Community discussions

MikroTik App

Search found 1827 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 7
by CZFan
Wed Oct 28, 2020 5:42 pm
Forum: Forwarding Protocols
Topic: BGP default originate
Replies: 1
Views: 80

Re: BGP default originate

Add a route filter for that peer and only allow default to it, something like:
/routing filter
add action=accept chain=BGP-Out prefix=0.0.0.0/0
add action=discard chain=BGP-Out
by CZFan
Tue Oct 27, 2020 10:58 am
Forum: General
Topic: GRE Tunnel with Hap ac3 LTE
Replies: 11
Views: 318

Re: GRE Tunnel with Hap ac3 LTE

... And if you do, is it even accessible from the outside? I've seen mobile operators assigning public IPs to LTE devices but NATing them to other public IPs anyway. Yup, had this with a customer of mine in Malawi, they were using public IPs belonging to some company in USA but NATed the connection...
by CZFan
Mon Oct 26, 2020 8:45 pm
Forum: Forwarding Protocols
Topic: VRF and overlapped IPs
Replies: 3
Views: 270

Re: VRF and overlapped IPs

You cannot use subnets that are directly overlapped in different VRFs in RouterOS v6...this is fixed in RouterOSv7 Would you mind elaborating on above? I am interested what other challenges might be with my config as per below. I can access all VRF routers from outside as well as inside from R1, in...
by CZFan
Fri Oct 23, 2020 3:31 pm
Forum: General
Topic: Best way to configure multi-SSID-AP with VLAN-breakout
Replies: 12
Views: 568

Re: Best way to configure multi-SSID-AP with VLAN-breakout

@bpwl, I suspect you might be onto something here, i.e. configs not cleaning up properly. I suspect it is more a "Winbox" issue. Was playing around with various configs re EoIP tunnel now in GNS 3 on CHR 6.45.9, had tunnel up, then made changes, tunnel down, then reverted the changes, tunnel stayed ...
by CZFan
Thu Oct 22, 2020 8:49 pm
Forum: General
Topic: IP address / device based volume stats
Replies: 3
Views: 156

Re: IP address / device based volume stats

There is a utility in Mikrotik Download archive called traffic counter.

It will count traffic going through the router, played with it little bit and seems cool, also suggested it to a customer of mine
MTArchive.JPG
by CZFan
Thu Oct 22, 2020 6:40 pm
Forum: General
Topic: Best way to configure multi-SSID-AP with VLAN-breakout
Replies: 12
Views: 568

Re: Best way to configure multi-SSID-AP with VLAN-breakout

My understanding is that "fraggle attack" (UDP Broadcast) is a variant of "smurf Attack" (ICMP),

Did you not maybe had a loop somewhere and the Draytek possibly interpreted this as a "fraggle attack"?
by CZFan
Thu Oct 22, 2020 6:33 pm
Forum: SwOS
Topic: CSS610-8G-2S+IN - no firmware to download?
Replies: 3
Views: 161

Re: CSS610-8G-2S+IN - no firmware to download?

...
Also, I tried to download the firmware manually, but there is nothing to download on the product's home page https://mikrotik.com/product/css610_8g_2s_in

Wow, seriously?

See screenshot below on same link you quoted!!
mtsoftware.JPG
by CZFan
Thu Oct 22, 2020 5:47 pm
Forum: Beginner Basics
Topic: Adding cAP AC to my network
Replies: 17
Views: 611

Re: Adding cAP AC to my network

...
Final comment, Dont use quotation marks for NAMES of anything. Quotes are used in MT to surround COMMENTS.
You are trying to hurt my brains and eyes with this approach

Quotation marks are necessary where names, comments, etc contains spaces
by CZFan
Tue Oct 20, 2020 3:59 am
Forum: Beginner Basics
Topic: help with denial of service internet minecraft server
Replies: 6
Views: 320

Re: help with denial of service internet minecraft server

Looks like a dons amplification attack,
Post full config ( between code tags [] in menu so we can see what is wrong
by CZFan
Tue Oct 13, 2020 12:40 am
Forum: General
Topic: Slow connection speed with „fasttrack” switched off.
Replies: 2
Views: 176

Re: Slow connection speed with „fasttrack” switched off.

I suspect more inefficiencies in your config.
Post results of /export file=filename hide-sensitive between code brackets
by CZFan
Tue Oct 13, 2020 12:28 am
Forum: General
Topic: Updating from 6.28
Replies: 4
Views: 207

Re: Updating from 6.28

That's very old, lots of security holes, metinstall is your friend
by CZFan
Mon Oct 12, 2020 3:57 pm
Forum: General
Topic: Having troubles with Q-in-Q on CRS305
Replies: 4
Views: 312

Re: Having troubles with Q-in-Q on CRS305

You are not showing full config, so it makes it difficult to assist.

All I can assume at this stage is that possibly you don't have "use service tag" configured on the vlan interface
by CZFan
Mon Oct 12, 2020 1:56 pm
Forum: General
Topic: Strange Tracking Problem on Mikrotik Filter rules
Replies: 8
Views: 330

Re: Strange Tracking Problem on Mikrotik Filter rules

Hi all, I usually drop all forwards as the last rule and allow only known tracked traffic. Now, I have an strange problem for creating a rule for allowing ping from one server to another. I should be able to do this using this rule: add action=accept chain=forward comment=Ping protocol=icmp src-add...
by CZFan
Sun Oct 11, 2020 6:52 pm
Forum: Beginner Basics
Topic: MTU LAN vs WAN
Replies: 6
Views: 309

Re: MTU LAN vs WAN

..., I’d know how to set the MTU, which is max package size +32. When I do the same test from my hAP ac the value looks different, naturally.
...
Should be +28 (20 bytes IP Header + 8 bytes ICMP Header)
by CZFan
Sun Oct 11, 2020 6:38 pm
Forum: Beginner Basics
Topic: need help with VLAN guest wireless on router and ap
Replies: 7
Views: 331

Re: need help with VLAN guest wireless on router and ap

Cant believe my friend recommended Mikrotik, "it's the best router" he said, "and if you have a problem they help you on forum"

what a bullshit.

Cry me a river...
by CZFan
Thu Oct 08, 2020 1:54 pm
Forum: Beginner Basics
Topic: How to get connected without any assigned IP to device?
Replies: 3
Views: 200

Re: How to get connected without any assigned IP to device?

Connect via the serial port with a console cable, set IP address, etc and then continue as per normal
by CZFan
Thu Oct 08, 2020 12:23 am
Forum: General
Topic: Having troubles with Q-in-Q on CRS305
Replies: 4
Views: 312

Re: Having troubles with Q-in-Q on CRS305

Post anonomized output from /export file=yourfilename between code brackets so we can see config and assist where possible
by CZFan
Wed Oct 07, 2020 12:57 pm
Forum: General
Topic: Connection NAT state srcnat?
Replies: 9
Views: 444

Re: Connection NAT state srcnat?

... My issue isn't really with invalid packets, but with private addresses leaking out. Supposedly they leak out because the packets are invalid, and so do not get srcnated. I want to either prevent anything that's not srcnated from going out on the WAN interface (which I thought would be doable us...
by CZFan
Tue Oct 06, 2020 7:16 pm
Forum: General
Topic: XBOX and MikroTik RouterOS v6.47 (stable) NAT | UPDATE: VPN
Replies: 16
Views: 566

Re: XBOX and MikroTik RouterOS v6.47 (stable) NAT

Hi there I have been trying to resolve this issue for the past 15 days, reading through forums but no luck at all As you may know, in order for XBOX to work properly, it needs an Open NAT - so far it is only Strict According to the Microsoft XBOX's website https://support.xbox.com/en-US/help/hardwa...
by CZFan
Mon Oct 05, 2020 3:48 pm
Forum: General
Topic: Using most available bandwidth wan
Replies: 35
Views: 1083

Re: Using most available bandwidth wan

I dont use NAT right now. I just have. Mikrotik vpn server setup. People vpn first, grab a local ip, and co nect to internal servers. So if this is the case i should use ecmp? Then is what i currenctly have what i can have as the ideal setup? Where does VPN come into the picture now? Your config sh...
by CZFan
Mon Oct 05, 2020 2:26 pm
Forum: Scripting
Topic: Torrent blocking working in y2020
Replies: 20
Views: 3003

Re: Torrent blocking working in y2020

The Torrent system on it's own is not illegal. Downloading copyrighted content is illegal. This is my understanding also, read an article yesterday that in Germany, some law firms are not so ethical (who would have thought) and sending very threatening letters to people to pay up, and the normal Jo...
by CZFan
Mon Oct 05, 2020 2:17 pm
Forum: General
Topic: Using most available bandwidth wan
Replies: 35
Views: 1083

Re: Using most available bandwidth wan

I think speedtest.net uses multiple connections for download. That is where i saw more than 50mbit. But yeah for the rest i get it. I just need help to change my config to pcc now. Can you help me with that please. I am not sure how to adapt my vlans and bridge to the pcc example Yes, speedtest.net...
by CZFan
Mon Oct 05, 2020 11:35 am
Forum: General
Topic: Using most available bandwidth wan
Replies: 35
Views: 1083

Re: Using most available bandwidth wan

I suspect that video does not shoe the "full truth"

ECMP is based on per connection, so if src and dst address is same, you will only use one of the uplinks, it is not a "per packet" solution
by CZFan
Mon Oct 05, 2020 1:01 am
Forum: General
Topic: any tool like UNMS for mikrotik hw?
Replies: 1
Views: 315

Re: any tool like UNMS for mikrotik hw?

Yes, called the Dude
by CZFan
Mon Oct 05, 2020 12:28 am
Forum: Beginner Basics
Topic: router not starting
Replies: 10
Views: 407

Re: router not starting

Reset button has various functions depending how long you press it during reset process.

Something like 5 seconds for factory reset, 10 seconds for metinstall and 15 seconds for capsman, can't remember the details but all described in wiki article
by CZFan
Sun Oct 04, 2020 9:55 pm
Forum: Beginner Basics
Topic: router not starting
Replies: 10
Views: 407

Re: router not starting

The problem is on your side, not the Mikrotik device Since the device pops up in netinstall, firewall, etc is ok and network connection profile also. copy the .npk file into same folder as netinstall.exe Make sure you laptop/pc doing netinstall from is in same IP range as per boot IP address in neti...
by CZFan
Sun Oct 04, 2020 7:33 pm
Forum: Forwarding Protocols
Topic: BGP NO-PREPEND REPLACE-AS ON CCR
Replies: 1
Views: 141

Re: BGP NO-PREPEND REPLACE-AS ON CCR

in the BGP peer config enable "as-override"
bgpasoverride.JPG
by CZFan
Fri Oct 02, 2020 8:55 pm
Forum: General
Topic: BIG FAIL restore
Replies: 5
Views: 283

Re: BIG FAIL restore

make sure you enter the user that created the backup correctly, below from wiki Warning: If password is not provided in RouterOS versions older than v6.43, then the backup file will be encrypted with the current user's password, except if the dont-encrypted property is used or the current user's pas...
by CZFan
Fri Oct 02, 2020 8:30 pm
Forum: Beginner Basics
Topic: RB3011UIAS-RM and TPLink C5400 Access Point [SOLVED]
Replies: 4
Views: 205

Re: RB3011UIAS-RM and TPLink C5400 Access Point [SOLVED]

When you referring to the TP-Link's MAC address, are you referring to the 3011's bridge host table, the switch host table or ARP table?

