Community discussions

MikroTik App

Search found 12138 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 41
by mkx
Thu May 09, 2024 8:03 am
Forum: Announcements
Topic: Long range wireless links - share your experience
Replies: 29
Views: 22569

Re: Long range wireless links - share your experience

My current 27km AirFiber 5XHD link on 3' (1m) 34dBi antennas and 100MHz of spectrum ... This setup hardly qualifies as "wifi based link". While it does use frequency from U-NII-3 band, it obviously doesn't use 802.11-compliant channel width (which would be either 80MHz or 160MHz) ... and ...
by mkx
Wed May 08, 2024 9:01 pm
Forum: RouterBOARD hardware
Topic: HAP AC3 not performing well (Can't reach max WiFi)
Replies: 4
Views: 262

Re: HAP AC3 not performing well (Can't reach max WiFi)

TxRx rate in the "Status" page of the WLAN2 interface shows to be 585Mbs. This shows you that signal loss between both devices is considerable. And apart from removing the obstacle there isn't much that can be done. Then it comes to efficiency of using the "raw interface rate" f...
by mkx
Wed May 08, 2024 8:38 pm
Forum: RouterBOARD hardware
Topic: Fan noise under SwOS on CRS310-8G+2S+
Replies: 3
Views: 231

Re: Fan noise under SwOS on CRS310-8G+2S+

I always assumed SwOS being way simpler might also lead to less CPU load and thus power consumption ... If configured properly, then handling of actual traffic would be done by switch ASIC in both cases. The difference is in management (but that's only effective when management is on-going ... and ...
by mkx
Wed May 08, 2024 7:59 pm
Forum: General
Topic: CRS310-8G+2S+IN brick
Replies: 6
Views: 290

Re: CRS310-8G+2S+IN brick

I'm out of ideas. You may want to ask support@mikrotik.com if there are any other options (if device had serial console, then you'd have option to boot back into ROS and proceed from there).
by mkx
Wed May 08, 2024 7:32 pm
Forum: General
Topic: RB5009 + SFP DFP-34X-2C2. How to get 2,5Gbps?
Replies: 2
Views: 169

Re: RB5009 + SFP DFP-34X-2C2. How to get 2,5Gbps?

Are you sure it's not optimally performing already? SFP+ has 10Gbps line rate ... AFAIK host and module always talk at this rate. What then module negotiates with its fiber peer is pretty differrent thing. And quite possibly it negotiates 2.5Gbps as well ... and that 500Mbps service you're subscribe...
by mkx
Wed May 08, 2024 6:53 pm
Forum: Beginner Basics
Topic: Netinstall
Replies: 1
Views: 108

Re: Netinstall

After picking router, netinstall may only show packages applicable to your router. Check hardware platform, it has to match ...
by mkx
Wed May 08, 2024 9:23 am
Forum: General
Topic: CRS310-8G+2S+IN brick
Replies: 6
Views: 290

Re: CRS310-8G+2S+IN brick

CRS devices which can dual boot ROS or SwOS are a bit nastier beasts. You said you netinstalled device with "7.11.1-4" which doesn't conform to Mikrotik version notation ... so not sure what exactly did you netinstall, but it might indicate you installed ROS. Indeed winbox should help acce...
by mkx
Wed May 08, 2024 9:14 am
Forum: Beginner Basics
Topic: How to block IP range when NATed?
Replies: 10
Views: 417

Re: How to block IP range when NATed?

I get this BL WL. I will try to make it that way. src-address-list is a path from the root or from some specific dir? I'm not sure I'm getting your question. src-address-list acts similarly to src-address ... but takes name of address list as parameter. You have a feasible address list in your conf...
by mkx
Tue May 07, 2024 10:49 pm
Forum: RouterBOARD hardware
Topic: Fan noise under SwOS on CRS310-8G+2S+
Replies: 3
Views: 231

Re: Fan noise under SwOS on CRS310-8G+2S+

I'd go with ROS without a second thought.

CRS310 can be quite a beast of a router when running ROS v7 (with L3HW) ... when you only need the device as a (higher-end) switch, this may compare to a a pile of chrome and huge alloy rims on a family sedan ... but why not if it's for free? :wink:
by mkx
Tue May 07, 2024 10:45 pm
Forum: Beginner Basics
Topic: How to block IP range when NATed?
Replies: 10
Views: 417

Re: How to block IP range when NATed?

Oh my, what a convoluted firewall. It would be much easier, if you'd have explicit ultimate rule in the line of chain=forward action=drop ... preceeded by explicit allow rules. Now, if you build a black list of addresses, it's wise to have white list as well. So you first accept connections from whi...
by mkx
Tue May 07, 2024 6:43 pm
Forum: General
Topic: Switch VLAN Table Dynamic entries or invalid ports
Replies: 1
Views: 138

Re: Switch VLAN Table Dynamic entries or invalid ports

I think that we should simply forget about anything changing for CRS1xx or CRS2xx. If these were made by any other vendor, they would be long since end of support (probably stuck at running v6.42 or something). Quite a few other devices are in the same boat (all having Qualcomm switch chips or Qualc...
by mkx
Tue May 07, 2024 6:38 pm
Forum: General
Topic: Debian installer (Preseed) fom dhcp
Replies: 1
Views: 176

Re: Debian installer (Preseed) fom dhcp

DHCP server in ROS lacks any of non-essential functionalities.
by mkx
Tue May 07, 2024 6:37 pm
Forum: General
Topic: CRS310-8G+2S+IN brick
Replies: 6
Views: 290

Re: CRS310-8G+2S+IN brick

Winbox and SwOS are two quite distinct things. Winbox is OK for ROS-running devices, one needs web browser for SwOS.
by mkx
Tue May 07, 2024 4:08 pm
Forum: Beginner Basics
Topic: How to block IP range when NATed?
Replies: 10
Views: 417

Re: How to block IP range when NATed?

Show us firewall configuration (execute /ip firewall export file=anynameyouwish from UI, fetch the file off device, open it with text editor and copy-paste it here inside [code] [/code] environment).
by mkx
Tue May 07, 2024 10:59 am
Forum: SwOS
Topic: Features SwOS RB260GS/RB260GSP
Replies: 6
Views: 476

Re: Features SwOS RB260GS/RB260GSP

I think if you better must go for a CRS switch which can offer much better management features because works using RouterOS, is worth the price increase Switching is SOOOO much easier to deal with in SwitchOS... Better and easier can be quite much anti-correlated. And easier can be subjective ... e...
by mkx
Tue May 07, 2024 10:50 am
Forum: RouterBOARD hardware
Topic: NetMetal ax / L23-UGSR — initial feedback from specs
Replies: 5
Views: 418

Re: NetMetal ax / L23-UGSR — initial feedback from specs

1. Any reason it does not support USB 3.0?
USB3.0 can kill 2.4GHz WiFi. USB2.0 can do up to (realistically) 400Mbps, which is not that bad either.
by mkx
Tue May 07, 2024 10:45 am
Forum: RouterBOARD hardware
Topic: 48V or 57V power supply for hEX PoE?
Replies: 7
Views: 530

Re: 48V or 57V power supply for hEX PoE?

Q(PSE): Hi, is there a device on the other end of this cable A(PD): Yes, I am here Q(PSE):Good, which kind of device are you? A(PD): I am an 802.3at device. Q(PSE):That's what you say, let me make sure, are you a 802.3at device? A:(PD):Yes, I am an 802.3at (class 4) device. A:(PSE):Ah, ok, I am giv...
by mkx
Tue May 07, 2024 10:40 am
Forum: RouterBOARD hardware
Topic: I cant solve bufferbloat issue with my hap ac2 router.
Replies: 4
Views: 634

Re: I cant solve bufferbloat issue with my hap ac2 router.

When fasttrack is disabled on hAP ac2, then max throughput is severely limited. My experience with IPv6 (no fasttrack support) shows that hAP ac2 can do somewhere around 350Mbps (give or take). Processing queues adds to CPU workload. So I guess you'd have to drastically reduce queue throughput (to s...
by mkx
Tue May 07, 2024 9:09 am
Forum: RouterBOARD hardware
Topic: RB450Gx4 Performance and POE out
Replies: 3
Views: 2100

Re: RB450Gx4 Performance and POE out

If max power consumption is maximum 16 W, how can the poe out be 57 V x 0.5 A = 18.5 W + 4 W internal use = 22.5 W. I guess that power consumption is calculated with offered powering options (18POW and 24HPOW) in mind, they both supply 24V. So 0.5A * 24V = 12W .. and 4W+12W=16W ... I guess that max...
by mkx
Tue May 07, 2024 9:01 am
Forum: Wireless Networking
Topic: Local vs Capsman Forwarding
Replies: 5
Views: 377

Re: Local vs Capsman Forwarding

So what the goal mikrotik have capsman feature if with this configuration the performance degraded? This feature was just fine with 802.11g (max 54Mbps code rate, 30Mbps actual data throughput) cAPs. A nice feature: CAPsMAN connection can be routed over MAN/WAN links and capsman forwarding in this ...
by mkx
Mon May 06, 2024 12:31 pm
Forum: Beginner Basics
Topic: Different Software-ID on same Model
Replies: 1
Views: 230

Re: Different Software-ID on same Model

I don't think software ID has anything with hardware[*]. I've got two devices RB951G, both purchased around the same time, both came with similar factory installed ROS and firmware, AFAIK there weren't different revisions of this model. And yet they have completely different software ID. [*]it might...
by mkx
Mon May 06, 2024 9:15 am
Forum: Beginner Basics
Topic: Trying to understand the need for MSS Clamping [SOLVED]
Replies: 5
Views: 507

Re: Trying to understand the need for MSS Clamping [SOLVED]

MTU/MSS/MRU was an issue from beginning of internet. In IPv4, packet fragmentation was allowed and until certain point in time, all routers did it if needed. However, it's burden for routers and fragmentation slowly ceased to happen, instead routers started to drop packets which exceeded MTU of next...
by mkx
Sun May 05, 2024 6:39 pm
Forum: RouterBOARD hardware
Topic: Any plans for a hEX PoE+?
Replies: 4
Views: 418

Re: Any plans for a hEX PoE+?

I bought a 48V PoE+ injector hoping I could feed the hEX S PoE-in (this worked) and simultaneously the AP using on eth5 using the PoE-out featuere, only to learn that this doesn't work when the hEX S is powered using PoE-in, even though the injector has more than enough power to supply the two devi...
by mkx
Sun May 05, 2024 6:27 pm
Forum: Announcements
Topic: v7.15rc [testing] is released!
Replies: 211
Views: 52367

Re: v7.15rc [testing] is released!

@kcarhc ... free storage space on 15.3MiB ARM devices is a different issue than RAM memory leak. It's common knowledge (without any speciffic insights) that hAP ac2 running ROS v7 should either be used as pretty simple AP or as router without any wireless package intalled. In both cases it runs pret...
by mkx
Sun May 05, 2024 6:10 pm
Forum: Beginner Basics
Topic: Mopidy issue
Replies: 9
Views: 818

Re: Mopidy issue

... mopidy needs now IP in config. Unless you configured web proxy on Mikrotik, it doesn't change payload of packets ... it can block them (firewall rules) or change source and destination IP address and/or port (NAT rules). As I already wrote, it's client which includes server FQDN in application ...
by mkx
Sun May 05, 2024 4:00 pm
Forum: Beginner Basics
Topic: Mopidy issue
Replies: 9
Views: 818

Re: Mopidy issue

If that's so then it seems mopidy doesn't seem to like being used with that particular name.

Does mopidy have any logs? Anything in them when you're unable to access mopidy using name?
by mkx
Sun May 05, 2024 3:13 pm
Forum: General
Topic: Changing MTU of 10G SFP Port Drops All Traffic On CCR2216
Replies: 3
Views: 304

Re: Changing MTU of 10G SFP Port Drops All Traffic On CCR2216

Thought not sure why you can't connect to it via IP.

My thinking is packets, transmitted by CCR, are too big for management station if that one is not set for jumbo frames as well. Wireshark might tell (probably not), some diagnostic counters on management station's NIC as well.
by mkx
Sun May 05, 2024 3:08 pm
Forum: Announcements
Topic: v7.14.3 [stable] is released!
Replies: 640
Views: 177222

Re: v7.14.3 [stable] is released!

Is there anything about wlan2 in logs since reboot?
by mkx
Sat May 04, 2024 9:13 pm
Forum: General
Topic: Changing MTU of 10G SFP Port Drops All Traffic On CCR2216
Replies: 3
Views: 304

Re: Changing MTU of 10G SFP Port Drops All Traffic On CCR2216

Changing MTU has to be done carefully ... and on all devices in same L3 network (subnet) as every member of eubnet has to be able to receive jumbo packets (MRU usually closely follows MTU). and this relies on all devices being able to use large L2MTU.
by mkx
Fri May 03, 2024 2:23 pm
Forum: RouterBOARD hardware
Topic: Cascading switches
Replies: 9
Views: 536

Re: Cascading switches

@jvanhambelgium - Just curious, why do you want to turn off STP considering there will likely be multiple devices connected to each switch? STP has nothing to do with number of devices connected to each switch, it has to do with loop detection and prevention. While one can never be sure there won't...
by mkx
Fri May 03, 2024 1:52 pm
Forum: General
Topic: [Feather Request] Ignore bad DHCPv6 DUID
Replies: 6
Views: 1900

Re: [Feather Request] Ignore bad DHCPv6 DUID

As @strods explained: the DUID sent out by ISP of @OP is not DUID value , it's only DUID type. So strictly speaking ROS can't treat "DUID as opaque VALUE" because value in this case is NULL. Yeah, probably wouldn't hurt anybody if ROS accepted NULL as DUID value ... but since ROS is doing ...
by mkx
Fri May 03, 2024 1:40 pm
Forum: Beginner Basics
Topic: Mopidy issue
Replies: 9
Views: 818

Re: Mopidy issue

Passing name, with which client is trying to connect server (e.g. SNI), is the matter of application layer, it has nothing to do with router or firewall (which work on lower layers). So why mopidy client doesn't tell mopidy server it's trying to access "music.lan" is up to mopidy client. Y...
by mkx
Fri May 03, 2024 1:28 pm
Forum: Beginner Basics
Topic: PPPoE Connection over SFP Port
Replies: 13
Views: 760

Re: PPPoE Connection over SFP Port

sfp-sfpplus1 interface doesn't seem to be in connected/running state. What does ODI UI say about GPON status? You'll have to verify it's established between SFP+ module and OLT.
by mkx
Thu May 02, 2024 9:13 pm
Forum: Wireless Networking
Topic: What download/upload can I get having such parameters.
Replies: 1
Views: 227

Re: What download/upload can I get having such parameters.

