Community discussions

MikroTik App

Search found 18285 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 61
by anav
Tue Dec 05, 2023 11:30 pm
Forum: Beginner Basics
Topic: Mullvad WG VPN as a second WAN for use of a subnet?
Replies: 1
Views: 83

Re: Mullvad WG VPN as a second WAN for use of a subnet?

Yeah use vlan filtering for the subnets, one bridge............
The bizarro approach to address, dhcp server pool,, if not for a specific needed reasons is cutsie crap for nothing.

viewtopic.php?t=14362
by anav
Tue Dec 05, 2023 11:28 pm
Forum: Wireless Networking
Topic: 802.11r for hAP ac2?
Replies: 71
Views: 9629

Re: 802.11r for hAP ac2?

Now lets get real and work on WIFI -7, that is where the meat is on the wifi BONE.
by anav
Tue Dec 05, 2023 6:25 pm
Forum: Wireless Networking
Topic: Wi-Fi 6E devices for an new project
Replies: 10
Views: 516

Re: Wi-Fi 6E devices for an new project

RICH, please dont waste valuable mikrotik resources on an interim, dead before it goes out the door, 6E standard. TP link and other are rolling out Wi-Fi 7 already and even zyxel is heavily discounting (dumping its new 6E stock). Normis, do not pass go, do not collect $200, go straight to jail if yo...
by anav
Tue Dec 05, 2023 5:34 pm
Forum: General
Topic: Port access and port trunk
Replies: 1
Views: 90

Re: Port access and port trunk

by anav
Tue Dec 05, 2023 4:35 pm
Forum: General
Topic: Routing rule VS mangle mark routing
Replies: 5
Views: 243

Re: Routing rule VS mangle mark routing

Also the requirement should be expressed in terms of user traffic required.
Mangling and routing rules are simply tools to use, for a purpose, and that purpose has not been communicated........
by anav
Tue Dec 05, 2023 2:44 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 1904

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

PM me the exact config, sure..........
For all ip routes its best to use the correct gateway vice etherX........... ( exception that comes to mind is wireguard )
If nothing else to demonstrate that the routes are meant for Static IPs/gateways, whereas one would need s cripts for dynamic ones.
by anav
Tue Dec 05, 2023 2:38 pm
Forum: Beginner Basics
Topic: PCC Config glitching but working ?
Replies: 1
Views: 87

Re: PCC Config glitching but working ?

As per your other post, (1) MISMATCH in address and gateway!! (2) Duplicate routes. /ip address add address=192.168.100.1/24 interface="LAN bridge" network=192.168.100.0 add address= 100. 90 . 8 0. 70 /29 interface=ether1 network=100.90.80.70 add address=110.100.90.80/30 interface=ether2 n...
by anav
Tue Dec 05, 2023 2:37 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 1904

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

Also it would appear you have some duplicates.......... /ip route add check-gateway=ping disabled=no distance=1 dst-address=0.0.0.0/0 gateway=100.80.90.70 pref-src="" routing-table=main scope=30 \ suppress-hw-offload=no target-scope=10 add check-gateway=ping disabled=no distance=2 dst-addr...
by anav
Tue Dec 05, 2023 2:32 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 1904

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

Sure, took me a couple of secs to find the problem. /ip address add address=192.168.100.1/24 interface="LAN bridge" network=192.168.100.0 add address= 100. 90 . 80 . 70 /29 interface=ether1 network=100.90.80.70 add address=110.100.90.80/30 interface=ether2 network=110.100.90.80 add address...
by anav
Mon Dec 04, 2023 10:39 pm
Forum: General
Topic: "NAT forward to gateway"
Replies: 10
Views: 482

Re: "NAT forward to gateway"

This is your basic default firewall ruleset with a focus on only identifying needed traffic and dropping everything else. /ip firewall-address list { using static dhcp leases mostly } add address=admin-IP1 list=Authorized comment="admin local desktop" add address=admin-IP2 list=Authorized ...
by anav
Mon Dec 04, 2023 9:57 pm
Forum: Beginner Basics
Topic: 2 WAN connections, mangle rules and wireguard [SOLVED]
Replies: 29
Views: 4663

Re: 2 WAN connections, mangle rules and wireguard [SOLVED]

Well what I recommend between two routers is Setting up WIREGUARD between the two, and if the server goes down, due to WAN1 failing, the client will regenerage the connection on WAN2 as I described. As the backup simply connect an easy MT to MT SSTP backup direct to WAN2. Thus you always have a seco...
by anav
Mon Dec 04, 2023 9:13 pm
Forum: Wireless Networking
Topic: hap ax2 + wireless access points
Replies: 5
Views: 283

Re: hap ax2 + wireless access points

If one has coax between rooms --> moca, if one has modern wiring - powerline are both options.
MOCA adapters can go up to 2.5 gig
https://www.electronicshub.org/best-moca-adapters/

Powerline.......... https://www.techradar.com/news/the-best ... e-adaptors
by anav
Mon Dec 04, 2023 9:11 pm
Forum: General
Topic: Unable to change default IP on RB5009
Replies: 20
Views: 750

Re: Unable to change default IP on RB5009

Maybe it doesnt work with the new wifiwave wave of products.
Or it was a big security risk?
by anav
Mon Dec 04, 2023 8:56 pm
Forum: Beginner Basics
Topic: 2 WAN connections, mangle rules and wireguard [SOLVED]
Replies: 29
Views: 4663

Re: 2 WAN connections, mangle rules and wireguard [SOLVED]

Hi Broderick, this already happens!! If you have a wireguard server on your Router and WAN1 is the primary, and it goes down the router switches to WAN2, the clients connecting to your WG server will lose connectivity and will try to reconnect and when the WANIP for the router becomes the second ISP...
by anav
Mon Dec 04, 2023 8:49 pm
Forum: General
Topic: Unable to change default IP on RB5009
Replies: 20
Views: 750

Re: Unable to change default IP on RB5009

So you can enter the router via the USB device? Just curious, how do you type on the usb device? small keyboard?
by anav
Mon Dec 04, 2023 7:45 pm
Forum: General
Topic: Unable to change default IP on RB5009
Replies: 20
Views: 750

Re: Unable to change default IP on RB5009

Not sure what it has to do with changing IP but okay.....
by anav
Mon Dec 04, 2023 6:29 pm
Forum: General
Topic: Unable to change default IP on RB5009
Replies: 20
Views: 750

Re: Unable to change default IP on RB5009

NM , posted in error
by anav
Mon Dec 04, 2023 6:28 pm
Forum: Beginner Basics
Topic: Good switch for home use or RB4011 RB5009?
Replies: 18
Views: 10542

Re: Good switch for home use or RB4011 RB5009?

NM....
by anav
Mon Dec 04, 2023 5:48 pm
Forum: Beginner Basics
Topic: L009UiGS-2HaxD-IN fast enough for 1GBIT Internet?
Replies: 4
Views: 219

Re: L009UiGS-2HaxD-IN fast enough for 1GBIT Internet?

What you can do is actually research a product before buying it. Too late now, but on the product page have a look at TEST RESULTS. The throughput one should expect to get with some basic filter rules is somewhere between 300-600Mbps. For 1 gig throughput your best bets are. a. hapax3 --> just over ...
by anav
Mon Dec 04, 2023 3:33 pm
Forum: Beginner Basics
Topic: Failover between 2 ISPs using gateways with same IP (was NAT traffic to VRF)
Replies: 36
Views: 3525

Re: Failover between 2 ISPs using gateways with same IP (was NAT traffic to VRF)

Well if they are static Ips, then that would be easier to deal with, you should confirm with your ISP that they are static!
Confirm you are paying for two separate 1 gig connections? and on each one you can get 1 gig at the same time......
by anav
Mon Dec 04, 2023 1:44 pm
Forum: Beginner Basics
Topic: Failover between 2 ISPs using gateways with same IP (was NAT traffic to VRF)
Replies: 36
Views: 3525

Re: Failover between 2 ISPs using gateways with same IP (was NAT traffic to VRF)

Well I dont understand this o ne...........
but within my LAN I need to allow access between all the VLANs.

Can you elaborate? If they all need access to each other why have separate vlans?

Can you confirm these are dynamic IPs that change BUT the gateway never changes??
by anav
Mon Dec 04, 2023 1:43 pm
Forum: Beginner Basics
Topic: About "Building Your First Firewall" ICMP jump-chain
Replies: 13
Views: 712

Re: About "Building Your First Firewall" ICMP jump-chain

If your server does not have secure login (encrypted) then you shouldnt be using those servers. Assuming they are secure logins, consider a. src-address-list on your dst-nat rules ( everyone is comming from a public IP address, static or dynamic either directly or from their upstream ISP modem/route...
by anav
Mon Dec 04, 2023 4:53 am
Forum: Beginner Basics
Topic: Failover between 2 ISPs using gateways with same IP (was NAT traffic to VRF)
Replies: 36
Views: 3525

Re: Failover between 2 ISPs using gateways with same IP (was NAT traffic to VRF)

Ahh okay one modem two WAN IPs, same gateway address............ Okay that makes sense, my bad.
by anav
Mon Dec 04, 2023 2:35 am
Forum: Beginner Basics
Topic: Failover between 2 ISPs using gateways with same IP (was NAT traffic to VRF)
Replies: 36
Views: 3525

Re: Failover between 2 ISPs using gateways with same IP (was NAT traffic to VRF)

What are you talking about? The original OP stated he was getting the same IP gateway from two ISPs starlink and something else, aka gateway=192.168.1.1 What does that have to do with you having two 1gig connections? Are you saying you are using two ISP supplied modem routers in front of you and eac...
by anav
Mon Dec 04, 2023 2:20 am
Forum: General
Topic: NordVPN too Slow after configuration
Replies: 1
Views: 170

Re: NordVPN too Slow after configuration

Use wireguard instead!!!
by anav
Mon Dec 04, 2023 2:18 am
Forum: General
Topic: Unable to change default IP on RB5009
Replies: 20
Views: 750

Re: Unable to change default IP on RB5009

Word of advice, assign to an empty port an IP address and work safely from that port to do all your config initially and then later acts as an emergency access, besides lot of use of SAFE MODE!!
viewtopic.php?t=181718
by anav
Mon Dec 04, 2023 2:14 am
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 28
Views: 2745

Re: Firewall - DNS Open? - Urgent [SOLVED]

Once you provide the details on wireguard I will send an updated config, that gets rid of all the crap..............
by anav
Mon Dec 04, 2023 2:11 am
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 28
Views: 2745

Re: Firewall - DNS Open? - Urgent [SOLVED]

You really need to explain your wireguard setup . ITS STILL WRONG!!! Where is the server for VPN01 for handshake? if not this router then this router is the client for handshake? Where is the server for MGNT for handshake? if not this router then this router is the client for handshake? Server Devi...
by anav
Mon Dec 04, 2023 2:00 am
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 28
Views: 2745

Re: Firewall - DNS Open? - Urgent [SOLVED]

If its disabled on the config, I delete it when looking at it....... KISS I delete all capsman config entries for easier viewing, now the config is looking smaller LOL No problem for queues, I worked around that so you can user fastrack for everything else......... You forgot to add additional vlans...
by anav
Sun Dec 03, 2023 8:07 pm
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 28
Views: 2745

Re: Firewall - DNS Open? - Urgent [SOLVED]

YOur three wans, in IP DHCP CLIENT did you enable default routes and if so did you put any script in there..........??

