Community discussions

MikroTik App

Search found 12058 matches

  • 1
  • 3
  • 4
  • 5
  • 6
  • 7
  • 41
by mkx
Fri Nov 17, 2023 11:15 am
Forum: Beginner Basics
Topic: Devices not accessible from local wifi [SOLVED]
Replies: 2
Views: 1252

Re: Devices not accessible from local wifi [SOLVED]

In the CAPsMAN setup, you have to set client-to-client-forwarding=yes (default is no) ... it's a datapath property.
by mkx
Fri Nov 17, 2023 8:53 am
Forum: Wireless Networking
Topic: RBLHGG-5HPacD2HPnD-XL LHG XL no DHCP asign on slave site in bridge [SOLVED]
Replies: 2
Views: 1431

Re: RBLHGG-5HPacD2HPnD-XL LHG XL no DHCP asign on slave site in bridge [SOLVED]

Since your wireless setup consists of all Mikrotik devices, your slave should be configured to "station-bridge" mode ... pseudobridge has a heap of problems, missing DHCP assignments is one of them.

Read extensive article about different station modes and their problems.
by mkx
Fri Nov 17, 2023 8:51 am
Forum: General
Topic: mikrotik with PPPoe and real ip behind bridge modem [SOLVED]
Replies: 101
Views: 23677

Re: mikrotik with PPPoe and real ip behind bridge modem [SOLVED]

It's an RB850Gx2 running ROS 6.47.9 Could be that the problems you're seeing are related to older version of either ROS or Winbox. The version of ROS you have on your device is pretty dated. It's fine to stay with v6, but you should upgrade it to latest v6, which is 6.49.10 ... And make sure you'er...
by mkx
Fri Nov 17, 2023 8:41 am
Forum: Beginner Basics
Topic: dhcp relay using LAN IP address as source
Replies: 10
Views: 3097

Re: dhcp relay using LAN IP address as source

I didn't realize this forum is not monitored by mikrotik which is pretty unusual. Well, it is monitored, but loosely. We do see some MT staffers discussing here and there, but this forum is more or less intended for user to user interaction. It seems that MT wants bugs and issues officially logged ...
by mkx
Thu Nov 16, 2023 10:44 pm
Forum: Scripting
Topic: GPT4 and writing scripts for Mikrotik
Replies: 51
Views: 5721

Re: GPT4 and writing scripts for Mikrotik

And you're seriously comparing GPT's ROS scripting skills with Rex? Oh my... we need more cats.
by mkx
Thu Nov 16, 2023 10:41 pm
Forum: Beginner Basics
Topic: Wifi Backend
Replies: 8
Views: 1456

Re: Wifi Backend

Winbox connectivity is configured under Tools>MAC Server ... and uses interface lists. Winbox visibility is configured under IP>Neighbors>Discovery Settings ... and again uses interface lists. Default setup uses two interface lists: WAN and LAN, by dedsult ether1 is member of WAN and bridge (includi...
by mkx
Thu Nov 16, 2023 10:24 pm
Forum: General
Topic: Fundamental problems at MikroTik
Replies: 32
Views: 4268

Re: Fundamental problems at MikroTik

For a, quote: "For a fly by night DYI", gear with youtube tutorials, provided by vendor and with actors speaking various dialects[*], is the best choice. With anything else, one is on his own. Umm, wait a minute, isn't this a part of DIY concept? Now I'm confused. [*] it would be unfair to...
by mkx
Thu Nov 16, 2023 10:10 pm
Forum: Beginner Basics
Topic: RB760iGS Dual Power Source
Replies: 2
Views: 826

Re: RB760iGS Dual Power Source

Quite possibly yes. AFAIK RB-GPOE works both ways (also as "extractor"), but requires the PSE to work with passive PoE devices. CRS328 can be set to work with passive PoE clients when selected low voltage output (26V), which is great in this case. The only remaining detail is how to "...
by mkx
Thu Nov 16, 2023 7:34 pm
Forum: General
Topic: Fundamental problems at MikroTik
Replies: 32
Views: 4268

Re: Fundamental problems at MikroTik

Nobody is forcing to order a CD and pay for preparing it and shipping. How about that documentation? I am practically forced to waste time in rereading sentences multiple times while trying to clarify what the (obviously) non-English speaker meant through an ugly translation. Is that what customers...
by mkx
Thu Nov 16, 2023 4:21 pm
Forum: RouterBOARD hardware
Topic: Mikrotik RB4011
Replies: 7
Views: 2806

Re: Mikrotik RB4011

My RB4011 has cores at 100% at less than 1 Gbps without FastTrack on v7 ... I have the opposite experience: my hAP ac2 was at 15-20% under v6 when doing 30Mbps (at the time I was using 30/5 VDSL), the same unit now is at 10% when doing 980Mbps (I have FO 1Gbps/100Mbps) on v7. Alas: I did netinstall...
by mkx
Thu Nov 16, 2023 4:14 pm
Forum: RouterBOARD hardware
Topic: CRS310-8G+2S+IN USB Port [SOLVED]
Replies: 14
Views: 4692

Re: CRS310-8G+2S+IN USB Port [SOLVED]

Just beware: traditionally, ROS wasn't known for exploiting full USB capacity when working with USB flash sticks. So if a device supports USB3, this doesn't mean you will get 100MBps of file transfer rates (if USB flash disk can do it on normal computers), it might still be limited at some significa...
by mkx
Thu Nov 16, 2023 4:11 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 93341

Re: v7.13beta [testing] is released!

Just wondering... Both times this happened after a regular shutdown (/system/shutdown). Is there anything special now that breaks configuration?
Check storage space ... right before shutdown. If storage is full (or close to full), then this might be the reason for problems.
by mkx
Thu Nov 16, 2023 4:10 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 93341

Re: v7.13beta [testing] is released!

zandhaas use check for updates button and ignore the above ranting. nothing special has to be done. upgrade and forget ******************************************************** And it's true but then you have the "old" wifi package and not the qcom-ac package installed. Yes, that's a part ...
by mkx
Wed Nov 15, 2023 7:00 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 93341

Re: v7.13beta [testing] is released!

free storage space 304 KiB
How much free storage did you have on 7.12?

I posted pretty detailed observations about storage usage in my post #71 above.
by mkx
Wed Nov 15, 2023 6:39 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 93341

Re: v7.13beta [testing] is released!

RAM consumption is a dynamic thing ... and it starts from 0 after each reboot, so you should not worry about it too much. Unless your device crashes, like @sinisa observes. After all, until 7.12 wave2 driver, requirement was device with 256MB RAM. And I guess your hAP ac2 has 128MB ...
by mkx
Wed Nov 15, 2023 4:20 pm
Forum: RouterBOARD hardware
Topic: Chateau LTE6 ax antenna recommendation
Replies: 4
Views: 1950

Re: Chateau LTE6 ax antenna recommendation

Beware of small antennae, usually antenna gain is inversely proportional to antenna size. An idea: since your problem is that device itself is inside metallic housing, why don't you re-use original antennae. only use cables of appropriate length? Depending on cable quality, additional loss is around...
by mkx
Wed Nov 15, 2023 4:16 pm
Forum: RouterBOARD hardware
Topic: L009UiGS-2HaxD-IN power consumption
Replies: 8
Views: 2748

Re: L009UiGS-2HaxD-IN power consumption

The point of my question is that minimum power draw doesn't matter if device actually draws higher power significant portion of time ... as you explained your setup lacks heat dissipation, but you have to make sure that device doesn't overheat during expected (extended) periods of time with higher a...
by mkx
Wed Nov 15, 2023 3:44 pm
Forum: Beginner Basics
Topic: PPoE Dynamic and Static IPs
Replies: 3
Views: 925

Re: PPoE Dynamic and Static IPs

The only way to get anything sent over PPPoE link is to have ISP to route it through. And since that traffic is actively routed via the PPPoE link towards you (ISP already configured their router to use your PPPoE link when sending the traffic for the new /29 address space), you don't have (and shou...
by mkx
Wed Nov 15, 2023 12:51 pm
Forum: Scripting
Topic: GPT4 and writing scripts for Mikrotik
Replies: 51
Views: 5721

Re: GPT4 and writing scripts for Mikrotik

ChatGPT is as good at writing ROS scripts as with any other things: mostly it gets things done (surprisingly well), but sometimes it fails miserably ... the problem with ChatGPT failing is not that it's failing, the problem is that it doesn't admit that it cant provide a good result, instead it pres...
by mkx
Wed Nov 15, 2023 12:35 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 93341

Re: v7.13beta [testing] is released!

*) disk - fixed hang on reboot when network file systems mounted; That is interesting! Strods says 'Please remember that actual "bugs" must be reported to support@mikrotik.com complemented with logs, supout files, etc.' above. @pe1chl, do I understand you correctly that you're complaining...
by mkx
Wed Nov 15, 2023 12:27 pm
Forum: RouterBOARD hardware
Topic: Chateau LTE6 ax antenna recommendation
Replies: 4
Views: 1950

Re: Chateau LTE6 ax antenna recommendation

... we require a smart LTE antenna ... What is your definition of word "smart" in this context? In UK smart means "having a clean, tidy, and stylish appearance" while in US smart means "intelligent, or able to think quickly or intelligently in difficult situations" ......
by mkx
Wed Nov 15, 2023 9:09 am
Forum: RouterBOARD hardware
Topic: Mikrotik RB4011
Replies: 7
Views: 2806

Re: Mikrotik RB4011

If one takes official test results with a pinch of salt, then RB4011 should be able of routing at roughly 2.5Gbps give or take. The number is approximately 10-times larger than the one of RB2011. I guess that your particular use case (200 1-to-1 NAT mappings) does mean somehow more complicated setup...
by mkx
Wed Nov 15, 2023 9:01 am
Forum: RouterBOARD hardware
Topic: L009UiGS-2HaxD-IN power consumption
Replies: 8
Views: 2748

Re: L009UiGS-2HaxD-IN power consumption

What I wrote above is my definition of idle device, for the purpose of measuring power consumption. Performance I need is full 1Gb routing with firewall, VPN and many many parallel connections. So what is your expected busy/idle ratio? If it's higher than 0.1 (or even less), then idle power consump...
by mkx
Wed Nov 15, 2023 8:54 am
Forum: General
Topic: Subject: MikroTik Router Storage Issue - 100% Full
Replies: 12
Views: 1477

Re: Subject: MikroTik Router Storage Issue - 100% Full

If I create a backup now, it's gone again after a reboot. It seems that you're not aware of one fact: on devices with flash storage equal or less than 64MB (I think that's the magic size, could be 32MB), the root of file structure resides on RAM disk and the (raminder of) permanent flash storage is...
by mkx
Wed Nov 15, 2023 8:49 am
Forum: General
Topic: Subject: MikroTik Router Storage Issue - 100% Full
Replies: 12
Views: 1477

Re: Subject: MikroTik Router Storage Issue - 100% Full

Then, I loaded my configuration, which is only 1 MB in size Configuration 1MB in size is not "only", it's huge for a 16MB flash device IMO. My hAP ac2 config, while device was running ROS v6, contained two country address lists (both for IPv4 and IPv6, so this actually makes 4 decently si...
by mkx
Wed Nov 15, 2023 8:41 am
Forum: General
Topic: IP public issue [SOLVED]
Replies: 2
Views: 828

Re: IP public issue [SOLVED]

If you're not able to decide which public IP address you're supposed to use, then I wonder if you have skills and information needed for the task you have to do?
by mkx
Wed Nov 15, 2023 8:31 am
Forum: Beginner Basics
Topic: dhcp relay using LAN IP address as source
Replies: 10
Views: 3097

Re: dhcp relay using LAN IP address as source

While waiting for a comment from MikroTik engineers, ...

If you're serious about getting a comment from MT, then you better open a support ticket with them ... using official support channels, this forum is not one of those.
by mkx
Wed Nov 15, 2023 8:28 am
Forum: Beginner Basics
Topic: Cannot get to the config page of pihole on mikrotik [SOLVED]
Replies: 9
Views: 1873

Re: Cannot get to the config page of pihole on mikrotik [SOLVED]

However, when users follow the official doc and at the end the cofiguration is not working, it can get frustrating. In the MT official doc, pihole container is only mentioned as an example of how to build a container. It doesn't touch the workings of the container contents at all ... so I don't see...
by mkx
Tue Nov 14, 2023 7:26 pm
Forum: RouterBOARD hardware
Topic: L009UiGS-2HaxD-IN power consumption
Replies: 8
Views: 2748

Re: L009UiGS-2HaxD-IN power consumption

*) - idle is defined as: configured and working device, few registered devices (wifi), small traffic (up to 1Mbit).
How comes that RB2011 doesn't have enough performance for what you wrote above?
by mkx
Tue Nov 14, 2023 7:18 pm
Forum: General
Topic: Flow control between CSS610 and CRS310
Replies: 7
Views: 1686

Re: Flow control between CSS610 and CRS310

Isn't it the other way around (enabling TX flow control does the signaling)? My bad. But the point is: you need both flow controls enabled on both sides of a link or else it doesn't work. Now, in your particular case: you're saying there are Tx pauses on CCS610 but no Rx pauses on conected CRS310 p...
by mkx
Tue Nov 14, 2023 3:41 pm
Forum: RouterBOARD hardware
Topic: Is Utilization of RouterBoards as 1Gbps RF signal processor possible?
Replies: 5
Views: 2088

Re: Is Utilization of RouterBoards as 1Gbps RF signal processor possible?

RouterBoards are far from SDRs. RouterOS is a closed source OS which only runs drivers made and approved by Mikrotik.

