Community discussions

Search found 3131 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 11
by anav
Thu Jul 18, 2019 1:23 am
Forum: Beginner Basics
Topic: Rate Limiting new connections
Replies: 4
Views: 683

Re: Rate Limiting new connections

Awesome so on a closed system, its not really required.
If I have port forwarding selected then it may be smart for me to rate limit the traffic/access to those devices (currently limited by access list and the devices required password login etc).
by anav
Thu Jul 18, 2019 1:23 am
Forum: Beginner Basics
Topic: VLAN Bridge Filtering ALternative
Replies: 9
Views: 1089

Re: VLAN Bridge Filtering ALternative

Okay mkx, thanks for muddying the waters with that last post. Not smart enough to really make sense of your wisdom. I have the RB450Gx4. Would that unit be capable of using the switch chip approach and retain HW offloading advantage without any serious drawbacks? Concur that sticking to vlan bridge ...
by anav
Thu Jul 18, 2019 1:18 am
Forum: Beginner Basics
Topic: Redirecting to another port [SOLVED]
Replies: 6
Views: 688

Re: Redirecting to another port [SOLVED]

The problem I see is that you use port 500 for all machine device traffic so intercepting port 500 traffic to send to the printer would block all other machine device traffic? At least that seems the logical issue. In other words, how does the router know when to direct the traffic from the machine ...
by anav
Wed Jul 17, 2019 3:19 am
Forum: Beginner Basics
Topic: VLAN Bridge Filtering ALternative
Replies: 9
Views: 1089

Re: VLAN Bridge Filtering ALternative

Life is a circle LOL. So there is no downside and I am an idiot for using bridge vlan filtering when I could be doing via switch chip
by anav
Wed Jul 17, 2019 3:17 am
Forum: Beginner Basics
Topic: Rate Limiting new connections
Replies: 4
Views: 683

Re: Rate Limiting new connections

Let me rephrase the question. If the advice was solid and logical then it would be in everyones config! Its not on the basic firewall config from the vendor and I have not really seen much interest expressed in this approach, so does it have limited scope?
by anav
Tue Jul 16, 2019 7:13 pm
Forum: Beginner Basics
Topic: Rate Limiting new connections
Replies: 4
Views: 683

Rate Limiting new connections

• Rate-limiting for each new TCP connection
• Rate-limiting for each new UDP connection

How do these configuration setups prevent attacks on ones Router?
What are the drawbacks?
by anav
Tue Jul 16, 2019 6:45 pm
Forum: Beginner Basics
Topic: VLAN Bridge Filtering ALternative
Replies: 9
Views: 1089

VLAN Bridge Filtering ALternative

https://mum.mikrotik.com/presentations/HU19/presentation_6775_1559545769.pdf I was interested on this presentation because it shows how to use VLANs but with the emphasis on using the switch CHIP and thus using hardware offloading. (vice using the more CPU intensive method of vlan bridge filtering)....
by anav
Tue Jul 16, 2019 6:33 pm
Forum: General
Topic: Why Mikrotik ???
Replies: 32
Views: 6631

Re: Why Mikrotik ???

So you prefer Latvian (aka Russian) backdoors?
Plus don't forget all the equipment is actually assembled in China so they put in their backdoor chips as well.
Excuse me while I change my tinfoil clothes, they get very sweaty.
by anav
Tue Jul 16, 2019 6:31 pm
Forum: General
Topic: RB450Gx4 and hAPac spanning tree problem
Replies: 11
Views: 1189

Re: RB450Gx4 and hAPac spanning tree problem

What version of OS are you running on both?
Please post config on both
/export hide-sensitive file=yourconfig16Jul
by anav
Tue Jul 16, 2019 6:24 pm
Forum: General
Topic: Why Mikrotik ???
Replies: 32
Views: 6631

Re: Why Mikrotik ???

I prefer not to do the homework for the student. ;-P Perhaps I am just not as gullible as the rest of you. This is typical for a University Level Course or typical of an analytical firm asking its stable of advisers to provide input for clients. This is not someone configuring their own equipment an...
by anav
Tue Jul 16, 2019 6:17 pm
Forum: Beginner Basics
Topic: 1wan + 2 lan isolated from each other
Replies: 63
Views: 4685

Re: 1wan + 2 lan isolated from each other

Looks good to me, keeping it simple as mkx suggested but i would combine them.......... and iunclude both the interfaces and source, dest addresses. /ip firewall filter add action=drop chain=forward dst-address=176.16.24.1/24 src-address=192.168.1.0/24 in-interface=bridge2 out-interface=bridge1 add ...
by anav
Tue Jul 16, 2019 2:27 pm
Forum: Beginner Basics
Topic: 1wan + 2 lan isolated from each other
Replies: 63
Views: 4685

Re: 1wan + 2 lan isolated from each other

Sure thing!
by anav
Tue Jul 16, 2019 5:05 am
Forum: Beginner Basics
Topic: 1wan + 2 lan isolated from each other
Replies: 63
Views: 4685

Re: 1wan + 2 lan isolated from each other

I have my internet coming in on vlanxx on my ether1 (bell fiber). IT HAS NOTHING TO DO WITH MY BRIDGES OR VLANS ON MY NETWORK.
You may have a more complicated setup?
by anav
Tue Jul 16, 2019 12:08 am
Forum: General
Topic: VLAN and filtering on non-CRS3xx devices
Replies: 11
Views: 977

Re: VLAN and filtering on non-CRS3xx devices

Everyone has their niche area of interest or expertise! Its always fun seeing what pretzel configurations you all come up with!!
by anav
Mon Jul 15, 2019 11:42 pm
Forum: Beginner Basics
Topic: 1wan + 2 lan isolated from each other
Replies: 63
Views: 4685

Re: 1wan + 2 lan isolated from each other

Sigh.................. one can lead a horse to water......... A 'sob' story for sure!! ;-P I started off using bridges and quickly discovered that one was limited in that the bridge could only be assigned one subnet. In addition one starts loading the bridge to do everything and it just gets in the ...
by anav
Mon Jul 15, 2019 6:25 pm
Forum: Wireless Networking
Topic: Single VLAN Bridge to Bridge [SOLVED]
Replies: 3
Views: 661

Re: Single VLAN Bridge to Bridge [SOLVED]

Another excellent reference.........
viewtopic.php?f=13&t=143620
by anav
Mon Jul 15, 2019 6:09 pm
Forum: General
Topic: VLAN and filtering on non-CRS3xx devices
Replies: 11
Views: 977

Re: VLAN and filtering on non-CRS3xx devices

This is why I would like to clone Sindy's brain and then somehow figure out how to siphon the knowledge into mine directly.
I just get giddy when MKX is schooled. ;-)
by anav
Mon Jul 15, 2019 6:04 pm
Forum: Beginner Basics
Topic: 2 x Lan, 2 x DVR, 1 Problem
Replies: 9
Views: 732

Re: 2 x Lan, 2 x DVR, 1 Problem

Well that was thorough, no crumbs for me. Off I go in search of for food. Excellent support as usual from Yoda
by anav
Mon Jul 15, 2019 6:02 pm
Forum: Beginner Basics
Topic: Access devices in one VLAN from other VLAN
Replies: 3
Views: 429

Re: Access devices in one VLAN from other VLAN

Well the good news is that the OS is somewhat up to date but I would update it to the latest current stable release. I am not a fan of using vlan01 as that can get confusing and would change the numbering to vlan10. But before doing that I would have a good read of an excellent resource to help you ...
by anav
Sun Jul 14, 2019 11:24 pm
Forum: General
Topic: VLAN VRRP
Replies: 18
Views: 1596

Re: VLAN VRRP

Sorry to hear about your injury. :-(
Having recently had a hand injury, understand the loss to some degree. Hoping you recover soonest!
I w i l l t y p e s l o w l y f o r y o u r p o s t s. ;-)
by anav
Sun Jul 14, 2019 11:19 pm
Forum: General
Topic: Port Forwarding Not Working but Shows Packets
Replies: 11
Views: 961

Re: Port Forwarding Not Working but Shows Packets

I would echo 2frogs recommendation for dst-nat rules. /ip firewall nat add action=dst-nat chain=dstnat comment="ALA USG VPN" dst-port=500 in-interface=ether1-gateway log=yes protocol=udp to-addresses=10.0.1.89 add action=dst-nat chain=dstnat comment="ALA USG VPN" dst-port=1701 in-interface=ether1-ga...
by anav
Sun Jul 14, 2019 11:06 pm
Forum: General
Topic: VLAN and filtering on non-CRS3xx devices
Replies: 11
Views: 977

Re: VLAN and filtering on non-CRS3xx devices

I personally think that peoples angst, about vlan filtering affect on CPU as something evils is too broad brush an approach. For most home owners the ease and convenience of vlan setups as per https://forum.mikrotik.com/viewtopic.php?t=143620 Is a great way to go. I am sure for enterprise scenarios ...
by anav
Sun Jul 14, 2019 11:02 pm
Forum: Beginner Basics
Topic: 1wan + 2 lan isolated from each other
Replies: 63
Views: 4685

Re: 1wan + 2 lan isolated from each other

Haha MKX, you know vlans are like catheters, you may not think you need them now but just wait a bit longer!!
by anav
Fri Jul 12, 2019 11:32 pm
Forum: Beginner Basics
Topic: Network isolation using VRF?
Replies: 8
Views: 826

Re: Network isolation using VRF?

Nice try but I went over the diagrams and nothing is clear in terms of order.
by anav
Fri Jul 12, 2019 11:27 pm
Forum: Beginner Basics
Topic: 1wan + 2 lan isolated from each other
Replies: 63
Views: 4685

Re: 1wan + 2 lan isolated from each other

I use vlans for all subnets.
By their nature all vlans do not talk on layer 2
Thus all I do in the forward chain is state what I wish to allow, ie LAN to WAN for whatever vlans,
then Drop ALL as the last rule which kills any L3 routing between the vlans.
Done!
by anav
Thu Jul 11, 2019 6:57 pm
Forum: Beginner Basics
Topic: Network isolation using VRF?
Replies: 8
Views: 826

Re: Network isolation using VRF?

1. what is the difference wrt the load on the CPU for both methods.
2. if i basically in my forward chain simply allow lan to wan traffic and have a generic drop all rule last,
- does that stop traffic between bridges and thus don't need many rules just one!
by anav
Mon Jul 08, 2019 8:39 pm
Forum: Beginner Basics
Topic: Port Forwarding RB2011UiAS
Replies: 10
Views: 896

Re: Port Forwarding RB2011UiAS

I am not interested in providing any assistance if OS is not updated. :-)
by anav
Mon Jul 08, 2019 2:30 pm
Forum: General
Topic: Redundant WAN links checking beyond the gateway
Replies: 4
Views: 379

Re: Redundant WAN links checking beyond the gateway

Couldnt agree with you more. I personally think you should write a book on MT & Everything you wanted to know about VPNs!
I would be the first in line to buy it! The other option is kidnapping and the vulcan mind meld.
by anav
Mon Jul 08, 2019 2:27 pm
Forum: General
Topic: Best Way to Isolate Bridges to Reach Each Other's IPs
Replies: 26
Views: 1616

Re: Best Way to Isolate Bridges to Reach Each Other's IPs

@Bartoz, whats your address will send you tissues also for the cryin!! Perhaps a puke bucket too LOL.
As for @mkx, since when are you from the hood? "staight" LOL
by anav
Mon Jul 08, 2019 3:29 am
Forum: General
Topic: DST NAT Rules Work for some connections.
Replies: 12
Views: 727

Re: DST NAT Rules Work for some connections.

