Community discussions

MikroTik App

Search found 1850 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 7
by tdw
Sun Jan 29, 2023 9:45 pm
Forum: Beginner Basics
Topic: How to run IPv6 from starlink on a mikrotik?
Replies: 16
Views: 5294

Re: How to run IPv6 from starlink on a mikrotik?

Configs posted there dont have dhcp client and gateway settings. No info what ip6 address was set for starlink interface.
As said before the WAN address and default gateway are obtained from Router Advertisments and the Mikrotik does not display these. Post your IPv6 configuration.
by tdw
Sun Jan 29, 2023 5:45 pm
Forum: Beginner Basics
Topic: How to run IPv6 from starlink on a mikrotik?
Replies: 16
Views: 5294

Re: How to run IPv6 from starlink on a mikrotik?

And logically, server address (gateway) cannot be accessible from provided prefix pool, because gateway must be somewhere in a provided prefix, usually this is 1st host. No. The prefix is a completely separate block of addresses to the 'WAN' connection from the provider. Some providers do steal the...
by tdw
Sun Jan 29, 2023 4:14 pm
Forum: Beginner Basics
Topic: How to run IPv6 from starlink on a mikrotik?
Replies: 16
Views: 5294

Re: How to run IPv6 from starlink on a mikrotik?

In IPv6 the roles and capabilities of a router and host are separated much more strictly than in IPv4, and also DHCP works slightly differently. You can only acquire an address with the DHCPv6 client if the provider supports it. DHCPv6 has no concept of a default gateway, the Add Default Route optio...
by tdw
Sun Jan 29, 2023 3:21 am
Forum: General
Topic: Mystery data
Replies: 1
Views: 336

Re: Mystery data

Post your configurations from /export hide-sensitive in a terminal window, after redacting serial number, public IPs, etc., in a code block for readbility (the '[]' icon in the menu above the text box when posting).
by tdw
Sun Jan 29, 2023 3:13 am
Forum: Beginner Basics
Topic: VLAN by MAC on CCR2004?
Replies: 9
Views: 1991

Re: VLAN by MAC on CCR2004?

I don't think the bridge firewall rules have the necessary functionality.

Using MAC addresses to control access is very dated and easily spoofed, there are more modern approaches it may be worth considering. e.g. 802.1X, LLDP voice VLAN or vendor specific DHCP options.
by tdw
Sun Jan 29, 2023 2:57 am
Forum: General
Topic: Router & Switch Upgrade and 10G SFP+ - Getting less than 1G
Replies: 4
Views: 764

Re: Router & Switch Upgrade and 10G SFP+ - Getting less than 1G

The CPU on the CRS isn't capable of handling 10Gb, use suitably powerful external devices for bandwidth testing.
by tdw
Fri Jan 27, 2023 3:37 pm
Forum: Beginner Basics
Topic: Many VLANs + DHCP Servers + hw offload ?
Replies: 4
Views: 583

Re: Many VLANs + DHCP Servers + hw offload ?

I tried using a single bridge, as suggested here https://help.mikrotik.com/docs/pages/viewpage.action?pageId=103841836#CRS1xx/2xxseriesswitchesexamples-Example2(TrunkandHybridPorts) but the problem is to assign different DHCP servers to different VLANs ( I cannot find a way to bind DHCP Server to V...
by tdw
Thu Jan 26, 2023 2:55 pm
Forum: General
Topic: Packet loss in VLAN when enabling EoIP tunnel
Replies: 2
Views: 897

Re: Packet loss in VLAN when enabling EoIP tunnel

I suspect that the L2 tunnel is just triggering an underlying issue. The VRRP configuration is incorrect - the VRRP interface should have a /32 netmask with services bound to the main (not VRRP) interface, DHCP pools on the main and backup routers should not overlap as there is no lease synchronisat...
by tdw
Wed Jan 25, 2023 2:20 pm
Forum: Beginner Basics
Topic: How to configure identical VLAN on different ports on the same bridge?
Replies: 3
Views: 2154

Re: How to configure identical VLAN on different ports on the same bridge?

So it looks like the {{sfp-sfpplus4}} needs to be a hybrid port? No, it is just that you cannot specify the same vlan-ids multiple times under /interface bridge vlans , you have to specify all of the interfaces for a particular ID at the same time. Be aware that the default bridge spanning tree set...
by tdw
Mon Jan 23, 2023 6:15 pm
Forum: General
Topic: Multiple WAN IPs - Questions?
Replies: 2
Views: 404

Re: Multiple WAN IPs - Questions?

There is no problem in having multiple src-nat rules on one router so outgoing traffic from each LAN subnet appears from a different public IP address. The question of one or more routers is more down to other things such as: Segregating managment, e.g. do the users of one LAN need management access...
by tdw
Mon Jan 23, 2023 1:36 pm
Forum: General
Topic: Certificates after restore backup
Replies: 10
Views: 1860

Re: Certificates after restore backup

To expand on post #6 you can import a CA and any intermediates generated elsewhere plus the server certificate and key. The CA and any intermediates should have the T flag, the server certificate should have the T & K flags. You can't duplicate the inbuilt certificate generation from one Mikroti...
by tdw
Sun Jan 22, 2023 4:23 pm
Forum: Beginner Basics
Topic: CAPsMAN and VLAN for guests [SOLVED]
Replies: 6
Views: 1874

Re: CAPsMAN and VLAN for guests [SOLVED]

The datapath.client-to-client-forwarding setting only applies to clients connected to the same CAP. With your settings: 1. Client A and Client B connected to the same CAP with SSID 'Mikrotik' can communicate 2. Client A and Client B connected to the same CAP with SSID 'Mikrotik Guest' cannot communi...
by tdw
Sun Jan 22, 2023 3:11 pm
Forum: Beginner Basics
Topic: CAPsMAN and VLAN for guests [SOLVED]
Replies: 6
Views: 1874

Re: CAPsMAN and VLAN for guests [SOLVED]

I have read many guides with wrong setups, without your help I would not have succeeded. Unfortunately many third-party guides and videos are incomplete or just wrong, often using outdated methods which are not applicable to newer firmware releases. The official Mikrotik help pages and old wiki pro...
by tdw
Sun Jan 22, 2023 3:45 am
Forum: Beginner Basics
Topic: MikroTik hAP lite TC Wireless client
Replies: 1
Views: 273

Re: MikroTik hAP lite TC Wireless client

Quickset should only be used for the initial configuration. You probably want CPE with Configuration Bridge and Bridge All LAN Ports as a starting point, then change settings with Winbox or Webfig. There are limitations in the 802.11 wireless protocol, these typically prevent true layer 2 bridging b...
by tdw
Sat Jan 21, 2023 11:46 pm
Forum: Beginner Basics
Topic: CAPsMAN and VLAN for guests [SOLVED]
Replies: 6
Views: 1874

Re: CAPsMAN and VLAN for guests [SOLVED]

You haven't specified which bridge the CAP should attach interfaces to, the main wireless network only works because the interfaces are (incorrectly) added to the bridge. /interface bridge port add bridge=bridge comment=defconf interface=ether2 add bridge=bridge comment=defconf interface=ether3 add ...
by tdw
Fri Jan 20, 2023 4:20 pm
Forum: General
Topic: IPv6 routing
Replies: 3
Views: 966

Re: IPv6 routing

If your provider is only issuing a single /64 you are stuck with having to resort to NAT, you need multiple subnets to route IPv6. If you have an IPv4 address which does not block IP protocol 41 you could use a free Hurricane Electric tunnel. They even support dynamic IPv4, you just need a script to...
by tdw
Wed Jan 18, 2023 6:08 pm
Forum: General
Topic: SSH server interface list
Replies: 1
Views: 277

Re: SSH server interface list

There isn't one, the SSH server listens on all interfaces. Default firewall rules have changed over time, currently they include 'drop input not from LAN interface list' which as you have found prevents access via VPN without additional rules or changes to the 'LAN' interface list. An earlier versio...
by tdw
Mon Jan 16, 2023 4:37 pm
Forum: General
Topic: EoIP split traffic [SOLVED]
Replies: 14
Views: 1520

Re: EoIP split traffic [SOLVED]

Offhand I'm not sure if multiple tunnels between the same public IP addresses will work with IPsec, the generated policies may interfere with each other so it would need testing. If you only used IPsec for the IPIP tunnel and established the EoIP tunnel between some internal IP addresses then the Eo...
by tdw
Mon Jan 16, 2023 4:06 pm
Forum: General
Topic: EoIP split traffic [SOLVED]
Replies: 14
Views: 1520

Re: EoIP split traffic [SOLVED]

Use GRE, IPIP or other IP tunnel plus routing for any subnets which are unique to a site. For any subnets which are shared across sites you are stuck with EoIP and a single gateway.
by tdw
Mon Jan 16, 2023 3:03 pm
Forum: General
Topic: EoIP split traffic [SOLVED]
Replies: 14
Views: 1520

Re: EoIP split traffic [SOLVED]

Your original question It is posible create something like split traffic? I mean that default gateway for the devices at branch offices would be the mikrotik in that office and send only internal company traffic over EoIP and Because if I need the same network on both branches are not compatible. To...
by tdw
Sat Jan 14, 2023 5:09 pm
Forum: General
Topic: RB2011 want to enable ipv6
Replies: 3
Views: 728

Re: RB2011 want to enable ipv6

Firstly for the Mikrotik to pick up the default route you need /ipv6 settings set accept-router-advertisements=yes Note the learnt default route does not appear in the IPv6 routing table. I'm not sure why you have non-default ND parameters, perhaps from earlier versions. The current defaults for tho...
by tdw
Sat Jan 14, 2023 4:07 am
Forum: General
Topic: RB2011 want to enable ipv6
Replies: 3
Views: 728

Re: RB2011 want to enable ipv6

Random blogs and videos on the Internet are often incomplete, less than optimal, or just wrong. 'Managed Address Configuration' is incorrect, it should only be enabled if you have a DHCPv6 server. 'Add Default Route' is incorrect but sometimes works, using Router Advertisments is the correct method....
by tdw
Mon Jan 09, 2023 3:10 pm
Forum: General
Topic: Certificates after restore backup
Replies: 10
Views: 1860

Re: Certificates after restore backup

Whilst the certificates and keys are stored in the .backup they will only be fully restored on the original hardware. The keys will not be restored on other hardware, even if it an identical model. (Whilst restoring a .backup on other devices is not officially supported it mostly works - you can res...
by tdw
Sat Jan 07, 2023 7:33 pm
Forum: General
Topic: DNS server binding to IP/VLAN
Replies: 9
Views: 1682

Re: DNS server binding to IP/VLAN

No, there is a single DNS server instance which listens on all local interface addresses.
by tdw
Fri Dec 23, 2022 2:43 pm
Forum: General
Topic: CRS305 Poor VLAN Performance
Replies: 20
Views: 1599

Re: CRS305 Poor VLAN Performance

It would have been helpful if you had posted the complete configuration with sensitive data redacted at the start. The issue is you have two bridges and CRS3xx only supports hardware offloading on one bridge. Ideally remove Mgmt-Bridge and configure an IP address directly on ether1 for local managem...
by tdw
Fri Dec 23, 2022 12:55 am
Forum: General
Topic: Unusable VLANS
Replies: 1
Views: 247

Re: Unusable VLANS

The add bridge=BR_VLAN ingress-filtering=no interface=sfp-sfpplus3 pvid=10 is incorrect as the interface is a member of the bond AE2. Other than that not all VLANs are distributed to all of the interfaces/bonds, you have: AE1 - 1u AE2 - 1u AE3 - 1u AE4 - 1u, 30t, 50t, 60t, 70t, 80t AE5 - 1u, 10t AE6...
by tdw
Thu Dec 22, 2022 7:52 pm
Forum: General
Topic: CRS305 Poor VLAN Performance
Replies: 20
Views: 1599

Re: CRS305 Poor VLAN Performance

What is the output of the commands /interface bridge port print and /interface bridge vlan print detail?
by tdw
Thu Dec 22, 2022 2:35 pm
Forum: General
Topic: CRS305 Poor VLAN Performance
Replies: 20
Views: 1599

Re: CRS305 Poor VLAN Performance

This should all be happening at L2 only In which case you do not need any /interface vlan entries - these provide the link between tagged VLANs in the bridge and services on the Mikrotik itself, via the implicit bridge-to-CPU port. These, plus the bridge ports having tagged=External-Bridge,... will...
by tdw
Mon Dec 19, 2022 4:09 pm
Forum: General
Topic: Recover router configuration by using SNMP?
Replies: 11
Views: 888

Re: Recover router configuration by using SNMP?

