Community discussions

MikroTik App

Search found 15585 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 52
by anav
Thu Mar 30, 2023 1:18 am
Forum: General
Topic: Can't ping between subnets on the same bridge
Replies: 27
Views: 514

Re: Can't ping between subnets on the same bridge

But of course, any OP STORY is pure conjecture, hearsay and usually wrong and the only thing that really counts is evidence aka the config. Even harder is getting the true requirements. If I read one more time I cant ping between subnets, i will reply, THEN GO MARRY THE FUCKING SUBNETS, pinging has ...
by anav
Thu Mar 30, 2023 1:14 am
Forum: General
Topic: Dual connection routing help required
Replies: 3
Views: 95

Re: Dual connection routing help required

A diagram would help because you failed to describe a switch which seems central to your setup, hiding information is not helpful. Since you didnt disclose the switch I will ignore it. Put all vlans on bridge, not on ether1 and forget switch.......... Furthermore what are these half done dst nat rul...
by anav
Thu Mar 30, 2023 1:01 am
Forum: General
Topic: Dynamic interface address in mangle rule
Replies: 3
Views: 93

Re: Dynamic interface address in mangle rule

State the requirement more clearly, mangling is a tool it is not a reason.
A config pops from requirements not the other way round.
What is the traffic issue you are facing.
by anav
Thu Mar 30, 2023 12:56 am
Forum: General
Topic: RB5009 IPSec Performance
Replies: 33
Views: 12842

Re: RB5009 IPSec Performance

Wow I would be happy with 500Mbps speeds based on their test results, you are doing better then they did.
(512 bytes are real world, ignore the other columns)
by anav
Thu Mar 30, 2023 12:55 am
Forum: General
Topic: Routing problem, new setup
Replies: 6
Views: 202

Re: Routing problem, new setup

Im confused, are these both just one flat network. All users are on the same subnet?? If there were vlans per subnet that would make sense ( for example one could have a trusted subnets with two SSIDs, 2.4 and 5ghz and the rest different vlans for diff purposes, guest wlan 5ghz, iot 2ghz, media 2ghz...
by anav
Thu Mar 30, 2023 12:50 am
Forum: General
Topic: Dual connection routing help required
Replies: 3
Views: 95

Re: Dual connection routing help required

CONFIG?

/export file=anynameyouwish ( minus router serial number and public wanip information )
by anav
Thu Mar 30, 2023 12:49 am
Forum: Beginner Basics
Topic: How to add second CRS326-24G-2S+RM with complex VLAN setup
Replies: 9
Views: 309

Re: How to add second CRS326-24G-2S+RM with complex VLAN setup

Why the LAG construct??? I dont know what is the correct way to approach bridge and vlans.??? Why not just push the vlans on a single trunk port to a switch......... In any case these /interface bridge vlan entries dont do anything..... add bridge=bridge1 comment="VLAN 16 - FAMILY" vlan-id...
by anav
Thu Mar 30, 2023 12:45 am
Forum: Beginner Basics
Topic: VLAN configuration RB750gr3
Replies: 3
Views: 90

Re: VLAN configuration RB750gr3

sounds good so APs it is.

A network diagram is helpful as is seeing the current stat of the config
/export file=anynameyouwish ( minus router serial number and any public WANIP information)

As per viewtopic.php?p=908118
by anav
Thu Mar 30, 2023 12:42 am
Forum: Beginner Basics
Topic: Connect Mikrotik to other router with WLAN for access to printer
Replies: 3
Views: 116

Re: Connect Mikrotik to other router with WLAN for access to printer

Good day............. It looks like both of your routers do not have public IP so thats not a good start. Can you access the ISP modem on the open wrt router side and forward ports to the openwrt router from the ISP router? As for the MT behind the LTE device, can you get a custom APN for a private ...
by anav
Wed Mar 29, 2023 11:54 pm
Forum: Beginner Basics
Topic: Dual WAN Configuration
Replies: 1
Views: 58

Re: Dual WAN Configuration

/export file=anynameyouwish (minus router serial number and any public WANIP Info )
by anav
Wed Mar 29, 2023 11:53 pm
Forum: Beginner Basics
Topic: VLAN configuration RB750gr3
Replies: 3
Views: 90

Re: VLAN configuration RB750gr3

YOu have to decide whether you want vlans or just assign etheports directly. The problem may be you dont know what you want yet. Vlans are necessary when you want to send more than one subnet on any given port....................in your case doesnt seem to apply? They are extremely flexible to apply...
by anav
Wed Mar 29, 2023 8:17 pm
Forum: Useful user articles
Topic: Config Issues / Locked Out - Aceessing Router/AP Config Without Bridge
Replies: 10
Views: 9431

Re: Config Issues / Locked Out - Aceessing Router/AP Config Without Bridge

THe default name for an etherport is ether5 Many people change the name to suit their purposes....... or keep the default. /interface ethernet set [ find default-name=ether2 ] set [ find default-name=ether3 ] set [ find default-name=ether4 ] name="ether3 - Fiber to Store 02" set [ find def...
by anav
Wed Mar 29, 2023 8:08 pm
Forum: General
Topic: Routing problem, new setup
Replies: 6
Views: 202

Re: Routing problem, new setup

by anav
Wed Mar 29, 2023 8:06 pm
Forum: Beginner Basics
Topic: How to add second CRS326-24G-2S+RM with complex VLAN setup
Replies: 9
Views: 309

Re: How to add second CRS326-24G-2S+RM with complex VLAN setup

and the reason not to provide the config/evidence on RB4011 is?????
by anav
Wed Mar 29, 2023 7:18 pm
Forum: Beginner Basics
Topic: Disconnected from LAN port and All other connections loose IP!
Replies: 11
Views: 448

Re: Disconnected from LAN port and All other connections loose IP!

Yeah, now I can read this thread again.......... my firefox knew it was bad news the rest of you do not have as smart as a fox as I do........

Seeing as you didnt fix the issues I brought up NO COMMENT this round. Try again.
by anav
Wed Mar 29, 2023 7:15 pm
Forum: General
Topic: Can't ping between subnets on the same bridge
Replies: 27
Views: 514

Re: Can't ping between subnets on the same bridge

1. You can only use one subnet assigned to a bridge is my understanding. Once you want more then vlans is the way! 2. Alternatively you dont need a bridge and can assigne each etherport a subnet. Its clean and simple to use vlans. PS. I also find it very confusing to use /26 and all IP addresses see...
by anav
Wed Mar 29, 2023 7:12 pm
Forum: Beginner Basics
Topic: Wireguard Mikrotik's S2S redirect all traffic
Replies: 1
Views: 55

Re: Wireguard Mikrotik's S2S redirect all traffic

In general --> https://forum.mikrotik.com/viewtopic.php?t=182373 New Poster --> https://forum.mikrotik.com/viewtopic.php?p=908118 Basically a diagram speaks volumes Config of all three devices required /export file=anynameyouwish ( minus router serial number and any publicWANIP information ) However...
by anav
Wed Mar 29, 2023 6:48 pm
Forum: General
Topic: Can't ping between subnets on the same bridge
Replies: 27
Views: 514

Re: Can't ping between subnets on the same bridge

Easy, One bridge ( no dhcp on bridge ) All vlans with interface bridge Forward chain last rule add action=drop chain=forward. ++++++++++++++++++++++++++++++++++++++++++ Then rules above last rule are simple --> only what you allow allow all vlans to internet allow A to C allow C to A NO rules requir...
by anav
Wed Mar 29, 2023 5:37 pm
Forum: Wireless Networking
Topic: 802.11r for hAP ac2?
Replies: 32
Views: 3724

Re: 802.11r for hAP ac2?

Where did you see that Holve... WifiWave2 FULLY replaces old wifi. Its one or the other not both. As for RB4011 turn wifi off and get a capax ;-P
by anav
Wed Mar 29, 2023 5:35 pm
Forum: General
Topic: Dynamic interface address in mangle rule
Replies: 3
Views: 93

Re: Dynamic interface address in mangle rule

Yes!
by anav
Wed Mar 29, 2023 3:31 pm
Forum: Beginner Basics
Topic: WHY Does One Thread LOCKUP my Firefox
Replies: 5
Views: 143

Re: WHY Does One Thread LOCKUP my Firefox

Well my firefox is zippier and all thread works except that one.......................
by anav
Wed Mar 29, 2023 3:26 pm
Forum: Beginner Basics
Topic: WHY Does One Thread LOCKUP my Firefox
Replies: 5
Views: 143

Re: WHY Does One Thread LOCKUP my Firefox

That doesnt explain why every other thread works fine including this one....... will try
...
badthread.JPG
by anav
Wed Mar 29, 2023 3:15 pm
Forum: RouterOS beta and rc versions
Topic: Wireguard use Hostname in endpoint
Replies: 62
Views: 13264

Re: Wireguard use Hostname in endpoint

Your personal issues have nothing to do with MT functionality! ;-)

Seriously my condolences for the 'family situation', its easy to forget not everyone is so lucky. :-(
by anav
Wed Mar 29, 2023 3:13 pm
Forum: Beginner Basics
Topic: WHY Does One Thread LOCKUP my Firefox
Replies: 5
Views: 143

WHY Does One Thread LOCKUP my Firefox

I can enter any thread and add posts etc, but this post locks up my computer, anyone else have this issue??
Sometimes the thread is half visible, and certainly cannot enter any new posts.

viewtopic.php?t=194837
by anav
Wed Mar 29, 2023 3:10 pm
Forum: RouterOS beta and rc versions
Topic: Wireguard use Hostname in endpoint
Replies: 62
Views: 13264

Re: Wireguard use Hostname in endpoint

Because, one doesnt have to expose ones's public IP on the internet to host servers........ THEREFORE ITS intrinsically more secure IT avoids all the users with so many useless firewall traps to try to stop people hitting on servers etc......... Clean, efficient and secure. Effects I would say conse...
by anav
Wed Mar 29, 2023 2:52 pm
Forum: RouterOS beta and rc versions
Topic: Wireguard use Hostname in endpoint
Replies: 62
Views: 13264

Re: Wireguard use Hostname in endpoint

Start on post 8, 28, 29 and further down. Various solutions have been presented to circumvent this problem (until they finally solve it in ROS itself, where it should be solved) AMEN TO THAT BROTHER, I already put in a request and nothing, so the more people that do...............the better chance ...
by anav
Wed Mar 29, 2023 2:51 pm
Forum: Wireless Networking
Topic: 802.11r for hAP ac2?
Replies: 32
Views: 3724

Re: 802.11r for hAP ac2?

There is nothing funny and nothing to hate but your own stupidity if made bad decisions knowing full well the limitations of older gen WIFI, after your first foray into mt wifi. I learned my lesson on capac and ended up with 3 thinking I was on top of the world.........wrongo, so yes, hate but hate ...
by anav
Wed Mar 29, 2023 2:42 pm
Forum: Beginner Basics
Topic: How to add second CRS326-24G-2S+RM with complex VLAN setup
Replies: 9
Views: 309

Re: How to add second CRS326-24G-2S+RM with complex VLAN setup

Step 1 - take a port of the bridge to use for configuration purposes give it an IP address liek 192.168.55.1/24 and add it to a management interface list, give your laptop an iPV4 address such as 192.168.55.5 and you are in. That way smooth sailing during bridge and vlan changes!! https://forum.mikr...
by anav
Wed Mar 29, 2023 2:34 pm
Forum: General
Topic: DHCP problem between 2 MikroTik devices
Replies: 8
Views: 255

Re: DHCP problem between 2 MikroTik devices

Note to pe1chl and ammo........... dont forget your ABCs......
viewtopic.php?p=908118

Or NOT, if you like playiing whackamole and guessing games. ;-P
by anav
Wed Mar 29, 2023 4:18 am
Forum: General
Topic: Routing problem, new setup
Replies: 6
Views: 202

Re: Routing problem, new setup

Without the config of each CAP, should I use my crystal ball ???
Duplicate mac address??
by anav
Tue Mar 28, 2023 4:11 pm
Forum: General
Topic: Very high traffic on Firewall "Drop all traffic not from Lan" rule
Replies: 5
Views: 362

Re: Very high traffic on Firewall "Drop all traffic not from Lan" rule

Updated it last night so some changes.
by anav
Tue Mar 28, 2023 2:26 pm
Forum: Beginner Basics
Topic: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]
Replies: 38
Views: 1709

Re: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]

