Community discussions

Search found 1258 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 26
by CZFan
Mon Jul 15, 2019 10:44 pm
Forum: Beginner Basics
Topic: Network isolation using VRF?
Replies: 8
Views: 545

Re: Network isolation using VRF?

Some experience i had with some other routers, the general setup is that if u have 2 networks, they wont see each other until you do routing. But Mikrotik for some reason does this for you. So to break this link all i did was: /ip route rule add action=drop dst-address=192.168.aa.0/24 src-address=1...
by CZFan
Sat Jul 13, 2019 1:22 pm
Forum: Forwarding Protocols
Topic: VPN Prob
Replies: 3
Views: 325

Re: VPN Prob

2 Things:
1. I am not sure if someone here on this public forum is going to help you circumvent the laws of the country
2. Cant do / suggest anything if you do not provide more info, i.e. current config
by CZFan
Sat Jul 13, 2019 1:07 am
Forum: General
Topic: VLAN VRRP
Replies: 18
Views: 1176

Re: VLAN VRRP

Trust you will make a quick and full recovery @sindy
by CZFan
Sat Jul 13, 2019 12:50 am
Forum: General
Topic: CRS3xx hardware offload with split-horizon? or similar setup?
Replies: 6
Views: 456

Re: CRS3xx hardware offload with split-horizon? or similar setup?

It shows on my CRS326 running 6.44.3
by CZFan
Sat Jul 13, 2019 12:37 am
Forum: General
Topic: IPSEC Traffic Flow
Replies: 3
Views: 294

Re: IPSEC Traffic Flow

I suspect your problem is due to what I call "The lazy mans" routing, i.e. NATing, packets are being src NATed one direction and gets to destination and back, but from destination routing is failing.

But as per @sindy, very difficult to say exactly where problem is without more info
by CZFan
Fri Jul 12, 2019 1:37 am
Forum: Wireless Networking
Topic: Single VLAN Bridge to Bridge [SOLVED]
Replies: 3
Views: 252

Re: Single VLAN Bridge to Bridge [SOLVED]

You should be looking at using a single bridge, then separating the staff and guest networks using VLAN's and firewall rules.

Below article should help
https://wiki.mikrotik.com/wiki/Manual:Bridge_VLAN_Table
by CZFan
Tue Jul 09, 2019 1:17 am
Forum: Beginner Basics
Topic: RouterOS - Route traffic through specific gateway problem
Replies: 3
Views: 266

Re: RouterOS - Route traffic through specific gateway problem

try adding Routing-Mark=to_Wan2 to the route you are trying to add
by CZFan
Sat Jul 06, 2019 2:10 pm
Forum: General
Topic: PPPoE Session packets being broadcast??
Replies: 39
Views: 1750

Re: PPPoE Session packets being broadcast??

@sindy,
If you connect with me on Skype (ID under my profile), I can send the the packet capture file done on sfpplus2 to see if you can see anything strange
by CZFan
Sat Jul 06, 2019 11:39 am
Forum: General
Topic: PPPoE Session packets being broadcast??
Replies: 39
Views: 1750

Re: PPPoE Session packets being broadcast??

i will get in touch with Mikrotik support
I'd neverteless like to see the config ;)

As requested, see attached, info is a bit anonymized, so hope it makes sense
by CZFan
Sat Jul 06, 2019 12:51 am
Forum: General
Topic: PPPoE Session packets being broadcast??
Replies: 39
Views: 1750

Re: PPPoE Session packets being broadcast??

No problem, will post it tomorrow
by CZFan
Sat Jul 06, 2019 12:48 am
Forum: Scripting
Topic: Script or CHR Scheduler Problem?
Replies: 1
Views: 237

Re: Script or CHR Scheduler Problem?

Bump, anyone?
by CZFan
Fri Jul 05, 2019 11:31 pm
Forum: General
Topic: PPPoE Session packets being broadcast??
Replies: 39
Views: 1750

Re: PPPoE Session packets being broadcast??