No. There are some things you can infer from SNMP such as IP addresses, routes, etc. but there is no way to determine others including firewall rules, IPsec/PPP secrets, etc.
by tdw
Mon Dec 19, 2022 3:07 pm
Forum: Beginner Basics
Topic: Default IPv6 copy/paste for SOHO use [SOLVED]
Replies: 11
Views: 2054

Re: Default IPv6 copy/paste for SOHO use [SOLVED]

All I needed to do to the above was change the WAN and LAN interface names. IPv6 interface lists would be nice :) Interface lists know nothing of higher level protocols, they can be used in IPv4 and/or IPv6 firewall rules. For info: DHCPv6 has no mechanism to obtain or provide a default gateway. Th...
by tdw
Wed Dec 14, 2022 7:24 pm
Forum: General
Topic: IPv6 no routing for clients [SOLVED]
Replies: 12
Views: 2914

Re: IPv6 no routing for clients [SOLVED]

Anyway, ARP doesn't exist as such for IPv6, as I understand it, as it is all done with ND. Yes. It appears the ISP has attached the /56 subnet directly to their end of the link, rather than routing it via a /64. Whilst it can be worked around with ND proxy or unnumbered links on equipment which sup...
by tdw
Tue Dec 13, 2022 12:49 am
Forum: General
Topic: /ip neighbor duplicate blank entry
Replies: 4
Views: 435

Re: /ip neighbor duplicate blank entry

Ubiquiti devices transmit minimal LLDP information on all interfaces, UISP uses this for the topology diagram generated data links. You can't turn it off.
by tdw
Mon Dec 05, 2022 2:57 pm
Forum: Beginner Basics
Topic: Remove Duplicate Users in PPP
Replies: 3
Views: 411

Re: Remove Duplicate Users in PPP

There is no scripting needed, with only-one=yes a user cannot establish more than one connection.
by tdw
Mon Dec 05, 2022 2:32 pm
Forum: Beginner Basics
Topic: Remove Duplicate Users in PPP
Replies: 3
Views: 411

Re: Remove Duplicate Users in PPP

If you set only-one=yes in the PPP profile used by a PPPoE or VPN server then only one connection can be established.
by tdw
Sun Dec 04, 2022 2:06 am
Forum: Beginner Basics
Topic: RB5009: Bridge filter rules help
Replies: 14
Views: 2123

Re: RB5009: Bridge filter rules help

I suspect some ISPs enforce the requirement of DHCP requests having a specific 802.1Q priority to prevent any other devices a client has from acquiring an address if misconnected directly to the WAN. Requiring a specific DHCP option in the request would be a more friendly way of them achieving this ...
by tdw
Sat Dec 03, 2022 3:36 pm
Forum: General
Topic: Windows 10 Router Advertisement leaking
Replies: 5
Views: 945

Re: Windows 10 Router Advertisement leaking

This has nothing to do with Mikrotik specifically, the same would be seen using a router from any other network vendor. It is well known that most Microsoft network drivers strip VLAN tags on ingress, so any tagged broadcast/multicast packets will also be delivered to the network stack rather than b...
by tdw
Fri Dec 02, 2022 3:45 pm
Forum: General
Topic: Number interface in snmp
Replies: 5
Views: 556

Re: Number interface in snmp

No directly. As mentioned before Mikrotik builds an index whilst enumerating interfaces - each new interface is assigned a sequentially increasing value which does not change. It is odd that the ethernet interfaces are not sequential as they would be discovered after a factory reset and cannot be re...
by tdw
Thu Dec 01, 2022 4:07 pm
Forum: General
Topic: Number interface in snmp
Replies: 5
Views: 556

Re: Number interface in snmp

The UI interface index is not the same, see what you get from /interface print oid - the final octet of the OIDs are the SNMP interface index.
by tdw
Thu Dec 01, 2022 2:22 pm
Forum: General
Topic: Number interface in snmp
Replies: 5
Views: 556

Re: Number interface in snmp

SNMP typically reports an interface index provided by the underlying OS, or from how it has built its index whilst enumerating the interfaces. There is no mechanism with SNMP to change this.
by tdw
Wed Nov 30, 2022 9:02 pm
Forum: Wireless Networking
Topic: Capsman to push bridge VLAN to CAPs [SOLVED]
Replies: 4
Views: 984

Re: Capsman to push bridge VLAN to CAPs [SOLVED]

You can configure the switch chip to make a subset of VLANs available on the ethernet ports and handle untagging, there isn't much you can do for the SFP port - maybe bridge filters. The CPU in the original hAP AC isn't great so you will only get wirespeed port-to-port throughput using the switch, i...
by tdw
Wed Nov 30, 2022 7:42 pm
Forum: General
Topic: IPv6 gateway by RA - possible?
Replies: 2
Views: 539

Re: IPv6 gateway by RA - possible?

The default IPv6 settings include forward=yes and accept-router-advertisements=yes-if-forwarding-disabled so if you are forwarding you need to set accept-router-advertisements=yes , otherwise forward=no if the Mikrotik is just an endpoint rather than router. Received router advertisments are not dis...
by tdw
Wed Nov 30, 2022 2:49 pm
Forum: General
Topic: Bonding with two PPOE interfaces from the same ISP
Replies: 2
Views: 368

Re: Bonding with two PPOE interfaces from the same ISP

Ethernet bonding is not the same as PPPoE MultiLink. Likely you want this https://wiki.mikrotik.com/wiki/Manual:M ... iple_links
by tdw
Mon Nov 28, 2022 8:53 pm
Forum: General
Topic: Possible for packet tagged "outside" switch to use pass through?
Replies: 7
Views: 765

Re: Possible for packet tagged "outside" switch to use pass through?

Per my previous post you have to explicitly add tagged port membership in /interface bridge vlan , just changing frame-types is insufficient. The switch only has tagged VLANs on combo2 . Why are you adding VLAN interfaces with an ID of 1 to various ports, it is unusual and not recommended unless you...
by tdw
Mon Nov 28, 2022 6:56 pm
Forum: General
Topic: On a clean setup with Microtik RB750Gr3 router, clients can't ping eachother
Replies: 3
Views: 337

Re: On a clean setup with Microtik RB750Gr3 router, clients can't ping eachother

If clients in the same subnet can't ping each other when connected via an unmanaged switch it has nothing to do with the Mikrotik, most likely client firewall rules.
by tdw
Mon Nov 28, 2022 4:22 pm
Forum: Wireless Networking
Topic: Capsman to push bridge VLAN to CAPs [SOLVED]
Replies: 4
Views: 984

Re: Capsman to push bridge VLAN to CAPs [SOLVED]

Set the cAP bridge vlan-filtering=no, any tagged VLANs arriving via eth1 will be available to the dynamic wlan interfaces.
by tdw
Mon Nov 28, 2022 3:02 pm
Forum: Beginner Basics
Topic: 1 bridge or 2?
Replies: 34
Views: 2470

Re: 1 bridge or 2?

A port can only be a member of one bridge.

Your description seems inconsistent, you say ether1 and ether2 are bridged but ether1 is the WAN, ether2 and ether3 have the same subnet.
by tdw
Sun Nov 27, 2022 10:57 pm
Forum: General
Topic: Possible for packet tagged "outside" switch to use pass through?
Replies: 7
Views: 765

Re: Possible for packet tagged "outside" switch to use pass through?

Is there anything else I would need to do on the switch to allow VLAN 100 to leave via the trunk? The /interface bridge vlan settings should include the interface in the tagged= list for the VLAN (assuming it's a CRS3xx using a VLAN aware bridge, CRS1xx/2xx use a different setup for hardware-offloa...
by tdw
Sun Nov 27, 2022 6:51 pm
Forum: General
Topic: Possible for packet tagged "outside" switch to use pass through?
Replies: 7
Views: 765

Re: Possible for packet tagged "outside" switch to use pass through?

1 - Yes. Use a hybrid port which supports untagged and one or more tagged VLANs, an access port is untagged only. 2 - It depends on how your public IPs are delivered. If they are a routed subnet separate from the WAN transit, or the WAN connection is PPPoE, you can simply have a public LAN/VLAN and ...
by tdw
Thu Nov 24, 2022 4:34 pm
Forum: Beginner Basics
Topic: PRTG webserver behind MK [SOLVED]
Replies: 4
Views: 750

Re: PRTG webserver behind MK [SOLVED]

Disabling Winbox completely would remove remote access. Rather than leaving accessible to the entire internet it is good practice to restrict access from a set of known addresses and/or setting up a VPN server on the Mikrotik so a VPN connection has to be established before a Winbox session can be s...
by tdw
Thu Nov 24, 2022 3:17 pm
Forum: Beginner Basics
Topic: PRTG webserver behind MK [SOLVED]
Replies: 4
Views: 750

Re: PRTG webserver behind MK [SOLVED]

Your firewall rules will drop any new incoming connections other than those from the local LAN, you need to permit connections from the WAN(s) where connection-nat-state=dstnat in addition to the dstnat rule. The firewall rules are less than optimal, ideally they should be ordered so the most freque...
by tdw
Wed Nov 23, 2022 8:38 pm
Forum: Wireless Networking
Topic: Problem with Cube60SA client 5GHz failover
Replies: 6
Views: 697

Re: Problem with Cube60SA client 5GHz failover

priority which is part of the STP "Bridge port ID" is the least significant of the selectors in the election process, "Root port path cost" is the most significant calculated from the sum of the path-cost values and usually the simplest adjustment to make to influence the active...
by tdw
Wed Nov 23, 2022 6:00 pm
Forum: Wireless Networking
Topic: Problem with Cube60SA client 5GHz failover
Replies: 6
Views: 697

Re: Problem with Cube60SA client 5GHz failover

Don't use add bridge=bridge interface=all on the station. Add the wlan60-1 and wlan1 interfaces explicitly and set the spanning tree path cost to favour the 60G interface, also make sure that the AP itself or something upstream is the root bridge.
by tdw
Mon Nov 21, 2022 6:23 pm
Forum: Beginner Basics
Topic: Bonding Questions (CRS109) [SOLVED]
Replies: 2
Views: 781

Re: Bonding Questions (CRS109) [SOLVED]

It varies depending on the Mikrotik device architecture. On CSS devices the ports are always part of the bridge. You can either assign two or more ports as a static link aggregation group or use LACP, either active or passive. From the help pages CSS610 use L2 hash https://help.mikrotik.com/docs/dis...
by tdw
Mon Nov 21, 2022 1:24 pm
Forum: General
Topic: Bonding 2 WAN interfaces for 1200Mbit
Replies: 5
Views: 1797

Re: Bonding 2 WAN interfaces for 1200Mbit

Does the modem support bonding and have you enabled it? AFAIK only some do, others support 2.5Gb on one of the ethernet interfaces instead.
by tdw
Thu Nov 10, 2022 8:55 pm
Forum: General
Topic: Yet Another ISP VLAN split [SOLVED]
Replies: 9
Views: 2197

Re: Yet Another ISP VLAN split [SOLVED]

CRS1xx/2xx devices do not support any hardware offloading when the bridge has vlan-filtering=yes . The bridge itself should be set to no and then configure the switch chip directly under /interface ethernet switch ... - see https://help.mikrotik.com/docs/pages/viewpage.action?pageId=103841835 and ht...
by tdw
Thu Nov 10, 2022 2:03 pm
Forum: Beginner Basics
Topic: SSPT and certificate use
Replies: 7
Views: 1346

Re: SSPT and certificate use

It is, if the client does not verify the server certificate chain then you are open to man-in-the-middle attacks.
by tdw
Wed Nov 02, 2022 3:58 pm
Forum: General
Topic: MT to UDM VLAN's
Replies: 3
Views: 948

Re: MT to UDM VLAN's

On the UDMSE WAN port, define the same tagged and untagged VLAN IDs that you did on the MikroTik router. You can't. On Ubiquiti gateway devices the WAN port is just a WAN port, you can't bridge other VLANs to the LAN ports. In a case where I needed to get an incoming WAN to a port on a Ubiquiti swi...
by tdw
Sun Oct 30, 2022 11:47 am
Forum: RouterBOARD hardware
Topic: How to connect via SSH to GPON SPF Module [SOLVED]
Replies: 9
Views: 11773

Re: How to connect via SSH to GPON SPF Module [SOLVED]

ah, the Rx Loss is indeed checked, but i'm unable to uncheck it, because it's grayed out. How can i uncheck this? It is a read-only value which reports the status from the SFP, you can't uncheck it. For a GPON SFP which only provide a management interface when active you have to connect it to the f...
by tdw
Fri Oct 28, 2022 10:02 pm
Forum: RouterBOARD hardware
Topic: Fastpath and Mangle rules incompatibality [SOLVED]
Replies: 7
Views: 1919

Re: Fastpath and Mangle rules incompatibality [SOLVED]

It is expected behaviour, fastpath and mangle are not compatible.
by tdw
Fri Oct 28, 2022 3:02 pm
Forum: Beginner Basics
Topic: Setting up CRS354-48G-4S+2Q+ vs CRS125-24G-1S as CAPsMAN server and other questions.
Replies: 5
Views: 608

Re: Setting up CRS354-48G-4S+2Q+ vs CRS125-24G-1S as CAPsMAN server and other questions.

Mangle and queues both require handling by the CPU so are not compatible with fasttrack or L3 hardware offload.
by tdw
Thu Oct 27, 2022 1:14 pm
Forum: Beginner Basics
Topic: Setting up CRS354-48G-4S+2Q+ vs CRS125-24G-1S as CAPsMAN server and other questions.
Replies: 5
Views: 608

Re: Setting up CRS354-48G-4S+2Q+ vs CRS125-24G-1S as CAPsMAN server and other questions.

CRS devices have low performance CPUs as they were intended as wire-speed layer 2 switches with minor use of the layer 3 services provided by the CPU, they were never intended to be high performance routers. With RouterOS 7 some CRS3xx/CRS5xx devices can now use the switch chip layer 3 hardware offl...
by tdw
Sun Oct 23, 2022 6:39 pm
Forum: General
Topic: CCR2004 - Vlans [SOLVED]
Replies: 11
Views: 1929

Re: CCR2004 - Vlans [SOLVED]

You are setting some interfaces to be both untagged with pvid=10 and pvid=20 under /interface bridge port and also tagged with tagged= under /interface bridge vlan - a bridge port should be either tagged or untagged for any particular VLAN ID. Why are you specifying a relay= setting for the DHCP ser...
by tdw
Sat Oct 22, 2022 9:41 pm
Forum: General
Topic: CCR2004 - Vlans [SOLVED]
Replies: 11
Views: 1929

Re: CCR2004 - Vlans [SOLVED]

Printing a few sections of the settings doesn't provide much useful information, post the output of /export after redacting any identifying information (serial number, public IPs, etc.)
by tdw
Tue Oct 18, 2022 8:03 pm
Forum: General
Topic: First attempt to set VLANs up
Replies: 31
Views: 2504

Re: First attempt to set VLANs up

This is strange. The Ingress filtering box is checked already: The default in RouterOS v7 is ingress-filtering=yes , but in v6 is ingress-filtering=no (I always thought it was an odd choice as in almost all cases filtering is good). As with many other settings the default values do not appear in /e...
by tdw
Mon Oct 17, 2022 1:28 am
Forum: Beginner Basics
Topic: RB50009 VLANs [SOLVED]
Replies: 4
Views: 736

Re: RB50009 VLANs [SOLVED]

You are missing the bridge itself (i.e. the intrinsic bridge-to-CPU port) as a tagged member for the new VLANs, without these there is no connection between the /interface bridge vlan IDs on trunk/access ports and the /interface vlan connected to the bridge. So in this case: /interface bridge vlan a...
by tdw
Sat Oct 15, 2022 9:22 pm
Forum: General
Topic: Bridge VLAN configuration issue.
Replies: 7
Views: 560

Re: Bridge VLAN configuration issue.

