configure it from scratch? Or did you restore config from backup file?
by mkx
Tue Nov 05, 2024 6:32 pm
Forum: Wireless Networking
Topic: Requesting help regarding my device running MESH
Replies: 20
Views: 514

Re: Requesting help regarding my device running MESH

... there is a huge difference in price, the price of the MOCA would allow me to re-route a CAT5e cable from the first floor.
So there's a way ... and I sense you're getting some will ... to do it properly :wink:
by mkx
Tue Nov 05, 2024 6:13 pm
Forum: Wireless Networking
Topic: WiFi Radio Issue
Replies: 9
Views: 386

Re: WiFi Radio Issue

Configuration of CRS refers to old wireless CAPsMAN. You have to configure the new WiFi capsman (there's a section with such title in document linked by @grusu above). If there's still wireless package installed on CRS, uninstall it.
by mkx
Tue Nov 05, 2024 11:27 am
Forum: RouterBOARD hardware
Topic: Rescriere bootloader in routerboard hEX S (RB 760iGS) [SOLVED]
Replies: 1
Views: 320

Re: Rescriere bootloader in routerboard hEX S (RB 760iGS) [SOLVED]

All MT devices have "primary" routerboot and "backup" routerboot. When upgrading routerboot, one upgrades primary one. It's (almost) impossible to upgrade backup routerboot. There's a procedure (button press) which selects backup routerboot ... and in that case, it should be poss...
by mkx
Tue Nov 05, 2024 11:21 am
Forum: Wireless Networking
Topic: Requesting help regarding my device running MESH
Replies: 20
Views: 514

Re: Requesting help regarding my device running MESH

Again, in my view a real ethernet cable is always better but as alternative, powerline can be used as well. @holvoetn, being European guy, keeps forgetting about possibility to use coax cables for data transmission ... there are even two standards, which allow using TV coaxial cables for data trans...
by mkx
Tue Nov 05, 2024 11:15 am
Forum: Wireless Networking
Topic: Unlock Wireless power to pump up dBm-s
Replies: 11
Views: 846

Re: Unlock Wireless power to pump up dBm-s

You have channel.width and channel.band set in wifi configuration profiles ... BTW, settings, which affect physical radio interface (frequency, band, width, Tx power, etc.) are only applied on master interface ... setting them on slave interfaces doesn't make any difference (and can be thus misleadi...
by mkx
Tue Nov 05, 2024 11:06 am
Forum: General
Topic: Migrating config between two identical routers
Replies: 1
Views: 147

Re: Migrating config between two identical routers

I read that the Backup/Restore option is a binary operation and is only really designed to backup/restore the same exact router but, can I use it to backup/restore the exact same MODEL of router? In your particular case (same router model, same ROS version), restoring backup on stand-by device will...
by mkx
Mon Nov 04, 2024 10:26 pm
Forum: Beginner Basics
Topic: Added 2nd rb5009 to my setup and lost internet connectivity.
Replies: 4
Views: 399

Re: Added 2nd rb5009 to my setup and lost internet connectivity.

I'll have to find out how to attach the second rb5009 as a switch instead of a router and try again. SOP when comissioning new device is to connect management computer directly to comissioned device ... and nothing else. It may be necessary to configure IP address on management computer manually (i...
by mkx
Mon Nov 04, 2024 10:08 pm
Forum: Beginner Basics
Topic: no internet access
Replies: 9
Views: 431

Re: no internet access

Basic problem of your WiFi AP is incomplete IP address setting, it's missing subnet setting. Change it like this: /ip address add address=192.168.11.251 /24 interface=bridgeLocal network=192.168.11.0 After you fix IP address, you'll be able to enter router's IP address which is currently rejected.
by mkx
Mon Nov 04, 2024 9:40 pm
Forum: Beginner Basics
Topic: no internet access
Replies: 9
Views: 431

Re: no internet access

Thanks, I suspect this too. But where to set GW for Bridge? See pics attached.

Set your main router's IP address in Gateway field.
by mkx
Mon Nov 04, 2024 9:19 pm
Forum: Wireless Networking
Topic: Unlock Wireless power to pump up dBm-s
Replies: 11
Views: 846

Re: Unlock Wireless power to pump up dBm-s

The settings I mentioned can be set in two locations: directly on wifi interface or in channel profile ... so check both places.
by mkx
Mon Nov 04, 2024 9:15 pm
Forum: Wireless Networking
Topic: AX No Supported Channels
Replies: 3
Views: 242

Re: AX No Supported Channels

Specs of Netmetal 5 ax say it's WiFi 6th generation ... not generation 6e (which added support for 6GHz bands) nor 7th generation (which also builds on 6GHz band).

So no, you can't drive Netmetal 5 ax higher than around 5.8GHz.
by mkx
Mon Nov 04, 2024 9:08 pm
Forum: Wireless Networking
Topic: wAP ax?
Replies: 226
Views: 24522

Re: wAP ax?

Why do clients then see weaker signal? Are higher gain antennas better for AP RX direction? Besides beeing more directional. Country limitation is about EIRP ... which is in most WiFi cases reduced to: Tx power + antenna gain. So the higher antenna gain, the lower Tx power ... but for clients the e...
by mkx
Mon Nov 04, 2024 8:00 pm
Forum: Wireless Networking
Topic: wAP ax?
Replies: 226
Views: 24522

Re: wAP ax?

BTW, what does /interface/wifi/radio/print detail show set to min-antenna-gain ? Acvording to your observations it should be set to 7 for both radios. 2 cap="MikroTik@xxxx" radio-mac=xxx tx-chains=0,1 rx-chains=0,1 bands=2ghz-g:20mhz,2ghz-n:20mhz,20/40mhz,2ghz-ax:20mhz,20/40mhz ciphers=tk...
by mkx
Mon Nov 04, 2024 7:45 pm
Forum: Wireless Networking
Topic: Requesting help regarding my device running MESH
Replies: 20
Views: 514

Re: Requesting help regarding my device running MESH

RB951Ui-2HnD (1F) should be configured both ap-bridge (to connect to 2F) Actually as "station-bridge" ... And "RB951Ui-2HnD (2F)" has to be "ap-bridge" (not sure, if mode "ap" - without bridge - is available though). I hope @OP is aware that all mentioned WiF...
by mkx
Mon Nov 04, 2024 7:38 pm
Forum: Wireless Networking
Topic: wAP ax?
Replies: 226
Views: 24522

Re: wAP ax?

And from these devices - all sharing the same SoC - you chose hap ax lite with the by far "lowest" values in the wireless specification table. I chose hAP ax lite because it poped up in my mind the first. Yes, it may be a poor choice ... but it does illustrate that Tx power can vary betwe...
by mkx
Mon Nov 04, 2024 7:23 pm
Forum: Wireless Networking
Topic: wAP ax?
Replies: 226
Views: 24522

Re: wAP ax?

Unless someone names me one "super-loose" country I could test the maximum values. Brazil is a "super-loose" country when it comes zo 2.4GHz band (30dBm Tx power). Pretty high Tx powers on 5GHz as well. BTW, what does /interface/wifi/radio/print detail show set to min-antenna-ga...
by mkx
Mon Nov 04, 2024 7:10 pm
Forum: General
Topic: IPv6 and Comcast
Replies: 3
Views: 286

Re: IPv6 and Comcast

Completely unset property dhcp-options="" ... setting it to empty value is not the same as not setting it at all.

