Community discussions

MikroTik App

Search found 1342 matches

by pcunite
Tue Mar 28, 2023 4:42 pm
Forum: General
Topic: Advice please CRS125-24G-1S-2HnD-IN or CRS326-24G-2S+IN [SOLVED]
Replies: 3
Views: 142

Re: Advice please CRS125-24G-1S-2HnD-IN or CRS326-24G-2S+IN [SOLVED]

If you want to learn the old way of configuring switches, lose an SFP+ port, and have useless wifi, the CRS125 is a good buy.
by pcunite
Sat Mar 25, 2023 3:48 pm
Forum: SwOS
Topic: CSS610-8G-2S+IN
Replies: 2
Views: 171

Re: CSS610-8G-2S+IN

Well, I like the smaller offerings sometimes. The frustration comes because this switch does not have RouterOS. I wish they would just put RouterOS on everything and have the option of SwOS for those that feel the need.
by pcunite
Sat Mar 25, 2023 3:42 pm
Forum: Beginner Basics
Topic: dns-server IP in VLAN tutorial
Replies: 11
Views: 385

Re: dns-server IP in VLAN tutorial

I prefer to avoid any usage with IP addresses. If I use IP addresses in firewall rules, it would make my configs less robust. A better approach in my opinion is to use VLAN interfaces names.

Absolutely, if possible.
by pcunite
Sat Mar 25, 2023 12:59 am
Forum: RouterBOARD hardware
Topic: MikroTik cAP ax [cAPGi-5HaxD2HaxD] (r2)
Replies: 93
Views: 11476

Re: MikroTik cAP ax [cAPGi-5HaxD2HaxD] (r2)

Whoa, just saw this. I was really needing a wifi refresh. The circular design looks nice. Would like it smaller, but I understand the antenna requirements require it.
by pcunite
Sat Mar 25, 2023 12:28 am
Forum: General
Topic: How do we request for an account deletion?
Replies: 17
Views: 738

Re: How do we request for an account deletion?

For the last 25 years of my career, we used Cisco for virtually everything--AiroNet-based WISP back in the late 90's to VMWare on UCS in the telco data center in the 2010's. Now, I'm on my own and have built a successful WISP with over a thousand MikroTik and Ubiquiti devices and love (well, love/h...
by pcunite
Sat Mar 25, 2023 12:26 am
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 336
Views: 70368

Re: v7.8 [stable] is released!

ok more and more people reporting problems so 7.8 is not that stable :) needs a lot of fixes

When v7 gets to be 7.99999 (that's five nines), I'll be ready to consider it stable.
by pcunite
Sat Mar 25, 2023 12:24 am
Forum: Beginner Basics
Topic: dns-server IP in VLAN tutorial
Replies: 11
Views: 385

Re: dns-server IP in VLAN tutorial

Which firewall rules ensures that it works? ... These are distinct networks, thus the packet would go through the "forward" chain. Actually, any packet intended for the router itself, (stated here as entering the router ) must involve the input chain. Therefore the appropriate rule appear...
by pcunite
Fri Mar 24, 2023 6:25 pm
Forum: General
Topic: How do we request for an account deletion?
Replies: 17
Views: 738

Re: How do we request for an account deletion?

MikroTik is broadening its user base. This is going to come from the non-corporate market. But I believe its going to be a good thing. The ivory tower brands have their place, but that's not MikroTik. I hope there is balance in the SKUs for the home user, small business, WISP, ISP, and maybe even so...
by pcunite
Fri Mar 24, 2023 6:15 pm
Forum: Beginner Basics
Topic: dns-server IP in VLAN tutorial
Replies: 11
Views: 385

Re: dns-server IP in VLAN tutorial

force any DNS queries in the environment to use the Router/DNS running instance Following up to myself here. In the VLAN examples, I don't show this concept , but made arrangements for it because when doing so I thought it easier, faster to use one ip address in a mangle rule vs accounting for all ...
by pcunite
Fri Mar 24, 2023 5:52 pm
Forum: Beginner Basics
Topic: dns-server IP in VLAN tutorial
Replies: 11
Views: 385

Re: dns-server IP in VLAN tutorial

Well, you'll have to forgive me for doing that. What I show works, naturally because we are dealing with a Router/Firewall device that has full control of everything and we are in total control of the hardware. There is a firewall rule ensuring it works. It would be proper, or maybe I should say, mo...
by pcunite
Fri Mar 24, 2023 4:53 pm
Forum: General
Topic: How do we request for an account deletion?
Replies: 17
Views: 738

Re: How do we request for an account deletion?

DarkNate, Your expertise is needed. Look, you have to be willing to love & forgive people to participate in the forums. This is an international forum with people coming from all kinds of backgrounds, needs, and wants. It is not just a bunch of networking techs. Ultimately, everyone one of us be...
by pcunite
Thu Mar 23, 2023 7:41 pm
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 336
Views: 70368

Re: v7.8 [stable] is released!

... the last netinstall was 7.4, or 7.5 ... it can´t be the way to netinstall every new stable version ...

Okay, thank you. I wasn't sure if you ever had. I agree. If you've already Netinstalled to v7, then I think that is adequate.
by pcunite
Wed Mar 22, 2023 10:52 pm
Forum: Wireless Networking
Topic: House wifi6 network with Mikrotik AX or Audience
Replies: 29
Views: 2845

Re: House wifi6 network with Mikrotik AX or Audience

Would like to see the wAP AC line updated with hAP x2 innards. Don't want install hAP x2 because they look like little switches to clients.
by pcunite
Wed Mar 22, 2023 6:36 pm
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 336
Views: 70368

Re: v7.8 [stable] is released!

... with 7.8 my core router (CRS326-24S+2Q+RM) did 3 times spontaneous reboots initiated from watchdog in the last 12 days ... back to 7.7 solves the problem.

Could you try a Netinstall and see if that changes anything?
by pcunite
Wed Mar 15, 2023 4:19 am
Forum: General
Topic: Routers Coming with Default Passwords
Replies: 20
Views: 616

Re: Routers Coming with Default Passwords

I agree. This is a product SKU for professionals. This is going to be a huge pain. We don't need a nanny. Let us manage our own passwords. Blank passwords don't hurt the internet, people do.
by pcunite
Tue Mar 14, 2023 9:19 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 225
Views: 318176

Re: Using RouterOS to VLAN your network

Am I right to think that this will not work with a CSS3xx switch running switchOS? Would I need a separate Lan interface for each Vlan trunk to the switch? Correct. This configuration series is only for RouterOS based MikroTik products. I've not ever used SwOS , but will be soon because I'm deployi...
by pcunite
Thu Mar 02, 2023 3:11 pm
Forum: Announcements
Topic: Newsletter 111
Replies: 24
Views: 15047

Re: Newsletter 111

Thank you for dessert (100 Gigabit) but I've not yet finished my dinner (short depth PoE switching). :-)
by pcunite
Thu Mar 02, 2023 3:08 pm
Forum: Announcements
Topic: v7.8 [stable] is released!
Replies: 336
Views: 70368

Re: v7.8 [stable] is released!

Why don't you take a 7.x and then just BUGFIX that version to finally release a LTS? Why every time just add a bunch of new features without fixing the previous issues? I don't think that is a productive way to build software. I love MT, I am also a trainer and diffuse Mikrotik's verb everywhere .....
by pcunite
Thu Mar 02, 2023 2:32 am
Forum: Beginner Basics
Topic: Fiber selection
Replies: 2
Views: 304

Re: Fiber selection

I've had very good experience with FS.com modules and cabling, so I would recommend that. I've standardized on OS2 SMF for everything, but in a home environment, you could naturally do MMF OM4. OS2 is just better, so I don't see the need to really use anything else unless you're supporting existing...
by pcunite
Thu Mar 02, 2023 1:30 am
Forum: RouterBOARD hardware
Topic: Difference between rev 1 and rev 2 of CRS317?
Replies: 3
Views: 853

Re: Difference between rev 1 and rev 2 of CRS317?

MikroTik and other vendors I think issue a revision for any change. It is not meant to indicate an improvement. So, another supplier was used for the capacitors, or different fans was sourced from a different company, etc.
by pcunite
Thu Mar 02, 2023 1:18 am
Forum: Beginner Basics
Topic: VLAN tutorial - Understanding menu "/interface bridge vlan"
Replies: 11
Views: 1004

Re: VLAN tutorial - Understanding menu "/interface bridge vlan"

I updated the examples on February 17th. You must have just missed the fixes for this exact sort of situation. As you've discovered, firmware updates have changed the [find] construct and can cause configuration issues. Basically [find] would do nothing at times depending on what had been done previ...
by pcunite
Thu Feb 23, 2023 6:22 am
Forum: General
Topic: Feature Request: Link "check-gateway" in routes to a netwatch item(s)
Replies: 8
Views: 704

Re: Feature Request: Link "check-gateway" in routes to a netwatch item(s)

If any MikroTik support staff are seeing this suggestion, it would be good to have something baked into RouterOS to handle link failure. Don't need to do it in routes, but baked it into netwatch perhaps.
by pcunite
Thu Feb 23, 2023 6:16 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 232
Views: 94669

Re: Bypassing AT&T Residential Gateways with MikroTik

Do go on ...

I plan to do it soon. In a few weeks or so.
by pcunite
Wed Feb 22, 2023 3:32 pm
Forum: General
Topic: Guys please help setting up dual WAN config
Replies: 29
Views: 1524

Re: Guys please help setting up dual WAN config

nobody?

Please read here.
by pcunite
Sat Feb 18, 2023 2:30 am
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 225
Views: 318176

Re: Using RouterOS to VLAN your network

An unfortunate limitation of RoS is that when the system receives a VLAN created by an add statement (I wish add would perform a set automatically) you must use a set later, and worse need to find it. Replying to my comment made last year. The add command now works as expected. So, I've updated the...
by pcunite
Thu Feb 16, 2023 8:35 pm
Forum: General
Topic: Mikrotik CRS326-24S+2Q+RM
Replies: 11
Views: 1410

Re: Mikrotik CRS326-24S+2Q+RM

It tells you in the brochure . What else do you need to know? RouterOS is fine as long as you don't try to use the CRS as a router. It is setup for switching. To understand your needs, you need to note the ports in use, direction of traffic, and the speed. Two 40 Gbps QSFP+ ports and twenty four 10 ...
by pcunite
Thu Feb 16, 2023 8:30 pm
Forum: Announcements
Topic: v7.8rc is released!
Replies: 125
Views: 35999

Re: v7.8rc is released!

Ability to specify domain name with some kind of a "none" action is on its way. We do not know how it will look yet, but you will be able to add dummy DNS record that will override DNS name lookup.

Thank you.
by pcunite
Thu Feb 16, 2023 8:22 pm
Forum: Beginner Basics
Topic: 3LANs to 3WANs are OK, but LAN to LAN is not
Replies: 26
Views: 1054

Re: 3LANs to 3WANs are OK, but LAN to LAN is not

Please see this topic here. Read slowly. You don't need to implement the fail over detection unless desired.
by pcunite
Wed Feb 08, 2023 10:03 pm
Forum: SwOS
Topic: [faturerequest] Showing which VLAN-s port is member of
Replies: 2
Views: 244

Re: [faturerequest] Showing which VLAN-s port is member of

Can you create a graphic mock up?
by pcunite
Wed Feb 08, 2023 10:02 pm
Forum: RouterBOARD hardware
Topic: Know if the product is new - rb5009 [SOLVED]
Replies: 13
Views: 1171

Re: Know if the product is new - rb5009 (scam?) [SOLVED]

Oil on a unit I'm working with as well.
by pcunite
Mon Feb 06, 2023 11:03 pm
Forum: Beginner Basics
Topic: Newbie question on VLAN
Replies: 5
Views: 452

Re: Newbie question on VLAN

Thanks for your zero effort answer. I've already see that topic. If you want share an useful answer please give me a guideline on how to resolve my problem. If you aren't able to do it please avoid this lazy reply BartoszP has shown you the greatest kindness. The linked article was literately creat...
by pcunite
Mon Feb 06, 2023 2:38 pm
Forum: Wireless Networking
Topic: My experience and issues in hi-density networks at school
Replies: 57
Views: 4382

Re: My experience and issues in hi-density networks at school

I don't yet recommend Cambium. ... MikroTik ... Has admitted in this forum over the years that there are some places and environments where they are absolutely not going to work ... As I have said for years ... If caps-man could control a good radio that could actually keep things connected... It w...
by pcunite
Fri Feb 03, 2023 9:58 pm
Forum: Useful user articles
Topic: MultiWAN with RouterOS
Replies: 26
Views: 3436

Re: MultiWAN with RouterOS

Okay, Example1 is ready for intensive criticism. What could be more clear? Are there any errors? A note about Example1: This is a recursive routing example. It is supposed to stand on its own as a deliverable. It answers the question: " How do I wire up multiple WANs and make sending/receiving,...
by pcunite
Fri Feb 03, 2023 3:15 pm
Forum: General
Topic: How to access Mikrotik behind Starlink (CGNAT) [SOLVED]
Replies: 48
Views: 2620

Re: How to access Mikrotik behind Starlink (CGNAT)

To add to what erlinden has said, you first have a server that is publicly accessible. It could be a DigitalOcean droplet virtual server, a Linode instance, or even a RPi server running in a buddy's rack. The point is, that you have a server outside of the CGNAT environment. The MikroTik behind CGNA...
by pcunite
Thu Feb 02, 2023 7:05 pm
Forum: Useful user articles
Topic: MultiWAN with RouterOS
Replies: 26
Views: 3436

Re: MultiWAN with RouterOS

you are using 1.1.1.1 for an ISP address?