Signal strength and quality are good, there's CA available. If you were the only user in these two cells, you could get something like 150/35 Mbps (R11e-LTE6 doesn't do CA in uplink). Actual performance will very much depend on cell load which varies with time of day and is usually the worst during ...
by mkx
Thu May 02, 2024 4:16 pm
Forum: General
Topic: [Discussion] MikroTik configuration abstraction complexity
Replies: 95
Views: 7060

Re: [Discussion] MikroTik configuration abstraction complexity

Configuration abstraction complexity stems from the simple fact that MikroTik never built their own custom data-plane, they relied on Linux kernel data-plane all these years instead ... Well, Mikrotik obviously doesn't have in-house development resources to go for custom anything large scale. They ...
by mkx
Thu May 02, 2024 11:36 am
Forum: Wireless Networking
Topic: Receive UDP packets without established connection
Replies: 7
Views: 400

Re: Receive UDP packets without established connection

Even though L4 data is unacknowledged type (UDP), WiFi layer (L2 in particular) still requires some bi-directional communication (ACKs of wireless frames for example) when data is sent to unicast destination address. Which means that jamming transmitting side effectively blocks it from transmitting ...
by mkx
Thu May 02, 2024 12:13 am
Forum: Wireless Networking
Topic: Receive UDP packets without established connection
Replies: 7
Views: 400

Re: Receive UDP packets without established connection

What in particular does mean "Mikrotik A is jammed"?
by mkx
Wed May 01, 2024 11:40 pm
Forum: Wireless Networking
Topic: Receive UDP packets without established connection
Replies: 7
Views: 400

Re: Receive UDP packets without established connection

UDP is state-less L4 protocol ... meaning that UDP connections are not really established, there is no connection handshake. Instead one side starts to transmit packets and the other side may (or may not) transmit packets in the opposite direction. Whether traffic is bidirectional or not entirely de...
by mkx
Wed May 01, 2024 8:55 pm
Forum: General
Topic: iperf3 in docker container not showing 10Gb/sec speed
Replies: 5
Views: 515

Re: iperf3 in docker container not showing 10Gb/sec speed

It was my understanding that CRS309-1G-8S+IN can switch at 10Gb/sec on ALL ports, and RB5009UG+S+IN router can handle 10Gb/sec across its SFP+ port. According to my understainding of official test results for RB5009 (and many other long-time forum members' understanding as well) it can route in rea...
by mkx
Wed May 01, 2024 8:45 pm
Forum: Beginner Basics
Topic: bad command name wireless
Replies: 4
Views: 282

Re: bad command name wireless

Where can I read more about it?
This post/thread might be interesting for a start: viewtopic.php?t=202578
by mkx
Wed May 01, 2024 7:08 pm
Forum: Wireless Networking
Topic: wifi-qcom(-ac) and VLAN-filtering
Replies: 17
Views: 1483

Re: wifi-qcom(-ac) and VLAN-filtering

The day I enable capsman on any of my devices, means my brain has been taken over by fungi! It's not very friendly for sure. But worth noting that there is no fast roaming without CAPsMAN... @anav is roaming between Nova Scotia and Italy. No amount of MT's "Fast Transition" will expedite ...
by mkx
Wed May 01, 2024 7:05 pm
Forum: Beginner Basics
Topic: Low performance on RB5009 with machine behind NAT
Replies: 24
Views: 2072

Re: Low performance on RB5009 with machine behind NAT

Cut the shite and allow official ONIE flashing, and let us install our own NOS. If you don't want to use ROS ... and you're saying other vendors provide whitebox devices with similar hardware ... so why would you want to use anything by Mikrotik? I'm guessing you're still intrigued by MT's price ta...
by mkx
Wed May 01, 2024 6:56 pm
Forum: General
Topic: [Discussion] MikroTik configuration abstraction complexity
Replies: 95
Views: 7060

Re: [Discussion] MikroTik configuration abstraction complexity

Many industry folks (outside Latvia) are of the opinion that MikroTik operates using Soviet economic/business model ... It's often very hard to get rid of some mental petterns if they are given (or enforced) to a few generations in a row. One of them is "USA are the greatest in known Universe ...
by mkx
Wed May 01, 2024 6:45 pm
Forum: Beginner Basics
Topic: bad command name wireless
Replies: 4
Views: 282

Re: bad command name wireless

6 S wifi1 wifi 1500 48:A9:8A:F2:68:BC
7 RS wifi2 wifi 1500 48:A9:8A:F2:68:BD

Your device is running new wifi driver, so the config is under /interface/wifi ...

Old driver names interfaces as wlanX ...
by mkx
Wed May 01, 2024 5:24 pm
Forum: Wireless Networking
Topic: Regular Link Outages
Replies: 4
Views: 328

Re: Regular Link Outages

I didn't say it's detecting actual radar, it might be something else which (to ROS) slightly resembles shape of a radar pulse (could be some BlueTooth gadget, could be some microwave owen, could be some other WiFi device transmitting a burst of energy not decodable by your devices, etc. So check log...
by mkx
Wed May 01, 2024 5:14 pm
Forum: General
Topic: /tool wol - target IP address?
Replies: 35
Views: 1990

Re: /tool wol - target IP address?

@libove is stating an almost sensible reason. I don't know why exactly would MSI break standard behaviour (could be they are trying to "enhance security" by ignoring broadcast frames ... or they are trying to skip processing usual broadcast packets, such as DHCP handshake and what not whil...
by mkx
Wed May 01, 2024 12:21 pm
Forum: Wireless Networking
Topic: hAP ax²: clients connection stability issue
Replies: 36
Views: 2429

Re: hAP ax²: clients connection stability issue

Maybe not coincidence because whilst the access point carries out the physical radar check, it could be CAPsMAN that decides what to do with the radar event and which frequency to move to? My reasoning here is that CAPsMAN holds the configuration data on frequency, not the access point? CAPsMAN ind...
by mkx
Wed May 01, 2024 12:08 pm
Forum: Wireless Networking
Topic: Regular Link Outages
Replies: 4
Views: 328

Re: Regular Link Outages

Did logs mention DFS/CAC?

It could be false positive radar detection based on some actual external interference (which appears on some schedule) ...
by mkx
Wed May 01, 2024 12:06 pm
Forum: Wireless Networking
Topic: Wrong TX power wifi-qcom-ac antenna gain missing
Replies: 3
Views: 281

Re: Wrong TX power wifi-qcom-ac antenna gain missing

Missing minimum antenna gain is not something universal, my Audience running wifi-qcom-ac shows (and uses) it. So you may want to create supout.rif and open trouble ticket with support@mikrotik.com ...
by mkx
Wed May 01, 2024 12:02 pm
Forum: General
Topic: /tool wol - target IP address?
Replies: 35
Views: 1990

Re: /tool wol - target IP address?

... at a minimum just please implement the (already submitted) feature request to do unicast instead of only broadcast. Please elaborate on the following two questions: What would be the benefit of using unicast ethernet frames instead of broadcasts? What would be benefit of using unicast IP addres...
by mkx
Wed May 01, 2024 11:58 am
Forum: General
Topic: ipv4 to ipv6
Replies: 1
Views: 227

Re: ipv4 to ipv6

You need NAT46 gateway inside your LAN. I'm pretty sure that ROS doesn't support NAT46 so you'll have to find some other solution.
by mkx
Wed May 01, 2024 11:51 am
Forum: General
Topic: /tool wol - target IP address?
Replies: 35
Views: 1990

Re: /tool wol - target IP address?

I am not even convinced that the encapsulated UDP packet may work ... It won't work without the "last mile router" collecting IP/MAC mappings. Without support on router it'll try to deliver UDP packet just like it was ordinary packet ... and will try to do ARP whohas inquiry which will ob...
by mkx
Tue Apr 30, 2024 8:54 pm
Forum: Wireless Networking
Topic: hAP ax²: clients connection stability issue
Replies: 36
Views: 2429

Re: hAP ax²: clients connection stability issue

Or does the AP that is controlled by capsman do the check.

Radar checks are always done by device which does Tx/Rx ... which means AP.
by mkx
Tue Apr 30, 2024 8:24 pm
Forum: General
Topic: Tool fetch returns error "status: failed" when trying to reach endpoint at localhost program [SOLVED]
Replies: 2
Views: 241

Re: Tool fetch returns error "status: failed" when trying to reach endpoint at localhost program [SOLVED]

Can you fetch data from X.Y.Z.T:7250 using another computer from same subnet? It is possible that your API server only binds to loopback interface (127.0.0.1 a.k.a. localhost).
by mkx
Tue Apr 30, 2024 5:55 pm
Forum: RouterBOARD hardware
Topic: mikrotik mUPS?
Replies: 14
Views: 1192

Re: mikrotik mUPS?

not a bad idea, just to put a lead acid akku instead of li-ion. You can't just replace batteries with different chemistry, each chemistry has different charging profile and (unsuspecting) charger may destroy batteries very soon. Batteries may suffer from undercharge (and usable authonomy is the lea...
by mkx
Tue Apr 30, 2024 5:23 pm
Forum: General
Topic: what can be done to improve RSRQ and SINR
Replies: 1
Views: 177

Re: what can be done to improve RSRQ and SINR

RSRQ (and consequently SINR) could indeed be better. Low RSRQ may indicate interference from other cell towers. If those are in same direction as your serving cell, then you can't do anything. If tce interferring cells are not in the same direction, then you might be able to improve RSRQ by changing...
by mkx
Mon Apr 29, 2024 9:30 pm
Forum: General
Topic: [Discussion] MikroTik configuration abstraction complexity
Replies: 95
Views: 7060

Re: [Discussion] MikroTik configuration abstraction complexity

All old text books circa 1980s LOL At which time Latvia was still part of Soviet Union. So those western (US in particular) books were probably banned ... or at least ignored because Soviet communism did things differently. So it might be that all of these concepts are somehow unknown to MT managem...
by mkx
Mon Apr 29, 2024 9:12 pm
Forum: General
Topic: ONT - SWITCH - Router [SOLVED]
Replies: 3
Views: 526

Re: ONT - SWITCH - Router [SOLVED]

Single bridge with vlan-filtering enabled.

Performance wise all options are similar, CPU will have to deal with VLAN tags in any case.

But: configuration of single bridge is more compact, more elegant and (to me) easier to read ... all of it means lesser probability to make an error in config.
by mkx
Mon Apr 29, 2024 9:02 pm
Forum: General
Topic: /tool wol - target IP address?
Replies: 35
Views: 1990

Re: /tool wol - target IP address?

The WoL magic is all inside the packet payload, meaning ffffffffffff plus the destination MAC address repeated N times. Ethernet headers are only of interest of L2 devices on the way (switches) ... if these (still) have dst-mac in their FDB tables, then they will pass frame on (hopefully) correct eg...
by mkx
Sun Apr 28, 2024 2:01 pm
Forum: General
Topic: date format in console
Replies: 2
Views: 335

Re: date format in console

In historical list of changelogs it's listed in changelog for 7.10 for console and webfig.
by mkx
Sat Apr 27, 2024 3:30 pm
Forum: Beginner Basics
Topic: Constant traffic between Mikrotik and computer
Replies: 8
Views: 565

Re: Constant traffic between Mikrotik and computer

Generally when winbox is connected to RIS device, there will be some traffic. How much depends on windows open in winbox, some get constantly updated with statistics, some don't cause a lot (or any) traffic. Depending on windows open and CPU power in ROS device also CPU load can increase considerabl...
by mkx
Sat Apr 27, 2024 12:32 pm
Forum: Beginner Basics
Topic: Cisco VLAN to Mikrotik
Replies: 1
Views: 290

Re: Cisco VLAN to Mikrotik

Is this enough for make it work? All wrong. Have a (very good) look at this tutorial: https://forum.mikrotik.com/viewtopic.php?t=143620 Your "ROSish" cludge doesn't seem to follow Cisco config (not closely at least), so I'm not trying to show correct config tor MT. If you won't be able to...
by mkx
Sat Apr 27, 2024 12:20 pm
Forum: RouterBOARD hardware
Topic: Adding a cooling fan to CRS326
Replies: 67
Views: 28965

Re: Adding a cooling fan to CRS326

I mean, it's subtle, but I can hear the low hum unless I turn on the radio or TV to drown it out... Congratuations, you found out why legal noise levels in night time are lower than in daytime. Because if there are no other noises present, then sound/noise with certain (low) level is more audible t...
by mkx
Sat Apr 27, 2024 12:11 pm
Forum: General
Topic: Any solution for admit-only-VLAN-tagged misconfiguration
Replies: 16
Views: 792

Re: Any solution for admit-only-VLAN-tagged misconfiguration

But @anav brings up a valid point. If the switch was 100 miles away, how were you managing it before?