Therefore I'm guessing that you'll have to forget about Mikrotik for your science project.
by mkx
Tue Nov 14, 2023 2:54 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 93341

Re: v7.13beta [testing] is released!

So when 7.12 with installed wifiwave2 package gets upgraded to 7.13beta1 (or newer), wifi-qcom (or wifi-qcom-ac) package replaces the previously installed wifiwave2 package. I noticed an important difference on AC2 (no previous wifiwave2). Wireless was there after upgrade... Sure thing ... because ...
by mkx
Tue Nov 14, 2023 2:24 pm
Forum: General
Topic: Flow control between CSS610 and CRS310
Replies: 7
Views: 1686

Re: Flow control between CSS610 and CRS310

Did you enable both tx-flow-control and rx-flow-control on all involved ports on both switches? As far as I understand, Rx flow control only signals the other end of each physical leg that it needs to pause if port receives feedback from upstream buffer ... and as far as I understand, most switches ...
by mkx
Tue Nov 14, 2023 2:11 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 93341

Re: v7.13beta [testing] is released!

The document, linked by @EdPa in post #2, says: The configuration menu used to be called 'wifiwave2' in RouterOS versions before 7.13, where it was a part of the 'wifiwave2' software package. So when 7.12 with installed wifiwave2 package gets upgraded to 7.13beta1 (or newer), wifi-qcom (or wifi-qcom...
by mkx
Tue Nov 14, 2023 1:58 pm
Forum: Beginner Basics
Topic: Cannot get to the config page of pihole on mikrotik [SOLVED]
Replies: 9
Views: 1873

Re: Cannot get to the config page of pihole on mikrotik [SOLVED]

You do realize that container images them selves are not Mikrotik's business, right? Anything you place inside container image is on you, you have to find relevant documentation (possibly on container package maintainer's site). Mikrotik only makes possible to run container images and that's where t...
by mkx
Tue Nov 14, 2023 1:43 pm
Forum: Beginner Basics
Topic: Upgrading without 2 reboots
Replies: 6
Views: 1453

Re: Upgrading without 2 reboots

What is possible to do to avoid double reboots, but requires quite some manual work: download main package of new ROS version for correct device platform open it using 7zip and extract correct routerboot firmware file. It's inside etc/ folder, but most platform packages contain multiple firmware fil...
by mkx
Tue Nov 14, 2023 1:31 pm
Forum: Beginner Basics
Topic: Multiple Subnets on Single Bridge Issues
Replies: 8
Views: 1629

Re: Multiple Subnets on Single Bridge Issues

Even if I can do VLAN tagging based on specific MAC addresses I would still need to route the traffic from bridge->bridge which I would think would result in the same behavior. Nope, from IP layer point of view, it would be vlanX <-> vlanY traffic ... in this case, bridge interface has no meaning a...
by mkx
Mon Nov 13, 2023 11:15 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 93341

Re: v7.13beta [testing] is released!

Do devices running the new wifi-qcom-ac package still have the old wifiwave2 limitation where VLANs couldn't be configured? Found it in the wiki: 802.11ac chipsets do not support this type of VLAN tagging (vlan-id), but they can be configured as VLAN access ports in bridge settings. Just upgraded m...
by mkx
Mon Nov 13, 2023 10:08 pm
Forum: RouterBOARD hardware
Topic: Mikrotik hAP AC² power indicator
Replies: 1
Views: 1690

Re: Mikrotik hAP AC² power indicator

hAP ac2 has a few led lit during normal operation: power led on tge same side as ethernet ports and power jack - between power jack and ether ports. It's steadily lit after power on. ethernet activity leds on the otger side ... beliw those dot pictograms (those dots are supposed to represent the num...
by mkx
Mon Nov 13, 2023 9:44 pm
Forum: Beginner Basics
Topic: Multiple Subnets on Single Bridge Issues
Replies: 8
Views: 1629

Re: Multiple Subnets on Single Bridge Issues

I stand by my first line of my previous post.

I'd think again (and again) about necessity to run two IP subnets over single ethernet broadcast domain.
by mkx
Mon Nov 13, 2023 9:40 pm
Forum: Announcements
Topic: v7.12.1 [stable] is released!
Replies: 252
Views: 95313

Re: v7.12 [stable] is released!

I was unable to import the public key ED25519 from my YubiKey, I successfully imported ed25519 keys, created by openssh. The pub file starts with "ssh-ed25519 ", continues with 69 characters (the actual publuc key) and followed with key owner identification (user@host). Format of file on ...
by mkx
Mon Nov 13, 2023 1:51 pm
Forum: General
Topic: I lost my license [SOLVED]
Replies: 4
Views: 1688

Re: I lost my license [SOLVED]

Do as it says: write to support@mikrotik.com
by mkx
Mon Nov 13, 2023 12:16 pm
Forum: Scripting
Topic: LTE Link Speed Calculation?
Replies: 6
Views: 1675

Re: LTE Link Speed Calculation?

As long as you take into account the differences between different technologies when estimating throughput from SINR, then you should get some sensible results. Just don't react on minor differences, when estimating throughput from SINR the error margin can even exceed 50% (I guess).
by mkx
Mon Nov 13, 2023 9:17 am
Forum: Wireless Networking
Topic: Mikrotik topology - Too many clients error
Replies: 2
Views: 1024

Re: Mikrotik topology - Too many clients error

As the error message says: disc-lite5 already serves maximum number of clients and the new one is not allowed to connect. Two things, in order from less important to the critical one: taking from description from diagram "PTP BRIDGE AP" ... I'm assuming that disc-lite5 is running in "...
by mkx
Mon Nov 13, 2023 9:09 am
Forum: Wireless Networking
Topic: hAP ax2, station mode: Unable to connect to ancient wifi using WPA-PSK w/ TKIP
Replies: 3
Views: 1542

Re: hAP ax2, station mode: Unable to connect to ancient wifi using WPA-PSK w/ TKIP

This seems to be ax-related bug. So I suggest you to create supout file at the time when ax2 is unable to communicate with OpenWRT (WPA-TKIP only) ... and open trouble ticket with support@mikrotik.com.
by mkx
Mon Nov 13, 2023 8:50 am
Forum: Beginner Basics
Topic: Multiple Subnets on Single Bridge Issues
Replies: 8
Views: 1629

Re: Multiple Subnets on Single Bridge Issues

You've placed yourself in a pond of mud ... I assume your client devices are configured with /24 subnet and proper gateway address, so initially they don't know a squat about the other subnet being available on the same physical network. And this is what happens: deviceA (e.g. from 10.0.0.0/24 subne...
by mkx
Mon Nov 13, 2023 8:25 am
Forum: General
Topic: Bridge Troubles
Replies: 3
Views: 816

Re: Bridge Troubles

I don't use DoH, so I can't provide you with definitive answer here. But: your setup uses FQDN of DoH server ... so before DNS DoH client on your router can resolve anything, it has to resolve FQDN of DoH server itself. Do you see the chicken-egg problem here? There are a few ways out, one is to set...
by mkx
Sun Nov 12, 2023 9:21 pm
Forum: Beginner Basics
Topic: Quick Guide?
Replies: 37
Views: 3277

Re: Quick Guide?

According to specs, both devices you mentioned are nearly identical wireless-wise. So they should perform similarly as long as positions of AP and clients doesn't change. Any obstacles, even TV set, negatively affect the range and throughput. When there's an obstacle close to a device (either AP or ...
by mkx
Sun Nov 12, 2023 4:18 pm
Forum: RouterBOARD hardware
Topic: RB5009
Replies: 6
Views: 2190

Re: RB5009

Honestly, it's not even worth the effort. It has no impact on router performance and is not indicative of any issue at all. Thank you! Netinstall didn't helped. :( Netinstall formats flash disk in a sense of writing new filesystem metadata. But I highly doubt that it does low-level format of flash ...
by mkx
Sun Nov 12, 2023 4:07 pm
Forum: General
Topic: sfp info not shown/eeprom-checksum: bad [SOLVED]
Replies: 10
Views: 4507

Re: sfp info not shown/eeprom-checksum: bad [SOLVED]

Meanwhile, still can not understand how to get to SFP Module information page... The IP manually assigned to the SFP interface leads to RouterOS Web GUI... :? If you try to access IP address, assigned to one of ROS interfaces, then ROS believes (rightfully so) that you're trying to use ROS service....
by mkx
Sun Nov 12, 2023 2:04 pm
Forum: General
Topic: IPv4 Fast Path not activated [SOLVED]
Replies: 6
Views: 1307

Re: IPv4 Fast Path not activated [SOLVED]

... Mikotik Manual:Fast Path says that FastTrack is FastPath+Connection Tracking. Does it means that FastTrack contains Fast Path? My interpretation is that without fastpath there is no fasttrack. However I have mixed feelings about the importance of fastpath ... as fastoath manual specifies, there...
by mkx
Sun Nov 12, 2023 12:31 pm
Forum: Scripting
Topic: LTE Link Speed Calculation?
Replies: 6
Views: 1675

Re: LTE Link Speed Calculation?

You really can't AFAIK. In theory it's possible, in practice not so much. SINR figure gives a very good estimate about maximum possible spectral efficiency. Google for "SINR throughput" to read more and get some tables/charts (one random link ). But then there are other unknowns. SINR val...
by mkx
Sun Nov 12, 2023 11:40 am
Forum: General
Topic: IPv4 Fast Path not activated [SOLVED]
Replies: 6
Views: 1307

Re: IPv4 Fast Path not activated [SOLVED]

Well, if you're running firewall, then fastpath doesn't make much sense (if I understand its function correctly, it's a shortcut between different drivers and traffic then bypasses some of generic L2 of ROS and all of L3, for firewalling such shortcuts should not happen). Fasttract is (again accordi...
by mkx
Sun Nov 12, 2023 11:19 am
Forum: Beginner Basics
Topic: Quick Guide?
Replies: 37
Views: 3277

Re: Quick Guide?

The information, shown in the screenshot, is actually data about reception on RB951 side for that particular wireless station (station doesn't report its stats to AP). So the values shown by AP mostly depend on station's transmit capabilities and (to a lesser extent) on AP's reception capabilities (...
by mkx
Sat Nov 11, 2023 6:47 pm
Forum: Announcements
Topic: v7.12.1 [stable] is released!
Replies: 252
Views: 95313

Re: v7.12 [stable] is released!

... I was assured that this bug has been fixed in the 7.12 branch.
Well, it isn't. Still...
[sarcasm]
Well, 7.12 branch isn't abandoned/surpassed yet.
[/sarcasm]
by mkx
Sat Nov 11, 2023 4:56 pm
Forum: RouterBOARD hardware
Topic: RB5009 power IN voltage range
Replies: 10
Views: 7213

Re: RB5009 power IN voltage range

I guess the concept you described is quite fine. If you care about autonomy while on batteries, make sure you get a highly efficient DC-DC down-converter. Some shitty ones can have efficiency as low as 50% and difference between 0.5A and 1A of power draw for 10W load (at 24V) is significant if batte...
by mkx
Sat Nov 11, 2023 4:39 pm
Forum: Announcements
Topic: v7.12.1 [stable] is released!
Replies: 252
Views: 95313

Re: v7.12 [stable] is released!

Noticed that on all of them I needed to reboot a second time to upgrade the routerboard firmware despite having "/system routerboard settings set auto-upgrade=yes" configured. That's expected and has been so ever since auto-upgrade is available. The reason is that .fwf files with new rout...
by mkx
Sat Nov 11, 2023 10:11 am
Forum: RouterBOARD hardware
Topic: MIKROTIK RB5009UG+S+IN DC Pin Power Failure [SOLVED]
Replies: 7
Views: 3124

Re: MIKROTIK RB5009UG+S+IN DC Pin Power Failure [SOLVED]

I don't think you can get around this "positive-negative" mismatch without DC-DC converter. Unless you're willing to mount RB so that metallic parts of its chassis don't touch metallic parts of rack and other devices (i.e. have its chasis galvanically isolated from the rest of your DC). Yo...
by mkx
Sat Nov 11, 2023 9:57 am
Forum: General
Topic: problem with my routerboard 5009_no save graph after rebooot
Replies: 7
Views: 896

Re: problem with my routerboard 5009_no save graph after rebooot

It could be 5009 specific (i.e. a bug), but anyway: check how frequently graphing data gets stored to flash, it's under Tools->Graphing->Interface Rules->Graphing Settings ... it seems that default is 24 hours, try setting it to shorter interval. This probably won't make the bug disappear, but you'l...
by mkx
Fri Nov 10, 2023 10:15 pm
Forum: RouterBOARD hardware
Topic: MIKROTIK RB5009UG+S+IN DC Pin Power Failure [SOLVED]
Replies: 7
Views: 3124

Re: MIKROTIK RB5009UG+S+IN DC Pin Power Failure [SOLVED]

I think @pe1chl is right: telco DC power supply is nominally -48V, so positive on chasis. IT gear, if DC powered, is almost always +48V, so negative on chasis.
by mkx
Fri Nov 10, 2023 9:41 pm
Forum: General
Topic: Can't ping gateway from vlan
Replies: 3
Views: 840

Re: Can't ping gateway from vlan

The config may partly work but it's all wrong. Have a look at this tutorial about how to properly configure VLANs on mikrotik devices.
by mkx
Fri Nov 10, 2023 6:02 pm
Forum: General
Topic: OS 7 -long term
Replies: 17
Views: 1875

Re: OS 7 -long term

You are wrong. Let's have a look... v6.48.4 [stable] on Mon Aug 23, 2021 v6.49 [stable] on Thu Oct 07, 2021 v6.48.5 [long-term] on Fri Oct 08, 2021 What your table doesn't show and I'm not sure it's possible to get that missing info from the past: when exactly did 6.48.x got promoted into long-term...
by mkx
Fri Nov 10, 2023 3:57 pm
Forum: General
Topic: OS 7 -long term
Replies: 17
Views: 1875

Re: OS 7 -long term

Which existing version should become long-term?