Opps, yes I had that incorrect in the diagram. Thank you. The rsc file was correct, however. DNS Host1 is 1.1.1.1, it is what the example is pinging. The ISP is 10.1.1.1 and the recursive route is naturally 1.1.1.1.
by pcunite
Thu Feb 02, 2023 6:23 pm
Forum: General
Topic: Routeros 7 mangle changes?
Replies: 5
Views: 674

Re: Routeros 7 mangle changes?

Things have changed. It is still a work in progress, but you can view a working configuration here. Download Example 1.
by pcunite
Thu Feb 02, 2023 12:29 am
Forum: General
Topic: modifying route distance dual wan
Replies: 48
Views: 2485

Re: modifying route distance dual wan

In the ISP1_route table, there is no point to use the recursion to monitor the uplink state - this table is used for responses that must use wan1 and if wan1 doesn't work, sending those packets via wan2 won't help. So the default route in ISP1_route can use directly PrimaryISP-gatewayIP as gateway ...
by pcunite
Tue Jan 31, 2023 12:36 am
Forum: Wireless Networking
Topic: MikroTik WiFi AP For CRS309 CRS326 CRS326 Fleet
Replies: 19
Views: 1149

Re: MikroTik WiFi AP For CRS309 CRS326 CRS326 Fleet

@pcunite, I find why choices are made helpful. Can you indulge me? Well, its MikroTik's typical offering. A configuration nightmare. So, I just never used it. Deploy your radios with correct channel (frequency) spacing, everything back to a switch, and then set passwords. Its a service call to chan...
by pcunite
Mon Jan 30, 2023 10:21 pm
Forum: Wireless Networking
Topic: MikroTik WiFi AP For CRS309 CRS326 CRS326 Fleet
Replies: 19
Views: 1149

Re: MikroTik WiFi AP For CRS309 CRS326 CRS326 Fleet

I actually got in with another manufacture who would chase down the bugs I presented Can you say who? To the OP, I use MikroTik wireless solutions for clients. However, the biggest job I did was about 20 AP's and in a quiet (RF) environment. I also do not use Capsman. The 20 counts was for coverage...
by pcunite
Fri Jan 20, 2023 9:35 pm
Forum: Useful user articles
Topic: MultiWAN with RouterOS
Replies: 26
Views: 3436

Re: MultiWAN with RouterOS

Is PCC also going to be part of the scope ?

A perfectly cooked beef tenderloin served with buttered mashed potatoes, lemon roasted asparagus, and ranch covered salad spears is not enough for you? You want ... dessert too?
by pcunite
Thu Jan 19, 2023 2:53 pm
Forum: Useful user articles
Topic: MultiWAN with RouterOS
Replies: 26
Views: 3436

Re: MultiWAN with RouterOS

... focus on "recursive lookup" (vs "netwatch techniques") for upstream failure detection seems a good call ... with the new netwatch detection mechanism in 7.7, I can see a well-design script doing better than RR ... when BFD comes, that may offer a 3rd failure detection option...
by pcunite
Wed Jan 18, 2023 11:36 pm
Forum: Useful user articles
Topic: MultiWAN with RouterOS
Replies: 26
Views: 3436

Re: MultiWAN with RouterOS

@anav, That means a lot. Your help on the forums is felt and you've helped me personally. You know more than me! These long form articles take a long time to produce. So, don't feel bad about that. We all have our own strengths. This is a way for me to give back. Give me a few weeks to get this arti...
by pcunite
Wed Jan 18, 2023 8:09 pm
Forum: Useful user articles
Topic: New User Pathway To Config Success
Replies: 55
Views: 22733

Re: New User Pathway To Config Success

Hello fellow forum compatriots! I have another article series I'm putting together and would like your valuable knowledge and skill to refine it for the benefit of the forum. When finished, it should be linked from here. This thread is a nice collection of user created content and shows the best doc...
by pcunite
Wed Jan 18, 2023 8:03 pm
Forum: Useful user articles
Topic: MultiWAN with RouterOS
Replies: 26
Views: 3436

Re: MultiWAN with RouterOS

Reserved
by pcunite
Wed Jan 18, 2023 8:03 pm
Forum: Useful user articles
Topic: MultiWAN with RouterOS
Replies: 26
Views: 3436

Re: MultiWAN with RouterOS

Reserved
by pcunite
Wed Jan 18, 2023 8:02 pm
Forum: Useful user articles
Topic: MultiWAN with RouterOS
Replies: 26
Views: 3436

Re: MultiWAN with RouterOS

Reserved
by pcunite
Wed Jan 18, 2023 8:02 pm
Forum: Useful user articles
Topic: MultiWAN with RouterOS
Replies: 26
Views: 3436

Re: MultiWAN with RouterOS

Example1: We will lead into this topic using a generic example that covers the majority of situations. We have four WAN connections and need a method to determine when a primary connection is down. When primary is deemed down, the router should switch the environment over to another WAN network. Be...
by pcunite
Wed Jan 18, 2023 8:01 pm
Forum: Useful user articles
Topic: MultiWAN with RouterOS
Replies: 26
Views: 3436

MultiWAN with RouterOS

Title: MultiWAN with RouterOS Welcome: This article aims to bring clarity to the daunting and confusing task of routing multiple WAN and ISP provider connections in and out of your network. We will be using RouterOS version 7 firmware to accomplish these techniques. Examples will include Static IP ...
by pcunite
Fri Jan 06, 2023 8:58 pm
Forum: SwOS
Topic: Voice VLAN
Replies: 4
Views: 605

Re: Voice VLAN

I use CR328 for this purpose. The MikroTik automated way is here. However, I just use hybrid ports.
by pcunite
Tue Jan 03, 2023 2:23 pm
Forum: Announcements
Topic: v6.49.7 [stable] is released!
Replies: 48
Views: 72931

Re: v6.49.7 [stable] is released!

When MikroTik was called out for not giving back to the community whatever patches they made to the GPL software they used back then, instead of doing the right thing, the opted to re-invent the wheel writing everything from scratch. MikroTik culture struggles with pride. However, humility is bring...
by pcunite
Fri Dec 30, 2022 5:19 pm
Forum: Announcements
Topic: Newsletter 109
Replies: 13
Views: 20927

Re: Newsletter 109

This thread was named "Newsletter 109" not "Wish us Merry Christmas eve", right? And tell me please, are there any xmas gifts like new products in the #109? Well, a newsletter, at least here in the US, is a cheesy update newspaper style info-graphic of what is going on. They con...
by pcunite
Fri Dec 30, 2022 5:14 pm
Forum: Wireless Networking
Topic: About MESH with Mikrotik devices
Replies: 6
Views: 835

Re: About MESH with Mikrotik devices

... if I can place them by wired to main switch, WDS will still needed or not? Just same SSID, freq. and bandwidth o different channels? If you wire the stations together, then you don't need "wireless bridging", or WDS. Ideally, you would put APs wherever you need coverage, with a slight...
by pcunite
Thu Dec 29, 2022 8:43 pm
Forum: General
Topic: modifying route distance dual wan
Replies: 48
Views: 2485

Re: modifying route distance dual wan

Could you please confirm me the configuration in my context to make recursive routing work ?

Watch the video I linked to. Watch slowly.
by pcunite
Thu Dec 29, 2022 4:24 pm
Forum: RouterBOARD hardware
Topic: CCR2116-12G-4S+ - Crashing on high load
Replies: 2
Views: 849

Re: CCR2116-12G-4S+ - Crashing on high load

Disable Connection Tracking.
by pcunite
Thu Dec 29, 2022 4:22 pm
Forum: General
Topic: RB5009Upr - Slightly asymetrical saturation rx/tx throughput from WAN to LAN when using 2.5G port
Replies: 1
Views: 452

Re: RB5009Upr - Slightly asymetrical saturation rx/tx throughput from WAN to LAN when using 2.5G port

You say 10% utilization. What does prints of /tool/profile and /system/resource/cpu show?
by pcunite
Thu Dec 29, 2022 4:18 pm
Forum: General
Topic: what do you think about using 4 RB5009UPr+S+IN like this?
Replies: 1
Views: 473

Re: what do you think about using 4 RB5009UPr+S+IN like this?

I'm all for reducing complexity and electrical costs. I've only recently started to play around with the RB5009 , but its not the all PoE out model like you've got. I'm sure you know that power in on this unit is what goes out. So, keep that in mind with your design. I like to look at the block diag...
by pcunite
Thu Dec 29, 2022 4:04 pm
Forum: Beginner Basics
Topic: Rb2011 as switch
Replies: 1
Views: 307

Re: Rb2011 as switch

I used to have one of these RB2011 units. Really cool hardware for its time. The most efficient way may not be possible. What do you mean by efficiency ? Speed, security, or logical sense? You can't have all three with this unit! A clue to design is looking at the block diagram . Ports 1 through 5 a...
by pcunite
Thu Dec 29, 2022 3:57 pm
Forum: Wireless Networking
Topic: About MESH with Mikrotik devices
Replies: 6
Views: 835

Re: About MESH with Mikrotik devices

Great first post! You've taken some time to present your question.

Would it be possible for you at all to avoid mesh entirely? Fiber is very cost effective now, for example. Would you consider that a possibility to wire access to all the APs and bring them back to a central switch?
by pcunite
Thu Dec 29, 2022 3:51 pm
Forum: General
Topic: modifying route distance dual wan
Replies: 48
Views: 2485

Re: modifying route distance dual wan

This can be tricky to get correct. I may do an entire article series on this someday. At the moment, forum member anav has an extensive resource here . See section I. IP ROUTE - Multi-WAN. If you prefer a video format, this example is useful. Take it slow understanding this concept. I know you want ...
by pcunite
Thu Dec 29, 2022 3:32 pm
Forum: SwOS
Topic: Problems with IPv6 Prefix Delegation on CSS610-8G-2S+ [SOLVED]
Replies: 21
Views: 2122

Re: Problems with IPv6 Prefix Delegation on CSS610-8G-2S+ [SOLVED]

A very warm welcome to the community for an MT-newbie who's trying to set up their home network with new hardware. It's okay we can be rude again, Christmas is over. There is an endless line of sub 10 post count'ers who have proven to be nothing more than fly-bys taking help but giving nothing back...
by pcunite
Thu Dec 29, 2022 1:30 am
Forum: Forwarding Protocols
Topic: Routing rule use cases
Replies: 10
Views: 4634

Re: Routing rule use cases

I use them with a client who has multiple ISP connections, one of which is another hardware item supplying LTE. With them, a couple of services always need to go out LTE. Some other rules allow LAN to go out the default route correctly. Example: /ip route rule #"LAN Destinations that should onl...
by pcunite
Thu Dec 29, 2022 1:06 am
Forum: Wireless Networking
Topic: any forum where to sell and buy stuff?
Replies: 6
Views: 637

Re: any forum where to sell and buy stuff?