Lets try to narrow this down first to the facts of one wan, 3 services duplicated but with different external incoming ports. After we figure out the config errors we can talk about RDP or anything else. Best to post your config so we can see the setup. /export hide-sensitive file=yourconfigjul07 In...
by anav
Mon Jul 08, 2019 3:23 am
Forum: General
Topic: Best Way to Isolate Bridges to Reach Each Other's IPs
Replies: 26
Views: 1616

Re: Best Way to Isolate Bridges to Reach Each Other's IPs

anav: maybe my toilet paper has just more layers than your? I think we need to explore this in philosophical terms........ but yes I am your basic one ply and you probably have at least 2 or 3 ;-P Seriously though, are you telling me that all my vlans can talk to each other on layer 3 because I spe...
by anav
Mon Jul 08, 2019 3:19 am
Forum: General
Topic: RULE for BANKS
Replies: 15
Views: 950

Re: RULE for BANKS

You guys are spoiling all the fun. I was going to suggest wrapping the router in tin foil next!! ;-)
by anav
Mon Jul 08, 2019 3:17 am
Forum: General
Topic: How do I allow DNS traffic from one VLAN to another? [SOLVED]
Replies: 9
Views: 810

Re: How do I allow DNS traffic from one VLAN to another? [SOLVED]

Haha Zeekay, I wish I could remove the nick addendum, it only reflects the number of posts not the quality of posts. ;-)
by anav
Sun Jul 07, 2019 11:31 pm
Forum: General
Topic: SFP RB4011
Replies: 19
Views: 1732

Re: SFP RB4011

So David, are you saying that in the near future we may be able to connect the RB4011 directly to the incoming fibre line from the street and bypass the ONT? I know the technician spent some time configuring the ONT to the account settings on their database (so they talk to each other). How would yo...
by anav
Sun Jul 07, 2019 11:25 pm
Forum: General
Topic: How do I allow DNS traffic from one VLAN to another? [SOLVED]
Replies: 9
Views: 810

Re: How do I allow DNS traffic from one VLAN to another? [SOLVED]

Word of caution, using pi-hole and DNS is tricky business. I tried doing it and ended up removing it due to the amount of weird scenarios where family members internet worked sporadically. Now I am a complete noob at RouterOS and there are so many ways to frig a setup that it should work just fine, ...
by anav
Sun Jul 07, 2019 11:21 pm
Forum: General
Topic: RULE for BANKS
Replies: 15
Views: 950

Re: RULE for BANKS

That is a great improvement!! Thanks. Let me see if I understand...... You want the router to be given a script (set of commands) that say Scan all the IPs in the world (ipv4 and ipv6?) Figure out which of those IPs belong to banks. Figure out which of the bank IPs belong to a specific country Write...
by anav
Sun Jul 07, 2019 11:11 pm
Forum: General
Topic: Best Way to Isolate Bridges to Reach Each Other's IPs
Replies: 26
Views: 1616

Re: Best Way to Isolate Bridges to Reach Each Other's IPs

@Bartoz, explain to me how devices from one bridge are going to magically access devices on a second bridge when the last forward rule in the forward chain is drop all?? (I know your knowledge far outstrips my few scribbles of notes on toilet paper that make up my imaginary expertise LOL, so please ...
by anav
Sun Jul 07, 2019 11:08 pm
Forum: General
Topic: RULE for BANKS
Replies: 15
Views: 950

Re: RULE for BANKS

I just did. Provide much more detail on your requirements.
by anav
Sun Jul 07, 2019 11:07 pm
Forum: General
Topic: Redundant WAN links checking beyond the gateway
Replies: 4
Views: 379

Re: Redundant WAN links checking beyond the gateway

Why Sindy would send you to a non approved MT site is beyond me. I suspect he has been drinking all afternoon. ;-)
What you seem to be asking is for recursive routing. Search the forum for those keywords and hopefully you will get some starting points.
(Search found 325 matches: recursive routing)
by anav
Sun Jul 07, 2019 11:04 pm
Forum: General
Topic: RULE for BANKS
Replies: 15
Views: 950

Re: RULE for BANKS

Your requirement is lacking too many details to sufficiently address...........
For example. Do you mean writing the banks name on toilet paper in a bar??
by anav
Sun Jul 07, 2019 11:03 pm
Forum: Beginner Basics
Topic: /ip firewall NAT on bridge with use-ip-firewall not working
Replies: 4
Views: 528

Re: /ip firewall NAT on bridge with use-ip-firewall not working

Concur with the approach of simply stating the requirements in terms of desired functionality users will experience without mention of config/settings. I have users x and users y, I want to ensure that users X access the internet with the following limitations...................., I want to ensure u...
by anav
Sun Jul 07, 2019 4:09 pm
Forum: General
Topic: Best Way to Isolate Bridges to Reach Each Other's IPs
Replies: 26
Views: 1616

Re: Best Way to Isolate Bridges to Reach Each Other's IPs

I am not sure what the fuss is about....... Bridges are already separated at layer2, vlans are separated at layer 2.
The only thing need be done is FW rules and mainly no FW rules.

established related
{any allow rules like lan to wan}
Last rule
add chain=forward action=drop.


Done!
by anav
Sat Jul 06, 2019 1:21 am
Forum: Wireless Networking
Topic: Problems with setting up AP's with VLAN
Replies: 6
Views: 646

Re: Problems with setting up AP's with VLAN

Good plan, do come back and let us know how it goes. The "A" team comprised of Jekkyl (me) and the evil My Hyde (mkx) are here to help! ;-)
by anav
Sat Jul 06, 2019 1:18 am
Forum: General
Topic: SFP RB4011
Replies: 19
Views: 1732

Re: SFP RB4011

This is what happens when you dont regulate industry and companies play these stupid games.
Make a standard and follow it.
by anav
Fri Jul 05, 2019 8:26 pm
Forum: Wireless Networking
Topic: Problems with setting up AP's with VLAN
Replies: 6
Views: 646

Re: Problems with setting up AP's with VLAN

Not sure why you need two bridges as vlans are vlans and dont need extra bridge separation. However the bigger issue may be that you dont use the bridge interface when defining the vlans. How bout you have a good review of this resource, change your config accordingly and then post back with further...
by anav
Thu Jul 04, 2019 7:34 pm
Forum: Beginner Basics
Topic: 5 port switch + wlan + guest wlan using rb951
Replies: 3
Views: 312

Re: 5 port switch + wlan + guest wlan using rb951

All that you have stated is very doable.
However one cannot guess at your current setup.
Please post your config for anal ysis.
/export hide=sensitive file=yourconfig4july
by anav
Thu Jul 04, 2019 7:32 pm
Forum: Beginner Basics
Topic: Guest wifi on multiple APs
Replies: 9
Views: 879

Re: Guest wifi on multiple APs

Of course you have a modem, in this case a Cable modem. A router does not work independent of a modem either by landline or wisp.
But understand your test router is really just being used for testing setup planning.
by anav
Thu Jul 04, 2019 7:30 pm
Forum: Beginner Basics
Topic: Advice | Recommendation for new router
Replies: 10
Views: 834

Re: Advice | Recommendation for new router

Services - PPPoE, SQM QoS cake?, ipv6 tunnelbroker, upnp and ability to add/ customize further. What to consider? Option 1: New router with built in wifi? Option 2: New router only + Tenda AC18 as wifi access point? Option 3: New router + new wifi access point? Some are suggesting the RB4011 and Ye...
by anav
Thu Jul 04, 2019 7:28 pm
Forum: Beginner Basics
Topic: Help needed with config
Replies: 9
Views: 779

Re: Help needed with config

Thanks guys... I'm head over to the link you sent anav..... via my ever deepening rabbit hole :) Hands on learning is definitely the way for me (with you guys help). Thanks again for the patience! No worries, you are doing better than I already. I completely ignored mkx at the beginning LOL. ( it w...
by anav
Thu Jul 04, 2019 2:43 pm
Forum: General
Topic: Need recommendations for wireless solution
Replies: 1
Views: 214

Re: Need recommendations for wireless solution

I would consider the 60HZ series, Pair up a set of these from the tower to a spot that has LOS with all the cottages. https://mikrotik.com/product/wireless_wire_dish Then connect the cottage side dish by ethernet ....... to this unit for example..... https://mikrotik.com/product/wap_60gx3_ap which c...
by anav
Thu Jul 04, 2019 2:30 pm
Forum: General
Topic: untagged vlan [SOLVED]
Replies: 9
Views: 742

Re: untagged vlan [SOLVED]

The link mkx provided is your best resource period.
Another good one is useful if you want to tackle a hybrid port (diagram 4 I believe).
https://wiki.mikrotik.com/wiki/Manual:Bridge_VLAN_Table
by anav
Thu Jul 04, 2019 2:27 pm
Forum: Beginner Basics
Topic: Advice | Recommendation for new router
Replies: 10
Views: 834

Re: Advice | Recommendation for new router

The RB4011 is a monster router.........
by anav
Thu Jul 04, 2019 2:26 pm
Forum: Beginner Basics
Topic: Help needed with config
Replies: 9
Views: 779

Re: Help needed with config

@mkx the effing comedian. Thanks for my morning chuckle mate!! As for the OP, see how quickly one can go down a rabbit hole.............. you have to watch out for these experts, they usually work in thin air and find it hard to relate to normal people. As for future plans the best thing is to provi...
by anav
Thu Jul 04, 2019 2:22 pm
Forum: Beginner Basics
Topic: 5 port switch + wlan + guest wlan using rb951
Replies: 3
Views: 312

Re: 5 port switch + wlan + guest wlan using rb951

Did you do any research before buying the routerboard of unknown type/name?
This is not a consumer off the shelf plugnplay device except for the default settings that allow it to be used out of the box but then
needs configuring beyond that.
by anav
Thu Jul 04, 2019 2:21 pm
Forum: Beginner Basics
Topic: Guest wifi on multiple APs
Replies: 9
Views: 879

Re: Guest wifi on multiple APs

So your router is not connected directly to a modem?
by anav
Thu Jul 04, 2019 4:45 am
Forum: Beginner Basics
Topic: How to choose proper Mikrotik hardware
Replies: 4
Views: 432

Re: How to choose proper Mikrotik hardware

Well I would look at something that has ipsec in the hardware so anything like a routerboard RGB450Gx4 or an RB4011 should be models to start considering.
by anav
Thu Jul 04, 2019 4:43 am
Forum: Beginner Basics
Topic: Help needed with config
Replies: 9
Views: 779

Re: Help needed with config

No worries sometimes I think I am only one config step ahead of you LOL. The point being is that do not even consider different designs on the other ethers until you understand what you are doing with one ether. So, that being said you decided to make the BRIDGE responsible for DHCP networking but t...
by anav
Thu Jul 04, 2019 4:37 am
Forum: Beginner Basics
Topic: Help with VLAN and separate WLAN's [SOLVED]
Replies: 8
Views: 698

Re: Help with VLAN and separate WLAN's [SOLVED]

Sure thing....
This is your best resource!!
viewtopic.php?t=143620

This has some useful info as well.
https://wiki.mikrotik.com/wiki/Manual:Bridge_VLAN_Table
by anav
Wed Jul 03, 2019 10:55 pm
Forum: Beginner Basics
Topic: Help needed with config
Replies: 9
Views: 779

Re: Help needed with config

I am curious why you elected to have /ip dhcp-server set to the bridge , but then, assign /ip address to ether2 I am just curious as how assigning it to ether2 is going to magically translate to all the other ether ports?? ;-) /ip neighbor discovery-settings set discover-interface-list=LAN I have se...
by anav
Wed Jul 03, 2019 8:51 pm
Forum: Wireless Networking
Topic: free wifi
Replies: 7
Views: 777

Re: free wifi

i believe dawood is working for the PRC ;-)
by anav
Wed Jul 03, 2019 8:48 pm
Forum: Wireless Networking
Topic: Connect Mikrotik Device to Ubiquiti AP via 802.1x [SOLVED]
Replies: 6
Views: 1137

Re: Connect Mikrotik Device to Ubiquiti AP via 802.1x [SOLVED]

Hmm I believe the latest firmware update may include something that helps........ ??

