Community discussions

MikroTik App

Search found 536 matches

  • 1
  • 2
by biomesh
Fri Mar 03, 2023 12:41 am
Forum: RouterOS beta and rc versions
Topic: L3HW Firewall Offloading - Doesn't Offload Inter-VLAN traffic [SOLVED]
Replies: 19
Views: 2473

Re: L3HW Firewall Offloading - Doesn't Offload Inter-VLAN traffic [SOLVED]

My crs317 with 7.8 works fine with inter and intra vlan traffic on the same or different interfaces.
by biomesh
Wed Mar 01, 2023 1:45 am
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 345
Views: 74495

Re: v7.8 [stable] is released!

Upgraded the following with no issues (been running over 34 hours)

ccr2004-16g-2s+, crs317, crs326-24g, crs112, cap ac, chr, crs318
by biomesh
Mon Feb 20, 2023 6:26 pm
Forum: General
Topic: How to mass configure 50 hAP units ?
Replies: 19
Views: 1136

Re: How to mass configure 50 hAP units ?

Flashfig is still listed as an option on the support website

https://help.mikrotik.com/docs/display/ROS/Flashfig
by biomesh
Sat Feb 04, 2023 11:49 pm
Forum: Beginner Basics
Topic: Disable CAP mode without UI
Replies: 4
Views: 318

Re: Disable CAP mode without UI

The reset button puts it into reset config mode, caps mode or netinstall mode. Choose which one works best for you.

You might need to have it be a cap temporarily so you can reset it the way you want it to.
by biomesh
Sat Feb 04, 2023 11:42 pm
Forum: Beginner Basics
Topic: Disable CAP mode without UI
Replies: 4
Views: 318

Re: Disable CAP mode without UI

/system/reset-configuration caps-mode=no
by biomesh
Sat Jan 28, 2023 3:42 pm
Forum: General
Topic: Forgetful Mikrotik [SOLVED]
Replies: 4
Views: 411

Re: Forgetful Mikrotik [SOLVED]

Are you out of space on your disk/flash?
by biomesh
Sat Jan 28, 2023 3:33 pm
Forum: RouterOS beta and rc versions
Topic: RB5009UPr+S+ Bandwidth Issue
Replies: 27
Views: 1640

Re: RB5009UPr+S+ Bandwidth Issue

Do you get full speed if you test from a device with only a 1 gig nic?
by biomesh
Fri Jan 27, 2023 6:11 pm
Forum: Announcements
Topic: v7.7 [stable] is released!
Replies: 357
Views: 91475

Re: v7.7 [stable] is released!

My l3hw offload for ipv6 on a crs317 works with no issues. Here is my ipv6 specific config: /interface ethernet switch set 0 l3-hw-offloading=yes /interface ethernet switch l3hw-settings set ipv6-hw=yes /ipv6 address add address=fd00:70::1 interface=vlan70 add address=fd00::2 advertise=no interface=...
by biomesh
Mon Jan 23, 2023 4:51 pm
Forum: RouterBOARD hardware
Topic: MikroTik hAP ax³ [C53UiG+5HPaxD2HPaxD]
Replies: 78
Views: 18011

Re: MikroTik hAP ax³ [C53UiG+5HPaxD2HPaxD]

@Larin my ccr2004-16G has factory firmware 7.4.1 and factory software of 7.3.1, so not out of the ordinary it seems. What does seem concerning is that you had so many writes during your uptime of less than 5 hours.

Are you doing any work with containers or a lot of graphing?
by biomesh
Fri Jan 20, 2023 6:03 pm
Forum: Announcements
Topic: v7.8beta [testing] is released!
Replies: 306
Views: 55037

Re: v7.8beta [testing] is released!

Why do you quote whole preceding post? Does it help answering? Do you repeat what your interlocutor says when you discuss?
For a CHR instance without an active license
by biomesh
Fri Jan 20, 2023 1:58 pm
Forum: Wireless Networking
Topic: Netpower 16P adapter
Replies: 3
Views: 303

Re: Netpower 16P adapter

If any device needs 48v, you need to have a 48v power supply attached. The switch can have both a 24v and 48v adapter connected to power different devices connected to the switch at the same time.
by biomesh
Fri Jan 13, 2023 5:42 pm
Forum: Wireless Networking
Topic: Horribly slow Wi-Fi on Mikrotik network
Replies: 133
Views: 17152

Re: Horribly slow Wi-Fi on Mikrotik network

Actually market is full of other brand AX AP's for half of that.
The cheapest competitor in the US would be UniF--k AP lite. Which is $100.
I would not say it is full of $50 AX APs but you can find a Zyxel wifi 6 AP on amazon for $75 USD. Its not what I would buy, but there are options.
by biomesh
Fri Jan 13, 2023 1:38 pm
Forum: Beginner Basics
Topic: Configuration help [SOLVED]
Replies: 5
Views: 496

Re: Configuration help [SOLVED]

Under /ip settings you have ip-forward=no. If you want the router to route packets between networks that needs to be set to yes.
by biomesh
Sat Jan 07, 2023 6:45 am
Forum: RouterBOARD hardware
Topic: CCR2004-1G-12S-2XS - are there any "before you buy" caveats?
Replies: 8
Views: 751

Re: CCR2004-1G-12S-2XS - are there any "before you buy" caveats?

The 12S+ had some issues initially with reboots (related to the port extender in the block diagram). I have not heard of issues with current versions, 7.5+, but they did exist. Be sure to check the test results and block diagram to see what the router can really do. The 2004-16G versions don't have ...
by biomesh
Fri Jan 06, 2023 9:39 pm
Forum: General
Topic: NextDNS service with RouterOS
Replies: 7
Views: 744

Re: NextDNS service with RouterOS

To get the full logging, you would need to have the nextdns client installed on the devices or install it somewhere (docker, raspi, etc) in router mode (setup-router true). Depending on the mikrotik device used, this can definitely be run as a docker container.
by biomesh
Fri Jan 06, 2023 9:24 pm
Forum: General
Topic: NextDNS service with RouterOS
Replies: 7
Views: 744

Re: NextDNS service with RouterOS

Also if you use the nextdns client (on a raspi, server, or in a docker container) you can specify different mac addresses to point to different configs. This is what I use to apply extra security to devices my kids use.
by biomesh
Fri Jan 06, 2023 9:21 pm
Forum: General
Topic: NextDNS service with RouterOS
Replies: 7
Views: 744

Re: NextDNS service with RouterOS

I use the pro for myself and my parents - for the last 30 days we have had 1.5 mil queries with the bulk of them coming from my home network.
by biomesh
Fri Jan 06, 2023 8:56 pm
Forum: General
Topic: NextDNS service with RouterOS
Replies: 7
Views: 744

Re: NextDNS service with RouterOS

If its a small charity, why not just use the "pro" nextdns plan which is $20 USD a year?
by biomesh
Thu Jan 05, 2023 3:20 pm
Forum: General
Topic: HW Offload on LAN ports not working [SOLVED]
Replies: 8
Views: 709

Re: HW Offload on LAN ports not working [SOLVED]

Use a command similar to

/interface/bridge/port set bridge=bridge-wan interface=ether1 hw=no

Repeat for all interfaces in the wan bridge.
by biomesh
Thu Jan 05, 2023 2:02 pm
Forum: General
Topic: HW Offload on LAN ports not working [SOLVED]
Replies: 8
Views: 709

Re: HW Offload on LAN ports not working [SOLVED]

You can only hardware offload on one bridge at a time. Remove the wan bridge, as it is not a bridged interface by default.
by biomesh
Tue Jan 03, 2023 2:29 pm
Forum: RouterBOARD hardware
Topic: CCR2216-PERFORMANCE problem
Replies: 11
Views: 1352

Re: CCR2216-PERFORMANCE problem

Since you won't share an export, there is only so much others on the forum can do to help.

I would start by checking fasttrack requirements

https://wiki.mikrotik.com/wiki/Manual:IP/Fasttrack

And then open a ticket with support.
by biomesh
Fri Dec 23, 2022 3:10 pm
Forum: RouterBOARD hardware
Topic: Please launch hAP with AX3000 or above
Replies: 8
Views: 849

Re: Please launch hAP with AX3000 or above

More chains do help wrt MU-MIMO.

The cpu/ram would also need to be adjusted to handle the extra load.
by biomesh
Thu Dec 22, 2022 10:07 pm
Forum: RouterBOARD hardware
Topic: CCR2004-16G-2S+PC NO USB, WHYYY!??
Replies: 15
Views: 1498

Re: CCR2004-16G-2S+PC NO USB, WHYYY!??

At least it is better than the sdcard slot on the ccr1009 and ROS7 where it just does not work anymore. Clearly defined expectations/features are better than empty promises.
by biomesh
Sun Dec 18, 2022 10:54 pm
Forum: Beginner Basics
Topic: CRS112 Router Throughout Issue
Replies: 3
Views: 288

Re: CRS112 Router Throughout Issue

The crs112 is a switch with very basic routing capacity.

https://mikrotik.com/product/CRS112-8G- ... estresults

Depending on your config ~30Mbps is probably to be expected.

The device only has a 400MHz Mips cpu, so it won't be able to do much on the routing side.
by biomesh
Thu Dec 15, 2022 1:28 pm
Forum: Beginner Basics
Topic: RB5009 upload problem
Replies: 11
Views: 1136

Re: RB5009 upload problem

Do you get full speeds using a 1G port on your lan / 5009 instead of the 2.5G port?
by biomesh
Fri Dec 09, 2022 2:05 pm
Forum: RouterBOARD hardware
Topic: NAND change and license migration ..Help
Replies: 35
Views: 2284

Re: NAND change and license migration ..Help

You admit you made a risky decision, and yet now want 'fairness'.

Either quietly email support and see if they can help, or buy a new license, or get rid of the device.

There isn't anything else to discuss anymore.
by biomesh
Sun Dec 04, 2022 1:57 pm
Forum: General
Topic: hAP ax2 Access Point Make in China - Legit?
Replies: 5
Views: 580

Re: hAP ax2 Access Point Make in China - Legit?

Check https://mikrotik.com/buy/

but it looks suspicious to me if the manufacturing third party (or whoever this is) would be trying to sell items outside of the normal distribution channels.
by biomesh
Mon Nov 28, 2022 6:24 pm
Forum: RouterBOARD hardware
Topic: CCR1009 Rebooting
Replies: 78
Views: 7214

Re: CCR1009 Rebooting

Just FYI my CCR1009 was running 7.5 for over a month without issues. I replaced it with a CCR2004, so the 1009 is not currently in use. The only issues I had with 7.x and the CCR1009 were/are: - sd card no longer works - in earlier 7.x version there was a bug with l2tp/ipsec where it would go into h...
by biomesh
Sun Nov 27, 2022 4:15 am
Forum: RouterBOARD hardware
Topic: CCR1009 Rebooting
Replies: 78
Views: 7214

Re: CCR1009 Rebooting

You might want to netinstall the device to make sure there isn't an issue with the flash or the os install. I would also check the capacitors to make sure none are failing. If you have a backup power supply, I would also test that as well.
by biomesh
Tue Nov 22, 2022 8:56 pm
Forum: General
Topic: CRS3xx config
Replies: 3
Views: 431

Re: CRS3xx config

I also create a vlan interface assigned to the bridge which will have the management IP. /interface vlan add interface=bridge1 name=vlan88 vlan-id=88 /ip address add address=192.168.88.1/24 comment=defconf interface=vlan88 network=\ 192.168.88.0 /interface bridge vlan add bridge=bridge tagged=bridge...
by biomesh
Tue Nov 15, 2022 9:44 pm
Forum: General
Topic: how does L3HW actually works?
Replies: 125
Views: 21331

Re: how does L3HW actually works?

Here is a snippet - not going into the actual enabling of l3hw as that is in the manual/wiki. This should be most of it to understand how I use it. CRS317 /ip address add address=192.168.6.1/23 interface=vlan600 network=192.168.6.0 add address=192.168.5.1/24 interface=vlan500 network=192.168.5.0 add...
by biomesh
Tue Nov 15, 2022 4:04 pm
Forum: General
Topic: how does L3HW actually works?
Replies: 125
Views: 21331

Re: how does L3HW actually works?

