Community discussions

Search found 474 matches

  • 1
  • 2
by k6ccc
Mon Sep 16, 2019 5:34 pm
Forum: Beginner Basics
Topic: Link Router and Switch and administrate together with WinBox
Replies: 5
Views: 335

Re: Link Router and Switch and administrate together with WinBox

What you are asking about is very similar to what I am doing. The only difference is that I am using my routers (a RB750r2 and a RB750Gr3) exclusively as routers - no switching at all. Each LAN or VLAN has only one port on the router (may be a dedicated LAN port, or may be a VLAN trunk port). All th...
by k6ccc
Sun Sep 15, 2019 5:48 am
Forum: Beginner Basics
Topic: Using RouterOS as a switch
Replies: 5
Views: 776

Re: Using RouterOS as a switch

Amm0 is correct. Essentially what I currently have is what dadoremix suggested. While that does allow VLAN 2 to communicate between ports 2 - 5, but that does not allow for the additional parts of the plan. I will be working with Amm0's suggestions shortly.

Thanks
by k6ccc
Sat Sep 14, 2019 11:47 pm
Forum: Beginner Basics
Topic: Using RouterOS as a switch
Replies: 5
Views: 776

Re: Using RouterOS as a switch

Thanks for the reply. I had assumed that I needed to build a bridge, and played with that last night for a couple hours without any success. I can see the traffic coming in from the three AREDN nodes with Torch, but nothing going out. I'm sure it's easy for most people that have used a bridge in ROS...
by k6ccc
Fri Sep 13, 2019 9:02 pm
Forum: Beginner Basics
Topic: Using RouterOS as a switch
Replies: 5
Views: 776

Using RouterOS as a switch

This is likely an easy one, but I have EXCLUSIVELY used Mikrotik routers as routers and never as a switch. Each LAN or VLAN on the routers connects directly to a CSS326 switch. I have run into a situation where I have run out of ports on one of my CSS326 switches and have an immediate need for a cou...
by k6ccc
Wed Sep 11, 2019 6:02 pm
Forum: Beginner Basics
Topic: How to enable Webfig access from internet?
Replies: 7
Views: 489

Re: How to enable Webfig access from internet?

Also, HIGHLY recommend putting some additional security on it. There are several things that can be done if you really insist on having a WebFig port directly accessed from the internet. For example, if able, restrict the source IPs that can access it to only the IPs that you want to have access. Fo...
by k6ccc
Fri Aug 30, 2019 6:09 am
Forum: General
Topic: Anyone can check the login webpage hotspot from attack codes!
Replies: 10
Views: 960

Re: Anyone can check the login webpage hotspot from attack codes!

I don't think this forum has a lot of professional web developers But it is impossible for users or designers Hotspot service does not know in the topics of page security! This is a forum for routers. Why are you even asking for html configuration help here? Take this to a forum for web designers. ...
by k6ccc
Thu Aug 29, 2019 2:37 am
Forum: Announcements
Topic: v6.45.5 [stable] is released!
Replies: 54
Views: 14760

Re: v6.45.5 [stable] is released!

I note that both alibloke and the chart that elbob2002 posted show the temperature stabilized at 58 degrees C. Makes me think that is what it is designed to do. I don't know what the specs for the CPU chips involved are, but as a comparison, the Raspberry Pi does not start throttling to control heat...
by k6ccc
Sun Aug 25, 2019 10:27 pm
Forum: Beginner Basics
Topic: Alternate DNS for one domain
Replies: 4
Views: 421

Re: Alternate DNS for one domain

RouterOS does not support this method of working. It has been requested many times but it has not been implemented. (what you need is the capability to set a static DNS record for local.mesh with type NS and pointing to the nameserver for that domain) That is exactly correct. As RouterOS also does ...
by k6ccc
Sun Aug 25, 2019 9:27 am
Forum: Beginner Basics
Topic: Alternate DNS for one domain
Replies: 4
Views: 421

Alternate DNS for one domain

Here is my situation. I have an RB-750Gr3 that has a WAN connection from my cable provider which provides DHCP and DNS services to the router. Ports 2, 3, & 5 are various LANs, and port 4 is a trunked port with several more VLANS. The trunked port connects to a managed switch where VLAN 5 (among oth...
by k6ccc
Fri Aug 23, 2019 7:55 am
Forum: General
Topic: New RB450G☓4 Breaks Google and its Services (Solved)
Replies: 13
Views: 1060

Re: New RB450G☓4 Breaks Google and its Services

Posting part of settings is not all that helpful.
/export config hide-sensitive file=yourconfigaug22
What am I doing wrong...see image below!

Screen Shot 2019-08-22 at 10.02.49 PM.png
Delete the word "config"
In other words: /export hide-sensitive file=your-config-22-Aug
by k6ccc
Sat Aug 10, 2019 2:11 am
Forum: SwOS
Topic: CRS326: RouterOS or SwOS?
Replies: 2
Views: 578

Re: CRS326: RouterOS or SwOS?

A lot of that is personal preferences. I have a CRS326 that is being used exclusively as a managed switch. Other than about a half dozen VLANs, there is nothing fancy. I am running it under SwitchOS and always have. I also have two CSS326 switches - obviously running SwitchOS, plus two a CSS106-5G-1...
by k6ccc
Fri Aug 09, 2019 6:15 pm
Forum: Beginner Basics
Topic: Remote WoL
Replies: 8
Views: 772

Re: Remote WoL

If you can access the router, you can either manually send the WOL command or type up a script and execute the script. By creating a scrpt in advance, you don't have to know the MAC of the target device. add dont-require-permissions=no name="Boot Old Family room PC on .101" owner=\ SuperMgr policy=t...
by k6ccc
Fri Aug 09, 2019 6:05 pm
Forum: Beginner Basics
Topic: Access wan from lan
Replies: 1
Views: 280

Re: Access wan from lan

Search for "hairpin nat".
by k6ccc
Thu Jul 25, 2019 6:16 pm
Forum: SwOS
Topic: Forwarding Problem CRS317-1G-16S+RM
Replies: 1
Views: 385

Re: Forwarding Problem CRS317-1G-16S+RM

Stefan, what software version?
by k6ccc
Thu Jul 25, 2019 6:13 pm
Forum: General
Topic: Firewall filter when port forwarded
Replies: 4
Views: 476

Re: Firewall filter when port forwarded

On this - add chain=forward action=accept in-interface=WAN \ connection-state=new nat-connection-state=dst nat Does/should the connection state need to be new? Or does it matter? It actually does not matter. Because there is a fastrack accept for established and related packets, the only time that ...
by k6ccc
Tue Jun 25, 2019 12:28 am
Forum: General
Topic: PoE 802.3 on two pair cable with CRS328-24P-4S+RM
Replies: 1
Views: 164

Re: PoE 802.3 on two pair cable with CRS328-24P-4S+RM

From the product page for the CRS328-24P-4S+RM:
PoE-Out is passed over mode B pins (4,5+)(7,8-).
That won't work on your 2 pair cable.
by k6ccc
Mon Jun 24, 2019 8:34 pm
Forum: General
Topic: Block Teamviewer
Replies: 24
Views: 17712

Re: Block Teamviewer

The very first rule in the Forward chain. Made it about as simple as I could: add action=passthrough chain=forward comment=\ "Counter for outbound to 188.172.217.0/24 - test for Teamviewer" \ connection-state="" dst-address=188.172.217.0/24 No connections listed to 188.172.217.xxx either.
by k6ccc
Mon Jun 24, 2019 6:02 pm
Forum: General
Topic: Block Teamviewer
Replies: 24
Views: 17712

Re: Block Teamviewer

So I did some digging and saw that TeamViewer Connect to a domain, 188.172.217.0/24 To test that, I created a passthrough firewall rule as a counter as the first rule in my forward chain. Any traffic to 188.172.217.0/24 should show up in the counter. There are two computers inside my firewall that ...
by k6ccc
Fri Jun 21, 2019 8:05 pm
Forum: General
Topic: Block Teamviewer
Replies: 24
Views: 17712

Re: Block Teamviewer

I would love to be able to block TeamViewer - but my situation is a little different. In my case, I am the TeamViewer user, but I want to be able to block TeamViewer unless I specifically allow it at the time - for example with a port knock to the router. For example, the computer at home can't norm...
by k6ccc
Thu Jun 20, 2019 1:48 am
Forum: SwOS
Topic: RB260 speed falls do 100M
Replies: 7
Views: 739

Re: RB260 speed falls do 100M

I'm sorry, but I thought it was simple to understand that the two RB260 Ether1 are connected together with a 50cm patch cable, so where is the cable problem? It was not simple to understand because you did not tell that in your original post. For all we know, you were trying to run gigabit over a k...
by k6ccc
Fri Jun 14, 2019 5:56 pm
Forum: Beginner Basics
Topic: CCR1016-12S-1S+ CPU 100% Every Day
Replies: 2
Views: 284

Re: CCR1016-12S-1S+ CPU 100% Every Day

You have given us almost no information to work with. What is this device doing? What's connected to it? How is it being used? Post your configuration.
by k6ccc
Thu Jun 13, 2019 7:09 pm
Forum: SwOS
Topic: CSS106 (RB260) VLANs between multiples swicthes and Hybrid port [SOLVED]
Replies: 3
Views: 903

Re: CSS106 (RB260) VLANs between multiples swicthes and Hybrid port [SOLVED]

I just wish that Mikrotik would standardize the interface between the different switches. I have one RB260, one CSS106, one CRS326 (running SwitchOS), and two CSS326s and it's annoying that the UI is so different between them.
by k6ccc
Sat Jun 08, 2019 7:19 am
Forum: Beginner Basics
Topic: DHCP reservation in or out of Pool/Scope?
Replies: 7
Views: 488

Re: DHCP reservation in or out of Pool/Scope?

I'm the same as all the rest here. All known DHCP clients are given a DHCP reservation outside of the IP Pool. Most of the pools are only 10 IPs (and in reality, I could normally get away with one or two).
by k6ccc
Fri Jun 07, 2019 4:53 pm
Forum: General
Topic: Time Based firewaal rules
Replies: 12
Views: 645

Re: Time Based firewaal rules

I figured it out!! You have to specify the time and day or days that you want the rule to be applied and then you have to press reset all counters to reset everything and allow the new rule to be applied. I checked it 3-4 times and it worked fine. Thank you all!!!! I definitely did not have to rese...
by k6ccc
Fri Jun 07, 2019 12:55 am
Forum: SwOS
Topic: Do CRS305&309 support other brands' RJ45 SFP module?
Replies: 3
Views: 681

Re: Do CRS305&309 support other brands' RJ45 SFP module?

Simple solution. I buy the Mikrotik SFPs that are specified to work with the device.
by k6ccc
Fri Jun 07, 2019 12:18 am
Forum: General
Topic: Time Based firewaal rules
Replies: 12
Views: 645

Re: Time Based firewaal rules

I have never had any time based firewall rules, but because of this thread, I created one for a test. The rule was a simple rule to drop all ICMP packets from the internet at the beginning of my Input chain with no time restriction. I am not at the location of this router, so my access is only via t...
by k6ccc
Thu Jun 06, 2019 7:30 am
Forum: SwOS
Topic: CRS326 Port security
Replies: 3
Views: 482

Re: CRS326 Port security

Never used a bridge, so can't help you there. However your firewall rules look OK - I think.
by k6ccc
Wed Jun 05, 2019 8:05 pm
Forum: SwOS
Topic: CRS326 Port security
Replies: 3
Views: 482

Re: CRS326 Port security

Off hand, I don't see a way to specify a MAC on a specific port, but you can enable port lock which locks the port to the first MAC that is connected. See the Forwarding tab.
by k6ccc
Mon Jun 03, 2019 5:08 am
Forum: SwOS
Topic: I am confused with Port Isolation on CSS326-24G Switch [SOLVED]
Replies: 5
Views: 781

Re: I am confused with Port Isolation on CSS326-24G Switch [SOLVED]

The check marks are the ports that the CAN be communicated with. For example, in your screen capture, port 1 can communicate with all other ports.
by k6ccc
Mon May 27, 2019 8:52 pm
Forum: SwOS
Topic: Difficulty with configuring CSS106-1G-4P-1S
Replies: 2
Views: 521

Re: Difficulty with configuring CSS106-1G-4P-1S

I still could not read your screen captures, but here are a couple of mine. Ports one and two are doing exactly what you want to do. Each of those is a Multi-SSID WiFi access point. Each is getting several VLANs that will each become a different SSID and also an untagged LAN that is used for cloud m...
by k6ccc
Mon May 27, 2019 7:29 pm
Forum: SwOS
Topic: Difficulty with configuring CSS106-1G-4P-1S
Replies: 2
Views: 521

Re: Difficulty with configuring CSS106-1G-4P-1S

I can’t read your images on my $&@#% iPhone, but I am doing exactly what you want to do on my CSS106. When I get to a computer, I’ll take a look.



Sent from a $&@#% iPhone using Tapatalk
by k6ccc
Sun May 26, 2019 4:57 am
Forum: Beginner Basics
Topic: RB750: firmware upgrade or not?
Replies: 5
Views: 579

Re: RB750: firmware upgrade or not?

