Community discussions

Search found 1045 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 21
by CZFan
Mon Dec 17, 2018 12:15 pm
Forum: General
Topic: Using queues to limit maximum bandwidth (NOT TO EXCEED)
Replies: 10
Views: 417

Re: Using queues to limit maximum bandwidth (NOT TO EXCEED)

Agree, at time of typing my previous post, I thought that there might be a misunderstanding between us.
by CZFan
Sun Dec 16, 2018 9:14 pm
Forum: General
Topic: Using queues to limit maximum bandwidth (NOT TO EXCEED)
Replies: 10
Views: 417

Re: Using queues to limit maximum bandwidth (NOT TO EXCEED)

The Child Q's are created dynamically Through what feature - DHCP? Hotspot? PPP? Can you execute "/queue simple print" and show the output? Printing the list will include all dynamic queues as separate items. Through "Simple Queues". Printing only shows the parent Q, see below screenshot. PCQ-Child...
by CZFan
Sat Dec 15, 2018 5:46 pm
Forum: General
Topic: Using queues to limit maximum bandwidth (NOT TO EXCEED)
Replies: 10
Views: 417

Re: Using queues to limit maximum bandwidth (NOT TO EXCEED)

The Child Q's are created dynamically
by CZFan
Fri Dec 14, 2018 9:03 pm
Forum: General
Topic: Using queues to limit maximum bandwidth (NOT TO EXCEED)
Replies: 10
Views: 417

Re: Using queues to limit maximum bandwidth (NOT TO EXCEED)

I don't agree with below, else what is the use of using PCQ? Also, the queue type setting for the parent will not have any effect if the parent has children. It looks like you have a PCQ queue set on the parent, which won't do anything. If you wish to use PCQ it has to be set on the child queues, no...
by CZFan
Fri Dec 14, 2018 8:30 pm
Forum: Beginner Basics
Topic: VLAN pass-through over router to AP
Replies: 7
Views: 326

Re: VLAN pass-through over router to AP

You can remove the below line:
/interface bridge vlan
add bridge=bridge-iptv tagged=ether1-gateway untagged=ether10-IPTV vlan-ids=6

Then remove ether3 from bridge-local and add it to bridge-iptv.

That should be all you need to do
by CZFan
Wed Dec 12, 2018 11:25 pm
Forum: Beginner Basics
Topic: Choosing router+switch pair for home net
Replies: 7
Views: 300

Re: Choosing router+switch pair for home net

The CRS can do wirespeed Switching, All routing (Incl Inter Vlan Traffic) goes via CPU and limited by that
by CZFan
Wed Dec 12, 2018 12:05 am
Forum: General
Topic: Brigde VLAN again [SOLVED]
Replies: 13
Views: 540

Re: Brigde VLAN again [SOLVED]

/interface bridge port add bridge=bridge1 frame-types=admit-all ingress-filtering=yes interface=sfp2 pvid=111 add bridge=bridge1 frame-types=admit-all ingress-filtering=yes interface=sfp3 pvid=111 add bridge=bridge1 frame-types=admit-all ingress-filtering=yes interface=sfp4 pvid=111 add bridge=brid...
by CZFan
Tue Dec 11, 2018 11:37 pm
Forum: Scripting
Topic: DHCP Binding Triggers Script
Replies: 9
Views: 297

Re: DHCP Binding Triggers Script

Good to hear. Note: you might want to run script by name, so you won't brake it in future
/system run script <name>
/system script run <name> :-)
by CZFan
Tue Dec 11, 2018 10:47 pm
Forum: Beginner Basics
Topic: Remove port from the default brige [SOLVED]
Replies: 17
Views: 512

Re: Remove port from the default brige [SOLVED]

Yes, cause 0x2^0 + 1 x 2^1 = 2 :-)
by CZFan
Tue Dec 11, 2018 7:43 pm
Forum: Beginner Basics
Topic: Remove port from the default brige [SOLVED]
Replies: 17
Views: 512

Re: Remove port from the default brige [SOLVED]

This is my understanding if you change from UAA to LAA: Convert the first octet from Hex to Bin, then change the 2nd-least-significant bit to 1, then convert back to Hex, i.e. B8 :69:F4:00:00:00 = 1011 1000, then change to 1011 10 1 0 back to Hex and the LAA MAC will then be BA :69:F4:00:00:00
by CZFan
Mon Dec 10, 2018 11:42 pm
Forum: Beginner Basics
Topic: sniffing tool
Replies: 1
Views: 119

Re: sniffing tool

Yes,

You can read all about it here: https://wiki.mikrotik.com/wiki/Manual:T ... et_Sniffer
by CZFan
Mon Dec 10, 2018 6:13 pm
Forum: Forwarding Protocols
Topic: no enforce-first-as in RouterOS?
Replies: 6
Views: 227

Re: no enforce-first-as in RouterOS?