Would be nice if there was a buy and sell on here. But, I don't know of any offhand.
by pcunite
Thu Dec 29, 2022 1:03 am
Forum: General
Topic: A year of fq_codel and cake deployment - how's it working?
Replies: 2
Views: 354

Re: A year of fq_codel and cake deployment - how's it working?

I have only recently started to use ROS 7. I consider version 7.6 stable enough to start playing around with. Others might have felt the same way and have not tested with it much. If so, would love to see the feedback and example configurations. Appreciate the work!
by pcunite
Wed Dec 28, 2022 10:59 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 232
Views: 94669

Re: Bypassing AT&T Residential Gateways with MikroTik

I tested with both a RB4011 and a RB5009 running ROS v7.6. I can confirm that the supplicant method does work with the following. Create a bridge (aka BR_ATT ) with VLAN filtering enabled, admit all, and uncheck ingress filtering. Add the ether1 interface to your new bridge. Setup everything else li...
by pcunite
Mon Dec 26, 2022 9:40 pm
Forum: General
Topic: Replacing a RB951G-2HnD what do you recommend?
Replies: 16
Views: 1114

Re: Replacing a RB951G-2HnD what do you recommend?

As a MikroTik enthusiast, you should get the RB5009 of course. It was made for you. I have the RB4011 because that is what was available at the time. Have never regretted the decision. Nice hardware. Always separate the radio hardware from routing and switching, so you can upgrade or optimally posit...
by pcunite
Sat Dec 24, 2022 7:06 pm
Forum: General
Topic: Simple failover?
Replies: 11
Views: 859

Re: Simple failover?

Maybe this video can be of help in ROS v7.

Nicely done! Helps to have someone show the process.
by pcunite
Sat Dec 24, 2022 5:42 pm
Forum: Announcements
Topic: Newsletter 109
Replies: 13
Views: 20927

Re: Newsletter 109

Merry Christmas eve!

@upower3,
We beat up on MikroTik another day. Today, we wish them well.
by pcunite
Sat Dec 24, 2022 7:09 am
Forum: General
Topic: Help troubleshooting latency crash on RB4011
Replies: 4
Views: 886

Re: Help troubleshooting latency crash on RB4011

I was curious as to what would make the arm based RB4011 crash. But you have given an export of the CCR1009-7G-1C-1S+, which is a Tile based design. Very different architecture and maybe there is a bug somewhere. With so many new connections, reconsider changing tcp-established-timeout=1d to somethi...
by pcunite
Thu Dec 22, 2022 7:04 pm
Forum: RouterBOARD hardware
Topic: CCR2004-16G-2S+PC NO USB, WHYYY!??
Replies: 15
Views: 1489

Re: CCR2004-16G-2S+PC NO USB, WHYYY!??

Will the CCR2004-16G-2S+ work for you?
by pcunite
Tue Dec 20, 2022 7:48 pm
Forum: Wireless Networking
Topic: Anyone tested LHG CAT18 device?
Replies: 15
Views: 1642

Re: Anyone tested LHG CAT18 device?

@korg,

How is your testing going? Would the ATL LTE18 kit perform better in your scenario?
by pcunite
Tue Dec 20, 2022 5:02 pm
Forum: General
Topic: Help troubleshooting latency crash on RB4011
Replies: 4
Views: 886

Re: Help troubleshooting latency crash on RB4011

What firmware and show an export between CODE tags here.
by pcunite
Mon Dec 12, 2022 5:04 pm
Forum: General
Topic: Building a secured Hotel network
Replies: 29
Views: 1752

Re: Building a secured Hotel network

Thank you for the easy to follow diagram. Read the links broderick has provided. Access from Office to Cam is as simple as a firewall rule in forward chain, in interface is Office, out interface is Cam, connection state is New, and action is accept.
by pcunite
Fri Dec 02, 2022 4:51 pm
Forum: General
Topic: Support not answering tickets?
Replies: 4
Views: 423

Re: Support not answering tickets?

They may not know how to respond. Lots of bugs with v7.
by pcunite
Fri Dec 02, 2022 4:50 pm
Forum: General
Topic: Mikrotik iOS App 1.2.11
Replies: 8
Views: 1015

Re: Mikrotik iOS App 1.2.11

App seems abandoned. I removed it. ROS web interface is more than adequate.
by pcunite
Fri Dec 02, 2022 5:38 am
Forum: RouterBOARD hardware
Topic: RB5009UPr+S+ SFP module not working
Replies: 12
Views: 2128

Re: RB5009UPr+S+ SFP module not working

I like the generic FS.com modules.
by pcunite
Fri Nov 11, 2022 8:20 pm
Forum: RouterBOARD hardware
Topic: which LTE router is best for me?
Replies: 8
Views: 1450

Re: which LTE router is best for me?

What adapter mods did you have to do to get the EM160R-GL in there? Was setup seamless?

MHF4 to SMA, 4in for M.2 modem antenna connections. A mini PCI-E to m.2 adapter for the modem itself. Setup was seamless and automatic after that. It just worked.
by pcunite
Wed Oct 12, 2022 5:09 pm
Forum: RouterBOARD hardware
Topic: which LTE router is best for me?
Replies: 8
Views: 1450

Re: which LTE router is best for me?

I don't have enough experience to really nail it down for you, but I have used a solution involving an LtAP router, EM160R-GL Cat16 LTE modem , and a QuPanel APLM4 LTE MIMO 4x4 directional antenna with seventeen foot lead mounted to roof. It is PoE powered, so install where needed. Running firmware ...
by pcunite
Sat Sep 24, 2022 12:15 am
Forum: RouterBOARD hardware
Topic: MikroTik hAP ax³ [C53UiG+5HPaxD2HPaxD]
Replies: 78
Views: 17962

Re: MikroTik hAP ax³ [C53UiG+5HPaxD2HPaxD]

USB is not for storage, its for external devices like LTE modems and such.
by pcunite
Fri Sep 23, 2022 12:41 am
Forum: General
Topic: RBGroove52HPn - TX Power cant be set >17dbm
Replies: 3
Views: 419

Re: RBGroove52HPn - TX Power cant be set >17dbm

What happens if you set:
Frequency mode to regulatory-doman
Country: Enter a value

and then via the command line set:
/interface wireless set antenna-gain=0
by pcunite
Thu Sep 22, 2022 11:01 pm
Forum: RouterOS beta and rc versions
Topic: Routing Mark and route traffic to a different GW
Replies: 7
Views: 2401

Re: Routing Mark and route traffic to a different GW

Sob,

Thank you for the findings. Upgraded to RoS 7.5 from 7.21 and hit this issue. Anav, I think this makes your New User Pathway To Config Success thread in need of an update.
by pcunite
Thu Sep 22, 2022 6:03 pm
Forum: RouterBOARD hardware
Topic: MikroTik hAP ax³ [C53UiG+5HPaxD2HPaxD]
Replies: 78
Views: 17962

Re: MikroTik hAP ax³

What is the M$RP?
by pcunite
Fri Sep 16, 2022 9:57 pm
Forum: General
Topic: VLANs not working
Replies: 17
Views: 1628

Re: VLANs not working

mkx has correctly explained the pitfalls of the confusing ROS syntax and exonerated my guilt. MikroTik is to blame, not I. You would think find would at least print an error to the screen. Nope, just keeps on confusing people. However, I don't find the lack of a status or error message as the real p...
by pcunite
Wed Sep 14, 2022 6:51 pm
Forum: General
Topic: VLANs not working
Replies: 17
Views: 1628

Re: VLANs not working

Suggesting your use of FIND nomenclature is too academic or CLI focused for many.

Yeah, I do understand and wish it was better. The mix of add, set coupled with find is confusing.
by pcunite
Wed Sep 14, 2022 5:28 am
Forum: General
Topic: VLANs not working
Replies: 17
Views: 1628

Re: VLANs not working

I blame MikroTik syntax as being weakly designed in this area. However, I can be the whipping boy. I can't feel the pain anymore.
by pcunite
Wed Aug 31, 2022 6:35 pm
Forum: RouterBOARD hardware
Topic: Smaller Netpower with PoE out
Replies: 6
Views: 645

Re: Smaller Netpower with PoE out

Agree, need a full line-up of PoE switches, rack and otherwise.
by pcunite
Thu Aug 25, 2022 6:49 am
Forum: General
Topic: VLAN for WLAN and Ethernet in CRS1xx
Replies: 5
Views: 451

Re: VLAN for WLAN and Ethernet in CRS1xx

Since you have now done most of the work, why not add it to Using RouterOS to VLAN your network, or at least add a link to your post so someone could more easily find it in the future?

Well, I don't really recommend using CRS1xx switches, but I understand some may have to.
by pcunite
Thu Aug 18, 2022 7:07 pm
Forum: General
Topic: VLAN for WLAN and Ethernet in CRS1xx
Replies: 5
Views: 451

Re: VLAN for WLAN and Ethernet in CRS1xx

I never added CRS1xx support to the article, but if I did, it would look something like this. CRS1xx VLAN Example ############################################################################### # Recommended reading # https://wiki.mikrotik.com/wiki/Manual:Basic_VLAN_switching # # Notes: Start with a...
by pcunite
Wed Jul 20, 2022 9:34 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 232
Views: 94669

Re: Bypassing AT&T Residential Gateways with MikroTik

It appears there is a much better bypass now using your own GPON generic stick like this FS branded GPON-ONU-34-20BI module. The generic module will not use OMCI extensions that enable 802.1x authentication. Per the link, you do need to match the OMCI version (0xA0), ONT Hardware version, ONT Softwa...
by pcunite
Wed Jul 20, 2022 6:19 pm
Forum: Announcements
Topic: Newsletter 106
Replies: 29
Views: 15436

Re: Newsletter 106

CSS610-8P-2S+IN looks good. Would prefer CRS (RouterOS).
by pcunite
Thu Jun 23, 2022 5:39 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 225
Views: 318176

Re: Using RouterOS to VLAN your network

So now I am also confused about the difference between these two options. Also, why do some examples only use "set bridge" The examples walk you through a process of adding things and then changing them. I did this to keep every line as short as I could. It is very possible to do it all o...
by pcunite
Wed Jun 15, 2022 8:58 pm
Forum: RouterBOARD hardware
Topic: I really need POE for this CRS312-4C+8XG-RM
Replies: 12
Views: 5392

Re: I really need POE for this CRS312-4C+8XG-RM

Got to use a CRS328-24P+S4-RM today ... They have been out of stock for forever ... could definitely get used to this platform.

Its a nice switch. I have five deployed at a multi-building client site and it seems to work well. Powering APs, RPi server, PBX, phones.
by pcunite
Sat Jun 04, 2022 12:16 am
Forum: Beginner Basics
Topic: VLAN
Replies: 4
Views: 496

Re: VLAN

Read my signature.
by pcunite
Tue May 24, 2022 7:16 pm
Forum: RouterBOARD hardware
Topic: CRS112-8P-4S-IN/CRS305-1G-4S+IN Tandem Tray
Replies: 9
Views: 2502

Re: CRS112-8P-4S-IN/CRS305-1G-4S+IN Tandem Tray

What do you mean by modern ?

CRS3xx line.
by pcunite
Mon May 23, 2022 11:05 pm
Forum: Beginner Basics
Topic: Chateau LTE12: mtu info
Replies: 6
Views: 1342

Re: Chateau LTE12: mtu info

I have a similar message to OP, except is states: "lte1 mbim: network advertises lower mtu: 1430". Is there something that I need to change?
by pcunite
Fri May 20, 2022 4:26 pm
Forum: RouterBOARD hardware
Topic: CRS112-8P-4S-IN/CRS305-1G-4S+IN Tandem Tray
Replies: 9
Views: 2502

Re: CRS112-8P-4S-IN/CRS305-1G-4S+IN Tandem Tray

First I screwed those brackets to both units and then joined those two brackets together. The separation between those 2 units is sufficient for a quite easy access to those nuts.

