Community discussions

MikroTik App

Search found 492 matches

  • 1
  • 2
by ivicask
Sun Jan 30, 2022 7:57 pm
Forum: General
Topic: firewall address list domains resolution frequency [SOLVED]
Replies: 6
Views: 2265

Re: firewall address list domains resolution frequency [SOLVED]

It's supposed to use TTL. What RouterOS version do you have? I noticed the same(any versions ever), what TTL you talk about ?In this case timeout value is empty because i never want entry to expire and get removed from address list, there is no TTL setting. I get over 1 Million DNS requests per day...
by ivicask
Sun Jan 30, 2022 7:49 pm
Forum: Announcements
Topic: v7.2rc2 and v7.2rc3 is released!
Replies: 222
Views: 86480

Re: v7.2rc2 and v7.2rc3 is released!

Torch for IPv6 still not working. Can anyone confirm? @ Mafioso Please read through this and tell us where Torch is noted THEN copy and paste it into excel or any document and do FIND/SEARCH for the word Torch, just in case you missed it doing in manually. What's new in 7.2rc2 (2022-Jan-28 11:00): ...
by ivicask
Sun Jan 30, 2022 7:39 pm
Forum: Wireless Networking
Topic: 14 years lasting BUG - disconnected, unicast key exchange timeout
Replies: 31
Views: 11771

Re: 14 years lasting BUG - disconnected, unicast key exchange timeout

I dont understand, how it's possible to manufacture so called router os and still have this HUGE, 14 years nover solved problem? How to fix it??? I have Shelly device, it connects to wifi and after few seconds receives "disconnected, unicast key exchange timeout, signal strength -52". WHy...
by ivicask
Fri Jan 21, 2022 12:17 am
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 443
Views: 226029

Re: v7.1.1 is released!

I have 7.1.1 on RB4011 with CAPS-man - here is some bug with bridge/capsman - any change with bridge (disable port, or change mode to rstp/none) cause almost frozen routerboard, reboot required. Simple: create bridge with eth ports, create caps-man with datapath add to bridge, then add cap. without...
by ivicask
Tue Jan 11, 2022 8:52 pm
Forum: RouterBOARD hardware
Topic: CCR2004 packet loss
Replies: 135
Views: 59380

Re: CCR2004 packet loss

I have also alot of packet lost on ethernet interfaces and some on SFP when going from 10gb to 1gb, the fifo suggestion made it even worse, some ports have 100 000 drops in few days with it...
CRS354-48G-4S+2Q+RM
by ivicask
Fri Dec 31, 2021 2:38 pm
Forum: General
Topic: You've got to be kidding me. [SOLVED]
Replies: 18
Views: 3399

Re: You've got to be kidding me. [SOLVED]

While I think the minimum amount of flash should be higher 64M or 128M and Ram should start at 128M, this would increase the cost of the devices. In your case you reference the hap light which is basically the cheapest device mt sells (along with the hap mini) at $20 usd. It only has 16M of flash -...
by ivicask
Fri Dec 31, 2021 8:31 am
Forum: RouterOS beta
Topic: some quick comments on configuring cake
Replies: 285
Views: 103945

Re: some quick comments on configuring cake

RB5009 arrived. Here's some brief testing of cake. ISP: Aussie Broadband Technology: Fibre To The Premise (FTTP) Down/Up: 1000M/50M /queue type add cake-diffserv=besteffort cake-nat=yes kind=cake name=cake-default add cake-ack-filter=filter cake-bandwidth=45.0Mbps cake-diffserv=besteffort cake-nat=...
by ivicask
Wed Dec 29, 2021 8:54 pm
Forum: Announcements
Topic: v7.2rc1 is released!
Replies: 240
Views: 161428

Re: v7.2rc1 is released!

These addresses can be temporarily disabled I don't like the fact that I have to disable those for the memory leak to not occur, but I disabled the scheduler tasks, cleared out the dynamic addresses, and upgraded back to 7.2.rc1. After reboot CPU and memory were stable. So yes, my issue was also li...
by ivicask
Sun Dec 26, 2021 2:56 pm
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 443
Views: 226029

Re: v7.1.1 is released!

Dude, so far it looks like a bug in 7.1.1 and 7.2rc1, these topics are for problems related to these specific versions, please don't spam the forums with offtopic talk. Wasted 3 posts for nothing. For general "don't use v7, v7 bad" please open another topic. Thank you. So, on topic, did y...
by ivicask
Tue Dec 21, 2021 10:41 pm
Forum: Announcements
Topic: v7.2rc1 is released!
Replies: 240
Views: 161428

Re: v7.2rc1 is released!

Updated from 7.1 hap ac2 crashing after 30mins out of memory, also cpu sticks at 35% with no traffic. Also memory leak on 2 other APs runing nothing but wifi..
Downgraded to 7.1.1 works fine so far.
by ivicask
Fri Dec 17, 2021 2:53 pm
Forum: Wireless Networking
Topic: Feedback : CAPSman tests, coming from Unifi
Replies: 19
Views: 6857

Re: Feedback : CAPSman tests, coming from Unifi

Did you add this for improved roaming?(fine tune the value to your liking) ... add action=reject allow-signal-out-of-range=6s client-to-client-forwarding=yes disabled=no interface=any signal-range=-120..-83 ssid-regexp="" At best it's not any better, at worse in your dark spots clients ge...
by ivicask
Fri Dec 17, 2021 1:28 pm
Forum: Wireless Networking
Topic: Feedback : CAPSman tests, coming from Unifi
Replies: 19
Views: 6857

Re: Feedback : CAPSman tests, coming from Unifi

Klembord-2.jpg . . To my experience this will not let you return to this AP for 6 sec, after you have been kicked out, even if your signal is now OK. Even if you set this to 1 sec, there is another cache for a short delay that says "banned(last failure ...)" This is a problem if the AP's ...
by ivicask
Fri Dec 17, 2021 11:46 am
Forum: Wireless Networking
Topic: Feedback : CAPSman tests, coming from Unifi
Replies: 19
Views: 6857

Re: Feedback : CAPSman tests, coming from Unifi

Interesting article and I would be happy to see these improvements. One other thing that is different that I have already suggested in the past but didn't see any action except the very first days of discussion is the fact that ubnt controller is pushing the parameters to the APs and if we loose fo...
by ivicask
Fri Dec 17, 2021 11:42 am
Forum: Wireless Networking
Topic: Feedback : CAPSman tests, coming from Unifi
Replies: 19
Views: 6857

Re: Feedback : CAPSman tests, coming from Unifi

Mikrotik : Constant ~1sec drop when roaming. We tried tried RSTP off/on, ROS 7/6.49.2, numerous resets and other tweaking. Constant ~1sec drop. Did you add this for improved roaming?(fine tune the value to your liking) /caps-man access-list add action=accept allow-signal-out-of-range=6s client-to-c...
by ivicask
Tue Dec 07, 2021 10:44 pm
Forum: Wireless Networking
Topic: Wifi 7 - MikroTik when???
Replies: 71
Views: 15257

Re: Wifi 7 - MikroTik when???

I also hope we don't see anymore same old wifi devices next year, wave2 and wifi 6 products are a must!
by ivicask
Thu Dec 02, 2021 2:42 pm
Forum: Announcements
Topic: v7.1 is released!
Replies: 785
Views: 227194

Re: v7.1 [testing] is released!

v7.1 contains routing fixes and improvements in order to fully comply with 6.x setups.
Please give us more detailed changelogs, even if it only says briefly like you wrote now, if we have related issue, we than know to flash new version and check if issue is resolved..
by ivicask
Wed Dec 01, 2021 10:35 am
Forum: Wireless Networking
Topic: How to Configure LHG5Ac
Replies: 4
Views: 2485

Re: How to Configure LHG5Ac

Thanks for the reply, now which model should i buy for AP and for wide beam,. My 2 stations are not in the same line, it will maximum 500mtr wide
Depends on distance and separation

How about you just buy another LHG5 and problem solved ? :)
by ivicask
Tue Nov 30, 2021 9:15 pm
Forum: Wireless Networking
Topic: How to Configure LHG5Ac
Replies: 4
Views: 2485

Re: How to Configure LHG5Ac

You can't, they come with level 3 licence and don't support ap mode, only bridge, so you can connect only one client. You could upgrade(buy) one to lvl 4 licence than it would work, but again this aps have very narrow beam so they would need to be positioned In same line behind each other in order t...
by ivicask
Wed Nov 17, 2021 9:52 pm
Forum: Forwarding Protocols
Topic: Best VPN tunnel for SQL connection between 2 offices
Replies: 7
Views: 4075

Re: Best VPN tunnel for SQL connection between 2 offices

I can confirm you, Wireguard is THE FASTEST for SQL from my own experience.
Also LTE is the worst for SQL :)
by ivicask
Mon Nov 15, 2021 11:50 pm
Forum: General
Topic: Brute passwords of microtik devices from the local network, how to identify malware?
Replies: 19
Views: 4232

Re: Brute passwords of microtik devices from the local network, how to identify malware?

You have virus i saw this at customers laptop also recently, it had some obvious name like crcs, i forgot exactly, and was even visible in regular startup entries...

Cleanup your pc dude.
by ivicask
Mon Nov 15, 2021 12:13 am
Forum: Wireless Networking
Topic: How to bridge 3 buildings wirelessly
Replies: 16
Views: 4723

Re: How to bridge 3 buildings wirelessly

Buy 6x sxt Sq 5ghz models(for 50mbit even none ac ones will be enough) but I recommend ac models for futureproof and put one at each of the arrows from Pic and all will work perfect fine even at much greater distance.
by ivicask
Sun Nov 14, 2021 5:07 pm
Forum: RouterOS beta
Topic: Periodic crashes in 7.1rc4
Replies: 31
Views: 13958

Re: Periodic crashes in 7.1rc4

Using cake or codel? Thats what's crashing my 4011.
by ivicask
Wed Nov 10, 2021 11:48 am
Forum: RouterBOARD hardware
Topic: CRS354-48G-4S+2Q+RM Speed not Stable
Replies: 8
Views: 4133

Re: CRS354-48G-4S+2Q+RM Speed not Stable

Its strange, i didnt limit any ports at all. I will change the server port and after disable the port and make some test. I just got the same switch and copies just fine, but i installed V7 on it immediately as i got it, so cant hurt to try also its running perfectly stable(for now). Do you use Rou...
by ivicask
Tue Nov 09, 2021 2:55 pm
Forum: RouterOS beta
Topic: v7.1rc6 [development] is released!
Replies: 145
Views: 56756

Re: v7.1rc6 [development] is released!

CAKE queue still not fix yet on hexS with
pppoe-server

Router reboot
IM also able to crash my 4011 in matter of 5min by setting codel queue, sent several logs, i think they really need to add some better debugging, they never find any crash log in supout that router self generates...
by ivicask
Tue Nov 09, 2021 10:14 am
Forum: RouterBOARD hardware
Topic: CRS354-48G-4S+2Q+RM Speed not Stable
Replies: 8
Views: 4133

Re: CRS354-48G-4S+2Q+RM Speed not Stable

I just got the same switch and copies just fine, but i installed V7 on it immediately as i got it, so cant hurt to try also its running perfectly stable(for now).
by ivicask
Wed Oct 27, 2021 9:13 pm
Forum: RouterOS beta
Topic: v7.1rc5 [development] is released!
Replies: 167
Views: 49196

Re: v7.1rc5 [development] is released!

Hello, Can someone please confirm the problem on wifi 5Ghz under heavy load ( e.g. copying a larger file, iperf) There is no disconnection from wifi, it just stops forwarding data. Same problem on RC4 and RC5, firmware updated. Mikrotik RB962UiGS-5HacT2HnT Laptop Lenovo T580 Intel Wireless-AC 8265 ...
by ivicask
Wed Oct 27, 2021 5:36 pm
Forum: General
Topic: Detected conflict by ARP response (configuration error?)
Replies: 6
Views: 19064

Re: Detected conflict by ARP response (configuration error?)

I get this also often on may sites and im 100% sure there is no static IPs because its all served and reserved by mikrotik DHCP it self.
I even get this few times a day on hotspot controlled by mikrotik hotspot controller, i doubt ppl put random static IPs on their phones..

Its just mikrotik issue..
by ivicask
Tue Oct 19, 2021 6:11 pm
Forum: Beginner Basics
Topic: Can't get second guest bridge to route to WAN
Replies: 9
Views: 1230

Re: Can't get second guest bridge to route to WAN

Practicing for Alzheimer's. I've been using Mikrotik routers for many years, since the RB133. but as I get older and not need to modify configurations much, I've forgotten quite a bit. I just purchased a hAP ac3 to use as the core for my new home network. I am trying to add a second LAN to support ...
by ivicask
Tue Oct 19, 2021 2:47 pm
Forum: General
Topic: Blocking Blogspot.com ? [SOLVED]
Replies: 17
Views: 2479

Re: Blocking Blogspot.com ? [SOLVED]

Hello. I would like to block the users in my networks from accessing their private blogs in blogspot.com, since it turns out they are most of time spending there, and this angry the boss quite a bit. Anyway I've tried the solution by adding blogspot.com to the address list, and then drop the traffi...
by ivicask
Fri Oct 15, 2021 1:28 pm
Forum: Wireless Networking
Topic: How many clients on CAP XL AC?
Replies: 6
Views: 4675

Re: How many clients on CAP XL AC?

The question is simple.. I need to cover areas with a lot of people.. conference hall, restaurant, swimming pool.. I mean, hundreds. A single CAP XL AC, how many clients is able to carry? I know it's even a matter of throughput so I say I could give 10Mb/1Mb limits via captive to each connected cli...
by ivicask
Thu Oct 07, 2021 11:40 pm
Forum: Announcements
Topic: v6.49 [stable] is released!
Replies: 219
Views: 96852

Re: v6.49 [stable] is released!