Like I said, care little how you handle ISp1 or ISp2 in terms of table and scheduling.
You simply need the first routing rule to be dst-address for the wireguard subnet and your windows laptop should be able to now receive the return traffic from device on .42 and .30
by anav
Mon Mar 27, 2023 11:02 pm
Forum: General
Topic: Modern way to stop ISP customers with WEB redirect
Replies: 9
Views: 341

Re: Modern way to stop ISP customers with WEB redirect

Are you using hotspot functionality?
by anav
Mon Mar 27, 2023 10:03 pm
Forum: Beginner Basics
Topic: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]
Replies: 38
Views: 1709

Re: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]

However, you do have two exceptions which need to go out to the internet and thus we need to tweak these rules...... FROM /routing rule add action=lookup-only-in-table dst-address=172.11.2.0/24 table=main { ensures wireguard return traffic will get back into the tunnel } add action=lookup-only-in-ta...
by anav
Mon Mar 27, 2023 9:56 pm
Forum: Beginner Basics
Topic: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]
Replies: 38
Views: 1709

Re: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]

Okay I understand now ISp1 and ISp2 are simply for access of linksys to get internet. Thats fine, and schedule works two, but not sure how that works..... The rules I have implemented ensure ether1 is primary and ether2 is secondary. Since it doesnt really matter and you have a way of alternating th...
by anav
Mon Mar 27, 2023 9:53 pm
Forum: Beginner Basics
Topic: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]
Replies: 38
Views: 1709

Re: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]

OKAY lets fix your setup. Assuming ether1 is priority. If ether2 is the priority reverse the gateways. By priority I mean all MT traffic 192.168.30.0/24, and 192.168.42.0/24 would follow the routes. Local traffic will deviate because you also create 'forcing' routing rules. /ip route add distance=5 ...
by anav
Mon Mar 27, 2023 8:35 pm
Forum: Beginner Basics
Topic: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]
Replies: 38
Views: 1709

Re: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]

Okay let me get this straight. One you are connected to the www in three different ways and have no firewall rules ??? On the mikrotik router you have two fixed WANIPs to two different providers ether1 and ether2. On the mikrotik you have two LANS, one for users 192.168.42.0/24 on ether5, and one to...
by anav
Mon Mar 27, 2023 7:51 pm
Forum: General
Topic: Port forward from LTE [SOLVED]
Replies: 28
Views: 550

Re: Port forward from LTE [SOLVED]

Will adjust article accordingly!!
by anav
Mon Mar 27, 2023 7:05 pm
Forum: General
Topic: Port forward from LTE [SOLVED]
Replies: 28
Views: 550

Re: Port forward from LTE [SOLVED]

As long as a. you have a proper formatted dst-nat rule b. have the default firewall rule blocking all WAN traffic except for dst-nat or own rule allowing dst-nat OR no firewall rules (meaning all is permitted). It should work. If it does not then it would seem you are stuck and need to contact ISP f...
by anav
Mon Mar 27, 2023 6:37 pm
Forum: General
Topic: Port forward from LTE [SOLVED]
Replies: 28
Views: 550

Re: Port forward from LTE [SOLVED]

/export file=anynameyouwish ( minus serial number and any public WANIP information )
by anav
Mon Mar 27, 2023 6:10 pm
Forum: General
Topic: How to deal with MTU size
Replies: 8
Views: 258

Re: How to deal with MTU size

Concur!
by anav
Mon Mar 27, 2023 6:03 pm
Forum: Wireless Networking
Topic: House wifi6 network with Mikrotik AX or Audience
Replies: 29
Views: 2849

Re: House wifi6 network with Mikrotik AX or Audience

I wish it were true. If I wanted set to defaults and that was it, I wouldnt buy MT for wifi. MT for wifi should provide the ability for the user to setup the config optimized for ones particular scenario. The structure and presentation should lead to a logical setup methodology. So far all I see is ...
by anav
Mon Mar 27, 2023 5:48 pm
Forum: General
Topic: how to fix lazy-ass ISP DHCP lease?
Replies: 21
Views: 613

Re: how to fix lazy-ass ISP DHCP lease?

Sending you a cat gif......... Cause you are so patient and helpful that I want to give you a................. https://media.tenor.com/fRIfg-otefcAAAAC/kith-cat.gif
by anav
Mon Mar 27, 2023 5:38 pm
Forum: General
Topic: Routing to another VLAN through VPN
Replies: 3
Views: 298

Re: Routing to another VLAN through VPN

As stated, a diagram well labelled for context and full config to marry up words and pictures with actual evidence.
/export file=anynameyouwish ( minus router serial number and any public WANIP information )
by anav
Mon Mar 27, 2023 5:13 pm
Forum: General
Topic: how to fix lazy-ass ISP DHCP lease?
Replies: 21
Views: 613

Re: how to fix lazy-ass ISP DHCP lease?

Too much water will have to pass under the bridge before there is only IPv6...
Translation: No need to wait for IPV6, you are welcome anytime and the sooner the better and yes Belgium, Slovenia and Czechia pale in comparison!!
by anav
Mon Mar 27, 2023 5:09 pm
Forum: General
Topic: how to fix lazy-ass ISP DHCP lease?
Replies: 21
Views: 613

Re: how to fix lazy-ass ISP DHCP lease?

Time to move on to IPv6! Agree.... Be careful what you wish for! I am barely grasping ipv4 fundamentals. If they switch to IPV6, I hope you have a spare bed in your house because I will be there for intensive training, oh and perhaps a little sampling of the fine foods and beverages ........ :-) My...
by anav
Mon Mar 27, 2023 5:03 pm
Forum: Beginner Basics
Topic: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]
Replies: 38
Views: 1709

Re: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]

To get it straight. Ether5 is the main LAN subnet and is 192.168.42.0/24 Ether3 is a LAN subnet to the Linksys Router where the Linksys Router gets its WANIP from ( and how the linksys gets its VPN connection ). Ether4 is WHAT , purpose etc...??? You have a wireguard server on the router for handsha...
by anav
Mon Mar 27, 2023 4:55 pm
Forum: Beginner Basics
Topic: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]
Replies: 38
Views: 1709

Re: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]

Yes, you would create a wireguard for the third party provider. I would keep a separate one for your own needs AKA remote into your router when travelling etc. You can always use the third party one for internet while remote as well. The latter question not so easy. In most VPN providers you get one...
by anav
Mon Mar 27, 2023 3:56 pm
Forum: Beginner Basics
Topic: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]
Replies: 38
Views: 1709

Re: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]

Sure you do,,,,,,,, get a wireguard account with a third party vpn provider just like you have on the linksys.
ExpressVPN doesnt have wirguard yet? ..... many others do.

You are making your config needlessly complex.
by anav
Mon Mar 27, 2023 3:39 am
Forum: Beginner Basics
Topic: How to implement VLAN in my Home-Network
Replies: 2
Views: 159

Re: How to implement VLAN in my Home-Network

When you want to use one bridge and you want to use the TPLINK as a proper vlan switch not port based, will help.
by anav
Mon Mar 27, 2023 3:37 am
Forum: Beginner Basics
Topic: Wiregurad setup on hAP ac2 - locked out of router
Replies: 3
Views: 156

Re: Wiregurad setup on hAP ac2 - locked out of router

email me check my profile.
by anav
Sun Mar 26, 2023 11:46 pm
Forum: Beginner Basics
Topic: Need help getting port forwarding to work
Replies: 3
Views: 157

Re: Need help getting port forwarding to work

What is this for?? /ip dhcp-server network add address=0.0.0.0/24 dns-server=0.0.0.0 gateway=0.0.0.0 netmask=24 Why do you have this set to your bridge??? Remove it. /ip dhcp-client add comment=defconf interface=bridgeLocal The WAN is your WiFI not the bridge................. add interface=wlan1 lis...
by anav
Sun Mar 26, 2023 11:41 pm
Forum: Beginner Basics
Topic: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]
Replies: 38
Views: 1709

Re: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]

from ether3 on Mikrotik router there is a LAN interface go t o the VPN router -(to WAN interface on VPN Router)- That is my point what VPN router? You only have two connections to the internet. Where is this VPN router located and what make or model is it? Then you have a link back to the mT on eth...
by anav
Sun Mar 26, 2023 11:38 pm
Forum: Beginner Basics
Topic: Help needed for Router-Switch-AP (all in one) scenario
Replies: 20
Views: 519

Re: Help needed for Router-Switch-AP (all in one) scenario

I think so, your idea is the correct one for sure......
by anav
Sun Mar 26, 2023 10:06 pm
Forum: Beginner Basics
Topic: Help needed for Router-Switch-AP (all in one) scenario
Replies: 20
Views: 519

Re: Help needed for Router-Switch-AP (all in one) scenario

A hybrid ether4 setup. /interface bridge port add bridge=BR1 frame-types=admit-only-untagged-and-priority-tagged interface=\ ether2 pvid=20 add bridge=BR1 frame-types=admit-only-untagged-and-priority-tagged interface=\ ether3 pvid=20 add bridge=BR1 frame-types=admit-only-untagged-and-priority-tagged...
by anav
Sun Mar 26, 2023 9:53 pm
Forum: Beginner Basics
Topic: Help needed for Router-Switch-AP (all in one) scenario
Replies: 20
Views: 519

Re: Help needed for Router-Switch-AP (all in one) scenario

Completely useless link, This one seems better --> https://cdn.cnetcontent.com/63/39/6339b2d6-cdfa-4913-9ef9-94aade99d29a.pdf However it would appear HP has quite an involved process which I trust you have mastered. There should be three vlans going to the HP VLAN99 to give it an IP address on the b...
by anav
Sun Mar 26, 2023 7:24 pm
Forum: Beginner Basics
Topic: Help needed for Router-Switch-AP (all in one) scenario
Replies: 20
Views: 519

Re: Help needed for Router-Switch-AP (all in one) scenario

Yes completely normal. Every trunk port be it MT, DSTINK, NETCRAP, TP-SHTINK has the native vlan1 set on every port. Its transparent and in the background. The only time it changes is if one sets a pvid, access port which replaces vlan id 1. The MT is configured properly suggest you figure out what ...
by anav
Sun Mar 26, 2023 7:20 pm
Forum: Beginner Basics
Topic: Disconnected from LAN port and All other connections loose IP!
Replies: 11
Views: 448

Re: Disconnected from LAN port and All other connections loose IP!

Quick Look. 1. Decide on etherport type as an ACCESS port ( add pvid ) or TRUNK Port and change frame types. /interface bridge port add bridge=bridge comment=defconf frame-types=\ admit-only-untagged-and-priority-tagged interface=ether2 pvid=missing 2. Same issue with etherport 10......................
by anav
Sun Mar 26, 2023 6:08 pm
Forum: Beginner Basics
Topic: Help needed for Router-Switch-AP (all in one) scenario
Replies: 20
Views: 519

Re: Help needed for Router-Switch-AP (all in one) scenario

Hehehe your attention to detail is lousy........ Whey did you keep pvid on a Trunk port, remove please. /interface bridge port add bridge=BR1 frame-types=admit-only-untagged-and-priority-tagged interface=\ ether2 pvid=20 add bridge=BR1 frame-types=admit-only-untagged-and-priority-tagged interface=\ ...
by anav
Sun Mar 26, 2023 5:47 pm
Forum: Beginner Basics
Topic: 100Mbps on a 2011UiAS
Replies: 8
Views: 278

Re: 100Mbps on a 2011UiAS

Yeah, its hard to know with such an old version of firmware.
by anav
Sun Mar 26, 2023 5:02 pm
Forum: Beginner Basics
Topic: Help needed for Router-Switch-AP (all in one) scenario
Replies: 20
Views: 519

Re: Help needed for Router-Switch-AP (all in one) scenario

Yes if you are honest with the information provided. Are you saying the RB2011 is NOT a router here, but simply acting as an AP.Switch behind an upstream router that is handing out DHCP??? If now you are actually stating that the WAP should get both vlan20 and vlan10 tagged then of course it wont wo...
by anav
Sun Mar 26, 2023 5:00 pm
Forum: Beginner Basics
Topic: 100Mbps on a 2011UiAS
Replies: 8
Views: 278

Re: 100Mbps on a 2011UiAS

Sounds like its the cable, what else would cap it suspiciously just under 100mbps ?
by anav
Sun Mar 26, 2023 4:59 pm
Forum: RouterOS beta and rc versions
Topic: mDNS repeater feature
Replies: 288
Views: 64286

Re: mDNS repeater feature

Maybe para 5 ( which at the bottom has a link to another solution ). - viewtopic.php?t=194646
by anav
Sun Mar 26, 2023 4:55 pm
Forum: Scripting
Topic: Help for block user use netshare
Replies: 15
Views: 1439

Re: Help for block user use netshare

Since the device is not under your control, I dont see how you expect to be able to do anything from the MT side............... The only advice I would say is start charging based on usage vice connection and that will allow you to make money regardless if one, two , 10 users are sharing a single vi...
by anav
Sun Mar 26, 2023 4:49 pm
Forum: Beginner Basics
Topic: Disconnected from LAN port and All other connections loose IP!
Replies: 11
Views: 448

Re: Disconnected from LAN port and All other connections loose IP!

