Community discussions

MikroTik App

Search found 19524 matches

by anav
Mon Jan 08, 2024 6:38 pm
Forum: Beginner Basics
Topic: New to Mkt, struggling with basic VLAN setup [SOLVED]
Replies: 15
Views: 3748

Re: New to Mkt, struggling with basic VLAN setup [SOLVED]

The doc shows it but your config still not correct. /interface bridge port add bridge=br-dcwifi ingress-filtering=yes frame-types=admit-priority-and-untagged interface=ether2 pvid=9 add bridge=br-dcwifi ingress-filtering=yes frame-types=admit-priority-and-untagged i interface=ether4 pvid=8 add bridg...
by anav
Mon Jan 08, 2024 6:35 pm
Forum: Beginner Basics
Topic: port forwarding
Replies: 61
Views: 4353

Re: port forwarding

Decent! Observations (1) One doesnt make port forwarding rules in the forward chain thus get rid of this .... The only thing that should be in the forward chain is one rule allowing dstnat. All port forwarding details are put in the dstnat chain rules. Also its in the wrong order if it was to be in ...
by anav
Mon Jan 08, 2024 4:37 pm
Forum: General
Topic: Access LAN through WG+L2TP tunnel
Replies: 6
Views: 1348

Re: Access LAN through WG+L2TP tunnel

I thought I had a solution but then ran up against the MAIN ISSUE. I see conflict in attempt to tell the R1 router how to route traffic headed towards theR2 subnet. a. L2TP for R1 subnet to R2 subnet b. Wireguard for remote users to same R2 subnet. Why not send R1 Subnet users ALSO over wireguard to...
by anav
Mon Jan 08, 2024 4:34 pm
Forum: General
Topic: DUAL-WAN PPPOE CLIENT WITH PCC LOAD BALANCING FAILED TO WORK
Replies: 5
Views: 1386

Re: DUAL-WAN PPPOE CLIENT WITH PCC LOAD BALANCING FAILED TO WORK

For mangle rules you dont need the first sets of rules................... Not explained properly by the video author, why he has the first set of rules which dont apply YET in your simple case. Start here for required rules........ You dont need both new and no-mark, no-mark is a better option norma...
by anav
Mon Jan 08, 2024 4:08 pm
Forum: General
Topic: DUAL-WAN PPPOE CLIENT WITH PCC LOAD BALANCING FAILED TO WORK
Replies: 5
Views: 1386

Re: DUAL-WAN PPPOE CLIENT WITH PCC LOAD BALANCING FAILED TO WORK

Sure, first I would update the firmware to the lastest stable update, 7.8 and earlier 7 versions had issues. Just to confirm you DON'T WANT primary/failover you want PCC/failover. The difference is that in primary/failover, only one ISP is providing connections. In PCC both ISPs are used at the same...
by anav
Mon Jan 08, 2024 4:00 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7040

Re: Wireguard guru needed [SOLVED]

Yes but your assuming AmmO can find the other thread. ;-)
by anav
Mon Jan 08, 2024 3:59 pm
Forum: Beginner Basics
Topic: EOIP over Wireguard (For RoMon purposes only) [SOLVED]
Replies: 33
Views: 4308

Re: EOIP over Wireguard (For RoMon purposes only) [SOLVED]

Dont look at me ;-). You need the expert and prompt advice of the perps Ammo and Holvoe to the rescue!!
by anav
Mon Jan 08, 2024 3:57 pm
Forum: Beginner Basics
Topic: still same problem and same issue please help!
Replies: 8
Views: 2481

Re: still same problem and same issue please help!

Edit: Please ensure you let folks know your router is behind another router, especially with unsafe configs as per below!! Even still I would only allow VPN to the router and then access config/subnets. /ip firewall filter add action=accept chain=input comment= "Router Access Remotely " ds...
by anav
Mon Jan 08, 2024 3:49 pm
Forum: Beginner Basics
Topic: New to Mkt, struggling with basic VLAN setup [SOLVED]
Replies: 15
Views: 3748

Re: New to Mkt, struggling with basic VLAN setup [SOLVED]

Read through this article and pay close attention to /interface bridge ports and /interface bridge vlans to find your error :-)
viewtopic.php?t=143620
by anav
Mon Jan 08, 2024 3:46 pm
Forum: Beginner Basics
Topic: port forwarding
Replies: 61
Views: 4353

Re: port forwarding

No point in showing you dont know how to config the router just yet. Please attempt the readings and then come back and post a complete config. Understanding is more important then copy and paste at this juncture /export file=anynameyouwish ( minus router serial number and any public WANIP informati...
by anav
Mon Jan 08, 2024 3:43 pm
Forum: Beginner Basics
Topic: Best way of 3 routers connection
Replies: 10
Views: 1722

Re: Best way of 3 routers connection

Sounds like a scenario for double nat. Modem, to MT Router, then to TPLINK router (for vpn mostly).
The hex need not route as my earlier post and can be connected to the AX as a switch.
by anav
Mon Jan 08, 2024 2:02 pm
Forum: Beginner Basics
Topic: New to Mkt, struggling with basic VLAN setup [SOLVED]
Replies: 15
Views: 3748

Re: New to Mkt, struggling with basic VLAN setup [SOLVED]

Ahh okay, I see you only have one subnet and are using a vlan for that. A bit unusual but perfectly fine.
My question is, where are your firewall rules?
Where is your internet connection??
by anav
Mon Jan 08, 2024 1:59 pm
Forum: Beginner Basics
Topic: port forwarding
Replies: 61
Views: 4353

Re: port forwarding

Have some reading to do!!

viewtopic.php?p=908118

viewtopic.php?t=191442

Only after you have gone over the above.....
viewtopic.php?t=179343
by anav
Mon Jan 08, 2024 5:44 am
Forum: Beginner Basics
Topic: LAN communication issue
Replies: 1
Views: 1054

Re: LAN communication issue

Any devices connected to your bridge ports should be able to see each other as you only have one flat network at L2. The firewall rules are for L3 traffic and they couldnt block same lan to same lan traffic anyway. Config looks okay on quick look. A. Either all are connected to PCs with strict firew...
by anav
Mon Jan 08, 2024 5:41 am
Forum: Beginner Basics
Topic: VLAN on the router switch port
Replies: 1
Views: 1015

Re: VLAN on the router switch port

One bridge, dont uses vlan1 (use any other for data), recommended NOT to use bridge for dhcp...........
viewtopic.php?t=143620
by anav
Sun Jan 07, 2024 11:07 pm
Forum: General
Topic: Setting VLAN ID on modem or on router
Replies: 7
Views: 1426

Re: Setting VLAN ID on modem or on router

If the modem passed the internet to you within a vlan then you need to set the vlan also on the router in most cases.
There is no harm to set the vlan in the router.

/interface vlan
add interface=etherY name=vlan-WAN vlan-id=XXXXX
/ip dhcp client
add interface=vlan-WAN
by anav
Sun Jan 07, 2024 8:12 pm
Forum: Beginner Basics
Topic: Best way of 3 routers connection
Replies: 10
Views: 1722

Re: Best way of 3 routers connection

I have no time for guesses, this is not a circus but you sir are a clown............. If you need to work on your imagination, go read a book. :-)
by anav
Sun Jan 07, 2024 6:52 pm
Forum: Beginner Basics
Topic: Best way of 3 routers connection
Replies: 10
Views: 1722

Re: Best way of 3 routers connection

Maybe?, dont you even know what you have???
In any case, no need for TPLINK router at all
by anav
Sun Jan 07, 2024 6:51 pm
Forum: General
Topic: Setting VLAN ID on modem or on router
Replies: 7
Views: 1426

Re: Setting VLAN ID on modem or on router

No need for vlan if the router gets a public IP and everything works in bridge mode.
If it does not then set vlan on modem and set vlan on router.
by anav
Sun Jan 07, 2024 5:56 pm
Forum: General
Topic: Under DNS Amplification attack, network unusable with Mikrotik routers
Replies: 12
Views: 2433

Re: Under DNS Amplification attack, network unusable with Mikrotik routers

BUT... I'd really recommend just start again with a new config... I personally think the default firewall is very well-calibrated (e.g. generally modifying the interface-list to add an WANs should be needed for 99% of CPE use cases). Disagree, not just a new config, NETINSTALL first , then new conf...
by anav
Sun Jan 07, 2024 5:54 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7040

Re: Wireguard guru needed [SOLVED]

I cant wait for holvoe to provide the necessary information!!!
by anav
Sun Jan 07, 2024 5:43 pm
Forum: Beginner Basics
Topic: Best way of 3 routers connection
Replies: 10
Views: 1722

Re: Best way of 3 routers connection

First, this is not a TPLINK forum and second, there is no such model TP link er650. There is however a wifi-extender (NOT A ROUTER) called the TP link RE650. This can be connected by ethernet to one of your routers to act as an access point. However its a dumb access point that cannot read vlans. At...
by anav
Sun Jan 07, 2024 5:26 pm
Forum: Beginner Basics
Topic: Wireguard setup with Router behind ISP Modem [SOLVED]
Replies: 4
Views: 1954

Re: Wireguard setup with Router behind ISP Modem [SOLVED]

Awesome, glad its working for you now.
by anav
Sun Jan 07, 2024 5:24 pm
Forum: General
Topic: MT to Pfsense Wireguard newbie needs help
Replies: 13
Views: 2384

Re: MT to Pfsense Wireguard newbie needs help

Nothing broken in Wireguard, simply MT has added in additional setting for BTH Wireguard and it can get a tad confusing is all.
by anav
Sun Jan 07, 2024 5:20 pm
Forum: General
Topic: Under DNS Amplification attack, network unusable with Mikrotik routers
Replies: 12
Views: 2433

Re: Under DNS Amplification attack, network unusable with Mikrotik routers

Lastly, and again sharing Anav's point of view leaving an open resolver is not best practice, and in all cases, not something any client should pay a consultant/service provider for. Find out who was responsible for those configs if provided by your company and if they are not gone, they should be ...
by anav
Sun Jan 07, 2024 5:17 pm
Forum: General
Topic: Under DNS Amplification attack, network unusable with Mikrotik routers
Replies: 12
Views: 2433

Re: Under DNS Amplification attack, network unusable with Mikrotik routers

A default config should not slow the performance. As intimated, its probably residual blocking going on from leaving DNS open...... Note here how DNS is allowed ONLY from the LAN, and in fact is the only thing LAN users should have access to on the router itself and perhaps NTP (for certain devices)...
by anav
Sun Jan 07, 2024 1:56 am
Forum: Beginner Basics
Topic: wireguard not open all websites
Replies: 1
Views: 1088

Re: wireguard not open all websites

That's nice. Now how do you expect us to help with practically no useful information.
What are you connecting to for example, third party VPN service???

