Community discussions

MikroTik App

Search found 361 matches

  • 1
  • 2
by inteq
Thu Feb 23, 2023 2:24 am
Forum: Virtualization
Topic: CHR licensed check bug report
Replies: 1
Views: 393

Re: CHR licensed check bug report

Had the same issue. You will need to open a ticket with Mikrotik. Some people around here are adamant the CHR licencing needs no overhaul, but it craps itself from time to time. For example in my case: SUP-54631 Hello! No, there was an issue on our side. It is fixed. Sorry for the inconvenience caus...
by inteq
Wed Jan 18, 2023 7:25 am
Forum: The Dude
Topic: How do I add MIBs to the dude
Replies: 29
Views: 23564

Re: How do I add MIBs to the dude

Seems I am starting to forget things, or if you don't use them for too long, you forget them either way. For future reference. No clue if the extra mibs are being used. Synology CPU temperature: CPU-T: [oid("1.3.6.1.4.1.6574.1.2.0")]C Synology HDD temperature: HDD1-T [oid("1.3.6.1.4.1...
by inteq
Wed Jan 18, 2023 6:06 am
Forum: The Dude
Topic: How do I add MIBs to the dude
Replies: 29
Views: 23564

Re: How do I add MIBs to the dude

"Perhaps the Synology MIB doesn't have any thing Dude considers a "table"?" Might be. As stated above a bit, I have another Dude that I have upgraded from ROS 6.3somethhing all the way to 7.7, without any extra mibs, that can read more from Synology, disk like temperatures, fans,...
by inteq
Wed Jan 18, 2023 12:19 am
Forum: The Dude
Topic: How do I add MIBs to the dude
Replies: 29
Views: 23564

Re: How do I add MIBs to the dude

In my case, the module shows just fine. Does not seem to be a path problem. But is is grayed out and not loaded when doing a snmp-walk, as seen in the image below. syno-mib.png Tried all snmp versions 1,2,3. I can see basic snmp info, mostly regarding network interfaces, but nothing contained in tha...
by inteq
Tue Jan 17, 2023 9:51 pm
Forum: The Dude
Topic: How do I add MIBs to the dude
Replies: 29
Views: 23564

Re: How do I add MIBs to the dude

One question.. i upload de MIB file and can view on Dude the entire mib node of the module, all parameters explained.. all ok. But, when i make a snmp-walk over the device that uses this MIB, the values of this module are not visible: i can see IF,SNMP,RFC module values..but not the specific module...
by inteq
Thu Jan 12, 2023 11:04 am
Forum: Virtualization
Topic: CHR license warning
Replies: 17
Views: 944

Re: CHR license warning

I am not asking for support. Znevnva, please got back to twitter/9gag or wherever you lurk during your spare time. I am asking for a warning somewhere in the logs, Winbox top bar or as a popup message. As Normis stated You can use CHR without a license, there are no limits. Trial mode (not licensed)...
by inteq
Thu Jan 12, 2023 4:34 am
Forum: Virtualization
Topic: CHR license warning
Replies: 17
Views: 944

Re: CHR license warning

Unfortunately, I do not have the VM backup anymore, but found a very quick way to reproduce the problem. Shutdown and unregister the VM. Copy it to a new datastore and import it. For some reason, once the VM is copied to another datastore, the interface names change inside RouterOS to ether3 and eth...
by inteq
Wed Jan 11, 2023 11:26 pm
Forum: Virtualization
Topic: CHR license warning
Replies: 17
Views: 944

Re: CHR license warning

@Normis, you keep stating it cannot happen, yet it did in my case. I tried looking for a way to manually remove the licence from within Winbox and could not find one. Will try later this evening to see what could have caused this, ESXI side. Maybe I switched the nics around, automatic MAC that got c...
by inteq
Tue Jan 10, 2023 3:58 pm
Forum: Virtualization
Topic: CHR license warning
Replies: 17
Views: 944

CHR license warning

This post is the rambling of a pissed off user in regards to CHR license and ~16 lost hours. Have a Supermicro server that was in dire need of a good cleaning and ESXI reinstall. This server has a CHR for routing (no NAT) and some VMs inside ESXI. Nothing fancy. So I decided I would do this during w...
by inteq
Tue Jan 10, 2023 6:11 am
Forum: Virtualization
Topic: X710 SR-IOV VF not recognized as a NIC in CHR
Replies: 6
Views: 1572

Re: X710 SR-IOV VF not recognized as a NIC in CHR

I use X722 on ESXI 8 with VMXNET3 and get 10 Gbps with minimal CPU usage.
vswitch is out of the question or why you need SR-IOV?
by inteq
Fri Jan 06, 2023 4:08 am
Forum: RouterBOARD hardware
Topic: [Request] CRS312-4C+8XG - disable zero rpm
Replies: 8
Views: 5845

Re: [Request] CRS312-4C+8XG - disable zero rpm

Spoke too soon. In SwOS, it seems the fan curve is totally diferent from RouterOS for the same device. As soon as the CPU hits 50 Celsius, the fans ramp up to 6.5K rpm, becoming way too loud. swos.png As soon as the temperature gets to around 48 Celsius, the fans will slow down to about 4K rpm. So s...
by inteq
Wed Jan 04, 2023 8:52 am
Forum: General
Topic: winbox DHCP Leases ping lease Improvement Suggestion
Replies: 4
Views: 385

Re: winbox DHCP Leases ping lease Improvement Suggestion

Useful feature to have.
Would not hold my breath tho.
by inteq
Tue Jan 03, 2023 11:19 pm
Forum: RouterBOARD hardware
Topic: CCR2216-PERFORMANCE problem
Replies: 11
Views: 1314

Re: CCR2216-PERFORMANCE problem

m8, remove the "top secret" parts from the export if you want help.
Like calling your doctor and saying "it hurts" while not telling where.
by inteq
Tue Jan 03, 2023 5:11 am
Forum: RouterBOARD hardware
Topic: [Request] CRS312-4C+8XG - disable zero rpm
Replies: 8
Views: 5845

Re: [Request] CRS312-4C+8XG - disable zero rpm

Gave up on some RouterOS features and switched to SwOS. Fans now remain on even @ 40 Celsius doing 3800-4000 rpm. Barely audible. Lost phy-temp and CPU load information via SNMP, as SwOS does not provide those. Seems the device has the capability to always run the fans, but for some reason, the one ...
by inteq
Tue Jan 03, 2023 3:25 am
Forum: RouterBOARD hardware
Topic: CRS312-4C+8XG-RM Fan mod
Replies: 9
Views: 1988

Re: CRS312-4C+8XG-RM Fan mod

Just opened my CRS213 to to try to do something about that pin and...I got fooled by the zoomed in image from above. The actual chip and pins are way smaller. Way too small for my skills, soldering iron and no magnifying glass. Guess I am at the mercy of MT support to fix this crappy zero rpm someti...
by inteq
Mon Jan 02, 2023 5:14 am
Forum: RouterBOARD hardware
Topic: RB3011 port flopping - bad design
Replies: 127
Views: 53744

Re: RB3011 port flopping - bad design

@jimmer Just to be sure, check for a firmware update on that Intel nic.
There were some firmware updates fixing exactly this port flapping.
In my case, with the X722 Intel 10 Gbps nics on Supermicro servers.
Since updating, no more flapping.
by inteq
Mon Jan 02, 2023 1:54 am
Forum: RouterBOARD hardware
Topic: CRS312-4C+8XG-RM Fan mod
Replies: 9
Views: 1988

Re: CRS312-4C+8XG-RM Fan mod

Can't the middle pin be desoldered and raised a bit instead of cutting ?
by inteq
Sun Jan 01, 2023 4:30 pm
Forum: RouterBOARD hardware
Topic: CRS312-4C+8XG-RM Fan mod
Replies: 9
Views: 1988

Re: CRS312-4C+8XG-RM Fan mod

@hyppen Thank you for taking your time to look into this. I am also looking for a way to disable this stupid zero rpm behavior, especially when https://mikrotik.com/product/crs312_4c_8xg_rm states MTBF Approximately 200'000 hours at 25C . (no clue if that refers to ambient or CPU actual temperature)...
by inteq
Sat Dec 31, 2022 5:26 pm
Forum: Wireless Networking
Topic: hAP ac2 impossible 5GHz wifi
Replies: 9
Views: 744

Re: hAP ac2 impossible 5GHz wifi

Try to set the 5 Ghz interface like so:
5.png
by inteq
Mon Dec 19, 2022 10:56 am
Forum: RouterBOARD hardware
Topic: DAC SFP+ cables
Replies: 5
Views: 783

Re: DAC SFP+ cables

Using some MikroTik S+AO0005 and MikroTik XS+DA0003 for some time now without any problems.
DId I miss something and there are problems with Mikrotik ones?
by inteq
Sun Dec 18, 2022 9:50 am
Forum: RouterBOARD hardware
Topic: CCR1009 Rebooting
Replies: 78
Views: 7110

Re: CCR1009 Rebooting

Found several other 1009s doing this. Mikrotik support sent me an alpha version that might fix this. Try routeros-7.7alpha255-tile-2.npk from https://box.mikrotik.com/f/61b327d9fb854902bd58/?dl=1 Or ask support. Installing now and will see how it goes. later edit: 6 days now and no more reboots. No ...
by inteq
Mon Dec 12, 2022 10:05 am
Forum: Scripting
Topic: Mail notification at temperature with TG-BT5-OUT
Replies: 5
Views: 733

Re: Mail notification at temperature with TG-BT5-OUT

This is what I am using [...]
I don't think it refers to the routerboard, but to the external TG-BT5-OUT...
Indeed, I admit I never bothered to look for what exactly the model is.
As it seems it is not a RouterOS device, forget what I said
by inteq
Mon Dec 12, 2022 9:58 am
Forum: Scripting
Topic: Mail notification at temperature with TG-BT5-OUT
Replies: 5
Views: 733

Re: Mail notification at temperature with TG-BT5-OUT

This is what I am using on ROS 7. Will not work on 6. 1st, get the sensor name with /system health print 2nd. edit the script and change the desired values :local DesiredTemp 70 :local MonitoredSensor "phy-temperature" :local NotifyTo ToEmail@domain.com" :local NotifyFrom "Router...
by inteq
Thu Dec 08, 2022 8:59 pm
Forum: RouterBOARD hardware
Topic: CCR1009 Rebooting
Replies: 78
Views: 7110

Re: CCR1009 Rebooting

Had a CCR1009 doing the same. Weird thing is that is was doing the same even after I took it out of the rack and place it on my desk without internet. A netinstall and the same config back and so far no reboots (not back in production tho). Mikrotik support stated they saw a problem from supout and ...
by inteq
Tue Nov 29, 2022 10:12 pm
Forum: RouterBOARD hardware
Topic: RB1100AHx4 vs CCR series for core/distribution?
Replies: 17
Views: 9416

Re: RB1100AHx4 vs CCR series for core/distribution?

No clue. This is the only CCR1009 I can test with.
Anybody else with one can test on local with random?
Maybe my unit is in a coma.

later edit:
found another 1009. Same story
3.png
by inteq
Tue Nov 29, 2022 11:09 am
Forum: RouterBOARD hardware
Topic: RB1100AHx4 vs CCR series for core/distribution?
Replies: 17
Views: 9416

Re: RB1100AHx4 vs CCR series for core/distribution?

Have a ressurected CCR1009 on the desk and was wondering the same thing. Purely computational wise, RB1100AHx4 is light years ahead of CCR1009 Bandwidth test on 127.0.0.1 for both I think shows that CCR1009 CCR1009.png RB1100AHx4 1100AHx4.png Also note that the CCR1009 was blank, without any firewal...
by inteq
Wed Nov 23, 2022 4:42 pm
Forum: General
Topic: Detect ISP limiting packets/second
Replies: 2
Views: 239

Re: Detect ISP limiting packets/second

Thank you mkx. Will try iperf3.
by inteq
Wed Nov 23, 2022 6:44 am
Forum: General
Topic: Detect ISP limiting packets/second
Replies: 2
Views: 239

Detect ISP limiting packets/second

Hello, Can one detect if the ISP is limiting pps between two locations? Might be totally wrong, but in Winbox, under IP/Firewall/Connections, if selecting Orig./Repl. Packets and filtering the connection in question, the amout of orig. packets should match the reply packets closely, correct? (might ...
by inteq
Fri Sep 16, 2022 2:54 am
Forum: RouterBOARD hardware
Topic: hardware idea for two-port high performance router
Replies: 2
Views: 543

Re: hardware idea for two-port high performance router

A small but powerfull 2 SPF+ only would be a dream for many locations.
I have only one location without a proper switch.
Rest, only ether1 and ether 2 in use, no matter how big the router is. Waste of ports to be frank.
by inteq
Mon Sep 05, 2022 5:24 am
Forum: The Dude
Topic: DUDE V7.4.1
Replies: 2
Views: 1079

Re: DUDE V7.4.1

Don't bother with 7.4.1 and even 7.5. You can't upgrade from The Dude.
by inteq
Fri Aug 26, 2022 12:49 am
Forum: The Dude
Topic: DUDE v7 server "needed packages are not available"
Replies: 29
Views: 5772

Re: DUDE v7 server "needed packages are not available"

7.4.1 same story
And I have a lot of devices to update...
by inteq
Mon Aug 15, 2022 11:41 am
Forum: General
Topic: Bridge is not transparent default ?
Replies: 38
Views: 1733

Re: Bridge is not transparent default ?

