Community discussions

MikroTik App

Search found 1398 matches

by erlinden
Wed Mar 22, 2023 5:15 pm
Forum: Beginner Basics
Topic: Weird routing behavior ??
Replies: 8
Views: 289

Re: Weird routing behavior ??

Talking about weird...are you using the RB5009 as switch?
Can you share the config of it?

/export file=anynameyoulike

Make sure to remove any personal info like serial and public IP information
by erlinden
Tue Mar 21, 2023 10:07 am
Forum: General
Topic: Capsman Setup when direclty connect 2 ap on isp router
Replies: 2
Views: 383

Re: Capsman Setup when direclty connect 2 ap on isp router

CAPsMAN server can be installed on any RouterOS device , even if the device itself does not have a wireless interface: https://help.mikrotik.com/docs/pages/viewpage.action?pageId=1409149#APController(CAPsMAN)-Overview g21 Make one of the aps CAPsMAN...that's it. But you might want to consider using...
by erlinden
Tue Mar 21, 2023 9:47 am
Forum: General
Topic: Firewall input drop all except LAN
Replies: 8
Views: 277

Re: Firewall input drop all except LAN

You can disable logging on this firewall rule.
by erlinden
Mon Mar 20, 2023 6:15 pm
Forum: Wireless Networking
Topic: capsman wifiwave2 no ip
Replies: 11
Views: 384

Re: capsman wifiwave2 no ip

i not use VLAN
You want to:
Router: viewtopic.php?t=143620#p706997
Accesspoint: viewtopic.php?t=143620#p706999
by erlinden
Mon Mar 20, 2023 11:53 am
Forum: Wireless Networking
Topic: capsman wifiwave2 no ip
Replies: 11
Views: 384

Re: capsman wifiwave2 no ip

Looking at your config...sure you use CAPsMAN? I was expecting some sort of configuration (but I'm not familiair with the WAVE2 package).
What is the use of all the bridges? And why not use multiple VLAN's (which will make your life easier on the firewall)?
by erlinden
Sun Mar 19, 2023 2:37 pm
Forum: Wireless Networking
Topic: capsman wifiwave2 no ip
Replies: 11
Views: 384

Re: capsman wifiwave2 no ip

Config would be very helpful:

/export file=anynameyoulike
by erlinden
Sat Mar 18, 2023 10:39 am
Forum: Wireless Networking
Topic: Capsman Problems [SOLVED]
Replies: 9
Views: 378

Re: Capsman Problems [SOLVED]

That was the problem...but this kind of problems should never exist.
Any professional networking device will give you the possibility to change MAC addresses. It's up to the user to have it changed...or not.
by erlinden
Sat Mar 18, 2023 10:38 am
Forum: Beginner Basics
Topic: Brand new hAP ax2 is not working at all ... :(
Replies: 3
Views: 244

Re: Brand new hAP ax2 is not working at all ... :(

What does
I can't connect to 192.168.88.1. Tried on different browsers, just in case.
mean? And have you tried with SSH?
Is there a password sticker on the RB?

Don't get disappointed, RoutersOS does have a steap learning curve. But once figured out...
by erlinden
Sat Mar 18, 2023 10:33 am
Forum: Wireless Networking
Topic: Different SSID's and bands
Replies: 3
Views: 168

Re: Different SSID's and bands

Can you please share the configuration:

 /caps-man export

That will provide a lot more information (at least, I hope).
by erlinden
Thu Mar 16, 2023 5:49 pm
Forum: General
Topic: DHCP dynamic leases
Replies: 13
Views: 618

Re: DHCP dynamic leases

Would it be possible to work with a single DHCP server? Van you please explain a bit more about the environment? Roaming (makes me think of wireless clients, is this correct?), three routers and leasetimes of 7 days doesn't sound like a regular network.
by erlinden
Wed Mar 15, 2023 6:02 pm
Forum: RouterBOARD hardware
Topic: help
Replies: 4
Views: 223

Re: help

From the wiki: https://wiki.mikrotik.com/wiki/Silent_boot https://wiki.mikrotik.com/wiki/Manual:RouterBOARD_settings And the helpfiles: https://help.mikrotik.com/docs/display/ROS/RouterBOOT#RouterBOOT-Configuration https://help.mikrotik.com/docs/display/ROS/RouterBOARD#RouterBOARD-Settings Check for...
by erlinden
Wed Mar 15, 2023 4:54 pm
Forum: RouterBOARD hardware
Topic: help
Replies: 4
Views: 223

Re: help

Sounds to me like you don't have a major problem....is beeping disabled (not sure if possible)?
And is that your only problem?
by erlinden
Tue Mar 14, 2023 6:11 pm
Forum: General
Topic: Some flame around v6.48.6 (split from the "v6.48.6 [long-term] is released!" topic)
Replies: 26
Views: 362

Re: v6.48.6 [long-term] is released!

Need some help, @batot...why did you create three bridges (for which most ports are disabled)? And can you please supply some explanation on how you want your router to act? Is China blocking necessary, or could you use a whitelist mechanism?

/ip upnp
set enabled=yes

Please...don't.
by erlinden
Tue Mar 14, 2023 11:56 am
Forum: General
Topic: Add which interface to dhcp assign logging
Replies: 7
Views: 236

Re: Add which interface to dhcp assign logging

Ah...now I understand, some sort of custom logging where this information is included.
by erlinden
Tue Mar 14, 2023 11:13 am
Forum: General
Topic: Add which interface to dhcp assign logging
Replies: 7
Views: 236

Re: Add which interface to dhcp assign logging

If I look in /ip/dhcp-server/leases in Winbox, it shows the bridge port. Are these connected through wire or wireless? The latter is (in my case) not shown, while everything connected to wire is.
by erlinden
Mon Mar 13, 2023 9:29 pm
Forum: General
Topic: Some flame around v6.48.6 (split from the "v6.48.6 [long-term] is released!" topic)
Replies: 26
Views: 362

Re: v6.48.6 [long-term] is released!

I checked your earlier screenprint and noticed that you are using two bridges. If you want to use hardware offloading you should migrate to a single bridge, combined with VLAN's if necessary. Are you using queues? Are you sure you want to be helped? Can you share a config that you feel confident wit...
by erlinden
Mon Mar 13, 2023 5:39 pm
Forum: General
Topic: Possible bridge problem with v7.8?
Replies: 8
Views: 526

Re: Possible bridge problem with v7.8?

Would be helpfull if you can supply both a network diagram showing the VLAN's and a complete output of your config.
by erlinden
Mon Mar 13, 2023 4:50 pm
Forum: Beginner Basics
Topic: Can't forward ports for minecraft server
Replies: 4
Views: 192

Re: Can't forward ports for minecraft server

My best guess: you are trying to forward to your router (I assume 192.168.88.1 is your router address?).
Can you connect to 192.168.88.1:25565 if you are on your LAN?
by erlinden
Mon Mar 13, 2023 4:33 pm
Forum: General
Topic: Some flame around v6.48.6 (split from the "v6.48.6 [long-term] is released!" topic)
Replies: 26
Views: 362

Re: v6.48.6 [long-term] is released!

Theoretical if you have right, how are you explain that upgrade to version 6.49.7 resolve problem? There are more explanations, if you want a good answer can you please share the config? /export hide-sensitive file=anynameyoulike Don't forget to remove serial/public IP/other personal information
by erlinden
Mon Mar 13, 2023 2:58 pm
Forum: Scripting
Topic: problem about user name in noip.com script.
Replies: 8
Views: 345

Re: problem about user name in noip.com script.

My I ask why you don't use the buildin service in MikroTik?

/ip/cloud
by erlinden
Sat Mar 11, 2023 2:39 pm
Forum: Wireless Networking
Topic: CCR1009 with 3 cAP ac
Replies: 2
Views: 215

Re: CCR1009 with 3 cAP ac

Defnitely a misconfig, would be usefull to have an export (if you want to continu the CAPsMAN route): /caps-man export file=anynameyoulike From an admin perspective I would use CAPsMAN, especially on being able to monitor all wirelles devices in one place. But there are enough reasons to stick to st...
by erlinden
Wed Mar 08, 2023 5:57 pm
Forum: SwOS
Topic: CRS309-1G-8S+IN - From Routeros to Swos
Replies: 13
Views: 676

Re: CRS309-1G-8S+IN - From Routeros to Swos

I have more that 30 bridges...
I hope you mean 30 VLAN's? Because anything can be handled with a single bridge (and will perform better).
by erlinden
Wed Mar 08, 2023 11:58 am
Forum: Scripting
Topic: Enable and Disable IP addresses in address list [SOLVED]
Replies: 10
Views: 419

Re: Enable and Disable IP addresses in address list [SOLVED]

Love self love, might want to mark rextended as the best solution to give him the credits.
And sorry for not knowing this, learned from rextended again!
by erlinden
Wed Mar 08, 2023 8:36 am
Forum: Beginner Basics
Topic: All ports open? Connectable via telnet
Replies: 2
Views: 216

Re: All ports open? Connectable via telnet

Can you please share your complete config? /export file=anynameyoulike Remove serial and any public IP information (as well from your opening post) and any personal information. Any reason for still running this older LTS version? By default, everything on the input chain is blocked, except through ...
by erlinden
Wed Mar 08, 2023 8:34 am
Forum: RouterBOARD hardware
Topic: hAP ax2 CapsMode/WiFi issue
Replies: 6
Views: 827

Re: hAP ax2 CapsMode/WiFi issue

If you install the wifiwav2 package, wireless interfaces should be available again. Think that would be the first step.
If that is not working (and you have more goovy stuff), you might want to consider performing a netinstall.

Why did you upgrade?
by erlinden
Tue Mar 07, 2023 3:14 pm
Forum: Scripting
Topic: Enable and Disable IP addresses in address list [SOLVED]
Replies: 10
Views: 419

Re: Enable and Disable IP addresses in address list [SOLVED]

you're not accurate in your description, a script can't read your mind.
I think the TS wants to be able to enable/disable items on a list...which is, as far as I know, not possible.
Hence the idea of moving items in between 2 lists.

Unfortunately, the TS wants a script he can use immediately...
by erlinden
Tue Mar 07, 2023 12:07 pm
Forum: Scripting
Topic: Enable and Disable IP addresses in address list [SOLVED]
Replies: 10
Views: 419

Re: Enable and Disable IP addresses in address list [SOLVED]

From a conceptual point of view: create two addresslists and move the entries accordingly.
by erlinden
Mon Mar 06, 2023 8:37 pm
Forum: Beginner Basics
Topic: Another ax2 with link speed issue
Replies: 7
Views: 648

Re: Another ax2 with link speed issue

VLAN config is the same for ether1 and 5, there is something wrong with ether1 on ax2, both of my ax2 have same problem...
Can you please share your config?

