Community discussions

Search found 2931 matches

  • 1
  • 6
  • 7
  • 8
  • 9
  • 10
by mkx
Mon Nov 05, 2018 6:31 pm
Forum: General
Topic: Firmware upgrade?
Replies: 3
Views: 405

Re: Firmware upgrade?

Usually I do the firmware upgrade first, since it waits for you to reboot, and then I do the software upgrade. Only after that I'll reboot the system. I never had any problems doing this, but I'm not sure if it is the correct way. How can you update firmware first and software later? Isn't firmware...
by mkx
Mon Nov 05, 2018 6:26 pm
Forum: General
Topic: PWR-Line AP
Replies: 48
Views: 8480

Re: PWR-Line AP

It would also be nice to have a power supply (24V/48V DC) with builtin power-line communications bridge. So to connect any MT device (Router, Switch, AP, ...) to this network. It would have two connectors: DC out and Ethernet. Just swap the orginal power supply against this new one and connect the ...
by mkx
Mon Nov 05, 2018 6:12 pm
Forum: Beginner Basics
Topic: Can't connect to hAP ac lite behind managed switch using Winbox (MAC address), but connection via IP address works [SOLVED]
Replies: 4
Views: 480

Re: Can't connect to hAP ac lite behind managed switch using Winbox (MAC address), but connection via IP address works [SOLVED]

MAC connections are allowed according to interface list. In CLI that's /tool mac-server mac-winbox, by default it's allowed from LAN interface list. Interface lists are under /interface list.
by mkx
Sun Nov 04, 2018 10:32 pm
Forum: Wireless Networking
Topic: 40 Km wireless link problem [SOLVED]
Replies: 6
Views: 778

Re: 40 Km wireless link problem [SOLVED]

If one link partner is burried in interference originating from its surrounding (as that's the case with AP in the middle of the town), the only possible solution is, as @mistry7 already wrote, to use antennae with narrower beam ... typically that means high-gain antennae. More important is to use h...
by mkx
Sun Nov 04, 2018 10:18 pm
Forum: Wireless Networking
Topic: Adding Virtual AP to cAP AC -Missing a Step? [SOLVED]
Replies: 51
Views: 3452

Re: Adding Virtual AP to cAP AC -Missing a Step? [SOLVED]

Regarding Q2: my pretty aged D-Link DES-1210-28 seemingly works with VLANs enabled all the time. By default all ports are configured as untagged members of VLAN 1 so seemingly it works as dummy switch. So it seems that it really can't be used as dummy switch ... if it is to pass VLAN-tagged frames, ...
by mkx
Sat Nov 03, 2018 9:32 pm
Forum: General
Topic: DHCP keep 'resetting' every 10-15 minutes
Replies: 2
Views: 302

Re: DHCP keep 'resetting' every 10-15 minutes

Please post exact (copy-paste) log entry from wAP about disassociation.

What is setting of Lease Time on DHCP server?
by mkx
Sat Nov 03, 2018 9:20 pm
Forum: General
Topic: rules order in raw firewall change
Replies: 11
Views: 748

Re: rules order in raw firewall change

how can i manage dynamic rules that be always top of my rules after restart? Depends how rules get added. With /ip firewall raw add you can use place-before=x ... where x is place where you want to put the new rule. If the rules are created and you can not influence the order, you can write a scrip...
by mkx
Sat Nov 03, 2018 6:02 pm
Forum: Beginner Basics
Topic: Access bridged GPON modem
Replies: 5
Views: 503

Re: Access bridged GPON modem

If mikrotik is configured properly, it should "just work". You can export configuration and post it here so we can check if there's something to improve. Connect to mikrotik via CLI and run command /exoort hide-sensitive . Paste result in code block ([] at the beginning of third formating items bloc...
by mkx
Sat Nov 03, 2018 4:32 pm
Forum: RouterBOARD hardware
Topic: mAP-2nD PoE Out question
Replies: 6
Views: 907

Re: mAP-2nD PoE Out question

This won't work ... mAP has passive PoE out which is not compatible with camera's 802.3af (active) PoE in.
by mkx
Sat Nov 03, 2018 4:15 pm
Forum: General
Topic: rules order in raw firewall change
Replies: 11
Views: 748

Re: rules order in raw firewall change

they should not yes, but i have this issue and also they will be upper of dynamic rules in raw tab
You're mentioning dynamic rules ... those obviously don't survive reboots. If you want those higher than static rules, you have to push them up when creating them.
by mkx
Sat Nov 03, 2018 4:09 pm
Forum: General
Topic: CRS212-1G-10S and VLAN
Replies: 5
Views: 581

Re: CRS212-1G-10S and VLAN

You should use single bridge. If you want to have wire-speed data transfers without CRS' CPU burning out (e.g. to do it in switch chip rather than in software), then stick to /interface ethernet switch section when configuring it. This is a post-6.41 type of configuration despites some users around ...
by mkx
Sat Nov 03, 2018 2:10 pm
Forum: Beginner Basics
Topic: Access bridged GPON modem
Replies: 5
Views: 503

Re: Access bridged GPON modem

The right thing to do is to remove ether4 (wire connection towards GPON) from the bridge and set IP address directly on ether4 interface.

Probably it could be done without removing ether4 from bridge, but it's tricky and in your case it doesn't bring any benefit.
by mkx
Sat Nov 03, 2018 2:06 pm
Forum: Beginner Basics
Topic: ethernet over lte/usb
Replies: 6
Views: 724

Re: ethernet over lte/usb

If you only get single IP address through LTE interface (which is pretty much a norm in public mobile networks), then you don't want to bridge all ethernet ports with LTE. Instead you want router device to do routing + NAT for all "LAN" devices, connected to ethernet ports (and WiFi access point). W...
by mkx
Sat Nov 03, 2018 2:02 pm
Forum: Beginner Basics
Topic: PC network isolation approach
Replies: 7
Views: 653

Re: PC network isolation approach

VLAN approach is the only scalable approach.
by mkx
Fri Nov 02, 2018 9:58 pm
Forum: Beginner Basics
Topic: Access bridged GPON modem
Replies: 5
Views: 503

Re: Access bridged GPON modem

It really depends on how the GPON CPE can be configured. If you can make its port1 both bridged and routed[*], then you can configure RB so that you'll be able to access GPON CPE from your LAN. [*] dual mode is not unheard of. I gave a xDSL modem which is configured to bridge mode so that PPPoE clie...
by mkx
Fri Nov 02, 2018 12:52 pm
Forum: General
Topic: Not enough disk space to perform update
Replies: 15
Views: 10034

Re: Not enough disk space to perform update

Depending on number of packages installed, but 8MB free space should be enough. However, the packagrs to be updated via system -> packages -> update are downloaded into RAM on units with small NAND and 9MB free memory does sound a bit tight. What you can try is to manually download needed packages a...
by mkx
Thu Nov 01, 2018 9:47 pm
Forum: Wireless Networking
Topic: Should i use a different mac address for each virtual ap ( ssid ) on the same radio ?
Replies: 1
Views: 395

Re: Should i use a different mac address for each virtual ap ( ssid ) on the same radio ?

You shoul use different MAC for each virtual AP. After device associates to AP, it communicates with it using AP's MAC. If multiple virtual APs share same MAC, then AP can not easily process incomming traffic. Even first step (decryption of received frames) can fail if different VAPs use different s...
by mkx
Thu Nov 01, 2018 9:40 pm
Forum: Wireless Networking
Topic: [ASK]Wireless question, tx power
Replies: 3
Views: 492

Re: [ASK]Wireless question, tx power

I've never played with tx power mode ... on all my WiFi capable Routerboards it's set to "default" whatever that might be.
by mkx
Thu Nov 01, 2018 9:25 pm
Forum: General
Topic: Bridge VLAN Filtering
Replies: 22
Views: 7039

Re: Bridge VLAN Filtering

I wonder if that RB750(1), configured as dummy switch, is not spoiling the party? I'd try to configure VLANs properly on it (all ports being trunk ports with appropriate VLANs admitted). Being a dummy switch, seeing frames with correct MAC addresses but not considering VLAN tags it might use shortcu...
by mkx
Thu Nov 01, 2018 8:35 pm
Forum: Beginner Basics
Topic: Isolate Hotspot from other interfaces on layer2
Replies: 1
Views: 374

Re: Isolate Hotspot from other interfaces on layer2

As long as guest traffic only lives inside single device (single routerboard) it is enough to properly use firewall. If traffic leaves one device and enters another one (e.g. AP separated from router), it's best to use VLANs.
by mkx
Thu Nov 01, 2018 8:21 am
Forum: Wireless Networking
Topic: [ASK]Wireless question, tx power
Replies: 3
Views: 492

Re: [ASK]Wireless question, tx power

If you want to decrease Tx power, then increase value of antenna-gain (and set country to your country).
by mkx
Wed Oct 31, 2018 11:19 pm
Forum: RouterBOARD hardware
Topic: wAP LTE - Would a network know its not a phone?
Replies: 1
Views: 1014

Re: wAP LTE - Would a network know its not a phone?

One of standard parts of handshake between device and mobile network is exchange of IMEI number (not mandatory but most networks do) ... IMEI is a unique number identifying device, first part identifies device manufacturer and model. The more important part of hanshake is sending device's capabiliti...
by mkx
Wed Oct 31, 2018 10:12 am
Forum: Beginner Basics
Topic: RouterOS freezes if I change the IP
Replies: 11
Views: 1009

Re: RouterOS freezes if I change the IP

Most reconfiguration involves change of device's IP address, which in turn invariantly means loss of (IP) connection. You can avoid being disconnected by using Winbox and connect via MAC address. Using safe mode does not help here. It is possible to reconfigure device to the desired config without b...
by mkx
Wed Oct 31, 2018 10:07 am
Forum: Beginner Basics
Topic: Need help understanding VLAN mode
Replies: 9
Views: 1430

Re: Need help understanding VLAN mode

3. Untagged frames from "hybrid" ports (when using bridge VLAN filtering without pvid set)
by mkx
Wed Oct 31, 2018 10:03 am
Forum: Beginner Basics
Topic: Firewall filter add to address list - decrease timeout
Replies: 5
Views: 756

Re: Firewall filter add to address list - decrease timeout

The rule adds to the list. If address is in the list already, the entry doesn't get changed. If you want to have different behaviours, you'll have to use more than one address list.
by mkx
Mon Oct 29, 2018 11:05 pm
Forum: Beginner Basics
Topic: cAP ac / v6.40.4 - frequent disconnects?
Replies: 10
Views: 779

Re: cAP ac / v6.40.4 - frequent disconnects?

I'm new to RouterOS & when I check WebFig->Log, I only see the last handfull of entries, starting with "router was rebooted without proper shutdown." Is there an easy way to retain entries longer than a single boot? You can either configure sending log messages to some other machine running syslog ...
by mkx
Mon Oct 29, 2018 10:56 pm
Forum: Beginner Basics
Topic: Need help understanding VLAN mode
Replies: 9
Views: 1430

Re: Need help understanding VLAN mode

You are right, I set default-vlan-id to 2 for both Ports 2 and 3. This explains how the laptop is able to get IP address from DHCP server. My mistake for missing the following stated very clearly on the wiki page: Net effect is as described in wiki (and highlited by you). However, I still want to b...
by mkx
Mon Oct 29, 2018 10:24 am
Forum: Beginner Basics
Topic: RMB11G and HAP AC poe connection
Replies: 4
Views: 819

Re: RMB11G and HAP AC poe connection

Functionality of ether1 port as WAN port is by default. You're free to change that as you wish.

Personally I don't think the UBNT PoE adapters would work, the 24V models are rated up to 1A which is slightly too low.
by mkx
Sun Oct 28, 2018 10:26 pm
Forum: Wireless Networking
Topic: Old device RB411 reboots, hw problems ?
Replies: 6
Views: 636

Re: Old device RB411 reboots, hw problems ?