Cant upgrade 2x LHG 5 AC from 6.49beta22 to 6.49 Stable, not enough space, i got nothing on internal storage...
by ivicask
Tue Sep 28, 2021 4:12 pm
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 119
Views: 131309

Re: DHCP Offering Lease Without Success

Hi (again), this thread is quite mixed up with a lot of different things. My issue seems to be of the kind of "mainly related to Apple devices". (I've seen it once with a Samsung mobile as well but very rarely.) I'm really wondering how this can be an issue since 2018 w/o anyone (like Mik...
by ivicask
Tue Sep 28, 2021 7:53 am
Forum: Beginner Basics
Topic: Why is my CAPsMAN network not as good as I hope for?
Replies: 25
Views: 5789

Re: Why is my CAPsMAN network not as good as I hope for?

As you can see from hes config above he did that, so did i, while you are right and old protocols are total performanse killers and cause problems, in this case its not helping. His config did not have those settings, thus the suggestion. Those are the settings I use with zero issues. I don't use a...
by ivicask
Mon Sep 27, 2021 11:09 pm
Forum: Beginner Basics
Topic: Why is my CAPsMAN network not as good as I hope for?
Replies: 25
Views: 5789

Re: Why is my CAPsMAN network not as good as I hope for?

I don't think it's config issue or anything we can do our side, I mostly only have issue with Apple devices and I think its something Mikrotik needs to resolve their side.
by ivicask
Mon Sep 27, 2021 10:32 pm
Forum: Beginner Basics
Topic: Why is my CAPsMAN network not as good as I hope for?
Replies: 25
Views: 5789

Re: Why is my CAPsMAN network not as good as I hope for?

I would set your 2ghz channels to 2ghz-onlyn or at least 2ghz-g/n. For 5ghz set it to 5ghz-n/ac. You could have issues negotiating the older protocols. As you can see from hes config above he did that, so did i, while you are right and old protocols are total performanse killers and cause problems,...
by ivicask
Mon Sep 27, 2021 8:16 pm
Forum: Beginner Basics
Topic: Why is my CAPsMAN network not as good as I hope for?
Replies: 25
Views: 5789

Re: Why is my CAPsMAN network not as good as I hope for?

I got same issues as you and i dont think there is anything left i didint try, other brands work fine on same setup with zero issues.
by ivicask
Mon Sep 27, 2021 9:04 am
Forum: RouterOS beta
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 83389

Re: v7.1rc4 [development] is released!

Darn! After a reboot I lost about 5000 of my 22000 address-list entries. Good that I had a reasonable recent export so I could restore more than 99%. The router is a 4011. Manual reboot or crash?My 4011 crash rebooted 2nd time now after 4 day uptime, no supout was generated, just" router reboo...
by ivicask
Fri Sep 24, 2021 11:34 am
Forum: Announcements
Topic: v6.49rc [testing] is released!
Replies: 36
Views: 19596

Re: v6.49rc [testing] is released!

DNS issue is absolutely irritating and its existing in 2+ months of 6.49 releases and was reported so many times by users i just dont get it how was it not fixed yet?
by ivicask
Wed Sep 22, 2021 9:13 am
Forum: RouterOS beta
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 83389

Re: v7.1rc4 [development] is released!

4011 rebooted after 1 day 15 hours uptime RC4, no crash log generated..
by ivicask
Mon Sep 20, 2021 6:03 pm
Forum: RouterOS beta
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 83389

Re: v7.1rc4 [development] is released!

Export creates code, that import can not read (starting with 7.1rc3): Export: /ip dhcp-client add add-default-route=no disabled=yes interface=FFNK script=":if (\$bound = \"\ Import: [admin@router] > import file-name=export.rsc verbose=yes #line 1 /ip dhcp-client #line 2 add add-default-ro...
by ivicask
Thu Sep 16, 2021 5:03 pm
Forum: General
Topic: Why firewall rules are so important...
Replies: 12
Views: 2439

Re: Why firewall rules are so important...

Maybe they are honeypots? I hope... :p
by ivicask
Wed Sep 15, 2021 11:00 am
Forum: RouterOS beta
Topic: v7.1rc3 [development] is released!
Replies: 172
Views: 50833

Re: v7.1rc3 [development] is released!

Do not use backup, use export for configuration. Thing is, simple export/import is broken in 7.1rc3, "expected end of line error" when line-break inside double-quote, example : /user group set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,pas\ sword,web,sniff...
by ivicask
Tue Sep 14, 2021 2:50 pm
Forum: Wireless Networking
Topic: Is there a way to force/encourage clients to use 5GHz if 2.5GHz gets crowded?
Replies: 10
Views: 2979

Re: Is there a way to force/encourage clients to use 5GHz if 2.5GHz gets crowded?

Yes you can restrict the number of clients. But it is for me by no means a measure for the load on that AP. 100 clients that are quiet give almost no load (happens more these days than some time ago with smartphones, smartwatches etc). 1 client, from far away, transmitting or receiving at 6 Mbps, c...
by ivicask
Tue Sep 14, 2021 2:22 pm
Forum: Wireless Networking
Topic: Is there a way to force/encourage clients to use 5GHz if 2.5GHz gets crowded?
Replies: 10
Views: 2979

Re: Is there a way to force/encourage clients to use 5GHz if 2.5GHz gets crowded?

@solarium14 How do you measure thet 2.4GHz "gets crowded"? Number of devices? Traffic? Signal quality? You can write a script which counts devices connected to 2.4 bands and then change ACL to drop block new connections or drop all these with quality below limits to "persuade" t...
by ivicask
Fri Sep 10, 2021 10:01 pm
Forum: General
Topic: MikroTik news and rumours – Chateau 5G & cAP ac XL
Replies: 12
Views: 2624

Re: MikroTik news and rumours – Chateau 5G & cAP ac XL

Please Mikrotik stop releasing from this point any new WIFI devices if they dont support at least new WAVE2, or even better WIFI6..
by ivicask
Fri Sep 10, 2021 1:19 am
Forum: General
Topic: Load balance torrent traffic?
Replies: 6
Views: 1571

Re: Load balance torrent traffic?

Oh, well... now give all the instruction and information that the OP ask, I go to bed, my help here is not needed, you are present. Even by doing simple load balance for each new conection evenly between 2 isps he can achieve what he wants, and torrents are best candidates for this. I was just tryi...
by ivicask
Fri Sep 10, 2021 1:07 am
Forum: General
Topic: Load balance torrent traffic?
Replies: 6
Views: 1571

Re: Load balance torrent traffic?

You are not the user than open the topic. The second line he have is already natted... Nat absolutely makes no difference, I use local hotspot to increase my torrent speeds, what's even funnier this hotspot blocks torrents you can't even open most of torrent sites, but I can use it just fine after ...
by ivicask
Fri Sep 10, 2021 12:58 am
Forum: General
Topic: Load balance torrent traffic?
Replies: 6
Views: 1571

Re: Load balance torrent traffic?

Is impossible to combine two ISP speed to download/upload with higer speed than the faster line. (Unless some technology on remote side intervenes) Is also impossible to use one line only for download and the other for upload. The communication between same remote service can happen only on same li...
by ivicask
Wed Sep 08, 2021 4:25 pm
Forum: RouterOS beta
Topic: My three rb750 routers with version 7.1, always restart automatically.why,please?
Replies: 5
Views: 1490

Re: My three rb750 routers with version 7.1, always restart automatically.why,please?

thanks
Are you using cake or codel on simple queue with interface as target?
by ivicask
Thu Sep 02, 2021 10:41 pm
Forum: RouterOS beta
Topic: v7.1rc2 [development] is released!
Replies: 194
Views: 44602

Re: v7.1rc2 [development] is released!

The PPPoE through a SFP still drops back to a MTU of 1480...it was fixed in Beta 6.49 so please patch ROS 7.x also.
Just chiming in again that I can second this. Thanks msatter for testing :) I always look for your reports.
Same here
by ivicask
Thu Sep 02, 2021 8:05 pm
Forum: Wireless Networking
Topic: Low throughput with 3x Audience
Replies: 37
Views: 8289

Re: Low throughput with 3x Audience

Did you try runing 802.11 instead nv2 for link between them?

Also is your routerboard firmware updated to match software?

Otherwise no ideas to help you, you did everything OK.
by ivicask
Tue Aug 31, 2021 12:59 pm
Forum: RouterOS beta
Topic: v7.1rc2 [development] is released!
Replies: 194
Views: 44602

Re: v7.1rc2 [development] is released!

Kernel failure 5mins after setting cake to my simple queue..I sent you supout (SUP-58379)
by ivicask
Sun Aug 29, 2021 11:47 am
Forum: RouterOS beta
Topic: v7.1rc1 [development] is released!
Replies: 344
Views: 78252

Re: v7.1rc1 [development] is released!

For me cake is crashing my SXTSQ 5 in matter of minutes even on RC2, its just simple wifi client with basic firewall rules..
It did create autosupout if any of devs wants it tell me,
by ivicask
Sun Aug 29, 2021 12:52 am
Forum: General
Topic: Port flapping (ether6 link down/up) on RB3011UiAS-RM
Replies: 54
Views: 35697

Re: Port flapping (ether6 link down/up) on RB3011UiAS-RM

I have port-flapping issue on my hAP AC2 as well. It didnt have it when I purchased it 4 months ago, I guess the issue started happening 1 month ago, maybe due to the firmware version. Its between my router (ac2 on ether1) and mikrotik SXT on the roof. I changed the cable and reset the router but t...
by ivicask
Thu Aug 26, 2021 3:38 pm
Forum: RouterOS beta
Topic: v7.1rc1 [development] is released!
Replies: 344
Views: 78252

Re: v7.1rc1 [development] is released!

Interestingly, my RB4011 has fq_codel on all interfaces and never crashes because of fq_codel.
Same here 3 totally different devices, I set fq codel mixed configs, from wifi interfaces, pppoe and queues and they all have 3 days uptime now.
by ivicask
Wed Aug 25, 2021 9:38 pm
Forum: RouterOS beta
Topic: v7.1rc1 [development] is released!
Replies: 344
Views: 78252

Re: v7.1rc1 [development] is released!

This might sound bizarre, but anyone experiencing kernel crashes with cake/fq_codel, can you confirm the router is stable if there is no active WinBox session to the device? We currently think the crashes are caused by WinBox management session shaping. I had the Mikrotik Android app open on my pho...
by ivicask
Wed Aug 25, 2021 6:13 pm
Forum: RouterOS beta
Topic: v7.1rc1 [development] is released!
Replies: 344
Views: 78252

Re: v7.1rc1 [development] is released!

time=17:35:10 topics=pppoe,ppp,info message=pppoe-wan: disconnected time=17:35:10 topics=script,warning message=ivicask ppp profile on-down test, if you see this, it works. time=17:35:15 topics=pppoe,ppp,info message=pppoe-wan: initializing... time=17:35:15 topics=pppoe,ppp,info message=pppoe-wan: ...
by ivicask
Wed Aug 25, 2021 5:27 pm
Forum: RouterOS beta
Topic: v7.1rc1 [development] is released!
Replies: 344
Views: 78252

Re: v7.1rc1 [development] is released!

One more thing i found broken is under PPP->Profile-> On up / Down Scripts dont work anymore, hope can be fixed in next update because i have some scripts for fast failover and email sending there..
by ivicask
Wed Aug 25, 2021 8:25 am
Forum: RouterOS beta
Topic: v7.1rc1 [development] is released!
Replies: 344
Views: 78252

Re: v7.1rc1 [development] is released!

Yes, it seems that limit and target-address are required. I don't think this should be the intended behavior, Mikrotik users (and guides on the internet) have been applying simple queues directly to interfaces for years without issues. It works great with the V6 queue types but V7 ones such as CAKE...
by ivicask
Mon Aug 23, 2021 3:34 pm
Forum: RouterOS beta
Topic: v7.1rc1 [development] is released!
Replies: 344
Views: 78252

Re: v7.1rc1 [development] is released!

After upgrade on one HEX S which i use only for Wireguard i get spamm of this for all peers constantly in log. wireguard1: =(peer): Handshake for peer did not complete after 5 seconds, retrying (try 16) But everything works fine, i also tried closing the WG port because i was thinking it may be inva...
by ivicask
Sat Aug 14, 2021 9:40 pm
Forum: General
Topic: Meshnetwork with Mikrotik Audience
Replies: 8
Views: 2079

Re: Meshnetwork with Mikrotik Audience

Hi @xvo, thanks for answering. What do you mean by "a wireless brigde"? I tried to do a setup in repeater mode with the third radio, but that did not work at all sadly. It means simple AP mode on one audience and client mode on other which connects them together like you used cable, but i...
by ivicask
Sun Aug 01, 2021 1:06 am
Forum: Wireless Networking
Topic: wmm in capsman
Replies: 5
Views: 1648

Re: wmm in capsman

It's on by default afik
by ivicask
Mon Jul 26, 2021 1:33 pm
Forum: Wireless Networking
Topic: WI-FI ROAMING 802.11r QUESTION
Replies: 41
Views: 28106

Re: WI-FI ROAMING 802.11r QUESTION

There is no "capsman roaming". Any client roaming is unrelated to capsman.
So how im going thru 4 floors of school with my phone running ping to google servers, and drop zero pings, while switching between 15 different mikrotik aps?
Isnt this an example of what you want to achieve?
by ivicask
Sun Jul 25, 2021 9:17 pm
Forum: Wireless Networking
Topic: WI-FI ROAMING 802.11r QUESTION
Replies: 41
Views: 28106

Re: WI-FI ROAMING 802.11r QUESTION

Whats wrong with capsman roaming, works with any Mt hardware, and works wonderful.
by ivicask
Wed Jul 07, 2021 3:32 pm
Forum: Announcements
Topic: v6.49beta [testing] is released!
Replies: 171
Views: 91388

Re: v6.49beta [testing] is released!

