Community discussions

MikroTik App

Search found 2104 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 8
by CZFan
Sat Jun 15, 2019 1:23 pm
Forum: Beginner Basics
Topic: Mikrotik RB2011 in "Router" Mode
Replies: 12
Views: 3117

Re: Mikrotik RB2011 in "Router" Mode

I am not really sure you are successfully pinging the SXT (192.168.88.1) as both devices have that same IP config on ether1 interfaces, so your config seems totally incorrect . You already have a "router / firewall / DHCP / etc" in the SXT, why not make the Hap AC2 a "switch+AP" ...
by CZFan
Thu Jun 13, 2019 11:42 am
Forum: Beginner Basics
Topic: Every device shows the same IP in Winbox Scan
Replies: 4
Views: 1411

Re: Every device shows the same IP in Winbox Scan

Suspect you have configured Proxy-Arp on interface(s).
by CZFan
Thu Jun 13, 2019 12:49 am
Forum: General
Topic: RouterOS Virtual Labs
Replies: 85
Views: 148852

Re: RouterOS Virtual Labs

@sebastia,
I created a new "project" in gns3 today and again, one of the my routers mixed up the ether ports.

Would you mind sharing a bit more of your setup, i.e. Which version of gns3, using virtualbox, VMware player, workstation, etc?
by CZFan
Wed Jun 12, 2019 2:16 pm
Forum: RouterBOARD hardware
Topic: Wireless wire 60Ghz default password
Replies: 31
Views: 22955

Re: Wireless wire 60Ghz default password

Took over client from another service provider, previous service provider created their own admin user / password and removed the default admin user. The equipment is now mounted on masts, etc, is there a way to get the default admin user / password from the device for record keeping purposes? Using...
by CZFan
Tue Jun 11, 2019 6:35 pm
Forum: Forwarding Protocols
Topic: ❗️❓ UNSTABLE VPLS on Wireless networks
Replies: 13
Views: 5245

Re: ❗️❓ UNSTABLE VPLS on Wireless networks

One bit of info missing, does the wireless link go down for 60 seconds before connects again? Reason I am asking is we have a wireless link, 2 x LHG 5ac's, short distance (about 700 meters) but sometimes takes up to 3 minutes to connect again if the wireless link dropped and reason seems to be takin...
by CZFan
Sun Jun 09, 2019 11:40 pm
Forum: General
Topic: RouterOS Virtual Labs
Replies: 85
Views: 148852

Re: RouterOS Virtual Labs

I'm trying to get CHR working on EVE-NG and it works but the interfaces dont seem to line up. I will put 192.168.1.1/24 on R1:ether1 and 192.168.1.2/24 on R2:ether1. I will make a connection from R1:ether1 and R2:ether1. I will then try to ping 192.168.1.2 from R1 with no success. I will move the I...
by CZFan
Sun Jun 09, 2019 1:32 pm
Forum: Beginner Basics
Topic: Wireless Wire (RBwAPG-60adkit) - Not working. Appreciate the help!
Replies: 7
Views: 2587

Re: Wireless Wire (RBwAPG-60adkit) - Not working. Appreciate the help!

I recently installed one of these Wireless Wire setups, straight from the supplier the 2 radios did not want to connect. After logging in on each device, I noticed both were in "Bridge" mode, changed the slave to "Station-Bridge" then it connected. Not sure if above is correct bu...
by CZFan
Sun Jun 09, 2019 12:26 am
Forum: General
Topic: Need Solution: How to get the maximum speed of my Connection from my MikrotikBoard 2011UiAS-2HnD [SOLVED]
Replies: 7
Views: 6883

Re: Need Solution: How to get the maximum speed of my Connection from my MikrotikBoard 2011UiAS-2HnD [SOLVED]

You will need to make use of firewall "fasttrack" rule.

Search the forum, many discussions re above, including on the 2011 router
by CZFan
Sat Jun 08, 2019 9:01 pm
Forum: Beginner Basics
Topic: Help! -- Something is dropping All traffic
Replies: 2
Views: 732

Re: Help! -- Something is dropping All traffic

Your problems is that "Cisco Small Business" thingy :-) Just joking, have to echo what @anav said, without seeing config and / or more info on environment, very difficult to assist. Maybe as a starting point provide full config (after deleting sensitive info) of 3011's and also a network d...
by CZFan
Sat Jun 08, 2019 8:53 pm
Forum: General
Topic: Time Based firewaal rules
Replies: 12
Views: 2842

Re: Time Based firewaal rules

I figured it out!! You have to specify the time and day or days that you want the rule to be applied and then you have to press reset all counters to reset everything and allow the new rule to be applied. I checked it 3-4 times and it worked fine. Thank you all!!!! I suspect that you have a rule be...
by CZFan
Sat Jun 08, 2019 8:27 pm
Forum: General
Topic: QUEUE TREE
Replies: 4
Views: 1193

Re: QUEUE TREE

Don't quite understand your question, you say you have seen this configuration and state that it worked??? Anyway, to answer your question, yes, you mark the connection, then the packets of this connection, the "connection" is both "up" and "down" traffic. Then apply th...
by CZFan
Sat Jun 08, 2019 8:20 pm
Forum: General
Topic: QinQ VLAN's Help needed [SOLVED]
Replies: 96
Views: 25754

Re: QinQ VLAN's Help needed [SOLVED]

@deepmedia
As a side note, I assume the 1.1.1.1, etc addresses are loopback addresses, anyway, personally I will stay away from them as they are routable on internet
by CZFan
Sat Jun 08, 2019 7:21 pm
Forum: General
Topic: Strange Mangle situation - Download fighting Upload [SOLVED]
Replies: 22
Views: 6362

Re: Strange Mangle situation - Download fighting Upload [SOLVED]

...

How in the world are you going to specify flow direction in the "Queue Tree" ? The Flow Direction is done in mangle with packer marking and then used as an input in the "Queue Tree".
...
QtreeIface.JPG
by CZFan
Sat Jun 08, 2019 2:25 am
Forum: General
Topic: Strange Mangle situation - Download fighting Upload [SOLVED]
Replies: 22
Views: 6362

Re: Strange Mangle situation - Download fighting Upload [SOLVED]

Hy I'm also confused. How can CZFan's example work? The mangle uses src-address-list, meaning "Download" traffic from a bunch of IPs. How can those packet marks be used in Queue trees for uploads? ... the mangle uses src-address-list, for the device starting the connection, in this case i...
by CZFan
Fri Jun 07, 2019 7:52 pm
Forum: General
Topic: Strange Mangle situation - Download fighting Upload [SOLVED]
Replies: 22
Views: 6362

Re: Strange Mangle situation - Download fighting Upload [SOLVED]

... So long this did the trick, but i had the assumption that what ever you put into Connection marking follows the Packet marking if you use "Connection marking" as input ? This had me fighting for a very long time and i hope it help others as well. Also this proves that almost every Tut...
by CZFan
Fri Jun 07, 2019 1:54 am
Forum: Beginner Basics
Topic: Problem with Firewall Rule
Replies: 3
Views: 1404

Re: Problem with Firewall Rule

It will block ssh, but as sftp runs over ssh session, it will also block sftp
by CZFan
Fri Jun 07, 2019 1:10 am
Forum: General
Topic: EoIP & Queue
Replies: 1
Views: 1446

Re: EoIP & Queue

Under queue tree, for VPN:IN, change parent to LAN interface, i.e. Bridge or what ever you called it
by CZFan
Fri Jun 07, 2019 12:12 am
Forum: General
Topic: Strange Mangle situation - Download fighting Upload [SOLVED]
Replies: 22
Views: 6362

Re: Strange Mangle situation - Download fighting Upload [SOLVED]

Not at my pc at the moment, but below with you doing some reading on wiki should get you there.

You should not specify interfaces in mangle rules, then in queue tree config, specify the interface / queue as required, i.e. Bridge interface for download and PPPoE interface for upload
by CZFan
Sun Jun 02, 2019 1:02 am
Forum: Beginner Basics
Topic: Can i intercept Traffic flowing through my MikroTik Router?
Replies: 3
Views: 1441

Re: Can i intercept Traffic flowing through my MikroTik Router?

Traffic flow is used for network statistics.

I think it will be better if you define "intercept" and what actually needs to happen to the frames / packets once intercepted in order for us to get a better unde standing of a our requirements and provide better suggestions.
by CZFan
Sun Jun 02, 2019 12:51 am
Forum: Beginner Basics
Topic: Ban IP's / Drop connections of RDP Brute forcers
Replies: 6
Views: 2375

Re: Ban IP's / Drop connections of RDP Brute forcers

Hmmmm, there is no reason why the action drop rule should be in the RAW firewall filter and NOT the input chain. As the rhyme goes. I would like to slap the peepee of the person that wrote the wikee. Slow day. ;-) Highly recommend you read through this thread for some sage advice! https://forum.mik...
by CZFan
Fri May 31, 2019 12:21 am
Forum: General
Topic: Trying to change IPSEC Peers from main to aggressive, getting an error I dont understand.
Replies: 9
Views: 6922

Re: Trying to change IPSEC Peers from main to aggressive, getting an error I dont understand.

Re firewall, also ensure you block DNS from outside on input chain
by CZFan
Thu May 23, 2019 12:23 am
Forum: General
Topic: VLAN trunk - master-slave way of config on physical interfaces [SOLVED]
Replies: 30
Views: 6122

Re: VLAN trunk - master-slave way of config on physical interfaces [SOLVED]

It never came to my mind to try to push VLANs through a L2TP tunnel in bridge mode, but I've expected it would be enough to configure the /interface bridge port and /interface bridge vlan items also for the L2TP interfaces. However, it seems RouterOS is not ready for this (at least as of 6.44.3). W...
by CZFan
Tue May 21, 2019 10:33 pm
Forum: General
Topic: Strange RP filter behavior
Replies: 12
Views: 3281

Re: Strange RP filter behavior

@macgaiver: Here you go, but be warned, once you see it, you can't unsee it.

Do you and @sindy visit each other in The Matrix for drinks :-)
by CZFan
Tue May 21, 2019 12:18 am
Forum: General
Topic: Route to multiple remote locations with same LAN subnet/network [SOLVED]
Replies: 8
Views: 4837

Re: Route to multiple remote locations with same LAN subnet/network [SOLVED]

Sindy=genius!!!
You should write a routerOS book, I will pre-order buy it now!

Yes, indeed, that he should do, will also order before publication.
His method of reaching or explains is excellent
by CZFan
Fri May 17, 2019 9:41 pm
Forum: General
Topic: Winbox Simple Queue display change
Replies: 2
Views: 1643

Re: Winbox Simple Queue display change

Toggle on or off by clicking on "#"
by CZFan
Thu May 16, 2019 10:10 pm
Forum: General
Topic: How to PCQ this?
Replies: 5
Views: 1657

Re: How to PCQ this?

Are the subnets consecutive? If so, aggregate / summarize the subnets
by CZFan
Wed May 15, 2019 11:50 pm
Forum: General
Topic: How to PCQ this?
Replies: 5
Views: 1657

Re: How to PCQ this?

Target should point to internal subnet, rest looks good
by CZFan
Tue May 14, 2019 3:34 am
Forum: General
Topic: Mk, NAT Open Request [Help needed]
Replies: 83
Views: 17875

Re: Mk, NAT Open Request [Help needed]

I think it is time you pride the config, in terminal window,
Export file=YourFileName hide-sensitive and either attach the file here or copy and paste the contents between source code brackets
by CZFan
Sun May 12, 2019 1:56 am
Forum: General
Topic: SXT 2 Discontinued?
Replies: 3
Views: 1110

Re: SXT 2 Discontinued?

