Community discussions

MikroTik App

Search found 514 matches

  • 1
  • 2
by k6ccc
Wed Jun 03, 2020 8:59 pm
Forum: SwOS
Topic: CSS326-24G-2S+ VLAN and sharing
Replies: 4
Views: 582

Re: CSS326-24G-2S+ VLAN and sharing

You largely need a router to accomplish what you are trying to do. Here's the problem. When you put both VLANs onto a single port (the NAS for example), the data stream from the switch to the NAS will have all the traffic VLAN tagged. Since your NAS presumably is not capable (or at least not configu...
by k6ccc
Sun May 31, 2020 11:28 pm
Forum: Beginner Basics
Topic: Router doesn't appear in Winbox interface despite reset procedure
Replies: 10
Views: 1305

Re: Router doesn't appear in Winbox interface despite reset procedure

As for managed list, I tried it and got nowhere - bad password. I fear I played with ROMON in the past and I have an old password so locked out? So what should one do if one cannot remember whatever master password was set in winbox?? I have never used RoMON, and I do not have WinBox save passwords...
by k6ccc
Sun May 31, 2020 10:14 pm
Forum: Beginner Basics
Topic: Router doesn't appear in Winbox interface despite reset procedure
Replies: 10
Views: 1305

Re: Router doesn't appear in Winbox interface despite reset procedure

Are you trying to "find" the router by expecting it to show up in the neighbors list or did you save the IP in the Managed list? Personally I find that the neighbors list to be only slightly less useful than worthless. For example I opened it when I read this message. There are two Mikrotik routers ...
by k6ccc
Fri May 29, 2020 12:36 am
Forum: SwOS
Topic: rb260G
Replies: 3
Views: 737

Re: rb260G

That is a very simple setup. Easiest way to explain it is to show you screen captures of one of mine. Assuming that this is a new install, I would assume it is a CSS106 running version 2.something firmware. First on the VLAN tab: http://extraphotos.info/mikrotik/CSS106-VLAN.PNG In this example, igno...
by k6ccc
Thu May 28, 2020 9:43 pm
Forum: Beginner Basics
Topic: Deny ip PUBLIC traffic
Replies: 10
Views: 1607

Re: Deny ip PUBLIC traffic

Input Chain only affects traffic that terminates in the router itself. Forward Chain affects traffic that passes through the router (what you are trying to do). Output chain affects traffic that originates in the router itself and is outbound to someplace else.. You can make all the rules in the wor...
by k6ccc
Thu May 28, 2020 9:32 pm
Forum: Beginner Basics
Topic: CRS328 makes me feel dumb
Replies: 2
Views: 454

Re: CRS328 makes me feel dumb

Can't help you on the bonding part (never done that), but VLANs are a piece of cake in either RouterOS or SwitchOS. As for routing between VLANs, RouteOS will automatically do that unless you specifically exclude that in firewall rules.
by k6ccc
Fri May 22, 2020 2:37 am
Forum: SwOS
Topic: VLANs Noob question
Replies: 1
Views: 418

Re: VLANs Noob question

That is easy, and fairly close to what I am doing with my CSS326 switch. First the VLAN tab: http://extraphotos.info/mikrotik/CSS_VLAN_for_gelcom.png I skipped a few ports so you would not need to figure out other stuff. Port 1 is my cable internet and gets assigned as VLAN 100. Port 9 is my DSL int...
by k6ccc
Fri May 22, 2020 2:15 am
Forum: SwOS
Topic: CRS-317 SwOS Web Config inaccessible after Upgrade to 2.11
Replies: 3
Views: 548

Re: CRS-317 SwOS Web Config inaccessible after Upgrade to 2.11

When you are able to get into it, on the system tab, check the status of the first two lines: Address Acquisition, and Static IP Address. As I recall, by default it will come up looking for a DHCP address. If you can't get into it, check your router to see if it assigned an address to the switch. Th...
by k6ccc
Mon May 11, 2020 5:28 am
Forum: Beginner Basics
Topic: How connect different router different subnet
Replies: 5
Views: 877

Re: How connect different router different subnet

Start by spending a while reading the Wiki: https://wiki.mikrotik.com/wiki/Main_Page If we just tell you the answer, you don't learn. If you read the Wiki, most of your questions will get answered, and you learn what the answer means. When you can't figure out some specific detail, then ask. You may...
by k6ccc
Mon May 11, 2020 12:21 am
Forum: Beginner Basics
Topic: Portforwarding refuses to work for me.
Replies: 5
Views: 838

Re: Portforwarding refuses to work for me.

Thanks, might be helpful. I tried to change router to my old TP-link one. I was still unable to portforward although it's "easier" UI, its probably about my new ISP blocking something and I've reached out to them. Thanks a lot for your reply though, I'll make sure to post an update if it works once...
by k6ccc
Sun May 10, 2020 10:12 pm
Forum: Beginner Basics
Topic: My first firewall config - requesting feedback! [SOLVED]
Replies: 9
Views: 1291

Re: My first firewall config - requesting feedback! [SOLVED]

One other addition. Keep all the rules in a particular chain together rather than mixing input, forward, output, whatever else you might add later. It does not make any difference to the router, but it makes it FAR easier for us human beings to read.
by k6ccc
Sun May 10, 2020 9:47 pm
Forum: Beginner Basics
Topic: Portforwarding refuses to work for me.
Replies: 5
Views: 838

Re: Portforwarding refuses to work for me.

NAT is actually very easy. Here is the command for NAT for my web server: add action=dst-nat chain=dstnat comment="Web Server on Jupiter." \ dst-address-type=local dst-port=80 protocol=tcp to-addresses=\ 192.168.101.11 to-ports=80 Then in Firewall rules, an accept for either that specific forward, o...
by k6ccc
Sun May 10, 2020 9:40 pm
Forum: Beginner Basics
Topic: Admin access via the internet
Replies: 14
Views: 1761

Re: Admin access via the internet

"VPN Access" checkbox the QuickSet window...
Step one - stop using QuickSet. QuickSet sort of can be used one time for an initial setup (ONLY IF YOU REALLY NEED TO), but as soon as you make ANY other change to the router config, then NEVER AGAIN touch QuickSet.
by k6ccc
Sun May 10, 2020 7:17 am
Forum: Beginner Basics
Topic: How connect different router different subnet
Replies: 5
Views: 877

Re: How connect different router different subnet

I agree with anav. Let the hex do all the routing and DHCP, and use the hAPs strictly as access points. Use different VLANs to keep things apart as needed.
by k6ccc
Thu May 07, 2020 12:02 am
Forum: Beginner Basics
Topic: Help me setup private network with a wireless hotspot
Replies: 19
Views: 2474

Re: Help me setup private network with a wireless hotspot

You really should not have two DHCP servers that are supplying IP addresses to the same LAN. Two DHCP servers feeding different LANs (or VLANs) is expected, but not on the same LAN. If for some reason you REALLY think that you need two DHCP servers on the same LAN, make sure that their address pools...
by k6ccc
Wed May 06, 2020 11:06 pm
Forum: Beginner Basics
Topic: Help me setup private network with a wireless hotspot
Replies: 19
Views: 2474

Re: Help me setup private network with a wireless hotspot

(1) what firewall rules that I miss? All of them. You have absolutely zero operational firewall filter rules. That means (among other bad stuff), your router is fully accessible from the internet. At the absolute least, restrict access to the router itself from WAN port. Start by reading this secti...
by k6ccc
Thu Apr 23, 2020 2:28 am
Forum: Beginner Basics
Topic: RB260GSP configuration via winbox
Replies: 2
Views: 870

Re: RB260GSP configuration via winbox

Anav is right. Both your switches are SwitchOS only and therefore they are configured exclusively via the web GUI. BTW, I have several CSS326 and a CSS106 (and another of it's predecessor the RB260GS) and they work quite well as a managed VLAN switch.
by k6ccc
Thu Apr 23, 2020 2:20 am
Forum: Beginner Basics
Topic: Setting up /29 over /30 [SOLVED]
Replies: 7
Views: 1668

Re: Setting up /29 over /30 [SOLVED]

I have the /30 setup correctly. Traffic moves through the router. On the other hand, I am not planning on using public IP addresses for everything. I want to have two separate lans eventually, each using a separate public IP address. With a /30 CIDR, you only have two available addresses - one is f...
by k6ccc
Thu Apr 16, 2020 2:39 am
Forum: SwOS
Topic: CSS326 VLAN forwarding not working
Replies: 1
Views: 1959

Re: CSS326 VLAN forwarding not working

Although not entirely what you describe, but most of my switches have one trunk port to somewhere else with all VLANs appearing tagged, and some number of untagged ports (in quite a few cases only one other port) on a particular VLAN. It works fine for me, but I have MAC learning turned on. In a VLA...
by k6ccc
Sat Apr 11, 2020 1:51 am
Forum: General
Topic: Please add basic portScan tool ( port scanner scan )
Replies: 47
Views: 18158

Re: Please add basic portScan tool ( port scanner scan )

There already is "/tool ip-scan" which scans using ping, arp, snmp and netbios and does IP lookup in DNS. Maybe you can specify what other features you would want it to have? (like other services it should scan for, or to have a list of ports) There have been a bunch of various posts, but the origi...
by k6ccc
Mon Apr 06, 2020 11:17 pm
Forum: SwOS
Topic: CSS326-24G-2S+RM hangs until power cycle
Replies: 89
Views: 19919

Re: CSS326-24G-2S+RM hangs until power cycle

Well, this one finally caught me last night. Below is a simplified drawing of the routers and switches here at home. I did not include any of the end user devices. I enabled the IPv6 package on router #1 and commanded the reboot. As far as I can tell, shortly after the reboot, I could not get into a...
by k6ccc
Thu Mar 26, 2020 11:42 pm
Forum: Beginner Basics
Topic: question about multiple routers
Replies: 1
Views: 1038

Re: question about multiple routers

Short answer is yes.
by k6ccc
Wed Mar 18, 2020 12:36 am
Forum: Beginner Basics
Topic: I need to enter AT commands via serial port and ROS
Replies: 4
Views: 1437

Re: I need to enter AT commands via serial port and ROS

You need to give us a little more information. First of all, which router? Yes, the hardware makes a difference as different hardware has different capabilities. What version of ROS? Again, different versions have different capabilities. What are trying to accomplish? The only thing I can think of i...
by k6ccc
Thu Mar 05, 2020 5:28 pm
Forum: General
Topic: Simple Port Forwarding
Replies: 5
Views: 1793

Re: Simple Port Forwarding

WinBox is fine. Forward chain is a normal chain in the firewall rules - not on the NAT tab (which will normally be srcnat and dstnat).
by k6ccc
Thu Mar 05, 2020 7:56 am
Forum: General
Topic: Simple Port Forwarding
Replies: 5
Views: 1793

Re: Simple Port Forwarding

Lookup hairpin NAT.
by k6ccc
Mon Mar 02, 2020 5:55 am
Forum: SwOS
Topic: VLAN problem
Replies: 2
Views: 2764

Re: VLAN problem

You gave us so little information that it is hard to help. For example, you showed that some pings worked - but no information on what was being pinged or from where. If you are allowing only untagged traffic on the test port, why are you allowing more than one LAN on that port?
by k6ccc
Mon Mar 02, 2020 5:33 am
Forum: General
Topic: Antenna Patterns for RBMetalG-52SHPacn
Replies: 9
Views: 2282

Re: Antenna Patterns for RBMetalG-52SHPacn

Draw a circle on a piece of paper and you just got a pattern for the omnidirectional antenna.
by k6ccc
Sat Feb 29, 2020 5:46 am
Forum: Beginner Basics
Topic: Firewall Rules for UDP Across LAN
Replies: 18
Views: 3317

Re: Firewall Rules for UDP Across LAN

You are making your life a bit more complex than it needs to be. Your rules 16 - 20 are completely un-needed because rule 21 is going to drop all of that anyway. As a general rule of thumb, most of us specifically allow what they want to allow and then drop everything else at the end of the chain. H...
by k6ccc
Sat Feb 29, 2020 2:33 am
Forum: Beginner Basics
Topic: Firewall Rules for UDP Across LAN
Replies: 18
Views: 3317

Re: Firewall Rules for UDP Across LAN

Since you have changed things from your original screen capture, please post you current firewall rules.
by k6ccc
Sat Feb 29, 2020 2:28 am
Forum: Beginner Basics
Topic: SOLVED: Help with Wyze Cam. NanoHD and Hex S
Replies: 12
Views: 2777

Re: SOLVED: Help with Wyze Cam. NanoHD and Hex S

Just an FYI, I have 19 Wyze cameras behind one of my Mikrotik Hex routers, and they work just fine. It really does not take anything special to get the Wyze cameras working. What works for your laptop or phone would work fine for the cameras. In my case, I have the cameras on my IoT network - which ...
by k6ccc
Sat Feb 15, 2020 2:14 am
Forum: Beginner Basics
Topic: Different VLANS with different PUB IPs [SOLVED]
Replies: 4
Views: 2003

Re: Different VLANS with different PUB IPs [SOLVED]

Until my ISP changed things around on me, I was doing exactly what you want to do. On my DSL, I had eight static IP addresses. All were in the same subnet. Here are a couple code segments that should help. First create the addresses on both the DSL and each LAN (two of which had a physical port and ...
by k6ccc
Thu Jan 16, 2020 8:20 pm
Forum: SwOS
Topic: RB260GSP - Activate DHCP server
Replies: 4
Views: 3878

Re: RB260GSP - Activate DHCP server

@dke, That thread is from four years ago and they are talking about the old RB260 that maxes out with 1.x firmware - NOT the current RB260 series (also known as the CSS106-5G-1S) which uses firmware versions 2.x. Yes, the current product with current firmware does as you describe (I have one), but w...
by k6ccc
Thu Jan 09, 2020 5:44 pm
Forum: Beginner Basics
Topic: Site to site RBLHGG-60AD to RBLHGG-60AD
Replies: 1
Views: 768

Re: Site to site RBLHGG-60AD to RBLHGG-60AD

Can you ping 192.168.88.254 from site 1? I'm not at all familiar with the pfsense routers, so I don't know if they have the ability to be configured to not respond to pings.
by k6ccc
Wed Nov 27, 2019 9:26 pm
Forum: SwOS
Topic: Terminal / ssh / telnet support for SwOS ?
Replies: 13
Views: 4509

Re: Terminal / ssh / telnet support for SwOS ?

