Community discussions

Search found 2250 matches

  • 1
  • 3
  • 4
  • 5
  • 6
  • 7
  • 45
by mkx
Sun May 12, 2019 12:48 pm
Forum: Beginner Basics
Topic: how copy configuration to an other router ?
Replies: 1
Views: 181

Re: how copy configuration to an other router ?

Can i upload the backup of the hap in the cap ? Definitely not. You should not even upload backup of another device of same model, the complications can be just too big to bother. The correct way is to create configuration export using command /export file=export.rsc , copy file to your computer, s...
by mkx
Sun May 12, 2019 1:02 am
Forum: General
Topic: CAPsMAN virtual wlans don't inherit wireless channel settings [SOLVED]
Replies: 3
Views: 164

Re: CAPsMAN virtual wlans don't inherit wireless channel settings [SOLVED]

You should let APs run on different channels so they won't cause interference to each other when there will be client devices in areas where signal of different APs overlap.
by mkx
Sun May 12, 2019 12:57 am
Forum: General
Topic: Mikrotik > Juniper VLAN trunk
Replies: 11
Views: 535

Re: Mikrotik > Juniper VLAN trunk

So basically you want to use RB2011 as access switch for the two VLANs? There are two ways of configuring VLANs on RB devices, but RB2011 being a rather old device with good switch chips it should perform better if VLANs are configured in switch chip. /interface ethernet switch port # check if the n...
by mkx
Sun May 12, 2019 12:09 am
Forum: General
Topic: IPTV-STB Q11 on Bridge Mikrotik
Replies: 1
Views: 106

Re: IPTV-STB Q11 on Bridge Mikrotik

It really depends on how your ISP delivers IPTV over WAN and thus how STB expects it to be delivered.
by mkx
Sat May 11, 2019 10:55 am
Forum: Beginner Basics
Topic: 6.44: DHCP server becomes invalid when removing ether2 from bridge
Replies: 8
Views: 387

Re: 6.44: DHCP server becomes invalid when removing ether2 from bridge

Either assign DHCPs to my favourite vehicle, VLANs, or to subnets directly. What if one doesn't use VLANs and uses bridge to join several physical ports to single L2 network, where should DHCP go then? I don't think that assigning my DHCP to your VLAN would do any good ... BTW, my friend @anav has ...
by mkx
Fri May 10, 2019 6:26 pm
Forum: Beginner Basics
Topic: 6.44: DHCP server becomes invalid when removing ether2 from bridge
Replies: 8
Views: 387

Re: 6.44: DHCP server becomes invalid when removing ether2 from bridge

At the first impulse I'd change the order of execution of points 1. and 2. But I'm not sure about inner working in RB. In theory bridge is entity separate from any member port, so if IP address is associated to ether2, it should be fine to change MAC address of the bridge and all L3 connections usin...
by mkx
Fri May 10, 2019 8:16 am
Forum: Wireless Networking
Topic: CapsMan provisioning of a Specific MAC
Replies: 4
Views: 269

Re: CapsMan provisioning of a Specific MAC

My (limited) experience with capsman is that order of entries in /caps-man provisioning matters. The first one that matches a CAP will get applied (the same logic as with firewall filter rules). So try to move the general provisioning rule (with radio-mac=00:00:00:00:00:00) to the end of provisionin...
by mkx
Fri May 10, 2019 8:06 am
Forum: Beginner Basics
Topic: cant view graphing
Replies: 6
Views: 329

Re: cant view graphing

Can you see webfig login page if you connect to browser via http? If yes, then follow advice by @WeWiNet, every single usage graph has separate setting about IP addresses of allowed clients. If not, check if /ip service print where name=www shows it active (i.e. not disabled and not invalid), that y...
by mkx
Thu May 09, 2019 11:26 pm
Forum: Beginner Basics
Topic: 6.44: DHCP server becomes invalid when removing ether2 from bridge
Replies: 8
Views: 387

Re: 6.44: DHCP server becomes invalid when removing ether2 from bridge

Bridge by default assumes MAC address of the first active member port. Highly likely that's ether2 in your particular setup. If you remove "MAC donor" port from bridge, it looses MAC address. Solution: on bridge set auto-mac=no admin-mac=uu:vv:ww:xx:yy:zz where the set MAC address is one of port MAC...
by mkx
Thu May 09, 2019 9:26 am
Forum: Beginner Basics
Topic: DhCP server for each port
Replies: 11
Views: 434

