Community discussions

MikroTik App

Search found 19553 matches

  • 1
  • 4
  • 5
  • 6
  • 7
  • 8
  • 66
by anav
Mon Nov 27, 2023 10:27 pm
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 41
Views: 6904

Re: Firewall - DNS Open? - Urgent [SOLVED]

(1) Where is bridge vlan-filtering=yes ?? /interface bridge add name=BRIDGE priority=0x7000 (2) Allowed IPs is not quite right, fixed....... add allowed-address=\ 10.10.9 .0/24 ,192.168.254.0/24,192.168.155.0/24,192.168.249.0/24 \ comment=PeerStS_DIM disabled=yes endpoint-address=vpn.test.com \ endp...
by anav
Mon Nov 27, 2023 9:57 pm
Forum: General
Topic: L2TP/IPSec VPN - Cannot get past phase 1
Replies: 5
Views: 1601

Re: L2TP/IPSec VPN - Cannot get past phase 1

Id rather not Crokinole my way into the OPs head................. and will let the OP provided the actual information.
by anav
Mon Nov 27, 2023 9:54 pm
Forum: General
Topic: Route Traffic through WireGuard to Internet [SOLVED]
Replies: 20
Views: 4989

Re: Route Traffic through WireGuard to Internet [SOLVED]

Philosophy. The default rules come set for a simple user on the bridge via ether2 and wan setup to work on ether1. The traffic is safely protected but it allows all traffic and drops some key things for general safety. When we want to do more, add vlans and other things its much easier, as the confi...
by anav
Mon Nov 27, 2023 9:42 pm
Forum: Beginner Basics
Topic: HELP VPN RB3011
Replies: 9
Views: 1486

Re: HELP VPN RB3011

Sounds very doable. Basically server router - input chain rule for port both routers. define interface add ip address add peers, wireguard Ip and remote subnets ( see article for difference between client peer setting and server peer setttings ) add forward chain rules needed for traffic flow add ip...
by anav
Mon Nov 27, 2023 9:16 pm
Forum: Beginner Basics
Topic: HELP VPN RB3011
Replies: 9
Views: 1486

Re: HELP VPN RB3011

Before thinking about configurating, its best to understand the requirements and PLAN!!! identify users/devices, groups of users/devices, including admin identify what traffic they need. Do the devices have single WAN or dual WAN? Is there any port forwarding involved on the two devices? What two de...
by anav
Mon Nov 27, 2023 9:14 pm
Forum: General
Topic: L2TP/IPSec VPN - Cannot get past phase 1
Replies: 5
Views: 1601

Re: L2TP/IPSec VPN - Cannot get past phase 1

Since the need for VPN is not clear. Which users are coming to the OFFICE and for what purposes?? Why do you hide a private IP address, assuming the upstream router handles the WAN connection and your WAN input is basically a LAN address on the subnet of the ISP router? The other thing funky about t...
by anav
Mon Nov 27, 2023 8:03 pm
Forum: Beginner Basics
Topic: HELP VPN RB3011
Replies: 9
Views: 1486

Re: HELP VPN RB3011

Wireguard has generally better performance and easier to setup. Do you control both ends of the tunnel? ( what is at both ends?) Does at least one end have a publicaly reachable IP address ( not cgnat or natted behind another router )?? If natted behind lets say an ISP modem router, can you forward ...
by anav
Mon Nov 27, 2023 8:01 pm
Forum: General
Topic: Route Traffic through WireGuard to Internet [SOLVED]
Replies: 20
Views: 4989

Re: Route Traffic through WireGuard to Internet [SOLVED]

Firewall Rules Server Router; /ip firewall address-list { static dhcp leases or wireguard ip } add address=172.16.24.XX list= Authorized comment="admin local desktop" add address=172.16.24.AA list=Authorized comment="admin local laptop" add address=172.16.24.BB list=Authorized c...
by anav
Mon Nov 27, 2023 7:05 pm
Forum: General
Topic: Route Traffic through WireGuard to Internet [SOLVED]
Replies: 20
Views: 4989

Re: Route Traffic through WireGuard to Internet [SOLVED]

Client Router (1) It would appear you are trying to use srcnat masquerade to route traffic. This is the wrong approach. /ip firewall nat add action=masquerade chain=srcnat dst-address=172.16.24.0/24 out-interface=\ wireguard-oam src-address=192.168.13.0/24 All you need is....... add action=masquera...
by anav
Mon Nov 27, 2023 4:31 pm
Forum: Beginner Basics
Topic: HELP VPN RB3011
Replies: 9
Views: 1486

Re: HELP VPN RB3011

Any reason you chose L2TP vice wireguard??
by anav
Mon Nov 27, 2023 4:30 pm
Forum: General
Topic: Route Traffic through WireGuard to Internet [SOLVED]
Replies: 20
Views: 4989

Re: Route Traffic through WireGuard to Internet [SOLVED]

Need facts/evidence.
So latest configs of the routers please.
by anav
Mon Nov 27, 2023 1:25 pm
Forum: Beginner Basics
Topic: Dual WAN failover, port forward not working when changing route distance
Replies: 22
Views: 2504

Re: Dual WAN failover, port forward not working when changing route distance

Well, good to know, defining the requirements clearly is best done before applying a config. a. you have two WANs. b. there is no failover c. the LAN should use WAN1 only if wan1 goes down, no LAN traffic goes to WAN2 if wan2 goes down, no LAN traffic goes to WAN1 Wan 2 is a static fixed WANIP You h...
by anav
Mon Nov 27, 2023 1:20 pm
Forum: Beginner Basics
Topic: HAP ac2 need help with load balancing on 2 WAN connections
Replies: 16
Views: 1927

Re: HAP ac2 need help with load balancing on 2 WAN connections

You got me Holvoe, apologies to the OP. I know squat about L2TP so will bow out.
by anav
Mon Nov 27, 2023 1:18 pm
Forum: General
Topic: Some problems in mikrotik 7
Replies: 6
Views: 1380

Re: Some problems in mikrotik 7

Is this whining or asking for help?
Provide a network diagram and full config

/export file=anynameyouwish ( minus router serial# and any public WANIP information, keys etc...)
by anav
Mon Nov 27, 2023 1:15 pm
Forum: General
Topic: Problems with DNS, LAN devices can't access internet
Replies: 10
Views: 1978

Re: Problems with DNS, LAN devices can't access internet

have been fighting a starlink DNS issue. I know this sounds strange and I am hoping someone will point out why it is behaving this way. Sounds like your asking for help to me......but okay, maybe your not. What a switch has to do with router issues is a bit strange to interject and you have no clari...
by anav
Mon Nov 27, 2023 2:44 am
Forum: Beginner Basics
Topic: Config with Advanced Firewall verification requested (WG, DoH & server are working great). Nothing is failing
Replies: 2
Views: 1178

Re: Config with Advanced Firewall verification requested (WG, DoH & server are working great). Nothing is failing

Just to clarify, my article uses untracked.........
viewtopic.php?t=180838

If you want me to look at your config, I will rip out anything that is not on those pages,,,,,,,,,
Not required, what I refer to as BLOAT.
by anav
Mon Nov 27, 2023 2:42 am
Forum: Beginner Basics
Topic: Dual WAN Load Balancing depending on usage
Replies: 1
Views: 943

Re: Dual WAN Load Balancing depending on usage

Hmm not really, you can setup PCC balancing to favour one over the other but thats hard wired into the config. The only thing I can say off the top is to make a vlan for WIFI in the house and basically route all the traffic from that wifi through the desired WAN. That way folks have a quick and dirt...
by anav
Mon Nov 27, 2023 2:39 am
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 1916

Re: PCC Loadbalancing and distant Port forwarding not working

The improvements to many functions and the ability to do wireguard are huge reasons to move ahead.
If this is a home no worries, 7.12.1 is decent enough.
by anav
Mon Nov 27, 2023 2:38 am
Forum: Beginner Basics
Topic: HAP ac2 need help with load balancing on 2 WAN connections
Replies: 16
Views: 1927

Re: HAP ac2 need help with load balancing on 2 WAN connections

Find that hard to believe, wireguard was not possible on vers6
edit: I didnt consider wG on another device, mia culpa!!
by anav
Mon Nov 27, 2023 2:37 am
Forum: Beginner Basics
Topic: Firewall doesn't work properly.
Replies: 14
Views: 1807

Re: Firewall doesn't work properly.

The friend is not exactly wrong,,,,,, just a tad misleading. EVERY SWITCH PORT when it comes Default has vlan1 assigned to the port. WE LEAVE THAT vlan1 alone. It works in the background and can basically be ignored. We dont change any vlan1 settings anywhere. EXCEPT.......... when we make a port an...
by anav
Mon Nov 27, 2023 2:28 am
Forum: General
Topic: Route Traffic through WireGuard to Internet [SOLVED]
Replies: 20
Views: 4989

Re: Route Traffic through WireGuard to Internet [SOLVED]

SERVER Comments 1. This indicates an issue....... /interface list member add comment=defconf interface= *C list=LAN I suspect its because you have not identified any LAN list interface members and yet you have a list?? 2. This is wrong. .......... IF you have IP DHCP Client you should not have a se...
by anav
Sun Nov 26, 2023 5:41 pm
Forum: Beginner Basics
Topic: separate different networks on a MikroTik router using the bridge
Replies: 6
Views: 1477

Re: separate different networks on a MikroTik router using the bridge

Seems illogical to me.
What is the purpose of buying a MIKROTIK router of that power and using it as a switch??
What am I missing???
by anav
Sun Nov 26, 2023 5:33 pm
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 1916

Re: PCC Loadbalancing and distant Port forwarding not working

Wait you are still on vers 6?? My configs are predicated on vers 7
by anav
Sun Nov 26, 2023 5:32 pm
Forum: Beginner Basics
Topic: HAP ac2 need help with load balancing on 2 WAN connections
Replies: 16
Views: 1927

Re: HAP ac2 need help with load balancing on 2 WAN connections

Do you have any port forwarding?
Do you have any VPNs........
Hoelve needs to learn to find all the requirements before planning a config ;-P
by anav
Sun Nov 26, 2023 5:30 pm
Forum: Beginner Basics
Topic: Firewall doesn't work properly.
Replies: 14
Views: 1807

Re: Firewall doesn't work properly.

Hi KAT,
There is no vlan1 in your config, in fact it looks like properly all the MT devices got an IP on the trusted 192.168.0.0/24 subnet. ( AKA VLAN100 )
Thus confused by the evidence in the configs contradicted by the diagram and your words??
by anav
Sun Nov 26, 2023 5:05 pm
Forum: Beginner Basics
Topic: Firewall doesn't work properly.
Replies: 14
Views: 1807

Re: Firewall doesn't work properly.

(1) Which Router is the one you are referring to in the diagram?????? I am assuming the 5009!! (2) What is with vlan1 between all the MT devices, I dont see that in the router config you have??? Assuming you meant on the diagram to put vlan100 which contains the 192.168.0.0/24 (3) So you have four V...
by anav
Sun Nov 26, 2023 5:01 pm
Forum: General
Topic: WireGuard server on Windows with a MikroTik router as a client
Replies: 12
Views: 3070

Re: WireGuard server on Windows with a MikroTik router as a client

ROUTER COMMENTS ( WOW, nice setup ) (1) Not sure what you mean by this line.............. add address=10.0.20.0/24 comment="the different DNS server is used to make th\ e router use the WireGuard VPN connection for DNS queries" dns-server=\ 208.67.222.222,208.67.220.220 gateway=10.0.20.1 F...
by anav
Sun Nov 26, 2023 4:18 pm
Forum: General
Topic: WireGuard server on Windows with a MikroTik router as a client
Replies: 12
Views: 3070

Re: WireGuard server on Windows with a MikroTik router as a client

Good day, The requirements are pretty good. Who needs access to the windows server, vlan10 and vlan20 Who needs access to vlan10, vlan20 does Who gets internet from wireguard, vlan20 does. +++++++++++++++++++++++++++++++++++++++++++++++++ Its the additional requirements that get a bit murky. a. vlan...
by anav
Sun Nov 26, 2023 2:56 pm
Forum: General
Topic: Route Traffic through WireGuard to Internet [SOLVED]
Replies: 20
Views: 4989

Re: Route Traffic through WireGuard to Internet [SOLVED]

Post your config here seeing as the OPs has solved his case and thus no interference.

