Community discussions

Search found 2925 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 10
by mkx
Sat Aug 31, 2019 5:09 pm
Forum: General
Topic: Address list limitations on number of entries
Replies: 2
Views: 367

Re: Address list limitations on number of entries

If your list contains individual host addresses which are at least partly continous, then you could reduce the number of entries by merging the continous addresses to (small) subnets. I the lust was: 20.20.30.13 20.40.50.42 20.40.50.43 20.30.66.77 then you could write it as 20.20.30.13 20.40.50.42/3...
by mkx
Sat Aug 31, 2019 4:30 pm
Forum: Beginner Basics
Topic: RB3011UiAS-RM is not showing USB Stick anymore
Replies: 4
Views: 648

Re: RB3011UiAS-RM is not showing USB Stick anymore

Nope, your RB doesn't seem to notice the USB device. Here's how it looks on my RBD52G when USB flash disk is plugged in: [fu@bar] /system resource usb> print # DEVICE VENDOR NAME SPEED 0 1-0 Linux 3.3.5 xhci-hcd-ipq40xx xHCI Host Controller 480 1 2-0 Linux 3.3.5 xhci-hcd-ipq40xx xHCI Host Controller...
by mkx
Sat Aug 31, 2019 3:00 pm
Forum: RouterBOARD hardware
Topic: LAN Ports issue
Replies: 2
Views: 528

Re: LAN Ports issue

No sign of working as status lights corresponding to ether ports don't light up or blink .. not even on device on the other end of the cable? And you tried with different devices otherwise known to be flawless?

Or no sign of working as no traffic passes despites status lights indicating link?
by mkx
Sat Aug 31, 2019 2:55 pm
Forum: Beginner Basics
Topic: RB3011UiAS-RM is not showing USB Stick anymore
Replies: 4
Views: 648

Re: RB3011UiAS-RM is not showing USB Stick anymore

Which way the RB is not recognising the stick? Does it show under /system resources usb ? Any pluged device should show there even if device isn't supported in ROS whatsoever. If it does but doesn't show as disk, then you'll have to reinitialize it ... if the USB device doesn't show under USB device...
by mkx
Sat Aug 31, 2019 12:10 pm
Forum: General
Topic: CRS112-8G-4S > No 100mbps fiber [SOLVED]
Replies: 11
Views: 1370

Re: CRS112-8G-4S > No 100mbps fiber [SOLVED]

Keep using CRS as switch and go for something small as router .... RB750Gr3 would do fine. Or a RBD52G, you'd get wireless for free. Both have HW acceleration for (some variants of) IPsec encryption ...
by mkx
Sat Aug 31, 2019 12:03 pm
Forum: General
Topic: CRS317 ROS new switch method with HW offload [SOLVED]
Replies: 4
Views: 552

Re: CRS317 ROS new switch method with HW offload [SOLVED]

As @Dude2048 explained ... single bridge it is. If switching can't be offloaded, then traffic is handled by CPU which is relatively slow in CRS3xx devices. Not capable of transfer speeds anywhere near wirespeeds. Which means CRS3xx are not really fit for inter-VLAN routing.
by mkx
Sat Aug 31, 2019 11:56 am
Forum: General
Topic: CRS317 ROS new switch method with HW offload [SOLVED]
Replies: 4
Views: 552

Re: CRS317 ROS new switch method with HW offload [SOLVED]

Your approach is correct. Generally it is advisable to configure single bridge per device as generally only one bridge can offload operations to underlying hardware (you can verify that by executing command /interface bridge port print , HW-offloaded ports show flag 'H' in front of port name). CRS3x...
by mkx
Sat Aug 31, 2019 11:50 am
Forum: Beginner Basics
Topic: How to configure the VLANs - two trunk and one access port
Replies: 4
Views: 668

Re: How to configure the VLANs - two trunk and one access port

I recomend to start by reading this excellent tutorial. After you do it and still have troubles, come back with concrete questions.
by mkx
Fri Aug 30, 2019 11:57 pm
Forum: General
Topic: CRS112-8G-4S > No 100mbps fiber [SOLVED]
Replies: 11
Views: 1370

Re: CRS112-8G-4S > No 100mbps fiber [SOLVED]

Official test results for your CRS do show, that simple routing without filter rules can be quite slow if packet size is small (PPS gets limited). With full-size packets your device should be able to route at leas few times more than whst you get. And who knows what test app used actually does ... J...
by mkx
Fri Aug 30, 2019 11:47 pm
Forum: RouterBOARD hardware
Topic: CWDM (one side), SFP wavelength specific on other end [SOLVED]
Replies: 3
Views: 679

Re: CWDM (one side), SFP wavelength specific on other end [SOLVED]

My limited testing with a few types of SFP (and SFP+) modules (some branded Ericsson and some OEM) with wavelengths between 1290 and 1610nm, both CWDM and "usual" 1310nm ones, showed that receiving photo-diode is always wide-band. E.g. link successfully established between "usual" 1310nm SFP and 157...
by mkx
Fri Aug 30, 2019 11:24 pm
Forum: General
Topic: CRS112-8G-4S > No 100mbps fiber [SOLVED]
Replies: 11
Views: 1370

Re: CRS112-8G-4S > No 100mbps fiber [SOLVED]

I don't think the problem is in switching v.s. bridging, this distinction only affects ether interfaces that are handling traffic for same broadcast domain, in your caee the Skynet subnet. Your current setup probably offloads traffic to switch chip as it is, you can verify it by executing command /i...
by mkx
Fri Aug 30, 2019 11:08 pm
Forum: General
Topic: Mikrotik Vlans
Replies: 1
Views: 399

Re: Mikrotik Vlans

If interface is already added as bridge port, but you need to change some of its properties, use set : /interface bridge port add bridge=bridge interface=sfp-sfpplus1 # set pvid on this port set [ find interface=sfp-sfpplus1 ] pvid=100 In ROS, VLAN settings are split in two sections: /interface brid...
by mkx
Fri Aug 30, 2019 10:35 pm
Forum: General
Topic: Remote Access to CRS309
Replies: 1
Views: 279

Re: Remote Access to CRS309

From what you posted it's not clear which port is tagged member and which is untagged member. Better post output of /interface bridge export and use [code] environment to improve readability. Indicate which interface has LAN IP address configured.
by mkx
Fri Aug 30, 2019 10:07 pm
Forum: Beginner Basics
Topic: Configure simple bridge+vlan, No ping; missing something basic? [SOLVED]
Replies: 3
Views: 630

Re: Configure simple bridge+vlan, No ping; missing something basic? [SOLVED]

As you created vlan88 interface on bridge and set bridge "interface" as tagged member port of VLAN 88, setting pvid on bridge to the same value is wrong ... (re)set pvid on bridge interface to pvid=1 ... Btw, if VLANs 20 and 70 are going to be used on wlan only, then bridge "interface" doesn't have ...
by mkx
Fri Aug 30, 2019 8:56 am
Forum: Wireless Networking
Topic: VirtualAP Bridging
Replies: 4
Views: 623

Re: VirtualAP Bridging

Try to post complete running config of hAP ac2 ... use /export hide-sensitive and don't obfuscate too much. Without that we can only guess what you configured and what not.
by mkx
Fri Aug 30, 2019 8:39 am
Forum: General
Topic: VLAN configuration approach, correct or not ?
Replies: 5
Views: 648

Re: VLAN configuration approach, correct or not ?

(1) VLANs configured at the Router chip (Software based) : This is the most universal way to configure VLANs but you will be forcing the Routing chip to behave as a L3 switch with inter-VLAN routing. This method works on any Mikrotik device (Switch or Router alike) and requires you to configure 1 V...
by mkx
Fri Aug 30, 2019 8:31 am
Forum: General
Topic: Bridge VLAN Filtering help [SOLVED]
Replies: 22
Views: 1977

Re: Bridge VLAN Filtering help [SOLVED]

... in a nutshell, assymetric vlan allows you to "switch" between VLAN's, so you don't have to "route" between these VLAN's Well, actually it does on egress what a typical windows NIC driver does on ingress ... strips all VLAN headers :lol: "switching" between VLANs is one of (benefitial if admin i...
by mkx
Thu Aug 29, 2019 11:51 pm
Forum: Wireless Networking
Topic: Bridged vlan on physical interfaces to the new (vlan bridge filtering)
Replies: 9
Views: 945

Re: Bridged vlan on physical interfaces to the new (vlan bridge filtering)

... two clients associated to different APs which are interconnected transparently at L2 can send frames to each other regardless the APs being set to block client-to-client forwarding. But this is easily resolved using bridge horizon where all bridge ports can forward traffic to one "uplink" port ...
by mkx
Thu Aug 29, 2019 11:34 pm
Forum: Beginner Basics
Topic: VLAN between two routers. Can it work!? If so how?
Replies: 9
Views: 845

Re: VLAN between two routers. Can it work!? If so how?

- so, yesterday I did a very basic speedtest to the only two 10G devices I have at the moment, the NAS and my PC. * Both connected to the CRS317. Both on another VLAN So you took your brand new Ferrari and went on to plow the field. If NAS and PC are in different VLANs, then transfers between tgem ...
by mkx
Thu Aug 29, 2019 4:53 pm
Forum: Beginner Basics
Topic: Mikrotik HAP Lite Home AP, Fritz 7590 as modem
Replies: 5
Views: 583

Re: Mikrotik HAP Lite Home AP, Fritz 7590 as modem

Connection from hAP to Fritz is considered as WAN for hAP and by default, connections from WAN to LAN are firewalled. At the same time, all connections from LAN to WAN are NAT-ed (they all appear to come from hAP regardless the original LAN client). To solve the problem you have two possibilities (o...
by mkx
Thu Aug 29, 2019 3:29 pm
Forum: Wireless Networking
Topic: Bridged vlan on physical interfaces to the new (vlan bridge filtering)
Replies: 9
Views: 945

Re: Bridged vlan on physical interfaces to the new (vlan bridge filtering)

Conceptually VLANs are almost as separate LANs. They separate devices on L2 (ethernet) level. If, on the other hand, you want to have those devices in same L2 domain (because you want to use single DHCP server which is L2/L3 service and serves IP addresses from single L3 domain (IP subnet), then you...
by mkx
Thu Aug 29, 2019 3:16 pm
Forum: General
Topic: Bridge VLAN Filtering help [SOLVED]
Replies: 22
Views: 1977

Re: Bridge VLAN Filtering help [SOLVED]

I think there was a possible error/omission in the config and that was what I was pointing out or at least asking. So I didn't react to your post. I'll deny that it might be due to oversight from my side ;-) Seriously though: yes, you're right (and that's why I didn't react ... so sorry I deprived ...
by mkx
Thu Aug 29, 2019 2:58 pm
Forum: Beginner Basics
Topic: RBM11G + R11e-LTE not working
Replies: 34
Views: 2592

Re: RBM11G + R11e-LTE not working

netinstall wipes all the configuration ... then it might resume default configuration (whatever that means for RBM11G) or no configuration, depending on what you select when doing netinstall ...
by mkx
Thu Aug 29, 2019 9:24 am
Forum: General
Topic: ROS7: Requests for wireless features
Replies: 7
Views: 1374

Re: ROS7: Requests for wireless features

I expect a miracle!

You know the timeline: we deliver the impossible immediately, for miracles you have to wait for a while ;-)
by mkx
Thu Aug 29, 2019 8:33 am
Forum: RouterBOARD hardware
Topic: Powerline and Powerline AP
Replies: 3
Views: 613

Re: Powerline and Powerline AP

Generally power-line works great when both (all) units are plugged to the same power circuit (i.e. on the same side of single fuse/breaker). In this case it seems that max distance is around 300 metres (but don't expect any kind of decent speed there). It works fine when units are plugged to differe...
by mkx
Thu Aug 29, 2019 8:20 am
Forum: General
Topic: CAPSMAN - Control or disable ethernet interfaces?
Replies: 1
Views: 216

Re: CAPSMAN - Control or disable ethernet interfaces?

You'll have to do it manually indeed. capsman only configures wireless interfaces, but doesn't touch neither bridge or any other interfaces.
by mkx
Thu Aug 29, 2019 8:11 am
Forum: General
Topic: Bridge VLAN Filtering help [SOLVED]
Replies: 22
Views: 1977

Re: Bridge VLAN Filtering help [SOLVED]

@anav, you're such a moving target (and my eyes are getting old as well) so it's hard to focus on you ;-) ... but anyway, I was just jumping in to explain @pe1chl the possible use case of this "huh?" feature. You boys are doing well so I'll stop to interfere.
by mkx
Wed Aug 28, 2019 11:19 pm
Forum: Wireless Networking
Topic: Two "mANT30 PA" as passive repeater. Possibly?
Replies: 3
Views: 440

Re: Two "mANT30 PA" as passive repeater. Possibly?