Need config
/export file=anynameyouwish ( minus router serial number, public WANIP information, keys etc.)
by anav
Sun Jan 07, 2024 1:50 am
Forum: Beginner Basics
Topic: Wireguard setup with Router behind ISP Modem [SOLVED]
Replies: 4
Views: 1954

Re: Wireguard setup with Router behind ISP Modem [SOLVED]

Okay, your diagram ONLY shows you getting a private IP from the ISP modem/router. Is there another diagram showing you getting a public IP from the ISP modem if so show that instead with fake numbers for example on the diagram. THe LANs will stay the same behind the MT. OR, can you on the ISP modem/...
by anav
Sun Jan 07, 2024 1:35 am
Forum: General
Topic: Under DNS Amplification attack, network unusable with Mikrotik routers
Replies: 12
Views: 2433

Re: Under DNS Amplification attack, network unusable with Mikrotik routers

Sounds like YOU are the problem! :-) Lets look at the config. 1. Why do you slovenia telekom as your DNS server. If you want ISP provider DNS you can set that in the IP DCHP settings or pppoe settings for example (dial out). Most folks use something like 1.1.1.1 or 8.8.8.8 for external servers.........
by anav
Sun Jan 07, 2024 1:24 am
Forum: General
Topic: Recommended for IPS/IDS
Replies: 6
Views: 3140

Re: Recommended for IPS/IDS

Different vendor.............. You will pay through the nose for a higher end device that can still provide the throughput required with IDS services applied and by the way those IDS... DPI services are not native to the router, you then additionally have to buy subscription services to activate them.
by anav
Sun Jan 07, 2024 1:22 am
Forum: General
Topic: how to block bridged packet routed through firewall
Replies: 8
Views: 2001

Re: how to block bridged packet routed through firewall

Sorry your requirement makes no sense. Dont care about what you want to try on the config...... illogical What are the traffic requirements from the user perspective? What equipment do you have and what is the network design.....? ROUTER to MT acting as a switch?? OR ROUTER to MT acting as a ROUTER?...
by anav
Sun Jan 07, 2024 1:18 am
Forum: General
Topic: No traffic between VLANs regardless of firewall
Replies: 7
Views: 1365

Re: No traffic between VLANs regardless of firewall

Classic error of trying to keep the bridge doing DHCP. If you need another subnet take the one you kept on the bridge and make it vlan10.... or something.
Many other errors as well.
Suggest you read....
viewtopic.php?t=143620
by anav
Sat Jan 06, 2024 9:47 pm
Forum: General
Topic: Can't access device on management VLAN remotely via Wireguard
Replies: 12
Views: 3326

Re: Can't access device on management VLAN remotely via Wireguard

Trust me, when attemtping to diagnose errors on my own config and a million other peoples config, its much easier to spot firewall errors when chains are grouped together. Of course, it doenst matter which chain is in which order, but it does matter within a chain the order. Ordering the chains them...
by anav
Sat Jan 06, 2024 8:45 pm
Forum: Forwarding Protocols
Topic: OSPF across Wireguard using ptp, not nbma? [SOLVED]
Replies: 7
Views: 2503

Re: OSPF across Wireguard using ptp, not nbma? [SOLVED]

Wojo........... If you are familiar with OSPF Looking to do something for failovers. Imagine 2 WAN inputs to MT router............. and a CHR on a VPS in the cloud. What I want to do is connect the two WANS via wireguard and L2TP (plain -->best way to handle packet fragmentation), [from MT router to...
by anav
Sat Jan 06, 2024 2:50 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7040

Re: Wireguard guru needed [SOLVED]

Well I have mine listed but that is because they are on the same network and same subnet for IP address.
ROMON is s tool that allows that sort of thing I think
by anav
Sat Jan 06, 2024 2:47 pm
Forum: General
Topic: Port forward through P2P wireguard to internet
Replies: 5
Views: 1283

Re: Port forward through P2P wireguard to internet

Awesome, glad its worked out for you........ Ive done many dumb things when it comes to MT, and most due to my lack of understanding of basic networking.
by anav
Fri Jan 05, 2024 10:32 pm
Forum: General
Topic: wireguard client on LTE isp
Replies: 5
Views: 1255

Re: wireguard client on LTE isp

Then please post full config, there is something else on the config p erhaps.

/export file=anynameyouwish ( minus router serial number and any public WANIP information, keys etc.)
by anav
Fri Jan 05, 2024 10:27 pm
Forum: Beginner Basics
Topic: RouterOS v7.0.5 Dual PPPoE Wan Setup.
Replies: 34
Views: 16004

Re: RouterOS v7.0.5 Dual PPPoE Wan Setup.

Please post full config so I can see what is going on. please.
/export file=anynameyouwish ( minus router serial number and any public WANIP information )
by anav
Fri Jan 05, 2024 10:17 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7040

Re: Wireguard guru needed [SOLVED]

Wrong approach gig.......... You know better.
You dont plan and start the config without knowing all the requirments and attempt to totally change the requirements at the end.
Is all traffic working as expected.............
by anav
Fri Jan 05, 2024 10:15 pm
Forum: Beginner Basics
Topic: Routing a VLAN through Wireguard
Replies: 5
Views: 1668

Re: Routing a VLAN through Wireguard

Only a fool thinks firewall rules need not be considered in wireguard traffic. I wont even look at the config until its one bridge and all vlans (bridge does no dhcp).
viewtopic.php?t=143620
by anav
Fri Jan 05, 2024 10:14 pm
Forum: Beginner Basics
Topic: Home web address goes to router.
Replies: 2
Views: 1059

Re: Home web address goes to router.

It also sounds as you have not turned off all router services either......... post complete config
by anav
Fri Jan 05, 2024 10:05 pm
Forum: General
Topic: Port forward through P2P wireguard to internet
Replies: 5
Views: 1283

Re: Port forward through P2P wireguard to internet

Yes, I now can ignore everything in orange becauses its nonsensical. Between these two locations is Wireguard P2P tunnel it's on same ISP provider , so I use internal IP addresses and it not go through internet, only through ISP LAN network in same city ). Whether or not the two ISP connections are ...
by anav
Fri Jan 05, 2024 10:00 pm
Forum: General
Topic: Winbox management via Back to Home VPN
Replies: 2
Views: 1002

Re: Winbox management via Back to Home VPN

Very good question, I have been asking Normis for clarification on the BTH thread in Announcement to get at the heart of these matters.
Thus far, disappointing answers.
by anav
Fri Jan 05, 2024 9:59 pm
Forum: General
Topic: wireguard client on LTE isp
Replies: 5
Views: 1255

Re: wireguard client on LTE isp

I think the issue is the smartphone blocking, as none of the changes above would necessarily block anything.
by anav
Fri Jan 05, 2024 9:52 pm
Forum: General
Topic: wireguard client on LTE isp
Replies: 5
Views: 1255

Re: wireguard client on LTE isp

Really well done for the most part....... dst address needs to be gone, and needs to be enabled! Modify this /routing rule add action=lookup-only-in-table comment="MY SMARTPHONE TO WG VM16 DOCKER" disabled=yes dst-address=0.0.0.0/0 \ src-address=10.2.1.197/32 table=_wg_vm16_docker TO /rout...
by anav
Fri Jan 05, 2024 9:48 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3474

Re: Wireguard Peers can't access IPs on VLANs

NOT correct, for example this are bogus nonsensical entries for bridge ports. add bridge=onebr interface=vlan200 add bridge=onebr interface=vlan800 add bridge=onebr interface=vlan900 Vlan200 is NOT a LAN member has nothing to do with local hex.......... Similarly client-list is not a WAN, its was a ...
by anav
Fri Jan 05, 2024 5:56 pm
Forum: General
Topic: Simple Web Server to Host Simple Files [SOLVED]
Replies: 15
Views: 4628

Re: Simple Web Server to Host Simple Files [SOLVED]

What I would do is create a Wireguard tunnel between the VPS and the mikrotik router. The server and files would be hosted on the Mikrotik Router. On the CHR I would port forward inquiries coming in externally from USers or in this case just the admin, to the VPS public IP or domain name/url etc.......
by anav
Fri Jan 05, 2024 5:19 pm
Forum: General
Topic: Port forward through P2P wireguard to internet
Replies: 5
Views: 1283

Re: Port forward through P2P wireguard to internet

I am sorry, do not understand the architecture?
I have two connections locally to the same ISP, but each connection gets a different public WANIIP from the provider. Two different accounts.
I connect them via Wireguard as well.
What you describe does not computer for me, so unable to help.
by anav
Fri Jan 05, 2024 5:16 pm
Forum: General
Topic: Simple hairpin not working
Replies: 17
Views: 1757

Re: Simple hairpin not working

Well stated vinfgjfg!! ( all that info was on the link provided, not sure how mangling got into the mix either ) The only issue is your last sentence has a typo...... Lastly, You may opt to isolate the router on its own subnet. In that case, only the dstnat is needed as you are no longer doing a hai...
by anav
Fri Jan 05, 2024 5:11 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 298
Views: 238917

Re: NEW FEATURE: Back to Home VPN

> Next post intimates that it doesnt work with different Winbox Ports?? only the BTH app (!) needs the default port. To set it up. We might fix that, but then again, if you have custom ports and whatnot, might as well just use winbox > how to setup the Mikrotik manually, when using your relay point...
by anav
Fri Jan 05, 2024 12:31 am
Forum: Beginner Basics
Topic: Port forwarding through Proton VPN?
Replies: 10
Views: 2106

Re: Port forwarding through Proton VPN?

Wish I had more info for you on BTH, but normands was on vacation today and didnt answer my BTH questions LOL.
by anav
Thu Jan 04, 2024 11:25 pm
Forum: Beginner Basics
Topic: RouterOS v7.0.5 Dual PPPoE Wan Setup.
Replies: 34
Views: 16004

Re: RouterOS v7.0.5 Dual PPPoE Wan Setup.

Yup, they were not required if doing recursive on the main routing table.
As stated full config, no more part configs..........
by anav
Thu Jan 04, 2024 6:14 pm
Forum: Beginner Basics
Topic: Problem NAT Server, Client's Public IP Not Show in log [SOLVED]
Replies: 4
Views: 1690

Re: Problem NAT Server, Client's Public IP Not Show in log [SOLVED]

Yeah, if you have a fixed/static WANIP, then you need to delete that first rule, its getting in the way. The fourth rule below is just a duplicate of the second rule, and should be removed as well. You should only need two rules. Question: Is there a reason on the SOURCENAT RULE, why you feel the ne...
by anav
Thu Jan 04, 2024 5:52 pm
Forum: Beginner Basics
Topic: RB5009 right choice? [SOLVED]
Replies: 1
Views: 1627

Re: RB5009 right choice? [SOLVED]

My opinion is yes, you should be able to maximize your 2.5 gig throughput as its rated to approx 3gig with 25 IP filter rules.
It is a new ARM64 product so the support should be good for many years.
by anav
Thu Jan 04, 2024 5:22 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 298
Views: 238917

Re: NEW FEATURE: Back to Home VPN

Yes, Normands, most interested in the manual setup. My question is regarding how to setup the Mikrotik manually, when using your, for want of better word, cloud touch relay point. Its not a full blown WG server, but a connection point that allows users to reach the MT regardless (no public IP and IS...
by anav
Thu Jan 04, 2024 5:13 pm
Forum: Beginner Basics
Topic: Port forwarding through Proton VPN?
Replies: 10
Views: 2106

Re: Port forwarding through Proton VPN?

You keep changing the story. Yes, it is common to use wireguard, as a safe method, for external originated traffic to reach a server or to config the router. PROTON VPN is not for this, its for traffic originated on the router heading outbound . Two different cases. You don't seem to grasp that exte...
by anav
Thu Jan 04, 2024 5:01 pm
Forum: Beginner Basics
Topic: Added Mikrotik to existing network. How to segregate/isolate?
Replies: 6
Views: 1802

Re: Added Mikrotik to existing network. How to segregate/isolate?

Just to be clear, the upstream router belongs to house owners and the hex belongs to you a tenant, and they dont have any wifi but would like to use your wifi?? Now yes you can setup your hex router as a router (double nat) and thus have your own subnets/vlans You can provide guest vlans that they c...
by anav
Thu Jan 04, 2024 4:23 pm
Forum: Virtualization
Topic: CHR image for ARM systems?
Replies: 11
Views: 5372

Re: CHR image for ARM systems?

What the hex is Ampere..... MT sold with a tazer ??

Assuming its like a new Cloud virtual computer or something not linux, not windows but something else VPS???
https://amperecomputing.com/

Is it software is it hardware.... seems rather vague to me.
by anav
Thu Jan 04, 2024 4:18 pm
Forum: Beginner Basics
Topic: Ping from wan
Replies: 4
Views: 1230

Re: Ping from wan

Yes ISPs can be ornery too, we have a bell fibre ISP that blocks ICMP ping as a normal function of their provided modem/routers and it cannot be changed by the home owner.
by anav
Thu Jan 04, 2024 4:15 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3474

Re: Wireguard Peers can't access IPs on VLANs

Just because things work for a limited test set, doesn't necessarily mean the config is correct LOL. MT can be misleading in that regard. The errors will bite you sooner or later. :-)
When you think you have a near finished final product post again.......
by anav
Thu Jan 04, 2024 1:28 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3474

Re: Wireguard Peers can't access IPs on VLANs

Not sure why you are continuing with off bridge setup?
You dont have enough ports ( with 5 on hex ), you need 1 for client on Main WIFI router subnet, 2 for 1790, 3,4 for switches and 5 from wifi router???