As for getting a new IP from the DHCP server, assuming you are using DHCP reservations in the DHCP server, simply give the MAC for the switch a new IP. Next time that the switch requests a new IP, it will get the new address. Nothing to do in SwitchOS. Obviously this is not instantaneous, but the sw...
by k6ccc
Fri Oct 25, 2019 6:24 am
Forum: SwOS
Topic: RB260GS as unmanaged? (No IP address)
Replies: 4
Views: 2339

Re: RB260GS as unmanaged? (No IP address)

Yes, out of the box, all ports will talk to each other. To keep from using an IP address, you could give it a static IP outside your IP range. But are you REALLY that short of IP addresses on your LAN?
by k6ccc
Tue Oct 08, 2019 7:36 am
Forum: Beginner Basics
Topic: Forwarding port 443 causes internet problems to anyone else?
Replies: 4
Views: 915

Re: Forwarding port 443 causes internet problems to anyone else?

My first guess is that your forwarding rule is not specific enough. For example, if you forward all port 443 traffic to something, then ALL traffic including your outbound https traffic will go there. On the other hand, it you only forward port 443 traffic that is inbound on your WAN connection, the...
by k6ccc
Thu Oct 03, 2019 2:21 am
Forum: SwOS
Topic: Switch identity character length and possible? bug
Replies: 5
Views: 2456

Re: Switch identity character length and possible? bug

That's RouterOS, not SwitchOS.
by k6ccc
Sat Sep 21, 2019 1:50 am
Forum: SwOS
Topic: SWOS VLAN and Trunk port
Replies: 2
Views: 2350

Re: SWOS VLAN and Trunk port

I am running very similar at home. These screen captures were done on a CSS326 for a different purpose and are a little out of date, but might give you some ideas. Links page: http://extraphotos.info/mikrotik/CSS326_Links.png VLAN tab: http://extraphotos.info/mikrotik/CSS326_VLAN.png VLANs tab: http...
by k6ccc
Sat Sep 21, 2019 1:12 am
Forum: Beginner Basics
Topic: Isolated Network
Replies: 10
Views: 1647

Re: Isolated Network

You need to give us a better idea of what you are trying to accomplish. Not enough information given.
by k6ccc
Thu Sep 19, 2019 6:30 pm
Forum: SwOS
Topic: CRS328-24P-4S+RM advertised SWOS 2.10 upgrade fails and installs 2.7p on 2.7 WORKAROUND
Replies: 6
Views: 3134

Re: CRS328-24P-4S+RM advertised SWOS 2.10 upgrade fails and installs 2.7p on 2.7 WORKAROUND

For what it's worth, I just updated a CRS326-24G-2S+, two CSS326-24G-2S+, and a CSS106-5G-1S from 2.9 to 2.10 without incident. Watching pings to the CRS, I dropped three pings during the restart, and on both CSS326 switches, I dropped one ping during the restart.
by k6ccc
Mon Sep 16, 2019 5:34 pm
Forum: Beginner Basics
Topic: Link Router and Switch and administrate together with WinBox
Replies: 11
Views: 1496

Re: Link Router and Switch and administrate together with WinBox

What you are asking about is very similar to what I am doing. The only difference is that I am using my routers (a RB750r2 and a RB750Gr3) exclusively as routers - no switching at all. Each LAN or VLAN has only one port on the router (may be a dedicated LAN port, or may be a VLAN trunk port). All th...
by k6ccc
Sun Sep 15, 2019 5:48 am
Forum: Beginner Basics
Topic: Using RouterOS as a switch
Replies: 5
Views: 1292

Re: Using RouterOS as a switch

Amm0 is correct. Essentially what I currently have is what dadoremix suggested. While that does allow VLAN 2 to communicate between ports 2 - 5, but that does not allow for the additional parts of the plan. I will be working with Amm0's suggestions shortly.

Thanks
by k6ccc
Sat Sep 14, 2019 11:47 pm
Forum: Beginner Basics
Topic: Using RouterOS as a switch
Replies: 5
Views: 1292

Re: Using RouterOS as a switch

Thanks for the reply. I had assumed that I needed to build a bridge, and played with that last night for a couple hours without any success. I can see the traffic coming in from the three AREDN nodes with Torch, but nothing going out. I'm sure it's easy for most people that have used a bridge in ROS...
by k6ccc
Fri Sep 13, 2019 9:02 pm
Forum: Beginner Basics
Topic: Using RouterOS as a switch
Replies: 5
Views: 1292

Using RouterOS as a switch

This is likely an easy one, but I have EXCLUSIVELY used Mikrotik routers as routers and never as a switch. Each LAN or VLAN on the routers connects directly to a CSS326 switch. I have run into a situation where I have run out of ports on one of my CSS326 switches and have an immediate need for a cou...
by k6ccc
Wed Sep 11, 2019 6:02 pm
Forum: Beginner Basics
Topic: How to enable Webfig access from internet?
Replies: 7
Views: 1406

Re: How to enable Webfig access from internet?

Also, HIGHLY recommend putting some additional security on it. There are several things that can be done if you really insist on having a WebFig port directly accessed from the internet. For example, if able, restrict the source IPs that can access it to only the IPs that you want to have access. Fo...
by k6ccc
Fri Aug 30, 2019 6:09 am
Forum: General
Topic: Anyone can check the login webpage hotspot from attack codes!
Replies: 10
Views: 1548

Re: Anyone can check the login webpage hotspot from attack codes!

I don't think this forum has a lot of professional web developers But it is impossible for users or designers Hotspot service does not know in the topics of page security! This is a forum for routers. Why are you even asking for html configuration help here? Take this to a forum for web designers. ...
by k6ccc
Thu Aug 29, 2019 2:37 am
Forum: Announcements
Topic: v6.45.5 [stable] is released!
Replies: 54
Views: 23393

Re: v6.45.5 [stable] is released!

I note that both alibloke and the chart that elbob2002 posted show the temperature stabilized at 58 degrees C. Makes me think that is what it is designed to do. I don't know what the specs for the CPU chips involved are, but as a comparison, the Raspberry Pi does not start throttling to control heat...
by k6ccc
Sun Aug 25, 2019 10:27 pm
Forum: Beginner Basics
Topic: Alternate DNS for one domain
Replies: 4
Views: 853

Re: Alternate DNS for one domain

RouterOS does not support this method of working. It has been requested many times but it has not been implemented. (what you need is the capability to set a static DNS record for local.mesh with type NS and pointing to the nameserver for that domain) That is exactly correct. As RouterOS also does ...
by k6ccc
Sun Aug 25, 2019 9:27 am
Forum: Beginner Basics
Topic: Alternate DNS for one domain
Replies: 4
Views: 853

Alternate DNS for one domain

Here is my situation. I have an RB-750Gr3 that has a WAN connection from my cable provider which provides DHCP and DNS services to the router. Ports 2, 3, & 5 are various LANs, and port 4 is a trunked port with several more VLANS. The trunked port connects to a managed switch where VLAN 5 (among oth...
by k6ccc
Fri Aug 23, 2019 7:55 am
Forum: General
Topic: New RB450G☓4 Breaks Google and its Services (Solved)
Replies: 13
Views: 1694

Re: New RB450G☓4 Breaks Google and its Services

Posting part of settings is not all that helpful.
/export config hide-sensitive file=yourconfigaug22
What am I doing wrong...see image below!

Screen Shot 2019-08-22 at 10.02.49 PM.png
Delete the word "config"
In other words: /export hide-sensitive file=your-config-22-Aug
by k6ccc
Sat Aug 10, 2019 2:11 am
Forum: SwOS
Topic: CRS326: RouterOS or SwOS?
Replies: 2
Views: 3443

Re: CRS326: RouterOS or SwOS?

A lot of that is personal preferences. I have a CRS326 that is being used exclusively as a managed switch. Other than about a half dozen VLANs, there is nothing fancy. I am running it under SwitchOS and always have. I also have two CSS326 switches - obviously running SwitchOS, plus two a CSS106-5G-1...
by k6ccc
Fri Aug 09, 2019 6:15 pm
Forum: Beginner Basics
Topic: Remote WoL
Replies: 8
Views: 1746

Re: Remote WoL

If you can access the router, you can either manually send the WOL command or type up a script and execute the script. By creating a scrpt in advance, you don't have to know the MAC of the target device. add dont-require-permissions=no name="Boot Old Family room PC on .101" owner=\ SuperMgr policy=t...
by k6ccc
Fri Aug 09, 2019 6:05 pm
Forum: Beginner Basics
Topic: Access wan from lan
Replies: 1
Views: 540

Re: Access wan from lan

Search for "hairpin nat".
by k6ccc
Thu Jul 25, 2019 6:16 pm
Forum: SwOS
Topic: Forwarding Problem CRS317-1G-16S+RM
Replies: 1
Views: 1742

Re: Forwarding Problem CRS317-1G-16S+RM

Stefan, what software version?
by k6ccc
Thu Jul 25, 2019 6:13 pm
Forum: General
Topic: Firewall filter when port forwarded
Replies: 4
Views: 1479

Re: Firewall filter when port forwarded

On this - add chain=forward action=accept in-interface=WAN \ connection-state=new nat-connection-state=dst nat Does/should the connection state need to be new? Or does it matter? It actually does not matter. Because there is a fastrack accept for established and related packets, the only time that ...
by k6ccc
Tue Jun 25, 2019 12:28 am
Forum: General
Topic: PoE 802.3 on two pair cable with CRS328-24P-4S+RM
Replies: 1
Views: 378

Re: PoE 802.3 on two pair cable with CRS328-24P-4S+RM

From the product page for the CRS328-24P-4S+RM:
PoE-Out is passed over mode B pins (4,5+)(7,8-).
That won't work on your 2 pair cable.
by k6ccc
Mon Jun 24, 2019 8:34 pm
Forum: General
Topic: Block Teamviewer
Replies: 24
Views: 19431

Re: Block Teamviewer

The very first rule in the Forward chain. Made it about as simple as I could: add action=passthrough chain=forward comment=\ "Counter for outbound to 188.172.217.0/24 - test for Teamviewer" \ connection-state="" dst-address=188.172.217.0/24 No connections listed to 188.172.217.xxx either.
by k6ccc
Mon Jun 24, 2019 6:02 pm
Forum: General
Topic: Block Teamviewer
Replies: 24
Views: 19431

Re: Block Teamviewer

So I did some digging and saw that TeamViewer Connect to a domain, 188.172.217.0/24 To test that, I created a passthrough firewall rule as a counter as the first rule in my forward chain. Any traffic to 188.172.217.0/24 should show up in the counter. There are two computers inside my firewall that ...
by k6ccc
Fri Jun 21, 2019 8:05 pm
Forum: General
Topic: Block Teamviewer
Replies: 24
Views: 19431

Re: Block Teamviewer

I would love to be able to block TeamViewer - but my situation is a little different. In my case, I am the TeamViewer user, but I want to be able to block TeamViewer unless I specifically allow it at the time - for example with a port knock to the router. For example, the computer at home can't norm...
by k6ccc
Thu Jun 20, 2019 1:48 am
Forum: SwOS
Topic: RB260 speed falls do 100M
Replies: 7
Views: 2297

Re: RB260 speed falls do 100M

I'm sorry, but I thought it was simple to understand that the two RB260 Ether1 are connected together with a 50cm patch cable, so where is the cable problem? It was not simple to understand because you did not tell that in your original post. For all we know, you were trying to run gigabit over a k...
by k6ccc
Fri Jun 14, 2019 5:56 pm
Forum: Beginner Basics
Topic: CCR1016-12S-1S+ CPU 100% Every Day
Replies: 2
Views: 570

Re: CCR1016-12S-1S+ CPU 100% Every Day

You have given us almost no information to work with. What is this device doing? What's connected to it? How is it being used? Post your configuration.
by k6ccc
Thu Jun 13, 2019 7:09 pm
Forum: SwOS
Topic: CSS106 (RB260) VLANs between multiples swicthes and Hybrid port [SOLVED]
Replies: 3
Views: 3203

Re: CSS106 (RB260) VLANs between multiples swicthes and Hybrid port [SOLVED]

I just wish that Mikrotik would standardize the interface between the different switches. I have one RB260, one CSS106, one CRS326 (running SwitchOS), and two CSS326s and it's annoying that the UI is so different between them.
by k6ccc
Sat Jun 08, 2019 7:19 am
Forum: Beginner Basics
Topic: DHCP reservation in or out of Pool/Scope?
Replies: 7
Views: 933

Re: DHCP reservation in or out of Pool/Scope?

