Community discussions

MikroTik App

Search found 19572 matches

by anav
Thu Jan 11, 2024 1:46 pm
Forum: Beginner Basics
Topic: DDoS help
Replies: 42
Views: 2758

Re: DDoS help

Sounds like shooting oneself in the foot.......
by anav
Thu Jan 11, 2024 1:44 pm
Forum: Beginner Basics
Topic: Firewall Rules maybe affecting Whatsapp
Replies: 3
Views: 1279

Re: Firewall Rules maybe affecting Whatsapp

Not true. I user whats app on my home wifi without any special settings for it. The mikrotik router is not app centric ( cannot block solely apps ) Your firewall rules are a bloated mess and probably have something to do with the issues. However, one needs to see the full config to asses what the fi...
by anav
Thu Jan 11, 2024 1:25 pm
Forum: Beginner Basics
Topic: DDoS help
Replies: 42
Views: 2758

Re: DDoS help

If truly DDOS then its the responsibility of your ISP and their upstream providers to counter an attack.
Your router is not equipped to do so.
by anav
Thu Jan 11, 2024 2:34 am
Forum: Beginner Basics
Topic: Difficulty Configuring Port Forwarding on RouterOS for Website Hosting
Replies: 2
Views: 648

Re: Difficulty Configuring Port Forwarding on RouterOS for Website Hosting

A couple of pointers on the last post. 1. The dst-nat rule does not require dst-address-type=local . 2 The general hairpin nat rule that will cover all servers in a subnet, or if just one............ one rule. add action=masquerade chain=srcnat comment="Hairpin NAT" dst-address= Local.Serv...
by anav
Thu Jan 11, 2024 2:29 am
Forum: Beginner Basics
Topic: Wireguard vpn
Replies: 2
Views: 641

Re: Wireguard vpn

Two ways, use of routing rules or use of mangles,
Either way you will need to add a table and an IP route.
by anav
Thu Jan 11, 2024 2:28 am
Forum: Beginner Basics
Topic: EOIP over Wireguard (For RoMon purposes only) [SOLVED]
Replies: 33
Views: 4353

Re: EOIP over Wireguard (For RoMon purposes only) [SOLVED]

Yes, gre is set as protocol. On remote router i left src address. I was lazy...
Showing the config or pertinent parts thereof would be nice!
by anav
Wed Jan 10, 2024 6:54 pm
Forum: Beginner Basics
Topic: EOIP over Wireguard (For RoMon purposes only) [SOLVED]
Replies: 33
Views: 4353

Re: EOIP over Wireguard (For RoMon purposes only) [SOLVED]

Do you set GRE protocol or not?
by anav
Wed Jan 10, 2024 6:48 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 299
Views: 244028

Re: NEW FEATURE: Back to Home VPN

Being of the drop all ilk at end of chains, I would prefer forward accept source-address=list=xxx out-interface-list=WAN disabled forward accept source-address-list=xxx out-interface-list=LAN disabled and let the admin decide if the users need one or the other or both. one could argue EQUALLY that p...
by anav
Wed Jan 10, 2024 6:36 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3492

Re: Wireguard Peers can't access IPs on VLANs

To RECAP. Hex is a router behind an upstream Router. The WAN IP for the hex is also its LANIP on the main subnet on the upstream router. The upstream router also has a guest subnet. The main subnet comes in on ether5 and we tag it with vlan200 The guest subnet comes in on ether2 and we tag it with v...
by anav
Wed Jan 10, 2024 4:15 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3492

Re: Wireguard Peers can't access IPs on VLANs

Okay, great feedback, not sure whats going on between hex and CHR......... but lets stick with hex reality.

Quick question. What IP addresses do the switches get ( from 900 vlan [( aka hex ) , or 200 vlan ( aka upstream router lan )] ??
by anav
Wed Jan 10, 2024 3:41 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3492

Re: Wireguard Peers can't access IPs on VLANs

The CHR has no LAN subnets may be the case?? The first rule allows all users coming in on wireguard to access all interfaces (subnets) listed in LAN. You may wish to provide limitations as to which subnets they have access to, or which wireguard users can access all subnets or even further which sub...
by anav
Wed Jan 10, 2024 1:58 pm
Forum: Beginner Basics
Topic: cAP ac bricked even with netinstall
Replies: 8
Views: 1441

Re: cAP ac bricked even with netinstall

Have a read of para H. for ideas. --> viewtopic.php?p=906567#p906567
by anav
Wed Jan 10, 2024 12:57 pm
Forum: General
Topic: Looking for a router for 10 Gigabit
Replies: 1
Views: 518

Re: Looking for a router for 10 Gigabit

2116 seems to have the specs you need.
by anav
Tue Jan 09, 2024 9:18 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 299
Views: 244028

Re: NEW FEATURE: Back to Home VPN

a. Why does the BTH config on the MT create a firewall rule blocking remote client to local LAN interface? Mine is empty. Not sure how the "back-to-home-lan-restricted-peers" address-list in firewall gets populated actually. So rule does nothing in my case. b. Why does the BTH config on t...
by anav
Tue Jan 09, 2024 8:42 pm
Forum: General
Topic: Forward WAN port to another subnet/router LAN [SOLVED]
Replies: 8
Views: 2076

Re: Forward WAN port to another subnet/router LAN [SOLVED]

Connecting via WG to remote?
Too much missing info.
Post full configs on both routers
/export file=anynameyouwish ( minus router serial number, public WANIP information, keys etc.)
by anav
Tue Jan 09, 2024 8:40 pm
Forum: General
Topic: dst-nat port forwarding not working
Replies: 8
Views: 1357

Re: dst-nat port forwarding not working

Okay, so this is all good information to know prior to looking at the config. The config is a story and the story is starting to make sense. Will have a relook at the config with a more informed context. :-) To be clear, a. do you get two public IPs from your ISP provider and sending one to Other lo...
by anav
Tue Jan 09, 2024 8:38 pm
Forum: General
Topic: Wi‑Fi 7 / 802.11be
Replies: 36
Views: 12147

Re: Wi‑Fi 7 / 802.11be

Only when I get my wifi7 smartphone which is what vendors should be aiming for in the home market.
by anav
Tue Jan 09, 2024 8:35 pm
Forum: Beginner Basics
Topic: RB5009 switch ACL ports=switch1-cpu not filtering
Replies: 13
Views: 3292

Re: RB5009 switch ACL ports=switch1-cpu not filtering

Fair enough, good thing my internet traffic is clean and doesn't need extra filtering ;-)
Hopefully someone else will pop-in.
by anav
Tue Jan 09, 2024 8:33 pm
Forum: Beginner Basics
Topic: EOIP over Wireguard (For RoMon purposes only) [SOLVED]
Replies: 33
Views: 4353

Re: EOIP over Wireguard (For RoMon purposes only) [SOLVED]

You need two reachable ip addresses on both devices. They need to see each other, as a matter of speaking. But you got it all backwards. You may want to start with describing user requirements, drawing of your network setup and export of all related devices :lol: Glad to see the brainwashing is wor...
by anav
Tue Jan 09, 2024 7:33 pm
Forum: Beginner Basics
Topic: EOIP over Wireguard (For RoMon purposes only) [SOLVED]
Replies: 33
Views: 4353

Re: EOIP over Wireguard (For RoMon purposes only) [SOLVED]

Sweet, I will be adding a remote RB4011 via WG to a ROMON list next week. For now, I want to try it locally. I have an RB450G attached to my main router but natted and it doesnt show up on my winbox list and I would like it to!!! No wg just Main ROUTER LAN to RB450G with local LAN address also the W...
by anav
Tue Jan 09, 2024 7:28 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 299
Views: 244028

Re: NEW FEATURE: Back to Home VPN

Now someone is finally providing useful information with which to discuss further. a. Why does the BTH config on the MT create a firewall rule blocking remote client to local LAN interface? b. Why does the BTH config on the MT create an input chain rule - because the router is still responsible for ...
by anav
Tue Jan 09, 2024 6:59 pm
Forum: General
Topic: dst-nat port forwarding not working
Replies: 8
Views: 1357

Re: dst-nat port forwarding not working

How are you having users connect to the device on vlan10? Direct LANIP address or some sort of DYNDNS name/url? Are users coming in Primary WAN1 or Secondary WAN2 ?? MANY MAJOR ISSUES: 1. Only two of the vlans have full networks, not sure what your expectations are for vlans 88 and 100 (where are th...
by anav
Tue Jan 09, 2024 6:21 pm
Forum: General
Topic: Wi‑Fi 7 / 802.11be
Replies: 36
Views: 12147

Re: Wi‑Fi 7 / 802.11be

Just put it down as a business loss, sending you postage to send to my location. :-) Its not something I would consider funny. https://forum.mikrotik.com/viewtopic.php?t=160561&start=300 I read the thread, couldnt find one single mention of supout report let alone the 100s I expected to see. Al...
by anav
Tue Jan 09, 2024 6:20 pm
Forum: General
Topic: CRS354-48P-4S+2Q+ traffic problem on ports 1 to 8
Replies: 429
Views: 124619

Re: CRS354-48P-4S+2Q+ traffic problem on ports 1 to 8

Hard to have sympathy reading this thread as Rextended alluded to ........ where are the 1000s supout reports..........???
by anav
Tue Jan 09, 2024 6:11 pm
Forum: Beginner Basics
Topic: Test VLAN isolation using InterVLAN Routing by Bridge
Replies: 2
Views: 1077

Re: Test VLAN isolation using InterVLAN Routing by Bridge

Firstly a better and original source for that documentation is found here..... https://forum.mikrotik.com/viewtopic.php?t=143620 Where you will find its best not to use vlan1 for data vlans. Also that when you change to using vlans on the bridge its wiser to go all vlans and have the bridge just do ...
by anav
Tue Jan 09, 2024 5:54 pm
Forum: Beginner Basics
Topic: RB5009 switch ACL ports=switch1-cpu not filtering
Replies: 13
Views: 3292

Re: RB5009 switch ACL ports=switch1-cpu not filtering

I dont follow.
So your configuration is based on fear and not facts??

What leakage are you talking about??
If I have a WAN or two, and a LAN with one flat subnet or multiple vlans in subnets.


YOU DECIDE in firewall rules (L3) where traffic is allowed to go.

?????????
by anav
Tue Jan 09, 2024 5:52 pm
Forum: General
Topic: Wi‑Fi 7 / 802.11be
Replies: 36
Views: 12147

Re: Wi‑Fi 7 / 802.11be

Just put it down as a business loss, sending you postage to send to my location. :-)
by anav
Tue Jan 09, 2024 5:47 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3492

Re: Wireguard Peers can't access IPs on VLANs

Good point, my bad, that rule got left out for some reason and I didnt notice. Its a standard default rule that should always be there, good pickup!
Added to the above to ensure accuracy.
by anav
Tue Jan 09, 2024 5:42 pm
Forum: General
Topic: Wireguard and WAN Interfaces
Replies: 3
Views: 1003

Re: Wireguard and WAN Interfaces

Sounds like an infestation of bloated firewall rules, which always cause unforeseen issues, especially by the copy whatever they see on youtube videos disease.
by anav
Tue Jan 09, 2024 3:12 pm
Forum: Beginner Basics
Topic: RB5009 switch ACL ports=switch1-cpu not filtering
Replies: 13
Views: 3292

Re: RB5009 switch ACL ports=switch1-cpu not filtering

Ahh okay, you are talking switches, I thought this was a Router discussion.
THus far you are talking gibberish, please give a practical example of what traffic you wish to flow through the ports or not flow through the ports.
by anav
Tue Jan 09, 2024 3:11 pm
Forum: General
Topic: MUM plans for 2023?
Replies: 52
Views: 9125

Re: MUM plans for 2023?