Right now there is no way to determine how you setup the WANs in terms of priority..........??
by anav
Sun Dec 03, 2023 7:36 pm
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 28
Views: 2745

Re: Firewall - DNS Open? - Urgent [SOLVED]

Which subnets or list of individual devices should be getting NTP services from the router??? Where are the remote subnets coming from in this rule................?? add action=accept chain=forward comment=Accept_Remote_to_Company \ dst-address-list=COMPANY src-address-list=REMOTE Reminder........ a...
by anav
Sun Dec 03, 2023 7:28 pm
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 28
Views: 2745

Re: Firewall - DNS Open? - Urgent [SOLVED]

This rule makes no sense to me...... add action=accept chain=input comment="Accept Radius" dst-port=3799,1812,1813 \ in-interface-list=!WAN protocol=udp src-address-list=FIREWAL WHere the only entry for firewall address list is the following add address=127.0.0.1 list=FIREWALL Another rule...
by anav
Sun Dec 03, 2023 6:54 pm
Forum: Beginner Basics
Topic: Failover between 2 ISPs using gateways with same IP (was NAT traffic to VRF)
Replies: 36
Views: 3525

Re: Failover between 2 ISPs using gateways with same IP (was NAT traffic to VRF)

Have you considered NOT using the starlink router and connect CGNAT direct to your router?
Your gateway in this case will be 100.64.0.1 ............ or something like that.
by anav
Sun Dec 03, 2023 6:26 pm
Forum: Useful user articles
Topic: Wireguard Success For The Beginner
Replies: 164
Views: 78334

Re: Wireguard Success For The Beginner

I see the issue. The paragraph stood on its own and if you tried to correlate with the previous para, it would seem non-congruent. I have adjusted it so that confusion is removed. Much thanks!
by anav
Sun Dec 03, 2023 5:26 pm
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 28
Views: 2745

Re: Firewall - DNS Open? - Urgent [SOLVED]

I will have a look. I am actually hoping that you are understanding the config better and learning as you go and gaining confidence in your own skills! Observations: 1. You have many vlans identified but not fully configured, assumed this was future plans and removed them from the config for the mom...
by anav
Sun Dec 03, 2023 3:05 pm
Forum: Beginner Basics
Topic: About "Building Your First Firewall" ICMP jump-chain
Replies: 13
Views: 712

Re: About "Building Your First Firewall" ICMP jump-chain

Why, none of those things are required for port forwarding.
by anav
Sun Dec 03, 2023 3:03 pm
Forum: Beginner Basics
Topic: Help with vlan, bridge and internet.
Replies: 3
Views: 227

Re: Help with vlan, bridge and internet.

Actually the RB4011 has two chips on it, so it kinda makes sense to split it into two bridges, but if my memory recalls only one of them will have Offload so in the end one bridge is best.
by anav
Sat Dec 02, 2023 10:42 pm
Forum: Useful user articles
Topic: Wireguard Success For The Beginner
Replies: 164
Views: 78334

Re: Wireguard Success For The Beginner

First, thanks for reviewing and making suggestions!!

Not sure I follow?
The setting in red, is under the heading of
/ip dhcp-network server NOT /ip address ???
by anav
Sat Dec 02, 2023 9:50 pm
Forum: General
Topic: Wireguard tunnel - speed problem
Replies: 18
Views: 929

Re: Wireguard tunnel - speed problem

Hmm, way better than my results 1gig to 1gig connection but that was using an RB4011 at one end and RGB450Gx4 at the other.
by anav
Sat Dec 02, 2023 7:16 pm
Forum: Beginner Basics
Topic: Issue with CAPsMAN v2 managing its own device
Replies: 8
Views: 451

Re: Issue with CAPsMAN v2 managing its own device

Good common sense information here!!!
Should go in your 'article' Holvoe,,,,,,,,, when the move is done. :-)
by anav
Sat Dec 02, 2023 6:44 pm
Forum: Beginner Basics
Topic: Issue with CAPsMAN v2 managing its own device
Replies: 8
Views: 451

Re: Issue with CAPsMAN v2 managing its own device

I just may hire you to setup my wifi.................. I just cannot afford the postage and cost of envelope to send the cheque. :-)
by anav
Sat Dec 02, 2023 5:57 pm
Forum: General
Topic: Wireguard tunnel - speed problem
Replies: 18
Views: 929

Re: Wireguard tunnel - speed problem

I would say 300-350 is pretty decent wireguard speeds, I would not be complaining.
by anav
Sat Dec 02, 2023 5:54 pm
Forum: Beginner Basics
Topic: Issue with CAPsMAN v2 managing its own device
Replies: 8
Views: 451

Re: Issue with CAPsMAN v2 managing its own device

In plain english, the setup for wifi on the device hosting capsman is different or separate from the wifi settings within capsman for the external devices.???
by anav
Sat Dec 02, 2023 2:50 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 1904

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

Generally anything is possible but its best to detail all the requirements PRIOR to setting up a config. I would stick to source for PCC because of the banking requirements etc....... I would also contemplate using the # of WANS you need to distribute traffic and then perhaps a couple of dedicated W...
by anav
Sat Dec 02, 2023 2:45 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 1904

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

Again, I dont understand the purpose. Showing someone combined WAN output is a useless exercise. Firstly unless you have a bonded setup with the SAME iSP you cannot ADD the throughput of ISP connection and do a speed test that shows the addition of all of them. What you do have is a larger total ban...
by anav
Sat Dec 02, 2023 2:40 pm
Forum: Beginner Basics
Topic: Need to block parent routers DHCP range
Replies: 2
Views: 201

Re: Need to block parent routers DHCP range

Concur, ideally the Landlord isnt using the same LAN for all his devices, but it seems to be the case. Probably one flat LAN.
Is the landlords router actually the iSPs modem/router or is it his own separate router. If so does it get a public IP?
by anav
Sat Dec 02, 2023 2:37 pm
Forum: Beginner Basics
Topic: Mikrotik Router to Router VLAN Setup [SOLVED]
Replies: 3
Views: 287

Re: Mikrotik Router to Router VLAN Setup [SOLVED]

Further this article addresses using any MT device as an AP/switch ( same same just without AP part).
viewtopic.php?t=182276
by anav
Sat Dec 02, 2023 2:32 pm
Forum: General
Topic: Wireguard Road Warrior to L2 LAN [SOLVED]
Replies: 4
Views: 308

Re: Wireguard Road Warrior to L2 LAN [SOLVED]

You need to understand better the use and setup of allowed IPs........
Check this -->viewtopic.php?t=182340
by anav
Fri Dec 01, 2023 11:47 pm
Forum: Beginner Basics
Topic: VLANs on hAP ax2, v7.13, no CAPsMAN - how?
Replies: 5
Views: 415

Re: VLANs on hAP ax2, v7.13, no CAPsMAN - how?

According to other experts here just stick to the defaults as much as possible....... and that its easy.
I beg to differ but check out some newer videos by MT for wifi, they will be helpful.
by anav
Fri Dec 01, 2023 11:45 pm
Forum: General
Topic: Wireguard client can't access local lan and internet
Replies: 6
Views: 455

Re: Wireguard client can't access local lan and internet

This is a mikrotik forum, if you have windows questions, go to a windows forum or a wireguard forum where windows may be discussed.
by anav
Fri Dec 01, 2023 11:44 pm
Forum: General
Topic: Como acceder en la configuracion de mi router, MikroTik?
Replies: 2
Views: 6674

Re: Como acceder en la configuracion de mi router, MikroTik?

First of all, the router is NOT yours it belongs to the ISP so respect their wishes. However since their device is acting as an ISP/ROUTER and you get a private IP, it is very normal to ask: a. if they can forward ports on the router for you OR b. they can describe the steps you can take to forward ...
by anav
Fri Dec 01, 2023 11:41 pm
Forum: General
Topic: Incomplete settings import
Replies: 2
Views: 205

Re: Incomplete settings import

RSC is not meant for exporting importing.
THe only function that does that is BACKUP and RESTORE and that is for the same device.
You can use an export to guide you manuallly configuring the new device,
and if you know what you are doing you can import chuncks of config via the TERMINAL CLI window.
by anav
Fri Dec 01, 2023 1:52 pm
Forum: General
Topic: Wireguard client can't access local lan and internet
Replies: 6
Views: 455

Re: Wireguard client can't access local lan and internet

If their devices do not allow split tunneling, then perhaps its not possible?
by anav
Fri Dec 01, 2023 5:54 am
Forum: General
Topic: Wireguard client can't access local lan and internet
Replies: 6
Views: 455

Re: Wireguard client can't access local lan and internet

Your explanation is off. If you mean to say that your MT router is the server and the remote clients can connect and reach local router services that would make more sense. Further if the computers that the remote users have cannot reach their local resources that is an issue with the devices they a...
by anav
Fri Dec 01, 2023 5:51 am
Forum: Beginner Basics
Topic: VLANs on hAP ax2, v7.13, no CAPsMAN - how?
Replies: 5
Views: 415

Re: VLANs on hAP ax2, v7.13, no CAPsMAN - how?

Much easier not to use capsman for only one AP .....

For vlans, use this guide. viewtopic.php?t=143620
by anav
Thu Nov 30, 2023 11:26 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 256
Views: 380608

Re: Using RouterOS to VLAN your network

Is this a planned exciting move, or a not so glad eviction notice?
by anav
Thu Nov 30, 2023 11:07 pm
Forum: Beginner Basics
Topic: Unintentionally isolated ethernet ports on RB5009
Replies: 7
Views: 459

Re: Unintentionally isolated ethernet ports on RB5009

Personally I dont ping other users for a living, it is of zero value to me. Can users access the devices they need to access on the LAN and conduct work? Or are they blocked? It doesnt matter what port they are connected to if all ports are part of the same bridge. All to say is so far I do not see ...
by anav
Thu Nov 30, 2023 10:41 pm
Forum: Virtualization
Topic: Documentation improvement: Are the container stateful or stateles?
Replies: 3
Views: 365

Re: Documentation improvement: Are the container stateful or stateles?

@normis--> suggest video how to use vlans with capsman.......... Basically the presenter should take this article viewtopic.php?t=143620
and 'bend it' as required for capsman.
by anav
Thu Nov 30, 2023 10:37 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 256
Views: 380608

Re: Using RouterOS to VLAN your network

The article is meant for vlans primarily and is not intended for vlans under capsman.
I agree its sorely needed but that is best left to an article describing capsman setup and suggest you go bug holvoetn to make such an article ;-)
by anav
Thu Nov 30, 2023 10:17 pm
Forum: General
Topic: Newbie with firewall - Is there a way of combining rules (lesser is better?)
Replies: 2
Views: 244

Re: Newbie with firewall - Is there a way of combining rules (lesser is better?)

