Community discussions

MikroTik App

Search found 3501 matches

by Zacharias
Sun Sep 05, 2021 5:42 pm
Forum: Beginner Basics
Topic: Issues with NAT rule
Replies: 13
Views: 2086

Re: Issues with NAT rule

I would recommend you to remove your Public IP... So vlan28 is your WAN interface ? The rules look fine ... I can't remove the public IP address because we have connection from more than one ISP. So the public DNS is set to resolve using the mentioned public IP address. So vlan28 is your WAN interf...
by Zacharias
Sun Sep 05, 2021 5:38 pm
Forum: Beginner Basics
Topic: VLAN
Replies: 10
Views: 1156

Re: VLAN

Yes indeed is confusing...

Many times i forget it too...
But its a L7 client-server protocol that assists L2 functionalities ...
by Zacharias
Sun Sep 05, 2021 5:32 pm
Forum: Beginner Basics
Topic: Good switch for home use or RB4011 RB5009?
Replies: 18
Views: 13103

Re: Good switch for home use or RB4011 RB5009?

The OP had CRS112 in comparison with other specific switches... Ofcorse he can get a CRS3xx... But that is another discussion... There was no comparison between CRS112 with any CRS3xx from my side ... In the small switch category I suggest you look at either TP link TL-SG3210XHP-M2 or Ubiquiti US-8-...
by Zacharias
Sat Sep 04, 2021 9:07 pm
Forum: Beginner Basics
Topic: Good switch for home use or RB4011 RB5009?
Replies: 18
Views: 13103

Re: Good switch for home use or RB4011 RB5009?

but the switching of RB5009 would be worst I think.
Worst in comparison with what device ?
by Zacharias
Sat Sep 04, 2021 8:36 pm
Forum: Beginner Basics
Topic: Good switch for home use or RB4011 RB5009?
Replies: 18
Views: 13103

Re: Good switch for home use or RB4011 RB5009?

What switch you choose or not depends on your actual needs... For example if you need POE or not and how many, if it should have SFPs and if yes how many, number of ports, the switch chip features and so on.... Personally i would choose the CRS112, with or without POE... However, between rb4011 and ...
by Zacharias
Sat Sep 04, 2021 6:15 pm
Forum: Beginner Basics
Topic: VLAN
Replies: 10
Views: 1156

Re: VLAN

@mkx, DHCP is a Layer 7 ( Application Layer ) Protocol ...
https://help.mikrotik.com/docs/display/ ... r+Networks
by Zacharias
Sat Sep 04, 2021 5:35 pm
Forum: Beginner Basics
Topic: Issues with NAT rule
Replies: 13
Views: 2086

Re: Issues with NAT rule

I would recommend you to remove your Public IP...

So vlan28 is your WAN interface ?
The rules look fine ...
by Zacharias
Sat Sep 04, 2021 4:45 pm
Forum: Beginner Basics
Topic: MikroTik hap ac lite configuration
Replies: 12
Views: 1697

Re: MikroTik hap ac lite configuration

It is a Routing matter...
You just need the correct routes on the Zyxel for each network you want to reach on the MikroTIK side ...

Screenshots are not really helpfull to see your configuration, it is better to export your config with /export hide-sensitive ...
by Zacharias
Sat Sep 04, 2021 4:26 pm
Forum: Wireless Networking
Topic: howto create WISP AP with basebox2
Replies: 5
Views: 3713

Re: howto create AP with basebox2

Post your configuration with /export hide-sensitive
by Zacharias
Sat Sep 04, 2021 4:04 pm
Forum: Beginner Basics
Topic: Setting static device ip
Replies: 20
Views: 2369

Re: Setting static device ip

Zacarias - confirmed limited access for the username and password the ISP have given me. I'll see what they will trust me with :-)
I thought so...
by Zacharias
Fri Sep 03, 2021 9:54 pm
Forum: Wireless Networking
Topic: WiFi and VLANs...VLAN filtering, MSTP or not?
Replies: 1
Views: 1084

Re: WiFi and VLANs...VLAN filtering, MSTP or not?

Bridge VLAN filtering on the AP is NOT necessary either on Capsman or Local Forwarding... Ofcorse you can configure it, but that does not make it a must... It all depends on what you need to achieve... There is an example in the wiki https://wiki.mikrotik.com/wiki/Manual:CAPsMAN_with_VLANs , as you ...
by Zacharias
Fri Sep 03, 2021 9:40 pm
Forum: Announcements
Topic: WinBox v3.29 released!
Replies: 113
Views: 35863

Re: WinBox v3.29 released!



It would be nice if we could scroll down the list ...
Or better when it would use multiple columns to fit everything without scrolling, when possible.
Yes, maybe that would be good too...
by Zacharias
Fri Sep 03, 2021 4:25 pm
Forum: Beginner Basics
Topic: gratuitous arp issue
Replies: 16
Views: 3028

Re: gratuitous arp issue

I guess there's room for bugs here
Yes, maybe ...
by Zacharias
Fri Sep 03, 2021 4:10 pm
Forum: Beginner Basics
Topic: Chateau LTE12 - Port forwarding 80 not working
Replies: 15
Views: 1667

Re: Chateau LTE12 - Port forwarding 80 not working

Normal dst nat rule -----> from the internet port is visible but appears closed Generally speaking, if a port is in listening state you can check if it is Open through the internet or not... So thats not really true... Actually a closed port is a port that is reachable but no application is listeni...
by Zacharias
Fri Sep 03, 2021 4:04 pm
Forum: Announcements
Topic: WinBox v3.29 released!
Replies: 113
Views: 35863

Re: WinBox v3.29 released!

*) added separate "Show Columns" window for list of visible columns;
It would be nice if we could scroll down the list ...
by Zacharias
Thu Sep 02, 2021 11:23 pm
Forum: Wireless Networking
Topic: Wireless Wire Dish only Power led lights
Replies: 3
Views: 966

Re: Wireless Wire Dish only Power led lights

Normally the Power and WiFi Led should be on after the alignment...
First, check the configuration on both devices, and also make sure on the AP side the status is in Running state...
Check the logs on both devices too...

Did you made any changes to their configuration ?
by Zacharias
Thu Sep 02, 2021 10:59 pm
Forum: Beginner Basics
Topic: gratuitous arp issue
Replies: 16
Views: 3028

Re: gratuitous arp issue

@mkx, how exactly MikroTIK finds that this IP is indeed in use ? What are the chances that there is another device in the same network with an APIPA address assigned and that being the same as the Phone's ( 169.254.8.184 )? I mean 169.254.8.184 is indeed duplicate or not ? From my point of view, yes...
by Zacharias
Thu Sep 02, 2021 10:32 pm
Forum: Wireless Networking
Topic: 802.11r for hAP ac2?
Replies: 75
Views: 14284

Re: 802.11r for hAP ac2?

Is that true?
As far as i know it is not implemented yet ...
by Zacharias
Thu Sep 02, 2021 9:59 pm
Forum: Beginner Basics
Topic: gratuitous arp issue
Replies: 16
Views: 3028

Re: gratuitous arp issue

The address space 169.254.x.y/16, is used when a host can not actually detect a DHCP server, thus it is assigning itself a link local address using a mechanism called APIPA ( Automatic Private IP Addressing )... So, first it seems that this device can not detect a DHCP Server... Gratuitous ARP, is u...
by Zacharias
Thu Sep 02, 2021 9:46 pm
Forum: RouterOS beta
Topic: ccr1009-8g-1s-1s+ rc1 to rc2
Replies: 1
Views: 879

Re: ccr1009-8g-1s-1s+ rc1 to rc2

Where is the problem ?
There are no details about the version thats all ...
by Zacharias
Thu Sep 02, 2021 9:31 pm
Forum: Beginner Basics
Topic: Chateau LTE12 - Port forwarding 80 not working
Replies: 15
Views: 1667

Re: Chateau LTE12 - Port forwarding 80 not working

oops, i was looking at the ipv6 firewall...
by Zacharias
Thu Sep 02, 2021 9:28 pm
Forum: General
Topic: Problem With DNS
Replies: 4
Views: 785

Re: Problem With DNS

Indeed it looks like a DNS problem...

But it can be anything wrong in your confguration that might cause this problem ...
by Zacharias
Thu Sep 02, 2021 9:15 pm
Forum: Beginner Basics
Topic: Chateau LTE12 - Port forwarding 80 not working
Replies: 15
Views: 1667

Re: Chateau LTE12 - Port forwarding 80 not working

First of all, Local address, is an address configured--assigned to one of the Routers interfaces... So, if for example you are in the subnet 10.10.10.0/24, and your Router has the address 10.10.10.1/24 and a host, the address 10.10.10.254/24, only 10.10.10.1/24 is a Local address... Also, from a qui...
by Zacharias
Thu Sep 02, 2021 9:01 pm
Forum: Wireless Networking
Topic: HELP: script to reset LTE card when internet connection is lost
Replies: 13
Views: 6109

Re: HELP: script to reset LTE card when internet connection is lost

The SIM card holder, as far as i remember from the last time i replaced the LTE modem on a WAP, is just on the back side of the PCB... no need to remove the modem...
But if you don't feel comfortable checking the SIM card holder, sure don't try it...
by Zacharias
Thu Sep 02, 2021 8:54 pm
Forum: General
Topic: RSTP and Pseudobridge
Replies: 4
Views: 810

Re: RSTP and Pseudobridge

Is there any RSTP option on your netgear?
If yes disable it...

if the port still goes in discarding state, post the configurations of both hex and wap, /export hide-sensitive
by Zacharias
Thu Sep 02, 2021 8:38 pm
Forum: Wireless Networking
Topic: I need Help For my Access Point Mikrotik sector 921 [SOLVED]
Replies: 7
Views: 1574

Re: I need Help For my Access Point Mikrotik sector 921 [SOLVED]

What do you mean you need the configuration ? Is there a starting point ? Read here: https://wiki.mikrotik.com/wiki/Manual:Interface/Wireless https://wiki.mikrotik.com/wiki/Bridging_Networks_with_SXT https://wiki.mikrotik.com/wiki/Manual:Wireless_Station_Modes https://wiki.mikrotik.com/wiki/Manual:W...
by Zacharias
Wed Sep 01, 2021 11:51 pm
Forum: General
Topic: RSTP and Pseudobridge
Replies: 4
Views: 810

Re: RSTP and Pseudobridge

No, it is not supposed to happen...
But certainly something is causing it...

Can you try station mode instead of station pseudobridge and see if the problem persists ?
by Zacharias
Wed Sep 01, 2021 10:03 pm
Forum: Wireless Networking
Topic: Omnitik U-5HnD Packet loss
Replies: 1
Views: 713

Re: Omnitik U-5HnD Packet loss

Why are you using super channel and not regulatory domain ?
by Zacharias
Wed Sep 01, 2021 9:59 pm
Forum: General
Topic: Different Public IP for different devices (On Different port preferably if posible)
Replies: 20
Views: 2632

Re: Different Public IP for different devices (On Different port preferably if posible)

@anav, you' re right on that...
Network diagrams are a must on Complex networks but not only... Even on simple topologies, visualising the Network is really helpfull...
by Zacharias
Wed Sep 01, 2021 9:55 pm
Forum: Wireless Networking
Topic: I need Help For my Access Point Mikrotik sector 921 [SOLVED]
Replies: 7
Views: 1574

Re: I need Help For my Access Point Mikrotik sector 921 [SOLVED]

What is the equipment on the client side ?
by Zacharias
Wed Sep 01, 2021 8:18 pm
Forum: Wireless Networking
Topic: I need Help For my Access Point Mikrotik sector 921 [SOLVED]
Replies: 7
Views: 1574

Re: I need Help For my Access Point Mikrotik sector 921 [SOLVED]

There is no such thing as general ideal Wireless settings for any PTP or PTMP Link... It all depends on the enviroment your Antenna exists... How crowded the air is, how much interference and noise from other Antennas there is, the obstacles between your Antenna and the CPE ( equipment on clients si...
by Zacharias
Wed Sep 01, 2021 7:57 pm
Forum: Wireless Networking
Topic: hAP ac as wireless bridge
Replies: 1
Views: 1000

Re: hAP ac as wireless bridge

What i would do is : 1. Configure the Hap in station mode ( i don't think you need any layer 2 communication with the AP or the network that the AP exists ) 2. Set the wlan interface of the HAP as WAN ( remove it from any bridge, create NAT masquerade rule for the wlan interface ) 3. Either enable D...
by Zacharias
Wed Sep 01, 2021 7:50 pm
Forum: Wireless Networking
Topic: HELP: script to reset LTE card when internet connection is lost
Replies: 13
Views: 6109

Re: HELP: script to reset LTE card when internet connection is lost

I dont't think that a reboot would solve such a problem... but anyways...