For me wifi is breaking when uploading anything on this test versions, fresh reseted wap ac,5ghz, download 300mbit fine, i go other direction hangs at 100kb few sec than wifi breaks and log says extensive data loss.Got same issue on devices like SXT 2ghz, WIFI disconnects on upload. Flashed back sta...
by ivicask
Tue Jul 06, 2021 6:23 pm
Forum: Announcements
Topic: v6.49beta [testing] is released!
Replies: 171
Views: 91388

Re: v6.49beta [testing] is released!

Just upgraded to 6.49beta54 and I can confirm that the DNS cache issue is still present. I was able to reproduce it using the same POC I provided to support (SUP-51096). Not only that but my router is crashing, 6.49beta54, out of memory, DNS using absurd amounts of memory, the issue is even worse o...
by ivicask
Tue Jul 06, 2021 4:54 pm
Forum: Announcements
Topic: v6.49beta [testing] is released!
Replies: 171
Views: 91388

Re: v6.49beta [testing] is released!

Why disable anything, for basic dns server with cache it worked fine and it's broken now, mikrotik should check and fix it so it works as before.
by ivicask
Mon Jul 05, 2021 8:12 pm
Forum: Announcements
Topic: v6.49beta [testing] is released!
Replies: 171
Views: 91388

Re: v6.49beta [testing] is released!

Regarding 6.49beta54:

No fixes for the DNS memory leak introduced in 6.49beta46?

Just asking based on the changelog, haven't tried it yet.
I got same issue, it uses all up all memory set even that there are only few entries in dns cache.
by ivicask
Tue Jun 29, 2021 2:07 pm
Forum: General
Topic: WiFi4EU validation
Replies: 3
Views: 1678

Re: WiFi4EU validation

I install a WiFi4EU network with Mikrotik CCR1009 as Gateway and hotspot, I edit hotspot portal captive to permit access without authentication and load visibility, it works fine, but WiFi4EU authority need to see captive portal remotely to verify the visibility. How can I do to permit access to we...
by ivicask
Fri Jun 25, 2021 12:21 pm
Forum: General
Topic: Under flood attack, how resolve this ? [SOLVED]
Replies: 107
Views: 17818

Re: Under flood attack, how resolve this ? [SOLVED]

If you can switch your DNS to DoT (TCP/853) or DoH (TCP/443) you can close all traffic incoming with source port 53 (TCP/UDP). Then if that working for you then you could ask upstream to temporary block all traffic with source port 53 because you swichted the protocol for DNS. General remark. As wi...
by ivicask
Fri Jun 25, 2021 11:20 am
Forum: General
Topic: Under flood attack, how resolve this ? [SOLVED]
Replies: 107
Views: 17818

Re: Under flood attack, how resolve this ? [SOLVED]

Get the RB4011, and maybe you can add a firewall rule in the Raw section that just blocks all UDP except for DNS and QUIC. Or just block all TCP/UDP/53 incoming from WAN from now, except from 8.8.8.8 and 1.1.1.1 and temporary use Google/Cloudflare for upstream resolving? This looks like some DNS am...
by ivicask
Mon Jun 07, 2021 4:11 pm
Forum: RouterOS beta
Topic: v7.1beta6 [development] is released!
Replies: 377
Views: 243973

Re: v7.1beta6 [development] is released!

Those messages are related to IPv6 on your local network. Unfortunately they do not include enough info to hunt down what device is causing them.
(there should be a MAC address or IPv6 address in those messages...)
Yeah i figured it already and disabled IPV6 as we dont use it at all.
by ivicask
Mon Jun 07, 2021 2:31 pm
Forum: RouterOS beta
Topic: v7.1beta6 [development] is released!
Replies: 377
Views: 243973

Re: v7.1beta6 [development] is released!

Anyone can tell me what is this?I only use this router (HEX) for wireguard and nothing else, first time i see this messages and thats only after beta 6
by ivicask
Tue Jun 01, 2021 10:47 am
Forum: General
Topic: RoMON can ping but not connect
Replies: 10
Views: 1439

Re: RoMON can ping but not connect

Got same issue on one location, i see all romons devices and can ping and all but cant connect, completely shut down FW doesnt help, i think they broke it with some update again like same happen recently before, and cant updated them right now as i cant connect via romon...gona need to go to location.
by ivicask
Fri May 21, 2021 2:03 pm
Forum: General
Topic: Feature requests
Replies: 1744
Views: 639856

Re: Feature requests

Can we get ICAP client support?
by ivicask
Thu May 06, 2021 3:10 pm
Forum: General
Topic: Decrease in software quality from mikrotik?
Replies: 16
Views: 2837

Re: Decrease in software quality from mikrotik?

Some notes to the wireless part. Radardetect/DFS is an increasing issue - The used chipsets cant distinguish wireless signals from Radar in a lot of situations - You could decrease the false detection rate using *correct* Gain-Data as this goes into the calculation - With newer Firmware, Vendors ha...
by ivicask
Fri Apr 30, 2021 11:22 am
Forum: Announcements
Topic: v6.49beta [testing] is released!
Replies: 171
Views: 91388

Re: v6.49beta [testing] is released!

You should remove this file from here and send to support@mikrotik.com. This file contains passwords etc so you should not post it in the forum here. Dont care its fresh router with mostly stock config passwords are unimportant EDIT:Checked file with rif viewer, there are no passwords inside at all..
by ivicask
Wed Apr 28, 2021 12:02 pm
Forum: Announcements
Topic: v6.49beta [testing] is released!
Replies: 171
Views: 91388

Re: v6.49beta [testing] is released!

Anyone care to send autosupout.rif file from the crashes experienced with these versions?
HAP AC 3, crashes 100% when i connect via phone to main SSID, doesnt crash when i connect to vritual one. Same setup works on release software.
by ivicask
Fri Jan 22, 2021 1:52 pm
Forum: General
Topic: CAPS / CAPsMAN over Powerline
Replies: 5
Views: 2536

Re: CAPS / CAPsMAN over Powerline

Can one PWR-LINE AP also be used as Capsman controler to control other PWR-LINE AP?
by ivicask
Fri Dec 04, 2020 10:36 am
Forum: RouterOS beta
Topic: v7.1beta3 [development] is released!
Replies: 261
Views: 80019

Re: v7.1beta3 [development] is released!

Is this a bug or some kinda of new feature, my bridge gets new MAC every time i reboot router (Hex), just installed beta3, so DHCP reservation is messed up as it gets new ip every reboot.
by ivicask
Wed Nov 18, 2020 1:10 pm
Forum: General
Topic: "Zoom" best practices
Replies: 10
Views: 5506

Re: "Zoom" best practices

I also have zoom issues with mikrotik, getting stuck on connecting etc, can't figure what to do
by ivicask
Wed Sep 23, 2020 3:41 pm
Forum: Announcements
Topic: Newsletter 97 (September 2020)
Replies: 87
Views: 38469

Re: Newsletter 97 (September 2020)

hAP ac3 looks wonderful!
Finally you decided to add external antennas to routers, what happend to all the talk how they are not needed you where telling us all this years when we complained about poor signal? :D
by ivicask
Fri Sep 18, 2020 1:09 pm
Forum: General
Topic: EOIP blocking TCP
Replies: 16
Views: 3022

Re: EOIP blocking TCP

I think i had same or similar issue, made tunnel between 2 routers, and on other side i linked it to SSID, you can connect, you get IP from DHCP, you can ping anything, use ip scanner to scan entire network, ping servers like 8.8.8.8, but web pages dont open, cant open RDC(tcp), cant enter network s...
by ivicask
Mon Aug 17, 2020 3:48 pm
Forum: General
Topic: Block internet access for devices by mac-address & schedule
Replies: 11
Views: 22102

Re: Block internet access for devices by mac-address & schedule

BTW all this wont work on most new phones like Samsung etc as they by default generate new MAC address every time they connected, just keep that in mind..
by ivicask
Mon Aug 10, 2020 3:25 pm
Forum: Wireless Networking
Topic: radar detected problems
Replies: 85
Views: 74400

Re: radar detected problems

Radar detection on mikrotik is bullshit i have to change country also in order to avoid it, i even had radar detection in basements where no signal can even penetrate or places where not even remotely radars exists to be detect at first place..Even setting all properly, setting skip DFS or setting &...
by ivicask
Wed Jul 29, 2020 12:07 am
Forum: Wireless Networking
Topic: CAPsMAN with local forwarding - customer separation [SOLVED]
Replies: 10
Views: 5047

Re: CAPsMAN with local forwarding - customer separation [SOLVED]

How about simple drop rule in firewall with source and destination IP same subnet? Maybe excluded wan interface if breaks net, not sure you can try.
by ivicask
Wed Jul 22, 2020 7:45 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 275
Views: 507796

Re: Using RouterOS to QoS your network - 2020 Edition

Are you sure about marking DNS / ICMP or ACK connections than their packet marks, because what im seeing that when i run speedtest some or sometimes entire bandwidth goes thru this QUEUE(DNS/ICMP/ACK) and as they have top prio actually choke my net. I changed it to only mark packets directly withou...
by ivicask
Wed Jul 22, 2020 7:18 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 275
Views: 507796

Re: Using RouterOS to QoS your network - 2020 Edition

Are you sure about marking DNS / ICMP or ACK connections than their packet marks, because what im seeing that when i run speedtest some or sometimes entire bandwidth goes thru this QUEUE(DNS/ICMP/ACK) and as they have top prio actually choke my net. I changed it to only mark packets directly withou...
by ivicask
Tue Jul 21, 2020 12:58 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 275
Views: 507796

Re: Using RouterOS to QoS your network - 2020 Edition

Are you sure about marking DNS / ICMP or ACK connections than their packet marks, because what im seeing that when i run speedtest some or sometimes entire bandwidth goes thru this QUEUE(DNS/ICMP/ACK) and as they have top prio actually choke my net. I changed it to only mark packets directly without...
by ivicask
Sun Jun 28, 2020 9:00 pm
Forum: General
Topic: Feature requests
Replies: 1744
Views: 639856

Re: Feature requests

Not sure if was asked but can we get option to specify multiple adress lists inside single firewall rule?
by ivicask
Tue Jun 23, 2020 3:35 pm
Forum: RouterBOARD hardware
Topic: RB4011 Metal temperature is really hot
Replies: 54
Views: 38430

Re: RB4011 Metal temperature is really hot

If cooler is hot it doesnt mean device is overheating it just means cooler is doing its job and taking the heat away from CPU or internal components.Did you ever had passively cooled GPU ?Its heatsink runs so hot even at idle that u cant touch it, but device is cool and works fine.
by ivicask
Tue Jun 23, 2020 11:48 am
Forum: General
Topic: PCQ Queue does not respect limits
Replies: 3
Views: 2484

Re: PCQ Queue does not respect limits

Got same problem, no matter what chain of mangle rules i set, prerouting,postrouting,forward, no matter what queues i try randomly some traffic just goes over limits and its not even properly detected by queues or its parents as you can see in example, parent queue should also show this traffic that...
by ivicask
Tue Jan 14, 2020 10:12 pm
Forum: Wireless Networking
Topic: CAPsMAN problem with Android
Replies: 8
Views: 5250

Re: CAPsMAN problem with Android

Same problem here with Samsung A70 at one customer and capsman, when roaming from ap to ap it drops net, its connected to wifi but says Internet may not be avaiable, you need to turn Wifi on off several times or just wait 5+ mins and it starts working. On other hand I have S10+ from Samsung and no i...
by ivicask
Sun Dec 22, 2019 3:59 pm
Forum: RouterOS beta
Topic: fq_codel or cake in v7
Replies: 68
Views: 41645

Re: fq_codel or cake in v7

Well, if you use PCQ you have some knobs to twiddle. I have improved ADSL2+ responsiveness with PCQ in simple queues by making the buffers smaller than the default (which otherwise seem to work well with 50+MBit speeds). For example on an ADSL2 annex m line with max-limit=1400k/16500k these queues ...
by ivicask
Thu Dec 19, 2019 1:18 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 180651

Re: v6.47beta [testing] is released!

Guscht You need to send supout.rif file to support@mikrotik.com and brief problem description. We are currently unable to reproduce such issue. ivicask Have you tried the 6.46 stable and 6.47 testing versions? RoMoN works for me now. Make sure both the end user and the agent is updated. If it is no...
by ivicask
Sat Dec 14, 2019 9:08 pm
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 180651

Re: v6.47beta [testing] is released!

ivicask - Have you reported this problem to support@mikrotik.com or https://help.mikrotik.com/servicedesk/customer/user/login?destination=portals ?? We are not aware of any RoMON problems; But some of your support confirmed it here, post #5 https://forum.mikrotik.com/viewtopic.php?f=21&t=154286...
by ivicask
Wed Dec 11, 2019 11:22 am
Forum: Announcements
Topic: v6.47beta [testing] is released!
Replies: 269
Views: 180651

Re: v6.47beta [testing] is released!

When is ROMON getting fixed?I need some other fixes from new betas, but they also break ROMON..
by ivicask
Sun Dec 08, 2019 2:10 pm
Forum: General
Topic: Doubts about DNS . [SOLVED]
Replies: 5
Views: 2650

Re: Doubts about DNS . [SOLVED]

Remove in your DHCP client setting if you want to use its dns or not.
by ivicask
Wed Nov 27, 2019 2:15 pm
Forum: Announcements
Topic: v6.46rc [testing] is released!
Replies: 16
Views: 19922

Re: v6.46rc [testing] is released!