@sindy, I don't know how to thank you, but again your posts have been extremely helpful and I learned a lot again! What you are saying about the CPU port makes a lot of sense and answered why I was seeing these frames (I keep forgetting the CPU is also seen as a "port") Yes, this ISP does have the b...
by CZFan
Fri Jul 05, 2019 10:52 pm
Forum: General
Topic: PPPoE Session packets being broadcast??
Replies: 39
Views: 1750

Re: PPPoE Session packets being broadcast??

Post the CRS config, maybe I can see something there (don't expect too much, though). And the output of /interface bridge port print.

I will be very surprised if there is something in the IT world that you can't resolve
by CZFan
Fri Jul 05, 2019 10:45 pm
Forum: General
Topic: PPPoE Session packets being broadcast??
Replies: 39
Views: 1750

Re: PPPoE Session packets being broadcast??

Will do that, but before I do that, my concern is not really why it is being sent to all clients from my CRS as ports going to client devices are trunk ports and contains all VLAN's of all ISPs, so it will make sense why from the CRS. But for some reason, these frames come in on the wire strange way...
by CZFan
Fri Jul 05, 2019 10:24 pm
Forum: General
Topic: PPPoE Session packets being broadcast??
Replies: 39
Views: 1750

Re: PPPoE Session packets being broadcast??

Host count shows just over 4200.

Not sure if this will help narrowing down where the problem is, but the interface directly connected to the ISP FP Rx count (Fast-Path?) shows exact same amount of traffic I see being "broadcast" to all devices.
by CZFan
Fri Jul 05, 2019 1:21 am
Forum: Beginner Basics
Topic: Problem Loading Websites
Replies: 2
Views: 254

Re: Problem Loading Websites

Post the results from "export hide-sensitive" here, someone will be able to look at any config problem
by CZFan
Thu Jul 04, 2019 11:46 pm
Forum: General
Topic: PPPoE Session packets being broadcast??
Replies: 39
Views: 1750

Re: PPPoE Session packets being broadcast??

I saw the keep alive responses being sent by the client device at the client device while the issue were present, i.e. I could see PPPoE session traffic to this client on other devices. What else I noticed short while ago, I looked at the MAC address of this client in host table in bridge, and notic...
by CZFan
Thu Jul 04, 2019 7:59 pm
Forum: General
Topic: PPPoE Session packets being broadcast??
Replies: 39
Views: 1750

Re: PPPoE Session packets being broadcast??

The CRS is a 326, max devices / MAC addresses inside the FTTh network is +- 2000. The concern I have is I have seen on the CPE management device these packets received sometimes reaches 80 - 90 Mb/s, this going all over the internal network not good, and it effectively becomes like a DDOS to custome...
by CZFan
Wed Jul 03, 2019 10:53 pm
Forum: General
Topic: PPPoE Session packets being broadcast??
Replies: 39
Views: 1750

Re: PPPoE Session packets being broadcast??

Apologies, I am providing L2 connectivity from clients behind OLTs to ISP's, the PPPoE AC is at the ISP. Yes, the dst MAC addresses belongs to customers behind the OLTs, traffic that I see, dst MACs changes every now and then, so it is not a specific customer behind OLTs whose traffic I see, but is ...
by CZFan
Wed Jul 03, 2019 9:50 pm
Forum: General
Topic: PPPoE Session packets being broadcast??
Replies: 39
Views: 1750

Re: PPPoE Session packets being broadcast??

@CZFan, @Anumrak's point of view made me review the whole thread and I've noticed I may be misunderstanding some points all the time. So 1) are the two clients whose traffic you could see to arrive to the "CPE management router" connected via your own OLTs or their MAC addresses are unrelated to yo...
by CZFan
Wed Jul 03, 2019 9:41 pm
Forum: General
Topic: PPPoE Session packets being broadcast??
Replies: 39
Views: 1750

Re: PPPoE Session packets being broadcast??