See https://help.mikrotik.com/docs/display/ ... ANandVLANs for VLAN setup examples on RB260 / CSS devices running SwOS.

The link you posted refers to setup on RB / CRS devices running RouterOS.
by tdw
Thu Oct 13, 2022 9:29 pm
Forum: General
Topic: First attempt to set VLANs up
Replies: 31
Views: 2504

Re: First attempt to set VLANs up

You are missing the bridge itself (i.e. the intrinsic bridge-to-CPU port) as a tagged member for all the VLANs except your base VLAN. Without these there is no connection between the other /interface bridge vlan IDs on trunk/access ports and the /interface vlan connected to the bridge. /interface br...
by tdw
Thu Oct 13, 2022 1:07 pm
Forum: Beginner Basics
Topic: Secure network, separate dhcp pool with vlan?
Replies: 3
Views: 639

Re: Secure network, separate dhcp pool with vlan?

It doesn't work like that. If you wish to isolate clients layer 2 / ethernet traffic you need to look at bridge horizon or port isolation, and disabling client-to-client traffic on any wireless APs. As this at the ethernet level the isolation applies to all packets, including IP - it cannot be diffe...
by tdw
Mon Oct 10, 2022 8:13 pm
Forum: General
Topic: Bridge two VLAN's
Replies: 5
Views: 678

Re: Bridge two VLAN's

The only annoying part of that is you seem to have to make a special remote pool of one and Burn an IP for the PPPOE server itself. I tried not having a PPPOE server local address but it wouldn't work .. I am guessing you have to do something fancy without it. The local PPPoE server address can be ...
by tdw
Sat Oct 08, 2022 8:41 pm
Forum: Beginner Basics
Topic: 3011 - Access Port - Untagged
Replies: 4
Views: 566

Re: 3011 - Access Port - Untagged

According to the wiki, the Mikrotik 3011 has no VLAN filtering. Or am I wrong? Where do I have to configure the 3011 untagged? /interface bridge port ? or here /interface ethernet switch vlan? It has no hardware-offloaded VLAN-aware bridge support. This is only an issue if you have significant traf...
by tdw
Sat Oct 08, 2022 6:32 pm
Forum: Beginner Basics
Topic: 3011 - Access Port - Untagged
Replies: 4
Views: 566

Re: 3011 - Access Port - Untagged

The /interface bridge vlan section, plus the pvid and vlan filtering settings under /interface bridge port , have no effect unless the bridge has vlan-filtering=yes . Do not attempt to use a VLAN-aware bridge and switch chip at the same time, and given the issues with hardware VLAN switching on devi...
by tdw
Wed Oct 05, 2022 2:40 pm
Forum: General
Topic: "Native" Untagged Vlan1 on a trunk [SOLVED]
Replies: 18
Views: 4013

Re: "Native" Untagged Vlan1 on a trunk [SOLVED]

There do not appear to be any valid bridge ports, are you using this purely as a router? If so, leave the switch settings at their default values and just attach the IP address to the bond interface: /interface vlan add interface=LAG10 name="vlan1 - Legacy" vlan-id=1 ... /interface etherne...
by tdw
Tue Oct 04, 2022 11:15 pm
Forum: General
Topic: "Native" Untagged Vlan1 on a trunk [SOLVED]
Replies: 18
Views: 4013

Re: "Native" Untagged Vlan1 on a trunk [SOLVED]

Post your configuration
by tdw
Sun Oct 02, 2022 7:37 pm
Forum: SwOS
Topic: LACP between 2 switch in SwOS
Replies: 5
Views: 2926

Re: LACP between 2 switch in SwOS

You can only have LACP to multiple switches if they implement MLAG. Not available in SwOS, but CRS3xx/CRS5xx/CCR2x16 devices running RouterOS 7 do https://help.mikrotik.com/docs/display/ ... tion+Group
by tdw
Sun Oct 02, 2022 1:29 pm
Forum: Beginner Basics
Topic: VLAN no IP via DHCP
Replies: 14
Views: 4416

Re: VLAN no IP via DHCP

If the majority of the traffic will undergo NAT or routing then the additional CPU load of VLAN-aware bridging is minimal. Using the switch chips only has a benefit for traffic between ports in the same VLAN, e.g. between a PC and NAS, other than on the very recent models which support L3 hardware o...
by tdw
Sat Oct 01, 2022 7:31 pm
Forum: Beginner Basics
Topic: VLAN no IP via DHCP
Replies: 14
Views: 4416

Re: VLAN no IP via DHCP

It looks as though when @pcunite reworked the Router-Switch-AP config some errors crept in as # L3 switching so Bridge must be a tagged member /interface bridge vlan set bridge=BR1 tagged=BR1 [find vlan-ids=80] set bridge=BR1 tagged=BR1 [find vlan-ids=90] only works if the bridge VLANs already exist...
by tdw
Sat Oct 01, 2022 5:39 pm
Forum: Beginner Basics
Topic: VLAN no IP via DHCP
Replies: 14
Views: 4416

Re: VLAN no IP via DHCP

The Mikrotik VLAN setup does have a steep learning curve, and it isn't helped by various changes which have been made to RouterOS over the years - historically you had to use a bridge per network/VLAN until VLAN-aware bridges were introduced. The main issue with your setup is you have configured the...
by tdw
Sat Oct 01, 2022 5:10 pm
Forum: Beginner Basics
Topic: CAPsMAN with vlans question [SOLVED]
Replies: 15
Views: 1956

Re: CAPsMAN with vlans question [SOLVED]

When sorting out your switch take note that CRS1xx/2xx do not support hardware-offload with a VLAN-aware bridge (i.e. where the bridge has vlan-filtering=yes ) You can use a VLAN-aware bridge but the performance will not be good, an example of the correct method to keep hardware offload is https://w...
by tdw
Tue Sep 27, 2022 3:27 pm
Forum: Scripting
Topic: l2tp,on up scripts get src.address?
Replies: 3
Views: 886

Re: l2tp,on up scripts get src.address?

Scripts are not needed, create a PPP profile including an address-list= property. Client addresses will be added to the list when the session is established, and also removed when the session terminates.
by tdw
Sun Sep 18, 2022 4:43 am
Forum: Beginner Basics
Topic: Can connect to SSTP VPN but can't interact with Windows Server
Replies: 11
Views: 2487

Re: Can connect to SSTP VPN but can't interact with Windows Server

Without seeing the configuration it is impossible to say what is wrong, post the output of /export hide-sensitive after redacting any other information such as public IP addresses. From the symptoms most likely firewall rules, VPN DNS settings. Using multiple bridges is generally not optimal as hard...
by tdw
Thu Sep 15, 2022 10:02 pm
Forum: General
Topic: Freeradius with Mikrotik !
Replies: 1
Views: 289

Re: Freeradius with Mikrotik !

Which service, as Mikrotik can use RADIUS for dhcp, dot1x, hotspot, ipsec, login, ppp and wireless. Likely you are running into a fundamental issue with RADIUS which typically needs either the credentials to be transmitted in plaintext secured by some other mechanism (e.g. TLS), or the credentials s...
by tdw
Wed Sep 14, 2022 8:01 pm
Forum: Beginner Basics
Topic: problem with multi bridge interface
Replies: 11
Views: 1471

Re: problem with multi bridge interface

As others have said you can only have a single bridge with hardware offload on your device. The D indicates the port is added dynamically, in this case from /interface bridge port add bridge=B-1 interface=static . This is generally not a good idea, add each port explicitly to the bridge. The only me...
by tdw
Mon Sep 12, 2022 6:54 pm
Forum: General
Topic: RB4011 - Missing "Flash" directory
Replies: 8
Views: 1781

Re: RB4011 - Missing "Flash" directory

I'm surprised the hotspot works at all as that configuration points to a folder which doesn't exist, given what you have posted it should have html-directory=DH-HOTSPOT for the hotspot server to use your uploaded files.
by tdw
Mon Sep 12, 2022 2:11 pm
Forum: General
Topic: allow packets to VPN client
Replies: 8
Views: 596

Re: allow packets to VPN client

If the VPN client uses an address which overlaps with the local subnet you have to enable proxy-arp so the Mikrotik replies to ARP requests from local devices on behalf of the VPN client. However, as you say you can SSH from the client on 10.1.1.200 (the VPN connection) to the server at 10.1.1.10 (o...
by tdw
Sun Sep 04, 2022 10:20 pm
Forum: General
Topic: RB4011 - Missing "Flash" directory
Replies: 8
Views: 1781

Re: RB4011 - Missing "Flash" directory

Hopefully that .backup isn't from the hEX S and been applied to the 4011 - restoring a backup from a different model often results in odd behaviour. What files are there in the DH-HOTSPOT folder, and what is HTML Directory set to under IP > Hotspot > Server Profiles (or html-directory= setting from ...
by tdw
Sun Sep 04, 2022 2:47 pm
Forum: General
Topic: RB4011 - Missing "Flash" directory
Replies: 8
Views: 1781

Re: RB4011 - Missing "Flash" directory

The default hotspot directory path is hotspot for devices with larger NAND, and flash/hotspot for smaller NOR storage. I wouldn't expect having the hotspot directory set to flash/hotspot to work on devices which don't present a flash directory unless there is a hidden symbolic link in the filesystem.
by tdw
Thu Sep 01, 2022 4:02 am
Forum: Virtualization
Topic: CHR EoIP issue
Replies: 2
Views: 2134

Re: CHR EoIP issue

From that error likely the same MAC address used at both sites. Post your configuration.
by tdw
Fri Aug 26, 2022 10:46 pm
Forum: General
Topic: L2TP / IPsec encrption algorhytm [SOLVED]
Replies: 2
Views: 787

Re: L2TP / IPsec encrption algorhytm [SOLVED]

I used https://www.ncsc.gov.uk/guidance/using-ipsec-protect-data as a reference several years ago, the legacy profile being more than suffcient for the data involved. /ip ipsec profile set [ find default=yes ] dh-group=modp2048 enc-algorithm=aes-128 hash-algorithm=sha256 /ip ipsec proposal set [ fin...
by tdw
Fri Aug 19, 2022 1:50 pm
Forum: Beginner Basics
Topic: CHR - VLAN Filtering on bridge kills access
Replies: 5
Views: 922

Re: CHR - VLAN Filtering on bridge kills access

There is certainly no problem using the default VLAN 1 untagged, e.g. if you have a working setup based on the intital configuration and then add some additional tagged VLANs on top. Using VLAN 1 tagged however is full of traps for the unwary, and a number of vendors hard-code VLAN 1 to be 'untagged...
by tdw
Mon Aug 01, 2022 5:34 pm
Forum: General
Topic: Cant get IPv6 using DHCPv6 Client
Replies: 4
Views: 3578

Re: Can get IPv6 using DHCPv6 Client

You can only acquire an address with the DHCPv6 client if the provider supports it. The most common mechanism is to use received router advertisments (RA) which unfortunately are not displayed by RouterOS, as discussed in other forum posts, and was completely broken in earler releases of RouterOS v7...
by tdw
Mon Aug 01, 2022 3:56 am
Forum: Beginner Basics
Topic: Accessing Forwarded port via A name when on network
Replies: 2
Views: 431

Re: Accessing Forwarded port via A name when on network

See https://help.mikrotik.com/docs/display/ ... HairpinNAT. Static DNS so internal and external lookps return corresponding internal and external addresses as an alternative should be fine too.
by tdw
Sun Jul 31, 2022 10:23 pm
Forum: General
Topic: Traffic that seems legit is getting dropped (due to conntrack table?)
Replies: 5
Views: 1478

Re: Traffic that seems legit is getting dropped (due to conntrack table?)

