Community discussions

MikroTik App

Search found 104 matches

by DL7JP
Sun May 12, 2024 2:53 pm
Forum: General
Topic: VLAN distribution over bridges / basic VLAN configuration hints
Replies: 7
Views: 299

Re: VLAN distribution over bridges / basic VLAN configuration hints

Good point. If I power the Router on port 13 over PoE from the Switch, the switch should also be down if the router is. Unless the router fails internally... will think about it. I will change it to a single bridge concept: - port1 connects VLAN 1, 15 , 25 to the switch - port 2-5 have untagged VLAN...
by DL7JP
Sun May 12, 2024 2:08 pm
Forum: General
Topic: VLAN distribution over bridges / basic VLAN configuration hints
Replies: 7
Views: 299

Re: VLAN distribution over bridges / basic VLAN configuration hints

Hm ... what do you mean? I only found "The bypass switch allows binding ports 11 and 12 together in bypass mode, which means that if the device loses power, the ports will be connected together, allowing data pass from one port to the other, as if the device would not be there." in the doc...
by DL7JP
Sun May 12, 2024 1:11 pm
Forum: General
Topic: VLAN distribution over bridges / basic VLAN configuration hints
Replies: 7
Views: 299

Re: VLAN distribution over bridges / basic VLAN configuration hints

Thanks a bunch, these are useful hints! Indeed, PoE in is only on Port 13, and this is on a switch chip with only 3 ports (11,12,13). I think I will change it as follows: eth1 -> 12, eth2 -> 13 (VoIP also goes into the switch), eth13 -> 1. Bridge-ISP and Bridge-LAN will then be on different switch c...
by DL7JP
Sun May 12, 2024 1:08 am
Forum: General
Topic: VLAN distribution over bridges / basic VLAN configuration hints
Replies: 7
Views: 299

VLAN distribution over bridges / basic VLAN configuration hints

Dear all, I decided to reconfigure my home network from scratch, it grew and grew over the last 10 years and became overly complex. Complexity is the worst enemy of security ;-). Attached is the plan: My ISP delivers VLAN 50 that assigns one public IP, and VLAN 40 for one IP for a VoIP client. Inter...
by DL7JP
Thu Mar 14, 2024 1:32 pm
Forum: Announcements
Topic: SwOS version 2.16 released!
Replies: 46
Views: 44243

Re: SwOS version 2.16 released!

It automagically was fixed on my switch ;-) ... today it showed 2.16 rather than 2.17rc2 as latest avail version, and I upgraded from 2.13 w/o problems.
by DL7JP
Sat Mar 02, 2024 11:53 pm
Forum: Announcements
Topic: SwOS version 2.16 released!
Replies: 46
Views: 44243

Re: SwOS version 2.16 released!

> The SwOS updates via your browser, not directly from the swich as far that I'm aware

Thanks for your answer! I updated a CRS328-24P-4S+ via Download & Upgrade, so this should actually work.
by DL7JP
Sat Mar 02, 2024 10:33 pm
Forum: Announcements
Topic: SwOS version 2.16 released!
Replies: 46
Views: 44243

Re: SwOS version 2.16 released!

I am confused by this update: See attached what the SwOS UI of a CRS354-48G-4S+2Q+ shows: System is up to date with 2.13, but also the Changelog of 2.16 is shown. Also 2.17rc2 is listed as the latest available version. If I click on download and upgrade, I get "ERROR: Could not retrieve firmwar...
by DL7JP
Fri Mar 01, 2024 8:48 pm
Forum: Announcements
Topic: v7.14.3 [stable] is released!
Replies: 641
Views: 182514

Re: v7.14 [stable] is released!

Updated RB1100AHx4, RB2011iL, CRS125-24G-1S, hAP ac^2 and hAP ac from 7.13.5 to 7.14. w/o problems; the first three run Wireguard, all fine, nothing unusual in the logs.
by DL7JP
Sat Oct 22, 2022 4:26 pm
Forum: Announcements
Topic: v7.6 [stable] is released!
Replies: 279
Views: 143774

Re: v7.6 [stable] is released!

RB1100AH, CRS125-24G, hAP ac, hAP ac^2, CCR2004-16G: Upgraded, no problems noticed.
by DL7JP
Fri Sep 02, 2022 2:10 pm
Forum: Announcements
Topic: v7.5 [stable] is released!
Replies: 219
Views: 70197

Re: v7.5 [stable] is released!

All devices with ARM cpu's are coming up at the wrong frequency after the 7.4.1 to 7.5 upgrade. You see this in the System / RouterBOARD menu. A warning appears that the cpu is not running at the default frequency. Clicking on the "Settings" button, you see it is incorrectly set to 716MHz...
by DL7JP
Wed Aug 31, 2022 4:47 pm
Forum: Announcements
Topic: v7.5 [stable] is released!
Replies: 219
Views: 70197

Re: v7.5 [stable] is released!

CRS125-24G, hAP ac, hAP ac^2, CCR2004-16G: Upgraded, no problems noticed.
by DL7JP
Fri Jul 22, 2022 2:22 am
Forum: General
Topic: RouterOS 7.1.5. "long-term": dead end?
Replies: 73
Views: 10545

Re: RouterOS 7.1.5. "long-term": dead end?

Well, v7 was so far simply a nightmare for customers and probably ruined quite a bit of Mikrotik's reputation. Can you imagine: I ran dozens of v6 "stable" routers on auto-update for years, just once some wireless links broke due to changes in frequency allocations of regulatory domains. I...
by DL7JP
Wed Jul 20, 2022 7:08 pm
Forum: General
Topic: RouterOS 7.1.5. "long-term": dead end?
Replies: 73
Views: 10545

Re: RouterOS 7.1.5. "long-term": dead end?

