Community discussions

MikroTik App

Search found 145 matches

by squeeze
Tue Apr 17, 2018 1:09 pm
Forum: General
Topic: OpenVPN SHA256 + UDP
Replies: 67
Views: 48360

Re: OpenVPN SHA256 + UDP

I'd consider switching to L2TP+ipsec or EoIP+ipsec(for mikrotik on both sides), both use UDP and encryption and should perform the same or better in performance. OpenVPN on UDP has been requested years ago and won't come too soon on Mikrotik, probably never. SHA256 is supported on the mentioned pro...
by squeeze
Mon Apr 16, 2018 5:27 pm
Forum: Wireless Networking
Topic: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi
Replies: 304
Views: 155216

Re: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi

This is worthless advice from Mikrotik support, if they really are asking you to remove the default bridge configuration, even for testing.
by squeeze
Mon Apr 16, 2018 5:23 pm
Forum: General
Topic: hap AC Lan no Gigabit connection
Replies: 1
Views: 755

Re: hap AC Lan no Gigabit connection

Different cable.
by squeeze
Sat Apr 14, 2018 8:51 pm
Forum: General
Topic: Port Forwarding for Security Camera's
Replies: 7
Views: 4614

Re: Port Forwarding for Security Camera's

TCP port 80 is the default HTTP port. This is basic World Wide Web and TCP protocol knowledge. In other words, all web browsers implicitly understand http://example.com as http://example.com:80. If you actually need both of these services on this default (unsecured) web services port, then there is ...
by squeeze
Sat Apr 14, 2018 3:45 pm
Forum: Beginner Basics
Topic: CCR - Mikrotik Bridge usage with multiple Vlans
Replies: 6
Views: 2906

Re: Mikrotik Bridge usage with multiple Vlans

Unless you have a switch chip, its single bridge for all VLANs. Also, why are you explicitly disabling hardware offloading?

You may also need to add the bridge name itself to the "tagged=" list for trunks to other devices.
by squeeze
Fri Apr 13, 2018 9:49 pm
Forum: Wireless Networking
Topic: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi
Replies: 304
Views: 155216

Re: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi

The IPQ4018 SoC supports beamforming (802.11ac TxBF), but that would require a phased antenna array design, which is highly unlikely. Basically, the chip is far more advanced than this specific device can fully support.
by squeeze
Fri Apr 13, 2018 3:34 am
Forum: Announcements
Topic: Winbox 3.13 released!
Replies: 59
Views: 42914

Re: Winbox 3.13 released!

Still no signature checking or HTTPS... man in the middle can easily compromise administrator's PC. https://i.imgur.com/TX7G9pq.gifv I was wondering what you meant. I did a Wireshark http monitor after pressing Check for Updates in Winbox: GET /routeros/winbox/LATEST.3 HTTP/1.1 HTTP/1.1 200 OK (app...
by squeeze
Thu Apr 12, 2018 3:55 pm
Forum: General
Topic: Interface or usb wifi for RB750Gr3? [SOLVED]
Replies: 1
Views: 2003

Re: Interface or usb wifi for RB750Gr3? [SOLVED]

No, return it and get a hAP AC or hAP AC lite. RB750Gr3 is a pure wired router.

Better yet, state your WiFi requirements for a more precise recommendation.
by squeeze
Thu Apr 12, 2018 12:46 pm
Forum: Beginner Basics
Topic: Batch set all LEDs [SOLVED]
Replies: 2
Views: 1793

Re: Batch set all LEDs [SOLVED]

/system leds set [find] type=off

worked for me. Thank you for the inspiration.
by squeeze
Thu Apr 12, 2018 11:44 am
Forum: General
Topic: Secure my DNS requests
Replies: 14
Views: 8781