But even if the sim holder is faulty, it is easy to check it... Wap has a screw at the bottom, when you remove it you can pull it and reveal the SIM holder ...
https://help.mikrotik.com/docs/display/UM/wAP+R+ac
by Zacharias
Wed Sep 01, 2021 7:46 pm
Forum: General
Topic: Different Public IP for different devices (On Different port preferably if posible)
Replies: 20
Views: 2632

Re: Different Public IP for different devices (On Different port preferably if posible)

@OzanOral26 ,
I see no Mangle configuration in your export... nor any routes....
Neither any Route rule as @anav suggested... Which is an alternative ofcorse...
by Zacharias
Wed Sep 01, 2021 10:49 am
Forum: Wireless Networking
Topic: HELP: script to reset LTE card when internet connection is lost
Replies: 13
Views: 6109

Re: HELP: script to reset LTE card when internet connection is lost

If the SIM card holder is faulty, how can a reboot, as you said earlier, solve the problem ?
by Zacharias
Wed Sep 01, 2021 10:47 am
Forum: Beginner Basics
Topic: Setting static device ip
Replies: 20
Views: 2369

Re: Setting static device ip

Yes, ISP supplied
Then it seems you don't have Full rights...
But check again to confirm it ...
by Zacharias
Tue Aug 31, 2021 11:39 pm
Forum: General
Topic: HotSpot minimum set of HTML files
Replies: 1
Views: 572

Re: HotSpot minimum set of HTML files

What do you mean ?
If you delete the logout page, when the user logs out, there will be no page displayed that the user indeed logged out...
What would be the actual reason to delete these pages ?
by Zacharias
Tue Aug 31, 2021 11:33 pm
Forum: Beginner Basics
Topic: Setting static device ip
Replies: 20
Views: 2369

Re: Setting static device ip

@mikejp, what ROS Device, model are you using ?
Did the ISP provided you that Router or not ?

Under system users, the username you are using, does it show Full Group permissions or not ?
by Zacharias
Tue Aug 31, 2021 7:00 pm
Forum: Beginner Basics
Topic: Private VLAN on a RB4011
Replies: 24
Views: 3372

Re: Private VLAN on a RB4011

they don't pass bridge logic handled by CPU. With forwarding=yes, Enabled Bridge firewall was working just fine between 2 wireless clients on the same radio.... I could allow or drop traffic between those hosts... Edit: On different device with not the same wireless chip ( as my first test ), Bridg...
by Zacharias
Tue Aug 31, 2021 6:25 pm
Forum: RouterOS beta
Topic: ZeroTier added to RouterOS v7.1rc2
Replies: 335
Views: 311295

Re: ZeroTier added to RouterOS v7rc2

So it can be used as an alternative to a VPN connection ?
by Zacharias
Tue Aug 31, 2021 5:49 pm
Forum: Beginner Basics
Topic: Private VLAN on a RB4011
Replies: 24
Views: 3372

Re: Private VLAN on a RB4011

@mkx, my actual test was on a Wireless interface (i know it can be done with setting forwarding to no)... On a wireless interface it is obvious that more than 1 hosts can exist on that same interface... And ofcorse on the wireless interface all the traffic goes through the CPU... Thus i could effect...
by Zacharias
Tue Aug 31, 2021 5:00 pm
Forum: Beginner Basics
Topic: Private VLAN on a RB4011
Replies: 24
Views: 3372

Re: Private VLAN on a RB4011

@mkx, i have nothing to disagree with... But, when using the Bridge Firewall, in order for it to work, you must disable the hardware offload, otherwise the traffic will bypass the CPU and the Bridge Firewall filter will not work... So, since it works ( at least on a quick lab test i run ), i can onl...
by Zacharias
Tue Aug 31, 2021 4:40 pm
Forum: Beginner Basics
Topic: Chateau LTE12 - Port forwarding 80 not working
Replies: 15
Views: 1667

Re: Chateau LTE12 - Port forwarding 80 not working

Did you try to change the external port ? For example use dst port: 8080 and port: 80
Is the counter on the specific rule zero or it counts packets ?
In any case, Low ports ( <1024 ) might be blocked from your ISP for security reasons... Thats why i suggested changing your external port...
by Zacharias
Tue Aug 31, 2021 3:52 pm
Forum: Wireless Networking
Topic: HELP: script to reset LTE card when internet connection is lost
Replies: 13
Views: 6109

Re: HELP: script to reset LTE card when internet connection is lost

Is the SIM card correctly positioned ?
Is the SIM card in good condition ?
by Zacharias
Tue Aug 31, 2021 3:42 pm
Forum: Beginner Basics
Topic: Inter-vlan routing [SOLVED]
Replies: 3
Views: 1629

Re: Inter-vlan routing [SOLVED]

I would suggest you to reset to no defaults when you re doing some practice instead of working on existing configuration ...
by Zacharias
Tue Aug 31, 2021 2:09 pm
Forum: Beginner Basics
Topic: Private VLAN on a RB4011
Replies: 24
Views: 3372

Re: Private VLAN on a RB4011

If more than one user exists on the same port, then nothing on MT device can prevent those users talk to each other as long as they are in same VLAN (or none VLAN). Why not if i enable the Bridge Firewall ? You can successfully block users to reach each other using the Bridge Firewall even if they ...
by Zacharias
Tue Aug 31, 2021 2:07 pm
Forum: Wireless Networking
Topic: WDS or repeater?
Replies: 5
Views: 1765

Re: WDS or repeater?

Am not sure if station pseudobridge creates any problems here.
Since you can't use station-bridge to connect to a CAP, what i would try is let the AP out of CapsMAN, configure manually the wireless interface as AP, then configure the reapear to station bridge mode...
And test again ...
by Zacharias
Mon Aug 30, 2021 9:46 pm
Forum: Beginner Basics
Topic: Private VLAN on a RB4011
Replies: 24
Views: 3372

Re: Private VLAN on a RB4011

If more that one users exist on the same port, that would not work ...
by Zacharias
Mon Aug 30, 2021 9:20 pm
Forum: Wireless Networking
Topic: WDS or repeater?
Replies: 5
Views: 1765

Re: WDS or repeater?

Are you sure you have configured it just as a Repeater ?
Post your wireless configuration for that AP with hide-sensitive...
by Zacharias
Mon Aug 30, 2021 4:59 pm
Forum: Beginner Basics
Topic: Private VLAN on a RB4011
Replies: 24
Views: 3372

Re: Private VLAN on a RB4011

You will need to enable the use-ip-firewall feature in the Bridge settings or use-ip-firewall-for-vlan if you use VLANs so that you can filter Layer 2 traffic.... Isolating everyone from everyone is not something that will happen just because you createVLANs.. Also, you will need to adjust the firew...
by Zacharias
Mon Aug 30, 2021 4:45 pm
Forum: Beginner Basics
Topic: Private VLAN on a RB4011
Replies: 24
Views: 3372

Re: Private VLAN on a RB4011

As @anav already wrote (using different words): what exactly does "Private VLAN" mean in your context? If wikipedia article describes your view of the matter, then ... hell yes, RB4011 can run large number of private VLANs. I would like everyone connecting to RB4011 to be isolated from ea...
by Zacharias
Mon Aug 30, 2021 3:58 pm
Forum: Beginner Basics
Topic: access in between the VLAN`s
Replies: 8
Views: 1505

Re: access in between the VLAN`s

You re not using any NAT to reach your server right ?
Only Routing is needed...
by Zacharias
Mon Aug 30, 2021 3:53 pm
Forum: Beginner Basics
Topic: access in between the VLAN`s
Replies: 8
Views: 1505

Re: access in between the VLAN`s

Your problem is not the VLANs... VLANs work on Layer 2 of the OSI model... They are used to create seperate broadcast domains... So... what i would do is check my Firewall... When you try to access VLAN109 from VLAN110, what actually happens in simple words, is as soon as the traffic reaches the Rou...
by Zacharias
Mon Aug 30, 2021 3:26 pm
Forum: Wireless Networking
Topic: LHG60 Signal Value [SOLVED]
Replies: 2
Views: 1738

Re: LHG60 Signal Value [SOLVED]

Thanks a lot...
by Zacharias
Sat Aug 28, 2021 7:29 pm
Forum: General
Topic: RB4011 cannot Netinstall
Replies: 4
Views: 4021

Re: RB4011 cannot Netinstall

Disable any firewall or antivirus program running on your computer..
Disable any other network adapter except the ethernet one used for Netinstall..
Try different versions of Netinstall...
Use a switch between RB4011 and your computer, as already suggested...
by Zacharias
Sat Aug 28, 2021 7:08 pm
Forum: Wireless Networking
Topic: WDS or repeater?
Replies: 5
Views: 1765

Re: WDS or repeater?

You can not use WDS on Capsman...
by Zacharias
Sat Aug 28, 2021 7:04 pm
Forum: General
Topic: Re: No browsing for 5 min.
Replies: 1
Views: 374

Re: No browsing for 5 min.

How could that be a general problem ?
by Zacharias
Sat Aug 28, 2021 7:03 pm
Forum: Beginner Basics
Topic: VLAN by MAC Address - RB5009ug+s+in
Replies: 4
Views: 3499

Re: VLAN by MAC Address - RB5009ug+s+in

What exactly are you trying to achieve ? According to the WiKi, RB5009 supports Bridge Vlan Filtering in Hardware Level, meaning that you will not loose the Hardware offload feature... https://help.mikrotik.com/docs/display/ROS/Switch+Chip+Features Also, here you can see how Bridge VLAN filtering wo...
by Zacharias
Fri Aug 27, 2021 10:28 pm
Forum: Wireless Networking
Topic: LHG60 Signal Value [SOLVED]
Replies: 2
Views: 1738

LHG60 Signal Value [SOLVED]

I have a question for the 60 GHz Devices...
What does the Signal Value indicate ?
Am not talking about the RSSI, but for the Signal value...What is the unit of measurement for that Value ?
by Zacharias
Fri Aug 27, 2021 4:26 pm
Forum: Scripting
Topic: Mikrotik cloud access via wan2 [SOLVED]
Replies: 24
Views: 12336

Re: Mikrotik cloud access via wan2 [SOLVED]

As said earlier, you need no NAT to enter a Router that has a Public IP assigned to one of its interfaces ... Check your NAT rules again ... The only reason why you would need NAT, is if the MikroTIK is behind another Router... In that case yes you would need NAT from the Router that is before the M...
by Zacharias
Fri Aug 27, 2021 4:09 pm
Forum: Beginner Basics
Topic: Network restructuring - Access port on RB4011 technically possible
Replies: 6
Views: 1142

Re: Network restructuring - Access port on RB4011 technically possible

If am not mistaken, it will be possible in the future to implement VLAN-Filtering without CPU-Resouces
New Feature in RouterOS 7.1rc1
Nice to know that ...
by Zacharias
Fri Aug 27, 2021 4:08 pm
Forum: Scripting
Topic: Mikrotik cloud access via wan2 [SOLVED]
Replies: 24
Views: 12336

Re: Mikrotik cloud access via wan2 [SOLVED]

the cloud updates to fixed ip and i gave you the result of that
ok, so where is the problem ?
by Zacharias
Fri Aug 27, 2021 3:51 pm
Forum: Wireless Networking
Topic: capsman dualband with same SSID on different channels ?
Replies: 9
Views: 2243

Re: capsman dualband with same SSID on different channels ?