Looks good! And proof, that we need a short depth modern PoE switch.
by pcunite
Wed May 18, 2022 6:43 pm
Forum: General
Topic: Issue with LTE interface on LHGR & Quectel EP06-A
Replies: 8
Views: 819

Re: Issue with LTE interface on LHGR & Quectel EP06-A

Change IMEI

Why?
by pcunite
Tue May 17, 2022 3:22 pm
Forum: Beginner Basics
Topic: trying routeros after years with cisco. Vlan interface ping not working
Replies: 20
Views: 1275

Re: trying routeros after years with cisco. Vlan interface ping not working

I see that this forum is as poisonous as ever. I'm very sorry for troubling you. I see that I should stayed where I was. Thank you for clarifying that for me. Don't take things too personally. It is just a forum with a wall of words coming at you. If we were all sitting around a table, we would be ...
by pcunite
Mon May 16, 2022 4:22 pm
Forum: Scripting
Topic: Setting Queue Tree max-limit value [SOLVED]
Replies: 3
Views: 1190

Re: Setting Queue Tree max-limit value [SOLVED]

just too much ] at the end...

Ugh ... thank you!

... run the script from console with /system scripts run command then you will see the errors ...

That's helpful, thank you!
by pcunite
Sun May 15, 2022 11:52 pm
Forum: Useful user articles
Topic: New User Pathway To Config Success
Replies: 55
Views: 22733

Re: NEW USER PATHWAY TO CONFIG SUCCESS

Ahhhhhhhhhhh I see your doing it by DESTINATION ADDRESS not by source address!! Okay, now it makes sense. Rather smart of you pcunite............. Also the potential implications of forcing an IP out a specific WANIP cannot be overstated!! But if you only had read my Para J, "SERVER EXAMPLE&qu...
by pcunite
Sun May 15, 2022 11:44 pm
Forum: Scripting
Topic: Setting Queue Tree max-limit value [SOLVED]
Replies: 3
Views: 1190

Setting Queue Tree max-limit value [SOLVED]

I need to change the max-limit value. I'm not sure how to debug scripts to see what is incorrect about this syntax. What is the error here? This should work. RouterOS v6.47.10 # Set QoS Values :local sGateway "1.2.3.4" :if ( $sGateway = "1.2.3.4") do={ :log info "Setting spe...
by pcunite
Thu May 12, 2022 11:18 pm
Forum: RouterOS beta and rc versions
Topic: SFP instability
Replies: 2
Views: 749

Re: SFP instability

I use the CRS328, CRS317, and RB4011, and several other MikroTik products with the FS modules with rOS v6. Working well. Using SFP-10GLRM-31 , and the red blue combo SFP-10G-BX BiDi models, among others. All with OS2 fiber, some simplex, some duplex. If you do upgrade to rOS v7, upgrade the RouterBo...
by pcunite
Thu May 12, 2022 3:22 pm
Forum: Announcements
Topic: NEWSLETTER 105
Replies: 53
Views: 39134

Re: NEWSLETTER 105

I hope that the new logo is just a bad joke. It must be...

I think it looks really nice. Very professional, tidy, and to the point. The new font is really nice.
by pcunite
Thu May 12, 2022 3:21 pm
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 65041

Re: v7.2.2 [stable] and v7.2.3 [stable] are released!

Known issues are forum tribal know-how distributed among thousands of forum entries and hidden behind a poor forum search ...It is no wonder the same issues and bugs are reported and asked about again and again ... I really enjoy MikroTik products personally, but can hardly recommend them to others...
by pcunite
Thu May 12, 2022 1:27 am
Forum: Useful user articles
Topic: New User Pathway To Config Success
Replies: 55
Views: 22733

Re: NEW USER PATHWAY TO CONFIG SUCCESS

Not sure what you mean?
Routing traffic out a specific WANIP, should not interfere with LAN to LAN traffic or VLAN to VLAN traffic which is more controlled by firewall rules.

I may have something mis-configured. Will test and report back.
by pcunite
Thu May 12, 2022 1:12 am
Forum: Useful user articles
Topic: New User Pathway To Config Success
Replies: 55
Views: 22733

Re: NEW USER PATHWAY TO CONFIG SUCCESS

A question about Section J. DIRECTING Users out Specific WAN . Say I'm directing a specific IP address out WAN2 (10.2.2.2 is a VoIP server). That's great, however, the LAN can no longer access it. So, do I need a rule like this? /ip route rule add action=lookup-only-in-table dst-address=10.2.2.0/24 ...
by pcunite
Fri May 06, 2022 2:46 am
Forum: Beginner Basics
Topic: VLANs on CRS326 - how hard can this be?
Replies: 3
Views: 550

Re: VLANs on CRS326 - how hard can this be?

See my signature.
by pcunite
Thu May 05, 2022 1:21 am
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 65041

Re: v7.2.2 [stable] and v7.2.3 [stable] are released!

@ work, we run everything v6, except 1 device with v7 for WireGuard.

Same. Needed to provide VPN (WireGuard) for a client so I went with a dedicated device running v7.2.1.
by pcunite
Wed May 04, 2022 8:09 pm
Forum: RouterBOARD hardware
Topic: Device request CRS318-16P-2S+RM
Replies: 12
Views: 1194

Re: Device request CRS318-16P-2S+RM

Is unapproved because you do not use two C14, one for low, and one for high voltage... :roll:

:-p
by pcunite
Wed May 04, 2022 4:39 pm
Forum: RouterBOARD hardware
Topic: Device request CRS318-16P-2S+RM
Replies: 12
Views: 1194

Re: Device request CRS318-16P-2S+RM

I requested one but named it incorrectly.
by pcunite
Tue May 03, 2022 7:09 pm
Forum: General
Topic: Best ACCESS POINT
Replies: 12
Views: 1016

Re: Best ACCESS POINT

I'm not an expert on wifi products from MikroTik, but I have done a large rollout. I used about twenty wAP ac units and two NetMetal ac2 units. We covered a campus of about ten buildings. Client had 30/30 fiber to the premises in a remote area. However, I've not used MikroTik in wifi in noisy (radio...
by pcunite
Tue May 03, 2022 3:29 am
Forum: Useful user articles
Topic: New User Pathway To Config Success
Replies: 55
Views: 22733

Re: NEW USER PATHWAY TO CONFIG SUCCESS

I have to confess something ... <SNIP> ... it's completely different to create serious quality document ... Great points. Yeah, sometimes I check out the forums to decompress too. And making a website with perfect configurations is a lot of effort! If you have a full time life, its just another thi...
by pcunite
Mon May 02, 2022 10:15 pm
Forum: RouterBOARD hardware
Topic: Is 'wAP R ac' + 'R11e-LTE-US' good choice for US/Canada?
Replies: 3
Views: 611

Re: Is 'wAP R ac' + 'R11e-LTE-US' good choice for US/Canada?

I'm working on a product and testing with the wAP R ac. I'm sure you're familiar with the other notable hardware options. I'll probably go with the Netmetal 5 ac. Yes, I think its fine for what it is, a fully enclosed unit. For my needs, I will need a different modem too. Probably going to go with t...
by pcunite
Mon May 02, 2022 9:43 pm
Forum: Useful user articles
Topic: New User Pathway To Config Success
Replies: 55
Views: 22733

Re: NEW USER PATHWAY TO CONFIG SUCCESS

I am trying to make things easier for beginners and helping them on a journey to understand what the config means, which is more important than getting it right the first time (copy and pasting someone else's works doesn't get one very far as I can attest too) Very true. The VLAN article in many wa...
by pcunite
Mon May 02, 2022 9:31 pm
Forum: Useful user articles
Topic: New User Pathway To Config Success
Replies: 55
Views: 22733

Re: NEW USER PATHWAY TO CONFIG SUCCESS

Not as knowledgeable as the others but I can proof-read. Easier with time-zone differences too. All of our past experiences bring something to the table. I'm involved with MikroTik mostly from dealing with phone systems. I'm extremely weak in other areas. When I need help, I'm lost really quick. I ...
by pcunite
Mon May 02, 2022 8:57 pm
Forum: Useful user articles
Topic: New User Pathway To Config Success
Replies: 55
Views: 22733

Re: NEW USER PATHWAY TO CONFIG SUCCESS

One thing is to think about the audience and intentions. I am trying to make things easier for beginners and helping them on a journey to understand what the config means, which is more important than getting it right the first time (copy and paste someone elses works doesnt get one very far as I c...
by pcunite
Mon May 02, 2022 7:04 pm
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 65041

Re: v7.2.2 [stable] is released!

Having developed SW myself for many years, I really wonder how MT manages to produce such blunders again and again. Sorry MikroTik, but something with your SW dev and test processes is more than broken. I have a software development background too. There is a lot to like about MikroTik. If we step ...
by pcunite
Mon May 02, 2022 5:30 pm
Forum: Useful user articles
Topic: New User Pathway To Config Success
Replies: 55
Views: 22733

Re: NEW USER PATHWAY TO CONFIG SUCCESS

There are so many good solutions found in the forums that should be gathered to a common place as "best practice" or something like it. Or maybe Sob/Sindy might want to write "the" book "RoS Best Practice"... I like, "MikroTik, the definitive guide" :-) Well,...
by pcunite
Mon May 02, 2022 3:23 pm
Forum: Useful user articles
Topic: New User Pathway To Config Success
Replies: 55
Views: 22733

Re: NEW USER PATHWAY TO CONFIG SUCCESS

Yes there may be some ways around it, but until someone like pcunite plays with it, tests it, finds the boundary conditions etc etc, then the guidance wont change. An article is not good enough. Of course if Sindy provides the guidance, then I wont have to wait for pcunite. :-) I know so very littl...
by pcunite
Sat Apr 30, 2022 3:45 am
Forum: Useful user articles
Topic: New User Pathway To Config Success
Replies: 55
Views: 22733

Re: NEW USER PATHWAY TO CONFIG SUCCESS

@pcunite: Multi WAN and rp-filter=strict are not friends. Oh my goodness. The rp-filter manual states: Warning: strict mode does NOT work with routing tables . Opps! Now that I've changed this, I can access internal servers now from both WAN ports! Woo-hoo! Adding input/output rules took care of pi...
by pcunite
Fri Apr 29, 2022 9:57 pm
Forum: Forwarding Protocols
Topic: Multi WAN Connection Tracking
Replies: 17
Views: 1746

Re: Multi WAN Connection Tracking

IDK how to do that...? From within the Winbox GUI tool, open up the menu item "New Terminal". Then type the following command: export file="Export.rsc" . Then navigate to the "Files" menu option and you'll note the newly exported configuration. Right click on it and do...
by pcunite
Fri Apr 29, 2022 9:38 pm
Forum: Forwarding Protocols
Topic: Multi WAN Connection Tracking
Replies: 17
Views: 1746

Re: Multi WAN Connection Tracking

This was the answer! Thank you so much tdw and mrz for you assistance! Once I added the rest of the mark rules the routing I had already setup worked. I've been working on this for WAY too long and you all got me where I needed to be. Thanks! May I see your configuration? I'm in this same boat and ...
by pcunite
Fri Apr 29, 2022 3:41 pm
Forum: Useful user articles
Topic: New User Pathway To Config Success
Replies: 55
Views: 22733

Re: NEW USER PATHWAY TO CONFIG SUCCESS

I'm attempting to configure the Multi-WAN Input To Servers (with mangling) option. I appeal for assistance as I'm unable to get this to work. Ether1 is ISP1, Ether3 is ISP3, (Ether2 is not plugged in at the moment). While pinging ISP3's static IP, I can see ping attempts being counted in the followi...
by pcunite
Wed Apr 27, 2022 9:46 pm
Forum: Useful user articles
Topic: New User Pathway To Config Success
Replies: 55
Views: 22733

Re: NEW USER PATHWAY TO CONFIG SUCCESS

I get that, but I need to understand the requirements to talk about the config ... PCUNITE, see new paragraph K! Excellent! I shall test this soon. So, you are correct, I need an example. I shall present one here: Some customers don't actively use fail-over and they don't actively load balance, not...
by pcunite
Wed Apr 27, 2022 4:19 pm
Forum: RouterBOARD hardware
Topic: Best Device for duel sim with failover
Replies: 1
Views: 378

Re: Best Device for duel sim with failover

Not qualified to answer the question yet. I'm going through the process of setting up failover to cellular with a wAP R ac . Final solution will probably be a NetMetal ac2 or LtAP . I'm working with three ISP WAN connections at the moment: PPPoE over 2.4Ghz, cellular, and a T1. I think that within t...
by pcunite
Wed Apr 27, 2022 4:03 am
Forum: RouterBOARD hardware
Topic: Device request CRS318-16P-2S+RM
Replies: 12
Views: 1194

Re: Device request CRS318-16P-2S+RM

Yes, need it.
by pcunite
Sun Apr 24, 2022 2:05 am
Forum: Useful user articles
Topic: New User Pathway To Config Success
Replies: 55
Views: 22733

Re: NEW USER PATHWAY TO CONFIG SUCCESS

Unless I misunderstood the request, multi-WAN router with e.g. 1.2.3.4 on WAN1 and 2.3.4.5 on WAN2, internal webserver with forwarded ports 80 and 443, and it should be possible to reach it using both public addresses. I can paint at least 5 different scenarios and its up to pcunite to come clean o...
by pcunite
Sat Apr 23, 2022 10:38 pm
Forum: Useful user articles
Topic: New User Pathway To Config Success
Replies: 55
Views: 22733

Re: NEW USER PATHWAY TO CONFIG SUCCESS

anav, I'm really enjoying your IP ROUTE - Multi-WAN section. I appreciate the updates and clarification. Its a lot of work to produce something like this, keeping things as simple as possible. Would like to see support added for how to allow Multi-WAN inbound support (ROS v6 & v7) too. This requ...
by pcunite
Sat Apr 23, 2022 6:54 am
Forum: Useful user articles
Topic: Isn't there any moderator/support section? Topic is solved
Replies: 38
Views: 3468

Re: Isn't there any moderator/support section? Topic is solved

Recently there's this new wave of "smart" spammers ...

