Community discussions

MikroTik App

Search found 19572 matches

by anav
Fri Mar 24, 2023 1:47 pm
Forum: Beginner Basics
Topic: Firewall Filter Rule before NAT rule
Replies: 14
Views: 22635

Re: Firewall Filter Rule before NAT rule

I will look at this sorry thread later but its clear that HAVING SAFELY SETUP SERVERS is a very important consideration for many many mikrotik users.

Thus Mikrotik MUST PROVIDE the Zerotrust Cloudflare tunnel in an options package for all users!!!
by anav
Fri Mar 24, 2023 1:35 pm
Forum: RouterOS beta
Topic: Bridge to Wireguard interface [SOLVED]
Replies: 20
Views: 17400

Re: Bridge to Wireguard interface [SOLVED]

Wireguard doesn't work with a bridge-lan is a ridiculous statement that means nothing! Wireguard is a peer to peer layer3 construct. If you want to connect subnets at layer 2 then a. use zerotier b. eiop over wg c. vxlan over wg. etc. I will connect Two routers, with bridge-LANS using WG . EASY PEA...
by anav
Fri Mar 24, 2023 1:16 pm
Forum: Announcements
Topic: v7.9beta [testing] is released!
Replies: 118
Views: 26657

Re: v7.9beta [testing] is released!

Impressive amount of work done here, regardless if what anyone specifically wanted didnt get done. The paperwork alone is not trivial, just imagine the testing and integration involved. Kudos to the dev team and test team.
by anav
Fri Mar 24, 2023 3:05 am
Forum: General
Topic: 2 WAN load balanced + 1 LAN - client machine not getting gateway
Replies: 8
Views: 555

Re: 2 WAN load balanced + 1 LAN - client machine not getting gateway

see the rest of my reply in the above post.
by anav
Fri Mar 24, 2023 2:57 am
Forum: General
Topic: 2 WAN load balanced + 1 LAN - client machine not getting gateway
Replies: 8
Views: 555

Re: 2 WAN load balanced + 1 LAN - client machine not getting gateway

Mangle rules........ /ip firewall mangle add action=accept chain=prerouting in -interface=Eth2-WAN1 add action=accept chain=prerouting in -interface=eth3-WAN2 TRY add action=accept chain=prerouting out -interface=Eth2-WAN1 add action=accept chain=prerouting out -interface=eth3-WAN2 NEXT: Wyy are you...
by anav
Fri Mar 24, 2023 2:28 am
Forum: General
Topic: 2 WAN load balanced + 1 LAN - client machine not getting gateway
Replies: 8
Views: 555

Re: 2 WAN load balanced + 1 LAN - client machine not getting gateway

(1) Why is your DHPC network not using the same subnet as the rest of the config. /ip dhcp-server network add address= 10.0.0.0/8 dns-server= 8.8.8.8 gateway=10.100.1.1 Why not use the routers DNS caching ability with external dns servers?? /ip dhcp-server network add address= 192.168.100.0/24 dns-s...
by anav
Thu Mar 23, 2023 11:40 pm
Forum: General
Topic: problem with nat port forwarding [SOLVED]
Replies: 3
Views: 2602

Re: problem with nat port forwarding [SOLVED]

Doing it wrong, There is one rule only for port forwarding required in the FORWARD CHAIN. The concept is different from most other routers I have used. WE dont make a forward rule for each port forward. We use the dst nat chain to do each rule. Check out - https://forum.mikrotik.com/viewtopic.php?t=...
by anav
Thu Mar 23, 2023 11:31 pm
Forum: Beginner Basics
Topic: configure hap ax3 as AP
Replies: 4
Views: 1878

Re: configure hap ax3 as AP

Hi Ammo, I deal in the management of software bugs and believe me its not hard for them to get buried or stuck.
Suggest resubmit the issue as a new one.............
by anav
Thu Mar 23, 2023 11:30 pm
Forum: General
Topic: 2ISP BALANCE PCC
Replies: 7
Views: 539

Re: 2ISP BALANCE PCC

Well you will need to provide a diagram because servers dont initiate/originate traffic, they respond to incoming requests?
I have no clue of what VPN you are using and how it actually works as your words are more confusing then enlightening.
by anav
Thu Mar 23, 2023 9:36 pm
Forum: Wireless Networking
Topic: Missing ACL enable/disable in QuickSet [SOLVED]
Replies: 24
Views: 6245

Re: Missing ACL enable/disable in QuickSet [SOLVED]

Priceless quote1: " Go to Wireless menu, then click Access List tab " Priceless quote2: " mkx which threads are you referring to? AFAIK hAP ax2 works like a charm. I use it personally too. If you have no specific report made, don't spread such false info then. " Yup everything i...
by anav
Thu Mar 23, 2023 9:33 pm
Forum: Beginner Basics
Topic: configure hap ax3 as AP
Replies: 4
Views: 1878

Re: configure hap ax3 as AP

Look at the example........ - viewtopic.php?t=182276
by anav
Thu Mar 23, 2023 9:09 pm
Forum: Wireless Networking
Topic: Missing ACL enable/disable in QuickSet [SOLVED]
Replies: 24
Views: 6245

Re: Missing ACL enable/disable in QuickSet [SOLVED]

Maybe they should assign more resources at MT to finish products instead of releasing them as beta software or at least produce a transparent road map for completion of feature sets.
by anav
Thu Mar 23, 2023 8:46 pm
Forum: General
Topic: 2ISP BALANCE PCC
Replies: 7
Views: 539

Re: 2ISP BALANCE PCC

A server does not open a tunnel as its the server for other users aka the destination address. Im assuming you mean users come into the router via the tunnel to access the server and not via its public WAN IP. Thus you must ensure the return information from the server goes back into the tunnel. So ...
by anav
Thu Mar 23, 2023 8:41 pm
Forum: General
Topic: 2ISP BALANCE PCC
Replies: 7
Views: 539

Re: 2ISP BALANCE PCC

Page 53-55 in the discher pdf https://www.khanacademy.org/computing/computer-science/cryptography/modarithmetic/a/what-is-modular-arithmetic Putting Items In Random Groups Suppose you have people who bought movie tickets, with a confirmation number. You want to divide them into 2 groups. What do you...
by anav
Thu Mar 23, 2023 8:27 pm
Forum: Wireless Networking
Topic: Missing ACL enable/disable in QuickSet [SOLVED]
Replies: 24
Views: 6245

Re: Missing ACL enable/disable in QuickSet [SOLVED]

The OP has a point. There is an ACCESS LIST Tab on wifi wave 2 and that seems to be to enter in each item individually with some ability to assign radius and other things............ HOWEVER, there is no single TAB or entry that would allow DISABLE all access list or ENABLE all access list. Further,...
by anav
Thu Mar 23, 2023 7:00 pm
Forum: RouterOS beta
Topic: Feature Request - Regex Capturing Groups
Replies: 7
Views: 2117

Re: Feature Request - Regex Capturing Groups

Possibly due to no recent graduates from computer software engineering in Latvia..........OR
Cheap assed owners who dont want to hire the necessary staff to make MT really shine and sing!!
by anav
Thu Mar 23, 2023 2:54 pm
Forum: Useful user articles
Topic: How to: Edge router and BNG optimization for ISPs Topic is solved
Replies: 68
Views: 90658

Re: How to: Edge router and BNG optimization for ISPs Topic is solved

Good, like the practical thinking!! So Darknates first rule should be the same as his second rule (in terms of list of local subnets) RAW RULE 1 BLOCK ANYTHING FROM WAN WITH SAME SUBNETS ON ROUTER (instead of bogon list) RAW RULE 2 BLOCK ANYTHING NOT FROM LOCAL SUBNETS COMING FROM LAN So no reason t...
by anav
Thu Mar 23, 2023 2:51 pm
Forum: Beginner Basics
Topic: Recursive Fail over [SOLVED]
Replies: 1
Views: 309

Re: Recursive Fail over [SOLVED]

by anav
Thu Mar 23, 2023 2:49 pm
Forum: Beginner Basics
Topic: Certain traffico out "main" route? [SOLVED]
Replies: 5
Views: 900

Re: Certain traffico out "main" route? [SOLVED]

Sorry words are not clear.
a. provide a diagram for context and
b. full config for actual evidence of what is setup.
/export file=anynameyouwish ( minus router serial number and any actual public WANIP information )
by anav
Thu Mar 23, 2023 2:46 pm
Forum: Beginner Basics
Topic: Weird routing behavior ??
Replies: 8
Views: 575

Re: Weird routing behavior ??

Your problems are not solved by hardware LOL

Just configure the MT as a basic switch iaw viewtopic.php?t=182276

just go look at the example.
by anav
Thu Mar 23, 2023 1:02 pm
Forum: Useful user articles
Topic: How to: Edge router and BNG optimization for ISPs Topic is solved
Replies: 68
Views: 90658

Re: How to: Edge router and BNG optimization for ISPs Topic is solved

So your saying the only entry on your ADDRESS LIST is 192.0.0.0/24 ? AND these are no longer valid to put on that source address list to block incoming 'bad' incoming on WAN? Netblock Description 0.0.0.0/8 "This" network 10.0.0.0/8 Private-use networks 100.64.0.0/10 Carrier-grade NAT 127.0...
by anav
Thu Mar 23, 2023 12:48 pm
Forum: Wireless Networking
Topic: Missing ACL enable/disable in QuickSet [SOLVED]
Replies: 24
Views: 6245

Re: Missing ACL enable/disable in QuickSet [SOLVED]

The value in quickset is to be able to select the generic mode of wifi the router applies, after that, dont visit quick set again.
by anav
Thu Mar 23, 2023 12:46 pm
Forum: General
Topic: RB2011 and degraded Internet speed
Replies: 9
Views: 772

Re: RB2011 and degraded Internet speed

Why would you replace a router with a wifi router, the 4011 has a WIRED only version and better anyway for the same price point is the RB5009?
by anav
Thu Mar 23, 2023 12:44 pm
Forum: General
Topic: WifiWave2 interface menu missing items?
Replies: 6
Views: 710

Re: WifiWave2 interface menu missing items?

Stop drinking 2xbottles of Italian wine at at time - we know its so good, but the errors, the errors.........
by anav
Thu Mar 23, 2023 12:42 pm
Forum: General
Topic: 2ISP BALANCE PCC
Replies: 7
Views: 539

Re: 2ISP BALANCE PCC

by anav
Thu Mar 23, 2023 12:38 pm
Forum: General
Topic: Can a Mikrotik RouterOS device handle FiOS gigabit
Replies: 2
Views: 370

Re: Can a Mikrotik RouterOS device handle FiOS gigabit

FIOS is an internet provider,
an internet provider provides an internet connection
an internet connection requires at some point a router.
Can an MT router handle FIOS gig connection --->YES
+++++++++++++++++++++++++++++++++++++++++++++

A switch has nothing to do with the above.
by anav
Thu Mar 23, 2023 12:36 pm
Forum: General
Topic: Express VPN OVPN on mikrotik
Replies: 7
Views: 3216

Re: Express VPN OVPN on mikrotik

Use Wireguard or zerotier
by anav
Thu Mar 23, 2023 12:34 pm
Forum: General
Topic: Wireguard on mikrotik AND on PC attached to it
Replies: 11
Views: 843

Re: Wireguard on mikrotik AND on PC attached to it

Like I said, WG is a peer to peer construct, so no issue connecting the three cities to NY router to router . Like I said, no issues connecting disparate subnets such as 10.0.1 and and 10.0.2 from satellite office to 10.0.1 at MAIN branch. But you cannot connect subnets 10.0.0 from satellite to 10.0...
by anav
Thu Mar 23, 2023 4:18 am
Forum: General
Topic: RB2011 and degraded Internet speed
Replies: 9
Views: 772

Re: RB2011 and degraded Internet speed

Getting a modern router with horsepower is certainly recommended.
Unaware of any method to avoid mangling in this case.
by anav
Thu Mar 23, 2023 4:13 am
Forum: General
Topic: Firewall input drop all except LAN
Replies: 8
Views: 1414

Re: Firewall input drop all except LAN

by anav
Thu Mar 23, 2023 4:12 am
Forum: General
Topic: Two default gateways. One DHCP one Wireguard
Replies: 1
Views: 230

Re: Two default gateways. One DHCP one Wireguard

Not enough info
Network diagram gives context
Describing user requirements without any config speak is essential
identify users/devices groups of users/devices and their traffic flow requirements
Finally config of devices at both ends of tunnel
by anav
Thu Mar 23, 2023 2:50 am
Forum: Wireless Networking
Topic: House wifi6 network with Mikrotik AX or Audience
Replies: 29
Views: 7004