Sorry but you can't use different frequencies on the same radio Band... Can you show the details from the Network analyzer ? As you re saying, you are using two frequencies for the 2.4 GHz at the same time, lets say 2412 and 2437 and two frequencies at the same time ( without the use of secondary fr...
by Zacharias
Fri Aug 27, 2021 3:50 pm
Forum: Scripting
Topic: Mikrotik cloud access via wan2 [SOLVED]
Replies: 24
Views: 12336

Re: Mikrotik cloud access via wan2 [SOLVED]

If you create a Route with a Routing Mark, the Route will not be used unless you Route traffic specifically to that Route, by using Mangles for example... I would suggest you to add the Route and give it some time... it might take some time to update the IP of the Cloud.. normally it should be 60 se...
by Zacharias
Fri Aug 27, 2021 3:44 pm
Forum: Announcements
Topic: WinBox v3.29 released!
Replies: 113
Views: 35863

Re: WinBox v3.29 released!

I ve noticed that as soon as you open Winbox, if there is for example the Log Window open, or anyother window, if you press the ESC button multiple times the Winbox will close too... Which did not happen with the previous version... @Zacharias I do not see the behavior you're reporting. not later ....
by Zacharias
Fri Aug 27, 2021 3:40 pm
Forum: Scripting
Topic: Mikrotik cloud access via wan2 [SOLVED]
Replies: 24
Views: 12336

Re: Mikrotik cloud access via wan2 [SOLVED]

I see no Routing Marks in your Routing Table...
by Zacharias
Thu Aug 26, 2021 5:14 pm
Forum: Wireless Networking
Topic: Wireless protocol
Replies: 1
Views: 1094

Re: Wireless protocol

According to the Wiki:
any : on AP - regular 802.11 Access Point or Nstreme Access Point; on station - selects Access Point without specific sequence, it could be changed by connect-list rules.
Source : https://wiki.mikrotik.com/wiki/Manual: ... e/Wireless
by Zacharias
Thu Aug 26, 2021 5:04 pm
Forum: Announcements
Topic: WinBox v3.29 released!
Replies: 113
Views: 35863

Re: WinBox v3.29 released!

I ve noticed that as soon as you open Winbox, if there is for example the Log Window open, or anyother window, if you press the ESC button multiple times the Winbox will close too... Which did not happen with the previous version... I use saved sessions so that as soon as i enter winbox, certain win...
by Zacharias
Thu Aug 26, 2021 4:50 pm
Forum: Scripting
Topic: Mikrotik cloud access via wan2 [SOLVED]
Replies: 24
Views: 12336

Re: Mikrotik cloud access via wan2 [SOLVED]

That is not an error...
Somewhere in your Firewall you have enabled the Log and it actually shows input traffic to port 8291 (MikroTik)...
by Zacharias
Tue Aug 24, 2021 10:37 pm
Forum: RouterBOARD hardware
Topic: hAP ac2 antenna mod
Replies: 4
Views: 4927

Re: hAP ac2 antenna mod

Nice work ...
by Zacharias
Tue Aug 24, 2021 10:33 pm
Forum: General
Topic: How to configure a CCRXXXX as router with VLAN trunk ports ?
Replies: 3
Views: 1939

Re: How to configure a CCRXXXX as router with VLAN trunk ports ?

Please create a network diagram.. it will help to understand your Network topology...

In general if you want to create a Trunk port on your CCR, you can create them directly to the Interface that connects to the Nework switch...
by Zacharias
Tue Aug 24, 2021 10:26 pm
Forum: Beginner Basics
Topic: Home Lab, Hairpin NAT situation(?) not working (with vlans) [SOLVED]
Replies: 9
Views: 2993

Re: Home Lab, Hairpin NAT situation(?) not working (with vlans) [SOLVED]

1. You have no HairPin NAT configured... You only have a dst-nat rule and nothing more... For the HairPin NAT you will need a src-nat rule ,out-interface=VLAN10, src-address=the Source address, dst-address=the destination address and action=masquerade... 2. VLANs work on Layer 2 of the OSI level... ...
by Zacharias
Tue Aug 24, 2021 8:47 pm
Forum: Wireless Networking
Topic: point a point sextant G
Replies: 1
Views: 1108

Re: point a point sextant G

You should ofcorse set your Antenna to Regulatory Domain and select your Country...
Then makes multiple tests to see what frequency gives you the best results...
by Zacharias
Tue Aug 24, 2021 7:54 pm
Forum: Beginner Basics
Topic: Network restructuring - Access port on RB4011 technically possible
Replies: 6
Views: 1142

Re: Network restructuring - Access port on RB4011 technically possible

@anav is right on that, i never saw what you have connected on that Access port from the diagram... You could as well configure it as a Hybrid port. A hybrid port acts an Access port as well as a Trunk port, it accepts Tagged and Untagged frames at the same time... When an untagged frame comes in on...
by Zacharias
Tue Aug 24, 2021 1:25 pm
Forum: Beginner Basics
Topic: Network restructuring - Access port on RB4011 technically possible
Replies: 6
Views: 1142

Re: Network restructuring - Access port on RB4011 technically possible

Is it technically possible to have et10 on the RB4011 configured as an access port for VLAN30? Sure why not... You can apply Bridge VLAN filtering on RB4011, which will be implemented in Software ( CPU Resources ) ofcorse... If it was only to use the SFP port as the Trunk port, personally i would n...
by Zacharias
Mon Aug 23, 2021 9:28 pm
Forum: Beginner Basics
Topic: Routing two public ip on one interface.
Replies: 1
Views: 651

Re: Routing two public ip on one interface.

On your NAT rules, create a NAT rule with action=masquerade chain=src-nat and src-address=the LAN subnet you want to use that specific WAN, out-interface= the WAN you want... Place it on top...
by Zacharias
Mon Aug 23, 2021 9:22 pm
Forum: RouterBOARD hardware
Topic: CRS305-1G-4S+IN Rack Mounting Options
Replies: 2
Views: 2267

Re: CRS305-1G-4S+IN Rack Mounting Options

But if it is a requirement to be rackmountable, why didn't you choose a switch that can be actually placed to a rack ?
by Zacharias
Mon Aug 23, 2021 9:15 pm
Forum: Wireless Networking
Topic: point a point sextant G
Replies: 1
Views: 1108

Re: point a point sextant G

by Zacharias
Mon Aug 23, 2021 9:12 pm
Forum: General
Topic: routerboard and pfSense
Replies: 1
Views: 477

Re: routerboard and pfSense

by Zacharias
Mon Aug 23, 2021 8:57 pm
Forum: General
Topic: ASK [QoS pcq]
Replies: 3
Views: 803

Re: ASK [QoS pcq]

There are some MUM presentations about Queues...
You can find many information there ...
by Zacharias
Mon Aug 23, 2021 8:54 pm
Forum: RouterBOARD hardware
Topic: RB4011 PoE out not working
Replies: 8
Views: 7213

Re: RB4011 PoE out not working

Test if you can power another POE device from your RB4011...
by Zacharias
Mon Aug 23, 2021 8:25 pm
Forum: Beginner Basics
Topic: 1 dhcp server, 2 pools, 2 different arp modes?
Replies: 6
Views: 1902

Re: 1 dhcp server, 2 pools, 2 different arp modes?

I want to have all eth in one bridge.
I never said anything different...
Let all your interfaces on one Bridge, set bridge ARP to enabled, but on the specific ethernet interface that your Guests are connected to set it to reply only...
Check again my previous post...
by Zacharias
Sun Aug 22, 2021 9:52 pm
Forum: Wireless Networking
Topic: LHG 5 doesnt connect to WIFI (different networks) but scans normally
Replies: 7
Views: 1657

Re: LHG 5 doesnt connect to WIFI (different networks) but scans normally

Sorry but i know nothing about how quick setup works... never used it...
1) i used station pseudobridge mode before (with reset), configured security profile etc;
Export your wireless configuration ...
by Zacharias
Sun Aug 22, 2021 9:45 pm
Forum: Beginner Basics
Topic: 1 dhcp server, 2 pools, 2 different arp modes?
Replies: 6
Views: 1902

Re: 1 dhcp server, 2 pools, 2 different arp modes?

On your Local network let the ARP on your Bridge Interface to enabled and set your Static IP addresses as you wish...

On the ethernet interface that is used for your Guests, set ARP to reply only... On the DHCP Server used for the Guest network, enable the add arp for leases...
by Zacharias
Sun Aug 22, 2021 7:44 pm
Forum: Scripting
Topic: Mikrotik cloud access via wan2 [SOLVED]
Replies: 24
Views: 12336

Re: Mikrotik cloud access via wan2 [SOLVED]

ok, so the cloud is updated but you can not access the device nor you can ping it, correct ?
There must be something wrong in your configuration ...

Maybe you should post your configuration with hide-sensitive ...
by Zacharias
Sun Aug 22, 2021 6:52 pm
Forum: General
Topic: RB4011iGS+RM The Dude
Replies: 1
Views: 680

Re: RB4011iGS+RM The Dude

There is no USB interface on the RB4011....

You can check the available CHR versions here https://mikrotik.com/download
by Zacharias
Sun Aug 22, 2021 6:47 pm
Forum: Beginner Basics
Topic: 1 dhcp server, 2 pools, 2 different arp modes?
Replies: 6
Views: 1902

Re: 1 dhcp server, 2 pools, 2 different arp modes?

You can't have two different ARP modes on the same Bridge...

What is that you want to achieve ?
In general, you can have ARP mode set to reply-only on your Bridge Interface and on your DHCP Server select add-arp-for-leases so that an ARP entry is created for every lease on your DHCP Server only...
by Zacharias
Sun Aug 22, 2021 6:28 pm
Forum: RouterBOARD hardware
Topic: RB4011 PoE out not working
Replies: 8
Views: 7213

Re: RB4011 PoE out not working

Check your Layer 1 ( your cable connected to the PD (Powered device) )...
by Zacharias
Sun Aug 22, 2021 6:17 pm
Forum: Wireless Networking
Topic: LHG 5 doesnt connect to WIFI (different networks) but scans normally
Replies: 7
Views: 1657

Re: LHG 5 doesnt connect to WIFI (different networks) but scans normally

You should use station-pseudobridge mode...
If your device is already configured with the quick setup, you might need to reset your device before applying again your configuration...
by Zacharias
Sun Aug 22, 2021 6:12 pm
Forum: Scripting
Topic: Mikrotik cloud access via wan2 [SOLVED]
Replies: 24
Views: 12336

Re: Mikrotik cloud access via wan2 [SOLVED]

You need no NAT, i already said that before... If the Cloud is updated with a public IP, it is accessible... Check in your firewall the Drop rules in the Input chain.. Or just creat an accept rule on chain input for 8291 and place it on top (we always prefer VPN Tunnels to access our Devices)... Can...
by Zacharias
Sun Aug 22, 2021 6:06 pm
Forum: General
Topic: OpenVPN connects, but doesn't allow connecting to LAN [SOLVED]
Replies: 10
Views: 8604

Re: OpenVPN connects, but doesn't allow connecting to LAN [SOLVED]

Great to know...