I am still experiencing the problem, and seeing these packets on ALL devices inside the FTTh network. Below screenshot from another customer device, seeing all these packets not meant for this device. I had something strange happen today, an not sure if I can replicate it again, but was trying to MA...
by CZFan
Tue Jul 02, 2019 6:17 pm
Forum: Scripting
Topic: Script or CHR Scheduler Problem?
Replies: 1
Views: 237

Script or CHR Scheduler Problem?

I am not very au fait with Mikrotik Scripting, and not sure if the problem is with Scheduler in CHR or if script is incorrect, so if someone does not mind helping me out here it will be much appreciated. What I have is a script to backup Dude config and database (On CHR), but it seems to be creating...
by CZFan
Tue Jul 02, 2019 5:02 pm
Forum: General
Topic: PPPoE Session packets being broadcast??
Replies: 39
Views: 1750

Re: PPPoE Session packets being broadcast??

Thx all for the feedback.

@sindy, believe me when I say, your feedback carry way more weight than 2c's
by CZFan
Wed Jun 26, 2019 4:16 pm
Forum: General
Topic: PPPoE Session packets being broadcast??
Replies: 39
Views: 1750

Re: PPPoE Session packets being broadcast??

Thank you @Anumrak,

I will dig a bit further and chat again to ISP....
by CZFan
Wed Jun 26, 2019 2:32 pm
Forum: General
Topic: PPPoE Session packets being broadcast??
Replies: 39
Views: 1750

Re: PPPoE Session packets being broadcast??

PPP frames inside ethernet providing unique layer 2 tunnel based on unicast frames on session level. Why torch should show you destination IP, when PPP tunnel operates only with mac address? Not sure I understand your post, is your question directed at me? Well yeah. I thought you didn't get why ds...
by CZFan
Wed Jun 26, 2019 2:30 pm
Forum: General
Topic: PPPoE Session packets being broadcast??
Replies: 39
Views: 1750

Re: PPPoE Session packets being broadcast??

PPP frames inside ethernet providing unique layer 2 tunnel based on unicast frames on session level. Why torch should show you destination IP, when PPP tunnel operates only with mac address? Not sure I understand your post, is your question directed at me? Well yeah. I thought you didn't get why ds...
by CZFan
Wed Jun 26, 2019 2:24 am
Forum: Beginner Basics
Topic: RB 3011: Very simple VLAN scenario not working. [SOLVED]
Replies: 3
Views: 349

Re: RB 3011: Very simple VLAN scenario not working. [SOLVED]

For access to the device itself, i.e. Management ip and or access to services on device, i.e. DHCP, etc, you will have to provide access to the CPU using the "bridge port", so the command will be:
/interface bridge vlan
add bridge=bridge tagged=bridge untagged=ether8 vlan-ids=10
by CZFan
Wed Jun 26, 2019 12:28 am
Forum: General
Topic: PPPoE Session packets being broadcast??
Replies: 39
Views: 1750

Re: PPPoE Session packets being broadcast??

PPP frames inside ethernet providing unique layer 2 tunnel based on unicast frames on session level. Why torch should show you destination IP, when PPP tunnel operates only with mac address?
Not sure I understand your post, is your question directed at me?
by CZFan
Mon Jun 24, 2019 11:47 pm
Forum: General
Topic: PPPoE Session packets being broadcast??
Replies: 39
Views: 1750

Re: PPPoE Session packets being broadcast??

Ether1 is connected to crs switch.

I think what is happening is the device not storing end user device MAC address and broadcasting this PPPoE session packets on all ports?
by CZFan
Sun Jun 23, 2019 4:14 pm
Forum: General
Topic: PPPoE Session packets being broadcast??
Replies: 39
Views: 1750

Re: PPPoE Session packets being broadcast??

Anyone? It is happening again, same ISP but different customer in the FTTh network.