Do you think this is possible? Hardly. Passive repeater ideally transmits all energy received by one antenna over the other antenna. If AP at point A transmits signal at +30 dBm (includes antenna gain) and potential station at point B would receive that signal at say -40dBm (which includes antenna ...
by mkx
Wed Aug 28, 2019 10:47 pm
Forum: General
Topic: Bridge VLAN Filtering help [SOLVED]
Replies: 22
Views: 1977

Re: Bridge VLAN Filtering help [SOLVED]

In my Netgear switch the same port can be untagged member of several different VLANs and the pvid defines what tag the received packets get, and I think the configuration of the MikroTik bridge VLAN filtering allows the same thing, but why would you want that? My good old Dlink switch has this func...
by mkx
Wed Aug 28, 2019 10:07 pm
Forum: Beginner Basics
Topic: hAP ac^2 Suddenly stopped reaching gateway periodically
Replies: 6
Views: 846

Re: hAP ac^2 Suddenly stopped reaching gateway periodically

Regarding ROS version: my RBD52G is currently running 6.45.1 and is stable. Regarding disabling switch-chip: set hw=no on all ether ports in /interface bridge port . You can verify the status by executing /interface bridge port print ... before disabling HW offload those ports should have a 'H' in t...
by mkx
Wed Aug 28, 2019 9:27 am
Forum: Beginner Basics
Topic: Help Help !! can not route between VLAN's :( :(
Replies: 8
Views: 875

Re: Help Help !! can not route between VLAN's :( :(

- the CRS-internal ping test which also did not and still does not forward the pings !!! very confusing! :shock:

What exactly are your executing for this test?
by mkx
Wed Aug 28, 2019 9:15 am
Forum: General
Topic: Serious problem: Free HDD Space 0 KiB, no space to save settings. RouterOS 6.45.3 [SOLVED]
Replies: 9
Views: 1215

Re: Serious problem: Free HDD Space 0 KiB, no space to save settings. RouterOS 6.45.3 [SOLVED]

Are you running User manager on this unit? If yes, then you really must add some disk storage ... for two reasons: 1. capacity, 2. built-in flash longevity (frequent wites wear off the flash storage, if built-in flash fails, your device becomes a brick without possibility to repair it).
by mkx
Wed Aug 28, 2019 9:07 am
Forum: General
Topic: Hardware Offload off and no Internet connection the first min/sek...
Replies: 2
Views: 438

Re: Hardware Offload off and no Internet connection the first min/sek...

The firewall rules you posted don't warrant use of "use IP firewall" on bridge ... as they all affect the connectivity towards internet and my personal view is that firewall should be running on main router (which ever it is). In addition to that, layer7 rules are very CPU intensive while CRS3xx hav...
by mkx
Wed Aug 28, 2019 9:00 am
Forum: Beginner Basics
Topic: RBM11G + R11e-LTE not working
Replies: 34
Views: 2592

Re: RBM11G + R11e-LTE not working

I realized that the internet dns have from internet have this format aa.bb But..when i create the dhcp server the dns range have this format aaa.bbb..could this create the problem? The format doesn't matter much as long as there are 4 numbers separated with a dot. I.e. 008.008.008.008 is exactly th...
by mkx
Wed Aug 28, 2019 8:58 am
Forum: Beginner Basics
Topic: RBM11G + R11e-LTE not working
Replies: 34
Views: 2592

Re: RBM11G + R11e-LTE not working

Then, probably the problem is that you not have DNS servers on your DHCP. This. Router basically doesn't deal with domain names, it only works with IP addresses. So if you can ping 8.8.8.8 from your PC , then router is forwarding packets between LAN and WAN just fine. You really need to focus on ho...
by mkx
Wed Aug 28, 2019 8:46 am
Forum: Beginner Basics
Topic: RB4011iGS with more subnets
Replies: 11
Views: 1162

Re: RB4011iGS with more subnets

If the RB configuration you posted is complete, then firewall is non-existing (and the device is thus open for any attacks). I strongly suggest to start again, this time select reset with factory defaults to have a very sensible firewall rules enabled. Anyway, if we start from empty firewall, you ca...
by mkx
Wed Aug 28, 2019 8:32 am
Forum: Beginner Basics
Topic: hAP ac^2 Suddenly stopped reaching gateway periodically
Replies: 6
Views: 846

Re: hAP ac^2 Suddenly stopped reaching gateway periodically

I've had similar issue with RBD52G, which went away after I did the following two things: upgrade ROS to 6.44 effectively stopped using switch chip for forwarding the traffice between ether ports (my setup includes VLANs and I configured bridge vlan-filtering which means all ethernet frames have to ...
by mkx
Wed Aug 28, 2019 8:27 am
Forum: Beginner Basics
Topic: Help Help !! can not route between VLAN's :( :(
Replies: 8
Views: 875

Re: Help Help !! can not route between VLAN's :( :(

- I did not post the whole config, mainly because it is big and probably just take the attention away from what at this moment my main problem is. "inter vlan routing". Behavoir is rather vague. As example I cannot ping between GW192.168.216.1 and GW 192.168.218.1. And I can not ping the GW192.168....
by mkx
Tue Aug 27, 2019 8:47 pm
Forum: Beginner Basics
Topic: Very Vague CPU-port- and Bridge-port-access and Bridge to VLAN-binding!
Replies: 1
Views: 265

Re: Very Vague CPU-port- and Bridge-port-access and Bridge to VLAN-binding!

I'm not quite sure that I understand all the details of your "complaint". I agree that VLANs are slightly confusing on ROS. But there is one thing that I guess confuses many people: the bridge. Bridge in ROS has two personalities: "kind of a switch" personality which passes traffic between member po...
by mkx
Tue Aug 27, 2019 4:43 pm
Forum: Beginner Basics
Topic: Remote Name Server [SOLVED]
Replies: 5
Views: 557

Re: Remote Name Server [SOLVED]

Tripple-check that the DST-NAT rule is correct. Also verify that firewall filter rules allow that connection (default filter rule allowing connections with connection-state=dst-nat is fine). Check bind config that it is not denying resolution for non-local clients (it should allow resolution of doma...
by mkx
Tue Aug 27, 2019 3:51 pm
Forum: General
Topic: The LTAP can switch the Dual SIM when the RSSI was weakness?
Replies: 52
Views: 3913

Re: The LTAP can switch the Dual SIM when the RSSI was weakness?

But, please, use RSRP for indication of signal strength ... RSSI includes also all the interference.
by mkx
Tue Aug 27, 2019 2:00 pm
Forum: Beginner Basics
Topic: tag all untagged traffic - can't get it working
Replies: 12
Views: 954

Re: tag all untagged traffic - can't get it working

It is advisable to configure all VLANs are tagged ... which doesn't mean it can not be untagged on the ethernet ports.
I'm having a hard time digesting this one, can you elaborate a little bit please?
Did you study the tutorial I linked in one of my previous posts?
by mkx
Tue Aug 27, 2019 1:55 pm
Forum: General
Topic: ICMP Firewall Potential Bug
Replies: 13
Views: 1153

Re: ICMP Firewall Potential Bug

What would carrier's usually do for this type of thing? This is our new border router before our transit. As a non-ISP person, I'd say ISP/carrier should not firewall much (if any at all) ... not on it's border router anyways. Either leave it to customers or do it at access routers ... unless you d...
by mkx
Tue Aug 27, 2019 1:51 pm
Forum: General
Topic: VLAN configuration approach, correct or not ?
Replies: 5
Views: 648

Re: VLAN configuration approach, correct or not ?

The new (since ROS version 6.41) approach is to have single VLAN-aware bridge spanning all LAN ports. Something in the line of following example: /interface bridge add name=bridge vlan-filtering=yes /interface bridge port add bridge=bridge ingress-filtering=yes frame-types=admit-only-untagged-and-pr...
by mkx
Tue Aug 27, 2019 12:48 pm
Forum: Beginner Basics
Topic: tag all untagged traffic - can't get it working
Replies: 12
Views: 954

Re: tag all untagged traffic - can't get it working

The mentioned tutorial is explaining the "bridge VLAN" (mentioned as #2 on my list). What you describe you want to do is perfectly doable. The tutorial briefly touches the "hybrid" setup - one VLAN untagged (native) and the rest of VLANs tagged, but also notes that hybrid access is a bit problematic...
by mkx
Tue Aug 27, 2019 12:34 pm
Forum: Beginner Basics
Topic: Help Help !! can not route between VLAN's :( :(
Replies: 8
Views: 875

Re: Help Help !! can not route between VLAN's :( :(

My guess is that the problem is what I wrote in the paragraph starting with "BTW, when constructing a member list of interfaces ...". However, I can't tell if that's the main reason because reasons for things not working as intended are numerous and you chose not to show complete configuration stuff.
by mkx
Tue Aug 27, 2019 10:55 am
Forum: Beginner Basics
Topic: Remote Name Server [SOLVED]
Replies: 5
Views: 557

Re: Remote Name Server [SOLVED]

May I install NS behind Mikrotik? (for this plan)

Sure you can. And establish port forwarding (port 53, protocols both TCP and UDP, forwarded to the server you'll use as NS).
by mkx
Tue Aug 27, 2019 9:21 am
Forum: General
Topic: ICMP Firewall Potential Bug
Replies: 13
Views: 1153

Re: ICMP Firewall Potential Bug

What is my solution to allow traceroutes into my network? If the traceroute uses UDP packets, it mostly selects a random destination UDP port and you can't really do anything to make it work if you don't want to open up just everything. If traceroute uses TCP packets (there's a tcptraceroute in lin...
by mkx
Tue Aug 27, 2019 8:55 am
Forum: General
Topic: Weird IPv6 stuff
Replies: 4
Views: 483

Re: Weird IPv6 stuff

How did router assign the anycast address to itself? If I issue /ipv6 address add interface=ether1 from-pool=<IPv6 pool name> then it will auto select a valid unicast address ... If you set it manually (as in /ipv6 address set interface=ether1 address=aaaa:bbbb::/64 ) then as I said, IPv6 in current...
by mkx
Tue Aug 27, 2019 8:41 am
Forum: Beginner Basics
Topic: Help Help !! can not route between VLAN's :( :(
Replies: 8
Views: 875

Re: Help Help !! can not route between VLAN's :( :(

The VLAN setup in config export is a minor mess. I suggest you to read through this tutorial . BTW, when constructing a member list of interfaces, only individual interface names may be enclosed in double quotes, not the whole list. I.e. tagged="05 GS1920,VirtualSwitch1,11 NAS_EM0" is not the same a...
by mkx
Tue Aug 27, 2019 8:32 am
Forum: Beginner Basics
Topic: tag all untagged traffic - can't get it working
Replies: 12
Views: 954

Re: tag all untagged traffic - can't get it working

I do have a VLAN configured in a bridge. The config command you posted a few posts back indicates that you're configuring VLANs on switch chip. So there are two ways of doing it: On switch chip You configure things in /interface ethernet switch port and /interface ethernet switch vlan configuraton ...
by mkx
Tue Aug 27, 2019 8:15 am
Forum: General
Topic: Request: FEC tunnel types
Replies: 27
Views: 3075

Re: Request: FEC tunnel types

@Amm0: what makes you claim that LTE is lossy?
by mkx
Mon Aug 26, 2019 8:27 pm
Forum: General
Topic: ICMP Firewall Potential Bug
Replies: 13
Views: 1153

Re: ICMP Firewall Potential Bug

Different traceroute programmes use different packet types. Some use same ICMP packets (windows does it IIRC), some use some UDP (linux does it).
by mkx
Mon Aug 26, 2019 8:11 pm
Forum: Beginner Basics
Topic: RBM11G + R11e-LTE not working
Replies: 34
Views: 2592

Re: RBM11G + R11e-LTE not working

What do print the following commands? /interface print detail /ip dhcp-client print detail # obfuscate any public data /ip address print detail # you might want to obfuscate public WAN address here /ip route print detail # obfuscate the public route Just try to obfuscate public data following the sa...
by mkx
Mon Aug 26, 2019 7:34 pm
Forum: General
Topic: Force NTP Client Update
Replies: 5
Views: 422

Re: Force NTP Client Update

Hey ntp client will determine on it's own how frequently it should poll the upstream server for time update. Usually it starts at 64s and backs down down to 1024s, once clocks are in sync and drift is under control. The problem is that mine is drifting too much for some reason, I need to manually u...
by mkx
Mon Aug 26, 2019 7:04 pm
Forum: General
Topic: Weird IPv6 stuff
Replies: 4
Views: 483

Re: Weird IPv6 stuff

2001:4bb8:248:2868::/64 is a network address (similar to aaa.bb.cc.0/24 in IPv4) do setting this address as host address is invalid (ability to set it anyway is a bug, but then lots of IPv6 implementation in current ROS is buggy).
by mkx
Mon Aug 26, 2019 6:55 pm
Forum: Beginner Basics
Topic: Remote Name Server [SOLVED]
Replies: 5
Views: 557

Re: Remote Name Server [SOLVED]

Could I use one IP address to two (or more) domain? Yes, if different subdomains resolve to same IP address. Most (if no all) HTTP servers support name based virtual servers. Non-ancient HTTPS srrvers do as well (using TLS SNI). How could I delegate to sub.domain.com to world wide? Could I use this...
by mkx
Mon Aug 26, 2019 6:47 pm
Forum: Beginner Basics
Topic: RBM11G + R11e-LTE not working
Replies: 34
Views: 2592

Re: RBM11G + R11e-LTE not working

Post full configuration of RBM11G ... you can get it by executing command /export hide-sensitive in a command window. Hide sensitive data (such as usernames and passwords) and then post it here, enclosing it in [code][/code] environment for better readability..
by mkx
Mon Aug 26, 2019 6:42 pm
Forum: Beginner Basics
Topic: hAP AC2 as main router over bridge setup
Replies: 2
Views: 365

Re: hAP AC2 as main router over bridge setup

Personally I'd add another RBD52G where Technicolor is. Then I'd forget about Technicolor's wireless, routing and firewalling (in short: configure it to bridge mode so that it semi-transparently passes traffic to your main RB). Then I'd configure one of RBD52Gs (possibly the one in the store room) t...
by mkx
Mon Aug 26, 2019 12:13 pm
Forum: Beginner Basics
Topic: RBM11G + R11e-LTE not working
Replies: 34
Views: 2592

Re: RBM11G + R11e-LTE not working

Does internet work on RBM11G itself? You can check it by executing
/ping www.google.com
If this works, then it's something about LAN setup (either IP settings on router, DHCP settings or firewall rules). If it doesn't, then it's something about LTE and/or WAN setup.
by mkx
Mon Aug 26, 2019 8:39 am
Forum: Beginner Basics
Topic: RBM11G + R11e-LTE not working
Replies: 34
Views: 2592

Re: RBM11G + R11e-LTE not working

IP -> Firewall -> NAT Add Chain: srcnat Out. Interface: lte1 Action: Masquerade (This on "action" tab) Regards. Or, better yet (if using firewall rules resembling default rules from recent ROS versions) add lte1 interface to WAN interface list. It'll magically make RB to use all the right firewall ...
by mkx
Mon Aug 26, 2019 8:38 am
Forum: Beginner Basics
Topic: Wireless CM9
Replies: 1
Views: 231

Re: Wireless CM9

A quick search in the internet reveals one CM9 minipci wireless card ... which seems to be single radio (with dual chain), but 2.4/5 GHz selectable. Which means you need two cards for your use case.
by mkx
Mon Aug 26, 2019 8:26 am
Forum: Beginner Basics
Topic: RB4011iGS with more subnets
Replies: 11
Views: 1162

Re: RB4011iGS with more subnets

The shown configuration doesn't correspond to how you described the config: - ether2 is 192.168.10.1/24, DHCP - connected to PC1 (Windows, IP 192.168.10.254) - ether10 is 192.168.20.1/24, DHCP - connected to PC2 (Windows, IP 192.168.20.254) The config doesn't show any IP config on ether2 - there's a...
by mkx
Sun Aug 25, 2019 10:59 pm
Forum: Wireless Networking
Topic: WiFi QOS keeps mobile device awake (WMM?)
Replies: 3
Views: 573

Re: WiFi QOS keeps mobile device awake (WMM?)