I just moved 4 non-critical routers 7.1.5 -> 7.4. Suprisingly, they all survived it.
by DL7JP
Wed Jul 20, 2022 6:36 pm
Forum: General
Topic: RouterOS 7.1.5. "long-term": dead end?
Replies: 73
Views: 10545

Re: RouterOS 7.1.5. "long-term": dead end?

OK, so versions showing up in the long-term channel might or might not be long-term. My bad, I guess I should have known this...
by DL7JP
Wed Jul 20, 2022 6:11 pm
Forum: General
Topic: RouterOS 7.1.5. "long-term": dead end?
Replies: 73
Views: 10545

Re: RouterOS 7.1.5. "long-term": dead end?

That is correct, there NEVER HAS BEEN a version 7 Long Term software/firmware offering yet.

Furthermore the latest Stable Version is 7.4, if you want use vers7.
Well, 7.1.5 was definitely offered in the long-term channel in early June. This is why I installed it.
by DL7JP
Wed Jul 20, 2022 5:39 pm
Forum: General
Topic: RouterOS 7.1.5. "long-term": dead end?
Replies: 73
Views: 10545

RouterOS 7.1.5. "long-term": dead end?

Dear all, about 6 weeks ago I moved most of my routers from 7.2.3 to 7.1.5, which was offered in the "long-term" channel. The the hope was to avoid crashed routers when updating in the (not so...) "stable" channel.
Now I get this. Can some kind soul explain what's going on here?
by DL7JP
Wed Apr 06, 2022 12:48 am
Forum: Announcements
Topic: v7.2 is released!
Replies: 359
Views: 62521

Re: v7.2 is released!

Upgraded RB1100AHx4, RB2011iL, CRS125-24G, cAP Lite, hAP ac, hAP ac^2 and mAP lite without problems.
by DL7JP
Sun Apr 03, 2022 2:05 am
Forum: General
Topic: Wireguard peer interface irregularly stop working
Replies: 66
Views: 18169

Re: Wireguard peer interface irregularly stop working

[/quote]
Well for morons like me that have very little exposure to anything other than a home network, we need eXtra help!
[/quote]

To confuse you even more ;-), WAN2 in your picture is actually https://hamnetdb.net/map.cgi - a (sort of) parallel version of the public internet.
by DL7JP
Sat Apr 02, 2022 11:58 pm
Forum: General
Topic: Wireguard peer interface irregularly stop working
Replies: 66
Views: 18169

Re: Wireguard peer interface irregularly stop working

Your diagram is not helpful and I would say adds to the confusion, as it show no etherport being connected external to the router.


You're right, the picture is now clearer. If you are in your own setup, you don't see the problems others might have to understand it.
by DL7JP
Sat Apr 02, 2022 11:35 pm
Forum: General
Topic: Wireguard peer interface irregularly stop working
Replies: 66
Views: 18169

Re: Wireguard peer interface irregularly stop working

> a. ONLY One cable is connected to ether1 from a source ( what is the source it is not clear) either1 (DFN, WAN) is assigned DDD.EEE.FFF.114/27, a cable goes into a port on a switch that is in this network. Another cable from one of the bridge ports (LAN) goes into another port on a switch that is ...
by DL7JP
Sat Apr 02, 2022 8:45 pm
Forum: General
Topic: Wireguard peer interface irregularly stop working
Replies: 66
Views: 18169

Re: Wireguard peer interface irregularly stop working

I am still stuck on ether1 carrying multiple WANIPs ?? If you assign the bridge as an IP DHCP client............... it must get a gateway and WANIP from somewhere. Is there another port the router uses for ISP??? Something I am not grasping. :-(.... ether1 (renamed to DFN) is not part opf the bridg...
by DL7JP
Sat Apr 02, 2022 8:26 pm
Forum: General
Topic: Wireguard peer interface irregularly stop working
Replies: 66
Views: 18169

Re: Wireguard peer interface irregularly stop working

1. The ISP is providing multiple Public IPs. 2. One Public IP is assigned to Ether1 but SERVES NO PURPOSE ???? WAIT< its strictly for the purpose of creating the WG tunnel as a server need public reachable IP!!! I dont see any traffic from the LAN going out this wanip ???? 3. ALL clients existing b...
by DL7JP
Sat Apr 02, 2022 7:57 pm
Forum: General
Topic: Wireguard peer interface irregularly stop working
Replies: 66
Views: 18169

Re: Wireguard peer interface irregularly stop working

For now I'm using scripting to try get around these issues. The following script should completely reset a wg tunnel
Thanks, I will have a look at it!
by DL7JP
Sat Apr 02, 2022 7:52 pm
Forum: General
Topic: Wireguard peer interface irregularly stop working
Replies: 66
Views: 18169

Re: Wireguard peer interface irregularly stop working

Thanks for embedding the picture! > I assume eth1-5 are all the same device ? Yes, they are all part of the router working as a WG-Server > Why represent them in 2 separate blocks then ? They are in different networks. > Where is your ISP connection which should be connected to eth1 ? The router has...
by DL7JP
Sat Apr 02, 2022 5:17 pm
Forum: General
Topic: Wireguard peer interface irregularly stop working
Replies: 66
Views: 18169

Re: Wireguard peer interface irregularly stop working

A picture would make things a lot more clear. Don't you think so ?
Hm, not sure how to add a picture here...
https://www.dropbox.com/s/dk5khwruya9qz9x/WG.png
by DL7JP
Sat Apr 02, 2022 3:46 pm
Forum: General
Topic: Wireguard peer interface irregularly stop working
Replies: 66
Views: 18169

Re: Wireguard peer interface irregularly stop working

Well, LAN is indeed be not be a good choice of a name for bridge-LST: It is connected to a (firewalled) subnet with public IP addresses, a seperate gateway to the Internet, and a dhcp server. So the router can reach the Internet via "WAN" and "LAN". WG peers are connecting from &...
by DL7JP
Sat Apr 02, 2022 12:33 pm
Forum: General
Topic: Wireguard peer interface irregularly stop working
Replies: 66
Views: 18169