After years of service, my first guess would be power supply being marginal and heading towards worse.
by mkx
Sun Oct 28, 2018 9:58 pm
Forum: Beginner Basics
Topic: RMB11G and HAP AC poe connection
Replies: 4
Views: 819

Re: RMB11G and HAP AC poe connection

If you're going to connect RBM11G to ether5 port of hAP ac, then in theory you could daisy-chain power as well. Declared PoEout max current on hAP ac is 700 mA while RBM11G consumes max 11W ... if you go with 24V supply, PoEout current would be around 460mA. However, hAP ac itself cunsumes up to 17W...
by mkx
Sun Oct 28, 2018 9:42 pm
Forum: Beginner Basics
Topic: Need help understanding VLAN mode
Replies: 9
Views: 1430

Re: Need help understanding VLAN mode

Port 2 - access port for VLAN2 Port 3 - access port for VLAN2 . Where vlan-mode=secure for all Ports 1 to 5, vlan-header=add-if-missing for Port 1, vlan-header=always-strip for Port 2 to 5. A laptop connected to Port 2 can successfully obtain an IP address from a DHCP server connected to Port 3. Bu...
by mkx
Sat Oct 27, 2018 4:23 pm
Forum: General
Topic: SSTP VPN Windows 7 client problem
Replies: 2
Views: 389

Re: SSTP VPN Windows 7 client problem

This forum is user forum, not support forum. Admins act more like police here, they are NOT responsible for giving information and answers (though mostly they are really helpful).
If you feel you need Mikrotik response urgently, contact their support via email support@mikrotik.com .
by mkx
Sat Oct 27, 2018 3:30 pm
Forum: RouterBOARD hardware
Topic: CRS317-1G-16S+RM - Hardware specification
Replies: 34
Views: 7281

Re: CRS317-1G-16S+RM - Hardware specification

i want to know million packets per seconds.
You can't get that data, it's confidential.

Perhaps data about thousands packets per second would do? It's there, in colums kpps (kilo=1000 packets per second). You might be able to calculate Mpps from that.
by mkx
Sat Oct 27, 2018 3:16 pm
Forum: Beginner Basics
Topic: VLAN not getting IP Address
Replies: 5
Views: 679

Re: VLAN not getting IP Address

From CLI execute command
/export hide-sensitive
and copy-paste here inside [ code] environment (that's the 7th icon from left - [] ).
by mkx
Sat Oct 27, 2018 2:36 pm
Forum: Wireless Networking
Topic: Cant connect to Lan from Wlan
Replies: 4
Views: 575

Re: Cant connect to Lan from Wlan

Can you ping wired device from another wired device? The wired device's firewall might interfer ...
i cant
So check firewall on the "problematic" device. Windows firewall by default blocks pings for example.
by mkx
Sat Oct 27, 2018 2:27 pm
Forum: General
Topic: Network topology help. [SOLVED]
Replies: 5
Views: 758

Re: Network topology help. [SOLVED]

When thinking of VLANs, think of them as separate LANs for a moment. Meaning that while end devices don't need to know anything about different (V)LANs (they just connect either physically to assigned ethernet port or wirelessly do assigned SSID), the access node of network (either ethernet switch o...
by mkx
Sat Oct 27, 2018 1:56 pm
Forum: Beginner Basics
Topic: VLAN not getting IP Address
Replies: 5
Views: 679

Re: VLAN not getting IP Address

Post configuration of mikrotik router so we can check if there's something not right.
by mkx
Fri Oct 26, 2018 8:07 pm
Forum: SwOS
Topic: css326 vlan question
Replies: 1
Views: 852

Re: css326 vlan question

Let's focus on Example #1 from the link posted .... Step 1) ... default VLAN ID gets configured for ports 6, 7 and 8. Meaning that if on ingress (from cable to port) switch receives untagged frame, it will add VLAN tag with VLAN ID set to the defined value (e.g. 200 on port 6). Likewise on egress (f...
by mkx
Fri Oct 26, 2018 7:33 pm
Forum: Wireless Networking
Topic: 4G modem does not reconnect (ppp)
Replies: 2
Views: 421

Re: 4G modem does not reconnect (ppp)

Current Firmware 3.33
Upgrade Firmware 6.43.4
I'd upgrade firmware and then check things again. Firmware version 3.33 is pretty old.
/system routerboard upgrade
and reboot.
by mkx
Fri Oct 26, 2018 7:28 pm
Forum: Wireless Networking
Topic: Cant connect to Lan from Wlan
Replies: 4
Views: 575

Re: Cant connect to Lan from Wlan

Can you ping wired device from another wired device? The wired device's firewall might interfer ...
by mkx
Fri Oct 26, 2018 3:10 pm
Forum: Beginner Basics
Topic: DHCP for VLANs, how?
Replies: 9
Views: 934

Re: DHCP for VLANs, how?

What you showed is not the way to manage VLANs anymore. It is now done in Bridge. No, what I described (VLANs on single ethernet port) is completely valid configuration in current ROS versions. It is called "router on a stick" and there's no need to use bridge (for this particular configuration). W...
by mkx
Fri Oct 26, 2018 2:40 pm
Forum: Announcements
Topic: v6.42.9 [long-term] is released!
Replies: 119
Views: 26020

Re: v6.42.9 [long-term] is released!

Does it happen when you change MAC address of just any member port or does it happen only when you change MAC address of a port which previously had same MAC address as bridge?
by mkx
Thu Oct 25, 2018 11:59 pm
Forum: Beginner Basics
Topic: DHCP for VLANs, how?
Replies: 9
Views: 934

Re: DHCP for VLANs, how?

You can not have two VLANs with same IP subnet. Well, technically you can if you try really hard. But it doesn't really make much sense doing it if you don't allow traffic between wifi devices and LAN. Bellow I'll outline one way of achieving what I understand you want to do. I'll assume you know ho...
by mkx
Thu Oct 25, 2018 10:07 pm
Forum: Beginner Basics
Topic: DHCP for VLANs, how?
Replies: 9
Views: 934

Re: DHCP for VLANs, how?

There are plenty of ways doing it. Specially so as your description of what you're trying to achieve is vague.
If you post current configuration, we might better understand your goal and we might spot the problem.
by mkx
Wed Oct 24, 2018 10:47 pm
Forum: Beginner Basics
Topic: IPTV via VLAN
Replies: 17
Views: 4059

Re: IPTV via VLAN

@mkx: pretty sure yes. I even connected the Amino box directly to the NTU. It receives an IP address then but does not get an connection to the ACS. I'm using Netgem set-top box which is configured to use untagged for normal internet (e.g. EPG download, youtube, deezer, etc.) but uses tagged VLAN t...
by mkx
Wed Oct 24, 2018 10:34 pm
Forum: Beginner Basics
Topic: Send two untagged vlan from trunk uplink to access port..
Replies: 4
Views: 562

Re: Send tvo untagged vlan from trunk uplink to access port..

If you want to simulate unmanaged switch, then you have to relay both VLANs tagged. Unmanaged switch will send frames regardless of VLAN tag and will most certainly not untag frames.
by mkx
Wed Oct 24, 2018 12:32 am
Forum: Beginner Basics
Topic: IPTV via VLAN
Replies: 17
Views: 4059

Re: IPTV via VLAN

Are you sure Amino is not expecting to receive stuff over tagged VLAN?
by mkx
Mon Oct 22, 2018 8:38 pm
Forum: General
Topic: Routing between two subnets
Replies: 1
Views: 225

Re: Routing between two subnets

If you didn't change much of the default setup, then homelan is considered as WAN by router2. Review firewall setup. If you trust homelan devices, then you can either remove all firewall rules (be careful about SRC NAT rule, disable it first and test internet connectivity from homelab to verify TP-L...
by mkx
Sat Oct 20, 2018 1:01 pm
Forum: Beginner Basics
Topic: linux-mikrotik static ip does not play nice.
Replies: 1
Views: 269

Re: linux-mikrotik static ip does not play nice.

As soon as you configured linux with static address and settings, it will not use DHCP protocol to obtain settings from router regardless of settings on router. If you set lease static on RB, it is still dynamic from client's (linux) perspective, but DHCP server reserves that IP address for particul...
by mkx
Sat Oct 20, 2018 10:52 am
Forum: Wireless Networking
Topic: ARM devices and NV2 protocol
Replies: 579
Views: 60193

Re: ARM devices and NV2 protocol

@Normis I 'll post here untill we 'll have an answer :-)

I apologize for my inistence but I need an answer

Thank You
They can only ignore us for so long 😀 eventually they will have to own up to it and fix it.
Sure they will fix it ... in ROS V7 :wink:
by mkx
Fri Oct 19, 2018 2:39 pm
Forum: Beginner Basics
Topic: WAN NAT Bridge and VLAN yes/no
Replies: 14
Views: 1933

Re: WAN NAT Bridge and VLAN yes/no

ether3 and ether4 should be L2 separated in all 3 examples. The only ports not L2 separared are ether1 and ether2 in examples 2 and 3. As to bridge's MAC addresses: as said it doesn't matter as long as networks with those bridges are L2 separated. It would become a problem if you would connect ether...
by mkx
Fri Oct 19, 2018 2:34 pm
Forum: General
Topic: v6 RC and v7 BETA
Replies: 126
Views: 24435

Re: v6 RC and v7 BETA

"soon" in what perspective? Is it relative to time scale of v7 presence on this forum ... or is it relative to age if solar system?
by mkx
Fri Oct 19, 2018 12:18 pm
Forum: RouterBOARD hardware
Topic: Routerboard 112
Replies: 4
Views: 654

Re: Routerboard 112

Or, if a low-end solution is adequate, complete solution for the same price: hAP ac lite (available in mini-tower enclosure as well). I'm using a pair in one of my installations, 5Ghz radio running nstreme as bridge between the two and 2.4GHz for 802.11 clients.
by mkx
Fri Oct 19, 2018 11:58 am
Forum: Beginner Basics
Topic: simple switch and WiFi AP (no dhcp, no nat)
Replies: 5
Views: 1984

Re: simple switch and WiFi AP (no dhcp, no nat)

Don't forget to set disable-pmkid=yes in wireless security profile.
by mkx
Thu Oct 18, 2018 11:55 pm
Forum: RouterBOARD hardware
Topic: hAP ac lite rebooting constantly
Replies: 3
Views: 801

Re: hAP ac lite rebooting constantly

Another point on the "try&fail" list is to replace the power supply.
by mkx
Thu Oct 18, 2018 10:51 pm
Forum: Beginner Basics
Topic: WAN NAT Bridge and VLAN yes/no
Replies: 14
Views: 1933

Re: WAN NAT Bridge and VLAN yes/no

As @tdw already wrote for your particular case bridge is not needed at all as every router port is member of different L3 network and even if connectivity between those subnets is needed, it must be achieved by routing not switching (remember, bridge is kind of switch). So not to suffer some unexpec...
by mkx
Thu Oct 18, 2018 8:52 pm
Forum: General
Topic: Is Switch based VLAN configuration obsolete if using hardware offload feature of bridge [SOLVED]
Replies: 3
Views: 429

Re: Is Switch based VLAN configuration obsolete if using hardware offload feature of bridge [SOLVED]

Two things happened between ROS 6.40 and current: shift from "master port" to "all ports". While traditionally switch ports were "enslaved" to one port and RB only dealt with master port, in "all ports" all of them are visible to ROS (but you better don't configure things directly on ports that are ...
by mkx
Thu Oct 18, 2018 8:17 pm
Forum: General
Topic: Split trunk eth/vlan port transparently to two physical ports
Replies: 3
Views: 407

Re: Split trunk eth/vlan port transparently to two physical ports

Personally I never liked mixing tagged and untagged packets on same wire. While I never configured pass-through I'd try to set-up another VLAN and use that one for pass-through instead of raw ethernet interface.
by mkx
Thu Oct 18, 2018 8:06 pm
Forum: Beginner Basics
Topic: simple switch and WiFi AP (no dhcp, no nat)
Replies: 5
Views: 1984

Re: simple switch and WiFi AP (no dhcp, no nat)

I think "Home AP" in quick set should do.
by mkx
Thu Oct 18, 2018 7:59 pm
Forum: Beginner Basics
Topic: WAN NAT Bridge and VLAN yes/no
Replies: 14
Views: 1933

Re: WAN NAT Bridge and VLAN yes/no

bridge in ROS has two personalities. First one is, as @ashpri nicely described, a managed switch (but unlike "normal" switch bridge ports can be other than ethernet ports). Second personallity is a network device (similarly to ethernet ports, wlan devices, LTE devices, VLAN interfaces, ...). This in...
by mkx
Wed Oct 17, 2018 10:46 pm
Forum: RouterBOARD hardware
Topic: R11e-4G vs. R11e-LTE
Replies: 4
Views: 1290

Re: R11e-4G vs. R11e-LTE

Anyway... Is there any reliable source what provider uses what bands (other then searching Google...). Your favourite provider should know that info ... if they don't know it or they don't want to share it with public, you might reconsider your devotion ... In MNOs' defence: things change with cont...
by mkx
Wed Oct 17, 2018 10:38 pm
Forum: Beginner Basics
Topic: WAN NAT Bridge and VLAN yes/no
Replies: 14
Views: 1933

Re: WAN NAT Bridge and VLAN yes/no

My guess is that with vlan-filtering it is possible to deal with all simple and most not-so-simple cases by using single bridge. Possible exempt from this rule would be not-so-simple configuration on RB with more than one switch chip where use of appropriate number of bridges would allow to use HW o...
by mkx
Wed Oct 17, 2018 7:44 pm
Forum: Beginner Basics
Topic: WAN NAT Bridge and VLAN yes/no
Replies: 14
Views: 1933

Re: WAN NAT Bridge and VLAN yes/no

@asphri ... part 1 (questions): 1. router will forward IP traffic between (V)LANs on which it has IP address defined. So if two (V)LANs need to communicate, there should be router that has connectivity (physical and VLAN) to both subnets and it needs IP address defined in both subnets. Firewall can ...
by mkx
Wed Oct 17, 2018 5:54 pm
Forum: Beginner Basics
Topic: How to write dynamic command line?
Replies: 4
Views: 419

Re: How to write dynamic command line?