So you set keepalive-frames=enabled and then you find odd the fact that clients are kept alive?
by mkx
Sun Aug 25, 2019 10:47 pm
Forum: Beginner Basics
Topic: RB4011iGS with more subnets
Replies: 11
Views: 1162

Re: RB4011iGS with more subnets

As somebody replied in some thread: the magic ball department is using another forum. If you want to get some useful input here, start by posting complete configuration - you can get it running /export hide-sensitive in command window.
by mkx
Sat Aug 24, 2019 10:30 pm
Forum: General
Topic: NTP Server Open to Internet
Replies: 1
Views: 302

Re: NTP Server Open to Internet

You'll have to add a firewall filter which will allow connections to UDP port 123 in chain=input ... and place this firewall rule above general drop all rule for same chain.
by mkx
Sat Aug 24, 2019 10:21 pm
Forum: Beginner Basics
Topic: Providing re-sellers real IP
Replies: 4
Views: 582

Re: Providing re-sellers real IP

First guess: you currently have one generic SRC-NAT rule (possibly with action=masquerade). You'll have to add specific SRC-NAT rule for each reseller, i.e. /ip firewall nat add action=src-nat chain=srcnat comment="reseller1" out-interface=<ISP interface> src-address=192.168.60.1/30 to-addresses=00...
by mkx
Sat Aug 24, 2019 8:22 pm
Forum: Beginner Basics
Topic: Need help with specific configuration on mAP lite
Replies: 4
Views: 542

Re: Need help with specific configuration on mAP lite

As your main wifi AP is not Mikrotik, you are very limited in selection of station modes. Really read tge manual document I linked in my previous post, it'll explain all the problems you're facing. I'm not familiar with QuickSet modes so I can't comment of feasibility of CPE mode for this particular...
by mkx
Sat Aug 24, 2019 8:13 pm
Forum: Beginner Basics
Topic: Providing re-sellers real IP
Replies: 4
Views: 582

Re: Providing re-sellers real IP

First guess: you currently have one generic SRC-NAT rule (possibly with action=masquerade). You'll have to add specific SRC-NAT rule for each reseller, i.e. /ip firewall nat add action=src-nat chain=srcnat comment="reseller1" out-interface=<ISP interface> src-address=192.168.60.1/30 to-addresses=000...
by mkx
Sat Aug 24, 2019 7:57 pm
Forum: General
Topic: Plex + Dynamic IP + DHCP IP
Replies: 4
Views: 510

Re: Plex + Dynamic IP + DHCP IP

... but will the hEX always force this MAC to x.x.x.27, nomatter wifi or rj45? DHCP server doesn't know hor does it care which interface Plex uses to connect to LAN, it only cares about MAC address ... so if Plex will use same MAC address for either wired or wlan connection, then DHCP server will o...
by mkx
Sat Aug 24, 2019 7:37 pm
Forum: Beginner Basics
Topic: Need help with specific configuration on mAP lite
Replies: 4
Views: 542

Re: Need help with specific configuration on mAP lite

The problem you're facing is that plain 802.11 doesn't support wireless bridges (which would transparently connect two parts of wired network). Most of WiFi vendors solve this using some proprietary extensions, so does Mikrotik. This, however, means that both APs participating in such bridge have to...
by mkx
Sat Aug 24, 2019 3:19 pm
Forum: General
Topic: Plex + Dynamic IP + DHCP IP
Replies: 4
Views: 510

Re: Plex + Dynamic IP + DHCP IP

For DST-NAT the WAN IP address doesn't really matter, it can be done without referencing it. However, destination (LAN/DMZ server) needs to have static IP address. And this part is not possible (at least with ROS DHCP server) if server's MAC address changes (each network interface has different MAC ...
by mkx
Sat Aug 24, 2019 12:43 pm
Forum: Beginner Basics
Topic: How to dumb bridge (?) using hAP ac lite
Replies: 11
Views: 1022

Re: How to dumb bridge (?) using hAP ac lite

Well, it isn't showing up in winbox.
I'm not sure about this, but it could be that device is not accepting MAC connections over ether1 ... so if your management PC is connected to ether1, try to plug it to some other ether port ...
by mkx
Sat Aug 24, 2019 12:37 pm
Forum: General
Topic: Recommended upgrade paths?
Replies: 2
Views: 463

Re: Recommended upgrade paths?

My suggestion for upgrades: export configuration to plain text using command /export verbose file=exported-config.rsc and copy file to management computer first upgrade to latest release with same major version number (e.g. upgrade the 4.10 device to 4.17) then upgrade it to lowest version with next...
by mkx
Fri Aug 23, 2019 10:41 pm
Forum: RouterBOARD hardware
Topic: RB2011UIAS-2HND-IN completely dead
Replies: 5
Views: 825

Re: RB2011UIAS-2HND-IN completely dead

I'd try with another power supply anyway. The modern switching type of power supplies tend to fail in the way that they provide correct voltage when not under load. When loaded, they drop the voltage and as the time goes by, voltage drop increases to the point when powered device no longer works (co...
by mkx
Fri Aug 23, 2019 10:25 pm
Forum: Wireless Networking
Topic: wireless repeater mode and IPv6 [SOLVED]
Replies: 4
Views: 549

Re: wireless repeater mode and IPv6 [SOLVED]

If both AP3 and AP2 are mikrotik, then you can create transparent wireless hop if you set one of the two APs to mode=bridge or mode=ap-bridge (the former if both APs are used exclusively for point-to-point connection, the later if master AP should serve "normal" stations as well). The other AP shoul...
by mkx
Fri Aug 23, 2019 10:16 pm
Forum: General
Topic: Routing or Bridge for p2p wireless link
Replies: 4
Views: 491

Re: Routing or Bridge for p2p wireless link

Bridge means less package processing on the involved devices ... which means lower delay and possibly higher throughput. However, bridge also means broadcasts (including ARP requests) for the whole subnet will hit all the wireless links (presumably bottlenecks) ... which means somewhat reduced throu...
by mkx
Fri Aug 23, 2019 9:45 pm
Forum: General
Topic: Firewall Rules PPPoE vs ethernet-port
Replies: 9
Views: 964

Re: Firewall Rules PPPoE vs ethernet-port

Just noticed: on the "non-standard" router the accept filter rule is in chain=forward ... should be in chain=input if IPsec is terminated on router itself. Thank you for your input. Tried also with chain=input - doesn't work either. I'm under the impression I didn't explain the setup good enough: M...
by mkx
Fri Aug 23, 2019 8:08 pm
Forum: Beginner Basics
Topic: How to dumb bridge (?) using hAP ac lite
Replies: 11
Views: 1022

Re: How to dumb bridge (?) using hAP ac lite

Winbox searches for routerboard devices and presents a list. Then you select presented device. Devices don't need IP address configured.

When device is reset to no configuration, it doesn't have IP address nor runs DHCP client ...
by mkx
Fri Aug 23, 2019 7:55 pm
Forum: General
Topic: Firewall Rules PPPoE vs ethernet-port
Replies: 9
Views: 964

Re: Firewall Rules PPPoE vs ethernet-port

Just noticed: on the "non-standard" router the accept filter rule is in chain=forward ... should be in chain=input if IPsec is terminated on router itself.
by mkx
Fri Aug 23, 2019 4:28 pm
Forum: General
Topic: Test for leaking VLAN's
Replies: 4
Views: 512

Re: Test for leaking VLAN's

First off you have to decide how you're supposed to see that a packet has leaked to the wrong VLAN. VLAN ID is obviously a wrong choice (specially so in the untagged section of a VLAN). You could look for packets with sender/receiver MAC address which are not supposed to be in the observed VLAN ... ...
by mkx
Fri Aug 23, 2019 4:20 pm
Forum: General
Topic: Firewall Rules PPPoE vs ethernet-port
Replies: 9
Views: 964

Re: Firewall Rules PPPoE vs ethernet-port

Are you absolutely positive that the "black box router" is transparent regarding udp ports 500 and 1701?

Generally firewall rules don't care about different ports other than using them as additional match criterion.
by mkx
Fri Aug 23, 2019 4:13 pm
Forum: Beginner Basics
Topic: Simplifying my forward chain? [SOLVED]
Replies: 6
Views: 665

Re: Simplifying my forward chain? [SOLVED]

Safer (and sometimes easier) way is to construct a list of explicitly allowed connections and drop the rest at the end. Your current one is the opposite: drop watever you thought it should be dropped and (implicitly) allow the rest. Any way you do it, there's an essential rule missing in your curren...
by mkx
Fri Aug 23, 2019 4:09 pm
Forum: Beginner Basics
Topic: VLAN on ISP connection
Replies: 2
Views: 359

Re: VLAN on ISP connection

The most straightnforward way, but with some limitations which might bite you in the future, would be this: keep ether1 (ISP) off any bridge at all costs create needed vlan interfaces off the ether1 - you probably already created one for VLAN 640 so you need to add one for VLAN 300 and possibly one ...
by mkx
Fri Aug 23, 2019 3:50 pm
Forum: General
Topic: Passive POE question (RB4011iGS+RM / cAP ac)
Replies: 1
Views: 367

Re: Passive POE question (RB4011iGS+RM / cAP ac)

PoE out for RB4011 actually says 600mA for voltages less than 30V and 400mA for voltages above 30V. Specs say about cAP ac consumption that it's 13W without attachments and 24W maximum. I'm not surewhat does count as attachment, but let's say you want to power "bare" cAP acs, so let's calculate with...
by mkx
Fri Aug 23, 2019 9:27 am
Forum: General
Topic: RB960PGS with POE burns in lightning
Replies: 1
Views: 301

Re: RB960PGS with POE burns in lightning

... inside the village there are RB960PGS connected to each other on cat5e cable ... Lightning strikes, even if not really near, can cause considerable voltage inducted in any metallic cable. Which includes cat5e cables if those are not laid inside some steel-reinforced concrete which would shield ...
by mkx
Fri Aug 23, 2019 9:09 am
Forum: Beginner Basics
Topic: How to dumb bridge (?) using hAP ac lite
Replies: 11
Views: 1022

Re: How to dumb bridge (?) using hAP ac lite

... reset the hAP ac lite with no defaults connect ot hAP ac lite using winbox MAC connection and configure the following: I thought that combination of these two steps would leave device with no configuration whatsoever, no bridge etc. I'm pretty sure that the first quoted bullet can not be achiev...
by mkx
Fri Aug 23, 2019 8:16 am
Forum: Beginner Basics
Topic: How to effectively configure 6 hEX units ?
Replies: 5
Views: 691

Re: How to effectively configure 6 hEX units ?

Configure 1 how you want it. Do an /export and then do a full reset on the others and import the .rsc file you made from the first one. Which would cover all but last two OP's points (SSH keys and password) ... those two are only possible to automate by using (binary) backups which should not be us...
by mkx
Fri Aug 23, 2019 8:06 am
Forum: Announcements
Topic: hAP lite
Replies: 389
Views: 164042

Re: hAP lite

Something like RB450Gx4 ...?
Or, if amount of RAM and storage offered by RB450Gx4 is not needed, a RBD52G (with wireless disabled) might be considered as well ... comes with a case and lower price-tag while offering same wired performance.
by mkx
Thu Aug 22, 2019 1:44 pm
Forum: General
Topic: fasttrack or RAW is better for blocking ddos attacks?
Replies: 2
Views: 320

Re: fasttrack or RAW is better for blocking ddos attacks?

