Community discussions

Search found 999 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 20
by CZFan
Thu Oct 18, 2018 9:35 pm
Forum: Beginner Basics
Topic: Routing and Switching
Replies: 2
Views: 128

Re: Routing and Switching

CCNA Routing and Switching Study Guide book

or online

http://www.freeccnastudyguide.com/study-guides/ccna/
by CZFan
Thu Oct 18, 2018 8:23 pm
Forum: General
Topic: CRS328 how to use as real router
Replies: 1
Views: 74

Re: CRS328 how to use as real router

Please note that the CRS328-24P-4S+RM is by design a switch with routing capabilities, so routing performance might not meet expectations. As example of configuring it, create a bridge and assign ports 2 - what ever to the bridge, this will form the switch part, then port 1 which is not part of the ...
by CZFan
Thu Oct 18, 2018 3:41 pm
Forum: Beginner Basics
Topic: Can't create wireless interface
Replies: 2
Views: 105

Re: Can't create wireless interface

HEX does not have wireless, you will have to connect a separate wifi access point
by CZFan
Wed Oct 17, 2018 11:07 pm
Forum: Beginner Basics
Topic: Hosts from 2 LAN's can't reach each other
Replies: 2
Views: 83

Re: Hosts from 2 LAN's can't reach each other

If the wlan is disabled, how can any client connect to the device via wlan?

You should remove wlan from bridge, then the clients on wlan will access the clients on LAN via layer 3. If not, you have firewall filter rules preventing this.
by CZFan
Tue Oct 16, 2018 8:15 pm
Forum: General
Topic: Routes for VPN clients.
Replies: 2
Views: 123

Re: Routes for VPN clients.

See below, old topic but I think it is still relevant

viewtopic.php?t=10405
by CZFan
Tue Oct 16, 2018 1:21 pm
Forum: Announcements
Topic: Winbox v3.18 released!
Replies: 25
Views: 3483

Re: Winbox v3.18 released!

I have logged into a 6.39.x earlier today with Winbox 3.18
by CZFan
Mon Oct 15, 2018 12:59 pm
Forum: General
Topic: Unable to get full gigabit speed on RB750Gr3
Replies: 28
Views: 1350

Re: Unable to get full gigabit speed on RB750Gr3

@OP, what do you have connected to the 750. And which ports are they connected to? Depending on how the 750r3 is configured, i.e. all switched ports will share 1Gb path, if not switched, then ports 1,3 & 5 shares 1Gb path and 2 & 4 shares another 1Gb path, so other devices might interfere with down...
by CZFan
Mon Oct 15, 2018 12:43 am
Forum: General
Topic: Unable to get full gigabit speed on RB750Gr3
Replies: 28
Views: 1350

Re: Unable to get full gigabit speed on RB750Gr3

@OP, what do you have connected to the 750. And which ports are they connected to?
by CZFan
Sun Oct 14, 2018 10:08 pm
Forum: General
Topic: Unable to get full gigabit speed on RB750Gr3
Replies: 28
Views: 1350

Re: Unable to get full gigabit speed on RB750Gr3

@sindy: You're probably drinking beer not very far from me. But shh, we don't want anyone to know that we're slowly taking over the forum (maybe we can accept @CZFan as honorary member, he could be useful, he's not as much into motorcycles as I initially thought , but other things). :) O ye of litt...
by CZFan
Sun Oct 14, 2018 3:56 pm
Forum: The Dude
Topic: Monitoring a Simple Q
Replies: 1
Views: 131

Re: Monitoring a Simple Q

Bump, anyone with info on how to monitor simple queues with Dude?
by CZFan
Sun Oct 14, 2018 2:28 pm
Forum: General
Topic: optimize FW rule by using connection-state=new ?
Replies: 6
Views: 314

Re: optimize FW rule by using connection-state=new ?