Re: House wifi6 network with Mikrotik AX or Audience

If MT wifi products had decent documentation, clear paths to setup, and users could understand all the available features and setup the APs with relative ease and they worked and provided consistent stable throughput, perhaps nOrmands you would have a leg to stand on to "get aggressive with mkx...
by anav
Thu Mar 23, 2023 2:29 am
Forum: General
Topic: Multiple default routes in main route table
Replies: 3
Views: 1247

Re: Multiple default routes in main route table

Sorry no capiche, I understand users or LAN subnets wanting to go out specific WANs, WAn1, Wan2, Wan3. Wans1-3 may be from the same or different ISPs. They may have different connection types, standard cable, wifi, PPPOE, or starlink for example. So your explanation does nothing to provide any fidel...
by anav
Thu Mar 23, 2023 1:06 am
Forum: General
Topic: Connecting remote offices [SOLVED]
Replies: 12
Views: 949

Re: Connecting remote offices [SOLVED]

Yes I was trying to convey that on my last post, use the existing bridge!!
Glad it worked!!
by anav
Wed Mar 22, 2023 11:02 pm
Forum: RouterOS beta
Topic: mDNS repeater feature
Replies: 330
Views: 101928

Re: mDNS repeater feature

I attempted to run mDSN discovery over wireguard but at two DIFFERENT LOCATIONs..........
Feel free to test it, to make sure it works..............academic at this point.
viewtopic.php?p=990840#p990840
by anav
Wed Mar 22, 2023 10:41 pm
Forum: Beginner Basics
Topic: communicate two networks
Replies: 1
Views: 319

Re: communicate two networks

The best way is probably zerotier where you can put two routers lans together as if they were on the same switch etc..... Best done with an ARM64 for example. You may get away with one ARM64 device at source (where the cameras actually are) and people can load zerotier on their laptops, cellphones e...
by anav
Wed Mar 22, 2023 10:39 pm
Forum: Beginner Basics
Topic: Outside Network with Port 5060
Replies: 3
Views: 355

Re: Outside Network with Port 5060

Without a config and a network diagram hard to say.........
by anav
Wed Mar 22, 2023 10:36 pm
Forum: Beginner Basics
Topic: Weird routing behavior ??
Replies: 8
Views: 575

Re: Weird routing behavior ??

So your using the RB5009 as a switch ??? Thats crazyee, let me send you a switch and you can send me the RB5009 :-) Why are you creating vlans on the router?? They should all be defined on the pFSENSE. So your using this as a full router with double NAT ??? Why not just use the RB5009 and throw the ...
by anav
Wed Mar 22, 2023 5:29 pm
Forum: Beginner Basics
Topic: Weird routing behavior ??
Replies: 8
Views: 575

Re: Weird routing behavior ??

Suggest you use a proper firewall appliance, I have no interest in looking at pfsense logs. Curl that!
by anav
Wed Mar 22, 2023 4:52 pm
Forum: General
Topic: Need some advice
Replies: 2
Views: 314

Re: Need some advice

yes
by anav
Wed Mar 22, 2023 4:51 pm
Forum: General
Topic: Transmit broadcast and WoL packets across VLANs?
Replies: 7
Views: 1238

Re: Transmit broadcast and WoL packets across VLANs?

Not sure how this would be done as the same commands dont translate directly but there are ways to achieve almost anything.
Zerotier functionality would create it such that you could put any two vlans on the same virtual switch to achieve the same effect I believe.
by anav
Wed Mar 22, 2023 1:19 pm
Forum: Beginner Basics
Topic: Wireguard: how to configure this network?
Replies: 12
Views: 1341

Re: Wireguard: how to configure this network?

separate wg interface.
by anav
Wed Mar 22, 2023 1:15 pm
Forum: Beginner Basics
Topic: a simple question about Mikrotik ports ?
Replies: 7
Views: 604

Re: a simple question about Mikrotik ports ?

Look at the timelines rextended. He was probably reading the original post and drafting a reply when you added your input. Imagine he went to get a coffee or take a piss............ comes back finishes his post, hits send and then both his and yours appears on the refresh. No harm no foul, just the ...
by anav
Wed Mar 22, 2023 1:08 pm
Forum: General
Topic: WireGuard AzireVPN - misbehavior
Replies: 39
Views: 3314

Re: WireGuard AzireVPN - misbehavior

When ready to not use ipv6, as stated can help troubleshoot.
In the meantime checkout PARA 7 and PARA 9 (D) -- viewtopic.php?t=182340
by anav
Wed Mar 22, 2023 1:07 pm
Forum: General
Topic: Wireguard on mikrotik AND on PC attached to it
Replies: 11
Views: 843

Re: Wireguard on mikrotik AND on PC attached to it

If you want to to span the same subnet over wireguard be clear about it. One does not span data transfer using wireguard addresses.
Your best bet is using zerotier first.
by anav
Wed Mar 22, 2023 3:39 am
Forum: General
Topic: WireGuard AzireVPN - misbehavior
Replies: 39
Views: 3314

Re: WireGuard AzireVPN - misbehavior

Is your network ipv6? if so cannot help as not fluent in such language.
by anav
Wed Mar 22, 2023 3:28 am
Forum: General
Topic: Very high traffic on Firewall "Drop all traffic not from Lan" rule
Replies: 5
Views: 1062

Re: Very high traffic on Firewall "Drop all traffic not from Lan" rule

I have 3 layers of firewalls in the user article, https://forum.mikrotik.com/viewtopic.php?t=180838 NOVICE --> raw beginner newbie NOVICE + MODIFIED --> Beginner with some experience APPRENTICE --> Beginner with confidence/knowledge/understanding Nothing else is really required............. PS Dont ...
by anav
Wed Mar 22, 2023 3:21 am
Forum: General
Topic: Firewall Drop DNS Local
Replies: 2
Views: 590

Re: Firewall Drop DNS Local

This is a safe starting point. add action=accept chain=input in-interface-list=LAN add action=accept chain=input comment="Allow DNS to local" dst-port=53 \ in-interface-list=LAN protocol=udp add action=accept chain=input comment="Allow DNS to local" dst-port=53 \ in-interface-lis...
by anav
Wed Mar 22, 2023 2:07 am
Forum: General
Topic: Firewall input drop all except LAN
Replies: 8
Views: 1414

Re: Firewall input drop all except LAN

Its simple for both chains a few default rules a few user rules drop all No need to get cute............ allow Admin to router allow users to needed services drop all else allow subnets to WAN ************** allow port forwarding drop all else **** any other needed traffic like to a shared printer f...
by anav
Wed Mar 22, 2023 2:02 am
Forum: Beginner Basics
Topic: settings for safe use...
Replies: 8
Views: 1518

Re: settings for safe use...

Interesting, I have always set RP filter to loose for multiple reasons but I dont have syn cookies checked, should I? Interesting link, seems like a valid checkbox to use. But I must check with my Tarot Cards. There is no point to using tcp syn cookies checkbox. Its only useful for targetted atacks ...
by anav
Wed Mar 22, 2023 12:30 am
Forum: General
Topic: Connecting remote offices [SOLVED]
Replies: 12
Views: 949

Re: Connecting remote offices [SOLVED]

Take the EOIP R1 Office router settings Router One /interface bridge ports add bridge=bridge interface=ether4-MainR1 add bridge=bridge interface=eoip-to-TWO pvid=20 /interface bridge vlan add bridge=bridge tagged=bridge untagged=eiop-to-TWO,ether4-MainR1 vlan-ids=20 The bridge already exists ether4 ...
by anav
Wed Mar 22, 2023 12:04 am
Forum: Beginner Basics
Topic: settings for safe use...
Replies: 8
Views: 1518

Re: settings for safe use...

I am a believe in simplify for both clarity and troubleshooting issues. Therefore. A. ONE BRIDGE B. VLANS for all subnets ( bridge just does bridging ) C. Capsman for one AP - COMPLETE WASTE of time and clutters up clean config. I had three at one time and you couldnt pay me to use capsman. In this ...
by anav
Tue Mar 21, 2023 11:20 pm
Forum: General
Topic: Connecting remote offices [SOLVED]
Replies: 12
Views: 949

Re: Connecting remote offices [SOLVED]

WARNING FOR ABOVE CONFIGS< not quite right yet, I have not removed vlans but there is a possibility I may not have too.......... investigating.
by anav
Tue Mar 21, 2023 10:43 pm
Forum: General
Topic: Connecting remote offices [SOLVED]
Replies: 12
Views: 949

Re: Connecting remote offices [SOLVED]

I didnt post the configs for POSSIBILITIES 2 and 3 so done here....... POSSIBLITIES 2 & 3 ( covers both methods eoip and vxlan ) - -> single bridge specifically for one spanned subnet at Satellite Office Note: The difference in POSSIBILITY 3, is that there is at least one other bridge for the ot...
by anav
Tue Mar 21, 2023 10:31 pm
Forum: General
Topic: Connecting remote offices [SOLVED]
Replies: 12
Views: 949

Re: Connecting remote offices [SOLVED]

TO RECAP, There are four possibilities: (1) USE WIREGUARD --> Single Subnet at Satellite: The configuration provided should work with all existing hardware with ONE internet connection provided by the MAIN office. No extra work is required to change any /interface bridge nat settings. This is predic...
by anav
Tue Mar 21, 2023 7:31 pm
Forum: General
Topic: Wireguard peer interface irregularly stop working
Replies: 66
Views: 17759

Re: Wireguard peer interface irregularly stop working

@retom
@Montecri

If you two [*****.***] actually read the thread..........
viewtopic.php?p=991310#p923407

This one is recommended:
**** FOR ADVANCED USERS ------- Courtesy of Sob/Dave ( called elegant by Chupaka even )
by anav
Tue Mar 21, 2023 7:25 pm
Forum: Beginner Basics
Topic: How to use multiple ports for one dhcp server
Replies: 4
Views: 683

Re: How to use multiple ports for one dhcp server

Sure, and take your electric bicycle using major highways from LA to NY.......... dont be ridonkulous
by anav
Tue Mar 21, 2023 7:16 pm
Forum: Beginner Basics
Topic: How to use multiple ports for one dhcp server
Replies: 4
Views: 683

Re: How to use multiple ports for one dhcp server

Why do you talk about ROUTER when you picked a switch???? We want to use the MikroTik CRS326-24G-2S+RM, I picked this one because it has 24 ports + 2 sfp ports. Right now we have 2 switches (24 ports), 1 for voip phones and 1 for the pcs. I was thinking about connecting all pcs straight to the route...
by anav
Tue Mar 21, 2023 7:10 pm
Forum: General
Topic: Connecting remote offices [SOLVED]
Replies: 12
Views: 949

Re: Connecting remote offices [SOLVED]

USING Wireguard to SPAN One Subnet Assumptions - One DCHP Server , Subnet Uses Main Office For Internet . SOLUTION METHOD ONE: EOIP OVER WIREGUARD a. create wireguard connectivity as per normal and then b. create the EOIP tunnel within the WG tunnel ( EOIP never concerns its self ever with local WA...
by anav
Tue Mar 21, 2023 6:32 pm
Forum: General
Topic: Connecting remote offices [SOLVED]
Replies: 12
Views: 949

Re: Connecting remote offices [SOLVED]

Dont give up me yet LOL. Can I ask if the offices have one local subnet aka on a bridge or MULTIPLE LOCAL subnets ?? Was the intention to have MAIN office internet for the single Subnet or try to use local WAN for internet at local router OR NO internet at all?? With this information a plausible sol...
by anav
Tue Mar 21, 2023 5:36 pm
Forum: Beginner Basics
Topic: NTP Server issues [SOLVED]
Replies: 9
Views: 1436

Re: NTP Server issues [SOLVED]

did you report that as a bug or do you get a spanking?? I was gonna comment your statement, but the comnent would probably be rated as PG18 :wink: Plus I only found this out the other day. Days of v6 in my home network are counted, so why should I bother to report ... And it's not a security proble...
by anav
Tue Mar 21, 2023 5:30 pm
Forum: General
Topic: Connecting remote offices [SOLVED]
Replies: 12
Views: 949

Re: Connecting remote offices [SOLVED]

Lucky for you Toto, just looking at this subject. ( okay so KC is in MO, but thats a ridonkulous proposition ) BUT why did you use old routers for a new purchase, an RB5009 would have been more appropriate, especially since ZEROTIER would have fixed your issues SO SO easily and with the right horsep...
by anav
Tue Mar 21, 2023 5:26 pm
Forum: Beginner Basics
Topic: NTP Server issues [SOLVED]
Replies: 9
Views: 1436

Re: NTP Server issues [SOLVED]

did you report that as a bug or do you get a spanking??
by anav
Tue Mar 21, 2023 4:52 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 258
Views: 48852

Re: MikroTik hAP ax3 poor WiFi performance

Just received an additional response: the wording of release notes is wrong. It should be AX2 for US and Europe. But AX3 / Chateau AX only for Europe is supported as well. (because of the FCC limitation on external antenna, they are excluded for US, I understand that) What If I choose some backward...
by anav
Tue Mar 21, 2023 4:45 pm
Forum: Beginner Basics
Topic: NTP Server issues [SOLVED]
Replies: 9
Views: 1436

Re: NTP Server issues [SOLVED]

In plain Italian
NTP is a router service.
a. enable NTP client settings to get ntp from www
b. enable NTP server settings to give to downstream devices
c. enable input chain rule for such LAN devices to reach router on port 123.
by anav
Tue Mar 21, 2023 3:22 pm
Forum: Beginner Basics
Topic: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]
Replies: 16
Views: 1057

Re: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]

Okay but only for RB4011 correct.

