Community discussions

MikroTik App

Search found 1120 matches

by Steveocee
Thu Nov 22, 2018 10:32 am
Forum: Beginner Basics
Topic: Fast failover
Replies: 4
Views: 2284

Re: Fast failover

This is the basic setup I use for both my main internet connections as well as my VPN setups, it's fast (very) and requires no additional scripting or netwatch usage. Just ensure your pppoe client does not create it's own default route. /ip route add check-gateway=ping comment=Internet distance=1 ga...
by Steveocee
Wed Nov 21, 2018 5:46 pm
Forum: General
Topic: Why blacklist burteforcers VS just dropping the ports/service?
Replies: 7
Views: 2078

Re: Why blacklist burteforcers VS just dropping the ports/service?

Pre-empting the worst is probably the best summary.
If they're poking at certain ports when they shouldn't then you probably don't want them poking at anything.
by Steveocee
Wed Nov 21, 2018 4:54 pm
Forum: Beginner Basics
Topic: client connect to wifi in other room - why [SOLVED]
Replies: 9
Views: 3213

Re: client connect to wifi in other room - why [SOLVED]

Roaming in this way is driven by the client device, you can have the best setup in the world but a sticky client won't move. You can try to encourage this movement by ensuring you are using non overlapping channels and employing a minimum RSSI on the AP's.
by Steveocee
Wed Nov 21, 2018 4:20 pm
Forum: Scripting
Topic: Need to hire script consultant
Replies: 6
Views: 2030

Re: Need to hire script consultant

I've dropped you an email. My extract has probably 95% of what you need, just need to change the line that grabs the MAC address to grab the SN and you should be good to go.
by Steveocee
Tue Nov 20, 2018 9:29 am
Forum: Forwarding Protocols
Topic: Redirect DNS to Local Server
Replies: 12
Views: 35965

Re: Redirect DNS to Local Server

A dst-nat rule should do this week enough. If you match against anything destined TCP/UDP 53 and just dst-nat it to your server you can rule all dns through it.

Have you specified it on the DHCP server as well or is the MT not doing that?
by Steveocee
Mon Nov 19, 2018 6:48 pm
Forum: General
Topic: Management high CPU on lots of Mikrotiks today - DDoS??
Replies: 15
Views: 2951

Re: Management high CPU on lots of Mikrotiks today - DDoS??

Glad you got it sorted.
Maybe just shuffle the "accept dst-nat" rule to number 3? You really want the rules with the most traffic towards the top so the packets are not delayed in being handled and est&rel will be the highest ones (in most applications).
by Steveocee
Mon Nov 19, 2018 5:24 pm
Forum: General
Topic: Management high CPU on lots of Mikrotiks today - DDoS??
Replies: 15
Views: 2951

Re: Management high CPU on lots of Mikrotiks today - DDoS??

Thanks for some feedback - i will look at making a few amendments to my base config generator to include some enhancements to the firewall. I have remove the IPs / screenshots from the post above Just removed my home routers firewall config with this to see how it works .. we specialise in VoIP so ...
by Steveocee
Mon Nov 19, 2018 5:15 pm
Forum: Beginner Basics
Topic: Kid Control
Replies: 6
Views: 1095

Re: Kid Control

I agree but just strange it allows it on Sat...
Because.......





MikroTik
by Steveocee
Mon Nov 19, 2018 5:06 pm
Forum: General
Topic: Management high CPU on lots of Mikrotiks today - DDoS??
Replies: 15
Views: 2951

Re: Management high CPU on lots of Mikrotiks today - DDoS??

You probably wouldn't with that implementation. You are only FT'ing the "input" traffic and not the "forward" with that rule. Once you apply it to the forward chain then things start to get a lot more interesting but it begs the question if you really "need" to? Trying ...
by Steveocee
Mon Nov 19, 2018 4:52 pm
Forum: Beginner Basics
Topic: Kid Control
Replies: 6
Views: 1095

Re: Kid Control

00:00:00-23:59:59
I doubt that second will go astray.
by Steveocee
Mon Nov 19, 2018 4:17 pm
Forum: General
Topic: Management high CPU on lots of Mikrotiks today - DDoS??
Replies: 15
Views: 2951

Re: Management high CPU on lots of Mikrotiks today - DDoS??

DNS is also open to the world!! Your firewall rules fast track anything going input then you have drop rules after this which will never work as you have already fast tracked the traffic. steve@general:~$ dig forum.mikrotik.com @X.X.X.X ; <<>> DiG 9.10.3-P4-Ubuntu <<>> forum.mikrotik.com @X.X.X.X ;;...
by Steveocee
Mon Nov 19, 2018 4:02 pm
Forum: Beginner Basics
Topic: Kid Control
Replies: 6
Views: 1095

Re: Kid Control

"00:00:00-00:00:00"

I think is what you want.
by Steveocee
Fri Nov 16, 2018 5:09 pm
Forum: Virtualization
Topic: CHR neighbour discovery problem
Replies: 13
Views: 12798

Re: CHR neighbour discovery problem

So quick follow up. MikroTik support have so far been very responsive however the implication is currently that the issue is with my computers L2 connectivity. My desktop and 2 laptops can't discover it (cabled and 2 wireless) however the 'Tik App on my phone on the same wireless AP as the laptops C...
by Steveocee
Fri Nov 16, 2018 3:58 pm
Forum: Forwarding Protocols
Topic: Interconnect two different network
Replies: 3
Views: 4937

Re: Interconnect two different network

If both networks are running from the one single RB2011 in the middle then you do not need to do anything to get them talking. Both networks are connected to a "router" so it will naturally route between them.
by Steveocee
Fri Nov 16, 2018 2:19 pm
Forum: Beginner Basics
Topic: rookie Port Forward for PS4 [SOLVED]
Replies: 15
Views: 9126

Re: rookie Port Forward for PS4 [SOLVED]

Right, the picture helps. >You need ALL the numbers you have mentioned >You need to change the in-interface to pppoe-out1 >You need another rule for the UDP traffic, to do this, open up your current one and choose "copy" which will open up another window copied from the first, go to genera...
by Steveocee
Fri Nov 16, 2018 11:04 am
Forum: Beginner Basics
Topic: Double port forwarding [SOLVED]
Replies: 5
Views: 2426

Re: Double port forwarding [SOLVED]

I think you want something like this, you won't be able to copy/paste it as my in-interface name is probably different to yours, change this for your WAN interface name and it should work.; /ip firewall nat add action=dst-nat chain=dstnat comment=example-rule dst-port=3189 in-interface=ether1_WAN pr...
by Steveocee
Fri Nov 16, 2018 10:56 am
Forum: Beginner Basics
Topic: rookie Port Forward for PS4 [SOLVED]
Replies: 15
Views: 9126

Re: rookie Port Forward for PS4 [SOLVED]

This will guide you through; https://www.youtube.com/watch?v=3ni_R03OOrg thanks but i know those things, i just don't know which one of these numbers is the port ! TCP: 1935,3478-3480 UDP: 3074,3478-3479 right now i put this (3478-3480) for both ports and chose Wlan1 for "In Interface" an...
by Steveocee
Thu Nov 15, 2018 5:52 pm
Forum: Beginner Basics
Topic: rookie Port Forward for PS4 [SOLVED]
Replies: 15
Views: 9126

Re: rookie Port Forward for PS4 [SOLVED]

This will guide you through;
https://www.youtube.com/watch?v=3ni_R03OOrg
by Steveocee
Wed Nov 14, 2018 1:31 pm
Forum: General
Topic: Shapeing 10G of traffic
Replies: 15
Views: 3900

Re: Shapeing 10G of traffic

How are you planning on shaping the traffic? (Out of interest).
I would recommend CHR as it is a "current" product where X86 has been left behind a bit in terms of hardware support.
by Steveocee
Wed Nov 14, 2018 12:57 pm
Forum: Beginner Basics
Topic: Down ports
Replies: 1
Views: 592

Re: Down ports

Your problem looks to be the same as others have found a common issue here;
viewtopic.php?f=3&t=128762&p=693740&hil ... ng#p693740
by Steveocee
Wed Nov 14, 2018 12:52 pm
Forum: Beginner Basics
Topic: wAP ac upgrade and wireless problems
Replies: 5
Views: 1414

Re: wAP ac upgrade and wireless problems

I think you are confusing routeros version a bit with your routerboard FW. If you are uploading the file to the wAP, do a system > reboot. That will initiate an update of routerOS. Once routerOS is updated go to system > routerboard and you will see that the 6.43.4 FW is available for the board. Hit...
by Steveocee
Tue Nov 13, 2018 4:50 pm
Forum: Beginner Basics
Topic: 3011 update
Replies: 10
Views: 2290

Re: 3011 update

I see so I have been using the wrong file for uprade ehhhhhhhh ok I will check the architecture and let you know
It's ARM like the poster above has said.
by Steveocee
Tue Nov 13, 2018 1:56 pm
Forum: General
Topic: l2tp with ipsec clients behind NAT no work
Replies: 3
Views: 3155

Re: l2tp with ipsec clients behind NAT no work

I too get this however it is not so much a problem as expected behaviour. You can use split VPN types as you have found or you could set up a VPN from the router and some sort of policy based routing to get around this.
by Steveocee
Tue Nov 13, 2018 9:24 am
Forum: Beginner Basics
Topic: DHCP issue [SOLVED]
Replies: 9
Views: 3162

Re: DHCP issue [SOLVED]

It sounds like there is a second DHCP server on your network. Maybe you have bridged the WAN interface? Could be a possibility. Try turning off your dhcp server and then connect to your network as dhcp client to check. Also posting config is needed with most problems, 95% of it will not be unique to...
by Steveocee
Mon Nov 12, 2018 4:16 pm
Forum: General
Topic: Migrating CRS125-24G-1S-RM from master-port to bridge
Replies: 3
Views: 893

Re: Migrating CRS125-24G-1S-RM from master-port to bridge

Thank you for your reply. But it's vary sad...
It's a change to how you need to operate. Sad in the short term I agree but once you adjust your working methods. It will become second nature as it currently is.
by Steveocee
Mon Nov 12, 2018 3:41 pm
Forum: RouterBOARD hardware
Topic: hAP AC2 availability
Replies: 26
Views: 8625

Re: hAP AC2 availability

We are the biggest UK distributor for MikroTik and we have stock: https://linitx.com/product/mikrotik-routerboard-hap-ac2-with-uk-psu-tower-shape/15370 Hope that helps Nick I live in EU, not in UK. Issue is for EU not UK. :) Good job they ship to the EU then!!! https://linitx.com/info/shippingreturns
by Steveocee
Sat Nov 10, 2018 7:22 pm
Forum: RouterBOARD hardware
Topic: RB1100AHx4 drops packets when CPU spikes to 20% and above
Replies: 1
Views: 1554

Re: RB1100AHx4 drops packets when CPU spikes to 20% and above

35% of a quad core is 100% load of a core in single core application. Total utilisation doesn't tell you this, if you check profile when CPU is that high I reckon you have a maxed out core hence the packet drops.
by Steveocee
Sat Nov 10, 2018 7:18 pm
Forum: General
Topic: Webfig remote access from WAN
Replies: 18
Views: 27444

Re: Webfig remote access from WAN

You will need to post your config to let everyone see and help.
by Steveocee
Fri Nov 09, 2018 6:11 pm
Forum: Wireless Networking
Topic: LHG 60G experience
Replies: 608
Views: 193919

Re: LHG 60G experience

Hi Steve, Just send me the airline tickets and I will be glad to stand at one end of the connection to move things around. I am really lucky ;-) On the other hand the fetid vapours of intoxicated Brits (on warm beer) may be a cloud to dense for your traffic ;-PP That's it. Must be the toxicity of t...
by Steveocee
Fri Nov 09, 2018 3:49 pm
Forum: Wireless Networking
Topic: LHG 60G experience
Replies: 608
Views: 193919

Re: LHG 60G experience

My 2.6Km link does not want to link up. I'm using 64800 as not totally sure about legalities of 66Ghz in the UK yet. Little bit gutted as I expected at least something. Apparently you do not direct the antenna. We previously worked with SIKLU so there is experience. The main thing that would be dir...
by Steveocee
Fri Nov 09, 2018 2:27 pm
Forum: Wireless Networking
Topic: LHG 60G experience
Replies: 608
Views: 193919

Re: LHG 60G experience

My 2.6Km link does not want to link up. I'm using 64800 as not totally sure about legalities of 66Ghz in the UK yet. Little bit gutted as I expected at least something.
by Steveocee
Fri Nov 09, 2018 11:01 am
Forum: General
Topic: Management Network for router access?
Replies: 10
Views: 3215

Re: Management Network for router access?

