Community discussions

MikroTik App

Search found 19783 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 66
by anav
Fri May 10, 2024 4:06 am
Forum: Beginner Basics
Topic: I need so advice on VLANs for devices connecting only via 2.4GHz wifi:
Replies: 8
Views: 542

Re: I need so advice on VLANs for devices connecting only via 2.4GHz wifi:

Just one of them. One would be the main router, the other would solely be an AP switch.
by anav
Thu May 09, 2024 10:45 pm
Forum: Forwarding Protocols
Topic: routing all trafic passthrough wireguard via wifi station
Replies: 5
Views: 353

Re: routing all trafic passthrough wireguard via wifi station

Still not enough detail, Please detail the relationship between every device in your diagram. Right now it looks like the laptop is directly connected to GWY1, which is directly connected to GWY2 Which is directly connected to the MANTBOX, which is directly connected toa wifi AP router which is dire...
by anav
Thu May 09, 2024 10:39 pm
Forum: General
Topic: Port forward from WAN to a host behind Wireguard
Replies: 9
Views: 809

Re: Port forward from WAN to a host behind Wireguard

I would need to see complete config, MT os does not work in isolation.

/export file=anynameyouwish ( minus router serial number, any public IP information, keys etc.)
by anav
Thu May 09, 2024 8:41 pm
Forum: Beginner Basics
Topic: Failover/Load Balancing + PBR
Replies: 16
Views: 690

Re: Failover/Load Balancing + PBR

Remove this rule.....
add action=reject chain=input in-interface-list=LAN log=yes log-prefix=\
rej_LAN reject-with=icmp-admin-prohibited


When you fixed the above items in the two posts and still cannot connect, then I will ahve someone else review the mangles as they look correct to me.
by anav
Thu May 09, 2024 8:39 pm
Forum: Beginner Basics
Topic: Failover/Load Balancing + PBR
Replies: 16
Views: 690

Re: Failover/Load Balancing + PBR

Of course they cannot, The Entrys dont match....... In fact having a symbol before a quote mark is probably really bad........... add add-default-route=no comment=WAN1-ISP interface=ether1-WAN1 script="if (\$\ bound=1) do={\r\ \n:local gw \$\"gateway-address\"\r\ \n/ip route set [ fin...
by anav
Thu May 09, 2024 8:20 pm
Forum: General
Topic: Port forward from WAN to a host behind Wireguard
Replies: 9
Views: 809

Re: Port forward from WAN to a host behind Wireguard

Well there are two approaches and the you wish will predicate the config option to go with. Question: do you want to know who the external IPs are at the M@ server ( identify them ) NO --> then source-nat all the traffic going into the wireguard tunnel at M1 --> advantage mangling not required you s...
by anav
Thu May 09, 2024 8:10 pm
Forum: General
Topic: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client
Replies: 30
Views: 1020

Re: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client

Probably firewall rules on your MT router dont allow it.
by anav
Thu May 09, 2024 3:21 pm
Forum: Beginner Basics
Topic: Failover/Load Balancing + PBR
Replies: 16
Views: 690

Re: Failover/Load Balancing + PBR

What is expected, and what is actually being observed??
by anav
Thu May 09, 2024 3:17 pm
Forum: General
Topic: Router unreachable after adding a routing mark "main"
Replies: 5
Views: 498

Re: Router unreachable after adding a routing mark "main"

@pe1chl Do you mean something like this at the start of mangle rules. /ip firewall mangle add action=accept chain=prerouting in-interface-list=LAN dst-address-list=MyWANS add action=accept chain=prerouting in-interface-list=LAN dst-address-type=local Where the first rule accepts traffic from any LAN...
by anav
Thu May 09, 2024 1:32 am
Forum: Beginner Basics
Topic: Failover/Load Balancing + PBR
Replies: 16
Views: 690

Re: Failover/Load Balancing + PBR

Ahh didnt realize that they were set to yes. That is better. Good catch.
by anav
Wed May 08, 2024 9:22 pm
Forum: General
Topic: WAN connection from second mikrotik router? [SOLVED]
Replies: 10
Views: 448

Re: WAN connection from second mikrotik router? [SOLVED]

Regardless, whether the cgnat lands on the ax3 or the RB5009 you cannot use it for port forwarding, its not a public IP that is reachable.
The only thing you can do is port forward on the WAN1 which is public on the Ax3, from there you can point to the RB5009 and an available server.........
by anav
Wed May 08, 2024 8:24 pm
Forum: Beginner Basics
Topic: Setup wireguard
Replies: 8
Views: 379

Re: Setup wireguard

Profile addition removed...
by anav
Wed May 08, 2024 8:24 pm
Forum: General
Topic: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client
Replies: 30
Views: 1020

Re: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client

I understand sorry, time delay to get questions answered. I will try to be patient :-)
by anav
Wed May 08, 2024 8:18 pm
Forum: Beginner Basics
Topic: Wireguard setup Roadwarrior [SOLVED]
Replies: 14
Views: 735

Re: Wireguard setup Roadwarrior [SOLVED]

No thanks, dont want to see that ugly looking set of firewall rules again. ;-)
Glad you got it sorted!
by anav
Wed May 08, 2024 8:10 pm
Forum: Beginner Basics
Topic: Failover/Load Balancing + PBR
Replies: 16
Views: 690

Re: Failover/Load Balancing + PBR

Correct, The only difference without LBing would be the mangling for LBing. Remember the routes we creates were also to ensure some users went out wan1 and some out wan2 along with establishing orderly main table routes. Without loadbalancing we would still need all six routes. I would have routing ...
by anav
Wed May 08, 2024 8:03 pm
Forum: General
Topic: Wireguard peer being unable to ping/connect to an address inside bridge1.
Replies: 1
Views: 131

Re: Wireguard peer being unable to ping/connect to an address inside bridge1.

Purpose of Wireguard, remote connection when away from home/business to access Router LAN, to access Router CONFIG, to go out Router internet?????
by anav
Wed May 08, 2024 8:01 pm
Forum: General
Topic: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client
Replies: 30
Views: 1020

Re: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client

Well you need to confirm something.
What is the wireguard IP address of the fritz --> ??
What is the subnet on the fritz trying to reach from MT -->??
by anav
Wed May 08, 2024 8:00 pm
Forum: General
Topic: WAN connection from second mikrotik router? [SOLVED]
Replies: 10
Views: 448

Re: WAN connection from second mikrotik router? [SOLVED]

One could always terminate both on the Ax3 and then send a single LAN only to the 5009 and that becomes WAN for the 5009 with a fixed private IP.
The desired WAN is only used by that LAN.
Advantages Disadvantages?
by anav
Wed May 08, 2024 5:52 pm
Forum: Forwarding Protocols
Topic: routing all trafic passthrough wireguard via wifi station
Replies: 5
Views: 353

Re: routing all trafic passthrough wireguard via wifi station

Okay lets break this down so it makes sense. You want to establish a wireguard connection from your LAPTOP to the MT MANTBOX. Does the mantbox have a public IP address associated with it, or is it connected to an ISP Router with a public IP and you can forward ports to the MANTBOX?? Then you want to...
by anav
Wed May 08, 2024 5:47 pm
Forum: Wireless Networking
Topic: Wifi 6 mesh
Replies: 7
Views: 438

Re: Wifi 6 mesh

@erlindend! Mesh is not a marketing gimmick LOL, its a systems where only one WIFI device is wired to the router or ISP modem/router and the rest of them connect to each other over wifi.
by anav
Wed May 08, 2024 5:46 pm
Forum: Wireless Networking
Topic: Very bad wifi performance in new HAP ax3
Replies: 18
Views: 903

Re: Very bad wifi performance in new HAP ax3

normis, you have a special Iphone LOL. I have the ax3 and dont get 800 but will go recheck now that you have made me curious.
by anav
Wed May 08, 2024 5:42 pm
Forum: Beginner Basics
Topic: Setup wireguard
Replies: 8
Views: 379

Re: Setup wireguard

See my profile
by anav
Wed May 08, 2024 5:32 pm
Forum: Beginner Basics
Topic: Failover/Load Balancing + PBR
Replies: 16
Views: 690

Re: Failover/Load Balancing + PBR

I could have gotten cute and used the fact that we made WAN1 primary ( as then vlan30 users would automatically go there ). However I chose simply to create the two WANS as is and use mangling to ensure connectivity as required. Dont be caught up on the fact that one wan is primary and another secon...
by anav
Wed May 08, 2024 5:18 pm
Forum: Beginner Basics
Topic: Setup wireguard
Replies: 8
Views: 379

Re: Setup wireguard

Meanwhile while you provide the answers, here is a guide for four routers with two of them being publicly reachable.
viewtopic.php?p=1062502&hilit=Four+rout ... d#p1062502
by anav
Wed May 08, 2024 5:12 pm
Forum: Beginner Basics
Topic: Setup wireguard
Replies: 8
Views: 379

Re: Setup wireguard

The question was simple WHICH ROUTER, has a reachable public IP. So far, you are batting zero. The reason I ask is the routers with public IP can be used as the Server for handshake in the wireguard network to be created. Since you four routers at play, I would advise Primary (with public IP) and th...
by anav
Wed May 08, 2024 5:08 pm
Forum: Beginner Basics
Topic: How to block IP range when NATed?
Replies: 11
Views: 480

Re: How to block IP range when NATed?

The approach is problematic ( more interested in blocking traffic vice focusing on needed traffic and simply dropping all else, Your attempt to run RDP for clients is going to cause issues. First and foremost RDP is an old protocol not considered secure. Its been replaced by citrix type functionalit...
by anav
Wed May 08, 2024 5:01 pm
Forum: General
Topic: [Help] VLAN Routing to VPN, with Local connections - Unusable performance when routing out Wireguard Interface
Replies: 7
Views: 494

Re: [Help] VLAN Routing to VPN, with Local connections - Unusable performance when routing out Wireguard Interface

Better to understand all the requirements BEFORE working on the config. As an overall approach is needed as many parts of the config are related.
Post your latest config for review.
by anav
Wed May 08, 2024 4:59 pm
Forum: General
Topic: WAN connection from second mikrotik router? [SOLVED]
Replies: 10
Views: 448

Re: WAN connection from second mikrotik router? [SOLVED]

Very weird, so from one ISP, and one cable from ISP modem ( in bridge mode ), you get two public IP addresses. One static and one PPPOE dial dynamic. They both come in on vlan1501. Do they have the same gateway? etc.. So if you were to run both on the AX3, how would you do it. FOR STATIC>> /IP dhcp ...
by anav
Wed May 08, 2024 3:21 pm
Forum: General
Topic: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client
Replies: 30
Views: 1020

Re: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client

Well you need to confirm something.
What is the wireguard IP address of the fritz --> ??
What is the subnet on the fritz trying to reach from MT -->??
by anav
Wed May 08, 2024 2:50 pm
Forum: Beginner Basics
Topic: 2-VPN Server on one Mirkotik with 2 PUblic IP
Replies: 2
Views: 191

Re: 2-VPN Server on one Mirkotik with 2 PUblic IP

Are both ends using MT routers? What does your client use?
Remember If WAN1 goes down, your wireguard will automatically switch to WAN2 with a slight delay.
The router will inform the client end that the endpoint address has changed.
by anav
Wed May 08, 2024 2:40 pm
Forum: Beginner Basics
Topic: wireGuard does not work for me on my mikrotik RB750r2
Replies: 1
Views: 180

Re: wireGuard does not work for me on my mikrotik RB750r2

Is this router connected to the internet. If so unplug immediately as you have no firewall protection. You dont know how to setup wireguard but you removed the perfectly good default firewall rules protecting your network ????? You are missing the allowing of handshake rule in the input chain and ma...
by anav
Wed May 08, 2024 2:38 pm
Forum: Beginner Basics
Topic: Wireguard interface on 2 different WAN
Replies: 3
Views: 228

Re: Wireguard interface on 2 different WAN

The question I have is WHY? As a backup? If you have wireguard setup on WAN1, and WAN1 fails and your router moves to using WAN2, your wireguard will also shift to WAN2 after some period of delay. If your purpose is to provide different access for different users, that starts to make a little sense ...
by anav
Wed May 08, 2024 2:34 pm
Forum: Beginner Basics
Topic: Setup wireguard
Replies: 8
Views: 379

Re: Setup wireguard

Which Router(s) have a reachable public IP address, or can forward ports from upstream router.
Dont really care about NORDVPN, has nothing to do with what your asking.
by anav
Wed May 08, 2024 2:30 pm
Forum: General
Topic: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client
Replies: 30
Views: 1020

Re: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client

/ip route
add dst-address=10.3.1.0/24 gateway=wireguard1 routing-table=main
by anav
Wed May 08, 2024 2:28 pm
Forum: General
Topic: Find best way to block many website
Replies: 7
Views: 372

Re: Find best way to block many website

Stated differently, MT devices cannot provide the answers you seek to comply with Govt Regulations.
by anav
Wed May 08, 2024 2:27 pm
Forum: General
Topic: Dynamic interface list woes
Replies: 3
Views: 242

Re: Dynamic interface list woes

Without seeing your config, one is guessing..........rather work on facts......