Maybe a good idea to post config of the 3011 config here (between code brackets) and a packet capture file, maybe someone spots a problem
by CZFan
Fri Oct 02, 2020 8:12 pm
Forum: General
Topic: Parent Queue Limits do not apply.
Replies: 7
Views: 363

Re: Parent Queue Limits do not apply.

parent queues is responsible for distributing the bandwidth, not limits if you are using PCQ, then you should not have child queues, the system will automatically create sub streams with limits for each client based on the pcq queue type configuration, here you can specify a limit for all sub stream...
by CZFan
Fri Oct 02, 2020 7:42 pm
Forum: Beginner Basics
Topic: router not starting
Replies: 10
Views: 407

Re: router not starting

select net boot and set ip to 192.168.88.3 Don't follow the manual on this, it is completely wrong Set ip to 192.168.88.1 instead and netinstall will work Dont agree The netinstall is a bootp server and will assign range you configure. I have been using range 192.168.1.2 in bootp client config on n...
by CZFan
Fri Oct 02, 2020 6:59 pm
Forum: General
Topic: Unbrick a HAP AC2 [SOLVED]
Replies: 3
Views: 233

Re: Unbrick a HAP AC2 [SOLVED]

I never tried this, but should not need another "default script", just straight netinstall should work
by CZFan
Fri Oct 02, 2020 6:55 pm
Forum: Beginner Basics
Topic: RB3011 Re-plugging WAN losing INTERNET
Replies: 3
Views: 215

Re: RB3011 Re-plugging WAN losing INTERNET

suspect the problem is with detect internet configs, I usually disable this by:
/int detect-internet set detect-interface-list=none lan-interface-list=none wan-interface-list=none internet-interface-list=none
by CZFan
Fri Oct 02, 2020 6:43 pm
Forum: Beginner Basics
Topic: RB3011UIAS-RM and TPLink C5400 Access Point [SOLVED]
Replies: 4
Views: 205

Re: RB3011UIAS-RM and TPLink C5400 Access Point [SOLVED]

From a 3011 point of view, the TP-Link will just be another network device, so suspect problem is on your TP-Link side. I actually did one of these exact setups for another customer of mine the other day, was not the Archer but was TP-Link. I had to configure the TP-Link as Access Point only, restar...
by CZFan
Fri Oct 02, 2020 6:26 pm
Forum: Beginner Basics
Topic: How much bad blocks is too much bad blocks?
Replies: 1
Views: 150

Re: How much bad blocks is too much bad blocks?

$40 is half the suggested retail price.

As far as bad block, dont know, might be the beginning of the end or it can still last a while, that you will have to decide if the price tag is good enough for the gamble
by CZFan
Fri Oct 02, 2020 6:21 pm
Forum: Beginner Basics
Topic: RB fail install in netinstall
Replies: 2
Views: 100

Re: RB fail install in netinstall

make sure you selected the package file (.npk)

I usually place the package file in same folder as netinstall.exe
by CZFan
Fri Oct 02, 2020 6:02 pm
Forum: Beginner Basics
Topic: Please Help . PPPoE Terminating
Replies: 3
Views: 195

Re: Please Help . PPPoE Terminating

error means client device disconnected but connected again before the previous session was teared down in PPPoE service.

You should look why the client devices disconnect frequently, that problem can be anywhere between PPPoE Access Concentrator and client device
by CZFan
Wed Sep 30, 2020 4:22 pm
Forum: Beginner Basics
Topic: [CCR1009-7G-1C-1S+] version 6.46.4 | forward ssh from outside to internal server
Replies: 2
Views: 169

Re: [CCR1009-7G-1C-1S+] version 6.46.4 | forward ssh from outside to internal server

try changing the rule below to:

/ip firewall filter add chain=forward action=accept protocol=tcp dst-address=192.168.50.5 in-interface=sfp1.120 out-interface=ether1.2150 port=2223
by CZFan
Wed Sep 30, 2020 4:06 pm
Forum: Beginner Basics
Topic: hw=yes not showing as hw offload?
Replies: 8
Views: 568

Re: hw=yes not showing as hw offload?

You shouldn't need to Awesome. It's just that Mikrotik's own guide said to add it in, and I was like "But why?" I'll try just using the default bridge, given it offloads to the switch, so therefore should be "wire speed" and not done in software. Mikrotik (And other vendors) assume the reader will ...
by CZFan
Wed Sep 30, 2020 3:10 pm
Forum: Beginner Basics
Topic: A routing conundrum
Replies: 10
Views: 538

Re: A routing conundrum

Some things you should try to do yourself atleast, below is where you can change the default route distance on a DHCP client More than happy to do so and to learn but quite frankly had no idea how to change the default route distance on a DHCP client... Thanks for your help there ! Pleasure, glad y...
by CZFan
Wed Sep 30, 2020 3:05 pm
Forum: General
Topic: Share 2mbps equal on two user with different limit-at
Replies: 5
Views: 1645

Re: Share 2mbps equal on two user with different limit-at

you are still mixing pcq and other queue types...
by CZFan
Wed Sep 30, 2020 2:57 pm
Forum: RouterBOARD hardware
Topic: hAP ac³
Replies: 22
Views: 1645

Re: hAP ac³

Believe me Normis " clearly labeled INTERNET " is not enough for tipical residential Customers ;-D Is some cases they are even not able to find out an electrical plug... ;-D Rgds Deployed a FTTh solution in a golf estate, first question sked when customers calls in and say they have no internet "is...
by CZFan
Tue Sep 29, 2020 12:09 pm
Forum: Beginner Basics
Topic: A routing conundrum
Replies: 10
Views: 538

Re: A routing conundrum

...
Next question is how do I achieve it ? Those automatic routes don't seem to be "editable", at least not from Winbox...
Some things you should try to do yourself atleast, below is where you can change the default route distance on a DHCP client
distance.JPG
by CZFan
Fri Sep 25, 2020 9:52 pm
Forum: The User Manager
Topic: user manager eats up my disk [SOLVED]
Replies: 8
Views: 589

Re: user manager eats up my disk [SOLVED]

I have not worked much with usermanager, but maybe rather do a backup / export of usermanager data, clear database, move it and then restore / import from backup
by CZFan
Fri Sep 25, 2020 8:37 pm
Forum: General
Topic: Share 2mbps equal on two user with different limit-at
Replies: 5
Views: 1645

Re: Share 2mbps equal on two user with different limit-at

You are confusing queue leaf objects and PCQ in your config.

Either change the queue type in leaf queues to "default-small" which will work perfect for 2M queues, alternatively configure the PCQ queue types correct and assign this to the parent and remove the leave queues
by CZFan
Thu Sep 24, 2020 9:47 pm
Forum: Beginner Basics
Topic: hw=yes not showing as hw offload?
Replies: 8
Views: 568

Re: hw=yes not showing as hw offload?

first, which router / switch model?

Devices with only 1 switch chip, will only support HW offload on one / first bridge created
by CZFan
Thu Sep 24, 2020 8:47 pm
Forum: Announcements
Topic: Expected down time for this forum SEPT 11
Replies: 42
Views: 4328

Re: Expected down time for this forum SEPT 11

So, on 9-11 we are going to update the forum. Great timing. I remember it as yesterday that we sat in front a small TV in the firm with the staff looking, with disbelieve what was happening in New York. Yup, recall this very well also, was at Microsoft Tech-Ed at Sun City at the time, all went back...
by CZFan
Wed Sep 23, 2020 3:20 pm
Forum: The User Manager
Topic: user manager eats up my disk [SOLVED]
Replies: 8
Views: 589

Re: user manager eats up my disk [SOLVED]

Use a MicroSD or USB storage for the user manager data
by CZFan
Tue Sep 22, 2020 8:36 pm
Forum: General
Topic: Multiple device with same IP access [SOLVED]
Replies: 5
Views: 599

Re: Multiple device with same IP access [SOLVED]

Might just be semantics or maybe I missed it, but I don't see any "route rules" in the information you have posted, Route Rules are typically found under /ip route rules . What you have implemented I suppose is emulating VRF as VRF also marks traffic, etc, but I dont know if what you tried is everyt...
by CZFan
Wed Sep 16, 2020 9:40 pm
Forum: Forwarding Protocols
Topic: MPLS and MTU
Replies: 5
Views: 550

Re: MPLS and MTU

...

does anyone have any recommendations for a qualified consultant about this?

If you are South Africa based, I can assist
by CZFan
Tue Sep 08, 2020 7:26 pm
Forum: General
Topic: How to remove 802.1Q header on "untagged" bridge egress
Replies: 25
Views: 1453

Re: How to remove 802.1Q header on "untagged" bridge egress

When explained so succinctly even the blind, will be claiming they "see the light"!
Grab a coffee,
https://www.youtube.com/watch?v=gwgOUzodS6E
All night long!

That's the dude from the Patrick Swayze movie "Road House", cool movie
by CZFan
Tue Sep 08, 2020 12:34 am
Forum: General
Topic: Mikrotik version RB941-2nD-TC HAP Lite cannot control bandwidth on Queues?
Replies: 1
Views: 155

Re: Mikrotik version RB941-2nD-TC HAP Lite cannot control bandwidth on Queues?

It can control bandwidth and queues, but on a way smaller scal as its bigger cousins like the CCR's, etc
by CZFan
Tue Sep 08, 2020 12:20 am
Forum: Beginner Basics
Topic: Mikrotik to Mikrotik connection BW issues
Replies: 1
Views: 196

Re: Mikrotik to Mikrotik connection BW issues

Do not test from device to device, test through devices using imperfect tool on a Client laptop device

EDIT: Was suppose to say "iPerf tool", bloody autocarrot
by CZFan
Tue Sep 08, 2020 12:17 am
Forum: Beginner Basics
Topic: Routing
Replies: 4
Views: 336

Re: Routing

Not even going to waste my time by looking at your configs.

Place config between code brackets, it is in the menu items
by CZFan
Tue Sep 08, 2020 12:11 am
Forum: Beginner Basics
Topic: Untagged and tagged VLANs in RouterOS
Replies: 6
Views: 462

Re: Untagged and tagged VLANs in RouterOS

What is router and switch make and models?
by CZFan
Wed Sep 02, 2020 12:32 am
Forum: General
Topic: How set logs back to default? [SOLVED]
Replies: 3
Views: 299

Re: How set logs back to default? [SOLVED]

Prove the results of "/system logging export" then someone can assist to get all back to default
by CZFan
Tue Sep 01, 2020 12:54 am
Forum: General
Topic: Multiple device with same IP access [SOLVED]
Replies: 5
Views: 599

Re: Multiple device with same IP access [SOLVED]

I think the only way you going to get this to work properly will be by using VRF configuration.

In a nutshell , VRF does for layer 3 what vlans does for layer 2
by CZFan
Tue Sep 01, 2020 12:16 am
Forum: General
Topic: No dst-nat support for shifted portmap ranges?
Replies: 20
Views: 3242

Re: dst-nat 'to-port=start-end' range bug?

Post it on the forum as a "feature request"

I have not used this yet, so maybe just search the forum for above, think there are "topic headings" for it.

Alternatively send mail to support@mikrotik.com requesting this feature
by CZFan
Mon Aug 31, 2020 8:12 pm
Forum: SwOS
Topic: Loopback not working CRS305-1G-4S+IN
Replies: 5
Views: 344

Re: Loopback not working CRS305-1G-4S+IN

You might be on to something here. I tried switching to a Netgear GS105 unmanaged gigabit switch and the result was the same, i can only reach my NAS when i try to connect to the ip but no when i use the domain name. Thanks for pointing me in the right direction, i didn't expect to be able to get a...
by CZFan
Mon Aug 31, 2020 7:51 pm
Forum: Beginner Basics
Topic: (RouterOS 6.47.2) DHCP "defconf offering lease without success"
Replies: 3
Views: 272

Re: (RouterOS 6.47.2) DHCP "defconf offering lease without success"

1. This is Mikrotik "Users" forum, not Mikrotik support
2. If you connect device directly to Mikrotik router (Bypassing DD-WRT device) does it get DHCP, if so, then maybe go and scream on DD-WRT forum
by CZFan
Wed Aug 26, 2020 12:27 am
Forum: Forwarding Protocols
Topic: New Bridge config + MPLS/VPLS working?
Replies: 2
Views: 340

Re: New Bridge config + MPLS/VPLS working?

Yup, have it at a customer of mine (WISP) and no issues
by CZFan
Tue Aug 25, 2020 3:27 am
Forum: General
Topic: Can't get 10Gb on crs326-24s+2q+rm
Replies: 7
Views: 811

Re: Can't get 10Gb on crs326-24s+2q+rm

With that device if traffic is going via CPU you will probably only see about 500Mb/s transfer.