I'm the same as all the rest here. All known DHCP clients are given a DHCP reservation outside of the IP Pool. Most of the pools are only 10 IPs (and in reality, I could normally get away with one or two).
by k6ccc
Fri Jun 07, 2019 4:53 pm
Forum: General
Topic: Time Based firewaal rules
Replies: 12
Views: 1208

Re: Time Based firewaal rules

I figured it out!! You have to specify the time and day or days that you want the rule to be applied and then you have to press reset all counters to reset everything and allow the new rule to be applied. I checked it 3-4 times and it worked fine. Thank you all!!!! I definitely did not have to rese...
by k6ccc
Fri Jun 07, 2019 12:55 am
Forum: SwOS
Topic: Do CRS305&309 support other brands' RJ45 SFP module?
Replies: 4
Views: 3429

Re: Do CRS305&309 support other brands' RJ45 SFP module?

Simple solution. I buy the Mikrotik SFPs that are specified to work with the device.
by k6ccc
Fri Jun 07, 2019 12:18 am
Forum: General
Topic: Time Based firewaal rules
Replies: 12
Views: 1208

Re: Time Based firewaal rules

I have never had any time based firewall rules, but because of this thread, I created one for a test. The rule was a simple rule to drop all ICMP packets from the internet at the beginning of my Input chain with no time restriction. I am not at the location of this router, so my access is only via t...
by k6ccc
Thu Jun 06, 2019 7:30 am
Forum: SwOS
Topic: CRS326 Port security
Replies: 3
Views: 1949

Re: CRS326 Port security

Never used a bridge, so can't help you there. However your firewall rules look OK - I think.
by k6ccc
Wed Jun 05, 2019 8:05 pm
Forum: SwOS
Topic: CRS326 Port security
Replies: 3
Views: 1949

Re: CRS326 Port security

Off hand, I don't see a way to specify a MAC on a specific port, but you can enable port lock which locks the port to the first MAC that is connected. See the Forwarding tab.
by k6ccc
Mon Jun 03, 2019 5:08 am
Forum: SwOS
Topic: I am confused with Port Isolation on CSS326-24G Switch [SOLVED]
Replies: 5
Views: 2864

Re: I am confused with Port Isolation on CSS326-24G Switch [SOLVED]

The check marks are the ports that the CAN be communicated with. For example, in your screen capture, port 1 can communicate with all other ports.
by k6ccc
Mon May 27, 2019 8:52 pm
Forum: SwOS
Topic: Difficulty with configuring CSS106-1G-4P-1S
Replies: 2
Views: 1948

Re: Difficulty with configuring CSS106-1G-4P-1S

I still could not read your screen captures, but here are a couple of mine. Ports one and two are doing exactly what you want to do. Each of those is a Multi-SSID WiFi access point. Each is getting several VLANs that will each become a different SSID and also an untagged LAN that is used for cloud m...
by k6ccc
Mon May 27, 2019 7:29 pm
Forum: SwOS
Topic: Difficulty with configuring CSS106-1G-4P-1S
Replies: 2
Views: 1948

Re: Difficulty with configuring CSS106-1G-4P-1S

I can’t read your images on my $&@#% iPhone, but I am doing exactly what you want to do on my CSS106. When I get to a computer, I’ll take a look.



Sent from a $&@#% iPhone using Tapatalk
by k6ccc
Sun May 26, 2019 4:57 am
Forum: Beginner Basics
Topic: RB750: firmware upgrade or not?
Replies: 5
Views: 1089

Re: RB750: firmware upgrade or not?

I always upgrade mine.
by k6ccc
Wed May 22, 2019 6:00 pm
Forum: General
Topic: CRS328-24P-4S+ Speed issue
Replies: 2
Views: 395

Re: CRS328-24P-4S+ Speed issue

It might be interesting to connect the two computers in question directly to each other. I would speculate that what you are seeing is more related to the performance of the computers involved and not the switches. Part of that statement is the difference in performance between upload and download. ...
by k6ccc
Mon May 20, 2019 12:30 am
Forum: General
Topic: USB port + HUB summary amperage
Replies: 3
Views: 512

Re: USB port + HUB summary amperage

Powered USB hubs usually don't draw power from upstream USB port ...
Correct. That's why I recommend them for fixed applications. Has solved many problems over the years.
by k6ccc
Sun May 19, 2019 10:15 pm
Forum: General
Topic: USB port + HUB summary amperage
Replies: 3
Views: 512

Re: USB port + HUB summary amperage

I don't have an answer to your specific question, but my general recommendation is any time you are using a USB hub in a fixed situation, use a powered hub. That solves the current limit issue. Since you are proposing to use a USB hub connected to a router, I assume it will be in a fixed installatio...
by k6ccc
Sun May 19, 2019 9:51 pm
Forum: SwOS
Topic: SWOS or ROUTEROS: Confused
Replies: 3
Views: 4691

Re: SWOS or ROUTEROS: Confused

This is likely more opinion rather than hard facts. There are some on the forum that hate SwitchOS and have nothing but problems, and there are some that have no issues with SwitchOS at all. Personally I am in the second camp. I have a CRS326-24G-2S, two CSS326-24G-2S, a CSS106-5G-1S, and a RB260GS ...
by k6ccc
Wed May 15, 2019 5:30 pm
Forum: Beginner Basics
Topic: Open all ports on all devises [SOLVED]
Replies: 6
Views: 1018

Re: Open all ports on all devises [SOLVED]

I clearly have no understanding of what he is trying to do. However I have never had any interest in on line gaming, so no idea how those kind of things work. I've never heard of a client / server type system where the server initiates the connection (which is why normal consumer routers work for mo...
by k6ccc
Wed May 15, 2019 5:21 am
Forum: Beginner Basics
Topic: Open all ports on all devises [SOLVED]
Replies: 6
Views: 1018

Re: Open all ports on all devises [SOLVED]

It does not work that way. A NAT forwards to a target IP. However in most situations, if the game is talking to a server somewhere else, the client initiates the connection and the router will forward responses to the IP that originated the request. No special setup is normally required. If you are ...
by k6ccc
Mon May 13, 2019 4:02 pm
Forum: Beginner Basics
Topic: Open all ports on all devises [SOLVED]
Replies: 6
Views: 1018

Re: Open all ports on all devises [SOLVED]

You have given us so little information to go on. For starters, either give us more details on how your three routers are connected to each other, the internet, and your devices - or better yet, a drawing. Second, export your config on all three routers and post here so we can see what you are doing...
by k6ccc
Thu May 09, 2019 12:01 am
Forum: Beginner Basics
Topic: DhCP server for each port
Replies: 11
Views: 1024

Re: DhCP server for each port

I see mkx beat me to the L2 vs L3 parts, so I'm not going to repeat that. You do not need to use bridges to create a DHCP server. However as noted above, IF an interface is a member of a bridge, then the DHCP server must be assigned to the Bridge - not the member interfaces. At least that's the way ...
by k6ccc
Wed May 08, 2019 5:25 pm
Forum: Beginner Basics
Topic: DhCP server for each port
Replies: 11
Views: 1024

Re: DhCP server for each port

Let's see if I have this right. Every single port will be a separate LAN with it's own DHCP server. So the router is being used exclusively as a router and not as a switch. If this is the case, why are you creating bridges? This is the way I use my routers. I have managed switches connected to the r...
by k6ccc
Fri May 03, 2019 8:35 pm
Forum: Beginner Basics
Topic: Share WiFi and LAN DHCP
Replies: 2
Views: 416

Re: Share WiFi and LAN DHCP

I don't know anything about the TP Link equipment, but it sounds like you want the TP Link to operate only as a WiFi access point and NOT have any router functions. You likely can make this work by turning off the DHCP server functionality in the TP Link and then connecting one of the LAN ports (NOT...
by k6ccc
Thu May 02, 2019 3:36 pm
Forum: SwOS
Topic: CSS326-24G slow inter-VLAN transfers
Replies: 3
Views: 2083

Re: CSS326-24G slow inter-VLAN transfers

You asked this question in the SwitchOS section of the forum and your subject specifies the CSS326 switch. However, since you are seeing an inter-VLAN issue, the problem almost certainly exists in the router and not the switch - since switches don’t route between VLANs. You did not give us much deta...
by k6ccc
Wed May 01, 2019 5:16 pm
Forum: SwOS
Topic: Mikrotik CSS326-24G VLANS [SOLVED]
Replies: 8
Views: 3051

Re: Mikrotik CSS326-24G VLANS [SOLVED]

As for your DHCP servers, from your drawing, they are some device that is untagged. Simply put them on a switch port that is untagged on the correct VLAN. Same concept as my Cable Modem on port 1. In my case that is untagged on VLAN 100, but the concept is the same.
by k6ccc
Sat Apr 27, 2019 3:40 am
Forum: SwOS
Topic: Problems with S+RJ10
Replies: 9
Views: 3339

Re: Problems with S+RJ10

My first question is if the issue it with the SFP or the Ethernet per in the computer - it could be either one. Can you plug the Cat-6 into another port on the switch (such as one of the gig-E ports on the switch). Let the computer go to sleep and see if the problem happens in that configuration. Ot...
by k6ccc
Thu Apr 25, 2019 12:12 am
Forum: SwOS
Topic: Mikrotik CSS326-24G VLANS [SOLVED]
Replies: 8
Views: 3051

Re: Mikrotik CSS326-24G VLANS [SOLVED]

Here are some screen captures from one of CSS326 switches located in my family room. Most of the ports don't really matter, but I will point out a few. Along with a bunch of end devices in the house, both internet modems connect to this switch (port 1 for the cable and port 9 for the DSL). Port 3 is...
by k6ccc
Wed Apr 24, 2019 5:33 pm
Forum: SwOS
Topic: Mikrotik CSS326-24G VLANS [SOLVED]
Replies: 8
Views: 3051

Re: Mikrotik CSS326-24G VLANS [SOLVED]

One other thing you could easily test. Configure a user PC port to VLAN 20 instead of VLAN 10 and confirm that the PC gets a DHCP address from DHCP server 2. That will confirm that your DHCP and switch to switch links are OK. Part two - Are you sure that your WiFi APs are configured properly for the...
by k6ccc
Wed Apr 24, 2019 5:28 pm
Forum: SwOS
Topic: Mikrotik CSS326-24G VLANS [SOLVED]
Replies: 8
Views: 3051

Re: Mikrotik CSS326-24G VLANS [SOLVED]

Your configuration is really pretty simple. The trunks between the three switches needs to have VLANs 10 & 20. Assuming that the WiFi APs know that SSID 1 connects to VLAN 10 and SSID 2 connects to VLAN 20, then the switch ports connected to the three Unifi APs will be just like the switch to switch...
by k6ccc
Tue Apr 23, 2019 7:10 am
Forum: General
Topic: Port Knocking, avoid scan-caused false positives?
Replies: 17
Views: 1767

Re: Port Knocking, avoid scan-caused false positives?

Why not just a set of firewall rules to catch port scanners. Those are well documented and work well. If the port scanner triggers, then the port knock never sees the triggers.
by k6ccc
Sun Apr 21, 2019 3:30 am
Forum: Beginner Basics
Topic: RouterOS - NAT problem (dst-nat)
Replies: 27
Views: 4336

Re: RouterOS - NAT problem (dst-nat)

First guess is that you did not open a hole in the firewall for your NAT. Unlike many consumer routers, RouterOS does not do that automatically.
by k6ccc
Fri Apr 19, 2019 7:50 pm
Forum: Beginner Basics
Topic: Multiple VLANs with one Router as Default Gateway in each VLAN
Replies: 7
Views: 1984

Re: Multiple VLANs with one Router as Default Gateway in each VLAN

What you are doing is very similar to what I am doing and it's not at all complicated. I am curious why you want two VLANs if part of your statement is that devices on one VLAN can communicate with devices on the other VLAN. If everything on both VLANs can communicate with each other, why separate t...
by k6ccc
Fri Apr 19, 2019 6:44 pm
Forum: Beginner Basics
Topic: wyze cam port forwarding
Replies: 8
Views: 1984

Re: wyze cam port forwarding

I can absolutely assure you that the Wyze cameras do NOT require anything "special" to be opened on a reasonably normal router configuration. As long as a LAN device can get to the internet and responses get back to it, it will connect just fine. I have 13 Wyze cameras (2 Pans and 11 V2). Other than...
by k6ccc
Tue Apr 16, 2019 4:19 pm
Forum: Beginner Basics
Topic: One website blocked
Replies: 4
Views: 593

Re: One website blocked

First of all, you are right - they don't respond to a ping. However that proves absolutely nothing since some network admins drop pings as some people consider it a security hole. If it really is on your end, please post your config, so we can see what you have. In order to export your config, follo...
by k6ccc
Mon Apr 15, 2019 5:25 pm
Forum: Beginner Basics
Topic: VLAN with multiple switches
Replies: 6
Views: 1121