I always upgrade mine.
by k6ccc
Wed May 22, 2019 6:00 pm
Forum: General
Topic: CRS328-24P-4S+ Speed issue
Replies: 2
Views: 198

Re: CRS328-24P-4S+ Speed issue

It might be interesting to connect the two computers in question directly to each other. I would speculate that what you are seeing is more related to the performance of the computers involved and not the switches. Part of that statement is the difference in performance between upload and download. ...
by k6ccc
Mon May 20, 2019 12:30 am
Forum: General
Topic: USB port + HUB summary amperage
Replies: 3
Views: 232

Re: USB port + HUB summary amperage

Powered USB hubs usually don't draw power from upstream USB port ...
Correct. That's why I recommend them for fixed applications. Has solved many problems over the years.
by k6ccc
Sun May 19, 2019 10:15 pm
Forum: General
Topic: USB port + HUB summary amperage
Replies: 3
Views: 232

Re: USB port + HUB summary amperage

I don't have an answer to your specific question, but my general recommendation is any time you are using a USB hub in a fixed situation, use a powered hub. That solves the current limit issue. Since you are proposing to use a USB hub connected to a router, I assume it will be in a fixed installatio...
by k6ccc
Sun May 19, 2019 9:51 pm
Forum: SwOS
Topic: SWOS or ROUTEROS: Confused
Replies: 3
Views: 611

Re: SWOS or ROUTEROS: Confused

This is likely more opinion rather than hard facts. There are some on the forum that hate SwitchOS and have nothing but problems, and there are some that have no issues with SwitchOS at all. Personally I am in the second camp. I have a CRS326-24G-2S, two CSS326-24G-2S, a CSS106-5G-1S, and a RB260GS ...
by k6ccc
Wed May 15, 2019 5:30 pm
Forum: Beginner Basics
Topic: Open all ports on all devises [SOLVED]
Replies: 6
Views: 511

Re: Open all ports on all devises [SOLVED]

I clearly have no understanding of what he is trying to do. However I have never had any interest in on line gaming, so no idea how those kind of things work. I've never heard of a client / server type system where the server initiates the connection (which is why normal consumer routers work for mo...
by k6ccc
Wed May 15, 2019 5:21 am
Forum: Beginner Basics
Topic: Open all ports on all devises [SOLVED]
Replies: 6
Views: 511

Re: Open all ports on all devises [SOLVED]

It does not work that way. A NAT forwards to a target IP. However in most situations, if the game is talking to a server somewhere else, the client initiates the connection and the router will forward responses to the IP that originated the request. No special setup is normally required. If you are ...
by k6ccc
Mon May 13, 2019 4:02 pm
Forum: Beginner Basics
Topic: Open all ports on all devises [SOLVED]
Replies: 6
Views: 511

Re: Open all ports on all devises [SOLVED]

You have given us so little information to go on. For starters, either give us more details on how your three routers are connected to each other, the internet, and your devices - or better yet, a drawing. Second, export your config on all three routers and post here so we can see what you are doing...
by k6ccc
Thu May 09, 2019 12:01 am
Forum: Beginner Basics
Topic: DhCP server for each port
Replies: 11
Views: 602

Re: DhCP server for each port

I see mkx beat me to the L2 vs L3 parts, so I'm not going to repeat that. You do not need to use bridges to create a DHCP server. However as noted above, IF an interface is a member of a bridge, then the DHCP server must be assigned to the Bridge - not the member interfaces. At least that's the way ...
by k6ccc
Wed May 08, 2019 5:25 pm
Forum: Beginner Basics
Topic: DhCP server for each port
Replies: 11
Views: 602

Re: DhCP server for each port

Let's see if I have this right. Every single port will be a separate LAN with it's own DHCP server. So the router is being used exclusively as a router and not as a switch. If this is the case, why are you creating bridges? This is the way I use my routers. I have managed switches connected to the r...
by k6ccc
Fri May 03, 2019 8:35 pm
Forum: Beginner Basics
Topic: Share WiFi and LAN DHCP
Replies: 2
Views: 220

Re: Share WiFi and LAN DHCP

I don't know anything about the TP Link equipment, but it sounds like you want the TP Link to operate only as a WiFi access point and NOT have any router functions. You likely can make this work by turning off the DHCP server functionality in the TP Link and then connecting one of the LAN ports (NOT...
by k6ccc
Thu May 02, 2019 3:36 pm
Forum: SwOS
Topic: CSS326-24G slow inter-VLAN transfers
Replies: 3
Views: 634

Re: CSS326-24G slow inter-VLAN transfers

You asked this question in the SwitchOS section of the forum and your subject specifies the CSS326 switch. However, since you are seeing an inter-VLAN issue, the problem almost certainly exists in the router and not the switch - since switches don’t route between VLANs. You did not give us much deta...
by k6ccc
Wed May 01, 2019 5:16 pm
Forum: SwOS
Topic: Mikrotik CSS326-24G VLANS [SOLVED]
Replies: 8
Views: 916

Re: Mikrotik CSS326-24G VLANS [SOLVED]

As for your DHCP servers, from your drawing, they are some device that is untagged. Simply put them on a switch port that is untagged on the correct VLAN. Same concept as my Cable Modem on port 1. In my case that is untagged on VLAN 100, but the concept is the same.
by k6ccc
Sat Apr 27, 2019 3:40 am
Forum: SwOS
Topic: Problems with S+RJ10
Replies: 9
Views: 1321

Re: Problems with S+RJ10

My first question is if the issue it with the SFP or the Ethernet per in the computer - it could be either one. Can you plug the Cat-6 into another port on the switch (such as one of the gig-E ports on the switch). Let the computer go to sleep and see if the problem happens in that configuration. Ot...
by k6ccc
Thu Apr 25, 2019 12:12 am
Forum: SwOS
Topic: Mikrotik CSS326-24G VLANS [SOLVED]
Replies: 8
Views: 916

Re: Mikrotik CSS326-24G VLANS [SOLVED]

Here are some screen captures from one of CSS326 switches located in my family room. Most of the ports don't really matter, but I will point out a few. Along with a bunch of end devices in the house, both internet modems connect to this switch (port 1 for the cable and port 9 for the DSL). Port 3 is...
by k6ccc
Wed Apr 24, 2019 5:33 pm
Forum: SwOS
Topic: Mikrotik CSS326-24G VLANS [SOLVED]
Replies: 8
Views: 916

Re: Mikrotik CSS326-24G VLANS [SOLVED]

One other thing you could easily test. Configure a user PC port to VLAN 20 instead of VLAN 10 and confirm that the PC gets a DHCP address from DHCP server 2. That will confirm that your DHCP and switch to switch links are OK. Part two - Are you sure that your WiFi APs are configured properly for the...
by k6ccc
Wed Apr 24, 2019 5:28 pm
Forum: SwOS
Topic: Mikrotik CSS326-24G VLANS [SOLVED]
Replies: 8
Views: 916

Re: Mikrotik CSS326-24G VLANS [SOLVED]

Your configuration is really pretty simple. The trunks between the three switches needs to have VLANs 10 & 20. Assuming that the WiFi APs know that SSID 1 connects to VLAN 10 and SSID 2 connects to VLAN 20, then the switch ports connected to the three Unifi APs will be just like the switch to switch...
by k6ccc
Tue Apr 23, 2019 7:10 am
Forum: General
Topic: Port Knocking, avoid scan-caused false positives?
Replies: 17
Views: 875

Re: Port Knocking, avoid scan-caused false positives?

Why not just a set of firewall rules to catch port scanners. Those are well documented and work well. If the port scanner triggers, then the port knock never sees the triggers.
by k6ccc
Sun Apr 21, 2019 3:30 am
Forum: Beginner Basics
Topic: RouterOS - NAT problem (dst-nat)
Replies: 23
Views: 1181

Re: RouterOS - NAT problem (dst-nat)

First guess is that you did not open a hole in the firewall for your NAT. Unlike many consumer routers, RouterOS does not do that automatically.
by k6ccc
Fri Apr 19, 2019 7:50 pm
Forum: Beginner Basics
Topic: Multiple VLANs with one Router as Default Gateway in each VLAN
Replies: 7
Views: 776

Re: Multiple VLANs with one Router as Default Gateway in each VLAN

What you are doing is very similar to what I am doing and it's not at all complicated. I am curious why you want two VLANs if part of your statement is that devices on one VLAN can communicate with devices on the other VLAN. If everything on both VLANs can communicate with each other, why separate t...
by k6ccc
Fri Apr 19, 2019 6:44 pm
Forum: Beginner Basics
Topic: wyze cam port forwarding
Replies: 8
Views: 1061

Re: wyze cam port forwarding

I can absolutely assure you that the Wyze cameras do NOT require anything "special" to be opened on a reasonably normal router configuration. As long as a LAN device can get to the internet and responses get back to it, it will connect just fine. I have 13 Wyze cameras (2 Pans and 11 V2). Other than...
by k6ccc
Tue Apr 16, 2019 4:19 pm
Forum: Beginner Basics
Topic: One website blocked
Replies: 4
Views: 352

Re: One website blocked

First of all, you are right - they don't respond to a ping. However that proves absolutely nothing since some network admins drop pings as some people consider it a security hole. If it really is on your end, please post your config, so we can see what you have. In order to export your config, follo...
by k6ccc
Mon Apr 15, 2019 5:25 pm
Forum: Beginner Basics
Topic: VLAN with multiple switches
Replies: 6
Views: 586

Re: VLAN with multiple switches

I'm going to let someone else answer the setup in RouterOS as I have NEVER used a bridge in ROS. I know there are some particulars about setting up VLANs in a bridge, but I don't know details.
by k6ccc
Thu Apr 11, 2019 9:32 pm
Forum: Beginner Basics
Topic: VLAN with multiple switches
Replies: 6
Views: 586

Re: VLAN with multiple switches

SwitchOS is strictly a switching OS whereas RouterOS is router OS that can play switch (but is optimized as a router). SwitchOS is far more limited, but if you only need switching, it works. There are a couple documented issues with the current version of SwitchOS - check out the SwitchOS section of...
by k6ccc
Thu Apr 11, 2019 12:50 am
Forum: Beginner Basics
Topic: VLAN with multiple switches
Replies: 6
Views: 586

Re: VLAN with multiple switches

I think sebus got your config incorrect. Please confirm that the CCR1009 has one link to the CRS125 and one link to the CRS326 (not that the two switches are daisy chained). Second, are you running the CRS125 and CRS326 in RouterOS or SwitchOS? What you are doing is easy, but we better need to under...
by k6ccc
Sat Apr 06, 2019 5:09 am
Forum: Beginner Basics
Topic: How to go back to dynamic IP in DHCP server [SOLVED]
Replies: 7
Views: 514

Re: How to go back to dynamic IP in DHCP server [SOLVED]

Just delete the lease and next time the device requests an address, it will get one from the regular pool.
by k6ccc
Thu Apr 04, 2019 6:33 pm
Forum: General
Topic: WAN Notifications
Replies: 6
Views: 405

Re: WAN Notifications

I was not suggesting that you monitor it for them, but rather that they set up a free account with UpTimeRobot.com and UTR will notify them when something fails.
by k6ccc
Wed Apr 03, 2019 5:46 pm
Forum: General
Topic: How to configure 4 Up-Links on same WAN with 4 vLANs
Replies: 12
Views: 633

Re: How to configure 4 Up-Links on same WAN with 4 vLANs

Yes. add action=src-nat chain=srcnat comment="Outgoing NAT from .201 LAN" \ disabled=no out-interface=E1-p10_DSL_Internet src-address=\ 192.168.201.0/24 to-addresses=208.127.104.77 add action=src-nat chain=srcnat comment="Outgoing NAT from .202 LAN" \ disabled=no out-interface=E1-p10_DSL_Internet sr...
by k6ccc
Wed Apr 03, 2019 1:04 am
Forum: General
Topic: How to configure 4 Up-Links on same WAN with 4 vLANs
Replies: 12
Views: 633

Re: How to configure 4 Up-Links on same WAN with 4 vLANs

@ivanobuffa
They were all part of a /24 network from my IP. I had eight addresses scattered through the range.
I will pull up my script later this evening. It was quite easy...
by k6ccc
Tue Apr 02, 2019 10:46 pm
Forum: SwOS
Topic: Unable to update firmware CSS 326-24G-2S+RM
Replies: 4
Views: 778

Re: Unable to update firmware CSS 326-24G-2S+RM

Does the switch have internet connectivity ?



