Community discussions

MikroTik App

Search found 1376 matches

by pcunite
Thu May 12, 2022 3:22 pm
Forum: Announcements
Topic: NEWSLETTER 105
Replies: 56
Views: 46139

Re: NEWSLETTER 105

I hope that the new logo is just a bad joke. It must be...

I think it looks really nice. Very professional, tidy, and to the point. The new font is really nice.
by pcunite
Thu May 12, 2022 3:21 pm
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 81974

Re: v7.2.2 [stable] and v7.2.3 [stable] are released!

Known issues are forum tribal know-how distributed among thousands of forum entries and hidden behind a poor forum search ...It is no wonder the same issues and bugs are reported and asked about again and again ... I really enjoy MikroTik products personally, but can hardly recommend them to others...
by pcunite
Fri May 06, 2022 2:46 am
Forum: Beginner Basics
Topic: VLANs on CRS326 - how hard can this be?
Replies: 3
Views: 828

Re: VLANs on CRS326 - how hard can this be?

See my signature.
by pcunite
Thu May 05, 2022 1:21 am
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 81974

Re: v7.2.2 [stable] and v7.2.3 [stable] are released!

@ work, we run everything v6, except 1 device with v7 for WireGuard.

Same. Needed to provide VPN (WireGuard) for a client so I went with a dedicated device running v7.2.1.
by pcunite
Wed May 04, 2022 8:09 pm
Forum: RouterBOARD hardware
Topic: Device request CRS318-16P-2S+RM
Replies: 12
Views: 1656

Re: Device request CRS318-16P-2S+RM

Is unapproved because you do not use two C14, one for low, and one for high voltage... :roll:

:-p
by pcunite
Wed May 04, 2022 4:39 pm
Forum: RouterBOARD hardware
Topic: Device request CRS318-16P-2S+RM
Replies: 12
Views: 1656

Re: Device request CRS318-16P-2S+RM

I requested one but named it incorrectly.
by pcunite
Tue May 03, 2022 7:09 pm
Forum: General
Topic: Best ACCESS POINT
Replies: 12
Views: 2326

Re: Best ACCESS POINT

I'm not an expert on wifi products from MikroTik, but I have done a large rollout. I used about twenty wAP ac units and two NetMetal ac2 units. We covered a campus of about ten buildings. Client had 30/30 fiber to the premises in a remote area. However, I've not used MikroTik in wifi in noisy (radio...
by pcunite
Mon May 02, 2022 10:15 pm
Forum: RouterBOARD hardware
Topic: Is 'wAP R ac' + 'R11e-LTE-US' good choice for US/Canada?
Replies: 3
Views: 928

Re: Is 'wAP R ac' + 'R11e-LTE-US' good choice for US/Canada?

I'm working on a product and testing with the wAP R ac. I'm sure you're familiar with the other notable hardware options. I'll probably go with the Netmetal 5 ac. Yes, I think its fine for what it is, a fully enclosed unit. For my needs, I will need a different modem too. Probably going to go with t...
by pcunite
Mon May 02, 2022 7:04 pm
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 81974

Re: v7.2.2 [stable] is released!

Having developed SW myself for many years, I really wonder how MT manages to produce such blunders again and again. Sorry MikroTik, but something with your SW dev and test processes is more than broken. I have a software development background too. There is a lot to like about MikroTik. If we step ...
by pcunite
Fri Apr 29, 2022 9:57 pm
Forum: Forwarding Protocols
Topic: Multi WAN Connection Tracking
Replies: 17
Views: 3171

Re: Multi WAN Connection Tracking

IDK how to do that...? From within the Winbox GUI tool, open up the menu item "New Terminal". Then type the following command: export file="Export.rsc" . Then navigate to the "Files" menu option and you'll note the newly exported configuration. Right click on it and do...
by pcunite
Fri Apr 29, 2022 9:38 pm
Forum: Forwarding Protocols
Topic: Multi WAN Connection Tracking
Replies: 17
Views: 3171

Re: Multi WAN Connection Tracking

This was the answer! Thank you so much tdw and mrz for you assistance! Once I added the rest of the mark rules the routing I had already setup worked. I've been working on this for WAY too long and you all got me where I needed to be. Thanks! May I see your configuration? I'm in this same boat and ...
by pcunite
Wed Apr 27, 2022 4:19 pm
Forum: RouterBOARD hardware
Topic: Best Device for duel sim with failover
Replies: 1
Views: 566

Re: Best Device for duel sim with failover

Not qualified to answer the question yet. I'm going through the process of setting up failover to cellular with a wAP R ac . Final solution will probably be a NetMetal ac2 or LtAP . I'm working with three ISP WAN connections at the moment: PPPoE over 2.4Ghz, cellular, and a T1. I think that within t...
by pcunite
Wed Apr 27, 2022 4:03 am
Forum: RouterBOARD hardware
Topic: Device request CRS318-16P-2S+RM
Replies: 12
Views: 1656

Re: Device request CRS318-16P-2S+RM

Yes, need it.
by pcunite
Sat Apr 23, 2022 6:54 am
Forum: Useful user articles
Topic: Isn't there any moderator/support section? Topic is solved
Replies: 38
Views: 7571

Re: Isn't there any moderator/support section? Topic is solved

Recently there's this new wave of "smart" spammers ...

Excellent observation. I noticed something off too in certain posts and wondered what the end-game was. It is always about the link.
by pcunite
Thu Apr 14, 2022 5:42 pm
Forum: Wireless Networking
Topic: T-Mobile Band 71 (600mhz) & Mikrotik Router?
Replies: 4
Views: 1588

Re: T-Mobile Band 71 (600mhz) & Mikrotik Router?

Any success with the Quectel EC25 line of Mini PCIe cards installed in a MikroTik wAP R or NetMetal ac²? The EC25-AFX has B14 and B71 support. The EC25-AF does not include B71 (looking at their PDF anyway). Personally, I need B14 for FirstNet use on ATT.
by pcunite
Thu Apr 14, 2022 3:22 pm
Forum: Wireless Networking
Topic: FirstNet (Public Safety)
Replies: 1
Views: 657

FirstNet (Public Safety)

Does MikroTik make a cellular modem compatible product for use with FirstNet (Public Safety)? I need Band B14 support. Also, is there a miniPCIe LTE CAT6 modem with B14 support that I could install in something like a wAP R, LtAP mini, or NetMetal ac²?
by pcunite
Thu Apr 14, 2022 4:52 am
Forum: General
Topic: mikrotik website down?
Replies: 7
Views: 760

Re: mikrotik website down?

Yes, same.
by pcunite
Tue Apr 12, 2022 1:20 am
Forum: Announcements
Topic: v7.2.1 [stable] is released!
Replies: 240
Views: 46834

Re: v7.2.1 [testing] is released!

Would this fix be related to running scripts such as the ATT gateway bypass? My ATT gateway bypass was broken in 7.2 but working in 7.1.5 EDIT: Just tested on an RB4011, ATT gateway script still not working. Reverted back to 7.1.5.

What error are you getting?
by pcunite
Mon Apr 11, 2022 4:36 pm
Forum: Announcements
Topic: NEWSLETTER 105
Replies: 56
Views: 46139

Re: NEWSLETTER 105

The new logo, youtube channel, and better community outreach is good. Being in the forums is a good thing. I would also like to see maybe one resource (a person) who's focus is exploring common use cases with MikroTik products. They will write verbose documentation and maybe videos on these subjects...
by pcunite
Mon Apr 11, 2022 4:26 pm
Forum: Announcements
Topic: v7.2.1 [stable] is released!
Replies: 240
Views: 46834

Re: v7.2.1 [testing] is released!

Or, you can do what many people do: wait for some brave souls to install and test it and report the experience.

I like to wait about six months to a year before touching MikroTik firmware ... with a feather.
by pcunite
Fri Feb 04, 2022 8:58 pm
Forum: SwOS
Topic: Mikrotik CRS317-1G-16S+RM weird VLAN issue
Replies: 2
Views: 5336

Re: Mikrotik CRS317-1G-16S+RM weird VLAN issue

Can you try using RouterOS 6.48.6 Long-term?
by pcunite
Wed Jan 12, 2022 6:37 pm
Forum: General
Topic: WireGuard Best Practices
Replies: 18
Views: 6514

Re: WireGuard Best Practices

@pcunite: Keys, not certificates.

Thank you for the correction. Nebula is worth a look.
by pcunite
Tue Jan 11, 2022 9:10 pm
Forum: General
Topic: WireGuard Best Practices
Replies: 18
Views: 6514

Re: WireGuard Best Practices

So, what is the best practice? How many support engineers do you have? How many end users (total devices)? 1-100 end devices: Option A: Single server key. 100-1000 end devices: Option B: Multiple server key, 1 server per 100. 1000+ end devices: Option C: Multiple server key, 1 server per device, pl...
by pcunite
Tue Jan 11, 2022 8:14 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 275
Views: 507041

Re: Using RouterOS to QoS your network - 2020 Edition

That would also mean I should apply the same thinking for Wifi devices. Exclude the ethernet port I use for the AP from QoS on the Switch, and let the WiFi QoS be handled by the AP. If the AP hardware can handle it. However, if the AP has a fast connection to the switch or router, then let the rout...
by pcunite
Tue Jan 11, 2022 7:47 pm
Forum: General
Topic: WireGuard Best Practices
Replies: 18
Views: 6514

Re: WireGuard Best Practices

I think your question is the answer. It depends, doesn't it? At least until WireGuard is truly everywhere and automated tools are available to update clients somehow. I only have limited experience with WireGuard, but am currently using an RPi server, behind the router. I would of course like to see...
by pcunite
Tue Jan 11, 2022 4:38 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 275
Views: 507041

Re: Using RouterOS to QoS your network - 2020 Edition

Not really understanding this text from the help. Is it saying one should implement QoS on the Switch instead of the Router? Theory, best practices, and what you need. It's all a balancing act. As a rule, you should QoS as close to the end device as possible. Consider what would happen if you had c...
by pcunite
Mon Jan 03, 2022 11:26 pm
Forum: General
Topic: RouterOS bridge mysteries explained
Replies: 86
Views: 27277

Re: RouterOS bridge mysteries explained

May I join this discussion as to why ? From the very beginning, and even now, the bridge, bridge port is confusing. It will always be confusing because it is an insufficient abstraction for the people who use it. This is why @sindy can not make it any clearer. No one more capable and patient than hi...
by pcunite
Fri Dec 31, 2021 10:31 pm
Forum: General
Topic: PSE-8 and PSE-24 boards
Replies: 18
Views: 3865

Re: PSE-8 and PSE-24 boards

Ugh, need a PSE-8 for a CRS112. Seems a shame. Only port 8 does not put out PoE correctly.
by pcunite
Fri Dec 31, 2021 10:13 pm
Forum: RouterBOARD hardware
Topic: I really need POE for this CRS312-4C+8XG-RM
Replies: 12
Views: 5973

Re: I really need POE for this CRS312-4C+8XG-RM

How many ports? How many watts? PoE++ (802.3bt) is 60W or 100W. Driving that much power, what use case? Might be cheaper to build a shelf with injector bricks for just what you need. Cisco Catalyst 9300 UPoE offerings PoE Texas GBT-24-M PoE Texas GBT-24-M-53V3000W Planet Tech UPOE-1600G FS.com S5860...
by pcunite
Fri Dec 31, 2021 9:43 pm
Forum: General
Topic: Nasty bug with Procurve switchs - STP - GVRP
Replies: 4
Views: 2617

Re: Nasty bug with Procurve switchs - STP - GVRP

Weird ... this could potentially be exploited to create a Denial of Service, assuming you can make them act funny from user accessible Access ports.
by pcunite
Wed Dec 29, 2021 4:31 am
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 275
Views: 507041