Re: Wireguard peer interface irregularly stop working

So firstly thanks to all here, very competent forum! I changed all peers to /32 In the past all worked fine for 1-2 days then tunnels got stuck. So, I will now wait for a few days, see if the problem comes up again and report back. UDP timing might also be a reason, but in the setup here there is no...
by DL7JP
Sat Apr 02, 2022 11:18 am
Forum: General
Topic: Wireguard peer interface irregularly stop working
Replies: 66
Views: 18169

Re: Wireguard peer interface irregularly stop working

> Yes but ALL traffic from that subnet will go through that peer. Hm ... but the configuration works. I would think the WG server sends traffic using the most specific subnet. There are a few other peers in /24, it might be that exactly these stop working after a couple of hours. I will check this.
by DL7JP
Sat Apr 02, 2022 11:06 am
Forum: General
Topic: Wireguard peer interface irregularly stop working
Replies: 66
Views: 18169

Re: Wireguard peer interface irregularly stop working

> If that peer is a spoke in your hub/ spoke setup, it should be /32.

What is the effect of /24 vs. /32? The peer with /24 can connect and traffic goes through the tunnel.
by DL7JP
Sat Apr 02, 2022 10:38 am
Forum: General
Topic: Wireguard peer interface irregularly stop working
Replies: 66
Views: 18169

Re: Wireguard peer interface irregularly stop working

> Why is this peer /24 vice 32? (allowed IPs)
Actually it is a typo, but it does not seem to matter.

WG peers connect to DDD.EEE.FFF.114, and the routing rule causes WG-server responses to use the same interface. The traffic from inside the WG-Tunnels is routed via the default route (bridge-LST).
by DL7JP
Sat Apr 02, 2022 1:14 am
Forum: General
Topic: Wireguard peer interface irregularly stop working
Replies: 66
Views: 18169

Re: Wireguard peer interface irregularly stop working

Here's the config, I refrained from stripping anything since there might be side effects, so it's a bit complex, I hope I cut out all sensitive information. The config (sort of) grew historically, so all comments on the config are appreciated, also beyond WG. The router has two public IPs and provid...
by DL7JP
Fri Apr 01, 2022 10:36 pm
Forum: General
Topic: Wireguard peer interface irregularly stop working
Replies: 66
Views: 18169

Re: Wireguard peer interface irregularly stop working

I tried with and without keepalives, makes no difference.
by DL7JP
Fri Apr 01, 2022 8:19 pm
Forum: General
Topic: Wireguard peer interface irregularly stop working
Replies: 66
Views: 18169

Wireguard peer interface irregularly stop working

I am running a WG server since 7.1beta6, now with 7.1.5. Through all versions I experience the same problem: Some WG peers irregularly become disconnected and cannot reconnect, the tunnel just stops working and no traffic is going through it any more. Reconnecting from the client fails, the peer int...
by DL7JP
Thu Mar 24, 2022 12:27 am
Forum: Announcements
Topic: v7.1.4 and v7.1.5 is released!
Replies: 202
Views: 40543

Re: v7.1.4 and v7.1.5 is released!

RB1100AHx4: No problems so far with the update, but also no complex configuration (2 VLANs, WG-Server, and abt 50 FW-Rules).
by DL7JP
Thu Mar 17, 2022 11:15 pm
Forum: Beginner Basics
Topic: Basic IPv6 Setup - prefix from ISP
Replies: 14
Views: 7818

Re: Basic IPv6 Setup - prefix from ISP

That is down to Mikrotik CLI quirks, use ping [:resolve ipv6.google.com] Thanks *sigh*. It seems like :resolve does not return a v6 address for hosts with both v4 and v6. This is probably the reason for problems like [admin@MikroTik] > system/package/update/check-for-updates channel: stable install...
by DL7JP
Thu Mar 17, 2022 10:34 pm
Forum: Beginner Basics
Topic: Basic IPv6 Setup - prefix from ISP
Replies: 14
Views: 7818

Re: Basic IPv6 Setup - prefix from ISP

One problem I see with this explanation is that you cracked the chicken and egg problem, you couldn't have it working from PC behind router, if router itself didn't have working default route. :) Good point, I don't understand it either :-). The router behaves strange in several ways, see e.g below...
by DL7JP
Thu Mar 17, 2022 9:23 pm
Forum: Beginner Basics
Topic: Basic IPv6 Setup - prefix from ISP
Replies: 14
Views: 7818

Re: Basic IPv6 Setup - prefix from ISP

If you look at whole address, not just at ::2 at the end, you'll see that it's not going to LAN You're right ... I still have to get used to v6 addresses, my bad. I did a traceroute from the succussfully connected PC and used the first hop as a gateway, which works.I am just somewhat surprised by t...
by DL7JP
Thu Mar 17, 2022 7:48 pm
Forum: Beginner Basics
Topic: Basic IPv6 Setup - prefix from ISP
Replies: 14
Views: 7818

Re: Basic IPv6 Setup - prefix from ISP

Thanks for the hint. I tried this and identified fe80::6e6c:d3ff:fe6e:20c9 as the likely gateway. But are already two such dynamic entries in my routing table (added by dhcp client): [admin@MikroTik] > ipv6/route/print Flags: D - DYNAMIC; I, A - ACTIVE; c, d, y - COPY; H - HW-OFFLOADED; + - ECMP Col...
by DL7JP
Thu Mar 17, 2022 11:18 am
Forum: Beginner Basics
Topic: Basic IPv6 Setup - prefix from ISP
Replies: 14
Views: 7818

