Community discussions

MikroTik App

Search found 1120 matches

by Steveocee
Wed Mar 20, 2019 4:09 pm
Forum: Beginner Basics
Topic: RB3011UiAS-RM Speeds
Replies: 5
Views: 2193

Re: RB3011UiAS-RM Speeds

Something very wrong there. Even the RB2011 could do 350Mb without fast track!
Config will tell the story.
by Steveocee
Tue Mar 19, 2019 12:43 pm
Forum: Virtualization
Topic: CHR Hardware
Replies: 20
Views: 20907

Re: CHR Hardware

Will you be licensing your ESXi installations? If not you can only use 8 vCPU's per machine so you'd have a lot of redundant cores. Saying that it's better to run WITHOUT HT for CHR so only 4 over.
by Steveocee
Mon Mar 18, 2019 10:44 pm
Forum: Beginner Basics
Topic: RB2011UiAS-2HnD-IN antennas
Replies: 1
Views: 828

Re: RB2011UiAS-2HnD-IN antennas

You may have been better buying a connectorised radio such as a Netbox or Netmetal.
I would generally advise leaving the antennas alone on the RB2011
by Steveocee
Mon Mar 18, 2019 9:42 pm
Forum: General
Topic: Block port tcp/udp
Replies: 12
Views: 9228

Re: Block port tcp/udp

Your router is very vulnerable. If it is public facing you need to update it and at a minimum put a public facing firewall on it.
by Steveocee
Mon Mar 18, 2019 6:05 pm
Forum: General
Topic: Block port tcp/udp
Replies: 12
Views: 9228

Re: Block port tcp/udp

IP>Firewall>Service Port isn't "the" service. It's a service helper. A very bad one at that. Do you have any port forwards? Are you using UPnP? 5060 is generally used for VOIP/SIP, do you have anything that uses that on your network? You could make a rule to drop it however surely your fir...
by Steveocee
Mon Mar 18, 2019 4:00 pm
Forum: Beginner Basics
Topic: CCR1016-12G VPN to discover ubiquiti radios for UNMS
Replies: 4
Views: 1814

Re: CCR1016-12G VPN to discover ubiquiti radios for UNMS

You won't be able to use discovery tool unless you use some kind of EOIP solution. UBNT discovery requires being on the same broadcast network which you won't be going in through VPN even though you can access the IP's.
by Steveocee
Mon Mar 18, 2019 12:59 pm
Forum: RouterBOARD hardware
Topic: CRS328-24P-4S+RM idle power consumption
Replies: 6
Views: 7837

Re: CRS328-24P-4S+RM idle power consumption

Here is my CRS328-24P-4S+RM Annotation 2019-03-18 105542.png This is running; 3 data only ports 3 48v ports running 2 UniFi AC Pro's and a PoE splitter for modem. 3 24v ports Running 2 UniFi CCTV cameras and an NSM5 3 SFP's I didn't think consumption was too bad to be fair bearing in mind I also run...
by Steveocee
Tue Mar 12, 2019 5:25 pm
Forum: General
Topic: Why (not) use Hairpin NAT
Replies: 28
Views: 10303

Re: Why (not) use Hairpin NAT

Firstly, thank you for linking my video 8) I use home.mydomain.com for getting into certain things remotely and from home. These are differentiated by port number. I can't do that with internal DNS so it suits me quite well. I shared what I found as I initially had a lot of problems getting a hairpi...
by Steveocee
Tue Mar 12, 2019 4:51 pm
Forum: Beginner Basics
Topic: Connecting two routers in two buildings with cable
Replies: 8
Views: 2918

Re: Connecting two routers in two buildings with cable

Hello, I'm assuming that the /16s are just to summarize local subnets and you don't have such a big network. Otherwise, break the subnet down to smaller ones (like /24). Also, I'd probably go with fiber regardless since your working with two buildings. Fiber will insulate you from grounding issues,...
by Steveocee
Mon Mar 11, 2019 1:25 pm
Forum: RouterBOARD hardware
Topic: CRS309-1G-8S+IN (General questions and experience)
Replies: 7
Views: 4086

Re: CRS309-1G-8S+IN (General questions and experience)

Liked & Subbed.
Nice to see well made content.
by Steveocee
Mon Mar 11, 2019 1:18 pm
Forum: Wireless Networking
Topic: 10Gb on RB2011 - bad idea?
Replies: 6
Views: 2270

Re: 10Gb on RB2011 - bad idea?

Great idea. Shame the RB2011 only has SFP and not SFP+ so won't do a 10Gb connection.
by Steveocee
Mon Mar 11, 2019 11:51 am
Forum: Beginner Basics
Topic: Firewall rules
Replies: 6
Views: 1601

Re: Firewall rules

You need hairpin NAT.
by Steveocee
Sun Mar 10, 2019 8:57 am
Forum: General
Topic: RB3011 and 10GB SFP
Replies: 3
Views: 3426

Re: RB3011 and 10GB SFP

Bummer, no worries. Thanks for the compatibility link! I'm not sure if anyone can verify or has tried but do the Cisco 1GB SFP's work with MikroTik routers? I've got a couple laying around at my parents i was thinking of having them ship me. Cisco GLC-SX-MM work absolutely fine. I picked a load up ...
by Steveocee
Sun Mar 10, 2019 8:31 am
Forum: Beginner Basics
Topic: HELP: how to per ip shaping?
Replies: 10
Views: 3970

Re: HELP: how to per ip shaping?

If i set 50m/50m in simple queue maxlimit, shaping will not work. Now, I set my values to 40m/40m and it worked. Why is that? Queue will only apply once you hit the max limit, if you set it higher than your connection can go then it will never apply itself. It going red only signifies traffic is ne...
by Steveocee
Sun Mar 10, 2019 8:21 am
Forum: Beginner Basics
Topic: Help with WAN bandwidth limiting
Replies: 12
Views: 4045

Re: Help with WAN bandwidth limiting

it's rx/tx , I think, so upload or download depending on that interface / target you apply it to.
Correct, however it is done from client of interface perspective so for pppoe interface the values do reverse.
by Steveocee
Fri Mar 08, 2019 3:52 pm
Forum: General
Topic: hEX S shows activity on disabled SFP port without a link
Replies: 6
Views: 1700

Re: hEX S shows activity on disabled SFP port without a link

Faulty hardware. Recently had similar with a CCR thinking ether5-7 was connected when they weren't.
by Steveocee
Fri Mar 08, 2019 2:35 pm
Forum: Wireless Networking
Topic: Configuring a Single SSID WLAN with Two wAP AC (RBwAPG-5HacT2HnD-US) and one hEX (RB750Gr3)
Replies: 6
Views: 1911

Re: Configuring a Single SSID WLAN with Two wAP AC (RBwAPG-5HacT2HnD-US) and one hEX (RB750Gr3)

Roaming is done by the client. You can only try to encourage it.
Make sure you use the same encryption method and key and try to separate the wireless channels as far as you can. It can help to stick a minimum RSSI of around -75 on to discourage sticky clients.
by Steveocee
Thu Mar 07, 2019 8:31 pm
Forum: General
Topic: RB4011 real world speed tests
Replies: 12
Views: 10470

Re: RB4011 real world speed tests

I think btest is limiting your results.
by Steveocee
Thu Mar 07, 2019 5:12 pm
Forum: General
Topic: RB4011 real world speed tests
Replies: 12
Views: 10470

Re: RB4011 real world speed tests

Just finished bandwidth test
What did you use to test?
25% on a quad core CPU device means 1 core was running at 100% whilst the others were idle.
by Steveocee
Thu Mar 07, 2019 4:49 pm
Forum: General
Topic: Interface shows R (running) when it's not
Replies: 9
Views: 5820

Re: Interface shows R (running) when it's not

You won't.

The interface on your CHR will always be connected to the vSwitch/port group in ESXi.
by Steveocee
Thu Mar 07, 2019 4:44 pm
Forum: RouterBOARD hardware
Topic: mikrotik 4011 not all ports leds are blinking
Replies: 1
Views: 1366

Re: mikrotik 4011 not all ports leds are blinking

Broken?

It does sound like there is a fault with the hardware there with the LED's being vertically stacked, bad track on the board probably.
by Steveocee
Thu Mar 07, 2019 1:57 pm
Forum: Wireless Networking
Topic: Back to back LHGG-60ad Ptp link (relay) [SOLVED]
Replies: 10
Views: 3885

Re: Back to back LHGG-60ad Ptp link (relay) [SOLVED]

This forum sometimes! The guy sis asking what seems a really simple question, can he back to back two of the 60Ghz links, the answer is yes. Who mentioned dual radios and PtMP? Radio A <WIRELESS> Radio B <CAT5> Radio C <WIRELESS> Radio D. Is there some additional text in the same colour as the page...
by Steveocee
Wed Mar 06, 2019 4:18 pm
Forum: RouterBOARD hardware
Topic: No beeper on HAP AC2
Replies: 6
Views: 8031

Re: No beeper on HAP AC2

Lets be honest though, the only use the beeper really gets is when you're bored and you want to play the Mario tune?
by Steveocee
Wed Mar 06, 2019 1:47 pm
Forum: General
Topic: How can i use datacenter multi ip on dsl?
Replies: 3
Views: 989

Re: How can i use datacenter multi ip on dsl?

You could set up a VPN in the datacenter. I need to ask though, why do you need that many IP's on your home connection? Have you heard of this amazing thing called NAT?
by Steveocee
Wed Mar 06, 2019 1:38 pm
Forum: Wireless Networking
Topic: wAP 60G AP to wAP 60G AP
Replies: 1
Views: 901

Re: wAP 60G AP to wAP 60G AP

Use bridge, not AP bridge and it will work.
Also ensure you have correctly set SSID and password.
by Steveocee
Wed Mar 06, 2019 10:37 am
Forum: Wireless Networking
Topic: New LHG 4G kit - RBLHGR&R11e-4G
Replies: 7
Views: 2142

Re: New LHG 4G kit - RBLHGR&R11e-4G

Hi Steveocee Thanks for your reply, have you found the new equipment gives greater range or is it about the same?. You might be better on EE as they use the 1800Mhz band where I can get clients pulling down up to 85Mb. O2 only work on the 800Mhz channel which I've found Ok but speeds rarely go abov...
by Steveocee
Wed Mar 06, 2019 10:34 am
Forum: Wireless Networking
Topic: Back to back LHGG-60ad Ptp link (relay) [SOLVED]
Replies: 10
Views: 3885

Re: Back to back LHGG-60ad Ptp link (relay) [SOLVED]

This forum sometimes! The guy sis asking what seems a really simple question, can he back to back two of the 60Ghz links, the answer is yes. Who mentioned dual radios and PtMP? Radio A <WIRELESS> Radio B <CAT5> Radio C <WIRELESS> Radio D. Is there some additional text in the same colour as the page ...
by Steveocee
Tue Mar 05, 2019 5:47 pm
Forum: Beginner Basics
Topic: RB4011 5Ghz Wifi unstable
Replies: 7
Views: 6569

Re: RB4011 5Ghz Wifi unstable

Having the device set to Auto is probably the worst way of operating the unit. It needs to be configured correctly otherwise it'll be all over the place.
Please give some details or config you have as an example (don't forget the country you are in) and I'm sure people on here will help you.
by Steveocee
Tue Mar 05, 2019 5:44 pm
Forum: Wireless Networking
Topic: Back to back LHGG-60ad Ptp link (relay) [SOLVED]
Replies: 10
Views: 3885

Re: Back to back LHGG-60ad Ptp link (relay) [SOLVED]

It will work as well as daisy-chaining switches will work.

As @mistry7 has already said, loosely there are 4 channels. 58, 60, 62 and 64 Ghz. Just don't reuse the same channel back to back and you'll be fine.
by Steveocee
Tue Mar 05, 2019 5:42 pm
Forum: Beginner Basics
Topic: 2 firmware update locations ?
Replies: 7
Views: 1750

Re: 2 firmware update locations ?

You are up to date.