Re: DhCP server for each port

VLANs won't make any difference in the dilemma how to segment network (to have many IP ranges depending on device's location) while not segmenting it (to have transparent networking between all connected devices). V in VLAN stands for Virtual ... and that refers to the physical infrastructure (i.e. ...
by mkx
Wed May 08, 2019 11:51 pm
Forum: Beginner Basics
Topic: DhCP server for each port
Replies: 11
Views: 434

Re: DhCP server for each port

The problem with the idea about different pool sizes and subnet masks is the following: IP subnet mask generally has to overlap 100% with L2 (ethernet) broadcast domain ... which allows members of such IP network to communicate with each other (and that includes gateway to other subnets) directly wi...
by mkx
Wed May 08, 2019 4:00 pm
Forum: General
Topic: Switching to new ISP-ROS script for bridge+VLAN+static IP please
Replies: 13
Views: 482

Re: Switching to new ISP-ROS script for bridge+VLAN+static IP please

You can handle the other parts of network as if nothing changed. For the WAN part, these steps should do: remove ether1 port from bridge if it is part of it now (by default it's not part of it anyway) remove any configuration touching ether1 (IP address, DHCP client, interface list membership) add V...
by mkx
Wed May 08, 2019 3:40 pm
Forum: General
Topic: Error on Wiki page
Replies: 4
Views: 287

Re: Error on Wiki page

Not that it matters in this context (after @Normis removed the misleading article), but anyways: Random MAC address MUST have second-lowermost bit SET in first octet! Please, change it to some of 2,6,A,E. Actually it can be one of 2,3,6,7,A,B,E,F ... all those have the second LSB set (and the first ...
by mkx
Wed May 08, 2019 3:12 pm
Forum: Beginner Basics
Topic: RB750Gr3 (hEX) using as switch and router
Replies: 2
Views: 179

Re: RB750Gr3 (hEX) using as switch and router

As to the concepts of solving your task (completely possible, BTW), I advise you to read through this excellent tutorial . After you have your setup up and running in software (with vlan-filtering on bridge), you can start to consider implementing things in hardware. You're mentioning hEX ... which ...
by mkx
Tue May 07, 2019 8:59 pm
Forum: Beginner Basics
Topic: Problem with NAT port forwarding
Replies: 7
Views: 285

Re: Problem with NAT port forwarding

You're mentioning another ISP and router ... are both WANs active at the same time?

This would mean a slightly complicated setup with potential routing triangle (in such case firewall can panic as it might not see both legs of the connection) and/or routing the other leg through different ISP.
by mkx
Tue May 07, 2019 8:49 pm
Forum: General
Topic: Discovering the MAC of a modem plugged into a Mikrotik [SOLVED]
Replies: 2
Views: 141

Re: Discovering the MAC of a modem plugged into a Mikrotik [SOLVED]

I don't think you can get WAN-facing MAC address of the modem from its LAN side. MAC addresses are only used (and thus known) within same broadcast domain and modem has two - LAN (where RB resides) and WAN (facing your ISP).
by mkx
Tue May 07, 2019 8:43 pm
Forum: General
Topic: RB2011UiAS-2HnD-IN replacement
Replies: 6
Views: 281

Re: RB2011UiAS-2HnD-IN replacement

You can definitely NOT use backup to transfer config between different device types. It's not fool-proof even between different devices of same type. You can create text export of configuration (it misses a few things, such as users, passwords, certifficates, ...) and then you can try to insert setu...
by mkx
Tue May 07, 2019 8:24 pm
Forum: Beginner Basics
Topic: Problem with NAT port forwarding
Replies: 7
Views: 285

Re: Problem with NAT port forwarding

How about firewall on your windows machine? By default it won't allowconnection from internet ...