Excellent observation. I noticed something off too in certain posts and wondered what the end-game was. It is always about the link.
by pcunite
Thu Apr 14, 2022 5:42 pm
Forum: Wireless Networking
Topic: T-Mobile Band 71 (600mhz) & Mikrotik Router?
Replies: 4
Views: 1046

Re: T-Mobile Band 71 (600mhz) & Mikrotik Router?

Any success with the Quectel EC25 line of Mini PCIe cards installed in a MikroTik wAP R or NetMetal ac²? The EC25-AFX has B14 and B71 support. The EC25-AF does not include B71 (looking at their PDF anyway). Personally, I need B14 for FirstNet use on ATT.
by pcunite
Thu Apr 14, 2022 3:22 pm
Forum: Wireless Networking
Topic: FirstNet (Public Safety)
Replies: 1
Views: 442

FirstNet (Public Safety)

Does MikroTik make a cellular modem compatible product for use with FirstNet (Public Safety)? I need Band B14 support. Also, is there a miniPCIe LTE CAT6 modem with B14 support that I could install in something like a wAP R, LtAP mini, or NetMetal ac²?
by pcunite
Thu Apr 14, 2022 4:52 am
Forum: General
Topic: mikrotik website down?
Replies: 7
Views: 539

Re: mikrotik website down?

Yes, same.
by pcunite
Tue Apr 12, 2022 1:20 am
Forum: Announcements
Topic: v7.2.1 [stable] is released!
Replies: 240
Views: 36120

Re: v7.2.1 [testing] is released!

Would this fix be related to running scripts such as the ATT gateway bypass? My ATT gateway bypass was broken in 7.2 but working in 7.1.5 EDIT: Just tested on an RB4011, ATT gateway script still not working. Reverted back to 7.1.5.

What error are you getting?
by pcunite
Mon Apr 11, 2022 4:36 pm
Forum: Announcements
Topic: NEWSLETTER 105
Replies: 53
Views: 39134

Re: NEWSLETTER 105

The new logo, youtube channel, and better community outreach is good. Being in the forums is a good thing. I would also like to see maybe one resource (a person) who's focus is exploring common use cases with MikroTik products. They will write verbose documentation and maybe videos on these subjects...
by pcunite
Mon Apr 11, 2022 4:26 pm
Forum: Announcements
Topic: v7.2.1 [stable] is released!
Replies: 240
Views: 36120

Re: v7.2.1 [testing] is released!

Or, you can do what many people do: wait for some brave souls to install and test it and report the experience.

I like to wait about six months to a year before touching MikroTik firmware ... with a feather.
by pcunite
Fri Feb 04, 2022 8:58 pm
Forum: SwOS
Topic: Mikrotik CRS317-1G-16S+RM weird VLAN issue
Replies: 2
Views: 3637

Re: Mikrotik CRS317-1G-16S+RM weird VLAN issue

Can you try using RouterOS 6.48.6 Long-term?
by pcunite
Wed Jan 12, 2022 6:37 pm
Forum: General
Topic: WireGuard Best Practices
Replies: 18
Views: 4932

Re: WireGuard Best Practices

@pcunite: Keys, not certificates.

Thank you for the correction. Nebula is worth a look.
by pcunite
Tue Jan 11, 2022 9:10 pm
Forum: General
Topic: WireGuard Best Practices
Replies: 18
Views: 4932

Re: WireGuard Best Practices

So, what is the best practice? How many support engineers do you have? How many end users (total devices)? 1-100 end devices: Option A: Single server key. 100-1000 end devices: Option B: Multiple server key, 1 server per 100. 1000+ end devices: Option C: Multiple server key, 1 server per device, pl...
by pcunite
Tue Jan 11, 2022 8:14 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 259
Views: 436665

Re: Using RouterOS to QoS your network - 2020 Edition

That would also mean I should apply the same thinking for Wifi devices. Exclude the ethernet port I use for the AP from QoS on the Switch, and let the WiFi QoS be handled by the AP. If the AP hardware can handle it. However, if the AP has a fast connection to the switch or router, then let the rout...
by pcunite
Tue Jan 11, 2022 7:47 pm
Forum: General
Topic: WireGuard Best Practices
Replies: 18
Views: 4932

Re: WireGuard Best Practices

I think your question is the answer. It depends, doesn't it? At least until WireGuard is truly everywhere and automated tools are available to update clients somehow. I only have limited experience with WireGuard, but am currently using an RPi server, behind the router. I would of course like to see...
by pcunite
Tue Jan 11, 2022 4:38 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 259
Views: 436665

Re: Using RouterOS to QoS your network - 2020 Edition

Not really understanding this text from the help. Is it saying one should implement QoS on the Switch instead of the Router? Theory, best practices, and what you need. It's all a balancing act. As a rule, you should QoS as close to the end device as possible. Consider what would happen if you had c...
by pcunite
Mon Jan 03, 2022 11:26 pm
Forum: General
Topic: RouterOS bridge mysteries explained
Replies: 51
Views: 13337

Re: RouterOS bridge mysteries explained

May I join this discussion as to why ? From the very beginning, and even now, the bridge, bridge port is confusing. It will always be confusing because it is an insufficient abstraction for the people who use it. This is why @sindy can not make it any clearer. No one more capable and patient than hi...
by pcunite
Fri Dec 31, 2021 10:31 pm
Forum: General
Topic: PSE-8 and PSE-24 boards
Replies: 18
Views: 3205

Re: PSE-8 and PSE-24 boards

Ugh, need a PSE-8 for a CRS112. Seems a shame. Only port 8 does not put out PoE correctly.
by pcunite
Fri Dec 31, 2021 10:13 pm
Forum: RouterBOARD hardware
Topic: I really need POE for this CRS312-4C+8XG-RM
Replies: 12
Views: 5392

Re: I really need POE for this CRS312-4C+8XG-RM

How many ports? How many watts? PoE++ (802.3bt) is 60W or 100W. Driving that much power, what use case? Might be cheaper to build a shelf with injector bricks for just what you need. Cisco Catalyst 9300 UPoE offerings PoE Texas GBT-24-M PoE Texas GBT-24-M-53V3000W Planet Tech UPOE-1600G FS.com S5860...
by pcunite
Fri Dec 31, 2021 9:43 pm
Forum: General
Topic: Nasty bug with Procurve switchs - STP - GVRP
Replies: 4
Views: 2075

Re: Nasty bug with Procurve switchs - STP - GVRP

Weird ... this could potentially be exploited to create a Denial of Service, assuming you can make them act funny from user accessible Access ports.
by pcunite
Wed Dec 29, 2021 4:31 am
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 259
Views: 436665

Re: Using RouterOS to QoS your network - 2020 Edition

Do you have any plans to release an updated 2021 (or 2022) guide for QoS that focuses on RouterOS 7.1.1 and CAKE / FQ_Codel? I wouldn't say I have plans. Have not really used v7 enough. I'll wait until it is more mainstream unless I find some pressing need for it. WireGuard is very interesting to m...
by pcunite
Wed Dec 15, 2021 4:08 pm
Forum: General
Topic: Feature Request Switches
Replies: 6
Views: 1396

Re: Feature Request Switches

I just remembered that I found and rejected such a switch before buying the CRS328 ... Agree, the CRS328 is just about the only PoE switch in MikroTik's lineup worth buying (outside of outdoor models). I mean, the goofy 8 port with two power supplies that you have to mount somewhere? I think its re...
by pcunite
Tue Dec 14, 2021 8:56 pm
Forum: General
Topic: Feature Request Switches
Replies: 6
Views: 1396

Re: Feature Request Switches

The CRS328-24P-4S+RM is a nice switch, but way too big. Need a short depth version. The CRS326-24G-2S+RM is due an upgrade to 4 SFP+ ports.
by pcunite
Tue Dec 07, 2021 10:00 pm
Forum: General
Topic: find switch port with fluke
Replies: 8
Views: 1566

Re: find switch port with fluke

The MikroTik Neighbor Discovery protocol may not be propagating correctly based on allowed interfaces. Especially so with VLAN. In In the Winbox GUI, go to IP / Neighbor List / Discovery Settings and observe.
by pcunite
Tue Dec 07, 2021 9:48 pm
Forum: RouterBOARD hardware
Topic: MikroTik RB5009UG+S+IN
Replies: 195
Views: 79001

Re: MikroTik RB5009UG+S+IN

I plan to buy some fiber optic SFP+ modules for my RB5009. Do you have any tips, for normal user please? I've been working with fiber a great deal lately and have some experience and advice. I have an opinion that I think is applicable to what even a home user should consider. Cost is a considerati...
by pcunite
Tue Sep 14, 2021 9:38 pm
Forum: Wireless Networking
Topic: Motel internet infrastructure
Replies: 12
Views: 1716

Re: Motel internet infrastructure

Find a professional who will use MikroTik. Then yes, wire in all the AP's back to a central switch. The switch in turn will be controlled by a MikroTik router. Always MikroTik, all the time. Working on an installation now with twenty wAP AC units. Going well.
by pcunite
Fri Sep 10, 2021 9:51 pm
Forum: General
Topic: MikroTik news and rumours – Chateau 5G & cAP ac XL
Replies: 12
Views: 2212

Re: MikroTik news and rumours – Chateau 5G & cAP ac XL

The exterior design is fine, don't want them to even look like something conspicuous. However, 16mb, and lack of new specs. Well, you can see the response from their customer base.
by pcunite
Thu Sep 09, 2021 1:12 am
Forum: Announcements
Topic: Newsletter 101
Replies: 43
Views: 17518

Re: Newsletter 101

What is up with MikroTik hardware production? Nobody has parts in stock and its getting pushed to December. Like the CRS328 PoE switch.
by pcunite
Fri Aug 20, 2021 3:05 pm
Forum: Announcements
Topic: Newsletter 101
Replies: 43
Views: 17518

Re: Newsletter 101

No need for IPSec because Wireguard rules the world now … the RB5009 is not enterprise gear where IPSec is the standard … home users love 💕 WireGuard. SMB will also love wireguard …. It’s becoming a WireGuard world. Agreed, the push is on. I'm using it, nay, forcing its use. :-) I did have an issue...
by pcunite
Thu Aug 19, 2021 5:08 pm
Forum: General
Topic: New to Mikrotik - need help
Replies: 12
Views: 909

Re: New to Mikrotik - need help

If I may, I hope I can help to clear up some confusion. We can help you better if you speak more about your application and less about networking. Sindy can handle that part for you, he is an expert in that domain. So, reading between the lines, it seems like you might be linking GMRS repeaters over...
by pcunite
Thu Aug 19, 2021 4:31 pm
Forum: General
Topic: Help to export certificates
Replies: 5
Views: 5208

Re: Help to export certificates

Can you do it in the GUI Winbox interface?
by pcunite
Thu Aug 05, 2021 5:07 am
Forum: Beginner Basics
Topic: Dual WAN Failover Script Ping Command [SOLVED]
Replies: 33
Views: 17352