Re: VLAN with multiple switches

I'm going to let someone else answer the setup in RouterOS as I have NEVER used a bridge in ROS. I know there are some particulars about setting up VLANs in a bridge, but I don't know details.
by k6ccc
Thu Apr 11, 2019 9:32 pm
Forum: Beginner Basics
Topic: VLAN with multiple switches
Replies: 6
Views: 1121

Re: VLAN with multiple switches

SwitchOS is strictly a switching OS whereas RouterOS is router OS that can play switch (but is optimized as a router). SwitchOS is far more limited, but if you only need switching, it works. There are a couple documented issues with the current version of SwitchOS - check out the SwitchOS section of...
by k6ccc
Thu Apr 11, 2019 12:50 am
Forum: Beginner Basics
Topic: VLAN with multiple switches
Replies: 6
Views: 1121

Re: VLAN with multiple switches

I think sebus got your config incorrect. Please confirm that the CCR1009 has one link to the CRS125 and one link to the CRS326 (not that the two switches are daisy chained). Second, are you running the CRS125 and CRS326 in RouterOS or SwitchOS? What you are doing is easy, but we better need to under...
by k6ccc
Sat Apr 06, 2019 5:09 am
Forum: Beginner Basics
Topic: How to go back to dynamic IP in DHCP server [SOLVED]
Replies: 11
Views: 2442

Re: How to go back to dynamic IP in DHCP server [SOLVED]

Just delete the lease and next time the device requests an address, it will get one from the regular pool.
by k6ccc
Thu Apr 04, 2019 6:33 pm
Forum: General
Topic: WAN Notifications
Replies: 6
Views: 739

Re: WAN Notifications

I was not suggesting that you monitor it for them, but rather that they set up a free account with UpTimeRobot.com and UTR will notify them when something fails.
by k6ccc
Wed Apr 03, 2019 5:46 pm
Forum: General
Topic: How to configure 4 Up-Links on same WAN with 4 vLANs
Replies: 12
Views: 1029

Re: How to configure 4 Up-Links on same WAN with 4 vLANs

Yes. add action=src-nat chain=srcnat comment="Outgoing NAT from .201 LAN" \ disabled=no out-interface=E1-p10_DSL_Internet src-address=\ 192.168.201.0/24 to-addresses=208.127.104.77 add action=src-nat chain=srcnat comment="Outgoing NAT from .202 LAN" \ disabled=no out-interface=E1-p10_DSL_Internet sr...
by k6ccc
Wed Apr 03, 2019 1:04 am
Forum: General
Topic: How to configure 4 Up-Links on same WAN with 4 vLANs
Replies: 12
Views: 1029

Re: How to configure 4 Up-Links on same WAN with 4 vLANs

@ivanobuffa
They were all part of a /24 network from my IP. I had eight addresses scattered through the range.
I will pull up my script later this evening. It was quite easy...
by k6ccc
Tue Apr 02, 2019 10:46 pm
Forum: SwOS
Topic: Unable to update firmware CSS 326-24G-2S+RM
Replies: 4
Views: 2419

Re: Unable to update firmware CSS 326-24G-2S+RM

Does the switch have internet connectivity ?



Sent from a $&@#% iPhone using Tapatalk
by k6ccc
Tue Apr 02, 2019 9:15 pm
Forum: General
Topic: How to configure 4 Up-Links on same WAN with 4 vLANs
Replies: 12
Views: 1029

Re: How to configure 4 Up-Links on same WAN with 4 vLANs

@k6ccc So are you like a suburb of LA? Seems like your on the cusp of Mountains, must be beautiful and close to ski hills? (prevalent raging forest fires in that area)? Correct. Glendora is about 20 miles east and slightly north of downtown Los Angeles. The city moto is "Pride of the Foothills". Th...
by k6ccc
Tue Apr 02, 2019 7:55 pm
Forum: General
Topic: How to configure 4 Up-Links on same WAN with 4 vLANs
Replies: 12
Views: 1029

Re: How to configure 4 Up-Links on same WAN with 4 vLANs

I've been doing this for years. Until very recently my RB750r2 had one DSL connection with five static IPs. There were different LANs (mostly via VLAN) that each routed traffic out the same DSL, but via different IP addresses. All it takes is a simple outgoing NAT statement to get the outgoing traff...
by k6ccc
Tue Apr 02, 2019 4:45 am
Forum: General
Topic: WAN Notifications
Replies: 6
Views: 739

Re: WAN Notifications

There are two perspectives here. One is to have the router detect a failure and alert you. The other is to determine if the router is visible from the internet. For part two, I suggest UpTimeRobot.com They can monitor specific ports, a normal ping, a website, and various other things. They can notif...
by k6ccc
Sat Mar 30, 2019 4:43 am
Forum: Beginner Basics
Topic: Static DNS issues
Replies: 1
Views: 413

Re: Static DNS issues

Someone on the internet is trying to connect to presumably a web server on your internet address on port 8080. Why do you think this has anything to do with your DNS?
by k6ccc
Wed Mar 27, 2019 6:27 pm
Forum: Beginner Basics
Topic: Block traffic between VLAN
Replies: 8
Views: 1064

Re: Block traffic between VLAN

Instead of explicitly blocking each VLAN, Block everything with a not interface command (note the explanation point before the interface name): add action=drop chain=forward comment=\ "Block all interfaces except internet from VLAN 10" out-interface=\ !E1-p10_DSL_Internet in-interface=VLAN_10 You wo...
by k6ccc
Tue Mar 26, 2019 7:47 pm
Forum: Beginner Basics
Topic: Firewall rule Order
Replies: 3
Views: 727

Re: Firewall rule Order

Allow what you specifically want allowed, then deny all. This is the last rule in the Forward chain. There is a similar one at the end of the Input chain.
add action=drop chain=forward comment=\
    "Drop any forward packets that get this far"
by k6ccc
Mon Mar 25, 2019 11:59 pm
Forum: SwOS
Topic: Can run OSPF on CRS326-24G-2S+RM
Replies: 4
Views: 2171

Re: Can run OSPF on CRS326-24G-2S+RM

Yes you can. With RouterOS only though.
Hi, elbob2002. Do you mean I can run ospf in CRS326-24G-2S+RM only booted with RouterOS.
OSPF is a routing protocol. Requires a router. When run under SwitchOS, the CRS326 is functioning as a switch - not a router.
by k6ccc
Mon Mar 25, 2019 11:56 pm
Forum: SwOS
Topic: CRS328-24P-4S+ Link Downs, Port Isolation, FAN Error
Replies: 14
Views: 3841

Re: CRS328-24P-4S+ Link Downs, Port Isolation, FAN Error

This thread is an interesting read. I have two CSS326-24G-2S+RM and one CRS326-24G-2S+RM that got updated to 2.9 a few days ago. Obviously no fan issues since the 326 doesn't have fans. I have not observed any problems - so far (64 1/2 hours). I will be watching however... I'll laugh my ass off if M...
by k6ccc
Fri Mar 22, 2019 11:15 pm
Forum: SwOS
Topic: New managed switch
Replies: 1
Views: 1847

Re: New managed switch

I'm using the CSS326-24G-2S+RM and CSS106-5G-1S for exactly that purpose. Quite happy with them.
by k6ccc
Fri Mar 22, 2019 10:56 pm
Forum: SwOS
Topic: Is possible to boot into ROS in CSS326-24G-2S+RM
Replies: 3
Views: 2509

Re: Is possible to boot into ROS in CSS326-24G-2S+RM

OK, now on a PC with a real keyboard instead of my #$%&* iPhone, so able to give a longer answer... The CSS326-24G-2S+RM can only run SwitchOS, whereas the CRS326-24G-2S+RM can be setup to boot into either RouterOS or SwitchOS. When the CRS326-24G-2S+RM boots into RouterOS it has full router functio...
by k6ccc
Fri Mar 22, 2019 9:02 pm
Forum: SwOS
Topic: Is possible to boot into ROS in CSS326-24G-2S+RM
Replies: 3
Views: 2509

Re: Is possible to boot into ROS in CSS326-24G-2S+RM

The CSS is SwitchOS only. The CRS is dual boot. In my opinion, if you need a switch, buy a switch - if you need a router, buy a router. I have five MT devices running Switch OS and very happy with them.



Sent from a $&@#% iPhone using Tapatalk
by k6ccc
Fri Mar 22, 2019 6:10 pm
Forum: Beginner Basics
Topic: Port forward on port 8080
Replies: 14
Views: 1468

Re: Port forward on port 8080

There is something being missed here. Export your configuration and post it.
/export hide-sensitive
by k6ccc
Fri Mar 22, 2019 5:21 pm
Forum: Beginner Basics
Topic: Port forward on port 8080
Replies: 14
Views: 1468

Re: Port forward on port 8080

Two thoughts. First, do your firewall rules allow the port forwarding? If you have an "all all DST-NAT" rule in the forward chain, that would take care of it, but if you don't do that, you generally need to specifically allow the forward. This is not likely the case since port forwarding worked on p...
by k6ccc
Mon Mar 18, 2019 6:38 am
Forum: Beginner Basics
Topic: Generate backup and send it by e-mail
Replies: 5
Views: 1655

Re: Generate backup and send it by e-mail

I am doing exactly that. Here are the settings: First setup your E-Mail server information. I am using a G-Mail account. /tool e-mail set address=smtp.gmail.com from="Router #2" password=Redacted port=587 \ start-tls=yes user=address@gmail.com Then the script that creates the files and sends them: #...
by k6ccc
Thu Mar 14, 2019 11:32 pm
Forum: Beginner Basics
Topic: Help with PPPoE client setup
Replies: 2
Views: 691

Re: Help with PPPoE client setup

Assuming you have everything configured correctly on your managed switch, hooked to eth4 (DSL modem connected to access port for VLAN VID=200) it should work. And it shouldn't be necessary to have dial-on-demand=yes ... Yes, it is. Every VLAN shows up on that trunk port except 100 (the cable intern...
by k6ccc
Thu Mar 14, 2019 7:15 am
Forum: Beginner Basics
Topic: Help with PPPoE client setup
Replies: 2
Views: 691

Help with PPPoE client setup

OK, first a little background. I have a cable based internet and a DSL based internet. The cable is a single DHCP address and until today my DSL was eight static IP addresses that connect to three separate MT routers. Today, my DSL was changed to a single DHCP addresses with PPPoE (the change was fo...
by k6ccc
Tue Mar 12, 2019 12:36 am
Forum: Beginner Basics
Topic: ICMP Drop
Replies: 4
Views: 522

Re: ICMP Drop

You could use the "nth" filter option to drop every nth packet. so for 10% every 10 packet should be dropped.
Just learned something new. Did not even know that existed, but sure enough - it's there...
by k6ccc
Mon Mar 11, 2019 7:41 pm
Forum: Beginner Basics
Topic: ICMP Drop
Replies: 4
Views: 522

Re: ICMP Drop

Hello guys, it is possible to permit icmp but dropping 10 percentage of the packets ? As kiaunel said, I don't know of a way to drop a certain percentage of packets. However you can rate limit certain packets to some number. For example 5 packets per second. add action=accept chain=ICMP comment=\ "...
by k6ccc
Wed Mar 06, 2019 6:20 pm
Forum: SwOS
Topic: Overruns on CSS326-24G-2S+RM
Replies: 46
Views: 15264

Re: Overruns on CSS326-24G-2S+RM

But with 199 days uptime You are running 2.8, right? I upgraded from 2.8 to 2.9 (CSS326), and saw the increase in Rx Overrruns and Tx Pauses. They are too frequent to my liking, but I don't think they have a real impact on network speed. At least, not for me. Truth be told, although I use a 10GB tr...
by k6ccc
Wed Mar 06, 2019 4:45 pm
Forum: SwOS
Topic: Overruns on CSS326-24G-2S+RM
Replies: 46
Views: 15264

Re: Overruns on CSS326-24G-2S+RM

Not my experience. Just looked at one of mine which shows an uptime of 199 days. There is 1 RX Overrun and 0 TX pauses. As I said, nothing faster than 1Gb/s....
by k6ccc
Wed Mar 06, 2019 12:41 am
Forum: SwOS
Topic: Overruns on CSS326-24G-2S+RM
Replies: 46
Views: 15264

Re: Overruns on CSS326-24G-2S+RM

Same here! Lot of tx/rx overruns on 10G port (SFP+ to CRS317) or pauses when flow control is enabled. I'll wait till next SWoS release and if it is not fixed will throw away and will declare it as another cheap junk. You are welcome to send them to me. I have been very happy with my CRS326 (in SWOS...
by k6ccc
Fri Mar 01, 2019 10:21 pm
Forum: SwOS
Topic: Switch identity character length and possible? bug
Replies: 5
Views: 2456

Re: Switch identity character length and possible? bug

I am having issues setting identity of RB260GS. I wanted to set: LOCATION - OFFICE - DEVICEn However, I get cut out, and SwOS version is added after the name. Is this normal, or a bug? Or maybe a browser thing? Tried to the switch, but it didn't work. I don’t remember for sure, but there is a limit...
by k6ccc
Fri Mar 01, 2019 7:43 am
Forum: General
Topic: Securing Mikrotik router using firewall rules causing issues. [SOLVED]
Replies: 21
Views: 2233

Re: Securing Mikrotik router using firewall rules causing issues. [SOLVED]

That Wiki post lists a large number of various rules and settings. Many of which need to be customized to your situation. Therefore, without you posting your configuration, we would only be guessing. Export and post your configuration.
by k6ccc
Wed Feb 13, 2019 5:18 pm
Forum: Beginner Basics
Topic: 100 mbps limit in p2p
Replies: 12
Views: 1693

Re: 100 mbps limit in p2p

set [ find default-name=ether4 ] speed=100Mbps
You state you are connected on ether4 which you have locked to 100Mbps
by k6ccc
Wed Feb 13, 2019 4:40 pm
Forum: Scripting
Topic: HELP! My Static IP gets changes to Dynamic everyday automatically.
Replies: 10
Views: 1365

Re: HELP! My Static IP gets changes to Dynamic everyday automatically.