What I explained is not to remove your AS, but the downstream private AS. i.e. Client (AS65500) ---- ISP (AS200) ---- Global Net At the ISP, they will strip the "Private AS" by using "Remove-Remote-AS" and only advertise aggregate. Anyway, seems this is only related to "Private AS" and possibly not ...
by CZFan
Mon Dec 10, 2018 5:40 pm
Forum: General
Topic: CCR1009-8 switch chip vlan & access ports
Replies: 10
Views: 279

Re: CCR1009-8 switch chip vlan & access ports

I am confused about the internet access port / vlan 112 part. Usually you will tag traffic going out, not coming in.

Can you elaborate a bit more what you are trying to achieve here, maybe confirm with the service provider how you are suppose to access internet services?
by CZFan
Mon Dec 10, 2018 4:33 pm
Forum: Forwarding Protocols
Topic: no enforce-first-as in RouterOS?
Replies: 6
Views: 227

Re: no enforce-first-as in RouterOS?

I am new to BGP, so take with a pinch of salt. This is usually used where an ISP (Upstream provider) needs to remove clients "private AS", and one of the requirements I understand is that the client then needs to have the same routing policy as the ISP. It is a setting called "Remove-Private-AS" in ...
by CZFan
Mon Dec 10, 2018 3:16 pm
Forum: General
Topic: Incorrect firewall behavious
Replies: 13
Views: 389

Re: Incorrect firewall behavious

... Of course people throw in drop invalid traffic and other things but if you have a drop everything else rule they will all be caught. .... My personal opinion the above is debatable, the last I checked part of the reason for dropping invalid was due to reasons that the packet might not be NATed ...
by CZFan
Mon Dec 10, 2018 3:03 pm
Forum: General
Topic: CCR1009-8 switch chip vlan & access ports
Replies: 10
Views: 279

Re: CCR1009-8 switch chip vlan & access ports

Is internet provided as a layer 2 or layer 3 service? Currently you have it configured as layer 2.

Maybe add a diagram so we an clearly see how things are connected

Just to confirm, are you sure the CCR1009 has a switch chip, it is my understanding that only fairly old CCR1009's have switch chips
by CZFan
Mon Dec 10, 2018 12:21 am
Forum: Beginner Basics
Topic: Simple Queue does not work [SOLVED]
Replies: 5
Views: 284

Re: Simple Queue does not work [SOLVED]

I highly doubt the above was the solution.

The queue types you mention there only changes the the queue "buffer" size, i.e. how many packets it will queue
by CZFan
Sun Dec 09, 2018 12:30 pm
Forum: Beginner Basics
Topic: Simple Queue does not work [SOLVED]
Replies: 5
Views: 284

Re: Simple Queue does not work [SOLVED]

IP address is assigned to ether2 directly, should be assigned to bridge that ether2 is a member of
by CZFan
Thu Dec 06, 2018 11:49 pm
Forum: General
Topic: Interface-list VS firewall address-list best practices and approach?
Replies: 8
Views: 276

Re: Interface-list VS firewall address-list best practices and approach?

Some Examples, but must use what makes sense to you,i.e.
Trusted Zone = LAN Zone
Untrusted Zone = WAN / Internet Zone
Semi Trusted Zone = DMZ Zone
etc
by CZFan
Thu Dec 06, 2018 6:32 pm
Forum: General
Topic: Interface-list VS firewall address-list best practices and approach?
Replies: 8
Views: 276

Re: Interface-list VS firewall address-list best practices and approach?

I use a mixture of both.

As you mentioned, Interface List is like "Zone" based, "trusted", "untrusted", etc. but sometimes need to be more granular, then I use Address Lists, etc
by CZFan
Tue Dec 04, 2018 11:43 am
Forum: RouterBOARD hardware
Topic: RB3011 vs RB4011
Replies: 1
Views: 402

Re: RB3011 vs RB4011

The only place I can see where the 3011 trumps the 4011 is you can do Vlan config in "software only " on 4011.

So the 4011 is a way better device, but will depend on what you planning to do with Vlans
by CZFan
Mon Dec 03, 2018 12:31 am
Forum: Beginner Basics
Topic: One /25 public subnet for 100 vlans without 1:1 nat?
Replies: 3
Views: 253

Re: One /25 public subnet for 100 vlans without 1:1 nat?