Oh you mean the version with WIFI7 and zerotrust cloudflare as an options package for all Devices.
by anav
Tue Jan 09, 2024 1:48 pm
Forum: Beginner Basics
Topic: EOIP over Wireguard (For RoMon purposes only) [SOLVED]
Replies: 33
Views: 4353

Re: EOIP over Wireguard (For RoMon purposes only) [SOLVED]

Yeah but ... if your IP setup is somehow bust, you're a dead fish too. No IP access anymore. Romon will still allow you to access those devices then via EOIP over wireguard (provided that channel is still operational). Zerotier will work as well for the same reason (L2 access). I have a different f...
by anav
Tue Jan 09, 2024 1:46 pm
Forum: General
Topic: Brute Force Attacks
Replies: 16
Views: 2422

Re: Brute Force Attacks

Its called blissful peace of mind. I dont log :-)
While your worrying, I am reading a great big book about how to help people with networking anxiety.
Apparently you can hit them over the head with a book, or tell them not to log.
by anav
Tue Jan 09, 2024 1:43 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 299
Views: 244028

Re: NEW FEATURE: Back to Home VPN

anav, before I answer. Have you used the BTH app and understand what it's purpose is? It enables Wireguard in router. That is all. No, I have not set it up yet because I dont understand how it works and likely not to unless I understand the role of the router is it a server for handshake - seems li...
by anav
Tue Jan 09, 2024 1:28 pm
Forum: Beginner Basics
Topic: RB5009 switch ACL ports=switch1-cpu not filtering
Replies: 13
Views: 3292

Re: RB5009 switch ACL ports=switch1-cpu not filtering

In view of learning something new, how does this relate to traffic from user to user, user to internet, internet to user, user to device, device to user.
What traffic are you
a. trying to allow?
b. afraid of that you need to block?
by anav
Tue Jan 09, 2024 1:25 pm
Forum: Beginner Basics
Topic: EOIP over Wireguard (For RoMon purposes only) [SOLVED]
Replies: 33
Views: 4353

Re: EOIP over Wireguard (For RoMon purposes only) [SOLVED]

Funny I log into all my routers via winbox over wireguard without ROMON.
I am not so lazy LOL. Just type in the IP address and winbox port at the top............. EOIP not required ;-PP
by anav
Tue Jan 09, 2024 1:18 pm
Forum: General
Topic: DUAL-WAN PPPOE CLIENT WITH PCC LOAD BALANCING FAILED TO WORK
Replies: 5
Views: 1410

Re: DUAL-WAN PPPOE CLIENT WITH PCC LOAD BALANCING FAILED TO WORK

Observations. 1. Remove IP DHCP client settings, your WAN connections are handled in the PPP menu. /ip dhcp-client add comment=defconf interface= *12 2. MAIN REASON is that you botched the mangles . YOur mangle rules are a large mess. I provided the short and sweet config needed........................
by anav
Tue Jan 09, 2024 1:05 pm
Forum: General
Topic: Wi‑Fi 7 / 802.11be
Replies: 36
Views: 12147

Re: Wi‑Fi 7 / 802.11be

Ahh so you are at work Normands, still waiting for the detailed response to this post ( you can use email if you prefer ) viewtopic.php?p=1046445#p1046445
by anav
Tue Jan 09, 2024 2:26 am
Forum: Beginner Basics
Topic: Connecting Switches to RouterBoard 3011
Replies: 2
Views: 2123

Re: Connecting Switches to RouterBoard 3011

So you are starting from scratch and want to be spoon fed without an ounce of effort, good luck with that.

Try here --> https://mikrotik.com/consultants
by anav
Tue Jan 09, 2024 2:23 am
Forum: Beginner Basics
Topic: New to Mkt, struggling with basic VLAN setup [SOLVED]
Replies: 15
Views: 3758

Re: New to Mkt, struggling with basic VLAN setup [SOLVED]

Correct, and thus the linked article was not followed, all good now I will bet.
by anav
Tue Jan 09, 2024 2:22 am
Forum: Beginner Basics
Topic: View full LTE WAN IP info
Replies: 2
Views: 904

Re: View full LTE WAN IP info

In IP DHCP client one clicks on the particular WAN connection and then looks at STATUS tab.
by anav
Mon Jan 08, 2024 11:10 pm
Forum: Beginner Basics
Topic: port forwarding
Replies: 61
Views: 4375

Re: port forwarding

You could reset to default or practice modifying the rules USING SAFE MODE. Not my partship to do....
by anav
Mon Jan 08, 2024 11:08 pm
Forum: Beginner Basics
Topic: New to Mkt, struggling with basic VLAN setup [SOLVED]
Replies: 15
Views: 3758

Re: New to Mkt, struggling with basic VLAN setup [SOLVED]

Correct, I prefer to manually insert the untagging as a visual crosscheck to make sure my bridge ports and bridge interfaces line up.
Also the untagging doesnt show up when exporting a config........
by anav
Mon Jan 08, 2024 8:56 pm
Forum: Beginner Basics
Topic: still same problem and same issue please help!
Replies: 8
Views: 2486

Re: still same problem and same issue please help!

My apologies, there was no indication that the router was behind another router......... Still a good practice to encrypt to the router and then visit the LAN or the config, especially if already using WG.
Good luck with L2TP issue, not an L2TP expert.
by anav
Mon Jan 08, 2024 8:53 pm
Forum: Beginner Basics
Topic: port forwarding
Replies: 61
Views: 4375

Re: port forwarding

Last post........ You didnt modify the firewall rules and your port forwarding destination nat rules are worse.
Good luck!
by anav
Mon Jan 08, 2024 8:51 pm
Forum: Beginner Basics
Topic: Wireguard Triangle
Replies: 7
Views: 2216

Re: Wireguard Triangle

Okay so your concern is what if the server Router is removed from the picture. The main reason why a tunnel would fail is if WAN connection was stopped or the router broke. a. If the traffic failed on Server Router1 for handshake (either router1 failure or internet failure at R1) routers 2,3 would n...
by anav
Mon Jan 08, 2024 6:45 pm
Forum: General
Topic: Access LAN through WG+L2TP tunnel
Replies: 6
Views: 1352

Re: Access LAN through WG+L2TP tunnel

1. You dont need to create two wireguard interfaces to isolate users. There are two easy options. a. Use firewall rules at R1, simply do not create an allow rule from one wg peer to the other wg peer..... b. Assign two different WG addresses on R1, one address schema for WG USER SN and another addre...
by anav
Mon Jan 08, 2024 6:44 pm
Forum: General
Topic: Access LAN through WG+L2TP tunnel
Replies: 6
Views: 1352

Re: Access LAN through WG+L2TP tunnel

Okay glad you got it sorted, will provide what I did next just for your viewing pleasure LOL.
by anav
Mon Jan 08, 2024 6:38 pm
Forum: Beginner Basics
Topic: New to Mkt, struggling with basic VLAN setup [SOLVED]
Replies: 15
Views: 3758

Re: New to Mkt, struggling with basic VLAN setup [SOLVED]

The doc shows it but your config still not correct. /interface bridge port add bridge=br-dcwifi ingress-filtering=yes frame-types=admit-priority-and-untagged interface=ether2 pvid=9 add bridge=br-dcwifi ingress-filtering=yes frame-types=admit-priority-and-untagged i interface=ether4 pvid=8 add bridg...
by anav
Mon Jan 08, 2024 6:35 pm
Forum: Beginner Basics
Topic: port forwarding
Replies: 61
Views: 4375

Re: port forwarding

Decent! Observations (1) One doesnt make port forwarding rules in the forward chain thus get rid of this .... The only thing that should be in the forward chain is one rule allowing dstnat. All port forwarding details are put in the dstnat chain rules. Also its in the wrong order if it was to be in ...
by anav
Mon Jan 08, 2024 4:37 pm
Forum: General
Topic: Access LAN through WG+L2TP tunnel
Replies: 6
Views: 1352

Re: Access LAN through WG+L2TP tunnel

I thought I had a solution but then ran up against the MAIN ISSUE. I see conflict in attempt to tell the R1 router how to route traffic headed towards theR2 subnet. a. L2TP for R1 subnet to R2 subnet b. Wireguard for remote users to same R2 subnet. Why not send R1 Subnet users ALSO over wireguard to...
by anav
Mon Jan 08, 2024 4:34 pm
Forum: General
Topic: DUAL-WAN PPPOE CLIENT WITH PCC LOAD BALANCING FAILED TO WORK
Replies: 5
Views: 1410

Re: DUAL-WAN PPPOE CLIENT WITH PCC LOAD BALANCING FAILED TO WORK

For mangle rules you dont need the first sets of rules................... Not explained properly by the video author, why he has the first set of rules which dont apply YET in your simple case. Start here for required rules........ You dont need both new and no-mark, no-mark is a better option norma...
by anav
Mon Jan 08, 2024 4:08 pm
Forum: General
Topic: DUAL-WAN PPPOE CLIENT WITH PCC LOAD BALANCING FAILED TO WORK
Replies: 5
Views: 1410

Re: DUAL-WAN PPPOE CLIENT WITH PCC LOAD BALANCING FAILED TO WORK

Sure, first I would update the firmware to the lastest stable update, 7.8 and earlier 7 versions had issues. Just to confirm you DON'T WANT primary/failover you want PCC/failover. The difference is that in primary/failover, only one ISP is providing connections. In PCC both ISPs are used at the same...
by anav
Mon Jan 08, 2024 4:00 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7053

Re: Wireguard guru needed [SOLVED]

Yes but your assuming AmmO can find the other thread. ;-)
by anav
Mon Jan 08, 2024 3:59 pm
Forum: Beginner Basics
Topic: EOIP over Wireguard (For RoMon purposes only) [SOLVED]
Replies: 33
Views: 4353

Re: EOIP over Wireguard (For RoMon purposes only) [SOLVED]

Dont look at me ;-). You need the expert and prompt advice of the perps Ammo and Holvoe to the rescue!!
by anav
Mon Jan 08, 2024 3:57 pm
Forum: Beginner Basics
Topic: still same problem and same issue please help!
Replies: 8
Views: 2486

Re: still same problem and same issue please help!

Edit: Please ensure you let folks know your router is behind another router, especially with unsafe configs as per below!! Even still I would only allow VPN to the router and then access config/subnets. /ip firewall filter add action=accept chain=input comment= "Router Access Remotely " ds...
by anav
Mon Jan 08, 2024 3:49 pm
Forum: Beginner Basics
Topic: New to Mkt, struggling with basic VLAN setup [SOLVED]
Replies: 15
Views: 3758

Re: New to Mkt, struggling with basic VLAN setup [SOLVED]

Read through this article and pay close attention to /interface bridge ports and /interface bridge vlans to find your error :-)
viewtopic.php?t=143620
by anav
Mon Jan 08, 2024 3:46 pm
Forum: Beginner Basics
Topic: port forwarding
Replies: 61
Views: 4375

Re: port forwarding

No point in showing you dont know how to config the router just yet. Please attempt the readings and then come back and post a complete config. Understanding is more important then copy and paste at this juncture /export file=anynameyouwish ( minus router serial number and any public WANIP informati...
by anav
Mon Jan 08, 2024 3:43 pm
Forum: Beginner Basics
Topic: Best way of 3 routers connection
Replies: 10
Views: 1730

Re: Best way of 3 routers connection

Sounds like a scenario for double nat. Modem, to MT Router, then to TPLINK router (for vpn mostly).
The hex need not route as my earlier post and can be connected to the AX as a switch.
by anav
Mon Jan 08, 2024 2:02 pm
Forum: Beginner Basics
Topic: New to Mkt, struggling with basic VLAN setup [SOLVED]
Replies: 15
Views: 3758

Re: New to Mkt, struggling with basic VLAN setup [SOLVED]

Ahh okay, I see you only have one subnet and are using a vlan for that. A bit unusual but perfectly fine.
My question is, where are your firewall rules?
Where is your internet connection??
by anav
Mon Jan 08, 2024 1:59 pm
Forum: Beginner Basics
Topic: port forwarding
Replies: 61
Views: 4375

Re: port forwarding

Have some reading to do!!

viewtopic.php?p=908118

viewtopic.php?t=191442

Only after you have gone over the above.....
viewtopic.php?t=179343
by anav
Mon Jan 08, 2024 5:44 am
Forum: Beginner Basics
Topic: LAN communication issue
Replies: 1
Views: 1057

Re: LAN communication issue

Any devices connected to your bridge ports should be able to see each other as you only have one flat network at L2. The firewall rules are for L3 traffic and they couldnt block same lan to same lan traffic anyway. Config looks okay on quick look. A. Either all are connected to PCs with strict firew...
by anav
Mon Jan 08, 2024 5:41 am
Forum: Beginner Basics
Topic: VLAN on the router switch port
Replies: 1
Views: 1020

Re: VLAN on the router switch port

One bridge, dont uses vlan1 (use any other for data), recommended NOT to use bridge for dhcp...........
viewtopic.php?t=143620
by anav
Sun Jan 07, 2024 11:07 pm
Forum: General
Topic: Setting VLAN ID on modem or on router
Replies: 7
Views: 1437

Re: Setting VLAN ID on modem or on router

If the modem passed the internet to you within a vlan then you need to set the vlan also on the router in most cases.
There is no harm to set the vlan in the router.