Is ROMON working on last 2 versions?It seams broken to me, simple wireless bridge between 2 routers, no firewall rules, i can see router listed(MAC,ROUTER OS version, Router model) but it cant connect it just timeouts with disconnected from ROMON after 10 sec.
by ivicask
Wed Nov 27, 2019 9:14 am
Forum: Announcements
Topic: Newsletter 92
Replies: 39
Views: 41608

Re: Newsletter 92

in this case CAT6 is not about speed, but about better coverage. Using the aggregation feature, you can get better signal, where there was no signal before. Otherwise you would not need such a big antenna, if we would be aiming for speed in good coverage areas. Did you notice that the 100Mbit port ...
by ivicask
Wed Nov 27, 2019 8:32 am
Forum: Announcements
Topic: Newsletter 92
Replies: 39
Views: 41608

Re: Newsletter 92

Seriously what a fail, you put CAT6 modems capable of up to 300mbit and than you put 100mbit lan ports on those 2 external routers?
by ivicask
Tue Nov 26, 2019 3:44 pm
Forum: General
Topic: Port 8000 forwarding for HIKVISION camera not working
Replies: 9
Views: 8468

Re: Port 8000 forwarding for HIKVISION camera not working

I think first rule is problem, app exepcts 80 to be web port, yet you redirected it to 8080, try for test change it from 8080 to original 80.

Also you may need 554 UDP/TCP for RSTP stream.

Try also forward UDP of that 8000 for test.
by ivicask
Wed Nov 20, 2019 4:59 pm
Forum: Scripting
Topic: I need to control the Facebook and Youtube Bandwidth
Replies: 5
Views: 5860

Re: I need to control the Facebook and Youtube Bandwidth

/system scheduler add interval=30s name=YoutubeAdressList on-event="/system script run YoutubeDns" policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon start-date=jan/22/2019 start-time=12:24:55 Add this script with name "YoutubeDns" :local myServers { "g...
by ivicask
Thu Nov 07, 2019 12:11 am
Forum: RouterBOARD hardware
Topic: hAP ac2 crashes every week
Replies: 8
Views: 5667

Re: hAP ac2 crashes every week

I have one of those with uptime of one year, so wouldn't say its general issue, maybe rma it and ask for replacement? Or talk to mikrotik support first.
by ivicask
Wed Oct 30, 2019 3:18 pm
Forum: General
Topic: NEW Public Bandwith Test Server
Replies: 56
Views: 80287

Re: NEW Public Bandwith Test Server

Authentication failed for me.
by ivicask
Sat Oct 26, 2019 9:02 pm
Forum: Wireless Networking
Topic: WiFi4EU
Replies: 13
Views: 7977

Re: WiFi4EU

hello, tell me pls, the snippet from ue works on your mtik?
Ofc it works, you just need to unblock it in walled garden so it can load before user is authenticated to hotspot. Also their default snipet has typos different " and ' check that.
by ivicask
Thu Oct 24, 2019 7:52 pm
Forum: RouterOS beta
Topic: 7.0beta3 available in testing?
Replies: 40
Views: 16938

Re: 7.0beta3 available in testing?

I installed on my SXT 5, and now it cant connect to AP anymore(CLIENT BRIDGE MODE), authentication timeout or association timeout, it connected once for 5 sec than again breaks and loops this error.And when i perform scan it shows this single ap 10 times under all different channels which ofc isnt r...
by ivicask
Fri Sep 27, 2019 8:33 am
Forum: General
Topic: Laptops are trying to hack my router
Replies: 8
Views: 3100

Re: Laptops are trying to hack my router

What AV you used to scan?
by ivicask
Tue Sep 24, 2019 10:29 pm
Forum: RouterOS beta
Topic: Torrent client
Replies: 59
Views: 36668

Re: Torrent client

Well for me torrent client would be most awesome for home use, schedule download/s over night when nobody is using net to download some stuff on external drive, silent, and low power use compared to PC, + you can use the same drive for direct access over network ..

Big + 1 from me.
by ivicask
Tue Sep 17, 2019 11:36 pm
Forum: Wireless Networking
Topic: WiFi4EU
Replies: 13
Views: 7977

Re: WiFi4EU

I'm using mikrotik only as hotspot controller, and Aruba for APs, they are expensive, but work way better than any mikrotik ever will.
by ivicask
Mon Sep 16, 2019 8:25 am
Forum: Wireless Networking
Topic: cAP-ac Throughput & High Ping Problems
Replies: 33
Views: 12049

Re: cAP-ac Throughput & High Ping Problems

I allways have similar problems with mikrotik and 2.4 ghz , do you have b/g/n enabled? Try set it to -g/n only, or N only if all devices support it.
by ivicask
Sun Jul 07, 2019 10:03 pm
Forum: Announcements
Topic: v6.46beta [testing] is released!
Replies: 150
Views: 106696

Re: v6.46beta [testing] is released!

Wishes for 6.46: - WinBox => CAPsMAN: Reboot button for CAPs Yes, I agree. It is annoying in CAPsMAN network to manual restart every AP. APs are updated automatically from CAPsMAN, and all APs have firmware autoupdate=yes, but still required additional manual restart for firmware update. +1 for that
by ivicask
Tue Jun 11, 2019 2:47 pm
Forum: Wireless Networking
Topic: 2.4 4-way handshake timeout
Replies: 18
Views: 15442

Re: 2.4 4-way handshake timeout

Got email from Mikrotik. Explained the problem and how to reproduce it. They did... And don't currently have a fix. So high density with interference... If you see 4-way handshake time out in Caps-man... Don't fight it. Don't mess with support. Just buy the Ruckus radio and move on. I get those als...
by ivicask
Fri Mar 08, 2019 11:27 am
Forum: RouterBOARD hardware
Topic: MUM Europe 2019: new hardware
Replies: 66
Views: 28688

Re: MUM Europe 2019: new hardware

That Audience with Cat6 LTE looks super interesting, cant wait to see full specs and price.
by ivicask
Mon Mar 04, 2019 10:46 pm
Forum: Wireless Networking
Topic: Wireless outdoor range
Replies: 1
Views: 971

Re: Wireless outdoor range

Hello Mikrotik community, I am looking to deploy an outdoor AP for a hotspot, I was wondering what the maximum realistic range an outdoor AP can deliver for mobile phones, as far as I know, indoor APs can only deliver about 10-20 meters reliable before disconnections are experienced. Any help would...
by ivicask
Mon Jan 28, 2019 2:34 pm
Forum: General
Topic: Examples of using RAW firewall?
Replies: 34
Views: 25758

Re: Examples of using RAW firewall?

Thanks ivicask.
Rule was worked once. Now users from IP addresses of the Black list tring to connect to sip port 5060 and rule not working.
I think u should change all those blacklist to
for example from add address=37.0.0.0 -> address=37.0.0.0/24
by ivicask
Mon Jan 28, 2019 12:24 pm
Forum: General
Topic: Examples of using RAW firewall?
Replies: 34
Views: 25758

Re: Examples of using RAW firewall?

Thanks MKX. I tried all variants but rule is not working. I have task from my chief - block all connections on ports 5060-5080 from abroad. I tried to block one subnet 37.0.0.0 but rule not working :( Here are my firewall settings Regards. Rule actually seams working fine as u can see one block in ...
by ivicask
Tue Jan 22, 2019 7:54 pm
Forum: General
Topic: Mark the traffic for YouTube, Facebook, etc.
Replies: 29
Views: 25908

Re: Mark the traffic for YouTube, Facebook, etc.

Hmmm Okay, so that sounds promising. However what you are telling me is that initial traffic will ALWAYS get out and not be rerouted because its done in real time not prerouting. Also, the script is not timed to user access but to a rote timing scheme that will run regardless if streaming is done (...
by ivicask
Tue Jan 22, 2019 3:36 pm
Forum: General
Topic: Mark the traffic for YouTube, Facebook, etc.
Replies: 29
Views: 25908

Re: Mark the traffic for YouTube, Facebook, etc.

@anav, tls-host only works for TCP, you should use ivicask script to read googlevideo.com dns from catch and write it to address list Thats basically what OP @mladen074 did but in simpler script, i actually jumped to lasts posts and missed the first post from him :) Not sure which one is better if ...
by ivicask
Tue Jan 22, 2019 2:52 pm
Forum: General
Topic: Mark the traffic for YouTube, Facebook, etc.
Replies: 29
Views: 25908

Re: Mark the traffic for YouTube, Facebook, etc.

yeah good stuff, i noticed that when you are using Mobile app, it uses UDP 443 instead of TCP. For desktop, i believe that google QUIC protocol is disabled by default, hence should work with TCP. (in where tls-host only works) It streams to my Windows 10 PC (Chrome) in UDP protocol also. The above ...
by ivicask
Tue Jan 22, 2019 2:34 pm
Forum: General
Topic: Mark the traffic for YouTube, Facebook, etc.
Replies: 29
Views: 25908

Re: Mark the traffic for YouTube, Facebook, etc.

Maybe google is using and additional dns structure. What ip's are being streamed from? which doman is that? You can contribute to the thread. I figured it, its streaming it over UDP actualy for me, i had TCP protocol as TLS matcher requires it and this of course didint work for me. I added this scr...
by ivicask
Tue Jan 22, 2019 2:16 pm
Forum: General
Topic: Mark the traffic for YouTube, Facebook, etc.
Replies: 29
Views: 25908

Re: Mark the traffic for YouTube, Facebook, etc.

I also tried implementing you tube Traffic control via this and its absolutely not working. TSL host thing is totally useless in this case and doesnt pick actual IP of video stream *.googlevideo.com *.youtube.com give me about 4 ip to my address list, but when i start youtube video it comes from so...
by ivicask
Tue Jan 22, 2019 12:45 pm
Forum: General
Topic: Mark the traffic for YouTube, Facebook, etc.
Replies: 29
Views: 25908

Re: Mark the traffic for YouTube, Facebook, etc.

I also tried implementing you tube Traffic control via this and its absolutely not working. TSL host thing is totally useless in this case and doesnt pick actual IP of video stream *.googlevideo.com *.youtube.com give me about 4 ip to my address list, but when i start youtube video it comes from so...
by ivicask
Tue Jan 22, 2019 11:58 am
Forum: General
Topic: Mark the traffic for YouTube, Facebook, etc.
Replies: 29
Views: 25908

Re: Mark the traffic for YouTube, Facebook, etc.

I also tried implementing you tube Traffic control via this and its absolutely not working. TSL host thing is totally useless in this case and doesnt pick actual IP of video stream *.googlevideo.com *.youtube.com give me about 4 ip to my address list, but when i start youtube video it comes from som...
by ivicask
Thu Jan 10, 2019 11:42 am
Forum: General
Topic: Hairpin NAT not working on RouterOS 6 line WAN load balancing
Replies: 8
Views: 2250

Re: Hairpin NAT not working on RouterOS 6 line WAN load balancing

Can anyone support me this problem. Thank you! For me doesnt work without this rule also add action=masquerade chain=srcnat comment=HAIRPIN dst-address=192.168.1.0/24 out-interface=LAN src-address=192.168.1.0/24 Change ips and out interface to match your network. He have this rule already add actio...
by ivicask
Thu Jan 10, 2019 11:25 am
Forum: General
Topic: Hairpin NAT not working on RouterOS 6 line WAN load balancing
Replies: 8
Views: 2250

Re: Hairpin NAT not working on RouterOS 6 line WAN load balancing

Can anyone support me this problem. Thank you! For me doesnt work without this rule also add action=masquerade chain=srcnat comment=HAIRPIN dst-address=192.168.1.0/24 out-interface=LAN src-address=192.168.1.0/24 Change ips and out interface to match your network. He have this rule already add actio...
by ivicask
Thu Jan 10, 2019 10:59 am
Forum: General
Topic: Hairpin NAT not working on RouterOS 6 line WAN load balancing
Replies: 8
Views: 2250

Re: Hairpin NAT not working on RouterOS 6 line WAN load balancing

Can anyone support me this problem.
Thank you!
For me doesnt work without this rule also

add action=masquerade chain=srcnat comment=HAIRPIN dst-address=192.168.1.0/24 out-interface=LAN src-address=192.168.1.0/24

Change ips and out interface to match your network.
by ivicask
Mon Dec 31, 2018 10:17 pm
Forum: Scripting
Topic: pppoe status script [SOLVED]
Replies: 7
Views: 14439

Re: pppoe status script [SOLVED]

this is not helping because i have more than 80 pppoe-out1-80 so any one disconect will be disconnect all Create several profiles for each pppoe with matching pppoe name inside, u can easy automate it to add via command line.. Or someone with a bit scripting knowlage could make u script which loops...
by ivicask
Mon Dec 31, 2018 10:09 pm
Forum: General
Topic: Why (not) use Hairpin NAT
Replies: 28
Views: 10302

Re: Why (not) use Hairpin NAT

Now i have set in my RDC connection file public dns name with ports matching which server i wanna access blablab.dyndns.org:3000 blablab.dyndns.org:4000 blablab.dyndns.org:5000 I see that could be a problem. But I would not have done it this way. For what you need to pay for dyndns.org each year to...
by ivicask
Mon Dec 31, 2018 9:30 pm
Forum: General
Topic: Why (not) use Hairpin NAT
Replies: 28
Views: 10302