/export file=anynameyoulike

Make sure to remove serial, public IP address and any other personal info.
by erlinden
Sun Mar 05, 2023 5:18 pm
Forum: Wireless Networking
Topic: RBmAP2n: WPA3
Replies: 2
Views: 211

Re: RBmAP2n: WPA3

I think it was introduced in the Wave2 driver, can't find any reference in the help files with the standard driver:
https://help.mikrotik.com/docs/display/ ... +Interface
by erlinden
Sun Mar 05, 2023 12:46 am
Forum: General
Topic: v7.8 seems not to export wpa2-pre-shared-key
Replies: 1
Views: 211

Re: v7.8 seems not to export wpa2-pre-shared-key

You have to explicitly add the parameter show-sensitive on (any) V7 to export all sensitive data. By default it is excluded from the export.
by erlinden
Sat Mar 04, 2023 2:41 pm
Forum: RouterBOARD hardware
Topic: hAP ax² dual band Wi-Fi 6 (802.11ax)
Replies: 287
Views: 48488

Re: hAP ax² dual band Wi-Fi 6 (802.11ax)

I'm not sure, maybe something wrong with my settings, but 1 meter away from the router all I can get over WiFi is
Instead of posting a result from speedtest, you could better post config and perform a throughput test with a tool like iPerf.
by erlinden
Fri Mar 03, 2023 11:40 pm
Forum: General
Topic: Attempting to Setup VLANs on Bridge
Replies: 11
Views: 927

Re: Attempting to Setup VLANs on Bridge

Haven't red all you wrote, any VLAN topic should have at least one link to this great topic:
viewtopic.php?t=143620
by erlinden
Fri Mar 03, 2023 4:30 pm
Forum: Beginner Basics
Topic: can not open SSH port on mikrotik router
Replies: 3
Views: 233

Re: can not open SSH port on mikrotik router

add action=accept chain=input comment="allow SSH temporarily" dst-port=22 protocol=tcp
If you add this after the Wireguard rule you should be able to connect.
by erlinden
Fri Mar 03, 2023 4:03 pm
Forum: Beginner Basics
Topic: can not open SSH port on mikrotik router
Replies: 3
Views: 233

Re: can not open SSH port on mikrotik router

The port should be explicitly be opened on the input chain (there is no port forward necessary), assuming you want to have this service available on the WAN site. And...as soon as you managed to get it to work...close it! Security wise you don't want this...never. Is this what you want to achieve? I...
by erlinden
Thu Mar 02, 2023 11:36 am
Forum: Wireless Networking
Topic: Channel frequency
Replies: 21
Views: 1329

Re: Channel frequency

I would like to know if the Mikrotik has any country that uses only the UNII-1 (36, 40, 44 and 48) and UNII-3 (149, 153, 157 and 161) channels in the 5GHz frequency?
Why? You want to live there?
by erlinden
Thu Mar 02, 2023 11:34 am
Forum: Beginner Basics
Topic: Dual wan port port forwarding issue.
Replies: 6
Views: 324

Re: Dual wan port port forwarding issue.

Don't you have/need firewall rules?
Did you set up hairpin NAT properly?

https://help.mikrotik.com/docs/display/ ... HairpinNAT
by erlinden
Wed Mar 01, 2023 4:44 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 189
Views: 16426

Re: MikroTik hAP ax3 poor WiFi performance

Instead/besides a backup, you can also perform an export which will save your configuration:
https://help.mikrotik.com/docs/display/ ... tandExport
by erlinden
Wed Mar 01, 2023 12:49 pm
Forum: General
Topic: CCR2216 CPU Problem
Replies: 16
Views: 1059

Re: CCR2216 CPU Problem

Should look more closely...why don't you add the VLAN on the bridge? Or better, what is the purpose of the VLAN? Or even "more" better, can you draw a diagram of how this device is supposed to work?

For reference:
viewtopic.php?f=23&t=143620
by erlinden
Wed Mar 01, 2023 10:27 am
Forum: Beginner Basics
Topic: hap ac2 low speed with 1gbps fiber [SOLVED]
Replies: 5
Views: 451

Re: hap ac2 low speed with 1gbps fiber [SOLVED]

The WiFi speed is very slow, up to 100Mbps with both 2.4 and 5 GHz. I can't find any capping configuration but I may absolutely be wrong. Do you have any suggestion? Your config is crappy in regards to wireless settings. Please use the search option in this forum (and search for user bpwl), you wil...
by erlinden
Sat Feb 25, 2023 11:18 am
Forum: Wireless Networking
Topic: Two APs - Same SSID with seamless connection for clients. How to?
Replies: 3
Views: 290

Re: Two APs - Same SSID with seamless connection for clients. How to?

As long as you configure as mentioned below, you will get your "seamless experience": SSID is identical All security settings are equal Channels are non overlapping Both accesspoints are on the same L2 network As far as I know there is no 802.11v currently (which would make the handover fa...
by erlinden
Fri Feb 24, 2023 11:37 am
Forum: Beginner Basics
Topic: Cannot reach Mikrotik wireguard server
Replies: 24
Views: 1096

Re: Cannot reach Mikrotik wireguard server

If you are trying from a pc connected to the MikroTik...what IP do you use to connect to? Might be that the ISP modem/router does not support NAT loopback. Can you: Test with a smartphone? => Check the counter on your MikroTik "wireguard handshake" rule, if hit you know port forwarding and...
by erlinden
Thu Feb 23, 2023 5:32 pm
Forum: General
Topic: DHCP server(s) on VLAN issue
Replies: 3
Views: 268

Re: DHCP server(s) on VLAN issue

Can you please share your config?

/export file=anynameyoulike

Remove any personal information like serial and public IP addresses
by erlinden
Wed Feb 22, 2023 12:35 pm
Forum: SwOS
Topic: How to run SwOS on MikroTik CRS354?
Replies: 2
Views: 289

Re: How to run SwOS on MikroTik CRS354?

According to the product (did I chose the correct?) page: https://mikrotik.com/product/crs354_48g_4splus2qplusrm is should be able to run it.
Why would you like to run SwitchOS?
What is your actual question? How to switch from RouterOS to SwitchOS?
by erlinden
Wed Feb 22, 2023 12:23 pm
Forum: General
Topic: Strange record after ROS update
Replies: 12
Views: 568

Re: Strange record after ROS update

Actually, mine is "set" to unknown (where Certificate is presented in red).
by erlinden
Wed Feb 22, 2023 11:59 am
Forum: General
Topic: Strange record after ROS update
Replies: 12
Views: 568

Re: Strange record after ROS update

So my question is how to reset a field that cannot be blank?
Make export, remove any unnecessary lines, reset the Tik without default and import your export.
Instead of reset, you can also do a netinstall.
by erlinden
Wed Feb 22, 2023 9:21 am
Forum: General
Topic: How to automate ISP bills?
Replies: 1
Views: 171

Re: How to automate ISP bills?

Not sure why you are reffering to a database, any customization like this can be done through an API:

V 6: https://wiki.mikrotik.com/wiki/Manual:API
V 7: https://help.mikrotik.com/docs/display/ROS/API
by erlinden
Tue Feb 21, 2023 6:10 pm
Forum: Wireless Networking
Topic: hap ax3, 7.7, WAP + WAP2 only allows WPA2 capable hosts, ac2 worked OK
Replies: 4
Views: 309

Re: hap ax3, 7.7, WAP + WAP2 only allows WPA2 capable hosts, ac2 worked OK

Why not drill a hole in ones head. You mean like a piercing? @TS: hAP ac2 is using a different wifi driver from the hAP ax2. Therefor there might be a difference in configuration. Unfortunately @anav forgot about the standard question (which is basically the "did you reboot your machine?"...
by erlinden
Tue Feb 21, 2023 6:04 pm
Forum: Beginner Basics
Topic: Extending WiFi network with additional AP
Replies: 2
Views: 229

Re: Extending WiFi network with additional AP

Roaming is a client thing, just make sure that SSID and all security settings are equal (and all devices are in the same L2 network. Fyi: CAPsMAN is great fun, think it still lacks some functionality (but might be a bit complex to configure...learning curve is steep) Mesh is when you have a wireless...
by erlinden
Tue Feb 21, 2023 3:58 pm
Forum: General
Topic: Strange record after ROS update
Replies: 12
Views: 568

Re: Strange record after ROS update

The only question is how to remove the certificate selected for openvpn from the configuration.
I'll just sit and watch till you finally Googled it.
by erlinden
Tue Feb 21, 2023 12:26 pm
Forum: Wireless Networking
Topic: Channel frequency
Replies: 21
Views: 1329

Re: Channel frequency

Have no experience with Wave2 (yet), but I would assume that the combination channelwidth 80MHz and frequency 5825 doesn't make sense. There doesn't seem to be a filter on the frequency dropdownlist, dependant on the channelwidth selected. As far as I can see, frequency 5825 is only supported when y...
by erlinden
Tue Feb 21, 2023 11:50 am
Forum: Wireless Networking
Topic: Channel frequency
Replies: 21
Views: 1329

Re: Channel frequency

Hop this clarifies it a bit more:

Image

So, your channel 42 is exactely in the middle as well as 155.
by erlinden
Tue Feb 21, 2023 11:30 am
Forum: Wireless Networking
Topic: Channel frequency
Replies: 21
Views: 1329

Re: Channel frequency

Channel 42 would be from 36 up to 48. You start with a control channel (20MHz wide) and add 3 x 20MHz extension channels to it. I.e. Control channel 5180 (channel 36) and extension channels Ceee would be from 5170 to 5250. You can also select a control channel somewhere in between (can't think of a ...
by erlinden
Mon Feb 20, 2023 5:38 pm
Forum: General
Topic: HEX S Issue
Replies: 13
Views: 682

Re: HEX S Issue

Comparing https://mikrotik.com/product/hap_ac2#fndtn-testresults with https://mikrotik.com/product/hex_s#fndtn-testresults it seems to me that the hEX S less performant than the cAP ac2. What is the CPU usage while running/testing?
by erlinden
Fri Feb 17, 2023 12:02 pm
Forum: Beginner Basics
Topic: Slow bandwidth debian server behind NAT
Replies: 8
Views: 751

Re: Slow bandwidth debian server behind NAT

I Do not understand, Why mikrotik has so slow speed when port forwarding ? I think you made some errors on the config: IP address should be set on the bridge, not on an interface that is part of the bridge If you want to do VLAN, you should have VLAN filtering turned on on the bridge What is the CP...
by erlinden
Fri Feb 17, 2023 11:18 am
Forum: RouterBOARD hardware
Topic: When would one reasonably choose RB2011 over hEX?
Replies: 6
Views: 464

Re: When would one reasonably choose RB2011 over hEX?

Higher production costs? And there still seems to be a market for it.
by erlinden
Fri Feb 17, 2023 10:57 am
Forum: RouterBOARD hardware
Topic: When would one reasonably choose RB2011 over hEX?
Replies: 6
Views: 464

Re: When would one reasonably choose RB2011 over hEX?

Well...I think it was introduced around 2014, I think you can say the RB2011 is reliable on the long term.
But instead of thinking about the differences...what are your requirements?
by erlinden
Thu Feb 16, 2023 12:02 pm
Forum: Beginner Basics
Topic: DDNS for my server with IP/Cloud?
Replies: 11
Views: 666

Re: DDNS for my server with IP/Cloud?