On the other hand, if you need connection tracking enabled, then RAW is the place to drop DDOS packets.
by mkx
Thu Aug 22, 2019 8:40 am
Forum: Beginner Basics
Topic: How to dumb bridge (?) using hAP ac lite
Replies: 11
Views: 1022

Re: How to dumb bridge (?) using hAP ac lite

I'm not sure about the QuickSet modes (I'm pretty sure there isn't one for exactly this setup, but there might be something really close to it ... and I may be entirely wrong about this), but you could go this way: download and install winbox to your management computer (if you're not familiar: that...
by mkx
Thu Aug 22, 2019 8:33 am
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 609
Views: 154592

Re: RouterOS v7.0 beta1 - when?

Maybe you are going backwards :)

Seems like that indeed :wink:

I certainly hope that folders from @Normis' screenshot are created in advance and that 7.0alpha219 was empty at the time ... which would mean that there are 219 alpha releases to go before we get some public RC :mrgreen:
by mkx
Wed Aug 21, 2019 3:43 pm
Forum: Beginner Basics
Topic: Remote Winbox access blocked from IP Services IP auto fill in from address, How do i stop the auto config
Replies: 1
Views: 293

Re: Remote Winbox access blocked from IP Services IP auto fill in from address, How do i stop the auto config

There was a winbox vulnerability present for quite a while which allowed remote user to use winbox service without knowing correct password (and username). You may want to check this thread to check if your problems are related ...
by mkx
Wed Aug 21, 2019 9:15 am
Forum: General
Topic: question about CCR 1072 CPU
Replies: 3
Views: 522

Re: question about CCR 1072 CPU

CPU producer marks CPUs with stock frequency with a reason. And the reason is that according to tests (and 6-sigma process) the CPU will run at stock frequency without a glitch for designed life-time. If the same CPU is run at higher frequency, it might not run without a glitch (over-clocking tricks...
by mkx
Wed Aug 21, 2019 9:03 am
Forum: General
Topic: Question about CCR and inter-vlan routing performances
Replies: 7
Views: 831

Re: Question about CCR and inter-vlan routing performances

I am more concerned if the CCR can use more than one CPU core when you have all traffic on 1 interface. (normally when you run 8 different interfaces the interrupt load and part of the filtering is spread over 8 cores) Even if interrupts are mapped statically (i.e. portX always interrupts coreY) - ...
by mkx
Tue Aug 20, 2019 10:57 pm
Forum: General
Topic: CCR1036 inter-vlan routing performance issue
Replies: 1
Views: 257

Re: CCR1036 inter-vlan routing performance issue

I'm afraid you're hitting the ceiling for single-connection throughput. Routing is single core per connection. If you'll test multiple parallel connections (e.g. 10), router will use more cores and cumulative throughput will be better.
by mkx
Tue Aug 20, 2019 10:52 pm
Forum: General
Topic: Not receive Advertising Link Partner SFP+, to SFP+
Replies: 1
Views: 299

Re: Not receive Advertising Link Partner SFP+, to SFP+

Auto negotiation is set to disabled. In this case there is no advertisements ... instead parameters are hard set to 1Gbps full-duplex. If the other end is not set to exactly the same, it's likely to see link failure...
by mkx
Tue Aug 20, 2019 10:46 pm
Forum: Beginner Basics
Topic: 4G LTE Confusion
Replies: 3
Views: 536

Re: 4G LTE Confusion

SXT-4g support ONLY 4G. It will not connect over anything other. SXT-LTE support 4G+3G+2G. In addition to that, 4G supports less of commonly used frequency bands than LTE (bands 1 - 2100MHz and 8 - 900 MHz). Also TDD band support is different. Whether this matters or not ... you'll have to find out...
by mkx
Tue Aug 20, 2019 3:02 pm
Forum: General
Topic: 1:1 Nat from ISP Can't port forward
Replies: 2
Views: 382

Re: 1:1 Nat from ISP Can't port forward

Probably you don't need netmap, you rather need (a few) simple DST-NAT rules ... where dst-address is router's WAN IP address (192.168.0.1) ... router knows nothing about real WAN IP, it is already hidden by ISP's modem.
by mkx
Tue Aug 20, 2019 12:36 pm
Forum: General
Topic: Feature requests
Replies: 1159
Views: 207333

Re: Feature requests

2. With your topic you want to say that the accuracy difference NTP+1PPS versus IEEE1588 is insignificant? 3. If in the future I decide to use a PTP/IEEE1588 grandmaster server and broadcast/unicast the clock via a VLAN, will this process of tagging/untagging have a big impact on the accuracy of th...
by mkx
Tue Aug 20, 2019 12:10 pm
Forum: General
Topic: Feature requests
Replies: 1159
Views: 207333

Re: Feature requests

1. Is there any component/hardware (eg: GPS) of a Mikrotik equipment which can provide to the other LAN equipment such kind of signal (1PPS)? 1. No idea. If I have to choose, then I'd hesitantly choose a yes. According to wiki (https://wiki.mikrotik.com/wiki/Manual:System/GPS): Note: The time is no...
by mkx
Tue Aug 20, 2019 11:30 am
Forum: General
Topic: RB450G to RB450G☓4 How to Transfer State
Replies: 10
Views: 1035

Re: RB450G to RB450G☓4 How to Transfer State

... would like to transfer my DNS cache of my establish, related IP state to the new router. The old router I had kept the default IP address (192.168.88.1); however, on the new router, the address and range is 10.0.8.2-10.0.8.254 with router on 10.0.8.1. You can't. Connection tracking states are m...
by mkx
Mon Aug 19, 2019 10:05 pm
Forum: General
Topic: Feature requests
Replies: 1159
Views: 207333

Re: Feature requests

2. If you use NTP (which is the most precise timing protocol supported by mikrotik) to propagate the time, then I don't think you gain much by using 1PPS source ... Precission gain will have order of magnitude of milliseconds and that's also order of magnitude of precission obtainable using NTP ove...
by mkx
Mon Aug 19, 2019 9:37 pm
Forum: General
Topic: Feature requests
Replies: 1159
Views: 207333

Re: Feature requests

Still I want to ask you about 1PPS signal. 1. Is there any component/hardware (eg: GPS) of a Mikrotik equipment which can provide to the other LAN equipment such kind of signal (1PPS)? 2. I have a heX router (NTP client) which is synchronized to a RB1100AH (NTP server). Directly connected to heX, t...
by mkx
Mon Aug 19, 2019 5:15 pm
Forum: General
Topic: Feature requests
Replies: 1159
Views: 207333

Re: Feature requests

Answer to questions 1,2,4 and 5 is: No. Variation of answer to question 2: most decent switches/routers are good enough as a (single?) step in otherwise fully IEEE1588-compliant path if they are lightly loaded so that delay jitter is really low. This way the additional constant delay due to active d...
by mkx
Sun Aug 18, 2019 11:30 am
Forum: Wireless Networking
Topic: Bridge VLAN performance drop
Replies: 1
Views: 325

Re: Bridge VLAN performance drop

CRS3xx should have HW offload support for VLANs ... if things are configured properly it should not experience any slowdowns in intra-VLAN frame forwarding. You shoukd be aware that CRS devices are essentially switches and L3 (routing) performance is lagging far behind. So whether the observed 30% p...
by mkx
Sat Aug 17, 2019 6:24 pm
Forum: Beginner Basics
Topic: Routing both lan and wan on one interface
Replies: 1
Views: 356

Re: Routing both lan and wan on one interface

It is possible and I'm sure there are many ways to do it. From L2 (connectivity) point of view, you can use separate VLANs to separate different networks (WAN v.s. LAN) passing the same wire. From L3 point kf view, you may want to consider if firewalling the WAN-addressed virtual server should be do...
by mkx
Sat Aug 03, 2019 9:19 pm
Forum: General
Topic: Transparent NAT
Replies: 5
Views: 558

Re: Transparent NAT

Most LTE modems playing smart by doing NAT themselves are not configurable enough to do netmap-style of NAT ... even if they do, you should find a way to configure that on the LTE modem thingy, nothing to be done on RB. And since you want to perform NAT on CCR in a smart way, you can't do netmap-sty...
by mkx
Sat Aug 03, 2019 7:31 pm
Forum: RouterBOARD hardware
Topic: CRS112x strange issue [SOLVED]
Replies: 7
Views: 1006

Re: CRS112x strange issue [SOLVED]

How are PCs set-up ... IP address, subnet mask, default gateway? Is there a DHCP server involved or you set them up manually?
by mkx
Sat Aug 03, 2019 5:07 pm
Forum: RouterBOARD hardware
Topic: CRS112x strange issue [SOLVED]
Replies: 7
Views: 1006

Re: CRS112x strange issue [SOLVED]

Did you tey to reboot CRS after change of IP? It shouldn't matter, but who knows ...

Does /interface bridge port print show 'H' in flags column for ether and sfp ports?
by mkx
Sat Aug 03, 2019 2:35 pm
Forum: Beginner Basics
Topic: Access DSL modem in "bridge mode" behind Mikrotik [SOLVED]
Replies: 12
Views: 1225

Re: Access DSL modem in "bridge mode" behind Mikrotik [SOLVED]

When you're testing ping from PfSense, does counter of the appropriate masquerade rule increase?
by mkx
Sat Aug 03, 2019 1:04 pm
Forum: Beginner Basics
Topic: Not showing IP on connected devices [SOLVED]
Replies: 13
Views: 1094

Re: Not showing IP on connected devices [SOLVED]

Please post output of command /export hide-sensitive (run it from a command window) ... and obfuscate public addresses ... paste it inside [code][/code] environment for better readability.

No need for verbosity, but do post complete setup, sometimes problems are hidden elsewhere.
by mkx
Sat Aug 03, 2019 12:58 pm
Forum: Beginner Basics
Topic: Two VLANs in a bridge or two bridges
Replies: 2
Views: 453

Re: Two VLANs in a bridge or two bridges

Option with two bridges allows HW offload on ether ports of one of bridges (probably you want this on LAN bridge), while single-bridge-multiple-VLAN does not if VLANs are configured on bridge.. If functionality-wise you're happy with your current setup, then you should stick to it. If you stick to t...
by mkx
Sat Aug 03, 2019 12:30 pm
Forum: Beginner Basics
Topic: Access DSL modem in "bridge mode" behind Mikrotik [SOLVED]
Replies: 12
Views: 1225

Re: Access DSL modem in "bridge mode" behind Mikrotik [SOLVED]

Does PfSense know about 172.16.2.0/24? Or it treats it as "normal" WAN address?

Can your RB ping Vigor?
by mkx
Sat Aug 03, 2019 10:19 am
Forum: General
Topic: Very simple VLAN
Replies: 16
Views: 1440

Re: Very simple VLAN

Thanks - and is there a simple way to "tie" the two subnets together so that everything (including broadcast) works across them both? Subnets and common broadcast domains don't go together. Unless you know well what you're doing ... but then you wouldn't be asking this particular question here ...
by mkx
Sat Aug 03, 2019 10:16 am
Forum: Beginner Basics
Topic: Port Forward/Passthrough
Replies: 5
Views: 540

Re: Port Forward/Passthrough

By default, connections from LAN to WAN are not restricted in any way. The only requirement us a working SRC-NAT configuration (which is there by default on SOHO models as well unless WAN connectivity type is a non-common one). You're mentioning a /25 WAN subnet which indicates a non-common setup (f...
by mkx
Fri Aug 02, 2019 7:39 pm
Forum: Beginner Basics
Topic: Routing between bridged interfaces and a port [SOLVED]
Replies: 1
Views: 383

Re: Routing between bridged interfaces and a port [SOLVED]

Router needs IP address for each subnet it should be routing to/from.

Read up some IP routing basics ... when you do, don't skip the part with multiple routers in same network, this is the part where fun begins.
by mkx
Fri Aug 02, 2019 2:32 pm
Forum: Beginner Basics
Topic: Router for 1Gbit Wan from Mikrotik (What model?)
Replies: 4
Views: 744

Re: Router for 1Gbit Wan from Mikrotik (What model?)

