Community discussions

Search found 1171 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 24
by CZFan
Tue Apr 23, 2019 4:22 am
Forum: Beginner Basics
Topic: RouterOS - NAT problem (dst-nat)
Replies: 17
Views: 472

Re: RouterOS - NAT problem (dst-nat)

@Anav, IIRC, you are using an email client with mail server hosted our side your network. Then the client will send mails out, either directly to your hosted mail server or alternative Skype server. The mail coming in, is being "pulled" by the mail client, so connection is into initiated from inside...
by CZFan
Tue Apr 23, 2019 4:00 am
Forum: General
Topic: Issues with internal traffic not getting NATed
Replies: 16
Views: 616

Re: Issues with internal traffic not getting NATed

I am struggling to understand what you are looking for here, the "drop invalid" rule is the built in solution
by CZFan
Tue Apr 23, 2019 3:46 am
Forum: General
Topic: Run script when a gateway fails over
Replies: 4
Views: 171

Re: Run script when a gateway fails over

Based on the limited information you provided, this should be sufficient:

Create / run a script to pick up active wan IP
by CZFan
Sun Apr 21, 2019 8:31 pm
Forum: Beginner Basics
Topic: RouterOS - NAT problem (dst-nat)
Replies: 17
Views: 472

Re: RouterOS - NAT problem (dst-nat)

RouterOS uses routes from "/ip route" to decide where to send packets. It doesn't automatically send replies back the same way from where the request came. So you have incoming connection on WAN2, but default route uses WAN1, so response packets are sent there and of course it doesn't work. Solutio...
by CZFan
Sun Apr 21, 2019 6:02 pm
Forum: Beginner Basics
Topic: Avoiding Double NAT with multiple routers
Replies: 25
Views: 8711

Re: Avoiding Double NAT with multiple routers


@anav I already did it (viewtopic.php?f=13&t=145144), but I got no answers... l don’t know what to do.

You now have an answer...
by CZFan
Sun Apr 21, 2019 6:01 pm
Forum: Beginner Basics
Topic: NAT problems - Xbox One and Nintendo Switch
Replies: 3
Views: 245

Re: NAT problems - Xbox One and Nintendo Switch

If you have hired a company to do the installation, then surely they must correct the problem / design of the network?

Alternatively, my suggestion will be to hire a Mikrotik Certified Consultant in your area. https://mikrotik.com/consultants
by CZFan
Fri Apr 19, 2019 3:22 am
Forum: General
Topic: Need advice with a proper router for my home.
Replies: 4
Views: 201

Re: Need advice with a proper router for my home.

What will you do that concerns you about the memory.
Hap ac2 has 4 cpu and that memory is more than sufficient
by CZFan
Mon Apr 15, 2019 11:50 pm
Forum: General
Topic: who can I hire to get a export to work as an import an a clone [SOLVED]
Replies: 7
Views: 328

Re: who can I hire to get a export to work as an import an a clone [SOLVED]

...

I can't seem to downgrade it to 6.34.4 Mikrotik seems to have deleted the firmware from there website

...

https://mikrotik.com/download/archive
by CZFan
Sun Apr 14, 2019 4:39 pm
Forum: General
Topic: help with queue
Replies: 4
Views: 244

Re: help with queue

Add a simple queue with target of CCTV IP and set rate limits required
by CZFan
Sun Apr 14, 2019 4:34 pm
Forum: Beginner Basics
Topic: HAP mini IPSEC+EoIP performance?
Replies: 4
Views: 253

Re: HAP mini IPSEC+EoIP performance?

As far as I can recall, Hap Mini and Lite has exactly the same specs, only difference is mini has 3 ether ports and Lite has 4 ether ports
by CZFan
Fri Apr 12, 2019 4:45 am
Forum: Wireless Networking
Topic: Some wireless questions
Replies: 5
Views: 330

Re: Some wireless questions

My main concern is to make sure the antennas are aligned, my thinking is does not matter settings you play with, if alignment is out, you will never have a stable / good link. but seems for some reason, no one here wants to comment on if the alignment tool in Winbox still works. I have set the chann...
by CZFan
Thu Apr 11, 2019 11:20 pm
Forum: General
Topic: L2TP VPN "L2TP UDP packet received from" over and over again.
Replies: 8
Views: 288

Re: L2TP VPN "L2TP UDP packet received from" over and over again.

Yup, that will also work as OpenVPN on MT is TCP Based.