For soho, if you only have one subnet and you are not using the switch as your main router, then there really is no benefit. If you have multiple subnets/vlans on your network but use a separate router, then yes there is a definite benefit. If you use your crs device as a router, it might be better ...
by biomesh
Wed Nov 09, 2022 12:35 am
Forum: General
Topic: Wireguard Slow upload
Replies: 18
Views: 2184

Re: Wireguard Slow upload

On a CCR2004-16G-2S+ I get ~4.6 Gbps single threaded iperf with no wireguard both directions. With wireguard, I get 1.17Gbps (without -R) and 833Mbps (with -R). All tests single threaded. You might want to check your wireguard config on the computer or firewall/antivirus, etc.
by biomesh
Tue Nov 08, 2022 3:27 pm
Forum: General
Topic: Unable to reach Total Available Bandwidth on RB750gr3
Replies: 21
Views: 1301

Re: Unable to reach Total Available Bandwidth on RB750gr3

I'm pretty sure you are hitting the max that this device can provide, considering you are using PPPOE and multi-wan (with the associated rules). The performance tests for 6.x show for a 512 packet size of 385.4 Mbps speed, which will be higher than 7.x due to the removal of the Linux route cache in ...
by biomesh
Fri Nov 04, 2022 1:11 pm
Forum: RouterBOARD hardware
Topic: PoE Out of hAP ax² to power SXT LTE Kit
Replies: 7
Views: 754

Re: PoE Out of hAP ax² to power SXT LTE Kit

I have bought a lot of mikrotik devices and I don't think I have ever seen a power supply "made" by them. I am sure they buy power supplies from different vendors as needs or supply levels change.
by biomesh
Wed Nov 02, 2022 1:50 pm
Forum: RouterBOARD hardware
Topic: CRS 305 after upgrade FW 7.6 CPU increased from 1 to 2 CPU
Replies: 4
Views: 537

Re: CRS 305 after upgrade FW 7.6 CPU increased from 1 to 2 CPU

The crs3xx series (many of them) have arm cpus. Many of the cpus have multiple cores, but with the older kernel could only use one with ros 6. With ros 7, these extra cores were enabled due to the newer Linux kernel. The crs328 is the only device so far that has had the extra core disabled in ros7.
by biomesh
Fri Oct 28, 2022 1:54 pm
Forum: RouterBOARD hardware
Topic: Any current issues with CCR2xxx series? Stay with CCR1xxx?
Replies: 1
Views: 334

Re: Any current issues with CCR2xxx series? Stay with CCR1xxx?

I have not had any reboot issues with a ccr2004-16G-2S+.

It shipped with 7.3.1, but upgraded it to 7.4 and subsequently to 7.5 and 7.6 with no issues.

It was an easy upgrade from my 1009.
by biomesh
Thu Oct 20, 2022 6:37 pm
Forum: General
Topic: RB3011 DHCP server fails to assign IPs to many Linux devices
Replies: 9
Views: 502

Re: RB3011 DHCP server fails to assign IPs to many Linux devices

How about removing

client-mac-limit=0

from your dhcp server.
by biomesh
Tue Oct 18, 2022 5:30 pm
Forum: Announcements
Topic: v7.6 [stable] is released!
Replies: 279
Views: 125937

Re: v7.6 [stable] is released!

Those two changelog entries don't mention anything about WinBox, from which you provided the screenshots. Look for them in CLI. These work via winbox on all of the devices that I upgraded. crs317, crs318, crs326, ccr2004, crs112, cap ac. For the cap ac and crs112 obviously the l3hw options are not ...
by biomesh
Thu Oct 13, 2022 12:02 am
Forum: General
Topic: CCR2004-16G-2S+ no default firewall?
Replies: 5
Views: 480

Re: CCR2004-16G-2S+ no default firewall?

Some models, like CCRs don't come with an extensive default config as they are not designed for inexperienced users. https://wiki.mikrotik.com/wiki/Manual:Default_Configurations Start with the forums or help website and build the config (disconnected from the Internet) https://help.mikrotik.com/docs...
by biomesh
Wed Oct 12, 2022 1:35 pm
Forum: General
Topic: 7.4.x and 7.5 SIP issue [SOLVED]
Replies: 16
Views: 1693

Re: 7.4.x and 7.5 SIP issue [SOLVED]

If it broke everyone's voip, I'm sure there would be more than just a handful of people reporting an issue. I am currently using 7.5 and have been regularly updating ROS with no issues on my voip services. I use asterisk connecting to multiple providers. You could post your config or revert and open...
by biomesh
Wed Oct 05, 2022 6:08 pm
Forum: Announcements
Topic: v7.6rc is released!
Replies: 94
Views: 22511

Re: v7.6rc is released!

I finally decided to test ipv6 l3hw offloading on my crs317 with l3hw ipv4 already enabled. It was a few quick changes and now I get full 10gbps ipv6 on my internal vlans.
by biomesh
Tue Oct 04, 2022 5:17 pm
Forum: General
Topic: No health information on RB941-2nD [SOLVED]
Replies: 1
Views: 543

Re: No health information on RB941-2nD [SOLVED]

No, only devices listed with voltage/current/temperature/fan sensors will have health data. The ~$25 device has none of those.

https://mikrotik.com/product/RB941-2nD
by biomesh
Tue Oct 04, 2022 4:23 pm
Forum: RouterBOARD hardware
Topic: NetPower16 P - Enough power with 96W
Replies: 3
Views: 414

Re: NetPower16 P - Enough power with 96W

Yes, look at the different docs for CRS318-16P-2S+. That is the full model number.
by biomesh
Tue Oct 04, 2022 1:50 pm
Forum: Scripting
Topic: How can I create a IPv6 /64 prefix from dhcpv6 client provided /56 prefix
Replies: 5
Views: 624

Re: How can I create a IPv6 /64 prefix from dhcpv6 client provided /56 prefix

Basic config dhcp client on the wan interface saving pd to a pool /ipv6 dhcp-client add add-default-route=yes interface=wan pool-name=comcast_ipv6 \ prefix-hint=::/60 request=address,prefix use-peer-dns=no ip address/prefix (::/64) assigned from the pd pool /ipv6 address add from-pool=comcast_ipv6 i...
by biomesh
Mon Oct 03, 2022 4:10 am
Forum: RouterBOARD hardware
Topic: RB850Gx2 less ram than in spec?
Replies: 3
Views: 512

Re: RB850Gx2 less ram than in spec?

I don't know how popular these were. They were discontinued in 2018 I believe.

For ram it should show the correct amount. For disk, It could have been partitioned.
by biomesh
Thu Sep 29, 2022 4:21 pm
Forum: Beginner Basics
Topic: Router on a stick with no bridge interface
Replies: 3
Views: 377

Re: Router on a stick with no bridge interface

First off the crs series - especially the 1xx and 2xx versions are primarily switches. You won't get great routing performance off of these devices. Second, running a speed test on a device itself is not the correct way to test as the device will use a lot of the CPU to just run the bandwidth test i...
by biomesh
Sun Sep 25, 2022 3:27 am
Forum: RouterBOARD hardware
Topic: [SOLVED] GESP - Confusion with the included hardware
Replies: 8
Views: 809

Re: GESP - Confusion with the included hardware

The original gesp looked like this

https://www.streakwave.com/mikrotik-ges ... -protector

The docs probably refer to the newer model.

Do you have the older or newer model?
by biomesh
Sat Sep 24, 2022 4:08 am
Forum: RouterBOARD hardware
Topic: MikroTik hAP ax³ [C53UiG+5HPaxD2HPaxD]
Replies: 78
Views: 18011

Re: MikroTik hAP ax³ [C53UiG+5HPaxD2HPaxD]

Wow a level 6 license.
by biomesh
Thu Sep 22, 2022 6:10 pm
Forum: RouterBOARD hardware
Topic: is CRS317-1G-16S+ better than CCR2004-1G-12S+2XS?
Replies: 3
Views: 510

Re: is CRS317-1G-16S+ better than CCR2004-1G-12S+2XS?

See what features can be hardware offloaded on a CRS317 https://help.mikrotik.com/docs/display/ROS/L3+Hardware+Offloading?src=contextnavpagetreemode If this is all you need now and in the future, go with a CRS317. If you need more than this or expect you will need more in the future get a CCR (or bo...
by biomesh
Thu Sep 08, 2022 5:33 pm
Forum: General
Topic: Slow internet speed but high LAN speed through CRS326
Replies: 5
Views: 524

Re: Slow internet speed but high LAN speed through CRS326

I would make sure you test iperf going from the server to the client (either using -d or -R option). The output you show is the "upload" on your ISP test. If that shows 1Gbps, then the switch is working properly - it doesn't do anything special for out of your local subnet traffic unless y...
by biomesh
Thu Sep 08, 2022 1:50 pm
Forum: General
Topic: Slow internet speed but high LAN speed through CRS326
Replies: 5
Views: 524

Re: Slow internet speed but high LAN speed through CRS326

If iperf both ways between switches work (with and without the -R option) then the issue would be at the firewall.

Check to see what the load is on the firewall and also check to see if you have enabled jumbo frames elsewhere in your network that is possibly being fragmented at the firewall.
by biomesh
Mon Sep 05, 2022 11:45 pm
Forum: Wireless Networking
Topic: if cAP loosing connection to CAPSMAN - they stop working
Replies: 10
Views: 865

Re: if cAP loosing connection to CAPSMAN - they stop working

There is no automated way integrated that will sync capsman config between devices. You could script syncing changes or use the rest api to make changes on multiple servers at the same time.
by biomesh
Sun Sep 04, 2022 8:48 pm
Forum: Beginner Basics
Topic: Subnet Mask 23 Work On Dhcp But Not Fixed Ip
Replies: 5
Views: 668

Re: Subnet Mask 23 Work On Dhcp But Not Fixed Ip

You can leave the router/gateway address the way it is, but set the network to 192.168.0.0 on the interface that has 192.168.1.1 assigned.
by biomesh
Fri Jul 22, 2022 3:48 pm
Forum: Wireless Networking
Topic: CapsMan on one of the APs?
Replies: 17
Views: 1198

Re: CapsMan on one of the APs?

Capsman also has the ability to set multiple capsman managers: When the list of available CAPsMANs is built, CAP selects a CAPsMAN based on the following rules: if caps-man-names parameter specifies allowed manager names (/system identity of CAPsMAN), CAP will prefer the CAPsMAN that is earlier in t...
by biomesh
Wed Jul 20, 2022 4:05 pm
Forum: Announcements
Topic: v7.4 [stable] is released!
Replies: 226
Views: 44767

Re: v7.4 [stable] is released!

ccr1009
crs318
crs317
crs326-24G
crs112-8G
cap-ac

All upgraded with no issues- upgraded from 7.3.
by biomesh
Mon Jul 18, 2022 2:42 pm
Forum: RouterBOARD hardware
Topic: Microtik crs326-24g-2s+rm
Replies: 4
Views: 537

Re: Microtik crs326-24g-2s+rm

That switch supports passive poe in (10-30V) according to the docs. This is only used to power the switch itself and not other connected devices.

https://mikrotik.com/product/CRS326-24G-2SplusRM
by biomesh
Fri Jul 15, 2022 3:07 pm
Forum: Beginner Basics
Topic: Newbie license/operation questions...
Replies: 2
Views: 325

Re: Newbie license/operation questions...

I suggest using a CHR version of routeros. It is a vm based install and you can choose the version based on max speed on the interfaces used. There is a 60 day trial license that can be used to verify functionality before spending any money on a license. The CHR licenses can be transferred between V...
by biomesh
Tue Jun 28, 2022 5:12 pm
Forum: Beginner Basics
Topic: CRS354 VLANs 100% cpu load
Replies: 9
Views: 763

Re: CRS354 VLANs 100% cpu load

I would not start over - here is a sample config for reference: /interface bridge add admin-mac=XX:XX:XX:XX:XX:XX auto-mac=no name=bridge1 priority=0x2000 \ pvid=75 vlan-filtering=yes /interface ethernet set [ find default-name=ether1 ] l2mtu=9080 mtu=9000 set [ find default-name=ether2 ] l2mtu=9080...
by biomesh
Tue Jun 28, 2022 4:24 pm
Forum: Beginner Basics
Topic: CRS354 VLANs 100% cpu load
Replies: 9
Views: 763

Re: CRS354 VLANs 100% cpu load

- you don't need vlan interfaces on a switch unless you are going to implement l3hw offloading (and perform routing) or want to assign an ip address for management to one of the vlans going through/to the switch (this vlan would be assigned to the bridge) - your ip address is assigned to ether2 and ...
by biomesh
Tue Jun 28, 2022 3:57 pm
Forum: Beginner Basics
Topic: CRS354 VLANs 100% cpu load
Replies: 9
Views: 763

Re: CRS354 VLANs 100% cpu load

Did you enable l3hw offloading? This is primarily a switch and while there are some layer 3 routing features offloaded to the switch chip, the CPU is not going to be able to handle much routing outside of the functionality in the l3hw offloading specs. https://help.mikrotik.com/docs/display/ROS/L3+H...
by biomesh
Sat Jun 25, 2022 4:16 pm
Forum: Beginner Basics
Topic: Hex S VLAN Routing Speed
Replies: 16
Views: 1270

Re: Hex S VLAN Routing Speed

You don't have any firewall rules (only nat) and that also includes fasttrack. Perhaps look at enabling fasttrack to see if that helps.
by biomesh
Sat Jun 25, 2022 4:12 pm
Forum: Beginner Basics
Topic: Hex S VLAN Routing Speed
Replies: 16
Views: 1270

Re: Hex S VLAN Routing Speed

A bridge is only necessary if you have to extend a network across multiple interfaces. If you only use one lan port (even with multiple vlan interfaces) you don't need to use a bridge.