CRS line are switches with L3 functionality. It's fine to use them with ROS as switches (you don't have to boot SwOS for that). You should go for RB line, such as RB750Gr3 (which probably barely reaches your requirements) or some faster model (those typically come with bigger number of ports) such a...
by mkx
Thu Aug 01, 2019 5:41 pm
Forum: General
Topic: CRS317-1G-16S+RM as storage switch
Replies: 4
Views: 646

Re: CRS317-1G-16S+RM as storage switch

CRSes will be as good as any other managed switch with regard to iSCSI...
by mkx
Thu Aug 01, 2019 3:10 pm
Forum: RouterBOARD hardware
Topic: GPeR question
Replies: 18
Views: 2302

Re: GPeR question

I can see a communication noise happening around here. How about MT guys writing a few lines of technical description about GPeR ... what is it, how it works. Doesn't really have to disclose some patented technology ... I guess it's about a fairly simple (electrical) signal shaper with some DC bypas...
by mkx
Thu Aug 01, 2019 12:33 pm
Forum: RouterBOARD hardware
Topic: RouterBOARD naming
Replies: 47
Views: 24404

Re: RouterBOARD naming

1. I prefer the classic or Hex-S (!) style :-)

Say hello to Flintstones next time you meet them :wink:

Black is new white :lol:
by mkx
Thu Aug 01, 2019 12:30 pm
Forum: RouterBOARD hardware
Topic: 1100x4 unexpected downgrade
Replies: 4
Views: 526

Re: 1100x4 unexpected downgrade

This could happen if NAND was partitioned (for fall-back) and the backup partition never got updated (neither ROS nor config). The mechanism is such that routerboot starts device from the other partition if there's an error making RB to reboot. Power outage counts as such (personally I don't think p...
by mkx
Thu Aug 01, 2019 12:24 pm
Forum: Wireless Networking
Topic: Long range connection
Replies: 17
Views: 1465

Re: Long range connection

Other technologies like 4G use a lot more power and they can do it. Just a tad of nitpicking: user's equipment in 4G operates at similar Tx powers as WiFi (max Tx power at around 20dBm) and also uses similarly shitty antennae (with gain around 0dBi) ... the difference is in the base stations: those...
by mkx
Thu Aug 01, 2019 7:02 am
Forum: Beginner Basics
Topic: No internet on LAN - hex rb750gr3 with E3372
Replies: 12
Views: 1159

Re: No internet on LAN - hex rb750gr3 with E3372

So did you try to add lte1 interface to WAN interface list? Did it do the trick or not?
by mkx
Wed Jul 31, 2019 10:20 pm
Forum: Beginner Basics
Topic: No internet on LAN - hex rb750gr3 with E3372
Replies: 12
Views: 1159

Re: No internet on LAN - hex rb750gr3 with E3372

None of your routing information/config is there?? Probably because all of it is dynamic. /ip route print and /ip address print would reveal lots of things. Before posting output of these commands do obfuscate public IP addresses ... but do it consistently so that it will be obvious what belongs to...
by mkx
Wed Jul 31, 2019 3:49 pm
Forum: Beginner Basics
Topic: NAT is blocking the acess to that port when active
Replies: 2
Views: 379

Re: NAT is blocking the acess to that port when active

Probably your DST-NAT rule is too general. Execute command /ip firewall nat export in a terminal window and post result here.
by mkx
Tue Jul 30, 2019 11:25 pm
Forum: General
Topic: NAT to a local server
Replies: 25
Views: 1880

Re: NAT to a local server

When setting in-interface=bridge NAT should stop working for connections from WAN ...
by mkx
Tue Jul 30, 2019 11:11 pm
Forum: Wireless Networking
Topic: How to get signal-strength from wireless card
Replies: 3
Views: 534

Re: How to get signal-strength from wireless card

Signal strength has its meaning for the receiving party. When device is in station mode, it only talks to single peer and signal strength of that peer is a fairly good indication of the two-way connection quality. When device is in ap mode (any of them), it's talking to many peers and none of them c...
by mkx
Tue Jul 30, 2019 5:31 pm
Forum: General
Topic: Calculating Power Consumption for POE
Replies: 2
Views: 409

Re: Calculating Power Consumption for POE

cAP ac supports PoE-out ... connected PoE client would count as attachment. Some other devices feature USB ports which can be used to connect some power-hungry peripherials, such as LTE modems or flash sticks... Or miniPCIe slots to add wireless or LTE interfaces ... All of those count as attachments.
by mkx
Tue Jul 30, 2019 5:22 pm
Forum: General
Topic: Router OS in GSM environment
Replies: 2
Views: 411

Re: Router OS in GSM environment

Routeros is about data (IP in particular) routing. If you're talking about VoIP, then many people did it. If you're talking about GSM circuit-switched voice, then ROS won't help you. Not many GSM chipsets support digital voice break-out ... and even if some does, it is 64kbps ADPCM or something simi...
by mkx
Mon Jul 29, 2019 11:16 pm
Forum: RouterBOARD hardware
Topic: GPeR question
Replies: 18
Views: 2302

Re: GPeR question

1) Of course it matters (and two port has nothing to do with it) Really ... what's the big difference between 2-port ethernet hub and 2-port ethernet switch? And yes, port count has everything to do with it. Instead of forwarding frame to the other port because forwarding table (MAC address list) o...
by mkx
Mon Jul 29, 2019 5:49 pm
Forum: General
Topic: PPPoE Client as main Link 3G as Backup
Replies: 1
Views: 303

Re: PPPoE Client as main Link 3G as Backup

How about searching for mikrotik dual wan failover using your favourite internet search page? One of top results is this manual page, seems promissing to me.
by mkx
Mon Jul 29, 2019 5:35 pm
Forum: General
Topic: Possible security breach
Replies: 12
Views: 4919

Re: Possible security breach

Old thread, I know, but I think its worth bumping. I had same thing happen to me. There were 2 ptty scripts in my scheduler. I had my router exposed to WAN with default username only a matter of minutes but didnt notice the script until a few days later. I deleted scripts, the admin user, the new r...
by mkx
Sun Jul 28, 2019 2:38 pm
Forum: General
Topic: Login failure for user Radius via api
Replies: 3
Views: 554

Re: Login failure for user Radius via api

API login method has changed.
by mkx
Sun Jul 28, 2019 2:33 pm
Forum: Beginner Basics
Topic: Vlan config and bridging
Replies: 3
Views: 567

Re: Vlan config and bridging

There are many points where things might have turned wrong way. Post output of /export hide-sensitive after you've mangled any remaining sensitive data such as public IP addresses ...
by mkx
Sat Jul 27, 2019 11:18 pm
Forum: Beginner Basics
Topic: Fixed IP using VLANs. How?
Replies: 1
Views: 336

Re: Fixed IP using VLANs. How?

IMHO LAN infrastructure devices should for very same reason have their IP addresses set statically.
by mkx
Fri Jul 26, 2019 8:59 pm
Forum: Wireless Networking
Topic: Wifi equipment for 70m distance behind windows
Replies: 14
Views: 1188

Re: Wifi equipment for 70m distance behind windows

Powering is not a problem...i have power outlet on balcony. A what to use for device in building 1? I'm not sure if supplied power adapter is weatherproof as well ... For the building1 any routerboard with 2.4GHz wireless would do. In absence of other ideas/reasons I'd go with second wAP ac (for no...
by mkx
Fri Jul 26, 2019 8:52 pm
Forum: General
Topic: How debug L2 and IP firewall?
Replies: 4
Views: 480

Re: How debug L2 and IP firewall?

I think you should properly separate ether2 from the rest of LAN on L2 by removing ether2 from brudge and then assure needed communication by routing and firewalling. You'd need separate subnet (probably a /30 would do) for connection between RB and the "untrusted network"'s gateway. If you go this ...
by mkx
Fri Jul 26, 2019 7:25 pm
Forum: General
Topic: How debug L2 and IP firewall?
Replies: 4
Views: 480

Re: How debug L2 and IP firewall?

  1. Are you testing connectivity from LAN device from one subnet towards router's address in another subnet or you're testing between LAN devices?
  2. Post complete configuration (output of command /export hide-sensitive and obfuscate sensitive data, such as public IP address)
by mkx
Fri Jul 26, 2019 7:09 pm
Forum: Wireless Networking
Topic: Wifi equipment for 70m distance behind windows
Replies: 14
Views: 1188

Re: Wifi equipment for 70m distance behind windows

If we set aside problem with powering (wireless powering wasn't seriously developed ever since Tesla failed to extort more money from J.P.Morgan), a wAP ac would make a good wireless hop.

As both hops (2.4 and 5GHz) would essentially be point-to-point, I'd configure them as nstreme bridges.
by mkx
Fri Jul 26, 2019 4:21 pm
Forum: Beginner Basics
Topic: VLAN 1003 über eigenen Switchport
Replies: 2
Views: 339

Re: VLAN 1003 über eigenen Switchport

Depends on how things are set up currently. If AP tags the traffic itself, then you can set port vlan security so that on ingress it only accepts tagged frames. A random passer-by won't know it needs to tag packets so for him the port will seem useless. If one knows to tag frames with correct VID, h...
by mkx
Fri Jul 26, 2019 1:51 pm
Forum: General
Topic: Feature requests
Replies: 1159
Views: 207333

Re: Feature requests

Need feature to detect if device have poe-out interfaces - now any poe-command (even print command) causes error in script if HW doesn't have poe-out interfaces... I don't know how to script it, but possibility is available already: /interface print where type=pppoe-out pppoe has no relation to poe...
by mkx
Fri Jul 26, 2019 1:49 pm
Forum: Wireless Networking
Topic: Wifi equipment for 70m distance behind windows
Replies: 14
Views: 1188

Re: Wifi equipment for 70m distance behind windows

If the reason for avoiding LAN cables is fear for interference from power lines to UTP cables or fear for some power surges, then you could use fibre connection between the "main wireless hop" (building-2-building) and their hAP ac2 ... dumb media converters supporting multi-mode fibre and 10/100 Mb...
by mkx
Fri Jul 26, 2019 1:41 pm
Forum: Wireless Networking
Topic: Intel Wireless Cards for ROS
Replies: 2
Views: 376

Re: Intel Wireless Cards for ROS

As far as I understand, x86 is not actively developed anymore ... hence no new drivers. Hence no support for newer hardware. MT suggests to switch over to CHR ... for one thing MT down't have to develop tons of drivers, VM abstraction layer takes care of that. With ROS7 things might change - who kno...
by mkx
Fri Jul 26, 2019 1:24 pm
Forum: General
Topic: Feature requests
Replies: 1159
Views: 207333

Re: Feature requests

Need feature to detect if device have poe-out interfaces - now any poe-command (even print command) causes error in script if HW doesn't have poe-out interfaces...

I don't know how to script it, but possibility is available already: /interface print where type=pppoe-out
by mkx
Thu Jul 25, 2019 10:43 pm
Forum: General
Topic: VLAN issue
Replies: 8
Views: 720

Re: VLAN issue

My thinking: ports ether23 and ether24 are set up equally. As VLANs seemingly work as they should on ether24 (Sonicwall trunk ... when connecting to different access ports computer becomes part of correct VLAN) - you might want to verify this by connecting Sonicwall to ether23 ... it serms that CRSe...
by mkx
Thu Jul 25, 2019 10:34 pm
Forum: Beginner Basics
Topic: Significant Speed Issues with MikroTik [SOLVED]
Replies: 18
Views: 1580

Re: Significant Speed Issues with MikroTik [SOLVED]

LAN IP address is bound to ether2 which is slave device of bridge ... and that's wrong. Move it to bridge interface. Where would I change this setting? I found the WAN ethernet but according to winbox it is already linked to the bridge. Perhaps I am looking in the wrong spot? That would be in /ip a...
by mkx
Thu Jul 25, 2019 8:50 pm
Forum: Beginner Basics
Topic: Significant Speed Issues with MikroTik [SOLVED]
Replies: 18
Views: 1580

Re: Significant Speed Issues with MikroTik [SOLVED]

LAN IP address is bound to ether2 which is slave device of bridge ... and that's wrong. Move it to bridge interface. Any good reason to limit advertised speeds on ether ports only to 1000-full? Autonegotiation will select it if both link partners support it, negotiation of anything else indicates pr...
by mkx
Thu Jul 25, 2019 8:01 pm
Forum: Beginner Basics
Topic: How change to swos in fiberbox csr105
Replies: 3
Views: 407

Re: How change to swos in fiberbox csr105

Check it yourself, specs for all switches are here . I guess they call them switches even though they run ROS because their CPU is weak and unable of routing anywhere near wirespeed, but they feature decent switch chip capable of wirespeed switching. Anyway, on most dual-OS devices ROS offers same s...
by mkx
Thu Jul 25, 2019 7:54 pm
Forum: Beginner Basics
Topic: Significant Speed Issues with MikroTik [SOLVED]
Replies: 18
Views: 1580

Re: Significant Speed Issues with MikroTik [SOLVED]

First thing is to profile CPUs to get idea whether CPU is bottleneck ... and which subsystem is hit most.
by mkx
Thu Jul 25, 2019 7:29 pm
Forum: General
Topic: VLAN issue
Replies: 8
Views: 720

Re: VLAN issue

OK,I'll assume then the print-out is fine. What I just noticed: ether21 and ether22 are not set to be members of VLAN 100 (neither tagged nor untagged) on any of switches. Which explains why clients of third SSID don't get anything ... when AP is connected to any of ether21 or ether22 ports. It does...
by mkx
Thu Jul 25, 2019 4:57 pm
Forum: General
Topic: VLAN issue
Replies: 8
Views: 720

Re: VLAN issue

What you posted as output of /interface bridge vlan print doesn't correspond to how it should be configured (nor how you wanted it configured). The difference between /interface bridge vlan export and /interface bridge vlan print is that the former shows configuration directives and the later shows ...
by mkx
Thu Jul 25, 2019 4:52 pm
Forum: RouterBOARD hardware
Topic: HEX S RB760iGS → console mode...?
Replies: 4
Views: 600

Re: HEX S RB760iGS → console mode...?