Re: Basic IPv6 Setup - prefix from ISP

Thanks to all, I am, getting closer but not yet there :-). @tdw: I am not using the Mikrotik DHCPv6 server and DHCPv6 client "add-default-route" yes or no does not seem to make a difference. The configuration below works in the sense that the attached Windows machine connects via v6 to the...
by DL7JP
Wed Mar 16, 2022 11:45 am
Forum: Beginner Basics
Topic: Basic IPv6 Setup - prefix from ISP
Replies: 14
Views: 7818

Re: Basic IPv6 Setup - prefix from ISP

The DHCPv6 client add-default-route=yes is a hacky bodge.
I tried without the default route flag, but no change. It seems to be another problem...
by DL7JP
Wed Mar 16, 2022 12:49 am
Forum: Beginner Basics
Topic: Basic IPv6 Setup - prefix from ISP
Replies: 14
Views: 7818

Basic IPv6 Setup - prefix from ISP

Dear all, I woudl be grateful if some kind sould could give me a hint what might be the problem here: My ISP delivers v6, if I connect a Windows 10 laptop to the "LAN" interface, it gets an address, but claims there is no Internet connection: Ethernet-Adapter LAN-Verbindung: Verbindungsspe...
by DL7JP
Thu Feb 24, 2022 2:59 am
Forum: Announcements
Topic: v7.1.3 is released!
Replies: 251
Views: 57383

Re: v7.1.3 is released!

Upgrading to 7.1.3 on RB1100AHx4 removed some of the device configuration. Lost part of the firewall, nat, mangle, static dhcp and other. This is beginning to threaten the functioning of the networks. The situation is simply catastrophic. The situation has not changed for last half year, RouterOS 7...
by DL7JP
Tue Feb 22, 2022 8:29 pm
Forum: Announcements
Topic: v7.1.3 is released!
Replies: 251
Views: 57383

Re: v7.1.3 is released!

I am more cautious with my RB1100AHx4 after the last update experience (firewall rules screwed up). Did any update this box?
I was brave enough to give it a try: Seems fine, no issues so far with the RB1100AH. Also CRS125-24G updated with no issues.
by DL7JP
Mon Feb 21, 2022 11:43 pm
Forum: Announcements
Topic: v7.1.3 is released!
Replies: 251
Views: 57383

Re: v7.1.3 is released!

RB2011iL, hAP ac2, hAp from 7.1.2 to 7.1.3 no problems noticed.
I am more cautious with my RB1100AHx4 after the last update experience (firewall rules screwed up). Did any update this box?
by DL7JP
Tue Feb 15, 2022 12:07 pm
Forum: General
Topic: wAP LR8 kit reset procedure
Replies: 4
Views: 804

Re: wAP LR8 kit reset procedure

Try Netinstall, don't forget to add LoRa package as well:
https://help.mikrotik.com/docs/display/ROS/Netinstall
Unfortunatey it won't come up in netinstall. I guess it's a hardware failure after only 1 1/2 years.
by DL7JP
Mon Feb 14, 2022 12:26 pm
Forum: General
Topic: wAP LR8 kit reset procedure
Replies: 4
Views: 804

Re: wAP LR8 kit reset procedure

Can you access it through mac-telnet winbox?
Unfortunately I cannot access the router this way. The copper interface establishes a link, but there is no traffice going over it.
by DL7JP
Sun Feb 13, 2022 12:17 am
Forum: General
Topic: wAP LR8 kit reset procedure
Replies: 4
Views: 804

wAP LR8 kit reset procedure

Dear all, my wAP LR8 kit stopped working - only the yellow Ethernet led is slowly flashing, no IP traffic on the interface. I tried to reset it with the reset button, but no luck: As soon as I power it up with the reset button pressed, a green led inside flashes quickly. It then lights continously f...
by DL7JP
Fri Feb 11, 2022 12:05 am
Forum: Announcements
Topic: v7.1.2 is released!
Replies: 127
Views: 39877

Re: v7.1.2 is released!

Hm ... the update re-ordered my firewall rules on an RB1100AHx4. Quite a mess.
by DL7JP
Sat Feb 05, 2022 2:36 am
Forum: Wireless Networking
Topic: Band Steering
Replies: 32
Views: 20021

Re: Band Steering

Cambium. Dò they only offer Cloud Management or on-premise Controller (VMware Image yuck) only? No Others options?
I am perfectly happy with Ruckus Unleashed. If you don't insist on Wifi6, you can get used Ruckus APs on ebay for OK prices.
by DL7JP
Thu Dec 23, 2021 3:13 pm
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 443
Views: 226617

Re: v7.1.1 is released!

Hi, I updated a RB1100AHx4 from 6.49.2 to 7.1 then 7.1.1 and ended up in a strange situation: The router works fine, but asa I reboot it all is screwed up: All bridges are gone, so all IPs are missing, no access via MAC-Telnet. After resetting it and restoring the 7.1 backup with 7.1.1 all works fi...
by DL7JP
Thu Dec 23, 2021 1:14 am
Forum: Announcements
Topic: v7.1.1 is released!
Replies: 443
Views: 226617

Re: v7.1.1 is released!

Hi, I updated a RB1100AHx4 from 6.49.2 to 7.1 then 7.1.1 and ended up in a strange situation: The router works fine, but asa I reboot it all is screwed up: All bridges are gone, so all IPs are missing, no access via MAC-Telnet. After resetting it and restoring the 7.1 backup with 7.1.1 all works fin...
by DL7JP
Thu Jun 24, 2021 12:00 am
Forum: General
Topic: So why do I want to run ROS on a Switch when SWOS is just fine?
Replies: 17
Views: 4246

Re: So why do I want to run ROS on a Switch when SWOS is just fine?