/export file=anynameyouwish ( minus router serial number, any public WANIP information, keys etc. )
by anav
Wed May 08, 2024 2:25 pm
Forum: General
Topic: Router unreachable after adding a routing mark "main"
Replies: 5
Views: 498

Re: Router unreachable after adding a routing mark "main"

The difference between V6 and V7 (1) In V7 you need to separately create tables. /routing table add fib name=to-ISP1 add fib name=to-ISP2 (2) Mangle rules do not change, you still need new-routing-mark=to-ISPX (3) Ip Routes change - you do NOT use route-marking in IP route, instead you use routing-t...
by anav
Wed May 08, 2024 2:19 pm
Forum: General
Topic: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client
Replies: 30
Views: 1020

Re: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client

What are the subnets on the fritz that the users on your local MT devices need to visit?? They need to be accounted for on both allowed IPs and IP routes. Since you have 0.0.0.0/0 set as allowed IPs, which covers both the case of internet and subnets, you dont really need to adjust allowed IPs. Sinc...
by anav
Wed May 08, 2024 2:12 pm
Forum: General
Topic: WAN connection from second mikrotik router? [SOLVED]
Replies: 10
Views: 448

Re: WAN connection from second mikrotik router? [SOLVED]

You cannot terminate A single ISP connection in two routers.
That being said, are you saying you get two separate WAN connections from ISP1 ??
by anav
Wed May 08, 2024 1:11 am
Forum: General
Topic: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client
Replies: 30
Views: 1020

Re: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client

The IP address is incorrect From: add address=192.168.1.5 interface=wireguard1 network=192.168.1.0 TO: add address=192.168.1.5 /24 interface=wireguard1 network=192.168.1.0 Remove this static DNS setting /ip dns static add address=192.168.88.1 comment=defconf name=router.lan The most important questi...
by anav
Tue May 07, 2024 11:49 pm
Forum: Beginner Basics
Topic: Cannot get WireGuard to route traffic
Replies: 6
Views: 574

Re: Cannot get WireGuard to route traffic

/ip firewall address-list add address=192.168.88.XX list= Authorized comment="admin desktop" add address=192.168.100.2 list=Authorized comment="admin remote phone" add address=192.168.100.2 list=Authorized comment="admin remote laptop" The question I have is the other ...
by anav
Tue May 07, 2024 10:59 pm
Forum: General
Topic: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client
Replies: 30
Views: 1020

Re: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client

Post your latest config with changes included please.
by anav
Tue May 07, 2024 10:06 pm
Forum: General
Topic: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client
Replies: 30
Views: 1020

Re: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client

Yes, this is necessary. add address=192.168.1.5 interface=wireguard1 network=192.168.1.0 The issue is the question I posed which you didnt answer. What is going out wireguard to the fritz, one user, all users etc...... Also can you confirm you have remote users hitting the fritz and needing then acc...
by anav
Tue May 07, 2024 10:01 pm
Forum: Beginner Basics
Topic: Failover/Load Balancing + PBR
Replies: 16
Views: 690

Re: Failover/Load Balancing + PBR

That is one approach get rid of the offending diagram LOL. (1) Since you are queueing and mangling, we need to remove the fastrack rule from the forward chain. (2) Primary WAN for vlan30 is WAN1 (3) Primary WAN for one user on vlan10 is WAN2 --> 172.16.10.100 (4) All other users should share the ava...
by anav
Tue May 07, 2024 8:01 pm
Forum: General
Topic: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client
Replies: 30
Views: 1020

Re: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client

(1) Pre-shared key is not required, and is not normally used, so for troubleshooting purposes remove for now. /interface wireguard peers add allowed-address=0.0.0.0/0 endpoint-address=x2061.myfritz.net \ endpoint-port=59162 interface=wireguard1 persistent-keepalive=25s \ preshared-key="=" ...
by anav
Tue May 07, 2024 7:00 pm
Forum: Beginner Basics
Topic: Mikrotik wAP AC - Router, no bridge, Beginner questions
Replies: 13
Views: 409

Re: Mikrotik wAP AC - Router, no bridge, Beginner questions

Glad its all working for you now. :-)
by anav
Tue May 07, 2024 6:50 pm
Forum: Beginner Basics
Topic: Question: SSIDs on different VLANs on LAN
Replies: 9
Views: 471

Re: Question: SSIDs on different VLANs on LAN

Not being clear, The MT you stated should be used as an AP. The PA you stated handles creation of vlans/subnets and handles DHCP. 1. On the MT AP 192.168.98.91 (assigned to ether2) should be just used for managing the MT AP. Understood that the IP address is assigned to the MT device and thus its on...
by anav
Tue May 07, 2024 6:41 pm
Forum: Forwarding Protocols
Topic: routing all trafic passthrough wireguard via wifi station
Replies: 5
Views: 353

Re: routing all trafic passthrough wireguard via wifi station

Sorry very confusing..... Can you draw a network diagram please....... Not sure which ones still valid...... Step1 - NETWORK DIAGRAM Provide a network diagram of your setup with enough detail so that the subnets (vlans), devices and their relationships are clearly established. If able, on the same, ...
by anav
Tue May 07, 2024 6:33 pm
Forum: Beginner Basics
Topic: Port forwarding on RBwAPGR-5HacD2HnD&R11e-LTE6
Replies: 6
Views: 365

Re: Port forwarding on RBwAPGR-5HacD2HnD&R11e-LTE6

Okay So compare the 62.x.x.x.x public IP you get via IP cloud, to your WANIP address you get in IP DHCP client. Are they the same?? It might show on your LTE settings ??? Or may show up as your gateway IP??? No need to show the numbers but if public they should all sorta lineup. Note even your IP cl...
by anav
Tue May 07, 2024 6:29 pm
Forum: Beginner Basics
Topic: Failover/Load Balancing + PBR
Replies: 16
Views: 690

Re: Failover/Load Balancing + PBR

Not my problem your diagram does not match the first few lines of the config. Stopped me cold. Not going to waste my time on such blatant inconsistencies. If you had said ignore the etherport designations on the diagram, because they were wrong, then I would have been prepared Your response did not ...
by anav
Tue May 07, 2024 6:23 pm
Forum: Beginner Basics
Topic: Mikrotik wAP AC - Router, no bridge, Beginner questions
Replies: 13
Views: 409

Re: Mikrotik wAP AC - Router, no bridge, Beginner questions

Fantastic!. Yes you can enable the IP DHCP client, and also select default-route= yes, and then remove the IP address and the manual route, comes to the same thing! However, you appear to be not listening, and keep running into a stone wall. Do you like the pain?? Please remove your bridge filter it...
by anav
Tue May 07, 2024 5:52 pm
Forum: Beginner Basics
Topic: Question: SSIDs on different VLANs on LAN
Replies: 9
Views: 471

Re: Question: SSIDs on different VLANs on LAN

Sorry, but your not making sense. You want different vlans (at least two ) to enter the MT AP, so it can distribute them over WIFI. If one of the those two vlans is not a trusted subnet ( limited to trusted users aka home vice guest ) then one should have a separate management subnet but will leave ...
by anav
Tue May 07, 2024 5:46 pm
Forum: General
Topic: Find best way to block many website
Replies: 7
Views: 372

Re: Find best way to block many website

Yes but that means you need equipment that can do DPI of encrypted traffic so that rules out most equipment unless you go high end Juniper etc with subscription services.
by anav
Tue May 07, 2024 4:29 pm
Forum: Beginner Basics
Topic: Port forwarding on RBwAPGR-5HacD2HnD&R11e-LTE6
Replies: 6
Views: 365

Re: Port forwarding on RBwAPGR-5HacD2HnD&R11e-LTE6

Are you sure you get a public IP address from the ISP provider??
by anav
Tue May 07, 2024 4:27 pm
Forum: Beginner Basics
Topic: Route a Static IP through Wireguard Tunnel
Replies: 4
Views: 311

Re: Route a Static IP through Wireguard Tunnel

Best to provide config after giving it a go.
by anav
Tue May 07, 2024 4:26 pm
Forum: Beginner Basics
Topic: Cannot get WireGuard to route traffic
Replies: 6
Views: 574

Re: Cannot get WireGuard to route traffic

(1) Yes local interface created. Extra routing only required if visiting subnets at other end of tunnel and you need to tell router to get there you need to go through tunnel. (2) It means an error on your config. Remove ether1 from dhcp client, it has nothing to do with WAN (3) FW rules are not the...
by anav
Tue May 07, 2024 4:00 pm
Forum: Beginner Basics
Topic: Mikrotik wAP AC - Router, no bridge, Beginner questions
Replies: 13
Views: 409

Re: Mikrotik wAP AC - Router, no bridge, Beginner questions

So the zyxel is a modem router or just a modem?? Will assume very little if any protection afforded by zyxel. Bridge Filter removed. No need to add a bridge. /ip dhcp-client add disabled= YES interface=ether2-UPLINK /ip firewall filter { order is important ! } add action=accept chain=input connectio...
by anav
Tue May 07, 2024 3:59 pm
Forum: Beginner Basics
Topic: Port forwarding trouble with PCC load balancing
Replies: 30
Views: 1978

Re: Port forwarding trouble with PCC load balancing

Nope, the fw rules and mangle rules are not as I put them so cannot really help much more.
by anav
Tue May 07, 2024 3:55 pm
Forum: Beginner Basics
Topic: Mikrotik wAP AC - Router, no bridge, Beginner questions
Replies: 13
Views: 409

Re: Mikrotik wAP AC - Router, no bridge, Beginner questions

If you want to use it as an AP, configure it as an AP. The steps would be: Reset to default: https://wiki.mikrotik.com/wiki/Manual:Reset Select Home AP in QuickSet Config the wireless part He wants two different subnet for wifi, NOT subnets from the main router. Using the MT device as a router is t...
by anav
Tue May 07, 2024 3:51 pm
Forum: Beginner Basics
Topic: Mikrotik wAP AC - Router, no bridge, Beginner questions
Replies: 13
Views: 409

Re: Mikrotik wAP AC - Router, no bridge, Beginner questions

I dont use ip forward, not familiar..... Also you state you would prefer not to use bridge, so what makes you think you can throw in a bridge filter ( advanced setting ) without any bridge ??? Lets stick to simple and what works please. (1) Get rid of bridge filter! (2) What is your intent for firew...
by anav
Tue May 07, 2024 3:40 pm
Forum: Beginner Basics
Topic: Question: SSIDs on different VLANs on LAN
Replies: 9
Views: 471

Re: Question: SSIDs on different VLANs on LAN

This is straightforward you are simply using the hapAX3 as a AP.switch Thus I would expect the input port is a trunk port carrying all the vlans required for data and the management VLAN ( which may be considered an already existing trusted user vlan) So which vlans are coming into the hapax3? Which...
by anav
Tue May 07, 2024 3:36 pm
Forum: Beginner Basics
Topic: Mikrotik wAP AC - Router, no bridge, Beginner questions
Replies: 13
Views: 409