You can use Woobm USB gadget to connect to router's console ... I can't vouch that it works with all RB devices but I haven't heard it doesn't either.
by mkx
Thu Jul 25, 2019 4:46 pm
Forum: Wireless Networking
Topic: Question use mikrotik equipment with unifi
Replies: 1
Views: 379

Re: Question use mikrotik equipment with unifi

For RB750Gr3 it's not so important the number of wireless clients, more important is how active those clients will be ... in particular number of open connections. If those clients will be decently non-active, they'd have a few thousand connections in total open at any given time ... which is not a ...
by mkx
Thu Jul 25, 2019 4:06 pm
Forum: General
Topic: VLAN issue
Replies: 8
Views: 720

Re: VLAN issue

One thing that strikes me odd: /interface bridge vlan add bridge=bridge tagged= " ether23-TRUNK,ether24-TRUNK,sfpplus1-TRUNK,sfpplus2-\ TRUNK,ether21-TRUNK,ether22-TRUNK " untagged= " ether1-VLAN10,ether2-VLAN10,e\ ther3-VLAN10,ether4-VLAN10,ether5-VLAN10,ether6-VLAN10,ether7-VLAN10,ether\ 8-VLAN10,...
by mkx
Thu Jul 25, 2019 4:00 pm
Forum: General
Topic: Multicast CPU Load Switch CRS328
Replies: 3
Views: 340

Re: Multicast CPU Load Switch CRS328

When I capturing with Wireshark, I see also the Multicast package on Members which are not subscriping the Multicast. So IGMP Snooping ist not working, is that right? Of course IGMP Snooping is activated. In our Cisco Enviroment its all working perfectly. IGMP snooping seems to be borken on Mikroti...
by mkx
Thu Jul 25, 2019 3:44 pm
Forum: Beginner Basics
Topic: Routing wireless to ethernet doesn't work
Replies: 11
Views: 726

Re: Routing wireless to ethernet doesn't work

Packets targeting directly accessible subnets will leave via corresponding interface. The original problem involves 3 subnets: 192.168.89.0./24 ... computer has address 192.168.89.15 and can communicate with any devices withing this subnet (including 192.168.89.1 which happens to be gateway for this...
by mkx
Thu Jul 25, 2019 3:31 pm
Forum: Announcements
Topic: v6.45.2 [stable] is released!
Replies: 206
Views: 35746

Re: v6.45.2 [stable] is released!

Not any direct method to access to flash neither ?
Nope. Not the system part of it.
by mkx
Thu Jul 25, 2019 2:36 pm
Forum: General
Topic: Multicast CPU Load Switch CRS328
Replies: 3
Views: 340

Re: Multicast CPU Load Switch CRS328

Verify that the ports in question (all of them) are actually hardware accelerated ... execute /interface bridge port print , the HW accelerated ports have flag H displayed in flags area. Note that all ports members of affected by multicast[*] need to be HW accelerated, if one single port is not, the...
by mkx
Thu Jul 25, 2019 2:29 pm
Forum: General
Topic: How to allow an URL for a specific port
Replies: 7
Views: 488

Re: How to allow an URL for a specific port

What we need is to open the 3000 port in our Mikrotik but not for all the inbound traffic or all the addresses. We need to open it only for a specific URL that we have for a voting platform. Port 3000 is not standard port for any particular protocol. So what protocol is it (kids doing programming t...
by mkx
Thu Jul 25, 2019 2:23 pm
Forum: Beginner Basics
Topic: Routing wireless to ethernet doesn't work
Replies: 11
Views: 726

Re: Routing wireless to ethernet doesn't work

The problem was in the routing information on your computers ... when computer gets configuration via DHCP, it usually gets default route. If some computer receives two such configurations (for two distinct interfaces), then it's somehow undefined how it routes own traffic. It receives two different...
by mkx
Thu Jul 25, 2019 2:19 pm
Forum: Announcements
Topic: v6.45.2 [stable] is released!
Replies: 206
Views: 35746

Re: v6.45.2 [stable] is released!

What actually that fix_space.npk does ??? Somewhere around ROS 6.41 the upgrade process could sometimes break and leave some files un-acounted for. Those could be removed only by net-installing the device. This npk tries to find such orphaned files and removes them. Newer versions are supposedly no...
by mkx
Thu Jul 25, 2019 2:12 pm
Forum: Wireless Networking
Topic: 2GHz WiFi 40MHz width best channel
Replies: 7
Views: 678

Re: 2GHz WiFi 40MHz width best channel

40MHz channel is contigous, so if you configure it as 2412-Ce, it will actually occupy frequency band between 2402 MHz and 2442 MHz. N.b. all published frequencies refer to channel centre frequency. So essentially it will be CH 1+5. What you're asking for (CH 3+11) would result in non-contigous chan...
by mkx
Thu Jul 25, 2019 12:46 pm
Forum: Announcements
Topic: v6.45.2 [stable] is released!
Replies: 206
Views: 35746

Re: v6.45.2 [stable] is released!

On hAP ac2 (and other devices witch tiny flash disks), root of what you see in /files print is in RAM disk and gets wiped after every restart. The non-volatile file storage is under /flash ...
by mkx
Thu Jul 25, 2019 12:41 pm
Forum: Beginner Basics
Topic: Routing wireless to ethernet doesn't work
Replies: 11
Views: 726

Re: Routing wireless to ethernet doesn't work

Do the computers on both networks know to use your RB as gateway between the two networks?

Or to ask it differently: is this RB the only router in the whole LAN story or is it additional router but there are other main routers in both subnets?
by mkx
Thu Jul 25, 2019 12:37 pm
Forum: Beginner Basics
Topic: How change to swos in fiberbox csr105
Replies: 3
Views: 407

Re: How change to swos in fiberbox csr105

Specifications for CRS105 (fiberbox) only mention RouterOS as supported OS. Specifications for CRS switches that support SwitchOS (e.g. CRS326) do mention that ...
by mkx
Thu Jul 25, 2019 12:28 pm
Forum: Announcements
Topic: v6.45.2 [stable] is released!
Replies: 206
Views: 35746

Re: v6.45.2 [stable] is released!

[*] it is possible to have two (or more) ROS versions installed in unit has flash storage with size of 64MB or more. In this case, one can partition flash to two halves and run different version of ROS in both partitions. If ROS crashes or fails to boot from one partition, it'll automatically try t...
by mkx
Thu Jul 25, 2019 9:11 am
Forum: RouterBOARD hardware
Topic: Quectel EP06-E and wAP R ac (RBwAPGR-5HacD2HnD)
Replies: 8
Views: 1471

Re: Quectel EP06 and wAP R ac (RBwAPGR-5HacD2HnD)

I suspect that the B28 tower is at a different location to the other tower doing band 3&7!? All 3 cells from different bands are run by the very same baseband hardware (same eNB ID). Which means that quite likely all 3 cells are located on the same tower. Quite likely because RF gear (DAC, power am...
by mkx
Wed Jul 24, 2019 10:56 pm
Forum: General
Topic: Port 80 redirect [SOLVED]
Replies: 14
Views: 723

Re: Port 80 redirect [SOLVED]

I can understand the sentiment of tourists passing by. Anyhow I'm inviting you for a beer (or if you dislike non-native beer which I would understand fully) some other beaverage when you hapoen to pass by ...
by mkx
Wed Jul 24, 2019 10:28 pm
Forum: General
Topic: Port 80 redirect [SOLVED]
Replies: 14
Views: 723

Re: Port 80 redirect [SOLVED]

Btw one of my biggest surprises in your country was to find a stallion on the menu of a normal restaurant. Yeah, I know ... I guess this is the real reason for the horse-loving Brits to leave EU :wink: Regarding the highway vignettes: it's a simple tax on all those Czechs and Polaks hoarding toward...
by mkx
Wed Jul 24, 2019 10:15 pm
Forum: General
Topic: IPSec performance
Replies: 4
Views: 682

Re: IPSec performance

Profile the CPU usage to see where CPU cycles are spent. In addition check the packet size of data traffic. If apps are using full 1500 byte frames, then IPsec will have to fragment them (due to own overhead) which means double frame rate and PPS is a constraint as well. Either reduce packet size (w...
by mkx
Wed Jul 24, 2019 10:06 pm
Forum: General
Topic: Feature request for v7.x
Replies: 269
Views: 63557

Re: Feature request for v7.x

I'd say that such an expensive hardware (as CCRs are) Apparently we have different definition of expensive... I think our CCR1009's are quite cheap. Perhaps not ... but we might have different perspectives. Me, for example, I associate CCRs with decent LAN size which deserves some dedicated boxes t...
by mkx
Wed Jul 24, 2019 5:30 pm
Forum: General
Topic: Getting a configuration suggestion
Replies: 5
Views: 347

Re: Getting a configuration suggestion

If the internet service is for a hotel, why would you even consider allowing one guest to hog all the bandwidth MKX.

As I wrote: it's up to OP to decide, I know what I would do (but that's not the point). I just mentioned a few possible reasons for choosing one over another, that's all.
by mkx
Wed Jul 24, 2019 5:22 pm
Forum: General
Topic: NTP server client troubleshooting
Replies: 2
Views: 273

Re: NTP server client troubleshooting

The dynamic servers come from DHCP server. If you configured IP address(es) of router manually or if DHCP server, serving IP config on particular VLAN, doesn't include list of NTP servers in its address lease, then the list of dynamic servers will be empty. If ntp client displays empty list of "dyna...
by mkx
Wed Jul 24, 2019 5:09 pm
Forum: General
Topic: Port 80 redirect [SOLVED]
Replies: 14
Views: 723

Re: Port 80 redirect [SOLVED]

I think the quote is "skin the cat" one shears sheep! ;-P
I don't eat cats and I don't know any other reason to skin an animal :wink:
by mkx
Wed Jul 24, 2019 5:06 pm
Forum: General
Topic: Bond: link loss is not detected by Mikrotik (LACP)
Replies: 5
Views: 444

Re: Bond: link loss is not detected by Mikrotik (LACP)

You mean that MII alone is not able to detect outage if only a single direction of a fiber link is affected? The whole thing depends heavily on how particular interface vendor implemented MII stuff inside their hardware ... But yes, generally speaking fiber modules have no idea about Tx part of the...
by mkx
Wed Jul 24, 2019 4:46 pm
Forum: General
Topic: Feature request for v7.x
Replies: 269
Views: 63557

Re: Feature request for v7.x

I'd say that such an expensive hardware (as CCRs are) sitting idle at some cheap enterprise, is a rare species which doesn't warrant developing new functionality. I mean ... having idle CCR costing anywhere between 425€ and 3000€, but saving some 1000€ by not buying a modest x86_64 server which woul...
by mkx
Wed Jul 24, 2019 4:38 pm
Forum: Beginner Basics
Topic: Virtual AP Mac address... use same ones?
Replies: 1
Views: 214

Re: Virtual AP Mac address... use same ones?

Theoretically you can safely apply MAC address exported from old device. The only limitation is that another wireless device with same MAC address should not exist in the neighbourhood. So if the original device was permanently switched off, you're good to (re)use the same MAC.
by mkx
Wed Jul 24, 2019 4:30 pm
Forum: General
Topic: Port 80 redirect [SOLVED]
Replies: 14
Views: 723

Re: Port 80 redirect [SOLVED]

@mkx: Or you can use ...

I know there are plenty of ways to "skin the sheep" ... I was just pointing out potential side effect if OP followed advice by @sindy as it was originally written. After one is aware of the problem, it's quite easy to find the way around ...
by mkx
Wed Jul 24, 2019 4:22 pm
Forum: General
Topic: RB4011, Ubiquiti devices, VLANs and IPSEC
Replies: 4
Views: 341

Re: RB4011, Ubiquiti devices, VLANs and IPSEC

All VLAN setup on RB4011 is ... well, wrong. I suggest you to read through this tutorial . Come back if things don't work after reading and understanding the tutorial. As to the roadwarior access ... it's hard to tell as you didn't post complete setup (at least /ip firewall mangle section is missing...
by mkx
Wed Jul 24, 2019 2:22 pm
Forum: General
Topic: Getting a configuration suggestion
Replies: 5
Views: 347

Re: Getting a configuration suggestion

There are two things which are to be corrected: If I didn't overlook something in the firewall filter list for chain=input , then access to DNS service from internet is allowed. Which is not good. There isn't a rule allowing it indeed, but for sanity sake there should be a rule /ip firewall filter a...
by mkx
Wed Jul 24, 2019 2:07 pm
Forum: General
Topic: Feature request for v7.x
Replies: 269
Views: 63557

Re: Feature request for v7.x

A solution like ha proxy in router os v7 would be usefull I like to run multiple ssl sites behind my mikrotik router on 1 public ip and lets encrypt support to automaticly secure them with ssl The only sensible part of this wish is "letsencrypt support for SSL certificates" ... If you're running mu...
by mkx
Wed Jul 24, 2019 2:03 pm
Forum: Announcements
Topic: v6.45.2 [stable] is released!
Replies: 206
Views: 35746

Re: v6.45.2 [stable] is released!

The point is that I haven't been able to restore the factory firmware (6.43) doing a factory reset (pressing button before turning on the power). Routerboards don't have dual firmware installed [*]. Factory reset only returns configuration to factory default [**], not the software version. Informat...
by mkx
Wed Jul 24, 2019 11:31 am
Forum: General
Topic: Port 80 redirect [SOLVED]
Replies: 14
Views: 723

Re: Port 80 redirect [SOLVED]

So add in-interface=your-wan-interface name or dst-address-type=local (or both) to your dst-nat rule ... My understanding is, that if you only set dst-address-type=local , you loose access to webfig (web GUI for administering routerboards ... in case you care, I personally use it). If you want to k...
by mkx
Wed Jul 24, 2019 11:20 am
Forum: General
Topic: Getting a configuration suggestion
Replies: 5
Views: 347

Re: Getting a configuration suggestion

The major thing, which might help, is to move firewall rule add action=fasttrack-connection chain=forward connection-state=established,related right above rule add action=accept chain=forward connection-state=established,related As it is now, nothing gets fast-tracked (and fast-tracking does speed-u...
by mkx
Wed Jul 24, 2019 11:08 am
Forum: General
Topic: Port 80 redirect [SOLVED]
Replies: 14
Views: 723

Re: Port 80 redirect [SOLVED]

The rule is too greedy and actually captures all connections targeting port 80 (even those from LAN towards internet). You should limit that to connections arriving through WAN interface. You can do it in one of the following two ways: add chain=dstnat action=dst-nat to-addresses=10.0.0.2 protocol=t...
by mkx
Wed Jul 24, 2019 9:27 am
Forum: Wireless Networking
Topic: 160MHz support for US RB4011
Replies: 4
Views: 646

Re: 160MHz support for US RB4011

For 160MHz channel, it would have to be possible to use a contigous 160MHz frequency channel. Which with limitations from "united states3" is not the case: chunk from 5170MHz to 5250MHz is exactly 80MHz wide, thus it can be used for 80MHz channel or 80+80MHz channel (one half of it) chunk from 5735M...
by mkx
Tue Jul 23, 2019 10:58 pm
Forum: RouterBOARD hardware
Topic: NetInstall -> Flashing with RouterOS 6.45.1
Replies: 8
Views: 1080

Re: NetInstall -> Flashing with RouterOS 6.45.1

Hello Mikrotik support,

This forum is not really official support channel, rather users's chat room with occasional MT personnel fly-by. If you expect response from MT, contact them at support@mikrotik.com ...
by mkx
Tue Jul 23, 2019 8:05 pm
Forum: General
Topic: Bond: link loss is not detected by Mikrotik (LACP)
Replies: 5
Views: 444

Re: Bond: link loss is not detected by Mikrotik (LACP)

Mii monitoring works approximately as well as speed (and duplex) auto-negotiation. I.e. it can sometimes fail if connection is marginal ... Which opens a question: is there a good reason not to allow autonegotiation on those two links?
by mkx
Tue Jul 23, 2019 4:03 pm
Forum: Wireless Networking
Topic: Mikrotik AP using 40Mhz but not find on the AP on the Ubiquiti station?
Replies: 3
Views: 440

Re: Mikrotik AP using 40Mhz but not find on the AP on the Ubiquiti station?