/export file=anynameyouwish ( minus router serial number, public WANIP information, keys, long dhcp lease lists, any ipv6 info if not using ipv6 )
by anav
Sun Nov 26, 2023 2:50 pm
Forum: General
Topic: difference in Wireguard behavior between laptop and phone
Replies: 8
Views: 1469

Re: difference in Wireguard behavior between laptop and phone

1. Allowed IPs on the mikrotik side have nothing to do with routing. 2. Allowed IPs are a matching flltering function for leaving traffic and a filtering function for arriving traffic. 3. An automatic route is created for wireguard IPs by the wireguard router due to ccreating the interface IP addres...
by anav
Sun Nov 26, 2023 2:45 pm
Forum: Beginner Basics
Topic: separate different networks on a MikroTik router using the bridge
Replies: 6
Views: 1477

Re: separate different networks on a MikroTik router using the bridge

Concur, one bridge and three vlans is all that is required here. Unless the fortigate cannot handle vlans? What is the purpose of the fortigate in this setup? Edge Router with some subscription services?? interface list=building one vlans 11,12,13,14 Interface list=building two vlans 21,22,23,24 int...
by anav
Sun Nov 26, 2023 2:29 pm
Forum: Beginner Basics
Topic: looking to switch to a 5g > router > AP setup
Replies: 7
Views: 1592

Re: looking to switch to a 5g > router > AP setup

You came here looking for reasons to 'convince' the wife to spend money. Just wanted to help the cause by better understanding the scenario because what you initially presented was a very weak case. :-) Anything is possible between two MT routers. Use the concept provided in post #2. Trunk port betw...
by anav
Sun Nov 26, 2023 2:26 pm
Forum: Beginner Basics
Topic: Firewall doesn't work properly.
Replies: 14
Views: 1807

Re: Firewall doesn't work properly.

Concur network diagram gives us context!

In addition need to see complete config again. ( not just snippet of firewall rules )
by anav
Sun Nov 26, 2023 2:24 pm
Forum: Beginner Basics
Topic: HAP ac2 need help with load balancing on 2 WAN connections
Replies: 16
Views: 1927

Re: HAP ac2 need help with load balancing on 2 WAN connections

What is PPC................ In terms of requirements. a. identify all the user(s)/devices, groups of users and devices ( including admin and external users) b. identify all the traffic they require do accomplish. What is the purpose of the two WANS. Use a primary and have a secondary as backup? USE ...
by anav
Sun Nov 26, 2023 2:22 pm
Forum: Beginner Basics
Topic: Help on RM3011UiAS's DHCP Servers
Replies: 2
Views: 925

Re: Help on RM3011UiAS's DHCP Servers

Firewall ideas -->viewtopic.php?t=180838
Vlan ideas -->viewtopic.php?t=143620
by anav
Sun Nov 26, 2023 5:26 am
Forum: General
Topic: difference in Wireguard behavior between laptop and phone
Replies: 8
Views: 1469

Re: difference in Wireguard behavior between laptop and phone

Good you have surmized there is no problem with your config, thus no help required.
by anav
Sun Nov 26, 2023 5:23 am
Forum: General
Topic: Problems with DNS, LAN devices can't access internet
Replies: 10
Views: 1978

Re: Problems with DNS, LAN devices can't access internet

@lostgone --> Start your own thread please.

@felipe Post your latest config
by anav
Sun Nov 26, 2023 5:20 am
Forum: Beginner Basics
Topic: Firewall doesn't work properly.
Replies: 14
Views: 1807

Re: Firewall doesn't work properly.

(1) You dont understand firewall rules. Why make allow port 53 rules, but then later drop everything not coming from the LAN. In other words the port 53 rules are allowed by the rule above and thus not necessary in your setup. However, its not at all what I suggested. (2) These ones also are unnecce...
by anav
Sun Nov 26, 2023 3:54 am
Forum: Beginner Basics
Topic: Issues about wireguard connectivity on RouterOS with multiple WAN ports
Replies: 13
Views: 2009

Re: Issues about wireguard connectivity on RouterOS with multiple WAN ports

firewall rules fixed Main issue is these rules which have been axed...... add action=drop chain=input comment="defconf: drop all coming from ha_ct" \ in-interface=pppoe_ha-ct add action=drop chain=input comment="defconf: drop all coming from ha_cu" \ in-interface=pppoe_ha-cu add ...
by anav
Sun Nov 26, 2023 3:39 am
Forum: Beginner Basics
Topic: Firewall doesn't work properly.
Replies: 14
Views: 1807

Re: Firewall doesn't work properly.

Change the approach of at least the forward chain, to DROP ALL. In this regard all connections between different subnets are blocked unless explicitly stated in the firewall rules. {forward chain} add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=e...
by anav
Sun Nov 26, 2023 3:36 am
Forum: General
Topic: Output route selection - Wireguard
Replies: 18
Views: 3202

Re: Output route selection - Wireguard

Same here. By using classic mangle rules such as: /ip firewall mangle add action=mark-connection chain=input connection-state=new in-interface=ether2-pppoe new-connection-mark="From WAN Telecom2" passthrough=yes add action=mark-routing chain=output connection-mark="From WAN Telecom2&...
by anav
Sun Nov 26, 2023 12:47 am
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 1916

Re: PCC Loadbalancing and distant Port forwarding not working

The above handles all the rules required.
Give that a shot and we will see how much progress is made!
by anav
Sun Nov 26, 2023 12:47 am
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 1916

Re: PCC Loadbalancing and distant Port forwarding not working

(1) Order of firewall rules fixed. (2) Its dumb to allow an entire subnet to configure the router and besides, 8291 is not a tcp protocol its udp! Created a firewall address list called authorized........ to solve.... (3) Got rid of unnecessary firewall address lists. (4) Removed logging on drop all...
by anav
Sat Nov 25, 2023 9:42 pm
Forum: General
Topic: Proton VPN suddenly stopped working
Replies: 8
Views: 1795

Re: Proton VPN suddenly stopped working

(1) Wrong order. ..... think through the logic. Will traffic from VPN subnet ever reach another local subnet with the order you have???? /routing rule add action=lookup-only-in-table disabled=no src-address=10.10.20.0/24 table=\ Proton_UK_WG add action=lookup-only-in-table disabled=no src-address=10...
by anav
Sat Nov 25, 2023 5:04 pm
Forum: Beginner Basics
Topic: Micro Tik Hex and tp link multi ap
Replies: 4
Views: 1195

Re: Micro Tik Hex and tp link multi ap

You didnt read that article very closely, where the EFF does it show the bridge doing any DHPC....... ALL VLANS So take your bridge subnet and assign it to a vlan. Then you need to actually turn on bridge vlan filtering=yes......... None of your bridge ports are assigned properly for access ports or...
by anav
Sat Nov 25, 2023 5:02 pm
Forum: Beginner Basics
Topic: Issues about wireguard connectivity on RouterOS with multiple WAN ports
Replies: 13
Views: 2009

Re: Issues about wireguard connectivity on RouterOS with multiple WAN ports

Then there is something else on your config that is blocking.
Please post FULL config

/export file=anynameyouwish ( minus router serial #, public WANIP information, keys, long dhcp lease lists, IPV6 anything if not using it)
by anav
Sat Nov 25, 2023 4:54 pm
Forum: General
Topic: After Wireguard Client configuration successfully, lan area cannot access wireguard area.
Replies: 6
Views: 1325

Re: After Wireguard Client configuration successfully, lan area cannot access wireguard area.

So assuming the SERVER is not third party, then the problem is also at the other end at the server end!! SeRVER CONSIDERATIONS : a. do you have 192.168.88.0/24 as allowed IPs at the server wg peer settings for router b?? b. do you have 192.168.100.2/32 as allowed IPs at the server wg peer settings f...
by anav
Sat Nov 25, 2023 4:45 pm
Forum: General
Topic: After Wireguard Client configuration successfully, lan area cannot access wireguard area.
Replies: 6
Views: 1325

Re: After Wireguard Client configuration successfully, lan area cannot access wireguard area.

What is the remote wireguard server - mikrotik or something else?? Concur lets fix that sourcenat mess..... (drop the crap rule) /ip firewall nat add action=src-nat chain=srcnat dst-address=192.168.100.0/24 dst-limit=\ 1,5,dst-address/1m40s limit=1,5:packet psd=21,3s,3,1 src-address=\ 192.168.88.0/2...
by anav
Sat Nov 25, 2023 4:41 pm
Forum: Beginner Basics
Topic: Dual WAN failover, port forward not working when changing route distance
Replies: 22
Views: 2504

Re: Dual WAN failover, port forward not working when changing route distance

(1) This default rule is now replaced and should be removed. add action=drop chain=forward comment=\ "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \ connection-state=new disabled=yes in-interface-list=WAN add action=accept chain=forward comment=Internet in-interfac...
by anav
Sat Nov 25, 2023 3:04 pm
Forum: Beginner Basics
Topic: Dual WAN, but second link is used only by some LAN machines [SOLVED]
Replies: 3
Views: 1420

Re: Dual WAN, but second link is used only by some LAN machines [SOLVED]

Need table /routing-table add name=useWAN2 Need route /ip route normal route ISP1 distance=2 check-gateway=ping table=main normal route ISP2 distance=4 table=main add dst-address=0.0.0.0/0 gateway=ISP2 routing-table=useWAN2 [/b] Need routing rules................. But be careful as a routing rule fo...
by anav
Sat Nov 25, 2023 2:58 pm
Forum: Beginner Basics
Topic: Issues about wireguard connectivity on RouterOS with multiple WAN ports
Replies: 13
Views: 2009

Re: Issues about wireguard connectivity on RouterOS with multiple WAN ports

Try these mangle rules. add chain=prerouting action=mark-connection connection-mark=no-mark \ in-interface=WAN2 new-connection-mark=incomingISP2 passthough=yes add chain=output action=mark-routing connection-mark=incomingISP2 \ new-routing-mark=useWAN2 passthough=no Dont forget the table. /routing t...
by anav
Sat Nov 25, 2023 5:41 am
Forum: General
Topic: After Wireguard Client configuration successfully, lan area cannot access wireguard area.
Replies: 6
Views: 1325

Re: After Wireguard Client Setup successfully, lan cannot access wireguard area.

Allowed peer should be 192.168.100.0/24, not 192.168.100.1/24
by anav
Fri Nov 24, 2023 11:31 pm
Forum: General
Topic: Is WireGuard traffic invisible to Torch [SOLVED]
Replies: 2
Views: 1315

Re: Is WireGuard traffic invisible to Torch [SOLVED]

The wirguard config is predicated upon the peer for a client to be the specific IP address as noted, which differentiates from the multiple peers possible.

The peer on the client or often remote device, should be the subnet and if a router then most definitely the subnet.
by anav
Fri Nov 24, 2023 5:24 pm
Forum: General
Topic: WireGuard server on Windows with a MikroTik router as a client
Replies: 12
Views: 3070

Re: WireGuard server on Windows with a MikroTik router as a client

Busy today but will look at i this weekend.
by anav
Fri Nov 24, 2023 5:22 pm
Forum: Beginner Basics
Topic: Dual WAN, but second link is used only by some LAN machines [SOLVED]
Replies: 3
Views: 1420

Re: Dual WAN, but second link is used only by some LAN machines [SOLVED]

How many machines?? You can use Routing rules for entire subnets - very easy, no mangles. You can use Routing rules for a few users - very easy, no mangles. Basically it comes down to you will need a routing rule per user so it depends how many rules you would like to make. add src-address=userX-IP ...
by anav
Fri Nov 24, 2023 5:05 pm
Forum: Beginner Basics
Topic: Dual WAN failover, port forward not working when changing route distance
Replies: 22
Views: 2504

Re: Dual WAN failover, port forward not working when changing route distance

Busy today, but if you post your latest config I will spend more time on it this weekend.
by anav
Fri Nov 24, 2023 2:25 pm
Forum: Beginner Basics
Topic: 2 Vlans, a firewall, and a PITA DNS.
Replies: 3
Views: 1096

Re: 2 Vlans, a firewall, and a PITA DNS.