Do packet counters of the NAT rule increase when you try to connect?
by mkx
Tue May 07, 2019 12:22 pm
Forum: SwOS
Topic: Problems with S+RJ10
Replies: 8
Views: 706

Re: Problems with S+RJ10

... Another strange thing is that it only negotiates at 5Gbps, not 10 ...
Negotiated speed highly depends on quality and length of UTP cables used to connect peripherial devices.
by mkx
Mon May 06, 2019 1:41 pm
Forum: General
Topic: CRS112 trunking
Replies: 5
Views: 270

Re: CRS112 trunking

You should not add trunked interfaces (sfp11 and sfp12) to the bridge1 ... only the trunk interface (trunk1).

The bridge should operate through trunk1 interface and only lower layers (switch chip) should be aware of what trunk1 really is.
by mkx
Sun May 05, 2019 2:57 pm
Forum: RouterBOARD hardware
Topic: RB951G-2HnD random reboots
Replies: 2
Views: 200

Re: RB951G-2HnD random reboots

Try to replace power adapter. When those start to fail, they are not able to supply enough power and device resets. Original power adapter is rated at 12V 1A (providing 12W power), replacement can be 9-30V (I advise to go with 12V or 24V) and power output at least 12W (so either 12V 1A or 24V at lea...
by mkx
Sat May 04, 2019 9:29 pm
Forum: SwOS
Topic: Can't even ping to GW from access port on CRS
Replies: 1
Views: 198

Re: Can't even ping to GW from access port on CRS

In section /interface bridge port you have to add all physical ports which will participate in switching traffic (regardless VLAN). First instinct would be to fuss with multiple bridges, but that's not necessary, vlan-filtering will enforce separation. According to your description those ports are a...
by mkx
Sat May 04, 2019 6:00 pm
Forum: Beginner Basics
Topic: HELP: Access Mikrotik Router Externally
Replies: 13
Views: 617

Re: HELP: Access Mikrotik Router Externally

ISP's modem and its subnet is considered as untrustworthy internet by Routerboard's firewall by default. You should reconsider your wish to connect to your RB from anywhere else than RB's LAN ... and if you are absolutely sure it should be allowed, you'll have to adjust firewall rules. As that means...
by mkx
Fri May 03, 2019 3:57 pm
Forum: General
Topic: Blocking Vlan routing with new bridge vlan filtering [SOLVED]
Replies: 8
Views: 383

Re: Blocking Vlan routing with new bridge vlan filtering [SOLVED]

The settings which you declared to fix the issue ... don't make much sense in the context of original post. My guess is that your settings are still flawed. But then, if you're happy about how things work, who are we to judge?
by mkx
Fri May 03, 2019 10:53 am
Forum: Beginner Basics
Topic: Bridge interface not showing traffic
Replies: 17
Views: 803

Re: Bridge interface not showing traffic

CCR doesn't have switch chip so majority (if not all) switch chip commands will fail.
by mkx
Thu May 02, 2019 11:34 pm
Forum: Beginner Basics
Topic: Connecting 2 routers & LTE via Powerline adapters. [SOLVED]
Replies: 7
Views: 447

Re: Connecting 2 routers & LTE via Powerline adapters. [SOLVED]

I'll describe example configuration for hAP ac lite. Configuration for CRS should be similar. I'll assume configuration which is default in recent ROS. If your current config is much different, post it so we'll know where to start from. The default NAT rule is such: /ip firewall nat add action=masqu...
by mkx
Thu May 02, 2019 10:43 pm
Forum: Beginner Basics
Topic: Connecting 2 routers & LTE via Powerline adapters. [SOLVED]
Replies: 7
Views: 447

Re: Connecting 2 routers & LTE via Powerline adapters. [SOLVED]

Do MT devices run firewall and NAT? Needed configuration changes depend on this information.
by mkx
Thu May 02, 2019 2:21 pm
Forum: General
Topic: Blocking Vlan routing with new bridge vlan filtering [SOLVED]
Replies: 8
Views: 383

Re: Blocking Vlan routing with new bridge vlan filtering [SOLVED]

All the psychics here who can find the issue without seeing the config are currently on vacation.
Except @sindy, he's around now. But even he prefers to work based on hard facts :-P
by mkx
Thu May 02, 2019 2:19 pm
Forum: General
Topic: Given the hardware similarities
Replies: 2
Views: 212

Re: Given the hardware similarities

Most probably not.
by mkx
Thu May 02, 2019 2:18 pm
Forum: General
Topic: No internet access on Mikrotik RB3011
Replies: 1
Views: 121

