Community discussions

MikroTik App

Search found 58 matches

by akakua
Wed May 01, 2024 2:41 pm
Forum: Wireless Networking
Topic: SA Query timeout
Replies: 67
Views: 14630

Re: SA Query timeout


No but I will have a go. Doesn't that reduce security?
sa query is part of protected management frames (802.11w), so you won't get any timeouts, if it disabled:)
by akakua
Tue Apr 30, 2024 6:37 pm
Forum: Wireless Networking
Topic: SA Query timeout
Replies: 67
Views: 14630

Re: SA Query timeout

has anyone tried to set "disabled" for management protection?
by akakua
Thu Apr 25, 2024 11:37 am
Forum: General
Topic: DHCP Relay in VRF
Replies: 5
Views: 2093

Re: DHCP Relay in VRF

I searched with no result - Maybe I look in the wrong direction :-|
Anybody found an "easy" way to add working dhcp relay to vrf-interfaces?

KR
https://help.mikrotik.com/docs/display/ ... cedin7.15)
by akakua
Mon Apr 15, 2024 3:17 pm
Forum: General
Topic: ROS Downgrade issue
Replies: 4
Views: 386

Re: ROS Downgrade issue

Where am I wrong?
you didn't read the log after reboot
by akakua
Thu Mar 21, 2024 5:28 pm
Forum: Wireless Networking
Topic: Mu-Mimo for cap ax
Replies: 2
Views: 444

Re: Mu-Mimo for cap ax

by akakua
Sun Mar 17, 2024 5:56 am
Forum: Wireless Networking
Topic: Can't use 80+80 or 160MHz WiFi channels [SOLVED]
Replies: 6
Views: 889

Re: Can't use 80+80 or 160MHz WiFi channels [SOLVED]

HAP AX³ supports a maximum channel width of 80 MHz.
by akakua
Sun Feb 18, 2024 5:05 am
Forum: Wireless Networking
Topic: hapax3 wifi 1 & 2 keep disconnecting
Replies: 1
Views: 368

Re: hapax3 wifi 1 & 2 keep disconnecting

Try to disable management protection
by akakua
Tue Dec 26, 2023 2:20 am
Forum: Wireless Networking
Topic: hap AX2: client connects and disconnects continously
Replies: 16
Views: 3456

Re: hap AX2: client connects and disconnects continously

try set "disabled" to "management protection"
by akakua
Tue Nov 21, 2023 11:36 am
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 94051

Re: v7.13beta [testing] is released!

On my RBD52G-5HacD2HnD and RB4011iGS+5HacQ2HnD with the wifi-qcom-ac package, I discovered that when the first user connects, the wireless interface goes through the RSTP listening and learning states, despite the Edge property being set to auto. In such a situation, you can forget about seamless ro...
by akakua
Mon Aug 21, 2023 2:21 pm
Forum: Forwarding Protocols
Topic: route print
Replies: 6
Views: 2432

Re: route print

/routing/route print detail
by akakua
Sat Aug 05, 2023 5:11 am
Forum: Beginner Basics
Topic: Ping not going outside of my vlans [SOLVED]
Replies: 15
Views: 2221

Re: Ping not going outside of my vlans [SOLVED]

Do you have routes to 172.16.10.0/28, 172.16.20.0/28, 172.16.30.0/24, 72.16.50.0/24 on router 192.168.1.1?
by akakua
Sat Jun 10, 2023 3:23 pm
Forum: General
Topic: One question on BCP L2 tunnel [SOLVED]
Replies: 6
Views: 1275

Re: One question on BCP L2 tunnel [SOLVED]

You can use l2tpv3.
by akakua
Thu Mar 23, 2023 2:14 pm
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 425
Views: 141422

Re: v7.8 [stable] is released!

Hardware offload does not work in bridge - ports on hAP ax3
Check the list of switch chips that supports hardware offloading - https://help.mikrotik.com/docs/display/ ... Offloading
by akakua
Mon Mar 06, 2023 3:32 pm
Forum: General
Topic: Internal Bridge Routing Help
Replies: 4
Views: 419

Re: Internal Bridge Routing Help

Just set the following addresses:
Bridge1: 192.168.222.1/24
Bridge2: 192.168.48.1/22
by akakua
Tue Feb 07, 2023 9:38 am
Forum: Beginner Basics
Topic: How to configure identical VLAN on different ports on the same bridge?
Replies: 3
Views: 2302

Re: How to configure identical VLAN on different ports on the same bridge?

