Community discussions

MikroTik App

Search found 1647 matches

by CZFan
Tue Jun 02, 2020 2:25 am
Forum: Beginner Basics
Topic: Router doesn't appear in Winbox interface despite reset procedure
Replies: 10
Views: 1272

Re: Router doesn't appear in Winbox interface despite reset procedure

If you followed the correct factory reset procedure, i.e. Power down router, press and hold reset button while powering up router until usr light starts flashing (about 5 to 7 seconds) release reset button. Then make sure you do not connect to ether1 of the router, but any other ether ports as there...
by CZFan
Tue Jun 02, 2020 1:58 am
Forum: Beginner Basics
Topic: Local Port definition and Port Forwarding
Replies: 2
Views: 201

Re: Local Port definition and Port Forwarding

Post output of "/export hide-sensitive" between code brackets, I.e.
by CZFan
Mon Jun 01, 2020 12:26 am
Forum: Beginner Basics
Topic: RTSP "TAB" Settings
Replies: 6
Views: 885

Re: RTSP Settings

IIRC, you have VLAN's in your environment, should not use RSTP then, but MSTP instead
by CZFan
Wed May 20, 2020 2:10 am
Forum: Beginner Basics
Topic: PPPOE client doesn't load some websites
Replies: 1
Views: 359

Re: PPPOE client doesn't load some websites

Sounds like it might be a fragmentation problem, change PPPoE MTU back to 1480, test again
by CZFan
Sat May 16, 2020 3:36 am
Forum: Beginner Basics
Topic: OSPF link with same subnets both ends
Replies: 2
Views: 652

Re: OSPF link with same subnets both ends

1.
Change subnet on one of the sites, then use whatever routing you want to
Or
2.
Bridge the sites using EOIP tunnel and merge them into the same broadcast domain. What out for duplicate IPs, etc
by CZFan
Thu May 14, 2020 2:13 am
Forum: Beginner Basics
Topic: VLAN for WAN?
Replies: 11
Views: 1376

Re: VLAN for WAN?

@OP:
First question, what speed internet do you have?
by CZFan
Thu May 14, 2020 1:59 am
Forum: Beginner Basics
Topic: simple queue
Replies: 7
Views: 1172

Re: simple queue

Parent Q max limit=10Mb
Child Q's:
Pc1 limit at 5Mb max limit 10Mb
Pc2 same as above.

This way, they each guaranteed 5Mb, if there is spare bandwidth, it will be used which ever device requested it and if only 1 device active, it will have full 10Mb available to it
by CZFan
Mon May 04, 2020 1:10 am
Forum: General
Topic: winbox or webfig does not show me anything in MPLS network
Replies: 2
Views: 875

Re: winbox or webfig does not show me anything in MPLS network

Sounds like MTU problem in network
by CZFan
Wed Apr 29, 2020 12:18 am
Forum: General
Topic: Splynx API required permissions
Replies: 1
Views: 948

Re: Splynx API required permissions

Bump
by CZFan
Fri Apr 24, 2020 1:29 pm
Forum: General
Topic: Splynx API required permissions
Replies: 1
Views: 948

Splynx API required permissions

I know this is not directly Mikrotik related, but did post on Splynx forum but not getting any response, so hope someone here can assist me. I followed the link below in order to provide Splynx API user permissions on Mikrotik but Splynx consultant insists that it requires "full admin permissions". ...
by CZFan
Sun Mar 29, 2020 10:59 pm
Forum: Announcements
Topic: v6.45.8 [long-term] is released!
Replies: 87
Views: 60624

Re: v6.45.8 [long-term] is released!

Is / has anyone else experience intermittent PPPoE drops with this version? I have a customer which is a fairly large ISP which and experiencing this. Besides for 1 router at a high site where the uplink ethernet interface goes up/down intermittently, the network is stable. I have pointed out the in...
by CZFan
Thu Mar 26, 2020 3:11 am
Forum: General
Topic: L2TP IPSec VPN not working from W10 (other Windows connects OK)
Replies: 4
Views: 963

Re: L2TP IPSec VPN not working from W10 (other Windows connects OK)

Can possibly be two scenarios, one is a register change if any of the devices are behind NAT.

Other is you need to connect using start->settings->VPN->the VPN you want to connect and click on connect there
by CZFan
Sat Mar 21, 2020 1:18 am
Forum: General
Topic: Best Tunnel MTU 1500 FOr PPPOE
Replies: 2
Views: 880

Re: Best Tunnel MTU 1500 FOr PPPOE

Depending on your network architecture, equipment, etc. the other option is to go OSPF/MPLS with VPLS
by CZFan
Thu Mar 19, 2020 10:40 pm
Forum: Beginner Basics
Topic: MikroTik Mtcna Home Learning
Replies: 13
Views: 2590

Re: MikroTik Mtcna Home Learning

Is there also an exam and a certificate as part of this effort, or is this just the training material...........

Mikrotik policy is you have to attend class based training to qualify for test / exam
by CZFan
Thu Mar 19, 2020 10:01 pm
Forum: General
Topic: Hello How can I change totallimit 2000 and limit 50
Replies: 9
Views: 1761

Re: Hello How can I change totallimit 2000 and limit 50

Can you repost the picture, can't access it
by CZFan
Wed Mar 18, 2020 12:34 pm
Forum: General
Topic: RB4011 SFP+ simple question
Replies: 1
Views: 880

Re: RB4011 SFP+ simple question

... i am looking at the data specs and it states that for 25 simple queues max troughput is just 4xx mbps which i think its very litle... ... I am not sure how you are reading the data specs, but the way I read it, for 25 simple queues, the max throughput is 9,792 Gb/s . You can probably expect a b...
by CZFan
Tue Mar 17, 2020 11:06 pm
Forum: General
Topic: 3CX NAT when using 2 Servers
Replies: 18
Views: 4136

Re: 3CX NAT when using 2 Servers

3cx has a packet capture facility, do a packet capture on 3cx server, view in wireshark to make sure correct port numbers are received by 3cx server from Mikrotik, if yes, then log call with 3cx, if no, come back here with packet capture details
by CZFan
Tue Mar 17, 2020 11:00 pm
Forum: General
Topic: Can't use vlan 1 as management vlan
Replies: 10
Views: 1983

Re: Can't use vlan 1 as management vlan

...
Update:
Tested it. Used
set 1 = ether 1
set 2 = ether 2
set 11 = switch1-cpu
...
Above is correct, the export seems to be screwed up in 6.46.4.

Apply as per my last post, then provide a full config, maybe there is a firewall rule or something preventing access.

use "export hide-sensitive"
by CZFan
Tue Mar 17, 2020 8:47 pm
Forum: Announcements
Topic: v6.46.4 [stable] is released!
Replies: 107
Views: 46112

Re: v6.46.4 [stable] is released!

Was playing with vlan on switch chip config, did an export, and some of the export config will be confusing for someone looking at it and not have access to the device, this was on a RB2011 /interface ethernet switch port set 1 vlan-header=add-if-missing vlan-mode=secure set 2 default-vlan-id=1 vlan...
by CZFan
Tue Mar 17, 2020 8:42 pm
Forum: General
Topic: Can't use vlan 1 as management vlan
Replies: 10
Views: 1983

Re: Can't use vlan 1 as management vlan

Not fully tested, but this seems to work on rb2011, which has the same switch chip /interface bridge add name=bridge1 protocol-mode=none /interface vlan add interface=bridge1 name=vlan1 vlan-id=1 /interface ethernet switch port set 1 vlan-header=add-if-missing vlan-mode=secure set 2 default-vlan-id=...
by CZFan
Tue Mar 17, 2020 7:01 pm
Forum: General
Topic: Can't use vlan 1 as management vlan
Replies: 10
Views: 1983

Re: Can't use vlan 1 as management vlan

IIRC, under /interface ethernet switch port you need to use vlan-header=leave-as-is on the Hap AC², etc
by CZFan
Mon Mar 16, 2020 6:34 pm
Forum: Beginner Basics
Topic: PPTP VPN
Replies: 1
Views: 1098

Re: PPTP VPN

Have you tried reading the Mikrotik Wiki?
by CZFan
Wed Mar 11, 2020 1:24 pm
Forum: Announcements
Topic: Winbox v3.22 released!
Replies: 117
Views: 45026

Re: Winbox v3.22 released!

I'm in love with new Log window :)
Ditto :-)
by CZFan
Wed Mar 11, 2020 1:23 pm
Forum: Announcements
Topic: Winbox v3.22 released!
Replies: 117
Views: 45026

Re: Winbox v3.22 released!

winbox64 is always opnening in a small window.....see picture :-(

I am not experiencing the same, Windows 10 version 1803
by CZFan
Mon Mar 09, 2020 11:32 pm
Forum: General
Topic: Multiple Internet Beakouts - cant connect via the Internet
Replies: 2
Views: 1190

Re: Multiple Internet Beakouts - cant connect via the Internet

To access the Mikrotik from Internet, you should not look under nat / mangle rules, but filter rules, and then look for chain=Input
by CZFan
Mon Mar 09, 2020 11:25 pm
Forum: General
Topic: How can I change the internet gateway metric? [SOLVED]
Replies: 11
Views: 3139

Re: How can I change the internet gateway metric? [SOLVED]

Measure the gate in imperial, then convert the numbers to metric and build a new gate based on the metric figures, voila :-)

Just joking, add a diagram, will make understanding what you want better
by CZFan
Mon Mar 09, 2020 7:21 pm
Forum: General
Topic: Router is infection by virus coinhive
Replies: 8
Views: 9139

Re: Router is infection by virus coinhive

If the old configuration were to contain some script, that sets passwords in your router and disables reinstall, it could do this before you run reset. @normis, Thank You, makes sense. Had a case where I suspected devices has been infected, did a netinstall but never checked if "keep old config" wa...
by CZFan
Mon Mar 09, 2020 1:32 pm
Forum: General
Topic: Router is infection by virus coinhive
Replies: 8
Views: 9139

Re: Router is infection by virus coinhive

I suggest to follow all MikroTik related news, this issue was fixed in April already. Please read instructions here: https://blog.mikrotik.com/security/winbox-vulnerability.html @normis, If I do a netinstall of an infected router, but "keep old configuration" is enabled, do an factory reset immedia...
by CZFan
Mon Mar 09, 2020 12:09 pm
Forum: Forwarding Protocols
Topic: OSPF Drops when adding a comment?
Replies: 13
Views: 3579

Re: OSPF Drops when adding a comment?

Is it normal for OSPF to drop / reload when only adding a comment on the OSPF
Try ro use CLI, i found that using
set comment="my comment" does not reset the session

I tested in CLI on GNS3 / CHR after the original incident, and did the same
by CZFan
Mon Mar 02, 2020 1:18 am
Forum: General
Topic: Vlan https issue
Replies: 9
Views: 2270

Re: Vlan https issue

Sounds like you have a MTU problem on your network
by CZFan
Sat Feb 29, 2020 3:39 pm
Forum: RouterBOARD hardware
Topic: OpenVPN Server config
Replies: 5
Views: 3015

Re: OpenVPN Server config

Also make sure you have a NAT/Masquerade rule to Internet for the VPN Subnet
by CZFan
Fri Feb 28, 2020 4:52 pm
Forum: Forwarding Protocols
Topic: OSPF Drops when adding a comment?
Replies: 13
Views: 3579

Re: OSPF Drops when adding a comment?