Re: Dual WAN Failover Script Ping Command [SOLVED]

pcunite, I do not understand what you are discussing regarding clearing connections. Is this something I should be worried about on my setup? Well, I don't know. It comes down to how ISP1 fails and the applications you are using. After the failover to the different ISP, if your application times ou...
by pcunite
Wed Aug 04, 2021 10:05 pm
Forum: Beginner Basics
Topic: Dual WAN Failover Script Ping Command [SOLVED]
Replies: 33
Views: 17352

Re: Dual WAN Failover Script Ping Command [SOLVED]

I do not insist further, I have already written you the script that does the right job, based on the real traffic of equipment in production and not only theoretically simulated. Its okay, I can sort it out. If you have a ping session, not stop (ping 8.8.8.8 -t), when the change over occurs it will...
by pcunite
Wed Aug 04, 2021 6:52 am
Forum: Beginner Basics
Topic: Dual WAN Failover Script Ping Command [SOLVED]
Replies: 33
Views: 17352

Re: Dual WAN Failover Script Ping Command [SOLVED]

If just one connection on connection tracking is already closed for timeout (or other reasons) during the execution of the clean, the script will stop with error because the connection is already closed, and do not finish his works. Okay, if that is the case, would it be possible to close connectio...
by pcunite
Wed Aug 04, 2021 4:38 am
Forum: RouterOS beta and rc versions
Topic: Feature Request: Shared VLAN Learning (SVL)
Replies: 2
Views: 1033

Re: Feature Request: Shared VLAN Learning (SVL)

Can you provide a link to the document you are referring to? What I understand about the benefits of an Asymmetric VLAN ( after searching ) is that you can have two VLANs in the same broadcast domain. You don't need a router as packets actually get switched. You can have a custom MAC table with two ...
by pcunite
Wed Aug 04, 2021 3:56 am
Forum: Beginner Basics
Topic: Dual WAN Failover Script Ping Command [SOLVED]
Replies: 33
Views: 17352

Re: Dual WAN Failover Script Ping Command [SOLVED]

rextended, Oh my goodness. This is awesome! It works excellent. You should make a separate post about WAN Failover and update the link in your signature to point to that new dedicated topic. It takes a good while to write up topics, so no pressure. Just a grateful user. Note, I changed the timeout t...
by pcunite
Tue Aug 03, 2021 9:23 pm
Forum: Beginner Basics
Topic: Dual WAN Failover Script Ping Command [SOLVED]
Replies: 33
Views: 17352

Re: Dual WAN Failover Script Ping Command [SOLVED]

Clear connection-tracking is needed because remote address unreachable do not cause the clear of connection-tracking. What access method you use? Thank you anav and rextended for your examples and help on this subject. I'm testing in a lab using two simple MikroTik units. So, my connection method i...
by pcunite
Tue Aug 03, 2021 6:11 am
Forum: Beginner Basics
Topic: Dual WAN Failover Script Ping Command [SOLVED]
Replies: 33
Views: 17352

Re: Dual WAN Failover Script Ping Command [SOLVED]

The WAN fail over technique works properly if I clear connection tracking. Otherwise, the network appears to timeout. I tested with a long ping session to a remote host and a VPN session. Disabling the interface will automatically clear connection tracking and makes the fail over occur right away. S...
by pcunite
Sat Jul 24, 2021 4:21 am
Forum: Virtualization
Topic: Is there a guide on how to size the VM for CHR?
Replies: 5
Views: 4427

Re: Is there a guide on how to size the VM for CHR?

You could take a look at bundles made by others to get a sense of what you might need. Here is one from r0c-n0c for example.
by pcunite
Fri Jul 23, 2021 4:15 pm
Forum: Wireless Networking
Topic: wireless redirection [SOLVED]
Replies: 4
Views: 1433

Re: wireless redirection [SOLVED]

Use two (optionally) QR codes. One to connect to your free wifi, and the other to open a web link (the menu at http:10.0.10.5/index.html or whatever).
by pcunite
Tue Jul 20, 2021 4:06 am
Forum: General
Topic: WireGuard server behind NAT (MikroTik router)
Replies: 2
Views: 3859

Re: WireGuard server behind NAT (MikroTik router)

Thank you anav, I will look into your notes and see how I comply.
by pcunite
Mon Jul 19, 2021 11:29 pm
Forum: General
Topic: WireGuard server behind NAT (MikroTik router)
Replies: 2
Views: 3859

WireGuard server behind NAT (MikroTik router)

I have a WireGuard server (Ubuntu 20.04) running behind a MikroTik router at remote Network B. It seems to work well, with one exception I would like your thoughts on. I'm getting a " Destination host unreachable " reply (which shows up as an invalid packet in a firewall rule), but only fo...
by pcunite
Wed Jul 14, 2021 9:19 pm
Forum: RouterBOARD hardware
Topic: CRS328-24P-4S+RM idle power consumption
Replies: 6
Views: 6903

Re: CRS328-24P-4S+RM idle power consumption

I have been testing the CRS328-24P-4S+RM and its power characteristics with a P4400 Kill-A-Watt meter. Firmware 6.47.10 installed. Power draw: 1) 19 watts, when powered on, nothing plugged into ports, the idle state. 2) 20 watts, when one SFP+ plugged into an available port. 3) 24 watts, when all SF...
by pcunite
Tue Jul 13, 2021 3:56 pm
Forum: Useful user articles
Topic: RingCentral QoS for Mikrotik Devices
Replies: 5
Views: 4608

Re: RingCentral QoS for Mikrotik Devices

Good to see this. I use MikroTik for several reasons, but getting VoIP correct is a big part of that.
by pcunite
Mon Jul 12, 2021 7:15 pm
Forum: General
Topic: "antenna gain" missing in 6.46.8?
Replies: 83
Views: 23098

Re: "antenna gain" missing in 6.46.8?

All of this happens automatically. I was just explaining what happens. For most of the world, you will want to run within Regulatory limits. Set country, all other stuff will be automatic. Just to confirm ... I'm installing 20 wAP AC's at a client site. Naturally, the power might need to be turned ...
by pcunite
Sat Jul 10, 2021 1:02 am
Forum: RouterOS beta and rc versions
Topic: L3HW User Manual Updated
Replies: 16
Views: 3815

Re: L3HW User Manual Updated

I still don't fully understand why PVID setting is mandatory in practice. @raimondsp writes that omitting to set it keeps the default setting of pvid=1 (which we already know very well), but the argument about bridging the port with other ports with pvid=1 seems moot to me if frame-types property i...
by pcunite
Thu Jul 08, 2021 3:38 pm
Forum: RouterOS beta and rc versions
Topic: L3HW User Manual Updated
Replies: 16
Views: 3815

Re: L3HW User Manual Updated

Thank you, excited about the changes, wireguard too.
by pcunite
Thu Jul 08, 2021 12:30 am
Forum: RouterBOARD hardware
Topic: Internal power supplies instead of wall warts
Replies: 9
Views: 2693

Re: Internal power supplies instead of wall warts

I think the annoying thing about wall warts is how to properly rack them. If there was a way to tie the wall wart to the back or side of the MikroTik device, that would be enough for most of us.

Yep. Would like to have a standard (another one?) so as to make them easy to manage and replace.
by pcunite
Sat Jul 03, 2021 7:26 pm
Forum: Beginner Basics
Topic: Tunneling VLAN traffic over Wireguard
Replies: 18
Views: 7040

Re: Tunneling VLAN traffic over Wireguard

AFAIK Wireguard is a layer 3 VPN so there is no concept of VLANs - it will route packets between different subnets at each end and firewall rules can be used to restrict which subnets can communicate with each other. If you really need to extend the layer 2 domain then VxLAN, GRETAP or in the Mikro...
by pcunite
Sat Jul 03, 2021 7:25 pm
Forum: RouterBOARD hardware
Topic: Holes at the low end of the CRS product line
Replies: 10
Views: 2483

Re: Holes at the low end of the CSR product line

Part of a nine building fiber rollout. Need switches with at least three SFP+ ports on them, PoE for 12'ish devices and short depth. Not unreasonable. The CRS328 is just total overkill.
by pcunite
Fri Jul 02, 2021 7:45 pm
Forum: Beginner Basics
Topic: Tunneling VLAN traffic over Wireguard
Replies: 18
Views: 7040

Re: Tunneling VLAN traffic over Wireguard

Hi pcunite, I too contemplated using the raspberry pi for WG but I think your throughput will suffer if using that device?? The Raspberry Pi might not have enough horsepower, I don't know yet. I was using it as a test. Could build a Ubuntu system if necessary. Would also consider using MikroTik har...
by pcunite
Fri Jul 02, 2021 4:30 pm
Forum: Beginner Basics
Topic: CRS326-24S+2Q+: IGMP-Snooping, Bridges, VLAN
Replies: 6
Views: 1081

Re: CRS326-24S+2Q+: IGMP-Snooping, Bridges, VLAN

Not familiar with your use case.
by pcunite
Fri Jul 02, 2021 4:27 pm
Forum: Beginner Basics
Topic: Tunneling VLAN traffic over Wireguard
Replies: 18
Views: 7040

Re: Tunneling VLAN traffic over Wireguard

Nice! For the corporate side, you could simply install Wireguard on any Linux instance and port-forward to it instead of having an extra MikroTik device (unless you want or need to of course). I have done this before and it's been very stable and reliable for my usage pattern (mind you, less than 5...
by pcunite
Fri Jul 02, 2021 4:19 pm
Forum: RouterBOARD hardware
Topic: Holes at the low end of the CRS product line
Replies: 10
Views: 2483

Re: Holes at the low end of the CSR product line

Why shouldn't the CRS112-8P-4S-IN be upgraded for SFP+ now that the cost delta for SFP+ has dropped so far? Agreed. The CRS112 is a funny thing with its 8 ethernet, yet 4 SFP? A tiny switch yet you need two power supplies to make it work for all PoE needs. It is an ungainly thing. The CRS326 is wha...
by pcunite
Fri Jul 02, 2021 6:10 am
Forum: Beginner Basics
Topic: Tunneling VLAN traffic over Wireguard
Replies: 18
Views: 7040

Re: Tunneling VLAN traffic over Wireguard

I will soon be looking into a solution to enable remote staff to use physical telephony devices (VoIP phones) alongside their personal laptops running behind their home internet service plans. Allowing them to VPN into the corporate network using Wireguard, running on a MikroTik, is the goal. My thi...
by pcunite
Fri Jul 02, 2021 5:36 am
Forum: SwOS
Topic: CSS610-8G-2S+IN No Link with Cisco H10GB-ACU10M Active DAC
Replies: 10
Views: 6235

Re: CSS610-8G-2S+IN No Link with Cisco H10GB-ACU10M Active DAC

Thank you for the update.
by pcunite
Fri Jul 02, 2021 12:53 am
Forum: RouterBOARD hardware
Topic: Internal power supplies instead of wall warts
Replies: 9
Views: 2693

Re: Internal power supplies instead of wall warts

Have not used it personally, but the Middle Atlantic PD-DC-125R, seems like it would help in a rack with a lot of such equipment. The nice thing about MikroTik, most units can be PoE powered over ether1. So, you can clean up power to them using a single PoE switch.
by pcunite
Sat Jun 19, 2021 5:50 am
Forum: General
Topic: RouterOS questions
Replies: 3
Views: 863

Re: RouterOS questions

Your question is outside the use case for most of the forum members. That said, seems like the HotSpot feature is what you're asking about. Would need to be customized, I guess.
by pcunite
Sat Jun 12, 2021 1:18 am
Forum: General
Topic: SFP auto disabled due to high temperature
Replies: 6
Views: 2210

Re: SFP auto disabled due to high temperature

Interesting. As another work-around, do you think these types of heatsinks on the SFP module would help?
by pcunite
Fri Jun 11, 2021 5:57 am
Forum: SwOS
Topic: Mikrotik CRS317-1G-16S+RM to cisco 2960
Replies: 3
Views: 4556

Re: Mikrotik CRS317-1G-16S+RM to cisco 2960

Use a generic sfp module from fs.com.
by pcunite
Thu Jun 10, 2021 5:47 am
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 225
Views: 318176

Re: Using RouterOS to VLAN your network

I have a question about security or probably best practices when it comes to VLANs with WIFI: I guess setting all access ports to " admit-only-untagged-and-priority-tagged " is clearer, but is there an actual impact on network security here, or are those just two ways to do the same thing...
by pcunite
Fri Apr 16, 2021 1:26 am
Forum: General
Topic: New hack/bug? User accounts wiped
Replies: 7
Views: 1371

Re: New hack/bug? User accounts wiped

RouterOS version is 6.44.6, device is a CCR1036-8G-2S+

I think 6.44.x was vulnerable, so I don't think this is a new'ish hack. Here is a post about it. I updated to 6.47.x a while back to play it safe.
by pcunite
Fri Apr 16, 2021 1:23 am
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 225
Views: 318176

Re: Using RouterOS to VLAN your network

I disagree, I find it very confusing to have set PVID on the bridge ports and then not put the associated untagged entries on the bridge vlan. When reading a config its dirt easy visually to see what a person has done. It's so difficult to have to double check a config when not seeing the config, e...
by pcunite
Thu Apr 15, 2021 7:28 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 225
Views: 318176

Re: Using RouterOS to VLAN your network

Yes, I think that would be good. I have the same problem with the MikroTik documentation actually. The reason I feel it is bad practice to unnecessarily set the "untagged" port statically in addition to the PVID is when it comes time to make changes, you have to remember to make the chang...
by pcunite
Mon Mar 08, 2021 6:56 pm
Forum: RouterBOARD hardware
Topic: RB4011 (WiFi) and again about the stability of the work.
Replies: 5
Views: 1598

Re: RB4011 (WiFi) and again about the stability of the work.