Lack of administration via encryted channels (TLS, ssh) is a downside of SWOS.
by DL7JP
Sun Jun 20, 2021 12:44 am
Forum: RouterOS beta
Topic: Configuring RouterOS as a wireguard client
Replies: 15
Views: 38576

Re: Configuring RouterOS as a wireguard client

Post your config /export hide-sensitive file=anynameyouwish so I can see the rest of the config and not just snippets. Also a network diagram to show the relationship of the two WG routers connected by internet, and the associated wireguard devices / subnets desired on the client side. I am assumin...
by DL7JP
Sat Jun 19, 2021 11:52 pm
Forum: RouterOS beta
Topic: Configuring RouterOS as a wireguard client
Replies: 15
Views: 38576

Re: Configuring RouterOS as a wireguard client

... just to complete this for the audience: I set up a route on the client
/ip route add dst-address=X.X.X.X/N gateway=192.168.100.1
all works fine - after I remembered this target subnet also has to be listed under Allowed Addresses to the client side WG peer :-).
by DL7JP
Sat Jun 19, 2021 11:03 pm
Forum: RouterOS beta
Topic: Configuring RouterOS as a wireguard client
Replies: 15
Views: 38576

Re: Configuring RouterOS as a wireguard client

Thanks, I am getting closer ... in viewtopic.php?f=23&t=174417&p=861477&hi ... rd#p861477 I did not find the configuration for a RouterOS WG client. So, here's what I tried (the sample Sure you did, look harder the RB4011 is a client WG device on the diagrams, its behind the Bell modem/...
by DL7JP
Sat Jun 19, 2021 10:59 pm
Forum: RouterOS beta
Topic: Configuring RouterOS as a wireguard client
Replies: 15
Views: 38576

Re: Configuring RouterOS as a wireguard client

The confusing thing is the listen port on the client side, where the documentation says "Port for WireGuard service to listen on for incoming sessions". Since a client won't have incoming sessions it seems I guess it's irrelevant and any port will do. Not completely, it's also the source ...
by DL7JP
Sat Jun 19, 2021 8:41 pm
Forum: RouterOS beta
Topic: Configuring RouterOS as a wireguard client
Replies: 15
Views: 38576

Re: Configuring RouterOS as a wireguard client

Thanks, I am getting closer ... in viewtopic.php?f=23&t=174417&p=861477&hi ... rd#p861477 I did not find the configuration for a RouterOS WG client. So, here's what I tried (the sample client configuration for my new RouterOS client is shown in my first post): RouterOS client device is c...
by DL7JP
Sat Jun 19, 2021 3:00 am
Forum: RouterOS beta
Topic: Configuring RouterOS as a wireguard client
Replies: 15
Views: 38576

Configuring RouterOS as a wireguard client

Dear all, I am quite excited about wireguard, and I successfully connect clients (Win, MacOS, Android, iOS) to a Miktrotik WG server. However, I fail to connect another Mikrotik router as a client, could some kind soul give me a hint how to do this? Here's a sample client configuration, how would it...
by DL7JP
Sun Jun 13, 2021 8:06 pm
Forum: General
Topic: VLAN across bridges
Replies: 10
Views: 2910

Re: VLAN across bridges

No i cannot help stubborn horse that refuses to drink clean good water.
The horse is more interested in learning how to find such water than in drinking it :-).
by DL7JP
Sun Jun 13, 2021 8:01 pm
Forum: General
Topic: VLAN across bridges
Replies: 10
Views: 2910

Re: VLAN across bridges

(see https://wiki.mikrotik.com/wiki/Manual:L ... figuration particularly points 7 & 8 for the potential issues)
Thanks a bunch, useful page! I wasn't aware of it!
by DL7JP
Sun Jun 13, 2021 1:17 pm
Forum: General
Topic: VLAN across bridges
Replies: 10
Views: 2910

Re: VLAN across bridges

You cannot directly share VLANs between bridges - VLAN 10 on bridge 1 and VLAN 10 on bridge 2 are completely independent ethernet / layer 2 networks. Hm... there is really no way? I guess I could do this with physical cables: Put both VLANs on an ethernet-port and connect the ports with a cable. No...
by DL7JP
Sun Jun 13, 2021 11:37 am
Forum: General
Topic: VLAN across bridges
Replies: 10
Views: 2910

Re: VLAN across bridges

Yes, this would be an option; but it meant I had to re-configure the router completely. I just want to "pass" my ISP's VoIP-VLAN to internal VoIP clients, and I'd prefer to minimize changes to the (complex) router configuration.
by DL7JP
Sun Jun 13, 2021 12:25 am
Forum: General
Topic: VLAN across bridges
Replies: 10
Views: 2910

Re: VLAN across bridges

No, use one bridge.
The bridges have more than these interfaces and untagged traffic on them is on different subnets. So, I have to route/firewall between them.
by DL7JP
Sat Jun 12, 2021 11:18 pm
Forum: General
Topic: VLAN across bridges
Replies: 10
Views: 2910

VLAN across bridges

Folks, here's another Q on my journey to understand the VLAN implementation: Suppose there are two bridges, and we want them to share the same VLAN (tagged 10 here). bridge1 could be an ISP delivering a VoIP over VLAN 10, bridge2 an internal network with VoIP phones. Would this be a preferred way to...
by DL7JP
Mon Jun 07, 2021 3:05 am
Forum: RouterOS beta
Topic: Wireguard VPN and to the Internet
Replies: 1
Views: 1766

Re: Wireguard VPN and to the Internet

I am not sure if I understand your Q compelety, but if you want to route all traffic of the client throught the WG server (which is possible) then a) configure "AllowedIPs = 0.0.0.0/0" on the client PC, b) make sure your WG server is routing/NAT-ing the traffic from the WG interface toward...
by DL7JP
Wed Jun 02, 2021 9:21 pm
Forum: General
Topic: WLAN SSIDs attached to VLANs
Replies: 17
Views: 8810