In terms of vlans, read this.
viewtopic.php?t=143620
by anav
Thu Jan 04, 2024 1:18 pm
Forum: Beginner Basics
Topic: RouterOS v7.0.5 Dual PPPoE Wan Setup.
Replies: 34
Views: 16004

Re: RouterOS v7.0.5 Dual PPPoE Wan Setup.

If its not working then I need to see full config as answering any more questions requires complete understanding.
/export file=anynameyouwish (minus router serial number, public wanip information, keys etc..)
by anav
Thu Jan 04, 2024 1:08 pm
Forum: General
Topic: Simple hairpin not working
Replies: 17
Views: 1757

Re: Simple hairpin not working

Rule in forward chain needs to be add chain=forward action=accept connection-nat-state=dstnat The old default rule can be deleted but you need to add two more rules. THis one above it....... add chain=forward action=accept in-interface-list=LAN out-interface-list=WAN comment="internet traffic&q...
by anav
Thu Jan 04, 2024 6:02 am
Forum: Beginner Basics
Topic: Added Mikrotik to existing network. How to segregate/isolate?
Replies: 6
Views: 1802

Re: Added Mikrotik to existing network. How to segregate/isolate?

Nobody likes chasing a moving story.
Right down all the requirements.

a. identify all the user(s)/device(s) and groups of users/devices
b. identify all the traffic flow they need.

Also, do you control the upstream router or does the ISP.aka and ISP modem router.
by anav
Thu Jan 04, 2024 4:35 am
Forum: General
Topic: 7.13 legacy devices - plans?
Replies: 9
Views: 1837

Re: 7.13 legacy devices - plans?

In Brazil you have a different plan LOL.
You have to plan for theft replacement. If it aint locked down and you are not paying the police, it gets disappeared.

But yes, typically at home, use it till its not fixable or no longer does the job required.
by anav
Thu Jan 04, 2024 3:24 am
Forum: General
Topic: Simple hairpin not working
Replies: 17
Views: 1757

Re: Simple hairpin not working

Its impossible to block or control DNS from an encrypted methodology to my knowledge.
In other words there are limits to what one can do with adguard/piehole/doh etc..... if the user is savvy enough.
by anav
Thu Jan 04, 2024 3:22 am
Forum: Beginner Basics
Topic: Separating networks
Replies: 3
Views: 1124

Re: Separating networks

So just internet COAX cable to ISP modem router and you get private IP from ISP modem router LAN.

Just plug one cable into your MIKROTIK ROUTER and then all users plugged into mikrotik router.
One bridge, create as many different vlans as you need to separate users, servers, iot equipment etc.
by anav
Thu Jan 04, 2024 3:20 am
Forum: Beginner Basics
Topic: Port forwarding issue [SOLVED]
Replies: 5
Views: 1669

Re: Port forwarding issue [SOLVED]

One bridge.
How every many vlans you need to have separate subnets.
One vlan for Servers, one vlan for trusted LAN users, one vlan for guests, one vlan for iot equipment etc...
by anav
Thu Jan 04, 2024 2:01 am
Forum: Beginner Basics
Topic: RouterOS v7.0.5 Dual PPPoE Wan Setup.
Replies: 34
Views: 16004

Re: RouterOS v7.0.5 Dual PPPoE Wan Setup.

Okay so you have a port forwarding requirement but no external traffic TO THE ROUTER ( aka no vpn services etc. no wireguard ). In which case you dont need the output chain set of rules But YOU ARE MISSING THE MARK ROUTES FOR THE RETURN due to PORT FOWARDING via PREROUTING!!!! A small note if you di...
by anav
Wed Jan 03, 2024 11:43 pm
Forum: Beginner Basics
Topic: Purchase recommendation
Replies: 13
Views: 1829

Re: Purchase recommendation

Concur, also because ARM products are more fully supported going forward.
by anav
Wed Jan 03, 2024 11:42 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7040

Re: Wireguard guru needed [SOLVED]

(7) NO. The purpose of the rule is to allow subnets from r1 coming in on wireguard ( in this case one subnet) to access r2 single subnet and of course the remote admin users. If you had multple subnets on r2, its doubtful that the local subnets/vlans would require access to each other at all, hence ...
by anav
Wed Jan 03, 2024 11:25 pm
Forum: Beginner Basics
Topic: Purchase recommendation
Replies: 13
Views: 1829

Re: Purchase recommendation

Hi Mozerd, how do you distinguish on a single computer, a different queue for gaming, and for NAS server access (file access), torrenting, streaming etc...............

Can you provide that fidelity or is it all, ONE IP, one queue applies ??
by anav
Wed Jan 03, 2024 11:23 pm
Forum: Beginner Basics
Topic: Beginning RouterOS 7 config- need help with enabling vlan filtering
Replies: 7
Views: 1509

Re: Beginning RouterOS 7 config- need help with enabling vlan filtering

To be clear, you have to communicate more accurately.
What device do you have,
Provide a network diagram.

It may very well be that you are talking about a switch not a router and I was giving advice thinking it was a router etc...........
by anav
Wed Jan 03, 2024 11:21 pm
Forum: General
Topic: 7.13 legacy devices - plans?
Replies: 9
Views: 1837

Re: 7.13 legacy devices - plans?

Don't you have this built into your obsolensce budget planning for 1,2,5,10,15 years down the line ;-) EVERY X years change TV (10) EVERY Y years change CAR (12 ish) EVERY Z years change IPHONE. (3 ish) EVERY A years change WIFI devices ( often coincides with IPHONE ) (3-5ish) EVERY B years change r...
by anav
Wed Jan 03, 2024 11:10 pm
Forum: General
Topic: Static route toward a list of networks [SOLVED]
Replies: 4
Views: 1738

Re: Static route toward a list of networks [SOLVED]

Hi there, The table is required because that is what we are creating, an independent new routing table, so that we can tell the router where to send traffic, separately from the Main Table. Mangling is a method of identifying traffic with some specificity, in order to apply routes as required. I hav...
by anav
Wed Jan 03, 2024 10:39 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3474

Re: Wireguard Peers can't access IPs on VLANs

Assuming I had it wrong all along and you need to pass the MAIN WIFI subnet to other devices behind the managed switches. I have modified the CHR script below. I also noted my handling of 1790 was not quite right, it needs to be defined as an interface, but no other place.... I also do not see the r...
by anav
Wed Jan 03, 2024 8:54 pm
Forum: General
Topic: Static route toward a list of networks [SOLVED]
Replies: 4
Views: 1738

Re: Static route toward a list of networks [SOLVED]

Correct. Each remote subnet must be a separate entry. The purpose is so that if local lan users need to reach remote subnets, the router knows where to send the local users!! The purpose is also so that remote users coming in to access local servers or use the local WAN, have their return traffic go...
by anav
Wed Jan 03, 2024 6:18 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3474

Re: Wireguard Peers can't access IPs on VLANs

To be clear are you trying the SAME configuration on both devices for testing purposes?? Yes, you may have errors if you relied on scripts as the config has changed significantly so the rest of the config will have to be modified as required. (1) Why do you still have the incorrect setting for wireg...
by anav
Wed Jan 03, 2024 4:20 pm
Forum: Beginner Basics
Topic: Purchase recommendation
Replies: 13
Views: 1829

Re: Purchase recommendation

MIKROTIK is not the answer either, that is if you are intent on content based control. MT does not have APPLICATION CONTROLS or deep packet inspection so it may not work for you. MT is a user based and by that I mean IP: based firewall router. So put users into vlans and subnets and then you can con...
by anav
Wed Jan 03, 2024 4:14 pm
Forum: Beginner Basics
Topic: RouterOS v7.0.5 Dual PPPoE Wan Setup.
Replies: 34
Views: 16004

Re: RouterOS v7.0.5 Dual PPPoE Wan Setup.

Post your config and I will have a look. Also an update to what I posted I was not entirely accurate. 1. The output chain rules ensure that external traffic TO THE ROUTER ( aka services like wireguard handshake ) that comes in WANX goes out WANX 2. One still needs prerouting chain rules to ensure th...
by anav
Wed Jan 03, 2024 2:41 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7040

Re: Wireguard guru needed [SOLVED]

R1 (1) Why did you use firewall address list=VPN, its not correct technically as you have one local address on the list which has nothing to do with wireguard, 192.168.100.92 The list is more accurately called Admin or Authorized. Confusing to call it VPN when its not. Yes it includes two wireguard...
by anav
Wed Jan 03, 2024 1:56 pm
Forum: Beginner Basics
Topic: Beginning RouterOS 7 config- need help with enabling vlan filtering
Replies: 7
Views: 1509

Re: Beginning RouterOS 7 config- need help with enabling vlan filtering

You can use code commands to encapsulate your config! ( black square with white square brackets on the same line as Bold Underline etc.......) Typically when first setting up bridge vlan filtering and later on if I screw something up on the bridge, I setup an off bridge access. Makes life much easie...
by anav
Wed Jan 03, 2024 1:53 pm
Forum: Beginner Basics
Topic: Separating networks
Replies: 3
Views: 1124

Re: Separating networks

ISP Device: Is it a modem/router or just router? Does it provide TV or telephone services or just internet?
by anav
Wed Jan 03, 2024 1:45 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3474

Re: Wireguard Peers can't access IPs on VLANs

I provided a much simpler, cleaner config, so cannot comment further.
by anav
Wed Jan 03, 2024 4:37 am
Forum: General
Topic: Force Users to Use Specific DNS Server
Replies: 31
Views: 21328

Re: Force Users to Use Specific DNS Server

Ah okay, I think of that as NAT RULE, as opposed to a MANGLE rule as opposed to filter rules (forward and input chain).
All other IP firewall. LOL.
by anav
Wed Jan 03, 2024 2:15 am
Forum: Beginner Basics
Topic: Port forwarding issue [SOLVED]
Replies: 5
Views: 1669

Re: Port forwarding issue [SOLVED]

As the article states. If you have USERS within the same SUBNET as the SERVER, and the users are not accessing the server by the server LAN IP address directly, but by the roundabout method of using the Domain Name/url/dyndns type name. then yes you need the hairpin nat rule. If you move the users o...
by anav
Wed Jan 03, 2024 2:14 am
Forum: General
Topic: Force Users to Use Specific DNS Server
Replies: 31
Views: 21328

Re: Force Users to Use Specific DNS Server

It is not clear what firewall rule you are talking about??
by anav
Tue Jan 02, 2024 11:04 pm
Forum: General
Topic: Force Users to Use Specific DNS Server
Replies: 31
Views: 21328

Re: Force Users to Use Specific DNS Server

Well will focus on DNS related rules........ In general the Device acting as DNS server has to have access to the internet to get DNS itself. EVEn a DOH servers needs some unencrypted DNS access to make the initial connection to an encrypted DOH server. So in general, one has to look at DNS servers ...
by anav
Tue Jan 02, 2024 10:51 pm
Forum: Beginner Basics
Topic: Port forwarding issue [SOLVED]
Replies: 5
Views: 1669

Re: Port forwarding issue [SOLVED]

by anav
Tue Jan 02, 2024 10:48 pm
Forum: Beginner Basics
Topic: CAPsMAN VLAN guest network - No connection
Replies: 4
Views: 1303

Re: CAPsMAN VLAN guest network - No connection

Well the only changes I see are in the forward chain are two rules. Difference in Green! FROM add action=accept chain=forward comment="allow internet traffic" \ in-interface-list=LAN out-interface-list=WAN add action=accept chain=forward comment="allow Smart Home access" \ dst-ad...
by anav
Tue Jan 02, 2024 10:33 pm
Forum: General
Topic: Simple WIreguard setup hints
Replies: 1
Views: 903

Re: Simple WIreguard setup hints

Three things. a. good to include diagram very helpful as we are not in your head. b. form follows function so a clear set of requirements will dictated a useful config. So need the following (i). identify users/groups of users including you as the admin (ii). identify the traffic they need to accomp...
by anav
Tue Jan 02, 2024 9:38 pm
Forum: General
Topic: DNS not resolving some domains
Replies: 23
Views: 2855

Re: DNS not resolving some domains

Hard to say as the OP thinks he knows better by not providing the evidence and information to make an accurate diagnosis.
by anav
Tue Jan 02, 2024 9:35 pm
Forum: General
Topic: Force Users to Use Specific DNS Server
Replies: 31
Views: 21328

Re: Force Users to Use Specific DNS Server

Caution that I have seen RECENTLY folks using these rules and not putting a SOURCE part of the rule. (in interface lan) IF you dont then anyone on the internet will start using your pi server!! I note the original link at the top of the thread showed this dangerous config and its from an old no long...
by anav
Tue Jan 02, 2024 9:30 pm
Forum: General
Topic: Force Users to Use Specific DNS Server
Replies: 31
Views: 21328

Re: Force Users to Use Specific DNS Server

Negative, to ports is implied to be the same as dstports if not entered. To-Ports is this really used when doing port translation. What is important is such sweeping rules in-interface-list=LAN is to ensure you exclude the pI LAN address or any other subnets not being subjegated to PI. /ip nat add a...
by anav
Tue Jan 02, 2024 9:26 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3474

Re: Wireguard Peers can't access IPs on VLANs

Which configuration, the OPs? If you look at the suggested config, all traffic from 800 and 900 vlans AND WIREGUARD, go through the WAN side of the router aka via ether5 and since there is a masquerade rule. all such traffic is already natted and gets a source IP of 192.168.2.2. That problem no long...
by anav
Tue Jan 02, 2024 9:20 pm
Forum: Beginner Basics
Topic: Port forwarding through Proton VPN?
Replies: 10
Views: 2106

Re: Port forwarding through Proton VPN?