RouterOS version 6.45.1 has been released in public "stable" channel!
MAJOR CHANGES IN v6.45.1:
----------------------
!) dot1x - added support for IEEE 802.1X Port-Based Network Access Control;
by anav
Wed Jul 03, 2019 8:43 pm
Forum: Wireless Networking
Topic: Which mode do I need?
Replies: 15
Views: 1255

Re: Which mode do I need?

How does your PC get internet now? If it is in another room, presumably it is wired to the current router? Your entire logic is faulty if the PC is getting wifi now as its main supply. If the wireless signal to the PC is poor due to construction/walls etc, what makes you think that the reverse path ...
by anav
Wed Jul 03, 2019 8:31 pm
Forum: Beginner Basics
Topic: Help needed with config
Replies: 9
Views: 779

Re: Help needed with config

This is not a factory refresh, where are all the default firewall rules??
I hope you realize that the default rules are there to protect your router from being hacked!!
by anav
Wed Jul 03, 2019 5:23 am
Forum: Beginner Basics
Topic: Port Forwarding (AND MORE) Still Not Working [SOLVED]
Replies: 4
Views: 530

Re: Port Forwarding (AND MORE) Still Not Working [SOLVED]

What you should start fresh with is the default setup as that is safe and a good place to start.
by anav
Tue Jul 02, 2019 4:32 pm
Forum: General
Topic: EoIP - tunnel drops after 60 secs [SOLVED]
Replies: 19
Views: 1278

Re: EoIP - tunnel drops after 60 secs [SOLVED]

Type really fast.............. ;-)
by anav
Tue Jul 02, 2019 4:30 pm
Forum: General
Topic: have a two WAN ports in RB951 Router
Replies: 2
Views: 288

Re: have a two WAN ports in RB951 Router

post your config
/export hide=sensitive file=yourconfigjul2
by anav
Tue Jul 02, 2019 4:27 pm
Forum: General
Topic: NordVpn and mikrotik?
Replies: 22
Views: 4378

Re: NordVpn and mikrotik?

ementat.......... Is that new info based on the latest firmware release? I remember seeing something about VPN improvements!
Can one extrapolate that any VPN provider that uses a similar setup can also be used with RouterOS now?
by anav
Tue Jul 02, 2019 4:23 pm
Forum: Beginner Basics
Topic: Port Forwarding (AND MORE) Still Not Working [SOLVED]
Replies: 4
Views: 530

Re: Port Forwarding (AND MORE) Still Not Working [SOLVED]

add action=accept chain=input port=69 protocol=udp add action=accept chain=forward port=69 protocol=udp What are those for? The only ports you should be allowing to or across your router is NONE!! (well maybe DNS to your router but only from the LAN side + admin access on the lan side to the router ...
by anav
Tue Jul 02, 2019 4:12 pm
Forum: Beginner Basics
Topic: How to switch immediately after a failover ?
Replies: 7
Views: 1019

Re: How to switch immediately after a failover ?

I think I have RP filter loose, because my router has no morals LOL. Seriously its set to loose for some reason but heck i cant remember LOL.
by anav
Tue Jul 02, 2019 4:10 pm
Forum: Beginner Basics
Topic: hEX (RB750Gr3) Serial Console
Replies: 8
Views: 1045

Re: hEX (RB750Gr3) Serial Console

Is this a requirement that could be well served by the raspberry pi?
by anav
Tue Jul 02, 2019 5:21 am
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 4563

Re: single IP constantly trying to log to my Mikrotik

Well there is additional functionality onion layers now to the question do you use raw rules or filter rules to block things. I simply thought raw was better because there was less load on the CPU. Apparently wrong headed thinking. Apparently connection tracking makes filter rules more efficient. Wh...
by anav
Mon Jul 01, 2019 11:31 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 75025

Re: v6.45.1 [stable] is released!

No issues in upgrading two CapAC and one RB450Gx4.
by anav
Mon Jul 01, 2019 9:27 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 75025

Re: v6.45.1 [stable] is released!

I am using capAC in AP WISP Mode and for some reason it does not have access to the internet (probably how I setup my vlans). Two questions. (1) What method can I use to manually upload the package (dont see a selection in packages)?? and (2) Should I change the capAC mode to home AP from AP Wisp mo...
by anav
Mon Jul 01, 2019 3:40 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 4563

Re: single IP constantly trying to log to my Mikrotik

THis in the 6.45 release looks like it may apply to parts of this discussion......
*) firewall - process packets by firewall when accepted by RAW with disabled connection tracking;

This is the area where I am lost.........
by anav
Sat Jun 29, 2019 4:45 pm
Forum: General
Topic: vlan on a bridge in a bridge
Replies: 17
Views: 1649

Re: vlan on a bridge in a bridge

Perhaps you don't like the management network on vlan id=1, but in large networks I prefer this metod because 1) if I put my computer in the trunk network, I can easily see all devices with both winbox (for mikrotiks) and other vendors applications; 2) if my wolrkers put on the network some new dev...
by anav
Sat Jun 29, 2019 4:41 pm
Forum: General
Topic: Native VLAN
Replies: 25
Views: 2092

Re: Native VLAN

What's missing from your posted config is root section of /interface bridge with definition of bridges themselves. And that I was talking about: you removed what you thought was unnecessary. If you knew what's necessary to show us, you probably wouldn't need advice in the first place ... @Young stu...
by anav
Sat Jun 29, 2019 4:38 pm
Forum: Beginner Basics
Topic: How to switch immediately after a failover ?
Replies: 7
Views: 1019

Re: How to switch immediately after a failover ?

I can see this happen on my browser when I switch from vpn to non-vpn scenario. Causes confusion LOL.
So Sebastia, this seems to be a safe and useful rule to have in place in general (like part of a default). Is there any danger or potential security risk to this rule??
by anav
Fri Jun 28, 2019 2:12 pm
Forum: General
Topic: [Feature request] Wireguard
Replies: 101
Views: 24647

Re: [Feature request] Wireguard

I bought a Raspberry Pi4 and use that for wireguard, it gives me wirespeed vpn on a 500Mbit connection
Is all your internet traffic done via wireguard through the Raspberry PI or are you talking a specific tunnel??
by anav
Thu Jun 27, 2019 6:15 pm
Forum: SwOS
Topic: CSS106 (RB260) VLANs between multiples swicthes and Hybrid port [SOLVED]
Replies: 3
Views: 1136

Re: CSS106 (RB260) VLANs between multiples swicthes and Hybrid port [SOLVED]

I have to wonder how it is that the Switch can use ALWAYS STRIP for an untagged vlan on a particular port (first example on provided link), and when in hybrid mode instead of ALWAYS STRIP, it says to use LEAVE AS IS (second example) ???? This does not seem to be a consistent approach!
by anav
Thu Jun 27, 2019 5:55 pm
Forum: Wireless Networking
Topic: Number of Wi-Fi connections on hAP mini
Replies: 8
Views: 1214

Re: Number of Wi-Fi connections on hAP mini

Your initial post tells me all I need to know. You install crappy TP Link wifi routers in small cafes and this is how you treat your customers LOL.
Suggest you install the RB4011 from now on and give your customers (and their clients) a decent product! ;-)
by anav
Thu Jun 27, 2019 5:52 pm
Forum: Wireless Networking
Topic: User manager wireless VLAN
Replies: 4
Views: 874

Re: User manager wireless VLAN

What is user manager??
by anav
Thu Jun 27, 2019 5:51 pm
Forum: General
Topic: Forum reliability
Replies: 18
Views: 2784

Re: Forum reliability

Suggest medication or get some exercise for whatever is troubling you.
by anav
Thu Jun 27, 2019 4:31 pm
Forum: General
Topic: Forum reliability
Replies: 18
Views: 2784

Re: Forum reliability

Have some coffee mtk, it helps me from taking MT forums too seriously LOL. You are correct Sebastia, over the past month I have noticed the forums being inaccessible numerous times. I thought it may be due to MT using their "NEW" powerline adapters in the server room and every time someone walks in ...
by anav
Thu Jun 27, 2019 4:18 pm
Forum: General
Topic: How to deny the all access from "wan" to "lan" in forward chain ?
Replies: 4
Views: 686

Re: How to deny the all access from "wan" to "lan" in forward chain ?

Sorry i will not give any advice for someone using old firmware. After you have upgraded to the latest stable firmware I would be happy to help.
by anav
Wed Jun 26, 2019 7:04 pm
Forum: General
Topic: Failover with email
Replies: 4
Views: 568

Re: Failover with email

I am a bit confused what is the difference between the check ping in your IP ROUTES, and the script check ping? If the route check ping is in the order of every few seconds, then the router will switch to the backup and nobody will know until the next script time check? Further the router could swit...
by anav
Wed Jun 26, 2019 6:56 pm
Forum: General
Topic: Redirect
Replies: 3
Views: 538

Re: Redirect

Suggest using a consultant in your area! It will save much time.
https://mikrotik.com/consultants
by anav
Wed Jun 26, 2019 6:53 pm
Forum: General
Topic: How to deny the all access from "wan" to "lan" in forward chain ?
Replies: 4
Views: 686

Re: How to deny the all access from "wan" to "lan" in forward chain ?

Please state your requirement in terms of use cases vice equipment functionality or specific router settings. In other words describe what you want users of your network to be able to do or not do. MT default the firewall rules that come with the latest versions are 'safe' out of the box and you nee...
by anav
Wed Jun 26, 2019 6:48 pm
Forum: Beginner Basics
Topic: make order in firewall rules
Replies: 7
Views: 661

Re: make order in firewall rules

I like that, nice and simple
just like
Europe drop all for UK
UK drop all for Europe ;-P

Perhaps soon when landing in the UK, Canadian Citizens will join the quick colonials line at customs....... while the europeans wait in long peon lines!!
by anav
Wed Jun 26, 2019 4:52 pm
Forum: General
Topic: Mikrotik vs Cisco advice
Replies: 12
Views: 34594

Re: Mikrotik vs Cisco advice

@kerberos2023

Your post sounds like an infomercial and has no basis in facts.. Zerobyte clearly laid out how OSPF is flawed and provided examples and yet your opinion is that it is fine.
Suggest you edit/delete your post or actually provide refuting evidence.
by anav
Wed Jun 26, 2019 4:33 pm
Forum: Beginner Basics
Topic: make order in firewall rules
Replies: 7
Views: 661

Re: make order in firewall rules

The best thing to do is to start with the default firewall rules that come with the latest firmware for RouterOS. Before adding rules, describe your network (a diagram works best). Describe what you wish to accomplish in terms of users (not by equipment) For example I ....... I have X groups of user...
by anav
Wed Jun 26, 2019 4:21 pm
Forum: Beginner Basics
Topic: Mikrotik App - Connection refused
Replies: 2
Views: 699

Re: Mikrotik App - Connection refused

Assuming you are trying to connect to the router from within your wifi network at home and not externally like at the coffee shop???
by anav
Wed Jun 26, 2019 4:19 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 4563

Re: single IP constantly trying to log to my Mikrotik

MKX for this beginner. Please elucidate the trodden masses on how to use (practical applications) of this new information on how to control connection tracking when using filter rules and raw rules. There have been some really eye opening statments and facts presented in this thread and its really d...
by anav
Wed Jun 26, 2019 4:13 pm
Forum: Beginner Basics
Topic: Guest wifi on multiple APs
Replies: 9
Views: 879