Re: WLAN SSIDs attached to VLANs

Thanks to bpwl and tdw for potently explaning things! I am slowly gaining an understanding of VLAN handling in RouterOS. I configured a VLAN-Interface vlan1 and put the dchp-client on it, becase a German tutorial https://administrator.de/tutorial/mikrotik-vlan-konfiguration-routeros-version-6-41-367...
by DL7JP
Tue Jun 01, 2021 11:32 pm
Forum: General
Topic: WLAN SSIDs attached to VLANs
Replies: 17
Views: 8810

Re: WLAN SSIDs attached to VLANs

Please use this great tutorial on how to configure VLAN's with MikroTik: https://forum.mikrotik.com/viewtopic.php?t=143620 OK, I read it and tried to adapt the Access Point scenaerio (#4). Here's my configuration with bridge VLAN siltering for what I explained in post #1: /interface bridge add name...
by DL7JP
Tue Jun 01, 2021 10:40 pm
Forum: General
Topic: WLAN SSIDs attached to VLANs
Replies: 17
Views: 8810

Re: WLAN SSIDs attached to VLANs

Btw, the config in post #4 might not to isolate vlans properly: I just had a client on wlan25/vlan25 that got an IP from the dhcp-server on wlan1/vlan1. I guess there is something missing.
by DL7JP
Tue Jun 01, 2021 3:19 pm
Forum: General
Topic: WLAN SSIDs attached to VLANs
Replies: 17
Views: 8810

Re: WLAN SSIDs attached to VLANs

Just for the records, here's the other solution I mentioned in my original post at the beginning - I guess it is less efficient: /interface bridge add name=bridge-vlan1 vlan-filtering=yes add frame-types=admit-only-untagged-and-priority-tagged name=bridge-vlan15 vlan-filtering=yes add frame-types=ad...
by DL7JP
Tue Jun 01, 2021 12:39 pm
Forum: General
Topic: WLAN SSIDs attached to VLANs
Replies: 17
Views: 8810

Re: WLAN SSIDs attached to VLANs

Should work. But disable STP on bridge and potentially on other end of cable as well. (Have run into cases where HP Procurve switches saw a loop when VLAN's were used, as it counted each VLAN as a direct path) It was not STP (was at default "RSTP" on both sides), but I rebooted the router...
by DL7JP
Tue Jun 01, 2021 1:36 am
Forum: General
Topic: WLAN SSIDs attached to VLANs
Replies: 17
Views: 8810

Re: WLAN SSIDs attached to VLANs

these requests do not show up on ether1 How do you check? If it is tagged on the bridge, it should be tagged on ether1. (Unless STP/RSTP is blocking the transfer) We have not defined a VLAN interface here that can read/write in the VLAN 15 or 25. Should not be needed for normal traffic. You did not...
by DL7JP
Mon May 31, 2021 11:53 pm
Forum: General
Topic: WLAN SSIDs attached to VLANs
Replies: 17
Views: 8810

Re: WLAN SSIDs attached to VLANs

Thanks a bunch, I will work myself through the tutorial in the next days. Meanwhile, I tried bpwl 's suggestion: 1. Also old style (when VLAN's were handled via Switch, or just handled with a non-smart bridge (this is one where the VLAN's are not configured)) For this method add all WLAN to the one ...
by DL7JP
Mon May 31, 2021 8:36 pm
Forum: General
Topic: WLAN SSIDs attached to VLANs
Replies: 17
Views: 8810

WLAN SSIDs attached to VLANs

Dear all, Here's a challenge for the VLAN / Wifi experts :-) : I have a bridge with the main interface of a WLAN Access Point (cAP) and eth1; on eth1 is the main LAN (untagged) and additionally two VLANs tagged 2 and 3. There are no VLANs explicitly configured in the Access Point, the VLANs 2 and 3 ...
by DL7JP
Thu May 27, 2021 12:14 am
Forum: RouterOS beta
Topic: How do I enable wireguard logging on 7.1beta6
Replies: 3
Views: 7364

Re: How do I enable wireguard logging on 7.1beta6

At the very least I need to know what peer logged on, from what IP address and when for audit purposes. I can do this on EdgeOS (Ubiquiti). I use a fw rule like this to log incoming connections: /ip firewall filter add action=accept chain=input comment="Wireguard Port" dst-port=12345 in-i...
by DL7JP
Mon May 24, 2021 2:27 pm
Forum: RouterOS beta
Topic: Wireguard bug: connections via WG tunnels suddenly failing
Replies: 9
Views: 5017

Re: Wireguard bug: connections via WG tunnels suddenly failing

I usually perform the following ritual when wg acting as a "client": 1. Disable/enable WG interface 2. Ping the WG endpoint/server 3. Ping the internal IP which should go over the tunnel ...and the tunnel magically comes back. The problem I described was with the Mikrotik router being the...
by DL7JP
Sat May 22, 2021 12:29 pm
Forum: General
Topic: Mikrotik VLAN Configuration / switch ports
Replies: 3
Views: 631

Re: Mikrotik VLAN Configuration / switch ports

Thanks a bunch, very useful explanation!
Ups, I was implicitly assuming it is supported since the winbox UI under switch shows this option... not exactly an intuitve UI :-)
by DL7JP
Fri May 21, 2021 11:38 pm
Forum: General
Topic: Mikrotik VLAN Configuration / switch ports
Replies: 3
Views: 631

Mikrotik VLAN Configuration / switch ports

Dear all, I am still a bit confused with the Mikrotik VLAN implementation, maybe some kind soul could give me a hint here: My main router is a RB1100AHx4, port eth1 is connected to my ISP delivering VoIP over VLAN 40. For whatever reason I can only get one IP address from their dhcp Server in the VL...
by DL7JP
Wed May 19, 2021 10:38 pm
Forum: RouterOS beta
Topic: Wireguard bug: connections via WG tunnels suddenly failing
Replies: 9
Views: 5017