Until you can find out who is messing with your router, you can also set the computer to a static IP, and then it never will look for a DHCP address at all.
But I agree with the others, you need to figure out who is changing your router configuration.
by k6ccc
Tue Feb 12, 2019 11:47 pm
Forum: Beginner Basics
Topic: hex lite (RB750r2) vs hex (RB750Gr3) for home network
Replies: 8
Views: 3167

Re: hex lite (RB750r2) vs hex (RB750Gr3) for home network

at the moment best router/price around 50-70euros is HAP AC 2. everything you need in this small magic box! it has also 2.4ghz/5ghz wifi. models you suggest dont have wifi. https://mikrotik.com/product/hap_ac2 If you need WiFi. I have WiFi, but it's not combined with my routers - nor would I want i...
by k6ccc
Tue Feb 12, 2019 9:37 pm
Forum: Beginner Basics
Topic: hex lite (RB750r2) vs hex (RB750Gr3) for home network
Replies: 8
Views: 3167

Re: hex lite (RB750r2) vs hex (RB750Gr3) for home network

I started out at my house with a RB750r2 and it worked fine for me - until I got cable based internet that supported 124 Mb/s download via a gigabit interface. Because of strange stuff I was doing, I had a ton of NAT forwarding, and firewall rules in place along with at least a half dozen VLANs and ...
by k6ccc
Tue Feb 12, 2019 5:57 am
Forum: Scripting
Topic: Dynu.com script for dynamic DNS
Replies: 5
Views: 5519

Re: Dynu.com script for dynamic DNS

I know this is a two year old thread, but I'm in the same boat. I added info log entries all over the place and remarked every line and ran the script. Obviously it ran fine with just the log full of the log entries. I then started at the top and removed the remarks one line at a time until it bombe...
by k6ccc
Mon Feb 04, 2019 10:28 pm
Forum: General
Topic: Basic Vlan setup on RB750hex and RB750
Replies: 2
Views: 422

Re: Basic Vlan setup on RB750hex and RB750

Like anav said, post your config or else we are guessing.. With that said, you said "the DHCP server". You need to configure a separate DHCP pool and server per VLAN. What you are doing with the RB750 (the one playing router) is somewhat similar to what I am doing with mine. Each of mine has one WAN...
by k6ccc
Sat Feb 02, 2019 11:11 pm
Forum: Beginner Basics
Topic: I need to set up my second static public IP for my mail server
Replies: 8
Views: 895

Re: I need to set up my second static public IP for my mail server

It looks like you are trying to do this in "Quick Set". Get out of Quick Set and NEVER touch it again. Quick Set is a fairly simple way to do a VERY basic setup for a MT router. Kinda like making it stupid like most "consumer" routers. If you are trying to do anything beyond the basics, you need to ...
by k6ccc
Sat Feb 02, 2019 5:20 am
Forum: Beginner Basics
Topic: I need to set up my second static public IP for my mail server
Replies: 8
Views: 895

Re: I need to set up my second static public IP for my mail server

Will the mail server be on the same LAN as the rest of your stuff at home or will be it be on a separate LAN? If it will be on a separate LAN, it's really easy.
by k6ccc
Fri Feb 01, 2019 1:16 am
Forum: General
Topic: DNS Flag Day
Replies: 3
Views: 845

Re: DNS Flag Day

Did you read the website briefly? There is no reason to worry if you are an Internet user without your own domain name. This change is affecting you only indirectly and you do not need to take any other steps. I did read it. I have three domains that run on my own server, but I get DNS from a comme...
by k6ccc
Thu Jan 31, 2019 11:09 pm
Forum: General
Topic: DNS Flag Day
Replies: 3
Views: 845

DNS Flag Day

For you experts out there, anything about this that I as a end user running MT routers to get to the internet need to do or look out for?
https://dnsflagday.net/
by k6ccc
Tue Jan 29, 2019 9:13 pm
Forum: Beginner Basics
Topic: Text based backup!!!cannot load [SOLVED]
Replies: 12
Views: 1183

Re: Text based backup!!!cannot load [SOLVED]

I agreed with pe1chl. Even minor differences in router types are going to create issues that you will have to manually fix. A while ago, I replaced a RB750r2 with a RB750Gr3. Pretty close - you would thing it would be pretty seamless. Nope. Ended up importing in VERY small chunks in order to get it ...
by k6ccc
Mon Jan 28, 2019 9:27 am
Forum: Beginner Basics
Topic: block inter VLAN traffic
Replies: 17
Views: 4200

Re: block inter VLAN traffic

Just drop it? add action=drop chain=forward in-interface=vlan100 out-interface=vlan200 add action=drop chain=forward in-interface=vlan200 out-interface=vlan100 Thanks would this keep the internet access . Yes. And I would strongly suggest that you spend a while reading the firewall sections of the ...
by k6ccc
Wed Jan 16, 2019 6:29 pm
Forum: Announcements
Topic: SwOS version 2.9 released!
Replies: 72
Views: 34706

Re: SwOS version 2.9 released!

Updated my CSS106-5G-1S from 2.8 and all appears to be working. However, after the upgrade, this is what the Upgrade page says: Firmware Current Installed Version 2.9 (built at Mon Jan 07 2019 03:04:37 GMT-0800 (GMT-08:00)) Latest Available Version 2.9 (built at Mon Jan 14 2019 02:29:12 GMT-0800 (GM...
by k6ccc
Tue Jan 15, 2019 11:23 pm
Forum: SwOS
Topic: Can’t factory reset SwOS on CRS328-24P-4S+
Replies: 9
Views: 4379

Re: Can’t factory reset SwOS on CRS328-24P-4S+

You have to let WinBox sit on the neighbors tab for 5 to 10 minutes before the switches show up. By George, you are right. Took hours, but three of my five switches have appeared. The CSS106-5G-1S two CSS-326-24G-2S are showing but the RB-260GS and CRS326-24G-2S (running SwOS) along with my RG750Gr...
by k6ccc
Tue Jan 15, 2019 6:10 pm
Forum: SwOS
Topic: Can’t factory reset SwOS on CRS328-24P-4S+
Replies: 9
Views: 4379

Re: Can’t factory reset SwOS on CRS328-24P-4S+

A SwOS device will appear in the neighbor list in Winbox but you cannot connect to it using winbox. As I said, I'll have to take your word on that - None of my five MT switches are seen on the neighbor list on WinBox 3.18. I don't even see all of my MT routers in the neighbor list. I even confirmed...
by k6ccc
Tue Jan 15, 2019 6:41 am
Forum: SwOS
Topic: Can’t factory reset SwOS on CRS328-24P-4S+
Replies: 9
Views: 4379

Re: Can’t factory reset SwOS on CRS328-24P-4S+

I’ll take your word on it, but my WinBox does not see any of my switches.

Jim



Sent from a $&@#% iPhone using Tapatalk
by k6ccc
Sun Jan 13, 2019 5:26 am
Forum: SwOS
Topic: Can’t factory reset SwOS on CRS328-24P-4S+
Replies: 9
Views: 4379

Re: Can’t factory reset SwOS on CRS328-24P-4S+

First of all, once it is in SwitchOS, you can’t connect via WinBox. Must connect via the web interface.

As for your DHCP address, does your DHCP server show an address assigned?



Sent from a $&@#% iPhone using Tapatalk
by k6ccc
Thu Jan 03, 2019 7:38 am
Forum: SwOS
Topic: CSS326-24G-2S+RM hangs until power cycle
Replies: 89
Views: 19919

Re: CSS326-24G-2S+RM hangs until power cycle

Only time I have had one of CSS326 switches hang is when I had a problem DSL modem. The modem would crash, and after power cycling it, the switch would shortly lock up. Replaced the DSL modem after we determined that it was having a problem. Never had a problem with the switch since. Currently it is...
by k6ccc
Mon Dec 24, 2018 10:12 pm
Forum: Beginner Basics
Topic: Winbox disconnecting
Replies: 1
Views: 361

Re: Winbox disconnecting

Are you doing something? By that, I mean have you started making parameter changes? If yes, what are you changing? Also, what version of WinBox and RouterOS?
by k6ccc
Mon Dec 24, 2018 5:33 am
Forum: SwOS
Topic: CSS326-24G-2S+ does not accept dhcp-provided IP!?
Replies: 2
Views: 2034

Re: CSS326-24G-2S+ does not accept dhcp-provided IP!?

The CSS326 runs SwitchOS and does not have a DHCP server. Although I normally run all of my switches with static IPs, I remember when I first got them and they factory defaulted to DHCP with fallback, the DHCP client worked. What is the setting of the Address Acquisition on the System tab? Also, wha...
by k6ccc
Thu Dec 20, 2018 11:32 pm
Forum: SwOS
Topic: CSS326-24G-2S - Where is WATCHDOG IP address to ping!!!???
Replies: 10
Views: 4214

Re: CSS326-24G-2S - Where is WATCHDOG IP address to ping!!!???

But if no one reports it as a bug, Mikrotik wont try to find it. Talking about here on a users forum does not constitute a trouble report.
by k6ccc
Mon Dec 17, 2018 12:21 am
Forum: Beginner Basics
Topic: Cloud Smart Switch 326-24G-2S+RM noise
Replies: 1
Views: 528

Re: Cloud Smart Switch 326-24G-2S+RM noise

I have two of them at home - one is a couple feet from me as I sit at my computer. There is a grill for a fan, but there isn't a fan mounted.
by k6ccc
Wed Dec 12, 2018 7:06 am
Forum: Beginner Basics
Topic: LAN and internet in the same public range /27
Replies: 10
Views: 1168

Re: LAN and internet in the same public range /27

Why are you wanting to use the same IP range?
by k6ccc
Tue Dec 11, 2018 11:05 pm
Forum: SwOS
Topic: Possible bug in stats for SwOS 2.0 in CSS326 ? [SOLVED]
Replies: 10
Views: 4245

Re: Possible bug in stats for SwOS 2.0 in CSS326 ? [SOLVED]

Kennethven,
This thread is almost 5 months old. Who are you even directing that to? And there is no PM capability on this forum.
by k6ccc
Sat Nov 17, 2018 12:54 am
Forum: General
Topic: How to secure port on the switch?
Replies: 8
Views: 962

Re: How to secure port on the switch?

don't understand your question. Note that switches don't have macs only network devices.
Wow! I'm going to have to tell all my switches that they don't really have a MAC. That will be a shock to them. How do you suppose layer two works without a MAC?
by k6ccc
Sat Nov 17, 2018 12:44 am
Forum: Beginner Basics
Topic: Winbox problem
Replies: 2
Views: 736

Re: Winbox problem

You have the WinBox port set to a non-standard 8219. Are you specifying the non-standard port when you try to connect? BTW, I also use a non-standard port for WinBox access to my routers.
by k6ccc
Fri Nov 16, 2018 3:04 pm
Forum: SwOS
Topic: 2 untagged VLAN same interface
Replies: 11
Views: 3476

Re: 2 untagged VLAN same interface

No. No way to know which LAN a packet is part of if they are both I tagged.