.... I also allow echo replies (Established) since I want the pongs to my pings to be accepted. If you have VPNs, that too. Lig ang Drop the rest.
...
I will also add ICMP Type 3, Code 4 for path MTU discovery to work properly
by CZFan
Sun Oct 14, 2018 2:16 pm
Forum: General
Topic: Unable to get full gigabit speed on RB750Gr3
Replies: 28
Views: 1350

Re: Unable to get full gigabit speed on RB750Gr3

your forward rules are below the input. Francois, this is nothing but a superstition. The order of the chains ( input , output , forward ) in a table doesn't matter at all; the order of rules within the same chain does. So you can even place the rules like I1, O1, O2, F1, I2, O3, F2, F3, F4, I3, I4...
by CZFan
Sat Oct 13, 2018 4:53 pm
Forum: General
Topic: VLAN project. Need help
Replies: 6
Views: 372

Re: VLAN project. Need help

As per the drawing of your config, your frames are coming in tagged and leaving tagged as well, which indicates the Vlans are living on other devices, so, except for management of device, you do not need Vlan interfaces on these devices. Bellow config should suffice (NB. Done from memory, not tested...
by CZFan
Sat Oct 13, 2018 4:26 pm
Forum: General
Topic: QOS/Queue Tree setup - multiple VLANS
Replies: 2
Views: 215

Re: QOS/Queue Tree setup - multiple VLANS

I have not tested this in a VLANed scenario, but with your config I would think the below should work: Mark connections in prerouting chain without specifying any in / out interfaces, this will mark connections in both directions Then mark packets based on connection marks, again, don't specify in /...
by CZFan
Fri Oct 12, 2018 9:50 pm
Forum: Beginner Basics
Topic: Router Attack [SOLVED]
Replies: 6
Views: 411

Re: Router Attack [SOLVED]

https://blog.mikrotik.com/security/winbox-vulnerability.html Thanks. So after that what is next step? Becouse i am still receiving report about the js:Miner-AL[pup], trying get connection to my lan Thanks in advance I had this at a new client recently, (It was the actual reason he became a client o...
by CZFan
Mon Oct 08, 2018 12:57 am
Forum: General
Topic: Unable to get full gigabit speed on RB750Gr3
Replies: 28
Views: 1350

Re: Unable to get full gigabit speed on RB750Gr3

Your firewall rules do include fasttrack rule, but your forward rules are below the input.
Move all chain=forward rules to the top, with fasttrack being the very first rule
by CZFan
Sat Oct 06, 2018 5:04 pm
Forum: General
Topic: Unable to get more than 175 IP's
Replies: 15
Views: 868

Re: Unable to get more than 175 IP's

Change From: /ip address add address=10.0.0.1/16 comment=defconf interface= ether2-master network=10.0.0.0 To: /ip address add address=10.0.0.1/16 comment=defconf interface= bridge network=10.0.0.0 Not related, but you might also want to change from: /ip dns static add address= 192.168.88.1 name=rou...
by CZFan
Sat Oct 06, 2018 4:50 pm
Forum: General
Topic: HAP AC2 Auto negotioation
Replies: 4
Views: 377

Re: HAP AC2 Auto negotioation

From the screenshot it looks like your AC2 is only advertising up to 100Mb Full, make sure the 1000Mb Half and Full are ticked on the "Ethernet" tab on same screen
by CZFan
Thu Oct 04, 2018 12:27 pm
Forum: General
Topic: hardware acceleration on only one bridge?
Replies: 13
Views: 522

Re: hardware acceleration on only one bridge?

Are you sure about this? I seem to be able to transfer at wire speed across all the ports without hitting the CPU. This is NOT the case through the bridging method. I was seeing <100Mbps that way. ... Unless Mikrotik has made some design changes recently, very sure. When you go from one vlan to ano...
by CZFan
Wed Oct 03, 2018 9:37 pm
Forum: General
Topic: hardware acceleration on only one bridge?
Replies: 13
Views: 522

Re: hardware acceleration on only one bridge?