Best will be to provide full config as a starting point
by CZFan
Mon Aug 24, 2020 12:47 am
Forum: Beginner Basics
Topic: No Internet access on connected Wifi [SOLVED]
Replies: 5
Views: 486

Re: No Internet access on connected Wifi [SOLVED]

Your config is all over the place, have dhcp server where you should not, with duplicate ip ranges in both wan and lan, etc.
Reset to default config and start again
by CZFan
Fri Aug 21, 2020 11:46 am
Forum: Beginner Basics
Topic: add port to existing VLAN not possible?
Replies: 12
Views: 2117

Re: add port to existing VLAN not possible?

you can do the same as per dlink with mikrotik gui
addvlanport.JPG
by CZFan
Fri Aug 21, 2020 1:24 am
Forum: Beginner Basics
Topic: L2TP VPN Client Not Routing
Replies: 1
Views: 217

Re: L2TP VPN Client Not Routing

If the Mikrotik at branch offices communicate properly, then it sounds like the devices at the main office does not know where to route the subnet for branch office to, so ensure you have a route at main office for th branch office subnet pointing to the branch office as gateway
by CZFan
Thu Aug 20, 2020 2:28 pm
Forum: General
Topic: MikroTik CCR2004-1G-12S+2XS - Test
Replies: 2
Views: 377

Re: MikroTik CCR2004-1G-12S+2XS - Test

looks awesome, if only I could understand what was being said :-)
by CZFan
Wed Aug 19, 2020 8:55 pm
Forum: General
Topic: RB3011 Switch VLAN Access Port Issue
Replies: 7
Views: 1391

Re: RB3011 Switch VLAN Access Port Issue

over a year on and i still have this issue with access ports having traffic fall onto the bridge. I run a single bridge and you can clearly see when touching the port that some traffic just doesnt have a vlan tag. Fix it mikrotik. You had my supout files for some time now. Your config as per OP is ...
by CZFan
Wed Aug 19, 2020 1:21 am
Forum: General
Topic: Mikrotik behind ADSL model/router - allow UPnP
Replies: 6
Views: 433

Re: Mikrotik behind ADSL model/router - allow UPnP

See if you can configure the ADSL router in bridge mode,
Then authentication and PPPoE dialup happens from the Mikrotik and this UpNP config will then be a lot simpler
by CZFan
Wed Aug 19, 2020 12:55 am
Forum: General
Topic: LAN clients connnection drops occasionaly
Replies: 4
Views: 455

Re: LAN clients connnection drops occasionaly

The DHCP fail to offer lease is probably due to the same reason you can't access any device, so start there.
It sounds like a possible broadcast stor or some network device causing jabber on the network, or a faulty switch
by CZFan
Wed Aug 19, 2020 12:48 am
Forum: General
Topic: disabling "connection traking" and use PPTP/L2tp services
Replies: 2
Views: 365

Re: disabling "connection traking" and use PPTP/L2tp services

If that rule is only used to provide Internet to Vpn clients, then you can maybe look into split tunnel config.
That what they wil use Vpn for work purposes and Internet access via there own internet connection
by CZFan
Wed Aug 19, 2020 12:39 am
Forum: General
Topic: Connecting two Mikrotik and managing both
Replies: 1
Views: 216

Re: Connecting two Mikrotik and managing both

From your description, it sounds like you are using an interface as a gateway on router A.
That gateway in that route should be the outside ip of router B.

Else post copy of both router configs:

In terminal window, enter /export file=routera hide-sensitive, same for router b
by CZFan
Tue Aug 18, 2020 11:46 pm
Forum: Announcements
Topic: Winbox v3.24 released!
Replies: 106
Views: 57553

Re: Winbox v3.24 released!

Winbox after a few days continuous connection to CCR2004 (it seems doesn't matter) with ROS 6.47.1. Used memory growed from 10 MB to 695.
winbox_memory.png
Check the Google Chrome memory usage, bet you that was used to monitor Cisco equipment :-)
by CZFan
Tue Aug 18, 2020 10:59 am
Forum: General
Topic: VLAN port accross bridge [SOLVED]
Replies: 5
Views: 1028

Re: VLAN port accross bridge [SOLVED]

...
Would it works if the switch between is different brand, but the end switch still mikrotik ?

If it is a half decent switch, should not cause problems
by CZFan
Tue Aug 18, 2020 12:12 am
Forum: General
Topic: VLAN port accross bridge [SOLVED]
Replies: 5
Views: 1028

Re: VLAN port accross bridge [SOLVED]

If ether 10 is the uplink, it should be tagged
by CZFan
Mon Aug 17, 2020 11:39 pm
Forum: General
Topic: Custom Firmware.
Replies: 2
Views: 833

Re: Custom Firmware.

I don't think it is "custom firmware" on the device, but custom default script yes.

Net install should solve that
by CZFan
Mon Aug 17, 2020 10:57 pm
Forum: General
Topic: PPPoE and OSPF drops
Replies: 20
Views: 4028

Re: PPPoE and OSPF drops

I guess if all those good things were in place, we would be paying Cisco prices for Mikrotik :-)
by CZFan
Mon Aug 17, 2020 8:02 pm
Forum: General
Topic: [Feature request] Dhcp relay and arp bind
Replies: 5
Views: 1265

Re: [Feature request] Dhcp relay and arp bind

Not sure if I am misunderstanding, but the MAC address is not sent across a layer 3 network and DHCP relay works across layer 3.

If you want to use ARP, etc in DHCP across layer 3, then instead of using DHCP Relay, rather build a layer 2 tunnel and issue DHCP via this
by CZFan
Mon Aug 17, 2020 7:52 pm
Forum: Beginner Basics
Topic: Firewall drop port scanners rule trigered by Avast Antivirus
Replies: 3
Views: 765

Re: Firewall drop port scanners rule trigered by Avast Antivirus

add "in interface" of your WAN interface to narrow down the conditions
by CZFan
Mon Aug 17, 2020 7:44 pm
Forum: General
Topic: PPPoE and OSPF drops
Replies: 20
Views: 4028

Re: PPPoE and OSPF drops

solution is given to you by a fellow Mikrotik Forum member, from topic you quoted earlier

Connection Tracking places a big load on router
pppoe-issue.JPG
by CZFan
Mon Aug 17, 2020 5:08 pm
Forum: Scripting
Topic: If else commands scripting.
Replies: 31
Views: 29665

Re: If else commands scripting.

apologies, left out the reference to the variable ($i) in the "do" statement, try below: { :foreach i in=[/ip firewall nat find where action="masquerade" && chain="srcnat" && !src-address-list && !dst-address-list] \ do={/ip firewall nat set $i src-address-list=AllowedSrc dst-address-list=AllowedDst...
by CZFan
Mon Aug 17, 2020 4:38 pm
Forum: General
Topic: Per Connection Classiefier (PCC) blocks incomming FaceTime calls
Replies: 34
Views: 2540

Re: Per Connection Classiefier (PCC) blocks incomming FaceTime calls

The NAT rules in the above script should already route the packets out on the same interface it came in on. What else should be added?

Not the NAT rules, but the Mangle rules does, but only for connections to the router itself. You will need to add in the "forward" chain
by CZFan
Mon Aug 17, 2020 4:36 pm
Forum: General
Topic: No dst-nat support for shifted portmap ranges?
Replies: 20
Views: 3242

Re: dst-nat 'to-port=start-end' range bug?

For the record, I'm seeing the same problem with TCP forwarding. It works if the two ranges are the same. If you shift the to-ports range, the relative port tracking fails What "Relative" port forwarding? Port number " 1 234" is not the same as " 2 234" and there are no relation between them. The f...
by CZFan
Mon Aug 17, 2020 1:08 am
Forum: Beginner Basics
Topic: load balancing example taken from wiki Mikrotik
Replies: 3
Views: 885

Re: load balancing example taken from wiki Mikrotik

Allow / deny access between sub nets with firewall rules
by CZFan
Mon Aug 17, 2020 12:48 am
Forum: General
Topic: Per Connection Classiefier (PCC) blocks incomming FaceTime calls
Replies: 34
Views: 2540

Re: Per Connection Classiefier (PCC) blocks incomming FaceTime calls

Route packets out the same wan interface it came in on.

Also no need for double NAT if ISP router is configured correctly
by CZFan
Mon Aug 17, 2020 12:27 am
Forum: General
Topic: No dst-nat support for shifted portmap ranges?
Replies: 20
Views: 3242

Re: dst-nat 'to-port=start-end' range bug?

Ok
So let's say dst-ports=10000-20000 and to-ports=30000-40000
If client tries to connect to port 12345, router should forward to 32345...
Why?

What will make it select port number 32345?
by CZFan
Mon Aug 17, 2020 12:23 am
Forum: General
Topic: VLAN port accross bridge [SOLVED]
Replies: 5
Views: 1028

Re: VLAN port accross bridge [SOLVED]

You have made ether 9 part of vlan 10, so as the config stands right now, it will only have layer 2 access to the bridge interface on the 2011.
So add your uplink interface on 2011 towards the 750 under bridge vlan
by CZFan
Mon Aug 17, 2020 12:05 am
Forum: General
Topic: Load Balancing Challenge
Replies: 3
Views: 871

Re: Load Balancing Challenge

Yes, if your failover is configured correctly, it will not use the fiber as part of the LB
by CZFan
Sun Aug 16, 2020 11:54 pm
Forum: General
Topic: No dst-nat support for shifted portmap ranges?
Replies: 20
Views: 3242

Re: dst-nat 'to-port=start-end' range bug?

I don't understand your logic, neither do I see how you can call this a bug? You are sending a port number, you tell the firewall to do port translation, to a "range" of ports, the port number you are sending is not part of this "range" the rule must translate to. What port number do you expect the ...
by CZFan
Sun Aug 16, 2020 10:13 pm
Forum: Scripting
Topic: If else commands scripting.
Replies: 31
Views: 29665

Re: If else commands scripting.

This should set src/dst address lists where both are none
{
:foreach i in=[ip firewall nat find where action="masquerade" && chain="srcnat" && !src-address-list && !dst-address-list]
do={/ip firewall nat set src-address-list=AllowedSrc dst-address-list=AllowedDst}
}
by CZFan
Sun Aug 16, 2020 9:55 pm
Forum: General
Topic: Load Balancing Challenge
Replies: 3
Views: 871

Re: Load Balancing Challenge

LTE is still available between 18:00 - 23:00, but will cost more as those hours are outside the "package" deal.