Sent from a $&@#% iPhone using Tapatalk
by k6ccc
Tue Nov 13, 2018 11:51 pm
Forum: SwOS
Topic: About VLAN configure in CRS317-1G-16S+RM
Replies: 12
Views: 4662

Re: About VLAN configure in CRS317-1G-16S+RM

I have five switches running SwitchOS (listed in my signature) without any problems at all. Only thing fancy I'm doing is VLANs, but all of them have over a dozen VLANs at my house...
by k6ccc
Mon Nov 05, 2018 7:37 am
Forum: Beginner Basics
Topic: MAC Reservations
Replies: 5
Views: 10687

Re: MAC Reservations

Please assist, i am network support agent, i have come across where i need to add/make mac reservation, static IP Reserve. I have to two questions, 1. If MAC address doesn't show up on leases, can i add it or maybe i need to plug LAN cable from RouterBoard to PC before? 2. How is IP DHCP reservatio...
by k6ccc
Tue Oct 30, 2018 10:22 pm
Forum: Beginner Basics
Topic: Hairpin NAT
Replies: 3
Views: 932

Re: Hairpin NAT

You did not list your firewall rules. I assume that there is either a rule that allows the specific NAT through the firewall, or all NATted packets through the firewall. Does that rule or rules specify the input being the WAN interface? That would stop NATTed packets that are coming in on one of the...
by k6ccc
Tue Oct 30, 2018 5:06 pm
Forum: Beginner Basics
Topic: blocking ping/ICMP
Replies: 4
Views: 1021

Re: blocking ping/ICMP

Thanks vecernik87 for the longer answer. My short answer was courtesy of needing to get to bed :)
by k6ccc
Tue Oct 30, 2018 6:29 am
Forum: Beginner Basics
Topic: blocking ping/ICMP
Replies: 4
Views: 1021

Re: blocking ping/ICMP

If you are just wanting to block ICMP packets, simply do just that. Something like this:
add action=drop chain=input in-interface=e1_Internet protocol=icmp
Obviously you would have to edit this to have the in-interface = whatever your internet interface is (as opposed to my e1_internet).
by k6ccc
Sat Oct 27, 2018 1:07 am
Forum: Beginner Basics
Topic: cant surf on new ip block
Replies: 4
Views: 872

Re: cant surf on new ip block

For starters, please export and post your configuration so we have some idea what you are doing.
by k6ccc
Fri Oct 26, 2018 4:51 pm
Forum: SwOS
Topic: About VLAN configure in CRS317-1G-16S+RM
Replies: 12
Views: 4662

Re: About VLAN configure in CRS317-1G-16S+RM

You're still not really telling us what you are trying to accomplish (we're not mind readers). Also, you are asking about this in the SwitchOS section of the forum. Can I assume you are doing this on your CRS317 operating in SwitchOS as opposed to RouterOS?
by k6ccc
Thu Oct 25, 2018 5:30 pm
Forum: SwOS
Topic: About VLAN configure in CRS317-1G-16S+RM
Replies: 12
Views: 4662

Re: About VLAN configure in CRS317-1G-16S+RM

Not enough information. What are you trying to accomplish?
by k6ccc
Sat Oct 06, 2018 7:57 am
Forum: SwOS
Topic: CRS317-1G-16S+ vlan list bug
Replies: 2
Views: 2372

Re: CRS317-1G-16S+ vlan list bug

For whatever it's worth, both of my CSS326-24G-2S switches with 2.8 have 17 VLANs and working perfectly.

I don't have any CRS317 routers.
by k6ccc
Tue Oct 02, 2018 6:24 pm
Forum: SwOS
Topic: 2.9 upgrade
Replies: 2
Views: 2905

Re: 2.9 upgrade

Not knowing the details of how upgrades are released, my speculation is that 2.9 is not really released yet. Maybe they were about to release it, so it got into the notes, but then an issue was found and the release halted. Just a guess....
by k6ccc
Mon Oct 01, 2018 6:06 pm
Forum: SwOS
Topic: CSS326 - Cannot connect to GUI [Solved]
Replies: 4
Views: 3160

Re: CSS326 - Cannot connect to GUI [Solved]

Has the same problem, purchased two new css326-24g-2s+rm , cannot acess the web GUI through 192.168.88.1 on both switches
What IP is your computer?
by k6ccc
Sat Sep 29, 2018 11:43 pm
Forum: Beginner Basics
Topic: quick set does not allow to set bridge mode on CRS328
Replies: 1
Views: 486

Re: quick set does not allow to set bridge mode on CRS328

Don't use Quick Set.
Quick Set is very limited in what it can do.
by k6ccc
Sat Sep 29, 2018 8:02 am
Forum: General
Topic: DHCP over 802.1Q VLAN
Replies: 2
Views: 561

Re: DHCP over 802.1Q VLAN

I have a switch with 802.1Q VLAN setup, where I want to use a mikrotik router for DHCP. If I have a DHCP server on a tagged VLAN interface, this should work fine going through the switch? Have an IP phone not picking up DHCP, I'll try a factory reset of the phone How is the iPhone getting to the ne...
by k6ccc
Wed Sep 19, 2018 7:08 pm
Forum: Beginner Basics
Topic: Bruteforce prevention Issue
Replies: 14
Views: 1820

Re: Bruteforce prevention Issue

I do use port knocking (among other things), and log any connection attempts. Of course for step one I see hits somewhat regularly due to random scans. I have NEVER seen a hit on step two if it was not me. As sob said, most of the attackers are simply going after the commonly used ports. I do also h...
by k6ccc
Sat Sep 15, 2018 10:33 am
Forum: SwOS
Topic: SwOS or RouterOS
Replies: 3
Views: 3772

Re: SwOS or RouterOS

I have two CSS326, one CRS326, one CSS106, and one RB260 that are all running SwitchOS, in addition to three RB750 routers running RouterOS. My general philosophy is that if you want a switch, buy a switch and run a switch OS. If you want a router, buy a router and run a router OS. I don’t mix the t...
by k6ccc
Fri Sep 14, 2018 6:33 am
Forum: SwOS
Topic: CRS317 boot issue after power failure
Replies: 22
Views: 5034

Re: CRS317 boot issue after power failure

2.9 does nothing for me, so I likely won't bother with this one...
by k6ccc
Fri Sep 14, 2018 6:32 am
Forum: SwOS
Topic: CRS317 boot issue after power failure
Replies: 22
Views: 5034

Re: CRS317 boot issue after power failure

I see SwOS 2.9 was released today. Who's gonna be brave and give it a test run? Where are you seeing that 2.9 was released? Not on the software download page and no announcements here on the forum. Ah, one of my switches shows that: Current Installed Version 2.8 (built at Fri Jul 13 2018 04:37:06 G...
by k6ccc
Thu Sep 13, 2018 7:52 pm
Forum: Beginner Basics
Topic: DHCP pool problem
Replies: 12
Views: 2523

Re: DHCP pool problem

right now i dont have a busy state in my IPs. what's the command to see this status? address=192.168.13.42 mac-address=00:E1:00:86:1E:34 client-id="1:0:e1:0:86:1e:34" address-lists="" server=defconf dhcp-option="" status=waiting last-seen=1w3d20h30m23s I normally use WinBox and there it's easy. Jus...
by k6ccc
Thu Sep 13, 2018 7:47 pm
Forum: Beginner Basics
Topic: DHCP pool problem
Replies: 12
Views: 2523

Re: DHCP pool problem

is it possible to have them take the lowest possible IP? No. ROS assigns IP addresses from the top of the pool. You have no control of that. My recommendation is that if you have devices that you want to have a specific address, let them connect (so they show up in the DHCP Leases list), and then c...
by k6ccc
Thu Sep 13, 2018 6:24 pm
Forum: Beginner Basics
Topic: DHCP pool problem
Replies: 12
Views: 2523

Re: DHCP pool problem

From the Wiki: Lease status: waiting - un-used static lease testing - testing whether this address is used or not (only for dynamic leases) by pinging it with timeout of 0.5s authorizing - waiting for response from radius server busy - this address is assigned statically to a client or already exist...
by k6ccc
Tue Sep 11, 2018 5:51 pm
Forum: Beginner Basics
Topic: Distinguishing between clients' routers
Replies: 7
Views: 809

Re: Distinguishing between clients' routers

Ahh of course... after having this enabled for a long time one forgets that it is even there...
Yep! Same here...
by k6ccc
Mon Sep 10, 2018 11:27 pm
Forum: Beginner Basics
Topic: Firewall rules with port scanner dropping
Replies: 3
Views: 5055

Re: Firewall rules with port scanner dropping

This is the last rule in my input chain. There is a similar rule in the forward chain. add action=drop chain=input comment=\ "Drop any other input packets that get this far" log-prefix=\ "Dropped connection" Remember how rule processing works. It's top to bottom, and if a rule is not explicitly drop...
by k6ccc
Mon Sep 10, 2018 12:51 am
Forum: Beginner Basics
Topic: Distinguishing between clients' routers
Replies: 7
Views: 809

Re: Distinguishing between clients' routers

You can set the "Note" to anything you darn well please.
by k6ccc
Fri Sep 07, 2018 6:40 pm
Forum: Beginner Basics
Topic: Firewall rules with port scanner dropping
Replies: 3
Views: 5055

Re: Firewall rules with port scanner dropping

You have a bunch of rules that add addresses to the Port Scanners list, but you never drop them. Do you have a drop everything rule at the end of the Input and Forward chains? My opinion is that dropping pings from the internet creates more problems than it solves. I know some people firmly believe ...
by k6ccc
Fri Sep 07, 2018 4:19 am
Forum: SwOS
Topic: Bandwidth control by vlan CSS326-24G-2S+
Replies: 1
Views: 2001

Re: Bandwidth control by vlan CSS326-24G-2S+

Your question is in the Switch OS section of the forum and your subject title asks about the CSS326 switch. However the text of your question asks about two specific routers. Are you trying to control BW in SwitchOS or Router OS? No way to do that in SwitchOS Sent from a $&@#% iPhone using Tapatalk
by k6ccc
Thu Sep 06, 2018 10:45 pm
Forum: SwOS
Topic: LAG (LACP) or RSTP or both???
Replies: 17
Views: 6108

Re: LAG (LACP) or RSTP or both???

You really need (R/M)STP to run on top of LACP bonding if you add the "Switch C" for the whole system to work (your lower picture). The LACP bonding itself will be treated like one physical port by RSTP - it can't disable only part of it. But if there is no other potential loops, and the LACP bondi...
by k6ccc
Thu Sep 06, 2018 9:07 pm
Forum: SwOS
Topic: LAG (LACP) or RSTP or both???
Replies: 17
Views: 6108

Re: LAG (LACP) or RSTP or both???

I would say so.
If you have many switches use of rstp becomes obvious...
Yes, makes sense.

Thanks for your help. Sounds like I largely had it figured out, but fully admit that I only knew enough to be dangerous!
by k6ccc
Thu Sep 06, 2018 8:38 pm
Forum: Beginner Basics
Topic: Bruteforce prevention Issue
Replies: 14
Views: 1820

Re: Bruteforce prevention Issue

Here's what I do to make a port knock easier. I have bookmarks in my browser for each one. Click the first one, wait a second, click the second on, etc. Takes seconds. This works if we are only managing 1 or 2 devices, but I am managing 500 routers in the field and increasing. This bookmark feature...
by k6ccc
Thu Sep 06, 2018 8:32 pm
Forum: SwOS
Topic: LAG (LACP) or RSTP or both???
Replies: 17
Views: 6108

Re: LAG (LACP) or RSTP or both???

But for your question, when LACP or static team active rstp doesn`t play any role as it simply puts port in edge mode.
So in a summary, RSTP in this case is only there to prevent you from doing something stupid (or cover your backsides if or when you do). Do I have that right?
by k6ccc
Thu Sep 06, 2018 8:22 pm
Forum: Beginner Basics
Topic: Bruteforce prevention Issue
Replies: 14
Views: 1820

Re: Bruteforce prevention Issue

Thank you for your all responses, I have a couple simple questions at first. One when you select code to add in what option are you picking ? I assume you mean where I included my code extract. It's the symbol to the left of the quotation marks. You can also just type "[ c o d e ]" and "[ / c o d e...
by k6ccc
Thu Sep 06, 2018 8:07 pm
Forum: SwOS
Topic: LAG (LACP) or RSTP or both???
Replies: 17
Views: 6108

Re: LAG (LACP) or RSTP or both???

LACP is for link aggregation. 2 ports on switch A and 2 ports on switch B. 2GB link between them with LACP. If not using LACP or static team 2 ports connected between switches would create LOOP. This is what RSTP is for. To prevent loops and lear about topology changes: Right. Got that part. 1. So ...
by k6ccc
Thu Sep 06, 2018 7:28 pm
Forum: Beginner Basics
Topic: Bruteforce prevention Issue
Replies: 14
Views: 1820

Re: Bruteforce prevention Issue

As Sob said, what you're doing is not overly helpful. At first I thought you were doing a port knock until I read it. You would do better with a port knock. add action=add-src-to-address-list address-list="Long Knock-1" \ address-list-timeout=15s chain=input comment=\ "Long Port Knock setup step 1" ...
by k6ccc
Thu Sep 06, 2018 6:54 pm
Forum: SwOS
Topic: LAG (LACP) or RSTP or both???
Replies: 17
Views: 6108

Re: LAG (LACP) or RSTP or both???

Well, now I'm back to confused. First of all, I fully understand how bad a loop can be. Last year at work on a microwave network that supports a large public safety radio 2-way radio system, we had a loop protection failure that resulted in a broadcast storm that took down the entire network. Really...
by k6ccc
Mon Sep 03, 2018 5:27 am
Forum: General
Topic: Chinese IP Cameras
Replies: 9
Views: 1298

Re: Chinese IP Cameras

I also have a bunch of Chinese cameras at home. I created a dedicated VLAN for them that is firewalled so that they can get to the internet (required for remote viewing), and nothing else on my home networks.
by k6ccc
Sun Sep 02, 2018 10:26 pm
Forum: SwOS
Topic: LAG (LACP) or RSTP or both???
Replies: 17
Views: 6108

Re: LAG (LACP) or RSTP or both???

Thanks again. You pretty well told me what I thought I already understood from reading, but I had been confused when some other guy in a different thread told me that I should always be using RSTP. It will be a while before I have time to bury another conduit between the house and garage, so I'm in ...
by k6ccc
Sun Sep 02, 2018 9:36 pm
Forum: SwOS
Topic: LAG (LACP) or RSTP or both???
Replies: 17
Views: 6108

Re: LAG (LACP) or RSTP or both???

Thanks for the reply. I'm curious why I can't use RSTP. I've read the Wiki about a million times (OK, not really a million) and don't see why I could not use RSTP, and in a different thread where this topic came up, it was recommended that I should always use RSTP. From my own research, I had assume...
by k6ccc
Fri Aug 31, 2018 9:28 pm
Forum: Beginner Basics
Topic: How to change mikrotik Rb750gr3 hotspot login page..?
Replies: 3
Views: 1046

Re: How to change mikrotik Rb750gr3 hotspot login page..?