Re: Using RouterOS to QoS your network - 2020 Edition

Do you have any plans to release an updated 2021 (or 2022) guide for QoS that focuses on RouterOS 7.1.1 and CAKE / FQ_Codel? I wouldn't say I have plans. Have not really used v7 enough. I'll wait until it is more mainstream unless I find some pressing need for it. WireGuard is very interesting to m...
by pcunite
Wed Dec 15, 2021 4:08 pm
Forum: General
Topic: Feature Request Switches
Replies: 6
Views: 1631

Re: Feature Request Switches

I just remembered that I found and rejected such a switch before buying the CRS328 ... Agree, the CRS328 is just about the only PoE switch in MikroTik's lineup worth buying (outside of outdoor models). I mean, the goofy 8 port with two power supplies that you have to mount somewhere? I think its re...
by pcunite
Tue Dec 14, 2021 8:56 pm
Forum: General
Topic: Feature Request Switches
Replies: 6
Views: 1631

Re: Feature Request Switches

The CRS328-24P-4S+RM is a nice switch, but way too big. Need a short depth version. The CRS326-24G-2S+RM is due an upgrade to 4 SFP+ ports.
by pcunite
Tue Dec 07, 2021 10:00 pm
Forum: General
Topic: find switch port with fluke
Replies: 8
Views: 1960

Re: find switch port with fluke

The MikroTik Neighbor Discovery protocol may not be propagating correctly based on allowed interfaces. Especially so with VLAN. In In the Winbox GUI, go to IP / Neighbor List / Discovery Settings and observe.
by pcunite
Tue Dec 07, 2021 9:48 pm
Forum: RouterBOARD hardware
Topic: MikroTik RB5009UG+S+IN
Replies: 202
Views: 93079

Re: MikroTik RB5009UG+S+IN

I plan to buy some fiber optic SFP+ modules for my RB5009. Do you have any tips, for normal user please? I've been working with fiber a great deal lately and have some experience and advice. I have an opinion that I think is applicable to what even a home user should consider. Cost is a considerati...
by pcunite
Tue Sep 14, 2021 9:38 pm
Forum: Wireless Networking
Topic: Motel internet infrastructure
Replies: 12
Views: 2026

Re: Motel internet infrastructure

Find a professional who will use MikroTik. Then yes, wire in all the AP's back to a central switch. The switch in turn will be controlled by a MikroTik router. Always MikroTik, all the time. Working on an installation now with twenty wAP AC units. Going well.
by pcunite
Fri Sep 10, 2021 9:51 pm
Forum: General
Topic: MikroTik news and rumours – Chateau 5G & cAP ac XL
Replies: 12
Views: 2605

Re: MikroTik news and rumours – Chateau 5G & cAP ac XL

The exterior design is fine, don't want them to even look like something conspicuous. However, 16mb, and lack of new specs. Well, you can see the response from their customer base.
by pcunite
Thu Sep 09, 2021 1:12 am
Forum: Announcements
Topic: Newsletter 101
Replies: 43
Views: 20690

Re: Newsletter 101

What is up with MikroTik hardware production? Nobody has parts in stock and its getting pushed to December. Like the CRS328 PoE switch.
by pcunite
Fri Aug 20, 2021 3:05 pm
Forum: Announcements
Topic: Newsletter 101
Replies: 43
Views: 20690

Re: Newsletter 101

No need for IPSec because Wireguard rules the world now … the RB5009 is not enterprise gear where IPSec is the standard … home users love 💕 WireGuard. SMB will also love wireguard …. It’s becoming a WireGuard world. Agreed, the push is on. I'm using it, nay, forcing its use. :-) I did have an issue...
by pcunite
Thu Aug 19, 2021 5:08 pm
Forum: General
Topic: New to Mikrotik - need help
Replies: 12
Views: 1098

Re: New to Mikrotik - need help

If I may, I hope I can help to clear up some confusion. We can help you better if you speak more about your application and less about networking. Sindy can handle that part for you, he is an expert in that domain. So, reading between the lines, it seems like you might be linking GMRS repeaters over...
by pcunite
Thu Aug 19, 2021 4:31 pm
Forum: General
Topic: Help to export certificates
Replies: 5
Views: 8917

Re: Help to export certificates

Can you do it in the GUI Winbox interface?
by pcunite
Thu Aug 05, 2021 5:07 am
Forum: Beginner Basics
Topic: Dual WAN Failover Script Ping Command [SOLVED]
Replies: 33
Views: 24095

Re: Dual WAN Failover Script Ping Command [SOLVED]

pcunite, I do not understand what you are discussing regarding clearing connections. Is this something I should be worried about on my setup? Well, I don't know. It comes down to how ISP1 fails and the applications you are using. After the failover to the different ISP, if your application times ou...
by pcunite
Wed Aug 04, 2021 10:05 pm
Forum: Beginner Basics
Topic: Dual WAN Failover Script Ping Command [SOLVED]
Replies: 33
Views: 24095

Re: Dual WAN Failover Script Ping Command [SOLVED]

I do not insist further, I have already written you the script that does the right job, based on the real traffic of equipment in production and not only theoretically simulated. Its okay, I can sort it out. If you have a ping session, not stop (ping 8.8.8.8 -t), when the change over occurs it will...
by pcunite
Wed Aug 04, 2021 6:52 am
Forum: Beginner Basics
Topic: Dual WAN Failover Script Ping Command [SOLVED]
Replies: 33
Views: 24095

Re: Dual WAN Failover Script Ping Command [SOLVED]

If just one connection on connection tracking is already closed for timeout (or other reasons) during the execution of the clean, the script will stop with error because the connection is already closed, and do not finish his works. Okay, if that is the case, would it be possible to close connectio...
by pcunite
Wed Aug 04, 2021 4:38 am
Forum: RouterOS beta
Topic: Feature Request: Shared VLAN Learning (SVL)
Replies: 2
Views: 1324

Re: Feature Request: Shared VLAN Learning (SVL)

Can you provide a link to the document you are referring to? What I understand about the benefits of an Asymmetric VLAN ( after searching ) is that you can have two VLANs in the same broadcast domain. You don't need a router as packets actually get switched. You can have a custom MAC table with two ...
by pcunite
Wed Aug 04, 2021 3:56 am
Forum: Beginner Basics
Topic: Dual WAN Failover Script Ping Command [SOLVED]
Replies: 33
Views: 24095

Re: Dual WAN Failover Script Ping Command [SOLVED]

rextended, Oh my goodness. This is awesome! It works excellent. You should make a separate post about WAN Failover and update the link in your signature to point to that new dedicated topic. It takes a good while to write up topics, so no pressure. Just a grateful user. Note, I changed the timeout t...
by pcunite
Tue Aug 03, 2021 9:23 pm
Forum: Beginner Basics
Topic: Dual WAN Failover Script Ping Command [SOLVED]
Replies: 33
Views: 24095

Re: Dual WAN Failover Script Ping Command [SOLVED]

Clear connection-tracking is needed because remote address unreachable do not cause the clear of connection-tracking. What access method you use? Thank you anav and rextended for your examples and help on this subject. I'm testing in a lab using two simple MikroTik units. So, my connection method i...
by pcunite
Tue Aug 03, 2021 6:11 am
Forum: Beginner Basics
Topic: Dual WAN Failover Script Ping Command [SOLVED]
Replies: 33
Views: 24095

Re: Dual WAN Failover Script Ping Command [SOLVED]

The WAN fail over technique works properly if I clear connection tracking. Otherwise, the network appears to timeout. I tested with a long ping session to a remote host and a VPN session. Disabling the interface will automatically clear connection tracking and makes the fail over occur right away. S...
by pcunite
Sat Jul 24, 2021 4:21 am
Forum: Virtualization
Topic: Is there a guide on how to size the VM for CHR?
Replies: 5
Views: 6311

Re: Is there a guide on how to size the VM for CHR?

You could take a look at bundles made by others to get a sense of what you might need. Here is one from r0c-n0c for example.
by pcunite
Fri Jul 23, 2021 4:15 pm
Forum: Wireless Networking
Topic: wireless redirection [SOLVED]
Replies: 4
Views: 1834

Re: wireless redirection [SOLVED]

Use two (optionally) QR codes. One to connect to your free wifi, and the other to open a web link (the menu at http:10.0.10.5/index.html or whatever).
by pcunite
Tue Jul 20, 2021 4:06 am
Forum: General
Topic: WireGuard server behind NAT (MikroTik router)
Replies: 2
Views: 5118

Re: WireGuard server behind NAT (MikroTik router)

Thank you anav, I will look into your notes and see how I comply.
by pcunite
Mon Jul 19, 2021 11:29 pm
Forum: General
Topic: WireGuard server behind NAT (MikroTik router)
Replies: 2
Views: 5118

WireGuard server behind NAT (MikroTik router)

I have a WireGuard server (Ubuntu 20.04) running behind a MikroTik router at remote Network B. It seems to work well, with one exception I would like your thoughts on. I'm getting a " Destination host unreachable " reply (which shows up as an invalid packet in a firewall rule), but only fo...
by pcunite
Wed Jul 14, 2021 9:19 pm
Forum: RouterBOARD hardware
Topic: CRS328-24P-4S+RM idle power consumption
Replies: 6
Views: 7803

Re: CRS328-24P-4S+RM idle power consumption

I have been testing the CRS328-24P-4S+RM and its power characteristics with a P4400 Kill-A-Watt meter. Firmware 6.47.10 installed. Power draw: 1) 19 watts, when powered on, nothing plugged into ports, the idle state. 2) 20 watts, when one SFP+ plugged into an available port. 3) 24 watts, when all SF...
by pcunite
Tue Jul 13, 2021 3:56 pm
Forum: Useful user articles
Topic: RingCentral QoS for Mikrotik Devices
Replies: 5
Views: 6968

Re: RingCentral QoS for Mikrotik Devices

Good to see this. I use MikroTik for several reasons, but getting VoIP correct is a big part of that.
by pcunite
Mon Jul 12, 2021 7:15 pm
Forum: General
Topic: "antenna gain" missing in 6.46.8?
Replies: 83
Views: 30287

Re: "antenna gain" missing in 6.46.8?

All of this happens automatically. I was just explaining what happens. For most of the world, you will want to run within Regulatory limits. Set country, all other stuff will be automatic. Just to confirm ... I'm installing 20 wAP AC's at a client site. Naturally, the power might need to be turned ...
by pcunite
Sat Jul 10, 2021 1:02 am
Forum: RouterOS beta
Topic: L3HW User Manual Updated
Replies: 16
Views: 4506

Re: L3HW User Manual Updated

I still don't fully understand why PVID setting is mandatory in practice. @raimondsp writes that omitting to set it keeps the default setting of pvid=1 (which we already know very well), but the argument about bridging the port with other ports with pvid=1 seems moot to me if frame-types property i...
by pcunite
Thu Jul 08, 2021 3:38 pm
Forum: RouterOS beta
Topic: L3HW User Manual Updated
Replies: 16
Views: 4506

Re: L3HW User Manual Updated

Thank you, excited about the changes, wireguard too.
by pcunite
Thu Jul 08, 2021 12:30 am
Forum: RouterBOARD hardware
Topic: Internal power supplies instead of wall warts
Replies: 9
Views: 3152

Re: Internal power supplies instead of wall warts

I think the annoying thing about wall warts is how to properly rack them. If there was a way to tie the wall wart to the back or side of the MikroTik device, that would be enough for most of us.