I just prefer SSTP over O-VPN as SSTP uses port 443, less chance of ISP's blocking it.
by CZFan
Thu Apr 11, 2019 9:43 pm
Forum: Forwarding Protocols
Topic: MikroTik and Cisco ASA
Replies: 5
Views: 341

Re: MikroTik and Cisco ASA

One suggestion will be to not use NATing between proxy / ASA / MT, but rather routing and only NAT out on MT
by CZFan
Thu Apr 11, 2019 9:04 pm
Forum: General
Topic: L2TP VPN "L2TP UDP packet received from" over and over again.
Replies: 8
Views: 288

Re: L2TP VPN "L2TP UDP packet received from" over and over again.

You can use certs with SSTP between MT's, but it is not required. My point was you can quickly test it without creating certs etc. if it works better, then implement with certs
by CZFan
Thu Apr 11, 2019 7:53 pm
Forum: General
Topic: L2TP VPN "L2TP UDP packet received from" over and over again.
Replies: 8
Views: 288

Re: L2TP VPN "L2TP UDP packet received from" over and over again.

UDP not good for unstable links, maybe try a TCP based site to site VPN, i.e. SSTP bwteen MT's, don't need certs in this case
by CZFan
Wed Apr 10, 2019 3:18 am
Forum: Wireless Networking
Topic: Some wireless questions
Replies: 5
Views: 330

Re: Some wireless questions

Thx for your response, and I might very well be wrong and please correct me if I am wrong My understanding is that it is 897Mb/s air rate (radio) and should be able E to get 450 - 500 Mb/s data rate. I did some more reading, and it seems like with the equipment used for the link and due to short dis...
by CZFan
Tue Apr 09, 2019 9:10 pm
Forum: Wireless Networking
Topic: Some wireless questions
Replies: 5
Views: 330

Re: Some wireless questions

Bump, anyone, please?
by CZFan
Mon Apr 08, 2019 9:00 pm
Forum: Wireless Networking
Topic: Some wireless questions
Replies: 5
Views: 330

Some wireless questions

Hi Have a PTP link (2 x LHG 5ac's) connected but not too happy re performance which I am sure is due to my limited knowledge on wireless and asking for some help. The distance between the devices is about 500m with clear line of sight, both devices are on ROS 6.44.1. I if I can get the link to push ...
by CZFan
Mon Apr 08, 2019 3:52 pm
Forum: General
Topic: Filter Rules - Output showing activity, why?
Replies: 4
Views: 211

Re: Filter Rules - Output showing activity, why?

cause your rules are incorrect: Forward chain, you have dst address list which should work ok, but should really be src address list input chain, again you have dst address list, this will never work as you should not have any China IPs as per address list on your router, so should also be src addre...
by CZFan
Sat Apr 06, 2019 9:59 pm
Forum: General
Topic: SIP port(s)
Replies: 6
Views: 302

Re: SIP port(s)

I want mind to grind coffee beans. They should call it the cAPpuccinoAC

:lol: :lol: :lol: :lol:
by CZFan
Sat Apr 06, 2019 2:37 am
Forum: Beginner Basics
Topic: PPTP Issues
Replies: 13
Views: 602

Re: PPTP Issues

If you coming with a Windows client behind a NAT and L2TP/IPSec server is also behind a NAT, have a look at this, it solved my problem:

https://support.microsoft.com/en-gb/hel ... in-windows
by CZFan
Fri Apr 05, 2019 5:54 pm
Forum: The User Manager
Topic: HEX S - User Manager (Will it be enough)
Replies: 2
Views: 274

Re: HEX S - User Manager (Will it be enough)

Would you use a Mini to transport the local school rugby / soccer team to a game?

The Hex S is a SOHO device, that is an acronym for "Small Office / Home Office", do you think what you are trying to do fits in there?
by CZFan
Thu Apr 04, 2019 11:12 am
Forum: Announcements
Topic: v6.44.2 [stable] is released!
Replies: 62
Views: 9218

Re: v6.44.2 [stable] is released!

Hi Emils,

Is this fix related to recent vulnerability issue that were going to go public on 9 April?
by CZFan
Mon Apr 01, 2019 4:03 am
Forum: Wireless Networking
Topic: Alignment Mode : How to use
Replies: 4
Views: 7981

Re: Alignment Mode : How to use

Is this functionality still working? I have 2 lhg 5ac devices, link is up in bridged ptp config currently syncing at 400Mbps, but when I try this, I get nada. no sounds on station side, no info in Winbox on station side. All I get is customer screaming at me every time I do this as the link between ...
by CZFan
Mon Apr 01, 2019 1:43 am
Forum: Announcements
Topic: v6.44.1 [stable] is released!
Replies: 86
Views: 15150

Re: v6.44.1 [stable] is released!