Using auto-mac the bridge MAC address can also change if you remove the "donnor" port from the bridge. Having bridge MAC address set statically could show even nastier side-effects in such case. The best approach would be to set bridge MAC address to a completely different MAC address for which you'...
by mkx
Wed Oct 17, 2018 5:43 pm
Forum: Beginner Basics
Topic: can't login to mikrotik router after reset
Replies: 2
Views: 880

Re: can't login to mikrotik router after reset

Try MAC-connect using winbox (there are ways to run it on mac). Working IP setup on RB is not needed for this kind of connection.
by mkx
Tue Oct 16, 2018 9:18 am
Forum: General
Topic: Split trunk eth/vlan port transparently to two physical ports
Replies: 3
Views: 407

Re: Split trunk eth/vlan port transparently to two physical ports

AFAIK it's normal that different VLANs on same physical ethernet device share same MAC address. After all, first action of a switch is to check destination MAC address and later (by switches aware of) VLAN tags. From dummy switch perspective it doesn't matter which MAC address is used as long as som...
by mkx
Mon Oct 15, 2018 7:30 pm
Forum: RouterBOARD hardware
Topic: R11e-4G vs. R11e-LTE
Replies: 4
Views: 1290

Re: R11e-4G vs. R11e-LTE

Both cards support a quite disjunct set of frequency bands. Decission on which one to use should therefore be based on which frequency bands are used by your favourite LTE network operator in the area of deployment. Choosecard that supports prefered band and/or supports more bands.
by mkx
Mon Oct 15, 2018 6:49 pm
Forum: Wireless Networking
Topic: guest don't work
Replies: 5
Views: 785

Re: guest don't work

Your export is not complete, I see no routes printed for instance
As OP is running DHCP client on bridge, default route should be dynamically configured by that ... and will not be seen in export (only in /ip route print). Other routes are not needed.
by mkx
Mon Oct 15, 2018 6:44 pm
Forum: Wireless Networking
Topic: guest don't work
Replies: 5
Views: 785

Re: guest don't work

wan2's address is not really regular: 20.20.20.0/24 is network address and should not be assigned to any device.
by mkx
Mon Oct 15, 2018 6:31 pm
Forum: General
Topic: rain of unsuccessful logins on hexs
Replies: 1
Views: 283

Re: rain of unsuccessful logins on hexs

Set-up firewall. A good manual on topic will help, there are nice examples at the end.
by mkx
Mon Oct 15, 2018 6:05 pm
Forum: General
Topic: Random Reboots
Replies: 7
Views: 855

Re: Random Reboots

There have been discussions that power supplies of CCRs sometimes fail. The cause are usually defunct capacitors. It is possible to replace them.
Try to search for those posts in this forum (probably in RouterBOARD hardware section).
by mkx
Mon Oct 15, 2018 5:49 pm
Forum: Announcements
Topic: URGENT security reminder
Replies: 84
Views: 34938

Re: URGENT security reminder

Ok! that is cool. I have a backup copy of /export file, I will reload script from scratch for security measure.
Before loading exported configuration do inspect it in case it contains something suspicious.
by mkx
Mon Oct 15, 2018 5:40 pm
Forum: Beginner Basics
Topic: WAP-LTE PoE voltage question [SOLVED]
Replies: 3
Views: 383

Re: WAP-LTE PoE voltage question [SOLVED]

As WAP can take up to 30V use highest available (19V). This way current will be the lowest giving slightly lower power loss in cables. Or it will support slightly longer PoE cables without causing instability (slightly too low voltage can cause reboots).
by mkx
Mon Oct 15, 2018 5:31 pm
Forum: Announcements
Topic: URGENT security reminder
Replies: 84
Views: 34938

Re: URGENT security reminder

If the attacker scans your ports, he will find the new port number too. Upgrade anyway! Hi All, I updated my Router OS from v6.41. to v643.2, updated winbox to current version, updated admin password, still the hacker was able to get full control of the system locking me out. What's the way out aga...
by mkx
Mon Oct 15, 2018 9:26 am
Forum: Beginner Basics
Topic: How to setup repeater for wlan with multiple virtual ssid/vlans
Replies: 3
Views: 654

Re: How to setup repeater for wlan with multiple virtual ssid/vlans

Not in repeater mode, that works only for one SSID. You could trunk the traffic together over the Wifi link with VLAN and then separate on the repeater into the subnets with their SSID. It will then look as if the SSID are "repeated". It is basically two AP with each having same SSID and linked tog...
by mkx
Sun Oct 14, 2018 10:16 pm
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 365
Views: 83827

Re: v6.44beta [testing] is released!

Change log for this beta clearly states that R11e firmware upgrade is available only for international version of devices .... can't you read? actually i can - that's why i stated my question: do you plan for allowing lte firmware upgrade on the US version? Sorry, didn't see the question in your pr...
by mkx
Sun Oct 14, 2018 10:42 am
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 365
Views: 83827

Re: v6.44beta [testing] is released!

Change log for this beta clearly states that R11e firmware upgrade is available only for international version of devices .... can't you read?
by mkx
Fri Oct 12, 2018 9:54 am
Forum: General
Topic: VLAN switch fallback or secure [SOLVED]
Replies: 12
Views: 1253

Re: VLAN switch fallback or secure [SOLVED]

If ports carrying same VLAN don't belong to same switch chip, then you'll have to use a CPU bridge between them. There are two possibilities: a) create dedicated bridge for particular VLAN or b) use common bridge (which, if configured that way, will transparently carry on VLAN). Which way is better ...
by mkx
Thu Oct 11, 2018 10:26 pm
Forum: General
Topic: VLAN configuration issue [SOLVED]
Replies: 12
Views: 923

Re: VLAN configuration issue [SOLVED]

What's missing is VLAN settings on switch1-cpu "port" under /interface ethernet switch port . Most probably it's port number 5 (you can verify it with command /interface ethernet switch port print ). I'd try the following code, but just before executing it I'd enter safe mode[*] ... if the setting i...
by mkx
Thu Oct 11, 2018 3:23 pm
Forum: General
Topic: VLAN configuration issue [SOLVED]
Replies: 12
Views: 923

Re: VLAN configuration issue [SOLVED]

How about posting your current configuration (output of /interface export)? Then we'll able to see what you did (as opposed to what you think you did)...
by mkx
Thu Oct 11, 2018 3:14 pm
Forum: General
Topic: VLAN switch fallback or secure [SOLVED]
Replies: 12
Views: 1253

Re: VLAN switch fallback or secure [SOLVED]

You can post relevant part of configuration (e.g. /interface export) and we can have a look.
by mkx
Wed Oct 10, 2018 5:30 pm
Forum: General
Topic: UK Lease line WAN subnet mask on MK routers
Replies: 2
Views: 631

Re: UK Lease line WAN subnet mask on MK routers

I seem to remember a thread or two on this forum where users complained about MT not allowing /31 netmask (if you think of it, it doesn't seem like valid net mask as it lacks network and broadcast addresses). But there's a workaround (from the first linked thread): /ip address add address=1.2.3.246/...
by mkx
Wed Oct 10, 2018 1:29 pm
Forum: Wireless Networking
Topic: Wireless router in every hotel room
Replies: 28
Views: 2885

Re: Wireless router in every hotel room

Technically, you can say that the number is also "maximum antenna gain in dBi" because if you set 30dBi antenna gain while you use it in 2402-2472 range, you will achieve 0dBm TX power, therefore disabling the output. Not exactly true. TX power expressed as 0dBm means TX power of 1mW. Which is almo...
by mkx
Wed Oct 10, 2018 12:30 pm
Forum: General
Topic: Can default configuration be hacked?
Replies: 8
Views: 1040

Re: Can default configuration be hacked?

It seems that some hacks of RB routers make changes that could not be simply undone. The only 100% cure is to netinstall hacked router. Configuration reset is not enough.
by mkx
Tue Oct 09, 2018 11:13 pm
Forum: Beginner Basics
Topic: Simple Hybrid VLAN ports on Microtik Hex
Replies: 1
Views: 234

Re: Simple Hybrid VLAN ports on Microtik Hex

All 3 VLAN interfaces (VLAN3, VLAN4 and VLAN5) should be members of a single bridge.
by mkx
Tue Oct 09, 2018 11:01 pm
Forum: Wireless Networking
Topic: Wireless router in every hotel room
Replies: 28
Views: 2885

Re: Wireless router in every hotel room

I guess it'll work with no_country_set as well ... here's what my RB951G says about limitations: /interface wireless info country-info no_country_set ranges: 2402-2472/b,g,gn20,gn40(30dBm) 2417-2457/g-turbo(20dBm) 5170-5250/a,an20,an40,ac20,ac40,ac80,ac160,ac80+80(17dBm) 5250-5330/a,an20,an40,ac20,a...
by mkx
Tue Oct 09, 2018 8:55 pm
Forum: Wireless Networking
Topic: Wireless router in every hotel room
Replies: 28
Views: 2885

Re: Wireless router in each hotel room

It is possible to lower TX power of wireless ... using a trick of setting higher antenna gain. As ROS tries to keep EIRP (transmitted power plus antenna gain) within legal limitations, setting higher antenna gain without actually using high-gain antenna means lower transmit power. Yuo'll have to exp...
by mkx
Tue Oct 09, 2018 5:45 pm
Forum: Beginner Basics
Topic: Pinging from VLAN interface not working
Replies: 3
Views: 308

Re: Pinging from VLAN interface not working

And also you need to specify out-interface=ether1 for your masquerade rule.
This.

And don't forget to set up good firewall rules.
by mkx
Mon Oct 08, 2018 10:58 pm
Forum: Beginner Basics
Topic: Firewall filter/nat best practices [SOLVED]
Replies: 3
Views: 1018

Re: Firewall filter/nat best practices [SOLVED]

In addition to what @Sob wrote: I find using src-address in dst-NAT translation also useful if same port should be forwarded to different DMZ/LAN hosts depending on the remote host's IP address. E.g.: /ip firewall nat add action=dst-nat chain=dstnat comment="ssh from remote1 goes to LAN1" in-interfa...
by mkx
Mon Oct 08, 2018 10:47 pm
Forum: Beginner Basics
Topic: Not allowing one certain IP address to see the rest of the network
Replies: 14
Views: 901

Re: Not allowing one certain IP address to see the rest of the network

If what OP wrote is read verbatim, then: laptop with IP address 192.168.0.22 should not see the rest of network 192.168.0.0/24 And that is not possible except in one particular case: that laptop is directly connected to a wired port of RB (and no other device is sharing that port). In this case brid...
by mkx
Mon Oct 08, 2018 10:32 pm
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 39002

Re: v6.43.1 [stable] and v6.43.2 [stable] are released!