I wonder why this properry is listed twice in the output of /ipv6/dhcp-client/print ...
by mkx
Mon Nov 04, 2024 7:06 pm
Forum: General
Topic: Cannot ping between Mikrotik CloudSwitch and RouterBoard when using a VLAN [SOLVED]
Replies: 6
Views: 520

Re: Cannot ping between Mikrotik CloudSwitch and RouterBoard when using a VLAN [SOLVED]

Not sure if the next thought actally applies, but you still may want to fix it: LAN interface list membership, which can be important for firewall (it seems to be used in IPv6 firewall though). This interface list has to contain interfaces not bridge ports. Most of times interfaces are those which a...
by mkx
Mon Nov 04, 2024 3:11 pm
Forum: General
Topic: wAP coverage -- picture included
Replies: 37
Views: 1691

Re: wAP coverage -- picture included

Maybe stupid question, but aren't the two HGO-antenna-OUT directly mounted too near to each other to do any good? Principle use of NetMetal ax is to attach good antennas to the RP-SMA connectors. The image with antennas attached shows secondary use, from product brochure: If necessary, you can adap...
by mkx
Mon Nov 04, 2024 2:58 pm
Forum: General
Topic: Cannot ping between Mikrotik CloudSwitch and RouterBoard when using a VLAN [SOLVED]
Replies: 6
Views: 520

Re: Cannot ping between Mikrotik CloudSwitch and RouterBoard when using a VLAN [SOLVED]

You didn't specify which ports on both devices are used to interconnect. So based on comments: port ether2 on RB5009 connects ether1 on CRS310. Which I guess should be trunk port, but you have on both ports set "frame-types=admit-only-untagged-and-priority-tagged" ?
by mkx
Mon Nov 04, 2024 2:49 pm
Forum: General
Topic: LHGG FG621-EA poor performance on Vodafone 4G [SOLVED]
Replies: 2
Views: 215

Re: LHGG FG621-EA poor performance on Vodafone 4G [SOLVED]

FG621-EA doesn't support carrier aggregation in uplink (while most contemporary smart devices do) ... and depending on MNO's configuration it may be forced to use cell with low capacity as serving cell which then limits UL speeds (for DL, where CA does work, this is not as big problem because the CA...
by mkx
Mon Nov 04, 2024 2:43 pm
Forum: General
Topic: CCR2004-1G-2XS-PCIe unexpected behavior
Replies: 6
Views: 2889

Re: CCR2004-1G-2XS-PCIe unexpected behavior

What I meant is that without knowing anything about networking and particular network layout in near vicinity of a networked device it's almost impossible to create a meaningful configuration ... specially if it includes advanced things (and having "Streaming Server" is advanced these days...
by mkx
Mon Nov 04, 2024 2:39 pm
Forum: General
Topic: New static route
Replies: 4
Views: 275

Re: New static route

Sorry, I don't use BTH (or WG), so I don't know how to set up default route via that kind of tunnels.
by mkx
Mon Nov 04, 2024 11:01 am
Forum: RouterBOARD hardware
Topic: Support for external LTE antennas
Replies: 11
Views: 972

Re: Support for external LTE antennas

I'm just curious though... Why wouldn't you just use a LHGG or SXT outside (as opposed to external antennae)? The general problem with MT's antennas (and even more with directional ones) is that their gain chart is really shitty. Take a look at LHGG ... indeed antenna gain is specced at 17dBi, but ...
by mkx
Mon Nov 04, 2024 10:51 am
Forum: General
Topic: wAP coverage -- picture included
Replies: 37
Views: 1691

Re: wAP coverage -- picture included

Dont forget: CRS: Cloud router switch ... ... which doesn't really belong into xAP family of devices, does it? And generally doesn't provide wireless coverage at all, does it? In case you missed: this thread was about wAP and @Normis tried to explain that wAP (due to being wall AP) doesn't really h...
by mkx
Mon Nov 04, 2024 10:49 am
Forum: General
Topic: Odd problem with DNS and VLANs
Replies: 2
Views: 208

Re: Odd problem with DNS and VLANs

You may want to add dns-server=<IP address> to settings under /ip dhcp-server network explicitly. Since you don't have them set explicitly, DHCP server might "invent" values for this property (as DHCP clients generally require it) and with automagically determined values is always potentia...
by mkx
Mon Nov 04, 2024 10:41 am
Forum: Beginner Basics
Topic: no internet access
Replies: 9
Views: 431

Re: no internet access

Also, unless I'm missing it, there isn't any masqerade stetting between the wan and lan. Not familiar with capsman, so could be in that already.

No, CAPsMAN doesn't do it. And since @OP is using this device as AP only, NAT is not something it is supposed to do (main router should do it).
by mkx
Mon Nov 04, 2024 9:25 am
Forum: Beginner Basics
Topic: no internet access
Replies: 9
Views: 431

Re: no internet access

The gateway should be set to the IP address of your router. This! You might want to consider using DHCP client (on the bridge) that handles correct IP addressing. There is one ... but as @OP writes, he's using static addressing, so likely he doesn't run DHCP server in his network. I agree that thes...
by mkx
Mon Nov 04, 2024 9:20 am
Forum: RouterBOARD hardware
Topic: Support for external LTE antennas
Replies: 11
Views: 972

Re: Support for external LTE antennas

I took a photo of a wAPac with 4 pigtails and an external 4x4 antenna. It works, but it requires the pigtails being exposed with ethernet/SIM/power, so it kinda easy to damage and crossing power. Looks neat though. But yes, such things are almost always a problem with DIY projects (or if device des...
by mkx
Mon Nov 04, 2024 9:04 am
Forum: Wireless Networking
Topic: Unlock Wireless power to pump up dBm-s
Replies: 11
Views: 846

Re: Unlock Wireless power to pump up dBm-s

What happens if you set "channel.band=2ghz-n" and channel.width="20mhz" ? And only one of these (leaving the other as you currently have it)?
by mkx
Mon Nov 04, 2024 8:55 am
Forum: General
Topic: wAP coverage -- picture included
Replies: 37
Views: 1691

Re: wAP coverage -- picture included

As in the name, it's a "wall acces point (wap)", Ah, so that's the meaning of initial letter in names of "xAP" devices ... so "cAP" means "ceiling AP". @Normins, do you mind explaining meaning of "h" in "hAP"? And are there any "pAP&q...
by mkx
Mon Nov 04, 2024 8:53 am
Forum: General
Topic: New static route
Replies: 4
Views: 275

Re: New static route

Your question is not very clear. So here's a "misty" (conceptual) answer: if next hop is not known this way or another (either IP address of next hop or point-to-point interface towards next hop), then it's not possible to create a route which would be helpful to router. You might get a mo...
by mkx
Mon Nov 04, 2024 8:49 am
Forum: General
Topic: Looking to upgrade
Replies: 4
Views: 243

Re: Looking to upgrade

@yxudous: if you don't feel like going for v7 (I'd recommend you to do it though, you'll be fine in hands of @anav and even if he won't be able to help, there are other experienced users of this forum willing to help), then you can safely upgrade from 6.48.1 to 6.49.17 ... there were no major (break...
by mkx
Sun Nov 03, 2024 11:34 pm
Forum: RouterBOARD hardware
Topic: Support for external LTE antennas
Replies: 11
Views: 972

Re: Support for external LTE antennas

fitted with a proper antenna connector (N-type) @mkx, out of curiosity, do you think N are better (or worse) than SMA for 4G/NR? I don't know if N connectors themselves perform any better or worse than others. But as you already wrote, when cables are in the question, thicker is always better and N...
by mkx
Sun Nov 03, 2024 11:14 pm
Forum: Wireless Networking
Topic: wAP ax?
Replies: 226
Views: 24522

Re: wAP ax?