On Stock in Germany

Same in South Africa
by CZFan
Sat May 11, 2019 9:57 pm
Forum: General
Topic: VLAN over Bridge
Replies: 42
Views: 6152

Re: VLAN over Bridge

... The way Google Fiber and the OP's ISP use of the CoS field in the VLAN tag is rather a misuse to me, because normally it is used to convey the information about frame priority, not that it would have to contain a single mandatory value. But I have no idea what weakness of their system they had ...
by CZFan
Sat May 11, 2019 8:49 pm
Forum: General
Topic: VLAN over Bridge
Replies: 42
Views: 6152

Re: VLAN over Bridge

... 3. While I've only worked on one RB4011 I don't recall all the switch menu options being set like this. But I won't know until this week when it's back up online at a the customer site to double check but wasn't there when I was doing the initial setup. ... The RB4011 has a RTL8367 switch chip ...
by CZFan
Sat May 11, 2019 8:38 pm
Forum: General
Topic: VLAN over Bridge
Replies: 42
Views: 6152

Re: VLAN over Bridge

@sindy & @anav, while your little spat is cute you both have failed to notice some glaring errors in this config. 1. bridgePrio6 is the one that is supposed to filter this WAN VLAN stuff. So why is it a _member_ of the default bridge?! That's a no no. 2. There is nothing that shows bridgePrio6 ...
by CZFan
Sun Apr 28, 2019 3:21 am
Forum: Forwarding Protocols
Topic: Output of "/routing bgp advertisements print" is truncated [SOLVED]
Replies: 5
Views: 11424

Re: Output of "/routing bgp advertisements print" is truncated [SOLVED]

Have you tried accessing the device with ssh and then run command?
by CZFan
Wed Apr 24, 2019 4:40 pm
Forum: General
Topic: use another dns for http
Replies: 12
Views: 1483

Re: use another dns for http

Personally, I would use Domain Controller as DNS (and DHCP) for internal clients, DNS should already be installed on DC Server as that is one of the requirements for AD to work properly
by CZFan
Wed Apr 24, 2019 3:52 am
Forum: General
Topic: ip scan to text file
Replies: 1
Views: 1276

Re: ip scan to text file

Think it will be something like
/tool ip-scan address=12.34.56.78 interface=ether1
by CZFan
Wed Apr 24, 2019 1:38 am
Forum: Beginner Basics
Topic: RouterOS - NAT problem (dst-nat)
Replies: 27
Views: 11296

Re: RouterOS - NAT problem (dst-nat)

...
Then the client will send mails out, either directly to your hosted mail server or alternative Skype server.
...
Suppose to be SMTP Server, Apple IOS auto correct :-(
by CZFan
Tue Apr 23, 2019 4:22 am
Forum: Beginner Basics
Topic: RouterOS - NAT problem (dst-nat)
Replies: 27
Views: 11296

Re: RouterOS - NAT problem (dst-nat)

@Anav, IIRC, you are using an email client with mail server hosted our side your network. Then the client will send mails out, either directly to your hosted mail server or alternative Skype server. The mail coming in, is being "pulled" by the mail client, so connection is into initiated f...
by CZFan
Tue Apr 23, 2019 4:00 am
Forum: General
Topic: Issues with internal traffic not getting NATed
Replies: 22
Views: 5631

Re: Issues with internal traffic not getting NATed

I am struggling to understand what you are looking for here, the "drop invalid" rule is the built in solution
by CZFan
Tue Apr 23, 2019 3:46 am
Forum: General
Topic: Run script when a gateway fails over
Replies: 5
Views: 1271

Re: Run script when a gateway fails over

Based on the limited information you provided, this should be sufficient:

Create / run a script to pick up active wan IP
by CZFan
Sun Apr 21, 2019 8:31 pm
Forum: Beginner Basics
Topic: RouterOS - NAT problem (dst-nat)
Replies: 27
Views: 11296

Re: RouterOS - NAT problem (dst-nat)

RouterOS uses routes from "/ip route" to decide where to send packets. It doesn't automatically send replies back the same way from where the request came. So you have incoming connection on WAN2, but default route uses WAN1, so response packets are sent there and of course it doesn't wor...
by CZFan
Sun Apr 21, 2019 6:02 pm
Forum: Beginner Basics
Topic: Avoiding Double NAT with multiple routers
Replies: 25
Views: 17851

Re: Avoiding Double NAT with multiple routers


@anav I already did it (viewtopic.php?f=13&t=145144), but I got no answers... l don’t know what to do.

You now have an answer...
by CZFan
Sun Apr 21, 2019 6:01 pm
Forum: Beginner Basics
Topic: NAT problems - Xbox One and Nintendo Switch
Replies: 32
Views: 11187

Re: NAT problems - Xbox One and Nintendo Switch

If you have hired a company to do the installation, then surely they must correct the problem / design of the network?

Alternatively, my suggestion will be to hire a Mikrotik Certified Consultant in your area. https://mikrotik.com/consultants
by CZFan
Fri Apr 19, 2019 3:22 am
Forum: General
Topic: Need advice with a proper router for my home.
Replies: 13
Views: 3184

Re: Need advice with a proper router for my home.

What will you do that concerns you about the memory.
Hap ac2 has 4 cpu and that memory is more than sufficient
by CZFan
Mon Apr 15, 2019 11:50 pm
Forum: General
Topic: who can I hire to get a export to work as an import an a clone [SOLVED]
Replies: 7
Views: 2295

Re: who can I hire to get a export to work as an import an a clone [SOLVED]

...

I can't seem to downgrade it to 6.34.4 Mikrotik seems to have deleted the firmware from there website

...

https://mikrotik.com/download/archive
by CZFan
Sun Apr 14, 2019 4:39 pm
Forum: General
Topic: help with queue
Replies: 4
Views: 1040

Re: help with queue

Add a simple queue with target of CCTV IP and set rate limits required
by CZFan
Sun Apr 14, 2019 4:34 pm
Forum: Beginner Basics
Topic: HAP mini IPSEC+EoIP performance?
Replies: 4
Views: 1791

Re: HAP mini IPSEC+EoIP performance?

As far as I can recall, Hap Mini and Lite has exactly the same specs, only difference is mini has 3 ether ports and Lite has 4 ether ports
by CZFan
Fri Apr 12, 2019 4:45 am
Forum: Wireless Networking
Topic: Some wireless questions
Replies: 5
Views: 1621

Re: Some wireless questions

My main concern is to make sure the antennas are aligned, my thinking is does not matter settings you play with, if alignment is out, you will never have a stable / good link. but seems for some reason, no one here wants to comment on if the alignment tool in Winbox still works. I have set the chann...
by CZFan
Thu Apr 11, 2019 11:20 pm
Forum: General
Topic: L2TP VPN "L2TP UDP packet received from" over and over again. [SOLVED]
Replies: 14
Views: 12370

Re: L2TP VPN "L2TP UDP packet received from" over and over again. [SOLVED]

Yup, that will also work as OpenVPN on MT is TCP Based.

I just prefer SSTP over O-VPN as SSTP uses port 443, less chance of ISP's blocking it.
by CZFan
Thu Apr 11, 2019 9:43 pm
Forum: Forwarding Protocols
Topic: MikroTik and Cisco ASA
Replies: 5
Views: 3333

Re: MikroTik and Cisco ASA

One suggestion will be to not use NATing between proxy / ASA / MT, but rather routing and only NAT out on MT
by CZFan
Thu Apr 11, 2019 9:04 pm
Forum: General
Topic: L2TP VPN "L2TP UDP packet received from" over and over again. [SOLVED]
Replies: 14
Views: 12370

Re: L2TP VPN "L2TP UDP packet received from" over and over again. [SOLVED]

You can use certs with SSTP between MT's, but it is not required. My point was you can quickly test it without creating certs etc. if it works better, then implement with certs
by CZFan
Thu Apr 11, 2019 7:53 pm
Forum: General
Topic: L2TP VPN "L2TP UDP packet received from" over and over again. [SOLVED]
Replies: 14
Views: 12370

Re: L2TP VPN "L2TP UDP packet received from" over and over again. [SOLVED]

UDP not good for unstable links, maybe try a TCP based site to site VPN, i.e. SSTP bwteen MT's, don't need certs in this case
by CZFan
Wed Apr 10, 2019 3:18 am
Forum: Wireless Networking
Topic: Some wireless questions
Replies: 5
Views: 1621

Re: Some wireless questions

Thx for your response, and I might very well be wrong and please correct me if I am wrong My understanding is that it is 897Mb/s air rate (radio) and should be able E to get 450 - 500 Mb/s data rate. I did some more reading, and it seems like with the equipment used for the link and due to short dis...
by CZFan
Tue Apr 09, 2019 9:10 pm
Forum: Wireless Networking
Topic: Some wireless questions
Replies: 5
Views: 1621

Re: Some wireless questions

Bump, anyone, please?
by CZFan
Mon Apr 08, 2019 9:00 pm
Forum: Wireless Networking
Topic: Some wireless questions
Replies: 5
Views: 1621

Some wireless questions

Hi Have a PTP link (2 x LHG 5ac's) connected but not too happy re performance which I am sure is due to my limited knowledge on wireless and asking for some help. The distance between the devices is about 500m with clear line of sight, both devices are on ROS 6.44.1. I if I can get the link to push ...
by CZFan
Mon Apr 08, 2019 3:52 pm
Forum: General
Topic: Filter Rules - Output showing activity, why?
Replies: 4
Views: 1244

Re: Filter Rules - Output showing activity, why?

cause your rules are incorrect: Forward chain, you have dst address list which should work ok, but should really be src address list input chain, again you have dst address list, this will never work as you should not have any China IPs as per address list on your router, so should also be src addre...
by CZFan
Sat Apr 06, 2019 9:59 pm
Forum: General
Topic: SIP port(s)
Replies: 6
Views: 1531

Re: SIP port(s)

I want mind to grind coffee beans. They should call it the cAPpuccinoAC

:lol: :lol: :lol: :lol:
by CZFan
Sat Apr 06, 2019 2:37 am
Forum: Beginner Basics
Topic: PPTP Issues
Replies: 13
Views: 2669

Re: PPTP Issues

If you coming with a Windows client behind a NAT and L2TP/IPSec server is also behind a NAT, have a look at this, it solved my problem:

https://support.microsoft.com/en-gb/hel ... in-windows
by CZFan
Fri Apr 05, 2019 5:54 pm
Forum: The User Manager
Topic: HEX S - User Manager (Will it be enough)
Replies: 4
Views: 6054

Re: HEX S - User Manager (Will it be enough)

Would you use a Mini to transport the local school rugby / soccer team to a game?

The Hex S is a SOHO device, that is an acronym for "Small Office / Home Office", do you think what you are trying to do fits in there?
by CZFan
Thu Apr 04, 2019 11:12 am
Forum: Announcements
Topic: v6.44.2 [stable] is released!
Replies: 67
Views: 37121

Re: v6.44.2 [stable] is released!

Hi Emils,

Is this fix related to recent vulnerability issue that were going to go public on 9 April?
by CZFan
Mon Apr 01, 2019 4:03 am
Forum: Wireless Networking
Topic: Alignment Mode : How to use
Replies: 5
Views: 15509

Re: Alignment Mode : How to use

Is this functionality still working? I have 2 lhg 5ac devices, link is up in bridged ptp config currently syncing at 400Mbps, but when I try this, I get nada. no sounds on station side, no info in Winbox on station side. All I get is customer screaming at me every time I do this as the link between ...
by CZFan
Mon Apr 01, 2019 1:43 am
Forum: Announcements
Topic: v6.44.1 [stable] is released!
Replies: 85
Views: 50559

Re: v6.44.1 [stable] is released!

Thx @mkx, @pe1chl for the info. Have over 1000 of these deployed in user homes (FTTx Deployment), so if things go wrong, not easy to get physical access to these plus user / client downtime. There was a time when I still had hair, when all jumped ship from Novell (had a very soft spot for Novell) to...
by CZFan
Sun Mar 31, 2019 4:28 am
Forum: Beginner Basics
Topic: WLAN - Users from LDAP and dynamic VLANs
Replies: 1
Views: 805

Re: WLAN - Users from LDAP and dynamic VLANs

IIRC, MT does not support dynamic VLAN's
by CZFan
Sun Mar 31, 2019 12:18 am
Forum: Announcements
Topic: v6.44.1 [stable] is released!
Replies: 85
Views: 50559

Re: v6.44.1 [stable] is released!

uninstall tr069 package, remove everything from /files, upgrade only routeros, after suiccessful upgrade install tr069 again Yes, if it was a device at my home, no issues, but now I must go do that on over 1000 devices at client site? WTF is it even necessary to do that, I am a patient person, been...
by CZFan
Sat Mar 30, 2019 11:59 pm
Forum: Announcements
Topic: v6.44.1 [stable] is released!
Replies: 85
Views: 50559

Re: v6.44.1 [stable] is released!