I was just mentioning it as something to consider testing.
by biomesh
Sat Jun 25, 2022 3:40 pm
Forum: Beginner Basics
Topic: Hex S VLAN Routing Speed
Replies: 16
Views: 1270

Re: Hex S VLAN Routing Speed

For the OP, you are only using two ports (wan and lan) so the bridge is not really necessary. I know on a ccr1009 the routing speed and cpu doesn't really differ with or without a bridge, but it might on your device. Are you using iperf for some of these tests btw? That would be the best way to test.
by biomesh
Sat Jun 18, 2022 10:35 pm
Forum: Announcements
Topic: v7.3 and v7.3.1 [stable] is released!
Replies: 270
Views: 65441

Re: v7.3 and v7.3.1 [stable] is released!

zerotier is only available for arm devices.
by biomesh
Fri Jun 17, 2022 2:58 am
Forum: Containers
Topic: v7.1rc3 adds container support
Replies: 493
Views: 131917

Re: v7.1rc3 adds Docker (TM) compatible container support

Any chance you might share some stats regarding mem and disk usage for some of the containers? So far I am only using a container I built for nextdns that is based on a small debian image. The tar file is 110MB and I still have the tar file on my disk and using ~300MB disk (I have other files on th...
by biomesh
Thu Jun 16, 2022 7:45 pm
Forum: Containers
Topic: v7.1rc3 adds container support
Replies: 493
Views: 131917

Re: v7.1rc3 adds Docker (TM) compatible container support

Did you install the container package from the "all packages" zip file?
by biomesh
Thu Jun 16, 2022 6:26 pm
Forum: Announcements
Topic: v7.4beta [testing] is released!
Replies: 189
Views: 51987

Re: v7.4beta [testing] is released!

Updated my containers from the 7.0x beta and was redeploy it on my CHR with no issues.
by biomesh
Fri Jun 10, 2022 3:13 pm
Forum: Beginner Basics
Topic: CRS305-1G-4S+IN as a media converter for WAN and switch for LAN?
Replies: 2
Views: 336

Re: CRS305-1G-4S+IN as a media converter for WAN and switch for LAN?

Just use vlans, and make sure it is properly configured. There is no reason why it can't work, but it does take more effort to configure than basic configs.
by biomesh
Thu Jun 09, 2022 11:36 pm
Forum: Beginner Basics
Topic: CAPsMAN unstable after upgrade to 7.3 [SOLVED]
Replies: 16
Views: 2236

Re: CAPsMAN unstable after upgrade to 7.3 [SOLVED]

If you see it on both, I would just skip capsman on 7.x for now.
by biomesh
Thu Jun 09, 2022 9:04 pm
Forum: Beginner Basics
Topic: CAPsMAN unstable after upgrade to 7.3 [SOLVED]
Replies: 16
Views: 2236

Re: CAPsMAN unstable after upgrade to 7.3 [SOLVED]

Since it is reporting out of memory conditions on the hap lite (which has 32MB RAM) you should probably move the capsman server to the cap lite since it has 64 MB RAM and let the hap lite be a capsman client. If you only have two APs, you could also just skip capsman and configure them separately. T...
by biomesh
Thu Jun 09, 2022 8:51 pm
Forum: General
Topic: CCR2216-1G-12XS-2XQ constanly reboots!!!! [SOLVED]
Replies: 21
Views: 2581

Re: CCR2216-1G-12XS-2XQ constanly reboots!!!! [SOLVED]

I see that your 192.168.1.x pool includes 192.168.1.1 which is already assigned to the router itself. It would not cause reboots, but should be fixed. The CCR devices do not come with a default firewall and so you must add one. I only see one firewall rule so you should work on that https://help.mik...
by biomesh
Thu Jun 09, 2022 2:43 pm
Forum: General
Topic: CCR2216-1G-12XS-2XQ constanly reboots!!!! [SOLVED]
Replies: 21
Views: 2581

Re: CCR2216-1G-12XS-2XQ constanly reboots!!!! [SOLVED]

Can you export and post your config so others can see what is configured on the device?
by biomesh
Fri Jun 03, 2022 3:16 pm
Forum: General
Topic: High CPU CRS354-48G-4S+2Q+
Replies: 14
Views: 1794

Re: High CPU CRS354-48G-4S+2Q+

The crs112 also has this issue. Reading the interface stats will increase the cpu load quite a bit.

I reported this issue, but I don't think there is much priority to look at or fix this on the mipsbe devices.
by biomesh
Wed May 18, 2022 11:19 pm
Forum: RouterBOARD hardware
Topic: RB dead? netinstall completes but no signs of life after reboot
Replies: 5
Views: 617

Re: RB dead? netinstall completes but no signs of life after reboot

The only other suggestion I would make is to check the power supply. A bad or failing PS can have many different symptoms.
by biomesh
Mon May 09, 2022 3:25 pm
Forum: RouterBOARD hardware
Topic: Chassis opening vs warranty [SOLVED]
Replies: 18
Views: 2412

Re: Chassis opening vs warranty [SOLVED]

This whole topic seems odd to me - just opening the case does not void the warranty, at least in the US. What you do once the case is open, makes more of a difference. If you have a model that takes nvme/ssd/ram and you add or replace a user controlled component, then I would say the warranty is sti...
by biomesh
Sun May 08, 2022 2:41 pm
Forum: General
Topic: CAPSMAN not installed RouterOS7 [SOLVED]
Replies: 2
Views: 614

Re: CAPSMAN not installed RouterOS7 [SOLVED]

You have the wifiwave2 package installed which does not work with capsman.
by biomesh
Mon May 02, 2022 10:28 pm
Forum: General
Topic: Wireguard slow speed
Replies: 39
Views: 6659

Re: Wireguard slow speed

Are both of the devices using the same ISP? I see your results from your work server is fine.

I was just wondering if they are on the same ISP since there could be an issue with bandwidth limits on peering points between networks along the way if they are not on the same ISP.
by biomesh
Sun May 01, 2022 3:32 pm
Forum: General
Topic: Wireguard slow speed
Replies: 39
Views: 6659

Re: Wireguard slow speed

He is at site 1 downloading from site 2, from what I understand.
by biomesh
Sun May 01, 2022 2:56 pm
Forum: General
Topic: CRS112 just died on me - 48V connection an issue? [SOLVED]
Replies: 7
Views: 716

Re: CRS112 just died on me - 48V connection an issue? [SOLVED]

The device can run on either voltage to power the device. The device will use the highest voltage connected to it to power itself though.
by biomesh
Sun May 01, 2022 2:44 pm
Forum: General
Topic: CRS112 just died on me - 48V connection an issue? [SOLVED]
Replies: 7
Views: 716

Re: CRS112 just died on me - 48V connection an issue? [SOLVED]

If it's under warranty, I would rma it. if not, perhaps someone else can give you things to check on the board itself for repairs.
by biomesh
Sun May 01, 2022 2:42 pm
Forum: General
Topic: Wireguard slow speed
Replies: 39
Views: 6659

Re: Wireguard slow speed

The wording is a bit off - he is downloading (100 mbps) from the second site (600mbps), so ideally it would be close to 100mbps in ideal/perfect situations.

Have you tried iperf3 between sites?
by biomesh
Sun May 01, 2022 2:35 pm
Forum: General
Topic: CRS112 just died on me - 48V connection an issue? [SOLVED]
Replies: 7
Views: 716

Re: CRS112 just died on me - 48V connection an issue? [SOLVED]

It should not matter. I would try with one power supply at a time, if you have different ones, try those.

From your description, this is the poe version of the switch, if it was not then you could also try to power via poe in.
by biomesh
Fri Apr 29, 2022 3:01 pm
Forum: General
Topic: CRS317 and TX-drops (maybe a workaround?)
Replies: 12
Views: 1892

Re: CRS317 and TX-drops (maybe a workaround?)

For the slower ports/interfaces try and set the ingress / egress port speed (switch interface) to close to what the interface can actually support. In the past when I used a 2.5 gb sfp+ adapter I had to set the rate to 2400 to get basically no retries and full speed (basically when sending traffic t...
by biomesh
Sun Apr 24, 2022 3:11 pm
Forum: RouterBOARD hardware
Topic: Problems with Temp. on CRS328
Replies: 8
Views: 891

Re: Problems with Temp. on CRS328

Make sure you reference

https://wiki.mikrotik.com/wiki/MikroTik ... patibility

Also note that 10gbaseT sfp+ devices can generate a lot of heat

https://wiki.mikrotik.com/wiki/S%2BRJ10 ... l_guidance
by biomesh
Sun Apr 24, 2022 3:05 pm
Forum: RouterBOARD hardware
Topic: Problems with Temp. on CRS328
Replies: 8
Views: 891

Re: Problems with Temp. on CRS328

Are the same type of sfp/sfp+ modules installed in both devices?

The temp reading (not cpu temp) on a number of switch models comes from the sfp/sfp+ modules themselves.
by biomesh
Fri Apr 22, 2022 3:13 pm
Forum: General
Topic: Yet another changelog thread
Replies: 52
Views: 2328

Re: v7.2.1 [stable] is released!

I think it is hilarious that gdanov thinks software companies will always provide full details of fixed bugs. I have worked for a global software company for over 20 years in a support role and found that while customers might think they are owed detailed answers on bugs/defects, it really depends o...
by biomesh
Wed Apr 20, 2022 6:02 pm
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 84555

Re: v7.3beta [testing] is released!

Is
*) ipsec - fixed IPsec IRQ initialization on startup on TILE;

Related to random high cpu seen on startup on TILE that shows as "networking" when using profile?
by biomesh
Wed Apr 20, 2022 6:14 am
Forum: Wireless Networking
Topic: WiFi with Apple Products
Replies: 13
Views: 5767

Re: WiFi with Apple Products

I would disable wpa2-eap and set the group key update to at least an hour (maybe more)
by biomesh
Tue Apr 19, 2022 11:50 pm
Forum: Wireless Networking
Topic: WiFi with Apple Products
Replies: 13
Views: 5767

Re: WiFi with Apple Products

You are better off posting an export of your config.
by biomesh
Tue Apr 19, 2022 7:41 pm
Forum: General
Topic: How bad is ROS for SMB sharing on a spare router?
Replies: 15
Views: 859

Re: How bad is ROS for SMB sharing on a spare router?

Well, you can mention to her .. usually she's the one doing flushing :-P Well clearly she doesnt want to go to bed next to someone with soap in their hair!!. Out of curiosity, how many flushes does it take to get all the shampoo out?? I used to joke with my kids about using the "toilet twirl&q...
by biomesh
Tue Apr 19, 2022 6:19 pm
Forum: General
Topic: How bad is ROS for SMB sharing on a spare router?
Replies: 15
Views: 859

Re: How bad is ROS for SMB sharing on a spare router?

Think of it this way:

How bad is it to clean your dishes/laundry in your toilet?