/interface vlan
add interface=etherY name=vlan-WAN vlan-id=XXXXX
/ip dhcp client
add interface=vlan-WAN
by anav
Sun Jan 07, 2024 8:12 pm
Forum: Beginner Basics
Topic: Best way of 3 routers connection
Replies: 10
Views: 1730

Re: Best way of 3 routers connection

I have no time for guesses, this is not a circus but you sir are a clown............. If you need to work on your imagination, go read a book. :-)
by anav
Sun Jan 07, 2024 6:52 pm
Forum: Beginner Basics
Topic: Best way of 3 routers connection
Replies: 10
Views: 1730

Re: Best way of 3 routers connection

Maybe?, dont you even know what you have???
In any case, no need for TPLINK router at all
by anav
Sun Jan 07, 2024 6:51 pm
Forum: General
Topic: Setting VLAN ID on modem or on router
Replies: 7
Views: 1437

Re: Setting VLAN ID on modem or on router

No need for vlan if the router gets a public IP and everything works in bridge mode.
If it does not then set vlan on modem and set vlan on router.
by anav
Sun Jan 07, 2024 5:56 pm
Forum: General
Topic: Under DNS Amplification attack, network unusable with Mikrotik routers
Replies: 12
Views: 2462

Re: Under DNS Amplification attack, network unusable with Mikrotik routers

BUT... I'd really recommend just start again with a new config... I personally think the default firewall is very well-calibrated (e.g. generally modifying the interface-list to add an WANs should be needed for 99% of CPE use cases). Disagree, not just a new config, NETINSTALL first , then new conf...
by anav
Sun Jan 07, 2024 5:54 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7053

Re: Wireguard guru needed [SOLVED]

I cant wait for holvoe to provide the necessary information!!!
by anav
Sun Jan 07, 2024 5:43 pm
Forum: Beginner Basics
Topic: Best way of 3 routers connection
Replies: 10
Views: 1730

Re: Best way of 3 routers connection

First, this is not a TPLINK forum and second, there is no such model TP link er650. There is however a wifi-extender (NOT A ROUTER) called the TP link RE650. This can be connected by ethernet to one of your routers to act as an access point. However its a dumb access point that cannot read vlans. At...
by anav
Sun Jan 07, 2024 5:26 pm
Forum: Beginner Basics
Topic: Wireguard setup with Router behind ISP Modem [SOLVED]
Replies: 4
Views: 1972

Re: Wireguard setup with Router behind ISP Modem [SOLVED]

Awesome, glad its working for you now.
by anav
Sun Jan 07, 2024 5:24 pm
Forum: General
Topic: MT to Pfsense Wireguard newbie needs help
Replies: 13
Views: 2408

Re: MT to Pfsense Wireguard newbie needs help

Nothing broken in Wireguard, simply MT has added in additional setting for BTH Wireguard and it can get a tad confusing is all.
by anav
Sun Jan 07, 2024 5:20 pm
Forum: General
Topic: Under DNS Amplification attack, network unusable with Mikrotik routers
Replies: 12
Views: 2462

Re: Under DNS Amplification attack, network unusable with Mikrotik routers

Lastly, and again sharing Anav's point of view leaving an open resolver is not best practice, and in all cases, not something any client should pay a consultant/service provider for. Find out who was responsible for those configs if provided by your company and if they are not gone, they should be ...
by anav
Sun Jan 07, 2024 5:17 pm
Forum: General
Topic: Under DNS Amplification attack, network unusable with Mikrotik routers
Replies: 12
Views: 2462

Re: Under DNS Amplification attack, network unusable with Mikrotik routers

A default config should not slow the performance. As intimated, its probably residual blocking going on from leaving DNS open...... Note here how DNS is allowed ONLY from the LAN, and in fact is the only thing LAN users should have access to on the router itself and perhaps NTP (for certain devices)...
by anav
Sun Jan 07, 2024 1:56 am
Forum: Beginner Basics
Topic: wireguard not open all websites
Replies: 1
Views: 1092

Re: wireguard not open all websites

That's nice. Now how do you expect us to help with practically no useful information.
What are you connecting to for example, third party VPN service???

Need config
/export file=anynameyouwish ( minus router serial number, public WANIP information, keys etc.)
by anav
Sun Jan 07, 2024 1:50 am
Forum: Beginner Basics
Topic: Wireguard setup with Router behind ISP Modem [SOLVED]
Replies: 4
Views: 1972

Re: Wireguard setup with Router behind ISP Modem [SOLVED]

Okay, your diagram ONLY shows you getting a private IP from the ISP modem/router. Is there another diagram showing you getting a public IP from the ISP modem if so show that instead with fake numbers for example on the diagram. THe LANs will stay the same behind the MT. OR, can you on the ISP modem/...
by anav
Sun Jan 07, 2024 1:35 am
Forum: General
Topic: Under DNS Amplification attack, network unusable with Mikrotik routers
Replies: 12
Views: 2462

Re: Under DNS Amplification attack, network unusable with Mikrotik routers

Sounds like YOU are the problem! :-) Lets look at the config. 1. Why do you slovenia telekom as your DNS server. If you want ISP provider DNS you can set that in the IP DCHP settings or pppoe settings for example (dial out). Most folks use something like 1.1.1.1 or 8.8.8.8 for external servers.........
by anav
Sun Jan 07, 2024 1:24 am
Forum: General
Topic: Recommended for IPS/IDS
Replies: 6
Views: 3293

Re: Recommended for IPS/IDS

Different vendor.............. You will pay through the nose for a higher end device that can still provide the throughput required with IDS services applied and by the way those IDS... DPI services are not native to the router, you then additionally have to buy subscription services to activate them.
by anav
Sun Jan 07, 2024 1:22 am
Forum: General
Topic: how to block bridged packet routed through firewall
Replies: 8
Views: 2013

Re: how to block bridged packet routed through firewall

Sorry your requirement makes no sense. Dont care about what you want to try on the config...... illogical What are the traffic requirements from the user perspective? What equipment do you have and what is the network design.....? ROUTER to MT acting as a switch?? OR ROUTER to MT acting as a ROUTER?...
by anav
Sun Jan 07, 2024 1:18 am
Forum: General
Topic: No traffic between VLANs regardless of firewall
Replies: 7
Views: 1380

Re: No traffic between VLANs regardless of firewall

Classic error of trying to keep the bridge doing DHCP. If you need another subnet take the one you kept on the bridge and make it vlan10.... or something.
Many other errors as well.
Suggest you read....
viewtopic.php?t=143620
by anav
Sat Jan 06, 2024 9:47 pm
Forum: General
Topic: Can't access device on management VLAN remotely via Wireguard
Replies: 12
Views: 3335

Re: Can't access device on management VLAN remotely via Wireguard

Trust me, when attemtping to diagnose errors on my own config and a million other peoples config, its much easier to spot firewall errors when chains are grouped together. Of course, it doenst matter which chain is in which order, but it does matter within a chain the order. Ordering the chains them...
by anav
Sat Jan 06, 2024 8:45 pm
Forum: Forwarding Protocols
Topic: OSPF across Wireguard using ptp, not nbma? [SOLVED]
Replies: 7
Views: 2552

Re: OSPF across Wireguard using ptp, not nbma? [SOLVED]

Wojo........... If you are familiar with OSPF Looking to do something for failovers. Imagine 2 WAN inputs to MT router............. and a CHR on a VPS in the cloud. What I want to do is connect the two WANS via wireguard and L2TP (plain -->best way to handle packet fragmentation), [from MT router to...
by anav
Sat Jan 06, 2024 2:50 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7053

Re: Wireguard guru needed [SOLVED]

Well I have mine listed but that is because they are on the same network and same subnet for IP address.
ROMON is s tool that allows that sort of thing I think
by anav
Sat Jan 06, 2024 2:47 pm
Forum: General
Topic: Port forward through P2P wireguard to internet
Replies: 5
Views: 1286

Re: Port forward through P2P wireguard to internet

Awesome, glad its worked out for you........ Ive done many dumb things when it comes to MT, and most due to my lack of understanding of basic networking.
by anav
Fri Jan 05, 2024 10:32 pm
Forum: General
Topic: wireguard client on LTE isp
Replies: 5
Views: 1265

Re: wireguard client on LTE isp

Then please post full config, there is something else on the config p erhaps.

/export file=anynameyouwish ( minus router serial number and any public WANIP information, keys etc.)
by anav
Fri Jan 05, 2024 10:27 pm
Forum: Beginner Basics
Topic: RouterOS v7.0.5 Dual PPPoE Wan Setup.
Replies: 34
Views: 16105

Re: RouterOS v7.0.5 Dual PPPoE Wan Setup.

Please post full config so I can see what is going on. please.
/export file=anynameyouwish ( minus router serial number and any public WANIP information )
by anav
Fri Jan 05, 2024 10:17 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7053

Re: Wireguard guru needed [SOLVED]

Wrong approach gig.......... You know better.
You dont plan and start the config without knowing all the requirments and attempt to totally change the requirements at the end.
Is all traffic working as expected.............
by anav
Fri Jan 05, 2024 10:15 pm
Forum: Beginner Basics
Topic: Routing a VLAN through Wireguard
Replies: 5
Views: 1710

Re: Routing a VLAN through Wireguard

Only a fool thinks firewall rules need not be considered in wireguard traffic. I wont even look at the config until its one bridge and all vlans (bridge does no dhcp).
viewtopic.php?t=143620
by anav
Fri Jan 05, 2024 10:14 pm
Forum: Beginner Basics
Topic: Home web address goes to router.
Replies: 2
Views: 1063

Re: Home web address goes to router.