See https://forum.mikrotik.com/viewtopic.php?p=936148#p936148 * Dropped Input SYN from INPUT Those are probably normal. My guess is it comes mostly from scanners examples: ``` input: in:telekom-pppoe out:(unknown 0), proto TCP (SYN), 14.135.120.222:53950->my.public.ip:195, len 52 input: in:telekom-p...
by tdw
Fri Jul 29, 2022 7:31 pm
Forum: RouterBOARD hardware
Topic: Debugging SFP28 DAC connection between CCR2004 and Ubiquiti switch
Replies: 13
Views: 3161

Re: Debugging SFP28 DAC connection between CCR2004 and Ubiquiti switch

Do you mean forward error correction? Yes There are comments in the Ubiquiti forums suggesting it is always enabled on their devices, e.g. https://community.ui.com/questions/Feature-Request-Ability-to-adjust-FEC-settings-on-SFP28-ports/fc21e071-c832-461b-b696-e19986d4b714 There appears to be nothin...
by tdw
Fri Jul 29, 2022 4:52 pm
Forum: RouterBOARD hardware
Topic: Debugging SFP28 DAC connection between CCR2004 and Ubiquiti switch
Replies: 13
Views: 3161

Re: Debugging SFP28 DAC connection between CCR2004 and Ubiquiti switch

During testing I tried setting values on both sides by disabling auto negotation, setting the ports speed manually, enabling, disabling flow control, etc. Nothing worked. Was that just speed autonegotiation? SFP28 introduced FEC to detect and correct link errors, it needs to be the same at both ends.
by tdw
Mon Jul 25, 2022 8:50 pm
Forum: Beginner Basics
Topic: Noob starting VLANs on RB2011 and Cisco Switches
Replies: 10
Views: 2029

Re: Noob starting VLANs on RB2011 and Cisco Switches

It is somewhat unusual to configure DHCP to hand out a DNS server address in a different subnet when the Mikrotik is also the gateway for those subnets, nothing immediately obvious but could be something in the firewall rules. Does the Mikrotik obtain DNS addresses from the PPPoE client? They should...
by tdw
Sat Jul 23, 2022 8:12 pm
Forum: General
Topic: Multiple VPN connections from different IPs [SOLVED]
Replies: 6
Views: 1593

Re: Multiple VPN connections from different IPs [SOLVED]

Pools are as the name suggests are a pool / list of addresses. When an item is allocated from the pool it cannot be used by anything else until released. There are address lists and interface lists which can be used in place of hard-coded addresses or interfaces, but only in certain places such as f...
by tdw
Sat Jul 23, 2022 1:03 pm
Forum: SwOS
Topic: MNDP and LLDP (Mikrotik Network Discovery Protocol)
Replies: 5
Views: 4502

Re: MNDP and LLDP (Mikrotik Network Discovery Protocol)

MNDP is broadcast to UDP port 5678, so tcpdump -i myinterfacename -s 0 -X broadcast and udp and dst port 5678 It consists of a number of TLVs, type and length are both 16-bit network byte order, i.e. big endian. I'm not aware of any official documentation, the Wireshark dissector code https://gitlab...
by tdw
Sat Jul 23, 2022 5:10 am
Forum: SwOS
Topic: MNDP and LLDP (Mikrotik Network Discovery Protocol)
Replies: 5
Views: 4502

Re: MNDP and LLDP (Mikrotik Network Discovery Protocol)

MNDP is broadcast so visible to everything within the layer 2 network, it doesn't provide information as to where it is within the network. LLDP requires special handling as each port on a device has to transmit different information, as it includes the port identity, and the device must not forward...
by tdw
Sat Jul 23, 2022 1:26 am
Forum: General
Topic: Multiple VPN connections from different IPs [SOLVED]
Replies: 6
Views: 1593

Re: Multiple VPN connections from different IPs [SOLVED]

Probably due to using using local-address=pool_router in the PPP profiles - as the pool only contains one address the pool is them empty for subsequent connections. Use local-address=192.168.1.1 instead. Pools should not overlap, it would be wise to delete pool_router , pool_local and dhcp_pool1
by tdw
Fri Jul 22, 2022 4:49 pm
Forum: General
Topic: external Radius server and mikrotik ???
Replies: 11
Views: 4747

Re: external Radius server and mikrotik ???

Along the lines of my earlier post, the JumpCloud RADIUS Server documentation says: Device or service endpoint that supports RADIUS and either EAP-TTLS/PAP or EAP-PEAP/MSCHAPv2 authentication methods. Simple PAP may also be used, but we highly recommend you use a more secure authentication protocol ...
by tdw
Thu Jul 21, 2022 9:20 pm
Forum: General
Topic: L2 Raw packet switching
Replies: 8
Views: 821

Re: L2 Raw packet switching

Not that I am aware of. I don't imagine any other network switch would pass them either if the packets have an invalid CRC.
by tdw
Thu Jul 21, 2022 8:13 pm
Forum: General
Topic: Multiple VPN connections from different IPs [SOLVED]
Replies: 6
Views: 1593

Re: Multiple VPN connections from different IPs [SOLVED]

If the clients are not behind the same public IP address it should just work. Use /export hide-sensitive for RoS v6 or just /export for RoS v7, copy the output, remove any other sensitive or personal information (such as serial number, static public IP addresses, credentials in scripts), and post in...
by tdw
Thu Jul 21, 2022 4:21 pm
Forum: Beginner Basics
Topic: Noob starting VLANs on RB2011 and Cisco Switches
Replies: 10
Views: 2029

Re: Noob starting VLANs on RB2011 and Cisco Switches

Likely you do not have /ip dns set allow-remote-requests=yes , without this the Mikrotik will only use any supplied DNS servers to resolve requests from itself and ignore requests from anything else. Generally it is best to post the actual configuration from the device rather than the script you app...
by tdw
Thu Jul 21, 2022 3:56 am
Forum: General
Topic: L2 Raw packet switching
Replies: 8
Views: 821

Re: L2 Raw packet switching

For devices with Atheros/Qualcomm switch chips you have to use a non-VLAN-aware bridge, otherwise hardware offload / switching is disabled, and then use switch rules - see https://help.mikrotik.com/docs/display/ROS/Switch+Chip+Features#SwitchChipFeatures-RuleTable . There are specific issues with th...
by tdw
Thu Jul 21, 2022 2:31 am
Forum: General
Topic: Problems with IPv6 Connectivity with a /64 Prefix Delegation
Replies: 12
Views: 3759

Re: Problems with IPv6 Connectivity with a /64 Prefix Delegation

It is odd that the sniffer is not picking up the ICMP activity. If you use an online traceroute tool, instead of ping, how far does the trace reach?
by tdw
Wed Jul 20, 2022 9:43 pm
Forum: Beginner Basics
Topic: Can't access LAN over VPN [SOLVED]
Replies: 19
Views: 13034

Re: Can't access LAN over VPN [SOLVED]

As the VPN client uses an address from the LAN you have to enable proxy ARP on that interface (bridge1). This is so the Mikrotik can answer ARP requests from devices connected to the local LAN ethernet on behalf of the VPN client. You may wish to change your IPsec secret not having redacted it, and ...
by tdw
Wed Jul 20, 2022 5:55 am
Forum: General
Topic: Problems with IPv6 Connectivity with a /64 Prefix Delegation
Replies: 12
Views: 3759

Re: Problems with IPv6 Connectivity with a /64 Prefix Delegation

Nothing immediately obvious. If you use any online IPv6 web tools to ping AA:BB:CC:6b0::1 do you see anything with the packet sniffer on ether1 RX?
by tdw
Wed Jul 20, 2022 5:27 am
Forum: General
Topic: Problems with IPv6 Connectivity with a /64 Prefix Delegation
Replies: 12
Views: 3759

Re: Problems with IPv6 Connectivity with a /64 Prefix Delegation

I was referring to the IPv6 address being added to the LAN (interface=bridge) from the pool, not the WAN (interface=ether1) address.

If ICMP works but other traffic doesn't it suggests a firewall issue. Post the output of /ipv6 export after redacting any public IP addresses, etc.
by tdw
Wed Jul 20, 2022 4:43 am
Forum: General
Topic: Problems with IPv6 Connectivity with a /64 Prefix Delegation
Replies: 12
Views: 3759

Re: Problems with IPv6 Connectivity with a /64 Prefix Delegation

Of note is the IP assigned to the ether1 interface is not from the same /64. The pool handed out via DHCPv6 is AA:BB:CC:6b0::/64, but the IP automatically assigned when I turned on RA in the settings is AA:BB:CC:6af:DD:EE:fe05:3a04/64. When I run ping from the router it shows up as from AA:BB:CC:6a...
by tdw
Wed Jul 20, 2022 12:45 am
Forum: General
Topic: Edge router sending ARP requests out WAN interface - How to stop
Replies: 4
Views: 1323

Re: Edge router sending ARP requests out WAN interface - How to stop

Is the subnet routed to you? Do you have proxy-ARP enabled on any interfaces? An export of the configuration would help.
by tdw
Wed Jul 20, 2022 12:38 am
Forum: General
Topic: Bridged L3 VLANs
Replies: 8
Views: 971

Re: Bridged L3 VLANs

There is nothing incorrect with using VLAN 1, you just need to take care as it is the default PVID on Mikrotik bridges and bridge ports so does not appear in the export which defaults to compact . The main issues with your original config are having use-service-tag=yes , which selects an ethernet ty...
by tdw
Mon Jul 18, 2022 5:53 pm
Forum: General
Topic: three pppoe client in (switch-mikrotik) [SOLVED]
Replies: 19
Views: 2287

Re: three pppoe client in (switch-mikrotik) [SOLVED]

In the last posted configuration the interface to the switch, and onward to the WAN connections, is not in a bridge. Should be something like /interface bridge ... add name=bridge protocol-mode=none /interface bridge port add bridge=bridge interface=sfp2 /interface vlan ... add interface= sfp2 bridg...
by tdw
Fri Jul 15, 2022 6:47 pm
Forum: General
Topic: Multiple VLANs over EoIPs and LACP in bridge
Replies: 3
Views: 652

Re: Multiple VLANs over EoIPs and LACP in bridge

A single VLAN-aware bridge on each Mikrotik. Individiual physical, logical(LACP/bond) and tunnel (EoIP) interfaces as bridge ports with PVID settings and bridge port vlan membership as required. Unless you really need layer 2 connectivity between sites, which has performance implications as the traf...
by tdw
Fri Jul 15, 2022 6:31 pm
Forum: Beginner Basics
Topic: Hardware offload in 7.3.1 on Hex S
Replies: 11
Views: 3865

Re: Hardware offload in 7.3.1 on Hex S

What is your use case, do you really need layer 3 hardware offload? CRS devices have low performance CPUs as they were intended as wire-speed layer 2 switches with minor use of the layer 3 services provided by the CPU. With RouterOS 7 some CRS3xx/CRS5xx devices can now use the switch chip layer 3 ha...
by tdw
Fri Jul 15, 2022 3:23 pm
Forum: Beginner Basics
Topic: Capsman, 3 SSIDs but Hotspot only on one SSID [SOLVED]
Replies: 8
Views: 1229

Re: Capsman, 3 SSIDs but Hotspot only on one SSID [SOLVED]

It can be confusing with both the CAPsMAN and CAP on the same device. Under /caps-man datapath the bridge= setting is only used for CAPsMAN forwarding. If using local forwarding you have to set bridge= under /interface wireless cap , as this is missing it is using the manually added bridge ports for...
by tdw
Fri Jul 15, 2022 2:07 pm
Forum: Beginner Basics
Topic: Hardware offload in 7.3.1 on Hex S
Replies: 11
Views: 3865

Re: Hardware offload in 7.3.1 on Hex S

No, the page you linked to and quoted says Bridge HW vlan-filtering was added in the RouterOS 7.1rc1 (for RTL8367) and 7.1rc5 (for MT7621) versions - this only provides layer 2 / ethernet hardware offloading on a VLAN-aware bridge (previous RouterOS on these models only supported hardware offloading...
by tdw
Fri Jul 15, 2022 1:57 pm
Forum: Beginner Basics
Topic: Capsman, 3 SSIDs but Hotspot only on one SSID [SOLVED]
Replies: 8
Views: 1229

Re: Capsman, 3 SSIDs but Hotspot only on one SSID [SOLVED]

You have too many bridge port members. The wlan interface membership will be added automatically by CAPsMAN. The VLAN interfaces are already connected to the bridge, they should not added as ports. /interface bridge port add bridge=bridge comment=defconf interface=ether2 add bridge=bridge comment=de...
by tdw
Fri Jul 15, 2022 12:30 pm
Forum: Beginner Basics
Topic: Capsman, 3 SSIDs but Hotspot only on one SSID [SOLVED]
Replies: 8
Views: 1229

Re: Capsman, 3 SSIDs but Hotspot only on one SSID [SOLVED]

DHCP servers cannot be attached to child/slave interfaces but VLAN interfaces are fine, in this case the DHCP servers should be attached to the VLAN interfaces on the CAPsMAN controller. Post your current configurations - in a terminal window use /export hide-sensitive for RoS v6 or just /export for...
by tdw
Thu Jul 14, 2022 9:04 pm
Forum: Beginner Basics
Topic: Capsman, 3 SSIDs but Hotspot only on one SSID [SOLVED]
Replies: 8
Views: 1229

Re: Capsman, 3 SSIDs but Hotspot only on one SSID [SOLVED]

Use a single bridge on both the CAPsMAN controller and CAPs. Configure the datapaths for each SSID with a VLAN. Add /interface vlan to the CAPsMAN controller bridge for the corresponding VLAN IDs used in the datapath, these provide access from the bridge VLANs to services provided by the Mikrotik CP...
by tdw
Wed Jul 13, 2022 10:06 pm
Forum: General
Topic: three pppoe client in (switch-mikrotik) [SOLVED]
Replies: 19
Views: 2287

Re: three pppoe client in (switch-mikrotik) [SOLVED]

The switch connfiguration looks incorrect as VLAN 1 should not be set to untagged on ports 1, 2 or 3. You can only have one untagged VLAN on a port, not all devices enforce this in their settings so you can configure invalid setups. All three PPPoE clients are shown as running. Just creating multipl...
by tdw
Wed Jul 13, 2022 9:58 pm
Forum: General
Topic: configure wifi in router with switch chip [SOLVED]
Replies: 3
Views: 1344

Re: configure wifi in router with switch chip [SOLVED]

Under /interface ethernet switch vlan switch1-cpu passes traffic from the switch chip to the CPU, only required for VLANs connected to services provided by the CPU such as IP address, routing, DHCP server and software-based interfaces (tunnels, wireless). Under /interface ethernet switch port use vl...
by tdw
Sun Jul 10, 2022 1:03 pm
Forum: General
Topic: PowerLine PRO PL7510Gi: how to connect using winbox
Replies: 6
Views: 572

Re: PowerLine PRO PL7510Gi: how to connect using winbox

If I remember correctly that model has no user interface, all of the device control is by way of the pushbutton and PoE on/off switch. You may be able to communicate with them using the Qualcomm open-source PLC utilites, although there is no real need to.
by tdw
Fri Jul 08, 2022 1:23 pm
Forum: General
Topic: external Radius server and mikrotik ???
Replies: 11
Views: 4747

Re: external Radius server and mikrotik ???

