hEXr3, 6.44.2 bridge mode

Hi
when im using the Quickset from a plain hEX(e.g. no own config) with 6.44.1/2 and set there bridge mode , dhcp based adress retrieval, i have the following effect.

  • system gets the IP via DHCP
  • i can no longer login (testet with and without password)

and Port 1 doesnt get assigned to the bridge. Or at least it doesnt assign the IP to this port.

Any idea ?

Is winbox telling you wrong pass or Could not connect?
can you connect with Ether 2.
we can not answer you unless we know more about this situation

After the change to Bridge (not touching the password at all) mode winbox can discover the hEX with the new IP adress. e.g. the adress will change from 192.68.88.1 to a local DHCP assigned IP.
Dependand which Ether i take (2-5) i see a different MAC but the same IP.
Then when i click connect the winbox times out.


Did this help.

Hi
making a NMAP scan (in bridge mode) showed that there nothing listening. Just Ping works. Or the firewall settngs get wrongly assigned.

so i would say this is a bug.

Make Winbox connect to the MAC address instead of IP address, so you can login again.
Then open terminal window and do a /export and check what went wrong and/or post it here.

problem identified, manually fixed and ticket opened.

Mikrotik is adding a default rule that nobody outside of the LAN can access. But for the bridge this is not working. Disabling this rule made the hEX bridge accessable.

What default rule? A firewall rule? A route rule? Why type of rule? You’re not explaining yourself clearly and this doesn’t help anyone down the road that might have this issue. So what did you actually manually change to fix this? Because this is sounding a lot like a configuration issue.

That is probably the right thing to do, unless you have lived under some stone for the last year!
Please show us what rule was added and why it is incorrect according to your view.

Don’t mind the impatient others, they understand IT but not people :slight_smile:

The best thing you can do is place a copy of your config here and then instead of wild-assed guessing or playing whackamole we can see the information needed directly!

To get a copy of the config you simply go to the left hand menu ‘new terminal’ icon in winbox and type in
/export hide-sensitive file=yourconfig (any name you wish)
Then to go the left hand menu ‘files’ icon and you will see the file there saved.
Right click and download to your desktop.
I use notepad ++ to open up config files.

Then simply copy and paste into the thread here. The only thing you should do is ensure that your ISP WAN address and ISP gateway address are not being shown.
Check ISP client setting and perhaps IP route settings for that.

To make the code appear elegant use the text bar above where bold is and highlight the code and then apply the icon that is a black square with white square brackets inside it.
Gluck!

Hi
after some researrch the problem seems to be on several areas.

  1. With 6.44 the dhcp package is no longer optional and it seems that it cannot be fully disabled. At least on my side a pool (which i never configured) appeared and assigned strange IP numbers 0.0.0.x . → so i switched back 6.43.
  2. having RSTP on the bridge switched on seems to make issues. Symptom: you can login via winbox using the MAC address and work without issues. With the IP obviosuly doesnt work for DHCP as the bridge doesnt get an IP. If you configure a fixed IP the system gets under a huge load (CPU 100%) and you get dropped often. → Switch of RSTP and fast forward on the bridge. see also here: http://forum.mikrotik.com/t/dhcp-client-on-bridge-does-not-work/118470/1

So now the system seems to work..

Remark to this gentleman argueing that im living on a stone. Im not sure if you know my setup and the reason for it, but i doubt. And you even doesnt know what is the plan. So plese stay in your own circles and cry but dont annoy others.

Hi,

I also can across this one as setting an hEX into bridge mode, in my testings, cuts all local IP connections.
I could still connect through Winbox but not with my browser anymore.
As I’m quite new in Mikrotik world, I didn’t dare to open a ticket but now, I’m glad it’s been done.

As many others, it seems, I would be very curious to get more details about this issue.
Has this behaviour been labelled as a “a feature” or “a bug” by Mikrotik support ?

Don’t mind the impatient others, they understand IT but not people > :slight_smile:

Well it’s a good thing this is a networking forum and not a physiology forum and the need to understand IT is greater than the need to understand people.

  1. With 6.44 the dhcp package is no longer optional and it seems that it cannot be fully disabled. At least on my side a pool (which i never configured) appeared and assigned strange IP numbers 0.0.0.x . → so i switched back 6.43.
  2. having RSTP on the bridge switched on seems to make issues. Symptom: you can login via winbox using the MAC address and work without issues. With the IP obviosuly doesnt work for DHCP as the bridge doesnt get an IP. If you configure a fixed IP the system gets under a huge load (CPU 100%) and you get dropped often. → Switch of RSTP and fast forward on the bridge. see also here: viewtopic.php?t=133156&sid=47ab86e30191 … 4ab6f9824b

Again, without see what you actually had in your config and what you actually fixed this doesn’t mean anything. I have routers running right now, on 6.44.x, where the DHCP server is completely disabled because it’s coming from another system on the network. I have numerous cAPs, wAPs and other devices that are in full bridge mode with the DHCP Client on the Bridge. I can also connect to them via Winbox over their IPs assigned to them over DHCP on the bridge and I don’t see issues with the CPU spiking through the sky.