My experience on hAP ac2: very unstable, plenty of watchdog reboots (most of them due to ping timeouts, pinged address is linux server on LAN). For me instability is regression from 6.42.9. I take my words back. Instability is not a regression from 6.42.9, my hAP ac2 was not completely stable while...
by mkx
Mon Oct 08, 2018 6:21 pm
Forum: Beginner Basics
Topic: Can HAP-L wifi be on same subnet as main LAN? [SOLVED]
Replies: 3
Views: 562

Re: Can HAP-L wifi be on same subnet as main LAN? [SOLVED]

I find the best way to learn ROS is to play with it, read manual in wiki and read posts in this forum (a few users are really an asset to community. I won't name any but anyone can quickly see who they are).
by mkx
Mon Oct 08, 2018 10:03 am
Forum: General
Topic: hAC AP using DHCP and boot file
Replies: 7
Views: 613

Re: hAC AP using DHCP and boot file

Out-of-a-box rourerboards don't try to boot from network. You will have to change that setting.
by mkx
Mon Oct 08, 2018 10:00 am
Forum: Beginner Basics
Topic: Can HAP-L wifi be on same subnet as main LAN? [SOLVED]
Replies: 3
Views: 562

Re: Can HAP-L wifi be on same subnet as main LAN? [SOLVED]

It is possible, you have to transform hAP lite from being "wireless router" to being "AP/switch". The easiest way of doing it will mean that ether1 will not be usable. These are steps to be done on your hAP lite: disable DHCP server bound to bridge bind DHCP client to bridge re-connect ethernet cabl...
by mkx
Mon Oct 08, 2018 9:49 am
Forum: Beginner Basics
Topic: switch on hEX Gr2
Replies: 7
Views: 551

Re: switch on hEX Gr2

Which is it: a) wireless clients can not communicatewith each other or b) wireless clients can not communicate with any LAN host, including wired? If it's a), then check setting of default-forwarding (should be yes). The other thing (which might cause either effect) is firewall on other LAN hosts wh...
by mkx
Sun Oct 07, 2018 8:27 pm
Forum: Beginner Basics
Topic: switch on hEX Gr2
Replies: 7
Views: 551

Re: switch on hEX Gr2

If you're going to use hEX as switch, the you presumably have another device as router. So you should disable all firewall rules for chain=forward, disable any DHCP server that might be still there and most definitely disable NAT that might still be active. If you need firewall to protect hEX itself...
by mkx
Sun Oct 07, 2018 8:07 pm
Forum: General
Topic: hAC AP using DHCP and boot file
Replies: 7
Views: 613

Re: hAC AP using DHCP and boot file

There are settings about boot procedure ... even if you get RB to boot via network, by default it uses bootp. Did you change boot device to "try-ethernet-once-then-nand" and boot protocol to "dhcp"?
by mkx
Sun Oct 07, 2018 7:54 pm
Forum: Beginner Basics
Topic: Problem with DHCP server and virtual AP
Replies: 6
Views: 844

Re: Problem with DHCP server and virtual AP

Are you using different address pool for guest wifi?
by mkx
Sun Oct 07, 2018 7:51 pm
Forum: Beginner Basics
Topic: switch on hEX Gr2
Replies: 7
Views: 551

Re: switch on hEX Gr2

Any firewall rules?
by mkx
Sun Oct 07, 2018 2:30 pm
Forum: Beginner Basics
Topic: switch on hEX Gr2
Replies: 7
Views: 551

Re: switch on hEX Gr2

Bind DHCP client to bridge.
by mkx
Sat Oct 06, 2018 6:39 pm
Forum: Beginner Basics
Topic: Question about virtual AP bridge and NAT
Replies: 7
Views: 450

Re: Question about virtual AP bridge and NAT

There are a few chains in the firewall, the most important two are input and forward: chain=input rules govern connections to router itself. So use of chain=input to prevent LAN devices from connecting router's http service is correct chain=forward rules govern connections to other destinations wher...
by mkx
Sat Oct 06, 2018 6:24 pm
Forum: RouterBOARD hardware
Topic: RB4011 - Poll - ONE thing you'd change
Replies: 15
Views: 4161

Re: RB4011 - Poll - ONE thing you'd change

@doneware: if the device is intended as router, then it has too many interfaces for it's CPU power ... I strongly doubt it is capable of routing 20Gbps ...which is what one could assume seeing its 10 1Gbps RJ45 ports and a SFP+ port. As a router (even as s router on a stick) it would need 5 ethrr po...
by mkx
Sat Oct 06, 2018 5:58 pm
Forum: Announcements
Topic: v6.42.9 [long-term] is released!
Replies: 119
Views: 26020

Re: v6.42.9 [long-term] is released!

My guess, based on my reputably bad memory, is as follows: by default there used to be single bridge present even with ROS 6.40 and earlier, if nothing else it would bridge the master port and wireless interface. Or, in case of 2011, it would bridge both master ports. So I guess upgrade procedure ac...
by mkx
Sat Oct 06, 2018 5:50 pm
Forum: Beginner Basics
Topic: I broke my network and can't access Webfig. Please help
Replies: 5
Views: 864

Re: I broke my network and can't access Webfig. Please help

It might be that there's some device in your network which assumes IP address 192.168.88.1 when it can't obtain address via DHCP. So if you are unable to use winbox with MAC connection, you may try to connect your laptop wired directly to a LAN port of RB750 while the rest of LAN is disconnected fro...
by mkx
Sat Oct 06, 2018 5:41 pm
Forum: Beginner Basics
Topic: Question about virtual AP bridge and NAT
Replies: 7
Views: 450

Re: Question about virtual AP bridge and NAT

Your firewall config features some rules which I guess you intended to prevent clients in different subnets from connecting each other (the ones with src-address=subnet1/24 dst-address=subnet2/24). They are not doing that, they are preventing those clients from connecting to router (note chain=input...
by mkx
Sat Oct 06, 2018 2:45 pm
Forum: Beginner Basics
Topic: wAP-LTE tunneling behind NAT LTE
Replies: 2
Views: 237

Re: wAP-LTE tunneling behind NAT LTE

Many MNOs don't allow connections from internet to mobile devices even if mobile devices get real public IP addresses. So it's better to have "mobile device", wAP LTE in your case, to initiate creation of tunneled connection. It us much easier to handle possible changes of IP address in case of disc...
by mkx
Sat Oct 06, 2018 2:39 pm
Forum: Beginner Basics
Topic: Question about virtual AP bridge and NAT
Replies: 7
Views: 450

Re: Question about virtual AP bridge and NAT

Output of /interface bridge print, /interface bridge export and /ip firewall export would help us to understand your current setup.
by mkx
Sat Oct 06, 2018 11:41 am
Forum: Wireless Networking
Topic: No internet via Wifi after restart of router
Replies: 3
Views: 448

Re: No internet via Wifi after restart of router

WiFi on your wap is not statically configured but it seems to be managed by CapsMan. Is the wap owned and managed by your ISP? Check output of command /interface print to see if wlan is configured dynamically. If wap is managed by your ISP, then you'll have to deal with them. If wap is your responsi...
by mkx
Sat Oct 06, 2018 11:14 am
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 39002

Re: v6.43.1 [stable] and v6.43.2 [stable] are released!

As I noted memory usage on my hAP ac2 is stable and I don't have VLAN filtering enabled (I'm dealing with VLANs on switch chip).
by mkx
Fri Oct 05, 2018 10:33 pm
Forum: General
Topic: Bridge and virtual AP - vlan filtering or use tag & VLAN ID
Replies: 4
Views: 777

Re: Bridge and virtual AP - vlan filtering or use tag & VLAN ID

There are two ways of dealing with VLANs: traditional one (still works and has some benefits over the other one) where you set VLAN stuff strictly on hardware (e.g. /interface ethernet switch config subtree and on /interface wireless) and the new one where you set things on bridge (with vlan-filteri...
by mkx
Fri Oct 05, 2018 10:11 pm
Forum: General
Topic: RB951G-2HnD bricks on each update after 6.43
Replies: 3
Views: 449

Re: RB951G-2HnD bricks on each update after 6.43

My RB951G is happily running on 6.43.1. Changelog doesn't show anything significant new on 6.43.2 compared to 6.43.1, so it's hard to tell if it's 6.43.2 that bricks RB951G or is it something else ...
by mkx
Fri Oct 05, 2018 7:09 pm
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 39002

Re: v6.43.1 [stable] and v6.43.2 [stable] are released!

My experience on hAP ac2: very unstable, plenty of watchdog reboots (most of them due to ping timeouts, pinged address is linux server on LAN). For me instability is regression from 6.42.9. I take my words back. Instability is not a regression from 6.42.9, my hAP ac2 was not completely stable while...
by mkx
Fri Oct 05, 2018 6:16 pm
Forum: General
Topic: HAP AC2 Auto negotioation
Replies: 4
Views: 590

Re: HAP AC2 Auto negotioation

Did you try using another patch cable?
You can run Cable Test[/u] from your RB ...
by mkx
Fri Oct 05, 2018 6:07 pm
Forum: General
Topic: Bridge and virtual AP - vlan filtering or use tag & VLAN ID
Replies: 4
Views: 777

Re: Bridge and virtual AP - vlan filtering or use tag & VLAN ID

Configuration with multiple bridges in scenarios like yours is "old school", which predates VLAN filtering on (CPU-run) bridge (introduced with ROS 6.41). If you configure things right, then using single bridge with vlan-filtering=yes is as safe as using any other VLAN-aware switch.
by mkx
Fri Oct 05, 2018 3:12 pm
Forum: General
Topic: WebService crashes periodically
Replies: 2
Views: 371

Re: WebService crashes periodically

From change log for release 6.43:
*) webfig - fixed www service becoming unresponsive;
Very same line in change log for release 6.42.9.
by mkx
Fri Oct 05, 2018 2:53 pm
Forum: General
Topic: upgrade to stable [solved]
Replies: 3
Views: 467

Re: upgrade to stable

Just to add some info to what @AlainCasault wrote: in a version series, RC is lower than "production". E.g. in 6.43 series rc66 is lower than 6.43 (without RC) or 6.43.2 and you can normally upgrade (select "current"/"stable" as package channel and get ROS to upgrade itself). Likewise RC of next rel...
by mkx
Thu Oct 04, 2018 10:59 pm
Forum: Beginner Basics
Topic: hAP ac2 no files, but almost no free space available
Replies: 5
Views: 985

Re: hAP ac2 no files, but almost no free space available

Actually I'm a believer in simplicity ... in a sense that the best gadget is such that performs only a few functions, but those to perfection. So I'll invest in a few hundred GB of SSD and put it into dedicated file/DLNA server ... and voila, I won't miss more space on my 'ac2 any more. I don't need...
by mkx
Thu Oct 04, 2018 2:31 pm
Forum: RouterBOARD hardware
Topic: RB951 Wifi slow but normal with cable [SOLVED]
Replies: 5
Views: 616

Re: RB951 Wifi slow but normal with cable [SOLVED]

How's intereference situation? Mikrotik2 has fixed channel while Mikrotik has it set to auto.... WiFi settings on both APs are completely different (some of them might actually affect transmitted power). So why don't you just copy settings from Mikrotik2 over to Mikrotik1? If signal from both APs ov...
by mkx
Thu Oct 04, 2018 12:16 pm
Forum: RouterBOARD hardware
Topic: RB951 Wifi slow but normal with cable [SOLVED]
Replies: 5
Views: 616

Re: RB951 Wifi slow but normal with cable [SOLVED]

Are both of your mikrotiks same model? If yes, can you compare ouptut of /interface wireless export between both of them to check if thare are some differences in how WiFi is set-up on both. One thing I'd change in your setup is tx-power-mode=all-rates-fixed ... this typically doesn't work great at ...
by mkx
Wed Oct 03, 2018 11:20 pm
Forum: Wireless Networking
Topic: hap ac achievable wifi speed?
Replies: 28
Views: 2279

Re: hap ac achievable wifi speed?

Did you fiddle with tx power settings on routerboard?
by mkx
Wed Oct 03, 2018 11:16 pm
Forum: RouterBOARD hardware
Topic: Powering a FiberBox
Replies: 5
Views: 537

Re: Powering a FiberBox

Check here about power plug dimensions.
by mkx
Wed Oct 03, 2018 10:48 pm
Forum: Wireless Networking
Topic: wAP LTE kit lock to a network
Replies: 4
Views: 1285

Re: wAP LTE kit lock to a network

OP is taking about locking on specific PLMN. Similar to roaming abroad when (possibly) all networks are allowed but one is for some reason preferred over others and modem has to be forced to register to that particular network.
by mkx
Wed Oct 03, 2018 10:33 pm
Forum: RouterBOARD hardware
Topic: Powering a FiberBox
Replies: 5
Views: 537

Re: Powering a FiberBox

How exactly would you do PoE over fibre (I've never seen PoE-capable RJ45 SFP modules)? Last time I checked, glass was a pretty good insulator. Other than that, pull a two-wire cable (with decent copper core cross-section) and use 24V or 28V power supply. I would assume you put a copper POE port in...
by mkx
Wed Oct 03, 2018 10:22 pm
Forum: RouterBOARD hardware
Topic: Groove 52 little reach vs Nanostation Loco M2
Replies: 9
Views: 805

Re: Groove 52 little reach vs Nanostation Loco M2

4.5 ° vertical beam width is very narrow. It translates to around 16m of height at 200m distance. So it's really important to mount it precisely vertical if surrounding area is flat. If it's not, mount it tilted so that antenna is perpendicular to the surrounding in general. Signal strength drops qu...
by mkx
Wed Oct 03, 2018 9:52 pm
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 39002

Re: v6.43.1 [stable] and v6.43.2 [stable] are released!