It doesn't really matter. If L2 configuration gets screwed, then no amount of L3/L4/L6 connectivity helps. Because all of it depends on working L2.
by mkx
Sat Apr 27, 2024 12:04 pm
Forum: General
Topic: Unable to find wifi radio data after upgrade to 7.14.3
Replies: 3
Views: 448

Re: Unable to find wifi radio data after upgrade to 7.14.3

It is kind of interesting, why device decided to use wrong package. I saw different files in packages then what was before, so I uploaded all of them within one and the same place, expecting routerOS to be intelligent enough to use correct package, but apparently it has happened the other way aroun...
by mkx
Sat Apr 27, 2024 11:49 am
Forum: Beginner Basics
Topic: carry vlans PTP
Replies: 2
Views: 315

Re: carry vlans PTP

Wireless drivers by default don't touch 802.1Q headers ... so if they receive frame with such header on one side (either radio or CPU side), they will pass it to the other side. So what you have to do is to bridge wired and wireless interface on each of SXT and make both interfaces (wired and wirele...
by mkx
Fri Apr 26, 2024 2:04 pm
Forum: General
Topic: This very simple firewall ruleset SHOULD work-- but.....
Replies: 4
Views: 410

Re: This very simple firewall ruleset SHOULD work-- but.....

Sure the dst-address- list is an IP address? This. dst-address-list property expects name of address list as parameter ... and doesn't complain if there isn't such list at the time of creating the rule. So in your case NAT rule expects address list with name "199.181.204.130" and containi...
by mkx
Fri Apr 26, 2024 8:31 am
Forum: RouterBOARD hardware
Topic: Mikrotik CCR1072 PSU1 & PSU2 Question
Replies: 3
Views: 399

Re: Mikrotik CCR1072 PSU1 & PSU2 Question

If you can do a "lab test", then remove PSU2 and see if device keeps running afterwards ... without any hiccups. With failing PSU you'd see strange things happen quite soon.
by mkx
Fri Apr 26, 2024 8:25 am
Forum: Wireless Networking
Topic: hAP ax²: clients connection stability issue
Replies: 36
Views: 2429

Re: hAP ax²: clients connection stability issue

It's called compression ... basic idea behind all compression algorithms is to remove any redundant information from data set ... even if that information doesn't seem redundant to humans' minds.
by mkx
Fri Apr 26, 2024 8:24 am
Forum: Wireless Networking
Topic: External 5G routers
Replies: 3
Views: 364

Re: External 5G routers

5G as in "WiFi 5GHz band" or as in "5G the mobile technology"? If the former, then there are a few models. If the later, then I guess we'll have to wait a bit longer, 5G is still not very mature technology and suitable (to MT) modem modules may not have price tag as low as MT's m...
by mkx
Fri Apr 26, 2024 8:20 am
Forum: General
Topic: Unreachable IPv6 ping from localhost
Replies: 7
Views: 1047

Re: Unreachable IPv6 ping from localhost

This way we see that there is a SLAAC (g) and a DHCP (d) route, which are identical. Only when the the DHCP route is set with the next-hop does the routing actually work. IMO when having two identical routes, either should work (and flags don't matter, they are metadata not routing information). It...
by mkx
Fri Apr 26, 2024 8:02 am
Forum: Announcements
Topic: v7.15rc [testing] is released!
Replies: 211
Views: 52367

Re: v7.15rc [testing] is released!

Where did wifi-qcom-ac package go? can't seems to find in extra package and why?
It's in the extras package archive, where it had always been. However, AFAIK it's only available for ARM architecture(s).
by mkx
Fri Apr 26, 2024 12:03 am
Forum: Wireless Networking
Topic: wifi-qcom(-ac) and VLAN-filtering
Replies: 17
Views: 1483

Re: wifi-qcom(-ac) and VLAN-filtering

So ax products supports bridge VLAN filtering, right?

All products support bridge VLAN filtering. What wifi-qcom-ac doesn't support is being a tagged trunk (or hybrid for that matter) port of a bridge (but wifi-qcom for ax devices does ... in certain scenarios).
by mkx
Fri Apr 26, 2024 12:01 am
Forum: Wireless Networking
Topic: wifi-qcom(-ac) and VLAN-filtering
Replies: 17
Views: 1483

Re: wifi-qcom(-ac) and VLAN-filtering

It should be consistent. It just feels unfinished.

I whole heartedly agree ... and hope that they'll bring them up to the same level eventually.
by mkx
Thu Apr 25, 2024 11:57 pm
Forum: Beginner Basics
Topic: Dynamic port forwarding
Replies: 4
Views: 344

Re: Dynamic port forwarding

Why does a server go down? Makes no sense. There are many reasons for server to go down ... one is that it emits smoke. Snd what @OP wants to do is a "poor man's high-availability". I'm affraid that out of the box, ROS doesn't have such functionality. But there's always possibility to cre...
by mkx
Thu Apr 25, 2024 11:39 pm
Forum: General
Topic: Help with inter VLAN routing (seems to work except web interface?)
Replies: 2
Views: 306

Re: Help with inter VLAN routing (seems to work except web interface?)

This NAT rule add action=dst-nat chain=dstnat dst-port=80 protocol=tcp to-addresses=\ 192.168.188.170 to-ports=80 is very greedy. It takes every connection attempt towards standard HTTP port 80 in any direction (from any of LAN subnets towards any other subnet and internet) and forwards it to the co...
by mkx
Thu Apr 25, 2024 11:24 pm
Forum: General
Topic: Unreachable IPv6 ping from localhost
Replies: 7
Views: 1047

Re: Unreachable IPv6 ping from localhost

Even when the "add-default-route" option is set to "yes", why would the DHCP client not add the correct IPv6 default route if it only requests an address and not a prefix? Because DHCPv6 protocol doesn't support passing routing information to client. And it doesn't matter if cli...
by mkx
Thu Apr 25, 2024 10:55 pm
Forum: General
Topic: RB911G-5HPacD Time Problem
Replies: 6
Views: 773

Re: RB911G-5HPacD Time Problem

I've seen system time to drift wildly on some computer when CPU frequency was not stable (e.g. due to thermal issues). But it was never at only half speed. So I think it's really up to MT support to shed some light here.
by mkx
Thu Apr 25, 2024 4:44 pm
Forum: Beginner Basics
Topic: hap AX3 - HW offloaded Bridge - traffic leak [SOLVED]
Replies: 3
Views: 449

Re: Non-STP Bridge forrwards traffic to other ports [SOLVED]

In theory that has nothing to do with bridge mode (none, STP, RSTP, MSTP). Bridge mode is about loop detection (and blocking ports where loops are detected). What you see is likely effect of improper FDB[*] handling and/or L2 hardware offload. The basic functionality of a bridge (or switch) is that ...
by mkx
Thu Apr 25, 2024 3:56 pm
Forum: Beginner Basics
Topic: Web Proxy - FTP Protocol
Replies: 9
Views: 521

Re: Web Proxy - FTP Protocol

If I try to connect to this FTP I can connect with proxy I cannot. But we need to use proxy because our security department will deploy netskope and limit access to the internet and ports including FTP There may be a bit of misunderstanding here. It's well known that FTP is an awfully outdated prot...
by mkx
Wed Apr 24, 2024 2:20 pm
Forum: General
Topic: Why Mikrotik decided to get rid of their Power Lan devices
Replies: 11
Views: 831

Re: Why Mikrotik decided to get rid of their Power Lan devices

Never heard about "devolo", nor even interested in. There are tons of such devices in the market.
If that's true for one random vendor (devolo), why isn't it also true for another random vendor (mikrotik)?
by mkx
Wed Apr 24, 2024 2:10 pm
Forum: Beginner Basics
Topic: Web Proxy - FTP Protocol
Replies: 9
Views: 521

Re: Web Proxy - FTP Protocol

OK, you did UDP traceroute, which is not really representative for your case (any firewall may let TCP 21 = FTP through, but not UDP 21 which doesn't map to anything). But even if it is representative, it's some host on active24 network edge which seems to drop connection, the last node which replie...
by mkx
Wed Apr 24, 2024 8:57 am
Forum: Beginner Basics
Topic: a basic (I think...) VLAN problem.
Replies: 11
Views: 709

Re: a basic (I think...) VLAN problem.

Traffic does not (and should) not leak from one VLAN to another. If traffic from one VLAN is intended to pass to another VLAN, then normally it should be routed. Config of switch you're showing doesn't include routing features. IEEE1588 (PTP) is normally multicast from GM. And it's normally not rout...
by mkx
Tue Apr 23, 2024 10:03 pm
Forum: General
Topic: Performances issue with PPPoe Client
Replies: 1
Views: 236

Re: Performances issue with PPPoe Client

Yes, it's known that using PPPoE seems to drop throughput more than one would expect (probably not as much as you're observing though). And yes, it is known that running bandwidth test on the device itself does stress CPU to the point it becomes the bottleneck (and taking precious CPU cycles away fr...
by mkx
Tue Apr 23, 2024 9:59 pm
Forum: General
Topic: RB911G-5HPacD Time Problem
Replies: 6
Views: 773

Re: RB911G-5HPacD Time Problem

ROS v6 without optional ntp package runs a SNTP client ... which obtains time every now and then using NTP protocol and adjusts clock (often this means stepping time). You may want to install ntp package which comes with NTP service (you don't have to allow clients to connect), but also tries to adj...
by mkx
Tue Apr 23, 2024 9:51 pm
Forum: General
Topic: RB 2011 UiAS vs RB 3011 UiAs
Replies: 5
Views: 361

Re: RB 2011 UiAS vs RB 3011 UiAs

on /export show-sensitive file=export
expected end of command (line 1 column 9)
export command in ROS v6 doesn't have property show-sensitive ... it's default behaviour. So simply re-run command without this property set.
by mkx
Tue Apr 23, 2024 4:04 pm
Forum: Beginner Basics
Topic: Web Proxy - FTP Protocol
Replies: 9
Views: 521

Re: Web Proxy - FTP Protocol

Personally I'm mostly advising against using ROS device for any high-level service (such as DNS server, web proxy server, file server, ...) if possible. They are, due to space constraints and MT in-house development, mostly quite limited functionality-wise, so using some general-purpose server machi...
by mkx
Tue Apr 23, 2024 3:55 pm
Forum: General
Topic: Cant load a older rsc script after updating to 7.14.3. [SOLVED]
Replies: 4
Views: 378

Re: Cant load a rsc script after updating to 7.14.3. [SOLVED]

Export scripts are not immutable between ROS versions. So there isn't necessarily anything wrong, it could be that there are some changes between both ROS versions which affect the way comands are executed. To see what exactly is wrong, you'll have to debug things. One way would be to post actual er...
by mkx
Tue Apr 23, 2024 12:06 pm
Forum: Wireless Networking
Topic: Wireless communication between 2 Mikrotik Routers
Replies: 7
Views: 449

Re: Wireless communication between 2 Mikrotik Routers

To me the crucial question is: are those devices supposed to connect with each other freely (as if they were connected to same ethernet hub) regardless the side of wireless link they are?
by mkx
Tue Apr 23, 2024 12:02 pm
Forum: Beginner Basics
Topic: invalid mtu 1492 on pppoe-out1
Replies: 5
Views: 415

Re: invalid mtu 1492 on pppoe-out1

PPPoE server may (erroneously) advertise incorrect MTU (in your case it seems as a viable number, sometimes the value is crazily high). At some version, ROS started to log such advetisements, but it otherwise ignores it. In your particular case you may want to try setting 1492 as MTU on your pppoe-o...
by mkx
Tue Apr 23, 2024 11:58 am
Forum: Beginner Basics
Topic: Web Proxy - FTP Protocol
Replies: 9
Views: 521

Re: Web Proxy - FTP Protocol

Web proxy is dealing with HTTP protocol ... specifically when clients are configured to use web proxy they use some extensions of HTTP protocol (so transparent proxying may not work even with unencrypted connections let alone with encrypted ones). FTP is completely different protocol ... and AFAIK R...
by mkx
Tue Apr 23, 2024 9:24 am
Forum: General
Topic: RB 2011 UiAS vs RB 3011 UiAs
Replies: 5
Views: 361

Re: RB 2011 UiAS vs RB 3011 UiAs

And I'll go even further: since the old router is running ancient version of ROS, its config is very likely either customized (to the point of being butchered) or based on ancient defaults. Specially if it's the later case I'd recommend to start from default config on new router (reset to factory de...
by mkx
Tue Apr 23, 2024 9:18 am
Forum: General
Topic: Unreachable IPv6 ping from localhost
Replies: 7
Views: 1047

Re: Unreachable IPv6 ping from localhost

You're doing IPv6 addressing wrong. Your router doesn't really need GUA (global) address on WAN port. However you do need a prefix to make enabling IPv6 on your LAN subnets possible. So instead of your DHCPv6 client config you should use something like this: /ipv6/dhcp-client add interface=ether1_WA...
by mkx
Tue Apr 23, 2024 9:08 am
Forum: General
Topic: Suggestion concerning recently exposed loopback interface. [SOLVED]
Replies: 3
Views: 354

Re: Suggestion concerning recently exposed loopback interface. [SOLVED]

The loopback interface was always there (vital for some operations so removing it would very probably cause some problems), but was hidden up to recent ROS versions. So seeing it is a feature. I'm afraid you'll have to learn to turn the blind eye to it if you don't see any use for it.
by mkx
Tue Apr 23, 2024 9:00 am
Forum: Announcements
Topic: v7.14.3 [stable] is released!
Replies: 640
Views: 177222

Re: v7.14.3 [stable] is released!