You have a "current" firmware (think of as BIOS) and a "factory firmware" which you will never be able to upgrade and is there purely for in case of emergency.
by Steveocee
Tue Mar 05, 2019 5:32 pm
Forum: General
Topic: dynamic ip in a dst-nat rule
Replies: 5
Views: 2661

Re: dynamic ip in a dst-nat rule

This won't be totally applicable but it explains how to get the dynamic bit down far easier than my typing will do.
https://www.youtube.com/watch?v=_kw_bQyX-3U
by Steveocee
Tue Mar 05, 2019 5:31 pm
Forum: General
Topic: VPN & 2 pppoe issue
Replies: 3
Views: 1129

Re: VPN & 2 pppoe issue

You should probably post your config as this will give us a better idea of what you have done and where it can be fixed. Make sure to use "hide-sensitive" flag so no personal information is posted.
by Steveocee
Tue Mar 05, 2019 5:28 pm
Forum: Beginner Basics
Topic: problem connecting to cctv from my local wifi network
Replies: 2
Views: 1048

Re: problem connecting to cctv from my local wifi network

Sounds like you need hairpin NAT. Youtube has some excellent videos on how to do it (mine being one of them).
by Steveocee
Tue Mar 05, 2019 5:27 pm
Forum: Beginner Basics
Topic: Help with WAN bandwidth limiting
Replies: 12
Views: 4045

Re: Help with WAN bandwidth limiting

OP has stated line saturation is causing the PPPoE connection to drop and has sensibly suggested a limit of the PPPoE interface, I honestly don't know where the logic in limiting users individually came from there? @OP the solution from @solar77 is perfect for you. Be aware though I think when you s...
by Steveocee
Tue Mar 05, 2019 5:16 pm
Forum: Beginner Basics
Topic: I've locked myself out of the router admin interface.
Replies: 2
Views: 1074

Re: I've locked myself out of the router admin interface.

I'm sure this will be a vlaid reason why not but.....plug into ether9?
by Steveocee
Tue Mar 05, 2019 3:45 pm
Forum: Wireless Networking
Topic: New LHG 4G kit - RBLHGR&R11e-4G
Replies: 7
Views: 2142

Re: New LHG 4G kit - RBLHGR&R11e-4G

Have had one on test for a couple of weeks. As I move about from client to client I've been doing some very barbaric speedtest.net results and comparing.

The long and short of my findings was give up if you plan on using O2 network.

Awaiting an EE SIM to see if things improve.
by Steveocee
Tue Mar 05, 2019 10:52 am
Forum: Beginner Basics
Topic: Control kids iPad usage time
Replies: 9
Views: 2989

Re: Control kids iPad usage time

As a parent of a 2, 3, 5 and 8 year old speaking. Have you considered saying "No"? No scripting needed.
The only "script" you'd possibly need is a CD set to loop saying no :lol:
Tell me about it. Hindsight eh?
by Steveocee
Mon Mar 04, 2019 6:48 pm
Forum: General
Topic: Outgoing SSH traffic is blocked
Replies: 7
Views: 3214

Re: Outgoing SSH traffic is blocked

*Fixed* Don't think my problem was related. I have a route policy on site that tells it to send certain devices up a VPN. I managed to go "to" the device down the WAN and then it was trying to respond back up the VPN hence firewalls blocking packets from unexpected sources. Good luck to th...
by Steveocee
Mon Mar 04, 2019 6:46 pm
Forum: General
Topic: Outgoing SSH traffic is blocked
Replies: 7
Views: 3214

Re: Outgoing SSH traffic is blocked

How strange.
I have just come across this problem myself. I am port forwarding from a specific remote IP back into my network and using torch I can see the LAN device trying to get back to it with dst IP but it simply isn't available.
by Steveocee
Sat Mar 02, 2019 7:09 am
Forum: Wireless Networking
Topic: 60Ghz 2.4km - possible?
Replies: 41
Views: 14569

Re: 60Ghz 2.4km - possible?

Just use a weird 5GHz channel nobody else is using
Losing a bucket of throughput, opening yourself up to local noise and losing full duplex.

I currently have a 2.4Km link on trial, it's struggling.
by Steveocee
Fri Mar 01, 2019 5:26 pm
Forum: Beginner Basics
Topic: Introduction to RouterOS documentation
Replies: 13
Views: 2451

Re: Introduction to RouterOS documentation

Hi Colin, Welcome to the world of MikroTik. Very little official documentation, lots of user input (with multiple solutions to 1 issue normally) and an extremely steep learning curve. Use the default config to start with, adapt it to get you "online" and then study it from there to unders...
by Steveocee
Fri Mar 01, 2019 4:39 pm
Forum: General
Topic: 2x CRS112 Loop with single uplink? [SOLVED]
Replies: 1
Views: 1449

Re: 2x CRS112 Loop with single uplink? [SOLVED]

Your bridge is using the MAC address of your ether port.

Set an admin-mac of your ether interface (I always use ether1 for continuity) but increment the second character EG 00:AA: becomes 02:AA

Will get rid of the error for you.
by Steveocee
Fri Mar 01, 2019 4:35 pm
Forum: Beginner Basics
Topic: Introduction to RouterOS documentation
Replies: 13
Views: 2451

Re: Introduction to RouterOS documentation

Hi Colin, Welcome to the world of MikroTik. Very little official documentation, lots of user input (with multiple solutions to 1 issue normally) and an extremely steep learning curve. Use the default config to start with, adapt it to get you "online" and then study it from there to underst...
by Steveocee
Fri Mar 01, 2019 10:50 am
Forum: RouterBOARD hardware
Topic: Passive PoE: MikroTik and Ubiquiti
Replies: 6
Views: 7747

Re: Passive PoE: MikroTik and Ubiquiti

I use G3's connected to a CRS328, works fine with no problems. I changed from a UniFi 8 port switch last week and to be honest didn't even remember the G3's are 24v only. I've been really impressed with the CRS328 so far.
by Steveocee
Thu Feb 28, 2019 4:36 pm
Forum: Beginner Basics
Topic: Control kids iPad usage time
Replies: 9
Views: 2989

Re: Control kids iPad usage time

As a parent of a 2, 3, 5 and 8 year old speaking. Have you considered saying "No"? No scripting needed.
by Steveocee
Thu Feb 28, 2019 3:35 pm
Forum: General
Topic: hap Mini
Replies: 10
Views: 3086

Re: hap Mini

lil0's OP The free space thing could be a problem, remove all packages you don't need. Remove all files you don't need (or at least back them up). Let's face it, do you need MPLS and BGP on this device? Probably not, be brutal, remove everything you don't need. I use a hAP Mini as a travel router a...
by Steveocee
Thu Feb 28, 2019 3:33 pm
Forum: General
Topic: hap Mini
Replies: 10
Views: 3086

Re: hap Mini

To be honest, this shouldn't escalate to an last resort like netinstall - the small size is not good because does not allow to use all compatible features simultaneously, it's like installing Linux and only be able to execute X11 or Console(tty) but not both - it is damaging the brand, and SPI Flas...
by Steveocee
Thu Feb 28, 2019 3:20 pm
Forum: General
Topic: Remote SSH access Issue Via NAT
Replies: 4
Views: 1578

Re: Remote SSH access Issue Via NAT

If the modem is truly in bridge mode then you won't be able to access it via the WAN through SSH. Your SSH should be hitting the MikroTik. This would only not be the case if it wasn't actually in bridge mode and was routing and your MikroTIk was simply taking a LAN connection from it. I use a modem ...
by Steveocee
Thu Feb 28, 2019 3:12 pm
Forum: Beginner Basics
Topic: Need help opening ports for Torrents on RB2011iLS-IN
Replies: 11
Views: 9198

Re: Need help opening ports for Torrents on RB2011iLS-IN

I really can't begin to tell you what a bad idea that is. So you're downloading P2P, maybe one of the files is infected, this then generates multiple services on the host, all of which then tell your router to open up ports which it does because UPnP is on which then enables more malicious software ...
by Steveocee
Mon Feb 25, 2019 8:43 pm
Forum: Beginner Basics
Topic: CRS112-8G-4S-IN question
Replies: 1
Views: 1024

Re: CRS112-8G-4S-IN question

Bridge all ports and enable hardware offload so it uses switch chip rather than CPU.
Job done.
by Steveocee
Mon Feb 25, 2019 8:41 pm
Forum: Beginner Basics
Topic: Control kids iPad usage time
Replies: 9
Views: 2989

Re: Control kids iPad usage time

IP>Kid Control
Maybe it won't limit to 30 mins per day but it's a start to minimise watch time.
by Steveocee
Fri Feb 22, 2019 5:08 pm
Forum: RouterBOARD hardware
Topic: SFP in SFP+ question
Replies: 2
Views: 1149

Re: SFP in SFP+ question

Dropped a bunch of Cisco GLC-SX-MM's into a CRS328-24P-4S+RM yesterday and all worked absolutely fine with auto negotiation. The "B" end's were a CRS125, CRS112 and UniFi 8 port.
by Steveocee
Fri Feb 22, 2019 5:05 pm
Forum: General
Topic: Mikrotik RB951G USB Port
Replies: 2
Views: 2885

Re: Mikrotik RB951G USB Port

The menu is under IP>SMB, you can create the share in there but for an honest opinion, it will be hideous to use. As it is USB2 based the transfer speed will be very slow and you'll have far less headache with a "real" NAS unit.
by Steveocee
Thu Feb 21, 2019 12:32 pm
Forum: Beginner Basics
Topic: L2TP/IPsec connection without sharing internet [SOLVED]
Replies: 6
Views: 9553

Re: L2TP/IPsec connection without sharing internet [SOLVED]

You can use mangle to add routing marks then set the appropriate routing marks in your IP>Routes. Use mangle to identify either src or destination and then apply either an "in-vpn" or "out-vpn" mark to it. I use very similar to identify specific LAN devices to be able to use my w...
by Steveocee
Thu Feb 21, 2019 12:16 pm
Forum: Beginner Basics
Topic: 2 Public IP
Replies: 3
Views: 1122

Re: 2 Public IP

No problem at all. I've recently spun something similar up for a customer request. My use case was pppoe-out1 with static IP X.X.X.1 and then it had a /29 of routed IP's Y.Y.Y.0/29 of which each port in the router (RB3011) was going to have a different LAN range but traffic coming from a correspondi...
by Steveocee
Tue Feb 19, 2019 10:14 pm
Forum: Beginner Basics
Topic: Forum have BUG 5 (five) years.
Replies: 9
Views: 3309

Re: Forum have BUG 5 (five) years.

Yeah @support !!! Why didn't you know this guy had problems for 5 years? Be more like Huawei and spy on your users data so we can complain about that instead!
by Steveocee
Tue Feb 19, 2019 10:11 pm
Forum: Beginner Basics
Topic: hairpin nat/routing [SOLVED]
Replies: 9
Views: 9623

Re: hairpin nat/routing [SOLVED]

Have a watch through this. Will explain everything you need.
https://www.youtube.com/watch?v=_kw_bQyX-3U&t=1s
by Steveocee
Wed Feb 13, 2019 3:48 pm
Forum: Beginner Basics
Topic: RB4011 not working? [SOLVED]
Replies: 2
Views: 2272

Re: RB4011 not working? [SOLVED]

Download Winbox and try L2 connection, no IP needed.
by Steveocee
Tue Feb 05, 2019 11:35 am
Forum: General
Topic: DNS resolution vulnerability
Replies: 14
Views: 4119

Re: DNS resolution vulnerability

This just sounds like you didn't set up your firewall properly. Not a vulnerability. If you enable DNS cacheing then the router will do it regardless, it is up to you then as the user to ensure that only requests you want answered are responded to. Usually a dro pUDP-53 rule from the WAN interface i...
by Steveocee
Wed Jan 30, 2019 2:59 pm
Forum: RouterBOARD hardware
Topic: hap mini, is 'foot' removeable?
Replies: 5
Views: 1975

Re: hap mini, is 'foot' removeable?

Forgot I made that video.
by Steveocee
Wed Jan 30, 2019 2:57 pm
Forum: Beginner Basics
Topic: DNS server behaviour
Replies: 5
Views: 1881

Re: DNS server behaviour

Yeah your config sounds screwed up. With a drop rule there should be no need for an extra rule in there. Also after the drop rule there should be no hits on any input rules........ This. Unless you have an established & related rule and the requests are coming form the same hosts and by some wi...
by Steveocee
Tue Jan 29, 2019 6:59 pm
Forum: RouterBOARD hardware
Topic: hap mini, is 'foot' removeable?
Replies: 5
Views: 1975

Re: hap mini, is 'foot' removeable?