It also sounds as you have not turned off all router services either......... post complete config
by anav
Fri Jan 05, 2024 10:05 pm
Forum: General
Topic: Port forward through P2P wireguard to internet
Replies: 5
Views: 1286

Re: Port forward through P2P wireguard to internet

Yes, I now can ignore everything in orange becauses its nonsensical. Between these two locations is Wireguard P2P tunnel it's on same ISP provider , so I use internal IP addresses and it not go through internet, only through ISP LAN network in same city ). Whether or not the two ISP connections are ...
by anav
Fri Jan 05, 2024 10:00 pm
Forum: General
Topic: Winbox management via Back to Home VPN
Replies: 2
Views: 1005

Re: Winbox management via Back to Home VPN

Very good question, I have been asking Normis for clarification on the BTH thread in Announcement to get at the heart of these matters.
Thus far, disappointing answers.
by anav
Fri Jan 05, 2024 9:59 pm
Forum: General
Topic: wireguard client on LTE isp
Replies: 5
Views: 1265

Re: wireguard client on LTE isp

I think the issue is the smartphone blocking, as none of the changes above would necessarily block anything.
by anav
Fri Jan 05, 2024 9:52 pm
Forum: General
Topic: wireguard client on LTE isp
Replies: 5
Views: 1265

Re: wireguard client on LTE isp

Really well done for the most part....... dst address needs to be gone, and needs to be enabled! Modify this /routing rule add action=lookup-only-in-table comment="MY SMARTPHONE TO WG VM16 DOCKER" disabled=yes dst-address=0.0.0.0/0 \ src-address=10.2.1.197/32 table=_wg_vm16_docker TO /rout...
by anav
Fri Jan 05, 2024 9:48 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3492

Re: Wireguard Peers can't access IPs on VLANs

NOT correct, for example this are bogus nonsensical entries for bridge ports. add bridge=onebr interface=vlan200 add bridge=onebr interface=vlan800 add bridge=onebr interface=vlan900 Vlan200 is NOT a LAN member has nothing to do with local hex.......... Similarly client-list is not a WAN, its was a ...
by anav
Fri Jan 05, 2024 5:56 pm
Forum: General
Topic: Simple Web Server to Host Simple Files [SOLVED]
Replies: 15
Views: 4695

Re: Simple Web Server to Host Simple Files [SOLVED]

What I would do is create a Wireguard tunnel between the VPS and the mikrotik router. The server and files would be hosted on the Mikrotik Router. On the CHR I would port forward inquiries coming in externally from USers or in this case just the admin, to the VPS public IP or domain name/url etc.......
by anav
Fri Jan 05, 2024 5:19 pm
Forum: General
Topic: Port forward through P2P wireguard to internet
Replies: 5
Views: 1286

Re: Port forward through P2P wireguard to internet

I am sorry, do not understand the architecture?
I have two connections locally to the same ISP, but each connection gets a different public WANIIP from the provider. Two different accounts.
I connect them via Wireguard as well.
What you describe does not computer for me, so unable to help.
by anav
Fri Jan 05, 2024 5:16 pm
Forum: General
Topic: Simple hairpin not working
Replies: 17
Views: 1767

Re: Simple hairpin not working

Well stated vinfgjfg!! ( all that info was on the link provided, not sure how mangling got into the mix either ) The only issue is your last sentence has a typo...... Lastly, You may opt to isolate the router on its own subnet. In that case, only the dstnat is needed as you are no longer doing a hai...
by anav
Fri Jan 05, 2024 5:11 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 299
Views: 244028

Re: NEW FEATURE: Back to Home VPN

> Next post intimates that it doesnt work with different Winbox Ports?? only the BTH app (!) needs the default port. To set it up. We might fix that, but then again, if you have custom ports and whatnot, might as well just use winbox > how to setup the Mikrotik manually, when using your relay point...
by anav
Fri Jan 05, 2024 12:31 am
Forum: Beginner Basics
Topic: Port forwarding through Proton VPN?
Replies: 10
Views: 2143

Re: Port forwarding through Proton VPN?

Wish I had more info for you on BTH, but normands was on vacation today and didnt answer my BTH questions LOL.
by anav
Thu Jan 04, 2024 11:25 pm
Forum: Beginner Basics
Topic: RouterOS v7.0.5 Dual PPPoE Wan Setup.
Replies: 34
Views: 16105

Re: RouterOS v7.0.5 Dual PPPoE Wan Setup.

Yup, they were not required if doing recursive on the main routing table.
As stated full config, no more part configs..........
by anav
Thu Jan 04, 2024 6:14 pm
Forum: Beginner Basics
Topic: Problem NAT Server, Client's Public IP Not Show in log [SOLVED]
Replies: 4
Views: 1701

Re: Problem NAT Server, Client's Public IP Not Show in log [SOLVED]

Yeah, if you have a fixed/static WANIP, then you need to delete that first rule, its getting in the way. The fourth rule below is just a duplicate of the second rule, and should be removed as well. You should only need two rules. Question: Is there a reason on the SOURCENAT RULE, why you feel the ne...
by anav
Thu Jan 04, 2024 5:52 pm
Forum: Beginner Basics
Topic: RB5009 right choice? [SOLVED]
Replies: 1
Views: 1641

Re: RB5009 right choice? [SOLVED]

My opinion is yes, you should be able to maximize your 2.5 gig throughput as its rated to approx 3gig with 25 IP filter rules.
It is a new ARM64 product so the support should be good for many years.
by anav
Thu Jan 04, 2024 5:22 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 299
Views: 244028

Re: NEW FEATURE: Back to Home VPN

Yes, Normands, most interested in the manual setup. My question is regarding how to setup the Mikrotik manually, when using your, for want of better word, cloud touch relay point. Its not a full blown WG server, but a connection point that allows users to reach the MT regardless (no public IP and IS...
by anav
Thu Jan 04, 2024 5:13 pm
Forum: Beginner Basics
Topic: Port forwarding through Proton VPN?
Replies: 10
Views: 2143

Re: Port forwarding through Proton VPN?

You keep changing the story. Yes, it is common to use wireguard, as a safe method, for external originated traffic to reach a server or to config the router. PROTON VPN is not for this, its for traffic originated on the router heading outbound . Two different cases. You don't seem to grasp that exte...
by anav
Thu Jan 04, 2024 5:01 pm
Forum: Beginner Basics
Topic: Added Mikrotik to existing network. How to segregate/isolate?
Replies: 6
Views: 1804

Re: Added Mikrotik to existing network. How to segregate/isolate?

Just to be clear, the upstream router belongs to house owners and the hex belongs to you a tenant, and they dont have any wifi but would like to use your wifi?? Now yes you can setup your hex router as a router (double nat) and thus have your own subnets/vlans You can provide guest vlans that they c...
by anav
Thu Jan 04, 2024 4:23 pm
Forum: Virtualization
Topic: CHR image for ARM systems?
Replies: 16
Views: 6230

Re: CHR image for ARM systems?

What the hex is Ampere..... MT sold with a tazer ??

Assuming its like a new Cloud virtual computer or something not linux, not windows but something else VPS???
https://amperecomputing.com/

Is it software is it hardware.... seems rather vague to me.
by anav
Thu Jan 04, 2024 4:18 pm
Forum: Beginner Basics
Topic: Ping from wan
Replies: 4
Views: 1243

Re: Ping from wan

Yes ISPs can be ornery too, we have a bell fibre ISP that blocks ICMP ping as a normal function of their provided modem/routers and it cannot be changed by the home owner.
by anav
Thu Jan 04, 2024 4:15 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3492

Re: Wireguard Peers can't access IPs on VLANs

Just because things work for a limited test set, doesn't necessarily mean the config is correct LOL. MT can be misleading in that regard. The errors will bite you sooner or later. :-)
When you think you have a near finished final product post again.......
by anav
Thu Jan 04, 2024 1:28 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3492

Re: Wireguard Peers can't access IPs on VLANs

Not sure why you are continuing with off bridge setup?
You dont have enough ports ( with 5 on hex ), you need 1 for client on Main WIFI router subnet, 2 for 1790, 3,4 for switches and 5 from wifi router???

In terms of vlans, read this.
viewtopic.php?t=143620
by anav
Thu Jan 04, 2024 1:18 pm
Forum: Beginner Basics
Topic: RouterOS v7.0.5 Dual PPPoE Wan Setup.
Replies: 34
Views: 16105

Re: RouterOS v7.0.5 Dual PPPoE Wan Setup.

If its not working then I need to see full config as answering any more questions requires complete understanding.
/export file=anynameyouwish (minus router serial number, public wanip information, keys etc..)
by anav
Thu Jan 04, 2024 1:08 pm
Forum: General
Topic: Simple hairpin not working
Replies: 17
Views: 1767

Re: Simple hairpin not working

Rule in forward chain needs to be add chain=forward action=accept connection-nat-state=dstnat The old default rule can be deleted but you need to add two more rules. THis one above it....... add chain=forward action=accept in-interface-list=LAN out-interface-list=WAN comment="internet traffic&q...
by anav
Thu Jan 04, 2024 6:02 am
Forum: Beginner Basics
Topic: Added Mikrotik to existing network. How to segregate/isolate?
Replies: 6
Views: 1804

Re: Added Mikrotik to existing network. How to segregate/isolate?

Nobody likes chasing a moving story.
Right down all the requirements.

a. identify all the user(s)/device(s) and groups of users/devices
b. identify all the traffic flow they need.

Also, do you control the upstream router or does the ISP.aka and ISP modem router.
by anav
Thu Jan 04, 2024 4:35 am
Forum: General
Topic: 7.13 legacy devices - plans?
Replies: 9
Views: 1842

Re: 7.13 legacy devices - plans?

In Brazil you have a different plan LOL.
You have to plan for theft replacement. If it aint locked down and you are not paying the police, it gets disappeared.

But yes, typically at home, use it till its not fixable or no longer does the job required.
by anav
Thu Jan 04, 2024 3:24 am
Forum: General
Topic: Simple hairpin not working
Replies: 17
Views: 1767

Re: Simple hairpin not working

Its impossible to block or control DNS from an encrypted methodology to my knowledge.
In other words there are limits to what one can do with adguard/piehole/doh etc..... if the user is savvy enough.
by anav
Thu Jan 04, 2024 3:22 am
Forum: Beginner Basics
Topic: Separating networks
Replies: 3
Views: 1130

Re: Separating networks

So just internet COAX cable to ISP modem router and you get private IP from ISP modem router LAN.

Just plug one cable into your MIKROTIK ROUTER and then all users plugged into mikrotik router.
One bridge, create as many different vlans as you need to separate users, servers, iot equipment etc.
by anav
Thu Jan 04, 2024 3:20 am
Forum: Beginner Basics
Topic: Port forwarding issue [SOLVED]
Replies: 5
Views: 1676

Re: Port forwarding issue [SOLVED]

One bridge.
How every many vlans you need to have separate subnets.
One vlan for Servers, one vlan for trusted LAN users, one vlan for guests, one vlan for iot equipment etc...
by anav
Thu Jan 04, 2024 2:01 am
Forum: Beginner Basics
Topic: RouterOS v7.0.5 Dual PPPoE Wan Setup.
Replies: 34
Views: 16105

Re: RouterOS v7.0.5 Dual PPPoE Wan Setup.

Okay so you have a port forwarding requirement but no external traffic TO THE ROUTER ( aka no vpn services etc. no wireguard ). In which case you dont need the output chain set of rules But YOU ARE MISSING THE MARK ROUTES FOR THE RETURN due to PORT FOWARDING via PREROUTING!!!! A small note if you di...
by anav
Wed Jan 03, 2024 11:43 pm
Forum: Beginner Basics
Topic: Purchase recommendation
Replies: 13
Views: 1852

Re: Purchase recommendation

Concur, also because ARM products are more fully supported going forward.
by anav
Wed Jan 03, 2024 11:42 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7053

Re: Wireguard guru needed [SOLVED]

(7) NO. The purpose of the rule is to allow subnets from r1 coming in on wireguard ( in this case one subnet) to access r2 single subnet and of course the remote admin users. If you had multple subnets on r2, its doubtful that the local subnets/vlans would require access to each other at all, hence ...
by anav
Wed Jan 03, 2024 11:25 pm
Forum: Beginner Basics
Topic: Purchase recommendation
Replies: 13
Views: 1852

Re: Purchase recommendation

Hi Mozerd, how do you distinguish on a single computer, a different queue for gaming, and for NAS server access (file access), torrenting, streaming etc...............

Can you provide that fidelity or is it all, ONE IP, one queue applies ??
by anav
Wed Jan 03, 2024 11:23 pm
Forum: Beginner Basics
Topic: Beginning RouterOS 7 config- need help with enabling vlan filtering
Replies: 7
Views: 1524

Re: Beginning RouterOS 7 config- need help with enabling vlan filtering

To be clear, you have to communicate more accurately.
What device do you have,
Provide a network diagram.

It may very well be that you are talking about a switch not a router and I was giving advice thinking it was a router etc...........
by anav
Wed Jan 03, 2024 11:21 pm
Forum: General
Topic: 7.13 legacy devices - plans?
Replies: 9
Views: 1842

Re: 7.13 legacy devices - plans?