E.g. on other manufacturer's equipment, one chain can remain operational while the other scans or surveys the band, monitors neighboring APs, etc. Out of curiosity: what's the price tag of that piece of equipment? And, unless it's got N+1 receivers (where N is MIMO rank), performance of live connec...
by mkx
Mon Apr 22, 2024 11:13 pm
Forum: General
Topic: PPPoE terminating and interfaces shutting down
Replies: 4
Views: 358

Re: PPPoE terminating and interfaces shutting down

recently i started having issues with my mikrotik router. It terminate pppoe, all interfaces shut down for 1 or 2 seconds and they come up again. I'd say that first 4 posted log lines belong to previous event sequence. Events sequence logically begins with flapping all ether ports. Which in turn dr...
by mkx
Mon Apr 22, 2024 11:03 pm
Forum: General
Topic: No DHCP on Bridge VLAN interface.
Replies: 21
Views: 1184

Re: No DHCP on Bridge VLAN interface.

Two things strike me: you only mention adding ether1 to bridge br0 as port in step #2. You don't mention enabling vlan-filtering on br0? Without it, pvid setting doesn't get enforced. The VLAN table definition is borked. Most important: you have to add bridge port as tagged VLAN member for all VLANs...
by mkx
Mon Apr 22, 2024 10:38 pm
Forum: Announcements
Topic: v7.14.3 [stable] is released!
Replies: 640
Views: 177222

Re: v7.14.3 [stable] is released!

This would only be possible if device would have two receivers ... But todays devices all have two, three or four receivers! You know all too well what I meant. And you also know well that chains of a radio (i.e. MIMO legs) are not independent and are not meant to be tuned individually (even if the...
by mkx
Mon Apr 22, 2024 7:38 pm
Forum: Announcements
Topic: v7.14.3 [stable] is released!
Replies: 640
Views: 177222

Re: v7.14.3 [stable] is released!

It would be nice when the AP would make (more) effort to monitor several channels at the same time while looking for a candidate channel... This would only be possible if device would have two receivers ... or DSP software which would allow receiving whole band at the same time. Radars tend to show...
by mkx
Mon Apr 22, 2024 7:27 pm
Forum: Beginner Basics
Topic: Routing/firewalling exceptions
Replies: 4
Views: 278

Re: Routing/firewalling exceptions

Sometimes it's easier not to mess with raw (and notrack) because raw rules are very rigid compared to filter rules (and, AFAIK, connection tracking is crucial for NAT). Instead it's possible to add another accept rule which matches traffic which should not be fasttracked and place it above the fastt...
by mkx
Mon Apr 22, 2024 7:12 pm
Forum: Announcements
Topic: v7.14.3 [stable] is released!
Replies: 640
Views: 177222

Re: v7.14.3 [stable] is released!

It seems to be related to DFS (hence only 5 GHz) and the specific position that they are located in, but definitely not hardware and/or config. If DFS is playing games, then it's mostly configuration (if device admin sees radar detections, then he should set other channels to operate on) and only p...
by mkx
Sun Apr 21, 2024 11:44 pm
Forum: Beginner Basics
Topic: CHATEAU LTE12 MIMO1 and MIMO2
Replies: 40
Views: 21340

Re: CHATEAU LTE12 MIMO1 and MIMO2

Antenna feeder cables should always be as short as possible. It depends on cable quality and frequency used, but it easily exceeds 5dB per 10m. As for the antenna, the almost only important thing is antenna gain (the higher the better), which again depends on frequency used. LTE can use anything bet...
by mkx
Sun Apr 21, 2024 1:38 pm
Forum: General
Topic: fasttrack x86
Replies: 4
Views: 403

Re: fasttrack x86

Fasttrack HW-Offloads established connections to the switch-chip, Wrong. It's one of possibilities, but (currently) it's a niche use. Fasttrack was available way before first devices with L3HW offload came to life. The old fasttrack manual page describes its behaviour nicely. The new help system do...
by mkx
Sun Apr 21, 2024 1:23 pm
Forum: Wireless Networking
Topic: cAP ax as Wi-Fi externder / Ethernet bridge?
Replies: 2
Views: 413

Re: cAP ax as Wi-Fi externder / Ethernet bridge?

CAPsMAN can only provision wifi interfaces after CAP connects to CAPsMAN. From your description I understand that there won't be any wired connection between hAP ax3 and cAP ax, so you'll have to use one of radios on cAP ax for uplink. If you can, I suggest you to dedicate one of radios on cAP ax to...
by mkx
Sun Apr 21, 2024 12:50 pm
Forum: Wireless Networking
Topic: wifi-qcom(-ac) and VLAN-filtering
Replies: 17
Views: 1483

Re: wifi-qcom(-ac) and VLAN-filtering

The recommendation is about setting VLANs in wifi-qcom driver (and wifi-qcom-ac lacks it). This compares to using switch chip part of config for wired ports. The way you worded the recommendation is no the way I understand it, so I can't comment directly on the wording you chose. Alas, the general i...
by mkx
Sun Apr 21, 2024 12:37 pm
Forum: General
Topic: Space ran out on Hap ac2 - is it safe to run it like that long term?
Replies: 3
Views: 423

Re: Space ran out on Hap ac2 - is it safe to run it like that long term?

... wondered if it's safe to run it as is with 0 space available? No, it's not safe, so you should act on it as soon as possible. Very likely it won't just crash (but it might), however it is very likely that it'll experience some problems if it happens to reboot for some reason (e.g. power outage ...
by mkx
Sun Apr 21, 2024 12:29 pm
Forum: General
Topic: fasttrack x86
Replies: 4
Views: 403

Re: fasttrack x86

Mikrotik Know this ?????
I bet they know this. But this is an user-to-user forum, so you have to ask MT directly, e.g. by sending them e-mail to support@mikrotik.com .
by mkx
Sun Apr 21, 2024 12:22 pm
Forum: Beginner Basics
Topic: Which PoE out switch for AX2/AX3 hap's?
Replies: 2
Views: 281

Re: Which PoE out switch for AX2/AX3 hap's?

As both devices only accept 18V-28V, you clearly need PoE switch which does "passive" PoE and is powered with 24V (or there about) power adapter. Next you have to carefully read power specifications of both devices and consider how you're going to use them. If you'll use them as simple APs...
by mkx
Sun Apr 21, 2024 12:14 pm
Forum: Announcements
Topic: v7.14.3 [stable] is released!
Replies: 640
Views: 177222

Re: v7.14.3 [stable] is released!

it hAP ac2 in screenshot? doubts

No, screenshots are from Audience (the other half of setup). @OP never claimed they were from hAP ac2.
by mkx
Sat Apr 20, 2024 11:37 pm
Forum: RouterBOARD hardware
Topic: hEX PoE (RB960PGS)
Replies: 10
Views: 609

Re: hEX PoE (RB960PGS)

Just out of curiosity, would an 802.3af device work plugged in the hEX S passive poe out port? Probably yes. The power negotiation phase (which is the basic difference between passive PoE and 802.3 PoE) in 802.3 af/at is there for PSE (PoE out device) to make sure that power can safely be enabled o...
by mkx
Sat Apr 20, 2024 11:27 pm
Forum: Wireless Networking
Topic: Silly constant wireless roaming breaks internet connection
Replies: 7
Views: 601

Re: Silly constant wireless roaming breaks internet connection

There should be a slight delay for subsequent handovers (to make one and then wait what happens), and/or the signal difference required to initiate one must be much higher. We should be able to specify both parameters. Three handovers within few seconds is way too much and almost never an appropria...
by mkx
Sat Apr 20, 2024 12:51 pm
Forum: Beginner Basics
Topic: Diff configurations or configuration history?
Replies: 3
Views: 431

Re: Diff configurations or configuration history?

The only history (and not really complete) is in logs ... until they persist. What many people do is they periodically create textual export and store them somwhere off device and use appropriate tool to compare different export files. One can use git to store files and use built-in tools to see dif...
by mkx
Sat Apr 20, 2024 12:30 pm
Forum: Wireless Networking
Topic: Silly constant wireless roaming breaks internet connection
Replies: 7
Views: 601

Re: Silly constant wireless roaming breaks internet connection

Roaming is always a RPITA, even on public mobile networks (e.g. LTE) where roaming/handover mechanizms are waaay better that what we have in WiFi. And the only solution is to design wireless signal coverage so that AP signal overlap (areas with similar signal strengths where stations want to roam to...
by mkx
Sat Apr 20, 2024 12:17 pm
Forum: General
Topic: [Feasibility] 6-16 devices with the same IP + computer that wants to access them
Replies: 3
Views: 370

Re: [Feasibility] 6-16 devices with the same IP + computer that wants to access them

You need one L3 interface per device with same IP address. It can either be a router with multiple routed ports or a VLAN-enabled switch with each pirt set as access port to different VLAN and backed with router using many VLANs. There were a few discussions about the same issue before (solutions we...
by mkx
Fri Apr 19, 2024 8:21 pm
Forum: RouterBOARD hardware
Topic: RB5009 - eth 1 (2.5G) keep appears on log with link down - link up several times
Replies: 3
Views: 403

Re: RB5009 - eth 1 (2.5G) keep appears on log with link down - link up several times

Would you recommend any brand?

I only have experience with one particular model (some not-so-recent model by Fluke), so my recommendations aren't very relevant.
by mkx
Fri Apr 19, 2024 2:47 pm
Forum: RouterBOARD hardware
Topic: RB5009 - eth 1 (2.5G) keep appears on log with link down - link up several times
Replies: 3
Views: 403

Re: RB5009 - eth 1 (2.5G) keep appears on log with link down - link up several times

It could be either of devices. But it could be the cable between the two devices. Ideally you'd check the cable using a professional UTP cable tester to verify that the cable is made according to specs (also frequency response and crosstalk, these tend to become a problem with high-speed links). Eve...
by mkx
Fri Apr 19, 2024 2:36 pm
Forum: Beginner Basics
Topic: AP Repeater setup
Replies: 2
Views: 545

Re: AP Repeater setup

I managed to have one ap (A) and the second mikrotik (B) configured as wds slave, but then, when A is off, B doesn't provide an access point. MT doesn't have anything like "fallback" for repeater AP. What often repeater AP does is that it uses radio (master wifi interface) to connect to s...
by mkx
Fri Apr 19, 2024 2:05 pm
Forum: Wireless Networking
Topic: Problems with connecting Samsung Tizen Smart TV to my WIFI network [SOLVED]
Replies: 5
Views: 613

Re: Problems with connecting Samsung Tizen Smart TV to my WIFI network [SOLVED]

Also many (older) IoT devices don't like seeing anything modern being broadcast in their SSID ... such as WPA3 or FT or similar.
by mkx
Fri Apr 19, 2024 12:29 pm
Forum: Wireless Networking
Topic: hAP ac - Slower wifi after RouterOS update
Replies: 11
Views: 641

Re: hAP ac - Slower wifi after RouterOS update

Out of curiosity, though. An antenna gain of 0 is, in my understanding, the maximum gain possiblr. Wouldn't increasing it to another number just make my connection even worse? In theory, antenna gain can be anything between negative infinity and large positive number. In reality most antennas have ...
by mkx
Thu Apr 18, 2024 8:17 pm
Forum: General
Topic: Interface activity doesn't count VLAN traffic
Replies: 4
Views: 361

Re: Interface activity doesn't count VLAN traffic

I am talking about the front LEDs yeah ?
Ah, right.

It could be that leds functionality refers to L3 interface (when configured so). And that excludes tagged traffic. You may want to open a ticket with support@mikrotik.com and have them clarify (and update/ammend help page as well).
by mkx
Thu Apr 18, 2024 7:35 pm
Forum: Beginner Basics
Topic: Upgrade not booting
Replies: 7
Views: 401

Re: Upgrade not booting

When you upliaded all packages, ROS tried to install all. And probably ran out of flash space.

You can do the upgrade, but this time only upload routeros package (base package) and wireless package (from accompanying extras packages). Nothing more.
by mkx
Thu Apr 18, 2024 2:15 pm
Forum: General
Topic: Interface activity doesn't count VLAN traffic
Replies: 4
Views: 361

Re: Interface activity doesn't count VLAN traffic

Actually it does show ... it shows all traffic, passing a physical port (tagged or untagged). If you are not seeing the same way, then explain actual topology and setup so we can see if there's misunderstanding or a possible bug. And what exactly you're observing, it could be I'm referring to someth...
by mkx
Wed Apr 17, 2024 7:49 pm
Forum: Beginner Basics
Topic: Upgrade not booting
Replies: 7
Views: 401

Re: Upgrade not booting

There was a breaking change between 7.12 and 7.13 regarding wireless package: it used to be part of base package before but now it's a separate package. If you use ROS built-in upgrade procedure (/system/packages/upgrade...), it's required to go via 7.12 ... if you upgrade by manually uploading npk ...
by mkx
Wed Apr 17, 2024 4:50 pm
Forum: Beginner Basics
Topic: Loading ONIE images on Mikrotik Switches
Replies: 6
Views: 590

Re: Loading ONIE images on Mikrotik Switches

Another aspect: MT is primarily software company (developing and marketing RouterOS). The rest (hardware, even SwitchOS) is "supporting activities". And they definitely are not heavily into hardware production (AFAIK they design their devices, but manufacturing is outsourced; I may be wron...
by mkx
Wed Apr 17, 2024 4:43 pm
Forum: Beginner Basics
Topic: Firewall rules not applying to bridge
Replies: 3
Views: 386

Re: Firewall rules not applying to bridge

However when trying to make a firewall rule to disallow traffic between the two hosts, it doesn't seem to apply and can still ping to device connected to port 11. Firewall rules act on L3 (IP) ... and that happens when router does routing between two devices. Routing is when both devices are aware ...
by mkx
Tue Apr 16, 2024 8:09 pm
Forum: Wireless Networking
Topic: RB4011iGS+5HacQ2HnD setup with cAP AX [SOLVED]
Replies: 2
Views: 418

Re: RB4011iGS+5HacQ2HnD setup with cAP AX [SOLVED]

I'd like to setup capsman, but I've seen that there are 2 versions. When I look into new one I don't see any interfaces which is suspicious to me. Is that ok? Would it be possible to run RB4011 as capsman server even for cAP AX? If capsman isn't the right way to go, what would be the easiest way to...
by mkx
Tue Apr 16, 2024 7:42 pm
Forum: General
Topic: Downgrade remote station over PtP link
Replies: 4
Views: 389

Re: Downgrade remote station over PtP link

I'm affraid you may have to drive. Unless the following succeeeds. You can try (in lab first!) to do both uninstall and downgrade in single step: upload the routeros package (desired version, e.g. 6.49.14) mark wireless package for uninstallation request downgrade reboot ... and keep fingers crossed
by mkx
Tue Apr 16, 2024 7:30 pm
Forum: General
Topic: /tool wol - target IP address?
Replies: 35
Views: 1990

Re: /tool wol - target IP address?