YES it can, just not through PROTON. You could host a CHR on VPS for example ( cloud server ) or linux OS etc............. (1) All users would go directly to the public IP of the CHR vice your public IP to connect to a server. (2) The CHR would then port forward that traffic INTO a wireguard TUNNEL ...
by anav
Tue Jan 02, 2024 9:13 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7040

Re: Wireguard guru needed [SOLVED]

In R1 the config is clear. We only allow select users on wireguard to access the LAN side. We allow remote users to come in on wireguard to go back out wireguard ( does not allow anything else ). Thus we ensure control of what occurs by making clear rules. add action=accept chain=forward in-interfac...
by anav
Tue Jan 02, 2024 9:07 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7040

Re: Wireguard guru needed [SOLVED]

The painting company should be charged for $gas money and time for your to fix the situation at a minimum. The company will only make changes if it causes them to lose some of their profit.............. Sadly, pride and ethical behaviour not so much. The relay rule should be clearly stated.............
by anav
Tue Jan 02, 2024 8:42 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3474

Re: Wireguard Peers can't access IPs on VLANs

Suggest your review line by line to digest all changes. No mangling required, no vlan for WAN needed. Tried to keep it clean and simple. Access to the router is safely done via Ether1 using 192.168.55.5 set in laptop ipv4 settings etc..... Setup so that you can access the router when sitting on the ...
by anav
Tue Jan 02, 2024 7:25 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3474

Re: Wireguard Peers can't access IPs on VLANs

Okay so to recap and make sure on same page. 1. VDSL Modem/Wifi Router is where internet terminates. The modem gets the public IP. It provides a flat network of 192.168.2.0/24 where the modem router is the gateway 192.168.2.1 2. HEX is a second router with NAT, its WANIP for all intensive purposes i...
by anav
Tue Jan 02, 2024 3:47 pm
Forum: Beginner Basics
Topic: Loadbalancing issues
Replies: 3
Views: 1063

Re: Loadbalancing issues

You cannot do that with the MT router it does not bond two connections such that one session can use both connections at the same time.
There may be some software you put on a PC or something that does that for torrenting, but there is no such config on the router itself.
by anav
Tue Jan 02, 2024 3:11 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7040

Re: Wireguard guru needed [SOLVED]

Well there is physical security and access on-site, and there is stupidity. a. for disconnecting a piece of equipment and then on top not plugging it back in. Be it dishonest or stupid, the employee has to go. I note the evil attempt by the OP to confuse me by putting R2 prior to R1.............. ;-...
by anav
Tue Jan 02, 2024 3:03 pm
Forum: Beginner Basics
Topic: Port forwarding through Proton VPN?
Replies: 10
Views: 2106

Re: Port forwarding through Proton VPN?

Just so I understand you have a hapax3 that gets a public IP......... If so you dont need Proton VPN for incoming, you can use your own router with wireguard to let remote users access home assistant. Even if its not a public IP ( behind an ISP router ) if you can forward a port on the ISP modem/rou...
by anav
Tue Jan 02, 2024 1:21 am
Forum: General
Topic: DNS not resolving some domains
Replies: 23
Views: 2855

Re: DNS not resolving some domains

Observations (1) The vlan7 you assigned to combo1 is all very nice but where is it in your pppoe connection?? /interface pppoe-client add add-default-route=yes disabled=no interface=combo1 max-mru=1400 max-mtu=1480 name=Telekom-DSL profile=telekom user= If indeed the ISP is providing pppoe over vlan...
by anav
Tue Jan 02, 2024 1:04 am
Forum: Beginner Basics
Topic: Set VLAN in eth ports
Replies: 4
Views: 1023

Re: Set VLAN in eth ports

(1) You have two rules and the second one is redundant on input chain. add action=accept chain=input comment="Allow VLAN" in-interface-list=VLAN { allows all VLANS full access to the ROUTER } add action=accept chain=input comment="Allow main VLAN Full Access" \ { allows main VLAN...
by anav
Tue Jan 02, 2024 12:47 am
Forum: Beginner Basics
Topic: CAP AC: Stripping MAC Addresses impacting DHCP
Replies: 12
Views: 2140

Re: CAP AC: DHCP assigned DNS

Do not understand about DHCP requests........... The Cap is not acting as a router solely as an AP switch and has no Firewall rules, no DHCP functionality...... or anything...... Since you use pi for DNS, assuming that you direct your users to PI already so why did you deviate on the setup provided?...
by anav
Tue Jan 02, 2024 12:32 am
Forum: Beginner Basics
Topic: openvpn connection [SOLVED]
Replies: 5
Views: 1181

Re: openvpn connection [SOLVED]

The only thing I can recommend is a newer model ( AKA newer ARM product )
hapax3, first choice hapax2 second choice, and then you can RUN wireguard via BTH and will be able to remotely connect to your network from anywhere.
by anav
Tue Jan 02, 2024 12:31 am
Forum: Beginner Basics
Topic: DHCP server not working on every device + port forwarding
Replies: 4
Views: 1058

Re: DHCP server not working on every device + port forwarding

PLEASE CONFIRM ASAP that you get a private IP address from the ISPs device. If you get a public IP then you need to unplug your router immediately and perhaps netinstall it because you HAVE NO protection because you have NO firewall rules at all. All traffic is permitted. Which means hackers have f...
by anav
Tue Jan 02, 2024 12:17 am
Forum: General
Topic: DNS not resolving some domains
Replies: 23
Views: 2855

Re: DNS not resolving some domains

If your MT device is setup properly, why are you here? Try a debian forum! If you want help then provide the config and we can decide, based on EVIDENCE not opinion, that there is nothing amiss on your config. /export file=anynameyouwish ( minus router serial number, public WANIP information, keys, ...
by anav
Mon Jan 01, 2024 11:11 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2216

Re: Inter-VLAN routing (unable to reach clients from VLAN)

Blocking ping on wan side seems pointless............ its actually useful and not a security risk.
by anav
Mon Jan 01, 2024 10:54 pm
Forum: Beginner Basics
Topic: HW-accelerated routing & firewall
Replies: 2
Views: 880

Re: HW-accelerated routing & firewall

I think your mixing up form and function. The MT Device is a switch and you clearly stated you have an upstream firewall that takes care of firewall rules etc. so not sure what the issue is?? Its a switch so Wire Speed should be a given. Security wise are you asking what additional security function...
by anav
Mon Jan 01, 2024 10:52 pm
Forum: General
Topic: route marking with two ISPs and PCC with wireguard
Replies: 6
Views: 1526

Re: route marking with two ISPs and PCC with wireguard

(1) The advice is to have a separate VLAN for users and a separate VLAN for managment if you need it. The concept of a management vlan is mostly so that all smart devices on the network are configured and reachable on this network that nobody else has access too. If you have a trusted subnet then yo...
by anav
Mon Jan 01, 2024 9:41 pm
Forum: Beginner Basics
Topic: openvpn connection [SOLVED]
Replies: 5
Views: 1181

Re: openvpn connection [SOLVED]

Mikrotik model?
by anav
Mon Jan 01, 2024 9:09 pm
Forum: Beginner Basics
Topic: openvpn connection [SOLVED]
Replies: 5
Views: 1181

Re: openvpn connection [SOLVED]

It would appear you dont have a public IP directly its handled by the modem/router and not passed to your router.
Can you access the ISP modem/router and forward ports to the MT router?
Which MT device do you have?
by anav
Mon Jan 01, 2024 8:51 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 298
Views: 238917

Re: NEW FEATURE: Back to Home VPN

when?? using back to home wireguard, regular wireguard, something else......... again no context, we are not inside your head nor have any inkling of what network we are looking at etc...
by anav
Mon Jan 01, 2024 8:35 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2216

Re: Inter-VLAN routing (unable to reach clients from VLAN)

SURE YOU DID YOU ADDED THIS RULE AND ITS STILL THERE> add action=drop chain=forward comment="drop Everything else in VLAN" \ in-interface-list=VLAN /ip firewall filter add action=accept chain=input comment=\ "defconf: accept established,related,untracked" connection-state=\ estab...
by anav
Mon Jan 01, 2024 8:32 pm
Forum: General
Topic: Model to use for site to site vpn ddns
Replies: 3
Views: 1636

Re: Model to use for site to site vpn ddns

@OP When you say static IP in the US, do you mean you get a public fixed IP, or fixed private IP ( like 192.168.1.X ) @Hey noob, what drugs are you on? The Hex is old and very under powered for the typical connections in US. Dont know about Mexico. The hex can be expected to get around 400-500Mbps o...
by anav
Mon Jan 01, 2024 8:09 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2216

Re: Inter-VLAN routing (unable to reach clients from VLAN)

(you dont need the vlan restricted list anymore by the way) The interface list VLAN-InternetAccess should not have quotes in your rule, remove them!! ( otherwise the rule is good ) add action=accept chain=forward comment="allow Internet access" \ connection-type="" in-interface-l...
by anav
Mon Jan 01, 2024 7:33 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2216

Re: Inter-VLAN routing (unable to reach clients from VLAN)

Seems okay, you keep screwing up the order of rules though..... (1) /ip firewall filter add action=accept chain=input comment=\ "defconf: accept established,related,untracked" connection-state=\ established,related,untracked ----> move up, and put the invalid rule, the icmp rule and the lo...
by anav
Mon Jan 01, 2024 7:18 pm
Forum: Beginner Basics
Topic: Port forwarding through Proton VPN?
Replies: 10
Views: 2106

Re: Port forwarding through Proton VPN?