Don't you have this built into your obsolensce budget planning for 1,2,5,10,15 years down the line ;-) EVERY X years change TV (10) EVERY Y years change CAR (12 ish) EVERY Z years change IPHONE. (3 ish) EVERY A years change WIFI devices ( often coincides with IPHONE ) (3-5ish) EVERY B years change r...
by anav
Wed Jan 03, 2024 11:10 pm
Forum: General
Topic: Static route toward a list of networks [SOLVED]
Replies: 4
Views: 1746

Re: Static route toward a list of networks [SOLVED]

Hi there, The table is required because that is what we are creating, an independent new routing table, so that we can tell the router where to send traffic, separately from the Main Table. Mangling is a method of identifying traffic with some specificity, in order to apply routes as required. I hav...
by anav
Wed Jan 03, 2024 10:39 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3492

Re: Wireguard Peers can't access IPs on VLANs

Assuming I had it wrong all along and you need to pass the MAIN WIFI subnet to other devices behind the managed switches. I have modified the CHR script below. I also noted my handling of 1790 was not quite right, it needs to be defined as an interface, but no other place.... I also do not see the r...
by anav
Wed Jan 03, 2024 8:54 pm
Forum: General
Topic: Static route toward a list of networks [SOLVED]
Replies: 4
Views: 1746

Re: Static route toward a list of networks [SOLVED]

Correct. Each remote subnet must be a separate entry. The purpose is so that if local lan users need to reach remote subnets, the router knows where to send the local users!! The purpose is also so that remote users coming in to access local servers or use the local WAN, have their return traffic go...
by anav
Wed Jan 03, 2024 6:18 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3492

Re: Wireguard Peers can't access IPs on VLANs

To be clear are you trying the SAME configuration on both devices for testing purposes?? Yes, you may have errors if you relied on scripts as the config has changed significantly so the rest of the config will have to be modified as required. (1) Why do you still have the incorrect setting for wireg...
by anav
Wed Jan 03, 2024 4:20 pm
Forum: Beginner Basics
Topic: Purchase recommendation
Replies: 13
Views: 1852

Re: Purchase recommendation

MIKROTIK is not the answer either, that is if you are intent on content based control. MT does not have APPLICATION CONTROLS or deep packet inspection so it may not work for you. MT is a user based and by that I mean IP: based firewall router. So put users into vlans and subnets and then you can con...
by anav
Wed Jan 03, 2024 4:14 pm
Forum: Beginner Basics
Topic: RouterOS v7.0.5 Dual PPPoE Wan Setup.
Replies: 34
Views: 16105

Re: RouterOS v7.0.5 Dual PPPoE Wan Setup.

Post your config and I will have a look. Also an update to what I posted I was not entirely accurate. 1. The output chain rules ensure that external traffic TO THE ROUTER ( aka services like wireguard handshake ) that comes in WANX goes out WANX 2. One still needs prerouting chain rules to ensure th...
by anav
Wed Jan 03, 2024 2:41 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7053

Re: Wireguard guru needed [SOLVED]

R1 (1) Why did you use firewall address list=VPN, its not correct technically as you have one local address on the list which has nothing to do with wireguard, 192.168.100.92 The list is more accurately called Admin or Authorized. Confusing to call it VPN when its not. Yes it includes two wireguard...
by anav
Wed Jan 03, 2024 1:56 pm
Forum: Beginner Basics
Topic: Beginning RouterOS 7 config- need help with enabling vlan filtering
Replies: 7
Views: 1524

Re: Beginning RouterOS 7 config- need help with enabling vlan filtering

You can use code commands to encapsulate your config! ( black square with white square brackets on the same line as Bold Underline etc.......) Typically when first setting up bridge vlan filtering and later on if I screw something up on the bridge, I setup an off bridge access. Makes life much easie...
by anav
Wed Jan 03, 2024 1:53 pm
Forum: Beginner Basics
Topic: Separating networks
Replies: 3
Views: 1130

Re: Separating networks

ISP Device: Is it a modem/router or just router? Does it provide TV or telephone services or just internet?
by anav
Wed Jan 03, 2024 1:45 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3492

Re: Wireguard Peers can't access IPs on VLANs

I provided a much simpler, cleaner config, so cannot comment further.
by anav
Wed Jan 03, 2024 4:37 am
Forum: General
Topic: Force Users to Use Specific DNS Server
Replies: 31
Views: 21518

Re: Force Users to Use Specific DNS Server

Ah okay, I think of that as NAT RULE, as opposed to a MANGLE rule as opposed to filter rules (forward and input chain).
All other IP firewall. LOL.
by anav
Wed Jan 03, 2024 2:15 am
Forum: Beginner Basics
Topic: Port forwarding issue [SOLVED]
Replies: 5
Views: 1676

Re: Port forwarding issue [SOLVED]

As the article states. If you have USERS within the same SUBNET as the SERVER, and the users are not accessing the server by the server LAN IP address directly, but by the roundabout method of using the Domain Name/url/dyndns type name. then yes you need the hairpin nat rule. If you move the users o...
by anav
Wed Jan 03, 2024 2:14 am
Forum: General
Topic: Force Users to Use Specific DNS Server
Replies: 31
Views: 21518

Re: Force Users to Use Specific DNS Server

It is not clear what firewall rule you are talking about??
by anav
Tue Jan 02, 2024 11:04 pm
Forum: General
Topic: Force Users to Use Specific DNS Server
Replies: 31
Views: 21518

Re: Force Users to Use Specific DNS Server

Well will focus on DNS related rules........ In general the Device acting as DNS server has to have access to the internet to get DNS itself. EVEn a DOH servers needs some unencrypted DNS access to make the initial connection to an encrypted DOH server. So in general, one has to look at DNS servers ...
by anav
Tue Jan 02, 2024 10:51 pm
Forum: Beginner Basics
Topic: Port forwarding issue [SOLVED]
Replies: 5
Views: 1676

Re: Port forwarding issue [SOLVED]

by anav
Tue Jan 02, 2024 10:48 pm
Forum: Beginner Basics
Topic: CAPsMAN VLAN guest network - No connection
Replies: 4
Views: 1316

Re: CAPsMAN VLAN guest network - No connection

Well the only changes I see are in the forward chain are two rules. Difference in Green! FROM add action=accept chain=forward comment="allow internet traffic" \ in-interface-list=LAN out-interface-list=WAN add action=accept chain=forward comment="allow Smart Home access" \ dst-ad...
by anav
Tue Jan 02, 2024 10:33 pm
Forum: General
Topic: Simple WIreguard setup hints
Replies: 1
Views: 909

Re: Simple WIreguard setup hints

Three things. a. good to include diagram very helpful as we are not in your head. b. form follows function so a clear set of requirements will dictated a useful config. So need the following (i). identify users/groups of users including you as the admin (ii). identify the traffic they need to accomp...
by anav
Tue Jan 02, 2024 9:38 pm
Forum: General
Topic: DNS not resolving some domains
Replies: 23
Views: 2930

Re: DNS not resolving some domains

Hard to say as the OP thinks he knows better by not providing the evidence and information to make an accurate diagnosis.
by anav
Tue Jan 02, 2024 9:35 pm
Forum: General
Topic: Force Users to Use Specific DNS Server
Replies: 31
Views: 21518

Re: Force Users to Use Specific DNS Server

Caution that I have seen RECENTLY folks using these rules and not putting a SOURCE part of the rule. (in interface lan) IF you dont then anyone on the internet will start using your pi server!! I note the original link at the top of the thread showed this dangerous config and its from an old no long...
by anav
Tue Jan 02, 2024 9:30 pm
Forum: General
Topic: Force Users to Use Specific DNS Server
Replies: 31
Views: 21518

Re: Force Users to Use Specific DNS Server

Negative, to ports is implied to be the same as dstports if not entered. To-Ports is this really used when doing port translation. What is important is such sweeping rules in-interface-list=LAN is to ensure you exclude the pI LAN address or any other subnets not being subjegated to PI. /ip nat add a...
by anav
Tue Jan 02, 2024 9:26 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3492

Re: Wireguard Peers can't access IPs on VLANs

Which configuration, the OPs? If you look at the suggested config, all traffic from 800 and 900 vlans AND WIREGUARD, go through the WAN side of the router aka via ether5 and since there is a masquerade rule. all such traffic is already natted and gets a source IP of 192.168.2.2. That problem no long...
by anav
Tue Jan 02, 2024 9:20 pm
Forum: Beginner Basics
Topic: Port forwarding through Proton VPN?
Replies: 10
Views: 2143

Re: Port forwarding through Proton VPN?

YES it can, just not through PROTON. You could host a CHR on VPS for example ( cloud server ) or linux OS etc............. (1) All users would go directly to the public IP of the CHR vice your public IP to connect to a server. (2) The CHR would then port forward that traffic INTO a wireguard TUNNEL ...
by anav
Tue Jan 02, 2024 9:13 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7053

Re: Wireguard guru needed [SOLVED]

In R1 the config is clear. We only allow select users on wireguard to access the LAN side. We allow remote users to come in on wireguard to go back out wireguard ( does not allow anything else ). Thus we ensure control of what occurs by making clear rules. add action=accept chain=forward in-interfac...
by anav
Tue Jan 02, 2024 9:07 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7053

Re: Wireguard guru needed [SOLVED]

The painting company should be charged for $gas money and time for your to fix the situation at a minimum. The company will only make changes if it causes them to lose some of their profit.............. Sadly, pride and ethical behaviour not so much. The relay rule should be clearly stated.............
by anav
Tue Jan 02, 2024 8:42 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3492

Re: Wireguard Peers can't access IPs on VLANs

Suggest your review line by line to digest all changes. No mangling required, no vlan for WAN needed. Tried to keep it clean and simple. Access to the router is safely done via Ether1 using 192.168.55.5 set in laptop ipv4 settings etc..... Setup so that you can access the router when sitting on the ...
by anav
Tue Jan 02, 2024 7:25 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3492

Re: Wireguard Peers can't access IPs on VLANs

Okay so to recap and make sure on same page. 1. VDSL Modem/Wifi Router is where internet terminates. The modem gets the public IP. It provides a flat network of 192.168.2.0/24 where the modem router is the gateway 192.168.2.1 2. HEX is a second router with NAT, its WANIP for all intensive purposes i...
by anav
Tue Jan 02, 2024 3:47 pm
Forum: Beginner Basics
Topic: Loadbalancing issues
Replies: 3
Views: 1065

Re: Loadbalancing issues

You cannot do that with the MT router it does not bond two connections such that one session can use both connections at the same time.
There may be some software you put on a PC or something that does that for torrenting, but there is no such config on the router itself.
by anav
Tue Jan 02, 2024 3:11 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7053

Re: Wireguard guru needed [SOLVED]

Well there is physical security and access on-site, and there is stupidity. a. for disconnecting a piece of equipment and then on top not plugging it back in. Be it dishonest or stupid, the employee has to go. I note the evil attempt by the OP to confuse me by putting R2 prior to R1.............. ;-...
by anav
Tue Jan 02, 2024 3:03 pm
Forum: Beginner Basics
Topic: Port forwarding through Proton VPN?
Replies: 10
Views: 2143

Re: Port forwarding through Proton VPN?