According to wikipedia article , the WoL magic frame is basically broadcast on ethernet layer, but as payload it does contain MAC address of device which is supposed to wake-up. Then there are extensions which make WoL packets routable (using destination IP address), but need support from "vict...
by mkx
Tue Apr 16, 2024 5:54 pm
Forum: General
Topic: Double destination NAT [SOLVED]
Replies: 2
Views: 413

Re: Double destination NAT [SOLVED]

It's doable, but slightly more complicate, it includes packet marking and using multiple routing tables (which helps ROS to select correct egress interface for each packet). Start by reading this topic.
by mkx
Tue Apr 16, 2024 5:47 pm
Forum: General
Topic: /tool wol - target IP address?
Replies: 35
Views: 1990

Re: /tool wol - target IP address?

Theoretically WOL could be on a BMC with an IP address ... In this case BMC is fully up & running, accepting HTTP / API / whatever conbections and one can use appropriate command to power on the whole system. WOL stands for Wake On LAN, meaning that host's NIC is half alive and ready to receive...
by mkx
Tue Apr 16, 2024 12:08 am
Forum: General
Topic: Network topology for bootstraping. [SOLVED]
Replies: 11
Views: 741

Re: Network topology for bootstraping. [SOLVED]

If you're thinking of a combo "interface is bridge port, but is anchor for a vlan interface" ... then no, it shouldn't be done like that (it falls into category "it shouldn't be used as interface"). The problem in your setup procedure is that you're effectively changing L2 topolo...
by mkx
Mon Apr 15, 2024 11:53 pm
Forum: SwOS
Topic: Create a Native VLAN?
Replies: 1
Views: 329

Re: Create a Native VLAN?

"Trunk with native VLAN" in Cisco is "hybrid" in Mikrotik. So configure port to: "vlan receive - any" and set "default vlan id" to "native VLAN ID" of your choice (e.g. 4000). You have to mark such port as member of VLAN with "native VLAN ID&quo...
by mkx
Mon Apr 15, 2024 11:42 pm
Forum: Wireless Networking
Topic: WiFi AC AR9888
Replies: 1
Views: 318

Re: WiFi AC AR9888

It seems that the only Mikrotik's own wifi card supporting 802.11 ac is R11e-5HacD. And that one is built around QCA9882. If you find a card built around same chipset, chances are that it'll work. Or go for this card if miniPCIe format suits you.
by mkx
Mon Apr 15, 2024 11:26 pm
Forum: General
Topic: Network topology for bootstraping. [SOLVED]
Replies: 11
Views: 741

Re: Network topology for bootstraping. [SOLVED]

I did another test incorporating the changes in my last post and I've now positively identified the point at which I lose connection to be enabling ether1 as a port on br0. It shouldn't come as a surprise. After an interface is "enslaved" as port of a bridge, it shouldn't be used as inter...
by mkx
Mon Apr 15, 2024 3:22 pm
Forum: Announcements
Topic: v7.14.3 [stable] is released!
Replies: 640
Views: 177222

Re: v7.14.2 [stable] is released!

wifi-qcom-ac doesn't support "native" VLAN tagging. So how do you make wifi interface a bridge port?
by mkx
Mon Apr 15, 2024 3:20 pm
Forum: General
Topic: ROS Downgrade issue
Replies: 4
Views: 380

Re: ROS Downgrade issue

Two things to check: list of currently installed packages. In order for downgrade/upgrade to succeed, files with all currently installed packages have to be uploaded to device. After performing next downgrade attempt and after you see it failed, check logs. It will always contain something about upg...
by mkx
Mon Apr 15, 2024 12:30 pm
Forum: General
Topic: Mikrotik RB1100 IP Conflict
Replies: 1
Views: 262

Re: Mikrotik RB1100 IP Conflict

Proxy-ARP might explain that ...
by mkx
Mon Apr 15, 2024 11:31 am
Forum: General
Topic: Network topology for bootstraping. [SOLVED]
Replies: 11
Views: 741

Re: Network topology for bootstraping. [SOLVED]

I'll comment on "just before loosing contact" config on hAP: you should never add vlan interface back to anchor. Like this: /interface vlan add comment=team451 interface=br0 name=team451 vlan-id=500 /interface bridge port add bridge=br0 comment=team451 interface=team451 internal-path-cost=...
by mkx
Mon Apr 15, 2024 9:00 am
Forum: General
Topic: Network topology for bootstraping. [SOLVED]
Replies: 11
Views: 741

Re: Network topology for bootstraping. [SOLVED]

Can you post the "bootstrapped" config of hEX? The one before trying to add ether1 to bridge (which breaks your connectivity)?
by mkx
Mon Apr 15, 2024 8:54 am
Forum: Beginner Basics
Topic: Low performance on RB5009 with machine behind NAT
Replies: 24
Views: 2072

Re: Low performance on RB5009 with machine behind NAT

Yes, and as I pointed out, that's a multi-port aggregate test, not a single-stream single-port test. mkx's point builds atop that. What you're saying makes no sense. It's not like each interface is dedicated to it's own single CPU core, so using more ports won't make the CPU process the packets any...
by mkx
Sun Apr 14, 2024 4:25 pm
Forum: Beginner Basics
Topic: router to mail.hamilton.com
Replies: 9
Views: 543

Re: router to mail.hamilton.com

I just configure ntp client server as pool.ntp.org, so, nothing to do with hamilton.com pool.ntp.org points at a few IP addresses, where public NTP servers reside. Addresses, to which pool.ntp.org resolves, can vary with subsequent DNS queries. And, again: the NTP servers arr volunteered by differe...
by mkx
Sun Apr 14, 2024 3:57 pm
Forum: General
Topic: Marvell 98DX3236 Slow Bandwidth
Replies: 2
Views: 364

Re: Marvell 98DX3236 Slow Bandwidth

Your screenshots show that you're using built-in bandwidth test. It is a well known fact (you're excused since you're new to ROS) that bandwidth test is heavy on CPU and on many device models it itself is a bottleneck. It is recommended to run tests using two external devices, known to be able to cr...
by mkx
Sun Apr 14, 2024 3:48 pm
Forum: Beginner Basics
Topic: Low performance on RB5009 with machine behind NAT
Replies: 24
Views: 2072

Re: Low performance on RB5009 with machine behind NAT

Is it possible to disable connection tracking for the scanner, while still swapping the LAN IP with WAN IP?

Nope, NAT relies on connection tracking. So no connection tracking, no NAT. At least in ROS.
by mkx
Sun Apr 14, 2024 10:47 am
Forum: Beginner Basics
Topic: Low performance on RB5009 with machine behind NAT
Replies: 24
Views: 2072

Re: Low performance on RB5009 with machine behind NAT

Take a look at the RB5009 test results . Your application is the lower rightmost number in the first table, ... Not even that. Tests are using normal long-living connections, so even tests which use tiny packets, can benefit of fast-tracking. OP is doing port scanning, which means that every third ...
by mkx
Sat Apr 13, 2024 11:20 pm
Forum: General
Topic: MSS-clamp equivalent for udp?
Replies: 3
Views: 413

Re: MSS-clamp equivalent for udp?

Just manually override MTU setting of EOIP interface. EOIP does fragment/defragment frames, which are otherwise too large to fit the outer MTU, if needed.
by mkx
Sat Apr 13, 2024 5:11 pm
Forum: Beginner Basics
Topic: netinstall for ax2
Replies: 7
Views: 465

Re: netinstall for ax2

Concentrate on working with ether1, other ports aren't used for netinstall process. Then follow this sequence (it worked most of times on all of my devices): connect cable between ether1 and PC setup PC appropriately (e.g. disable firewall, excess network interfaces, ...) start netinstall executable...
by mkx
Sat Apr 13, 2024 5:02 pm
Forum: RouterBOARD hardware
Topic: hAP ac2 essentially dead after a RouterOS update and multiple resets
Replies: 3
Views: 893

Re: hAP ac2 essentially dead after a RouterOS update and multiple resets

If nothing else helps you'll have to netinstall the device. Note that the process is very fragile and sometimes takes lots of experimenting with different details before it succeeds.
by mkx
Sat Apr 13, 2024 4:57 pm
Forum: RouterBOARD hardware
Topic: Mikrotik DAC between SFP and SFP+ ports
Replies: 2
Views: 577

Re: Mikrotik DAC between SFP and SFP+ ports

I think that passive DACs require both connected devices to be of same SFP generation/variety ... as these DACs more or less simply connect appropriate SFP signal lines together. Many devices have SFP ports that are actually single rate (e.g. SFP+ only supports 10Gbps ... it's the module which can n...
by mkx
Sat Apr 13, 2024 4:25 pm
Forum: Beginner Basics
Topic: Using RB5009 in bridge mode [SOLVED]
Replies: 14
Views: 1489

Re: Using RB5009 in bridge mode [SOLVED]

PPPoE can't really be in bridge mode because bridge is L2 and PPPoE is L3. IP address is "integral part" of L3 interface, it can't be "forwarded" elsewhere. What usually "put in bridge mode" means is that that device is L2-transparrent ... passing either DHCP handshake ...
by mkx
Sat Apr 13, 2024 4:23 pm
Forum: Beginner Basics
Topic: forwarding incoming UPD traffic addressed to the router itself
Replies: 26
Views: 1083

Re: forwarding incoming UPD traffic addressed to the router itself

NATed traffic also gets fasttracked if appropriate rules are set. And in this case indeed rules, which handle traffic initially, don't get hit any more and thus counters don't increment.
by mkx
Sat Apr 13, 2024 10:15 am
Forum: General
Topic: VLAN filtering blocks DHCP Client on trunk port [SOLVED]
Replies: 8
Views: 882

Re: VLAN configuration with active changes [SOLVED]

Clearly 'hiding' the true mac address............ Perhaps you prefer "FU:FU:FU:FU:FU:FU" "=) Yup, I figured as much. But every time I see somebody playing this game (not knowing that MAC addresses are almost the least sensitive information a config can contain), I always wonder what ...
by mkx
Sat Apr 13, 2024 10:12 am
Forum: General
Topic: VLAN filtering blocks DHCP Client on trunk port [SOLVED]
Replies: 8
Views: 882

Re: VLAN filtering blocks DHCP Client on trunk port [SOLVED]

I'll pay close attention to this versus the link you sent me. In particular pay attention to these details: bridge CPU-facing port VLAN membership has to be configured explicitly as well frame-types, tagged/untagged and PVID properties have to be consistent distinction between different properties ...
by mkx
Fri Apr 12, 2024 7:12 pm
Forum: General
Topic: VLAN filtering blocks DHCP Client on trunk port [SOLVED]
Replies: 8
Views: 882

Re: VLAN configuration with active changes [SOLVED]

You have a number of errors in VLAN-related config. I suggest you to go through the definitive guide to ROS VLANing.

BTW, I don't think FF:FF:FF:FF:FF:FF is a valid MAC address for bridge.
by mkx
Fri Apr 12, 2024 7:07 pm
Forum: General
Topic: wifi-qcom-ac Package for 802.11r Fast Transition [SOLVED]
Replies: 2
Views: 534

Re: wifi-qcom-ac Package for 802.11r Fast Transition [SOLVED]

For FT to work, CAP devices have to run wifi-qcom (or wifi-qcom-ac) driver. Which means ROS 7.13+ and ARM architecture. As to CAPsMAN device: it has to run ROS 7.13+ as well. But it doesn't have to run wifi-qcom (or wifi-qcom-ac) as these are "only" wireless chipset drivers. Core functiona...
by mkx
Fri Apr 12, 2024 12:23 pm
Forum: General
Topic: Problem mac telnet into hEX
Replies: 9
Views: 662

Re: Problem mac telnet into hEX

All devices I mentioned, run 7.13.2. None are hEX. Here's export from one of them: /interface bridge add admin-mac=E6:8D:8C:49:EE:4A auto-mac=no name=bridge port-cost-mode=short /interface bridge port add bridge=bridge interface=ether1 internal-path-cost=10 path-cost=10 add bridge=bridge interface=e...
by mkx
Fri Apr 12, 2024 8:44 am
Forum: Wireless Networking
Topic: CAPsMANv2 configuration for secondary SSIDs on different VLANs
Replies: 40
Views: 10150

Re: CAPsMANv2 configuration for secondary SSIDs on different VLANs

- cAP ax: reset config and set it in CAPs mode (this is enough) - CAPsMAN: config datapaths with corresponding VLAN id's Use a hybrid port with management VLAN untagged, Corporate and Guest tagged. Just to clarify: the last line (regarding hybrid port) refers to port to which cAP ax devices are con...
by mkx
Fri Apr 12, 2024 8:32 am
Forum: Virtualization
Topic: P1 license on CHR instance after deadline date
Replies: 3
Views: 518

Re: P1 license on CHR instance after deadline date

I guess you should ask support@mikrotik.com to clarify what happens after 60 days of internet unavailability to licensed CHR. And report back their answer as it'll be probably interesting for a few other people.
by mkx
Thu Apr 11, 2024 9:27 pm
Forum: Beginner Basics
Topic: DHCP client dynamic entries.
Replies: 2
Views: 341

Re: DHCP client dynamic entries.