NAT PMP, is nothing to do with MT. So lets get the facts. You have a third party VPN connecting your router (as a client ) to the PROTON wireguard server. Typically this is NOT for incoming originated requests, this is designed for sending some subnets or all subnets out the proton site for internet...
by anav
Mon Jan 01, 2024 6:59 pm
Forum: Beginner Basics
Topic: Force the router to use a specific WAN
Replies: 5
Views: 1076

Re: Force the router to use a specific WAN

Yes but that has nothing to do with mangling or whatever. Connect ISP1s modem or modem router to ether1 for example. Then if its pppoe connection assign the parameters in the PPP menu. IF its a ISP assigned dhcp scenario, add the parameters in IP DHCP. IF its a Static Public IP assigned, you can do ...
by anav
Mon Jan 01, 2024 6:53 pm
Forum: Beginner Basics
Topic: CAPsMAN VLAN guest network - No connection
Replies: 4
Views: 1303

Re: CAPsMAN VLAN guest network - No connection

Well I am not sure you handled vlans correctly, and in fact, once you start using vlans I recommend you turn the bridge affiliated subnet INTO a vlan and then your errors with the other vlans will become clearer. My sense is that is the root of your problems not the firewall. Suggest you read this t...
by anav
Mon Jan 01, 2024 6:34 pm
Forum: Beginner Basics
Topic: Set VLAN in eth ports
Replies: 4
Views: 1023

Re: Set VLAN in eth ports

(1) This open ended nonsense sourcenat rule is from the default rules........ ?? /ip firewall nat add action=masquerade chain=srcnat add action=masquerade chain=srcnat comment="defconf: masquerade" \ ipsec-policy=out,none out-interface-list=WAN (2) No idea what you are doing with these see...
by anav
Mon Jan 01, 2024 6:29 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 298
Views: 238917

Re: NEW FEATURE: Back to Home VPN

Is it possible to connect multiple Wireguard peers with Mikrotik at the same time? And use it for VPN service in an Organization instead of L2TP or SSTP? Have you used wireguard? Its not an enterprise solution where 1000s of employees need to VPN into work............ However yes, one can have many...
by anav
Mon Jan 01, 2024 6:21 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 298
Views: 238917

Re: NEW FEATURE: Back to Home VPN

Did somebody else noticed ping increase and drop in speed ?
Your post has no context. Do you mean if you are drinking a cup of coffee while running on the treadmill??
by anav
Mon Jan 01, 2024 6:15 pm
Forum: Beginner Basics
Topic: New user in new property existing equipment
Replies: 4
Views: 1067

Re: New user in new property existing equipment

I am not familiar with LTE products, dont worry many are. If you have two internet connections, LTE and skydish direct? Then you have two main possibilities. a. USE BOTH at the same time and provide the full available bandwidth b. USE ONE as a PRIMARY, and the other as SECONDARY (backup), so that if...
by anav
Mon Jan 01, 2024 6:08 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2216

Re: Inter-VLAN routing (unable to reach clients from VLAN)

Pinging gateway IPs, is reaching the router as they are local interfaces, does not mean you can actually reach users..... Lets look at the config......... (1) INPUT CHAIN, clearly you want reasonable security and thus I am assuming you want limited access to those that config the router. Hence allow...
by anav
Mon Jan 01, 2024 5:12 pm
Forum: Useful user articles
Topic: secondary router blocking issue from isp.
Replies: 1
Views: 1050

Re: secondary router blocking issue from isp.

First, this is a USEFUL ARTICLES FORUM.
You should post your question in Beginner Forum or GENERAL FORUM.
So please open a new thread there and close this one and when you do, please post a network diagram as what you have stated is NOT clear.
by anav
Mon Jan 01, 2024 5:01 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3474

Re: Wireguard Peers can't access IPs on VLANs

Perhaps I was imagining it because the first times I opened it the router stated was a 5009. When I do it today its now on the HEX> Looking at your diagram, can you confirm you use three different ether ports on the WIFI Router to connect three different vlans to three ports on the HEX??? What I was...
by anav
Mon Jan 01, 2024 7:45 am
Forum: Beginner Basics
Topic: Force the router to use a specific WAN
Replies: 5
Views: 1076

Re: Force the router to use a specific WAN

The requirement is not clear. The router provides services such as wireguard server for handshake, and there are ways to ensure that if traffic coming on WANX for that purpose goes out WANX. Its not clear to me thats what you mean?? It is rare to see input chain in mangling as that is traffic to the...
by anav
Mon Jan 01, 2024 3:51 am
Forum: Beginner Basics
Topic: Router is blocking outgoing web traffic [SOLVED]
Replies: 6
Views: 1028

Re: Router is blocking outgoing web traffic [SOLVED]

The default rules from MT already add such a rule in the forward chain.
I agree 100% that its common and thus why I suggested that Mikrotik add Zerotrust cloudflare tunnel as an options package for all devices. :-)
by anav
Sun Dec 31, 2023 8:45 pm
Forum: Beginner Basics
Topic: Basic CAPsMAN configuration with multiple VLANS
Replies: 6
Views: 906

Re: Basic CAPsMAN configuration with multiple VLANS

Really, so no datpaths and vlans in capsman, they took it out, how nice!! About time to remove vlans from wifi configs.........
by anav
Sun Dec 31, 2023 7:44 pm
Forum: Scripting
Topic: DynDNS Script from Mikrotik Wiki (correction)
Replies: 29
Views: 31019

Re: DynDNS Script from Mikrotik Wiki (correction)

Kitty has claws, do not mess with it, even with only one eye open you will get hurt, thinking your script knowledge is somehow better, such a comedian. You do know that cat is just Yoda in disguise.
by anav
Sun Dec 31, 2023 7:41 pm
Forum: General
Topic: Selection of Mikrotik hardware for PPPoE/Hotspot ISP
Replies: 3
Views: 603

Re: Selection of Mikrotik hardware for PPPoE/Hotspot ISP

The 5009 should have no issues handling this throughput.
by anav
Sun Dec 31, 2023 7:39 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7040

Re: Wireguard guru needed [SOLVED]

Just because your willing to sell your soul to cloudflare, some of use prefer not relying upon third party providers. :-P However, if port forwarding is in the mix, then cloudflare is a viable compromise, and for this case, it should be available on all MT devices, as a package, not hidden in contai...
by anav
Sun Dec 31, 2023 7:38 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2216

Re: Inter-VLAN routing (unable to reach clients from VLAN)

All good, now we both know we are not going insane :-) ( in my case more insane )
by anav
Sun Dec 31, 2023 7:36 pm
Forum: Beginner Basics
Topic: still same problem and same issue please help!
Replies: 8
Views: 2481

Re: still same problem and same issue please help!

L2TP windows client does not connect to wireguard, suggest you have to connect to an L2TP server.............. '=P As noted, your config is likely wrong and the fact that you havent posted a.. your complete config b. network diagrams Is completely absurd as this is not your fist post. You know very ...
by anav
Sun Dec 31, 2023 7:34 pm
Forum: Beginner Basics
Topic: Basic CAPsMAN configuration with multiple VLANS
Replies: 6
Views: 906

Re: Basic CAPsMAN configuration with multiple VLANS

Holvoe, that link is TOTALLY USELESS for those wanting to setup capsman and datapaths and VLANS.

Either make one (user article -as I have requested numerous times or stop suggesting something that doesnt fit.......
by anav
Sun Dec 31, 2023 7:31 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3474

Re: Wireguard Peers can't access IPs on VLANs

As pointed out you supplied a config for an RB5009. You have not stated where this router fits. You have not provided a hex config. Explain more how the upstream router works.......... does it provide an IP address on a private local subnet to the hex. You mention, NATing, please expound. A network ...
by anav
Sun Dec 31, 2023 7:28 pm
Forum: General
Topic: Selection of Mikrotik hardware for PPPoE/Hotspot ISP
Replies: 3
Views: 603

Re: Selection of Mikrotik hardware for PPPoE/Hotspot ISP

Too many unanswered details.
What is the throughput of each WAN.
Are the ISPs for all six different?

How many users are anticipated.
What kind of traffic will they be using,.......

Network diagram to show what happens after RB5009, switches APs etc.....
by anav
Sun Dec 31, 2023 5:17 pm
Forum: General
Topic: Reverse SSH port tuneling
Replies: 5
Views: 845

Re: Reverse SSH port tuneling

I would look at wireguard as the way to go.
One could have all devices on the same wireguard subnet easily reachable from the office or if away remotely.
by anav
Sun Dec 31, 2023 5:09 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7040

Re: Wireguard guru needed [SOLVED]

R2 that I posted is the last config on R2 because after that i lost connection :lol:
Too funny. By the way since its dirt easy to establish an SSTP connection between two MT routers, I always do one as a backup to WG.
by anav
Sun Dec 31, 2023 5:08 pm
Forum: Beginner Basics
Topic: Router is blocking outgoing web traffic [SOLVED]
Replies: 6
Views: 1028

Re: Router is blocking outgoing web traffic [SOLVED]

without evidence, its all opinion.

/export file=anynameyouwish ( minus router serial number, any public WANIP information )
by anav
Sun Dec 31, 2023 5:03 pm
Forum: Beginner Basics
Topic: WiFi client isolation with VLANs and remote gateway
Replies: 3
Views: 932

Re: WiFi client isolation with VLANs and remote gateway

Dont use vlan1 to pass data, its gets confusing especially as you are mixing devices. The MT uses it in the background.. If you are using vlans then go all vlans. If the HAPAC is simply acting as an AP/Switch the below works............ Hence a TRUNK Port carrying all vlans from pfsense to MT. The M...
by anav
Sun Dec 31, 2023 5:00 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2216

Re: Inter-VLAN routing (unable to reach clients from VLAN)

Hence why I asked if you had actually tried to reach a device, not just pinging............ ( in post #10 )
by anav
Sun Dec 31, 2023 4:54 pm
Forum: Beginner Basics
Topic: Terrible wifi speed - L009UiGS-2HaxD-IN - Wifi 6 (Router OS 7.13) [SOLVED]
Replies: 28
Views: 5356

Re: Terrible wifi speed - L009UiGS-2HaxD-IN - Wifi 6 (Router OS 7.13) [SOLVED]

holvoe, you missed the memo, he is using the same device with two separate access points, one gets him very good speeds and the L0009 crap. Suspect the testing device is not the issue but who knows......... @haha Did the OP try the 20/40 setting?? @haha DISABLE THIS RULE AND SEE if there is a differ...
by anav
Sun Dec 31, 2023 4:39 pm
Forum: General
Topic: Can't access device on management VLAN remotely via Wireguard
Replies: 12
Views: 3326

Re: Can't access device on management VLAN remotely via Wireguard

@Verylab 1. The client device has nothing to do with accepting an incoming handshake, the request to join wireguard comes from the client device and is outbound traffic. The router wireguard service is hosted on the Server device at the incoming handshake and thus needs the input chain rule TO the r...
by anav
Sun Dec 31, 2023 2:54 am
Forum: Beginner Basics
Topic: Terrible wifi speed - L009UiGS-2HaxD-IN - Wifi 6 (Router OS 7.13) [SOLVED]
Replies: 28
Views: 5356

Re: Terrible wifi speed - L009UiGS-2HaxD-IN - Wifi 6 (Router OS 7.13) [SOLVED]

In general marketing speeds are misleading, use the 1/3 rule. Basically they typically combine up and down so already one is at 50% and then there are losses due to propagation interference from other access points, walls electrical circuits etc.. So realistically would look at around 180 Mbps as a ...
by anav
Sat Dec 30, 2023 11:45 pm
Forum: Beginner Basics
Topic: CAP AC: Stripping MAC Addresses impacting DHCP
Replies: 12
Views: 2140

Re: CAP AC: DHCP assigned DNS

Ahh okay so your not using vlans........... and only want to send one flat subnet to the CAPAC ?? /interface bridge add ingress-filtering=no name=bridge /interface ethernet set [ find default-name=ether2 ] name=emergaccess /interface list add name= management /interface wireless AS REQUIRED assuming...
by anav
Sat Dec 30, 2023 11:42 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2216

Re: Inter-VLAN routing (unable to reach clients from VLAN)

Yes, I am all out of ideas, there is no logical reason I see that its not working. I would try two things myself personally first, grasping at silly straws....... a. change dns servers such that it looks like /ip dhcp-server network add address=10.0.10.0/24 dns-server= 10.0.10.1 gateway=10.0.10.1 ad...
by anav
Sat Dec 30, 2023 10:26 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2216

Re: Inter-VLAN routing (unable to reach clients from VLAN)

Yes admit all is the default. Other than that missing the issue. Did you try a reboot of the router after making those changes?? If after a reboot still no joy try adding this rule to the forward chain above the drop all rule. add chain=forward action=accept src-address=192.168.2.0/24 dst-address=10...
by anav
Sat Dec 30, 2023 10:05 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2216

Re: Inter-VLAN routing (unable to reach clients from VLAN)

1. Who told you to put only vlan tagged on the bridge settings............... mostly just need to enable vlan filtering only.??? Remove it!!! This is your issue. /interface bridge add frame-types=admit-only-vlan-tagged name=Main_Bridge protocol-mode=none \ vlan-filtering=yes 2. Personal preference I...
by anav
Sat Dec 30, 2023 9:26 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7040

Re: Wireguard guru needed [SOLVED]

I dont guess LOL< when I see two udpated configs, I can look at the evidence. :-)
by anav
Sat Dec 30, 2023 9:25 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2216

Re: Inter-VLAN routing (unable to reach clients from VLAN)

Your firewall rules seem fine and yes, the rule does exactly that. Remember we modify the default rule into three rules and thus change the concept of allow everything except wan to lan traffic without dst nat rules TO block everything and only allow traffic we specifically state is permitted aka la...
by anav
Sat Dec 30, 2023 9:20 pm
Forum: General
Topic: How can I protect my VPN network from attempted intrusion?
Replies: 9
Views: 1442

Re: How can I protect my VPN network from attempted intrusion?