Can one subnet provide addressing for many vlans without 1:1 natting? I want one vlan per customer's CPE router, but instead of each vlan having its own /30, just one /25 is used across all vlans. The reason I want to do it this way is to avoid the use of PPPoE but still keep customer's traffic sepa...
by CZFan
Sat Dec 01, 2018 10:28 pm
Forum: The Dude
Topic: How to pass parameters to a function
Replies: 8
Views: 1809

Re: How to pass parameters to a function

Any news about this feature ?
Bump
by CZFan
Fri Nov 30, 2018 11:48 pm
Forum: Beginner Basics
Topic: Routing between 2 Subnets
Replies: 22
Views: 920

Re: Routing between 2 Subnets

Hi, I have configured several Subnets on my RB3011. All Subnets cannot see each other, it is disabled by FW-Rule. Now I would like to configure some exceptions. I have a local SIP Server on Subnet1 with IP: 192.168.1.10. Client on Subnet1 can connect correctly to the Server, but Clients on Subnet2(...
by CZFan
Tue Nov 27, 2018 11:56 pm
Forum: Beginner Basics
Topic: Routing between 2 Subnets
Replies: 22
Views: 920

Re: Routing between 2 Subnets

NTP = Network Time Protocol makes use of port 123
by CZFan
Mon Nov 26, 2018 11:53 pm
Forum: Beginner Basics
Topic: Avoid double PAT
Replies: 5
Views: 250

Re: Avoid double PAT

Ask ISPs to add route on CPEs to be our LAN range via the RB960.
by CZFan
Sun Nov 25, 2018 2:37 pm
Forum: General
Topic: L2TP/IPSec behind NAT
Replies: 8
Views: 333

Re: L2TP/IPSec behind NAT

You mention "On the modem I have configured VPN passthrough - IPSec and PPTP" but trying to configure L2TP, I would assume you will need to configure L2TP passthrough on the modem, if it is not there, then it is not supported on the modem and will not work
by CZFan
Sat Nov 24, 2018 4:32 pm
Forum: General
Topic: RB2001UiAS-2HnD-in poor routing speed
Replies: 3
Views: 193

Re: RB2001UiAS-2HnD-in poor routing speed

With my RB2011, when I changed from a 20/2 Mbps DSL link to 1000/100 Mbps fibre link, had the same issue. I added fasttrack and improved on my firewall rules and got ~850/97 Mbps through my RB2011. In my case the config was using DHCP client and not PPPoE on my router, but think with PPPoE you shoul...
by CZFan
Mon Nov 19, 2018 8:51 pm
Forum: General
Topic: How many VLANs do I need?
Replies: 8
Views: 346

Re: How many VLANs do I need?

You dont need to complicate things with Vlans, just use separate subnets and block with firewall
by CZFan
Sat Nov 17, 2018 11:37 pm
Forum: Beginner Basics
Topic: VLAN connect to internet
Replies: 6
Views: 321

Re: VLAN connect to internet

Why complicate things with VLAN's, just create your IPs on each interface
by CZFan
Mon Nov 12, 2018 11:43 am
Forum: Announcements
Topic: Newsletter 85
Replies: 31
Views: 7376

Re: Newsletter 85

And more LTE products with old and slow cat4 modems...I dont understand how can anyone even get more than 100mbit from this, i cant get more than 30mbit sitting next to tower, while anything else from super old mobile phone(6-7 years) to 2x cheaper routers achieve at least 2x speed if not more.. Wh...
by CZFan
Mon Nov 12, 2018 11:37 am
Forum: Beginner Basics
Topic: scrNAT'ed Trafic in the output queue?
Replies: 3
Views: 199

Re: scrNAT'ed Trafic in the output queue?

It is your router, telling the mail server that the host (Girlfriend Cell Phone) is not reachable, i.e. she has left the building
by CZFan
Thu Nov 01, 2018 10:55 pm
Forum: General
Topic: forward all traffic from one IP on all ports except 3
Replies: 1
Views: 113

Re: forward all traffic from one IP on all ports except 3

Minimum will be 2 rules, combine rules 1 and 2
by CZFan
Thu Nov 01, 2018 10:13 pm
Forum: Beginner Basics
Topic: Configure each port to its own broadcast domain (RB750Gr3)
Replies: 2
Views: 454

Re: Configure each port to its own broadcast domain (RB750Gr3)

Don't need any bridges then, best way is to simply configure the gateway ip on each port
by CZFan
Thu Nov 01, 2018 1:19 am
Forum: Beginner Basics
Topic: 3 VLANs on WAN [SOLVED]
Replies: 7
Views: 545

Re: 3 VLANs on WAN [SOLVED]

Remove all bridges, then add the VLAN's directly to ether 1, then create first bridge for ports 2-4 and wlan.
Then create another bridge, put eth5 and vlan14 in it
by CZFan
Sun Oct 28, 2018 7:58 pm
Forum: General
Topic: Tunnel between 2 MT where on one there is no public IP
Replies: 3
Views: 203

Re: Tunnel between 2 MT where on one there is no public IP

Do you need routed access between sites or must the be on same layer 2 network?