Re: Secure my DNS requests

From their homepage: WireGuard is not yet complete. You should not rely on this code. It has not undergone proper degrees of security auditing and the protocol is still subject to change. We're working toward a stable 1.0 release, but that time has not yet come. So one day it may become great and i...
by squeeze
Tue Apr 10, 2018 10:30 pm
Forum: Wireless Networking
Topic: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi
Replies: 304
Views: 155216

Re: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi

Nope, pls check viewtopic.php?f=2&t=132576
I meant WLAN<->WAN (not Ethernet LAN<->WAN). Thank you for the clarification.
by squeeze
Tue Apr 10, 2018 2:02 pm
Forum: Beginner Basics
Topic: Batch set all LEDs [SOLVED]
Replies: 2
Views: 1793

Batch set all LEDs [SOLVED]

Is it possible to batch set the type of all LEDs in one line or command string?

Pseudo-example:
/system leds set [find where leds=XXX] type=off

Can the above work and what would XXX be to set all LEDs regardless of names?
by squeeze
Tue Apr 10, 2018 1:20 pm
Forum: Announcements
Topic: Winbox 3.13 released!
Replies: 59
Views: 42914

Re: Winbox 3.13 released!

winbox.exe is now signed executable;
Thank you.

Image
by squeeze
Tue Apr 10, 2018 12:34 pm
Forum: Wireless Networking
Topic: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi
Replies: 304
Views: 155216

Re: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi

Based on the above findings, the problem comes from the link between the data of APs and the routing block to the external interface WAN port. If the hAP ac^2 is configured as an AP, it should work very well. So, it is a LAN-WAN routing issue. Can I confirm with all on here who have posted data acr...
by squeeze
Tue Apr 10, 2018 3:15 am
Forum: General
Topic: Low Bandwidth / Firewall Rules
Replies: 2
Views: 931

Re: Low Bandwidth / Firewall Rules

IP has no source address validation - that is the reason why IP spoofing exists at all - therefore you cannot trust the source IP from unknown sources.
by squeeze
Tue Apr 10, 2018 2:06 am
Forum: Beginner Basics
Topic: I'm at a loss, any help is good help at this moment...
Replies: 22
Views: 4611

Re: I'm at a loss, any help is good help at this moment...

You've isolated the problem to RB2011 or all its clients and all their physical connections (except cable to issue PC). Isolate the problem much more to the PC or router, i.e. physically disconnect all other clients to the RB2011 ports or disable their Ethernet/WiFi interfaces on the router. If prob...
by squeeze
Tue Apr 10, 2018 12:36 am
Forum: Wireless Networking
Topic: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi
Replies: 304
Views: 155216

Re: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi

You can test as reliably as iperf3 (though without the range of options) using the Windows btest.exe application or Bandwidth Test on other router devices, as long as you run it from two devices through the router being tested. Btest actually has functionality iperf3 does not, though iperf2 has: you...
by squeeze
Mon Apr 09, 2018 3:18 pm
Forum: General
Topic: Secure my DNS requests
Replies: 14
Views: 8781

Re: Secure my DNS requests

Let's hope that Mikrotik is going to develop better support in router, for OpenVPN and IKE2 as client.
And Wireguard which trounces both of them for security, throughput, and latency.
by squeeze
Sun Apr 08, 2018 6:00 pm
Forum: Scripting
Topic: Best scripts for firewall and router protection [SOLVED]
Replies: 16
Views: 110150

Re: Best scripts for firewall and router protection [SOLVED]

Before anything else. I just want to clarify your initial post for other new people: The best additional protections for your new Mikrotik router are simply everything on " Manual:Securing Your Router " page before the "Firewall" section. Absolutely stop reading past this point :...
by squeeze
Sat Apr 07, 2018 7:48 pm
Forum: Scripting
Topic: Best scripts for firewall and router protection [SOLVED]
Replies: 16
Views: 110150

Re: Best scripts for firewall and router protection [SOLVED]

Either you, 1. Be very careful to understand what parts constitute every component of your firewall from the Default Configuration, then re-apply them to your customized setup, OR 2. Export your config, save the non-firewall parts that you changed from default, then factory reset the router and star...
by squeeze
Sat Apr 07, 2018 11:46 am
Forum: Beginner Basics
Topic: Need a little explanation about log entries...
Replies: 5
Views: 2498

Re: Need a little explanation about log entries...