Can you:
  • Please supply the /export file=anynameyoulike (wihtout the serial/public IP/anything else personal)?
  • tell if you have any experience with NAT loopback and port forwarding?
by erlinden
Wed Feb 15, 2023 12:58 pm
Forum: General
Topic: ispModem -> STaticip -> Route gateway unreachable
Replies: 5
Views: 297

Re: ispModem -> STaticip -> Route gateway unreachable

Did you fill in 223.178.222.199 or 223.178.222.199/24 as IP address? It should be the latter.
by erlinden
Tue Feb 14, 2023 9:59 am
Forum: Beginner Basics
Topic: Extremely poor WiFi of MacBook Pro M1 PRO [SOLVED]
Replies: 17
Views: 1392

Re: Extremely poor WiFi performance hAP ax² [SOLVED]

Instead of using speedtest, you better test with a tool like iPerf. That will give a better indication of the wireless speed.
I'll check your config in the mean time...
by erlinden
Mon Feb 13, 2023 8:54 pm
Forum: Beginner Basics
Topic: Tagged VLAN on WAN (HeX)
Replies: 4
Views: 309

Re: Tagged VLAN on WAN (HeX)

Don't forget, assuming you didn't mess up the firewall, to add the vlanISP to the WAN addresslist.
Otherwise Internet won't work (while you have a public IP address assigned to this interface).
by erlinden
Sun Feb 12, 2023 11:58 am
Forum: Beginner Basics
Topic: no supported channels for 80+80Mhz [SOLVED]
Replies: 7
Views: 576

Re: no supported channels for 80+80Mhz [SOLVED]

When selecting 160MHz I think DFS channels are required. And, there are only two options for a 160MHz bandwidth: 5170MHz - 5330MHz or 5490MHz - 5650MHz. I have absolutely no experience with this, but I assume you should change frequency and allow DFS channel first. And from the documentation I would...
by erlinden
Sat Feb 11, 2023 11:57 pm
Forum: Beginner Basics
Topic: Port forwarding not working
Replies: 2
Views: 213

Re: Port forwarding not working

My advice: Reset your device and start configuring from scratch up. Your firewall is a joke (being polite), and you only want to do remote management through VPN. You might even want to consider a netinstall as your device could very well be compromised. Please read: https://help.mikrotik.com/docs/d...
by erlinden
Sat Feb 11, 2023 11:26 am
Forum: General
Topic: bonding aggregation 1Gpbs [SOLVED]
Replies: 1
Views: 237

Re: bonding aggregation 1Gpbs [SOLVED]

Absolutely no clue what your question might be, but here is something you probably want to read:

https://help.mikrotik.com/docs/display/ROS/Bonding
by erlinden
Fri Feb 10, 2023 11:27 pm
Forum: General
Topic: Router fails to detect new version [SOLVED]
Replies: 7
Views: 405

Re: Router fails to detect new version [SOLVED]

Select the test channel!
by erlinden
Fri Feb 10, 2023 10:24 pm
Forum: General
Topic: Router fails to detect new version [SOLVED]
Replies: 7
Views: 405

Re: Router fails to detect new version [SOLVED]

If you want to upgrade to v7, please select test instead of stable. Or download the package manually, place it in the root and reboot. Why do you want to upgrade?
by erlinden
Thu Feb 09, 2023 10:44 am
Forum: Wireless Networking
Topic: Cannot connect 1 Device via 2.4 GHz
Replies: 5
Views: 705

Re: Cannot connect 1 Device via 2.4 GHz

Would start with not using extension channel on the 2.4GHz radio. Also, adjust your transmission power to something sane. Think if you require 802.11a and 802.11b (more of a standard advice, probably won't help sole your problem). Might want to update the RouterOS (any reason for running this versio...
by erlinden
Thu Feb 09, 2023 9:21 am
Forum: Wireless Networking
Topic: Cannot obtain IP address when trying to connect to hap ac2 set up as repeater [SOLVED]
Replies: 8
Views: 586

Re: Cannot obtain IP address when trying to connect to hap ac2 set up as repeater [SOLVED]

Is your MikroTik wirelessly connected at all? Is your security settings correct (WPA AND WPA2)? Is the SSID correct? Are you sure you can connect wirelessly on the 5GHz band? Has anything changed on the wireless network you connect to? Does your MikroTik get an IP address (DHHCP Client)? Why do you ...
by erlinden
Thu Feb 09, 2023 9:00 am
Forum: Beginner Basics
Topic: [SOLVED] Sanity check firewall rules
Replies: 14
Views: 1482

Re: Sanity check firewall rules

If your MikroTik has a public IP address, the firewall is not complete. But it would help if you supply us with a complete network diagram (clients are not relevant). And also supply us the complete export:

/export file=anynameyoulike

Make sure to remove serial/public IP/anything als personal
by erlinden
Wed Feb 08, 2023 6:17 pm
Forum: General
Topic: how to get total uptime
Replies: 10
Views: 553

Re: how to get total uptime

Though it does make perfect sense to you, please enlighten me...why do you need that information?
As far as I know it is not available, might be worth to suggest it to MikroTik.
by erlinden
Wed Feb 08, 2023 5:31 pm
Forum: General
Topic: how to get total uptime
Replies: 10
Views: 553

Re: how to get total uptime

/system/resource print This will provide information like: uptime: 3w5d23h29m44s version: 7.7 (stable) build-time: Jan/12/2023 07:35:45 factory-software: 6.44.3 free-memory: 927.3MiB total-memory: 1024.0MiB cpu: ARM cpu-count: 4 cpu-load: 3% free-hdd-space: 421.6MiB total-hdd-space: 512.2MiB archit...
by erlinden
Wed Feb 08, 2023 12:25 pm
Forum: Wireless Networking
Topic: Cannot obtain IP address when trying to connect to hap ac2 set up as repeater [SOLVED]
Replies: 8
Views: 586

Re: Cannot obtain IP address when trying to connect to hap ac2 set up as repeater [SOLVED]

Sure MikroTik is your way to go?
  1. Open Terminal (it's in the menu)
  2. /export file=anynameyoulike (and press enter)
  3. Open Files
  4. Download the anynameyoulike.rsc file
  5. Open the file with your preferred edittor
  6. Copy the content and paste it here (don't forget to remove the personal information
by erlinden
Wed Feb 08, 2023 12:11 pm
Forum: Wireless Networking
Topic: Cannot obtain IP address when trying to connect to hap ac2 set up as repeater [SOLVED]
Replies: 8
Views: 586

Re: Cannot obtain IP address when trying to connect to hap ac2 set up as repeater [SOLVED]

Give us some more info:
/export file=anynameyoulike

Remove serial and public IP (and any other personal info) and post in between [ code] tags.
by erlinden
Tue Feb 07, 2023 10:03 am
Forum: General
Topic: Wrong log message order for DHCP messages.
Replies: 7
Views: 394

Re: Wrong log message order for DHCP messages.

I order by time.
Ok, that is your problem...
by erlinden
Mon Feb 06, 2023 6:16 pm
Forum: General
Topic: Wrong log message order for DHCP messages.
Replies: 7
Views: 394

Re: Wrong log message order for DHCP messages.

Strange...haven't seen this behaviour. The log isn't ordered on the #column...that would help :o
by erlinden
Mon Feb 06, 2023 5:57 pm
Forum: General
Topic: Wrong log message order for DHCP messages.
Replies: 7
Views: 394

Re: Wrong log message order for DHCP messages.

That wouldn't make sense...can you share /log print ?
by erlinden
Mon Feb 06, 2023 12:45 pm
Forum: Beginner Basics
Topic: Initial setup
Replies: 6
Views: 540

Re: Initial setup

by erlinden
Mon Feb 06, 2023 11:41 am
Forum: Beginner Basics
Topic: hAP ax2 link speed problem [SOLVED]
Replies: 14
Views: 1010

Re: hAP ax2 link speed problem [SOLVED]

Any other ideas or should i return it as defective unit ?
After all the steps you took...RMA it indeed.
by erlinden
Fri Feb 03, 2023 5:43 pm
Forum: Beginner Basics
Topic: hAP ax2 link speed problem [SOLVED]
Replies: 14
Views: 1010

Re: hAP ax2 link speed problem [SOLVED]

You might want to try netinstall the device:
https://help.mikrotik.com/docs/display/ROS/Netinstall
by erlinden
Fri Feb 03, 2023 2:47 pm
Forum: General
Topic: How to access Mikrotik behind Starlink (CGNAT) [SOLVED]
Replies: 48
Views: 2544

Re: How to access Mikrotik behind Starlink (CGNAT)

You would have to initiate the VPN from the MikroTik (run a VPN client) to a public VPN server.
by erlinden
Thu Feb 02, 2023 9:14 pm
Forum: Beginner Basics
Topic: CCR upgrade dont work 7.5 > 7.7
Replies: 9
Views: 428

Re: CCR upgrade dont work 7.5 > 7.7

Netinstall and import the export file you created before the upgrade?
Did you install any additional packages?
by erlinden
Thu Feb 02, 2023 6:01 pm
Forum: Beginner Basics
Topic: CCR upgrade dont work 7.5 > 7.7
Replies: 9
Views: 428

Re: CCR upgrade dont work 7.5 > 7.7

Check the logging?
Sure the file is ok?
Filename should be: routeros-arm64-7.7.npk
by erlinden
Thu Feb 02, 2023 4:52 pm
Forum: Beginner Basics
Topic: CCR upgrade dont work 7.5 > 7.7
Replies: 9
Views: 428

Re: CCR upgrade dont work 7.5 > 7.7

When using WinBox, upgrading through /system/packages is the easiest way.
Are you sure you downloaded the correct architecture? What CCR do you use (can be ARM and ARM 64)?
by erlinden
Thu Feb 02, 2023 4:48 pm
Forum: Beginner Basics
Topic: No router menagement possible while connected via VPN [SOLVED]
Replies: 8
Views: 688

Re: No router menagement possible while connected via VPN [SOLVED]

The firewall is probably blocking because the VPN clients are not on the LAN address list:
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
in-interface-list=!LAN
by erlinden
Thu Feb 02, 2023 11:45 am
Forum: General
Topic: CAPsMan Configuration
Replies: 4
Views: 441

Re: CAPsMan Configuration

Can you please share your config? Specifically of the CAPsMAN?

/export file=anynameyoulike

Make sure to remove serial, public IP and anything else personal
by erlinden
Wed Feb 01, 2023 9:51 am
Forum: Wireless Networking
Topic: Problem with IoT device on hAP ax2
Replies: 7
Views: 834

Re: Problem with IoT device on hAP ax2

Two things in regards to Wifi:

- don't use WPA-PSK
- don't use extension channels on the 2.4GHz radio

Not sure if it is related to your problem or if it is a problem by itself
by erlinden
Wed Feb 01, 2023 9:41 am
Forum: Beginner Basics
Topic: Unable to stop Inter-VLAN traffic
Replies: 6
Views: 458

Re: Unable to stop Inter-VLAN traffic

Prefer to use a drop everything else on the end of the chain rules...so both input and forward have this drop rule. Next, please post a complete export and remove the screenshots (as there is so much more info in the export) and use code tags for markup [ code]: /export file=anynameyoulike Make sure...
by erlinden
Sun Jan 29, 2023 2:27 pm
Forum: General
Topic: Broken network with CAPsMAN (very slow speed and latency, disconnects)
Replies: 2
Views: 255

Re: Broken network with CAPsMAN (very slow speed and latency, disconnects)

Might have to look better...I think some parts of the config is missing?
Why use 2.4GHz radios only?

[Update]
Was expecting some intelligent on the radio channel settings...I think it is currently configured as "fingers crossed".
by erlinden
Wed Jan 25, 2023 4:50 pm
Forum: General
Topic: Simple filter rules not working [SOLVED]
Replies: 12
Views: 584

Re: Simple filter rules not working [SOLVED]

Check the "in" and "out" interfaces, that might give you a clue.
Hope this is not your entire firewall?
by erlinden
Wed Jan 25, 2023 3:58 pm
Forum: Beginner Basics
Topic: DDNS name and public address doesn't show up
Replies: 4
Views: 225

Re: DDNS name and public address doesn't show up

Might show up in Quick Set at VPN Access. Just don't use Quick Set.
by erlinden
Wed Jan 25, 2023 2:29 pm
Forum: General
Topic: How to monitor for attacks
Replies: 10
Views: 488

Re: How to monitor for attacks

You might want to have a look at these YouTube videos:

Bruteforce protection - MikroTik firewall rules:
https://youtu.be/UXGVQmFUfL4

Port knocking with MikroTik:
https://youtu.be/ZaWTuqIdhLM
by erlinden
Wed Jan 25, 2023 1:46 pm
Forum: Beginner Basics
Topic: Importing default config not working
Replies: 15
Views: 748

Re: Importing default config not working

Do I need the extra package?🤔
As far as I know the hAP ax3 requires wifiwave2 package.