It's a great idea to have a management network if your end devices can be separated like that. Once you are in a SOHO/SMB environment then this becomes almost standard to have multiple LANs (/vlans). The trick is ensuring nobody simply plugs in to your MGMT network to access the devices. Ensuring yo...
by Steveocee
Wed Nov 07, 2018 10:55 am
Forum: Beginner Basics
Topic: How can I config. so that LAN 1 goes to WAN 1, and LAN 2 goes to WAN 2 with "failover"?
Replies: 3
Views: 823

Re: How can I config. so that LAN 1 goes to WAN 1, and LAN 2 goes to WAN 2 with "failover"?

Pardon me for asking but is there a specific "need" to have the traffics behave in this way?
You could simplify your life massively by using a PCQ load balanced queue and balancing over the 2 connections which would introduce failover as well.
by Steveocee
Wed Nov 07, 2018 10:53 am
Forum: Scripting
Topic: Put Latency on Graph
Replies: 1
Views: 1039

Re: Put Latency on Graph

Smokeping.
by Steveocee
Wed Nov 07, 2018 10:51 am
Forum: Forwarding Protocols
Topic: Firewall filter rules ordering
Replies: 7
Views: 23260

Re: Firewall filter rules ordering

Setting up a NAT rule is not enough. If your firewall is blocking the connection then the NAT rule will not work. You'd be better doing an export of both your firewall filters and NAT table for everyone to see and advise on. The default config has a rule to drop anything non-dst NAT'd which is very ...
by Steveocee
Tue Nov 06, 2018 5:31 pm
Forum: Announcements
Topic: Newsletter 85
Replies: 30
Views: 24192

Re: Newsletter 85

CRS305-1G-4S+IN Maybe a stupid question but could one use the above device as an ethernet translation/adapter device (ethernet in from the LAN, fibre out to specific locations or devices)? The info says the ethernet is strictly for management so me thinks not. You could use an SFP+ to ether net ada...
by Steveocee
Tue Nov 06, 2018 3:39 pm
Forum: General
Topic: CRS125 poor throughput & low cpu load [SOLVED]
Replies: 41
Views: 8621

Re: CRS125 poor throughput & low cpu load [SOLVED]

Which one would be recommended? Small physical size would be good for me...
Where is your budget at? A hAP AC2 could do what you want but so could a CCR1009. Budget plays a part.
I take it the CRS125 can be reused as a switch if you need that many ethernet ports?
by Steveocee
Tue Nov 06, 2018 3:04 pm
Forum: General
Topic: CRS125 poor throughput & low cpu load [SOLVED]
Replies: 41
Views: 8621

Re: CRS125 poor throughput & low cpu load [SOLVED]

So, I have too much firewall rules and/or too much VLAN routing?
Yes.
by Steveocee
Tue Nov 06, 2018 10:49 am
Forum: General
Topic: CRS125 poor throughput & low cpu load [SOLVED]
Replies: 41
Views: 8621

Re: CRS125 poor throughput & low cpu load [SOLVED]

You need a ROUTER not a SWITCH WITH L3 CAPABILITY.
Your config is far beyond what I would ever want to deploy onto a CRS125, you are asking too much of it.
by Steveocee
Tue Nov 06, 2018 10:45 am
Forum: Virtualization
Topic: CHR neighbour discovery problem
Replies: 13
Views: 12798

Re: CHR neighbour discovery problem

I suggest you all write to Mikrotik support, seeing as they clearly don't believe me - based on the fact that they have done NOTHING about this bug in the last 9 months.
Posting here is essentially pointless.
Done.
by Steveocee
Mon Nov 05, 2018 10:26 pm
Forum: RouterBOARD hardware
Topic: Desired switch
Replies: 7
Views: 2212

Re: Desired switch

Would be nice if CRS112 was half rack width with option to join 2 together to make 16 port full width.
by Steveocee
Mon Nov 05, 2018 6:16 pm
Forum: Beginner Basics
Topic: how to Config Mikrotik with 1:1 bandwitdh ratio
Replies: 5
Views: 1203

Re: how to Config Mikrotik with 1:1 bandwitdh ratio

How are you auth'ing these users?

You can build contention groups within simple queues without too much problems. Just need a way of identifying who is in which pipe;
https://wiki.mikrotik.com/wiki/Manual:HTB
by Steveocee
Mon Nov 05, 2018 6:12 pm
Forum: Beginner Basics
Topic: Can't copy big files through VPN
Replies: 3
Views: 1962

Re: Can't copy big files through VPN

SMB over the web is hideous. Latency will affect the performance massively. If you can you might be better trying to get an FTP or SFTP up and attack it that way.
by Steveocee
Mon Nov 05, 2018 4:56 pm
Forum: Beginner Basics
Topic: DNS: Difference between "IP>DNS" and "DHCP>Networks" [SOLVED]
Replies: 25
Views: 12752

Re: DNS: Difference between "IP>DNS" and "DHCP>Networks" [SOLVED]

Interesting as both statements can actually be correct at the same time if you read the information as a whole..... User added entries (user in place of admin, you know, the ones you specify yourself) take priority over servers gained dynamically -HOWEVER- If a server is gained dynamically BEFORE a ...
by Steveocee
Mon Nov 05, 2018 4:51 pm
Forum: RouterBOARD hardware
Topic: 60Ghz Perplexed
Replies: 6
Views: 2463

Re: 60Ghz Perplexed

Normis I understand your comment about 8 Clients 125Mbps etc, but the problem is we are competing with full fibre installs in the UK and a speed test at 100Mbps is not what they signed up for or expect. We offer 100, 250, 500 and 1Gbps plans and having that missing product in the middle is a real p...
by Steveocee
Mon Nov 05, 2018 4:45 pm
Forum: RouterBOARD hardware
Topic: FTTH FIBER 200MB
Replies: 4
Views: 1717

Re: FTTH FIBER 200MB

This implies that the router is certainly capable;
https://mikrotik.com/product/RB951G-2Hn ... estresults

Most likely an issue with your configuration. Can you post an export for all to see?
by Steveocee
Mon Nov 05, 2018 10:49 am
Forum: Beginner Basics
Topic: DNS: Difference between "IP>DNS" and "DHCP>Networks" [SOLVED]
Replies: 25
Views: 12752

Re: DNS: Difference between "IP>DNS" and "DHCP>Networks" [SOLVED]

Unless you find an alternate reference stating otherwise, I think you may owe me some brewskis :-)))))) "When both static and dynamic servers are set, static server entries are more preferred, however it does not indicate that static server will always be used (for example, previously query wa...
by Steveocee
Sun Nov 04, 2018 11:47 am
Forum: Beginner Basics
Topic: DNS: Difference between "IP>DNS" and "DHCP>Networks" [SOLVED]
Replies: 25
Views: 12752

Re: DNS: Difference between "IP>DNS" and "DHCP>Networks" [SOLVED]

Hi Steve, - DHCP Client, USE PEER DNS, instructs the router to use ISP DNS servers - IP DNS, allows one to enter in manually selected DNS Servers such as google and dyndns They both show up on the IP DNS page, and from what I gather the USE PEER DNS takes precedence and thus although one may have g...
by Steveocee
Sat Nov 03, 2018 1:27 pm
Forum: Scripting
Topic: Blacklist Filter (Development Topic)
Replies: 188
Views: 62602

Re: Blacklist Filter (Development Topic)

For IntusDave:
Do you have any problem or do you update? I run your script but the script didn't download nothing.

I thank you for your help!
Are you running IP > Cloud ? Would be the "easiest" thing to check at this point as it is a prerequisite.
by Steveocee
Sat Nov 03, 2018 11:18 am
Forum: Beginner Basics
Topic: Bypass simple Queue
Replies: 2
Views: 1977

Re: Bypass simple Queue

Create a another simple queue above your current one with target IP as your 1 device which will take priority.

Or you can create fast track rule for your 1 device which will then stop using queues.
by Steveocee
Sat Nov 03, 2018 9:53 am
Forum: RouterBOARD hardware
Topic: Desired switch
Replies: 7
Views: 2212

Re: Desired switch

I think the answer in your use is to simply get a CRS328 which is a little more expensive but has some "growing room". https://mikrotik.com/product/crs328_24p_4s_rm I hope that dedicated PoE and non-PoE ports will not be a thing in the future and they adopt the standard they are currently ...
by Steveocee
Fri Nov 02, 2018 12:31 pm
Forum: Beginner Basics
Topic: Need a Public IP for MY local network
Replies: 1
Views: 542

Re: Need a Public IP for MY local network

Yes the simplest way would be to run a VPN over the router and then forward ports from the VPN IP address to your server. This would work in fairness like a PPPoE connection.
by Steveocee
Thu Nov 01, 2018 6:55 pm
Forum: Wireless Networking
Topic: Big Mall Wireless Design
Replies: 1
Views: 1001

Re: Big Mall Wireless Design

Being totally honest you sound like you need a local consultant rather than help from the community with this. It's not just the design but the implementation as well will need to be very specific and a local consultant will be able to do all of this for you. For kit, the cAP or wAP AC would probabl...
by Steveocee
Thu Nov 01, 2018 5:03 pm
Forum: Virtualization
Topic: CHR neighbour discovery problem
Replies: 13
Views: 12798

Re: CHR neighbour discovery problem

I too have this problem. Winbox finds all RB & CRS devices in my network but my CHR takes about 4 tries to discover if at all.
by Steveocee
Thu Nov 01, 2018 1:54 pm
Forum: RouterBOARD hardware
Topic: PoE in on eth1 shuts RB2011 down
Replies: 1
Views: 1304

Re: PoE in on eth1 shuts RB2011 down

We have been using the RB2011 boards for some time now and have just recently experienced two units that will shut down when eth1 is plugged into a cisco poe switch. Works great when the poe is turned off on the switch port but is there any explanation as to why our past units are fine and only rec...
by Steveocee
Mon Oct 29, 2018 5:16 pm
Forum: General
Topic: Client wants to access NAT'd web server from inside LAN using WAN IP [SOLVED]
Replies: 4
Views: 3253

Re: Client wants to access NAT'd web server from inside LAN using WAN IP [SOLVED]

Take what you need from this. Explains how to hairpin NAT, create the correct port forwards and can be adapted for dynamic or static WAN IP (plus some comedy phrases);
https://www.youtube.com/watch?v=_kw_bQyX-3U
by Steveocee
Thu Oct 25, 2018 4:15 pm
Forum: Beginner Basics
Topic: CRS212-1G-10S-1S+IN
Replies: 2
Views: 1029

Re: CRS212-1G-10S-1S+IN

Think of the entire CRS range as a switch with "some" routing capability.
by Steveocee
Wed Oct 24, 2018 6:49 pm
Forum: General
Topic: CRS125 poor throughput & low cpu load [SOLVED]
Replies: 41
Views: 8621

Re: CRS125 poor throughput & low cpu load [SOLVED]

CRS125 is at heart a switch with some routing functionality, you shouldn't expect too much from it. Best I have ever had was 125Mb throughput but that was without fast track. Btest is an inefficient beast as well, you'd be better iPerfing through the router rather than in/out of it due to it's very ...
by Steveocee
Wed Oct 24, 2018 6:46 pm
Forum: Beginner Basics
Topic: Choosing the right router for the job
Replies: 5
Views: 1448

Re: Choosing the right router for the job

The 3011 would be a good choice if it was stable. It has a lot of port flapping issues which are yet to be fixed so I wouldn't confidently tell you to buy one. The RB1100AHx4 is very good and would easily cope with what you need however is a bit pricier than the 3011. Maybe the Hex or the Hex-S if y...
by Steveocee
Mon Oct 22, 2018 6:25 pm
Forum: Virtualization
Topic: VMware ESXi v6 - CHR 6.42.3 - Virtual Machine Crash then Update
Replies: 3
Views: 8235