WiFi authentication is not the issue here. The OP wanted to authenticate logins to the Mikrotik itself which requires the RADIUS server to support plain MS-CHAPv2, not encapsulated EAP
by tdw
Thu Jul 07, 2022 3:32 pm
Forum: General
Topic: VLAN on a bridge with a physical interface
Replies: 7
Views: 989

Re: VLAN on a bridge with a physical interface

There will be little difference in performance between the old-style multiple bridges and a single VLAN-aware bridge, so whilst configuring the switch chip would improve performance it may not be necessary. It is certainly possible to migrate from the old-style multiple bridges to a single bridge wi...
by tdw
Wed Jul 06, 2022 12:23 pm
Forum: Beginner Basics
Topic: Embarrassed New User VLAN Issues
Replies: 12
Views: 1246

Re: Embarrassed New User VLAN Issues

Winbox will run under Wine on Linux and macOS. Open a terminal session/window (you can either SSH to the Mikrotik or use New Terminal in Winbox, I can't remember if the web interface has an equivalent). The command /export hide-sensitive (for RouterOS 6, or just /export in RouterOS 7) generates a te...
by tdw
Sat Jul 02, 2022 3:23 pm
Forum: Beginner Basics
Topic: PPPoA with Vigor 166
Replies: 6
Views: 679

Re: PPPoA with Vigor 166

If you have more than one WAN you need mangle rules for IPv4 if doing anything other than active-backup failover. It is currently not possible have more than one IPv6 WAN connection (see the numerous form posts). If the ISP doesn't assign a fixed IP it would be unusual to be able to force one by set...
by tdw
Sat Jul 02, 2022 2:03 pm
Forum: Beginner Basics
Topic: PPPoA with Vigor 166
Replies: 6
Views: 679

Re: PPPoA with Vigor 166

Draytek modems support DSL connections, not cable which is typically DOCSIS. PPPoA is only applicable to ADSL variants as VDSL uses PTM framing instead of ATM cells. You should not have to specify the WAN address, it will be assigned during link negotiation. There are many posts in the forum regardi...
by tdw
Fri Jul 01, 2022 10:24 pm
Forum: General
Topic: Issue communicating with VLAN
Replies: 8
Views: 970

Re: Issue communicating with VLAN

You have an incomplete mix of old-style bridge-per-vlan and new-style VLAN-aware bridge. Use a single VLAN aware bridge, see the section https://help.mikrotik.com/docs/display/ ... NFiltering in the documentation
by tdw
Mon Jun 27, 2022 9:36 pm
Forum: General
Topic: Mikrotik to a TP-Link EAP660 HD, multi SSID map to VLAN
Replies: 11
Views: 2638

Re: Mikrotik to a TP-Link EAP660 HD, multi SSID map to VLAN

They can be configured standalone or with the controller, there are various manuals and guides on the TP-Link support website. You may be able to use their app to configure the device directly, otherwise connect it to a regular untagged network which has a DHCP server, find the IP address of the TP-...
by tdw
Mon Jun 27, 2022 8:25 pm
Forum: General
Topic: VLANs - use one interface as a trunk and also for the Internet access (while bridging)
Replies: 3
Views: 2031

Re: VLANs - use one interface as a trunk and also for the Internet access (while bridging)

Bridges have an implicit bridge-to-CPU port which provides access from all of the other bridge ports to IP resources (e.g. DHCP, routing, etc.) on the Mikrotik itself, see https://forum.mikrotik.com/viewtopic.php?t=173692 You need to include this port in the bridge VLAN membership /interface bridge ...
by tdw
Mon Jun 27, 2022 7:25 pm
Forum: Beginner Basics
Topic: Using Hex S as an edge router for L2TP connection
Replies: 3
Views: 580

Re: Using Hex S as an edge router for L2TP connection

You can, but it introduces a layer of NAT so you have to configure port forwarding on both the Mikrotik and Synology routers. For example if the Hex S is using its default LAN of 192.168.88.1/24 and the RT2600AC has a "WAN" address of 192.168.88.2/24, set either statically or by DHCP reser...
by tdw
Mon Jun 27, 2022 6:59 pm
Forum: General
Topic: Mikrotik to a TP-Link EAP660 HD, multi SSID map to VLAN
Replies: 11
Views: 2638

Re: Mikrotik to a TP-Link EAP660 HD, multi SSID map to VLAN

You could either use hybrid instead of trunk ports with management VLAN untagged + all WiFi VLANs tagged, or set the EAP660 to use a VLAN for management as shown in https://static.tp-link.com/upload/manua ... 110_UG.pdf on page 83.
by tdw
Mon Jun 27, 2022 4:37 pm
Forum: Beginner Basics
Topic: how to route public IP to another machine without NAT [SOLVED]
Replies: 4
Views: 2209

Re: how to route public IP to another machine without NAT [SOLVED]

So on your CCR /ip address add address=10.101.1.1/32 interface=sfp12 network=RR.SS.TT.UU which will automatically add the /32 route And if the other device were a Mikrotik /ip address add address=RR.SS.TT.UU/32 interface=ether1 network=10.101.1.1 /ip route add comment="default gateway" dis...
by tdw
Mon Jun 27, 2022 3:35 pm
Forum: General
Topic: Routing IPV4 over IPV6 (IPv6 DS Lite) [SOLVED]
Replies: 6
Views: 3314

Re: Routing IPV4 over IPV6 (IPv6 DS Lite) [SOLVED]

Neither of those links show the correct method, they may luckily work for those particular users setups and ISPs. You should not have a DHCPv4 client as the DS-Lite is not set up that way, and you certainly should not be setting a tunnel address which overlaps with your WAN. The DS-Lite standard (se...
by tdw
Mon Jun 27, 2022 1:25 pm
Forum: Beginner Basics
Topic: how to route public IP to another machine without NAT [SOLVED]
Replies: 4
Views: 2209

Re: how to route public IP to another machine without NAT [SOLVED]

Mikrotiks and various other devices support /32, you can use any local address on the Mikrotik for the CCR end and one of your spare public addresses for the machine end. If the public addresses are attached to a layer 2 network you will have to enable proxy ARP.
by tdw
Mon Jun 27, 2022 1:16 pm
Forum: General
Topic: 802.1x PEAP+mschapv2 on WAN dot1x RouterBOARD ROS 7.3.1
Replies: 7
Views: 1210

Re: 802.1x PEAP+mschapv2 on WAN dot1x RouterBOARD ROS 7.3.1

As the supplicant ends up in the authenticated state it must be mostly working. If the Mikrotik cannot log the unencrypted payload of the EAPOL-Packet EAP-Request/EAP-Response messages then whatever logs/debugging that the Cisco ISE provides may shed some light. Bridging another interface such as a ...
by tdw
Sun Jun 26, 2022 2:03 pm
Forum: General
Topic: CCR1009 VLAN and Wi-Tek POE Switch
Replies: 4
Views: 808

Re: CCR1009 VLAN and Wi-Tek POE Switch

Configured with a single bridge having vlan-filtering=no so VLAN tags are not treated differently to any other ethertypes? On the bridge vlan-filtering is enabled. This was with reference to your statement about the CRS, but you posted the CCR configuration. That looks fine except /interface bridge...
by tdw
Sun Jun 26, 2022 1:32 pm
Forum: General
Topic: 802.1x PEAP+mschapv2 on WAN dot1x RouterBOARD ROS 7.3.1
Replies: 7
Views: 1210

Re: 802.1x PEAP+mschapv2 on WAN dot1x RouterBOARD ROS 7.3.1

Any hints of how to force the dot1x module to do the additional MSCHAPv2 Auth? Or do you suspect it's doing MSCHAPv2 here, encapsulated by the PEAP tunnel, with the log only showing details about the PEAP tunnel? Yes. From the help pages eap-peap actually means PEAPv0/EAP-MSCHAPv2. When I remove EA...
by tdw
Sat Jun 25, 2022 1:03 pm
Forum: General
Topic: CCR1009 VLAN and Wi-Tek POE Switch
Replies: 4
Views: 808

Re: CCR1009 VLAN and Wi-Tek POE Switch

Here I am running CAPSMan using VLANs on the CCR with the "bridge" method. Do you mean local forwarding mode? On the CRS328 switches I am not doing anything in the VLAN sections. Configured with a single bridge having vlan-filtering=no so VLAN tags are not treated differently to any other...
by tdw
Fri Jun 24, 2022 4:34 pm
Forum: General
Topic: Routing IPV4 over IPV6 (IPv6 DS Lite) [SOLVED]
Replies: 6
Views: 3314

Re: Routing IPV4 over IPV6 (IPv6 DS Lite) [SOLVED]

The configuration appears to contain random bits and pieces taken from bad examples. Firstly the IPv6 setup is incorrect: DHCPv6 has no mechanism to obtain or provide a default gateway. The Mikrotik DHCPv6 client add-default-route=yes is a hacky bodge, it uses the address of the DHCPv6 server from w...
by tdw
Thu Jun 23, 2022 2:06 am
Forum: General
Topic: INFO CONFIGURATION
Replies: 1
Views: 317

Re: INFO CONFIGURATION

There are limitations with wireless connections, especially if AP & station are not from the same vendor. See https://wiki.mikrotik.com/wiki/Manual:W ... tion_Modes
by tdw
Fri Jun 17, 2022 6:24 pm
Forum: General
Topic: Is VLAN's from Mikrotik Tagged or Untagged
Replies: 33
Views: 5870

Re: Is VLAN's from Mikrotik Tagged or Untagged

It depends if the switch firmware provides any access to the switch chip FDB management.
by tdw
Fri Jun 17, 2022 4:21 pm
Forum: General
Topic: Is VLAN's from Mikrotik Tagged or Untagged
Replies: 33
Views: 5870

Re: Is VLAN's from Mikrotik Tagged or Untagged

Depending on how the D-Link and TP-Link switches are connected to the rest of your infrastructure it may be switch FDB entries have to age out, this can be as much as 5 minutes depending on the make/model and/or settings where configurable.
by tdw
Fri Jun 17, 2022 3:03 pm
Forum: General
Topic: PPPoE client, wired transparent bridge not working [SOLVED]
Replies: 2
Views: 759

Re: PPPoE client, wired transparent bridge not working [SOLVED]

The PPPoE client is an IP interface, not an ethernet interface, so you cannot add it to a layer 2 bridge.
by tdw
Tue Jun 14, 2022 1:25 am
Forum: General
Topic: Bridge VLAN's and Unifi AP with multiple SSID
Replies: 15
Views: 2898

Re: Bridge VLAN's and Unifi AP with multiple SSID

Hopefully that isn't connected directly to the internet, not having any rules protecting it from external access. As written the masquerade rules will act on all traffic, including between subnets, not just externally. It may be that, although the forward chain is processed before srcnat so the rule...
by tdw
Tue Jun 14, 2022 1:00 am
Forum: General
Topic: Is VLAN's from Mikrotik Tagged or Untagged
Replies: 33
Views: 5870

Re: Is VLAN's from Mikrotik Tagged or Untagged

There are a number of issues with using multiple bridges with VLANs
…for devices with switch chips.
No, there can be an number of issues when using switch chips or not. In this case the Bridged VLAN on physical interfaces scenario is likely to cause problems.
by tdw
Mon Jun 13, 2022 10:20 pm
Forum: General
Topic: Is VLAN's from Mikrotik Tagged or Untagged
Replies: 33
Views: 5870

Re: Is VLAN's from Mikrotik Tagged or Untagged

All of those VLANs (3500, 3508, 3510, 3518, 3520, 2528) will be tagged on egress/ingress on the physical interfaces. There are a number of issues with using multiple bridges with VLANs, see https://help.mikrotik.com/docs/display/ROS/Layer2+misconfiguration , a single VLAN-aware bridge is the preferr...
by tdw
Mon Jun 13, 2022 9:33 pm
Forum: General
Topic: Is VLAN's from Mikrotik Tagged or Untagged
Replies: 33
Views: 5870

Re: Is VLAN's from Mikrotik Tagged or Untagged

That provides no useful information.

As other have said post the output of /export hide-sensitive (RouterOS 6) or /export (RouterOS 7) after redacting any other potentially sensitive information (serial number, public IP addresses, scripts containing credentials)
by tdw
Mon Jun 13, 2022 9:01 pm
Forum: General
Topic: Bridge VLAN's and Unifi AP with multiple SSID
Replies: 15
Views: 2898

Re: Bridge VLAN's and Unifi AP with multiple SSID

For some reason the network is still reachable from VLAN31 to VLAN32. Setting firewall rules did not have any effect. Any idea why? Order of the rules is important, post all of the configuration not just small extracts. Also do you know why bridge-local has to be added as tagged in /interface bridg...
by tdw
Mon Jun 13, 2022 7:38 pm
Forum: General
Topic: Is VLAN's from Mikrotik Tagged or Untagged
Replies: 33
Views: 5870

Re: Is VLAN's from Mikrotik Tagged or Untagged

It depends on how you configure the interfaces on the devices. You can have all VLANs tagged only (sometimes referred to as a trunk interface or port), or one untagged and the remainder tagged (sometimes referred to as a hybrid interface or port).
by tdw
Mon Jun 13, 2022 2:05 am
Forum: General
Topic: Bridge VLAN's and Unifi AP with multiple SSID
Replies: 15
Views: 2898

Re: Bridge VLAN's and Unifi AP with multiple SSID

No. The default forward policy is allow, you have to explicitly add rules to drop inter-VLAN traffic.
by tdw
Sun Jun 12, 2022 10:52 pm
Forum: General
Topic: Bridge VLAN's and Unifi AP with multiple SSID
Replies: 15
Views: 2898

Re: Bridge VLAN's and Unifi AP with multiple SSID

That has nothing to do with the VLANs being tagged or untagged, inter-VLAN access is determined by firewall rules on the Mikrotik.
by tdw
Sun Jun 12, 2022 8:43 pm
Forum: General
Topic: Bridge VLAN's and Unifi AP with multiple SSID
Replies: 15
Views: 2898

Re: Bridge VLAN's and Unifi AP with multiple SSID

If you are using the UniFi controller default network, which is always untagged, for management just attach the Staff network SSID to that. You do not need a network defined for VLAN 31, only VLAN 32 & 33 to be able to link SSIDs to those. Configure the Mikrotik port connected to the AP with VLA...
by tdw
Sun Jun 12, 2022 6:52 pm
Forum: Wireless Networking
Topic: Radar detect problem
Replies: 33
Views: 17119

Re: Radar detect problem

You want to pick a channel that isn't in the DFS block (radar sensing ones)
That is impossible in any country subject ETSI regulations, all channels permitted for outdoor operation mandate DFS.
by tdw
Fri Jun 10, 2022 12:31 am
Forum: Beginner Basics
Topic: Advice for an encrypted tunnel in the local network
Replies: 3
Views: 1260

Re: Advice for an encrypted tunnel in the local network

It was not clear in the original description that they were different bridges, so that is fine.