Yep. Would like to have a standard (another one?) so as to make them easy to manage and replace.
by pcunite
Sat Jul 03, 2021 7:26 pm
Forum: Beginner Basics
Topic: Tunneling VLAN traffic over Wireguard
Replies: 18
Views: 9356

Re: Tunneling VLAN traffic over Wireguard

AFAIK Wireguard is a layer 3 VPN so there is no concept of VLANs - it will route packets between different subnets at each end and firewall rules can be used to restrict which subnets can communicate with each other. If you really need to extend the layer 2 domain then VxLAN, GRETAP or in the Mikro...
by pcunite
Sat Jul 03, 2021 7:25 pm
Forum: RouterBOARD hardware
Topic: Holes at the low end of the CRS product line
Replies: 10
Views: 3004

Re: Holes at the low end of the CSR product line

Part of a nine building fiber rollout. Need switches with at least three SFP+ ports on them, PoE for 12'ish devices and short depth. Not unreasonable. The CRS328 is just total overkill.
by pcunite
Fri Jul 02, 2021 7:45 pm
Forum: Beginner Basics
Topic: Tunneling VLAN traffic over Wireguard
Replies: 18
Views: 9356

Re: Tunneling VLAN traffic over Wireguard

Hi pcunite, I too contemplated using the raspberry pi for WG but I think your throughput will suffer if using that device?? The Raspberry Pi might not have enough horsepower, I don't know yet. I was using it as a test. Could build a Ubuntu system if necessary. Would also consider using MikroTik har...
by pcunite
Fri Jul 02, 2021 4:30 pm
Forum: Beginner Basics
Topic: CRS326-24S+2Q+: IGMP-Snooping, Bridges, VLAN
Replies: 6
Views: 1345

Re: CRS326-24S+2Q+: IGMP-Snooping, Bridges, VLAN

Not familiar with your use case.
by pcunite
Fri Jul 02, 2021 4:27 pm
Forum: Beginner Basics
Topic: Tunneling VLAN traffic over Wireguard
Replies: 18
Views: 9356

Re: Tunneling VLAN traffic over Wireguard

Nice! For the corporate side, you could simply install Wireguard on any Linux instance and port-forward to it instead of having an extra MikroTik device (unless you want or need to of course). I have done this before and it's been very stable and reliable for my usage pattern (mind you, less than 5...
by pcunite
Fri Jul 02, 2021 4:19 pm
Forum: RouterBOARD hardware
Topic: Holes at the low end of the CRS product line
Replies: 10
Views: 3004

Re: Holes at the low end of the CSR product line

Why shouldn't the CRS112-8P-4S-IN be upgraded for SFP+ now that the cost delta for SFP+ has dropped so far? Agreed. The CRS112 is a funny thing with its 8 ethernet, yet 4 SFP? A tiny switch yet you need two power supplies to make it work for all PoE needs. It is an ungainly thing. The CRS326 is wha...
by pcunite
Fri Jul 02, 2021 6:10 am
Forum: Beginner Basics
Topic: Tunneling VLAN traffic over Wireguard
Replies: 18
Views: 9356

Re: Tunneling VLAN traffic over Wireguard

I will soon be looking into a solution to enable remote staff to use physical telephony devices (VoIP phones) alongside their personal laptops running behind their home internet service plans. Allowing them to VPN into the corporate network using Wireguard, running on a MikroTik, is the goal. My thi...
by pcunite
Fri Jul 02, 2021 5:36 am
Forum: SwOS
Topic: CSS610-8G-2S+IN No Link with Cisco H10GB-ACU10M Active DAC
Replies: 10
Views: 8203

Re: CSS610-8G-2S+IN No Link with Cisco H10GB-ACU10M Active DAC

Thank you for the update.
by pcunite
Fri Jul 02, 2021 12:53 am
Forum: RouterBOARD hardware
Topic: Internal power supplies instead of wall warts
Replies: 9
Views: 3152

Re: Internal power supplies instead of wall warts

Have not used it personally, but the Middle Atlantic PD-DC-125R, seems like it would help in a rack with a lot of such equipment. The nice thing about MikroTik, most units can be PoE powered over ether1. So, you can clean up power to them using a single PoE switch.
by pcunite
Sat Jun 19, 2021 5:50 am
Forum: General
Topic: RouterOS questions
Replies: 3
Views: 1052

Re: RouterOS questions

Your question is outside the use case for most of the forum members. That said, seems like the HotSpot feature is what you're asking about. Would need to be customized, I guess.
by pcunite
Sat Jun 12, 2021 1:18 am
Forum: General
Topic: SFP auto disabled due to high temperature
Replies: 7
Views: 3931

Re: SFP auto disabled due to high temperature

Interesting. As another work-around, do you think these types of heatsinks on the SFP module would help?
by pcunite
Fri Jun 11, 2021 5:57 am
Forum: SwOS
Topic: Mikrotik CRS317-1G-16S+RM to cisco 2960
Replies: 3
Views: 6361

Re: Mikrotik CRS317-1G-16S+RM to cisco 2960

Use a generic sfp module from fs.com.
by pcunite
Thu Jun 10, 2021 5:47 am
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 294
Views: 429196

Re: Using RouterOS to VLAN your network

I have a question about security or probably best practices when it comes to VLANs with WIFI: I guess setting all access ports to " admit-only-untagged-and-priority-tagged " is clearer, but is there an actual impact on network security here, or are those just two ways to do the same thing...
by pcunite
Fri Apr 16, 2021 1:26 am
Forum: General
Topic: New hack/bug? User accounts wiped
Replies: 7
Views: 1768

Re: New hack/bug? User accounts wiped

RouterOS version is 6.44.6, device is a CCR1036-8G-2S+

I think 6.44.x was vulnerable, so I don't think this is a new'ish hack. Here is a post about it. I updated to 6.47.x a while back to play it safe.
by pcunite
Fri Apr 16, 2021 1:23 am
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 294
Views: 429196

Re: Using RouterOS to VLAN your network

I disagree, I find it very confusing to have set PVID on the bridge ports and then not put the associated untagged entries on the bridge vlan. When reading a config its dirt easy visually to see what a person has done. It's so difficult to have to double check a config when not seeing the config, e...
by pcunite
Thu Apr 15, 2021 7:28 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 294
Views: 429196

Re: Using RouterOS to VLAN your network

Yes, I think that would be good. I have the same problem with the MikroTik documentation actually. The reason I feel it is bad practice to unnecessarily set the "untagged" port statically in addition to the PVID is when it comes time to make changes, you have to remember to make the chang...
by pcunite
Mon Mar 08, 2021 6:56 pm
Forum: RouterBOARD hardware
Topic: RB4011 (WiFi) and again about the stability of the work.
Replies: 5
Views: 1847

Re: RB4011 (WiFi) and again about the stability of the work.

Well, very sorry to hear of your troubles. I enjoy MikroTik products and I hate to hear such stories. I think if you could, mail it to a forum member who is very familiar with the WiFi side of thing. You know, to offer some proof to help your case. You probably really do have a bad hardware unit. Ho...
by pcunite
Wed Mar 03, 2021 10:04 pm
Forum: RouterBOARD hardware
Topic: New CRS328-16P-4S+RM rumors
Replies: 5
Views: 2327

Re: New CRS328-16P-4S+RM rumors

Not gonna happen. With that port spec, it would be CRS320-16P-4S+RM.

Well, you know how rumors are! Incorrect information. How did you arrive at CRS320?
by pcunite
Wed Mar 03, 2021 8:56 pm
Forum: Wireless Networking
Topic: 25Km distance, devices to get 100+Mbps PTP link?
Replies: 2
Views: 1189

Re: 25Km distance, devices to get 100+Mbps PTP link?

Use the PTP Calulator this link to see options involving frequency and distance.
by pcunite
Wed Mar 03, 2021 8:49 pm
Forum: RouterBOARD hardware
Topic: New CRS328-16P-4S+RM rumors
Replies: 5
Views: 2327

New CRS328-16P-4S+RM rumors

Look at what showed up on my desktop today! Wonder if it is going to be true? I could really use this switch model.



Image
by pcunite
Mon Feb 22, 2021 10:35 pm
Forum: Beginner Basics
Topic: Problem with new 3gb/s connection with RB4011, I can ping but now browse
Replies: 10
Views: 1414

Re: Problem with new 3gb/s connection with RB4011, I can ping but now browse

MikroTik S+31DLC10D module. So, sfp connected between fiberbox and rb4011, network cable between fiberbox and rb4011. What gives you confidence that the SFP is compatible with the fiberbox? Previously you have an RJ45 connection. That SFP module is single mode 1310nm. Is your ISP good with that? Lo...
by pcunite
Mon Feb 22, 2021 9:38 pm
Forum: Beginner Basics
Topic: Problem with new 3gb/s connection with RB4011, I can ping but now browse
Replies: 10
Views: 1414

Re: Problem with new 3gb/s connection with RB4011, I can ping but now browse

All working fine when setting Wan to ether1.

What kind, brand, etc. SFP module are you using in the RB4011's SFP+ slot?
by pcunite
Mon Feb 22, 2021 9:27 pm
Forum: Beginner Basics
Topic: Problem with new 3gb/s connection with RB4011, I can ping but now browse
Replies: 10
Views: 1414

Re: Problem with new 3gb/s connection with RB4011, I can ping but now browse

How do you mean rule out? SFP+ port is set as Wan and then the rest of the network is plugged in ether 1-5. Am i doing something wrong here? No, you're not doing anything wrong. I was just stating that you might try a test with an Ethernet port to verify the issue is with the SFP port and not somet...
by pcunite
Mon Feb 22, 2021 7:04 pm
Forum: Beginner Basics
Topic: Problem with new 3gb/s connection with RB4011, I can ping but now browse
Replies: 10
Views: 1414

Re: Problem with new 3gb/s connection with RB4011, I can ping but now browse

Please try to use ether1 to rule out the SFP module. Report back.
by pcunite
Fri Feb 19, 2021 9:04 pm
Forum: Scripting
Topic: Append Bridge vlan values
Replies: 2
Views: 1368

Re: Append Bridge vlan values

Is there a reason why you explicitly set the untagged= parameter as this will be dynamically populated. I am considering removing lines referencing the untagged member because of the reasons you note. I also needed to set the tagged member as well. I really appreciate the help. I'm looking into how...
by pcunite
Fri Feb 19, 2021 6:12 am
Forum: Scripting
Topic: Append Bridge vlan values
Replies: 2
Views: 1368

Append Bridge vlan values

I'm attempting to set some values under the /interface bridge vlan command, namely the untagged property. Normally, I set this like so: set bridge=BR1 tagged=ether4 [find vlan-ids=10] . However, I need a way to append the value to what is already present. Here's what I've cobbled together so far, bu...
by pcunite
Thu Feb 18, 2021 11:11 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 294
Views: 429196

Re: Using RouterOS to VLAN your network

One thing I do not like about the configuration shown in the examples up at the top (which are otherwise very good) is that it has unnecessary use of the "untagged" setting. @mducharme What if I put in a disclaimer, stating it was unnecessary and handled automatically? This article series...
by pcunite
Thu Feb 18, 2021 11:02 pm
Forum: Wireless Networking
Topic: MİkroTik Wireless Gig+ Test
Replies: 14
Views: 3138

Re: MİkroTik Wireless Gig+ Test

Intel AX200 connected at 1.2Gbit/s at Aruba AP-555 with 80 MHz channel == stable 800 Mbit/s up and down while copy a big file to and from a SMB file server.

Tell the rest of the class what you paid for the Aruba.
by pcunite
Mon Feb 15, 2021 4:42 pm
Forum: Announcements
Topic: v6.47.9 [long-term] is released!
Replies: 73
Views: 47283

Re: v6.47.9 [long-term] is released!