My experience on hAP ac2: very unstable, plenty of watchdog reboots (most of them due to ping timeouts, pinged address is linux server on LAN).
For me instability is regression from 6.42.9.
by mkx
Wed Oct 03, 2018 9:46 pm
Forum: Beginner Basics
Topic: hap lite works fine but not reachable from LAN
Replies: 9
Views: 709

Re: hap lite works fine but not reachable from LAN

@ceroca: actually you've probably answered my question. As @solar77 also indicated, you were using hAP lite as if your LAN was public internet. As such it does not allow any connection coming in from "internet", by default that's ether1 port. You can reconfigure hAP as simple switch/AP without firew...
by mkx
Wed Oct 03, 2018 9:17 pm
Forum: Beginner Basics
Topic: Dual Router - IPTV
Replies: 3
Views: 361

Re: Dual Router - IPTV

You can do it just like you wrote.. remove ether2 from default bridge, create another bridge, add ether1 and ether2 to the new bridge, move DHCP client from ether1 to new bridge and add new bridge to WAN interface list. One of bridges will loose HW offload, depending on amount of traffic between por...
by mkx
Tue Oct 02, 2018 10:07 pm
Forum: RouterBOARD hardware
Topic: Powering a FiberBox
Replies: 5
Views: 537

Re: Powering a FiberBox

How exactly would you do PoE over fibre (I've never seen PoE-capable RJ45 SFP modules)? Last time I checked, glass was a pretty good insulator.

Other than that, pull a two-wire cable (with decent copper core cross-section) and use 24V or 28V power supply.
by mkx
Tue Oct 02, 2018 8:58 pm
Forum: General
Topic: Set up new vlan bridging mechanism, but can't ping devices on my trunk port
Replies: 2
Views: 218

Re: Set up new vlan bridging mechanism, but can't ping devices on my trunk port

What does command ifconfig, executed on linux client, show? It should show 3 active devices, hopefully all of them with non-zero packet count after you've been pinging all of it's addresses.
by mkx
Tue Oct 02, 2018 8:50 pm
Forum: Beginner Basics
Topic: hap lite works fine but not reachable from LAN
Replies: 9
Views: 709

Re: hap lite works fine but not reachable from LAN

When you connect a wireless device to hAP lite (e.g. a smart phone), does it get IP address from correct IP network (192.168.1.x)? Can you connect to hAP lite from wireless devices using webfig?
by mkx
Mon Oct 01, 2018 11:59 pm
Forum: Wireless Networking
Topic: hap ac achievable wifi speed?
Replies: 28
Views: 2279

Re: hap ac achievable wifi speed?

When testing my hAP ac2 I noticed that CPU load is higher during DL than during UL which made my ac2 faster in UL than in DL.
by mkx
Mon Oct 01, 2018 9:41 pm
Forum: General
Topic: Strange problem with bridging
Replies: 9
Views: 824

Re: Strange problem with bridging

If the "thank you" was ironic... It wasn't, I meant it, really. It's always pleasure to read your insightful explanations. I've had my doubts and you actually confirmed them at the end of your post :wink: BTW, yes I do remember Serbo-Croatian, it used to be almost considered one of "native" languag...
by mkx
Mon Oct 01, 2018 9:27 pm
Forum: RouterBOARD hardware
Topic: Groove 52 little reach vs Nanostation Loco M2
Replies: 9
Views: 805

Re: Groove 52 little reach vs Nanostation Loco M2

Ideally place antenna so that majority of client devices will stay inside main beam most of time. As we don't know type of your antenna nor we know distribution of client devices so it's hard to give any serious recommendation.
by mkx
Mon Oct 01, 2018 7:15 pm
Forum: General
Topic: Strange problem with bridging
Replies: 9
Views: 824

Re: Strange problem with bridging

Thank you sindy. I fully understand the need for proxy arp in case of /32 "subnets" (myself I grew up when analogue modem dial-up using SLIP and PPP was a norm and using proxy arp on dial-in server was way to go). But I've never stumbled upon "cisco recomended" use of it ... at least I didn't notice...
by mkx
Mon Oct 01, 2018 5:07 pm
Forum: Announcements
Topic: v6.42.9 [long-term] is released!
Replies: 119
Views: 26020

Re: v6.42.9 [long-term] is released!

@Chupaka and @pe1chl: the way 6.40 config is converted, there's no sign of bridge vlan-filtering. Bridge acts as a dummy (VLAN unaware) switch. VLAN filtering is done by switch chip in hardware. Its only after you start configuring VLANs on bridge (transforming it to VLAN-aware switch) when yiu loos...
by mkx
Mon Oct 01, 2018 4:56 pm
Forum: General
Topic: Strange problem with bridging
Replies: 9
Views: 824

Re: Strange problem with bridging

Thanks for the link. The example is false, IMO proxy-arp there is abused to fix mistake in L3 config. So I'm still eager to find out why would I want to have proxy-arp on bridge.
by mkx
Mon Oct 01, 2018 4:30 pm
Forum: Announcements
Topic: v6.42.9 [long-term] is released!
Replies: 119
Views: 26020

Re: v6.42.9 [long-term] is released!

But when an existing configuration with master-port with VLAN subinterfaces on the master-port is converted to a single bridge with VLAN subinterfaces on the bridge and VLAN filtering, the result is that it is no longer hw-accelerated. This is simply not true, at least not on RB951G. In old config,...
by mkx
Sun Sep 30, 2018 7:31 pm
Forum: General
Topic: Strange problem with bridging
Replies: 9
Views: 824

Re: Strange problem with bridging

Other than that, when an interface is a slave of another interface, it cannot have its own IP configuration. So in your case, the dhcp-client on ether1 should not be there ...
... and the same goes for DHCP client on sfp1.

Out of curiosity: why would I want to have arp=proxy-arp on the bridge?
by mkx
Sun Sep 30, 2018 6:07 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88791

Re: Winbox vulnerability: please upgrade

There are two wireless packages installed. Try to uninstall wireless-cm2 (this might not be possible if it's part of bundle). Other than that, I'd try to upgrade first to 6.40.9 (you might be able to perform that without downloading package, change package channel to bugfix only ) ... that's the las...
by mkx
Sun Sep 30, 2018 3:45 pm
Forum: Wireless Networking
Topic: hap ac achievable wifi speed?
Replies: 28
Views: 2279

Re: hap ac achievable wifi speed?

When you have an urge to use WiFi around a corner it's better to use 2.4GHz band (if you don't use it already). That highly depends on interference from neighbours' APs of course. My RB951G, hidden inside a closet, behind a brick wall (or around two corners if that signal actually travels through th...
by mkx
Sun Sep 30, 2018 3:41 pm
Forum: General
Topic: Problem with Mikrotik WAP
Replies: 1
Views: 168

Re: Problem with Mikrotik WAP

Post configuration so we can have a look.
by mkx
Sun Sep 30, 2018 3:28 pm
Forum: Wireless Networking
Topic: hap ac achievable wifi speed?
Replies: 28
Views: 2279

Re: hap ac achievable wifi speed?

is there anything i can do to improve reception out of ideal conditions? i read increasing tx power sometimes works, but mostly only over-stresses the transciever chip... i also don't want to move mt under my couch. When using 5GHz band (and higher), LOS gets quite important. Brick wall penetration...
by mkx
Sun Sep 30, 2018 11:39 am
Forum: Wireless Networking
Topic: hap ac achievable wifi speed?
Replies: 28
Views: 2279

Re: hap ac achievable wifi speed?

How close to hAP ac is client? Too close (e.g. less than say 2 metres without any obstacles in between) degrades service as well.
by mkx
Sun Sep 30, 2018 10:35 am
Forum: General
Topic: Infected 6.38.5 Clients Upgrade fails to load
Replies: 7
Views: 687

Re: Infected 6.38.5 Clients Upgrade fails to load

Don't post same issue multiple times in different sections of this forum.
by mkx
Sun Sep 30, 2018 10:24 am
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88791

Re: Winbox vulnerability: please upgrade

Verify that uploaded npk file is intended for correct platform.

Check the list of installed packages. If there's a package listed more than once, upgrade won't succeed and the only remedy is to perform netinstall.
by mkx
Sat Sep 29, 2018 8:09 pm
Forum: General
Topic: Firewall Questions
Replies: 8
Views: 898

Re: Firewall Questions

While I like Sob's way I still see a reason to implement black listing in case when there's a service exposed to internet. If one can construct a list of likely attackers, then one might block access to otherwise exposed service. Example (not entirely realistic): I'm running a public http and https ...
by mkx
Fri Sep 28, 2018 10:12 pm
Forum: Beginner Basics
Topic: hAP ac2 no files, but almost no free space available
Replies: 5
Views: 985

Re: hAP ac2 no files, but almost no free space available

That's quite normal when non-volatile storage of a computer is only 16MB ... what you see under /file is not the whole disk, it's just the part you can access. On my hAP ac2 (ROS 6.43.1) it shows 3008kiB free (that's less than 3MB), so you actually have more free space than I have. To whom can I com...
by mkx
Fri Sep 28, 2018 10:03 pm
Forum: RouterBOARD hardware
Topic: I thought my router died today
Replies: 3
Views: 525

Re: I thought my router died today

Could be that NAND storage died ... what does /system resource print show at bad-blocks?
by mkx
Fri Sep 28, 2018 7:12 pm
Forum: RouterBOARD hardware
Topic: Hardware offload on sfp port in hEX S mmips
Replies: 11
Views: 1535

Re: Hardware offload on sfp port in hEX S mmips

I don't think there's a specific limitation that there's a dedicated core which takes care of SFP port. Data flow through interface is more or less serial, there are buffers and queues (if there's QoS in play). So I guess the benefit of multi-threaded process dealing with single interface is nowhere...
by mkx
Fri Sep 28, 2018 5:55 pm
Forum: SwOS
Topic: Lost access
Replies: 1
Views: 675

Re: Lost access

Can't you perform factory reset according to instructions from wiki?
by mkx
Fri Sep 28, 2018 4:18 pm
Forum: Beginner Basics
Topic: Replacing ethernet with wireless connection [SOLVED]
Replies: 4
Views: 496

Re: Replacing ethernet with wireless connection [SOLVED]

1st question: yes ... to have different settings RB would need second radio. 2nd question: probably not. Both wlan APs have indeed different MAC addresses, but that would be all. Clients don't expect different passwords on different APs that share SSID ... or else roaming between APs would not reall...
by mkx
Fri Sep 28, 2018 3:31 pm
Forum: Beginner Basics
Topic: access different subnet from wan interface
Replies: 10
Views: 677

Re: access different subnet from wan interface

But how exactly does masquerade look like? If you didn't have masquerade enabled, then you'd gave to add routes to reach local lans on the other router. E.g. #mikrotik-1: /ip route add dst-address=192.168.20.0/24 gateway=192.168.1.20 # # mikrotik-2: /ip route add dst-address=192.168.10.1/24 gateway=...
by mkx
Fri Sep 28, 2018 12:08 am
Forum: Beginner Basics
Topic: access different subnet from wan interface
Replies: 10
Views: 677

Re: access different subnet from wan interface

Next thing to check: that NAT rule on mikrotik-1 ... how exactly does it look like?
by mkx
Thu Sep 27, 2018 11:43 pm
Forum: Beginner Basics
Topic: access different subnet from wan interface
Replies: 10
Views: 677

Re: access different subnet from wan interface

No, there's implicit "accept all" at the end of (now empty) firewall rule list. Which kind of administration tool are you trying to use (winbox, webfig, ssh, ...) and are you trying to connect using IP address (supposedly 192.168.1.20)? You might want to check /ip services on mikrotik-2 to verify th...
by mkx
Thu Sep 27, 2018 11:26 pm
Forum: Beginner Basics
Topic: access different subnet from wan interface
Replies: 10
Views: 677

Re: access different subnet from wan interface

Did you adjust firewall settings on mikrotik-2? Default firewall does not allow any connectivity initiated from WAN interface and connections from mikrotik-1 are considered WAN connections by mikrotik-2 ...
by mkx
Thu Sep 27, 2018 4:25 pm
Forum: General
Topic: strange error on mikrotik crs 326
Replies: 3
Views: 299

Re: strange error on mikrotik crs 326

Are ethernet ports members of a bridge? If yes, what's MAC address of a bridge and is it perhaps same as MAC address of ether5?
by mkx
Thu Sep 27, 2018 4:19 pm
Forum: General
Topic: Switch can't get IP address [SOLVED]
Replies: 7
Views: 517

Re: Switch can't get IP address [SOLVED]

RB's CPU is yet another port on switch chip. As your management connections are actually answered by services running on CPU, you need to explicitly configure all needed (VLANs, ...) for that as well.
by mkx
Thu Sep 27, 2018 4:16 pm
Forum: RouterBOARD hardware
Topic: Groove 52 little reach vs Nanostation Loco M2
Replies: 9
Views: 805

Re: Groove 52 little reach vs Nanostation Loco M2

Frequency 2ghz / bgn, Protocol: 802.11, antenna gain: 15dbi, txpower: all fixes rated 23dbm. The use is to distribute to wireless equipment: cell phones, laptops, tablets. If you don't fear the "radio police", then set antenna gain to low value, such as 0 or 3 dBi. Try to set txpower=card-rates ......
by mkx
Thu Sep 27, 2018 3:41 pm
Forum: General
Topic: dhcp1: failed to give out ip address pool <dhcp_pool1> is empty [SOLVED]
Replies: 7
Views: 2320

Re: dhcp1: failed to give out ip address pool <dhcp_pool1> is empty [SOLVED]

@CPU4U: you can see shorter DHCP lease kicking in in your screenshot. There's a log entry "hotspot info debug" saying an user logged out due to lost DHCP lease. 5 seconds earlier DHCP lease was de-assigned and device did not try to re-new the lease. There are many devices which promptly re-new the l...
by mkx
Thu Sep 27, 2018 3:30 pm
Forum: General
Topic: How to create two vlan and two dhcp servers
Replies: 2
Views: 303

Re: How to create two vlan and two dhcp servers

In addition to steps, described by @xvo, perform also this step:
0) remove port2 and port3 from any bridge

If you want to have those two ports members of bridge (e.g. to switch untagged traffic between these two ports and rest of your RB), then setup is slightly more complex.
by mkx
Thu Sep 27, 2018 7:16 am
Forum: General
Topic: Is mikrotik a good choice?
Replies: 56
Views: 3762

Re: Is mikrotik a good choice?