Sent from a $&@#% iPhone using Tapatalk
by k6ccc
Tue Apr 02, 2019 9:15 pm
Forum: General
Topic: How to configure 4 Up-Links on same WAN with 4 vLANs
Replies: 12
Views: 633

Re: How to configure 4 Up-Links on same WAN with 4 vLANs

@k6ccc So are you like a suburb of LA? Seems like your on the cusp of Mountains, must be beautiful and close to ski hills? (prevalent raging forest fires in that area)? Correct. Glendora is about 20 miles east and slightly north of downtown Los Angeles. The city moto is "Pride of the Foothills". Th...
by k6ccc
Tue Apr 02, 2019 7:55 pm
Forum: General
Topic: How to configure 4 Up-Links on same WAN with 4 vLANs
Replies: 12
Views: 633

Re: How to configure 4 Up-Links on same WAN with 4 vLANs

I've been doing this for years. Until very recently my RB750r2 had one DSL connection with five static IPs. There were different LANs (mostly via VLAN) that each routed traffic out the same DSL, but via different IP addresses. All it takes is a simple outgoing NAT statement to get the outgoing traff...
by k6ccc
Tue Apr 02, 2019 4:45 am
Forum: General
Topic: WAN Notifications
Replies: 6
Views: 405

Re: WAN Notifications

There are two perspectives here. One is to have the router detect a failure and alert you. The other is to determine if the router is visible from the internet. For part two, I suggest UpTimeRobot.com They can monitor specific ports, a normal ping, a website, and various other things. They can notif...
by k6ccc
Sat Mar 30, 2019 4:43 am
Forum: Beginner Basics
Topic: Static DNS issues
Replies: 1
Views: 235

Re: Static DNS issues

Someone on the internet is trying to connect to presumably a web server on your internet address on port 8080. Why do you think this has anything to do with your DNS?
by k6ccc
Wed Mar 27, 2019 6:27 pm
Forum: Beginner Basics
Topic: Block traffic between VLAN
Replies: 8
Views: 529

Re: Block traffic between VLAN

Instead of explicitly blocking each VLAN, Block everything with a not interface command (note the explanation point before the interface name): add action=drop chain=forward comment=\ "Block all interfaces except internet from VLAN 10" out-interface=\ !E1-p10_DSL_Internet in-interface=VLAN_10 You wo...
by k6ccc
Tue Mar 26, 2019 7:47 pm
Forum: Beginner Basics
Topic: Firewall rule Order
Replies: 3
Views: 345

Re: Firewall rule Order

Allow what you specifically want allowed, then deny all. This is the last rule in the Forward chain. There is a similar one at the end of the Input chain.
add action=drop chain=forward comment=\
    "Drop any forward packets that get this far"
by k6ccc
Mon Mar 25, 2019 11:59 pm
Forum: SwOS
Topic: Can run OSPF on CRS326-24G-2S+RM
Replies: 4
Views: 624

Re: Can run OSPF on CRS326-24G-2S+RM

Yes you can. With RouterOS only though.
Hi, elbob2002. Do you mean I can run ospf in CRS326-24G-2S+RM only booted with RouterOS.
OSPF is a routing protocol. Requires a router. When run under SwitchOS, the CRS326 is functioning as a switch - not a router.
by k6ccc
Mon Mar 25, 2019 11:56 pm
Forum: SwOS
Topic: CRS328-24P-4S+ Link Downs, Port Isolation, FAN Error
Replies: 14
Views: 1836

Re: CRS328-24P-4S+ Link Downs, Port Isolation, FAN Error

This thread is an interesting read. I have two CSS326-24G-2S+RM and one CRS326-24G-2S+RM that got updated to 2.9 a few days ago. Obviously no fan issues since the 326 doesn't have fans. I have not observed any problems - so far (64 1/2 hours). I will be watching however... I'll laugh my ass off if M...
by k6ccc
Fri Mar 22, 2019 11:15 pm
Forum: SwOS
Topic: New managed switch
Replies: 1
Views: 546

Re: New managed switch

I'm using the CSS326-24G-2S+RM and CSS106-5G-1S for exactly that purpose. Quite happy with them.
by k6ccc
Fri Mar 22, 2019 10:56 pm
Forum: SwOS
Topic: Is possible to boot into ROS in CSS326-24G-2S+RM
Replies: 3
Views: 607

Re: Is possible to boot into ROS in CSS326-24G-2S+RM

OK, now on a PC with a real keyboard instead of my #$%&* iPhone, so able to give a longer answer... The CSS326-24G-2S+RM can only run SwitchOS, whereas the CRS326-24G-2S+RM can be setup to boot into either RouterOS or SwitchOS. When the CRS326-24G-2S+RM boots into RouterOS it has full router functio...
by k6ccc
Fri Mar 22, 2019 9:02 pm
Forum: SwOS
Topic: Is possible to boot into ROS in CSS326-24G-2S+RM
Replies: 3
Views: 607

Re: Is possible to boot into ROS in CSS326-24G-2S+RM

The CSS is SwitchOS only. The CRS is dual boot. In my opinion, if you need a switch, buy a switch - if you need a router, buy a router. I have five MT devices running Switch OS and very happy with them.



Sent from a $&@#% iPhone using Tapatalk
by k6ccc
Fri Mar 22, 2019 6:10 pm
Forum: Beginner Basics
Topic: Port forward on port 8080
Replies: 14
Views: 636

Re: Port forward on port 8080

There is something being missed here. Export your configuration and post it.
/export hide-sensitive
by k6ccc
Fri Mar 22, 2019 5:21 pm
Forum: Beginner Basics
Topic: Port forward on port 8080
Replies: 14
Views: 636

Re: Port forward on port 8080

Two thoughts. First, do your firewall rules allow the port forwarding? If you have an "all all DST-NAT" rule in the forward chain, that would take care of it, but if you don't do that, you generally need to specifically allow the forward. This is not likely the case since port forwarding worked on p...
by k6ccc
Mon Mar 18, 2019 6:38 am
Forum: Beginner Basics
Topic: Generate backup and send it by e-mail
Replies: 2
Views: 377

Re: Generate backup and send it by e-mail

I am doing exactly that. Here are the settings: First setup your E-Mail server information. I am using a G-Mail account. /tool e-mail set address=smtp.gmail.com from="Router #2" password=Redacted port=587 \ start-tls=yes user=address@gmail.com Then the script that creates the files and sends them: #...
by k6ccc
Thu Mar 14, 2019 11:32 pm
Forum: Beginner Basics
Topic: Help with PPPoE client setup
Replies: 2
Views: 245

Re: Help with PPPoE client setup

Assuming you have everything configured correctly on your managed switch, hooked to eth4 (DSL modem connected to access port for VLAN VID=200) it should work. And it shouldn't be necessary to have dial-on-demand=yes ... Yes, it is. Every VLAN shows up on that trunk port except 100 (the cable intern...
by k6ccc
Thu Mar 14, 2019 7:15 am
Forum: Beginner Basics
Topic: Help with PPPoE client setup
Replies: 2
Views: 245

Help with PPPoE client setup

OK, first a little background. I have a cable based internet and a DSL based internet. The cable is a single DHCP address and until today my DSL was eight static IP addresses that connect to three separate MT routers. Today, my DSL was changed to a single DHCP addresses with PPPoE (the change was fo...
by k6ccc
Tue Mar 12, 2019 12:36 am
Forum: Beginner Basics
Topic: ICMP Drop
Replies: 4
Views: 273

Re: ICMP Drop

You could use the "nth" filter option to drop every nth packet. so for 10% every 10 packet should be dropped.
Just learned something new. Did not even know that existed, but sure enough - it's there...
by k6ccc
Mon Mar 11, 2019 7:41 pm
Forum: Beginner Basics
Topic: ICMP Drop
Replies: 4
Views: 273

Re: ICMP Drop

Hello guys, it is possible to permit icmp but dropping 10 percentage of the packets ? As kiaunel said, I don't know of a way to drop a certain percentage of packets. However you can rate limit certain packets to some number. For example 5 packets per second. add action=accept chain=ICMP comment=\ "...
by k6ccc
Wed Mar 06, 2019 6:20 pm
Forum: SwOS
Topic: Overruns on CSS326-24G-2S+RM
Replies: 36
Views: 9016

Re: Overruns on CSS326-24G-2S+RM

But with 199 days uptime You are running 2.8, right? I upgraded from 2.8 to 2.9 (CSS326), and saw the increase in Rx Overrruns and Tx Pauses. They are too frequent to my liking, but I don't think they have a real impact on network speed. At least, not for me. Truth be told, although I use a 10GB tr...
by k6ccc
Wed Mar 06, 2019 4:45 pm
Forum: SwOS
Topic: Overruns on CSS326-24G-2S+RM
Replies: 36
Views: 9016

Re: Overruns on CSS326-24G-2S+RM

Not my experience. Just looked at one of mine which shows an uptime of 199 days. There is 1 RX Overrun and 0 TX pauses. As I said, nothing faster than 1Gb/s....
by k6ccc
Wed Mar 06, 2019 12:41 am
Forum: SwOS
Topic: Overruns on CSS326-24G-2S+RM
Replies: 36
Views: 9016

Re: Overruns on CSS326-24G-2S+RM

Same here! Lot of tx/rx overruns on 10G port (SFP+ to CRS317) or pauses when flow control is enabled. I'll wait till next SWoS release and if it is not fixed will throw away and will declare it as another cheap junk. You are welcome to send them to me. I have been very happy with my CRS326 (in SWOS...
by k6ccc
Fri Mar 01, 2019 10:21 pm
Forum: SwOS
Topic: Switch identity character length and possible? bug
Replies: 1
Views: 379

Re: Switch identity character length and possible? bug

I am having issues setting identity of RB260GS. I wanted to set: LOCATION - OFFICE - DEVICEn However, I get cut out, and SwOS version is added after the name. Is this normal, or a bug? Or maybe a browser thing? Tried to the switch, but it didn't work. I don’t remember for sure, but there is a limit...
by k6ccc
Fri Mar 01, 2019 7:43 am
Forum: General
Topic: Securing Mikrotik router using firewall rules causing issues. [SOLVED]
Replies: 21
Views: 1299

Re: Securing Mikrotik router using firewall rules causing issues. [SOLVED]

That Wiki post lists a large number of various rules and settings. Many of which need to be customized to your situation. Therefore, without you posting your configuration, we would only be guessing. Export and post your configuration.
by k6ccc
Wed Feb 13, 2019 5:18 pm
Forum: Beginner Basics
Topic: 100 mbps limit in p2p
Replies: 12
Views: 959

Re: 100 mbps limit in p2p

set [ find default-name=ether4 ] speed=100Mbps
You state you are connected on ether4 which you have locked to 100Mbps
by k6ccc
Wed Feb 13, 2019 4:40 pm
Forum: Scripting
Topic: HELP! My Static IP gets changes to Dynamic everyday automatically.
Replies: 10
Views: 781

Re: HELP! My Static IP gets changes to Dynamic everyday automatically.

Until you can find out who is messing with your router, you can also set the computer to a static IP, and then it never will look for a DHCP address at all.
But I agree with the others, you need to figure out who is changing your router configuration.
by k6ccc
Tue Feb 12, 2019 11:47 pm
Forum: Beginner Basics
Topic: hex lite (RB750r2) vs hex (RB750Gr3) for home network
Replies: 8
Views: 1107

Re: hex lite (RB750r2) vs hex (RB750Gr3) for home network

at the moment best router/price around 50-70euros is HAP AC 2. everything you need in this small magic box! it has also 2.4ghz/5ghz wifi. models you suggest dont have wifi. https://mikrotik.com/product/hap_ac2 If you need WiFi. I have WiFi, but it's not combined with my routers - nor would I want i...
by k6ccc
Tue Feb 12, 2019 9:37 pm
Forum: Beginner Basics
Topic: hex lite (RB750r2) vs hex (RB750Gr3) for home network
Replies: 8
Views: 1107

Re: hex lite (RB750r2) vs hex (RB750Gr3) for home network

I started out at my house with a RB750r2 and it worked fine for me - until I got cable based internet that supported 124 Mb/s download via a gigabit interface. Because of strange stuff I was doing, I had a ton of NAT forwarding, and firewall rules in place along with at least a half dozen VLANs and ...
by k6ccc
Tue Feb 12, 2019 5:57 am
Forum: Scripting
Topic: Dynu.com script for dynamic DNS
Replies: 4
Views: 3377

Re: Dynu.com script for dynamic DNS

I know this is a two year old thread, but I'm in the same boat. I added info log entries all over the place and remarked every line and ran the script. Obviously it ran fine with just the log full of the log entries. I then started at the top and removed the remarks one line at a time until it bombe...
by k6ccc
Mon Feb 04, 2019 10:28 pm
Forum: General
Topic: Basic Vlan setup on RB750hex and RB750
Replies: 2
Views: 280

Re: Basic Vlan setup on RB750hex and RB750

Like anav said, post your config or else we are guessing.. With that said, you said "the DHCP server". You need to configure a separate DHCP pool and server per VLAN. What you are doing with the RB750 (the one playing router) is somewhat similar to what I am doing with mine. Each of mine has one WAN...
by k6ccc
Sat Feb 02, 2019 11:11 pm
Forum: Beginner Basics
Topic: I need to set up my second static public IP for my mail server
Replies: 8
Views: 501

Re: I need to set up my second static public IP for my mail server

It looks like you are trying to do this in "Quick Set". Get out of Quick Set and NEVER touch it again. Quick Set is a fairly simple way to do a VERY basic setup for a MT router. Kinda like making it stupid like most "consumer" routers. If you are trying to do anything beyond the basics, you need to ...
by k6ccc
Sat Feb 02, 2019 5:20 am
Forum: Beginner Basics
Topic: I need to set up my second static public IP for my mail server
Replies: 8
Views: 501