I am more worried about the low 2.4ghz coverage.
What does "low 2.4ghz coverage" mean exactly?

@infabo wrote in another thread that he observed 2.4GHz radio at mostly the same RSSI as 5GHz ... while usually it would be a bit stronger. Didn't post too many details though.
by mkx
Sun Nov 03, 2024 11:11 pm
Forum: Wireless Networking
Topic: wAP ax?
Replies: 226
Views: 24522

Re: wAP ax?

Unless that QCN-6102 in between has something to do with it ...

If one can rely on block duagram, then it's QCN-6102 chip (and not the SoC) which is running the 5GHz radio. And various unreliable online sources say it supports 160MHz bandwidth and 2x2 MIMO.
by mkx
Sun Nov 03, 2024 4:33 pm
Forum: RouterBOARD hardware
Topic: Support for external LTE antennas
Replies: 11
Views: 972

Re: Support for external LTE antennas

Yes, mostly that's it.

There are a few devices (GrooveA 52, GrooveA 52 ac, metal 52 ac) which are fitted with a proper antenna connector (N-type). And there are some possibilities for full DIY (e.g. L23UGSR-5HaxD2HaxD board as a base).
by mkx
Sun Nov 03, 2024 4:19 pm
Forum: General
Topic: off-topic - Effect of DST on graphs
Replies: 5
Views: 369

Re: Note sure if ok to post...off-topic

I could change all 1,000,000,000 aspects of my life to 24 hour UTC.

Sticking to local sun time (+-30 minutes; i.e. local time zone) would already do miracles. The transitions between DST and "normal" time are fruitless and causing all sorts of nuisances.
by mkx
Sun Nov 03, 2024 11:16 am
Forum: Wireless Networking
Topic: Feasibility of CAPsMAN VLAN and VPN Configuration on Point to Multi-Point with RB4011iGS+RM [SOLVED]
Replies: 18
Views: 2563

Re: Feasibility of CAPsMAN VLAN and VPN Configuration on Point to Multi-Point with RB4011iGS+RM [SOLVED]

"Traffic direction" over PtMP has nothing to do with radio topology of PtMP setup. It's all about radio: single radio can not be station to two APs because it can only operate at one frequency. For this reason hub devices normally operate as APs and spoke devices operate as stations. It is...
by mkx
Sun Nov 03, 2024 10:43 am
Forum: Beginner Basics
Topic: Added 2nd rb5009 to my setup and lost internet connectivity.
Replies: 4
Views: 399

Re: Added 2nd rb5009 to my setup and lost internet connectivity.

One thing that might cause problems: by default all ROS devices (IIRC only some PtP devices are exception) cone configured with 192.168.88.1 as their LAN IP address. So it's almost essential to perform basic configuration (e.g. setting IP addresses, admin user's password, etc.) before connecting it ...
by mkx
Sat Nov 02, 2024 7:42 pm
Forum: Wireless Networking
Topic: Feasibility of CAPsMAN VLAN and VPN Configuration on Point to Multi-Point with RB4011iGS+RM [SOLVED]
Replies: 18
Views: 2563

Re: Feasibility of CAPsMAN VLAN and VPN Configuration on Point to Multi-Point with RB4011iGS+RM [SOLVED]

Configuration of PtMP gear is a separate task from configuring the rest of APs. In principle you first configure the device which will act as AP-bridge (the "hub" device) ... set up wireless parameters. Then set both "spoke" devices as station-bridge devices and get them connect ...
by mkx
Sat Nov 02, 2024 1:50 pm
Forum: Beginner Basics
Topic: Virtualized VLANs (for Proxmox) [SOLVED]
Replies: 12
Views: 4950

Re: Virtualized VLANs (for Proxmox) [SOLVED]

If we want to utilize all available vlans on single NIC, nothing works except with the configuration above, i.e. adding non-existent pvid. Not entirely true. When setting VLAN-related thing on bridge and sub-items, things are pretty much divided: items under bridge/port are about ingress behaviour ...
by mkx
Sat Nov 02, 2024 1:02 pm
Forum: Beginner Basics
Topic: Port forward firewall rule
Replies: 3
Views: 280

Re: Port forward firewall rule

When doing firewall filters which target specific DST-NAT rules, it's important to keep in mind that in packet processing, DST-NAT is done sooner than firewall filter rules (see excellent description of packet fliw in ROS ). So firewall filter rules have to match rewritten (by DST-NAT rule) dst-* va...
by mkx
Sat Nov 02, 2024 11:17 am
Forum: Beginner Basics
Topic: CAPsMAN with two bridges [SOLVED]
Replies: 6
Views: 359

Re: CAPsMAN with two bridges [SOLVED]

When using CAPsMAN to provision remote CAPs, datapath is applied remotely (there is no such thing as capsman forwarding in new wifi capsman anymore). Which means that CAP devices need bridge-guest pre-existing, CAPsMAN only provisions wifi radio but doesn't add/adjust other config. And then, when yo...
by mkx
Sat Nov 02, 2024 11:09 am
Forum: Wireless Networking
Topic: Feasibility of CAPsMAN VLAN and VPN Configuration on Point to Multi-Point with RB4011iGS+RM [SOLVED]
Replies: 18
Views: 2563

Re: Feasibility of CAPsMAN VLAN and VPN Configuration on Point to Multi-Point with RB4011iGS+RM [SOLVED]

Forget about CAPsMAN for your PtMP setup: CAPsMAN can only provision APs and in your case AP-bridge (SXT in garage) is not accessible from CAPsMAN (RB4011) until the link between main building and garage is already up ... which means AP-bridge device can't be provisioned by capsman. And since PtMP w...
by mkx
Sat Nov 02, 2024 10:42 am
Forum: Wireless Networking
Topic: Trying to understand vlan-filtering + datapath.vlan-id in capsman AX
Replies: 2
Views: 258

Re: Trying to understand vlan-filtering + datapath.vlan-id in capsman AX

Do these interfaces get added as access ports or trunk ports to bridge? Check it using /interface/bridge/vlan/print . If they are added as untagged, then it VLAN settings are ihnored and you'll have to set vlan-filtering=yes on bridge on all cAP devices. (Do enable safe mode before enabling vlan-fil...
by mkx
Sat Nov 02, 2024 10:22 am
Forum: General
Topic: Network setup with caps
Replies: 2
Views: 188

Re: Network setup with caps

It doesn't matter much. Well, if you do some traffic flow analysis (we can't do it for you), then you may discover some prevailing traffic directions (e.g. between wifi stations and NAS). And you probably want as little network hops as possible ... in average. Which, in case of massive wifi<->NAS tr...
by mkx
Sat Nov 02, 2024 10:08 am
Forum: Beginner Basics
Topic: Port forward firewall rule
Replies: 3
Views: 280

Re: Port forward firewall rule

The first rule you posted is MT's try to use single rule instead of two. And it only works with defaukt rules, as soon as you try to change NAT concepts (e.g. when adding hairpin NAT) it stops working. In principle it's possible to repkace the rule with two: add action=accept chain=forward in-interf...
by mkx
Fri Nov 01, 2024 4:56 pm
Forum: Wireless Networking
Topic: wAP ax?
Replies: 226
Views: 24522

Re: wAP ax?