@CZFan, @gdelacruz: is there anything in the log about upgrading (or its failure)? When I try to uninstall the packages that are disabled, I get error, cant uninstall bundled package Have over 1000 of these devices deployed at 1 client only Log info after trying to upgrade: 23:46:30 system,info ins...
by CZFan
Sat Mar 30, 2019 3:16 pm
Forum: Announcements
Topic: v6.44.1 [stable] is released!
Replies: 85
Views: 50559

Re: v6.44.1 [stable] is released!

unfortunately my MT is not upgrading to 6.44 from 6.43.12. i am using the upgrade tool from winbox. downloading and reboot but it does not change at all... pls. advise .. using RB952Ui-5ac2nD.. thanks Having the same problem on 1 device, trying to upgrade from 6.43.8 to 6.44.1, it downloads it, reb...
by CZFan
Fri Mar 15, 2019 8:51 pm
Forum: Announcements
Topic: v6.44.1 [stable] is released!
Replies: 85
Views: 50559

Re: v6.44.1 [stable] is released!

Hi all,
I noticed since 6.44 and now 6.44.1 some neighbors are displayed without their IP address.. is there a solution?

My guess will be those devices do not have an IP on the interface reported on.
by CZFan
Fri Mar 15, 2019 3:29 pm
Forum: Announcements
Topic: v6.44.1 [stable] is released!
Replies: 85
Views: 50559

Re: v6.44.1 [stable] is released!

Updated hAP AC2 and CCR1009 from 6.44 to 6.44.1 I am seeing a lot of dropped Forwarded packets as INVALID. These are packets that should have hit the New connection from a local device in the address list. But are getting dropped. Also ... Updated my Hap AC^2, also getting lots of invalids dropped,...
by CZFan
Thu Mar 14, 2019 2:03 pm
Forum: Announcements
Topic: Statement on Vault 7 document release
Replies: 92
Views: 85425

Re: Statement on Vault 7 document release

upgrade ≠ reset configuration

On upgrade system files are replaced with new ones.

You are using the wrong symbol to explain to IT people, should use "!=" instead, then they will better understand :-)
by CZFan
Wed Mar 13, 2019 6:57 am
Forum: General
Topic: Why (not) use Hairpin NAT
Replies: 28
Views: 10299

Re: Why (not) use Hairpin NAT

So I missed this thread when it was new, but it's not too late to disagree now - hairpin NAT is awesome! ;) Ok, that was just to even things out a little. Reality is that haipin NAT should be unnecessary and by long time obsolete hack from old IPv4 + NAT times that were supposed to end years ago. U...
by CZFan
Mon Mar 11, 2019 1:35 pm
Forum: General
Topic: Is it possible to use remote log server over Mikrotik to Mikrotik SSTP VPN?
Replies: 1
Views: 580

Re: Is it possible to use remote log server over Mikrotik to Mikrotik SSTP VPN?

Will have to configure routing, make sure FW's do not block this traffic between sites and ensure your syslog server accepts from these IP's, that should be all
by CZFan
Sat Mar 09, 2019 1:02 am
Forum: Announcements
Topic: v6.44 [stable] is released!
Replies: 218
Views: 97290

Re: v6.44 [stable] is released!

Hi Since the last update we have had multiple clients complaining about existing sites where VoIP experiences issues, from de-registration, no audio, one way audio. Currently we downgrading the clients back to 6.43.8 which works. I've sent multiple supouts and support tickets to Support with no fee...
by CZFan
Fri Mar 01, 2019 5:34 pm
Forum: General
Topic: Drop traffic between two different vlans that are on the same interface
Replies: 10
Views: 1809

Re: Drop traffic between two different vlans that are on the same interface

Trafic that you are trying to avoid in your ping command is not for the forward chain, is for the input chain. If you do not want users on vlanx communicate with the interface of the VLANy on the router , you need to block the traffic on the input chain. Regards. What you said makes no sense to me....
by CZFan
Fri Mar 01, 2019 3:40 pm
Forum: RouterBOARD hardware
Topic: CRS328 SFP+ Port Flapping
Replies: 6
Views: 2926

Re: CRS328 SFP+ Port Flapping

Just thinking, I have a CRS326, up time currently reported as 51d12h, have zero downtime / flaps on SFP+ port.

Are the flaps not maybe caused by the other side?
by CZFan
Tue Feb 26, 2019 12:15 pm
Forum: Beginner Basics
Topic: Packet Routing Help
Replies: 2
Views: 963

Re: Packet Routing Help

I think it will be best for you to engage with a Mikrotik Consultant in your local area

https://mikrotik.com/consultants
by CZFan
Tue Feb 26, 2019 12:23 am
Forum: General
Topic: Fasttrack and Simple Queue
Replies: 8
Views: 16116

Re: Fasttrack and Simple Queue

For the Qs to correctly match both directions you need to add the following rule before fast track rule:
chain=forward action=accept connection-state=established,related dst-address-list=alist_to_s-queue log=no log-prefix=""
by CZFan
Fri Feb 22, 2019 3:17 pm
Forum: RouterBOARD hardware
Topic: SFP in SFP+ question
Replies: 2
Views: 1149

Re: SFP in SFP+ question

I had to change the link sync to manual with every SFP module in SFP+ ports, this was on CCR1036, CCR1072 & CRS326 IIRC

Also, I think they do state that in the manual
by CZFan
Mon Feb 18, 2019 12:14 am
Forum: Beginner Basics
Topic: RB2011 slow internet even with fasttrack [SOLVED]
Replies: 104
Views: 43314

Re: RB2011 slow internet even with fasttrack [SOLVED]

If I may ask, what device is this ISP modem, make, model, etc?
by CZFan
Sun Feb 17, 2019 4:37 pm
Forum: Beginner Basics
Topic: RB2011 slow internet even with fasttrack [SOLVED]
Replies: 104
Views: 43314

Re: RB2011 slow internet even with fasttrack [SOLVED]

Maybe you should approach your ISP?
by CZFan
Sat Feb 16, 2019 12:35 am
Forum: The Dude
Topic: SNMP not stable across bridged wireless link
Replies: 1
Views: 2812

SNMP not stable across bridged wireless link

I am monitoring about 40 devices using the Dude. Have 3 devices that are across a bridged wireless PTP link. For any devices on the other side of this wireless link, I get every now and then (intermittent) SNMP timeouts and with that false notifications. Have done the normal checks, etc, i.e. CPU lo...
by CZFan
Fri Feb 15, 2019 11:52 pm
Forum: General
Topic: NEW Public Bandwith Test Server
Replies: 56
Views: 80279

Re: NEW Public Bandwith Test Server

It's almost like Mikrotik should run one

Please forward the bandwidth test link for Cisco, Juniper, Huawei, Zyxel, TP-Link, ....
by CZFan
Tue Feb 12, 2019 8:02 pm
Forum: General
Topic: CRS109-8G Crashes/reboots often
Replies: 19
Views: 4401

Re: CRS109-8G Crashes/reboots often

Yes, the wireless radios draw quit a bit of power.

It sounds as if the CRS109 meets your requirements, if that is the case, and it was me, I will buy the correct power supply, add a virtual WLan and voila, you have 2 x SSIDs
by CZFan
Tue Feb 12, 2019 6:42 pm
Forum: General
Topic: DHCP Client brige l2tp tunnel [SOLVED]
Replies: 12
Views: 5516

Re: DHCP Client brige l2tp tunnel [SOLVED]

You need to remove WLAn from bridge and add L2TP interface to bridge on L2TP client side, i.e. on your AP, the server side should be done dynamically of configured correctly. You DHCP client should also be bound to L2TP client interface i need wifi clients to get ip from dhcp server from ether2 Ok,...
by CZFan
Tue Feb 12, 2019 6:35 pm
Forum: General
Topic: Cisco style Q in Q tunnels
Replies: 2
Views: 1236

Re: Cisco style Q in Q tunnels

Topic below might get you started:

viewtopic.php?t=135504
by CZFan
Mon Feb 11, 2019 11:14 pm
Forum: General
Topic: DHCP Client brige l2tp tunnel [SOLVED]
Replies: 12
Views: 5516

Re: DHCP Client brige l2tp tunnel [SOLVED]

You need to remove WLAn from bridge and add L2TP interface to bridge on L2TP client side, i.e. on your AP, the server side should be done dynamically of configured correctly.
You DHCP client should also be bound to L2TP client interface
by CZFan
Mon Feb 11, 2019 9:12 pm
Forum: General
Topic: CRS109-8G Crashes/reboots often
Replies: 19
Views: 4401

Re: CRS109-8G Crashes/reboots often

... But... Before making this upgrade I've made another observation: when my phones are turned off and my laptop is docked (networ connection via ethernet port) - everything works seamlessly. I've transferred over 10GB of data and nothing happened. As soon as I've turned on my phone and played some...
by CZFan
Sun Feb 10, 2019 9:29 pm
Forum: Beginner Basics
Topic: RB2011 slow internet even with fasttrack [SOLVED]
Replies: 104
Views: 43314

Re: RB2011 slow internet even with fasttrack [SOLVED]

Well done, glad I could help. FYI, IIRC, that is exactly what I achieved with my 2011, 812Mb/s The link you posted to the firewall config, I just did a quick scan through it and off the bat it looks over complicated for many environments, I will also be weary of the following 2 rules as generally yo...
by CZFan
Sun Feb 10, 2019 8:58 pm
Forum: Beginner Basics
Topic: Cloud Router Switch administration [SOLVED]
Replies: 11
Views: 3375

Re: Cloud Router Switch administration [SOLVED]

And here I thought SBC = Small Business Community :-) Yes, run the device in Router OS, not Switch OS Depend on what you want to do when accessing the devices, the easiest will be to use VPN, then you become part of the internal network and can access the devices. I do not think using different DNS ...
by CZFan
Sun Feb 10, 2019 6:17 pm
Forum: Beginner Basics
Topic: RB2011 slow internet even with fasttrack [SOLVED]
Replies: 104
Views: 43314

Re: RB2011 slow internet even with fasttrack [SOLVED]

Generic, home use FW rules for me are: (With fwd chain rules first) 1. Drop invalid, fwd chain 2. accept Fastrack, fwd chain, est, rel 3. accept fwd chain, est, rel 4.allow new from lan, fwd chain 5. allow dst nat, in wan, connection new, fwd chain 6. drop all fwd chain Then use similar for Input ch...
by CZFan
Sun Feb 10, 2019 2:32 pm
Forum: Beginner Basics
Topic: RB2011 slow internet even with fasttrack [SOLVED]
Replies: 104
Views: 43314

Re: RB2011 slow internet even with fasttrack [SOLVED]

Back in the times I had a 1Gb internet, my one son (Serious gamer) was living with us and he paid for the link. This is not the case anymore, he has moved out, moved the 1Gb link with him, so now I have a measly 40/20 fibre link so will not prove anything anymore unfortunately.
by CZFan
Sun Feb 10, 2019 2:21 pm
Forum: General
Topic: L2TP/IPsec multiple client connections problem
Replies: 7
Views: 16173

Re: L2TP/IPsec multiple client connections problem

Thanks pe1chl for clarifying. I wish there is a way to like a reply when someone provides a solution or the correct answer.
..