I'm not enabling vlan filtering on the bridge. The guides I found on using the switch chip dont suggest that. Right now, port 5 and port 4 cannot see each other. If I assign a VLAN 14 interface on the hEX connected to port 5 (ie, PVID=15) it can't communicate with port 4. So Vlans are being properl...
by CZFan
Wed Oct 03, 2018 7:40 pm
Forum: The Dude
Topic: Monitoring a Simple Q
Replies: 1
Views: 131

Monitoring a Simple Q

Hi, I am totally new to this, and not a coder of any type, and in need of some guidance on monitoring a Simple Q and getting some history of up / downloads of this Q in Dude. What I have done so far is: Created a Static Item with name of the Simple Q I want to monitor Added a link between the Router...
by CZFan
Wed Oct 03, 2018 12:39 pm
Forum: General
Topic: hardware acceleration on only one bridge?
Replies: 13
Views: 522

Re: hardware acceleration on only one bridge?

@syadnom, did you enable "Vlan Filtering" on the bridge?

Also do a test from vlan 12 to vlan 13 and at the same time from vlan 14 to vlan 15? I suspect your results might be different then.
by CZFan
Wed Oct 03, 2018 12:22 pm
Forum: General
Topic: Quick Mount Pro Dimensions [SOLVED]
Replies: 2
Views: 133

Re: Quick Mount Pro Dimensions [SOLVED]

Bump, Any drill hole template drawings please?

Else I have to get up on the roof, disconnect everything, take measurements, go and buy / make a u-bolts, go back and install again and all this time client will be down.
by CZFan
Wed Oct 03, 2018 12:32 am
Forum: General
Topic: hardware acceleration on only one bridge?
Replies: 13
Views: 522

Re: hardware acceleration on only one bridge?

@vecernik, not totally correct in this case.

Each port will be on a separate vlan, then any comms between these ports (VLAN's) will need to be routed which will go via cpu so HW offload will be lost
by CZFan
Wed Oct 03, 2018 12:00 am
Forum: Beginner Basics
Topic: Help - Traffic not visible in Queue Tree
Replies: 6
Views: 278

Re: Help - Traffic not visible in Queue Tree

My comment re crystal ball, we can't help if you only post part on the info.

Re your question if passthrough=no does not work, on your 2nd post, again with only part of the config, you have passthrough =yes for every packet mark
by CZFan
Tue Oct 02, 2018 7:26 pm
Forum: General
Topic: hardware acceleration on only one bridge?
Replies: 13
Views: 522

Re: hardware acceleration on only one bridge?

It is called "Router on a Stick", not Switch on a stick.

Depending on the number of switch chips on the device, with the Hex POE you have only 1 switch chip, so only 1 bridge with HW Offload, but i.e. on 2011, you can have 2 bridges with HW Offload as it has 2 switch chips.
by CZFan
Tue Oct 02, 2018 2:06 pm
Forum: General
Topic: Quick Mount Pro Dimensions [SOLVED]
Replies: 2
Views: 133

Quick Mount Pro Dimensions [SOLVED]

Hi, I have to buy / make some U-Bolts for the Quick Mount pro, https://mikrotik.com/product/QMP Have a client who have mounted this on a pole on the roof with cable ties, if anyone has the dimensions or a URL where I can get this it will be appreciated. I need the diameter for the holes and distance...
by CZFan
Tue Oct 02, 2018 12:50 am
Forum: Beginner Basics
Topic: RADIUS on Different Subnet
Replies: 5
Views: 268

Re: RADIUS on Different Subnet

Off the bat, it can be 2 things, you need to add second Mikrotik route in radius as nas device, and then possible firewall rules blocking comma
by CZFan
Fri Sep 28, 2018 11:54 pm
Forum: Beginner Basics
Topic: Help - Traffic not visible in Queue Tree
Replies: 6
Views: 278

Re: Help - Traffic not visible in Queue Tree

You forgot to post a picture of the crystal ball
by CZFan
Wed Sep 26, 2018 7:13 pm
Forum: General
Topic: Is mikrotik a good choice?
Replies: 54
Views: 2079

Re: Is mikrotik a good choice?