On both wAP ac and hAP ax lite (so predumably on wAP ax as well) Tx power is limited by EIRP and thus range of wireless "cell" is exactly the same (at least in direction where each device's antenna has best gain) And why do I observe worse RSSI on the same distance? How much worse are you...
by mkx
Fri Nov 01, 2024 12:56 pm
Forum: Wireless Networking
Topic: wAP ax?
Replies: 226
Views: 24522

Re: wAP ax?

I think I understand your confusion, so I'll try to explain things. Tx power, used at any given moment, is capped by 3 independent limits: country regulatory limits of EIRP which includes antenna gain These limits can be per frequency sub-band and can include other things (e.g. TPC capability which ...
by mkx
Fri Nov 01, 2024 11:31 am
Forum: Wireless Networking
Topic: wAP ax?
Replies: 226
Views: 24522

Re: wAP ax?

Regulatory domain is Austria. When there is a 2.5dbm antenna inside, then 13dbm tx power is a huge bug. After reading all the posts in this thread, with special focus on your posts, I still don't understand your reasoning ... I don't know from where exactly you took the 13dBm figure (you posted som...
by mkx
Fri Nov 01, 2024 10:53 am
Forum: Wireless Networking
Topic: SXTsq 5ac as a PtP link - looking for suggestions for improvements
Replies: 8
Views: 861

Re: SXTsq 5ac as a PtP link - looking for suggestions for improvements

Interference (in this case a constructive one) can explain big differences in signal strengths. And at 5.5GHz, the mentioned displacement (10-15cm) is "many wavelengths" (which are characteristical for distance between "interference bands"). I know that @OP wrote that there's LOS...
by mkx
Fri Nov 01, 2024 10:23 am
Forum: Wireless Networking
Topic: capsman dualband with same SSID on different channels ?
Replies: 11
Views: 2891

Re: capsman dualband with same SSID on different channels ?

Is it possible to set up the secondary frequency for a 160mhz channel on the wifi1 interface, then create two virtual SSID's that each use one of the 80mhz channels? No, it's single radio regardless the channel width. Virtual SSIDs operate over "master" channel, they can't have separate r...
by mkx
Thu Oct 31, 2024 8:02 pm
Forum: Wireless Networking
Topic: Connection lost when lease extended?
Replies: 16
Views: 1317

Re: Connection lost when lease extended?

Here are the wireless debug lines: Oct/31/2024 12:27:04 wireless,debug B8:74:24:3A:AA:F4@cap-wifi2 associated, signal strength -21 Oct/31/2024 13:33:25 wireless,debug B8:74:24:3A:AA:F4@cap-wifi2 disassociated, connection lost, signal strength -19 Signal strengths, mentioned here (-19dBm, -21dBm), a...
by mkx
Thu Oct 31, 2024 4:46 pm
Forum: Beginner Basics
Topic: usb antenna on routerOS
Replies: 3
Views: 224

Re: usb antenna on routerOS

It's not loading drivers, it's just showing name instead of numerical IDs. Unlike in Windows (where drivers provide device names), in Linux (and ROS is on top of Linux) there's a text file, a database of USB (and PCI) IDs and mapping to device names. And this file has no relation to drivers on the d...
by mkx
Thu Oct 31, 2024 11:30 am
Forum: RouterBOARD hardware
Topic: SXTsq Lite5 with Atheros AR9300 max rf tx power.
Replies: 6
Views: 636

Re: SXTsq Lite5 with Atheros AR9300 max rf tx power.

Is there still a wil to overdrive the PA?

I don't think it's still possible to overdrive PA.
by mkx
Thu Oct 31, 2024 11:21 am
Forum: Wireless Networking
Topic: wAP ax?
Replies: 226
Views: 24522

Re: wAP ax?

Reported TX-power is like both antennas have 7dbi. That's what basically the PDF @ ffcid.io said: 6.9dbi 2ghz, 7dbi 5ghz. And that is what is burned into ROS as well. It may be a coincidence, but you're interpreting things wrong. What ROS reports as country-info is not what device can do, it's per-...
by mkx
Wed Oct 30, 2024 7:34 pm
Forum: General
Topic: Switch IP Packet Loss w/ HW Offload or Two Uplinks [SOLVED]
Replies: 5
Views: 401

Re: Switch IP Packet Loss w/ HW Offload or Two Uplinks [SOLVED]

I suggest you to upgrade ROS to latest v7 (7.16.1 at this time) on CRS. There were some changes in how RSTP works after 7.13. Also I wouldn't bother with setting port properties, bridge priority setting should do just fine. Port cost is inversely proportional to port speed, even without manually set...
by mkx
Wed Oct 30, 2024 4:56 pm
Forum: General
Topic: Only able to reach WebFig from some IPs
Replies: 4
Views: 408

Re: Only able to reach WebFig from some IPs

Based on the fact that router1 has 2 IP quite similar addresses I'd say that /28 is indeed the correct netmask. But: your laptop is in a completely different subnet than switch ... and switch is missing any route which would allow it to communicate outside its IP subnet (e.g. setting a default route...
by mkx
Wed Oct 30, 2024 11:37 am
Forum: General
Topic: Switch IP Packet Loss w/ HW Offload or Two Uplinks [SOLVED]
Replies: 5
Views: 401

Re: Switch IP Packet Loss w/ HW Offload or Two Uplinks [SOLVED]

Please, post config export from both devices ... run /interface export on both devices for start. It's much more readable than output of "print detail" for one thing. And why would you want to disable HW offload on switch? If you do, then all traffic via switch will have to pass CPU and yo...
by mkx
Wed Oct 30, 2024 10:45 am
Forum: General
Topic: Only able to reach WebFig from some IPs
Replies: 4
Views: 408

Re: Only able to reach WebFig from some IPs

My arithmetics says that 172.31.157.21/28 is outside of subnet 172.31.157.3/28 (which spans between .0 and .15, the first address being network address and the last being broadcast address). Config says your device uses /25 netmask (which covers both mentioned addresses), but is the same netmask use...
by mkx
Wed Oct 30, 2024 10:40 am
Forum: General
Topic: Netmetal AX wireless link
Replies: 4
Views: 320

Re: Netmetal AX wireless link

This is a hard question for me ... because I never used WDS for anything (neither with legacy wireless nor with new wifi). I always used bridge if I needed link between islands of devices (was lucky to always have had MT on both sides). I read some rumours that even WDS isn't really universally comp...
by mkx
Wed Oct 30, 2024 10:32 am
Forum: Beginner Basics
Topic: Mikrotik no longer handing IPs in reverse order?
Replies: 12
Views: 677

Re: Mikrotik no longer handing IPs in reverse order?