Wow, thx, did not expect that and dropped +- 1000 PPPoE connections earlier, ouch
by CZFan
Fri Feb 28, 2020 3:04 pm
Forum: Beginner Basics
Topic: proxy server
Replies: 1
Views: 1438

Re: proxy server

Take note that proxy will not work with HTTPS traffic, which is 90% of web traffic these days
by CZFan
Fri Feb 28, 2020 2:55 pm
Forum: Forwarding Protocols
Topic: OSPF Drops when adding a comment?
Replies: 13
Views: 3579

OSPF Drops when adding a comment?

Is it normal for OSPF to drop / reload when only adding a comment on the OSPF Interface?

RoS and Firmware 6.45.8 Long Term.
by CZFan
Mon Feb 24, 2020 3:30 pm
Forum: Announcements
Topic: v6.46.3 [stable] is released!
Replies: 28
Views: 35171

Re: v6.46.3 [stable] is released!

just had a case on a Hap AC2 where the 2,4 GHz wlan1 stopped running, nothing in the log file. Created supout file but when I restarted device to see if it solves the problem, the supout file created during the problem was deleted. (Supout file should be created in "/flash" if it exists by default) ...
by CZFan
Sun Feb 23, 2020 10:54 pm
Forum: General
Topic: 3CX NAT when using 2 Servers
Replies: 18
Views: 4136

Re: 3CX NAT when using 2 Servers

@anav,

Ports 9000 - 10999 is rtp ports, required for the voip audio, need 2 per voip conversation so nothing wrong there
by CZFan
Sun Feb 23, 2020 1:22 pm
Forum: Forwarding Protocols
Topic: Problem with a VPN Server Router behind Mikrotik
Replies: 4
Views: 2163

Re: Problem with a VPN Server Router behind Mikrotik

For PPTP you will also need the helper, i.e.
/ip firewall service-port
set pptp disabled=no
by CZFan
Sun Feb 23, 2020 12:27 am
Forum: General
Topic: 3CX NAT when using 2 Servers
Replies: 18
Views: 4136

Re: 3CX NAT when using 2 Servers

This is more a question for 3cx forum
by CZFan
Sun Feb 23, 2020 12:06 am
Forum: General
Topic: Ip Nat
Replies: 7
Views: 1725

Re: Ip Nat

You can setup an EOIP tunnel between office and home and access camera on dvr via via the tunnel
by CZFan
Sat Feb 22, 2020 11:47 pm
Forum: Beginner Basics
Topic: Multiple IP Pools on different LAN ports
Replies: 1
Views: 1127

Re: Multiple IP Pools on different LAN ports

The correct way will be to configure VLAN's for each subnet in a single bridge, alternative, you can remove ether4 from the current bridge and create the 2nd DHCP on ether4
by CZFan
Sat Feb 22, 2020 12:28 pm
Forum: Forwarding Protocols
Topic: OSPF Default Route not propigating.
Replies: 2
Views: 1579

Re: OSPF Default Route not propigating.

Just noticed the same thing, deployed OSPF for a customer Wednesday this week, the default route was being distributed at the time, checking this morning, it was not being distributed. Running 6.45.8 long term Changing distribute-default=always-as-type-1 to "never" and back to "always-as-type-1" cor...
by CZFan
Sat Feb 22, 2020 12:54 am
Forum: Beginner Basics
Topic: MT+SSTP VPN (VPN subnet + LAN all together?)
Replies: 5
Views: 2069

Re: MT+SSTP VPN (VPN subnet + LAN all together?)

There is a way to bind a route to the VPN interface, late here now, had my sleeping pill already, so maybe try google, if you don't come right, come back here
by CZFan
Sat Feb 22, 2020 12:48 am
Forum: Beginner Basics
Topic: VPN configuration bypass china firewall
Replies: 11
Views: 2957

Re: VPN configuration bypass china firewall

Here is my problem with this, you are asking someone to help you break the laws of the country, and that on a public forum?
by CZFan
Sat Feb 22, 2020 12:40 am
Forum: Beginner Basics
Topic: Native VLAN + 1 tagged VLAN
Replies: 3
Views: 1460

Re: Native VLAN + 1 tagged VLAN

What you are looking for is called hybrid vlan, see:

https://wiki.mikrotik.com/wiki/Manual:Bridge_VLAN_Table
by CZFan
Fri Feb 21, 2020 7:27 pm
Forum: Forwarding Protocols
Topic: BGP Route selection
Replies: 1
Views: 1446

Re: BGP Route selection

You seem to have multiple instances of BGP, see below. BGP weights, etc will not work between instances i.e.: " /routing bgp instance set default disabled=yes add as=65100 name=LDC router-id=10.15.155.2 add as=65100 name=VDC router-id=10.15.155.6 " Change this to be in the same instance, i.e. defaul...
by CZFan
Fri Feb 21, 2020 7:07 pm
Forum: General
Topic: Using the Loopback address for Software Upgrade/Checking for updates
Replies: 5
Views: 1371

Re: Using the Loopback address for Software Upgrade/Checking for updates

Sorry, have not played with IPv6 on RouterOS yet, and see there is no "NAT" in IP6 firewall.

I assumed that NAT, i.e. changing of a source address, etc, will still be there.

Best maybe is to see why your IP6 is not working properly on RouterOS, posting copy of config here and someone might assist
by CZFan
Fri Feb 21, 2020 12:55 pm
Forum: General
Topic: Using the Loopback address for Software Upgrade/Checking for updates
Replies: 5
Views: 1371

Re: Using the Loopback address for Software Upgrade/Checking for updates

Have you tried a source NAT rule to the Mikrotik FTP server?
by CZFan
Fri Feb 21, 2020 12:05 pm
Forum: Beginner Basics
Topic: Date format Please Help
Replies: 5
Views: 1459

Re: Date format Please Help

Date.JPG
by CZFan
Fri Feb 21, 2020 11:17 am
Forum: Beginner Basics
Topic: Help with VLAN setup
Replies: 4
Views: 1552

Re: Help with VLAN setup

It should be simple: - bridge all ports together - bridge itself is your untagged LAN - give PVID 2 to bridge port ether1 - add VLAN interface with id 2 on bridge - VLAN interface is your new WAN - configure VLAN assigment on bridge (in Bridge->VLANs), add VLAN 2 as untagged on ether1 and tagged on...
by CZFan
Fri Feb 21, 2020 10:43 am
Forum: General
Topic: RB2011UiAS looses about 40 megabits of thgougpput!?!
Replies: 49
Views: 6454

Re: RB2011UiAS looses about 40 megabits of thgougpput!?!

So they are choosing wireless pollution and high latency? I suppose the problem here is that the current copper cabling infrastructure is so old and causing lots and lots of problems. To make that worse, the copper cabling theft here is huge, Telkom or the electricity companies will replace a cable...
by CZFan
Thu Feb 20, 2020 7:54 pm
Forum: General
Topic: RB2011UiAS looses about 40 megabits of thgougpput!?!
Replies: 49
Views: 6454

Re: RB2011UiAS looses about 40 megabits of thgougpput!?!

... In the past I even bought a SFP VDSL modem for it, to replace the Draytek 130 VDSL modem I use at home. But that never really worked, mostly because RouterOS does not include support for it to readout the line parameters and MikroTik apparently isn't interested in VDSL (I can understand they do...
by CZFan
Thu Feb 20, 2020 6:33 pm
Forum: RouterBOARD hardware
Topic: CCR1009 collision and loop
Replies: 7
Views: 3114

Re: CCR1009 collision and loop

Start by looking at the cable between the CCR and netgear device, replace if necessary
by CZFan
Thu Feb 20, 2020 6:30 pm
Forum: General
Topic: Using the Loopback address for Software Upgrade/Checking for updates
Replies: 5
Views: 1371

Re: Using the Loopback address for Software Upgrade/Checking for updates

not sure I understand correctly, but Mikrotik ping has source address attribute / switch?
by CZFan
Thu Feb 20, 2020 6:26 pm
Forum: General
Topic: RB2011UiAS looses about 40 megabits of thgougpput!?!
Replies: 49
Views: 6454

Re: RB2011UiAS looses about 40 megabits of thgougpput!?!

@vortex,

Yes, I hear you and agree,but for a 25Mb/s internet connection, the RB2011 is over priced as that can be achieved with a hap mini.

Should the RB2011 had 10 x 1Gb/s ports, I can see a longer life time
by CZFan
Thu Feb 20, 2020 6:00 pm
Forum: General
Topic: RB2011UiAS looses about 40 megabits of thgougpput!?!
Replies: 49
Views: 6454

Re: RB2011UiAS looses about 40 megabits of thgougpput!?!

@pe1chl, yes, you are right, I think the typical networks these days and types fast FTTh connections users have at home, it is maybe time for this little "work horse" to retire :-)

To me, the RB2011 is like Novell, still have a very soft spot for it but times have moved on and so should we
by CZFan
Thu Feb 20, 2020 5:21 pm
Forum: General
Topic: QinQ advice needed!
Replies: 12
Views: 2563

Re: QinQ advice needed!

Wow, for once, I can maybe assist @Sob, For "Provider Bridge" config, you don't need to add a vlan sub interface which is probably reason your config failed, the bridge (new bridge vlan filtering way) looks at ether type, and will add the SVID based on the pvid value of the customer facing "access p...
by CZFan
Thu Feb 20, 2020 5:11 pm
Forum: General
Topic: RB2011UiAS looses about 40 megabits of thgougpput!?!
Replies: 49
Views: 6454

Re: RB2011UiAS looses about 40 megabits of thgougpput!?!

I max out my 500/50 connection with the 2011 but I don't use queues.

Agree, I use to get +- 850 with my RB2011 on a 1000/100 Mb/s FTTh link. Had about 15 Firewall rules, no PPPoE though, was DHCP assigned IP. Latency was also super slow, my son use to kill the others while gaming
by CZFan
Thu Feb 20, 2020 3:50 pm
Forum: General
Topic: RB2011UiAS looses about 40 megabits of thgougpput!?!
Replies: 49
Views: 6454

Re: RB2011UiAS looses about 40 megabits of thgougpput!?!

Have you tried with:

/interface bridge settings
set use-ip-firewall=no
by CZFan
Thu Feb 20, 2020 3:27 pm
Forum: Beginner Basics
Topic: Date format Please Help
Replies: 5
Views: 1459

Re: Date format Please Help

you looking for something like this?
:local mydate ([:pick [/system clock get date] 4 6] . [:pick [/system clock get date] 0 3] . [:pick [/system clock get date] 7 11]);
by CZFan
Thu Feb 20, 2020 1:11 pm
Forum: General
Topic: QinQ advice needed!
Replies: 12
Views: 2563

Re: QinQ advice needed!

The s-tag side needs to be confirmed as usually that is done on the ISP switch and commonly known as "provider bridge" config. With this, customers can then pass through any vlans they want. If above is correct, then all you have to do is standard vlan config on Hex. Confirm above first and post bac...
by CZFan
Wed Feb 19, 2020 11:09 pm
Forum: General
Topic: Getting IP From Vlans But wont connet to internet. [SOLVED]
Replies: 6
Views: 1890

Re: Getting IP From Vlans But wont connet to internet. [SOLVED]

Where is internet break out for site B?
by CZFan
Wed Feb 19, 2020 11:06 pm
Forum: General
Topic: QinQ advice needed!
Replies: 12
Views: 2563

Re: QinQ advice needed!