...

Mikrotik don't do/make directly GPON/MODEM. ...
https://mikrotik.com/product/SFPONU
by CZFan
Tue Sep 25, 2018 8:24 pm
Forum: General
Topic: Retag frames on a trunk port
Replies: 11
Views: 358

Re: Retag frames on a trunk port

What happens to the Vlan's once it gets to the other side of Vlan 6? If they split out again according to their Vlan's, then you can look intgo Service Tag / QinQ. If the Vlan's comes from the schools, and Vlan 6 is just your uplink Vlan, won't it be better to terminate Vlan's 1 - 5 on your device, ...
by CZFan
Tue Sep 25, 2018 5:30 pm
Forum: General
Topic: Retag frames on a trunk port
Replies: 11
Views: 358

Re: Retag frames on a trunk port

Will "Use Service Tag" not work here, i.e. you have C-Vlans 1,2,3,4&5, with S-Vlan 6

Or maybe QinQ, have Vlan 6 attached to ether2, with Vlan's 1-5 attached to vlan 6?
by CZFan
Mon Sep 24, 2018 8:02 pm
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 23626

Re: v6.43.1 [stable] and v6.43.2 [stable] is released!

Can you provide link to the documentation
Look at the very bottom of this wiki page (in the "Winbox" section).
Got it, thx.

I think it should rather be placed under headings for TX power, not right, right at the bottom of the document under some willy nilly comment about Winbox.
by CZFan
Mon Sep 24, 2018 7:40 pm
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 23626

Re: v6.43.1 [stable] and v6.43.2 [stable] is released!

Current TX Power = 0dBm
Current TX power readings are not supported for 802.11ac-capable wireless cards. That's a known (and documented!) limitation that has always been there.
My post is on the 802.11b/g/n WLAN card

Can you provide link to the documentation, want to go read up a bit more
by CZFan
Mon Sep 24, 2018 5:17 pm
Forum: Beginner Basics
Topic: PPTP behind ISP Router (NAT problem)
Replies: 12
Views: 450

Re: PPTP behind ISP Router (NAT problem)

Any specific reasons you have Bridge ARP configured as "arp=proxy-arp"?

If not, change that to arp=enabled
by CZFan
Mon Sep 24, 2018 4:34 pm
Forum: Beginner Basics
Topic: Multi-hop/Cascading VPN
Replies: 2
Views: 127

Re: Multi-hop/Cascading VPN

Nothing strange there, just make sure your routing / policies configured properly
by CZFan
Mon Sep 24, 2018 4:21 pm
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 23626

Re: v6.43.1 [stable] and v6.43.2 [stable] is released!

Note sure if someone has mentioned this before, if so, apologies for reposting

Current TX Power = 0dBm

board-name: hAP ac^2
model: RBD52G-5HacD2HnD
firmware-type: ipq4000L
factory-firmware: 3.43
current-firmware: 6.43.1
upgrade-firmware: 6.43.1
Current TX Power.JPG
by CZFan
Sun Sep 23, 2018 1:01 pm
Forum: Beginner Basics
Topic: Router connections
Replies: 5
Views: 358

Re: Router connections

Hi, The S-seen reply means that "seen new connection is replied by your device" , A-assured means "the connection is trusted" , C-confirmed means "connection is confirmed by your device or firewall" , d-dst-nat , F- i think this is FIN i mean no more data from sender it seen after a connection is c...
by CZFan
Fri Sep 21, 2018 9:07 pm
Forum: Beginner Basics
Topic: VLAN configuration with RB 1100AH en CRS125
Replies: 8
Views: 278

Re: VLAN configuration with RB 1100AH en CRS125

Yes, sorry, for management to the device itself you will need to create a vlan interface on the device
by CZFan
Fri Sep 21, 2018 8:58 pm
Forum: Beginner Basics
Topic: VLAN configuration with RB 1100AH en CRS125
Replies: 8
Views: 278

Re: VLAN configuration with RB 1100AH en CRS125

AFAIK in the second config snippet, those vlan interfaces shoud have been created on bridge not on ether2.