To make sure that it's your intended device handing out DHCP leases, fire up wireshark on client device and analyse DHCP handshake (trigger DHCP lease handshake by either executing renewal or by unplugging/replugging lan cable). If nothing else you'll see DHCP server's MAC address ... If there will ...
by mkx
Tue Oct 29, 2024 8:55 pm
Forum: Wireless Networking
Topic: CAPSMAN possibility
Replies: 2
Views: 249

Re: CAPSMAN possibility

Nope, both devices will never be controlled by same capsman ... so no benefit of sharing same config. And nothing of enhancing mobility.
by mkx
Tue Oct 29, 2024 8:30 pm
Forum: Beginner Basics
Topic: SSID Name for WiFi 2GHz and 5Ghz
Replies: 10
Views: 444

Re: SSID Name for WiFi 2GHz and 5Ghz

If one needs strong 2.4GHz signal for improved coverage, then the only way of decent mobility (in both directions, i.e. also from 2.4GHz to 5GHz) is to use new drivers (wifi) and rely on mobility functions ... where client still has decisive powers. By "mobility functions" do you mean cli...
by mkx
Tue Oct 29, 2024 8:17 pm
Forum: General
Topic: Netmetal AX wireless link
Replies: 4
Views: 320

Re: Netmetal AX wireless link

New ax devices require running wifi-qcom driver. While this driver brings better support for ac standard and introduces support for ax standard (not provided by older wireless drivers), it also cones with some drawbacks (or setbacks): it doesn't support nv2 (and neither nstreme) ... and the "br...
by mkx
Tue Oct 29, 2024 6:13 pm
Forum: General
Topic: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]
Replies: 47
Views: 2092

Re: RouterOS x86, no support for Chelsio T540 VF? [SOLVED]

Like addressing a FreeBSD request for the unsupported Bhyve ? Perhaps they could do it in no time because the issue is not about supporting anything specific to FreeBSD host (it's been said multiple times but you fail to get this through) but rather about including a hardware driver which already e...
by mkx
Tue Oct 29, 2024 6:02 pm
Forum: Beginner Basics
Topic: SSID Name for WiFi 2GHz and 5Ghz
Replies: 10
Views: 444

Re: SSID Name for WiFi 2GHz and 5Ghz

If one needs strong 2.4GHz signal for improved coverage, then the only way of decent mobility (in both directions, i.e. also from 2.4GHz to 5GHz) is to use new drivers (wifi) and rely on mobility functions ... where client still has decisive powers.
by mkx
Tue Oct 29, 2024 5:56 pm
Forum: Beginner Basics
Topic: Noob questions like Basic default reset-setup good enough?
Replies: 2
Views: 243

Re: Noob questions like Basic default reset-setup good enough?

My view: factory default setup is pretty decent, so performing reset to factory defaults is fine ... and then proceed from there I don't recomend to delete things from default config ... not until you fully grasp the ROS way of doing things. Related to that: ROS has a pretty steep learning curve fro...
by mkx
Tue Oct 29, 2024 5:43 pm
Forum: Beginner Basics
Topic: SSID Name for WiFi 2GHz and 5Ghz
Replies: 10
Views: 444

Re: SSID Name for WiFi 2GHz and 5Ghz

Roaming is what I would like to happen in my network as well. If your hAP ac3 runs RouterOS version 7.13 or newer, you can install wifi-qcom-ac drivers ... and uninstall wireless drivers. With this you'll get newer, more potent drivers, on your AP. One if new features, which come with wifi-qcom(-ac...
by mkx
Tue Oct 29, 2024 11:54 am
Forum: General
Topic: Hairpin NAT not working
Replies: 11
Views: 803

Re: Hairpin NAT not working

So that means i should just remove from the rule in-interface completely so it doesnt make a difference if the trafic comes from lan or wan? Yes. But you should replace it with some other matcher (as you already discovered). Let's dissect one of DST-NAT rules (they all are pretty similar, so they a...
by mkx
Tue Oct 29, 2024 11:20 am
Forum: Beginner Basics
Topic: Mikrotik hAP ax3 - slow download speed through wired connection
Replies: 6
Views: 1468

Re: Mikrotik hAP ax3 - slow download speed through wired connection

use /tools/profile when under load and bad throughput. I guess there is something running over cpu. In my case CPU tops at 20% max during download. Is that CPU load on single CPU or average? When doing scp (or single threaded iperf), there's a single connection and by design, all packets belonging ...
by mkx
Tue Oct 29, 2024 11:14 am
Forum: Beginner Basics
Topic: Routing between VLANs on RB4011 [SOLVED]
Replies: 6
Views: 432

Re: Routing between VLANs on RB4011 [SOLVED]

Is ether9 (on the wire side of port, towards PoE switch) supposed to carry tagged or untagged frames? Bridge port configuration ( add bridge=bridge interface=ether9 pvid=200 ) implies it's supposed to be untagged on wire side, but bridge vlan configuration ( add bridge=bridge tagged=ether9,bridge vl...
by mkx
Tue Oct 29, 2024 9:07 am
Forum: General
Topic: Hairpin NAT not working
Replies: 11
Views: 803

Re: Hairpin NAT not working

and just to be complete here are all my NAT rules to see if there is no conflict You don't have any dst-nat rule which would act on traffic towards traefik which is originating from LAN. All your dst-nat rules include in-interface-list=WAN and depending on configuration not shown here router's LAN ...
by mkx
Mon Oct 28, 2024 3:39 pm
Forum: Beginner Basics
Topic: Unable to route via VLANs
Replies: 16
Views: 965

Re: Unable to route via VLANs

I'm a bit sceptical seeing the VLAN ID list enclosed in double qoute marks ("), in ROS value lists usually aren't.

I've missed this part of config, though, I was focusing on the one posted in opening post of this thread.
by mkx
Mon Oct 28, 2024 2:05 pm
Forum: Beginner Basics
Topic: Unable to route via VLANs
Replies: 16
Views: 965

Re: Unable to route via VLANs

Read the first article I linked above ... it'll tell you what's the "cpu-facing bridge port". Spolier alert: properties, set on /inteface/bridge items, are mostly about "cpu-facing bridge port" (of the particular bridge), only a few are about "switch-like" entity. Which...
by mkx
Mon Oct 28, 2024 1:59 pm
Forum: RouterBOARD hardware
Topic: Replacement rack ear screws
Replies: 4
Views: 372

Re: Replacement rack ear screws

A fellow forum user @arnd did measurements and posted results in this post. I strongly believe that all MT rack-mountable devices use same type of "ear mounting" screws...
by mkx
Mon Oct 28, 2024 1:53 pm
Forum: Beginner Basics
Topic: Unable to route via VLANs
Replies: 16
Views: 965

Re: Unable to route via VLANs

As I wrote, default config has pvid=1 set on all bridge ports, including cpu-facing bridge port ... which means that you should use it as untagged on bridge interface (i.e. don't create VLAN interface for it). The other possibility is to make cpu-facing bridge port tagged member of VLAN 1 (and then ...
by mkx
Mon Oct 28, 2024 1:46 pm
Forum: Wireless Networking
Topic: RF Characteristics of hAP AC Lite
Replies: 8
Views: 396

Re: RF Characteristics of hAP AC Lite

Here is a maybe better description: https://www.arednmesh.org/comment/10459#comment-10459 One connector is definitely in the left hand corner, but you are right, the other two are on the opposite side of the PCB. Right. Another look at specs of hAP ac lite reminded me that 2.4GHz has 2 chains (for ...
by mkx
Mon Oct 28, 2024 1:25 pm
Forum: Beginner Basics
Topic: Unable to route via VLANs
Replies: 16
Views: 965

Re: Unable to route via VLANs

The management VLAN across the network is VLAN 1. Is it "native" or "trunk"? In Mikrotik world, "native" translates to "access port" to that VLAN[*] ... and MT default config uses VID=1 as well ... but it's untagged over "cpu-facing bridge port" (se...
by mkx
Mon Oct 28, 2024 12:08 pm
Forum: Wireless Networking
Topic: RF Characteristics of hAP AC Lite
Replies: 8
Views: 396

Re: RF Characteristics of hAP AC Lite

the two antennas are the two dark blocks in bottom left corne I don't think so. The "higher" block (the one on picture closer to the center vertically) is actually USB port. Wireless chip is the one with large "Q" on it and all the RF seems to be routed to the lower right corner...
by mkx
Mon Oct 28, 2024 11:13 am
Forum: Announcements
Topic: Newsletter #121 | October 2024
Replies: 50
Views: 5892

Re: Newsletter #121 | October 2024

Sorry guys, but 802.11be was standartized already - 26.9.2024. https://standards.ieee.org/ieee/802.11be/7516/ Oh yes, this was ages ago. Yes, some vendors do develop and even start to market products before final standard gets adopted. They count on the possibility to make their products compliant ...
by mkx
Mon Oct 28, 2024 8:03 am
Forum: RouterBOARD hardware
Topic: SXTsq Lite5 with Atheros AR9300 max rf tx power.
Replies: 6
Views: 636

Re: SXTsq Lite5 with Atheros AR9300 max rf tx power.