There is, click the "Accept this answer" (green tick) on post that provided solution
by CZFan
Sun Feb 10, 2019 2:09 pm
Forum: Beginner Basics
Topic: Cloud Router Switch administration [SOLVED]
Replies: 11
Views: 3375

Re: Cloud Router Switch administration [SOLVED]

I think for 100Mb internet link, CRS328-4C-20S-4S+RM will suffice, but also note that the CRS328-4C-20S-4S+RM is mainly a Fibre switch, i.e. mainly for connecting fibre cables. It does have 4 x combo ports and you will need to buy modules for these ports in order to use UTP. From your explanation, a...
by CZFan
Sun Feb 10, 2019 12:21 am
Forum: General
Topic: Slow ethernet speeds with hAP AC
Replies: 1
Views: 795

Re: Slow ethernet speeds with hAP AC

I think the more relevant question is why do you want to make a "Router" do "Switching" function?

To use another analogy, there is a difference between cars and buses for specific reasons.
by CZFan
Sat Feb 09, 2019 11:37 pm
Forum: Beginner Basics
Topic: RB2011 slow internet even with fasttrack [SOLVED]
Replies: 104
Views: 43314

Re: RB2011 slow internet even with fasttrack [SOLVED]

I have managed to get ~ 850Mb/s with RB2011, using NAT (No PPPoE). About a year ago, the RB2011 retired to my lab area and has been replaced with a HAP AC2 and I no longer have a 1Gb/s Internet link.

Why do you not start by providing your full config, and we can make suggestions?
by CZFan
Sat Feb 09, 2019 11:17 pm
Forum: Beginner Basics
Topic: QoS Tree VoIP problem
Replies: 42
Views: 9653

Re: QoS Tree VoIP problem

You dont have to spend all that money for a 4011, just keep the CRS109 as a "switch only" and add a Mikrotik hEX for the "Routing".
by CZFan
Sat Feb 09, 2019 11:10 pm
Forum: Beginner Basics
Topic: Cloud Router Switch administration [SOLVED]
Replies: 11
Views: 3375

Re: Cloud Router Switch administration [SOLVED]

Based on limited info in this thread, it seems you have gone the wrong way around purchasing hardware before understanding what is available and what will meet your requirements. It will be difficult to answer accurately without knowing what your internet link size / speed, what routing protocols ar...
by CZFan
Sat Feb 09, 2019 7:35 pm
Forum: Beginner Basics
Topic: Cloud Router Switch administration [SOLVED]
Replies: 11
Views: 3375

Re: Cloud Router Switch administration [SOLVED]

Hi all, Last night I purchased CRS328-4C-20S-4S+RM switch. .... My intention is to drop ISP router at some point as I manage to grasp sufficient knowledge with this device. ... Thank you kindly Please keep in mind, this device is a switch, with some routing capabilities. So depending on your intern...
by CZFan
Sat Feb 09, 2019 7:21 pm
Forum: General
Topic: CRS109-8G Crashes/reboots often
Replies: 19
Views: 4401

Re: CRS109-8G Crashes/reboots often

... But... Before making this upgrade I've made another observation: when my phones are turned off and my laptop is docked (networ connection via ethernet port) - everything works seamlessly. I've transferred over 10GB of data and nothing happened. As soon as I've turned on my phone and played some...
by CZFan
Mon Feb 04, 2019 12:40 am
Forum: General
Topic: Define SIP in PPPoE
Replies: 5
Views: 1892

Re: Define SIP in PPPoE

Will it not be easier to allow SIP traffic only to the SIP providers you / building management approves of with Address Lists?
by CZFan
Sun Feb 03, 2019 1:24 am
Forum: Beginner Basics
Topic: Ping 8.8.8.8 ko but ping 8.8.4.4 ok...!
Replies: 13
Views: 5506

Re: Ping 8.8.8.8 ko but ping 8.8.4.4 ok...!

I suspect the problem is not on your router config, but higher up the chain.

Do a trace route (Tools-->Traceroute) to 8.8.8.8 to see where it times out
by CZFan
Wed Jan 30, 2019 12:40 am
Forum: SwOS
Topic: 2 untagged VLAN same interface
Replies: 11
Views: 5760

Re: 2 untagged VLAN same interface

If I understand the OP correctly, the closest you will get to this is called hybrid vlan config. This is where you have a port configured for vlan trunking i.e. tagged vlan (vlan 10 as ex) and same port also configured as an access port for vlan 20 untagged
by CZFan
Mon Jan 28, 2019 11:43 pm
Forum: Beginner Basics
Topic: Traffic Forwarding
Replies: 16
Views: 2520

Re: Traffic Forwarding

Intra-Vlan is 2 hosts communicating on same Vlan (layer 2) Inter-Vlan is 2 hosts communication on different Vlans (Layer 3) Apologies, I just recalled sindy's post re vlan filtering disables HW Offload, hence you need to use switch vlan config in this case The point I was trying to make is that irre...
by CZFan
Mon Jan 28, 2019 10:29 pm
Forum: Beginner Basics
Topic: Traffic Forwarding
Replies: 16
Views: 2520

Re: Traffic Forwarding

I suspect there is no difference between Switch Chip Vlan config and Bridge Vlan config (Have not tested it though). My reason for thinking this is: When you have 2 ports in the same vlan on bridge vlan config, you will have HW Offload active and full port based (switched) speed between these ports,...
by CZFan
Mon Jan 28, 2019 9:56 pm
Forum: General
Topic: Don't buy Mikrotik hardware! NO SUPPORT
Replies: 23
Views: 4598

Re: Don't buy Mikrotik hardware! NO SUPPORT

Hi, I'm afraid to say this, but DON'T buy any hardware from Mikotik, NO SUPPORT AT ALL. For more than a year problem with Mikrotik WAPac and WiFi clients with broadcom chipset. Emailed a lot, given all necessary info, no results, last emails don't have any response! Have you tried Cisco's free supp...
by CZFan
Mon Jan 28, 2019 9:50 pm
Forum: General
Topic: DHCP philosophy - where/what is it best served by?
Replies: 9
Views: 2239

Re: DHCP philosophy - where/what is it best served by?

You should absolutely not push to control DNS in a Windows Active Directory environment. Not sure why you would want the headache. DNS is very important for Outlook clients for example. Do you know how to setup the resolution for Autodiscover? There are other topics no doubt too that we don't under...
by CZFan
Sun Jan 27, 2019 11:59 pm
Forum: Beginner Basics
Topic: Traffic Forwarding
Replies: 16
Views: 2520

Re: Traffic Forwarding

IIRC, I tested this on my 2011 a while back, with a single bridge, HW offload was active / enabled
by CZFan
Sat Jan 26, 2019 7:41 pm
Forum: Beginner Basics
Topic: DNS from way of internet
Replies: 4
Views: 1028

Re: DNS from way of internet

I have not worked in detail on DNS servers for a good couple of years now, (+- 10), but IIRC do not think you can specify port numbers in DNS.

Think you will have to enter the 2nd port number i.e. 81 as part of the URL e.e. http://www.yourdnsrecord.sub-domain.domain:81
by CZFan
Sat Jan 26, 2019 5:47 pm
Forum: Beginner Basics
Topic: DNS from way of internet
Replies: 4
Views: 1028

Re: DNS from way of internet

Yes, that is working as per design. The public DNS will tell the world what address to use to get to your network. The router on your network edge then translates this to for port 80 in this case to your internal web server address as per the NAT rule you configured. So that is all the router knows ...
by CZFan
Fri Jan 25, 2019 12:17 am
Forum: Beginner Basics
Topic: Cannot ping/connect default gateway [SOLVED]
Replies: 8
Views: 5249

Re: Cannot ping/connect default gateway [SOLVED]

From reading OP, should just work, as you will have DAC routes added dynamically.which should allow comms between these

Best is provide the output of: /export file=myconfig hide-sensitive and pas this here between the code brackets
by CZFan
Thu Jan 24, 2019 3:53 pm
Forum: Wireless Networking
Topic: PPPoE Possible MTU Issues
Replies: 5
Views: 1836

Re: PPPoE Possible MTU Issues

If speed varies, then I doubt it is ethernet syc related. Majority of problems experienced with MPLS, etc is usually MTU related, but what I would suggest is go and have a cup of coffee with the client, then test from his connection and capture / sniff some packets to see if any excessive fragmentat...
by CZFan
Wed Jan 23, 2019 2:53 pm
Forum: RouterBOARD hardware
Topic: Can the hAP ac² act as a router? [SOLVED]
Replies: 3
Views: 2488

Re: Can the hAP ac² act as a router? [SOLVED]

Hello, can the hAP ac² act as a router instead of an access point? I want it to act as a DHCP server and use firewall nat rules.

Exactly what it is designed for
by CZFan
Tue Jan 22, 2019 11:14 pm
Forum: Wireless Networking
Topic: PPPoE Possible MTU Issues
Replies: 5
Views: 1836

Re: PPPoE Possible MTU Issues

Can you provide a diagram of network, note on drawing where client is and where data is that he is downloading?

Just want to see where the possible problem areas might be
by CZFan
Tue Jan 22, 2019 10:25 pm
Forum: Wireless Networking
Topic: PPPoE Possible MTU Issues
Replies: 5
Views: 1836

Re: PPPoE Possible MTU Issues

Have you checked the client's Ethernet sync speed?
by CZFan
Sun Jan 20, 2019 6:37 pm
Forum: Beginner Basics
Topic: Bridges across 4011
Replies: 14
Views: 2154

Re: Bridges across 4011

DHCP broadcast, request, etc is layer 2, firewall is layer 3 of OSI model
dhcp protocol is in UDP, based on IP, and using broadcast ip's when necessary.
See https://en.wikipedia.org/wiki/Dynamic_H ... n_Protocol

True, wasn't thinking it through properly
by CZFan
Sun Jan 20, 2019 6:15 pm
Forum: Beginner Basics
Topic: Bridges across 4011
Replies: 14
Views: 2154

Re: Bridges across 4011

DHCP broadcast, request, etc is layer 2, firewall is layer 3 of OSI model
by CZFan
Sun Jan 20, 2019 6:00 pm
Forum: Beginner Basics
Topic: how to do Dynamic nat 100 private ip with /24 public ip
Replies: 10
Views: 5288

Re: how to do Dynamic nat 100 private ip with /24 public ip

Typically used when you have like lots of users / devices behind a NAT to prevent running out of port numbers (PAT) for a single IP NAT but not typically for 100 users/devices, never tested, but maybe: There a wiki for that ;-) https://wiki.mikrotik.com/wiki/Manual:IP/Firewall/NAT#1:1_mapping Not r...
by CZFan
Sun Jan 20, 2019 3:57 pm
Forum: Beginner Basics
Topic: how to do Dynamic nat 100 private ip with /24 public ip
Replies: 10
Views: 5288

Re: how to do Dynamic nat 100 private ip with /24 public ip

Typically used when you have like lots of users / devices behind a NAT to prevent running out of port numbers (PAT) for a single IP NAT but not typically for 100 users/devices, never tested, but maybe: /ip firewall nat add action=src-nat chain=srcnat out-interface-list=WAN src-address=192.168.88.0/2...
by CZFan
Sat Jan 19, 2019 6:18 pm
Forum: General
Topic: Mikrotik CRS326 6.43.8 not forwarding some L2 traffic ?
Replies: 4
Views: 1090

Re: Mikrotik CRS326 6.43.8 not forwarding some L2 traffic ?

I think you should reset device to default, test again...
by CZFan
Sat Jan 19, 2019 3:00 pm
Forum: General
Topic: rb750Gr3 keeps rebooting
Replies: 16
Views: 7412

Re: rb750Gr3 keeps rebooting

Had this before on a 951G when I did an update wrong, late, on a Friday afternoon :-(

Netinstall saved me :-)
by CZFan
Sat Jan 19, 2019 2:16 pm
Forum: General
Topic: Mikrotik CRS326 6.43.8 not forwarding some L2 traffic ?
Replies: 4
Views: 1090

Re: Mikrotik CRS326 6.43.8 not forwarding some L2 traffic ?

What is the purpose of below in your config?
/ip firewall nat
add action=masquerade chain=srcnat out-interface=bridge1 src-address=192.168.88.2-192.168.88.253
by CZFan
Sat Jan 19, 2019 1:10 pm
Forum: Beginner Basics
Topic: How do I see connected devices?
Replies: 5
Views: 57526

Re: How do I see connected devices?