So the only way to do what you want will need to be done by making use of scrips
by CZFan
Sat Aug 15, 2020 1:36 pm
Forum: General
Topic: PPPoE and OSPF drops
Replies: 20
Views: 4028

Re: PPPoE and OSPF drops

Indeed, both Mikrotik support and other colleagues of the forum pointed to alternative hardware as a solution, thank you.
Hmmm, I read it more like the problem is your architecture / configuration, but anyway....
by CZFan
Sat Aug 15, 2020 12:53 am
Forum: General
Topic: PPPoE and OSPF drops
Replies: 20
Views: 4028

Re: PPPoE and OSPF drops

... If you don't find a fix, I'd suggest looking for an alternative vendor for PPPoE concentrator duties, as we are currently doing. This problem was first reported in 2009 (11 years ago!!) and still has not been fixed. We can reliably reproduce and trigger the problem (if we drop any downstream ne...
by CZFan
Fri Aug 14, 2020 9:34 pm
Forum: Beginner Basics
Topic: Very Odd Throughput Issue
Replies: 2
Views: 822

Re: Very Odd Throughput Issue

Have you tried to remove the "dumb switch" out of the picture to make sure that is not the cause? i.e. connect Computer 1 directly to ether 2 If your WAN is on ether 1, and LAN on ether2, with correct config, you should get full 1Gb/s traffic If you test between ether 3 and ether 1, you will only ge...
by CZFan
Fri Aug 14, 2020 12:52 am
Forum: Beginner Basics
Topic: CRS305-1G-4S+in and Telus GPON SFP+
Replies: 2
Views: 447

Re: CRS305-1G-4S+in and Telus GPON SFP+

Firstly, the CRS is not a router, it is a switch by design and not sure you are going to get your full speed unless in a switched config. Secondly, IIRC, Mikrotikdoes not support GPoN SFP interfaces, so my suggestion will be: Connect the GPoN fiber to the ISP supplied Nokia, configure Nokia in a "Br...
by CZFan
Thu Aug 13, 2020 12:11 am
Forum: General
Topic: Cannot get gbit switch performance on RB2011
Replies: 5
Views: 1288

Re: Cannot get gbit switch performance on RB2011

You can configure vlan on the switch chip directly via menu-->switch item, see link below.

https://wiki.mikrotik.com/wiki/Manual:S ... p_Features

Also keep in mind, any "routing" will have to be done via CPU, so if any routing between vlans the above will not make any difference
by CZFan
Mon Aug 10, 2020 1:15 pm
Forum: RouterBOARD hardware
Topic: RB750GR3 or HAP AC2? Which one should I go for and why?
Replies: 12
Views: 2674

Re: RB750GR3 or HAP AC2? Which one should I go for and why?

if money is not an issue, go HAP AC2, alternatively you can also look at the newer HAP AC3
by CZFan
Mon Aug 10, 2020 1:12 pm
Forum: Wireless Networking
Topic: radar detected problems
Replies: 60
Views: 33463

Re: radar detected problems

Hi All, I can see this problem is old news without a solution to all, even Normis and Mikrotik. I got the problem solved on my own and my own way as you see on attached file. Since I made the country change, i stop getting the radar detection and the link is running nicely and smoothly fine. Guys, ...
by CZFan
Mon Aug 10, 2020 12:59 pm
Forum: Beginner Basics
Topic: load balancing example taken from wiki Mikrotik
Replies: 3
Views: 885

Re: load balancing example taken from wiki Mikrotik

/ip route rule
add disabled=no dst-address=192.168.1.0/24 table=main
add disabled=no dst-address=192.168.2.0/24 table=main
by CZFan
Mon Aug 10, 2020 11:28 am
Forum: Beginner Basics
Topic: add port to existing VLAN not possible?
Replies: 12
Views: 2117

Re: add port to existing VLAN not possible?

can you post the "pseudo code" of exactly what you are trying to achieve? Nevermind, I think I get what you are trying to do. Maybe the easiest will be to add comments to the vlan config lines, and then reference that when you want to amend settings via script { :foreach myvlan in=[/interface bridge...
by CZFan
Mon Aug 10, 2020 11:19 am
Forum: Scripting
Topic: If else commands scripting.
Replies: 31
Views: 29665

Re: If else commands scripting.

Dears, I am trying to use this script to check two-parameter but it just executes without any action. :foreach i in=[ip firewall nat find action=masquerade chain=srcnat src-address-list=no dst-address-list=no ] do={/ip firewall nat set src-address-list=AllowedSrc dst-address-list=AllowedDst} I'd li...
by CZFan
Mon Aug 10, 2020 12:07 am
Forum: Beginner Basics
Topic: add port to existing VLAN not possible?
Replies: 12
Views: 2117

Re: add port to existing VLAN not possible?

You will use set when changing an existing line in vlan table, and add to add a new line in the vlan table
by CZFan
Sun Aug 09, 2020 11:37 pm
Forum: Beginner Basics
Topic: Join 2 different networks
Replies: 6
Views: 1278

Re: Join 2 different networks

10.1.1.0/8 is part of the same subnet as 10.0.0.0/8, so your client device, i.e. 10.0.0.6 will never send the packet to the gateway, does not matter what NAT, routes etc you have on either router
by CZFan
Mon Aug 03, 2020 1:02 am
Forum: Forwarding Protocols
Topic: Point-to-point (/31) addresses
Replies: 77
Views: 51696

Re: Point-to-point (/31) addresses

@TomjNorthidaho, some creative thinking there, I might pop your balloon though :-)
That method is called point to point addressing and but should work
by CZFan
Sat Aug 01, 2020 2:34 am
Forum: General
Topic: Port Forwarding multiple XBox consoles
Replies: 5
Views: 1208

Re: Port Forwarding multiple XBox consoles

I don't have XBox, but doesn't it simply work with UPnP? ... Though I really like the info...what is the reason for opening a topic on this subject on a MikroTik forum? In my previous post I explained there has been a couple of questions on the multipli consoles and port forwarding to each and no s...
by CZFan
Sat Aug 01, 2020 1:46 am
Forum: Beginner Basics
Topic: Reset router and no longer able to use it
Replies: 2
Views: 691

Re: Reset router and no longer able to use it

You should not access it "from" IP address 192.168.88.1, as that will be the router address.
Then also make sure you try and access the router from ports 2 and up, as ether 1 will have firewall rules as per default config preventing access to device
by CZFan
Fri Jul 31, 2020 9:46 pm
Forum: General
Topic: Port scanner shows port 53 open although blocked in firewall
Replies: 4
Views: 1245

Re: Port scanner shows port 53 open although blocked in firewall

Solved. Had an accept rule above that couldn't find. Thank you.

And in there lies the magic in posting "full configs" when asking help, due to COVID-19 crystal ball manufacturing has been closed down
by CZFan
Fri Jul 31, 2020 9:29 pm
Forum: General
Topic: Port Forwarding multiple XBox consoles
Replies: 5
Views: 1208

Re: Port Forwarding multiple XBox consoles

Don't know, I use XBox for streaming :-) and only have 1, not a gamer at all myself.
But seen many people posting here asking help as they have multiple consoles behind router, thought it might help.
As it is an in game thing from Activision, should work even for PS consoles
by CZFan
Fri Jul 31, 2020 7:20 pm
Forum: General
Topic: Port Forwarding multiple XBox consoles
Replies: 5
Views: 1208

Port Forwarding multiple XBox consoles

I have found something that I thought might be worth sharing... Problem with multiple XBox consoles behind same router as Microsoft only allows 1 TCP/UDP port, i.e. 3074 But seems like Activision (Call of Duty) is allowing more ports within the game itself, and you can use more ports for multiple XB...
by CZFan
Fri Jul 31, 2020 5:31 pm
Forum: General
Topic: Unstopabale unsucessful ping
Replies: 24
Views: 3966

Re: Unstopabale unsucessful ping

I suspect you are doing a continues pin from a device in the LAN? No, not a bug. The route has been cached, hence the symptoms. If you prefer, you can disable route cache in ip settings, but this can have negative performance impact That's right, i make continues ping from a device in the LAN. And ...
by CZFan
Thu Jul 30, 2020 11:32 pm
Forum: General
Topic: Unstopabale unsucessful ping
Replies: 24
Views: 3966

Re: Unstopabale unsucessful ping

I suspect you are doing a continues pin from a device in the LAN?
No, not a bug.
The route has been cached, hence the symptoms. If you prefer, you can disable route cache in ip settings, but this can have negative performance impact
by CZFan
Wed Jul 29, 2020 2:16 am
Forum: Beginner Basics
Topic: Hardware offload
Replies: 4
Views: 1308

Re: Hardware offload

Personally, I find no issues with these devices as they are classified as SOHO devices and do the job they are designed for very well. With that said, people wanting to run all services possible on a single device plus 40 (exaggerated ) vlans in a SOHO environment I think is just silly. If it has to...
by CZFan
Wed Jul 29, 2020 1:32 am
Forum: Beginner Basics
Topic: Hardware offload
Replies: 4
Views: 1308

Re: Hardware offload

Disable STP on the bridge should enable hardware offload
by CZFan
Tue Jul 28, 2020 1:55 am
Forum: General
Topic: capability question
Replies: 7
Views: 1159

Re: capability question

Not sure I understand

SFP+ is a 10Gb/s interface, minus 2Gb/s used, leaves 8Gb/s for growth /spare
by CZFan
Sat Jul 25, 2020 1:16 am
Forum: Beginner Basics
Topic: mAP (RBmAP2nD) as WiFi range extender
Replies: 2
Views: 636

Re: mAP (RBmAP2nD) as WiFi range extender

If both devices are Mikrotik, you can read up and use WDS which will extend wifi range
See Mikrotik wiki articles for WDS
by CZFan
Sat Jul 25, 2020 1:02 am
Forum: Beginner Basics
Topic: Linking Two Routers With Same IP
Replies: 1
Views: 445

Re: Linking Two Routers With Same IP

192.168.100.10 is outside pc2 & 3 network, so the packets will be sent to router 2. Use something like 192.168.50.1/30 at router 1 and 192.168.50.2/30 at router 2 for connection between routers. On router 2 you will need a route pointing to gateway 192.168.50.1 for destination 192.168.100.0/24 Then ...
by CZFan
Sat Jul 25, 2020 12:33 am
Forum: Beginner Basics
Topic: HAP AC Lite (used as AP) keeps resetting
Replies: 10
Views: 1662

Re: HAP AC Lite (used as AP) keeps resetting

I am convinced this is a power supply issue, replace with same as per specs in data sheet and should be fine[flash=][/flash]
by CZFan
Tue Jul 21, 2020 12:49 am
Forum: Beginner Basics
Topic: how i can set limit data for group on Simble queue
Replies: 4
Views: 1039

Re: how i can set limit data for group on Simble queue

Configure that group of users to use a unique subnet, then specify the subnet as target in simple queue
by CZFan
Tue Jul 21, 2020 12:46 am
Forum: Beginner Basics
Topic: Mangle "Mark Connection" Troubleshooting [SOLVED]
Replies: 9
Views: 1938

Re: Mangle "Mark Connection" Troubleshooting [SOLVED]

"If there is more than one route with the same distance, selection is done in random (except for BGP " It also mentions route in FIB, and FIB is in Linux kernel, so assume to understand why ether 1 takes precedence one needs to look at Linux docs. https://wiki.mikrotik.com/wiki/Manual:Route_Selectio...
by CZFan
Tue Jul 21, 2020 12:22 am
Forum: General
Topic: SIM card position for LHG LTE kit
Replies: 8
Views: 2036

Re: SIM card position for LHG LTE kit

Remember to add a office tape onto SIM card, this help you exit the sim in future !
cool tip, thx for sharing
by CZFan
Mon Jul 20, 2020 10:14 pm
Forum: The Dude
Topic: Can Dude monitor a Win10 PC with firewall on?
Replies: 6
Views: 1434

Re: Can Dude monitor a Win10 PC with firewall on?

... Windows 10 default settings blocks ping, and I don't want to require users to change their settings. I am on the same network segment as the users whose PCs I want to monitor. ... No, Windows 10 default settings only blocks pings from outside its local subnet, so if Dude is on same network as P...
by CZFan
Mon Jul 20, 2020 9:32 pm
Forum: Beginner Basics
Topic: Firewall Layer 7 Filter
Replies: 4
Views: 1053

Re: Firewall Layer 7 Filter

...
I have an issue where Facebook has been blocked on a Unifi Network Router using a layer 7 protocol rule which is working 100%.
...

Not sure I understand, should you not then amend the layer 7 block rule on the Unify router?
by CZFan
Fri Jul 17, 2020 9:46 pm
Forum: General
Topic: VLAN Isolation
Replies: 43
Views: 7675

Re: VLAN Isolation

I personally dont think you should disable IP Forwarding, etc. What's the point of allowing IP forwarding only to block all L3 connectivity with firewall? Like you said in a post before, "there is a right way" Should not be an "All or Nothing" approach, tomorrow, OP changes his / her mind, and want...
by CZFan
Fri Jul 17, 2020 8:08 pm
Forum: General
Topic: VLAN Isolation
Replies: 43
Views: 7675

Re: VLAN Isolation

If you dont want the VLANs to be able to communicate with each other on layer 3, i.e. ICMP traffic, you should block this with firewall rules Then regarding "duplicate ping packets", think it will be best to show this in a packet capture as evidence, I personally dont think you should disable IP For...
by CZFan
Tue Jul 14, 2020 11:27 pm
Forum: Beginner Basics
Topic: Miss icmp connection...
Replies: 2
Views: 747

Re: Miss icmp connection...

Probably depends on your topology, i.e. Some IPs is going via bridge / switch and CPU never sees them

Provide network diagram and device config for more assistance
by CZFan
Tue Jul 14, 2020 7:21 pm
Forum: General
Topic: Move custom.json file to skins folder?
Replies: 12
Views: 2172

Re: Move custom.json file to skins folder?