Wild guess because I just woke up. Maybe because your machine has a static IP in 192.168.1.0 that is default on Asus and Mikrotik's default is 192.168.88.0 ? Change pool and DHCP server details to 182.168.1.0 or 192.168.0.0 network on Mikrotik. Could be that the machine has a firewall allowing only ...
by inteq
Wed Aug 03, 2022 7:41 am
Forum: RouterBOARD hardware
Topic: [Request] CRS312-4C+8XG - disable zero rpm
Replies: 8
Views: 5845

Re: [Request] CRS312-4C+8XG - disable zero rpm

RouterOS 7.4 and the exact same behavior.
Pretty please with sugar on top allow us to disable zero rpm.
Fans @ ~4k rpm are barely audible and are doing an excellent job in keeping the switch cool.
by inteq
Sun Jul 24, 2022 6:50 am
Forum: The Dude
Topic: Problem SNMP speed interface
Replies: 12
Views: 10370

Re: Problem SNMP speed interface

by inteq
Thu Jul 21, 2022 12:46 pm
Forum: The Dude
Topic: SNMP Feature Request or Work Around
Replies: 1
Views: 515

Re: SNMP Feature Request or Work Around

CPU-Load: [oid("1.3.6.1.2.1.25.3.3.1.2.1")]%
Screenshot 2022-07-21 130247.png
by inteq
Sun Jul 17, 2022 2:34 am
Forum: Scripting
Topic: eth port speedcheck
Replies: 4
Views: 641

Re: eth port speedcheck

Using The Dude, add a new probe like:
1.png
With OID:
iso.org.dod.internet.mgmt.mib-2.interfaces.ifTable.ifEntry.ifSpeed.1
Some routers will have a different OID. For example, HAP AC2 uses
 iso.org.dod.internet.mgmt.mib-2.interfaces.ifTable.ifEntry.ifSpeed.3
for port 1
Add the probe to the device
by inteq
Sun Jun 19, 2022 12:57 am
Forum: Wireless Networking
Topic: WiFi reverberation
Replies: 3
Views: 474

WiFi reverberation

Hello, I have a location built like a doomsday bunker, with lots of reinforced concrete. Most rooms are like this: ceiling.png Yeah, I skipped art classes if you cannot tell from the masterpiece above. Now, the owner would like the AP placement in the blue spot (out of sight). The problem is that be...
by inteq
Thu Jun 16, 2022 12:19 pm
Forum: Wireless Networking
Topic: Wifi romaing Hap ac3
Replies: 18
Views: 995

Re: Wifi romaing Hap ac3

Mikrotik does NOT (edited) really have proper roaming I am afraid.
Try using capsman on the router and setup the two APs as caps.
Make sure you are not using Access Lists for WiFi with reject based on signal. That will cause disconnects as you describe.
by inteq
Thu Jun 16, 2022 11:56 am
Forum: Wireless Networking
Topic: Wifi romaing Hap ac3
Replies: 18
Views: 995

Re: Wifi romaing Hap ac3

You have 3 routers in your local network?
Or one router and two APs (or configured as AP)?
by inteq
Sun Jun 12, 2022 7:09 pm
Forum: General
Topic: FIREWALL AND SPAM PROTECTION(RouterOS v6.47.8 (stable))
Replies: 4
Views: 513

Re: FIREWALL AND SPAM PROTECTION(RouterOS v6.47.8 (stable))

Playing the bad cop here: if you need to ask how to remove your mail server from a blacklist, I strongly advise you should think about getting a service from the big guys in the business.
by inteq
Sat Jun 11, 2022 7:47 pm
Forum: General
Topic: DNS over HTTPS
Replies: 235
Views: 95179

Re: DNS over HTTPS

That's what DoH (and others similar) was created for, so you don't spy/track/hijack your clients DNS requests.
While at the same time most DoH "supporters" use cloudflare, google and Co servers. The mothers of all spies.
DoH is a stupid idea.
by inteq
Sat Jun 11, 2022 4:38 pm
Forum: General
Topic: CRS312-4C+8XG slow speed 10 Gbps to 1 Gbps
Replies: 3
Views: 316

Re: CRS312-4C+8XG slow speed 10 Gbps to 1 Gbps

try checking your PC 10g nic windows advanced settings
Thank you.
intmod.jpg
This little piggy was to blame. Was disabled. Enabled it and problem is gone.
by inteq
Sat Jun 11, 2022 3:51 pm
Forum: General
Topic: CRS312-4C+8XG slow speed 10 Gbps to 1 Gbps
Replies: 3
Views: 316

CRS312-4C+8XG slow speed 10 Gbps to 1 Gbps

Hello, I have a CRS312-4C+8XG https://mikrotik.com/product/crs312_4c_8xg_rm Using RouterOS version 6.49.6. No queues or firewall rules. Plain switching. PC connected via cooper 10 Gbps to it. ( 5 meters ) NAS connected via cooper 10 Gbps to it ( 1 meter ) Problem When connecting a 1 Gbps client to t...
by inteq
Sun May 08, 2022 5:01 pm
Forum: RouterBOARD hardware
Topic: Unboxing and more - MikroTik CCR2116 & CCR2216
Replies: 4
Views: 1337

Re: Unboxing and more - MikroTik CCR2116 & CCR2216

Never understood tech channels on youtube with English title, English description and alien language.
by inteq
Tue Apr 26, 2022 2:51 pm
Forum: The Dude
Topic: Dude - Slow DDNS to IP [SOLVED]
Replies: 2
Views: 868

Re: Dude - Slow DDNS to IP [SOLVED]

The DNS Lookup Interval default value is 60 minutes
and you can change that on device property, not on general settings.
Thank you rextended.
An extra pair of eyes always helps.
by inteq
Tue Apr 26, 2022 2:01 pm
Forum: The Dude
Topic: Dude - Slow DDNS to IP [SOLVED]
Replies: 2
Views: 868

Dude - Slow DDNS to IP [SOLVED]

Hello, As to not reopen a topic from 2008 https://forum.mikrotik.com/viewtopic.php?p=105231 , I am opening a new one. I am monitoring quite a lot of devices with dynamic IPs, thus the need for DDNS. The problem: The Dude is very slow to detect IP changes. Cannot say for sure, but it seems it can tak...
by inteq
Thu Feb 10, 2022 3:04 pm
Forum: RouterBOARD hardware
Topic: RB4011 - loose antennae
Replies: 6
Views: 6039

Re: RB4011 - loose antennae

Got another RB4011 and the difference is night and day. The antennae are pretty tight.
Got my answer.
by inteq
Sun Jan 30, 2022 4:19 pm
Forum: General
Topic: How do I allow DNS traffic from one VLAN to another? [SOLVED]
Replies: 12
Views: 8118

Re: How do I allow DNS traffic from one VLAN to another? [SOLVED]

No clue where you got lost. This setup works just fine for hundreds of clients.
If you need a small diagram, reply and will do one.
by inteq
Sat Jan 22, 2022 4:33 pm
Forum: RouterBOARD hardware
Topic: RB4011 - loose antennae
Replies: 6
Views: 6039

RB4011 - loose antennae

Hello, Need confirmation from someone with a MikroTik RB4011iGS+5HacQ2HnD-IN if the antennae on their router are a bit loose or not. Have a client I suspect dropped their MikroTik RB4011iGS+5HacQ2HnD-IN and now some of the antennae are very loose. So loose that it barely stays upright on its own. Bu...
by inteq
Fri Jan 21, 2022 6:03 am
Forum: General
Topic: l2tp with ipsec between CHR and RB
Replies: 24
Views: 2330

Re: l2tp with ipsec between CHR and RB

You are missing/messing something in your config. Since the same config works for the OP in 6.48.6 but doesn't in 6.49.2 and 7.1.1, I'd assume some encryption algo or alike to behave different between the versions, depending on CPU architecture. So I'd suggest to compare the /ip ipsec profile and /...
by inteq
Thu Jan 20, 2022 6:38 pm
Forum: General
Topic: l2tp with ipsec between CHR and RB
Replies: 24
Views: 2330

Re: l2tp with ipsec between CHR and RB

Tested from a RB1100AHx4 to a CHR on a ESXI 7 VM. Both on RoS 6.49.2
All good. Both ways.
You are missing/messing something in your config.
by inteq
Tue Jan 18, 2022 3:03 pm
Forum: General
Topic: L2TP/IPsec Issues with Windows 11 update - kb5009566
Replies: 29
Views: 18395

Re: L2TP/IPsec Issues with Windows 11 update - kb5009566

@inteq
Thank you for sharing I liked the Client "Draytek" it's very useful.
Did you test all the protocols working with MT?
Just L2TP with IPSEC
by inteq
Tue Jan 18, 2022 11:39 am
Forum: General
Topic: L2TP/IPsec Issues with Windows 11 update - kb5009566
Replies: 29
Views: 18395

Re: L2TP/IPsec Issues with Windows 11 update - kb5009566

MS has released a out-of-band fix for this VPN issue. Windows 10: https://support.microsoft.com/en-gb/topic/january-17-2022-kb5010793-os-builds-19042-1469-19043-1469-and-19044-1469-out-of-band-f2d4f178-5b36-49cb-a6fd-4bf9857574f9 Windows update catalog (Win 10): https://www.catalog.update.microsoft...
by inteq
Tue Jan 18, 2022 7:30 am
Forum: General
Topic: L2TP/IPsec Issues with Windows 11 update - kb5009566
Replies: 29
Views: 18395

Re: L2TP/IPsec Issues with Windows 11 update - kb5009566

Windows 10: wusa /uninstall /kb:5009543 yeah this works, and you will have reenter the L2TP username/password in windows, the IPsec PSK remained. Just use https://www.draytek.com/products/smart-vpn-client/ Works just fine with Mikrotik. You can export your profiles and import them back when needed....
by inteq
Fri Jan 14, 2022 10:28 am
Forum: Scripting
Topic: Black list for failed login to IPSec VPN
Replies: 49
Views: 24014

Re: Black list for failed login to IPSec VPN

Thank you Jotne
by inteq
Fri Jan 14, 2022 5:01 am
Forum: Scripting
Topic: Black list for failed login to IPSec VPN
Replies: 49
Views: 24014

Re: Black list for failed login to IPSec VPN

There is an 1.3 in this thread as well. Test it out. (Do not remember what was changed from 1.2 to 1.3)
Tested the 1.3 version a bit and found some problems.
err.png
I guess the script was not supposed to add phase1 to the list, right?
by inteq
Thu Jan 13, 2022 3:24 pm
Forum: Scripting
Topic: Black list for failed login to IPSec VPN
Replies: 49
Views: 24014

Re: Black list for failed login to IPSec VPN

There is an 1.3 in this thread as well. Test it out. (Do not remember what was changed from 1.2 to 1.3)
Missed the 1.3 one. Will test now.
Thank you.
by inteq
Thu Jan 13, 2022 3:19 pm
Forum: Scripting
Topic: Black list for failed login to IPSec VPN
Replies: 49
Views: 24014

Re: Black list for failed login to IPSec VPN

Was looking for such a script for a long time. Trying to implement it on a router getting lots of "negotiation failed" but I have an issue. The offending IP is added to IPSEC list, but it also adds 0.0.0.0 to the same list for some reason. Any clue as to why? Nothing in log showing 0.0.0....
by inteq
Thu Jan 13, 2022 1:38 pm
Forum: Scripting
Topic: Black list for failed login to IPSec VPN
Replies: 49
Views: 24014