Or, maybe I just had the post open on web browser for a long period before posting....
by CZFan
Fri Jan 18, 2019 11:40 pm
Forum: Announcements
Topic: Photos of towers and masts
Replies: 84
Views: 61616

Re: Photos of towers and masts

^^^^
You can pay me what you want, you will not get me on that tower :shock: :shock:
by CZFan
Fri Jan 18, 2019 11:36 pm
Forum: Beginner Basics
Topic: Your Support Please
Replies: 5
Views: 983

Re: Your Support Please

It sounds like you have duplicate MACs or IPs connected to the switch.

Will it be possible to post config of all 3 Mikrotiks here:
/export file=MT1 hide-sensitive
/export file=MT2 hide-sensitive
...
by CZFan
Fri Jan 18, 2019 10:40 pm
Forum: General
Topic: mikrotik products release dates not shown
Replies: 4
Views: 1557

Re: mikrotik products release dates not shown

might be a good idea, so you can see exactly which version/model/year the device is which you found in the back of the storeroom under all the dust or when buying a 2nd hand one
by CZFan
Fri Jan 18, 2019 10:17 pm
Forum: General
Topic: RB951G-2HnD MTU problem [SOLVED]
Replies: 14
Views: 2792

Re: RB951G-2HnD MTU problem [SOLVED]

I have a chain Cisco 4900M - Dlink DGS3620-28SC - Mikrotik RB951G. And i can ping from Cisco to Dlink's address(from RB subnet) with 1700 and df-bit, so i don't think that it is Dlink problem. Is it possible that in that RB installed old chip that doesn't support some functions? CPU Ar9344 v3.33 Up...
by CZFan
Fri Jan 18, 2019 9:16 pm
Forum: Beginner Basics
Topic: How do I see connected devices?
Replies: 5
Views: 57526

Re: How do I see connected devices?

Look at IP-->Firewall, Connections tab
by CZFan
Thu Jan 17, 2019 3:51 pm
Forum: Forwarding Protocols
Topic: RB433AH + BGP: low memory
Replies: 5
Views: 2758

Re: RB433AH + BGP: low memory

Personally I see the 4011 as a SOHO device, my minimum suggestion will be CCR1009.
by CZFan
Tue Jan 15, 2019 10:27 pm
Forum: The Dude
Topic: Read Only monitoring with The Dude
Replies: 6
Views: 4561

Re: Read Only monitoring with The Dude

.... The "read only" account does have some unexpected restriction (like can't initiate a ping, etc), .
...

If I recall correctly, think I got around this last time by adding "Test" to the read only user policy
by CZFan
Mon Jan 14, 2019 11:38 pm
Forum: Beginner Basics
Topic: OVPN Help .... 2 tunnels
Replies: 6
Views: 1580

Re: OVPN Help .... 2 tunnels

thx CZFan !!!!

it was the missing "add distance=1 dst-address=192.168.10.0/24 gateway=172.22.22.1"

regards, richard

Pleasure, glad I could help
by CZFan
Sun Jan 13, 2019 12:52 pm
Forum: RouterBOARD hardware
Topic: Router that does not sound like a Jet Engine for Home 10G Internet?
Replies: 7
Views: 3274

Re: Router that does not sound like a Jet Engine for Home 10G Internet?

the 4011 doesn’t have 2 sfp+ ports, but you can squeeze out way more than 1gbps. and it has no fans. there is one thing i don’t quite understand: 10Gbps internet connnectivity for home? this is quite an overkill square! but let’s assume you need this bw, but why’d you place the router into your liv...
by CZFan
Sun Jan 13, 2019 12:37 pm
Forum: General
Topic: CCR1036-8G-2S+with HIGH CPU load
Replies: 9
Views: 2618

Re: CCR1036-8G-2S+with HIGH CPU load

I am experiencing this on a CCR1036-12G-4S-EM, when I disable SNMP, it goes away so think it is SNMP related.

Have upgraded a couple of versions already since I originally noticed it and currently running 6.43.8 but still the same
by CZFan
Sat Jan 12, 2019 11:49 pm
Forum: General
Topic: RB2011 configuration question
Replies: 4
Views: 1095

Re: RB2011 configuration question

I think the reason for your problem firewall is not allowing L2TP/IPSec ports before the " add action=drop chain=input in-interface=pppoe-out1 " rule, which is kind off a "Drop All" rule, but only for incoming from the WAN/Internet. You need to add accept rules on input chain for...
by CZFan
Sat Jan 12, 2019 9:26 pm
Forum: General
Topic: how websites are blocked in big companies & countries
Replies: 2
Views: 1105

Re: how websites are blocked in big companies & countries

Mikrotik is not designed for this and should not be used for this.

Look into products like Sonicwall, which can inspect encrypted data and is designed for things like this
by CZFan
Sat Jan 12, 2019 9:17 pm
Forum: General
Topic: Wrong "Last Link Down Time" in Winbox
Replies: 24
Views: 10592

Re: Wrong "Last Link Down Time" in Winbox

I was able to resolve this on our workstations, it seems to be a difference in how Winbox is writing session files. If you delete the "%userprofile%\appdata\roaming\mikrotik\winbox\sessions" directory, then it all works fine again and correct link down dates are shown. We've confirmed tha...
by CZFan
Sat Jan 12, 2019 9:10 pm
Forum: General
Topic: update error - not enough disk space
Replies: 2
Views: 16451

Re: update error - not enough disk space

Use Netinstall to reformat and install ROS.

https://wiki.mikrotik.com/wiki/Manual:Netinstall
by CZFan
Sat Jan 12, 2019 9:04 pm
Forum: General
Topic: VPN Tunel (SSTP) on mikrotik ccr1009-7g-1c-1s+
Replies: 1
Views: 1134

Re: VPN Tunel (SSTP) on mikrotik ccr1009-7g-1c-1s+

What I don't see in the instructions on link you posted is installing of the client cert on Windows, you will need both CA and Client Cert. Look at the links below, maybe it will be of some help https://wiki.mikrotik.com/wiki/Manual:Interface/SSTP https://wiki.mikrotik.com/wiki/Manual:Create_Certifi...
by CZFan
Sat Jan 12, 2019 8:45 pm
Forum: General
Topic: RB2011 configuration question
Replies: 4
Views: 1095

Re: RB2011 configuration question

Is this a site-to-site VPN or road warrior (Traveling users) VPN? If road warrior setup, depending on your firewall rules, but generally there should not be any changes required on the router, but on the clients to point to new IP / FQDN. Provide full export /export file=whateverfilename hide-sensit...
by CZFan
Wed Jan 09, 2019 1:02 am
Forum: Announcements
Topic: v6.43.8 [stable] is released!
Replies: 169
Views: 83281

Re: v6.43.8 [stable] is released!

Not sure if mentioned in this thread / topic yet, but upgraded CHR with Dude running couple of days ago. Tonight I had to do some maintenance on network equipment and but could not disable notifications in the Dude. Untick all in notifications, click apply, then OK. as soon as I bounced the first ne...
by CZFan
Wed Jan 09, 2019 12:01 am
Forum: Beginner Basics
Topic: Why my network is Reachable ???
Replies: 12
Views: 2232

Re: Why my network is Reachable ???

by CZFan
Tue Jan 08, 2019 2:38 pm
Forum: General
Topic: catch-all rule block all the traffic
Replies: 7
Views: 2986

Re: catch-all rule block all the traffic

With a "Default Drop" Rule, you will typically also need to allow "new" from LAN. If you are using the router as DNS server, the the below rule should be removed as that will prevent the router from doing DNS lookups successfully and the symptom will be there is no internet acces...
by CZFan
Sun Jan 06, 2019 9:19 pm
Forum: Beginner Basics
Topic: Cant connect to new routher MikroTik 4011iGS+5HacQ2HnD
Replies: 3
Views: 924

Re: Cant connect to new routher MikroTik 4011iGS+5HacQ2HnD

Default IP range is 192.168.88.1/24, you can use 192.168.88.10/24
by CZFan
Sun Jan 06, 2019 2:52 pm
Forum: General
Topic: Temperature tolerance of RB2011UiAS-2HnD-IN [SOLVED]
Replies: 6
Views: 1999

Re: Temperature tolerance of RB2011UiAS-2HnD-IN [SOLVED]

No issues, no drops nothing, the 2011 is a little workhorse
by CZFan
Sun Jan 06, 2019 2:07 pm
Forum: General
Topic: can I NAT a L2TP server?
Replies: 4
Views: 1446

Re: can I NAT a L2TP server?

Are you using IPSec? If so, forward ports 500, 1701 & 4500

Also remember to open these ports in firewall of destination device
by CZFan
Sun Jan 06, 2019 2:04 pm
Forum: General
Topic: Temperature tolerance of RB2011UiAS-2HnD-IN [SOLVED]
Replies: 6
Views: 1999

Re: Temperature tolerance of RB2011UiAS-2HnD-IN [SOLVED]

Those temperatures are very normal. When I was using 2011, mine was constantly around +- 40, except when I did big downloads at 100 Mb/s using wifi the temp will go up to 65.
by CZFan
Sun Jan 06, 2019 1:28 pm
Forum: General
Topic: can I NAT a L2TP server?
Replies: 4
Views: 1446

Re: can I NAT a L2TP server?

Yes, use port forwarding (Destination NAT) to point to new server / ip
by CZFan
Sun Jan 06, 2019 12:28 am
Forum: Beginner Basics
Topic: Allow sending e-mail through Gmail smtp but block everything else
Replies: 3
Views: 3005

Re: Allow sending e-mail through Gmail smtp but block everything else

below is rules i use to allow mails to / from gmail. #first create address list /ip firewall address-list add address=smtp.gmail.com list=Gmail-SMTP /ip firewall filter add action=accept chain=forward comment="G-Mail SMTP" dst-address-list=Gmail-SMTP dst-port=587 out-interface-list=WAN pro...
by CZFan
Fri Jan 04, 2019 3:10 pm
Forum: Beginner Basics
Topic: FW upgrade problem - RouterBOARD 750G r2
Replies: 2
Views: 732

Re: FW upgrade problem - RouterBOARD 750G r2

With some routers you need to place the upgrade file .npk in the /flash folder, not the root. If placed in root, it will be deleted during restart
by CZFan
Fri Jan 04, 2019 2:54 pm
Forum: Wireless Networking
Topic: 30 day Turn Around Email Support Normis
Replies: 4
Views: 1282

Re: 30 day Turn Around Email Support Normis

Maybe pay for a consultant? Usually when you pay for a service, you can expect faster response times.
by CZFan
Fri Jan 04, 2019 12:35 am
Forum: General
Topic: Forwarding traffic inside the same subnet without replacing the source MAC
Replies: 4
Views: 1144

Re: Forwarding traffic inside the same subnet without replacing the source MAC

The description in the OP is also a bit confusing to me. But why not place the Cisco Meraking inside the LAN of the Miktoik router users gateway points to the Meraki, go through the Meraki to the MT Router where things get routed and NATed. Just open the necessary ports on the MT in order for the Mr...
by CZFan
Thu Jan 03, 2019 10:13 pm
Forum: General
Topic: Forwarding traffic inside the same subnet without replacing the source MAC
Replies: 4
Views: 1144

Re: Forwarding traffic inside the same subnet without replacing the source MAC

"...Because the Mikrotik replaces the source MAC address of outbound traffic with its own..."

This is not Mikrotik, but how IP & routing works
by CZFan
Thu Jan 03, 2019 6:24 pm
Forum: General
Topic: Cannot remotely connect via WinBox. [SOLVED]
Replies: 13
Views: 8074

Re: Cannot remotely connect via WinBox. [SOLVED]

Below might be reason for your problem

/tool mac-server mac-winbox set [ find default=yes ] disabled=yes
by CZFan
Thu Jan 03, 2019 5:52 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS+RM no switch settings?
Replies: 38
Views: 18005

Re: RB4011iGS+RM no switch settings?