Re: Guest wifi on multiple APs

Hi there I have very much the same setup in my house. I have my main mikrotik router (previously a hex router and now the RB450Gx4). It is connected to a managed 24 port switch from one port which connects to one capac and another managed switch in an entertainment area. The Router is also connected...
by anav
Tue Jun 25, 2019 8:33 pm
Forum: General
Topic: vlan on a bridge in a bridge
Replies: 17
Views: 1649

Re: vlan on a bridge in a bridge

Good day. Why be frustrated, you have access to the most amazing cheap but high quality vino, delicious coffee etc.. Let MT wait and enjoy life! While sipping,either liquid suggest you read this most excellent reference on setting up vlans......... https://forum.mikrotik.com/viewtopic.php?f=13&t=143...
by anav
Tue Jun 25, 2019 8:15 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 4563

Re: single IP constantly trying to log to my Mikrotik

Translation please (Belgian to English)! The Belgian Alfa-Rome driver showed that french fries were actually invented by Belgians. Uhmm, no, hold it. @sebastia showed that global firewall setting /ip firewall connection tracking set enabled=no actually introduces two raw firewall rules, shown in hi...
by anav
Tue Jun 25, 2019 8:14 pm
Forum: Beginner Basics
Topic: Firewall rule for accessing winbox
Replies: 7
Views: 556

Re: Firewall rule for accessing winbox

Will echo the sentiments being made here, that external access to your router BUT NOT via VPN is not a recommended security practice. As for others giving you advice without even seeing your config makes me shake my head. Not that the learning bits provided are not stuff of gold, but basing advice o...
by anav
Sat Jun 22, 2019 4:38 am
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 4563

Re: single IP constantly trying to log to my Mikrotik

Translation please (Belgian to English)!
by anav
Fri Jun 21, 2019 6:06 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 4563

Re: single IP constantly trying to log to my Mikrotik

Ha, you think your confused. I will wait for the dust to settle on this one.
by anav
Thu Jun 20, 2019 11:22 pm
Forum: General
Topic: US ban on some products from China ( is there a possible effect to Mikrotik ?)
Replies: 6
Views: 866

Re: US ban on some products from China ( is there a possible effect to Mikrotik ?)

anav & huntermic - I like your thinking . If you don't see it or check it , then the future of your business & products & services looks bright. There is no need to keep alert towards any future potential issues. I am actually very concerned.......... with the supply of potatoes from Idaho! ;-P The...
by anav
Thu Jun 20, 2019 6:22 pm
Forum: Wireless Networking
Topic: About to purchase hAP AC/AC^2 router
Replies: 4
Views: 542

Re: About to purchase hAP AC/AC^2 router

What is your ISP wan connection rated at? Do you have coax to any rooms in the house? I am thinking of two ideas. a. hapac2 and using the asus via (coax adapter or electrical powerline adapter) in another section of the house. b. hapac only for better wifi coverage by itself but unless centrally pla...
by anav
Thu Jun 20, 2019 6:01 pm
Forum: Wireless Networking
Topic: About to purchase hAP AC/AC^2 router
Replies: 4
Views: 542

Re: About to purchase hAP AC/AC^2 router

All wired or a mix of wired and wireless? how big is the house, how many floors? do you currently have any access points just the asus wifi router? is you house wired for ethernet or coax at all? In general i would say the hap ac2 is the more powerful router in that it has ipsec hardware built in (b...
by anav
Thu Jun 20, 2019 4:58 pm
Forum: General
Topic: Linux vulnerabilities: CVE-2019-11477, CVE-2019-11478, CVE-2019-11479
Replies: 15
Views: 3192

Re: Linux vulnerabilities: CVE-2019-11477, CVE-2019-11478, CVE-2019-11479

I do not see any particular rule, similar to the ones posted in this thread, referenced in the blog (standard IPV4 or input chain traffic) that would specifically target the CVEs?
( I mean as an interim mod, until new vers' are out).
by anav
Thu Jun 20, 2019 4:39 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 4563

Re: single IP constantly trying to log to my Mikrotik

Aha! I drive an old shitbox and i have the same questions as the Alfa Romeo driver (lucky dog) which proves that he has better taste for inanimate objects LOL ( and less frugal - no Catalan blood at all ).
by anav
Wed Jun 19, 2019 10:18 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 4563

Re: single IP constantly trying to log to my Mikrotik

Very interesting update Sir. @vecernik87 can you boil that down into simple english. It seems to this poor befuddled brain that he is saying, it doesn't really matter which way the question is solved unless one is hitting 100% load. He seems to pass on that if load is an issue, then established rela...
by anav
Wed Jun 19, 2019 3:12 am
Forum: General
Topic: US ban on some products from China ( is there a possible effect to Mikrotik ?)
Replies: 6
Views: 866

Re: US ban on some products from China ( is there a possible effect to Mikrotik ?)

Why not whine about your impending inability to shop at the dollar store where all the products come from China. Every IT manufacturer from Cisco to no name iptv remote controls come from China. Get over yourselves. The supply of products will be sourced to an appropriate vendor of an appropriate co...
by anav
Tue Jun 18, 2019 5:45 pm
Forum: General
Topic: Problem forcing specific DNS server
Replies: 1
Views: 245

Re: Problem forcing specific DNS server

Would have to see the configs to pick out the source of the issue.
by anav
Tue Jun 18, 2019 5:43 pm
Forum: General
Topic: Linux vulnerabilities: CVE-2019-11477, CVE-2019-11478, CVE-2019-11479
Replies: 15
Views: 3192

Re: Linux vulnerabilities: CVE-2019-11477, CVE-2019-11478, CVE-2019-11479

None of these CVE-s are noted in the MT Security Blog and thus they are not real! ;-) On the other hand Rich1 is not a Trump kinda guy and thus the concerns are probably on the up and up. Is the thinking that its not MT config that is vulnerable but the linux kernel and thus not their problem???? Ju...
by anav
Tue Jun 18, 2019 5:29 pm
Forum: General
Topic: No routing to external network
Replies: 8
Views: 639

Re: No routing to external network

Why people insist on not showing their firewall rules is beyond me as its often key as to why some items are blocked you know as in filter rules. Shall we assume you have no filter rules?? Can one assume ether ports 2,3,4,5 connect to ports on the Cisco??? I am assuming the bridg10 traffic works bec...
by anav
Tue Jun 18, 2019 5:13 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 4563

Re: single IP constantly trying to log to my Mikrotik

@anav of course you do :wink: I didn't expect anything less.
What can I say, its a beautiful day here, went rowing this morning, and I have that rare urge to ride a pony! ;-)
by anav
Tue Jun 18, 2019 3:01 pm
Forum: Beginner Basics
Topic: dual wan with an hap ac2 ?
Replies: 5
Views: 702

Re: dual wan with an hap ac2 ?

newbie question here, why are you using things like googles DNS for check gateway and not getting the closest address to the device on the ISP side via a traceroute from the router?
It it more a case of using a known (robust) unlikely to be down source.
by anav
Tue Jun 18, 2019 2:52 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 4563

Re: single IP constantly trying to log to my Mikrotik

That is awesome!! Luv it.
by anav
Mon Jun 17, 2019 10:19 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 4563

Re: single IP constantly trying to log to my Mikrotik

The point was I understand about the order of firewall rules and efficiency of checking packets. What I was questioning and wanted to see a reference about was this line........... " Things like tracked connections (and also address lists) are stored in a clever way so the match can be made more qui...
by anav
Mon Jun 17, 2019 6:24 pm
Forum: General
Topic: No routing to external network
Replies: 8
Views: 639

Re: No routing to external network

Get rid of the Crisco device and get a real firewall.........
Seriously, without seeing the config on the MT its hard to guess.

/export hide-sensitive file=yourconfig17jun
by anav
Mon Jun 17, 2019 6:21 pm
Forum: Beginner Basics
Topic: Help with Firewall [SOLVED]
Replies: 5
Views: 541

Re: Help with Firewall [SOLVED]

There are many far wiser on this forum (at least for MT configs) that may chime in. Patience is your friend.
by anav
Mon Jun 17, 2019 6:19 pm
Forum: Beginner Basics
Topic: Redirect Port to specific WAN [SOLVED]
Replies: 7
Views: 717

Re: Redirect Port to specific WAN [SOLVED]

If WAN2 for whatever reason (ISP problems) goes down do you want everyone to go to WAN1 for backup purposes?

This assumes wan1 and wan2 are not from the same provider, if they are you can disregard this question as both would be not available in the case of ISP failure.
by anav
Mon Jun 17, 2019 6:11 pm
Forum: Beginner Basics
Topic: dual wan with an hap ac2 ?
Replies: 5
Views: 702

Re: dual wan with an hap ac2 ?

/ip route add check-gateway=ping distance=2 gateway=8.8.4.4 target-scope=30 add check-gateway=ping distance=3 gateway=208.67.220.220 target-scope=30 add distance=10 gateway=ispgateway(secondary) target-scope=30 add distance=2 dst-address=8.8.4.4/32 gateway=ispgateway(primary) add distance=3 dst-addr...
by anav
Mon Jun 17, 2019 4:22 pm
Forum: Beginner Basics
Topic: Help with Firewall [SOLVED]
Replies: 5
Views: 541

Re: Help with Firewall [SOLVED]

Yes, thats easy.
Attend some MT Academy training sessions, or get your company to hire a real IT person, or third, hire an MT consultant.
by anav
Mon Jun 17, 2019 1:38 pm
Forum: General
Topic: Radical change coming for home and small business networking
Replies: 37
Views: 2984

Re: Radical change coming for home and small business networking

DOCSIS=DODO bird. If you are not using fibreop by now you must have a single eyebrow! ;-)
by anav
Mon Jun 17, 2019 1:34 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 4563

Re: single IP constantly trying to log to my Mikrotik

Okay that makes more sense now.
by anav
Sun Jun 16, 2019 6:09 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 4563

Re: single IP constantly trying to log to my Mikrotik

Useless ref in regard to the question posed........................... looking for a reference that the router processes filter rules of accepted/related more efficiently than other firewall filter rules in general and specifically better than raw rules. If it was so important and so clear, then it ...
by anav
Sun Jun 16, 2019 6:04 pm
Forum: Beginner Basics
Topic: dual wan with an hap ac2 ?
Replies: 5
Views: 702

Re: dual wan with an hap ac2 ?