Just so I understand you have a hapax3 that gets a public IP......... If so you dont need Proton VPN for incoming, you can use your own router with wireguard to let remote users access home assistant. Even if its not a public IP ( behind an ISP router ) if you can forward a port on the ISP modem/rou...
by anav
Tue Jan 02, 2024 1:21 am
Forum: General
Topic: DNS not resolving some domains
Replies: 23
Views: 2930

Re: DNS not resolving some domains

Observations (1) The vlan7 you assigned to combo1 is all very nice but where is it in your pppoe connection?? /interface pppoe-client add add-default-route=yes disabled=no interface=combo1 max-mru=1400 max-mtu=1480 name=Telekom-DSL profile=telekom user= If indeed the ISP is providing pppoe over vlan...
by anav
Tue Jan 02, 2024 1:04 am
Forum: Beginner Basics
Topic: Set VLAN in eth ports
Replies: 4
Views: 1040

Re: Set VLAN in eth ports

(1) You have two rules and the second one is redundant on input chain. add action=accept chain=input comment="Allow VLAN" in-interface-list=VLAN { allows all VLANS full access to the ROUTER } add action=accept chain=input comment="Allow main VLAN Full Access" \ { allows main VLAN...
by anav
Tue Jan 02, 2024 12:47 am
Forum: Beginner Basics
Topic: CAP AC: Stripping MAC Addresses impacting DHCP
Replies: 12
Views: 2147

Re: CAP AC: DHCP assigned DNS

Do not understand about DHCP requests........... The Cap is not acting as a router solely as an AP switch and has no Firewall rules, no DHCP functionality...... or anything...... Since you use pi for DNS, assuming that you direct your users to PI already so why did you deviate on the setup provided?...
by anav
Tue Jan 02, 2024 12:32 am
Forum: Beginner Basics
Topic: openvpn connection [SOLVED]
Replies: 5
Views: 1184

Re: openvpn connection [SOLVED]

The only thing I can recommend is a newer model ( AKA newer ARM product )
hapax3, first choice hapax2 second choice, and then you can RUN wireguard via BTH and will be able to remotely connect to your network from anywhere.
by anav
Tue Jan 02, 2024 12:31 am
Forum: Beginner Basics
Topic: DHCP server not working on every device + port forwarding
Replies: 4
Views: 1066

Re: DHCP server not working on every device + port forwarding

PLEASE CONFIRM ASAP that you get a private IP address from the ISPs device. If you get a public IP then you need to unplug your router immediately and perhaps netinstall it because you HAVE NO protection because you have NO firewall rules at all. All traffic is permitted. Which means hackers have f...
by anav
Tue Jan 02, 2024 12:17 am
Forum: General
Topic: DNS not resolving some domains
Replies: 23
Views: 2930

Re: DNS not resolving some domains

If your MT device is setup properly, why are you here? Try a debian forum! If you want help then provide the config and we can decide, based on EVIDENCE not opinion, that there is nothing amiss on your config. /export file=anynameyouwish ( minus router serial number, public WANIP information, keys, ...
by anav
Mon Jan 01, 2024 11:11 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2233

Re: Inter-VLAN routing (unable to reach clients from VLAN)

Blocking ping on wan side seems pointless............ its actually useful and not a security risk.
by anav
Mon Jan 01, 2024 10:54 pm
Forum: Beginner Basics
Topic: HW-accelerated routing & firewall
Replies: 2
Views: 890

Re: HW-accelerated routing & firewall

I think your mixing up form and function. The MT Device is a switch and you clearly stated you have an upstream firewall that takes care of firewall rules etc. so not sure what the issue is?? Its a switch so Wire Speed should be a given. Security wise are you asking what additional security function...
by anav
Mon Jan 01, 2024 10:52 pm
Forum: General
Topic: route marking with two ISPs and PCC with wireguard
Replies: 6
Views: 1541

Re: route marking with two ISPs and PCC with wireguard

(1) The advice is to have a separate VLAN for users and a separate VLAN for managment if you need it. The concept of a management vlan is mostly so that all smart devices on the network are configured and reachable on this network that nobody else has access too. If you have a trusted subnet then yo...
by anav
Mon Jan 01, 2024 9:41 pm
Forum: Beginner Basics
Topic: openvpn connection [SOLVED]
Replies: 5
Views: 1184

Re: openvpn connection [SOLVED]

Mikrotik model?
by anav
Mon Jan 01, 2024 9:09 pm
Forum: Beginner Basics
Topic: openvpn connection [SOLVED]
Replies: 5
Views: 1184

Re: openvpn connection [SOLVED]

It would appear you dont have a public IP directly its handled by the modem/router and not passed to your router.
Can you access the ISP modem/router and forward ports to the MT router?
Which MT device do you have?
by anav
Mon Jan 01, 2024 8:51 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 299
Views: 244028

Re: NEW FEATURE: Back to Home VPN

when?? using back to home wireguard, regular wireguard, something else......... again no context, we are not inside your head nor have any inkling of what network we are looking at etc...
by anav
Mon Jan 01, 2024 8:35 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2233

Re: Inter-VLAN routing (unable to reach clients from VLAN)

SURE YOU DID YOU ADDED THIS RULE AND ITS STILL THERE> add action=drop chain=forward comment="drop Everything else in VLAN" \ in-interface-list=VLAN /ip firewall filter add action=accept chain=input comment=\ "defconf: accept established,related,untracked" connection-state=\ estab...
by anav
Mon Jan 01, 2024 8:32 pm
Forum: General
Topic: Model to use for site to site vpn ddns
Replies: 3
Views: 1640

Re: Model to use for site to site vpn ddns

@OP When you say static IP in the US, do you mean you get a public fixed IP, or fixed private IP ( like 192.168.1.X ) @Hey noob, what drugs are you on? The Hex is old and very under powered for the typical connections in US. Dont know about Mexico. The hex can be expected to get around 400-500Mbps o...
by anav
Mon Jan 01, 2024 8:09 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2233

Re: Inter-VLAN routing (unable to reach clients from VLAN)

(you dont need the vlan restricted list anymore by the way) The interface list VLAN-InternetAccess should not have quotes in your rule, remove them!! ( otherwise the rule is good ) add action=accept chain=forward comment="allow Internet access" \ connection-type="" in-interface-l...
by anav
Mon Jan 01, 2024 7:33 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2233

Re: Inter-VLAN routing (unable to reach clients from VLAN)

Seems okay, you keep screwing up the order of rules though..... (1) /ip firewall filter add action=accept chain=input comment=\ "defconf: accept established,related,untracked" connection-state=\ established,related,untracked ----> move up, and put the invalid rule, the icmp rule and the lo...
by anav
Mon Jan 01, 2024 7:18 pm
Forum: Beginner Basics
Topic: Port forwarding through Proton VPN?
Replies: 10
Views: 2143

Re: Port forwarding through Proton VPN?

NAT PMP, is nothing to do with MT. So lets get the facts. You have a third party VPN connecting your router (as a client ) to the PROTON wireguard server. Typically this is NOT for incoming originated requests, this is designed for sending some subnets or all subnets out the proton site for internet...
by anav
Mon Jan 01, 2024 6:59 pm
Forum: Beginner Basics
Topic: Force the router to use a specific WAN
Replies: 5
Views: 1092

Re: Force the router to use a specific WAN

Yes but that has nothing to do with mangling or whatever. Connect ISP1s modem or modem router to ether1 for example. Then if its pppoe connection assign the parameters in the PPP menu. IF its a ISP assigned dhcp scenario, add the parameters in IP DHCP. IF its a Static Public IP assigned, you can do ...
by anav
Mon Jan 01, 2024 6:53 pm
Forum: Beginner Basics
Topic: CAPsMAN VLAN guest network - No connection
Replies: 4
Views: 1316

Re: CAPsMAN VLAN guest network - No connection

Well I am not sure you handled vlans correctly, and in fact, once you start using vlans I recommend you turn the bridge affiliated subnet INTO a vlan and then your errors with the other vlans will become clearer. My sense is that is the root of your problems not the firewall. Suggest you read this t...
by anav
Mon Jan 01, 2024 6:34 pm
Forum: Beginner Basics
Topic: Set VLAN in eth ports
Replies: 4
Views: 1040

Re: Set VLAN in eth ports

(1) This open ended nonsense sourcenat rule is from the default rules........ ?? /ip firewall nat add action=masquerade chain=srcnat add action=masquerade chain=srcnat comment="defconf: masquerade" \ ipsec-policy=out,none out-interface-list=WAN (2) No idea what you are doing with these see...
by anav
Mon Jan 01, 2024 6:29 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 299
Views: 244028

Re: NEW FEATURE: Back to Home VPN

Is it possible to connect multiple Wireguard peers with Mikrotik at the same time? And use it for VPN service in an Organization instead of L2TP or SSTP? Have you used wireguard? Its not an enterprise solution where 1000s of employees need to VPN into work............ However yes, one can have many...
by anav
Mon Jan 01, 2024 6:21 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 299
Views: 244028

Re: NEW FEATURE: Back to Home VPN

Did somebody else noticed ping increase and drop in speed ?
Your post has no context. Do you mean if you are drinking a cup of coffee while running on the treadmill??
by anav
Mon Jan 01, 2024 6:15 pm
Forum: Beginner Basics
Topic: New user in new property existing equipment
Replies: 4
Views: 1076

Re: New user in new property existing equipment

I am not familiar with LTE products, dont worry many are. If you have two internet connections, LTE and skydish direct? Then you have two main possibilities. a. USE BOTH at the same time and provide the full available bandwidth b. USE ONE as a PRIMARY, and the other as SECONDARY (backup), so that if...
by anav
Mon Jan 01, 2024 6:08 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2233

Re: Inter-VLAN routing (unable to reach clients from VLAN)

Pinging gateway IPs, is reaching the router as they are local interfaces, does not mean you can actually reach users..... Lets look at the config......... (1) INPUT CHAIN, clearly you want reasonable security and thus I am assuming you want limited access to those that config the router. Hence allow...
by anav
Mon Jan 01, 2024 5:12 pm
Forum: Useful user articles
Topic: secondary router blocking issue from isp.
Replies: 1
Views: 1064

Re: secondary router blocking issue from isp.

First, this is a USEFUL ARTICLES FORUM.
You should post your question in Beginner Forum or GENERAL FORUM.
So please open a new thread there and close this one and when you do, please post a network diagram as what you have stated is NOT clear.
by anav
Mon Jan 01, 2024 5:01 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3492

Re: Wireguard Peers can't access IPs on VLANs

Perhaps I was imagining it because the first times I opened it the router stated was a 5009. When I do it today its now on the HEX> Looking at your diagram, can you confirm you use three different ether ports on the WIFI Router to connect three different vlans to three ports on the HEX??? What I was...
by anav
Mon Jan 01, 2024 7:45 am
Forum: Beginner Basics
Topic: Force the router to use a specific WAN
Replies: 5
Views: 1092

Re: Force the router to use a specific WAN

The requirement is not clear. The router provides services such as wireguard server for handshake, and there are ways to ensure that if traffic coming on WANX for that purpose goes out WANX. Its not clear to me thats what you mean?? It is rare to see input chain in mangling as that is traffic to the...
by anav
Mon Jan 01, 2024 3:51 am
Forum: Beginner Basics
Topic: Router is blocking outgoing web traffic [SOLVED]
Replies: 6
Views: 1040

Re: Router is blocking outgoing web traffic [SOLVED]

The default rules from MT already add such a rule in the forward chain.
I agree 100% that its common and thus why I suggested that Mikrotik add Zerotrust cloudflare tunnel as an options package for all devices. :-)
by anav
Sun Dec 31, 2023 8:45 pm
Forum: Beginner Basics
Topic: Basic CAPsMAN configuration with multiple VLANS
Replies: 6
Views: 909

Re: Basic CAPsMAN configuration with multiple VLANS

Really, so no datpaths and vlans in capsman, they took it out, how nice!! About time to remove vlans from wifi configs.........
by anav
Sun Dec 31, 2023 7:44 pm
Forum: Scripting
Topic: DynDNS Script from Mikrotik Wiki (correction)
Replies: 30
Views: 31324

Re: DynDNS Script from Mikrotik Wiki (correction)

Kitty has claws, do not mess with it, even with only one eye open you will get hurt, thinking your script knowledge is somehow better, such a comedian. You do know that cat is just Yoda in disguise.
by anav
Sun Dec 31, 2023 7:41 pm
Forum: General
Topic: Selection of Mikrotik hardware for PPPoE/Hotspot ISP
Replies: 3
Views: 604

Re: Selection of Mikrotik hardware for PPPoE/Hotspot ISP

The 5009 should have no issues handling this throughput.
by anav
Sun Dec 31, 2023 7:39 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7053

Re: Wireguard guru needed [SOLVED]

Just because your willing to sell your soul to cloudflare, some of use prefer not relying upon third party providers. :-P However, if port forwarding is in the mix, then cloudflare is a viable compromise, and for this case, it should be available on all MT devices, as a package, not hidden in contai...
by anav
Sun Dec 31, 2023 7:38 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2233

Re: Inter-VLAN routing (unable to reach clients from VLAN)

All good, now we both know we are not going insane :-) ( in my case more insane )
by anav
Sun Dec 31, 2023 7:36 pm
Forum: Beginner Basics
Topic: still same problem and same issue please help!
Replies: 8
Views: 2486

Re: still same problem and same issue please help!