Re: Mikrotik wAP AC - Router, no bridge, Beginner questions

Is the MT AP acting as a router?
Giving out dhcp, routing etc and the upstream router is solely being used as a WAN source, providing a private IP on its LAN to the MT device??
by anav
Tue May 07, 2024 3:33 pm
Forum: Beginner Basics
Topic: Failover/Load Balancing + PBR
Replies: 16
Views: 690

Re: Failover/Load Balancing + PBR

Just looking at your etherports on the config, I get confused because your diagram and your wording are in conflict. Without consistency, there is no point in assessing config. The ports on your router ether1 and ether2 Go to WAN -- config text -- Check ether3 goes to Switch1 -- config text--- WRONG...
by anav
Tue May 07, 2024 3:26 pm
Forum: General
Topic: CapsMan VLAN trouble
Replies: 8
Views: 438

Re: CapsMan VLAN trouble

Besides the main router how many APs are you controlling?
by anav
Tue May 07, 2024 3:25 pm
Forum: General
Topic: Find best way to block many website
Replies: 7
Views: 372

Re: Find best way to block many website

Not sure what you mean.
The govt blocks websites and you want to be able to access such websites?
The govt expects you to block websites as a private homeowner?
by anav
Tue May 07, 2024 1:11 am
Forum: Beginner Basics
Topic: Loadbalancing two internet connections - do I need a seperate
Replies: 1
Views: 234

Re: Loadbalancing two internet connections - do I need a seperate

Load balancing is fairly straight foward on RoS
I would get your money back, the device does not do DPI inspections ( of encrypted traffic ) and thus is a ripoff.
by anav
Tue May 07, 2024 1:10 am
Forum: Wireless Networking
Topic: Full wifi device isolation
Replies: 4
Views: 334

Re: Full wifi device isolation

VLANS are extremely useful in preventing groups of users from accessing each other and are recommended. For users within a VLAN, then firewall rules are useless. In the old way of WIFI one could use access lists ............... however all i can find on my hapax3 is clien-isolation. Here is a quote ...
by anav
Tue May 07, 2024 1:01 am
Forum: General
Topic: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client
Replies: 30
Views: 1020

Re: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client

Without seeing the complete config, hard to say
/export file=anynameyouwish (minus router serial number, any public WANIP informaiton, keys )
by anav
Mon May 06, 2024 11:40 pm
Forum: Beginner Basics
Topic: Port forwarding on RBwAPGR-5HacD2HnD&R11e-LTE6
Replies: 6
Views: 365

Re: Port forwarding on RBwAPGR-5HacD2HnD&R11e-LTE6

best to post your config thus far.


/export file=anynameyouwish ( minus router serial #, any public WANIP information, keys etc )
by anav
Mon May 06, 2024 10:42 pm
Forum: General
Topic: Prevent Port Scanners using PSD rule
Replies: 1
Views: 249

Re: Prevent Port Scanners using PSD rule

Dont waste your time.
Allow needed traffic
Drop all else.
If you are using VPN, you are fine.
by anav
Mon May 06, 2024 9:57 pm
Forum: General
Topic: Routing table mixed
Replies: 2
Views: 247

Re: Routing table mixed

Will need to some mangling and routes and tables.
by anav
Mon May 06, 2024 8:53 pm
Forum: General
Topic: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client
Replies: 30
Views: 1020

Re: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client

The problem is not MT centric its more like you dont understand how to setup WG period. ROUTER WIREGUARD SERVER FRIZBOX [Interface] PrivateKey = yLLoDlrjI8fLdv8KxoSvP9tbla8KY2Sqglua+bshJUE= ListenPort = 59162 Address = 10.3.1.1 /24 [Peer] PublicKey = 1/po8VJryRbMhluUbH8IU725lKsToVohwrma4uFDYio= Pres...
by anav
Mon May 06, 2024 7:58 pm
Forum: Beginner Basics
Topic: Forwarding ports
Replies: 15
Views: 1217

Re: Forwarding ports

I still see iPV6 lists and firewall rules LOL (2) what is the purpose of this rule.......... Lets get rid of it for now (DISABLE) /ip dns static add address=192.168.30.5 name=srv.lan ???? Also add this /ip dns set allow-remote-requests=yes servers =1.1.1.1 { unless using ISP dns, if so ignore the ad...
by anav
Mon May 06, 2024 7:11 pm
Forum: Beginner Basics
Topic: Wireguard setup Roadwarrior [SOLVED]
Replies: 14
Views: 735

Re: Wireguard setup Roadwarrior [SOLVED]

Overall dont see anything glaring. You have not made the changes I recommended in the first go around and I am not about to go through that again, suffice to say, they were not provided lightly and may help gain success. Once you fix those, then we can look at anything else that may be more obvious....
by anav
Mon May 06, 2024 7:06 pm
Forum: General
Topic: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client
Replies: 30
Views: 1020

Re: Configuration Issue Between FRITZ!Box WireGuard Server and MikroTik Client

We need to see the MT config and also understand how the users on the MT if any are being directed out the tunnel and why?
Requirements!! + Config, then we can assist on the proper config.
by anav
Mon May 06, 2024 5:58 pm
Forum: Beginner Basics
Topic: ISP CONFIGURATION [SOLVED]
Replies: 8
Views: 522

Re: ISP CONFIGURATION [SOLVED]

It seems to me, through my presence in this forum, that some, but not all, are aggressive in a very annoying way when asking any question, either because the Mikrotik OS is new to them, or they are new members and have forgotten that they are in a forum and the main goal is to help each other and e...
by anav
Mon May 06, 2024 5:56 pm
Forum: General
Topic: Need help to prepare for MTCNA exam
Replies: 2
Views: 277

Re: Need help to prepare for MTCNA exam

Wise advice!
If you need extra help..........
https://www.youtube.com/@MAICT
by anav
Mon May 06, 2024 4:15 pm
Forum: Beginner Basics
Topic: Forwarding ports
Replies: 15
Views: 1217

Re: Forwarding ports

(1) Why do you keep adding bridge to the interface lists....... its not required! /interface list member add interface=pppoe-wan list=WAN add interface=vlan1 list=LAN add interface=vlan2 list=LAN add interface=vlan3 list=LAN add interface=vlan99-work list=LAN add interface=vlan100-mgmt list=LAN add ...
by anav
Mon May 06, 2024 2:52 pm
Forum: Beginner Basics
Topic: Wireguard setup Roadwarrior [SOLVED]
Replies: 14
Views: 735

Re: Wireguard setup Roadwarrior [SOLVED]

Yes, the issue is you have a CGNAT connection. If your device was an arm,arm64,tile architecture one could also use the BTH VPN wireguard functionality (which would allow you to deal with the CGNAT shortcoming). The only other option I know of, but have not implemented is using IPV6 to do so. Snippe...
by anav
Mon May 06, 2024 3:32 am
Forum: Beginner Basics
Topic: Pinging the Wireguard client from the server host machine
Replies: 1
Views: 229

Re: Pinging the Wireguard client from the server host machine

Without a network diagram for starters, your explanation makes little sense.
Would also need configs to understand where there are issues.
by anav
Sun May 05, 2024 11:16 pm
Forum: Beginner Basics
Topic: ISP CONFIGURATION [SOLVED]
Replies: 8
Views: 522

Re: ISP CONFIGURATION [SOLVED]

Sure, I will direct you to the perfect spot to get support you need.
https://mikrotik.com/consultants
by anav
Sun May 05, 2024 5:44 pm
Forum: Beginner Basics
Topic: Help me improve
Replies: 2
Views: 305

Re: Help me improve

Which interface is this that is giving you errors on the bridge??? add bridge=bridge interface=*9 THis rule makes no sense as configured, why is it set to DROP?? add action=drop chain=forward comment="port forwarding" connection-nat-state=\ dstnat Three options make sense. a. one if you wa...
by anav
Sun May 05, 2024 5:41 pm
Forum: Beginner Basics
Topic: Forwarding ports
Replies: 15
Views: 1217

Re: Forwarding ports

Post complete config for review as previous.
by anav
Sun May 05, 2024 5:33 pm
Forum: Beginner Basics
Topic: Wireguard setup Roadwarrior [SOLVED]
Replies: 14
Views: 735

Re: Wireguard setup Roadwarrior [SOLVED]

The allowed IPs in the router setting ( for the peer windows client) is correct as is : /interface wireguard peers add allowed-address= 172.16.0.2/32 interface=wireguard1 public-key=\ "123123123123123123=" Concur on the client side device (windows10) allowed address should be: 192.168.1 .0...
by anav
Sat May 04, 2024 8:23 pm
Forum: Beginner Basics
Topic: Allow All Port Forwarding On Microtik Hap AC2
Replies: 15
Views: 701

Re: Allow All Port Forwarding On Microtik Hap AC2

Ahh okay, so basically default forward just means NO BSS blocking. All wired clients within a WLAN ( same SSID ) can reach/see each other..
by anav
Sat May 04, 2024 7:16 pm
Forum: Beginner Basics
Topic: Allow All Port Forwarding On Microtik Hap AC2
Replies: 15
Views: 701

Re: Allow All Port Forwarding On Microtik Hap AC2

So how is the user selecting the printer and printing???
by anav
Sat May 04, 2024 6:53 pm
Forum: Beginner Basics
Topic: Allow All Port Forwarding On Microtik Hap AC2
Replies: 15
Views: 701

Re: Allow All Port Forwarding On Microtik Hap AC2

All port forwarding is ridiculous. All you need is the IP address of the printer and the main port(s) the printer uses....... Need one port forwarding rule in forward chain.... add chain=forward action=accept connection-nat-state=dstnat THen need dstnat rules something like add chain=dstnat action=d...
by anav
Sat May 04, 2024 6:52 pm
Forum: Beginner Basics
Topic: How to allow traffic from outside WAN port on default RB750GR3
Replies: 7
Views: 484

Re: How to allow traffic from outside WAN port on default RB750GR3

Notepad ++ has the ability to compare two configs, very nice!!!
by anav
Sat May 04, 2024 4:07 pm
Forum: Beginner Basics
Topic: Wireless Wire not usable as AiMesh ethernet backhaul?
Replies: 1
Views: 230

Re: Wireless Wire not usable as AiMesh ethernet backhaul?

It should its basically a wifi ethernet cable concept.
by anav
Sat May 04, 2024 4:03 pm
Forum: General
Topic: [Help] VLAN Routing to VPN, with Local connections - Unusable performance when routing out Wireguard Interface
Replies: 7
Views: 494

Re: [Help] VLAN Routing to VPN, with Local connections - Unusable performance when routing out Wireguard Interface

Before I look at the config, what is the purpose of your management VLAN? If you want vlan10 and 99 to fully talk to each other drop vlan99 and keep vlan10. As for the other vlans, only the management vlan should really see all other vlans. All vlans should be able to access a shared printer. Do any...
by anav
Sat May 04, 2024 3:58 pm
Forum: General
Topic: Wireguard road warrior setup does not work under WiFi
Replies: 21
Views: 1251

Re: Wireguard road warrior setup does not work under WiFi

A whitelist to allow external WANIPs to connect to your wireguard port is not required. That is the purpose of the VPN connection. Only those with proper encrypted credentials will be able to connect and thus there is no need for a whitelist.
by anav
Sat May 04, 2024 2:48 am
Forum: General
Topic: Wireguard road warrior setup does not work under WiFi
Replies: 21
Views: 1251

Re: Wireguard road warrior setup does not work under WiFi

Wrong. There is no whitelist created by the wireguard interface??????\ By creating a wireguard interface and a wireguard IP address, one setups the possibility of a working wireguard structure. You still need the input chain rule to allow the handshake of clients to reach the router. You still need ...
by anav
Sat May 04, 2024 2:43 am
Forum: General
Topic: Strange issue with srd/dst address type 'local'
Replies: 4
Views: 920

Re: Strange issue with srd/dst address type 'local'

Id rather not play what if I do this or that on a config.............useless. Instead state reality and requirements a. identify user(s)/device(s) and groups of users/devices including yourself as admin b. identify what traffic they need to accomplish. The config will fall out naturally from well th...
by anav
Fri May 03, 2024 11:47 pm
Forum: Wireless Networking
Topic: Product Recommendation for Outdoor Mesh WiFi w/ Hotspot 2.0
Replies: 1
Views: 236