A few days ago I was playing with similar setup (PtP link on 5GHz) and I had a similar problem. I was using two hAP ac lites (so Mikrotik on both sides). One thing: according to wikipedia list of channels , frequency 5800 doesn't seem to be a valid channel, it seems like one should choose either 578...
by mkx
Tue Jul 23, 2019 3:53 pm
Forum: General
Topic: [ASK] FastTrack for SpeedTest
Replies: 14
Views: 930

Re: [ASK] FastTrack for SpeedTest

Of course it will not be useful for fasttrack, because connection marks are not processed for fasttracked connections. I guess it may serve OP's purpose ... connection marks are not processed for fasttracked connections because once a connection is fasttracked, it can not be un-fasttracked and will...
by mkx
Tue Jul 23, 2019 10:58 am
Forum: General
Topic: Watchdog biting on an unreliable connection - queue issue
Replies: 2
Views: 232

Re: Watchdog biting on an unreliable connection - queue issue

My personal view (I'm sure many around here will disagree) is that ICMP with so many network admins (and "admins") blocking it is inherently unreliable. Thus it's unfit to depend upon for device watchdog unless you control all devices involved. E.g. it is probably fine to use pings against some othe...
by mkx
Tue Jul 23, 2019 10:44 am
Forum: Beginner Basics
Topic: Q: src.port <> dst.port
Replies: 8
Views: 757

Re: Q: src.port <> dst.port

Regarding firewall > nat forwarding settings .. In general>src.port field there is "25,80,443,587" and in action>dst.port field there is "25-587" Be careful. There are 3 distinct port settings: src-port , dst-port and to-ports ... src-port check the port used by client. Usually that's some random h...
by mkx
Mon Jul 22, 2019 10:18 pm
Forum: Beginner Basics
Topic: 1wan + 2 lan isolated from each other
Replies: 63
Views: 4416

Re: 1wan + 2 lan isolated from each other

Sigh ... You mentioned: you don't have corresponding /ip dhcp-server network nor /ip dhcp-server ... . Maybe I don´t understand you but I think I do have the network: add address=192.168.1.200/30 dhcp-option=option_para_deco dns-server=172.26.23.3 gateway=192.168.1.1 \ netmask=24 and no need for a d...
by mkx
Mon Jul 22, 2019 7:09 pm
Forum: RouterBOARD hardware
Topic: Mikrotik RBSXTR (No Modem) 9dBi 60 degree LTE Antenna
Replies: 8
Views: 1011

Re: Mikrotik RBSXTR (No Modem) 9dBi 60 degree LTE Antenna

I'm not to knowledgeable when it comes to antennas. The negative gain... this is usually in relation to something? In short: yes, this is relative figure - imaginnary truly omni-directional antenna would have gain of 0dBi). Higher the number, better signal. The most ordinary dipole antennae have ga...
by mkx
Mon Jul 22, 2019 4:29 pm
Forum: General
Topic: IPTV Lan Help.
Replies: 10
Views: 788

Re: IPTV Lan Help.

Solution by @sindy is for sure more resource-effective. I just wrote minimum changes from your current setup. I'd suggest you first implement my changes and if IPTV starts to work, go ahead and implement what @sindy wrote.
by mkx
Mon Jul 22, 2019 4:27 pm
Forum: General
Topic: Bond: link loss is not detected by Mikrotik (LACP)
Replies: 5
Views: 444

Re: Bond: link loss is not detected by Mikrotik (LACP)

What is setting of link-monitoring attribute of bond? Not every interface and every mode supports all possible values.
by mkx
Mon Jul 22, 2019 4:21 pm
Forum: General
Topic: NAT and Firewall forward rules
Replies: 5
Views: 406

Re: NAT and Firewall forward rules

Default ROS firewall includes the following two rules: ... filter add chain=forward action=accept connection-state=established,related,untracked comment="defconf: accept established,related, untracked" ... filter add chain=forward action=drop connection-state=new connection-nat-state=!dstnat in-inte...
by mkx
Mon Jul 22, 2019 4:09 pm
Forum: Beginner Basics
Topic: New filter rules ?
Replies: 6
Views: 729

Re: New filter rules ?

Rules #0, #6 and #7 are around for quite some time (let's say at least since 6.42 if not earlier ... rule #0 is probably around ever since fast-track got introduced) ... rule #4 is new to me as well ...
by mkx
Mon Jul 22, 2019 4:03 pm
Forum: Beginner Basics
Topic: 1wan + 2 lan isolated from each other
Replies: 63
Views: 4416

Re: 1wan + 2 lan isolated from each other

I don't know what exactly you mean by "I must have stopped the ipTV service" ... but you don't have DHCP server running on LAN2 - you don't have corresponding /ip dhcp-server network nor /ip dhcp-server ...
by mkx
Mon Jul 22, 2019 9:18 am
Forum: General
Topic: IPTV Lan Help.
Replies: 10
Views: 788

Re: IPTV Lan Help.

OpenWRT IPTV create a switch -> Vlan 20 CPU = Tagged ethernet1/wan connection = Tagged ethernet3/IPTV connection = Untagged Create an interface name: IPTV static address: 192.168.2.245 IPV4 gateway: 255.255.255.0 Physical settings Vlan interface:eth0.20 This part would be probably translated to ROS...
by mkx
Sun Jul 21, 2019 12:33 pm
Forum: Announcements
Topic: v6.45.2 [stable] is released!
Replies: 206
Views: 35746

Re: v6.45.2 [stable] is released!

Did you reboot device after uploading additional .npk's? What does log contain about it?

BTW, security requires DHCP package ....
by mkx
Sun Jul 21, 2019 11:53 am
Forum: RouterBOARD hardware
Topic: Mikrotik RBSXTR (No Modem) 9dBi 60 degree LTE Antenna
Replies: 8
Views: 1011

Re: Mikrotik RBSXTR (No Modem) 9dBi 60 degree LTE Antenna

The PDF linked in previous post shows gain pattern in the bottom two charts. The left chart shows gain as function of frequency in low frequency bands and prooves that the dish is mediocre antenna for these frequencies at best (simple dipole antenna would have gain of around 2dBi but in narrow frequ...
by mkx
Sat Jul 20, 2019 5:58 pm
Forum: Announcements
Topic: v6.45.2 [stable] is released!
Replies: 206
Views: 35746

Re: v6.45.2 [stable] is released!

Cannot upgrade HAP lite series

Did you bother to scan through even this topic? It's been mentioned many times that hAP lite devices have low amount RAM and flash and sadly some steps have to be taken to get them to upgrade.
by mkx
Sat Jul 20, 2019 5:55 pm
Forum: Announcements
Topic: v6.45.2 [stable] is released!
Replies: 206
Views: 35746

Re: v6.45.2 [stable] is released!

Sysadmins that know Mikrotik well also know not to update anything for a few days after release or to do updates on non-critical test HW first. It's always nice to see a new release, but then I always have to check the forum to see how broken it actually is... that's the reality. But Mikrotik is al...
by mkx
Sat Jul 20, 2019 5:46 pm
Forum: General
Topic: Need to set up access to NAS openvpn
Replies: 45
Views: 2682

Re: Need to set up access to NAS openvpn

True about the mask, but it really is unusual, /18 is huge network .... One of larger ISPs in my country (which in turn is fairly small) operating FTTH and VDSL used /16 netmask until a year ago. They went to /17 after that. Still some way to reach /18 ;-) Their network is running fairly good, seem...
by mkx
Sat Jul 20, 2019 2:52 pm
Forum: Announcements
Topic: v6.45.2 [stable] is released!
Replies: 206
Views: 35746

Re: v6.45.2 [stable] is released!

I've got a hAP-lite and hAP-mini in a test setup for OSPF routing, neither will upgrade. hAP's need quite some free RAM, they download upgrade packages to RAM disk. I fear that devices with tiny 32MB RAMs are on their edge if you run OSPF ... as it needs some RAM to contain routing tables. Same pro...
by mkx
Fri Jul 19, 2019 1:21 pm
Forum: Announcements
Topic: v6.46beta [testing] is released!
Replies: 102
Views: 36525

Re: v6.46beta [testing] is released!

I understand that they are using TTL this way to spread users over the servers. Using short TTL for load-sharing is abuse of DNS TTL. This kind of load sharing should be done by adding multiple A records to same FQDM and let DNS round-robin mechanism to spread the load. I understand that it's out o...
by mkx
Fri Jul 19, 2019 9:07 am
Forum: General
Topic: Block Chromecast [SOLVED]
Replies: 5
Views: 584

Re: Block Chromecast [SOLVED]

There are a few problems with your setup. I'm assuming your AP1 has similar configuration ... AP1 (LAN part of it at least) and AP2 share same L2 domain ... this is an assumption as you didn't post config of AP1. Which means that only one DHCP server (on one of APs) should be running Your subnet is ...
by mkx
Fri Jul 19, 2019 8:42 am
Forum: Beginner Basics
Topic: cant ping the second subnet on vpn site to site
Replies: 3
Views: 371

Re: cant ping the second subnet on vpn site to site

Probably it has to do with your fi]/ip firewall[/i] settings ... on both HQ and branch routers. Crystal ball is moot these days, so instead post complete config of both routers and we might get some idea. Export configs using /export hide-sensitive ...
by mkx
Fri Jul 19, 2019 8:38 am
Forum: Beginner Basics
Topic: 1wan + 2 lan isolated from each other
Replies: 63
Views: 4416

Re: 1wan + 2 lan isolated from each other

Using custom chains has certainly some good effects: you can reuse same filters for multiple original chains (e.g. if you want to limit ICMP traffic to certain types and you want to do it for both chain=input and chain=forward) and you jump to the generic chain (filter rule execution returns to the ...
by mkx
Thu Jul 18, 2019 11:00 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 609
Views: 154592

Re: RouterOS v7.0 beta1 - when?

Another one time... When chupaca... When can we use ROS v7?
We won't use ROS v7, ROS v7 will use us ...
by mkx
Thu Jul 18, 2019 10:57 pm
Forum: Announcements
Topic: v6.46beta [testing] is released!
Replies: 102
Views: 36525

Re: v6.46beta [testing] is released!

It would be nice if the TTL of the resolved domain could be ignored in the settings of IKEv2. TTL in DNS system is there with a reason. Every sane DNS admin will have loong TTLs when changes are not expected. So when TTL is short, it shouldn't be overriden, could be that IP address will really chan...
by mkx
Thu Jul 18, 2019 10:36 pm
Forum: Beginner Basics
Topic: 1wan + 2 lan isolated from each other
Replies: 63
Views: 4416

Re: 1wan + 2 lan isolated from each other

The top-most firewall rule accepts just everything and none of later rules for chain=forward don't restrict anything. The default fast-track rule greediness is limited by condition connection-state=established,related . But fast-tracking also goes in the way of mangling, so you may want to disable t...
by mkx
Thu Jul 18, 2019 10:11 pm
Forum: General
Topic: RB750GR3 dropping camera data
Replies: 7
Views: 663

Re: RB750GR3 dropping camera data

However, there's a loopback adapter which then gives the camera an IP of 192.168.0.129.

Can you post a sketch of network layout with physical connections and addresses of the interfaces? Can be hand-drawn and photographed.
by mkx
Thu Jul 18, 2019 10:05 pm
Forum: General
Topic: Block Chromecast [SOLVED]
Replies: 5
Views: 584

Re: Block Chromecast [SOLVED]

By using chain=forward ... input is for traffic targeting router/AP itself.

And even if you fix it, it can happen it still won't work, depending on overall configuration of AP2. So if it doesn't work, post complete output of command /export hide-sensitive
by mkx
Thu Jul 18, 2019 6:09 pm
Forum: General
Topic: RB750GR3 dropping camera data
Replies: 7
Views: 663

Re: RB750GR3 dropping camera data

Move ip address to "interface" bridge1 ... your current setup is not correct even though things seem to work somehow. While it might seem that it has nothing to do with your problems, it might interfere (some weird problems have already been reported in this forum that went away after such error was...
by mkx
Thu Jul 18, 2019 5:49 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 69385

Re: v6.45.1 [stable] is released!