Re: I need to set up my second static public IP for my mail server

Will the mail server be on the same LAN as the rest of your stuff at home or will be it be on a separate LAN? If it will be on a separate LAN, it's really easy.
by k6ccc
Fri Feb 01, 2019 1:16 am
Forum: General
Topic: DNS Flag Day
Replies: 3
Views: 543

Re: DNS Flag Day

Did you read the website briefly? There is no reason to worry if you are an Internet user without your own domain name. This change is affecting you only indirectly and you do not need to take any other steps. I did read it. I have three domains that run on my own server, but I get DNS from a comme...
by k6ccc
Thu Jan 31, 2019 11:09 pm
Forum: General
Topic: DNS Flag Day
Replies: 3
Views: 543

DNS Flag Day

For you experts out there, anything about this that I as a end user running MT routers to get to the internet need to do or look out for?
https://dnsflagday.net/
by k6ccc
Tue Jan 29, 2019 9:13 pm
Forum: Beginner Basics
Topic: Text based backup!!!cannot load [SOLVED]
Replies: 12
Views: 748

Re: Text based backup!!!cannot load [SOLVED]

I agreed with pe1chl. Even minor differences in router types are going to create issues that you will have to manually fix. A while ago, I replaced a RB750r2 with a RB750Gr3. Pretty close - you would thing it would be pretty seamless. Nope. Ended up importing in VERY small chunks in order to get it ...
by k6ccc
Mon Jan 28, 2019 9:27 am
Forum: Beginner Basics
Topic: block inter VLAN traffic
Replies: 17
Views: 1770

Re: block inter VLAN traffic

Just drop it? add action=drop chain=forward in-interface=vlan100 out-interface=vlan200 add action=drop chain=forward in-interface=vlan200 out-interface=vlan100 Thanks would this keep the internet access . Yes. And I would strongly suggest that you spend a while reading the firewall sections of the ...
by k6ccc
Wed Jan 16, 2019 6:29 pm
Forum: Announcements
Topic: SwOS version 2.9 released!
Replies: 72
Views: 24882

Re: SwOS version 2.9 released!

Updated my CSS106-5G-1S from 2.8 and all appears to be working. However, after the upgrade, this is what the Upgrade page says: Firmware Current Installed Version 2.9 (built at Mon Jan 07 2019 03:04:37 GMT-0800 (GMT-08:00)) Latest Available Version 2.9 (built at Mon Jan 14 2019 02:29:12 GMT-0800 (GM...
by k6ccc
Tue Jan 15, 2019 11:23 pm
Forum: SwOS
Topic: Can’t factory reset SwOS on CRS328-24P-4S+
Replies: 9
Views: 1358

Re: Can’t factory reset SwOS on CRS328-24P-4S+

You have to let WinBox sit on the neighbors tab for 5 to 10 minutes before the switches show up. By George, you are right. Took hours, but three of my five switches have appeared. The CSS106-5G-1S two CSS-326-24G-2S are showing but the RB-260GS and CRS326-24G-2S (running SwOS) along with my RG750Gr...
by k6ccc
Tue Jan 15, 2019 6:10 pm
Forum: SwOS
Topic: Can’t factory reset SwOS on CRS328-24P-4S+
Replies: 9
Views: 1358

Re: Can’t factory reset SwOS on CRS328-24P-4S+

A SwOS device will appear in the neighbor list in Winbox but you cannot connect to it using winbox. As I said, I'll have to take your word on that - None of my five MT switches are seen on the neighbor list on WinBox 3.18. I don't even see all of my MT routers in the neighbor list. I even confirmed...
by k6ccc
Tue Jan 15, 2019 6:41 am
Forum: SwOS
Topic: Can’t factory reset SwOS on CRS328-24P-4S+
Replies: 9
Views: 1358

Re: Can’t factory reset SwOS on CRS328-24P-4S+

I’ll take your word on it, but my WinBox does not see any of my switches.

Jim



Sent from a $&@#% iPhone using Tapatalk
by k6ccc
Sun Jan 13, 2019 5:26 am
Forum: SwOS
Topic: Can’t factory reset SwOS on CRS328-24P-4S+
Replies: 9
Views: 1358

Re: Can’t factory reset SwOS on CRS328-24P-4S+

First of all, once it is in SwitchOS, you can’t connect via WinBox. Must connect via the web interface.

As for your DHCP address, does your DHCP server show an address assigned?



Sent from a $&@#% iPhone using Tapatalk
by k6ccc
Thu Jan 03, 2019 7:38 am
Forum: SwOS
Topic: CSS326-24G-2S+RM hangs until power cycle
Replies: 19
Views: 2955

Re: CSS326-24G-2S+RM hangs until power cycle

Only time I have had one of CSS326 switches hang is when I had a problem DSL modem. The modem would crash, and after power cycling it, the switch would shortly lock up. Replaced the DSL modem after we determined that it was having a problem. Never had a problem with the switch since. Currently it is...
by k6ccc
Mon Dec 24, 2018 10:12 pm
Forum: Beginner Basics
Topic: Winbox disconnecting
Replies: 1
Views: 196

Re: Winbox disconnecting

Are you doing something? By that, I mean have you started making parameter changes? If yes, what are you changing? Also, what version of WinBox and RouterOS?
by k6ccc
Mon Dec 24, 2018 5:33 am
Forum: SwOS
Topic: CSS326-24G-2S+ does not accept dhcp-provided IP!?
Replies: 2
Views: 559

Re: CSS326-24G-2S+ does not accept dhcp-provided IP!?

The CSS326 runs SwitchOS and does not have a DHCP server. Although I normally run all of my switches with static IPs, I remember when I first got them and they factory defaulted to DHCP with fallback, the DHCP client worked. What is the setting of the Address Acquisition on the System tab? Also, wha...
by k6ccc
Thu Dec 20, 2018 11:32 pm
Forum: SwOS
Topic: CSS326-24G-2S - Where is WATCHDOG IP address to ping!!!???
Replies: 10
Views: 2381

Re: CSS326-24G-2S - Where is WATCHDOG IP address to ping!!!???

But if no one reports it as a bug, Mikrotik wont try to find it. Talking about here on a users forum does not constitute a trouble report.
by k6ccc
Mon Dec 17, 2018 12:21 am
Forum: Beginner Basics
Topic: Cloud Smart Switch 326-24G-2S+RM noise
Replies: 1
Views: 307

Re: Cloud Smart Switch 326-24G-2S+RM noise

I have two of them at home - one is a couple feet from me as I sit at my computer. There is a grill for a fan, but there isn't a fan mounted.
by k6ccc
Wed Dec 12, 2018 7:06 am
Forum: Beginner Basics
Topic: LAN and internet in the same public range /27
Replies: 10
Views: 757

Re: LAN and internet in the same public range /27

Why are you wanting to use the same IP range?
by k6ccc
Tue Dec 11, 2018 11:05 pm
Forum: SwOS
Topic: Possible bug in stats for SwOS 2.0 in CSS326 ? [SOLVED]
Replies: 10
Views: 1943

Re: Possible bug in stats for SwOS 2.0 in CSS326 ? [SOLVED]

Kennethven,
This thread is almost 5 months old. Who are you even directing that to? And there is no PM capability on this forum.
by k6ccc
Sat Nov 17, 2018 12:54 am
Forum: General
Topic: How to secure port on the switch?
Replies: 8
Views: 661

Re: How to secure port on the switch?

don't understand your question. Note that switches don't have macs only network devices.
Wow! I'm going to have to tell all my switches that they don't really have a MAC. That will be a shock to them. How do you suppose layer two works without a MAC?
by k6ccc
Sat Nov 17, 2018 12:44 am
Forum: Beginner Basics
Topic: Winbox problem
Replies: 2
Views: 503

Re: Winbox problem

You have the WinBox port set to a non-standard 8219. Are you specifying the non-standard port when you try to connect? BTW, I also use a non-standard port for WinBox access to my routers.
by k6ccc
Fri Nov 16, 2018 3:04 pm
Forum: SwOS
Topic: 2 untagged VLAN same interface
Replies: 11
Views: 1722

Re: 2 untagged VLAN same interface

No. No way to know which LAN a packet is part of if they are both I tagged.



Sent from a $&@#% iPhone using Tapatalk
by k6ccc
Tue Nov 13, 2018 11:51 pm
Forum: SwOS
Topic: About VLAN configure in CRS317-1G-16S+RM
Replies: 12
Views: 2809

Re: About VLAN configure in CRS317-1G-16S+RM

I have five switches running SwitchOS (listed in my signature) without any problems at all. Only thing fancy I'm doing is VLANs, but all of them have over a dozen VLANs at my house...
by k6ccc
Mon Nov 05, 2018 7:37 am
Forum: Beginner Basics
Topic: MAC Reservations
Replies: 5
Views: 5718

Re: MAC Reservations

Please assist, i am network support agent, i have come across where i need to add/make mac reservation, static IP Reserve. I have to two questions, 1. If MAC address doesn't show up on leases, can i add it or maybe i need to plug LAN cable from RouterBoard to PC before? 2. How is IP DHCP reservatio...
by k6ccc
Tue Oct 30, 2018 10:22 pm
Forum: Beginner Basics
Topic: Hairpin NAT
Replies: 3
Views: 649

Re: Hairpin NAT

You did not list your firewall rules. I assume that there is either a rule that allows the specific NAT through the firewall, or all NATted packets through the firewall. Does that rule or rules specify the input being the WAN interface? That would stop NATTed packets that are coming in on one of the...
by k6ccc
Tue Oct 30, 2018 5:06 pm
Forum: Beginner Basics
Topic: blocking ping/ICMP
Replies: 4
Views: 601

Re: blocking ping/ICMP

Thanks vecernik87 for the longer answer. My short answer was courtesy of needing to get to bed :)
by k6ccc
Tue Oct 30, 2018 6:29 am
Forum: Beginner Basics
Topic: blocking ping/ICMP
Replies: 4
Views: 601

Re: blocking ping/ICMP

If you are just wanting to block ICMP packets, simply do just that. Something like this:
add action=drop chain=input in-interface=e1_Internet protocol=icmp
Obviously you would have to edit this to have the in-interface = whatever your internet interface is (as opposed to my e1_internet).
by k6ccc
Sat Oct 27, 2018 1:07 am
Forum: Beginner Basics
Topic: cant surf on new ip block
Replies: 4
Views: 607

Re: cant surf on new ip block

For starters, please export and post your configuration so we have some idea what you are doing.
by k6ccc
Fri Oct 26, 2018 4:51 pm
Forum: SwOS
Topic: About VLAN configure in CRS317-1G-16S+RM
Replies: 12
Views: 2809

Re: About VLAN configure in CRS317-1G-16S+RM

You're still not really telling us what you are trying to accomplish (we're not mind readers). Also, you are asking about this in the SwitchOS section of the forum. Can I assume you are doing this on your CRS317 operating in SwitchOS as opposed to RouterOS?
by k6ccc
Thu Oct 25, 2018 5:30 pm
Forum: SwOS
Topic: About VLAN configure in CRS317-1G-16S+RM
Replies: 12
Views: 2809

Re: About VLAN configure in CRS317-1G-16S+RM

Not enough information. What are you trying to accomplish?
by k6ccc
Sat Oct 06, 2018 7:57 am
Forum: SwOS
Topic: CRS317-1G-16S+ vlan list bug
Replies: 2
Views: 950

Re: CRS317-1G-16S+ vlan list bug

For whatever it's worth, both of my CSS326-24G-2S switches with 2.8 have 17 VLANs and working perfectly.