Maybe I'm missing something here, but the RB750Gr3 does not have WiFi.
Note: I am not using MikroTik for my WiFi - only for routers and switches. So I could be missing something.
by k6ccc
Mon Aug 27, 2018 9:56 pm
Forum: SwOS
Topic: DHCP Snooping on SwOS 2.8 CRS328-24P-4S+RM
Replies: 6
Views: 3691

Re: DHCP Snooping on SwOS 2.8 CRS328-24P-4S+RM

Do you have DHCP Snooping enabled on the end device ports of the switch (ports 1, 7, 13, & 15 if I counted right)?
by k6ccc
Mon Aug 27, 2018 2:34 am
Forum: SwOS
Topic: CSS106 - access via SFP problem
Replies: 1
Views: 2031

Re: CSS106 - access via SFP problem

What software version is your CSS? My CSS106-5G-1S is version 2.8 and is configured quite different than yours. The SFP is a gigabit link from this switch to a CSS326-24G-2S in my family room. It is exclusively a tagged trunk port. The two Open Mesh ports are WiFi access points that have both a non-...
by k6ccc
Fri Aug 24, 2018 8:16 am
Forum: General
Topic: Sofware VLAN/Bridge on RuterOS explained.
Replies: 62
Views: 24933

Re: Sofware VLAN/Bridge on RuterOS explained.

I use routers EXCLUSIVELY as routers and switches as switches. Each port of my routers is either a single LAN or a VLAN trunk port. The same exercise is needed when configuring RB running ROS if that RB is to be used as smart switch. Not that I would recommend that since HW offload is disabled and ...
by k6ccc
Fri Aug 24, 2018 7:18 am
Forum: SwOS
Topic: Website download for CRS 2.8 links to CSS
Replies: 4
Views: 2530

Re: Website download for CRS 2.8 links to CSS

Well, I for one am quite happy with my two CSS326-24G-2S and also the CRS326-24G-2S (running SwitchOS). I have not found any way in SwitchOS to determine the CPU load, so I can't tell you how much I'm loading them. Reality is likely not all that much. This is at my house and then also a MicroWave pa...
by k6ccc
Fri Aug 24, 2018 1:42 am
Forum: SwOS
Topic: LAG (LACP) or RSTP or both???
Replies: 17
Views: 6108

Re: LAG (LACP) or RSTP or both???

Nobody have anything?
by k6ccc
Fri Aug 24, 2018 1:39 am
Forum: General
Topic: Sofware VLAN/Bridge on RuterOS explained.
Replies: 62
Views: 24933

Re: Sofware VLAN/Bridge on RuterOS explained.

Yes, thank you both for the education. I didn't really need it, but it was interesting. I have a different solution. I use routers EXCLUSIVELY as routers and switches as switches. Each port of my routers is either a single LAN or a VLAN trunk port. Never does any LAN or VLAN appear on more than one ...
by k6ccc
Thu Aug 23, 2018 6:01 pm
Forum: Beginner Basics
Topic: Error:could not connect to 192.168.15.1
Replies: 4
Views: 13140

Re: Error:could not connect to 192.168.15.1

i noticed that the winbox port has change ... what can be the reason ? Can I assume that you mean that when you connect via the MAC address, you are able to see that the service port for WinBox has changed. If that is the case, you would need to specify the non-standard port. In your case, that wou...
by k6ccc
Wed Aug 22, 2018 8:37 am
Forum: SwOS
Topic: Link status of SFP S+RJ10
Replies: 4
Views: 2779

Re: Link status of SFP S+RJ10

Just an FYI, about an hour ago I installed a S-RJ01 into a CSS326-24G-2S that has SwitchOS 2.8. It behaved exactly as I expected. Link showed as down with no cable plugged in. When I plugged in a cable to a RB260GS with a third party SFP, the link came right up and showed 1G. Pings to both the far e...
by k6ccc
Tue Aug 21, 2018 4:01 pm
Forum: General
Topic: Winbox access to Mikrotik behind a MIkrotik
Replies: 9
Views: 921

Re: Winbox access to Mikrotik behind a MIkrotik

Use non-standard ports for WinBox access to the PTPs. Then it’s just standard NATting to get to them from the internet.



Sent from a $&@#% iPhone using Tapatalk
by k6ccc
Mon Aug 20, 2018 9:22 pm
Forum: SwOS
Topic: What's VLAN-tagging the packets?
Replies: 8
Views: 3045

Re: What's VLAN-tagging the packets?

EdPa, thanks for the explanation. A couple suggestions to pass along to the software people. Any chance of making the VLAN and VLANs tabs look and operate the same between the CSS326 and the CSS106 & RB260GS. I have both types of switches and it is annoying to have to think quite differently between...
by k6ccc
Mon Aug 20, 2018 9:11 pm
Forum: SwOS
Topic: CSS326-24G-2S - Where is WATCHDOG IP address to ping!!!???
Replies: 10
Views: 4214

Re: CSS326-24G-2S - Where is WATCHDOG IP address to ping!!!???

I don't believe that the WatchDog timer is for a specific link, but rather looking for internal process locking up. Hence, no IP to be pinging.
by k6ccc
Mon Aug 20, 2018 10:01 am
Forum: Beginner Basics
Topic: Updating firmware
Replies: 4
Views: 795

Re: Updating firmware

Taking your thought, I did a comparison of the Saturday night and Sunday night script files for both routers - before and after my updates Sunday morning. There were only two differences. First is that the software version was different. Well, it darn well better be! Second was a login script that w...
by k6ccc
Mon Aug 20, 2018 6:03 am
Forum: Beginner Basics
Topic: Updating firmware
Replies: 4
Views: 795

Re: Updating firmware

Funny you should bring this up today. This morning I updated both of my RB750s from 6.42.1 to 6.42.6 and updated the firmware on both from quite old to current. The upgrades went very well. I already have a scheduled script to do a daily backup and export, so I have a good baseline. I had not planne...
by k6ccc
Mon Aug 20, 2018 4:19 am
Forum: Beginner Basics
Topic: Trying to get past "sfp-type: (unknown)"
Replies: 7
Views: 976

Re: Trying to get past "sfp-type: (unknown)"

I had the same issue with some HP 2610-48s. Had to use HP SFPs.
by k6ccc
Mon Aug 20, 2018 12:35 am
Forum: Beginner Basics
Topic: Trying to get past "sfp-type: (unknown)"
Replies: 7
Views: 976

Re: Trying to get past "sfp-type: (unknown)"

Because it's the Cisco that is showing no link, I am guessing that it is the end that does not like the really cheap SFP. Just a guess however.
by k6ccc
Sun Aug 19, 2018 8:14 pm
Forum: Beginner Basics
Topic: Trying to get past "sfp-type: (unknown)"
Replies: 7
Views: 976

Re: Trying to get past "sfp-type: (unknown)"

My first guess is that the SFP is not really compatible with one or both of the devices that they are plugged into. I have found with several equipment brands (MikroTik and others as well) that not all SFPs will work. In fact just this morning I found that none of my assorted pile of 1GigE SFPs woul...
by k6ccc
Sun Aug 19, 2018 7:14 pm
Forum: General
Topic: Bridges getting deleted
Replies: 7
Views: 1009

Re: Bridges getting deleted

What hardware?
by k6ccc
Sat Aug 18, 2018 2:14 am
Forum: SwOS
Topic: What's VLAN-tagging the packets?
Replies: 8
Views: 3045

Re: What's VLAN-tagging the packets?

Are you implying that SwOS will just tag unconditionally if a port is a member of multiple VLANs or something? Could be. I really don't know. I certainly don't claim to be the expert. In fact I just learned an hour ago that a setting in 2.7 did not work quite the way I expected for un-tagged ports....
by k6ccc
Fri Aug 17, 2018 11:01 pm
Forum: SwOS
Topic: What's VLAN-tagging the packets?
Replies: 8
Views: 3045

Re: What's VLAN-tagging the packets?

You have to have VLAN tagging on the trunk port or else you would have both VLAN 2 & 3 untagged (and therefore no longer separate) on the trunk port.
by k6ccc
Fri Aug 17, 2018 2:13 am
Forum: Wireless Networking
Topic: Can I run separate Hotspot servers per VLAN?
Replies: 8
Views: 1196

Re: Can I run separate Hotspot servers per VLAN?

As I recall, the NanoStation will happily pass VLAN traffic and is VLAN aware for the management interface, but I'm not aware of the ability to specify which VLAN to use for locally connected stations. Note that I am using them for a point to point link with a managed switch (CSS326-24G-2S) on each ...
by k6ccc
Thu Aug 16, 2018 5:36 pm
Forum: Beginner Basics
Topic: Understanding Default config: bridge
Replies: 4
Views: 4677

Re: Understanding Default config: bridge

It depends on what you are doing. I am not using a bridge on any of my routers. However, I am using my routers exclusively as routers. Each port is either a separate LAN or a trunk port with multiple VLANs. Everything is routed in between ports. Each port is connected to a different port of a manage...
by k6ccc
Thu Aug 16, 2018 3:22 pm
Forum: General
Topic: I've closed all service ports by mistake [SOLVED]
Replies: 4
Views: 995

Re: I've closed all service ports by mistake [SOLVED]

Hopefully you have previously saved backups so after the net install, you can restore from your backup. If not, lesson learned - backup, backup, and off site backup.



Sent from a $&@#% iPhone using Tapatalk
by k6ccc
Wed Aug 15, 2018 7:36 pm
Forum: SwOS
Topic: LAG (LACP) or RSTP or both???
Replies: 17
Views: 6108

LAG (LACP) or RSTP or both???

This is an area where have no experience so looking for suggestions. My situation at home is as follows. In my Family room I have a CSS324-24G-2S with various computers, WiFi, lighting controls, and monitoring devices connected. Both my DSL and cable internet connections also come into the Family ro...
by k6ccc
Wed Aug 15, 2018 6:11 pm
Forum: Announcements
Topic: SwOS version 2.8 released!
Replies: 37
Views: 19923

Re: SwOS version 2.8 released!

on my CSS326-24G-2S+ manual upgrade dont works. switch not accessible(web) after manual upgrade. to access the switch again, i had to boot backup SwOS. i tried upgrade from backup SwOS(2.0p) to 2.8, and reset configuration - but no success. Most likely the switch changed from a static IP to DHCP. C...
by k6ccc
Wed Aug 15, 2018 5:42 pm
Forum: General
Topic: Question on Firewall and blacklists
Replies: 4
Views: 757

Re: Question on Firewall and blacklists

Here's another example of using stuff in the Output chain. I was recently troubleshooting a problem and I wanted to be able to verify that packets were going out on the interface that they should have been. So I created the following set of output chain rules that served only to count packets on eac...
by k6ccc
Wed Aug 15, 2018 5:25 am
Forum: General
Topic: Question on Firewall and blacklists
Replies: 4
Views: 757

Re: Question on Firewall and blacklists

Yes. The Input chain only affects traffic that will terminate on the router itself. The Forward chain affects traffic that will pass through the router. Note that you have an allow connected and related traffic in the Forward chain, that rule will allow responses to one of your users who connects to...
by k6ccc
Wed Aug 15, 2018 4:13 am
Forum: Beginner Basics
Topic: 2 vlans with mikrotik and unifi - no way to make it work
Replies: 1
Views: 460

Re: 2 vlans with mikrotik and unifi - no way to make it work

The problem is your dumb switch. Some dumb switches will pass 802.1Q VLAN traffic and some will not. I have no idea if your tplink will or not. Assuming that it won't, my suggestion would be to split it up. Have the tplink and the attached computers connected as they are now. Then run a separate con...
by k6ccc
Tue Aug 14, 2018 5:18 pm
Forum: General
Topic: Moving a port - what did I miss???
Replies: 3
Views: 547

Re: Moving a port - what did I miss???

Thanks again Sindy! That was it, and yes, that was a leftover from old times. Confirmed that with an AutoCAD drawing from early last year. As soon as I changed the VLAN switch setting for that port, pings started working, and forwarding traffic started working properly. As this router is used exclus...
by k6ccc
Tue Aug 14, 2018 3:41 pm
Forum: General
Topic: Moving a port - what did I miss???
Replies: 3
Views: 547

Re: Moving a port - what did I miss???

Thanks for the catch Sindy. Ether2 is not supposed to be a hybrid port at all. It should be all untagged traffic. I’m on a commuter train on my phone right now so I can’t look for a couple hours, but that was likely a leftover from time past. The .131 LAN is currently a VLAN on the 802.1q trunk on p...
by k6ccc
Tue Aug 14, 2018 5:43 am
Forum: General
Topic: Moving a port - what did I miss???
Replies: 3
Views: 547

Moving a port - what did I miss???