My thinking is that using STP to create redundant links between two directly attached devices is (slight) abuse.

In this case it would be better to use bonding. There are many varieties, if you only want to have backup line, you can use active-backup mode.
by mkx
Thu Jul 18, 2019 9:16 am
Forum: General
Topic: Possible to get port MAC used in Agent Remote ID field?
Replies: 3
Views: 339

Re: Possible to get port MAC used in Agent Remote ID field?

What you see in Remote Agent ID is HEX notation of text string "CC:2D:E0:67:38:B9" ... 0x43 is "C", 0x3a is ":" etc. If you wanted Remote Agent ID returned in the same way as MAC (less formatting, which includes ":" signs), you'd have to enter port name as some text garbage, but in ISO 8859-2 code p...
by mkx
Thu Jul 18, 2019 9:06 am
Forum: General
Topic: Firewall question
Replies: 6
Views: 510

Re: Firewall question

SMTP servers have all the information needed to make educated decision about rate limiting. Some SMTP servers support limiting incoming mail rate.
by mkx
Thu Jul 18, 2019 8:53 am
Forum: Beginner Basics
Topic: Redirecting to another port [SOLVED]
Replies: 6
Views: 619

Re: Redirecting to another port [SOLVED]

You'll have to use /interface bridge settings set use-ip-firewall=yes , disable HW acceleration on one (or both) involved ether ports (to force traffic through router's CPU) and then construct appropriate NAT rules (probably a single rule would do but make it specific enough so that it doesn't mess ...
by mkx
Thu Jul 18, 2019 8:44 am
Forum: Beginner Basics
Topic: Interface Confusion IP Firewall Filter
Replies: 1
Views: 283

Re: Interface Confusion IP Firewall Filter

ROS firewall has notion of connection states. Usual approach is to use a quite general firewall rule near to beginning of firewall rule list add action=accept chain=forward connection-state=established,related,untracked which passes packets of connections which have already been allowed by other rul...
by mkx
Thu Jul 18, 2019 8:31 am
Forum: Beginner Basics
Topic: 1wan + 2 lan isolated from each other
Replies: 63
Views: 4416

Re: 1wan + 2 lan isolated from each other

How should I proceed with the firewall to separate the lans? see post #24 by @anav In addition to those 2 rules, add rule which allows necessary connectivity between management devices in 192.168.1.0/24 and AP (IP address 172.16.24.120) ... possibly limit the connectivity to only a few necessary po...
by mkx
Thu Jul 18, 2019 8:15 am
Forum: Beginner Basics
Topic: VLAN Bridge Filtering ALternative
Replies: 9
Views: 987

Re: VLAN Bridge Filtering ALternative

Specs say that RB450Gx4 uses IPQ4019 SoC which in turn is supposed to have AR8327 switch chip embedded. If it's true what @tdw writes about Atheros' proprietary extension (and I believe he's right) and if that embedded switch chip really is complete AR8327 (I've mild doubts about that, my RBD52G usi...
by mkx
Thu Jul 18, 2019 8:08 am
Forum: Beginner Basics
Topic: APbridge mode vs Station mode [SOLVED]
Replies: 3
Views: 500

Re: APbridge mode vs Station mode [SOLVED]

what is the difference between the ap-bridge mode and station mode. Basic operation of WiFi is point to multipoint. The role of central device (access point) are numerous: it broadcasts system information, such as SSID, encryption configuration (WEP, WPA, WPA2), etc. selects frequency channel to wo...
by mkx
Wed Jul 17, 2019 9:03 pm
Forum: Beginner Basics
Topic: 1wan + 2 lan isolated from each other
Replies: 63
Views: 4416

Re: 1wan + 2 lan isolated from each other

I still think that Ubiquiti AP doesn't like address 172.16.24.2 for its management interface. And that RB config is fine regarding that. What still confuses me is that it obviously falls back to some weird default configuration if it can't connect to management console after restart. Can't you confi...
by mkx
Wed Jul 17, 2019 5:32 pm
Forum: Beginner Basics
Topic: VLAN Bridge Filtering ALternative
Replies: 9
Views: 987

Re: VLAN Bridge Filtering ALternative

Sadly modern SOHO-class RB devices seem to contain crippled switch chips ... Internally Mikrotik will be using VLANs to perform this multiplexing/demuliplexing with the Realtek and MediaTek switch chips, and don't provide any user access to VLAN functionality. Thanks for the explanation and link to...
by mkx
Wed Jul 17, 2019 5:18 pm
Forum: General
Topic: RouterOS v7.0 beta1 - when?
Replies: 609
Views: 154592

Re: RouterOS v7.0 beta1 - when?

Will not run, you need one core per pixel.
Image
by mkx
Wed Jul 17, 2019 5:13 pm
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 69385

Re: v6.45.1 [stable] is released!

It's when I apply the bridge config that things gets weird...
As @pe1chl wrote: you have to remove router functionality by hand (either via GUI or CLI, just don't use quickset).
by mkx
Wed Jul 17, 2019 11:38 am
Forum: General
Topic: Mikrotik Point to Multi Point Configuration
Replies: 6
Views: 443

Re: Mikrotik Point to Multi Point Configuration

... but different ip, right?
That would make management easier.
by mkx
Wed Jul 17, 2019 11:33 am
Forum: General
Topic: Mikrotik Point to Multi Point Configuration
Replies: 6
Views: 443

Re: Mikrotik Point to Multi Point Configuration

Correct. But do read about different station modes ... the usual "station" mode might not give you the functionality you are after ...
by mkx
Wed Jul 17, 2019 11:26 am
Forum: General
Topic: Why Mikrotik ???
Replies: 32
Views: 6238

Re: Why Mikrotik ???

I wasn't ware of that (I thought they only had maritime border after Алекса́ндр II Никола́евич sold Alaska to the USA) ... where is that land border located?
by mkx
Wed Jul 17, 2019 11:22 am
Forum: General
Topic: Mikrotik Point to Multi Point Configuration
Replies: 6
Views: 443

Re: Mikrotik Point to Multi Point Configuration

ap-bridge is the one serving multiple stations. And that happens to be default wireless mode. If you want mikrotik box to act as client of an AP, you have to change its mode to some variety of "station" ... you can read about differences in manual.
by mkx
Wed Jul 17, 2019 11:19 am
Forum: Beginner Basics
Topic: 1wan + 2 lan isolated from each other
Replies: 63
Views: 4416

Re: 1wan + 2 lan isolated from each other

I guess the real issue here is how Unifi console wants to connect to AP (and vice versa) ... BTW, in which subnet is Unifi console sitting? Could be that AP wants permanent connection to Unifi console and if it looses it (due to some IP reconfig), it reverts to some kind of defaults?
by mkx
Wed Jul 17, 2019 11:03 am
Forum: General
Topic: Why Mikrotik ???
Replies: 32
Views: 6238

Re: Why Mikrotik ???

This is highly offensive to Latvians. We have no connection to russia ...

Last time I checked (it was like right now), Latvia had 216km of connection to Russia with at least 7 major doors ... not counting backdoors :wink:
by mkx
Wed Jul 17, 2019 10:46 am
Forum: General
Topic: rb750gr3 Gigabit auto negotiation [SOLVED]
Replies: 16
Views: 1331

Re: rb750gr3 Gigabit auto negotiation [SOLVED]

I do understand that, but when you just like to see interface info and write this and get: /interface ethernet set [ find default-name=ether1 ] name=ether1-Wan speed=100Mbps Its not intuitive at all what is then the speed is showing. speed=100Mbps could then be. Actual speed? Auto negotiation off s...
by mkx
Wed Jul 17, 2019 9:29 am
Forum: General
Topic: RB750GR3 dropping camera data
Replies: 7
Views: 663

Re: RB750GR3 dropping camera data

RB750Gr3 is not a switch, it's a router. With default configuration it's ether1 port is WAN. You can use it as a switch, but be sure only to use ports ether2-ether5.
by mkx
Wed Jul 17, 2019 9:19 am
Forum: Wireless Networking
Topic: Wifi Latency issue
Replies: 2
Views: 461

Re: Wifi Latency issue

I guess that the weird ping pattern observed on the phone is due to power-saving kicking in when phone is idle (wireless can be power hungry and optimizing it by putting wifi chip to sleep frequently is one of first things to do). If a device is connected to AC (suppose the Ambivision gadget is) thi...
by mkx
Wed Jul 17, 2019 9:10 am
Forum: Wireless Networking
Topic: LHG LTE kit overampllification [SOLVED]
Replies: 5
Views: 728

Re: LHG LTE kit overampllification [SOLVED]

Does a floor make some difference in this case?
Floor in what sense?
by mkx
Wed Jul 17, 2019 9:08 am
Forum: Beginner Basics
Topic: VLAN Bridge Filtering ALternative
Replies: 9
Views: 987

Re: VLAN Bridge Filtering ALternative

... I currenly don't have any device with modern switch chip to test with). Sadly modern SOHO-class RB devices seem to contain crippled switch chips (RB4011 has RTL8367, RB750Gr3 has MT7621) which don't have any VLAN support what so ever. Seems like MT is trying to create some gap between RB and CR...
by mkx
Wed Jul 17, 2019 8:59 am
Forum: Beginner Basics
Topic: VLAN Bridge Filtering ALternative
Replies: 9
Views: 987

Re: VLAN Bridge Filtering ALternative

Sadly what @Sob writes is true: MT devs stopped at implementing HW offload for CRS3xx, other devices with capable switch chips didn't get that treatment. The positive thing about bridge vlan-filtering is unified configuration on any RB device. When doing stuff on switch chip, one has to study partic...
by mkx
Wed Jul 17, 2019 8:38 am
Forum: Beginner Basics
Topic: 1wan + 2 lan isolated from each other
Replies: 63
Views: 4416

Re: 1wan + 2 lan isolated from each other

[] > /ping src-address=172.16.24.1 192.168.1.1 count=4
This test showed that RB4011 can reach itself. :wink:
by mkx
Wed Jul 17, 2019 8:27 am
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 69385

Re: v6.45.1 [stable] is released!

Is it me or 6.45.1 is giving everyone a different type of headache? Judging from posts in this tread it does seem that 6.45.1 is a troublesome child of MT. This is not my personal experience though, have updated 6 pieces (2x hAP ac lite, 1x hAP, 2x RB951G and 1xhAP ac2) from 6.44.x and I didn't hav...
by mkx
Tue Jul 16, 2019 11:50 pm
Forum: Beginner Basics
Topic: 1wan + 2 lan isolated from each other
Replies: 63
Views: 4416

Re: 1wan + 2 lan isolated from each other

First to routing and firewalling: I don't see anything in RB4011 config which would prevent connectivity from 172.16.24.2 to 192.168.1.1. Firewall is very permissive (allows just anything in chain=forward, also everything on chain=input except for connections originating from internet). I wonder why...
by mkx
Tue Jul 16, 2019 4:30 pm
Forum: Beginner Basics
Topic: Routing betwe Mikrotik and Cisco ASA
Replies: 3
Views: 420

Re: Routing betwe Mikrotik and Cisco ASA

If I'm correct about ASA's firewall connection tracking engine tripping ... then the most correct way would be to turn off connection tracking for those connections on cisco ASA. I have no idea whatsoever how to do it (if that's possible at all, I'd expect it is). I've other ideas, but as they are m...
by mkx
Tue Jul 16, 2019 11:15 am
Forum: Beginner Basics
Topic: Routing betwe Mikrotik and Cisco ASA
Replies: 3
Views: 420

Re: Routing betwe Mikrotik and Cisco ASA

There are 2 potential problems: do firewalls on devices in both networks (cisco and RB) allow connections from the "alien" LANs? does cisco ASA perform as firewall as well? As replies from RB network towards cisco network won't pass ASA (unless you play with NAT on RB), this could screw connection t...
by mkx
Tue Jul 16, 2019 11:06 am
Forum: RouterBOARD hardware
Topic: CRS312-4C+8XG-RM questions
Replies: 7
Views: 1080

Re: CRS312-4C+8XG-RM questions

We will update the CRS312-4C+8XG documentation regarding that.
You could update the Specifications table by mentioning those 4 combo ports as well ...
by mkx
Tue Jul 16, 2019 10:56 am
Forum: RouterBOARD hardware
Topic: Lost RouterOS due to major power failure - Netinstall doesn't work
Replies: 1
Views: 338

Re: Lost RouterOS due to major power failure - Netinstall doesn't work

Netinstall is very fragile and it is vital to follow procedure in official Netinstall manual ... including warnings about windows firewall and network interfaces. Netinstall is evolving as well so you may want to try different netinstall versions. As it is highly advisable to use same version of ROS...
by mkx
Tue Jul 16, 2019 10:48 am
Forum: Wireless Networking
Topic: LHG LTE kit overampllification [SOLVED]
Replies: 5
Views: 728

Re: LHG LTE kit overampllification [SOLVED]

It can become a problem if you get real close to the tower. You can remedy that by turning LHG dish slightly away from the cell tower - the LHG has quite narrow antenna beam (making it high gain) but slight miss-alignment will give additional signal degradation if needed. Most of LTE devices like to...
by mkx
Tue Jul 16, 2019 10:43 am
Forum: Announcements
Topic: v6.45.1 [stable] is released!
Replies: 416
Views: 69385

Re: v6.45.1 [stable] is released!

All packages have to be the same version (and system package leads the game).
  • 1
  • 2
  • 3
  • 4
  • 5
  • 10