The PoE issue was introduced in 6.46.8, as the comments from that release prove it.

Using a hEX PoE to power two Dahua SD1A203T-GN. PoE set to auto on. Firmware v6.47.9 without issue. I think these units are 2 or 3 years old. Factory firmware was 6.42.7.
by pcunite
Sun Feb 14, 2021 10:40 pm
Forum: RouterBOARD hardware
Topic: Which ROS devices do you expect the most?
Replies: 17
Views: 4481

Re: Which ROS devices do you expect the most?

A CRS326-24G with 4 SFP+ ports. A 16 port ethernet short depth version of the CRS328-24P.
by pcunite
Sat Feb 13, 2021 4:01 pm
Forum: General
Topic: Windows 10 unable to connect to IPSEC/IKE2 VPN
Replies: 6
Views: 6128

Re: Windows 10 unable to connect to IPSEC/IKE2 VPN

See my post here.
by pcunite
Fri Feb 12, 2021 5:33 pm
Forum: Beginner Basics
Topic: Inter-vlan routing and default firewall
Replies: 4
Views: 2542

Re: Inter-vlan routing and default firewall

This surely wins an award as the longest first post ever. Well done simpleIT! You win a prize! Cozy up to a fireplace and read the provided material anav has linked for you. Read slowly, its all there.
by pcunite
Thu Feb 11, 2021 6:58 am
Forum: Beginner Basics
Topic: 10G Port for Uplink
Replies: 2
Views: 1205

Re: 10G Port for Uplink

It might be best for you to read my VLAN tutorial, linked in my signature. Read slowly. It will all make sense. It shows how to mange all devices on the network. How to setup everything from scratch.
by pcunite
Thu Feb 11, 2021 6:31 am
Forum: Wireless Networking
Topic: wAP ac lte kit passthrough to rb4011 with vlans
Replies: 2
Views: 933

Re: wAP ac lte kit passthrough to rb4011 with vlans

You only need to create an SSID that represents each VLAN. See post here for examples.
by pcunite
Wed Feb 10, 2021 5:27 pm
Forum: Announcements
Topic: v6.47.9 [long-term] is released!
Replies: 73
Views: 47283

Re: v6.47.9 [long-term] is released!

I upgraded a hAP mini from 6.47.8 and got the same WiFi problem as with 6.48, fixed by downgrading.

After upgrading RouterOS and RouterBOARD, then doing a reset, then adding back your config via console, do you still have the same issues?
by pcunite
Wed Feb 10, 2021 5:23 pm
Forum: General
Topic: Performance issues with 6.48 and 6.48.1 on ARM/RB4011
Replies: 2
Views: 1342

Re: Performance issues with 6.48 and 6.48.1 on ARM/RB4011

What is the observed behavior under 6.47.9?
by pcunite
Wed Feb 10, 2021 5:12 pm
Forum: Announcements
Topic: v6.47.9 [long-term] is released!
Replies: 73
Views: 47283

Re: v6.47.9 [long-term] is released!

Upgraded from 6.44 and 6.46 and went largely without incident. Mix of RB4011, RB3011, RB2011, hAP ac lite, hEX PoE, CRS112-8P, CRS326-24G, hAP ac, hAP ac², wAP ac, and cAP ac. This feels like a good update. Time will tell. I miss antenna gain on the AP's but at least can get to it via CLI.
by pcunite
Tue Feb 09, 2021 7:14 pm
Forum: Scripting
Topic: Automatic startup mikrotik
Replies: 3
Views: 1571

Re: Automatic startup mikrotik

Use a remotely controllable power outlet, like this, this, or this.
by pcunite
Sat Feb 06, 2021 11:29 pm
Forum: RouterBOARD hardware
Topic: 10G Fiber run of 700m, which SFP+ module and cable?
Replies: 6
Views: 2398

Re: 10G Fiber run of 700m, which SFP+ module and cable?

Thank you! This is very interesting. I do have the option of specifying the cabling. Can I use use simplex single strand LC-LC cables everywhere? Even for short runs? Naturally, I'll do what is cheaper, but to have BiDi duplex over single strand can I buy OS2 9/125, single strand single mode cables ...
by pcunite
Sat Feb 06, 2021 5:13 am
Forum: RouterBOARD hardware
Topic: 10G Fiber run of 700m, which SFP+ module and cable?
Replies: 6
Views: 2398

10G Fiber run of 700m, which SFP+ module and cable?

I have an upcoming project to where I will require a fiber run in excess of 300m. Probably about 620 meters distance. I would like to be able to maintain a 10G link between the buildings if possible. I only have experience with 850nm Dual LC modules (like the S-85DLC05D) with 50/125 OM3 LC-LC style ...
by pcunite
Sat Jan 02, 2021 3:10 am
Forum: General
Topic: VLANs, CAPsMAN and the case of the missing DHCP
Replies: 3
Views: 735

Re: VLANs, CAPsMAN and the case of the missing DHCP

Your example configuration script does not provide enough context. I recommend you study the article you linked first, get it working correctly, before trying to add a CAPsMAN into the mix. The reason you can't broadcast DHCP requests could be because of a couple of reasons. I would need to see how ...
by pcunite
Fri Dec 04, 2020 7:10 pm
Forum: General
Topic: "antenna gain" missing in 6.46.8?
Replies: 83
Views: 30287

Re: "antenna gain" missing in 6.46.8?

normis says: You can adjust Tx-power by selecting "all rates fixed" in Tx Power Mode and afterwards setting a lower Tx power.

Would it be possible to bring back Antenna Gain or something similar? I need a simple way to lower power.
by pcunite
Thu Dec 03, 2020 11:51 pm
Forum: General
Topic: "antenna gain" missing in 6.46.8?
Replies: 83
Views: 30287

Re: "antenna gain" missing in 6.46.8?

Antenna-gain is now a CLI-only parameter.

Why?
by pcunite
Mon Oct 26, 2020 5:10 pm
Forum: Scripting
Topic: Mikrotik Scripting needs to be useful! Requests!
Replies: 5
Views: 1393

Re: Mikrotik Scripting needs to be useful! Requests!

Agree, I wish there was a proper onboard API to control them.
by pcunite
Sun Oct 25, 2020 2:47 am
Forum: Beginner Basics
Topic: Problems with vlan interface [SOLVED]
Replies: 2
Views: 1098

Re: Problems with vlan interface [SOLVED]

Good to hear. The 2011 units are under powered.
by pcunite
Fri Oct 23, 2020 8:25 pm
Forum: General
Topic: CCR2004-1G-12S+2XS - ATT Residential Fiber Termination via ONT
Replies: 3
Views: 1237

Re: CCR2004-1G-12S+2XS - ATT Residential Fiber Termination via ONT

A discussion with interested individuals is occurring here.
by pcunite
Fri Oct 23, 2020 2:08 am
Forum: General
Topic: PSA: Trickbot is using compromised Mikrotik devices. Secure your routers reachable from the internet.
Replies: 18
Views: 3551

Re: PSA: Trickbot is using compromised Mikrotik devices. Secure your routers reachable from the internet.

Unfortunately that is inconclusive. The CVE says "6.41.3 through 6.46.5, and 7.x through 7.0 Beta5" which would potentially include 6.46.1. Unfortunately I've never seen MT publish their software development hierarchy so I'm not sure. Additionally, they haven't posted any further details ...
by pcunite
Thu Oct 22, 2020 11:44 pm
Forum: General
Topic: PSA: Trickbot is using compromised Mikrotik devices. Secure your routers reachable from the internet.
Replies: 18
Views: 3551

Re: PSA: Trickbot is using compromised Mikrotik devices. Secure your routers reachable from the internet.

All MikroTik routers should be running
6.47.4 [stable]
6.46.6 [long-term]
or 7.0beta6 [testing]
due to CVE-2020-11881

Please confirm 6.46.1 (stable) is unaffected.
by pcunite
Thu Oct 22, 2020 12:49 am
Forum: Wireless Networking
Topic: What MT boxes can support spectral scan? - Cheap spectrum analyzer instead? [SOLVED]
Replies: 23
Views: 5779

Re: What MT boxes can support spectral scan? - Cheap spectrum analyzer instead? [SOLVED]

To run the scan on Groove there are prerequisites

Thanks for sharing. To confirm, can't scan on 5Ghz via Winbox? Have to use Dude?
by pcunite
Sat Oct 17, 2020 6:34 am
Forum: General
Topic: HAP AC Wired and Wireless VLAN CPU optimisation
Replies: 8
Views: 1237

Re: HAP AC Wired and Wireless VLAN CPU optimisation

Sure, but does the RB3011 have wifi? I think he wants devices at both sites to provide wifi!

Sorry, yes the hAP AC2 would be better in his scenario.
by pcunite
Fri Oct 16, 2020 12:54 am
Forum: General
Topic: HAP AC Wired and Wireless VLAN CPU optimisation
Replies: 8
Views: 1237

Re: HAP AC Wired and Wireless VLAN CPU optimisation

MikroTik has too many SKUs. For 100mb service, consider the RB3011 or better the RB4011. Hang the Wifi AP's off available ports.
by pcunite
Wed Sep 23, 2020 4:46 pm
Forum: Beginner Basics
Topic: AT&T FTTH, VLANs, CapsMAN Full Config (RouterOS 7 Updated)
Replies: 27
Views: 5313

Re: AT&T FTTH, VLANs, CapsMAN Full Config

Appreciate the great effort here. You have put the work into this. The information about how to configure these devices needs to be more open, more clear, and easily digestible. This will help to move that forward. An entire topic should be spent on Service Discovery between VLANs, I should think.
by pcunite
Wed Sep 23, 2020 4:15 pm
Forum: Announcements
Topic: Newsletter 97 (September 2020)
Replies: 87
Views: 38361

Re: Newsletter 97 (September 2020)

Excellent videos! Good to see the team and the products, puts a human touch behind the brand. Please consider making a 16 port PoE switch as described.
by pcunite
Tue Sep 08, 2020 11:39 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 294
Views: 429196

Re: Using RouterOS to VLAN your network

... getting some pushback of late on the use of pvid and the associated bridge vlan settings ... personally I think its clearer when configuring and reading to have the bridge vlan settings visible. Is there any downside to RELYING on the dynamically generated settings? This is why I initially show...
by pcunite
Tue Sep 01, 2020 3:27 pm
Forum: RouterBOARD hardware
Topic: 16 port short depth PoE switch
Replies: 9
Views: 2169

Re: 16 port short depth PoE switch

No, not RB4011 again ... They really should produce one device with two different cases (IN and RM), just like they did with RB2011 or certain models of CCR1009... The ears on the RB4011 are bad, yes. However, the one that ships with the CRS112 is really nice. But yes, a pure rack-mount would be ap...
by pcunite
Mon Aug 31, 2020 9:22 pm
Forum: RouterBOARD hardware
Topic: 16 port short depth PoE switch
Replies: 9
Views: 2169

Re: 16 port short depth PoE switch

A crs318-16P-2S+ would be great. I would like it in an "IN" desktop form factor, although I am sure a RM version would be popular too.