One bridge..............
viewtopic.php?t=143620
by anav
Fri Nov 24, 2023 2:23 pm
Forum: Beginner Basics
Topic: Issues about wireguard connectivity on RouterOS with multiple WAN ports
Replies: 13
Views: 2009

Re: Issues about wireguard connectivity on RouterOS with multiple WAN ports

Too busy today to look at it, but I would scrap any mangle rules you have for wireguard.
What is required is mangle rules ensuring traffic coming in wanx, goes out wanx.
by anav
Fri Nov 24, 2023 2:19 pm
Forum: Beginner Basics
Topic: Dual WAN failover, port forward not working when changing route distance
Replies: 22
Views: 2504

Re: Dual WAN failover, port forward not working when changing route distance

I have a great idea, why dont you ask the people making vidoes for help........... The onus is ON YOU, to read the mikrotik docs and read as many threads as possible to learn. There are some decent videos out there by a few people the rest will lead you astray. Network Berg is good Network Trip is g...
by anav
Wed Nov 22, 2023 11:06 pm
Forum: General
Topic: multi vlan with multi wan setup
Replies: 16
Views: 2516

Re: multi vlan with multi wan setup

Try harder, and read more....... the answer are available......
by anav
Wed Nov 22, 2023 11:04 pm
Forum: Beginner Basics
Topic: Dual WAN failover, port forward not working when changing route distance
Replies: 22
Views: 2504

Re: Dual WAN failover, port forward not working when changing route distance

Sorry you still have not explained how you are using DNS to 'force' users through one WAN or the other.
What DNS records?

Forcing users out a specific WAN is accomplished via routing of some sort.
by anav
Wed Nov 22, 2023 11:02 pm
Forum: Beginner Basics
Topic: looking to switch to a 5g > router > AP setup
Replies: 7
Views: 1592

Re: looking to switch to a 5g > router > AP setup

?? Do you have a multitude of servers feeding many users........ Not sure what the need is for 10gigs? As for poe...... injectors are cheap....... https://www.amazon.ca/PoE-Injector/s?k=PoE+Injector Your not making a real case to keep the 5009 thus far......... , maybe you want to show the wife this...
by anav
Wed Nov 22, 2023 10:16 pm
Forum: Beginner Basics
Topic: looking to switch to a 5g > router > AP setup
Replies: 7
Views: 1592

Re: looking to switch to a 5g > router > AP setup

Sell the RB5009, there is no need to keep it when you get the chateau 5G AX. To me its pointless to keep both. Give the RB to family or donate to some organization, it would be wasted otherwise. There is nothing to be gained by keeping it. The same rules can be used on the Chateau as its the same RO...
by anav
Wed Nov 22, 2023 10:08 pm
Forum: General
Topic: multi vlan with multi wan setup
Replies: 16
Views: 2516

Re: multi vlan with multi wan setup

Sorry its you that doesnt understand, didnt ask for your configuration BS. . All I asked for is how to set the gateway for a vlan if there is more than just one wan-interface. I asked to explain what users and devices you had and what traffic requirements they had. The network diagram shows what equ...
by anav
Wed Nov 22, 2023 9:48 pm
Forum: Beginner Basics
Topic: looking to switch to a 5g > router > AP setup
Replies: 7
Views: 1592

Re: looking to switch to a 5g > router > AP setup

Dont understand what you are trying to accomplish. 1. The RB5009 is a better router in terms of routing it can actually handle a 2.5 gig ISP connection with firewall rules implemented. The latest chateau 5G AX cannot ( good for 1gig fiber ). 2. There is no need for the chateau to do routing if you h...
by anav
Wed Nov 22, 2023 9:45 pm
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 1916

Re: PCC Loadbalancing and distant Port forwarding not working

The point being, a. you have associated the address pool with the bridge-lan via the dhcp-server. b. you associated the Ip address with two different etherports, that are also members of the bridge but NOT the bridge. and yet dont see the problem, means you either dont understand networking, or mikr...
by anav
Wed Nov 22, 2023 9:38 pm
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 99
Views: 12626

Re: Multi-WAN Load Balancing Starlink issue

No word of a lie, but I was out running on friggin mountain in Spain recently when my bowels told me I was in a dire very dire short fused situation. I went off the beaten path to ensure isolation, just in case, and was just in time. What a relief,,,,,, However, I could have really used a BIG LEAF, ...
by anav
Wed Nov 22, 2023 9:34 pm
Forum: General
Topic: multi vlan with multi wan setup
Replies: 16
Views: 2516

Re: multi vlan with multi wan setup

Here is the scoop, makes two of us who dont get it, the diagram was a good start,
however you need to
a. identify all the user(s)/device(s) and groups of users/devices
b. what traffic they should be able to accomplish.

Do not use any config speak just actual users device and traffic required.
by anav
Wed Nov 22, 2023 9:25 pm
Forum: General
Topic: multi vlan with multi wan setup
Replies: 16
Views: 2516

Re: multi vlan with multi wan setup

(1) Why would I bother commenting the config linked is missing the wireguard information, I dont work on snippets. Besides lacking in firewall rules AND ROUTES. (2) Where is the sourcenat rule for outgoing information going out ether3.................. (3) Why is ether2 sourcnat have the associated ...
by anav
Wed Nov 22, 2023 7:52 pm
Forum: Forwarding Protocols
Topic: LAN connection through WIREGUARD
Replies: 3
Views: 1303

Re: LAN connection through WIREGUARD

Depends on the firewall rules........
How did you ensure the wireguard could reach the device and config it???
by anav
Wed Nov 22, 2023 7:42 pm
Forum: Beginner Basics
Topic: Dual WAN failover, port forward not working when changing route distance
Replies: 22
Views: 2504

Re: Dual WAN failover, port forward not working when changing route distance

Okay....... (1) Point 4, big risk learn Wireguard!! (2) Point 5, good for port forwarding to work properly from the LAN side, the new rules will work the default you had would not. (2) I don't understand your point about DNS in terms of deciding server routing can you elaborate/explain as I see noth...
by anav
Wed Nov 22, 2023 6:36 pm
Forum: General
Topic: Bridge PVID [SOLVED]
Replies: 13
Views: 2876

Re: Bridge PVID [SOLVED]

Another perspective........... Dont mess with the bridge, keep it at defaults and dont use it for any data traffic. KISS!! Managment vlan would be typically identified also as a member of the management INTERFACE LIST and used for neighbours discovery and mac-server winmac-server setting. All smart ...
by anav
Wed Nov 22, 2023 6:17 pm
Forum: Beginner Basics
Topic: No Internet wireguard
Replies: 8
Views: 1270

Re: No Internet wireguard

ON MT Server Router (1) You only have one wireguard peer not three as per the diagram. (2) The peer setting on the server do not require keep alive, that is something for the client end. (3) I do not see any subnets for the LAN under IP addresses?? (4) The IP address for the WG interface is not the ...
by anav
Wed Nov 22, 2023 6:00 pm
Forum: Beginner Basics
Topic: Dual WAN failover, port forward not working when changing route distance
Replies: 22
Views: 2504

Re: Dual WAN failover, port forward not working when changing route distance

/ip route add check-gateway=ping distance=11 dst-address=0.0.0.0/0 gateway=ether1 routing-table=main add check-gateway=ping distance=12 dst-address=0.0.0.0/0 gateway=ether2 routing-table=main add dst-address=0.0.0.0/0 gateway=ether2 routing-table=to_ether2 From this setup. all user originated traffi...
by anav
Wed Nov 22, 2023 5:50 pm
Forum: Beginner Basics
Topic: Dual WAN failover, port forward not working when changing route distance
Replies: 22
Views: 2504

Re: Dual WAN failover, port forward not working when changing route distance

Observations: (1) First problem is your interface lists, there is no reason to have two separate WAN LISTS. Should be just WAN and just LAN. Anything else only leads to confusion. The reason to create interface lists is when grouping of subnets makes sense for rules, OR you need to indicate a specif...
by anav
Wed Nov 22, 2023 4:47 pm
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 1916

Re: PCC Loadbalancing and distant Port forwarding not working

Sorry still dont understand the config, (1) Why does the bridge not have an IP address assigned to it?? Why does ether 12 instead have an IP address?? Why not use something standard anyway like 10.0.0 .1 /24 Why does ether11 have some bizarro subnet assigned......?? /ip address add address= 10.0.0.7...
by anav
Wed Nov 22, 2023 3:28 pm
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 1916

Re: PCC Loadbalancing and distant Port forwarding not working

I came from zyxel myself, and yes its more ProSumer, whereas MT is more IT based programming. For example zyxel has always had a loop back button. I never knew what it did or why it was there, but on MT you have to accomplish the same thing by understanding source nat and destination nat more comple...
by anav
Wed Nov 22, 2023 3:26 pm
Forum: Beginner Basics
Topic: No Internet wireguard
Replies: 8
Views: 1270

Re: No Internet wireguard

What needs to be clear are who/what are at each end of the wireguard connections.
What is server for handshake what is peer for handshake.
A network diagram would help.
by anav
Wed Nov 22, 2023 3:23 pm
Forum: General
Topic: multi vlan with multi wan setup
Replies: 16
Views: 2516

Re: multi vlan with multi wan setup

Wrong approach ldb..... What the OP needs to do is state the requirement of traffic flow based on a. identifying user(s)/device(s) and groups of users/devices including the admin b. identify the traffic flows they should have/be able to accomplish. Without any word of the config...... A network diag...
by anav
Wed Nov 22, 2023 2:37 am
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 1916

Re: PCC Loadbalancing and distant Port forwarding not working

I also dont think you have a clue about port forwarding with a rule like this..... Created a youtube/google monster.......... ( very disorganized rule order as well ) add action=accept chain=forward dst-address=10.0.0.144 dst-port=80,443 \ protocol=tcp When the rest of the config is cleaned up I wou...
by anav
Wed Nov 22, 2023 2:28 am
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 1916

Re: PCC Loadbalancing and distant Port forwarding not working

Dont name your bridge LAN, its very confusing to the reader and probably to the router. Name it something else like bridge-lan I have no idea what you are doing with this so called lan subnet, is it supposed to be attached to the bridge, ether12, ether11. You are very confused......... /ip dhcp-serv...
by anav
Tue Nov 21, 2023 11:56 pm
Forum: Beginner Basics
Topic: Solid network security in RouterOS
Replies: 10
Views: 1777

Re: Solid network security in RouterOS

The MT router will only provide one subnet to the APs. That subnet can be used for the main HOMELAN wifi and the two guest WLANS will be made by the APs. To make use of the Roaming capability of wifiwave2, you will need these APs --> https://mikrotik.com/product/cap_ax They are NOT mesh. Each needs ...
by anav
Tue Nov 21, 2023 11:50 pm
Forum: General
Topic: Proton VPN suddenly stopped working
Replies: 8
Views: 1795

Re: Proton VPN suddenly stopped working

Please post a real config in the standard format. That was a horrible abomination to look at.

/export file=anynameyouwish (minus router serial number and any public WANIP information, keys etc....)
by anav
Tue Nov 21, 2023 9:00 pm
Forum: Beginner Basics
Topic: Solid network security in RouterOS
Replies: 10
Views: 1777

Re: Solid network security in RouterOS

Nope! The MT has not wifi controls over non-MT wifi appliances. It can firewall, queue, etc like any other vlan.
by anav
Tue Nov 21, 2023 8:57 pm
Forum: General
Topic: wireguard not working any more
Replies: 10
Views: 2037

Re: wireguard not working any more

The reason for the suggestion of /29 mask was due to the following sentence (requirements driven). Quote: " I used wireguard for some time on my old RB2011 for connection to another Mikrotik router as well as for mobile connection [/b]. It worked very good. Now, with the CCR1009 I have some iss...
by anav
Tue Nov 21, 2023 1:15 pm
Forum: General
Topic: wireguard not working any more
Replies: 10
Views: 2037

Re: wireguard not working any more

Yes, give it a go, for all the suggestions, otherwise why ask for help?? As for the last point, hogwash. The MT device only creates routes automatically for local interfaces. Hence why in the route list you will see <dac> routes for local subnets and even the wireguard interface. Since the router is...
by anav
Tue Nov 21, 2023 1:09 pm
Forum: Beginner Basics
Topic: How to route all traffic through WireGuard VPN and keep LAN access? [SOLVED]
Replies: 9
Views: 2848

Re: How to route all traffic through WireGuard VPN and keep LAN access? [SOLVED]

Perhaps they block certain ports? WG can use any port you choose.
by anav
Tue Nov 21, 2023 2:49 am
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 93190

Re: v7.13beta [testing] is released!