I don't have any CRS317 routers.
by k6ccc
Tue Oct 02, 2018 6:24 pm
Forum: SwOS
Topic: 2.9 upgrade
Replies: 2
Views: 1532

Re: 2.9 upgrade

Not knowing the details of how upgrades are released, my speculation is that 2.9 is not really released yet. Maybe they were about to release it, so it got into the notes, but then an issue was found and the release halted. Just a guess....
by k6ccc
Mon Oct 01, 2018 6:06 pm
Forum: SwOS
Topic: CSS326 - Cannot connect to GUI [Solved]
Replies: 4
Views: 1498

Re: CSS326 - Cannot connect to GUI [Solved]

Has the same problem, purchased two new css326-24g-2s+rm , cannot acess the web GUI through 192.168.88.1 on both switches
What IP is your computer?
by k6ccc
Sat Sep 29, 2018 11:43 pm
Forum: Beginner Basics
Topic: quick set does not allow to set bridge mode on CRS328
Replies: 1
Views: 301

Re: quick set does not allow to set bridge mode on CRS328

Don't use Quick Set.
Quick Set is very limited in what it can do.
by k6ccc
Sat Sep 29, 2018 8:02 am
Forum: General
Topic: DHCP over 802.1Q VLAN
Replies: 2
Views: 342

Re: DHCP over 802.1Q VLAN

I have a switch with 802.1Q VLAN setup, where I want to use a mikrotik router for DHCP. If I have a DHCP server on a tagged VLAN interface, this should work fine going through the switch? Have an IP phone not picking up DHCP, I'll try a factory reset of the phone How is the iPhone getting to the ne...
by k6ccc
Wed Sep 19, 2018 7:08 pm
Forum: Beginner Basics
Topic: Bruteforce prevention Issue
Replies: 14
Views: 1034

Re: Bruteforce prevention Issue

I do use port knocking (among other things), and log any connection attempts. Of course for step one I see hits somewhat regularly due to random scans. I have NEVER seen a hit on step two if it was not me. As sob said, most of the attackers are simply going after the commonly used ports. I do also h...
by k6ccc
Sat Sep 15, 2018 10:33 am
Forum: SwOS
Topic: SwOS or RouterOS
Replies: 3
Views: 1972

Re: SwOS or RouterOS

I have two CSS326, one CRS326, one CSS106, and one RB260 that are all running SwitchOS, in addition to three RB750 routers running RouterOS. My general philosophy is that if you want a switch, buy a switch and run a switch OS. If you want a router, buy a router and run a router OS. I don’t mix the t...
by k6ccc
Fri Sep 14, 2018 6:33 am
Forum: SwOS
Topic: CRS317 boot issue after power failure
Replies: 22
Views: 3097

Re: CRS317 boot issue after power failure

2.9 does nothing for me, so I likely won't bother with this one...
by k6ccc
Fri Sep 14, 2018 6:32 am
Forum: SwOS
Topic: CRS317 boot issue after power failure
Replies: 22
Views: 3097

Re: CRS317 boot issue after power failure

I see SwOS 2.9 was released today. Who's gonna be brave and give it a test run? Where are you seeing that 2.9 was released? Not on the software download page and no announcements here on the forum. Ah, one of my switches shows that: Current Installed Version 2.8 (built at Fri Jul 13 2018 04:37:06 G...
by k6ccc
Thu Sep 13, 2018 7:52 pm
Forum: Beginner Basics
Topic: DHCP pool problem
Replies: 12
Views: 1367

Re: DHCP pool problem

right now i dont have a busy state in my IPs. what's the command to see this status? address=192.168.13.42 mac-address=00:E1:00:86:1E:34 client-id="1:0:e1:0:86:1e:34" address-lists="" server=defconf dhcp-option="" status=waiting last-seen=1w3d20h30m23s I normally use WinBox and there it's easy. Jus...
by k6ccc
Thu Sep 13, 2018 7:47 pm
Forum: Beginner Basics
Topic: DHCP pool problem
Replies: 12
Views: 1367

Re: DHCP pool problem

is it possible to have them take the lowest possible IP? No. ROS assigns IP addresses from the top of the pool. You have no control of that. My recommendation is that if you have devices that you want to have a specific address, let them connect (so they show up in the DHCP Leases list), and then c...
by k6ccc
Thu Sep 13, 2018 6:24 pm
Forum: Beginner Basics
Topic: DHCP pool problem
Replies: 12
Views: 1367

Re: DHCP pool problem

From the Wiki: Lease status: waiting - un-used static lease testing - testing whether this address is used or not (only for dynamic leases) by pinging it with timeout of 0.5s authorizing - waiting for response from radius server busy - this address is assigned statically to a client or already exist...
by k6ccc
Tue Sep 11, 2018 5:51 pm
Forum: Beginner Basics
Topic: Distinguishing between clients' routers
Replies: 7
Views: 574

Re: Distinguishing between clients' routers

Ahh of course... after having this enabled for a long time one forgets that it is even there...
Yep! Same here...
by k6ccc
Mon Sep 10, 2018 11:27 pm
Forum: Beginner Basics
Topic: Firewall rules with port scanner dropping
Replies: 3
Views: 3179

Re: Firewall rules with port scanner dropping

This is the last rule in my input chain. There is a similar rule in the forward chain. add action=drop chain=input comment=\ "Drop any other input packets that get this far" log-prefix=\ "Dropped connection" Remember how rule processing works. It's top to bottom, and if a rule is not explicitly drop...
by k6ccc
Mon Sep 10, 2018 12:51 am
Forum: Beginner Basics
Topic: Distinguishing between clients' routers
Replies: 7
Views: 574

Re: Distinguishing between clients' routers

You can set the "Note" to anything you darn well please.
by k6ccc
Fri Sep 07, 2018 6:40 pm
Forum: Beginner Basics
Topic: Firewall rules with port scanner dropping
Replies: 3
Views: 3179

Re: Firewall rules with port scanner dropping

You have a bunch of rules that add addresses to the Port Scanners list, but you never drop them. Do you have a drop everything rule at the end of the Input and Forward chains? My opinion is that dropping pings from the internet creates more problems than it solves. I know some people firmly believe ...
by k6ccc
Fri Sep 07, 2018 4:19 am
Forum: SwOS
Topic: Bandwidth control by vlan CSS326-24G-2S+
Replies: 1
Views: 682

Re: Bandwidth control by vlan CSS326-24G-2S+

Your question is in the Switch OS section of the forum and your subject title asks about the CSS326 switch. However the text of your question asks about two specific routers. Are you trying to control BW in SwitchOS or Router OS? No way to do that in SwitchOS Sent from a $&@#% iPhone using Tapatalk
by k6ccc
Thu Sep 06, 2018 10:45 pm
Forum: SwOS
Topic: LAG (LACP) or RSTP or both???
Replies: 17
Views: 2827

Re: LAG (LACP) or RSTP or both???

You really need (R/M)STP to run on top of LACP bonding if you add the "Switch C" for the whole system to work (your lower picture). The LACP bonding itself will be treated like one physical port by RSTP - it can't disable only part of it. But if there is no other potential loops, and the LACP bondi...
by k6ccc
Thu Sep 06, 2018 9:07 pm
Forum: SwOS
Topic: LAG (LACP) or RSTP or both???
Replies: 17
Views: 2827

Re: LAG (LACP) or RSTP or both???

I would say so.
If you have many switches use of rstp becomes obvious...
Yes, makes sense.

Thanks for your help. Sounds like I largely had it figured out, but fully admit that I only knew enough to be dangerous!
by k6ccc
Thu Sep 06, 2018 8:38 pm
Forum: Beginner Basics
Topic: Bruteforce prevention Issue
Replies: 14
Views: 1034

Re: Bruteforce prevention Issue

Here's what I do to make a port knock easier. I have bookmarks in my browser for each one. Click the first one, wait a second, click the second on, etc. Takes seconds. This works if we are only managing 1 or 2 devices, but I am managing 500 routers in the field and increasing. This bookmark feature...
by k6ccc
Thu Sep 06, 2018 8:32 pm
Forum: SwOS
Topic: LAG (LACP) or RSTP or both???
Replies: 17
Views: 2827

Re: LAG (LACP) or RSTP or both???

But for your question, when LACP or static team active rstp doesn`t play any role as it simply puts port in edge mode.
So in a summary, RSTP in this case is only there to prevent you from doing something stupid (or cover your backsides if or when you do). Do I have that right?
by k6ccc
Thu Sep 06, 2018 8:22 pm
Forum: Beginner Basics
Topic: Bruteforce prevention Issue
Replies: 14
Views: 1034

Re: Bruteforce prevention Issue

Thank you for your all responses, I have a couple simple questions at first. One when you select code to add in what option are you picking ? I assume you mean where I included my code extract. It's the symbol to the left of the quotation marks. You can also just type "[ c o d e ]" and "[ / c o d e...
by k6ccc
Thu Sep 06, 2018 8:07 pm
Forum: SwOS
Topic: LAG (LACP) or RSTP or both???
Replies: 17
Views: 2827

Re: LAG (LACP) or RSTP or both???

LACP is for link aggregation. 2 ports on switch A and 2 ports on switch B. 2GB link between them with LACP. If not using LACP or static team 2 ports connected between switches would create LOOP. This is what RSTP is for. To prevent loops and lear about topology changes: Right. Got that part. 1. So ...
by k6ccc
Thu Sep 06, 2018 7:28 pm
Forum: Beginner Basics
Topic: Bruteforce prevention Issue
Replies: 14
Views: 1034

Re: Bruteforce prevention Issue

As Sob said, what you're doing is not overly helpful. At first I thought you were doing a port knock until I read it. You would do better with a port knock. add action=add-src-to-address-list address-list="Long Knock-1" \ address-list-timeout=15s chain=input comment=\ "Long Port Knock setup step 1" ...
by k6ccc
Thu Sep 06, 2018 6:54 pm
Forum: SwOS
Topic: LAG (LACP) or RSTP or both???
Replies: 17
Views: 2827

Re: LAG (LACP) or RSTP or both???

Well, now I'm back to confused. First of all, I fully understand how bad a loop can be. Last year at work on a microwave network that supports a large public safety radio 2-way radio system, we had a loop protection failure that resulted in a broadcast storm that took down the entire network. Really...
by k6ccc
Mon Sep 03, 2018 5:27 am
Forum: General
Topic: Chinese IP Cameras
Replies: 9
Views: 817

Re: Chinese IP Cameras

I also have a bunch of Chinese cameras at home. I created a dedicated VLAN for them that is firewalled so that they can get to the internet (required for remote viewing), and nothing else on my home networks.
by k6ccc
Sun Sep 02, 2018 10:26 pm
Forum: SwOS
Topic: LAG (LACP) or RSTP or both???
Replies: 17
Views: 2827

Re: LAG (LACP) or RSTP or both???

Thanks again. You pretty well told me what I thought I already understood from reading, but I had been confused when some other guy in a different thread told me that I should always be using RSTP. It will be a while before I have time to bury another conduit between the house and garage, so I'm in ...
by k6ccc
Sun Sep 02, 2018 9:36 pm
Forum: SwOS
Topic: LAG (LACP) or RSTP or both???
Replies: 17
Views: 2827

Re: LAG (LACP) or RSTP or both???

Thanks for the reply. I'm curious why I can't use RSTP. I've read the Wiki about a million times (OK, not really a million) and don't see why I could not use RSTP, and in a different thread where this topic came up, it was recommended that I should always use RSTP. From my own research, I had assume...
by k6ccc
Fri Aug 31, 2018 9:28 pm
Forum: Beginner Basics
Topic: How to change mikrotik Rb750gr3 hotspot login page..?
Replies: 3
Views: 667

Re: How to change mikrotik Rb750gr3 hotspot login page..?

Maybe I'm missing something here, but the RB750Gr3 does not have WiFi.
Note: I am not using MikroTik for my WiFi - only for routers and switches. So I could be missing something.
by k6ccc
Mon Aug 27, 2018 9:56 pm
Forum: SwOS
Topic: DHCP Snooping on SwOS 2.8 CRS328-24P-4S+RM
Replies: 6
Views: 1976

Re: DHCP Snooping on SwOS 2.8 CRS328-24P-4S+RM

Do you have DHCP Snooping enabled on the end device ports of the switch (ports 1, 7, 13, & 15 if I counted right)?
by k6ccc
Mon Aug 27, 2018 2:34 am
Forum: SwOS
Topic: CSS106 - access via SFP problem
Replies: 1
Views: 645

Re: CSS106 - access via SFP problem

What software version is your CSS? My CSS106-5G-1S is version 2.8 and is configured quite different than yours. The SFP is a gigabit link from this switch to a CSS326-24G-2S in my family room. It is exclusively a tagged trunk port. The two Open Mesh ports are WiFi access points that have both a non-...
by k6ccc
Fri Aug 24, 2018 8:16 am
Forum: General
Topic: Sofware VLAN/Bridge on RuterOS explained.
Replies: 58
Views: 15122

Re: Sofware VLAN/Bridge on RuterOS explained.

I use routers EXCLUSIVELY as routers and switches as switches. Each port of my routers is either a single LAN or a VLAN trunk port. The same exercise is needed when configuring RB running ROS if that RB is to be used as smart switch. Not that I would recommend that since HW offload is disabled and ...
by k6ccc
Fri Aug 24, 2018 7:18 am
Forum: SwOS
Topic: Website download for CRS 2.8 links to CSS
Replies: 4
Views: 1027

Re: Website download for CRS 2.8 links to CSS

Well, I for one am quite happy with my two CSS326-24G-2S and also the CRS326-24G-2S (running SwitchOS). I have not found any way in SwitchOS to determine the CPU load, so I can't tell you how much I'm loading them. Reality is likely not all that much. This is at my house and then also a MicroWave pa...
by k6ccc
Fri Aug 24, 2018 1:42 am
Forum: SwOS
Topic: LAG (LACP) or RSTP or both???
Replies: 17
Views: 2827

Re: LAG (LACP) or RSTP or both???

Nobody have anything?
by k6ccc
Fri Aug 24, 2018 1:39 am
Forum: General
Topic: Sofware VLAN/Bridge on RuterOS explained.
Replies: 58
Views: 15122

Re: Sofware VLAN/Bridge on RuterOS explained.