Re: Wireguard bug: connections via WG tunnels suddenly failing

what specific log entry can be made to pinpoint if this happens?
Otherwise way to much noise on logs??
There seems to be no specific logging topic for wireguard - in fact I haven't seen any usefol log entry in this case. Debugging wireguard connections is really tough...
by DL7JP
Wed May 19, 2021 10:35 pm
Forum: RouterOS beta
Topic: Wireguard bug: connections via WG tunnels suddenly failing
Replies: 9
Views: 5017

Re: Wireguard bug: connections via WG tunnels suddenly failing

I'm currently debugging something similar. Couple questions to you: 1. Is disabling the WG interface and re-enabling it again fixes the problem? 2. Can RB ping the client in this broken state? Sorry, I am not here too often ... as to 1, I did not try this, will do so when it happens next time; howe...
by DL7JP
Fri May 14, 2021 6:57 pm
Forum: RouterOS beta
Topic: Wireguard bug: connections via WG tunnels suddenly failing
Replies: 9
Views: 5017

Wireguard bug: connections via WG tunnels suddenly failing

I am experimenting since 3 monhts or so with the wireguard implementation running on a RB450G. It it works, it works like a charm, but I regularly see clients suddenly failing to route via the tunnel, without having touched the condiguration on either side. The incomming connection is shown in the s...
by DL7JP
Fri Jan 29, 2021 11:48 am
Forum: RouterOS beta
Topic: wireguard configuration
Replies: 4
Views: 3182

Re: wireguard configuration

One common interface is enough. Why it doesn't work for you, it's hard to tell. I don't think there's anything in current RouterOS to help you with that, some statistics for individual peers, logs, or anything. I tried to reproduce this by setting up a new interface, now I can have multiple clients...
by DL7JP
Thu Jan 28, 2021 10:10 pm
Forum: RouterOS beta
Topic: wireguard configuration
Replies: 4
Views: 3182

wireguard configuration

I am experimenting with wg - performance is impressive, but if there is something wrong, I find it hard to debug. I did not come across much documentation so far, is there something detailed around on Mikrotik specifics? I want to connect multiple peers (Android, IOS, Win10) to a router and tried to...
by DL7JP
Thu Jan 28, 2021 7:53 pm
Forum: RouterOS beta
Topic: Routing marks / mangle
Replies: 9
Views: 12524

Re: Routing marks / mangle

The router is up again, it seems it did not like being powered both by a power supply and PoE... I configured the router again, what you suggested worked, thanks a lot! Here's the code for others with similar problems: /routing table add name=viaDFN fib /ip route add dst-address=0.0.0.0/0 gateway=1....
by DL7JP
Wed Jan 27, 2021 10:54 pm
Forum: RouterOS beta
Topic: Routing marks / mangle
Replies: 9
Views: 12524

Re: Routing marks / mangle

> I missed it in original post, but even v6 config wasn't correct. The mangle rule in prerouting is useless, all work is done by the one in output. Thanks for the hint. > As for WG, I seem to be a little lost in description. The situation is this: The router has two Ethernet interfaces with public I...
by DL7JP
Wed Jan 27, 2021 7:15 pm
Forum: RouterOS beta
Topic: Routing marks / mangle
Replies: 9
Views: 12524

Re: Routing marks / mangle

Hint: https://forum.mikrotik.com/viewtopic.php?p=840547#p840547 Thanks a bunch! I am getting closer :-) ... here's the configuration now: /routing table add name=viaDFN fib /ip firewall mangle add action=mark-routing chain=output new-routing-mark=viaDFN passthrough=yes src-address=1.2.3.4 add actio...
by DL7JP
Wed Jan 27, 2021 1:44 am
Forum: RouterOS beta
Topic: Routing marks / mangle
Replies: 9
Views: 12524

Routing marks / mangle

Dear all, I am trying to migrate our VPN-Server to v7 since wireguard is the best thing since sliced bread :-), but I am stuck with mangle/routing. The situation is this: The VPN-router has two interfaces with public IPs, one is exclusively for incoming VPN connections (“DFN” below, IP 1.2.3.4), the...
by DL7JP
Fri May 29, 2020 1:33 am
Forum: General
Topic: Run a script if a firewall rule is triggered
Replies: 12
Views: 7916

Re: Run a script if a firewall rule is triggered

Why would you a function like this? I do ask, since If I do now the reason, I may see another way to solve this. My application is quite simple: I grant access to certain services based on port knocking. Being well aware that this is not very secure, I want to monitor this, whereas I am only intere...
by DL7JP
Wed May 27, 2020 10:28 pm
Forum: General
Topic: Run a script if a firewall rule is triggered
Replies: 12
Views: 7916

Run a script if a firewall rule is triggered

Dear all, I am looking for a way to run a script if a firewall rule is triggered and pass the source IP that triggered the rule to the script. I guess I could add the IP to a fw address list and regularly scan the address list by a scheduled script, but I am wondering if the gurus here know a more e...
by DL7JP
Fri May 10, 2019 6:14 pm
Forum: Scripting
Topic: Routing exeptions for connections from the routers itself
Replies: 7
Views: 2300

Re: Routing exeptions for connections from the routers itself

@nostromog: Thanks a bunch! This sound quite like what I was looking for. Nice trick, I did not think about this... will test it.
by DL7JP
Fri May 10, 2019 3:31 pm
Forum: Scripting
Topic: Routing exeptions for connections from the routers itself
Replies: 7
Views: 2300

Re: Routing exeptions for connections from the routers itself

When you apparently don't mind sending your alert messages through your VPN (which will fail whenever the internet connection is down or the VPN is down) why not send the telegram message from your central system as an action on the syslog server there? The reason is that there is no central system...
by DL7JP
Fri May 10, 2019 11:28 am
Forum: Scripting
Topic: Routing exeptions for connections from the routers itself
Replies: 7
Views: 2300