113MB/s equates to approx 1Gb/s, and that is the interface limit
by CZFan
Thu Jan 03, 2019 5:25 pm
Forum: General
Topic: Cannot remotely connect via WinBox. [SOLVED]
Replies: 13
Views: 8074

Re: Cannot remotely connect via WinBox. [SOLVED]

Also check PC Firewall. Connection Profile might be public instead of private then windows firewall will be more restrictive
by CZFan
Wed Jan 02, 2019 12:18 pm
Forum: Beginner Basics
Topic: OVPN Help .... 2 tunnels
Replies: 6
Views: 1580

Re: OVPN Help .... 2 tunnels

Yes, you will have to tell the Garage router where 192.168.10.x network is, i.e. add route like below on Garage router

add distance=1 dst-address=192.168.10.0/24 gateway=172.22.22.1
by CZFan
Sat Dec 29, 2018 9:42 pm
Forum: General
Topic: Filtering Rules
Replies: 4
Views: 1120

Re: Filtering Rules

First thing you should do is update your router, 6.40.6 is fairly old and many security loopholes
by CZFan
Thu Dec 27, 2018 11:20 pm
Forum: General
Topic: RB3011 dropping packets unless packet sniffer running [SOLVED]
Replies: 3
Views: 1697

Re: RB3011 dropping packets unless packet sniffer running [SOLVED]

Packet sniffer disables a coupe of things, one of them is fasttrack, so try and disable fasttrack firewall rule if you have this enabled, reboot or clear all connections in firewall connections tab and test again without packet sniffer. If it resolves the problem, I will suggest you look at your fir...
by CZFan
Thu Dec 27, 2018 9:50 pm
Forum: General
Topic: Post Very good ... Thank you for that.
Replies: 3
Views: 1143

Post Very good ... Thank you for that.

What is up with these posts, someone trying to build up post count or is forum hacked?
by CZFan
Sat Dec 22, 2018 2:54 pm
Forum: Beginner Basics
Topic: network desing - 2 gateways
Replies: 2
Views: 594

Re: network desing - 2 gateways

Not sure I understand OP explanation, but this might guide you in the right way

https://wiki.mikrotik.com/wiki/Advanced ... _Scripting
by CZFan
Thu Dec 20, 2018 10:44 am
Forum: General
Topic: Vlan Routing Problem [SOLVED]
Replies: 18
Views: 3593

Re: Vlan Routing Problem [SOLVED]

There is a difference in way Vlans are configured pre and post 6.41, read below, there are also some examples which include both pre and post 6.41 config

https://wiki.mikrotik.com/wiki/Manual:S ... ivate_VLAN
by CZFan
Wed Dec 19, 2018 11:50 pm
Forum: General
Topic: problem with firewall
Replies: 1
Views: 858

Re: problem with firewall

First, you should update RouterOS, 6.34 is very old and many security loopholes. Then, there are different chains in the firewall, input, forward and output. The ones you want to focus is input (to the router) and forward (through the router) Below samples of "Drop All" rules for input and...
by CZFan
Mon Dec 17, 2018 12:15 pm
Forum: General
Topic: Using queues to limit maximum bandwidth (NOT TO EXCEED)
Replies: 14
Views: 8502

Re: Using queues to limit maximum bandwidth (NOT TO EXCEED)

Agree, at time of typing my previous post, I thought that there might be a misunderstanding between us.
by CZFan
Sun Dec 16, 2018 9:14 pm
Forum: General
Topic: Using queues to limit maximum bandwidth (NOT TO EXCEED)
Replies: 14
Views: 8502

Re: Using queues to limit maximum bandwidth (NOT TO EXCEED)

The Child Q's are created dynamically Through what feature - DHCP? Hotspot? PPP? Can you execute "/queue simple print" and show the output? Printing the list will include all dynamic queues as separate items. Through "Simple Queues". Printing only shows the parent Q, see below s...
by CZFan
Sat Dec 15, 2018 5:46 pm
Forum: General
Topic: Using queues to limit maximum bandwidth (NOT TO EXCEED)
Replies: 14
Views: 8502

Re: Using queues to limit maximum bandwidth (NOT TO EXCEED)

The Child Q's are created dynamically
by CZFan
Fri Dec 14, 2018 9:03 pm
Forum: General
Topic: Using queues to limit maximum bandwidth (NOT TO EXCEED)
Replies: 14
Views: 8502

Re: Using queues to limit maximum bandwidth (NOT TO EXCEED)

I don't agree with below, else what is the use of using PCQ? Also, the queue type setting for the parent will not have any effect if the parent has children. It looks like you have a PCQ queue set on the parent, which won't do anything. If you wish to use PCQ it has to be set on the child queues, no...
by CZFan
Fri Dec 14, 2018 8:30 pm
Forum: Beginner Basics
Topic: VLAN pass-through over router to AP
Replies: 7
Views: 2410

Re: VLAN pass-through over router to AP

You can remove the below line:
/interface bridge vlan
add bridge=bridge-iptv tagged=ether1-gateway untagged=ether10-IPTV vlan-ids=6

Then remove ether3 from bridge-local and add it to bridge-iptv.

That should be all you need to do
by CZFan
Wed Dec 12, 2018 11:25 pm
Forum: Beginner Basics
Topic: Choosing router+switch pair for home net
Replies: 7
Views: 1789

Re: Choosing router+switch pair for home net

The CRS can do wirespeed Switching, All routing (Incl Inter Vlan Traffic) goes via CPU and limited by that
by CZFan
Wed Dec 12, 2018 12:05 am
Forum: General
Topic: Brigde VLAN again [SOLVED]
Replies: 13
Views: 2457

Re: Brigde VLAN again [SOLVED]

/interface bridge port add bridge=bridge1 frame-types=admit-all ingress-filtering=yes interface=sfp2 pvid=111 add bridge=bridge1 frame-types=admit-all ingress-filtering=yes interface=sfp3 pvid=111 add bridge=bridge1 frame-types=admit-all ingress-filtering=yes interface=sfp4 pvid=111 add bridge=brid...
by CZFan
Tue Dec 11, 2018 11:37 pm
Forum: Scripting
Topic: DHCP Binding Triggers Script
Replies: 10
Views: 6093

Re: DHCP Binding Triggers Script

Good to hear. Note: you might want to run script by name, so you won't brake it in future
/system run script <name>
/system script run <name> :-)
by CZFan
Tue Dec 11, 2018 10:47 pm
Forum: Beginner Basics
Topic: Remove port from the default brige [SOLVED]
Replies: 17
Views: 16582

Re: Remove port from the default brige [SOLVED]

Yes, cause 0x2^0 + 1 x 2^1 = 2 :-)
by CZFan
Tue Dec 11, 2018 7:43 pm
Forum: Beginner Basics
Topic: Remove port from the default brige [SOLVED]
Replies: 17
Views: 16582

Re: Remove port from the default brige [SOLVED]

This is my understanding if you change from UAA to LAA: Convert the first octet from Hex to Bin, then change the 2nd-least-significant bit to 1, then convert back to Hex, i.e. B8 :69:F4:00:00:00 = 1011 1000, then change to 1011 10 1 0 back to Hex and the LAA MAC will then be BA :69:F4:00:00:00
by CZFan
Mon Dec 10, 2018 11:42 pm
Forum: Beginner Basics
Topic: sniffing tool
Replies: 1
Views: 640

Re: sniffing tool

Yes,

You can read all about it here: https://wiki.mikrotik.com/wiki/Manual:T ... et_Sniffer
by CZFan
Mon Dec 10, 2018 6:13 pm
Forum: Forwarding Protocols
Topic: no enforce-first-as in RouterOS?
Replies: 10
Views: 5792

Re: no enforce-first-as in RouterOS?

What I explained is not to remove your AS, but the downstream private AS. i.e. Client (AS65500) ---- ISP (AS200) ---- Global Net At the ISP, they will strip the "Private AS" by using "Remove-Remote-AS" and only advertise aggregate. Anyway, seems this is only related to "Priv...
by CZFan
Mon Dec 10, 2018 5:40 pm
Forum: General
Topic: CCR1009-8 switch chip vlan & access ports
Replies: 10
Views: 2612

Re: CCR1009-8 switch chip vlan & access ports

I am confused about the internet access port / vlan 112 part. Usually you will tag traffic going out, not coming in.

Can you elaborate a bit more what you are trying to achieve here, maybe confirm with the service provider how you are suppose to access internet services?
by CZFan
Mon Dec 10, 2018 4:33 pm
Forum: Forwarding Protocols
Topic: no enforce-first-as in RouterOS?
Replies: 10
Views: 5792

Re: no enforce-first-as in RouterOS?

I am new to BGP, so take with a pinch of salt. This is usually used where an ISP (Upstream provider) needs to remove clients "private AS", and one of the requirements I understand is that the client then needs to have the same routing policy as the ISP. It is a setting called "Remove-...
by CZFan
Mon Dec 10, 2018 3:16 pm
Forum: General
Topic: Incorrect firewall behavious
Replies: 13
Views: 1831

Re: Incorrect firewall behavious

... Of course people throw in drop invalid traffic and other things but if you have a drop everything else rule they will all be caught. .... My personal opinion the above is debatable, the last I checked part of the reason for dropping invalid was due to reasons that the packet might not be NATed ...
by CZFan
Mon Dec 10, 2018 3:03 pm
Forum: General
Topic: CCR1009-8 switch chip vlan & access ports
Replies: 10
Views: 2612

Re: CCR1009-8 switch chip vlan & access ports

Is internet provided as a layer 2 or layer 3 service? Currently you have it configured as layer 2.

Maybe add a diagram so we an clearly see how things are connected

Just to confirm, are you sure the CCR1009 has a switch chip, it is my understanding that only fairly old CCR1009's have switch chips
by CZFan
Mon Dec 10, 2018 12:21 am
Forum: Beginner Basics
Topic: Simple Queue does not work [SOLVED]
Replies: 5
Views: 3109

Re: Simple Queue does not work [SOLVED]

I highly doubt the above was the solution.

The queue types you mention there only changes the the queue "buffer" size, i.e. how many packets it will queue
by CZFan
Sun Dec 09, 2018 12:30 pm
Forum: Beginner Basics
Topic: Simple Queue does not work [SOLVED]
Replies: 5
Views: 3109

Re: Simple Queue does not work [SOLVED]

IP address is assigned to ether2 directly, should be assigned to bridge that ether2 is a member of
by CZFan
Thu Dec 06, 2018 11:49 pm
Forum: General
Topic: Interface-list VS firewall address-list best practices and approach?
Replies: 8
Views: 3115

Re: Interface-list VS firewall address-list best practices and approach?

Some Examples, but must use what makes sense to you,i.e.
Trusted Zone = LAN Zone
Untrusted Zone = WAN / Internet Zone
Semi Trusted Zone = DMZ Zone
etc
by CZFan
Thu Dec 06, 2018 6:32 pm
Forum: General
Topic: Interface-list VS firewall address-list best practices and approach?
Replies: 8
Views: 3115

Re: Interface-list VS firewall address-list best practices and approach?

I use a mixture of both.

As you mentioned, Interface List is like "Zone" based, "trusted", "untrusted", etc. but sometimes need to be more granular, then I use Address Lists, etc
by CZFan
Tue Dec 04, 2018 11:43 am
Forum: RouterBOARD hardware
Topic: RB3011 vs RB4011
Replies: 1
Views: 11118

Re: RB3011 vs RB4011

The only place I can see where the 3011 trumps the 4011 is you can do Vlan config in "software only " on 4011.

So the 4011 is a way better device, but will depend on what you planning to do with Vlans
by CZFan
Mon Dec 03, 2018 12:31 am
Forum: Beginner Basics
Topic: One /25 public subnet for 100 vlans without 1:1 nat?
Replies: 3
Views: 1092

Re: One /25 public subnet for 100 vlans without 1:1 nat?