Reported to ISP again, but does not seem they know where the problem is, almost like vlan 501 leaking over to native vlan from their side?

Have pcap file if that will help, but I cant see anything funny in it?
by CZFan
Sat Jun 22, 2019 10:37 pm
Forum: Scripting
Topic: Script to releases memory
Replies: 5
Views: 455

Re: Script to releases memory

Yes there is, "/system reboot" :-)

Maybe disable services that are not being used, i.e. Hotspot, routing, etc in System->Packages.
by CZFan
Sat Jun 22, 2019 10:16 pm
Forum: Wireless Networking
Topic: Low speed
Replies: 4
Views: 386

Re: Low speed

Can the device you downloading to achieve more?
by CZFan
Sat Jun 22, 2019 10:11 pm
Forum: Beginner Basics
Topic: RB2011 WAN interface not reaching full speed
Replies: 10
Views: 957

Re: RB2011 WAN interface not reaching full speed

Hi

Hint: next time export config with "/export hide-sensitive compact"
i am sure "export" defaults to compact?
by CZFan
Sat Jun 22, 2019 10:05 pm
Forum: Beginner Basics
Topic: hAP AC - Fiber ISP Nid
Replies: 2
Views: 228

Re: hAP AC - Fiber ISP Nid

To ensure hardware offload on LAN ports, create first bridge and assign ports 1-4 and wifi to it. Create vlan interfaces and assign them to SFP interface. NATing, firewall rules, etc will need to be setup against relevant VLAN's, i.e. masquerade will need to go on out interface vlan 5. Create 2nd br...
by CZFan
Sat Jun 22, 2019 9:23 pm
Forum: General
Topic: PPPoE Session packets being broadcast??
Replies: 39
Views: 1750

PPPoE Session packets being broadcast??

I had a situation today and want to understand why this will happen (Dont have much experience with PPPoE, etc) The environment is FTTh where customers connect to relevant ISP across Vlan & PPPoE, OLTs connects to CRS on Isolated Trunk (Vlan) Ports, then branches out to the relevant ISPs based on Vl...
by CZFan
Fri Jun 21, 2019 2:04 pm
Forum: Beginner Basics
Topic: Connect to LAN through mikrotik connected to VPN
Replies: 1
Views: 184

Re: Connect to LAN through mikrotik connected to VPN

Is the VPN server a seperate device from Mikrotik? If so, you will have to tell the VPN server how to get to 192.168.1.x subnet
by CZFan
Fri Jun 21, 2019 1:32 am
Forum: General
Topic: Mikrotik Interface
Replies: 2
Views: 262

Re: Mikrotik Interface

Please under what circumstance can an interface on router got disabled automatically without manual disabling Your question is a bit vague, are you asking to disable an interface other ways besides doing it manually or did you have an experience where the interface got disabled and all the technici...
by CZFan
Fri Jun 21, 2019 12:58 am
Forum: Wireless Networking
Topic: rx rate problem
Replies: 9
Views: 604

Re: rx rate problem

????

Did you see the suggestion from @mkx posted 13 May?
by CZFan
Fri Jun 21, 2019 12:45 am
Forum: Beginner Basics
Topic: RB2011 WAN interface not reaching full speed
Replies: 10
Views: 957

Re: RB2011 WAN interface not reaching full speed

That does not look like the full export and without seeing firewall filter and mangle rules, it makes it difficult to make suggestions.