Re: Black list for failed login to IPSec VPN

Do not worry to use any time interval, parse all logs, the script prevent double-set IP on address list than cause interruption for error on duplicate entry. This script do not prevent the lock of your own remote IP if some error happen meantime. Remember to create the whitelist of yours IPs and ad...
by inteq
Wed Jan 12, 2022 3:16 pm
Forum: General
Topic: L2TP/IPSec VPN - <random ip> failed to get valid proposal. [SOLVED]
Replies: 9
Views: 5219

Re: L2TP/IPSec VPN - <random ip> failed to get valid proposal. [SOLVED]

...
If you are after the best practice for this. there are scripts in the forum that can read log entries and add the src address to your black list.
Can you point us to one of those?
I looked and came up empty.
by inteq
Wed Jan 12, 2022 1:52 pm
Forum: General
Topic: L2TP/IPsec Issues with Windows 11 update - kb5009566
Replies: 29
Views: 18395

Re: L2TP/IPsec Issues with Windows 11 update - kb5009566

Windows 10:
wusa /uninstall /kb:5009543
by inteq
Sun Dec 26, 2021 3:04 pm
Forum: General
Topic: How do I block pronographic images in my RB?
Replies: 82
Views: 16207

Re: How do I block pronographic images in my RB?

most web browsers now default to using DNS over HTTPS to increase user privacy.
Good one.
/s
by inteq
Fri Dec 17, 2021 8:22 pm
Forum: General
Topic: Adapt FTP brute force banning rules for LT2P/IPSEC [SOLVED]
Replies: 5
Views: 1526

Re: Adapt FTP brute force banning rules for LT2P/IPSEC [SOLVED]

The problem is if a user reconnects/disconnects too fast, it will end up in the blacklist also.
by inteq
Thu Dec 16, 2021 12:29 am
Forum: General
Topic: Which types of ports would you like to see for a high speed router
Replies: 179
Views: 53806

Re: Which types of ports would you like to see for a high speed router

2 x SFP+ (10G)
2 x 10Gbit copper (10G)
1 x Management with PoE

99% of locations I manage are using only 1 ISP, thus most multi port routers are pretty much empty (only using two ports because switches on RBs are crap)
by inteq
Wed Dec 15, 2021 11:55 pm
Forum: General
Topic: v6.49 cut me off - invalid username or password (rant)
Replies: 12
Views: 3130

Re: v6.49 cut me off - invalid username or password (rant)

Only two options:
A: not a "safe controlled environment" and someone else changed the password.
B: you changed the password or restored a backup containing a password and Alzeheimer wants to know your location.
by inteq
Mon Dec 06, 2021 3:28 pm
Forum: The Dude
Topic: The Dude Agent Port Issue
Replies: 5
Views: 6710

Re: The Dude Agent Port Issue

I am all for more options and customizability, don't get me wrong.
Just curious as to why the need for a diferent WinBox port and more importantly, why "is not an option for some"?
by inteq
Sat Dec 04, 2021 7:38 am
Forum: Wireless Networking
Topic: 802.11ac severe speed degradation with ROS above 6.45.9 (LTS)
Replies: 28
Views: 10791

Re: 802.11ac severe speed degradation with ROS above 6.45.9 (LTS)

Dowgraded from 6.49.1 to 6.45.9 one of my home wAP to test this.
The AP is a cap on a 1100AHx4DE.
Tested both versions on 5 Ghz at ~ 5m distance, direct sight and could not observe any differences.

6.49.1
Screenshot_20211204-071551_Speedtest.jpg
6.45.9
Screenshot_20211204-072340_Speedtest.jpg
by inteq
Sat Nov 27, 2021 7:44 pm
Forum: The Dude
Topic: The dude . links creation question
Replies: 3
Views: 7070

Re: The dude . links creation question

Do all devices allow inbound Winbox port? If yes, it is accessible from all devices?
Have you set the type to RouterOS for each device?
by inteq
Sun Nov 21, 2021 3:16 am
Forum: The Dude
Topic: The Dude Agent Port Issue
Replies: 5
Views: 6710

Re: The Dude Agent Port Issue

If you are changing the default Winbox port hoping to be "stealthy", you are doing it wrong.
Just leave the darn port at default and setup good firewall rules/allow only whitelisted management IPs
by inteq
Sat Nov 20, 2021 1:46 am
Forum: Announcements
Topic: v6.49.1 [stable] is released!
Replies: 138
Views: 73641

Re: v6.49.1 [stable] is released!

No issues updating on:
RB1100AHx2,AHx4 and Dude edition. RB4011, CCR1009 and a lonely HeX S
HAP AC2&3
WAP and CAP AC (old and new models),Audience
CRS312
by inteq
Sat Nov 20, 2021 1:36 am
Forum: RouterBOARD hardware
Topic: [Request] CRS312-4C+8XG - disable zero rpm
Replies: 8
Views: 5845

Re: [Request] CRS312-4C+8XG - disable zero rpm

6.49.1 and it seems something has been changed. Not necessarly for the better. 8 minutes after upgrade and reboot the fans were still spinning at 8k rpm. I thought to myself "I should stop sending requests to support" thinking the fans now will be locked at 8k rpm. Did not notice this beha...
by inteq
Fri Oct 29, 2021 9:27 am
Forum: The Dude
Topic: Monitor l2tp links [SOLVED]
Replies: 0
Views: 5009

Monitor l2tp links [SOLVED]

Hello, Trying to monitor some l2tp links that feed into one central location. Everything works OK. The problems is if a l2tp link goes down for whatever reason, The Dude will default the monitored interface to another available interface and never recover, even after the l2tp link comes back online....
by inteq
Mon Oct 25, 2021 12:26 pm
Forum: RouterBOARD hardware
Topic: [Request] CRS312-4C+8XG - disable zero rpm
Replies: 8
Views: 5845

Re: [Request] CRS312-4C+8XG - disable zero rpm

Mikrotik support stated:

Hello,

Thank you for the report!
We have managed to reproduce the issue locally in our labs and look forward to fixing it on upcoming RouterOS versions, unfortunately, I cannot provide an ETA now.
by inteq
Sun Oct 24, 2021 4:21 pm
Forum: RouterBOARD hardware
Topic: [Request] CRS312-4C+8XG - disable zero rpm
Replies: 8
Views: 5845

[Request] CRS312-4C+8XG - disable zero rpm

Hello, Testing a CRS312-4C+8XG destined for office environment and I have to say the noise level is decent at ~4k rpm (as reported by Winbox with ROS 6.49). The problem is the fans will stop spinning under a certain temperature (~50 Celsius CPU and ~ 55 Celsius PHY), the temperature will quickly ris...
by inteq
Mon Oct 11, 2021 5:49 am
Forum: Wireless Networking
Topic: hap ac3 - worse than hap lite?
Replies: 15
Views: 3640

Re: hap ac3 - worse than hap lite?

Don't bother looking for a fix to your setup. hAP AC3 just sucks for some reason. Maybe they will fix it in a future RouterOS version.
viewtopic.php?p=827986#p823038
by inteq
Tue Oct 05, 2021 6:09 am
Forum: General
Topic: No audio on sip calls over VPN
Replies: 8
Views: 1988

Re: No audio on sip calls over VPN

In IP/Firewall/Raw add a rule with source as your VPN pool and destination as your PBX IP in prerouting chain and with action no track.
Copy the rule and reverse source with destination.
by inteq
Sun Sep 12, 2021 6:45 pm
Forum: General
Topic: Automatically filter a rogue public IP
Replies: 6
Views: 914

Re: Automatically filter a rogue public IP

Any time you open a port for some specific program, there is a chance it will end badly. But at least in the case of RDP, we know there are lots of vulnerabilities. Some patched, some not yet found and a lot of them with released patches but not applied. For example: https://nvd.nist.gov/vuln/detail...
by inteq
Thu Sep 09, 2021 8:26 pm
Forum: General
Topic: Automatically filter a rogue public IP
Replies: 6
Views: 914

Re: Automatically filter a rogue public IP

1st: never ever open rdp to public.
Use a VPN or allow RDP port only for certain trusted static IPs or ddns
by inteq
Wed Aug 04, 2021 4:13 pm
Forum: The Dude
Topic: The Dude Server on CHR free license and 1Mbps limit
Replies: 8
Views: 6691

Re: The Dude Server on CHR free license and 1Mbps limit

@sid5632 can you please tell what was the issue exactly? What does "CHR was stopping transmitting" means?
I ask, because I also have problems with Dude on CHR randomly making everything inaccessible for short periods of time (10-30 seconds). Dude disabled=no problems.
by inteq
Sun Jul 25, 2021 10:39 am
Forum: Virtualization
Topic: Unable to utilize more than 1Gb of ram CHR on Proxmox
Replies: 3
Views: 4206

Re: Unable to utilize more than 1Gb of ram CHR on Proxmox

Just a guess, but try to disable hugepages (+pdpe1gb)
Don't have this issue on ESXi
by inteq
Sat Jul 24, 2021 6:26 am
Forum: Virtualization
Topic: CHR feature requests
Replies: 81
Views: 32659

Re: CHR feature requests

Well, expired license means you cannot upgrade ROS version. The router itself continues to work just as before. Support stated the same, nevertheless, I do not agree. At least one function did not work while the problem was active, so who knows what other functions are disabled? I only checked IP/C...
by inteq
Thu Jul 15, 2021 10:34 am
Forum: Virtualization
Topic: CHR feature requests
Replies: 81
Views: 32659

Re: CHR feature requests

Just discovered that my CHR unlimited license was not updating/renewing. Who knows for how long this has been going on. Support fixed it after two days and stated the problem was on MT's end. Would be nice to get a warning in Winbox about license issues. Never crossed my mind to check the license st...
by inteq
Tue Jun 15, 2021 1:09 pm
Forum: The Dude
Topic: Dude causing massive packet loss/disruption of service
Replies: 9
Views: 6861

Re: Dude causing massive packet loss/disruption of service

Yes, CPU and RAM barely used.
No comment regarding the "I never run 2 totaly different functions on 1 device"
by inteq
Tue Jun 15, 2021 10:49 am
Forum: The Dude
Topic: Dude causing massive packet loss/disruption of service
Replies: 9
Views: 6861

Re: Dude causing massive packet loss/disruption of service

The Dude is running on the router. Physical, VM, makes no difference.
by inteq
Fri Jun 11, 2021 4:37 pm
Forum: The Dude
Topic: Dude causing massive packet loss/disruption of service
Replies: 9
Views: 6861

Dude causing massive packet loss/disruption of service

Hello, Had some issues with a lot of routerboards causing internet service disruption/massive packet loss. Randomly, the router would not be accessible for 10-30 seconds. No interface flopping logged. Even weirder, a subnet behind the router will also lose connectivity when this happens. A netwatch ...
by inteq
Fri Jun 11, 2021 10:59 am
Forum: RouterBOARD hardware
Topic: hAP ac³
Replies: 42
Views: 12477

Re: hAP ac³

Bought Mikrotik hap ac3. Have a questions on wireless interfaces. In winbox, interface wlan1 or 2 in current Tx power there is no information. 2.4Ghz showing 0 Tx power, 5Ghz showing nothing. In Freq. usage function Hap Lite is always showing many channels with 75...90...50 usage, at the same time ...
by inteq
Tue May 25, 2021 4:50 pm
Forum: Beginner Basics
Topic: wAP AC Continuous Reboot After Upgrade to 6.43.8
Replies: 27
Views: 11180

Re: wAP AC Continuous Reboot After Upgrade to 6.43.8

I've always wondered if the reason I routinely encounter this problem is because I'm not running on a physical PC, but inside a Windows VM on a Mac device. Just for my curiosity, are you running on a physical PC?
Yes. Physical machine with W10. No VM.
by inteq
Tue May 25, 2021 8:00 am
Forum: Beginner Basics
Topic: wAP AC Continuous Reboot After Upgrade to 6.43.8
Replies: 27
Views: 11180

Re: wAP AC Continuous Reboot After Upgrade to 6.43.8

Netinstall works, not all users do!
Say thank you for not stumbling upon this issue (yet) and move on if you have nothing better to add.
by inteq
Mon May 24, 2021 5:25 pm
Forum: Beginner Basics
Topic: wAP AC Continuous Reboot After Upgrade to 6.43.8
Replies: 27
Views: 11180

Re: wAP AC Continuous Reboot After Upgrade to 6.43.8

Had this issue today with a RBwAPG-5HacD2HnD. Failed upgrade to 6.48.2 and had to be sent back to me from another city. Netinstall did nothing and had to resort to the trick of closing the program, opening it again, deleting set and quickly install. This was the only way to successfully unbrick it a...
by inteq
Sat May 22, 2021 4:11 pm
Forum: RouterBOARD hardware
Topic: HAP AC3 Antenna
Replies: 4
Views: 3540

Re: HAP AC3 Antenna

The RF Amplifier will be damaged if both antenna is not attached to the board. How does one know tht RF Amp is damaged? I've just purchased used ac3 and 5Ghz performance is really poor. Can it be because of damaged RF Amp? Cannot vouch for the possibility of damage without them attached, but can vo...
by inteq
Mon Apr 12, 2021 6:32 pm
Forum: RouterBOARD hardware
Topic: RB5011?
Replies: 19
Views: 4480

Re: RB5011?