Well, OP's ap.rsc mentions it's from RB4011 ... hence my post is highly relevant in this thread.
Yes, but it was not in my applicable useful article yet AP SWITCH SETUP, so it couldnt be true. Now that its added, I believe you. ;-PP
...
rb4.JPG
by anav
Tue Mar 21, 2023 3:18 pm
Forum: Beginner Basics
Topic: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]
Replies: 16
Views: 1057

Re: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]

My apologies to the OP. This should work. /interface bridge vlan add bridge=bridge-vlan tagged=ether1-trunk, bridge-vlan untagged=wifi1,wifi2,ether2-pc,ether3-dockingstation,ether4-nas,ether5-laptop,ether6,ether9 vlan-ids=10 add bridge=bridge-vlan tagged=ether1-trunk, bridge-vlan untagged=wifi-guest...
by anav
Tue Mar 21, 2023 3:16 pm
Forum: Beginner Basics
Topic: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]
Replies: 16
Views: 1057

Re: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]

It's been explained that when they first implemented L2 HW offload, they implemented it so that CPU-switch interconnect will only pass VLANs of which bridge interface is member (either tagged or untagged). And it worked perfectly because those devices were wired-only devices with single switch chip...
by anav
Tue Mar 21, 2023 3:11 pm
Forum: Beginner Basics
Topic: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]
Replies: 16
Views: 1057

Re: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]

Wait, so you are saying that both switch chips need the bridge to be tagged for every vlan?? and what does switch chip have to do with WIFI Bridge ports ur killen me............ In that case, it explains why the OP had success tagging when it seemed illogical. MKX I could kiss you, well you know wha...
by anav
Tue Mar 21, 2023 2:51 pm
Forum: Beginner Basics
Topic: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]
Replies: 16
Views: 1057

Re: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]

(1) Remove bridge1 /interface bridge add ingress-filtering=no name=bridge-vlan protocol-mode=none vlan-filtering=yes add name=bridge1 (2) Confirm the iot and guest WIRED gets addresses ( ether8 and ether7) . If they DO then (4) is correct. If they do not then perhaps (5) is the answer. (3) Add to th...
by anav
Tue Mar 21, 2023 2:40 pm
Forum: Wireless Networking
Topic: Open SSID gets wrong VLAN
Replies: 8
Views: 1617

Re: Open SSID gets wrong VLAN

NO FIREWALL RULES REQUIRED Going to assume you get an IP address on the 192.168.8.0/24 and will fix it to 192.168.88.2 It would appear that the above device is not getting fed from a trunk port # software id = F7Y9-BEGS # # model = C52iG-5HaxD2HaxD # serial number = {removed for security reasons} /i...
by anav
Tue Mar 21, 2023 2:23 pm
Forum: Wireless Networking
Topic: Open SSID gets wrong VLAN
Replies: 8
Views: 1617

Re: Open SSID gets wrong VLAN

Nice of you to mention that now LOL, but now that I read it you did say homeAP................ Its still a completely hosed setup. As I said get rid of datapath and vlans in wifi, keep wifi to wifi settings!!, and you only define the management vlan! FINALLY WHAT IS THE MANAGEMENT VLAN or subnet ???...
by anav
Tue Mar 21, 2023 2:14 pm
Forum: General
Topic: Multiple default routes in main route table
Replies: 3
Views: 1247

Re: Multiple default routes in main route table

If its whole subnets, dont use mangling. If its a few users, dont use mangling Instead use routing rules ( and I wont use your example of lan subnets somehow being in the same structure as each WAN subnet ;-PPP ) Consists of 3 steps {add tables} /routing table add fib name= useWAN1 /routing table ad...
by anav
Tue Mar 21, 2023 2:03 pm
Forum: General
Topic: Plugging laptop into VLAN port, blocks bridge interface of other router.
Replies: 6
Views: 522

Re: Plugging laptop into VLAN port, blocks bridge interface of other router.

When you decide to have one bridge, and all subnets on vlans, I can help.
by anav
Tue Mar 21, 2023 2:01 pm
Forum: General
Topic: Firewall input drop all except LAN
Replies: 8
Views: 1414

Re: Firewall input drop all except LAN

First of all why do you use such a twisted rule?? defconf: drop all not coming from LAN rule in the firewall. Basically it is an input drop !LAN Much better and clearer to simply say accept all coming from LAN drop all else This leads to the logical next step, which you may have not noticed with the...
by anav
Tue Mar 21, 2023 1:50 pm
Forum: Beginner Basics
Topic: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]
Replies: 16
Views: 1057

Re: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]

TWO THINGS to fix. (1) FIX the interface bridge vlan rules --> only the BASE vlan, where the AP/Switch gets its IP address from (.99) needs the bridge to be tagged !! From /interface bridge vlan add bridge=bridge-vlan tagged=ether1-trunk, bridge-vlan untagged=wifi1,wifi2,ether2-pc,ether3-dockingstat...
by anav
Tue Mar 21, 2023 1:16 pm
Forum: RouterOS beta
Topic: Routing mark and Os7 with two isp [SOLVED]
Replies: 10
Views: 4667

Re: Routing mark and Os7 with two isp [SOLVED]

Would also agree with the previous poster that your rules are a bit funny to have worked well in the past......... Agree with your approach using firewall address lists as you state its not just whole subnets but subnets plus or minus a number of folks that may change from time to time. Much easier ...
by anav
Tue Mar 21, 2023 1:07 pm
Forum: RouterOS beta
Topic: Routing mark and Os7 with two isp [SOLVED]
Replies: 10
Views: 4667

Re: Routing mark and Os7 with two isp [SOLVED]

I see nothing wrong with your setup; but would change the sourcenat rules as its not clear which WAN they refer to and thus not sure if they would work right. From: /ip firewall nat add action=masquerade chain=srcnat src-address=192.168.1.0/24 add action=masquerade chain=srcnat src-address=192.168.4...
by anav
Tue Mar 21, 2023 2:01 am
Forum: Scripting
Topic: Black list for failed login to IPSec VPN
Replies: 62
Views: 34319

Re: Black list for failed login to IPSec VPN

My script!

add chain=input action=drop
add chain=forward action=drop

That was easy.
by anav
Tue Mar 21, 2023 1:58 am
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 258
Views: 48852

Re: MikroTik hAP ax3 poor WiFi performance

Hoping you get your MT wifi6 soon bpwl, cannot wait for the 'blessed' configuration that works!!
by anav
Tue Mar 21, 2023 1:56 am
Forum: General
Topic: Very high traffic on Firewall "Drop all traffic not from Lan" rule
Replies: 5
Views: 1062

Re: Very high traffic on Firewall "Drop all traffic not from Lan" rule

Because there is tons of traffic on the WWW always hitting routers, nothing unusual. You are simply in effect logging it now by showing what is dropped. For a starting firewall this is ideal........... /ip firewall filter {Input Chain} add action=accept chain=input comment="defconf: accept esta...
by anav
Tue Mar 21, 2023 1:52 am
Forum: Beginner Basics
Topic: no VPN on lan side
Replies: 2
Views: 432

Re: no VPN on lan side

Depends................ firewall rules, vlans many ways...........
by anav
Tue Mar 21, 2023 1:50 am
Forum: Beginner Basics
Topic: Hairpin NAT not working from local network [SOLVED]
Replies: 14
Views: 2504

Re: Hairpin NAT not working from local network [SOLVED]

FIXED: /ip firewall filter add action=accept chain=input comment="default configuration" \ connection-state=established,related,untracked add action=drop chain=input comment="defconf: drop invalid" connection-state=\ invalid add action=accept chain=input protocol=icmp add action=...
by anav
Mon Mar 20, 2023 9:38 pm
Forum: RouterOS beta
Topic: Routing mark and Os7 with two isp [SOLVED]
Replies: 10
Views: 4667

Re: Routing mark and Os7 with two isp [SOLVED]

/ip route add check-gateway=ping disabled= yes distance=1 dst-address=0.0.0.0/0 gateway=192.168.1.2 pref-src="" routing-table=isp2 scope=30 suppress-hw-offload=no target-scope=10 add disabled=yes distance=1 dst-address=0.0.0.0/0 gateway=pppoe-out1 pref-src=0.0.0.0 routing-table=isp1 scope=...
by anav
Mon Mar 20, 2023 9:26 pm
Forum: Beginner Basics
Topic: Route specific IP only when connected to specific Virtual AP
Replies: 11
Views: 590

Re: Route specific IP only when connected to specific Virtual AP

Okay lets see if I have it correctly you have two wifi interfaces on the LAN side (not 1, not 3 not 4 etc,) vWLAN1 - ALL internet traffic goes out local uplink internet (even 1.2.3.4) vWLAN2 - All internet traffic goes out local uplink internet EXCEPT for one single WANIP 1.2.3.4 that must use Wireg...
by anav
Mon Mar 20, 2023 8:03 pm
Forum: Beginner Basics
Topic: Route specific IP only when connected to specific Virtual AP
Replies: 11
Views: 590

Re: Route specific IP only when connected to specific Virtual AP

Sorry makes no sense to me (diagram useless in adding additional info) You either have a regular (local) path to the internet via the uplink on the router to whatever is providing you internet. OR You have a wireguard path to the internet via another router somewhere (friend, your own, third party p...
by anav
Mon Mar 20, 2023 7:41 pm
Forum: Beginner Basics
Topic: Route specific IP only when connected to specific Virtual AP
Replies: 11
Views: 590

Re: Route specific IP only when connected to specific Virtual AP

Please be clear........... Do you want to connect to the internet via the wireguard connection if so /interface bridge port add bridge=br1 interface=wifi1 add bridge=br1 interface=vWLAN-two add bridge=br1 interface=vWLAN-three /routing rule add action=lookup interface=vWLAN-two table=useWG /routing ...
by anav
Mon Mar 20, 2023 7:31 pm
Forum: General
Topic: Multi WAN both on DHCP [SOLVED]
Replies: 22
Views: 3988

Re: Multi WAN both on DHCP [SOLVED]

Outside my scope! jajaja (pun intended)
by anav
Mon Mar 20, 2023 7:24 pm
Forum: Beginner Basics
Topic: Route specific IP only when connected to specific Virtual AP
Replies: 11
Views: 590

Re: Route specific IP only when connected to specific Virtual AP

Modified my post, I had an idea!!
see if that works,
it should be quick to try!!
by anav
Mon Mar 20, 2023 7:20 pm
Forum: Beginner Basics
Topic: Route specific IP only when connected to specific Virtual AP
Replies: 11
Views: 590

Re: Route specific IP only when connected to specific Virtual AP

Well thats silly.............. No way to isolate guest from family, or iOT devices etc. At least assign different subnets to the WLANs............. and dont use a bridge OR create vlans and assign to bridge. If your happy with one flat network then you will have to decide the complexity. How many pe...
by anav
Mon Mar 20, 2023 7:16 pm
Forum: General
Topic: Multi WAN both on DHCP [SOLVED]
Replies: 22
Views: 3988

Re: Multi WAN both on DHCP [SOLVED]

Yes you are just telling the router where to go by matching the script comment entry with the existing comment entry!