Yes, I meant ROS version ... typing on a tablet (no tactile feedback from keyboard) is a RPITA. And ROS stands for RouterOS. So your device is running ROS version 6.49.11 ... but where did the "2.9.31" number came from? If it's from "System -> Router board " under "Current f...
by mkx
Sun Oct 27, 2024 9:51 pm
Forum: Beginner Basics
Topic: Testing mikrotik rb951g-2hnd with jperf and wifi Download over wifi is much slower than the upload
Replies: 4
Views: 877

Re: Testing mikrotik rb951g-2hnd with jperf and wifi Download over wifi is much slower than the upload

There are a few things which might explain your observations: wireless transmission is more CPU demanding than reception ... and CPU in RB951G is no rocket if your RB is running decently new version of ROS, then it might be limited with Tx power ... and if client is not very close to AP, then lack o...
by mkx
Sun Oct 27, 2024 9:36 pm
Forum: RouterBOARD hardware
Topic: SXTsq Lite5 with Atheros AR9300 max rf tx power.
Replies: 6
Views: 636

Re: SXTsq Lite5 with Atheros AR9300 max rf tx power.

Which ROS verdion are you running on your SXTsq Lite5? Tx power calculations have changed in the last few years and currently actual Tx power (output from RF power amplifier) is determined with the following rules: use country regulatory limit (EIRP) for the used channel and reduce it by antenna gai...
by mkx
Sun Oct 27, 2024 9:11 pm
Forum: Beginner Basics
Topic: Client isolation with hardware offloading
Replies: 4
Views: 325

Re: Client isolation with hardware offloading

No, it won't work nicely. You're using device as a switch, so you're looking at using software bridge. And there aren't any fine-tuning knobs as to what to offload from bridge to hardware and what not. If you'd go via ip-firewall on bridge, all the traffic would have to pass software bridge (CPU bou...
by mkx
Sun Oct 27, 2024 9:03 pm
Forum: General
Topic: "radar detected" But No Recovery - Am I Doing Something Stupid?
Replies: 7
Views: 392

Re: "radar detected" But No Recovery - Am I Doing Something Stupid?

Still ... the frequency range you're allowing is 5 20MHz-channels wide, not allowing much room for avoidance of radar ... specially so as you're using default setting (of 80MHz wide channels). And it doesn't matter if radar detection is real or spurious, in both cases it's likely to happen again.
by mkx
Sun Oct 27, 2024 3:33 pm
Forum: Beginner Basics
Topic: Client isolation with hardware offloading
Replies: 4
Views: 325

Re: Client isolation with hardware offloading

I always had an impression that whatever is set under /interface ethernet is performed by switch chip, i.e. hardware offloaded.

So are there any indications that drvice's CPU is doing the work?

And do mention device type, when it comes to HW offload things depend a lot on actual hardware used.
by mkx
Sun Oct 27, 2024 11:37 am
Forum: Beginner Basics
Topic: Wireless AP and Router on different subnets - imperfect communication
Replies: 3
Views: 275

Re: Wireless AP and Router on different subnets - imperfect communication

Conceptually a very important question: do you have any reason not to configure AP as only switch/AP combo (i.e. eliminate the routing part) and let wireless clients become full-time part of "main" LAN ? Because this is very much possible with Mikrotik wireless devices.
by mkx
Fri Oct 25, 2024 1:15 pm
Forum: Beginner Basics
Topic: Mangle Rules blocked my DNS IP
Replies: 9
Views: 687

Re: Mangle Rules blocked my DNS IP

... no-one on your network would be able to access TikTok though, unless you manually allowed it. Or if user uses device which uses own configuration for certain services, such as DNS over HTTPS towards app producers' favourite DoH provider (can be Web browser with DoH support and has DoH server ad...
by mkx
Fri Oct 25, 2024 10:09 am
Forum: RouterBOARD hardware
Topic: CCR2004-1G-12S+2XS rebooting
Replies: 4
Views: 823

Re: CCR2004-1G-12S+2XS rebooting

It is interesting that router has wrong time after booting and ntp fix it after while, This is normal with MT devices, they don't have RTC built in and ROS has to use some tricks to come up with approximation of correct tine (but that's usually several minutes or even tens of minutes in the past). ...
by mkx
Fri Oct 25, 2024 9:58 am
Forum: RouterBOARD hardware
Topic: Recommend router and switch connected with private fiber
Replies: 32
Views: 1611

Re: Recommend router and switch connected with private fiber

When it comes to infrastructure prices, multi-mode fiber and SFP modules come cheaper than single-mode ones (the later is used by telecoms because it allows for much longer distances). Just make sure the cable is OM-3 or higher, lower-specced cables don't support 10Gbps at those distances. If budget...
by mkx
Fri Oct 25, 2024 9:40 am
Forum: RouterBOARD hardware
Topic: CSS610-8P-2S+IN -> CSS610-8G-2S+IN power
Replies: 3
Views: 282

Re: CSS610-8P-2S+IN -> CSS610-8G-2S+IN power

Ah, I missed this: I attempted to draw power from the DC jack on front side of the P switch and deliver it to the front DC jack of the G switch. No, this is not possible, jacks are power-in-only. They are "protected" by a diode ... which also prevents from funny things to happen if multipl...
by mkx
Fri Oct 25, 2024 9:22 am
Forum: Wireless Networking
Topic: LTE ISP throttle...
Replies: 8
Views: 588

Re: LTE ISP throttle...

EDIT: Interestingly, it appears to apply to the LTE device. When I tried to apply it to the hEX, I got the error below.

The article, linked in post #3 above, says that mangling rule should go to chain=postrouting ...
by mkx
Fri Oct 25, 2024 9:12 am
Forum: General
Topic: L009UiGS-2HaxD-IN - Practical WiFi speeds, real life?
Replies: 3
Views: 320

Re: L009UiGS-2HaxD-IN - Practical WiFi speeds, real life?

(Antenna gain is lower, I have not tested range, but I did notice that it is quite good.) As country regulatory limitations are for EIRP and this includes antenna gain, the AP range doesn't depend on antenna gain (as it used to decades ago)... unless RF power amplifier lacks power. So what higher a...
by mkx
Fri Oct 25, 2024 8:53 am
Forum: Announcements
Topic: Newsletter #121 | October 2024
Replies: 50
Views: 5892

Re: Newsletter #121 | October 2024

The "hEX refresh" does not have IPsec test results, ...