What?, You didnt test for deserialize, like thats on page 1 of the Fetch Manual. :-)
Lest not forget at least the 10 references to that subject , in "Dummies Guide to Testing Scripts"

You guys kill me with real networking skills! We are not worthy.
by anav
Tue Nov 21, 2023 2:39 am
Forum: Scripting
Topic: GPT4 and writing scripts for Mikrotik
Replies: 51
Views: 5706

Re: GPT4 and writing scripts for Mikrotik

People can agree to disagree.
I don't agree :-P
I agree with you completely
by anav
Tue Nov 21, 2023 2:38 am
Forum: Scripting
Topic: GPT4 and writing scripts for Mikrotik
Replies: 51
Views: 5706

Re: GPT4 and writing scripts for Mikrotik

Why ?
The discussion on itself remains civil.
People can agree to disagree.
There is no discussion, its someone concerned about pushing an ideology and not using their own brain.
We have enough of that crap in the world today. ( similar to rextended's comment on social media ).
by anav
Tue Nov 21, 2023 2:33 am
Forum: Beginner Basics
Topic: Pass Voip traffic from WAN 1, have Done 3 WAN Load Balancing and Fail Over
Replies: 1
Views: 790

Re: Pass Voip traffic from WAN 1, have Done 3 WAN Load Balancing and Fail Over

How do you identify VOIP traffic, source address? --> is it contained with a subnet, if so routing rules, --> is it contained within a few IPs, if so routing rules Destination address --> is it contained with a subnet, if so routing rules, --> is it contained within a few IPs, if so routing rules An...
by anav
Tue Nov 21, 2023 2:26 am
Forum: General
Topic: wireguard not working any more
Replies: 10
Views: 2037

Re: wireguard not working any more

Your config seems off to me. Lets assume the CCR1009 is the WG server for the handshakes for both the other router and the mobile connection. (1) Not sure a /30 mask cuts it a /29 mask gives you six useable IPs, since you seem shy to use the standard /24. (2) The allowed IPs on the CCR1009 are missi...
by anav
Mon Nov 20, 2023 10:29 pm
Forum: Scripting
Topic: GPT4 and writing scripts for Mikrotik
Replies: 51
Views: 5706

Re: GPT4 and writing scripts for Mikrotik

No point in responding, this has nothing to do with MT. The troll is here to talk about GPT in some bogus cultish form............ ( the measured opines of both MKX and rextended are refreshing and indicative of open, inquisitive and reasoning minds.) . I'm only sad that the admins have not locked t...
by anav
Mon Nov 20, 2023 9:13 pm
Forum: Wireless Networking
Topic: Making APs work as a mesh - E.g., Netgear WAX220
Replies: 3
Views: 1326

Re: Making APs work as a mesh - E.g., Netgear WAX220

Why do you post the same silly questions twice??? viewtopic.php?t=201645
by anav
Mon Nov 20, 2023 9:11 pm
Forum: Wireless Networking
Topic: Using non-MT Access Points in a mesh config - does it work?
Replies: 7
Views: 1612

Re: Using non-MT Access Points in a mesh config - does it work?

Concur, and the answer is still no. MT cannot create a mesh network besides the fact that mesh APs do not handle vlan tags. What business class APs, do, besides read vlan tags is they have some sort of controller which allows efficient roaming between the APs, be it TPLINK or other vendors. With AX3...
by anav
Mon Nov 20, 2023 6:14 pm
Forum: Beginner Basics
Topic: How to route all traffic through WireGuard VPN and keep LAN access? [SOLVED]
Replies: 9
Views: 2848

Re: How to route all traffic through WireGuard VPN and keep LAN access? [SOLVED]

I see nothing wrong on the config side. You have the right allowed peer, you have firewall settings that allow the traffic. Can you post your WIreguard settings on the laptop? If you want to access the 10 subnet from the laptop you would need to have allow IPS on the laptop on its peer settings: all...
by anav
Mon Nov 20, 2023 5:39 pm
Forum: Beginner Basics
Topic: How can I see my Guest wireless users on my Router?
Replies: 5
Views: 1134

Re: How can I see my Guest wireless users on my Router?

Concur its hard to find a home AP, mesh or not that handles vlans.
All brands be it tp link etc, have a business class AP that can handle vlan tags, but they dont come in a mesh variety.
by anav
Mon Nov 20, 2023 3:51 am
Forum: Beginner Basics
Topic: How can I see my Guest wireless users on my Router?
Replies: 5
Views: 1134

Re: How can I see my Guest wireless users on my Router?

Nope, the mikrotik has nothing to do with the internal shenanigans of the AP. What it sounds like its doing is within the AP taking your 192.168.88.0 traffic and sort of splitting into both subnets. What I dont know is if its taking an .88 address for each lease and then converting/giving it to .3 a...
by anav
Mon Nov 20, 2023 3:35 am
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 99
Views: 12626

Re: Multi-WAN Load Balancing Starlink issue

Just to have a sample practical, minimalist but secure (shortNsweet) firewall available for your perusal. Its based on allowing only authorized traffic and dropping everything else. The input chain rule allowed admin access is based on a firewall address list one create and which is comprised of loc...
by anav
Sun Nov 19, 2023 5:14 pm
Forum: General
Topic: multi vlan with multi wan setup
Replies: 16
Views: 2516

Re: multi vlan with multi wan setup

This is an excellent source to review and once you have a config to show
/export file=anynameyouwish (minus router serial number and any public WANIP information.)

viewtopic.php?t=143620
by anav
Sun Nov 19, 2023 2:59 pm
Forum: General
Topic: wireguard not working any more
Replies: 10
Views: 2037

Re: wireguard not working any more

Did you forget to upgrade the admins' firmware as well?
by anav
Sun Nov 19, 2023 3:16 am
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 99
Views: 12626

Re: Multi-WAN Load Balancing Starlink issue

Jaysen, just to be clear, I was ONLY talking about the connection-mark nomenclature for Mangle rules! There is no change to either the mangles routing-mark nomenclature or especially to any naming in the IP Routes . The mangle rules for marking routes should remain as is --> useWANX , as do the IP R...
by anav
Sat Nov 18, 2023 10:01 pm
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 99
Views: 12626

Re: Multi-WAN Load Balancing Starlink issue

@Sir Bryan sounds fascinating! Any chance we could see how you setup OSPF+BDF in RoS 7 for this to work?? An examples of the type of network arrangement your espousing may be of great potential use by the OP as an alternative approach to engineer in slow time, and of utmost interest to me as well. [...
by anav
Sat Nov 18, 2023 9:13 pm
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 99
Views: 12626

Re: Multi-WAN Load Balancing Starlink issue

(1) Personally recommend you dont use the same entry names for connection marks and routing marks. It gets terribly hard to read. For instance. For the initial set of rules use connection marks incoming-WAN1 ( reflect traffic is originating from outside the router ) For the PCC traffic use connectio...
by anav
Sat Nov 18, 2023 8:13 pm
Forum: Beginner Basics
Topic: Blocking discord using address list
Replies: 9
Views: 1853

Re: Blocking discord using address list

Get an expensive router with expensive services and use their APP Patrol/control
by anav
Sat Nov 18, 2023 8:11 pm
Forum: Beginner Basics
Topic: Problem with VLAN Setup
Replies: 10
Views: 1363

Re: Problem with VLAN Setup

Personal choice. All my switches/APs get an IP from the managment VLAN but they are set fixed upon lease or I do it manually via mac address. Having all MTs on the same network makes IP neighbours discovery set to the interface List which I make and only contains the managment VLAN, I can see all my...
by anav
Sat Nov 18, 2023 4:04 pm
Forum: Beginner Basics
Topic: Problem with VLAN Setup
Replies: 10
Views: 1363

Re: Problem with VLAN Setup

On the 5009 basic math, 4 vlans, 4 addresses, but ONLY 3 pools, 3 dhcp servers, and 3 dhcp-server networks!! ( assuming either base or managment is not really being used ?? ) Plus bridge port should look like this, personal preference: /interface bridge port add bridge=bridge interface=ether2 ingres...
by anav
Sat Nov 18, 2023 4:00 pm
Forum: Beginner Basics
Topic: Problem with VLAN Setup
Replies: 10
Views: 1363

Re: Problem with VLAN Setup

AndyM1988, what everyone was asking is that you provide the relevant configuration snippets. Anyway ... On the RB5009, if you look at the hosts on the bridge (/interface bridge host print), do you see entries in the different VLANs? If your computer is connected to the CRS326, do you see its MAC ad...
by anav
Sat Nov 18, 2023 3:59 pm
Forum: Beginner Basics
Topic: Blocking discord using address list
Replies: 9
Views: 1853

Re: Blocking discord using address list

One cannot block apps with MT............
by anav
Sat Nov 18, 2023 5:49 am
Forum: Beginner Basics
Topic: wireguard connection restricted to a single internal IP [SOLVED]
Replies: 8
Views: 3364

Re: wireguard connection restricted to a single internal IP [SOLVED]

Nope, the rules are not in order and you have mixed things up... Cleaned up ... /ip firewall filter add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \ connection-state=established,related hw-offload=yes add action=accept chain=forward comment=\ "defconf: acce...
by anav
Sat Nov 18, 2023 3:25 am
Forum: General
Topic: Wireguard 7.12 peer failed
Replies: 6
Views: 1513

Re: Wireguard 7.12 peer failed

No goinag yours is a different problem. Failure to apply wireguard rules properly. Admin error!
by anav
Fri Nov 17, 2023 11:59 pm
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 99
Views: 12626

Re: Multi-WAN Load Balancing Starlink issue

(1) I personally like to use a different connection mark for the PCC LAN traffic, then what I used for the WANS, just for ease of readings, but thats personal preference. I personally do not understand what are the ramifications, if any, by having the first set of mangle rule group for routing marks...
by anav
Fri Nov 17, 2023 11:19 pm
Forum: Beginner Basics
Topic: Problem with VLAN Setup
Replies: 10
Views: 1363

Re: Problem with VLAN Setup

If its not in config format not going to look at it.

Or as TDW was trying to say ;-PPPP facts/evidence please..........
by anav
Fri Nov 17, 2023 8:48 pm
Forum: General
Topic: Secure SOHO network configuration
Replies: 14
Views: 1447

Re: Secure SOHO network configuration

You said the need was to isolate devices.............. My reply is that you cannot easily isolate devices if in the same subnet L2, aka a normal subnet or vlan. One should isolate devices in layer2 by putting them in their own subnet, makes things easy. You can put each one in a different subnet or ...
by anav
Fri Nov 17, 2023 8:11 pm
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 99
Views: 12626

Re: Multi-WAN Load Balancing Starlink issue

I'm too sexy for youtube video ;-PP { he did a decent job of reading the teleprompter which was slightly to the left of the camera, above is better LOL ) Nothing major but without discussing really what the heck his purpose was for putting distances on the routes......... Assuming some sort of very ...
by anav
Fri Nov 17, 2023 8:10 pm
Forum: General
Topic: Secure SOHO network configuration
Replies: 14
Views: 1447

Re: Secure SOHO network configuration

It is much harder to isolate devices at L2, and thus if you have untrustworthy devices keep them in their own subnet period.
You can always drill L3 holes to allow one way communication to such devices.
by anav
Fri Nov 17, 2023 7:20 pm
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 99
Views: 12626

Re: Multi-WAN Load Balancing Starlink issue

FWIW the PCC youtube vid made by MT is quite good. https://www.youtube.com/watch?v=nlb7XAv57tw Used it again to clean up an AC3 LTE setup for PCC sharing across VDSL and LTE. Only, THIS time I disabled the subtitles which all of a sudden made me see a couple of important things I missed the previou...
by anav
Fri Nov 17, 2023 6:57 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 93190

Re: v7.13beta [testing] is released!