Well, very sorry to hear of your troubles. I enjoy MikroTik products and I hate to hear such stories. I think if you could, mail it to a forum member who is very familiar with the WiFi side of thing. You know, to offer some proof to help your case. You probably really do have a bad hardware unit. Ho...
by pcunite
Wed Mar 03, 2021 10:04 pm
Forum: RouterBOARD hardware
Topic: New CRS328-16P-4S+RM rumors
Replies: 5
Views: 1882

Re: New CRS328-16P-4S+RM rumors

Not gonna happen. With that port spec, it would be CRS320-16P-4S+RM.

Well, you know how rumors are! Incorrect information. How did you arrive at CRS320?
by pcunite
Wed Mar 03, 2021 8:56 pm
Forum: Wireless Networking
Topic: 25Km distance, devices to get 100+Mbps PTP link?
Replies: 2
Views: 858

Re: 25Km distance, devices to get 100+Mbps PTP link?

Use the PTP Calulator this link to see options involving frequency and distance.
by pcunite
Wed Mar 03, 2021 8:49 pm
Forum: RouterBOARD hardware
Topic: New CRS328-16P-4S+RM rumors
Replies: 5
Views: 1882

New CRS328-16P-4S+RM rumors

Look at what showed up on my desktop today! Wonder if it is going to be true? I could really use this switch model.



Image
by pcunite
Mon Feb 22, 2021 10:35 pm
Forum: Beginner Basics
Topic: Problem with new 3gb/s connection with RB4011, I can ping but now browse
Replies: 10
Views: 1085

Re: Problem with new 3gb/s connection with RB4011, I can ping but now browse

MikroTik S+31DLC10D module. So, sfp connected between fiberbox and rb4011, network cable between fiberbox and rb4011. What gives you confidence that the SFP is compatible with the fiberbox? Previously you have an RJ45 connection. That SFP module is single mode 1310nm. Is your ISP good with that? Lo...
by pcunite
Mon Feb 22, 2021 9:38 pm
Forum: Beginner Basics
Topic: Problem with new 3gb/s connection with RB4011, I can ping but now browse
Replies: 10
Views: 1085

Re: Problem with new 3gb/s connection with RB4011, I can ping but now browse

All working fine when setting Wan to ether1.

What kind, brand, etc. SFP module are you using in the RB4011's SFP+ slot?
by pcunite
Mon Feb 22, 2021 9:27 pm
Forum: Beginner Basics
Topic: Problem with new 3gb/s connection with RB4011, I can ping but now browse
Replies: 10
Views: 1085

Re: Problem with new 3gb/s connection with RB4011, I can ping but now browse

How do you mean rule out? SFP+ port is set as Wan and then the rest of the network is plugged in ether 1-5. Am i doing something wrong here? No, you're not doing anything wrong. I was just stating that you might try a test with an Ethernet port to verify the issue is with the SFP port and not somet...
by pcunite
Mon Feb 22, 2021 7:04 pm
Forum: Beginner Basics
Topic: Problem with new 3gb/s connection with RB4011, I can ping but now browse
Replies: 10
Views: 1085

Re: Problem with new 3gb/s connection with RB4011, I can ping but now browse

Please try to use ether1 to rule out the SFP module. Report back.
by pcunite
Fri Feb 19, 2021 9:04 pm
Forum: Scripting
Topic: Append Bridge vlan values
Replies: 2
Views: 1068

Re: Append Bridge vlan values

Is there a reason why you explicitly set the untagged= parameter as this will be dynamically populated. I am considering removing lines referencing the untagged member because of the reasons you note. I also needed to set the tagged member as well. I really appreciate the help. I'm looking into how...
by pcunite
Fri Feb 19, 2021 6:12 am
Forum: Scripting
Topic: Append Bridge vlan values
Replies: 2
Views: 1068

Append Bridge vlan values

I'm attempting to set some values under the /interface bridge vlan command, namely the untagged property. Normally, I set this like so: set bridge=BR1 tagged=ether4 [find vlan-ids=10] . However, I need a way to append the value to what is already present. Here's what I've cobbled together so far, bu...
by pcunite
Thu Feb 18, 2021 11:11 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 225
Views: 318176

Re: Using RouterOS to VLAN your network

One thing I do not like about the configuration shown in the examples up at the top (which are otherwise very good) is that it has unnecessary use of the "untagged" setting. @mducharme What if I put in a disclaimer, stating it was unnecessary and handled automatically? This article series...
by pcunite
Thu Feb 18, 2021 11:02 pm
Forum: Wireless Networking
Topic: MİkroTik Wireless Gig+ Test
Replies: 14
Views: 2471

Re: MİkroTik Wireless Gig+ Test

Intel AX200 connected at 1.2Gbit/s at Aruba AP-555 with 80 MHz channel == stable 800 Mbit/s up and down while copy a big file to and from a SMB file server.

Tell the rest of the class what you paid for the Aruba.
by pcunite
Mon Feb 15, 2021 4:42 pm
Forum: Announcements
Topic: v6.47.9 [long-term] is released!
Replies: 73
Views: 40897

Re: v6.47.9 [long-term] is released!

The PoE issue was introduced in 6.46.8, as the comments from that release prove it.

Using a hEX PoE to power two Dahua SD1A203T-GN. PoE set to auto on. Firmware v6.47.9 without issue. I think these units are 2 or 3 years old. Factory firmware was 6.42.7.
by pcunite
Sun Feb 14, 2021 10:40 pm
Forum: RouterBOARD hardware
Topic: Which ROS devices do you expect the most?
Replies: 17
Views: 3828

Re: Which ROS devices do you expect the most?

A CRS326-24G with 4 SFP+ ports. A 16 port ethernet short depth version of the CRS328-24P.
by pcunite
Sat Feb 13, 2021 4:01 pm
Forum: General
Topic: Windows 10 unable to connect to IPSEC/IKE2 VPN
Replies: 6
Views: 4225

Re: Windows 10 unable to connect to IPSEC/IKE2 VPN

See my post here.
by pcunite
Fri Feb 12, 2021 5:33 pm
Forum: Beginner Basics
Topic: Inter-vlan routing and default firewall
Replies: 4
Views: 1957

Re: Inter-vlan routing and default firewall

This surely wins an award as the longest first post ever. Well done simpleIT! You win a prize! Cozy up to a fireplace and read the provided material anav has linked for you. Read slowly, its all there.
by pcunite
Thu Feb 11, 2021 6:58 am
Forum: Beginner Basics
Topic: 10G Port for Uplink
Replies: 2
Views: 717

Re: 10G Port for Uplink

It might be best for you to read my VLAN tutorial, linked in my signature. Read slowly. It will all make sense. It shows how to mange all devices on the network. How to setup everything from scratch.
by pcunite
Thu Feb 11, 2021 6:31 am
Forum: Wireless Networking
Topic: wAP ac lte kit passthrough to rb4011 with vlans
Replies: 2
Views: 754

Re: wAP ac lte kit passthrough to rb4011 with vlans

You only need to create an SSID that represents each VLAN. See post here for examples.
by pcunite
Wed Feb 10, 2021 5:27 pm
Forum: Announcements
Topic: v6.47.9 [long-term] is released!
Replies: 73
Views: 40897

Re: v6.47.9 [long-term] is released!

I upgraded a hAP mini from 6.47.8 and got the same WiFi problem as with 6.48, fixed by downgrading.

After upgrading RouterOS and RouterBOARD, then doing a reset, then adding back your config via console, do you still have the same issues?
by pcunite
Wed Feb 10, 2021 5:23 pm
Forum: General
Topic: Performance issues with 6.48 and 6.48.1 on ARM/RB4011
Replies: 2
Views: 1148

Re: Performance issues with 6.48 and 6.48.1 on ARM/RB4011

What is the observed behavior under 6.47.9?
by pcunite
Wed Feb 10, 2021 5:12 pm
Forum: Announcements
Topic: v6.47.9 [long-term] is released!
Replies: 73
Views: 40897

Re: v6.47.9 [long-term] is released!

Upgraded from 6.44 and 6.46 and went largely without incident. Mix of RB4011, RB3011, RB2011, hAP ac lite, hEX PoE, CRS112-8P, CRS326-24G, hAP ac, hAP ac², wAP ac, and cAP ac. This feels like a good update. Time will tell. I miss antenna gain on the AP's but at least can get to it via CLI.
by pcunite
Tue Feb 09, 2021 7:14 pm
Forum: Scripting
Topic: Automatic startup mikrotik
Replies: 3
Views: 1249

Re: Automatic startup mikrotik

Use a remotely controllable power outlet, like this, this, or this.
by pcunite
Sat Feb 06, 2021 11:29 pm
Forum: RouterBOARD hardware
Topic: 10G Fiber run of 700m, which SFP+ module and cable?
Replies: 6
Views: 1998

Re: 10G Fiber run of 700m, which SFP+ module and cable?

Thank you! This is very interesting. I do have the option of specifying the cabling. Can I use use simplex single strand LC-LC cables everywhere? Even for short runs? Naturally, I'll do what is cheaper, but to have BiDi duplex over single strand can I buy OS2 9/125, single strand single mode cables ...
by pcunite
Sat Feb 06, 2021 5:13 am
Forum: RouterBOARD hardware
Topic: 10G Fiber run of 700m, which SFP+ module and cable?
Replies: 6
Views: 1998

10G Fiber run of 700m, which SFP+ module and cable?

I have an upcoming project to where I will require a fiber run in excess of 300m. Probably about 620 meters distance. I would like to be able to maintain a 10G link between the buildings if possible. I only have experience with 850nm Dual LC modules (like the S-85DLC05D) with 50/125 OM3 LC-LC style ...
by pcunite
Sat Jan 02, 2021 3:10 am
Forum: General
Topic: VLANs, CAPsMAN and the case of the missing DHCP
Replies: 3
Views: 649

Re: VLANs, CAPsMAN and the case of the missing DHCP

Your example configuration script does not provide enough context. I recommend you study the article you linked first, get it working correctly, before trying to add a CAPsMAN into the mix. The reason you can't broadcast DHCP requests could be because of a couple of reasons. I would need to see how ...
by pcunite
Fri Dec 04, 2020 7:10 pm
Forum: General
Topic: "antenna gain" missing in 6.46.8?
Replies: 83
Views: 23098

Re: "antenna gain" missing in 6.46.8?

normis says: You can adjust Tx-power by selecting "all rates fixed" in Tx Power Mode and afterwards setting a lower Tx power.

Would it be possible to bring back Antenna Gain or something similar? I need a simple way to lower power.
by pcunite
Thu Dec 03, 2020 11:51 pm
Forum: General
Topic: "antenna gain" missing in 6.46.8?
Replies: 83
Views: 23098

Re: "antenna gain" missing in 6.46.8?

Antenna-gain is now a CLI-only parameter.