Thx @mkx, @pe1chl for the info. Have over 1000 of these deployed in user homes (FTTx Deployment), so if things go wrong, not easy to get physical access to these plus user / client downtime. There was a time when I still had hair, when all jumped ship from Novell (had a very soft spot for Novell) to...
by CZFan
Sun Mar 31, 2019 4:28 am
Forum: Beginner Basics
Topic: WLAN - Users from LDAP and dynamic VLANs
Replies: 1
Views: 137

Re: WLAN - Users from LDAP and dynamic VLANs

IIRC, MT does not support dynamic VLAN's
by CZFan
Sun Mar 31, 2019 12:18 am
Forum: Announcements
Topic: v6.44.1 [stable] is released!
Replies: 86
Views: 15150

Re: v6.44.1 [stable] is released!

uninstall tr069 package, remove everything from /files, upgrade only routeros, after suiccessful upgrade install tr069 again Yes, if it was a device at my home, no issues, but now I must go do that on over 1000 devices at client site? WTF is it even necessary to do that, I am a patient person, been...
by CZFan
Sat Mar 30, 2019 11:59 pm
Forum: Announcements
Topic: v6.44.1 [stable] is released!
Replies: 86
Views: 15150

Re: v6.44.1 [stable] is released!

@CZFan, @gdelacruz: is there anything in the log about upgrading (or its failure)? When I try to uninstall the packages that are disabled, I get error, cant uninstall bundled package Have over 1000 of these devices deployed at 1 client only Log info after trying to upgrade: 23:46:30 system,info ins...
by CZFan
Sat Mar 30, 2019 3:16 pm
Forum: Announcements
Topic: v6.44.1 [stable] is released!
Replies: 86
Views: 15150

Re: v6.44.1 [stable] is released!

unfortunately my MT is not upgrading to 6.44 from 6.43.12. i am using the upgrade tool from winbox. downloading and reboot but it does not change at all... pls. advise .. using RB952Ui-5ac2nD.. thanks Having the same problem on 1 device, trying to upgrade from 6.43.8 to 6.44.1, it downloads it, reb...
by CZFan
Fri Mar 15, 2019 8:51 pm
Forum: Announcements
Topic: v6.44.1 [stable] is released!
Replies: 86
Views: 15150

Re: v6.44.1 [stable] is released!

Hi all,
I noticed since 6.44 and now 6.44.1 some neighbors are displayed without their IP address.. is there a solution?

My guess will be those devices do not have an IP on the interface reported on.
by CZFan
Fri Mar 15, 2019 3:29 pm
Forum: Announcements
Topic: v6.44.1 [stable] is released!
Replies: 86
Views: 15150

Re: v6.44.1 [stable] is released!

Updated hAP AC2 and CCR1009 from 6.44 to 6.44.1 I am seeing a lot of dropped Forwarded packets as INVALID. These are packets that should have hit the New connection from a local device in the address list. But are getting dropped. Also ... Updated my Hap AC^2, also getting lots of invalids dropped,...
by CZFan
Thu Mar 14, 2019 2:03 pm
Forum: Announcements
Topic: Statement on Vault 7 document release
Replies: 92
Views: 41872

Re: Statement on Vault 7 document release

upgrade ≠ reset configuration

On upgrade system files are replaced with new ones.

You are using the wrong symbol to explain to IT people, should use "!=" instead, then they will better understand :-)
by CZFan
Wed Mar 13, 2019 6:57 am
Forum: General
Topic: Why (not) use Hairpin NAT
Replies: 20
Views: 1155

Re: Why (not) use Hairpin NAT

So I missed this thread when it was new, but it's not too late to disagree now - hairpin NAT is awesome! ;) Ok, that was just to even things out a little. Reality is that haipin NAT should be unnecessary and by long time obsolete hack from old IPv4 + NAT times that were supposed to end years ago. U...
by CZFan
Mon Mar 11, 2019 1:35 pm
Forum: General
Topic: Is it possible to use remote log server over Mikrotik to Mikrotik SSTP VPN?
Replies: 1
Views: 103

Re: Is it possible to use remote log server over Mikrotik to Mikrotik SSTP VPN?

Will have to configure routing, make sure FW's do not block this traffic between sites and ensure your syslog server accepts from these IP's, that should be all
by CZFan
Sat Mar 09, 2019 1:02 am
Forum: Announcements
Topic: v6.44 [stable] is released!
Replies: 219
Views: 27949

Re: v6.44 [stable] is released!