That cat needs some exercise and less treats. Why does it have chicken/turkey looking legs LOL
by anav
Fri Nov 17, 2023 6:42 pm
Forum: General
Topic: windows client wireguard vpn ip
Replies: 4
Views: 1528

Re: windows client wireguard vpn ip

Think of allowed IPs on any device as a separate mini firewall. There are two flows of traffic - exiting the tunnel at the local device (inbound/incoming to the local LAN). - entering the tunnel at the local device (outbound/leaving the router) Therefore for the first case, the wireguard code looks ...
by anav
Fri Nov 17, 2023 5:39 pm
Forum: General
Topic: windows client wireguard vpn ip
Replies: 4
Views: 1528

Re: windows client wireguard vpn ip

The wireguard subnet should be different from the LAN subnets!

Please read here for more info on wireguard as to making guesses: viewtopic.php?t=182340
by anav
Fri Nov 17, 2023 5:35 pm
Forum: Beginner Basics
Topic: Blocking traffic to rest of network but allowing access to forwarded ports on public IP
Replies: 3
Views: 843

Re: Blocking traffic to rest of network but allowing access to forwarded ports on public IP

(1) Question about your settings here... what is vlan10? [/color]? Point of personal preference i prefer to manually untag bridge ports on the config so they show up on the export and can follow the Admin/s logic. /interface bridge vlan add bridge=bridge tagged=bridge vlan-ids= 10 add bridge=bridge ...
by anav
Fri Nov 17, 2023 5:13 pm
Forum: Announcements
Topic: v7.12.1 [stable] is released!
Replies: 252
Views: 95163

Re: v7.12 [stable] is released!

Nice explanation!
by anav
Fri Nov 17, 2023 4:27 pm
Forum: Beginner Basics
Topic: Blocking traffic to rest of network but allowing access to forwarded ports on public IP
Replies: 3
Views: 843

Re: Blocking traffic to rest of network but allowing access to forwarded ports on public IP

Full config
/export file=anynameyouwish ( minus router serial number and any public WAN IP information )
by anav
Fri Nov 17, 2023 4:25 pm
Forum: General
Topic: Secure SOHO network configuration
Replies: 14
Views: 1447

Re: Secure SOHO network configuration

Its normal to isolate users by vlans because the vlans do it as they are L2 constructs and we ensure the firewall rules do the same at L3. Whats NOT normal is your requirement to isolate wifi users from themselves within the same subnet or isolate wifi users from lan users in the same subnet. That t...
by anav
Fri Nov 17, 2023 12:55 am
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 93190

Re: v7.13beta [testing] is released!

I cant see anything but a big grey blob in the middle ????
by anav
Fri Nov 17, 2023 12:53 am
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 294
Views: 430000

Re: Using RouterOS to VLAN your network

Next item, people keep messing up on. They keep a bridge address and pool and add addresses for the vlans but FORGET about pools, dhcp server etc for the VLANS. Please add a paragraph that says, NO need for bridge to do DHCP once you have vlans make all subnets vlans for a clean, consistent approach...
by anav
Fri Nov 17, 2023 12:46 am
Forum: General
Topic: VLAN Issues
Replies: 13
Views: 2042

Re: VLAN Issues

Lets get real here you didnt read the first reference at all!! How else can you explain this...... TWO VLANS and only one pool and one dhcp server and they are not for either vlan ???? /ip pool add name=default-dhcp ranges=192.168.88.10-192.168.88.254 /ip dhcp-server add address-pool=default-dhcp i...
by anav
Fri Nov 17, 2023 12:37 am
Forum: General
Topic: Routing between two Wireguard interfaces
Replies: 4
Views: 841

Re: Routing between two Wireguard interfaces

Much appreciated on a very detailed answer. I expected to get grilled for my shiet firewall rules, keep that grilling, please. 1) I assume you are talking about my External Peer 1? b) Yes the second peer is for my external device (in this case my phone), keepalive removed. Also, what two other peer...
by anav
Thu Nov 16, 2023 11:51 pm
Forum: General
Topic: Problems with mangle-rules on RouterOS 7.12
Replies: 12
Views: 1793

Re: Problems with mangle-rules on RouterOS 7.12

/ip firewall mangle add action=mark-connection chain=prerouting connection-mark=no-mark in-interface=eth11-WAN-2 new-connection-mark=MARK-WAN-2 passthrough=yes
/ip firewall mangle add action=mark-routing chain=output connection-mark=MARK-WAN-2 new-routing-mark=WAN-2
passthrough=no
by anav
Thu Nov 16, 2023 11:44 pm
Forum: General
Topic: Routing between two Wireguard interfaces
Replies: 4
Views: 841

Re: Routing between two Wireguard interfaces

Router2 1. ALLOWED IPs. a. The first peer config line is from the client MT2, to the server MT1 - All looks good to me, just not sure why you used 172.16.0.0/30 vice the standard 172.16.0.0 /24 ?? b. The second peer is from the server MT2 to the client (laptop?). Why is there a persistent keep aliv...
by anav
Thu Nov 16, 2023 9:41 pm
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 99
Views: 12626

Re: Multi-WAN Load Balancing Starlink issue

gotsprings looks like your trying to put mikrotik wan solutions under the bus LOL. Here I am trying to figure out optimal failover WAN approaches and it turns out I just need to use BigLeaf.....................
Please send $$$$
by anav
Thu Nov 16, 2023 9:32 pm
Forum: General
Topic: Fundamental problems at MikroTik
Replies: 32
Views: 4262

Re: Fundamental problems at MikroTik

IMO documentation is pretty decent, specially if you compare it to some documentation, originating in China. For a trained IT network engineer, concur. For a fly by night DYI its woefully inadequate but since everything is based on logic and rules, no mountain is too high and there is always some s...
by anav
Thu Nov 16, 2023 7:01 pm
Forum: Beginner Basics
Topic: routing between subnets to host [SOLVED]
Replies: 6
Views: 1494

Re: routing between subnets to host [SOLVED]

Yes, the key is the firewall rules.......
by anav
Thu Nov 16, 2023 6:54 pm
Forum: Virtualization
Topic: CHR License P1 - Invalid Cloud ??
Replies: 3
Views: 1119

Re: CHR License P1 - Invalid Cloud ??

Ahh reading this ......... seems to indicate its a manual perpetual thing LOL. CHR License Levels License levels described until now do not apply to Cloud Hosted Routers (CHRs). CHR is a RouterOS version intended for running as a virtual machine. It has its own 4 license levels as well as trial wher...
by anav
Thu Nov 16, 2023 6:51 pm
Forum: Virtualization
Topic: CHR License P1 - Invalid Cloud ??
Replies: 3
Views: 1119

Re: CHR License P1 - Invalid Cloud ??

P1, limited upgrades? next renewal is later on today previous deadline march 2023..

Is there some sort of process where you have to hit the renewal button or something and before this deadline thingy.. So weird.
by anav
Thu Nov 16, 2023 6:08 pm
Forum: General
Topic: Fundamental problems at MikroTik
Replies: 32
Views: 4262

Re: Fundamental problems at MikroTik

Like I said, delete this thread its a farce from the get go.
by anav
Thu Nov 16, 2023 6:06 pm
Forum: Beginner Basics
Topic: How to route all traffic through WireGuard VPN and keep LAN access? [SOLVED]
Replies: 9
Views: 2848

Re: How to route all traffic through WireGuard VPN and keep LAN access? [SOLVED]

Thats a good sign as it looks like you are getting at least the correct IP address. There may be an issue with your windows wireguard client did you get the client from the wireguard website (if so good, if from a MS windows site, not good). Ensure you have no blocking firewall or AV on windows side...
by anav
Thu Nov 16, 2023 4:41 pm
Forum: General
Topic: VPN server like CIsco Asa Anyconnect
Replies: 6
Views: 1487

Re: VPN server like CIsco Asa Anyconnect

by anav
Thu Nov 16, 2023 4:39 pm
Forum: General
Topic: Fundamental problems at MikroTik
Replies: 32
Views: 4262

Re: Fundamental problems at MikroTik

Someone change the title... since this about obtaining the GPL source. Nobody is asking $45 USD to get GPL covered source. In fairness, I think the software license agreement does list $45 duplication fee. To get a CD with the corresponding source code for the GPL-covered programs in this distribut...
by anav
Thu Nov 16, 2023 3:42 pm
Forum: Forwarding Protocols
Topic: WAN Failover and/or recursive routing issue
Replies: 20
Views: 3224

Re: WAN Failover and/or recursive routing issue

Typically if one has a primary / failover scenario and folks want some devices to go out WAN2 then one uses routing rules. Routing rules are great for whole subnets or a few users, however if you have many users, one has two choices, a.. make as many rules as per users. b. mangle by firewall address...
by anav
Thu Nov 16, 2023 3:39 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 93190

Re: v7.13beta [testing] is released!

MT is getting better and releasing youtube videos that are helpful case in point, althought doesnt necessarily answer your migration question is a step in the right direction!
https://www.youtube.com/watch?v=37aff6d14Xk&t=485s
by anav
Thu Nov 16, 2023 3:34 pm
Forum: General
Topic: Fundamental problems at MikroTik
Replies: 32
Views: 4262

Re: Fundamental problems at MikroTik

Other than the insightful comments by justin, and factual comments by Mrz and Normis, the rest of this thread is Fake News and annoying whining. Rather than being insighful, the author of this thread is trying to incite some anger for a nothing-burger. Yawn!! Please Delete this thread, I could have ...
by anav
Thu Nov 16, 2023 3:26 pm
Forum: Beginner Basics
Topic: How to route all traffic through WireGuard VPN and keep LAN access? [SOLVED]
Replies: 9
Views: 2848

Re: How to route all traffic through WireGuard VPN and keep LAN access? [SOLVED]

Since the MT router is the server for handshake, there is no NEED for KEEP ALIVE on the peer setting for the laptop. Looking at the config, it would appear you should be able to do both. /interface list member add comment=defconf interface=bridge list=LAN add comment=defconf interface=ether1 list=WA...
by anav
Thu Nov 16, 2023 3:14 pm
Forum: General
Topic: Permanently replace factory default
Replies: 2
Views: 697

Re: Permanently replace factory default

Yes.
by anav
Thu Nov 16, 2023 2:57 pm
Forum: General
Topic: Problems with mangle-rules on RouterOS 7.12
Replies: 12
Views: 1793

Re: Problems with mangle-rules on RouterOS 7.12

The only difference between 6 and 7, is that you need to add a table, and the extra route reflects the table not the routing mark. Otherwise those two rules help ensure traffic that comes into WAN2 goes out WAN2. Not sure why you think it wont.......... You could also try adding (if a static wanip) ...
by anav
Thu Nov 16, 2023 3:12 am
Forum: General
Topic: Problems with mangle-rules on RouterOS 7.12
Replies: 12
Views: 1793

Re: Problems with mangle-rules on RouterOS 7.12

Not sure why you have three rules it should be the first rule and one more............. combo of the other two. /ip firewall mangle add action=mark-connection chain=prerouting connection-mark=no-mark in-interface=eth11-WAN-A1 new-connection-mark=MARK-WAN-A1 passthrough=yes /ip firewall mangle add ac...
by anav
Wed Nov 15, 2023 7:05 pm
Forum: Beginner Basics
Topic: 7.13 Beta 5Ghz issue (hap ax2)
Replies: 15
Views: 2117

Re: 7.13 Beta 5Ghz issue (hap ax2)

Q: why do you use Canadian country settings when you are based in Kiev ?
Everything is better in Canada!!
by anav
Wed Nov 15, 2023 6:59 pm
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 99
Views: 12626

Re: Multi-WAN Load Balancing Starlink issue

Those are dogsled miles :-)

Your second point lost its train of thought........
the reason why..... if that even if........................... ??????
by anav
Wed Nov 15, 2023 6:55 pm
Forum: General
Topic: VoIP over Wireguard Vpn: one way audio problem.
Replies: 17
Views: 2734

Re: VoIP over Wireguard Vpn: one way audio problem.