They could make some ears to accommodate us both. I think it is a needed SKU.
by pcunite
Sat Aug 29, 2020 6:07 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 275
Views: 507041

Re: Using RouterOS to QoS your network - 2020 Edition

@pcunite thanks for doing this. I've noticed a few things that I'd like your input on. @blurrybird, >>why you are detecting VoIP by just blanket accepting 10,000+ ports? The original article was created a long time ago. The VoIP equipment I used at the time used those range of ports. I think it is ...
by pcunite
Fri Aug 28, 2020 11:28 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

I can no longer recommend the RB4011 as I've been getting the issue described here with it hitting 100% CPU, freezing up, etc. I'm at very low load (residential), but still happens what seems like once a month now. Going back to the CCR1009 that I didn't sell, yet, along with the switch. Sorry to h...
by pcunite
Fri Aug 28, 2020 11:25 pm
Forum: RouterBOARD hardware
Topic: 16 port short depth PoE switch
Replies: 9
Views: 2169

16 port short depth PoE switch

I need an improved CRS112-8P-4S-IN rackmount switch. I see that the netPower 16P is close to what I would want, hardware wise, but in an incompatible design for my needs. The CRS328-24P-4S+RM is too big. Any news of a possible CRS328-16P-4S+RM on the horizon?
by pcunite
Fri Aug 28, 2020 11:12 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 275
Views: 507041

Re: Using RouterOS to QoS your network - 2020 Edition

I have been wading thru this thread since the 2013 beginning looking for a "final" recommended way to provide the QoS to make a couple of VOIP phones to work. But that appears not to be. My configuration, as shown, is what you are looking for. It works. I use it on multiple networks. Don'...
by pcunite
Fri Jul 03, 2020 12:15 am
Forum: Beginner Basics
Topic: RB3011 Second Switch as another router
Replies: 2
Views: 1056

Re: RB3011 Second Switch as another router

Absolutely, that is the purpose of this hardware. If you have a speed issue, as pointed out, then you can make adjustments. Keep everything on the same switch group if you can, then it can hit the CPU to get out to WAN. If you need to hit the other bridge, I don't think it will be that bad for one o...
by pcunite
Sat Jun 27, 2020 12:17 am
Forum: Announcements
Topic: MikroTik newsletter May 2020 (#95)
Replies: 50
Views: 43565

Re: MikroTik newsletter May 2020 (#95)

I just find out that netPower 16P is CRS318-16P-2S+OUT. So, we suggest mikrotik can release CRS318-16P-2S+IN-2HnD.

Yes, this could be the update to the CRS112-8P-4S-IN.
by pcunite
Thu Jun 25, 2020 6:54 pm
Forum: General
Topic: Cert cannot be imported on IOS13
Replies: 4
Views: 1584

Re: Cert cannot be imported on IOS13

Things have changed with iOS 13 and macOS 10.15. Study the link. You can use a tool like CertManEX to create these new types or openssl.
by pcunite
Sun May 31, 2020 2:15 am
Forum: Wireless Networking
Topic: Additional Security for Wifi Devices.
Replies: 5
Views: 2471

Re: Additional Security for Wifi Devices.

You can be as restrictive as you feel you need to be. What is the threat vector? Are you protecting access from neighbors (don't have valid access credentials) or clients within (do have credentials)? * Turn the power down to prevent signals escaping the home. Use more low power units to fill in gap...
by pcunite
Thu May 21, 2020 10:01 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

Official Response from MT Support: How would you expect to treat VLAN-ID 0 packets in RouterOS? Should we allow the users to configure a special-purpose VLAN interface that accepts these packets? How should RouterOS respond - with or without VLAN-ID 0 header? Glad to see them thinking about it. I d...
by pcunite
Wed May 20, 2020 10:38 pm
Forum: Beginner Basics
Topic: Assign unique DHCP server to an AP?
Replies: 3
Views: 1062

Re: Assign unique DHCP server to an AP?

Study VLAN techniques as noted in my signature.
by pcunite
Fri May 15, 2020 1:37 am
Forum: General
Topic: Dot1x Client improper start frame version
Replies: 2
Views: 1566

Re: Dot1x Client improper start frame version

Thank you.
by pcunite
Thu May 14, 2020 12:06 am
Forum: RouterBOARD hardware
Topic: What is your opinion of Mikrotik routers?
Replies: 3
Views: 2090

Re: What is your opinion of Mikrotik routers?

I like how they use just enough power to accomplish the goal. I didn't want big beefy hardware, unless I needed it. Take the RB4011 for example, handles 1G fiber service just fine on small networks.
by pcunite
Thu May 14, 2020 12:02 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

The best option would be for the bridge to be able to strip VLAN 0, but isn't that something MT needs to fix?

Its not so much a fix, as it is additional functionality we want.
by pcunite
Fri May 08, 2020 10:12 pm
Forum: RouterBOARD hardware
Topic: RB5011
Replies: 40
Views: 23084

Re: RB5011

+2
Make two case options, a proper rack-mount, and a nice desktop version.
by pcunite
Fri May 08, 2020 10:10 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

I want to clarify with some information provided to me. The ATT Residential RG sends all outgoing packets as 802.1p (tagged with VLAN 0). Their Commercial gateways sends all outgoing packets as 802.1q PVID 2 (tagged with VLAN 2). These are not always enforced, as I understand it. My residential 1G f...
by pcunite
Fri May 08, 2020 6:51 pm
Forum: RouterBOARD hardware
Topic: CCR2004-1G-12S+2XS with more RAM ?
Replies: 15
Views: 8302

Re: CCR2004-1G-12S+2XS with more RAM ?

Can someone measure its idle power usage? Preferably with one or two 10g ports connected (optical sfp+ or DAC).
Also, how loud is it under low load circumstances?

I would like to know as well. Also, if I disconnect the fans, or redundant power, can I get the power usage down?
by pcunite
Fri May 08, 2020 6:37 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

... for CCRs, what model switches have people been using in front it to take care of the vlan 0 tagging?

Ask wojo
by pcunite
Fri May 08, 2020 6:47 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

I'm surprised the hEX/RB750Gr3 isn't recommended especially for people on 300/300 or 100/100. Does it not work well with wpa_supplicant despite having a switch chip?

Recommended just means what most have reported success with. Since the RB4011 is known to work, it is therefore, recommended.
by pcunite
Thu May 07, 2020 11:43 pm
Forum: General
Topic: hAP ac2 board in a difference case?
Replies: 6
Views: 2921

Re: hAP ac2 board in a difference case?

If anyone has an .stl for the RB750 / hEX case, would you mind sharing?

I would like a square case for the cAP AC too.
by pcunite
Thu May 07, 2020 11:42 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

Both? The Bridge Method and the Supplicant Method?

I was referring to the Supplicant Method, only the RB4011 is recommended.
by pcunite
Thu May 07, 2020 6:31 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS, turn off blue LED, still not possible?
Replies: 2
Views: 2353

Re: RB4011iGS, turn off blue LED, still not possible?

What happens when you use a Sharpie pen on it?
by pcunite
Thu May 07, 2020 6:25 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

I have the BGW210 and I was able to downgrade the modem back to firmware 1.0.29 and extracted the keys and certs, then upgraded it back to firmware 2.6.4 and it works fine. My MikroTik router is the CRS125-24G-1S-2HnD ... how do I do that with this router? Only the RB4011 is recommended at this time.
by pcunite
Thu May 07, 2020 6:02 pm
Forum: General
Topic: hAP ac2 board in a difference case?
Replies: 6
Views: 2921

Re: hAP ac2 board in a difference case?

So, I picked up a hEX and ... the boards are identical size and layout - ports, power, usb, LEDs, etc. The hAP board will fit very nicely into the hEX case for anyone interested :-).

Really? Nice find! I had not thought of that. When you say hEX, you mean this one?
by pcunite
Wed Apr 29, 2020 4:25 pm
Forum: Announcements
Topic: MikroTik newsletter May 2020 (#95)
Replies: 50
Views: 43565

Re: MikroTik newsletter May 2020 (#95)

Good to see a desktop version of the CRS3XX line. I need the CRS112-8P-4S-IN upgraded to the CRS3xx hardware and have 16 ports, rackmount or desktop (short depth PoE switch).
by pcunite
Sun Apr 19, 2020 8:33 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 275
Views: 507041

Re: Using RouterOS to QoS your network - 2020 Edition

@pcunite No worries. I'll see if I can rerun the test graphs with the updated baseline when office reopens. I've seen some weird packet issues when using RED for the defaults. So, I've gone back to SFQ for default but use RED for the bulky flows. The behavior of RED as default causes the VoIP queue...
by pcunite
Fri Apr 17, 2020 4:58 pm
Forum: Announcements
Topic: Winbox v3.23 released!
Replies: 60
Views: 49808

Re: Winbox v3.23 released!

Does not preserve chosen interior window sizing and spacing after selecting Session / Save. Windows 10, 125DPI.
by pcunite
Fri Apr 17, 2020 4:16 pm
Forum: Beginner Basics
Topic: No IP Address Acquired
Replies: 30
Views: 21129

Re: No IP Address Acquired

If upstream hardware requires 802.1p, then that ability is not configurable with MikroTik, yet. Instead, you'll need to place a Cisco switch in front of the MikroTik and have it set the bits on the outgoing packets.
by pcunite
Thu Apr 16, 2020 10:46 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 275
Views: 507041

Re: Using RouterOS to QoS your network - 2020 Edition

Set parent queues to have a bucket-size of 0.005. Changed the default queue to sfq . (Using red gave similar performance, but multiple downloads seemed less fair). Rationale for the 0.005 size is to copy CoDel as much as possible. @bharrisau, I've have tested your feedback and have made changes to ...
by pcunite
Tue Apr 14, 2020 6:26 pm
Forum: General
Topic: VLAN offloading
Replies: 25
Views: 6029

Re: VLAN offloading

The hAP ac is a very under powered device. The hAP ac2 is much better for just about everyone not doing something crazy. I use both at different locations. The bugs on the hAP ac2, my understanding, can be avoided if using the pure software approach to VLANs (if doing vlans). Don't try to use the sw...
by pcunite
Tue Apr 14, 2020 6:21 pm
Forum: Beginner Basics
Topic: Packet Priority
Replies: 3
Views: 2437

Re: Packet Priority

See my signature. Note that your hAP ac is under-powered for QoS tasks.
by pcunite
Tue Apr 14, 2020 5:51 pm
Forum: General
Topic: Does QOS on Wan/Download work?
Replies: 9
Views: 3067

Re: Does QOS on Wan/Download work?

You are asking a lot in one post. I'll respond to your conversation points. Have more: It is always ideal to have a faster router and a bigger pipe to manage incoming packets. If you can, always have more available to you than what will ever be sent to you. If applications don't play by the rules, t...
by pcunite
Thu Apr 09, 2020 8:23 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 275
Views: 507041

Re: Using RouterOS to prioritize (Qos) traffic for a Class C

Do you need to mark the connection before mark the packet? Yes/No/Why? Please add some words about this in your second post where you talk about marking. How to use RouterOS to accomplish a task vs. how RouterOS itself works are two different concepts. I only focus on the former. However, everyone ...
by pcunite
Tue Apr 07, 2020 8:34 pm
Forum: Wireless Networking
Topic: Additional AP
Replies: 11
Views: 4815

Re: Additional AP

If you know and understand MikroTik, it is the better option. However, there are situations to where MikroTik (circa 2020) offerings are not the best: Over 50 clients per AP 100Mbps plus data requirements per connected client You will not get the fastest WiFi speed from current MikroTik hardware. In...
by pcunite
Mon Apr 06, 2020 6:56 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS+ 802.1Q VLANs
Replies: 4
Views: 3358

Re: RB4011iGS+ 802.1Q VLANs

This device is expressly created for the purpose of using the CPU and vlans. You should configure it that way.
by pcunite
Fri Mar 27, 2020 1:53 pm
Forum: Wireless Networking
Topic: rb4011 wireless version setting / reboot automatically
Replies: 29
Views: 9427

Re: rb4011 wireless version setting / reboot automatically

I know it is frustrating. The non-wifi model is a great product. Not sure what is happening on the other SKU. I do think it would help to have clear documentation on how to setup the various options. Its possible to create a unwise configuration. The software will happily let you do it.
by pcunite
Sat Mar 21, 2020 4:04 am
Forum: General
Topic: SSL certificate for mynetname domain
Replies: 10
Views: 4930

Re: SSL certificate for mynetname domain

Own certificates are ok, but for own use (personal or some closed group). They are useless for services that have random visitors, because they would have to trust your CA to be able to verify them.