But if I still wanted to, how would one go about fixing this problem above?
quote tdw
You could change from RSTP to MSTP, which supports different groups of VLANs on parallel paths, disable spanning tree entirely, or bond the interfaces together as best fits your setup.
by akakua
Tue Jan 24, 2023 6:26 pm
Forum: General
Topic: bandwidth speed limit for range ip ( from 20 to 80)
Replies: 6
Views: 1299

Re: bandwidth speed limit for range ip ( from 20 to 80)

you can specify a mask instead of an address. for example 192.168.88.0/26, so the queue will cover the range 192.168.88.0-192.168.88.63
by akakua
Wed Dec 28, 2022 2:30 pm
Forum: Beginner Basics
Topic: RB4011iGS+5HacQ2HnD-IN - IPoE - SFP
Replies: 7
Views: 803

Re: RB4011iGS+5HacQ2HnD-IN - IPoE - SFP

You bought an ethernet SFP module, but your isp uses gpon.
by akakua
Sun Dec 04, 2022 3:41 pm
Forum: Beginner Basics
Topic: Interface vs Port In Mikrotik Router
Replies: 4
Views: 798

Re: Interface vs Port In Mikrotik Router

Port - L2
Interface - L3
by akakua
Thu Nov 24, 2022 4:18 am
Forum: General
Topic: Firewall Help Please
Replies: 3
Views: 388

Re: Firewall Help Please

/ip firewall filter add action=drop chain=forward connection-state=new out-interface=ether1 src-address=192.0.0.0/24 place-before=0
by akakua
Mon Nov 21, 2022 1:56 pm
Forum: Beginner Basics
Topic: problem with my attemps to block youtube users [SOLVED]
Replies: 11
Views: 1445

Re: problem with my attemps to block youtube users [SOLVED]

Youtube uses QUIC protocol, not HTTPS.
by akakua
Tue Nov 01, 2022 2:01 pm
Forum: General
Topic: Can't get IPv6 SLAAC on router under another router
Replies: 10
Views: 2293

Re: Can't get IPv6 SLAAC on router under another router

Set on "client router" -
ipv6/settings/set accept-router-advertisements=yes
by akakua
Sat Oct 29, 2022 9:05 am
Forum: Forwarding Protocols
Topic: RouterOS 7 OSPF filters question
Replies: 2
Views: 1420

Re: RouterOS 7 OSPF filters bug ?

Be aware that the default action of the routing filter chain is "reject"

https://help.mikrotik.com/docs/display/ ... nd+Filters
by akakua
Sat Oct 22, 2022 4:01 pm
Forum: General
Topic: CCR2004 - Vlans [SOLVED]
Replies: 11
Views: 1987

Re: CCR2004 - Vlans [SOLVED]

by akakua
Thu Oct 20, 2022 7:33 pm
Forum: General
Topic: VLAN Bridge over Bond not working
Replies: 5
Views: 931

Re: VLAN Bridge over Bond not working

If you need to use one interface(ether or bond) with vlans, just set on it vlan interfaces. If you need trunk vlans between ports of the router - use bridge with vlan filtering.
by akakua
Thu Oct 20, 2022 7:19 pm
Forum: General
Topic: dns doesn't work with management vrf
Replies: 4
Views: 1381

Re: dns doesn't work with management vrf

Just use main as mgmt.
by akakua
Thu Oct 20, 2022 4:27 pm
Forum: General
Topic: VLAN Bridge over Bond not working
Replies: 5
Views: 931

Re: VLAN Bridge over Bond not working

https://help.mikrotik.com/docs/display/ ... interfaces
Enlighten yourself.
I gave you the config, just use it.
by akakua
Thu Oct 20, 2022 12:00 pm
Forum: General
Topic: VLAN Bridge over Bond not working
Replies: 5
Views: 931

Re: VLAN Bridge over Bond not working

Try to delete this weird vlan interface\bridge interface thing and use this config /interface bridge add name=bridge_VF vlan-filtering=yes /interface bridge port add bridge=bridge_VF interface=bond1 add bridge=bridge_VF interface=bond2 /interface bridge vlan add bridge=bridge_VF tagged=bridge_VF,bon...
by akakua
Mon Oct 17, 2022 10:09 am
Forum: Beginner Basics
Topic: Winbox do not show IPv6 neighbors
Replies: 9
Views: 4187