Oops...too late
by erlinden
Wed Jan 25, 2023 11:06 am
Forum: Beginner Basics
Topic: Block internet access for child
Replies: 10
Views: 422

Re: Block internet access for child

Nope...you should have both Saturday and Sunday from 00:00:00 to 01:00:00.
by erlinden
Wed Jan 25, 2023 10:00 am
Forum: RouterBOARD hardware
Topic: CAP ac dead after upgrade
Replies: 11
Views: 767

Re: CAP ac dead after upgrade

By not starting up you (also) mean:
- no DHCP request?
- not discoverable?
by erlinden
Tue Jan 24, 2023 12:01 pm
Forum: General
Topic: simple bridge configuration on 1100
Replies: 7
Views: 358

Re: simple bridge configuration on 1100

You might want to consider doing it the bridge vlan filtering way:
viewtopic.php?f=13&t=143620

What RouterOS version are both Tiks running?
by erlinden
Tue Jan 24, 2023 11:19 am
Forum: General
Topic: simple bridge configuration on 1100
Replies: 7
Views: 358

Re: simple bridge configuration on 1100

What is the expected result and what is the actual result?
Can you share the complete config?

/export file=anynameyoulike

Don't forget to remove any personal information
by erlinden
Tue Jan 24, 2023 9:56 am
Forum: General
Topic: Default firewall Rules in ROS vs DDOS attack
Replies: 3
Views: 292

Re: Default firewall Rules in ROS vs DDOS attack

DDOS Mitigation won't help most users (ISP can/should help in this case).

The number of rules will increase complexity. As long as you know what you do (and what every rules reason for being is) you won't make it vurnerable.
by erlinden
Tue Jan 24, 2023 9:06 am
Forum: Beginner Basics
Topic: VPN Slow Speed
Replies: 11
Views: 971

Re: VPN Slow Speed

To start: can you please use the correct notation: m = millli M = Mega b = bit B = byte Usually network speed is witten in Mbps (or Mb/s) or Gbps (or Gb/s). Wireguard should be able to do better, can you share your config? /export file=anynameyoulike Make sure to remove any personal information. Dur...
by erlinden
Sat Jan 21, 2023 10:10 pm
Forum: Beginner Basics
Topic: HAP Ax3 no-link
Replies: 14
Views: 1521

Re: HAP Ax3 no-link

Oops, I missed the most important part...clone the MAC address of the pc (which can be found with the command ipconfig /all ). Just red your post again, what you are saying is that the pc gets an IP address on eth1, but not on eth2? Sounds like you bind your DHCP server to eth1 (which doesn't make s...
by erlinden
Sat Jan 21, 2023 5:14 pm
Forum: Beginner Basics
Topic: HAP Ax3 no-link
Replies: 14
Views: 1521

Re: HAP Ax3 no-link

Can you connect the router (with the eth1 port connected) to test if the DHCP client is working?
If a pc is working on the connection, can you test with the pc's address cloned in the MikroTik on eth1?

And...never ever use Quickset after any manual adjustment to the config.
by erlinden
Sat Jan 21, 2023 5:09 pm
Forum: Wireless Networking
Topic: A bug in the 7.x system?
Replies: 10
Views: 731

Re: A bug in the 7.x system?

Perhaps have a look at this:
https://help.mikrotik.com/docs/pages/vi ... Id=8978441

Mesh = wireless backhaul (and has absolutely nothing to do with seamless roaming).
by erlinden
Sat Jan 21, 2023 12:35 pm
Forum: Wireless Networking
Topic: A bug in the 7.x system?
Replies: 10
Views: 731

Re: A bug in the 7.x system?

I have absolutely no idea what you mean by mesh...if both interfaces are added to the bridge (and the wireless is configured as ap-bridge) clients on wireless will receive IP address. Can you share your config to find out why it is not working for you? /export file=anynameyoulike Make sure to remove...
by erlinden
Sat Jan 21, 2023 11:41 am
Forum: Beginner Basics
Topic: HAP Ax3 no-link
Replies: 14
Views: 1521

Re: HAP Ax3 no-link

If you want to really wipe everythng on router, then netinstall the device. Beware that it's a very fragile process (a bit less so if using linux variant).
Did you perform the netinstall succesfully, @Tent1987?
by erlinden
Fri Jan 20, 2023 5:43 pm
Forum: Beginner Basics
Topic: How to lower Wireless TX Power
Replies: 3
Views: 270

Re: How to lower Wireless TX Power

Think it requires advanced options (push the advanced button to get the tab):

https://help.mikrotik.com/docs/display/ ... PowerTable
by erlinden
Fri Jan 20, 2023 10:32 am
Forum: General
Topic: caps and access router question [SOLVED]
Replies: 5
Views: 373

Re: caps and access router question [SOLVED]

Is there a reason why you are not doing VLAN filtering on the bridge (instead of creating a bridge per vlan)?
viewtopic.php?t=143620
by erlinden
Thu Jan 19, 2023 4:31 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 189
Views: 16426

Re: MikroTik hAP ax3 poor WiFi performance

I'm just saying it gives less coverage or maybe i'm doing a mistake, so i appreciate any comment toward the solution.
Yes...it's a mistake on your site. Please read my previous post and change config accordingly.
by erlinden
Thu Jan 19, 2023 3:32 pm
Forum: General
Topic: RB4011 crashing with 7.7
Replies: 10
Views: 1210

Re: RB4011 crashing with 7.7

Take in consideration what @holvoetn mentioned: export your complete config (/export show-sensitive file=anynameyoulike), do a netinstall and perform an import of the config (/import file=anynameyoulike). Hope it helps!
by erlinden
Thu Jan 19, 2023 3:29 pm
Forum: Wireless Networking
Topic: MikroTik hAP ax3 poor WiFi performance
Replies: 189
Views: 16426

Re: MikroTik hAP ax3 poor WiFi performance

You are using 40MHz bandwidth on the 2.4GHz radio of the MikroTik while the Asus is 20MHz. That will make a huge difference, especially looking at the saturation of the 2.4GHz band. Next, if you want to compare you should use the same settings (bands) on both devices (ofcourse not at the same time).
by erlinden
Thu Jan 19, 2023 3:06 pm
Forum: General
Topic: RB4011 crashing with 7.7
Replies: 10
Views: 1210

Re: RB4011 crashing with 7.7

Nope...

How fast after boot does it happen?
Have you sent the supout file yet?
Anything exotic in your config?
by erlinden
Thu Jan 19, 2023 12:05 pm
Forum: Wireless Networking
Topic: how to use all freq range 2312-2497
Replies: 2
Views: 240

Re: how to use all freq range 2312-2497

Depends on regulations (which depends on country code), can you check:

/interface wireless info allowed-channels

https://help.mikrotik.com/docs/display/ ... +Interface
by erlinden
Wed Jan 18, 2023 5:34 pm
Forum: General
Topic: rate limit in the server profile tab of the hotspot
Replies: 4
Views: 287

Re: rate limit in the server profile tab of the hotspot

Seems that the help page is not up to date yet, the wiki is: https://wiki.mikrotik.com/wiki/Manual:IP/Hotspot/Profile Rate limitation in form of rx-rate[/tx-rate] [rx-burst-rate[/tx-burst-rate] [rx-burst-threshold[/tx-burst-threshold] [rx-burst-time[/tx-burst-time]]]] [priority] [rx-rate-min[/tx-rat...
by erlinden
Wed Jan 18, 2023 4:50 pm
Forum: General
Topic: rate limit in the server profile tab of the hotspot
Replies: 4
Views: 287

Re: rate limit in the server profile tab of the hotspot

Where exactely do you see this setting?
I checked the helppage, but it wasn't mentioned:
https://help.mikrotik.com/docs/pages/vi ... d=56459266

If it has to do with the wireless device:
https://help.mikrotik.com/docs/display/ ... SRatetable
by erlinden
Wed Jan 18, 2023 12:29 pm
Forum: General
Topic: Queues Not Working
Replies: 7
Views: 668

Re: Queues Not Working

I'm using simple queues (which work pretty straight forward). Might be sufficient for you as well?
/queue simple
add dst=[WAN interface] max-limit=100M/100M name=[ANYNAMEYOULIKE] target=[IP ADDRESS]
by erlinden
Tue Jan 17, 2023 12:39 pm
Forum: General
Topic: confused about vlans [SOLVED]
Replies: 2
Views: 295

Re: confused about vlans [SOLVED]

The answer to VLAN everything:
viewtopic.php?f=23&t=143620
by erlinden
Tue Jan 17, 2023 11:14 am
Forum: Beginner Basics
Topic: 2,4GHz SSID disappears after a few hours
Replies: 7
Views: 598

Re: 2,4GHz SSID disappears after a few hours

Is the SSID still broadcasted?
Does disable&enalbe the interface solve the problem?
Can you share your config?
/export file=anynameyoulike

Make sure you remove any personal information.
by erlinden
Mon Jan 16, 2023 9:47 pm
Forum: Announcements
Topic: v7.7 [stable] is released!
Replies: 357
Views: 91041

Re: v7.7 [stable] is released!

I read some comments about higher temperature, nothing about freezing devices.
Couldn't help it, what are freezes in your case? Can you share your config to get some proper feedback?
/export file=anynameyoulike

Make sure to get rid of all personal information.
by erlinden
Mon Jan 16, 2023 9:40 pm
Forum: Wireless Networking
Topic: Wireless FAQ
Replies: 81
Views: 152504

Re: Wireless FAQ

Hello every one, just starting in mikrotik world, I have a RB951G-2HnD but my wireless is too slow, is there a way to connect an 5g external ap to one of its ports but slave to local lan?
Yes, exactly as you describe.
by erlinden
Mon Jan 16, 2023 6:03 pm
Forum: General
Topic: Redirect to website
Replies: 4
Views: 319

Re: Redirect to website

by erlinden
Mon Jan 16, 2023 4:48 pm
Forum: Beginner Basics
Topic: HAP Ax3 no-link
Replies: 14
Views: 1521

Re: HAP Ax3 no-link

Some guy at work told me there is a way to re-install the preconfigured config (when u buy it), he was talking about a package. If you perform a reset (/system reset-configuration) it will perform a reset and apply a default configuration. Only if you thick the "No Default Configuration" ...
by erlinden
Mon Jan 16, 2023 3:34 pm
Forum: Beginner Basics
Topic: HAP Ax3 no-link
Replies: 14
Views: 1521

Re: HAP Ax3 no-link

Can you please share your current configuration:
/export file=anynameyoulike

Make sure to remove any personal information.