RouterOS for the most part is RouterOS meaning you can do everything on most devices. So yes dual or triple or quadruple wan is possible. You need to state your requirements more clearly however. 1. Do you want failover ( a primary and if it fails then go to secondary) 2. Shared, load balance, make ...
by anav
Sat Jun 15, 2019 10:27 pm
Forum: Wireless Networking
Topic: IPTV over Wi-Fi
Replies: 4
Views: 685

Re: IPTV over Wi-Fi

First thing I would think is suspect that the throughput of your setup is not adequate. What speeds have you measured from the second MT after the repeating. Much better do use ethernet or a direct wifi link (not repeating) such as use a pair of wireless wire (LOS) to extend wifi over 60ghz for exam...
by anav
Sat Jun 15, 2019 10:22 pm
Forum: Beginner Basics
Topic: My first Mikrotik Router - Firewall Help
Replies: 16
Views: 1155

Re: My first Mikrotik Router - Firewall Help

Yes. You just have to keep LAN interface list updated. Generally when constructing some rules one should use criteria which has least possibility of spoofing. Remote attacker can easily spoof src-address but can hardly spoof ingress interface. That is GOLD advice.......... IF only MT would put gems...
by anav
Sat Jun 15, 2019 10:16 pm
Forum: Beginner Basics
Topic: single IP constantly trying to log to my Mikrotik
Replies: 57
Views: 4563

Re: single IP constantly trying to log to my Mikrotik

@pe1chl Don't get me wrong, in fact everytime MKX is wrong I do a happy dance and treat myself to a nice cold beer! BUT...... "Things like tracked connections (and also address lists) are stored in a clever way so the match can be made more quickly than by checking them all." Appears to be an assump...
by anav
Fri Jun 14, 2019 2:58 am
Forum: General
Topic: vlan bridge to port [SOLVED]
Replies: 10
Views: 767

Re: vlan bridge to port [SOLVED]

How do you bridge to another bridge???
Why not put all on same bridge LOL.
by anav
Thu Jun 13, 2019 12:04 am
Forum: General
Topic: Annoyed with Mikrotik 'Support'
Replies: 8
Views: 710

Re: Annoyed with Mikrotik 'Support'

There are also many consultants around the world that can help. Sometimes spending a bit on money relieves great stress and gets a solution working quickly. MT equipment is designed for people familiar with networking to a fairly high level. To be clear, just like 'Jon Snow' I know jack sheite (noth...
by anav
Thu Jun 13, 2019 12:01 am
Forum: Beginner Basics
Topic: i need to help
Replies: 2
Views: 307

Re: i need to help

You are asking very basic questions for someone starting a business that people will expect to be reliable and useful. For starters you should provide a diagram with the layout of the area you plan to cover. Where power can be supplied? where ethernet cabling can be provided? what line of sights you...
by anav
Wed Jun 12, 2019 11:54 pm
Forum: Beginner Basics
Topic: How to block access vlan from my local network?
Replies: 9
Views: 820

Re: How to block access vlan from my local network?

Looking at your filter rules..... For clarity you should separate INPUT CHAIN (first) and then FORWARD CHAIN. Far less confusing. /ip firewall filter add action=accept chain=input comment="Accept Related or Established Connections" connection-state=\ established,related MISSING add action=accept cha...
by anav
Wed Jun 12, 2019 11:30 pm
Forum: Beginner Basics
Topic: How to block access vlan from my local network?
Replies: 9
Views: 820

Re: How to block access vlan from my local network?

@anav The second routerboard used as access point From rb750 port 2 connect to my lan via unmanaged switch. And from switch connected to rb941 port 2 is bridge with ports(1,2,3,wlan1). From rb750 port3 assign vlan10 connected direct to rb941 bridge1 with (port4,wlan2) assigned vlan10. Is correct th...
by anav
Wed Jun 12, 2019 11:23 pm
Forum: Beginner Basics
Topic: Hacked recently [SOLVED]
Replies: 7
Views: 1061

Re: Hacked recently [SOLVED]

Incorrect advice, first we dont know what firmware he had to begin with so its an assumption not fact if his firmware is or is not up to date. Secondly, if there is hacked firmware the only 'safe' method for an update or reset is to dowload a clean copy of the latest firmware and apply it via netins...
by anav
Tue Jun 11, 2019 6:21 pm
Forum: General
Topic: Issues with my setup
Replies: 11
Views: 720

Re: Issues with my setup

I dont see your vlans identified by any dhcp settings?
You seem to use eth ports on the router not identified on the drawing as well (nor indicate which ether port goes to the pfsense).
by anav
Tue Jun 11, 2019 6:15 pm
Forum: General
Topic: Organise MFM Lists
Replies: 0
Views: 207

Organise MFM Lists

https://mikrotik.com/mfm/software

Thanks for sending us down this link Normis. I didn't know it existed.
However there is no table of contents and the lists are not even alphabetical. Can you at least put some minimal effort into a searchable organized list.
Thanks!
by anav
Tue Jun 11, 2019 6:14 pm
Forum: General
Topic: Implementing a Blacklist [SOLVED]
Replies: 2
Views: 361

Re: Implementing a Blacklist [SOLVED]

The easiest solution.................. Thats easy..... Let someone else do all the work......... https://forum.mikrotik.com/viewtopic.php?f=2&t=137632 (for basically $10 a month, or 4 cups a coffee a month) I would be using that except I am using Axiom Shield (as I can claim it as a business expense).
by anav
Tue Jun 11, 2019 5:56 pm
Forum: Beginner Basics
Topic: Adding a non-Mikrotik Router to a Mikrotik router as a range extender.
Replies: 1
Views: 258

Re: Adding a non-Mikrotik Router to a Mikrotik router as a range extender.

What do you mean by extender? How will you connect the MT to the non-MT?
Will the non MT unit be acting as a router or simply an access point/switch etc..........
by anav
Tue Jun 11, 2019 5:45 pm
Forum: Beginner Basics
Topic: How to block access vlan from my local network?
Replies: 9
Views: 820

Re: How to block access vlan from my local network?

Quick question, it is not clear to me the purpose of the second routerboard? It would seem you are using it simply or mostly as an access point switch which is vlan aware?? If so how are you connecting the two devices together for the vlans? I am assuming LAN from the main router is coming out ether...
by anav
Mon Jun 10, 2019 8:22 pm
Forum: Beginner Basics
Topic: How to block access vlan from my local network?
Replies: 9
Views: 820

Re: How to block access vlan from my local network?

Post both configs

/export hide-sensitive file=myconfigs10jun
by anav
Mon Jun 10, 2019 4:38 am
Forum: Beginner Basics
Topic: Inter Vlan communication and inter network communication issue [SOLVED]
Replies: 10
Views: 911

Re: Inter Vlan communication and inter network communication issue [SOLVED]

@mkx thankyou for the help. It seems the problem in firewall. Firewall a mess. Have been able to solve the issue. Configuration good up and running. Now cleaning the firewall as recommended by @anav and to meet my requirements.
That is good news!!
by anav
Mon Jun 10, 2019 4:37 am
Forum: Beginner Basics
Topic: Wireless Wire (RBwAPG-60adkit) - Not working. Appreciate the help!
Replies: 7
Views: 629

Re: Wireless Wire (RBwAPG-60adkit) - Not working. Appreciate the help!

finally got them to work... honestly not sure what the deal was but happy to say they're up and running.

Thanks for the help!
Well glad you got them up and running but your feedback is not helpful. What did you do to get them to work?
We need to be able to help the next person!!!
by anav
Mon Jun 10, 2019 4:36 am
Forum: Beginner Basics
Topic: NAT problems - Xbox One and Nintendo Switch
Replies: 32
Views: 3724

Re: NAT problems - Xbox One and Nintendo Switch

Hey Rodrigo,
This is a decent guide for adjusting the TP link.
https://www.dslreports.com/faq/11233

What I am not clear on is the logging in part of your users.
Do you mean to use the Access Point (radio part) of the TP links (ssid and password)?
by anav
Sat Jun 08, 2019 7:47 pm
Forum: General
Topic: Sofware VLAN/Bridge on RuterOS explained.
Replies: 62
Views: 18314

Re: Sofware VLAN/Bridge on RuterOS explained.

Suggest you have a good read (at least twice through this thread and examples to get a good understanding). https://forum.mikrotik.com/viewtopic.php?f=13&t=143620 Once you understand then the wiki here will be more useful and if you have a special case need for a hybrid port, then look at the fourth...
by anav
Sat Jun 08, 2019 7:43 pm
Forum: Beginner Basics
Topic: Help! -- Something is dropping All traffic
Replies: 2
Views: 285

Re: Help! -- Something is dropping All traffic

Without seeing any configurations on the routers, I would have to guess tiny Irish Gremlins live in your routers! ;-)
by anav
Sat Jun 08, 2019 4:13 am
Forum: Beginner Basics
Topic: 1 mikrotik, 2 ISPs, 2 LANs, can't make LANS see each other
Replies: 2
Views: 334

Re: 1 mikrotik, 2 ISPs, 2 LANs, can't make LANS see each other

You should reset to defaults and start new.
Dont add any firewall rules as the defaults work out of the box.
Then come back and post what you have.
It will be easier to discern when much cleaner.
Then after if you want to add all the xtra garbage in you can to a working config
by anav
Fri Jun 07, 2019 9:07 pm
Forum: Beginner Basics
Topic: Can't watch twitch live streams [SOLVED]
Replies: 2
Views: 370

Re: Can't watch twitch live streams [SOLVED]

I was going to say,m that one has to sit still to watch a twitch stream LOL............ Glad you found the error!
by anav
Fri Jun 07, 2019 9:06 pm
Forum: Beginner Basics
Topic: Using RouterOS to VLAN your network
Replies: 91
Views: 25975

Re: Using RouterOS to VLAN your network

@antech, this thread is to discuss the examples provided by the author. If you are having VLAN issues please start another thread. When you do I will point out the obvious error I spotted. :-) @mixig, please read through the reference from beginning to end, the answer you seek is answered within, hi...
by anav
Thu Jun 06, 2019 11:35 pm
Forum: Beginner Basics
Topic: Mark vlan on access port
Replies: 3
Views: 313

Re: Mark vlan on access port

Ahh okay so your config works you just need an explanation of the settings. I thought they were in the reference?
Well I am sure others will chime in with more detail.
by anav
Thu Jun 06, 2019 10:35 pm
Forum: Beginner Basics
Topic: Port forwarding
Replies: 2
Views: 300

Re: Port forwarding

Draw a diagram as the written explanation is very confusing.
by anav
Thu Jun 06, 2019 6:22 pm
Forum: General
Topic: hAP ac² as switch + ap
Replies: 9
Views: 833

Re: hAP ac² as switch + ap

You would probably create a bridge setup on the hapac and define your etherent interfaces and any vlans if any.
No need to create new subnets or anything else.
A diagram of what you are thinking would help that would show what subnets you wish to have and how they are distributed
by anav
Thu Jun 06, 2019 5:14 pm
Forum: Beginner Basics
Topic: guest wifi + VLAN confusion
Replies: 7
Views: 976

Re: guest wifi + VLAN confusion

Before looking at the configs........ Just to be clear on the diagrams. 1. DHCP/subnets and associated LANs/VLANs are created on the RB750. 2. The hapac is in WISP mode, if not what mode? 3. The hapac has its own LANIP on the main LAN provided by the RB750. 4. The only VLAN is 20 and its for a guest...
by anav
Thu Jun 06, 2019 5:08 pm
Forum: Beginner Basics
Topic: Wireless Wire (RBwAPG-60adkit) - Not working. Appreciate the help!
Replies: 7
Views: 629

Re: Wireless Wire (RBwAPG-60adkit) - Not working. Appreciate the help!

Hmm I don't have these units so cannot be of much help. Here is the wiki for manual setup but as warning states........ "Wireless Wire kit devices comes in pre-configured, connected pairs. Manual configuration is optional" https://wiki.mikrotik.com/wiki/Manual:Interface/W60G ON the product page, the...
by anav
Thu Jun 06, 2019 3:35 pm
Forum: Wireless Networking
Topic: RBwAPG-60adkit - no wireless multiple vlan trunk
Replies: 3
Views: 490

Re: RBwAPG-60adkit - no wireless multiple vlan trunk

Where are the addresses/subnets for all the other vlans (not vlan1)??
by anav
Thu Jun 06, 2019 3:33 pm
Forum: General
Topic: Traffic routing between isolated bridges/subnets
Replies: 3
Views: 305

Re: Traffic routing between isolated bridges/subnets

Without seeing your config I am loathe to play guessing games.
If subnets are on different bridges then they should be blocked at L2 and firewall rules should dictate access between them.
So it should work.
by anav
Thu Jun 06, 2019 3:31 pm
Forum: General
Topic: Load balancing?
Replies: 1
Views: 219

Re: Load balancing?