Sorry, don't like problems just thrown over the wall hoping someone will catch it and do it for you.

What have you tried so far, export of config what you tried?
by CZFan
Tue Feb 18, 2020 11:27 pm
Forum: Scripting
Topic: Scheduler issue
Replies: 6
Views: 2001

Re: Scheduler issue

You should only need "read" & "write" permissions

Try and add below before the script name in the scheduler
/system script run <NameOfScript>
by CZFan
Tue Feb 18, 2020 5:18 pm
Forum: Beginner Basics
Topic: Can't ping from one subnet to another created od diffs ports on router
Replies: 5
Views: 1525

Re: Can't ping from one subnet to another created od diffs ports on router

Not necessarily the correct way, but with the limited information you provide, NATing everything out the bridge interface should give internet access to all devices behind the CCR
by CZFan
Tue Feb 18, 2020 2:16 pm
Forum: Beginner Basics
Topic: Can't ping from one subnet to another created od diffs ports on router
Replies: 5
Views: 1525

Re: Can't ping from one subnet to another created od diffs ports on router

can you provide results of below command in CLI?

/export hide-sensitive
by CZFan
Tue Feb 18, 2020 1:09 pm
Forum: Beginner Basics
Topic: Can't ping from one subnet to another created od diffs ports on router
Replies: 5
Views: 1525

Re: Can't ping from one subnet to another created od diffs ports on router

Look at your firewall rules, start with the ones on client devices
by CZFan
Mon Feb 17, 2020 10:02 pm
Forum: Beginner Basics
Topic: MT+SSTP VPN (VPN subnet + LAN all together?)
Replies: 5
Views: 2069

Re: MT+SSTP VPN (VPN subnet + LAN all together?)

Not sure if you noticed, but this is Mikrotik forum, not Microsoft / Windows.

Anyway, the way you have added the route it will not survive a restart, you have to use the "persistent" switch.

Best way will be to enable using the default gateway on remote network when you configure the VPN client.
by CZFan
Mon Feb 17, 2020 3:56 pm
Forum: Beginner Basics
Topic: RouterOS - NAT problem (dst-nat)
Replies: 27
Views: 4307

Re: RouterOS - NAT problem (dst-nat)

hi
I want to create a PPPoE server but I have a poor concept about firewall so I want to set firewall rules for my users. so I need some standard firewall rules for PPPoE server.
...
https://wiki.mikrotik.com/wiki/Manual:TOC
Alternatively
https://mikrotik.com/consultants
by CZFan
Mon Feb 17, 2020 3:46 pm
Forum: General
Topic: PCQ Queues
Replies: 2
Views: 933

Re: PCQ Queues

Do you have fasttrack enabled? Either disable it or do more specific configuration for fasttrack
by CZFan
Mon Feb 17, 2020 3:28 pm
Forum: General
Topic: No more than 160 Mbps in a 600 Mbps with RouterBOARD 2011UiAS-2HnD
Replies: 6
Views: 1731

Re: No more than 160 Mbps in a 600 Mbps with RouterBOARD 2011UiAS-2HnD

@OP, please be more specific, is the 160Mb/s via LAN cable or wifi?
by CZFan
Thu Feb 13, 2020 1:22 pm
Forum: Wireless Networking
Topic: CPU utilization is too high
Replies: 2
Views: 1553

Re: CPU utilization is too high

Contact one closest to you:
https://mikrotik.com/consultants
by CZFan
Thu Feb 13, 2020 12:08 pm
Forum: General
Topic: UDP broadcast does not work in vlan
Replies: 3
Views: 1154

Re: UDP broadcast does not work in vlan

first need to understand your problem properly, broadcasts should not be able to cross vlans, so when you are saying you sending a broadcast and want to get this on another vlan, what exactly do you mean / doing?
by CZFan
Wed Feb 12, 2020 4:51 pm
Forum: Forwarding Protocols
Topic: Very strange BGP Best Route Selection
Replies: 4
Views: 2121

Re: Very strange BGP Best Route Selection

I think the answer to your question is point 2 in the quoted URL.

The route engine received the first path from the default BGP instance, and does not see the path from the other instance as "better" since the distance is 20 for both, hence it keeps the first path received
by CZFan
Tue Feb 11, 2020 9:44 pm
Forum: General
Topic: Possible fix for hAP ac2 rebooting randomly
Replies: 103
Views: 16826

Re: Possible fix for hAP ac2 rebooting randomly

Davis , Yes, I'm using IPSec in an L2TP tunnel on my router. After removing the NTP packet, the reboots stopped for 2 days. Then I installed this package again, turned off watchdog, and after 38 hours the router crashed without showing any signs of life. Now I have enabled watchdog and removed the ...
by CZFan
Tue Feb 11, 2020 9:36 pm
Forum: General
Topic: LAN Bridge works fine only with "USE IP Firewall" option, or torch enabled
Replies: 13
Views: 2318

Re: LAN Bridge works fine only with "USE IP Firewall" option, or torch enabled

... My question only applies to the firewall on the bridge. LAN is unstable when I disable "Use IP Firewall" option. It works fine also, when that option is disabled, and Torch is enabled for checking traffic in that interfaces. Only on ether, that have the same MAC address like bridge interface wo...
by CZFan
Sun Feb 09, 2020 3:34 am
Forum: General
Topic: UDP broadcast does not work in vlan
Replies: 3
Views: 1154

Re: UDP broadcast does not work in vlan

If you are sending broadcasts, you should not see it in any other vlan. If you do, you config is wrong and the limited information about config supplied is not sufficient to help
by CZFan
Fri Feb 07, 2020 4:05 pm
Forum: RouterBOARD hardware
Topic: CRS317 326 and 328 performance problem ?
Replies: 16
Views: 4474

Re: CRS317 326 and 328 performance problem ?

...
Do we really need to change the brand ?
Not sure if I am in a bad mood today, but when someone comes here and asks for help, and then puts a comment like above in their post, I am loath to even attempt to assist
by CZFan
Mon Feb 03, 2020 11:30 pm
Forum: General
Topic: Public IP server natted on internal subnet
Replies: 3
Views: 621

Re: Public IP server natted on internal subnet

Search for hairpin nat
by CZFan
Mon Feb 03, 2020 12:08 pm
Forum: General
Topic: EoIP over PPTP problem - only one side comes up?
Replies: 6
Views: 1072

Re: EoIP over PPTP problem - only one side comes up?

Very good point, changed pool to only .250 and modified all the tunnels, still seems the EoIP doesn't want to come up... EoIP over internet directly, is it secure? M Secure? you were making use of PPTP, which is not secure at all! EoIP has IPSec option built in to encrypt data travelling across tun...
by CZFan
Sun Feb 02, 2020 11:36 pm
Forum: Beginner Basics
Topic: Preventing physical ports from using WAN port
Replies: 5
Views: 1426

Re: Preventing physical ports from using WAN port

... but I'm too afraid of having the wrong settings in the MikroTik.

Regards,
Martijn
I am afraid, you will then never learn networking. To learn / understand networking, especially in the beginning, there will always be lots of breaks, research, fix, rinse and repeat cycles
by CZFan
Sun Feb 02, 2020 2:17 am
Forum: General
Topic: EoIP over PPTP problem - only one side comes up?
Replies: 6
Views: 1072

Re: EoIP over PPTP problem - only one side comes up?

Why use EOIP on top of PPTP? Just use EOIP straight
by CZFan
Sat Feb 01, 2020 4:00 pm
Forum: General
Topic: DAC detected but no link [SOLVED]
Replies: 2
Views: 726

Re: DAC detected but no link [SOLVED]

I have not checked compatibility table, but try and disable auto negotiation and set speed / duplex to 1Gb/Full on both devices
by CZFan
Sat Feb 01, 2020 3:43 pm
Forum: General
Topic: Public/Private IP on single interface
Replies: 2
Views: 587

Re: Public/Private IP on single interface

Can work, suggest make use of Vlans between the router and switch to logically separate the private traffic from public traffic
by CZFan
Fri Jan 31, 2020 12:19 am
Forum: General
Topic: Port Forwarding Broken?
Replies: 4
Views: 624

Re: Port Forwarding Broken?

I am not a gamer, but IIRC, to get "open" on the console, it must be directly connected to the Internet. One way of achieving this I suppose is to route a /29 to the customer, then at customer side, bridge 2 ports for the WAN. One port used for actual WAN and other for the console, then configure on...
by CZFan
Thu Jan 30, 2020 12:57 am
Forum: General
Topic: Help! NAT rule says Connection Tracking not on, but it's on!
Replies: 5
Views: 661

Re: Help! NAT rule says Connection Tracking not on, but it's on!

Lol, I think you have 2 choices:
1. Do a netinstall to correct it.
2. Send a supout file to Mikrotik support and ask for a favor if they can see how you got into this and how to get out of it.

Then please do tell :-)
by CZFan
Thu Jan 30, 2020 12:52 am
Forum: General
Topic: Port Forwarding Broken?
Replies: 4
Views: 624

Re: Port Forwarding Broken?

To add to what @Zacharias said, also try and remove NAT on your CCR
by CZFan
Thu Jan 30, 2020 12:21 am
Forum: Wireless Networking
Topic: Strange behaviour on 5 GHz radio with 6.46.x RouterOS
Replies: 3
Views: 1460

Re: Strange behaviour on 5 GHz radio with 6.46.x RouterOS

5GHz has a multitude of channels to scan, try and reduce this with scan lists and see if it helps
by CZFan
Wed Jan 29, 2020 4:29 pm
Forum: Announcements
Topic: v6.45.8 [long-term] is released!
Replies: 87
Views: 60624

Re: v6.45.8 [long-term] is released!

...
it's a regular firmware (6.45.7 in our case) plus bugfixes and improvements only, without adding new functionality

I suspect the long term version does include new functionality, but only once it has been vetted via the stable release
by CZFan
Mon Jan 27, 2020 11:14 pm
Forum: Forwarding Protocols
Topic: OSPF Transit Fabric
Replies: 8
Views: 2041

Re: OSPF Transit Fabric

I’ve just received an answer from MikroTik: Thank you for the report. There is a known problem with enabled connection tracking and fragmented packets. If OSPF packet is being fragmented, then connection tracking passes it to OSPF twice, causing an error. Currently as a workaround I can suggest to ...
by CZFan
Mon Jan 27, 2020 7:44 pm
Forum: Wireless Networking
Topic: RBwAP2nD connected users
Replies: 10
Views: 2532

Re: RBwAP2nD connected users

...
sorry, mistyped, it not CSS but CRS326-24G-2S+RM as the main router
Same applies as per @Zacharias, rather get an additional device for the routing, i.e. Hex
by CZFan
Mon Jan 27, 2020 5:52 pm
Forum: General
Topic: BUG? Restore from hAP ac to ac2 reverses ports
Replies: 2
Views: 535

Re: BUG? Restore from hAP ac to ac2 reverses ports

"Backup" utility is only meant for using between exactly same device for exactly these reasons, i.e. something went corrupt in software / config, then you use the backup to apply to the same device you made the backup from. They way to use between different devices is to "export" config, then edit a...
by CZFan
Sun Jan 26, 2020 9:54 pm
Forum: Beginner Basics
Topic: vlan tagging between router and switch not working [SOLVED]
Replies: 8
Views: 1887

Re: vlan tagging between router and switch not working [SOLVED]

You don't need to set switch-cpu as tagged, the bridge interface is the switch CPU port.