Re: Product Recommendation for Outdoor Mesh WiFi w/ Hotspot 2.0

For PTP I would look at --> https://mikrotik.com/product/wireless_w ... ifications --> gig link on 60Hz so no interference with other wifi.
MT does not make mesh systems for local distribution of wifi.
by anav
Fri May 03, 2024 11:43 pm
Forum: Beginner Basics
Topic: How to limit mac addresses to connect to Mikrotik 7.8
Replies: 4
Views: 386

Re: How to limit mac addresses to connect to Mikrotik 7.8

You can do that by only manually assigning DHCP leases I thought. Make use of ARP list etc.
by anav
Fri May 03, 2024 11:42 pm
Forum: Beginner Basics
Topic: Port forwarding trouble with PCC load balancing
Replies: 30
Views: 1978

Re: Port forwarding trouble with PCC load balancing

Ammo are you saying that for PPPOE one cannot decline the default route and use manual routes ???
Also if that is true then how do you manage check-gateway=ping on the main route ( is that available on the PPOE DHCP client settings somewhere)???
by anav
Fri May 03, 2024 7:14 pm
Forum: General
Topic: [Discussion] MikroTik configuration abstraction complexity
Replies: 95
Views: 7085

Re: [Discussion] MikroTik configuration abstraction complexity

Can be improved by AI.............. Will have to be as soon the DDOS attach will be AI run.
by anav
Fri May 03, 2024 5:37 pm
Forum: Beginner Basics
Topic: Port forwarding trouble with PCC load balancing
Replies: 30
Views: 1978

Re: Port forwarding trouble with PCC load balancing

Sounds more like a PPPOE ISP problem, perhaps they are blocking ICMP.
Otherwise out of ideas, perhaps someone else can do bettter.
by anav
Fri May 03, 2024 5:35 pm
Forum: General
Topic: Wireguard road warrior setup does not work under WiFi
Replies: 21
Views: 1251

Re: Wireguard road warrior setup does not work under WiFi

Then cannot help you.
I thought we were discussing using the wireguard on the MT router.
by anav
Fri May 03, 2024 4:37 pm
Forum: Beginner Basics
Topic: 1 wan for browsing, 1 wan for external services
Replies: 12
Views: 793

Re: 1 wan for browsing, 1 wan for external services

There are many ways to skin the cat as mkx and rextended say. :-) So yes, If you just have this, /ip firewall mangle add chain=prerouting src-address=192.168.X.X action=mark-routing new-routing-mark=WAN2 Any traffic from that LANIP should go out WAN2. That means ANY TRAFFIC!! Think about it. Also, Y...
by anav
Fri May 03, 2024 4:27 pm
Forum: Beginner Basics
Topic: How to limit mac addresses to connect to Mikrotik 7.8
Replies: 4
Views: 386

Re: How to limit mac addresses to connect to Mikrotik 7.8

Only give the SSID password to those that need it for any particular Subnet WLAN
by anav
Fri May 03, 2024 4:26 pm
Forum: Beginner Basics
Topic: Redirect streaming traffic to specific WAN in dual WAN configuration [SOLVED]
Replies: 5
Views: 626

Re: Redirect streaming traffic to specific WAN in dual WAN configuration [SOLVED]

Not a problem due to encryption and type of protocols used by modern sites, it is IMPOSSIBLE to do what you are asking. Cannot be done on APP basis. Thus for practical purpose I recommend have dedidcated subnets for such purposes. So you can have vlan10 wired for normal WAN traffic (WAN1) and vlan20...
by anav
Fri May 03, 2024 4:20 pm
Forum: Beginner Basics
Topic: Forwarding ports
Replies: 15
Views: 1217

Re: Forwarding ports

(1) The Management VLAN/SUBNET has no pool, no dhcp etc. Which makes sense if you are attempting to use the setup to config the router OFF the bridge and highly recommended. In this case, no VLAN is defined and ether 7 is NOT associated from the bridge. This is what I will show. (2) Dont need connec...
by anav
Fri May 03, 2024 3:43 pm
Forum: Beginner Basics
Topic: Port forwarding trouble with PCC load balancing
Replies: 30
Views: 1978

Re: Port forwarding trouble with PCC load balancing

This could be the error we were not seeing......... /ip address add address=172.16. 20 .1/16 comment=LAN interface=bridge-LAN network=\ 172.16. 0 .0 I think it should be: /ip address add address=172.16.20.1/16 comment=LAN interface=bridge-LAN network=\ 172.16.20.0 ???? I am not good with larger subn...
by anav
Fri May 03, 2024 3:39 pm
Forum: General
Topic: Setup Wireguard to use NextDNS
Replies: 2
Views: 271

Re: Setup Wireguard to use NextDNS

Are you saying next dns provides wg services?
by anav
Thu May 02, 2024 7:36 pm
Forum: Beginner Basics
Topic: RDP output
Replies: 2
Views: 262

Re: RDP output

Be advised RDP is not really concerned best practice as a security protocol.
by anav
Thu May 02, 2024 7:35 pm
Forum: General
Topic: Firewall rules for vlan not working
Replies: 2
Views: 268

Re: Firewall rules for vlan not working

Your setup is confused. One bridge, use three vlans. The subnet you make the bridge use, just change into another vlan, so we are simplifying the config. For the management subnet, just assign it directly to whatever port is called management, it would appear this is simply a backup off bridge confi...
by anav
Thu May 02, 2024 5:24 pm
Forum: Wireless Networking
Topic: hAP ax² 3 Vlans at internal Atenna
Replies: 51
Views: 2472

Re: hAP ax² 3 Vlans at internal Atenna

I was going to visit Croatia, but I am afraid I will not see any of the people. They will all be inside their houses trying to fix capsman on their home routers. Who will serve beer???
by anav
Thu May 02, 2024 5:19 pm
Forum: General
Topic: Wireguard road warrior setup does not work under WiFi
Replies: 21
Views: 1251

Re: Wireguard road warrior setup does not work under WiFi

The test should not be Laptop on LAN going out wifi to same router, The test should be like cellular, from a separate WAN source, like a friends house etc.. to the router in his house. The problem is that he can connect to his router via WG from his iphone from any cellular connection but never when...
by anav
Thu May 02, 2024 4:48 pm
Forum: General
Topic: How to block YouTube effectively
Replies: 37
Views: 2211

Re: How to block YouTube effectively

Education is what you need, MT wont replace parenting.
by anav
Thu May 02, 2024 4:46 pm
Forum: Beginner Basics
Topic: 1 wan for browsing, 1 wan for external services
Replies: 12
Views: 793

Re: 1 wan for browsing, 1 wan for external services

(1) Fix Interface List Members: /interface list member add comment=defconf interface=bridge list=LAN add comment=defconf interface=WAN1 list=WAN add interface=WAN2 list=WAN (2) Add some routing tables in case needed. /routing table add fib name=to-WAN1 add fib name=to-WAN2 (3) Why do you have IP DHC...
by anav
Thu May 02, 2024 3:22 pm
Forum: Beginner Basics
Topic: Unable to block YOUTUBE,FAEBOOK,...
Replies: 4
Views: 347

Re: Unable to block YOUTUBE,FAEBOOK,...

or the corporation uses edge routers or other internal routers with IDS services ( with ability to look at encrypted data )
by anav
Thu May 02, 2024 3:20 pm
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 1541

Re: wireguard with vlan bridge

Concur, it depends how many layers is 'enough' for the particular scenario.
by anav
Thu May 02, 2024 1:39 am
Forum: Beginner Basics
Topic: Port forwarding trouble with PCC load balancing
Replies: 30
Views: 1978

Re: Port forwarding trouble with PCC load balancing

What I would do is keep ether5 for off bridge configuration of the router, No need for DHCP pools, etc, just keep the IP address only and ensure its part of managment interface and LAN interface. Then just plug in PC or laptop change nic card ipv4 settings to an address within the range and you have...
by anav
Thu May 02, 2024 1:37 am
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 1541

Re: wireguard with vlan bridge

Your speaking gibberish. Wifi is not a thing, you have a number of vlans, those are real. If you mean vlan30 smarthome etc........ then of course anyone on that network has no capability to access the config nor should they. Folks should be in the managment vlan to do so. So what you are really sayi...
by anav
Wed May 01, 2024 11:23 pm
Forum: Beginner Basics
Topic: Port forwarding trouble with PCC load balancing
Replies: 30
Views: 1978

Re: Port forwarding trouble with PCC load balancing

Okay so that is much clearer, thanks! Ether2 is for a third wan connection but not in the mix at the moment. Ether3,4 not used. Ether5, separate subnet NOT on the bridge but part of the LAN overall. Ether6-10 WHERE IT GOES WRONG. First you should not attempt to have the bridge trying to give out DHC...
by anav
Wed May 01, 2024 10:01 pm
Forum: General
Topic: bridge stops forwarding traffic
Replies: 1
Views: 192

Re: bridge stops forwarding traffic

Why would you do anything on the bridge setup other than turn on vlan-filtering. Once you get cute you run into problems.
I see your routers are not for allowing traffic they are designed to block mac addresses primarily.
by anav
Wed May 01, 2024 9:27 pm
Forum: Beginner Basics
Topic: Port forwarding trouble with PCC load balancing
Replies: 30
Views: 1978

Re: Port forwarding trouble with PCC load balancing

Well your setup is wrong with regard to the LAN and vlans so PCC doesnt matter at all until the LAN is fixed. You are mixing up dhcp from bridge and then you have vlans going nowhere........ So Please be clear, What are your ports connected to. ether2 ( stand alone subnet not on the bridge )? ether3...
by anav
Wed May 01, 2024 8:42 pm
Forum: Wireless Networking
Topic: hAP ax² 3 Vlans at internal Atenna
Replies: 51
Views: 2472

Re: hAP ax² 3 Vlans at internal Atenna

Even better the config you make without capsman on the capac is IDENTICAL to the setup for the capsman AX, minor wifi setting difference but everything else the same. Copy and paste into terminal and go!

Oh my bad, you paid for the pain misery and frustration advice..... Enjoy! :-)
by anav
Wed May 01, 2024 8:40 pm
Forum: Wireless Networking
Topic: wifi-qcom(-ac) and VLAN-filtering
Replies: 17
Views: 1485

Re: wifi-qcom(-ac) and VLAN-filtering

My TP LINK oldie AP cant hold a candle to the AX3 LOL.
But I am thinking of getting a zyxel wifi 7 device.,
Fast roaming not required. Im in my own home, anything I do for serious is on the PC.
I dont run around the house trying to lose signal .........you guys crack me up
by anav
Wed May 01, 2024 7:41 pm
Forum: Wireless Networking
Topic: Wifi 7 - MikroTik when???
Replies: 79
Views: 16546

Re: Wifi 7 - MikroTik when???

?????????????
bbox.jpg
by anav
Wed May 01, 2024 7:38 pm
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 1541

Re: wireguard with vlan bridge

If you are authorized, should be able to connect through any interface I imagine...............
NO guarantees on anything when using unmanaged switch LOL.
by anav
Wed May 01, 2024 4:45 pm
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 1541

Re: wireguard with vlan bridge

Awesome, good catch, I thought I had found that earlier and thought I had put it in an earlier post but I often get distracted. :-(

add action=accept chain=input comment="Access for MGMT" in-interface-list=\
MGMT src-address-list=Authorize <---
by anav
Wed May 01, 2024 4:15 pm
Forum: Wireless Networking
Topic: Wifi 7 - MikroTik when???
Replies: 79
Views: 16546

Re: Wifi 7 - MikroTik when???