I am tying the following, but it is not working: /tool> fetch address=192.168.88.1 src-path=/files/custom.json dst-path=/files/skins/custom.json Sorry I am a fetch newbie. Can anyone help with the correct syntax? Amend paths, etc as per your requirements /tool fetch address=192.168.88.1 mode=ftp sr...
by CZFan
Tue Jul 14, 2020 4:27 pm
Forum: General
Topic: Move custom.json file to skins folder?
Replies: 12
Views: 2172

Re: Move custom.json file to skins folder?

Moving into folders can only be done in two ways. Winbox (can be used in Linux too, with Wine), or using Fetch to directly download the file into the correct folder.
Actually a third way is to download using Fetch from one folder to other folder, locally.
SCP and or FileZilla?
by CZFan
Tue Jul 14, 2020 12:13 am
Forum: Beginner Basics
Topic: SSTP Split Tunnel problem
Replies: 1
Views: 537

Re: SSTP Split Tunnel problem

Not sure if I am missing the purpose of the OP, but maybe ha,be a rad through these
https://docs.microsoft.com/en-us/window ... pn-routing
by CZFan
Sun Jul 12, 2020 6:05 pm
Forum: Beginner Basics
Topic: Port forward on LTE
Replies: 21
Views: 4056

Re: Port forward on LTE

If the USB device does not know about the LAN subnet, then you can try the "fake" DMZ method (I hate the person that coined this "DMZ" phrase on these home devices) like you stated you have done already. This way the "DMZ" forwarding will have to point to your Mikrotik, then your Mikrotik will have ...
by CZFan
Sun Jul 12, 2020 5:04 pm
Forum: Beginner Basics
Topic: Port forward on LTE
Replies: 21
Views: 4056

Re: Port forward on LTE

Its opened as dmz already so it sbould be ok from the dongle side. What i dont understand how that mikrotik will know fixedwanip belongs to lte interface You will have to tell the Mikrotik whatever enters each WAN interface must leave same WAN interface going out to Internet, i.e. route rules and o...
by CZFan
Sun Jul 12, 2020 4:52 pm
Forum: Beginner Basics
Topic: Port forward on LTE
Replies: 21
Views: 4056

Re: Port forward on LTE

You will have to do port forwarding on the USB dongle. If that is not possible, then you will have to configure the USB dongle in bridge / passthrough mode (if possible) so it can pass the public IP directly to the Mikrotik and then do port forwarding on the Mikrotik
by CZFan
Sun Jul 12, 2020 4:38 pm
Forum: Beginner Basics
Topic: Public IP access Local IP
Replies: 9
Views: 2214

Re: Public IP access Local IP



In the ether 1 i have 100.70.1.181/20 (from my ISP)

Address as per above falls within the CGNAT range and no matter what port forwarding you do on your device, it will not work as you are being NATed at the ISP side
by CZFan
Fri Jul 10, 2020 1:30 pm
Forum: General
Topic: Why UDP Bandwidth Test always show Lost Packets = 0?
Replies: 4
Views: 711

Re: Why UDP Bandwidth Test always show Lost Packets = 0?

You have been answered, in the same topic / thread you quoted above.

i.e.
TCP = Connection Oriented Protocol
UDP = Connection-less Protocol

For UDP to know / track packet errors / drops / etc, it must be coded in the higher up OSI layers
by CZFan
Fri Jul 10, 2020 2:01 am
Forum: Forwarding Protocols
Topic: MPLS labels missing in traceroute output [SOLVED]
Replies: 8
Views: 1788

Re: MPLS labels missing in traceroute output [SOLVED]

You must use the trace route within Winbox, either in cli in Winbox or menu option in Winbox, this will show you the labels between hops
by CZFan
Fri Jul 03, 2020 11:53 pm
Forum: Beginner Basics
Topic: Combining firewall filter connection-state
Replies: 1
Views: 479

Re: Combining firewall filter connection-state

Within the same filter condition it is OR, between multiple filter conditions it is AND
by CZFan
Fri Jul 03, 2020 3:04 pm
Forum: Beginner Basics
Topic: Is a hEX (RB750Gr3) powerfull enough...
Replies: 6
Views: 1054

Re: Is a hEX (RB750Gr3) powerfull enough...

Hex is a great fit for those needs. If your managed switch has an SFP port the HEX S, may be a nice option. Thanks! Yeah - my switch does have that option, but I already got the "normal" hEX from earlier so all things considered I'm gonna try to make it work as is and take it from there... In your ...
by CZFan
Thu Jul 02, 2020 2:57 pm
Forum: General
Topic: Traffic Generator - Big vs small packets (strange) results
Replies: 7
Views: 1163

Re: Traffic Generator - Big vs small packets (strange) results

The testing method you are trying to design is fundamentally flawed, you placing a shit load on the CPU of the router by using traffic generator, so with this heavy load, you can expect packet loss, etc.

As I said before, test "through" the router using tools i.e. iPerf, etc
by CZFan
Thu Jul 02, 2020 12:32 pm
Forum: General
Topic: RB2011UiAS-2Hnd Booting Log Error [SOLVED]
Replies: 5
Views: 862

Re: RB2011UiAS-2Hnd Booting Log Error [SOLVED]

...
Message: error while running customized default configuration script: no such item

The error started to appear suddenly 3 weeks ago.
No changes were made to the router configuration.
...

I am 99.9999% convinced you made a change, i.e. updated / upgraded the ROS version hence the error
by CZFan
Thu Jul 02, 2020 1:12 am
Forum: General
Topic: Schedule to enable and disable interface in mikrotik
Replies: 14
Views: 9487

Re: Schedule to enable and disable interface in mikrotik

Personally can't recall if I ever had issues with devices connecting to eithe 2 / 5 Ghz, except in very noisy areas where neighbors wifi routers interfered so much with each other that the client devices failed to connect,
by CZFan
Thu Jul 02, 2020 12:57 am
Forum: General
Topic: Doubt about PPPoE Local Address
Replies: 16
Views: 3753

Re: Doubt about PPPoE Local Address

Thx @mducharme PPPOE terminates on a central AC, so OSPF is not causing multiple lines going down, so can't be that. Also only static src/dst NAT rules, no masquerade The symptoms are CPE sends numerous echo request to PPPoE AC, the AC sends out echo reply 85 seconds after receiving first echo reque...
by CZFan
Wed Jul 01, 2020 5:17 pm
Forum: General
Topic: Schedule to enable and disable interface in mikrotik
Replies: 14
Views: 9487

Re: Schedule to enable and disable interface in mikrotik

Below will disable all interfaces where name contains "wlan"
/interface disable [find where name~"wlan"]
Then it seems you have a spelling mistake in the script name, so correct this and should work

1 name="DiisableWLAN" owner="admin"
by CZFan
Wed Jul 01, 2020 4:53 pm
Forum: General
Topic: Traffic Generator - Big vs small packets (strange) results
Replies: 7
Views: 1163

Re: Traffic Generator - Big vs small packets (strange) results

To "properly" test a router, you need to test traffic / packets through the router, not generate traffic from the router, traffic generator is just to use to give some guideline and see if there is something major wrong, i.e. you get 50Mb/s instead of 100Mb/s, etc Post results as through the router ...
by CZFan
Tue Jun 30, 2020 1:12 pm
Forum: General
Topic: Doubt about PPPoE Local Address
Replies: 16
Views: 3753

Re: Doubt about PPPoE Local Address

..
So my question is, must the local address be attached to a physical / virtual interface?
...
Sorry, don't think I was clear in my question, what I meant to ask was:

So my question is, must the local address be "static" configured to a physical / virtual interface?
by CZFan
Mon Jun 29, 2020 10:03 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 62
Views: 8258

Re: LAN to LAN forwarding [SOLVED]

...
Hmm. yes, you are right. But I think that problem is solvable too. I'll check.
Like your energy / enthusiasm / attitude towards a problem!!
by CZFan
Mon Jun 29, 2020 9:49 pm
Forum: General
Topic: LAN to LAN forwarding [SOLVED]
Replies: 62
Views: 8258

Re: LAN to LAN forwarding [SOLVED]

@xvo, "that thing..." gave me a good laugh.

Might be a solution, but that will mean all clients will have to be reconfigured to point to WAN address and not internal address of server
by CZFan
Mon Jun 29, 2020 7:17 pm
Forum: Forwarding Protocols
Topic: New Bridge/Vlan leakage
Replies: 8
Views: 1313

Re: New Bridge/Vlan leakage

... Yes. I want to do routing between vlans. So it should be reachable. My problem is to see the bridge mac *and* the Ethernet MAC. Sorry, then I misunderstood your question in OP. In default config, MNDP broadcasts on all interfaces except dynamic ones, so in this case, the ether interface as well...
by CZFan
Mon Jun 29, 2020 5:18 pm
Forum: Forwarding Protocols
Topic: New Bridge/Vlan leakage
Replies: 8
Views: 1313

Re: New Bridge/Vlan leakage

As I said in my post, the "bridge" interface provides access to the CPU, i.e. the device itself, you have: /interface bridge vlan add bridge=bridge1 tagged= bridge1 untagged=ether2 vlan-ids=1 add bridge=bridge1 tagged=ether2, bridge1 untagged=vplsTunnelXXX vlan-ids=4 add bridge=bridge1 tagged=ether2...
by CZFan
Mon Jun 29, 2020 2:20 pm
Forum: Forwarding Protocols
Topic: New Bridge/Vlan leakage
Replies: 8
Views: 1313

Re: New Bridge/Vlan leakage

The expected behavior all depends on how you did the configuration and without seeing this makes it impossible to comment. I do suspect that you stopped halfway, if you read further in the quoted URL, you will see where it talks about "Unintentionally allowed management access..." And explains how ...
by CZFan
Mon Jun 29, 2020 12:10 am
Forum: Forwarding Protocols
Topic: New Bridge/Vlan leakage
Replies: 8
Views: 1313

Re: New Bridge/Vlan leakage

The expected behavior all depends on how you did the configuration and without seeing this makes it impossible to comment. I do suspect that you stopped halfway, if you read further in the quoted URL, you will see where it talks about "Unintentionally allowed management access..." And explains how t...
by CZFan
Sun Jun 28, 2020 10:50 pm
Forum: Beginner Basics
Topic: Inter-vlan routing speed issues (RB750Gr3 + CSS326-24G-2S+RM)
Replies: 3
Views: 899

Re: Inter-vlan routing speed issues (RB750Gr3 + CSS326-24G-2S+RM)

If hex is not in a "switched" configuration, and depending on your internet connection speed and usage, you might get a bit more between VLAN's.
Make ether1 your WAN interface, ether2 for "Trusted" vlan and ether3 for "Services" vlan.
That way you will have 2 X 1gb/s paths between ethers 2, 3 & CPU
by CZFan
Sun Jun 28, 2020 1:11 am
Forum: General
Topic: Doubt about PPPoE Local Address
Replies: 16
Views: 3753

Re: Doubt about PPPoE Local Address

Thank you very much for your excellent advice. Should the IP address chosen be added to an interface on the router? For example, if I use 10.0.0.1, should I make a bridge called loopback and add that IP to it? You should use an IP address that your router has on some interface, but it doesn't matte...
by CZFan
Sun Jun 28, 2020 12:14 am
Forum: General
Topic: How mikrotik MAC address connection works without IP address [SOLVED]
Replies: 5
Views: 1470

Re: How mikrotik MAC address connection works without IP address [SOLVED]

... It all is quite similar to how Novell NetWARE operated in the days before it used IP as intermediate layer. Novell Netware used IPX protocol which works at the network layer, i.e. Layer 3 The more correct way of describing is, the same as "Microsoft workgroup" networking used to work, i.e. Netb...
by CZFan
Thu Jun 25, 2020 11:30 pm
Forum: General
Topic: DNS forward based on domain name
Replies: 29
Views: 8582