Yes, thank you both for the education. I didn't really need it, but it was interesting. I have a different solution. I use routers EXCLUSIVELY as routers and switches as switches. Each port of my routers is either a single LAN or a VLAN trunk port. Never does any LAN or VLAN appear on more than one ...
by k6ccc
Thu Aug 23, 2018 6:01 pm
Forum: Beginner Basics
Topic: Error:could not connect to 192.168.15.1
Replies: 4
Views: 9461

Re: Error:could not connect to 192.168.15.1

i noticed that the winbox port has change ... what can be the reason ? Can I assume that you mean that when you connect via the MAC address, you are able to see that the service port for WinBox has changed. If that is the case, you would need to specify the non-standard port. In your case, that wou...
by k6ccc
Wed Aug 22, 2018 8:37 am
Forum: SwOS
Topic: Link status of SFP S+RJ10
Replies: 4
Views: 1217

Re: Link status of SFP S+RJ10

Just an FYI, about an hour ago I installed a S-RJ01 into a CSS326-24G-2S that has SwitchOS 2.8. It behaved exactly as I expected. Link showed as down with no cable plugged in. When I plugged in a cable to a RB260GS with a third party SFP, the link came right up and showed 1G. Pings to both the far e...
by k6ccc
Tue Aug 21, 2018 4:01 pm
Forum: General
Topic: Winbox access to Mikrotik behind a MIkrotik
Replies: 9
Views: 593

Re: Winbox access to Mikrotik behind a MIkrotik

Use non-standard ports for WinBox access to the PTPs. Then it’s just standard NATting to get to them from the internet.



Sent from a $&@#% iPhone using Tapatalk
by k6ccc
Mon Aug 20, 2018 9:22 pm
Forum: SwOS
Topic: What's VLAN-tagging the packets?
Replies: 8
Views: 1485

Re: What's VLAN-tagging the packets?

EdPa, thanks for the explanation. A couple suggestions to pass along to the software people. Any chance of making the VLAN and VLANs tabs look and operate the same between the CSS326 and the CSS106 & RB260GS. I have both types of switches and it is annoying to have to think quite differently between...
by k6ccc
Mon Aug 20, 2018 9:11 pm
Forum: SwOS
Topic: CSS326-24G-2S - Where is WATCHDOG IP address to ping!!!???
Replies: 10
Views: 2381

Re: CSS326-24G-2S - Where is WATCHDOG IP address to ping!!!???

I don't believe that the WatchDog timer is for a specific link, but rather looking for internal process locking up. Hence, no IP to be pinging.
by k6ccc
Mon Aug 20, 2018 10:01 am
Forum: Beginner Basics
Topic: Updating firmware
Replies: 4
Views: 554

Re: Updating firmware

Taking your thought, I did a comparison of the Saturday night and Sunday night script files for both routers - before and after my updates Sunday morning. There were only two differences. First is that the software version was different. Well, it darn well better be! Second was a login script that w...
by k6ccc
Mon Aug 20, 2018 6:03 am
Forum: Beginner Basics
Topic: Updating firmware
Replies: 4
Views: 554

Re: Updating firmware

Funny you should bring this up today. This morning I updated both of my RB750s from 6.42.1 to 6.42.6 and updated the firmware on both from quite old to current. The upgrades went very well. I already have a scheduled script to do a daily backup and export, so I have a good baseline. I had not planne...
by k6ccc
Mon Aug 20, 2018 4:19 am
Forum: Beginner Basics
Topic: Trying to get past "sfp-type: (unknown)"
Replies: 7
Views: 637

Re: Trying to get past "sfp-type: (unknown)"

I had the same issue with some HP 2610-48s. Had to use HP SFPs.
by k6ccc
Mon Aug 20, 2018 12:35 am
Forum: Beginner Basics
Topic: Trying to get past "sfp-type: (unknown)"
Replies: 7
Views: 637

Re: Trying to get past "sfp-type: (unknown)"

Because it's the Cisco that is showing no link, I am guessing that it is the end that does not like the really cheap SFP. Just a guess however.
by k6ccc
Sun Aug 19, 2018 8:14 pm
Forum: Beginner Basics
Topic: Trying to get past "sfp-type: (unknown)"
Replies: 7
Views: 637

Re: Trying to get past "sfp-type: (unknown)"

My first guess is that the SFP is not really compatible with one or both of the devices that they are plugged into. I have found with several equipment brands (MikroTik and others as well) that not all SFPs will work. In fact just this morning I found that none of my assorted pile of 1GigE SFPs woul...
by k6ccc
Sun Aug 19, 2018 7:14 pm
Forum: General
Topic: Bridges getting deleted
Replies: 7
Views: 645

Re: Bridges getting deleted

What hardware?
by k6ccc
Sat Aug 18, 2018 2:14 am
Forum: SwOS
Topic: What's VLAN-tagging the packets?
Replies: 8
Views: 1485

Re: What's VLAN-tagging the packets?

Are you implying that SwOS will just tag unconditionally if a port is a member of multiple VLANs or something? Could be. I really don't know. I certainly don't claim to be the expert. In fact I just learned an hour ago that a setting in 2.7 did not work quite the way I expected for un-tagged ports....
by k6ccc
Fri Aug 17, 2018 11:01 pm
Forum: SwOS
Topic: What's VLAN-tagging the packets?
Replies: 8
Views: 1485

Re: What's VLAN-tagging the packets?

You have to have VLAN tagging on the trunk port or else you would have both VLAN 2 & 3 untagged (and therefore no longer separate) on the trunk port.
by k6ccc
Fri Aug 17, 2018 2:13 am
Forum: Wireless Networking
Topic: Can I run separate Hotspot servers per VLAN?
Replies: 8
Views: 848

Re: Can I run separate Hotspot servers per VLAN?

As I recall, the NanoStation will happily pass VLAN traffic and is VLAN aware for the management interface, but I'm not aware of the ability to specify which VLAN to use for locally connected stations. Note that I am using them for a point to point link with a managed switch (CSS326-24G-2S) on each ...
by k6ccc
Thu Aug 16, 2018 5:36 pm
Forum: Beginner Basics
Topic: Understanding Default config: bridge
Replies: 4
Views: 2663

Re: Understanding Default config: bridge

It depends on what you are doing. I am not using a bridge on any of my routers. However, I am using my routers exclusively as routers. Each port is either a separate LAN or a trunk port with multiple VLANs. Everything is routed in between ports. Each port is connected to a different port of a manage...
by k6ccc
Thu Aug 16, 2018 3:22 pm
Forum: General
Topic: I've closed all service ports by mistake [SOLVED]
Replies: 4
Views: 586

Re: I've closed all service ports by mistake [SOLVED]

Hopefully you have previously saved backups so after the net install, you can restore from your backup. If not, lesson learned - backup, backup, and off site backup.



Sent from a $&@#% iPhone using Tapatalk
by k6ccc
Wed Aug 15, 2018 7:36 pm
Forum: SwOS
Topic: LAG (LACP) or RSTP or both???
Replies: 17
Views: 2827

LAG (LACP) or RSTP or both???

This is an area where have no experience so looking for suggestions. My situation at home is as follows. In my Family room I have a CSS324-24G-2S with various computers, WiFi, lighting controls, and monitoring devices connected. Both my DSL and cable internet connections also come into the Family ro...
by k6ccc
Wed Aug 15, 2018 6:11 pm
Forum: Announcements
Topic: SwOS version 2.8 released!
Replies: 37
Views: 12555

Re: SwOS version 2.8 released!

on my CSS326-24G-2S+ manual upgrade dont works. switch not accessible(web) after manual upgrade. to access the switch again, i had to boot backup SwOS. i tried upgrade from backup SwOS(2.0p) to 2.8, and reset configuration - but no success. Most likely the switch changed from a static IP to DHCP. C...
by k6ccc
Wed Aug 15, 2018 5:42 pm
Forum: General
Topic: Question on Firewall and blacklists
Replies: 4
Views: 503

Re: Question on Firewall and blacklists

Here's another example of using stuff in the Output chain. I was recently troubleshooting a problem and I wanted to be able to verify that packets were going out on the interface that they should have been. So I created the following set of output chain rules that served only to count packets on eac...
by k6ccc
Wed Aug 15, 2018 5:25 am
Forum: General
Topic: Question on Firewall and blacklists
Replies: 4
Views: 503

Re: Question on Firewall and blacklists

Yes. The Input chain only affects traffic that will terminate on the router itself. The Forward chain affects traffic that will pass through the router. Note that you have an allow connected and related traffic in the Forward chain, that rule will allow responses to one of your users who connects to...
by k6ccc
Wed Aug 15, 2018 4:13 am
Forum: Beginner Basics
Topic: 2 vlans with mikrotik and unifi - no way to make it work
Replies: 1
Views: 318

Re: 2 vlans with mikrotik and unifi - no way to make it work

The problem is your dumb switch. Some dumb switches will pass 802.1Q VLAN traffic and some will not. I have no idea if your tplink will or not. Assuming that it won't, my suggestion would be to split it up. Have the tplink and the attached computers connected as they are now. Then run a separate con...
by k6ccc
Tue Aug 14, 2018 5:18 pm
Forum: General
Topic: Moving a port - what did I miss???
Replies: 3
Views: 357

Re: Moving a port - what did I miss???

Thanks again Sindy! That was it, and yes, that was a leftover from old times. Confirmed that with an AutoCAD drawing from early last year. As soon as I changed the VLAN switch setting for that port, pings started working, and forwarding traffic started working properly. As this router is used exclus...
by k6ccc
Tue Aug 14, 2018 3:41 pm
Forum: General
Topic: Moving a port - what did I miss???
Replies: 3
Views: 357

Re: Moving a port - what did I miss???

Thanks for the catch Sindy. Ether2 is not supposed to be a hybrid port at all. It should be all untagged traffic. I’m on a commuter train on my phone right now so I can’t look for a couple hours, but that was likely a leftover from time past. The .131 LAN is currently a VLAN on the 802.1q trunk on p...
by k6ccc
Tue Aug 14, 2018 5:43 am
Forum: General
Topic: Moving a port - what did I miss???
Replies: 3
Views: 357

Moving a port - what did I miss???

I have managed to apparently do something stupid. I was moving one of my LANs from port ether3 to ether2 on an RB750r2. This router is being used exclusively as a router - there is no bridge and every port is a different LAN or trunk port with multiple VLANs. Should be simple enough and I've done th...
by k6ccc
Tue Aug 14, 2018 3:31 am
Forum: SwOS
Topic: CSS326-24G-2S+ firmware 2.8 broken web UI
Replies: 4
Views: 1282

Re: CSS326-24G-2S+ firmware 2.8 broken web UI

After upgrade to v2.8, switch goes from "static IP" to "DHCP with fallback", - looks like a bug.
so put DHCP server on top of swtich and use that dynamic assigned IP to back to Static IP

Not a bug. That's the way it's designed.
by k6ccc
Mon Aug 13, 2018 12:35 am
Forum: SwOS
Topic: Website download for CRS 2.8 links to CSS
Replies: 4
Views: 1027

Re: Website download for CRS 2.8 links to CSS

For your first part, I would assume that since you are looking for SwitchOS and not RouterOS, you should be getting the same SwitchOS as the CSS. That is the case with the CRS326, so I'm guessing it's the same with the CRS328. For your second part, depending on what version you upgraded from, very l...
by k6ccc
Thu Aug 09, 2018 2:32 am
Forum: Beginner Basics
Topic: Can't ping radio on LAN from radio on WAN side
Replies: 2
Views: 287

Re: Can't ping radio on LAN from radio on WAN side

I find it easy to believe that it does not work. You are mixing up your subnets. You are trying to get a 10.10.25.x device to talk on a router that has a port on the 192.168.10.x subnet. Can't get there. Now if you were to use very small subnets, and give the router an additional address on the WAN ...
by k6ccc
Wed Aug 08, 2018 7:34 pm
Forum: General
Topic: Do not open port tcp/23 to your device from internet you will be hacked
Replies: 6
Views: 978

Re: Do not open port tcp/23 to your device from internet you will be hacked

Short comment would be: DUH! OK, now for the longer, more polite answer. Anyone who runs almost any type of server these days will see piles of attack attempts on a variety of ports. Yes, Telnet is one of the most common. I don't log them, but I do have firewall rules that drop and count packets. I ...
by k6ccc
Tue Aug 07, 2018 1:11 am
Forum: Announcements
Topic: Winbox v3.16 released!
Replies: 63
Views: 26775

Re: Winbox v3.16 released!

If you go to the software download page and select Winbox, the dropdown shows 3.17, but that results in a 404 error. Might want to fixed the webpage - either that or 3.17 is about to be released about the time I post this message :)
by k6ccc
Sun Aug 05, 2018 9:55 pm
Forum: General
Topic: VLANs with "stacked" switches
Replies: 12
Views: 1143

Re: VLANs with "stacked" switches

I'd argue to keep with the best practice and use STP or the new MSTP implementation. It's just good common sense loop protection. That said it looks like you're using the old way VLANs where done but not in a complete way. I'd urge you to migrate to the VLAN aware bridging approach. It's documented...
by k6ccc
Sun Aug 05, 2018 7:51 am
Forum: General
Topic: VLANs with "stacked" switches
Replies: 12
Views: 1143

Re: VLANs with "stacked" switches

I imagine you're either running in the per-VLAN based mode or do not have STP correctly running. I haven't actually sniffed a link without an untagged VLAN defined to see if MikroTik hides this fault to keep networks working despite the best effort of their admins. Of course I know what Spanning Tr...
by k6ccc
Fri Aug 03, 2018 6:48 pm
Forum: General
Topic: VLANs with "stacked" switches
Replies: 12
Views: 1143

Re: VLANs with "stacked" switches

I don't know if this is an issue, but if I were doing it, the trunks between routers and switches would have nothing but VLAN tagged traffic - no untagged traffic. That's how I'm doing it at home with my three routers and five switches.
by k6ccc
Tue Jul 31, 2018 7:01 pm
Forum: Announcements
Topic: SwOS version 2.8 released!
Replies: 37
Views: 12555

Re: SwOS version 2.8 released!