Re: VMware ESXi v6 - CHR 6.42.3 - Virtual Machine Crash then Update

I have the following Configuration:
VMware ESXi v6.0.0
I am using ESXi 6.5.0 u2 with absolutely no issues at all. Is there any reason you have not updated your ESXi installation?
by Steveocee
Mon Oct 22, 2018 1:56 pm
Forum: General
Topic: LHG60 Link goes down when it rains
Replies: 21
Views: 4772

Re: LHG60 Link goes down when it rains

What channel are you using? The oxygen absorption effect is lessened as you go above 60Ghz. The "testing" 66Ghz channel is marketed as capable of 4Km so the current 64800 may give you the push you need.
by Steveocee
Mon Oct 22, 2018 1:51 pm
Forum: Beginner Basics
Topic: Simple Port Forwarding Question [SOLVED]
Replies: 1
Views: 1184

Re: Simple Port Forwarding Question [SOLVED]

No danger at all. It will work absolutely fine.
by Steveocee
Mon Oct 22, 2018 1:48 pm
Forum: Beginner Basics
Topic: Why I cannot obtain IP from ether4? [SOLVED]
Replies: 3
Views: 1747

Re: Why I cannot obtain IP from ether4? [SOLVED]

The interface is classed as a slave as it is part of a bridge, you can't run a DHCP client or server on a salve port, you would need to put it onto the bridge. That and the above.
by Steveocee
Fri Oct 19, 2018 6:42 pm
Forum: Scripting
Topic: Blacklist Filter (Development Topic)
Replies: 188
Views: 62602

Re: Blacklist Filter (Development Topic)

I've watched list "2" slowly grow over time, I think it was "only" around 14,000 entries when you first started this thread off and now it is up to 23,500+ entries. Seriously amazing stuff Dave.
by Steveocee
Fri Oct 19, 2018 11:23 am
Forum: General
Topic: Which Mikrotik router for this pilot GPON setup
Replies: 1
Views: 1101

Re: Which Mikrotik router for this pilot GPON setup

I would be tempted to future proof from the start and look at either a pair of 1016's or a 1036 (the pair of 1016 is for fault tolerance).
by Steveocee
Fri Oct 19, 2018 11:18 am
Forum: General
Topic: PSN NAT Type
Replies: 5
Views: 3647

Re: PSN NAT Type

Can you get the NAT type working if you remove the load balancer, so running a single connection first (even though it may be bad) and then add the load balancer back?

A correct implementation of UPnP should work (although not secure) but should as a minimum be consistent.
by Steveocee
Fri Oct 19, 2018 11:15 am
Forum: General
Topic: /ip dns servers= (cache) - how are multiple servers used?
Replies: 19
Views: 6662

Re: /ip dns servers= (cache) - how are multiple servers used?

My understanding was that DNS servers were always used in preference order. First one until it is not available at which point the queries go to the second.

If this is not the case it is both good and bad news I guess.
by Steveocee
Fri Oct 19, 2018 11:13 am
Forum: General
Topic: Which Mikrotik Product To Buy?
Replies: 4
Views: 1411

Re: Which Mikrotik Product To Buy?

Without knowing exact specification of what you want to achieve or you want to spend then I'd agree with Normis. That's a great all rounder.
by Steveocee
Fri Oct 19, 2018 11:08 am
Forum: Beginner Basics
Topic: Bridge to Bridge Connections
Replies: 3
Views: 894

Re: Bridge to Bridge Connections

If you have 2 separate bridges in the router then traffic behind them should be able to talk to each other anyway due to the fact you are connecting to a router. It will route as it's default mechanism. You actually have to try hard and firewall/filter them not to. You should be able to achieve what...
by Steveocee
Wed Oct 17, 2018 3:40 pm
Forum: Beginner Basics
Topic: PPTP VPN Protection
Replies: 9
Views: 3321

Re: PPTP VPN Protection

Put a cheap MT unit behind with IP>Cloud enabled.
Create address list on your router to only allow those DDNS names access to PPTP port.
Drop all other PPTP requests
by Steveocee
Wed Oct 17, 2018 1:49 pm
Forum: Beginner Basics
Topic: which is faster a many entries in the firewall or one with ip list
Replies: 2
Views: 996

Re: which is faster a many entries in the firewall or one with ip list

Address list is much more efficient for CPU than multiple FW lines.
by Steveocee
Wed Oct 17, 2018 10:54 am
Forum: RouterBOARD hardware
Topic: LHG60 3,8 km
Replies: 3
Views: 1457

Re: LHG60 3,8 km

This is excellent! I am now significantly more confident my 2.5Km link will work. (Hope you don't need your backup).
by Steveocee
Wed Oct 17, 2018 10:43 am
Forum: General
Topic: Network for children with limited Internet connection time
Replies: 9
Views: 2353

Re: Network for children with limited Internet connection time

Kid Control is by far the easiest way of achieving time based access across a child's devices. You can restrict the time slots (multiples throughout the day) speed and easily assign multiple devices to a child group.
by Steveocee
Mon Oct 15, 2018 6:23 pm
Forum: General
Topic: QoS trees colors
Replies: 3
Views: 1775

Re: QoS trees colors

I have a question about trees colors (green, yellow, green). I found in old post that color states are related with limit-at and max-value. green - a class the actual rate of which is equal or less than limit-at... yellow - a class the actual rate of which is greater than limit-at and equal or less...
by Steveocee
Mon Oct 15, 2018 4:26 pm
Forum: Beginner Basics
Topic: Router dropping traffic as "drop invalid"
Replies: 6
Views: 4709

Re: Router dropping traffic as "drop invalid"

Can you try disabling fasttrack. That stops connection tracking and may be what is causing the packets not to be classed as established or related.
by Steveocee
Mon Oct 15, 2018 3:59 pm
Forum: Beginner Basics
Topic: Need help with an online game
Replies: 2
Views: 899

Re: Need help with an online game

You will need to provide some more information for people to be able to help you. Can you provide an export of your config so we can see what the router is doing? Try turning off fasttrack as that stops connection tracking and may be part of the issue you are getting.
by Steveocee
Mon Oct 15, 2018 3:55 pm
Forum: Beginner Basics
Topic: WAP-LTE PoE voltage question [SOLVED]
Replies: 3
Views: 1354

Re: WAP-LTE PoE voltage question [SOLVED]

The WAP LTE can take a direct input of between 9&30v.
You could use the bundled 4 pin automotive installation cable and use 12v to power it.
by Steveocee
Mon Oct 15, 2018 2:08 pm
Forum: Wireless Networking
Topic: RB2011 Wireless Performance Troubleshoot
Replies: 6
Views: 2201

Re: RB2011 Wireless Performance Troubleshoot

Ok so after upgrading from 6.43 to 6.43.2 the problems ceased. It gets decent throughput and performance but still not compared to a RB941's throughput performance with the exact same settings and firmware. Have you actually tried Nest's suggestion? What that guy doesn't know about WiFi isn't worth...
by Steveocee
Mon Oct 15, 2018 1:42 pm
Forum: Beginner Basics
Topic: Router dropping traffic as "drop invalid"
Replies: 6
Views: 4709

Re: Router dropping traffic as "drop invalid"

Can you do a full export of your firewall?
Are you explicitly accepting already established and related connections?
by Steveocee
Sun Oct 14, 2018 9:41 am
Forum: Forwarding Protocols
Topic: RB4011 vs. CCR1009 BGP
Replies: 46
Views: 23609

Re: RB4011 vs. CCR1009 BGP

Have been saying for a long time there is room for a CCR with a quad core and the 4011 is close to making it (that rack mount though).

Almost like the CCR line went AMD mentality (more cores are better) than the Intel way of faster better cores.

Excited about this new generation of CCR
by Steveocee
Sun Oct 14, 2018 9:37 am
Forum: Beginner Basics
Topic: Looking up cloud.mikrotik.com every second
Replies: 24
Views: 14516

Re: Looking up cloud.mikrotik.com every second

Is there a chance of running 6.43? The is a new implementation of IP cloud and it may be a "legacy" feature.
by Steveocee
Fri Oct 12, 2018 3:54 pm
Forum: RouterBOARD hardware
Topic: CCR1009-7G-1C-1S+PC Scaling
Replies: 1
Views: 855

Re: CCR1009-7G-1C-1S+PC Scaling

Will be perfectly fine and work with existing switches without issue.
by Steveocee
Fri Oct 12, 2018 3:47 pm
Forum: Forwarding Protocols
Topic: RB4011 vs. CCR1009 BGP
Replies: 46
Views: 23609

Re: RB4011 vs. CCR1009 BGP

Yes, we are aware of this peculiarity and we are working also on new routers that have higher power per core, not just many cores.
That is extremely good news.
by Steveocee
Thu Oct 11, 2018 10:58 am
Forum: General
Topic: CLOUD ROUTER SWITCH
Replies: 6
Views: 2133

Re: CLOUD ROUTER SWITCH

Some models are lacking CPU information on the website. So far, just looking at the MHz on the listing is enough to categorize the models: 400 MHz: essentially switch, very low routing performance 600 MHz: RB2011-class router 800 MHz: about the same routing performance, different arch 800 MHz dual ...
by Steveocee
Thu Oct 11, 2018 10:56 am
Forum: Beginner Basics
Topic: Looking up cloud.mikrotik.com every second
Replies: 24
Views: 14516

Re: Looking up cloud.mikrotik.com every second

As a temporary work around have you tried making cloud.mikrotik a DNS static entry in the main router and sending the traffic nowhere? It may remove the flood of outbound DNS but obviously won't stop it as such.
by Steveocee
Wed Oct 10, 2018 6:48 pm
Forum: RouterBOARD hardware
Topic: HP NC375T not recognized
Replies: 3
Views: 1711

Re: HP NC375T not recognized

X86 or CHR?
I believe MT put most of the ongoing work and drivers into CHR now and do not update X86 so much.
by Steveocee
Wed Oct 10, 2018 6:47 pm
Forum: General
Topic: CLOUD ROUTER SWITCH
Replies: 6
Views: 2133

Re: CLOUD ROUTER SWITCH

Some models are lacking CPU information on the website. So far, just looking at the MHz on the listing is enough to categorize the models: 400 MHz: essentially switch, very low routing performance 600 MHz: RB2011-class router 800 MHz: about the same routing performance, different arch 800 MHz dual ...
by Steveocee
Wed Oct 10, 2018 6:44 pm
Forum: Beginner Basics
Topic: PPTP VPN Protection
Replies: 9
Views: 3321

Re: PPTP VPN Protection

You are opening a VPN server up to the world and are unhappy the world is trying to use it. Are you expecting the genuine VPN connections from a set IP address(es) or range or is it more a road warrior kind of setup? If you are expecting specific IP's then you can add them to a list and amend your a...
by Steveocee
Wed Oct 10, 2018 11:35 am
Forum: Wireless Networking
Topic: LHG 60G experience
Replies: 608
Views: 193919

Re: LHG 60G experience

Interesting experiences.
I have some test kit going up soon which is by Google mapping 2.63Km clear LOS tower to tower.
I'm not expecting full PHY rates but am wondering what it will reach and how any rain will affect the link. My hope is that it folds back and doesn't go off completely.
by Steveocee
Wed Oct 10, 2018 11:24 am
Forum: Virtualization
Topic: CHR license on router with no internet
Replies: 12
Views: 13317

Re: CHR license on router with no internet

From fresh install CHR is slightly hindered, you will only get 1Mb in one direction but full speeds in the other. Once you give it internet and assign it to your account it goes into trial mode (60 days) use. Once the 60 days runs out there is no detriment to the OS, it carries on working fine apart...
by Steveocee
Tue Oct 09, 2018 1:45 pm
Forum: Beginner Basics
Topic: No internet connection on my switch
Replies: 9
Views: 5591

Re: No internet connection on my switch

I actually thought that a CCR didn't have much of a config on it straight out of the box.