My favourite kebab-retailer said that 7.1.5 was a good one ...
by mkx
Fri Nov 10, 2023 11:25 am
Forum: General
Topic: Bridge Troubles
Replies: 3
Views: 816

Re: Bridge Troubles

Trying to figure out why Bridge is passing packets through firewall. Packets from where to where? Since your posted setup heavily deviates from defaults, I strongly suggest you to disable detect-internet , i.e. /interface/detect-internet/set detect-interface-list=none . As to DNS: you're heavily ma...
by mkx
Thu Nov 09, 2023 9:17 pm
Forum: General
Topic: Bonding interface breaks bridge
Replies: 4
Views: 743

Re: Bonding interface breaks bridge

How would you implement this within a flat network setup? Either simply add bond interface (bonding1) to bridge1 which makes the bond (from layer 2 perspective) equal member of LAN network. You can do teh same on both devices, in that case use one as switch only, without firewalling, routing, DHCP ...
by mkx
Thu Nov 09, 2023 7:26 pm
Forum: Announcements
Topic: v7.12.1 [stable] is released!
Replies: 252
Views: 95313

Re: v7.12 [stable] is released!

Hi buy one Rb L41G-2axD I upgraded from 7.8 to 7.12and the Wireless interface disappeared, what should I do to get the wireless interface back?
Install wifwave2 package (from extra packages). Next time use built-in upgrade feature which upgrades all installed packages automaticalky.
by mkx
Thu Nov 09, 2023 7:19 pm
Forum: General
Topic: Mikrotik packet Sniffer Broken?
Replies: 2
Views: 681

Re: Mikrotik packet Sniffer Broken?

Are you sure that bridge HW offload is disabled (at least for ports which are of interest)?
by mkx
Thu Nov 09, 2023 7:14 pm
Forum: General
Topic: Bonding interface breaks bridge
Replies: 4
Views: 743

Re: Bonding interface breaks bridge

Huh? This is definitely a no-go: /ip address add address=192.168.1.9/24 interface=bridge1 network=192.168.1.0 add address=192.168.1.31/24 interface=bonding1 network=192.168.1.0 You can't have two independent interfaces with same network address and expect for router to figure it out. And if the same...
by mkx
Thu Nov 09, 2023 7:06 pm
Forum: Beginner Basics
Topic: Quick Guide?
Replies: 37
Views: 3277

Re: Quick Guide?

Config says that device should be transmitting SSID with name MikroTik-2C00AA and that it's an open AP, i.e. no password needed and no encryption used over the air. Config also says it's running ancient ROS version and that config has a minor error in config (due to error in default config): LAN IP ...
by mkx
Thu Nov 09, 2023 4:31 pm
Forum: Announcements
Topic: v7.12.1 [stable] is released!
Replies: 252
Views: 95313

Re: v7.12 [stable] is released!

RB951G boots with 7.12. Can't say if it's stable, nobody's at home ATM. ;-)
by mkx
Thu Nov 09, 2023 4:29 pm
Forum: General
Topic: crs309 poor 10gb performance
Replies: 28
Views: 2676

Re: crs309 poor 10gb performance

Post #11 above (by @jericho63) IMO shows that throughput problems are not due to traffic hitting CPU (it'd be much higher than 2% at 2.5Gbps) but some other reasons, internal to how switch chip handles the traffic. High CPU load while running btest is usual but has nothing with normal traffic handli...
by mkx
Thu Nov 09, 2023 2:54 pm
Forum: General
Topic: crs309 poor 10gb performance
Replies: 28
Views: 2676

Re: crs309 poor 10gb performance

Did you try to enable flow control (both Tx and Rx) on all involved ports? The thing that bothers a switch the most is speed change - from faster to slower port. In this case switch has to buffer data and we all know that buffer bloat is bad. So when that tiny buffer fills up, switch has two choices...
by mkx
Thu Nov 09, 2023 2:49 pm
Forum: General
Topic: FIDO ed25519 user ssh keys
Replies: 1
Views: 611

Re: FIDO ed25519 user ssh keys

From release notes of 7.12 (released today):
*) ssh - added support for user ed25519 public keys;
So upgrade to 7.12 and check if it works for you. If not, then ask for support directly MT support (support@mikrotik.com), posting in this forum won't help (much).
by mkx
Thu Nov 09, 2023 12:30 pm
Forum: Beginner Basics
Topic: dstnat rules not works
Replies: 13
Views: 1924

Re: dstnat rules not works

If you try to access PiHole web interface by connecting to that IP address explicitly and you don't get the expected behaviour, then this has nothing to do with dst-nat, it has either something to do with routing or config on PiHole device itself. So post full config of your router to see if it's th...
by mkx
Thu Nov 09, 2023 12:29 pm
Forum: Beginner Basics
Topic: Understanding ARP
Replies: 2
Views: 919

Re: Understanding ARP

To get better idea about what's going on you may want to fire up wireshark on client and capture all communication. But in a nutshell it's like this: client has IP address 192.168.0.254, netmask /24 and gateway 192.168.0.1. Let's assume there are no specific routing rules on client. similarly server...
by mkx
Thu Nov 09, 2023 8:20 am
Forum: Beginner Basics
Topic: Quick Guide?
Replies: 37
Views: 3277

Re: Quick Guide?

The whole wireless shebang should be under "Wireless" menu subtree (winbox, top part of left frame). Check the settings there. If you can't figure it out, then post the textual config export: open terminal window, execute command /export hide-sensitive file=anynameyouwish , fetch the resul...
by mkx
Wed Nov 08, 2023 10:15 pm
Forum: Beginner Basics
Topic: Quick Guide?
Replies: 37
Views: 3277

Re: Quick Guide?

Nothing wrong with it, IMO it was one of greatest Mikrotiks at its time. I've got 2 of gigabit variant (RB951G) at home and they are fine. Great as switches, fine as 2.4GHz APs (802.11 n only) with very decent range (being high-power wifi APs). A bit slow if used as routers (should handle 100Mbps ju...
by mkx
Wed Nov 08, 2023 10:07 pm
Forum: Beginner Basics
Topic: Better way to extend my wifi network with same SSID [SOLVED]
Replies: 1
Views: 1325

Re: Better way to extend my wifi network with same SSID [SOLVED]

If you can't go with wires, then configure naster wireless interface on cAP as station-bridge. The rest of config should be as dull as possible: create a btidge, set all interfaces as bridge ports (both ethernet interfaces, master wireless interface as well as virtual wireless interface), create a v...
by mkx
Wed Nov 08, 2023 9:46 pm
Forum: General
Topic: Problems on routing to second gateway
Replies: 12
Views: 1329

Re: Problems on routing to second gateway

If I understand you correctly, you're trying to use dual WAN with some policy-based routing? If that's right, then ... PBR works best if the device enforcing policy is the default/only gateway for LAN hosts. In case of your prefered provider that will mean double NAT but most of time this won't hurt...
by mkx
Wed Nov 08, 2023 9:38 pm
Forum: Beginner Basics
Topic: Quick Guide?
Replies: 37
Views: 3277

Re: Quick Guide?

Hi, I just received a new RB951 router ...

My, oh my .... that device is discontinued (note the filter settings), how did you manage to buy a new one?

Anyways, let me google that for you ... it's the first link offered.
by mkx
Wed Nov 08, 2023 7:00 pm
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93709

Re: v7.12rc is released!

at some time a release has to be made.

Says who? ;-)
by mkx
Wed Nov 08, 2023 4:16 pm
Forum: Wireless Networking
Topic: Devices connected on the same antenna cannot ping each other
Replies: 1
Views: 982

Re: Devices connected on the same antenna cannot ping each other

Assuming you're running legacy capsman (with separate configuration subtree under /capsman) ... your caps-man datapath config most probably lacks setting client-to-client-forwarding=yes ...
by mkx
Wed Nov 08, 2023 4:10 pm
Forum: General
Topic: Problem routing two bridges [SOLVED]
Replies: 4
Views: 961

Re: Problem routing two bridges [SOLVED]

ping from bridge0 to bridge1 address > ping 192.168.77.1 interface=bridge0 When you run ping with interface= property set, this actually overrides the egress interface selection (you probably expected that it somehow selects source IP address). Essentially you're overriding part of routing process,...
by mkx
Wed Nov 08, 2023 3:59 pm
Forum: Beginner Basics
Topic: Weird routing behavior with another CIDR
Replies: 4
Views: 963

Re: Weird routing behavior with another CIDR

A few errors in your config: you configure VLAN interface vlan100 on ether3 ... which is later enslaved as bridge port. You should never do that ... if ether3 is supposed to carry non-vlan traffic which is of interest of other bridge ports, then you should properly configure bridge with vlan filteri...
by mkx
Tue Nov 07, 2023 9:42 pm
Forum: Beginner Basics
Topic: LtAP LTE6 kit: underperforming mobile internet
Replies: 21
Views: 2659

Re: LtAP LTE6 kit: underperforming mobile internet

I also read that germany has 'deactivated' it's 3G. The freed up frequencies are used for LTE. Does the LtAP ignore those frequencies if I uncheck 3G? The 2G/3G/LTE checks are about technology, not about frequencies. So you can safely uncheck 2G and 3G, your LtAP will not ignore LTE on B1 and B8 (t...
by mkx
Tue Nov 07, 2023 7:55 am
Forum: Beginner Basics
Topic: IPv6 Configuration under Router OS 7
Replies: 39
Views: 3721

Re: IPv6 Configuration under Router OS 7

Your IPv6 settings are the same as I have when ISP uses simple IPv6 over ethernet. So I guess these should be fine unless your ISP requires something special ... Regarding prefix: DHCPv6 has two properties: pool-prefix-length which should be left set to 64 unless you know (much) better .. and prefix...
by mkx
Mon Nov 06, 2023 10:15 pm
Forum: Beginner Basics
Topic: IPv6 Configuration under Router OS 7
Replies: 39
Views: 3721

Re: IPv6 Configuration under Router OS 7

A question: what kind of technology (from your router's point of view) does your ISP use? Is it plain ethernet? Or is it PPPoE? In the later case default route is configured differently.
by mkx
Mon Nov 06, 2023 10:12 pm
Forum: Beginner Basics
Topic: IPv6 Configuration under Router OS 7
Replies: 39
Views: 3721

Re: IPv6 Configuration under Router OS 7

Dynamic gateway is missing. On my router I get such entry: Flags: D - DYNAMIC; A - ACTIVE; c - CONNECT, g - SLAAC; + - ECMP Columns: DST-ADDRESS, GATEWAY, DISTANCE DST-ADDRESS GATEWAY DISTANCE DAg ::/0 fe80::2cc8:1bff:fe77:dee6%vlan-99 1 Note the 'g' flag (gateway).
by mkx
Mon Nov 06, 2023 9:47 pm
Forum: Beginner Basics
Topic: IPv6 Configuration under Router OS 7
Replies: 39
Views: 3721

Re: IPv6 Configuration under Router OS 7

You can check actual state of IPv6 routing table by executing /ipv6/route/print But it comes with a gotcha: you have to run fairly recent ROSv7 ... 7.11.2 is fine but I don't remember when print command of routes started to display dynamic routes. You can also run /tool/traceroute 2001:4860:4860::88...
by mkx
Mon Nov 06, 2023 6:10 pm
Forum: Beginner Basics
Topic: IPv6 Configuration under Router OS 7
Replies: 39
Views: 3721

Re: IPv6 Configuration under Router OS 7

IPv6 routing is different than IPv4 .... in particular, DHCPv6 doesn't provide gateway information. Instead, Routing Anouncements are sent out by routers. By default, ROS is configured to ignore those ... which might be safe but it's wrong. You should enable it: /ipv6/settings/set accept-router-adve...
by mkx
Mon Nov 06, 2023 5:35 pm
Forum: Beginner Basics
Topic: IPv6 Configuration under Router OS 7
Replies: 39
Views: 3721

Re: IPv6 Configuration under Router OS 7

You should set address to your LAN interface. By setting whole address, you are not actually using pool functionality (which takes care that all prefixes actually fall into pool prefix space) risking invalid configuration in case that assigned prefix changes ... using pool changes in prefix are hand...
by mkx
Mon Nov 06, 2023 4:32 pm
Forum: Beginner Basics
Topic: IPv6 Configuration under Router OS 7
Replies: 39
Views: 3721

Re: IPv6 Configuration under Router OS 7

I don't know how exactly you configured those IPv6 addresses ... but in principle it should be done like this: /ipv6/address add address=::aa:bbcc:ddee from-pool=pool2 interface=exampleInterface The above will pull a yet-unused /64 prefix from named pool and add the postfix part set by address prope...
by mkx
Mon Nov 06, 2023 8:53 am
Forum: Beginner Basics
Topic: IPv6 Configuration under Router OS 7
Replies: 39
Views: 3721

Re: IPv6 Configuration under Router OS 7

When configuring DHCPv6 client, you should set (or rather: leave at default) pool-prefix-length=64. Because that's the prefix size created by the pool when one configures IPv6 address with from-pool=ZZZ property.
by mkx
Sat Nov 04, 2023 9:40 pm
Forum: Beginner Basics
Topic: DHCP Offer not received on other side of trunk [solved]
Replies: 12
Views: 2358