So conceptually speaking you want A. Use Primary Connection (not backups) as first vector (no load balancing). Failover! B. Upon failover USE Backups but in a load balance scenario between the five back up connections. Can you clarify (for backups) that you have 5 different ethernet connections from...
by anav
Thu Jun 06, 2019 3:27 pm
Forum: Beginner Basics
Topic: Mark vlan on access port
Replies: 3
Views: 313

Re: Mark vlan on access port

Your best bet is to read some decent resources....
First and foremost the best resource is this one.........
viewtopic.php?f=13&t=143620
by anav
Thu Jun 06, 2019 3:25 pm
Forum: Beginner Basics
Topic: Inter Vlan communication and inter network communication issue [SOLVED]
Replies: 10
Views: 911

Re: Inter Vlan communication and inter network communication issue [SOLVED]

I would add that most of what you have is not needed. Simply use firewall rules that state what is allowed and then at the end of the input chain and forward chain make drop all rules. Done............ Then monitor traffic and if there is a specific source or type of traffic that you feel is hamperi...
by anav
Thu Jun 06, 2019 3:22 pm
Forum: Beginner Basics
Topic: Port forwarding question
Replies: 4
Views: 413

Re: Port forwarding question

No worries, that dumb router would be a real pain for multiple IP blocks as well.
As Sob indicated if the DMZ+ simply forwards all ports, then the MT should work for you just fine.
by anav
Thu Jun 06, 2019 3:20 pm
Forum: Beginner Basics
Topic: Block IP adress trying to access RDP
Replies: 10
Views: 967

Re: Block IP adress trying to access RDP

you can count attempts in mangle prerouting chain. I do not think the Mangle section will be the right place for such a rule. I am suggesting to use firewall raw section with dst-limit parameters. In general its safer to capture in filter, but okay to drop in raw as raw is stateless and thus easier...
by anav
Wed Jun 05, 2019 5:55 pm
Forum: Beginner Basics
Topic: Port forwarding question
Replies: 4
Views: 413

Re: Port forwarding question

I dont know where to begin, (the fact that you are using some hacks from the internet for MT setup is alarming) First of all, the primary router should be placed in a passthrough mode, such that a public IP is passed to the MT router. (Change the Modem/Router from the ISP into acting solely as a mod...
by anav
Wed Jun 05, 2019 3:53 pm
Forum: Wireless Networking
Topic: Large Apartment, no Ethernet
Replies: 28
Views: 2062

Re: Large Apartment, no Ethernet

Good to know mkx, are the automatic fuses common in apartment building and the like? In vicinity of where I live (like 1000 km radius) automatic fuses somehow became standard for new wirings (either new buildings or adapted old flats/buildings). Only old people (like my parents who actually need po...
by anav
Wed Jun 05, 2019 3:42 pm
Forum: Beginner Basics
Topic: guest wifi + VLAN confusion
Replies: 7
Views: 976

Re: guest wifi + VLAN confusion

This is how I set vlan on my bridge (minus the dhcp and firewall rules, to keep it simple): /interface bridge add name=bridge1 protocol-mode=none vlan-filtering=yes /interface ethernet set [ find default-name=ether1 ] comment="UPLINK - TRUNK" set [ find default-name=ether2 ] comment="DOWNLINK - TRU...
by anav
Tue Jun 04, 2019 5:02 pm
Forum: General
Topic: Providing Internet access to VLANs
Replies: 21
Views: 1569

Re: Providing Internet access to VLANs

Oopsy i see it now too LOL. Typically I look for a mis-match between what the interface setting is.......... not expecting a more basic operator error. However, my sympathy is low as the OP still is using vlan-id=1 and using the bridge for DHCP.......................... But if it works............. ...
by anav
Tue Jun 04, 2019 4:55 pm
Forum: Beginner Basics
Topic: how to make a geust network for dutch KPN config
Replies: 3
Views: 438

Re: how to make a geust network for dutch KPN config

Your setup to attach to your ISP provider is too complicated for my rudimentary level of understanding.
by anav
Tue Jun 04, 2019 2:30 pm
Forum: Wireless Networking
Topic: Large Apartment, no Ethernet
Replies: 28
Views: 2062

Re: Large Apartment, no Ethernet

anav, the original poster said they need 50Mbit total. When the time in future comes and his country can cheaply provide him 500Mbit or more, there will be options to upgrade. Why spend more now? Disagree, for a nominal few more bucks, one gets future growth capacity and better circuit technology. ...
by anav
Tue Jun 04, 2019 2:29 pm
Forum: Wireless Networking
Topic: Large Apartment, no Ethernet
Replies: 28
Views: 2062

Re: Large Apartment, no Ethernet

Good to know mkx, are the automatic fuses common in apartment building and the like?
The only technology I was aware of vis-a-vis fuses was the mind blowing stuff of digital fuses currently being funded by major fuse manufacturers.
by anav
Tue Jun 04, 2019 1:59 am
Forum: Wireless Networking
Topic: Large Apartment, no Ethernet
Replies: 28
Views: 2062

Re: Large Apartment, no Ethernet

Perhaps the rest of the world has no aspirations for faster ethernet? It keeps increasing where I am.... I always attempt to plan for a few years down the line which tends to stretch my dollar, euro, peso a bit farther. Sorry I cannot and will not condone a non gigabit ethernet device in this day an...
by anav
Tue Jun 04, 2019 1:53 am
Forum: Beginner Basics
Topic: Confused with PASSTHROUGH YES/NO in Mangle
Replies: 7
Views: 680

Re: Confused with PASSTHROUGH YES/NO in Mangle

^^^ You added question marks by mistake. ;)
They were rhetorical question marks!! ;-P
by anav
Mon Jun 03, 2019 7:16 pm
Forum: Beginner Basics
Topic: guest wifi + VLAN confusion
Replies: 7
Views: 976

Re: guest wifi + VLAN confusion

Suggest you ignore the second advice and go with the first one. Use bridge vlan filtering and use this resource!!
viewtopic.php?f=13&t=143620

(tis what I have done on similar devices)
by anav
Mon Jun 03, 2019 7:14 pm
Forum: Beginner Basics
Topic: Confused with PASSTHROUGH YES/NO in Mangle
Replies: 7
Views: 680

Re: Confused with PASSTHROUGH YES/NO in Mangle

So, if a packet matches a rule early on in the mangle rules BUT................ will also need to be processed again by lets say 10 mangle rules later, then the first rule that packet is involved in MUST have passthrough=yes??
by anav
Mon Jun 03, 2019 7:10 pm
Forum: Beginner Basics
Topic: VLAN Trunk and Access Ports on Same Device
Replies: 2
Views: 298

Re: VLAN Trunk and Access Ports on Same Device

Concur with MKX, that is the best reference for setting up VLANS. Take note that the author avoids using vlan1 for anything other than default settings for some devices. In other words do not use vlan1 as some sort of untagged entity and dont use it for an admin vlan. The one thing I am not sure the...
by anav
Mon Jun 03, 2019 7:03 pm
Forum: Beginner Basics
Topic: NAT problem?
Replies: 12
Views: 797

Re: NAT problem?

Perhaps there is a Router God, that can see configurations over long distances??
by anav
Mon Jun 03, 2019 7:02 pm
Forum: Beginner Basics
Topic: Does RouterOS support these features?
Replies: 3
Views: 381

Re: Does RouterOS support these features?

Could you not use Raspberry PI for the LTE input stream to the router?
How bout Rasperbby PI for the open vpn?
by anav
Sun Jun 02, 2019 4:43 pm
Forum: General
Topic: MOAB mother of all blacklists
Replies: 88
Views: 11872

Re: MOAB mother of all blacklists

What was the cost before the price hike? What is the percentage increase and why is the increase necessary?
by anav
Sun Jun 02, 2019 3:38 pm
Forum: Wireless Networking
Topic: Large Apartment, no Ethernet
Replies: 28
Views: 2062

Re: Large Apartment, no Ethernet

@ingdaka......... Please do some research before suggesting a powerline product that although announced new is really circa 2011. The top powerlines are using QCA7500 chips with a 10/100/1000 ethernet connection.
by anav
Thu May 30, 2019 5:08 pm
Forum: Beginner Basics
Topic: Setup WAN port, multiple public address [SOLVED]
Replies: 8
Views: 639

Re: Setup WAN port, multiple public address [SOLVED]

And the netmask. You have 65000 IP addresses?

Sent from my cell phone. Sorry for the errors.
Mon Dieu !!!!!
or in Quebec
Ostie de tabarnak
Get an IPAD LOL.............
by anav
Thu May 30, 2019 5:03 pm
Forum: Wireless Networking
Topic: BackYard Wifi Antenna/AP
Replies: 0
Views: 283

BackYard Wifi Antenna/AP

After reading about the wAP 60Gx3 AP and its 180 phased antenna. I started wondering (based upon other thread requests), if MT makes anything in the 2.4/5Ghz spectrum that is similar? In other words, a device that will radiate out for 180 deg (and avoid the back into the house omni scenario and avoi...
by anav
Thu May 30, 2019 4:58 pm
Forum: Wireless Networking
Topic: two "hap ac lite" as AP over 10 meters behind walls
Replies: 3
Views: 379

Re: two "hap ac lite" as AP over 10 meters behind walls

Some thoughts. Using the omni directional hap ac lite behind walls in an area probably already congested with 2.4/5Ghz wifi is bound to be problematic. Suggesting the following which completely avoids wifi congestion and provides very fast/stable connection. They are not ugly and are actually small ...
by anav
Thu May 30, 2019 4:48 pm
Forum: Wireless Networking
Topic: Weird 5GHz Roaming Issue
Replies: 4
Views: 666

Re: Weird 5GHz Roaming Issue

I have two cap ACs at my place as well with the router being the RB450Gx4. No capsman yet as it was easy to play with both and learn setups that way. For small scale I dont see the need nor desire the extra complication and CPU overhead for running another network/infrastructure. In any case, just w...
by anav
Thu May 30, 2019 4:42 pm
Forum: Wireless Networking
Topic: Which mode do I need?
Replies: 15
Views: 1255

Re: Which mode do I need?

I am confused. Why are you only thinking about wifi to the set top box? Are you stating you have no ethernet wiring distribution in your location? Go to your hardware store and find the longest drill bit you can find!!!! Thick wall problem solved!! It sounds like you would need to use a 2.4ghz frequ...
by anav
Thu May 30, 2019 4:37 pm
Forum: General
Topic: My firewall rules - please advise
Replies: 9
Views: 690

Re: My firewall rules - please advise

The winbox default settings are home safe out of the box. Then when configuring the router often folks add too much stuff or dont understand what they are doing. So its best to post the complete config as there are many related moving parts. :-) (in other words just filter rules is not the whole sto...
by anav
Thu May 30, 2019 4:30 pm
Forum: General
Topic: Make external IP address accessible on secondary port
Replies: 8
Views: 582

Re: Make external IP address accessible on secondary port

I'm with got springs on this one. Could and should be done on one router. Anything else is overly complex.
by anav
Thu May 30, 2019 4:25 pm
Forum: Beginner Basics
Topic: Setup WAN port, multiple public address [SOLVED]
Replies: 8
Views: 639

Re: Setup WAN port, multiple public address [SOLVED]

Doesnt make sense.
The more important facts which you have not provided is
A. What did you ask for?? or perhaps be in reality
B. Is this a homework question??
by anav
Wed May 29, 2019 6:04 pm
Forum: General
Topic: Routing to interface with IPIP-dummy
Replies: 15
Views: 845

Re: Routing to interface with IPIP-dummy

Hi msatter! Besides that the config and setting are ZING above my head, I am interested in the potential practical applications of what you are doing.
What use cases will this adaption solve or deliver??
by anav
Wed May 29, 2019 5:59 pm
Forum: Wireless Networking
Topic: 600 ports 5 comms rooms
Replies: 1
Views: 290

Re: 600 ports 5 comms rooms

Suggest you hire a consultant who is actually trained and experienced.
Start here. :-)
https://mikrotik.com/consultants
by anav
Wed May 29, 2019 5:57 pm
Forum: General
Topic: Where found good documentations, tutorials
Replies: 2
Views: 273

Re: Where found good documentations, tutorials

The MUM archives are also an excellent source of material.
by anav
Wed May 29, 2019 5:53 pm
Forum: General
Topic: Firewall\Nat port forward
Replies: 4
Views: 313

Re: Firewall\Nat port forward

On my dstnat (port forwarding rule) I used in-interface-list=WAN (since I have dual wan), if I had a single wan it would have been in-interface=wan. Note, if you know the limited WANIPs external that need access to your server then you could add them to an address list and they would be under source...
by anav
Wed May 29, 2019 5:07 pm
Forum: General
Topic: ssh from routeros to linux server
Replies: 6
Views: 491

Re: ssh from routeros to linux server

Are you saying we need to reprogram/code the user? ;-)
by anav
Wed May 29, 2019 5:06 pm
Forum: Beginner Basics
Topic: Are these redundant dns firewall rules?
Replies: 2
Views: 455

Re: Are these redundant dns firewall rules?