If you can't get connection from the router, go back to basics, is the CCR getting an IP? Does the interface have an IP?
by Steveocee
Tue Oct 09, 2018 1:40 pm
Forum: Beginner Basics
Topic: Manage export - import
Replies: 4
Views: 1743

Re: Manage export - import

Hi, What editor are you using? It's probably not the best idea to move between versions with an imported export as the newer version may not have some of the older references, some things change between version numbers which you may be referencing. To debug you could manually copy and paste the line...
by Steveocee
Sun Oct 07, 2018 6:35 pm
Forum: General
Topic: Birmingham MUM 2018
Replies: 13
Views: 2857

Re: Birmingham MUM 2018

Really looking forward to it.
by Steveocee
Tue Sep 25, 2018 10:52 am
Forum: General
Topic: RB3011 - set or change PIN
Replies: 1
Views: 2313

Re: RB3011 - set or change PIN

LCD > PIN
Capture.PNG
by Steveocee
Fri Sep 21, 2018 6:03 pm
Forum: General
Topic: ip cloud without default route
Replies: 4
Views: 1331

Re: ip cloud without default route

If you are unticking "add-default-route" then you simply need to correctly create a route for the router to reach the web.
Can you do an export of your static routes.
by Steveocee
Thu Sep 20, 2018 3:20 pm
Forum: RouterBOARD hardware
Topic: 100Mb LAN - what's the point?
Replies: 13
Views: 4487

Re: 100Mb LAN - what's the point?

OP has a point. New 60Ghz "Lite" model can do 60Ghz connection so up to Gbit over the air in full duplex and is specced with a 10/100 port. Mental! This is a CPE unit for connecting to an access point. If the AP has a gigabit connection and there are 8 CPEs connected, nobody can get more ...
by Steveocee
Thu Sep 20, 2018 11:17 am
Forum: RouterBOARD hardware
Topic: 100Mb LAN - what's the point?
Replies: 13
Views: 4487

Re: 100Mb LAN - what's the point?

OP has a point. New 60Ghz "Lite" model can do 60Ghz connection so up to Gbit over the air in full duplex and is specced with a 10/100 port. Mental!
by Steveocee
Mon Sep 17, 2018 4:09 pm
Forum: Beginner Basics
Topic: Are interface lists worth using?
Replies: 4
Views: 1337

Re: Are interface lists worth using?

Absolutely!

I find them very handy when setting up firewall and NAT rules.
by Steveocee
Tue Sep 11, 2018 9:12 am
Forum: General
Topic: Got fq_codel yet?
Replies: 36
Views: 17585

Re: Got fq_codel yet?

Just signed up to the forums to say... I really want this feature too. At this rate I'm going to have to buy an Ubiquiti EdgeRouter X to replace my hEX... Not quite as good as codel but use an sfq until it gets implemented. Just make sure you set the limits a few kB below what your service can do t...
by Steveocee
Mon Sep 10, 2018 2:52 pm
Forum: Announcements
Topic: v6.43 [current] is released!
Replies: 147
Views: 71256

Re: v6.43 [current] is released!

Have just moved my CHR up and cannot see any Winbox entry for IP>Cloud however terminal I can access it and apply it.
by Steveocee
Mon Sep 10, 2018 2:50 pm
Forum: Scripting
Topic: Blacklist Filter (Development Topic)
Replies: 188
Views: 62602

Re: Blacklist Filter (Development Topic)

Have just noticed 6.43 has moved into the current branch so have updated accordingly. Can't seem to find IP>Cloud though?? Looking forward to using the IntrusBL again.

**It's not in Winbox but is there in the terminal.
by Steveocee
Fri Sep 07, 2018 5:09 pm
Forum: General
Topic: Winbox via wine on Ubuntu 18.04
Replies: 5
Views: 5021

Re: Winbox via wine on Ubuntu 18.04

Discovering CHR via Winbox is very hit and miss. My CHR sometimes comes up if I refresh neighbours about 4 times and leave it for 5 mins. I wouldn't pin "all" of the blame on Winbox/WINE combo at this point.
by Steveocee
Tue Sep 04, 2018 5:12 pm
Forum: RouterBOARD hardware
Topic: Need new hardware (8ports and 16ports)
Replies: 29
Views: 5093

Re: Need new hardware (8ports and 16ports)

Steveocee This image compares only the color of the device in the interior, rather than laying the cable to the workstations (everything is done in the cable duct 25x60 mm) CRS112 or CRS326 is not suitable for tasks (expensive and two-storey ports, us need one floor ports UTP hid in cable channel 2...
by Steveocee
Tue Sep 04, 2018 5:11 pm
Forum: RouterBOARD hardware
Topic: Need new hardware (8ports and 16ports)
Replies: 29
Views: 5093

Re: Need new hardware (8ports and 16ports)

And one port should be placed on bootom side to be pluggable directly from the wall with 5 cm hidden cable. This port should be PoE In to power device. and ports should be colored to let users easy find one ... I am almost listening to technician saying "look for purple port and connect cable ...
by Steveocee
Tue Sep 04, 2018 4:17 pm
Forum: RouterBOARD hardware
Topic: Need new hardware (8ports and 16ports)
Replies: 29
Views: 5093

Re: Need new hardware (8ports and 16ports)

Image example It would never look like that though. Surely a CRS112 or CRS326 would do what you need? They can be wall mounted by turning the rack ears 90 degrees. I've taken the liberty of making your image look realistic though. Please note you can use different coloured LAN cables if you wish. 1...
by Steveocee
Tue Sep 04, 2018 3:59 pm
Forum: Beginner Basics
Topic: Got hacked, think I need help with configuring routerOS
Replies: 17
Views: 6522

Re: Got hacked, think I need help with configuring routerOS

Problem is here: RouterOS 6.35.4 Reset your RB3011 to factory default. Update it to the latest RouterOS 6.42.7 at time of writing this. Check for any scripts, scheduled tasks or files that look like they shouldn't be there. Change the admin details, create a new user for yourself, give yourself admi...
by Steveocee
Tue Sep 04, 2018 3:40 pm
Forum: Wireless Networking
Topic: 2.4 and 5 ghz dual band
Replies: 1
Views: 629

Re: 2.4 and 5 ghz dual band

Don't quote me but I thought on that model it was either 2.4Ghz or 5Ghz. Not simultaneous.
by Steveocee
Tue Sep 04, 2018 11:42 am
Forum: RouterBOARD hardware
Topic: RB3011 - SFP not working - hardware defect?
Replies: 8
Views: 3665

Re: RB3011 - SFP not working - hardware defect?

I have 6 SFP modules from various vendors and none of them work in rb3011. They work in all my other network equipment. i will try to replace the rb3011. Sorry to say that unless they are MikroTik modules you will not get much support. You should always use the correct module per device rather than...
by Steveocee
Tue Sep 04, 2018 11:32 am
Forum: RouterBOARD hardware
Topic: Whats the best current home routerboard for a gigabit ISP?
Replies: 20
Views: 13069

Re: Whats the best current home routerboard for a gigabit ISP?

Budget would be useful.

hAP AC or hAP AC2 would be towards the top of the pile.

If you can wait a short while one of these viewtopic.php?f=3&t=138613
by Steveocee
Mon Sep 03, 2018 6:39 pm
Forum: Beginner Basics
Topic: Hap MINI Configuration
Replies: 2
Views: 914

Re: Hap MINI Configuration

Make sure you are in ether2 or ether3 and use Winbox. If L3 is an issue you should be able to L2 into it.
by Steveocee
Mon Sep 03, 2018 6:16 pm
Forum: RouterBOARD hardware
Topic: RB3011 - SFP not working - hardware defect?
Replies: 8
Views: 3665

Re: RB3011 - SFP not working - hardware defect?

Have you correct SFP modules for send and receive? normally blue and yellow bars on them Blue and yellow is generally if you are using BiDi SFP's to denote which end you have used. I use Cisco GLC-SX-MM with no issues on my RB3011 so there is some evidence they "may" work. Have you got an...
by Steveocee
Fri Aug 31, 2018 5:52 pm
Forum: Beginner Basics
Topic: Quest network download limit [SOLVED]
Replies: 6
Views: 3639

Re: Quest network download limit [SOLVED]

So you've got a guest network that you want to slow down but they are still a member of your "private" LAN? You'd be better going down the slightly longer route and splitting them off with their own "guest" bridge and IP range to separate them from your LAN and it will give you m...
by Steveocee
Fri Aug 31, 2018 4:33 pm
Forum: Scripting
Topic: Blacklisting seems popular, honeypot made simple
Replies: 12
Views: 8031

Re: Blacklisting seems popular, honeypot made simple

A couple of days ago I think I may have found a slight "hiccp" with my brutal approach. The kids couldn't get Amazon prime to work and last night I also couldn't watch an Amazon video. Disabled my drop blocklist rule and they started working, looks like something from Amazon "poked&qu...
by Steveocee
Fri Aug 31, 2018 4:30 pm
Forum: Beginner Basics
Topic: Quest network download limit [SOLVED]
Replies: 6
Views: 3639

Re: Quest network download limit [SOLVED]

The queues may not have worked if the interfaces you specified were part of a guest bridge. Try applying 1 simple queue to the bridge rather than the interfaces and you should find it starts working.
by Steveocee
Thu Aug 30, 2018 4:21 pm
Forum: RouterBOARD hardware
Topic: mUPS max output current...way too low
Replies: 5
Views: 2163

Re: mUPS max output current...way too low

The current MUPS is only really aimed at single device upkeep such as clients CPE to keep internet going in case of power outage. When I read your first post my knee-jerk reaction was that RB260GSP ships with 2.5A power adapter which I would not expect a MUPS to be able to do. It of course has the e...
by Steveocee
Thu Aug 30, 2018 4:16 pm
Forum: RouterBOARD hardware
Topic: Memory Upgrade Ram
Replies: 2
Views: 2452

Re: Memory Upgrade Ram

Whilst this won't answer your question directly. If it was me I'd have whipped the top off the router to see what RAM it has currently and taken specs from that. MT have a 1036 "EM" model that ships with 2x8GB DIMMs so you can get at least 16GB in there. Begs the question though, what are ...
by Steveocee
Thu Aug 30, 2018 4:12 pm
Forum: RouterBOARD hardware
Topic: RB4011
Replies: 387
Views: 193151

Re: RB4011

The images released were probably just prototype. I can't see MT negating a feature like the USB from it's mid level tier lineup. LCD I wouldn't blame them from dropping, they're a waste of resource at best.
by Steveocee
Wed Aug 29, 2018 3:14 pm
Forum: Beginner Basics
Topic: Reinstall RouterOS (password issue)
Replies: 4
Views: 1107

Re: Reinstall RouterOS (password issue)

Do you need to reinstall RouterOS? You can do a hardware reset which puts the router back to factory settings or you can netinstall as others have said.
by Steveocee
Tue Aug 28, 2018 6:21 pm
Forum: General
Topic: Suggestion: simple speed limiter
Replies: 8
Views: 2741

Re: Suggestion: simple speed limiter

Yep. Those 2 drop downs in the advanced tab are too far out of reach 8) :lol:
by Steveocee
Tue Aug 28, 2018 4:32 pm
Forum: General
Topic: Suggestion: simple speed limiter
Replies: 8
Views: 2741

Re: Suggestion: simple speed limiter

Simple queue is perfectly adequate for this. Just use the first tab.
With only first tab is impossible to perform an elementary task in one queue:
set summary limit + set per IP limit
Have you looked into Queue type PCQ? I thought that would do what you are looking at?
by Steveocee
Tue Aug 28, 2018 9:10 am
Forum: Beginner Basics
Topic: multiple subnets on multiple ports - make them talk.
Replies: 3
Views: 1156

Re: multiple subnets on multiple ports - make them talk.

The subnets on each port only need a router between them to talk to each other. Thankfully you have that.
By its nature the CCR should try to route between the subnets unless you have stopped them from talking to each other.

Can you post more config?
by Steveocee
Mon Aug 27, 2018 11:22 pm
Forum: Beginner Basics
Topic: Problems after upgrade QUEUE does not work
Replies: 3
Views: 1067

Re: Problems after upgrade QUEUE does not work

Have you changed the queue recently? Maybe remove and re-add it. Have you rebooted the router? Rubbish answer but it did get me out of a similar situation once. The queue is pointed at the bridge, do you mean to limit the entire bridge like this? What is it you are trying to limit? WAN link? Can you...
by Steveocee
Mon Aug 27, 2018 11:19 pm
Forum: Beginner Basics
Topic: quota Limit on WAN interfaces
Replies: 2
Views: 1304

Re: quota Limit on WAN interfaces

You may be able to "bodge" this by setting up your LAN as a hotspot client and limiting data used that way? Very long winded way around doing it but should work.
by Steveocee
Mon Aug 27, 2018 11:18 pm
Forum: Beginner Basics
Topic: Looking up cloud.mikrotik.com every second
Replies: 24
Views: 14516

Re: Looking up cloud.mikrotik.com every second

Under the IP>Cloud setting, check to see if the time update function is ticked (by default it usually is) as this will keep looking time up. Enter your chosen NTP server in System>SNTP client instead.