Re: DHCP Offer not received on other side of trunk

You'll have to show the config of both MTs ... export them to text file and copy-paste contents inside [code] [/code] block.
by mkx
Sat Nov 04, 2023 5:29 pm
Forum: Announcements
Topic: Newsletter #114 | September 2023
Replies: 72
Views: 15509

Re: Newsletter #114 | September 2023

The list, per-se, doesn't clarify the contiguous vs. non-contiguous, it just says it supports intra-band CA (e.g. 1+1).
by mkx
Sat Nov 04, 2023 1:12 pm
Forum: General
Topic: PPPoE Server on VLAN Interface with ARP Reply-Only [SOLVED]
Replies: 9
Views: 2275

Re: PPPoE Server on VLAN Interface with ARP Reply-Only [SOLVED]

PPPoE works directly over ethernet (MAC) so nothing that ARP can help you with. If you're using ARP reply-only as a sort of security measure, you'll have to reconsider your strategy.
by mkx
Sat Nov 04, 2023 1:08 pm
Forum: Beginner Basics
Topic: Isolating a LAN on a specific port
Replies: 7
Views: 1685

Re: Isolating a LAN on a specific port

All of rules where you have log=yes are suspects. It's not clear why neither input nor output interfaces are known, but if you find the exact rule logging these events it might be possible to find explanation.
by mkx
Fri Nov 03, 2023 10:48 pm
Forum: Wireless Networking
Topic: 5G Radio Not Working
Replies: 5
Views: 1303

Re: 5G Radio Not Working

Clients are connecting to 5G when they start the connection near the AP. If they connect at further distances, they don't switch from 2G to 5G when they get close to the AP. This behaviour very much depends on clients (and almost doesn't depend on AP). The wifiwave2 driver enables the roaming featu...
by mkx
Fri Nov 03, 2023 10:09 pm
Forum: Beginner Basics
Topic: LtAP LTE6 kit: underperforming mobile internet
Replies: 21
Views: 2659

Re: LtAP LTE6 kit: underperforming mobile internet

Try only activating LTE bands 2, 5, 12 and 41n (?) as these the only ones both provided by T-Mobile according to their FAQ ...
The bands you're mentioning are not used in Europe. Bands, mentioned by @OP in OP, are just fine.
by mkx
Fri Nov 03, 2023 3:18 pm
Forum: Beginner Basics
Topic: LtAP LTE6 kit: underperforming mobile internet
Replies: 21
Views: 2659

Re: LtAP LTE6 kit: underperforming mobile internet

The maximum speed for 3g is 7.2 Mbps. Actually UMTS/HSPA (3G used in Europe and hence Gernany) can be a bit faster, but not many MNOs kept up with 3G development after they rolled out LTE. Most HSPA networks go up to 21Mbps (DL), another step is 42Mbps (but that's sort of CA, not many HSPA networks...
by mkx
Fri Nov 03, 2023 3:06 pm
Forum: Wireless Networking
Topic: LHGs - repeatedly losing Winbox connection
Replies: 15
Views: 3017

Re: LHGs - repeatedly losing Winbox connection

Two suggestions (not sure if any if them will help): disable "Detect internet" ... winbox is only allowed through LAN interfaces and if "detect internet" somehow misdetects and "proclaims" LAN interface as WAN, then you loose connectivity. IMO "Detect internet"...
by mkx
Fri Nov 03, 2023 2:49 pm
Forum: General
Topic: Slow Internet Speed Sophos RED and Mikrotik
Replies: 1
Views: 426

Re: Slow Internet Speed Sophos RED and Mikrotik

A far shot: if firewall rules (including mangle) are incompatible with fasttrack, user throughput drops to the floor. If you post mikrotiks' config (text export), we might be able to help you better.
by mkx
Fri Nov 03, 2023 12:48 pm
Forum: General
Topic: Mikrotik router mode with two external ports [SOLVED]
Replies: 1
Views: 524

Re: Mikrotik router mode with two external ports [SOLVED]

Sure thing. Before doing anything else, create backup fetch file off device (so you can revert to current config in case something goes wrong). Also get winbox (if you don't have it already) for the same reason (it can connect to MT device even if IP setup is FUBAR). The most straight-forward way (b...
by mkx
Fri Nov 03, 2023 9:52 am
Forum: Wireless Networking
Topic: hap3 low WiFi speed [SOLVED]
Replies: 8
Views: 2175

Re: hap3 low WiFi speed [SOLVED]

0 - install wifiwave2 package (and reconfigure wireless setup, wifiwave2 uses different configuration tree). You're running legacy wireless drivers and those make much slower wireless than the new wifiwave2 drivers. And you're lucky to have hAP ac3 which is one of few pre-ax devices capable of runni...
by mkx
Thu Nov 02, 2023 10:29 pm
Forum: Wireless Networking
Topic: Chateau 5g ax 5ghz Network just disappeared
Replies: 5
Views: 1316

Re: Chateau 5g ax 5ghz Network just disappeared

I'd be very surprised if 5GHz interface goes silent and there's nothing in logs. The only explanation would be older version of ROS running on your Chateau ax. In early ROS 7.x versions there were quite some bugs in wifiwave2 driver, in latest versions (7.11.2 as of time I'm writing this) wireless w...
by mkx
Thu Nov 02, 2023 9:25 pm
Forum: Wireless Networking
Topic: hap ax3/ax2 with jumbo frames
Replies: 6
Views: 1453

Re: hap ax3/ax2 with jumbo frames

... may we connect it on L2 with keeping every bridge own MTU? No, you can not. MTU is integral property of a L3 network ... which most of times overlaps with L2 broadcast domain (or L2.5 if one uses some advanced L2 tech, such as VLAN). Fragmentation is performed by L3 entity (IP stack of e.g. a r...
by mkx
Thu Nov 02, 2023 9:10 pm
Forum: General
Topic: Config CRS-4C+8XG
Replies: 7
Views: 727

Re: Config CRS-4C+8XG

Correct. You also don't add bridge port to list of VLAN members.
by mkx
Thu Nov 02, 2023 5:27 pm
Forum: General
Topic: Mikrotik HAP AX3 2.5gb not working
Replies: 5
Views: 806

Re: Mikrotik HAP AX3 2.5gb not working

Again: how exactly does the network topology look like when hAP ax3 is in the picture? BTW, when doing speedtests, try to select same server every time. My experience is that some servers some times give lower results than others. If your ISP runs their own speedtest server, use that one, many ISPs ...
by mkx
Thu Nov 02, 2023 5:25 pm
Forum: General
Topic: Config CRS-4C+8XG
Replies: 7
Views: 727

Re: Config CRS-4C+8XG

I can be helpful, but I don't like spoon-feeding fellow users. So: did you go through tutorial I linked in my previous post? If yes, what exactly seems to be a problem?
by mkx
Thu Nov 02, 2023 4:21 pm
Forum: General
Topic: Mikrotik HAP AX3 2.5gb not working
Replies: 5
Views: 806

Re: Mikrotik HAP AC3 2.5gb not working

One thing that does affect throughout is the fact that hAP ax3 has only got one 2.5Gbps port ... so if you connect it between PC and cable, one of legs will be limited to 1Gbps. Next: if you're trying to use wireless, make sure hAP ax3 is connected to cable using the 2.5Gbps port. Then: default wire...
by mkx
Thu Nov 02, 2023 3:18 pm
Forum: Scripting
Topic: Stop a script running from the scheduler [SOLVED]
Replies: 17
Views: 3319

Re: Stop a script running from the scheduler [SOLVED]

It seems that you can't stop those scripts. But reconsider the strategy of your script ... or implement some checks. If it's run every minute, does it have to run in endless loop? Perhaps you could drop the loop and rely on scheduler to run it frequently. Or add ability to detect already running scr...
by mkx
Thu Nov 02, 2023 3:04 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110829

Re: Bypassing AT&T Residential Gateways with MikroTik

Why would HW Offload break my configuration? Most probably switch chip can not (or is not properly set-up by bridge to) work with required 802.1Q headers. And since WAN port is the only port of that bridge, offloading doesn't make much of a difference, apart from handling 802.1Q headers (which seem...
by mkx
Thu Nov 02, 2023 2:48 pm
Forum: Beginner Basics
Topic: SFP Help
Replies: 4
Views: 1248

Re: SFP Help

GPON SFPs are pretty tricky in ROS as well.
by mkx
Thu Nov 02, 2023 2:40 pm
Forum: Wireless Networking
Topic: Setup cAP ax With Multiple SSIDs for VLANs
Replies: 44
Views: 5828

Re: Setup cAP ax With Multiple SSIDs for VLANs

Yup, capsman2 (with wave2 CAPs) definitely improves mobility (roaming), so it's sensible to run capsman2 even for only 2 compatible APs. And since capsman2 shares quite some configuration with local wifiwave2 instance, I wouldn't be so negative about using capsman anymore (this was way different for...
by mkx
Thu Nov 02, 2023 2:34 pm
Forum: Wireless Networking
Topic: Chateau 5g ax 5ghz Network just disappeared
Replies: 5
Views: 1316

Re: Chateau 5g ax 5ghz Network just disappeared

Some of 5GHz channels are subject to radar detection ... if AP detects anything remotely similar to radar signals it has to stop transmitting and search for different channel. Depending on particular setup it might be too limired to find a different channel to use. However, something should be in lo...
by mkx
Thu Nov 02, 2023 2:31 pm
Forum: Wireless Networking
Topic: WiFi Wave2 CAPsMAN Lokal CAP fails
Replies: 4
Views: 1616

Re: WiFi Wave2 CAPsMAN Lokal CAP fails

In few words: I can't run CAPsMAN and a CAP on the same device. You don't have to ... and you're not supposed to. Wifiwave2 and capsman2 share setup, so you should provision local wifiwave2 interfaces directly, just use same security profiles (datapaths can be different).. All the bells and whistle...
by mkx
Thu Nov 02, 2023 10:57 am
Forum: Wireless Networking
Topic: Wireless Bridge to Multiple SSIDs / WLANs
Replies: 1
Views: 1066

Re: Wireless Bridge to Multiple SSIDs / WLANs

station-pseudobridge has many gotchas, including the one which requires wired device to communicate with main network do that station-pseudobridge device (hAP ac lite) learns mapping between IP address and MAC. In general wireless bridges really work nice (transparent etc.) only if both AP and stati...
by mkx
Thu Nov 02, 2023 10:46 am
Forum: General
Topic: Access single IP on a different interface
Replies: 1
Views: 466

Re: Access single IP on a different interface

Having same nerwork addresses on different interfaces always means problems. And case when connected device has same IP address as router itself (even though on unrelatted interface) borders to impossible. Fixing your setup by changing some network address is much easier than working around it. Whic...
by mkx
Thu Nov 02, 2023 10:40 am
Forum: General
Topic: ISP binding internal IP address
Replies: 11
Views: 2027

Re: ISP binding internal IP address

what a shitty forum You have specific issues particular to your ISP (I could be calling names here), which don't have much with Mikrotik and ROS. You can't realistically expect a cookbook recipe for solving your problem if none of forum members ever encountered similar issues. Can you? And calling ...
by mkx
Thu Nov 02, 2023 10:35 am
Forum: General
Topic: CRS309-1G-8S+IN limited to 2.5 Gbps internet speed?
Replies: 2
Views: 889

Re: CRS309-1G-8S+IN limited to 2.5 Gbps internet speed?

100-feet long stretch of UTP cable is pretty long (it's actually more than 30m which is rating of your SFP module). Even though it's a CAT-8 and thus good for some high throughputs, reachable range depends on transciever's power capabilities ... and longer stretches require quite high power, not man...
by mkx
Thu Nov 02, 2023 10:19 am
Forum: Beginner Basics
Topic: Isolating a LAN on a specific port
Replies: 7
Views: 1685

Re: Isolating a LAN on a specific port

The firewall you're currently using onky drops unwanted connections coming in via ether1 (the penultimate rule) in selective way - it doesn't affect DSTNAT-ed connections. The last rule drops a few more connectiobs (which are not dropped by previous rule). But: your firewall doesn't have any rule wh...
by mkx
Thu Nov 02, 2023 10:07 am
Forum: Beginner Basics
Topic: Switch unreachable after adding second one on management vlan [SOLVED]
Replies: 3
Views: 1338

Re: Switch unreachable after adding second one on management vlan [SOLVED]

The config export is not complete. But anyway: never add VLAN interface back to bridge as port. Instead you should be setting bridge pirt as tagged member of MGMT VLAN. /interface bridge vlan add bridge=bridge comment=LAN tagged= bridge, sfp-sfpplus4,ether10 untagged=MGMT_NET vlan-ids=900 And make s...
by mkx
Wed Nov 01, 2023 9:21 pm
Forum: General
Topic: SFP port causes "PSU entered state FAIL"
Replies: 5
Views: 1096

Re: SFP port causes "PSU entered state FAIL"

By shuffling SFP modules around you more or lesd prooved it's likely a matter of faulty SFP cage. I've no idea if it can be (easily) repaired. So you should avoid using it (yeah, I know). Or try to find a module that doesn't trip the problem and is useful to you, my hunch is that a non-DDM module mi...
by mkx
Wed Nov 01, 2023 4:34 pm
Forum: RouterBOARD hardware
Topic: RB450Gx4 DC in 24V but PoE out only 9V [SOLVED]
Replies: 7
Views: 3889

Re: RB450Gx4 DC in 24V but PoE out only 9V [SOLVED]

MT devices typically don't do voltage conversions for PoE. If you measured much lower PoE out voltage than supply voltage (0.1V is acceptable, 15V is not), then there's a hardware damage in your device.
by mkx
Wed Nov 01, 2023 4:29 pm
Forum: General
Topic: SFP port causes "PSU entered state FAIL"
Replies: 5
Views: 1096

Re: SFP port causes "PSU entered state FAIL"

It seems that there's single i2c bus in your device and that both power supplies' management and SFP's DDM interfaces connect to that bus. And if sone device hogs that i2c bus, then polling status of other devices times out. It's hard to tell why SFP5 seems to be a problem, could be it's (manufactur...
by mkx
Wed Nov 01, 2023 4:19 pm
Forum: General
Topic: Config CRS-4C+8XG
Replies: 7
Views: 727

Re: Config CRS-4C+8XG

If properly configured, both OSes should provide equal performance. ROS seems to be much better supported these days (active development) though ... As to ROS configuration: use single bridge and use VLANs (even if they are strictly internal to device) to separate traffic between different port grou...
by mkx
Wed Nov 01, 2023 4:11 pm
Forum: Beginner Basics
Topic: Layer 2 tunnel over the internet , options?
Replies: 4
Views: 1409

Re: Layer 2 tunnel over the internet , options?