Re: DNS forward based on domain name

Just noticed it myself in changelog :-)
Good news indeed

Although regex has been mentioned before by staff to be heavy
@xsebastia, welcome back. It's been a while
by CZFan
Thu Jun 25, 2020 7:01 pm
Forum: Forwarding Protocols
Topic: Mikrotik CCR 1072 route cache
Replies: 5
Views: 1279

Re: Mikrotik CCR 1072 route cache

route cache has been removed from newer linux kernels because of the performance impact under load. Turn route cache off, your router will survive a bit better in a DDoS with it disabled. Reason was that it was "buggy" and no one was maintaining it, hence being removed https://lists.openwall.net/ne...
by CZFan
Wed Jun 24, 2020 1:36 am
Forum: Beginner Basics
Topic: Unable to log into CSS326-24G-2S+RM
Replies: 1
Views: 391

Re: Unable to log into CSS326-24G-2S+RM

The CSS switches can only be managed via web browser, not Winbox.
Make sure your PCC has an IP in same range as CSS device, i.e. 192.168.88.10/24
If not successful try and factory reset device and do above again
by CZFan
Wed Jun 24, 2020 1:21 am
Forum: Wireless Networking
Topic: hAP ac or hAP ac^2 moderator please do not delete this post [SOLVED]
Replies: 77
Views: 11347

Re: hAP ac or hAP ac^2 moderator please do not delete this post [SOLVED]

Go ahead Shy, get the HEX, but first get a notarized piece of paper from CZFAN and XVO that you will achieve 1gig speed with default rule set plus maybe 5 extra rules. The paper should state that if you are unable to achieve 1gig, they will send you $1000US dollars as payment of apology and shame. ...
by CZFan
Tue Jun 23, 2020 10:46 pm
Forum: General
Topic: About IPsec and routing
Replies: 4
Views: 937

Re: About IPsec and routing

IPSec uses "Policies" to route, check in IPSec->Policies if the correct src / dst ranges are specified
by CZFan
Tue Jun 23, 2020 5:27 pm
Forum: Wireless Networking
Topic: hAP ac or hAP ac^2 moderator please do not delete this post [SOLVED]
Replies: 77
Views: 11347

Re: hAP ac or hAP ac^2 moderator please do not delete this post [SOLVED]

Geez, I need to add another so called 'experts' to the list (ochwepheshe)
Take your Hex 1GIG and politely shove it.
Hmmmm, maybe you should add one more to the list (self-opinionated)
by CZFan
Tue Jun 23, 2020 4:56 pm
Forum: Beginner Basics
Topic: PPPOE client doesn't load some websites [SOLVED]
Replies: 4
Views: 1476

Re: PPPOE client doesn't load some websites [SOLVED]

Sounds like it might be a fragmentation problem, change PPPoE MTU back to 1480, test again
1455-1492 caused a fragmentation and under 1455 caused time out!

Why don't you just leave the MTU settings to default, the PPPoE client will then detect correct MTU size
PPPoE MTU.JPG
by CZFan
Tue Jun 23, 2020 4:40 pm
Forum: General
Topic: Different DHCP pools on ports from 192.168.1.0/21 network?
Replies: 4
Views: 702

Re: Different DHCP pools on ports from 192.168.1.0/21 network?

"Discovery" is a layer 2 thing, with 2 or more IP subnets, you move to Layer 3.

Access each other on Layer 3 will not be a problem, but depends on the routing (Mikrotik will route between local subnets by default) and firewall rules on both Router Firewall as well as client devices
by CZFan
Tue Jun 23, 2020 4:33 pm
Forum: Announcements
Topic: v6.47 [stable] is released!
Replies: 349
Views: 96777

Re: v6.47 [stable] is released!

With this stable v6.47 release on my CCR1009 via CLI if I issue the following directive /ip firewall filter remove [find where comment="testing"] the directive completes without error but the rule is not removed Why? It means that the find did not find a match. Make sure case is correct if text, al...
by CZFan
Tue Jun 23, 2020 4:14 pm
Forum: Wireless Networking
Topic: hAP ac or hAP ac^2 moderator please do not delete this post [SOLVED]
Replies: 77
Views: 11347

Re: hAP ac or hAP ac^2 moderator please do not delete this post [SOLVED]

Using default config with fasttrack enabled - it will.
I cant remember the default config on the hEX, if it is "switched or not", but will definitely route 1Gb/s depending on your config.
by CZFan
Tue Jun 23, 2020 4:04 pm
Forum: Beginner Basics
Topic: CRS312 Issues
Replies: 20
Views: 3363

Re: CRS312 Issues

In Winbox:

Menu->Bridge->Ports
Select interface to be removed and click on "-" minus sign

In CLI:
/interface bridge port remove [find where interface="ether9"]
by CZFan
Tue Jun 23, 2020 3:34 pm
Forum: General
Topic: Intermittent loss of packets.............argg
Replies: 28
Views: 4745

Re: Intermittent loss of packets.............argg

This is probably why you see "packet loss"

add chain=ICMP comment=" Echo request - Avoiding Ping Flood" icmp-options=8:0 limit=1,5:packet protocol=icmp
by CZFan
Tue Jun 23, 2020 3:31 pm
Forum: General
Topic: Intermittent loss of packets.............argg
Replies: 28
Views: 4745

Re: Intermittent loss of packets.............argg

Jumps are harmless, it's what's in the target chain. It sometimes happens that people use random configs they find on internet and don't undestand what they do. ;)

lol, yes, it is that syndrome that if you think you can do "copy & paste", you are an IT expert :-)
by CZFan
Tue Jun 23, 2020 1:48 am
Forum: Beginner Basics
Topic: Using WLAN1 as WAN
Replies: 6
Views: 1101

Re: Using WLAN1 as WAN

You can create your own WAN interface list item, or use the interface WLAN1 directly with in / out-interface properties, etc
by CZFan
Sun Jun 21, 2020 1:41 am
Forum: Beginner Basics
Topic: CCR1036-8G-2S+EM Slow Download Great Upload
Replies: 1
Views: 594

Re: CCR1036-8G-2S+EM Slow Download Great Upload

Post a copy of the config here between code brackets so we can get some idea of your environment
by CZFan
Sat Jun 20, 2020 7:37 pm
Forum: Beginner Basics
Topic: CRS312 Issues
Replies: 20
Views: 3363

Re: CRS312 Issues

The WAN interface (ether9) must not be part of the bridge config, must be totally removed
IP address for LAN should be assigned to bridge interface, not sub/slave interface ether1
by CZFan
Sat Jun 20, 2020 7:19 pm
Forum: General
Topic: how to stop all traffic being routed though L2TP
Replies: 7
Views: 1661

Re: how to stop all traffic being routed though L2TP

Below should help you, replace IP / Prefixes as per your environment You can turn off taking over your entire connection by going to the properties of the VPN, Networking tab, Internet Protocol (TCP/IP) properties, Advanced, untick Use default gateway on remote network. This may or may not leave a r...
by CZFan
Sat Jun 20, 2020 2:41 am
Forum: General
Topic: how to stop all traffic being routed though L2TP
Replies: 7
Views: 1661

Re: how to stop all traffic being routed though L2TP

You can disable using remote gateway under VPN config, then add a persistent route to that subnet and attach that rout to your VPN profile. This will then only route traffic meant for the VPN via the VPN, all other traffic will be routed as per normal. I don't have the config for this on me now, but...
by CZFan
Sat Jun 20, 2020 2:33 am
Forum: Beginner Basics
Topic: CRS312 Issues
Replies: 20
Views: 3363

Re: CRS312 Issues

Sounds like you configured / connected it up as a switch. Which CRS's are anyway.

Post the exported config here and someone will try and assist
by CZFan
Thu Jun 18, 2020 1:49 am
Forum: General
Topic: Need help, certain websites stop working after EOIP
Replies: 3
Views: 911

Re: Need help, certain websites stop working after EOIP

Sounds like MTU issue, post anonymized version of the config (between code bracket) here for someone to look at
by CZFan
Thu Jun 18, 2020 1:45 am
Forum: Beginner Basics
Topic: Private VLAN [SOLVED]
Replies: 7
Views: 1867

Re: Private VLAN [SOLVED]

IIRC, only the CRS3xx switches support private vlan config.

The RB4011 switch chip is very limited
by CZFan
Wed Jun 17, 2020 10:04 pm
Forum: General
Topic: Intermittent loss of packets.............argg
Replies: 28
Views: 4745

Re: Intermittent loss of packets.............argg

@Anav, Not sure if I missed anything, but I have not seen any evidence in this thread that indicates any problems on the 450. Changing things from the default, i.e. flow control, etc is going to make your environment more complicated and more prone to problems. You are welcome to throw money at it a...
by CZFan
Tue Jun 16, 2020 1:44 am
Forum: General
Topic: Intermittent loss of packets.............argg
Replies: 28
Views: 4745

Re: Intermittent loss of packets.............argg

Anav, first do as you preach, i.e. Diagram with copes of config posted here.

Then someone can have a more educated look at things
by CZFan
Tue Jun 16, 2020 1:29 am
Forum: General
Topic: [SOLVED] Forwarding traffic to ftp in a tunnel through a specific IP
Replies: 4
Views: 945

Re: Forwarding traffic to ftp in a tunnel through a specific IP

FTP is a bit more complicated than other protocols, you have 2 modes, active and passive, but then also 2 sets of ports to deal with, i.e. Control and data.

Best will be for a certified Mikrotik consultant to assist,
by CZFan
Tue Jun 16, 2020 12:54 am
Forum: Forwarding Protocols
Topic: PPPoE over BGP based VPLS on a mesh network
Replies: 2
Views: 737

Re: PPPoE over BGP based VPLS on a mesh network

Tried to send you a PM but seems stuck in my outbox. Quick look of your config, it seems you are trying to do VPLS with eBGP. According to the RFC it should be possible, but I am not sure if it is supported by Mikrotik. I can assist with the config, I am based in Randburg. Contact info under my prof...
by CZFan
Tue Jun 09, 2020 3:01 am
Forum: Announcements
Topic: v6.45.9 [long-term] is released!
Replies: 83
Views: 63886

Re: v6.45.9 [long-term] is released!

Skins in web-interface stopped working after upgrading to 6.45.9. Checked on 2 different architecture routers. If the skin is assigned to a specific group (read only for example), a user of this group after login to web interface will see all elements, even the ones that were deselected in skin. If...
by CZFan
Sun Jun 07, 2020 2:53 am
Forum: Forwarding Protocols
Topic: DHCP Relay over OSPF?
Replies: 3
Views: 1356

Re: DHCP Relay over OSPF?

You will have to post the exported config of the devices
by CZFan
Thu Jun 04, 2020 8:01 pm
Forum: General
Topic: SXTsq_Lite2 with RB2011 setup [SOLVED]
Replies: 11
Views: 2269

Re: SXTsq_Lite2 with RB2011 setup [SOLVED]

DHCP works on Layer 2 (LAN) not Layer 3 (Routed)

So the question is why do you need the WAN IP on the 2011?

My suggestion will be to configure firewall, dhcp, etc on the SXT, on the 2011 create a bridge and place all interfaces, ether and wlan in the bridge and use it as a switch
by CZFan
Tue Jun 02, 2020 2:25 am
Forum: Beginner Basics
Topic: Router doesn't appear in Winbox interface despite reset procedure
Replies: 10
Views: 1809

Re: Router doesn't appear in Winbox interface despite reset procedure

If you followed the correct factory reset procedure, i.e. Power down router, press and hold reset button while powering up router until usr light starts flashing (about 5 to 7 seconds) release reset button. Then make sure you do not connect to ether1 of the router, but any other ether ports as there...
by CZFan
Tue Jun 02, 2020 1:58 am
Forum: Beginner Basics
Topic: Local Port definition and Port Forwarding
Replies: 47
Views: 5826

Re: Local Port definition and Port Forwarding

Post output of "/export hide-sensitive" between code brackets, I.e.
by CZFan
Mon Jun 01, 2020 12:26 am
Forum: Beginner Basics
Topic: RTSP "TAB" Settings
Replies: 6
Views: 1243

Re: RTSP Settings

IIRC, you have VLAN's in your environment, should not use RSTP then, but MSTP instead
by CZFan
Wed May 20, 2020 2:10 am
Forum: Beginner Basics
Topic: PPPOE client doesn't load some websites [SOLVED]
Replies: 4
Views: 1476

Re: PPPOE client doesn't load some websites [SOLVED]

Sounds like it might be a fragmentation problem, change PPPoE MTU back to 1480, test again
by CZFan
Sat May 16, 2020 3:36 am
Forum: Beginner Basics
Topic: OSPF link with same subnets both ends
Replies: 2
Views: 920

Re: OSPF link with same subnets both ends

1.
Change subnet on one of the sites, then use whatever routing you want to
Or
2.
Bridge the sites using EOIP tunnel and merge them into the same broadcast domain. What out for duplicate IPs, etc
by CZFan
Thu May 14, 2020 2:13 am
Forum: Beginner Basics
Topic: VLAN for WAN?
Replies: 11
Views: 1670

Re: VLAN for WAN?