The evidence, that matters is the lastest config, not picture...........
by anav
Sun Mar 26, 2023 4:46 pm
Forum: Beginner Basics
Topic: Help needed for Router-Switch-AP (all in one) scenario
Replies: 20
Views: 519

Re: Help needed for Router-Switch-AP (all in one) scenario

Then clearly you had not only a mismatch between /interface bridge ports and /interface bridge vlan but also both had errors. Remember an ACCESS port strips tags on the way out for the identified PVID and puts them back on for returning traffic. A Trunk port carries the vlans to the other side. A Hy...
by anav
Sun Mar 26, 2023 4:15 pm
Forum: Beginner Basics
Topic: Help needed for Router-Switch-AP (all in one) scenario
Replies: 20
Views: 519

Re: Help needed for Router-Switch-AP (all in one) scenario

NO, you have setup ether4 to strip the vlan tag when leaving the port ( access port pvid=XX ) and then adding the tag back in when the data from the AP comes back into the router port. If your intention was to send tagged data to the AP, then this assumes the AP is a smart AP??? What are you sending...
by anav
Sun Mar 26, 2023 4:02 pm
Forum: Beginner Basics
Topic: Help needed for Router-Switch-AP (all in one) scenario
Replies: 20
Views: 519

Re: Help needed for Router-Switch-AP (all in one) scenario

Next time please dont use verbose unless requested LOL> Sorry for not picking this up the first go around! Here it is......... /ip pool add name=BLUE_POOL ranges=10.0.10.2-10.0.10.254 add name=GREEN_POOL ranges=192.168.10.50-192.168.10.254 add name=BASE_POOL ranges= 192.168.0.254-192.168.88.10 Shoul...
by anav
Sun Mar 26, 2023 3:58 pm
Forum: RouterOS beta and rc versions
Topic: mDNS repeater feature
Replies: 288
Views: 64286

Re: mDNS repeater feature

For posters here........... Do not mind Darknate's lack of personal communication skills (probably why he has more dates with large networks than real people ;-) ) and of course the rampant narcissism. He has a lot of experience with many large networks that is invaluable to other large network user...
by anav
Sun Mar 26, 2023 2:44 pm
Forum: Beginner Basics
Topic: Help needed for Router-Switch-AP (all in one) scenario
Replies: 20
Views: 519

Re: Help needed for Router-Switch-AP (all in one) scenario

Looks good so far........ 1. Minor point even though you have a correct config for /interface bridge vlans it doesnt really communicate well so always do it manually so to crosscheck easily the bridge ports. /interface bridge vlan add bridge=BR1 tagged=BR1 vlan-ids=10 add bridge=BR1 tagged=BR1 vlan-...
by anav
Sun Mar 26, 2023 2:34 pm
Forum: Beginner Basics
Topic: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]
Replies: 38
Views: 1709

Re: can not access the ip range for the out interface in my wireguard tunnel [SOLVED]

I dont understand your network probably because I dont understand the use cases, you mix up users and config in such a way its not readable. Thus forget the config for now and concentrate on use cases. a. Identify all users/devices or group of users/device (including admiin) b. Identify where they a...
by anav
Sun Mar 26, 2023 4:16 am
Forum: Beginner Basics
Topic: Help needed for Router-Switch-AP (all in one) scenario
Replies: 20
Views: 519

Re: Help needed for Router-Switch-AP (all in one) scenario

Of course I can, because I can see through the internet with my spy camera and see your config. Access port or Router: --> . untag data upon leaving device tag data upon renentering device. Trunk port on Router --> leave tags on as traffic going to smart device which returns tagged traffic. Suspect ...
by anav
Sun Mar 26, 2023 4:08 am
Forum: Beginner Basics
Topic: Disconnected from LAN port and All other connections loose IP!
Replies: 11
Views: 448

Re: Disconnected from LAN port and All other connections loose IP!

Yeah get rid of the bridge giving out dhcp and stick to all vlans, much cleaner............
by anav
Sun Mar 26, 2023 4:05 am
Forum: Beginner Basics
Topic: Wiregurad setup on hAP ac2 - locked out of router
Replies: 3
Views: 156

Re: Wiregurad setup on hAP ac2 - locked out of router

Sounds like you will have to start from scratch (push reset button) to put it back to defaults. Funny the route rule you put in, should not have done that by the way. Since the MT configs for home devices comes standard with a bridge where all ports are connected ( save ether1 which is usually autos...
by anav
Sun Mar 26, 2023 2:55 am
Forum: Useful user articles
Topic: HOW TO: mDNS and SSDP over Wireguard
Replies: 1
Views: 205

Re: HOW TO: mDNS and SSDP over Wireguard

Interesting thread! Good to use to check similar work done here --> viewtopic.php?t=194646
Where Solution 5 addresses mDSN and at the bottom of the post I linked to this thread.
The diagram is very nice!
by anav
Sat Mar 25, 2023 9:02 pm
Forum: Beginner Basics
Topic: Firewall rules for VLANs using their interface name
Replies: 14
Views: 457

Re: Firewall rules for VLANs using their interface name

Vlans are cheap put the IOT device that is the problem in its own vlan.
Maybe one you experts can figure out a vxlan solution LOL.
by anav
Sat Mar 25, 2023 7:28 pm
Forum: Beginner Basics
Topic: Firewall rules for VLANs using their interface name
Replies: 14
Views: 457

Re: Firewall rules for VLANs using their interface name

Yes and thats why they are on their own VLAN on any sane configuration. :-)

So I guess this means that this addresses the USE CASE OF.........
MT device coupled with stewpid AP? as anyone with a smart AP would never combine guests wiith iot with family on the same SSID and same VLAN.
by anav
Sat Mar 25, 2023 6:53 pm
Forum: Beginner Basics
Topic: Neighbour Discovery
Replies: 6
Views: 259

Re: Neighbour Discovery

Not sure of your added complexity, but the idea I have for discovery is to ensure all MT devices can be easily disovered for the purpose of winbox discover. In that vein they should all get the same IP from the same Base or Management or Trusted Subnet. That subnet should be listed on a specific pur...
by anav
Sat Mar 25, 2023 6:49 pm
Forum: Beginner Basics
Topic: Firewall rules for VLANs using their interface name
Replies: 14
Views: 457

Re: Firewall rules for VLANs using their interface name

How would I apply a firewall rule for each VLAN? To allow/block traffic between a VLAN to itself. This makes little sense to me? Do you have a use case? Why would you want to filter some vlan users from other vlan users in the same vlan. The whole purpose of VLANS is to segregate a group of users/d...
by anav
Sat Mar 25, 2023 4:49 pm
Forum: Beginner Basics
Topic: Firewall rules for VLANs using their interface name
Replies: 14
Views: 457

Re: Firewall rules for VLANs using their interface name

Hi MKX I think you have a typo........ But when one enables IP firewall for VLAN traffic, this is sort of extension of firewall functionality (because normally firewall ................. Did you actually mean But when one enables Bridge IP firewall for VLAN traffic, this is sort of extension of fire...
by anav
Sat Mar 25, 2023 4:45 pm
Forum: General
Topic: How do we request for an account deletion?
Replies: 17
Views: 738

Re: How do we request for an account deletion?

There are smart people with brains and there are smart people with no brains. What do I mean? Some people know HOW to do things. Some know WHY to do things. Majority aren't in the latter, that's not my duty to fix, visit a shrink for medical treatment. Luckily I am not so smart and thus can save my...
by anav
Sat Mar 25, 2023 4:41 pm
Forum: General
Topic: How do we request for an account deletion?
Replies: 17
Views: 738

Re: How do we request for an account deletion?

And you too pcunite!!
by anav
Fri Mar 24, 2023 11:16 pm
Forum: Useful user articles
Topic: How to: Edge router and BNG optimization for ISPs
Replies: 34
Views: 50415

Re: How to: Edge router and BNG optimization for ISPs

The first one no clue how to formulat a rule, beyond my scope or understanding
The second one,,,,,,,,,,, I think your saying..

add chain=prerouting action=drop in-interface-list=LAN dst-address=WANIP ???

but we dst-address WANIP for dstnat rules???
by anav
Fri Mar 24, 2023 10:57 pm
Forum: Useful user articles
Topic: How to: Edge router and BNG optimization for ISPs
Replies: 34
Views: 50415

Re: How to: Edge router and BNG optimization for ISPs

So there is alignment on RAW RULE 1 BLOCK ANYTHING FROM WAN WITH SAME SUBNETS ON ROUTER RAW RULE 2 BLOCK ANYhTING FROM WAN WITH DESTINATION OF PRIVATE SUBNETS RAW RULE 2 BLOCK ANYTHING NOT FROM LOCAL SUBNETS COMING FROM LAN. No IP Routes with black hole make sense in home setting or SOHO setting. /i...
by anav
Fri Mar 24, 2023 7:18 pm
Forum: General
Topic: Mikrotik And Starlink Port Forwarding Question
Replies: 7
Views: 281

Re: Mikrotik And Starlink Port Forwarding Question

If the connection you had was from a vpn connection to an external host, there is no reason why reverse traffic is not possible. Its transparent to the starlink at that point. I have not used zerotier, the link I gave you and the MT DOCS are your best resources. ( https://help.mikrotik.com/docs/disp...
by anav
Fri Mar 24, 2023 7:00 pm
Forum: General
Topic: 2 WAN load balanced + 1 LAN - client machine not getting gateway
Replies: 8
Views: 288

Re: 2 WAN load balanced + 1 LAN - client machine not getting gateway

Probably because they are dynamic WANIps?? or likely using in-interface is NOT a valid approach so my error!!

In the xample I was following they didnt use in-interface, they used dst-add =
Will have to think how to mimic that so it works.
by anav
Fri Mar 24, 2023 6:54 pm
Forum: General
Topic: Mikrotik And Starlink Port Forwarding Question
Replies: 7
Views: 281

Re: Mikrotik And Starlink Port Forwarding Question

To clarify. Standard VPN functionality requires you to have a publicly accessible IP, not the case with Starlink. Thus you cannot use your router as the HOME BASE for VPN like wireguard Therefore you have to use an external HOME Base for the VPN, it could be another location (relative, friends house...
by anav
Fri Mar 24, 2023 6:49 pm
Forum: Useful user articles
Topic: How to: Edge router and BNG optimization for ISPs
Replies: 34
Views: 50415

Re: How to: Edge router and BNG optimization for ISPs

I am stiill waiting for a response on Blackhole. Its clearly an accessible option on the routes menu. Rextended succintly pointed out its not worth it in most cases, perhaps he meant the home user. I was hoping darknate could explain why its used in business or if not really applicable there either....
by anav
Fri Mar 24, 2023 6:44 pm
Forum: Beginner Basics
Topic: dns-server IP in VLAN tutorial
Replies: 11
Views: 385

Re: dns-server IP in VLAN tutorial

No need to dissect the VLAN config oriented approach for your focused firewall questions. Its simple, ONLY the ADMIN needs access TO THE ROUTER for config. Users ONLY need access to ROUTER SERVICES> CAPICHE? How you want to set that up for your own device is up to you. A simple approach that works i...
by anav
Fri Mar 24, 2023 4:37 pm
Forum: RouterOS beta and rc versions
Topic: Bridge to Wireguard interface [SOLVED]
Replies: 19
Views: 9512

Re: Bridge to Wireguard interface [SOLVED]

ukvpn is a bridge, just so that I can organise a dhcpd for connected devices on ether{4,5} I presume what you are trying to do is get the devices on ether4 and ether5 to go online through the wireguard VPN whereas everything else should go online the normal way. Is this correct? If so, you need to ...
by anav
Fri Mar 24, 2023 4:25 pm
Forum: Announcements
Topic: v7.9beta [testing] is released!
Replies: 109
Views: 14351

Re: v7.9beta [testing] is released!

Well, I admit that I must have really expressed myself extremely clumsily if it was perceived that it should have been done ALREADY! 😘 But as I said, "someone" should consider a bump to v1.10.6 as soon as possible to avoid angry Android and ipv6 users. Otherwise it looks like a grand upda...
by anav
Fri Mar 24, 2023 2:42 pm
Forum: Announcements
Topic: v7.9beta [testing] is released!
Replies: 109
Views: 14351

Re: v7.9beta [testing] is released!