The EoIP interface should have mtu=1500 per the documentation, a lesser value will break things in odd ways. Then the sfp28-1 interface should have a MTU to accommodate the encapsulation and encryption.
by tdw
Thu Jun 09, 2022 11:50 pm
Forum: Beginner Basics
Topic: Multiple IP addresses on eth1 (wan) nat/routing help [SOLVED]
Replies: 4
Views: 4712

Re: Multiple IP addresses on eth1 (wan) nat/routing help [SOLVED]

No, the connection tracking handles replies. The dstnat rules are for the inbound port forwarding, the srcnat rules are for any outbound connections from the servers e.g. package updates. Rule order is important, any specific srcnat rules must appear before the generic srcnat/masquerade rule which h...
by tdw
Thu Jun 09, 2022 9:15 pm
Forum: Beginner Basics
Topic: Multiple IP addresses on eth1 (wan) nat/routing help [SOLVED]
Replies: 4
Views: 4712

Re: Multiple IP addresses on eth1 (wan) nat/routing help [SOLVED]

Assuming the servers have private IP addresses all you need is both addresses added to a single WAN interface and appropriate srcnat / dstnat rules, routing marks/tables and mangling are not required, e.g. /ip address add address=x.x.150.227/28 interface=ether1 add address=x.x.150.232/28 interface=e...
by tdw
Thu Jun 09, 2022 5:32 pm
Forum: General
Topic: RouterOS + FreeRadius + Active Directory
Replies: 3
Views: 1218

Re: RouterOS + FreeRadius + Active Directory

MAJOR CHANGES IN v6.43:
!) radius - use MS-CHAPv2 for "login" service authentication;
by tdw
Thu Jun 09, 2022 5:19 pm
Forum: Beginner Basics
Topic: Advice for an encrypted tunnel in the local network
Replies: 3
Views: 1260

Re: Advice for an encrypted tunnel in the local network

Why have you added the SFP interfaces to the bridge? The ethernet traffic will be encapsulated by the EoIP interface and routed across the /30 subnet between the SFP interfaces at either end. I'm surprised you do not have a broadcast storm by having both the EoIP and SFP interfaces in the same bridg...
by tdw
Thu Jun 09, 2022 4:12 pm
Forum: Beginner Basics
Topic: Creating multiple VLANs on existing CCR1009-7G-1C-1S+ with active PPPoE and Hotspot without VLAN
Replies: 24
Views: 2639

Re: Creating multiple VLANs on existing CCR1009-7G-1C-1S+ with active PPPoE and Hotspot without VLAN

You can't do it the new way it won't work on most hardware as the port is neither pure access or trunk. That is completely incorrect - VLAN-aware bridges support untagged only (access), 1 or more tagged only (trunk), or untagged with 1 or more tagged (hybrid) on any bridge port. The only devices wh...
by tdw
Thu Jun 09, 2022 1:28 pm
Forum: Scripting
Topic: IoT: How to read Modbus TCP on hEX (no serial port)
Replies: 10
Views: 2869

Re: IoT: How to read Modbus TCP on hEX (no serial port)

There is no mechanism to open a TCP connection and send arbitrary data on Mikrotiks. Implementing only read-holding-registers is an odd choice as these are typically device outputs or settings, if only a single Modbus command was going to be implemented read-input-registers would have been a better ...
by tdw
Thu Jun 09, 2022 12:58 pm
Forum: Beginner Basics
Topic: Creating multiple VLANs on existing CCR1009-7G-1C-1S+ with active PPPoE and Hotspot without VLAN
Replies: 24
Views: 2639

Re: Creating multiple VLANs on existing CCR1009-7G-1C-1S+ with active PPPoE and Hotspot without VLAN

Using multiple bridges is the old way of connecting multiple VLANs between ports and/or the Mikrotik services, and has many pitfalls https://help.mikrotik.com/docs/display/ROS/Layer2+misconfiguration . The suggested configuration has multiple faults, a single VLAN-aware bridge with appropriate confi...
by tdw
Thu Jun 09, 2022 1:15 am
Forum: Beginner Basics
Topic: Manage router via VPN
Replies: 2
Views: 976

Re: Manage router via VPN

The default firewall rules have add action=drop chain=input comment="drop all not coming from LAN" in-interface-list=!LAN so VPN connections would be blocked by default. Ping works due to the rule before this add action=accept chain=input comment="accept ICMP" protocol=icmp . You...
by tdw
Wed Jun 08, 2022 11:58 pm
Forum: Scripting
Topic: IoT: How to read Modbus TCP on hEX (no serial port)
Replies: 10
Views: 2869

Re: IoT: How to read Modbus TCP on hEX (no serial port)

There are two separate functions: A Modbus TCP server to serial port gateway: /iot modbus set which takes parameters disabled , hardware-port , tcp-port , timeout . A Modbus client: /iot modbus read-holding-registers which takes parameters ip , port , num-regs , reg-addr , slave-id , timeout (plus t...
by tdw
Wed Jun 08, 2022 7:08 pm
Forum: Scripting
Topic: IoT: How to read Modbus TCP on hEX (no serial port)
Replies: 10
Views: 2869

Re: IoT: How to read Modbus TCP on hEX (no serial port)

I guess some scripting is needed? No. From the top of the help article "The feature allows KNOT to act as a TCP bridge and read data from Modbus-supported devices connected to a 2-pin terminal block on the board. Modbus clients (slaves) can access the data from the Modbus server (master - KNOT...
by tdw
Tue Jun 07, 2022 5:39 pm
Forum: General
Topic: IPV6 on Mikrotik Router OS7 device
Replies: 7
Views: 725

Re: IPV6 on Mikrotik Router OS7 device

if using ppp then you maybe need to "interface/pppoe-client/set add-default-route=no ..."
Unlikely. add-default-route=yes is OK on point-to-point connections such as PPPoE, the usual misconfiguration is to also enable add-default-route in the IPv6 DHCP client.
by tdw
Tue Jun 07, 2022 5:35 pm
Forum: General
Topic: IPV6 on Mikrotik Router OS7 device
Replies: 7
Views: 725

Re: IPV6 on Mikrotik Router OS7 device

I configure 2406:xxx::1/64 to ethernet1 and 2406:xxx::2/64 to a laptop. When I try to traceroute to Internet, it doesn't go beyond 2406:xxx::1. Please help.
How are things connected together as ether1 is usually the WAN connection?
by tdw
Tue Jun 07, 2022 3:46 pm
Forum: Beginner Basics
Topic: Can't connect to hEX after setting up vlans
Replies: 6
Views: 893

Re: Can't connect to hEX after setting up vlans

The VLAN membership of the Netgear only shows 1 VLAN at a time so I'll post here what it is. As for Port PVID, all ports I put in VLAN 99. VLAN Membership of switch is as follows Port 1 has all VLANS tagged As with the Mikrotik you are mixing untagged and tagged operation for the same VLAN ID. Any ...
by tdw
Tue Jun 07, 2022 12:29 pm
Forum: Beginner Basics
Topic: Can't connect to hEX after setting up vlans
Replies: 6
Views: 893

Re: Can't connect to hEX after setting up vlans

You have /interface bridge port add bridge=bridge comment=defconf interface=ether5 # with default pvid=1 but /interface bridge vlan add bridge=bridge tagged=bridge,ether3,ether4 untagged=ether5 vlan-ids=99 so mixing tagged on ingress and untagged on egress for VLAN 99. You haven't shown the Netgear ...
by tdw
Sat Jun 04, 2022 1:51 am
Forum: General
Topic: comcast ipv6 help [SOLVED]
Replies: 2
Views: 1091

Re: comcast ipv6 help [SOLVED]

Screenshots rarely provide all the information, posting the configuration (from running /export in a terminal window) after redacting any public IP addresses, serial number, etc. provides the exact setup, in this case /ipv6 export is probably sufficient. You appear to have disabled IPv6 forwarding s...
by tdw
Fri Jun 03, 2022 5:31 pm
Forum: General
Topic: Static IP not resolving Internet
Replies: 15
Views: 2526

Re: Static IP not resolving Internet

You are manually setting an ARP entry which conflicts with the DHCP lease entry:

/ip arp
add address=192.168.1.10 interface=bridge1 mac-address=00:25:90:4B:6B:4B

and
/ip dhcp-server lease
add address=192.168.1.10 client-id=1:e4:35:c8:7e:37:ee mac-address=E4:35:C8:7E:37:EE server=dhcp1
by tdw
Fri Jun 03, 2022 4:18 pm
Forum: Beginner Basics
Topic: Can't see the internet - 0.0.0.0
Replies: 11
Views: 2267

Re: Can't see the internet - 0.0.0.0

Oops yes, I misread the section. But as you say the gateway=0.0.0.0 and gateway=0.0.0.1 entries make no sense for the DHCP server and should be removed.
by tdw
Fri Jun 03, 2022 2:28 pm
Forum: Beginner Basics
Topic: Which MTU size should I set on my interfaces?
Replies: 15
Views: 13627

Re: Which MTU size should I set on my interfaces?

There should be no need to change the MTU of either the base ethernet interface (Fiber) or the VLAN on top of it (Telenor VLAN101) as this only affects layer 3 IPoE packets, PPPoE is layer 2 and easily fits within the L2MTU of 1594. With providers supporting RFC4638 this certainly works on 6.48.6 an...
by tdw
Fri Jun 03, 2022 1:12 pm
Forum: Beginner Basics
Topic: VLAN packet loss
Replies: 8
Views: 949

Re: VLAN packet loss

You do not add IP addresses to bridge members. To make ether4 untagged reachable with IP: /interface vlan add interface=bridge1 name=vlan_prod vlan-id=28 ... /interface bridge vlan add bridge=bridge1 tagged= bridge1, ether1_trunk untagged=ether4_prod vlan-ids=28 ... /ip address add address=10.36.8.1...
by tdw
Fri Jun 03, 2022 11:32 am
Forum: Beginner Basics
Topic: VLAN packet loss
Replies: 8
Views: 949

Re: VLAN packet loss

Additionally the configuration has more than one of these https://wiki.mikrotik.com/wiki/Manual:L ... figuration, use a single VLAN-aware bridge.

use-ip-firewall=yes impacts performance, it is not necessary in most use cases.
by tdw
Fri Jun 03, 2022 12:07 am
Forum: Beginner Basics
Topic: Which MTU size should I set on my interfaces?
Replies: 15
Views: 13627

Re: Which MTU size should I set on my interfaces?

The change-tcp-mss=yes setting in the default and default-encryption PPP profiles will sort out MSS clamping on the PPPoE connection (PPPoE client interfaces default to the default profile). The PPPoE client MRU/MTU should be adjusted to best fill any segmentation imposed by the WAN technology, ofte...
by tdw
Thu Jun 02, 2022 2:15 pm
Forum: General
Topic: How to mapp IPV4 to IPV6 and vice versa
Replies: 1
Views: 1423

Re: How to mapp IPV4 to IPV6 and vice versa

What do you mean by mapp? There are tunnel interfaces - 6to4 which encapsulates IPv6 packets for transport across an IPv4-only network, and ipipv6 which encapsulates IPv4 packets for transport across an IPv6-only network. It is impossible for IPv4 clients to access IPv6 hosts. There are transition m...
by tdw
Wed Jun 01, 2022 10:05 pm
Forum: General
Topic: What is the best wayside/IP console/backdoor access method? [SOLVED]
Replies: 6
Views: 1501

Re: What is the best wayside/IP console/backdoor access method? [SOLVED]

You only need to mark connections in the input chain for traffic arriving via the backup interface, plus the usual mark routing from connection mark and a routing table with a default route via the backup gateway. Either a whitelist and/or using a VPN server on the Mikrotik to gain access to Winbox ...
by tdw
Wed Jun 01, 2022 6:30 pm
Forum: General
Topic: Totally off-topic - is this a fibre cable? [SOLVED]
Replies: 12
Views: 1641

Re: Totally off-topic - is this a fibre cable? [SOLVED]

It is standard UK Openreach drop wire which can run upto 68 metres unsupported overhead. Thick UV resistant polythene sheath, ripcord, three steel strength members (one uninsulated, two with cream insulation) and a single signal pair coloured orange & white, either Dropwire 11 with 0.5mm diamete...
by tdw
Wed Jun 01, 2022 12:40 pm
Forum: Beginner Basics
Topic: Can't see the internet - 0.0.0.0
Replies: 11
Views: 2267

Re: Can't see the internet - 0.0.0.0

I believe these work in order of operation - and if that rule is first it will catch-all and try give a gateway of 0.0.0.0 - which will never work. M ove the 10.0/24 rule (the 3rd one) to the top of the list so it matches first and the client is given 192.168.10.1 as gateway - as then it'll at leas...
by tdw
Mon May 30, 2022 10:50 pm
Forum: RouterOS beta
Topic: NAT only NAT'ing 99% of packets. [SOLVED]
Replies: 9
Views: 4241

Re: NAT only NAT'ing 99% of packets. [SOLVED]

No, fasttrack is a connection tracking attribute.
by tdw
Mon May 30, 2022 6:35 pm
Forum: RouterOS beta
Topic: NAT only NAT'ing 99% of packets. [SOLVED]
Replies: 9
Views: 4241

Re: NAT only NAT'ing 99% of packets. [SOLVED]

When the Mikrotik connection tracking sees the end of a TCP conversation (FIN -> ACK+FIN -> ACK) the tracking entry is removed. Any repeated or unsolicited invalid transmissions from a client, e.g. FIN+ACK, RST+ACK or RST will not create a new connection tracking entry so no NAT will be applied. Thi...
by tdw
Mon May 30, 2022 5:56 pm
Forum: RouterOS beta
Topic: NAT only NAT'ing 99% of packets. [SOLVED]
Replies: 9
Views: 4241

Re: NAT only NAT'ing 99% of packets. [SOLVED]