You seem to have configured VLAN's via switch and bridge config. Set ether5 under switch vlan menu back to defaults and test again
by CZFan
Sun Jan 26, 2020 3:12 pm
Forum: General
Topic: RouterOS - Disassoc / Deauth client via cli?
Replies: 2
Views: 654

Re: RouterOS - Disassoc / Deauth client via cli?

Remove the client device in wireless registration table via CLI, i.e. /interface wireless registration-table remove numbers=?,?,? or /interface wireless registration-table remove [find where comment="Client1"] or /interface wireless registration-table remove [find where comment~"ient1"] or /interfac...
by CZFan
Sun Jan 26, 2020 2:17 pm
Forum: Beginner Basics
Topic: Dumb DHCP Server Question
Replies: 3
Views: 1098

Re: Dumb DHCP Server Question

Depends on your requirements, but typically, read default, it is off
by CZFan
Sun Jan 26, 2020 4:49 am
Forum: Beginner Basics
Topic: routing problem [SOLVED]
Replies: 7
Views: 1697

Re: routing problem [SOLVED]

What is client IP address when ping from downstream, suspect that radio does not have route to client ip hence sending the packet upstream via gateway instead of back to client device
by CZFan
Sun Jan 26, 2020 4:42 am
Forum: Beginner Basics
Topic: Dumb DHCP Server Question
Replies: 3
Views: 1098

Re: Dumb DHCP Server Question

My understanding is that it is suppose to add MACs from DHCP clients dynamically to ARP table, then you can prevent people using static IP config by setting interface ARP mode to reply only.

Have not tested it myself yet, but IIRC, read a couple of posts saying it does not work
by CZFan
Sun Jan 26, 2020 4:28 am
Forum: General
Topic: RBSXTR bridge Problem
Replies: 1
Views: 436

Re: RBSXTR bridge Problem

I think you need to re read the wiki info, based on the info in diagram you posted, it looks totally wrong and setting up EoIP is not rocket science stuff
by CZFan
Sat Jan 25, 2020 3:21 pm
Forum: RouterBOARD hardware
Topic: RB411 no ethernet connection
Replies: 48
Views: 7012

Re: RB411 no ethernet connection

Have you tried with baud rate = 9600
by CZFan
Sat Jan 25, 2020 2:19 pm
Forum: General
Topic: What is the solution of whole update Mikrotik without Not enough disk space?
Replies: 35
Views: 3490

Re: What is the solution of whole update Mikrotik without Not enough disk space?

Contact one closest to you for this and other Mikrotik problems you are experiencing

https://mikrotik.com/consultants
by CZFan
Fri Jan 24, 2020 5:38 pm
Forum: General
Topic: What is the solution of whole update Mikrotik without Not enough disk space?
Replies: 35
Views: 3490

Re: What is the solution of whole update Mikrotik without Not enough disk space?

.... And of course you must be able to reach internet from the device. So in Tools->Ping try to ping 8.8.8.8. That must work. When not, fix it first. (check IP->Routes etc) It is much better to check ping mikrotik.com as it checks not only Internet access but also a DNS resolver. No, you need to pi...
by CZFan
Fri Jan 24, 2020 3:44 pm
Forum: General
Topic: Quality of Service
Replies: 3
Views: 601

Re: Quality of Service

This very much depends on your environment, and there is not a one size fits all.

Suggestion will be to contact a certified consultant closes to you

https://mikrotik.com/consultants
by CZFan
Thu Jan 23, 2020 2:54 pm
Forum: Forwarding Protocols
Topic: OSPF Transit Fabric
Replies: 8
Views: 2041

Re: OSPF Transit Fabric

Sounds like a loop in the network, but the timing of 30 minutes is confusing me a bit.

I have seen people reporting that disabling neighbor discovery solves the problem, also (R)STP, but that might just hide an actual problem. With the various vlans, maybe configure MSTP if not already done
by CZFan
Wed Jan 22, 2020 5:27 pm
Forum: General
Topic: My public IP is getting raped by port scanners - is that normal?
Replies: 24
Views: 3590

Re: My public IP is getting raped by port scanners - is that normal?

restart your router to get new IP
Did he say he was on a dynamic address?
No. So it's not the most sensible suggestion.

Did he say he is on static? So you can take you comment and shove it
by CZFan
Wed Jan 22, 2020 12:02 am
Forum: General
Topic: My public IP is getting raped by port scanners - is that normal?
Replies: 24
Views: 3590

Re: My public IP is getting raped by port scanners - is that normal?

Looks more like a SYN flood, restart your router to get new IP
by CZFan
Mon Jan 20, 2020 11:40 am
Forum: Forwarding Protocols
Topic: question about bgp community
Replies: 5
Views: 1690

Re: question about bgp community

I dont think it can be done in one rule, just create an accept rule for the community one, then another for the no community one before your discard rule
by CZFan
Sun Jan 19, 2020 2:19 pm
Forum: Beginner Basics
Topic: VPN recommendations (security over ease/speed)
Replies: 5
Views: 1291

Re: VPN recommendations (security over ease/speed)

You can also look into L2TP/IPSec, IKE/IKEv2 VPNs
by CZFan
Sun Jan 19, 2020 2:14 pm
Forum: Wireless Networking
Topic: Hap AC2 extreme slow wifi
Replies: 16
Views: 4937

Re: Hap AC2 extreme slow wifi

Client device's Wi-Fi data rate will not exceed 54 Mbps when wired equivalent privacy (WEP) or temporal key integrity protocol (TKIP) encryption is configured. The IEEE* 802.11n prohibits using high throughput with WEP or TKIP as the unicast cipher. If you use these encryption methods, your data ra...
by CZFan
Sun Jan 19, 2020 2:09 pm
Forum: General
Topic: hEX S (RB760iGS) Winbox Login failed,How to log in to the console
Replies: 3
Views: 551

Re: hEX S (RB760iGS) Winbox Login failed,How to log in to the console

If device has been compromised, they might have disabled these services, then the only way to recover device is by netinstall, but you will lose current config though.
by CZFan
Sun Jan 19, 2020 2:04 pm
Forum: Wireless Networking
Topic: Hap AC2 extreme slow wifi
Replies: 16
Views: 4937

Re: Hap AC2 extreme slow wifi

@mozerd, Thx, my post was not to question / dispute what you said, I have little radio frequency technical knowledge and have a natural inquiring mind when it comes to technical stuff and like to understand why, how, etc. to learn more I understand that encryption using CPU will tax the CPU, but did...
by CZFan
Sun Jan 19, 2020 12:23 am
Forum: Wireless Networking
Topic: Hap AC2 extreme slow wifi
Replies: 16
Views: 4937

Re: Hap AC2 extreme slow wifi

I understand that tkip is old technology and deprecated and fully anderstand that it can have a huge performance impact on devices like hap lite or even RB2011.
Now the hap ac2 is not a beast, but this CPU runs circles around the 2011. So my question is why such a big performance hit on hap ac2?
by CZFan
Sat Jan 18, 2020 9:04 pm
Forum: General
Topic: Route not going unreachable !!!
Replies: 17
Views: 1998

Re: Route not going unreachable !!!

can you post a redacted / sanitized version of "/export hide-sensitive" so we can have a look?
by CZFan
Sat Jan 18, 2020 8:48 pm
Forum: General
Topic: Devices behind switches not seen by devices on mikrotik
Replies: 13
Views: 1877

Re: Devices behind switches not seen by devices on mikrotik

...
SO I can see the Mac Mini from the Plex. But not vice versa.

If this is the result after setting bridge protocol mode to none, then you might possibly have a loop in your network causing the problems
by CZFan
Sat Jan 18, 2020 1:17 pm
Forum: General
Topic: Protect from hacking router
Replies: 5
Views: 1062

Re: Protect from hacking router

The device was probably compromised before you did software update, the ONLY way to correct that is to do a Netinstall
by CZFan
Sat Jan 18, 2020 1:12 pm
Forum: General
Topic: Route not going unreachable !!!
Replies: 17
Views: 1998

Re: Route not going unreachable !!!

That route, although it says reachable via ether6, will not be used by the router as the route is not "Active"

What you seeing might be a Winbox refresh thing, do you see the same when doing a /ip route print in cli?
by CZFan
Fri Jan 17, 2020 10:49 pm
Forum: General
Topic: Protect from hacking router
Replies: 5
Views: 1062

Re: Protect from hacking router

That article seems to be from the year 2012. Many security enhancements in Mikrotik since then.

Make sure you run at least the latest long tern version of ROS, have secure passwords and not allowing services to be open directly to Internet
by CZFan
Fri Jan 17, 2020 9:07 pm
Forum: General
Topic: Devices behind switches not seen by devices on mikrotik
Replies: 13
Views: 1877

Re: Devices behind switches not seen by devices on mikrotik

@mkx, no way that you will know, but fyi, Cool Ideas is the ISP's name so ether1 is the WAN

Also had a brief look through config, and besides what you mentioned, dont see anything else wrong and my suspicion is that problem is downstream to the other devices / switches
by CZFan
Fri Jan 17, 2020 5:46 pm
Forum: General
Topic: Traffic segmentation on an interface level?
Replies: 8
Views: 1301

Re: Traffic segmentation on an interface level?

@mkx, yes, you are correct, should have worded my post better, was more related to @cdiedrich's post re CPU going nuts with horizon config
by CZFan
Fri Jan 17, 2020 4:23 pm
Forum: General
Topic: Traffic segmentation on an interface level?
Replies: 8
Views: 1301

Re: Traffic segmentation on an interface level?

I dont see in OP what model the switch is and or topology, but what about switch port isolation?
by CZFan
Fri Jan 17, 2020 12:17 pm
Forum: Announcements
Topic: v6.46.2 [stable] is released!
Replies: 121
Views: 31189

Re: v6.46.2 [stable] is released!

LeftyTs, the downloaded files are no longer visible in /files section when using Package Updater. You can still reboot the device and it will upgrade. Or use /sys pac upd cancel to free the storage.

Is this mentioned in the change details? Documented in Wiki?
by CZFan
Tue Jan 14, 2020 11:46 pm
Forum: General
Topic: Route not going unreachable !!!
Replies: 17
Views: 1998

Re: Route not going unreachable !!!

First question, which ROS version?
by CZFan
Mon Jan 13, 2020 10:07 pm
Forum: General
Topic: Assign static IP address to VPN client problem
Replies: 9
Views: 1263

Re: Assign static IP address to VPN client problem

Totally agree with @cdiedrich, but if you insist, and to expand on what @Zacharias said, you will need to configure proxy-arp on the LAN facing interface, may it be physical, bridge or vlan If that does not work, then you might have other network problems, i.e. firewall rules, routing issues, etc an...
by CZFan
Sun Jan 12, 2020 1:09 pm
Forum: Beginner Basics
Topic: help with basic setup
Replies: 6
Views: 1179

Re: help with basic setup

" how to “connect” the bridge to WAN? .. sorry im very much a noob at this"

This will be the "routing" part, so based on the IP configuration, etc, it will route from the bridge to WAN
by CZFan
Sat Jan 11, 2020 1:50 pm
Forum: General
Topic: Voip phone with PC access port? [SOLVED]
Replies: 6
Views: 1061

Re: Voip phone with PC access port? [SOLVED]

configure CRS port as a trunk port for the relevant vlans, then do tagging on the phone for phone and pc.