Re: Why (not) use Hairpin NAT

server0.home.com 192.168.10.50 server1.home.com 192.168.10.51 server2.home.com 192.168.10.52 server3.home.com 192.168.10.53 server4.home.com 192.168.10.54 server5.home.com 192.168.10.55 server6.home.com 192.168.10.56 server7.home.com 192.168.10.57 server8.home.com 192.168.10.58 server9.home.com 192...
by ivicask
Mon Dec 31, 2018 9:06 pm
Forum: General
Topic: Why (not) use Hairpin NAT
Replies: 28
Views: 10302

Re: Why (not) use Hairpin NAT

Use internal DNS. When someone on the internet asks for your server web.myserver.com on inernal ip 192.168.10.50 he asks a public DNS and gets IP 85.12.134.20 (sample IP) Then when you are on the internal net, you will use the DNS server you get from your DHCP server. That should not be google or o...
by ivicask
Mon Dec 31, 2018 8:50 pm
Forum: General
Topic: Why (not) use Hairpin NAT
Replies: 28
Views: 10302

Re: Why (not) use Hairpin NAT

I agree with quoted comment by thirdstreetzero. Just think about going IPv6 ... no NAT there. So HairpinNAT really is an obscure solution to a specific problem ... and use case of @ivicask is just further exagerated misuse. Quite a few times people requested full-featured DNS server for ROS ... and...
by ivicask
Mon Dec 31, 2018 11:55 am
Forum: General
Topic: Why (not) use Hairpin NAT
Replies: 28
Views: 10302

Re: Why not use Hairpin NAT

Not sure what your post means?Why not to use? Anyways, with DNS you can only do single internal host, if u need multiple ips to work with DNS name inside ur network u simple must use hairpin. For example how would you access 3 different IPs via dns name ?If you add static entry for like mydomain.dyn...
by ivicask
Thu Dec 27, 2018 4:21 pm
Forum: Wireless Networking
Topic: LHG 60G experience
Replies: 608
Views: 194065

Re: LHG 60G experience

what do you expect more if you bond 5ghz+60ghz? anyway there is 1gbps ethernet port, i dont get your idea (: my point, just to get ANY connection during bad weather, okay let it be at least 100mbps for snow fall or heavy rain, so the customers would not fuck up to red our phones :) What if you go a...
by ivicask
Thu Dec 27, 2018 11:20 am
Forum: Wireless Networking
Topic: LHG 60G experience
Replies: 608
Views: 194065

Re: LHG 60G experience

Yes LHG60 is great hardware with improved distance and 5 GHZ backup it 'll be a must for 2019 wating for more info
I wonder if its only backup failover, or you can agregate 2 links 60+5ghz at the same time for bigger throughput along for instant failover.
by ivicask
Sat Dec 08, 2018 10:48 pm
Forum: General
Topic: Crowd Funding of v7
Replies: 32
Views: 12110

Re: Crowd Funding of v7

What do you mean with queue "parallelization"? Each parent queue already works on separate CPU core in v6. Really?Because when i asked support why cant my RB750Gr3 route more than 150mbit of traffic with queues and single core gets stuck at 100% while router all cores arent going even ove...
by ivicask
Mon Dec 03, 2018 3:00 pm
Forum: Announcements
Topic: MikroTik smartphone app (ex Tik-App)
Replies: 487
Views: 272271

Re: Tik App, MikroTik android utility ALPHA test

I wonder is i possible to add some kinda of bandwidth test into this app?So i can quickly test actual wifi performance from router to my phone directly, it would be the most useful thing ever.
by ivicask
Thu Nov 29, 2018 2:01 pm
Forum: General
Topic: QoS and Firewall Mangle questions [SOLVED]
Replies: 2
Views: 1359

Re: QoS and Firewall Mangle questions [SOLVED]

Check if you have fastrack rule in firewall, disable it.
by ivicask
Thu Nov 22, 2018 9:27 am
Forum: General
Topic: QOS not working with file hosting sites like Megaupload
Replies: 16
Views: 4161

Re: QOS not working with file hosting sites like Megaupload

I'm leaving some reserved bandwidth for dns and some other small packets, and also downloads get grouped under another parent which has limit a bit below my total download speed, this way it doesn't saturate download and gives time for queues to drop packets so everything works smooth. If u like i ...
by ivicask
Wed Nov 21, 2018 8:06 pm
Forum: General
Topic: Why blacklist burteforcers VS just dropping the ports/service?
Replies: 7
Views: 2078

Re: Why blacklist burteforcers VS just dropping the ports/service?

If you have drop rules that simply drop packets to ports/services you do not use like ssh, ftp, telnet, winbox, etc... what is the advantage to creating a timed black list and dropping that? Is it to gain the logs and perform further action? If you have the IP/Services turned for all those is there...
by ivicask
Wed Nov 21, 2018 5:34 pm
Forum: General
Topic: Queue Trees, CPU Utilization and Watchdog reboots
Replies: 12
Views: 3544

Re: Queue Trees, CPU Utilization and Watchdog reboots

If these reboots are just because router is slow to respond due to high cpu load, but does respond, you could disable watchdog for time being... I did that, than router froze and was not accessible for 5mins and until I force rebooted him via power, it still did switch traffic to my acces point con...
by ivicask
Wed Nov 21, 2018 5:28 pm
Forum: General
Topic: Why blacklist burteforcers VS just dropping the ports/service?
Replies: 7
Views: 2078

Re: Why blacklist burteforcers VS just dropping the ports/service?

If you have drop rules that simply drop packets to ports/services you do not use like ssh, ftp, telnet, winbox, etc... what is the advantage to creating a timed black list and dropping that? Is it to gain the logs and perform further action? If you have the IP/Services turned for all those is there...
by ivicask
Wed Nov 21, 2018 8:39 am
Forum: General
Topic: QOS not working with file hosting sites like Megaupload
Replies: 16
Views: 4161

Re: QOS not working with file hosting sites like Megaupload

I'm leaving some reserved bandwidth for dns and some other small packets, and also downloads get grouped under another parent which has limit a bit below my total download speed, this way it doesn't saturate download and gives time for queues to drop packets so everything works smooth. If u like i c...
by ivicask
Wed Nov 21, 2018 12:32 am
Forum: General
Topic: QOS not working with file hosting sites like Megaupload
Replies: 16
Views: 4161

Re: QOS not working with file hosting sites like Megaupload

add action=mark-connection chain=postrouting comment=DOWNLOADS_5+MB connection-bytes=\ 5000000-0 new-connection-mark=HTTP_DOWNLOADS_5+_2 passthrough=yes port=80,443,8080 protocol=\ tcp add action=mark-packet chain=postrouting connection-mark=DOWNLOADS_5+_2 new-packet-mark=\ HTTP_DOWNLOADS_5+ passthr...
by ivicask
Tue Nov 20, 2018 10:14 pm
Forum: General
Topic: QOS not working with file hosting sites like Megaupload
Replies: 16
Views: 4161

Re: QOS not working with file hosting sites like Megaupload

You using that download manager of theirs? I downloaded alot from mega thru browser directly this days and goes properly thru my queue for large downloads, simple mangle of ports 443,80,8080 and bytes set to 5+mb.
by ivicask
Tue Nov 20, 2018 6:16 pm
Forum: General
Topic: Queue Trees, CPU Utilization and Watchdog reboots
Replies: 12
Views: 3544

Re: Queue Trees, CPU Utilization and Watchdog reboots

I actually have the same issue with exact same router, got 3 random watchdoog reboots so far in past 10 days, but this first time ever happen to me since latest update (44beta28), but didint had much time to debug it or change versions..
by ivicask
Mon Nov 12, 2018 10:22 am
Forum: Announcements
Topic: Newsletter 85
Replies: 30
Views: 24260

Re: Newsletter 85

And more LTE products with old and slow cat4 modems...I dont understand how can anyone even get more than 100mbit from this, i cant get more than 30mbit sitting next to tower, while anything else from super old mobile phone(6-7 years) to 2x cheaper routers achieve at least 2x speed if not more.. Why...
by ivicask
Mon Nov 05, 2018 3:00 pm
Forum: General
Topic: Need help with VPN routing
Replies: 0
Views: 754

Need help with VPN routing

So im preparing one CRC router for my customer, and i want to make separate DHCP POOL for VPN users.And this does work without problem unless i un-tick the "use default gateway on remote network" under VPN profile under windows, than i cant ping between subnets anymore.But if i dont untick...
by ivicask
Thu Oct 25, 2018 10:06 am
Forum: General
Topic: Port Scan Drop ?
Replies: 6
Views: 3548

Re: Port Scan Drop ?

Attacker can't use spoofed IP for scanning because such results wouldn't make it back to him (unless he is your ISP and all your traffic pass through him) Spoofed IP is used mostly for (D)DoS attacks where you don't care about response or where you want the response to be sent to someone else on pu...
by ivicask
Wed Oct 24, 2018 3:01 pm
Forum: General
Topic: Port Scan Drop ?
Replies: 6
Views: 3548

Re: Port Scan Drop ?

Best practice says you should drop all unknown input, there's no need to make rules specifically for port scanners. Yea, but than attacker can scan for ports and for example find my none standard RDP port and than do further attacks on it, this way he get IP block for port scan attempts and he does...
by ivicask
Fri Sep 28, 2018 12:15 pm
Forum: General
Topic: something is wrong with my DNS resolving...
Replies: 8
Views: 2606

Re: something is wrong with my DNS resolving...

https://i.imgur.com/xjwAmyu.jpg My DNS settings looks ok to me, i did not make any changes for years. This problem occurred yesterday without any modification from my side. I also noticed unauthorized attempt to log in into my router viewtopic.php?f=2&t=139702 My current suspicion is that someo...
by ivicask
Sat Sep 22, 2018 8:40 pm
Forum: General
Topic: restore back to identical devices never works :(
Replies: 28
Views: 7195

Re: restore back to identical devices never works :(

At the very leat, we should be able to import a backup into another device of same model and RoS/bootloader version. Certificates, users and all. I think that is working. But in practice it is not enough. E.g. I have 2 installs of CCR1009-8G-1S-1S+ which when broken is no longer available and would...
by ivicask
Tue Sep 18, 2018 6:11 pm
Forum: General
Topic: Port 60000 attacks, anyone info on this?
Replies: 11
Views: 5136

Re: Port 60000 attacks, anyone info on this?

I'm seeing them too. From two different routers: [admin@MikroTik] > /log print count-only where message~":60000->" 6 and [admin@MikroTik] > /log print count-only where message~":60000->" 14 They are stealth in the sense that they avoid typical blacklisting attempts; just a few c...
by ivicask
Tue Sep 18, 2018 4:46 pm
Forum: General
Topic: Port 60000 attacks, anyone info on this?
Replies: 11
Views: 5136

Re: Port 60000 attacks, anyone info on this?

... i was just wondering if anyone else is getting probed via this port as it seams im catching this on several locations and not 100% sure what to do about it. Could be, but I don't notice as I have a general drop rule at the end of firewall rules list. It does show increasing number of connection...
by ivicask
Tue Sep 18, 2018 4:33 pm
Forum: General
Topic: Port 60000 attacks, anyone info on this?
Replies: 11
Views: 5136

Re: Port 60000 attacks, anyone info on this?

... i was just wondering if anyone else is getting probed via this port as it seams im catching this on several locations and not 100% sure what to do about it. Could be, but I don't notice as I have a general drop rule at the end of firewall rules list. It does show increasing number of connection...
by ivicask
Tue Sep 18, 2018 4:29 pm
Forum: General
Topic: Port 60000 attacks, anyone info on this?
Replies: 11
Views: 5136

Re: Port 60000 attacks, anyone info on this?

I don't get it why would anybody want to allow connections to some random port (3389 is as nice random number as any other between 0 and 65536) from internet at large? Your firewall rule is not complete ... attacker can easily change source port to some other and your rule won't catch anything. I g...
by ivicask
Tue Sep 18, 2018 4:16 pm
Forum: General
Topic: Port 60000 attacks, anyone info on this?
Replies: 11
Views: 5136

Re: Port 60000 attacks, anyone info on this?

I don't get it why would anybody want to allow connections to some random port (3389 is as nice random number as any other between 0 and 65536) from internet at large? Your firewall rule is not complete ... attacker can easily change source port to some other and your rule won't catch anything. I g...
by ivicask
Tue Sep 18, 2018 11:45 am
Forum: General
Topic: Port 60000 attacks, anyone info on this?
Replies: 11
Views: 5136

Port 60000 attacks, anyone info on this?

After recently one of our server got hacked over RDC and got crpytolocker i noticed theres frequent port 60000 TCP to 3389 and also other random ports attemps. After bit googling it says that port 60000 is "deepthroat" trojan attack port. For now i added firewall rule to catch all source p...
by ivicask
Mon Sep 17, 2018 1:17 pm
Forum: General
Topic: How to remotely administer Mikrotik routers in safeway
Replies: 19
Views: 4080

Re: How to remotely administer Mikrotik routers in safeway

Hello As we all know it's very important how to configure firewall and services on our Miktotik routers. A lot of us are using Winbox for remote administrating because its easiest, changing port from 8021 to any other doesnt rise security level. So next step is to use SSH but I read that I can't fo...
by ivicask
Fri Sep 14, 2018 4:26 pm
Forum: Beginner Basics
Topic: Is it possible make queue tree under simple queue
Replies: 5
Views: 3354

Re: Is it possible make queue tree under simple queue

Why not create new PCQ queue with desired limits, but add a bit above burst limits, set this queue to hotspot interface, it should smoothen out browsing while downloading.
by ivicask
Tue Aug 28, 2018 10:42 pm
Forum: Announcements
Topic: v6.43rc [release candidate] is released!
Replies: 557
Views: 224019

Re: v6.43rc [release candidate] is released!