Of course ...
by pcunite
Sat Mar 21, 2020 12:46 am
Forum: General
Topic: Not much of help here
Replies: 2
Views: 1465

Re: Not much of help here

It is fairly commercial here, especially related to the HotSpot feature.
by pcunite
Sat Mar 21, 2020 12:44 am
Forum: General
Topic: SSL certificate for mynetname domain
Replies: 10
Views: 4930

Re: SSL certificate for mynetname domain

I like using my own certificates. To do this, you'll need to create a self-signed Root certificate. Then create all your end entity certs signed by your root. Install your entity certs as normal. Then export the Root, without its private key (in X509v3 DER or PEM format) and install that on all comp...
by pcunite
Fri Mar 13, 2020 11:37 pm
Forum: Announcements
Topic: Winbox v3.22 released!
Replies: 117
Views: 85025

Re: Winbox v3.22 released!

I would still very much like to see the following changes: - easier widget for selection of columns (a modal panel with checkmarks for all possible columns in a "square" layout where multiple checkmarks can be toggled before clicking OK) Agreed, takes way to much effort to deselect all th...
by pcunite
Fri Mar 06, 2020 3:23 pm
Forum: General
Topic: Today - Linus tech tips, MIKROTIK !!!!!
Replies: 2
Views: 3371

Re: Today - Linus tech tips, MIKROTIK !!!!!

Have you gotten around to creating such a series? I'm a home user and looking into using MikroTik. Good to have you here! MikroTik's are a lot of fun. If you get frustrated, we'll try to help. I have not produced the series because I would need compensation for such an endeavor. It takes a very lon...
by pcunite
Sun Mar 01, 2020 3:23 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

@pcunite What about this? However, my concern is that in other posts, I saw that the "bridge" method ATT offers out of the box forces you to use their small NAT tables on the ATT gateway ... is that still the case with this "dumb bridge" method? The bridge method, as shown at th...
by pcunite
Sat Feb 29, 2020 10:45 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

is the only advantage of going with the supplicant method to prevent having the actual ATT Gateway powered on and active at all times?

Basically, yes. If you are willing to keep the ATT RG powered up, then its a very good method.
by pcunite
Tue Feb 25, 2020 5:34 am
Forum: General
Topic: Prioritise Voip traffic using simple queues
Replies: 2
Views: 1604

Re: Prioritise Voip traffic using simple queues

I'm not familiar with simple Queues, never used them. You can see my signature for how I handle this.
by pcunite
Tue Feb 18, 2020 1:35 am
Forum: Scripting
Topic: Find External IP ? [SOLVED]
Replies: 26
Views: 89272

Re: Find External IP ? [SOLVED]

I had a need to do this recently. Here is a full working example that posts JSON to a PHP server and then emails the data. Apply this to your router # Install this script and name it "GetIPAddress" # Enable the scheduler to run once a day and also on boot /system scheduler add name=RunGetI...
by pcunite
Mon Feb 17, 2020 10:28 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 294
Views: 429196

Re: Using RouterOS to VLAN your network

in the topic Switch with a separate router (RoaS), what is the difference between the Switch Config file and the Router Config file?

The two files are the configurations for the two hardware devices that will be in use. One a switch, the other a router.
by pcunite
Fri Feb 14, 2020 3:14 pm
Forum: General
Topic: Large blacklists for firewall
Replies: 37
Views: 9117

Re: Large blacklists for firewall

11K should be fine. I have 4,000 on an RB3011 and its no trouble. Use RAW rules something like this: /ip firewall raw add action=drop chain=prerouting disabled=yes in-interface=ether1 src-address-list=PortScanners add action=add-src-to-address-list address-list=PortScanners address-list-timeout=2w c...
by pcunite
Fri Feb 14, 2020 3:05 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

I can't get a lease. Applied fallback VLAN and it still doesn't work. The RB750Gr3 uses a MT7621 switch chip . The Atheros8227 chips need fallback mode set. For the other types, you might try a different setting. Until MikroTik has a consistent firmware across the hardware lines, we will have to gu...
by pcunite
Wed Feb 12, 2020 5:34 pm
Forum: General
Topic: VLAN for Security Cameras HowTo
Replies: 3
Views: 3978

Re: VLAN for Security Cameras HowTo

I use a similar setup too. Read the article mkx linked to. It will tell you all you need to know. After that, you'll make custom firewall rules. I allow IP Cameras to access NTP servers and nothing else, for example. Take time to really study the article. It won't waste your time.
by pcunite
Mon Feb 10, 2020 4:23 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

I tried this on an RB4011 using certs from an NVG510. Unfortunately I kept getting "rejected" after "authenticating", I did make sure I set the clock properly.

The certs from the NVG510 work for VDSL, but not for fiber service.
by pcunite
Wed Feb 05, 2020 7:09 pm
Forum: General
Topic: 2 Mikrotik Fails in a week reputation tarnished, major opportunity for MT
Replies: 6
Views: 1899

Re: 2 Mikrotik Fails in a week reputation tarnished, major opportunity for MT

What I find so frustrating, and the OP no doubt too, is the lack of documentation for all of these various use cases. It takes a while for a big tree to fall, but when it does, there is no stopping it. Hopefully, MikroTik will think about their brand and the collection of us who really are the face ...
by pcunite
Wed Feb 05, 2020 3:16 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 275
Views: 507041

Re: Using RouterOS to QoS your network - 2020 Edition

Set the two parent queues (UP and DOWN) to have a bucket-size of 0.005. Create a bulkUp queue of kind PCQ, set the pcq-limit to 11*[upload rate in Mbps] (100ms of upload bandwidth) and the pcq-total-limit to 10 times that. Select all 4 classifier options. Create a bulkDown queue of kind sqf. Change...
by pcunite
Wed Feb 05, 2020 3:12 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 275
Views: 507041

Re: Using RouterOS to QoS your network - 2020 Edition

Shouldn't the topic be moved to viewforum.php?f=23?

I'm okay with that. Please keep the original url and redirect it to whatever the new one will be. Also, remove many of the old posts that don't advance the topic, since the new 2020 edition for example.
by pcunite
Fri Jan 31, 2020 5:56 am
Forum: General
Topic: VLAN separation [SOLVED]
Replies: 2
Views: 2734

Re: VLAN separation [SOLVED]

Study the link in my signature until you can quote it from memory. Then ... you will have mastered VLAN separation.
by pcunite
Sat Jan 25, 2020 10:00 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 275
Views: 507041

Re: Using RouterOS to prioritize (Qos) traffic for a Class C

what about when there are several LAN interfaces?

There are several ways, in RouterOS, to combine several things into one. Maybe VLAN, maybe interface lists, maybe address lists. Its up to you. Then you simply mangle them and send them to the queue.
by pcunite
Thu Jan 23, 2020 4:16 pm
Forum: Announcements
Topic: v6.46.2 [stable] is released!
Replies: 120
Views: 63218

Re: v6.46.2 [stable] is released!

Pride comes before a fall. Companies much larger than MikroTik have had to learn this valuable lesson. One more time ... please hire a Product Manager who understands your users.
by pcunite
Wed Jan 22, 2020 3:17 pm
Forum: RouterBOARD hardware
Topic: Update on CRS354 Switches? (moved post)
Replies: 13
Views: 6416

Re: Update on CRS354 Switches? (moved post)

poe variant ???

This is a short depth model, very useful. PoE would be larger and needed too for IP Camera rollouts.
by pcunite
Tue Jan 21, 2020 5:03 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

This is amazing. 802.1x method was incredibly easily once converted to .pem.

Enjoy! It is a really nice solution.
by pcunite
Tue Jan 21, 2020 5:02 am
Forum: RouterBOARD hardware
Topic: Recent batch PSU Failures
Replies: 5
Views: 4597

Re: Recent batch PSU Failures

It is useful for the community to know. Yes, do let MikroTik know directly. They probably source these power supply units and do not make them themselves.
by pcunite
Tue Jan 21, 2020 4:57 am
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 275
Views: 507041

Re: Using RouterOS to QoS your network - 2020 Edition

do you prefer to put highest priority 1 (in my situation game : Apex) to fast track?

Fast Track is CPU usage mitigation technique. Queuing is a bandwidth utilization technique. Different goals. If the CPU can handle it, you need to use Queue technique only.
by pcunite
Mon Jan 20, 2020 10:00 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 275
Views: 507041

Re: Using RouterOS to QoS your network - 2020 Edition

#DOWN
add name=DOWN max-limit=1M parent=LAN queue=default
# UP
add name=UP max-limit=100k parent=WAN queue=default

I will still get : Download Mbps 9.68, Upload Mbps 0.56

How is this possible?

You can not use Fast Track and Queues Tree together.
by pcunite
Mon Jan 20, 2020 5:32 pm
Forum: Announcements
Topic: v6.46.2 [stable] is released!
Replies: 120
Views: 63218

Re: v6.46.2 [stable] is released!

Can anyone post reasonable reason why it's important? Verification that file is downloaded is plain strange.

It breaks the user experience "feedback" expected in the GUI. If I drag'n drop a file into the Files menu, I expect to see something present after the upload progress bar.
by pcunite
Sat Jan 18, 2020 5:07 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

... is buying the certs themselves possible or do I need to specifically buy a NVG510 ... ?

You can purchase certs off eBay.
by pcunite
Fri Jan 17, 2020 7:22 pm
Forum: RouterBOARD hardware
Topic: Update on CRS354 Switches? (moved post)
Replies: 13
Views: 6416

Re: Update on CRS354 Switches? (moved post)

Miro, a South African distributor for MikroTik has this PDF on their website.

Nice find.
by pcunite
Fri Jan 17, 2020 7:09 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

Thank you for your hard work, I want to report a possible bug or perhaps it's AT&T causing this, but lately I can't even go past seven days of uptime before getting "rebinding" or "searching". I then need to restart the router and AT&T Gateway. Since I work night-shift m...
by pcunite
Tue Jan 14, 2020 2:56 am
Forum: General
Topic: How to change Queue Tree max-limit using scheduler scripts? [SOLVED]
Replies: 1
Views: 1540

Re: How to change Queue Tree max-limit using scheduler scripts? [SOLVED]

Post your question under the Scripting section. There is an active group that likes to do that.
by pcunite
Fri Jan 10, 2020 4:15 pm
Forum: Beginner Basics
Topic: Change network name [SOLVED]
Replies: 9
Views: 12334

Re: Change network name [SOLVED]

You'll need to do so in the Registry.
by pcunite
Thu Jan 09, 2020 1:26 am
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 275
Views: 507041

Re: Using RouterOS to QoS your network - 2020 Edition

How to add some TCP ports and prioritize them as VOIP? can I simply do this and it will be enough? Please study the example more closely. VoIP packets on your network will not be the same as others. Using Mangle , you will choose what you need to mark. It could be via IP Address, standard SIP or RT...
by pcunite
Wed Jan 08, 2020 7:42 pm
Forum: General
Topic: Traffic shaping and VLAN's
Replies: 7
Views: 7333

Re: Traffic shaping and VLAN's

I have updated my articles on traffic shaping (QoS). See the link in my signature.
by pcunite
Tue Jan 07, 2020 4:59 pm
Forum: Wireless Networking
Topic: PTMP and VLANS
Replies: 2
Views: 2269

Re: PTMP and VLANS

It is not clear what you are asking for. See the VLAN article in my signature.
by pcunite
Tue Jan 07, 2020 12:49 am
Forum: General
Topic: CCR1009-7G Refuses to Route to Internet
Replies: 2
Views: 1338

Re: CCR1009-7G Refuses to Route to Internet

Post the output (between code tags) of export file="myExport.rsc".
by pcunite
Sat Jan 04, 2020 3:18 am
Forum: General
Topic: VLANs setup (the new way)
Replies: 24
Views: 15964

Re: VLANs setup (the new way)

For the purposes of hooking up a PC on port 4 when needed for management, yes I'd thought leaving it as untagged on VLAN 99 as no-one else will have physical access to this and it was purely a quick way should I be locked out.