Re: Winbox do not show IPv6 neighbors

I checked on several PCs and found on all of them that only one ip interface listens to multicast [FF02::1]:5678 when I use winbox. For example, if a PC has a wireless and wired interface, it can only listen on the wireless interface, and if you connect to the Mikrotik via cable, then the router in ...
by akakua
Sun Oct 16, 2022 8:13 am
Forum: Scripting
Topic: Block dynamic ip in dhcp leases (Script)
Replies: 2
Views: 663

Re: Block dynamic ip in dhcp leases (Script)

ip dhcp-server set dhcp1 address-pool=static-only
by akakua
Wed Sep 28, 2022 12:38 pm
Forum: General
Topic: Feature requests
Replies: 1744
Views: 642262

Re: Feature requests

Create dynamic vlan entry with added tagged bridge to it in "interface/bridge/vlan/" when i set interface vlan on bridge with vlan filtering enabled, like you alredy doing it with pvid.
by akakua
Wed Sep 14, 2022 7:12 pm
Forum: General
Topic: Layer7 DoH blocking [SOLVED]
Replies: 7
Views: 2220

Re: Layer7 DoH blocking [SOLVED]

Answer why you use doh as domain name resolver - this will be reason.
by akakua
Sat Jul 30, 2022 4:33 pm
Forum: Beginner Basics
Topic: Accessing my Switch via VLAN
Replies: 22
Views: 1949

Re: Accessing my Switch via VLAN

/interface bridge vlan add bridge=bridge tagged="bridge,ether24_opnsense2,ether23_opnsense1,ether21_SynoBond\ 1,sfp-sfpplus3_proxmox,sfp-sfpplus1_wifi" untagged=\ ether2_nosbox,ether3_IPMI-edgebox,ether1_edgebox vlan-ids=10 add bridge=bridge tagged="bridge,ether24_opnsense2,ether23_o...
by akakua
Sat Jul 30, 2022 2:11 pm
Forum: Beginner Basics
Topic: Accessing my Switch via VLAN
Replies: 22
Views: 1949

Re: Accessing my Switch via VLAN

Do you have route on switch to vlan networks?
by akakua
Tue May 17, 2022 6:52 pm
Forum: Beginner Basics
Topic: Lost "Management VLAN" access to switches [SOLVED]
Replies: 6
Views: 1476

Re: Lost "Management VLAN" access to switches [SOLVED]

Routes on switches?
by akakua
Fri May 13, 2022 9:22 am
Forum: General
Topic: Download traffic is not showing on Interface!
Replies: 21
Views: 2140

Re: Download traffic is not showing on Interface!

You can ask them to give you control of the entire 56.56.56.0/27 network and create second /29 network between ESXi and their router. You must set second IP on interface ether1 of CHR from the /29 network and set a default route via IP address from the /29 network of their router. They must set the ...
by akakua
Thu May 12, 2022 8:56 pm
Forum: General
Topic: Download traffic is not showing on Interface!
Replies: 21
Views: 2140

Re: Download traffic is not showing on Interface!

I think all devices are on the same network. when the server sends data to its gateway on .3, then chr forwards it to its gateway .1 (this explains the rx tx rate in the upload test) the response is returned directly via .1 to the server (this explains the rx tx rate in the download test)
by akakua
Thu May 12, 2022 8:19 pm
Forum: General
Topic: Download traffic is not showing on Interface!
Replies: 21
Views: 2140

Re: Download traffic is not showing on Interface!

What netmasks is used for ip interfaces of mikrotik chr and main gateway of server?
by akakua
Fri May 06, 2022 5:40 pm
Forum: General
Topic: How can i block this type of attack ?
Replies: 12
Views: 2489

Re: How can i block this type of attack ?

does ptpp have vulnerabilities (not mitm attacks, because the guys from the log are not capable of this) that allow you to take over the server or log in to it without a login and password?
by akakua
Fri May 06, 2022 5:21 pm
Forum: General
Topic: How can i block this type of attack ?
Replies: 12
Views: 2489

Re: How can i block this type of attack ?