Can you enable proxy-arp on your Bridge and let your configuration as it was before, does it work now?
by Zacharias
Sun Aug 22, 2021 5:52 pm
Forum: Scripting
Topic: Mikrotik cloud access via wan2 [SOLVED]
Replies: 24
Views: 12336

Re: Mikrotik cloud access via wan2 [SOLVED]

1) why distance 10 and not 1. That is a route with a Routing Mark, in my case there was no reason to set it to 1 or 100... When you update the IP address successfully you will be able to access your Router through your static IP... Ofcorse you should allow TCP 8291 on your Firewall (not good for Se...
by Zacharias
Sun Aug 22, 2021 5:40 pm
Forum: RouterBOARD hardware
Topic: Mikrotik Audience LTE6 kit connection problem
Replies: 5
Views: 1596

Re: Mikrotik Audience LTE6 kit connection problem

ok, but as you said, some times it goes close to -120dbm ...
My opinion as already stated, is that you should imporve the signal quality and then see how it goes...
by Zacharias
Sun Aug 22, 2021 5:35 pm
Forum: The User Manager
Topic: how to prevent wifi tether users from internet access
Replies: 3
Views: 6500

Re: how to prevent wifi tether users from internet access

You 're welcome...
Ofcorse someone who has the knowledge can change the TTL again and thus having Internet again...
by Zacharias
Sun Aug 22, 2021 5:25 pm
Forum: Wireless Networking
Topic: capsman dualband with same SSID on different channels ?
Replies: 9
Views: 2243

Re: capsman dualband with same SSID on different channels ?

What exactly did you solve? As stated in my earlier post, even if you put 2 or 3 frequencies in the List, only 1 will be used... Even if you configure different frequencies, on slave configuration for example, only the frequency in the master configuration will be used... You can check that with a w...
by Zacharias
Sat Aug 21, 2021 11:06 pm
Forum: General
Topic: OpenVPN connects, but doesn't allow connecting to LAN [SOLVED]
Replies: 10
Views: 8604

Re: OpenVPN connects, but doesn't allow connecting to LAN [SOLVED]

Is the OVPN server configured in ethernet or IP mode ? You can try the IP mode and use different addresses for the OVPN than your network.. Then add the Route to your Client... I can see you are using the same IP address space for the OVPN server as your LAN network... So the Route is not needed in ...
by Zacharias
Sat Aug 21, 2021 10:56 pm
Forum: General
Topic: OpenVPN connects, but doesn't allow connecting to LAN [SOLVED]
Replies: 10
Views: 8604

Re: OpenVPN connects, but doesn't allow connecting to LAN [SOLVED]

As i mentioned in my previous post, in your OVPN client's config you should add a Route for your local network...

What is your LAN subnet ? The same are you are using on the OVPN server ?
by Zacharias
Sat Aug 21, 2021 10:55 pm
Forum: Wireless Networking
Topic: LHG 5 doesnt connect to WIFI (different networks) but scans normally
Replies: 7
Views: 1657

Re: LHG 5 doesnt connect to WIFI (different networks) but scans normally

What device are you trying to connect the LHG to ? also maybe someone can show max possible Passive PoE parameters Depends on the cable quality... In any case you can't exceed the maximum distance of the ethernet cable, which according to the standard is 100 m ... There are ways you can extend the P...
by Zacharias
Sat Aug 21, 2021 10:32 pm
Forum: General
Topic: OpenVPN connects, but doesn't allow connecting to LAN [SOLVED]
Replies: 10
Views: 8604

Re: OpenVPN connects, but doesn't allow connecting to LAN [SOLVED]

Is the OPVN client a Compuer or an other Mikrotik device ?
by Zacharias
Sat Aug 21, 2021 10:25 pm
Forum: Forwarding Protocols
Topic: SMTP, IMAP cant connect to mail server
Replies: 2
Views: 3354

Re: SMTP, IMAP cant connect to mail server

VLANs are used to create different network segments ( for network segmentation in simple words)... They work in the Layer 2 of OSI model... If you are blocking something you need to check your Firewall ... Although, when you say that some sites do work but some others dont, my mind goes to MTU probl...
by Zacharias
Sat Aug 21, 2021 10:15 pm
Forum: Beginner Basics
Topic: Problems getting 1gb internet dl speeds with CRS309-1G-8S+ [SOLVED]
Replies: 2
Views: 1096

Re: Problems getting 1gb internet dl speeds with CRS309-1G-8S+ [SOLVED]

From a quick look i can see you are using CRS309 in Routing mode, so as i can see from the Ethernet Results for this device it can achieve about 340 Mbps (in Routing with 512 Byte packets) ... https://mikrotik.com/product/crs309_1g_8s_in#fndtn-testresults So the speeds look normal... This device is ...
by Zacharias
Sat Aug 21, 2021 10:06 pm
Forum: General
Topic: OpenVPN connects, but doesn't allow connecting to LAN [SOLVED]
Replies: 10
Views: 8604

Re: OpenVPN connects, but doesn't allow connecting to LAN [SOLVED]

Is there a route to your LAN on the OVPN conifig ?

For example ( part of OVPN config):
# Add route for Remote Host's Subnet
route 192.168.10.0 255.255.255.0
by Zacharias
Sat Aug 21, 2021 9:51 pm
Forum: Beginner Basics
Topic: SXT LTE Passthrough questions
Replies: 5
Views: 1872

Re: SXT LTE Passthrough questions

It all depends on what you want to achieve...

If i were you and i only needed to connect the LTE to my computer, i would not use the passthrough at all...
However, you can check if you are able to create a VLAN on your computers network adapter...
by Zacharias
Sat Aug 21, 2021 9:46 pm
Forum: Scripting
Topic: Mikrotik cloud access via wan2 [SOLVED]
Replies: 24
Views: 12336

Re: Mikrotik cloud access via wan2 [SOLVED]

There is something wrong with your configuration then... Working example: Routing Table: /ip route add check-gateway=ping distance=10 gateway=192.168.33.1 routing-mark=Test Address List: /ip firewall address-list add address=cloud.mikrotik.com list=Cloud add address=cloud2.mikrotik.com list=Cloud2 M...
by Zacharias
Sat Aug 21, 2021 1:17 pm
Forum: RouterBOARD hardware
Topic: RB5009UG+S+IN form factor
Replies: 9
Views: 4503

Re: RB5009UG+S+IN form factor

There are small/medium Racks , as well as wall mounted small racks...
Anyways, i do understand you, it would be nice if we could have everything consuming the least space possible...
by Zacharias
Sat Aug 21, 2021 12:49 pm
Forum: Scripting
Topic: Mikrotik cloud access via wan2 [SOLVED]
Replies: 24
Views: 12336

Re: Mikrotik cloud access via wan2 [SOLVED]

On the Mangles Facility create a Rule on the output chain, with destination address cloud.mikrotik.com or cloud2.mikrotik.com (depends on the device ROS version) and then create a new Routing Mark to the WAN you want to use (that Routing Mark should ofcorse exist in your Routing Table)... You could ...
by Zacharias
Sat Aug 21, 2021 12:11 pm
Forum: RouterBOARD hardware
Topic: RB5009UG+S+IN form factor
Replies: 9
Views: 4503

Re: RB5009UG+S+IN form factor

My opinion is that the All in one idea might be nice for a home user...
In a production enviroment i dont really understand why would i need in a 1U rack space to have a switch, a Router and a POE switch all together... I will just use one more 1U space to place my POE switch and thats all...
by Zacharias
Sat Aug 21, 2021 12:09 pm
Forum: Beginner Basics
Topic: SXT LTE Passthrough questions
Replies: 5
Views: 1872

Re: SXT LTE Passthrough questions

For now i dont have a router between my SXT and my devices
Then why exactly you need the passthrough for ?
by Zacharias
Fri Aug 20, 2021 6:41 pm
Forum: General
Topic: Cannot authenticate on CCR1016-12G Router via L2TP VPN
Replies: 5
Views: 635

Re: Cannot authenticate on CCR1016-12G Router via L2TP VPN

Sorry but i ve never come up with such a problem...
And i don't really see why the special characters can cause any problem...

I do use VPNs, with complex passwords and never had a problem like the one you describe...
by Zacharias
Fri Aug 20, 2021 6:06 pm
Forum: RouterBOARD hardware
Topic: RB5009UG+S+IN form factor
Replies: 9
Views: 4503

Re: RB5009UG+S+IN form factor

@Scimitar,
right now there is no such solution ...
by Zacharias
Fri Aug 20, 2021 1:52 pm
Forum: General
Topic: ASK [QoS pcq]
Replies: 3
Views: 803

Re: ASK [QoS pcq]

If the queue size is small, you will increase the packet loss but decrease the Latency. If the queue size is big, you will decrease the packet loss but increase the Latency. It all depends on what you need and what applications are used inside your network... In any case, if you device the Total Que...
by Zacharias
Fri Aug 20, 2021 12:51 pm
Forum: Beginner Basics
Topic: SXT LTE Passthrough questions
Replies: 5
Views: 1872

Re: SXT LTE Passthrough questions

You should create a Management VLAN to access the LTE device from your Network and ether1 as the passthrough Interface ... Go to Interfaces VLAN, create a new VLAN on interface ether1 with VID lets say 10 and name it VLAN10. Assign an IP address to VLAN10, for example 192.168.10.1/24 Then on the LTE...
by Zacharias
Fri Aug 20, 2021 11:13 am
Forum: General
Topic: Cannot authenticate on CCR1016-12G Router via L2TP VPN
Replies: 5
Views: 635

Re: Cannot authenticate on CCR1016-12G Router via L2TP VPN

What Logging Rules do I need to enable? <= critical / error / firewall / info / warning
None, just check if there is any entry on the Log in red color when you re trying to connect...
What is your ROS version ?
by Zacharias
Fri Aug 20, 2021 10:59 am
Forum: RouterBOARD hardware
Topic: Mikrotik Audience LTE6 kit connection problem
Replies: 5
Views: 1596

Re: Mikrotik Audience LTE6 kit connection problem

But after some time RSRP becomes more than -120-124 and RSSI -90-92 and I can’t use the Internet anymore.
That is a really Poor signal...
So it is normal to have connection problems...
You should place the Audience somewhere with a better signal coverage...
by Zacharias
Fri Aug 20, 2021 10:54 am
Forum: RouterBOARD hardware
Topic: RB5009UG+S+IN form factor
Replies: 9
Views: 4503

Re: RB5009UG+S+IN form factor

that could be grouped to the advertised "up to 4 in a 1 HE space" with similar mounting options?
No...
Specially looking for
- PoE out
- some more SFP+
- some 10G/2.5G RJ45 ethernet
What you' re looking for is a POE Switch, not a Router...
by Zacharias
Fri Aug 20, 2021 10:52 am
Forum: General
Topic: Cannot authenticate on CCR1016-12G Router via L2TP VPN
Replies: 5
Views: 635

Re: Cannot authenticate on CCR1016-12G Router via L2TP VPN

If I use another username / PWD WITHOUT special characters I CAN logon, but ONLY via the Web interface (NOT via WinBox, that stays "stuck" on "Logging in ...")
And what does the log say on the CCR ?
by Zacharias
Fri Aug 20, 2021 9:34 am
Forum: Beginner Basics
Topic: SXT LTE6 kit connected to single PC, no Internet
Replies: 6
Views: 1230

Re: SXT LTE6 kit connected to single PC, no Internet

On Winbox, go to IP, Addresses and change from ether1 to Bridge Interface ...
by Zacharias
Fri Aug 20, 2021 9:32 am
Forum: RouterBOARD hardware
Topic: Routerboard 1100 AHx2 Ports 1-10 not working
Replies: 3
Views: 1757

Re: Routerboard 1100 AHx2 Ports 1-10 not working

If the Leds are on, even with no cable connected and you did netinstall the device, if the problem is not solved then it seems as a hardware problem...
by Zacharias
Fri Aug 20, 2021 9:29 am
Forum: Wireless Networking
Topic: capsman dualband with same SSID on different channels ?
Replies: 9
Views: 2243

Re: capsman dualband with same SSID on different channels ?

It is not possible to use multiple frequencies on a single radio. A single radio can't use more than one frequencies anyways... (except on 5GHz, when using the secondary frequency feature for 160MHz channels) The AP will only choose 1 frequency to use... So even if you put multiple frequencies in t...
by Zacharias
Thu Aug 19, 2021 1:02 am
Forum: Wireless Networking
Topic: capsman dualband with same SSID on different channels ?
Replies: 9
Views: 2243

Re: capsman dualband with same SSID on different channels ?