"HAP AC2 lack memory"
What you need more memory for on that tiny thing?
by inteq
Fri Apr 09, 2021 9:43 pm
Forum: RouterBOARD hardware
Topic: S+RJ10 transceiver 101oC temperature - Causing burn injury
Replies: 5
Views: 2941

Re: S+RJ10 transceiver 101oC temperature - Causing burn injury

My solution on the only two switches using those modules is to put a small 40mm fan inside blowing straight onto the modules and one on the back exhausting air. Ugly part: requires an external power supply for the fans. sfp.png Fun fact: both modules are in use, nevertheless, one is always 10 degree...
by inteq
Wed Feb 24, 2021 6:41 pm
Forum: General
Topic: DNS-resolution without DNS-Sever, Route or IP
Replies: 6
Views: 1331

Re: DNS-resolution without DNS-Sever, Route or IP

Have you cleared DNS cache?
by inteq
Mon Feb 22, 2021 9:15 pm
Forum: General
Topic: Winbox - Darkmode - Please [SOLVED]
Replies: 31
Views: 14395

Re: Winbox - Darkmode - For the love of God, Please. [SOLVED]

Yes, because changing a color would take an entire team of devs several months. /s
What does WinBox background color have to do with ROS other bugs is beyond me.
by inteq
Sat Feb 06, 2021 6:44 pm
Forum: Wireless Networking
Topic: 2.4 4-way handshake timeout
Replies: 18
Views: 12408

Re: 2.4 4-way handshake timeout

Don't fight it. Don't mess with support. Just buy the Ruckus radio and move on.
U R funny. Check https://forums.ruckuswireless.com/conve ... e247913632
by inteq
Sat Jan 23, 2021 3:37 am
Forum: RouterBOARD hardware
Topic: Hap AC3 Availability
Replies: 4
Views: 1387

Re: Hap AC3 Availability

We can only hope the reason for AC3 not being in stock is because they are working on making those antennae actually doing something useful, like extending coverage.
by inteq
Thu Jan 14, 2021 5:29 pm
Forum: Wireless Networking
Topic: Wireless disconnected, group key exchange timeout
Replies: 68
Views: 69572

Re: Wireless disconnected, group key exchange timeout

Having this issue with lots of Xiaomi devices, like Air purifiers and smart speakers.
Changed the group-key-update to 1 hour now. Will see.
by inteq
Thu Jan 14, 2021 3:02 am
Forum: General
Topic: 3 routers in a row defective possible? [SOLVED]
Replies: 24
Views: 6076

Re: 3 routers in a row defective possible? [SOLVED]

Enabled The Dude again for one week. Packet loss and problems started. Disable again.No more packet loss. I do not think it is related to ARM, because after trying 4 ARM Mikrotik routers I moved this particular location to a CHR unlimited and the same problem continues. Funny thing is that RouterOS ...
by inteq
Thu Dec 24, 2020 12:23 pm
Forum: General
Topic: 3 routers in a row defective possible? [SOLVED]
Replies: 24
Views: 6076

Re: 3 routers in a row defective possible? [SOLVED]

Quick update I disabled Dude notification for some time and just stopped thinking about it too much. Beginning of December I decided to just disable The Dude because in my mind, the program had a lot of false positives. I just became numb to connection issues reported by The Dude. Lo and behold, 2 w...
by inteq
Thu Dec 03, 2020 11:59 am
Forum: General
Topic: timeout while waiting for program 20
Replies: 23
Views: 15009

Re: timeout while waiting for program 20

1 day max to update to the latest stable RouterOS since release. So latest.
by inteq
Sun Nov 22, 2020 9:45 pm
Forum: General
Topic: share UPS info with other machines on the network [SOLVED]
Replies: 3
Views: 1629

Re: share UPS info with other machines on the network [SOLVED]

Most APC UPS will cut power once they send the critical battery status and after a predefined delay.
So in theory, the fact the RouterOS is dumb in this regard does not matter.
by inteq
Wed Nov 18, 2020 1:32 pm
Forum: Scripting
Topic: capsman wireless standalone flip script asked [SOLVED]
Replies: 8
Views: 1487

Re: capsman wireless standalone flip script asked [SOLVED]

I do not get it You ping the capsman IP and if no response you disable caps mode. Every X minutes you enable caps mode to check if your device connects to the manager, in the process booting every WiFi device off the network. That is one weird WiFi experience for devices on that network. If the clie...
by inteq
Wed Nov 18, 2020 4:30 am
Forum: Scripting
Topic: capsman wireless standalone flip script asked [SOLVED]
Replies: 8
Views: 1487

Re: capsman wireless standalone flip script asked [SOLVED]

Won't work. Your hap ac lite will need to enable caps mode to be able to check if it can connect to the manager, disconnecting all wifi clients in the process. A https://mikrotik.com/product/ltap_mini_lte_kit might work, having a GPS. You could then script by GPS location. If at certain coordinate, ...
by inteq
Sun Nov 15, 2020 11:31 pm
Forum: Scripting
Topic: Run command in specific timeframe
Replies: 5
Views: 961

Re: Run command in specific timeframe

Just double checked and it seems RouterOS does not support this type of time calculation without extra math involved.
by inteq
Sun Nov 15, 2020 7:39 pm
Forum: Scripting
Topic: Run command in specific timeframe
Replies: 5
Views: 961

Re: Run command in specific timeframe

Execute your command inside the do={ }
by inteq
Sun Nov 15, 2020 7:25 pm
Forum: Scripting
Topic: Run command in specific timeframe
Replies: 5
Views: 961

Re: Run command in specific timeframe

See if this helps:
:local time [/system clock get time];
:if ($time >= "03:00:00" || $time <= "04:00:00") do={ :log warning hammer time } 
by inteq
Sat Nov 14, 2020 10:52 pm
Forum: The User Manager
Topic: Hotspot Radius Server not responding
Replies: 1
Views: 4115

Re: Hotspot Radius Server not responding

I admit I only tried for a short time to troubleshoot userman, but I ended up ditching it in favor of an external RADIUS server. Synology for example comes with a RADIUS server package and I use it everywhere one is to be found for VPN auth and such. An alternative is a small Raspberry PI3/4 with a ...
by inteq
Sat Nov 14, 2020 3:22 pm
Forum: Wireless Networking
Topic: Low speed through CAPSMAN [SOLVED]
Replies: 6
Views: 4130

Re: Low speed through CAPSMAN [SOLVED]

Theory is not the problem. Real world testing with the devices I work with tells me there is no difference. And wAP ac has some pretty slow CPU. No clue what you mean by "So, if I will turn local forwarding off, all devies will get dhcp not from capsman, but from local network.". Local for...
by inteq
Fri Nov 13, 2020 2:46 pm
Forum: The Dude
Topic: Dude setup and device status keeps/stays Unknown [SOLVED]
Replies: 6
Views: 2923

Re: Dude setup and device status keeps/stays Unknown [SOLVED]

"What test causes the status to be set to Up?: the service status being monitored on each device. For example ping."
Thank God you "Found the solution myself".
by inteq
Wed Nov 11, 2020 4:09 pm
Forum: RouterBOARD hardware
Topic: hAP ac³
Replies: 42
Views: 12477

Re: hAP ac³

Antenna gain cannot be configured under capsman. I updated all 3 devices to the latest stable RouterOS. Reset into capsman mode: reset.png capsman set to auto provision using 00:00:00:00:00:00 MAC on both 2.4 and 5Ghz. Settings on AP: -disabled all IP/Services but Winbox. -disabled all IP/Firewall/S...
by inteq
Wed Nov 11, 2020 12:08 am
Forum: The Dude
Topic: Dude setup and device status keeps/stays Unknown [SOLVED]
Replies: 6
Views: 2923

Re: Dude setup and device status keeps/stays Unknown [SOLVED]

The agent is setup on The Dude server for each device. What test causes the status to be set to Up?: the service status being monitored on each device. For example ping. You said the two wAPs are setup identically. By any chance you copied the config from one to the other? If so, check if wAPs have ...
by inteq
Tue Nov 10, 2020 11:19 pm
Forum: The Dude
Topic: Dude setup and device status keeps/stays Unknown [SOLVED]
Replies: 6
Views: 2923

Re: Dude setup and device status keeps/stays Unknown [SOLVED]

Which service is being monitored on the 172.19.3.249 wAP?
if ping, can you ping it from the dude server?
The agent is correctly setup for it?
by inteq
Tue Nov 10, 2020 6:11 pm
Forum: RouterBOARD hardware
Topic: hAP ac³
Replies: 42
Views: 12477

Re: hAP ac³

Same exact RouterOS version. Same exact settings for WiFi, all 3 devices provisioned through capsman 00:00:00:00:00:00 on both radios, with channel 36 (5180Mhz) on 5Ghz, only-AC All 3 devices tested one at a time, so close to no radio interference. Only the testing client registered on capsman. Mayb...
by inteq
Tue Nov 10, 2020 10:01 am
Forum: RouterBOARD hardware
Topic: WiFi of hAP ac³ vs. hAP ac³ LTE6 kit [SOLVED]
Replies: 4
Views: 1369

Re: WiFi of hAP ac³ vs. hAP ac³ LTE6 kit [SOLVED]

I have tested AC3 and AC2, that is why I was telling you to skip ac3. External antennae are just for show on ac3. See https://forum.mikrotik.com/viewtopic.php?f=3&t=166931&p=823038#p823038 On the other hand, both ac2 and ac3 are pretty cheap to buy, so go buy one and test if it helps you sto...
by inteq
Sun Nov 08, 2020 9:02 am
Forum: RouterBOARD hardware
Topic: Idea for 1U Core Router with 4xSFP+
Replies: 9
Views: 3806

Re: Idea for 1U Core Router with 4xSFP+

For my use cases, bare metal RoS would be a waste. I admit I did not even try without virtualization.
ESXi throughput with 4 cores allocated:
bt.png
by inteq
Sun Nov 08, 2020 7:46 am
Forum: RouterBOARD hardware
Topic: Idea for 1U Core Router with 4xSFP+
Replies: 9
Views: 3806

Re: Idea for 1U Core Router with 4xSFP+

Using https://www.supermicro.com/en/products/ ... -FN8TP.cfm under ESXi
No BGP tho and this model only has 2X SFP+, but the option to add a PCIe via a 90 degree angle riser (included)
by inteq
Sat Nov 07, 2020 5:41 pm
Forum: RouterBOARD hardware
Topic: Idea for 1U Core Router with 4xSFP+
Replies: 9
Views: 3806

Re: Idea for 1U Core Router with 4xSFP+

Supermicro has some nice 1U with 4X SFP+, 2x 10Gb ethernet and 2x 1Gb ethernet
See https://www.supermicro.com/en/products/ ... /rackmount
by inteq
Sat Nov 07, 2020 4:42 pm
Forum: RouterBOARD hardware
Topic: WiFi of hAP ac³ vs. hAP ac³ LTE6 kit [SOLVED]
Replies: 4
Views: 1369

Re: WiFi of hAP ac³ vs. hAP ac³ LTE6 kit [SOLVED]

Both worse than ac2
by inteq
Fri Nov 06, 2020 3:36 pm
Forum: General
Topic: timeout while waiting for program 20
Replies: 23
Views: 15009

Re: timeout while waiting for program 20

Random timeout while waiting for program 20 while monitoring with Dude a remote RB1100Ahx4 DE. snmp behind the remote RB also did not work on APs and other snmp enabled devices.. Disabled and enabled Dude and everything is back to normal. No reboot required. Can't be sure these days is something is ...
by inteq
Thu Nov 05, 2020 7:15 am
Forum: General
Topic: hAP ac³ identifies as hAP ac³
Replies: 3
Views: 688

Re: hAP ac³ identifies as hAP ac³

Indeed.
1.png
by inteq
Thu Oct 29, 2020 11:39 pm
Forum: The Dude
Topic: MikroTik RB1100AHx4 Dude Edition
Replies: 3
Views: 1673