I cant update CCR1009-7G-1C from 6.43rc51 to 6.43rc64, i click check for updates, download&install, after reboot i still have old version.Tried also manually downloading the file and puting into root and rebooting, same thing. EDIT:I figured it , i had other router package so it failed to select...
by ivicask
Sun Aug 05, 2018 7:07 pm
Forum: Wireless Networking
Topic: High Ping on 2.4GHz
Replies: 13
Views: 4666

Re: High Ping on 2.4GHz

I often have this problem with 2.4ghz, where its un-usable, without any close networks to interfere, what helps alot is set mode to G/N, or only N if you dont need backward compatibility.
by ivicask
Sat Aug 04, 2018 10:55 am
Forum: Wireless Networking
Topic: Caps selecting same channel
Replies: 32
Views: 16961

Re: Caps selecting same channel

Anything new on this topic? CAPSMAN still uses the same frequency for all 5 GHz radios on my hap AC devices regardless of any configuration I might try. There is only one setup that works: in case I DON'T set any frequencies AND uncheck "skip DFS channels" I end up having different channe...
by ivicask
Mon Jul 09, 2018 12:40 pm
Forum: Beginner Basics
Topic: SSID for kids Zone with OpenDNS
Replies: 14
Views: 3938

Re: SSID for kids Zone with OpenDNS

HI, I haven't got a different DHCP server for each SSID because I couldn't create one. Couldn't add New DHCP server - can not run on slave interface (6) Sorry to be dum but this is my debut with routerboard OS. I think that having a different DHCP server for each SSID is the way I'll like to go for...
by ivicask
Mon Jul 09, 2018 12:15 pm
Forum: Beginner Basics
Topic: SSID for kids Zone with OpenDNS
Replies: 14
Views: 3938

Re: SSID for kids Zone with OpenDNS

Hi, I managed to create multiple SSID in my house. One of the SSID is for my children and their friends (9 years old). The idea of having multiple ssid was to be able to control the content on the kids wifi using OpenDNS. So far, I haven't managed to figure out how to set dns per ssid so that my ma...
by ivicask
Thu Jun 21, 2018 9:25 am
Forum: Wireless Networking
Topic: wAP LTE kit - phenomenally bad performance
Replies: 20
Views: 7934

Re: wAP LTE kit - phenomenally bad performance

my phone does 4g 50+download and 15+ upload at same location, same provider, different SIM You can forget about it, alot of users including me already complained about it, dont bother with this device if u expect any normal speeds, its just terrible. https://forum.mikrotik.com/viewtopic.php?f=7&...
by ivicask
Mon Jun 11, 2018 10:39 am
Forum: General
Topic: MT Router honeypot.
Replies: 20
Views: 5941

Re: MT Router honeypot.

I wonder if Mikrotik has honeypot routers, pretty sure they dont or they would already capture all the previous exploits before it would spread like they did.

Any official statement regarding this from mikrotik?
by ivicask
Sun Jun 10, 2018 8:33 pm
Forum: Wireless Networking
Topic: 60Ghz 2.4km - possible?
Replies: 41
Views: 14569

Re: 60Ghz 2.4km - possible?

Hey folks. We need to replace one of our 5Ghz Links due to high noise. We would like to switch to 60 Ghz. The Link is 2.4km and has 600 meters of altitude change. We don’t need a Gigabit. 100 mbits would be plenty. Has anyone any experience if this is even possible? We got about 15% less Air preass...
by ivicask
Thu Jun 07, 2018 9:22 am
Forum: Wireless Networking
Topic: Suggested CAPsMAN Hardware
Replies: 11
Views: 3738

Re: Suggested CAPsMAN Hardware

Ok, Thanks for the replies. Local Forwarding isn't an option, so we need some model with higher CPU. Also Fast-Track can't be used, because we need some firewall rules to hide the rest of our network from the CAPs Clients. I think we will go with RB1100x4 or maybe we will try the RB3011. I will rep...
by ivicask
Wed Jun 06, 2018 12:08 am
Forum: Wireless Networking
Topic: Suggested CAPsMAN Hardware
Replies: 11
Views: 3738

Re: Suggested CAPsMAN Hardware

What's wrong with RB750Gr3, I use it with 7 Wap Ac, we have 150mbit line, and few queue tree rules, one simple queue for guest network, and up to 70 clients, works fine. Note I use local forwarding, not sure if it would work so good with capsman forwarding, u may need use higher cpu power product th...
by ivicask
Tue Jun 05, 2018 2:03 pm
Forum: Announcements
Topic: MikroTik News June 2018 (Issue #83)
Replies: 44
Views: 32898

Re: MikroTik News June 2018 (Issue #83)

- new, improved SXT LTE kit with two Ethernet ports Same price but ....inferior....:( Yes, hope MT stops recycling those old modems, and give us some LTE product with LTE 6+ category What do you guys mean? It is much better than SXT LTE first generation: "In comparison with our first generatio...
by ivicask
Tue Jun 05, 2018 9:35 am
Forum: Announcements
Topic: MikroTik News June 2018 (Issue #83)
Replies: 44
Views: 32898

Re: MikroTik News June 2018 (Issue #83)

- new, improved SXT LTE kit with two Ethernet ports

Same price but ....inferior....:(
Yes, hope MT stops recycling those old modems, and give us some LTE product with LTE 6+ category
by ivicask
Mon Jun 04, 2018 3:29 pm
Forum: RouterBOARD hardware
Topic: wAP ac overheating?Crashing
Replies: 10
Views: 7647

wAP ac overheating?Crashing

I have one wAP ac whos giving me problems for some time, but unfortunately is also out of warranty so i just wonder what are normal temps for this device?When i copy files over 5ghz interface at around (450mbit/s ) speeds, the router hits 80c and than randomly starts crashing and its not visible on ...
by ivicask
Thu May 24, 2018 1:53 pm
Forum: RouterBOARD hardware
Topic: wAP ac not discoverable over ethernet
Replies: 5
Views: 3786

Re: wAP ac not discoverable over ethernet

I have couple of wAP ac devices that for some odd reason doesn't come up in the Winbox discovery. Connecting via MAC address fails too. Connecting over IP is OK. If I'm connected to Wifi, then everything works as expected (discovery + connecting over MAC and IP). Is this expected behavior? Coz for ...
by ivicask
Wed May 16, 2018 9:40 am
Forum: Announcements
Topic: Future of LTE products, user feedback requested
Replies: 208
Views: 102753

Re: Future of LTE products, user feedback requested

I would be happy with product like this

https://mikrotik.com/product/mant_lte_5o

But with integrated modem and 1 lan port, nothing more..
And atleast CAT6 is a MUST so it doesnt work like some 10 year old phone/device with horrific perfomance like current WAP LTE works.
by ivicask
Sat May 12, 2018 10:46 am
Forum: RouterBOARD hardware
Topic: 3x3 MIMO antennas >20dBi
Replies: 19
Views: 4681

Re: 3x3 MIMO antennas >20dBi

Just wondering if someone can tell me why there are no 3x3 MIMO antennas on the market much greater than 20dBi ? I have a couple of RB921UAGS-5SHPacD-NM(triple chain capable) doing about 8KM's point to point, but limited to 2x2 due to antenna limitations(cant find a commercial 28 to 30dBi antenna w...
by ivicask
Mon Apr 23, 2018 4:12 pm
Forum: Beginner Basics
Topic: WiFi comparison between hAP ac2 and hAP ac
Replies: 12
Views: 19500

Re: WiFi comparison between hAP ac2 and hAP ac

I'm doing WiFi coverage tests between 2 Models: RBD52G-5HacD2HnD-TC (I will call it hAPac2) RB962UiGS-5HacT2HnT (I will call it hAPac) WiFi comparison between hAP ac2 and hAP ac.png The suggested price of both models results in a price difference of $ 60.00 My question: Where is such a big differen...
by ivicask
Mon Apr 23, 2018 3:17 pm
Forum: Announcements
Topic: Advisory: Vulnerability exploiting the Winbox port [SOLVED]
Replies: 203
Views: 259530

Re: Advisory: Vulnerability exploiting the Winbox port

But that whats the point of this, i ran it 3 times and got all my ports listed 3 times before mikrotik blocked it, "attacker" already have all it needs. Scan this 93.155.148.98 - my IP address and tell me the open ports please! It shows none now, but is this site already on your block lis...
by ivicask
Mon Apr 23, 2018 3:03 pm
Forum: Announcements
Topic: Advisory: Vulnerability exploiting the Winbox port [SOLVED]
Replies: 203
Views: 259530

Re: Advisory: Vulnerability exploiting the Winbox port

But if i run it from https://mxtoolbox.com/SuperTool.aspx?action=scan, it finishes every time and shows my open ports on router without blocking it.. Try for your self. OK, try this : ip fi fi add action=add-src-to-address-list address-list=Port_Scanner address-list-timeout=1w chain=input comment=&...
by ivicask
Mon Apr 23, 2018 2:34 pm
Forum: Announcements
Topic: Advisory: Vulnerability exploiting the Winbox port [SOLVED]
Replies: 203
Views: 259530

Re: Advisory: Vulnerability exploiting the Winbox port

What do do : 1) Firewall the Winbox port from the public interface, and from untrusted networks. It is best, if you only allow known IP addresses to connect to your router to any services, not just Winbox. We suggest this to become common practice. As an alternative, possibly easier, use the "...
by ivicask
Wed Apr 11, 2018 12:28 pm
Forum: RouterBOARD hardware
Topic: Hardware for Traffic Shaping ~500mbps
Replies: 3
Views: 1911

Re: Hardware for Traffic Shaping ~500mbps

Hi Everyone, I am looking for a recommendation for hardware that is capable of doing traffic shaping on a line that is about 500dn/100up without choking. I currently have a 300/20 link and am using other vendor hardware that employs hardware offloading that is reaching it's limit due to QOS turning...
by ivicask
Sun Apr 08, 2018 5:14 pm
Forum: General
Topic: Proxy causes 100% load on only 30mbit bandwidth?
Replies: 1
Views: 1242

Proxy causes 100% load on only 30mbit bandwidth?

I have one RB911G connected to another wifi as client, and i just want to use it as proxy server so i can add it to my Dropbox or Mozila settings so i can surf over other net. Moment i run speedtest CPU gets lucked down to 100% and cant pass more than 30mbit, while im having 50mbit speed.The cache i...
by ivicask
Sun Apr 08, 2018 2:30 pm
Forum: General
Topic: Huge outgoing DNS requests (100gb in week)
Replies: 10
Views: 3097

Re: Huge outgoing DNS requests (100gb in week)

Well it simple stopped, now it had like 30mb dns traffic in a week, i did nothing, upgraded or even rebooted router.

Will monitor if it happens again.
by ivicask
Fri Apr 06, 2018 5:24 pm
Forum: General
Topic: Huge outgoing DNS requests (100gb in week)
Replies: 10
Views: 3097

Re: Huge outgoing DNS requests (100gb in week)

6.41rc52, doubt it's infected, it was installed 2 months ago, had latest version of os since installed, I have very stric firewall rules, I drop dns requests from net etc.. router has complex pass etc.
by ivicask
Fri Apr 06, 2018 3:33 pm
Forum: General
Topic: Huge outgoing DNS requests (100gb in week)
Replies: 10
Views: 3097

Re: Huge outgoing DNS requests (100gb in week)

Wireshark shows all standard query packets, and gets responding ip addresses resolved back , but i do see them repeating, even it already got proper ip adresses reported back, and domain and ip exist. Still doesnt make sense, if it does return proper IP why is it repeating requests and not simple c...
by ivicask
Fri Apr 06, 2018 3:27 pm
Forum: General
Topic: Huge outgoing DNS requests (100gb in week)
Replies: 10
Views: 3097

Re: Huge outgoing DNS requests (100gb in week)

Check the DNS cache, but this is a likely explanation, depending on the number of clients using your DNS. Even if u unplug entire network, meaning only Mikrotik leaves, this DNS requests still go . And we are talking about like 20 clients max who use internet lightly, its impossible they do 100gb D...
by ivicask
Fri Apr 06, 2018 2:57 pm
Forum: General
Topic: Huge outgoing DNS requests (100gb in week)
Replies: 10
Views: 3097

Re: Huge outgoing DNS requests (100gb in week)

Check the DNS cache, but this is a likely explanation, depending on the number of clients using your DNS. Even if u unplug entire network, meaning only Mikrotik leaves, this DNS requests still go . And we are talking about like 20 clients max who use internet lightly, its impossible they do 100gb D...
by ivicask
Fri Apr 06, 2018 11:20 am
Forum: General
Topic: MUM berlin
Replies: 28
Views: 5730

Re: MUM berlin

Ah common Mikrotik, mANT 5o LTE, at first i was YES, finally new LTE device, than realized its just antena. Was it a problem to give us such product with builtin LTE modem of higher category than current ones you have.Thats all pointless what you did.WAP LTE performs so bad, no antena will help it, ...
by ivicask
Fri Apr 06, 2018 9:58 am
Forum: General
Topic: Huge outgoing DNS requests (100gb in week)
Replies: 10
Views: 3097

Huge outgoing DNS requests (100gb in week)

I just installed one HAP ac at one customer, they got NEW HP switch with fiber connection to internet from ISP, and its connected to my LAN1 port on Mikrotik which has fixed ip 192.168.1.3, than all is routed out thru LAN port 2 on mikrotik on range 192.168.100.0/24 to customers internal netowrk. No...
by ivicask
Thu Mar 29, 2018 2:48 pm
Forum: General
Topic: Router + switch + ap all in one solution
Replies: 15
Views: 3938

Re: Router + switch + ap all in one solution

I don't think so. The RB750Gr3 is a nice router, check in the specs what its achievable performance is, but when you are talking about 1Gbps internet and of course you are going to speedtest that, this class of router is simply not going to cut it (with a manageable configuration w.r.t firewall and...
by ivicask
Sun Mar 25, 2018 4:39 pm
Forum: General
Topic: Feature requests
Replies: 1744
Views: 639856

Re: Feature requests

Hello to disable DNS attacking please add listen address on better from use ip firewall filters /ip dns allow-remote-requist=yes /ip dns listen-src-address=192.168.88.0/24,x.xx,y.y.y Regards Cant you already do that via firewall, dont understand what more you need, if you want to block DNS requests...
by ivicask
Tue Mar 06, 2018 12:14 pm
Forum: General
Topic: Cant ping by hostname outside mikrotik via IPIP tunnel
Replies: 0
Views: 797

Cant ping by hostname outside mikrotik via IPIP tunnel

So i created an IPIP tunel between 2 locations, NAT and routes are properly added and i can ping without issue networks form both sides, enter network shares, RDC etc. Problem is i cant access any of them by hostname of server/computer. Mikrotik from its console can ping by name without issues, but ...
by ivicask
Mon Feb 12, 2018 4:38 pm
Forum: RouterBOARD hardware
Topic: CAP ac bad Antenna design?
Replies: 95
Views: 37118

Re: CAP ac bad Antenna design?