What you need to answer to yourself is the purpose of the two sets of rules. then we can assess the validity of one or both. We cannot guess what you are thinking LOL.

SET A: Purpose.... I want to

SET B: Purpose..... I will use these rules to........
by anav
Wed May 29, 2019 5:03 pm
Forum: Beginner Basics
Topic: Managing two separate subnet with same class addresses
Replies: 9
Views: 625

Re: Managing two separate subnet with same class addresses

Why?
So Sob can show off his MT networking skills ;-)
by anav
Wed May 29, 2019 4:56 pm
Forum: Beginner Basics
Topic: WIFI DEFAULT FORWARD USING BRIDGED VLAN
Replies: 2
Views: 255

Re: WIFI DEFAULT FORWARD USING BRIDGED VLAN

Hmmmmmmmmmmm?? Checking the wiki: default-forwarding (yes | no; Default: yes) This is the value of forwarding for clients that do not match any entry in the access-list I thought default forward was for allowing all those who access the AP to be automatically allowed to have their traffic forwarded ...
by anav
Tue May 28, 2019 9:10 pm
Forum: General
Topic: Help regarding 2 subnets/vlans
Replies: 9
Views: 516

Re: Help regarding 2 subnets/vlans

We can agree to disagree, the use of PVID1 is not recommended as different vendors handle it differently. Keeping it as a default setting, especially in routeros OR swOS tends to have best results and if a management vlan is required just use a different number and simply dont use vlan1 for any work...
by anav
Tue May 28, 2019 9:05 pm
Forum: Beginner Basics
Topic: How to reserve IP in mikrotik hex poe lite [SOLVED]
Replies: 7
Views: 540

Re: How to reserve IP in mikrotik hex poe lite [SOLVED]

As long as you have the mac address of the devices you can add them manually in winbox.
by anav
Tue May 28, 2019 5:31 pm
Forum: General
Topic: How to create group of address lists?
Replies: 7
Views: 831

Re: How to create group of address lists?

I like your plan. a. there are no hackers in france and germany (FACT) b. there are no computers in france and germany that can be hacked and controlled by Bots (FACT) c. allowing access to winbox by external IPs is very safe (FACT). FACT Foundation for the Advancement of Cardiac Therapies, In (when...
by anav
Tue May 28, 2019 5:21 pm
Forum: General
Topic: Help regarding 2 subnets/vlans
Replies: 9
Views: 516

Re: Help regarding 2 subnets/vlans

I think the entire setup is crap that failed to follow the excellent link Sindy provided.
setting bridge to pvid=2 is the first mistake
using vlan-id=1, another mistake.
by anav
Tue May 28, 2019 5:10 pm
Forum: Beginner Basics
Topic: One last Newbie Question.. Hopefully
Replies: 4
Views: 425

Re: One last Newbie Question.. Hopefully

Instead of guessing what the OP has done why not simply ask for the config..........
Argg and I thought this would be a new week, lessons learned and all that.......
Cant teach an old mkx dog new tricks LOL.

/export hide-sensitive file=yourconfigmay28
by anav
Mon May 27, 2019 3:43 pm
Forum: General
Topic: How to create group of address lists?
Replies: 7
Views: 831

Re: How to create group of address lists?

So you want to allow access to winbox from external sources by IP address?
What about vpn connection?
by anav
Sat May 25, 2019 2:36 am
Forum: General
Topic: DHCP and VLAN's
Replies: 2
Views: 264

Re: DHCP and VLAN's

Also not recommended to use vlan1 for an actual vlan...............
by anav
Fri May 24, 2019 9:49 pm
Forum: Beginner Basics
Topic: Can WAN with multiple VLAN will work with trunked port for Internet and IPTV?
Replies: 14
Views: 1006

Re: Can WAN with multiple VLAN will work with trunked port for Internet and IPTV?

Wow, so no other special requirements for the ISP IPTV other than VLAN tagging?
That is progressive thinking!! Bell Fibe and others in the US require special CoS type prioritization of the data at the initial handshake which is a killer requirement.
by anav
Fri May 24, 2019 4:02 pm
Forum: General
Topic: Configuring VLAN access port
Replies: 7
Views: 481

Re: Configuring VLAN access port

In other words a decent diagram will help and the config
/export hide-sensitive file=yourconfigmay24
by anav
Fri May 24, 2019 3:59 pm
Forum: General
Topic: Dual WAN with Vlan [SOLVED]
Replies: 17
Views: 1296

Re: Dual WAN with Vlan [SOLVED]

From the magic book of Sindy Spells! Sindy floats, then he must be a witch. Burn the witch!! When I am awake I will have to revisit this thread to unpretzel my brain to figure it out. Perhaps I am never destined to see the Matrix. Sob does the same magic for ip route rules..............................
by anav
Thu May 23, 2019 10:39 pm
Forum: General
Topic: Mikrotik router with Windows Server DHCP Server?
Replies: 2
Views: 512

Re: Mikrotik router with Windows Server DHCP Server?

Seems overly complicated or at least disjointed.

Without a full understanding of the network an optimal design/setup is not possible by guessing.
Is the Sonicwall doing all the routing?
Is the MT simply a managed switch?
Have you thought of using VLANS?
by anav
Thu May 23, 2019 10:35 pm
Forum: General
Topic: Mikrotik hap ac doesn't see local network
Replies: 3
Views: 299

Re: Mikrotik hap ac doesn't see local network

is this a home network or a business setup??

Concur, draw/provide a diagram.
Then post both configs...........
/export hide-sensitive file=yourconfigmay23
by anav
Thu May 23, 2019 10:32 pm
Forum: Beginner Basics
Topic: Multiple WAN/ISP ip addressess to different ports
Replies: 5
Views: 412

Re: Multiple WAN/ISP ip addressess to different ports

Concur, the setup is basic and the IT admin is negligent. :-)
by anav
Thu May 23, 2019 8:13 pm
Forum: General
Topic: How to routing between two nat subnet?
Replies: 11
Views: 584

Re: Routing Whackamole between two Forum Gurus

Sob and pe1chi, SERIOUSLY, do you guys like torture and punishment? Simply ask for a DIAGRAM and both configs on the routers. (you know /export hide-sensitive file=yourconfig23may ) Your guessing game would be funny if it was intentional ;-PPPPP Changed the Title of the thread........ " Routing Whac...
by anav
Thu May 23, 2019 6:09 pm
Forum: General
Topic: Two connection and two gateway
Replies: 29
Views: 1215

Re: Two connection and two gateway

Can I give Sindy a patience award. You continually impress me man!!
Somebody close to him buy him a good meal and a hearty beer! Assuming its a guy, if not, then an excellent meal and classy white wine.
by anav
Thu May 23, 2019 6:04 pm
Forum: Beginner Basics
Topic: Multiple WAN/ISP ip addressess to different ports
Replies: 5
Views: 412

Re: Multiple WAN/ISP ip addressess to different ports

Which MT unit and which firmware are you running?
by anav
Thu May 23, 2019 6:03 pm
Forum: Beginner Basics
Topic: 1 Bridge with VLAN vs multi bridge
Replies: 5
Views: 421

Re: 1 Bridge with VLAN vs multi bridge

I make the CPU do the work, call me a slave driver.
When the CPU starts complaining I threaten to get a newer CPU and throw the current one in the trash bin.
The CPU then stops complaining. :-)
by anav
Thu May 23, 2019 5:49 pm
Forum: Beginner Basics
Topic: hAP ac - How to configure?
Replies: 15
Views: 1131

Re: hAP ac - How to configure?

First thing I would do is find out what is the wifi card in my PC and see if it has any known issues with the qualcomm wifi chip in the router. If there is nothing on the net, then chances are its probably wifi settings on the router that need adjusting. Unfortunately I am no guru............... Pro...
by anav
Thu May 23, 2019 5:41 pm
Forum: Beginner Basics
Topic: Ban IP's / Drop connections of RDP Brute forcers
Replies: 6
Views: 723

Re: Ban IP's / Drop connections of RDP Brute forcers

Hmmmm, there is no reason why the action drop rule should be in the RAW firewall filter and NOT the input chain. As the rhyme goes. I would like to slap the peepee of the person that wrote the wikee. Slow day. ;-) Highly recommend you read through this thread for some sage advice! https://forum.mikr...
by anav
Thu May 23, 2019 5:37 pm
Forum: Beginner Basics
Topic: hAP ac - How to configure?
Replies: 15
Views: 1131

Re: hAP ac - How to configure?

Sounds like perhaps tweaking some wifi settings. If the computer is in the same room as the AP you should get close to same speeds as wired. Looking at the test results....... I would state you should be getting around 500-800 wired. (512K setting with 25 bridge- 25 filter rules) Seeing as your inte...
by anav
Wed May 22, 2019 9:49 pm
Forum: General
Topic: IKEv2 for Windows and iOS
Replies: 10
Views: 596

Re: IKEv2 for Windows and iOS

Hi Sindy, I know on my IOS IKEv2 setup I had to create a false or weird type of LAN subnet for the connection. I cannot seem to be able to identify an interface for this and there was not direction to create an address addition in the config. I believe I just created it in the IKEv2 setup (IPSEC are...
by anav
Wed May 22, 2019 9:45 pm
Forum: General
Topic: Configuring VLAN access port
Replies: 7
Views: 481

Re: Configuring VLAN access port

Have a slow long read of this excellent source which will help you clean up your config and provide all the answers you desire! https://forum.mikrotik.com/viewtopic.php?f=13&t=143620 After reading that you should be well on your way to success. The MT wiki resources have been playing catchup such th...
by anav
Wed May 22, 2019 9:41 pm
Forum: Beginner Basics
Topic: 1 Bridge with VLAN vs multi bridge
Replies: 5
Views: 421

Re: 1 Bridge with VLAN vs multi bridge

Having one Bridge for me simplifies the setup. Read through this source for the best approach Ive seen. https://forum.mikrotik.com/viewtopic.php?f=13&t=143620 I have multiple vlans, multiple managed and unmanaged switches and multiple APs (two cap acs and others). I use one bridge on any mikrotik de...
by anav
Tue May 21, 2019 4:53 pm
Forum: General
Topic: New Setup Advice
Replies: 4
Views: 465

Re: New Setup Advice

I personally use this device and am very happy with performance(no wifi). https://mikrotik.com/product/rb450gx4 However if you want to connect to the router with sfp ports, then have a look at............ https://mikrotik.com/product/RB953GS-5HnT-RP (has two SFP cages). This is the best price point ...
by anav
Tue May 21, 2019 4:36 pm
Forum: Beginner Basics
Topic: Plex Media Server Remote Access - Port Forwarding
Replies: 16
Views: 1572