@PG, MT has been busy over the past (seems like a century) year or two, modernizing their WIFI setup in RoS and thus the transition for them to adopt WIFI7 should be relatively smooth.
by anav
Wed May 01, 2024 4:12 pm
Forum: Wireless Networking
Topic: wifi-qcom(-ac) and VLAN-filtering
Replies: 17
Views: 1485

Re: wifi-qcom(-ac) and VLAN-filtering

The day I enable capsman on any of my devices, means my brain has been taken over by fungi!
Vlan filtering works on any MT AP product just fine without out, and I still have all my hair!
by anav
Wed May 01, 2024 4:06 pm
Forum: Wireless Networking
Topic: hAP ax² 3 Vlans at internal Atenna
Replies: 51
Views: 2472

Re: hAP ax² 3 Vlans at internal Atenna

The beauty of simplicity, no capsman, works with any MT AP, the setup remains the SAME, regardless, ac, ax etc. !!
Gigabyte, I am just jealous of your capsman skills!
by anav
Wed May 01, 2024 4:00 pm
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 1541

Re: wireguard with vlan bridge

Nothing I can see......
by anav
Wed May 01, 2024 3:06 pm
Forum: Beginner Basics
Topic: Port forwarding trouble with PCC load balancing
Replies: 30
Views: 1978

Re: Port forwarding trouble with PCC load balancing

Not until you post a complete config, dont work from snippets
by anav
Tue Apr 30, 2024 11:35 pm
Forum: General
Topic: Advice on choosing WiFi equipment
Replies: 15
Views: 771

Re: Advice on choosing WiFi equipment

Yes freezing and thawing does wonders on ill constructed outdoor equip.
by anav
Tue Apr 30, 2024 11:05 pm
Forum: General
Topic: Advice on choosing WiFi equipment
Replies: 15
Views: 771

Re: Advice on choosing WiFi equipment

Im thinking of the pro cubes myself for a later project on my property. Easy way to get internet and thus wifi to another location.
by anav
Tue Apr 30, 2024 10:38 pm
Forum: General
Topic: Advice on choosing WiFi equipment
Replies: 15
Views: 771

Re: Advice on choosing WiFi equipment

You mean the same link from post #2 ?
by anav
Tue Apr 30, 2024 10:26 pm
Forum: Wireless Networking
Topic: hAP ax² 3 Vlans at internal Atenna
Replies: 51
Views: 2472

Re: hAP ax² 3 Vlans at internal Atenna

Have fun with capsman on this one LOL......... More hair pulled out, turned grey, whilst a non-capsman config is up and running in 15 minutes. :-P
Heck i could probably do it in 10 minutes if drunk.
by anav
Tue Apr 30, 2024 10:22 pm
Forum: Beginner Basics
Topic: Route specific sites and one IP Address through PIA VPN
Replies: 6
Views: 761

Re: Route specific sites and one IP Address through PIA VPN

yes that is required for third party vpn providers as they only expect to see at their end the IP address they gave you.
By using sourcenat all your users will have their IP converted to the wireguard IP when sent through the tunnel..
by anav
Tue Apr 30, 2024 6:48 pm
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 1541

Re: wireguard with vlan bridge

Not correct. If you are on behind your router instead of mac address type in the interface address you are on: 192.168.10.1 : winboxport and you should gain access to the config. Open winbox see the available devices down below and the IP address shown. Use that IPaddress and the winbox port as per ...
by anav
Tue Apr 30, 2024 4:11 pm
Forum: Beginner Basics
Topic: Wireguard client allow for all bridge subnets
Replies: 20
Views: 1502

Re: Wireguard client allow for all bridge subnets

Well it should connect. Perhaps the AP is not recognizing the client wireguard address as being "allowed"?
by anav
Tue Apr 30, 2024 4:02 pm
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 1541

Re: wireguard with vlan bridge

Why do you still have 0.0.0.0/0 , :00 Should be just 0.0.0.0/0 I meant the router config in code blocks LOL. Your wireguard should already be able to reach the router via winbox. Simply connect to the tunnel as you normally do. Then open winbox on the client device and at the top put the particulars...
by anav
Tue Apr 30, 2024 1:53 pm
Forum: Beginner Basics
Topic: Wireguard client allow for all bridge subnets
Replies: 20
Views: 1502

Re: Wireguard client allow for all bridge subnets

Not without the latest config
by anav
Tue Apr 30, 2024 1:51 pm
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 1541

Re: wireguard with vlan bridge

Post your config again but use code tags around it. The black square with white brackets inside it, on the same line as Bold and Underline etc....
by anav
Tue Apr 30, 2024 1:49 pm
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 1541

Re: wireguard with vlan bridge

Just 0.0.0.0/0 not sure what the other noise is after it.

Also missing persistent-keep-alive setting whatever it looks like on the client device.
by anav
Mon Apr 29, 2024 11:39 pm
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 1541

Re: wireguard with vlan bridge

But you are not connecting MT CHR? That is for a cloud server. You have your own MT and the user is connecting directly to the router. In any case those are generic instructions, I have provided the same info. What You need to provide is the client wireguard settings. Post it all but just use KKKKKK...
by anav
Mon Apr 29, 2024 9:41 pm
Forum: General
Topic: ONT - SWITCH - Router [SOLVED]
Replies: 3
Views: 532

Re: ONT - SWITCH - Router [SOLVED]

Best to listen to mkx the first time, will save you lots of grief LOL.
by anav
Mon Apr 29, 2024 9:38 pm
Forum: General
Topic: [Discussion] MikroTik configuration abstraction complexity
Replies: 95
Views: 7085

Re: [Discussion] MikroTik configuration abstraction complexity

Funny that, today I was watching one of my favourite youtube distractions, losing my self in the world of "Bald & Bankrupt" . Today I learned about Tajikistan! Good thing they left the USSR otherwise Voldemort would have pulled all the able bodied men to fight in Ukraine. https://www.y...
by anav
Mon Apr 29, 2024 9:36 pm
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 1541

Re: wireguard with vlan bridge

Dont understand this comment, can you explain in more detail please. under network adapters WG client NIC doesn't have GW set The WG client device needs the following Create a WG interface and provide a public key ) this key will go in the allowed IPs on the mikrotik device for peer public key Will ...
by anav
Mon Apr 29, 2024 9:25 pm
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 1541

Re: wireguard with vlan bridge

As I said, when you mess with standards ( trying to use an unmanaged switch for vlans ) results are not predictable and thus why I prefer not to get involved. Smarhome30 or vlan30 does not have internet because you didnt give it LAN membership!! /interface list member add interface=ether8-WAN-Static...
by anav
Mon Apr 29, 2024 9:23 pm
Forum: General
Topic: [Discussion] MikroTik configuration abstraction complexity
Replies: 95
Views: 7085

Re: [Discussion] MikroTik configuration abstraction complexity

@darknate: Resources: Engineering Management ( besides the academics of maths, physics, statistics-probability, electrical, programming, chemistry, drawing, thermodynamics etc...) All old text books circa 1980s LOL PRODUCTION/OPERATIONS MANAGEMENT : Concepts Structure & Analysis --> Richard J Te...
by anav
Mon Apr 29, 2024 8:36 pm
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 1541

Re: wireguard with vlan bridge

(1) For Allowed IPs for your remote peer client remove the unecessary stuff should look like. /interface wireguard peers add allowed-address=10.10.20.2/32 interface=wireguard1 public-key="hidden" (2) At client peer (at the client device ) for DNS put the interface of wireguard 10.10.20.1 (...
by anav
Mon Apr 29, 2024 8:05 pm
Forum: Beginner Basics
Topic: VPN - device routing
Replies: 6
Views: 692

Re: VPN - device routing

Without looking at your config, the problem I see is that your modem is giving you a private IP as a WAN address to the HEX, but then why do your LAN subnet devices have the same LAN structure??? modem=192.168. 2. 1 Hex WAN IP provided by modem is 192.168. 2 .5 makes sense! AppleTV=192.168. 2 .115 w...
by anav
Mon Apr 29, 2024 7:45 pm
Forum: General
Topic: Internal access to WAN connection over VLAN
Replies: 2
Views: 299

Re: Internal access to WAN connection over VLAN

Well without looking at the config, the VLAN is created at the switch and is solely for the purposes of moving the connection from ether7 to ether8. At the RB one simply terminates vlan90 on the incoming port Simply assign a vlan to the interface and in IP DHCPclient use vlan90 as the interface. You...
by anav
Mon Apr 29, 2024 7:41 pm
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 1541

Re: wireguard with vlan bridge

MODIFIED NAMES TO MAKE SENSE /interface ethernet set [ find default-name=ether1 ] comment="POE swith /wi-fi" name=ether1-LAN-Hybrid set [ find default-name=ether2 ] comment="proxmox" name=ether2-LAN-Hybrid set [ find default-name=ether3 ] comment="ABB IPS 2.1" name=ethe...
by anav
Mon Apr 29, 2024 6:29 pm
Forum: Beginner Basics
Topic: 1 wan for browsing, 1 wan for external services
Replies: 12
Views: 793

Re: 1 wan for browsing, 1 wan for external services

Provide a config so we can see the state of the setup so far.
/export file=anynameyouwish ( minus router serial number, any public WANIP information )
by anav
Mon Apr 29, 2024 6:25 pm
Forum: Beginner Basics
Topic: 1 wan for browsing, 1 wan for external services
Replies: 12
Views: 793

Re: 1 wan for browsing, 1 wan for external services

Yes distance is the easiest separator. One recommendation is to put the users and the servers on different subnets and then you simply need to use routing rules to force servers out WAN1. If not and they are all on one LAN subnet then you will need to mangle and use source-address lists to separate ...
by anav
Mon Apr 29, 2024 5:09 pm
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 1541

Re: wireguard with vlan bridge

STOP in the name ov coding And to innkeeping with your outstanding direction why is so hard for you not to use code tags which makes far easier to follow each of your coded step ... then perhap the people you are helping would follow your direction by also using code tags for their code :D [/quote] ...
by anav
Mon Apr 29, 2024 5:08 pm
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 1541

Re: wireguard with vlan bridge

Okay, so lets say the vlans are all visible on the unmanged switch, I can pretend that LOL. In any case the unmanaged switch needs to be passed as untagged and thus the port would have to be considered hybrid port. That is for ether1, what is the case for ether2 also appears to be asking for hybrid,...
by anav
Mon Apr 29, 2024 4:13 pm
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 1541

Re: wireguard with vlan bridge

I cannot guarantee success when out of my element....... same with capsman, IPV6 etc..............
by anav
Mon Apr 29, 2024 4:10 pm
Forum: General
Topic: Advice on choosing WiFi equipment
Replies: 15
Views: 771

Re: Advice on choosing WiFi equipment

Wow MT support has a help line for answering product questions?? Dont they normally say go talk to a dealer?
by anav
Mon Apr 29, 2024 4:08 pm
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 1541

Re: wireguard with vlan bridge

I cannot help further as I dont support using an unmanaged switch for multiple vlans. Hopefully somebody else will.
by anav
Mon Apr 29, 2024 2:23 pm
Forum: Beginner Basics
Topic: GrooveA as Wireguard client
Replies: 1
Views: 238

Re: GrooveA as Wireguard client

Why not!
Sounds like a good idea.....
by anav
Mon Apr 29, 2024 2:22 pm
Forum: Beginner Basics
Topic: Hex S run VPN as client for home network? [SOLVED]
Replies: 5
Views: 363

Re: Hex S run VPN as client for home network? [SOLVED]

Check tp-link forums.
by anav
Mon Apr 29, 2024 2:21 pm
Forum: Beginner Basics
Topic: 1 wan for browsing, 1 wan for external services
Replies: 12
Views: 793

Re: 1 wan for browsing, 1 wan for external services

Yes very easy. Make WAN2 Primary WAN, you can add wireguard to this so you can remote config the router. Can you confirm that WAN2 (gig) is a publicly reachable IP static or dynamic or the upstream router can port forward to it?? WAN1 will be secondary but the idea is to use routing rules to force t...
by anav
Mon Apr 29, 2024 2:17 pm
Forum: Beginner Basics
Topic: Hex S run VPN as client for home network? [SOLVED]
Replies: 5
Views: 363

Re: Hex S run VPN as client for home network? [SOLVED]

Normis is correct the hexS should be fine. Expect wireguard connectivity at least in the 100-200 range.
by anav
Mon Apr 29, 2024 2:15 pm
Forum: General
Topic: Winbox connection denied through VPN
Replies: 7
Views: 771

Re: Winbox connection denied through VPN

The fact that you have nothing at all that looks like the default firewall rules there are two possibilities a. you are very experienced and the rules are great and you dont need help b. you copied them from various places and really need lots of help. If it the latter case keep reading, if its a. t...
by anav
Mon Apr 29, 2024 2:09 pm
Forum: General
Topic: Multiple gateways in RouterOS 7.6
Replies: 4
Views: 540