Can you do it - yes
Should you do it - no
by biomesh
Sat Apr 16, 2022 3:22 pm
Forum: Beginner Basics
Topic: 1st "complex" routerOS build issue
Replies: 5
Views: 585

Re: 1st "complex" routerOS build issue

If you do actually use capsman on such a slow device as a crs112, I world suggest not using capsman forwarding.
by biomesh
Fri Apr 15, 2022 5:31 pm
Forum: RouterBOARD hardware
Topic: CCR1009-7G-1C-1S+ very High CPU usage
Replies: 6
Views: 1190

Re: CCR1009-7G-1C-1S+ very High CPU usage

Get a supout and submit it to support. I have seen this a few times, but I can't reproduce the issue at will.
by biomesh
Fri Apr 15, 2022 5:44 am
Forum: Beginner Basics
Topic: CRS 112 Switch Configure
Replies: 1
Views: 311

Re: CRS 112 Switch Configure

Post an export of your config so that members can see what needs to be fixed.
by biomesh
Tue Apr 05, 2022 6:57 pm
Forum: General
Topic: Which product can support at least 200 hotspot users?
Replies: 16
Views: 1181

Re: Which product can support at least 200 hotspot users?

The SMIPS devices are for very light use / lab / toy use. Don't expect it to do much, especially with 32MB RAM.
by biomesh
Tue Apr 05, 2022 5:22 pm
Forum: General
Topic: Which product can support at least 200 hotspot users?
Replies: 16
Views: 1181

Re: Which product can support at least 200 hotspot users?

But I think the OP wants to build a network for 200 people for $25 USD. Isn't the cheapest way the best way? :lol:
by biomesh
Tue Apr 05, 2022 4:49 pm
Forum: Announcements
Topic: Missing RouterOS configuration after a reboot on very rare occasions [SOLVED]
Replies: 73
Views: 20295

Re: Missing RouterOS configuration after a reboot on very rare occasions [SOLVED]

They key question here: HOW did you get to that 7.2rc7 version ? Coming from ROS6 OR ROS7 <7.1 and then upgrade upgrade upgrade ? Or netinstall from a version >=7.1 and then moving on to 7.2rc7 ?? I am going to assume the first option. And then it DOES apply, if I understood it well. Strods did not...
by biomesh
Mon Apr 04, 2022 3:24 pm
Forum: General
Topic: https://support.mikrotik.com/ provides SSL_ERROR_BAD_CERT_DOMAIN
Replies: 10
Views: 649

Re: https://support.mikrotik.com/ provides SSL_ERROR_BAD_CERT_DOMAIN

Since this is a dns, web server or reverse proxy configuration issue, I would open a ticket to get someone internally to fix.
by biomesh
Mon Apr 04, 2022 3:08 pm
Forum: General
Topic: Slow speed on 10G ports
Replies: 2
Views: 473

Re: Slow speed on 10G ports

If you are running the bandwidth tests on the devices themselves that is the issue. This is primarily a switch and the cpu will get overloaded from generating the traffic. Normally you will setup two devices (destop, laptop, etc) to run bandwidth test and have the switch "between" the two ...
by biomesh
Fri Mar 25, 2022 12:14 am
Forum: General
Topic: DHCP tftp option for Grandstream provisioning [SOLVED]
Replies: 14
Views: 2544

Re: DHCP tftp option for Grandstream provisioning [SOLVED]

Option 66 is tftp server name not tftp server address(option 150). Using that option decodes correctly in wireshark when using a URL. You can use 'https://192.168.1.1:8090' s'https://192.168.1.1:8090' I would use the packet sniffer from the router to make sure it is being sent. If wireshark decodes ...
by biomesh
Thu Mar 24, 2022 8:08 pm
Forum: General
Topic: DHCP tftp option for Grandstream provisioning [SOLVED]
Replies: 14
Views: 2544

Re: DHCP tftp option for Grandstream provisioning [SOLVED]

Why are you using a http url for a tftp address? RFC5859 states this needs to be an IP address (or multiple IP addresses) not a URL. You need to convert each octet of the IP address to HEX and then set the option. For instance if I have two tftp servers: 192.168.6.1 and 10.1.1.1 it would be: 0xC0A80...
by biomesh
Thu Mar 24, 2022 7:23 pm
Forum: General
Topic: Help! 3011 Capped at 150Mbps
Replies: 9
Views: 1326

Re: Help! 3011 Capped at 150Mbps

Looking at the block diagram, eth1-eth5 has access to both cpus. You have a module in sfp1 (looing at the comments on the interface at least) which means sfp1 and eth6-eth10 only have access to one cpu core. You could try to move the interfaces around to see if that helps performance. You don't stat...
by biomesh
Thu Mar 24, 2022 5:17 am
Forum: Beginner Basics
Topic: 10Gbit network and internet [SOLVED]
Replies: 2
Views: 1321

Re: 10Gbit network and internet [SOLVED]

The crs305 is primarily a switch with some l3 features. With version 7 you can get some l3 hardware offloading of the routing, but that device does not support offloading of fasttrack or nat. Due to this limitation, your speeds, if you plan on using a firewall would be pretty low. You could try a cr...
by biomesh
Thu Mar 10, 2022 5:28 pm
Forum: General
Topic: RouterOS 7 Bridge VLAN/DHCP client issue after upgrade
Replies: 22
Views: 3875

Re: RouterOS 7 Bridge VLAN/DHCP client issue after upgrade

Here are the relevant snippets: /interface bridge add admin-mac=AA:BB:CC:DD:EE:FF auto-mac=no name=bridge1 priority=0x2000 \ pvid=75 vlan-filtering=yes /interface bridge vlan add bridge=bridge1 tagged=sfp-sfpplus1 untagged=ether24,bridge1 vlan-ids=75 /ip dhcp-client add interface=bridge1 On this dev...
by biomesh
Thu Mar 10, 2022 2:25 pm
Forum: General
Topic: RouterOS 7 Bridge VLAN/DHCP client issue after upgrade
Replies: 22
Views: 3875

Re: RouterOS 7 Bridge VLAN/DHCP client issue after upgrade

I have used the dhcp client/bridge combo for quite some time on crs3xx switches. It worked flawlessly in the 6.x and 7.x versions until 7.2rc2/3. I reported the issue with support and in my report pointed out that switching to tagged/vlan interface config did indeed work. Both methods have their use...
by biomesh
Sun Feb 20, 2022 8:07 am
Forum: General
Topic: CCR2004-16G-2S+ NAT rules are flaky and often do not work [SOLVED]
Replies: 5
Views: 976

Re: CCR2004-16G-2S+ NAT rules are flaky and often do not work [SOLVED]

Post your config if you want good feedback and not guesses.
by biomesh
Tue Feb 15, 2022 1:54 pm
Forum: Wireless Networking
Topic: Wi-Fi issue
Replies: 20
Views: 2859

Re: Wi-Fi issue

I would try local forwarding as you aren't using a super powerful device as a capsman server.
This would be in your data path config.
by biomesh
Sun Feb 13, 2022 2:53 pm
Forum: Announcements
Topic: v7.1.2 is released!
Replies: 127
Views: 31597

Re: v7.1.2 is released! => CCR1009 stuck in boot loop

Learning the hard way.... Post Mortem analysis: Press any key within 2 seconds to enter setup.. loading kernel... OK setting up elf image... OK jumping to kernel code Could not mount ubifs/yaffs filesystem: No such device This just means you need to netinstall. This is a random issue seen at least ...
by biomesh
Sun Feb 13, 2022 2:46 pm
Forum: General
Topic: TILE Broken After Rollback from 7.1.2 to 7.1.1
Replies: 3
Views: 624

Re: TILE Broken After Rollback from 7.1.2 to 7.1.1

When you see Could not mount ubifs/yaffs filesystem This means you need to netinstall. I had this happen on my ccr1009 during one of the 7.x updates - the rest of the 7.x updates were fine. Imo, it looks like something is corrupting the partition/partition table. In my case it was 7.2rc2 to 7.2rc3. ...
by biomesh
Wed Feb 02, 2022 11:12 pm
Forum: General
Topic: Trouble with Netinstall using Linux
Replies: 6
Views: 1352

Re: Trouble with Netinstall using Linux

Does it run correctly without using sudo? It runs fine on a Linux VM in my lab using root.
by biomesh
Wed Feb 02, 2022 4:13 pm
Forum: General
Topic: Trouble with Netinstall using Linux
Replies: 6
Views: 1352

Re: Trouble with Netinstall using Linux

The netinstall binary is compiled for intel architectures (i686/x86_64) and won't run on arm devices, like a Raspberry PI.
by biomesh
Fri Jan 28, 2022 8:01 pm
Forum: Announcements
Topic: v7.2rc2 and v7.2rc3 is released!
Replies: 222
Views: 74556

Re: v7.2rc2 and v7.2rc3 is released!

Had an issue with the upgrade ccr1009 - the nand /filesystem was corrupt and had to netinstall. I also was able to duplicate the issue with high utilization on the ccr1009 with regards to l2tp/ipsec. I had no issues with the netinstall/reimport with the exception of the certs, which is to be expecte...
by biomesh
Fri Jan 28, 2022 3:20 pm
Forum: Announcements
Topic: v7.2rc2 and v7.2rc3 is released!
Replies: 222
Views: 74556

Re: v7.2rc2 is released!

On my crs3xx devices seems to have broken access to my management interfaces (dhcp client on the bridge). The switches work but I can't manage them except through a console cable. ccr1009, cap ac, crs112, and chr working fine. I think this has to do with some of the changes to vlan filtering. **mayb...
by biomesh
Sun Jan 23, 2022 7:24 pm
Forum: General
Topic: Frequent reboots of hAP ac2 [SOLVED]
Replies: 24
Views: 4219

Re: Frequent reboots of hAP ac2 [SOLVED]

Have you tried a different power supply (swap the one with the bad device with one of the good ones) or maybe netinstalled the device?

It could be some sort of nand/flash issue and that it why I mentioned netinstall.
by biomesh
Wed Jan 19, 2022 3:16 pm
Forum: General
Topic: CCR1009 CPU load 100%
Replies: 11
Views: 2809

Re: CCR1009 CPU load 100%

An insecure router can remain that way until it is compromised.

If load has not changed going to or through the server, outside of a hardware failure(which this does not seem too be the case) then you should really start to closely look at the config.
by biomesh
Tue Jan 18, 2022 8:21 pm
Forum: General
Topic: CCR1009 CPU load 100%
Replies: 11
Views: 2809

Re: CCR1009 CPU load 100%

If you can't post the export you should deal with mikrotik support only. Since this is a user forum we can only help if we have actual examples/exports to look at.
by biomesh
Fri Jan 07, 2022 12:13 am
Forum: General
Topic: Wireguard Speed and CPU
Replies: 7
Views: 5200

Re: Wireguard Speed and CPU

Using iperf3 and my ccr1009 and wireguard I average 450Mbps at ~50% cpu. This is on 7.2rc1.
by biomesh
Wed Jan 05, 2022 3:35 pm
Forum: RouterBOARD hardware
Topic: Number of CPU cores on CRS3xx
Replies: 13
Views: 4681

Re: Number of CPU cores on CRS3xx

Those with dual core support were a different chipset 98dx82xx series vs 98dx3236.