Yes it is. I have trouble keeping it on to be fair, the device is so light and once you have a cat5 and power cable plugged in it struggles to stand up with it's own weight.
by Steveocee
Mon Jan 28, 2019 5:36 pm
Forum: Wireless Networking
Topic: LHG 60G experience
Replies: 608
Views: 194102

Re: LHG 60G experience

Finally got my link up! 64Ghz wasn't cutting it but when I've tried out 66Ghz we now have a link. There is still some more panning that needs to be done, still not quite the 4Km touted recently.
66g1.JPG
by Steveocee
Wed Jan 16, 2019 4:20 pm
Forum: Beginner Basics
Topic: Test user on Desktop computer.
Replies: 3
Views: 1193

Re: Test user on Desktop computer.

X86 isn't really a supported variant any more. "Real" hardware installations are now advised to be done using CHR through a Virtual Host.
by Steveocee
Tue Jan 15, 2019 12:29 pm
Forum: Beginner Basics
Topic: Performance issue with Bell FTTH 940mbps/940mbps internet on Mikrotik CRS328-24P-4S+ (Bell Home Hub bypass)
Replies: 9
Views: 3794

Re: Performance issue with Bell FTTH 940mbps/940mbps internet on Mikrotik CRS328-24P-4S+ (Bell Home Hub bypass)

CRS series are primarily switches with an amount of L3 capability. I think you'd need to use fast track and hardly anything else to get near the throughput you want. Ideally you'd need an RB3011 or upwards to route at those sorts of speeds.
by Steveocee
Wed Dec 26, 2018 11:18 pm
Forum: Virtualization
Topic: Problem buying a copy CHR
Replies: 1
Views: 4506

Re: Problem buying a copy CHR

You don't buy CHR. You can buy a CHR license though, is that what you mean?
by Steveocee
Wed Dec 26, 2018 11:05 pm
Forum: Beginner Basics
Topic: Configure RB3011 to work with Comcast SB6183
Replies: 5
Views: 2305

Re: Configure RB3011 to work with Comcast SB6183

Assuming Comcast work like most, you can connect a DHCP-client device to the modem and you're on the net. If so, reset the RB3011 to factory defaults and connect the modem to ether1. Should get you up and running (providing they don't have any weird MAC timeout restrictions on the services) and then...
by Steveocee
Mon Dec 24, 2018 11:52 am
Forum: RouterBOARD hardware
Topic: VDSL2
Replies: 5
Views: 2393

Re: VDSL2

Not heard any mumbles of it.
The SFP approach is the closest yet but there will be little appetite in going for VDSL now with the general lean towards fibre to the premises.
by Steveocee
Sun Dec 23, 2018 10:18 am
Forum: Wireless Networking
Topic: Config RB952UI-2nd with 4 NMS2 for captive portail project
Replies: 1
Views: 948

Re: Config RB952UI-2nd with 4 NMS2 for captive portail project

This will be a LOT for someone to write for you a step by step guide. Maybe watch some YouTube tutorials first? Setting up router, then hotspot, then come back with any configuration issues or changes that need making?
by Steveocee
Sun Dec 23, 2018 10:11 am
Forum: Wireless Networking
Topic: Broadcast Storm avoiding
Replies: 1
Views: 1651

Re: Broadcast Storm avoiding

Are you using client isolation? That would mitigate a lot for you, you should not get a storm across all ports though unless you add the ports to a bridge and then have a single pppoe server on the bridge.
by Steveocee
Sun Dec 23, 2018 9:58 am
Forum: RouterBOARD hardware
Topic: Problems with Mikrotik RB951Ui-2HnD
Replies: 2
Views: 2561

Re: Problems with Mikrotik RB951Ui-2HnD

Your router has been hacked and likely has a script running on startup.

You need to do a netinstall to latest version and then re on figure securely before connecting back to the web.
by Steveocee
Sun Dec 23, 2018 9:55 am
Forum: RouterBOARD hardware
Topic: Ethernet flapping on RB3011
Replies: 5
Views: 2962

Re: Ethernet flapping on RB3011

I’m on mobile but search this forum for the term “port flopping”. There is a large thread about it, why it is happening and how the problem hasn’t yet been fully solved.
by Steveocee
Sat Dec 22, 2018 11:08 am
Forum: Beginner Basics
Topic: Hairpin NAT is not working
Replies: 13
Views: 8015

Re: Hairpin NAT is not working

@Steveocee Thanks for wonderful and helpful video that you share in youtube, I am totally new user to Mikrotik but base on your guidance from the video, after some testing and reboot finally I able to get the loopback/ Hairpin NAT plus DYNDNS work perfectly with my Dynamic IP. Keep up the good job ...
by Steveocee
Wed Dec 19, 2018 1:55 pm
Forum: Beginner Basics
Topic: Locking down a Port Forward - noob question
Replies: 2
Views: 1020

Re: Locking down a Port Forward - noob question

Do you actually need the port open? Could the traffic be part of your established or related chain instead? If you are "dialling out" to this company then you shouldn't need this rule.

Can you do an export (hiding the addresses of course) so we can see and help?
by Steveocee
Tue Dec 18, 2018 3:09 am
Forum: Wireless Networking
Topic: Newbie: LHG 5ac only hitting 100mbps
Replies: 30
Views: 6838

Re: Newbie: LHG 5ac only hitting 100mbps

Several people have already said, you are not missing anything. Your expectation of the product is too high. Either use an LHG60 to get gigabit or you will have to deal with the connection you are getting. The fact you are gettin 800+ burst rates is impressive to say the least, especially in the con...
by Steveocee
Tue Dec 18, 2018 3:05 am
Forum: General
Topic: Any alternatives for IP Cloud (DDNS)?
Replies: 1
Views: 1122

Re: Any alternatives for IP Cloud (DDNS)?

It was only temporary downtime, not full shut down. The current version is quite stable also.
You can script the router to pull WAN ip from your interface if you really need it to on net watch up but that is very long way around an easily solvable problem.
by Steveocee
Fri Dec 14, 2018 4:52 pm
Forum: Beginner Basics
Topic: Blocking traffic on the same NAT doesn't work
Replies: 10
Views: 2291

Re: Blocking traffic on the same NAT doesn't work

^^^^ Anav missed the easy solution. Although correct in that they are essentially in a L2 network, you can force L3 connectivity.

If the interfaces are in the same bridge you can use the bridge settings to use IP firewall or bridge filters and stop them from talking that way.
by Steveocee
Fri Dec 14, 2018 4:49 pm
Forum: Beginner Basics
Topic: Basic ROUTING [SOLVED]
Replies: 9
Views: 2793

Re: Basic ROUTING [SOLVED]

Should be doable with a dst-nat rule I think.
Need a bit more info from your side to give you a more exact answer though.
by Steveocee
Fri Dec 14, 2018 1:10 pm
Forum: Beginner Basics
Topic: Web filter for Childs
Replies: 7
Views: 3427

Re: Web filter for Childs

MikroTik Kid Control is brilliant for controlling who can access the net at what times and at what speeds across a grouped amount of devices.
No good for site control though.
by Steveocee
Fri Dec 14, 2018 12:34 pm
Forum: Beginner Basics
Topic: Mikrotik reserving some of my bandwith and I don't want that
Replies: 18
Views: 3858

Re: Mikrotik reserving some of my bandwith and I don't want that

I want to stream 4k high bitrate media, to 4 devices around the house if its possible I'd like to do that from a big external HDD hooked up to the router via usb 3.0 or something faster via NFS or something similar. If I can do this it basically means I can avoid buying a NAS which would be amazing...
by Steveocee
Fri Dec 14, 2018 12:16 pm
Forum: Beginner Basics
Topic: Web filter for Childs
Replies: 7
Views: 3427

Re: Web filter for Childs

Separate network for her devices and use something like OpenDNS to filter DNS requests?
by Steveocee
Thu Dec 13, 2018 5:13 pm
Forum: Wireless Networking
Topic: New 60ghz channel release expectation
Replies: 4
Views: 2205

Re: New 60ghz channel release expectation

The channel is not something MikroTik are releasing, the channel itself is already there. MikroTik are enabling the use of the channel through firmware which currently is only in the RC version but will ultimately release to current (whenever that may be). It is the 66000 channel which moves further...
by Steveocee
Tue Dec 11, 2018 1:03 pm
Forum: Beginner Basics
Topic: Remove port from the default brige [SOLVED]
Replies: 17
Views: 16586

Re: Remove port from the default brige [SOLVED]

Interesting
So I will then always set up bridges like this:
/interface bridge
add admin-mac=x[26AE]:xx:xx:xx:xx:xx auto-mac=no name=bridge
Where x are random[0-9A-F]
My MTCNA tutor taught to increment the first digit set by 2.
IE 00:AA:BB becomes 02:AA:BB
by Steveocee
Mon Dec 10, 2018 3:27 pm
Forum: Beginner Basics
Topic: Remove port from the default brige [SOLVED]
Replies: 17
Views: 16586

Re: Remove port from the default brige [SOLVED]

What happens if you use MAC address rather than IP? I always use MAC where I can as it means I don't lock myself out with L3 problems.
by Steveocee
Mon Dec 10, 2018 1:13 pm
Forum: Beginner Basics
Topic: Remove port from the default brige [SOLVED]
Replies: 17
Views: 16586

Re: Remove port from the default brige [SOLVED]

Are you plugged in to ether2 when you are doing this? If you are connecting to the router via IP, the IP sits on the bridge, if you remove the port from the bridge then you lose your IP connectivity.
by Steveocee
Mon Dec 10, 2018 8:56 am
Forum: Beginner Basics
Topic: DNS defaults to router gateway
Replies: 1
Views: 2023

Re: DNS defaults to router gateway

IP>DHCP-SERVER>NETWORKS

Click into your network and then use the DNS box to full in the DNS servers you want to hand to DHCP clients.

That should work, do an ipconfig release and renew just in case.
by Steveocee
Mon Dec 10, 2018 8:51 am
Forum: Wireless Networking
Topic: wAP ac is slow with manager forwarding and high CPU
Replies: 9
Views: 3400

Re: wAP ac is slow with manager forwarding and high CPU

Do you need to run the traffic locally through manager? The traffic is being tunneled back to the manager hence where the CPU usage is coming from, without tunneling you should get full speed.
by Steveocee
Mon Dec 10, 2018 8:48 am
Forum: Wireless Networking
Topic: Associate with two 5ghz networks at the same time in station mode(client) with SXTsq 5 ac
Replies: 2
Views: 1061

Re: Associate with two 5ghz networks at the same time in station mode(client) with SXTsq 5 ac

You can't connect to two networks as a client regardless of version.

If you had a board with 2 of the 5ghz chips then yes but certainly not through virtual. It simply can't do what you are asking.
by Steveocee
Mon Dec 10, 2018 8:45 am
Forum: Wireless Networking
Topic: Wireless Wire 60Ghz PTP link: weather problems?
Replies: 7
Views: 5033

Re: Wireless Wire 60Ghz PTP link: weather problems?

80m should be fine even with heavy rain. Maybe use the upper channels if you can.

Performance on these is great and I find the quoted distances to be a minimum.
by Steveocee
Sun Dec 09, 2018 11:12 am
Forum: General
Topic: Allow only one country to access router [SOLVED]
Replies: 3
Views: 3877

Re: Allow only one country to access router [SOLVED]

I use similar to exclude a few countries from reaching me and my router (and vice versa). Your router is most likely trying to reach DNS outside your country and updates will be coming from MT (Latvia?) so a different approach is probably needed. If this is for access control you would be better rea...
by Steveocee
Fri Dec 07, 2018 3:45 pm
Forum: RouterBOARD hardware
Topic: pleaaaas help :CCR1036 ether ports doen't respond
Replies: 6
Views: 2511

Re: pleaaaas help :CCR1036 ether ports doen't respond

Serial into it and see if anything is amiss. We use a standard USB-Serial adapter and then a Dev/Null cable in between to get access. Console you will see if ports are disabled or not. Recently had a similar problem not being able to netinstall a CCR and I ended up leaving it connected for around 15...
by Steveocee
Fri Dec 07, 2018 3:42 pm
Forum: Beginner Basics
Topic: SXT LTE traffic Monitor
Replies: 2
Views: 1456

Re: SXT LTE traffic Monitor

You could turn on graphing for the LTE interface, activate the www server (make sure you firewall it properly) and view it locally?
by Steveocee
Fri Dec 07, 2018 2:09 pm
Forum: General
Topic: block p2p on router os version 6.4
Replies: 7
Views: 3205

Re: block p2p on router os version 6.4

Very difficult in general now as most P2P uses encryption.
Hope they integrate IDS/IPS feature in RouterOS in v7.
I like your optimism.
by Steveocee
Fri Dec 07, 2018 2:06 pm
Forum: Beginner Basics
Topic: Ludvigs first experience with routeros, and Pihole.
Replies: 2
Views: 1508

Re: Ludvigs first experience with routeros, and Pihole.