Set up SSTP between the two routerboards and run the VOIP through that vice wireguard?? Its quick and easy to set this up using mchap2 no certificates. Just for giggles on the routerboard that is client for handshake. set up this mangle rule which helps if there are any MTU issues...... If it was a ...
by anav
Wed Nov 15, 2023 5:55 pm
Forum: Beginner Basics
Topic: Port Forwarding problem
Replies: 1
Views: 923

Re: Port Forwarding problem

Please put code blocks at start/end of config, the black square with white square brackets above, on the same line as bold and underline!!

Did you read --> viewtopic.php?t=179343
by anav
Wed Nov 15, 2023 5:50 pm
Forum: Beginner Basics
Topic: dstnat rules not works
Replies: 13
Views: 1922

Re: dstnat rules not works

(1) Found this rule in your NAT rules LOL, should be in forward chain. add action=accept chain=forward comment="internet traffic" in-interface-list=\ LAN out-interface-list=WAN src-address=!10.10.0.0/24 (2) No idea why the redirect rules are not working, hopefully someone with better eyes ...
by anav
Wed Nov 15, 2023 4:59 pm
Forum: Beginner Basics
Topic: Need advice for home network with RB1100 and CRS125
Replies: 2
Views: 835

Re: Need advice for home network with RB1100 and CRS125

Wont get 1gig via wifi until maybe WIFI7, so hold off on buying new APs till then. :-)
by anav
Wed Nov 15, 2023 4:26 pm
Forum: Beginner Basics
Topic: MT as a Wireguard client: problem with routing or/and firewall
Replies: 10
Views: 1687

Re: MT as a Wireguard client: problem with routing or/and firewall

(1) Set internet detect to NONE,having it up sometimes causes issues.... (2) Yes all the users from the MT router going out WG to the ubuntu server will have as source address the wireguard IP address allocated to the MT router. There is nothing wrong with this as the MT router upon return traffic e...
by anav
Tue Nov 14, 2023 11:12 pm
Forum: Forwarding Protocols
Topic: WAN Failover and/or recursive routing issue
Replies: 20
Views: 3224

Re: WAN Failover and/or recursive routing issue

Typically to ensure WAN traffic goes out proper WAN you need: 1. Sourcenat Masquerade for that interface. Normally addressed by the default rule. add chain=srcnat action=masquerade out-interface-list=WAN 2. Mangle Rules: To ensure incoming on WANX goes out WANX add chain=prerouting action=mark-conne...
by anav
Tue Nov 14, 2023 10:44 pm
Forum: Beginner Basics
Topic: Cannot get to the config page of pihole on mikrotik [SOLVED]
Replies: 9
Views: 1870

Re: Cannot get to the config page of pihole on mikrotik [SOLVED]

If the admin URL entry was consistent across all containers then I concur it should be noted, but if its solely pi-hole centric, for you to expect MT to put tailor made solutions in their docs, for your particular scenario is a stretch.
by anav
Tue Nov 14, 2023 9:50 pm
Forum: Forwarding Protocols
Topic: WAN Failover and/or recursive routing issue
Replies: 20
Views: 3224

Re: WAN Failover and/or recursive routing issue

Network diagram would be helpful to understand what devices are involved etc. config to see the routing and mangling parts and firewall rules in context..... Also what is the problem of manually creating a standard route for the WANs.............. this will not get in the way of anything?? If for ex...
by anav
Tue Nov 14, 2023 9:02 pm
Forum: Beginner Basics
Topic: Long identyfing network in Win
Replies: 11
Views: 2156

Re: Long identyfing network in Win

You didn't hookup the spark plugs?
No gas in the car.
Dont know how to use the key? Its a push button stewpid.......
..........
...........
..........
by anav
Tue Nov 14, 2023 9:00 pm
Forum: Beginner Basics
Topic: Solid network security in RouterOS
Replies: 10
Views: 1777

Re: Solid network security in RouterOS

TP Link / Zyxel etc......... 2024 LOL
by anav
Tue Nov 14, 2023 8:21 pm
Forum: Virtualization
Topic: CHR License P1 - Invalid Cloud ??
Replies: 3
Views: 1119

CHR License P1 - Invalid Cloud ??

CHR : Why if the license block in SYSTEM shows P1 and yet in the IP CLOUD menu there is the warning in red: CHR trial licence expired NOTE in DOCS P1 (perpetual-1) license level allows CHR to run indefinitely. It is limited to 1Gbps upload per interface. All the rest of the features provided by CHR...
by anav
Tue Nov 14, 2023 8:15 pm
Forum: The Dude
Topic: Is DUDE Supported??
Replies: 7
Views: 2978

Re: Is DUDE Supported??

So the alternative is Zabbix ?? ( not the $$$$$ PRTG of course )
by anav
Tue Nov 14, 2023 7:52 pm
Forum: General
Topic: can't get upnp to work [SOLVED]
Replies: 14
Views: 1904

Re: can't get upnp to work [SOLVED]

Why do you need upnp, its like old insecure protocol..........
by anav
Tue Nov 14, 2023 7:52 pm
Forum: The Dude
Topic: Is DUDE Supported??
Replies: 7
Views: 2978

Re: Is DUDE Supported??

Not sure if thats a yes or no answer LOL
by anav
Tue Nov 14, 2023 7:46 pm
Forum: Beginner Basics
Topic: Solid network security in RouterOS
Replies: 10
Views: 1777

Re: Solid network security in RouterOS

I hope MT skips any notion of 6E and goes straight to 7.
Cap BE LOL................... On a few android phones and coming to apple phones in 2024.
by anav
Tue Nov 14, 2023 7:32 pm
Forum: Beginner Basics
Topic: Solid network security in RouterOS
Replies: 10
Views: 1777

Re: Solid network security in RouterOS

No you cannot configure one based on the other at least NEVER using backup , you can try to copy chunks of script across. Nothing wrong with the TP links depending upon model............. there business APs read vlan tags just fine. I have EAP245, EAP660HD and EAP610 myself and they all work fine wi...
by anav
Tue Nov 14, 2023 7:31 pm
Forum: Beginner Basics
Topic: Long identyfing network in Win
Replies: 11
Views: 2156

Re: Long identyfing network in Win

You may have misconfigured one of the devices..............
Unfortunately, my ouiji board is out for servicing...........
by anav
Tue Nov 14, 2023 7:17 pm
Forum: General
Topic: Block access to my LAN via WireGuard
Replies: 1
Views: 855

Re: Block access to my LAN via WireGuard

(1) Draw a diagram of your network. (2) post config /export file=anynameyouwish ( minus router serial number, any public WANIP information, keys, etc. ) Read through this --> https://forum.mikrotik.com/viewtopic.php?t=191442 Then read the script below and attempt to understand what each line means. ...
by anav
Tue Nov 14, 2023 6:24 pm
Forum: The Dude
Topic: Is DUDE Supported??
Replies: 7
Views: 2978

Is DUDE Supported??

I note that there is no DUDE manual or documentation at the newer MT DOCUMENTS SITE ????
by anav
Tue Nov 14, 2023 5:49 pm
Forum: Forwarding Protocols
Topic: IS-IS
Replies: 134
Views: 53307

Re: IS-IS

Looking way back at the comparison table, Virtual Links Supported ( ospf yes / is-is NO ). Isnt that a plus for OSPF?
by anav
Tue Nov 14, 2023 5:30 pm
Forum: Beginner Basics
Topic: dstnat rules not works
Replies: 13
Views: 1922

Re: dstnat rules not works

IF a user on casa net or domus net is bypassing PI, then perhaps its the browser using a DNS bypass ??
by anav
Tue Nov 14, 2023 5:16 pm
Forum: Beginner Basics
Topic: dstnat rules not works
Replies: 13
Views: 1922

Re: dstnat rules not works

(1) Missing last rule of input chain add chain=input action=drop comment="Drop All Else" add action=accept chain= input comment=PiHole dst-port=53 in-interface-list=\ LAN protocol=tcp ======== goes here ============= add action=accept chain= forward comment="defconf: accept in ipsec p...
by anav
Tue Nov 14, 2023 4:42 pm
Forum: Beginner Basics
Topic: dstnat rules not works
Replies: 13
Views: 1922

Re: dstnat rules not works

I only comment on full config not snippets
by anav
Tue Nov 14, 2023 4:21 pm
Forum: Beginner Basics
Topic: dstnat rules not works
Replies: 13
Views: 1922

Re: dstnat rules not works

You need to create the interface list...... a bit tricky but select INTERFACES in winbox, then SELECT TAB "Interface List" Below this Select the word lists ( on the same line as the + symbol ) You should get a popup that allows you to add a list. Hit the + symbol to add: Enter in name TRUS...
by anav
Tue Nov 14, 2023 3:37 pm
Forum: General
Topic: Dual WAN: Route specific WireGuard peer through second WAN
Replies: 7
Views: 1636

Re: Dual WAN: Route specific WireGuard peer through second WAN

Post your request in its own thread and provide a network diagram and the full config.......
/export file=anynameyouwish (minus router serial number, public WANIP information, keys, long lease lists etc...)
by anav
Tue Nov 14, 2023 3:33 pm
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 99
Views: 12626

Re: Multi-WAN Load Balancing Starlink issue

Hi Jaysen, fair question as I had not defined what that was anywhere. Since it was not clear to me which LAN side entities were getting PCCd so to speak I left it as an new interface list. It has nothing to do with the WANS.... So once you define what subnets will be included in the PCC you can add ...
by anav
Tue Nov 14, 2023 2:45 pm
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 99
Views: 12626

Re: Multi-WAN Load Balancing Starlink issue

my apologies jaysen, the information I provided is at the edge of my scope of expertise, the rest is a tad over my head.
by anav
Tue Nov 14, 2023 2:33 pm
Forum: Beginner Basics
Topic: wireguard router access while router is also in vpn, is it possible? [SOLVED]
Replies: 36
Views: 3732

Re: wireguard router access while router is also in vpn, is it possible? [SOLVED]

It was my bad LOL......... Basic stupid, went the wrong way on the Netmask bar. the first routing rule should be add dst-address=192.168.0.0 /22 action=lookup-only-in-table routing-table=main ++++++++++++++++++++++++++++++++++++++++++ What is t his route for?? You dont need it!! add comment="u...
by anav
Tue Nov 14, 2023 6:17 am
Forum: Beginner Basics
Topic: Multiple Subnets on Single Bridge Issues
Replies: 8
Views: 1613

Re: Multiple Subnets on Single Bridge Issues

Wish I could help, dont have the networking acumen, all I can see is stuffing cooked spaghetti noodles up a straw.
by anav
Tue Nov 14, 2023 6:14 am
Forum: General
Topic: Feature Request: Wireguard over VRF
Replies: 2
Views: 1739

Re: Feature Request: Wireguard over VRF

Sweet, without VRF, there appears to be anarchy in the wireguard world, I support getting rid of anarchy, with chaos :-)
by anav
Tue Nov 14, 2023 5:27 am
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 99
Views: 12626

Re: Multi-WAN Load Balancing Starlink issue

Okay you have other issues. Your way of separating users and use of vlans and bridge is very confusing. You have only one pool but then many addresses, whats going on. Looks like you should have 3 vlans, subscribers group1, subscribers group2 and servers. One bridge-lan is fine, assign the three vla...
by anav
Tue Nov 14, 2023 2:54 am
Forum: General
Topic: WireGuard and mangle routing
Replies: 25
Views: 2525

Re: WireGuard and mangle routing

The good news is that they are not polluting the internet.
I dont log noise myself, just insure the config is properly setup/secured.
by anav
Tue Nov 14, 2023 2:17 am
Forum: General
Topic: WireGuard and mangle routing
Replies: 25
Views: 2525

Re: WireGuard and mangle routing

The main table is where the router looks to sort out which routes are active, is my understanding. It doesnt necessarily use that route depending upon admin policies/rules. I dont know what happens exactly, between router and ISP, in terms of whether or not the route in the main table is required to...
by anav
Tue Nov 14, 2023 2:10 am
Forum: General
Topic: Can't send script json request [SOLVED]
Replies: 7
Views: 1218

Re: Can't send script json request [SOLVED]

Cloud flare Teething problems and pale in comparison (pun intended) to devastating solar flares. ;-)
https://www.dw.com/en/can-solar-flares- ... o-64663358
by anav
Tue Nov 14, 2023 12:34 am
Forum: General
Topic: Can't send script json request [SOLVED]
Replies: 7
Views: 1218

Re: Can't send script json request [SOLVED]

@AMMO --> They dont want to feel the wrath of the llama and thus are doing everything to appease........... I guess next up is cloudflare zero trust tunnel in an options package LOL
by anav
Tue Nov 14, 2023 12:31 am
Forum: Forwarding Protocols
Topic: WAN Failover and/or recursive routing issue
Replies: 20
Views: 3224

Re: WAN Failover and/or recursive routing issue

Think about it. You either have default routes from ppoe or IP DCHP client because on checked the box for default routes. OR You have to create them manually. ++++++++++++++++++++++++++++ If one was adding a private IP address for the WANIP directly again you would then have to add a corresponding d...
by anav
Mon Nov 13, 2023 11:39 pm
Forum: General
Topic: Can't send script json request [SOLVED]
Replies: 7
Views: 1218

Re: Can't send script json request [SOLVED]

@ MT STAFF -- >what MT ROS should do is parse JSON. The cheap hack of parsing text is a fragile approach.