My guess is that kernel support for the 98dx3236 was not complete with the old kernel in 6x
by biomesh
Tue Jan 04, 2022 5:53 pm
Forum: RouterBOARD hardware
Topic: Number of CPU cores on CRS3xx
Replies: 13
Views: 4681

Re: Number of CPU cores on CRS3xx

According to the following PDF, they are dual core. I am guessing the updated kernel in v7 allowed for the use of both cores vs the v6 kernel.

https://wifimag.ro/pdf/Prestera_98DX3336_pb.pdf
by biomesh
Fri Dec 31, 2021 2:55 pm
Forum: General
Topic: You've got to be kidding me. [SOLVED]
Replies: 18
Views: 2537

Re: You've got to be kidding me. [SOLVED]

16M of flash is really too small no matter what. I was trying to point out that the smips devices have more issues than the rest due to limited flash and memory. Outside of the smips devices I have not had issues upgrading 6.x. Going to 7.x I had issues but that is because I used separate packages. ...
by biomesh
Fri Dec 31, 2021 2:21 pm
Forum: General
Topic: You've got to be kidding me. [SOLVED]
Replies: 18
Views: 2537

Re: You've got to be kidding me. [SOLVED]

While I think the minimum amount of flash should be higher 64M or 128M and Ram should start at 128M, this would increase the cost of the devices. In your case you reference the hap light which is basically the cheapest device mt sells (along with the hap mini) at $20 usd. It only has 16M of flash - ...
by biomesh
Thu Dec 30, 2021 6:03 pm
Forum: Beginner Basics
Topic: 1GB Fiber Internet, only 300MB via CRS309
Replies: 5
Views: 1774

Re: 1GB Fiber Internet, only 300MB via CRS309

You are using it as a router, generally not a good idea for a switch. You might get better performance using the l3hw offloading on this device with ros 7 (which you are using)

https://help.mikrotik.com/docs/display/ ... Offloading
by biomesh
Thu Dec 30, 2021 3:09 pm
Forum: Beginner Basics
Topic: 1GB Fiber Internet, only 300MB via CRS309
Replies: 5
Views: 1774

Re: 1GB Fiber Internet, only 300MB via CRS309

If it's only used for switching it should not be hitting the CPU at all. If you get high CPU during the tests, then you have a configuration issue and you should post an export of your config. If you are using it for routing, well, this might be the best you will get as this is primarily a switch wi...
by biomesh
Wed Dec 29, 2021 7:26 pm
Forum: RouterBOARD hardware
Topic: hAP ac3 Block Diagram Discrepency
Replies: 3
Views: 3080

Re: hAP ac3 Block Diagram Discrepency

All of the other devices with that chipset - hapac2/capac/wap ac show it as part of the SoC as well.
by biomesh
Tue Dec 28, 2021 9:52 pm
Forum: Wireless Networking
Topic: CAPSMAN and WMM
Replies: 6
Views: 3411

Re: CAPSMAN and WMM

If you use capsman, then some settings are enabled by default and some cannot be changed. As for WMM it is enabled when using capsman. I am unsure why you would not want to use it.
by biomesh
Mon Dec 27, 2021 2:24 am
Forum: RouterBOARD hardware
Topic: CCR 1009 and SD card
Replies: 11
Views: 10540

Re: CCR 1009 and SD card

There is an open bug with sd cards on the ccr1009 models (at least) on 7.x
by biomesh
Wed Dec 22, 2021 6:57 pm
Forum: RouterOS beta and rc versions
Topic: Ipv6 preferred pool
Replies: 5
Views: 1917

Re: Ipv6 preferred pool

It could - just a bit more work on the programming side since the ::1:0:0:0:1/64 etc would need to calculate the source PD and then determine how to apply the value. With a /48 it could be a literal assignment. Perhaps the command could be written as ::{1}:0:0:0:1/64 etc to determine if it is a lite...
by biomesh
Wed Dec 22, 2021 5:02 pm
Forum: RouterOS beta and rc versions
Topic: Ipv6 preferred pool
Replies: 5
Views: 1917

Re: Ipv6 preferred pool

I think that would help if you have a static (or fairly static) larger delegation. In my case I get a /60 from comcast and it can change (not often, but it can), so the /48 prefix example would not work in my situation. I am just looking for delegation stickiness when assigning addresses/prefixes fr...
by biomesh
Wed Dec 22, 2021 3:14 pm
Forum: RouterOS beta and rc versions
Topic: Ipv6 preferred pool
Replies: 5
Views: 1917

Ipv6 preferred pool

I submitted the following as a feature request. Any feedback, support or improvements to the idea are welcome. When ipv6 is used with a pd and addresses are assigned to interfaces with the from-pool option, the assignment seems totally random. Is there a way there could be a preferred address option...
by biomesh
Tue Dec 21, 2021 6:14 pm
Forum: Announcements
Topic: v7.2rc1 is released!
Replies: 240
Views: 149823

Re: v7.2rc1 is released!

This version broke communication between a crs318 and a crs317 with a SFP+ 10Gbase-T adapters (same adapter type on both ends). It works fine with 7.1 and 7.1.1.
by biomesh
Sat Dec 11, 2021 2:45 pm
Forum: RouterOS beta and rc versions
Topic: Speed drop after update to 7.1stable [SOLVED]
Replies: 39
Views: 13600

Re: Speed drop after update to 7.1stable [SOLVED]

Did you disable your layer 7 rule as well for your test?
by biomesh
Sun Dec 05, 2021 7:06 pm
Forum: General
Topic: Mikrotik equipment to the new home
Replies: 20
Views: 3438

Re: Mikrotik equipment to the new home

I mean if you go to the FCC website... They have year downs of the units. And the boards are stamped as Emplus.
I didn't see it on the eap660HD pdfs, but the quality is not that good. The ethernet/power/reset layout on the tp-link is also different compared to the engenius/netgear models.
by biomesh
Sun Dec 05, 2021 2:58 pm
Forum: General
Topic: Mikrotik equipment to the new home
Replies: 20
Views: 3438

Re: Mikrotik equipment to the new home

TP-Link and Eugenius clearly went to the same OEM this time around. Looks like Emplus WAP380 is definitely the Eugenius WAP.
Are you thinking of the Netgear APs? They are basically the engenius APs but with less RAM.
by biomesh
Sat Dec 04, 2021 11:20 pm
Forum: Announcements
Topic: v7.1 is released!
Replies: 785
Views: 191174

Re: v7.1 is released!

There is problem with sending e-mails from router in Netwatch tool (Up and Down scripts) Sending from Terminal is OK /tool e-mail send to="someone@somedomain.tld" subject="Failover is UP" body="Main ISP failed..." tls=yes The same command in Netwatch, tab Up and Down s...
by biomesh
Fri Dec 03, 2021 5:34 pm
Forum: Announcements
Topic: v7.1 is released!
Replies: 785
Views: 191174

Re: v7.1 [testing] is released!

Looks like I lost access to SD cards on my CCR1009 with this release. My existing sd card is not visible and a new card is also not visible.
by biomesh
Fri Dec 03, 2021 4:57 pm
Forum: Announcements
Topic: v7.1 is released!
Replies: 785
Views: 191174

Re: v7.1 [testing] is released!

I saw my ccr1009 had 95+% utilization on 4 cores (represented as "networking" in the profile tool) and l2tp/ipsec (looked more like an ipsec issue) would not connect as a client. A reboot had everything back to normal. I did not get a supout.rif, but I will get one if I see the issue again.
by biomesh
Fri Dec 03, 2021 2:14 pm
Forum: Announcements
Topic: v7.1 is released!
Replies: 785
Views: 191174

Re: v7.1 [testing] is released!

On devices with only 16M of flash I always use the minimum packages needed. The upgrade worked on most devices, but any with the wireless package installed it failed with the space error. When the device is wired, this is just an extra reboot to remove the package and reboot then upgrade. For device...
by biomesh
Sun Nov 21, 2021 3:00 am
Forum: Containers
Topic: v7.1rc3 adds container support
Replies: 493
Views: 131917

Re: v7.1rc3 adds Docker (TM) compatible container support

Either rebuild the image/container or map it to persistent storage on the router.
by biomesh
Thu Nov 18, 2021 3:57 pm
Forum: General
Topic: link up/down cause
Replies: 4
Views: 846

Re: link up/down cause

It could be something else, but linking at 10M half duplex is highly suspicious of a bad cable.
by biomesh
Thu Nov 18, 2021 1:38 pm
Forum: General
Topic: No audio on sip calls over VPN
Replies: 8
Views: 2007

Re: No audio on sip calls over VPN

Check the values for
Settings -> asterisk sip settings -> general sip settings -> nat settings -> local networks

If your network is not listed here, it will be precessed as at nat connection, even if it is not.

One of the symptoms of mis configured nat settings is no audio.
by biomesh
Wed Nov 17, 2021 11:35 pm
Forum: General
Topic: 100% CPU on MIPS 24kc V7.4
Replies: 5
Views: 1936

Re: 100% CPU on MIPS 24kc V7.4

Running winbox with windows with counters/statistics (like firewall or interface) will increase the CPU quite a bit. You are using one(if not the) slowest of the CPUs available on current hardware. I suggest closing all windows in your session and close /re-open winbox. Your CPU will most likely be ...
by biomesh
Tue Nov 16, 2021 2:09 pm
Forum: Beginner Basics
Topic: Problem with port isolation on crs326-24g-2s+rm
Replies: 11
Views: 2068

Re: Problem with port isolation on crs326-24g-2s+rm

I would start by only using one bridge and making sure all ports are hardware offloaded.

Normally by just having one bridge and all ports assigned to it will take care of it.
by biomesh
Fri Nov 12, 2021 5:01 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 140
Views: 41578

Re: Mikrotik router Hacked!!!

Scenario: Bob reads about this, Bob updates his unsecured router, Bob sets protected routerboot thinking at it as a security measure, confirms it with the press of the button. Pedro gets in Bobs unsecured router easily, sees the protected bootloader set, changes the reformat-hold-button and reforma...
by biomesh
Fri Nov 12, 2021 2:57 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 140
Views: 41578

Re: Mikrotik router Hacked!!!

Thanks Normis - great motivation to get people to upgrade!
by biomesh
Thu Nov 11, 2021 10:51 pm
Forum: General
Topic: which switch to choose for 1/2.5Gbps switching? [SOLVED]
Replies: 10
Views: 2733

Re: which switch to choose for 1/2.5Gbps routing? [SOLVED]

If you need 10 up to 10G ports then the CRS317 would be the best fit if you plan on using some 1G only SFP adapters or if you are going to use SFP+ DACs for some connections.

https://wiki.mikrotik.com/wiki/S%2BRJ10 ... l_guidance
by biomesh
Tue Nov 09, 2021 5:37 pm
Forum: General
Topic: CRS317 10G port to 1G speed issues [SOLVED]
Replies: 4
Views: 1015

Re: CRS317 10G port to 1G speed issues [SOLVED]

Set it a bit below, perhaps 900-920 Mbps. Basically run iperf tests until you see the retries drop to zero or almost zero for the correct value.
by biomesh
Tue Nov 09, 2021 5:34 pm
Forum: Beginner Basics
Topic: CRS309 Switch - cannot ping gateway or any other host
Replies: 17
Views: 2990

Re: CRS309 Switch - cannot ping gateway or any other host

The ccr1009 can route around 7-8 Gbps with or without a bridge involved. It really does not matter with the tests I have done in the past.
by biomesh
Tue Nov 09, 2021 2:02 pm
Forum: General
Topic: CRS317 10G port to 1G speed issues [SOLVED]
Replies: 4
Views: 1015

Re: CRS317 10G port to 1G speed issues [SOLVED]

Is the slowness only on the customers download/receiving speed but not the upload/send?

If so, I would set an egress rate limit on the port to see if that addresses the issue for you.
by biomesh
Fri Nov 05, 2021 3:11 pm
Forum: General
Topic: Mikrotik router Hacked!!!
Replies: 140
Views: 41578

Re: Mikrotik router Hacked!!!

It would be also interesting to see exports from what you call a good/clean config vs one that is hacked.
by biomesh
Tue Nov 02, 2021 6:30 pm
Forum: General
Topic: RouterBOARD 941-2nD V6.48.3 get 100% CPU after power down
Replies: 1
Views: 390

Re: RouterBOARD 941-2nD V6.48.3 get 100% CPU after power down

Run /tool/profile
and see what is taking up the CPU. If you have an export you can post that as well.
by biomesh
Tue Nov 02, 2021 1:16 pm
Forum: Wireless Networking
Topic: CAPsMAN error no supported Channels [SOLVED]
Replies: 7
Views: 4352

Re: CAPsMAN error no supported Channels [SOLVED]

Each radio can either be 5g or 2g. You need a separate provisioning rule/entry for each radio. This means a dual band device would need 2 separate rules.
by biomesh
Mon Oct 25, 2021 11:34 pm
Forum: General
Topic: RB951Ui-2HnD - Stuck on loop after upgrading to 6.49
Replies: 1
Views: 448

Re: RB951Ui-2HnD - Stuck on loop after upgrading to 6.49

I always recommend the following when using a device with usb but no console port:

https://mikrotik.com/product/woobm
by biomesh
Sat Oct 16, 2021 2:39 pm
Forum: Wireless Networking
Topic: hap ac3 - worse than hap lite?
Replies: 15
Views: 3652

Re: hap ac3 - worse than hap lite?

Capsman at this time, cannot manage radios using the wave2 package.
by biomesh
Thu Oct 14, 2021 3:34 am
Forum: Beginner Basics
Topic: Why is my CAPsMAN network not as good as I hope for?
Replies: 25
Views: 4992

Re: Why is my CAPsMAN network not as good as I hope for?