IP > DHCP-Server > Networks Change the DNS server you are handing out to the IP of your Pi-Hole. Done. Be careful with Pi-Hole though, I would be more inclined to statically set the DNS in the client devices rather than blanket the network as I've read recently it has been a bit flakey with provider...
by Steveocee
Fri Dec 07, 2018 2:01 pm
Forum: General
Topic: PoE passive on port 5, same voltage as input
Replies: 1
Views: 734

Re: PoE passive on port 5, same voltage as input

Hex can do 48v in and out but does not have WiFi chip built in. You would need a separate AP.
https://mikrotik.com/product/RB960PGS
by Steveocee
Fri Dec 07, 2018 1:56 pm
Forum: RouterBOARD hardware
Topic: RB4011: wlan1 disabling itself [SOLVED]
Replies: 307
Views: 177641

Re: RB4011: wlan1 disabling itself [SOLVED]

Steveocee: The solution to this is to reduse the 2,4GHz transmit power a bit so that clients sees the 5GHz net as the strongest when close. This would reduce the 2,4GHz theoretical coverage, but normally not the actual/usable coverage, since coverage is normally limited by tx power on client. Yep, ...
by Steveocee
Fri Dec 07, 2018 1:31 pm
Forum: General
Topic: firewall is pushing the cpu
Replies: 23
Views: 9470

Re: firewall is pushing the cpu

Are you sure it is not just somebody trying to attack your router and it's doing it's job? Does/Has the CPU usage subside(d)?
by Steveocee
Fri Dec 07, 2018 12:05 pm
Forum: RouterBOARD hardware
Topic: RB4011: wlan1 disabling itself [SOLVED]
Replies: 307
Views: 177641

Re: RB4011: wlan1 disabling itself [SOLVED]

Are you using the same SSID name for both your 5G network and 2G network? Devices roaming from 5G to 2G would leave the 5G AP as running but not active. My P20 Lite is a PITA as it's dual band and I have done everything I can to get it to prefer 5G but it always ends up on 2.4G
by Steveocee
Fri Dec 07, 2018 11:48 am
Forum: General
Topic: firewall is pushing the cpu
Replies: 23
Views: 9470

Re: firewall is pushing the cpu

With firewalls my personal ethos is drop everything and allow only what you want. Your firewall was allowing what you want and dropping "some" stuff. Your rules can be much simpler if you set them up as per below and that may transpire into better CPU utilisation. Nobody has asked what mod...
by Steveocee
Fri Dec 07, 2018 10:29 am
Forum: General
Topic: Interface-list VS firewall address-list best practices and approach?
Replies: 8
Views: 3117

Re: Interface-list VS firewall address-list best practices and approach?

Its worthwhile stating that one can make up numerous Interface Lists (subset1, newlist23, etc) but the options for each list is fixed at interfaces. Valid entries are: WAN entries, LAN entries, dynamic entries, or No entries They are applied as an Inclusion Entry or an Exclulsion entry. So there is...
by Steveocee
Thu Dec 06, 2018 6:29 pm
Forum: Scripting
Topic: Need help to email ping results / mode button event
Replies: 1
Views: 2016

Re: Need help to email ping results / mode button event

You will need to set up /tools email to work correctly but when done use the below to create a script and then run the script on mode button being pressed; #Define Email variables here :local toEmail toaddress@mikrotik.com :local fromEmail fromaddress@mikrotik.com #Ping Variables :local avgRtt; :loc...
by Steveocee
Thu Dec 06, 2018 5:21 pm
Forum: Beginner Basics
Topic: New hEX S setup, but no internet.
Replies: 1
Views: 823

Re: New hEX S setup, but no internet.

It is doubtful the router is faulty. Most likely a misconfiguration. Please post your config for us so we can see and advise.
Enter into terminal; export hide-sensitive=yes
This will export your config hiding most specific details, ensure to edit out anything else.
by Steveocee
Thu Dec 06, 2018 5:09 pm
Forum: General
Topic: Interface-list VS firewall address-list best practices and approach?
Replies: 8
Views: 3117

Re: Interface-list VS firewall address-list best practices and approach?

I too do similar with my setup. Interface list as an example "WANs" for my 2 WAN interfaces which is good for firewall & NAT rules and make use of address lists in multiple ways. I think of it more as interface-list for hardware interfaces and address-lists for IP related. Sometimes bo...
by Steveocee
Thu Dec 06, 2018 2:18 pm
Forum: General
Topic: Winbox question in regards to traffic
Replies: 6
Views: 2095

Re: Winbox question in regards to traffic

There is a padlock in the top right corner of Winbox. If it is lit and locked you are encrypted. If not then you aren't.
by Steveocee
Thu Dec 06, 2018 12:27 pm
Forum: General
Topic: block p2p on router os version 6.4
Replies: 7
Views: 3205

Re: block p2p on router os version 6.4

Very difficult in general now as most P2P uses encryption.
by Steveocee
Thu Dec 06, 2018 12:05 pm
Forum: General
Topic: HELP MIKROTIK STATIC ROUTE
Replies: 3
Views: 1038

Re: HELP MIKROTIK STATIC ROUTE

You can have multiple routes all with the same priority however RouterOS will prioritise more specific routes over others. In your instance you can set routes to those individual IP's through the relevant WAN interfaces and still have a generic 0.0.0.0/0 rule all with the same priority and them coin...
by Steveocee
Wed Dec 05, 2018 3:48 pm
Forum: General
Topic: pcc does not work with fasttrack
Replies: 4
Views: 1329

Re: pcc does not work with fasttrack

It's useful in certain instances.
by Steveocee
Wed Dec 05, 2018 2:23 pm
Forum: Beginner Basics
Topic: Possible Loop Errors.
Replies: 8
Views: 2885

Re: Possible Loop Errors.

Good info all the way round.
I suspect it may have been this.......... .g. laptop connected to wifi and eth at the same time with those interfaces bridged.
It has not re-occurred yet.
PEBKAC ?
by Steveocee
Wed Dec 05, 2018 1:21 pm
Forum: Scripting
Topic: How to create a loop to add bridge with pre-defined configuration?
Replies: 4
Views: 1496

Re: How to create a loop to add bridge with pre-defined configuration?

Hello,

This shouldn't be too difficult to do, do you need the bridge names to be dynamic some how or just a set name and comment for each? Reading your script you've already made I don't see the need for scripting what could be a few lines of config though?
by Steveocee
Wed Dec 05, 2018 1:06 pm
Forum: General
Topic: Crowd Funding of v7
Replies: 32
Views: 12110

Re: Crowd Funding of v7

It might be easy to hire any kind of developer, but to find a person who can quickly adapt and start working on important v7 RouterOS features - not an easy task. Anyway. Multi Threaded BGP doesn't exist. It will not be coming in v7 and is not implemented in any other brand routers. You can read ot...
by Steveocee
Wed Dec 05, 2018 1:04 pm
Forum: General
Topic: the pcc dose not work when it works with fasttrack
Replies: 18
Views: 4997

Re: the pcc dose not work when it works with fasttrack

PCC requires mangle and connection tracking to work.
Fast track removes all connection tracking in an effort to process packets faster.

No bug. No magic.
by Steveocee
Wed Dec 05, 2018 1:01 pm
Forum: Beginner Basics
Topic: Asociation
Replies: 1
Views: 682

Re: Asociation

Very open ended question with not enough detail.

An unhelpful answer would be: Are they both turned on?
A helpful answer would be, please post your configs for all to see and help you.

Both answers are applicable with ambiguity of question.
by Steveocee
Wed Dec 05, 2018 10:31 am
Forum: Beginner Basics
Topic: Possible Loop Errors.
Replies: 8
Views: 2885

Re: Possible Loop Errors.

Hey Steve, can you elaborate? My bridge has a mac assigned, why would one need to assign it a different one? Or Are you saying that each interface to bridge interaction should see a different bridge mac address and if so how to do that??? By default the bridge uses auto-mac which grabs the MAC addr...
by Steveocee
Tue Dec 04, 2018 6:02 pm
Forum: Scripting
Topic: Limit user/IP by volume
Replies: 2
Views: 1326

Re: Limit user/IP by volume

Where is "total-bytes" coming from? The router does not register or hold this information unless using hotspot.
by Steveocee
Tue Dec 04, 2018 2:23 pm
Forum: Beginner Basics
Topic: Possible Loop Errors.
Replies: 8
Views: 2885

Re: Possible Loop Errors.

It can be helpful setting a MAC address for your bridge. I generally tend to use ether1 MAC as a template so if the MAC is 00:01:02 I will increment the second character by 2 so it becomes a made up MAC of 02:01:02 and this has resolved these situations before.
by Steveocee
Mon Dec 03, 2018 5:42 pm
Forum: Beginner Basics
Topic: Can't connect to 192.168.88.1 and winbox wrong username
Replies: 1
Views: 1132

Re: Can't connect to 192.168.88.1 and winbox wrong username

How are you trying to reset? You can't just push the reset button with MT. Are you deploying this to a public facing connection straight away? Try resetting (properly) then connecting only your computer to the device, ensure you use a decent admin password in doing so. To reset you need to hold rese...
by Steveocee
Mon Dec 03, 2018 5:39 pm
Forum: Beginner Basics
Topic: Netinstall not install routeros
Replies: 3
Views: 1162

Re: Netinstall not install routeros

Try having console open and watch what it says to do. I had similar and the router was waiting for a reboot.
by Steveocee
Mon Dec 03, 2018 5:02 pm
Forum: RouterBOARD hardware
Topic: RB4011: wlan1 disabling itself [SOLVED]
Replies: 307
Views: 177641

Re: RB4011: wlan1 disabling itself [SOLVED]

What does it say in the logs?
5Ghz may be disabling itself if it "thinks" it is seeing DFS and is in a DFS channel. You need to provide more of your config for further help.
by Steveocee
Mon Dec 03, 2018 10:53 am
Forum: Wireless Networking
Topic: Improve PTMP download
Replies: 11
Views: 2990

Re: Improve PTMP download

Even with a fully implemented and well working TDMA I would not expect you to be able to manage a 10Mb upload from one client whilst still providing anywhere near 70Mb to the others as download. For the cost of a single CPE it's worth keeping your 16 customers happy so 1 doesn't ruin the experience ...
by Steveocee
Fri Nov 30, 2018 5:42 pm
Forum: Beginner Basics
Topic: 750Gr3 Private Internet Access PPTP
Replies: 8
Views: 3550

Re: 750Gr3 Private Internet Access PPTP

Your PPTP client is creating it's own route which is not helping /interface pptp-client add add-default-route=yes connect-to=XXXX.privateinternetaccess.com \ dial-on-demand=yes disabled=no name=PPTP-PIA password=XXXXX user=\ XXXXX Should be /interface pptp-client add add-default-route=no connect-to=...
by Steveocee
Fri Nov 30, 2018 5:34 pm
Forum: RouterBOARD hardware
Topic: Non-Microtik SFP+ DAC with CRS317... is it OK?
Replies: 5
Views: 3211

Re: Non-Microtik SFP+ DAC with CRS317... is it OK?

MikroTik and UBNT SFP compatibility is quite good. I've just deployed a pair of UBNT SFP's one end to a UniFi switch and the other to a hAP AC.
by Steveocee
Fri Nov 30, 2018 11:37 am
Forum: General
Topic: CoDel support?
Replies: 46
Views: 20526

Re: CoDel support?

Any update?
Not available (yet) but both SFQ and PCQ can provide a solution if you don't have brand flexibility.
by Steveocee
Thu Nov 29, 2018 4:32 pm
Forum: Wireless Networking
Topic: Improve PTMP download
Replies: 11
Views: 2990

Re: Improve PTMP download

I would be very tempted to install an additional piece of hardware to serve this client on their own link leaving your large sector for the others.