L2TP windows client does not connect to wireguard, suggest you have to connect to an L2TP server.............. '=P As noted, your config is likely wrong and the fact that you havent posted a.. your complete config b. network diagrams Is completely absurd as this is not your fist post. You know very ...
by anav
Sun Dec 31, 2023 7:34 pm
Forum: Beginner Basics
Topic: Basic CAPsMAN configuration with multiple VLANS
Replies: 6
Views: 909

Re: Basic CAPsMAN configuration with multiple VLANS

Holvoe, that link is TOTALLY USELESS for those wanting to setup capsman and datapaths and VLANS.

Either make one (user article -as I have requested numerous times or stop suggesting something that doesnt fit.......
by anav
Sun Dec 31, 2023 7:31 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3492

Re: Wireguard Peers can't access IPs on VLANs

As pointed out you supplied a config for an RB5009. You have not stated where this router fits. You have not provided a hex config. Explain more how the upstream router works.......... does it provide an IP address on a private local subnet to the hex. You mention, NATing, please expound. A network ...
by anav
Sun Dec 31, 2023 7:28 pm
Forum: General
Topic: Selection of Mikrotik hardware for PPPoE/Hotspot ISP
Replies: 3
Views: 604

Re: Selection of Mikrotik hardware for PPPoE/Hotspot ISP

Too many unanswered details.
What is the throughput of each WAN.
Are the ISPs for all six different?

How many users are anticipated.
What kind of traffic will they be using,.......

Network diagram to show what happens after RB5009, switches APs etc.....
by anav
Sun Dec 31, 2023 5:17 pm
Forum: General
Topic: Reverse SSH port tuneling
Replies: 5
Views: 854

Re: Reverse SSH port tuneling

I would look at wireguard as the way to go.
One could have all devices on the same wireguard subnet easily reachable from the office or if away remotely.
by anav
Sun Dec 31, 2023 5:09 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7053

Re: Wireguard guru needed [SOLVED]

R2 that I posted is the last config on R2 because after that i lost connection :lol:
Too funny. By the way since its dirt easy to establish an SSTP connection between two MT routers, I always do one as a backup to WG.
by anav
Sun Dec 31, 2023 5:08 pm
Forum: Beginner Basics
Topic: Router is blocking outgoing web traffic [SOLVED]
Replies: 6
Views: 1040

Re: Router is blocking outgoing web traffic [SOLVED]

without evidence, its all opinion.

/export file=anynameyouwish ( minus router serial number, any public WANIP information )
by anav
Sun Dec 31, 2023 5:03 pm
Forum: Beginner Basics
Topic: WiFi client isolation with VLANs and remote gateway
Replies: 3
Views: 937

Re: WiFi client isolation with VLANs and remote gateway

Dont use vlan1 to pass data, its gets confusing especially as you are mixing devices. The MT uses it in the background.. If you are using vlans then go all vlans. If the HAPAC is simply acting as an AP/Switch the below works............ Hence a TRUNK Port carrying all vlans from pfsense to MT. The M...
by anav
Sun Dec 31, 2023 5:00 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2233

Re: Inter-VLAN routing (unable to reach clients from VLAN)

Hence why I asked if you had actually tried to reach a device, not just pinging............ ( in post #10 )
by anav
Sun Dec 31, 2023 4:54 pm
Forum: Beginner Basics
Topic: Terrible wifi speed - L009UiGS-2HaxD-IN - Wifi 6 (Router OS 7.13) [SOLVED]
Replies: 28
Views: 5459

Re: Terrible wifi speed - L009UiGS-2HaxD-IN - Wifi 6 (Router OS 7.13) [SOLVED]

holvoe, you missed the memo, he is using the same device with two separate access points, one gets him very good speeds and the L0009 crap. Suspect the testing device is not the issue but who knows......... @haha Did the OP try the 20/40 setting?? @haha DISABLE THIS RULE AND SEE if there is a differ...
by anav
Sun Dec 31, 2023 4:39 pm
Forum: General
Topic: Can't access device on management VLAN remotely via Wireguard
Replies: 12
Views: 3335

Re: Can't access device on management VLAN remotely via Wireguard

@Verylab 1. The client device has nothing to do with accepting an incoming handshake, the request to join wireguard comes from the client device and is outbound traffic. The router wireguard service is hosted on the Server device at the incoming handshake and thus needs the input chain rule TO the r...
by anav
Sun Dec 31, 2023 2:54 am
Forum: Beginner Basics
Topic: Terrible wifi speed - L009UiGS-2HaxD-IN - Wifi 6 (Router OS 7.13) [SOLVED]
Replies: 28
Views: 5459

Re: Terrible wifi speed - L009UiGS-2HaxD-IN - Wifi 6 (Router OS 7.13) [SOLVED]

In general marketing speeds are misleading, use the 1/3 rule. Basically they typically combine up and down so already one is at 50% and then there are losses due to propagation interference from other access points, walls electrical circuits etc.. So realistically would look at around 180 Mbps as a ...
by anav
Sat Dec 30, 2023 11:45 pm
Forum: Beginner Basics
Topic: CAP AC: Stripping MAC Addresses impacting DHCP
Replies: 12
Views: 2147

Re: CAP AC: DHCP assigned DNS

Ahh okay so your not using vlans........... and only want to send one flat subnet to the CAPAC ?? /interface bridge add ingress-filtering=no name=bridge /interface ethernet set [ find default-name=ether2 ] name=emergaccess /interface list add name= management /interface wireless AS REQUIRED assuming...
by anav
Sat Dec 30, 2023 11:42 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2233

Re: Inter-VLAN routing (unable to reach clients from VLAN)

Yes, I am all out of ideas, there is no logical reason I see that its not working. I would try two things myself personally first, grasping at silly straws....... a. change dns servers such that it looks like /ip dhcp-server network add address=10.0.10.0/24 dns-server= 10.0.10.1 gateway=10.0.10.1 ad...
by anav
Sat Dec 30, 2023 10:26 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2233

Re: Inter-VLAN routing (unable to reach clients from VLAN)

Yes admit all is the default. Other than that missing the issue. Did you try a reboot of the router after making those changes?? If after a reboot still no joy try adding this rule to the forward chain above the drop all rule. add chain=forward action=accept src-address=192.168.2.0/24 dst-address=10...
by anav
Sat Dec 30, 2023 10:05 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2233

Re: Inter-VLAN routing (unable to reach clients from VLAN)

1. Who told you to put only vlan tagged on the bridge settings............... mostly just need to enable vlan filtering only.??? Remove it!!! This is your issue. /interface bridge add frame-types=admit-only-vlan-tagged name=Main_Bridge protocol-mode=none \ vlan-filtering=yes 2. Personal preference I...
by anav
Sat Dec 30, 2023 9:26 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7053

Re: Wireguard guru needed [SOLVED]

I dont guess LOL< when I see two udpated configs, I can look at the evidence. :-)
by anav
Sat Dec 30, 2023 9:25 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2233

Re: Inter-VLAN routing (unable to reach clients from VLAN)

Your firewall rules seem fine and yes, the rule does exactly that. Remember we modify the default rule into three rules and thus change the concept of allow everything except wan to lan traffic without dst nat rules TO block everything and only allow traffic we specifically state is permitted aka la...
by anav
Sat Dec 30, 2023 9:20 pm
Forum: General
Topic: How can I protect my VPN network from attempted intrusion?
Replies: 9
Views: 1448

Re: How can I protect my VPN network from attempted intrusion?

CPU usage for no gain. Simply dont log it. Out of sight out of mind.
by anav
Sat Dec 30, 2023 9:17 pm
Forum: General
Topic: route marking with two ISPs and PCC with wireguard
Replies: 6
Views: 1541

Re: route marking with two ISPs and PCC with wireguard

Observations (1) DO NOT USE VLAN-ID=1. Its already used by the router in the background and should not be used to carry data, it can cause weird things down the line. Instead just switch that to VLAN-ID=99 for example because its actually called vlan99_BASE, why you assigned 1 is beyond me.............
by anav
Sat Dec 30, 2023 8:56 pm
Forum: General
Topic: Dual WAN PCC ok but no web browsing
Replies: 19
Views: 1693

Re: Dual WAN PCC ok but no web browsing

What you mean redundant via VRRP. What is the part you are concerned about?? You have a mickrotik device with two WAN sources. Either both are up, one is up or both are down. How is VRRP going to help you here?? A network diagram may clear up the mystery. Ahh. reread the first post, have two HEXES d...
by anav
Sat Dec 30, 2023 7:43 pm
Forum: General
Topic: route marking with two ISPs and PCC with wireguard
Replies: 6
Views: 1541

Re: route marking with two ISPs and PCC with wireguard

I will have a look and see what I can figure out................... The funny thing about MT, it can allow some traffic if the config is almost there, but eventually any errors will reach up and grab you by the nuts.........
by anav
Sat Dec 30, 2023 7:42 pm
Forum: General
Topic: Dual WAN PCC ok but no web browsing
Replies: 19
Views: 1693

Re: Dual WAN PCC ok but no web browsing

Hmm, not sure what you are doing,,,,, but whats wrong with 2 or three vlans for subnets, one bridge and then doing PCC as needed. As well the deviation from default firewall rules ( aka the mess and utter garbage) makes the overall situation far more complex than it needs to be. Can you state simply...
by anav
Sat Dec 30, 2023 3:52 pm
Forum: Wireless Networking
Topic: Microtik AP advice
Replies: 14
Views: 2390

Re: Microtik AP advice

Sweet performance!
by anav
Sat Dec 30, 2023 3:51 pm
Forum: Wireless Networking
Topic: VLAN Trunk over WiFi for SOHO networks - use EoIP or else?
Replies: 6
Views: 1869

Re: VLAN Trunk over WiFi for SOHO networks - use EoIP or else?

WHy not considering using WIFI ethernet also known as 60hz wifi. Basically creates a 1 gig connection between two points that acts like an ethernet cable and called wireless wire. You can put whatever you want at the other end, switch access point etc.... You can pass as many vlans as you like ........
by anav
Sat Dec 30, 2023 3:47 pm
Forum: Beginner Basics
Topic: Help with first home server
Replies: 2
Views: 659

Re: Help with first home server

This is a perfect case for BTH! In this case we will establish a VPN tunnel from the router to the BTH mikrotik relay server and then all remote users will have a pathway to reach the router. In this regard AT LEAST, you can access your router and LAN securely and get rid of the bogus access you hav...
by anav
Sat Dec 30, 2023 3:44 pm
Forum: Beginner Basics
Topic: hap ax^2 config
Replies: 24
Views: 2176

Re: hap ax^2 config

Just showing that nature is more powerful than technology.
Also note that If Turn around quickly enough I can light my own flatulence.
by anav
Sat Dec 30, 2023 3:39 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7053

Re: Wireguard guru needed [SOLVED]

As per my post, the best way to do this is add a list of static LOCAL IPs and wireguard IPs, ( including the off bridge IP ) into a SOURCE ADDRESS LIST. These are the only users allowed to the router. The LAN users get access to DNS services, the only ones they need.......... This rule you had 5 cha...
by anav
Sat Dec 30, 2023 3:30 pm
Forum: Beginner Basics
Topic: CAP AC: Stripping MAC Addresses impacting DHCP
Replies: 12
Views: 2147

Re: CAP AC: DHCP assigned DNS

This is how I setup my capac ( as an AP/switch) ( sorry no capsman ).
viewtopic.php?t=182276
by anav
Sat Dec 30, 2023 3:28 pm
Forum: Beginner Basics
Topic: Trouble with port forwarding through a Wireguard VPN [SOLVED]
Replies: 14
Views: 3137

Re: Trouble with port forwarding through a Wireguard VPN [SOLVED]

I trust you to apply an excellent config for a specific purpose. However, this is not the case, you have invented a requirement not requested, likely to never be requested and it only ends up confusing people trying to learn. The bottom line is the output chain rule is not needed here. For anybody r...
by anav
Sat Dec 30, 2023 3:20 pm
Forum: Beginner Basics
Topic: Inter-VLAN routing (unable to reach clients from VLAN)
Replies: 24
Views: 2233