Try adding a firewall rule add action=drop chain=forward connection-state=invalid after the accept established/related.
by tdw
Sat May 28, 2022 1:14 pm
Forum: General
Topic: someone set my 2 cAP ac devices with same mac address! [SOLVED]
Replies: 8
Views: 1273

Re: someone set my 2 cAP ac devices with same mac address! [SOLVED]

It may have been unintentional. If you make a .backup on one device and restore it on another (not officially supported but works if the two devices are the same model) various things, including the original MAC addresses, are cloned. These can be reset - in Winbox if you open an interface one of th...
by tdw
Fri May 27, 2022 9:21 pm
Forum: General
Topic: IPv6 NAT T-Mobile Home Internet
Replies: 17
Views: 5900

Re: IPv6 NAT T-Mobile Home Internet

also test-ipv6.com gives me this message: Your browser has a real working IPV6 address but is avoiding using it. If you are using Windows then IPv4 is favoured over IPv6 ULA C:\>netsh interface ipv6 show prefixpolicies Querying active state... Precedence Label Prefix ---------- ----- --------------...
by tdw
Fri May 27, 2022 6:26 pm
Forum: General
Topic: IPv6 NAT T-Mobile Home Internet
Replies: 17
Views: 5900

Re: IPv6 NAT T-Mobile Home Internet

And don't use all-zeros for the host part of the address, it is reserved. Use add address=::1/64 from-pool=private-pool interface=... or add eui-64=yes from-pool=private-pool interface=...
by tdw
Fri May 27, 2022 4:51 pm
Forum: General
Topic: Testing v7, no need for ipv6
Replies: 28
Views: 4023

Re: Testing v7, no need for ipv6

You can't remove it but it can be disabled /ipv6 settings set disable-ipv6=yes
by tdw
Fri May 27, 2022 4:40 pm
Forum: Beginner Basics
Topic: hAP-ac2 unable to transmit/recieve over media Converter
Replies: 1
Views: 334

Re: hAP-ac2 unable to transmit/recieve over media Converter

hAP ac2 has gigabit ethernet interfaces, hAP lite has fast ethernet interfaces. As #3 works I suspect your PC also has fast ethernet rather than gigabit. Less expensive media converters do not support different rates on the copper and optical interfaces, or it may be a poor design which advertises c...
by tdw
Fri May 27, 2022 3:32 pm
Forum: Beginner Basics
Topic: Help with SSTP configuration and local network ping.
Replies: 6
Views: 1820

Re: Help with SSTP configuration and local network ping.

Changes along the lines of: ... /interface bridge add arp=proxy-arp name=bridge-lan # proxy ARP is not required ... /interface sstp-server add name=sstp-in1 user=name # name should match the PPP secret username ... /ip firewall nat add action=masquerade chain=srcnat out-interface=bridge-wan add acti...
by tdw
Thu May 26, 2022 5:14 pm
Forum: Beginner Basics
Topic: Help with SSTP configuration and local network ping.
Replies: 6
Views: 1820

Re: Help with SSTP configuration and local network ping.

My boss would like to Ping the ISP 1 devices while connected to VPN client and vice versa. I told him that with my knowledge its not possible and the local subnet for one ISP should be different. He keeps insisting that a simple firewall rule will do the trick. The issue is that each mikrotik has a...
by tdw
Thu May 26, 2022 12:53 am
Forum: Beginner Basics
Topic: Dumb AP: Static IP and DHCP Client
Replies: 5
Views: 1397

Re: Dumb AP: Static IP and DHCP Client

For the route, yes. I suspect updates worked because the DNS entry was cached, add 192.168.3.1 as a DNS server too.

RouterOS can be rather a steep learning curve, it is basically linux underneath with a custom user interface on top.
by tdw
Wed May 25, 2022 3:53 pm
Forum: General
Topic: How to setup VLAN on Mikrotik PWR-LINE? [SOLVED]
Replies: 0
Views: 719

Re: How to setup VLAN on Mikrotik PWR-LINE? [SOLVED]

The power line interface should behave as any other ethernet-like layer2 interface, so the example https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge#VLAN_Example_#1_(Trunk_and_Access_Ports) should work with pwr-line1 as the trunk and an ethernet interface as an access port. Unless you really ne...
by tdw
Wed May 25, 2022 2:05 pm
Forum: Beginner Basics
Topic: Dumb AP: Static IP and DHCP Client
Replies: 5
Views: 1397

Re: Dumb AP: Static IP and DHCP Client

You can add a default route under IP > Route and a DNS server under IP > DNS. Alternatively if the router you are connecting this Mikrotik to supports static DHCP leases you could assign an address that way.
by tdw
Mon May 23, 2022 11:02 pm
Forum: General
Topic: IPv6 Support? When actually?
Replies: 2
Views: 417

Re: IPv6 Support? When actually?

Why are you manually handing out/assigning FE80:: addresses? This seems wrong.. Is it a static /48? I strongly suggest you use that instead.. IPv6 prefixes.. IPv6-Pool and IPv6-DHCP-Server on your central router. It is nothing to do with the user configuration or global unicast (GUA) / unique local...
by tdw
Mon May 23, 2022 4:37 pm
Forum: General
Topic: SIP Issues
Replies: 40
Views: 7156

Re: SIP Issues

As the Mikrotik is responding with ICMP host unreachable that suggests the issue is with the Mikrotik - AnyNode connection. If the ARP table entry expires and is not refreshed for some reason the Mikrotik would send that response.
by tdw
Mon May 23, 2022 3:13 pm
Forum: General
Topic: SIP Issues
Replies: 40
Views: 7156

Re: SIP Issues

It is already open by way of the connection tracking shown in post #5.

Getting ICMP host unreachable responses points to something more complex, hence the requests to see a packet trace of the registration process.
by tdw
Mon May 23, 2022 12:50 pm
Forum: General
Topic: Have internet, but switch will not update.
Replies: 3
Views: 470

Re: Have internet, but switch will not update.

Does the Mikrotik DHCP client have use-peer-dns=yes? Is the DHCP server configured to send DNS server(s) (option 6) if requested by a client?
by tdw
Mon May 23, 2022 12:59 am
Forum: Beginner Basics
Topic: RB4011 IPv6 setup - only link-local address on PC
Replies: 15
Views: 2166

Re: RB4011 IPv6 setup - only link-local address on PC

It varies. Not having NAT is good, the literal IP format takes some getting used to, but some of the under-the-hood stuff is quite different - Neighbour Discovery replacing ARP and IPv4 Router Discovery / Router Redirect, requiring multicast, DHCPv6 not having any concept of gateways....
by tdw
Sun May 22, 2022 11:42 pm
Forum: Beginner Basics
Topic: RB4011 IPv6 setup - only link-local address on PC
Replies: 15
Views: 2166

Re: RB4011 IPv6 setup - only link-local address on PC

IPv6 isn't just IPv4 with larger addresses, some of the underlying mechanisms are different. The outbound packet from PC to Mikrotik is sent to the default gateway, which in this case the the Mikrotik link-local address via a specific interface. As the first traceroute packet will have a TTL of 1, a...
by tdw
Sun May 22, 2022 10:38 pm
Forum: Beginner Basics
Topic: trying to get rid of vlan 1 on 951G-2HnD [SOLVED]
Replies: 19
Views: 1855

Re: trying to get rid of vlan 1 on 951G-2HnD [SOLVED]

There is additional overhead with routing compared to software bridging. I would still expect somewhat better routing performance from a hAP ac2.
by tdw
Sun May 22, 2022 9:49 pm
Forum: Beginner Basics
Topic: trying to get rid of vlan 1 on 951G-2HnD [SOLVED]
Replies: 19
Views: 1855

Re: trying to get rid of vlan 1 on 951G-2HnD [SOLVED]

what a hunk of junk, even an hex or capac, handles that with ease...........
They would as the processors are several times more powerful:
RB951G-2HnD - single-core 600MHz MIPS
hEX - dual-core 880MHz MIPS
cAP ac - quad-core 716MHz ARM
by tdw
Sun May 22, 2022 8:34 pm
Forum: Beginner Basics
Topic: trying to get rid of vlan 1 on 951G-2HnD [SOLVED]
Replies: 19
Views: 1855

Re: trying to get rid of vlan 1 on 951G-2HnD [SOLVED]

That would be fine if the Atheros/Qualcomm switch chips supported hardware offload with vlan-aware bridges. Given the RB951G-2HnD is an older device the CPU performance would likely limit software bridged thoughput to a few hundred Mbps.
by tdw
Sun May 22, 2022 7:47 pm
Forum: General
Topic: IKEv2 between MikroTiks, sides switching, initiator <> responder
Replies: 15
Views: 5489

Re: IKEv2 between MikroTiks, sides switching, initiator <> responder

I have recently discovered this whilst looking at replacing IKE with IKE2 and thought I was doing something wrong. It doesn't affect the current use case, but what happens if you are using mode-config ? And what appears to be another error in the documentation - for peer exchange-mode it says "...
by tdw
Sun May 22, 2022 7:16 pm
Forum: Beginner Basics
Topic: trying to get rid of vlan 1 on 951G-2HnD [SOLVED]
Replies: 19
Views: 1855

Re: trying to get rid of vlan 1 on 951G-2HnD [SOLVED]

Yes
/interface ethernet switch port
set 0 default-vlan-id=70; set 5 default-vlan-id=70

(obviously with safe mode, just in case)
by tdw
Sun May 22, 2022 6:41 pm
Forum: Beginner Basics
Topic: trying to get rid of vlan 1 on 951G-2HnD [SOLVED]
Replies: 19
Views: 1855

Re: trying to get rid of vlan 1 on 951G-2HnD [SOLVED]

The /ip dhcp-client add disabled=no interface=bridge-ALL configuration will acquire an address using untagged traffic through the switch1-cpu port. This currently has PVID 1, the export does not show the deafults, fully it would be set 5 default-vlan-id=1 vlan-mode=secure . Similarly the ether1-WAN ...
by tdw
Sun May 22, 2022 4:14 pm
Forum: Beginner Basics
Topic: RB4011 IPv6 setup - only link-local address on PC
Replies: 15
Views: 2166

Re: RB4011 IPv6 setup - only link-local address on PC

****:****:*****:*****::/64 dev enp37s0 proto ra metric 100 pref medium fe80::/64 dev enp37s0 proto kernel metric 100 pref medium fe80::/64 dev enp37s0.99 proto kernel metric 256 pref medium default via fe80::de2c:6eff:fe18:caa dev enp37s0 proto ra metric 20100 pref medium So this PC is picking up R...
by tdw
Sun May 22, 2022 2:52 am
Forum: Beginner Basics
Topic: RB4011 IPv6 setup - only link-local address on PC
Replies: 15
Views: 2166

Re: RB4011 IPv6 setup - only link-local address on PC

The default firewall rules drop forwarded traffic arriving through any interfaces not in the LAN interface list. Routing is hop-by-hop so routes via link-local addresses are fine, if you check the routes on your PC the default route (::0) will be to the link-local address of the Mikrotik interface. ...
by tdw
Sat May 21, 2022 9:04 pm
Forum: Beginner Basics
Topic: Problem with Ubiquiti cloud controller when APs are behind a Mikrotik
Replies: 13
Views: 1568

Re: Problem with Ubiquiti cloud controller when APs are behind a Mikrotik

That suggests it is something else if pings are successfully bypassing the hotspot, maybe additional firewall rules. You can use the packet sniffer, filter on the IP address of the AP.
by tdw
Sat May 21, 2022 8:08 pm
Forum: Beginner Basics
Topic: Problem with Ubiquiti cloud controller when APs are behind a Mikrotik
Replies: 13
Views: 1568

Re: Problem with Ubiquiti cloud controller when APs are behind a Mikrotik

Works on our hotspots. Can the AP resolve the inform URL address, the AP DNS server address would typically be set to the same as the gateway address, and does the Mikrotik apply srcnat to the outbound WAN traffic?
by tdw
Sat May 21, 2022 7:56 pm
Forum: Beginner Basics
Topic: Problem with Ubiquiti cloud controller when APs are behind a Mikrotik
Replies: 13
Views: 1568

Re: Problem with Ubiquiti cloud controller when APs are behind a Mikrotik

Yes, AP MAC address.