In other words we use the comment block as a tool to create an entry that is unique and found by router during script.
by anav
Mon Mar 20, 2023 7:12 pm
Forum: General
Topic: Wireguard help (again)
Replies: 25
Views: 2281

Re: Wireguard help (again)

Its all here at the original link I gave you LOL one or two threads ago!

viewtopic.php?t=182340

Checkout (4) Configuring IP address
Checkout (9) C. UNDERSTANDING THE CRYPTO KEY ROUTING PROCESS (CKRP)
by anav
Mon Mar 20, 2023 7:03 pm
Forum: Beginner Basics
Topic: Route specific IP only when connected to specific Virtual AP
Replies: 11
Views: 590

Re: Route specific IP only when connected to specific Virtual AP

Yes............ How do you assign traffic (from internet/uplink) to users on multiple virtual wlans? (Assuming one MAIN WLAN and then several vWLANS using main WLAN as master) If via vlans then this becomes simple as you only need to do three things for a subnet lets say vlan10-Users which is 192.16...
by anav
Mon Mar 20, 2023 5:47 pm
Forum: General
Topic: Wireguard help (again)
Replies: 25
Views: 2281

Re: Wireguard help (again)

This is my understanding of why this works: Non-212 endpoints have peer configs for 212 that have 10.10.100.0/24; doing this tells the other side (212) that 212 should route all 10.10.100.0/24 to it. NEGATIVE!!! FOR TWO REASONS. a. (outgoing) to be able to ping from a client device to any other dev...
by anav
Mon Mar 20, 2023 5:07 pm
Forum: Beginner Basics
Topic: Block access between wan, lan and VOIP
Replies: 3
Views: 405

Re: Block access between wan, lan and VOIP

Config makes no sense to me, can you draw a diagram of intentions.
There is no need for vlans if you are only using two ports.
Otherwise create one bridge and any subnet becomes a vlan on the bridge.
by anav
Mon Mar 20, 2023 4:52 pm
Forum: Wireless Networking
Topic: 802.11ax 4x4:4 Wi-Fi 6 Access Point
Replies: 5
Views: 2393

Re: 802.11ax 4x4:4 Wi-Fi 6 Access Point

If you want 4x4 mu-mimo, and wifi6, look no further than the Chateau 5G AX.

Caveat: The 4x4 mu-mimo is only for the Cellular LOL.
by anav
Mon Mar 20, 2023 4:24 pm
Forum: Wireless Networking
Topic: Open SSID gets wrong VLAN
Replies: 8
Views: 1617

Re: Open SSID gets wrong VLAN

Strange behaviour is what is absolutely expected due to the admins STRANGE configuration. The router is just following commands. :-0 Where did you get the config advice from ( which link )? 1. Thats because no one in their right mind assigns a vlan1 to the bridge. 2. Why are you using vlans in wifi ...
by anav
Mon Mar 20, 2023 2:44 pm
Forum: General
Topic: Wireguard help (again)
Replies: 25
Views: 2281

Re: Wireguard help (again)

The errors have been explained many times....................
As I said, if you want me to teamviewer in, and do it myself, am willing.
Advice here is not getting through.
by anav
Mon Mar 20, 2023 2:39 pm
Forum: Scripting
Topic: Send Traceroute Report to the Telegram
Replies: 15
Views: 2038

Re: Send Traceroute Report to the Telegram

rextended, first rule of discipline is that when you say end of help, it really means end of help ;-)
Dont write any childrens books..........
by anav
Mon Mar 20, 2023 2:27 pm
Forum: Beginner Basics
Topic: NAT to change IP addresses using dstnat on ip-range
Replies: 5
Views: 1641

Re: NAT to change IP addresses using dstnat on ip-range

Check out this, fresh out of the box........
viewtopic.php?p=990947#p990947
by anav
Mon Mar 20, 2023 2:09 pm
Forum: General
Topic: Wireguard on mikrotik AND on PC attached to it
Replies: 11
Views: 843

Re: Wireguard on mikrotik AND on PC attached to it

Sorry no capiche. Do not use wireguard as a LAN subnet on routers. Clearly for single devices, the wireguard address is its address. For users on routers, they dont have a wireguard address and the subnet of wireguard on the router is to be able to ping devices, and create routes etc... So again its...
by anav
Mon Mar 20, 2023 12:46 pm
Forum: General
Topic: WiFI VlAN Tag with upstream switch
Replies: 3
Views: 334

Re: WiFI VlAN Tag with upstream switch

I'm not paid enough for such novel thinking, however if MT added a zerotrust cloudflare options package for all MT devices, I would probably be inspired to recommend MT switches. ;-)
by anav
Mon Mar 20, 2023 12:38 pm
Forum: Beginner Basics
Topic: Wireguard: how to configure this network?
Replies: 12
Views: 1341

Re: Wireguard: how to configure this network?

Can you clarify Router2. It seems you want it to be able to go out internet via 3 locations, local, vps and Router 0. Do you mean different subnets on Router2 or the same single subnet? If the latter this will not be possible I dont think. If router2 requests internet, its first peer to peer link wi...
by anav
Mon Mar 20, 2023 1:58 am
Forum: Beginner Basics
Topic: NAT to change IP addresses using dstnat on ip-range
Replies: 5
Views: 1641

Re: NAT to change IP addresses using dstnat on ip-range

I think the problem is locally, any attempt to have a destination address in the same subnet will never see the light of day of an L3 rule. My grasp of fundamentals is weak so that is just a guess as sourcenat seems to come as a last step in traffic flow. Why not change device needing access to a di...
by anav
Mon Mar 20, 2023 1:43 am
Forum: General
Topic: WiFI VlAN Tag with upstream switch
Replies: 3
Views: 334

Re: WiFI VlAN Tag with upstream switch

You need to do this on the pfsense router and cisco switch so wrong forum.
by anav
Sun Mar 19, 2023 10:46 pm
Forum: General
Topic: Recursive routing from V6 to V7
Replies: 2
Views: 1302

Re: Recursive routing from V6 to V7

read para I - viewtopic.php?t=182373

See recursive routing and two rules of thumb.
by anav
Sun Mar 19, 2023 9:33 pm
Forum: General
Topic: Network discovery over wireguard
Replies: 33
Views: 4958

Re: Network discovery over wireguard

With the help of some friends, as I am not worthy or capable.
@HighTechLab This should solve your request!
viewtopic.php?p=990840#p990840
by anav
Sun Mar 19, 2023 9:07 pm
Forum: General
Topic: Wireguard help (again)
Replies: 25
Views: 2281

Re: Wireguard help (again)

I was hoping for...... Got it all working now I want to expand my wireguard network such that client devices on Server Router 212 are A, B, C, D, E, where E is router 312 - where E is going to act as a Server going to the following peers, Server for clients M, N, O, P - TWO relay points LOL, get a d...
by anav
Sun Mar 19, 2023 4:34 pm
Forum: General
Topic: WireGuard RoadWarior plus VLAN configuration
Replies: 18
Views: 2583

Re: WireGuard RoadWarior plus VLAN configuration

(1) From /interface list members TO: /interface list member add interface=pppoe-out1 list=WAN add interface=vlan10 list=WAN add interface=BASE_VLAN list=VLAN add interface=BLUE_VLAN list=VLAN add interface=GREEN_VLAN list=VLAN add interface=RED_VLAN list=VLAN add interface=BASE_VLAN list=BASE [/size...
by anav
Sun Mar 19, 2023 4:12 pm
Forum: General
Topic: Network discovery over wireguard
Replies: 33
Views: 4958

Re: Network discovery over wireguard

I dont believe its possible or more accurately I dont think its stable if you do........... Even in the same subnet its very tricky to get right.
by anav
Sun Mar 19, 2023 4:05 pm
Forum: General
Topic: Wireguard help (again)
Replies: 25
Views: 2281

Re: Wireguard help (again)

Its simple, At initial connection, the handshake there is between one client and one server. In your case you have many clients and thus each will undergo an initial handshake with 212. You ONLY have peer to peer networks between each client and the Server. There is no direct peer to peer connection...
by anav
Sun Mar 19, 2023 3:19 pm
Forum: General
Topic: Network discovery over wireguard
Replies: 33
Views: 4958

Re: Network discovery over wireguard

Good thread! ZEROTIER is the clear answer both being arm devices. @OP, to be clear the person requiring access to devices at work lives at home so its HOME TO WORK flow? @ UpRunTech, were the subnets you connected via EOIP, different. My understanding is that spanning has to be to the same subnet?? ...
by anav
Sun Mar 19, 2023 12:11 am
Forum: General
Topic: Wireguard help (again)
Replies: 25
Views: 2281

Re: Wireguard help (again)

If 212 is the only main server for handshakes, I pointed out why its not working and the fixes.
Ensure you do them and post again for any additional refinements...........
by anav
Sat Mar 18, 2023 9:50 pm
Forum: General
Topic: Container/Docker -Adguard/Pihole For REAL.
Replies: 34
Views: 9930

Re: Container/Docker -Adguard/Pihole For REAL.

And to the point, if it aint vlans ( and one or more bridges ) not interested.
by anav
Sat Mar 18, 2023 6:01 pm
Forum: Beginner Basics
Topic: Internet access control at home
Replies: 6
Views: 1159

Re: Internet access control at home

isnt there kids home function on router??
by anav
Sat Mar 18, 2023 3:18 pm
Forum: General
Topic: No access to internal network from OpenVPN clients
Replies: 5
Views: 502

Re: No access to internal network from OpenVPN clients

Hahaha, like I said, wireguard is included on RoS, no need for any additional complexity............ can lead a horse to water........
by anav
Sat Mar 18, 2023 2:21 pm
Forum: General
Topic: Wireguard help (again)
Replies: 25
Views: 2281

Re: Wireguard help (again)

HEX212: The only two things noted on 212 are below, so dont really see a show stopper here....... (1) Your laptop etc is missing persistent-keep-alive setting on the peer for 212. (2) Why do you have keep alive set on the HEX for all the client peers that are routers except the one discussed at (2)...
by anav
Sat Mar 18, 2023 1:47 pm
Forum: Beginner Basics
Topic: hEX setup as a PPPoE router + dumb switch
Replies: 2
Views: 739

Re: hEX setup as a PPPoE router + dumb switch

(1) The IP address of your LAN network should be interface bridge !!! /ip address add address=192.168.1.1/24 comment=defconf interface= ether2 network=\ 192.168.1.0 (2) DISABLE or remove THIS rule as your internet is done through pppoe /ip dhcp-client add comment=defconf interface=ether1 (3) You for...
by anav
Sat Mar 18, 2023 1:42 pm
Forum: Beginner Basics
Topic: Block access between wan, lan and VOIP
Replies: 3
Views: 405

Re: Block access between wan, lan and VOIP

Its probably due to the default firewall rules which pretty much are safe but allow LAN to LAN traffic at layer 3. To confirm would need to see your config to adjust the firewall.......... /export file=anynameyouwish ( minus router serial number or any public WAN IP information ). [Since it looks li...
by anav
Sat Mar 18, 2023 5:06 am
Forum: Beginner Basics
Topic: Can't get source NAT to work
Replies: 3
Views: 978

Re: Can't get source NAT to work

Regular Servers dont originate traffic..............So why does this one? --> Does it stream for example

YOu have to ensure traffic is routed out the appropriate WAN or ensure the WAN being used has source nat associated.
by anav
Fri Mar 17, 2023 11:14 pm
Forum: General
Topic: Container/Docker -Adguard/Pihole For REAL.
Replies: 34
Views: 9930

Re: Container/Docker -Adguard/Pihole For REAL.

Yes but AMMO clearly MT and others are pushing the idea of a separate bridge just for containers but I prefer a separate VLAN for each service/functionality.
by anav
Fri Mar 17, 2023 11:11 pm
Forum: General
Topic: No access to internal network from OpenVPN clients
Replies: 5
Views: 502

Re: No access to internal network from OpenVPN clients

Yeah, use wireguard, faster, easier better supported by RoS.
by anav
Fri Mar 17, 2023 11:10 pm
Forum: General
Topic: Wireguard on mikrotik AND on PC attached to it
Replies: 11
Views: 843

Re: Wireguard on mikrotik AND on PC attached to it

Why do you have the private LANs identical behind both routers that can get confusing fast and not a good idea generally.
by anav
Fri Mar 17, 2023 6:38 pm
Forum: General
Topic: Container/Docker -Adguard/Pihole For REAL.
Replies: 34
Views: 9930

Re: Container/Docker -Adguard/Pihole For REAL.