The new hAPac^2 and cAPac have two chains, since most devices only have 2 chains and the third chain is rarely used. What about load balancing between chains?What if i have 20 + various devices which have mix of 1 or 2 chains, arent all 3 chains on Mikrotik device used and give better overall throu...
by ivicask
Mon Feb 05, 2018 2:45 pm
Forum: General
Topic: Shorten URL via Mikrotik, possible?
Replies: 1
Views: 1183

Shorten URL via Mikrotik, possible?

I wonder if its posibble to shroten URL somehow from mine mikrotik router for one TV in network.I tried using online URL shortners but they are not realible or have link expiration or max opening.And its too complicated for me to enter this long URL who sometimes changes into TV. For xample link loo...
by ivicask
Tue Jan 30, 2018 11:18 am
Forum: Wireless Networking
Topic: Tired of disconnection problem
Replies: 4
Views: 1554

Re: Tired of disconnection problem

I have same issue on several locations with different aps.. For example this is my HOME, and the client that says extnesive data loos is a TV who doesnt move inch, and as u can see signal is more than powerful(-48-62), still i get random disconnects for all devices at home, Philips TV, HTC phone, AS...
by ivicask
Tue Jan 16, 2018 3:07 pm
Forum: General
Topic: Block many websites
Replies: 20
Views: 22442

Re: Block many websites

New and exciting way to block things introduced in latest 6.41, block by SSL certificate name with TLS-HOST: /ip firewall filter add action=drop chain=forward protocol=tcp tls-host=*facebook.com What about sites who dont use SSL?Or does sites SSL certificate needs to be named same name as site?How ...
by ivicask
Tue Jan 16, 2018 2:58 pm
Forum: General
Topic: Block many websites
Replies: 20
Views: 22442

Re: Block many websites

That is indeed very simple, but unfortunately it will not work correctly! One IP address can handle multiple websites, so when you block this way you will block other sites as well. Well than in that case you can do DNS block /ip dns static add address=127.0.0.1 regexp=facebook.com etc And in order...
by ivicask
Tue Jan 16, 2018 2:49 pm
Forum: General
Topic: Block many websites
Replies: 20
Views: 22442

Re: Block many websites

Thanks Normis, By ip you mean to block the ip addresses of websites in Firewall->Filter Rules right? I ll try that /ip firewall address-list add address=facebook.com list=blocked_web add address=youtube.com list=blocked_web add address=whatever.com list=blocked_web etc continue the list from your e...
by ivicask
Sat Dec 30, 2017 8:01 pm
Forum: Wireless Networking
Topic: SXTsq 5 ac. WTF? It doesn't work.
Replies: 82
Views: 31322

Re: SXTsq 5 ac. WTF? It doesn't work.

So it's official that
SXT SQ AC cannot function properly under NV2 protocol?
Could You paste what support replyed to You?
IM using them with nv2 and they work fine.
by ivicask
Fri Dec 29, 2017 11:31 am
Forum: Wireless Networking
Topic: SXTsq 5 ac. WTF? It doesn't work.
Replies: 82
Views: 31322

Re: SXTsq 5 ac. WTF? It doesn't work.

Maybe he created loop on network, happend to me once while doing initial configuration of new APs, i connected 2 of APs on same switch and after connecting them together via their wireless which is bridged to lan ports your basically creating loop on switch same as you connected LAN cable bewtween p...
by ivicask
Fri Dec 29, 2017 10:38 am
Forum: Wireless Networking
Topic: SXTsq 5 ac. WTF? It doesn't work.
Replies: 82
Views: 31322

Re: SXTsq 5 ac. WTF? It doesn't work.

-28dB signal is much too much. Get it down to -55 or something. -28dB signal is much too much. Get it down to -55 or something. I've given an example of test in office. Problem doesn't depend of signal strength. Iv read your entire posts and i cant even understand whats your problem. I have just fr...
by ivicask
Mon Oct 23, 2017 5:26 pm
Forum: Wireless Networking
Topic: wAP LTE Kit EU - Slow LTE speed
Replies: 68
Views: 31998

Re: wAP LTE Kit EU - Slow LTE speed

Can you do one test for me?Meassure the speed as normal, than try disabling onboard WIFI and repeat the test again over lan. Do you see any noticeable difference? Dont have unit anymore to test for my self Yes, i would do. But it needs to connect again. Sadly if i do changes on LTE interface (like ...
by ivicask
Mon Oct 23, 2017 3:37 pm
Forum: Wireless Networking
Topic: wAP LTE Kit EU - Slow LTE speed
Replies: 68
Views: 31998

Re: wAP LTE Kit EU - Slow LTE speed

I've compared SXT-LTE and wAP LTE, and seems to me, the SXT-LTE is much faster (if supported band is available). At home, SXT-LTE could do ~80/35mbps almost any time, but wAP LTE only the half (~35/18mbps) on band3, 20MHz. Also, it would be really helpful, if scan would display not only one provide...
by ivicask
Mon Oct 23, 2017 1:43 pm
Forum: Wireless Networking
Topic: wAP LTE Kit EU - Slow LTE speed
Replies: 68
Views: 31998

Re: wAP LTE Kit EU - Slow LTE speed

In future we plan to introduce CAT6 or faster LTE category products but I can't provide any ETA on such products.
Hope it will be soon because i prefer to use Mikrotik always :)

Thanks.
by ivicask
Mon Oct 23, 2017 1:34 pm
Forum: Wireless Networking
Topic: wAP LTE Kit EU - Slow LTE speed
Replies: 68
Views: 31998

Re: wAP LTE Kit EU - Slow LTE speed

what speed you are getting from the wap lte and from the usb modem? What LTE category your USB modem supports? Try to compare which band each unit uses as maybe the wap lte connected to different bands or cell tower. Got similar question here, with ZTE MF286 modem that provider gives on same spot i...
by ivicask
Mon Oct 23, 2017 12:18 pm
Forum: Wireless Networking
Topic: wAP LTE Kit EU - Slow LTE speed
Replies: 68
Views: 31998

Re: wAP LTE Kit EU - Slow LTE speed

what speed you are getting from the wap lte and from the usb modem? What LTE category your USB modem supports? Try to compare which band each unit uses as maybe the wap lte connected to different bands or cell tower. Got similar question here, with ZTE MF286 modem that provider gives on same spot i...
by ivicask
Mon Oct 09, 2017 10:18 am
Forum: Announcements
Topic: v6.41rc [release candidate] is released! New bridge implementation!
Replies: 561
Views: 209272

Re: v6.41rc [release candidate] is released! New bridge implementation!

Hello, after upgrading RBwAPR-2nD & R11e-LTE to version 6.41rc38 , I received a critical error after which the router has been permanently rebooting . if you want a relative version older than that, you need to log in with a static IP address, quickly roll over the main package, and quickly dow...
by ivicask
Fri Oct 06, 2017 10:41 pm
Forum: General
Topic: WAP LTE Sim not working
Replies: 1
Views: 1884

WAP LTE Sim not working

New AP, fresh setup no other settings(Tried factory reset).I cant get SIM to work, i input proper APN and pin but nothing is working, if i press scan under LTE interface i get Modem not configured, what possible im doing wrong?The sim it self its form TELE 2 provider in Croatia and works in another ...
by ivicask
Mon Sep 25, 2017 2:56 pm
Forum: Wireless Networking
Topic: Caps selecting same channel
Replies: 32
Views: 16961

Re: Caps selecting same channel

Now I've replicated this issue at home. Took a brand new hAPac and a new wAPac, ros 6.40.3, copied system identity, capsman, caps, bridge, vlan, switch and IP settings from the customer. They are connected to each other with a 30cm cable, and they select same channel for both radios. I live at at p...
by ivicask
Mon Sep 25, 2017 9:24 am
Forum: General
Topic: Avg rate exceeds Max Limit
Replies: 0
Views: 761

Avg rate exceeds Max Limit

I noticed often internet starts lag badly, even netwatch script i made to ping google servers and play a tone on net down activates as net was down just because of this. Upload is getting choked on DSL modem but i set rate below our maximum DSL upload speed (around 10% less) But see screenshot/s, up...
by ivicask
Fri Sep 22, 2017 9:20 am
Forum: Announcements
Topic: Newsletter 78 with 1GBPS WIRELESS PRODUCT ANNOUNCEMENT!
Replies: 109
Views: 49914

Re: Newsletter 78 with 1GBPS WIRELESS PRODUCT ANNOUNCEMENT!

@normis can RBwAPG-60ad be used in multipoint connections?Or its limited to single AP?
by ivicask
Tue Aug 29, 2017 1:28 pm
Forum: Announcements
Topic: v6.41rc [release candidate] is released! New bridge implementation!
Replies: 561
Views: 209272

Re: v6.41rc [release candidate] is released! New bridge implementation!

So how is this new bridge HW offload supposed to work?I upgraded my WAP AC and than I printed my bridges after upgrade and they all say hw=no, tried creating new bridge, still says no. Also I see there is new option Bridge Fast forward, what does it do?I tried ticking it again i see no differences a...
by ivicask
Sun Aug 13, 2017 12:25 pm
Forum: General
Topic: Cant get 3389 port forward only on single PC
Replies: 13
Views: 5053

Re: Cant get 3389 port forward only on single PC

@k6ccc just to report back, all working fine now, it was never problem in Mikrotik, that user had some 3d party terminal server on Windows 7, and that software was in some weird state and only connections from local lan worked.They reinstalled that software and now all works fine. Thanks for help ag...
by ivicask
Mon Aug 07, 2017 1:26 pm
Forum: General
Topic: Cant get 3389 port forward only on single PC
Replies: 13
Views: 5053

Re: Cant get 3389 port forward only on single PC

if 2 pc works but only one is not with same settings... 1. anycase try to make src-nat add action=dst-nat chain=dstnat dst-port=4001 in-interface=WAN protocol=tcp to-addresses=192.168.2.205 to-ports=3389 add action=src-nat chain=srcnat dst-address=192.168.2.205 dst-port=3389 protocol=tcp to-address...
by ivicask
Fri Aug 04, 2017 7:12 pm
Forum: General
Topic: Cant get 3389 port forward only on single PC
Replies: 13
Views: 5053

Re: Cant get 3389 port forward only on single PC

It goes establishing connection for 1-2 sec, than it pops "internal error" That does not sound like a firewall error to me. A firewall issue would just fail to connect. Stupid question. You are trying to connect to your external address and port 4001 (since that's the port you are forward...
by ivicask
Fri Aug 04, 2017 5:36 pm
Forum: General
Topic: Cant get 3389 port forward only on single PC
Replies: 13
Views: 5053

Re: Cant get 3389 port forward only on single PC

To make things wierder, I forgot to mention, it worked first day I set it at customer than it stoped working next day , mikrotik or isp router wasn't touched.

I will try your suggestions tomorow, thanks for now.
by ivicask
Fri Aug 04, 2017 5:01 pm
Forum: General
Topic: Cant get 3389 port forward only on single PC
Replies: 13
Views: 5053

Re: Cant get 3389 port forward only on single PC

1. windows firewall can restrict to access while you are from different net https://technet.microsoft.com/en-us/library/dd421713(v=ws.10).aspx Block edge traversal (default) Prevent applications from receiving unsolicited traffic from the Internet through a NAT edge device. 1b don't shutdown firewa...
by ivicask
Fri Aug 04, 2017 2:36 pm
Forum: General
Topic: Cant get 3389 port forward only on single PC
Replies: 13
Views: 5053

Re: Cant get 3389 port forward only on single PC

1. check your pc's firewall again, check gateway on pc 2. make src-nat add action=src-nat chain=srcnat dst-address=192.168.2.205 dst-port=3389 protocol=tcp to-addresses=192.168.2.X Remote works from local network, so its no firewall (and firewall is currently full off) And that 2, makes no sense to...
by ivicask
Fri Aug 04, 2017 9:23 am
Forum: General
Topic: Cant get 3389 port forward only on single PC
Replies: 13
Views: 5053

Cant get 3389 port forward only on single PC

I have weird issue at one customer, and im out if ideas how else to debug it. They have LTE router from their ISP and i put DMZ zone on Mikrotik behind it(HAP AC.I did several port forwards, few servers, video server etc and they all work just fine. But there is this single PC i cant RDC from outsid...
by ivicask
Wed Jun 21, 2017 9:45 am
Forum: General
Topic: Skype blocked after firmware update
Replies: 9
Views: 2927

Re: Skype blocked after firmware update

Its not mikrotik problem, they have huge outage and services go randomly up/down
by ivicask
Sun Jun 11, 2017 3:00 pm
Forum: Beginner Basics
Topic: Upload problem Queue Tree+PCQ
Replies: 18
Views: 6984

Re: Upload problem Queue Tree+PCQ

Hi!, Yes, I noticed that and changed. Is better now (last post). Regards QoS will not work with two different queue structures set to the same parent interface - instead of one on bridge and one on ether1 you now have two on the bridge and two on ether1, this won't work. ivicask's solution uses the...
by ivicask
Thu Jun 08, 2017 9:41 am
Forum: Beginner Basics
Topic: Upload problem Queue Tree+PCQ
Replies: 18
Views: 6984

Re: Upload problem Queue Tree+PCQ

I had same problems as you, only way to properly fix it, is to leave some reservation for your on-line games and make more parent queues to put in control unwanted traffic that slows the important one As you can see in this example i made for you. 1.PNG You can also make more parent queues like this...
by ivicask
Fri May 26, 2017 9:09 pm
Forum: Announcements
Topic: v6.40rc [release candidate] is released!
Replies: 231
Views: 78098

Re: v6.40rc [release candidate] is released!