I guess you have "detect internet" feature enabled ... and adding a DHCP client to interface, which is determined to be a WAN interface, is one of "magic" things which happen. If you have incentive (and knowledge) to fine-tune router's config, then I suggest you to disable "...
by mkx
Thu Apr 11, 2024 3:34 pm
Forum: General
Topic: Issues with inter vlan routing
Replies: 2
Views: 381

Re: Issues with inter vlan routing

Having "connection-state" property set to empty string "" is not the same as not having it set at all. So unset connection-state property on your inter-VLAN firewall rules.
by mkx
Thu Apr 11, 2024 3:29 pm
Forum: General
Topic: Problem mac telnet into hEX
Replies: 9
Views: 662

Re: Problem mac telnet into hEX

Well, by default there is only one bridge. Called, bridge. so I don't know what you mean by "manually set MAC addresses on all bridges" ... I have a few Mikrotik devices on the LAN, each have one bridge and I manually set MAC addresses on each and every bridge. Hence use of plural "b...
by mkx
Thu Apr 11, 2024 3:25 pm
Forum: General
Topic: does the mynetname expires after a while?
Replies: 5
Views: 853

Re: does the mynetname expires after a while?

If you replace old router with a new one and the public IP address is the same, then you'll end up with two A records: <old_SN>.sn.mynetname.net and <new_SN>.sn.mynetname.net ... both pointing at same address. I don't see how this is a problem, if you know <new SN>, then old record won't make any ha...
by mkx
Thu Apr 11, 2024 3:14 pm
Forum: General
Topic: 1-to-1 Nat when outside/public interface is a layer 2 connection [SOLVED]
Replies: 3
Views: 513

Re: 1-to-1 Nat when outside/public interface is a layer 2 connection [SOLVED]

With lots of fiddling it is possible to replace the two 1783-NATR devices with a single "multi purpose" router. But it's not easy as both "private" LANs use same IP address space and this is actually problem from routing point of view. So it is actually much easier to use one NAT...
by mkx
Thu Apr 11, 2024 3:11 pm
Forum: General
Topic: Mikrotik CRS326 RM - WebUI & Winbox disconections
Replies: 5
Views: 652

Re: Mikrotik CRS326 RM - WebUI & Winbox disconections

Are there any of devices you listed in your previous post which are interconnected with more than single UTP cable? In particular I'm thinking of connection between AX88U and CRS326 ... To be on the "fast" side: please ammend the description with exhastive list of connection between the de...
by mkx
Thu Apr 11, 2024 3:02 pm
Forum: Beginner Basics
Topic: Can't ping with firewall (nat)
Replies: 9
Views: 572

Re: Can't ping with firewall (nat)

why is this working and : chain=srcnat action=src-nat to-addresses=10.10.5.50 src-address=10.10.1.0/24 out-interface=ether5 did not work? Because you used wrong address setting for to-address property. The "to-address" property of src-nat rule sets the IP address which will replace the or...
by mkx
Thu Apr 11, 2024 2:55 pm
Forum: Beginner Basics
Topic: port forwarding problem [SOLVED]
Replies: 21
Views: 1770

Re: port forwarding problem [SOLVED]

Are you sure that cameras provide their service on ports 8001 and 8002? I'd guess they are actually using standard port 80 ... in which case NAT rules should have "to-ports=80" set.
by mkx
Thu Apr 11, 2024 2:50 pm
Forum: Beginner Basics
Topic: Slow connections across vlans with hex [SOLVED]
Replies: 12
Views: 1244

Re: Slow connections across vlans with hex [SOLVED]

This is wrong: /interface vlan add interface=ether3 name=CAM88 vlan-id=88 add interface=ether3 name=IoT687 vlan-id=687 add interface=ether3 name=VLAN82 vlan-id=82 add interface=ether3 name=VLAN3000 vlan-id=3000 add interface=ether3 name=WIFI20 vlan-id=20 add interface=ether3 name=WORK999 vlan-id=999...
by mkx
Wed Apr 10, 2024 9:36 pm
Forum: Wireless Networking
Topic: hAP ax3 wireless problem [SOLVED]
Replies: 145
Views: 18536

Re: hAP ax3 wireless problem [SOLVED]

usually the antennas should be vertical, no matter how you install the device Nope. MIMO works best if reception from both Tx antennas is as uncorrelated as possible. Antennas are polarized and with 2x2 MIMO, different polarization makes best possible diversity ... and that's when both antennas are...
by mkx
Wed Apr 10, 2024 3:33 pm
Forum: SwOS
Topic: How to VLAN? [SOLVED]
Replies: 7
Views: 1272

Re: How to VLAN? [SOLVED]

You should set Egress setting on access ports (on SwOS device ports 2-5) to "Always Strip".
by mkx
Wed Apr 10, 2024 3:25 pm
Forum: General
Topic: Problem mac telnet into hEX
Replies: 9
Views: 662

Re: Problem mac telnet into hEX

Mikrotik (and members of the board) advise is that of assigning manually a mac address to the bridge, but it has to be seen if - even if doing that - it would be listed on another device with /tool/mac-telnet ... Just checked ... I have manually set MAC addresses on all bridges ... and /tool/mac-te...
by mkx
Wed Apr 10, 2024 2:46 pm
Forum: General
Topic: Is the PPPOE server built by oneself separated from the PPPOE server of the operator, without affecting each other?
Replies: 4
Views: 371

Re: Is the PPPOE server built by oneself separated from the PPPOE server of the operator, without affecting each other?

Not only in ROS, also elsewhere. VLANs work between devices, if one uses them but the rest don't then they are either no good or interfere with traffic. Here kicks in the suggestion by @loloski: show us the physical/logical network topology (which includes ISP gear) so we can suggest you all the nec...
by mkx
Wed Apr 10, 2024 2:43 pm
Forum: Beginner Basics
Topic: Firewall rule to share device among subnets [SOLVED]
Replies: 8
Views: 636

Re: Firewall rule to share device among subnets [SOLVED]

In Firewall / Address list I create 2 new records with the same name and each should have the subnet? Is this the way?
Yes, enter address with subnet mask, e.g. "192.168.4.0/23"
by mkx
Wed Apr 10, 2024 2:33 pm
Forum: General
Topic: Is the PPPOE server built by oneself separated from the PPPOE server of the operator, without affecting each other?
Replies: 4
Views: 371

Re: Is the PPPOE server built by oneself separated from the PPPOE server of the operator, without affecting each other?

PPPoE works directly over ethernet ... so VRRP and routing etc. doesn't affect it. So yes, ISP's and your own PPPoE servers can interfere with each other. You should separate WAN and LAN on L2 (it seems you don't have it right now, only on L3), VLANs seem a natural solution to your problem (in this ...
by mkx
Wed Apr 10, 2024 2:29 pm
Forum: General
Topic: DHCP IPv6 Dynamic Binding (PPP) - Make Static
Replies: 9
Views: 801

Re: DHCP IPv6 Dynamic Binding (PPP) - Make Static

So far I didn't stumble upon setup where DHCPv6 server was dynamic, so I'm a bit lost here. In your case, how does DHCPv6 server pppoe-sn_dsnw2845b110 get created? Since pools are all static, you should be able to create static DHCPv6 serve as well ... and in that case, you should be able to make le...
by mkx
Wed Apr 10, 2024 2:22 pm
Forum: Beginner Basics
Topic: Firewall rule to share device among subnets [SOLVED]
Replies: 8
Views: 636

Re: Firewall rule to share device among subnets [SOLVED]

I have created a Firewall rule which works, but it gives access also from these subnets 192.168.0.x, 192.168.1.x , 192.168.2.x as well Is it possible to give access only to 192.168.4.0/23 and 192.168.10.0/23 with another way? You'll have to use two rules, each targeting individual subnet. Problem w...
by mkx
Wed Apr 10, 2024 12:26 pm
Forum: RouterBOARD hardware
Topic: Is the RB1100x4 still actively in production?
Replies: 3
Views: 509

Re: Is the RB1100x4 still actively in production?

RB1100AHx4 is still listed as "current device" on Mikrotik web page. So it should be able to buy it. Whether it's from old stock of from production line ... that can only Mikrotik answer (but I highly doubt they would). As to local distributor's stock: they tend to keep in stock models tha...
by mkx
Wed Apr 10, 2024 12:19 pm
Forum: Wireless Networking
Topic: hAP ax3 no internet connection for mobile clients
Replies: 4
Views: 428

Re: hAP ax3 no internet connection for mobile clients

This is really weird. In your opening post you wrote that wireless client can ping gateway (router), but the rest of (internet?) traffic is blocked for a while. But if device wants to communicate with internet, it is sending traffic to router ... and that works as you are saying. You can try to torc...
by mkx
Wed Apr 10, 2024 12:06 pm
Forum: General
Topic: DHCP IPv6 Dynamic Binding (PPP) - Make Static
Replies: 9
Views: 801

Re: DHCP IPv6 Dynamic Binding (PPP) - Make Static

Show config ... the /ipv6/dhcp-server/export part at least.
by mkx
Wed Apr 10, 2024 11:59 am
Forum: General
Topic: Mikrotik CRS326 RM - WebUI & Winbox disconections
Replies: 5
Views: 652

Re: Mikrotik CRS326 RM - WebUI & Winbox disconections

Your topology description is a bit fuzzy ... but combined with log entry it indicates you might have some misconfiguration of your device ...
by mkx
Wed Apr 10, 2024 11:58 am
Forum: General
Topic: DHCP IPv6 Dynamic Binding (PPP) - Make Static
Replies: 9
Views: 801

Re: DHCP IPv6 Dynamic Binding (PPP) - Make Static

Is the prefix pool ... which DHCPv6 uses to fetch prefixes for clients ... a dynamic (i.e. fetched from upstream DHCPv6 server) or a static one?
by mkx
Wed Apr 10, 2024 8:03 am
Forum: Wireless Networking
Topic: hAP ax3 no internet connection for mobile clients
Replies: 4
Views: 428

Re: hAP ax3 no internet connection for mobile clients

The way you explain the symptoms, the problem might be also in ARP entry aging on switches/bridges ... all mentioned devices are part of it, including the TP-link switch. If you can, connect both hAPs to hEX directly just to make sure that TP-link isn't playing games.
by mkx
Wed Apr 10, 2024 7:04 am
Forum: Beginner Basics
Topic: [SOLVED] Prevent connections to IP address
Replies: 4
Views: 376

Re: Prevent connections to IP address

Where are you accessing 192.168.1.40:8123 from, the rest of LAN? If that's so, you can't block traffic on router because traffic between two LAN devices doesn't pass router.
by mkx
Tue Apr 09, 2024 4:22 pm
Forum: Announcements
Topic: WinBox v3.40 released!
Replies: 143
Views: 135475

Re: WinBox v3.40 released!

I'm not trying to diss it (too much) but defending the existing isn't too helpful when you're trying to think outside the existing box. It would really help if you stated what are your wishes/requirements from the new web app. Because there are many things that can already be done, but using a few ...
by mkx
Tue Apr 09, 2024 3:49 pm
Forum: Beginner Basics
Topic: filtering big local lan
Replies: 4
Views: 366

Re: filtering big local lan

Can I improve the rules further?

I don't really have much experience with switch chip ACLs so I can't give you any further assistance.
by mkx
Tue Apr 09, 2024 3:46 pm
Forum: Announcements
Topic: WinBox v3.40 released!
Replies: 143
Views: 135475

Re: WinBox v3.40 released!

I see native WinBox on Linux in my dream when i sleep ))) Which is why IMO effort should be directed at web applications, not native apps. There's already WebFig ... functionality-wise it's on par with WinBox, so no need to re-invent the wheel. But there's a very important difference, which can not...
by mkx
Tue Apr 09, 2024 7:26 am
Forum: Beginner Basics
Topic: I can't ping the external network
Replies: 5
Views: 382

Re: I can't ping the external network

I'm out of ideas ... sorry.
by mkx
Mon Apr 08, 2024 10:07 pm
Forum: Beginner Basics
Topic: I can't ping the external network
Replies: 5
Views: 382

Re: I can't ping the external network

Your config shows that your ROS is using 192.168.10.1 as gateway. Is this correct? Is gateway allowing traffic?
by mkx
Mon Apr 08, 2024 9:55 pm
Forum: General
Topic: UTF-8 representation problem?
Replies: 8
Views: 785

Re: UTF-8 representation problem?