The very first question, which pops in my mind when reading your post, is: why L2 connectivity? Unless you have very specific reason, L3 connectivity would be better in several aspects.
by mkx
Wed Nov 01, 2023 4:06 pm
Forum: Beginner Basics
Topic: CAP 5G interface inactive state
Replies: 2
Views: 974

Re: CAP 5G interface inactive state

I am having some issues enabling 5G on my CAP devices, so far CAP devices are registered and able to see them in the CAP-interface, however the state it comes in is inactive. If you're referring to state of wireless interface (and in conjunction with it as bridge port), then status "not runnin...
by mkx
Wed Nov 01, 2023 3:24 pm
Forum: Announcements
Topic: Newsletter #114 | September 2023
Replies: 72
Views: 15509

Re: Newsletter #114 | September 2023

if you are on a saturated tower getting max 10%, CA isn’t going to do a whole lot ... My experience (my previous career was senior radio engineer for incumbent MNO) is that indeed CA doesn't make miracles. But in most cases it will increase user's throughput anywhere between 25% and 300% depending ...
by mkx
Wed Nov 01, 2023 1:50 pm
Forum: Announcements
Topic: Newsletter #114 | September 2023
Replies: 72
Views: 15509

Re: Newsletter #114 | September 2023

I would argue that areas with such low speed demands might be better with a cheaper LTE modem and the CAT 6 and up more suited to areas with gigabit ports. These days it's imposible to get near modem or cell tower maximum throughput, with many concurrent devices we're all aiming at getting roughly ...
by mkx
Wed Nov 01, 2023 12:14 am
Forum: General
Topic: hAP AC2 random boot loop
Replies: 9
Views: 2280

Re: hAP AC2 random boot loop

Firewall address lists can consume quite a bit of permanent storage ... my solution on a hAP ac2 since upgraded to v7 is to not use firewall address lists, at least nothing with more than a few tens of members (I've learned my lesson the hard way - I had to netinstall device to get out of death spir...
by mkx
Tue Oct 31, 2023 7:27 pm
Forum: General
Topic: DMZ VLANs
Replies: 3
Views: 623

Re: DMZ VLANs

You should be using single bridge. And yes, you should be using firewall. The two items above are not correlated (i.e. by using multiple bridges one doesn't bypass necessity for firewall). And no, creating DMZ doesn't really depend on switch chip - in some cases switch chip can offload CPU but AFAIK...
by mkx
Tue Oct 31, 2023 4:35 pm
Forum: General
Topic: Static routing does not work without NAT
Replies: 7
Views: 1221

Re: Static routing does not work without NAT

Another question, does 1:1 NAT described by mkx implies that I have to assign all of my private hosts addresses to one WAN interface? If your ISP assigns you a subnet (e.g. /28) and reserves one IP address for own use (telling you to use it as upstream gateway address), then this means that those I...
by mkx
Tue Oct 31, 2023 4:22 pm
Forum: General
Topic: RB1100AHx4 VLAN with HW offload with multiple switch chips
Replies: 15
Views: 2784

Re: RB1100AHx4 VLAN with HW offload with multiple switch chips

From performance point of view ... yes. I guess (I don't have a RB1100 nor RB4011 to test) that both bridges would be HW offloaded, specially so if one would take care to "enslave" correct set of ports. Passive wire instead of power hungry CPU. The only difference is 1Gbps (wire) vs. 2.5Gb...
by mkx
Tue Oct 31, 2023 2:48 pm
Forum: General
Topic: Pihole container run out of disk space [SOLVED]
Replies: 10
Views: 1255

Re: Pihole container run out of disk space [SOLVED]

/disk set usb1 type=hardware add parent=usb1 partition-number=1 partition-offset=512 partition-size=\ "128 035 675 648" type=partition The above is configuration. If you execute /disk/print you'll see actual running values, one of them being slot . Also observe flags column, it should con...
by mkx
Tue Oct 31, 2023 12:52 pm
Forum: Beginner Basics
Topic: Inter-Vlan Routing on CRS112-8G-4S-IN
Replies: 10
Views: 1681

Re: Inter-Vlan Routing on CRS112-8G-4S-IN

Nothing you can do on CRS (apart from disabling that SRC NAT rule). Instead you have to configure Sophos with static route towards your LAN. I'm not familiar with sophos syntax, in Mikrotik diakect it would be this /ip/route add dst-address=192.168.200.0/24 gateway=10.0.0.2 Quite likely Sophos will ...
by mkx
Tue Oct 31, 2023 10:45 am
Forum: General
Topic: RB1100AHx4 VLAN with HW offload with multiple switch chips
Replies: 15
Views: 2784

Re: RB1100AHx4 VLAN with HW offload with multiple switch chips

The interconnect between both switch chips traverses CPU so it can't be HW accelerated (CPU has to shift all the bits). True HW acceleration would be if both switch chips would interconnect directly (i.e. you'd have switch port named e.g. switch1-switch2 just like you have switch1-cpu). You can make...
by mkx
Tue Oct 31, 2023 10:41 am
Forum: General
Topic: WifiWave2 Guest network with external router for DHCP
Replies: 7
Views: 1922

Re: WifiWave2 Guest network with external router for DHCP

You should post configuration of both Mikrotiks to get any meaningful feedback. Execute /export hide-sensitive file=anynameyouwish in terminal window, fetch file off device, open it with text editor, redact any remaining sensitive data (such as serial number or wireless password; public IP address w...
by mkx
Tue Oct 31, 2023 10:32 am
Forum: General
Topic: RB3011, VLAN switching/routing and DHCP server
Replies: 11
Views: 1333

Re: RB3011, VLAN switching/routing and DHCP server

I.e. whatever chipset differences can exist within the same family but different models, they are masked by standardized CLI which might slightly differ in command args only. As @tdw already explained, you are overdoing things. The problem with MT is not lack of grand unified UI for L2 stuff, unifi...
by mkx
Mon Oct 30, 2023 8:38 pm
Forum: General
Topic: RB3011, VLAN switching/routing and DHCP server
Replies: 11
Views: 1333

Re: RB3011, VLAN switching/routing and DHCP server

... config depending on chipset used (which is very low level and should be taken care at another layer of abstraction ...
There is another abstraction level: bridge with VLAN filtering enabled. But it seems you don't like its performance on your particular device.
by mkx
Sun Oct 29, 2023 1:03 pm
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93709

Re: v7.12rc is released!

However, different wireless drivers do interact with passing frames beyond basic MAC addressing and some drivers might burp on frames they don't recognize. I think the problem is that the drivers have to do some kind of workaround to replace ARP. The WiFi has the same MAC for all clients, but they ...
by mkx
Sun Oct 29, 2023 11:02 am
Forum: Beginner Basics
Topic: DHCP Offer not received on other side of trunk [solved]
Replies: 12
Views: 2358

Re: DHCP Offer not received on other side of trunk

Does the same issue persist if you bypass the OpenWRT (i.e. if you connect wAP ac to same trunk port of ac2)?
by mkx
Sat Oct 28, 2023 5:42 pm
Forum: Beginner Basics
Topic: Static IPv6 DNS entries
Replies: 12
Views: 2227

Re: Static IPv6 DNS entries

When thinking about parsing ND info ... keep in mind that every IPv6 device can have multiple IPv6 addresses active and some of them will change over time (that's one of design goals of SLAAC). Also router will only have host in neighbour table if host communicates via router (if it only communicate...
by mkx
Sat Oct 28, 2023 4:41 pm
Forum: General
Topic: Case Study: Disabling NAT and Firewall on LAN Routers
Replies: 11
Views: 1322

Re: Case Study: Disabling NAT and Firewall on LAN Routers

This can work without NAT on LRs. Instead you have to configure routing on WR. Either by adding a number of static routes or by running a routing protocol (e.g. BGP or OSPF) on the interconnection segment ... In either case you have to make sure all those LAN segments (off LR routers) have unique ad...
by mkx
Sat Oct 28, 2023 2:33 pm
Forum: Beginner Basics
Topic: Static IPv6 DNS entries
Replies: 12
Views: 2227

Re: Static IPv6 DNS entries

ROS DHCPv6 server doesn't hand out IPv6 addresses, do you can not assign static leases. So I guess this means your plans can't be done solely using ROS. If you come up with idependent way of setting computers with static IPv6 addresses (either 3rd party DHCPv6 server or manual setup), then you can c...
by mkx
Sat Oct 28, 2023 1:40 pm
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93709

Re: v7.12rc is released!

In theory every 802.11 device should be able to pass 802.1Q tagged packet if it fits the MTU of wireless interface. After all, the 802.1Q header comes after usual ethernet headers and from ethernet point of view only payload type differs (from e.g. IPv4 or IPv6 payload type). And that doesn't affect...
by mkx
Sat Oct 28, 2023 12:51 pm
Forum: General
Topic: Large file copying to my NAS kills Wifi and LAN for all other home users
Replies: 8
Views: 1886

Re: Large file copying to my NAS kills Wifi and LAN for all other home users

Where should I start looking at? First you have to diagnose what exactly means "freezes all other network traffic". Obviously that's not exactly the case as your own observation goes: you can still get very decent throughput from your PC to internet (or is it the other way around?). Think...
by mkx
Sat Oct 28, 2023 11:22 am
Forum: General
Topic: What happens internally on router when packet sniffer is enabled?
Replies: 10
Views: 1353

Re: What happens internally on router when packet sniffer is enabled?

Indeed your config doesn't contain anything that fasttrack might be affecting. Fastpath is another thing. I see you're setting slightly larger-than-standard MTU on VLAN interfaces ... what are MTU and L2MTU settings on underlying physical interface (sfpplus1)? Make sure they are both large enough to...
by mkx
Sat Oct 28, 2023 11:10 am
Forum: Beginner Basics
Topic: Inter-Vlan Routing on CRS112-8G-4S-IN
Replies: 10
Views: 1681

Re: Inter-Vlan Routing on CRS112-8G-4S-IN

L2 config: https://wiki.mikrotik.com/wiki/Manual:CRS1xx/2xx_series_switches_examples L3 config: just like ordinary router running ROS. Since you'll have VLANs on switch chip, bridge will be configured as VLAN-agnostic entity. But you'll need vlan interfaces, one per VLAN, and IP setup will be bound ...
by mkx
Sat Oct 28, 2023 10:55 am
Forum: Beginner Basics
Topic: DNS Server
Replies: 3
Views: 1290

Re: DNS Server

dig 'mobilesvr' returns SERVFAIL As per RFC 1034 domain names are either absolute and are composed from multiple (that's 2 or more) parts, delimited with a dot "." ... or relative which doesn't contain a dot, and, when used, software needs to append domain name. Each DNS entry should be t...
by mkx
Fri Oct 27, 2023 9:48 pm
Forum: Wireless Networking
Topic: AP+STA mode in parallel on 2.4GHz and 2 different subnets
Replies: 2
Views: 1183

Re: AP+STA mode in parallel on 2.4GHz and 2 different subnets

... if I create wifi3 and make it "slave" of wifi2 to also function on 2.4GHz it simply doesn't work and in status it always says "scanning". Basics first: only master interface can set properties of physical radio, prime example is frequency used. Any slave interface will piggy...
by mkx
Fri Oct 27, 2023 4:35 pm
Forum: General
Topic: What happens internally on router when packet sniffer is enabled?
Replies: 10
Views: 1353

Re: What happens internally on router when packet sniffer is enabled?

Post the config of router so we can see what exactly is configured. Without it, we can only guess. And that ain't fun to me.
by mkx
Fri Oct 27, 2023 4:31 pm
Forum: Beginner Basics
Topic: Dynamic interface list members added automatically [SOLVED]
Replies: 4
Views: 1559

Re: Dynamic interface list members added automatically [SOLVED]

Many people wonder about perils of detect intetnet. To disable it, it's best to set all items to "none" (without the double quotes).
by mkx
Fri Oct 27, 2023 4:16 pm
Forum: General
Topic: What happens internally on router when packet sniffer is enabled?
Replies: 10
Views: 1353

Re: What happens internally on router when packet sniffer is enabled?