What exactly does not work?
Give more details ...
by Zacharias
Wed Aug 18, 2021 7:44 pm
Forum: General
Topic: RouterOS bridges have same MAC address
Replies: 20
Views: 10117

Re: RouterOS bridges have same MAC address

I'm pointing out that the idea of ​​putting a random mac-address is a bullshit. Any actual reference on that instead of your personal opinion ? The addresses created with the way i described above, are locally administered unicast MAC addresses, as far as i know and remember... So it does not look ...
by Zacharias
Wed Aug 18, 2021 7:14 pm
Forum: General
Topic: RouterOS bridges have same MAC address
Replies: 20
Views: 10117

Re: RouterOS bridges have same MAC address

just type 12 hexadecimal digits randomly
I gave an option...
You like to type 12 HEX digits, someone else might not ...
by Zacharias
Wed Aug 18, 2021 6:40 pm
Forum: RouterBOARD hardware
Topic: MikroTik RB5009UG+S+IN
Replies: 202
Views: 93317

Re: MikroTik RB5009UG+S+IN

It is likely assumed that in a rack where you want 2 or 4 of these routers, you already have some air circulation and cooling.
Some air cooling would certainly help...
by Zacharias
Wed Aug 18, 2021 6:35 pm
Forum: General
Topic: RouterOS bridges have same MAC address
Replies: 20
Views: 10117

Re: RouterOS bridges have same MAC address

An easy way to create a new MAC address is, go to /Interfaces Eoip, click add and then check the Mac address field, you can copy and use that MAC address...
Do not click OK, just exit from EoIP Facility...
by Zacharias
Wed Aug 18, 2021 6:30 pm
Forum: Beginner Basics
Topic: SXT LTE6 kit connected to single PC, no Internet
Replies: 6
Views: 1230

Re: SXT LTE6 kit connected to single PC, no Internet

1. Upgrade to 6.48.3

2. Assign 192.168.88.1/24 to your Bridge Interface, not to the slave port (ether1)
/ip address
add address=192.168.88.1/24 comment=defconf interface=ether1 network=\
    192.168.88.0

Then test again...
by Zacharias
Wed Aug 18, 2021 6:24 pm
Forum: General
Topic: only one of 2 vlans route to internet
Replies: 4
Views: 555

Re: only one of 2 vlans route to internet

Sorry but you have no VLAN configuration at all... However, from a real quick look the rule add action=drop chain=input src-address-list=!Thosts is most probably causing the second subnet not being able to resolve DNS queries, thus no internet access from youtr side... Add your second subnet to the ...
by Zacharias
Wed Aug 18, 2021 6:17 pm
Forum: General
Topic: CCR1036-8G-2S+ regular packet loss
Replies: 4
Views: 1017

Re: CCR1036-8G-2S+ regular packet loss

Have you checked the Logs on all your devices ?
by Zacharias
Mon Aug 16, 2021 8:39 pm
Forum: General
Topic: RouterOS bridges have same MAC address
Replies: 20
Views: 10117

Re: RouterOS bridges have same MAC address

Everything you need to know about Bridges is here https://help.mikrotik.com/docs/display/ROS/Bridge
by Zacharias
Mon Aug 16, 2021 8:31 pm
Forum: General
Topic: PROBLEM WHEN RESTRICTING BANDWIDTH [SOLVED]
Replies: 1
Views: 823

Re: PROBLEM WHEN RESTRICTING BANDWIDTH [SOLVED]

How do you restrict the Bandwitdh ?
With Simple queues or Queue trees and how?
by Zacharias
Mon Aug 16, 2021 8:28 pm
Forum: Wireless Networking
Topic: SXT LTE6 Partial disconnections
Replies: 5
Views: 1590

Re: SXT LTE6 Partial disconnections

Use /export hide-sensitive and post your code inside code tags...
by Zacharias
Mon Aug 16, 2021 8:19 pm
Forum: General
Topic: Cell Lock = No Carrier Aggregation
Replies: 2
Views: 1287

Re: Cell Lock = No Carrier Aggregation

Carrier aggregation indeed works even if you use Cell lock.. I ve tried it my self and it works... So there must be a reason that in your case prevents it from working... What makes a band to be considered wrong ? In any cases in the general tab of the LTE interface you can choose only the Bands tha...
by Zacharias
Mon Aug 16, 2021 8:16 pm
Forum: General
Topic: Error (a new version of modem firmware is available)
Replies: 1
Views: 871

Re: Error (a new version of modem firmware is available)

But i don't see any newer beta version than 7.1beta6 ...
Where do you get theat error ? In the logs ?
by Zacharias
Mon Aug 16, 2021 8:11 pm
Forum: General
Topic: CCR1036-8G-2S+ regular packet loss
Replies: 4
Views: 1017

Re: CCR1036-8G-2S+ regular packet loss

Are you sure no Loops are created (not physical ones)?
How have you achieved a Loop free topology ?
by Zacharias
Mon Aug 16, 2021 8:02 pm
Forum: Beginner Basics
Topic: SXT LTE6 kit connected to single PC, no Internet
Replies: 6
Views: 1230

Re: SXT LTE6 kit connected to single PC, no Internet

Export your configuration (with hide-sensitive parameter)...
by Zacharias
Mon Aug 16, 2021 8:00 pm
Forum: RouterBOARD hardware
Topic: Routerboard 1100 AHx2 Ports 1-10 not working
Replies: 3
Views: 1757

Re: Routerboard 1100 AHx2 Ports 1-10 not working

Are the Leds On even if there is no cable connected ?

you could try to netinstall your device ...

https://wiki.mikrotik.com/wiki/Manual:Netinstall
by Zacharias
Mon Aug 16, 2021 7:52 pm
Forum: Wireless Networking
Topic: SXT LTE 4 replacement
Replies: 2
Views: 1005

Re: SXT LTE 4 replacement

Cat 6 LTE supports carrier aggregation, meaning it can use more that 1 bands at the same time, thus providing better performance results...

However, even for a Cat 4 LTE, your speeds are very low...
by Zacharias
Mon Aug 16, 2021 7:42 pm
Forum: Beginner Basics
Topic: LHG LTE kit - Remote Access
Replies: 1
Views: 504

Re: LHG LTE kit - Remote Access

Not knowing more details about the network topology i don't think i can help...

In general, you could setup a VPN to access the remote Network, that is the safest and recommended way ...
by Zacharias
Mon Aug 16, 2021 7:39 pm
Forum: General
Topic: only one of 2 vlans route to internet
Replies: 4
Views: 555

Re: only one of 2 vlans route to internet

What VLAN implementation are you using ?
Bridge VLAN filtering ?
Hardware VLAN using switch chip?
Posting your configuration (with hide-sensitive) would certainly help ...
by Zacharias
Mon Aug 16, 2021 7:35 pm
Forum: Wireless Networking
Topic: SXT LTE6 Partial disconnections
Replies: 5
Views: 1590

Re: SXT LTE6 Partial disconnections

What do you mean by disconnection ?
Does the LTE interface goes down ? R flag missing ?
Or the LTE is Running ?

You can export your configuration with hide-sensitive parameter and post it so we can have a look...
by Zacharias
Sun Aug 15, 2021 10:41 pm
Forum: Beginner Basics
Topic: New to Mikrotik
Replies: 54
Views: 4895

Re: New to Mikrotik

There are many examples around the Wiki according to VLANs...
Ofcorse you can create a VLAN trunk on your CCR...

What have you tried so far ?
Network diagram ?
by Zacharias
Sat Aug 14, 2021 8:09 pm
Forum: General
Topic: Create 2 VPN with different route?
Replies: 10
Views: 4774

Re: Create 2 VPN with different route?

When one of the tunnels goes down, the route via that interface will become inactive and the one with lowest distance value will be chosen among those that remain active. @sindy, my answer was according to your responce above... Since we only have two WAN interfaces here, if one goes down, only one...
by Zacharias
Sat Aug 14, 2021 7:28 pm
Forum: General
Topic: Create 2 VPN with different route?
Replies: 10
Views: 4774

Re: Create 2 VPN with different route?

When one of the tunnels goes down, the route via that interface will become inactive and the one with lowest distance value will be chosen among those that remain active. Or he cant just use lookup instead of lookup only in table , so if the WAN in the Route Rules specified for that source address ...
by Zacharias
Sat Aug 14, 2021 7:11 pm
Forum: Wireless Networking
Topic: RBLHGR&R11e-LTE6 drops lte connection every 10-30 minutes
Replies: 5
Views: 1425

Re: RBLHGR&R11e-LTE6 drops lte connection every 10-30 minutes

Have you set the correct APN settings of your provider ?
In case the APN settings were wrong he would probably not register at all ...
by Zacharias
Thu Aug 12, 2021 1:56 pm
Forum: Beginner Basics
Topic: WinBox Cannot connect to CRS305-1G-4S+IN devices
Replies: 13
Views: 2324

Re: WinBox Cannot connect to CRS305-1G-4S+IN devices

Are you sure the problem is on the switches ?
Did you try to access them through another computer ?
by Zacharias
Thu Aug 12, 2021 1:47 pm
Forum: Beginner Basics
Topic: WinBox Cannot connect to CRS305-1G-4S+IN devices
Replies: 13
Views: 2324

Re: WinBox Cannot connect to CRS305-1G-4S+IN devices

Does the device run RouteOS or swOS ?
by Zacharias
Thu Aug 12, 2021 11:14 am
Forum: Wireless Networking
Topic: RBLHGR&R11e-LTE6 drops lte connection every 10-30 minutes
Replies: 5
Views: 1425

Re: RBLHGR&R11e-LTE6 drops lte connection every 10-30 minutes

The connection looks very good...
So there must be another reason...

On the general tab of the LTE, select only LTE in Network Mode and see how it goes ...
by Zacharias
Wed Aug 11, 2021 7:22 pm
Forum: General
Topic: L2TP interface to Bridge not working on CHR ? [SOLVED]
Replies: 33
Views: 4296

Re: L2TP interface to Bridge not working on CHR ? [SOLVED]

so you never added the bridge interface on the l2tp profile for both the client and server as it is already mentioned in the wiki... No, I added the bridge interface on the l2tp profile on server CHR side (see OP) but didn't do the same on the client side as I tought that I don't need the bridge in...
by Zacharias
Wed Aug 11, 2021 7:12 pm
Forum: General
Topic: L2TP interface to Bridge not working on CHR ? [SOLVED]
Replies: 33
Views: 4296

Re: L2TP interface to Bridge not working on CHR ? [SOLVED]

yes ok...
so you never added the bridge interface on the l2tp profile for both the client and server as it is already mentioned in the wiki...

Nice you solved it anyways...
by Zacharias
Wed Aug 11, 2021 7:06 pm
Forum: RouterBOARD hardware
Topic: LHG 5 upgrade issue
Replies: 1
Views: 1326

Re: LHG 5 upgrade issue

There are many things changed since 6.35.4...

Obviously there are some country regulations applied...
No issue to me ...
by Zacharias
Wed Aug 11, 2021 7:02 pm
Forum: General
Topic: Create 2 VPN with different route?
Replies: 10
Views: 4774

Re: Create 2 VPN with different route?

Sure it is...
Just route your VPN client through the ISP you need using either Routing Rules or Mangles Facility...
by Zacharias
Wed Aug 11, 2021 6:50 pm
Forum: Wireless Networking
Topic: RBLHGR&R11e-LTE6 drops lte connection every 10-30 minutes
Replies: 5
Views: 1425

Re: RBLHGR&R11e-LTE6 drops lte connection every 10-30 minutes

When you do register, what are the values of RSRP, RSRQ and SINR ?
by Zacharias
Wed Aug 11, 2021 6:48 pm
Forum: General
Topic: L2TP interface to Bridge not working on CHR ? [SOLVED]
Replies: 33
Views: 4296

Re: L2TP interface to Bridge not working on CHR ? [SOLVED]

But the way you describe it is that the problem was on the default profile...