Mikrotik is purported to be working on a "multiplatform client" ... US-ASCII works on all modern platforms just fine :wink: For the record: my native language doesn't fit in any western 8-bit encodings, even less in 7-bit US-ASCII, so I'm grateful for UTF-8. But when it comes to networkin...
by mkx
Mon Apr 08, 2024 9:46 pm
Forum: Beginner Basics
Topic: filtering big local lan
Replies: 4
Views: 366

Re: filtering big local lan

Since both ports connect devices in same subnet, they clearly have to be in same bridge. But: simple bridge (no VLANs, etc.) is by default offloaded to hardware so bridge filters can't catch traffic (bridge is executed by CPU, HW offloaded traffic never leaves switch chip). There are two options: 1)...
by mkx
Mon Apr 08, 2024 9:31 pm
Forum: Beginner Basics
Topic: I can't ping the external network
Replies: 5
Views: 382

Re: I can't ping the external network

If you run comnand
/tool/traceroute 8.8.8.8
what does it show?
by mkx
Mon Apr 08, 2024 11:45 am
Forum: Beginner Basics
Topic: Cloud detects WAN IP, but says it is behind NAT
Replies: 2
Views: 309

Re: Cloud detects WAN IP, but says it is behind NAT

On your router, look in "IP address" and check which IP address is listed for your WAN interface. Then compare it to pubic IP address, reported in various places (cloud is one thing, there are several web pages telling you this information). If they are not the same, then your WAN IP addre...
by mkx
Sun Apr 07, 2024 9:32 pm
Forum: Beginner Basics
Topic: VLAN traffic stalls after starting/stopping flow
Replies: 5
Views: 811

Re: VLAN traffic stalls after starting/stopping flow

If you want any feedback from MT support, then you'll have to open support ticket. This is merely an user forum, hosted on MT's servers ... and occasionally visited by MT staffers. It is not means of official support.
by mkx
Sun Apr 07, 2024 6:29 pm
Forum: Wireless Networking
Topic: hAP AX3 5G range troubleshooting
Replies: 62
Views: 3588

Re: hAP AX3 5G range troubleshooting

Out of interest, inSSIDer is reporting signal strength of ~-50 but the hAP ax2 log shows about -20 lower. Why the difference? Each device reports strength of signal received from the link peer . inSSIDer is reporting signal strength of AP, received by laptop. And hAP ax3 reports signal strength of ...
by mkx
Sun Apr 07, 2024 6:15 pm
Forum: Beginner Basics
Topic: Cannot access HAPax3 wireless config html/webpage [SOLVED]
Replies: 2
Views: 399

Re: Cannot access HAPax3 wireless config html/webpage [SOLVED]

By default, device considers ether1 to be WAN port and management is not possible via that port. Management is possible via all other ports (including wireless). However: by default it also serves as router and its LAN address is 192.168.88.1/24 ... which conflicts with your existing LAN. The best w...
by mkx
Sun Apr 07, 2024 2:10 pm
Forum: Wireless Networking
Topic: hAP ax3 wireless problem [SOLVED]
Replies: 145
Views: 18536

Re: hAP ax3 wireless problem [SOLVED]

WAF?

It doesn't hurt either, so why do you bother?
by mkx
Sun Apr 07, 2024 10:52 am
Forum: General
Topic: DNS in NTP client?
Replies: 16
Views: 6300

Re: DNS in NTP client?

What's wrong with server-dns-names property? Used instead of primary-ntp and secondary-ntp?
by mkx
Sat Apr 06, 2024 3:02 pm
Forum: RouterBOARD hardware
Topic: RB5009 2,5Gbe problems [SOLVED]
Replies: 29
Views: 9403

Re: RB5009 2,5Gbe problems [SOLVED]

I am one of these "others" as well :) I connect to ISP using SFP module ...
Ah, OK, that explains it.
by mkx
Sat Apr 06, 2024 1:39 pm
Forum: RouterBOARD hardware
Topic: RB5009 2,5Gbe problems [SOLVED]
Replies: 29
Views: 9403

Re: RB5009 2,5Gbe problems [SOLVED]

I cannot tell difference when it comes to CPU usage on RB5009. Both before and after disabling HW offload it's ~30% when transferring between WAN and LAN @ 2Gbit speed. That's because vast majority of CPU resourdes are used for firewalling, some for routing and only minor portion for interface hand...
by mkx
Sat Apr 06, 2024 11:14 am
Forum: Wireless Networking
Topic: hAP Reset After Power Outage and Don't Reconnect
Replies: 2
Views: 522

Re: hAP Reset After Power Outage and Don't Reconnect

One of possible outcomes of using reset button is configuration reset to factory defaults (which doesn't include CAPsMAN). Another one is to put device into CAP mode.

You can do that also via any of UIs (I'd suggest you winbox as it allows connection even if device doesn't have usable IP setup).
by mkx
Sat Apr 06, 2024 11:09 am
Forum: Wireless Networking
Topic: hAP ax3 wireless problem [SOLVED]
Replies: 145
Views: 18536

Re: hAP ax3 wireless problem [SOLVED]

For many years we have been using "United states" here in Ukraine )) ... We can use 12,13 channels in 2,4GHz, but in real life we have a lot of American gadgets IMO the first one explains the second one. But the second one doesn't explain the first one, using Ukraine country settings does...
by mkx
Sat Apr 06, 2024 11:01 am
Forum: General
Topic: 1x RB5009 + 3x hAP ax^3 - Hotspot VLAN Radius Help
Replies: 9
Views: 731

Re: 1x RB5009 + 3x hAP ax^3 - Hotspot VLAN Radius Help

While we wait to be joined by @mkx

Nah, not my piece of pie. There are too many buzzwords in the thread title which I don't do (hotspot, radius, ...).
by mkx
Sat Apr 06, 2024 10:46 am
Forum: Beginner Basics
Topic: Can't use IPv6 provider prefix [SOLVED]
Replies: 1
Views: 343

Re: Can't use IPv6 provider prefix [SOLVED]

Better ask your ISP about possibilities. Either they could configure their router to hand out prefixes (preferrably larger than /64, /60 would be fine), or to bridge mode do that your MT would be talking to tgeir core directly (I guess tgat in this case your MT would receive prefixes). The way it is...
by mkx
Sat Apr 06, 2024 10:38 am
Forum: Announcements
Topic: v7.14.3 [stable] is released!
Replies: 640
Views: 177222

Re: v7.14.2 [stable] is released!

When someone disables that graphic... doesn't it get removed from the storage?
Only the stats data ... which I guess is a few kB. But graphics library and anything else needed stays installed ... probably most of it is needed for WebFig graphs anyway.
by mkx
Sat Apr 06, 2024 10:36 am
Forum: Announcements
Topic: v7.14.3 [stable] is released!
Replies: 640
Views: 177222

Re: v7.14.2 [stable] is released!

If someone want to partition, I'd say 64MB would be the minimum acceptable. It might if ROS was changed to use RAM disks more aggressivelly. As it is now, 128MB on audience isn't enough (or it wasn't back in v7.5 times), with 64MB partitions upgrade didn't succeed due to lack of flash space. It's b...
by mkx
Fri Apr 05, 2024 8:38 pm
Forum: General
Topic: Firewall/Routing Question
Replies: 19
Views: 884

Re: Firewall/Routing Question

At Router A, what does the router see.......... It should see source being user from RouterB with destination IP of server on Router A LAn, ( if traffic is sourcenatted, the source IP would be the wireguard IP of B ). The rule I suggested for site B is a dst-nat ... so src-address is not changed. T...
by mkx
Fri Apr 05, 2024 3:22 pm
Forum: Wireless Networking
Topic: mAntBox 15ax superchannel is missing...
Replies: 10
Views: 646

Re: mAntBox 15ax superchannel is missing...

Can we expect some solution in this problem? The only solution is to forget about superchannel altogether ... it wasn't obeying country-specific regulatory constraints and as such is illegal. Since majority of users didn't care about country regulations (and created havoc), EU (and many other count...
by mkx
Fri Apr 05, 2024 3:15 pm
Forum: Announcements
Topic: v7.14.3 [stable] is released!
Replies: 640
Views: 177222

Re: v7.14.2 [stable] is released!

subprofile can be assigned to main configuration profile, which can be assigned to interface. Subprofile values can be overwritten in main configuration profile, and all values can be overwritten on the interface itself. The problem I an see is that often users consider properties set to empty valu...
by mkx
Fri Apr 05, 2024 3:10 pm
Forum: General
Topic: Firewall/Routing Question
Replies: 19
Views: 884

Re: Firewall/Routing Question

You can make the NAT rule as general as you want. But it may soon break something else. For example establishment of wireguard tunnel (tunnel might drop momentarily while siteA address doesn't change and then wireguard connection may get NAT-ed to 192.168.0.1 which is not accessible until after wire...
by mkx
Fri Apr 05, 2024 2:53 pm
Forum: General
Topic: CCR abnormal interface status
Replies: 4
Views: 376

Re: CCR abnormal interface status

What is connected to such a port?

It could be some device in sleep mode ... often LAN interfaces are configured into 10Mbps half-duplex mode (which seems to require least amount of power). But seeing it go up for a second and then down again is a bit weird.
by mkx
Fri Apr 05, 2024 12:42 pm
Forum: General
Topic: How to do Inter-VLAN Bridging with MikroTik? [SOLVED]
Replies: 15
Views: 992

Re: How to do Inter-VLAN Bridging with MikroTik? [SOLVED]

But only with an L2 misconfiguration, i.e. if I put, say, ether1 through ether4 in bridge1, set up a few VLAN interfaces on bridge1 and then put them all in bridge2. The problem will be that the moment a packet actually gets bridged between VLANs, it will need to first get flooded to all ports in b...
by mkx
Fri Apr 05, 2024 12:24 pm
Forum: General
Topic: IPv6 trouble [SOLVED]
Replies: 19
Views: 1687

Re: IPv6 trouble [SOLVED]

The ether1-gateway WAN interface has RA effectively disabled (ra-lifetime=none) On my routers I set "advertise=no" to addresses which are not supposed to be advertised (so no RA for that particular address). And it seems that if an interface doesn't have any address without this setting, ...
by mkx
Fri Apr 05, 2024 12:12 pm
Forum: General
Topic: Firewall/Routing Question
Replies: 19
Views: 884

Re: Firewall/Routing Question

No, hairpin NAT is not the problem here, communication between client on site B and server on Site A has to pass router (actually both of them) in both directions (if it doesn't, then one needs hairpin NAT). The problem here is selection of the route from site B to site A (and back) when client uses...
by mkx
Fri Apr 05, 2024 9:20 am
Forum: Beginner Basics
Topic: Not getting wireline speeds
Replies: 28
Views: 1314

Re: Not getting wireline speeds

So it is the usual case of two very different things that - in order to better distinguish them - are called in Mikrotikish with the same or a very similar name. Sort of homonyms or homographs. Well not really. Routing is pure L3 function and according to that, all devices which MT says support L3H...
by mkx
Fri Apr 05, 2024 12:06 am
Forum: Beginner Basics
Topic: Not getting wireline speeds
Replies: 28
Views: 1314

Re: Not getting wireline speeds

Mkx posted that this switch supports L3HW offloading. You just re-stated that it doesn't. One of the two must be accurate, not both. We're both right ... I already mentioned that L3HW offload in this switch only covers routing, not firewalling. And @chechito is talking about firewalling in his late...
by mkx
Thu Apr 04, 2024 11:36 pm
Forum: General
Topic: HW Offloading
Replies: 11
Views: 1128

Re: HW Offloading

None of the CRS3XX series of switches then has L3HW offloading if I had to base it on ethernet test results ( very slow ).

Generally I don't really trust test results from MT. So in this case I'd go with documentation, like official L3HW offload manual with its L3HW Device Support section.
by mkx
Thu Apr 04, 2024 11:32 pm
Forum: General
Topic: HW Offloading
Replies: 11
Views: 1128

Re: HW Offloading

Didn't somebody mention routers a few posts higher?
Just to be clear is HW offloading possible on some routers regarding its chip, completetely different from L3HW offloading discussed for switches?
by mkx
Thu Apr 04, 2024 11:25 pm
Forum: General
Topic: How to do Inter-VLAN Bridging with MikroTik? [SOLVED]
Replies: 15
Views: 992

Re: How to do Inter-VLAN Bridging with MikroTik? [SOLVED]

I can create a VLAN interface with id=1, that's for sure. But it appears that it's either not capturing traffic, You're right, it's not capturing traffic. Reason being that native VLAN comes untagged off bridge interface while any VLAN interface expects tagged frames on "anchor" side. If ...
by mkx
Thu Apr 04, 2024 11:12 pm
Forum: General
Topic: HW Offloading
Replies: 11
Views: 1128

Re: HW Offloading

RB5009 doesn't support L3HW offload. On routers that do (those have capable switch chips built in), the L3GW offload concept is the same as on switches. The difference is in the effectiveness of handling traffic which for some reason (e.g. route prefixes already offloaded use up all the ASIC route p...
by mkx
Thu Apr 04, 2024 10:49 pm
Forum: General
Topic: Firewall/Routing Question
Replies: 19
Views: 884

Re: Firewall/Routing Question

Is there a way to make it so that I can browse to A.dyndns.org:81 It may be possible to construct a DST-NAT combination on router of site B which would work most of time ... except in time periods after change of A public IP address (because A.dyndns.org has to be updated and TTL of the old record ...
by mkx
Thu Apr 04, 2024 9:01 am
Forum: Beginner Basics
Topic: wifi24 in italics, dhcp server gives invalid..
Replies: 6
Views: 664

Re: wifi24 in italics, dhcp server gives invalid..

Have seen this when you have removed names from userlist and they are pointed at from another setting. I know. I was hinting @OP to remove those because clearly they are remnants of something not needed any more. Probably they are not the reason for problems though, but it's always good to have cle...
by mkx
Thu Apr 04, 2024 8:28 am
Forum: Beginner Basics
Topic: Not getting wireline speeds
Replies: 28
Views: 1314

Re: Not getting wireline speeds

Sirbyran, lets make it real, ..................... @Sirbyran is referring to CRS310 capability of doing L3HW offloading: https://help.mikrotik.com/docs/display/ROS/L3+Hardware+Offloading#L3HardwareOffloading-L3HWDeviceSupport That makes CRS310 a wirespeed router. But, as he also noted, it can suppo...
by mkx
Thu Apr 04, 2024 8:24 am
Forum: Beginner Basics
Topic: wifi24 in italics, dhcp server gives invalid..
Replies: 6
Views: 664

Re: wifi24 in italics, dhcp server gives invalid..