If it's mainly just the apple devices, try to increase the lease time. Others have reported issues with shorter lease times on apple devices.
by biomesh
Wed Oct 13, 2021 6:07 pm
Forum: Beginner Basics
Topic: Why is my CAPsMAN network not as good as I hope for?
Replies: 25
Views: 4992

Re: Why is my CAPsMAN network not as good as I hope for?

Generally speaking local-forwarding=no means all wifi traffic will be handled by the capsman server (via a bridge interface) and will be slower than with local-forwarding=yes - many times much slower. I have never heard of faster performance with local-forwarding=no unless you have something very od...
by biomesh
Tue Oct 12, 2021 7:24 pm
Forum: General
Topic: How to create IPv6 subnet with prefix delegation
Replies: 6
Views: 3989

Re: How to create IPv6 subnet with prefix delegation

Generally you would start with your dhcp client to get the prefixes and add them to a pool: /ipv6 dhcp-client add add-default-route=yes interface=wan pool-name=comcast_ipv6 prefix-hint=::/60 request=address,prefix use-peer-dns=no Then you just need to add an address to the the vlan interface that co...
by biomesh
Wed Oct 06, 2021 2:26 pm
Forum: General
Topic: Fans in CRS326-24G-2S+IN
Replies: 3
Views: 609

Re: Fans in CRS326-24G-2S+IN

The fan holes only fit 30x30 fans so that is your limitation. I ran then externally mounted from a USB power supply adapter for a while until I got tired of the sound. Not the most professional looking, but it works.
by biomesh
Wed Oct 06, 2021 12:57 am
Forum: General
Topic: Fans in CRS326-24G-2S+IN
Replies: 3
Views: 609

Re: Fans in CRS326-24G-2S+IN

The space available on the IN cases only allow for a 30x30 fan, which there are not as many choices as the fans for the RM version which allow for 40x40 fans. For the most part you are left with using fans for raspberry pis. These are generally cheap and can run 3.3v or 5v but are not very quiet.
by biomesh
Thu Sep 30, 2021 10:03 pm
Forum: General
Topic: CRS326 Rack ears [SOLVED]
Replies: 5
Views: 1171

Re: CRS326 Rack ears [SOLVED]

My CRS326 (IN version) has two small holes, not four and the holes are smaller and don't have any threads like any other rack capable mikrotik devices. Your best best is a shelf like stated above.
by biomesh
Mon Sep 27, 2021 11:19 pm
Forum: Beginner Basics
Topic: Why is my CAPsMAN network not as good as I hope for?
Replies: 25
Views: 4992

Re: Why is my CAPsMAN network not as good as I hope for?

As you can see from hes config above he did that, so did i, while you are right and old protocols are total performanse killers and cause problems, in this case its not helping. His config did not have those settings, thus the suggestion. Those are the settings I use with zero issues. I don't use a...
by biomesh
Mon Sep 27, 2021 10:05 pm
Forum: Beginner Basics
Topic: Why is my CAPsMAN network not as good as I hope for?
Replies: 25
Views: 4992

Re: Why is my CAPsMAN network not as good as I hope for?

I would set your 2ghz channels to 2ghz-onlyn or at least 2ghz-g/n. For 5ghz set it to 5ghz-n/ac. You could have issues negotiating the older protocols.
by biomesh
Fri Sep 24, 2021 7:49 pm
Forum: Wireless Networking
Topic: wifi devices hop between access points
Replies: 6
Views: 1467

Re: wifi devices hop between access points

If you have the APs spread out you could use the access list and have accept rules for those MAC addresses to each AP with a signal level that is really good i.e. (-50..120). This way if the device gets too far away from any one AP it will only connect to one of the APs. This won't help though if th...
by biomesh
Thu Sep 23, 2021 11:23 pm
Forum: Wireless Networking
Topic: Capsman WPA2 key for each device
Replies: 2
Views: 916

Re: Capsman WPA2 key for each device

Do they randomize the full mac address or just the last three octets (or something similar)? If part of the mac address is consistent between devices you could use the mac mask option to only have the rule to apply to certain mac address ranges. There is no way that I can see where you can limit the...
by biomesh
Thu Sep 23, 2021 11:11 pm
Forum: Beginner Basics
Topic: IPv6 help [SOLVED]
Replies: 15
Views: 2968

Re: IPv6 help [SOLVED]

I don't see an issue with your vlan config on the router, but you could have an issue with your switch. As for the IPv6 config, you really should not hard reference a prefix allocation unless you are 100% sure they are static as you will break your config easily. The default IPv6 address assignment ...
by biomesh
Wed Sep 22, 2021 2:18 pm
Forum: RouterBOARD hardware
Topic: NetPower 16p.... Rubbish PoE design. Workarounds?
Replies: 20
Views: 3452

Re: NetPower 16p.... Rubbish PoE design. Workarounds?

or is your NetPower 16P capable of delivering 48V while being powered at 24V ?
These devices don't have a way for you to select what the power source is for the switch itself. It will use the source with the highest voltage.
by biomesh
Wed Sep 22, 2021 2:09 pm
Forum: Wireless Networking
Topic: Client can connect to 5GHz only after disabling 802.11ac [SOLVED]
Replies: 17
Views: 4643

Re: Client can connect to 5GHz only after disabling 802.11ac [SOLVED]

Just a guess since there is no export, but the channels could be set to Auto and it's using a dfs channel. Some devices won't even attempt to look at anything in the dfs range.
by biomesh
Mon Sep 20, 2021 4:37 pm
Forum: RouterOS beta and rc versions
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 70111

Re: v7.1rc4 [development] is released!

Removing and re-adding the veth interface and container allowed it to start again. Containers should be able to start properly after an OS upgrade.
by biomesh
Mon Sep 20, 2021 3:09 pm
Forum: RouterOS beta and rc versions
Topic: v7.1rc4 [development] is released!
Replies: 276
Views: 70111

Re: v7.1rc4 [development] is released!

My chr test system can no longer start the container that worked on rc3. No debug log output at all.
by biomesh
Sun Sep 19, 2021 4:02 pm
Forum: General
Topic: CRS312-4C+8XG L2 VLAN slow performance [Fixed]
Replies: 8
Views: 1068

Re: CRS312-4C+8XG L2 VLAN slow performance, misconfiguration?

Run iperf tests through endpoints connected through the switch, not the bandwidth test on the switch itself.
by biomesh
Fri Sep 17, 2021 9:04 pm
Forum: Wireless Networking
Topic: I have enabled CAPs on 2.1GHz and can't enable it on 5GHz [SOLVED]
Replies: 5
Views: 1216

Re: I have enabled CAPs on 2.1GHz and can't enable it on 5GHz [SOLVED]

You can specify multiple capsman servers on a cap but it will only use one at a time.
by biomesh
Fri Sep 17, 2021 8:32 pm
Forum: Wireless Networking
Topic: I have enabled CAPs on 2.1GHz and can't enable it on 5GHz [SOLVED]
Replies: 5
Views: 1216

Re: I have enabled CAPs on 2.1GHz and can't enable it on 5GHz [SOLVED]

Click the down arrow next to that field to get another value to select wlan2.
by biomesh
Fri Sep 17, 2021 2:10 pm
Forum: RouterOS beta and rc versions
Topic: PLEASE MikroTik made NetInstall version for Docker....
Replies: 41
Views: 6188

Re: PLEASE MikroTik made NetInstall version for Docker....

The linux netinstall docs are here:

https://help.mikrotik.com/docs/display/ ... nsforLinux

I saw the segfaults, but I think it was before I exposed the ports in the container or I had something else misconfigured.
by biomesh
Fri Sep 17, 2021 4:33 am
Forum: General
Topic: Inconsistent static DHCP with SFP+/DAC
Replies: 4
Views: 780

Re: Inconsistent static DHCP with SFP+/DAC

Is the client Id the same in the lease? This is really the unique identifier and if you don't have one on the lease, it falls back to the Mac address.

I would just check to see if the device connected is trying to send a different client Id or let's say one with all zeros.
by biomesh
Thu Sep 16, 2021 10:38 pm
Forum: Wireless Networking
Topic: DIfferent access list for each Cap [SOLVED]
Replies: 6
Views: 1716

Re: DIfferent access list for each Cap [SOLVED]

It has nothing to do with roaming. It just has to do with the creation of the capsman interfaces. If you are going to use access rules for specific AP interfaces, then you will want "create enabled" vs "create dynamic enabled". I had capsman set with dynamic interfaces until I ne...
by biomesh
Thu Sep 16, 2021 2:24 pm
Forum: Wireless Networking
Topic: DIfferent access list for each Cap [SOLVED]
Replies: 6
Views: 1716

Re: DIfferent access list for each Cap [SOLVED]

Yes, just create access rules using the interface option. The first rule would be for the external AP(accept). If you have two radios then you would have two rules. Then underneath those you would have the rules for the internal aps, but for every accept rule, also add the signal range you are looki...
by biomesh
Thu Sep 16, 2021 3:20 am
Forum: General
Topic: CRS112 sw bridge to hw bridge
Replies: 5
Views: 1003

Re: CRS112 sw bridge to hw bridge

The best examples are in the wiki:

https://wiki.mikrotik.com/wiki/Manual:C ... s_examples

(tdw beat me by a few minutes)
by biomesh
Wed Sep 15, 2021 1:22 pm
Forum: RouterOS beta and rc versions
Topic: PLEASE MikroTik made NetInstall version for Docker....
Replies: 41
Views: 6188

Re: PLEASE MikroTik made NetInstall version for Docker....

I don't have a Mac os device, but normally with netinstall, the client address (-a) is on the same network as the server. When running on routeros docker, netinstall will fail to run if this is not correct.

So in your case it could be "-a 192.168.65.100"
by biomesh
Wed Sep 15, 2021 1:21 am
Forum: Containers
Topic: v7.1rc3 adds container support
Replies: 493
Views: 131917

Re: v7.1rc3 adds Docker (TM) compatible container support

about time someone tried to use nextdns. is it working well? sending client device names etc?
It works just like the nextdns client that I run on some raspberrypis - no problems at all.
by biomesh
Tue Sep 14, 2021 6:20 pm
Forum: General
Topic: CRS317 Switch VLAN
Replies: 20
Views: 1769

Re: CRS317 Switch VLAN

@Zacharias: 1) If you change the PVID, on switch2, you are effectively changing the vlan it is on and so it cannot communicate with it anymore, especially with vlan-filtering and ingress-filtering enabled 2) The traffic coming from the bridge (internal) what is affected by this setting - if you are ...
by biomesh
Tue Sep 14, 2021 3:45 pm
Forum: RouterOS beta and rc versions
Topic: PLEASE MikroTik made NetInstall version for Docker....
Replies: 41
Views: 6188

Re: PLEASE MikroTik made NetInstall version for Docker....

Well, unfortunately it does not work that way. I assumed that and spent a LOT of time on it. I could only get a bridged mode of 172.17.0.0/16 to work and not a bridged mode to my local network. Perhaps there is a way, but there is almost no docs on the feature as it is new. From what I have seen, on...
by biomesh
Tue Sep 14, 2021 2:55 pm
Forum: RouterOS beta and rc versions
Topic: PLEASE MikroTik made NetInstall version for Docker....
Replies: 41
Views: 6188

Re: PLEASE MikroTik made NetInstall version for Docker....

Getting netinstall to work in a container is not difficult when using host networking. When using bridge mode - which is the only mode I have seen on the examples for ROS it won't work. The container will reside in a 172.17.0.0/16 network and when you run netinstall you have to provide an ip address...
by biomesh
Mon Sep 13, 2021 11:15 pm
Forum: Containers
Topic: v7.1rc3 adds container support
Replies: 493
Views: 131917

Re: v7.1rc3 adds Docker (TM) compatible container support

Here is my config for the nextdns client for use on CHR. The nextdns client does have builds for ARM, so for those interested it would probably work there as well. Dockerfile: FROM debian:bullseye-slim RUN apt-get update && apt-get install -y apt-transport-https curl && \ curl -o /us...
by biomesh
Mon Sep 13, 2021 1:27 am
Forum: General
Topic: CRS317 Switch VLAN
Replies: 20
Views: 1769

Re: CRS317 Switch VLAN

For management, you can either set the pvid or create a vlan interface and assign it to the bridge. The DHCP client or IP address would be set on the bridge when using pvid but would be handled via the vlan interface otherwise.
by biomesh
Sat Sep 11, 2021 2:46 pm
Forum: General
Topic: CRS317 Switch VLAN
Replies: 20
Views: 1769

Re: CRS317 Switch VLAN

You only have vlan 201 defined on one port. It will not get switched to any other port. You would have to tag another port or set the pvid on another port to 201. If you are trying to route between vlans, this is best done on your router, not the switch. To route with this switch you would need ros7...
by biomesh
Thu Sep 09, 2021 5:12 pm
Forum: RouterOS beta and rc versions
Topic: v7.1rc3 [development] is released!
Replies: 172
Views: 42633

Re: v7.1rc3 [development] is released!