Re: No internet access on Mikrotik RB3011

Post output of /export hide-sensitive and obfuscate public IP address, SSID and PSK.
by mkx
Thu May 02, 2019 2:16 pm
Forum: Beginner Basics
Topic: hex S bridges, firewall and routing
Replies: 2
Views: 193

Re: hex S bridges, firewall and routing

Post output of /export hide-sensitive ... replace public IP address with text and hide SSIDs and PSKs.
by mkx
Thu May 02, 2019 2:14 pm
Forum: Beginner Basics
Topic: Connecting 2 routers & LTE via Powerline adapters. [SOLVED]
Replies: 7
Views: 447

Re: Connecting 2 routers & LTE via Powerline adapters. [SOLVED]

You'll have to describe the functionality and settings of each individual device: do they perform firewalling? what are their WAN and LAN IP addresses? do they perform NAT? what kind of connectivity between subnets do you need, full (almost transparent) or just for a few select services? And perhaps...
by mkx
Thu May 02, 2019 11:22 am
Forum: Wireless Networking
Topic: New network design - workable?
Replies: 1
Views: 204

Re: New network design - workable?

Yes, you can use a pair of dual-radio devices, dedicating one radio to backhaul, to achieve what you envisioned.
by mkx
Thu May 02, 2019 11:16 am
Forum: General
Topic: Mikrotik haplite have port 3-4 led lighting up without cable plugged in
Replies: 1
Views: 139

Re: Mikrotik haplite have port 3-4 led lighting up without cable plugged in

Closely inspect for any bent pins inside the connector. If you're not affraid of opening the case, inspect the circuit board for any traces of corrosion or impurities. Or some damages (cracks, shorts) in soldered parts ...
by mkx
Thu May 02, 2019 11:07 am
Forum: General
Topic: Blocking Vlan routing with new bridge vlan filtering [SOLVED]
Replies: 8
Views: 383

Re: Blocking Vlan routing with new bridge vlan filtering [SOLVED]

Post outputs of

/interface bridge export
/interface vlan export
/interface list export
/ip address export (and change/mask public IP addresses)
/ip firewall export (and change/mask public IP addresses)
by mkx
Thu May 02, 2019 10:58 am
Forum: Beginner Basics
Topic: Bridge interface not showing traffic
Replies: 17
Views: 803

Re: Bridge interface not showing traffic

On the LAN side, I have ETH2 connected to a Cisco switch where our VoIP phones get connected to a PBX on the cloud. The problem is that I barely see any traffic on the WAN bridge, where its participant ports are having 200+ Mbps traffic, the WAN bridge barely shows any traffic, like 20Kbps or somet...
by mkx
Thu May 02, 2019 10:42 am
Forum: RouterOS v7
Topic: Feature request for v7.x
Replies: 256
Views: 58500

Re: Feature request for v7.x

I hope full SwOS function are merged into RouterOS
Which functionality can you enable/configure in SwOS that can not be done in ROS?
by mkx
Wed May 01, 2019 7:22 pm
Forum: General
Topic: No TX sniffed on hardware offloaded ports
Replies: 3
Views: 178

Re: No TX sniffed on hardware offloaded ports

I missed that point.

What happens if you sniff packets off non-ethernet port (eoip or wireless), do you still get only one direction (if yes, ingress as well?) or both?
by mkx
Wed May 01, 2019 7:12 pm
Forum: Beginner Basics
Topic: portforwarding issue
Replies: 8
Views: 396

Re: portforwarding issue

Check PC's firewall ... does it allow inbound connections from internet?
by mkx
Tue Apr 30, 2019 4:15 pm
Forum: Beginner Basics
Topic: Some advice regarding the order of firewall rule
Replies: 6
Views: 318

Re: Some advice regarding the order of firewall rule

@anav, I'm leaving stunts to you, Canadians. We, Slovenians, don't have feeling for that (did you hear about duel Petterson v.s. Žižek?)
by mkx
Tue Apr 30, 2019 3:25 pm
Forum: General
Topic: I have My rooter down
Replies: 2
Views: 182

Re: I have My rooter down

Reduce DHCP lease time if it is too long. May be to double the average time customers hang around. One hour should be probably enough for majority of clients.