Both IP addresses are the same fixed IP of the AP. The to-address is part of the internal hotspot translation system, it has nothing to do with the destination of traffic from the AP.
by tdw
Sat May 21, 2022 7:10 pm
Forum: Beginner Basics
Topic: Problem with Ubiquiti cloud controller when APs are behind a Mikrotik
Replies: 13
Views: 1568

Re: Problem with Ubiquiti cloud controller when APs are behind a Mikrotik

We have always used /ip hotspot ip-binding add mac-address=XX:XX:XX:XX:XX:XX address=NNN.NNN.NNN.NNN to-address=NNN.NNN.NNN.NNN type=bypassed with the device address either set statically or getting it from a static DHCP lease. Never tried it without the addresses, the wiki isn't clear what would ha...
by tdw
Sat May 21, 2022 6:25 pm
Forum: Beginner Basics
Topic: Problem with Ubiquiti cloud controller when APs are behind a Mikrotik
Replies: 13
Views: 1568

Re: Problem with Ubiquiti cloud controller when APs are behind a Mikrotik

For outbound UniFi APs -> controller connections you only need to add hotspot IP bindings, MAC and IP addresses.
by tdw
Sat May 21, 2022 5:51 pm
Forum: Beginner Basics
Topic: RB4011 IPv6 setup - only link-local address on PC
Replies: 15
Views: 2166

Re: RB4011 IPv6 setup - only link-local address on PC

Providing the configuration rather than a few screenshots would be better. Firstly you need you an globally unique address on the WAN port and a default route so the router itself can access the internet. As the WAN connection appears to be IPoE the correct method to obtain the default route is to u...
by tdw
Sat May 21, 2022 2:58 pm
Forum: Beginner Basics
Topic: Can't route between 2 subnets
Replies: 7
Views: 2278

Re: Can't route between 2 subnets

At minimum, you need something like "/ip/route add dst-address=192.168.88.0/24 gateway=192.168.100.2" to get packets from the 0 network to the 100 network, and its inverse to get the replies back. No, not in this case. Directly connected networks (e.g. adding an IP address to an ethernet ...
by tdw
Sat May 21, 2022 2:41 am
Forum: Beginner Basics
Topic: Basic Router + switch + ap with VLAN [SOLVED]
Replies: 2
Views: 1166

Re: Basic Router + switch + ap with VLAN [SOLVED]

The switch is missing /interface bridge vlan entries for all VLANs except 99. You should not set the bridge PVID to have the same value as an /interface vlan , either /interface bridge add name=BR1 protocol-mode=none pvid= 99 1 vlan-filtering=yes /interface vlan add interface=BR1 name=MGMT_VLAN vlan...
by tdw
Thu May 19, 2022 5:39 pm
Forum: General
Topic: SIP Issues
Replies: 40
Views: 7156

Re: SIP Issues

Do you see the registration messages between the Mikrotik and SBC in the packet trace in both directions (SBC -> Mikrotik and Mikrotik -> SBC)
by tdw
Thu May 19, 2022 5:05 pm
Forum: General
Topic: SIP Issues
Replies: 40
Views: 7156

Re: SIP Issues

Is the phone registered with the PBX? If there is no connection (under IP > Firewall > Connections) the incoming packets have nowhere to go and will be dropped. There is little point setting 1000M-half,1000M-full on ether1 as the device only supports fast, not gigabit, ethernet. The Drop External Ac...
by tdw
Wed May 18, 2022 2:38 pm
Forum: Beginner Basics
Topic: pppoe client/server using bto modem and internal dslam
Replies: 4
Views: 592

Re: pppoe client/server using bto modem and internal dslam

The old BT Huawei/ECI modems already handle the VLAN 101 tagging internally so you attach the PPPoE client directly to the ethernet inteface connected to the modem.
by tdw
Tue May 17, 2022 1:27 am
Forum: Beginner Basics
Topic: Dual WAN failover messes with DNS
Replies: 3
Views: 1206

Re: Dual WAN failover messes with DNS

As you have multiple DNS servers added by having the DHCP client setting use-peer-dns=yes there is no control over which of the listed servers will be used. If the ISPs only permit DNS lookups from their servers via their connection you may well get lookup failures. The simplest fix is to set one or...
by tdw
Mon May 16, 2022 9:57 pm
Forum: Beginner Basics
Topic: Share 192.168.88.00/24 subnet on VPN with OpenVPN
Replies: 4
Views: 985

Re: Share 192.168.88.00/24 subnet on VPN with OpenVPN

Routes specify the destination, 192.168.88.0/24 is from the locally attached LAN so adding the static route for the same subnet is incorrect. The Mikrotik OpenVPN client automatically adds a static route back to the server with the netmask specified by the server, so the static route to 10.8.0.0/24 ...
by tdw
Mon May 16, 2022 7:46 pm
Forum: Beginner Basics
Topic: Share 192.168.88.00/24 subnet on VPN with OpenVPN
Replies: 4
Views: 985

Re: Share 192.168.88.00/24 subnet on VPN with OpenVPN

As two unconnected networks (the VPN tunnel and the local LAN) share the same address range any devices attached to the LAN will expect those addresses to be directly reachable on the local ethernet network. If you set arp=proxy-arp on the bridge the Mikrotik will return its own MAC address to reque...
by tdw
Mon May 16, 2022 6:13 pm
Forum: General
Topic: ROS7 - VLAN Switch chip
Replies: 15
Views: 1748

Re: ROS7 - VLAN Switch chip

switch1-cpu is the internal ethernet connection between the CPU and switch, without that there is no connection from the external ports through the switch to the CPU for management access. There have been odd interfactions when only some ports are configured for 802.1Q VLANs as the other ports are s...
by tdw
Mon May 16, 2022 5:51 pm
Forum: General
Topic: PPPOE disconnects - UK FTTC
Replies: 6
Views: 1017

Re: PPPOE disconnects - UK FTTC

PPP sessions should be able to reject unsupported control protocols during negotiation without aborting the entire session, certainly it works fine the other way around with an IPv6-enabled Mikrotik connecting to an IPv4-only ISP (Plusnet). Maybe the ISP or carrier has changed something which only m...
by tdw
Mon May 16, 2022 5:30 pm
Forum: Wireless Networking
Topic: vlans to multiple access points
Replies: 7
Views: 1410

Re: vlans to multiple access points

Those APs do not have any management APIs, it would be a case of the logging in to each AP and manually changing the settings. You could use WPA2-Enterprise and an external RADIUS server to manage the authentication so it is centralised. This would only work if all of the client devices support it, ...
by tdw
Sun May 15, 2022 2:34 am
Forum: General
Topic: Inter-VLAN Routing Across IPSec VPN
Replies: 9
Views: 1834

Re: Inter-VLAN Routing Across IPSec VPN

No. There are no 'IPsec interfaces' to apply routes to as Mikrotik do not implement an equivalent of Cisco VTI, or similar by other manufacturers. IPsec policies match traffic to be transported or tunneled based on some combination of addresses, protocols and ports. A packet matching a policy gets e...
by tdw
Sat May 14, 2022 11:37 pm
Forum: Beginner Basics
Topic: ipv6 only works when pinging from the router [SOLVED]
Replies: 6
Views: 2822

Re: ipv6 only works when pinging from the router [SOLVED]

What are you expecting /ipv6 route add disabled=no dst-address=::/0 gateway=ether1 to do? Using gateway=someinterface is only valid for point-to-point media, so not ethernet. The gateway will be learnt from the upstream RAs due to accept-router-advertisements=yes , although this was broken in 7.1.x,...
by tdw
Sat May 14, 2022 2:30 pm
Forum: General
Topic: Inter Switch VLAN
Replies: 3
Views: 616

Re: Inter Switch VLAN

One of the paths forming the inetswitch - site1switch - interswitch - site2switch loop will be disabled by spanning tree, and as you do not have the same VLANs configured on each path connectivity will be lost. If you wish to have redundant paths with blocks on different links for some VLANs you wil...
by tdw
Fri May 13, 2022 2:17 pm
Forum: Forwarding Protocols
Topic: RTSP Over WiFI Not Blocking
Replies: 4
Views: 1183

Re: RTSP Over WiFI Not Blocking

That won't work. Each branch of the layer 2 network tree exchanges packets with its immediate neighbour and each node builds a list of path costs back to the root to determine which ports should be enabled and which blocked.

Offhand I can't think of any methods which would work in this scenario.
by tdw
Fri May 13, 2022 1:56 pm
Forum: Beginner Basics
Topic: DNS forward server for router itself
Replies: 4
Views: 639

Re: DNS forward server for router itself

There is no way to distinguish requests as the Mikrotik is making requests on behalf of the clients, the client - Mikrotik and Mikrotik - external server requests are not directly related. Instead of setting the DHCP server to provide the IP address of the router as the DNS server to clients you cou...
by tdw
Fri May 13, 2022 1:43 pm
Forum: Forwarding Protocols
Topic: RTSP Over WiFI Not Blocking
Replies: 4
Views: 1183

Re: RTSP Over WiFI Not Blocking

You mean RSTP (Rapid Spanning Tree Protocol) not RTSP (Real Time Streaming Protocol).

Does the rest of your network have RSTP enabled? All of the non-edge devices in your layer 2 network should have it configured.
by tdw
Thu May 12, 2022 8:36 pm
Forum: General
Topic: RSTP Problem with Bridge VLAN Filtering
Replies: 12
Views: 3239

Re: RSTP Problem with Bridge VLAN Filtering

Had to also update DHCP relay to use the new VLAN interfaces. So far so good. You would, but the full configuration wasn't provided so any other use if interfaces was unknown. I use routing marks in the mangle table to mark outbound (public IPs) per VLAN so I can pick it up in the routing rules and...
by tdw
Wed May 11, 2022 9:27 pm
Forum: General
Topic: RSTP Problem with Bridge VLAN Filtering
Replies: 12
Views: 3239

Re: RSTP Problem with Bridge VLAN Filtering

If a Mikrotik bridge is set to protocol-mode=none it is not 802.1D compliant as the so-called 'slow protocols' which include STP, LACP, etc. are forwarded between ports which is likely the cause of your problem. This is actually useful in some scenarios, but not here. As you are using the 'old style...
by tdw
Wed May 11, 2022 2:11 pm
Forum: Beginner Basics
Topic: poor bridge/vlan throughput
Replies: 8
Views: 1573

Re: poor bridge/vlan throughput

Between devices on the same VLAN you are bridging layer 2 traffic, a Mikrotik which supports hardware-offloading on a vlan-aware bridge will pass this at wire speed. Between devices on different VLANs you are routing layer 3 traffic, this is limited by the CPU performance of the Mikrotik unless you ...
by tdw
Mon May 09, 2022 9:40 pm
Forum: Beginner Basics
Topic: Remote Access Local PPPOE client
Replies: 1
Views: 1107

Re: Remote Access Local PPPOE client

Does the PPPoE router allow remote management and ping on its WAN port? What firewall rules are on your Mikrotik PPPoE server?
by tdw
Sun May 08, 2022 1:42 am
Forum: Beginner Basics
Topic: Routerboard hEX PoE lite (RB750UPr2) - PoE max speed
Replies: 6
Views: 1016

Re: Routerboard hEX PoE lite (RB750UPr2) - PoE max speed

That device has fast ethernet (10/100Mbit) interfaces, not gigabit.
by tdw
Fri May 06, 2022 7:01 pm
Forum: Beginner Basics
Topic: DHCP working only in few VLANS
Replies: 8
Views: 1910

Re: DHCP working only in few VLANS

I'm misremembering where things should go. On the controller under /caps-man configuration the datapath.bridge= setting should be left blank/unset. On the CAP under /interface wireless cap the bridge= setting should be the name of the bridge on the CAP.
by tdw
Thu May 05, 2022 5:51 pm
Forum: Beginner Basics
Topic: DHCP working only in few VLANS
Replies: 8
Views: 1910

Re: DHCP working only in few VLANS

What is the configuration on the APs? With CAPsMAN local-forwarding=yes the datapath.bridge= specifies the name of the bridge on the AP NOT on the controller. The bridge names on the AP and controller can be the same or different, you just have to use the correct name if they are different. There ma...
by tdw
Wed May 04, 2022 7:27 pm
Forum: Wireless Networking
Topic: Capsman and advertise ipv6dns to clients [SOLVED]
Replies: 13
Views: 2010

Re: Capsman and advertise ipv6dns to clients [SOLVED]

Yes, but with a rather different configuration - v6.48.6; ND has advertise-dns=no , as this version does not allow the offered DNS servers to be configured, and other-configuration=yes ; DNSv6 addresses provided by DHCP option 23. Additionally no capsman, as the radios are configured directly, but t...
by tdw
Wed May 04, 2022 5:42 pm
Forum: Beginner Basics
Topic: MikroTik hAP Lite as OVPN Client [SOLVED]
Replies: 2
Views: 1747

Re: MikroTik hAP Lite as OVPN Client [SOLVED]

Likely you have selected the wrong certificate for the OVPN client - it should be the client certificate, not the CA or server certificate. The CA and any intermediate certs used by the server only have to be installed under System > Certificates so the can be found when Verify Server Certificate is...
by tdw
Tue May 03, 2022 11:23 pm
Forum: General
Topic: IPv6 help needed
Replies: 4
Views: 745

Re: IPv6 help needed

It depends on what your configuration was previously, it may be incorrect and just happened to work accidentally. In particular DHCPv6 has no mechanism to obtain or provide a default gateway. The Mikrotik DHCPv6 client add-default-route=yes is a hacky bodge, it uses the address of the DHCPv6 server ...
by tdw
Tue May 03, 2022 11:07 pm
Forum: General
Topic: Login with freeradius -> openldap
Replies: 1
Views: 1270

Re: Login with freeradius -> openldap

I can't recall what was used previously, from the changelog... MAJOR CHANGES IN v6.43: !) radius - use MS-CHAPv2 for "login" service authentication; I suspect transporting plain-text credentials over plain RADIUS only protected by a simple secret was considered a bad idea. You are correct ...
by tdw
Tue May 03, 2022 12:35 pm
Forum: Beginner Basics
Topic: IPv6 Address Pool decision
Replies: 4
Views: 1080

Re: IPv6 Address Pool decision

Last time I tried, probably on 6.48.6, with a /48 it didn't appear to work, may be different in v7.
by tdw
Mon May 02, 2022 11:07 pm
Forum: Beginner Basics
Topic: IPv6 Address Pool decision
Replies: 4
Views: 1080

Re: IPv6 Address Pool decision

You can't, as discussed in several forum topics. It would be nice if you could do
/ipv6 address
add address=::50:0:0:0:1 from-pool=provider interface=vlan50
by tdw
Mon May 02, 2022 7:07 pm
Forum: Wireless Networking
Topic: Capsman and advertise ipv6dns to clients [SOLVED]
Replies: 13
Views: 2010

Re: Capsman and advertise ipv6dns to clients [SOLVED]

Maybe viewtopic.php?t=157341 although odd that it affects DNS but not the gateway.
by tdw
Sat Apr 30, 2022 2:26 pm
Forum: General
Topic: IPv6 Default route invalid?
Replies: 4
Views: 2553

Re: IPv6 Default route invalid?

To expand on the WAN-side configuration... DHCPv6 has no mechanism to obtain or provide a default gateway. The Mikrotik DHCPv6 client add-default-route=yes is a hacky bodge, it uses the address of the DHCPv6 server from which the address/prefix/other information was received - this works if the DHCP...
by tdw
Fri Apr 29, 2022 10:56 pm
Forum: Beginner Basics
Topic: False dynamic route
Replies: 9
Views: 1113

Re: False dynamic route

You still incorrectly have gateways set to interfaces, not addresses. Post the output of /export hide-sensitive after redacting any public IP addresses, etc.
  • 1
  • 2
  • 3
  • 4
  • 5
  • 7