IP by default has no source validation.

They are forging/spoofing their source IP to probe your MT weaknesses, i.e. one of which is the ND port.

Depending on what type of business you run, you can just ignore it if you're not some type of ISP, as far as I'm aware.
by squeeze
Thu Apr 05, 2018 5:28 am
Forum: General
Topic: Any plans to make cross-platform WinBox?
Replies: 33
Views: 8217

Re: Any plans to make cross-platform WinBox?

Web and SSH are already as cross-platform as it is possible to be. On top of that, Mikrotik's feature-complete CLI is much easier to use and learn than competitors, afaik. No one but some subset of power users would want anything more, and power users already have access to emulators and VMs, includ...
by squeeze
Wed Apr 04, 2018 2:09 pm
Forum: General
Topic: Log all console commands [SOLVED]
Replies: 31
Views: 19513

Re: Log all console commands [SOLVED]

Impressive six year thread for a feature that appears almost trivial for Mikrotik compared to direct competitors (*) and would instantly increase their popularity with businesses scaling up and larger enterprises ... How strange to ignore such an easy win when they have already done 90% of the leg w...
by squeeze
Wed Apr 04, 2018 1:17 pm
Forum: Wireless Networking
Topic: hAP ac 5GHz max speed
Replies: 52
Views: 25388

Re: hAP ac 5GHz max speed

Hi, I can confirm that the hAP AC connects with 3 chans to a newer MacBookPro on 1G+ Thruput tested with iperf3 from this MBP to a server on the wired part of my local network On 1GB wire I get approx 960Mbit/s On 5GHz wifi I get approx 530Mbit/s This 530Mbit/s seems about the max because the hAP A...
by squeeze
Wed Apr 04, 2018 7:06 am
Forum: General
Topic: WiFi with VLANS
Replies: 9
Views: 1582

Re: WiFi with VLANS

Make sure your trunk port is a tagged member of your management VLAN. Ideally, avoid the use of VLAN ID 1, which seems to correspond to the default VLAN ID of Mikrotik, therefore used for untagged traffic. Like some other devices, this common default VLAN ID either does not behave exactly like other...
by squeeze
Wed Apr 04, 2018 5:37 am
Forum: Wireless Networking
Topic: Wi-Fi speed issues on hAP AC Lite
Replies: 39
Views: 37035

Re: Wi-Fi speed issues on hAP AC Lite

Would be nice if people would not talk so loosely about wildly different WiFi models. After all this thread started specifically about the hAP AC Lite and an asymmetric download issue. provide client and distance information. Are you using an AC client and what type, e.g. phone, tablet, laptop, MacB...
by squeeze
Mon Apr 02, 2018 11:11 am
Forum: Beginner Basics
Topic: slow internet after 1 or 2 hours ...
Replies: 9
Views: 4047

Re: slow internet after 1 or 2 hours ...

i reset the router still the same problem i removed torrent rules What does that mean? If you firmware or factory reset the router, how could you remove any "torrent rules". There should not be any. You need to test the router with a perfectly default configuration from a reset back to fi...
by squeeze
Mon Apr 02, 2018 12:40 am
Forum: Announcements
Topic: Urgent security advisory
Replies: 110
Views: 143020

Re: Urgent security advisory

TL;DR. Centralization in security information helps Mikrotik every bit as it does its existing customers, prospective customers and the broader community. Mikrotik need to be much more direct and centralized about even the very basics, like what specific vulnerabilities have been fixed and when (we...
by squeeze
Sun Apr 01, 2018 11:20 pm
Forum: Wireless Networking
Topic: hAP ac^2 Problems---Extremely Poor Performance found in 2.4G and 5G WiFi
Replies: 304
Views: 155216