Can one subnet provide addressing for many vlans without 1:1 natting? I want one vlan per customer's CPE router, but instead of each vlan having its own /30, just one /25 is used across all vlans. The reason I want to do it this way is to avoid the use of PPPoE but still keep customer's traffic sepa...
by CZFan
Sat Dec 01, 2018 10:28 pm
Forum: The Dude
Topic: How to pass parameters to a function
Replies: 10
Views: 9492

Re: How to pass parameters to a function

Any news about this feature ?
Bump
by CZFan
Fri Nov 30, 2018 11:48 pm
Forum: Beginner Basics
Topic: Routing between 2 Subnets
Replies: 22
Views: 12165

Re: Routing between 2 Subnets

Hi, I have configured several Subnets on my RB3011. All Subnets cannot see each other, it is disabled by FW-Rule. Now I would like to configure some exceptions. I have a local SIP Server on Subnet1 with IP: 192.168.1.10. Client on Subnet1 can connect correctly to the Server, but Clients on Subnet2(...
by CZFan
Tue Nov 27, 2018 11:56 pm
Forum: Beginner Basics
Topic: Routing between 2 Subnets
Replies: 22
Views: 12165

Re: Routing between 2 Subnets

NTP = Network Time Protocol makes use of port 123
by CZFan
Mon Nov 26, 2018 11:53 pm
Forum: Beginner Basics
Topic: Avoid double PAT
Replies: 5
Views: 1258

Re: Avoid double PAT

Ask ISPs to add route on CPEs to be our LAN range via the RB960.
by CZFan
Sun Nov 25, 2018 2:37 pm
Forum: General
Topic: L2TP/IPSec behind NAT
Replies: 8
Views: 4936

Re: L2TP/IPSec behind NAT

You mention "On the modem I have configured VPN passthrough - IPSec and PPTP" but trying to configure L2TP, I would assume you will need to configure L2TP passthrough on the modem, if it is not there, then it is not supported on the modem and will not work
by CZFan
Sat Nov 24, 2018 4:32 pm
Forum: General
Topic: RB2001UiAS-2HnD-in poor routing speed
Replies: 3
Views: 1042

Re: RB2001UiAS-2HnD-in poor routing speed

With my RB2011, when I changed from a 20/2 Mbps DSL link to 1000/100 Mbps fibre link, had the same issue. I added fasttrack and improved on my firewall rules and got ~850/97 Mbps through my RB2011. In my case the config was using DHCP client and not PPPoE on my router, but think with PPPoE you shoul...
by CZFan
Mon Nov 19, 2018 8:51 pm
Forum: General
Topic: How many VLANs do I need?
Replies: 8
Views: 1943

Re: How many VLANs do I need?

You dont need to complicate things with Vlans, just use separate subnets and block with firewall
by CZFan
Sat Nov 17, 2018 11:37 pm
Forum: Beginner Basics
Topic: VLAN connect to internet
Replies: 6
Views: 1061

Re: VLAN connect to internet

Why complicate things with VLAN's, just create your IPs on each interface
by CZFan
Mon Nov 12, 2018 11:43 am
Forum: Announcements
Topic: Newsletter 85
Replies: 30
Views: 24224

Re: Newsletter 85

And more LTE products with old and slow cat4 modems...I dont understand how can anyone even get more than 100mbit from this, i cant get more than 30mbit sitting next to tower, while anything else from super old mobile phone(6-7 years) to 2x cheaper routers achieve at least 2x speed if not more.. Wh...
by CZFan
Mon Nov 12, 2018 11:37 am
Forum: Beginner Basics
Topic: scrNAT'ed Trafic in the output queue?
Replies: 3
Views: 920

Re: scrNAT'ed Trafic in the output queue?

It is your router, telling the mail server that the host (Girlfriend Cell Phone) is not reachable, i.e. she has left the building
by CZFan
Thu Nov 01, 2018 10:55 pm
Forum: General
Topic: forward all traffic from one IP on all ports except 3
Replies: 1
Views: 541

Re: forward all traffic from one IP on all ports except 3

Minimum will be 2 rules, combine rules 1 and 2
by CZFan
Thu Nov 01, 2018 10:13 pm
Forum: Beginner Basics
Topic: Configure each port to its own broadcast domain (RB750Gr3)
Replies: 2
Views: 1335

Re: Configure each port to its own broadcast domain (RB750Gr3)

Don't need any bridges then, best way is to simply configure the gateway ip on each port
by CZFan
Thu Nov 01, 2018 1:19 am
Forum: Beginner Basics
Topic: 3 VLANs on WAN [SOLVED]
Replies: 7
Views: 2364

Re: 3 VLANs on WAN [SOLVED]

Remove all bridges, then add the VLAN's directly to ether 1, then create first bridge for ports 2-4 and wlan.
Then create another bridge, put eth5 and vlan14 in it
by CZFan
Sun Oct 28, 2018 7:58 pm
Forum: General
Topic: Tunnel between 2 MT where on one there is no public IP
Replies: 3
Views: 972

Re: Tunnel between 2 MT where on one there is no public IP

Do you need routed access between sites or must the be on same layer 2 network?

If routed, look at SSTP tunnel with one side that does not have public IP as a client and dial into the other site.

If you need layer 2, then look at bridge control protocol over SSTP
by CZFan
Fri Oct 26, 2018 7:38 pm
Forum: General
Topic: one to one NAT, access control [SOLVED]
Replies: 1
Views: 863

Re: one to one NAT, access control [SOLVED]

you mean something like below?
/ip firewall filter
add chain=forward in-interface=<WAN interface> dst-address=a.a.a.2 protocol=tcp port=!80,443 action=drop
by CZFan
Thu Oct 25, 2018 9:43 pm
Forum: General
Topic: RBSXTR&R11E-LTE and dual wan failover
Replies: 4
Views: 2761

Re: RBSXTR&R11E-LTE and dual wan failover

The SXT LTE is directional, so other question will be is the towers of the 2 ISP's in same location?
by CZFan
Wed Oct 24, 2018 12:51 am
Forum: General
Topic: Get VLAN list with SNMP from bridge interface
Replies: 6
Views: 3568

Re: Get VLAN list with SNMP from bridge interface

Use print oid
by CZFan
Tue Oct 23, 2018 1:32 am
Forum: General
Topic: 31 subnet - Not finding an answer to default gateway.
Replies: 23
Views: 13488

Re: 31 subnet - Not finding an answer to default gateway.

Provide export of the routes
by CZFan
Tue Oct 23, 2018 1:30 am
Forum: General
Topic: CRS125 poor throughput & low cpu load [SOLVED]
Replies: 41
Views: 8626

Re: CRS125 poor throughput & low cpu load [SOLVED]

Well - the CRS is a switch...

Use a router for routing!
Could not agree more
by CZFan
Sun Oct 21, 2018 3:33 pm
Forum: General
Topic: BTest problem
Replies: 1
Views: 600

BTest problem

Is there any known problems with BTest, I am trying ti tests on a device ,

When I do in send, it seems to work properly
When I do in receive, it shows running, but shows 0 bytes
When I do in both, then it works for only couple of seconds and then says "no such test"
BTest.JPG
by CZFan
Sun Oct 21, 2018 11:49 am
Forum: General
Topic: Mass Managing Mikrotik
Replies: 11
Views: 7369

Re: Mass Managing Mikrotik

Look into the Tr069 protocol, there are both commercial and open source applications for this
i.e.
commercial - avsystem
open source - freeacs, genieacs
by CZFan
Fri Oct 19, 2018 11:56 pm
Forum: General
Topic: EoIP config help needed
Replies: 5
Views: 1261

Re: EoIP config help needed

Your MT devices are behind a NATed device, so will not work.

You either need to put fiber routers which I suspect is ONU/ONT's, in bridge mode or configure port forwarding on them if that is possible
by CZFan
Thu Oct 18, 2018 8:23 pm
Forum: General
Topic: CRS328 how to use as real router
Replies: 1
Views: 572

Re: CRS328 how to use as real router

Please note that the CRS328-24P-4S+RM is by design a switch with routing capabilities, so routing performance might not meet expectations. As example of configuring it, create a bridge and assign ports 2 - what ever to the bridge, this will form the switch part, then port 1 which is not part of the ...
by CZFan
Thu Oct 18, 2018 3:41 pm
Forum: Beginner Basics
Topic: Can't create wireless interface
Replies: 2
Views: 1069

Re: Can't create wireless interface

HEX does not have wireless, you will have to connect a separate wifi access point
by CZFan
Wed Oct 17, 2018 11:07 pm
Forum: Beginner Basics
Topic: Hosts from 2 LAN's can't reach each other
Replies: 2
Views: 748

Re: Hosts from 2 LAN's can't reach each other

If the wlan is disabled, how can any client connect to the device via wlan?

You should remove wlan from bridge, then the clients on wlan will access the clients on LAN via layer 3. If not, you have firewall filter rules preventing this.
by CZFan
Tue Oct 16, 2018 8:15 pm
Forum: General
Topic: Routes for VPN clients.
Replies: 2
Views: 679

Re: Routes for VPN clients.

See below, old topic but I think it is still relevant

viewtopic.php?t=10405
by CZFan
Tue Oct 16, 2018 1:21 pm
Forum: Announcements
Topic: Winbox v3.18 released!
Replies: 49
Views: 206695

Re: Winbox v3.18 released!

I have logged into a 6.39.x earlier today with Winbox 3.18
by CZFan
Mon Oct 15, 2018 12:59 pm
Forum: General
Topic: Unable to get full gigabit speed on RB750Gr3
Replies: 33
Views: 21609

Re: Unable to get full gigabit speed on RB750Gr3

@OP, what do you have connected to the 750. And which ports are they connected to? Depending on how the 750r3 is configured, i.e. all switched ports will share 1Gb path, if not switched, then ports 1,3 & 5 shares 1Gb path and 2 & 4 shares another 1Gb path, so other devices might interfere w...
by CZFan
Mon Oct 15, 2018 12:43 am
Forum: General
Topic: Unable to get full gigabit speed on RB750Gr3
Replies: 33
Views: 21609

Re: Unable to get full gigabit speed on RB750Gr3

@OP, what do you have connected to the 750. And which ports are they connected to?
by CZFan
Sun Oct 14, 2018 10:08 pm
Forum: General
Topic: Unable to get full gigabit speed on RB750Gr3
Replies: 33
Views: 21609

Re: Unable to get full gigabit speed on RB750Gr3

@sindy: You're probably drinking beer not very far from me. But shh, we don't want anyone to know that we're slowly taking over the forum (maybe we can accept @CZFan as honorary member, he could be useful, he's not as much into motorcycles as I initially thought , but other things). :) O ye of litt...
by CZFan
Sun Oct 14, 2018 3:56 pm
Forum: The Dude
Topic: Monitoring a Simple Q
Replies: 1
Views: 3135

Re: Monitoring a Simple Q

Bump, anyone with info on how to monitor simple queues with Dude?
by CZFan
Sun Oct 14, 2018 2:28 pm
Forum: General
Topic: optimize FW rule by using connection-state=new ?
Replies: 6
Views: 2294

Re: optimize FW rule by using connection-state=new ?