It's that upload with TDMA that is affecting you. I doubt there is very little you can do to mitigate it doing this other than splitting the load.
by Steveocee
Thu Nov 29, 2018 10:30 am
Forum: RouterBOARD hardware
Topic: Can anyone help me identify this routerboard?
Replies: 2
Views: 1378

Re: Can anyone help me identify this routerboard?

Agreed. Certainly not an RB. Most likely an Alix as previously mentioned.
by Steveocee
Thu Nov 29, 2018 10:27 am
Forum: RouterBOARD hardware
Topic: Routerboard Spec Recommendation
Replies: 6
Views: 2138

Re: Routerboard Spec Recommendation

The Hex(s) would only be as powerful if a little less than your current router so I would steer away from that if possible. RB4011 is a relatively decent choice although I would argue that as this is effectively a corporate and production environment it would be very good justification to run in a C...
by Steveocee
Tue Nov 27, 2018 10:44 am
Forum: General
Topic: SFP+ conflict with Another Ether port (ISP) [SOLVED]
Replies: 7
Views: 1799

Re: SFP+ conflict with Another Ether port (ISP) [SOLVED]

You don't have the ether into the combo port do you? Combo is 1 or the other and not both.
by Steveocee
Tue Nov 27, 2018 10:42 am
Forum: Virtualization
Topic: CHR disk size
Replies: 6
Views: 7004

Re: CHR disk size

If you add it through ESXi as you normally would then it should present in RouterOS as "Disk1" or similar.
by Steveocee
Tue Nov 27, 2018 10:39 am
Forum: Beginner Basics
Topic: Explain what a Master/Slave interface is
Replies: 6
Views: 37053

Re: Explain what a Master/Slave interface is

If you WAN links are more than 100/100 then I'd recommend getting a dedicated router and switch rather than the CRS112 I'm currently targeting routing between dual Gigabit WAN links (800/200Mb/s for download/upload on each) and 20 WiFi access point. Which product withing [1] Mikrotik routers range ...
by Steveocee
Mon Nov 26, 2018 11:44 pm
Forum: Beginner Basics
Topic: Filter traffic in bridg.
Replies: 9
Views: 1778

Re: Filter traffic in bridg.

Can we get some example of your config?
by Steveocee
Mon Nov 26, 2018 11:32 pm
Forum: Forwarding Protocols
Topic: Can I enable UPnP on my local bridged ap [SOLVED]
Replies: 1
Views: 1805

Re: Can I enable UPnP on my local bridged ap [SOLVED]

Your ISP will need to make this change for you. It's incredibly simple and easy for them to set up but UPnP is looked down on due to it being a huge security risk. You may be better off setting your XBOX to a static non DHCP ranged IP and then asking for relevant ports to be forwarded to it. Your ho...
by Steveocee
Mon Nov 26, 2018 11:29 pm
Forum: General
Topic: SFP+ conflict with Another Ether port (ISP) [SOLVED]
Replies: 7
Views: 1799

Re: SFP+ conflict with Another Ether port (ISP) [SOLVED]

How do you want to use your 2 connections? Are you wanting to load balance them or have a simple failover? Simple failover could be achieved like this; /ip route add check-gateway=ping distance=1 gateway=PRIMARY_WAN_INTERFACE add distance=2 gateway=SECONDARY_WAN_INTERFACE For your NAT rules I would ...
by Steveocee
Mon Nov 26, 2018 11:22 pm
Forum: Beginner Basics
Topic: Failover dual ISP with 6.4x OS
Replies: 4
Views: 1333

Re: Failover dual ISP with 6.4x OS

I use a far simpler version of what @anav uses but probably just as viable for you. It's fast, simple and doesn't require any scripting either (nice for a MT solution). This takes anav's approach and uses the actual WAN interfaces, my personal ones are pppoe_client1 and 2 but you get the idea. /ip r...
by Steveocee
Mon Nov 26, 2018 11:18 pm
Forum: Beginner Basics
Topic: Firewall rule effectiveness
Replies: 4
Views: 1081

Re: Firewall rule effectiveness

Firewall rules run from top to bottom. It's good practise to have a "drop all" at the bottom anyway but if you wanted something as a counter then yes you could move it higher up. Due to the way traffic "cascades" though if a packet matches on a rule higher up then it won't cascad...
by Steveocee
Mon Nov 26, 2018 11:17 pm
Forum: Beginner Basics
Topic: Explain what a Master/Slave interface is
Replies: 6
Views: 37053

Re: Explain what a Master/Slave interface is

Master/Slave relationship used to be when you wanted to switch interfaces on the same switch chip. The master was designated as a "main" interface with all slaves able to switch to it, from itand between each other. 6.41 flipped that on it's head with the "new" bridge implementat...
by Steveocee
Mon Nov 26, 2018 11:11 pm
Forum: Beginner Basics
Topic: mANTBox to hEX S
Replies: 3
Views: 898

Re: mANTBox to hEX S

Hi Carlos, The mANT mentioned will be fine for what you want. Although all (well most) MikroTik kit has fully fledged RouterOS running on it, it's incredibly versatile in that it can be configured to do more or less anything you want. If you wanted to achieve what you said in your OP you can simply ...
by Steveocee
Mon Nov 26, 2018 11:06 pm
Forum: Beginner Basics
Topic: Avoid double PAT
Replies: 5
Views: 1259

Re: Avoid double PAT

What are you doing that double PAT is becoming a problem? I only ask because there is so much "oooooooh don't do that" about this but rarely is the root cause mentioned other than the originator has "read it's bad". What are you struggling doing OP? Is there any room to speak wit...
by Steveocee
Mon Nov 26, 2018 4:47 pm
Forum: Virtualization
Topic: CHR disk size
Replies: 6
Views: 7004

Re: CHR disk size

Maybe both are correct?
System disk size can only be up to 16GB however that does not stop you adding additional disk at a size of your choice?
by Steveocee
Sat Nov 24, 2018 9:06 am
Forum: Beginner Basics
Topic: newbie
Replies: 4
Views: 1799

Re: newbie

So you bought this pre configured by liberty?
If you did and you net install them you will lose all settings, some people can be very rash with suggestions on here.

Do you want to actually reset the device to factory or simply gain access and add an extra VPN tunnel,?
by Steveocee
Thu Nov 22, 2018 5:09 pm
Forum: Beginner Basics
Topic: DHCP Clients don't resolve static DNS entries [SOLVED]
Replies: 1
Views: 1019

Re: DHCP Clients don't resolve static DNS entries [SOLVED]

You can also encourage (read as force) people to use your DNS with the below as well, just make sure they are placed at the top of your NAT table. /ip firewall nat add action=redirect chain=dstnat comment="DNS Loopback" dst-port=53 protocol=tcp src-address=192.168.109.0/24 add action=redir...
by Steveocee
Thu Nov 22, 2018 4:42 pm
Forum: General
Topic: Print system configuration
Replies: 5
Views: 28245

Re: Print system configuration

Using export via terminal is the best way to "see" your config in it's raw format. A slightly more person friendly approach would be to do something like; export file=myrouterexport This saves the export locally. Then using Winbox go into "Files" and download the complete RSC file.
by Steveocee
Thu Nov 22, 2018 4:24 pm
Forum: Beginner Basics
Topic: Filter traffic in bridg.
Replies: 9
Views: 1778

Re: Filter traffic in bridg.

Are you using hardware offload? If so, turn it off as this will negate that.
by Steveocee
Thu Nov 22, 2018 4:23 pm
Forum: General
Topic: Can't get 1Gbps on CRS125-24G-1S-2HnD
Replies: 7
Views: 1880

Re: Can't get 1Gbps on CRS125-24G-1S-2HnD

Yep, this is default value now, even for Gb capable switch (?) [admin@Mancave-Switch] > /interface ethernet export # nov/22/2018 14:20:55 by RouterOS 6.43.4 # software id = DV88-GETP # # model = CRS125-24G-1S # serial number = REMOVED /interface ethernet set [ find default-name=ether1 ] speed=100Mbp...
by Steveocee
Thu Nov 22, 2018 12:54 pm
Forum: General
Topic: Can't get 1Gbps on CRS125-24G-1S-2HnD
Replies: 7
Views: 1880

Re: Can't get 1Gbps on CRS125-24G-1S-2HnD

What happens if you remove auto negotiation, can you force Gb?
by Steveocee
Thu Nov 22, 2018 12:50 pm
Forum: Beginner Basics
Topic: IP Based Bandwidth Priority
Replies: 1
Views: 672

Re: IP Based Bandwidth Priority

This is very easily doable using a simple queue however you'd need to give some more details for anybody to give you a meaningful response that you can glean config from.
by Steveocee
Thu Nov 22, 2018 12:48 pm
Forum: Beginner Basics
Topic: Filter bridged traffic
Replies: 1
Views: 623

Re: Filter bridged traffic

Making more threads just halves the attention 8)
viewtopic.php?f=13&t=141884
by Steveocee
Thu Nov 22, 2018 12:47 pm
Forum: Beginner Basics
Topic: Filter traffic in bridg.
Replies: 9
Views: 1778

Re: Filter traffic in bridg.

I'm not totally understanding what you are asking? Is this filtering out port 21 on outbound traffic or just internally?
by Steveocee
Thu Nov 22, 2018 12:45 pm
Forum: Beginner Basics
Topic: Blocked router
Replies: 3
Views: 947

Re: Blocked router

If you are physically connected to the router then you should be able to use L2 MAC connection through Winbox.
by Steveocee
Thu Nov 22, 2018 11:26 am
Forum: RouterBOARD hardware
Topic: PoE In, Hex Lite
Replies: 2
Views: 907

Re: PoE In, Hex Lite

Passive only and 24v at that. I thought Netgear "only" did 48v PoE

https://mikrotik.com/product/RB750r2
by Steveocee
Thu Nov 22, 2018 11:23 am
Forum: General
Topic: Queue Trees, CPU Utilization and Watchdog reboots
Replies: 12
Views: 3544

Re: Queue Trees, CPU Utilization and Watchdog reboots

Your rules don't look especially heavy, I've had similar amounts running on an RB951Ui which on paper has a worse CPU (read that "on paper" part though). Saying that the RB951Ui often in my testing performs better with Btest then the hap AC which should be better due to the newer and faste...
by Steveocee
Thu Nov 22, 2018 10:56 am
Forum: Beginner Basics
Topic: Mikrotik RB960PGS with Ubiquiti AP
Replies: 1
Views: 1104

Re: Mikrotik RB960PGS with Ubiquiti AP

Would be fine.
I use a Hex PoE Lite at my parents paired with one of the older UAP-AC-LR's which runs from 24v and the pairing has always been rock solid.
by Steveocee
Thu Nov 22, 2018 10:32 am
Forum: Beginner Basics
Topic: Fast failover
Replies: 4
Views: 2287

Re: Fast failover

This is the basic setup I use for both my main internet connections as well as my VPN setups, it's fast (very) and requires no additional scripting or netwatch usage. Just ensure your pppoe client does not create it's own default route. /ip route add check-gateway=ping comment=Internet distance=1 ga...
by Steveocee
Wed Nov 21, 2018 5:46 pm
Forum: General
Topic: Why blacklist burteforcers VS just dropping the ports/service?
Replies: 7
Views: 2078

Re: Why blacklist burteforcers VS just dropping the ports/service?

Pre-empting the worst is probably the best summary.
If they're poking at certain ports when they shouldn't then you probably don't want them poking at anything.
by Steveocee
Wed Nov 21, 2018 4:54 pm
Forum: Beginner Basics
Topic: client connect to wifi in other room - why [SOLVED]
Replies: 9
Views: 3214

Re: client connect to wifi in other room - why [SOLVED]

Roaming in this way is driven by the client device, you can have the best setup in the world but a sticky client won't move. You can try to encourage this movement by ensuring you are using non overlapping channels and employing a minimum RSSI on the AP's.
by Steveocee
Wed Nov 21, 2018 4:20 pm
Forum: Scripting
Topic: Need to hire script consultant
Replies: 6
Views: 2031

Re: Need to hire script consultant

I've dropped you an email. My extract has probably 95% of what you need, just need to change the line that grabs the MAC address to grab the SN and you should be good to go.
by Steveocee
Tue Nov 20, 2018 9:29 am
Forum: Forwarding Protocols
Topic: Redirect DNS to Local Server
Replies: 12
Views: 35994

Re: Redirect DNS to Local Server

A dst-nat rule should do this week enough. If you match against anything destined TCP/UDP 53 and just dst-nat it to your server you can rule all dns through it.