Re: MikroTik RB1100AHx4 Dude Edition

Winbox/Dude/Services
Double click on your RB1100AHx4 DE and change the agent
by inteq
Mon Oct 26, 2020 7:21 pm
Forum: The Dude
Topic: RB1100AHx4 DE vs CHR
Replies: 0
Views: 1077

RB1100AHx4 DE vs CHR

Hello, Been using The Dude for about 2 years now on a RB100AHx4 Dude Edition. Lots of false positives, unbelievable high latency recorded and unstable upgrade of ROS devices. No crashes. Decided to switch to a CHR VM running on ESXi 7/Supermicro server. Moved the db to the CHR and beside having to r...
by inteq
Wed Oct 21, 2020 4:30 am
Forum: Wireless Networking
Topic: Audience as CAP Configure all 3 radios
Replies: 2
Views: 758

Re: Audience as CAP Configure all 3 radios

You can have only two configurations/provisioning rules. Set the provisioning for 5Ghz to 00:00:00:00:00:00 instead of the MAC of each CAP. One for 2.4 and one for 5Ghz The trick is to not select a frequency for 5Ghz and have the 3rd wlan enabled on the Audience. You might also need to set the band ...
by inteq
Tue Oct 20, 2020 2:13 pm
Forum: Wireless Networking
Topic: Low speed through CAPSMAN [SOLVED]
Replies: 6
Views: 4130

Re: Low speed through CAPSMAN [SOLVED]

No clue why I see this recommendation so often or why it works for some people (if not placebo) but in all my setups with wAP local-forwarding=yes or no, makes absolutely no difference. Same speed. max 400Mbps download max 500Mbps upload. Just tested this again on a wAP AC. One SSID with local-forwa...
by inteq
Fri Oct 16, 2020 6:20 pm
Forum: RouterBOARD hardware
Topic: hAP ac³
Replies: 42
Views: 12477

Re: hAP ac³

I know professionals with cool expensive toys will laugh their asses off, but this is the best I can do: one smartphone with WiFiman from Ubiquiti. wAP ac and Samsung Galaxy S9+ 1. Direct line of sight at 3 meters distance wap1.png 2. Behind a 19 cm thick concrete wall at 6 meters distance wap2.png ...
by inteq
Fri Oct 16, 2020 4:33 pm
Forum: The Dude
Topic: Dude dead again?
Replies: 5
Views: 2453

Re: Dude dead again?

6.47.4 and zero crashes on a RB1100AHx4 Dude Edition.
Have some issues with it, like remote upgrades getting stuck on upload all the time, but crashing is not one of them.
by inteq
Thu Oct 15, 2020 10:04 pm
Forum: RouterBOARD hardware
Topic: hAP ac³
Replies: 42
Views: 12477

Re: hAP ac³

Thank you @andriys for point this out. Indeed, you are correct.
I have briefly tested with only one concrete wall between the ac3 and the client and noticed the same behavior.
Tomorrow I will test this more thoroughly and get back with details in an up to 4 thick concrete walls location.
by inteq
Thu Oct 15, 2020 3:47 am
Forum: RouterBOARD hardware
Topic: hAP ac³
Replies: 42
Views: 12477

Re: hAP ac³

Tested today my first hAP ac3 Not impressed. Not even one bit. Same exact performance as hAP ac2, in a body twice the size, more expensive and with two useless antennae. Tested a hAP ac2, a wAP ac and the new hAP ac3 in the exact same location with an Intel AX200 client, direct line of sight at ~3-4...
by inteq
Tue Oct 06, 2020 2:00 am
Forum: RouterBOARD hardware
Topic: New haP ac2 became a brick
Replies: 18
Views: 9452

Re: New haP ac2 became a brick

Long shot but try repeatedly to put it in netinstall. And I mean 20-30 times.
Had two routerboards which I had to do this. Managed to fix them this way.

later edit: more then one month since original post. My bad. Maybe helps someone else in the future.
by inteq
Mon Oct 05, 2020 11:48 am
Forum: Wireless Networking
Topic: Audience throughput wifi problem
Replies: 6
Views: 1978

Re: Audience throughput wifi problem

4 Audience units without meshing in a building with 4 floors. 1 unit / floor. All 4 units CAP clients to a RB1100AHx4. Internet: 1 Gbps up/down fiber. Client: Intel AX200 and Samsung Galaxy S9+ wlan1 2Ghz 2 chains: ~90 Mbps up and down (might push more, but only 20 Mhz enabled) wlan2 5Ghz 2 chains: ...
by inteq
Fri Oct 02, 2020 1:12 am
Forum: Wireless Networking
Topic: Two CapaCs, Roaming Between them Optimized.
Replies: 4
Views: 872

Re: Two CapaCs, Roaming Between them Optimized.

I would not use access lists for WiFi.
Rejecting a client with it will disconnect any WiFi call.
I can "roam" just fine between access points without access list reject based on signal and keep my call.
by inteq
Wed Sep 30, 2020 9:51 pm
Forum: RouterBOARD hardware
Topic: hAP ac³
Replies: 42
Views: 12477

Re: hAP ac³

Even professionals call them modem because they got used to speaking with non-tech customers that only knows this terminology. Try talking to your average Joe and tell them about ONU/ONT. You just tell them modem and they know what you are talking about. No point in correcting them or explaining. Yo...
by inteq
Sun Sep 20, 2020 5:29 am
Forum: General
Topic: hAP ac2 over heated vent holes mod
Replies: 16
Views: 2320

Re: hAP ac2 over heated vent holes mod

I am all for mods, but ffs, stop this facebook crap.
I will not touch a facebook link even with a ten foot pole.
by inteq
Mon Sep 07, 2020 10:02 pm
Forum: General
Topic: IPsec passthrough issue (WiFi Calling)
Replies: 5
Views: 2924

Re: IPsec passthrough issue (WiFi Calling)

Using WiFi calling with default UDP timeouts and no problems here. Not with your provider tho.
by inteq
Fri Sep 04, 2020 3:54 am
Forum: The Dude
Topic: Upgrade stuck on uploading
Replies: 0
Views: 972

Upgrade stuck on uploading

I usually end up upgrading manually each site, but I would really like to get to the bottom of this. The Dude is installed on a RB1100AHx4 Dude Edition on the factory SATA SSD. I select the RBs 1st and "Upgrade to 6.47.3" or whatever the version might be. 99% of the time the uploads will g...
by inteq
Tue Sep 01, 2020 3:04 am
Forum: General
Topic: Script doesn't works
Replies: 4
Views: 667

Re: Script doesn't works

/tool e-mail send to=me@server.com subject="Something" body="Blahblah";
by inteq
Wed Aug 26, 2020 4:55 pm
Forum: Scripting
Topic: Check if list is empty
Replies: 2
Views: 1168

Re: Check if list is empty

After scratching my neuron a bit I came up with this Create a script that runs every 10 minutes or so: :local listcount ([/ip firewall address-list print count-only where list~"allowed-countries"]) :if ( $listcount = 0 ) do={ /tool fetch "https://api.telegram.org/botX:Y/sendmessage?ch...
by inteq
Wed Aug 26, 2020 1:04 pm
Forum: Scripting
Topic: Check if list is empty
Replies: 2
Views: 1168

Check if list is empty

Hello, Need to filter some services by country. Using the following script to download and create a list: ip firewall address-list :local update do={ :do { :local data ([:tool fetch url=$url output=user as-value]->"data") :local array [find dynamic list=allowed-countries] :foreach value in...
by inteq
Tue Aug 25, 2020 1:51 pm
Forum: General
Topic: DNS TIMEOUT
Replies: 7
Views: 1547

Re: DNS TIMEOUT

Both employees and guests networks are using the same DNS server or different ones? I bet not, thus guests having no problems.
Are you using any king of QoS? Maybe double check it. Might cut off DNS.
Are you using any king of rate limiting or "ddos" protection? Try disabling.
by inteq
Fri Aug 14, 2020 4:23 pm
Forum: General
Topic: RB4011 and RB1100 AHx4 "bricks" randomly
Replies: 222
Views: 70340

Re: RB4011 and RB1100 AHx4 "bricks" randomly

A new RB4011, bought last August, just died. No link on any port. Reset not working. Just keeping track here :) later edit: How I unbricked this RB4011 The RB had no link on any port. Reset to factory defaults did nothing. Could not put it into netinstall mode. So I took it apart to check for visibl...
by inteq
Wed Aug 12, 2020 4:09 am
Forum: General
Topic: Netwatch DNS Resolution
Replies: 1
Views: 1279

Re: Netwatch DNS Resolution

I use this to check a DNS server and change mikrotik's DNS server if it fails :local PrimaryDNS "1.2.3.4"; :local BackupDNS "9.9.9.9,149.112.112.112"; :local TestDomain "google.com"; :local ConfiguredDNS [/ip dns get servers]; :if ($ConfiguredDNS = $PrimaryDNS) do={ :do...
by inteq
Thu Jul 30, 2020 10:07 am
Forum: General
Topic: RB4011 and RB1100 AHx4 "bricks" randomly
Replies: 222
Views: 70340

Re: RB4011 and RB1100 AHx4 "bricks" randomly

And another RB4011 with 100% CPU usage on one core without traffic, just waiting to crash. And another useless response from support with "netinstall blah blah blah" after I sent them supout.rif I guess up time and letting the client actually use the devices they pay for is an unknown for ...
by inteq
Thu Jul 23, 2020 1:22 pm
Forum: General
Topic: Router Startup Problem
Replies: 2
Views: 843

Re: Router Startup Problem

Are you working for some optician business trying to get some sales going?
See https://wiki.mikrotik.com/wiki/Manual:Netinstall
by inteq
Wed Jul 22, 2020 1:58 pm
Forum: General
Topic: Renew License
Replies: 1
Views: 759

Re: Renew License

Are you able to login to https://mikrotik.com/client/login ?
Just tested on a CHR and everything works
by inteq
Fri Jul 17, 2020 7:28 pm
Forum: General
Topic: Wanted switch....
Replies: 1
Views: 881

Re: Wanted switch....

wanted.jpg
by inteq
Thu Jul 16, 2020 11:55 am
Forum: General
Topic: 3 routers in a row defective possible? [SOLVED]
Replies: 24
Views: 6076

Re: 3 routers in a row defective possible? [SOLVED]

Will setup with arp-ping=yes and interval=100ms and get back with details.
ping gatewayIP arp-ping=yes interface=ether1 interval=100ms
Thank you.
by inteq
Thu Jul 16, 2020 9:50 am
Forum: General
Topic: firefox 78.0.2 can not connect to mikrotik sites ...
Replies: 10
Views: 3634

Re: firefox 78.0.2 can not connect to mikrotik sites ...

I would not touch FF with a ten foot pole, but for you, I ran the portable FF 78.0.2 and I see no problem.
mt.png
by inteq
Thu Jul 16, 2020 8:59 am
Forum: General
Topic: 3 routers in a row defective possible? [SOLVED]
Replies: 24
Views: 6076

Re: 3 routers in a row defective possible? [SOLVED]

No BGP.
Just ISP > ONT > Mikrotik.
Direct connected IP on one ether and a subnet on another ether.
The netwatch and script is run on Mikrotik

Simple diagram
1.png
by inteq
Thu Jul 16, 2020 12:53 am
Forum: General
Topic: Protect RouterBOOT
Replies: 2
Views: 985

Re: Protect RouterBOOT

Format=no license. At least this was the case the last time I checked, a looong time ago.
If you want a clean device, use netinstall
If for some strange reason you really need to format, 1st ask at support@mikrotik.com explaining what you want to do and why.
by inteq
Wed Jul 15, 2020 10:46 pm
Forum: General
Topic: 3 routers in a row defective possible? [SOLVED]
Replies: 24
Views: 6076

Re: 3 routers in a row defective possible? [SOLVED]

This is getting a bit ridiculous. I setup a 4th Mikrotik in the location, a RB1100AHx4 Dude Edition. Problem still persists. I bought a P-Unlimited CHR license and setup RouterOS inside ESXi on a Supermicro server equipped with Intel X722 nics. Problem still persists. Setup a Netwatch to call a trac...
by inteq
Sat Jul 11, 2020 6:07 pm
Forum: General
Topic: Block outbound BPDU
Replies: 1
Views: 929

Re: Block outbound BPDU

Disable STP on the bridge.
by inteq
Sat Jul 11, 2020 6:02 pm
Forum: General
Topic: firefox 78.0.2 can not connect to mikrotik sites ...
Replies: 10
Views: 3634

Re: firefox 78.0.2 can not connect to mikrotik sites ...