@mkx, is that issue related to egress untagging of a VLAN tag or of the proprietary tag bearing the Ethernet interface address which the CPU uses to tell the switch which egress port to use? The former. I know it's unusual setup but it I'm using such setup (and not the only one, MT support wrote th...
by mkx
Wed Sep 26, 2018 9:47 pm
Forum: General
Topic: Is mikrotik a good choice?
Replies: 56
Views: 3762

Re: Is mikrotik a good choice?

the mikrotik has to be configured with a V-Lan (835) on the Wan port and with a ppoe connection Just a word of caution: according to MT support, switch chip embedded in IPQ4xxx (the SoC used in hAP ac2) features a bug in scenario which includes pppoe-client run on top of vlan interface, PPPoE disco...
by mkx
Wed Sep 26, 2018 9:09 pm
Forum: Beginner Basics
Topic: Replacing ethernet with wireless connection [SOLVED]
Replies: 4
Views: 496

Re: Replacing ethernet with wireless connection [SOLVED]

There are basically two ways: the easy way gives separate subnet on MK1 and devices using MK1 wireless are protected from devices hooked off MK0 same as from internet (including firewall, NAT, etc.). The hard way will make devices using MK1 belong to same subnet as devices off MK0. Rough guide for t...
by mkx
Wed Sep 26, 2018 8:45 pm
Forum: Beginner Basics
Topic: Help Microtik
Replies: 5
Views: 547

Re: Help Microtik

Most probably your router had been compromised. I'd say you need to read some Wiki and some threads on this forum. Later get your router back in good condition. It's hardly worth trying to fix the setup, it's better to start off with factory default settings and add specifgic stuff you need. Do your...
by mkx
Wed Sep 26, 2018 4:33 pm
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 39002

Re: v6.43.1 [stable] and v6.43.2 [stable] is released!

I was hoping to see actual configuration ... better yet, post output of /inteface bridge print, /interface bridge port print and /interface ethernet print ... it would be interesting to see where MAC of both bridges comes from.
by mkx
Wed Sep 26, 2018 3:12 pm
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 39002

Re: v6.43.1 [stable] and v6.43.2 [stable] is released!

I found a strange behavior about bridges - might be only WinBox issue but still...
Can you post output of command /interface bridge export? Just to check if there's something weird.
by mkx
Wed Sep 26, 2018 9:18 am
Forum: General
Topic: Linux hosts not being VLAN tagged properly since v6.41
Replies: 3
Views: 250

Re: Linux hosts not being VLAN tagged properly since v6.41

An idea: try to use wireshark on one of dual-boot machines and observe traffic when you try to ping it from one of working machines. Compare traces taken in both OS-es to see some difference. Most probably there won't be any difference, I've yet to see L2 box to behave differently towards same clien...
by mkx
Wed Sep 26, 2018 9:09 am
Forum: Beginner Basics
Topic: New HaP lite ac can not access an http site
Replies: 1
Views: 171

Re: New HaP lite ac can not access an http site

Everybody has plenty of ideas. Almost all of them most definitively don't apply to your case, but we don't know which ones might apply as you did not provide any specifics about your problem ... e.g. export of your hAP's config, details about LAN schematic and details about particular misbehaviour.
by mkx
Tue Sep 25, 2018 11:13 pm
Forum: Beginner Basics
Topic: Mikrotik Repeater No Internet
Replies: 5
Views: 993

Re: Mikrotik Repeater No Internet

Post your current config and we'll try to push forward.
by mkx
Tue Sep 25, 2018 11:10 pm
Forum: Beginner Basics
Topic: Block HTTPS [SOLVED]
Replies: 3
Views: 601

Re: Block HTTPS [SOLVED]

Instead of using action=drop you could use action=reject ... so browser would not have to wait for connection to timeout, but would get rejected connection immediately. I guess that message, generated by browser, might reflect that distinction.
by mkx
Tue Sep 25, 2018 10:27 pm
Forum: General
Topic: Linux hosts not being VLAN tagged properly since v6.41
Replies: 3
Views: 250

Re: Linux hosts not being VLAN tagged properly since v6.41

Not sure it affects linux hosts, but: any particular reason for having arp=proxy-arp on vlan20 interface?

Apart from that, you've some remnants of trying to convert to bridge vlan style (/interface bridge vlan section ... it doesn't do any harm, but it could make some confusion).
by mkx
Tue Sep 25, 2018 9:11 pm
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 39002

Re: v6.43.1 [stable] and v6.43.2 [stable] is released!

Since ROS 6.43 there are entries setting ethernet speed to 100Mbps for every cooper not auto negotiated interface on every MT device. Is it normal? ..... set [ find default-name=ether5 ] speed=100Mbps set [ find default-name=ether6 ] speed=100Mbps set [ find default-name=ether7 ] speed=100Mbps .......
by mkx
Tue Sep 25, 2018 7:27 am
Forum: General
Topic: VLAN switch fallback or secure [SOLVED]
Replies: 12
Views: 1253

Re: VLAN switch fallback or secure [SOLVED]

Cureent ROS versions allow dealing with VLANs in two ways: nww way using bridge vlan-filtering and old way with switch chip settings. You can (for now, no ETA) safely continue to use old way after upgrading to current ROS. AFAIK switch chip setup is not translated to bridge vlan-filtering (yet) on u...
by mkx
Tue Sep 25, 2018 7:19 am
Forum: General
Topic: Packet sniffer- not capturing traffic between ports 2 and 3 [SOLVED]
Replies: 2
Views: 290

Re: Packet sniffer- not capturing traffic between ports 2 and 3 [SOLVED]

As long as you have HW offload active, traffic between two ports of same switch chip will not be seen by CPU and hence not by packet sniffer. When you disable HW offload for "sniffed" port, traffic to/from should start passing CPU and you'll be able to sniff it. I'm not sure whether HW offload shoul...
by mkx
Tue Sep 25, 2018 7:11 am
Forum: Beginner Basics
Topic: Mikrotik Repeater No Internet
Replies: 5
Views: 993

Re: Mikrotik Repeater No Internet

There are a few things wrong: Remove wlan1 from bridge-local Bind dhcp-client to wlan1 (not bridge-local) set local address (192.168.88.1) to bridge-local (not ether2-master) bind dhcp-server to bridge-local fix your firewall (your WAN interface is wlan1 and there's nothing protecting you from WAN i...
by mkx
Mon Sep 24, 2018 10:34 pm
Forum: General
Topic: Firmware vs RouterOS [SOLVED]
Replies: 5
Views: 619

Re: Firmware vs RouterOS [SOLVED]

Yes, matching versions are fine.
by mkx
Mon Sep 24, 2018 7:25 pm
Forum: RouterBOARD hardware
Topic: Bridge split-horizon vs hw-offload
Replies: 5
Views: 893

Re: Bridge split-horizon vs hw-offload

...I thought VLAN was something basic that should be hw-offloaded on all products ...
So did I :wink:
by mkx
Mon Sep 24, 2018 5:00 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 371
Views: 70405

Re: RB4011

There's one big difference between doing VLAN switching in switch chip and doing VLAN "switching" on bridge: misery of datapath between switch chip and CPU. If switching is done within switch chip, it can be up to 5Gbps (sum of all ports' throughput) ... while if it's done by CPU, interconnect limit...
by mkx
Mon Sep 24, 2018 4:22 pm
Forum: Beginner Basics
Topic: no such item when disable/enable peer from terminal
Replies: 1
Views: 166

Re: no such item when disable/enable peer from terminal

Numbers to which various set commands refer don't exist per-se. You have to "create" them before using them, e.g. by executing command /ip ipsec policy print ... probably you'll have policies #0 and #1.
by mkx
Mon Sep 24, 2018 10:06 am
Forum: General
Topic: Email via Gmail no longer working since Aug 22 [SOLVED]
Replies: 9
Views: 1243

Re: Email via Gmail no longer working since Aug 22 [SOLVED]

@Samot: in case you missed the point of solution of OPs problem: when setting up tool mail, one has to use specifically FQDN and not IP. Both are, per your explanation, URNs ... the first one solves problem and other does not.
by mkx
Sun Sep 23, 2018 8:28 pm
Forum: General
Topic: Log File Dates & Times seem to be incorrect
Replies: 6
Views: 465

Re: Log File Dates & Times seem to be incorrect

Why do you not send your log entry directly to a server using Syslog receiver? Should be one step less, instead of sending saved logs. OP is dealing with logs directly on RB itself. And I was just saying that mangled timestamps (current day logs shown without date part) are the way in which /log pr...
by mkx
Sun Sep 23, 2018 6:40 pm
Forum: General
Topic: Log File Dates & Times seem to be incorrect
Replies: 6
Views: 465

Re: Log File Dates & Times seem to be incorrect

Regarding lack of date part: it's how /log print formats it. If log is written to disk and you fetch log file to some PC, you can open it in text editor. There log entries all have full date and time. Other than that, I would like to see date formatting in neutral way as well ... e.g. according to I...
by mkx
Sun Sep 23, 2018 4:09 pm
Forum: General
Topic: dhcp1: failed to give out ip address pool <dhcp_pool1> is empty [SOLVED]
Replies: 7
Views: 2320

Re: dhcp1: failed to give out ip address pool <dhcp_pool1> is empty [SOLVED]

As you're getting pool empty after roughly 24 hours, I'd decrease lease time to something like 3 hours. In my setups, I keep lease time around 1 hour or below on subnets where I expect most of devices "to come and go". On subnets with more persistent devices (e.g. where most devices are wired), I se...
by mkx
Sun Sep 23, 2018 1:12 pm
Forum: RouterBOARD hardware
Topic: Bridge split-horizon vs hw-offload
Replies: 5
Views: 893

Re: Bridge split-horizon vs hw-offload

I use bridge VLAN filtering, and hw-offload works fine here on CRS328-24P-4S+ with ROS 6.42.7 and now 6.43.2 - as long as I don't try to isolate ports by setting horizon. CRS series 300 is AFAIK currently only HW that does HW offload non-trivial tasks. HW offload on all other device types is curren...
by mkx
Sun Sep 23, 2018 1:05 pm
Forum: Beginner Basics
Topic: Accedss from LAN to LAN
Replies: 8
Views: 685

Re: Accedss from LAN to LAN

Either there's lots of config missing (all the wired interface configuration and local IP addressing) or you have another router in your LAN which should handle connectivity between your two LAN subnets.
If it's the former, paste complete export of configuration.
by mkx
Sun Sep 23, 2018 12:46 pm
Forum: General
Topic: Email via Gmail no longer working since Aug 22 [SOLVED]
Replies: 9
Views: 1243

Re: Email via Gmail no longer working since Aug 22 [SOLVED]

/tool e-mail set address="smtp.gmail.com" haha, works perfectly. I honestly didnt think to just try using the URL, I assumed it was still IP only, as per the wiki on it. thanks. FYI, smtp.gmail.com used in @nescafe202's code is not URL , it's FQDN . Try to be precise, everybody will understand you ...
by mkx
Sun Sep 23, 2018 12:35 pm
Forum: General
Topic: dhcp1: failed to give out ip address pool <dhcp_pool1> is empty [SOLVED]
Replies: 7
Views: 2320

Re: dhcp1: failed to give out ip address pool <dhcp_pool1> is empty [SOLVED]

What is setting of lease-time on DHCP server? Default value is 10 minutes which might be the right value for busy hotspot with many clients connecting just for short period of time. Shorter time means more lease renewals for active clients but also means shorter time when non-active client occupies ...
by mkx
Sun Sep 23, 2018 12:12 pm
Forum: Beginner Basics
Topic: Accedss from LAN to LAN
Replies: 8
Views: 685

Re: Accedss from LAN to LAN

Post complete configuration of your routerboard so we can check for any mistakes or omissions. You can get it using command /export hide-sensitive and paste it here inside code environment. You may want to hide sensitive data (such as public IP address) that might still be present in the export.
by mkx
Sat Sep 22, 2018 10:16 pm
Forum: RouterBOARD hardware
Topic: Bridge split-horizon vs hw-offload
Replies: 5
Views: 893

Re: Bridge split-horizon vs hw-offload

Some switch chips have a feature to deal with VLAN tags and VLAN-aware switching. Bridge vlan-filtering is not HW-offloaded simply by using this functionality ...
by mkx
Sat Sep 22, 2018 9:03 pm
Forum: Beginner Basics
Topic: Routing on Hyper-V
Replies: 2
Views: 304

Re: Routing on Hyper-V

Did you add route to access your VM network on FritzBox?