Am just trying to understand what the misconfiguration was ...
by Zacharias
Wed Aug 11, 2021 6:44 pm
Forum: General
Topic: openvpn and AES-256-GCM
Replies: 17
Views: 11178

Re: openvpn and AES-256-GCM

Maybe yes, maybe no... it depends...
by Zacharias
Wed Aug 11, 2021 6:38 pm
Forum: General
Topic: openvpn and AES-256-GCM
Replies: 17
Views: 11178

Re: openvpn and AES-256-GCM

AES 256-CBC cipher is not considered strong ?
it's just deprecated for new openvpn client version, I'm not saying that AES 256-CBC is weak
It is, but it still works ...
by Zacharias
Wed Aug 11, 2021 6:25 pm
Forum: General
Topic: openvpn and AES-256-GCM
Replies: 17
Views: 11178

Re: openvpn and AES-256-GCM

so what do you suggest to implement an strong and easy VPN system for windows clients? AES 256-CBC cipher is not considered strong ? With L2tp/Ipsec I have problem when two people over same ip try to connect, one of them is kicked after few time. There is an explanation from @sindy as to why this h...
by Zacharias
Wed Aug 11, 2021 6:05 pm
Forum: General
Topic: L2TP interface to Bridge not working on CHR ? [SOLVED]
Replies: 33
Views: 4296

Re: L2TP interface to Bridge not working on CHR ? [SOLVED]

So where was the problem with adding the Bridge in the default profile ?
by Zacharias
Tue Aug 10, 2021 8:46 pm
Forum: General
Topic: Is there any way to etherboot from ether2?
Replies: 3
Views: 1398

Re: Is there any way to etherboot from ether2?

Well, i don't think so ?
Ether1 is used for that...

https://help.mikrotik.com/docs/display/ROS/Netinstall
by Zacharias
Tue Aug 10, 2021 8:07 pm
Forum: General
Topic: L2TP interface to Bridge not working on CHR ? [SOLVED]
Replies: 33
Views: 4296

Re: L2TP interface to Bridge not working on CHR ? [SOLVED]

Yes. Sorry I wasn't precise enough.
Now it is understood, thanks
by Zacharias
Tue Aug 10, 2021 7:46 pm
Forum: General
Topic: L2TP interface to Bridge not working on CHR ? [SOLVED]
Replies: 33
Views: 4296

Re: L2TP interface to Bridge not working on CHR ? [SOLVED]

the virtual switch only accepts frames with source MAC address of the NIC itself
@sindy,

you mean the VMs NIC then, right ?
by Zacharias
Tue Aug 10, 2021 7:12 pm
Forum: General
Topic: L2TP interface to Bridge not working on CHR ? [SOLVED]
Replies: 33
Views: 4296

Re: L2TP interface to Bridge not working on CHR ? [SOLVED]

the virtual switch only accepts frames with source MAC address of the NIC itself. @sindy, So you mean that if for example a VM wants to communicate with a physical host, outside the virtualization engine, that physical host will see the mac address of the VM or the mac address of the physical NIC o...
by Zacharias
Tue Aug 10, 2021 11:30 am
Forum: General
Topic: L2TP interface to Bridge not working on CHR ? [SOLVED]
Replies: 33
Views: 4296

Re: L2TP interface to Bridge not working on CHR ? [SOLVED]

@sindy, are you refering to promiscuous mode (Vmware) or something else? Yes, I do, but as it may be called otherwise on other virtualization platforms (it's called MAC address spoofing in Microsoft's Hyper-V), I was more verbose about the behaviour. ok, but why if promiscuous mode is disabled woul...
by Zacharias
Mon Aug 09, 2021 10:09 pm
Forum: General
Topic: L2TP interface to Bridge not working on CHR ? [SOLVED]
Replies: 33
Views: 4296

Re: L2TP interface to Bridge not working on CHR ? [SOLVED]

@webor,

what virtualization engine do you use ?

@sindy, are you refering to promiscuous mode ( Vmware) or something else?
by Zacharias
Mon Aug 09, 2021 8:42 pm
Forum: General
Topic: I need to know how to configure Weighted load balancing
Replies: 25
Views: 3726

Re: I need to know how to configure Weighted load balancing

@rextended, i do not care about your personal opinion at all... :D In my earlier post i just explained the importance of the probabilites because you never mentioned it at the beginning but only after i made a comment on that. 2/0 & 2/1 = 100 % is different to : 2/0 & 2/1 = 50% + 50% Nothing...
by Zacharias
Mon Aug 09, 2021 7:45 pm
Forum: General
Topic: I need to know how to configure Weighted load balancing
Replies: 25
Views: 3726

Re: I need to know how to configure Weighted load balancing

@Rextended, Page 126, indicates that using both addresses and ports gives you better possibility for even distribution. So, using lets say src address or both addresses the possibilities are less. But ofcorse, increasing the number of connections you increase the possibilities of even distribution. ...
by Zacharias
Mon Aug 09, 2021 3:42 pm
Forum: The Dude
Topic: Feature Request - Password Profile to Assign to Items
Replies: 16
Views: 10958

Re: Feature Request - Password Profile to Assign to Items

Syntesis:
Change all password on already monitored devices using ros_command("/user set rextended password=!RxR$$io22")
Yes, but how do you apply that to multiple devices in order to change the password to more than one Ros devices ?

As for the Dude, got it... nice to know...
by Zacharias
Mon Aug 09, 2021 3:35 pm
Forum: General
Topic: I need to know how to configure Weighted load balancing
Replies: 25
Views: 3726

Re: I need to know how to configure Weighted load balancing

@rextended, What exactly are you talking about ?because am totally confused... I pasted the text and the source where it belongs so that it is easier for you to read... Did you even see the word source ? Provided with a link ? Indicating where that text belongs to... That was an example, even if it ...
by Zacharias
Sun Aug 08, 2021 9:02 pm
Forum: General
Topic: I need to know how to configure Weighted load balancing
Replies: 25
Views: 3726

Re: I need to know how to configure Weighted load balancing

Each line is a different WAN and you need a SingleWAN address list for sites who don't like you changing the source-address all the time. I do agree, both addresses and ports does create a more even load distribution. As you said, there will be a problem with sites that do not like seeing a differe...
by Zacharias
Sun Aug 08, 2021 8:53 pm
Forum: The Dude
Topic: Feature Request - Password Profile to Assign to Items
Replies: 16
Views: 10958

Re: Feature Request - Password Profile to Assign to Items

I don't understand your description on post #8 ...
by Zacharias
Sun Aug 08, 2021 8:40 pm
Forum: General
Topic: I need to know how to configure Weighted load balancing
Replies: 25
Views: 3726

Re: I need to know how to configure Weighted load balancing

@rextended, This means that two completely unrelated connections could match the same PCC matcher, and would be put on the same line. PCC works better the more connections you put across it so that the hash function has more chances to produce different outputs. Source : https://update.mikrotik.com/...
by Zacharias
Sat Aug 07, 2021 8:04 pm
Forum: The Dude
Topic: Feature Request - Password Profile to Assign to Items
Replies: 16
Views: 10958

Re: Feature Request - Password Profile to Assign to Items

Am not really sure i understand ...
by Zacharias
Sat Aug 07, 2021 8:01 pm
Forum: General
Topic: Looking for recommendation [SOLVED]
Replies: 9
Views: 1623

Re: Looking for recommendation [SOLVED]

That is true...
by Zacharias
Sat Aug 07, 2021 7:56 pm
Forum: General
Topic: I need to know how to configure Weighted load balancing
Replies: 25
Views: 3726

Re: I need to know how to configure Weighted load balancing

2/0 & 2/1 = 50% + 50%.... instead 3/0, 3/1, 3/2 = 33,3_% + 33,3_% + 33,3_% for do 66,6_% / 33.3_% must used 3/0 & 3/1 omitting 3/3 @rextended how exactly did you make these calculations ? The hashing algorithm used on PCC does not divide the traffic equally... So this : 2/0 & 2/1 = 50% ...
by Zacharias
Sat Aug 07, 2021 1:57 pm
Forum: General
Topic: Looking for recommendation [SOLVED]
Replies: 9
Views: 1623

Re: Looking for recommendation [SOLVED]

Provide more details...
by Zacharias
Sat Aug 07, 2021 1:50 pm
Forum: The Dude
Topic: Feature Request - Password Profile to Assign to Items
Replies: 16
Views: 10958

Re: Feature Request - Password Profile to Assign to Items

It's already possbile on The Dude change all password at the same time since v4.
How ?
Does it change the credentials on Dude and/or the monitored devices credentials as well ?
by Zacharias
Sat Aug 07, 2021 1:39 pm
Forum: General
Topic: L2TP interface to Bridge not working on CHR ? [SOLVED]
Replies: 33
Views: 4296

Re: L2TP interface to Bridge not working on CHR ? [SOLVED]

Did you take a look here in case you miss something ?
https://wiki.mikrotik.com/wiki/Manual:B ... _bridging)
by Zacharias
Sat Aug 07, 2021 1:29 pm
Forum: General
Topic: I need to know how to configure Weighted load balancing
Replies: 25
Views: 3726

Re: I need to know how to configure Weighted load balancing

Here is an example of how you could add more weight on your WAN 1 Interface : add chain=prerouting in-interface=LAN connection-mark=no-mark dst-address-type=!local \ per-connection-classifier=both-addresses:4/0 action=mark-connection new-connection-mark=ISP1_conn add chain=prerouting in-interface=LA...
by Zacharias
Fri Aug 06, 2021 11:04 pm
Forum: General
Topic: Is blocking websites by URL really impossible?
Replies: 21
Views: 4036

Re: Is blocking websites by URL really impossible?

@mkx, also I discover than if packet is fragmented, tls-host do not work... I do not know why, I'm expecting defragment before check, but do not happen.... That is referenced already... Note that matcher will not be able to match hostname if TLS handshake frame is fragmented into multiple TCP segme...
by Zacharias
Fri Aug 06, 2021 10:50 pm
Forum: General
Topic: vlan not running
Replies: 4
Views: 1093

Re: vlan not running

Do you have IP address set on interface vlan533? If you don't, that explains
@mkx it would be in a Running state even with no address assigned on the VLAN interface...
by Zacharias
Fri Aug 06, 2021 10:40 pm
Forum: General
Topic: Switch Recommendation [SOLVED]
Replies: 13
Views: 1759

Re: Switch Recommendation [SOLVED]

and manage the ports using Winbox, as if they were all the same unit? The controller Bridge and Port extender is about virtually extending the ports. You can expand the capacity of your network without using this particular function. If this is correct, would you consider this the logical way to ex...
by Zacharias
Fri Aug 06, 2021 10:04 pm
Forum: RouterBOARD hardware
Topic: RB4011 Light Stuck On
Replies: 5
Views: 6797

Re: RB4011 Light Stuck On

Am talking about the Led on port 10 that stays on...
by Zacharias
Thu Aug 05, 2021 8:53 pm
Forum: General
Topic: 1 Network 2 DHCP's and 2 WAN's
Replies: 2
Views: 464

Re: 1 Network 2 DHCP's and 2 WAN's

ok, so you want to route the IP Phone devices through the LTE ?

That is the case ?

If yes you can either go with Routing Rules or with the Mangle Facility ....

But i need more information ...
by Zacharias
Thu Aug 05, 2021 7:48 pm
Forum: General
Topic: Cannot access VPN clients from LAN [SOLVED]
Replies: 7
Views: 1919

Re: Cannot access VPN clients from LAN [SOLVED]

192.168.16.x/24 belongs to 192.168.0.0/16... so that is why it is dropped by the firewall ...
by Zacharias
Thu Aug 05, 2021 7:45 pm
Forum: RouterOS beta
Topic: more modern ssh in routerOS please
Replies: 22
Views: 6753

Re: more modern ssh in routerOS please

@leveche does it work now if you change strong-crypto=yes ?
by Zacharias
Thu Aug 05, 2021 7:39 pm
Forum: General
Topic: Hap AC2 slow wireless
Replies: 9
Views: 1788

Re: Hap AC2 slow wireless

Check on the Registration table the channel width used by your client device.. Does it use 80 MHz ?
Also on the Status page of your AP the frequency selected ...
by Zacharias
Thu Aug 05, 2021 7:16 pm
Forum: RouterBOARD hardware
Topic: RB4011 Light Stuck On
Replies: 5
Views: 6797

Re: RB4011 Light Stuck On

I noticed if I power the RB4011 from a 48volt power supply on the back, the led of port 10 stay on.
Really ?
Ros version ?