CPU usage for no gain. Simply dont log it. Out of sight out of mind.
by anav
Sat Dec 30, 2023 9:17 pm
Forum: General
Topic: route marking with two ISPs and PCC with wireguard
Replies: 6
Views: 1526

Re: route marking with two ISPs and PCC with wireguard

Observations (1) DO NOT USE VLAN-ID=1. Its already used by the router in the background and should not be used to carry data, it can cause weird things down the line. Instead just switch that to VLAN-ID=99 for example because its actually called vlan99_BASE, why you assigned 1 is beyond me.............
by anav
Sat Dec 30, 2023 8:56 pm
Forum: General
Topic: Dual WAN PCC ok but no web browsing
Replies: 19
Views: 1680

Re: Dual WAN PCC ok but no web browsing

What you mean redundant via VRRP. What is the part you are concerned about?? You have a mickrotik device with two WAN sources. Either both are up, one is up or both are down. How is VRRP going to help you here?? A network diagram may clear up the mystery. Ahh. reread the first post, have two HEXES d...
by anav
Sat Dec 30, 2023 7:43 pm
Forum: General
Topic: route marking with two ISPs and PCC with wireguard
Replies: 6
Views: 1526

Re: route marking with two ISPs and PCC with wireguard

I will have a look and see what I can figure out................... The funny thing about MT, it can allow some traffic if the config is almost there, but eventually any errors will reach up and grab you by the nuts.........
by anav
Sat Dec 30, 2023 7:42 pm
Forum: General
Topic: Dual WAN PCC ok but no web browsing
Replies: 19
Views: 1680

Re: Dual WAN PCC ok but no web browsing

Hmm, not sure what you are doing,,,,, but whats wrong with 2 or three vlans for subnets, one bridge and then doing PCC as needed. As well the deviation from default firewall rules ( aka the mess and utter garbage) makes the overall situation far more complex than it needs to be. Can you state simply...
by anav
Sat Dec 30, 2023 3:52 pm
Forum: Wireless Networking
Topic: Microtik AP advice
Replies: 14
Views: 2375

Re: Microtik AP advice

Sweet performance!
by anav
Sat Dec 30, 2023 3:51 pm
Forum: Wireless Networking
Topic: VLAN Trunk over WiFi for SOHO networks - use EoIP or else?
Replies: 6
Views: 1860

Re: VLAN Trunk over WiFi for SOHO networks - use EoIP or else?

WHy not considering using WIFI ethernet also known as 60hz wifi. Basically creates a 1 gig connection between two points that acts like an ethernet cable and called wireless wire. You can put whatever you want at the other end, switch access point etc.... You can pass as many vlans as you like ........
by anav
Sat Dec 30, 2023 3:47 pm
Forum: Beginner Basics
Topic: Help with first home server
Replies: 2
Views: 656

Re: Help with first home server

This is a perfect case for BTH! In this case we will establish a VPN tunnel from the router to the BTH mikrotik relay server and then all remote users will have a pathway to reach the router. In this regard AT LEAST, you can access your router and LAN securely and get rid of the bogus access you hav...
by anav
Sat Dec 30, 2023 3:44 pm
Forum: Beginner Basics
Topic: hap ax^2 config
Replies: 24
Views: 2157

Re: hap ax^2 config

Just showing that nature is more powerful than technology.
Also note that If Turn around quickly enough I can light my own flatulence.
by anav
Sat Dec 30, 2023 3:39 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7040

Re: Wireguard guru needed [SOLVED]

As per my post, the best way to do this is add a list of static LOCAL IPs and wireguard IPs, ( including the off bridge IP ) into a SOURCE ADDRESS LIST. These are the only users allowed to the router. The LAN users get access to DNS services, the only ones they need.......... This rule you had 5 cha...
by anav
Sat Dec 30, 2023 3:30 pm
Forum: Beginner Basics
Topic: CAP AC: Stripping MAC Addresses impacting DHCP
Replies: 12
Views: 2140

Re: CAP AC: DHCP assigned DNS

This is how I setup my capac ( as an AP/switch) ( sorry no capsman ).
viewtopic.php?t=182276
by anav
Sat Dec 30, 2023 3:28 pm
Forum: Beginner Basics
Topic: Trouble with port forwarding through a Wireguard VPN [SOLVED]
Replies: 14
Views: 3093

Re: Trouble with port forwarding through a Wireguard VPN [SOLVED]

I trust you to apply an excellent config for a specific purpose. However, this is not the case, you have invented a requirement not requested, likely to never be requested and it only ends up confusing people trying to learn. The bottom line is the output chain rule is not needed here. For anybody r...
by anav
Sat Dec 30, 2023 3:20 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2216

Re: Inter-VLAN routing (unable to reach clients from VLAN)

THe easy way to do this is to modify the concept of the default firewall setup which is allow everything block a few things, to Block everything and allow only needed traffic. Hence this ( and in the right order ) : ( default rules to keep in the right order ) add action=fasttrack-connection chain=f...
by anav
Sat Dec 30, 2023 3:08 pm
Forum: Beginner Basics
Topic: hap ax^2 config
Replies: 24
Views: 2157

Re: hap ax^2 config

Maybe he doesn't trust a cat wielding a chainsaw.... '=P
by anav
Sat Dec 30, 2023 3:04 pm
Forum: General
Topic: Help Troubleshooting DualWAN configuration.rsc
Replies: 3
Views: 1353

Re: Help Troubleshooting DualWAN configuration.rsc

Good opportunity to stop trying to copy and start trying to learn! Print off the config and then start adding from winbox one config line at a time. You will quickly find out that you cannot enter certain settings unless others are already setup................. let the learning begin!! @holvoe, you...
by anav
Fri Dec 29, 2023 11:30 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7040

Re: Wireguard guru needed [SOLVED]

Yes, that is the rule removed that did you in. Since your kicking yourself, go back to post 7 to reread, ;-)
by anav
Fri Dec 29, 2023 11:29 pm
Forum: Beginner Basics
Topic: Trouble with port forwarding through a Wireguard VPN [SOLVED]
Replies: 14
Views: 3093

Re: Trouble with port forwarding through a Wireguard VPN [SOLVED]

Now your making up crap..... There is no need in this scenario, and no clear future need for the output chain in a future scenario from incoming Wireguard traffic from the other Device. If one was to have WG incoming to this router perhaps............ So instead of exiting gracefuly from this thread...
by anav
Fri Dec 29, 2023 11:25 pm
Forum: General
Topic: simple 3 isp dhcp clients with aggregation
Replies: 16
Views: 2646

Re: simple 3 isp dhcp clients with aggregation

Not familiar with other tools someone might use, I am strictly referring to the performance provided by the MT config.
If there is aggregation wrt to a single session, some other device/software is performing this not the MT.
by anav
Fri Dec 29, 2023 11:19 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3474

Re: Wireguard Peers can't access IPs on VLANs

The hex is basically acting as a switch. It does not need any addresses other than the trusted network and assuming this as vlan200 subnet Post config of hex /export file=anynameyouwish ( minus router serial number, any public WANIP information, keys etc..). Edit: See config now at bottom of your po...
by anav
Fri Dec 29, 2023 9:21 pm
Forum: General
Topic: How to block ip scanners
Replies: 3
Views: 904

Re: How to block ip scanners

/export file=anynameyouwish ( minus router serial number, and any public WANIP information )
by anav
Fri Dec 29, 2023 9:19 pm
Forum: General
Topic: simple 3 isp dhcp clients with aggregation
Replies: 16
Views: 2646

Re: simple 3 isp dhcp clients with aggregation

Nope the best you can hope for, on any one sessions, is the maximum throughput of the ISP the user is connected to. The total amount of bandwidth is greater to share. So instead of 50 users sharing 500Mbps of throughput, they are sharing 1Gbps throughput, so each user has more opportunity for a bigg...
by anav
Fri Dec 29, 2023 6:50 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7040

Re: Wireguard guru needed [SOLVED]

I am sure it will the first and LAST time LOL.
by anav
Fri Dec 29, 2023 6:03 pm
Forum: General
Topic: Reverse SSH port tuneling
Replies: 5
Views: 845

Re: Reverse SSH port tuneling

Sounds unnecessarily complex.
What is the requirement for you the admin or a user.........
In plain english without any protocol or config speak.........
by anav
Fri Dec 29, 2023 6:00 pm
Forum: Beginner Basics
Topic: Trouble with port forwarding through a Wireguard VPN [SOLVED]
Replies: 14
Views: 3093

Re: Trouble with port forwarding through a Wireguard VPN [SOLVED]

Disagree, the traffic being discussed is very specific, its outside user, port forwarded at VPS into the tunnel to servers on MT device. There is no user that will be coming into VPS on a public IP (not in tunnel) being directed to the MT config aka to the router itself. Magic mushrooms for xmas?? W...
by anav
Fri Dec 29, 2023 5:57 pm
Forum: Beginner Basics
Topic: Load balancing & failover with multiple WAN on MikroTik?
Replies: 2
Views: 650

Re: Load balancing & failover with multiple WAN on MikroTik?

Then post your complete config here. /export file=anynameyouwish ( minus router serial number, any public WANIP information, keys etc..). Ensure you discuss any port forwardings or VPNs in the mix. Any subnets not involved in PCC ( if any ). Other special traffic flows you need........... Did you pl...
by anav
Fri Dec 29, 2023 5:51 pm
Forum: Beginner Basics
Topic: hap ax^2 problem [SOLVED]
Replies: 6
Views: 1353

Re: hap ax^2 problem [SOLVED]

I'm shocked, MKX forgot to state after the advice, reset to deafaulst and THEN USE QUICKSET????
by anav
Fri Dec 29, 2023 5:49 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7040

Re: Wireguard guru needed [SOLVED]

So Holvoe, the config is correct and thus you can impart ROMON wisdom. Do pray tell while I show you how to actually review a config, what value does ROMON provide in this scenario...............I would like to know as I probably could use it too. Observations (1) There is no point in having ether5,...
by anav
Fri Dec 29, 2023 5:34 pm
Forum: Beginner Basics
Topic: hap ax^2 config
Replies: 24
Views: 2157

Re: hap ax^2 config

Ahh so MT configuration is your hobby, full time clown '=P
by anav
Fri Dec 29, 2023 5:32 pm
Forum: General
Topic: Wireguard tunnel unable to use inet on the other side of tunnel.... [SOLVED]
Replies: 5
Views: 1257

Re: Wireguard tunnel unable to use inet on the other side of tunnel.... [SOLVED]

Thank god for peer reviews in science, is all I can say....... In any case, now readers will know that your 'solution' is slightly flawed and an explanation is provided as to why and the correct config has been provided. Not about you or me, quite correct, its about others also looking for assistance.
by anav
Fri Dec 29, 2023 4:41 pm
Forum: Beginner Basics
Topic: hap ax^2 config
Replies: 24
Views: 2157

Re: hap ax^2 config

I knew you guys belonged to the same wifi masochist club!
Just waiting for the updated User article on how to setup vlans with new wifi and capsman......... ???
by anav
Fri Dec 29, 2023 4:17 pm
Forum: General
Topic: How to block ip scanners
Replies: 3
Views: 904

Re: How to block ip scanners

Not sure what you are doing, a poorly worded explanation is useless. A. provide a network diagram B. provide full config /export file=anynameyouwish ( minus router serial number, public WANIP information, etc.. ) C. Clearly state the requirements. - identify all users - identify traffic they need to...
by anav
Fri Dec 29, 2023 3:04 pm
Forum: General
Topic: Using WireGuard to connect to router from guest network using the same router
Replies: 2
Views: 790

Re: Using WireGuard to connect to router from guest network using the same router

Would have been easy to spot if you had provided the config.
/export file=anynameyouwish ( m inus router serial number, public WANIP information, keys etc..)