Search all forums for JSON and see what you find!!
by anav
Mon Nov 13, 2023 11:35 pm
Forum: General
Topic: WireGuard and mangle routing
Replies: 25
Views: 2525

Re: WireGuard and mangle routing

You have made changes, so you say ;-), repost config so we can work from facts/evidence!
by anav
Mon Nov 13, 2023 11:26 pm
Forum: Beginner Basics
Topic: Solid network security in RouterOS
Replies: 10
Views: 1777

Re: Solid network security in RouterOS

No need for capsman controller for wifi as your other APs are not MT. One bridge, as many vlans as you need for isolated networks. Best reference for vlan setup - https://forum.mikrotik.com/viewtopic.php?t=143620 Firewall advice --> https://forum.mikrotik.com/viewtopic.php?t=180838 Configuring safel...
by anav
Mon Nov 13, 2023 9:48 pm
Forum: Beginner Basics
Topic: Multiple Subnets on Single Bridge Issues
Replies: 8
Views: 1613

Re: Multiple Subnets on Single Bridge Issues

I have white clothes on, not diving in LOL
by anav
Mon Nov 13, 2023 8:51 pm
Forum: Beginner Basics
Topic: dstnat rules not works
Replies: 13
Views: 1922

Re: dstnat rules not works

(1) Only see two subnets being directed to the pi (veth)...... so the rest are not supposed to is that correct?? add address=192.168.0.0/24 dns-server= 192.168.55.55 gateway=192.168.0.1 \ netmask=24 add address=192.168.240.0/24 dns-server= 192.168.55.55 gateway=192.168.240.1 \ netmask=24 (2) Allow t...
by anav
Mon Nov 13, 2023 7:22 pm
Forum: Beginner Basics
Topic: wireguard router access while router is also in vpn, is it possible? [SOLVED]
Replies: 36
Views: 3732

Re: wireguard router access while router is also in vpn, is it possible? [SOLVED]

recommend adding this mangle rule to help with third party VPN MTU issues that seem to crop up. No harm to put this in. /ip firewall mangle add action=change-mss chain=forward comment="Clamp MSS to PMTU for Outgoing packets" new-mss=clamp-to-pmtu out-interface=wireguard-inet passthrough=ye...
by anav
Mon Nov 13, 2023 7:12 pm
Forum: Beginner Basics
Topic: wireguard router access while router is also in vpn, is it possible? [SOLVED]
Replies: 36
Views: 3732

Re: wireguard router access while router is also in vpn, is it possible? [SOLVED]

Still need some more work on FORWARD CHAIN FW RULES a. order is wrong, fastrack rule should be first, b. duplicate rule , should be deleted. We already have the rule allowing wg interface to the LAN. c. modify rule to be clearer (not an error though), we need to give access for 1.1 subnet to jellyfi...
by anav
Mon Nov 13, 2023 7:01 pm
Forum: Beginner Basics
Topic: wireguard router access while router is also in vpn, is it possible? [SOLVED]
Replies: 36
Views: 3732

Re: wireguard router access while router is also in vpn, is it possible? [SOLVED]

nohup, are you not reading what I write? That very subject is already addressed twice!! Your LAN traffic ( from 192.168.0.X to 192.168.1.X and vice versa and remote ireguard incoming as well ) will work just fine. Have you actually tested it with real world test. Keep in mind that you only allow 192...
by anav
Mon Nov 13, 2023 5:39 pm
Forum: Beginner Basics
Topic: wireguard router access while router is also in vpn, is it possible? [SOLVED]
Replies: 36
Views: 3732

Re: wireguard router access while router is also in vpn, is it possible? [SOLVED]

(1) Minor: Change this to NONE mac-server by itself is not secure access method. /tool mac-server set allowed-interface-list= LAN /tool mac-server mac-winbox set allowed-interface-list=LAN (2) Rest looks good. You should have no issues connecting from your remote Wireguard loging to a.. access the r...
by anav
Mon Nov 13, 2023 4:24 pm
Forum: General
Topic: WireGuard and mangle routing
Replies: 25
Views: 2525

Re: WireGuard and mangle routing

Dont understand your address 1.1.1.1 its a DNS address, for what purpose is it being used?? Dont understand why you consider the Wireguard subnet as part of the LAN? Is the wireguard hosting incoming traffic to the LAN? I thought it was a peer heading outbound.......??? I dont see the point of namin...
by anav
Mon Nov 13, 2023 3:59 pm
Forum: General
Topic: WireGuard and mangle routing
Replies: 25
Views: 2525

Re: WireGuard and mangle routing

Quick question, what are your wireguarding too? Another MT router, a third party VPN provider etc.... If its a third party provider did they give you a DNS to use?? If its a third party provider the extra clamping Mangle rule, provided in the above post is spot on to ensure no MTU issues!! Is it nor...
by anav
Mon Nov 13, 2023 3:38 pm
Forum: Beginner Basics
Topic: Forward port 80 on wan to 192.168.1.10:80 from outside and inside networks [SOLVED]
Replies: 11
Views: 3376

Re: Forward port 80 on wan to 192.168.1.10:80 from outside and inside networks [SOLVED]

Hi Lucas, instead, of looking at the instructions, read the link they came from so that one LEARNS what one is configuring,

viewtopic.php?t=179343
by anav
Mon Nov 13, 2023 3:29 pm
Forum: Beginner Basics
Topic: wireguard router access while router is also in vpn, is it possible? [SOLVED]
Replies: 36
Views: 3732

Re: wireguard router access while router is also in vpn, is it possible? [SOLVED]

(1) To answer your question about local access I turn your attention to the config I gave you back at post# These are the rules provided. /routing rule add dst-address=192.168.0.0 /22 action=lookup-only-in-table table=main comment="covers 192.168.0.1-192.168.3.254 " add src-address=192.168...
by anav
Mon Nov 13, 2023 1:45 am
Forum: Beginner Basics
Topic: two internet interfaces and vlan config
Replies: 8
Views: 1153

Re: two internet interfaces and vlan config

You need to clarify your intent... What do you mean by I've also left the bridge network so that the OC200 can access the internet without having a VLAN. What is OC200. Where is it located. Why do you think it needs a bridge network as if that is any better or easier than a vlan once you are using v...
by anav
Mon Nov 13, 2023 1:43 am
Forum: Beginner Basics
Topic: routing for dummies
Replies: 6
Views: 1201

Re: routing for dummies

Sure, if the other end is capable of adding more allowed IPs, ( how would we know - not communicated) thats viable as well.
by anav
Mon Nov 13, 2023 1:40 am
Forum: General
Topic: Wireguard 7.12 peer failed
Replies: 6
Views: 1513

Re: Wireguard 7.12 peer failed

So the issues have nothing to do with Wireguard when configured properly.
The issues pertain to creating automated accounts using the 'new functionality'??

If so, then you should be sending supouts to Mikrotik to ensure they know about it as we cannot fix it.
by anav
Mon Nov 13, 2023 12:52 am
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 41
Views: 6904

Re: Firewall - DNS Open? - Urgent [SOLVED]

I dont comment on partial configs.
/export file=anynameyouwish (minus router serial number, public WANIP information, keys, long lease lists etc...)
by anav
Mon Nov 13, 2023 12:48 am
Forum: General
Topic: Wireguard site-to-site routing with a central server
Replies: 8
Views: 1952

Re: Wireguard site-to-site routing with a central server

I should have been more clear, the config in ROS cannot be viewed in isolation there are many moving connected parts and thus everytime you make changes we need to see the full configuration, its fact/evidence!! Thus doing a part config on one device is way short of the mark!! /export file=anynameyo...
by anav
Mon Nov 13, 2023 12:46 am
Forum: General
Topic: Wireguard site-to-site routing with a central server
Replies: 8
Views: 1952

Re: Wireguard site-to-site routing with a central server

No the default rules are the ones that come on the router pre-configured, very basic and designed to allow a user to plug ether1 into the WAN side and ones PC into ether2 and safely navigate the internet after that one should quickly move to a better design for more complex scenarios. IN this case w...
by anav
Mon Nov 13, 2023 12:45 am
Forum: General
Topic: Wireguard 7.12 peer failed
Replies: 6
Views: 1513

Re: Wireguard 7.12 peer failed

When you have a real issue with a config ( and there is no connectivty where expected ) please post back, otherwise its just rambling whiny noise.
by anav
Mon Nov 13, 2023 12:43 am
Forum: Beginner Basics
Topic: Moving to VLANs on L009 and Netgear Prosafe managed switch
Replies: 5
Views: 1064

Re: Moving to VLANs on L009 and Netgear Prosafe managed switch

Correct just add another vlan! No it would be vlanid=XX ANY NUMBER BUT ONE , did you not read the article?? The IP for the router is the WANIP, Each subnet and in this case VLAN gets an IP address, dhcp server, dhcp-server network IP pool. Each vlan upon creation has interface bridge. Yes default fi...
by anav
Sun Nov 12, 2023 10:22 pm
Forum: Beginner Basics
Topic: two internet interfaces and vlan config
Replies: 8
Views: 1153

Re: two internet interfaces and vlan config

Observations 1. Bad nomenclature to call an etherport a WLAN it will confuse the shit out of everybody. /interface ethernet set [ find default-name=ether1 ] name=wlan_ee /interface ethernet set [ find default-name=ether5 ] name=wlan_vf Instead if you want to name it, ( so its clear that the port is ...
by anav
Sun Nov 12, 2023 9:57 pm
Forum: Beginner Basics
Topic: routing for dummies
Replies: 6
Views: 1201

Re: routing for dummies

Yes but being vague like you are is not helpful. Is the wireguard at the other send a SERVER of some sort, most likely with an IP of .1 What are the allowed IPs at the other, firewall rules etc.......... Is it a MT in VPS like CHR> Is it an MT at someones home Is it a third party VPN provider and if...
by anav
Sun Nov 12, 2023 9:35 pm
Forum: Beginner Basics
Topic: Moving to VLANs on L009 and Netgear Prosafe managed switch
Replies: 5
Views: 1064

Re: Moving to VLANs on L009 and Netgear Prosafe managed switch

Adapt, so you have two vlans and no management vlan, still you should have at least a trusted vlan then, where the admin usually works and no nefarious users or devices lurk?? That in effect becomes your base vlan in concept. One bridge, identify all vlans to the bridge, If you are worried about loc...
by anav
Sun Nov 12, 2023 9:05 pm
Forum: General
Topic: EOIP Tunnel between two Mikrotiks, one is behind CGNat with VPN with Post Forwarding
Replies: 10
Views: 1210

Re: EOIP Tunnel between two Mikrotiks, one is behind CGNat with VPN with Post Forwarding

Recommend skipping pureVPN since you have two MT routers and using a third party VPN to try some hack is a waste of time. OPTIONS: 1. Use Wireguard transparently to encrypt and run EOIP over it! Example --> https://forum.mikrotik.com/viewtopic.php?p=990837#p990836 2. Use Wireguard transparentlyy to ...
by anav
Sun Nov 12, 2023 8:54 pm
Forum: Beginner Basics
Topic: routing for dummies
Replies: 6
Views: 1201

Re: routing for dummies

Draw a diagram, to indicate, WAN connections and subnets on router and where wireguard is going to/coming from.
viewtopic.php?t=182340

Also will need full config
/export file=anynameyouwish (minus router serial number, public WANIP information, keys, long lease lists ....)
by anav
Sun Nov 12, 2023 6:57 pm
Forum: General
Topic: EOIP Tunnel between two Mikrotiks, one is behind CGNat with VPN with Post Forwarding
Replies: 10
Views: 1210

Re: EOIP Tunnel between two Mikrotiks, one is behind CGNat with VPN with Post Forwarding

So both routers are NOT mikrotik, and neither has a public IP?
by anav
Sun Nov 12, 2023 6:56 pm
Forum: Beginner Basics
Topic: Can ping VPN from ROS but not from wifi client, why?
Replies: 5
Views: 1234

Re: Can ping VPN from ROS but not from wifi client, why?