Please also check with other cable.
by erlinden
Sun Jan 15, 2023 12:32 pm
Forum: General
Topic: Queues Not Working
Replies: 7
Views: 668

Re: Queues Not Working

Can you please share your config:
/export hide-sensitive file=anynameyoulike
Don't forget to remove any personal information.
by erlinden
Sat Jan 14, 2023 3:08 pm
Forum: Beginner Basics
Topic: Wlan has no internet access but lan has internet access [SOLVED]
Replies: 24
Views: 1214

Re: Wlan has no internet access but lan has internet access [SOLVED]

Do you get an IP address when connected through wireless?
by erlinden
Sat Jan 14, 2023 12:10 am
Forum: Beginner Basics
Topic: Winbox does not find hAP ac [SOLVED]
Replies: 28
Views: 1502

Re: Winbox does not find hAP ac [SOLVED]

As described you would have to make available access on the WAN port of the MikroTik. Just open the Winbox port on the WAN port input chain...that is it.
by erlinden
Fri Jan 13, 2023 3:57 pm
Forum: Beginner Basics
Topic: hap AX3 CAP mode [SOLVED]
Replies: 14
Views: 1714

Re: hap AX3 CAP mode [SOLVED]

For the time being you can configure it as stand alone instead of cAP.
by erlinden
Thu Jan 12, 2023 10:02 am
Forum: Beginner Basics
Topic: Connect to hidden SSID
Replies: 4
Views: 357

Re: Connect to hidden SSID

What is the purpose of making it hidden?
Can you unhide it, connect the tv and make it hidden again?
by erlinden
Wed Jan 11, 2023 4:29 pm
Forum: Beginner Basics
Topic: Hardware offload in 7.3.1 on Hex S
Replies: 11
Views: 2280

Re: Hardware offload in 7.3.1 on Hex S

But the problem is..... will mikrotik add support for this?
Is it a problem if MikroTik supplies support?
Or would it be a problem if no support is supplied?

Please be honest...is your question serious?
by erlinden
Tue Jan 10, 2023 4:31 pm
Forum: Beginner Basics
Topic: Appreciate some guidance... Port Forwarding
Replies: 3
Views: 266

Re: Appreciate some guidance... Port Forwarding

Instead of using the interface list, you can als use the interface that is the WAN port of your router.
Other option is to add the addreslist (/interface) and add the WAN port interface to it. After this you will be able to select it from the dropdownlist.
by erlinden
Tue Jan 10, 2023 1:28 pm
Forum: Beginner Basics
Topic: unable to install openWRT on my RB951ui
Replies: 12
Views: 866

Re: unable to install openWRT on my RB951ui

Your screenshot states that OpenWRT is no longer supported by OpenWRT on specific MikroTik hardware. MikroTik has never supported any other OS other then the once they supply with their hardware.
by erlinden
Tue Jan 10, 2023 12:39 pm
Forum: Beginner Basics
Topic: unable to install openWRT on my RB951ui
Replies: 12
Views: 866

Re: unable to install openWRT on my RB951ui

Do you think MikroTik did support it any time?
Think this question should be asked on the OpenWRT forum instead.
by erlinden
Tue Jan 10, 2023 9:57 am
Forum: Wireless Networking
Topic: Capsman performance degradation due to many clients?
Replies: 10
Views: 655

Re: Capsman performance degradation due to many clients?

Can you share your config?
/export file=anynameyoulike(and remove any personal information).
by erlinden
Mon Jan 09, 2023 3:12 pm
Forum: Beginner Basics
Topic: VLAN traffic / Firewall
Replies: 14
Views: 842

Re: VLAN traffic / Firewall

As mentioned, the current config is necessary, especially the firewall rules (as interVLAN traffic is allowed by default).

You can use /export on the Terminal (i.e. /ip firewall export or /export).
by erlinden
Sun Jan 08, 2023 7:41 pm
Forum: Beginner Basics
Topic: HAP ax3 configuration [SOLVED]
Replies: 9
Views: 1720

Re: HAP ax3 configuration [SOLVED]

Ok, can you share your current config (/wireless export)? Make sure to remove the personal info if any. If you place it between code tags it will be most readable.
by erlinden
Sun Jan 08, 2023 7:32 pm
Forum: Beginner Basics
Topic: HAP ax3 configuration [SOLVED]
Replies: 9
Views: 1720

Re: HAP ax3 configuration [SOLVED]

Have you set country code?
by erlinden
Sat Jan 07, 2023 11:33 am
Forum: Beginner Basics
Topic: SSH to Mikrotik router from WAN
Replies: 12
Views: 894

Re: SSH to Mikrotik router from WAN

By disabling the rule every port on your router is open from the internet. That's absolutely terrible from a security perspective. What is the purpose for this forward in the first place? Do you want to be able to perform admin on the MT? As mentioned, if (and you really don't!) you want to have SSH...
by erlinden
Fri Jan 06, 2023 5:11 pm
Forum: General
Topic: hAP AC2 cannot use IP CLOUD DDNS
Replies: 15
Views: 1081

Re: hAP AC2 cannot use IP CLOUD DDNS

Already tried a netinstall to make sure the device is clean?
by erlinden
Fri Jan 06, 2023 3:44 pm
Forum: General
Topic: Optimized firewall rules thought experiment
Replies: 9
Views: 572

Re: Optimized firewall rules thought experiment

Default rules will prefend any access from the Internet to the internal network.

What I like to do is end both input and forward chain with a rule dropping everything else (first make sure that anything you like to do is allowed).
by erlinden
Fri Jan 06, 2023 10:52 am
Forum: General
Topic: Could not resolve dns name [SOLVED]
Replies: 5
Views: 458

Re: Could not resolve dns name [SOLVED]

Do you have Internet access at all on the MikroTik?
Does a ping 8.8.8.8 give a response?
by erlinden
Thu Jan 05, 2023 4:39 pm
Forum: Wireless Networking
Topic: Problems with CAPsMAN
Replies: 8
Views: 598

Re: Problems with CAPsMAN

Besides fixed channels, you can also read this topic:
viewtopic.php?t=177019

Summarized: check DHCP lease time and use 40MHz channelwidth on 5GHz and 20MHz on 2.4GHz radio.
by erlinden
Thu Jan 05, 2023 3:55 pm
Forum: Wireless Networking
Topic: Problems with CAPsMAN
Replies: 8
Views: 598

Re: Problems with CAPsMAN

Could be anything, but auto is never a good option...

Can you share /caps-man export?
by erlinden
Thu Jan 05, 2023 2:36 pm
Forum: General
Topic: HW Offload on LAN ports not working [SOLVED]
Replies: 8
Views: 702

Re: HW Offload on LAN ports not working [SOLVED]

Why do you have a bridge configured for WAN? There is only one interface (eth1) on the bridge!?
by erlinden
Thu Jan 05, 2023 12:13 pm
Forum: Wireless Networking
Topic: mikrotik wireless network ping spikes [SOLVED]
Replies: 15
Views: 10296

Re: mikrotik wireless network ping spikes [SOLVED]

/interface wireless
station-roaming (disabled | enabled; Default: disabled)

Station Roaming feature is available only for 802.11 wireless protocol and only for station modes.
https://help.mikrotik.com/docs/display/ ... +Interface
by erlinden
Thu Jan 05, 2023 10:15 am
Forum: Beginner Basics
Topic: RB960PGS plus Pihole [SOLVED]
Replies: 2
Views: 359

Re: RB960PGS plus Pihole [SOLVED]

Several options:

If you redirect the router IP will be used in the logging of the PiHole.
You better set DNS server in the /ip dhcp-server network section (from commandline it would be /ip dhcp-server network set 0 dns-server=[ip address PiHole])
by erlinden
Wed Jan 04, 2023 11:13 am
Forum: General
Topic: HTTPS server access from LAN fails, from WAN it works.
Replies: 5
Views: 716

Re: HTTPS server access from LAN fails, from WAN it works.

How is the url resolved? If with public IP address you have to have Hairpin NAT in place:
https://help.mikrotik.com/docs/display/ ... HairpinNAT
by erlinden
Sun Jan 01, 2023 10:50 pm
Forum: General
Topic: winbox DHCP Leases ping lease Improvement Suggestion
Replies: 4
Views: 386

Re: winbox DHCP Leases ping lease Improvement Suggestion

why not?
Because, for me, I don't see the benefit. And there is more to improve in my opinion. Your turn :-P
by erlinden
Sat Dec 31, 2022 9:19 pm
Forum: Wireless Networking
Topic: hAP ac2 impossible 5GHz wifi
Replies: 9
Views: 746

Re: hAP ac2 impossible 5GHz wifi

In addition to the post of @inteq:
  • Set the country code
  • Enable WMM Support
As mentioned, DFS requires some patience (up till 10 minutes) during startup.
by erlinden
Sat Dec 31, 2022 12:51 pm
Forum: General
Topic: RB5009 and DoH get stuck on reboot
Replies: 4
Views: 280

Re: RB5009 and DoH get stuck on reboot

Totally lost now. I must admit that after 12 years with Mikrotik today I surrendered and ordered Omada kit.
Lol...thanks for informing us. Hope this other vendor will solve your problem.

Btw, if you share your current config (minus all personal info) we can have a look at it.
by erlinden
Sat Dec 31, 2022 12:47 pm
Forum: General
Topic: ISP
Replies: 34
Views: 1946

Re: ISP & SPEEDTEST

What problem does it solve? By the public IP address you are always able to determine the ISP.
by erlinden
Sat Dec 31, 2022 11:25 am
Forum: Beginner Basics
Topic: VLAN Trunking from RouterOS to SwOS
Replies: 26
Views: 2016

Re: VLAN Trunking from RouterOS to SwOS

I still see two bridges, as mentioned earlier please stick to one bridge. When it comes to VLAN, please use this topic only: https://forum.mikrotik.com/viewtopic.php?t=143620 It has got lots of examples and will guide you to a working environment. My experience is that there is a lot of crap, escpec...
by erlinden
Sat Dec 24, 2022 3:51 pm
Forum: General
Topic: High CPU Load on 3011. How to optimize config?
Replies: 3
Views: 604

Re: High CPU Load on 3011. How to optimize config?

In addition to the screenshots...can you please share your config?
/export file=anynameyoulike

Please make sure that all personal information is removed
by erlinden
Thu Dec 22, 2022 12:40 pm
Forum: Forwarding Protocols
Topic: Crazy Issue
Replies: 18
Views: 1386

Re: Crazy Issue

Ok...can you please also share /ip route export?
by erlinden
Thu Dec 22, 2022 12:30 pm
Forum: Forwarding Protocols
Topic: Crazy Issue
Replies: 18
Views: 1386

Re: Crazy Issue

Can you share your /ip route print?
by erlinden
Thu Dec 22, 2022 11:42 am
Forum: Wireless Networking
Topic: Need to know MikroTik cap xl ac Coverage Range
Replies: 6
Views: 631

Re: Need to know MikroTik cap xl ac Coverage Range

How did you get to the number 8?
Is there always a line of sight?
What are the requirements?
by erlinden
Thu Dec 22, 2022 11:26 am
Forum: General
Topic: CRS305 Poor VLAN Performance
Replies: 20
Views: 1013

Re: CRS305 Poor VLAN Performance

Is there a reason you haven't set frame-types: frame-types=admit-only-untagged-and-priority-tagged Next to that, you configure different pvid from vlan-ids. Perhaps have a look at this help page: https://help.mikrotik.com/docs/display/ROS/Bridging+and+Switching#BridgingandSwitching-BridgeVLANFiltering
by erlinden
Wed Dec 21, 2022 3:52 pm
Forum: Wireless Networking
Topic: hAP ac3 - Unable to select channel 11
Replies: 22
Views: 1334

Re: hAP ac3 - Unable to select channel 11

Thanks @own3r1138, I indeed made a tpo.
Can you let us know how things go after making the adjustments, @Tony359?
by erlinden
Wed Dec 21, 2022 2:10 pm
Forum: Wireless Networking
Topic: hAP ac3 - Unable to select channel 11
Replies: 22
Views: 1334

Re: hAP ac3 - Unable to select channel 11

Yes, that's just fine.