I was trying to add a bridge to my CHR (running on vmware) and once I set auto-mac=no (with a unique MAC address) then ARP would stop working. Setting auto-mac=yes instantly reverted back to normal operation. A reboot did not resolve the issue. I have a hap ac2 running the same version with auto-mac...
by biomesh
Thu Sep 09, 2021 1:17 pm
Forum: RouterBOARD hardware
Topic: The big CCR2004 reboot thread (was 2004 hardware issues?)
Replies: 448
Views: 121824

Re: The big CCR2004 reboot thread (was 2004 hardware issues?)

The 2004-16G-2S+ uses different hardware (the same switch chip in the 5009) which is not in the original 2004. Until more people buy the 16G-2S+ version it will be hard to say what the real issue is with these devices.
by biomesh
Thu Sep 09, 2021 1:06 am
Forum: RouterBOARD hardware
Topic: CRS112 switch low throughput [SOLVED]
Replies: 6
Views: 3045

Re: CRS112 switch low throughput [SOLVED]

1) Don't run a speedtest / bandwidth test directly on the devices themselves. These are very slow CPU - 400Mhz. Instead run iperf tests on two devices connected to the switches/routers. 2) If you just connect via winbox, and don't have any interface window open, CPU utilization is under 10%. if you ...
by biomesh
Wed Sep 08, 2021 6:24 am
Forum: RouterBOARD hardware
Topic: Netpower 16P max PoE out contradictory
Replies: 6
Views: 2426

Re: Netpower 16P max PoE out contradictory

From what I see on mine, it draws power from the highest voltage source, not the one with the least load.
by biomesh
Tue Sep 07, 2021 2:06 pm
Forum: General
Topic: mynetname.net is suspended
Replies: 80
Views: 38198

Re: mynetname.net is suspended

Is there a way for these names that are reported as having malware, etc to be disabled via a blacklist? This way if the person running one of these devices emails support they can have their devices validated before it is re enabled. This would prevent the whole domain from being blocked. (Note: I u...
by biomesh
Sun Aug 29, 2021 5:00 pm
Forum: Beginner Basics
Topic: Can't get a simple bridge vlan to work
Replies: 9
Views: 1221

Re: Can't get a simple bridge vlan to work

Compare your IP address commands. Your vlan60 is missing the subnet mask.
by biomesh
Sat Aug 28, 2021 3:16 pm
Forum: Beginner Basics
Topic: Need help with IP firewall filter schedule
Replies: 3
Views: 783

Re: Need help with IP firewall filter schedule

The rule is flagged as inactive and invalid since the time range is not in the current time. It will become active during that specific time range. If you see this during the actual time you want it to be active, you might want to change your time range. I would start by just changing 0s to 1s to se...
by biomesh
Sat Aug 28, 2021 12:05 am
Forum: General
Topic: CRS317 running hot [SOLVED]
Replies: 7
Views: 1029

Re: CRS317 running hot [SOLVED]

My CRS317 with ambient temp at 25C and running 6.48.4 (with updated firmware) has a cpu temp of 47C and overall temp of 51C. This includes one 10GbaseT copper adapter and 9 SFP+ DACs. The CPU is between 2-3% utilization. My fans never run (except on reboot of course) I have a feeling that something ...
by biomesh
Tue Aug 24, 2021 11:41 pm
Forum: Wireless Networking
Topic: Wifi sucks in an outside garage
Replies: 16
Views: 2335

Re: Wifi sucks in an outside garage

You might be able, depending on coverage area and distance to the garage, use a wireless wire kit to connect the house and garage and use whatever AP you want in the garage for 2.4/5 g access.
by biomesh
Tue Aug 24, 2021 11:38 pm
Forum: Wireless Networking
Topic: Wifi sucks in an outside garage
Replies: 16
Views: 2335

Re: Wifi sucks in an outside garage

msatter's comment was related to your topic for this post
by biomesh
Tue Aug 24, 2021 4:40 pm
Forum: Wireless Networking
Topic: Wifi sucks in an outside garage
Replies: 16
Views: 2335

Re: Wifi sucks in an outside garage

You need a level 4 license for the device to act as an AP.

https://wiki.mikrotik.com/wiki/Manual:L ... nse_Levels
by biomesh
Tue Aug 24, 2021 1:27 pm
Forum: Announcements
Topic: v6.48.4 [stable] is released!
Replies: 68
Views: 67253

Re: v6.48.4 [stable] is released!

I have the Ccr1009-8g-1s-1s+PC and those shipped with 24V power bricks. With .4, the voltage is showing ~40V instead of ~24V.
by biomesh
Mon Aug 23, 2021 10:33 pm
Forum: Announcements
Topic: v6.48.4 [stable] is released!
Replies: 68
Views: 67253

Re: v6.48.4 [stable] is released!

I have a CCR1009 with the incorrect voltage reported, like post #5. Seems to only affect tile based devices. All of my arm or mipsbe devices with voltage monitoring are correct.
by biomesh
Mon Aug 23, 2021 5:15 am
Forum: RouterOS beta and rc versions
Topic: Roku Ultra disables switch chip on RB4011
Replies: 1
Views: 939

Re: Roku Ultra disables switch chip on RB4011

On the bridge port for that device, set edge=yes (under stp) if using winbox.

I had issues with another switch and the Roku with (r)stp.

This was only with newer rokus btw.
by biomesh
Sun Aug 22, 2021 9:46 pm
Forum: Beginner Basics
Topic: IPv6 DNS
Replies: 9
Views: 6192

Re: IPv6 DNS

Yes, only the ipv6 address will be sent via rdnss.
by biomesh
Sun Aug 22, 2021 4:29 am
Forum: Beginner Basics
Topic: IPv6 DNS
Replies: 9
Views: 6192

Re: IPv6 DNS

Ok, you can skip that step then. Just run through the steps in the first sentence. You should see the rdnss value in radvdump.
by biomesh
Sun Aug 22, 2021 2:28 am
Forum: Beginner Basics
Topic: IPv6 DNS
Replies: 9
Views: 6192

Re: IPv6 DNS

Select the advertise DNS option on your nd interface entry and add your local ipv6 address to your Dns server config. If you don't want to use your Dns server from your ISP, set "use peer DNS" to no on your ipv6 DHCP client entry.
by biomesh
Sat Aug 21, 2021 2:45 pm
Forum: Beginner Basics
Topic: IPv6 DNS
Replies: 9
Views: 6192

Re: IPv6 DNS

You can definitely set the nd rdnss values in Ros 6.x with the DNS server option(not using DHCP options). I don't run v7 and I verified my config. Perhaps v7 adds additional functionality for dhcpv6.
by biomesh
Sat Aug 21, 2021 5:26 am
Forum: Beginner Basics
Topic: IPv6 DNS
Replies: 9
Views: 6192

Re: IPv6 DNS

You need to make sure you have an ipv6 address assigned to an interface and have the DNS server set to allow remote requests. If you want rdnss values to be sent in the neighbor advertisments, you need to add the ipv6 address to the DNS server list of DNS servers (settings) and set the ipv6 nd inter...
by biomesh
Thu Aug 19, 2021 2:39 pm
Forum: Beginner Basics
Topic: Help configuring admin vlan on cAP ac [SOLVED]
Replies: 13
Views: 1741

Re: Help configuring admin vlan on cAP ac [SOLVED]

If you want two DHCP clients on the same device, make sure both are not set to add the default route. Also, if you are tagging traffic outbound for management interface, this is normally done with vlan interfaces assigned to the bridge that includes ether1 (your uplink). The DHCP clients would then ...
by biomesh
Wed Aug 18, 2021 3:28 pm
Forum: Wireless Networking
Topic: wifi network interruptions since last update round
Replies: 4
Views: 1039

Re: wifi network interruptions since last update round

I have not had any of those issues with any specific version listed. If you have rstp/stp enabled on a bridge where your wireless interface is, that could be the issue due to the connection changes.
by biomesh
Wed Aug 18, 2021 2:37 pm
Forum: Wireless Networking
Topic: wifi network interruptions since last update round
Replies: 4
Views: 1039

Re: wifi network interruptions since last update round

I would not go with beta software unless there is an actual feature or fix you are looking for. As for the actual problem, it sounds like rstp/stp is enabled on bridges on some(or all) of your devices. If disabling that doesn't work, then post the exports from your devices, so we can look for issues...
by biomesh
Wed Aug 18, 2021 2:24 pm
Forum: Beginner Basics
Topic: Router disappears after running script for system reset-configuration
Replies: 10
Views: 1182

Re: Router disappears after running script for system reset-configuration

The process works, you just have at least one issue in your script. I see you have your lan IP address assigned to ether1, not the bridge interface. It looks like all interfaces are assigned to the bridge, which won't work if you actually want this to work correctly (as a router). If you were just c...
by biomesh
Sat Aug 14, 2021 3:25 pm
Forum: General
Topic: Pass ISP DHCP to PFsense 2 Mikrotik switches away ?
Replies: 3
Views: 1456

Re: Pass ISP DHCP to PFsense 2 Mikrotik switches away ?

Set the pvid of the port connected to the internet device(modem) to the vlan Id you want to send to your router. Ideally you want to have this port be untagged traffic only on the modem connected port(you don't want other vlans being sent out this port). This vlan tagged traffic should then be set o...
by biomesh
Tue Aug 10, 2021 9:13 pm
Forum: General
Topic: Management access w/out VLAN filtering
Replies: 2
Views: 626

Re: Management access w/out VLAN filtering

This will work. The bridge is only needed if multiple ports need access to the vlan. On this config, only ether5 is part of vlan 99.
by biomesh
Tue Aug 10, 2021 8:40 pm
Forum: Beginner Basics
Topic: Routing Between Two ports CRS112-8G-4S-IN
Replies: 3
Views: 1132

Re: Routing Between Two ports CRS112-8G-4S-IN

This is really a switch and won't route very well due to the very weak CPU (400MHz mips). I would suggest following the wiki examples for VLANs and sending those two vlans to your router and let it handle the routing for you. https://wiki.mikrotik.com/wiki/Manual:CRS1xx/2xx_series_switches_examples ...
by biomesh
Mon Aug 09, 2021 10:01 pm
Forum: General
Topic: any trick to make cap client keep settings while capsman is down?
Replies: 21
Views: 2654

Re: any trick to make cap client keep settings while capsman is down?

I don't think this is how capsman was designed to operate. You can have a cloud controller, but if you don't want to lose your APs, then just add a local capsman server that is enabled/disabled with netwatch. If it can't ping the cloud capsman server, it would enable the local capsman server and if ...
by biomesh
Sat Aug 07, 2021 3:07 pm
Forum: General
Topic: Looking for recommendation [SOLVED]
Replies: 9
Views: 1237

Re: Looking for recommendation [SOLVED]

Hex Poe does not have wifi. A good choice would be a hap ac2.
by biomesh
Sat Aug 07, 2021 2:34 pm
Forum: General
Topic: How can I deep debug a 100% CPU load [SOLVED]
Replies: 6
Views: 1545

Re: How can I deep debug a 100% CPU load [SOLVED]

/tool profile
Will be your best help with this.

By chance do you have capsman forwarding enabled? This is a low end CPU and it would be no surprise to see such an issue there.
by biomesh
Wed Aug 04, 2021 9:25 pm
Forum: Wireless Networking
Topic: Devices unable to connect - client facing [SOLVED]
Replies: 22
Views: 7290

Re: Devices unable to connect - client facing [SOLVED]

You don't even need to have a rates entry - it will use the defaults if none are defined. /caps-man channel add band=2ghz-onlyn control-channel-width=20mhz extension-channel=disabled \ frequency=2412 name=2ch1 tx-power=10 add band=2ghz-onlyn control-channel-width=20mhz extension-channel=disabled \ f...
by biomesh
Wed Aug 04, 2021 4:06 am
Forum: Wireless Networking
Topic: Devices unable to connect - client facing [SOLVED]
Replies: 22
Views: 7290

Re: Devices unable to connect - client facing [SOLVED]

I use 40mhz channels for 5Ghz and 20mhz channels for 2.4Ghz. I have cap ac devices. Power is 10 for 2.4 and 22 for 5. I don't have 2.4 enabled on all aps. Hardware supported modes for 2.4 is gn and for 5 ac. If you want an export I can get this tomorrow. I have never customized the rates untill I di...
by biomesh
Tue Aug 03, 2021 10:58 pm
Forum: Wireless Networking
Topic: Devices unable to connect - client facing [SOLVED]
Replies: 22
Views: 7290

Re: Devices unable to connect - client facing [SOLVED]

Just FYI, I used your most current rate settings and I had a few devices that would not connect (via capsman)- in my case these were amazon echo devices(different models). Going back to the built in rate settings allowed the devices to connect.