Just make ether4 an Access port for VLAN 99.
by pcunite
Fri Jan 03, 2020 10:20 pm
Forum: General
Topic: VLANs setup (the new way)
Replies: 24
Views: 15964

Re: VLANs setup (the new way)

Thanks for the reply, I took the "bridge PVID" part from here . And the wiki is also extremely confusing. If you look closely they are showing you multiple ways to setup management access. You don't truly want to connect to the switch with untagged traffic, do you? In the article you will...
by pcunite
Fri Jan 03, 2020 6:43 pm
Forum: General
Topic: VLANs setup (the new way)
Replies: 24
Views: 15964

Re: VLANs setup (the new way)

Beautiful diagram. I love to see nicely put together information. I am grateful to mkx, sindy, and others for helping me to create the article. I'm not good at editing configurations, and I'm in a rush at the moment, so they'll have to chime in on this one. Something that caught my eye is that your ...
by pcunite
Thu Jan 02, 2020 6:04 pm
Forum: General
Topic: RB4011iGS+RM plus CAP AC - VLANs in the home
Replies: 17
Views: 4420

Re: RB4011iGS+RM plus CAP AC - VLANs in the home

Do you use interface lists more than address lists because of performance? I don't know which is more performant. But I must admit a hate with Address Lists and seeing all those ungainly things showing up there without a way to put them into neat little folders. I would assume, not having access to...
by pcunite
Thu Jan 02, 2020 5:53 pm
Forum: General
Topic: RB4011iGS+RM plus CAP AC - VLANs in the home
Replies: 17
Views: 4420

Re: RB4011iGS+RM plus CAP AC - VLANs in the home

Do you have a more secure example? I'm not the authority on firewall rules. An example would look something like this: # Sample INPUT example limiting Router exposure from the LAN (VLAN) /ip firewall filter add chain=input action=accept connection-state=established,related comment="Allow Estab...
by pcunite
Thu Jan 02, 2020 5:30 pm
Forum: Scripting
Topic: New C++ Connector | MikrotikPlus
Replies: 2
Views: 2711

Re: Brand new C++ Connector

Thank you. I always like to see a C++ implementation of something. Really shows you what is needed and easier to translate to other options too. I don't have a need right now for this, but might in the future.
by pcunite
Thu Jan 02, 2020 5:11 am
Forum: General
Topic: RB4011iGS+RM plus CAP AC - VLANs in the home
Replies: 17
Views: 4420

Re: RB4011iGS+RM plus CAP AC - VLANs in the home

I've taken to downloading all of your examples and putting them in vscode with the MikroTik extension in tabs. ... the "Learn MikroTik book I bought" suggests blowing away the default firewall config and using some of their examples which are slightly different ... they drop invalid conne...
by pcunite
Wed Jan 01, 2020 8:04 pm
Forum: General
Topic: RB4011iGS+RM plus CAP AC - VLANs in the home
Replies: 17
Views: 4420

Re: RB4011iGS+RM plus CAP AC - VLANs in the home

Current Issues I'm trying to solve: internet access on management vlan, printer on vlan60 talk to vlan10, learn better firewall rules All equipment should be on its own VLAN which I call the Base ( MGMT ) VLAN. Do this before you do anything else, and have a PC plugged into this VLAN so you can adm...
by pcunite
Tue Dec 31, 2019 5:11 am
Forum: General
Topic: RB4011iGS+RM plus CAP AC - VLANs in the home
Replies: 17
Views: 4420

Re: RB4011iGS+RM plus CAP AC - VLANs in the home

How the heck do you get into this thing?

Isn't it fun? : - )

Plug your PC and cAP AC into a switch. Manually assign the PC an .88 network (192.168.88.123). Reset the cAP AC. When it boots back up, you can connect to it via IP or MAC.
by pcunite
Tue Dec 31, 2019 2:28 am
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 275
Views: 507041

Re: Using RouterOS to prioritize (Qos) traffic for a Class C net

I have a question to ask the admins (how do we private message you and talk about the forums)? I am planning on rewriting this article. What is the best course of action to maintain the link (which is pinned and also maybe linked elsewhere)? I would like for all posts to be deleted except for the fi...
by pcunite
Tue Dec 31, 2019 2:09 am
Forum: General
Topic: RB4011iGS+RM plus CAP AC - VLANs in the home
Replies: 17
Views: 4420

Re: RB4011iGS+RM plus CAP AC - VLANs in the home

Now for my questions with the cAP AC. I would like to have wifi on vlans. Do I need CAPSMan? For the RB4011, do I need to get rid of the default vlan of 0 on interface ethernet switch port? Assuming you are following this guide , set the cAP AC exactly as demonstrated in the article. Always think o...
by pcunite
Sun Dec 29, 2019 11:25 pm
Forum: Beginner Basics
Topic: Recommend way to block Ads with Mikrotik
Replies: 64
Views: 69063

Re: Recommend way to block Ads with Mikrotik

I found the free DNS servers at AdGuard to be very good. They seem to have more locations and the roundtrip is only 50ms. They also have some "family friendly" DNS servers which may interest some households.

Nice find. Will give them a try.
by pcunite
Sat Dec 28, 2019 7:00 pm
Forum: Beginner Basics
Topic: Recommend way to block Ads with Mikrotik
Replies: 64
Views: 69063

Re: Recommend way to block Ads with Mikrotik

@stuartkoh

Thanks for the write-up.
by pcunite
Sat Dec 28, 2019 4:14 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

i have tested that with no better results. :(

Well, sorry to hear that. We need RouterOS to have better support for 802.1p tags is what this is coming down to.
by pcunite
Sat Dec 28, 2019 6:04 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

I have just tested a config on the 3011 and it don't seem to be able to get the vlan0 working like the rb4011 does. :(

You'll have to do something like this:

/interface ethernet switch port
set ether1 vlan-mode=fallback
by pcunite
Fri Dec 27, 2019 8:34 pm
Forum: Beginner Basics
Topic: Recommend way to block Ads with Mikrotik
Replies: 64
Views: 69063

Re: Recommend way to block Ads with Mikrotik

I think pi hole is the best way to block ads. The best $10 i ever spent. Check out this thread on reddit: Update: I understand now. A Pi Zero W is plugged into a MikroTik's USB port to get power and also act like an ethernet card. The MikroTik is this person's router, and they send DNS queries to t...
by pcunite
Fri Dec 27, 2019 6:07 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

Is this configuration specific to the RB4011 with the vlan0 att RG bypass or supplicant? /interface ethernet switch port set 0 default-vlan-id=0 set 1 default-vlan-id=0 etc... I don't follow your question. The default values on an RB4011, for whatever reason as determined by MikroTik, do set defaul...
by pcunite
Fri Dec 27, 2019 6:01 pm
Forum: SwOS
Topic: Replace the Cisco 3750G switch
Replies: 4
Views: 4531

Re: Replace the Cisco 3750G switch

MikroTik does not yet offer a real multilayer switch, not with any performance you are probably going to need. Look at the size, costs, and feature set of a Cisco, and you can understand their value for a given situation. The routing decision is made with higher cost ASIC circuits.
by pcunite
Fri Dec 27, 2019 5:29 pm
Forum: General
Topic: CRS328 low space
Replies: 3
Views: 1818

Re: CRS328 low space

To get a little more space, only install the minimal number of packages, not the default firmware. This will free up a MB or two.
by pcunite
Wed Dec 25, 2019 9:33 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

After all I returned it and bought an RB4011. Wish everything works fine when I receive the new model.

I will help you!
: - )
by pcunite
Wed Dec 25, 2019 9:26 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

Someone, please test with a CCR1009 (the new one without any switch chips), and see how you fair.
by pcunite
Tue Dec 24, 2019 8:29 pm
Forum: General
Topic: Queue Setup
Replies: 3
Views: 1405

Re: Queue Setup

You could have each class of customer on a different VLANs. ID 10 is for 10mb customers, ID 20 for 20mb service, and so on. However you want to classify them. How else will you distinguish the traffic coming into a single concentrator? You most certainly must have something in the packets.
by pcunite
Tue Dec 24, 2019 5:30 pm
Forum: General
Topic: Queue Setup
Replies: 3
Views: 1405

Re: Queue Setup

I don't have practical experience in this area, however, it would be fun to theorize how to do it. Far more knowledge people are here. How many customers, what are your bandwidth plans, and will you be handing out public IPs? Concentration switch provides a port for every customer. MikroTik will soo...
by pcunite
Tue Dec 24, 2019 4:58 pm
Forum: General
Topic: hAP CPU usage
Replies: 10
Views: 3168

Re: hAP CPU usage

Why do you recommend the RB4011 but without wireless?

There is a very long thread about wifi, on the 5Ghz side, cutting out. Try one from a dealer you can return it to. I would prefer to recommend it if possible.
by pcunite
Tue Dec 24, 2019 4:17 pm
Forum: General
Topic: hAP CPU usage
Replies: 10
Views: 3168

Re: hAP CPU usage

Right now I only see one solution. I need a more powerful router. Would it be better to get an Ethernet router and a separate access point for wireless? Yes, at the moment separate out the Wifi, as MikroTik does not have a great all-in-one unit, today anyway. So, you're looking at getting the RB401...
by pcunite
Tue Dec 24, 2019 7:46 am
Forum: General
Topic: Can't get IP address - DHCP client ignores lease offer
Replies: 7
Views: 5974

Re: Can't get IP address - DHCP client ignores lease offer

I am working on this very issue here . Since you're bypassing the retail gateway, you'll need to process 802.1P packets. Ultimately we need MikroTik to enable us to use VLAN id 0, and set the 802.1p bits on egress. For now, you can support the ingress like so: # allow ingress packets with VLAN ID 0,...
by pcunite
Tue Dec 24, 2019 7:10 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

No Switch option, this is my menu. Okay, well that makes sense as their is no switch chip. Hmmm, I don't yet know how to accept anything over the WAN interface on the CCR1009. As wojo has explained, a carefully constructed bridge with vlan-filtering=yes should do it. But I don't know why it fails f...
by pcunite
Tue Dec 24, 2019 5:12 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

Thanks for the update. Need to find the equivalent of that command, if not I'm going to return this router. There is probably a way to process VLAN 0 with the CCR1009. I just don't own one to test. In the Winbox GUI (version 3.20), do you even have a Switch menu? Some of the older CCR's did have sw...
by pcunite
Mon Dec 23, 2019 11:36 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

Update When working with the Atheros8227 switch chip, you must set vlan-mode=fallback on the WAN port. This enabled me to get the hEX PoE to work. Therefore, it seems that on some MikroTik boards, they will drop ingress packets that have a VLAN id of 0. Thus, you must account for this. Of note, I o...
by pcunite
Mon Dec 23, 2019 9:41 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

Well, I have some more info. It seems that @jack2020 is correct, there can be a configuration to where a bare interface or even a bridge, will not be able to process EAPOL with a good certificate. Acting on wojo's switch chip theory, I am testing with a hEX Poe Lite . Just to see what would happen. ...
by pcunite
Mon Dec 23, 2019 6:03 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

Here is my configuration with my modification. I removed the real MAC address for this post.