When we upgraded to version 1.10.3 it was the latest one. We can't upgrade and release on the same day. We need to test it too : ) So true, LARSA look at post #16 :-) My impatient vampire mouse. That is why I am not clamouring for the ZeroTrust Cloudlfare Tunnel options package (for all mt users) o...
by anav
Fri Mar 24, 2023 2:39 pm
Forum: General
Topic: WireGuard and placing a client on the LAN segment of my network
Replies: 34
Views: 1860

Re: WireGuard and placing a client on the LAN segment of my network

MTU clueless here so cannot help............ but here is the link to the user article based on this thread....... https://forum.mikrotik.com/viewtopic.php?t=194646 Comments welcome. 1. UNIFI Controller to UNIFI APs - via Wireguard and EOIP. - https://forum.mikrotik.com/viewtopic.php?p=990837#p990836...
by anav
Fri Mar 24, 2023 2:34 pm
Forum: General
Topic: Route ALL traffic for 1 LAN IP from site A (via Wiregard tunnel) to site B
Replies: 20
Views: 2033

Re: Route ALL traffic for 1 LAN IP from site A (via Wiregard tunnel) to site B

Awesome it would be nice to have a summary post where you state here is what I wanted to accomplish and here is the final config.......
by anav
Fri Mar 24, 2023 2:27 pm
Forum: General
Topic: hEX S/RB760iGS IKEv2 RoadWarrior throughput
Replies: 5
Views: 373

Re: hEX S/RB760iGS IKEv2 RoadWarrior throughput

Wireguard is probably faster.
by anav
Fri Mar 24, 2023 1:47 pm
Forum: Beginner Basics
Topic: Firewall Filter Rule before NAT rule
Replies: 14
Views: 20792

Re: Firewall Filter Rule before NAT rule

I will look at this sorry thread later but its clear that HAVING SAFELY SETUP SERVERS is a very important consideration for many many mikrotik users.

Thus Mikrotik MUST PROVIDE the Zerotrust Cloudflare tunnel in an options package for all users!!!
by anav
Fri Mar 24, 2023 1:35 pm
Forum: RouterOS beta and rc versions
Topic: Bridge to Wireguard interface [SOLVED]
Replies: 19
Views: 9512

Re: Bridge to Wireguard interface [SOLVED]

Wireguard doesn't work with a bridge-lan is a ridiculous statement that means nothing! Wireguard is a peer to peer layer3 construct. If you want to connect subnets at layer 2 then a. use zerotier b. eiop over wg c. vxlan over wg. etc. I will connect Two routers, with bridge-LANS using WG . EASY PEA...
by anav
Fri Mar 24, 2023 1:16 pm
Forum: Announcements
Topic: v7.9beta [testing] is released!
Replies: 109
Views: 14351

Re: v7.9beta [testing] is released!

Impressive amount of work done here, regardless if what anyone specifically wanted didnt get done. The paperwork alone is not trivial, just imagine the testing and integration involved. Kudos to the dev team and test team.
by anav
Fri Mar 24, 2023 3:05 am
Forum: General
Topic: 2 WAN load balanced + 1 LAN - client machine not getting gateway
Replies: 8
Views: 288

Re: 2 WAN load balanced + 1 LAN - client machine not getting gateway

see the rest of my reply in the above post.
by anav
Fri Mar 24, 2023 2:57 am
Forum: General
Topic: 2 WAN load balanced + 1 LAN - client machine not getting gateway
Replies: 8
Views: 288

Re: 2 WAN load balanced + 1 LAN - client machine not getting gateway

Mangle rules........ /ip firewall mangle add action=accept chain=prerouting in -interface=Eth2-WAN1 add action=accept chain=prerouting in -interface=eth3-WAN2 TRY add action=accept chain=prerouting out -interface=Eth2-WAN1 add action=accept chain=prerouting out -interface=eth3-WAN2 NEXT: Wyy are you...
by anav
Fri Mar 24, 2023 2:28 am
Forum: General
Topic: 2 WAN load balanced + 1 LAN - client machine not getting gateway
Replies: 8
Views: 288

Re: 2 WAN load balanced + 1 LAN - client machine not getting gateway

(1) Why is your DHPC network not using the same subnet as the rest of the config. /ip dhcp-server network add address= 10.0.0.0/8 dns-server= 8.8.8.8 gateway=10.100.1.1 Why not use the routers DNS caching ability with external dns servers?? /ip dhcp-server network add address= 192.168.100.0/24 dns-s...
by anav
Thu Mar 23, 2023 11:40 pm
Forum: General
Topic: problem with nat port forwarding [SOLVED]
Replies: 3
Views: 147

Re: problem with nat port forwarding [SOLVED]

Doing it wrong, There is one rule only for port forwarding required in the FORWARD CHAIN. The concept is different from most other routers I have used. WE dont make a forward rule for each port forward. We use the dst nat chain to do each rule. Check out - https://forum.mikrotik.com/viewtopic.php?t=...
by anav
Thu Mar 23, 2023 11:31 pm
Forum: Beginner Basics
Topic: configure hap ax3 as AP
Replies: 4
Views: 206

Re: configure hap ax3 as AP

Hi Ammo, I deal in the management of software bugs and believe me its not hard for them to get buried or stuck.
Suggest resubmit the issue as a new one.............
by anav
Thu Mar 23, 2023 11:30 pm
Forum: General
Topic: 2ISP BALANCE PCC
Replies: 7
Views: 251

Re: 2ISP BALANCE PCC

Well you will need to provide a diagram because servers dont initiate/originate traffic, they respond to incoming requests?
I have no clue of what VPN you are using and how it actually works as your words are more confusing then enlightening.
by anav
Thu Mar 23, 2023 9:36 pm
Forum: Wireless Networking
Topic: Missing ACL enable/disable in QuickSet [SOLVED]
Replies: 18
Views: 542

Re: Missing ACL enable/disable in QuickSet [SOLVED]

Priceless quote1: " Go to Wireless menu, then click Access List tab " Priceless quote2: " mkx which threads are you referring to? AFAIK hAP ax2 works like a charm. I use it personally too. If you have no specific report made, don't spread such false info then. " Yup everything i...
by anav
Thu Mar 23, 2023 9:33 pm
Forum: Beginner Basics
Topic: configure hap ax3 as AP
Replies: 4
Views: 206

Re: configure hap ax3 as AP

Look at the example........ - viewtopic.php?t=182276
by anav
Thu Mar 23, 2023 9:09 pm
Forum: Wireless Networking
Topic: Missing ACL enable/disable in QuickSet [SOLVED]
Replies: 18
Views: 542

Re: Missing ACL enable/disable in QuickSet [SOLVED]

Maybe they should assign more resources at MT to finish products instead of releasing them as beta software or at least produce a transparent road map for completion of feature sets.
by anav
Thu Mar 23, 2023 8:46 pm
Forum: General
Topic: 2ISP BALANCE PCC
Replies: 7
Views: 251

Re: 2ISP BALANCE PCC

A server does not open a tunnel as its the server for other users aka the destination address. Im assuming you mean users come into the router via the tunnel to access the server and not via its public WAN IP. Thus you must ensure the return information from the server goes back into the tunnel. So ...
by anav
Thu Mar 23, 2023 8:41 pm
Forum: General
Topic: 2ISP BALANCE PCC
Replies: 7
Views: 251

Re: 2ISP BALANCE PCC

Page 53-55 in the discher pdf https://www.khanacademy.org/computing/computer-science/cryptography/modarithmetic/a/what-is-modular-arithmetic Putting Items In Random Groups Suppose you have people who bought movie tickets, with a confirmation number. You want to divide them into 2 groups. What do you...
by anav
Thu Mar 23, 2023 8:27 pm
Forum: Wireless Networking
Topic: Missing ACL enable/disable in QuickSet [SOLVED]
Replies: 18
Views: 542

Re: Missing ACL enable/disable in QuickSet [SOLVED]

The OP has a point. There is an ACCESS LIST Tab on wifi wave 2 and that seems to be to enter in each item individually with some ability to assign radius and other things............ HOWEVER, there is no single TAB or entry that would allow DISABLE all access list or ENABLE all access list. Further,...
by anav
Thu Mar 23, 2023 7:00 pm
Forum: RouterOS beta and rc versions
Topic: Feature Request - Regex Capturing Groups
Replies: 7
Views: 248

Re: Feature Request - Regex Capturing Groups

Possibly due to no recent graduates from computer software engineering in Latvia..........OR
Cheap assed owners who dont want to hire the necessary staff to make MT really shine and sing!!
by anav
Thu Mar 23, 2023 2:54 pm
Forum: Useful user articles
Topic: How to: Edge router and BNG optimization for ISPs
Replies: 34
Views: 50415

Re: How to: Edge router and BNG optimization for ISPs

Good, like the practical thinking!! So Darknates first rule should be the same as his second rule (in terms of list of local subnets) RAW RULE 1 BLOCK ANYTHING FROM WAN WITH SAME SUBNETS ON ROUTER (instead of bogon list) RAW RULE 2 BLOCK ANYTHING NOT FROM LOCAL SUBNETS COMING FROM LAN So no reason t...
by anav
Thu Mar 23, 2023 2:51 pm
Forum: Beginner Basics
Topic: Recursive Fail over [SOLVED]
Replies: 1
Views: 101

Re: Recursive Fail over [SOLVED]

by anav
Thu Mar 23, 2023 2:49 pm
Forum: Beginner Basics
Topic: Certain traffico out "main" route?
Replies: 1
Views: 88

Re: Certain traffico out "main" route?

Sorry words are not clear.
a. provide a diagram for context and
b. full config for actual evidence of what is setup.
/export file=anynameyouwish ( minus router serial number and any actual public WANIP information )
by anav
Thu Mar 23, 2023 2:46 pm
Forum: Beginner Basics
Topic: Weird routing behavior ??
Replies: 8
Views: 306

Re: Weird routing behavior ??

Your problems are not solved by hardware LOL

Just configure the MT as a basic switch iaw viewtopic.php?t=182276

just go look at the example.
by anav
Thu Mar 23, 2023 1:02 pm
Forum: Useful user articles
Topic: How to: Edge router and BNG optimization for ISPs
Replies: 34
Views: 50415

Re: How to: Edge router and BNG optimization for ISPs

So your saying the only entry on your ADDRESS LIST is 192.0.0.0/24 ? AND these are no longer valid to put on that source address list to block incoming 'bad' incoming on WAN? Netblock Description 0.0.0.0/8 "This" network 10.0.0.0/8 Private-use networks 100.64.0.0/10 Carrier-grade NAT 127.0...
by anav
Thu Mar 23, 2023 12:48 pm
Forum: Wireless Networking
Topic: Missing ACL enable/disable in QuickSet [SOLVED]
Replies: 18
Views: 542

Re: Missing ACL enable/disable in QuickSet [SOLVED]

The value in quickset is to be able to select the generic mode of wifi the router applies, after that, dont visit quick set again.
by anav
Thu Mar 23, 2023 12:46 pm
Forum: General
Topic: RB2011 and degraded Internet speed
Replies: 9
Views: 328

Re: RB2011 and degraded Internet speed

Why would you replace a router with a wifi router, the 4011 has a WIRED only version and better anyway for the same price point is the RB5009?
by anav
Thu Mar 23, 2023 12:44 pm
Forum: General
Topic: WifiWave2 interface menu missing items?
Replies: 6
Views: 276

Re: WifiWave2 interface menu missing items?