Just providing some feedback.
by biomesh
Tue Aug 03, 2021 1:29 pm
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 13
Views: 14301

Re: DHCP Offering Lease Without Success

I was referring to the unifi config wrt mesh
by biomesh
Tue Aug 03, 2021 5:06 am
Forum: Wireless Networking
Topic: Devices unable to connect - client facing [SOLVED]
Replies: 22
Views: 7290

Re: Devices unable to connect - client facing [SOLVED]

Could it be your basic rates? Perhaps they can't connect at the basic rates for association. Do you have logs perhaps?

If you don't set rates at all (and use the built in rates) does that make a difference?
by biomesh
Mon Aug 02, 2021 9:46 pm
Forum: General
Topic: Bridge vlan solution without adding interface vlan
Replies: 30
Views: 2371

Re: Bridge vlan solution without adding interface vlan

No, that would "only" create a huge broadcast domain, not a collision domain.
I think I was having a flashback to the days of coax, BNC and terminators. :D
by biomesh
Mon Aug 02, 2021 8:58 pm
Forum: General
Topic: Bridge vlan solution without adding interface vlan
Replies: 30
Views: 2371

Re: Bridge vlan solution without adding interface vlan

I was referring from the OP where he wanted to create a 10.0.0.0/16 network with these vlans- onto one bridge - thus creating a huge collision domain.
by biomesh
Mon Aug 02, 2021 7:48 pm
Forum: General
Topic: Bridge vlan solution without adding interface vlan
Replies: 30
Views: 2371

Re: Bridge vlan solution without adding interface vlan

Do you think simply bridging your network would work anyway? 1500 networks into one collision domain?
by biomesh
Mon Aug 02, 2021 7:02 pm
Forum: General
Topic: Bridge vlan solution without adding interface vlan
Replies: 30
Views: 2371

Re: Bridge vlan solution without adding interface vlan

What Mikrotik hardware are you using in that 48 VLANs is putting extra load on the device?

The reasoning behind not using VLANs and routing seems odd.
by biomesh
Mon Aug 02, 2021 2:48 pm
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 13
Views: 14301

Re: DHCP Offering Lease Without Success

Do you by chance have mesh enabled with unifi? It has been a while since I replaced my unifi aps but they would always randomly have arp issues. Back then(probably a year and a half ago) no progress was made on the issue. I swapped them out (in this case with cap ac devices - but most any other woul...
by biomesh
Mon Aug 02, 2021 2:32 pm
Forum: Wireless Networking
Topic: CAPsMAN reconnections
Replies: 15
Views: 2984

Re: CAPsMAN reconnections

Looking at this log, the device is choosing to move between different access points. These are not errors, but just log entries showing the client roam. Roaming decisions are make by the client. If the client was being dropped for a poor signal, the disconnect message would be different. At least fo...
by biomesh
Sun Aug 01, 2021 5:10 pm
Forum: General
Topic: SIP ALG issue not resolving. [SOLVED]
Replies: 18
Views: 2664

Re: SIP ALG issue not resolving. [SOLVED]

A dst-nat to the same port is not really of any use. For dst-nat rules these are for non natted networks to natted networks - like your wan interface. Generally you would not want to use the from/to ports but use to/from address. This would mean that if you want asterisk and 3cx available from your ...
by biomesh
Sun Aug 01, 2021 3:34 pm
Forum: General
Topic: SIP ALG issue not resolving. [SOLVED]
Replies: 18
Views: 2664

Re: SIP ALG issue not resolving. [SOLVED]

If this is going to replace asterisk, then you should set in-interface or out-interface on your nat rules so that the router does not nat the traffic between subnets and only going out of your wan interface.
by biomesh
Sun Aug 01, 2021 3:24 pm
Forum: General
Topic: SIP ALG issue not resolving. [SOLVED]
Replies: 18
Views: 2664

Re: SIP ALG issue not resolving. [SOLVED]

Is 3cx always going to asterisk for the primary connection? If so there is no need for any firewall rule for this server. The router will just route packets normally between subnets.
by biomesh
Sun Aug 01, 2021 2:35 am
Forum: General
Topic: SIP ALG issue not resolving. [SOLVED]
Replies: 18
Views: 2664

Re: SIP ALG issue not resolving. [SOLVED]

My guess is that 3cx has a similar setting.
by biomesh
Sat Jul 31, 2021 8:20 pm
Forum: General
Topic: SIP ALG issue not resolving. [SOLVED]
Replies: 18
Views: 2664

Re: SIP ALG issue not resolving. [SOLVED]

Yes
by biomesh
Sat Jul 31, 2021 7:46 pm
Forum: General
Topic: SIP ALG issue not resolving. [SOLVED]
Replies: 18
Views: 2664

Re: SIP ALG issue not resolving. [SOLVED]

With asterisk/Freepbx you need to define "local" networks that do not need nat. If this is not set then it will try to nat the traffic and you will get one way audio.
by biomesh
Sat Jul 31, 2021 6:40 am
Forum: Wireless Networking
Topic: Slow speed with Cap AC
Replies: 38
Views: 8729

Re: Slow speed with Cap AC

5700MHz is the max freq in many regions (and even 5700 is already special)! If your tablet is set to such a region/country it will not scan for other channels than allowed for the region. I'm sure it's a chipset or firmware issue. I have a few Samsung devices, an older 'higher end' tablet, a curren...
by biomesh
Thu Jul 29, 2021 3:09 pm
Forum: RouterBOARD hardware
Topic: cAP ac (RBcAPGi-5acD2nD) POE in question
Replies: 9
Views: 2701

Re: cAP ac (RBcAPGi-5acD2nD) POE in question

My cap ac devices draw under 5W most of the time. I have used different(brands and types of) passive and at/af switches and injectors with no issues.

I suggest trying a different switch(maybe even a different brand).
by biomesh
Tue Jul 27, 2021 6:50 pm
Forum: Beginner Basics
Topic: IPv6 for home
Replies: 15
Views: 8765

Re: IPv6 for home

mkx did say "proper DHCPv6 server"... The mikrotik DHCPv6 server is not fully featured, so I would not consider it proper either.
by biomesh
Tue Jul 27, 2021 4:31 pm
Forum: Wireless Networking
Topic: CAPsMAN Help
Replies: 14
Views: 2169

Re: CAPsMAN Help

If your cap config has not changed from before that is why the filtering is not working on port 8. The management traffic is set to vlan 0 by default. You can either change the cap config to use a VLAN interface or configure port 8 to have a /interface ethernet switch ingress-vlan-translation entry ...
by biomesh
Tue Jul 27, 2021 4:10 pm
Forum: Beginner Basics
Topic: IPv6 for home
Replies: 15
Views: 8765

Re: IPv6 for home

Here is a simple ipv6 config(very simplified from my config). This works for comcast, and requests a /60 prefix (the max for residential comcast service). If there are /60 prefixes available, it should work (I have seen times where there are none available). The following uses WAN as your external i...
by biomesh
Tue Jul 27, 2021 2:57 pm
Forum: Wireless Networking
Topic: Slow speed with Cap AC
Replies: 38
Views: 8729

Re: Slow speed with Cap AC

I have a Samsung tablet that refuses to operate normally on any configuration with channel 165/5825. No other brand of device has the issue.

When in doubt check other devices and alter the config accordingly.
by biomesh
Tue Jul 27, 2021 4:09 am
Forum: Beginner Basics
Topic: VLANS & Management VLAN
Replies: 27
Views: 6537

Re: VLANS & Management VLAN

On my ccr1009 I found zero difference performance wise when (using it as a router on a stick) between assigning vlans to the interface vs a bridge.

In my case everything is coming in on one interface, so vlan filtering really isn't a concept here as the router would handle it all anyway.
by biomesh
Sun Jul 25, 2021 3:55 am
Forum: General
Topic: IPv4 only network DNS issues with mobile devices [SOLVED]
Replies: 11
Views: 1395

Re: IPv4 only network DNS issues with mobile devices [SOLVED]

Your rules only cover udp, so don't forget the tcp rules for DNS (not as common as udp). I don't know if any failover scenario other than using bgp and creating an anycast address to be used by DNS. You would use bird on the pihole devices for bgp. In the dst-nat rule you would use the anycast addre...
by biomesh
Sun Jul 25, 2021 1:09 am
Forum: General
Topic: IPv4 only network DNS issues with mobile devices [SOLVED]
Replies: 11
Views: 1395

Re: IPv4 only network DNS issues with mobile devices [SOLVED]

I don't know why the phones would do this(have not seen this on phones at least). You are best off using a dst nat rule that redirects port 53 traffic to your pi hole servers. I use a rule like this to point to my local resolvers that then use doh.
by biomesh
Sat Jul 24, 2021 9:24 pm
Forum: General
Topic: IPv4 only network DNS issues with mobile devices [SOLVED]
Replies: 11
Views: 1395

Re: IPv4 only network DNS issues with mobile devices [SOLVED]

Devices don't have to use DHCP assigned DNS - Chromecast devices for instance only use 8.8.8.8. You mentioned slaac assigned by the mobile connection. I was following your assumption and trying to verify the the source. If you want better answers with out a lot of guessing, post your export (with hi...
by biomesh
Sat Jul 24, 2021 8:46 pm
Forum: General
Topic: IPv4 only network DNS issues with mobile devices [SOLVED]
Replies: 11
Views: 1395

Re: IPv4 only network DNS issues with mobile devices [SOLVED]

To prove your theory, disable mobile data on the phone to see what happens.

You should really post your export so everyone can see the whole config.
by biomesh
Thu Jul 22, 2021 3:25 pm
Forum: Beginner Basics
Topic: Can't get over 1G on CRS309 10G ports
Replies: 5
Views: 1274

Re: Can't get over 1G on CRS309 10G ports

It can switch at wire speed, not route. You don't want anything hitting the CPU if you can avoid it.

How are you running your tests? Iperf with multiple threads? Have you changed the window size to match between all devices?
by biomesh
Wed Jul 21, 2021 3:00 pm
Forum: Wireless Networking
Topic: CAPsMAN reconnections
Replies: 15
Views: 2984

Re: CAPsMAN reconnections

This could be due to the reject rule at the top of the list. These are processed top down and generally you would want an overall disconnect rule at the bottom. If you create allow access rules with the appropriate signal range (-75..120) and with an allow out of range time of 15-20 seconds, this sh...
by biomesh
Fri Jul 16, 2021 4:31 pm
Forum: General
Topic: Many dhcp via one port on
Replies: 5
Views: 910

Re: Many dhcp via one port on

Take a look at https://forum.mikrotik.com/viewtopic.php?t=143620 for vlan configurations. In particular look at the router.rsc for an example configuration. It contains everything you are looking for. The one port connected to the ccr1016 would be a trunk port for all vlans. You will create a vlan i...
by biomesh
Fri Jul 16, 2021 1:00 am
Forum: Beginner Basics
Topic: need to assign vlan to a bridge
Replies: 2
Views: 605

Re: need to assign vlan to a bridge

You should migrate from a dual bridge config to a single bridge config and configure the correct VLANs on the correct ports along with PVID, taggged and untagged status per port. Once done, you can enable vlan filtering on the bridge. The link from the switch would just be for tagged packets and wou...
by biomesh
Wed Jul 14, 2021 2:32 am
Forum: Wireless Networking
Topic: CAPsMAN Help
Replies: 14
Views: 2169

Re: CAPsMAN Help

1) The ingress vlan translation is really for those ports that have untagged traffic. If your ap has tagged traffic for the capsman user traffic and for management, then it would not be required for that port. You would only need to say the egress vlan tags and the vlans on the switch. For most use ...
  • 1
  • 2