Something like (linux style)
route add -net 192.168.101.0 netmask 255.255.255.0 gw 192.168.100.1
Without that machines in your home lan (including FritzBox) don't know how to send replies back to macines in VM network.
by mkx
Sat Sep 22, 2018 12:50 pm
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 39002

Re: v6.43.1 [stable] and v6.43.2 [stable] is released!

While generally I agree with pe1chl I still think that vast majority of things that switch chips are capable of doing should be HW offloaded before "legacy" way of configuring them gets murdered . Problem is that as soon one configures one simple thing which is not HW offloaded, all HW offload stops...
by mkx
Sat Sep 22, 2018 11:13 am
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 39002

Re: v6.43.1 [stable] and v6.43.2 [stable] is released!

What we need is a version that can auto-convert existing configurations that use a combination of master-port, VLAN subinterfaces on that master port, and switch configuration for tagged/untagged VLAN on the ports, into a new configuation with a single bridge with VLAN filtering and full hardware a...
by mkx
Fri Sep 21, 2018 11:01 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 371
Views: 70405

Re: RB4011

I'm starting to think that the only reason for RB4011 to have that SFP+ is that MT can claim it offers "1733 Mbps data rate" (see top most banner on all forum pages). One could hardly claim that if all wired ports were 1Gbps. That is related to wifi performance as it has 4 chains for 5GHz radio. In...
by mkx
Fri Sep 21, 2018 10:32 pm
Forum: Wireless Networking
Topic: Wireless Wire MCS direction?
Replies: 6
Views: 630

Re: Wireless Wire MCS direction?

On the other hand, if the example in manual is correct, then MCS is displayed among other RX-related stuff, TX-related stuff is groupped at the end of printout.
by mkx
Fri Sep 21, 2018 10:00 pm
Forum: Wireless Networking
Topic: Wireless Wire MCS direction?
Replies: 6
Views: 630

Re: Wireless Wire MCS direction?

Most of us, forum members, don't have wireless wire devices at hand. If you post some screen shots with said readings, we can speculate further. My point is: if one device only reports one MCS, then it might be only one direction ... and slightly more meaningful (to me at least) would be to report M...
by mkx
Fri Sep 21, 2018 9:51 pm
Forum: General
Topic: Firmware vs RouterOS [SOLVED]
Replies: 5
Views: 619

Re: Firmware vs RouterOS [SOLVED]

Essentially when you update ROS, firmware update file is prepared for that device ... but you need to execute firmware update manually.
by mkx
Fri Sep 21, 2018 9:47 pm
Forum: General
Topic: routerOS licence ? [SOLVED]
Replies: 7
Views: 628

Re: routerOS licence ? [SOLVED]

x86 is for setting a pc for being router etc? Yes. It is not that popular any more because it lacks drivers for newer hardware (NICs, disks, ...). Nowadays it's more popular to run CHR, which is essentially x86, but running as VM letting hypervisor to deal with bare hardware and utilizing virtualiz...
by mkx
Fri Sep 21, 2018 9:34 pm
Forum: General
Topic: Can't Log in After Upgrade
Replies: 21
Views: 4324

Re: Can't Log in After Upgrade

Suggestion by @spacemind might not be the best. I'd start from default setup, which has decent firewall rules (20 or so, definitely much less than 100500) that protect RB from attacks originating from internet. And then proceed with adding necessary changes according to needs. Definitely avoid all t...
by mkx
Fri Sep 21, 2018 9:23 pm
Forum: General
Topic: Bridge problems.
Replies: 4
Views: 428

Re: Bridge problems.

A thought: did you set bridge IP address with subnet mask included? I.e. 192.168.1.2/24 ...
Another thing: do you have any route set? Does it stay after you remove eth1 IP address and is it still meaningful?
by mkx
Fri Sep 21, 2018 9:12 pm
Forum: General
Topic: Weird outbound UDP traffic
Replies: 19
Views: 2185

Re: Weird outbound UDP traffic

There are two "levels" of "router reset": reset to default config. Default config on my models has "time zone detect" enabled and according to janisk cloud functionality is used for this. It is debatable whether this should be enabled or not, my vote is NO (my network gear and servers are all set to...
by mkx
Fri Sep 21, 2018 9:05 pm
Forum: Beginner Basics
Topic: VLAN configuration with RB 1100AH en CRS125
Replies: 8
Views: 691

Re: VLAN configuration with RB 1100AH en CRS125

AFAIK in the second config snippet, those vlan interfaces shoud have been created on bridge not on ether2. ... For OP's setup, you don't need to create any VLAN interfaces on the CRS Indeed. Maybe one for management access from the selected VLAN, from names one would assume VLAN ID 200. Or OP can d...
by mkx
Fri Sep 21, 2018 8:53 pm
Forum: Beginner Basics
Topic: VLAN configuration with RB 1100AH en CRS125
Replies: 8
Views: 691

Re: VLAN configuration with RB 1100AH en CRS125

AFAIK in the second config snippet, those vlan interfaces shoud have been created on bridge not on ether2. But that is not stopping the switching. Somehow you have to set all those ports with vlan configuration ... There's a WiKi about VLAN config on CRS1xx/2xx and indeed it is different than on mos...
by mkx
Fri Sep 21, 2018 4:41 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 371
Views: 70405

Re: RB4011

I'm starting to think that the only reason for RB4011 to have that SFP+ is that MT can claim it offers "1733 Mbps data rate" (see top most banner on all forum pages).
One could hardly claim that if all wired ports were 1Gbps.
by mkx
Fri Sep 21, 2018 4:22 pm
Forum: Wireless Networking
Topic: Wireless Wire MCS direction?
Replies: 6
Views: 630

Re: Wireless Wire MCS direction?

It should as it is standardized. Check this table . But which direction? Transmit or receive? Both. If parties don't agree about MCS, connection fails. So RX side can report correct MCS as well. Even though it's TDD, MCS can be different for TX and RX. One example why this can happen is interferenc...
by mkx
Fri Sep 21, 2018 2:38 pm
Forum: Beginner Basics
Topic: VLAN configuration with RB 1100AH en CRS125
Replies: 8
Views: 691

Re: VLAN configuration with RB 1100AH en CRS125

Definitely do it "the old school" way ... that is using /interface ethernet switch configuration section. If you'll do it "the new" way, everything will pass CRS' CPU which will overload both CPU and connection between CPU and switch chip. I don't have CRS125 so I don't know if commands are same as ...
by mkx
Fri Sep 21, 2018 2:15 pm
Forum: Beginner Basics
Topic: Please Help with home/office network
Replies: 4
Views: 590

Re: Please Help with home/office network

If I remember correct, ROS 6.40 still has that master port configuration. Which means port ether5 is part of switch group and nothing you set on ether5 (including VLANs) doesn't really work. My suggestion: upgrade router1 to 6.43.2 and re-apply your current setup. Probability that it all starts to b...
by mkx
Thu Sep 20, 2018 9:34 pm
Forum: Wireless Networking
Topic: Wireless Wire MCS direction?
Replies: 6
Views: 630

Re: Wireless Wire MCS direction?

It should as it is standardized. Check this table.
by mkx
Thu Sep 20, 2018 3:27 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88791

Re: Winbox vulnerability: please upgrade

So, us, professional users of ROS, ...
See how your own position is skewing your point of view? :wink:

Seriously: even being myself a "home user" by all standards I'm with you on this.
by mkx
Thu Sep 20, 2018 3:19 pm
Forum: General
Topic: Weird outbound UDP traffic
Replies: 19
Views: 2185

Re: Weird outbound UDP traffic

Did some magic with PTR
It's time to rock'n'roll! :smile:
by mkx
Thu Sep 20, 2018 3:14 pm
Forum: Announcements
Topic: Winbox vulnerability: please upgrade
Replies: 329
Views: 88791

Re: Winbox vulnerability: please upgrade

Everything outside default protection rules. It should be only warning, nothing else. So, everyone else that does not use the default firewall will get annoying warnings about a supposedly insecure firewall configuration? No, not everybody. Only those who care enough to check their router from time...
by mkx
Thu Sep 20, 2018 2:39 pm
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 39002

Re: v6.43.1 [stable] is released!

Yesterday upgraded two CCRs from 6.41.3 to 6.43.1 in the hotel I had vacation in Greece :) At least, now it's not vulnerable to WinBox user database reading xD Unfortunately, WinBox access is still allowed for every Free WiFi user in the hotel :( Chupaka you seem tired. I would be more than happy t...
by mkx
Thu Sep 20, 2018 12:04 pm
Forum: General
Topic: Multiple IP from same ISP
Replies: 9
Views: 669

Re: Multiple IP form same ISP

@Jotne, couldn't you avoid creating bridges Bridge_P10, Bridge_P11 and Bridge_P12 by binding DHCP clients directly to ether ports 10,11 and 12 respectively?
by mkx
Thu Sep 20, 2018 7:29 am
Forum: Beginner Basics
Topic: DNS issue
Replies: 5
Views: 614

Re: DNS issue

Can you ping any of IPs you entered as upstream DNS servers? Check FW rules for chains output and input ... input should accept at least established and related connections ....
by mkx
Wed Sep 19, 2018 2:48 pm
Forum: Beginner Basics
Topic: Update package not properly downloaded and rebooted.
Replies: 2
Views: 284

Re: Update package not properly downloaded and rebooted.

I'm glad it did.

Next time you might want do the upgrade "by hand". Download upgrade package (npk files) manually from https://mikrotik.com/download, then transfer those files to remote RB - either using scp or winbox or webfig ... and after transfer successfully finishes, reboot the remote RB.
by mkx
Wed Sep 19, 2018 9:37 am
Forum: General
Topic: CRS317 Crashing v6.43
Replies: 3
Views: 552

Re: CRS317 Crashing v6.43

I'm seeing similar behaviour on different device: hAP ac2. Architecture (ARM) is the same though. As I'm using it as router I can't really let it hang until I get by, so I set up watchdog with remote IP to be pinged as well. I'm getting watchdog reboots in any odd hours, so I don't think it correlat...
by mkx
Wed Sep 19, 2018 9:17 am
Forum: Beginner Basics
Topic: How to route between a bridge and a subnet?
Replies: 8
Views: 1668

Re: How to route between a bridge and a subnet?

The rule you posted will do most of work. It doesn't prevent from establishing untracked connections, such as most UDP connections (unless that's handled by some app helper that understands the application behaviour, I don't know if ROS has some). You can verify this by running iperf in UDP mode (ru...
by mkx
Tue Sep 18, 2018 8:43 pm
Forum: General
Topic: NTFS support
Replies: 34
Views: 5709

Re: NTFS support

I vote +1 for making all SOHO features a separate package. I consider SOHO features, stuff like: Quick Set SMB Kid Control Detect Internet Default Firewall UPnP I would even go as far to include 'Cloud' in that list, but many will disagree with me on that one. IMHO there is no need for those in an ...
by mkx
Tue Sep 18, 2018 4:41 pm
Forum: General
Topic: Port 60000 attacks, anyone info on this?
Replies: 11
Views: 1139

Re: Port 60000 attacks, anyone info on this?

... i was just wondering if anyone else is getting probed via this port as it seams im catching this on several locations and not 100% sure what to do about it. Could be, but I don't notice as I have a general drop rule at the end of firewall rules list. It does show increasing number of connection...
by mkx
Tue Sep 18, 2018 4:32 pm
Forum: General
Topic: Port 60000 attacks, anyone info on this?
Replies: 11
Views: 1139

Re: Port 60000 attacks, anyone info on this?

... i was just wondering if anyone else is getting probed via this port as it seams im catching this on several locations and not 100% sure what to do about it. Could be, but I don't notice as I have a general drop rule at the end of firewall rules list. It does show increasing number of connection...
by mkx
Tue Sep 18, 2018 4:26 pm
Forum: General
Topic: Port 60000 attacks, anyone info on this?
Replies: 11
Views: 1139

Re: Port 60000 attacks, anyone info on this?