Glad you got it sorted!
by anav
Fri Dec 29, 2023 3:03 pm
Forum: General
Topic: Wireguard tunnel unable to use inet on the other side of tunnel.... [SOLVED]
Replies: 5
Views: 1257

Re: Wireguard tunnel unable to use inet on the other side of tunnel.... [SOLVED]

YOur configs are not complete and do not show firewall rules or interface list / members etc.. So cannot comment on the rest of the config. In your case, it would have been simpler not to mangle anything on RB -table add fib name=useWG -Ip route add dst-address=0.0.0.0/0 gateway=wireguard1 routing-t...
by anav
Fri Dec 29, 2023 2:56 pm
Forum: General
Topic: Wireguard tunnel unable to use inet on the other side of tunnel.... [SOLVED]
Replies: 5
Views: 1257

Re: Wireguard tunnel unable to use inet on the other side of tunnel.... [SOLVED]

Self solving is rather arrogant. Allowed IPs on Router A works but the moment you add any peers like remote users that need access RA or RB remotely, the error will show itself more clearly. In other words the Allowed IP settings on Router A ( the server ) would be better served as follows; peer RB ...
by anav
Fri Dec 29, 2023 12:01 am
Forum: General
Topic: Individual firewall and Node-RED port problem [SOLVED]
Replies: 17
Views: 1836

Re: Individual firewall and Node-RED port problem [SOLVED]

Unfortunately I cannot comment as I dont use or are familiar with vlans using datapaths and capsman.
I will say that bridge vlan filtering does not seem to be turned on, and I dont see any /interface bridge vlan settings.........
by anav
Thu Dec 28, 2023 11:42 pm
Forum: General
Topic: Policy based routing
Replies: 9
Views: 947

Re: Policy based routing

Sorry I dont see tunnel within a tunnel at all............ All the more reason for network diagram LOL Okay Can you confirm the source address coming on wireguard is not limited to. a. single wireguard source addresses ( like from individual WG users ) b. private subnets from another device connecte...
by anav
Thu Dec 28, 2023 11:36 pm
Forum: Beginner Basics
Topic: Trouble with port forwarding through a Wireguard VPN [SOLVED]
Replies: 14
Views: 3093

Re: Trouble with port forwarding through a Wireguard VPN [SOLVED]

add chain=output connection-mark=wg-conn action=mark-routing new-routing-mark=wg I was with you till you posted the output chain rule......... There is no traffic from the router itself we need to be concerned with ??? I came up with two other variations, for fun but they dont add much in this case...
by anav
Thu Dec 28, 2023 11:19 pm
Forum: Beginner Basics
Topic: Trouble with port forwarding through a Wireguard VPN [SOLVED]
Replies: 14
Views: 3093

Re: Trouble with port forwarding through a Wireguard VPN [SOLVED]

Without a network diagram Im a tad lost. Using linux at the VPS is of no help either............ He wants to see originating IP address at the VPS or at the MT device??? Thus port forwards the traffic from there with destination address to his servers which are actually at the MT. So he needs port f...
by anav
Thu Dec 28, 2023 10:27 pm
Forum: General
Topic: Policy based routing
Replies: 9
Views: 947

Re: Policy based routing

A network diagram would allow us to better see through the fog of your explanation and the missing pieces which should have been provided up front.
by anav
Thu Dec 28, 2023 9:28 pm
Forum: General
Topic: Policy based routing
Replies: 9
Views: 947

Re: Policy based routing

Not understanding the additional complexity. a. need route back into tunnel created automatically on MT router by the use of the ip address of the wireguard on the router creates a DAC route. Thus any incoming traffic from a source with wireguard IP, already has a route back........ b. Need a firewa...
by anav
Thu Dec 28, 2023 6:30 pm
Forum: Beginner Basics
Topic: Trouble with port forwarding through a Wireguard VPN [SOLVED]
Replies: 14
Views: 3093

Re: Trouble with port forwarding through a Wireguard VPN [SOLVED]

Again, do you mean port forwarding done at the VPS or done once the traffic arrives at the MT.

I guess i dont get why doesnt the client go through WG and straight to the device in question???
The old firewall forward chain :-)
by anav
Thu Dec 28, 2023 6:28 pm
Forum: Beginner Basics
Topic: hEX PoE lite default + vlan
Replies: 12
Views: 3183

Re: hEX PoE lite default + vlan

The solution that I would advise is the following: /interface bridge port add bridge=bridge interface=ether2 pvid=10 add bridge=bridge interface=ether3 pvid=10 add bridge=bridge interface=ether4 pvid=10 add bridge=bridge interface=ether5 pvid=10 /interface bridge vlan add bridge=bridge tagged=bridge...
by anav
Thu Dec 28, 2023 6:20 pm
Forum: General
Topic: Individual firewall and Node-RED port problem [SOLVED]
Replies: 17
Views: 1836

Re: Individual firewall and Node-RED port problem [SOLVED]

Not without the complete config shown
/export file=anynameyouwish ( minus router serial number, public WANIP information, keys, long dhcp lease lists )
by anav
Thu Dec 28, 2023 3:27 pm
Forum: Beginner Basics
Topic: Wireguard
Replies: 8
Views: 2054

Re: Wireguard

Okay on the first point, my bad, in pre-routing the out-interface is not yet known (chosen) and thus its the wrong item to put down here. (First to ensure any traffic to or from wireguard to the LAN DOESNT not get mangled........) add chain=prerouting action=accept src-address=192.168.0.0/24 out-int...
by anav
Thu Dec 28, 2023 3:25 pm
Forum: Beginner Basics
Topic: Multiple Isolated Wifi networks on a wired AP bridge
Replies: 2
Views: 973

Re: Multiple Isolated Wifi networks on a wired AP bridge

For the secondary device acting as an AP/switch follow this advice.
viewtopic.php?t=182276
by anav
Thu Dec 28, 2023 2:29 pm
Forum: Beginner Basics
Topic: Wireguard
Replies: 8
Views: 2054

Re: Wireguard

On the first point I will look into it, does appear confusing, I suspect you have done something else in the config that is causing the problem.......... As for the second point, that was not a stated requirement and if you hide facts from creating a config then expect it to work while adding t hing...
by anav
Thu Dec 28, 2023 2:19 pm
Forum: Beginner Basics
Topic: Trouble with port forwarding through a Wireguard VPN [SOLVED]
Replies: 14
Views: 3093

Re: Trouble with port forwarding through a Wireguard VPN [SOLVED]

WHy not use BTH wireguard and dispense with the VPS.

However, SOB, I dont get your solution? How is the OP going to see the public IP address of the incoming port forwarded traffic landing at the MIkrotik which I think was his question?
by anav
Thu Dec 28, 2023 2:10 pm
Forum: General
Topic: VLAN : struggling with hybrid port [SOLVED]
Replies: 7
Views: 1462

Re: VLAN : struggling with hybrid port [SOLVED]

In that case........ https://forum.mikrotik.com/viewtopic.php?t=182276 Where the RB5009 gets an IP on the trusted subnet/vlan. As far as hybrid ports go /interface bridge port add bridge=bridge interface=etherAP pivd=XX ( where the pvid is the one vlan that is going to the AP device untagged ) /inte...
by anav
Thu Dec 28, 2023 5:14 am
Forum: General
Topic: VLAN : struggling with hybrid port [SOLVED]
Replies: 7
Views: 1462

Re: VLAN : struggling with hybrid port [SOLVED]

So which device is the MT, what you call the switch?
Where is the rest of the config, like the firewall rules etc........ or are you saying the RB5009 is only acting as a switch?
by anav
Thu Dec 28, 2023 4:14 am
Forum: Beginner Basics
Topic: VLAN Isolation with IOT and Guest
Replies: 3
Views: 1448

Re: VLAN Isolation with IOT and Guest

THe easiest thing to do when initially setting up the bridge and vlans is to take one port OFF the bridge and do all the configuring from that port. https://forum.mikrotik.com/viewtopic.php?t=181718 Turn on bridge vlan-filtering from off bridge port access!! You need to get rid of vlan1 and make it ...
by anav
Thu Dec 28, 2023 4:12 am
Forum: General
Topic: Local interfaces to wireguard
Replies: 6
Views: 984

Re: Local interfaces to wireguard

Your config makes no sense, and is so full of errors its a surprize anything works, where did you get all your advice?
Best bet is to draw a network diagram and explain what the requirements are.

users and the traffic they need.
by anav
Wed Dec 27, 2023 11:01 pm
Forum: Beginner Basics
Topic: connect to winbox through vpn [SOLVED]
Replies: 10
Views: 1519

Re: connect to winbox through vpn [SOLVED]

Because you dont block it........ You decided to allow it with this rule. add action=drop chain=forward comment=\ "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \ connection-state=new in-interface-list=WAN The only thing blocked by this default rule is WAN to LAN tr...
by anav
Wed Dec 27, 2023 10:55 pm
Forum: Beginner Basics
Topic: Why isn't DHCP working on my VLAN?
Replies: 9
Views: 1097

Re: Why isn't DHCP working on my VLAN?

(1) Get rid of the ingress filtering=no on bridge setting.......... is there a reason you put that there?/ (2) As far as your configuration why bother with VPN vlan. There is no VPN attached? Why not attache the subnet directly to the etherport2?? (3) You have no setting for bridge vlan /interface b...
by anav
Wed Dec 27, 2023 9:09 pm
Forum: Beginner Basics
Topic: VLan on L009
Replies: 5
Views: 779

Re: VLan on L009

I always take one port off the bridge and do all my configuring from there much nicer experience and use safe mode !!!

viewtopic.php?t=181718
by anav
Wed Dec 27, 2023 9:07 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7040

Re: Wireguard guru needed [SOLVED]

Send new configs with the latest issues of what doesnt work....
by anav
Wed Dec 27, 2023 7:12 pm
Forum: General
Topic: VLAN : struggling with hybrid port [SOLVED]
Replies: 7
Views: 1462

Re: VLAN : struggling with hybrid port [SOLVED]

Not a clue .......
Your diagram does not identify which device is the MT??
The switch make is not identified either, ( able to read vlans?)
Your MT config is not complete
/export file=anynameyouwish ( minus router serial number and any public WANIP information)
by anav
Wed Dec 27, 2023 5:53 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7040

Re: Wireguard guru needed [SOLVED]

Comments: Okay so we solved the initial problems in that subnet .100 (r1) can reach subnet .88 (r2) and the reverse should not be possible. So now I find it very confusing that you are asking R2 to be able to ping R1 subnet. Are you confused?? The only thing that should be pingable from R2 is the wi...
by anav
Wed Dec 27, 2023 5:06 pm
Forum: Beginner Basics
Topic: Wireguard Question
Replies: 9
Views: 879

Re: Wireguard Question

Typically people use a DYNDNS name/url associated with the public IP of their network. It could be you are behind an ISP router etc.... A free one available is your IP Cloud on the router ( my netname ) So for endpoint and port you put into the client device peer settings Endpoint = 4g5c933264sw.sn....
by anav
Wed Dec 27, 2023 5:02 pm
Forum: Beginner Basics
Topic: connect to winbox through vpn [SOLVED]
Replies: 10
Views: 1519

Re: connect to winbox through vpn [SOLVED]