Re: Routing exeptions for connections from the routers itself

You can not use Syslog?
Well, I probably could, but I find a Telegram group more versatile and I already use it a lot to monitor Mikrotik routers.
by DL7JP
Fri May 10, 2019 1:29 am
Forum: Scripting
Topic: Routing exeptions for connections from the routers itself
Replies: 7
Views: 2300

Routing exeptions for connections from the routers itself

Here's a challenge for the routing experts :-) I have a script that uses the Telegram messenger API to notify about logins, errors, etc. on a router; this is done by "/tool fetch url="https://api.telegram.org/bot...." in a script. Since api.telegram.org is blocked in several countries...
by DL7JP
Sat May 26, 2018 12:59 am
Forum: General
Topic: SSTP Server Problem (port used by another service)
Replies: 6
Views: 5187

Re: SSTP Server Problem (port used by another service)

Thanks for your comments! I looked at the post cited, and came up with this: - SSTP Server configured to run at port 4431, and /ip firewall nat add action=dst-nat chain=dstnat dst-port=443 in-interface=eth1 to-addresses=XXX.XXX.XXX.XXX to-ports=4431 where eth1 is the interface clients will connect t...
by DL7JP
Fri May 25, 2018 10:37 pm
Forum: General
Topic: SSTP Server Problem (port used by another service)
Replies: 6
Views: 5187

Re: SSTP Server Problem (port used by another service)

> Yes, just change port number with 444 for example on both sides !
Technically this works, but the idea is to offer VPN-Access when traveling: I would like to stick with 443 since this port is open outgoing for clients from just about everywhere.
by DL7JP
Fri May 25, 2018 10:10 pm
Forum: General
Topic: SSTP Server Problem (port used by another service)
Replies: 6
Views: 5187

SSTP Server Problem (port used by another service)

Hi, I found a few hints in the forum about this, but did not spot a solution - sorry in case I overlooked it... I use a RB1100AHx4 with a public IP address at eth1 and a hotspot at eth2 with a private IP Address range. When activating the SSTP Server port 443, it complains: "Couldn't change SST...
by DL7JP
Sun Sep 24, 2017 12:21 am
Forum: General
Topic: hAp ac: Reset Problem
Replies: 4
Views: 5586

Re: hAp ac: Reset Problem

For the records: Remove the tape opposite the eth ports, the enclosure can then be opened (the plastic noses are quite robust). I managed to get it into netboot mode by a short circuit over the reset button - it seems indeed to have a problem and does not consistently close its contacts when pressed...
by DL7JP
Fri Sep 22, 2017 9:46 pm
Forum: General
Topic: hAp ac: Reset Problem
Replies: 4
Views: 5586

Re: hAp ac: Reset Problem

Try netinstalling it I tried this multiple times, also with different PCs - no luck, the device reboots while the reset-button is pressed. Can the part of the firmware that handles this stage when booting get corrupted? If not, the reset button might have a mechanical/electrical problem, but the en...
by DL7JP
Thu Sep 21, 2017 11:23 pm
Forum: General
Topic: hAp ac: Reset Problem
Replies: 4
Views: 5586

hAp ac: Reset Problem

Dear all, I upgraded an hAp from 6.36.4 to 6.40.3 (using "System - Packages - check for updates" in Winbox), afterwards it was at 6.40.3, but the wireless interfaces were missing. I then tried to install the wireless package separately by dropping wireless-6.40.3-mipsbe.npk into the files ...
by DL7JP
Tue Dec 15, 2015 12:18 am
Forum: Beginner Basics
Topic: Firewall Q: Bridged Network vs. Routed Subnets
Replies: 3
Views: 1232

Re: Firewall Q: Bridged Network vs. Routed Subnets

Thanks for your opinions! I decided to go for 4 separate private /24 nets and route rather then bridge - conceptually it seems the more elegant solution in particular since one /24 is WLAN.

As to CCR: I will try to keep the high bandwidth traffic on switched ports, and I will see how well it works.
by DL7JP
Wed Dec 09, 2015 1:48 am
Forum: Beginner Basics
Topic: Firewall Q: Bridged Network vs. Routed Subnets
Replies: 3
Views: 1232

Firewall Q: Bridged Network vs. Routed Subnets

Dear all, I am going to set up a network in a private adress space, which is structured in 4 segments: DMZ (NAT-ing into the public Internet), servers, clients, and guests. All these come together at a CRS125-24G-1S-RM, where there is a unique assignment from segments to the router ports, and a poli...
by DL7JP
Sat Dec 27, 2014 6:29 pm
Forum: RouterBOARD hardware
Topic: RB450G Netinstall
Replies: 1
Views: 1701

Re: RB450G Netinstall

but the device does not show up in the netinstall program. Can someone kindly point me to the correct procedure?
Sry, my own mistake: Ethernet cable was broken ... all OK now.
by DL7JP
Sat Dec 27, 2014 12:10 pm
Forum: RouterBOARD hardware
Topic: RB450G Netinstall
Replies: 1
Views: 1701

RB450G Netinstall

Hi, yesterday I used "search for updates" and "update" on a RB450G, the result is a bricked device in a boot-loop. I tried to Netinstall (hold reset button until yellow user led stops blinking, I also tried holding longer), but the device does not show up in the netinstall progra...
by DL7JP
Mon Dec 22, 2014 4:29 pm
Forum: RouterBOARD hardware
Topic: mAP 2n blinking
Replies: 25
Views: 15618

Re: mAP 2n blinking

Everyone tried Netinstall and connecting with MAC address? In that case, contact the seller for RMA procedure. We have not yet received any mAP devices for warranty repair, so it is hard to estimate what could be wrong, we would need to have at least one to look at. I tried to netinstall it, but th...
by DL7JP
Sat Dec 20, 2014 11:50 am
Forum: RouterBOARD hardware
Topic: mAP 2n blinking
Replies: 25
Views: 15618

Re: mAP 2n blinking

Yep.. exatly the same problem here. Just that it worked for 3 days :-)