Have you specified it on the DHCP server as well or is the MT not doing that?
by Steveocee
Mon Nov 19, 2018 6:48 pm
Forum: General
Topic: Management high CPU on lots of Mikrotiks today - DDoS??
Replies: 15
Views: 2952

Re: Management high CPU on lots of Mikrotiks today - DDoS??

Glad you got it sorted.
Maybe just shuffle the "accept dst-nat" rule to number 3? You really want the rules with the most traffic towards the top so the packets are not delayed in being handled and est&rel will be the highest ones (in most applications).
by Steveocee
Mon Nov 19, 2018 5:24 pm
Forum: General
Topic: Management high CPU on lots of Mikrotiks today - DDoS??
Replies: 15
Views: 2952

Re: Management high CPU on lots of Mikrotiks today - DDoS??

Thanks for some feedback - i will look at making a few amendments to my base config generator to include some enhancements to the firewall. I have remove the IPs / screenshots from the post above Just removed my home routers firewall config with this to see how it works .. we specialise in VoIP so ...
by Steveocee
Mon Nov 19, 2018 5:15 pm
Forum: Beginner Basics
Topic: Kid Control
Replies: 6
Views: 1095

Re: Kid Control

I agree but just strange it allows it on Sat...
Because.......





MikroTik
by Steveocee
Mon Nov 19, 2018 5:06 pm
Forum: General
Topic: Management high CPU on lots of Mikrotiks today - DDoS??
Replies: 15
Views: 2952

Re: Management high CPU on lots of Mikrotiks today - DDoS??

You probably wouldn't with that implementation. You are only FT'ing the "input" traffic and not the "forward" with that rule. Once you apply it to the forward chain then things start to get a lot more interesting but it begs the question if you really "need" to? Trying ...
by Steveocee
Mon Nov 19, 2018 4:52 pm
Forum: Beginner Basics
Topic: Kid Control
Replies: 6
Views: 1095

Re: Kid Control

00:00:00-23:59:59
I doubt that second will go astray.
by Steveocee
Mon Nov 19, 2018 4:17 pm
Forum: General
Topic: Management high CPU on lots of Mikrotiks today - DDoS??
Replies: 15
Views: 2952

Re: Management high CPU on lots of Mikrotiks today - DDoS??

DNS is also open to the world!! Your firewall rules fast track anything going input then you have drop rules after this which will never work as you have already fast tracked the traffic. steve@general:~$ dig forum.mikrotik.com @X.X.X.X ; <<>> DiG 9.10.3-P4-Ubuntu <<>> forum.mikrotik.com @X.X.X.X ;;...
by Steveocee
Mon Nov 19, 2018 4:02 pm
Forum: Beginner Basics
Topic: Kid Control
Replies: 6
Views: 1095

Re: Kid Control

"00:00:00-00:00:00"

I think is what you want.
by Steveocee
Fri Nov 16, 2018 5:09 pm
Forum: Virtualization
Topic: CHR neighbour discovery problem
Replies: 13
Views: 12822

Re: CHR neighbour discovery problem

So quick follow up. MikroTik support have so far been very responsive however the implication is currently that the issue is with my computers L2 connectivity. My desktop and 2 laptops can't discover it (cabled and 2 wireless) however the 'Tik App on my phone on the same wireless AP as the laptops C...
by Steveocee
Fri Nov 16, 2018 3:58 pm
Forum: Forwarding Protocols
Topic: Interconnect two different network
Replies: 3
Views: 4938

Re: Interconnect two different network

If both networks are running from the one single RB2011 in the middle then you do not need to do anything to get them talking. Both networks are connected to a "router" so it will naturally route between them.
by Steveocee
Fri Nov 16, 2018 2:19 pm
Forum: Beginner Basics
Topic: rookie Port Forward for PS4 [SOLVED]
Replies: 15
Views: 9126

Re: rookie Port Forward for PS4 [SOLVED]

Right, the picture helps. >You need ALL the numbers you have mentioned >You need to change the in-interface to pppoe-out1 >You need another rule for the UDP traffic, to do this, open up your current one and choose "copy" which will open up another window copied from the first, go to genera...
by Steveocee
Fri Nov 16, 2018 11:04 am
Forum: Beginner Basics
Topic: Double port forwarding [SOLVED]
Replies: 5
Views: 2427

Re: Double port forwarding [SOLVED]

I think you want something like this, you won't be able to copy/paste it as my in-interface name is probably different to yours, change this for your WAN interface name and it should work.; /ip firewall nat add action=dst-nat chain=dstnat comment=example-rule dst-port=3189 in-interface=ether1_WAN pr...
by Steveocee
Fri Nov 16, 2018 10:56 am
Forum: Beginner Basics
Topic: rookie Port Forward for PS4 [SOLVED]
Replies: 15
Views: 9126

Re: rookie Port Forward for PS4 [SOLVED]

This will guide you through; https://www.youtube.com/watch?v=3ni_R03OOrg thanks but i know those things, i just don't know which one of these numbers is the port ! TCP: 1935,3478-3480 UDP: 3074,3478-3479 right now i put this (3478-3480) for both ports and chose Wlan1 for "In Interface" an...
by Steveocee
Thu Nov 15, 2018 5:52 pm
Forum: Beginner Basics
Topic: rookie Port Forward for PS4 [SOLVED]
Replies: 15
Views: 9126

Re: rookie Port Forward for PS4 [SOLVED]

This will guide you through;
https://www.youtube.com/watch?v=3ni_R03OOrg
by Steveocee
Wed Nov 14, 2018 1:31 pm
Forum: General
Topic: Shapeing 10G of traffic
Replies: 15
Views: 3902

Re: Shapeing 10G of traffic

How are you planning on shaping the traffic? (Out of interest).
I would recommend CHR as it is a "current" product where X86 has been left behind a bit in terms of hardware support.
by Steveocee
Wed Nov 14, 2018 12:57 pm
Forum: Beginner Basics
Topic: Down ports
Replies: 1
Views: 592

Re: Down ports

Your problem looks to be the same as others have found a common issue here;
viewtopic.php?f=3&t=128762&p=693740&hil ... ng#p693740
by Steveocee
Wed Nov 14, 2018 12:52 pm
Forum: Beginner Basics
Topic: wAP ac upgrade and wireless problems
Replies: 5
Views: 1414

Re: wAP ac upgrade and wireless problems

I think you are confusing routeros version a bit with your routerboard FW. If you are uploading the file to the wAP, do a system > reboot. That will initiate an update of routerOS. Once routerOS is updated go to system > routerboard and you will see that the 6.43.4 FW is available for the board. Hit...
by Steveocee
Tue Nov 13, 2018 4:50 pm
Forum: Beginner Basics
Topic: 3011 update
Replies: 10
Views: 2291

Re: 3011 update

I see so I have been using the wrong file for uprade ehhhhhhhh ok I will check the architecture and let you know
It's ARM like the poster above has said.
by Steveocee
Tue Nov 13, 2018 1:56 pm
Forum: General
Topic: l2tp with ipsec clients behind NAT no work
Replies: 3
Views: 3157

Re: l2tp with ipsec clients behind NAT no work

I too get this however it is not so much a problem as expected behaviour. You can use split VPN types as you have found or you could set up a VPN from the router and some sort of policy based routing to get around this.
by Steveocee
Tue Nov 13, 2018 9:24 am
Forum: Beginner Basics
Topic: DHCP issue [SOLVED]
Replies: 9
Views: 3167

Re: DHCP issue [SOLVED]

It sounds like there is a second DHCP server on your network. Maybe you have bridged the WAN interface? Could be a possibility. Try turning off your dhcp server and then connect to your network as dhcp client to check. Also posting config is needed with most problems, 95% of it will not be unique to...
by Steveocee
Mon Nov 12, 2018 4:16 pm
Forum: General
Topic: Migrating CRS125-24G-1S-RM from master-port to bridge
Replies: 3
Views: 893

Re: Migrating CRS125-24G-1S-RM from master-port to bridge

Thank you for your reply. But it's vary sad...
It's a change to how you need to operate. Sad in the short term I agree but once you adjust your working methods. It will become second nature as it currently is.
by Steveocee
Mon Nov 12, 2018 3:41 pm
Forum: RouterBOARD hardware
Topic: hAP AC2 availability
Replies: 26
Views: 8634

Re: hAP AC2 availability

We are the biggest UK distributor for MikroTik and we have stock: https://linitx.com/product/mikrotik-routerboard-hap-ac2-with-uk-psu-tower-shape/15370 Hope that helps Nick I live in EU, not in UK. Issue is for EU not UK. :) Good job they ship to the EU then!!! https://linitx.com/info/shippingreturns
by Steveocee
Sat Nov 10, 2018 7:22 pm
Forum: RouterBOARD hardware
Topic: RB1100AHx4 drops packets when CPU spikes to 20% and above
Replies: 1
Views: 1555

Re: RB1100AHx4 drops packets when CPU spikes to 20% and above

35% of a quad core is 100% load of a core in single core application. Total utilisation doesn't tell you this, if you check profile when CPU is that high I reckon you have a maxed out core hence the packet drops.
by Steveocee
Sat Nov 10, 2018 7:18 pm
Forum: General
Topic: Webfig remote access from WAN
Replies: 18
Views: 27477

Re: Webfig remote access from WAN

You will need to post your config to let everyone see and help.
by Steveocee
Fri Nov 09, 2018 6:11 pm
Forum: Wireless Networking
Topic: LHG 60G experience
Replies: 608
Views: 194102

Re: LHG 60G experience

Hi Steve, Just send me the airline tickets and I will be glad to stand at one end of the connection to move things around. I am really lucky ;-) On the other hand the fetid vapours of intoxicated Brits (on warm beer) may be a cloud to dense for your traffic ;-PP That's it. Must be the toxicity of t...
by Steveocee
Fri Nov 09, 2018 3:49 pm
Forum: Wireless Networking
Topic: LHG 60G experience
Replies: 608
Views: 194102

Re: LHG 60G experience

My 2.6Km link does not want to link up. I'm using 64800 as not totally sure about legalities of 66Ghz in the UK yet. Little bit gutted as I expected at least something. Apparently you do not direct the antenna. We previously worked with SIKLU so there is experience. The main thing that would be dir...
by Steveocee
Fri Nov 09, 2018 2:27 pm
Forum: Wireless Networking
Topic: LHG 60G experience
Replies: 608
Views: 194102

Re: LHG 60G experience

My 2.6Km link does not want to link up. I'm using 64800 as not totally sure about legalities of 66Ghz in the UK yet. Little bit gutted as I expected at least something.
by Steveocee
Fri Nov 09, 2018 11:01 am
Forum: General
Topic: Management Network for router access?
Replies: 10
Views: 3216

Re: Management Network for router access?

It's a great idea to have a management network if your end devices can be separated like that. Once you are in a SOHO/SMB environment then this becomes almost standard to have multiple LANs (/vlans). The trick is ensuring nobody simply plugs in to your MGMT network to access the devices. Ensuring yo...
by Steveocee
Wed Nov 07, 2018 10:55 am
Forum: Beginner Basics
Topic: How can I config. so that LAN 1 goes to WAN 1, and LAN 2 goes to WAN 2 with "failover"?
Replies: 3
Views: 823

Re: How can I config. so that LAN 1 goes to WAN 1, and LAN 2 goes to WAN 2 with "failover"?