That "should" sort it.
by Steveocee
Mon Aug 27, 2018 11:15 pm
Forum: General
Topic: Suggestion: simple speed limiter
Replies: 8
Views: 2741

Re: Suggestion: simple speed limiter

Hello,

current Queues has a very large number of settings and a very complex and confusing.

Please add simple speed limiter.
Simple queue is perfectly adequate for this. Just use the first tab. What is it you are trying to limit?
by Steveocee
Mon Aug 27, 2018 11:10 pm
Forum: General
Topic: Mikrotik CCR-1009-7G-1C Port Loop Problem
Replies: 2
Views: 702

Re: Mikrotik CCR-1009-7G-1C Port Loop Problem

As per previous reply. Please post a config so we can see for a loop, have you set an admin-mac address on your bridge? Sometimes this helps. I usually grab ether1's MAC and increase second character eg; E4:CC:D4 becomes E6:CC:D4
by Steveocee
Mon Aug 27, 2018 11:08 pm
Forum: General
Topic: [Feature request] Wireguard
Replies: 148
Views: 65858

Re: [Feature request] Wireguard

+1 Was reading about this earlier. Would love to see the MikroTik finger "on the pulse".
by Steveocee
Mon Aug 27, 2018 11:07 pm
Forum: General
Topic: Upgrading office network with MikroTik RB3011UiAS-RM
Replies: 1
Views: 708

Re: Upgrading office network with MikroTik RB3011UiAS-RM

Hi, Maybe a couple of WAP AC's would do the trick? Having said that as much as the guys on this forum may not like me mentioning it, something like a UBNT nanoHD would serve even better. I find MikroTik routers absolutely amazing for routers and switching but wireless I sometimes find lacking or lag...
by Steveocee
Fri Aug 24, 2018 6:07 pm
Forum: RouterBOARD hardware
Topic: Please give a remote hard reset option!!!
Replies: 11
Views: 5231

Re: Please give a remote hard reset option!!!

Also dangerous in a lot of situations.
That's why there is also a software option to turn it off.
by Steveocee
Fri Aug 24, 2018 4:09 pm
Forum: RouterBOARD hardware
Topic: Wireless wire dish, distance
Replies: 3
Views: 1685

Re: Wireless wire dish, distance

Hello world !!!

Does anyone make some test installations wth the wireless wire dish kit, and can show some results ?
I am looking for some hardware for a stable 4,5 km connection. I need ~500mbit/s.
Can these devices provide this ?

TIA
wayne
80Ghz may be better suited.
by Steveocee
Fri Aug 24, 2018 4:07 pm
Forum: RouterBOARD hardware
Topic: RBmAPL-2nD buggy? LAN/WLAN doesnt work
Replies: 3
Views: 971

Re: RBmAPL-2nD buggy? LAN/WLAN doesnt work

Sounds like it is faulty. How old is it? Will the seller not allow you to return?
by Steveocee
Fri Aug 24, 2018 4:06 pm
Forum: RouterBOARD hardware
Topic: Please give a remote hard reset option!!!
Replies: 11
Views: 5231

Re: Please give a remote hard reset option!!!

Do you mean kind of like the reset button you get on UBNT PoE?
That would be a pretty amazing idea.
by Steveocee
Thu Aug 23, 2018 6:58 pm
Forum: General
Topic: It's Mikrotik warehouse burned ???
Replies: 15
Views: 131347

Re: It's Mikrotik warehouse burned ???

This is why there is no V7. Upload to a current router and fire starts.
by Steveocee
Wed Aug 22, 2018 6:05 pm
Forum: General
Topic: HW Offload CRS 2 bridges
Replies: 5
Views: 3564

Re: HW Offload CRS 2 bridges

Not that I have a huge need for this but it would be great if MikroTik just made it work. I fear it may be hardware related as "old" software would only allow X amount of master's in a master-slave switch configuration.
by Steveocee
Wed Aug 22, 2018 5:50 pm
Forum: Scripting
Topic: Blacklisting seems popular, honeypot made simple
Replies: 12
Views: 8031

Re: Blacklisting seems popular, honeypot made simple

I've stuck the following onto a spare IP we have kicking about just to see what is prodding at it. It's harvesting a lot of IP's at the moment, forward planning is to have the IP's added dynamically then upload them to a server centrally then all border routers pull from that. You need to set a whit...
by Steveocee
Wed Aug 22, 2018 4:40 pm
Forum: Beginner Basics
Topic: Disable PoE
Replies: 5
Views: 14250

Re: Disable PoE

Even though it is labelled all ports PoE, routerOS gives you full option to force it on, off or auto on.

It will be fine.
by Steveocee
Wed Aug 22, 2018 3:51 pm
Forum: General
Topic: pppoe-out connection
Replies: 13
Views: 4102

Re: pppoe-out connection

Are you sure it is PPPoE related and not that the carrier link has gone down? What technology are you connecting over?
by Steveocee
Wed Aug 22, 2018 12:29 pm
Forum: Scripting
Topic: Blacklist Filter (Development Topic)
Replies: 188
Views: 62602

Re: Blacklist Filter (Development Topic)

@IntrusDave Can I ask if there is any way to relax this "need" for cloud? With 6.43 being an RC candidate many people won't run this on their "normal" equipment and only on test stuff. I love your script, I really do but I don't want to run a potentially unstable routerOS releas...
by Steveocee
Wed Aug 22, 2018 10:43 am
Forum: Scripting
Topic: Blacklist Filter (Development Topic)
Replies: 188
Views: 62602

Re: Blacklist Filter (Development Topic)

for some reason many of my firewalls do not seem to have the version of the code that supports the ddns. So when I go to /ip there is no "cloud". This is true for both x86 versions and CHR running 6.42.7. Has anybody else seen this? You need 6.43 on your CHR to run IP>Cloud and it has bee...
by Steveocee
Mon Aug 20, 2018 6:03 pm
Forum: Scripting
Topic: Blacklisting seems popular, honeypot made simple
Replies: 12
Views: 8031

Re: Blacklisting seems popular, honeypot made simple

This is a fantastic start!

I'll grab hold of this later and push it to a test router I have to see what it does or doesn't break.

Thank you
by Steveocee
Mon Aug 20, 2018 12:30 pm
Forum: RouterBOARD hardware
Topic: Queue Tree Performance
Replies: 1
Views: 1110

Re: Queue Tree Performance

When you mangle you are inspecting every packet so the CPU in those Hex's will start to max out quite quickly, yes they are brilliant for the price but the VPN performance is in part to the HW offloading. You need something with more CPU power. As a minimum you would want an RB3011, better yet an RB...
by Steveocee
Sun Aug 19, 2018 9:38 am
Forum: Wireless Networking
Topic: High gain directional antenna to normal antenna
Replies: 3
Views: 985

Re: High gain directional antenna to normal antenna

You would generally get better receive rates at the client end but you may struggle in getting RX rates at the AP up. IT wouldn't be uncommon to get a-symmetrical results. In PtP there would be little reason not to run matched antennas.
by Steveocee
Fri Aug 17, 2018 6:34 pm
Forum: General
Topic: SIP Registration issue
Replies: 10
Views: 3157

Re: SIP Registration issue

First thing to check is SIP helper turned off in your routers? IP>Firewall>Services ?
Occasionally clients call up with SIP issues and ask for SIP-ALG to be turned off which the above is the "go to" in this occasion.
by Steveocee
Fri Aug 17, 2018 4:08 pm
Forum: RouterBOARD hardware
Topic: Cracked cover on RouterBOARD DISC Lite5
Replies: 61
Views: 18399

Re: Cracked cover on RouterBOARD DISC Lite5

When ubiquity had problems with cracking ToughCable, they replaced it. When almost all car industry had a airbag,brake or software problems, they recall the cars for service. When Samsung had sell explosive phones, they replace the phones. Can you see the problem now? All of the above have a cost v...
by Steveocee
Fri Aug 17, 2018 11:01 am
Forum: Beginner Basics
Topic: Cannot block specific website
Replies: 5
Views: 1504

Re: Cannot block specific website

Expanding on previous comment. Use static DNS entry and force DNS requests to your MikroTik.
by Steveocee
Wed Aug 15, 2018 11:02 pm
Forum: RouterBOARD hardware
Topic: Random latency peaks: CCR1016-12S-1S+ hardware design issue suspected!
Replies: 8
Views: 3672

Re: Random latency peaks: CCR1016-12S-1S+ hardware design issue suspected!

An older issue with lower end models was that having the LCD screen active would cause latency spikes. Don’t know if you have LCD active but may be worth a try turning it off if it is on?
by Steveocee
Wed Aug 15, 2018 10:59 pm
Forum: Beginner Basics
Topic: POE Mikrotik hEX lite (RB750r2) and Ubiquiti Unifi AP
Replies: 3
Views: 2925

Re: POE Mikrotik hEX lite (RB750r2) and Ubiquiti Unifi AP

Yes should definitely work.
by Steveocee
Wed Aug 15, 2018 6:15 pm
Forum: Beginner Basics
Topic: POE Mikrotik hEX lite (RB750r2) and Ubiquiti Unifi AP
Replies: 3
Views: 2925

Re: POE Mikrotik hEX lite (RB750r2) and Ubiquiti Unifi AP

It depends which UAP you are using. Some will work from 24v power source and some need 48v power source.

From memory the UAP-AC-Lite and LR will power up from 24v and anything above that needs 48v (AC-Pro and onwards).
by Steveocee
Wed Aug 15, 2018 4:30 pm
Forum: Beginner Basics
Topic: Cannot block specific website
Replies: 5
Views: 1504

Re: Cannot block specific website

How are you trying to block it?
You could use the TLS matcher in firewall to block it.
by Steveocee
Wed Aug 15, 2018 10:49 am
Forum: General
Topic: New IP cloud is coming.
Replies: 84
Views: 47038

Re: New IP cloud is coming.

Will it be available for x86 router soon?
I am also looking forward to have support in x86
I hear mumbles of CHR being available from 6.43 so there could quite possibly be x86 implementation.
by Steveocee
Mon Aug 13, 2018 4:10 pm
Forum: General
Topic: MOAB mother of all blacklists
Replies: 88
Views: 22661

Re: MOAB mother of all blacklists

Stupid question, why a RAW and Filter drop rule? Can't there be 1 rule in RAW which kills everything on the list?
by Steveocee
Mon Aug 13, 2018 4:06 pm
Forum: Beginner Basics
Topic: OpenVPN - can't access Mikrotik (192.168.88.1) - other hosts are accesible
Replies: 6
Views: 3531

Re: OpenVPN - can't access Mikrotik (192.168.88.1) - other hosts are accesible

Steveocee thank you for explanation. The one more thing I would like to ask: Is adding new rule like I mentioned above safe? Or maybe there are other ways to get the router accessible over VPN? That rule could be tightened down a little more by specifying the in-interface as your VPN. I think that ...
by Steveocee
Mon Aug 13, 2018 3:14 pm
Forum: RouterBOARD hardware
Topic: RB3011 POE out max power
Replies: 9
Views: 2498

Re: RB3011 POE out max power

I would not want to daisy chain anything off the back of the RB3011. Personally I would be putting a passive injector between all the equipment mentioned. Why? The power output is not enough especially if you are looking at running kit out of the following kits PoE. It just won't be reliable.
by Steveocee
Mon Aug 13, 2018 2:11 pm
Forum: Beginner Basics
Topic: OpenVPN - can't access Mikrotik (192.168.88.1) - other hosts are accesible
Replies: 6
Views: 3531

Re: OpenVPN - can't access Mikrotik (192.168.88.1) - other hosts are accesible

That should work as long as it is above the block access rule.
The original rule was input chain so would only apply to traffic destined for the router. If you were blocking access to the LAN you'd want a forward rule as well, that is why you can ping hosts and not the router.
by Steveocee
Mon Aug 13, 2018 1:22 pm
Forum: Wireless Networking
Topic: Camp WiFi Design
Replies: 2
Views: 819

Re: Camp WiFi Design

Single SSID is simple. Set same SSID and ensure AP's are on different non overlapping channels. Roaming is handled by the client mostly anyway.
by Steveocee
Mon Aug 13, 2018 1:19 pm
Forum: Beginner Basics
Topic: Router Recommendation
Replies: 10
Views: 3373