Re: Multiple gateways in RouterOS 7.6

What happens if wan1 or wan2 is not available. Do you want for example for users on WAN2 to have access to WAN1? What happens if wan1 is down? What type of VPN do you have to remotely configure the router ( if the router has a publicly reachable IP, or the upstream router does and you can port forwa...
by anav
Mon Apr 29, 2024 2:07 pm
Forum: General
Topic: Advice on choosing WiFi equipment
Replies: 15
Views: 771

Re: Advice on choosing WiFi equipment

Best bet is 60HZ link. No interference from regular wifi. Its 1gig and just like an extended ethernet cable in function.
https://mikrotik.com/product/wireless_wire
https://mikrotik.com/product/wireless_wire_cube_pro
by anav
Mon Apr 29, 2024 2:00 pm
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 1541

Re: wireguard with vlan bridge

Since your text does not match reality and the config is mixed up. What is connected to each port ether1 ( unmanaged switch / managed switch / dumb AP / smart AP, dumb device like PC )? ether2 ( unmanaged switch / managed switch / dumb AP / smart AP, dumb device like PC )? ether3 ( unmanaged switch ...
by anav
Sun Apr 28, 2024 11:57 pm
Forum: Beginner Basics
Topic: 1 wan for browsing, 1 wan for external services
Replies: 12
Views: 793

Re: 1 wan for browsing, 1 wan for external services

What do you mean you............. Its the clients router so why do you need it for navigation?? by the way navigation means nothing to me, if you are asking about how to navigate in an airplane using the sun, moon or stars, that would make sense. :-) a. What does the client need in full detail. What...
by anav
Sun Apr 28, 2024 11:54 pm
Forum: General
Topic: Bringing my own router to work - idea validation
Replies: 5
Views: 639

Re: Bringing my own router to work - idea validation

First thing to do is check with the department or persons responsible for both IT and security to ensure that its within the rules of the company.
by anav
Sun Apr 28, 2024 11:53 pm
Forum: General
Topic: Wireguard road warrior setup does not work under WiFi
Replies: 21
Views: 1251

Re: Wireguard road warrior setup does not work under WiFi

Did you try a laptop with a wireguard client as well using same wifi, that would really narrow it down to the phone.
by anav
Sun Apr 28, 2024 11:52 pm
Forum: General
Topic: wireguard with vlan bridge
Replies: 39
Views: 1541

Re: wireguard with vlan bridge

What you would like is not a valid requirement, what is valid is what traffic your users and yourself as admin need. Thus the Wireguard IP is a unique IP address structure. Through firewall rules you can decide which if any wireguard remote users have access to the router for config purposes and to ...
by anav
Sun Apr 28, 2024 11:18 pm
Forum: General
Topic: Wireguard road warrior setup does not work under WiFi
Replies: 21
Views: 1251

Re: Wireguard road warrior setup does not work under WiFi

Well if it works on 5G then you know your router and phone are setup correctly.
Wondering if one has to do something different on the phone when connecting via WIFI, dont think so?
by anav
Sun Apr 28, 2024 4:33 pm
Forum: Beginner Basics
Topic: Route specific sites and one IP Address through PIA VPN
Replies: 6
Views: 761

Re: Route specific sites and one IP Address through PIA VPN

(1) This client peer allowed IPs settings makes little sense. As per the other remote users, there is no need for endpoint anything!! Assuming this is another router as you have the wireguard address and a subnet identified. Also the wireguard address in the allowed IPs for the remote router is wron...
by anav
Sun Apr 28, 2024 4:29 pm
Forum: Beginner Basics
Topic: Redirect streaming traffic to specific WAN in dual WAN configuration [SOLVED]
Replies: 5
Views: 626

Re: Redirect streaming traffic to specific WAN in dual WAN configuration [SOLVED]

Sorry you cannot effectively trap websites for streaming traffic.
What you can do is dedicate a subnet for streaming traffic or an SSID if doing it over wifi.
Then you can mangle that subnet or associated vlan to a specific WAN.
by anav
Sun Apr 28, 2024 3:19 pm
Forum: Beginner Basics
Topic: Can't seem to grasp WireGuard [SOLVED]
Replies: 5
Views: 541

Re: Can't seem to grasp WireGuard [SOLVED]

SKIP to 12 to fix your issue! or perhaps 4 is the problem? (1) The real crime in the nomenclature of your vlans, you have a,b,c but you assign them to vlans 10,30,20 lol, drive me nuts. :-) j/k (2) Problem here! You introduce two vlans that are NOT defined ??? They should be removed. /interface brid...
by anav
Sun Apr 28, 2024 2:43 pm
Forum: Beginner Basics
Topic: Issues with Configuring VLAN and LAN on the Same Port on RB5009 [SOLVED]
Replies: 5
Views: 437

Re: Issues with Configuring VLAN and LAN on the Same Port on RB5009 [SOLVED]

A bridge port can express 3 use cases. - trunk port carrying multiple vlans ( all tagged ) - an access port carrying one vlan ( untagged ) - a hybrid port carrying one vlan (untagged) and one or more vlans (tagged). In the case of trunk or hybrid the receiving device must be able to handle both tagg...
by anav
Sun Apr 28, 2024 2:40 am
Forum: Beginner Basics
Topic: Forwarding ports
Replies: 15
Views: 1217

Re: Forwarding ports

need to see full config
by anav
Sat Apr 27, 2024 8:42 pm
Forum: General
Topic: Load Balancing PPC (2WAN) not balancing well
Replies: 2
Views: 345

Re: Load Balancing PPC (2WAN) not balancing well

1. Dont need check-gateway=ping for the additional routes ( non-main routes) 2. You have to provide more detail. Is there any traffic directly to either WAN ( aka like wireguard connection )? 3. Do you have any servers on the LAN side, that external users need to reach and if so by one WAN? both WAN...
by anav
Sat Apr 27, 2024 7:53 pm
Forum: Beginner Basics
Topic: Sanity check for my VLAN setup and more
Replies: 4
Views: 393

Re: Sanity check for my VLAN setup and more

So in summary, the vlan1 thingy is normal and should be there. I have it in all my configs, not an issue. Dont try and get too fancy. :-) Your bridge vlan interface setup is not wrong, just not efficient as can be stated with less rules is all. Your real problem is that you need more wifi. You need ...
by anav
Sat Apr 27, 2024 7:50 pm
Forum: General
Topic: wireguard vpn client on mikrotik
Replies: 7
Views: 435

Re: wireguard vpn client on mikrotik

Okay you forgot to make some changes plus some more modifications. We should at least add default rules but for now no rules = everything passes so not in the way of success. (1) Lets keep DHCP server-network standard. /ip dhcp-server network add address=10.1.0.0/24 dns-server=10.1.0.254 gateway=10....
by anav
Sat Apr 27, 2024 6:24 pm
Forum: General
Topic: wireguard vpn client on mikrotik
Replies: 7
Views: 435

Re: wireguard vpn client on mikrotik

(1) Ether4 has an IP address and a Pool, but MISSING is dhcp server and dhcp-server network ????? (2) I gather you want all bridge traffic to go out internet on VPS. (3) On this note I would get rid of the static DNS setting and modify: from: /ip dns set allow-remote-requests=yes /ip dns static add ...
by anav
Sat Apr 27, 2024 5:44 pm
Forum: Beginner Basics
Topic: Sanity check for my VLAN setup and more
Replies: 4
Views: 393

Re: Sanity check for my VLAN setup and more

The only thing required on the bridge is to give it a name other, than bridge, if so inclined, and at some point change vlan-filtering to yes ( aka get rid of frame type setting and leave that to bridge ports, as you have done!! ) For each bridge port setting I also add ingress-filtering=yes Interfa...
by anav
Sat Apr 27, 2024 5:42 pm
Forum: Beginner Basics
Topic: Forwarding ports
Replies: 15
Views: 1217

Re: Forwarding ports

probably running into hairpin nat.
Are local router users trying to reach the server via its LANIP address or by some DYNDNS URL ( aka the WANIP ).
Should not affect external users ( did you test like with cell phone via cellular )?
by anav
Sat Apr 27, 2024 5:21 pm
Forum: General
Topic: Multiple default routes in main route table
Replies: 7
Views: 1922

Re: Multiple default routes in main route table

The reason for six rules ( actually only 3 default type routes using table main, the other three are routes that could pertain to mangling or routing rules. In your case you only have two WANS, and really one WAN at a time. The VPN is not a WAN exactly but you force vlan9 out the tunnel vice the loc...
by anav
Sat Apr 27, 2024 5:17 pm
Forum: General
Topic: Any solution for admit-only-VLAN-tagged misconfiguration
Replies: 16
Views: 797

Re: Any solution for admit-only-VLAN-tagged misconfiguration

Disagree because its mkx of course, if the WIreguard has access to the input chain, and not connected to the bridge in any way ( the main culprit in these things ), perhaps wireguard would not be affected.
by anav
Sat Apr 27, 2024 5:15 pm
Forum: General
Topic: wireguard vpn client on mikrotik
Replies: 7
Views: 435

Re: wireguard vpn client on mikrotik

After you provide your config I can comment constructively.
/export file=anynameyouwish ( minus router serial #, any public WANIP information, keys etc.)
by anav
Fri Apr 26, 2024 9:10 pm
Forum: Beginner Basics
Topic: I need so advice on VLANs for devices connecting only via 2.4GHz wifi:
Replies: 8
Views: 542

Re: I need so advice on VLANs for devices connecting only via 2.4GHz wifi:

All the control setup is done on the main router,
The second device acting solely as a swittch/AP has a minimal setup.
by anav
Fri Apr 26, 2024 9:09 pm
Forum: General
Topic: wireguard vpn client on mikrotik
Replies: 7
Views: 435

Re: wireguard vpn client on mikrotik

create wireguard interface, any port can be chosen. if you are given a private key put in the private key here before generating the interface or hitting apply Add wireguard interface to WAN interface list Add allowed IPs = 0.0.0.0/0 name of wireguard interface and endpoint address and endpoint port...
by anav
Fri Apr 26, 2024 7:32 pm
Forum: General
Topic: Get Two public IP on the same interface [SOLVED]
Replies: 23
Views: 934

Re: Get Two public IP on the same interface [SOLVED]

Ahh, single interface now thats challenging.......... But how is this different from any group of public IPs coming from a single provider over a single interface. Typically one uses one IP for the router and a second IP directly for a server for example. What to do if one wants to use them both for...
by anav
Fri Apr 26, 2024 6:35 pm
Forum: General
Topic: Get Two public IP on the same interface [SOLVED]
Replies: 23
Views: 934

Re: Get Two public IP on the same interface [SOLVED]

For whole subnets ( probably vlans ) it may be easiest to use routing rules and tables. The routes already shown above. /routing table add fib name=useWAN1 add fib name=useWAN2 /routing rules add action=lookup-in-table min-prefix=0 routing-table=main comment="ensures local traffic is permitted&...
by anav
Fri Apr 26, 2024 6:21 pm
Forum: General
Topic: Get Two public IP on the same interface [SOLVED]
Replies: 23
Views: 934

Re: Get Two public IP on the same interface [SOLVED]

The answer is not to make multiple bridges. Do you want subnets to equally access the available WANS, ( like in PCC load balance ) Do you want some subnets to go out WAN1 and some out WAN2 Do you have remote users coming in to LAN servers and if so over which WAN Do you have remote users coming in v...
by anav
Fri Apr 26, 2024 6:12 pm
Forum: General
Topic: Winbox connection denied through VPN
Replies: 7
Views: 771

Re: Winbox connection denied through VPN

The input chain should not be open to the internet except for handshaking for a VPN. ONe does not directly acccess winbox aka the router (input chain) for config purposes, instead you make the tunnel connection via VPN and then allow that vpn interface or subnet etc access the input chain. In other ...
by anav
Fri Apr 26, 2024 6:09 pm
Forum: General
Topic: simple 3 isp dhcp clients with aggregation
Replies: 21
Views: 3579