Lets forget Pi-hole its so yesterday (betamax). Either discuss adguard or blocky for example.
by anav
Fri Mar 17, 2023 4:37 pm
Forum: Beginner Basics
Topic: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]
Replies: 16
Views: 1057

Re: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]

Okay so you want it as a dumb switch which tells me you only have one subnet coming into it and its feeding a bunch of dumb devices on one subnet. In other words, as always I never trust what people say/write, I only go by the evidence and your diagrams and config support the fact that the RB4011 is...
by anav
Fri Mar 17, 2023 4:13 pm
Forum: General
Topic: Wireguard on mikrotik AND on PC attached to it
Replies: 11
Views: 843

Re: Wireguard on mikrotik AND on PC attached to it

sorry no images are being shown, and do you have a config on the MT to show?
by anav
Fri Mar 17, 2023 4:06 pm
Forum: General
Topic: Check please my configuration and firewall
Replies: 6
Views: 887

Re: Check please my configuration and firewall

(1) I can understand you making changed to the forward chain, aka to refine access but what I dont understand is the BS rules you add in the input chain. /ip firewall filter add action=accept chain=input comment="established, related, untracked" \ connection-state=established,related,untra...
by anav
Fri Mar 17, 2023 3:40 pm
Forum: Beginner Basics
Topic: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]
Replies: 16
Views: 1057

Re: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]

So the AX3 is your main router and the RB4011 is WHAT? Supposed to be a AP/Switch or another router ( do you really want double NAT )???
by anav
Fri Mar 17, 2023 3:36 pm
Forum: Beginner Basics
Topic: Basic VLAN config
Replies: 1
Views: 375

Re: Basic VLAN config

Nothing is clear, network diagram needed!
Is RB4011 main router attached to internet and switch is behind the router
OR
is RB4011 simply a switch within a nework etc......
by anav
Fri Mar 17, 2023 3:34 pm
Forum: Beginner Basics
Topic: Trunk and VLAN's - RB951, Router os 6.4x
Replies: 2
Views: 327

Re: Trunk and VLAN's - RB951, Router os 6.4x

nework diagram please, are both acting as routers, where is internet, etc.......
by anav
Fri Mar 17, 2023 3:39 am
Forum: Containers
Topic: DNS not working in containers with DNS over HTTPS setup on router
Replies: 7
Views: 4102

Re: DNS not working in containers with DNS over HTTPS setup on router

Hi there, so you use containers for some functionality, but use the DOH on the router itself. Q1. Did the solution you found to your issue, mean that the Container bypasses DOH for DNS and goes to the router to DND and then out to the internet? Q2. If not, how did you get the containers traffic to t...
by anav
Fri Mar 17, 2023 3:29 am
Forum: General
Topic: Container/Docker -Adguard/Pihole For REAL.
Replies: 34
Views: 9930

Re: Container/Docker -Adguard/Pihole For REAL.

Thats fine but I have a single bridge with multiple VLANS.
So you are saying create a separate vlan for the docker??
by anav
Fri Mar 17, 2023 12:08 am
Forum: General
Topic: Multiple WAN and Wireguard all traffic (without one bridge traffic)
Replies: 2
Views: 654

Re: Multiple WAN and Wireguard all traffic (without one bridge traffic)

(1) This can be shortened. If using bridge and not vlans, the two bridges suffices for LAN interface list members! Also I see no purpose to the VPN list ?????? /interface list member add comment=defconf interface=bridge list=LAN add interface=lte_play list=WAN add interface=wg_biuro_lux list=VPN ???...
by anav
Thu Mar 16, 2023 11:37 pm
Forum: General
Topic: Container/Docker -Adguard/Pihole For REAL.
Replies: 34
Views: 9930

Container/Docker -Adguard/Pihole For REAL.

If one does go down the route of using some sort of DNS protection there are many options. 1. USE IPV4 servers from DNS providers that have some decent functionality against ads etc. These seem to work well but do not provide any granularity into whats is happening with clients etc..... no dashboard...
by anav
Thu Mar 16, 2023 11:07 pm
Forum: General
Topic: Route ALL traffic for 1 LAN IP from site A (via Wiregard tunnel) to site B
Replies: 21
Views: 3764

Re: Route ALL traffic for 1 LAN IP from site A (via Wiregard tunnel) to site B

Normally its a good idea to solve issues before piling on new stuff LOL.
by anav
Thu Mar 16, 2023 5:00 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 294
Views: 430686

Re: Using RouterOS to VLAN your network

Your theories only hurt us practical guys LOL
by anav
Thu Mar 16, 2023 3:16 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 294
Views: 430686

Re: Using RouterOS to VLAN your network

Why is this required?? You already have on the /interface bridge ports, ingress-filtering=yes and frame-types identified ????? ####################################### # Turn on VLAN mode ####################################### /interface bridge set BR1 vlan-filtering=yes frame-types=admit-only-vlan-...
by anav
Thu Mar 16, 2023 1:18 am
Forum: General
Topic: What model to use?
Replies: 34
Views: 2304

Re: What model to use?

Yes but this is the first time you mention you already have the router I was suggesting the 2116 LOL.. Good to go then.

The only router you pointed out was the 2004, which we know now, since you actually provided useful information, is NOT hooked up to fiber but to the 2116.
by anav
Wed Mar 15, 2023 11:14 pm
Forum: General
Topic: What model to use?
Replies: 34
Views: 2304

Re: What model to use?

No LOL, I mean YOU are paying for 10gig fibre connection. 1. You have customer A, who wants to pay you for 5gigs for throughput 2. You may need some throughput for your own needs in same location (unknown , no context) 3. You are looking for other customers at location B,C,D that may want 1gig servi...
by anav
Wed Mar 15, 2023 9:08 pm
Forum: General
Topic: What model to use?
Replies: 34
Views: 2304

Re: What model to use?

You missed my point completely sippan, he should adjust for his fibre throughput not the throughput to the client............
by anav
Wed Mar 15, 2023 9:06 pm
Forum: Beginner Basics
Topic: Forward port 80 on wan to 192.168.1.10:80 from outside and inside networks [SOLVED]
Replies: 11
Views: 3388

Re: Forward port 80 on wan to 192.168.1.10:80 from outside and inside networks [SOLVED]

Highly recommend that all those using your server provide you with their fixed static WANIP or their WANIP via a dyndns name. No excuses there are plenty of free providers. Then you make up an address list of those users..................... add chain=dstnat action=dst-nat dst-address-list=MYWANIP d...
by anav
Wed Mar 15, 2023 9:02 pm
Forum: Beginner Basics
Topic: Forward port 80 on wan to 192.168.1.10:80 from outside and inside networks [SOLVED]
Replies: 11
Views: 3388

Re: Forward port 80 on wan to 192.168.1.10:80 from outside and inside networks [SOLVED]

Some routers are for home owners, plugNplay. MT is for those who are willing to learn how traffic flows in devices and then have to program the router accordingly. If you expect to read an article without any understanding of ROS and make complete sense of it, then you are mistaken Its called experi...
by anav
Wed Mar 15, 2023 7:35 pm
Forum: General
Topic: What model to use?
Replies: 34
Views: 2304

Re: What model to use?

Hi Angel, the logic escapes me? You have a 10Gigabit Fibre line you are paying for. You have one customer that is asking for 5gb, Solution: Get a router that can handle 5gb only ?? Test result for queues and filters show a throughput of between 5-8gigs Better Solution: Get a router that can handle 1...
by anav
Wed Mar 15, 2023 6:59 pm
Forum: General
Topic: Mikrotik as NTP server, reachable but does not sync
Replies: 8
Views: 1548

Re: Mikrotik as NTP server, reachable but does not sync

ith NTP server on 6.49.7 is that even if it synchronizes properly, it's not accepted by NTP client on ROS 7.8. ROS 7.8 server is fine for other 7.8 clients though. @anav: you're risking of getting a special badge: "zerotrust spammer of the month" :wink: There are two truths in life! Ukrai...
by anav
Wed Mar 15, 2023 6:31 pm
Forum: General
Topic: Routers Coming with Default Passwords
Replies: 69
Views: 7311

Re: Routers Coming with Default Passwords

Even my cat knows you can preconfigure netinstall............ (with script).

"When using the Configure script option, it is suggested to introduce a delay before configuration execution."
https://help.mikrotik.com/docs/display/ROS/Netinstall
by anav
Wed Mar 15, 2023 6:18 pm
Forum: General
Topic: Check please my configuration and firewall
Replies: 6
Views: 887

Re: Check please my configuration and firewall

(1) FROM /interface bridge add arp=proxy-arp frame-types=admit-only-vlan-tagged name=bridge \ vlan-filtering=yes TO /interface bridge add arp=proxy-arp name=bridge vlan-filtering=yes (2) INGRESS-FILTERING=YES missing from all /interface bridge port settings. (3) WG info, good clarity on requirements...
by anav
Wed Mar 15, 2023 4:51 pm
Forum: General
Topic: Support for WAN side connections for multiple links
Replies: 9
Views: 1021

Re: Support for WAN side connections for multiple links

The second rule ( mark routing ) change to passthrough=no! and where are the rules to ensure same same for second WAN? The same approach can be applied to wireguard, think about it. The initial handshake has to come in and out of the same WAN. So by using the endpoint or server address dyndns name e...
by anav
Wed Mar 15, 2023 3:41 pm
Forum: General
Topic: Support for WAN side connections for multiple links
Replies: 9
Views: 1021

Re: Support for WAN side connections for multiple links

Okay got it. Dont worry about how incoming users get to a particular WAN Just be concerned that we ensure same in same out. Basic concept ip route add route for WAN1 table=main add route for WAN2 table=main add route for WAN1 table= isp1-out add route for WAN2 table = ISP2-OUT Preroute mangle new co...
by anav
Wed Mar 15, 2023 3:30 pm
Forum: General
Topic: Fasttrack not working on RB5009
Replies: 13
Views: 2068

Re: Fasttrack not working on RB5009

So far dont see why....... (1) Set this to NONE as mac-server by itself is not a secure access method! /tool mac-server set allowed-interface-list= listBridge (2) I am not a bond expert so the bridge ports look fine, was just wondering if the non-slave port needs to be the one on the bridge and not ...
by anav
Wed Mar 15, 2023 2:53 pm
Forum: General
Topic: WireGuard RoadWarior plus VLAN configuration
Replies: 18
Views: 2583

Re: WireGuard RoadWarior plus VLAN configuration

I will leave RDP to you LOL. I personally dont like to use it, its either wireguard in and access device or use Teamviewer LOL I was thinking about this last night. There is no issue with having a base VLAN if you want all smart devices to be on a separate VLAN. You can certainly add a fixed DHCP IP...
by anav
Wed Mar 15, 2023 2:47 pm
Forum: General
Topic: Mikrotik as NTP server, reachable but does not sync
Replies: 8
Views: 1548

Re: Mikrotik as NTP server, reachable but does not sync

Very understandable spyghost, I entered the thread, calm descended and problems magically got solved.
Now only if mikrotik could weave a little magic AND PROVIDE

Zerotrust Cloudflare tunnel as an options package for all MT devices!!!!
by anav
Wed Mar 15, 2023 2:45 pm
Forum: General
Topic: Some flame around v6.48.6 (split from the "v6.48.6 [long-term] is released!" topic)
Replies: 26
Views: 1485

Re: Some flame around v6.48.6 (split from the "v6.48.6 [long-term] is released!" topic)

A reminder that without evidence, aka full config, any OP input is an "opinion at best". When the OP is hostile or refuses to provide evidence, I move on. There is paid support (consultants) for that level of arrogance/stupidity. In my work I have provided MT with feedback/issues and they ...
by anav
Wed Mar 15, 2023 2:35 pm
Forum: Beginner Basics
Topic: settings for safe use...
Replies: 8
Views: 1518

Re: settings for safe use...

I would say you have some minor errors that need fixing.
Provide full export
/export file=anynameyouwish (minus router serial number and any public WANIP information )
by anav
Wed Mar 15, 2023 1:44 pm
Forum: General
Topic: Policy-Route Depends on default route ?
Replies: 4
Views: 664

Re: Policy-Route Depends on default route ?

Are the routers all acting as routers in one connected setup or at different locations and connected by internet?