Stop drinking 2xbottles of Italian wine at at time - we know its so good, but the errors, the errors.........
by anav
Thu Mar 23, 2023 12:42 pm
Forum: General
Topic: 2ISP BALANCE PCC
Replies: 7
Views: 251

Re: 2ISP BALANCE PCC

by anav
Thu Mar 23, 2023 12:38 pm
Forum: General
Topic: Can a Mikrotik RouterOS device handle FiOS gigabit
Replies: 2
Views: 162

Re: Can a Mikrotik RouterOS device handle FiOS gigabit

FIOS is an internet provider,
an internet provider provides an internet connection
an internet connection requires at some point a router.
Can an MT router handle FIOS gig connection --->YES
+++++++++++++++++++++++++++++++++++++++++++++

A switch has nothing to do with the above.
by anav
Thu Mar 23, 2023 12:36 pm
Forum: General
Topic: Express VPN OVPN on mikrotik
Replies: 5
Views: 1282

Re: Express VPN OVPN on mikrotik

Use Wireguard or zerotier
by anav
Thu Mar 23, 2023 12:34 pm
Forum: General
Topic: Wireguard on mikrotik AND on PC attached to it
Replies: 11
Views: 534

Re: Wireguard on mikrotik AND on PC attached to it

Like I said, WG is a peer to peer construct, so no issue connecting the three cities to NY router to router . Like I said, no issues connecting disparate subnets such as 10.0.1 and and 10.0.2 from satellite office to 10.0.1 at MAIN branch. But you cannot connect subnets 10.0.0 from satellite to 10.0...
by anav
Thu Mar 23, 2023 4:18 am
Forum: General
Topic: RB2011 and degraded Internet speed
Replies: 9
Views: 328

Re: RB2011 and degraded Internet speed

Getting a modern router with horsepower is certainly recommended.
Unaware of any method to avoid mangling in this case.
by anav
Thu Mar 23, 2023 4:13 am
Forum: General
Topic: Firewall input drop all except LAN
Replies: 8
Views: 333

Re: Firewall input drop all except LAN

by anav
Thu Mar 23, 2023 4:12 am
Forum: General
Topic: Two default gateways. One DHCP one Wireguard
Replies: 1
Views: 92

Re: Two default gateways. One DHCP one Wireguard

Not enough info
Network diagram gives context
Describing user requirements without any config speak is essential
identify users/devices groups of users/devices and their traffic flow requirements
Finally config of devices at both ends of tunnel
by anav
Thu Mar 23, 2023 2:50 am
Forum: Wireless Networking
Topic: House wifi6 network with Mikrotik AX or Audience
Replies: 29
Views: 2849

Re: House wifi6 network with Mikrotik AX or Audience

If MT wifi products had decent documentation, clear paths to setup, and users could understand all the available features and setup the APs with relative ease and they worked and provided consistent stable throughput, perhaps nOrmands you would have a leg to stand on to "get aggressive with mkx...
by anav
Thu Mar 23, 2023 2:29 am
Forum: General
Topic: Multiple default routes in main route table
Replies: 3
Views: 183

Re: Multiple default routes in main route table

Sorry no capiche, I understand users or LAN subnets wanting to go out specific WANs, WAn1, Wan2, Wan3. Wans1-3 may be from the same or different ISPs. They may have different connection types, standard cable, wifi, PPPOE, or starlink for example. So your explanation does nothing to provide any fidel...
by anav
Thu Mar 23, 2023 1:06 am
Forum: General
Topic: Connecting remote offices [SOLVED]
Replies: 12
Views: 425

Re: Connecting remote offices [SOLVED]

Yes I was trying to convey that on my last post, use the existing bridge!!
Glad it worked!!
by anav
Wed Mar 22, 2023 11:02 pm
Forum: RouterOS beta and rc versions
Topic: mDNS repeater feature
Replies: 288
Views: 64286

Re: mDNS repeater feature

I attempted to run mDSN discovery over wireguard but at two DIFFERENT LOCATIONs..........
Feel free to test it, to make sure it works..............academic at this point.
viewtopic.php?p=990840#p990840
by anav
Wed Mar 22, 2023 10:41 pm
Forum: Beginner Basics
Topic: communicate two networks
Replies: 1
Views: 137

Re: communicate two networks

The best way is probably zerotier where you can put two routers lans together as if they were on the same switch etc..... Best done with an ARM64 for example. You may get away with one ARM64 device at source (where the cameras actually are) and people can load zerotier on their laptops, cellphones e...
by anav
Wed Mar 22, 2023 10:39 pm
Forum: Beginner Basics
Topic: Outside Network with Port 5060
Replies: 3
Views: 142

Re: Outside Network with Port 5060

Without a config and a network diagram hard to say.........
by anav
Wed Mar 22, 2023 10:36 pm
Forum: Beginner Basics
Topic: Weird routing behavior ??
Replies: 8
Views: 306

Re: Weird routing behavior ??

So your using the RB5009 as a switch ??? Thats crazyee, let me send you a switch and you can send me the RB5009 :-) Why are you creating vlans on the router?? They should all be defined on the pFSENSE. So your using this as a full router with double NAT ??? Why not just use the RB5009 and throw the ...
by anav
Wed Mar 22, 2023 5:29 pm
Forum: Beginner Basics
Topic: Weird routing behavior ??
Replies: 8
Views: 306

Re: Weird routing behavior ??

Suggest you use a proper firewall appliance, I have no interest in looking at pfsense logs. Curl that!
by anav
Wed Mar 22, 2023 4:52 pm
Forum: General
Topic: Need some advice
Replies: 2
Views: 124

Re: Need some advice

yes
by anav
Wed Mar 22, 2023 4:51 pm
Forum: General
Topic: Transmit broadcast and WoL packets across VLANs?
Replies: 7
Views: 250

Re: Transmit broadcast and WoL packets across VLANs?

Not sure how this would be done as the same commands dont translate directly but there are ways to achieve almost anything.
Zerotier functionality would create it such that you could put any two vlans on the same virtual switch to achieve the same effect I believe.
by anav
Wed Mar 22, 2023 1:19 pm
Forum: Beginner Basics
Topic: Wireguard: how to configure this network?
Replies: 12
Views: 956

Re: Wireguard: how to configure this network?

separate wg interface.
by anav
Wed Mar 22, 2023 1:15 pm
Forum: Beginner Basics
Topic: a simple question about Mikrotik ports ?
Replies: 7
Views: 239

Re: a simple question about Mikrotik ports ?

Look at the timelines rextended. He was probably reading the original post and drafting a reply when you added your input. Imagine he went to get a coffee or take a piss............ comes back finishes his post, hits send and then both his and yours appears on the refresh. No harm no foul, just the ...
by anav
Wed Mar 22, 2023 1:08 pm
Forum: General
Topic: WireGuard AzireVPN - misbehavior
Replies: 3
Views: 146

Re: WireGuard AzireVPN - misbehavior

When ready to not use ipv6, as stated can help troubleshoot.
In the meantime checkout PARA 7 and PARA 9 (D) -- viewtopic.php?t=182340
by anav
Wed Mar 22, 2023 1:07 pm
Forum: General
Topic: Wireguard on mikrotik AND on PC attached to it
Replies: 11
Views: 534

Re: Wireguard on mikrotik AND on PC attached to it

If you want to to span the same subnet over wireguard be clear about it. One does not span data transfer using wireguard addresses.
Your best bet is using zerotier first.
by anav
Wed Mar 22, 2023 3:39 am
Forum: General
Topic: WireGuard AzireVPN - misbehavior
Replies: 3
Views: 146

Re: WireGuard AzireVPN - misbehavior

Is your network ipv6? if so cannot help as not fluent in such language.
by anav
Wed Mar 22, 2023 3:28 am
Forum: General
Topic: Very high traffic on Firewall "Drop all traffic not from Lan" rule
Replies: 5
Views: 362

Re: Very high traffic on Firewall "Drop all traffic not from Lan" rule

I have 3 layers of firewalls in the user article, https://forum.mikrotik.com/viewtopic.php?t=180838 NOVICE --> raw beginner newbie NOVICE + MODIFIED --> Beginner with some experience APPRENTICE --> Beginner with confidence/knowledge/understanding Nothing else is really required............. PS Dont ...
by anav
Wed Mar 22, 2023 3:21 am
Forum: General
Topic: Firewall Drop DNS Local
Replies: 2
Views: 126

Re: Firewall Drop DNS Local

This is a safe starting point. add action=accept chain=input in-interface-list=LAN add action=accept chain=input comment="Allow DNS to local" dst-port=53 \ in-interface-list=LAN protocol=udp add action=accept chain=input comment="Allow DNS to local" dst-port=53 \ in-interface-lis...
by anav
Wed Mar 22, 2023 2:07 am
Forum: General
Topic: Firewall input drop all except LAN
Replies: 8
Views: 333

Re: Firewall input drop all except LAN

Its simple for both chains a few default rules a few user rules drop all No need to get cute............ allow Admin to router allow users to needed services drop all else allow subnets to WAN ************** allow port forwarding drop all else **** any other needed traffic like to a shared printer f...
by anav
Wed Mar 22, 2023 2:02 am
Forum: Beginner Basics
Topic: settings for safe use...
Replies: 8
Views: 673

Re: settings for safe use...

Interesting, I have always set RP filter to loose for multiple reasons but I dont have syn cookies checked, should I? Interesting link, seems like a valid checkbox to use. But I must check with my Tarot Cards. There is no point to using tcp syn cookies checkbox. Its only useful for targetted atacks ...
by anav
Wed Mar 22, 2023 12:30 am
Forum: General
Topic: Connecting remote offices [SOLVED]
Replies: 12
Views: 425

Re: Connecting remote offices [SOLVED]

Take the EOIP R1 Office router settings Router One /interface bridge ports add bridge=bridge interface=ether4-MainR1 add bridge=bridge interface=eoip-to-TWO pvid=20 /interface bridge vlan add bridge=bridge tagged=bridge untagged=eiop-to-TWO,ether4-MainR1 vlan-ids=20 The bridge already exists ether4 ...
by anav
Wed Mar 22, 2023 12:04 am
Forum: Beginner Basics
Topic: settings for safe use...
Replies: 8
Views: 673

Re: settings for safe use...

I am a believe in simplify for both clarity and troubleshooting issues. Therefore. A. ONE BRIDGE B. VLANS for all subnets ( bridge just does bridging ) C. Capsman for one AP - COMPLETE WASTE of time and clutters up clean config. I had three at one time and you couldnt pay me to use capsman. In this ...
by anav
Tue Mar 21, 2023 11:20 pm
Forum: General
Topic: Connecting remote offices [SOLVED]
Replies: 12
Views: 425

Re: Connecting remote offices [SOLVED]

WARNING FOR ABOVE CONFIGS< not quite right yet, I have not removed vlans but there is a possibility I may not have too.......... investigating.
by anav
Tue Mar 21, 2023 10:43 pm
Forum: General
Topic: Connecting remote offices [SOLVED]
Replies: 12
Views: 425

Re: Connecting remote offices [SOLVED]

I didnt post the configs for POSSIBILITIES 2 and 3 so done here....... POSSIBLITIES 2 & 3 ( covers both methods eoip and vxlan ) - -> single bridge specifically for one spanned subnet at Satellite Office Note: The difference in POSSIBILITY 3, is that there is at least one other bridge for the ot...
by anav
Tue Mar 21, 2023 10:31 pm
Forum: General
Topic: Connecting remote offices [SOLVED]
Replies: 12
Views: 425

Re: Connecting remote offices [SOLVED]

TO RECAP, There are four possibilities: (1) USE WIREGUARD --> Single Subnet at Satellite: The configuration provided should work with all existing hardware with ONE internet connection provided by the MAIN office. No extra work is required to change any /interface bridge nat settings. This is predic...
by anav
Tue Mar 21, 2023 7:31 pm
Forum: General
Topic: Wireguard peer interface irregularly stop working
Replies: 61
Views: 6899

Re: Wireguard peer interface irregularly stop working

@retom
@Montecri

If you two [*****.***] actually read the thread..........
viewtopic.php?p=991310#p923407

This one is recommended:
**** FOR ADVANCED USERS ------- Courtesy of Sob/Dave ( called elegant by Chupaka even )
by anav
Tue Mar 21, 2023 7:25 pm
Forum: Beginner Basics
Topic: How to use multiple ports for one dhcp server
Replies: 4
Views: 159

Re: How to use multiple ports for one dhcp server

Sure, and take your electric bicycle using major highways from LA to NY.......... dont be ridonkulous
by anav
Tue Mar 21, 2023 7:16 pm
Forum: Beginner Basics
Topic: How to use multiple ports for one dhcp server
Replies: 4
Views: 159

Re: How to use multiple ports for one dhcp server

Why do you talk about ROUTER when you picked a switch???? We want to use the MikroTik CRS326-24G-2S+RM, I picked this one because it has 24 ports + 2 sfp ports. Right now we have 2 switches (24 ports), 1 for voip phones and 1 for the pcs. I was thinking about connecting all pcs straight to the route...
by anav
Tue Mar 21, 2023 7:10 pm
Forum: General
Topic: Connecting remote offices [SOLVED]
Replies: 12
Views: 425

Re: Connecting remote offices [SOLVED]