You can use whitelist or port knocking. Or you can use strong usernames and passwords and just ignore this messages.
by akakua
Wed May 04, 2022 5:39 pm
Forum: General
Topic: Can't access router after downgrade
Replies: 10
Views: 1021

Re: Can't access router after downgrade

At least you can connect via serial port and do some diagnostic. Maybe need to upgrade routerboard?
by akakua
Fri Apr 22, 2022 6:08 am
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 104922

Re: v7.3beta [testing] is released!

What's new in 7.3beta34 (2022-Apr-20 08:23): *) bgp - improved stability when editing BGP template; *) ccr - added "passthrough" flag for interfaces on CCR2004-1G-2XS-PCIe; *) dhcpv4-server - added "age" parameter for dynamic leases; *) dhcpv4-server - fixed minor logging typo; ...
by akakua
Fri Aug 27, 2021 7:21 am
Forum: RouterOS beta
Topic: v7.1rc1 [development] is released!
Replies: 344
Views: 78678

Re: v7.1rc1 [development] is released!

hw-offload=yes means that this rule can be offloaded to hardware, as long as it supports offloading.
Thank you so much, now everything has become clear. Can you tell me where can I find more information about the Firewall hardware offloading implementation in RouterOS?
by akakua
Fri Aug 27, 2021 6:56 am
Forum: RouterOS beta
Topic: v7.1rc1 [development] is released!
Replies: 344
Views: 78678

Re: v7.1rc1 [development] is released!

Airtime fairness is enabled by default for wifiwave2 interfaces. What about WMM support in wifiwave2? I discovered that the fasttrack-conection rule of default firewall on my RB951G-2HnD changed, now it looks like this: ip firewall filter add action=fasttrack-connection chain=forward comment="...
by akakua
Sat Jul 24, 2021 7:31 pm
Forum: Beginner Basics
Topic: Which FW rule permits 'services'
Replies: 9
Views: 1567

Re: Which FW rule permits 'services'

A rule without context is not much help. Questions - "Which FW rule permits 'services'" and "Could someone explain to me where is the corresponding INPUT rule for the 'services' to be accepted by the firewall?" Answer - "/ip firewall filter add action=drop chain=input comme...
by akakua
Sat Jul 24, 2021 5:42 pm
Forum: Beginner Basics
Topic: Which FW rule permits 'services'
Replies: 9
Views: 1567

Re: Which FW rule permits 'services'

/ip firewall filter add action=drop chain=input comment="Input drop all not coming from LAN" in-interface-list=!LAN
by akakua
Sun May 02, 2021 6:35 am
Forum: Scripting
Topic: How to completely prohibit winbox from logging in with MAC address, [SOLVED]
Replies: 2
Views: 1727

Re: How to completely prohibit winbox from logging in with MAC address, [SOLVED]

/tool mac-server set allowed-interface-list=none
/tool mac-server mac-winbox set allowed-interface-list=none
/tool mac-server ping set enabled=no
by akakua
Tue Feb 23, 2021 5:00 am
Forum: Beginner Basics
Topic: Basic routing
Replies: 11
Views: 1624

Re: Basic routing

/ip firewall nat add action=masquerade chain=srcnat out-interface="VLAN1425"
by akakua
Mon Feb 22, 2021 4:20 am
Forum: Beginner Basics
Topic: Basic routing
Replies: 11
Views: 1624

Re: Basic routing

If they give you IP address in network 172.16.10.0/24, then you can do "masq" to interface cam vlan, but if you need real routing, then ask your ISP to add static route to your local network (192.168.1.0/24) on gateway of cams network (172.16.10.0/24) (they never do that)
by akakua
Sat Feb 06, 2021 9:11 am
Forum: General
Topic: STATIC ROUTE NOT WORKING TROUGH VPN [SOLVED]
Replies: 2
Views: 1002

Re: STATIC ROUTE NOT WORKING TROUGH VPN [SOLVED]

Add static route to 172.16.50.0 on router A.
by akakua
Sun Jul 19, 2020 7:12 am
Forum: General
Topic: help locating/identifying unknown Mikrotik device
Replies: 5
Views: 3195

Re: help locating/identifying unknown Mikrotik device

I just noticed that I have a Mikrotik device appearing in my DHCP table. As far as I knew: 1. I only had two Mikrotik devices on-site. 2. Both were not connected. 3. Both were assigned static IPs when in use (prior to disconnection). I've tried: 1. Connecting to the IP address of this device, and I...