Why?
by pcunite
Mon Oct 26, 2020 5:10 pm
Forum: Scripting
Topic: Mikrotik Scripting needs to be useful! Requests!
Replies: 5
Views: 1227

Re: Mikrotik Scripting needs to be useful! Requests!

Agree, I wish there was a proper onboard API to control them.
by pcunite
Sun Oct 25, 2020 2:47 am
Forum: Beginner Basics
Topic: Problems with vlan interface [SOLVED]
Replies: 2
Views: 956

Re: Problems with vlan interface [SOLVED]

Good to hear. The 2011 units are under powered.
by pcunite
Fri Oct 23, 2020 8:25 pm
Forum: General
Topic: CCR2004-1G-12S+2XS - ATT Residential Fiber Termination via ONT
Replies: 3
Views: 1048

Re: CCR2004-1G-12S+2XS - ATT Residential Fiber Termination via ONT

A discussion with interested individuals is occurring here.
by pcunite
Fri Oct 23, 2020 2:08 am
Forum: General
Topic: PSA: Trickbot is using compromised Mikrotik devices. Secure your routers reachable from the internet.
Replies: 18
Views: 3145

Re: PSA: Trickbot is using compromised Mikrotik devices. Secure your routers reachable from the internet.

Unfortunately that is inconclusive. The CVE says "6.41.3 through 6.46.5, and 7.x through 7.0 Beta5" which would potentially include 6.46.1. Unfortunately I've never seen MT publish their software development hierarchy so I'm not sure. Additionally, they haven't posted any further details ...
by pcunite
Thu Oct 22, 2020 11:44 pm
Forum: General
Topic: PSA: Trickbot is using compromised Mikrotik devices. Secure your routers reachable from the internet.
Replies: 18
Views: 3145

Re: PSA: Trickbot is using compromised Mikrotik devices. Secure your routers reachable from the internet.

All MikroTik routers should be running
6.47.4 [stable]
6.46.6 [long-term]
or 7.0beta6 [testing]
due to CVE-2020-11881

Please confirm 6.46.1 (stable) is unaffected.
by pcunite
Thu Oct 22, 2020 12:49 am
Forum: Wireless Networking
Topic: What MT boxes can support spectral scan? - Cheap spectrum analyzer instead? [SOLVED]
Replies: 23
Views: 4698

Re: What MT boxes can support spectral scan? - Cheap spectrum analyzer instead? [SOLVED]

To run the scan on Groove there are prerequisites

Thanks for sharing. To confirm, can't scan on 5Ghz via Winbox? Have to use Dude?
by pcunite
Sat Oct 17, 2020 6:34 am
Forum: General
Topic: HAP AC Wired and Wireless VLAN CPU optimisation
Replies: 8
Views: 1059

Re: HAP AC Wired and Wireless VLAN CPU optimisation

Sure, but does the RB3011 have wifi? I think he wants devices at both sites to provide wifi!

Sorry, yes the hAP AC2 would be better in his scenario.
by pcunite
Fri Oct 16, 2020 12:54 am
Forum: General
Topic: HAP AC Wired and Wireless VLAN CPU optimisation
Replies: 8
Views: 1059

Re: HAP AC Wired and Wireless VLAN CPU optimisation

MikroTik has too many SKUs. For 100mb service, consider the RB3011 or better the RB4011. Hang the Wifi AP's off available ports.
by pcunite
Wed Sep 23, 2020 4:46 pm
Forum: Beginner Basics
Topic: AT&T FTTH, VLANs, CapsMAN Full Config
Replies: 18
Views: 3788

Re: AT&T FTTH, VLANs, CapsMAN Full Config

Appreciate the great effort here. You have put the work into this. The information about how to configure these devices needs to be more open, more clear, and easily digestible. This will help to move that forward. An entire topic should be spent on Service Discovery between VLANs, I should think.
by pcunite
Wed Sep 23, 2020 4:15 pm
Forum: Announcements
Topic: Newsletter 97 (September 2020)
Replies: 87
Views: 33326

Re: Newsletter 97 (September 2020)

Excellent videos! Good to see the team and the products, puts a human touch behind the brand. Please consider making a 16 port PoE switch as described.
by pcunite
Tue Sep 08, 2020 11:39 pm
Forum: Useful user articles
Topic: Using RouterOS to VLAN your network
Replies: 225
Views: 318176

Re: Using RouterOS to VLAN your network

... getting some pushback of late on the use of pvid and the associated bridge vlan settings ... personally I think its clearer when configuring and reading to have the bridge vlan settings visible. Is there any downside to RELYING on the dynamically generated settings? This is why I initially show...
by pcunite
Tue Sep 01, 2020 3:27 pm
Forum: RouterBOARD hardware
Topic: 16 port short depth PoE switch
Replies: 9
Views: 1829

Re: 16 port short depth PoE switch

No, not RB4011 again ... They really should produce one device with two different cases (IN and RM), just like they did with RB2011 or certain models of CCR1009... The ears on the RB4011 are bad, yes. However, the one that ships with the CRS112 is really nice. But yes, a pure rack-mount would be ap...
by pcunite
Mon Aug 31, 2020 9:22 pm
Forum: RouterBOARD hardware
Topic: 16 port short depth PoE switch
Replies: 9
Views: 1829

Re: 16 port short depth PoE switch

A crs318-16P-2S+ would be great. I would like it in an "IN" desktop form factor, although I am sure a RM version would be popular too.

They could make some ears to accommodate us both. I think it is a needed SKU.
by pcunite
Sat Aug 29, 2020 6:07 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 259
Views: 436665

Re: Using RouterOS to QoS your network - 2020 Edition

@pcunite thanks for doing this. I've noticed a few things that I'd like your input on. @blurrybird, >>why you are detecting VoIP by just blanket accepting 10,000+ ports? The original article was created a long time ago. The VoIP equipment I used at the time used those range of ports. I think it is ...
by pcunite
Fri Aug 28, 2020 11:28 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 232
Views: 94669

Re: Bypassing AT&T Residential Gateways with MikroTik

I can no longer recommend the RB4011 as I've been getting the issue described here with it hitting 100% CPU, freezing up, etc. I'm at very low load (residential), but still happens what seems like once a month now. Going back to the CCR1009 that I didn't sell, yet, along with the switch. Sorry to h...
by pcunite
Fri Aug 28, 2020 11:25 pm
Forum: RouterBOARD hardware
Topic: 16 port short depth PoE switch
Replies: 9
Views: 1829

16 port short depth PoE switch

I need an improved CRS112-8P-4S-IN rackmount switch. I see that the netPower 16P is close to what I would want, hardware wise, but in an incompatible design for my needs. The CRS328-24P-4S+RM is too big. Any news of a possible CRS328-16P-4S+RM on the horizon?
by pcunite
Fri Aug 28, 2020 11:12 pm
Forum: Useful user articles
Topic: Using RouterOS to QoS your network - 2020 Edition
Replies: 259
Views: 436665

Re: Using RouterOS to QoS your network - 2020 Edition

I have been wading thru this thread since the 2013 beginning looking for a "final" recommended way to provide the QoS to make a couple of VOIP phones to work. But that appears not to be. My configuration, as shown, is what you are looking for. It works. I use it on multiple networks. Don'...
by pcunite
Fri Jul 03, 2020 12:15 am
Forum: Beginner Basics
Topic: RB3011 Second Switch as another router
Replies: 2
Views: 986

Re: RB3011 Second Switch as another router

Absolutely, that is the purpose of this hardware. If you have a speed issue, as pointed out, then you can make adjustments. Keep everything on the same switch group if you can, then it can hit the CPU to get out to WAN. If you need to hit the other bridge, I don't think it will be that bad for one o...
by pcunite
Sat Jun 27, 2020 12:17 am
Forum: Announcements
Topic: MikroTik newsletter May 2020 (#95)
Replies: 50
Views: 39919

Re: MikroTik newsletter May 2020 (#95)

I just find out that netPower 16P is CRS318-16P-2S+OUT. So, we suggest mikrotik can release CRS318-16P-2S+IN-2HnD.

Yes, this could be the update to the CRS112-8P-4S-IN.
by pcunite
Thu Jun 25, 2020 6:54 pm
Forum: General
Topic: Cert cannot be imported on IOS13
Replies: 4
Views: 1481

Re: Cert cannot be imported on IOS13

Things have changed with iOS 13 and macOS 10.15. Study the link. You can use a tool like CertManEX to create these new types or openssl.
by pcunite
Sun May 31, 2020 2:15 am
Forum: Wireless Networking
Topic: Additional Security for Wifi Devices.
Replies: 5
Views: 2107

Re: Additional Security for Wifi Devices.

You can be as restrictive as you feel you need to be. What is the threat vector? Are you protecting access from neighbors (don't have valid access credentials) or clients within (do have credentials)? * Turn the power down to prevent signals escaping the home. Use more low power units to fill in gap...
by pcunite
Thu May 21, 2020 10:01 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 232
Views: 94669

Re: Bypassing AT&T Residential Gateways with MikroTik

Official Response from MT Support: How would you expect to treat VLAN-ID 0 packets in RouterOS? Should we allow the users to configure a special-purpose VLAN interface that accepts these packets? How should RouterOS respond - with or without VLAN-ID 0 header? Glad to see them thinking about it. I d...
by pcunite
Wed May 20, 2020 10:38 pm
Forum: Beginner Basics
Topic: Assign unique DHCP server to an AP?
Replies: 3
Views: 990

Re: Assign unique DHCP server to an AP?

Study VLAN techniques as noted in my signature.
by pcunite
Fri May 15, 2020 1:37 am
Forum: General
Topic: Dot1x Client improper start frame version
Replies: 2
Views: 1499

Re: Dot1x Client improper start frame version

Thank you.
by pcunite
Thu May 14, 2020 12:06 am
Forum: RouterBOARD hardware
Topic: What is your opinion of Mikrotik routers?
Replies: 3
Views: 1952

Re: What is your opinion of Mikrotik routers?

I like how they use just enough power to accomplish the goal. I didn't want big beefy hardware, unless I needed it. Take the RB4011 for example, handles 1G fiber service just fine on small networks.
by pcunite
Thu May 14, 2020 12:02 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 232
Views: 94669

Re: Bypassing AT&T Residential Gateways with MikroTik

The best option would be for the bridge to be able to strip VLAN 0, but isn't that something MT needs to fix?

Its not so much a fix, as it is additional functionality we want.
by pcunite
Fri May 08, 2020 10:12 pm
Forum: RouterBOARD hardware
Topic: RB5011
Replies: 40
Views: 20397

Re: RB5011

+2
Make two case options, a proper rack-mount, and a nice desktop version.
by pcunite
Fri May 08, 2020 10:10 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 232
Views: 94669

Re: Bypassing AT&T Residential Gateways with MikroTik

I want to clarify with some information provided to me. The ATT Residential RG sends all outgoing packets as 802.1p (tagged with VLAN 0). Their Commercial gateways sends all outgoing packets as 802.1q PVID 2 (tagged with VLAN 2). These are not always enforced, as I understand it. My residential 1G f...
by pcunite
Fri May 08, 2020 6:51 pm
Forum: RouterBOARD hardware
Topic: CCR2004-1G-12S+2XS with more RAM ?
Replies: 15
Views: 7375

Re: CCR2004-1G-12S+2XS with more RAM ?

Can someone measure its idle power usage? Preferably with one or two 10g ports connected (optical sfp+ or DAC).
Also, how loud is it under low load circumstances?

I would like to know as well. Also, if I disconnect the fans, or redundant power, can I get the power usage down?
by pcunite
Fri May 08, 2020 6:37 pm
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 232
Views: 94669

Re: Bypassing AT&T Residential Gateways with MikroTik

... for CCRs, what model switches have people been using in front it to take care of the vlan 0 tagging?

Ask wojo
by pcunite
Fri May 08, 2020 6:47 am
Forum: Useful user articles
Topic: Bypassing AT&T Residential Gateways with MikroTik
Replies: 232
Views: 94669

Re: Bypassing AT&T Residential Gateways with MikroTik

I'm surprised the hEX/RB750Gr3 isn't recommended especially for people on 300/300 or 100/100. Does it not work well with wpa_supplicant despite having a switch chip?

Recommended just means what most have reported success with. Since the RB4011 is known to work, it is therefore, recommended.