USING Wireguard to SPAN One Subnet Assumptions - One DCHP Server , Subnet Uses Main Office For Internet . SOLUTION METHOD ONE: EOIP OVER WIREGUARD a. create wireguard connectivity as per normal and then b. create the EOIP tunnel within the WG tunnel ( EOIP never concerns its self ever with local WA...
by anav
Tue Mar 21, 2023 6:32 pm
Forum: General
Topic: Connecting remote offices [SOLVED]
Replies: 12
Views: 425

Re: Connecting remote offices [SOLVED]

Dont give up me yet LOL. Can I ask if the offices have one local subnet aka on a bridge or MULTIPLE LOCAL subnets ?? Was the intention to have MAIN office internet for the single Subnet or try to use local WAN for internet at local router OR NO internet at all?? With this information a plausible sol...
by anav
Tue Mar 21, 2023 5:36 pm
Forum: Beginner Basics
Topic: NTP Server issues [SOLVED]
Replies: 9
Views: 375

Re: NTP Server issues [SOLVED]

did you report that as a bug or do you get a spanking?? I was gonna comment your statement, but the comnent would probably be rated as PG18 :wink: Plus I only found this out the other day. Days of v6 in my home network are counted, so why should I bother to report ... And it's not a security proble...
by anav
Tue Mar 21, 2023 5:30 pm
Forum: General
Topic: Connecting remote offices [SOLVED]
Replies: 12
Views: 425

Re: Connecting remote offices [SOLVED]

Lucky for you Toto, just looking at this subject. ( okay so KC is in MO, but thats a ridonkulous proposition ) BUT why did you use old routers for a new purchase, an RB5009 would have been more appropriate, especially since ZEROTIER would have fixed your issues SO SO easily and with the right horsep...
by anav
Tue Mar 21, 2023 5:26 pm
Forum: Beginner Basics
Topic: NTP Server issues [SOLVED]
Replies: 9
Views: 375

Re: NTP Server issues [SOLVED]

did you report that as a bug or do you get a spanking??
by anav
Tue Mar 21, 2023 4:52 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 193
Views: 17417

Re: MikroTik hAP ax3 poor WiFi performance

Just received an additional response: the wording of release notes is wrong. It should be AX2 for US and Europe. But AX3 / Chateau AX only for Europe is supported as well. (because of the FCC limitation on external antenna, they are excluded for US, I understand that) What If I choose some backward...
by anav
Tue Mar 21, 2023 4:45 pm
Forum: Beginner Basics
Topic: NTP Server issues [SOLVED]
Replies: 9
Views: 375

Re: NTP Server issues [SOLVED]

In plain Italian
NTP is a router service.
a. enable NTP client settings to get ntp from www
b. enable NTP server settings to give to downstream devices
c. enable input chain rule for such LAN devices to reach router on port 123.
by anav
Tue Mar 21, 2023 3:22 pm
Forum: Beginner Basics
Topic: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]
Replies: 16
Views: 546

Re: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]

Okay but only for RB4011 correct.

Well, OP's ap.rsc mentions it's from RB4011 ... hence my post is highly relevant in this thread.
Yes, but it was not in my applicable useful article yet AP SWITCH SETUP, so it couldnt be true. Now that its added, I believe you. ;-PP
...
rb4.JPG
by anav
Tue Mar 21, 2023 3:18 pm
Forum: Beginner Basics
Topic: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]
Replies: 16
Views: 546

Re: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]

My apologies to the OP. This should work. /interface bridge vlan add bridge=bridge-vlan tagged=ether1-trunk, bridge-vlan untagged=wifi1,wifi2,ether2-pc,ether3-dockingstation,ether4-nas,ether5-laptop,ether6,ether9 vlan-ids=10 add bridge=bridge-vlan tagged=ether1-trunk, bridge-vlan untagged=wifi-guest...
by anav
Tue Mar 21, 2023 3:16 pm
Forum: Beginner Basics
Topic: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]
Replies: 16
Views: 546

Re: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]

It's been explained that when they first implemented L2 HW offload, they implemented it so that CPU-switch interconnect will only pass VLANs of which bridge interface is member (either tagged or untagged). And it worked perfectly because those devices were wired-only devices with single switch chip...
by anav
Tue Mar 21, 2023 3:11 pm
Forum: Beginner Basics
Topic: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]
Replies: 16
Views: 546

Re: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]

Wait, so you are saying that both switch chips need the bridge to be tagged for every vlan?? and what does switch chip have to do with WIFI Bridge ports ur killen me............ In that case, it explains why the OP had success tagging when it seemed illogical. MKX I could kiss you, well you know wha...
by anav
Tue Mar 21, 2023 2:51 pm
Forum: Beginner Basics
Topic: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]
Replies: 16
Views: 546

Re: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]

(1) Remove bridge1 /interface bridge add ingress-filtering=no name=bridge-vlan protocol-mode=none vlan-filtering=yes add name=bridge1 (2) Confirm the iot and guest WIRED gets addresses ( ether8 and ether7) . If they DO then (4) is correct. If they do not then perhaps (5) is the answer. (3) Add to th...
by anav
Tue Mar 21, 2023 2:40 pm
Forum: Wireless Networking
Topic: Open SSID gets wrong VLAN
Replies: 8
Views: 602

Re: Open SSID gets wrong VLAN

NO FIREWALL RULES REQUIRED Going to assume you get an IP address on the 192.168.8.0/24 and will fix it to 192.168.88.2 It would appear that the above device is not getting fed from a trunk port # software id = F7Y9-BEGS # # model = C52iG-5HaxD2HaxD # serial number = {removed for security reasons} /i...
by anav
Tue Mar 21, 2023 2:23 pm
Forum: Wireless Networking
Topic: Open SSID gets wrong VLAN
Replies: 8
Views: 602

Re: Open SSID gets wrong VLAN

Nice of you to mention that now LOL, but now that I read it you did say homeAP................ Its still a completely hosed setup. As I said get rid of datapath and vlans in wifi, keep wifi to wifi settings!!, and you only define the management vlan! FINALLY WHAT IS THE MANAGEMENT VLAN or subnet ???...
by anav
Tue Mar 21, 2023 2:14 pm
Forum: General
Topic: Multiple default routes in main route table
Replies: 3
Views: 183

Re: Multiple default routes in main route table

If its whole subnets, dont use mangling. If its a few users, dont use mangling Instead use routing rules ( and I wont use your example of lan subnets somehow being in the same structure as each WAN subnet ;-PPP ) Consists of 3 steps {add tables} /routing table add fib name= useWAN1 /routing table ad...
by anav
Tue Mar 21, 2023 2:03 pm
Forum: General
Topic: Plugging laptop into VLAN port, blocks bridge interface of other router.
Replies: 6
Views: 266

Re: Plugging laptop into VLAN port, blocks bridge interface of other router.

When you decide to have one bridge, and all subnets on vlans, I can help.
by anav
Tue Mar 21, 2023 2:01 pm
Forum: General
Topic: Firewall input drop all except LAN
Replies: 8
Views: 333

Re: Firewall input drop all except LAN

First of all why do you use such a twisted rule?? defconf: drop all not coming from LAN rule in the firewall. Basically it is an input drop !LAN Much better and clearer to simply say accept all coming from LAN drop all else This leads to the logical next step, which you may have not noticed with the...
by anav
Tue Mar 21, 2023 1:50 pm
Forum: Beginner Basics
Topic: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]
Replies: 16
Views: 546

Re: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]

TWO THINGS to fix. (1) FIX the interface bridge vlan rules --> only the BASE vlan, where the AP/Switch gets its IP address from (.99) needs the bridge to be tagged !! From /interface bridge vlan add bridge=bridge-vlan tagged=ether1-trunk, bridge-vlan untagged=wifi1,wifi2,ether2-pc,ether3-dockingstat...
by anav
Tue Mar 21, 2023 1:16 pm
Forum: RouterOS beta and rc versions
Topic: Routing mark and Os7 with two isp [SOLVED]
Replies: 8
Views: 372

Re: Routing mark and Os7 with two isp [SOLVED]

Would also agree with the previous poster that your rules are a bit funny to have worked well in the past......... Agree with your approach using firewall address lists as you state its not just whole subnets but subnets plus or minus a number of folks that may change from time to time. Much easier ...
by anav
Tue Mar 21, 2023 1:07 pm
Forum: RouterOS beta and rc versions
Topic: Routing mark and Os7 with two isp [SOLVED]
Replies: 8
Views: 372

Re: Routing mark and Os7 with two isp [SOLVED]

I see nothing wrong with your setup; but would change the sourcenat rules as its not clear which WAN they refer to and thus not sure if they would work right. From: /ip firewall nat add action=masquerade chain=srcnat src-address=192.168.1.0/24 add action=masquerade chain=srcnat src-address=192.168.4...
by anav
Tue Mar 21, 2023 2:01 am
Forum: Scripting
Topic: Black list for failed login to IPSec VPN
Replies: 50
Views: 24322

Re: Black list for failed login to IPSec VPN

My script!

add chain=input action=drop
add chain=forward action=drop

That was easy.
by anav
Tue Mar 21, 2023 1:58 am
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 193
Views: 17417

Re: MikroTik hAP ax3 poor WiFi performance

Hoping you get your MT wifi6 soon bpwl, cannot wait for the 'blessed' configuration that works!!
by anav
Tue Mar 21, 2023 1:56 am
Forum: General
Topic: Very high traffic on Firewall "Drop all traffic not from Lan" rule
Replies: 5
Views: 362

Re: Very high traffic on Firewall "Drop all traffic not from Lan" rule

Because there is tons of traffic on the WWW always hitting routers, nothing unusual. You are simply in effect logging it now by showing what is dropped. For a starting firewall this is ideal........... /ip firewall filter {Input Chain} add action=accept chain=input comment="defconf: accept esta...
by anav
Tue Mar 21, 2023 1:52 am
Forum: Beginner Basics
Topic: no VPN on lan side
Replies: 3
Views: 197

Re: no VPN on lan side

Depends................ firewall rules, vlans many ways...........
by anav
Tue Mar 21, 2023 1:50 am
Forum: Beginner Basics
Topic: Hairpin NAT not working from local network [SOLVED]
Replies: 3
Views: 363

Re: Hairpin NAT not working from local network [SOLVED]

FIXED: /ip firewall filter add action=accept chain=input comment="default configuration" \ connection-state=established,related,untracked add action=drop chain=input comment="defconf: drop invalid" connection-state=\ invalid add action=accept chain=input protocol=icmp add action=...
by anav
Mon Mar 20, 2023 9:38 pm
Forum: RouterOS beta and rc versions
Topic: Routing mark and Os7 with two isp [SOLVED]
Replies: 8
Views: 372

Re: Routing mark and Os7 with two isp [SOLVED]

/ip route add check-gateway=ping disabled= yes distance=1 dst-address=0.0.0.0/0 gateway=192.168.1.2 pref-src="" routing-table=isp2 scope=30 suppress-hw-offload=no target-scope=10 add disabled=yes distance=1 dst-address=0.0.0.0/0 gateway=pppoe-out1 pref-src=0.0.0.0 routing-table=isp1 scope=...
by anav
Mon Mar 20, 2023 9:26 pm
Forum: Beginner Basics
Topic: Route specific IP only when connected to specific Virtual AP
Replies: 11
Views: 360

Re: Route specific IP only when connected to specific Virtual AP

Okay lets see if I have it correctly you have two wifi interfaces on the LAN side (not 1, not 3 not 4 etc,) vWLAN1 - ALL internet traffic goes out local uplink internet (even 1.2.3.4) vWLAN2 - All internet traffic goes out local uplink internet EXCEPT for one single WANIP 1.2.3.4 that must use Wireg...
by anav
Mon Mar 20, 2023 8:03 pm
Forum: Beginner Basics
Topic: Route specific IP only when connected to specific Virtual AP
Replies: 11
Views: 360

Re: Route specific IP only when connected to specific Virtual AP

Sorry makes no sense to me (diagram useless in adding additional info) You either have a regular (local) path to the internet via the uplink on the router to whatever is providing you internet. OR You have a wireguard path to the internet via another router somewhere (friend, your own, third party p...
by anav
Mon Mar 20, 2023 7:41 pm
Forum: Beginner Basics
Topic: Route specific IP only when connected to specific Virtual AP
Replies: 11
Views: 360

Re: Route specific IP only when connected to specific Virtual AP

Please be clear........... Do you want to connect to the internet via the wireguard connection if so /interface bridge port add bridge=br1 interface=wifi1 add bridge=br1 interface=vWLAN-two add bridge=br1 interface=vWLAN-three /routing rule add action=lookup interface=vWLAN-two table=useWG /routing ...
by anav
Mon Mar 20, 2023 7:31 pm
Forum: General
Topic: Multi WAN both on DHCP [SOLVED]
Replies: 22
Views: 2534

Re: Multi WAN both on DHCP [SOLVED]

Outside my scope! jajaja (pun intended)
by anav
Mon Mar 20, 2023 7:24 pm
Forum: Beginner Basics
Topic: Route specific IP only when connected to specific Virtual AP
Replies: 11
Views: 360

Re: Route specific IP only when connected to specific Virtual AP

Modified my post, I had an idea!!
see if that works,
it should be quick to try!!
by anav
Mon Mar 20, 2023 7:20 pm
Forum: Beginner Basics
Topic: Route specific IP only when connected to specific Virtual AP
Replies: 11
Views: 360

Re: Route specific IP only when connected to specific Virtual AP

Well thats silly.............. No way to isolate guest from family, or iOT devices etc. At least assign different subnets to the WLANs............. and dont use a bridge OR create vlans and assign to bridge. If your happy with one flat network then you will have to decide the complexity. How many pe...
by anav
Mon Mar 20, 2023 7:16 pm
Forum: General
Topic: Multi WAN both on DHCP [SOLVED]
Replies: 22
Views: 2534

Re: Multi WAN both on DHCP [SOLVED]

Yes you are just telling the router where to go by matching the script comment entry with the existing comment entry!