My recommendations
  • You can turn off WPS Mode (from a security perspective).
  • Don't use 802.11a/b unless absolutely necessary
  • Set WWM on (advanced settings)
  • Optimize Rx Power (advanced settings)
by erlinden
Wed Dec 21, 2022 12:28 pm
Forum: Wireless Networking
Topic: hAP ac3 - Unable to select channel 11
Replies: 22
Views: 1334

Re: hAP ac3 - Unable to select channel 11

Factory defaults work...well, optimization should be done afterwards. Every channel (1, 2, 3...11) in 2.4GHz is 5MHz wide. By choosing channel 1,6 or 11, you choose 20MHz it total (hence the adjacent channels). If you select to use extension channel (channel width) instead of using 20MHz you use 40M...
by erlinden
Wed Dec 21, 2022 11:55 am
Forum: Wireless Networking
Topic: hAP ac3 - Unable to select channel 11
Replies: 22
Views: 1334

Re: hAP ac3 - Unable to select channel 11

UInless you live in a place where there are no nearby Wifi networks, you could better not set a 40MHz bandwidth on the 2.4GHz radio. Instead, turn extension channel off. Besides (though no problem related), configure extension channels manually (i.e. Ceee), otherwise there is no predictable outcome ...
by erlinden
Wed Dec 21, 2022 11:12 am
Forum: Wireless Networking
Topic: hAP ac3 - Unable to select channel 11
Replies: 22
Views: 1334

Re: hAP ac3 - Unable to select channel 11

Can you please share:

/interface/wireless/ export hide-sensitive
by erlinden
Tue Dec 20, 2022 12:32 pm
Forum: General
Topic: Mikrotik HAP ac. Wi Fi upload is very slow.
Replies: 55
Views: 2251

Re: Mikrotik HAP ac. Wi Fi upload is very slow.

So much that can be configured:
  • Don't use 802.11a neither 802.11b
  • Don't use extension channel on the 2.4GHz radio
  • Consider using 40MHz bandwidth on the 5GHz radio
  • Specify your channels explicitely
  • Don't use wpa-psk, only use wpa2-aes
  • Country code
by erlinden
Mon Dec 19, 2022 5:49 pm
Forum: Beginner Basics
Topic: Config migration from RB2011 to RB4011 [SOLVED]
Replies: 9
Views: 815

Re: Config migration from RB2011 to RB4011 [SOLVED]

Just simply ignore all errors on wireless/wlan/lcd.
Learned something again today!
by erlinden
Mon Dec 19, 2022 4:49 pm
Forum: Beginner Basics
Topic: Config migration from RB2011 to RB4011 [SOLVED]
Replies: 9
Views: 815

Re: Config migration from RB2011 to RB4011 [SOLVED]

After exporting your current configuration, you can easily edit it in any text editor. You have to change it manually, otherwise the import will fail. Also, if you have fixed MAC addresses, you have to change them. And make sure that you are running the same RouterOS. Do you have (many) users config...
by erlinden
Fri Dec 16, 2022 12:50 pm
Forum: Wireless Networking
Topic: Terribly slow Wi-Fi speed
Replies: 14
Views: 1022

Re: Terribly slow Wi-Fi speed

Fully agree with tips from @erlinden. Important tips!
What a compliment! And thanks for learning from you again!
by erlinden
Fri Dec 16, 2022 10:44 am
Forum: Wireless Networking
Topic: Terribly slow Wi-Fi speed
Replies: 14
Views: 1022

Re: Terribly slow Wi-Fi speed

If you mean by old ancient...yes Interference will always have to be avoided...sharing the same channel is the worst you can do. When I used CAPsMAN (years ago, so I have to answer by heart) I made a configuration per radio. That way I could specify everything per radio. Roaming will definitely work...
by erlinden
Fri Dec 16, 2022 9:21 am
Forum: Wireless Networking
Topic: Terribly slow Wi-Fi speed
Replies: 14
Views: 1022

Re: Terribly slow Wi-Fi speed

From your configuration I would like to give you the following hints/tips: Don't use 802.11a neither 802.11b Don't use extension channel on the 2.4GHz radio Consider using 40MHz bandwidth on the 5GHz radio Specify your channels explicitely Don't use tkip And furthermore...don't share a config that m...
by erlinden
Thu Dec 15, 2022 2:20 pm
Forum: Beginner Basics
Topic: Need help to setup my switch [CRS226]
Replies: 5
Views: 300

Re: Need help to setup my switch [CRS226]

Can you please share your current configuration?
/export hide-sensitive file=anynameyoulike

Make sure to remove any personal information.
by erlinden
Wed Dec 14, 2022 10:42 am
Forum: General
Topic: Disable router webinterface from Guest network
Replies: 10
Views: 1238

Re: Disable router webinterface from Guest network

Grandstream, if using Cloud GWN, requires an Internet connection on the default VLAN (otherwise you are not able to configure the accesspoint). This can be accomplished by having an Internet VLAN untagged on the port where the GWN is connected to. Not sure if all is set including management VLAN you...
by erlinden
Mon Dec 12, 2022 10:43 am
Forum: General
Topic: Managed AP IP connected device addresses [SOLVED]
Replies: 4
Views: 436

Re: Managed AP IP connected device addresses [SOLVED]

IP addresses can be found /ip dhcp-server leases
If you want to know the connected devices per radio, you have to look at /caps-man/registration-table/ (I'm doing this by hard)
by erlinden
Sun Dec 11, 2022 12:15 pm
Forum: Beginner Basics
Topic: Help... Setup NAT ON RB2011UiAS-2HnD Failed....
Replies: 6
Views: 373

Re: Help... Setup NAT ON RB2011UiAS-2HnD Failed....

May I suggest starting from scratch...getting everything in place correctly (not many interfaces on the bridge), and then reconfigure to multi WAN?
by erlinden
Sun Dec 11, 2022 11:46 am
Forum: Beginner Basics
Topic: Capsman Master-Slave Configuration
Replies: 5
Views: 755

Re: Capsman Master-Slave Configuration

It's been a while since I used CAPsMAN: think you should do all the configuration on the manager site and not on the CAPs site.
by erlinden
Sun Dec 11, 2022 11:42 am
Forum: Beginner Basics
Topic: Help... Setup NAT ON RB2011UiAS-2HnD Failed....
Replies: 6
Views: 373

Re: Help... Setup NAT ON RB2011UiAS-2HnD Failed....

Mmmm...a lot of things not making sense: where are your firewall filter rules? why is there a DHCP client on the bridge? what is the purpose of the 192.168.222.x network? /ip dns has the 192.168.30.1 entry...are you behind NAT? why the static routes? less important...WPA-PSK? You can (nearly) leave ...
by erlinden
Sat Dec 10, 2022 1:46 pm
Forum: Beginner Basics
Topic: Newbie CRS312 trouble with VLAN & DHCP
Replies: 14
Views: 932

Re: Newbie CRS312 trouble with VLAN & DHCP

Please show your onfig: /export hide-sensitive file=anynameyoulike
And just make sure you removed any personal information
by erlinden
Sat Dec 10, 2022 1:44 pm
Forum: General
Topic: rb5009, vlan, only-hardware-queue, speedtest and tx drop issue
Replies: 4
Views: 456

Re: rb5009, vlan, only-hardware-queue, speedtest and tx drop issue

Perhaps you can add your model number and your config?

/export hide-sensitive file=anynameyoulike
Make sure to remove any personal information
by erlinden
Wed Dec 07, 2022 9:41 pm
Forum: Beginner Basics
Topic: Zyxel access point with mikrotik
Replies: 3
Views: 286

Re: Zyxel access point with mikrotik

Common, you can do a lot better than this. If you are serious, please provide some relevant information.
by erlinden
Tue Dec 06, 2022 2:10 pm
Forum: Beginner Basics
Topic: DHCP dont have ping!
Replies: 17
Views: 1196

Re: DHCP dont have ping!

In case you missed: Don't write novels, post /export hide-sensitive file=x. Use find&replace in your favourite text editor to systematically replace all occurrences of each public IP address potentially identifying you by a distinctive pattern such as my.public.ip.1. You're very welcome, @rexten...
by erlinden
Tue Dec 06, 2022 12:49 pm
Forum: Wireless Networking
Topic: hAP ax2 randomly drops WiFi SSIDs (both 2,4 and 5Ghz)
Replies: 18
Views: 2902

Re: hAP ax2 randomly drops WiFi SSIDs (both 2,4 and 5Ghz)

@Coolbox:
security.authentication-types=wpa-psk,wpa2-psk
I would expect at least wpa2-psk (and perhaps wpa3). Why use wpa-psk?
by erlinden
Fri Dec 02, 2022 11:45 pm
Forum: Wireless Networking
Topic: hAP ax2 randomly drops WiFi SSIDs (both 2,4 and 5Ghz)
Replies: 18
Views: 2902

Re: hAP ax2 randomly drops WiFi SSIDs (both 2,4 and 5Ghz)

Just to make sure: can you share your config (to see if anything could cause this)?
/export hide-sensitive file=anynameyoulike (and make sure to remove any personal information)
by erlinden
Wed Nov 30, 2022 4:31 pm
Forum: Wireless Networking
Topic: Is it possible to have two 2Ghz wifi's on hapac2
Replies: 16
Views: 1131

Re: Is it possible to have two 2Ghz wifi's on hapac2

You are right. I am sorry for the confusion.
No need to apologize, and feel free to ask for help if required.
by erlinden
Wed Nov 30, 2022 3:58 pm
Forum: Wireless Networking
Topic: Is it possible to have two 2Ghz wifi's on hapac2
Replies: 16
Views: 1131

Re: Is it possible to have two 2Ghz wifi's on hapac2

Yes, is possible using virtual wlan. It will be tied to the physical wlan1 (using same channel and other wifi related settings) but it can have a different SSID. Agree, but that was not the question, hence my answer. Therefor I prefer a topicstarter to explain the problem instead of coming up with ...
by erlinden
Wed Nov 30, 2022 1:48 pm
Forum: General
Topic: DHCP server is pushing both internal and received dynamic IPs to clients
Replies: 7
Views: 355

Re: DHCP server is pushing both internal and received dynamic IPs to clients

I mean, the behaviour can be overwritten by setting the DNS server explicitely:
/ip dhcp-server network add address=192.168.128.0/24 dns-server=192.168.128.1 comment=defconf gateway=192.168.128.1 netmask=24
by erlinden
Wed Nov 30, 2022 1:37 pm
Forum: General
Topic: very high CPU usage after migrating to 7.x
Replies: 7
Views: 666

Re: very high CPU usage after migrating to 7.x

Sounds a bit dramatic...is there a functional requirement for switching to v7?
by erlinden
Wed Nov 30, 2022 1:10 pm
Forum: General
Topic: DHCP server is pushing both internal and received dynamic IPs to clients
Replies: 7
Views: 355

Re: DHCP server is pushing both internal and received dynamic IPs to clients

I think it can be overwritten by setting DNS server in /ip dhcp-server network
by erlinden
Wed Nov 30, 2022 1:03 pm
Forum: General
Topic: very high CPU usage after migrating to 7.x
Replies: 7
Views: 666

Re: very high CPU usage after migrating to 7.x

Is a downgrade to LTS (6.48.6) an option?
by erlinden
Wed Nov 30, 2022 11:49 am
Forum: Wireless Networking
Topic: Is it possible to have two 2Ghz wifi's on hapac2
Replies: 16
Views: 1131