If routed, look at SSTP tunnel with one side that does not have public IP as a client and dial into the other site.

If you need layer 2, then look at bridge control protocol over SSTP
by CZFan
Fri Oct 26, 2018 7:38 pm
Forum: General
Topic: one to one NAT, access control [SOLVED]
Replies: 1
Views: 125

Re: one to one NAT, access control [SOLVED]

you mean something like below?
/ip firewall filter
add chain=forward in-interface=<WAN interface> dst-address=a.a.a.2 protocol=tcp port=!80,443 action=drop
by CZFan
Thu Oct 25, 2018 9:43 pm
Forum: General
Topic: RBSXTR&R11E-LTE and dual wan failover
Replies: 5
Views: 298

Re: RBSXTR&R11E-LTE and dual wan failover

The SXT LTE is directional, so other question will be is the towers of the 2 ISP's in same location?
by CZFan
Wed Oct 24, 2018 12:51 am
Forum: General
Topic: Get VLAN list with SNMP from bridge interface
Replies: 5
Views: 312

Re: Get VLAN list with SNMP from bridge interface

Use print oid
by CZFan
Tue Oct 23, 2018 1:32 am
Forum: General
Topic: 31 subnet - Not finding an answer to default gateway.
Replies: 16
Views: 728

Re: 31 subnet - Not finding an answer to default gateway.

Provide export of the routes
by CZFan
Tue Oct 23, 2018 1:30 am
Forum: General
Topic: CRS125 poor throughput & low cpu load [SOLVED]
Replies: 41
Views: 1460

Re: CRS125 poor throughput & low cpu load [SOLVED]

Well - the CRS is a switch...

Use a router for routing!
Could not agree more
by CZFan
Sun Oct 21, 2018 3:33 pm
Forum: General
Topic: BTest problem
Replies: 1
Views: 147

BTest problem

Is there any known problems with BTest, I am trying ti tests on a device ,

When I do in send, it seems to work properly
When I do in receive, it shows running, but shows 0 bytes
When I do in both, then it works for only couple of seconds and then says "no such test"
BTest.JPG
by CZFan
Sun Oct 21, 2018 11:49 am
Forum: General
Topic: Mass Managing Mikrotik
Replies: 11
Views: 1104

Re: Mass Managing Mikrotik

Look into the Tr069 protocol, there are both commercial and open source applications for this
i.e.
commercial - avsystem
open source - freeacs, genieacs
by CZFan
Fri Oct 19, 2018 11:56 pm
Forum: General
Topic: EoIP config help needed
Replies: 5
Views: 414

Re: EoIP config help needed

Your MT devices are behind a NATed device, so will not work.

You either need to put fiber routers which I suspect is ONU/ONT's, in bridge mode or configure port forwarding on them if that is possible
by CZFan
Thu Oct 18, 2018 9:35 pm
Forum: Beginner Basics
Topic: Routing and Switching
Replies: 2
Views: 235

Re: Routing and Switching

CCNA Routing and Switching Study Guide book

or online

http://www.freeccnastudyguide.com/study-guides/ccna/
by CZFan
Thu Oct 18, 2018 8:23 pm
Forum: General
Topic: CRS328 how to use as real router
Replies: 1
Views: 146

Re: CRS328 how to use as real router

Please note that the CRS328-24P-4S+RM is by design a switch with routing capabilities, so routing performance might not meet expectations. As example of configuring it, create a bridge and assign ports 2 - what ever to the bridge, this will form the switch part, then port 1 which is not part of the ...
by CZFan
Thu Oct 18, 2018 3:41 pm
Forum: Beginner Basics
Topic: Can't create wireless interface
Replies: 2
Views: 173

Re: Can't create wireless interface

HEX does not have wireless, you will have to connect a separate wifi access point
by CZFan
Wed Oct 17, 2018 11:07 pm
Forum: Beginner Basics
Topic: Hosts from 2 LAN's can't reach each other
Replies: 2
Views: 149

Re: Hosts from 2 LAN's can't reach each other

If the wlan is disabled, how can any client connect to the device via wlan?

You should remove wlan from bridge, then the clients on wlan will access the clients on LAN via layer 3. If not, you have firewall filter rules preventing this.
  • 1
  • 2
  • 3
  • 4
  • 5
  • 21