Pardon me for asking but is there a specific "need" to have the traffics behave in this way?
You could simplify your life massively by using a PCQ load balanced queue and balancing over the 2 connections which would introduce failover as well.
by Steveocee
Wed Nov 07, 2018 10:53 am
Forum: Scripting
Topic: Put Latency on Graph
Replies: 1
Views: 1042

Re: Put Latency on Graph

Smokeping.
by Steveocee
Wed Nov 07, 2018 10:51 am
Forum: Forwarding Protocols
Topic: Firewall filter rules ordering
Replies: 7
Views: 23271

Re: Firewall filter rules ordering

Setting up a NAT rule is not enough. If your firewall is blocking the connection then the NAT rule will not work. You'd be better doing an export of both your firewall filters and NAT table for everyone to see and advise on. The default config has a rule to drop anything non-dst NAT'd which is very ...
by Steveocee
Tue Nov 06, 2018 5:31 pm
Forum: Announcements
Topic: Newsletter 85
Replies: 30
Views: 24268

Re: Newsletter 85

CRS305-1G-4S+IN Maybe a stupid question but could one use the above device as an ethernet translation/adapter device (ethernet in from the LAN, fibre out to specific locations or devices)? The info says the ethernet is strictly for management so me thinks not. You could use an SFP+ to ether net ada...
by Steveocee
Tue Nov 06, 2018 3:39 pm
Forum: General
Topic: CRS125 poor throughput & low cpu load [SOLVED]
Replies: 41
Views: 8629

Re: CRS125 poor throughput & low cpu load [SOLVED]

Which one would be recommended? Small physical size would be good for me...
Where is your budget at? A hAP AC2 could do what you want but so could a CCR1009. Budget plays a part.
I take it the CRS125 can be reused as a switch if you need that many ethernet ports?
by Steveocee
Tue Nov 06, 2018 3:04 pm
Forum: General
Topic: CRS125 poor throughput & low cpu load [SOLVED]
Replies: 41
Views: 8629

Re: CRS125 poor throughput & low cpu load [SOLVED]

So, I have too much firewall rules and/or too much VLAN routing?
Yes.
by Steveocee
Tue Nov 06, 2018 10:49 am
Forum: General
Topic: CRS125 poor throughput & low cpu load [SOLVED]
Replies: 41
Views: 8629

Re: CRS125 poor throughput & low cpu load [SOLVED]

You need a ROUTER not a SWITCH WITH L3 CAPABILITY.
Your config is far beyond what I would ever want to deploy onto a CRS125, you are asking too much of it.
by Steveocee
Tue Nov 06, 2018 10:45 am
Forum: Virtualization
Topic: CHR neighbour discovery problem
Replies: 13
Views: 12822

Re: CHR neighbour discovery problem

I suggest you all write to Mikrotik support, seeing as they clearly don't believe me - based on the fact that they have done NOTHING about this bug in the last 9 months.
Posting here is essentially pointless.
Done.
by Steveocee
Mon Nov 05, 2018 10:26 pm
Forum: RouterBOARD hardware
Topic: Desired switch
Replies: 7
Views: 2213

Re: Desired switch

Would be nice if CRS112 was half rack width with option to join 2 together to make 16 port full width.
by Steveocee
Mon Nov 05, 2018 6:16 pm
Forum: Beginner Basics
Topic: how to Config Mikrotik with 1:1 bandwitdh ratio
Replies: 5
Views: 1203

Re: how to Config Mikrotik with 1:1 bandwitdh ratio

How are you auth'ing these users?

You can build contention groups within simple queues without too much problems. Just need a way of identifying who is in which pipe;
https://wiki.mikrotik.com/wiki/Manual:HTB
by Steveocee
Mon Nov 05, 2018 6:12 pm
Forum: Beginner Basics
Topic: Can't copy big files through VPN
Replies: 3
Views: 1963

Re: Can't copy big files through VPN

SMB over the web is hideous. Latency will affect the performance massively. If you can you might be better trying to get an FTP or SFTP up and attack it that way.
by Steveocee
Mon Nov 05, 2018 4:56 pm
Forum: Beginner Basics
Topic: DNS: Difference between "IP>DNS" and "DHCP>Networks" [SOLVED]
Replies: 25
Views: 12755

Re: DNS: Difference between "IP>DNS" and "DHCP>Networks" [SOLVED]

Interesting as both statements can actually be correct at the same time if you read the information as a whole..... User added entries (user in place of admin, you know, the ones you specify yourself) take priority over servers gained dynamically -HOWEVER- If a server is gained dynamically BEFORE a ...
by Steveocee
Mon Nov 05, 2018 4:51 pm
Forum: RouterBOARD hardware
Topic: 60Ghz Perplexed
Replies: 6
Views: 2463

Re: 60Ghz Perplexed

Normis I understand your comment about 8 Clients 125Mbps etc, but the problem is we are competing with full fibre installs in the UK and a speed test at 100Mbps is not what they signed up for or expect. We offer 100, 250, 500 and 1Gbps plans and having that missing product in the middle is a real p...
by Steveocee
Mon Nov 05, 2018 4:45 pm
Forum: RouterBOARD hardware
Topic: FTTH FIBER 200MB
Replies: 4
Views: 1717

Re: FTTH FIBER 200MB

This implies that the router is certainly capable;
https://mikrotik.com/product/RB951G-2Hn ... estresults

Most likely an issue with your configuration. Can you post an export for all to see?
by Steveocee
Mon Nov 05, 2018 10:49 am
Forum: Beginner Basics
Topic: DNS: Difference between "IP>DNS" and "DHCP>Networks" [SOLVED]
Replies: 25
Views: 12755

Re: DNS: Difference between "IP>DNS" and "DHCP>Networks" [SOLVED]

Unless you find an alternate reference stating otherwise, I think you may owe me some brewskis :-)))))) "When both static and dynamic servers are set, static server entries are more preferred, however it does not indicate that static server will always be used (for example, previously query wa...
by Steveocee
Sun Nov 04, 2018 11:47 am
Forum: Beginner Basics
Topic: DNS: Difference between "IP>DNS" and "DHCP>Networks" [SOLVED]
Replies: 25
Views: 12755

Re: DNS: Difference between "IP>DNS" and "DHCP>Networks" [SOLVED]

Hi Steve, - DHCP Client, USE PEER DNS, instructs the router to use ISP DNS servers - IP DNS, allows one to enter in manually selected DNS Servers such as google and dyndns They both show up on the IP DNS page, and from what I gather the USE PEER DNS takes precedence and thus although one may have g...
by Steveocee
Sat Nov 03, 2018 1:27 pm
Forum: Scripting
Topic: Blacklist Filter (Development Topic)
Replies: 188
Views: 62631

Re: Blacklist Filter (Development Topic)

For IntusDave:
Do you have any problem or do you update? I run your script but the script didn't download nothing.

I thank you for your help!
Are you running IP > Cloud ? Would be the "easiest" thing to check at this point as it is a prerequisite.
by Steveocee
Sat Nov 03, 2018 11:18 am
Forum: Beginner Basics
Topic: Bypass simple Queue
Replies: 2
Views: 1980

Re: Bypass simple Queue

Create a another simple queue above your current one with target IP as your 1 device which will take priority.

Or you can create fast track rule for your 1 device which will then stop using queues.
by Steveocee
Sat Nov 03, 2018 9:53 am
Forum: RouterBOARD hardware
Topic: Desired switch
Replies: 7
Views: 2213

Re: Desired switch

I think the answer in your use is to simply get a CRS328 which is a little more expensive but has some "growing room". https://mikrotik.com/product/crs328_24p_4s_rm I hope that dedicated PoE and non-PoE ports will not be a thing in the future and they adopt the standard they are currently ...
by Steveocee
Fri Nov 02, 2018 12:31 pm
Forum: Beginner Basics
Topic: Need a Public IP for MY local network
Replies: 1
Views: 542

Re: Need a Public IP for MY local network

Yes the simplest way would be to run a VPN over the router and then forward ports from the VPN IP address to your server. This would work in fairness like a PPPoE connection.
by Steveocee
Thu Nov 01, 2018 6:55 pm
Forum: Wireless Networking
Topic: Big Mall Wireless Design
Replies: 1
Views: 1001

Re: Big Mall Wireless Design

Being totally honest you sound like you need a local consultant rather than help from the community with this. It's not just the design but the implementation as well will need to be very specific and a local consultant will be able to do all of this for you. For kit, the cAP or wAP AC would probabl...
by Steveocee
Thu Nov 01, 2018 5:03 pm
Forum: Virtualization
Topic: CHR neighbour discovery problem
Replies: 13
Views: 12822

Re: CHR neighbour discovery problem

I too have this problem. Winbox finds all RB & CRS devices in my network but my CHR takes about 4 tries to discover if at all.
by Steveocee
Thu Nov 01, 2018 1:54 pm
Forum: RouterBOARD hardware
Topic: PoE in on eth1 shuts RB2011 down
Replies: 1
Views: 1304

Re: PoE in on eth1 shuts RB2011 down

We have been using the RB2011 boards for some time now and have just recently experienced two units that will shut down when eth1 is plugged into a cisco poe switch. Works great when the poe is turned off on the switch port but is there any explanation as to why our past units are fine and only rec...
by Steveocee
Mon Oct 29, 2018 5:16 pm
Forum: General
Topic: Client wants to access NAT'd web server from inside LAN using WAN IP [SOLVED]
Replies: 4
Views: 3254

Re: Client wants to access NAT'd web server from inside LAN using WAN IP [SOLVED]

Take what you need from this. Explains how to hairpin NAT, create the correct port forwards and can be adapted for dynamic or static WAN IP (plus some comedy phrases);
https://www.youtube.com/watch?v=_kw_bQyX-3U
by Steveocee
Thu Oct 25, 2018 4:15 pm
Forum: Beginner Basics
Topic: CRS212-1G-10S-1S+IN
Replies: 2
Views: 1029

Re: CRS212-1G-10S-1S+IN

Think of the entire CRS range as a switch with "some" routing capability.
by Steveocee
Wed Oct 24, 2018 6:49 pm
Forum: General
Topic: CRS125 poor throughput & low cpu load [SOLVED]
Replies: 41
Views: 8629

Re: CRS125 poor throughput & low cpu load [SOLVED]

CRS125 is at heart a switch with some routing functionality, you shouldn't expect too much from it. Best I have ever had was 125Mb throughput but that was without fast track. Btest is an inefficient beast as well, you'd be better iPerfing through the router rather than in/out of it due to it's very ...
by Steveocee
Wed Oct 24, 2018 6:46 pm
Forum: Beginner Basics
Topic: Choosing the right router for the job
Replies: 5
Views: 1448

Re: Choosing the right router for the job

The 3011 would be a good choice if it was stable. It has a lot of port flapping issues which are yet to be fixed so I wouldn't confidently tell you to buy one. The RB1100AHx4 is very good and would easily cope with what you need however is a bit pricier than the 3011. Maybe the Hex or the Hex-S if y...
by Steveocee
Mon Oct 22, 2018 6:25 pm
Forum: Virtualization
Topic: VMware ESXi v6 - CHR 6.42.3 - Virtual Machine Crash then Update
Replies: 3
Views: 8275

Re: VMware ESXi v6 - CHR 6.42.3 - Virtual Machine Crash then Update

I have the following Configuration:
VMware ESXi v6.0.0
I am using ESXi 6.5.0 u2 with absolutely no issues at all. Is there any reason you have not updated your ESXi installation?
by Steveocee
Mon Oct 22, 2018 1:56 pm
Forum: General
Topic: LHG60 Link goes down when it rains
Replies: 21
Views: 4775

Re: LHG60 Link goes down when it rains

What channel are you using? The oxygen absorption effect is lessened as you go above 60Ghz. The "testing" 66Ghz channel is marketed as capable of 4Km so the current 64800 may give you the push you need.
by Steveocee
Mon Oct 22, 2018 1:51 pm
Forum: Beginner Basics
Topic: Simple Port Forwarding Question [SOLVED]
Replies: 1
Views: 1185

Re: Simple Port Forwarding Question [SOLVED]

No danger at all. It will work absolutely fine.
by Steveocee
Mon Oct 22, 2018 1:48 pm
Forum: Beginner Basics
Topic: Why I cannot obtain IP from ether4? [SOLVED]
Replies: 3
Views: 1747

Re: Why I cannot obtain IP from ether4? [SOLVED]

The interface is classed as a slave as it is part of a bridge, you can't run a DHCP client or server on a salve port, you would need to put it onto the bridge. That and the above.
by Steveocee
Fri Oct 19, 2018 6:42 pm
Forum: Scripting
Topic: Blacklist Filter (Development Topic)
Replies: 188
Views: 62631

Re: Blacklist Filter (Development Topic)

I've watched list "2" slowly grow over time, I think it was "only" around 14,000 entries when you first started this thread off and now it is up to 23,500+ entries. Seriously amazing stuff Dave.
by Steveocee
Fri Oct 19, 2018 11:23 am
Forum: General
Topic: Which Mikrotik router for this pilot GPON setup
Replies: 1
Views: 1101

Re: Which Mikrotik router for this pilot GPON setup

I would be tempted to future proof from the start and look at either a pair of 1016's or a 1036 (the pair of 1016 is for fault tolerance).
by Steveocee
Fri Oct 19, 2018 11:18 am
Forum: General
Topic: PSN NAT Type
Replies: 5
Views: 3647

Re: PSN NAT Type

Can you get the NAT type working if you remove the load balancer, so running a single connection first (even though it may be bad) and then add the load balancer back?