Re: Is it possible to have two 2Ghz wifi's on hapac2

There is no way to make a 5GHz radio into a 2.4GHz radio (and vice versa).
People tend to move away from the 2.4GHz radio (due to heavy interference), what makes you want to use this specifi band?
by erlinden
Tue Nov 29, 2022 2:17 pm
Forum: Beginner Basics
Topic: basics: guest WiFi network / no internet access
Replies: 8
Views: 931

Re: basics: guest WiFi network / no internet access

Anyone else have idea what could be wrong with my setup ? Agree with anav: read a bit more about VLAN. Besides...you only want your router to take care of DHCP, not your accesspoint. About your wireless settings: - don't use auto - only choose 20MHz channelwidth on the 2.4GHz radio - don't use XXXX...
by erlinden
Mon Nov 28, 2022 8:51 pm
Forum: Wireless Networking
Topic: Master SSID dropping to kbs speeds on all cAP ac units [SOLVED]
Replies: 43
Views: 3673

Re: Master SSID dropping to kbs speeds on all cAP ac units [SOLVED]

Is it prohibited to the 5GHz radio, or does it also happen on the 2.4GHz radio? Do all accesspoints have the same behaviour? Does the logging give you any clue? Sure the VLAN section is correct? I'm missing the frame-types=admit-only-untagged-and-priority-tagged on the /interface brdige port. But my...
by erlinden
Mon Nov 28, 2022 1:48 pm
Forum: Beginner Basics
Topic: vlan on bridge [SOLVED]
Replies: 7
Views: 929

Re: vlan on bridge [SOLVED]

I don't see the pools specified...is this your complete config?
by erlinden
Thu Nov 24, 2022 5:04 pm
Forum: Beginner Basics
Topic: Can't access the internal network with SSTP VPN road-warrior connection
Replies: 8
Views: 748

Re: Can't access the internal network with SSTP VPN road-warrior connection

Most VPN solutions require routes...have you configured one for the VPN clients?
Can you please share your config?

/export hide-sensitive file=anynameyoulike (don't leave any personal info in it)
by erlinden
Wed Nov 23, 2022 10:48 am
Forum: Wireless Networking
Topic: CAPsMAN - bind by mac to 2.4 GHz network
Replies: 9
Views: 545

Re: CAPsMAN - bind by mac to 2.4 GHz network

This problem can be solved with the access lists. there you can list the interfaces to which the device with the given MAC can connect
Assuming the MAC address is static (which isn't when it comes to wireless interfaces).

Still waiting for your config, kekraiser
by erlinden
Tue Nov 22, 2022 1:22 pm
Forum: General
Topic: Specific domain/web only works via VPN
Replies: 5
Views: 331

Re: Specific domain/web only works via VPN

Your public IP might be listed on the webserver, where the VPN public IP address isn't? Is it a public webserver? What error do you get?
by erlinden
Tue Nov 22, 2022 12:44 pm
Forum: Wireless Networking
Topic: CAPsMAN - bind by mac to 2.4 GHz network
Replies: 9
Views: 545

Re: CAPsMAN - bind by mac to 2.4 GHz network

Let's first focus on the problem: what is the logging saying?
Can we check the CAPsMAN config (as well): /caps-man export (make sure to remove any personal data.
by erlinden
Fri Nov 18, 2022 6:58 pm
Forum: General
Topic: RB850Gx2 upgrade to 7.6 failed
Replies: 9
Views: 824

Re: RB850Gx2 upgrade to 7.6 failed

by erlinden
Fri Nov 18, 2022 12:01 pm
Forum: Beginner Basics
Topic: Rb4011 switch all to sfp
Replies: 5
Views: 512

Re: Rb4011 switch all to sfp

Would be helpful if you share your current config (/export hide-sensitive file=anynameyoulike), make sure to remove any private information.
by erlinden
Thu Nov 17, 2022 12:17 pm
Forum: General
Topic: RB850Gx2 upgrade to 7.6 failed
Replies: 9
Views: 824

Re: RB850Gx2 upgrade to 7.6 failed

Is there anything in de logging giving a clue?
by erlinden
Tue Nov 15, 2022 2:55 pm
Forum: Beginner Basics
Topic: DHCP dont have ping!
Replies: 17
Views: 1196

Re: DHCP dont have ping!

Do the clients respond to ping? Could be a firewall in between (for instance). Can clients ping one another?
by erlinden
Mon Nov 14, 2022 11:54 am
Forum: Beginner Basics
Topic: Setting up newly bought Mikrotik Router
Replies: 7
Views: 614

Re: Setting up newly bought Mikrotik Router

As shown in the CMD prompt, your computer doesn't get an IP address as well. That makes me believe that it is not MikroTik related. Some ISP's do require some patience before handing out an IP address to a "new" mac address. At least reboot modem (or better leave it powered off for a while...
by erlinden
Mon Nov 14, 2022 10:28 am
Forum: Beginner Basics
Topic: Setting up newly bought Mikrotik Router
Replies: 7
Views: 614

Re: Setting up newly bought Mikrotik Router

Hereby my tips: Don't use Quickset Use default configuration When posting a topic, supply as much relevant information as possible Can you please start with default configuration and check if it works? If you attach a computer on the networkcable that is connected to the WAN port of the MT, do you g...
by erlinden
Fri Nov 11, 2022 3:06 pm
Forum: Beginner Basics
Topic: Ether 9 doesn't connect to VLAN while others do.
Replies: 7
Views: 872

Re: Ether 9 doesn't connect to VLAN while others do.

I think the bridge is missing in the /interface bridge vlan section.

Seems mkx already mentioned it...
by erlinden
Fri Nov 11, 2022 1:15 pm
Forum: Wireless Networking
Topic: How Superchannel in CapsMan
Replies: 1
Views: 257

Re: How Superchannel in CapsMan

Transmission power can be set like this:
/caps-man interface channel tx-power

But I'm not sure if that answers your question?
by erlinden
Thu Nov 10, 2022 8:43 am
Forum: General
Topic: Configure VLAN for 2 switches connected in series
Replies: 3
Views: 235

Re: Configure VLAN for 2 switches connected in series

An excelent starting point is this topic:
viewtopic.php?t=143620

In regards to the switch chipset, please check if it is feasable for your hardware:
https://help.mikrotik.com/docs/display/ ... p+Features
by erlinden
Tue Nov 08, 2022 11:42 am
Forum: Wireless Networking
Topic: Using WifiWave2 interface on station mode [SOLVED]
Replies: 1
Views: 402

Re: Using WifiWave2 interface on station mode [SOLVED]

In station mode the SSID that is configured is used as the SSID it will connect to.

Tip: check your Wifi settings, there is room for improvement.
by erlinden
Tue Nov 08, 2022 8:24 am
Forum: Wireless Networking
Topic: importing and exporting config files
Replies: 24
Views: 199634

Re: importing and exporting config files

Apart from the fact that you are misusing another topic:
  1. Export the current config
  2. Compare it to the one you are trying to import
by erlinden
Sun Nov 06, 2022 11:08 am
Forum: General
Topic: RB4011 vlan bridge
Replies: 4
Views: 463

Re: RB4011 vlan bridge

Something like this: /interface bridge add admin-mac=[fill in a MAC address of one of the ether ports] auto-mac=no ingress-filtering=no name=Bridge1 protocol-mode=none vlan-filtering=yes /interface vlan add interface=Bridge1 name=Vlan22 vlan-id=22 /interface bridge port add bridge=Bridge1 frame-type...
by erlinden
Sun Nov 06, 2022 10:54 am
Forum: Beginner Basics
Topic: Internet speed
Replies: 15
Views: 971

Re: Internet speed

I have the seam issue my total speed 500mb i can get if i connect my PC direct to Huawei 5G N5368X max router but if i connect RB5009UG+S+IN to huawei 5G N5368X max router and connect my PC to RB5009UG+S+IN with fasttrack UPD,TCP i get 200mb You don't have the same issue (as you don't have an RB201...
by erlinden
Fri Nov 04, 2022 4:12 pm
Forum: Wireless Networking
Topic: hAP ax² - second virtual WLAN on 2.4GHz ? [SOLVED]
Replies: 8
Views: 1237

Re: hAP ax² - second virtual WLAN on 2.4GHz ? [SOLVED]

What version of RouterOS are you running?
And can you share your config (/export hide-sensitive file=anynameyoulike, don't forget to remove any personal information)?
by erlinden
Fri Nov 04, 2022 2:20 pm
Forum: Wireless Networking
Topic: No supported channels [SOLVED]
Replies: 11
Views: 1264

Re: No supported channels [SOLVED]

Still trying to use WPA...hurting my eyes...

In your configuration there is nothing in regards to channel...have you tried setting the channel manually (or auto)?
Is this the complete config?
by erlinden
Wed Nov 02, 2022 5:46 pm
Forum: General
Topic: Three Networks behind 3 Routers with same Gateway
Replies: 4
Views: 327

Re: Three Networks behind 3 Routers with same Gateway

What is the purpose of having 4 routers, where 1 would be sufficient? In regards to access to servers: consider dividing into 6 VLAN's, 3 server VLAN's (per network) and 3 client VLAN's per network. Access can then be easily handled by the correct firewall rules. Love to link this topic: https://for...
by erlinden
Wed Nov 02, 2022 9:20 am
Forum: Wireless Networking
Topic: Does wifiwave2 support a repeater mode?
Replies: 5
Views: 521

Re: Does wifiwave2 support a repeater mode?

You really can't provide network through the LAN cable? Or what other use case do you have to need repeater mode?
by erlinden
Wed Nov 02, 2022 9:19 am
Forum: General
Topic: Recommended Firewall Filter & Raw rules [SOLVED]
Replies: 6
Views: 991

Re: Recommended Firewall Filter & Raw rules [SOLVED]

Can you please use export instead of print for providing this information (glad you used the code tags!).
That will make it a lot more readable!
by erlinden
Mon Oct 31, 2022 6:03 pm
Forum: General
Topic: Forward source port to another port number [SOLVED]
Replies: 6
Views: 763

Re: Forward source port to another port number [SOLVED]

Sorry, then I misunderstood your requirement. You only want to "translate" the port...correct?
Then I think you have to add a source nat rule together with masquerade. But no clue if there can be some sort of port translation.
by erlinden
Mon Oct 31, 2022 5:04 pm
Forum: General
Topic: Forward source port to another port number [SOLVED]
Replies: 6
Views: 763

Re: Forward source port to another port number [SOLVED]

add action=dst-nat chain=dstnat dst-address=[public IP address] dst-port=10222 protocol=tcp to-addresses=[private IP address] to-ports=22 log=yes

Be aware that this is security through obscurity...which is not secure. Is it absolutely necessary to makes this service publically available?
by erlinden
Sun Oct 30, 2022 5:56 pm
Forum: Beginner Basics
Topic: ip firewall nat problem
Replies: 10
Views: 518

Re: ip firewall nat problem

At least the default configuration is not complete. You might want to consider adding the default firewall rules (but it might cause a non working router). Perhaps better to share the complete config befor making any changes: /export hide-sensitive file=anynameyoulike (remove any private information...
by erlinden
Sun Oct 30, 2022 5:35 pm
Forum: Beginner Basics
Topic: ip firewall nat problem
Replies: 10
Views: 518

Re: ip firewall nat problem

Where are the default firewall rules? If this router is connected to the Internet and has a public IP address...you might be in bigger problems than a non-working port forward. May I advise you to netinstall this device and keep the default firewall rules. From there, you can start with adding addit...
by erlinden
Sun Oct 30, 2022 5:14 pm
Forum: Beginner Basics
Topic: ip firewall nat problem
Replies: 10
Views: 518

Re: ip firewall nat problem

For port forwarding you have to use the dstnat chain (and not the srcnat chain).