Firewall rule guidelines 1. Single Subnets --> use dst-address or src-address 2. More than one subnet (whole subnets) --> use interface lists 3. If you have any list that includes a bunch of users (less than a subnet) or from different subnets (with or without whole subnets) then use firewall addres...
by anav
Thu Nov 30, 2023 10:11 pm
Forum: Beginner Basics
Topic: Unintentionally isolated ethernet ports on RB5009
Replies: 7
Views: 459

Re: Unintentionally isolated ethernet ports on RB5009

This is an unusual rule, did you invent it yourself, or watch youtube from hell channel?? At least its disabled. At the moment I see no reason why users cannot see each other being all on the same subnet and visible at L2. If there are no issues between wired users but issues betwee wired and wired ...
by anav
Thu Nov 30, 2023 6:51 pm
Forum: Beginner Basics
Topic: Moving from DD-WRT to RB3011
Replies: 6
Views: 347

Re: Moving from DD-WRT to RB3011

No that is too old for one thing and is not the link I provided for vlan setup. Dont run away from help LOL.
by anav
Thu Nov 30, 2023 6:48 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 1904

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

1) If some users speed test will they receive the combined speed test result. If not can we make it so that they are able to achieve that result (this is just a requirement and i understand that LB is not for this) Do not understand the question? Conducting a speed test is not a valid user requirem...
by anav
Thu Nov 30, 2023 5:55 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 1904

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

(1) By the way, using ether1, ether2, ether3 WORKS in your config as all your WANIPs are static. My example should reflect the IPs only, so as to not lead others astray. No need to change your config in that regard but I will change my example provided above. :-) (2) Also I may confuse people by usi...
by anav
Thu Nov 30, 2023 5:40 pm
Forum: General
Topic: Road warrior Wireguard
Replies: 5
Views: 398

Re: Road warrior Wireguard

Would concur, wireguard does not scale (pun intended) like an enterprise VPN.
However, tailscale which depends however on a third party, may have some tools/functionality to support such a requirement.

https://tailscale.com/
by anav
Thu Nov 30, 2023 5:38 pm
Forum: Beginner Basics
Topic: Unintentionally isolated ethernet ports on RB5009
Replies: 7
Views: 459

Re: Unintentionally isolated ethernet ports on RB5009

You clearly know where the problem lies, by NOT including your full config.
by anav
Thu Nov 30, 2023 5:35 pm
Forum: Beginner Basics
Topic: Moving from DD-WRT to RB3011
Replies: 6
Views: 347

Re: Moving from DD-WRT to RB3011

Yes absolutely recommend wireguard for both connecting to proton and to host your own wireguard so you can remote into the router to config it or for LAN services or to use its internet or to be forwarded out protons internet.
by anav
Thu Nov 30, 2023 5:32 pm
Forum: Beginner Basics
Topic: About "Building Your First Firewall" ICMP jump-chain
Replies: 13
Views: 712

Re: About "Building Your First Firewall" ICMP jump-chain

Because they are not necessary and are bloatware............ Instead stick to the defaults........... The defaults are safe for a single user and a single WAN and LAN subnet with no complexities. Once you go beyond that, its 99.999 percent of the time needed to start mucking about in the rules. The ...
by anav
Thu Nov 30, 2023 5:22 pm
Forum: Beginner Basics
Topic: Moving from DD-WRT to RB3011
Replies: 6
Views: 347

Re: Moving from DD-WRT to RB3011

VLANS approach is best described here ---> https://forum.mikrotik.com/viewtopic.php?t=143620 We do one bridge approach here. Open VPN has varied success on MT gear. Recommend you replace your proton connetion to Wireguard. If your MT gets a public IP, or if you are behind and ISP modem/router and ca...
by anav
Thu Nov 30, 2023 12:04 am
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 1904

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

Now for the ROUTES. We have the ones we created for the non-pcc mangles as show above...... /ip route add dst-address=0.0.0.0/0 gateway=100.100.100.90 table=useWAN1 add dst-address=0.0.0.0/0 gateway=110.110.110.100 table=useWAN2 add dst-address=0.0.0.0/0 gateway=192.168.10.1 table=useWAN3 Next we ne...
by anav
Wed Nov 29, 2023 11:51 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 1904

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

Third Step lets do the PCC MANGLES. ( 6 mark connections and 6 route markings aka tables ) (using src-address ONLY not both) /ip firewall mangle add action=mark-connection chain=prerouting connection-mark=no-mark dst-address-type=!local \ in-interface=LAN-bridge new-connection-mark=WANA-B passthroug...
by anav
Wed Nov 29, 2023 11:35 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 1904

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

Non-PCC MANGLE RULES, ensuring traffic entering a WAN exits the same WAN deals with any traffic to the router itself or to any servers on the LAN. These will not interfere with any normal traffic either. /ip firewall mangle add action=mark-connection chain=prerouting connection-mark=no-mark \ in-int...
by anav
Wed Nov 29, 2023 11:04 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 1904

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

First step Basic firewall rules. /ip firewall address-list { use static dhcp leases } add address=192.168.100.X list=Authorized comment="local admin desktop" add address=192.168.100.AB list=Authorized comment="local admin laptop" add address=192.168.100.CD list=Authorized comment...
by anav
Tue Nov 28, 2023 9:42 pm
Forum: General
Topic: Official docs to L2TP-v3 L2TP-ETHER
Replies: 11
Views: 3339

Re: Official docs to L2TP-v3 L2TP-ETHER

For L2TP over WG --> viewtopic.php?t=182340
Check out para 10
(10) L2TP thru WIREGUARD for MTU Issues
by anav
Tue Nov 28, 2023 9:12 pm
Forum: General
Topic: Second third party WireGuard VPN with same network provided [SOLVED]
Replies: 30
Views: 2942

Re: Second third party WireGuard VPN with same network provided [SOLVED]

Quick Look Config 1. Listening port settings for the interface, on the client device, can be anything and do not have to match the ENDPOINT listening port and are basically random. In your case highly recommend to make them different. /interface wireguard add listen-port= 51820 mtu=1420 name=wiregua...
by anav
Tue Nov 28, 2023 9:07 pm
Forum: General
Topic: Second third party WireGuard VPN with same network provided [SOLVED]
Replies: 30
Views: 2942

Re: Second third party WireGuard VPN with same network provided [SOLVED]

Well in terms of requirements, routing ports is nonsensical. What is the user traffic that you are trying to execute. ex. users from LANA on router A need to access LANB on Router B ( via wireguar ) users from LANC on router A need to use internet available at Router B etc... If worded in terms of d...
by anav
Tue Nov 28, 2023 7:49 pm
Forum: General
Topic: Second third party WireGuard VPN with same network provided [SOLVED]
Replies: 30
Views: 2942

Re: Second third party WireGuard VPN with same network provided [SOLVED]

to make recommendations for the two WG, need to see config
/export file=anynameyouwish ( minus router serial #, any publicWANIP information, keys, long dhcp lease lists etc..)
by anav
Tue Nov 28, 2023 7:25 pm
Forum: General
Topic: Second third party WireGuard VPN with same network provided [SOLVED]
Replies: 30
Views: 2942

Re: Second third party WireGuard VPN with same network provided [SOLVED]

Also recommend you move to 7.12 once we have resolved the issue.
by anav
Tue Nov 28, 2023 6:02 pm
Forum: Announcements
Topic: Newsletter #115 | November 2023
Replies: 16
Views: 7143

Re: Newsletter #115 | November 2023

I like the clear explanation, that to upgrade to beyond 7.12 you need to upgrade first to 7.12.
by anav
Tue Nov 28, 2023 4:49 pm
Forum: General
Topic: Proton VPN suddenly stopped working
Replies: 8
Views: 939

Re: Proton VPN suddenly stopped working

Please post the latest config for me to look at.
by anav
Tue Nov 28, 2023 2:42 pm
Forum: Beginner Basics
Topic: Can't access or ping devices in a LAN over WireGuard tunnel
Replies: 3
Views: 393

Re: Can't access or ping devices in a LAN over WireGuard tunnel

First you need to backup and make a coherent plan and before that read this --> https://forum.mikrotik.com/viewtopic.php?t=182340 You will quickly surmize that putting 0.0.0.0/0 at both ends is not the right approach. Once reading, you may make some changes to the config. Give it a try. If still not...
by anav
Tue Nov 28, 2023 2:26 pm
Forum: Beginner Basics
Topic: PCC Mangle and routes reducing Client speeds ? [SOLVED]
Replies: 23
Views: 1904

Re: PCC Mangle and routes reducing Client speeds ? [SOLVED]

(1) Your doing PCC, drop any queueing of WANS for the moment. (2) interface list members...... should be modified to the below /interface list member add interface=ether2-TW list=WAN add interface=ether1-PIE1 list=WAN add interface=ether3-PIE3 list=WAN add interface=ether4-LTE4 list=WAN add interfac...
by anav
Tue Nov 28, 2023 2:17 pm
Forum: General
Topic: ip cloud DDNS does not work
Replies: 5
Views: 1299

Re: ip cloud DDNS does not work

Why would you comment on such an old thread? Do you know the context, did you read the link?
MT at the time was having problems at their end............
by anav
Tue Nov 28, 2023 2:14 am
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 28
Views: 2745

Re: Firewall - DNS Open? - Urgent [SOLVED]

(1) YES, THAT IS THE WAY. (2) WHAT ARE YOU TALKING ABOUT SUBNET 16? Point #2 was pointing that your allowed Ip 10.10.9.X/32 was wrong..... The correct version is blue. (3) If you look at the config line its clearly an /ip address entry. Its disabled which is good, I am saying just get rid of it. (4)...
by anav
Mon Nov 27, 2023 11:10 pm
Forum: General
Topic: Second third party WireGuard VPN with same network provided [SOLVED]
Replies: 30
Views: 2942

Re: Second third party WireGuard VPN with same network provided [SOLVED]

Hmm good question.
Post your config.
/export file=anynameyouwish ( minus router serial number, public WANIP informaiton, keys, long dhcp lease lists etc.)
by anav
Mon Nov 27, 2023 10:57 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 69698

Re: v7.13beta [testing] is released!

Dont tell anyone, they might want them back LOL

Ahh confusion due to RAM vs Storage.......... I was looking at Storage.........
Capax hapax3 hapax2 have 1Gb of RAM.
hapac3 has 256Mb of RAM

perhaps your thinking hapac3 or hex devices........
by anav
Mon Nov 27, 2023 10:55 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 69698

Re: v7.13beta [testing] is released!

But the same specs page you linked above lists 128MB ... hmm. You ok?
Even the capax/hap ax3 have 128MB - meaning the 128MB is sufficient........
Edit. looking at storage not ram, my bad.
by anav
Mon Nov 27, 2023 10:30 pm
Forum: Beginner Basics
Topic: HELP VPN RB3011
Replies: 9
Views: 541

Re: HELP VPN RB3011

Yes......... and https://help.mikrotik.com/docs/display/ROS/WireGuard https://www.youtube.com/watch?v=vn9ky7p5ESM&t=8s&pp=ygUSd2lyZWd1YXJkIG1pa3JvdGlr https://www.youtube.com/watch?v=OGBWSpl1Wik&t=103s&pp=ygUSd2lyZWd1YXJkIG1pa3JvdGlr https://www.youtube.com/watch?v=7F9LG7Qgpmg&pp...
by anav
Mon Nov 27, 2023 10:27 pm
Forum: General
Topic: Firewall - DNS Open? - Urgent [SOLVED]
Replies: 28
Views: 2745

Re: Firewall - DNS Open? - Urgent [SOLVED]

(1) Where is bridge vlan-filtering=yes ?? /interface bridge add name=BRIDGE priority=0x7000 (2) Allowed IPs is not quite right, fixed....... add allowed-address=\ 10.10.9 .0/24 ,192.168.254.0/24,192.168.155.0/24,192.168.249.0/24 \ comment=PeerStS_DIM disabled=yes endpoint-address=vpn.test.com \ endp...
by anav
Mon Nov 27, 2023 9:57 pm
Forum: General
Topic: L2TP/IPSec VPN - Cannot get past phase 1
Replies: 5
Views: 398

Re: L2TP/IPSec VPN - Cannot get past phase 1

Id rather not Crokinole my way into the OPs head................. and will let the OP provided the actual information.
by anav
Mon Nov 27, 2023 9:54 pm
Forum: General
Topic: Route Traffic through WireGuard to Internet [SOLVED]
Replies: 20
Views: 2344

Re: Route Traffic through WireGuard to Internet [SOLVED]

Philosophy. The default rules come set for a simple user on the bridge via ether2 and wan setup to work on ether1. The traffic is safely protected but it allows all traffic and drops some key things for general safety. When we want to do more, add vlans and other things its much easier, as the confi...
by anav
Mon Nov 27, 2023 9:42 pm
Forum: Beginner Basics
Topic: HELP VPN RB3011
Replies: 9
Views: 541

Re: HELP VPN RB3011

Sounds very doable. Basically server router - input chain rule for port both routers. define interface add ip address add peers, wireguard Ip and remote subnets ( see article for difference between client peer setting and server peer setttings ) add forward chain rules needed for traffic flow add ip...
by anav
Mon Nov 27, 2023 9:16 pm
Forum: Beginner Basics
Topic: HELP VPN RB3011
Replies: 9
Views: 541