Not sure, but I am guessing something with Firefox and by default enabled DoH in it.
by inteq
Sun Jul 05, 2020 5:14 pm
Forum: General
Topic: Blocking Torrent and P2P on RouterOS 6.44 and above
Replies: 6
Views: 18830

Re: Blocking Torrent and P2P on RouterOS 6.44 and above

Far from 100% but you can try a VM with pihole, intercept all DNS requests while blocking external DNS requests and use a blocklist with popular torrent trackers. Monitor pihole queries and add the missing ones. If this is for a business network, put HR to work. Notify employees and 1st strike you a...
by inteq
Sat Jul 04, 2020 12:15 am
Forum: General
Topic: VPN immediately disconnecting after authentication (Windows 10 client) [SOLVED]
Replies: 7
Views: 15122

Re: VPN immediately disconnecting after authentication [SOLVED]

Delete all WAN Miniports from device manager and restart.
With a bit of luck, that will fix it.
by inteq
Fri Jul 03, 2020 6:22 pm
Forum: General
Topic: 13Mbps for 480 students network?
Replies: 16
Views: 4083

Re: 13Mbps for 480 students network?

To be frank, only when I read "13Mbps lease line cost us USD3716.32/month" I thought that something is wrong and looked at the date.
by inteq
Thu Jun 25, 2020 7:36 pm
Forum: General
Topic: ping problem
Replies: 8
Views: 3444

Re: ping problem

Disable firewall on one of the machines that does not respond to ping. If you have Windows machines, open a command prompt and run: netsh advfirewall show allprofiles state Make sure the results are as in the image below: fw.png If ping works with firewall disabled, enable the firewall and create a ...
by inteq
Thu Jun 25, 2020 4:43 am
Forum: General
Topic: 3 routers in a row defective possible? [SOLVED]
Replies: 24
Views: 6076

Re: 3 routers in a row defective possible? [SOLVED]

Reinstalled the 3rd RB1100AHx4 tonight and did not have to wait longer than 2 hours for the first interruption. This time it lasted 2 minutes as reported by Dude. So far used 4 different factory crimped ethernet cables and one cat 6 made by me. /interface ethernet print stats taken after the 1st inc...
by inteq
Wed Jun 24, 2020 1:13 pm
Forum: General
Topic: RB1100AHx2 inconsistent CPU usage reported
Replies: 1
Views: 833

Re: RB1100AHx2 inconsistent CPU usage reported

Mikrotik responded with:
Hello

We have determined that this is a cosmetic issue that was introduced in v6.47 on some specific routers. We will try to resolve this problem as soon as possible.

Best regards
by inteq
Wed Jun 24, 2020 12:16 pm
Forum: General
Topic: 3 routers in a row defective possible? [SOLVED]
Replies: 24
Views: 6076

Re: 3 routers in a row defective possible? [SOLVED]

@sob I have tried without the Drop invalid rule when @tippenring suggested here https://forum.mikrotik.com/viewtopic.php?f=2&t=162627&p=801420#p801383. No change. @sindy Will have to reinstall the RB1100AHx4 to be able to check /interface ethernet print stats but if I recall there were some ...
by inteq
Tue Jun 23, 2020 9:59 pm
Forum: General
Topic: 3 routers in a row defective possible? [SOLVED]
Replies: 24
Views: 6076

Re: 3 routers in a row defective possible? [SOLVED]

To recap, 3 routerboards in a pure routing config, no NAT, no DHCP, no STP and even tested without a bridge: random packet loss lasting from couple of seconds to 1 minute. Did a test with only one interface setup with a public IP, without routing or anything else plugged into it: random packet loss....
by inteq
Tue Jun 23, 2020 1:44 am
Forum: General
Topic: Intermittent loss of packets.............argg
Replies: 28
Views: 8134

Re: Intermittent loss of packets.............argg

@anav
Found anything interesting?
by inteq
Sat Jun 20, 2020 7:34 pm
Forum: General
Topic: RB4011 and RB1100 AHx4 "bricks" randomly
Replies: 222
Views: 70340

Re: RB4011 and RB1100 AHx4 "bricks" randomly

And a new RB1100AHx4 started crashing. 2nd time today.
crash.png
by inteq
Sat Jun 20, 2020 10:48 am
Forum: General
Topic: Block gamers UDP traffic
Replies: 14
Views: 4519

Re: Block gamers UDP traffic

If the location is a business and the request comes straight from the top, imho the only viable solution is per computer screen monitoring after all employees have been notified. You get caught gaming, you are out. Trying to cover all bases on the router is a cat and mouse game. And we all know Jerr...
by inteq
Sat Jun 20, 2020 10:10 am
Forum: General
Topic: Stop making customers lab rats
Replies: 47
Views: 11790

Re: Stop making customers lab rats

Another 5 still pending investigation with lots of packet loss and 3 just quit working out of warranty. I'm curious, on your routers experiencing packet loss, do you have a firewall rule that drops invalids in the forward chain? If so, I'd be curious to see what happens if you disable that rule. Wi...
by inteq
Sat Jun 20, 2020 10:06 am
Forum: General
Topic: Stop making customers lab rats
Replies: 47
Views: 11790

Re: Stop making customers lab rats

Folosesti si switchuri Mikrotik ? Using switches also, but very few, so cannot really comment on those. Two CSS326. Both "modded" with two fans: one on the rear for air intake and one internal, blowing down on S+RJ10 modules. No problems with them besides crazy SPF+ modules temperatures. ...
by inteq
Sat Jun 20, 2020 1:16 am
Forum: General
Topic: Stop making customers lab rats
Replies: 47
Views: 11790

Re: Stop making customers lab rats

Reality is: Mikrotik should do a better job at quality control. A lot better. I am in far from a big Mikrotik client with around ~ 100 routers and ~200 access points, but still I had to RMA close to 10 routers for various reasons, ranging from DoA to flapping ports and mysterious crashes. Another 5 ...
by inteq
Thu Jun 18, 2020 5:24 pm
Forum: General
Topic: Bridge throughput problem
Replies: 1
Views: 726

Re: Bridge throughput problem

I would say because generating data is using a lot of CPU cycles, which your APs are in short supply. Thus, lower throughput.
by inteq
Wed Jun 17, 2020 11:32 pm
Forum: General
Topic: RB1100AHx2 inconsistent CPU usage reported
Replies: 1
Views: 833

RB1100AHx2 inconsistent CPU usage reported

Hello, The only RB1100AHx2 left in use is showing some strange CPU usage. Tool/Profile is showing consistent 100% CPU usage while System/Resources is showing almost constant 0% with small spikes to 1-2%. The unit is monitored with Dude, where the router shows again close to no CPU usage. Any clue if...
by inteq
Wed Jun 17, 2020 11:18 am
Forum: General
Topic: RB4011 and RB1100 AHx4 "bricks" randomly
Replies: 222
Views: 70340

Re: RB4011 and RB1100 AHx4 "bricks" randomly

Sending supout is in vain. They will just reply with a standard "Connect a serial cable to this device, open serial console and make sure that you have successfully connected to RouterOS CLI. . No I don't think sending supout in this case is in vain. More feedback will result in improvement. I...
by inteq
Wed Jun 17, 2020 10:42 am
Forum: General
Topic: 3 routers in a row defective possible? [SOLVED]
Replies: 24
Views: 6076

Re: 3 routers in a row defective possible? [SOLVED]

Sorry for bump, but this one is strange. Installed the 2nd RB1100AHx4 (the one purchased after the 1st RB4011) in another location. Same provider, same FTTH tech. 2 weeks already and absolutely stable. No packet loss at all. Setup a PC with intel nic in place of 3rd RB1100AHx4, in the problematic lo...
by inteq
Wed Jun 17, 2020 10:14 am
Forum: General
Topic: DNS over HTTPS
Replies: 235
Views: 95179

Re: DNS over HTTPS

In my opinion, doh is the first example of how much mikrotik cares about the safety of its users and other initiatives in this direction are welcome. Don't be fooled into thinking DoH provides any "safety" for users. I mean don't do stupid stuff online just because you have DoH enabled th...
by inteq
Wed Jun 17, 2020 3:00 am
Forum: General
Topic: RB4011 and RB1100 AHx4 "bricks" randomly
Replies: 222
Views: 70340

Re: RB4011 and RB1100 AHx4 "bricks" randomly

After few days or weeks, they just brick. I am very pissed off that mikrotik is pretty much ignoring this issue. . Please send Mikrotik supout and return them for repair if Mikrotik diagnose the issue as hardware issue. The more reports and investigations the better it will be long term. Sending su...
by inteq
Mon Jun 15, 2020 4:16 pm
Forum: RouterBOARD hardware
Topic: Mysterious Chateau CAT18
Replies: 7
Views: 4486

Re: Mysterious Chateau CAT18

Was expecting to see some castle with some state of the art cabling.
by inteq
Tue Jun 02, 2020 12:50 pm
Forum: General
Topic: RB4011 and RB1100 AHx4 "bricks" randomly
Replies: 222
Views: 70340

Re: RB4011 and RB1100 AHx4 "bricks" randomly

And again on a RB4011iGS+RM
crash.png
Hi,

What should i configure to get result as above? i mean automatically reboot after crash

regards,
M
Not 100% sure, but I guess that is handled by Watchdog under System.
by inteq
Mon Jun 01, 2020 11:55 am
Forum: General
Topic: 3 routers in a row defective possible? [SOLVED]
Replies: 24
Views: 6076

3 routers in a row defective possible? [SOLVED]

Hello, So I have a FTTH location where internet drops completely between 10 seconds to 2 minutes, at random times, for 1-4 times a day. Nothing in logs. No link downs on interface. Online UPS. 1st router: a RB4011. Because the router crashed couple of times, I thought those random internet dropouts ...
by inteq
Sun May 17, 2020 2:40 pm
Forum: General
Topic: ROS 6.x LOG display problem with high resolution and scaling
Replies: 9
Views: 3748

Re: ROS 6.x LOG display problem with high resolution and scaling

The issue is from at least 2013, if not from the beginning. ( viewtopic.php?t=77074 )
Still present in May 2020
by inteq
Tue May 12, 2020 11:13 pm
Forum: General
Topic: Winbox - router does not support secure connection
Replies: 4
Views: 5926

Re: Winbox - router does not support secure connection

I would try to do a netinstall and start from scratch.
For some reason, I am thinking about a hacked router in this case.
by inteq
Tue May 12, 2020 11:04 pm
Forum: General
Topic: RB1100AHx4 queries for www.mikrotik.com
Replies: 6
Views: 2098

Re: RB1100AHx4 queries for www.mikrotik.com

As I said: "The DNS on the router is not enabled.", thus no clients behind the router can cause this.
Somehow, the router itself queries for www.mikrotik.com
by inteq
Tue May 12, 2020 10:25 pm
Forum: General
Topic: RB1100AHx4 queries for www.mikrotik.com
Replies: 6
Views: 2098

RB1100AHx4 queries for www.mikrotik.com

Hello I have a RB1100AHx4 that sends lots of queries for www.mikrotik.com The DNS on the router is not enabled. No NAT, only routing. No scripts, no netwatch and I am unable to find the reason why this router queries www.mikrotik.com so much. As soon as I flush DNS cache, the record pops back in. qu...
by inteq
Fri May 08, 2020 6:53 am
Forum: General
Topic: RB4011 and RB1100 AHx4 "bricks" randomly
Replies: 222
Views: 70340

Re: RB4011 and RB1100 AHx4 "bricks" randomly

Setup Dude to monitor CPU on all 4011s
So far only two have issues but tired of this.
Starting to replace all 4011. Not worth the trouble.
cpu.png
by inteq
Sun May 03, 2020 3:22 pm
Forum: The Dude
Topic: Add CAPSMAN devices with same IP but behind different agents
Replies: 0
Views: 2011

Add CAPSMAN devices with same IP but behind different agents

Hello, My search came up empty so asking here. Setup a Dude Server on a RB1100AHx4 Dude Edition. Now, I need to monitor several locations with Mikrotik APs in CAPSMAN mode. I can add the APs in 1st location just fine, but on 2nd, 3rd, etc location, because APs have the same private IPs as on the 1st...
by inteq
Fri Apr 24, 2020 8:36 pm
Forum: General
Topic: RB4011 and RB1100 AHx4 "bricks" randomly
Replies: 222
Views: 70340

Re: RB4011 and RB1100 AHx4 "bricks" randomly

And again on a RB4011iGS+RM
crash.png
by inteq
Sun Mar 15, 2020 5:02 pm
Forum: General
Topic: 3CX NAT when using 2 Servers
Replies: 18
Views: 6626

Re: 3CX NAT when using 2 Servers

I have 2 3CX servers with firewall test failed on WUI, but everything works just fine for 3 years now. If you don't have any problems with RTP and calls, just ignore it. Me thinks 3CX is a bit dumb in that regard. Hi! are you using different ports for RTP on both servers? bests, Christian No. Using...
by inteq
Thu Mar 12, 2020 9:40 pm
Forum: Wireless Networking
Topic: Really disappointed in the lack of support. Evolved 3G Really?
Replies: 14
Views: 9147

Re: Really disappointed in the lack of support. Evolved 3G Really?