Hm, i upgraded my WAP AC to RC 13 and i cant connect to router anymore via HTTP or WINBOX via IP, i can only connect via WINBOX via MAC address.Also router it self doesn't have access to internet anymore(cant check for new version, connection timed out)Other than that everything else works, internet...
by ivicask
Mon May 15, 2017 9:59 am
Forum: General
Topic: Feature request: CAPsManager - roaming
Replies: 80
Views: 39507

Re: Feature request: CAPsManager - roaming

Just wanted to say for everyone asking for roaming implementation like Ubiquiti has, did anyone actually tried it so far? I have several of this UniFI APs at one customer, and i tried zero hand off feature and made everything so much worse and unstable that i had to turn it off, it simple doesn't w...
by ivicask
Sun May 14, 2017 9:21 pm
Forum: General
Topic: Feature request: CAPsManager - roaming
Replies: 80
Views: 39507

Re: Feature request: CAPsManager - roaming

Just wanted to say for everyone asking for roaming implementation like Ubiquiti has, did anyone actually tried it so far? I have several of this UniFI APs at one customer, and i tried zero hand off feature and made everything so much worse and unstable that i had to turn it off, it simple doesn't wo...
by ivicask
Thu May 11, 2017 3:16 pm
Forum: General
Topic: Firewall rules only using one CPU
Replies: 8
Views: 2747

Re: Firewall rules only using one CPU

Good day, Recently our upstream provider has been threatening to terminate our service because they have started to receive a metric Sh!t ton of abuse mails from because internet users on the network is downloading illegal torrents, with 5000 customers that's no surprise. So i started to setup a me...
by ivicask
Mon May 08, 2017 2:01 pm
Forum: Wireless Networking
Topic: SXT 5 AC bandwith problem
Replies: 28
Views: 4825

Re: SXT 5 AC bandwith problem

Internal test and real test tell same. I tried copy data over link and speed is 400 and 300mbps. Depend on way.
Maybe you have some network in close proximity to that other side on same/near frequencies?
Try running frequencies usage scan on both sides and set it to lowest used channel.
by ivicask
Mon May 08, 2017 10:42 am
Forum: Wireless Networking
Topic: SXT 5 AC bandwith problem
Replies: 28
Views: 4825

Re: SXT 5 AC bandwith problem

Yes I try changeing wireless protocol, but best performance I have on 802.11.
400mbps one way, 300mbps opposite way.
If you get 400mbps real throughput than where is the problem?Dont expect to get 600+, thats just link speeds you will never reach that.
by ivicask
Mon May 08, 2017 10:12 am
Forum: Wireless Networking
Topic: SXT 5 AC bandwith problem
Replies: 28
Views: 4825

Re: SXT 5 AC bandwith problem

CCQ is around 80-95%.
Did you try changing wireless protocol?For me nv2 nstreme works the best, i have older SXT 5gz and im getting 130mbit speeds over 1KM link.
by ivicask
Mon May 08, 2017 10:05 am
Forum: Wireless Networking
Topic: Lock client to specific CAPsMAN interface?
Replies: 5
Views: 3502

Re: Lock client to specific CAPsMAN interface?

Im running a CAPsMAN server on an RB962. The wifi on the device is controlled by CAPsMAN with an additional waP AC. This makes me get 4 interface total 2 x 2.4 and 2 x 5GHz. I want to lock some clients to one of this 4 interfaces because of the range to get the best possible signal. Tried many diff...
by ivicask
Sat May 06, 2017 5:12 pm
Forum: General
Topic: Huge performance drop with mangle + queue tree rules, CPU 50% max
Replies: 22
Views: 10240

Re: Huge performance drop with mangle + queue tree rules, CPU 50% max

what is the port 1723 dstnat rule for. Surely you dont need to dstnat to your router. I have much more in my firewall and nat than you have on a HAP lite never see CPU going above 10% total with simple queues. never see any issues. I would look out for an error here or a loop or some sort of attack...
by ivicask
Sat May 06, 2017 12:48 am
Forum: Wireless Networking
Topic: RouterBoard hAP AC Slow wireless performance.
Replies: 35
Views: 17058

Re: RouterBoard hAP AC Slow wireless performance.

Apple tech spec for all 2015 Macbook Air shows https://www.apple.com/macbook-air/features/ 1300 Mbps ! Chipset : Broadcom BCM43xx Well it's strange, because mine air book clearely showed dual band ac under device manager sorry dont have it anymore around to check anything or tell you anything more ...
by ivicask
Sat May 06, 2017 12:33 am
Forum: Wireless Networking
Topic: RouterBoard hAP AC Slow wireless performance.
Replies: 35
Views: 17058

Re: RouterBoard hAP AC Slow wireless performance.

I know where to check my MacOS device wifi spec, but I don't see over there this dual or triple wording.
Well tell me what wifi chip model it has, simple Google will reveal its specs..
by ivicask
Sat May 06, 2017 12:28 am
Forum: Wireless Networking
Topic: RouterBoard hAP AC Slow wireless performance.
Replies: 35
Views: 17058

Re: RouterBoard hAP AC Slow wireless performance.

That is interesting. Friend of mine has same model same time and got 1200-1300 connection from Netgear 5G Router. I just wondering where can I find this information in mac about WiFi card dual/triple ? Check model specifications for wifi, not sure how to check under OSX, I installed windows as cust...
by ivicask
Fri May 05, 2017 11:27 pm
Forum: Wireless Networking
Topic: RouterBoard hAP AC Slow wireless performance.
Replies: 35
Views: 17058

Re: RouterBoard hAP AC Slow wireless performance.

Still only 867 Mb. How to fix setup up to 1200-1300Mb ? @IntrusDave how to get Channel 100 on Mikrotik wAP ac ? I'm not too much into mac but as far I know Mac Air doesn't have triple chain wifi, I had new Mac Air yesterday at work and it showed as dual chain in device manager, also connected 867mbit
by ivicask
Fri May 05, 2017 2:22 pm
Forum: Wireless Networking
Topic: CAPsMAN not working on 2.4GHz, 5GHz OK
Replies: 13
Views: 5625

Re: CAPsMAN not working on 2.4GHz, 5GHz OK

Thanks for your reply. Below are my configurations. I noticed, that the CAPsMAN forwarding channel shuts down if I connect to the 2.4GHz network. When I connect to 5GHz, the channel works and the display "channel: 2412/20-Ce/gn(20dBm), SSID: MTIK-24, CAPsMAN forwarding" and "channel:...
by ivicask
Fri May 05, 2017 2:07 pm
Forum: General
Topic: Expert needed for remote paid support
Replies: 3
Views: 1141

Re: Expert needed for remote paid support

Hi R1CH, and thank you for your prompt response. I will try this solution since I am thinking that many of the clients will connect to 5Ghz, because many devices have support for 5Ghz nowadays. But I am still having some things that are not so clear. Indeed, the 2.4Ghz band is very crowded, but why...
by ivicask
Fri May 05, 2017 1:59 pm
Forum: Announcements
Topic: v6.40rc [release candidate] is released!
Replies: 231
Views: 78098

Re: v6.40rc [release candidate] is released!

*) dns - made loading thousands of static entries faster;

Thank you MIkrotik for this, my routers starts/restart so much faster now (around 10k DNS entries)
by ivicask
Fri May 05, 2017 1:57 pm
Forum: Wireless Networking
Topic: RouterBoard hAP AC Slow wireless performance.
Replies: 35
Views: 17058

Re: RouterBoard hAP AC Slow wireless performance.

Please help me how to configure my wAP ac (RBwAPG-5HacT2HnD-BE) to run this same 1300 Mb (MAcBook) speed like in mentoned by IntrusDave? Is this country Switzerland. 5240/20-eeeC/ac/P(20dBm)??? The default config for the wireless should be pretty good. The only thing I changed on my hAP AC is locki...
by ivicask
Fri May 05, 2017 1:44 pm
Forum: General
Topic: Huge performance drop with mangle + queue tree rules, CPU 50% max
Replies: 22
Views: 10240

Re: Huge performance drop with mangle + queue tree rules, CPU 50% max

Can you post your nat and mangle rules. /ip firewall nat add action=masquerade chain=srcnat comment="defconf: masquerade" out-interface=pppoe-out1 add action=masquerade chain=srcnat out-interface=WAN_IZLAZ add action=masquerade chain=srcnat out-interface=DISZG_GOST_BRIDGE add action=dst-n...
by ivicask
Thu May 04, 2017 11:04 pm
Forum: General
Topic: Huge performance drop with mangle + queue tree rules, CPU 50% max
Replies: 22
Views: 10240

Re: Huge performance drop with mangle + queue tree rules, CPU 50% max

are you not under some sort of attack. I find it weird your router is hitting 28% on firewall as well as queues. confirm how many clients you have running off this. can you do export on your firewall. During tests there was like 3 clients.Nobody was active, because i would see traffic on pppoe conn...
by ivicask
Thu May 04, 2017 1:22 pm
Forum: General
Topic: Huge performance drop with mangle + queue tree rules, CPU 50% max
Replies: 22
Views: 10240

Re: Huge performance drop with mangle + queue tree rules, CPU 50% max

This may sound silly, but do you really need the Simple queues? I'm using Queue tree, this is just example so someone doesn't tell me how mangle or Queue tree rules are bad ,or how i should change that or that, thats why i disabled all rules for test. Performance issue happens with both Queue tree ...
by ivicask
Thu May 04, 2017 12:35 pm
Forum: General
Topic: Huge performance drop with mangle + queue tree rules, CPU 50% max
Replies: 22
Views: 10240

Re: Huge performance drop with mangle + queue tree rules, CPU 50% max

Here we go again, problem is back, nothing was touched in configuration, i tried again disabling all firewall, mangle, Queue tree rules. I set single simple queue rule, limit it to 500/500mbit, i get top 170mbit on speedest I disable simple rule i get 250mbit again. Comparing to my previos screensho...
by ivicask
Tue May 02, 2017 7:46 pm
Forum: General
Topic: Huge performance drop with mangle + queue tree rules, CPU 50% max
Replies: 22
Views: 10240

Re: Huge performance drop with mangle + queue tree rules, CPU 50% max

Do test: in this simple queue, try to use queue type = sfq. (create new one or simply use wireless-default) and check again.
I did try that! Now its pointless as i dont have problem!
by ivicask
Tue May 02, 2017 6:35 pm
Forum: General
Topic: Huge performance drop with mangle + queue tree rules, CPU 50% max
Replies: 22
Views: 10240

Re: Huge performance drop with mangle + queue tree rules, CPU 50% max

i see firewall use about twice resources than qos. So, probably you can try to optimize your firewall rules (mangle) Well i have simple mangle rules, and as long everything works and CPU isnt crossing even 50% total i dont want to touch anything.. But as i said original problem was with ALL firewal...
by ivicask
Tue May 02, 2017 4:20 pm
Forum: General
Topic: Huge performance drop with mangle + queue tree rules, CPU 50% max
Replies: 22
Views: 10240

Re: Huge performance drop with mangle + queue tree rules, CPU 50% max

@ivicask: what others are saying is that in multi-cpu boards (like your hEX or my CCR) some processes that don't use multi-threading can consume a single core to 100% but what you see in total (that one you see in winbox) is a fraction of percent. Given that you have a dual-cpu system, if one goes ...
by ivicask
Tue May 02, 2017 3:49 pm
Forum: General
Topic: Huge performance drop with mangle + queue tree rules, CPU 50% max
Replies: 22
Views: 10240

Re: Huge performance drop with mangle + queue tree rules, CPU 50% max

Can you click on system -- >settings ---> resources Then click on CPU and run your test again. You will see this will show each of the CPU cores and you can see if one is maxing out. You can then click Tools Profile to see the name of the process that is using all your resources. I believe that onl...
by ivicask
Tue May 02, 2017 3:13 pm
Forum: General
Topic: Huge performance drop with mangle + queue tree rules, CPU 50% max
Replies: 22
Views: 10240

Re: Huge performance drop with mangle + queue tree rules, CPU 50% max

On a different scenario but I have the same problem. Many simple queues on a CCR1009, CPU is fine (<50%) but throughput is really limited. Disabling queues makes it flow without issues. I don't know what to do. Yep seams same issue as me, and i just got replay from MT, here is what they replied: &q...
  • 1
  • 2