Re: Router Recommendation

Your description is very vague. Anything from this page, maybe buy the best your budget allows?
https://mikrotik.com/products/group/wir ... and-office

If you can be more specific then we can advise better.
by Steveocee
Mon Aug 13, 2018 1:18 pm
Forum: Beginner Basics
Topic: OpenVPN - can't access Mikrotik (192.168.88.1) - other hosts are accesible
Replies: 6
Views: 3531

Re: OpenVPN - can't access Mikrotik (192.168.88.1) - other hosts are accesible

Your firewall filter rule disallows access from anything not on your LAN interface list. You are effectively not coming from your LAN interface when VPN'ing in to the router. That is most likely the cause.
by Steveocee
Mon Aug 13, 2018 12:07 pm
Forum: RouterBOARD hardware
Topic: RB3011 POE out max power
Replies: 9
Views: 2498

Re: RB3011 POE out max power

So I have to put a passive injector between RB760iGS and RB912UAG-5HPND. I dont want to use another PSU than my 24V/5A industrial railed one. I would not want to daisy chain anything off the back of the RB3011. Personally I would be putting a passive injector between all the equipment mentioned. Yo...
by Steveocee
Mon Aug 13, 2018 9:44 am
Forum: Scripting
Topic: Blacklist Filter (Development Topic)
Replies: 188
Views: 62602

Re: Blacklist Filter (Development Topic)

Yes, I've blocked most of the IP's that are trying to leach the lists. Still working on an auth system that is reliable. I think it's going to have to be based on the the Cloud DNS.. [/ip cloud set ddns-enable=yes] is going to be required, unless MikroTik gives me a way to authenticate better than ...
by Steveocee
Mon Aug 13, 2018 9:39 am
Forum: RouterBOARD hardware
Topic: RB3011 POE out max power
Replies: 9
Views: 2498

Re: RB3011 POE out max power

IIRC the max power output for an RB3011 is 0.5A (500ma)
What does the IIRC mean? Sorry I dont understand. Is it factory specification?
“If I Remember Correctly”
by Steveocee
Sun Aug 12, 2018 7:37 pm
Forum: RouterBOARD hardware
Topic: RB3011 POE out max power
Replies: 9
Views: 2498

Re: RB3011 POE out max power

IIRC the max power output for an RB3011 is 0.5A (500ma)
by Steveocee
Sun Aug 12, 2018 7:25 pm
Forum: Scripting
Topic: Blacklist Filter (Development Topic)
Replies: 188
Views: 62602

Re: Blacklist Filter (Development Topic)

@IntrusDave
Have you changed the beta availability again? I've just checked my list to make sure it's still updating nicely and noticed I've jumped form some 2K to 16K entries!
Thank you 8)
by Steveocee
Sat Aug 11, 2018 7:52 pm
Forum: Virtualization
Topic: The CPU has been disabled by the guest operating system
Replies: 32
Views: 16633

Re: The CPU has been disabled by the guest operating system

If you run maybe 2 cores do any get disabled?
by Steveocee
Sat Aug 11, 2018 12:10 pm
Forum: Beginner Basics
Topic: Dual WAN setup
Replies: 4
Views: 2012

Re: Dual WAN setup

Set your primary as distance 1 and enable check gateway.
Set secondary link as distance 2.

Router will go down primary until it cannot reach gateway where it will failover with no need for additional scripting.

Simple, but it works well.
by Steveocee
Thu Aug 09, 2018 7:36 pm
Forum: Virtualization
Topic: The CPU has been disabled by the guest operating system
Replies: 32
Views: 16633

Re: The CPU has been disabled by the guest operating system

ESXi on the free license will only allow up to 8 vCPUs, have you paid for ESXi? Usually ESXi would not start the VM and tell you to pay for it but maybe you’re getting a weird behaviour?

How many CPUs are you allocating?
by Steveocee
Wed Aug 08, 2018 11:59 pm
Forum: General
Topic: Line by line config restore from 6.34 to 6.42 firmware
Replies: 16
Views: 2495

Re: Line by line config restore from 6.34 to 6.42 firmware

You could also check if the new CCR can run 6.40 firmware (see in System->Resources what is the factory software, is it 6.40 or lower?) If so, you could downgrade to 6.40.8 and it will probably load your export without further issue, then you can upgrade again to 6.42.6 and it will automatically co...
by Steveocee
Wed Aug 08, 2018 10:11 pm
Forum: Virtualization
Topic: The CPU has been disabled by the guest operating system
Replies: 32
Views: 16633

Re: The CPU has been disabled by the guest operating system

How many CPU's are you assigning to the CHR installation? What happens if you set just 1?
by Steveocee
Wed Aug 08, 2018 10:08 pm
Forum: General
Topic: Line by line config restore from 6.34 to 6.42 firmware
Replies: 16
Views: 2495

Re: Line by line config restore from 6.34 to 6.42 firmware

Thanks! This is the next line not working set [ find default-name=ether4 ] advertise=100M-full,1000M-full comment=\ "Database Server" master-port=ether1-Group1-Master name=ether4-Group1 6.41 did away with master-slave configuration and introduced hardware offload to a software bridge.
by Steveocee
Wed Aug 08, 2018 6:32 pm
Forum: General
Topic: Line by line config restore from 6.34 to 6.42 firmware
Replies: 16
Views: 2495

Re: Line by line config restore from 6.34 to 6.42 firmware

Flow control is not present in the newer firmware hence not being able to apply it.
by Steveocee
Wed Aug 08, 2018 3:25 pm
Forum: General
Topic: 6.42.1 POE Overload
Replies: 12
Views: 5288

Re: 6.42.1 POE Overload

How are you powering the powerbox? I seem to remember reading recently (can't remember what thread) that you will get this if it is powered by PoE but not if it is by mains DC jack.
by Steveocee
Wed Aug 08, 2018 3:15 pm
Forum: Beginner Basics
Topic: PPPOE capping bandwitch
Replies: 1
Views: 567

Re: PPPOE capping bandwitch

Hello,
Can you post your config? Make sure to use the hide sensitive command so no needful details are shared with the world.
by Steveocee
Wed Aug 08, 2018 11:12 am
Forum: Beginner Basics
Topic: BANDWIDTH CONTROL
Replies: 1
Views: 650

Re: BANDWIDTH CONTROL

Can you post a bit more about what you are trying to achieve and how you have already gone about it?
Do an export of your config but hiding sensitive details or just your queues and we can probably help you.
by Steveocee
Wed Aug 08, 2018 11:03 am
Forum: Scripting
Topic: Blacklist Filter (Development Topic)
Replies: 188
Views: 62602

Re: Blacklist Filter (Development Topic)

It's limited for now, hoping to have a very basic auth system in place by tomorrow morning. My server logs show at least 2 people trying VERY hard to figure out how to trick the server to sending the list to a wget/curl client. Sorry, but the blaintant abuse won't be tolerated. I'll post a simple G...
by Steveocee
Wed Aug 08, 2018 10:59 am
Forum: Beginner Basics
Topic: Kid Control New User blocked
Replies: 3
Views: 1076

Re: Kid Control New User blocked

Yes. I know. But after pressing the button apply or OK in the WebFig all the input I made disappear and the user get the status blocked. But I found a solution: Adding a user in the terminal works well. the user gets blocked (and the input disappears) while adding a user in the WebFig. Thanks! If y...
by Steveocee
Tue Aug 07, 2018 6:54 pm
Forum: RouterBOARD hardware
Topic: RB951Ui-2HnD PoE out failure.
Replies: 7
Views: 3749

Re: RB951Ui-2HnD PoE out failure.

From another WISP in the UK. We too are seeing this problem. More often than not PoE disappears, a reboot does not fix it but a prolonged power off (1hr) does.
We don't want to switch back to injectors either we have seen a sharp rise in routers going "duff" and dropping power out of P5.
by Steveocee
Tue Aug 07, 2018 6:50 pm
Forum: Scripting
Topic: Blacklist Filter (Development Topic)
Replies: 188
Views: 62602

Re: Blacklist Filter (Development Topic)

I see everybody here is amazed how great service it is, but has anybody think about security risks of such service? Importing third-party script to your router without any validation? I wonder why this list is not provided as plain list of IPs and let everybody implement custom script parsing and v...
by Steveocee
Tue Aug 07, 2018 1:29 pm
Forum: Scripting
Topic: Blacklist Filter (Development Topic)
Replies: 188
Views: 62602

Re: Blacklist Filter (Development Topic)

Just put this onto my CHR home router. Had to fiddle the script a little bit to make it work though which I expected I may need to; Note, disk1 is not present and I had to add in a "?" after the "fetch.php" /tool fetch mode=https dst-path=/blacklist/filters.rsc url="https://...
by Steveocee
Tue Aug 07, 2018 11:12 am
Forum: General
Topic: PPTP VPN connection over PPPoE
Replies: 2
Views: 2992

Re: PPTP VPN connection over PPPoE

There is absolutely no problem in using the router as a PPtP client whilst it has a PPPoE internet connection. The issue you are facing sounds like you are allowing the PPtP tunnel to apply it's own default route weighted "1". Do not allow it to create it's own route and then build your ro...
by Steveocee
Tue Aug 07, 2018 11:10 am
Forum: General
Topic: MOAB mother of all blacklists
Replies: 88
Views: 22661

Re: MOAB mother of all blacklists

/watching

Interested to see feedback from those using this.
by Steveocee
Tue Aug 07, 2018 10:55 am
Forum: Beginner Basics
Topic: Kid Control New User blocked
Replies: 3
Views: 1076

Re: Kid Control New User blocked

You need to click the drop down next to the days. You are creating the user with no allotted time slot to use their device.
Once you click the drop down they will get time slot 00:00:00 - 00:00:00 which is always on.
by Steveocee
Tue Aug 07, 2018 10:54 am
Forum: Beginner Basics
Topic: bandwidth management
Replies: 3
Views: 1043

Re: bandwidth management

How do you want to share it?
Purpose built QoS?
Perfectly balanced per connection?
Round robin of connections trying to make use of it?
by Steveocee
Tue Aug 07, 2018 10:53 am
Forum: Beginner Basics
Topic: bonding mikrotik
Replies: 3
Views: 788

Re: bonding mikrotik

All the info you need will be just here; https://wiki.mikrotik.com/wiki/Manual:Interface/Bonding I have played around with bonding using 2 CCR's and a few ethernet's between them, I found the best results from using the "rr" method. Using 5Ghz dishes though it could be more beneficial to s...
by Steveocee
Mon Aug 06, 2018 8:29 am
Forum: General
Topic: CCR1009-7G-1C-1S+ vs CCR1009-7G-1C-1S+PC
Replies: 18
Views: 6634

Re: CCR1009-7G-1C-1S+ vs CCR1009-7G-1C-1S+PC

PC model is 9x1Ghz cores
Non-PC model is 9x1.2Ghz cores

These are stock figures but a small difference to be noticed if you are doing CPU intensive tasks.
by Steveocee
Mon Aug 06, 2018 8:24 am
Forum: Beginner Basics
Topic: Need help setting up my network.
Replies: 2
Views: 794

Re: Need help setting up my network.

Please post a config for the problem device.

What are you using dude to monitor exactly? Your ISPs network? I didn’t quite understand that bit. You don’t really have a network to monitor?
by Steveocee
Mon Aug 06, 2018 8:22 am
Forum: Virtualization
Topic: The CPU has been disabled by the guest operating system
Replies: 32
Views: 16633

Re: The CPU has been disabled by the guest operating system

When you say you have just installed CHR, do you mean you’ve used the premade OVA from MikroTik or you have used an ISO to install or how have you done it? Googleing the problem refers you to the VMware help center and the general consensus is it is caused by a kernel panic in the guest. So how have...
by Steveocee
Sun Aug 05, 2018 6:15 pm
Forum: Beginner Basics
Topic: Is export logically arranged?
Replies: 1
Views: 766

Re: Is export logically arranged?

Alphabetical as far as I’ve always understood it.
by Steveocee
Sun Aug 05, 2018 6:13 pm
Forum: Beginner Basics
Topic: Unsecured Network after login
Replies: 4
Views: 1986

Re: Unsecured Network after login

There is no security key for your connection to the wireless. It means you are susceptible to some unscrupulous people.
My advice would be to get a VPN to encapsulate your traffic so you can’t be intercepted.
by Steveocee
Fri Aug 03, 2018 10:36 am
Forum: General
Topic: How to separate the national and international bandwidth?
Replies: 3
Views: 1442

Re: How to separate the national and international bandwidth?