Re: Inter-VLAN routing (unable to reach clients from VLAN)

THe easy way to do this is to modify the concept of the default firewall setup which is allow everything block a few things, to Block everything and allow only needed traffic. Hence this ( and in the right order ) : ( default rules to keep in the right order ) add action=fasttrack-connection chain=f...
by anav
Sat Dec 30, 2023 3:08 pm
Forum: Beginner Basics
Topic: hap ax^2 config
Replies: 24
Views: 2176

Re: hap ax^2 config

Maybe he doesn't trust a cat wielding a chainsaw.... '=P
by anav
Sat Dec 30, 2023 3:04 pm
Forum: General
Topic: Help Troubleshooting DualWAN configuration.rsc
Replies: 3
Views: 1354

Re: Help Troubleshooting DualWAN configuration.rsc

Good opportunity to stop trying to copy and start trying to learn! Print off the config and then start adding from winbox one config line at a time. You will quickly find out that you cannot enter certain settings unless others are already setup................. let the learning begin!! @holvoe, you...
by anav
Fri Dec 29, 2023 11:30 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7053

Re: Wireguard guru needed [SOLVED]

Yes, that is the rule removed that did you in. Since your kicking yourself, go back to post 7 to reread, ;-)
by anav
Fri Dec 29, 2023 11:29 pm
Forum: Beginner Basics
Topic: Trouble with port forwarding through a Wireguard VPN [SOLVED]
Replies: 14
Views: 3137

Re: Trouble with port forwarding through a Wireguard VPN [SOLVED]

Now your making up crap..... There is no need in this scenario, and no clear future need for the output chain in a future scenario from incoming Wireguard traffic from the other Device. If one was to have WG incoming to this router perhaps............ So instead of exiting gracefuly from this thread...
by anav
Fri Dec 29, 2023 11:25 pm
Forum: General
Topic: simple 3 isp dhcp clients with aggregation
Replies: 18
Views: 2989

Re: simple 3 isp dhcp clients with aggregation

Not familiar with other tools someone might use, I am strictly referring to the performance provided by the MT config.
If there is aggregation wrt to a single session, some other device/software is performing this not the MT.
by anav
Fri Dec 29, 2023 11:19 pm
Forum: General
Topic: Wireguard Peers can't access IPs on VLANs
Replies: 32
Views: 3492

Re: Wireguard Peers can't access IPs on VLANs

The hex is basically acting as a switch. It does not need any addresses other than the trusted network and assuming this as vlan200 subnet Post config of hex /export file=anynameyouwish ( minus router serial number, any public WANIP information, keys etc..). Edit: See config now at bottom of your po...
by anav
Fri Dec 29, 2023 9:21 pm
Forum: General
Topic: How to block ip scanners
Replies: 3
Views: 913

Re: How to block ip scanners

/export file=anynameyouwish ( minus router serial number, and any public WANIP information )
by anav
Fri Dec 29, 2023 9:19 pm
Forum: General
Topic: simple 3 isp dhcp clients with aggregation
Replies: 18
Views: 2989

Re: simple 3 isp dhcp clients with aggregation

Nope the best you can hope for, on any one sessions, is the maximum throughput of the ISP the user is connected to. The total amount of bandwidth is greater to share. So instead of 50 users sharing 500Mbps of throughput, they are sharing 1Gbps throughput, so each user has more opportunity for a bigg...
by anav
Fri Dec 29, 2023 6:50 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7053

Re: Wireguard guru needed [SOLVED]

I am sure it will the first and LAST time LOL.
by anav
Fri Dec 29, 2023 6:03 pm
Forum: General
Topic: Reverse SSH port tuneling
Replies: 5
Views: 854

Re: Reverse SSH port tuneling

Sounds unnecessarily complex.
What is the requirement for you the admin or a user.........
In plain english without any protocol or config speak.........
by anav
Fri Dec 29, 2023 6:00 pm
Forum: Beginner Basics
Topic: Trouble with port forwarding through a Wireguard VPN [SOLVED]
Replies: 14
Views: 3137

Re: Trouble with port forwarding through a Wireguard VPN [SOLVED]

Disagree, the traffic being discussed is very specific, its outside user, port forwarded at VPS into the tunnel to servers on MT device. There is no user that will be coming into VPS on a public IP (not in tunnel) being directed to the MT config aka to the router itself. Magic mushrooms for xmas?? W...
by anav
Fri Dec 29, 2023 5:57 pm
Forum: Beginner Basics
Topic: Load balancing & failover with multiple WAN on MikroTik?
Replies: 2
Views: 655

Re: Load balancing & failover with multiple WAN on MikroTik?

Then post your complete config here. /export file=anynameyouwish ( minus router serial number, any public WANIP information, keys etc..). Ensure you discuss any port forwardings or VPNs in the mix. Any subnets not involved in PCC ( if any ). Other special traffic flows you need........... Did you pl...
by anav
Fri Dec 29, 2023 5:51 pm
Forum: Beginner Basics
Topic: hap ax^2 problem [SOLVED]
Replies: 6
Views: 1371

Re: hap ax^2 problem [SOLVED]

I'm shocked, MKX forgot to state after the advice, reset to deafaulst and THEN USE QUICKSET????
by anav
Fri Dec 29, 2023 5:49 pm
Forum: Beginner Basics
Topic: Wireguard guru needed [SOLVED]
Replies: 54
Views: 7053

Re: Wireguard guru needed [SOLVED]

So Holvoe, the config is correct and thus you can impart ROMON wisdom. Do pray tell while I show you how to actually review a config, what value does ROMON provide in this scenario...............I would like to know as I probably could use it too. Observations (1) There is no point in having ether5,...
by anav
Fri Dec 29, 2023 5:34 pm
Forum: Beginner Basics
Topic: hap ax^2 config
Replies: 24
Views: 2176

Re: hap ax^2 config

Ahh so MT configuration is your hobby, full time clown '=P
by anav
Fri Dec 29, 2023 5:32 pm
Forum: General
Topic: Wireguard tunnel unable to use inet on the other side of tunnel.... [SOLVED]
Replies: 5
Views: 1268

Re: Wireguard tunnel unable to use inet on the other side of tunnel.... [SOLVED]

Thank god for peer reviews in science, is all I can say....... In any case, now readers will know that your 'solution' is slightly flawed and an explanation is provided as to why and the correct config has been provided. Not about you or me, quite correct, its about others also looking for assistance.
by anav
Fri Dec 29, 2023 4:41 pm
Forum: Beginner Basics
Topic: hap ax^2 config
Replies: 24
Views: 2176

Re: hap ax^2 config

I knew you guys belonged to the same wifi masochist club!
Just waiting for the updated User article on how to setup vlans with new wifi and capsman......... ???
by anav
Fri Dec 29, 2023 4:17 pm
Forum: General
Topic: How to block ip scanners
Replies: 3
Views: 913

Re: How to block ip scanners

Not sure what you are doing, a poorly worded explanation is useless. A. provide a network diagram B. provide full config /export file=anynameyouwish ( minus router serial number, public WANIP information, etc.. ) C. Clearly state the requirements. - identify all users - identify traffic they need to...
by anav
Fri Dec 29, 2023 3:04 pm
Forum: General
Topic: Using WireGuard to connect to router from guest network using the same router
Replies: 2
Views: 790

Re: Using WireGuard to connect to router from guest network using the same router

Would have been easy to spot if you had provided the config.
/export file=anynameyouwish ( m inus router serial number, public WANIP information, keys etc..)

Glad you got it sorted!
by anav
Fri Dec 29, 2023 3:03 pm
Forum: General
Topic: Wireguard tunnel unable to use inet on the other side of tunnel.... [SOLVED]
Replies: 5
Views: 1268

Re: Wireguard tunnel unable to use inet on the other side of tunnel.... [SOLVED]

YOur configs are not complete and do not show firewall rules or interface list / members etc.. So cannot comment on the rest of the config. In your case, it would have been simpler not to mangle anything on RB -table add fib name=useWG -Ip route add dst-address=0.0.0.0/0 gateway=wireguard1 routing-t...
by anav
Fri Dec 29, 2023 2:56 pm
Forum: General
Topic: Wireguard tunnel unable to use inet on the other side of tunnel.... [SOLVED]
Replies: 5
Views: 1268

Re: Wireguard tunnel unable to use inet on the other side of tunnel.... [SOLVED]

Self solving is rather arrogant. Allowed IPs on Router A works but the moment you add any peers like remote users that need access RA or RB remotely, the error will show itself more clearly. In other words the Allowed IP settings on Router A ( the server ) would be better served as follows; peer RB ...
by anav
Fri Dec 29, 2023 12:01 am
Forum: General
Topic: Individual firewall and Node-RED port problem [SOLVED]
Replies: 17
Views: 1853

Re: Individual firewall and Node-RED port problem [SOLVED]

Unfortunately I cannot comment as I dont use or are familiar with vlans using datapaths and capsman.
I will say that bridge vlan filtering does not seem to be turned on, and I dont see any /interface bridge vlan settings.........
by anav
Thu Dec 28, 2023 11:42 pm
Forum: General
Topic: Policy based routing
Replies: 9
Views: 962

Re: Policy based routing

Sorry I dont see tunnel within a tunnel at all............ All the more reason for network diagram LOL Okay Can you confirm the source address coming on wireguard is not limited to. a. single wireguard source addresses ( like from individual WG users ) b. private subnets from another device connecte...
by anav
Thu Dec 28, 2023 11:36 pm
Forum: Beginner Basics
Topic: Trouble with port forwarding through a Wireguard VPN [SOLVED]
Replies: 14
Views: 3137

Re: Trouble with port forwarding through a Wireguard VPN [SOLVED]

add chain=output connection-mark=wg-conn action=mark-routing new-routing-mark=wg I was with you till you posted the output chain rule......... There is no traffic from the router itself we need to be concerned with ??? I came up with two other variations, for fun but they dont add much in this case...
by anav
Thu Dec 28, 2023 11:19 pm
Forum: Beginner Basics
Topic: Trouble with port forwarding through a Wireguard VPN [SOLVED]
Replies: 14
Views: 3137

Re: Trouble with port forwarding through a Wireguard VPN [SOLVED]

Without a network diagram Im a tad lost. Using linux at the VPS is of no help either............ He wants to see originating IP address at the VPS or at the MT device??? Thus port forwards the traffic from there with destination address to his servers which are actually at the MT. So he needs port f...
by anav
Thu Dec 28, 2023 10:27 pm
Forum: General
Topic: Policy based routing
Replies: 9
Views: 962

Re: Policy based routing

A network diagram would allow us to better see through the fog of your explanation and the missing pieces which should have been provided up front.
by anav
Thu Dec 28, 2023 9:28 pm
Forum: General
Topic: Policy based routing
Replies: 9
Views: 962

Re: Policy based routing

Not understanding the additional complexity. a. need route back into tunnel created automatically on MT router by the use of the ip address of the wireguard on the router creates a DAC route. Thus any incoming traffic from a source with wireguard IP, already has a route back........ b. Need a firewa...
by anav
Thu Dec 28, 2023 6:30 pm
Forum: Beginner Basics
Topic: Trouble with port forwarding through a Wireguard VPN [SOLVED]
Replies: 14
Views: 3137

Re: Trouble with port forwarding through a Wireguard VPN [SOLVED]

Again, do you mean port forwarding done at the VPS or done once the traffic arrives at the MT.

I guess i dont get why doesnt the client go through WG and straight to the device in question???
The old firewall forward chain :-)
by anav
Thu Dec 28, 2023 6:28 pm
Forum: Beginner Basics
Topic: hEX PoE lite default + vlan
Replies: 12
Views: 3197

Re: hEX PoE lite default + vlan

The solution that I would advise is the following: /interface bridge port add bridge=bridge interface=ether2 pvid=10 add bridge=bridge interface=ether3 pvid=10 add bridge=bridge interface=ether4 pvid=10 add bridge=bridge interface=ether5 pvid=10 /interface bridge vlan add bridge=bridge tagged=bridge...