Re: simple 3 isp dhcp clients with aggregation

What you are saying makes little sense to me. First off VPN is for remote clients coming in on a particlular WAN OR VPN is going outbound to a third party provider. So I have no clue about why you would have VPN between vlan1 and vlan2 -- use firewall rules. Also, why is vlan2 not part of the LAN? S...
by anav
Fri Apr 26, 2024 5:58 pm
Forum: General
Topic: Any solution for admit-only-VLAN-tagged misconfiguration
Replies: 16
Views: 797

Re: Any solution for admit-only-VLAN-tagged misconfiguration

So no wireguard connectivity to the switch??
by anav
Fri Apr 26, 2024 5:57 pm
Forum: General
Topic: Get Two public IP on the same interface [SOLVED]
Replies: 23
Views: 934

Re: Get Two public IP on the same interface [SOLVED]

config??
by anav
Fri Apr 26, 2024 5:56 pm
Forum: General
Topic: Dual WAN - what setup is recommended? [SOLVED]
Replies: 4
Views: 601

Re: Dual WAN - what setup is recommended? [SOLVED]

sorry not familiar with ipv6 so cannot assist.
by anav
Fri Apr 26, 2024 12:45 am
Forum: Beginner Basics
Topic: Setting up Outline VPN on MikroTik Router
Replies: 1
Views: 346

Re: Setting up Outline VPN on MikroTik Router

suggest put shadowsocks into the Search window and hope for the best.
by anav
Thu Apr 25, 2024 11:47 pm
Forum: Beginner Basics
Topic: Dynamic port forwarding
Replies: 4
Views: 344

Re: Dynamic port forwarding

Why does a server go down? Makes no sense.
by anav
Thu Apr 25, 2024 11:45 pm
Forum: Beginner Basics
Topic: Eth1 vlan 911 tagging for ISP connection [SOLVED]
Replies: 21
Views: 1059

Re: Eth1 vlan 911 tagging for ISP connection [SOLVED]

You need to go to IP DHCP client next.....
and select vlan 911 as the interface ( not vlanfiber! )
by anav
Thu Apr 25, 2024 11:30 pm
Forum: Beginner Basics
Topic: Port forwarding trouble with PCC load balancing
Replies: 30
Views: 1978

Re: Port forwarding trouble with PCC load balancing

Most mods/changed............. /interface vlan add interface=bridge-LAN name=vlanbridge vlan-id=5 add interface=bridge-LAN name=vlan10-Ospiti vlan-id=10 add interface=bridge-LAN name=vlan11-IoT vlan-id=11 add interface=bridge-LAN name=vlan13-Inaffidabile vlan-id=13 /interface pppoe-client add add-de...
by anav
Thu Apr 25, 2024 11:11 pm
Forum: Beginner Basics
Topic: Port forwarding trouble with PCC load balancing
Replies: 30
Views: 1978

Re: Port forwarding trouble with PCC load balancing

Working on it, on ip routes at the moment. To gain better control visibility of routes, not using default routes in pppoe settings...
Its not clear to me if you wanted ether2 to be PCCd as well ?? Its a separate LAN but did you want it PCCd??
by anav
Thu Apr 25, 2024 8:30 pm
Forum: Beginner Basics
Topic: Port forwarding trouble with PCC load balancing
Replies: 30
Views: 1978

Re: Port forwarding trouble with PCC load balancing

Yup was just asking where the vlans went because it was a mystery LOL and your ether6 setting was misleading.. Since you have vpn connections coming to the router and also port forward to VLAN, and PCC you need three sets of mangles. One for VPN One of PF One for PCC Another issue I see is duplicate...
by anav
Thu Apr 25, 2024 4:55 pm
Forum: General
Topic: Mikrotik RB750gr3 wireguard issue
Replies: 6
Views: 552

Re: Mikrotik RB750gr3 wireguard issue

I cannot advise on a specific item until the config is fixed, and thus we can coherently address the requirement, in a logical manner. Thus my recommendation is to address the items noted, get rid of whats app for the moment, simplify all rules ( get rid of bridge filters and make firewal rules defa...
by anav
Thu Apr 25, 2024 4:53 pm
Forum: General
Topic: Multiple default routes in main route table
Replies: 7
Views: 1922

Re: Multiple default routes in main route table

That is not an example to use in any config, its generic. For example on a config the first three main routes should be separated by distance etc.. If you have a real config with real questions, then post your config and we can discuss your particular requirments - how many wans, - primary failover ...
by anav
Thu Apr 25, 2024 4:49 pm
Forum: General
Topic: Why Mikrotik decided to get rid of their Power Lan devices
Replies: 11
Views: 834

Re: Why Mikrotik decided to get rid of their Power Lan devices

There is no value added to go with MT in this case, and they have very little experience compared to companies like develo that have dedicated staff for these products.
If you dont believe me, thats okay but stop wasting time on speculation and write to mikrotik directly to get the answers you seek.
by anav
Thu Apr 25, 2024 4:45 pm
Forum: General
Topic: Security issue with DST NAT rules
Replies: 2
Views: 334

Re: Security issue with DST NAT rules

Zero trust cloudflare tunnel removes the need to open port is you can run it. Best bet is to create a source address list of allowed IPs, which renders ports invisible on scans, otherwise they are visible but closed on scans. Any server you have open should be encrypted access in some way shape or f...
by anav
Thu Apr 25, 2024 4:43 pm
Forum: General
Topic: Why Mikrotik decided to get rid of their Power Lan devices
Replies: 11
Views: 834

Re: Why Mikrotik decided to get rid of their Power Lan devices

Its a niche item, its has nothing to do with RoS and is best left to existing producers of stated products
by anav
Thu Apr 25, 2024 4:41 pm
Forum: General
Topic: SSTP Mikrotik Client / probably bug 6.41.3
Replies: 19
Views: 6905

Re: SSTP Mikrotik Client / probably bug 6.41.3

Between two MT devices, setting up SSTP without certificate was fairly easy, as a backup to wireguard.
Now I am inclined to use IP-IP tunnel using IPsec secret as an easy and more secure backup. So SSTP retired LOL.
by anav
Thu Apr 25, 2024 4:38 pm
Forum: Announcements
Topic: NEW FEATURE: Back to Home VPN
Replies: 300
Views: 248369

Re: NEW FEATURE: Back to Home VPN

My bad, I didnt realize that BTH was NOT possible to connect two routers that do not have publicly reachable IPs etc.. Its only valid for a router without a public IP and a remote device like phone.
by anav
Thu Apr 25, 2024 4:36 pm
Forum: Beginner Basics
Topic: Port forwarding trouble with PCC load balancing
Replies: 30
Views: 1978

Re: Port forwarding trouble with PCC load balancing

Many config errors, but conceptually the biggest problem so far is that you assign VLANS, but dont assign them to any ports. Why do you have them if they are not going to any ports? You dont assign vlans to vlan ids in /interface bridge vlans, you assign (tagged or untagged bridge or wlan ports) So ...
by anav
Thu Apr 25, 2024 12:56 pm
Forum: Beginner Basics
Topic: BTH between two mikrotik devices [SOLVED]
Replies: 9
Views: 545

Re: BTH between two mikrotik devices [SOLVED]

My bad Normis, I had never grasped this shortcoming. Why have you not programmed in both punching through CGNAT for example? Is this a future development or not possible? In this case one option is to rent a cloud server and put a CHR on it for example as the wireguard server, to act as the go betwe...
by anav
Thu Apr 25, 2024 2:41 am
Forum: Beginner Basics
Topic: I need so advice on VLANs for devices connecting only via 2.4GHz wifi:
Replies: 8
Views: 542

Re: I need so advice on VLANs for devices connecting only via 2.4GHz wifi:

If just starting out I do personally would stay away from capsman, it adds a layer of additional complexity that should only be tackled when more comfortable with RoS. Yes you can only use one vlan for 2.4 but then all users on that vlan will have access to each other. The idea is to create virtual ...
by anav
Wed Apr 24, 2024 11:00 pm
Forum: Beginner Basics
Topic: Helldivers 2 connection issues with Mikrotik configuration? [SOLVED]
Replies: 10
Views: 1344

Re: Helldivers 2 connection issues with Mikrotik configuration? [SOLVED]

First take any subnet off the bridge and create another vlan.
viewtopic.php?t=143620


State clearly the requirments
a. identify users/devices and groups of users/devices including admin
b. identify what traffic they should accomplish. Too confusing at the moment.
by anav
Wed Apr 24, 2024 10:21 pm
Forum: General
Topic: Mikrotik RB750gr3 wireguard issue
Replies: 6
Views: 552

Re: Mikrotik RB750gr3 wireguard issue

Your problem is not wireguard its the rest of the config. Too much noise, for me to look at that might interfere with a standard config. Why are you using bridge filters. Why is your config more about blocking vice focussing on only allowing needed traffic? Your dst nat rules are all wrong.............
by anav
Wed Apr 24, 2024 10:20 pm
Forum: General
Topic: Why Mikrotik decided to get rid of their Power Lan devices
Replies: 11
Views: 834

Re: Why Mikrotik decided to get rid of their Power Lan devices

I hear two tomato soup cans joined by twine, works well!
by anav
Wed Apr 24, 2024 10:19 pm
Forum: General
Topic: Multiple public IPs, different internal zones
Replies: 10
Views: 972

Re: Multiple public IPs, different internal zones

Now you are making less sense. Suggest a. full config /export file=anynameyouwish ( minus router serial number, any real public WANIP information, keys etc.) b. requirements without solutions i. identify all user(s)/devices(s) groups of users devices ii. identify all traffic they require. Include ad...
by anav
Wed Apr 24, 2024 10:14 pm
Forum: General
Topic: [solved] Dual-WAN PPPoE +DHCP (LAN clients on same VLAN split routing, no load balance)
Replies: 16
Views: 1470

Re: [solved] Dual-WAN PPPoE +DHCP (LAN clients on same VLAN split routing, no load balance)

I had no issues implementing this in winbox ???

Here is my export line, after doing so!
/routing rule
add action=lookup disabled=no min-prefix=0 table=main


The only thing I did was take the default rule already supplied and added at the very bottom: Min Prefix: 0 and hit apply.
by anav
Wed Apr 24, 2024 10:09 pm
Forum: General
Topic: Multiple public IPs, different internal zones
Replies: 10
Views: 972

Re: Multiple public IPs, different internal zones

So far all seems double but the problem I have is with your last zone. How do you propose to assign some users to 14, some to 15 and some to 16? We could do it with address lists I suppose but why the grouping. Why not zone3 to 14, zone4 to 15, and zone5 to 16 for example. OR Alternatively Share (lo...
by anav
Wed Apr 24, 2024 3:21 am
Forum: General
Topic: No DHCP on Bridge VLAN interface.
Replies: 21
Views: 1193

Re: No DHCP on Bridge VLAN interface.

Just confirms that capsman is not worth the stress it causes.
All my non-capsman MT APs, rarely change mostly setup and forget
by anav
Wed Apr 24, 2024 3:00 am
Forum: Beginner Basics
Topic: I need so advice on VLANs for devices connecting only via 2.4GHz wifi:
Replies: 8
Views: 542

Re: I need so advice on VLANs for devices connecting only via 2.4GHz wifi:

Yes, use all vlans vlan10 home vlan20 IOT devices 2ghz vlan25 IOT devices 5ghz vlan30 guest wifi let your imagination run wild... Vlan guide --> https://forum.mikrotik.com/viewtopic.php?t=143620 To setup vlan bridge filtering with minimal fuss take one port off the bridge and give it its own IP addr...
by anav
Wed Apr 24, 2024 2:48 am
Forum: General
Topic: Wireguard connection being dropped by firewall on new router, worked fine on old router with same settings.
Replies: 9
Views: 575

Re: Wireguard connection being dropped by firewall on new router, worked fine on old router with same settings.

RB5009 (home) /interface wireguard peers add allowed-address=172.16.0.0/24,192.168.32.2/32 interface=WG-5009 public key="***" comment="Work Router (L009)" add allowed-address=192.168.32.3/32 interface=WG-5009 public key="*+++" comment=RemoteUser1 add allowed-address=192...
by anav
Wed Apr 24, 2024 2:39 am
Forum: General
Topic: Wireguard connection being dropped by firewall on new router, worked fine on old router with same settings.
Replies: 9
Views: 575

Re: Wireguard connection being dropped by firewall on new router, worked fine on old router with same settings.