Re: HELP VPN RB3011

Before thinking about configurating, its best to understand the requirements and PLAN!!! identify users/devices, groups of users/devices, including admin identify what traffic they need. Do the devices have single WAN or dual WAN? Is there any port forwarding involved on the two devices? What two de...
by anav
Mon Nov 27, 2023 9:14 pm
Forum: General
Topic: L2TP/IPSec VPN - Cannot get past phase 1
Replies: 5
Views: 398

Re: L2TP/IPSec VPN - Cannot get past phase 1

Since the need for VPN is not clear. Which users are coming to the OFFICE and for what purposes?? Why do you hide a private IP address, assuming the upstream router handles the WAN connection and your WAN input is basically a LAN address on the subnet of the ISP router? The other thing funky about t...
by anav
Mon Nov 27, 2023 8:03 pm
Forum: Beginner Basics
Topic: HELP VPN RB3011
Replies: 9
Views: 541

Re: HELP VPN RB3011

Wireguard has generally better performance and easier to setup. Do you control both ends of the tunnel? ( what is at both ends?) Does at least one end have a publicaly reachable IP address ( not cgnat or natted behind another router )?? If natted behind lets say an ISP modem router, can you forward ...
by anav
Mon Nov 27, 2023 8:01 pm
Forum: General
Topic: Route Traffic through WireGuard to Internet [SOLVED]
Replies: 20
Views: 2344

Re: Route Traffic through WireGuard to Internet [SOLVED]

Firewall Rules Server Router; /ip firewall address-list { static dhcp leases or wireguard ip } add address=172.16.24.XX list= Authorized comment="admin local desktop" add address=172.16.24.AA list=Authorized comment="admin local laptop" add address=172.16.24.BB list=Authorized c...
by anav
Mon Nov 27, 2023 7:05 pm
Forum: General
Topic: Route Traffic through WireGuard to Internet [SOLVED]
Replies: 20
Views: 2344

Re: Route Traffic through WireGuard to Internet [SOLVED]

Client Router (1) It would appear you are trying to use srcnat masquerade to route traffic. This is the wrong approach. /ip firewall nat add action=masquerade chain=srcnat dst-address=172.16.24.0/24 out-interface=\ wireguard-oam src-address=192.168.13.0/24 All you need is....... add action=masquera...
by anav
Mon Nov 27, 2023 4:31 pm
Forum: Beginner Basics
Topic: HELP VPN RB3011
Replies: 9
Views: 541

Re: HELP VPN RB3011

Any reason you chose L2TP vice wireguard??
by anav
Mon Nov 27, 2023 4:30 pm
Forum: General
Topic: Route Traffic through WireGuard to Internet [SOLVED]
Replies: 20
Views: 2344

Re: Route Traffic through WireGuard to Internet [SOLVED]

Need facts/evidence.
So latest configs of the routers please.
by anav
Mon Nov 27, 2023 1:25 pm
Forum: Beginner Basics
Topic: Dual WAN failover, port forward not working when changing route distance
Replies: 22
Views: 1381

Re: Dual WAN failover, port forward not working when changing route distance

Well, good to know, defining the requirements clearly is best done before applying a config. a. you have two WANs. b. there is no failover c. the LAN should use WAN1 only if wan1 goes down, no LAN traffic goes to WAN2 if wan2 goes down, no LAN traffic goes to WAN1 Wan 2 is a static fixed WANIP You h...
by anav
Mon Nov 27, 2023 1:20 pm
Forum: Beginner Basics
Topic: HAP ac2 need help with load balancing on 2 WAN connections
Replies: 16
Views: 818

Re: HAP ac2 need help with load balancing on 2 WAN connections

You got me Holvoe, apologies to the OP. I know squat about L2TP so will bow out.
by anav
Mon Nov 27, 2023 1:18 pm
Forum: General
Topic: Some problems in mikrotik 7
Replies: 6
Views: 653

Re: Some problems in mikrotik 7

Is this whining or asking for help?
Provide a network diagram and full config

/export file=anynameyouwish ( minus router serial# and any public WANIP information, keys etc...)
by anav
Mon Nov 27, 2023 1:15 pm
Forum: General
Topic: Problems with DNS, LAN devices can't access internet
Replies: 10
Views: 1112

Re: Problems with DNS, LAN devices can't access internet

have been fighting a starlink DNS issue. I know this sounds strange and I am hoping someone will point out why it is behaving this way. Sounds like your asking for help to me......but okay, maybe your not. What a switch has to do with router issues is a bit strange to interject and you have no clari...
by anav
Mon Nov 27, 2023 2:44 am
Forum: Beginner Basics
Topic: Config with Advanced Firewall verification requested (WG, DoH & server are working great). Nothing is failing
Replies: 2
Views: 333

Re: Config with Advanced Firewall verification requested (WG, DoH & server are working great). Nothing is failing

Just to clarify, my article uses untracked.........
viewtopic.php?t=180838

If you want me to look at your config, I will rip out anything that is not on those pages,,,,,,,,,
Not required, what I refer to as BLOAT.
by anav
Mon Nov 27, 2023 2:42 am
Forum: Beginner Basics
Topic: Dual WAN Load Balancing depending on usage
Replies: 1
Views: 239

Re: Dual WAN Load Balancing depending on usage

Hmm not really, you can setup PCC balancing to favour one over the other but thats hard wired into the config. The only thing I can say off the top is to make a vlan for WIFI in the house and basically route all the traffic from that wifi through the desired WAN. That way folks have a quick and dirt...
by anav
Mon Nov 27, 2023 2:39 am
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 986

Re: PCC Loadbalancing and distant Port forwarding not working

The improvements to many functions and the ability to do wireguard are huge reasons to move ahead.
If this is a home no worries, 7.12.1 is decent enough.
by anav
Mon Nov 27, 2023 2:38 am
Forum: Beginner Basics
Topic: HAP ac2 need help with load balancing on 2 WAN connections
Replies: 16
Views: 818

Re: HAP ac2 need help with load balancing on 2 WAN connections

Find that hard to believe, wireguard was not possible on vers6
edit: I didnt consider wG on another device, mia culpa!!
by anav
Mon Nov 27, 2023 2:37 am
Forum: Beginner Basics
Topic: Firewall doesn't work properly.
Replies: 14
Views: 838

Re: Firewall doesn't work properly.

The friend is not exactly wrong,,,,,, just a tad misleading. EVERY SWITCH PORT when it comes Default has vlan1 assigned to the port. WE LEAVE THAT vlan1 alone. It works in the background and can basically be ignored. We dont change any vlan1 settings anywhere. EXCEPT.......... when we make a port an...
by anav
Mon Nov 27, 2023 2:28 am
Forum: General
Topic: Route Traffic through WireGuard to Internet [SOLVED]
Replies: 20
Views: 2344

Re: Route Traffic through WireGuard to Internet [SOLVED]

SERVER Comments 1. This indicates an issue....... /interface list member add comment=defconf interface= *C list=LAN I suspect its because you have not identified any LAN list interface members and yet you have a list?? 2. This is wrong. .......... IF you have IP DHCP Client you should not have a se...
by anav
Sun Nov 26, 2023 5:41 pm
Forum: Beginner Basics
Topic: separate different networks on a MikroTik router using the bridge
Replies: 6
Views: 449

Re: separate different networks on a MikroTik router using the bridge

Seems illogical to me.
What is the purpose of buying a MIKROTIK router of that power and using it as a switch??
What am I missing???
by anav
Sun Nov 26, 2023 5:33 pm
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 986

Re: PCC Loadbalancing and distant Port forwarding not working

Wait you are still on vers 6?? My configs are predicated on vers 7
by anav
Sun Nov 26, 2023 5:32 pm
Forum: Beginner Basics
Topic: HAP ac2 need help with load balancing on 2 WAN connections
Replies: 16
Views: 818

Re: HAP ac2 need help with load balancing on 2 WAN connections

Do you have any port forwarding?
Do you have any VPNs........
Hoelve needs to learn to find all the requirements before planning a config ;-P
by anav
Sun Nov 26, 2023 5:30 pm
Forum: Beginner Basics
Topic: Firewall doesn't work properly.
Replies: 14
Views: 838

Re: Firewall doesn't work properly.

Hi KAT,
There is no vlan1 in your config, in fact it looks like properly all the MT devices got an IP on the trusted 192.168.0.0/24 subnet. ( AKA VLAN100 )
Thus confused by the evidence in the configs contradicted by the diagram and your words??
by anav
Sun Nov 26, 2023 5:05 pm
Forum: Beginner Basics
Topic: Firewall doesn't work properly.
Replies: 14
Views: 838

Re: Firewall doesn't work properly.

(1) Which Router is the one you are referring to in the diagram?????? I am assuming the 5009!! (2) What is with vlan1 between all the MT devices, I dont see that in the router config you have??? Assuming you meant on the diagram to put vlan100 which contains the 192.168.0.0/24 (3) So you have four V...
by anav
Sun Nov 26, 2023 5:01 pm
Forum: General
Topic: WireGuard server on Windows with a MikroTik router as a client
Replies: 12
Views: 1790

Re: WireGuard server on Windows with a MikroTik router as a client

ROUTER COMMENTS ( WOW, nice setup ) (1) Not sure what you mean by this line.............. add address=10.0.20.0/24 comment="the different DNS server is used to make th\ e router use the WireGuard VPN connection for DNS queries" dns-server=\ 208.67.222.222,208.67.220.220 gateway=10.0.20.1 F...
by anav
Sun Nov 26, 2023 4:18 pm
Forum: General
Topic: WireGuard server on Windows with a MikroTik router as a client
Replies: 12
Views: 1790

Re: WireGuard server on Windows with a MikroTik router as a client

Good day, The requirements are pretty good. Who needs access to the windows server, vlan10 and vlan20 Who needs access to vlan10, vlan20 does Who gets internet from wireguard, vlan20 does. +++++++++++++++++++++++++++++++++++++++++++++++++ Its the additional requirements that get a bit murky. a. vlan...
by anav
Sun Nov 26, 2023 2:56 pm
Forum: General
Topic: Route Traffic through WireGuard to Internet [SOLVED]
Replies: 20
Views: 2344

Re: Route Traffic through WireGuard to Internet [SOLVED]

Post your config here seeing as the OPs has solved his case and thus no interference.

/export file=anynameyouwish ( minus router serial number, public WANIP information, keys, long dhcp lease lists, any ipv6 info if not using ipv6 )
by anav
Sun Nov 26, 2023 2:50 pm
Forum: General
Topic: difference in Wireguard behavior between laptop and phone
Replies: 8
Views: 691

Re: difference in Wireguard behavior between laptop and phone

1. Allowed IPs on the mikrotik side have nothing to do with routing. 2. Allowed IPs are a matching flltering function for leaving traffic and a filtering function for arriving traffic. 3. An automatic route is created for wireguard IPs by the wireguard router due to ccreating the interface IP addres...
by anav
Sun Nov 26, 2023 2:45 pm
Forum: Beginner Basics
Topic: separate different networks on a MikroTik router using the bridge
Replies: 6
Views: 449

Re: separate different networks on a MikroTik router using the bridge

Concur, one bridge and three vlans is all that is required here. Unless the fortigate cannot handle vlans? What is the purpose of the fortigate in this setup? Edge Router with some subscription services?? interface list=building one vlans 11,12,13,14 Interface list=building two vlans 21,22,23,24 int...
by anav
Sun Nov 26, 2023 2:29 pm
Forum: Beginner Basics
Topic: looking to switch to a 5g > router > AP setup
Replies: 7
Views: 567

Re: looking to switch to a 5g > router > AP setup

You came here looking for reasons to 'convince' the wife to spend money. Just wanted to help the cause by better understanding the scenario because what you initially presented was a very weak case. :-) Anything is possible between two MT routers. Use the concept provided in post #2. Trunk port betw...
by anav
Sun Nov 26, 2023 2:26 pm
Forum: Beginner Basics
Topic: Firewall doesn't work properly.
Replies: 14
Views: 838

Re: Firewall doesn't work properly.