Not to downplay the importance of publishing IPsec results ... but lately they are becoming increasingly irrelevant. Most people are moving towards wireguard (and alikes), which AFAIK doesn't use IPsec HW offload.
by mkx
Thu Oct 24, 2024 7:59 pm
Forum: RouterBOARD hardware
Topic: CSS610-8P-2S+IN -> CSS610-8G-2S+IN power
Replies: 3
Views: 282

Re: CSS610-8P-2S+IN -> CSS610-8G-2S+IN power

The P version of CSS610 should be able to power the G version just fine. G version accepts anything between 12V and 57V on PoE-in, so even with some voltage drop in cables it should be fine. Max rated power consumption of G variant is specced at 11W, even if input voltage would drop to 44V this mean...
by mkx
Thu Oct 24, 2024 6:47 pm
Forum: Wireless Networking
Topic: Best hardware for indoor extension of high speed wireless connection
Replies: 6
Views: 575

Re: Best hardware for indoor extension of high speed wireless connection

I'd be interested to know if there is a possibility to switch from cabled connections to wireless connections within the building. No, definitely not. If walls are not made of paper, no wireless technology can offer better performance than at least half decent wires or coax. Beware that wired techn...
by mkx
Thu Oct 24, 2024 6:40 pm
Forum: Wireless Networking
Topic: worst performance of NetBox 5AX.. Is there any user who uses this NetBox 5AX??
Replies: 23
Views: 3415

Re: worst performance of NetBox 5AX.. Is there any user who uses this NetBox 5AX??

configuration.antenna-gain=20 Can you lower it down, 20 is high I have tried 5GHz ax 5GHz AC 5GHz A/N 20/40/80 Mhz 20/40 Mhz You're advised to do one thing and you come back telling that doing something else didn't help. Which means that giving advices to you is useless. So not a Mikrotik problem.
by mkx
Thu Oct 24, 2024 6:27 pm
Forum: Beginner Basics
Topic: IPSEC Fasttrack
Replies: 12
Views: 616

Re: IPSEC Fasttrack

So if I've understood correctly, the FastTrack firewall rule is not an "accept FastTracked connections" but something more like "accept that this new connections will be Fasttracked", is it correct? In that case, everything make sense, sorry for the misunderstanding. Correct. Wi...
by mkx
Thu Oct 24, 2024 6:20 pm
Forum: Beginner Basics
Topic: Can't figure out port forwarding
Replies: 12
Views: 596

Re: Can't figure out port forwarding

Something doesn't add up ... there's no configuration line (neither firewall or anything else) which would explain "refuse from within the network" ... firewall rules, which "refuse" connections, are "action=reject". All firewall rules shown are either accept or "d...
by mkx
Thu Oct 24, 2024 3:33 pm
Forum: Beginner Basics
Topic: IPSEC Fasttrack
Replies: 12
Views: 616

Re: IPSEC Fasttrack

Once a connection is fasttracked, most of the packets will bypass the firewall and are not affected by the two defconf filter rules. That's not correct because default rules don't have "connection state new only" so they will always match before FastTrack because they match established se...
by mkx
Thu Oct 24, 2024 2:41 pm
Forum: Beginner Basics
Topic: IPSEC Fasttrack
Replies: 12
Views: 616

Re: IPSEC Fasttrack

Packets with encrypted payload, belonging to IPsec tunnel (don't know how to describe them better) will use chains input and output ... Establishment of IPsec tunnel between two peers will usually start by sending packets (and thus using chain=output, default config allows all) and then return packe...
by mkx
Thu Oct 24, 2024 11:38 am
Forum: Wireless Networking
Topic: LTE ISP throttle...
Replies: 8
Views: 588

Re: LTE ISP throttle...

I'd say on hEX ... because SXT doesn't touch TTL value of passing packets if it's in passthrough mode.
by mkx
Thu Oct 24, 2024 11:30 am
Forum: General
Topic: arp/proxy arp problem
Replies: 5
Views: 318

Re: arp/proxy arp problem

I don't have practical experience with OVPN ... so far I'm using other encrypted point-to-point tunnels (IPIP, ...) so I can't give you any more practical suggestions. Hopefully somebody else with OVPN experience will pass by and help you further.
by mkx
Thu Oct 24, 2024 11:13 am
Forum: Beginner Basics
Topic: IPSEC Fasttrack
Replies: 12
Views: 616

Re: IPSEC Fasttrack

I think you can use connection-state=new on the mangle rule to alleviate a lot of that processing. The most processing it's possible to bypass/skip is to fasttrack packets, as already explained further packets belonging to fasttracked connections skip lots of processing. So no need to bother with c...
by mkx
Thu Oct 24, 2024 9:59 am
Forum: General
Topic: Planned MLAG Setup correct? [SOLVED]
Replies: 15
Views: 1991

Re: Planned MLAG Setup correct? [SOLVED]

but one of the blue links is an alternate port? The role of blue links depends on particular setup. If nothing special is done about them, then they are active/backup, handled by xSTP. If they are configured as LACP bonds (between both pair of MLAG-configured switches), then the way they are used d...
by mkx
Thu Oct 24, 2024 9:16 am
Forum: General
Topic: arp/proxy arp problem
Replies: 5
Views: 318

Re: arp/proxy arp problem

Set one of 10.3.100.x/24 addresses to OVPN interface ... and let router do routing. You may have to adjust firewall filter rules, default allows almost all communication except for WAN to elsewhere. Depending on needs you either have to add some firewall rules which will deal with OVPN traffic expli...
by mkx
Thu Oct 24, 2024 9:06 am
Forum: General
Topic: Mikrotik internal DNS source IP selection
Replies: 2
Views: 272

Re: Mikrotik internal DNS source IP selection

The rule for selecting IP address is: do the routing selection and take IP address, associated with egress interface. Which is either pref-src (if set) or interface's "native" IP address. Which is more or less the same procedure as when it comes to SRC NAT action masquerade. My experience ...
by mkx
Thu Oct 24, 2024 8:48 am
Forum: Beginner Basics
Topic: Can't figure out port forwarding
Replies: 12
Views: 596

Re: Can't figure out port forwarding

I have a feeling that there are some other (minor?) issues with your config. Can you export complete config and post it here? Execute /export file=anynameyouwish from terminal window, fetch the resulting file, open it in your favourite text editor, redact any remaining sensitive data (such as passwo...
by mkx
Thu Oct 24, 2024 8:37 am
Forum: Beginner Basics
Topic: Mangle Rules blocked my DNS IP
Replies: 9
Views: 687

Re: Mangle Rules blocked my DNS IP

My personal view: trying to selectively block certain contents (like TikTok) is becoming almost futile due to encryption everywhere ... and since trying to do it created quite some problems to you, I'd simply give up (and deal with users of "unwanted" services in other ways).
by mkx
Thu Oct 24, 2024 7:35 am
Forum: Beginner Basics
Topic: Mangle Rules blocked my DNS IP
Replies: 9
Views: 687

Re: Mangle Rules blocked my DNS IP

That's because your L7 firewall rule works on all kinds of traffic, including DNS requests. Controversely it may or may not work with majority of "infringing" traffic, which is encrypted HTTPS ... it only works with SSL abd TLS up to version 1.2 because these carry SNI (server name indicat...
by mkx
Thu Oct 24, 2024 7:22 am
Forum: Beginner Basics
Topic: Can't figure out port forwarding
Replies: 12
Views: 596

Re: Can't figure out port forwarding

The problem was that you did not have a rule to accept port forwarded connections!