You can use https://mikrotikconfig.com/firewall/ to generate national IP lists. I would suggest generating just 1 which uses your country IP addresses. Rename the list to "national" or similar to suit. Mangle your traffic marking dst-address-list national traffic and then another mangle ru...
by Steveocee
Fri Aug 03, 2018 10:33 am
Forum: RouterBOARD hardware
Topic: LHG 60 6.43rc51 Unstable
Replies: 3
Views: 1488

Re: LHG 60 6.43rc51 Unstable

Thats a long way for the LHG60's!
by Steveocee
Thu Aug 02, 2018 12:43 pm
Forum: RouterBOARD hardware
Topic: CCR1009-7G-1S-1C+PC Problem OverHeat [SOLVED]
Replies: 13
Views: 7914

Re: CCR1009-7G-1S-1C+PC Problem OverHeat [SOLVED]

Is the environment very warm? I would dare say the obvious of would a standard cooling (non-PC) unit do the same?
Have you "overclocked" the CPU at all? Can you try running the CPU at a lower frequency and see if you get the same? System>Routerboard>Settings
by Steveocee
Thu Aug 02, 2018 11:56 am
Forum: Beginner Basics
Topic: Failover with Email
Replies: 4
Views: 1495

Re: Failover with Email

You could run a script on schedule to check if pppoe_out1 is down and if it is then send email?
Probably not quite as "clean" as using Netwatch but would certainly overcome the problem.
by Steveocee
Thu Aug 02, 2018 11:50 am
Forum: Beginner Basics
Topic: Nat not working
Replies: 4
Views: 1318

Re: Nat not working

By default the www service is enabled and the router will hold port 80. You can change that to free it up or you can disable www service if you are using Winbox.

Can you post some config?
by Steveocee
Thu Aug 02, 2018 10:43 am
Forum: Beginner Basics
Topic: Bridge port loop
Replies: 3
Views: 1106

Re: Bridge port loop

This is something which seems to crop up now and again. I am yet to find a "real" solution to it.

Are you using an admin MAC on your bridge? May be worth applying an admin MAC.
by Steveocee
Wed Aug 01, 2018 1:45 pm
Forum: Beginner Basics
Topic: Does wlan1 need to be part of bridge? [SOLVED]
Replies: 13
Views: 2816

Re: Does wlan1 need to be part of bridge? [SOLVED]

As Normis has mentioned. You will need a src-nat rule (copy the existing one and put your new range in) but also make sure you haven't made a mistake with the IP address on your new network. You MUST put the subnet after the IP address. You could do an export hide-sensitive to help us see your confi...
by Steveocee
Wed Aug 01, 2018 1:39 pm
Forum: Beginner Basics
Topic: Natting Problem (HairPin Nat) [SOLVED]
Replies: 11
Views: 2830

Re: Natting Problem (HairPin Nat) [SOLVED]

My god, you're a genius, I never thought of using .5.0/24 as my source but sure thats the most logical thing. It seems so simple now. And of course yeah 192.168.20.78/24 is the gateway I marked the diagram wrongly. Thank you so much for sticking with this and for all your help!! Glad you got it wor...
by Steveocee
Wed Aug 01, 2018 12:33 pm
Forum: Virtualization
Topic: CHR EULA?
Replies: 6
Views: 4768

Re: CHR EULA?

License the CHR to your account for the 30 day trial and then don't upgrade. Full speeds and no cost.
by Steveocee
Wed Aug 01, 2018 6:37 am
Forum: Beginner Basics
Topic: Natting Problem (HairPin Nat) [SOLVED]
Replies: 11
Views: 2830

Re: Natting Problem (HairPin Nat) [SOLVED]

Using a hairpin in its basic format, maybe something like this? Although I would point out that in your diagram you have listed VLAN704 with IP 192.168.20.64/28 which is the network address so I'm not sure if that may be affecting you? Either way try masquerading your /24 at your /28 as theoreticall...
by Steveocee
Tue Jul 31, 2018 6:41 pm
Forum: Beginner Basics
Topic: About "I am not a robot"
Replies: 4
Views: 2465

Re: About "I am not a robot"

I am " I AM NOT A ROBOT ERROR" in my network with several locations , kindly help me with how to fix this issue. what is the steps to take in mikrotik. An read could not harm. It is a problem created by Google on purpose because it does not like not to be able pinpoint a IP address to a u...
by Steveocee
Tue Jul 31, 2018 6:20 pm
Forum: Beginner Basics
Topic: Natting Problem (HairPin Nat) [SOLVED]
Replies: 11
Views: 2830

Re: Natting Problem (HairPin Nat) [SOLVED]

I've just re-read your diagram and initial post. As you are running 2 separate networks on independent IP ranges you probably don't need hairpin NAT in the way that my video implies. If your port forwards have an "in-interface" then that will be what is tripping you up as you aren't going ...
by Steveocee
Tue Jul 31, 2018 4:42 pm
Forum: Beginner Basics
Topic: Natting Problem (HairPin Nat) [SOLVED]
Replies: 11
Views: 2830

Re: Natting Problem (HairPin Nat) [SOLVED]

You need to remove the "out-interface" from your hairpin rule. The traffic won't actually go out if you're NAT'ing it back in.
by Steveocee
Tue Jul 31, 2018 1:19 pm
Forum: Beginner Basics
Topic: IP Firewall Filter rule not working with Bridge Mode
Replies: 4
Views: 6268

Re: IP Firewall Filter rule not working with Bridge Mode

If you are using a bridge then the firewall won't work from default. Why would a firewall filter a LAN bridge?
You need to go into Bridge > Settings and check "use IP firewall" to run the bridge traffic through your filters.
by Steveocee
Tue Jul 31, 2018 11:12 am
Forum: Beginner Basics
Topic: using a RB3011UiAS-RM as a PPPoe server
Replies: 4
Views: 1966

Re: using a RB3011UiAS-RM as a PPPoe server

What is the spec of your current server? May be worth just re-purposing the box and running CHR.
by Steveocee
Mon Jul 30, 2018 6:58 pm
Forum: Beginner Basics
Topic: Hairpin NAT not working
Replies: 8
Views: 2462

Re: Hairpin NAT not working

Hi Steveo I did watch your video a few times over the weekend, configured it exactly like your setup with the addition of having a static WAN IP. Still won't work. Any ideas? Make a new thread on this forum (so you don't spam this one) and post your config. Lets go through it and we'll sort it.
by Steveocee
Mon Jul 30, 2018 3:37 pm
Forum: Virtualization
Topic: The CPU has been disabled by the guest operating system
Replies: 32
Views: 16633

Re: The CPU has been disabled by the guest operating system

is it CHR not compatible with ESXi 6 ?
CHR is certainly compatible with ESXi 6 and 6.5(u2).

You must surely have some log files purporting to this?
by Steveocee
Mon Jul 30, 2018 3:33 pm
Forum: Beginner Basics
Topic: Hairpin NAT not working
Replies: 8
Views: 2462

Re: Hairpin NAT not working

thanks for your help, but I've added my LAN port to the Hairpin NAT and it's still not working
Have a watch of this. My very simple way of hair-pinning your NAT.
https://www.youtube.com/watch?v=_kw_bQyX-3U
by Steveocee
Mon Jul 30, 2018 12:39 pm
Forum: Beginner Basics
Topic: FTTC PPPoE client does not recover from blipping except via Watchdog [SOLVED]
Replies: 3
Views: 1577

Re: FTTC PPPoE client does not recover from blipping except via Watchdog [SOLVED]

Hello, /interface pppoe-client add add-default-route=yes default-route-distance=0 disabled=no interface=eth1_WAN keepalive-timeout=disabled max-mru=1500 max-mtu=1500 name=pppoe-out1 password=xxx profile=aaisp user=xxx Your problem is that keepalive-timeout is disabled. Set this to what is usually th...
by Steveocee
Mon Jul 30, 2018 12:30 pm
Forum: Wireless Networking
Topic: Wire 60 - through the trees
Replies: 6
Views: 2606

Re: Wire 60 - through the trees

Rule of thumb: the lower the frequency, the better it handles obstacles. 900MHz is good for non-LOS 2GHz is also fine 5GHz not so good 60GHz impossible ^^^ This exactly. If you struggle with 5Ghz then you shouldn't be thinking of going higher. Through trees 2.4Ghz would probably pull in what you wa...
by Steveocee
Fri Jul 27, 2018 6:34 pm
Forum: General
Topic: chr support fast path?
Replies: 6
Views: 2148

Re: chr support fast path?

What packets exactly are you thinking you are fast pathing"ing"? From? To?

https://wiki.mikrotik.com/wiki/Manual:Fast_Path
by Steveocee
Fri Jul 27, 2018 4:09 pm
Forum: Beginner Basics
Topic: Axis IP Cameras is not working
Replies: 9
Views: 2307

Re: Axis IP Cameras is not working

UPnP is a dirty but easy way of achieving what you want. I'd warn you away from it though as it can cause a lot of security issues as it gives devices the capability to poke holes in your firewall. Here is an easy way to enable UPnP https://www.youtube.com/watch?v=kkeu2t_6O2c You may be better thoug...
by Steveocee
Wed Jul 25, 2018 5:45 pm
Forum: General
Topic: btest - Where Is
Replies: 7
Views: 74016

Re: btest - Where Is

MikroTik would rather you no longer use it as it is so inefficient. They recommend to use traffic generator instead.
by Steveocee
Tue Jul 24, 2018 5:24 pm
Forum: Beginner Basics
Topic: First mikrotik router-- ned help understanding security instructions.
Replies: 3
Views: 1418

Re: First mikrotik router-- ned help understanding security instructions.

You can use WINE and run Winbox so you can get the "good" graphical experience from the router, you can also use SSH to get into the router. The command you found is fine to drop into the terminal replacing your LAN range with the XXXX/YY figures. The command in short allows user 0 (defaul...
by Steveocee
Tue Jul 24, 2018 3:07 pm
Forum: General
Topic: Feature Request: Processor, USB 3.0, M.2, and MSata Driver Support
Replies: 1
Views: 1294

Re: Feature Request: Processor, USB 3.0, M.2, and MSata Driver Support

Whilst not bare metal. You can use these features easily if you run a CHR instance.
by Steveocee
Mon Jul 23, 2018 9:19 am
Forum: RouterBOARD hardware
Topic: Recommend a RouterBoard
Replies: 2
Views: 1077

Re: Recommend a RouterBoard

The RB3011 seemed to be dead in the water from its launch with the “eggs” being thrown into the RB1100AHx4 basket shortly after its release. As an RB3011 user, I wouldn’t have said I was content, it certainly won’t route Gb once you load firewall rules and if you start mangling packets for queue tre...
by Steveocee
Mon Jul 23, 2018 9:08 am
Forum: Beginner Basics
Topic: MT as openvpn server
Replies: 1
Views: 1429

Re: MT as openvpn server

OpenVPN is quite lacking in RouterOS. There are many who are asking for better support. For now I would stick with your Cisco deployment if it is working for you.
by Steveocee
Mon Jul 23, 2018 9:06 am
Forum: Beginner Basics
Topic: Traffic prioritization - critique my setup (VoIP)
Replies: 1
Views: 600

Re: Traffic prioritization - critique my setup (VoIP)

Are you using fast track? If you are fast tracking any packets then they are not connection tracked so they will not be restricted under your queues which is some cases could harm your VOIP. What router are you using? It may be a little more work now going to a “full blown” queue tree but would make...
by Steveocee
Thu Jul 19, 2018 1:01 pm
Forum: Wireless Networking
Topic: Full duplex / bonding PtP link with 4 x QRT2 ?
Replies: 5
Views: 1521

Re: Full duplex / bonding PtP link with 4 x QRT2 ?

That's a real shame. In that case absolutely go with another pair of QRTs.
by Steveocee
Thu Jul 19, 2018 12:31 am
Forum: General
Topic: Unknown admin user created?!
Replies: 1
Views: 889

Re: Unknown admin user created?!

Sounds like your router is compromised.