CRS+CSS: How many ports can be aggregated concurrently with LACP at maximum? Suggestion. If you are going to ask a question that is totally unrelated to the current topic, start a new post rather than ask in an unrelated thread. For one thing it makes finding the question and answer far easier when...
by k6ccc
Thu Jul 26, 2018 5:37 pm
Forum: SwOS
Topic: Possible bug in stats for SwOS 2.0 in CSS326 ? [SOLVED]
Replies: 10
Views: 1943

Re: Possible bug in stats for SwOS 2.0 in CSS326 ? [SOLVED]

Happy I could help.
by k6ccc
Thu Jul 26, 2018 12:30 am
Forum: Announcements
Topic: SwOS version 2.8 released!
Replies: 37
Views: 12555

Re: SwOS version 2.8 released!

For me manual upgrade don't work. I only see "don't interrupt", switch reboted (I see it uptime on router in neigbord) Are you sure? I did take the time to do a manual update on my CSS106-5G-1S. Prior to the upgrade, I started a continuous ping to the switch from this PC. After starting the upgrade...
by k6ccc
Thu Jul 26, 2018 12:11 am
Forum: Announcements
Topic: SwOS version 2.8 released!
Replies: 37
Views: 12555

Re: SwOS version 2.8 released!

None of my switches see it as an available upgrade. Have not the time at the moment to try a manual upgrade yet.
by k6ccc
Thu Jul 26, 2018 12:06 am
Forum: SwOS
Topic: Possible bug in stats for SwOS 2.0 in CSS326 ? [SOLVED]
Replies: 10
Views: 1943

Re: Possible bug in stats for SwOS 2.0 in CSS326 ? [SOLVED]

SwitchOS 2.7 and below used 32 bits for the stats. Real easy to roll over. VERY likely what you are seeing. According to the release notes for 2.8 (just released) one of the changes:
*) use 64bit counters under Stats tab for byte accounting;
by k6ccc
Wed Jul 25, 2018 2:12 am
Forum: General
Topic: Calling all Mikrotik Switch experts
Replies: 7
Views: 694

Re: Calling all Mikrotik Switch experts

I would also say I am not an expert, but I have several and they are in daily production use. First one I got was a RB260GS. Depend on time of year, it has somewhere between three and all six ports in use (the sfp is an electrical gigabit interface). It is out in a brick column in my front yard so i...
by k6ccc
Tue Jul 24, 2018 10:49 pm
Forum: Beginner Basics
Topic: VLAN segregation and bridge setting [SOLVED]
Replies: 15
Views: 1200

Re: VLAN segregation and bridge setting [SOLVED]

Thanks mkx. That was what I thought...
by k6ccc
Tue Jul 24, 2018 8:44 pm
Forum: Beginner Basics
Topic: VLAN segregation and bridge setting [SOLVED]
Replies: 15
Views: 1200

Re: VLAN segregation and bridge setting [SOLVED]

Kind of related to this. In my case, both of my routers are used EXCLUSIVELY for routing. Each physical port is either a trunk carrying multiple VLANs to a smart switch, or a specific LAN that is going to a switch. Never does the same LAN appear on more than one physical port. Is there any reason un...
by k6ccc
Thu Jul 19, 2018 7:41 am
Forum: Beginner Basics
Topic: Why in MT everything, including VLANs can always access each other unless blocked by firewall? [SOLVED]
Replies: 14
Views: 1344

Re: Why in MT everything, including VLANs can always access each other unless blocked by firewall? [SOLVED]

Depends on what you are trying to accomplish. I fully admit that this is not normal, but I have 15 VLANs at my house. With the exception of a few select situations, none of them talk to each other. I also have two active routers, and four switches (all smart devices) - then a microwave path 4.2 mile...
by k6ccc
Wed Jul 18, 2018 4:18 pm
Forum: General
Topic: Restore corrupted Routerboard with damaged Eth1
Replies: 6
Views: 827

Re: Restore corrupted Routerboard with damaged Eth1

Throw away the RB, if it has been hit by a thunderstrike there's no software update that could solve the problem. P.S. if you update from version 5 to 6 you have to upgrade to bugfix version of 6, for example 5.25 check for updates makes download 6.40.8 bugfix. Please read my post. The Routerboard ...
by k6ccc
Wed Jul 18, 2018 8:07 am
Forum: Beginner Basics
Topic: Why in MT everything, including VLANs can always access each other unless blocked by firewall? [SOLVED]
Replies: 14
Views: 1344

Re: Why in MT everything, including VLANs can always access each other unless blocked by firewall? [SOLVED]

Yes, the basic firewall configuration is that all is allowed unless specifically blocked by firewall. It's a router - it routes. The normal way to set it up is to explicitly allow what you want and then at the end of each chain, drop everything. That way only the traffic that you allow will get thro...
by k6ccc
Tue Jul 17, 2018 5:30 am
Forum: Beginner Basics
Topic: IP Outside the IP Pool
Replies: 9
Views: 609

Re: IP Outside the IP Pool

Did what you suggest, what happens is when I changed it to desired static ip outside the pool, the status is waiting. The machine itself didn't acquire the assigned IP I put. Remember that the machine in question does not get a new address as soon as you change it't static reservation. It has no wa...
by k6ccc
Mon Jul 16, 2018 6:17 am
Forum: General
Topic: SSH or SNMP , How to get UBNT AF capacity and send it through Mikrotik
Replies: 9
Views: 590

Re: SSH or SNMP , How to get UBNT AF capacity and send it through Mikrotik

Are you asking if the router can send a command to the AirFiber and then do something with the result?
by k6ccc
Mon Jul 16, 2018 5:57 am
Forum: General
Topic: SSH or SNMP , How to get UBNT AF capacity and send it through Mikrotik
Replies: 9
Views: 590

Re: SSH or SNMP , How to get UBNT AF capacity and send it through Mikrotik

Maybe I'm not understanding your request. How does the MikroTik have anything to do with the AirFiber (other than presumably riding on the ethernet path that the Air Fiber provides)?
by k6ccc
Mon Jul 16, 2018 5:38 am
Forum: General
Topic: SSH or SNMP , How to get UBNT AF capacity and send it through Mikrotik
Replies: 9
Views: 590

Re: SSH or SNMP , How to get UBNT AF capacity and send it through Mikrotik

I think you need to be asking that on a Ubiquiti forum - not here.
by k6ccc
Mon Jul 16, 2018 1:04 am
Forum: Beginner Basics
Topic: Script to reduce Wi-Fi transmitter power on schedule/at night
Replies: 34
Views: 3114

Re: Script to reduce Wi-Fi transmitter power on schedule/at night

even if someone sleeps only 1 meter away from the router?

If you're really worried that much, move the router a bit, but even at a foot or two, it's really a non-issue.
by k6ccc
Sun Jul 15, 2018 9:43 pm
Forum: Beginner Basics
Topic: Script to reduce Wi-Fi transmitter power on schedule/at night
Replies: 34
Views: 3114

Re: Script to reduce Wi-Fi transmitter power on schedule/at night

Hey,
The goal is to reduce the emf emf radiation as the router is in a bed room.

Unless you are sleeping with your head laying on the antenna, that is a complete non issue.
Don't worry about it.
by k6ccc
Wed Jun 13, 2018 8:19 pm
Forum: General
Topic: MT Router honeypot.
Replies: 20
Views: 1968

Re: MT Router honeypot.

I see your firewall rule adds any IP to the bad list. So I am now on your bad list - ha ha ha
Entertaining...
by k6ccc
Thu Jun 07, 2018 5:45 am
Forum: SwOS
Topic: CSS326-24G-2S partial lockup issue
Replies: 1
Views: 622

Re: CSS326-24G-2S partial lockup issue

Anything?
Still happening.
by k6ccc
Mon May 28, 2018 1:13 am
Forum: SwOS
Topic: SWOS 2.7 Uptime?
Replies: 3
Views: 1033

Re: SWOS 2.7 Uptime?

No, NOT 1.17 or lower, I know it's on that. The newer hardware RB260GS on SWOS 2.7. Where is the uptime on there? It seems it's gone missing from the web pages for some odd reason. I can only see it shown in a neighbor view from another Mikrotik device. RB260GS.jpg Looks like it depends on which sw...
by k6ccc
Sun May 27, 2018 9:32 am
Forum: SwOS
Topic: SWOS 2.7 Uptime?
Replies: 3
Views: 1033

Re: SWOS 2.7 Uptime?

System tab, General section, last line.
by k6ccc
Fri May 25, 2018 11:09 pm
Forum: General
Topic: Mikrotik bricked by backup, reset button not working anymore
Replies: 25
Views: 3888

Re: Mikrotik bricked by backup, reset button not working anymore

Q1: Can a backup completely brick the router? Q2: What can I do next to unbrick it? 1) If the file got corrupted it certainly could. 2) You already answered that one yourself - Netinstall Assuming that this is the SAME ROUTER, If you have another backup file, try it after the Netinstall. If it's a ...
by k6ccc
Fri May 25, 2018 6:57 pm
Forum: General
Topic: [Security] Attackers changed DNS servers
Replies: 8
Views: 4975

Re: [Security] Attackers changed DNS servers

Simple answer - upgrade to the current release.

Took me about 3 seconds to find it in the Announcements section:
viewtopic.php?f=21&t=133533
by k6ccc
Wed May 23, 2018 10:28 pm
Forum: SwOS
Topic: CRS-317 - Does SWoS have a physical advantage over RouterOS
Replies: 7
Views: 4749

Re: CRS-317 - Does SWoS have a physical advantage over RouterOS

I’m my general opinion, you want a router, buy a router; if you want a switch, buy a switch. In this case, use the OS that applies with the same principle. On my three routers at home, the closest I get to having any of them function as a switch is to use VLANs to get more LANs onto a finite number ...
by k6ccc
Wed May 23, 2018 10:17 pm
Forum: SwOS
Topic: CRS317 boot issue after power failure
Replies: 22
Views: 3097

Re: CRS317 boot issue after power failure

In my opinion, regardless of this problem, you should have protected power for your network core.



Sent from a $&@#% iPhone using Tapatalk
by k6ccc
Wed May 23, 2018 7:17 pm
Forum: SwOS
Topic: CSS326-24G-2S partial lockup issue
Replies: 1
Views: 622

CSS326-24G-2S partial lockup issue

I have a CSS326-24G-2S+RM that is running SwitchOS version 2.7 that sort of locks up once in a while. This switch is about six months old. I'm hoping someone either has seen something similar and / or has some advise. This switch is in my family room and is powered from a UPS so there should not be ...
by k6ccc
Wed May 02, 2018 11:27 pm
Forum: SwOS
Topic: RB260GS V1.17 VLAN how to
Replies: 1
Views: 792

Re: RB260GS V1.17 VLAN how to

I can tell you that is not how I have my RB260 set up. Frankly, I am a bit confused about what you are trying to accomplish. I am assuming that your SFP port (which you state is your uplink), is connected to a smart device. If that's the case, why do you have any non-tagged traffic on that port. Are...
by k6ccc
Wed May 02, 2018 3:44 am
Forum: SwOS
Topic: DHCP on RB260GSP not working
Replies: 2
Views: 812

Re: DHCP on RB260GSP not working

Off hand, it sounds like it is not communicating with the router. Couple things to check: Are you getting link lights at both ends of the cable between the switch and the router? Are you using VLANs, and if so, are the VLAN settings between the switch and the router compatible? Can you look at route...
by k6ccc
Tue May 01, 2018 1:40 am
Forum: RouterBOARD hardware
Topic: Copper link longer than 100 meters
Replies: 16
Views: 1702

Re: Copper link longer than 100 meters

I had to link two HDMI extenders with a CAT5e, because they didn't work through a wireless link (I don't know why). Most likely the HDMI extenders didn't work over the WiFi link because it's not Ethernet. Just because it's a RJ-45 connector, does not mean it's Ethernet. For the purpose, there is no...
by k6ccc
Fri Apr 13, 2018 8:11 am
Forum: SwOS
Topic: Where did SwOS for the old RB260GS/GSP go?
Replies: 2
Views: 1171

Re: Where did SwOS for the old RB260GS/GSP go?

Good question. I have one of the RB260GS switches in service.
by k6ccc
Wed Apr 11, 2018 8:22 am
Forum: Announcements
Topic: Winbox 3.13 released!
Replies: 61
Views: 21315

Re: Winbox 3.13 released!

k6ccc - Do you run Winbox with administrator permissions?
The computer I was having the issue on is running Windows XP and yes, the normal account that is used on that computer has admin.
by k6ccc
Tue Apr 10, 2018 6:45 pm
Forum: Announcements
Topic: Winbox 3.13 released!
Replies: 61
Views: 21315

Re: Winbox 3.13 released!