In other words we use the comment block as a tool to create an entry that is unique and found by router during script.
by anav
Mon Mar 20, 2023 7:12 pm
Forum: General
Topic: Wireguard help (again)
Replies: 25
Views: 849

Re: Wireguard help (again)

Its all here at the original link I gave you LOL one or two threads ago!

viewtopic.php?t=182340

Checkout (4) Configuring IP address
Checkout (9) C. UNDERSTANDING THE CRYPTO KEY ROUTING PROCESS (CKRP)
by anav
Mon Mar 20, 2023 7:03 pm
Forum: Beginner Basics
Topic: Route specific IP only when connected to specific Virtual AP
Replies: 11
Views: 360

Re: Route specific IP only when connected to specific Virtual AP

Yes............ How do you assign traffic (from internet/uplink) to users on multiple virtual wlans? (Assuming one MAIN WLAN and then several vWLANS using main WLAN as master) If via vlans then this becomes simple as you only need to do three things for a subnet lets say vlan10-Users which is 192.16...
by anav
Mon Mar 20, 2023 5:47 pm
Forum: General
Topic: Wireguard help (again)
Replies: 25
Views: 849

Re: Wireguard help (again)

This is my understanding of why this works: Non-212 endpoints have peer configs for 212 that have 10.10.100.0/24; doing this tells the other side (212) that 212 should route all 10.10.100.0/24 to it. NEGATIVE!!! FOR TWO REASONS. a. (outgoing) to be able to ping from a client device to any other dev...
by anav
Mon Mar 20, 2023 5:07 pm
Forum: Beginner Basics
Topic: Block access between wan, lan and VOIP
Replies: 3
Views: 193

Re: Block access between wan, lan and VOIP

Config makes no sense to me, can you draw a diagram of intentions.
There is no need for vlans if you are only using two ports.
Otherwise create one bridge and any subnet becomes a vlan on the bridge.
by anav
Mon Mar 20, 2023 4:52 pm
Forum: Wireless Networking
Topic: 802.11ax 4x4:4 Wi-Fi 6 Access Point
Replies: 3
Views: 379

Re: 802.11ax 4x4:4 Wi-Fi 6 Access Point

If you want 4x4 mu-mimo, and wifi6, look no further than the Chateau 5G AX.

Caveat: The 4x4 mu-mimo is only for the Cellular LOL.
by anav
Mon Mar 20, 2023 4:24 pm
Forum: Wireless Networking
Topic: Open SSID gets wrong VLAN
Replies: 8
Views: 602

Re: Open SSID gets wrong VLAN

Strange behaviour is what is absolutely expected due to the admins STRANGE configuration. The router is just following commands. :-0 Where did you get the config advice from ( which link )? 1. Thats because no one in their right mind assigns a vlan1 to the bridge. 2. Why are you using vlans in wifi ...
by anav
Mon Mar 20, 2023 2:44 pm
Forum: General
Topic: Wireguard help (again)
Replies: 25
Views: 849

Re: Wireguard help (again)

The errors have been explained many times....................
As I said, if you want me to teamviewer in, and do it myself, am willing.
Advice here is not getting through.
by anav
Mon Mar 20, 2023 2:39 pm
Forum: Scripting
Topic: Send Traceroute Report to the Telegram
Replies: 15
Views: 473

Re: Send Traceroute Report to the Telegram

rextended, first rule of discipline is that when you say end of help, it really means end of help ;-)
Dont write any childrens books..........
by anav
Mon Mar 20, 2023 2:27 pm
Forum: Beginner Basics
Topic: NAT to change IP addresses using dstnat on ip-range
Replies: 5
Views: 278

Re: NAT to change IP addresses using dstnat on ip-range

Check out this, fresh out of the box........
viewtopic.php?p=990947#p990947
by anav
Mon Mar 20, 2023 2:09 pm
Forum: General
Topic: Wireguard on mikrotik AND on PC attached to it
Replies: 11
Views: 534

Re: Wireguard on mikrotik AND on PC attached to it

Sorry no capiche. Do not use wireguard as a LAN subnet on routers. Clearly for single devices, the wireguard address is its address. For users on routers, they dont have a wireguard address and the subnet of wireguard on the router is to be able to ping devices, and create routes etc... So again its...
by anav
Mon Mar 20, 2023 12:51 pm
Forum: Useful user articles
Topic: Discovery & Cast With Wireguard
Replies: 6
Views: 544

Re: DISCOVERY/CAST WIREGUARD

6. Identical Subnets Using WG Between Two Locations (not my solution - dont have the smarts) SOLUTION METHOD: ADDING VIRTUAL SUBNETS VIA NETMAP The basic scenario is one where two locations joined via wireguard ( 172.22.0.0/24 ) have the same LANIP structure and both cannot be changed. A user on on...
by anav
Mon Mar 20, 2023 12:46 pm
Forum: General
Topic: WiFI VlAN Tag with upstream switch
Replies: 3
Views: 170

Re: WiFI VlAN Tag with upstream switch

I'm not paid enough for such novel thinking, however if MT added a zerotrust cloudflare options package for all MT devices, I would probably be inspired to recommend MT switches. ;-)
by anav
Mon Mar 20, 2023 12:38 pm
Forum: Beginner Basics
Topic: Wireguard: how to configure this network?
Replies: 12
Views: 956

Re: Wireguard: how to configure this network?

Can you clarify Router2. It seems you want it to be able to go out internet via 3 locations, local, vps and Router 0. Do you mean different subnets on Router2 or the same single subnet? If the latter this will not be possible I dont think. If router2 requests internet, its first peer to peer link wi...
by anav
Mon Mar 20, 2023 1:58 am
Forum: Beginner Basics
Topic: NAT to change IP addresses using dstnat on ip-range
Replies: 5
Views: 278

Re: NAT to change IP addresses using dstnat on ip-range

I think the problem is locally, any attempt to have a destination address in the same subnet will never see the light of day of an L3 rule. My grasp of fundamentals is weak so that is just a guess as sourcenat seems to come as a last step in traffic flow. Why not change device needing access to a di...
by anav
Mon Mar 20, 2023 1:43 am
Forum: General
Topic: WiFI VlAN Tag with upstream switch
Replies: 3
Views: 170

Re: WiFI VlAN Tag with upstream switch

You need to do this on the pfsense router and cisco switch so wrong forum.
by anav
Sun Mar 19, 2023 10:46 pm
Forum: General
Topic: Recursive routing from V6 to V7
Replies: 2
Views: 178

Re: Recursive routing from V6 to V7

read para I - viewtopic.php?t=182373

See recursive routing and two rules of thumb.
by anav
Sun Mar 19, 2023 9:33 pm
Forum: General
Topic: Network discovery over wireguard
Replies: 17
Views: 571

Re: Network discovery over wireguard

With the help of some friends, as I am not worthy or capable.
@HighTechLab This should solve your request!
viewtopic.php?p=990840#p990840
by anav
Sun Mar 19, 2023 9:22 pm
Forum: Useful user articles
Topic: Discovery & Cast With Wireguard
Replies: 6
Views: 544

Re: DISCOVERY/CAST WIREGUARD EOIP VXLAN UNIFI ETC

5. mDSN Discovery Between Home and Office Devices. ( help from others ) SOLUTION METHOD ADD A CONNECTING SUBNET/INTERMEDIARY - EOIP OVER WIREGUARD a. create wireguard connectivity as per normal and then b. create the EOIP tunnel within the WG tunnel ( EOIP never concerns its self ever with local WA...
by anav
Sun Mar 19, 2023 9:22 pm
Forum: Useful user articles
Topic: Discovery & Cast With Wireguard
Replies: 6
Views: 544

Re: DISCOVERY/CAST WIREGUARD EOIP VXLAN UNIFI ETC

4. Unifi Controller to Unifi APs via Wireguard & DNS+DHCP SOLUTION METHOD FOUR( preferred option ): Use DNS and DHCP a. create wireguard connectivity as per normal and then b. create the IP DNS SETTINGS and DHCP SERVER SETTINGS on Router 2. c. modify configs to allow Access Points via Wireguard...
by anav
Sun Mar 19, 2023 9:21 pm
Forum: Useful user articles
Topic: Discovery & Cast With Wireguard
Replies: 6
Views: 544

Re: DISCOVERY/CAST WIREGUARD EOIP VXLAN UNIFI ETC

3. Unifi Controller to Unifi APs via Wireguard & DHCP Option SOLUTION METHOD THREE: USE DHCP OPTION 43 a. create wireguard connectivity as per normal and then b. create the DHCP Option settings on R2 for the unifi Access Points. c. modify configs to allow Access Points via Wireguard (L3 traffic...
by anav
Sun Mar 19, 2023 9:21 pm
Forum: Useful user articles
Topic: Discovery & Cast With Wireguard
Replies: 6
Views: 544

Re: DISCOVERY/CAST WIREGUARD EOIP VXLAN UNIFI ETC

2. Unifi Controller to Unifi APs via Wireguard & VXLAN SOLUTION METHOD TWO: VXLAN OVER WIREGUARD [/b][/color]a. create wireguard connectivity as per normal and then b. create the VXLAN tunnel within the WG tunnel ( vxlan never concerns its self with local WANIPs at either end ) c. modify config...
by anav
Sun Mar 19, 2023 9:20 pm
Forum: Useful user articles
Topic: Discovery & Cast With Wireguard
Replies: 6
Views: 544

Re: DISCOVERY/CAST WIREGUARD EOIP VXLAN UNIFI ETC

1. Unifi Controller to Unifi APs via Wireguard & EOIP SOLUTION METHOD ONE: EOIP OVER WIREGUARD a. create wireguard connectivity as per normal and then b. create the EOIP tunnel within the WG tunnel ( EOIP never concerns its self ever with local WANIPs at either end ) c. modify configs to avoid ...
by anav
Sun Mar 19, 2023 9:16 pm
Forum: Useful user articles
Topic: Discovery & Cast With Wireguard
Replies: 6
Views: 544

Discovery & Cast With Wireguard

{ linked from New User Pathway To Success Config Success - https://forum.mikrotik.com/viewtopic.php?t=182373 } Please find the following potential Solutions attempting to get two locations to communicate for discovery/cast situations and other useful scenarios. The first four examples discuss how t...
by anav
Sun Mar 19, 2023 9:07 pm
Forum: General
Topic: Wireguard help (again)
Replies: 25
Views: 849

Re: Wireguard help (again)

I was hoping for...... Got it all working now I want to expand my wireguard network such that client devices on Server Router 212 are A, B, C, D, E, where E is router 312 - where E is going to act as a Server going to the following peers, Server for clients M, N, O, P - TWO relay points LOL, get a d...
by anav
Sun Mar 19, 2023 4:34 pm
Forum: General
Topic: WireGuard RoadWarior plus VLAN configuration
Replies: 13
Views: 735

Re: WireGuard RoadWarior plus VLAN configuration

(1) From /interface list members TO: /interface list member add interface=pppoe-out1 list=WAN add interface=vlan10 list=WAN add interface=BASE_VLAN list=VLAN add interface=BLUE_VLAN list=VLAN add interface=GREEN_VLAN list=VLAN add interface=RED_VLAN list=VLAN add interface=BASE_VLAN list=BASE [/size...
by anav
Sun Mar 19, 2023 4:12 pm
Forum: General
Topic: Network discovery over wireguard
Replies: 17
Views: 571

Re: Network discovery over wireguard

I dont believe its possible or more accurately I dont think its stable if you do........... Even in the same subnet its very tricky to get right.
by anav
Sun Mar 19, 2023 4:05 pm
Forum: General
Topic: Wireguard help (again)
Replies: 25
Views: 849

Re: Wireguard help (again)

Its simple, At initial connection, the handshake there is between one client and one server. In your case you have many clients and thus each will undergo an initial handshake with 212. You ONLY have peer to peer networks between each client and the Server. There is no direct peer to peer connection...
by anav
Sun Mar 19, 2023 3:19 pm
Forum: General
Topic: Network discovery over wireguard
Replies: 17
Views: 571

Re: Network discovery over wireguard

Good thread! ZEROTIER is the clear answer both being arm devices. @OP, to be clear the person requiring access to devices at work lives at home so its HOME TO WORK flow? @ UpRunTech, were the subnets you connected via EOIP, different. My understanding is that spanning has to be to the same subnet?? ...
by anav
Sun Mar 19, 2023 12:11 am
Forum: General
Topic: Wireguard help (again)
Replies: 25
Views: 849

Re: Wireguard help (again)

If 212 is the only main server for handshakes, I pointed out why its not working and the fixes.
Ensure you do them and post again for any additional refinements...........
by anav
Sat Mar 18, 2023 9:50 pm
Forum: General
Topic: Container/Docker -Adguard/Pihole For REAL.
Replies: 20
Views: 831

Re: Container/Docker -Adguard/Pihole For REAL.