FYI, Grandstream support is this way ---->
by CZFan
Thu Jan 09, 2020 11:39 pm
Forum: General
Topic: firewall vs nat packet flow
Replies: 8
Views: 1521

Re: firewall vs nat packet flow

NATed traffic do go via firewall. In default config there is a rule that accepts Dst NATed packets.

If you want more control, change / remove this rule
by CZFan
Wed Jan 08, 2020 4:56 pm
Forum: General
Topic: What does "defconf" mean?
Replies: 6
Views: 1192

Re: What does "defconf" mean?

That is "DEFCON", and not "DEFCONF" :-)
by CZFan
Wed Jan 08, 2020 4:35 pm
Forum: General
Topic: RSTP, Stability...
Replies: 2
Views: 491

Re: RSTP, Stability...

or contact a certified Mikrotik consultant to physically meet you onsite and look at your network

https://mikrotik.com/consultants
by CZFan
Wed Jan 08, 2020 4:34 pm
Forum: Wireless Networking
Topic: SXTsq 5 ac loosing http/webfig access after applying PtP bridge AP mode, pings OK :/
Replies: 13
Views: 2404

Re: SXTsq 5 ac loosing http/webfig access after applying PtP bridge AP mode, pings OK :/

Maybe start with posting the config of the devices, failing that, maybe contact a certified Mikrotik consultant to physically meet you onsite

https://mikrotik.com/consultants
by CZFan
Wed Jan 08, 2020 3:43 pm
Forum: Beginner Basics
Topic: Nested simple quque
Replies: 6
Views: 1314

Re: Nested simple quque

@CZFan, name tab does the same...

Not disagreeing with you, I just always used the "#" header
by CZFan
Wed Jan 08, 2020 12:54 pm
Forum: General
Topic: Bring Tapatalk back
Replies: 26
Views: 3557

Re: Bring Tapatalk back


BTW, not only that relative time format is ugly and non-informative, ...

Maybe I am just getting old and becoming more resistive to change, but I agree with above
by CZFan
Wed Jan 08, 2020 11:46 am
Forum: Announcements
Topic: v6.46.1 [stable] is released!
Replies: 72
Views: 33908

Re: v6.46.1 [stable] is released!

Can you disable DHCP package? When I disable DHCP package, after restart it is enable again.
I read a while ago that DHCP package is now a prerequisite for the security package, so maybe that is reason it enables when restart
by CZFan
Tue Jan 07, 2020 9:42 pm
Forum: Beginner Basics
Topic: Invalid user/pass after reset
Replies: 16
Views: 1786

Re: Invalid user/pass after reset

No, something does not sound right here, especially if you say you had the same problem recently on a 260, which runs switchos and not ros.

Make sure basics are correct, i.e.
1. Your reset procedure is correct
2. Your CAPS lock is not on, etc.
3. You are trying to access the correct device,
4. etc
by CZFan
Tue Jan 07, 2020 7:03 pm
Forum: Beginner Basics
Topic: Crs305 not able to get ip on Wan port [SOLVED]
Replies: 14
Views: 2143

Re: Crs305 not able to get ip on Wan port [SOLVED]

What does your ISP use, DHCP or PPPoE?
by CZFan
Tue Jan 07, 2020 6:37 pm
Forum: Beginner Basics
Topic: Nested simple quque
Replies: 6
Views: 1314

Re: Nested simple quque

left click on "#" column header
q1.JPG
q2.JPG
by CZFan
Tue Jan 07, 2020 12:24 pm
Forum: Beginner Basics
Topic: Terminology - NAT-ing address? [SOLVED]
Replies: 6
Views: 1344

Re: Terminology - NAT-ing address? [SOLVED]

My assumption is they want to configure what they call these day "DMZ", i.e. forward all ports to the private IP of your router (In my view, term DMZ in this config is not the correct terminology)
by CZFan
Fri Jan 03, 2020 5:49 pm
Forum: Wireless Networking
Topic: RB4011 PoE output + cAP ac PoE input without PoE injector??
Replies: 14
Views: 3342

Re: RB4011 PoE output + cAP ac PoE input without PoE injector??

by using various electronic setups, i.e. voltage doubler circuits, etc
by CZFan
Thu Jan 02, 2020 8:47 pm
Forum: Wireless Networking
Topic: RB4011 PoE output + cAP ac PoE input without PoE injector??
Replies: 14
Views: 3342

Re: RB4011 PoE output + cAP ac PoE input without PoE injector??

The confusing bit for me is that most switches talk Watts not Volts and most are af standard but not af/at?
...
They all really talk the same language.

Power (W) = Volts(V) x Amperes(A)

So if a device gets 12V and draws 3A, Power(W) will be 36 Watts
by CZFan
Thu Jan 02, 2020 1:31 pm
Forum: RouterOS v7 BETA
Topic: ros v7 beta4 recursive route
Replies: 4
Views: 1852

Re: ros v7 beta4 recursive route

Your config seems wrong, hence I posted the links. i.e. you have 2 routes with a scope of 10, so how must the recursive route decide which route to use?
by CZFan
Thu Jan 02, 2020 12:27 am
Forum: General
Topic: CAPsMAN VLANs not working properly
Replies: 5
Views: 1021

Re: CAPsMAN VLANs not working properly

Have you thought of making use of services offered by Mikrotik certified consultants?
by CZFan
Thu Jan 02, 2020 12:21 am
Forum: General
Topic: Slow WiFi
Replies: 4
Views: 853

Re: Slow WiFi

Best will be to post a copy of the configuration here, BETWEEN code brackets please.
Run "export hide-sensitive" in cli interface and post results here, then someone might spot a problem and advise
by CZFan
Wed Jan 01, 2020 3:01 am
Forum: Beginner Basics
Topic: L2TP Server doesn't give a default gateway to the client - why?
Replies: 29
Views: 8902

Re: L2TP Server doesn't give a default gateway to the client - why?

The gateway of 0.0.0.0 is the gateway for the VPN connection, and I'd as per design.
0.0.0.0, in IP means this network, the VPN is a point to point connection, with the gateway 0.0.0.0 behing the gateway for this network, hope it makes sense
by CZFan
Wed Jan 01, 2020 2:28 am
Forum: Beginner Basics
Topic: hAP lite Upgrade 6.43.13 to higer version fail [SOLVED]
Replies: 3
Views: 1324

Re: hAP lite Upgrade 6.43.13 to higer version fail [SOLVED]

Suspect the problem is due to limited disk space on hap lite.
Do selective package upgrade method or netinstall as suggested in post above
by CZFan
Wed Jan 01, 2020 2:04 am
Forum: Beginner Basics
Topic: Bandwidth Upgrade Problem
Replies: 4
Views: 1172

Re: Bandwidth Upgrade Problem

With my old RB2011, I got around 100Mb down sitting about 3-5 meters from router. That was actual throughput. So what you getting is probably on par.
by CZFan
Wed Jan 01, 2020 1:54 am
Forum: General
Topic: Slow WiFi
Replies: 4
Views: 853

Re: Slow WiFi

First thing that comes to mind with you saying you had to enable fasttrack rules is probably firewall rule order.
Where is the fasttrack rule currently? Move to higher up, i.e. First or second rule as example, depending you firewall rule config
by CZFan
Wed Jan 01, 2020 1:41 am
Forum: General
Topic: PPPoE client interface can not connect to a Juniper PPPoE server
Replies: 2
Views: 715

Re: PPPoE client interface can not connect to a Juniper PPPoE server

Post a packet capture of where it is not working
by CZFan
Tue Dec 31, 2019 10:29 pm
Forum: General
Topic: Simple Queue Master/Child Priority Issue
Replies: 2
Views: 595

Re: Simple Queue Master/Child Priority Issue

Not that it will matter, but you say guest is 192.168.68.1/24 but in queue you have a /23?

What does the ques say, do they show traffic / counters?

Have you tested 1 machine on its own, can it get full speed, may they cant and hence load is spread?
by CZFan
Tue Dec 31, 2019 8:55 pm
Forum: General
Topic: Possible to reach Mikrotik DynDNS behind NAT? (through upnp or something else?)
Replies: 30
Views: 3827

Re: Possible to reach Mikrotik DynDNS behind NAT? (through upnp or something else?)

I hope no one replies him back... He will just keep on being offensive and rude... I have already reported his post where he verbally attacks me...

To be honest, I don't give a flying F^&%%$ what he thinks, posts etc
by CZFan
Tue Dec 31, 2019 8:49 pm
Forum: General
Topic: Possible to reach Mikrotik DynDNS behind NAT? (through upnp or something else?)
Replies: 30
Views: 3827

Re: Possible to reach Mikrotik DynDNS behind NAT? (through upnp or something else?)

I see no reason to "admit I am wrong". Everything I have written here is correct. End of discussion.

So enlighten us why you say it will not work? Then we can also learn something not be so dumb
by CZFan
Tue Dec 31, 2019 8:39 pm
Forum: Beginner Basics
Topic: Basic frustrations - VPNs and Firewalls
Replies: 4
Views: 1135

Re: Basic frustrations - VPNs and Firewalls

Does it work when you connect to ports 6 - 10 on the RB2011?
by CZFan
Tue Dec 31, 2019 8:04 pm
Forum: General
Topic: Internet to M.T. router trough PC
Replies: 5
Views: 887

Re: Internet to M.T. router trough PC

If you mean that Windows PC would have the role of router and MT router would be connected behing it as client, then yes, Windows can do it. You can find it it network adapter's properties, it's called something like "internet connection sharing". All I remember about it was that it worked, but it ...
by CZFan
Tue Dec 31, 2019 7:50 pm
Forum: General
Topic: Possible to reach Mikrotik DynDNS behind NAT? (through upnp or something else?)
Replies: 30
Views: 3827

Re: Possible to reach Mikrotik DynDNS behind NAT? (through upnp or something else?)

It looks like both of you are too dumb to understand that any usage of RoMon is not an option to solve the OP's problem of managing a router that is on a remote network behind another router doing NAT. I did not imagine that people could get that dumb, but apparently it is possible! Oh well... And ...
by CZFan
Tue Dec 31, 2019 3:33 pm
Forum: General
Topic: Possible to reach Mikrotik DynDNS behind NAT? (through upnp or something else?)
Replies: 30
Views: 3827

Re: Possible to reach Mikrotik DynDNS behind NAT? (through upnp or something else?)

I would assume I read it exactly the way you did. BUT: Nowhere did anyone say RoMon IS the solution, it is an OPTION. Maybe you know the OP personally and know what is within his power, but I suspect @Zacharias don't, and I definitely don't. So if this is so important to the OP, and it is within his...
by CZFan
Tue Dec 31, 2019 2:18 pm
Forum: Beginner Basics
Topic: CRS309 with 2 VLANs and one trunk
Replies: 5
Views: 1229

Re: CRS309 with 2 VLANs and one trunk

If you want to add sfp8 as a tagged (Trunk) port, use below

"/interface bridge vlan add bridge=BR1 tagged=sfp-sfpplus8 vlan-ids=62"

For management of device, you must set the bridge also as a tagged port
by CZFan
Tue Dec 31, 2019 1:15 pm
Forum: General
Topic: Possible to reach Mikrotik DynDNS behind NAT? (through upnp or something else?)
Replies: 30
Views: 3827

Re: Possible to reach Mikrotik DynDNS behind NAT? (through upnp or something else?)