At least you can save entries. Both 3.12 and 3.13 allow me to save entries, but next time WinBox is opened, none of the saved entries are there. Sorry, works fine for me both on Windows and MacOS. What if you play with File -> New... / Open...? Interesting, I have never needed to do that before. Wi...
by k6ccc
Tue Apr 10, 2018 5:45 pm
Forum: Announcements
Topic: Winbox 3.13 released!
Replies: 61
Views: 21315

Re: Winbox 3.13 released!

If you click on saved router entry in list, focus still jumps to Password field, so mouse scrolling doesn't work :(
At least you can save entries. Both 3.12 and 3.13 allow me to save entries, but next time WinBox is opened, none of the saved entries are there.
by k6ccc
Mon Apr 09, 2018 2:18 am
Forum: Beginner Basics
Topic: About hidding mangle rules also firewall filter
Replies: 2
Views: 348

Re: About hidding mangle rules also firewall filter

Change the router password and don't give it out.
Or am I not understanding your question?
by k6ccc
Sun Apr 08, 2018 10:44 am
Forum: SwOS
Topic: CSS326 - Cannot connect to GUI [Solved]
Replies: 4
Views: 1498

Re: CSS326 - Cannot connect to GUI

Hello everyone Four weeks ago I bought a MikroTik CSS326 smart switch. For the last few weeks it served as a "dumb" switch for a small network environment. I unpacked the switch, plugged in all the PC and the Router. Everything works just fine this way. Last weekend I wanted to use some of the "sma...
by k6ccc
Sat Mar 31, 2018 6:38 am
Forum: SwOS
Topic: SWOS shell configuration
Replies: 1
Views: 983

Re: SWOS shell configuration

No



Sent from a $&@#% iPhone using Tapatalk
by k6ccc
Sat Mar 31, 2018 1:42 am
Forum: General
Topic: RouterOS making unaccounted outbound winbox connections [SOLVED]
Replies: 64
Views: 29514

Re: RouterOS making unaccounted outbound winbox connections [SOLVED]

I use a non-standard port for all the ways into the router (including WinBox) - in addition to other things for security. I have a firewall rule that drops traffic bound for the standard ports for www, ftp, ssh, & WinBox. The real purpose of those rules is to give me packet counts since they would b...
by k6ccc
Wed Mar 14, 2018 9:27 pm
Forum: SwOS
Topic: Firmware upgrade
Replies: 1
Views: 720

Re: Firmware upgrade

EXACTLY which switch? Most likely the answer is no. At least for some of the switches, the 2.x firmware goes with newer hardware and is not compatible. For example, I have two RB260GS switches. One is the "classic" RB260GS and the other is the newer CSS106-5G-1S. They look the same until you read th...
by k6ccc
Fri Mar 09, 2018 1:20 am
Forum: General
Topic: Two routers one service
Replies: 13
Views: 1084

Re: Two routers one service

That is an interesting option. I wonder what RB#2 WAN settings would be though seeing as every address in the subnet will be routed to me ... What would the gateway address be? and would WAN be a /32? That's going to depend on how your ISP sets things up. In my case, I have eight non-continuous sta...
by k6ccc
Thu Mar 08, 2018 1:58 am
Forum: General
Topic: Two routers one service
Replies: 13
Views: 1084

Re: Two routers one service

If you want the two routers completely independent of each other (other than arriving via the same fiber), get a small dumb gigabit switch with one port going to the fiber connection, and one connection to the WAN port of each of the router. That way a failure of one router does not effect the other...
by k6ccc
Sun Mar 04, 2018 4:28 pm
Forum: SwOS
Topic: RB260GSP + 2.7 How to make switch only give ip from WLAN dchp to one device on the inside?
Replies: 3
Views: 744

Re: RB260GSP + 2.7 How to make switch only give ip from WLAN dchp to one device on the inside?

Your switch is in the wrong place. Since your ISP provides you only one address, there should only be one device that can directly see the ISP connection. That should be your router WAN port. Everything else should be downstream of the router. If you used your arrangement in your second post, the de...
by k6ccc
Wed Feb 14, 2018 7:24 am
Forum: SwOS
Topic: CSS106 & Uptime
Replies: 5
Views: 1542

Re: CSS106 & Uptime

Oh, I should note that mine is a CSS106-5G-1S
by k6ccc
Wed Feb 14, 2018 7:23 am
Forum: SwOS
Topic: CSS106 & Uptime
Replies: 5
Views: 1542

Re: CSS106 & Uptime

I just looked at one of mine that got 2.7 yesterday. Sure enough, no uptime display,
by k6ccc
Fri Nov 17, 2017 6:01 pm
Forum: Beginner Basics
Topic: tcp/554 and tcp/555 open, why?
Replies: 10
Views: 1117

Re: tcp/554 and tcp/555 open, why?

A couple things. In your first post you said you added specific drop rules in the INPUT chain for ports 544 and 555. Those are not shown in the filter export you posted a few posts later, so I assume you later deleted that. You were surprised that the drop rule showed no traffic when doing your NMAP...
by k6ccc
Thu Nov 16, 2017 7:17 pm
Forum: Beginner Basics
Topic: What's the reason to use SwOS instead of RouterOS?
Replies: 11
Views: 7798

Re: What's the reason to use SwOS instead of RouterOS?

I pretty much have a concept that if you want switch functionality, buy a switch; if you want router functionality, but a router. I don't cross that. In the case of the newer MT products that will boot into either, the question is what do you want it to do? As my signature says, I do have one of tho...
by k6ccc
Mon Nov 13, 2017 11:26 pm
Forum: General
Topic: Port knocking source address list [SOLVED]
Replies: 23
Views: 2301

Re: Port knocking source address list [SOLVED]

I use port knocking for some remote access. I am doing exactly what the OP is wanting to do. My "normal" port knock is four steps. I have a short port knock that only works from one address that only takes two steps. That way when I'm at the one specific address, I can get in easier, but when not co...
by k6ccc
Tue Oct 24, 2017 5:55 pm
Forum: Beginner Basics
Topic: CRS317 - want SwOS, but won't boot
Replies: 17
Views: 2904

Re: CRS317 - want SwOS, but won't boot

Many thanks. We were expecting something in the console to tell us that "you are now in SwOS".
It did (the 10th line of text):
SwOS v2.0p
And after you updated the firmware:
SwOS v2.6
by k6ccc
Sun Oct 22, 2017 8:49 pm
Forum: General
Topic: port open for specific IP range
Replies: 5
Views: 669

Re: port open for specific IP range

One other thing you could do is set up a port knock in the router that would allow you to open the port for your camera from whatever IP you were coming from. That way the inbound port is normally dead, until you run the port knock, and then the port opens for some amount of time allowing you to con...
by k6ccc
Sat Oct 21, 2017 2:30 am
Forum: Beginner Basics
Topic: Auto upgrade, packages no internet
Replies: 1
Views: 406

Re: Auto upgrade, packages no internet

What hardware are you talking about?
What current software version do you have?
Do you have an internet connection? I assume yes or else you would not be asking.
by k6ccc
Thu Oct 19, 2017 7:26 am
Forum: Beginner Basics
Topic: One way video - PBX [SOLVED]
Replies: 9
Views: 803

Re: One way video - PBX [SOLVED]

Thanks, the problem was the src-ports. Can I make you a question k6ccc? Why it is? It supposed that the softphones must works in a fixed ranges of ports? Very simple. The device that is originating the packet picks a semi-random port number to use for the origination. It will always be a port numbe...
by k6ccc
Wed Oct 18, 2017 8:25 pm
Forum: Beginner Basics
Topic: One way video - PBX [SOLVED]
Replies: 9
Views: 803

Re: One way video - PBX [SOLVED]

add action=accept chain=forward dst-port=10000-20000 protocol=udp src-port=\
    10000-20000
I would leave off the src-port part of that rule. Source ports can be all over the place.
by k6ccc
Wed Oct 18, 2017 1:09 am
Forum: Beginner Basics
Topic: What file/s do I download to update RouterOS?
Replies: 3
Views: 433

Re: What file/s do I download to update RouterOS?

as it says at the top of the download page: If you are already running RouterOS, upgrading to the latest version can be done by clicking on "Check For Updates" in QuickSet or System > Packages menu in WebFig or WinBox. If you don't have ROS running and the router can communicate with the internet, o...
by k6ccc
Mon Oct 16, 2017 11:17 pm
Forum: Beginner Basics
Topic: How to send a backup to email [SOLVED]
Replies: 13
Views: 3387

Re: How to send a backup to email [SOLVED]

and K6ccc do i have to use these 3 scripts ? or the 1st one would do it ? and where to paste it ? in terminal ? Sorry for the delay - busy weekend... You need to run all three. The first one is the script that will create and send the backups. That gets run as often as you want to back up the confi...
by k6ccc
Fri Oct 13, 2017 6:51 pm
Forum: Beginner Basics
Topic: access winbox from internet
Replies: 9
Views: 1856

Re: access winbox from internet

This was taken essentially directly from the Wiki. The only changes I made were to make this a separate chain and jump to it, specifically drop packets from IPs on my "Manual Blacklist" list, and to exclude IPs on my "Safe" list from being affected. add action=drop chain=Attack comment=\ "Drop all c...
by k6ccc
Fri Oct 13, 2017 6:19 pm
Forum: Beginner Basics
Topic: How to send a backup to email [SOLVED]
Replies: 13
Views: 3387

Re: How to send a backup to email [SOLVED]

I do this every night on both my routers. Here is the script that I use. /system script add name="Daily Backup" owner=Admin policy=ftp,read,policy,test,sensitive \ source="# Policies needed: ftp, read, policy, sensitive, test\r\ \n# Policies NOT needed: password, reboot, write, sniff, romon\r\ \n:lo...
by k6ccc
Fri Oct 13, 2017 6:02 pm
Forum: Beginner Basics
Topic: access winbox from internet
Replies: 9
Views: 1856

Re: access winbox from internet

Use of non-standard port numbers (for God's sake, don't use port 80), This isn't really useful in today's world. Port scanners also fingerprint the sockets they discover, so even if it's sshd running on port 9147, they'll find and catalog it. That is sort of true. Casual attacks are only looking fo...
by k6ccc
Thu Oct 12, 2017 7:16 pm
Forum: Beginner Basics
Topic: access winbox from internet
Replies: 9
Views: 1856

Re: access winbox from internet

router ip:192.168.1.1 (i want maintain the router from port 8728 ,8291,80) As normal, ZeroByte had it right, but if you are going to allow internet access to your router, you need to look very seriously at access security. There are several different things that can be implemented, including (but n...
by k6ccc
Fri Sep 08, 2017 6:44 pm
Forum: SwOS
Topic: VLAN and VLANs tab conflict?
Replies: 2
Views: 744

Re: VLAN and VLANs tab conflict?

Suggestion, try reading the manual on the Wiki before asking questions. At least TRY to find the answer yourself. Took me about 10 seconds to find this about the VLANs tab settings: Each port has individual VLAN header options for each VLAN ID. Depending on VLAN mode if lookup is done in this table,...
by k6ccc
Sun Aug 27, 2017 11:44 pm
Forum: Beginner Basics
Topic: Two routers
Replies: 2
Views: 425

Re: Two routers

You are not giving us enough information. What other networks? You are not showing any other networks. Second, what purpose does router #1 serve? at least going by your drawing, router #1 does not serve any useful purpose.
by k6ccc
Wed Aug 23, 2017 8:25 pm
Forum: General
Topic: Unable to paste byte 0
Replies: 7
Views: 802

Re: Unable to paste byte 0

You say you are pasting from your computer to the router. Tell us exactly what steps you are doing.


Sent from my phone using Tapatalk, so blame any typos on Android!
by k6ccc
Wed Aug 23, 2017 12:45 am
Forum: General
Topic: telnet on port 80
Replies: 11
Views: 2082

Re: telnet on port 80

I would not advise managing the router from port 80 using telnet. Use port 23 for that. Or better use SSH on port 22. Or even better, SSH on a non-standard port with some other restrictions such as what IPs or interfaces can access, port knocking, VPN, etc. In additon to other security features, my...
by k6ccc
Tue Aug 22, 2017 5:16 am
Forum: General
Topic: Solar Eclipse tempreture effect on a Mikrotik
Replies: 2
Views: 664

Re: Solar Eclipse tempreture effect on a Mikrotik

Cool - literally!
by k6ccc
Sun Aug 20, 2017 9:48 pm
Forum: Beginner Basics
Topic: Port forwarding issue [SOLVED]
Replies: 20
Views: 1950

Re: Port forwarding issue [SOLVED]

Remove rule 4 from your firewall. Rule 8 is the correct one.
You sure about that? Rule 4 is in the input chain and wont have any affect on port forwarding.
by k6ccc
Sun Aug 20, 2017 6:15 am
Forum: General
Topic: How to stop ma scanners
Replies: 17
Views: 1801

Re: How to stop ma scanners

a hacker must scan a network to collect macs here is where the prevention acts (!=packets sniffing)
Nope. All you have to do is receive. If you never transmit, there is no way to detect it.
  • 1
  • 2