There was, rule #11 (the last one) from the printout. Problem is/was, that NAT rules are/were wrong ... as I wrote two times already.
by mkx
Wed Oct 23, 2024 9:39 pm
Forum: Beginner Basics
Topic: Can't figure out port forwarding
Replies: 12
Views: 596

Re: Can't figure out port forwarding

I disabled this rule: You should be worried as you potentially opened your LAN for external attacks. Read the rule I posted again. I didn't change the rule to in-interface=WAN but rather to in-interface-list=WAN. Since you don't complain about internet not working, I assume that the SRC NAT (masque...
by mkx
Wed Oct 23, 2024 7:27 pm
Forum: General
Topic: hAC ax2 Mode Button To Power Off and Power On when pressed? [SOLVED]
Replies: 5
Views: 341

Re: hAC ax2 Mode Button To Power Off and Power On when pressed? [SOLVED]

I suggest to unplug wire from MT device itself. Reason being that power adapter (embedded in wall plug) contains capacitors, which try to power connected device after AC fails (or is disconnected), And while doing so, voltage steadily drops and when it drops below device minimum required voltage, un...
by mkx
Wed Oct 23, 2024 7:16 pm
Forum: Beginner Basics
Topic: possible SYN flooding on tcp port 53 [SOLVED]
Replies: 7
Views: 524

Re: possible SYN flooding on tcp port 53 [SOLVED]

Try to add this rule somewhere to the top of rules (e.g. right below the "accept established,related" rule) add chain=input action=log log-prefix="TCP 53" connection-state=new protocol=tcp dst-port=53 For a good measure, you can add a similar rule, but for chain=forward. They sho...
by mkx
Wed Oct 23, 2024 6:27 pm
Forum: Beginner Basics
Topic: possible SYN flooding on tcp port 53 [SOLVED]
Replies: 7
Views: 524

Re: possible SYN flooding on tcp port 53 [SOLVED]

Do are you saying you saw it in log? Or what?
by mkx
Wed Oct 23, 2024 6:21 pm
Forum: Beginner Basics
Topic: possible SYN flooding on tcp port 53 [SOLVED]
Replies: 7
Views: 524

Re: possible SYN flooding on tcp port 53 [SOLVED]

How do you figure it's a syn flooding going on? (I'm not saying it doesn't, just wondering what makes you think it is)
by mkx
Wed Oct 23, 2024 6:19 pm
Forum: General
Topic: hAC ax2 Mode Button To Power Off and Power On when pressed? [SOLVED]
Replies: 5
Views: 341

Re: hAC ax2 Mode Button To Power Off and Power On when pressed? [SOLVED]

There is no power off button. I guess you could create a script which would perform "shutdown" ... but it wouldn't power off device (none of MT hardware so far supports power off from ROS) so you'd have to time yourself before cutting power. Piwer-on is simply done by connecting power, no ...
by mkx
Wed Oct 23, 2024 5:30 pm
Forum: General
Topic: Datasheet for new improved hEX?
Replies: 66
Views: 5741

Re: Datasheet for new improved hEX?

ŽThe best solution would be to have this info both on router and PSU pages, but just on the PSU one would be good. IMO the info should be for devices. PAs are "consumables", which get replaced (with 3rd party parts) every so often, devices are not. Devices dictate voltages and nax piwer, ...
by mkx
Wed Oct 23, 2024 5:20 pm
Forum: General
Topic: arp/proxy arp problem
Replies: 5
Views: 318

Re: arp/proxy arp problem

Unless you have good reasons not to, you can dedicate a separate IP subnet to OpenVPN ... traffic will be routed (instead of bridged), so no need for proxy arp. Some device firewalls may get triggered though ...
by mkx
Wed Oct 23, 2024 11:58 am
Forum: General
Topic: Planned MLAG Setup correct? [SOLVED]
Replies: 15
Views: 1991

Re: Planned MLAG Setup correct? [SOLVED]

Even though I am using LACP with Layer 3 + Layer 4 hashing, the distribution of traffic is still uneven. The TX traffic always favors a single bond, while RX is properly spread across two bonds. As far as Rx goes, it's up to transmitter (i.e. the pair of switches in MLAG config) to decide which par...
by mkx
Wed Oct 23, 2024 11:46 am
Forum: Beginner Basics
Topic: Port Forwarding not working properly
Replies: 3
Views: 341

Re: Port Forwarding not working properly

I'm not checking the config in details ... but it does sound like you have to configure hairpin NAT.
by mkx
Wed Oct 23, 2024 11:44 am
Forum: Beginner Basics
Topic: New subnets unable to route
Replies: 5
Views: 343

Re: New subnets unable to route

Your dhcp-server network settings need to correspond to the used subnet. Just a small (but not unimportant) detail: the only IP address in DHCP server network config, which absolutely must correspond to network address and mask, is gateway IP address (which should be within client's network address...
by mkx
Wed Oct 23, 2024 10:16 am
Forum: General
Topic: Planned MLAG Setup correct? [SOLVED]
Replies: 15
Views: 1991

Re: Planned MLAG Setup correct? [SOLVED]

I plan a similar Setup. One question about your picture: the blue and red connections are result in a loop, so one link is "alternate" right? In MLAG setup, the interconnect between collaborating switches is not active/backup kind of link, it's ICCP link (see MLAG manual ) which is always...
by mkx
Wed Oct 23, 2024 8:09 am
Forum: Beginner Basics
Topic: Can't figure out port forwarding
Replies: 12
Views: 596

Re: Can't figure out port forwarding

I have the default firewall rules: 4 ;;; defconf: drop all not coming from LAN chain=input action=drop in-interface-list=!LAN 5 ;;; defconf: accept to local loopback (for CAPsMAN) chain=input action=accept dst-address=127.0.0.1 These two are in opposite order in default firewall rules ... As they a...
by mkx
Wed Oct 23, 2024 7:55 am
Forum: General
Topic: Whats the point of this default FW rule?
Replies: 21
Views: 1383

Re: Whats the point of this default FW rule?

What mkx should have said :-) :-) And what I'm saying is that when a packet with dst-address=<some valid LAN IP> enters router via WAN interface - and this is ONLY possible if via the mac address of the router Almost wrong. Any router (in same ISP customer subnet) can be configured with /ip/route a...
by mkx
Tue Oct 22, 2024 6:53 pm
Forum: Beginner Basics
Topic: why my computer assigned IANA IP?
Replies: 39
Views: 1551

Re: why my computer assigned IANA IP?

do you have any troubleshooting idea I could start with ?

I do ... but I think we're way out of scope of this forum already. Plus it would take more effort for me to write all ideas I have than would take to actually check them on your PC.

So I won't continue in discussion in this thread.
by mkx
Tue Oct 22, 2024 6:49 pm
Forum: General
Topic: Datasheet for new improved hEX?
Replies: 66
Views: 5741

Re: Datasheet for new improved hEX?

It would be nice to know what the diameter is ...
Did you follow the link from my post?

I do agree that it would be nice to have it specified in all product brochures and product pages (in powering section).
by mkx
Tue Oct 22, 2024 6:47 pm
Forum: General
Topic: Datasheet for new improved hEX?
Replies: 66
Views: 5741

Re: Datasheet for new improved hEX?

Hold on and I'll pull the power cable from the router so I can try in vain to get exact specs from looking at the plug, despite that info possibly already available.... No, not all RBs use same power adapters. They use at least 3 different voltages (12V, 24V and 48V) and within same voltage they us...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 45