Let me add, RoMon itself does not work over L3, BUT, if all devices are Mikrotik and running RoMon, you can access all devices over a L3 network via the RoMon agent. If configured as per above, it will create a RoMon network, similar to what OSPF does for L3 routing So if all OPs devices were Mikrot...
by CZFan
Tue Dec 31, 2019 3:38 am
Forum: General
Topic: Examples of using RAW firewall?
Replies: 34
Views: 11912

Re: Examples of using RAW firewall?

I guess it will be something like
/ip firewall raw
Add chain=pre-routing dst-address-type=!local action=notrack 
by CZFan
Tue Dec 31, 2019 2:55 am
Forum: General
Topic: Changing PPPoE client name disconnects PPPoE and re-connects - WHY?
Replies: 9
Views: 1572

Re: Changing PPPoE client name disconnects PPPoE and re-connects - WHY?

So if you are coding a system, why do you want to make things complicated and add areas that can cause problems / errors, i.e. If this changed, restart service, if that changed, don't restart service, etc the list can go on and on... With a PPPoE user, I will agree with way it is, if anything change...
by CZFan
Tue Dec 31, 2019 2:41 am
Forum: General
Topic: Automatic MTU/MRU for the PPPoE Client
Replies: 12
Views: 3384

Re: Automatic MTU/MRU for the PPPoE Client

MT PPPoE server only sends out MRU as option during discover / session stage
by CZFan
Tue Dec 31, 2019 2:31 am
Forum: General
Topic: Possible to reach Mikrotik DynDNS behind NAT? (through upnp or something else?)
Replies: 30
Views: 3827

Re: Possible to reach Mikrotik DynDNS behind NAT? (through upnp or something else?)

RoMon works very good on a routed / L3 network, not wise the expose to Internet for obvious reasons
by CZFan
Mon Dec 30, 2019 2:00 pm
Forum: Beginner Basics
Topic: How to go back to dynamic IP in DHCP server [SOLVED]
Replies: 11
Views: 2424

Re: How to go back to dynamic IP in DHCP server [SOLVED]

@mkx,
I disagree, if one understands how DHCP / Lease, etc works, then "removing / deleting" the lease make 100% sense.
by CZFan
Mon Dec 30, 2019 12:25 am
Forum: General
Topic: route internet from one IP over VPN
Replies: 21
Views: 2889

Re: route internet from one IP over VPN

In short, if you get a ping reply (via VPN connection), the routing is working, and if you can ping the name and get a reply (Via VPN connection), name resolution is also fine.

Then you need to look at firewall rules that might possibly block ports 80/443, etc
by CZFan
Mon Dec 30, 2019 12:04 am
Forum: Beginner Basics
Topic: How to go back to dynamic IP in DHCP server [SOLVED]
Replies: 11
Views: 2424

Re: How to go back to dynamic IP in DHCP server [SOLVED]

.... A button that simply carried out the command would make a lot of noobs much more comfortable and save a lot of time with many people having to ask the question and wait for answers.

That button is there already!!
RemoveLease.JPG
by CZFan
Sun Dec 29, 2019 11:50 pm
Forum: General
Topic: route internet from one IP over VPN
Replies: 21
Views: 2889

Re: route internet from one IP over VPN

if you can ping the IP address, but not browse, then you probably have a name resolution problem, can be tested by using ping www.google.com or trace route to same url. Suggest you remove the mangle, etc rules created for the policy based routing, ensure the VPN is working 100%. Then follow below ex...
by CZFan
Sun Dec 29, 2019 6:50 pm
Forum: General
Topic: route internet from one IP over VPN
Replies: 21
Views: 2889

Re: route internet from one IP over VPN

what is the problem you are experiencing, total lack of internet access, i.e. unable to ping / trace route to a public IP like 8.8.8.8 or name / domain resolution?
by CZFan
Sun Dec 29, 2019 12:34 am
Forum: General
Topic: route internet from one IP over VPN
Replies: 21
Views: 2889

Re: route internet from one IP over VPN

The info you provided is very limited. With that said, my first suggestion will be to check if you have NAT rule for the VPN connection.
Also noticed you have passthrough as yes, if there are other rout mark rules after that rule, packet might be remarked and not following correct route
by CZFan
Wed Dec 25, 2019 11:33 pm
Forum: General
Topic: ASK [Wireless-Channel}
Replies: 10
Views: 1448

Re: ASK [Wireless-Channel}

The channel width is 20, to use 40MHz channel, you make use of extension channel
by CZFan
Tue Dec 24, 2019 8:32 pm
Forum: Beginner Basics
Topic: PIA via OpenVPN client on RB750Gr3 help
Replies: 16
Views: 2456

Re: PIA via OpenVPN client on RB750Gr3 help

I was just trying to go with OVPN because its obviously more secure and newer. "obviously more secure"? I don't think so! Don't listen to those kiddies that claim their VPN pet project is the best, before you know you are in those queues here that always want the next VPN protocol to be added to Ro...
by CZFan
Tue Dec 24, 2019 6:48 am
Forum: General
Topic: A lot of TCP Retransmission and TCP Dup ACK
Replies: 4
Views: 1485

Re: A lot of TCP Retransmission and TCP Dup ACK

Does not seem to be duplicate packets, as per screenshot, the sequence numbers changes. so I suspect packet loss between devices
by CZFan
Tue Dec 24, 2019 6:40 am
Forum: Beginner Basics
Topic: Dual sim schedule
Replies: 2
Views: 801

Re: Dual sim schedule

IIRC, there are steps to use the dual sim facility switching between sim cards using a script, then all you have to do is create a schedule to run the script at times you want to change between sims, search for this in Mikrotik Wiki and apply accordingly to your situation /application
by CZFan
Tue Dec 24, 2019 6:24 am
Forum: General
Topic: ASK [Wireless-Channel}
Replies: 10
Views: 1448

Re: ASK [Wireless-Channel}

channel width = 20
by CZFan
Mon Dec 23, 2019 4:26 pm
Forum: Beginner Basics
Topic: Tagged and untagged VLANs on same port?
Replies: 7
Views: 1380

Re: Tagged and untagged VLANs on same port?

on 2011, hybrid vlan config is only supported on ports 1-5
by CZFan
Sun Dec 22, 2019 2:58 pm
Forum: Wireless Networking
Topic: Apple devices experiencing packet loss
Replies: 6
Views: 2356

Re: Apple devices experiencing packet loss

Only suggestion I can make is that you will have to record some packet traces to see where problem might be.

Below might help you start.

https://forums.developer.apple.com/thread/45283
https://forums.developer.apple.com/thread/45210
by CZFan
Sun Dec 22, 2019 12:29 am
Forum: General
Topic: Is Mangle Output Chain broken? [SOLVED]
Replies: 3
Views: 1017

Re: Is Mangle Output Chain broken? [SOLVED]

@Sob, Thx, makes more sense again. Think what threw me out was 2 things: 1. I could successfully ping 192.168.200.14 from my Windows command prompt.This makes sense as the conn and routing is marked for table WAN2 before routing decision. 2. When I tried to ping from inside to outside, even when spe...
by CZFan
Sat Dec 21, 2019 12:36 am
Forum: Forwarding Protocols
Topic: Critical issue on STP flapping
Replies: 7
Views: 2232

Re: Critical issue on STP flapping

Sounds like you have a loop in the network
by CZFan
Sat Dec 21, 2019 12:01 am
Forum: Beginner Basics
Topic: multi wan
Replies: 2
Views: 904

Re: multi wan

by CZFan
Fri Dec 20, 2019 11:26 pm
Forum: General
Topic: Is Mangle Output Chain broken? [SOLVED]
Replies: 3
Views: 1017

Is Mangle Output Chain broken? [SOLVED]

Hi, I am trying to configure Dual WAN with mangle rules. The problem is access to the router itself. Attached is sample config from a lab I have setup, and cant seem to get access to the router once IP is disabled that provides default gateway and would have thought that PBR using mangle would have ...
by CZFan
Thu Dec 19, 2019 5:21 pm
Forum: General
Topic: How to filter "ip firewall address-list"
Replies: 6
Views: 1693

Re: How to filter "ip firewall address-list"

You can use POSIX regular expressions, with some exceptions.
Cool, thank you
by CZFan
Thu Dec 19, 2019 4:39 pm
Forum: General
Topic: How to filter "ip firewall address-list"
Replies: 6
Views: 1693

Re: How to filter "ip firewall address-list"

Or using filter by address and not by address list name: /ip firewall address-list print where address ~"46" /ip firewall address-list print where address ~"192.168.1.[8]" /ip firewall address-list print where address ~"55.[1]" very cool, learned something new again, the [] part, thank you for shar...
by CZFan
Thu Dec 19, 2019 4:29 pm
Forum: General
Topic: Mikrotik reboot loop with EOIP
Replies: 4
Views: 843

Re: Mikrotik reboot loop with EOIP

check power supply
by CZFan
Thu Dec 19, 2019 4:00 pm
Forum: Wireless Networking
Topic: VLAN "probably loop" log message
Replies: 11
Views: 2588

Re: VLAN "probably loop" log message

fist step will be is "What has changed", i.e. last change made
by CZFan
Wed Dec 18, 2019 11:50 pm
Forum: Beginner Basics
Topic: L2TP Server doesn't give a default gateway to the client - why?
Replies: 29
Views: 8902

Re: L2TP Server doesn't give a default gateway to the client - why?

Just found on mikrotik wiki another piece of puzzling information: Warning: Only one L2TP/IpSec connection can be established through the NAT. Which means that only one client can connect to the sever located behind the same router. That's kind of limiting usefulness of VPN is not it? I mean rotuer...
by CZFan
Wed Dec 18, 2019 3:35 pm
Forum: Beginner Basics
Topic: FTTH very slow download speed (upload ok)
Replies: 15
Views: 3627

Re: FTTH very slow download speed (upload ok)

It's insantiy to use PPPoE in gigabit speeds, what are people thinking... I don't think the RB2011 can handle 1000Mbps PPPoE traffic. that's a lot of re-framing/fragmentation that needs to be handled in software. For pure IPv4 routing it surly can to much more. Maybe the RB4011 can handle it. Yup, ...
by CZFan
Wed Dec 18, 2019 12:58 pm
Forum: General
Topic: Subnetting in one network
Replies: 4
Views: 769

Re: Subnetting in one network

I thinks OPs network is too small to be concerned about broadcasts, etc. Splitting up is just going to add unnecessary complication, and if you asking that type of questions, then I suspect the knowledge is not there yet, rather just KISS
by CZFan
Tue Dec 17, 2019 12:06 am
Forum: General
Topic: 19/5000 DHCP, why this? [SOLVED]
Replies: 1
Views: 519

Re: 19/5000 DHCP, why this? [SOLVED]

I am really struggling to understand what you asking, but anyway, the ip subnet in firewall rule is not the connection, but it is a subnet manually entered in firewall rule as one of the rules conditions
by CZFan
Fri Dec 13, 2019 12:37 pm
Forum: Beginner Basics
Topic: Can't get dhcp using vlans and bridge port configuration [SOLVED]
Replies: 2
Views: 812

Re: Can't get dhcp using vlans and bridge port configuration [SOLVED]

Dont see any config for ether1 (Trunk to MK1) under bridge vlan on MK2
by CZFan
Thu Dec 12, 2019 12:33 am
Forum: Beginner Basics
Topic: CRS326 InterVLAN Routing by Bridge
Replies: 9
Views: 1592

Re: CRS326 InterVLAN Routing by Bridge

Maybe better to post full config, maybe we can spot a typo error or something
by CZFan
Wed Dec 11, 2019 6:07 pm
Forum: General
Topic: RB951G Simultaneous LAN Connections
Replies: 1
Views: 550

Re: RB951G Simultaneous LAN Connections

I am not sure I understand what you are trying to determine here, but my 2c's 1. RB951G is a SOHO device, 50 - 70, or even using up a /24 subnet, is not a SOHO environment. 2. As per your topology, LAN - LAN packets / frames should not touch the router. 3. I think the capacity of the router should b...
by CZFan
Sat Dec 07, 2019 12:47 am
Forum: General
Topic: "Netwatch" for interface status?
Replies: 2
Views: 538

Re: "Netwatch" for interface status?