Re: hAP ac^2---Extremely Poor Performance found in 2.4G and 5G WiFi

This is 5Ghz on my hAP AC2

http://www.speedtest.net/result/7188352780

We cannot see the image and your speed test information is useless without knowing the expected speed of the connection.
by squeeze
Sun Apr 01, 2018 8:01 am
Forum: General
Topic: Disabling wireless radios so that they use no power
Replies: 1
Views: 1012

Disabling wireless radios so that they use no power

Is there a method in RouterOS or otherwise in Mikrotik routers to disable wireless radios, such as for WiFi, so that they consume no power? If not, what about minimum power consumption? Does simply disabling the RouterOS Wireless interfaces in the device user interface have any impact on power draws...
by squeeze
Sun Apr 01, 2018 7:48 am
Forum: General
Topic: hAP ac² noisy when using WiFi [SOLVED]
Replies: 21
Views: 8001

Re: hAP ac² noisy when using WiFi [SOLVED]

Do not interfere with it, just return it as faulty and describe the reason for useful feedback to all. This is clearly a hardware QA issue, i.e. probably not even an issue with the model at all. Also, why are you considering to interfer with the faulty hardware of a brand new device, especially for ...
by squeeze
Sun Apr 01, 2018 1:16 am
Forum: Beginner Basics
Topic: HAP AC performance issues
Replies: 9
Views: 4153

Re: HAP AC performance issues

Out of interest, can you determine the make and model of the ISP's router?
by squeeze
Fri Mar 30, 2018 10:01 pm
Forum: General
Topic: Mikrotik for 900/100 Mbit WAN
Replies: 7
Views: 1941

Re: Mikrotik for 900/100 Mbit WAN

So I have bought hAP ac2 and its amazing, on same settings as my RB951G cpu usage is only 2-3% when fully using 100 Mbit PPPoE, while on RB951G cpu usage was ~20% ( with fastpath, without it was double that ). Did you get 900/100 Mbit WAN connection speed with the hAP ac2, PPPoE and same IP firewal...
by squeeze
Fri Mar 30, 2018 2:34 am
Forum: General
Topic: hEX - missing usb hub support
Replies: 6
Views: 2215

Re: hEX - missing usb hub support

Thank you very much for the report and your careful research!

Do you or anyone else happen to know if the new hAP ac² (RBD52G-5HacD2HnD-TC (International), RBD52G-5HacD2HnD-TC-US (USA)) would also have similar issues with USB controllers?
by squeeze
Thu Mar 29, 2018 3:14 pm
Forum: General
Topic: Thank you for the great Cable Test feature!
Replies: 5
Views: 1825

Re: Thank you for the great Cable Test feature!

It is implemented in only few models unfortunately. Isn't port mirroring supported in almost all the switch chips ? Oh nevermind, you meant this about the cable test: This works on SXT-G, SXT Lite, RB711G, RB2011, RB750 series and other devices with the same switch chips, and also the Cloud Core se...
by squeeze
Thu Mar 29, 2018 6:49 am
Forum: General
Topic: Help me decide
Replies: 11
Views: 2540

Re: Help me decide

I would have loved to hear sindy's suggestions for an alternative. At this price point, you could consider building your own pfSense box or even get an RT-AC86U as an edge VPN router, if you care about OpenVPN performance at all. Both of those have fast enough CPUs with hardware acceleration (AES-NI...
by squeeze
Thu Mar 29, 2018 1:33 am
Forum: General
Topic: Router + switch + ap all in one solution
Replies: 15
Views: 3938

Re: Router + switch + ap all in one solution

There is no single device on the market that could guarantee all those features, especially at that price point. If you really want all those features, your time and money is likely better served researching separate devices, i.e. a router just for routing tech + NAT + (basic) VPN, connected to a sw...
by squeeze
Wed Mar 28, 2018 11:44 pm
Forum: Beginner Basics
Topic: DHCP Server Error
Replies: 4
Views: 4999