Pinhole reset, upgrade firmware, pinhole reset and then change admin details.
by Steveocee
Thu Jul 19, 2018 12:29 am
Forum: Wireless Networking
Topic: Full duplex / bonding PtP link with 4 x QRT2 ?
Replies: 5
Views: 1521

Re: Full duplex / bonding PtP link with 4 x QRT2 ?

If you are going to spend money on another pair of QRT's then maybe consider the LHG60? That will give 1Gb full duplex up to 1.5Km and no bonding needed!
by Steveocee
Wed Jul 18, 2018 10:08 pm
Forum: Beginner Basics
Topic: RB3011UiAS-RM Configuration WITH IPSEC
Replies: 9
Views: 2681

Re: RB3011UiAS-RM Configuration WITH IPSEC

This is all very possible. what are you asking for? Will it do it? Yes. Have you tried and it is broken? Post your config. Can someone write you a full script to do this? Hire a consultant. why you don't ask what i am missing or had currently? instead of thinking I clearly stated that if you have t...
by Steveocee
Wed Jul 18, 2018 10:37 am
Forum: Beginner Basics
Topic: Why in MT everything, including VLANs can always access each other unless blocked by firewall? [SOLVED]
Replies: 14
Views: 3721

Re: Why in MT everything, including VLANs can always access each other unless blocked by firewall? [SOLVED]

To answer your thread title directly.

You are buying a router. Why would you expect it not to route as its default action?
When you add VLANs and additional subnets you are attaching them all to a router, therefore it will route between the networks.
by Steveocee
Wed Jul 18, 2018 2:18 am
Forum: Scripting
Topic: /system default-configuration
Replies: 5
Views: 2323

Re: /system default-configuration

I thought you could configure the default script using flashfig? Or is that not what you meant?
by Steveocee
Wed Jul 18, 2018 2:17 am
Forum: Scripting
Topic: CCR1009
Replies: 3
Views: 1652

Re: CCR1009

Hi i am CCR1009. i want config hostpost using free customer ( Wifi marketing). i have not document. Please help me. send document full config local on CCR1009 mail: tu.huynhngoc@trade.nguyenkim.com thank you Your Google must not be working. https://wiki.mikrotik.com/wiki/Manual:Hotspot_Introduction...
by Steveocee
Wed Jul 18, 2018 2:10 am
Forum: General
Topic: Limit Bandwidth to Subnet
Replies: 4
Views: 2923

Re: Limit Bandwidth to Subnet

The problem with doing that is when the connection is quiet, all clients still only get 2Mb. You could look at doing something like this to ensure a fair service to all, it creates a queue called default-sfq (as my OCD doesn't allow a hotspot or wireless queue on the WAN), target could be your PPPoE...
by Steveocee
Tue Jul 17, 2018 10:27 pm
Forum: General
Topic: First time MT user, got new CCR1009-7G, how to create VLAN (interface vs bridge)?
Replies: 3
Views: 1541

Re: First time MT user, got new CCR1009-7G, how to create VLAN (interface vs bridge)?

If you create a VLAN against an interface then the tag applies to that interface on either ingress or egress. If you apply the VLAN to a bridge then the VLAN tag is there for any interfaces that are ports of that bridge. If you have 1 "main" bridge and the VLANs are attached to it then eff...
by Steveocee
Tue Jul 17, 2018 5:04 pm
Forum: Beginner Basics
Topic: MikroTik crs109 – 8g-1s-2hnd-in router as dsl connected [SOLVED]
Replies: 2
Views: 989

Re: MikroTik crs109 – 8g-1s-2hnd-in router as dsl connected [SOLVED]

It is not. The CRS109 is a switch primarily and has no DSL modem built in. You would need a stand alone modem to demodulate and then you could potentially use the CRS109 as a router however I will warn you now, the performance won't be brilliant as it is a switch with some L3 capabilities. Not a des...
by Steveocee
Tue Jul 17, 2018 10:39 am
Forum: Beginner Basics
Topic: Firewall not working when accessing router via MAC address? [SOLVED]
Replies: 5
Views: 1488

Re: Firewall not working when accessing router via MAC address? [SOLVED]

As far as I am aware it is 1 operation which has multiple points of entry.

MAC Winbox has been a bit of a lifesaver when I've made a schoolboy error without using safe mode.
by Steveocee
Mon Jul 16, 2018 11:02 pm
Forum: Beginner Basics
Topic: IP Outside the IP Pool
Replies: 9
Views: 2596

Re: IP Outside the IP Pool

IP>ARP and you can see what IP's are talking to your router.
by Steveocee
Mon Jul 16, 2018 11:00 pm
Forum: Beginner Basics
Topic: Firewall not working when accessing router via MAC address? [SOLVED]
Replies: 5
Views: 1488

Re: Firewall not working when accessing router via MAC address? [SOLVED]

When you connect by MAC address you are connecting via layer 2.
Your firewall works on layer 3.
by Steveocee
Sat Jul 14, 2018 8:47 pm
Forum: General
Topic: UBNT and Mikrotik VLAN solution [SOLVED]
Replies: 4
Views: 2714

Re: UBNT and Mikrotik VLAN solution [SOLVED]

^^^ This. Let the UBNT kit do the tagging and untagging and leave the MikroTik kit in the middle effectively as "dumb" for bridging. On my home setup I have vlans attached to my main LAN bridge on the main router, all other kit is "dumb" switched and my Unifi AP's do VLAN tagging...
by Steveocee
Sat Jul 14, 2018 8:44 pm
Forum: Beginner Basics
Topic: create an outdoor access point
Replies: 1
Views: 583

Re: create an outdoor access point

Someone with the same username as you posted the same question!!! Can you believe that?

viewtopic.php?f=3&t=136739
by Steveocee
Sat Jul 14, 2018 8:40 pm
Forum: Beginner Basics
Topic: RB3011UiAS-RM Configuration WITH IPSEC
Replies: 9
Views: 2681

Re: RB3011UiAS-RM Configuration WITH IPSEC

This is all very possible. what are you asking for? Will it do it? Yes. Have you tried and it is broken? Post your config. Can someone write you a full script to do this? Hire a consultant.
by Steveocee
Sat Jul 14, 2018 8:37 pm
Forum: Beginner Basics
Topic: SSID for kids Zone with OpenDNS
Replies: 14
Views: 3938

Re: SSID for kids Zone with OpenDNS

Found it, it was pre 6.41 but was made so it could be "drag-drop-imported" onto an RB951Ui It creates a guest bridge, duplicates existing SSID and appends -Guest onto the new one, creates simple queue to limit speeds, creates firewall rules to stop networks talking to one another, uses sep...
by Steveocee
Sat Jul 14, 2018 8:27 pm
Forum: Beginner Basics
Topic: SSID for kids Zone with OpenDNS
Replies: 14
Views: 3938

Re: SSID for kids Zone with OpenDNS

Sorry, but publishing more details about a future commercial product goes too far. Wait, and you'll see. As a good comparison, for hotspots with special requirements, MT also is not properly suited, because closed. No problem to install squid or nginx on openwrt, for eample, if required for special...
by Steveocee
Sat Jul 14, 2018 9:36 am
Forum: Beginner Basics
Topic: SSID for kids Zone with OpenDNS
Replies: 14
Views: 3938

Re: SSID for kids Zone with OpenDNS

Perfectly within the realms of a MikroTik Yes, you are correct, to match the basic requirements of the thread starter. However, in case of more demanding functionality, MT not usable any more for commercial product. Why is the MT not usable? It will do perfectly fine. Even in more demanding applica...
by Steveocee
Fri Jul 13, 2018 4:53 pm
Forum: Beginner Basics
Topic: SSID for kids Zone with OpenDNS
Replies: 14
Views: 3938

Re: SSID for kids Zone with OpenDNS

You might simply wait, to buy a router with your requested features. Time to wait depends upon your location, as I am doing a commercial product based on openwrt implementing your request :-) MT is not the best platform for such a device. Because too closed. Perfectly within the realms of a MikroTi...
by Steveocee
Fri Jul 13, 2018 4:46 pm
Forum: Virtualization
Topic: How to use a CHR P1 license?
Replies: 7
Views: 5107

Re: How to use a CHR P1 license?

If you can live with the current version of RouterOS you don't have to apply your license and it will work fine.
by Steveocee
Thu Jul 12, 2018 7:35 pm
Forum: RouterBOARD hardware
Topic: create an outdoor access point
Replies: 3
Views: 1174

Re: create an outdoor access point

Process is the same whether 1m or 10Km.

What wil you be using at the far end? Is the PtP, PtMP or are you hoping to provide to mobile devices?
by Steveocee
Thu Jul 12, 2018 7:32 pm
Forum: Virtualization
Topic: Install Mikrotik on a X86 server
Replies: 4
Views: 4546

Re: Install Mikrotik on a X86 server

Visualise should be "virtualize". Installing to bare metal has many problems and it seems that Mikrotik is focusing on virtual versions instead on native ones. Lol Damn autocorrect! Yes I meant virtualise. If you are asking about bare metal install then can I assume you have a spare machi...
by Steveocee
Thu Jul 12, 2018 5:45 pm
Forum: Virtualization
Topic: Install Mikrotik on a X86 server
Replies: 4
Views: 4546

Re: Install Mikrotik on a X86 server

You can but it is recommended to use CHR and visualise. Driver support is better for CHR, CHR supports 64bit and licensing is better (and you can move licenses with CHR).
by Steveocee
Thu Jul 12, 2018 4:58 pm
Forum: General
Topic: Anyone using Ubiquiti branded SFP transceivers in your Mikrotik routers?
Replies: 4
Views: 5097

Re: Anyone using Ubiquiti branded SFP transceivers in your Mikrotik routers?

I am using my "old reliable" go to Cisco GLC-SX-MM in both my UBNT kit and MikroTik if that is of any use to you (probably not). There is definitely compatibility between those 3.
by Steveocee
Thu Jul 12, 2018 4:56 pm
Forum: General
Topic: CCR 1036 12G 4S - Low traffic
Replies: 11
Views: 2206

Re: CCR 1036 12G 4S - Low traffic

As @chechito says, check profile when it happens. Remember that even though your CPU is "only" hitting 10%, you have 36 cores making up 100% and if one of those is running at full steam as RouterOS likes to single thread things there is a high chance you are maxxing out your capabilities w...
by Steveocee
Thu Jul 12, 2018 3:38 pm
Forum: RouterBOARD hardware
Topic: RB2011UAS-2HND-IN but with 5ghz
Replies: 1
Views: 1225

Re: RB2011UAS-2HND-IN but with 5ghz

How about something like this?
https://mikrotik.com/product/RB962UiGS-5HacT2HnT

Unless you "need" 10 ethernet ports at which point I'd recommend an RB2011 with a WAP-AC.
by Steveocee
Thu Jul 12, 2018 3:37 pm
Forum: Beginner Basics
Topic: Bridge Fast Path Packets not counting
Replies: 4
Views: 1743

Re: Bridge Fast Path Packets not counting

May sound stupid but post a "working" config and then your config for the device not working for us to compare.
Most likely a simple setting in bridge like "use firewall" not checked.
by Steveocee
Wed Jul 11, 2018 12:41 pm
Forum: General
Topic: VPN attacks? Blocking?
Replies: 10
Views: 13296

Re: VPN attacks? Blocking?

Having a public facing VPN sever will get prodded regularly by people trying to gain access maliciously. If you have absolutely no way of locking down the accepted IP's then the best you can do is use complex usernames and passwords with a good passphrase. Do a whois lookup on the IP and add the sub...
by Steveocee
Wed Jul 11, 2018 12:36 pm
Forum: Wireless Networking
Topic: Cap AC, Hap AC2 or UniFi?
Replies: 38
Views: 29240

Re: Cap AC, Hap AC2 or UniFi?

MikroTik for routing.
Ubiquiti Unifi for wireless access.

I have a single UAP-AC-LR covering a 1930's 4 bed semi from the attic and I get amazing signal and speeds everywhere.
by Steveocee
Wed Jul 11, 2018 12:17 pm
Forum: General
Topic: Feature Request: fq_codel as queue
Replies: 0
Views: 1220

Feature Request: fq_codel as queue

Hi, With the likes of UBNT now sporting flashy titles such as "smart queue management" and digging down to discover that in reality it's "just" implementation of fq_codel. Would there be the chance of implementing it into the next generation of RouterOS? I understand that it requ...