What are these two entries? /interface bridge port add bridge=bridge comment=defconf interface= *6 /interface bridge port add bridge=bridge comment=defconf disabled=yes interface= *7 Does log have anything about wifi24 and DHCP server? Best to reboot device and check log immediately after it comes u...
by mkx
Thu Apr 04, 2024 8:07 am
Forum: General
Topic: WiFi Isolation Using VLANs
Replies: 2
Views: 315

Re: WiFi Isolation Using VLANs

Additionally, I've noticed in some tutorials that firewalls are used to block access between VLANs. If I'm required to use a firewall, what's the purpose of using VLANs? This is a common knowledge, the same for all network vendors (in no way specific to Mikrotik): OSI layers can explain some of you...
by mkx
Wed Apr 03, 2024 10:43 pm
Forum: Wireless Networking
Topic: hAP ac3 5GHz antenna-gain locked, using 6
Replies: 20
Views: 1167

Re: hAP ac3 5GHz antenna-gain locked, using 6

What if I use long feeder cables? How can I compensate attenuation? Minimum antenna gain is only fixed for devices with permanently attached antennas. Devices, which only have antenna connectors and one has to use external antennas, don't have it set (or they have it set to 0). I don't think that u...
by mkx
Wed Apr 03, 2024 9:47 pm
Forum: General
Topic: Downgrading RouterOS
Replies: 10
Views: 5925

Re: Downgrading RouterOS

Did you check log after reboot (which was supposed to downgrade but failed to do so)?
by mkx
Wed Apr 03, 2024 9:36 pm
Forum: General
Topic: CCR2004-1G-12S+2XS: IPv4 routing performance less than IPv6?
Replies: 4
Views: 464

Re: CCR2004-1G-12S+2XS: IPv4 routing performance less than IPv6?

Both sfp-sfpplus8 and bond/9+10 are trunk (all tagged) ports. So how are hosts configured regarding VLANs? And, BTW, you didn't post full config. So I'll assume you're just trolling and not expecting to get any usable advice if you won't post full config (sensitive data obfuscated, not left out).. I...
by mkx
Wed Apr 03, 2024 1:02 pm
Forum: General
Topic: EoIP Log Entries explanation requested
Replies: 2
Views: 234

Re: EoIP Log Entries explanation requested

I'd say it's normal. I see similar stuff on my IPIP links (it also uses IPsec under the hood).
by mkx
Wed Apr 03, 2024 12:47 pm
Forum: Beginner Basics
Topic: Any idea?
Replies: 1
Views: 261

Re: Any idea?

Do all leases show all-zero MAC addresses or just some? Lease list showing such MAC address usually indicates that the lease was offered but the handshake did not finish. Could be that the devices (webcams) only perform first part of handshake (getting lease offer) but not the second part (mutual ac...
by mkx
Wed Apr 03, 2024 12:42 pm
Forum: General
Topic: Downgrading RouterOS
Replies: 10
Views: 5925

Re: Downgrading RouterOS

when i /system/packages/downgrade the system reboots but doesnt downgrade to 7.13 You have to manually upload NPKs for all packages currently running (e.g. routeros and wireless) for the target version and correct architecture. then execute "downgrade" and reboot. After router boots up, i...
by mkx
Wed Apr 03, 2024 10:16 am
Forum: General
Topic: bridge vlan across a routed network
Replies: 3
Views: 307

Re: bridge vlan across a routed network

You want to use EOIP to bridge vlan500 interface on HQ mikrotik and whatever vlan interface (can be 500 as well, I don't see a reason to have it different) on branch office mikrotik.
by mkx
Wed Apr 03, 2024 9:23 am
Forum: General
Topic: How to do Inter-VLAN Bridging with MikroTik? [SOLVED]
Replies: 15
Views: 992

Re: How to do Inter-VLAN Bridging with MikroTik? [SOLVED]

(I also don't quite like how the router has to have a separate address for each VLAN, this seems pretty unnecessary) It seems that you don't quite understand the (V)LAN concept, do you? I haven't read your explanation in depth, just skimmed it ... and it seems to me you want to have a flat LAN, so ...
by mkx
Wed Apr 03, 2024 9:20 am
Forum: General
Topic: CCR2004-1G-12S+2XS: IPv4 routing performance less than IPv6?
Replies: 4
Views: 464

Re: CCR2004-1G-12S+2XS: IPv4 routing performance less than IPv6?

Show us the config. From what is shown so far and what you explained it seems like IPv4 is being routed while IPv6 is being bridged ... but only look at config can tell what you actually have.
by mkx
Wed Apr 03, 2024 9:16 am
Forum: Beginner Basics
Topic: Using CRS309-1G-8S+IN as switch with MLAG [SOLVED]
Replies: 4
Views: 727

Re: Using CRS309-1G-8S+IN as switch with MLAG [SOLVED]

How about showing complete config of your switches? What you've shown is not complete. And since you don't know where the error is, I don't think you can decide which part of config is relevant and which isn't. But I agree that you have lots of holes in your VLAN setup (and errors as well), so it's ...
by mkx
Wed Apr 03, 2024 7:09 am
Forum: Beginner Basics
Topic: DHCP Server - DNS blank or router IP [SOLVED]
Replies: 8
Views: 598

Re: DHCP Server - DNS blank or router IP [SOLVED]

Generally the argument to give clients real DNS is some clients is additional caching slows upstream changes from appearing as quickly (e.g. since there cached, clients have to wait for the TTL to expire and unable to "force" DNS to re-resolve)... Every recursive DNS resolver (including y...
by mkx
Tue Apr 02, 2024 3:17 pm
Forum: General
Topic: bridge vlan across a routed network
Replies: 3
Views: 307

Re: bridge vlan across a routed network

You can't bridge L2 networks (that's what VALNs are) over L3 (IP) just like that. You need some L2 tunnel, running on top of L3 ... in MT world (both routers are MT according to your description) that's EIOP. Beware that EOIP alone doesn't encrypt traffic, so you may want to run EIOP on top of IPsec...
by mkx
Tue Apr 02, 2024 3:12 pm
Forum: Beginner Basics
Topic: Does "Detect Internet" actually do anything?
Replies: 15
Views: 8485

Re: Does "Detect Internet" actually do anything?

As @normis said: this function is intended to detect (and autoconfigure to certain extent) WAN-facing interfaces (which is a very good thing). However, the experience is that detection success rate is lower than we would all love to see and when it fails, then the whole router starts to behave in ra...
by mkx
Tue Apr 02, 2024 12:15 pm
Forum: SwOS
Topic: netpower SwitchOS - fiber ring topology
Replies: 1
Views: 243

Re: netpower SwitchOS - fiber ring topology

You can do the ring. But make sure RSTP is enabled. And I suggest you to make bridge priority on CSS, connected to uplink, lower than the rest of devices (e.g. to (0x)4000) so that it wins root bridge selection ... selection about which segment of your fiber ring will be disabled will be made relati...
by mkx
Tue Apr 02, 2024 11:20 am
Forum: Wireless Networking
Topic: 802.11b required for me but missing in ROS7 WiFi [SOLVED]
Replies: 12
Views: 1029

Re: 802.11b required for me but missing in ROS7 WiFi [SOLVED]

But, a few devices now cant connect to the new wireless network: Another thought: did you try to remove those devices from your wireless network and re-add them? I seem to remember this was necessary on certain smart phones (but not all of them ... all running various versions of Android) when I st...
by mkx
Tue Apr 02, 2024 10:40 am
Forum: Wireless Networking
Topic: 802.11b required for me but missing in ROS7 WiFi [SOLVED]
Replies: 12
Views: 1029

Re: 802.11b required for me but missing in ROS7 WiFi [SOLVED]

You should enable CCMP cipher - screenshot shows that note of ciphers are selected and I don't know what's default.

Also try to disable FT, it's another AP capability which some clients may trip over.
by mkx
Tue Apr 02, 2024 10:35 am
Forum: General
Topic: [ask] how to check mac address on vlan
Replies: 4
Views: 365

Re: [ask] how to check mac address on vlan

If you have bridge with vlan-filtering, then something like /interface/bridge/host/print where vid=<vlan id> where <vlan id> is VLAN ID you want to query. Another possibility (not sure if it's available on all ROS devices): /interface/ethernet/switch/host/print where vlan-id=<vlan id>
by mkx
Tue Apr 02, 2024 9:24 am
Forum: Wireless Networking
Topic: 802.11b required for me but missing in ROS7 WiFi [SOLVED]
Replies: 12
Views: 1029

Re: 802.11b required for me but missing in ROS7 WiFi [SOLVED]

There are a few settings available in new wifi configuration which might upset older stations (in no particular order): enabling wpa3 authentication type enabling anything but "ccmp" and "ccmp-256" as encryption type setting "management-protection" to anything other tha...
by mkx
Tue Apr 02, 2024 9:17 am
Forum: Wireless Networking
Topic: configure "cAP ac" to "RB4011iGS+RM" router
Replies: 4
Views: 332

Re: configure "cAP ac" to "RB4011iGS+RM" router

One prerequisite is to have wireless package installed on RB4011 (not wifi-qcom-ac ... which drops support for 2.4GHz radio on RB4011 anyway). Then you have to configure things in /capsman configuration subtree. When everything is configured there correctly, you should be able to put your cAP ac int...
by mkx
Tue Apr 02, 2024 9:06 am
Forum: Beginner Basics
Topic: VLANs seems not to isolate each other [SOLVED]
Replies: 3
Views: 488

Re: VLANs seems not to isolate each other [SOLVED]

... but I can ping and get access from VLAN 10 to 11 ... In addition to what @CGGXANNX wrote also note that due to how firewall works, router will respond to pings regardless which of its IP address is being targeted (e.g. pinging router's address in VLAN 11 from a client inside VLAN 10). It is pos...
by mkx
Mon Apr 01, 2024 5:29 pm
Forum: Announcements
Topic: v7.14.3 [stable] is released!
Replies: 640
Views: 177222

Re: v7.14.2 [stable] is released!

Could the "memory leak" be due to 0 disk space available?
It might ... because ROS might be caching writes to flash. AFAIK that's not what linux kernel usually does though.
by mkx
Mon Apr 01, 2024 5:25 pm
Forum: General
Topic: IPv6 trouble [SOLVED]
Replies: 19
Views: 1687

Re: IPv6 trouble [SOLVED]

I've set pool-prefix-lenght=64 on the dhcpv6 client, but did not made a difference. From various posts about my KPN ipv6 settings, I always found 48 to be used and I see the prefix I get is also /48. My feeling tells me that 48 is all I will get? The pool-prefix-length property sets the prefix size...
by mkx
Mon Apr 01, 2024 3:58 pm
Forum: General
Topic: hap AC^2 upgrade to 7.14.2 - broken device with bootloop [SOLVED]
Replies: 7
Views: 776

Re: hap AC^2 upgrade to 7.14.2 - broken device with bootloop [SOLVED]

The port that you should NOT (normally) use for netinstall is ether1 (or anyway WAN ports) try one of ether2+. See: https://forum.mikrotik.com/viewtopic.php?t=206301 Wrong. Netinstall is always done via ether1 (which is usually WAN port) ... and this includes devices with single (management) ether ...
by mkx
Mon Apr 01, 2024 3:56 pm
Forum: General
Topic: hap AC^2 upgrade to 7.14.2 - broken device with bootloop [SOLVED]
Replies: 7
Views: 776

Re: hap AC^2 upgrade to 7.14.2 - broken device with bootloop [SOLVED]

Try these steps:
  1. Disconnect everything
  2. Start netinstall on linux machine
  3. Connect ethernet cable brtween PC and ether1
  4. Press reset and keep pressing it until step #6
  5. Plug in power plug
  6. When netinstall executable on linux machine detects hAP ac2, release reset button
by mkx
Mon Apr 01, 2024 3:52 pm
Forum: General
Topic: I'm trying to setup VLANs but I get no gateway
Replies: 4
Views: 361

Re: I'm trying to setup VLANs but I get no gateway

Guess it is a good idea to set up the router from scratch. Before[*] starting from scratch, have a look at this tutorial to get an idea about how VLANs are properly done in ROS. [*] I wrote "before" not because you shouldn't tear your config apart but to learn how to do it properly from s...
by mkx
Mon Apr 01, 2024 3:47 pm
Forum: General
Topic: hap AC^2 upgrade to 7.14.2 - broken device with bootloop [SOLVED]
Replies: 7
Views: 776

Re: hap AC^2 upgrade to 7.14.2 - broken device with bootloop [SOLVED]

Netinstall does work in vast majority of cases. But it's a very fragile process (a bit less so if using linux netinstall) so it may take some (or many) tries to make evrything click together.
by mkx
Mon Apr 01, 2024 2:15 pm
Forum: General
Topic: IPv6 trouble [SOLVED]
Replies: 19
Views: 1687

Re: IPv6 trouble [SOLVED]

Set pool-prefix-length=64 on your DHCPv6 client.

And why all those advertise-*=no in ipv6 nd setup?
by mkx
Mon Apr 01, 2024 10:02 am
Forum: General
Topic: DHCP Lease Status Offered
Replies: 3
Views: 357

Re: DHCP Lease Status Offered

Post MT's config. Without it it's not clear what you mean by saying "I am using DHCP on VLAN"...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 41