Concur network diagram gives us context!

In addition need to see complete config again. ( not just snippet of firewall rules )
by anav
Sun Nov 26, 2023 2:24 pm
Forum: Beginner Basics
Topic: HAP ac2 need help with load balancing on 2 WAN connections
Replies: 16
Views: 818

Re: HAP ac2 need help with load balancing on 2 WAN connections

What is PPC................ In terms of requirements. a. identify all the user(s)/devices, groups of users and devices ( including admin and external users) b. identify all the traffic they require do accomplish. What is the purpose of the two WANS. Use a primary and have a secondary as backup? USE ...
by anav
Sun Nov 26, 2023 2:22 pm
Forum: Beginner Basics
Topic: Help on RM3011UiAS's DHCP Servers
Replies: 2
Views: 274

Re: Help on RM3011UiAS's DHCP Servers

Firewall ideas -->viewtopic.php?t=180838
Vlan ideas -->viewtopic.php?t=143620
by anav
Sun Nov 26, 2023 5:26 am
Forum: General
Topic: difference in Wireguard behavior between laptop and phone
Replies: 8
Views: 691

Re: difference in Wireguard behavior between laptop and phone

Good you have surmized there is no problem with your config, thus no help required.
by anav
Sun Nov 26, 2023 5:23 am
Forum: General
Topic: Problems with DNS, LAN devices can't access internet
Replies: 10
Views: 1112

Re: Problems with DNS, LAN devices can't access internet

@lostgone --> Start your own thread please.

@felipe Post your latest config
by anav
Sun Nov 26, 2023 5:20 am
Forum: Beginner Basics
Topic: Firewall doesn't work properly.
Replies: 14
Views: 838

Re: Firewall doesn't work properly.

(1) You dont understand firewall rules. Why make allow port 53 rules, but then later drop everything not coming from the LAN. In other words the port 53 rules are allowed by the rule above and thus not necessary in your setup. However, its not at all what I suggested. (2) These ones also are unnecce...
by anav
Sun Nov 26, 2023 3:54 am
Forum: Beginner Basics
Topic: Issues about wireguard connectivity on RouterOS with multiple WAN ports
Replies: 13
Views: 1017

Re: Issues about wireguard connectivity on RouterOS with multiple WAN ports

firewall rules fixed Main issue is these rules which have been axed...... add action=drop chain=input comment="defconf: drop all coming from ha_ct" \ in-interface=pppoe_ha-ct add action=drop chain=input comment="defconf: drop all coming from ha_cu" \ in-interface=pppoe_ha-cu add ...
by anav
Sun Nov 26, 2023 3:39 am
Forum: Beginner Basics
Topic: Firewall doesn't work properly.
Replies: 14
Views: 838

Re: Firewall doesn't work properly.

Change the approach of at least the forward chain, to DROP ALL. In this regard all connections between different subnets are blocked unless explicitly stated in the firewall rules. {forward chain} add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=e...
by anav
Sun Nov 26, 2023 3:36 am
Forum: General
Topic: Output route selection - Wireguard
Replies: 18
Views: 2127

Re: Output route selection - Wireguard

Same here. By using classic mangle rules such as: /ip firewall mangle add action=mark-connection chain=input connection-state=new in-interface=ether2-pppoe new-connection-mark="From WAN Telecom2" passthrough=yes add action=mark-routing chain=output connection-mark="From WAN Telecom2&...
by anav
Sun Nov 26, 2023 12:47 am
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 986

Re: PCC Loadbalancing and distant Port forwarding not working

The above handles all the rules required.
Give that a shot and we will see how much progress is made!
by anav
Sun Nov 26, 2023 12:47 am
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 986

Re: PCC Loadbalancing and distant Port forwarding not working

(1) Order of firewall rules fixed. (2) Its dumb to allow an entire subnet to configure the router and besides, 8291 is not a tcp protocol its udp! Created a firewall address list called authorized........ to solve.... (3) Got rid of unnecessary firewall address lists. (4) Removed logging on drop all...
by anav
Sat Nov 25, 2023 9:42 pm
Forum: General
Topic: Proton VPN suddenly stopped working
Replies: 8
Views: 939

Re: Proton VPN suddenly stopped working

(1) Wrong order. ..... think through the logic. Will traffic from VPN subnet ever reach another local subnet with the order you have???? /routing rule add action=lookup-only-in-table disabled=no src-address=10.10.20.0/24 table=\ Proton_UK_WG add action=lookup-only-in-table disabled=no src-address=10...
by anav
Sat Nov 25, 2023 5:04 pm
Forum: Beginner Basics
Topic: Micro Tik Hex and tp link multi ap
Replies: 4
Views: 448

Re: Micro Tik Hex and tp link multi ap

You didnt read that article very closely, where the EFF does it show the bridge doing any DHPC....... ALL VLANS So take your bridge subnet and assign it to a vlan. Then you need to actually turn on bridge vlan filtering=yes......... None of your bridge ports are assigned properly for access ports or...
by anav
Sat Nov 25, 2023 5:02 pm
Forum: Beginner Basics
Topic: Issues about wireguard connectivity on RouterOS with multiple WAN ports
Replies: 13
Views: 1017

Re: Issues about wireguard connectivity on RouterOS with multiple WAN ports

Then there is something else on your config that is blocking.
Please post FULL config

/export file=anynameyouwish ( minus router serial #, public WANIP information, keys, long dhcp lease lists, IPV6 anything if not using it)
by anav
Sat Nov 25, 2023 4:54 pm
Forum: General
Topic: After Wireguard Client configuration successfully, lan area cannot access wireguard area.
Replies: 6
Views: 488

Re: After Wireguard Client configuration successfully, lan area cannot access wireguard area.

So assuming the SERVER is not third party, then the problem is also at the other end at the server end!! SeRVER CONSIDERATIONS : a. do you have 192.168.88.0/24 as allowed IPs at the server wg peer settings for router b?? b. do you have 192.168.100.2/32 as allowed IPs at the server wg peer settings f...
by anav
Sat Nov 25, 2023 4:45 pm
Forum: General
Topic: After Wireguard Client configuration successfully, lan area cannot access wireguard area.
Replies: 6
Views: 488

Re: After Wireguard Client configuration successfully, lan area cannot access wireguard area.

What is the remote wireguard server - mikrotik or something else?? Concur lets fix that sourcenat mess..... (drop the crap rule) /ip firewall nat add action=src-nat chain=srcnat dst-address=192.168.100.0/24 dst-limit=\ 1,5,dst-address/1m40s limit=1,5:packet psd=21,3s,3,1 src-address=\ 192.168.88.0/2...
by anav
Sat Nov 25, 2023 4:41 pm
Forum: Beginner Basics
Topic: Dual WAN failover, port forward not working when changing route distance
Replies: 22
Views: 1381

Re: Dual WAN failover, port forward not working when changing route distance

(1) This default rule is now replaced and should be removed. add action=drop chain=forward comment=\ "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \ connection-state=new disabled=yes in-interface-list=WAN add action=accept chain=forward comment=Internet in-interfac...
by anav
Sat Nov 25, 2023 3:04 pm
Forum: Beginner Basics
Topic: Dual WAN, but second link is used only by some LAN machines [SOLVED]
Replies: 3
Views: 415

Re: Dual WAN, but second link is used only by some LAN machines [SOLVED]

Need table /routing-table add name=useWAN2 Need route /ip route normal route ISP1 distance=2 check-gateway=ping table=main normal route ISP2 distance=4 table=main add dst-address=0.0.0.0/0 gateway=ISP2 routing-table=useWAN2 [/b] Need routing rules................. But be careful as a routing rule fo...
by anav
Sat Nov 25, 2023 2:58 pm
Forum: Beginner Basics
Topic: Issues about wireguard connectivity on RouterOS with multiple WAN ports
Replies: 13
Views: 1017

Re: Issues about wireguard connectivity on RouterOS with multiple WAN ports

Try these mangle rules. add chain=prerouting action=mark-connection connection-mark=no-mark \ in-interface=WAN2 new-connection-mark=incomingISP2 passthough=yes add chain=output action=mark-routing connection-mark=incomingISP2 \ new-routing-mark=useWAN2 passthough=no Dont forget the table. /routing t...
by anav
Sat Nov 25, 2023 5:41 am
Forum: General
Topic: After Wireguard Client configuration successfully, lan area cannot access wireguard area.
Replies: 6
Views: 488

Re: After Wireguard Client Setup successfully, lan cannot access wireguard area.

Allowed peer should be 192.168.100.0/24, not 192.168.100.1/24
by anav
Fri Nov 24, 2023 11:31 pm
Forum: General
Topic: Is WireGuard traffic invisible to Torch [SOLVED]
Replies: 2
Views: 440

Re: Is WireGuard traffic invisible to Torch [SOLVED]

The wirguard config is predicated upon the peer for a client to be the specific IP address as noted, which differentiates from the multiple peers possible.

The peer on the client or often remote device, should be the subnet and if a router then most definitely the subnet.
by anav
Fri Nov 24, 2023 5:24 pm
Forum: General
Topic: WireGuard server on Windows with a MikroTik router as a client
Replies: 12
Views: 1790

Re: WireGuard server on Windows with a MikroTik router as a client

Busy today but will look at i this weekend.
by anav
Fri Nov 24, 2023 5:22 pm
Forum: Beginner Basics
Topic: Dual WAN, but second link is used only by some LAN machines [SOLVED]
Replies: 3
Views: 415

Re: Dual WAN, but second link is used only by some LAN machines [SOLVED]

How many machines?? You can use Routing rules for entire subnets - very easy, no mangles. You can use Routing rules for a few users - very easy, no mangles. Basically it comes down to you will need a routing rule per user so it depends how many rules you would like to make. add src-address=userX-IP ...
by anav
Fri Nov 24, 2023 5:05 pm
Forum: Beginner Basics
Topic: Dual WAN failover, port forward not working when changing route distance
Replies: 22
Views: 1381

Re: Dual WAN failover, port forward not working when changing route distance

Busy today, but if you post your latest config I will spend more time on it this weekend.
by anav
Fri Nov 24, 2023 2:25 pm
Forum: Beginner Basics
Topic: 2 Vlans, a firewall, and a PITA DNS.
Replies: 3
Views: 355

Re: 2 Vlans, a firewall, and a PITA DNS.

One bridge..............
viewtopic.php?t=143620
by anav
Fri Nov 24, 2023 2:23 pm
Forum: Beginner Basics
Topic: Issues about wireguard connectivity on RouterOS with multiple WAN ports
Replies: 13
Views: 1017

Re: Issues about wireguard connectivity on RouterOS with multiple WAN ports

Too busy today to look at it, but I would scrap any mangle rules you have for wireguard.
What is required is mangle rules ensuring traffic coming in wanx, goes out wanx.
by anav
Fri Nov 24, 2023 2:19 pm
Forum: Beginner Basics
Topic: Dual WAN failover, port forward not working when changing route distance
Replies: 22
Views: 1381

Re: Dual WAN failover, port forward not working when changing route distance

I have a great idea, why dont you ask the people making vidoes for help........... The onus is ON YOU, to read the mikrotik docs and read as many threads as possible to learn. There are some decent videos out there by a few people the rest will lead you astray. Network Berg is good Network Trip is g...
by anav
Wed Nov 22, 2023 11:06 pm
Forum: General
Topic: multi vlan with multi wan setup
Replies: 16
Views: 1182

Re: multi vlan with multi wan setup

Try harder, and read more....... the answer are available......
by anav
Wed Nov 22, 2023 11:04 pm
Forum: Beginner Basics
Topic: Dual WAN failover, port forward not working when changing route distance
Replies: 22
Views: 1381

Re: Dual WAN failover, port forward not working when changing route distance

Sorry you still have not explained how you are using DNS to 'force' users through one WAN or the other.
What DNS records?