I'm fearing you're spreading some more FUD here ... No reason to fear. I said 4G LTE is just marketing and not real, true 4G. I am talking speed wise. You replied with "Actually its the other way around" and I asked "What is the other way around?" Are you stating that 4G LTE = r...
by inteq
Thu Mar 12, 2020 4:48 pm
Forum: Wireless Networking
Topic: Really disappointed in the lack of support. Evolved 3G Really?
Replies: 14
Views: 9147

Re: Really disappointed in the lack of support. Evolved 3G Really?

Actually its the other way around:
What is the other way around?
The discussion is about 4G LTE not "true" LTE.
by inteq
Thu Mar 12, 2020 11:46 am
Forum: Wireless Networking
Topic: Really disappointed in the lack of support. Evolved 3G Really?
Replies: 14
Views: 9147

Re: Really disappointed in the lack of support. Evolved 3G Really?

To reiterate what SiB stated:
4G LTE is technically 3G with some magic sprinkled on top. More precisely you can call it 3.95G.
The 4G in the name is only marketing. A bit like what AT&T did with their fake 5G E logo.
by inteq
Mon Mar 09, 2020 1:25 pm
Forum: General
Topic: UPNP -> which port are open?
Replies: 7
Views: 3702

Re: UPNP -> which port are open?

You can test your upnp with https://www.xldevelopment.net/upnpwiz.php ( https://www.virustotal.com/gui/file/817 ... /detection )
The tool allows for test upnp rules creation on your router and it works with mikrotik.
by inteq
Sun Mar 08, 2020 10:00 pm
Forum: General
Topic: UPNP -> which port are open?
Replies: 7
Views: 3702

Re: UPNP -> which port are open?

As freemannnn stated, you can see the automatically created rules in Firewall/NAT, with the comment starting with "upnp" If you do not see any such rules, go to IP/UPnP, disable the service, delete all your upnp interfaces and recreate them. Enable the service. See https://forum.mikrotik.c...
by inteq
Fri Mar 06, 2020 8:26 am
Forum: Beginner Basics
Topic: Ping drops first 2-3 packets then low stable latency. [SOLVED]
Replies: 3
Views: 6972

Re: Ping drops first 2-3 packets then low stable latency. [SOLVED]

Can you observe the same high latency when you ping directly from your Mikrotik router? How about other machines connected to the router? Do you have arp enabled on your internal interfaces/bridges?
I recall seeing such behavior on infected machines and networks with arp poisoning.
by inteq
Thu Mar 05, 2020 9:26 pm
Forum: Beginner Basics
Topic: I can't ping from an OVPN
Replies: 2
Views: 2226

Re: I can't ping from an OVPN

Try:

On Site A
/ip firewall nat
add action=accept chain=srcnat dst-address=192.168.2.0/24 \
    src-address=192.168.1.0/24

On Site B
/ip firewall nat
add action=accept chain=srcnat dst-address=192.168.1.0/24 \
    src-address=192.168.2.0/24
by inteq
Sun Mar 01, 2020 2:30 pm
Forum: Scripting
Topic: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)
Replies: 208
Views: 52772

Re: Address lists downloader (DShield, Spamhaus DROP/EDROP, etc)

PSA
Make sure you have whitelisted your private IPs if using https://raw.githubusercontent.com/fireh ... el1.netset
by inteq
Sat Feb 29, 2020 6:55 pm
Forum: General
Topic: Winbox - Open in new window makes text smaller
Replies: 0
Views: 2124

Winbox - Open in new window makes text smaller

Hello, First time today I have used the Winbox feature "Open in new window". Useful feature and saves a few clicks when opening many sessions. Nevertheless, with "Open in new window" ticked, the text in the new window is a lot smaller. oinw.png I can zoom in, but it seems the zoo...
by inteq
Sat Feb 29, 2020 6:19 am
Forum: General
Topic: RB1100AHx4 crash every 20 - 40 days [SOLVED]
Replies: 17
Views: 14403

Re: RB1100AHx4 crash every 20 - 40 days [SOLVED]

The question is: are you using an UPS for your rack/router?
Normally, the log "system,error,critical router was rebooted without proper shutdown" is the result of power loss and not an actual error/crash.
by inteq
Fri Feb 28, 2020 11:19 am
Forum: General
Topic: RB1100AHx4 crash every 20 - 40 days [SOLVED]
Replies: 17
Views: 14403

Re: RB1100AHx4 crash every 20 - 40 days [SOLVED]

viewtopic.php?f=2&t=149062

"Power users" use search.
by inteq
Wed Feb 26, 2020 9:05 am
Forum: General
Topic: RB4011 and RB1100 AHx4 "bricks" randomly
Replies: 222
Views: 70340

Re: RB4011 and RB1100 AHx4 "bricks" randomly

There are services 24*7, i can't reboot it every day...

I see. But if you prefer bricking... it is better a 30 sec outage for reboot in the night....
We prefer a fix. Rebooting every night ain't one. I hope you don't do that to your users.
by inteq
Tue Feb 25, 2020 8:25 am
Forum: General
Topic: 3CX NAT when using 2 Servers
Replies: 18
Views: 6626

Re: 3CX NAT when using 2 Servers

I have 2 3CX servers with firewall test failed on WUI, but everything works just fine for 3 years now.
If you don't have any problems with RTP and calls, just ignore it.
Me thinks 3CX is a bit dumb in that regard.
by inteq
Sun Feb 23, 2020 8:17 pm
Forum: Beginner Basics
Topic: How could I detect malware in my LAN
Replies: 6
Views: 3170

Re: How could I detect malware in my LAN

Tested on a simple firewall with 1st rule Accept established and related packets and 2nd rule Drop invalid packets (in forward section) I have the log rule as 3rd and it works just fine. Works with and without FastTrak and as long as the connection is forwarded. Test with another port, like 443 to b...
by inteq
Fri Feb 21, 2020 10:27 pm
Forum: RouterBOARD hardware
Topic: Diagnosing RB1100Ahx2 noise situation
Replies: 1
Views: 3003

Re: Diagnosing RB1100Ahx2 noise situation

Get an Y fan splitter and connect both fans to main if you want lower noise.
That is what I did on all AHx2 units.
by inteq
Fri Feb 21, 2020 8:20 pm
Forum: Scripting
Topic: IP block in mikrotik at specific time
Replies: 2
Views: 2405

Re: IP block in mikrotik at specific time

Not enough information.
You want to block access to cameras from within your local network or prevent access to them from internet?
Cameras are connected to your NVR Ethernet ports or to your dumb switch?
by inteq
Fri Feb 21, 2020 8:08 pm
Forum: General
Topic: Not full gigabit speed
Replies: 0
Views: 1437

Re: Not full gigabit speed

While testing your bandwidth, start a Tools/Profile to check if your CPU cores are not being fully utilized.
You can also test your Mikrotik's bandwidth here: viewtopic.php?f=2&t=104266
by inteq
Thu Feb 13, 2020 5:08 pm
Forum: Scripting
Topic: Diabling a DHCP server
Replies: 8
Views: 5464

Re: Diabling a DHCP server

https://wiki.mikrotik.com/wiki/Manual:S ... ter_values

But for most entries with a identifier, you can use the name instead:

/ip dhcp-server disable default
/ip dhcp-server enable default
Thank you. Good info.
by inteq
Thu Feb 13, 2020 1:31 pm
Forum: Scripting
Topic: Diabling a DHCP server
Replies: 8
Views: 5464

Re: Diabling a DHCP server

You should never use numerical index in scripts.
Any particular reason?
by inteq
Thu Feb 13, 2020 6:58 am
Forum: General
Topic: redirect ping public ip to 8.8.8.8
Replies: 5
Views: 2311

Re: redirect ping public ip to 8.8.8.8

What is the reason to port forward an ICMP packet to a DNS Server ?
Because everyone and their brother uses Google DNS as their default internet ping tester.
Then you would want it the other way around, Redirect icmp 8.8.8.8 to your IP
by inteq
Wed Feb 12, 2020 12:21 am
Forum: Beginner Basics
Topic: RB1100Hx2 basic setup
Replies: 9
Views: 3494

Re: RB1100Hx2 basic setup

Believe me...I have...tried...to read....your...question 3....times...but I....was...unable....to focus...and....understand...it.
by inteq
Wed Feb 12, 2020 12:11 am
Forum: Scripting
Topic: How to get IP address through CAPsMAN?
Replies: 4
Views: 3525

Re: How to get IP address through CAPsMAN?

Scripting is out of the question, as with every run, all clients will be disconnected from WiFi. At least I was not able to find a way to avoid that. My solution. (viable only for small deployments or locations without many guests like hotels or public venues) 1. Open your DHCP server lease window a...
by inteq
Tue Feb 11, 2020 2:03 pm
Forum: General
Topic: redirect ping public ip to 8.8.8.8
Replies: 5
Views: 2311

Re: redirect ping public ip to 8.8.8.8

1.png
2.png
by inteq
Tue Feb 11, 2020 1:49 pm
Forum: General
Topic: Mikrotik Rack-mounted Devices Visio Stencils
Replies: 53
Views: 73208

Re: Mikrotik Rack-mounted Devices Visio Stencils

C'mon, these are not realistic representations!
At least part of the unit should be obscured by the mighty power LED. If your eyes are not sore when you look at it, it is not a genuine Mikrotik.
by inteq
Tue Feb 11, 2020 1:15 am
Forum: Scripting
Topic: Diabling a DHCP server
Replies: 8
Views: 5464

Re: Diabling a DHCP server

To disable
/ip dhcp-server disable 0
To enable
/ip dhcp-server enable 0
If you have multiple DHCP servers, use /ip dhcp-server print to find the number corresponding to your server.
by inteq
Sun Feb 09, 2020 3:52 pm
Forum: Scripting
Topic: Transfering Address list from a Mikrotik device to another one and update it
Replies: 1
Views: 2239

Re: Transfering Address list from a Mikrotik device to another one and update it

Looks to me you will need to export your dynamic list to a file. See https://forum.mikrotik.com/viewtopic.php?t=114683 for some examples. Upload that list to a FTP server and make them available via a http server. Grab the rsc and import it where you need it. See https://wiki.mikrotik.com/wiki/Manua...
by inteq
Sun Feb 09, 2020 3:40 pm
Forum: Scripting
Topic: Script to capture Whatsapp IPs
Replies: 3
Views: 7301

Re: Script to capture Whatsapp IPs

Do you have some sort of pi-hole on your network?
Data=0.0.0.0 looks like a pi-hole blocking access to that domain. (if type != unknown)
by inteq
Thu Feb 06, 2020 4:06 am
Forum: Wireless Networking
Topic: CAPsMAN Broken With 5Ghz AC?
Replies: 3
Views: 3982

Re: CAPsMAN Broken With 5Ghz AC?

For 5 Ghz, just do not set anything besides frequency and band on channel settings
Example
36.png
by inteq
Thu Feb 06, 2020 3:56 am
Forum: General
Topic: Feature request: ask confirm for every operation
Replies: 9
Views: 1984

Re: Feature request: ask confirm for every operation

If it is not enabled by default, nobody will enable it. If it is enabled by default, everyone will disable it. Including the OP. Have frequent backups. Script them and send them by email daily. If it is an important router, pay bloody attention. Also, there is "Safe Mode" if you really hav...
by inteq
Tue Feb 04, 2020 5:36 pm
Forum: General
Topic: DHCP response mishandled (?) by MT AP
Replies: 2
Views: 883

Re: DHCP response mishandled (?) by MT AP

Login with Winbox to your AP.
Open a terminal and paste:
export compact hide-sensitive file=myconfig
Paste the content of that file here
by inteq
Mon Feb 03, 2020 10:51 pm
Forum: General
Topic: How to disable promiscuous mode?
Replies: 2
Views: 1592

Re: How to disable promiscuous mode?