Hi Since the last update we have had multiple clients complaining about existing sites where VoIP experiences issues, from de-registration, no audio, one way audio. Currently we downgrading the clients back to 6.43.8 which works. I've sent multiple supouts and support tickets to Support with no fee...
by CZFan
Fri Mar 01, 2019 5:34 pm
Forum: General
Topic: Drop traffic between two different vlans that are on the same interface
Replies: 10
Views: 394

Re: Drop traffic between two different vlans that are on the same interface

Trafic that you are trying to avoid in your ping command is not for the forward chain, is for the input chain. If you do not want users on vlanx communicate with the interface of the VLANy on the router , you need to block the traffic on the input chain. Regards. What you said makes no sense to me....
by CZFan
Fri Mar 01, 2019 3:40 pm
Forum: RouterBOARD hardware
Topic: CRS328 SFP+ Port Flapping
Replies: 6
Views: 623

Re: CRS328 SFP+ Port Flapping

Just thinking, I have a CRS326, up time currently reported as 51d12h, have zero downtime / flaps on SFP+ port.

Are the flaps not maybe caused by the other side?
by CZFan
Tue Feb 26, 2019 12:15 pm
Forum: Beginner Basics
Topic: Packet Routing Help
Replies: 2
Views: 342

Re: Packet Routing Help

I think it will be best for you to engage with a Mikrotik Consultant in your local area

https://mikrotik.com/consultants
by CZFan
Tue Feb 26, 2019 12:23 am
Forum: General
Topic: Fasttrack and Simple Queue
Replies: 6
Views: 1454

Re: Fasttrack and Simple Queue

For the Qs to correctly match both directions you need to add the following rule before fast track rule:
chain=forward action=accept connection-state=established,related dst-address-list=alist_to_s-queue log=no log-prefix=""
by CZFan
Fri Feb 22, 2019 3:17 pm
Forum: RouterBOARD hardware
Topic: SFP in SFP+ question
Replies: 2
Views: 292

Re: SFP in SFP+ question

I had to change the link sync to manual with every SFP module in SFP+ ports, this was on CCR1036, CCR1072 & CRS326 IIRC

Also, I think they do state that in the manual
by CZFan
Mon Feb 18, 2019 12:14 am
Forum: Beginner Basics
Topic: RB2011 slow internet even with fasttrack
Replies: 89
Views: 6983

Re: RB2011 slow internet even with fasttrack

If I may ask, what device is this ISP modem, make, model, etc?
by CZFan
Sun Feb 17, 2019 4:37 pm
Forum: Beginner Basics
Topic: RB2011 slow internet even with fasttrack
Replies: 89
Views: 6983

Re: RB2011 slow internet even with fasttrack

Maybe you should approach your ISP?
by CZFan
Sat Feb 16, 2019 12:35 am
Forum: The Dude
Topic: SNMP not stable across bridged wireless link
Replies: 0
Views: 240

SNMP not stable across bridged wireless link

I am monitoring about 40 devices using the Dude. Have 3 devices that are across a bridged wireless PTP link. For any devices on the other side of this wireless link, I get every now and then (intermittent) SNMP timeouts and with that false notifications. Have done the normal checks, etc, i.e. CPU lo...
by CZFan
Fri Feb 15, 2019 11:52 pm
Forum: General
Topic: NEW Public Bandwith Test Server
Replies: 29
Views: 4812

Re: NEW Public Bandwith Test Server

It's almost like Mikrotik should run one

Please forward the bandwidth test link for Cisco, Juniper, Huawei, Zyxel, TP-Link, ....
by CZFan
Tue Feb 12, 2019 8:02 pm
Forum: General
Topic: CRS109-8G Crashes/reboots often
Replies: 19
Views: 1227

Re: CRS109-8G Crashes/reboots often

Yes, the wireless radios draw quit a bit of power.

It sounds as if the CRS109 meets your requirements, if that is the case, and it was me, I will buy the correct power supply, add a virtual WLan and voila, you have 2 x SSIDs
by CZFan
Tue Feb 12, 2019 6:42 pm
Forum: General
Topic: DHCP Client brige l2tp tunnel [SOLVED]
Replies: 12
Views: 1046

Re: DHCP Client brige l2tp tunnel [SOLVED]

You need to remove WLAn from bridge and add L2TP interface to bridge on L2TP client side, i.e. on your AP, the server side should be done dynamically of configured correctly. You DHCP client should also be bound to L2TP client interface i need wifi clients to get ip from dhcp server from ether2 Ok,...
by CZFan
Tue Feb 12, 2019 6:35 pm
Forum: RouterOS v6 RC and v7 BETA
Topic: Cisco style Q in Q tunnels
Replies: 2
Views: 338

Re: Cisco style Q in Q tunnels

Topic below might get you started:

viewtopic.php?t=135504
  • 1
  • 2
  • 3
  • 4
  • 5
  • 24