@OP:
First question, what speed internet do you have?
by CZFan
Thu May 14, 2020 1:59 am
Forum: Beginner Basics
Topic: simple queue
Replies: 7
Views: 1446

Re: simple queue

Parent Q max limit=10Mb
Child Q's:
Pc1 limit at 5Mb max limit 10Mb
Pc2 same as above.

This way, they each guaranteed 5Mb, if there is spare bandwidth, it will be used which ever device requested it and if only 1 device active, it will have full 10Mb available to it
by CZFan
Mon May 04, 2020 1:10 am
Forum: General
Topic: winbox or webfig does not show me anything in MPLS network
Replies: 2
Views: 1033

Re: winbox or webfig does not show me anything in MPLS network

Sounds like MTU problem in network
by CZFan
Wed Apr 29, 2020 12:18 am
Forum: General
Topic: Splynx API required permissions
Replies: 1
Views: 1105

Re: Splynx API required permissions

Bump
by CZFan
Fri Apr 24, 2020 1:29 pm
Forum: General
Topic: Splynx API required permissions
Replies: 1
Views: 1105

Splynx API required permissions

I know this is not directly Mikrotik related, but did post on Splynx forum but not getting any response, so hope someone here can assist me. I followed the link below in order to provide Splynx API user permissions on Mikrotik but Splynx consultant insists that it requires "full admin permissions". ...
by CZFan
Sun Mar 29, 2020 10:59 pm
Forum: Announcements
Topic: v6.45.8 [long-term] is released!
Replies: 87
Views: 64893

Re: v6.45.8 [long-term] is released!

Is / has anyone else experience intermittent PPPoE drops with this version? I have a customer which is a fairly large ISP which and experiencing this. Besides for 1 router at a high site where the uplink ethernet interface goes up/down intermittently, the network is stable. I have pointed out the in...
by CZFan
Thu Mar 26, 2020 3:11 am
Forum: General
Topic: L2TP IPSec VPN not working from W10 (other Windows connects OK)
Replies: 4
Views: 1393

Re: L2TP IPSec VPN not working from W10 (other Windows connects OK)

Can possibly be two scenarios, one is a register change if any of the devices are behind NAT.

Other is you need to connect using start->settings->VPN->the VPN you want to connect and click on connect there
by CZFan
Sat Mar 21, 2020 1:18 am
Forum: General
Topic: Best Tunnel MTU 1500 FOr PPPOE
Replies: 2
Views: 985

Re: Best Tunnel MTU 1500 FOr PPPOE

Depending on your network architecture, equipment, etc. the other option is to go OSPF/MPLS with VPLS
by CZFan
Thu Mar 19, 2020 10:40 pm
Forum: Beginner Basics
Topic: MikroTik Mtcna Home Learning
Replies: 13
Views: 2848

Re: MikroTik Mtcna Home Learning

Is there also an exam and a certificate as part of this effort, or is this just the training material...........

Mikrotik policy is you have to attend class based training to qualify for test / exam
by CZFan
Thu Mar 19, 2020 10:01 pm
Forum: General
Topic: Hello How can I change totallimit 2000 and limit 50
Replies: 9
Views: 1959

Re: Hello How can I change totallimit 2000 and limit 50

Can you repost the picture, can't access it
by CZFan
Wed Mar 18, 2020 12:34 pm
Forum: General
Topic: RB4011 SFP+ simple question
Replies: 1
Views: 979

Re: RB4011 SFP+ simple question

... i am looking at the data specs and it states that for 25 simple queues max troughput is just 4xx mbps which i think its very litle... ... I am not sure how you are reading the data specs, but the way I read it, for 25 simple queues, the max throughput is 9,792 Gb/s . You can probably expect a b...
by CZFan
Tue Mar 17, 2020 11:06 pm
Forum: General
Topic: 3CX NAT when using 2 Servers
Replies: 18
Views: 4630

Re: 3CX NAT when using 2 Servers

3cx has a packet capture facility, do a packet capture on 3cx server, view in wireshark to make sure correct port numbers are received by 3cx server from Mikrotik, if yes, then log call with 3cx, if no, come back here with packet capture details
by CZFan
Tue Mar 17, 2020 11:00 pm
Forum: General
Topic: Can't use vlan 1 as management vlan
Replies: 10
Views: 2475

Re: Can't use vlan 1 as management vlan

...
Update:
Tested it. Used
set 1 = ether 1
set 2 = ether 2
set 11 = switch1-cpu
...
Above is correct, the export seems to be screwed up in 6.46.4.

Apply as per my last post, then provide a full config, maybe there is a firewall rule or something preventing access.

use "export hide-sensitive"
by CZFan
Tue Mar 17, 2020 8:47 pm
Forum: Announcements
Topic: v6.46.4 [stable] is released!
Replies: 107
Views: 50152

Re: v6.46.4 [stable] is released!

Was playing with vlan on switch chip config, did an export, and some of the export config will be confusing for someone looking at it and not have access to the device, this was on a RB2011 /interface ethernet switch port set 1 vlan-header=add-if-missing vlan-mode=secure set 2 default-vlan-id=1 vlan...
by CZFan
Tue Mar 17, 2020 8:42 pm
Forum: General
Topic: Can't use vlan 1 as management vlan
Replies: 10
Views: 2475

Re: Can't use vlan 1 as management vlan

Not fully tested, but this seems to work on rb2011, which has the same switch chip /interface bridge add name=bridge1 protocol-mode=none /interface vlan add interface=bridge1 name=vlan1 vlan-id=1 /interface ethernet switch port set 1 vlan-header=add-if-missing vlan-mode=secure set 2 default-vlan-id=...
by CZFan
Tue Mar 17, 2020 7:01 pm
Forum: General
Topic: Can't use vlan 1 as management vlan
Replies: 10
Views: 2475

Re: Can't use vlan 1 as management vlan

IIRC, under /interface ethernet switch port you need to use vlan-header=leave-as-is on the Hap AC², etc
by CZFan
Mon Mar 16, 2020 6:34 pm
Forum: Beginner Basics
Topic: PPTP VPN
Replies: 1
Views: 1198

Re: PPTP VPN

Have you tried reading the Mikrotik Wiki?
by CZFan
Wed Mar 11, 2020 1:24 pm
Forum: Announcements
Topic: Winbox v3.22 released!
Replies: 117
Views: 50969

Re: Winbox v3.22 released!

I'm in love with new Log window :)
Ditto :-)
by CZFan
Wed Mar 11, 2020 1:23 pm
Forum: Announcements
Topic: Winbox v3.22 released!
Replies: 117
Views: 50969

Re: Winbox v3.22 released!

winbox64 is always opnening in a small window.....see picture :-(

I am not experiencing the same, Windows 10 version 1803
by CZFan
Mon Mar 09, 2020 11:32 pm
Forum: General
Topic: Multiple Internet Beakouts - cant connect via the Internet
Replies: 2
Views: 1297

Re: Multiple Internet Beakouts - cant connect via the Internet

To access the Mikrotik from Internet, you should not look under nat / mangle rules, but filter rules, and then look for chain=Input
by CZFan
Mon Mar 09, 2020 11:25 pm
Forum: General
Topic: How can I change the internet gateway metric? [SOLVED]
Replies: 11
Views: 3900

Re: How can I change the internet gateway metric? [SOLVED]

Measure the gate in imperial, then convert the numbers to metric and build a new gate based on the metric figures, voila :-)

Just joking, add a diagram, will make understanding what you want better
by CZFan
Mon Mar 09, 2020 7:21 pm
Forum: General
Topic: Router is infection by virus coinhive
Replies: 8
Views: 9769

Re: Router is infection by virus coinhive

If the old configuration were to contain some script, that sets passwords in your router and disables reinstall, it could do this before you run reset. @normis, Thank You, makes sense. Had a case where I suspected devices has been infected, did a netinstall but never checked if "keep old config" wa...
by CZFan
Mon Mar 09, 2020 1:32 pm
Forum: General
Topic: Router is infection by virus coinhive
Replies: 8
Views: 9769

Re: Router is infection by virus coinhive

I suggest to follow all MikroTik related news, this issue was fixed in April already. Please read instructions here: https://blog.mikrotik.com/security/winbox-vulnerability.html @normis, If I do a netinstall of an infected router, but "keep old configuration" is enabled, do an factory reset immedia...
by CZFan
Mon Mar 09, 2020 12:09 pm
Forum: Forwarding Protocols
Topic: OSPF Drops when adding a comment?
Replies: 13
Views: 4027

Re: OSPF Drops when adding a comment?

Is it normal for OSPF to drop / reload when only adding a comment on the OSPF
Try ro use CLI, i found that using
set comment="my comment" does not reset the session

I tested in CLI on GNS3 / CHR after the original incident, and did the same
by CZFan
Mon Mar 02, 2020 1:18 am
Forum: General
Topic: Vlan https issue
Replies: 9
Views: 2505

Re: Vlan https issue

Sounds like you have a MTU problem on your network
by CZFan
Sat Feb 29, 2020 3:39 pm
Forum: RouterBOARD hardware
Topic: OpenVPN Server config
Replies: 5
Views: 3895

Re: OpenVPN Server config

Also make sure you have a NAT/Masquerade rule to Internet for the VPN Subnet
by CZFan
Fri Feb 28, 2020 4:52 pm
Forum: Forwarding Protocols
Topic: OSPF Drops when adding a comment?
Replies: 13
Views: 4027

Re: OSPF Drops when adding a comment?

Wow, thx, did not expect that and dropped +- 1000 PPPoE connections earlier, ouch
by CZFan
Fri Feb 28, 2020 3:04 pm
Forum: Beginner Basics
Topic: proxy server
Replies: 1
Views: 1532

Re: proxy server

Take note that proxy will not work with HTTPS traffic, which is 90% of web traffic these days
by CZFan
Fri Feb 28, 2020 2:55 pm
Forum: Forwarding Protocols
Topic: OSPF Drops when adding a comment?
Replies: 13
Views: 4027

OSPF Drops when adding a comment?

Is it normal for OSPF to drop / reload when only adding a comment on the OSPF Interface?

RoS and Firmware 6.45.8 Long Term.
by CZFan
Mon Feb 24, 2020 3:30 pm
Forum: Announcements
Topic: v6.46.3 [stable] is released!
Replies: 28
Views: 37386

Re: v6.46.3 [stable] is released!

just had a case on a Hap AC2 where the 2,4 GHz wlan1 stopped running, nothing in the log file. Created supout file but when I restarted device to see if it solves the problem, the supout file created during the problem was deleted. (Supout file should be created in "/flash" if it exists by default) ...
by CZFan
Sun Feb 23, 2020 10:54 pm
Forum: General
Topic: 3CX NAT when using 2 Servers
Replies: 18
Views: 4630

Re: 3CX NAT when using 2 Servers

@anav,

Ports 9000 - 10999 is rtp ports, required for the voip audio, need 2 per voip conversation so nothing wrong there
by CZFan
Sun Feb 23, 2020 1:22 pm
Forum: Forwarding Protocols
Topic: Problem with a VPN Server Router behind Mikrotik
Replies: 4
Views: 2555

Re: Problem with a VPN Server Router behind Mikrotik

For PPTP you will also need the helper, i.e.
/ip firewall service-port
set pptp disabled=no
by CZFan
Sun Feb 23, 2020 12:27 am
Forum: General
Topic: 3CX NAT when using 2 Servers
Replies: 18
Views: 4630

Re: 3CX NAT when using 2 Servers

This is more a question for 3cx forum
by CZFan
Sun Feb 23, 2020 12:06 am
Forum: General
Topic: Ip Nat
Replies: 7
Views: 1900

Re: Ip Nat

You can setup an EOIP tunnel between office and home and access camera on dvr via via the tunnel
by CZFan
Sat Feb 22, 2020 11:47 pm
Forum: Beginner Basics
Topic: Multiple IP Pools on different LAN ports
Replies: 1
Views: 1225

Re: Multiple IP Pools on different LAN ports

The correct way will be to configure VLAN's for each subnet in a single bridge, alternative, you can remove ether4 from the current bridge and create the 2nd DHCP on ether4
by CZFan
Sat Feb 22, 2020 12:28 pm
Forum: Forwarding Protocols
Topic: OSPF Default Route not propigating.
Replies: 2
Views: 1837

Re: OSPF Default Route not propigating.