Re: Plex Media Server Remote Access - Port Forwarding

Why would you have a public IP on the plex??
by anav
Mon May 20, 2019 8:12 pm
Forum: General
Topic: firewall filter protocol 47 gre
Replies: 13
Views: 1445

Re: firewall filter protocol 47 gre

Hi Sindy can you state in plane ingleesh, what the issue is here.
It seems that the router cannot see into encrypted traffic and how is this bad???
by anav
Mon May 20, 2019 5:25 pm
Forum: General
Topic: Route to multiple remote locations with same LAN subnet/network [SOLVED]
Replies: 6
Views: 500

Re: Route to multiple remote locations with same LAN subnet/network [SOLVED]

Sindy=genius!!!
You should write a routerOS book, I will pre-order buy it now!
by anav
Mon May 20, 2019 5:20 pm
Forum: Beginner Basics
Topic: Help with VLAN and separate WLAN's [SOLVED]
Replies: 8
Views: 698

Re: Help with VLAN and separate WLAN's [SOLVED]

Why did you buy Mikrotik with no networking experience or knowledge??
Do you have configs for the three units you can post to see what you have accomplished so far??
by anav
Mon May 20, 2019 5:17 pm
Forum: Beginner Basics
Topic: CAPsMAN, VLANs & multiple SSIDs headaches
Replies: 1
Views: 223

Re: CAPsMAN, VLANs & multiple SSIDs headaches

I would leave the capsman part out of it until you have configured the two capac unit and vlans by themselves. Your current config needs much work but suggestions will just confuse and not help at this point.... The capsman adds a third layer of unnecessary complexity which will get in the way of un...
by anav
Sun May 19, 2019 6:44 pm
Forum: General
Topic: f/w 6.44.1 problem
Replies: 6
Views: 469

Re: f/w 6.44.1 problem

So great for torrenting for a couple of hours at a time........... where is the problem?
It cannot be your config because it looks a lot like the Emperor's new clothes.
by anav
Sat May 18, 2019 7:27 pm
Forum: Beginner Basics
Topic: Getting to grips with port forwarding
Replies: 3
Views: 313

Re: Getting to grips with port forwarding

Easy Peasy..... Step One: Create the Destination Nat rule for the specific server. This is also where you apply limitations on the external allowed WANIP! /ip firewall nat add chain=dstnat action=dst-nat dst-port=[specific external port] protocol=tcp source-address-list=ServerPurpose1access to-addre...
by anav
Sat May 18, 2019 5:39 pm
Forum: General
Topic: Visio Stencils
Replies: 4
Views: 1044

Re: Visio Stencils

Sounds like something MT should post as a link to their Support Tab at the website!!!
by anav
Sat May 18, 2019 5:36 pm
Forum: Beginner Basics
Topic: Help with VLAN and separate WLAN's [SOLVED]
Replies: 8
Views: 698

Re: Help with VLAN and separate WLAN's [SOLVED]

Is the first router(1) the only router and the others are acting as access points and switches??
by anav
Sat May 18, 2019 5:34 pm
Forum: Beginner Basics
Topic: Plex Media Server Remote Access - Port Forwarding
Replies: 16
Views: 1572

Re: Plex Media Server Remote Access - Port Forwarding

Please post your config and then we can sort out (or isolate the router from being the problem) the issue.

/export hide-sensitive file=youconfigmay18
by anav
Fri May 17, 2019 10:27 pm
Forum: Beginner Basics
Topic: Stop forwarding from default Bridge to Interface "etherX" [SOLVED]
Replies: 2
Views: 276

Re: Stop forwarding from default Bridge to Interface "etherX" [SOLVED]

Simple, draw a diagram and post your config, then we will be able to give credible responses instead of guessing. /export hide-sensitive file=yourconfigmay17 No need to confine your port for admin control. Simply use firewall rules and winbox rules and you can limit it by IP without contorting your ...
by anav
Fri May 17, 2019 7:29 pm
Forum: Beginner Basics
Topic: Forward the port 80 to another port in mikrotik
Replies: 7
Views: 506

Re: Forward the port 80 to another port in mikrotik

Well without knowing his configuration, NO DIAGRAM, NO CONFIGURATION, what is the point of your postt?? If its two subnets on the same router one needs to ensure fw rules allows crosstalk vice routing solution in my limited experience. @source address, for security reasons I like to ensure always li...
by anav
Fri May 17, 2019 4:18 pm
Forum: Beginner Basics
Topic: Forward the port 80 to another port in mikrotik
Replies: 7
Views: 506

Re: Forward the port 80 to another port in mikrotik

You right are, me Phuck......
/ip firewall nat
chain=dstnat action=dst-nat source-address-list=zone1 dst address=192.168.192.10 dst-port=80 protocol=tcp/
to-addressess=192.168.192.10 to-ports=8080
by anav
Thu May 16, 2019 9:21 pm
Forum: General
Topic: Dual bridge / DHCP servers on 6.43.+
Replies: 1
Views: 213

Re: Dual bridge / DHCP servers on 6.43.+

Yes!
Although your first setup should work just fine as well.
Perhaps posting your config and a diagram will help point out any errors in the current configuration.
/export hide-sensitive file=yourconfig16May
by anav
Thu May 16, 2019 9:19 pm
Forum: General
Topic: NAt Configuration
Replies: 7
Views: 449

Re: NAt Configuration

More basic than than there is a flaw in your configuration........... add address=192.168.88.1/24 interface= ether2 network=192.168.88.0 This needs to change to........... add address=192.168.88.1/24 interface= bridge1 network=192.168.88.0 Also for your sourcenat rule, it can be simplified.............
by anav
Thu May 16, 2019 9:12 pm
Forum: Beginner Basics
Topic: vlan and guest in mode bridge ?
Replies: 5
Views: 422

Re: vlan and guest in mode bridge ?

Not sure what you mean but YES, all the settings are available. If you mean give out DHCPs, I believe it has to be in router mode.
by anav
Thu May 16, 2019 3:33 pm
Forum: General
Topic: dst-nat with changing port
Replies: 20
Views: 1185

Re: dst-nat with changing port

Post your config
/export hide-sensitive file=yourconfigmay16
by anav
Wed May 15, 2019 6:12 pm
Forum: Beginner Basics
Topic: Forward the port 80 to another port in mikrotik
Replies: 7
Views: 506

Re: Forward the port 80 to another port in mikrotik

Thats right, the rule I made takes any request from zone one lan users that is headed for port 8080 and sends it to the specific zone 2 IP address and translated to port 80. I thought that would accomplish the aim LOL. Without seeing the OPs config...... /export hide-sensitive file=yourconfig15may W...
by anav
Wed May 15, 2019 6:08 pm
Forum: Beginner Basics
Topic: [solved] VLAN-subnet over 3 devices / routing? switching?
Replies: 3
Views: 331

Re: VLAN-subnet over 3 devices / routing? switching?

Better than google translate is a detailed diagram showing your setup.
by anav
Tue May 14, 2019 5:30 pm
Forum: Beginner Basics
Topic: Port still closed after forwarding
Replies: 4
Views: 477

Re: Port still closed after forwarding

Your are probably tentatively, said hesitantly, right. ;-P
My firewall rules have drop all at end of input and forward chains.
So I should caveat my response with those conditions.
by anav
Tue May 14, 2019 5:27 pm
Forum: Beginner Basics
Topic: Forward the port 80 to another port in mikrotik
Replies: 7
Views: 506

Re: Forward the port 80 to another port in mikrotik

/ip firewall nat
chain=dstnat action=dst-nat source-address-list=zone1 dst port=8080 protocol=tcp/
to-addressess=192.168.192.10 to-ports=80

* suggest you make a firewall address list for the range required
by anav
Tue May 14, 2019 5:19 pm
Forum: Beginner Basics
Topic: no internet access
Replies: 3
Views: 335

Re: no internet access

Use this reference for vlans..........
viewtopic.php?f=13&t=143620
by anav
Tue May 14, 2019 5:17 pm
Forum: Beginner Basics
Topic: If I use "src-nat" i can not ping external(internet) resources
Replies: 6
Views: 528

Re: If I use "src-nat" i can not ping external(internet) resources

Exactly what I was going to suggest. See great minds do think alike@! ;-)
by anav
Tue May 14, 2019 5:15 pm
Forum: Beginner Basics
Topic: Re-phrase o a warning on Wiki PCC page
Replies: 3
Views: 309

Re: Re-phrase o a warning on Wiki PCC page

Makes perfect sense I imagine to someone with networking experience. Its gibberish to me LOL.
by anav
Mon May 13, 2019 11:30 pm
Forum: General
Topic: LAN and WAN on One PHysical port
Replies: 7
Views: 558

Re: LAN and WAN on One PHysical port

As long as those square boxes with red arrows (assuming switches) are managed switches this should be doable.
by anav
Mon May 13, 2019 11:26 pm
Forum: Beginner Basics
Topic: Port still closed after forwarding
Replies: 4
Views: 477

Re: Port still closed after forwarding

My experience as to normal behaviour.
No ports forwarded: no port visible on scan
Port forwarded: port visible on scan but shown as closed
Port forwarded with an allowed firewall access list of wan ips on the dst nat rule: no port visible on scan.
by anav
Sun May 12, 2019 9:27 pm
Forum: General
Topic: VLAN over Bridge
Replies: 41
Views: 1865

Re: VLAN over Bridge

hey zigjack can you post a working config for us (slow me) to look at please!
CONGRATS!!!
by anav
Sun May 12, 2019 5:29 pm
Forum: General
Topic: LAN and WAN on One PHysical port
Replies: 7
Views: 558

Re: LAN and WAN on One PHysical port

Can you provide a diagram or at least explain what your situation is. Why would your wan port coming from the ISP be the same physical port to your LAN??? Perhaps you have a switch between your ISP modem and your router?? In that case assuming the switch is vlan capable, there should be no issue wit...
by anav
Sun May 12, 2019 5:06 pm
Forum: General
Topic: VLAN over Bridge
Replies: 41
Views: 1865

Re: VLAN over Bridge

As an aside this was the same result for my old zyxel router. The stupid router would not respond with the correct priority on the handshake and thus would never get a TV IP address. The CoS setting would work every other time/place except for the original handshake, most frustrating. Would love to ...
by anav
Sun May 12, 2019 5:35 am
Forum: General
Topic: VLAN over Bridge
Replies: 41
Views: 1865

Re: VLAN over Bridge

Thanks Sindy for the xplanation. No harm in a bridge for DHCP purposes (was hit over the head with a ruler I think by Sob, first time I questioned WAN and bridges LOL). It just is confusing for people when adding other bits of their network on the same bridge. So, assuming then that one can have a b...
by anav
Sat May 11, 2019 8:27 pm
Forum: General
Topic: VLAN over Bridge
Replies: 41
Views: 1865

Re: VLAN over Bridge

Seriously, how would one, for traffic coming from an ISP on vlan XX, also ensure that the router meets the necessary requirements of replying with handshakes/traffic with the correct DSCP (tos), CoS or QoS. So confusing.......... just how bout the right "priority" LOL I thought mangling was just for...
by anav
Sat May 11, 2019 8:22 pm
Forum: General
Topic: VLAN over Bridge
Replies: 41
Views: 1865

Re: VLAN over Bridge

by anav
Sat May 11, 2019 7:14 pm
Forum: General
Topic: VLAN over Bridge
Replies: 41
Views: 1865

Re: VLAN over Bridge

THis seems to apply" The CoS field can be set in two places: /ip firewall mangle or /interface bridge filter When working directly on the vlan interface (edge router or device that adds the tag), use /ip firewall mangle. When dealing with bridges use /interface bridge filter. To set the CoS field th...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 11