I ve never used a 48Volt power supply on a RB4011...
by Zacharias
Thu Aug 05, 2021 7:12 pm
Forum: General
Topic: Cannot access VPN clients from LAN [SOLVED]
Replies: 7
Views: 1919

Re: Cannot access VPN clients from LAN [SOLVED]

It seems that the VPN address space you re trying to reach through yout Lan belongs to that address list...
Can you confirm that ?
If that is the pool of the VPN we re talking about 192.168.16.2-192.168.16.200, then it is obviously added to that address list (192.168.0.0/16)
by Zacharias
Thu Aug 05, 2021 6:58 pm
Forum: General
Topic: Generate connected routes with routing marks
Replies: 5
Views: 822

Re: Generate connected routes with routing marks

@pe1chl there is a little reference about Routing Rules here : https://wiki.mikrotik.com/wiki/Manual:IP/Route To my understanding, when you create a Routing Mark, what you actually do is you create a custom Table. So, as there is the Main Routing Table, the Local Routing Table there are the ones tha...
by Zacharias
Thu Aug 05, 2021 6:42 pm
Forum: General
Topic: Hap AC2 slow wireless
Replies: 9
Views: 1788

Re: Hap AC2 slow wireless

WMM is about traffic prioritization not speed ...
by Zacharias
Thu Aug 05, 2021 6:26 pm
Forum: General
Topic: Cannot access VPN clients from LAN [SOLVED]
Replies: 7
Views: 1919

Re: Cannot access VPN clients from LAN [SOLVED]

What does the rule say? It says that whatever goes in your Bridge interface and wants to go out from any interface other than your Bridge, that could be the VPN in your case, and if the address you try to reach belongs to the address list you have configured and if the chain is the forward one ( tra...
by Zacharias
Thu Aug 05, 2021 6:15 pm
Forum: The Dude
Topic: Is possible to add Winbox to Dude 6.48.3
Replies: 11
Views: 7860

Re: Is possible to add Winbox to Dude 6.48.3

I get "ERROR: could not connect to XX.XX.XX.XX
This is an indication that you can not reach or connect to the device for some reason..

It is not a problem related to The Dude and Winbox ...
by Zacharias
Thu Aug 05, 2021 6:13 pm
Forum: General
Topic: Hap AC2 slow wireless
Replies: 9
Views: 1788

Re: Hap AC2 slow wireless

Did you try 80MHz channel width ? (if it is supported by the client device)

Also, am sure you know that you cant reach the theoritical maximum right ?
by Zacharias
Wed Aug 04, 2021 8:52 pm
Forum: Beginner Basics
Topic: Multicast packets arrive twice, what did I do wrong?
Replies: 3
Views: 1679

Re: Multicast packets arrive twice, what did I do wrong?

Is your ROS version updated to 6.48.3 ?
by Zacharias
Mon Aug 02, 2021 3:03 am
Forum: Wireless Networking
Topic: Block gateway access from connected wifi clients,
Replies: 15
Views: 3592

Re: Block gateway access from connected wifi clients,

@anav as @rextended replied earlier, the packets coming from the AP are src-nated upon leaving the WAN interface of the AP, thus they will appear as coming from 192.168.1.x/24 to the Netgear. Also, you cant use the Input Chain on the AP, since you do not target an IP configured on any of the APs int...
by Zacharias
Mon Aug 02, 2021 1:46 am
Forum: Beginner Basics
Topic: Dual Wan and incoming port translation
Replies: 10
Views: 1085

Re: Dual Wan and incoming port translation

@anav, same distance on all routes ?
by Zacharias
Sun Aug 01, 2021 9:31 pm
Forum: Beginner Basics
Topic: Dual Wan and incoming port translation
Replies: 10
Views: 1085

Re: Dual Wan and incoming port translation

Maybe the OP means that NAT does not work when using the Second WAN while the first one is still UP ?
by Zacharias
Sun Aug 01, 2021 8:11 pm
Forum: RouterBOARD hardware
Topic: Add LTE SIM card to CCR1009-7G-1C-1S+
Replies: 2
Views: 2240

Re: Add LTE SIM card to CCR1009-7G-1C-1S+

There are Mikrotik LTE devices as well...

Not USB though...

https://mikrotik.com/products/group/lte-5g-products
by Zacharias
Sun Aug 01, 2021 3:39 pm
Forum: General
Topic: Slow wireless speed on Mikrotik RB912UAG-2HPnD [SOLVED]
Replies: 17
Views: 2417

Re: Slow wireless speed on Mikrotik RB912UAG-2HPnD [SOLVED]

Actually am wrong, the number of streams depends on the number of chains... And each antenna has its own chains...

So 2 chains means 2 antennas...

Correct me if am wrong...
by Zacharias
Sun Aug 01, 2021 3:01 pm
Forum: General
Topic: Slow wireless speed on Mikrotik RB912UAG-2HPnD [SOLVED]
Replies: 17
Views: 2417

Re: Slow wireless speed on Mikrotik RB912UAG-2HPnD [SOLVED]

If you can use a smartphone with 2 strams (2 antennas inside) you can reach 100Mbit/s when the link is 300Mbps-40Mhz/2S/SGI
I dont think that the number of streams depends on the number of the antennas on modern MIMO...
by Zacharias
Sun Aug 01, 2021 2:40 pm
Forum: Wireless Networking
Topic: Can cAP decide channel in a smarter way
Replies: 11
Views: 5966

Re: Can cAP decide channel in a smarter way

Am not really sure that letting the frequency to Auto will result in the optimal frequency selection...
by Zacharias
Sat Jul 31, 2021 11:25 am
Forum: General
Topic: Best Practice to keep TCP session on CCR
Replies: 5
Views: 1419

Re: Best Practice to keep TCP session on CCR

But the default timeout of an established TCP connection is already 1 Day...

https://wiki.mikrotik.com/wiki/Manual:I ... n_tracking
by Zacharias
Sat Jul 31, 2021 11:20 am
Forum: General
Topic: Local Server Can't be Accessed Because of Port [SOLVED]
Replies: 4
Views: 992

Re: Local Server Can't be Accessed Because of Port [SOLVED]

And what was the solution ?
by Zacharias
Sat Jul 31, 2021 11:18 am
Forum: RouterOS beta
Topic: Bridge to Wireguard interface [SOLVED]
Replies: 20
Views: 17433

Re: Bridge to Wireguard interface [SOLVED]

Is there a specific reason using Wireguard ?
by Zacharias
Sat Jul 31, 2021 11:14 am
Forum: Beginner Basics
Topic: Multicast packets arrive twice, what did I do wrong?
Replies: 3
Views: 1679

Re: Multicast packets arrive twice, what did I do wrong?

except that I can't figure out how to tell it not to duplicate multicast traffic over all interfaces in a bonded link. In 802.3ad connections belonging to a unique session are placed on the same link ... The ordering of Frames will not change, nor they will be split across the Links or be duplicate...
by Zacharias
Sat Jul 31, 2021 10:47 am
Forum: General
Topic: BUG or not BUG? /ip firewall nat add chain=[dstnat|srcnat]
Replies: 13
Views: 1672

Re: BUG or not BUG? /ip firewall nat add chain=[dstnat|srcnat]

Correct, the default action is the same whether using CLI or Winbox...
by Zacharias
Sat Jul 31, 2021 10:39 am
Forum: The Dude
Topic: The Dude Server on CHR free license and 1Mbps limit
Replies: 8
Views: 9772

Re: The Dude Server on CHR free license and 1Mbps limit

It is supported ...
MikroTik support don't recommend running Dude on CHR at all
Any reference on that ?
by Zacharias
Fri Jul 30, 2021 11:06 pm
Forum: The Dude
Topic: The Dude Server on CHR free license and 1Mbps limit
Replies: 8
Views: 9772

Re: The Dude Server on CHR free license and 1Mbps limit

It is limited to 1Mbps upload per interface...
https://wiki.mikrotik.com/wiki/Manual:C ... l%20guest.

No, i dont remember any message from the days when i was using a free CHR License with the Dude ...
by Zacharias
Fri Jul 30, 2021 10:39 pm
Forum: Beginner Basics
Topic: How to connect to fiber ont/cpe?
Replies: 3
Views: 815

Re: How to connect to fiber ont/cpe?

Export the configuration with hide-sensitive...
by Zacharias
Fri Jul 30, 2021 10:23 pm
Forum: General
Topic: LTE DHCP over VLAN
Replies: 7
Views: 2434

Re: LTE DHCP over VLAN

I don't think you can set VLANs on LTE interfaces because LTE interfaces are not L2 ethernet interfaces. @mkx the OP wants to use the passthrough feature... ( if i understood right ) I ve implemented a couple of times LTE passthrough the way i described in my previous post with success... There may...
by Zacharias
Fri Jul 30, 2021 10:11 pm
Forum: Wireless Networking
Topic: Block gateway access from connected wifi clients,
Replies: 15
Views: 3592

Re: Block gateway access from connected wifi clients,

@anav what is your point here?
Using RAW firewall will work as well...
by Zacharias
Thu Jul 29, 2021 10:22 pm
Forum: General
Topic: VPN - L2TP + IPSEC
Replies: 3
Views: 528

Re: VPN - L2TP + IPSEC

Then something is not correct on the way you implement the VPN connection...

You could post your configuration with hide-sensitive...
Also a network diagram always helps...
by Zacharias
Thu Jul 29, 2021 10:19 pm
Forum: General
Topic: LTE DHCP over VLAN
Replies: 7
Views: 2434

Re: LTE DHCP over VLAN

Create a management VLAN interface on the LTEs and on your Routers... For example if ether1 connects the Router to the LTE, create a VLAN interface on both devices on the ether1, and then as passthrough interface you should use the ether1 interface (not the VLAN) . The VLAN will be used for manageme...
by Zacharias
Thu Jul 29, 2021 10:11 pm
Forum: General
Topic: R11e-LTE6 Registration Status Denied
Replies: 7
Views: 1588

Re: R11e-LTE6 Registration Status Denied

I am not understanding what you mean by "moved between radio"? Could you explain?
Between antennas ...
by Zacharias
Thu Jul 29, 2021 10:03 pm
Forum: General
Topic: VPN - L2TP + IPSEC
Replies: 3
Views: 528

Re: VPN - L2TP + IPSEC

On the client machine you should remove the default Gateway option located on your VPN adapter TCP/IPv4 advanced settings...
by Zacharias
Thu Jul 29, 2021 9:55 pm
Forum: Wireless Networking
Topic: Block gateway access from connected wifi clients,
Replies: 15
Views: 3592

Re: Block gateway access from connected wifi clients,

Now i am trying to understand whats the difference between adding this rule on this RAW section vs the Filter Rules as it was shown in those tutorial guides.
Your answer is here : https://wiki.mikrotik.com/wiki/Manual:IP/Firewall/Raw
by Zacharias
Thu Jul 29, 2021 3:57 pm
Forum: RouterBOARD hardware
Topic: MikroTik RB5009UG+S+IN
Replies: 202
Views: 93317

Re: MikroTik RB5009UG+S+IN

Any information about the capabilities of the switch chip ?
Can it hardware offload while using Bridge VLAN filtering ?
Or using the old switch chip configuration ?
by Zacharias
Thu Jul 29, 2021 3:26 pm
Forum: Beginner Basics
Topic: How to connect to fiber ont/cpe?
Replies: 3
Views: 815

Re: How to connect to fiber ont/cpe?