...
For OP's setup, you don't need to create any VLAN interfaces on the CRS
by CZFan
Fri Sep 21, 2018 8:55 pm
Forum: Beginner Basics
Topic: VLAN configuration with RB 1100AH en CRS125
Replies: 8
Views: 278

Re: VLAN configuration with RB 1100AH en CRS125

I don't see anywhere you are specifying tagged and or untagged (Access) ports, etc. Below is my understanding for the CRS1xx VLAN config straight from manual https://wiki.mikrotik.com/wiki/Manual:CRS1xx/2xx_series_switches_examples#Example_1_.28Trunk_and_Access_ports.29 To configure Port 1 as trunk ...
by CZFan
Thu Sep 20, 2018 3:50 pm
Forum: Beginner Basics
Topic: RB2011 slow internet even with fasttrack
Replies: 37
Views: 1458

Re: RB2011 slow internet even with fasttrack

Please log a call with support@mikrotik.com, inlcude reference to this post/topic
by CZFan
Wed Sep 19, 2018 8:15 pm
Forum: General
Topic: Weird outbound UDP traffic
Replies: 19
Views: 700

Re: Weird outbound UDP traffic

@Uqbar,

Please keep us posted
by CZFan
Wed Sep 19, 2018 7:46 pm
Forum: Beginner Basics
Topic: RB2011 slow internet even with fasttrack
Replies: 37
Views: 1458

Re: RB2011 slow internet even with fasttrack

Sorry, without actually being at the network, can't offer more
by CZFan
Wed Sep 19, 2018 7:44 pm
Forum: Beginner Basics
Topic: PPTP behind ISP Router (NAT problem)
Replies: 12
Views: 450

Re: PPTP behind ISP Router (NAT problem)

On the server side: Change /ppp secret add local-address=192.168.9.1 name=test profile="server" remote-address 192.168.9.2 service=pptp routes="192.168.3.0/24 192.168.9.2 1" Remove /ip route add check-gateway=ping distance=1 dst-address=192.168.3.0/24 gateway=192.168.9.2 The routes= under /ppp secre...
by CZFan
Tue Sep 18, 2018 2:14 pm
Forum: Beginner Basics
Topic: PPTP behind ISP Router (NAT problem)
Replies: 12
Views: 450

Re: PPTP behind ISP Router (NAT problem)

please provide a new diagram and include the VPN addresses.

Also the config of both routers after obfuscating any sensitive information
by CZFan
Mon Sep 17, 2018 11:34 pm
Forum: Beginner Basics
Topic: PPTP behind ISP Router (NAT problem)
Replies: 12
Views: 450

Re: PPTP behind ISP Router (NAT problem)

Are you sure you allow the other LAN IP's in via firewall on Mikrotik?
by CZFan
Mon Sep 17, 2018 12:56 am
Forum: Beginner Basics
Topic: RB2011 slow internet even with fasttrack
Replies: 37
Views: 1458

Re: RB2011 slow internet even with fasttrack

Apologies if you mentioned it earlier, but from what version to what version did you upgrade when you first noticed the difference?
by CZFan
Sun Sep 16, 2018 9:47 pm
Forum: Beginner Basics
Topic: RB2011 slow internet even with fasttrack
Replies: 37
Views: 1458

Re: RB2011 slow internet even with fasttrack

Firstly, when pasting config, please place this between the code brackets, makes it easier to read and not such long posts. Then, I am a bit confused, you are showing 2 speedtests screens, one with 158Mb download and another with 448Mb download. the 448Mb is not to bad. In current config, you have m...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 20