Forcing users out a specific WAN is accomplished via routing of some sort.
by anav
Wed Nov 22, 2023 11:02 pm
Forum: Beginner Basics
Topic: looking to switch to a 5g > router > AP setup
Replies: 7
Views: 567

Re: looking to switch to a 5g > router > AP setup

?? Do you have a multitude of servers feeding many users........ Not sure what the need is for 10gigs? As for poe...... injectors are cheap....... https://www.amazon.ca/PoE-Injector/s?k=PoE+Injector Your not making a real case to keep the 5009 thus far......... , maybe you want to show the wife this...
by anav
Wed Nov 22, 2023 10:16 pm
Forum: Beginner Basics
Topic: looking to switch to a 5g > router > AP setup
Replies: 7
Views: 567

Re: looking to switch to a 5g > router > AP setup

Sell the RB5009, there is no need to keep it when you get the chateau 5G AX. To me its pointless to keep both. Give the RB to family or donate to some organization, it would be wasted otherwise. There is nothing to be gained by keeping it. The same rules can be used on the Chateau as its the same RO...
by anav
Wed Nov 22, 2023 10:08 pm
Forum: General
Topic: multi vlan with multi wan setup
Replies: 16
Views: 1182

Re: multi vlan with multi wan setup

Sorry its you that doesnt understand, didnt ask for your configuration BS. . All I asked for is how to set the gateway for a vlan if there is more than just one wan-interface. I asked to explain what users and devices you had and what traffic requirements they had. The network diagram shows what equ...
by anav
Wed Nov 22, 2023 9:48 pm
Forum: Beginner Basics
Topic: looking to switch to a 5g > router > AP setup
Replies: 7
Views: 567

Re: looking to switch to a 5g > router > AP setup

Dont understand what you are trying to accomplish. 1. The RB5009 is a better router in terms of routing it can actually handle a 2.5 gig ISP connection with firewall rules implemented. The latest chateau 5G AX cannot ( good for 1gig fiber ). 2. There is no need for the chateau to do routing if you h...
by anav
Wed Nov 22, 2023 9:45 pm
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 986

Re: PCC Loadbalancing and distant Port forwarding not working

The point being, a. you have associated the address pool with the bridge-lan via the dhcp-server. b. you associated the Ip address with two different etherports, that are also members of the bridge but NOT the bridge. and yet dont see the problem, means you either dont understand networking, or mikr...
by anav
Wed Nov 22, 2023 9:38 pm
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 94
Views: 7451

Re: Multi-WAN Load Balancing Starlink issue

No word of a lie, but I was out running on friggin mountain in Spain recently when my bowels told me I was in a dire very dire short fused situation. I went off the beaten path to ensure isolation, just in case, and was just in time. What a relief,,,,,, However, I could have really used a BIG LEAF, ...
by anav
Wed Nov 22, 2023 9:34 pm
Forum: General
Topic: multi vlan with multi wan setup
Replies: 16
Views: 1182

Re: multi vlan with multi wan setup

Here is the scoop, makes two of us who dont get it, the diagram was a good start,
however you need to
a. identify all the user(s)/device(s) and groups of users/devices
b. what traffic they should be able to accomplish.

Do not use any config speak just actual users device and traffic required.
by anav
Wed Nov 22, 2023 9:25 pm
Forum: General
Topic: multi vlan with multi wan setup
Replies: 16
Views: 1182

Re: multi vlan with multi wan setup

(1) Why would I bother commenting the config linked is missing the wireguard information, I dont work on snippets. Besides lacking in firewall rules AND ROUTES. (2) Where is the sourcenat rule for outgoing information going out ether3.................. (3) Why is ether2 sourcnat have the associated ...
by anav
Wed Nov 22, 2023 7:52 pm
Forum: Forwarding Protocols
Topic: LAN connection through WIREGUARD
Replies: 3
Views: 382

Re: LAN connection through WIREGUARD

Depends on the firewall rules........
How did you ensure the wireguard could reach the device and config it???
by anav
Wed Nov 22, 2023 7:42 pm
Forum: Beginner Basics
Topic: Dual WAN failover, port forward not working when changing route distance
Replies: 22
Views: 1381

Re: Dual WAN failover, port forward not working when changing route distance

Okay....... (1) Point 4, big risk learn Wireguard!! (2) Point 5, good for port forwarding to work properly from the LAN side, the new rules will work the default you had would not. (2) I don't understand your point about DNS in terms of deciding server routing can you elaborate/explain as I see noth...
by anav
Wed Nov 22, 2023 6:36 pm
Forum: General
Topic: Bridge PVID [SOLVED]
Replies: 13
Views: 1110

Re: Bridge PVID [SOLVED]

Another perspective........... Dont mess with the bridge, keep it at defaults and dont use it for any data traffic. KISS!! Managment vlan would be typically identified also as a member of the management INTERFACE LIST and used for neighbours discovery and mac-server winmac-server setting. All smart ...
by anav
Wed Nov 22, 2023 6:17 pm
Forum: Beginner Basics
Topic: No Internet wireguard
Replies: 8
Views: 519

Re: No Internet wireguard

ON MT Server Router (1) You only have one wireguard peer not three as per the diagram. (2) The peer setting on the server do not require keep alive, that is something for the client end. (3) I do not see any subnets for the LAN under IP addresses?? (4) The IP address for the WG interface is not the ...
by anav
Wed Nov 22, 2023 6:00 pm
Forum: Beginner Basics
Topic: Dual WAN failover, port forward not working when changing route distance
Replies: 22
Views: 1381

Re: Dual WAN failover, port forward not working when changing route distance

/ip route add check-gateway=ping distance=11 dst-address=0.0.0.0/0 gateway=ether1 routing-table=main add check-gateway=ping distance=12 dst-address=0.0.0.0/0 gateway=ether2 routing-table=main add dst-address=0.0.0.0/0 gateway=ether2 routing-table=to_ether2 From this setup. all user originated traffi...
by anav
Wed Nov 22, 2023 5:50 pm
Forum: Beginner Basics
Topic: Dual WAN failover, port forward not working when changing route distance
Replies: 22
Views: 1381

Re: Dual WAN failover, port forward not working when changing route distance

Observations: (1) First problem is your interface lists, there is no reason to have two separate WAN LISTS. Should be just WAN and just LAN. Anything else only leads to confusion. The reason to create interface lists is when grouping of subnets makes sense for rules, OR you need to indicate a specif...
by anav
Wed Nov 22, 2023 4:47 pm
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 986

Re: PCC Loadbalancing and distant Port forwarding not working

Sorry still dont understand the config, (1) Why does the bridge not have an IP address assigned to it?? Why does ether 12 instead have an IP address?? Why not use something standard anyway like 10.0.0 .1 /24 Why does ether11 have some bizarro subnet assigned......?? /ip address add address= 10.0.0.7...
by anav
Wed Nov 22, 2023 3:28 pm
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 986

Re: PCC Loadbalancing and distant Port forwarding not working

I came from zyxel myself, and yes its more ProSumer, whereas MT is more IT based programming. For example zyxel has always had a loop back button. I never knew what it did or why it was there, but on MT you have to accomplish the same thing by understanding source nat and destination nat more comple...
by anav
Wed Nov 22, 2023 3:26 pm
Forum: Beginner Basics
Topic: No Internet wireguard
Replies: 8
Views: 519

Re: No Internet wireguard

What needs to be clear are who/what are at each end of the wireguard connections.
What is server for handshake what is peer for handshake.
A network diagram would help.
by anav
Wed Nov 22, 2023 3:23 pm
Forum: General
Topic: multi vlan with multi wan setup
Replies: 16
Views: 1182

Re: multi vlan with multi wan setup

Wrong approach ldb..... What the OP needs to do is state the requirement of traffic flow based on a. identifying user(s)/device(s) and groups of users/devices including the admin b. identify the traffic flows they should have/be able to accomplish. Without any word of the config...... A network diag...
by anav
Wed Nov 22, 2023 2:37 am
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 986

Re: PCC Loadbalancing and distant Port forwarding not working

I also dont think you have a clue about port forwarding with a rule like this..... Created a youtube/google monster.......... ( very disorganized rule order as well ) add action=accept chain=forward dst-address=10.0.0.144 dst-port=80,443 \ protocol=tcp When the rest of the config is cleaned up I wou...
by anav
Wed Nov 22, 2023 2:28 am
Forum: Beginner Basics
Topic: PCC Loadbalancing and distant Port forwarding not working
Replies: 14
Views: 986

Re: PCC Loadbalancing and distant Port forwarding not working

Dont name your bridge LAN, its very confusing to the reader and probably to the router. Name it something else like bridge-lan I have no idea what you are doing with this so called lan subnet, is it supposed to be attached to the bridge, ether12, ether11. You are very confused......... /ip dhcp-serv...
by anav
Tue Nov 21, 2023 11:56 pm
Forum: Beginner Basics
Topic: Solid network security in RouterOS
Replies: 10
Views: 1013

Re: Solid network security in RouterOS

The MT router will only provide one subnet to the APs. That subnet can be used for the main HOMELAN wifi and the two guest WLANS will be made by the APs. To make use of the Roaming capability of wifiwave2, you will need these APs --> https://mikrotik.com/product/cap_ax They are NOT mesh. Each needs ...
by anav
Tue Nov 21, 2023 11:50 pm
Forum: General
Topic: Proton VPN suddenly stopped working
Replies: 8
Views: 939

Re: Proton VPN suddenly stopped working

Please post a real config in the standard format. That was a horrible abomination to look at.

/export file=anynameyouwish (minus router serial number and any public WANIP information, keys etc....)
by anav
Tue Nov 21, 2023 9:00 pm
Forum: Beginner Basics
Topic: Solid network security in RouterOS
Replies: 10
Views: 1013

Re: Solid network security in RouterOS

Nope! The MT has not wifi controls over non-MT wifi appliances. It can firewall, queue, etc like any other vlan.
by anav
Tue Nov 21, 2023 8:57 pm
Forum: General
Topic: wireguard not working any more
Replies: 10
Views: 770

Re: wireguard not working any more

The reason for the suggestion of /29 mask was due to the following sentence (requirements driven). Quote: " I used wireguard for some time on my old RB2011 for connection to another Mikrotik router as well as for mobile connection [/b]. It worked very good. Now, with the CCR1009 I have some iss...
by anav
Tue Nov 21, 2023 1:15 pm
Forum: General
Topic: wireguard not working any more
Replies: 10
Views: 770

Re: wireguard not working any more

Yes, give it a go, for all the suggestions, otherwise why ask for help?? As for the last point, hogwash. The MT device only creates routes automatically for local interfaces. Hence why in the route list you will see <dac> routes for local subnets and even the wireguard interface. Since the router is...
by anav
Tue Nov 21, 2023 1:09 pm
Forum: Beginner Basics
Topic: How to route all traffic through WireGuard VPN and keep LAN access? [SOLVED]
Replies: 9
Views: 973

Re: How to route all traffic through WireGuard VPN and keep LAN access? [SOLVED]

Perhaps they block certain ports? WG can use any port you choose.
by anav
Tue Nov 21, 2023 2:49 am
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 69698

Re: v7.13beta [testing] is released!