It seems your needs only need firewall rules at ROS1 if all connected, and for the latter just use wireguard or zerotier.
by anav
Wed Mar 15, 2023 3:54 am
Forum: General
Topic: WireGuard RoadWarior plus VLAN configuration
Replies: 18
Views: 2583

Re: WireGuard RoadWarior plus VLAN configuration

(1) You define 4 VLANS to BR1 but only have 3 pools? 3 DHCP Servers? 3 DHCP-Server Networks? This leads me to believe you dont really have a BASE VLAN................. Thus I will assume you actually have a trusted VLAN on the BLUE vlan and I get rid of 99 (2) All bridge ports are trunk ports, I wou...
by anav
Tue Mar 14, 2023 11:59 pm
Forum: RouterOS beta
Topic: Wireguard use Hostname in endpoint
Replies: 63
Views: 19982

Re: Wireguard use Hostname in endpoint

Yeah you guys lost me long ago. Do you have a story that can be told that is easier to grasp. The way I understood is that the peer initiates a connection (single handshake with the endpoint device) and the two communicating devices send traffic back and forth as required during a session. When no t...
by anav
Tue Mar 14, 2023 10:16 pm
Forum: General
Topic: Check please my configuration and firewall
Replies: 6
Views: 887

Re: Check please my configuration and firewall

Excellent diagram!!! 1) Bridge itself, Remove frame-types=admit-only-vlan-tagged name=bridge pvid=50 \ and reset the vlan to default=1 (2) Confused as to why you have 5 vlans identified but magically 7 IP addresses??? /interface vlan add interface=bridge name="VLAN10(Cameras)" vlan-id=10 ...
by anav
Tue Mar 14, 2023 9:32 pm
Forum: General
Topic: how to use mikrotik router to bypass internet censorship in iran?
Replies: 9
Views: 1541

Re: how to use mikrotik router to bypass internet censorship in iran?

You know Normis, I would bet that the User in IRAN could share stuff with the world or each other on servers if they had............. An options package for ZERO TRUST Cloudflare Tunnel, available for all MT devices.................. ++++++++++++++++++++++++++++++++++++++++++++ When I said "Get...
by anav
Tue Mar 14, 2023 7:22 pm
Forum: General
Topic: Can not access to the remote LAN through wireguard [SOLVED]
Replies: 21
Views: 3254

Re: Can not access to the remote LAN through wireguard [SOLVED]

(1) You do not need to create a route for wireguard on the router. ( Get rid of the one you made ) When you add the ip address add address=10.0.2.1/24 interface=wireguard1 network=10.0.2.0 this automatically creates a route for you. <dac> dst-address=10.0.2.0/24 gateway=wireguard1 routing-table=main...
by anav
Tue Mar 14, 2023 5:44 pm
Forum: RouterOS beta
Topic: Marked routes with policy routing slow responses
Replies: 3
Views: 2050

Re: Marked routes with policy routing slow responses

There is also another way to deal with mangling in fastrack depending upon the complexity of the scenario. See if you can spot it?? /ip firewall filter add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \ connection-mark=no mark connection-state=established,related ...
by anav
Tue Mar 14, 2023 5:40 pm
Forum: Beginner Basics
Topic: Priority LAN to WAN connection
Replies: 5
Views: 707

Re: Priority LAN to WAN connection

Correct, distance has no bearing on that non main table entry.
by anav
Tue Mar 14, 2023 5:17 pm
Forum: General
Topic: Can access branch office devices from LAN but can't access from VPN clients
Replies: 6
Views: 1273

Re: Can access branch office devices from LAN but can't access from VPN clients

No thats your wrong assumption. You use the same WG interface on the Main router. You have to be far more clearer in your intentions. IS IT a. RW warrior connects to Main router via wireguard and then connects to branch office via ISPEC OR b. RW connects all the way to Branch Office via wireguard by...
by anav
Tue Mar 14, 2023 5:13 pm
Forum: General
Topic: Can not access to the remote LAN through wireguard [SOLVED]
Replies: 21
Views: 3254

Re: Can not access to the remote LAN through wireguard [SOLVED]

Wouldnt this work and avoids marking/mangling.... Firewall rule/ routing table/ ip route / routing rules /ip firewall filter add action=forward chain=accept in-interface=wirequard dst-address= 192.168.2.2 /routing table add fib name=useOP /ip route add dst=0.0.0.0./0 gwy=192.168.2.4 table=useOP /rou...
by anav
Tue Mar 14, 2023 5:05 pm
Forum: General
Topic: Vpn Error
Replies: 4
Views: 766

Re: Vpn Error

Try putting your config in code blocks to shorten it. Highlight your text with them, the black square with white square brackets on the same line as BOLD, Underline etc.
by anav
Tue Mar 14, 2023 5:04 pm
Forum: General
Topic: Support for WAN side connections for multiple links
Replies: 9
Views: 1021

Re: Support for WAN side connections for multiple links

1. The relationship between WAN1 and WAN2. ( assuming two different providers correct?) Is one Primary, to be used by all users and the other secondary only if WAN1 fails. 2. How are external users directed to WAN2 for example, DYDNS name if dynamic, or BY WANIP if fixed/static? All servers on WAN2 ...
by anav
Tue Mar 14, 2023 1:42 pm
Forum: General
Topic: Can access branch office devices from LAN but can't access from VPN clients
Replies: 6
Views: 1273

Re: Can access branch office devices from LAN but can't access from VPN clients

As I said you dont have WG settings on branch office.......... 1/2 done
by anav
Tue Mar 14, 2023 1:36 pm
Forum: Beginner Basics
Topic: How to setup to network tunneling over ADSL link
Replies: 5
Views: 805

Re: How to setup to network tunneling over ADSL link

Set up a wireguard tunnel and you will easily have the connectivity you desire.
See para F. - viewtopic.php?t=182373
by anav
Tue Mar 14, 2023 3:00 am
Forum: General
Topic: WireGuard RoadWarior plus VLAN configuration
Replies: 18
Views: 2583

Re: WireGuard RoadWarior plus VLAN configuration

Dont guess, be articulate. (diagram is great by the way) For example you have used 0.0.0.0/0 at both client devices on the allowed address for peer settings to the router. Assuming you want a. access to internet via router. b. for client 8.3 it appears you also want to be able to reach mail server o...
by anav
Tue Mar 14, 2023 2:50 am
Forum: General
Topic: Fasttrack vs. RAW Firewall rules
Replies: 6
Views: 934

Re: Fasttrack vs. RAW Firewall rules

You need to read again..............RAW occurs before any conntrack is done........... therefore fastrack which comes after never sees the packets that match to the raw filter rules.

Look at the fifth diagram labelled: Packet Flow Chains
https://wiki.mikrotik.com/wiki/Manual:Packet_Flow
by anav
Tue Mar 14, 2023 1:34 am
Forum: General
Topic: Fasttrack vs. RAW Firewall rules
Replies: 6
Views: 934

Re: Fasttrack vs. RAW Firewall rules

My understanding is that there is no interaction between RAW filter firewall rules and fastrack. Raw happens before any connection tracking etc.
Mangling, queues etc are a different story and one has to consider fastrack in the configuration.
by anav
Mon Mar 13, 2023 11:34 pm
Forum: General
Topic: Can not access to the remote LAN through wireguard [SOLVED]
Replies: 21
Views: 3254

Re: Can not access to the remote LAN through wireguard [SOLVED]

What is so special about openwrt that the traffic needs to go from wireguard through MT router and then not directly to WAN? I dont get it?
What is is that the MT router cannot do??
by anav
Mon Mar 13, 2023 11:32 pm
Forum: General
Topic: What model to use?
Replies: 34
Views: 2304

Re: What model to use?

Perhaps this a ChatGPT invasion LOL
by anav
Mon Mar 13, 2023 11:30 pm
Forum: Beginner Basics
Topic: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]
Replies: 38
Views: 2573

Re: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]

Techsystem, if you didnt understand what was done and why it works, then the config might work, but the effort from my perspective is a fail.
by anav
Mon Mar 13, 2023 10:53 pm
Forum: Useful user articles
Topic: How to: Edge router and BNG optimization for ISPs Topic is solved
Replies: 68
Views: 90658

Re: How to: Edge router and BNG optimization for ISPs Topic is solved

Now I understand where my logic failed...... There is a substantial difference between blocking in RAW packets leaving the LAN that are not from LAN subnets existing on the router. and RBH which is predicated on removing any traffic from the LAN to private IP addresses ( or non-valid public IPs ). S...
by anav
Mon Mar 13, 2023 10:36 pm
Forum: Beginner Basics
Topic: Wireguard: how to configure this network?
Replies: 12
Views: 1341

Re: Wireguard: how to configure this network?

R0 - Three items ( table, route, routing rule) /routing table add fib name=useVPS [/i] /ip route add dst--address=0.0.0.0./0 gateway=RO-WAN table=main add dst-address=0.0.0.0/0 gateway=wireguard-interface table=useVPS /routing rule add action=lookup src-address=172.16.20.0/24 table=useVPS Note1: If...
by anav
Mon Mar 13, 2023 10:20 pm
Forum: Beginner Basics
Topic: Wireguard: how to configure this network?
Replies: 12
Views: 1341

Re: Wireguard: how to configure this network?

Good to know, we can probably dispense with any mangling!! Any issues with pinging is at your VPS see below! (1) As indicated you need to ensure you have an equivalent rule on VPS add action=accept chain=forward in-interface=wireguard-interface out-interface=wireguard-interface (2) Route to all subn...
by anav
Mon Mar 13, 2023 10:18 pm
Forum: RouterOS beta
Topic: Marked routes with policy routing slow responses
Replies: 3
Views: 2050

Re: Marked routes with policy routing slow responses

Impossible to tell, you didnt provide your config!!
by anav
Mon Mar 13, 2023 10:10 pm
Forum: General
Topic: WireGuard and placing a client on the LAN segment of my network
Replies: 34
Views: 4610

Re: WireGuard and placing a client on the LAN segment of my network

WINNER WINNER TURKEY DINNER - Marino! SOLUTION METHOD FOUR - PREFERRED Option USE DNS ONLY a. create wireguard connectivity as per normal and then b. create the IP DNS SETTINGS and DHCP SERVER SETTINGS on Router 2. c. modify configs to allow Access Points via Wireguard (L3 traffic) to route to Unifi...
by anav
Mon Mar 13, 2023 9:02 pm
Forum: General
Topic: WireGuard and placing a client on the LAN segment of my network
Replies: 34
Views: 4610

Re: WireGuard and placing a client on the LAN segment of my network

3) Make alternative recommendations even if it includes somehow telling the Unifi Controller to go "look" for LAN B 0.X via client interface tunnel WG connected on 2.X ps : I know I can re-enroll/adopt the Unifi equipment and connect them to the controller on LAN A easy enough, but I don'...
by anav
Mon Mar 13, 2023 7:56 pm
Forum: General
Topic: WireGuard and placing a client on the LAN segment of my network
Replies: 34
Views: 4610

Re: WireGuard and placing a client on the LAN segment of my network

I only make the configs, I have no use for them personally LOL, so have no clue when the rubber meats the road!!
by anav
Mon Mar 13, 2023 7:55 pm
Forum: General
Topic: Can not access to the remote LAN through wireguard [SOLVED]
Replies: 21
Views: 3254

Re: Can not access to the remote LAN through wireguard [SOLVED]

Why do you send wg to openwrt??? what is GFW???

Are the users coming into the router via WG and then NOT going out the local WAN but out a remote WAN via an openwrt tunnel ????
by anav
Mon Mar 13, 2023 7:49 pm
Forum: General
Topic: What model to use?
Replies: 34
Views: 2304

Re: What model to use?