.... I also allow echo replies (Established) since I want the pongs to my pings to be accepted. If you have VPNs, that too. Lig ang Drop the rest.
...
I will also add ICMP Type 3, Code 4 for path MTU discovery to work properly
by CZFan
Sun Oct 14, 2018 2:16 pm
Forum: General
Topic: Unable to get full gigabit speed on RB750Gr3
Replies: 33
Views: 21609

Re: Unable to get full gigabit speed on RB750Gr3

your forward rules are below the input. Francois, this is nothing but a superstition. The order of the chains ( input , output , forward ) in a table doesn't matter at all; the order of rules within the same chain does. So you can even place the rules like I1, O1, O2, F1, I2, O3, F2, F3, F4, I3, I4...
by CZFan
Sat Oct 13, 2018 4:53 pm
Forum: General
Topic: VLAN project. Need help
Replies: 6
Views: 1295

Re: VLAN project. Need help

As per the drawing of your config, your frames are coming in tagged and leaving tagged as well, which indicates the Vlans are living on other devices, so, except for management of device, you do not need Vlan interfaces on these devices. Bellow config should suffice (NB. Done from memory, not tested...
by CZFan
Sat Oct 13, 2018 4:26 pm
Forum: General
Topic: QOS/Queue Tree setup - multiple VLANS
Replies: 2
Views: 2794

Re: QOS/Queue Tree setup - multiple VLANS

I have not tested this in a VLANed scenario, but with your config I would think the below should work: Mark connections in prerouting chain without specifying any in / out interfaces, this will mark connections in both directions Then mark packets based on connection marks, again, don't specify in /...
by CZFan
Fri Oct 12, 2018 9:50 pm
Forum: Beginner Basics
Topic: Router Attack [SOLVED]
Replies: 6
Views: 2982

Re: Router Attack [SOLVED]

https://blog.mikrotik.com/security/winbox-vulnerability.html Thanks. So after that what is next step? Becouse i am still receiving report about the js:Miner-AL[pup], trying get connection to my lan Thanks in advance I had this at a new client recently, (It was the actual reason he became a client o...
by CZFan
Mon Oct 08, 2018 12:57 am
Forum: General
Topic: Unable to get full gigabit speed on RB750Gr3
Replies: 33
Views: 21609

Re: Unable to get full gigabit speed on RB750Gr3

Your firewall rules do include fasttrack rule, but your forward rules are below the input.
Move all chain=forward rules to the top, with fasttrack being the very first rule
by CZFan
Sat Oct 06, 2018 5:04 pm
Forum: General
Topic: Unable to get more than 175 IP's
Replies: 18
Views: 3415

Re: Unable to get more than 175 IP's

Change From: /ip address add address=10.0.0.1/16 comment=defconf interface= ether2-master network=10.0.0.0 To: /ip address add address=10.0.0.1/16 comment=defconf interface= bridge network=10.0.0.0 Not related, but you might also want to change from: /ip dns static add address= 192.168.88.1 name=rou...
by CZFan
Sat Oct 06, 2018 4:50 pm
Forum: General
Topic: HAP AC2 Auto negotioation
Replies: 4
Views: 1523

Re: HAP AC2 Auto negotioation

From the screenshot it looks like your AC2 is only advertising up to 100Mb Full, make sure the 1000Mb Half and Full are ticked on the "Ethernet" tab on same screen
by CZFan
Thu Oct 04, 2018 12:27 pm
Forum: General
Topic: hardware acceleration on only one bridge?
Replies: 13
Views: 3737

Re: hardware acceleration on only one bridge?

Are you sure about this? I seem to be able to transfer at wire speed across all the ports without hitting the CPU. This is NOT the case through the bridging method. I was seeing <100Mbps that way. ... Unless Mikrotik has made some design changes recently, very sure. When you go from one vlan to ano...
by CZFan
Wed Oct 03, 2018 9:37 pm
Forum: General
Topic: hardware acceleration on only one bridge?
Replies: 13
Views: 3737

Re: hardware acceleration on only one bridge?

I'm not enabling vlan filtering on the bridge. The guides I found on using the switch chip dont suggest that. Right now, port 5 and port 4 cannot see each other. If I assign a VLAN 14 interface on the hEX connected to port 5 (ie, PVID=15) it can't communicate with port 4. So Vlans are being properl...
by CZFan
Wed Oct 03, 2018 7:40 pm
Forum: The Dude
Topic: Monitoring a Simple Q
Replies: 1
Views: 3135

Monitoring a Simple Q

Hi, I am totally new to this, and not a coder of any type, and in need of some guidance on monitoring a Simple Q and getting some history of up / downloads of this Q in Dude. What I have done so far is: Created a Static Item with name of the Simple Q I want to monitor Added a link between the Router...
by CZFan
Wed Oct 03, 2018 12:39 pm
Forum: General
Topic: hardware acceleration on only one bridge?
Replies: 13
Views: 3737

Re: hardware acceleration on only one bridge?

@syadnom, did you enable "Vlan Filtering" on the bridge?

Also do a test from vlan 12 to vlan 13 and at the same time from vlan 14 to vlan 15? I suspect your results might be different then.
by CZFan
Wed Oct 03, 2018 12:22 pm
Forum: General
Topic: Quick Mount Pro Dimensions [SOLVED]
Replies: 2
Views: 730

Re: Quick Mount Pro Dimensions [SOLVED]

Bump, Any drill hole template drawings please?

Else I have to get up on the roof, disconnect everything, take measurements, go and buy / make a u-bolts, go back and install again and all this time client will be down.
by CZFan
Wed Oct 03, 2018 12:32 am
Forum: General
Topic: hardware acceleration on only one bridge?
Replies: 13
Views: 3737

Re: hardware acceleration on only one bridge?

@vecernik, not totally correct in this case.

Each port will be on a separate vlan, then any comms between these ports (VLAN's) will need to be routed which will go via cpu so HW offload will be lost
by CZFan
Wed Oct 03, 2018 12:00 am
Forum: Beginner Basics
Topic: Help - Traffic not visible in Queue Tree
Replies: 6
Views: 1362

Re: Help - Traffic not visible in Queue Tree

My comment re crystal ball, we can't help if you only post part on the info.

Re your question if passthrough=no does not work, on your 2nd post, again with only part of the config, you have passthrough =yes for every packet mark
by CZFan
Tue Oct 02, 2018 7:26 pm
Forum: General
Topic: hardware acceleration on only one bridge?
Replies: 13
Views: 3737

Re: hardware acceleration on only one bridge?

It is called "Router on a Stick", not Switch on a stick.

Depending on the number of switch chips on the device, with the Hex POE you have only 1 switch chip, so only 1 bridge with HW Offload, but i.e. on 2011, you can have 2 bridges with HW Offload as it has 2 switch chips.
by CZFan
Tue Oct 02, 2018 2:06 pm
Forum: General
Topic: Quick Mount Pro Dimensions [SOLVED]
Replies: 2
Views: 730

Quick Mount Pro Dimensions [SOLVED]

Hi, I have to buy / make some U-Bolts for the Quick Mount pro, https://mikrotik.com/product/QMP Have a client who have mounted this on a pole on the roof with cable ties, if anyone has the dimensions or a URL where I can get this it will be appreciated. I need the diameter for the holes and distance...
by CZFan
Tue Oct 02, 2018 12:50 am
Forum: Beginner Basics
Topic: RADIUS on Different Subnet
Replies: 5
Views: 1977

Re: RADIUS on Different Subnet

Off the bat, it can be 2 things, you need to add second Mikrotik route in radius as nas device, and then possible firewall rules blocking comma
by CZFan
Fri Sep 28, 2018 11:54 pm
Forum: Beginner Basics
Topic: Help - Traffic not visible in Queue Tree
Replies: 6
Views: 1362

Re: Help - Traffic not visible in Queue Tree

You forgot to post a picture of the crystal ball
by CZFan
Wed Sep 26, 2018 7:13 pm
Forum: General
Topic: Is mikrotik a good choice?
Replies: 56
Views: 10380

Re: Is mikrotik a good choice?

...

Mikrotik don't do/make directly GPON/MODEM. ...
https://mikrotik.com/product/SFPONU
by CZFan
Tue Sep 25, 2018 8:24 pm
Forum: General
Topic: Retag frames on a trunk port
Replies: 11
Views: 1720

Re: Retag frames on a trunk port

What happens to the Vlan's once it gets to the other side of Vlan 6? If they split out again according to their Vlan's, then you can look intgo Service Tag / QinQ. If the Vlan's comes from the schools, and Vlan 6 is just your uplink Vlan, won't it be better to terminate Vlan's 1 - 5 on your device, ...
by CZFan
Tue Sep 25, 2018 5:30 pm
Forum: General
Topic: Retag frames on a trunk port
Replies: 11
Views: 1720

Re: Retag frames on a trunk port

Will "Use Service Tag" not work here, i.e. you have C-Vlans 1,2,3,4&5, with S-Vlan 6

Or maybe QinQ, have Vlan 6 attached to ether2, with Vlan's 1-5 attached to vlan 6?
by CZFan
Mon Sep 24, 2018 8:02 pm
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 85756

Re: v6.43.1 [stable] and v6.43.2 [stable] is released!

Can you provide link to the documentation
Look at the very bottom of this wiki page (in the "Winbox" section).
Got it, thx.

I think it should rather be placed under headings for TX power, not right, right at the bottom of the document under some willy nilly comment about Winbox.
by CZFan
Mon Sep 24, 2018 7:40 pm
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 85756

Re: v6.43.1 [stable] and v6.43.2 [stable] is released!

Current TX Power = 0dBm
Current TX power readings are not supported for 802.11ac-capable wireless cards. That's a known (and documented!) limitation that has always been there.
My post is on the 802.11b/g/n WLAN card

Can you provide link to the documentation, want to go read up a bit more
by CZFan
Mon Sep 24, 2018 5:17 pm
Forum: Beginner Basics
Topic: PPTP behind ISP Router (NAT problem)
Replies: 12
Views: 5438

Re: PPTP behind ISP Router (NAT problem)

Any specific reasons you have Bridge ARP configured as "arp=proxy-arp"?

If not, change that to arp=enabled
by CZFan
Mon Sep 24, 2018 4:34 pm
Forum: Beginner Basics
Topic: Multi-hop/Cascading VPN
Replies: 2
Views: 712

Re: Multi-hop/Cascading VPN

Nothing strange there, just make sure your routing / policies configured properly
by CZFan
Mon Sep 24, 2018 4:21 pm
Forum: Announcements
Topic: v6.43.1 [stable] and v6.43.2 [stable] are released!
Replies: 186
Views: 85756

Re: v6.43.1 [stable] and v6.43.2 [stable] is released!

Note sure if someone has mentioned this before, if so, apologies for reposting

Current TX Power = 0dBm

board-name: hAP ac^2
model: RBD52G-5HacD2HnD
firmware-type: ipq4000L
factory-firmware: 3.43
current-firmware: 6.43.1
upgrade-firmware: 6.43.1
Current TX Power.JPG
by CZFan
Sun Sep 23, 2018 1:01 pm
Forum: Beginner Basics
Topic: Router connections
Replies: 5
Views: 1931

Re: Router connections

Hi, The S-seen reply means that "seen new connection is replied by your device" , A-assured means "the connection is trusted" , C-confirmed means "connection is confirmed by your device or firewall" , d-dst-nat , F- i think this is FIN i mean no more data from sender i...
by CZFan
Fri Sep 21, 2018 9:07 pm
Forum: Beginner Basics
Topic: VLAN configuration with RB 1100AH en CRS125
Replies: 8
Views: 2107

Re: VLAN configuration with RB 1100AH en CRS125

Yes, sorry, for management to the device itself you will need to create a vlan interface on the device
by CZFan
Fri Sep 21, 2018 8:58 pm
Forum: Beginner Basics
Topic: VLAN configuration with RB 1100AH en CRS125
Replies: 8
Views: 2107

Re: VLAN configuration with RB 1100AH en CRS125

AFAIK in the second config snippet, those vlan interfaces shoud have been created on bridge not on ether2.

...
For OP's setup, you don't need to create any VLAN interfaces on the CRS
by CZFan
Fri Sep 21, 2018 8:55 pm
Forum: Beginner Basics
Topic: VLAN configuration with RB 1100AH en CRS125
Replies: 8
Views: 2107

Re: VLAN configuration with RB 1100AH en CRS125

I don't see anywhere you are specifying tagged and or untagged (Access) ports, etc. Below is my understanding for the CRS1xx VLAN config straight from manual https://wiki.mikrotik.com/wiki/Manual:CRS1xx/2xx_series_switches_examples#Example_1_.28Trunk_and_Access_ports.29 To configure Port 1 as trunk ...
by CZFan
Thu Sep 20, 2018 3:50 pm
Forum: Beginner Basics
Topic: RB2011 slow internet even with fasttrack [SOLVED]
Replies: 104
Views: 43314

Re: RB2011 slow internet even with fasttrack [SOLVED]

Please log a call with support@mikrotik.com, inlcude reference to this post/topic
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 8