What?, You didnt test for deserialize, like thats on page 1 of the Fetch Manual. :-)
Lest not forget at least the 10 references to that subject , in "Dummies Guide to Testing Scripts"

You guys kill me with real networking skills! We are not worthy.
by anav
Tue Nov 21, 2023 2:39 am
Forum: Scripting
Topic: GPT4 and writing scripts for Mikrotik
Replies: 51
Views: 2784

Re: GPT4 and writing scripts for Mikrotik

People can agree to disagree.
I don't agree :-P
I agree with you completely
by anav
Tue Nov 21, 2023 2:38 am
Forum: Scripting
Topic: GPT4 and writing scripts for Mikrotik
Replies: 51
Views: 2784

Re: GPT4 and writing scripts for Mikrotik

Why ?
The discussion on itself remains civil.
People can agree to disagree.
There is no discussion, its someone concerned about pushing an ideology and not using their own brain.
We have enough of that crap in the world today. ( similar to rextended's comment on social media ).
by anav
Tue Nov 21, 2023 2:33 am
Forum: Beginner Basics
Topic: Pass Voip traffic from WAN 1, have Done 3 WAN Load Balancing and Fail Over
Replies: 1
Views: 229

Re: Pass Voip traffic from WAN 1, have Done 3 WAN Load Balancing and Fail Over

How do you identify VOIP traffic, source address? --> is it contained with a subnet, if so routing rules, --> is it contained within a few IPs, if so routing rules Destination address --> is it contained with a subnet, if so routing rules, --> is it contained within a few IPs, if so routing rules An...
by anav
Tue Nov 21, 2023 2:26 am
Forum: General
Topic: wireguard not working any more
Replies: 10
Views: 770

Re: wireguard not working any more

Your config seems off to me. Lets assume the CCR1009 is the WG server for the handshakes for both the other router and the mobile connection. (1) Not sure a /30 mask cuts it a /29 mask gives you six useable IPs, since you seem shy to use the standard /24. (2) The allowed IPs on the CCR1009 are missi...
by anav
Mon Nov 20, 2023 10:29 pm
Forum: Scripting
Topic: GPT4 and writing scripts for Mikrotik
Replies: 51
Views: 2784

Re: GPT4 and writing scripts for Mikrotik

No point in responding, this has nothing to do with MT. The troll is here to talk about GPT in some bogus cultish form............ ( the measured opines of both MKX and rextended are refreshing and indicative of open, inquisitive and reasoning minds.) . I'm only sad that the admins have not locked t...
by anav
Mon Nov 20, 2023 9:13 pm
Forum: Wireless Networking
Topic: Making APs work as a mesh - E.g., Netgear WAX220
Replies: 3
Views: 474

Re: Making APs work as a mesh - E.g., Netgear WAX220

Why do you post the same silly questions twice??? viewtopic.php?t=201645
by anav
Mon Nov 20, 2023 9:11 pm
Forum: Wireless Networking
Topic: Using non-MT Access Points in a mesh config - does it work?
Replies: 7
Views: 627

Re: Using non-MT Access Points in a mesh config - does it work?

Concur, and the answer is still no. MT cannot create a mesh network besides the fact that mesh APs do not handle vlan tags. What business class APs, do, besides read vlan tags is they have some sort of controller which allows efficient roaming between the APs, be it TPLINK or other vendors. With AX3...
by anav
Mon Nov 20, 2023 6:14 pm
Forum: Beginner Basics
Topic: How to route all traffic through WireGuard VPN and keep LAN access? [SOLVED]
Replies: 9
Views: 973

Re: How to route all traffic through WireGuard VPN and keep LAN access? [SOLVED]

I see nothing wrong on the config side. You have the right allowed peer, you have firewall settings that allow the traffic. Can you post your WIreguard settings on the laptop? If you want to access the 10 subnet from the laptop you would need to have allow IPS on the laptop on its peer settings: all...
by anav
Mon Nov 20, 2023 5:39 pm
Forum: Beginner Basics
Topic: How can I see my Guest wireless users on my Router?
Replies: 5
Views: 409

Re: How can I see my Guest wireless users on my Router?

Concur its hard to find a home AP, mesh or not that handles vlans.
All brands be it tp link etc, have a business class AP that can handle vlan tags, but they dont come in a mesh variety.
by anav
Mon Nov 20, 2023 3:51 am
Forum: Beginner Basics
Topic: How can I see my Guest wireless users on my Router?
Replies: 5
Views: 409

Re: How can I see my Guest wireless users on my Router?

Nope, the mikrotik has nothing to do with the internal shenanigans of the AP. What it sounds like its doing is within the AP taking your 192.168.88.0 traffic and sort of splitting into both subnets. What I dont know is if its taking an .88 address for each lease and then converting/giving it to .3 a...
by anav
Mon Nov 20, 2023 3:35 am
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 94
Views: 7451

Re: Multi-WAN Load Balancing Starlink issue

Just to have a sample practical, minimalist but secure (shortNsweet) firewall available for your perusal. Its based on allowing only authorized traffic and dropping everything else. The input chain rule allowed admin access is based on a firewall address list one create and which is comprised of loc...
by anav
Sun Nov 19, 2023 5:14 pm
Forum: General
Topic: multi vlan with multi wan setup
Replies: 16
Views: 1182

Re: multi vlan with multi wan setup

This is an excellent source to review and once you have a config to show
/export file=anynameyouwish (minus router serial number and any public WANIP information.)

viewtopic.php?t=143620
by anav
Sun Nov 19, 2023 2:59 pm
Forum: General
Topic: wireguard not working any more
Replies: 10
Views: 770

Re: wireguard not working any more

Did you forget to upgrade the admins' firmware as well?
by anav
Sun Nov 19, 2023 3:16 am
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 94
Views: 7451

Re: Multi-WAN Load Balancing Starlink issue

Jaysen, just to be clear, I was ONLY talking about the connection-mark nomenclature for Mangle rules! There is no change to either the mangles routing-mark nomenclature or especially to any naming in the IP Routes . The mangle rules for marking routes should remain as is --> useWANX , as do the IP R...
by anav
Sat Nov 18, 2023 10:01 pm
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 94
Views: 7451

Re: Multi-WAN Load Balancing Starlink issue

@Sir Bryan sounds fascinating! Any chance we could see how you setup OSPF+BDF in RoS 7 for this to work?? An examples of the type of network arrangement your espousing may be of great potential use by the OP as an alternative approach to engineer in slow time, and of utmost interest to me as well. [...
by anav
Sat Nov 18, 2023 9:13 pm
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 94
Views: 7451

Re: Multi-WAN Load Balancing Starlink issue

(1) Personally recommend you dont use the same entry names for connection marks and routing marks. It gets terribly hard to read. For instance. For the initial set of rules use connection marks incoming-WAN1 ( reflect traffic is originating from outside the router ) For the PCC traffic use connectio...
by anav
Sat Nov 18, 2023 8:13 pm
Forum: Beginner Basics
Topic: Blocking discord using address list
Replies: 9
Views: 832

Re: Blocking discord using address list

Get an expensive router with expensive services and use their APP Patrol/control
by anav
Sat Nov 18, 2023 8:11 pm
Forum: Beginner Basics
Topic: Problem with VLAN Setup
Replies: 10
Views: 697

Re: Problem with VLAN Setup

Personal choice. All my switches/APs get an IP from the managment VLAN but they are set fixed upon lease or I do it manually via mac address. Having all MTs on the same network makes IP neighbours discovery set to the interface List which I make and only contains the managment VLAN, I can see all my...
by anav
Sat Nov 18, 2023 4:04 pm
Forum: Beginner Basics
Topic: Problem with VLAN Setup
Replies: 10
Views: 697

Re: Problem with VLAN Setup

On the 5009 basic math, 4 vlans, 4 addresses, but ONLY 3 pools, 3 dhcp servers, and 3 dhcp-server networks!! ( assuming either base or managment is not really being used ?? ) Plus bridge port should look like this, personal preference: /interface bridge port add bridge=bridge interface=ether2 ingres...
by anav
Sat Nov 18, 2023 4:00 pm
Forum: Beginner Basics
Topic: Problem with VLAN Setup
Replies: 10
Views: 697

Re: Problem with VLAN Setup

AndyM1988, what everyone was asking is that you provide the relevant configuration snippets. Anyway ... On the RB5009, if you look at the hosts on the bridge (/interface bridge host print), do you see entries in the different VLANs? If your computer is connected to the CRS326, do you see its MAC ad...
by anav
Sat Nov 18, 2023 3:59 pm
Forum: Beginner Basics
Topic: Blocking discord using address list
Replies: 9
Views: 832

Re: Blocking discord using address list

One cannot block apps with MT............
by anav
Sat Nov 18, 2023 5:49 am
Forum: Beginner Basics
Topic: wireguard connection restricted to a single internal IP [SOLVED]
Replies: 7
Views: 1212

Re: wireguard connection restricted to a single internal IP [SOLVED]

Nope, the rules are not in order and you have mixed things up... Cleaned up ... /ip firewall filter add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \ connection-state=established,related hw-offload=yes add action=accept chain=forward comment=\ "defconf: acce...
by anav
Sat Nov 18, 2023 3:25 am
Forum: General
Topic: Wireguard 7.12 peer failed
Replies: 6
Views: 852

Re: Wireguard 7.12 peer failed

No goinag yours is a different problem. Failure to apply wireguard rules properly. Admin error!
by anav
Fri Nov 17, 2023 11:59 pm
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 94
Views: 7451

Re: Multi-WAN Load Balancing Starlink issue

(1) I personally like to use a different connection mark for the PCC LAN traffic, then what I used for the WANS, just for ease of readings, but thats personal preference. I personally do not understand what are the ramifications, if any, by having the first set of mangle rule group for routing marks...
by anav
Fri Nov 17, 2023 11:19 pm
Forum: Beginner Basics
Topic: Problem with VLAN Setup
Replies: 10
Views: 697

Re: Problem with VLAN Setup

If its not in config format not going to look at it.

Or as TDW was trying to say ;-PPPP facts/evidence please..........
by anav
Fri Nov 17, 2023 8:48 pm
Forum: General
Topic: Secure SOHO network configuration
Replies: 14
Views: 729

Re: Secure SOHO network configuration

You said the need was to isolate devices.............. My reply is that you cannot easily isolate devices if in the same subnet L2, aka a normal subnet or vlan. One should isolate devices in layer2 by putting them in their own subnet, makes things easy. You can put each one in a different subnet or ...
by anav
Fri Nov 17, 2023 8:11 pm
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 94
Views: 7451

Re: Multi-WAN Load Balancing Starlink issue

I'm too sexy for youtube video ;-PP { he did a decent job of reading the teleprompter which was slightly to the left of the camera, above is better LOL ) Nothing major but without discussing really what the heck his purpose was for putting distances on the routes......... Assuming some sort of very ...
by anav
Fri Nov 17, 2023 8:10 pm
Forum: General
Topic: Secure SOHO network configuration
Replies: 14
Views: 729

Re: Secure SOHO network configuration

It is much harder to isolate devices at L2, and thus if you have untrustworthy devices keep them in their own subnet period.
You can always drill L3 holes to allow one way communication to such devices.
by anav
Fri Nov 17, 2023 7:20 pm
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 94
Views: 7451

Re: Multi-WAN Load Balancing Starlink issue

FWIW the PCC youtube vid made by MT is quite good. https://www.youtube.com/watch?v=nlb7XAv57tw Used it again to clean up an AC3 LTE setup for PCC sharing across VDSL and LTE. Only, THIS time I disabled the subtitles which all of a sudden made me see a couple of important things I missed the previou...
by anav
Fri Nov 17, 2023 6:57 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 69698

Re: v7.13beta [testing] is released!

That cat needs some exercise and less treats. Why does it have chicken/turkey looking legs LOL
by anav
Fri Nov 17, 2023 6:42 pm
Forum: General
Topic: windows client wireguard vpn ip
Replies: 4
Views: 315

Re: windows client wireguard vpn ip

Think of allowed IPs on any device as a separate mini firewall. There are two flows of traffic - exiting the tunnel at the local device (inbound/incoming to the local LAN). - entering the tunnel at the local device (outbound/leaving the router) Therefore for the first case, the wireguard code looks ...
by anav
Fri Nov 17, 2023 5:39 pm
Forum: General
Topic: windows client wireguard vpn ip
Replies: 4
Views: 315

Re: windows client wireguard vpn ip

The wireguard subnet should be different from the LAN subnets!