Re: DHCP Server Error

Router: /system logging topics=dhcp Process of elimination: MAC "lock": unlock whatever it is you did with the MAC. If it works, then you know it is this, or what do you mean? Device: test with a different device Connection logical type: check with another network or a different band (2.4G...
by squeeze
Wed Mar 28, 2018 2:29 pm
Forum: General
Topic: Why isn't WMM Support default?
Replies: 19
Views: 17369

Re: Why isn't WMM Support default?

Just being going through my Wireless settings: Why is WMM disabled by default in 802.11n/ac devices? This is already perverse because those standards are stated to require tools in WMM for HT (High Throughput) link rates, i.e. greater than 54Mbps (*) and is enabled by default for Wi-Fi Certified dev...
by squeeze
Wed Mar 28, 2018 6:44 am
Forum: Beginner Basics
Topic: Please add a wiki document on settings to maximize home user privacy. [SOLVED]
Replies: 4
Views: 2032

Re: Please add a wiki document on settings to maximize home user privacy. [SOLVED]

First, Mikrotik routers with the latest RouterOS and firmware appear already very private and have a high security potential. The default is nothing available on the WAN and no responses except to pings. Even penetration tools like nmap will find no WAN leaks with all conventional scans. If your rou...
by squeeze
Tue Mar 27, 2018 10:54 am
Forum: Beginner Basics
Topic: [RB750Gr3] DHCP failure on default/native VLAN (VLAN ID 1) of bridge [SOLVED]
Replies: 2
Views: 2905

Re: [RB750Gr3] DHCP failure on default/native VLAN (VLAN ID 1) of bridge [SOLVED]

I conducted a simple experiment and changed VLAN ID 1 everywhere to VLAN ID 4. DHCP on that subnet promptly started working on one of the "Default" VLAN ports of the router. That is, I did the equivalent of: /interface vlan set interface=bridge-vlan name=Default vlan-id=4 set interface=bri...
by squeeze
Tue Mar 27, 2018 1:24 am
Forum: Beginner Basics
Topic: [RB750Gr3] DHCP failure on default/native VLAN (VLAN ID 1) of bridge [SOLVED]
Replies: 2
Views: 2905

[RB750Gr3] DHCP failure on default/native VLAN (VLAN ID 1) of bridge [SOLVED]

Device: RB750Gr3 on RouterOS 6.41.3 Problem: DHCP clients are not receiving IPs from the default or native VLAN (VLAN ID 1). I tested both a default VLAN port on the router and a native VLAN port on a VLAN-aware switch attached to the trunk. Neither worked. DHCP works on all other ports. Context: a...
by squeeze
Fri Mar 23, 2018 7:22 pm
Forum: Beginner Basics
Topic: [RB750Gr3 (hEX)] - Simple VLAN and Management network
Replies: 1
Views: 6181

Re: [RB750Gr3 (hEX)] - Simple VLAN and Management network

Solution: The key was realizing that, despite the VLAN ID user interface to the NIC in Windows, my PC client was not VLAN-aware. So, having a tagged management port was preventing the router from talking to the PC above Layer 2. This occurred to me after the Wireshark software traffic analyzer coul...
by squeeze
Thu Mar 22, 2018 8:55 pm
Forum: Beginner Basics
Topic: [RB750Gr3 (hEX)] - Simple VLAN and Management network
Replies: 1
Views: 6181

[RB750Gr3 (hEX)] - Simple VLAN and Management network

FIRST POST I recently purchased an RB750Gr3 for home use. I am just trying to get a simple VLAN setup working, including a Management port on the Hex itself and a Management VLAN. Using typical VLAN membership tables I have seen on other routers, this is my intent: VLAN Ports 2 3 4 5 1 X U U U Segre...