What is the configuration on the hex ?
Port 2 of the hex or on port 2 of the raycore cp7 ?
by Zacharias
Wed Jul 28, 2021 8:53 pm
Forum: Beginner Basics
Topic: VLANS & Management VLAN
Replies: 27
Views: 10406

Re: VLANS & Management VLAN

ok @mkx thanks for your reply... The only reason i tend to configure a router like that is when i do not actually need the Bridge interface... So if i dont need it why would i create it in the first place... If something changes it is not a big deal to create a Bridge and configure my VLANs... Now i...
by Zacharias
Tue Jul 27, 2021 1:32 am
Forum: Beginner Basics
Topic: VLANS & Management VLAN
Replies: 27
Views: 10406

Re: VLANS & Management VLAN

@mkx i dont mean between ports of the same device... If you have a Router and a Switch, lets say the switch is a CRS so you apply VLANs with Bridge filtering method, on the router side ( no switch chip ), why is it bad or wrong to create your Vlans directly on the interface that connects these two ?...
by Zacharias
Mon Jul 26, 2021 10:01 pm
Forum: General
Topic: IPTV Configuration
Replies: 5
Views: 4317

Re: IPTV Configuration

Indeed the IPTv sources are inside the LAN... The CRS where the headend is connected is configured as a Querier and Permanent Multicast Router... Also all the ports in all the switches around the network where the TVs are connected have "fast-leave" enabled... Igmp-snooping is ofcorse enab...
by Zacharias
Mon Jul 26, 2021 9:27 pm
Forum: General
Topic: Bonding 802.3ad issue
Replies: 11
Views: 4247

Re: Bonding 802.3ad issue

Only CRS3xx devices support 802.3ad on hardware Level..
So am not sure if the Problem is software related to the devices that do not support LACP on hardware level... Maybe high CPU ?

I Only use 802.3ad on CRS3xx devices and i ve not seen any problems...
by Zacharias
Mon Jul 26, 2021 9:08 pm
Forum: Beginner Basics
Topic: VLANS & Management VLAN
Replies: 27
Views: 10406

Re: VLANS & Management VLAN

You can use the CCR with Software VLANs as well... In general you can create VLANs either in hardware or in Software... There are 3 ways you can do that, 1. Bridge VLAN Filtering ( it will consume CPU resources for devices that do not support it ), 2. Switch Chip VLANs ( for devices with Switch Chip...
by Zacharias
Thu Jul 22, 2021 4:48 pm
Forum: General
Topic: IPTV Configuration
Replies: 5
Views: 4317

Re: IPTV Configuration

Thanks for the replies... Can i use one of CRS328's that the Headend is connected to as the IGMP Querier and the rest of the CRS328's that the TVs are connected to just have IGMP Snooping enabled ? OR the Querier must be the Router in my network ? Does it affect the performance of the CRS328 to act ...
by Zacharias
Wed Jul 21, 2021 10:04 pm
Forum: General
Topic: IPTV Configuration
Replies: 5
Views: 4317

IPTV Configuration

I need some help to understand how IPTV works and what configuration is needed as far as the Router and switches are concerned... Up to now i ve seen that multicast packet must be installed... But what protocol must be used ? IGMP Proxy or PIM and what is better ? I found implementations with both I...
by Zacharias
Mon Jul 19, 2021 12:41 am
Forum: Beginner Basics
Topic: RouterOS do not drop unknown vlans?
Replies: 5
Views: 1102

Re: RouterOS do not drop unknown vlans?

Settng ingress filtering on the bridge itself = to stating if the vlan is not defined anywhere on the bridge then discard it from any port According to the manual it is used to limit the allowed VLANs that can access the CPU port in specific.. The ingress-filtering can be used on the CPU port (brid...
by Zacharias
Sun Jul 18, 2021 9:49 pm
Forum: General
Topic: Cannot access router over trunk+switch
Replies: 35
Views: 3186

Re: Cannot access router over trunk+switch

@anav alhough the guide you recommend is an excellent one, i ve read it many times my self and has helped me a lot is for Bridge VLAN Filtering... The switches used here, seems to me they are not any of CRS3XX Series... So if the OP uses Bridge VLAN Filtering will loose the Hardware offload on the B...
by Zacharias
Sun Jul 18, 2021 9:43 pm
Forum: General
Topic: Error on setup OVPN
Replies: 3
Views: 480

Re: Error on setup OVPN

What do you mean ?
If a user does not provide a certificate and on the server side you have enabled the require client certificate then the user will not be able to connect...
by Zacharias
Sun Jul 18, 2021 9:19 pm
Forum: General
Topic: default route prevents use of additional LTE passthrough WAN
Replies: 22
Views: 3676

Re: default route prevents use of additional LTE passthrough WAN

On your first rule set passthrough=yes Also, what comes from your first WAN connection should leave from that first WAN Interface and what comes from your second WAN should leave as well from the Second one... So, do you mark those connection on the output chain ? Example: add chain=output connectio...
by Zacharias
Sun Jul 18, 2021 9:05 pm
Forum: Beginner Basics
Topic: VLANS & Management VLAN
Replies: 27
Views: 10406

Re: VLANS & Management VLAN

Switch and Router models ? Also many information around in the Mikrotik wiki... Router - CCR1009-7G-1C-PC Switch - CRS112-8P-4S-IN CRS112 does not suppport Bridge VLAN filtering along with VLANs... So you should use the old way of VLANs... Examples here : https://wiki.mikrotik.com/wiki/Manual:CRS1x...
by Zacharias
Wed Jul 14, 2021 9:36 pm
Forum: Beginner Basics
Topic: VLANS & Management VLAN
Replies: 27
Views: 10406

Re: VLANS & Management VLAN

Switch and Router models ?

Also many information around in the Mikrotik wiki...
by Zacharias
Wed Jul 14, 2021 9:27 pm
Forum: RouterBOARD hardware
Topic: SXTsq 5 ac on CRS328-24P-4S+ POE switch 'Current too low'
Replies: 3
Views: 2381

Re: SXTsq 5 ac on CRS328-24P-4S+ POE switch 'Current too low'

Source: https://wiki.mikrotik.com/wiki/Manual:PoE-Out#PoE-Out_Monitoring current-too-low - current-too-low means that PD draws too low current (<10mA) than normal PoE-Out device should, reason for this can be: Delivered voltage at PD is too low for normal powering (for example Vmin = >30V, but provi...
by Zacharias
Wed Jul 14, 2021 9:19 pm
Forum: RouterBOARD hardware
Topic: [SOLVED] New device - PoE input died on second use?
Replies: 4
Views: 1936

Re: New device - PoE input died on second use?

It can be anything...

If i were you i would try to power the CRS with another POE device and see how it goes...
by Zacharias
Wed Jul 14, 2021 9:10 pm
Forum: Wireless Networking
Topic: Purpose of using Bridge for CAP
Replies: 3
Views: 1908

Re: Purpose of using Bridge for CAP

What do you mean by tunnel mode ? CapsMAN can be either in CapsMAN Forwarding Mode or Local Forwarding Mode... In case Capsman Forwarding mode is used, the Cap interface will be automatically added to the Capsman's Router Bridge Interface, not on your CAP, so on your Cap you could just use your ethe...
by Zacharias
Sun Jul 11, 2021 11:30 pm
Forum: RouterBOARD hardware
Topic: Antenna Gain
Replies: 21
Views: 64772

Re: Antenna Gain


So setting the antenna gain does not focus the radiation beam?
Beamforming antennas can do that by changing the number of radiating elements ...
by Zacharias
Sun Jul 11, 2021 10:48 pm
Forum: RouterBOARD hardware
Topic: Uncertainty before buying equipment (MikroTik CRS112-8P-4S-IN) [SOLVED]
Replies: 7
Views: 3569

Re: Uncertainty before buying equipment (MikroTik CRS112-8P-4S-IN) [SOLVED]

I agree with @xvo...
CRS112 is a switch, it can handle L3 traffic but with very low performance...
Also, it can do VLANs but with the old way, not with Bridge VLAN filtering cause you will loose the Hardware offload...
And it can power passive and af/at devices if the correct PSU is used ...
by Zacharias
Sun Jul 11, 2021 10:07 pm
Forum: RouterBOARD hardware
Topic: hEX PoE RB960PGS does not power Netgear WAX214 [SOLVED]
Replies: 7
Views: 3431

Re: hEX PoE RB960PGS does not power Netgear WAX214 [SOLVED]

Oh, I see. Does MikroTik have a recommended one?
I wonder why it doesn't come with the appropriate power supply though, is a 24V one actually cheaper?
You can't use a 24V power supply to provide af/at POE...
by Zacharias
Wed Jul 07, 2021 4:30 pm
Forum: General
Topic: default route prevents use of additional LTE passthrough WAN
Replies: 22
Views: 3676

Re: default route prevents use of additional LTE passthrough WAN

If you search in the forum you will find a script to use in the DHCP client so that the Gateway address in the Routing Table is automatically renewed upon an address change...
by Zacharias
Fri Jul 02, 2021 9:26 pm
Forum: General
Topic: default route prevents use of additional LTE passthrough WAN
Replies: 22
Views: 3676

Re: default route prevents use of additional LTE passthrough WAN

Actually i believe its better to use passthrough because everything stays in one place, firewall, Nat etc...
In most of my setups i do use pasthrough along with VLANs for management puproses of the LTE Device...
by Zacharias
Wed Jun 30, 2021 7:44 pm
Forum: General
Topic: Resolve domain name with local DNS
Replies: 10
Views: 11662

Re: Resolve domain name with local DNS

however, the parameter out-interface=LAN what does it mean, because in my case I don't have such interface. I that option I have: It means that the out interface is your Lan Network... Masquerade is a unique subversion of action=srcnat, https://wiki.mikrotik.com/wiki/Manual:IP/Firewall/NAT#Masquera...
by Zacharias
Mon Jun 28, 2021 10:29 pm
Forum: Beginner Basics
Topic: A lot of disconnections. [SOLVED]
Replies: 12
Views: 9989

Re: A lot of disconnections. [SOLVED]

"extensive data loss" - local interface decided to drop connection to remote device because of inability to send data to remote after multiple failures at lowest possible rate. Possible causes - too weak signal, remote device turned off, strong interference, some other RF related issue th...
by Zacharias
Mon Jun 28, 2021 10:23 pm
Forum: Beginner Basics
Topic: How do I assign a static IP address to a device?
Replies: 3
Views: 2385

Re: How do I assign a static IP address to a device?

@aesmith is right...
What is the addressing used in your configuration ?

However you certainly can assign those addresses on your WAPs...
by Zacharias
Mon Jun 28, 2021 9:14 pm
Forum: General
Topic: default route prevents use of additional LTE passthrough WAN
Replies: 22
Views: 3676

Re: default route prevents use of additional LTE passthrough WAN

Interface name as Gateway is not used for nexthop lookup... https://wiki.mikrotik.com/wiki/Manual:IP/Route#Nexthop_lookup You can use interface name as gateway in ppp Tunnels/ Interfaces... So, use the IP address as Gateway for your LTE Interface and you can use a Script on your DHCP client to chang...
by Zacharias
Mon Jun 28, 2021 9:03 pm
Forum: General
Topic: Resolve domain name with local DNS
Replies: 10
Views: 11662

Re: Resolve domain name with local DNS

Using a static DNS entry with Mikrotik as DNS server would work as well...
However reading about Hairping NAT will help you understand why it doesn't work right now...
by Zacharias
Sun Jun 27, 2021 9:58 pm
Forum: General
Topic: Internet disconnects
Replies: 10
Views: 1612

Re: Internet disconnects

Roaming, good or not, depends on your Client device...
by Zacharias
Sun Jun 27, 2021 9:41 pm
Forum: General
Topic: Resolve domain name with local DNS
Replies: 10
Views: 11662

Re: Resolve domain name with local DNS

by Zacharias
Sun Jun 27, 2021 9:25 pm
Forum: General
Topic: Internet disconnects
Replies: 10
Views: 1612

Re: Internet disconnects

What does the log say when the device disconnects ?

You can as well enable debug mοde in the wireless interface to get more information ...