What are your qualifications, general IT knowledge or actual Mikrotik Certifications???
If this is your company business, it sounds like you need to hire a consultant.............
https://mikrotik.com/consultants
by anav
Mon Mar 13, 2023 7:47 pm
Forum: Beginner Basics
Topic: Help with pinging between only "existing" VLANs, not any I create now
Replies: 6
Views: 576

Re: Help with pinging between only "existing" VLANs, not any I create now

So are you saying you define vlans elsewhere (other devices) but they need to traverse this router enroute somewhere else be it internet or other devices on the network????
by anav
Mon Mar 13, 2023 7:46 pm
Forum: Beginner Basics
Topic: Help with pinging between only "existing" VLANs, not any I create now
Replies: 6
Views: 576

Re: Help with pinging between only "existing" VLANs, not any I create now

To manage the configuration and possible burps with bridge and/or vlan configuration, I prefer to create an off-bridge port. Lets say ether5, ensure its off the bridge. create an IP address for it. 192.168.55.1/24 interface=ether5 network=192.168.55.0 Done! Now you can plug in a laptop to ether5 set...
by anav
Mon Mar 13, 2023 4:48 pm
Forum: Beginner Basics
Topic: My ISP is getting internet connection perfectly, but I can't get mikrotek router to connect my PC to internet
Replies: 1
Views: 262

Re: My ISP is getting internet connection perfectly, but I can't get mikrotek router to connect my PC to internet

If your intent was to never learn MT ROS, and thus enter the router, you should replace with TPLINK router.
by anav
Mon Mar 13, 2023 4:47 pm
Forum: Beginner Basics
Topic: Can't forward ports for minecraft server
Replies: 4
Views: 398

Re: Can't forward ports for minecraft server

Not interested, if all your doing is copying shit without an iota of attempt to learn.
by anav
Mon Mar 13, 2023 4:37 pm
Forum: General
Topic: Can not access to the remote LAN through wireguard [SOLVED]
Replies: 21
Views: 3254

Re: Can not access to the remote LAN through wireguard [SOLVED]

(1) Are you accessing internet of network from wireguard clients or just subnets and the router/devices for config purposes? (2) Why are you marking wireguard traffic? (3) Why are your source nat rules SO OBTUSE. and I dont even see a default rule??? (4) Are you attempting to run your own DNS server...
by anav
Mon Mar 13, 2023 4:04 pm
Forum: General
Topic: WireGuard and placing a client on the LAN segment of my network
Replies: 34
Views: 4610

Re: WireGuard and placing a client on the LAN segment of my network

Stick to (conspiracy) theories ;-) Reading on the always 100% accurate internet........ "I've tunneled VXLAN over Wireguard on Linux. In my setup, my WAN's MTU was 1500 bytes, and my Wireguard tunnel's MTU was 1550, with the VXLAN's MTU being 1500. Surprisingly, traffic and iperf3 tests going o...
by anav
Mon Mar 13, 2023 1:43 pm
Forum: General
Topic: WireGuard RoadWarior plus VLAN configuration
Replies: 18
Views: 2583

Re: WireGuard RoadWarior plus VLAN configuration

Your requirements are poorly worded and thus have no clue what you want to do. Provide a network diagram, that often helps. OR Provide a clear set of user requirements for wireguard specific traffic 1. Identify and Define user/device X needs for flow of traffic. To reach user/device Y or groups of u...
by anav
Mon Mar 13, 2023 1:28 pm
Forum: General
Topic: WireGuard and placing a client on the LAN segment of my network
Replies: 34
Views: 4610

Re: WireGuard and placing a client on the LAN segment of my network

Thanks nichy I will review................... I thought the vni had to be duplicated................ like EOIP code etc......... Confirmed think of vni as the Group code for all members on the same vxlan. In terms of the port setting, what I was instructed is that they do not need to be identical, b...
by anav
Mon Mar 13, 2023 1:23 pm
Forum: General
Topic: Can not access to the remote LAN through wireguard [SOLVED]
Replies: 21
Views: 3254

Re: Can not access to the remote LAN through wireguard [SOLVED]

Because I deal only in home networks, I need simple talk.

Is the problem that you cannot get your wireguard users 'pad/notebook' to use the local DNS server at device .2.3 ??

Aka what is the problem in clearer terms
by anav
Mon Mar 13, 2023 1:15 pm
Forum: Scripting
Topic: Mikrotik script editor and ChatGPT
Replies: 20
Views: 4003

Re: Mikrotik script editor and ChatGPT

I asked ChatGPT how to best setup a server on MT, do you know what the response was?

Not possible until Mikrotik adds zerotrust cloudflare tunnel as an options package for all MT routers, and then Mikrotik will be the safest server option on the market!
by anav
Mon Mar 13, 2023 1:10 pm
Forum: General
Topic: IPsec road warrior tunnel all traffic
Replies: 5
Views: 796

Re: IPsec road warrior tunnel all traffic

Always on.? ................... that is why there is a persistent keep alive setting on the wireguard client side................... assuming the client device (router) is always on, the tunnel is always up.
by anav
Mon Mar 13, 2023 1:06 pm
Forum: Beginner Basics
Topic: Can't forward ports for minecraft server
Replies: 4
Views: 398

Re: Can't forward ports for minecraft server

the full config not snippets is better ( minus router serial number and any public wanip information )
why are you port forwarding to the IP address of the LAN subnet 192.168.88.1 vice the IP address of the server 192.168.88.XY
by anav
Mon Mar 13, 2023 1:03 pm
Forum: Beginner Basics
Topic: Priority LAN to WAN connection
Replies: 5
Views: 707

Re: Priority LAN to WAN connection

EASY WAY TO DO THIS - avoids mangling Step1 - create routes /ip route distance=5 dst-address=0.0.0.0/0 gwy=ISP1-gatewayIP table=main check-gateway=ping distance=10 dst-address=0.0.0.0/0 gwy=ISP2-gatewayIP table=main From this alone, you have ALL USERS going to ISP1 and if that is not available the r...
by anav
Mon Mar 13, 2023 12:51 pm
Forum: Beginner Basics
Topic: Help with pinging between only "existing" VLANs, not any I create now
Replies: 6
Views: 576

Re: Help with pinging between only "existing" VLANs, not any I create now

(1) So many vlans but you only really define 4 of them.............. (2) you can shorten up your /interface bridge vlan /interface bridge vlan add bridge=bridge tagged=bridge,sfp-sfpplus1-CRS328-1 untagged="ether4 - CMM P\ C,ether5 - Living Room,ether3 - Google Wifi,ether6 - Chris Work laptop&q...
by anav
Mon Mar 13, 2023 5:07 am
Forum: Beginner Basics
Topic: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]
Replies: 38
Views: 2573

Re: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]

You have no firewall rules so traffic is not being blocked to your lan subnets for incoming wireguard.
Did you fix the other items........... (what do the client devices have for allowed addresses for their single peer entry for the main router?)
by anav
Mon Mar 13, 2023 2:21 am
Forum: Useful user articles
Topic: How to: Edge router and BNG optimization for ISPs Topic is solved
Replies: 68
Views: 90658

Re: How to: Edge router and BNG optimization for ISPs Topic is solved

THanks, in another thread you noted to use two raw rules to stop private IPs from leaking in or out of a router when using NAT. Is this a replacement for bogon rules or an addition to? I have used bogon rules but prefer doing so in ip routes - blackhole. I don't remember what you mean. The blackhol...
by anav
Mon Mar 13, 2023 2:19 am
Forum: General
Topic: IPsec road warrior tunnel all traffic
Replies: 5
Views: 796

Re: IPsec road warrior tunnel all traffic

If you want to use fireguard.........oops wireguard LOL, it takes 10 minute max to setup. Not familiar with ipsec and its best suited for an enterprise environment anyway
by anav
Mon Mar 13, 2023 1:24 am
Forum: Beginner Basics
Topic: Wireguard: how to configure this network?
Replies: 12
Views: 1341

Re: Wireguard: how to configure this network?

VPS Discussion (1) Looking at the VPS it is seemingly configured properly as a WG Server for the initial handshake. The only comment I would make is ensure the single peer on the local Routers, to the VPS uses the nomenclature for wireguard as follows: 10.66.66.0/24 . (2) I dont see any allowance f...
by anav
Sun Mar 12, 2023 9:26 pm
Forum: RouterOS beta
Topic: VxLAN example configuration
Replies: 19
Views: 35693

Re: VxLAN example configuration

No need, working on it, almost there......... https://forum.mikrotik.com/viewtopic.php?t=194310#p989515 That was effort #3 ( vxlan over wireguard ) effort #2 is through DHCP options effort #1 is via WG and EOIP ( not yet done as have to deal with where internet comes from on spanned subnets) All thr...
by anav
Sun Mar 12, 2023 9:22 pm
Forum: Beginner Basics
Topic: Wireguard: how to configure this network?
Replies: 12
Views: 1341

Re: Wireguard: how to configure this network?

Is VPS the only wireguard device? If not would need config of all MT devices (full)
by anav
Sun Mar 12, 2023 9:21 pm
Forum: Beginner Basics
Topic: Wireguard: how to configure this network?
Replies: 12
Views: 1341

Re: Wireguard: how to configure this network?

I still dont see which routers have internet access directly it appears at the moment only Router 0 ???
by anav
Sun Mar 12, 2023 9:16 pm
Forum: Beginner Basics
Topic: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]
Replies: 38
Views: 2573

Re: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]

This is all you need........ /ip firewall nat add action=masquerade chain=srcnat out-interface=ether1 add action=masquerade chain=srcnat out-interface=ether2 add action=dst-nat chain=dstnat comment=PBX-1 dst-address=192.168.2.2\ dst-port= protocol=tcp to-addresses=192.168.1.100 to-ports= add action=...
by anav
Sun Mar 12, 2023 9:09 pm
Forum: Beginner Basics
Topic: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]
Replies: 38
Views: 2573

Re: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]

So you dont have public IPs they are private IPs from some upstream router where port fowarding can be done??
by anav
Sun Mar 12, 2023 5:36 pm
Forum: RouterOS beta
Topic: VxLAN example configuration
Replies: 19
Views: 35693

Re: VxLAN example configuration

Do you have a vxlan over wireguard example.
Im confused as to the local address I assumed these would be addresses anchored to a local wireguard address at each end
just not sure if the VTEP setting applies only to an external vxlan aware device and not used when the MT is the VXlan smart device?
by anav
Sun Mar 12, 2023 4:56 pm
Forum: General
Topic: WireGuard and placing a client on the LAN segment of my network
Replies: 34
Views: 4610

Re: WireGuard and placing a client on the LAN segment of my network

IPSEC has no utility in a home environment IMHO. Haters expected LOL...... You missed the point completely, the unif controller and AP are not in the same location and just to make sure you understand, not under the same local router! :-) How did I manage to glean that from the OP, probably his comm...
by anav
Sun Mar 12, 2023 4:53 pm
Forum: General
Topic: Mikrotik as NTP server, reachable but does not sync
Replies: 8
Views: 1548

Re: Mikrotik as NTP server, reachable but does not sync

A question you have to ask because the poster assumed he knew where the problem lies and did not provide the full config but only parts of the config......... Therefore its not clear if both server and client are configured.................. Also I use NTP server settings without stating any broadca...
by anav
Sun Mar 12, 2023 2:02 pm
Forum: General
Topic: Can not access to the remote LAN through wireguard [SOLVED]
Replies: 21
Views: 3254

Re: Can not access to the remote LAN through wireguard [SOLVED]

Provide a network diagram to help describe.
by anav
Sun Mar 12, 2023 1:57 pm
Forum: General
Topic: WireGuard and placing a client on the LAN segment of my network
Replies: 34
Views: 4610

Re: WireGuard and placing a client on the LAN segment of my network

AMMO, as you can see my EOIP solution is almost there, just need to figure out internet and WAN implications ( which is what I was expecting Holvoe to come in and show me the way.......... The dhcp options solutions should work for unifi....... good to go! As for vxlan, set WG to 1550, should make i...
by anav
Sun Mar 12, 2023 1:53 pm
Forum: Useful user articles
Topic: How to: Edge router and BNG optimization for ISPs Topic is solved
Replies: 68
Views: 90658

Re: How to: Edge router and BNG optimization for ISPs Topic is solved

THanks, in another thread you noted to use two raw rules to stop private IPs from leaking in or out of a router when using NAT.
Is this a replacement for bogon rules or an addition to? I have used bogon rules but prefer doing so in ip routes - blackhole.
by anav
Sun Mar 12, 2023 1:38 pm
Forum: Beginner Basics
Topic: interface list in /interface/bridge/vlan
Replies: 2
Views: 458

Re: interface list in /interface/bridge/vlan

Where does it indicate this is possible?
by anav
Sun Mar 12, 2023 1:33 pm
Forum: Beginner Basics
Topic: How to setup to network tunneling over ADSL link
Replies: 5
Views: 805

Re: How to setup to network tunneling over ADSL link

Is it straight IP to IP communications, you didnt clarify how the servers talk to each other?
If straight IP to IP, all you need is a wireguard tunnel
If its broadcast, you can use vxlan over wireguard to do this. It may be easier than EOIP over wireguard.
by anav
Sun Mar 12, 2023 1:30 pm
Forum: Beginner Basics
Topic: Port Forwarding Not Working
Replies: 3
Views: 408

Re: Port Forwarding Not Working

Since you have no vlans on the bridge, turn vlan-filtering OFF.