Remark to this gentleman argueing that im living on a stone. Im not sure if you know my setup and the reason for it, but i doubt. And you even doesnt know what is the plan. So plese stay in your own circles and cry but dont annoy others.

You’re right, we don’t know your setup, that is why we ASKED TO SEE IT and other questions. You failed to provide any real information and a solution that you think is an actual solution but it’s not because the issue(s) you think you are having aren’t real issues they are just configuration problems. So check your attitude.

Hi
today i had some time to make some tests. Below you find what i did. Everybody can draw its own conclusion out of it. This is shared that others are aware.

\

All config was done via Winbox 3.18,
Naming conventions for the configs in the attached ZIP: hex_

step : comment

1: starting config: hexr3 with 6.44.13 bridge mode, router board FW 6.43.13
2: reset config via winbox menue, reboot: see hex 6.44.13 router, routerboard FW 6.43.13
3:install 6.44.2
4: routeboard upgrade tp 6.44.2
reboot

5: set hex to bridge via quickset menue in winbox , only check-box changed ; Configuration Mode: set to Bridge then press Apply

IP adress of Hex changed to local assigned IP from DHCP → Clicking IP connect doesnt work, using hX MAC works.

changes seen (just have a look into the atteched config.) And compare it to the 6.43.13.

  1. strange DHCP pool added
  2. firewall config added
  3. dhcp-server added
  4. static DNS server added




    6: Switchng back to 6.34.13–>
    7: reset config and then set to bridge mode → again strange config

somehow the system fell back to factory firmware 3.41 (routerboard) → upgraded routerboard FW and made config reset

After all these test i can no longer confirm that this is an 6.44 issue. Might be a Winbox issue.
But what is definitly happening with the switch to the bridge mode.

  1. DHCP range added to pool, DHCP server advertises 0.0.0.0 as default router
  2. firewall config not adjusted to local needs
  3. /ip dns static is not updated (still pointing to 192.168.88.1) or sometimes pointint to 0.0.0.0

now last try:
11: lets reset config and disable local dhcp server, delete local ip pool.
12: switch to bridge mode → now at least the strange DHCP range doesnt get populated.

hEX_configs.zip (13.3 KB)

Can you test it again, this time using Webfig to do the config (as long as you’re able to actually use it)? This would either definitely point at winbox or away from it.

Yes it looks like the “bridge” template is not really OK, probably almost nobody uses it and it receives little attention.
(normally people who want a 5-port bridge will buy a switch instead!)

DHCP server on bridge mode of course makes no sense, it should be deleted.
The firewall with WAN and LAN sides also makes no sense, so it should be changed.

Winbox is not involved in this, the creation of configs from templates is done entirely by the router itself.

When you want to use your hEX as a bridge I advise you to reset it without default configuration and create the bridge manually.
(just create a bridge and add all ports to it, add a DHCP client when you wish (no server), and when it is facing the internet create
some INPUT rules to limit access to the configuration)

Hi
i would also assume that hEX is normaly used as a router and yes you are right a switch would be normaly better , but i wanted to use the hEX as a VPN endpoint. Now the plan has changed and im going to use some CHR for this.

As mentioned this is to share my findings that others can save some time and Mikrotik can provide a fix in the future.

Have a nice easter weekend. Im now enjoing the sun in the Munich Alps.

All I see in that zip file is a bunch of configs that look incomplete. Did you actually try to see this stuff manually or just do this all through Quickset? What happens when you create the DHCP server on your own and assign IPs and the settings?

Again, I do this with hEX’s and other routers quite a lot. This isn’t a hEX issue, it’s a user issue.

Agreed Samot, quickset is just a starting point its not meant for any special changes or specific setups. The hex works out of the box for a basic LAN and basic WAN.

For the OP, just use this…
https://www.youtube.com/watch?v=XKYmgtVs9kc

hEX PoE has unique PoE passthrough capabilities (you can power it with PoE while it PoE-powers up to 4 devices !) that that renders it as a very attractive switch to power up AP, IP cameras or phones in places there AC power is missing.

6.44 hEX offers a bridge mode which, IMHO, is currently broken as the first consequence of applying it is kicking all connections out including local management.
This can be easily reproduced.

Fortunately, workarounds exist but a working bridge mode or no bridge mode at all, would be better, IMHO.

@olivier https://www.youtube.com/watch?v=XKYmgtVs9kc