A correct implementation of UPnP should work (although not secure) but should as a minimum be consistent.
by Steveocee
Fri Oct 19, 2018 11:15 am
Forum: General
Topic: /ip dns servers= (cache) - how are multiple servers used?
Replies: 19
Views: 6670

Re: /ip dns servers= (cache) - how are multiple servers used?

My understanding was that DNS servers were always used in preference order. First one until it is not available at which point the queries go to the second.

If this is not the case it is both good and bad news I guess.
by Steveocee
Fri Oct 19, 2018 11:13 am
Forum: General
Topic: Which Mikrotik Product To Buy?
Replies: 4
Views: 1411

Re: Which Mikrotik Product To Buy?

Without knowing exact specification of what you want to achieve or you want to spend then I'd agree with Normis. That's a great all rounder.
by Steveocee
Fri Oct 19, 2018 11:08 am
Forum: Beginner Basics
Topic: Bridge to Bridge Connections
Replies: 3
Views: 895

Re: Bridge to Bridge Connections

If you have 2 separate bridges in the router then traffic behind them should be able to talk to each other anyway due to the fact you are connecting to a router. It will route as it's default mechanism. You actually have to try hard and firewall/filter them not to. You should be able to achieve what...
by Steveocee
Wed Oct 17, 2018 3:40 pm
Forum: Beginner Basics
Topic: PPTP VPN Protection
Replies: 9
Views: 3322

Re: PPTP VPN Protection

Put a cheap MT unit behind with IP>Cloud enabled.
Create address list on your router to only allow those DDNS names access to PPTP port.
Drop all other PPTP requests
by Steveocee
Wed Oct 17, 2018 1:49 pm
Forum: Beginner Basics
Topic: which is faster a many entries in the firewall or one with ip list
Replies: 2
Views: 996

Re: which is faster a many entries in the firewall or one with ip list

Address list is much more efficient for CPU than multiple FW lines.
by Steveocee
Wed Oct 17, 2018 10:54 am
Forum: RouterBOARD hardware
Topic: LHG60 3,8 km
Replies: 3
Views: 1457

Re: LHG60 3,8 km

This is excellent! I am now significantly more confident my 2.5Km link will work. (Hope you don't need your backup).
by Steveocee
Wed Oct 17, 2018 10:43 am
Forum: General
Topic: Network for children with limited Internet connection time
Replies: 9
Views: 2357

Re: Network for children with limited Internet connection time

Kid Control is by far the easiest way of achieving time based access across a child's devices. You can restrict the time slots (multiples throughout the day) speed and easily assign multiple devices to a child group.
by Steveocee
Mon Oct 15, 2018 6:23 pm
Forum: General
Topic: QoS trees colors
Replies: 3
Views: 1776

Re: QoS trees colors

I have a question about trees colors (green, yellow, green). I found in old post that color states are related with limit-at and max-value. green - a class the actual rate of which is equal or less than limit-at... yellow - a class the actual rate of which is greater than limit-at and equal or less...
by Steveocee
Mon Oct 15, 2018 4:26 pm
Forum: Beginner Basics
Topic: Router dropping traffic as "drop invalid"
Replies: 6
Views: 4716

Re: Router dropping traffic as "drop invalid"

Can you try disabling fasttrack. That stops connection tracking and may be what is causing the packets not to be classed as established or related.
by Steveocee
Mon Oct 15, 2018 3:59 pm
Forum: Beginner Basics
Topic: Need help with an online game
Replies: 2
Views: 904

Re: Need help with an online game

You will need to provide some more information for people to be able to help you. Can you provide an export of your config so we can see what the router is doing? Try turning off fasttrack as that stops connection tracking and may be part of the issue you are getting.
by Steveocee
Mon Oct 15, 2018 3:55 pm
Forum: Beginner Basics
Topic: WAP-LTE PoE voltage question [SOLVED]
Replies: 3
Views: 1355

Re: WAP-LTE PoE voltage question [SOLVED]

The WAP LTE can take a direct input of between 9&30v.
You could use the bundled 4 pin automotive installation cable and use 12v to power it.
by Steveocee
Mon Oct 15, 2018 2:08 pm
Forum: Wireless Networking
Topic: RB2011 Wireless Performance Troubleshoot
Replies: 6
Views: 2204

Re: RB2011 Wireless Performance Troubleshoot

Ok so after upgrading from 6.43 to 6.43.2 the problems ceased. It gets decent throughput and performance but still not compared to a RB941's throughput performance with the exact same settings and firmware. Have you actually tried Nest's suggestion? What that guy doesn't know about WiFi isn't worth...
by Steveocee
Mon Oct 15, 2018 1:42 pm
Forum: Beginner Basics
Topic: Router dropping traffic as "drop invalid"
Replies: 6
Views: 4716

Re: Router dropping traffic as "drop invalid"

Can you do a full export of your firewall?
Are you explicitly accepting already established and related connections?
by Steveocee
Sun Oct 14, 2018 9:41 am
Forum: Forwarding Protocols
Topic: RB4011 vs. CCR1009 BGP
Replies: 46
Views: 23622

Re: RB4011 vs. CCR1009 BGP

Have been saying for a long time there is room for a CCR with a quad core and the 4011 is close to making it (that rack mount though).

Almost like the CCR line went AMD mentality (more cores are better) than the Intel way of faster better cores.

Excited about this new generation of CCR
by Steveocee
Sun Oct 14, 2018 9:37 am
Forum: Beginner Basics
Topic: Looking up cloud.mikrotik.com every second
Replies: 24
Views: 14533

Re: Looking up cloud.mikrotik.com every second

Is there a chance of running 6.43? The is a new implementation of IP cloud and it may be a "legacy" feature.
by Steveocee
Fri Oct 12, 2018 3:54 pm
Forum: RouterBOARD hardware
Topic: CCR1009-7G-1C-1S+PC Scaling
Replies: 1
Views: 855

Re: CCR1009-7G-1C-1S+PC Scaling

Will be perfectly fine and work with existing switches without issue.
by Steveocee
Fri Oct 12, 2018 3:47 pm
Forum: Forwarding Protocols
Topic: RB4011 vs. CCR1009 BGP
Replies: 46
Views: 23622

Re: RB4011 vs. CCR1009 BGP

Yes, we are aware of this peculiarity and we are working also on new routers that have higher power per core, not just many cores.
That is extremely good news.
by Steveocee
Thu Oct 11, 2018 10:58 am
Forum: General
Topic: CLOUD ROUTER SWITCH
Replies: 6
Views: 2133

Re: CLOUD ROUTER SWITCH

Some models are lacking CPU information on the website. So far, just looking at the MHz on the listing is enough to categorize the models: 400 MHz: essentially switch, very low routing performance 600 MHz: RB2011-class router 800 MHz: about the same routing performance, different arch 800 MHz dual ...
by Steveocee
Thu Oct 11, 2018 10:56 am
Forum: Beginner Basics
Topic: Looking up cloud.mikrotik.com every second
Replies: 24
Views: 14533

Re: Looking up cloud.mikrotik.com every second

As a temporary work around have you tried making cloud.mikrotik a DNS static entry in the main router and sending the traffic nowhere? It may remove the flood of outbound DNS but obviously won't stop it as such.
by Steveocee
Wed Oct 10, 2018 6:48 pm
Forum: RouterBOARD hardware
Topic: HP NC375T not recognized
Replies: 3
Views: 1711

Re: HP NC375T not recognized

X86 or CHR?
I believe MT put most of the ongoing work and drivers into CHR now and do not update X86 so much.
by Steveocee
Wed Oct 10, 2018 6:47 pm
Forum: General
Topic: CLOUD ROUTER SWITCH
Replies: 6
Views: 2133

Re: CLOUD ROUTER SWITCH

Some models are lacking CPU information on the website. So far, just looking at the MHz on the listing is enough to categorize the models: 400 MHz: essentially switch, very low routing performance 600 MHz: RB2011-class router 800 MHz: about the same routing performance, different arch 800 MHz dual ...
by Steveocee
Wed Oct 10, 2018 6:44 pm
Forum: Beginner Basics
Topic: PPTP VPN Protection
Replies: 9
Views: 3322

Re: PPTP VPN Protection

You are opening a VPN server up to the world and are unhappy the world is trying to use it. Are you expecting the genuine VPN connections from a set IP address(es) or range or is it more a road warrior kind of setup? If you are expecting specific IP's then you can add them to a list and amend your a...
by Steveocee
Wed Oct 10, 2018 11:35 am
Forum: Wireless Networking
Topic: LHG 60G experience
Replies: 608
Views: 194102

Re: LHG 60G experience

Interesting experiences.
I have some test kit going up soon which is by Google mapping 2.63Km clear LOS tower to tower.
I'm not expecting full PHY rates but am wondering what it will reach and how any rain will affect the link. My hope is that it folds back and doesn't go off completely.
by Steveocee
Wed Oct 10, 2018 11:24 am
Forum: Virtualization
Topic: CHR license on router with no internet
Replies: 12
Views: 13369

Re: CHR license on router with no internet

From fresh install CHR is slightly hindered, you will only get 1Mb in one direction but full speeds in the other. Once you give it internet and assign it to your account it goes into trial mode (60 days) use. Once the 60 days runs out there is no detriment to the OS, it carries on working fine apart...
by Steveocee
Tue Oct 09, 2018 1:45 pm
Forum: Beginner Basics
Topic: No internet connection on my switch
Replies: 9
Views: 5598

Re: No internet connection on my switch

I actually thought that a CCR didn't have much of a config on it straight out of the box.

If you can't get connection from the router, go back to basics, is the CCR getting an IP? Does the interface have an IP?
by Steveocee
Tue Oct 09, 2018 1:40 pm
Forum: Beginner Basics
Topic: Manage export - import
Replies: 4
Views: 1744

Re: Manage export - import

Hi, What editor are you using? It's probably not the best idea to move between versions with an imported export as the newer version may not have some of the older references, some things change between version numbers which you may be referencing. To debug you could manually copy and paste the line...
by Steveocee
Sun Oct 07, 2018 6:35 pm
Forum: General
Topic: Birmingham MUM 2018
Replies: 13
Views: 2857

Re: Birmingham MUM 2018

Really looking forward to it.
by Steveocee
Tue Sep 25, 2018 10:52 am
Forum: General
Topic: RB3011 - set or change PIN
Replies: 1
Views: 2321

Re: RB3011 - set or change PIN

LCD > PIN
Capture.PNG
by Steveocee
Fri Sep 21, 2018 6:03 pm
Forum: General
Topic: ip cloud without default route
Replies: 4
Views: 1331

Re: ip cloud without default route

If you are unticking "add-default-route" then you simply need to correctly create a route for the router to reach the web.
Can you do an export of your static routes.
by Steveocee
Thu Sep 20, 2018 3:20 pm
Forum: RouterBOARD hardware
Topic: 100Mb LAN - what's the point?
Replies: 13
Views: 4487

Re: 100Mb LAN - what's the point?

OP has a point. New 60Ghz "Lite" model can do 60Ghz connection so up to Gbit over the air in full duplex and is specced with a 10/100 port. Mental! This is a CPE unit for connecting to an access point. If the AP has a gigabit connection and there are 8 CPEs connected, nobody can get more ...
by Steveocee
Thu Sep 20, 2018 11:17 am
Forum: RouterBOARD hardware
Topic: 100Mb LAN - what's the point?
Replies: 13
Views: 4487

Re: 100Mb LAN - what's the point?

OP has a point. New 60Ghz "Lite" model can do 60Ghz connection so up to Gbit over the air in full duplex and is specced with a 10/100 port. Mental!
by Steveocee
Mon Sep 17, 2018 4:09 pm
Forum: Beginner Basics
Topic: Are interface lists worth using?
Replies: 4
Views: 1338

Re: Are interface lists worth using?

Absolutely!

I find them very handy when setting up firewall and NAT rules.