I used The Dude for this
by CZFan
Fri Dec 06, 2019 12:22 am
Forum: Wireless Networking
Topic: Point-to-Point configuration
Replies: 6
Views: 1833

Re: Point-to-Point configuration

Technically speaking, that is not setting up a point to point link, that process is that extend your wifi...
by CZFan
Thu Dec 05, 2019 11:39 pm
Forum: Beginner Basics
Topic: Sending Data over 1WAN and Voice over another WAN
Replies: 3
Views: 642

Re: Sending Data over 1WAN and Voice over another WAN

How do you mark traffic in Mikrotik?

Do a search for policy based routing
by CZFan
Mon Dec 02, 2019 6:15 pm
Forum: General
Topic: Site to Site L2TP VPN
Replies: 13
Views: 1979

Re: Site to Site L2TP VPN

Did you configure routes?

IPSec is interface less. Policy plays the game.
Not a "pure" IPSec site to site VPN, it is a L2TP Site to Site VPN, so normal routing applies
by CZFan
Mon Dec 02, 2019 2:07 pm
Forum: Forwarding Protocols
Topic: OSPF did a thing...
Replies: 4
Views: 1960

Re: OSPF did a thing...

With the limited info provided, my guess will be you probably have 2 DR/Master fighting over who should be DR/Master
by CZFan
Mon Dec 02, 2019 1:23 pm
Forum: General
Topic: Site to Site L2TP VPN
Replies: 13
Views: 1979

Re: Site to Site L2TP VPN

If you can ping from a pc one side to a printer other side and vice versa, then routing is working.

Then problem is probably due to Windows firewall as they drop connections coming in from different subnet than LAN address by default
by CZFan
Sun Dec 01, 2019 12:39 pm
Forum: Beginner Basics
Topic: Disk Space changed from 128M to 16M [SOLVED]
Replies: 5
Views: 960

Re: Disk Space changed from 128M to 16M [SOLVED]

Nothing has changed, RB750r2 only has 16MB storage

https://mikrotik.com/product/RB750r2
by CZFan
Tue Nov 26, 2019 11:35 pm
Forum: General
Topic: Lost poe in port menu
Replies: 5
Views: 626

Re: Lost poe in port menu

The obvious question will be, have you tried a long term / stable version instead of a beta version?
by CZFan
Mon Nov 25, 2019 3:54 pm
Forum: Wireless Networking
Topic: LTE Interface disappear
Replies: 2
Views: 1524

Re: LTE Interface disappear

Thx @uldise, Had to drive out to customer, 2 hour round trip. I dont think the USB power would have helped, as we powered the device down, i.e. pulled the ethernet cable supplying POE to device and did not make a difference either. Managed to get it up again by flipping between SIM slots a & b a cou...
by CZFan
Mon Nov 25, 2019 12:02 pm
Forum: Wireless Networking
Topic: LTE Interface disappear
Replies: 2
Views: 1524

LTE Interface disappear

I have a customer down at the moment, they have a RBSXTR (SXT LTE) running RoS 6.44.6 Long Term and same firmware. Modem firmware is v13. The LTE interface disappeared this morning, restarting the device did not work, switching between SIM slots "a & b" and back to "a" brought the LTE interface back...
by CZFan
Mon Nov 25, 2019 12:48 am
Forum: General
Topic: Background scan done remotely and problems with it
Replies: 3
Views: 542

Re: Background scan done remotely and problems with it

Make sure you have not set any scan lists on wireless interface
by CZFan
Fri Nov 22, 2019 10:11 pm
Forum: Announcements
Topic: v6.44.6 [long-term] is released!
Replies: 54
Views: 44215

Re: v6.44.6 [long-term] is released!

...
previousely used v6.37.1
...

You will have to ensure your devices have not been compromised
by CZFan
Fri Nov 22, 2019 2:18 pm
Forum: Beginner Basics
Topic: Internet Speed
Replies: 41
Views: 4462

Re: Internet Speed

With my previous RB2011 I could get ~800Mb/s download with fasttrack enabled. All depends on the config used. Ofcorse 2011 can reach that speed, test results show even better performance than yours when fast path is used. But when you use firewall, queues ect then things change. I strongly suggest ...
by CZFan
Fri Nov 22, 2019 11:38 am
Forum: Forwarding Protocols
Topic: BGP: Remove extra prepends from upstream
Replies: 2
Views: 1573

Re: BGP: Remove extra prepends from upstream

I am sure the upstream provider did this by design for a reason, best will be to agree with them routing policy
by CZFan
Thu Nov 21, 2019 11:56 pm
Forum: Beginner Basics
Topic: LHG LTE US TTL
Replies: 1
Views: 407

Re: LHG LTE US TTL

I am not sure I understand what you are trying to achieving, but belo might help

/ip firewall mangle
add action=change-ttl chain=postrouting new-ttl=set:65 out-interface=lte1 passthrough=yes
by CZFan
Thu Nov 21, 2019 11:39 pm
Forum: Beginner Basics
Topic: Internet Speed
Replies: 41
Views: 4462

Re: Internet Speed

My 2c
With my previous RB2011 I could get ~800Mb/s download with fasttrack enabled.

During the times the speed tests were done, found also that different browsers gave very different results
by CZFan
Thu Nov 21, 2019 7:46 pm
Forum: General
Topic: LTE Modem Firmware Upgrade [SOLVED]
Replies: 3
Views: 1306

Re: LTE Modem Firmware Upgrade [SOLVED]

@eworm,

Thank you very much
by CZFan
Thu Nov 21, 2019 6:20 pm
Forum: General
Topic: LTE Modem Firmware Upgrade [SOLVED]
Replies: 3
Views: 1306

LTE Modem Firmware Upgrade [SOLVED]

I am trying to understand / find out some info re modem firmware upgrade process. Can this be done across the LTE connection, i.e. I connect to device remotely via the LTE connection to upgrade? How does the upgrade process work, is it similar to ROS upgrade where it downloads to another section / p...
by CZFan
Wed Nov 20, 2019 11:42 am
Forum: General
Topic: cAP ac bricked after update - netinstall not working
Replies: 8
Views: 2599

Re: cAP ac bricked after update - netinstall not working

"...I can briefly see the "sending offer" message, but no progress bar whatsoever appears...."

I had this before, and IIRC, what solved it for me was placing the ROS .npk file in the same folder as where I am running Netinstall from and then selecting that in Netinstall
by CZFan
Wed Nov 20, 2019 11:09 am
Forum: General
Topic: PPTP issue after routerboard update
Replies: 12
Views: 1085

Re: PPTP issue after routerboard update

IIRC, an interface pointing to *FFFF points to an interface that does not exist anymore, i.e. deleted
by CZFan
Wed Nov 13, 2019 8:47 pm
Forum: General
Topic: CCR1036 WISP Setup - Please Help
Replies: 4
Views: 507

Re: CCR1036 WISP Setup - Please Help

For something like this, suggest contacting one closest to you:

https://mikrotik.com/consultants
by CZFan
Tue Nov 12, 2019 10:26 pm
Forum: Forwarding Protocols
Topic: /routing ospf virtual-link
Replies: 3
Views: 1905

Re: /routing ospf virtual-link

Virtual links in OSPF has two functions / purposes. Linking a non backbone area to the backbone area via a different non backbone are, connecting a backbone area that has been partitioned / merged. Depending on how critical your environment is, my suggestion to you make contact with a Mikrotik certi...
by CZFan
Tue Nov 12, 2019 9:29 pm
Forum: The Dude
Topic: Will there be a Dude V7?
Replies: 1
Views: 2228

Will there be a Dude V7?

See topic heading
by CZFan
Tue Nov 12, 2019 5:04 pm
Forum: General
Topic: Switch rule doesn't work
Replies: 18
Views: 2043

Re: Switch rule doesn't work

Thank you @sindy,

The reason I said it does not matter in this situation, IIRC, the OP said he uses ether 1 and not SFP interface

I hope and pray the Mikrotik community do not lose you as a member
by CZFan
Tue Nov 12, 2019 12:01 pm
Forum: General
Topic: Switch rule doesn't work
Replies: 18
Views: 2043

Re: Switch rule doesn't work

Not that it matters in this situation, but the sfp interface of the RB2011 is connected to switch chip 8327. @sindy, would you mind to elaborate a little on the post "cause rules are executed on ingress only" As per @pe1chl post, if you set the rulke to ether 1, then surely that is still ingress, i....
by CZFan
Sun Nov 10, 2019 9:46 pm
Forum: General
Topic: What is wrong with bridges and eoip?
Replies: 16
Views: 3190

Re: What is wrong with bridges and eoip?

Do you ask why the bridge MTU auto-adjusts to the lowest one of its member interfaces' MTUs, or why an MTU smaller than 1500 causes trouble when accessing https servers? i asked why MTU of bridge changes, was not aware that bridge auto adjust to lowest member MTU, but did find the info about an hou...
by CZFan
Sat Nov 09, 2019 9:04 pm
Forum: General
Topic: What is wrong with bridges and eoip?
Replies: 16
Views: 3190

Re: What is wrong with bridges and eoip?

I would bet that your MTU changed when you added the EOIP interface to the bridge. While your LAN PC's are using 1500, your bridge likely shrunk to 1480 or less. ...

I experienced this before, would you care to elaborate on why this will happen?
by CZFan
Thu Nov 07, 2019 5:26 pm
Forum: SwOS
Topic: Terminal / ssh / telnet support for SwOS ?
Replies: 13
Views: 4481

Re: Terminal / ssh / telnet support for SwOS ?