Have you solved your issue.
Also your convoluted explanation sorely needed a diagram.
by anav
Sun Nov 12, 2023 4:31 pm
Forum: General
Topic: How to disconnect active SSH or Winbox or TCP session
Replies: 9
Views: 12354

Re: How to disconnect active SSH or Winbox or TCP session

The solution is.
a. netinsall the current router, its config can no longer be trusted.
b. use a checklist for deployments and get out of the bad habit of editing router without first changing password etc.............
by anav
Sun Nov 12, 2023 4:29 pm
Forum: Beginner Basics
Topic: Creating WAN-separated VLAN
Replies: 10
Views: 1531

Re: Creating WAN-separated VLAN

Draw a network diagram so that its clearer for all.........
Not sure about mac address finessing, but the rest is very doable.
by anav
Sun Nov 12, 2023 4:28 pm
Forum: Beginner Basics
Topic: two internet interfaces and vlan config
Replies: 8
Views: 1153

Re: two internet interfaces and vlan config

I have something similar but dont use the controller. So create two vlans vlanEE10 and vlanVF20 192.168.1.0/24 192.168.2.0/24 Trunk the vlans to the ethernet port(s) leading to the AP(s)... You should have two routes already to the wans either because you have selected - use default route if using I...
by anav
Sun Nov 12, 2023 4:17 pm
Forum: Announcements
Topic: WinBox v3.40 released!
Replies: 143
Views: 132951

Re: WinBox v3.40 released!

Not all functions are in winbox though, so partially correct ;-PP
by anav
Sun Nov 12, 2023 2:51 pm
Forum: Beginner Basics
Topic: Moving to VLANs on L009 and Netgear Prosafe managed switch
Replies: 5
Views: 1064

Re: Moving to VLANs on L009 and Netgear Prosafe managed switch

Easily done follow this excellent guide.........

viewtopic.php?t=143620


Use of /interface bridge ports and /interface bridge vlans is the magic sauce for assignments!
by anav
Sun Nov 12, 2023 2:45 pm
Forum: Beginner Basics
Topic: two internet interfaces and vlan config
Replies: 8
Views: 1153

Re: two internet interfaces and vlan config

What is missing is that you need two subnets! ( and most likely vlans ) What is not clear is whether you are wired to ONE ACCESS POINT or TWO ACCESS POINTs. The diagram says PLURAL s!! but you only have two WLANS, so clarification is needed. Furthermore if its to ONE access point, is it a smart acce...
by anav
Sun Nov 12, 2023 2:44 pm
Forum: Beginner Basics
Topic: two internet interfaces and vlan config
Replies: 8
Views: 1153

Re: two internet interfaces and vlan config

To confirm. a. you have TWO WANS for internet (both cellular) b. the Cell service tends to be spotty at times and thus you want the PEOPLE to be able to switch to the other WAN. c. you will use two different WLANs to offer this option. Not a problem there is no primary or secondary WAN, both should ...
by anav
Sun Nov 12, 2023 4:17 am
Forum: General
Topic: Migrate configuration to different hardware [SOLVED]
Replies: 8
Views: 2440

Re: Migrate configuration to different hardware [SOLVED]

NO DO NOT!! use backup from one device to another!!! One approach to consider is to export your file and open in notepadd++ /export file=anynameyouwish Then you will have to edit the file to remove things that are specific identifiers to the old router. Then you can use terminal to paste entries di...
by anav
Sun Nov 12, 2023 4:12 am
Forum: Beginner Basics
Topic: New L009UiGS-2HaxD - Need help port forwarding past default config
Replies: 3
Views: 994

Re: New L009UiGS-2HaxD - Need help port forwarding past default config

My advice is a package deal, no cherry picking allowed as design always takes in context of the whole, any other approach will lead to unhappiness configing the MT router.
by anav
Sun Nov 12, 2023 3:49 am
Forum: Beginner Basics
Topic: WireGuard settings VPN mullvad [SOLVED]
Replies: 4
Views: 1543

Re: WireGuard settings VPN mullvad [SOLVED]

Get rid of the 2 mangle rules not useful. /ip firewall mangle add action=accept chain=forward in-interface=bridge-vpn out-interface=wg0 /ip firewall mangle add action=accept chain=forward in-interface=wg0 out-interface=bridge-vpn This indicates a problem, /interface list member add interface =*C lis...
by anav
Sat Nov 11, 2023 10:34 pm
Forum: Beginner Basics
Topic: WireGuard settings VPN mullvad [SOLVED]
Replies: 4
Views: 1543

Re: WireGuard settings VPN mullvad [SOLVED]

You dont want to redirect vpn dns. so modify to /ip firewall nat add action=redirect src-address=192.168.88.0/24 chain=dstnat dst-port=53 protocol=tcp /ip firewall nat add action=redirect src-address=192.168.88.0/24 chain=dstnat dst-port=53 protocol=udp Mullvad should have given you a DNS /ip dhcp-s...
by anav
Sat Nov 11, 2023 6:31 pm
Forum: Beginner Basics
Topic: orignal post disappeard.....????
Replies: 2
Views: 864

orignal post disappeard.....????

EDIT removed
by anav
Sat Nov 11, 2023 2:26 pm
Forum: Beginner Basics
Topic: New L009UiGS-2HaxD - Need help port forwarding past default config
Replies: 3
Views: 994

Re: New L009UiGS-2HaxD - Need help port forwarding past default config

Once you want to get past the default config its best to change the Forward Chain concept from allow everything except WAN not destinanted. TO Block everything unless its allowed. SO take this rule and remove it and replace with three rules. add action=drop chain=forward comment=\ "defconf: dro...
by anav
Sat Nov 11, 2023 2:24 pm
Forum: General
Topic: WireGuard and mangle routing
Replies: 25
Views: 2525

Re: WireGuard and mangle routing

Not interested unless you post the complete config. Why so smart to only post what you think we need, but asking us what is the problem, seems ironic to me. ;-)

/export file=anynameyouwish (minus router serial number, public WANIP information,keys etc.)
by anav
Fri Nov 10, 2023 10:35 pm
Forum: General
Topic: Can't ping gateway from vlan
Replies: 3
Views: 840

Re: Can't ping gateway from vlan

??????????? Its as switch not a router!

Check out this --> https://help.mikrotik.com/docs/display/ ... p+features
and this --> https://www.youtube.com/watch?v=YLtGQAQ8iS0
by anav
Fri Nov 10, 2023 9:59 pm
Forum: General
Topic: They are attacking me?
Replies: 13
Views: 1648

Re: They are attacking me?

erlinden where/how do you block port 853? add chain=forward action=drop in-interface-list=LAN dst-port=853 protocol=udp add chain=forward action=drop in-interface-list=LAN dst-port=853 protocol=tcp Or are you thinking in raw add chain=preouting action=drop dst-port=853 protocol=udp add chain=preouti...
by anav
Fri Nov 10, 2023 6:20 pm
Forum: General
Topic: Problems on routing to second gateway
Replies: 12
Views: 1320

Re: Problems on routing to second gateway

THose are shit requirements, I dont care about packets, packets dont make money, packets dont blow kisses, PEOPLE use the router.......... what do people need to do....... browse, bank, access servers, etc.......... PEOPLE can be directed to use certain traffic paths, group of users X ( a vlan) shou...
by anav
Fri Nov 10, 2023 5:55 pm
Forum: General
Topic: Problems on routing to second gateway
Replies: 12
Views: 1320

Re: Problems on routing to second gateway

Draw a diagram to hard to understand what you need as you focus on what doesnt work and need more context........ Also have no idea of the actual user traffic requirements Ensure you detail the OVPN structure, the L2TP structure in the diagram.... I see on the bridge you have assigned 3 IP addresses...
by anav
Fri Nov 10, 2023 5:28 pm
Forum: Beginner Basics
Topic: Multiple Tunnels
Replies: 14
Views: 1826

Re: Multiple Tunnels

Without better diagrams showing everything, I cannot begin to guess. You have flawed logic or missing rules, but too hard for me to tell based on the diagram I am looking at.

Add one that puts the COmputer on a network attached to a modem etc, MORE detail and showing the subnets invovled.
by anav
Fri Nov 10, 2023 3:49 pm
Forum: General
Topic: OS 7 -long term
Replies: 17
Views: 1865

Re: OS 7 -long term

MT is waiting until you give up waiting and will release it the next day.
Do you like asking questions that no one here knows and even MT staff do not know.
by anav
Fri Nov 10, 2023 3:05 pm
Forum: General
Topic: Problems on routing to second gateway
Replies: 12
Views: 1320

Re: Problems on routing to second gateway

Talking about LAN.. probably what I need is just a srcnat at "wan2", no routing then is needed. Packet come with InternetsourceIP:randomTCP - publicIPWAN2:target TCP this is destnat on my router, where I need to build config InternetsourceIP:randomTCP - internalrouterIPWAN2:target TCP now...
by anav
Fri Nov 10, 2023 3:02 pm
Forum: General
Topic: MikroTik constantly try to check ICMP to local IP on WAN interface?
Replies: 1
Views: 424

Re: MikroTik constantly try to check ICMP to local IP on WAN interface?

Without seeing how you have tortured your config, not possible.
by anav
Fri Nov 10, 2023 3:01 pm
Forum: General
Topic: How to secure the environment?
Replies: 20
Views: 1954

Re: How to secure the environment?

I will look at it today.
by anav
Fri Nov 10, 2023 2:59 pm
Forum: Beginner Basics
Topic: From documentation - why is "WAN interface is now pppoe-out"
Replies: 4
Views: 1076

Re: From documentation - why is "WAN interface is now pppoe-out"

Because the pppoe client name provided is now considered the ACTIVE INTERFACE for wan traffic, not ether1. Similarly like on my router I have a VLAN for fiber that is the active interface. In these cases ether1 is not that relevant in rules and should not be used, as the interface list for WAN needs...
by anav
Fri Nov 10, 2023 2:40 pm
Forum: Beginner Basics
Topic: MT as a Wireguard client: problem with routing or/and firewall
Replies: 10
Views: 1687

Re: MT as a Wireguard client: problem with routing or/and firewall

(1) THIRD RULE WRONG ON TWO COUNTS , bad format & duplicate. besides being nonsensical ............. learn to review your work :-) /ip address add address=192.168.88.1/24 comment=defconf interface=bridge network=\ 192.168.88.0 add address=10.8.0.5/24 comment="wg MT Address" interface=w...
by anav
Fri Nov 10, 2023 4:44 am
Forum: General
Topic: Is mikrotik update site working ? [SOLVED]
Replies: 5
Views: 1001

Re: Is mikrotik update site working ? [SOLVED]

Funny how so many posters blame everything (including inanimate objects) for their failures. ;-)
by anav
Fri Nov 10, 2023 4:42 am
Forum: Beginner Basics
Topic: MT as a Wireguard client: problem with routing or/and firewall
Replies: 10
Views: 1687

Re: MT as a Wireguard client: problem with routing or/and firewall

Anytime you make changes, you have to post a new config, I only work from facts........
  • 1
  • 4
  • 5
  • 6
  • 7
  • 8
  • 66