The Packet Sniffer tool might put an ether in promiscuous mode?
by inteq
Mon Feb 03, 2020 5:44 pm
Forum: General
Topic: Add DNS over HTTPS (DoH) support
Replies: 130
Views: 113334

Re: Add DNS over HTTPS (DoH) support

But the privacy/restriction problem will only move from the ISP resolver to the DoH resolver chosen. Whether that is an improvement, depends on the local situation. but at least the user has the choice of which DNS resolver to trust and it's obscured to the transit providers. The question is: will ...
by inteq
Mon Feb 03, 2020 11:56 am
Forum: General
Topic: DNS Servers possible bug [SOLVED]
Replies: 5
Views: 2041

Re: DNS Servers possible bug [SOLVED]

/ip dns set allow-remote-requests=yes cache-max-ttl=2d query-server-timeout=3s servers=192.168.1.111,208.67.220.220,1.1.1.1,8.8.8.8 is your problem. If your private DNS has response times in 100s of ms, most likely it is the worst performer of the bunch. Thus, it will only be queried as a last reso...
by inteq
Sun Feb 02, 2020 6:46 pm
Forum: General
Topic: RB4011 and RB1100 AHx4 "bricks" randomly
Replies: 222
Views: 70340

Re: RB4011 and RB1100 AHx4 "bricks" randomly

No queues or pppoe server/client.
Not even NAT. Just routing.
2nd time this one crashes and reboots
mt.png
by inteq
Sun Feb 02, 2020 3:58 pm
Forum: Scripting
Topic: weird behavior using Netwatch commands & scripts [SOLVED]
Replies: 3
Views: 9677

Re: weird behavior using Netwatch commands & scripts [SOLVED]

Try another way of using your pi-hole. No need to disable the NAT rule

viewtopic.php?f=2&t=149968&p=738612#p738526
by inteq
Sun Feb 02, 2020 3:52 pm
Forum: General
Topic: Device reporting "false port" using capsman
Replies: 2
Views: 808

Re: Device reporting "false port" using capsman

Might be that your DHCP is not assigning the same IP to the scanner host and/or wifi printer, thus the scanner host cannot connect to the printer.
Try to make the leases static.
by inteq
Sun Feb 02, 2020 3:47 pm
Forum: General
Topic: Routing public IP addresses odd behaviour [SOLVED]
Replies: 9
Views: 2543

Re: Routing public IP addresses odd behaviour [SOLVED]

Anything else I need to add? Yes. Several hours at least on https://wiki.mikrotik.com/wiki/Manual:TOC As I said earlier: So, your /28 allow you to have 14 hosts. From 1 to 17 there are more than 14 hosts If that 123.123.123.?/28 is a real public subnet, you can only use 14 hosts (IP addresses) If y...
by inteq
Sun Feb 02, 2020 11:39 am
Forum: General
Topic: Winbox 3.20 (both 64bit and 32bit) crashing on DNS filter
Replies: 5
Views: 3353

Re: Winbox 3.20 (both 64bit and 32bit) crashing on DNS filter

1. Backup your Addresses from Winbox 2. Go to %APPDATA%\Mikrotik\Winbox and delete everything. 3. Remove the contents of the folder where you have your winbox.exe and download the latest from mikrotik.com 3. Restore your Addresses 4. Test Tried to replicate your issue and I could not get Winbox to ...
by inteq
Sat Feb 01, 2020 11:02 pm
Forum: General
Topic: Audiophile Level(Low Noise Floor, Silent) Mikrotik vs Ubiquiti Unifi Network Switch
Replies: 31
Views: 7700

Re: Audiophile Level(Low Noise Floor, Silent) Mikrotik vs Ubiquiti Unifi Network Switch

What? You just want a plain switch? Why didn't You say sooner?
He said so right from the start.
Why do you think most of us are having fun here.
by inteq
Sat Feb 01, 2020 6:39 pm
Forum: General
Topic: Bring Tapatalk back
Replies: 32
Views: 6756

Re: Bring Tapatalk back

Never understood the need for Tapatalk.
Most forums these days are mobile friendly and we have bookmarks in browsers for some time now.
Why do people use it?
by inteq
Sat Feb 01, 2020 6:23 pm
Forum: General
Topic: Routing public IP addresses odd behaviour [SOLVED]
Replies: 9
Views: 2543

Re: Routing public IP addresses odd behaviour [SOLVED]

So, your /28 allow you to have 14 hosts.
As far as I can tell, you have a 123.123.123.16/28
You assign 123.123.123.17/28 to your bridge and 123.123.123.18/28 123.123.123.19/28 etc to clients behind the bridge.
Correct so far?
by inteq
Sat Feb 01, 2020 6:16 pm
Forum: General
Topic: Slow DHCP
Replies: 1
Views: 1662

Re: Slow DHCP

Ehlo, 1. Identity has nothing to do with the name of your cabled network. See https://wiki.mikrotik.com/wiki/Manual:System/identity 2. Make sure you do not have another DHCP server in your LAN and leave ARP set to Enabled if you do not have any specific reason to set it otherwise. 3. If all else fai...
by inteq
Sat Feb 01, 2020 6:02 pm
Forum: General
Topic: Audiophile Level(Low Noise Floor, Silent) Mikrotik vs Ubiquiti Unifi Network Switch
Replies: 31
Views: 7700

Re: Audiophile Level(Low Noise Floor, Silent) Mikrotik vs Ubiquiti Unifi Network Switch

Don't go, please!
We don't have too many fun topics around here.
Please stay :(
by inteq
Fri Jan 31, 2020 12:32 pm
Forum: General
Topic: Changing PPPoE client name disconnects PPPoE and re-connects - WHY?
Replies: 10
Views: 2768

Re: Changing PPPoE client name disconnects PPPoE and re-connects - WHY?

Would be nice if the OS would change firewall rules and such without disconnecting the client.
No clue if it is possible or if it affects other stuff.
Then again, if you keep changing the name so many times, you are doing something wrong.
by inteq
Thu Jan 30, 2020 10:02 pm
Forum: General
Topic: Possible fix for hAP ac2 rebooting randomly
Replies: 117
Views: 33900

Re: Possible fix for hAP ac2 rebooting randomly

Had one location with a hAP ac2 with the same symptoms.
The owner was using a lousy power strip and of course, without an UPS.

Changed the power strip to a more sturdy one and added an UPS.
No more problems since.
by inteq
Thu Jan 30, 2020 2:23 pm
Forum: General
Topic: Audiophile Level(Low Noise Floor, Silent) Mikrotik vs Ubiquiti Unifi Network Switch
Replies: 31
Views: 7700

Re: Audiophile Level(Low Noise Floor, Silent) Mikrotik vs Ubiquite Unifi Network Switch

Thank you for the good laugh with "audio grade network switch". I needed that.
by inteq
Tue Jan 14, 2020 8:29 pm
Forum: RouterBOARD hardware
Topic: RB4011iGS+5HacQ2HnD ports and power issue
Replies: 1
Views: 2822

Re: RB4011iGS+5HacQ2HnD ports and power issue

The unit does not have the 1st 5 ports with PoE support. Only ether10 provides PoE out. I am thinking you are using an additional PoE capable switch that somehow does not negotiate power delivery as it should and it is causing the reboots. Just a guess. RB4011iGS does not have a WAN port. Any port c...
by inteq
Tue Jan 14, 2020 12:53 am
Forum: General
Topic: DHCP Offering Lease Without Success
Replies: 113
Views: 99195

Re: DHCP Offering Lease Without Success

I have this problem with lots of Mikrotik APs like RouterBOARD wAP G-5HacT2HnD and DHCP on routers like RB1100AHx4 and RB4011 AP without bridge gets an IP instantly on ether1. As soon as a bridge is created, no soup. The DHCP server is stuck on Offered To fix it I need to set STP Protocol Mode to No...
by inteq
Sun Jan 12, 2020 9:52 am
Forum: General
Topic: Add DNS over HTTPS (DoH) support
Replies: 130
Views: 113334

Re: Add DNS over HTTPS (DoH) support

I might be a minority here, but all this DNS over https/TLS,etc, in my opinion, has nothing to do with user's privacy at all, but it has everything to do with making ad blocking and corporate filtering obsolete.
by inteq
Fri Jan 10, 2020 4:31 pm
Forum: General
Topic: RB4011 and RB1100 AHx4 "bricks" randomly
Replies: 222
Views: 70340

Re: RB4011 and RB1100 AHx4 "bricks" randomly

Only one RB4011 (without WiFi) out of 12 crashed once with some process stuck.
None of RB1100AHx4 or RB1100AHx4 Dude Edition out of 19 crashed so far.
Also, bricking can happen to Mikrotiks, but it did not happen to me (yet) and if a power reset fixes it, it did not happen to you (yet).
by inteq
Fri Jan 10, 2020 7:02 am
Forum: General
Topic: Mikrotik LHG LTE kit test - video
Replies: 3
Views: 1454

Re: Mikrotik LHG LTE kit test - video

Just bought some LTEs from Mikrotik and was looking for some reviews.
Forum topic is in English, Youtube video description is in English, Youtube audio...Hungarian...
by inteq
Wed Jan 08, 2020 4:15 pm
Forum: General
Topic: RSTP, Stability...
Replies: 2
Views: 859

Re: RSTP, Stability...

Hello,

1. Disable neighbor discovery
2. Make sure you did not copy the config from one switch to another, thus having the same mac somewhere
3. Use search
by inteq
Tue Jan 07, 2020 5:00 pm
Forum: Wireless Networking
Topic: low troughput
Replies: 4
Views: 2361

Re: low troughput

Your devices are connecting on 2.4 Ghz instead of 5 Ghz, thus lower speed.
Make sure your clients have 5 Ghz WiFi support and setup your MT APs accordingly.
Thought about replying in Latin, but being the start of a new year, I decided to play nice. (also, I suck at Latin)
by inteq
Wed Nov 20, 2019 6:41 am
Forum: Wireless Networking
Topic: CAPsMAN slow my WiFi down
Replies: 25
Views: 13690

Re: CAPsMAN slow my WiFi down

It is clear that using capsman slows down wifi a lot. No matter the config, capsman will be slower. No clue as to why yet and it seems, Mikrotik is also in the dark or they just don't care/know. If you really need that extra speed, ditch capsman and in the future Mikrotik. That is what I will do whe...
by inteq
Sun Nov 17, 2019 3:26 pm
Forum: RouterBOARD hardware
Topic: UPnP Error
Replies: 1
Views: 2811

Re: UPnP Error

"while the IP Address in the rules is set to the correct one" I am guessing you are forcing the IP instead of using interface.
Try using the interface without forcing IP.
Make sure the internal interface is set to your bridge not your actual etherX, if you are using a bridge.
by inteq
Sat Nov 09, 2019 7:25 pm
Forum: General
Topic: Un dispositivo Varias IP
Replies: 19
Views: 3426

Re: Un dispositivo Varias IP

Yeah, everyone should just post in their native language.
Those who respond, should do it in their native language also, specially if its another language entirely.
Let's prove Tower of Babel is viable!
/s
by inteq
Fri Nov 08, 2019 6:23 pm
Forum: Wireless Networking
Topic: Reboot capsman clients after RouterOS update
Replies: 1
Views: 2172

Reboot capsman clients after RouterOS update

All my Mikrotik WiFi setups are capsman managed. APs are getting the new update from the central capsman server and reboot after the update is done. But to also upgrade the firmware on the APs, a second reboot is required. Some deployments have 10+ APs and would be a pain to log into every one of th...
by inteq
Mon Nov 04, 2019 1:36 am
Forum: General
Topic: Slow speed through gre+ipsec tunnel
Replies: 14
Views: 8997

Re: Slow speed through gre+ipsec tunnel

Test using iperf3 from a client behind each of your routers.
Not using the routers themselves.
by inteq
Fri Nov 01, 2019 5:10 pm
Forum: Scripting
Topic: delay a script by 4 seconds.
Replies: 6
Views: 19788

Re: delay a script by 4 seconds.

You want a delay after each entry from firewall is removed? Or after all entries are removed?
by inteq
Fri Nov 01, 2019 3:28 am
Forum: Scripting
Topic: delay a script by 4 seconds.
Replies: 6
Views: 19788

Re: delay a script by 4 seconds.

:delay 4000ms;
But I feel there is more to your question than a simple delay
by inteq
Thu Oct 31, 2019 3:17 am
Forum: General
Topic: Why the official Mikrotik.com site does use the Let's Encrypt?
Replies: 9
Views: 2439

Re: Why the official Mikrotik.com site does use the Let's Encrypt?

I still buy certificates for some clients, but lately, most of them issue 1 year certificates only. It is a hassle to renew manually so LE is a smart choice. For example, I just bought a 4 year extension for a client. My surprise: the certificate is valid only for 1 year, after which I have to reque...
  • 1
  • 2