I'm not aware of fasttrack messing with individual packets. But it does mess with certain firewall features. One of them is mangling.
by mkx
Fri Oct 27, 2023 2:06 pm
Forum: General
Topic: Bridge without interfaces [SOLVED]
Replies: 2
Views: 872

Re: Bridge without interfaces [SOLVED]

And using IP address which is router's own address on that "non-populated" bridge is separate issue any way. Because when router processes packets, it first checks if the packet is targeting any of its own addresses (and performs appropriate action, DST-NAT is one possibility, servicing re...
by mkx
Fri Oct 27, 2023 9:21 am
Forum: Beginner Basics
Topic: Inter-Vlan Routing on CRS112-8G-4S-IN
Replies: 10
Views: 1681

Re: Inter-Vlan Routing on CRS112-8G-4S-IN

... CRS112 have a dedicate chip for switch and l3 hardwareoffloading

Where did you see L3 HW offloading mentioned for CRS112 (it does have L3 functionality but not performance)? There are products that indeed feature L3 HW offloading, but those are in CRS3xx family.
by mkx
Fri Oct 27, 2023 8:04 am
Forum: General
Topic: What happens internally on router when packet sniffer is enabled?
Replies: 10
Views: 1353

Re: What happens internally on router when packet sniffer is enabled?

Enabling packet sniffer disables fasttrack/fastpath. So you need to check with your config why any of these two break your data streams (and fasttrack is prime suspect).
by mkx
Fri Oct 27, 2023 7:45 am
Forum: General
Topic: Bridge not forwarding fragmented packets from PPPoE server
Replies: 1
Views: 559

Re: Bridge not forwarding fragmented packets from PPPoE server

Check MTU size of bridge ports (L2MTU property). If I understand you right, bridge is passing PPOoE frames. So it won't do fragmentation, no L2 device does fragmentation (only router / L3 device can), so you have to ensure that resulting frames are snall enough to pass all L2 entities. PPPoE comes w...
by mkx
Fri Oct 27, 2023 7:39 am
Forum: General
Topic: created SUP-132403 about adding an option in winbox to enable safe mode on connection
Replies: 2
Views: 600

Re: created SUP-132403 about adding an option in winbox to enable safe mode on connection

Just as you see use cases for what you requested (keep user from locking self out of router by dedsult) I can see the oposite: many users forgetting to press that "commit" (or "un-safe" or whatever) button before logging out and thus loosing all the changes made during the sessio...
by mkx
Thu Oct 26, 2023 9:45 pm
Forum: SwOS
Topic: CRS106-1C-5S SWOS
Replies: 5
Views: 5452

Re: CRS106-1C-5S SWOS

Product page in Specifications under Operating System doesn't list SwOS ... for devices actually offering dual boot this item lists both OSes.

So no, it's not possible to run SwOS on CRS106-1C-5S.
by mkx
Thu Oct 26, 2023 9:35 pm
Forum: General
Topic: port forwarding specific domain / hostname
Replies: 5
Views: 862

Re: port forwarding specific domain / hostname

No, ROS NAT is layer 4 (TCP or UDP) function. For your needs you need a layer 7 server (reverse proxy). All the popular web servers can do it (nginx, apache, etc.) and there are some specialized products (haproxy, traefik, etc.) None of them are available natively in ROS, but you can run (at least s...
by mkx
Thu Oct 26, 2023 9:23 pm
Forum: Beginner Basics
Topic: Inter-Vlan Routing on CRS112-8G-4S-IN
Replies: 10
Views: 1681

Re: Inter-Vlan Routing on CRS112-8G-4S-IN

Can I use the CRS112 as a Layer 3 switch?

You can (as @tangent already wrote). BUT: the performance will be waaaay lower than wirespeed. L3 is on CRS1xx entirely done by CPU and your switch's CPU is pretry slow.
by mkx
Thu Oct 26, 2023 7:04 pm
Forum: Beginner Basics
Topic: How to find router password
Replies: 36
Views: 4135

Re: How to find router password

When router is reset to factory defaults, then admin password is reset as well. Newer devices have default password printed on a label (which is more or less hidden), older devices have empty default password. If you have newer device but the label was destroyed or lost, then theoretically official ...
by mkx
Thu Oct 26, 2023 6:22 pm
Forum: General
Topic: LtAP LTE6 usb power reset -- which bus number?
Replies: 18
Views: 1728

Re: LtAP LTE6 usb power reset -- which bus number?

When on line with MT support it would be worth to ask if those mini-PCIe slots actually are powered via USB bus. It could be that they are powered independently (if they're dual-bus, USB and PCIe, then they need independent powering for times when PCIe device uses the slot) and in this case it would...
by mkx
Thu Oct 26, 2023 4:19 pm
Forum: General
Topic: RB750GR3 local network speed capped at 100mbps [SOLVED]
Replies: 15
Views: 2268

Re: RB750GR3 local network speed capped at 100mbps [SOLVED]

Which local speed? You only have routed interfaces which means there is no local traffic. IMO "local traffic" would be traffic bridged/switched between ports members of same (local) subnet. As @tangent wrote: you have queues all over the place, affecting all (vast majority?) of traffic .....
by mkx
Thu Oct 26, 2023 10:46 am
Forum: Beginner Basics
Topic: Is a Masquerade rule necessary to access hardware from another network
Replies: 5
Views: 1233

Re: Is a Masquerade rule necessary to access hardware from another network

Do I understand correctly that with the created masquerade rule, the router will replace my address (192.168.0.28) in packets with its own (192.168.123.1)? That's the basic idea about SRC NAT. Action can be either src-nat or masquerade, both will replace src-address (and possibly src-port), details...
by mkx
Thu Oct 26, 2023 9:20 am
Forum: Beginner Basics
Topic: Is a Masquerade rule necessary to access hardware from another network
Replies: 5
Views: 1233

Re: Is a Masquerade rule necessary to access hardware from another network

Very probably ... because likely the "alien" equipment you need to connect doesn't use your MT router as its default gateway. Adding that src-nat rule will make "alien" device believe that traffic is coming from router itself and that one has IP address in same IP subnet as "...
by mkx
Thu Oct 26, 2023 9:17 am
Forum: General
Topic: RB750GR3 local network speed capped at 100mbps [SOLVED]
Replies: 15
Views: 2268

Re: RB750GR3 local network speed capped at 100mbps [SOLVED]

... local speed capped at 100mbps (its should 1gbps) Which local speed? You only have routed interfaces which means there is no local traffic. IMO "local traffic" would be traffic bridged/switched between ports members of same (local) subnet. As @tangent wrote: you have queues all over th...
by mkx
Wed Oct 25, 2023 5:06 pm
Forum: RouterBOARD hardware
Topic: Failure with hAP AC3 WiFi coverage
Replies: 20
Views: 4681

Re: Failure with hAP AC3 WiFi coverage

set [ find default-name=wlan2 ] adaptive-noise-immunity=ap-and-client-mode allow-sharedkey=yes band=5ghz-a/n/ac channel-width=20/40/80mhz-XXXX country=canada2 disabled=no frequency=5745 mode=ap-bridge \
ssid="Edwin(5G)"

set time-zone-name=America/Puerto_Rico

Ts, ts, ts ...
by mkx
Wed Oct 25, 2023 5:04 pm
Forum: RouterBOARD hardware
Topic: hAPax2 RAM size 1GB or 128MB ?
Replies: 18
Views: 3783

Re: hAPax2 RAM size 1GB or 128MB ?

Some of enumerated features were gone with some reasons. E.g. displays were soem times placed on top of unit ... which can be rack-mountable. In that case it was obscured by equipment, mounted above such unit ... and thus useless. In addition, display activity (refreshes) was frequently causing real...
by mkx
Wed Oct 25, 2023 4:52 pm
Forum: Wireless Networking
Topic: LHGG - change modem for CAT12/16?
Replies: 18
Views: 2967

Re: LHGG - change modem for CAT12/16?

Indeed that's the biggest issue when it comes to mobile broadband performance. Physical layer (LTE carriers) is shared medium and a very congested one (many concurrent users). I would agree, but for the mast I connect to, if I walk towards it (and achieve additional tree clearance), BW increases si...
by mkx
Wed Oct 25, 2023 3:07 pm
Forum: General
Topic: How is that possible at all: traceroute reports 2 hops with same IP
Replies: 5
Views: 1088

Re: How is that possible at all: traceroute reports 2 hops with same IP

If packet, used by traceroute (linux traceroute usually uses UDP packet, targeting a random high port, some traceroute tools use ICMP packets), is DST-NATed, then the same final address will be shown twice: when TTL expires at the moment when packet hits NAT-performing device and that device replies...
by mkx
Wed Oct 25, 2023 10:41 am
Forum: RouterBOARD hardware
Topic: Failure with hAP AC3 WiFi coverage
Replies: 20
Views: 4681

Re: Failure with hAP AC3 WiFi coverage

/interface/wireless/info/hw-info <5G interface> whould show HW capabilities of a particular radio. hAP ac2 (pretty similar wireless hardware as hAP ac3) says "ranges: 4920-5925/5/a,an20,an40,ac20,ac40,ac80" However, wikipedia channel list lists part of UNII3 as indoor-only in certain regi...
by mkx
Wed Oct 25, 2023 10:37 am
Forum: Wireless Networking
Topic: LHGG - change modem for CAT12/16?
Replies: 18
Views: 2967

Re: LHGG - change modem for CAT12/16?

I'm just of opinion that congestion is what kills you,

Indeed that's the biggest issue when it comes to mobile broadband performance. Physical layer (LTE carriers) is shared medium and a very congested one (many concurrent users).
by mkx
Wed Oct 25, 2023 8:56 am
Forum: General
Topic: LtAP LTE6 usb power reset -- which bus number?
Replies: 18
Views: 1728

Re: LtAP LTE6 usb power reset -- which bus number?

Can I upgrade the firmware to 6.49.8 remotely?

You can. And it's mostly safe to do it.
by mkx
Wed Oct 25, 2023 7:43 am
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93709

Re: v7.12rc is released!

It seems that the bridge and/or the ethernet port is taken down before the NFS share is unmounted? In "normal" linux servers, when NFS server is stopped, it doesn't communicate with clients, it simply drops dead. (After that, NFS clients might hang waiting for NFS server to get alive agai...
by mkx
Tue Oct 24, 2023 10:44 pm
Forum: Wireless Networking
Topic: LHGG - change modem for CAT12/16?
Replies: 18
Views: 2967

Re: LHGG - change modem for CAT12/16?

... whatever difference in CAT6 to CAT18 offer using same 2x2 antenna is going to be some smaller percentages (e.g. there is also FEC rate associated with the QAM, so performance is still pretty linear) Linear? Indeed higher modulations will only bring improvement in throughput in perfect radio con...
by mkx
Tue Oct 24, 2023 10:23 pm
Forum: General
Topic: Mikrotik Car Charger
Replies: 4
Views: 893

Re: Mikrotik Car Charger

Also: only a fraction of MT products accept power supply in range of 10V-14.5V (which is voltage range expected during car operation).
by mkx
Mon Oct 23, 2023 9:14 pm
Forum: General
Topic: Confimation: Model LHG R-R11e-LTE
Replies: 2
Views: 725

Re: Confimation: Model LHG R-R11e-LTE

The built-in modem, R11e-LTE, does support LTE band 20.

Just a word of wisdom: LHG has pretty poor antenna gain for lower frequencies (below 1GHz) (source: LHG-LTE brochure). So if signal strength of your chosen MNO is not good, then don't expect stelar performance.
by mkx
Mon Oct 23, 2023 6:22 pm
Forum: SwOS
Topic: No SwOS for CRS310-8G+2S+ ?
Replies: 9
Views: 3661

Re: No SwOS for CRS310-8G+2S+ ?

IIRC initial design goal was to support dual-OS on all CRS3xx devices. It seems MT gave up on this quite early into introduction of devices from this family, so it's likely that your CRS won't see SwOS support. But as @holvoetn suggested, you better ask support@miktotik about that.
by mkx
Mon Oct 23, 2023 6:15 pm
Forum: Beginner Basics
Topic: SwOS’s Independent VLAN Lookup feature in RouterOS
Replies: 1
Views: 1161

Re: SwOS’s Independent VLAN Lookup feature in RouterOS

I guess you're talking about "IVL - Independent Learning" ... and is the only mode supported by bridge (most switches support also SVL - Shared learning). But my guess is that this is not your problem, probably it's RSTP ... if you're connecting two bridges/switches using two physical link...
by mkx
Mon Oct 23, 2023 6:01 pm
Forum: General
Topic: Downloading and uploading using scp
Replies: 6
Views: 2279

Re: Downloading and uploading using scp

I was using these commands: scp user@router:usb1-part1/log.5.txt . scp log.5.txt user@router:flash/ My router has USB stick plugged in (it's mounted under /usb1-part1) and I have logging configured to store files there. The first command fetched one of older log files to linux PC. The second command...
by mkx
Mon Oct 23, 2023 5:48 pm
Forum: General
Topic: Downloading and uploading using scp
Replies: 6
Views: 2279

Re: Downloading and uploading using scp

It is possible to scp single file ... just don't include the leading / on path to sorce file name. Example: scp username@router:flash/skins/default.json . Essentially it's exactly the same as shown by /file/print . And copying files to router works the same way ... without leading / in the destinati...
by mkx
Mon Oct 23, 2023 5:08 pm
Forum: SwOS
Topic: No SwOS for CRS310-8G+2S+ ?
Replies: 9
Views: 3661

Re: No SwOS for CRS310-8G+2S+ ?

Even more conclusive: product page doesn't mention SwOS at all.

Only a handful of CRS devices actually support dual boot and product pages of those do mention both OSes as supported. One example is CRS326-24G-2S+IN.
by mkx
Mon Oct 23, 2023 3:04 pm
Forum: General
Topic: LtAP LTE6 usb power reset -- which bus number?
Replies: 18
Views: 1728

Re: LtAP LTE6 usb power reset -- which bus number?