I have managed to apparently do something stupid. I was moving one of my LANs from port ether3 to ether2 on an RB750r2. This router is being used exclusively as a router - there is no bridge and every port is a different LAN or trunk port with multiple VLANs. Should be simple enough and I've done th...
by k6ccc
Tue Aug 14, 2018 3:31 am
Forum: SwOS
Topic: CSS326-24G-2S+ firmware 2.8 broken web UI
Replies: 4
Views: 2750

Re: CSS326-24G-2S+ firmware 2.8 broken web UI

After upgrade to v2.8, switch goes from "static IP" to "DHCP with fallback", - looks like a bug.
so put DHCP server on top of swtich and use that dynamic assigned IP to back to Static IP

Not a bug. That's the way it's designed.
by k6ccc
Mon Aug 13, 2018 12:35 am
Forum: SwOS
Topic: Website download for CRS 2.8 links to CSS
Replies: 4
Views: 2530

Re: Website download for CRS 2.8 links to CSS

For your first part, I would assume that since you are looking for SwitchOS and not RouterOS, you should be getting the same SwitchOS as the CSS. That is the case with the CRS326, so I'm guessing it's the same with the CRS328. For your second part, depending on what version you upgraded from, very l...
by k6ccc
Thu Aug 09, 2018 2:32 am
Forum: Beginner Basics
Topic: Can't ping radio on LAN from radio on WAN side
Replies: 2
Views: 441

Re: Can't ping radio on LAN from radio on WAN side

I find it easy to believe that it does not work. You are mixing up your subnets. You are trying to get a 10.10.25.x device to talk on a router that has a port on the 192.168.10.x subnet. Can't get there. Now if you were to use very small subnets, and give the router an additional address on the WAN ...
by k6ccc
Wed Aug 08, 2018 7:34 pm
Forum: General
Topic: Do not open port tcp/23 to your device from internet you will be hacked
Replies: 6
Views: 1633

Re: Do not open port tcp/23 to your device from internet you will be hacked

Short comment would be: DUH! OK, now for the longer, more polite answer. Anyone who runs almost any type of server these days will see piles of attack attempts on a variety of ports. Yes, Telnet is one of the most common. I don't log them, but I do have firewall rules that drop and count packets. I ...
by k6ccc
Tue Aug 07, 2018 1:11 am
Forum: Announcements
Topic: Winbox v3.16 released!
Replies: 63
Views: 35128

Re: Winbox v3.16 released!

If you go to the software download page and select Winbox, the dropdown shows 3.17, but that results in a 404 error. Might want to fixed the webpage - either that or 3.17 is about to be released about the time I post this message :)
by k6ccc
Sun Aug 05, 2018 9:55 pm
Forum: General
Topic: VLANs with "stacked" switches
Replies: 12
Views: 1898

Re: VLANs with "stacked" switches

I'd argue to keep with the best practice and use STP or the new MSTP implementation. It's just good common sense loop protection. That said it looks like you're using the old way VLANs where done but not in a complete way. I'd urge you to migrate to the VLAN aware bridging approach. It's documented...
by k6ccc
Sun Aug 05, 2018 7:51 am
Forum: General
Topic: VLANs with "stacked" switches
Replies: 12
Views: 1898

Re: VLANs with "stacked" switches

I imagine you're either running in the per-VLAN based mode or do not have STP correctly running. I haven't actually sniffed a link without an untagged VLAN defined to see if MikroTik hides this fault to keep networks working despite the best effort of their admins. Of course I know what Spanning Tr...
by k6ccc
Fri Aug 03, 2018 6:48 pm
Forum: General
Topic: VLANs with "stacked" switches
Replies: 12
Views: 1898

Re: VLANs with "stacked" switches

I don't know if this is an issue, but if I were doing it, the trunks between routers and switches would have nothing but VLAN tagged traffic - no untagged traffic. That's how I'm doing it at home with my three routers and five switches.
by k6ccc
Tue Jul 31, 2018 7:01 pm
Forum: Announcements
Topic: SwOS version 2.8 released!
Replies: 37
Views: 19923

Re: SwOS version 2.8 released!

CRS+CSS: How many ports can be aggregated concurrently with LACP at maximum? Suggestion. If you are going to ask a question that is totally unrelated to the current topic, start a new post rather than ask in an unrelated thread. For one thing it makes finding the question and answer far easier when...
by k6ccc
Thu Jul 26, 2018 5:37 pm
Forum: SwOS
Topic: Possible bug in stats for SwOS 2.0 in CSS326 ? [SOLVED]
Replies: 10
Views: 4245

Re: Possible bug in stats for SwOS 2.0 in CSS326 ? [SOLVED]

Happy I could help.
by k6ccc
Thu Jul 26, 2018 12:30 am
Forum: Announcements
Topic: SwOS version 2.8 released!
Replies: 37
Views: 19923

Re: SwOS version 2.8 released!

For me manual upgrade don't work. I only see "don't interrupt", switch reboted (I see it uptime on router in neigbord) Are you sure? I did take the time to do a manual update on my CSS106-5G-1S. Prior to the upgrade, I started a continuous ping to the switch from this PC. After starting the upgrade...
by k6ccc
Thu Jul 26, 2018 12:11 am
Forum: Announcements
Topic: SwOS version 2.8 released!
Replies: 37
Views: 19923

Re: SwOS version 2.8 released!

None of my switches see it as an available upgrade. Have not the time at the moment to try a manual upgrade yet.
by k6ccc
Thu Jul 26, 2018 12:06 am
Forum: SwOS
Topic: Possible bug in stats for SwOS 2.0 in CSS326 ? [SOLVED]
Replies: 10
Views: 4245

Re: Possible bug in stats for SwOS 2.0 in CSS326 ? [SOLVED]

SwitchOS 2.7 and below used 32 bits for the stats. Real easy to roll over. VERY likely what you are seeing. According to the release notes for 2.8 (just released) one of the changes:
*) use 64bit counters under Stats tab for byte accounting;
by k6ccc
Wed Jul 25, 2018 2:12 am
Forum: General
Topic: Calling all Mikrotik Switch experts
Replies: 7
Views: 989

Re: Calling all Mikrotik Switch experts

I would also say I am not an expert, but I have several and they are in daily production use. First one I got was a RB260GS. Depend on time of year, it has somewhere between three and all six ports in use (the sfp is an electrical gigabit interface). It is out in a brick column in my front yard so i...
by k6ccc
Tue Jul 24, 2018 10:49 pm
Forum: Beginner Basics
Topic: VLAN segregation and bridge setting [SOLVED]
Replies: 15
Views: 1861

Re: VLAN segregation and bridge setting [SOLVED]

Thanks mkx. That was what I thought...
by k6ccc
Tue Jul 24, 2018 8:44 pm
Forum: Beginner Basics
Topic: VLAN segregation and bridge setting [SOLVED]
Replies: 15
Views: 1861

Re: VLAN segregation and bridge setting [SOLVED]

Kind of related to this. In my case, both of my routers are used EXCLUSIVELY for routing. Each physical port is either a trunk carrying multiple VLANs to a smart switch, or a specific LAN that is going to a switch. Never does the same LAN appear on more than one physical port. Is there any reason un...
by k6ccc
Thu Jul 19, 2018 7:41 am
Forum: Beginner Basics
Topic: Why in MT everything, including VLANs can always access each other unless blocked by firewall? [SOLVED]
Replies: 14
Views: 1861

Re: Why in MT everything, including VLANs can always access each other unless blocked by firewall? [SOLVED]

Depends on what you are trying to accomplish. I fully admit that this is not normal, but I have 15 VLANs at my house. With the exception of a few select situations, none of them talk to each other. I also have two active routers, and four switches (all smart devices) - then a microwave path 4.2 mile...
by k6ccc
Wed Jul 18, 2018 4:18 pm
Forum: General
Topic: Restore corrupted Routerboard with damaged Eth1
Replies: 6
Views: 1365

Re: Restore corrupted Routerboard with damaged Eth1

Throw away the RB, if it has been hit by a thunderstrike there's no software update that could solve the problem. P.S. if you update from version 5 to 6 you have to upgrade to bugfix version of 6, for example 5.25 check for updates makes download 6.40.8 bugfix. Please read my post. The Routerboard ...
by k6ccc
Wed Jul 18, 2018 8:07 am
Forum: Beginner Basics
Topic: Why in MT everything, including VLANs can always access each other unless blocked by firewall? [SOLVED]
Replies: 14
Views: 1861

Re: Why in MT everything, including VLANs can always access each other unless blocked by firewall? [SOLVED]

Yes, the basic firewall configuration is that all is allowed unless specifically blocked by firewall. It's a router - it routes. The normal way to set it up is to explicitly allow what you want and then at the end of each chain, drop everything. That way only the traffic that you allow will get thro...
by k6ccc
Tue Jul 17, 2018 5:30 am
Forum: Beginner Basics
Topic: IP Outside the IP Pool
Replies: 9
Views: 913

Re: IP Outside the IP Pool

Did what you suggest, what happens is when I changed it to desired static ip outside the pool, the status is waiting. The machine itself didn't acquire the assigned IP I put. Remember that the machine in question does not get a new address as soon as you change it't static reservation. It has no wa...
by k6ccc
Mon Jul 16, 2018 6:17 am
Forum: General
Topic: SSH or SNMP , How to get UBNT AF capacity and send it through Mikrotik
Replies: 9
Views: 920

Re: SSH or SNMP , How to get UBNT AF capacity and send it through Mikrotik

Are you asking if the router can send a command to the AirFiber and then do something with the result?
by k6ccc
Mon Jul 16, 2018 5:57 am
Forum: General
Topic: SSH or SNMP , How to get UBNT AF capacity and send it through Mikrotik
Replies: 9
Views: 920

Re: SSH or SNMP , How to get UBNT AF capacity and send it through Mikrotik

Maybe I'm not understanding your request. How does the MikroTik have anything to do with the AirFiber (other than presumably riding on the ethernet path that the Air Fiber provides)?
by k6ccc
Mon Jul 16, 2018 5:38 am
Forum: General
Topic: SSH or SNMP , How to get UBNT AF capacity and send it through Mikrotik
Replies: 9
Views: 920

Re: SSH or SNMP , How to get UBNT AF capacity and send it through Mikrotik

I think you need to be asking that on a Ubiquiti forum - not here.
by k6ccc
Mon Jul 16, 2018 1:04 am
Forum: Beginner Basics
Topic: Script to reduce Wi-Fi transmitter power on schedule/at night
Replies: 34
Views: 4336

Re: Script to reduce Wi-Fi transmitter power on schedule/at night

even if someone sleeps only 1 meter away from the router?

If you're really worried that much, move the router a bit, but even at a foot or two, it's really a non-issue.
by k6ccc
Sun Jul 15, 2018 9:43 pm
Forum: Beginner Basics
Topic: Script to reduce Wi-Fi transmitter power on schedule/at night
Replies: 34
Views: 4336

Re: Script to reduce Wi-Fi transmitter power on schedule/at night

Hey,
The goal is to reduce the emf emf radiation as the router is in a bed room.

Unless you are sleeping with your head laying on the antenna, that is a complete non issue.
Don't worry about it.
by k6ccc
Wed Jun 13, 2018 8:19 pm
Forum: General
Topic: MT Router honeypot.
Replies: 20
Views: 2837

Re: MT Router honeypot.

I see your firewall rule adds any IP to the bad list. So I am now on your bad list - ha ha ha
Entertaining...
by k6ccc
Thu Jun 07, 2018 5:45 am
Forum: SwOS
Topic: CSS326-24G-2S partial lockup issue
Replies: 1
Views: 1988

Re: CSS326-24G-2S partial lockup issue

Anything?
Still happening.
by k6ccc
Mon May 28, 2018 1:13 am
Forum: SwOS
Topic: SWOS 2.7 Uptime?
Replies: 3
Views: 2530

Re: SWOS 2.7 Uptime?

No, NOT 1.17 or lower, I know it's on that. The newer hardware RB260GS on SWOS 2.7. Where is the uptime on there? It seems it's gone missing from the web pages for some odd reason. I can only see it shown in a neighbor view from another Mikrotik device. RB260GS.jpg Looks like it depends on which sw...
by k6ccc
Sun May 27, 2018 9:32 am
Forum: SwOS
Topic: SWOS 2.7 Uptime?
Replies: 3
Views: 2530

Re: SWOS 2.7 Uptime?

System tab, General section, last line.
by k6ccc
Fri May 25, 2018 11:09 pm
Forum: General
Topic: Mikrotik bricked by backup, reset button not working anymore
Replies: 25
Views: 5873

Re: Mikrotik bricked by backup, reset button not working anymore

Q1: Can a backup completely brick the router? Q2: What can I do next to unbrick it? 1) If the file got corrupted it certainly could. 2) You already answered that one yourself - Netinstall Assuming that this is the SAME ROUTER, If you have another backup file, try it after the Netinstall. If it's a ...
by k6ccc
Fri May 25, 2018 6:57 pm
Forum: General
Topic: [Security] Attackers changed DNS servers
Replies: 8
Views: 5670

Re: [Security] Attackers changed DNS servers

Simple answer - upgrade to the current release.

Took me about 3 seconds to find it in the Announcements section:
viewtopic.php?f=21&t=133533
by k6ccc
Wed May 23, 2018 10:28 pm
Forum: SwOS
Topic: CRS-317 - Does SWoS have a physical advantage over RouterOS
Replies: 7
Views: 6800

Re: CRS-317 - Does SWoS have a physical advantage over RouterOS

I’m my general opinion, you want a router, buy a router; if you want a switch, buy a switch. In this case, use the OS that applies with the same principle. On my three routers at home, the closest I get to having any of them function as a switch is to use VLANs to get more LANs onto a finite number ...
  • 1
  • 2