Read up on fasttrack, enable it and test again
by CZFan
Wed Jun 19, 2019 1:44 pm
Forum: General
Topic: Google pings corrupts
Replies: 1
Views: 183

Google pings corrupts

Hi, Not strictly a Mikrotik related question, but just want to see if you guys get the same. This started recently, can't ping any Google services with packets bigger than 92, if I do, packets gets corrupted. I get this from 2 locations which has nothing in common except using Mikrotik routers, diff...
by CZFan
Wed Jun 19, 2019 2:15 am
Forum: Beginner Basics
Topic: RB2011 WAN interface not reaching full speed
Replies: 10
Views: 957

Re: RB2011 WAN interface not reaching full speed

Start by upgrading to 6.44.3, then post results of "export hide-sensitive" here (between source code bracket so, see menu bot tons above)
by CZFan
Wed Jun 19, 2019 2:10 am
Forum: Beginner Basics
Topic: RB751G-2hnd - VLAN on ether5 - No bridge - DHCP server issues
Replies: 3
Views: 287

Re: RB751G-2hnd - VLAN on ether5 - No bridge - DHCP server issues

From your post, I ge the feeling there is a bigger picture / goal missing, anyway. Using info in your post, you do not need to do any config so on the chip level as it seems there will be no vlan switching. Then add the vlan to ether 5, add IP address to vlan interface, same with DHCP server. The si...
by CZFan
Sun Jun 16, 2019 9:18 pm
Forum: Beginner Basics
Topic: Config VPN and DDNS + smartphone
Replies: 5
Views: 397

Re: Config VPN and DDNS + smartphone

Have you tried to connect with pc/laptop? Apple (iPhone, etc) have dropped support for pptp vpn a while ago due to pptp not being secure, not even allowing it on passthrough, maybe Samsung followed same process. Will be a good idea if you used another VPN type anyway, one that is more secure, i.e. L...
by CZFan
Sun Jun 16, 2019 8:29 pm
Forum: General
Topic: Hardware VLAN [SOLVED]
Replies: 7
Views: 544

Re: Hardware VLAN [SOLVED]

Yes,
/interface vlan
add interface=bridge1 vlan-id=2 name=vlan2

/ip address
add address=192.168.2.1/24 interface=vlan2
Also see...
https://wiki.mikrotik.com/wiki/Manual:B ... witch_chip
by CZFan
Sun Jun 16, 2019 7:32 pm
Forum: Wireless Networking
Topic: How replace a failing Wireless Wire Dish unit ?
Replies: 2
Views: 228

Re: How replace a failing Wireless Wire Dish unit ?

Besides admin users, IP addresses, for normal management, etc,you will have to configure the following as a minimum to get the link up:

1. Mode: "Bridge" or "Station Bridge" depending which one you replacing
2: SSID
3: SSID Password
by CZFan
Sun Jun 16, 2019 7:26 pm
Forum: Wireless Networking
Topic: Configuring a Wireless Wire Dish as a switch ?
Replies: 2
Views: 228

Re: Configuring a Wireless Wire Dish as a switch ?

Not sure I understand correct, but there is only 1 Ethernet interface on these devices?

However, you can connect a switch on both sides of it
by CZFan
Sat Jun 15, 2019 11:44 pm
Forum: Beginner Basics
Topic: SXT LTE kit and router Zyxel NBG-416N
Replies: 2
Views: 276

Re: SXT LTE kit and router Zyxel NBG-416N

Search for SXT passthrough
by CZFan
Sat Jun 15, 2019 10:11 pm
Forum: General
Topic: One device in my network will not work
Replies: 4
Views: 216

Re: One device in my network will not work

I can't understand at all. That's pretty common here, I've reverted to guessing. Here in particular, I've guessed that "it's my Mikrotik" actually means "it's caused by some issue on my Mikrotik". Let's see whether the guess was correct. Must be a "bug" in the forum software, the crystal ball facil...
by CZFan
Sat Jun 15, 2019 9:24 pm
Forum: General
Topic: need help choosing hardware
Replies: 5
Views: 347

Re: need help choosing hardware

The 866Mb/s is probably "Radio" speed, which will equate to approximately 50% of that for Data Throughput due to wireless overhead, etc. I recently replaced a Mikrotik LHG 5 AC wireless link with the Mikrotik 60GHz "Wireless Wire" product, end result is I have XBox / PS4 gamers on the other side of ...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 26