And to the point, if it aint vlans ( and one or more bridges ) not interested.
by anav
Sat Mar 18, 2023 6:01 pm
Forum: Beginner Basics
Topic: Internet access control at home
Replies: 6
Views: 535

Re: Internet access control at home

isnt there kids home function on router??
by anav
Sat Mar 18, 2023 3:18 pm
Forum: General
Topic: No access to internal network from OpenVPN clients
Replies: 5
Views: 230

Re: No access to internal network from OpenVPN clients

Hahaha, like I said, wireguard is included on RoS, no need for any additional complexity............ can lead a horse to water........
by anav
Sat Mar 18, 2023 2:21 pm
Forum: General
Topic: Wireguard help (again)
Replies: 25
Views: 849

Re: Wireguard help (again)

HEX212: The only two things noted on 212 are below, so dont really see a show stopper here....... (1) Your laptop etc is missing persistent-keep-alive setting on the peer for 212. (2) Why do you have keep alive set on the HEX for all the client peers that are routers except the one discussed at (2)...
by anav
Sat Mar 18, 2023 1:47 pm
Forum: Beginner Basics
Topic: hEX setup as a PPPoE router + dumb switch
Replies: 2
Views: 187

Re: hEX setup as a PPPoE router + dumb switch

(1) The IP address of your LAN network should be interface bridge !!! /ip address add address=192.168.1.1/24 comment=defconf interface= ether2 network=\ 192.168.1.0 (2) DISABLE or remove THIS rule as your internet is done through pppoe /ip dhcp-client add comment=defconf interface=ether1 (3) You for...
by anav
Sat Mar 18, 2023 1:42 pm
Forum: Beginner Basics
Topic: Block access between wan, lan and VOIP
Replies: 3
Views: 193

Re: Block access between wan, lan and VOIP

Its probably due to the default firewall rules which pretty much are safe but allow LAN to LAN traffic at layer 3. To confirm would need to see your config to adjust the firewall.......... /export file=anynameyouwish ( minus router serial number or any public WAN IP information ). [Since it looks li...
by anav
Sat Mar 18, 2023 5:06 am
Forum: Beginner Basics
Topic: Can't get source NAT to work
Replies: 2
Views: 327

Re: Can't get source NAT to work

Regular Servers dont originate traffic..............So why does this one? --> Does it stream for example

YOu have to ensure traffic is routed out the appropriate WAN or ensure the WAN being used has source nat associated.
by anav
Fri Mar 17, 2023 11:14 pm
Forum: General
Topic: Container/Docker -Adguard/Pihole For REAL.
Replies: 20
Views: 831

Re: Container/Docker -Adguard/Pihole For REAL.

Yes but AMMO clearly MT and others are pushing the idea of a separate bridge just for containers but I prefer a separate VLAN for each service/functionality.
by anav
Fri Mar 17, 2023 11:11 pm
Forum: General
Topic: No access to internal network from OpenVPN clients
Replies: 5
Views: 230

Re: No access to internal network from OpenVPN clients

Yeah, use wireguard, faster, easier better supported by RoS.
by anav
Fri Mar 17, 2023 11:10 pm
Forum: General
Topic: Wireguard on mikrotik AND on PC attached to it
Replies: 11
Views: 534

Re: Wireguard on mikrotik AND on PC attached to it

Why do you have the private LANs identical behind both routers that can get confusing fast and not a good idea generally.
by anav
Fri Mar 17, 2023 6:38 pm
Forum: General
Topic: Container/Docker -Adguard/Pihole For REAL.
Replies: 20
Views: 831

Re: Container/Docker -Adguard/Pihole For REAL.

Lets forget Pi-hole its so yesterday (betamax). Either discuss adguard or blocky for example.
by anav
Fri Mar 17, 2023 4:37 pm
Forum: Beginner Basics
Topic: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]
Replies: 16
Views: 546

Re: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]

Okay so you want it as a dumb switch which tells me you only have one subnet coming into it and its feeding a bunch of dumb devices on one subnet. In other words, as always I never trust what people say/write, I only go by the evidence and your diagrams and config support the fact that the RB4011 is...
by anav
Fri Mar 17, 2023 4:13 pm
Forum: General
Topic: Wireguard on mikrotik AND on PC attached to it
Replies: 11
Views: 534

Re: Wireguard on mikrotik AND on PC attached to it

sorry no images are being shown, and do you have a config on the MT to show?
by anav
Fri Mar 17, 2023 4:06 pm
Forum: General
Topic: Check please my configuration and firewall
Replies: 6
Views: 541

Re: Check please my configuration and firewall

(1) I can understand you making changed to the forward chain, aka to refine access but what I dont understand is the BS rules you add in the input chain. /ip firewall filter add action=accept chain=input comment="established, related, untracked" \ connection-state=established,related,untra...
by anav
Fri Mar 17, 2023 3:40 pm
Forum: Beginner Basics
Topic: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]
Replies: 16
Views: 546

Re: VLAN - no ip but dhcp lease offered for wifi interface on ap [SOLVED]

So the AX3 is your main router and the RB4011 is WHAT? Supposed to be a AP/Switch or another router ( do you really want double NAT )???
by anav
Fri Mar 17, 2023 3:36 pm
Forum: Beginner Basics
Topic: Basic VLAN config
Replies: 1
Views: 174

Re: Basic VLAN config

Nothing is clear, network diagram needed!
Is RB4011 main router attached to internet and switch is behind the router
OR
is RB4011 simply a switch within a nework etc......
by anav
Fri Mar 17, 2023 3:34 pm
Forum: Beginner Basics
Topic: Trunk and VLAN's - RB951, Router os 6.4x
Replies: 2
Views: 115

Re: Trunk and VLAN's - RB951, Router os 6.4x

nework diagram please, are both acting as routers, where is internet, etc.......
by anav
Fri Mar 17, 2023 3:39 am
Forum: Containers
Topic: DNS not working in containers with DNS over HTTPS setup on router
Replies: 7
Views: 680

Re: DNS not working in containers with DNS over HTTPS setup on router

Hi there, so you use containers for some functionality, but use the DOH on the router itself. Q1. Did the solution you found to your issue, mean that the Container bypasses DOH for DNS and goes to the router to DND and then out to the internet? Q2. If not, how did you get the containers traffic to t...
by anav
Fri Mar 17, 2023 3:29 am
Forum: General
Topic: Container/Docker -Adguard/Pihole For REAL.
Replies: 20
Views: 831

Re: Container/Docker -Adguard/Pihole For REAL.

Thats fine but I have a single bridge with multiple VLANS.
So you are saying create a separate vlan for the docker??
by anav
Fri Mar 17, 2023 12:08 am
Forum: General
Topic: Multiple WAN and Wireguard all traffic (without one bridge traffic)
Replies: 2
Views: 175

Re: Multiple WAN and Wireguard all traffic (without one bridge traffic)

(1) This can be shortened. If using bridge and not vlans, the two bridges suffices for LAN interface list members! Also I see no purpose to the VPN list ?????? /interface list member add comment=defconf interface=bridge list=LAN add interface=lte_play list=WAN add interface=wg_biuro_lux list=VPN ???...
by anav
Thu Mar 16, 2023 11:37 pm
Forum: General
Topic: Container/Docker -Adguard/Pihole For REAL.
Replies: 20
Views: 831

Container/Docker -Adguard/Pihole For REAL.

If one does go down the route of using some sort of DNS protection there are many options. 1. USE IPV4 servers from DNS providers that have some decent functionality against ads etc. These seem to work well but do not provide any granularity into whats is happening with clients etc..... no dashboard...
by anav
Thu Mar 16, 2023 11:07 pm
Forum: General
Topic: Route ALL traffic for 1 LAN IP from site A (via Wiregard tunnel) to site B
Replies: 20
Views: 2033

Re: Route ALL traffic for 1 LAN IP from site A (via Wiregard tunnel) to site B

Normally its a good idea to solve issues before piling on new stuff LOL.
by anav
Thu Mar 16, 2023 5:00 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 225
Views: 318185

Re: Using RouterOS to VLAN your network

Your theories only hurt us practical guys LOL
by anav
Thu Mar 16, 2023 3:16 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 225
Views: 318185

Re: Using RouterOS to VLAN your network

Why is this required?? You already have on the /interface bridge ports, ingress-filtering=yes and frame-types identified ????? ####################################### # Turn on VLAN mode ####################################### /interface bridge set BR1 vlan-filtering=yes frame-types=admit-only-vlan-...
by anav
Thu Mar 16, 2023 1:18 am
Forum: General
Topic: What model to use?
Replies: 31
Views: 1157

Re: What model to use?

Yes but this is the first time you mention you already have the router I was suggesting the 2116 LOL.. Good to go then.

The only router you pointed out was the 2004, which we know now, since you actually provided useful information, is NOT hooked up to fiber but to the 2116.
by anav
Wed Mar 15, 2023 11:14 pm
Forum: General
Topic: What model to use?
Replies: 31
Views: 1157

Re: What model to use?

No LOL, I mean YOU are paying for 10gig fibre connection. 1. You have customer A, who wants to pay you for 5gigs for throughput 2. You may need some throughput for your own needs in same location (unknown , no context) 3. You are looking for other customers at location B,C,D that may want 1gig servi...
by anav
Wed Mar 15, 2023 9:08 pm
Forum: General
Topic: What model to use?
Replies: 31
Views: 1157

Re: What model to use?

You missed my point completely sippan, he should adjust for his fibre throughput not the throughput to the client............
by anav
Wed Mar 15, 2023 9:06 pm
Forum: Beginner Basics
Topic: Forward port 80 on wan to 192.168.1.10:80 from outside and inside networks
Replies: 9
Views: 881

Re: Forward port 80 on wan to 192.168.1.10:80 from outside and inside networks

Highly recommend that all those using your server provide you with their fixed static WANIP or their WANIP via a dyndns name. No excuses there are plenty of free providers. Then you make up an address list of those users..................... add chain=dstnat action=dst-nat dst-address-list=MYWANIP d...
by anav
Wed Mar 15, 2023 9:02 pm
Forum: Beginner Basics
Topic: Forward port 80 on wan to 192.168.1.10:80 from outside and inside networks
Replies: 9
Views: 881

Re: Forward port 80 on wan to 192.168.1.10:80 from outside and inside networks

Some routers are for home owners, plugNplay. MT is for those who are willing to learn how traffic flows in devices and then have to program the router accordingly. If you expect to read an article without any understanding of ROS and make complete sense of it, then you are mistaken Its called experi...
by anav
Wed Mar 15, 2023 7:35 pm
Forum: General
Topic: What model to use?
Replies: 31
Views: 1157

Re: What model to use?

Hi Angel, the logic escapes me? You have a 10Gigabit Fibre line you are paying for. You have one customer that is asking for 5gb, Solution: Get a router that can handle 5gb only ?? Test result for queues and filters show a throughput of between 5-8gigs Better Solution: Get a router that can handle 1...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 52