For the wireshark output, please put the VLAN and DSCP values to the left of the Info column, so we can see them.
by pcunite
Mon Dec 23, 2019 5:05 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

I tried the bridge_ont option and for some reason my authorization fails, I think something is wrong with this certificate. On lines 14,18,21 the system ask for my real ip address? I include my wireshark image. Thanks with any idea. I also tried the configuration without the bridge and I have no re...
by pcunite
Sun Dec 22, 2019 10:44 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

I added DSCP into my Wireshark columns, and it shows CS6 level for all packets coming from the ONT.

I updated my capture post to show DSCP.
by pcunite
Sun Dec 22, 2019 10:00 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

One thought -- it looks like you are on a RB4011iGS+ ( block diagram ) which has two RTL8367 switch chips. The CCR1009-7G-1C-1S+PC ( block diagram ) does not have any. Perhaps that architecture is what allows for the processing of those VLAN 0 tagged packets, whereas in my situation, I have a raw C...
by pcunite
Sun Dec 22, 2019 4:50 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

Here is my capture. Please make one for your WAN interface, so we can compare. Go to Tools / Packet Sniffer . Under the General tab set the File Name to be something.pcap . Under the Filter tab, set the Interface , then Direction any . Then press Start . When done press Stop then download the file f...
by pcunite
Sun Dec 22, 2019 8:36 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

My time is correct and synced via NTP. Can you get some captures on the wire to see if your IP traffic is encapsulated with VLAN 0 by hooking up wireshark to the MikroTik. Replying to this again, going to take a break for now. However, please test the following: Do a System / Reset Configuration un...
by pcunite
Sun Dec 22, 2019 8:18 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

Yes, and it works! I'll will update the article now. Basically, follow the article, but set the clock, under System / Clock to be the correct time and date. Then reboot. Thereafter, you can unplug the cable, release/renew IP, turn off the interface, whatever, and it will re-auth correctly. My time ...
by pcunite
Sun Dec 22, 2019 8:08 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

Well, after going around and around with this, I was finally able to get it to work with only using ether1 . The system time must be correct. Set that, then reboot. And with just the interface (no bridge), you can disconnect the ONT ethernet cable or disable that interface, bring it back and it'll ...
by pcunite
Sun Dec 22, 2019 7:34 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

Well, after going around and around with this, I was finally able to get it to work with only using ether1. The system time must be correct. Set that, then reboot.
by pcunite
Sun Dec 22, 2019 5:09 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

I remove the WAN Bridge, ether1 is alone, the only bridge that I have is for the LAN. Do I need to remove the LAN_Bridge and create a new one for the LAN? No, the LAN side is fine. What we are doing is fairly advanced here. I understand it must be confusing for you. We are only talking about WAN in...
by pcunite
Sun Dec 22, 2019 5:03 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

I change the clock with right date and time, import the certificates again, use the one with KT with the DOTx . And the same message. Thanks Okay, I think what may have happened is that I too had a bridge, then took it out of the bridge. After that, is stays working. Please try wojo scripts. I will...
by pcunite
Sun Dec 22, 2019 4:34 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

Sadly with the new Mikrotik CCR1009 I'm still have the same message "Authenticaded without server" and no IP address. I also tried the script to verify the Dot1x status and no luck. Looking for any help. Thanks Yes, I just tested my system again (resetting everything for testing) and get ...
by pcunite
Sat Dec 21, 2019 5:13 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

I think I have authorization but for some reason I never get an ip address. The message that I received under the dot1.x is authenticated without server . Any idea? I'm very new to this, so I don't know all the edge cases yet. The Dot1x documentation mentions it and states access to the port is gra...
by pcunite
Sat Dec 21, 2019 5:04 pm
Forum: General
Topic: Help with VLANs on CRS125-24G-1S-2HnD
Replies: 26
Views: 5037

Re: Help with VLANs on CRS125-24G-1S-2HnD

The PoE injector supplied with cAP ac is a passive one. So, powering it from RB4011 should be fine ...

mkx is correct and is confirmed in this thread. The cAP AC can be powered from the passive PoE on the RB4011's ether10 port. Thank you, mkx.
by pcunite
Fri Dec 20, 2019 11:02 pm
Forum: General
Topic: Help with VLANs on CRS125-24G-1S-2HnD
Replies: 26
Views: 5037

Re: Help with VLANs on CRS125-24G-1S-2HnD

@jthompson333, I realized I have made a potently false statement. I power an hAP AC with my RB4011's port 10. The cAP AC, however, on its incoming port, appears to require 802.3af/at PoE. The output on the RB4011 is passive. So, you may in fact require an injector! Ugh, sorry about that. However, th...
by pcunite
Fri Dec 20, 2019 10:53 pm
Forum: General
Topic: Anybody ues AT&T Gigabit Fiber with Mikrotik RouterOS?
Replies: 89
Views: 27622

Re: Anybody ues AT&T Gigabit Fiber with Mikrotik RouterOS?

@pcunite, Great article. I've followed this thread for a while ... writing down the cleverness here isn't easy. I'd suggest adding a third option, that of getting a /29 public IP block (5 IPs) from AT&T and adding that to the article. This solution has worked well for me - with the key being to...
by pcunite
Fri Dec 20, 2019 9:47 pm
Forum: General
Topic: Help with VLANs on CRS125-24G-1S-2HnD
Replies: 26
Views: 5037

Re: Help with VLANs on CRS125-24G-1S-2HnD

Do I need an injector to power the cAP AC? Will the RB4011iGS+RM power it on its own? Down the road, could I use the CRS as an extra switch? Just debating if I should try and eBay it. Port 10 on the RB4011 will power the cAP AC, which is how I use mine. Regarding the switch, sell it now. You only w...
by pcunite
Fri Dec 20, 2019 8:14 pm
Forum: General
Topic: Help with VLANs on CRS125-24G-1S-2HnD
Replies: 26
Views: 5037

Re: Help with VLANs on CRS125-24G-1S-2HnD

As my luck would have it, isp supplies is out of stock on the RB4011iGS+RM. Any other vendors you trust?

Baltic Networks and r0c-n0c are authorized dealers in the community.
by pcunite
Fri Dec 20, 2019 8:01 pm
Forum: Beginner Basics
Topic: What is the practical difference between cAP lite and cAP?
Replies: 5
Views: 2415

Re: What is the practical difference between cAP lite and cAP?

Is it not hilarious how many SKUs they have? I hope they retire them soon. I'm trying to see the difference because you asked. The price?

:-)
by pcunite
Fri Dec 20, 2019 7:42 pm
Forum: General
Topic: Help with VLANs on CRS125-24G-1S-2HnD
Replies: 26
Views: 5037

Re: Help with VLANs on CRS125-24G-1S-2HnD

Have you had good luck buying from amazon? I have bought a few units from ispsupplies in the past- just to get some support for warranty if needed. Yes, I really like ISP Supplies. Amazon makes me leery, although I have used equipment bought from them just fine. When you have settled on your new ha...
by pcunite
Fri Dec 20, 2019 7:37 pm
Forum: General
Topic: Anybody ues AT&T Gigabit Fiber with Mikrotik RouterOS?
Replies: 89
Views: 27622

Re: Anybody ues AT&T Gigabit Fiber with Mikrotik RouterOS?

Please read my new article on this subject. This thread is no longer current.
by pcunite
Fri Dec 20, 2019 4:30 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

Supplicant Method Overview: This option is the preferred way because the ATT RG can be stowed away while MikroTik hardware performs all necessary tasks. All that is required are valid certificates extracted from your ATT RG and a native supplicant client. MikroTik includes this client via their Dot...
by pcunite
Fri Dec 20, 2019 4:28 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Re: Bypassing AT&T Residential Gateways with MikroTik

Bridge Method Overview: If you know anything about this option, then you know it has gone by several names: dumb switch bypass, eap-proxy , VLAN bypass, and true bridge mode. Well, they all share a common configuration in that they allow the ATT RG to handle the EAP-TLS protocol . After that, the R...
by pcunite
Fri Dec 20, 2019 4:27 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 236
Views: 110589

Bypassing AT&T Residential Gateways with MikroTik

Title: Bypassing AT&T Residential Gateways with MikroTik Welcome: If you have AT&T FTTH service and would like to use your MikroTik hardware to its fullest potential, this article is for you. Discover how to connect directly to the Fiber ONT device, bypassing other middleware hardware. The ...
by pcunite
Fri Dec 20, 2019 6:03 am
Forum: General
Topic: 802.1x / dot1x client not working when interface is on a bridge
Replies: 11
Views: 5000

Re: 802.1x / dot1x client not working when interface is on a bridge

Can you share your configuration (snippets of the important parts) here? It is indeed possible that something has changed in the latest releases! Exciting. Where I got stuck last time was I *had* to place the interface on the bridge to pull DHCP due to the VLAN 0 issue. What ISP do you have and do ...
by pcunite
Fri Dec 20, 2019 5:57 am
Forum: General
Topic: Help with VLANs on CRS125-24G-1S-2HnD
Replies: 26
Views: 5037

Re: Help with VLANs on CRS125-24G-1S-2HnD

Also, if there is no way to do this with this one box, then I'm open to getting a Hex PoE, along with a cAP AC, or some other setup. Well, my big issue is that the CRS125 is not powerful enough to handle anything that will hit the CPU on it, like the routing. Also, no 5Ghz channels. How many wired ...
by pcunite
Fri Dec 20, 2019 4:22 am
Forum: General
Topic: Help with VLANs on CRS125-24G-1S-2HnD
Replies: 26
Views: 5037

Re: Help with VLANs on CRS125-24G-1S-2HnD

I made a diagram of what I was trying to do.

Looks great. Give me time to put something together.
by pcunite
Thu Dec 19, 2019 10:48 pm
Forum: General
Topic: PoE switch for Dahua IP cameras
Replies: 12
Views: 4261

Re: PoE switch for Dahua IP cameras

If there is any other MikroTik solution, not as expensive as the 8 or 16 port switch option?

Yes, I use the hEX PoE at one particular location. You'll also need the 48POW.
by pcunite
Thu Dec 19, 2019 8:31 pm
Forum: General
Topic: Anybody ues AT&T Gigabit Fiber with Mikrotik RouterOS?
Replies: 89
Views: 27622

Re: Anybody ues AT&T Gigabit Fiber with Mikrotik RouterOS?

Thanks for the info, I need to buy a new one. Any progress with using wpa_supplicant (Dot1x) to completely remove the use of the AT&T RG gateway?

Yes, I have it working now. I will make a new thread showing how to do this.
by pcunite
Thu Dec 19, 2019 8:14 pm
Forum: General
Topic: 802.1x / dot1x client not working when interface is on a bridge
Replies: 11
Views: 5000

Re: 802.1x / dot1x client not working when interface is on a bridge

@wojo

I'm able to use ether1 and get Dot1x Cert status authenticated. Also DHCP client on ether1 pulled an IP, all without putting ether1 on a bridge. Everything seems to be working fine. Using firmware 6.46.1 on an RB4011. Can you update this thread with your success?
by pcunite
Wed Dec 18, 2019 11:51 pm
Forum: General
Topic: Help with VLANs on CRS125-24G-1S-2HnD
Replies: 26
Views: 5037

Re: Help with VLANs on CRS125-24G-1S-2HnD

Port 1 - i.e. ether1-gateway is hooked up to a Motorola cable modem.

How much Internet bandwidth are you working with?