I don't get it why would anybody want to allow connections to some random port (3389 is as nice random number as any other between 0 and 65536) from internet at large? Your firewall rule is not complete ... attacker can easily change source port to some other and your rule won't catch anything. I g...
by mkx
Tue Sep 18, 2018 3:29 pm
Forum: General
Topic: Port 60000 attacks, anyone info on this?
Replies: 11
Views: 1139

Re: Port 60000 attacks, anyone info on this?

I don't get it why would anybody want to allow connections to some random port (3389 is as nice random number as any other between 0 and 65536) from internet at large? Your firewall rule is not complete ... attacker can easily change source port to some other and your rule won't catch anything. I gu...
by mkx
Tue Sep 18, 2018 2:56 pm
Forum: Beginner Basics
Topic: How to route between a bridge and a subnet?
Replies: 8
Views: 1668

Re: How to route between a bridge and a subnet?

OTOH, you mentioned you could connect both RBs directly bypassing the said switch. Personally I'd go that way I still need the dumb switch to connect the rest of the network; Is it possible to use VLAN only for one subnet and not use it for the other? It surely is possible. As VLANs are a layer jus...
by mkx
Tue Sep 18, 2018 2:15 pm
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 39002

Re: v6.43.1 [stable] is released!

Maybe it's winbox. CLI is fine:
> /system package update check-for-updates 
            channel: current
  installed-version: 6.43.1
     latest-version: 6.43.1
             status: System is already up to date
by mkx
Tue Sep 18, 2018 11:11 am
Forum: Beginner Basics
Topic: How to route between a bridge and a subnet?
Replies: 8
Views: 1668

Re: How to route between a bridge and a subnet?

If the configuration you posted is complete, then at least default route is missing ... without it, devices in 192.168.89.x won't have internet access: /ip route add gateway=192.168.88.1 One reason you're getting invalids on the main router is that devices in 192.168.88.x don't know how to access 19...
by mkx
Tue Sep 18, 2018 10:44 am
Forum: General
Topic: DST-NAT in pair with SRC-NAT?
Replies: 15
Views: 808

Re: DST-NAT in pair with SRC-NAT?

You only need DST-NAT rule: /ip firewall nat add action=dst-nat chain=dstnat in-interface-list=WAN protocol=tcp dst-port=25 to-addresses=<ip address of your SMTP server> The problem would be if your SMTP server in your LAN has dynamic address. My stand is that servers should have static addresses (e...
by mkx
Tue Sep 18, 2018 10:35 am
Forum: General
Topic: Bridges and VLANs
Replies: 1
Views: 233

Re: Bridges and VLANs

There's no need to use 3 bridges, you can do it with single bridge. The logical hierarchy in mikrotik is something like this: physical interfaces (ether, wifi, ...) <---> bridge <---> logical interfaces, such as VLAN interfaces If you're dealing with VLANs, then you configure them on bridge. So the ...
by mkx
Tue Sep 18, 2018 9:54 am
Forum: General
Topic: How do I keep traffic separate on Vlan and Lan?
Replies: 1
Views: 277

Re: How do I keep traffic separate on Vlan and Lan?

The best and the only 100% solution is to use separate physical infrastructure ... both ethernet cables and (if needed) WiFi access points using uncorrelated channels. I guess that using common router should be fine if IP cameras have to be accessible from internet (or the rest of LAN), but be sure ...
by mkx
Tue Sep 18, 2018 9:23 am
Forum: Beginner Basics
Topic: How to route between a bridge and a subnet?
Replies: 8
Views: 1668

Re: How to route between a bridge and a subnet?

Beware that default configuration of "consumer-class" mikrotiks is to have ether1 configured as WAN port. Firewall rules are set accordingly. In your case this is quite wrong and you need to remove all firewall rules and set them according to your needs. In addition to that you either need to NAT IP...
by mkx
Mon Sep 17, 2018 8:17 pm
Forum: Announcements
Topic: v6.43 [current] is released!
Replies: 148
Views: 28769

Re: v6.43 [current] is released!

I cannot upgrade to 6.43. I think something messed up with packets installed The wireless package is installed both in basic bundle and as separate package. Until you resolve this issue, you can not upgrade to newer version. Whatever you try, first create backup and text configuration export (/expo...
by mkx
Mon Sep 17, 2018 3:44 pm
Forum: General
Topic: How to remotely administer Mikrotik routers in safeway
Replies: 19
Views: 1326

Re: How to remotely administer Mikrotik routers in safeway

In case you use dynamic ip simple add your dns name under adress list, than under nat add it to src address list. hmm interesting and easy to implement. How often Mikrotik routers updates dns entries in address list? ie. My LTE modem got new IP evertytime its connect to network so I imagine that my...
by mkx
Mon Sep 17, 2018 9:02 am
Forum: General
Topic: Stopping connections to TCP port 1720
Replies: 6
Views: 1065

Re: Stopping connections to TCP port 1720

Did you check if socks are enabled? Use command /ip socks print to verify.
by mkx
Sun Sep 16, 2018 3:31 pm
Forum: Wireless Networking
Topic: Different Vlans for every Access Point
Replies: 11
Views: 1349

Re: Different Vlans for every Access Point

@hanyassar: your configuration is quite complex and I don't feel comfortable dissecting it ... there are things that I don't like (such as addresses set on ether ports that are members of bridge) and would do differently (I'm not saying they're wrong as they are now). If I were facing the same task,...
by mkx
Sun Sep 16, 2018 1:48 pm
Forum: Wireless Networking
Topic: Different Vlans for every Access Point
Replies: 11
Views: 1349

Re: Different Vlans for every Access Point

Thanks for the reply...The Access Points I'm using are TP-Links and and not Mikrotik. Do you suggest me trying your method? Is mine wrong? I'm not sure what you did configure and what might be still missing. If it's not working for you, you can post here the exported configuration from RB2011 (/exp...
by mkx
Sun Sep 16, 2018 1:14 pm
Forum: Wireless Networking
Topic: Different Vlans for every Access Point
Replies: 11
Views: 1349

Re: Different Vlans for every Access Point

If APs are mikrotiks, then you may want to start using CapsMan. There are 3 steps when configuring VLANs: create necessary vlan interfaces on 2011's bridge (/interface vlan add interface=bridge vlan-id=xxx ). Avoid using VLAN ID=1 at all costs. To these intetfaces bind services that should be availa...
by mkx
Sun Sep 16, 2018 12:50 pm
Forum: General
Topic: Mikrotik attacked. No idea how.
Replies: 7
Views: 845

Re: Mikrotik attacked. No idea how.

- if unsure, perform a netinstall to wipe all and start over
... and don't use binary backup to restore configuration ... as you can never be sure when your router was actually compromised. Rather use ASCII configuration exports and check it thoroughly before applying.
by mkx
Sun Sep 16, 2018 12:33 pm
Forum: General
Topic: Mikrotik attacked. No idea how.
Replies: 7
Views: 845

Re: Mikrotik attacked. No idea how.

Anything fishy in logs?
by mkx
Sun Sep 16, 2018 12:26 pm
Forum: General
Topic: Firewall rule for external ip access
Replies: 1
Views: 207

Re: Firewall rule for external ip access

Make sure you don't limit the dstnat rule for 1.1.1.3:80 to be valid only from WAN interface. It should be also valid for LAN interface where lives 192.168.2.1/24 subnet.
by mkx
Sun Sep 16, 2018 12:08 pm
Forum: Beginner Basics
Topic: Bridging and Speed
Replies: 12
Views: 941

Re: Bridging and Speed

My guess is that hAP ac² would be capable of routing at 1Gbps. And any RB with similar CPU performance would do as well (current hEX probably as well). But current implementation of bridge, when using non-trivial functionality such as VLAN filtering, does not allow to use RB devices for switching ta...
by mkx
Sun Sep 16, 2018 11:56 am
Forum: Announcements
Topic: v6.43 [current] is released!
Replies: 148
Views: 28769

Re: v6.43 [current] is released!

Changing the identity on hAp ac² crashes the router with an error: "kernel failure in previous boot".
You mean changing identity name as in
/system identity set name="some other name"
The above command doesn't crash my hAP ac² ... running ROS 6..43.
by mkx
Sat Sep 15, 2018 10:57 pm
Forum: Beginner Basics
Topic: Bridging and Speed
Replies: 12
Views: 941

Re: Bridging and Speed

What I observed on my RB951G is that if I configured it in new bridge vlan filtering way (so that HW offload was not possible) and did a throughput test between two ports, I did get wire speed, but CPU usage was higher than 90%. Meaning there's no reserve for another pair of wire speed transfers... ...
by mkx
Sat Sep 15, 2018 6:42 pm
Forum: Beginner Basics
Topic: Login via WINBOX not working [SOLVED]
Replies: 2
Views: 2411

Re: Login via WINBOX not working [SOLVED]

Check if winbox service is enabled (IP -> Services) and check the port number as well ... if it's not set to default 8291, you'll have to set it in winbox application. Check settings in firewall (IP -> Firewall -> Filter rules) ... verify correct port numbrr and from where access is allowed (source ...
by mkx
Sat Sep 15, 2018 5:21 pm
Forum: Beginner Basics
Topic: Access modem behind Mikrotik [SOLVED]
Replies: 6
Views: 1081

Re: Access modem behind Mikrotik [SOLVED]

Just noticed: correct setting of IP address on ether1 interface would be 192.168.1.2/24 ... without netmask things might behave slightly unpredictable.
by mkx
Sat Sep 15, 2018 5:17 pm
Forum: Beginner Basics
Topic: Access modem behind Mikrotik [SOLVED]
Replies: 6
Views: 1081

Re: Access modem behind Mikrotik [SOLVED]

Nothing is hacky here. Vigor has it's address set and no other device in the same subnet (your RB included) is allowed to have exactly same address.
by mkx
Sat Sep 15, 2018 5:14 pm
Forum: Beginner Basics
Topic: The Dude - server
Replies: 2
Views: 322

Re: The Dude - server

Did you go through wiki about The Dude? In section about installation it writes about server part being installed on Routerboard devices and client part being installed on Windows PC.
by mkx
Sat Sep 15, 2018 5:01 pm
Forum: Beginner Basics
Topic: Access modem behind Mikrotik [SOLVED]
Replies: 6
Views: 1081

Re: Access modem behind Mikrotik [SOLVED]

Either follow advice by @korg (run DHCP client on ether1 device, it'll also add route to subnet where Vigor is accessible) or try to find out actual IP address of Vigor's LAN address. It seems that default IP address of Vigor is 192.168.1. 1 so you must set some other address on ether1 of your RB (n...
by mkx
Sat Sep 15, 2018 4:47 pm
Forum: Beginner Basics
Topic: Bridging and Speed
Replies: 12
Views: 941

Re: Bridging and Speed

If the new bridge setup is simple enough, it will be hardware-offloaded so there should be no difference between old and new setup performance wise. However, if setup is not simple (adding VLANs to the mix is enough), it will not be HW offloaded so performance might be lower or RB's CPU load will be...
by mkx
Sat Sep 15, 2018 10:53 am
Forum: Beginner Basics
Topic: Trying to Deconflict Port Speed between Winbox and CLI [SOLVED]
Replies: 3
Views: 357

Re: Trying to Deconflict Port Speed between Winbox and CLI [SOLVED]

Port speed setting changed from default 100Mbps in 6.42.7 and before to 1Gbps in 6.43. Upgrade, however, doesn't change settings, while export shows whatever setting different than export. If you set port speed to 1Gbps, it won't be exported at all. Note that this setting is ignored when auto negoti...
by mkx
Fri Sep 14, 2018 10:37 pm
Forum: Announcements
Topic: v6.43 [current] is released!
Replies: 148
Views: 28769

Re: v6.43 [current] is released!

It really depends on scale of attack (and possibly there's some mis-handling of zero size UDP packets in ROS). But I'd say that major contribution to service failure is that you're logging each malformed UDP packet. Try to silently drop it, it might help your CCR to survive.
by mkx
Fri Sep 14, 2018 10:27 pm
Forum: General
Topic: IP Cloud
Replies: 113
Views: 66407

Re: IP Cloud

Janisk, we, who have our own dns, do not use your ip cloud service at all. Happily. I'm pretty sure that (W)ISPs are not target audience for cloud DNS, minority among home users are. Minority that is exposing some (small) part of home computing resources to internet (if only to have remote administ...
by mkx
Fri Sep 14, 2018 5:46 pm
Forum: Beginner Basics
Topic: Mikrotik gateway DMZ settings
Replies: 5
Views: 1603

Re: Mikrotik gateway DMZ settings

NAT has precedence as it actually defines which chain of FW rules apply - either forward (if dst-nat matches) or input.
  • 1
  • 6
  • 7
  • 8
  • 9
  • 10