Update: oops...you did that already. Can you share your complete firewall:
/ip firewall export
by erlinden
Fri Oct 28, 2022 11:38 am
Forum: Beginner Basics
Topic: Cannot access WAN IP from LAN
Replies: 5
Views: 461

Re: Cannot access WAN IP from LAN

Yes, but nothing worked for me :/.
Then it's time to start an topic (check) and share your config (not checked yet :D ):
/export file=anynameyoulike (don't forget the code tags and remove any personal infogrmation)
by erlinden
Thu Oct 27, 2022 5:50 pm
Forum: Wireless Networking
Topic: Wireless channels and vlans
Replies: 12
Views: 1171

Re: Wireless channels and vlans

If the 2.4GHz band is saturated, well...it is. Can you perform a wireless scan with both devices and share it here? Can you please remove CAPsMAN as it is not the best choice? Last but not least…can you share the config of both MikroTik devices (remove all personal information) and share it here? An...
by erlinden
Wed Oct 26, 2022 5:39 pm
Forum: General
Topic: Is ROS:7.6 ready for real production work?
Replies: 18
Views: 1876

Re: Is ROS:7.6 ready for real production work?

Is there a roadmap for releasing a v7 LTS, normis?
by erlinden
Wed Oct 26, 2022 5:08 pm
Forum: General
Topic: CCR2004 - Vlans [SOLVED]
Replies: 11
Views: 1114

Re: CCR2004 - Vlans [SOLVED]

so I managed to make it work from a clear configuration, now I have the problem I can ping items cross vlans... You don't have a problem, you are/were not aware that inter VLAN communiction isn't blocked by default. You have to block it manually on the forward chain. Or better...block everything on...
by erlinden
Wed Oct 26, 2022 4:54 pm
Forum: Announcements
Topic: v6.49.7 [stable] is released!
Replies: 48
Views: 71604

Re: v6.49.7 [stable] is released!

Really interested what you say regarding new smartphone software.
by erlinden
Wed Oct 26, 2022 4:00 pm
Forum: Announcements
Topic: v6.48.6 [long-term] is released!
Replies: 126
Views: 250079

Re: v6.48.6 [long-term] is released!

You might want to consider opening a new topic, batot. I think that to do some investigation, you might want to share your config. Seeing your previous version...sure your router is not compromised?
by erlinden
Wed Oct 26, 2022 1:56 pm
Forum: General
Topic: Roll back to v6.?
Replies: 8
Views: 487

Re: Roll back to v6.?

Thank you and I apologize.
Glad you came to this conclusion, there is a great community working with Mikrotik and answering all kinds of questions on this forum. Feel free anytime!
by erlinden
Wed Oct 26, 2022 8:35 am
Forum: General
Topic: Roll back to v6.?
Replies: 8
Views: 487

Re: Roll back to v6.?

Don't understand your question (don't speak native English, my appologies...). Are you looking for the differences between v6 and v7 and what you loose after upgrading (what was available and working in v6)? Though I understand your reply to the post of smyers119 ...what was your reason for upgradin...
by erlinden
Tue Oct 25, 2022 4:11 pm
Forum: Wireless Networking
Topic: Slow connection speeds with CapsMan
Replies: 4
Views: 518

Re: Slow connection speeds with CapsMan

Can you test with one client connected through wire and the other wireless?
Can you leave the MTU flag out?
by erlinden
Tue Oct 25, 2022 3:56 pm
Forum: RouterBOARD hardware
Topic: Is it bug or hardware issue?
Replies: 3
Views: 412

Re: Is it bug or hardware issue?

Can you please share the config: /export hide-sensitive file=anynameyoulike
Don't forget to remove any personal/privacy information.

Do you have any script running/anything scheduled?
by erlinden
Mon Oct 24, 2022 4:34 pm
Forum: Wireless Networking
Topic: Slow connection speeds with CapsMan
Replies: 4
Views: 518

Re: Slow connection speeds with CapsMan

The first thing I would change is setting channels and extension channels manually. Besides, 2.4GHz works best (most times) if you use 20MHz bandwidth (where 5GHz better works on 40 or 80MHz, depending on interference). For testing purposes you better use iPerf instead of speedtest.net. At what spee...
by erlinden
Sat Oct 22, 2022 5:23 pm
Forum: RouterBOARD hardware
Topic: The new version of CAP AC --> CAP AX?
Replies: 7
Views: 3347

Re: The new version of CAP AC --> CAP AX?

Roaming is a client thing. There are some advantages on using 802.11r (the process is faster), but as long as SSID and security is identical (and the radios aren't interfering) your client will roam seamless.

I am also curious about the date of introduction of (in my case) the wAP ax.
by erlinden
Sat Oct 22, 2022 5:18 pm
Forum: Beginner Basics
Topic: CAP AC as wifi extender for a non-Mikrotik network
Replies: 2
Views: 270

Re: CAP AC as wifi extender for a non-Mikrotik network

I used this blogpost to configure a travel router.
You might not need NAT, but the idea is exactly the same:

https://www.justinho.com/blog/2017/07/1 ... -lite.html
by erlinden
Sat Oct 22, 2022 10:53 am
Forum: General
Topic: RB3011 DHCP server fails to assign IPs to many Linux devices
Replies: 9
Views: 499

Re: RB3011 DHCP server fails to assign IPs to many Linux devices

Can you start with a DHCP server using default settings (just remove the current and add a new one)?
by erlinden
Sat Oct 22, 2022 10:47 am
Forum: Beginner Basics
Topic: Internet issues (InvalidPackets) after upgrading ROSv6>v7 [SOLVED]
Replies: 8
Views: 1713

Re: Internet issues (InvalidPackets) after upgrading ROSv6>v7 [SOLVED]

Can you share your config? /export file=anynameyoulike
Make sure to remove any privacy information
by erlinden
Fri Oct 21, 2022 4:48 pm
Forum: Beginner Basics
Topic: Netinstall hAP ac2
Replies: 4
Views: 1309

Re: Netinstall hAP ac2

Instead of using 192.168.88.3 you should use 192.168.88.1
by erlinden
Thu Oct 20, 2022 5:56 pm
Forum: General
Topic: RB3011 DHCP server fails to assign IPs to many Linux devices
Replies: 9
Views: 499

Re: RB3011 DHCP server fails to assign IPs to many Linux devices

Can you please share the config of the Mikrotik (without any privacy information)?
/export file=anynameyoulike
Besides...have you already debugged DHCP on the Mikrotik (or used Wireshark to have a look why it is failing)?
by erlinden
Wed Oct 19, 2022 2:06 pm
Forum: Announcements
Topic: v7.6 [stable] is released!
Replies: 279
Views: 125452

Re: v7.6 [stable] is released!

/interface bridge
add admin-mac=X:X:X:X:X:X auto-mac=no comment=defconf name=bridge \
protocol-mode=none
What a most creative implementation of firewall rules. You have to do some work on that.
In that mess you will probably find the blocking rule as well.
by erlinden
Wed Oct 19, 2022 12:19 pm
Forum: Announcements
Topic: v7.6 [stable] is released!
Replies: 279
Views: 125452

Re: v7.6 [stable] is released!

If I run Winbox from local, it works, if I perform winbox from wireguard tunnel, it blocks and does not enter.
Is this new behaviour? Can you share your config (/ip/firewall/filter/ export)? Make sure to remove any privacy related information
by erlinden
Tue Oct 18, 2022 5:55 pm
Forum: SwOS
Topic: How to restore to factory firmware
Replies: 9
Views: 811

Re: How to restore to factory firmware

Sorry, wasn't aware that this device is running SWoS.
Can't you manually change the URL to a previous version? Any reason on why you want (or have) to downgrade?
by erlinden
Tue Oct 18, 2022 3:57 pm
Forum: SwOS
Topic: How to restore to factory firmware
Replies: 9
Views: 811

Re: How to restore to factory firmware

It would require the software, what version are you looking for?
by erlinden
Sun Oct 16, 2022 7:15 pm
Forum: RouterBOARD hardware
Topic: Rb5009 required daily reset
Replies: 3
Views: 703

Re: Rb5009 required daily reset

Debugging is done by using the log (and extending specifiic parts to the log).
But a good start is to share your config (make sure there is no information in it): /export hide-sensitive
by erlinden
Wed Oct 12, 2022 6:19 pm
Forum: Beginner Basics
Topic: Router change - no internet access on APs [SOLVED]
Replies: 2
Views: 494

Re: Router change - no internet access on APs [SOLVED]

What does a tracert www.mikrotik.com do an a noot-working device (or any non Windows equivalent)?
Why the daily reboot?
by erlinden
Wed Oct 12, 2022 3:22 pm
Forum: General
Topic: CCR2004 v7.5 half options in winbox [SOLVED]
Replies: 5
Views: 648

Re: CCR2004 v7.5 half options in winbox [SOLVED]

Do you have access through SSH (and does it crash there as well)?
by erlinden
Wed Oct 12, 2022 3:09 pm
Forum: General
Topic: CCR2004 v7.5 half options in winbox [SOLVED]
Replies: 5
Views: 648

Re: CCR2004 v7.5 half options in winbox [SOLVED]

Wat version of Winbox do you use?
by erlinden
Tue Oct 11, 2022 11:30 am
Forum: General
Topic: DHCP user oversight: DHCP config'd for 192.168.. but device has 192.68.. [SOLVED]
Replies: 3
Views: 774

Re: DHCP wierdness: MT DHCP config'd for 192.168.. but device has 192.68.. [SOLVED]

Could be your DHCP server ;-), think you want to check your pool.
by erlinden
Mon Oct 10, 2022 10:35 am
Forum: General
Topic: Browser address bar often forgets the link after I press Enter and does nothing
Replies: 4
Views: 382

Re: Browser address bar often forgets the link after I press Enter and does nothing

If you can reproduce this behaviour in a non MikroTik environment, you can assume it is not MikroTik related.

What devices are you talking about? Do they all share the same default search engine?
And what makes you think it is MikroTik related?
by erlinden
Sat Oct 08, 2022 9:34 am
Forum: Beginner Basics
Topic: vlan access to winbox
Replies: 5
Views: 799

Re: vlan access to winbox

This rule defines who has access to the router: add action=drop chain=input comment="defconf: drop all not coming from LAN" \ in-interface-list=!LAN Together with this rule anything has access to your router: /interface list member add comment=defconf interface=CapDataPath list=LAN I would...
by erlinden
Thu Oct 06, 2022 3:44 pm
Forum: Wireless Networking
Topic: CAPsMAN firewall configuration
Replies: 3
Views: 449

Re: CAPsMAN firewall configuration

It's up to you have all traffic is routed. Perhaps good to make a network diagram, also containing zones and authorization.
Please read:
https://help.mikrotik.com/docs/display/ROS/CAPsMAN

Specifically:
datapath.client-to-client-forwarding
datapath.local-forwarding
by erlinden
Thu Oct 06, 2022 2:37 pm
Forum: Wireless Networking
Topic: CAPsMAN firewall configuration
Replies: 3
Views: 449

Re: CAPsMAN firewall configuration

From my perspective a firewall on an accesspoint doesn't make sense. Why would you think you need a firewall?
by erlinden
Tue Oct 04, 2022 4:53 pm
Forum: Beginner Basics
Topic: wireguard on android
Replies: 34
Views: 2972

Re: wireguard on android

Difference I see when I look at my settings in Android (and please provide /wireguard export excluding the keys):

MTU left auto
Persistent keepalive left empty

What you can do (besides above):
Check if the firewall filter rule is hit
Check if the peer shows on the router