I don't have a LtAP LTE6 so I can't say this with confidence. But the way I understand product description and block diagram, the device has only one LTE modem built in (and it's shown on the output you showed in previous post), connected to USB bus. This card can use either SIM2 or SIM3 slot. Then ...
by mkx
Mon Oct 23, 2023 2:39 pm
Forum: Beginner Basics
Topic: GrooveA52ac - 2.4GHz and 5GHz at the same time?
Replies: 2
Views: 1117

Re: GrooveA52ac - 2.4GHz and 5GHz at the same time?

Groove has single dual-band radio, so it can only operate in one frequency at any time. If you need dual connectiviry, then you have to use true dual-radio device (any other Mikrotik with support for both 2.4GHz and 5GHz) or two devices.
by mkx
Mon Oct 23, 2023 9:17 am
Forum: RouterBOARD hardware
Topic: crs326 access problem [SOLVED]
Replies: 5
Views: 3519

Re: crs326 access problem [SOLVED]

Is the admin MAC set on bridge unique in your network?
by mkx
Sun Oct 22, 2023 9:41 pm
Forum: General
Topic: Adding a new WAN to eth4 passthrough on RouterOS 7.11.2 (RB941-2nD)
Replies: 7
Views: 931

Re: Adding a new WAN to eth4 passthrough on RouterOS 7.11.2 (RB941-2nD)

What you're describing is "bridging" eth1 and eth4 ... which obviously involves a bridge. A straight-forward way would be to create a new bridge, move eth4 to it and add eth1 to it. Which would imediately invalidate all WAN IP setup ... you'd have to move everything, which refers to eth1, ...
by mkx
Sun Oct 22, 2023 5:35 pm
Forum: Wireless Networking
Topic: Wireless station scanning issue
Replies: 6
Views: 2004

Re: Wireless station scanning issue

When using wireless interface as router upstream interface, it should not be part of any bridge. Only when wireless interface is stand-alone, it can be used directly for L3 stuff (e.g. DHCP client). To allow wireless interface to connect to different APs, you configure them in interface/wifiwave2/ac...
by mkx
Sun Oct 22, 2023 3:35 pm
Forum: Beginner Basics
Topic: WIFI VLAN on ax^2
Replies: 4
Views: 1504

Re: WIFI VLAN on ax^2

Anything higher than 1 will do (though it is probably limited). Right, VLAN ID is limited to 12 bits, which limits values to range 0-4095. However, 0 and 4095 are reserved values, which leaves values 1-4094 for normal use (both values included). As @erlinden mentioned, most vendors abuse VID 1 as s...
by mkx
Sun Oct 22, 2023 3:28 pm
Forum: General
Topic: EoIP routing
Replies: 3
Views: 1032

Re: EoIP routing

You're asking about problem with your routing but you don't provide the setup you have (and serms to have an error in it)?
by mkx
Sun Oct 22, 2023 3:26 pm
Forum: General
Topic: SFP functionality on CRS125-24G-1S
Replies: 6
Views: 906

Re: SFP functionality on CRS125-24G-1S

... CRS125 does HW offloading in ROS v6... L2 yes, L3 not. And in v7 the L2 HW offload on CRS125 remains just the same as it was in v6. Please note that I'm not trying to persuade you into buying a new L2 switch, I'm just fixing some misplaced statements not to mislead other readers. So I simply st...
by mkx
Sun Oct 22, 2023 2:57 pm
Forum: General
Topic: Pwd and Pwd-wlan faulty
Replies: 4
Views: 950

Re: Pwd and Pwd-wlan faulty

I guess the only ambiguous character in Pwd is the third one ... which is capital o ("oh") ... if it was digit zero, it would be crossed.
by mkx
Sun Oct 22, 2023 2:52 pm
Forum: Wireless Networking
Topic: Capsman - all devices for a SSID connect to only one AP
Replies: 9
Views: 2134

Re: Capsman - all devices for a SSID connect to only one AP

You can either set MAC addresses for virtual AP interfaces or they will be created by ROS automatically. If you set them by hand, then you yourself have to make sure they are unique in your network (and neighbourhood). If ROS creates them automatically, then they will be based on physical interface'...
by mkx
Sun Oct 22, 2023 1:55 pm
Forum: General
Topic: Time to move from hEX to RB5009?
Replies: 20
Views: 2234

Re: Time to move from hEX to RB5009?

It's not an update, it's your data being sent in the wild (TX on your wan port).

The blue line (featuring a spike) is Rx.
by mkx
Sun Oct 22, 2023 1:16 pm
Forum: General
Topic: SFP functionality on CRS125-24G-1S
Replies: 6
Views: 906

Re: SFP functionality on CRS125-24G-1S

I beg to differ: CRS326-24G-2S+ has two SFP+ (10Gbps) ports while CRS125 has one SFP (1Gbos) port. In addition CRS326 supports (limited) L3HW offloading and can thus serve as a wirespeed router in a small(ish) multi-LAN environment (no stateful FW allowed so this feature really has limited usability...
by mkx
Sun Oct 22, 2023 11:39 am
Forum: General
Topic: MikroTik Pro (for Android)
Replies: 13
Views: 2658

Re: MikroTik Pro (for Android)

I guess Konstantin wonders to which of interfaces applies the "(Limited access)" part. I guess it wouldn't be a question is the output was "Available on lte1 (Limited access), ether1" ... or if the comment explicitly mentioned interface name. Or if MT dropped the "detect int...
by mkx
Sun Oct 22, 2023 11:31 am
Forum: General
Topic: LtAP LTE6 usb power reset -- which bus number?
Replies: 18
Views: 1728

Re: LtAP LTE6 usb power reset -- which bus number?

Command system/resource/usb/print will show (among others) device identification in format <bus>-<device>. Hopefully at least bus number doesn't change with each reboot ...
by mkx
Sat Oct 21, 2023 5:17 pm
Forum: Beginner Basics
Topic: One router, two separated LAN [SOLVED]
Replies: 5
Views: 1969

Re: One router, two separated LAN [SOLVED]

No VLAN ? Party spoiler ... :?
I'm sure @anav will jump out of the hEX s shortly and will tell all about VLANs :lol:
by mkx
Sat Oct 21, 2023 5:15 pm
Forum: General
Topic: RouterOS v7 x86_64 best hdd available? SSD enterprise? nvme ?
Replies: 3
Views: 845

Re: RouterOS v7 x86_64 best hdd available? SSD enterprise? nvme ?

Use whichever actually work with ROS. I don't know how is v7 support for storage, v6 was less than stellar in this regard. I'm not running any kind of similar setup, so I don't have 1st hand experience. But AFAIK ROS only uses permanent storage for own files, config and some limited amount of volati...
by mkx
Sat Oct 21, 2023 4:20 pm
Forum: Beginner Basics
Topic: One router, two separated LAN [SOLVED]
Replies: 5
Views: 1969

Re: One router, two separated LAN [SOLVED]

From performance point of view not optimal, but sytactically correct and probably easier to comprehend way would be: create two bridges (e.g. named LAN1 and LAN2) add ether2 and ether3 to LAN1 and ether4 and ether5 to LAN2 configure LAN1 with IP address for LAN network 1 configure DHCP server for LA...
by mkx
Sat Oct 21, 2023 11:13 am
Forum: Beginner Basics
Topic: Seperate lan subnets
Replies: 10
Views: 1890

Re: Seperate lan subnets

Rules for access router's own IP addresses by default don't care about ingress interface, so it's expected that you're able to ping addresses 192.168.1, 192.168.2.1 and 192.168.3.1 if access to router's "native" address is allowed. This is a cosmetic issue but if it really bothers you, it ...
by mkx
Sat Oct 21, 2023 10:35 am
Forum: General
Topic: Detect internet stopped working
Replies: 31
Views: 2894

Re: Detect internet stopped working

Another proof that benefits of "detect internet" functionality are ... questionable.
by mkx
Fri Oct 20, 2023 7:08 pm
Forum: Wireless Networking
Topic: LHGG - change modem for CAT12/16?
Replies: 18
Views: 2967

Re: LHGG - change modem for CAT12/16?

From RF point of view, CA modems will have multiple transmitters, each covering certain frequency band range. Hence set of supported CA combinations. E.g. if one radio covers both B3 and B1 ... 1800 and 2100 bands ... then B1+B3 CA combination is not supported. If second radio covers B8+B20+B68 (900...
by mkx
Fri Oct 20, 2023 6:58 pm
Forum: RouterBOARD hardware
Topic: New hAP ax lite LTE
Replies: 199
Views: 26703

Re: New hAP ax lite LTE

But perhaps physical memory reservation happens in the main package in expectation of the wifiwave2 package. Back in the day of plain BIOS and stupid MMUs, what happened was this: physical memory was contiguous address space and started from 0 to the RAM size (e.g. 33554431 for 32MB size). If there...
by mkx
Fri Oct 20, 2023 6:31 pm
Forum: General
Topic: IP masquerading issue
Replies: 3
Views: 1118

Re: IP masquerading issue

Not without seeing (full) configuration of router from building 2.
by mkx
Fri Oct 20, 2023 6:17 pm
Forum: General
Topic: Static routing does not work without NAT
Replies: 7
Views: 1221

Re: Static routing does not work without NAT

217.147.160.50 is outside 217.147.160.32/28 subnet (which spans from .32 to .47, first one being network address and last one being briadcast address). Next complication is use of addresses from same subnet on different interfaces. There are multiple ways out and which is the best largely depends o...
by mkx
Fri Oct 20, 2023 2:58 pm
Forum: Wireless Networking
Topic: LHGG - change modem for CAT12/16?
Replies: 18
Views: 2967

Re: LHGG - change modem for CAT12/16?

Different modems support different CA combinations. And CA combinations can be different in DL and UL. So yes, CA-capable modems can Rx on multiple frequencies at the same time and some (CAT 16 do) can Tx on multiple frequencies at the same time. Simultaneous Tx and Tx over multiple frequencies is t...
by mkx
Fri Oct 20, 2023 2:49 pm
Forum: General
Topic: (Resolved) NTP & DNS clients not working .. just firewall misconfig
Replies: 23
Views: 2372

Re: NTP & DNS clients not working .. device probably corrupted

/ip firewall filter add action=accept chain=input comment=CONNEXIONS_ETABLIES connection-state=established,related src-address-list=allowed_to_router This rule is unusual. Without the highlited part it is already pretty safe as it will only allow traffic which is already in some kind of established...
by mkx
Fri Oct 20, 2023 2:40 pm
Forum: General
Topic: hAp ax3 POE out?
Replies: 24
Views: 3937

Re: hAp ax3 POE out?

If you really want to have wifi AP and that door camera display daisy-chained, then obviously hAP ax3 is not the right product. There are a few APs by Mikrotik (yes, they are likely worse with regard to wireless performance) that would allow your intended topology. E.g. hAP ac lite TC (or non-TC var...
by mkx
Fri Oct 20, 2023 9:06 am
Forum: General
Topic: hAp ax3 POE out?
Replies: 24
Views: 3937

Re: hAp ax3 POE out?

But your video screen can be powered from CRS. @shazrul wants to daisy-chain the door intercomm display off ax3 and he wants to power that display off ax3 which in turn has to be powered over PoE as well. The way I see things, the design is flawed ... IMO (but that might be my own personal understa...
by mkx
Fri Oct 20, 2023 8:56 am
Forum: General
Topic: CRS326 switch
Replies: 1
Views: 565

Re: CRS326 switch

Connect those users to switch.
Connect switch to router using two connections and configure ports used into LACP bond (on both sides). Having them in bond will automatically load-ballance traffic across both physical links.
by mkx
Fri Oct 20, 2023 8:50 am
Forum: Announcements
Topic: WinBox v3.40 released!
Replies: 143
Views: 133557

Re: WinBox v3.40 released!

While it would be nice to have dark mode (I don't care though), the question why are certain users nagging about it with every new winbox version is highly relevant. Release threads in this forum (such as this) should be used to report bugs (possibly specific to the particular version). And lack of ...
by mkx
Thu Oct 19, 2023 10:22 pm
Forum: RouterBOARD hardware
Topic: Switch with poe & SFP
Replies: 10
Views: 2780

Re: Switch with poe & SFP

@mkx, am I missing something?

No, you're right. Seems I was looking at specs for hEX PoE lite when writing my post :oops:
by mkx
Thu Oct 19, 2023 10:12 pm
Forum: RouterBOARD hardware
Topic: CSS106 - VLANs Tab
Replies: 1
Views: 1894

Re: CSS106 - VLANs Tab

For reasons, similar to the one causing your confusion, is better not to use VLAN 1. If other vendor's equipment is actually using management over untagged (some call it "native VLAN"), then you can use any other VLAN ID on MT equipment and configure relevant ports as hybrid (i.e. tagged f...
by mkx
Thu Oct 19, 2023 10:05 pm
Forum: Wireless Networking
Topic: ax3 wifiwave2
Replies: 7
Views: 1624

Re: ax3 wifiwave2

Well, I want my apple trees to produce bananas ... but it's not gonna happen either :wink: The thing is that WiFi clients behave pretty much as they want and network infrastructure has to cope with it this way or another. Some device vendors (e.g. apple) are known to twist standards their way and th...
by mkx
Thu Oct 19, 2023 7:29 pm
Forum: Wireless Networking
Topic: ax3 wifiwave2
Replies: 7
Views: 1624

Re: ax3 wifiwave2

I don't think you can.