Just noticed the same thing, deployed OSPF for a customer Wednesday this week, the default route was being distributed at the time, checking this morning, it was not being distributed. Running 6.45.8 long term Changing distribute-default=always-as-type-1 to "never" and back to "always-as-type-1" cor...
by CZFan
Sat Feb 22, 2020 12:54 am
Forum: Beginner Basics
Topic: MT+SSTP VPN (VPN subnet + LAN all together?)
Replies: 5
Views: 2318

Re: MT+SSTP VPN (VPN subnet + LAN all together?)

There is a way to bind a route to the VPN interface, late here now, had my sleeping pill already, so maybe try google, if you don't come right, come back here
by CZFan
Sat Feb 22, 2020 12:48 am
Forum: Beginner Basics
Topic: VPN configuration bypass china firewall
Replies: 11
Views: 3397

Re: VPN configuration bypass china firewall

Here is my problem with this, you are asking someone to help you break the laws of the country, and that on a public forum?
by CZFan
Sat Feb 22, 2020 12:40 am
Forum: Beginner Basics
Topic: Native VLAN + 1 tagged VLAN
Replies: 3
Views: 1600

Re: Native VLAN + 1 tagged VLAN

What you are looking for is called hybrid vlan, see:

https://wiki.mikrotik.com/wiki/Manual:Bridge_VLAN_Table
by CZFan
Fri Feb 21, 2020 7:27 pm
Forum: Forwarding Protocols
Topic: BGP Route selection
Replies: 1
Views: 1659

Re: BGP Route selection

You seem to have multiple instances of BGP, see below. BGP weights, etc will not work between instances i.e.: " /routing bgp instance set default disabled=yes add as=65100 name=LDC router-id=10.15.155.2 add as=65100 name=VDC router-id=10.15.155.6 " Change this to be in the same instance, i.e. defaul...
by CZFan
Fri Feb 21, 2020 7:07 pm
Forum: General
Topic: Using the Loopback address for Software Upgrade/Checking for updates
Replies: 5
Views: 1569

Re: Using the Loopback address for Software Upgrade/Checking for updates

Sorry, have not played with IPv6 on RouterOS yet, and see there is no "NAT" in IP6 firewall.

I assumed that NAT, i.e. changing of a source address, etc, will still be there.

Best maybe is to see why your IP6 is not working properly on RouterOS, posting copy of config here and someone might assist
by CZFan
Fri Feb 21, 2020 12:55 pm
Forum: General
Topic: Using the Loopback address for Software Upgrade/Checking for updates
Replies: 5
Views: 1569

Re: Using the Loopback address for Software Upgrade/Checking for updates

Have you tried a source NAT rule to the Mikrotik FTP server?
by CZFan
Fri Feb 21, 2020 12:05 pm
Forum: Beginner Basics
Topic: Date format Please Help
Replies: 5
Views: 1605

Re: Date format Please Help

Date.JPG
by CZFan
Fri Feb 21, 2020 11:17 am
Forum: Beginner Basics
Topic: Help with VLAN setup
Replies: 4
Views: 1681

Re: Help with VLAN setup

It should be simple: - bridge all ports together - bridge itself is your untagged LAN - give PVID 2 to bridge port ether1 - add VLAN interface with id 2 on bridge - VLAN interface is your new WAN - configure VLAN assigment on bridge (in Bridge->VLANs), add VLAN 2 as untagged on ether1 and tagged on...
by CZFan
Fri Feb 21, 2020 10:43 am
Forum: General
Topic: RB2011UiAS looses about 40 megabits of thgougpput!?!
Replies: 49
Views: 7053

Re: RB2011UiAS looses about 40 megabits of thgougpput!?!

So they are choosing wireless pollution and high latency? I suppose the problem here is that the current copper cabling infrastructure is so old and causing lots and lots of problems. To make that worse, the copper cabling theft here is huge, Telkom or the electricity companies will replace a cable...
by CZFan
Thu Feb 20, 2020 7:54 pm
Forum: General
Topic: RB2011UiAS looses about 40 megabits of thgougpput!?!
Replies: 49
Views: 7053

Re: RB2011UiAS looses about 40 megabits of thgougpput!?!

... In the past I even bought a SFP VDSL modem for it, to replace the Draytek 130 VDSL modem I use at home. But that never really worked, mostly because RouterOS does not include support for it to readout the line parameters and MikroTik apparently isn't interested in VDSL (I can understand they do...
by CZFan
Thu Feb 20, 2020 6:33 pm
Forum: RouterBOARD hardware
Topic: CCR1009 collision and loop
Replies: 7
Views: 3404

Re: CCR1009 collision and loop

Start by looking at the cable between the CCR and netgear device, replace if necessary
by CZFan
Thu Feb 20, 2020 6:30 pm
Forum: General
Topic: Using the Loopback address for Software Upgrade/Checking for updates
Replies: 5
Views: 1569

Re: Using the Loopback address for Software Upgrade/Checking for updates

not sure I understand correctly, but Mikrotik ping has source address attribute / switch?
by CZFan
Thu Feb 20, 2020 6:26 pm
Forum: General
Topic: RB2011UiAS looses about 40 megabits of thgougpput!?!
Replies: 49
Views: 7053

Re: RB2011UiAS looses about 40 megabits of thgougpput!?!

@vortex,

Yes, I hear you and agree,but for a 25Mb/s internet connection, the RB2011 is over priced as that can be achieved with a hap mini.

Should the RB2011 had 10 x 1Gb/s ports, I can see a longer life time
by CZFan
Thu Feb 20, 2020 6:00 pm
Forum: General
Topic: RB2011UiAS looses about 40 megabits of thgougpput!?!
Replies: 49
Views: 7053

Re: RB2011UiAS looses about 40 megabits of thgougpput!?!

@pe1chl, yes, you are right, I think the typical networks these days and types fast FTTh connections users have at home, it is maybe time for this little "work horse" to retire :-)

To me, the RB2011 is like Novell, still have a very soft spot for it but times have moved on and so should we
by CZFan
Thu Feb 20, 2020 5:21 pm
Forum: General
Topic: QinQ advice needed!
Replies: 12
Views: 2888

Re: QinQ advice needed!

Wow, for once, I can maybe assist @Sob, For "Provider Bridge" config, you don't need to add a vlan sub interface which is probably reason your config failed, the bridge (new bridge vlan filtering way) looks at ether type, and will add the SVID based on the pvid value of the customer facing "access p...
by CZFan
Thu Feb 20, 2020 5:11 pm
Forum: General
Topic: RB2011UiAS looses about 40 megabits of thgougpput!?!
Replies: 49
Views: 7053

Re: RB2011UiAS looses about 40 megabits of thgougpput!?!

I max out my 500/50 connection with the 2011 but I don't use queues.

Agree, I use to get +- 850 with my RB2011 on a 1000/100 Mb/s FTTh link. Had about 15 Firewall rules, no PPPoE though, was DHCP assigned IP. Latency was also super slow, my son use to kill the others while gaming
by CZFan
Thu Feb 20, 2020 3:50 pm
Forum: General
Topic: RB2011UiAS looses about 40 megabits of thgougpput!?!
Replies: 49
Views: 7053

Re: RB2011UiAS looses about 40 megabits of thgougpput!?!

Have you tried with:

/interface bridge settings
set use-ip-firewall=no
by CZFan
Thu Feb 20, 2020 3:27 pm
Forum: Beginner Basics
Topic: Date format Please Help
Replies: 5
Views: 1605

Re: Date format Please Help

you looking for something like this?
:local mydate ([:pick [/system clock get date] 4 6] . [:pick [/system clock get date] 0 3] . [:pick [/system clock get date] 7 11]);
by CZFan
Thu Feb 20, 2020 1:11 pm
Forum: General
Topic: QinQ advice needed!
Replies: 12
Views: 2888

Re: QinQ advice needed!

The s-tag side needs to be confirmed as usually that is done on the ISP switch and commonly known as "provider bridge" config. With this, customers can then pass through any vlans they want. If above is correct, then all you have to do is standard vlan config on Hex. Confirm above first and post bac...
by CZFan
Wed Feb 19, 2020 11:09 pm
Forum: General
Topic: Getting IP From Vlans But wont connet to internet. [SOLVED]
Replies: 6
Views: 2310

Re: Getting IP From Vlans But wont connet to internet. [SOLVED]

Where is internet break out for site B?
by CZFan
Wed Feb 19, 2020 11:06 pm
Forum: General
Topic: QinQ advice needed!
Replies: 12
Views: 2888

Re: QinQ advice needed!

Sorry, don't like problems just thrown over the wall hoping someone will catch it and do it for you.

What have you tried so far, export of config what you tried?
by CZFan
Tue Feb 18, 2020 11:27 pm
Forum: Scripting
Topic: Scheduler issue
Replies: 6
Views: 2334

Re: Scheduler issue

You should only need "read" & "write" permissions

Try and add below before the script name in the scheduler
/system script run <NameOfScript>
by CZFan
Tue Feb 18, 2020 5:18 pm
Forum: Beginner Basics
Topic: Can't ping from one subnet to another created od diffs ports on router
Replies: 5
Views: 1664

Re: Can't ping from one subnet to another created od diffs ports on router

Not necessarily the correct way, but with the limited information you provide, NATing everything out the bridge interface should give internet access to all devices behind the CCR
by CZFan
Tue Feb 18, 2020 2:16 pm
Forum: Beginner Basics
Topic: Can't ping from one subnet to another created od diffs ports on router
Replies: 5
Views: 1664

Re: Can't ping from one subnet to another created od diffs ports on router

can you provide results of below command in CLI?

/export hide-sensitive
by CZFan
Tue Feb 18, 2020 1:09 pm
Forum: Beginner Basics
Topic: Can't ping from one subnet to another created od diffs ports on router
Replies: 5
Views: 1664

Re: Can't ping from one subnet to another created od diffs ports on router

Look at your firewall rules, start with the ones on client devices
by CZFan
Mon Feb 17, 2020 10:02 pm
Forum: Beginner Basics
Topic: MT+SSTP VPN (VPN subnet + LAN all together?)
Replies: 5
Views: 2318

Re: MT+SSTP VPN (VPN subnet + LAN all together?)

Not sure if you noticed, but this is Mikrotik forum, not Microsoft / Windows.

Anyway, the way you have added the route it will not survive a restart, you have to use the "persistent" switch.

Best way will be to enable using the default gateway on remote network when you configure the VPN client.
by CZFan
Mon Feb 17, 2020 3:56 pm
Forum: Beginner Basics
Topic: RouterOS - NAT problem (dst-nat)
Replies: 27
Views: 5357

Re: RouterOS - NAT problem (dst-nat)

hi
I want to create a PPPoE server but I have a poor concept about firewall so I want to set firewall rules for my users. so I need some standard firewall rules for PPPoE server.
...
https://wiki.mikrotik.com/wiki/Manual:TOC
Alternatively
https://mikrotik.com/consultants
  • 1
  • 2
  • 3
  • 4
  • 5
  • 7