WRONG, users do not get access to the router ONLY THE ADMINs should get access to config the router. How do to this. Create a source-address-list=Admin fireall address list!! /ip firewall address-list add address=IP1 list=Admin (local admin desktop) add address=IP2 list=Admin (local admin laptop) ad...
by anav
Wed Dec 27, 2023 4:57 pm
Forum: Beginner Basics
Topic: RB850Gx2 througput dropped after upgrade 6.49.11->7.13. FastTrack may be not working
Replies: 14
Views: 1212

Re: RB850Gx2 througput dropped after upgrade 6.49.11->7.13. FastTrack may be not working

Concur, but do have a question. Can you netinstall right to verssion 7.13 or do you have to netinstall to 7.12 and then upgrade to 7.13?? MKX is giving excellent advice. For basic firewall modify the deafult slightly to this... /ip firewall filter {Input Chain} add action=accept chain=input comment=...
by anav
Wed Dec 27, 2023 4:52 pm
Forum: General
Topic: Port knocking in random order
Replies: 10
Views: 1343

Re: Port knocking in random order

Ahh okay, understood.
by anav
Wed Dec 27, 2023 4:48 pm
Forum: General
Topic: Port knocking in random order
Replies: 10
Views: 1343

Re: Port knocking in random order

One could easily replace the port knocking with my cell phone connecting to wireguard ( logged ) and script uses that for WOL. :-)
Food for thought.
Assuming you has already thought of that but its not so easy maybe....
by anav
Wed Dec 27, 2023 4:44 pm
Forum: General
Topic: IP Firewall/NAT Input and Output Chain
Replies: 16
Views: 1514

Re: IP Firewall/NAT Input and Output Chain

Thanks for the very clear distinction/clarification of the topic, I had no idea! Yes, some practical uses of these new non chain flows would be quite interesting.
by anav
Wed Dec 27, 2023 4:42 pm
Forum: General
Topic: No Christmas video from MT?
Replies: 4
Views: 730

Re: No Christmas video from MT?

Its been a difficult year in Latvia, and the staff deserve a break from work to spend time with families. They have put out a shit load of videos in the recent months, so not surprized as they may just be a tad burned out. Still its early, might get something for new years. I think seeing Normunds a...
by anav
Wed Dec 27, 2023 4:37 pm
Forum: General
Topic: I Tink i got hacked
Replies: 16
Views: 1634

Re: I Tink i got hacked

Why did you have unsecure API enabled and running.
Perhaps you need to take some courses before being allowed to setup a router?

Netinstall, stop arguing do it, you wont get any other advice, stop wasting our time.
by anav
Wed Dec 27, 2023 4:35 pm
Forum: General
Topic: How can I protect my VPN network from attempted intrusion?
Replies: 9
Views: 1442

Re: How can I protect my VPN network from attempted intrusion?

change default ports if you can. Hence why I like wireguard as you can elect to use any port.........
by anav
Wed Dec 27, 2023 4:49 am
Forum: General
Topic: Port knocking in random order
Replies: 10
Views: 1343

Re: Port knocking in random order

Interesting appraoch their k6, , but has no bearing on what the op is doing or my comment.......
How does a port knocking affect a wake on LAN for PCs....... not sure how I see that would work.
by anav
Wed Dec 27, 2023 4:46 am
Forum: General
Topic: IP Firewall/NAT Input and Output Chain
Replies: 16
Views: 1514

Re: IP Firewall/NAT Input and Output Chain

Good thing, but sometimes people then make the mistake of putting their own router in DMZ which is then wide open, hopefully not the case here.
by anav
Wed Dec 27, 2023 12:39 am
Forum: Beginner Basics
Topic: Wireguard Question
Replies: 9
Views: 879

Re: Wireguard Question

Where did you get the MS wireguard app from??

Check firewalls or AV on windows laptop.
by anav
Wed Dec 27, 2023 12:17 am
Forum: Beginner Basics
Topic: RB850Gx2 througput dropped after upgrade 6.49.11->7.13. FastTrack may be not working
Replies: 14
Views: 1212

Re: RB850Gx2 througput dropped after upgrade 6.49.11->7.13. FastTrack may be not working

Also recognize that there was a hit on throughput for most older routers when moving from vers6 to vers7....... it may also have affected your model.
by anav
Wed Dec 27, 2023 12:12 am
Forum: Beginner Basics
Topic: my firewall config [SOLVED]
Replies: 2
Views: 909

Re: my firewall config [SOLVED]

Everything MKX said is bang on....... Where I would suggest a slight difference so that you can add more rules later with ease is to take the last rule in the forward chain and convert that to three rules which are clear and in fact provide a bit better security overall. /ip firewall ........ add ch...
by anav
Wed Dec 27, 2023 12:03 am
Forum: General
Topic: IP Firewall/NAT Input and Output Chain
Replies: 16
Views: 1514

Re: IP Firewall/NAT Input and Output Chain

I dont assume anything and took what you said at face value. If you don't need anything pacific you can just use action, input , accept to allow everything . As for services, you wont find anyone on this forum that leaves all those services open and running, at least the unsecure ones anyway. its ni...
by anav
Wed Dec 27, 2023 12:01 am
Forum: General
Topic: Port knocking in random order
Replies: 10
Views: 1343

Re: Port knocking in random order

Dont you use 5 ports, why only three............ what is the right number of ports 3,456??
by anav
Tue Dec 26, 2023 8:02 pm
Forum: Beginner Basics
Topic: How to block specific Youtube url ?
Replies: 5
Views: 1015

Re: How to block specific Youtube url ?

To start tackling Applications and Sites with any degree of certainly one needs to get a very $$router with deep packet inspection and of course the additional subscription services more $$$, to accomplish this and I mean $$ to get a unit that allows one to do this and maintain a high level of throu...
by anav
Tue Dec 26, 2023 7:56 pm
Forum: General
Topic: IP Firewall/NAT Input and Output Chain
Replies: 16
Views: 1514

Re: IP Firewall/NAT Input and Output Chain

If you don't need anything pacific you can just use action, input , accept to allow everything. Very bad advice.................. just saying shut it........... To be specific, allowing all connections from the internet to your device is reckless. Mikrotik provides a safe default setup that is basi...
by anav
Tue Dec 26, 2023 5:05 pm
Forum: General
Topic: Routing Mark
Replies: 2
Views: 481

Re: Routing Mark

Please use google translate and provide useful information such as a config.
/export file=anynameyouwish ( minus router serial number, and any public WANIP information )
by anav
Tue Dec 26, 2023 5:03 pm
Forum: General
Topic: Individual firewall and Node-RED port problem [SOLVED]
Replies: 17
Views: 1836

Re: Individual firewall and Node-RED port problem [SOLVED]

No, if done properly but I prefer to go all vlans once I start using vlans.
by anav
Tue Dec 26, 2023 3:47 pm
Forum: Beginner Basics
Topic: No internet via VLAN Wireguard Client [SOLVED]
Replies: 5
Views: 1262

Re: No internet via VLAN Wireguard Client [SOLVED]

FW rules seem fine. Easiest solution: Lets say you wanted vlan60 going over ether5 as a trunk port ( meaning ether 5 is connected to a smart device that can read tags). Then dont use bridge vlan filtering for this and remove ether5 from the bridge. simply assign vlan60 to ether5 when defining the in...
by anav
Tue Dec 26, 2023 3:38 pm
Forum: Beginner Basics
Topic: ...
Replies: 17
Views: 1722

Re: Am I safe with this firewall config? (I'm fairly new)

Why are you running Wireguard on a raspberry Pi and NOT the router???
by anav
Tue Dec 26, 2023 3:35 pm
Forum: General
Topic: Port knocking in random order
Replies: 10
Views: 1343

Re: Port knocking in random order

Why? Use wireguard to access router, simpler and more secure.
by anav
Tue Dec 26, 2023 3:34 pm
Forum: General
Topic: Individual firewall and Node-RED port problem [SOLVED]
Replies: 17
Views: 1836

Re: Individual firewall and Node-RED port problem [SOLVED]

Loopback is internal to the router and should not have any ill effects for your traffic.
See what Mkx states two posts below, he actually knows stuff.....I just read listen and believe what he and very select few others say. :-)
by anav
Mon Dec 25, 2023 10:47 pm
Forum: General
Topic: Individual firewall and Node-RED port problem [SOLVED]
Replies: 17
Views: 1836

Re: Individual firewall and Node-RED port problem [SOLVED]

Not sure what you mean by vlan1, but if you are using vlans then use all vlans ( but not vlan1 for data). Thus make it vlan10. Remember with a drop all rule at the end of the forward chain all subnets are automatically isolated at L3, and thus for the config below you only need to add to the above, ...
by anav
Mon Dec 25, 2023 10:08 pm
Forum: Beginner Basics
Topic: ...
Replies: 17
Views: 1722

Re: Am I safe with this firewall config? (I'm fairly new)

(1) Looks better, not quite sure what you are trying to accomplish with this rule.. add action=dst-nat chain=dstnat comment="Wireguard (network_pi)" dst-port=\ 51820 in-interface=pppoe-out1 protocol=udp to-addresses=192.168.1.111 \ to-ports=51820 May be perfectly fine if I understood its i...
by anav
Mon Dec 25, 2023 9:57 pm
Forum: General
Topic: Individual firewall and Node-RED port problem [SOLVED]
Replies: 17
Views: 1836

Re: Individual firewall and Node-RED port problem [SOLVED]

Something like this should be the default FW ruleset as a staring point for anyone that starts to make changes to the config. /ip firewall address-list ( mostly from static dhcp leases ) add address=IP1 list= Admin (desktop) add address=IP2 list=Admin (laptop) add address=IP3 list=Admin (smartphone/...
by anav
Mon Dec 25, 2023 9:50 pm
Forum: General
Topic: Individual firewall and Node-RED port problem [SOLVED]
Replies: 17
Views: 1836

Re: Individual firewall and Node-RED port problem [SOLVED]

Not much! In fact if port 8291 is your winbox port, your FW is a piece of trash. Also you have no clue on the importance of order of firewalls and finally its hard to read being disorganized mixing up the chains. Finally without seeing the rest of the config and subnets/vlans its hard to really com...
by anav
Mon Dec 25, 2023 5:47 pm
Forum: Beginner Basics
Topic: RB750Gr3: Slow internet connection - do I need another router
Replies: 3
Views: 810

Re: RB750Gr3: Slow internet connection - do I need another router

Although one cannot stop smart kids from bypassing your DNS, you can make it a bit better/stronger with some additional rules. add chain=dst-nat action=dstnat in-interface=VLAN40 dst-port=53 protocol=udp to-addresss=10.0.30.17 add chain=dst-nat action=dstnat in-interface=VLAN40 dst-port=53 protocol=...
by anav
Mon Dec 25, 2023 5:43 pm
Forum: Beginner Basics
Topic: RB750Gr3: Slow internet connection - do I need another router
Replies: 3
Views: 810

Re: RB750Gr3: Slow internet connection - do I need another router

1. Concur with erlindens observation. 2. Firewall rules are a bit disorganized and after review, my big issues is the ridiculousness of allowing all vlans to the router and then after attempting to only alllow managment vlan to config router......... had a good chuckle, I also removed this rule awai...
by anav
Mon Dec 25, 2023 5:26 pm
Forum: Announcements
Topic: v7.14beta [testing] is released!
Replies: 510
Views: 154761

Re: v7.14beta [testing] is released!

If only the hapac2 could run clouflare zerotrust tunnel...... oh wait, its an arm device, it already can, but why not a package for all devices!!! C'mon MT be diverse and non-discriminatory for a change, this ARM favouritism is annoying. :-) ( shedding no tears for hapac2 )
by anav
Mon Dec 25, 2023 4:28 pm
Forum: Beginner Basics
Topic: Dual WAN, same Gateway, no need for load balancing or failover, just specify which vlans use which wan port
Replies: 23
Views: 4786

Re: Dual WAN, same Gateway, no need for load balancing or failover, just specify which vlans use which wan port

vlans are automatically eliminated by a drop all rule at the end of the forward chain.
Thus all that is required is to make allow rules for what is permitted.