Other than that I dont see any other issues which leads me to believe you are probably not getting a reachable public IP.
by anav
Sun Mar 12, 2023 1:27 pm
Forum: Beginner Basics
Topic: Slow Hex file transfer speed
Replies: 19
Views: 2110

Re: Slow Hex file transfer speed

My questions yet unanswered (when using vlan-filtering=yes as per pcunite's work) to any satisfaction is what about the ingress filtering checkbox on the bridge a. should that be checked. b. what does it do c. how is it related to ingress filtering on each /interface bridge port line. d. how is it r...
by anav
Sun Mar 12, 2023 12:59 am
Forum: General
Topic: WireGuard and placing a client on the LAN segment of my network
Replies: 34
Views: 4610

Re: WireGuard and placing a client on the LAN segment of my network

SOLUTION METHOD 3 - VXLAN OVER WIREGUARD TUNNEL a. create wireguard connectivity as per normal and then b. create the VXLAN tunnel within the WG tunnel ( vxlan never concerns its self with local WANIPs at either end ) c. modify configs to avoid L2 conflicts with identical subnets. For those not fam...
by anav
Sat Mar 11, 2023 10:17 pm
Forum: General
Topic: WireGuard and placing a client on the LAN segment of my network
Replies: 34
Views: 4610

Re: WireGuard and placing a client on the LAN segment of my network

SOLUTION METHOD TWO USE DHCP OPTION 43 a. create wireguard connectivity as per normal and then b. create the DHCP Option settings on R2 for the unifi Access Points. c. modify configs to allow Access Points via Wireguard (L3 traffic) to route to Unific controller IP. a. Setup WG as per usual. /MT De...
by anav
Sat Mar 11, 2023 9:47 pm
Forum: General
Topic: WireGuard and placing a client on the LAN segment of my network
Replies: 34
Views: 4610

Re: WireGuard and placing a client on the LAN segment of my network

Well what format for the option 43 value does MT accept...........

192;168;168;50
or
01;04;192;168;168;50

or something else because my attempts show popup message "couldnt add new dhcp option, wrong data type! (6)"
by anav
Sat Mar 11, 2023 9:17 pm
Forum: General
Topic: Lost Connectivity
Replies: 3
Views: 692

Re: Lost Connectivity

So when the HOST router has connection issues ( host= server for initial handshake ), what happens is that the client router will attempt to re-connect with the host router. THis also happens when a dynamic WANIP changes. So the Mikrotik client attempts to find the endpoint again. The problem is if ...
by anav
Sat Mar 11, 2023 9:07 pm
Forum: Beginner Basics
Topic: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]
Replies: 38
Views: 2573

Re: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]

Well the config bares little resemblance to your first post, so not sure I can help as i dont know what is truth?? Also, on the config, it is unclear what you are doing with the two WANs? Is WAN1 Primary and WAN2 secondary. Is there failover between the WANS, Are there some users that should not use...
by anav
Sat Mar 11, 2023 8:55 pm
Forum: Beginner Basics
Topic: Port Forwarding Not Working
Replies: 3
Views: 408

Re: Port Forwarding Not Working

(1) What is vlan1 (id=6), it has no IP Pool no structure..............and NO purpose. Get rid of it in both the definition of a vlan part and get rid of /interface bridge vlan rules, without the vlan you dont need it. (2) WHY DUPLICATE DST NAT RULES?? (3)What is the purpose of this rule....... add a...
by anav
Sat Mar 11, 2023 8:48 pm
Forum: Beginner Basics
Topic: Slow Hex file transfer speed
Replies: 19
Views: 2110

Re: Slow Hex file transfer speed

No capiche! Sorry. Zilcho Nada, this is what I read....

אין לי מושג מה אתה מנסה להגיד.
by anav
Sat Mar 11, 2023 5:56 pm
Forum: Beginner Basics
Topic: Slow Hex file transfer speed
Replies: 19
Views: 2110

Re: Slow Hex file transfer speed

I have no clue what you just said or recommended. Set bridge to vlan-filtering=yes works and causes no issues. If you want to be anal and correct then assign ingress filtering on every bridge port (except hybrid ports) then assign frame types allowed specific to trunk ports and access ports ( hybrid...
by anav
Sat Mar 11, 2023 5:51 pm
Forum: Wireless Networking
Topic: WIFI + BRIDGE + VLANS (access,trunk,hybrid)
Replies: 6
Views: 2191

Re: WIFI + BRIDGE + VLANS (access,trunk,hybrid)

I want to better understand Case1, in case their is a scenario where it may make sense to use it. However I cannot wrap my head around Case 1, if you do assign vlan-id=5, vlan-mode=use tag! More specifically what do you then do on the /interface bridge port settings and /interface bridge vlan settin...
by anav
Sat Mar 11, 2023 5:34 pm
Forum: Wireless Networking
Topic: WIFI + BRIDGE + VLANS (access,trunk,hybrid)
Replies: 6
Views: 2191

Re: WIFI + BRIDGE + VLANS (access,trunk,hybrid)

Your answer was confusing I DONT USE wifi settings to apply any VLAN etc... Therefore the response made no sense to me. :-( I apply vlans through interface bridge port and bridge vlan settings only. After re-reading I understand that CASE 2 is exactly what I am asking and based on vlanid=1 on the wi...
by anav
Sat Mar 11, 2023 5:33 pm
Forum: Wireless Networking
Topic: WIFI + BRIDGE + VLANS (access,trunk,hybrid)
Replies: 6
Views: 2191

Re: WIFI + BRIDGE + VLANS (access,trunk,hybrid)

ANSWER What happens with the WLAN1 wireless settings ..... when set to (case 1) If "Vlan mode = use tag", "VLAN ID = 5" , the packets from the bridge will be filtered on VLAN ID, will be tagged when sent to the bridge, untagged when sent to wifi WLAN1 now acts a a VLAN aware swi...
by anav
Sat Mar 11, 2023 5:32 pm
Forum: Wireless Networking
Topic: WIFI + BRIDGE + VLANS (access,trunk,hybrid)
Replies: 6
Views: 2191

WIFI + BRIDGE + VLANS (access,trunk,hybrid)

The basic question, can you send vlan tagged frames like a trunk port approach over WLAN. All I know is sending untagged data over WLAN. Begs the question I suppose as well about hybrid!! @bpwl can you tag a WLAN?? typical MT setup - access port /interface bridge port add bridge=bridge interface=WLA...
by anav
Sat Mar 11, 2023 2:06 pm
Forum: Wireless Networking
Topic: CCR1009 with 3 cAP ac
Replies: 2
Views: 912

Re: CCR1009 with 3 cAP ac

Simplify your setup and remove capsman.
Once you config one capac, the other two are usually almost identical. Easy Peasy and it works.
by anav
Sat Mar 11, 2023 1:59 pm
Forum: Beginner Basics
Topic: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]
Replies: 38
Views: 2573

Re: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]

Great now provide the export
/export file=anynameyouwish ( minus router serial number and any public WANIP information )
by anav
Sat Mar 11, 2023 1:47 pm
Forum: Beginner Basics
Topic: Slow Hex file transfer speed
Replies: 19
Views: 2110

Re: Slow Hex file transfer speed

The only thing the bridge needs is vlan-filtering=yes, there is no reason to put frame types, that is done on bridge ports.
by anav
Sat Mar 11, 2023 5:01 am
Forum: General
Topic: How should I configure a site-to-site VPN tunnel based on wireguard in a multi-wan environment?
Replies: 6
Views: 765

Re: How should I configure a site-to-site VPN tunnel based on wireguard in a multi-wan environment?

First comment is that it is not clear if which router is considered the server for the initial handshake and which one the client. Second comment why do they both have 0.0.0.0/0 selected at peer allowed IP settings. Typically one uses 0.0.0.0/0 at one end to signify that users local on that device a...
by anav
Sat Mar 11, 2023 2:47 am
Forum: Beginner Basics
Topic: VLAN ax3
Replies: 20
Views: 2808

Re: VLAN ax3

Is it just the wifi where you are not getting any dhcp??
by anav
Sat Mar 11, 2023 2:44 am
Forum: Beginner Basics
Topic: Slow Hex file transfer speed
Replies: 19
Views: 2110

Re: Slow Hex file transfer speed

The config is not correct............ (1) WRONG /interface bridge add admin-mac=<mac> auto-mac=no comment=defconf name=bridge pvid=10 vlan-filtering=yes CORRECT /interface bridge add admin-mac=<mac> auto-mac=no comment=defconf name=bridge vlan-filtering=yes (2) WRONG /interface bridge port add bridg...
by anav
Fri Mar 10, 2023 7:53 pm
Forum: Beginner Basics
Topic: VLAN ax3
Replies: 20
Views: 2808

Re: VLAN ax3

Your config has no errors I can see.
Try rebooting the router...........
by anav
Fri Mar 10, 2023 6:54 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 258
Views: 48852

Re: MikroTik hAP ax3 poor WiFi performance

bpwl can you tag a WLAN?? typical MT setup - access port /interface bridge port add bridge=bridge interface=WLAN1 pvid=5 /interface bridge vlan add bridge=bridge tagged=bridge untagged=WLAN1 vlan-ids=5 Possible? trunk port /interface bridge port add bridge=bridge interface=WLAN1 /interface bridge vl...
by anav
Fri Mar 10, 2023 6:22 pm
Forum: Beginner Basics
Topic: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]
Replies: 38
Views: 2573

Re: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]

I suspect your equipment drinks blood and goes out at night ................. A diagram will help, then instead of rambling sentences that make no sense right down your user requirements with respect to wireguard. Router X ( wg server for initial handshake) Router Y (wg client router for initial han...
by anav
Fri Mar 10, 2023 6:19 pm
Forum: Beginner Basics
Topic: redirect users to another ISP without using Routing rules
Replies: 7
Views: 672

Re: redirect users to another ISP without using Routing rules

Not really, Its a one line simple mangle rule (plus some route stuff), The only reason for two simple forward chain rules is to keep using fasstrack for everything else. DONE!!!! Do you need lifejackets, Ive heard all the sharks in the pacific are congregating off the shoreline awaiting all the fres...
by anav
Fri Mar 10, 2023 6:17 pm
Forum: Beginner Basics
Topic: Port Forwarding seemed simple, but...
Replies: 7
Views: 513

Re: Port Forwarding seemed simple, but...

Thanks again.... let me actually read the reference.....
Fixed it for ya
(another clue that you didnt is the fact that you still have both dst-port and to-port LOL )
by anav
Fri Mar 10, 2023 6:16 pm
Forum: Beginner Basics
Topic: VPN cyberghostvpn
Replies: 15
Views: 12019

Re: VPN cyberghostvpn

Well I have no clue what cyberghost provides you for client information???? In terms of information They provide you with your wireguard IP address They provide you with a public key from them which you stick into your router wireguard peer settings for the hostcyberguard They provide you with and e...
by anav
Fri Mar 10, 2023 5:49 pm
Forum: Beginner Basics
Topic: redirect users to another ISP without using Routing rules
Replies: 7
Views: 672

Re: redirect users to another ISP without using Routing rules

@ammo Shouldn't you be busy building an ARK right now??? Your solution is interesting but what if you have 20 users are they are all from different subnets ! ;-P @op there are so many resources available to you..................... (anything by the network berg or (MAICT) maher haddad on youtube is ...
by anav
Fri Mar 10, 2023 5:47 pm
Forum: Beginner Basics
Topic: Port Forwarding seemed simple, but...
Replies: 7
Views: 513

Re: Port Forwarding seemed simple, but...

No the guidance certainly did not!!

Where is the dst-address=WANIP of the router for fixed//static WANIP OR
where is the out-interface-list=WAN for dynamic wanip or any variation needed for hairpin NAT.
by anav
Fri Mar 10, 2023 3:17 pm
Forum: General
Topic: Can access branch office devices from LAN but can't access from VPN clients
Replies: 6
Views: 1273

Re: Can access branch office devices from LAN but can't access from VPN clients

You are missing the wg config on the branch office to tie into the wg server at the main office. ??????
It is like your 1/2 done.
by anav
Fri Mar 10, 2023 3:12 pm
Forum: General
Topic: Is it possible to start a Home server with an RB2011UiAS-2HnD-IN ?
Replies: 9
Views: 1263

Re: Is it possible to start a Home server with an RB2011UiAS-2HnD-IN ?

You wont be able to do much from Iran and your router is too old to be useful in any kind of $$ enterprise besides not knowing much about networking or MT routers.
It would be criminal to take money from unsuspecting clients at this point and its probably an illegal use of your internet connection.