Dont know if it will work, but maybe try and change something under system tab, i.e. un-tick and re-tick something and then click apply to save changes, maybe then it will then renew DHCP lease
by CZFan
Wed Nov 06, 2019 11:11 pm
Forum: General
Topic: RB2011UiAS-2HnD-IN and Spectrum Cable Ultra (400Mbps)
Replies: 25
Views: 3116

Re: RB2011UiAS-2HnD-IN and Spectrum Cable Ultra (400Mbps)

Can you post full config here, using export hide-sensitive, place output of export between code brackets, on the button menus, please look for it
by CZFan
Tue Nov 05, 2019 10:53 pm
Forum: Wireless Networking
Topic: Wi-Fi auto channel select & N-only
Replies: 15
Views: 3236

Re: Wi-Fi auto channel select & N-only

When wireless interface starts up, it will scan and select channel with the least number of "networks". If you get a router with a mode button, you can configure a script to disable wireless for couple of seconds and enable again which will cause router to rescan frequencies, else you will have to d...
by CZFan
Tue Nov 05, 2019 8:41 pm
Forum: General
Topic: DNAT where source is also translated.
Replies: 22
Views: 2254

Re: DNAT where source is also translated.

replace your 2nd rule with,
/ip firewall nat
add chain=srcnat action=src-nat in-interface=<YourWANInterface> dst-address=172.x.x.199 to-addresses=172.x.x.123
by CZFan
Tue Nov 05, 2019 6:25 pm
Forum: General
Topic: 100 Mbps download limit on CRS109-8G-1S-2HnD
Replies: 4
Views: 866

Re: 100 Mbps download limit on CRS109-8G-1S-2HnD

I agree that it is a switch really, but this device has the same specs as the 2011 and with 2011 in a home / office environment I could reach ~800Mb/s downloads and would think this device should be capable of the same
by CZFan
Tue Nov 05, 2019 6:05 pm
Forum: RouterBOARD hardware
Topic: Unable to reinstall Routerbord
Replies: 6
Views: 2215

Re: Unable to reinstall Routerbord

... The routerOS that i have used early routeros-mipsbe for my RB495G The i tried to download all modells and then netinstall will match with routeros-smips but trying to install it ends with a format error… ... I dont have any experience with this specific router model, but in your post you mentio...
by CZFan
Tue Nov 05, 2019 5:58 pm
Forum: General
Topic: MSTP
Replies: 4
Views: 984

Re: MSTP

If there is no need for the vlans in the STP and only Mikrotik devices, just stick with RSTP?
by CZFan
Sat Nov 02, 2019 6:58 pm
Forum: General
Topic: L2TP server works for Mac, iPhone, not Windows 10 [SOLVED]
Replies: 11
Views: 2722

Re: L2TP server works for Mac, iPhone, not Windows 10 [SOLVED]

to me it looks like the VPN server is behind a NAT, i.e. 192.168.100.2. In that case, you will have to make registry changes on Windows VPN client.

https://support.microsoft.com/en-za/hel ... in-windows
by CZFan
Fri Nov 01, 2019 10:53 pm
Forum: General
Topic: I've Tried (almost) everything: IPSEC IKEv2 11.5 Mbps on 100Mbps Connection Hap AC2
Replies: 11
Views: 2155

Re: I've Tried (almost) everything: IPSEC IKEv2 11.5 Mbps on 100Mbps Connection Hap AC2

The device you RDP from, is connection nag with wifi or wired LAN cable? Wifi might not be optimally configured which might case the stuck issues
by CZFan
Fri Nov 01, 2019 9:38 pm
Forum: Beginner Basics
Topic: RB750R2 BASIC home Vlan Setup
Replies: 6
Views: 1183

Re: RB750R2 BASIC home Vlan Setup

Looking at the network diagram, I don't understand why you want to complicate things with Vlans. Just remove ether 5 from bridge, configure separate IP subnet on this and block traffic between the 2 LANs with firewall rules
by CZFan
Thu Oct 31, 2019 8:53 pm
Forum: Announcements
Topic: Wireless link calculator updated
Replies: 71
Views: 43080

Re: Wireless link calculator updated

also experiencing same problem re elevation for here in RSA
by CZFan
Thu Oct 31, 2019 2:50 pm
Forum: General
Topic: slow wifi speed mikrotik RB941-2nD
Replies: 11
Views: 1343

Re: slow wifi speed mikrotik RB941-2nD

Also change Antenna Gain from 4 to 2 on that device
by CZFan
Thu Oct 31, 2019 2:30 pm
Forum: Announcements
Topic: Winbox v3.20 released!
Replies: 42
Views: 20940

Re: Winbox v3.20 released!

Not a major issue, more of an annoyance, double click does not work under "Neighbors" tab
by CZFan
Thu Oct 31, 2019 1:48 pm
Forum: Beginner Basics
Topic: RouterOS - Route traffic through specific gateway problem
Replies: 15
Views: 2759

Re: RouterOS - Route traffic through specific gateway problem

Seems you have made some progress, in your OP you stated the packet never reaches 10.1.1.138 and from the trace route now it does. I dont know what device 10.2.60.59 is and can only assume it is a PC/Workstation/Server, then my assumption would be that there are: 1. Firewall on this device blocking ...
by CZFan
Wed Oct 30, 2019 2:01 pm
Forum: Scripting
Topic: Script to delete itself after executing... [SOLVED]
Replies: 7
Views: 3243

Re: Script to delete itself after executing... [SOLVED]

Thank you @vecernik87 Changed yours a bit and added to bottom of my script and will test with a new remote deployment later today: :do { /file remove [find where name="myscript.rsc" || name="flash/myscript.rsc"] } on-error={:log error "Unable to delete Config Script File..."}; Just as a matter of in...
by CZFan
Wed Oct 30, 2019 12:02 am
Forum: Scripting
Topic: Script to delete itself after executing... [SOLVED]
Replies: 7
Views: 3243

Re: Script to delete itself after executing... [SOLVED]

@eworm, no, the file name used there is an arbitrary name.

@Chris, I think you are on the money, will test it
by CZFan
Tue Oct 29, 2019 6:44 pm
Forum: Scripting
Topic: Script to delete itself after executing... [SOLVED]
Replies: 7
Views: 3243

Re: Script to delete itself after executing... [SOLVED]

Thx Chris,

Yes, it will be a file on router

I tried /file remove [find where name="mycript.rsc"] as last line and then the script fails / does not execute. Any reason why this will cause it to fail? If I remove that line, then script executes fine.
by CZFan
Tue Oct 29, 2019 12:56 pm
Forum: Beginner Basics
Topic: RouterOS - Route traffic through specific gateway problem
Replies: 15
Views: 2759

Re: RouterOS - Route traffic through specific gateway problem

Well, you have my entire config, no firewall rules

I can only find config for 10.24.14.1?
by CZFan
Tue Oct 29, 2019 12:46 pm
Forum: Scripting
Topic: Script to delete itself after executing... [SOLVED]
Replies: 7
Views: 3243

Script to delete itself after executing... [SOLVED]

I have read something about this a while ago on this forum, but cant seem to find it... I have created a script to configure the devices using System-->Reset Configuration and enabling no backup / no default and then select script to run after reset. My concern here is that this script also sets dif...
by CZFan
Mon Oct 28, 2019 10:05 pm
Forum: Beginner Basics
Topic: RouterOS - Route traffic through specific gateway problem
Replies: 15
Views: 2759

Re: RouterOS - Route traffic through specific gateway problem

I should have included in my previous post, ignore the high ping rates and time outs, my gns3 setup was broken at the time.

The purpose of my screenshot was more to show the route taken.

Is there no firewall rules blocking icmp on 10.1.1.138?
by CZFan
Mon Oct 28, 2019 12:17 am
Forum: Forwarding Protocols
Topic: Route flap after DR goes down
Replies: 7
Views: 2523

Re: Route flap after DR goes down

Are you only experiencing this in gns3 or same on actual Mikrotik devices?

What is your gns3 setup?
by CZFan
Sun Oct 27, 2019 4:02 pm
Forum: Forwarding Protocols
Topic: OSPF ignoring Priority?
Replies: 5
Views: 2481

Re: OSPF ignoring Priority?

Apologies, made a typo in my previous post.

The BDR is set as 1 and DR set as 255. Surely restart of just one device of these that formed adjacency should be enough to start election process. Else if the DR goes down and comes back up again, it will stay BDR?
by CZFan
Sun Oct 27, 2019 3:47 am
Forum: Forwarding Protocols
Topic: OSPF ignoring Priority?
Replies: 5
Views: 2481

Re: OSPF ignoring Priority?

DR priority is set as 1. I restarted the device which surely should start the election process?
by CZFan
Sun Oct 27, 2019 1:25 am
Forum: Beginner Basics
Topic: How to Forward the IP
Replies: 3
Views: 921

Re: How to Forward the IP

You can do a script to monitor the ip, if not available it must add forwarding rules. Then when up, remove these rules again
by CZFan
Sun Oct 27, 2019 12:00 am
Forum: Forwarding Protocols
Topic: OSPF ignoring Priority?
Replies: 5
Views: 2481

OSPF ignoring Priority?

Hi, Running ROS 6.44.5 long term on CHR, trying to set it as a DR server but seems OSPF is ignoring the Priority, i.e. on the interface, I set Priority for the device I want to be the DR to 255 and others are set to 1, but it stays as BDR / Backup? Disabled Instances, Networks, rebooted device, no c...
by CZFan
Fri Oct 25, 2019 11:15 pm
Forum: Beginner Basics
Topic: RouterOS - Route traffic through specific gateway problem
Replies: 15
Views: 2759

Re: RouterOS - Route traffic through specific gateway problem

EDIT, sorry, my brain is tired and made a mistake in previous post: The below rules is wrong, as you are port forwarding these, so you need to accept dstnat connection NAT state for forward chain. /ip firewall filter add action=accept chain=input disabled=no dst-address=10.30.52.242 dst-port=\ 8080 ...
by CZFan
Fri Oct 25, 2019 2:50 am
Forum: RouterBOARD hardware
Topic: Antenna Gain
Replies: 19
Views: 50265

Re: Antenna Gain

To clarify once more, since this bit of information got lost in the discussion ... setting the antenna gain number in RouterOS settings has only one use - reduction of TX power to match the total output power with the local regulations. If you don't care about that, do not enter anything in this se...
by CZFan
Thu Oct 24, 2019 10:24 pm
Forum: Wireless Networking
Topic: Spectrum Analyzing
Replies: 9
Views: 2219

Re: Spectrum Analyzing

I dont think the spectral scan works with Mikrotik 5GHz capable devices, IIRC I tried it on a Hap AC2 and said something about cant do it on this device
by CZFan
Thu Oct 24, 2019 10:14 pm
Forum: Wireless Networking
Topic: Hap AC2 - crap wifi 5GHz
Replies: 26
Views: 7174

Re: Hap AC2 - crap wifi 5GHz

One thing that might explain the difference between hAP ac2 and the old wireless router is adherence to country regulations ... all wifi vendors are forced to do it since a year or two ago ... previously this was not really enforced. In "worst case" the difference might be as high as 10dB ... or a ...
by CZFan
Thu Oct 24, 2019 1:04 am
Forum: Beginner Basics
Topic: RouterOS - Route traffic through specific gateway problem
Replies: 15
Views: 2759

Re: RouterOS - Route traffic through specific gateway problem

It is a bit late here now, i.e. 12:00 am, I will map out your config in the morning and see if I find anything
by CZFan
Sat Oct 19, 2019 4:18 pm
Forum: Beginner Basics
Topic: Challenges configuring /31 network.
Replies: 9
Views: 1042

Re: Challenges configuring /31 network.

TTL expired in Transit sounds like a routing loop, have you tried running a trace route?