What exactly is the problem?
by mkx
Thu Oct 19, 2023 7:21 pm
Forum: Wireless Networking
Topic: ax3 wifiwave2
Replies: 7
Views: 1624

Re: ax3 wifiwave2

WiFi clients are puting their radios to sleep (power saving) and then wake up occasionally to check if they need to communicate. So any packets sent towards them will be buffered on AP for some time. They will put radios to sleep after some idle time (as few tens of miliseconds so ping response when...
by mkx
Thu Oct 19, 2023 7:00 pm
Forum: Beginner Basics
Topic: CRS1XX Access management on hybrid vlan port
Replies: 6
Views: 1190

Re: CRS1XX Access management on hybrid vlan port

IMO switching should entirely be done by switch chip according to your config, so this is fine. I'd just use another VLAN ID for management of the switch, personally I have always bad feeling mixing untagged traffic with tagged in inner parts of ROS.
by mkx
Thu Oct 19, 2023 6:44 pm
Forum: Beginner Basics
Topic: CRS1XX Access management on hybrid vlan port
Replies: 6
Views: 1190

Re: CRS1XX Access management on hybrid vlan port

Ability to HW offload does depend on switch model and CRS1xx doesn't support it. So you should configure your device according to these examples. You actually mostly did it.
by mkx
Thu Oct 19, 2023 4:05 pm
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93709

Re: v7.12rc is released!

If we were to wind back a bit regarding tagging/vlan and go back to documented basics I think that we'd better understand the tag/untag stuff around wave2 interfaces if we would consider the built-in wireless interface as if it was external ... then bridge would have several ports (etherX) and wifi...
by mkx
Thu Oct 19, 2023 10:34 am
Forum: Beginner Basics
Topic: CRS1XX Access management on hybrid vlan port
Replies: 6
Views: 1190

Re: CRS1XX Access management on hybrid vlan port

Post current config (in terminal window execute /export hide-sensitive file=anynameyouwish, fetch resulting file, open it with text editor, redact any remaining sensitive data and copy-ćpaste it inside [code] [/code] environment - the [] symbol above post editor).
by mkx
Thu Oct 19, 2023 10:32 am
Forum: Wireless Networking
Topic: Two ac^3 with wifiwave2: one no 5GHz [SOLVED]
Replies: 30
Views: 4916

Re: Two ac^3 with wifiwave2: one no 5GHz [SOLVED]

Which is why I asked for config...
... and which is why I asked about logs (wireless driver scanning for radars does emit log messages).
by mkx
Thu Oct 19, 2023 8:23 am
Forum: Beginner Basics
Topic: newbie doesn't undestand mikrotik logic
Replies: 12
Views: 2131

Re: newbie doesn't undestand mikrotik logic

If you want to use your hAP ax2 as CAP device, then you should configure QuickSet mode to "CAP" (currently it's Home AP Dual ... see upper left corner of your screenshot). If that mode is not available on hAP ax2, then you'll have to do things manually (come back in that case for further i...
by mkx
Thu Oct 19, 2023 8:18 am
Forum: Announcements
Topic: v7.12rc is released!
Replies: 225
Views: 93709

Re: v7.12rc is released!

So, wifi interfaces should in fact be among the tagged ports for the respective bridge VLAN, when VLAN filtering is enabled on the bridge. Except if the VLAN of the datapth is the same as the bridge's PVID, right? Because that's how mine behaves. Not exactly the same as with vlan-id set to 1. wifiw...
by mkx
Wed Oct 18, 2023 8:16 pm
Forum: General
Topic: Firewall Rule Order [SOLVED]
Replies: 4
Views: 950

Re: Firewall Rule Order [SOLVED]

Your rule has two (matcher) properties: src-address-list=LAN The address list (among others) contains 192.168.1.0/24, so if packet's src address is e.g. 192.168.1.20, this property matches src-address=!192.168.1.0/24 If packet's src address is 192.168.1.20, then this property doesn't match (property...
by mkx
Wed Oct 18, 2023 8:05 pm
Forum: SwOS
Topic: SwOS help for a trunk port
Replies: 17
Views: 4240

Re: SwOS help for a trunk port

Terminology slightly varies between vendors. Generally there are 3 types of ports (when it comes to VLANs) and in MT dialect they are called: access port Port which only accepts untagged frames on ingress and only transmits untagged frames on egress. It has set "default VLAN ID" or PVID wh...
by mkx
Wed Oct 18, 2023 7:39 pm
Forum: General
Topic: Firewall Rule Order [SOLVED]
Replies: 4
Views: 950

Re: Firewall Rule Order [SOLVED]

Firewall rule trigfers when all properties, which are set, match. Properties, even if they seem to be similar (like src-address and src-address-list), are not handled "intelligently", they are handled in very straight forward manner. There is no magic (or AI) behind it. And no precedence, ...
by mkx
Wed Oct 18, 2023 4:12 pm
Forum: SwOS
Topic: SwOS help for a trunk port
Replies: 17
Views: 4240

Re: SwOS help for a trunk port

Meaning of "VLAN mode = optional" is this: Disabled VLAN filtering . Handle packets with VLAN tag ID that is not present in VLAN table just like packets without VLAN tag. In laymans words: if VLAN mode is set to optional, then switch will handle frames according to VLAN receive setting, bu...
by mkx
Wed Oct 18, 2023 3:34 pm
Forum: Beginner Basics
Topic: How to tell if I'm behind NAT?
Replies: 4
Views: 2222

Re: How to tell if I'm behind NAT?

Any address, present on the list of IANA IPv4 special registry , is not truly public address. If your router receives one of those as WAN IP address this almost certainly means you're behind another layer of NAT (e.g. CG-NAT). And that inevitably brings problems with port accessibility and what not....
by mkx
Wed Oct 18, 2023 8:20 am
Forum: Beginner Basics
Topic: First time user - Diving into the deep end
Replies: 37
Views: 3671

Re: First time user - Diving into the deep end

You have to make BR1 port tagged member of relevant VLANs (in case of ether4 that's VLAN 10). Further more: if ether4 is to be access (untagged) port, then it should be set as untagged member of said VLAN. And vlan interfaces (i.e. VL10), anchored to bridge interface, should never be made bridge por...
by mkx
Tue Oct 17, 2023 11:56 pm
Forum: SwOS
Topic: SwOS help for a trunk port
Replies: 17
Views: 4240

Re: SwOS help for a trunk port

Ingress and egress are about the direction of a (tagged) frame when passing a port. Ingress port is the port which receives tge frame (from the wire). Egress port is the port via which frame ultimatelly leaves the switch (or there may be multiple in some particular cases). The first screenshot is ab...
by mkx
Tue Oct 17, 2023 11:38 pm
Forum: Wireless Networking
Topic: cAP ax 5 GHz not working
Replies: 15
Views: 3247

Re: cAP ax 5 GHz not working

Frequencies between 5260 and 5720 MHz (give or take, it slightly depends on country regulations) are subject to DFS. In short this means that when device selects such a frequency, it has to "listen" (without transmiting anything) for a minute or for 10 minutes (depending on particular freq...
by mkx
Tue Oct 17, 2023 11:32 pm
Forum: Wireless Networking
Topic: Two ac^3 with wifiwave2: one no 5GHz [SOLVED]
Replies: 30
Views: 4916

Re: Two ac^3 with wifiwave2: one no 5GHz [SOLVED]

Anything in logs?
by mkx
Tue Oct 17, 2023 11:24 pm
Forum: Beginner Basics
Topic: How can I enter as a neighbor?
Replies: 1
Views: 949

Re: How can I enter as a neighbor?

It's the firewall setup and mac-server setup, both by default rely on interface list membership. And it's extremely dangerous to allow access to router via usual intetnet so it's blocked by default. If you know better, you can easily change it.
by mkx
Tue Oct 17, 2023 12:04 pm
Forum: General
Topic: Is this an attack?
Replies: 5
Views: 962

Re: Is this an attack?

As port 22 (ssh) is a very well known these days, I'd be much surprised if some port scanner wouldn't check it. So I'd say that what you see is completely expected ... and thus logging attempts is only adding to log size. Personally I don't see any value (added or removed :wink:) in logging blocked ...
by mkx
Tue Oct 17, 2023 8:27 am
Forum: Beginner Basics
Topic: L3 Hardware offloading in Mikrotik
Replies: 2
Views: 1224

Re: L3 Hardware offloading in Mikrotik

The way things are implemented in ROS it's bridge functionality that gets offloaded to underlying switch (hardware). And L3HW offload is again offloaded to switch. Hence requirement to use bridge (and consequently VLANs to separate different networks) in order to offload anything to hardware. And th...
by mkx
Mon Oct 16, 2023 10:07 pm
Forum: RouterBOARD hardware
Topic: Switch with poe & SFP
Replies: 10
Views: 2780

Re: Switch with poe & SFP

This largely depends on switch providing PoE to RB960GSP ... one thing you have to keep in mind is voltage rating, it accepts 11-30V (so 802.3 af/at is out of question). If you go with 24V ... then 3 cAP ax devices use up to 10W each and 5W the switch, total around 35W which is roughly 1.5A (at ment...
by mkx
Mon Oct 16, 2023 4:15 pm
Forum: RouterBOARD hardware
Topic: Question about connection and choosing best router solution.
Replies: 12
Views: 2675

Re: Question about connection and choosing best router solution.

All of the devices (at least router and "core" switches) will have to deal with VLANs ... but IMO when going the VLAN path it's best to go all the way down to edge ports (i.e. ports to which the VLAN-ignorant devices are connected), which then includes also the small access switches. The o...
by mkx
Mon Oct 16, 2023 12:30 pm
Forum: RouterBOARD hardware
Topic: Switch with poe & SFP
Replies: 10
Views: 2780

Re: Switch with poe & SFP

PoE-in and multiple PoE-out are in reality exclusive ... PoE-in simply doesn't have capacity to provide power for multiple PoE-out ports. If you drop this requirement, then there are many devices which cover the rest of requirements, check the list of switches and lok for "xxP" in the mode...
by mkx
Mon Oct 16, 2023 12:25 pm
Forum: RouterBOARD hardware
Topic: Question about connection and choosing best router solution.
Replies: 12
Views: 2675

Re: Question about connection and choosing best router solution.

Creating different VLANs for different classes of devices makes lots of sense. The control over what they can do with regard to connections towards other networks (internet included) is a pretty big bonus. So I'm all for it. In particular: it would probably be easier to place recorder into same VLAN...
by mkx
Mon Oct 16, 2023 12:22 pm
Forum: Beginner Basics
Topic: Noob Shock and horror
Replies: 13
Views: 1852

Re: Noob Shock and horror

It's up to your decision whether you want to stay with v6 (truly stable version) or go with v7 (comes with some new functionality, such as wireguard and better support for switch chip on your device but is being pretty intensively developed meaning there are quite a few bugs and you'd have to upgrad...
by mkx
Mon Oct 16, 2023 9:01 am
Forum: RouterBOARD hardware
Topic: Question about connection and choosing best router solution.
Replies: 12
Views: 2675

Re: Question about connection and choosing best router solution.

I understood you just fine (the only "dangling" issue was if you'd combine 3a and 4 to have MLAG but you clarified that this was not planned) ... So the RSTP thing I was mentioning would be "5. ROUTER-RJ45 --> HP SW2" which would be normally blocked (by RSTP processes on both HP ...
by mkx
Mon Oct 16, 2023 8:43 am
Forum: RouterBOARD hardware
Topic: Question about connection and choosing best router solution.
Replies: 12
Views: 2675

Re: Question about connection and choosing best router solution.

It seems you like to complicate your network topology :wink: Since you're mentioning LAG ... additionally to have the both switches connected directly (i.e. cascade), you could connect both switches to main router and let RSTP do its job. If you can afford two connections between main rack and multi...
by mkx
Mon Oct 16, 2023 7:09 am
Forum: RouterBOARD hardware
Topic: Question about connection and choosing best router solution.
Replies: 12
Views: 2675

Re: Question about connection and choosing best router solution.

If you will setup LANs so that devices connected to both of your switches will communicate between each other (e.g. if you'll have a NAS connected to one of switches and clients connected to the other one), then I suggest you to connect switches directly and only connect the closest switch to router...
by mkx
Sun Oct 15, 2023 10:48 pm
Forum: Beginner Basics
Topic: Isolate single PC on LAN port [SOLVED]
Replies: 6
Views: 23675

Re: Isolate single PC on LAN port [SOLVED]

Bridge filters are, IMO, a bit unflexible (if not for other things they are not stateful). But if you can come up with some which will do the job for you, then by all means go for it.
by mkx
Sun Oct 15, 2023 10:45 pm
Forum: RouterBOARD hardware
Topic: Question about connection and choosing best router solution.
Replies: 12
Views: 2675

Re: Question about connection and choosing best router solution.

There are two CCR2004 models: CCR2004-1G-12S+2XS which @holvoetn is referring to and has all SFP+ ports connected to single switch (ether1 is meant for OOB management) and CCR2004-16G-2S+ which has SFP+ ports connected directly to CPU while RJ45 ports are handled by two distinct switch chips. The la...
by mkx
Sun Oct 15, 2023 10:28 pm
Forum: Beginner Basics
Topic: Isolate single PC on LAN port [SOLVED]
Replies: 6
Views: 23675

Re: Isolate single PC on LAN port [SOLVED]

You could try to use firewall rules to block according to MAC address ... but that would mean that main router would have to process all traffic through that particular port (shared between LAN device and "quaranteened" device) which might affect overall performance. But doable indeed. You...
  • 1
  • 3
  • 4
  • 5
  • 6
  • 7
  • 41