Btw, default lease time (in 6.44.3 via webfig) seems to be 10 minutes.

Do you use hotspot portal? That one seems to have different defaults.
by mkx
Tue Apr 30, 2019 3:18 pm
Forum: General
Topic: No TX sniffed on hardware offloaded ports
Replies: 3
Views: 178

Re: No TX sniffed on hardware offloaded ports

That's right, if HW offload is enabled, it can well happen that they don't enter device's CPU which is where sniffer can fetch them.
by mkx
Tue Apr 30, 2019 3:16 pm
Forum: General
Topic: RB3011 switch chip hw offload VLAN configuration [SOLVED]
Replies: 2
Views: 264

Re: RB3011 switch chip hw offload VLAN configuration [SOLVED]

Whatever passes wire untagged doesn't have any particular tag kn either side. I'm guessing Ubiquiti is calling "untagged VLAN 1" what is simply "untagged" and should be treated like such in Mikrotik. So you're getting the untaggedstuff to the bridge already. For the tagged stuff, change your config ...
by mkx
Tue Apr 30, 2019 2:24 pm
Forum: Beginner Basics
Topic: Some advice regarding the order of firewall rule
Replies: 6
Views: 318

Re: Some advice regarding the order of firewall rule

As I wrote: rules get triggered when all criteria are met. Then really depends on zhe ordrr of rules (if matching allow comes before matching deny, then traffic is allowed). If none rules match, then traffic is (implicitly) allowed. Many forum regulars consider approach "allow what needed, deny eve...
by mkx
Tue Apr 30, 2019 12:03 pm
Forum: Beginner Basics
Topic: Some advice regarding the order of firewall rule
Replies: 6
Views: 318

Re: Some advice regarding the order of firewall rule

Rules for individual cgain (input, forward, output) are processed in order from rule 1 towarss the end. Processing stops when there's a match. So: generaly rules which affect most packets should come earlier. When there are rules potentially matching same packets, order is obviously very important. ...
by mkx
Tue Apr 30, 2019 11:56 am
Forum: Beginner Basics
Topic: Server internet traffic
Replies: 1
Views: 119

Re: Server internet traffic

Your NAT rules are flawed. Post output of /ip firewall export hide-sensitive (redact public addresses but if tgere are more than one, do it in the way it is obvious which is which).
by mkx
Mon Apr 29, 2019 11:01 pm
Forum: Wireless Networking
Topic: Have client router pull from differnet dhcp
Replies: 1
Views: 125

Re: Have client router pull from differnet dhcp

The rule of thumb is: one DHCP server per L2 network. But then ... you can always make a static DHCP lease for certain MAC address (you can't easily define different gateway etc., so it's hard to force a device into non-default subnet. There's possibility to add DHCP options though). But then, if yo...
by mkx
Mon Apr 29, 2019 9:38 pm
Forum: Wireless Networking
Topic: Mikrotik WLAN & CAPsMAN - Bad download perfomance
Replies: 41
Views: 3467

Re: Mikrotik wireless LAN - WiFi - MIMO not working

Still get 0 improvement with 3 spatial streams, 3 chains working between wAP AC client and Asus AC68 unit. To have MIMO (multiple spatial streams) working, those streams have to be well separated (radio-wise) from each other. A great separation technique is use of two orthogonal polarizations (if u...
by mkx
Mon Apr 29, 2019 9:20 pm
Forum: Wireless Networking
Topic: Mikrotik WLAN & CAPsMAN - Bad download perfomance
Replies: 41
Views: 3467

Re: Mikrotik wireless LAN - WiFi - MIMO not working

... it local forwarding mode enabled. With CAPsMAN forwarding, with totally the same load applied, wAPs go insane 80-90% load, wireless speed drop a little too. I can't really understand it, since, shouldn't it be other way round? If local forwarding, wAP's CPU only needs to copy packets from wirel...
by mkx
Mon Apr 29, 2019 8:59 pm
Forum: Beginner Basics
Topic: Basic DNS Question
Replies: 5
Views: 304

Re: Basic DNS Question

Made my day, all yesses.......
I'm such a nice person. Not everybody notices it at first glance though ........
  • 1
  • 3
  • 4
  • 5
  • 6
  • 7
  • 45