Please read here for more info on wireguard as to making guesses: viewtopic.php?t=182340
by anav
Fri Nov 17, 2023 5:35 pm
Forum: Beginner Basics
Topic: Blocking traffic to rest of network but allowing access to forwarded ports on public IP
Replies: 3
Views: 290

Re: Blocking traffic to rest of network but allowing access to forwarded ports on public IP

(1) Question about your settings here... what is vlan10? [/color]? Point of personal preference i prefer to manually untag bridge ports on the config so they show up on the export and can follow the Admin/s logic. /interface bridge vlan add bridge=bridge tagged=bridge vlan-ids= 10 add bridge=bridge ...
by anav
Fri Nov 17, 2023 5:13 pm
Forum: Announcements
Topic: v7.12.1 [stable] is released!
Replies: 243
Views: 62790

Re: v7.12 [stable] is released!

Nice explanation!
by anav
Fri Nov 17, 2023 4:27 pm
Forum: Beginner Basics
Topic: Blocking traffic to rest of network but allowing access to forwarded ports on public IP
Replies: 3
Views: 290

Re: Blocking traffic to rest of network but allowing access to forwarded ports on public IP

Full config
/export file=anynameyouwish ( minus router serial number and any public WAN IP information )
by anav
Fri Nov 17, 2023 4:25 pm
Forum: General
Topic: Secure SOHO network configuration
Replies: 14
Views: 729

Re: Secure SOHO network configuration

Its normal to isolate users by vlans because the vlans do it as they are L2 constructs and we ensure the firewall rules do the same at L3. Whats NOT normal is your requirement to isolate wifi users from themselves within the same subnet or isolate wifi users from lan users in the same subnet. That t...
by anav
Fri Nov 17, 2023 12:55 am
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 69698

Re: v7.13beta [testing] is released!

I cant see anything but a big grey blob in the middle ????
by anav
Fri Nov 17, 2023 12:53 am
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 256
Views: 380608

Re: Using RouterOS to VLAN your network

Next item, people keep messing up on. They keep a bridge address and pool and add addresses for the vlans but FORGET about pools, dhcp server etc for the VLANS. Please add a paragraph that says, NO need for bridge to do DHCP once you have vlans make all subnets vlans for a clean, consistent approach...
by anav
Fri Nov 17, 2023 12:46 am
Forum: General
Topic: VLAN Issues
Replies: 13
Views: 1521

Re: VLAN Issues

Lets get real here you didnt read the first reference at all!! How else can you explain this...... TWO VLANS and only one pool and one dhcp server and they are not for either vlan ???? /ip pool add name=default-dhcp ranges=192.168.88.10-192.168.88.254 /ip dhcp-server add address-pool=default-dhcp i...
by anav
Fri Nov 17, 2023 12:37 am
Forum: General
Topic: Routing between two Wireguard interfaces
Replies: 4
Views: 332

Re: Routing between two Wireguard interfaces

Much appreciated on a very detailed answer. I expected to get grilled for my shiet firewall rules, keep that grilling, please. 1) I assume you are talking about my External Peer 1? b) Yes the second peer is for my external device (in this case my phone), keepalive removed. Also, what two other peer...
by anav
Thu Nov 16, 2023 11:51 pm
Forum: General
Topic: Problems with mangle-rules on RouterOS 7.12
Replies: 12
Views: 842

Re: Problems with mangle-rules on RouterOS 7.12

/ip firewall mangle add action=mark-connection chain=prerouting connection-mark=no-mark in-interface=eth11-WAN-2 new-connection-mark=MARK-WAN-2 passthrough=yes
/ip firewall mangle add action=mark-routing chain=output connection-mark=MARK-WAN-2 new-routing-mark=WAN-2
passthrough=no
by anav
Thu Nov 16, 2023 11:44 pm
Forum: General
Topic: Routing between two Wireguard interfaces
Replies: 4
Views: 332

Re: Routing between two Wireguard interfaces

Router2 1. ALLOWED IPs. a. The first peer config line is from the client MT2, to the server MT1 - All looks good to me, just not sure why you used 172.16.0.0/30 vice the standard 172.16.0.0 /24 ?? b. The second peer is from the server MT2 to the client (laptop?). Why is there a persistent keep aliv...
by anav
Thu Nov 16, 2023 9:41 pm
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 94
Views: 7451

Re: Multi-WAN Load Balancing Starlink issue

gotsprings looks like your trying to put mikrotik wan solutions under the bus LOL. Here I am trying to figure out optimal failover WAN approaches and it turns out I just need to use BigLeaf.....................
Please send $$$$
by anav
Thu Nov 16, 2023 9:32 pm
Forum: General
Topic: Fundamental problems at MikroTik
Replies: 32
Views: 2358

Re: Fundamental problems at MikroTik

IMO documentation is pretty decent, specially if you compare it to some documentation, originating in China. For a trained IT network engineer, concur. For a fly by night DYI its woefully inadequate but since everything is based on logic and rules, no mountain is too high and there is always some s...
by anav
Thu Nov 16, 2023 7:01 pm
Forum: Beginner Basics
Topic: routing between subnets to host [SOLVED]
Replies: 6
Views: 488

Re: routing between subnets to host [SOLVED]

Yes, the key is the firewall rules.......
by anav
Thu Nov 16, 2023 6:54 pm
Forum: Virtualization
Topic: CHR License P1 - Invalid Cloud ??
Replies: 3
Views: 371

Re: CHR License P1 - Invalid Cloud ??

Ahh reading this ......... seems to indicate its a manual perpetual thing LOL. CHR License Levels License levels described until now do not apply to Cloud Hosted Routers (CHRs). CHR is a RouterOS version intended for running as a virtual machine. It has its own 4 license levels as well as trial wher...
by anav
Thu Nov 16, 2023 6:51 pm
Forum: Virtualization
Topic: CHR License P1 - Invalid Cloud ??
Replies: 3
Views: 371

Re: CHR License P1 - Invalid Cloud ??

P1, limited upgrades? next renewal is later on today previous deadline march 2023..

Is there some sort of process where you have to hit the renewal button or something and before this deadline thingy.. So weird.
by anav
Thu Nov 16, 2023 6:08 pm
Forum: General
Topic: Fundamental problems at MikroTik
Replies: 32
Views: 2358

Re: Fundamental problems at MikroTik

Like I said, delete this thread its a farce from the get go.
by anav
Thu Nov 16, 2023 6:06 pm
Forum: Beginner Basics
Topic: How to route all traffic through WireGuard VPN and keep LAN access? [SOLVED]
Replies: 9
Views: 973

Re: How to route all traffic through WireGuard VPN and keep LAN access? [SOLVED]

Thats a good sign as it looks like you are getting at least the correct IP address. There may be an issue with your windows wireguard client did you get the client from the wireguard website (if so good, if from a MS windows site, not good). Ensure you have no blocking firewall or AV on windows side...
by anav
Thu Nov 16, 2023 4:41 pm
Forum: General
Topic: VPN server like CIsco Asa Anyconnect
Replies: 6
Views: 703

Re: VPN server like CIsco Asa Anyconnect

by anav
Thu Nov 16, 2023 4:39 pm
Forum: General
Topic: Fundamental problems at MikroTik
Replies: 32
Views: 2358

Re: Fundamental problems at MikroTik

Someone change the title... since this about obtaining the GPL source. Nobody is asking $45 USD to get GPL covered source. In fairness, I think the software license agreement does list $45 duplication fee. To get a CD with the corresponding source code for the GPL-covered programs in this distribut...
by anav
Thu Nov 16, 2023 3:42 pm
Forum: Forwarding Protocols
Topic: WAN Failover and/or recursive routing issue
Replies: 20
Views: 1990

Re: WAN Failover and/or recursive routing issue

Typically if one has a primary / failover scenario and folks want some devices to go out WAN2 then one uses routing rules. Routing rules are great for whole subnets or a few users, however if you have many users, one has two choices, a.. make as many rules as per users. b. mangle by firewall address...
by anav
Thu Nov 16, 2023 3:39 pm
Forum: Announcements
Topic: v7.13beta [testing] is released!
Replies: 467
Views: 69698

Re: v7.13beta [testing] is released!

MT is getting better and releasing youtube videos that are helpful case in point, althought doesnt necessarily answer your migration question is a step in the right direction!
https://www.youtube.com/watch?v=37aff6d14Xk&t=485s
by anav
Thu Nov 16, 2023 3:34 pm
Forum: General
Topic: Fundamental problems at MikroTik
Replies: 32
Views: 2358

Re: Fundamental problems at MikroTik

Other than the insightful comments by justin, and factual comments by Mrz and Normis, the rest of this thread is Fake News and annoying whining. Rather than being insighful, the author of this thread is trying to incite some anger for a nothing-burger. Yawn!! Please Delete this thread, I could have ...
by anav
Thu Nov 16, 2023 3:26 pm
Forum: Beginner Basics
Topic: How to route all traffic through WireGuard VPN and keep LAN access? [SOLVED]
Replies: 9
Views: 973

Re: How to route all traffic through WireGuard VPN and keep LAN access? [SOLVED]

Since the MT router is the server for handshake, there is no NEED for KEEP ALIVE on the peer setting for the laptop. Looking at the config, it would appear you should be able to do both. /interface list member add comment=defconf interface=bridge list=LAN add comment=defconf interface=ether1 list=WA...
by anav
Thu Nov 16, 2023 3:14 pm
Forum: General
Topic: Permanently replace factory default
Replies: 2
Views: 328

Re: Permanently replace factory default

Yes.
by anav
Thu Nov 16, 2023 2:57 pm
Forum: General
Topic: Problems with mangle-rules on RouterOS 7.12
Replies: 12
Views: 842

Re: Problems with mangle-rules on RouterOS 7.12

The only difference between 6 and 7, is that you need to add a table, and the extra route reflects the table not the routing mark. Otherwise those two rules help ensure traffic that comes into WAN2 goes out WAN2. Not sure why you think it wont.......... You could also try adding (if a static wanip) ...
by anav
Thu Nov 16, 2023 3:12 am
Forum: General
Topic: Problems with mangle-rules on RouterOS 7.12
Replies: 12
Views: 842

Re: Problems with mangle-rules on RouterOS 7.12

Not sure why you have three rules it should be the first rule and one more............. combo of the other two. /ip firewall mangle add action=mark-connection chain=prerouting connection-mark=no-mark in-interface=eth11-WAN-A1 new-connection-mark=MARK-WAN-A1 passthrough=yes /ip firewall mangle add ac...
by anav
Wed Nov 15, 2023 7:05 pm
Forum: Beginner Basics
Topic: 7.13 Beta 5Ghz issue (hap ax2)
Replies: 15
Views: 924

Re: 7.13 Beta 5Ghz issue (hap ax2)

Q: why do you use Canadian country settings when you are based in Kiev ?
Everything is better in Canada!!
by anav
Wed Nov 15, 2023 6:59 pm
Forum: General
Topic: Multi-WAN Load Balancing Starlink issue
Replies: 94
Views: 7451

Re: Multi-WAN Load Balancing Starlink issue

Those are dogsled miles :-)

Your second point lost its train of thought........
the reason why..... if that even if........................... ??????
by anav
Wed Nov 15, 2023 6:55 pm
Forum: General
Topic: VoIP over Wireguard Vpn: one way audio problem.
Replies: 16
Views: 1345

Re: VoIP over Wireguard Vpn: one way audio problem.

Set up SSTP between the two routerboards and run the VOIP through that vice wireguard?? Its quick and easy to set this up using mchap2 no certificates. Just for giggles on the routerboard that is client for handshake. set up this mangle rule which helps if there are any MTU issues...... If it was a ...
by anav
Wed Nov 15, 2023 5:55 pm
Forum: Beginner Basics
Topic: Port Forwarding problem
Replies: 1
Views: 275

Re: Port Forwarding problem

Please put code blocks at start/end of config, the black square with white square brackets above, on the same line as bold and underline!!

Did you read --> viewtopic.php?t=179343
  • 1
  • 2
  • 3
  • 4
  • 5
  • 61