1. Do not require to masquerade your wireguard as you have both ends as MT devices and full control of rules and routes and allowed IP.s Remove the orange rule. /ip firewall nat add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=\ out,none out-interface-list=WAN ...
by anav
Wed Apr 24, 2024 2:11 am
Forum: General
Topic: Wireguard connection being dropped by firewall on new router, worked fine on old router with same settings.
Replies: 9
Views: 575

Re: Wireguard connection being dropped by firewall on new router, worked fine on old router with same settings.

Looking then at the L0009 ++++++++++ (1) Allowed IPs review. /interface wireguard peers add allowed-address=10.0.10.0/24,192.168.32.1/32,192.168.32.3/32 \ endpoint-address=174.126.54.183 endpoint-port=13231 interface=WG1 \ persistent-keepalive=25s public-key"=" a. I will assume that somewh...
by anav
Wed Apr 24, 2024 2:07 am
Forum: General
Topic: Wireguard connection being dropped by firewall on new router, worked fine on old router with same settings.
Replies: 9
Views: 575

Re: Wireguard connection being dropped by firewall on new router, worked fine on old router with same settings.

Well if you are using your phone to connect to the RB5009 which then allows you to connect to the L009, then you also need to post the 5009.
by anav
Tue Apr 23, 2024 11:30 pm
Forum: Beginner Basics
Topic: AP and Firewall [SOLVED]
Replies: 3
Views: 319

Re: AP and Firewall [SOLVED]

I would only ensure that the management VLAN has accces to config the AP.
I would also make it accessible on management VLAN via winbox.
by anav
Tue Apr 23, 2024 11:26 pm
Forum: Beginner Basics
Topic: Addlist/DNS Blocking Problem
Replies: 4
Views: 455

Re: Addlist/DNS Blocking Problem

We dont assume here we need facts!
by anav
Tue Apr 23, 2024 11:23 pm
Forum: Beginner Basics
Topic: WireGuard Config Issue
Replies: 4
Views: 433

Re: WireGuard Config Issue

I dont know what the problem is?? I didnt say to change the Wireguard IP address of your device? I clearly stated FIXING ALLOWED IPS ( IP autorises ) a. for wireguard address of the remote site/server for handshake put in 192.168.5.0/24 and also any remote subnet if applicable like 192.168.10.0/24. ...
by anav
Tue Apr 23, 2024 11:12 pm
Forum: General
Topic: Wireguard connection being dropped by firewall on new router, worked fine on old router with same settings.
Replies: 9
Views: 575

Re: Wireguard connection being dropped by firewall on new router, worked fine on old router with same settings.

Your wording and config is very confusing a network diagram would be good.
Its not clear to me which MT is at work and which is at home and which is acting as server for handshake.
by anav
Tue Apr 23, 2024 11:05 pm
Forum: General
Topic: Why Mikrotik decided to get rid of their Power Lan devices
Replies: 11
Views: 834

Re: Why Mikrotik decided to get rid of their Power Lan devices

Do you mean powerline devices ( ethernet over electrical circuits) or do you mean wifi devices capable of POE powering other devices??

IF the former, then these are apparently good --> https://www.devolo.global/products
by anav
Tue Apr 23, 2024 3:01 am
Forum: Beginner Basics
Topic: Wireguard client allow for all bridge subnets
Replies: 20
Views: 1502

Re: Wireguard client allow for all bridge subnets

Nope, just a first post process that eliminates 99% of the problems I see on initial posts and one of the points would be cleaning up disabled rules that have no purpose.
by anav
Tue Apr 23, 2024 2:58 am
Forum: General
Topic: Check Gateway ping failover not working for Provider
Replies: 4
Views: 367

Re: Check Gateway ping failover not working for Provider

A config is not snippets...... and not into chasing moving targets! Provide a network diagram ( should detail any vlans, WAN sources and type ( static,dynamic, public, not publice ) Provide a complete config Provide requirements a. identify all user(s)/device(s) and groups of users/devices including...
by anav
Tue Apr 23, 2024 2:06 am
Forum: Beginner Basics
Topic: Wireguard client allow for all bridge subnets
Replies: 20
Views: 1502

Re: Wireguard client allow for all bridge subnets

I want to see the config, warts and all LOL and it may provide OP intentions thus I dont favour your approach. I have no heartache with disabled rules that may have a purpose. Case in point. ( planning on port forwarding later ) add action=accept chain=forward comment="internet traffic" in...
by anav
Mon Apr 22, 2024 11:56 pm
Forum: Beginner Basics
Topic: Guest wifi on 2 Routers with the same ssid
Replies: 14
Views: 1223

Re: Guest wifi on 2 Routers with the same ssid

What is a tad frustrating is most of these changes, if not all, were already provided at Post #4 and yet you didn't implement them ???
by anav
Mon Apr 22, 2024 11:31 pm
Forum: Beginner Basics
Topic: Guest wifi on 2 Routers with the same ssid
Replies: 14
Views: 1223

Re: Guest wifi on 2 Routers with the same ssid

(1) Would ensure these are complete though........ Missing PVID!! add bridge=bridge ingress-filtering=yes frame-types=admit-priority-and-untagged interface=wlan1 pvid=2 add bridge=bridge ingress-filtering=yes frame-types=admit-priority-and-untagged interface=wlan2 pvid=2 (2) Then, you define wlan3 a...
by anav
Mon Apr 22, 2024 11:21 pm
Forum: Beginner Basics
Topic: Management VLAN issue [SOLVED]
Replies: 10
Views: 635

Re: Management VLAN issue [SOLVED]

Vlan-id of 1 Not the name but the actual ID. Nothing should get a vlan-id of 1 as that is a background default vlan id in most devices.
Leave it out of any data flow or any management vlan etc.... This also applies to MT, where the bridge uses it in the background already.
by anav
Mon Apr 22, 2024 10:08 pm
Forum: General
Topic: Help choosing the right device
Replies: 4
Views: 297

Re: Help choosing the right device

Hapax3
by anav
Mon Apr 22, 2024 8:58 pm
Forum: General
Topic: Help choosing the right device
Replies: 4
Views: 297

Re: Help choosing the right device

I cannot think of a single device MT makes that would provide reasonable signal throughout an entire house. In fact unless you get into special business class devices, its not something I would recommend. I would go one of two ways depending upon physical structures and device needs.... a. divide ho...
by anav
Mon Apr 22, 2024 8:55 pm
Forum: Beginner Basics
Topic: Management VLAN issue [SOLVED]
Replies: 10
Views: 635

Re: Management VLAN issue [SOLVED]

dont use vlan1 do use this guide for vlans - https://forum.mikrotik.com/viewtopic.php?t=143620 Your best bet to config bridge and vlans safely is to take one etherport off bridge lets say 10. Remove from bridge. Give it its own IP address 192.168.55.1/24 Add it to the management Interface. /interfac...
by anav
Mon Apr 22, 2024 8:47 pm
Forum: Beginner Basics
Topic: I have no idea how to setup my Mikrotik router
Replies: 4
Views: 363

Re: I have no idea how to setup my Mikrotik router

/The road to MT heaven unfortunately takes a winding path through hell :-) https://www.youtube.com/watch?v=2k6tFHDPUek https://www.youtube.com/watch?v=fv5h5EtFN2s (with vlans) Basically instead of the interface in the PPPOE client setting being ether1-wan, you select the vlan name assigned. The vlan...
by anav
Mon Apr 22, 2024 8:45 pm
Forum: Beginner Basics
Topic: Wireguard client allow for all bridge subnets
Replies: 20
Views: 1502

Re: Wireguard client allow for all bridge subnets

Hi Jaclaz, yes that is true.... Keep in mind that I read thoroughly all the configs, everytime I read a disabled rule that has no potential purpose I BARF, Its a distraction and a waste of my time, to read a cluttered config full of garbage. The cleaner and leaner the config, its easier for all to s...
by anav
Mon Apr 22, 2024 8:41 pm
Forum: General
Topic: [solved] Dual-WAN PPPoE +DHCP (LAN clients on same VLAN split routing, no load balance)
Replies: 16
Views: 1470

Re: [solved] Dual-WAN PPPoE +DHCP (LAN clients on same VLAN split routing, no load balance)

Often the case. Routing rules are powerful as they move all the traffic out that door............ so the trick when using them is to move other traffic first. Some chap (rplant) came up with a trick to do so, on a one liner, as the first rule in Routing Rules, which is pretty cool. /routing rule add...
by anav
Mon Apr 22, 2024 8:26 pm
Forum: General
Topic: WIREGUARD SERVER CLOUD GATEWAY WITH FAILOVER
Replies: 4
Views: 587

Re: WIREGUARD SERVER CLOUD GATEWAY WITH FAILOVER

(1) Remove pre-shared key in wireguard settings ( at both ends ) (2) You hardly have any firewall rules? Are you behind an upstream router with firewall rules?? Also your two rules are garbage if they are intended to handle wireguard. Since the MT is acting as a client for handshake, there is no nee...
by anav
Mon Apr 22, 2024 8:06 pm
Forum: Beginner Basics
Topic: Internet connection on CRS326 behind external router
Replies: 2
Views: 257

Re: Internet connection on CRS326 behind external router

Also be aware you are asking the CRS326 to perform routing functions and its a switch so not quite sure what performance will be realized. In terms of the upstream router and configuration. If the upstream router cannot read vlans sending it vlan99 would be a waste of time. The private WANIP, will b...
by anav
Mon Apr 22, 2024 7:59 pm
Forum: Beginner Basics
Topic: hEX S "RB760iGS" to hEX S "RB760iGS" sfp1 vlan trunk.
Replies: 2
Views: 223

Re: hEX S "RB760iGS" to hEX S "RB760iGS" sfp1 vlan trunk.

Concur, where is the internet?
Are they both acting as switches and thus where is the source of all the VLANs, upstream router?
You need to provide context, a network diagram for starters.
by anav
Mon Apr 22, 2024 7:55 pm
Forum: Beginner Basics
Topic: Wireguard client allow for all bridge subnets
Replies: 20
Views: 1502

Re: Wireguard client allow for all bridge subnets

When people get cute they run into issues... For example why do you have such a huge /22 network for the main subnet?? In any case, I think thats where you run into problems, overlap maybe?? (1) Try changing wireguard IP address to 192.168.80.1/24 interface=wireguard-vpn network=192.168.80.0 ( shoul...
by anav
Mon Apr 22, 2024 7:39 pm
Forum: Beginner Basics
Topic: Back to home Desktop
Replies: 4
Views: 372

Re: Back to home Desktop

For your first setup, use the phone. Then with the phone, use the "share" option in the BTH app and send the invitation to your Desktop PC (whatsapp, airdrop, email etc). In the Desktop PC you will need WireGuard application. you can import the shared Config file there
Nice trick.
by anav
Mon Apr 22, 2024 7:35 pm
Forum: Beginner Basics
Topic: WireGuard Config Issue
Replies: 4
Views: 433

Re: WireGuard Config Issue

Let say the router LAN is 192.168.10.0/24 FIXING Allowed IPs. ( IP autorises ) a. wireguard address should be in the format: 192.168.65. 0/24 b. LAN address of the remote subnet on the router also needs to be included: 192.168.10.0/24 c. If your goal is to provide internet access for remote users th...
by anav
Mon Apr 22, 2024 2:53 am
Forum: General
Topic: Back to Home Not Working on iPhone
Replies: 6
Views: 654

Re: Back to Home Not Working on iPhone

Ensure keys are correct,
by anav
Sun Apr 21, 2024 10:41 pm
Forum: Beginner Basics
Topic: Guest wifi on 2 Routers with the same ssid
Replies: 14
Views: 1223

Re: Guest wifi on 2 Routers with the same ssid

I have provided examples of complete configs, apply knowledge gained, make the effort yourself, and then post your config results.
  • 1
  • 2
  • 3
  • 4
  • 5
  • 66